Skip to content

teller-steps: derive the step roster and the plane rows from the tree; add the decision row, rename voice to streaming, owe the 7 decision gating gaps by name (X5 finding 3) - #628

Open
MattJackson wants to merge 15 commits into
predevfrom
lane-gb-teller-steps-derive
Open

MattJackson wants to merge 15 commits into
predevfrom
lane-gb-teller-steps-derive

Conversation

@MattJackson

Copy link
Copy Markdown
Collaborator

teller-steps: derive the step roster and the plane rows from the tree (X5 finding 3)

The matrix was a roster the file wrote for itself: "every plane carries every declared step" was checked only against the file's own lists. Now both lists are DERIVED and compared with the matrix (check_roster, row teller-steps:matrix):

  • Steps: derived from the kernel's own StepName::ALL, as a set AND in loop order. The kernel's teller (crates/busbar-kernel/src/teller.rs) imports it from crates/busbar-contract/src/caps/step.rs:67 (enum at :42). Each step is spelled the way its as_str arm spells it.
  • Planes: derived from the PlaneMeta KEY of every plane-kind crate (busbar-plane-*). The kind census does this through a new kind_isolation::plane_meta_declarations, which reuses the census's own declared_meta_keys. Every key must have a matrix row, and every row must be a key some crate's impl PlaneMeta declares.
  • RED cases, each named:
    • a plane crate with no row;
    • a plane crate with no key;
    • a kernel step the matrix lacks;
    • a matrix step the kernel does not declare;
    • steps out of the kernel's order;
    • a row no crate declares.

Spec wording drift (coordinator ruling): spec l.154 (THE DESIGN §1) says exit, but the contract's StepName says Encode (spec row 72, l.2266, owner-locked, cites step.rs:42). Encode is persisted in audit records, so the matrix follows the contract: step exit is renamed to encode. The spec is not edited.

admin row: kept, and derived rather than hand-kept. busbar-core-admin/src/admin_codec/meta.rs:69 declares impl PlaneMeta for AdminPlane { KEY = "admin" }, and the root-admin leg serves it through the loop. With that, set equality holds.

Rows:

  • voice is renamed to streaming everywhere the roster names the plane: row, root-voice -> root-streaming, comments and notes. The voice.rig|… ids and testing/voice-conformance paths are genuinely voice-named and stay.
  • New row decision, the plugin's own PlaneMeta KEY (coordinator ruling). Its leg is root-decisions (crates/busbar/src/root/tests/serve_tests.rs, feature plane-decisions).
  • Root verdicts for the decision row:
    • authenticate: proven by the_data_router_built_with_the_door_serves_only_its_claims.
    • route: proven by a_plane_stating_no_breaker_fact_keeps_the_default_bench.
    • meter and encode: proven by a_claimed_request_is_served_through_the_door_and_its_money_posted.
    • the other six: none, each with an argued note.
  • Rig cells for the decision row: no rig in the tree has a decisions/jev scenario, so the cells are honest "none". The exception is arrival, which uses the shared concurrency|inbound-shed|n8.

Owed gaps (coordinator ruling, a visible floor that only shrinks, not an exemption): qa/teller-steps.json owed_gaps names the 7 decision gating gaps BY NAME, with owner DECISIONS-FIX: decision.authenticate, .verify, .admit, .route, .meter, .audit, .encode. teller-steps:gating-gaps passes only while the owed list EXACTLY equals the measured gaps:

  • a gap nobody owes is RED;
  • an owed entry that is no longer a gap is RED until it is struck.

The owed list is printed in the row detail on every run.

Arm and legacy adapter kept consistent:

  • cargo xtask teller-steps prints ROSTER: and OWED: lines, and translate() reads them back into the same Findings.
  • --root-legs adds plane-decisions to ROOT_FEATURES.
  • --root-legs now reads a #[path] mount (root/serve.rs mounts tests/serve_tests.rs as mod door_tests) to name the libtest module. The old file-stem convention could not produce root::serve::door_tests.

Proof (Latchkey, large)

  • Red without the fix: plant commit 90bb15e (the plants and data; run() still wired the old way). gate teller-steps --selftest (job cli-e4147d8a):
    • a plane crate with no matrix row: expected Red { naming: ["busbar-plane-shadow declares plane 'shadow', which carries no matrix row"] }, got Green
    • a kernel step missing from the matrix: expected Red { naming: ["which the matrix's 'steps' lacks"] }, got Green
    • a matrix step the kernel does not declare: expected Red { naming: ["steps.meter is a step the kernel does not declare"] }, got Green
    • a matrix row for a plane no crate declares and the kernel's steps in another order than the matrix's: also got Green.
    • an owed gap that was closed and not struck: IMPOSSIBLE (gating already red without the owed rule).
  • Green with the fix: merged head 736adcd (job cli-fe02f820). --selftest: 21 cases, all as expected, "the gate is proven RED-able". Budget: serial 18892 of 19811 work units.
  • The gate before and after:
    • BEFORE, predev 2bf9d9b: 5 rows PASS (50 cells, 5 legs, 0 gating gaps).
    • AFTER, head: 5 rows PASS (60 cells, 6 legs, 7 of 60 gating cells "none", each owed by name).
  • gate --all: base 2bf9d9b vs head, 555 rows each, the same row set. No row is worse. The non-PASS diff is only ship-ready:standing-reds, which is FAIL on base and not FAIL on head.
  • cargo test -p xtask (unfiltered) passes. cargo clippy -p xtask --all-targets -- -D warnings is clean. cargo fmt --all --check is clean.

Newly seen findings

The 7 decision gating gaps above are owned by DECISIONS-FIX (assigned by the coordinator), and that lane stacks the jev rig cells on this branch.

… no matrix row, a kernel step the matrix lacks, a matrix step or row the tree does not declare, the kernel's order, an owed gap closed and not struck; the matrix renames voice to streaming, adds the decision row and its root leg, and follows the contract's StepName::Encode
…e kernel's StepName::ALL (set and order), rows from every plane-kind crate's PlaneMeta KEY, and the gating gaps held to the owed_gaps list exactly
@MattJackson
MattJackson enabled auto-merge October 7, 2026 23:20
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

promote into predev: BOARD @71961859d: 0 failing test row(s), 11 DENY row(s)

DENY rows (11)

gate row detail
construction one-pick-site 3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8
kind-isolation kind-isolation:deps 3 finding(s), 93 shipped edge instance(s) over 30 class(es), 93 declaration(s); 56 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w
kind-isolation kind-isolation:test-deps 3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge
kind-isolation kind-isolation:law0 11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular
kind-isolation-ship kind-isolation:deps 10 finding(s) over 93 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a
kind-isolation-ship kind-isolation:test-deps 10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship
kind-isolation-ship kind-isolation:law0 11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular
kind-isolation-ship kind-isolation:faces 2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is
kind-isolation-ship kind-isolation:legacy-drain 3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier)
ship-ready ship-ready:ship-twin 'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is
structure-lint structure-lint:plane-dup:unledgered 22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger

Judged against base bd3947661: 0 new red, 0 worse, 5 standing (excused).

Reused PASS by input key (1, 1 min not re-run)
step key produced by
build:deletion-matrix febb102901ce1b39 18e473c06

tests passed: 24272, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/38058422807 . Artifact verdict-71961859d7f864774238d031312f1f92964fd252 (failures.json, junit.xml, raw.log; 90 days).

…her pool ends at verify before its dial), admit and audit over the served door; the matrix cites the cells
@MattJackson MattJackson added fixing and removed fixing labels Oct 10, 2026
…seals (Approve/ScopeDenied before admit and dial), not Verify/PoolNotPermitted

The served decisions door judges a key's pool grant at its approve seat, as the mcp and
a2a doors do; its verify step never refuses. CI's first panic was 'refused at verify:
unit_end: Refused(Approve, ScopeDenied)'. The cell is renamed to say what it proves and the
matrix row cites the new name.
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 10, 2026
@MattJackson MattJackson added fixing and removed fixing labels Oct 10, 2026
…root crate

The decisions verify test grew busbar x plane by 4 (figure 11 -> 15): two
plane-decisions cfg lines (serve_keyed and the test) and the bare mcp and
a2a in its doc. serve_keyed folds into serve_governed as its allowed_pools
argument (one cfg line gone), the doc says 'as every served door does', and
the budget test's doc drops a redundant 'llm plane' to offset the test's own
unavoidable cfg line. Net zero against predev; no ceiling raised.

Not proved on Latchkey: the run budget is spent (RUN_CAP); the PR's CI is
the proof.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant