Skip to content

P3 FLIP-LLM: the llm plane served through its door on the plane driver (dev-only llm-on-driver switch) - #464

Open
MattJackson wants to merge 73 commits into
predevfrom
p3-flip-llm
Open

MattJackson wants to merge 73 commits into
predevfrom
p3-flip-llm

Conversation

@MattJackson

@MattJackson MattJackson commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Part 3 §12 'The switch': the llm plane's project binding, far-end hook overrides through the kernel's existing egress walk (no second walk), K7 door probes, DECL-FOLD registry fold, per_request fee unit reported by the plane (money-B1; ledger_identity green), PLANELOG accepted difference (owner-signed 2026-10-04, #85), accept written by the plane. Hook gate on the driver: 85/85 llm-origin + 153 kernel/loader/ranking. Default build unchanged (switch never default). Oracle (door vs legacy, golden/1.5.5): door-only fails = 6 h2 cells (t-h2host #459) + 2 mint-refresh cells (seam mint parity) — all owned. instance-noun-neutrality:llm recorded as switch debt struck at D3.


Checks before queue (merge with predev fb5f12a / #511)

The walk's own words, every plane, with predev's bytes for the newer planes. The kernel hands each plane the exhausted walk's sentence in RefusalIn.text. The llm plane renders it in 1.5.5's words. For mcp, predev is the baseline (spec l.4593/l.4834), so the mcp door's refusal slot answers every BreakerOpen non-arrival refusal with the reason word breaker_open. Four new cells in root/tests/serve_tests.rs tools_door (*_in_predevs_bytes) pin the exact bytes predev serves, each run green on predev first:

  • (A) tripped server, -32030, unchanged;
  • (B) generic arm, {"code":-32000,"message":"breaker_open"};
  • (C, D) task continuation, the MCP upstream call failed: breaker_open.

The mcp conformance battery reads 63/63 on both trees.

Body-ingress convenience routes, positive cell. crates/busbar/tests/plane_integration.rs::an_audience_bound_token_is_confined_to_its_door_plane, with the llm plane's body ingress installed, asserts:

  • POST /{name}/v1/messages and POST /{provider}/{model}/v1/messages are mounted on the router;
  • both are guarded (not RouteAuth::None) and walked: anonymous gets 401, a keyed caller is admitted.

The root rig without body ingress counts the kernel's own 3 guarded routes (spec l.4093).

Oracle: strict replay of the llm Responses cells on the #464 tip

bin/oracle record --filter '^llm\|[a-z]+\|responses\|' then bin/oracle replay --baseline-version 1.5.5 --strict --id-filter '^llm\|[a-z]+\|responses\|' (RELEASE_REF e00d97f659), on Latchkey, #464 tip vs predev fb5f12a:

rc cells in scope judged diverging accepted
predev fb5f12a 1 34 15 6
#464 e5d118d 1 34 5 15

The 10 cells llm|{anthropic,bedrock,cohere,gemini,openai}|responses|request|ok(_stream) read PASS on #464 (identical or a registered ACCEPTED difference); on predev all 10 FAIL with effects.audit 0 -> 3 (6f6b8d2, codec/drops.rs ANSWER_DEFAULTS). rc stays 1 on both because of the same 5 cells, identical on predev: llm|responses|responses|request|{ok,ok_stream,upstream_down} and llm|anthropic|anthropic|request|{ok,ok_stream}, effects.egress same-dialect accept header (owned by #493).

ACCEPTED (report count) 6 -> 15: 9 cells pass on #464 by a registered difference. 6 of them are the Responses-door cells above, which FAIL on predev on effects.audit (a class no entry covers) and now match their body/header entry. The other 3 (llm|openai|anthropic|request|ok, llm|responses|anthropic|request|ok(_stream)) are premise cells that pass the same way on predev. Every entry is predev's, unchanged by #464 (its only register change is the PLANELOG entry, egress.image-detail|high|*, which matches none of these), and each carries an owner signoff:

cell ACCEPTED entry signoff
llm|bedrock|responses|request|ok_stream S-1 bedrock text blocks carry no contentBlockStart owner, 2026-09-04 parity triage
llm|cohere|responses|request|ok S-9 responses url citations survive the hop owner, 2026-09-06 round-5 codec audit
llm|cohere|responses|request|ok_stream E7-1 non-Responses doors stream when the backend is Responses-shaped owner, 2026-09-04 E7 triage
llm|gemini|responses|request|ok_stream E7-1 owner, 2026-09-04 E7 triage
llm|openai|responses|request|ok_stream E7-1 owner, 2026-09-04 E7 triage
llm|openai|responses|request|ok S-5 openai chat required members owner, 2026-09-04 maximum spec compliance
llm|openai|anthropic|request|ok S-5 owner, 2026-09-04 maximum spec compliance
llm|responses|anthropic|request|ok S-6 responses required members owner, 2026-09-04 maximum spec compliance
llm|responses|anthropic|request|ok_stream S-2 responses stream lifecycle frames owner, 2026-09-04 parity triage

Merge with predev 7d04bf0 (2026-10-07)

Two merges: predev 2bf9d9b (#535, U22 routed hook order), then predev 7d04bf0 (#487 auth split, #589, #594-#600, #610).

  • Hook order (ruled shape). Every plane runs predev's routed order (RoutedScope / HookStage::routed, LiveHooks + GovCaller). This line's per-unit arrived_in dialect binding rides inside it: the routed bind is Bind { dialect: arrived_in }, and a gate-first unit carries the arrived dialect's name. The lane's own pools-plane binder (HookStage::binder, kernel EngineCaller/HostSource/KeyLookup) is dropped. LiveHooks + GovCaller give the same facts on the same HostHooks bind path, so the hook sequence is unchanged.
  • Auth split (P2 D1: the auth split — auth-kind logic leaves the kernel for the auth plugins (stacked on #484) #487). The door reach takes predev's one process set of outbound auth instances (door_steps::process_auths). The model-serving pools, their live App handle and the config-apply refresh stay this line's, and so does sealed_settings (the dialect's host-label auth parameters). Manifests, the lock and the kind-isolation rows are predev's: busbar-auth-oauth 98fb861d14 contains 360a0d2c46, the compiled-in entry this line had cherry-picked as 22abf69390. qa/DESIGN-BINDINGS.md is regenerated.
  • info.auth_modules lists declares_chain_module rows only (sigv4 excluded), so 1.5.5's [keys, admin-tokens]. auth_tests::the_info_auth_modules_are_the_inbound_rows_only is green under --features llm-on-driver. The pin cell for this rides P2 D1: the auth split — auth-kind logic leaves the kernel for the auth plugins (stacked on #484) #487, not this PR.

Oracle: the auth-header claim is refuted

Recorded on the pre-merge #464 tip. Regex ^llm\|[a-z]+\|(anthropic|gemini)\|request\|ok(_stream)?$, door build (llm-on-driver), strict replay vs golden 1.5.5: rc 0, 24 PASS. Entry 581 rewrites only anthropic-beta / openai-beta / user-agent / accept, and the golden x-api-key / x-goog-api-key headers are reproduced.

Oracle: llm cells, predev 7d04bf0 vs this merge (Latchkey cli-c6aba011)

bin/oracle record --filter '^llm\|' then bin/oracle replay --baseline-version 1.5.5 --strict --id-filter '^llm\|' (engine pin 4d52f387c4; the filter widens to 5 premise cells; 138 cells recorded on each side), default build:

replay rc PASS / ACCEPTED FAIL
predev 7d04bf0 1 128 10
this merge 0 138 0

Only 10 cells move, all llm|{anthropic,bedrock,cohere,gemini,openai}|responses|request|ok(_stream). On predev they FAIL on effects.audit (6f6b8d2, codec/drops.rs ANSWER_DEFAULTS). On this merge they read PASS (gemini ... ok) or ACCEPTED by an existing owner-signed entry: S-4 (anthropic ok, ok_stream), F-014 (bedrock ok), S-1 (bedrock ok_stream), S-9 (cohere ok), E7-1 (cohere, gemini and openai ok_stream), S-5 (openai ok). The other 128 rows are identical, verdict and diff hash. The register is predev's apart from this PR's signed PLANELOG entry. No 1.5.5 cell moves unsigned.

Proof (Latchkey, head 6d28214's tree)

cli-c6aba011:

  • fmt clean; design-bindings --write then the gate, green.
  • clippy -D warnings: workspace, -p busbar --features llm-on-driver, -p busbar --no-default-features, all clean.
  • busbar-kernel 2872/0/5; busbar-contract 1244/0/5; busbar-plane-llm 2298/0/2.
  • busbar default 1047/0/2, plus ledger_identity (below).
  • busbar --features llm-on-driver (--bin busbar, hook_parity_driver, plane_driver) 797/0/0.
  • busbar-plugin-loader 667/0/3, plus the two secret-kind both-ways cells (below).

cli-1f654ad8 (the harness prerequisites cli-c6aba011 lacked: the secret-env cdylib built from its pinned checkout, and BUSBAR_ORACLE_RUST_BIN):

  • a_dropped_in_secret_plugin_is_the_same_plugin_through_the_axis and a_linked_and_a_dropped_in_secret_plugin_resolve_identically ok.
  • ledger_identity 8/0.

…ess walk, and the driver's flip seams (BUSBAR-1.6.0.md Part 3 section 12, lines 2573-2576 "the route step is the kernel's existing egress walk ... the driver builds no second walk", 2655-2659 "A far end exposes its candidates and a constraint the hooks apply")

Ported from the lane-dg-llm snapshot onto the foundation (5e0560f) without its a2a/h2/DEL-LLM pieces:
- busbar-kernel-egress: the walk takes the unit's hook Shape (Walk::next_shaped): each pick's
  admissible members as the hooks keep and order them (the order is the pick's preference), a
  required restrict no member satisfies sheds Shed::restrict_no_lane; Walk::walking names the pool
  the walk is in. Member.passthrough (a pool's upstream_credentials: passthrough), the latency port.
- EgressFarEnd: candidates/constrain/remaining/failure (the routing tap's untried count and last
  failover label), MemberFacts (tags, tier, cost), the restrict's veto at the fallback boundary,
  the exhaustion terminal's own words (Pick/End::Exhausted carry Shed::detail), a terminal's
  dispatch relayed and never failed over or counted as an attempt, the latency signal at the
  response head, the pool-passthrough credential lending (an empty credential when the caller
  presented none).
- the driver: DriverSteps::refused_words and ::attempting, render_as's Retry-After, the head stated
  once; hooks.rs binds the unit's dialect, reads the current generation (HostSource), the
  production EngineCaller, a taps-only unit proceeds over an unreadable request, the access
  amendment names the caller's governance key.
- the kernel's own tables view (ConfigTables) and the root's config projection on App; ingress:
  any_body_ingress; telemetry, core_routes, router and caller-credential seams the door path uses.
- tests: the K5 far-end constraint and restrict cases, the least-bad relay, the pool-passthrough
  lending, the K5 hook cases over the driver double's project (plane_driver_hook_cases.rs).
…t module, its door's tail facts, and the dialect auth parameters (BUSBAR-1.6.0.md Part 3 section 12 lines 2568-2571 "`project`. A pure plane op that writes the hook kind's own `RequestView`"; lines 2655-2658 "`project` may return a rewrite, which the plane applies and re-projects; `PromptView` carries plane-flattened messages; the projection may carry the end user")

Ported from the lane-dg-llm snapshot (f804c37, d6bca87, cd46f09, b0b7299 and the
plane parts of 24cda1e/5ac7cc8790/b26be1ca6d/99d4dd92e9/e581423073), without the LLM-UA, DEL-LLM
or a2a pieces:
- busbar-plane-llm exchange/project.rs: the hook view read through the operation's own reader, as
  1.5.5's hook seam read it (turns, screenable characters, tools, end user, the system field and one
  (role, text) per wire turn); a request-stage rewrite applied in the unit's own dialect and kept as
  the unit's request, so every attempt is written from it; an unreadable body REFUSED, the unit's
  refusal then reading 1.5.5's unreadable-body sentence; a gate veto rendered as the gate's own words.
- plane_door: the `project` slot (strings in the host arena, turns in the host turn buffer, the one
  re-call when short); an arrival names its route (the model as a pool first, else a direct entry;
  ARCHITECT Q-SW6/Q-FL2/Q-FL3); the token classes under the card names 1.5.5 priced (input, output,
  cache_read, cache_write); `pool` as the registration noun and the grant's scope kind; each
  dialect's default outbound style and one need per style (ARCHITECT Q-L1-AUTH (A)).
- AUTHPARAMS (ARCHITECT RULINGS 2026-10-03 14:45Z, Q-L6-AUTHPARAMS): DialectAuth.params appended
  (layout golden and C header follow), checked by check_dialect_auth and kept by the loader; the
  anthropic key-family and bedrock sigv4 parameters the dialects state.
- the far request carries its dialect's declared static fields (ARCHITECT SD-3 (1)) and lays a
  same-dialect caller's fields over busbar's as 1.5.5's header map did; a whole rendered answer
  states its length.
- the auth plugins' compiled-in entries (busbar-auth-sigv4, busbar-auth-oauth) for the `auths` row.
… composed on the serve path and every arrival it claims is served through the kernel's plane driver, its hook stage bound and its egress the model-serving walk (BUSBAR-1.6.0.md Part 3 section 12 lines 2669-2674 "The switch ... a fold adds only its door rows. A development-only cargo feature flips a plane onto the driver during its fold ... The llm flip's gate is every hook test green on the driver"; lines 2573-2576 the route pump is the kernel's existing egress walk)

Ported from the lane-dg-llm snapshot's FLIP-LLM (2), (4), (5), (6), (8a), (8b), oracle rounds and
follow-ups (24cda1e, e91a20b, 5ac7cc8, b26be1c, c679bf1, 072d65c, 99d4dd9,
8b7b35d, e581423, 8039732, 5613e7b), onto predev's serving slice, without the default
flip, DEL-LLM, DECL-FOLD, h2 or K7-door-probe pieces:
- root::door_steps: kernel_sections (providers' dialect fields, models, pools, limits) beside the
  door sections; the plane serving the pools map walks the uniform model-serving section; DoorConfig
  per generation (the root's ConfigProjection); the destination guard at verify with 1.5.5's words;
  a blocked admission's message and Retry-After; 1.5.5's flat request fee on that plane; the
  dialect's auth parameters sealed under the provider's own (sealed_settings).
- root::model_egress (new): the model-serving walk over the kernel's own lane cells, every bound the
  configuration states (weights, attempt timeouts, max_concurrent, context windows, failover budget,
  on_exhausted, per-pool breaker ladders), outcomes through the lane store's record calls.
- root::serve: the HookStage (HostHooks over the current generation's engine host, EngineCaller),
  a config apply refreshing the door-served llm, the open front door admitting anonymously on the
  pools plane, the forward span, the request families and translation counter.
- busbar Cargo.toml: `llm-on-driver` carries the sigv4 and oauth auth rows (auth-sigv4, auth-oauth on
  the `auths` axis, ARCHITECT Q-L1-AUTH (A)), so the default build is unchanged.
- tests: tests/hook_parity_driver (the 1.5.5 hook tests of llm origin, 69, verbatim names and values,
  plus the 16 held legacy-crate hook tests; 85/85 green on the driver), root::serve hook-seat tests,
  the AUTHPARAMS seal test, computed_refusal_sites pins the hook-stage and destination-guard sites.
…text (RefusalIn::text is the kernel's own message: the reason's spelling or the walk terminal's own words, BUSBAR-1.6.0.md Part 3 section 12 line 2573 the route pump's exhaustion terminals); the kernel sections' providers key is read off Kind::Transport.root() (root_key_spelling)
… now held twice (the legacy crate's and the driver's verbatim home) name their legacy file, the switch's auth rows and instance-noun leaks are written down, the config projection sits above the boot build's blocking-ffi exemption

- design-bindings: PB-1/6/28/46/84 and their siblings cite the busbar-llm test by path.rs::name (the
  pattern PB-5 already uses), since the hook parity suite on the driver repeats each 1.5.5 name
  verbatim (BUSBAR-1.6.0.md Part 3 section 12 "The switch": the hook tests run verbatim); the ledger
  regenerated, 104 mapped, none unproven.
- kind-isolation: busbar -> busbar-auth-sigv4 / busbar-auth-oauth, each 1 declaration, carried by the
  `llm-on-driver` switch (ARCHITECT Q-L1-AUTH (A)).
- instance-noun-neutrality: the switch's three files that name the plane under proof (the parity
  suite's main.rs, the serve hook-seat tests and their cfg in serve.rs), each struck with the switch
  at the llm fold's D3 (1.6.0-TODO.md "the `llm-on-driver` dev cargo feature").
- blocking-ffi: set_config_projection moves above the boot build's allow marker, which exempts the
  call directly below it only.
# Conflicts:
#	crates/busbar-kernel/tests/plane_driver.rs
…l|high|{anthropic,bedrock,gemini}, body only) and its CHANGELOG line, ported from 118b2f5 (TLSDEST not taken): OWNER SIGNED 2026-10-04, #85 (OWNER 2026-09-28 PLUGIN LOGGING: one log file per plugin instance); the plugins.logs paragraph that said plugin log lines had not moved is corrected
…eports it exactly where 1.5.5 billed the flat request fee; the plane's report is the one fee decider on the door (owner #77, money-B1 ruling on the p3-flip-llm park, option (b); BUSBAR-1.6.0.md Part 0 "money = f(ledger, ratecard)": the ledger must carry what 1.5.5 billed)

- busbar-plane-llm: `per_request` (busbar_contract::plane::PER_REQUEST, family `request`) is the
  tail's last billable class and its one fee unit. The answer that opens the caller's reply under
  a success status incurs it (1.5.5's finish kept the fee for a 2xx caller status and refunded it
  otherwise); from then every answer that carries counts carries the far end's last cumulative
  counts and the fee unit's 1. A non-2xx reply, a far-end request and a probe incur none.
- root door_steps: every door plane's fee refund is its reported fee units (FeeRefund::PlaneFeeUnits);
  the pools plane's caller-status special case is gone, so one decider remains.
- the ledger identity holds on the switch build: the node's books carry the 4 x 30000 micro-units
  of flat fee the legacy rows carry (tests/ledger_identity.rs green under `llm-on-driver`).
…tored the behaviour on predev): the ruling's pins ported from lane-llm-ua (6adf6fb, 0830cf1, bffce13) — tests/exchange_user_agent.rs (a same-dialect far end sees exactly the caller's user-agent, a caller that sent none carries the dialect's 1.5.5 fingerprint, a translated hop writes the far dialect's), and each dialect's egress_user_agent and head_fields state where the fingerprint is written
…e kernel plane registry before the config prepass (ARCHITECT RULING 2026-10-03 Q-DEL-A2A-DECL; BUSBAR-1.6.0.md #49 OWNER-LOCKED: a plane's config section comes from its Statement `sections.owns`; R2-C), ported from 9b277c5 with the fallback/probe facts of 2deb3c9

- contract: plane_calls::PlaneRegistration (the registry facts a door states, its own validate,
  and `fallback`: the tail's TAIL_FALLBACK).
- loader: the plane kind keeps the tail's nouns, billable families, TAIL_PROBES and TAIL_FALLBACK at
  bind; kinds::plane::registration builds one registration for a linked and a dropped door.
- kernel: plane::door::fold turns a registration into a PlaneDecl whose every word is the door's.
- root: plane_rows folds every door candidate beside the linked rows; a key a linked row registers
  keeps that row, so under `llm-on-driver` the proto-llm row keeps the llm key until the default flip.
Not taken: the a2a pieces (DECL-FOLD 2's facing/audience, CLAIM_PATTERN, caller_credential_refusal),
which are not on the plane ABI of this tree.
…rough the kernel's probe unit (BUSBAR-1.6.0.md Part 3 section 12 "Nested units, work continuations and probes are units of their own ... a health probe is a kernel-originated unit pinned to one member"; "Probes (K7). A pure probe schedule, bound to the far end; a member's health follows the 1.5.5 lane health configuration"), ported from 2deb3c9

- root::model_egress: each model's provider `health:` over the process defaults resolved per lane
  (ModelPools.probes), and ModelServing::probe_members for the schedule.
- root::serve: the plane serving the `pools` map whose tail states TAIL_PROBES arms a PlaneProbes
  target per generation over its sealed egress and spawns the kernel probe service's probers on a
  schedule phase-stable across a config apply; probe unit keys come from the node's one mint
  (Node::kernel_and_keys).
- main: under `llm-on-driver` the legacy row's on-host probers are not spawned beside them, so a
  lane is probed once, as 1.5.5 probed it.
…eutrality ruling: the http door writes no default accept, so the plane writes it where 1.5.5 did — every llm request carried its own explicit accept, the single answer's or the dialect's stream framing, never a client default); a same-dialect caller's accept no longer replaces it (1.5.5's bytes: the oracle's same-dialect cells carry application/json, not the caller's */*). Conformance pins the per-request fee unit beside the far end's counts.
…he predev merge brought 833cef6's pin of the same plane_driver route_async site this branch had reviewed and pinned from 5613e7b)
…akes (a folded door's &'static registry row, the door rows' probe dispatcher) are reviewed hold-escape known_sites; main.rs's switch-scoped skip of the legacy probers is a recorded llm instance-noun row, struck with the switch at D3
@MattJackson
MattJackson enabled auto-merge October 5, 2026 01:33
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

promote into predev: BOARD @6d282147f: 0 failing test row(s), 9 DENY row(s)

DENY rows (9)

gate row detail
construction one-pick-site 3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:358; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8
kind-isolation kind-isolation:deps 3 finding(s), 96 shipped edge instance(s) over 32 class(es), 96 declaration(s); 59 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w
kind-isolation kind-isolation:test-deps 4 finding(s), 43 test edge instance(s) over 26 class(es), 43 declaration(s); 27 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge
kind-isolation-ship kind-isolation:deps 13 finding(s) over 96 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a
kind-isolation-ship kind-isolation:test-deps 18 finding(s) over 43 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship
kind-isolation-ship kind-isolation:faces 3 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is
kind-isolation-ship kind-isolation:legacy-drain 3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier)
ship-ready ship-ready:ship-twin 'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is
structure-lint structure-lint:plane-dup:unledgered 22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger

Judged against base 7d04bf0c9: 0 new red, 0 worse, 5 standing (excused).

tests passed: 24501, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/37715353502 . Artifact verdict-6d282147f5d2fc586e8408749e14042e8cd5a842 (failures.json, junit.xml, raw.log; 90 days).

…e switch's code names no plane, the stand-in hook axis keeps its own dispatcher

- main.rs: the config-apply refresh of the door planes is gated on `linked_axis_node` (Served::post
  exists only there), so --no-default-features and every single-plane-* leg compile again.
- instance-noun-neutrality:llm green again, no debt row: build.rs emits `linked_fold_on_driver`
  (a `<plane>-on-driver` fold switch is on, BUSBAR-1.6.0.md Part 3 section 12 "The switch") and
  `LINKED_PLANE_DOORS` (each linked plane-door row's door, resolved as the root resolves its
  entry). The hook parity suite and the serve hook-seat tests gate on the cfg and find the plane
  under proof as the linked door whose Statement declares the `pools` map; its dialects and op
  classes are read off the door's tail; the seat tests install the legacy row's seams through the
  manifest's `node_plane` alias; main.rs's legacy-prober skip reads the cfg. The 1.5.5 test
  reject_kind_mapping_matches_status_semantics keeps its name and values, now proven end to end
  through the door (each gate status's Anthropic error type). The four switch rows added to
  qa/instance-noun-neutrality.toml are gone.
- busbar-kernel test_support: hook_axis_stand_in opens each registry's rows on a dispatcher of its
  own again (adeb523, which a port had reverted to one shared dispatcher): a slow-gate test's
  wedged worker no longer FAULTs dlopen_decide_order_and_abstain in the timing and core-duplex-ws legs.
MattJackson added a commit that referenced this pull request Oct 5, 2026
…to its dev): the http door writes no default accept (transport neutrality)

The door writes only the fields its caller wrote. Every caller that sent 1.5.5's client default
accept: */* now carries it in its own fields, in the place 1.5.5 put it:
- the auth mint request: already done in 11dd91b (after content-type);
- the llm plane: writes its own accept in its dialect fields (PR #464, the llm flip);
- every other plane and plugin that sends over an http need must write it where 1.5.5 sent it.

Lock: only the transport-http source line moved. Run on Latchkey: root connector/door_steps/serve/
oauth 108/108, root plane_driver 47/47, auth-oauth conformance 4/4, default build ok.
… as main's first act, before any plane registers), not a leaked probe dispatcher of their own, so the switch build's thread count is the configured dispatcher's (root_dispatcher_boot) and no hold escapes; the hold-escapes exemption for door_rows is withdrawn
…der the llm flip

The plane ABI the seam lane owns is taken whole (PlaneRegistration's owns/secret_refs/admin
routes/facing, DoorApply's per-generation refresh, the gate-first hook order, the held far end and
its session routes, the registration probe binds), and the flip's own facts ride on it
(BUSBAR-1.6.0.md Part 3 section 12, lines 2542-2680):

- PlaneRegistration keeps `fallback` (TAIL_FALLBACK) beside the seam's fields; the door fold states it.
- The registration probe binds go on the process's one dispatcher (booted first in main), so the
  fold adds no worker to the process's thread count (root_dispatcher_boot).
- ServedFacts keeps `consumed`, the dialect_auth parameters (Q-L6-AUTHPARAMS), `probes` and
  `fallback` beside the seam's `owns`, `caller_credential_refusal` and `tail_flags`.
- The plane serving the `pools` map binds the kernel's hook stage in 1.5.5's order (K5); a plane
  whose tail states TAIL_HOOKS_GATED binds the gate-first stage.
- DoorLive carries the generation's facts (translation dialects) and its K7 probe target; the
  model-serving plane is refreshed from the configuration projection
  (DoorAppliers::refresh_models, on the handle's appliers), every other plane by DoorApply::apply.
- The driver's refusal rendering keeps the walk terminal's words and the steps' Retry-After beside
  the seam's steps' words and the vetoing hook's name.
…ot is PlaneCancelIn/PlaneCancelOut; the llm door states it (BUSBAR-1.6.0.md Part 3 section 12)
…RCHITECT RULING 2026-10-04)

A Responses answer restates the request's tools, tool_choice and parallel_tool_calls, at their
defaults when the caller set none. A TRANSLATE answer drops them, and the drop walk named each as
an egress.control_unrepresentable row, so the 11 llm|*|responses|request|ok(_stream) cells gained
three audit rows 1.5.5 never wrote. The answer walk (drops::Carried) now takes the dialect's
declared echoed defaults (ANSWER_DEFAULTS for Responses): a member equal to its default names no
drop and writes no row; any value the caller set is still named and audited.

Test: an_echoed_request_default_names_no_drop_and_a_caller_set_value_still_does (the echo names
nothing; RED arm: a real tool, a directed choice and parallel calls off are each still named).
…Q128 U14; BUSBAR-1.6.0.md Part 3 section 12)

Eleven cells driven end to end through the data router built with the door's claims, the kernel's
hook stage, the model-serving walk over the kernel's lane cells and the node's book, each reading
the capability where the kernel keeps it: breaker-trip (the member's (pool, lane) cell stops
admitting), breaker-fastfail (a tripped member is never dialled again), failover-reroute (the twin's
answer before the first byte), disposition (a far end's refusal of the request is relayed, not failed
over, not charged to the cell), egress-auth (the member's bound credential, never the caller's
token), metrics (the attempt on the scrape under its pool and lane), governance-budget (the fee on
the key; a spent budget refuses with Retry-After before any dial), audit-chain (one record per unit),
hooks-gate (refused before dispatch), hooks-tap (the request tap sees the rewritten request) and
catalogue (a restricted key lists only the pool it reaches and its member).

The cells live in root/tests/serve_door.rs (coordinator ruling: a #[path] test file of a declared
root module is a leg file): its decisions items are gated on plane-decisions and the door cells on
the fold switch. The shared rig is serve_hook_seats' run(), generalized (members and weights,
pooled members, allowed pools, a day budget).
… the five-plane capability columns (Q128 U14), the gated screen inside the teller's chain; the door rows probe on the process's one dispatcher
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 7, 2026
MattJackson added a commit that referenced this pull request Oct 7, 2026
…lling fix) into p3-flip-llm-del

# Conflicts:
#	Cargo.lock
#	crates/busbar-llm/src/engine/usage.rs
#	crates/busbar-llm/src/lib.rs
#	xtask/tests/declared_classes.rs
… into p3-flip-llm: hooks.rs -> hooks/mod.rs carries this line's driver hooks; the door test file follows its rename to serve_tests.rs (this line's cells, predev's caller-credential assert); TestApp builds the kernel's own tables under the one fallback decl and runs its build_runtime only when it has one; main keeps the node's post beside data_mounts' refusals
…a decoded arrival carries both its trust facts (#499) and its sticky key (this line)
@MattJackson
MattJackson enabled auto-merge October 7, 2026 11:33
@MattJackson
MattJackson added this pull request to the merge queue Oct 7, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 7, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 7, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 7, 2026
…p3-flip-llm: busbar-auth-sigv4 and -oauth leave the tree; the llm fold's linked auths rows pin them from their own repos (sigv4 dev c22578a, oauth dev 98fb861, each carrying the compiled_in::door entry this line's rows name)
…n 22abf69), keeping predev's loopback-allowed mint need (spec l.611); oauth dev 98fb861 merged it back to operator-infrastructure
@MattJackson
MattJackson enabled auto-merge October 7, 2026 14:24
…a refusal's Retry-After is the walk's floor, else its own stated wait, else the kernel refusal's (#511 Q5); llm-on-driver keeps its linked auth rows beside the mcp door row; main keeps the node's post beside the line carrier; the door tests file serves both planes' cells; the fold allocation entry is predev's
…k's shed in 1.5.5's words, as this line's sibling cells do (RefusalIn.text is the kernel's own message, every plane); the boundary walk's core-route floor counts the kernel's own guarded routes (3), the body-ingress convenience routes being a plane's (spec l.4093)
@MattJackson
MattJackson disabled auto-merge October 7, 2026 15:48
…predev served it

The kernel plane driver now hands every plane the walk's own sentence in RefusalIn.text for an
exhausted walk (the model door renders it in 1.5.5's words). The mcp door's baseline is predev
(spec l.4593, l.4834: for the new planes the baseline is current predev behaviour), and predev
handed this door the reason word `breaker_open` there. With a resolved server the door renders its
own -32030 sentence and never repeats the text, so that arm is unchanged; but two paths repeat it:

- the generic arm (BreakerOpen with no resolved server: a call whose tool left the catalogue on a
  reload while it waited out its server's timeout): predev 503
  {"error":{"code":-32000,"message":"breaker_open"},"id":41,"jsonrpc":"2.0"}, #464 said
  "The service is temporarily overloaded. Please retry shortly." instead;
- a task's continuation refused by the walk (a stalled or a tripped server): tasks/get stated
  {"code":-32603,"message":"the MCP upstream call failed: breaker_open"} on predev, the walk's
  sentence on #464.

The door's refusal slot now takes the reason's own word for a kernel refusal whose reason is
BreakerOpen (every walk terminal the kernel renders as an exhaustion), so both paths serve predev's
bytes again. Four root cells in tools_door pin the bytes, each run green on predev fb5f12a first:
the tripped server's -32030 control, the generic arm, and the two task paths.
…uarded and walked

/{name}/v1/messages and /{provider}/{model}/v1/messages are 1.5.5 surface that the kernel router
mounts only where a plane installed body ingress (any_body_ingress). The audience-bound boundary
walk's app installs it through its linked planes, so the cell now states it: body ingress is
installed, both patterns are in the router's core-route table on POST with a key's bar (never
RouteAuth::None), and the walk reaches both, an anonymous caller refused 401 and a keyed caller
admitted. This is the positive proof beside the root door_boundary floor that counts the kernel's
own guarded routes.
…plane names no kernel-side vocabulary (purity: busbar_contract::caps is the kernel's)
@MattJackson
MattJackson enabled auto-merge October 7, 2026 16:31
…ixture data (tool_door_wire.txt), as its other wire words are, so the root's test source names no plane; the busbar -> busbar-auth-sigv4 dep row is struck (the extracted crate is no shipped edge, measured)
…he parent's crossing, and 73 others) into p3-flip-llm
…to p3-flip-llm

Every plane runs predev's routed hook order, the llm/pools door included: the stage is keyed by a
RoutedScope, a gate-first binder binds via bind_gated(container, principal), and serve.rs binds
every non-gated plane through HookStage::routed (LiveHooks over the live generation, GovCaller
for principal-to-key lookup). This line's per-unit arrived_in dialect binding rides inside it:
SessionStage carries arrived_in, the routed bind is Bind { dialect: arrived_in }, and a gate-first
unit's UnitHooks carry the arrived dialect's name. The lane's own pools-plane binder (HookStage::
binder, kernel EngineCaller/HostSource/KeyLookup, HostHooks over a host source) is dropped:
LiveHooks + GovCaller cover the same facts (key, groups, rate headroom, budget, hook_read).
host_stage_tests and serve_tests take both sides' cells; the pools-door cells import the hook-seat
far end and script under aliases beside predev's decisions helpers.
) into p3-flip-llm

The auth split (P2 D1) links sigv4 and oauth by default and gives the process one set of outbound
auth instances (door_steps::process_auths). The door reach takes that set; the model-serving pools,
their live App handle and the config-apply refresh stay this line's. Manifests, lock and the
kind-isolation rows are predev's: its busbar-auth-oauth pin 98fb861d14 carries 360a0d2c46, the
compiled-in entry this line cherry-picked as 22abf69390, and its busbar-auth-header pin is newer.
door_steps keeps both: predev's upgrade-claim wording and this line's sealed_settings (the
dialect's host-label auth parameters) and DoorReach::models. qa/DESIGN-BINDINGS.md is regenerated.
@MattJackson
MattJackson added this pull request to the merge queue Oct 8, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Oct 8, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant