Repository navigation
busbar-a2a: the push-volume window cell runs on an injected clock - #552
Merged
Merged
Conversation
…ddled a window boundary and re-runs it on a fresh task, so the 61st-push-is-429 assertion is judged only inside one window (CI run 37602258893 flaked when the fixed 60s window rolled mid-run)
MattJackson
enabled auto-merge
October 7, 2026 11:17
promote into
|
| crate | test | step | first panic |
|---|---|---|---|
transport_dropped_in_serves |
a_dropped_in_transport_registers_through_the_one_fold_and_serves |
test:dropped-in-tcp-transport | crates/busbar/tests/transport_dropped_in_serves.rs:168:13: busbar exited (ExitStatus(unix_wait_status(512))) before serving; log: |
-p busbar --test transport_dropped_in_serves |
test target failed |
test:dropped-in-tcp-transport |
DENY rows (12)
| gate | row | detail |
|---|---|---|
| construction | one-pick-site |
3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8 |
| kind-isolation | kind-isolation:deps |
3 finding(s), 76 shipped edge instance(s) over 27 class(es), 76 declaration(s); 61 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w |
| kind-isolation | kind-isolation:test-deps |
5 finding(s), 36 test edge instance(s) over 19 class(es), 36 declaration(s); 22 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge |
| kind-isolation-ship | kind-isolation:deps |
15 finding(s) over 76 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hooks-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the |
| kind-isolation-ship | kind-isolation:test-deps |
13 finding(s) over 36 test edge(s): ship-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is 'not-allowed': the architecture grants no cleanliness -> legacy edge, and the ship criterion is t |
| kind-isolation-ship | kind-isolation:faces |
4 finding(s) over 31 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Store' 2 time(s) in shipped source — the entry face of kind 'store'. A trait implementation is a claim |
| kind-isolation-ship | kind-isolation:testkit |
2 finding(s) over 12 crate(s): battery-ignored crates/busbar-plane-decisions busbar-plane-decisions carries a tests/conformance.rs whose every entry is '#[ignore]'d (or which has none). 'cargo test' |
| kind-isolation-ship | kind-isolation:legacy-drain |
5 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier) |
| kind-isolation-ship | kind-isolation:control-path |
73 finding(s) over 3 control surface(s): upstream crates/busbar-core-admin/src/admin_codec/meta.rs:84 busbar-core-admin names 'egress' — a control surface has no upstream to reach, so the vocabulary o |
| ship-ready | ship-ready:ship-twin |
'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is |
| instance-noun-neutrality | instance-noun-neutrality:voice |
tracked known-debt census — 8: crates/busbar-plane-llm/src/codec/gemini/handler.rs×7 [cross-plugin] | crates/busbar-plane-llm/src/codec/gemini/tests/handler_tests.rs×2 [cross-plugin] | crates/busbar |
| structure-lint | structure-lint:plane-dup:unledgered |
23 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs mcp:crates/busbar-mcp/src/mcp/config.rs voice:crates/busbar-voice/src/config.rs (the ledger row signs for |
Judged against base 2bbe362db: 0 new red, 0 worse, 7 standing (excused).
tests passed: 22718, failed: 1. Run: https://github.com/GetBusbar/busbar/actions/runs/37613134223 . Artifact verdict-74c205d2b41da829120f61b9b2aece4176da5ef2 (failures.json, junit.xml, raw.log; 90 days).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The legacy crate's cell a_live_token_is_bounded_to_sixty_pushes_per_task_per_window pushes 61 times at the real /a2a/push endpoint and expects the 61st to be 429. The endpoint reads the host wall clock (pushback.rs, ctx.host.clock_now_secs()) and the limiter's window is a fixed 60 seconds keyed on now - now % 60. If the wall clock crosses a minute boundary between push 1 and push 61, the budget legitimately refills and the 61st push is 202. That is what failed in CI run 37602258893 (PR #540, test:no-default-features leg: "the 61st push inside one window must be refused", left 202 right 429); it passed on rerun.
There is no injectable clock behind ctx.host on this path: the harness serves the real router over the engine host, whose clock_now slot reads the kernel wall clock, and the only kernel clock pin is a thread-local that a spawned server task cannot see. Adding a production seam would change shipped code for a test, so the cell instead judges only attempts that sit inside one window. It reads the host wall clock's window before the first push and after the last; an attempt that straddled a boundary is discarded and re-run on a fresh harness and task (its own budget), and an attempt inside one window asserts exactly what it asserted before (60 x 202, then 429). A boundary is crossed at most once a minute, so a second attempt is clean; three straddles in a row panic, never skip. No assertion is weakened. The only non-test change is PUSH_RATE_WINDOW_SECS becoming pub(crate) so the cell uses the production window length rather than a copy; behaviour is unchanged.
Audit: pushback_limiter_tests.rs already drives PushLimiter::admit with an injected now (no wall clock). No other cell in pushback_tests.rs depends on a window or second boundary (its only sleeps are bounded polls for the detached delivery). The plane crate (busbar-plane-a2a PushLimiter::admit(task, now_secs) and its push-volume test) already takes an injected clock and is untouched.
Proof on Latchkey (large):