Repository navigation
plugin-loader plane suite: public_url and a sessions leg, so every plane runs the published suite both ways - #543
Merged
Merged
Conversation
… an optional sessions leg any plane drives from its own conformance.json The plane kind's script takes plane.public_url (handed to `open`; the refresh frame carries none, so the instance keeps the one its open was handed), an arrival's claim, head fields and named route, the ATTEMPT's pool and the caller's reference on every piece, a short answer met over a fields buffer as well as a units one, and plane.sessions: units on one claim driven step by step (an arrival, pieces from the caller, the far end or the kernel keyed by a stream, a piece met short and re-called once, drive, project), every step a Recorder line at its exact pin and judged by the contract against the step's want. Every new input is optional; absent, the fold is byte-identical (the decisions plane's 467-line fold dump compared equal on base and head). The loader's plane fixture claims its session door when opened under a public URL; the new conformance_plane_sessions_tests drive the leg over it linked and dropped in, with RED arms for a moved count on any session step, a step answering otherwise than wanted, an unknown want, a piece called short that is not, and inputs naming a step twice.
MattJackson
enabled auto-merge
October 7, 2026 10:22
…e line and in a want, so the suite spells no plane's section key (kind-isolation matrix back to base, 14862)
promote into
|
| crate | test | step | first panic |
|---|---|---|---|
transport_dropped_in_serves |
a_dropped_in_transport_registers_through_the_one_fold_and_serves |
test:dropped-in-tcp-transport | crates/busbar/tests/transport_dropped_in_serves.rs:168:13: busbar exited (ExitStatus(unix_wait_status(512))) before serving; log: |
-p busbar --test transport_dropped_in_serves |
test target failed |
test:dropped-in-tcp-transport |
DENY rows (12)
| gate | row | detail |
|---|---|---|
| construction | one-pick-site |
3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8 |
| kind-isolation | kind-isolation:deps |
3 finding(s), 76 shipped edge instance(s) over 27 class(es), 76 declaration(s); 61 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w |
| kind-isolation | kind-isolation:test-deps |
5 finding(s), 36 test edge instance(s) over 19 class(es), 36 declaration(s); 22 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge |
| kind-isolation-ship | kind-isolation:deps |
15 finding(s) over 76 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hooks-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the |
| kind-isolation-ship | kind-isolation:test-deps |
13 finding(s) over 36 test edge(s): ship-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is 'not-allowed': the architecture grants no cleanliness -> legacy edge, and the ship criterion is t |
| kind-isolation-ship | kind-isolation:faces |
4 finding(s) over 31 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Store' 2 time(s) in shipped source — the entry face of kind 'store'. A trait implementation is a claim |
| kind-isolation-ship | kind-isolation:testkit |
2 finding(s) over 12 crate(s): battery-ignored crates/busbar-plane-decisions busbar-plane-decisions carries a tests/conformance.rs whose every entry is '#[ignore]'d (or which has none). 'cargo test' |
| kind-isolation-ship | kind-isolation:legacy-drain |
5 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier) |
| kind-isolation-ship | kind-isolation:control-path |
73 finding(s) over 3 control surface(s): upstream crates/busbar-core-admin/src/admin_codec/meta.rs:84 busbar-core-admin names 'egress' — a control surface has no upstream to reach, so the vocabulary o |
| ship-ready | ship-ready:ship-twin |
'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is |
| instance-noun-neutrality | instance-noun-neutrality:voice |
tracked known-debt census — 8: crates/busbar-plane-llm/src/codec/gemini/handler.rs×7 [cross-plugin] | crates/busbar-plane-llm/src/codec/gemini/tests/handler_tests.rs×2 [cross-plugin] | crates/busbar |
| structure-lint | structure-lint:plane-dup:unledgered |
23 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs mcp:crates/busbar-mcp/src/mcp/config.rs voice:crates/busbar-voice/src/config.rs (the ledger row signs for |
Judged against base 6afec149a: 0 new red, 0 worse, 7 standing (excused).
tests passed: 23411, failed: 1. Run: https://github.com/GetBusbar/busbar/actions/runs/37606920055 . Artifact verdict-626f43a313a5b3a57b9326699f0bf93605f5fbfa (failures.json, junit.xml, raw.log; 90 days).
MattJackson
added a commit
that referenced
this pull request
Oct 7, 2026
…p3-flip-llm: busbar-auth-sigv4 and -oauth leave the tree; the llm fold's linked auths rows pin them from their own repos (sigv4 dev c22578a, oauth dev 98fb861, each carrying the compiled_in::door entry this line's rows name)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
PLANE-EXTRACT: a plane is a plugin like any other kind, one suite, both doors. busbar-plugin-loader's published plane script (
crates/plugin-loader/src/conformance/plane.rs) now takes the inputs every plane needs to runconformance_suite!from its own repo. The seven test names are unchanged. The suite source uses neutral nouns only.New
conformance.jsoninputs (all optional; absent = today's behaviour)plane.public_urlopenasPlaneOpenIn::public_url(and toopen again).RefreshInhas no public URL field, so the instance keeps the oneopenwas handed.plane.claimed/unclaimed.claimArriveIn::claim, the snapshot claim index. Every piece andprojectof the script's units carries the claimed one.plane.claimed/unclaimed.fieldsplane.claimed.route{class, entry}ArriveOut::route/pool, and the contract checks themplane.pool/plane.caller_refOnPieceIn::poolon ATTEMPT pieces andcaller_refon every pieceplane.short.buffer: "fields"fields_needed=on the line)plane.sessions[]Each session step is a
Recorderline with its exact pin: 1 crossing, or 2 for a piece metshort. Each step is labelled<name> <label>, sored_a_moved_crossing_count_is_refusedandBUSBAR_CONFORMANCE_RED=countcover the new legs like every other step. The contract judges each step against itswant.outcomeis required, and a want may also nameto_far_end,done,more,status,verb,target,need,emitted,emitted_has,fields,units,route,ready,body_hasandrewritten. A want key the suite does not know is refused, so two equal folds of failures still prove nothing. The per-piece host lists grew to 8, and the session line also printsneed.Decisions' fold is byte-identical. I dumped the 467-line both-ways fold from
busbar-plane-decisions' unchanged suite on base and on head (a scratch dump, not committed), andcmpreported no difference.Loader-side tests
crates/plugin-loader/src/tests/conformance_plane_sessions_tests.rsruns over the in-treeplane_door_pluginfixture, linked and dropped in. When opened under a public URL, the fixture now also claimsGET /upgrade; no existing test opens it under one. The tests cover:drivenaming the stream, a collection, a two-piece far-end answer, one piece met short,project) and a request unit through a 4-byte reply buffer, both ways, at their pins, the folds equal, every want met. Without a URL,openhands none.The streaming plane runs it (scratch, not in this PR)
I applied this commit onto #503's head and changed
crates/busbar-plane-streamingas follows:tests/door_witness.rstests/conformance.rsbecame theconformance_suite!macrofeatures = ["conformance"]conformance.jsonbelowResults on Latchkey, release build with
BUSBAR_EXPECT_RELEASE=1:BUSBAR_CONFORMANCE_RED=countfails on the comparator (Linked: step 'facts': 0 crossing(s), pinned 1)door_witness12/12 greenDecisions: 7/7 green in release, and its RED run fails on the comparator.
The JSON seeds GetBusbar/busbar-plane-streaming. It covers:
need=5)m-cap, the projected session params, caller audio to the far end (need=4), the usage turn's six reported counts, a collection, a units-short re-call, and the caller's end settling the open turnstreaming tests/conformance.json
{ "settings": { "session": { "model": "m-cap" } }, "plane": { "bad_settings": [ { "nonsense_key": 1 }, { "session_max_secs": 0 } ], "refresh_settings": { "session": { "model": "m-cap" } }, "public_url": "https://gw.example.com/ignored?q=1#f", "open_claims": [ [ "POST", "/v1/realtime/client_secrets" ], [ "POST", "/v1/realtime/calls" ], [ "GET", "/v1/realtime/sideband/{call_id}" ], [ "GET", "/v1/realtime/gemini/{call_id}" ], [ "GET", "/twilio/{call_id}" ] ], "refresh_claims": [ [ "POST", "/v1/realtime/client_secrets" ], [ "POST", "/v1/realtime/calls" ], [ "GET", "/v1/realtime/sideband/{call_id}" ], [ "GET", "/v1/realtime/gemini/{call_id}" ], [ "GET", "/twilio/{call_id}" ] ], "member": "m-cap", "caller_ref": "c0ffee", "claimed": { "unit": 7, "claim": 1, "method": "POST", "target": "/v1/realtime/calls", "route": { "class": "direct", "entry": "m-cap" } }, "unclaimed": { "unit": 8, "claim": 9, "method": "GET", "target": "/v1/realtime/nowhere", "status": 404 }, "request": "v=0\r\no=- 1 1 IN IP4 127.0.0.1\r\ns=oracle-offer\r\nt=0 0\r\n", "request_out": "v=0\r\no=- 1 1 IN IP4 127.0.0.1\r\ns=oracle-offer\r\nt=0 0\r\n", "far_end": { "status": 201, "fields": [ [ "location", "/v1/realtime/calls/rtc_oracle0001" ] ], "answer": "v=0\r\no=- 2 2 IN IP4 127.0.0.1\r\ns=oracle-answer\r\nt=0 0\r\n", "answer_out": "v=0\r\no=- 2 2 IN IP4 127.0.0.1\r\ns=oracle-answer\r\nt=0 0\r\n", "units": [] }, "narrow": { "unit": 9, "reply_cap": 16, "more": 3 }, "short": { "unit": 11, "buffer": "fields" }, "empty": { "unit": 10, "outcome": "Ready" }, "sessions": [ { "name": "mint", "unit": 30, "claim": 0, "steps": [ { "label": "arrive", "arrive": { "method": "POST", "target": "/v1/realtime/client_secrets" }, "want": { "outcome": "Ready", "route": { "class": "direct", "entry": "m-cap" } } }, { "label": "attempt", "piece": { "from": "kernel", "attempt": 1 }, "want": { "outcome": "Ready", "to_far_end": true, "verb": "POST", "target": "/v1/realtime/client_secrets", "need": 5, "emitted": "{\"expires_after\":{\"anchor\":\"created_at\",\"seconds\":600},\"session\":{\"model\":\"m-cap\"}}" } }, { "label": "caller", "piece": { "from": "caller", "last": true }, "want": { "outcome": "Ready", "emitted": "", "to_far_end": false } }, { "label": "far_end", "piece": { "from": "far_end", "status": 200, "last": true, "bytes": "{\"value\":\"ek_oracle_0001\",\"expires_at\":1767225600}" }, "want": { "outcome": "Ready", "done": true, "status": 200, "emitted_has": [ "ek_oracle_0001" ], "fields": [ [ "content-type", "application/json" ], [ "content-length", "55" ] ] } } ] }, { "name": "sideband", "reply_cap": 262144, "unit": 20, "stream": 20, "claim": 2, "steps": [ { "label": "upgrade", "arrive": { "method": "GET", "target": "/v1/realtime/sideband/rtc_1" }, "want": { "outcome": "Ready", "route": { "class": "direct", "entry": "m-cap" } } }, { "label": "project", "project": {}, "want": { "outcome": "Ready", "rewritten": false, "body_has": [ "\"model\":\"m-cap\"" ] } }, { "label": "caller audio", "piece": { "from": "caller", "bytes": [ "{\"type\":\"input_audio_buffer.append\",\"audio\":\"", { "repeat": "A", "times": 128000 }, "\"}" ] }, "want": { "outcome": "Ready", "to_far_end": true, "more": 0, "verb": "GET", "target": "/v1/realtime", "emitted_has": [ "input_audio_buffer.append" ], "units": [], "need": 4 } }, { "label": "drive", "drive": true, "want": { "outcome": "Ready", "ready": [] } }, { "label": "turn attempt", "piece": { "from": "kernel", "attempt": 1 }, "want": { "outcome": "Ready", "emitted": "", "to_far_end": false, "done": false, "units": [] } }, { "label": "far usage", "piece": { "from": "far_end", "status": 101, "bytes": "{\"type\":\"response.done\",\"response\":{\"usage\":{\"input_token_details\":{\"audio_tokens\":10,\"text_tokens\":3},\"output_token_details\":{\"audio_tokens\":20,\"text_tokens\":4}}}}" }, "want": { "outcome": "Ready", "to_far_end": false, "done": false, "units": [ [ 0, 10 ], [ 1, 20 ], [ 2, 3 ], [ 3, 4 ], [ 4, 2 ], [ 6, 1 ] ] } }, { "label": "collect", "piece": { "from": "kernel" }, "want": { "outcome": "Ready", "emitted": "", "more": 0, "done": false, "units": [ [ 0, 10 ], [ 1, 20 ], [ 2, 3 ], [ 3, 4 ], [ 4, 2 ], [ 6, 1 ] ] } }, { "label": "short", "piece": { "from": "caller", "bytes": [ "{\"type\":\"input_audio_buffer.append\",\"audio\":\"", { "repeat": "A", "times": 128000 }, "\"}" ], "short": "units" }, "want": { "outcome": "Ready", "to_far_end": true, "units": [ [ 0, 10 ], [ 1, 20 ], [ 2, 3 ], [ 3, 4 ], [ 4, 2 ], [ 6, 1 ] ], "need": 4 } }, { "label": "caller end", "piece": { "from": "caller", "last": true }, "want": { "outcome": "Ready", "done": true, "units": [ [ 0, 10 ], [ 1, 20 ], [ 2, 3 ], [ 3, 4 ], [ 4, 4 ], [ 6, 1 ] ] } } ] }, { "name": "hooks", "unit": 31, "claim": 2, "steps": [ { "label": "rewrite", "project": { "rewrite": "{\"voice\":\"marin\"}" }, "want": { "outcome": "Ready", "rewritten": true, "body_has": [ "\"voice\":\"marin\"", "\"model\":\"m-cap\"" ] } }, { "label": "rewrite unread", "project": { "rewrite": "{\"voice\":7}" }, "want": { "outcome": "Refused" } } ] }, { "name": "request on a session door", "unit": 21, "claim": 2, "steps": [ { "label": "attempt", "piece": { "from": "kernel", "attempt": 1 }, "want": { "outcome": "Refused" } } ] }, { "name": "unclaimed door", "unit": 12, "claim": 5, "steps": [ { "label": "arrive", "arrive": { "method": "GET", "target": "/.well-known/oauth-protected-resource/v1/realtime" }, "want": { "outcome": "Refused", "status": 404 } }, { "label": "attempt", "piece": { "from": "kernel", "attempt": 1 }, "want": { "outcome": "Refused" } } ] } ], "refusal": { "status": 403, "text": "denied", "reply": "{\"error\":{\"code\":null,\"message\":\"denied\",\"param\":null,\"type\":\"permission_error\"}}" } } }Kind-isolation matrix: the +11 report-only hits, listed and removed
The first push measured 14862 -> 14873 on
kind-isolation:matrix. All 11 hits were in one cell, busbar-plugin-loader x plane, and all were the needlestreams. That is the streaming plane's alias and config-section key, which the matrix derives as a plane word. The suite was using the word for the stream ids thatdrivenames:streamswant keystreams=label"streams"in the WANTS list"streams"match arm injudgelet streamsbindingformat!("streams={streams:?}")"streams": [40]"streams": []streamswantNone of the 11 is inherent to a neutral suite. All are avoidable: the noun is the suite's own label, not anything the ABI names. Fix commit
ae5a74654renames the want key and line label toready(the stream idsdrivenames as ready). Results:cargo xtask gate kind-isolation --reportmeasures 14862 again, the same as base.ae5a74654(Latchkeycli-1a7f7129-15f3-46a6-b457-5f89546b3508) is in the table below.The streaming
conformance.jsonabove uses"ready"accordingly.What the other planes would need
ArriveOut::route_flagsis not on the line (the session/stream route bits).tickandcancelstay ticket-less, so a session ceiling or a cancel on a session's ticket is not driven.public_url, an arrival's claim index and head fields (protocol-version, method and accept headers), many units in one script (sessions), an answer streamed in several far-end pieces (pieces withoutlast),morere-calls as pinned steps, and project rewrite withbody_has/rewritten. Still lacking: a HOST that answers kernel services (the relay script's entitlement table; the suite binds a plane with no host services). Record writes (RECORD_AUDITrows) andOnPieceOut::laneare not on the line. The prompt view's turns fromprojectare not surfaced.pool, SSE answers as several far-end pieces in a session step list, and narrow/short as today. Still lacking:refusalis fixed atREFUSAL_GATEwith nounit/plane_code/target(llm's witness rendersREFUSAL_KERNELby unit and target).OnPieceOut::verdictis not on the line.Checks
cargo xtask gate --all --format=tsv, base70776f1d3vs headcargo fmt --all -- --checkcargo clippy --workspace --all-targets --locked -- -D warningscargo test -p busbar-plugin-loader --features conformance --lib| fix round
ae5a74654: gate --all, tags in the bundle (Latchkeycli-1a7f7129-15f3-46a6-b457-5f89546b3508) | GATE EXIT 1 on both base and head (base carries 12 FAIL rows). 562 judged rows, verdict columns identical to base70776f1d3(547 PASS / 12 FAIL / 3 EXCUSED), non-PASS rows byte-identical; kind-isolation matrix MEASURED 14862 = base || loader
conformance::tests at the stacked head (Latchkeycli-0b18cf3f-fbc1-45dd-b0bb-244061914efa) | 42 passed, 0 failed |