Repository navigation
P-item refusal-reason collapse: one refusal classification; every surface a class-to-wire table - #535
Queued
MattJackson wants to merge 2 commits into
Queued
MattJackson wants to merge 2 commits into
MattJackson wants to merge 2 commits into
Conversation
…face a class-to-wire table RefusalCode::class (busbar-contract abi/plane) is the one reason-to-family match, total, no catch-all. The kernel's default status, the llm plane's kind_of / is_authentication / refusal_shape, the a2a, mcp, decisions and streaming refusal_render, and the admin surface's answer_for become class-to-wire tables. The streaming plane's catch-all that answered every unnamed reason as internal is gone. The llm plane's served statuses and kinds stay byte-identical: two rows become the class default, four rows keep its answers. Pins: p_item_refusal_reason_collapse_* in busbar-contract (the classification), in each new plane (only a node fault renders internal; one class, one answer), in busbar-llm (no llm refusal reads as an internal error) and in xtask (the source scan: no renderer names a reason).
MattJackson
enabled auto-merge
October 7, 2026 09:12
promote into
|
| crate | test | step | first panic |
|---|---|---|---|
| `` | nextest xtask::cli::selftest_runs_every_registered_gates_red_proof |
test:workspace | |
transport_dropped_in_serves |
a_dropped_in_transport_registers_through_the_one_fold_and_serves |
test:dropped-in-tcp-transport | crates/busbar/tests/transport_dropped_in_serves.rs:168:13: busbar exited (ExitStatus(unix_wait_status(512))) before serving; log: |
-p busbar --test transport_dropped_in_serves |
test target failed |
test:dropped-in-tcp-transport |
DENY rows (12)
| gate | row | detail |
|---|---|---|
| construction | one-pick-site |
3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8 |
| kind-isolation | kind-isolation:deps |
3 finding(s), 76 shipped edge instance(s) over 27 class(es), 76 declaration(s); 61 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w |
| kind-isolation | kind-isolation:test-deps |
5 finding(s), 36 test edge instance(s) over 19 class(es), 36 declaration(s); 22 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge |
| kind-isolation-ship | kind-isolation:deps |
15 finding(s) over 76 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hooks-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the |
| kind-isolation-ship | kind-isolation:test-deps |
13 finding(s) over 36 test edge(s): ship-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is 'not-allowed': the architecture grants no cleanliness -> legacy edge, and the ship criterion is t |
| kind-isolation-ship | kind-isolation:faces |
4 finding(s) over 31 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Store' 2 time(s) in shipped source — the entry face of kind 'store'. A trait implementation is a claim |
| kind-isolation-ship | kind-isolation:testkit |
2 finding(s) over 12 crate(s): battery-ignored crates/busbar-plane-decisions busbar-plane-decisions carries a tests/conformance.rs whose every entry is '#[ignore]'d (or which has none). 'cargo test' |
| kind-isolation-ship | kind-isolation:legacy-drain |
5 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier) |
| kind-isolation-ship | kind-isolation:control-path |
73 finding(s) over 3 control surface(s): upstream crates/busbar-core-admin/src/admin_codec/meta.rs:84 busbar-core-admin names 'egress' — a control surface has no upstream to reach, so the vocabulary o |
| ship-ready | ship-ready:ship-twin |
'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is |
| instance-noun-neutrality | instance-noun-neutrality:voice |
tracked known-debt census — 8: crates/busbar-plane-llm/src/codec/gemini/handler.rs×7 [cross-plugin] | crates/busbar-plane-llm/src/codec/gemini/tests/handler_tests.rs×2 [cross-plugin] | crates/busbar |
| structure-lint | structure-lint:plane-dup:unledgered |
23 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs mcp:crates/busbar-mcp/src/mcp/config.rs voice:crates/busbar-voice/src/config.rs (the ledger row signs for |
Judged against base 2bbe362db: 0 new red, 0 worse, 8 standing (excused).
tests passed: 24749, failed: 1. Run: https://github.com/GetBusbar/busbar/actions/runs/37618679456 . Artifact verdict-a6c96abcc5cecc8dd651d848c7d5259ca1ffc90f (failures.json, junit.xml, raw.log; 90 days).
MattJackson
added this pull request to the merge queue
Oct 7, 2026
Any commits made after this event will not be merged.
…: Untrusted joins the Forbidden class; the planes keep predev's imports
MattJackson
enabled auto-merge
October 7, 2026 12:06
MattJackson
added this pull request to the merge queue
Oct 7, 2026
Any commits made after this event will not be merged.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Spec DONE item 2: "All P-item behaviours match 1.5.5 — refusal-reason collapse … fixed as BUGS, not signed (#43/#71)". TODO L-ENG9 asked for one classifier. ARCHITECT ruling (2026-10-07): one shared, total classifier lives in
busbar-contract/src/abi/next to the RefusalCode table. The llm grouping is the authority, because the llm plane is the only one 1.5.5 shipped. The llm stays byte-identical. Each other surface keeps its own class→wire table.The 1.5.5 behaviour
On the llm surface, 1.5.5 answered each limit reason with its own status and kind, never a 500:
rate_limit_errorinsufficient_quota, or 400 on bedrockpermission_errorSource: v1.5.5
crates/busbar/src/ingress/mod.rs:237-305. The P-item (drive log P1/P2, 470351a) is a plane answering a policy refusal as "this node broke".The root
Eight hand-copied reason→family matches had drifted apart:
refusal_statuskind_of,is_authentication,refusal_shaperefusal_renderanswer_forThe streaming one still ended in
_ => "internal".The fix
RefusalClass(14 classes) andRefusalCode::class()are now the ONE reason→class match. It has no_arm. Helpers:class_of,class_of_refusal,class_of_word. A reverseFrom<RefusalReason> for ReasonCodeis generated from the samereasons!table.class_status(class).kind_ofandis_authenticationgive the same kind as today for every reason.Unreachabledefault, and GroupFrozen 403 is now theForbiddendefault.llm_refusal_statuses.rs, which checks against the 1.5.5 golden cells, stays green unchanged.Byte moves, all on surfaces that are new in 1.6.0 (fixed P-item bugs; baseline is predev; nothing signed)
Every reason now answers as its class does. "Before → after" lists every reason whose answer changes; no other reason's answer changes.
streaming (the headline: the
_ => "internal"arm is gone;error.code,error.message)internal→rate_limited: OverBudget ("could not be opened"), InFlight ("too many sessions")forbidden: GroupFrozeninvalid_request: NoRate, Unpriced, Replayed, Superseded ("could not be opened"); CursorBudget ("could not be read")unauthorized: ChallengeExhaustedunavailable: DestinationBudgetExhausted ("no provider is reachable"); every other reason in this list ("could not be opened")rate_limited→unavailable(their class is Unavailable; the llm surface answers them 503 overloaded)invalid_request→unauthorizedforbidden→unauthorizedunauthorized→invalid_requestinvalid_request→internal(a node fault)unavailable)a2a / mcp / decisions (same shape on each wire)
admin
answer_forkernel default status (
class_status; the llm plane's rows keep every llm status as it was)upstream_downanswer)llm
refusal_shape(thePlane-trait encoder, which is not on the served door path)Each now matches what the served path already answered.
Pins (
p_item_refusal_reason_collapse_*)busbar-contract/tests/p_item_refusal_reason_collapse.rs:encode_refusalbytes.busbar-llm/tests/llm_refusal_statuses.rs: for every dialect and every reason, no llm refusal is a bare 500, andapi_erroris used only for node faults and the 504 timeout.xtask/tests/p_item_refusal_reason_collapse.rs, the source scan:ReasonCode::/RefusalReason::/RefusalCode::/R::), andkind_ofnames no reason spelling;Proof (Latchkey)
refusal_renderback fails the streaming pin and the xtask scan.llm_refusal_statuses.rs(cli-18a97d6a); xtask pin (cli-8e00771c).root::serve/root::registrytests need example cdylibs the job did not build, andledger_identityneeds the oracle engine checkout. The same tests fail the same way on base d07eaf7 (cli-067ea515). Everything else is green, includingmoney_never_ends_an_admitted_unit.request|{over_budget,over_budget_total,unauthenticated,malformed,out_of_scope,upstream_down},http.crosscut|{413,unknown-path},route.failover|*,route.529|*,concurrency|*,queue|*,teller|*,cooldown|*,crosscut.traps|*,admin.ops|*, plus premise cells: 358 cells.upstream_downcells on the egress accept header and lane_state, owned by P6 ORACLE-STRICT: strict-replay reds cleared or routed (auth_modules, register under signed rulings, engine pin 2119a67a6f, bin/oracle Q128, scrape-reload cell, 1.6 plugin source pins) #493.clippy --all-targets -D warnings(contract, kernel, five planes, busbar-llm, busbar, xtask): green.cargo xtask abi-header: green.cargo xtask gate --all: RED in kind-isolation, kind-isolation-ship and ship-ready only, exactly as on base.No signed diff and no accepted-differences entry.
Re-proof after merging origin/predev (#499, #505), head a6c96ab
plane_driver/mod.rsand the a2a, decisions, llm and mcpplane.rsfiles.BoundedVec/Spanare no longer imported.Untrusted(code 42) joinsRefusalClass::Forbidden._ => 403already sent it.forbidden, where predev's catch-all saidinternal.ledger_identity, which needs the oracle engine checkout.p_item_refusal_reason_collapsepins pass. The xtask scan passes (3 tests).clippy --all-targets -D warningsandxtask abi-headerare green.bin/oracle replay --baseline-version 1.5.5 --strict --id-filter, branch cli-fa9760a8 vs base cli-4dfce92d.Streaming byte move:
Untrusted(42),internal→forbiddenUntrustedchanges fromerror.codeinternal/ "the session could not be opened at this time" toforbidden/ "the caller may not open a session for this operation".Untrusted(the kernel's Approve did not trust the unit's stated counterparty). Streaming had no arm for it, so predev's_ => "internal"catch-all called it a node fault. The one classification puts it inForbidden.Untrustedin its permission family, so they don't move:refusal_shape:RefusalReason::PoolNotPermitted | RefusalReason::Untrusted => (403, KIND_PERMISSION)CODE_UNSUPPORTED_OPERATION, "the caller may not perform this operation"CODE_REFUSED, "the caller may not perform this operation"unsupported_operation, "the caller may not perform this operation"ReasonCode::Untrusted => 403, and admin answers 403 forbidden. Neither moves.golden/1.6.0-pre(--id-filter '^streams\|', branch cli-a7467163 vs base cli-e745b10f):identical, with the same detail sha on both sides.Untrustedrefusal, so this move is proven by the plane's own test (p_item_refusal_reason_collapse_only_a_node_fault_is_internal_and_one_class_one_answer, which walks every RefusalCode throughencode_refusal), not by an oracle cell.