Skip to content

busbar-a2a: the push-volume window cell runs on an injected clock - #552

Merged
MattJackson merged 1 commit into
predevfrom
a2a-pushback-clock
Oct 7, 2026
Merged

MattJackson merged 1 commit into
predevfrom
a2a-pushback-clock

Conversation

@MattJackson

Copy link
Copy Markdown
Collaborator

The legacy crate's cell a_live_token_is_bounded_to_sixty_pushes_per_task_per_window pushes 61 times at the real /a2a/push endpoint and expects the 61st to be 429. The endpoint reads the host wall clock (pushback.rs, ctx.host.clock_now_secs()) and the limiter's window is a fixed 60 seconds keyed on now - now % 60. If the wall clock crosses a minute boundary between push 1 and push 61, the budget legitimately refills and the 61st push is 202. That is what failed in CI run 37602258893 (PR #540, test:no-default-features leg: "the 61st push inside one window must be refused", left 202 right 429); it passed on rerun.

There is no injectable clock behind ctx.host on this path: the harness serves the real router over the engine host, whose clock_now slot reads the kernel wall clock, and the only kernel clock pin is a thread-local that a spawned server task cannot see. Adding a production seam would change shipped code for a test, so the cell instead judges only attempts that sit inside one window. It reads the host wall clock's window before the first push and after the last; an attempt that straddled a boundary is discarded and re-run on a fresh harness and task (its own budget), and an attempt inside one window asserts exactly what it asserted before (60 x 202, then 429). A boundary is crossed at most once a minute, so a second attempt is clean; three straddles in a row panic, never skip. No assertion is weakened. The only non-test change is PUSH_RATE_WINDOW_SECS becoming pub(crate) so the cell uses the production window length rather than a copy; behaviour is unchanged.

Audit: pushback_limiter_tests.rs already drives PushLimiter::admit with an injected now (no wall clock). No other cell in pushback_tests.rs depends on a window or second boundary (its only sleeps are bounded polls for the detached delivery). The plane crate (busbar-plane-a2a PushLimiter::admit(task, now_secs) and its push-volume test) already takes an injected clock and is untouched.

Proof on Latchkey (large):

  • cargo fmt --all --check: rc 0
  • cargo clippy --locked -p busbar-a2a --all-targets --all-features -- -D warnings: rc 0
  • cargo test --locked -p busbar-a2a --features test-support --no-fail-fast: 632 passed, 0 failed
  • cargo test --locked -p busbar-a2a --no-default-features --features test-support --no-fail-fast: 632 passed, 0 failed (the pushback cells only compile with test-support; a bare run has 16 tests)
  • the pinned cell run 20 times with --exact: 20/20 passed

…ddled a window boundary and re-runs it on a fresh task, so the 61st-push-is-429 assertion is judged only inside one window (CI run 37602258893 flaked when the fixed 60s window rolled mid-run)
@MattJackson
MattJackson enabled auto-merge October 7, 2026 11:17
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

promote into predev: BOARD @74c205d2b: 2 failing test row(s), 12 DENY row(s)

Failing tests (2)

crate test step first panic
transport_dropped_in_serves a_dropped_in_transport_registers_through_the_one_fold_and_serves test:dropped-in-tcp-transport crates/busbar/tests/transport_dropped_in_serves.rs:168:13: busbar exited (ExitStatus(unix_wait_status(512))) before serving; log:
-p busbar --test transport_dropped_in_serves test target failed test:dropped-in-tcp-transport

DENY rows (12)

gate row detail
construction one-pick-site 3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8
kind-isolation kind-isolation:deps 3 finding(s), 76 shipped edge instance(s) over 27 class(es), 76 declaration(s); 61 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w
kind-isolation kind-isolation:test-deps 5 finding(s), 36 test edge instance(s) over 19 class(es), 36 declaration(s); 22 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge
kind-isolation-ship kind-isolation:deps 15 finding(s) over 76 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hooks-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the
kind-isolation-ship kind-isolation:test-deps 13 finding(s) over 36 test edge(s): ship-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is 'not-allowed': the architecture grants no cleanliness -> legacy edge, and the ship criterion is t
kind-isolation-ship kind-isolation:faces 4 finding(s) over 31 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Store' 2 time(s) in shipped source — the entry face of kind 'store'. A trait implementation is a claim
kind-isolation-ship kind-isolation:testkit 2 finding(s) over 12 crate(s): battery-ignored crates/busbar-plane-decisions busbar-plane-decisions carries a tests/conformance.rs whose every entry is '#[ignore]'d (or which has none). 'cargo test'
kind-isolation-ship kind-isolation:legacy-drain 5 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier)
kind-isolation-ship kind-isolation:control-path 73 finding(s) over 3 control surface(s): upstream crates/busbar-core-admin/src/admin_codec/meta.rs:84 busbar-core-admin names 'egress' — a control surface has no upstream to reach, so the vocabulary o
ship-ready ship-ready:ship-twin 'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is
instance-noun-neutrality instance-noun-neutrality:voice tracked known-debt census — 8: crates/busbar-plane-llm/src/codec/gemini/handler.rs×7 [cross-plugin] | crates/busbar-plane-llm/src/codec/gemini/tests/handler_tests.rs×2 [cross-plugin] | crates/busbar
structure-lint structure-lint:plane-dup:unledgered 23 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs mcp:crates/busbar-mcp/src/mcp/config.rs voice:crates/busbar-voice/src/config.rs (the ledger row signs for

Judged against base 2bbe362db: 0 new red, 0 worse, 7 standing (excused).

tests passed: 22718, failed: 1. Run: https://github.com/GetBusbar/busbar/actions/runs/37613134223 . Artifact verdict-74c205d2b41da829120f61b9b2aece4176da5ef2 (failures.json, junit.xml, raw.log; 90 days).

@MattJackson
MattJackson added this pull request to the merge queue Oct 7, 2026
Merged via the queue into predev with commit 1619f24 Oct 7, 2026
8 checks passed
@MattJackson
MattJackson deleted the a2a-pushback-clock branch October 7, 2026 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant