Skip to content

plugin-loader plane suite: public_url and a sessions leg, so every plane runs the published suite both ways - #543

Merged
MattJackson merged 2 commits into
predevfrom
p5-plane-suite
Oct 7, 2026
Merged

MattJackson merged 2 commits into
predevfrom
p5-plane-suite

Conversation

@MattJackson

@MattJackson MattJackson commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

What

PLANE-EXTRACT: a plane is a plugin like any other kind, one suite, both doors. busbar-plugin-loader's published plane script (crates/plugin-loader/src/conformance/plane.rs) now takes the inputs every plane needs to run conformance_suite! from its own repo. The seven test names are unchanged. The suite source uses neutral nouns only.

New conformance.json inputs (all optional; absent = today's behaviour)

input what it does
plane.public_url handed to open as PlaneOpenIn::public_url (and to open again). RefreshIn has no public URL field, so the instance keeps the one open was handed.
plane.claimed/unclaimed.claim ArriveIn::claim, the snapshot claim index. Every piece and project of the script's units carries the claimed one.
plane.claimed/unclaimed.fields the arrival's head fields
plane.claimed.route {class, entry} the arrive line also names ArriveOut::route/pool, and the contract checks them
plane.pool / plane.caller_ref OnPieceIn::pool on ATTEMPT pieces and caller_ref on every piece
plane.short.buffer: "fields" the short answer meets a fields buffer of capacity 0 instead of units (fields_needed= on the line)
plane.sessions[] units on one claim driven step by step: `{name, unit, claim, stream?, reply_cap?, steps:[{label, arrive

Each session step is a Recorder line with its exact pin: 1 crossing, or 2 for a piece met short. Each step is labelled <name> <label>, so red_a_moved_crossing_count_is_refused and BUSBAR_CONFORMANCE_RED=count cover the new legs like every other step. The contract judges each step against its want. outcome is required, and a want may also name to_far_end, done, more, status, verb, target, need, emitted, emitted_has, fields, units, route, ready, body_has and rewritten. A want key the suite does not know is refused, so two equal folds of failures still prove nothing. The per-piece host lists grew to 8, and the session line also prints need.

Decisions' fold is byte-identical. I dumped the 467-line both-ways fold from busbar-plane-decisions' unchanged suite on base and on head (a scratch dump, not committed), and cmp reported no difference.

Loader-side tests

crates/plugin-loader/src/tests/conformance_plane_sessions_tests.rs runs over the in-tree plane_door_plugin fixture, linked and dropped in. When opened under a public URL, the fixture now also claims GET /upgrade; no existing test opens it under one. The tests cover:

  • GREEN: a live session (arrival with route, caller piece, drive naming the stream, a collection, a two-piece far-end answer, one piece met short, project) and a request unit through a 4-byte reply buffer, both ways, at their pins, the folds equal, every want met. Without a URL, open hands none.
  • RED: a moved count on every session step; a step answering otherwise than wanted (units, outcome, ready streams, body, verb, route); an unknown want key; a piece called short that is not (it crosses 1 where 2 are pinned, and names no room); two sessions sharing a name or two steps sharing a label.

The streaming plane runs it (scratch, not in this PR)

I applied this commit onto #503's head and changed crates/busbar-plane-streaming as follows:

  • its hand-written witness moved to tests/door_witness.rs
  • tests/conformance.rs became the conformance_suite! macro
  • the loader dev-dep got features = ["conformance"]
  • it got the conformance.json below

Results on Latchkey, release build with BUSBAR_EXPECT_RELEASE=1:

  • all seven suite tests green both ways
  • BUSBAR_CONFORMANCE_RED=count fails on the comparator (Linked: step 'facts': 0 crossing(s), pinned 1)
  • door_witness 12/12 green

Decisions: 7/7 green in release, and its RED run fails on the comparator.

The JSON seeds GetBusbar/busbar-plane-streaming. It covers:

  • the five doors claimed under the public URL
  • the SDP unit as the claimed unit, through narrow and fields-short
  • the mint request unit (need=5)
  • a sideband live session: upgrade with direct route m-cap, the projected session params, caller audio to the far end (need=4), the usage turn's six reported counts, a collection, a units-short re-call, and the caller's end settling the open turn
  • the hook rewrite and the refused rewrite
  • a request unit on a session door refused
  • the unclaimed metadata door refused 404
streaming tests/conformance.json
{
  "settings": {
    "session": {
      "model": "m-cap"
    }
  },
  "plane": {
    "bad_settings": [
      {
        "nonsense_key": 1
      },
      {
        "session_max_secs": 0
      }
    ],
    "refresh_settings": {
      "session": {
        "model": "m-cap"
      }
    },
    "public_url": "https://gw.example.com/ignored?q=1#f",
    "open_claims": [
      [
        "POST",
        "/v1/realtime/client_secrets"
      ],
      [
        "POST",
        "/v1/realtime/calls"
      ],
      [
        "GET",
        "/v1/realtime/sideband/{call_id}"
      ],
      [
        "GET",
        "/v1/realtime/gemini/{call_id}"
      ],
      [
        "GET",
        "/twilio/{call_id}"
      ]
    ],
    "refresh_claims": [
      [
        "POST",
        "/v1/realtime/client_secrets"
      ],
      [
        "POST",
        "/v1/realtime/calls"
      ],
      [
        "GET",
        "/v1/realtime/sideband/{call_id}"
      ],
      [
        "GET",
        "/v1/realtime/gemini/{call_id}"
      ],
      [
        "GET",
        "/twilio/{call_id}"
      ]
    ],
    "member": "m-cap",
    "caller_ref": "c0ffee",
    "claimed": {
      "unit": 7,
      "claim": 1,
      "method": "POST",
      "target": "/v1/realtime/calls",
      "route": {
        "class": "direct",
        "entry": "m-cap"
      }
    },
    "unclaimed": {
      "unit": 8,
      "claim": 9,
      "method": "GET",
      "target": "/v1/realtime/nowhere",
      "status": 404
    },
    "request": "v=0\r\no=- 1 1 IN IP4 127.0.0.1\r\ns=oracle-offer\r\nt=0 0\r\n",
    "request_out": "v=0\r\no=- 1 1 IN IP4 127.0.0.1\r\ns=oracle-offer\r\nt=0 0\r\n",
    "far_end": {
      "status": 201,
      "fields": [
        [
          "location",
          "/v1/realtime/calls/rtc_oracle0001"
        ]
      ],
      "answer": "v=0\r\no=- 2 2 IN IP4 127.0.0.1\r\ns=oracle-answer\r\nt=0 0\r\n",
      "answer_out": "v=0\r\no=- 2 2 IN IP4 127.0.0.1\r\ns=oracle-answer\r\nt=0 0\r\n",
      "units": []
    },
    "narrow": {
      "unit": 9,
      "reply_cap": 16,
      "more": 3
    },
    "short": {
      "unit": 11,
      "buffer": "fields"
    },
    "empty": {
      "unit": 10,
      "outcome": "Ready"
    },
    "sessions": [
      {
        "name": "mint",
        "unit": 30,
        "claim": 0,
        "steps": [
          {
            "label": "arrive",
            "arrive": {
              "method": "POST",
              "target": "/v1/realtime/client_secrets"
            },
            "want": {
              "outcome": "Ready",
              "route": {
                "class": "direct",
                "entry": "m-cap"
              }
            }
          },
          {
            "label": "attempt",
            "piece": {
              "from": "kernel",
              "attempt": 1
            },
            "want": {
              "outcome": "Ready",
              "to_far_end": true,
              "verb": "POST",
              "target": "/v1/realtime/client_secrets",
              "need": 5,
              "emitted": "{\"expires_after\":{\"anchor\":\"created_at\",\"seconds\":600},\"session\":{\"model\":\"m-cap\"}}"
            }
          },
          {
            "label": "caller",
            "piece": {
              "from": "caller",
              "last": true
            },
            "want": {
              "outcome": "Ready",
              "emitted": "",
              "to_far_end": false
            }
          },
          {
            "label": "far_end",
            "piece": {
              "from": "far_end",
              "status": 200,
              "last": true,
              "bytes": "{\"value\":\"ek_oracle_0001\",\"expires_at\":1767225600}"
            },
            "want": {
              "outcome": "Ready",
              "done": true,
              "status": 200,
              "emitted_has": [
                "ek_oracle_0001"
              ],
              "fields": [
                [
                  "content-type",
                  "application/json"
                ],
                [
                  "content-length",
                  "55"
                ]
              ]
            }
          }
        ]
      },
      {
        "name": "sideband",
        "reply_cap": 262144,
        "unit": 20,
        "stream": 20,
        "claim": 2,
        "steps": [
          {
            "label": "upgrade",
            "arrive": {
              "method": "GET",
              "target": "/v1/realtime/sideband/rtc_1"
            },
            "want": {
              "outcome": "Ready",
              "route": {
                "class": "direct",
                "entry": "m-cap"
              }
            }
          },
          {
            "label": "project",
            "project": {},
            "want": {
              "outcome": "Ready",
              "rewritten": false,
              "body_has": [
                "\"model\":\"m-cap\""
              ]
            }
          },
          {
            "label": "caller audio",
            "piece": {
              "from": "caller",
              "bytes": [
                "{\"type\":\"input_audio_buffer.append\",\"audio\":\"",
                {
                  "repeat": "A",
                  "times": 128000
                },
                "\"}"
              ]
            },
            "want": {
              "outcome": "Ready",
              "to_far_end": true,
              "more": 0,
              "verb": "GET",
              "target": "/v1/realtime",
              "emitted_has": [
                "input_audio_buffer.append"
              ],
              "units": [],
              "need": 4
            }
          },
          {
            "label": "drive",
            "drive": true,
            "want": {
              "outcome": "Ready",
              "ready": []
            }
          },
          {
            "label": "turn attempt",
            "piece": {
              "from": "kernel",
              "attempt": 1
            },
            "want": {
              "outcome": "Ready",
              "emitted": "",
              "to_far_end": false,
              "done": false,
              "units": []
            }
          },
          {
            "label": "far usage",
            "piece": {
              "from": "far_end",
              "status": 101,
              "bytes": "{\"type\":\"response.done\",\"response\":{\"usage\":{\"input_token_details\":{\"audio_tokens\":10,\"text_tokens\":3},\"output_token_details\":{\"audio_tokens\":20,\"text_tokens\":4}}}}"
            },
            "want": {
              "outcome": "Ready",
              "to_far_end": false,
              "done": false,
              "units": [
                [
                  0,
                  10
                ],
                [
                  1,
                  20
                ],
                [
                  2,
                  3
                ],
                [
                  3,
                  4
                ],
                [
                  4,
                  2
                ],
                [
                  6,
                  1
                ]
              ]
            }
          },
          {
            "label": "collect",
            "piece": {
              "from": "kernel"
            },
            "want": {
              "outcome": "Ready",
              "emitted": "",
              "more": 0,
              "done": false,
              "units": [
                [
                  0,
                  10
                ],
                [
                  1,
                  20
                ],
                [
                  2,
                  3
                ],
                [
                  3,
                  4
                ],
                [
                  4,
                  2
                ],
                [
                  6,
                  1
                ]
              ]
            }
          },
          {
            "label": "short",
            "piece": {
              "from": "caller",
              "bytes": [
                "{\"type\":\"input_audio_buffer.append\",\"audio\":\"",
                {
                  "repeat": "A",
                  "times": 128000
                },
                "\"}"
              ],
              "short": "units"
            },
            "want": {
              "outcome": "Ready",
              "to_far_end": true,
              "units": [
                [
                  0,
                  10
                ],
                [
                  1,
                  20
                ],
                [
                  2,
                  3
                ],
                [
                  3,
                  4
                ],
                [
                  4,
                  2
                ],
                [
                  6,
                  1
                ]
              ],
              "need": 4
            }
          },
          {
            "label": "caller end",
            "piece": {
              "from": "caller",
              "last": true
            },
            "want": {
              "outcome": "Ready",
              "done": true,
              "units": [
                [
                  0,
                  10
                ],
                [
                  1,
                  20
                ],
                [
                  2,
                  3
                ],
                [
                  3,
                  4
                ],
                [
                  4,
                  4
                ],
                [
                  6,
                  1
                ]
              ]
            }
          }
        ]
      },
      {
        "name": "hooks",
        "unit": 31,
        "claim": 2,
        "steps": [
          {
            "label": "rewrite",
            "project": {
              "rewrite": "{\"voice\":\"marin\"}"
            },
            "want": {
              "outcome": "Ready",
              "rewritten": true,
              "body_has": [
                "\"voice\":\"marin\"",
                "\"model\":\"m-cap\""
              ]
            }
          },
          {
            "label": "rewrite unread",
            "project": {
              "rewrite": "{\"voice\":7}"
            },
            "want": {
              "outcome": "Refused"
            }
          }
        ]
      },
      {
        "name": "request on a session door",
        "unit": 21,
        "claim": 2,
        "steps": [
          {
            "label": "attempt",
            "piece": {
              "from": "kernel",
              "attempt": 1
            },
            "want": {
              "outcome": "Refused"
            }
          }
        ]
      },
      {
        "name": "unclaimed door",
        "unit": 12,
        "claim": 5,
        "steps": [
          {
            "label": "arrive",
            "arrive": {
              "method": "GET",
              "target": "/.well-known/oauth-protected-resource/v1/realtime"
            },
            "want": {
              "outcome": "Refused",
              "status": 404
            }
          },
          {
            "label": "attempt",
            "piece": {
              "from": "kernel",
              "attempt": 1
            },
            "want": {
              "outcome": "Refused"
            }
          }
        ]
      }
    ],
    "refusal": {
      "status": 403,
      "text": "denied",
      "reply": "{\"error\":{\"code\":null,\"message\":\"denied\",\"param\":null,\"type\":\"permission_error\"}}"
    }
  }
}

Kind-isolation matrix: the +11 report-only hits, listed and removed

The first push measured 14862 -> 14873 on kind-isolation:matrix. All 11 hits were in one cell, busbar-plugin-loader x plane, and all were the needle streams. That is the streaming plane's alias and config-section key, which the matrix derives as a plane word. The suite was using the word for the stream ids that drive names:

# file:line (at 626f43a) hits what it was
1 crates/plugin-loader/src/conformance/plane.rs:64 1 module doc: the streams want key
2 crates/plugin-loader/src/conformance/plane.rs:705 1 the drive line's streams= label
3 crates/plugin-loader/src/conformance/plane.rs:1353 1 "streams" in the WANTS list
4 crates/plugin-loader/src/conformance/plane.rs:1422 1 the "streams" match arm in judge
5 crates/plugin-loader/src/conformance/plane.rs:1423 1 let streams binding
6 crates/plugin-loader/src/conformance/plane.rs:1427 1 the want path in a parse message
7-8 crates/plugin-loader/src/conformance/plane.rs:1429 2 format!("streams={streams:?}")
9 crates/plugin-loader/src/tests/conformance_plane_sessions_tests.rs:31 1 fixture inputs: "streams": [40]
10 crates/plugin-loader/src/tests/conformance_plane_sessions_tests.rs:34 1 fixture inputs: "streams": []
11 crates/plugin-loader/src/tests/conformance_plane_sessions_tests.rs:194 1 RED arm editing the streams want

None of the 11 is inherent to a neutral suite. All are avoidable: the noun is the suite's own label, not anything the ABI names. Fix commit ae5a74654 renames the want key and line label to ready (the stream ids drive names as ready). Results:

  • cargo xtask gate kind-isolation --report measures 14862 again, the same as base.
  • No line of the three touched files appears in any matrix cell.
  • Gate --all on ae5a74654 (Latchkey cli-1a7f7129-15f3-46a6-b457-5f89546b3508) is in the table below.

The streaming conformance.json above uses "ready" accordingly.

What the other planes would need

  • streaming (FLIP-STREAMING: the streaming plane served through its door; busbar-voice deleted #503): everything above, and it runs green. Still lacking: ArriveOut::route_flags is not on the line (the session/stream route bits). tick and cancel stay ticket-less, so a session ceiling or a cancel on a session's ticket is not driven.
  • mcp (P3 FLIP-MCP: the mcp plane served through its door on the kernel plane driver #511): now offered: public_url, an arrival's claim index and head fields (protocol-version, method and accept headers), many units in one script (sessions), an answer streamed in several far-end pieces (pieces without last), more re-calls as pinned steps, and project rewrite with body_has/rewritten. Still lacking: a HOST that answers kernel services (the relay script's entitlement table; the suite binds a plane with no host services). Record writes (RECORD_AUDIT rows) and OnPieceOut::lane are not on the line. The prompt view's turns from project are not surfaced.
  • llm (P3 FLIP-LLM: the llm plane served through its door on the plane driver (dev-only llm-on-driver switch) #464): now offered: arrival head fields, the ATTEMPT's pool, SSE answers as several far-end pieces in a session step list, and narrow/short as today. Still lacking: refusal is fixed at REFUSAL_GATE with no unit/plane_code/target (llm's witness renders REFUSAL_KERNEL by unit and target). OnPieceOut::verdict is not on the line.

Checks

check result
cargo xtask gate --all --format=tsv, base 70776f1d3 vs head verdict columns identical (547 PASS / 12 FAIL / 3 EXCUSED on both); the non-PASS rows are byte-identical. The only detail changes are file counts (+1 source file) and the report-only kind-isolation matrix hit count (14862 -> 14873).
cargo fmt --all -- --check clean
cargo clippy --workspace --all-targets --locked -- -D warnings clean
cargo test -p busbar-plugin-loader --features conformance --lib green apart from tests that need other crates' cdylibs prebuilt (secret_env), as on base
merge-tree against predev clean

| fix round ae5a74654: gate --all, tags in the bundle (Latchkey cli-1a7f7129-15f3-46a6-b457-5f89546b3508) | GATE EXIT 1 on both base and head (base carries 12 FAIL rows). 562 judged rows, verdict columns identical to base 70776f1d3 (547 PASS / 12 FAIL / 3 EXCUSED), non-PASS rows byte-identical; kind-isolation matrix MEASURED 14862 = base |
| loader conformance:: tests at the stacked head (Latchkey cli-0b18cf3f-fbc1-45dd-b0bb-244061914efa) | 42 passed, 0 failed |

… an optional sessions leg any plane drives from its own conformance.json

The plane kind's script takes plane.public_url (handed to `open`; the refresh frame carries none, so
the instance keeps the one its open was handed), an arrival's claim, head fields and named route,
the ATTEMPT's pool and the caller's reference on every piece, a short answer met over a fields
buffer as well as a units one, and plane.sessions: units on one claim driven step by step (an
arrival, pieces from the caller, the far end or the kernel keyed by a stream, a piece met short and
re-called once, drive, project), every step a Recorder line at its exact pin and judged by the
contract against the step's want. Every new input is optional; absent, the fold is byte-identical
(the decisions plane's 467-line fold dump compared equal on base and head).

The loader's plane fixture claims its session door when opened under a public URL; the new
conformance_plane_sessions_tests drive the leg over it linked and dropped in, with RED arms for a
moved count on any session step, a step answering otherwise than wanted, an unknown want, a piece
called short that is not, and inputs naming a step twice.
@MattJackson
MattJackson enabled auto-merge October 7, 2026 10:22
…e line and in a want, so the suite spells no plane's section key (kind-isolation matrix back to base, 14862)
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

promote into predev: BOARD @626f43a31: 2 failing test row(s), 12 DENY row(s)

Failing tests (2)

crate test step first panic
transport_dropped_in_serves a_dropped_in_transport_registers_through_the_one_fold_and_serves test:dropped-in-tcp-transport crates/busbar/tests/transport_dropped_in_serves.rs:168:13: busbar exited (ExitStatus(unix_wait_status(512))) before serving; log:
-p busbar --test transport_dropped_in_serves test target failed test:dropped-in-tcp-transport

DENY rows (12)

gate row detail
construction one-pick-site 3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8
kind-isolation kind-isolation:deps 3 finding(s), 76 shipped edge instance(s) over 27 class(es), 76 declaration(s); 61 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w
kind-isolation kind-isolation:test-deps 5 finding(s), 36 test edge instance(s) over 19 class(es), 36 declaration(s); 22 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge
kind-isolation-ship kind-isolation:deps 15 finding(s) over 76 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hooks-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the
kind-isolation-ship kind-isolation:test-deps 13 finding(s) over 36 test edge(s): ship-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is 'not-allowed': the architecture grants no cleanliness -> legacy edge, and the ship criterion is t
kind-isolation-ship kind-isolation:faces 4 finding(s) over 31 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Store' 2 time(s) in shipped source — the entry face of kind 'store'. A trait implementation is a claim
kind-isolation-ship kind-isolation:testkit 2 finding(s) over 12 crate(s): battery-ignored crates/busbar-plane-decisions busbar-plane-decisions carries a tests/conformance.rs whose every entry is '#[ignore]'d (or which has none). 'cargo test'
kind-isolation-ship kind-isolation:legacy-drain 5 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier)
kind-isolation-ship kind-isolation:control-path 73 finding(s) over 3 control surface(s): upstream crates/busbar-core-admin/src/admin_codec/meta.rs:84 busbar-core-admin names 'egress' — a control surface has no upstream to reach, so the vocabulary o
ship-ready ship-ready:ship-twin 'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is
instance-noun-neutrality instance-noun-neutrality:voice tracked known-debt census — 8: crates/busbar-plane-llm/src/codec/gemini/handler.rs×7 [cross-plugin] | crates/busbar-plane-llm/src/codec/gemini/tests/handler_tests.rs×2 [cross-plugin] | crates/busbar
structure-lint structure-lint:plane-dup:unledgered 23 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs mcp:crates/busbar-mcp/src/mcp/config.rs voice:crates/busbar-voice/src/config.rs (the ledger row signs for

Judged against base 6afec149a: 0 new red, 0 worse, 7 standing (excused).

tests passed: 23411, failed: 1. Run: https://github.com/GetBusbar/busbar/actions/runs/37606920055 . Artifact verdict-626f43a313a5b3a57b9326699f0bf93605f5fbfa (failures.json, junit.xml, raw.log; 90 days).

@MattJackson
MattJackson added this pull request to the merge queue Oct 7, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 7, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 7, 2026
Merged via the queue into predev with commit 62a3336 Oct 7, 2026
@MattJackson
MattJackson deleted the p5-plane-suite branch October 7, 2026 13:29
MattJackson added a commit that referenced this pull request Oct 7, 2026
…p3-flip-llm: busbar-auth-sigv4 and -oauth leave the tree; the llm fold's linked auths rows pin them from their own repos (sigv4 dev c22578a, oauth dev 98fb861, each carrying the compiled_in::door entry this line's rows name)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant