Skip to content

plane-delete: the decisions probe reaches a real route (keyed boot, one decisions model) - #542

Queued
MattJackson wants to merge 2 commits into
predevfrom
p5-plane-delete-decisions-model
Queued

MattJackson wants to merge 2 commits into
predevfrom
p5-plane-delete-decisions-model

Conversation

@MattJackson

Copy link
Copy Markdown
Collaborator

Stacked on #538 (its fixture store: fix is this branch's parent). Land after it.

The plane-delete boot leg read the decisions plane as UNSERVED. Its fixture configured no decisions model, and POST /v1/systemone is claimed only for exactly one model (plane_door::snapshot_spec, FLIP-DECISIONS #497), so the route was never mounted.

The probe can't go on the existing open boot. The plane's door claim is admitted by the key chain alone, and with no chain the kernel's R2 ratchet (plane::registry::build_dispatch) refuses to boot, by design (BUSBAR-9007 "mounts 1 path(s) but bound no admission").

  • A third boot, keyed: a closed [keys] chain plus the decisions: section with one model.
    • The model's provider is a jev row at a closed port: the route only has to be mounted, no far-end answer is needed.
    • The provider row is written only alongside the section.
    • Every request on this boot, the absence calibration included, carries a data-plane key minted through the admin API.
  • UNSERVED mark removed: no plane carries it now. The mark is now a list (UNSERVED_PLANES); the self-test marks a plane itself, so the mechanism stays proven.

Proof, Latchkey job cli-d311b27f (large), on this head:

  • --probe-control: all 5 planes reach a real route.
    • llm 405, mcp 200, a2a 503 and streaming 501, each against its boot's measured absence.
    • plane-decisions 503 against keyed absence 404.
  • --selftest: ALL GREEN.
  • plane-decisions strong form with boot: PASS.
    • The positive control answers 503 with the plane present, and 404 with it gone.
    • Every neighbour still serves.
    • The refusal witness names decisions: as an unknown field.

…he control boots again

Q-STORE (B) (01af484, 2026-10-02) made a config with no store: block a boot refusal (BUSBAR-9007).
The harness' fixture config never got the block, so from then on neither the mcp nor the open boot came
up on any tree. The boot leg had no control, and every plane's deletion verdict read RED for that
reason alone. The reason was also invisible: the boot and build diagnostics printed inside
$(control_codes) and $(build_bin) and were captured, so only 'control build/boot failed' showed.
They go to stderr now. The self-test's fixture check requires the store: line in the plane-free base.
…ot with one decisions model

POST /v1/systemone is claimed only for exactly one configured decisions model (plane_door::snapshot_spec,
FLIP-DECISIONS #497). The fixture configured none, so the route was not mounted, and the plane carried
an UNSERVED mark that let its boot leg read absent on the control. The plane's door claim is admitted
by the key chain alone: with no chain, the kernel's R2 ratchet (plane::registry::build_dispatch) refuses
the boot, so it cannot be probed on the open boot. A third boot, keyed, holds the closed chain plus the
decisions section with one model on a jev provider at a closed port. The route only has to be mounted;
no far-end answer is needed. Every request on that boot, absence calibration included, carries a
data-plane key minted through the admin API. No plane is UNSERVED any more. The mark is a list
(UNSERVED_PLANES), and the self-test marks a plane itself to keep the mechanism proven.
@MattJackson
MattJackson enabled auto-merge October 7, 2026 10:08
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

promote into predev: BOARD @cd64caba9: 3 failing test row(s), 12 DENY row(s)

Failing tests (3)

crate test step first panic
`` nextest xtask::cli::selftest_runs_every_registered_gates_red_proof test:workspace
transport_dropped_in_serves a_dropped_in_transport_registers_through_the_one_fold_and_serves test:dropped-in-tcp-transport crates/busbar/tests/transport_dropped_in_serves.rs:168:13: busbar exited (ExitStatus(unix_wait_status(512))) before serving; log:
-p busbar --test transport_dropped_in_serves test target failed test:dropped-in-tcp-transport

DENY rows (12)

gate row detail
construction one-pick-site 3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8
kind-isolation kind-isolation:deps 3 finding(s), 76 shipped edge instance(s) over 27 class(es), 76 declaration(s); 61 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w
kind-isolation kind-isolation:test-deps 5 finding(s), 36 test edge instance(s) over 19 class(es), 36 declaration(s); 22 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge
kind-isolation-ship kind-isolation:deps 15 finding(s) over 76 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hooks-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the
kind-isolation-ship kind-isolation:test-deps 13 finding(s) over 36 test edge(s): ship-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is 'not-allowed': the architecture grants no cleanliness -> legacy edge, and the ship criterion is t
kind-isolation-ship kind-isolation:faces 4 finding(s) over 31 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Store' 2 time(s) in shipped source — the entry face of kind 'store'. A trait implementation is a claim
kind-isolation-ship kind-isolation:testkit 2 finding(s) over 12 crate(s): battery-ignored crates/busbar-plane-decisions busbar-plane-decisions carries a tests/conformance.rs whose every entry is '#[ignore]'d (or which has none). 'cargo test'
kind-isolation-ship kind-isolation:legacy-drain 5 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier)
kind-isolation-ship kind-isolation:control-path 73 finding(s) over 3 control surface(s): upstream crates/busbar-core-admin/src/admin_codec/meta.rs:84 busbar-core-admin names 'egress' — a control surface has no upstream to reach, so the vocabulary o
ship-ready ship-ready:ship-twin 'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is
instance-noun-neutrality instance-noun-neutrality:voice tracked known-debt census — 8: crates/busbar-plane-llm/src/codec/gemini/handler.rs×7 [cross-plugin] | crates/busbar-plane-llm/src/codec/gemini/tests/handler_tests.rs×2 [cross-plugin] | crates/busbar
structure-lint structure-lint:plane-dup:unledgered 23 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs mcp:crates/busbar-mcp/src/mcp/config.rs voice:crates/busbar-voice/src/config.rs (the ledger row signs for

Judged against base 6afec149a: 0 new red, 0 worse, 8 standing (excused).

Reused PASS by input key (1, 0 min not re-run)
step key produced by
build:deletion-matrix e8abda037a36c02e 6afec149a

tests passed: 24689, failed: 1. Run: https://github.com/GetBusbar/busbar/actions/runs/37605454665 . Artifact verdict-cd64caba9387c5a0eb8bad12d307039162395e0b (failures.json, junit.xml, raw.log; 90 days).

@MattJackson
MattJackson added this pull request to the merge queue Oct 7, 2026
Any commits made after this event will not be merged.
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to invalid changes in the merge commit Oct 7, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 7, 2026
Any commits made after this event will not be merged.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant