…r reads plane-declared data
`crates/busbar-kernel/src/proto/` no longer exists and the kernel holds no protocol or dialect
name (spec Part 2 #49). Dialects are inside a plane; a plane reading its own declarations is the
accepted mechanical change (l.1186); dispatch is by capability key (#26); the error catalogue is
error_map data (l.4688). Customer-visible behaviour is byte-identical to 1.5.5: the oracle replays
with no difference over llm|teller|http.crosscut|neutrality (183 cells) and over
ops.scrape|boot.*|egress.*|documented|route.failover|usage.gemini|billing|cli|core|config.migrate|
admin.ops (747 cells). The only FAIL rows are the same 9 missing.candidate cells the base shows.
ABI (busbar-contract/src/abi, the one home of ABI shapes; appended, never renumbered):
- RefusalCode NoRoute=43, WrongMethod=44, HandlerPanic=45 (42 stays reserved for #499).
- Claim gains inbound_style (STYLE_REQUEST_SIGNATURE) and path_form (the shared abi/transport/route
vocabulary PATH_EXACT..PATH_CONTAINS), checked by check::claim_form.
- PlaneTail.dialects: dialects[0] is the plane's default dialect for an entry that names none.
- ServeIn gains a trailing `listing` blob (the names the kernel computed for /v1/models).
- Header and layout golden regenerated.
Consumer by consumer:
- auth failure status/envelope (auth/mod.rs, proxy::auth_failure_status_and_kind removed): the
matched line's claimant renders the refusal through PlaneDriver::refuse_unitless; the status is
the plane's stated (dialect, reason) row, else the listener's own 1.5.5 status.
- SigV4 pre-step: runs only on a fallback line whose claim states inbound_style
request-signature; the lookup is lazy (allocation ratchet holds at base).
- fallback 404/405/413 and the panic 500 (ingress/dispatch.rs, router.rs, ingress/native.rs):
NoRoute/WrongMethod/HandlerPanic rendered by the line's claimant, else listener_default.
- ingress detection (guest.rs Line/LineFacts, ListenerLines): the llm plane's claims carry the
1.5.5 ladder: exact POST lines, the /v1beta/models subtree, the converse patterns (signed),
the */v1/messages and gemini :action suffix lines, and the "/" contains fallback per verb.
- quota/limit refusal status (ingress::limit_refusal): the plane's refusal_statuses row.
- provider `protocol:` vocabulary, default and validation (config/providers.rs,
config_validate, appbuild, telemetry): plane::fallback_wire_formats(), dialects[0] the default.
- /v1/models and /v1beta/models (endpoints.rs): the kernel keeps the routes and computes visible
names; the fallback plane renders them through serve with ServeIn.listing.
- codec host services (entropy, wall clock, usage tap, translate cap): armed by
plane_host::arm_codec_host_services at boot; MountHost removed.
- egress auth prebuild (egress_auth resolve/prebuild_auth/Declared*): dead on this base, deleted;
bearer_auth_headers is the one helper left. kernel-identity present_declared deleted (no caller).
- request telemetry (telemetry.rs): the bank keeps the fallback plane's wire formats it was laid
out over, so the per-request family lookup walks no registry (whole-path allocations back to
the base's 725).
- busbar root: the protocols axis and test-linked-protocols are removed; door mounts honour
path_form and skip what the kernel's core lines hold; DoorLines implements ListenerLines.
Gates: design-bindings PB-30/PB-65 cite the new homes; construction/c1-literals strike the
drained providers.rs literal and the deleted proto path; structure-lint's decl_for census and
fn-scoped rows point at busbar-plane-llm exchange::decl_for (the six identical private copies
there now use it); the axis bans lose the deleted kernel proto/ arm. cli_validate's signing-gate
test rides linked_axis_node (the same one-line fix as f8e9b71), so the workspace clippy is green.
Test coverage map (F25 ruling; no test deleted without it):
Re-homed:
- root linked_protocols (11) -> crates/busbar-plane-llm/tests/linked_protocols.rs (same names).
- kernel proto envelope tests (2) -> crates/busbar-plane-llm/tests/listing.rs.
- kernel operation-label tests (2) -> crates/busbar-plane-llm/tests/operation_labels.rs.
- usage tap -> crates/busbar-kernel/src/plane_host/tests/codec_host_services_tests.rs.
- empty registry -> kernel config_validate the_empty_set... and plane_dispatch
...no_fallback_plane_empties_the_list.
A1-7 registry-fold mechanics: registry deleted (D2-PROTO), no successor (installed_tests
a_prefix_slice..., proto.rs installed_declarations_are_folded_ahead..., a_later_registration...,
a_protocol_nobody_wrote..., protocol_install the_test_seam_does_not_redeclare..., root
a_declaration_without_a_codec..., a_codec_less_declaration_does_not_move...).
B8 -> busbar-auth-header style_tests::the_static_styles_build_their_header_at_open;
busbar-auth-sigv4 signing_tests::every_recorded_signing_row_signs_as_the_dialects_signer_wrote,
::the_held_day_key_signs_exactly_as_a_fresh_derivation
B9 -> crates/busbar/src/root/tests/door_steps.rs::the_api_key_override_binds_its_own_need_for_every_dialect
B10 -> busbar-auth-header present_tests::custom_header_builder_presents_the_raw_key_under_its_own_name,
::a_custom_header_style_omits_a_key_with_crlf_in_it, ::header_value_rule_is_the_header_value_type_rule
B11 -> busbar-plane-llm declared_scheme_tests::the_declared_dialects_carry_a_scheme_and_no_builder
B12 -> busbar-auth-header present_tests::every_static_dialects_recorded_credential_is_presented_as_its_builder_wrote;
busbar-auth-sigv4 signing_tests::every_recorded_signing_row_signs_as_the_dialects_signer_wrote
B13 -> busbar-auth-sigv4 every_recorded_signing_row...; sigv4_tests::sign_v4_matches_aws_published_example
B14 -> busbar-auth-sigv4 signing_tests::session_token_is_sent_and_signed_over_the_writer_header_set
B15 -> busbar-auth-sigv4 signing_tests::unsendable_or_incomplete_signing_credentials_sign_nothing,
::an_access_key_id_the_wire_cannot_carry_signs_nothing
B16 -> root door_steps::a_members_binding_is_opened_with_its_dialects_parameters_under_the_providers_own;
busbar-plane-llm test_bedrock_sigv4_fips_host_derives_correct_region,
declared_scheme_tests::the_declared_region_answers_every_fixture_host
B17 -> busbar-auth-header present_tests::bearer_builder_presents_every_admitted_key_and_omits_the_rest
B18 -> busbar-plane-llm tests/exchange_attempt.rs::no_client_header_leaves_egress_unchanged;
busbar-auth-header a_family_table_presents_by_prefix_then_by_mode
B19 -> busbar-plane-llm declared_scheme_tests::only_the_versioned_dialect_declares_a_static_header
B20 -> busbar-auth-sigv4 instance_tests::an_unsendable_session_token_is_reported_in_the_signers_own_words
B21 -> busbar-auth-header instance_tests::an_unpresentable_credential_is_reported_in_its_builders_own_words
B22 -> busbar-auth-oauth mint_tests::the_first_tick_mints_and_the_request_path_presents_it
B23 -> busbar-plane-llm handler_cells::no_handler_lookup_returns_none_for_unsupported_op
B24 -> busbar-contract tests/codec_rejects.rs::sub_op_reject_carries_op_and_model
B25 -> busbar-mcp mcp_tests::a_non_chat_operation_failure_reaches_the_breaker_with_a_status_attributed
B26 -> busbar-plane-llm handler_cells::every_cell_of_the_six_protocols_reports_its_protocol_vocabulary
B27 all_seven_protocols_frame_over_http -> busbar-plane-llm linked_protocols::every_declared_verb_has_a_serving_handler
B28 framing_carries_the_codec_through_unchanged: its subject (frame/OpDispatch) is deleted; reported.
New: plane_door claim tests (dialect per path under every verb, signed style on converse only,
dialects[0] default), refusal_statuses unit-less row, listing (4 + 48 cells), root
serve_listing (5), contract claim inbound_style/path_form checks.
D2-PROTO (architect ruling 2026-10-07). This PR moves the dialect machinery out of
crates/busbar-kernel/src/proto/and into the plane that holds the dialects. Every kernel consumer now reads plane-declared data.crates/busbar-kernel/src/proto/is deleted, and the kernel names no protocol or dialect (spec Part 2 #49, l.1186, #26, l.4688).The commit message holds the details: the consumer-by-consumer rework, the ABI appends (RefusalCode 43-45, Claim.inbound_style/path_form, the PlaneTail.dialects[0] default rule, ServeIn.listing) and the full F25 test coverage map.
Proof (at c5473d7, merged with p3-flip-llm-del bfb954a)
cargo fmt --all --check: clean.cargo clippy --workspace --all-targets --all-features -- -D warnings: clean.--id-filter, on the same engine for HEAD c5473d7 and base bfb954a:^(llm|teller|http\.crosscut|neutrality)\|: 183 cells, 183 judged rows each side, 165 PASS / 18 FAIL, rc=1 on both.^(ops\.scrape|boot\.refusal|boot\.warning|egress\.auth|egress\.headers|documented|route\.failover|usage\.gemini|billing|cli|core|config\.migrate|admin\.ops)\|: 754 cells, 806 judged rows each side, 687 PASS / 119 FAIL, rc=3 on both.crates/busbar/tests/law7_model_section_present.rsboots the shipped binary on three documents. Each is held to bytes measured from a reference binary:models: {}from v1.5.5, a decisions document withmodels: {}from predev 6afec14, and no model section from this release (per the ruling). ORACLE-BURN is adding the cellneutrality|models-empty|surface.crates/busbar-kernel/srchas no dialect literal in code. What remains: the kernel's/v1/modelsand/v1beta/modelscore routes (ruling D: the kernel keeps the routes), and the 1.5.5 byte-identicalconfig_validatereserved-name message that mentions/v1/messages.