Skip to content

D2-PROTO: the kernel's protocol registry leaves; kernel consumers read plane-declared data - #545

Closed
MattJackson wants to merge 4 commits into
p3-flip-llm-delfrom
p6-d2-proto
Closed

MattJackson wants to merge 4 commits into
p3-flip-llm-delfrom
p6-d2-proto

Conversation

@MattJackson

@MattJackson MattJackson commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

D2-PROTO (architect ruling 2026-10-07). This PR moves the dialect machinery out of crates/busbar-kernel/src/proto/ and into the plane that holds the dialects. Every kernel consumer now reads plane-declared data. crates/busbar-kernel/src/proto/ is deleted, and the kernel names no protocol or dialect (spec Part 2 #49, l.1186, #26, l.4688).

The commit message holds the details: the consumer-by-consumer rework, the ABI appends (RefusalCode 43-45, Claim.inbound_style/path_form, the PlaneTail.dialects[0] default rule, ServeIn.listing) and the full F25 test coverage map.

Proof (at c5473d7, merged with p3-flip-llm-del bfb954a)

  • cargo fmt --all --check: clean.
  • cargo clippy --workspace --all-targets --all-features -- -D warnings: clean.
  • Unfiltered suites:
    • busbar-kernel: 3009 passed.
    • busbar-plane-llm: 2446 passed.
    • busbar-contract: 1242 passed.
    • busbar-mcp (test-support): 557 passed.
    • busbar-kernel-identity: 105 passed.
    • busbar-auth-header: 19 passed.
    • busbar-auth-sigv4: 23 passed.
    • busbar-voice: 6 passed.
    • busbar-core-admin: 452 passed.
    • busbar (root, cdylibs built): 1007 passed, 6 failed, the same six as base bfb954a: the 4 framed_tests, the allocation ratchet (725 on both sides), and the ledger_identity reconcile.
  • Oracle replay against 1.5.5, strict, --id-filter, on the same engine for HEAD c5473d7 and base bfb954a:
    • ^(llm|teller|http\.crosscut|neutrality)\|: 183 cells, 183 judged rows each side, 165 PASS / 18 FAIL, rc=1 on both.
    • ^(ops\.scrape|boot\.refusal|boot\.warning|egress\.auth|egress\.headers|documented|route\.failover|usage\.gemini|billing|cli|core|config\.migrate|admin\.ops)\|: 754 cells, 806 judged rows each side, 687 PASS / 119 FAIL, rc=3 on both.
    • Every verdict row is byte-identical between HEAD and base.
  • Law 7, present not non-empty (85b8463): crates/busbar/tests/law7_model_section_present.rs boots the shipped binary on three documents. Each is held to bytes measured from a reference binary: models: {} from v1.5.5, a decisions document with models: {} from predev 6afec14, and no model section from this release (per the ruling). ORACLE-BURN is adding the cell neutrality|models-empty|surface.
  • xtask gates touched: design-bindings, construction, c1-literals, abi-header, door-only and structure-lint (decl_for rows) are green, except rows that are red on the base too. The red set matches the base except for rows that only fail because the branch has no pushed base; the selftest unproven set matches the base (tracing and structure-lint, both budget-only).
  • Grep: crates/busbar-kernel/src has no dialect literal in code. What remains: the kernel's /v1/models and /v1beta/models core routes (ruling D: the kernel keeps the routes), and the 1.5.5 byte-identical config_validate reserved-name message that mentions /v1/messages.

…r reads plane-declared data

`crates/busbar-kernel/src/proto/` no longer exists and the kernel holds no protocol or dialect
name (spec Part 2 #49). Dialects are inside a plane; a plane reading its own declarations is the
accepted mechanical change (l.1186); dispatch is by capability key (#26); the error catalogue is
error_map data (l.4688). Customer-visible behaviour is byte-identical to 1.5.5: the oracle replays
with no difference over llm|teller|http.crosscut|neutrality (183 cells) and over
ops.scrape|boot.*|egress.*|documented|route.failover|usage.gemini|billing|cli|core|config.migrate|
admin.ops (747 cells). The only FAIL rows are the same 9 missing.candidate cells the base shows.

ABI (busbar-contract/src/abi, the one home of ABI shapes; appended, never renumbered):
- RefusalCode NoRoute=43, WrongMethod=44, HandlerPanic=45 (42 stays reserved for #499).
- Claim gains inbound_style (STYLE_REQUEST_SIGNATURE) and path_form (the shared abi/transport/route
  vocabulary PATH_EXACT..PATH_CONTAINS), checked by check::claim_form.
- PlaneTail.dialects: dialects[0] is the plane's default dialect for an entry that names none.
- ServeIn gains a trailing `listing` blob (the names the kernel computed for /v1/models).
- Header and layout golden regenerated.

Consumer by consumer:
- auth failure status/envelope (auth/mod.rs, proxy::auth_failure_status_and_kind removed): the
  matched line's claimant renders the refusal through PlaneDriver::refuse_unitless; the status is
  the plane's stated (dialect, reason) row, else the listener's own 1.5.5 status.
- SigV4 pre-step: runs only on a fallback line whose claim states inbound_style
  request-signature; the lookup is lazy (allocation ratchet holds at base).
- fallback 404/405/413 and the panic 500 (ingress/dispatch.rs, router.rs, ingress/native.rs):
  NoRoute/WrongMethod/HandlerPanic rendered by the line's claimant, else listener_default.
- ingress detection (guest.rs Line/LineFacts, ListenerLines): the llm plane's claims carry the
  1.5.5 ladder: exact POST lines, the /v1beta/models subtree, the converse patterns (signed),
  the */v1/messages and gemini :action suffix lines, and the "/" contains fallback per verb.
- quota/limit refusal status (ingress::limit_refusal): the plane's refusal_statuses row.
- provider `protocol:` vocabulary, default and validation (config/providers.rs,
  config_validate, appbuild, telemetry): plane::fallback_wire_formats(), dialects[0] the default.
- /v1/models and /v1beta/models (endpoints.rs): the kernel keeps the routes and computes visible
  names; the fallback plane renders them through serve with ServeIn.listing.
- codec host services (entropy, wall clock, usage tap, translate cap): armed by
  plane_host::arm_codec_host_services at boot; MountHost removed.
- egress auth prebuild (egress_auth resolve/prebuild_auth/Declared*): dead on this base, deleted;
  bearer_auth_headers is the one helper left. kernel-identity present_declared deleted (no caller).
- request telemetry (telemetry.rs): the bank keeps the fallback plane's wire formats it was laid
  out over, so the per-request family lookup walks no registry (whole-path allocations back to
  the base's 725).
- busbar root: the protocols axis and test-linked-protocols are removed; door mounts honour
  path_form and skip what the kernel's core lines hold; DoorLines implements ListenerLines.

Gates: design-bindings PB-30/PB-65 cite the new homes; construction/c1-literals strike the
drained providers.rs literal and the deleted proto path; structure-lint's decl_for census and
fn-scoped rows point at busbar-plane-llm exchange::decl_for (the six identical private copies
there now use it); the axis bans lose the deleted kernel proto/ arm. cli_validate's signing-gate
test rides linked_axis_node (the same one-line fix as f8e9b71), so the workspace clippy is green.

Test coverage map (F25 ruling; no test deleted without it):
Re-homed:
- root linked_protocols (11) -> crates/busbar-plane-llm/tests/linked_protocols.rs (same names).
- kernel proto envelope tests (2) -> crates/busbar-plane-llm/tests/listing.rs.
- kernel operation-label tests (2) -> crates/busbar-plane-llm/tests/operation_labels.rs.
- usage tap -> crates/busbar-kernel/src/plane_host/tests/codec_host_services_tests.rs.
- empty registry -> kernel config_validate the_empty_set... and plane_dispatch
  ...no_fallback_plane_empties_the_list.
A1-7 registry-fold mechanics: registry deleted (D2-PROTO), no successor (installed_tests
  a_prefix_slice..., proto.rs installed_declarations_are_folded_ahead..., a_later_registration...,
  a_protocol_nobody_wrote..., protocol_install the_test_seam_does_not_redeclare..., root
  a_declaration_without_a_codec..., a_codec_less_declaration_does_not_move...).
B8  -> busbar-auth-header style_tests::the_static_styles_build_their_header_at_open;
       busbar-auth-sigv4 signing_tests::every_recorded_signing_row_signs_as_the_dialects_signer_wrote,
       ::the_held_day_key_signs_exactly_as_a_fresh_derivation
B9  -> crates/busbar/src/root/tests/door_steps.rs::the_api_key_override_binds_its_own_need_for_every_dialect
B10 -> busbar-auth-header present_tests::custom_header_builder_presents_the_raw_key_under_its_own_name,
       ::a_custom_header_style_omits_a_key_with_crlf_in_it, ::header_value_rule_is_the_header_value_type_rule
B11 -> busbar-plane-llm declared_scheme_tests::the_declared_dialects_carry_a_scheme_and_no_builder
B12 -> busbar-auth-header present_tests::every_static_dialects_recorded_credential_is_presented_as_its_builder_wrote;
       busbar-auth-sigv4 signing_tests::every_recorded_signing_row_signs_as_the_dialects_signer_wrote
B13 -> busbar-auth-sigv4 every_recorded_signing_row...; sigv4_tests::sign_v4_matches_aws_published_example
B14 -> busbar-auth-sigv4 signing_tests::session_token_is_sent_and_signed_over_the_writer_header_set
B15 -> busbar-auth-sigv4 signing_tests::unsendable_or_incomplete_signing_credentials_sign_nothing,
       ::an_access_key_id_the_wire_cannot_carry_signs_nothing
B16 -> root door_steps::a_members_binding_is_opened_with_its_dialects_parameters_under_the_providers_own;
       busbar-plane-llm test_bedrock_sigv4_fips_host_derives_correct_region,
       declared_scheme_tests::the_declared_region_answers_every_fixture_host
B17 -> busbar-auth-header present_tests::bearer_builder_presents_every_admitted_key_and_omits_the_rest
B18 -> busbar-plane-llm tests/exchange_attempt.rs::no_client_header_leaves_egress_unchanged;
       busbar-auth-header a_family_table_presents_by_prefix_then_by_mode
B19 -> busbar-plane-llm declared_scheme_tests::only_the_versioned_dialect_declares_a_static_header
B20 -> busbar-auth-sigv4 instance_tests::an_unsendable_session_token_is_reported_in_the_signers_own_words
B21 -> busbar-auth-header instance_tests::an_unpresentable_credential_is_reported_in_its_builders_own_words
B22 -> busbar-auth-oauth mint_tests::the_first_tick_mints_and_the_request_path_presents_it
B23 -> busbar-plane-llm handler_cells::no_handler_lookup_returns_none_for_unsupported_op
B24 -> busbar-contract tests/codec_rejects.rs::sub_op_reject_carries_op_and_model
B25 -> busbar-mcp mcp_tests::a_non_chat_operation_failure_reaches_the_breaker_with_a_status_attributed
B26 -> busbar-plane-llm handler_cells::every_cell_of_the_six_protocols_reports_its_protocol_vocabulary
B27 all_seven_protocols_frame_over_http -> busbar-plane-llm linked_protocols::every_declared_verb_has_a_serving_handler
B28 framing_carries_the_codec_through_unchanged: its subject (frame/OpDispatch) is deleted; reported.
New: plane_door claim tests (dialect per path under every verb, signed style on converse only,
  dialects[0] default), refusal_statuses unit-less row, listing (4 + 48 cells), root
  serve_listing (5), contract claim inbound_style/path_form checks.
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

promote into p3-flip-llm-del: NO VERDICT @99e055f7e

The hop ended without writing a verdict (runner lost, timeout, cancel, or it died before the engine judged): preflight: failure at step Run cargo run --locked --release --no-default-features -p busbar-release-cli --bin busbar-release -- ci preflight; publish: runner lost at step Run bash "$GITHUB_WORKSPACE/busbar-release/ci/promote/fallback.sh", Post Run actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1.

No failing-test list exists for this run. Run: https://github.com/GetBusbar/busbar/actions/runs/37627664089 . Re-run the hop, or read the job's step list in the run page.

…ty or not; the auth plugin's omitted-credential lines carry 1.5.5's protocol field at warning

Law 7 reads "present", not "non-empty" (spec Part 1 Law 7; coordinator ruling 2026-10-07).
#545's first cut removed the kernel's own dialect table. After that, a deployment whose
model-serving section was written empty (`models: {}`) had no line claimant: the root built the
plane's sections only when models or pools were non-empty, so the fallback plane never opened.
Every no-unit refusal and the listing then fell to the listener default. The oracle never saw
this because its configs always write a model.
- config/prepass.rs: the key reader records that the document writes `models:` or `pools:`
  (`DeployCfg::model_sections_written`, carried onto `RootCfg`).
- root door_steps `kernel_sections`: models/pools are handed over whenever written.
- tests/law7_model_section_present.rs boots the shipped binary on three documents and holds
  nine answers to bytes measured from a reference binary:
  - `models: {}`: v1.5.5 a71b21e (401 invalid x-api-key, 403 AccessDeniedException, 405, the
    dialect 404s, the empty listings).
  - A decisions document with `models: {}`: predev 6afec14.
  - No model-serving section: the plane is not loaded and the listener answers. Predev refuses
    that document at parse.
- kernel config test the_model_serving_sections_are_recorded_when_written_even_empty.

B21 (coordinator ruling: log lines are customer-visible):
- busbar-auth-header reports each credential it cannot present at WARN.
- The text is the 1.5.5 builder's message followed by its fields as tracing's formatter wrote
  them, measured on the 1.5.5 macro calls: ` protocol="openai"`, ` header="x-goog-api-key"`,
  ` protocol="anthropic" header="x-api-key"`.
- The protocol is plane data. The llm plane's bearer and credential-family dialects state
  `"protocol"` in their auth parameters; the static-header and signing dialects, whose 1.5.5
  lines named none, state none.
- Pinned by instance_tests::an_unpresentable_credential_is_reported_in_its_builders_own_words
  and plane_door::each_dialects_auth_parameters_name_the_protocol_its_1_5_5_line_carried.

Coverage map, B28 framing_carries_the_codec_through_unchanged ->
crates/plugin-loader/src/tests/transport_door_conformance_tests.rs::a_linked_and_a_dropped_in_door_frame_identically
("emit is the wire, byte for byte"; every framer runs that suite both ways).
The base brings the decisions flip's door-route refusals (PlaneRefusalSpec, pair_door_refusals,
PlaneDriver::refuse_unitless for a door route's 401, ARCHITECT 2026-10-05/06), D4's
metrics -> snapshot move, and config validation's union of a configured door plane's dialects.

Resolutions:
- auth/mod.rs: the auth step's `Door` carries the door route's refusal beside the listener's
  lines and the method. A door route's 401 is its plane's rendering, exactly as the base rules.
  Every other denial goes through the line the request matched (D2-PROTO), so
  `auth_failure_status_and_kind` / `vendor_auth_failure_message` stay deleted.
- plane_driver: the base's `refuse_unitless(reason, dialect, target)` keeps its name.
  D2-PROTO's listener-status form is `refuse_unitless_at(dialect, reason, status, text, target)`,
  used by the listener lines.
- root serve.rs / main.rs: `DataMounts` is (routes, sessions, refusals, lines). The routes and
  their refusals pair at boot, and the lines go to the handle.
- Kernel import lists take the base's `snapshot` and drop `proto`. Handlers' doc names
  snapshot::BILLING_TAP_DECODE_FAIL_TOTAL. The root tests and serve_listing name
  `busbar_kernel::snapshot`. The PROTO_OPENAI import the base re-touched in metrics_cross_plane is
  dropped; it reads the fallback plane's dialect.
- qa/c1-literals.toml: both sides' strikes. The base moved the sections.rs literals and D2-PROTO
  drained providers.rs.
- busbar-mcp's breaker-attribution port names the kernel's breaker once, keeping the
  ports-only-tests ceiling at 185.
…uest path's 1.5.5 spans (ARCHITECT RULING D1 2026-10-06); no conflicts
@MattJackson

Copy link
Copy Markdown
Collaborator Author

PLANE-EXTRACT (ARCHITECT ruling): crates/busbar-plane-decisions is leaving busbar for GetBusbar/busbar-plane-decisions. The busbar extraction PR lands once #575 and #560 are in, and it does not wait for this PR. When you rebase over it, drop this PR's crates/busbar-plane-decisions hunks. The PLANE-EXTRACT lane carries them as a PR on GetBusbar/busbar-plane-decisions plus a busbar pin bump. mcp follows later under the same rule; you'll get a separate note when it does.

@MattJackson
MattJackson deleted the branch p3-flip-llm-del October 10, 2026 02:28
@MattJackson

Copy link
Copy Markdown
Collaborator Author

Dead: closed when its base p3-flip-llm-del was deleted. It is not on predev, and the D2 stack waits for #464 as task draft-546-d2-kernel-stack. Branch p6-d2-proto bundled at ~/Library/Caches/busbar-release/salvage/GetBusbar_busbar-p6-d2-proto-1791611302.bundle and deleted.

@MattJackson
MattJackson deleted the p6-d2-proto branch October 10, 2026 06:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant