Skip to content

FLIP-STREAMING: the streaming plane served through its door; busbar-voice deleted - #503

Open
MattJackson wants to merge 126 commits into
predevfrom
p3-flip-streaming
Open

MattJackson wants to merge 126 commits into
predevfrom
p3-flip-streaming

Conversation

@MattJackson

Copy link
Copy Markdown
Collaborator

FLIP-STREAMING: the streaming plane is served through its door (busbar-plane-streaming), compiled in and dropped in. The legacy busbar-voice crate is deleted (DEL-VOICE), and the plane runs no tool executor (Law 11, Q98).

Includes p3-seam-ledger (#475) at 9ac6031. Merged with predev ca9ce1a.

Changes beyond the earlier lane:

  • predev merge fallout: the dest_judge flags word, the store row (Q-STORE (B)), compose_planes_over carrying public_url and hooks next to Q4: a plane's declared breaker fact (plane-neutral) #495's linked table, and serve_door taking Q4: a plane's declared breaker fact (plane-neutral) #495's breaker cells whole
  • the streaming door's validate reads the stage-3g deal ({streams: <section>}). Before this fix the flipped build refused every streams: config at boot
  • the voice conformance harness moved to its own testkit crate, testing/voice-conformance/harness. This keeps kind-isolation:closure green; the plane's only loader user is now tests/conformance.rs
  • golden/1.6.0-pre: streams|mint|client-secrets and streams|sdp|calls were re-recorded at the flipped upstream head order (authorization first), per the ARCHITECT 2026-10-04 18:10 ruling. Status and bodies are unchanged
  • RELEASE_REF and the oracle pin moved to busbar-release 30d072960a (busbar-release#168), which strikes the voice runtime plan row because busbar-voice no longer exists. The engine code is unchanged

Proof (Latchkey cli-7c706d20 at 5897c63, plus oracle-only cli-1ddd9b87 at e0eb1a8):

  • fmt, check (all-features, ndf), clippy -D warnings (all-features, default): green
  • the single-plane legs (streaming, llm, mcp, a2a, decision), the root test-harness, plugin-loader, and busbar-plane-streaming: green
  • the dropped-in tcp leg is red with the same failure predev has (http composes over tcp, which no transport serves)
  • xtask gate --all against predev: no new red rows. The only row changes are three busbar-voice rows that no longer exist
  • voice conformance rig: 14/14 legs pass, and the RED arm reds 13 legs
  • ws Autobahn: 11 failures, a strict subset of predev's 13. Control is green and the negative control is red
  • oracle: 7/7 streams cells are identical to golden/1.6.0-pre, and neutrality|routes|voice-shaped-404 is identical to 1.5.5. neutrality|boot-lines is red on predev too (tracing init, boot logging installs once; shadow-oracle cells regenerated by the pinned engine #473)

…e-request doors' answers and the served metadata document (fold S3a, S2c, S3b; 4 carried commits)

-- busbar-plane-streaming: the plane's door, compiled in and dropped in (fold S3a)
src/door.rs states the plane once, in its Statement tail, and publishes a snapshot per generation.
The tail carries the streams section (and providers required), the three dialects, the session
grant kind, the six billable classes, the per-session fee, the needs per direction (keyed ws/http
and signed ws inbound; the provider's ws and http outbound, targeted by streams.session.model) and
the egress target path. The snapshot claims the five doors a session opens through:
POST /v1/realtime/client_secrets, POST /v1/realtime/calls, the sideband and Gemini Live sockets,
and /twilio/{call_id}. It also binds the audience and metadata URL from one reading of the public
base URL. A deployment with no public URL claims nothing. validate/open/refresh judge the settings
blob with the streams grammar (unknown keys and a zero ceiling refused).

The door serves no unit yet. arrive, on_piece, refusal, serve and project answer REFUSED;
cancel answers CANCEL_FAILED, which bills nothing. The door is not linked into any build.

examples/streaming_door.rs exports the same door as a cdylib. tests/door.rs loads it through the
loader's plane kind, beside the linked door, and pins one transcript for both, plus the tail
against the kind's own check_tail.

Dependencies: url (already in Cargo.lock) for the one public-URL reading; manifest-allowlist
reviewed_extra gains busbar-plane-streaming = ["url"]. Dev-only: busbar-plugin-loader.

-- streaming: a tool call no one on the node serves is relayed to the caller; the echo executor leaves production (fold S2c, ARCHITECT ruling (c))
The served runtime ran every tool call through EchoToolExecutor. It serves every name, so the
gateway answered each call the model made with an echo of its own arguments, and the caller never
saw the call. The production executor is now ClientRelay, which serves no tool. The session pump
relays each call it does not serve to the caller, in the caller's dialect (open, argument deltas,
close). It plans the call's reply in the node's open-call table when one is bound, and never
authors the result. This is the loop the upstream realtime protocols define. A call a test executor
serves still runs and is answered as before. No server-side execution is added.

Tool calls are counted exactly as before (one per call opened), and no metering call site moves.

EchoToolExecutor is now a test double in busbar-voice's testkit, present only in test builds.
RED: session_pump_tests::a_call_no_one_on_this_node_serves_is_relayed_to_the_caller_and_never_answered_here
fails before this change: the call is executed, no call reaches the caller, and a
function_call_output is written upstream.

-- busbar-plane-streaming: the one-request doors' driver answers, and the door classifies an arrival (fold S3b)
src/driven.rs states the plane's answers to the kernel plane driver for the mint and SDP doors, as
plain data:
- which door a claim is, its dialect and the session-open op class;
- the ATTEMPT request bound for the far end: verb and target explicit, then fields and body. The
  mint carries the locked session params, the clamped lifetime and the caller's safety identifier.
  The SDP offer is relayed as it arrived. The plane never writes the credential.
- what the caller is answered from the far end's answer. The mint answers the secret and expiry, or
  the served plane's 502 text byte for byte (the status printed with its canonical reason phrase,
  as the served path printed it). The SDP relays status, application/sdp and Location, and names
  the rtc_ call id for the session record.

The door's arrive now classifies a claimed arrival: its door's dialect, the one op class the tail
now declares (streaming.session.open), and a required principal. An unpublished claim is refused.
The unit's pieces are still declined, so nothing is served or charged through the door.

-- streaming: the protected-resource metadata a refused caller is pointed at is served (ARCHITECT ruling on the metadata observation)
The served plane's challenge pointed at
<public_url>/.well-known/oauth-protected-resource/v1/realtime, but nothing served that document.
busbar-voice now mounts it the way mcp does: GET, RouteAuth::None, the RFC 9728 document built by
the kernel's one metadata renderer, with the plane's audience as `resource`. The plane is configured
with no authorization server, so the document names none.

The door claims the same route (CLAIM_OPEN | CLAIM_EXACT). Its arrive answers PRINCIPAL_NONE for it,
and driven::metadata_reply is the same document as data.

RED: mount_tests::the_resource_metadata_the_challenge_points_at_is_served follows the admission's
pointer to a served, credential-free route that names the audience. It fails before this change
because no route serves the pointer's path.

(cherry picked from commit b054f73)
… record, the unserved adapter deleted, the mint names no caller without a reference (fold S3c-1, S4-1, S1c; 5 carried commits)

-- busbar-plane-streaming: one live session as the driver serves it, with the telephony envelope (fold S3c-1, ARCHITECT ruling (b))
src/session_unit.rs is SessionUnit<C>, sans I/O. It holds the session pump, the session's
cumulative units per billable class (every closed turn adds to them, and the plane never cuts on
money; the kernel owns the cut), the wall-clock ceiling on the tick, the end that settles an open
turn once, and on the telephony door the Twilio Media Streams envelope (TwilioEnvelope, the one
Twilio reader).

On that door a start is checked against the locked g711_ulaw format (another format ends the
session). Media on the admitted stream becomes the far end's uplink append with the audio
unchanged. Media for another stream and any unmodelled event are dropped, and a stop ends the
session and settles the open turn. Model audio goes back to the caller as media frames on the call's
stream, and a barge-in clears the carrier's queued audio.

RED (ruling (b), the defect fix): session_unit_tests::the_callers_audio_on_the_telephony_door_reaches_the_far_end.
The served telephony leg fed Twilio's event-tagged frames to the realtime reader, which dropped
them, so the caller's audio reached no one.

Not served yet: the door does not drive SessionUnit until the kernel's session driver exists (S5).

-- busbar-plane-streaming: a live session keeps its record as the served plane did (fold S4-1)
SessionUnit now holds the session's record (VoiceSessionRow: id, owner, turns, updated_at, terminal,
rtc_call_id) and queues its writes the way the served plane wrote them: once at open, once when
the provider names the call (the SDP answer's rtc_ id), and once terminal at the end (a second end
writes nothing). The served plane never advanced the turn cursor, and neither does this. The owner
is the caller's reference the kernel lends, never the principal. The door hands the writes to the
kernel's records service once the session driver serves the door.

-- busbar-plane-streaming: the unserved plane's behaviour tests move onto the session pump and unit; the Twilio reader closes the empty-stream gap (fold S1c prep)
These changes get the unserved StreamingPlane (plane.rs, twilio.rs, ulaw.rs, oneshot.rs) ready for
deletion with no behaviour test lost (F25 map: busbar-run/foldstreaming-f25-plane-tests.tsv):

- The behaviour tests the plane-trait adapter carried are re-expressed on SessionPump and
  SessionUnit:
  - two open tool calls wait on two correlations;
  - an upstream error still meters its turn (40 s, 2 calls);
  - a barge-in carries its turn's counters onto the turn that takes over;
  - a non-UTF-8 or unknown caller frame goes nowhere;
  - milliseconds meter as whole seconds rounded up;
  - a Twilio stop settles audio and tool calls;
  - one full turn reports the six classes [10,20,3,4,1,1], cached excluded;
  - an empty streamSid start refuses the call;
  - a media payload resuming after padding is refused and never billed.
- TwilioBridge refuses a start with an empty stream id and never matches media without one. This
  closes the vacuous-binding gap the old reader had fixed. It also refuses a frame that is not
  Twilio's shape or carries unclean base64 (the old reader's refusal), and still drops an event it
  does not model.
- The zero-allocation downlink renderer moves into the one Twilio codec as
  TwilioEnvelope::encode_media_into. It writes the codec's own member order (event, streamSid,
  media), pinned by twilio_tests, and tests/alloc_gate.rs keeps its zero-allocation baseline
  against it.
- The tool-reply correlation key and deadline move from plane.rs to open_calls.rs, beside the leg
  that names them. plane.rs re-exports them until it is deleted.

-- busbar-plane-streaming: the unserved StreamingPlane adapter and its duplicate Twilio reader are deleted (fold S1c, F11, ARCHITECT ruling)
F11: the served implementation is the base. This deletes the plane-trait adapter nothing serves:
plane.rs (impl Plane / SessionPlane for StreamingPlane), twilio.rs (the second Twilio reader; ruling:
TwilioEnvelope is the one), ulaw.rs (a PCM16 transcoder no served path uses: the telephony leg is
locked to g711_ulaw both ways), oneshot.rs (the one-shot transcribe/tts dialect, outside the owner's
three-dialect scope). Also gone: session.rs's VoiceSessionState/Pending (the adapter's state) and
the test harness only the adapter used.

UNREACHABILITY, mechanically:
- The one production registration of StreamingPlane is the claims axis. There
  crates/busbar/src/root/registry.rs::plane_claims reads `(row.plane)().key()` (Plugin::key, lib.rs)
  and `row.claims` (PlaneMeta::CLAIMS, claims.rs), and nothing calls a Plane or SessionPlane method.
- Outside busbar-plane-streaming, no crate names busbar_plane_streaming::{plane, twilio, ulaw,
  oneshot} or session::VoiceSessionState. The one exception was the tool-reply deadline and
  correlation key, which the previous commit moved to open_calls. The grep over crates/ is empty.
- The served path (busbar-voice mount/runtime/topology) never reached the adapter.
So no served byte and no metered unit moves. Non-$ under the ARCHITECT's S1c ruling.

F25 (busbar-run/foldstreaming-f25-plane-tests.tsv, 60 rows):
- 18 port: re-expressed in the previous commit on SessionPump and SessionUnit.
- 19 covered: already asserted by the new modules' tests.
- 23 retire, each with its reason in the map. Seven are the µ-law transcoder, two the one-shot
  meters, and the rest the adapter's decode/encode plumbing.
The dialed-upstream lane fix (e157135) keeps its plane half in driven_tests (the Gemini door is
dialect 1). Its lane half belongs to the kernel's route at session open, and the driver session
suite must pin it.

The /v1/audio/* and BidiGenerateContent claims in claims.rs stay until S1a, which also gives the
audio paths back to the llm plane.

-- busbar-plane-streaming: the mint names no caller when the kernel lends no reference
K2 lends OnPieceIn.caller_ref only on a node that has signing-key material. The mint ATTEMPT now
takes it as an Option: when it is absent or empty, the OpenAI-Safety-Identifier header is omitted
rather than guessed. driven_tests pins both forms.

(cherry picked from commit 33cc324)
…door; proof fixes (4 carried commits)

-- busbar-voice runtime tests: drop the import the retired fold test used

-- fold-streaming proof fixes: the caller-ref pin test binds its HKDF key before expanding; two paths the S1c deletion left behind are struck
- busbar-kernel-identity caller_ref_tests: the pseudo-random key is bound before expand, which the
  borrow checker requires; rustfmt layout.
- qa/construction.toml kernel-seal-impls known_sites: busbar-plane-streaming/src/tests/harness.rs is
  deleted with the unserved adapter (S1c), and nothing else forges the seal there.
- xtask no_float_money ALLOWED_COUNT_READS: the two src/twilio.rs rows go with that file. The
  surviving Twilio reader, codec/topology/twilio.rs, keeps its own two rows.

-- busbar-plane-streaming: the plane answers each loop step through the door (ARCHITECT: restore the steps through the door, not the adapter); rustfmt
The unserved adapter's Plane-trait methods were the plane's only per-step answers, so deleting them
left kind-isolation:plane-steps red. driven.rs now states the plane's answer at each loop step, as
plain data the door and the driver use:
- authenticate: the principal a door needs.
- verify: the egress target path, streams.session.model.
- approve: the session grant and its pool.
- admit: the arrival estimate, none (a session pays for what the far end reports).
- route: the ATTEMPT request per door. The sessions dial the dialect's socket with no credential in
  the target; mint and SDP send their one request; the metadata document sends nothing.
- meter: the session's cumulative units per class index.
- audit: the action a door's unit is audited under.
The door's arrive answers through authenticate and admit. Every step has a pinned test.

This commit also carries rustfmt layout for the files the slice touched.

-- busbar-voice mount: the metadata route names the kernel through the imports already there (ports-only back to its base count)
The metadata route and its test had added three busbar_kernel:: spellings, and ports-only /
ports-only-tests turned red. The route now reads PlaneReqCtx and the metadata renderer through
mount.rs's existing busbar_kernel::plane_routes and ::ingress imports, and the test reaches
PlaneReqCtx as super::PlaneReqCtx. Measured by grep: every busbar-voice file's busbar_kernel:: count
equals the base 23d8a6b.

(cherry picked from commit c6906fb)
….rs, one Steps trait, text frames, the door's one session constructor (S3f; 6 carried commits)

-- streaming plane door both-ways proof moves to the loader, the #2 witness shape (ARCHITECT: the dev edge only as the witness); the dropped-door transcript bug is fixed
The first proof run failed the_dropped_door_answers_as_the_linked_door_does. The test reused one
dropped instance across both scripts, so the second script's open met an instance already open
(REFUSED), while a fresh linked instance answered READY. The doors themselves answered
identically. Each script now loads a fresh instance of each door.

The both-ways test also moves into crates/plugin-loader, as #2 (4)/(5) orders a kind's witness.
plugin-loader dev-depends on the real plane (busbar-plane-streaming), builds the dropped door as its
own `streaming_door` example (tests/fixtures/streaming_door.rs: export_door! over the plane's door),
and src/tests/streaming_door_tests.rs runs the same pinned transcripts. This removes the plane's
forbidden test edge plane -> plugin-tooling, and the kernel crates the loader's closure dragged into
the plane's test graph (closure-test-reach to kernel-ledger and kernel-wal). The plane crate keeps no
example and no dev edge on the loader. qa/kind-isolation.toml gains the one [[dep]] row for the
loader's test edge, cited to #2 like the transport and store witnesses.

-- streaming plane door both-ways proof: back in the plane, as tests/conformance.rs (the ARCHITECT's DOOR-TRANSPORT witness grant)
The previous commit put the witness in the loader, which traded the plane's test edge for a
forbidden plugin-tooling -> plane edge. The granted shape (ARCHITECT 2026-09-27, DOOR-TRANSPORT,
#2 (4)/(5); kind-isolation's conformance_witness_edges) is the plugin's own: a plugin of any kind
dev-depends on busbar-plugin-loader, and only its tests/conformance.rs names the loader. The ws
transport uses this shape.

The same test, with the dropped-door fix kept (a fresh instance per script), is now
crates/busbar-plane-streaming/tests/conformance.rs. The streaming_door example builds the cdylib.
The loader's dev edge, example and [[dep]] row are removed.

-- busbar-plane-streaming: the loop-step answers are one Steps trait the plane's doors implement; a design citation spelled in words; rustfmt
The kernel's plane-steps rule reads each step as a method the plane implements. The step answers
are now the Steps trait (authenticate, verify, approve, admit, route, meter, audit), implemented for
Door. The door's arrive answers through it. Behaviour and tests are unchanged; the step test calls
the methods.

The section-sign citation in driven.rs is spelled in words, as the crate's style test requires.
rustfmt also orders busbar-voice runtime/mod.rs's tool re-exports.

-- busbar-plane-streaming: a session's emitted frames are text messages, and either opcode is read (S3f plane half)
SessionUnit states FRAMES_ARE_TEXT: the realtime dialects and the telephony envelope are JSON
events, so the door sets the text bit (OnPieceOut PIECE_OUT_TEXT, in K2's layout commit) on every
frame a session emits. Inbound frames are read by their bytes: Gemini Live's server sends its JSON
in binary frames. The door's per-answer RED lands when on_piece is wired over K2's OnPieceOut; this
commit pins the plane's statement and that a Gemini frame's answers are text.

-- busbar-plane-streaming: the door's one session constructor; the telephony door opens the Twilio envelope's session (ARCHITECT ruling (b) RED)
sessions::open decides, per session door, the codec and the caller-side envelope in one place.
- The sideband door: OpenAI Realtime over the operator's locked params.
- The Gemini door: Gemini Live.
- The telephony door: OpenAI Realtime locked to g711_ulaw both ways, exactly as the served
  telephony leg locked it, behind TwilioEnvelope, the one Twilio reader.
- The one-request doors open no session.

RED, with the arm kept: sessions_tests::the_telephony_door_opens_a_session_behind_the_twilio_envelope.
A Twilio start plus media on the telephony door reaches the far end as an uplink append; the same
frames on a door with no envelope reach no one, which is the served defect.

-- session_unit_tests: the text-frame statement is checked at compile time (clippy assertions_on_constants)

(cherry picked from commit 86b96de)
… each door a guest-list line; the ladder RED (fold S3c-2a, section 6 step 3; 6 carried commits)

-- busbar-plane-streaming: one request unit as the route pump drives it; the mint, the SDP offer and the metadata document answer each piece (fold S3c-2a)
The route pump pushes an ATTEMPT, then the caller's body, then the far end's answer. RequestUnit
answers each in the plane's own vocabulary:
- The mint's ATTEMPT carries the whole request. The served path reads no caller body for the mint
  (its ttl is the default), so the caller's pieces answer nothing.
- The SDP ATTEMPT is the request head. The offer is relayed to the far end as it arrives.
- The far end's answer is gathered and answered once, on its last piece: mint_reply or sdp_reply.
  The Location comes from the kept response head, and a new ATTEMPT forgets the previous far end.
- The metadata document is answered on the first piece and dials nothing.
Writing the answers into the host's buffers is the door's slot (next slice, over K2's piece
layout: caller_ref, the kept head fields).

-- busbar-plane-streaming tests: rustfmt the Twilio claim RED ported from the deleted conformance file

-- request_unit: the far end's piece handler is not a from_* constructor (clippy wrong_self_convention); rustfmt

-- busbar-plane-streaming: each door is a guest-list line with its upgrade, default inbound auth and refusal dialect; the ladder RED (section 6 brief, step 3)
The ROUTES table now states each line the way the spec's guest list reads it (BUSBAR-1.6.0.md
section 6, 'Auth points and guest lists', step 3):
- method set, path (exact or {…} pattern; no prefix and no predicate, since no two doors share a
  path), and transport;
- upgrade for the three sockets: auth at Head on the upgrade request, then the connection goes to
  ws;
- the default inbound style (bearer, webhook-signature for the telephony line, none for the
  metadata document);
- refusal_dialect.
Door::dialect and Door::is_open now read the door's line, so there is one source.

RED (src/tests/ladder_tests.rs):
- every served route (the mount table plus the one telephony claim) resolves to the same
  (dialect, door, default auth) under the spec's match;
- fifteen requests no served route took resolve to no line, among them the deleted
  /v1/realtime/telephony leg and the /v1/audio paths;
- each line's own witness reaches it, and no two lines tie.
The match here is written from the spec. It becomes the kernel's guest-list match once
INBOUND-LISTEN's abi/transport match vocabulary lands. The published Claim flags are unchanged.

-- ladder RED: a served path under another method is 405 with the line's Allow, not no-route (ARCHITECT: the OWNER-approved kernel rule keeps predev's 405)
Six wrong-method cases move out of the no-route list and into their own RED. Each resolves to no
line, and its Allow is exactly the method of the one line whose path matches. The no-route list
keeps only paths that no line matches.

-- rustfmt: ladder_tests.rs SERVED const tuples
Applied verbatim from the proof job fmt diff (fs3); not re-run after the patch.

(cherry picked from commit 9be1f2c)
…y answers executes_here; qa: streams|metadata|protected-resource is an accepted difference (3 carried commits)

-- busbar-voice: name the streaming plane crate once per import group, not once per item (kind-isolation voice x plane nets down)
The re-exports of Outbound and SESSION_CEILING_REASON share one statement, the
three session imports share one group, and two doc comments no longer spell the
crate path. No behaviour change.

-- busbar-plane-streaming: ClientRelay answers ToolExecutor::executes_here, the name predev 1555e2d gave the trait method (rebase fix; census:count keeps one `serves`)

-- qa: streams|metadata|protected-resource is an accepted difference (ARCHITECT ruling on the metadata observation, owner-delegated 2026-10-01)
Fold commit 5768d32dc serves the RFC 9728 document at
<public_url>/.well-known/oauth-protected-resource/v1/realtime, the path the plane's challenge points
refused callers at. Nothing served that path before; that was a defect. The document comes from the
kernel's one metadata renderer, so it is the same document the mcp route serves
(bearer_methods_supported ["header"]). The pinned pre-fold build (golden/1.6.0-pre) answered that GET
with 401 invalid_api_key.

This is a register row, not a re-baseline: goldens are never blessed. Scope:
- the one cell (`^streams\|metadata\|protected-resource$`, expected_cells 1);
- the body class only;
- a premise that pins the candidate's single step to a 200 carrying exactly that document
  (bearer_methods_supported ["header"], a resource, no authorization server, no second step).
Signed as owner-delegated to the ARCHITECT. It expires against baseline 1.6.0-pre on 2026-12-31.
Its changelog line is added verbatim under 1.6.0 Improvements.

(cherry picked from commit ae77c52)
…'s loader, a refused arrival names REFUSAL_NO_DOOR and a 404; the tail names no caller-credential refusal on predev (4 carried commits)

-- busbar-plane-streaming door: published on P1's SDK (sdk::publish, Out<'_, T>)
P1 (SDK-SAFE) removed abi::sdk::Published and the `&mut out` slot form. The streaming door now
publishes the way P1's own doors do (plugin-loader's plane_door_plugin fixture):
- Each generation's snapshot is an owned SnapshotSpec: the six doors as ClaimSpecs, built from
  ROUTES by Route::claim, which carries each line's refusal dialect onto the claim; the audience and
  metadata URL from the one reading of the public base URL. It is published with Out::publish into
  the instance's Generations<PlaneSnapshot> and retired with its generation.
- A deployment with no public URL publishes an empty snapshot, which claims nothing, as before.
- Every slot takes Out<'_, T>, and scalar answers go through Out::set.
- The One Statement moves: the plane's sections and its needs ride on the Statement, not the
  PlaneTail. Section and the SECTION_* flags come from mechanism::door. The tail states P1's
  refusal_statuses and caller_credential_refusal as none.
- Need states no kept response headers and the host's default timeout.
No behaviour change: the same claims, audience, metadata URL, sections and needs.

-- busbar-plane-streaming conformance test: loads both doors through P1's loader (LinkedRow::of, the stated rendering for the dropped door, a labelled Bind with no connection table, ValidateIn's lent reason buffer absent); Route::claim wrapped as rustfmt wants

-- busbar-plane-streaming door: a refused arrival names the plane's code and a 404 (REFUSAL_NO_DOOR: no door of the plane serves that claim), as every REFUSED arrive must under the plane kind's check; rustfmt of the plane import list

-- busbar-plane-streaming door: the tail names no caller-credential refusal on predev (the field arrives with FOLD-A2A C1, which has not landed; the door set it to NONE)

(cherry picked from commit 2865331)
…the ledger (mount.rs:962/1164, testkit/echo.rs:9, topology/minter_https.rs:25, topology/telephony.rs:30; ARCHITECT ruling)

-- door-only: busbar-voice names no busbar_plane_streaming item at mount.rs:962 or testkit/echo.rs:9 (ARCHITECT ruling: a crate outside the plane reaches it only through its door, or the item moves to the side that owns it)
- committed_session_config moves back to busbar-voice (mount.rs), predev's body verbatim. Its only
  production caller is voice's hooks-TAP leg; the plane's door path never calls it. The plane
  copy and its two plane tests are deleted. Voice's own
  committed_session_config_refuses_what_it_cannot_use_and_patches_what_it_can still pins it.
- testkit/echo.rs (a test double, compiled only under test or test-support) implements voice's
  tool port as every voice file names it (crate::runtime::tools::ToolExecutor, as
  runtime/session.rs does). It no longer spells the plane crate.

No ledger row added; the gate is not widened. Served bytes unchanged.

-- door-only: busbar-voice's served mint, SDP and telephony legs keep their own pure pieces (mount.rs:1164, topology/minter_https.rs:25, topology/telephony.rs:30), as on predev
The fold's S2a moved the mint's request body, lifetime clamp and answer read, the SDP answer's
rtc_ call id and the telephony g711 lock into busbar-plane-streaming. busbar-voice, which still
serves those legs, then named them by Rust path, outside the plane's door. The ARCHITECT ruling
allows two fixes: re-route through the door, or move the item to the side that owns it.

The served legs are voice's until the streaming flip, so voice keeps predev's bodies verbatim
(minter_https.rs and telephony.rs are byte-for-byte predev; rtc_call_id_of is predev's
mount.rs function). The plane keeps its copies (broker.rs, session_params.rs) for its own door
path (driven.rs, sessions.rs). The two copies meet again when the flip deletes voice's legs.
Served bytes are predev's by construction.

Re-routing these legs through the door is the streaming flip: the governed open, the budget,
the durable row and the rtc stamp all move onto the kernel driver. That flip is escalated to the
ARCHITECT (escalate.q, FOLD-STREAMING door-only), and this commit is dropped if the ruling is
the flip. No ledger row added; the gate is not widened.

(cherry picked from commit fcf5bdd)
…o.lock as cargo resolves it (busbar-plane-streaming's url and busbar-plugin-loader edges)

(cherry picked from commit ac41f95)
…ted_resource_route

structure-lint:plane-dup:unledgered read voice's new `metadata_route` as a third copy of the
mcp/a2a symbol the ledger signs for those two only. Voice's handler does not duplicate theirs: it
hands its Metadata to the one shared renderer (protocol::metadata). It is renamed for what it
serves, so the duplicate count stays at predev's 24.

(cherry picked from commit f56d1a3)
…metadata document) answer their pieces through on_piece; the owed reply and the three-buffer settle have one SDK home (abi::sdk::piece)

BUSBAR-1.6.0.md Part 3 section 12, "The route pump" and "Crossings": the plane keeps what it
needs keyed by the kernel's unit; a full reply buffer answers more = 1 and the kernel re-calls
with the same from and zero bytes; an answer short of its field/arena room is re-called with the
same piece.

- The door keeps one RequestUnit per unit (bounded at MAX_UNITS, oldest dropped first), built at
  the unit's first piece over the newest live generation's session params and audience, and
  writes its answers: the ATTEMPT's verb, target, fields and body (to the far end), the caller's
  SDP offer (to the far end), and the caller's answer with its status and fields. A short answer
  is kept and re-answered from the kept copy, never read twice.
- A session door's pieces are refused: the kernel's driver serves request units only (no duplex
  session leg exists in plane_driver).
- busbar_contract::abi::sdk::piece: Owed (owe/pay across more = 1, EMIT_DONE with the last byte
  only), is_recall, settle. The llm, mcp, a2a and decisions doors each carry a private copy of
  this logic; each adopts the SDK home in its own lane (DEC-SERVE's two open branches rewrite the
  decisions door body, so it is not migrated here).

Tests (tests/conformance.rs, linked and dropped through the one loader):
the_one_request_doors_answer_their_pieces_through_the_door pins every answer, including the mint
ATTEMPT body equal to the far-end bytes of the recorded streams|mint|client-secrets cell
(golden/1.6.0-pre) and the metadata document paid 16 bytes at a time;
the_dropped_door_answers_the_one_request_doors_as_the_linked_door_does. RED before this commit:
on_piece answered REFUSED for every piece.

(cherry picked from commit f64d877)
…r axis under the development-only switch streaming-on-driver, bound through the loader's one load

BUSBAR-1.6.0.md Part 3 section 12, "The switch": a development-only cargo feature flips a plane
onto the driver during its fold and is deleted when the fold completes. The row follows the
decisions door row (#398, merged in here; this branch lands after #192 and #398):
streaming-on-driver = ["plane-streaming"], linked crate busbar-plane-streaming (already a root
edge), axis plane-door, entry busbar_plane_streaming::door. Never in default. With it on, the
busbar-voice row stays linked and serves every streaming route until the serve path hands the
door the arrivals it takes. TRANSITIONAL: deleted with busbar-voice.

The root's busbar-plane-streaming comment named a "root streaming unit" that does not exist; it
now names the switch's row.

Test: every_plane_switch_links_its_door_and_the_default_build_does_not, table-driven over every
plane-door row whose feature is not in default (decisions' and streaming's today), so the llm
switch's row is covered by the same test when it lands.

(cherry picked from commit 187da27)
…ontract ceiling moves); the switch's prose names no legacy crate and no plane instance it does not need

Measured on Latchkey (cli-5f45b31f) after the fold branches and predev were merged:
- construction: busbar-contract 29998 over its 29926 ceiling, the +72 being abi::sdk::piece.
  The module moves to busbar-plane-streaming/src/piece.rs, private to the door, unchanged in
  substance; whether the SDK takes it for every plane door is 1.6.0-QUESTIONS.md PIECE-HOME.
- kind-isolation --posture: busbar x legacy 85 -> 87 and busbar-plane-streaming x legacy 24 -> 25
  (the switch comment and the door doc named the legacy crate), busbar x plane 787 -> 792 (the
  switch comment and the switch test's prose). Q77 (owner 2026-09-25): risen rows wait for the
  final ledger pass, so they are drained here rather than re-armed: the comment, the door doc and
  the test name only the feature and the axis.

(cherry picked from commit 276afc5)
…OWNER 2026-10-02); after train/1 the piece answer moves to busbar-contract abi::sdk::piece and the five plane doors drop their copies (PIECE-SHARE)

(cherry picked from commit 2622ebb)
…stUnit::open), not a Unit minted

plane-pricing-blindness:unit-key (promote run 37088191095, shard 1) read door.rs's
`RequestUnit::new(` as `Unit::new`, the kernel-sealed constructor that attaches a UnitKey. The
door mints no unit identity: RequestUnit is the plane's own state for a unit the kernel already
keyed, held by that key. The constructor is named for what it does, `open`, as SessionUnit's is;
no money act moves and none is added.

(cherry picked from commit badd3db)
…e route, not the plane instance

kind-isolation:matrix busbar-voice x plane read 871 against predev's 870 on promote run 37088191095;
the one added hit is this lane's new handler text. Q77: drained, not re-armed.

(cherry picked from commit f37b012)
…ts audio reaches the far end and is counted, and the far end's audio reaches the caller

TODO STREAMING ("A PHONE CALL THAT CANNOT WORK, AND IS BILLED ANYWAY", first finding): every frame
on /v1/realtime/telephony/{call_id} went to the realtime codec, which reads no Twilio Media Streams
event, so the caller's audio never reached the model while the session opened, dialed and settled
one-way output; the far end's realtime frames went to the phone unenveloped.

- TwilioBridge and CallerStep move from session_unit.rs into codec::topology::twilio, the envelope's
  one home; the door's session unit and the live proxy both read it there.
- TelephonyProxy carries the envelope on the telephony leg (begin_telephony always;
  open_admitted_telephony when the leg is Ingress::Telephony, not the Gemini Live leg): caller
  `media` goes on as the far end's uplink append and is counted under audio_seconds_in; the
  caller's `stop`, or a frame the envelope refuses, hard-closes the carrier and the call ends with
  its open turn settled once; frames bound for the caller are rewritten into Twilio `media`/`clear`.
- The no-provider fallback is unchanged (no far end, no envelope, nothing heard or counted).

MONEY: a telephony call now bills the caller's audio_seconds_in (0 before: the audio was dropped)
and the provider-reported input tokens the far end now receives.

Tests (red without the envelope: the far end hears nothing, nothing is ledgered, the refused frame
leaves the call open): a_telephony_caller_is_heard_counted_and_answered_in_the_carriers_envelope,
a_telephony_frame_not_in_the_carriers_shape_ends_the_call_unheard,
a_leg_with_no_envelope_relays_the_far_ends_dialect_both_ways; the served witness and the mount
test place their call through testkit::telephony::place_call, speaking Twilio.

(cherry picked from commit 519c31c)
…t; the ceiling finding was closed on predev (Q21a/Q37)

(cherry picked from commit 2b2370a)
… the response-head rule (KEEP_NAMED, nothing kept or denied), the pump tests take the fold's STR-2 resolution, and busbar-voice serves no metadata route

The fold's door builds on the widened Need (keep_mode, deny list). The fold tip's session_pump_tests
carry MONEY-AUDIT STR-2 as the fold resolved it. The voice failed-dial refund cell names the
telephony flag the telephony money commit added.

The protected-resource metadata route (5768d32dc, carried in b054f73) is NOT served by
busbar-voice: its accepted difference (STREAMS-METADATA) is not in accepted-differences.json, and
this lane adds none, so streams|metadata|protected-resource keeps its golden/1.6.0-pre answer.
…iver's duplex vocabulary (K6): one frame per answer, unsolicited output named on the driver ticket, cumulative units on every answer, the ceiling on the tick clock

BUSBAR-1.6.0.md Part 3 section 12 "Duplex sessions (K6)" and Part 4 "Duplex sessions": the session
pumps pieces on two tickets; unsolicited output wakes the instance's driver ticket and `drive` names
it, collected FROM_KERNEL; cumulative units feed the kernel's session account (THE DESIGN section 7).
Spec Part 2 #18: the plane is streaming; the realtime voice dialects are dialects inside it.

- busbar-plane-streaming session_door.rs (new): one Live per stream over the door's codec (sideband
  and telephony: OpenAI Realtime, telephony locked to g711 as the served plane locked it; gemini:
  Gemini Live). A caller piece goes through the session and its far-bound frame is that answer's
  EMIT_TO_FAR_END (one turn); a far-end piece's caller frame is its answer; every frame keeps its own
  message boundary, so frames past the first are queued as unsolicited output; a far-side answer only
  reaches the caller and the session's end is answered on the caller side; the caller's last piece
  settles the open turn once; a cancel on either side's ticket forgets the session; the
  streams.session_max_secs ceiling is read on the tick clock (the door ticks every second while a live
  generation configures one; a piece carries no reading on that clock).
- door.rs: on_piece with a stream goes to session_piece (only a caller piece opens a session; units
  reported on every answer; far-bound frames carry the dialect socket's verb and target; caller frames
  PIECE_OUT_TEXT; a short answer is re-called from the stored answer, so no audio is counted twice);
  tick notes the driver ticket; drive names the ready sessions; cancel ends a session. A request unit
  on a session door is still refused. train/14 widened Need: the door's needs keep KEEP_NAMED and
  deny nothing.
- session_unit.rs: close_at_ceiling, the host-measured ceiling; tick uses it.
- busbar-contract abi/sdk/services.rs: Wake, the host's wake from HostTables, so a door under
  #![forbid(unsafe_code)] can name its driver ticket. SDK only; no ABI shape changes.

Tests: src/tests/session_door_tests.rs; tests/conformance.rs a_live_session_is_answered_through_the_door
and the_dropped_door_answers_a_live_session_as_the_linked_door_does (both ways, the real loader).

(cherry picked from commit e68c1f1)
…arrival names, project and the session open's hook view, upgrade-line claims, one outbound need per (transport, auth), text far writes, the lost voice proofs (plane half of lane-dg-streaming 974b5f7 5b8f145 322d2d4 98e9a95 cb5b3e4 3cf37af 0de6bdc)

Written against the plane-seam names (OnPieceOut::need, MULTI-NEED); builds once p3-plane-seam's
SEAM-ABI lands.
…port-ws on the connector-door axis; ARCHITECT Q-L5B-WS-DOOR, ruled 2026-10-04 for this lane: the same single-entry door-only shape as stdio's ruling (A) and the grpc exemplar), so the streaming door's ws needs bind compiled-in (lane-dg-streaming fb1c81d)
…aming

# Conflicts:
#	crates/busbar-contract/src/abi/sdk/mod.rs
#	crates/busbar/Cargo.toml
#	qa/construction.toml
…he style's default), and the tail states no caller-credential refusal and no admin routes
…ws#11): the dial's opening fields, held early messages, EMIT_TEXT writes, and the RFC 6455 failure order (lane-ws-read-end's framer half)
…ws#11 head; tree equal to 5f0b51273a): the ws row keeps its in-process build, since the root's transport-door build serves only a framer over the host's socket
…oot half): the composition folds a section's session.model from the top-level models catalog into the plane's route table, and hands each door plane the deployment's public URL

compose_served takes Deployment { public_url, catalog }; compose_planes keeps its signature
(compose_planes_in reads the deployment); open() hands PlaneOpenIn.public_url; the folded route table
is what DoorPools and member_routes read. The 1.5.5 shape of both sections is unchanged: the settings
the door opens with are never folded. Test: serve_planes
a_session_model_from_the_top_level_catalog_is_folded_into_the_route_table.
…ng: compose_served/compose_planes take the seam's public_url, so ROUTE's Deployment leaves; the catalog fold rides DoorReach.catalog (and ApplyReach, so a config apply re-derives the same route table)
@MattJackson MattJackson added fixing and removed fixing labels Oct 10, 2026
@MattJackson MattJackson added fixing and removed fixing labels Oct 10, 2026
…etion; the secret-source scan drives the streaming door

- population FLOOR 941 -> 926 (23 crates), tracing SCAN_FLOOR 971 -> 955, no-deferral
  DISCOVERY_FLOOR 932 -> 917: the counts CI measured at b2897a2 once the busbar-voice crate
  left the tree (a reviewed removal of a whole crate, not a scan gone blind). Fixes the
  settings-leak, response-header, blocking-ffi, tracing, no-deferral and no-deferral-strict-done
  gate rows, their selftests, and the two xtask infra no_deferral tests.
- secret_source.rs: the linked streaming door (found by the audio class it meters, as its root
  cells find it) gets the compose-time and across-an-apply drivers the decisions door has;
  serve_tests.rs' session_door rig takes the provider credential as a secret reference
  (session_keyed) and answers the composition's refusal. Fixes
  every_linked_door_plane_is_driven.

Not proven on a runner: the Latchkey run budget is spent (RUN_CAP), so the PR's CI is the proof.
The kind-isolation / kind-isolation-ship armed rows are not addressed here.
@MattJackson

Copy link
Copy Markdown
Collaborator Author

RULING (architect, Law 9, docs/design/BUSBAR-1.6.0.md l.2082-2097: "pins its ceiling at TODAY'S MEASURED VALUE and refuses every rise ... The drain runs behind it, ratcheting the ceiling down"): kind-isolation is judged PER CELL, no-worse-than-base. A PR may not raise any cell above its base; a cell it lowers takes the new, lower ceiling. Lowering or striking one [[law0]] row does NOT arm the whole row, and a PR is NOT required to drain predev's unrelated standing over-ceiling cells. Those are predev's own reds, owned by kind-isolation:law0-base (#747) and drained by their own lanes. No ceiling rises. If the engine's armed-red rule still judges the whole row, that is an engine defect being fixed in busbar-release now; this PR proceeds on its own cells.

@MattJackson MattJackson added fixing and removed fixing labels Oct 10, 2026
…955 under predev's computed floor plant

xtask/src/gates/tracing.rs conflicted: this branch re-pinned SCAN_FLOOR 971 -> 955 because
busbar-voice is deleted (BUSBAR-1.6.0.md decision #19: "busbar-voice is deleted (voice = a
streaming dialect, #18)"); predev 13a9ecb replaced the one-file selftest plant with
floor_plant / Overlay::below_floor. Both kept: floor 955 (the merged tree's crates walk still
reads 955 files; predev added or removed no files since d7929b6) with predev's plant and
its doc text.
@MattJackson MattJackson added fixing and removed fixing labels Oct 11, 2026
Conflicts: qa/teller-steps.json, xtask/src/gates/population.rs.

teller-steps: predev (#628) renamed the matrix's voice row to streaming and
re-pointed its root leg at gauntlet_kernel.rs session-rider cells whose
witnesses live in busbar-voice/src/tests/served_witness.rs. This branch
deletes busbar-voice, so those witnesses and cells no longer exist. Ruling:
keep predev's names (leg root-streaming, plane streaming, step encode) per
F10 (BUSBAR-1.6.0.md: "No plane-level 'voice' identifier remains"), and point
the leg at the streaming door's served cells in serve_tests.rs, the leg this
branch already proves and the one capability-equality's root column names
since FLIP-STREAMING. busbar-voice's deletion is row #19 ("busbar-core and
busbar-voice are DELETED in 1.6.0").

population: keep predev's computed selftest plant wording and the branch's
re-pin to 926 (busbar-voice deleted), measured on the merged tree: 926
non-test .rs under crates/, 23 crates.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant