Skip to content

mcp: the MCP-FIX stack (plane-mcp findings 1-18, 24): passthrough, dest.judge, dead plane, line carrier, sessions, stdio, tasks, bounds - #673

Closed
MattJackson wants to merge 56 commits into
predevfrom
lane-mcpfix-bounds
Closed

MattJackson wants to merge 56 commits into
predevfrom
lane-mcpfix-bounds

Conversation

@MattJackson

@MattJackson MattJackson commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

The one PR that lands the MCP-FIX stack (busbar-plane-mcp audit findings). It contains, by merge in landing order: #634 passthrough, #639 destjudge, #638 deadplane, #637 line, #640 sessions-v2, #645 stdio-v2, #660 tasks, and this branch's own bounds work; plus #616 (ask) and #615 (sampling), which sit ahead in the merge queue and touch the same files. #634 #638 #639 #640 #645 #660 are drafts and show merged when this lands.

What it closes

group findings PR (detail, RED plant, original proof)
passthrough 2, 3: a tool result, a task result and an upstream error reach the caller as the upstream sent them; the outputSchema replacement and the markup strip on results are deleted; BUSBAR-7065 retired #634 (RED 6bc5958, 381e4c3; cli-d431829e)
destjudge 4 [security]: argument URLs are judged by the kernel's dest.judge; plane-local host rules deleted #639 (RED f8af9d2; cli-74b2870f)
deadplane 12: the unserved Plane/SessionPlane impl and the cross-plane sampling route are deleted; the xtask refusal-collapse scan drops its mcp row #638 (RED 87a59c0; cli-7463c40a)
line 16, 17: the line carrier refuses subscribe/setLevel (-32601) and bounds its live asks #637 (RED 8f6c4e4; cli-7c7be1aa)
sessions 1, 18: the session revisions and the 2024-11-05 event stream, both directions; the session byte account never underflows #640 (RED 7150aa7; cli-17ae3789)
stdio 5 [security], 13, 14: relaying calls are serialised per stdio child in arrival order so each ask reaches only its caller, an ask raised with no call open is refused; a lease reads whole frames; Frames reads each byte once #645 (RED 11b3ca7; cli-56d97d32)
tasks 6, 24: the task store is host records; leftover live handles are settled; an owed settle is made again #660 (RED 7c81fbb; cli-e1d0037d)
bounds (this branch) 7, 8, 9, 15 and the unit table: an upstream answer under REPLY_MAX, the uri dedupe, the refused unit dropped, a per-owner listen quota; a full unit table refuses (429) and evicts nothing RED 67e0b43, 64a2244; cli-2f87e482
ask (#616, queued) 10, 11: the final ask round needs its answer; a failed host clock refuses sealed state #616 (RED 6643353, b7fc13f)
sampling (#615, queued) the resolved-completion seam and the ask satisfier are deleted; an upstream's ask is relayed #615 (RED 6d297d1)

Known limits (rulings)

  • Sessions: busbar does not act as a 2024-11-05 SSE client upstream and holds no upstream resource subscription. An upstream that offers only 2024-11-05 gets the upstream-failure answer naming that revision.
  • Stdio: an ask raised by a finished call after the next call opened is attributed to that next call (the wire's limit); a serial child holding a relayed ask blocks the member's next relaying call until the retry or the ask TTL (300 s); a waiting call is answered busy past its timeout:.
  • Line carrier: subscribe and setLevel stay -32601 in every revision the carrier speaks; subscribe for the old revisions is served on the HTTP sessions.

Cross-group resolutions made in the merges

  • deadplane x predev P-item refusal-reason collapse: one refusal classification; every surface a class-to-wire table #535: refusal_words lived only in the deleted unserved impl; tool_plane.rs and its test stay deleted.
  • deadplane x stdio: tests/alloc_gate.rs keeps the counting allocator and the finding-14 plant; the decode pin drove the deleted impl.
  • sessions x line: the carrier's initialize negotiation is re-applied on line's -32601 carrier, declaring neither subscribe nor logging; the subscription uri bound moves to door_sessions.rs.
  • tasks x stdio: Step::Wait stays for stdio's waiting call; the run's call takes destjudge's (services, ticket); the door test's records_composed takes both the wall clock and the dest judge.
  • bounds x sessions: REPLY_MAX is checked at the gather, before the client ladder; with keep() gone, the line carrier's revision table admits a new carrier session only while it has room (a full one is answered in the stateless revision), and the session stream table is bounded by the unit table's admission.
  • ask x tasks: the relayed task leg opens the retry's state and keeps ask's rule that an unreadable clock opens nothing.
  • sampling x passthrough/deadplane: call.rs's settle doc says both an ask and a result are relayed; purity.rs keeps both source scans.
  • Hop reds named on mcp tasks: the task store is host records; leftover live handles are settled; an owed settle is made again until it lands (plane-mcp findings 6, 24) #660 (run 37720341630), fixed here: mcp_stdio_serve now expects the negotiated session revision; the kind-isolation-ship selftest plants its short-circuit step in busbar-plane-a2a, because the mcp plane is now door-only.

Proof

Latchkey cli-af296ba4-4bea-4bc7-8d9b-22c41bf0b838 ran on the combined tree, which matches this head on every touched path except the two hop-red fixes above. RED on 6d297d1: 3 of 3 failed. GREEN-EXIT=0: fmt, clippy -D warnings (kernel, llm, plane-mcp), tests for busbar-kernel, busbar-llm and busbar-plane-mcp, a busbar build, plane_host_universal_purity and plane_node. Each group's own RED and GREEN job is listed in the table. This PR's hop is the gate.

1.5.5 had no MCP plane. An unconfigured node's GET /mcp is still the 1.5.5 404.

…pls the unserved Plane traits (finding 12; spec Law 11, never-constructed). Source scan: the honest plant for a pure deletion; fails while NestedPlane, SAMPLING_OP, impl Plane/SessionPlane for McpPlane exist
… struck cross-plane sampling route (finding 12)

The crate serves only plane_door::door; nothing constructed McpPlane as a Plane. Removes src/tool_plane.rs
(impl Plane / SessionPlane for McpPlane, the sampling row to DestinationFacts::NestedPlane, the roots row, the
second meter that disagreed with the served door's) and tool_meta::SAMPLING_OP. Law 11 (spec 420-421, 2123-2129):
no call is routed to another plane on the content's say-so; spec 1930: a capability that is never constructed
does not ship. Server and the McpPlane field were read only by that impl and go with it; McpPlane stays as the
PlaneMeta/Plugin carrier the door reads (tool_door.rs PLANE/CLAIMS). The served door's meter is untouched.

Tests driving the dead impl retire under the coordinator's finding-12 order (F25, spec 1181); surviving
assertions move to plane-free tables (conformance, declarations_agree).
…indings 2, 3)

Plants three tests in busbar-plane-mcp src/tests/call.rs, driving the pure settle the door
serves every tools/call answer through (call::settle_call):

- a_result_reaches_its_caller_as_the_upstream_sent_it: a result carrying `Vec<String>` and
  `<b>x</b>` in content text, structuredContent and _meta must reach the caller unchanged, its
  bytes the upstream's own. Fails today: the built-in markup strip serves `Vec` and `x`
  (finding 2, call.rs:1382).
- structured_output_breaking_the_published_schema_is_relayed_unchanged: a structuredContent
  that fails the tool's published outputSchema must be relayed unchanged, dispatched, audited
  applied. Fails today: busbar answers its own isError "The structured result was NOT served"
  (finding 3, call.rs:1355-1378). Replaces structured_output_breaking_the_published_schema_is_a_tool_failure,
  which asserted the replacement.
- the_task_path_names_no_rewrite_of_the_result: a source plant over door_tasks.rs (the task
  continuation is reached only through a live door). Fails today: door_tasks.rs:755 runs the
  strip over every completed task result.

Spec (docs/design/BUSBAR-1.6.0.md): Law 11, lines 2123-2133 ("A plane reads content ONLY to
translate dialects and to meter usage", 2126; "Code that answers, executes or branches on what a
request or response asks for is a defect: it is deleted", 2131-2132); product hard rules
3369-3373 ("every client header and body field passes through unchanged, except what busbar
governs").
…ip and the outputSchema replacement are deleted (findings 2, 3)

Finding 2 [HIGH] (markup stripper on tool results):
- call.rs completed(): the result no longer passes through sanitize::normalise_json. The
  caller's answer carries the upstream's own `result` bytes (serde_json RawValue over the far
  end's answer) under the caller's id, instead of a re-serialised parsed Value; the one
  addition is the dialect's `resultType: complete` on a result object that carries none. A
  `resultType` the upstream sent is no longer overwritten.
- door_tasks.rs continuation_answered(): a completed task stores the upstream's result as it
  came (End::Completed(value)).
- sanitize.rs: normalise_json deleted (no caller left). normalise / normalise_opt stay: they
  serve busbar's own section text (catalogue descriptions, prompts/get, resources/read) and
  busbar's words on a failed leg.
- busbar-plane-mcp Cargo.toml: serde_json names `raw_value` itself.

Finding 3 [HIGH] (structuredContent schema failure replaced by busbar's error):
- call.rs completed(): the outputschema::check branch and its "The structured result was NOT
  served" answer are deleted; the upstream's result is relayed unchanged, dispatched, audited
  applied.
- outputschema.rs and src/tests/outputschema_tests.rs deleted: the check has no caller ("a
  capability that is never constructed does not ship", THE DESIGN 1930).

Tests retired: src/tests/outputschema_tests.rs (16 tests of the deleted check);
sanitize_tests.rs every_wrapper_normalises_through_the_same_function loses its normalise_json
half (renamed the_optional_wrapper_normalises_through_the_same_function, normalise_opt half
kept). call.rs a_result_is_normalised_stamped_and_dispatched is renamed
a_result_is_stamped_and_dispatched and now pins the relayed bytes and the empty-result stamp.

Prose: call.rs module doc, sanitize.rs module doc, tools_config.rs output_schema doc,
tests/sanitize_complexity.rs doc, docs/mcp.md (output_schema row, catalogue and
markup-normalisation paragraphs) no longer claim results are stripped or validated.

Spec (docs/design/BUSBAR-1.6.0.md): Law 11, 2123-2133 (2126 "A plane reads content ONLY to
translate dialects and to meter usage"; 2131-2132 "Code that answers, executes or branches on
what a request or response asks for is a defect: it is deleted, never added"); product hard
rules 3369-3373 ("every client header and body field passes through unchanged, except what
busbar governs"); 1930.
…8, 9, 15)

Plants that fail on the unfixed tree: a unit the kernel refuses stays held (9);
a piece the plane refuses leaves its unit held (9); an upstream answer is
gathered with no reply ceiling (7, source-shape plant: the gather site needs a
kernel-admitted call this harness has no host to make); a request over the
64-uri ceiling is refused only after the whole array is read (8); one caller's
subscriptions are not refused at a per-owner quota (15).
Spec: BUSBAR-1.6.0.md 379-390 (mcp bullet, per-owner session and byte quotas),
199-201 (nothing evicts live work; an eviction is not a refusal).
… and the per-owner subscription quota (findings 7, 8, 9, 15)

7: an upstream answer is gathered only up to the SDK's REPLY_MAX; past it the call fails as a bad upstream answer does (upstream_failed).
8: resourceSubscriptions are deduplicated through a set and read no further than the first uri past MAX_SUBSCRIBED_URIS.
9: a unit the kernel refuses (refusal slot) or whose piece the plane refuses is dropped from the unit map.
15: subscriptions/listen holds at most 64 streams per caller; the 65th is refused 429 subscription_quota in the caller's own answer, never evicting another caller's stream (keep() no longer used for listens).
Spec: BUSBAR-1.6.0.md 379-390 (per-owner session and byte quotas), 199-201 (a refusal is a fact the caller can act on and an eviction is not).
…finding 4)

Two served-door tests in the root rig (crates/busbar/src/root/tests/door_steps.rs):
- a_host_the_deployment_refuses_is_refused_in_the_arguments: the rig's deployment blocks
  `blocked.example` (security.blocked_metadata_hosts); a call whose arguments name it must be
  refused 403 / -32000 / tool_argument_refused before it is sent. The plane's own predicate admits
  it, so this fails on the unfixed tree: the plane never asks the host.
- every_internal_address_the_guard_refuses_is_refused_in_the_arguments: the nine addresses the
  connector's guard refuses as internal (198.18.0.1, 192.0.0.8, 0.1.2.3, [::ffff:198.18.0.1],
  [::1%25lo], [fe80::1%25eth0], 224.0.0.1, 255.255.255.255, [ff02::1]) are refused in arguments
  by that same judgement.

The rig's kernel services now carry the deployment's one destination judge (the connector's
guard), as root::serve::kernel_services composes it in production, so the test host's dest.judge
is the kernel's real judgement, not a stub.

Spec (docs/design/BUSBAR-1.6.0.md): 5140 (B.3 item 11: argument-embedded URL judging is
dest.judge), 1579 (the dest.judge row), 614-621 (one guard, every scattered check deleted).
…anged (finding 2)

Plants an_upstream_error_message_reaches_its_caller_unchanged in busbar-plane-mcp
src/tests/call.rs: an upstream error whose message carries `Vec<String>` and `<b>x</b>` must
reach the caller byte-identical inside busbar's failure words. Fails today:
call.rs upstream_failure_result runs the markup strip over the whole text, serving `Vec` and
`x`. The envelope shape (isError result) is unchanged by this plant.

Spec (docs/design/BUSBAR-1.6.0.md): Law 11, 2126 and 2131-2132; product hard rules 3369-3373.
…d (finding 2)

call.rs upstream_failure_result no longer runs sanitize::normalise over its text. The text is
busbar's fixed wording ("The MCP server `<server>` did not complete this tool call: ...")
around the reason, and on an upstream error the reason carries the upstream's own JSON-RPC
error message, which the strip rewrote (`Vec<String>` -> `Vec`). The envelope (an isError
result) is unchanged. sanitize.rs and tests/sanitize_complexity.rs docs no longer name the
failure text as a strip site.

Spec (docs/design/BUSBAR-1.6.0.md): Law 11, 2126 and 2131-2132; product hard rules 3369-3373.
The structured-output check it reported is deleted (34df85d), so nothing emits the code.
Retired the way the catalogue retires a code (busbar-kernel diagnostics 8013): the number and
slug are kept, `retired: true`, the title marked RETIRED, the summary says what was removed and
why, the action is "Nothing emits this code." The plane's declares.json carries the same
title/summary/action (src/tests/diagnostics_tests.rs the_declares_file_states_the_catalog holds
it to the constant). docs/diagnostics-mcp.{md,json} edited by hand in the kernel renderer's exact
form (render_markdown_for appends " *(retired)*" to the heading; render_json_for writes
"retired": true): no committed-page test exists for the mcp page.

Spec (docs/design/BUSBAR-1.6.0.md): Law 11, 2131-2132; 1930.
…lane-mcp finding 15 class)

On the unfixed tree the 4097th arrival is accepted and unit 1 is evicted.
Spec: BUSBAR-1.6.0.md 199-201 (admission bounds live work; nothing evicts it; an eviction is not a refusal the caller can act on).
… evicting the oldest live unit; keep() removed

Spec: BUSBAR-1.6.0.md 199-201 (admission bounds live work; nothing evicts it). Per-owner bound not added: the arrival carries no caller reference.
… rules are deleted (finding 4)

plane-mcp finding 4 [HIGH]: the argument SSRF guard decided in the plane (argguard::judge_host
over busbar_contract::net::host_is_cloud_metadata / is_alternate_ipv4_encoding /
host_is_private_or_loopback under the registration's allow_private) and never asked the host.

- argguard.rs: judge_host now asks the host's ONE destination judge for every host the walk
  finds (an IPv6 literal bracketed, as dest.judge reads host[:port]) and renders its DEST_*
  verdict; a host that gives no verdict refuses the value (fail closed). SsrfPolicy and the local
  host rules are deleted; the walk, the scheme allowlist and the host reader stay.
- call.rs: the guard leaves admit_trusted (and its allow_private parameter) for
  judge_arguments, run on the admitted call, so the door's ask seal and the judge never hold the
  unit's handle counter at once. The refusal bytes are unchanged: 403, JSON-RPC -32000,
  data.reason tool_argument_refused, the same call-log line.
- tool_door.rs: dest_verdict asks dest.judge (Services::dest_judge_as) under the deployment's
  default egress class, DEST_REFUSE_PRIVATE unless the registration granted allow_private, name
  only (never DEST_RESOLVE, so it never pends), each on a fresh handle of the unit's ticket.
- door_tasks.rs: the task path's re-judgement of the arguments asks the same judge.
- tests: argguard_tests judge through a stand-in host over the contract's address predicates;
  call tests prove the host's verdict alone decides, each host is asked once for the called tool,
  and a host with no verdict refuses.

Spec (docs/design/BUSBAR-1.6.0.md): 5140 (Appendix C B.3 item 11: argument-embedded URL judging
is dest.judge, called where it is called today), 5111 (the B.2 row: dest.judge may pend: no),
1579 (the dest.judge row: judged against the egress rules, allow-list, class, metadata hosts),
614-621 (every outbound check in ONE place; every scattered check deleted in its favour),
4945 (class 0 of dest.judge is the deployment's security section).
…r node, leftover live handles settled, a refused settle made again

Finding 6 [HIGH] (plane-mcp audit): live task state lives only in the
instance's memory, a task not held in this process answers "unknown", and
live work handles an earlier process left (or a settle that did not land)
are never settled, so they pile up until work.open refuses every
task-creating call.

Three plants in the task_continuation rig (crates/busbar door_steps.rs),
each failing by assertion on the unfixed tree:

- a_live_task_created_on_one_node_is_answered_by_another: two nodes over
  one set of host rows; tasks/get on the second node for a live task the
  first created answers -32602 unknown instead of the first node's answer
  (BUSBAR-1.6.0.md line 389, "the task store is host records").
- the_live_handles_a_gone_process_left_are_settled_and_a_new_task_is_admitted:
  a process fills its host's bound of live work and ends; past the runs'
  lease the next process's task call is refused 503 at the bound instead
  of settling the leftover handles and being admitted (lines 199-202,
  "Admission bounds live work; nothing evicts it").
- a_settle_the_store_refuses_is_made_again_until_it_lands: the store
  refuses two settle writes; the handle stays live for ever instead of
  being settled by a following create.

The rig gains what the plants stand on: typed rows two rigs share
(Ledger::Rows, with the host's bound of live work), a wall clock the test
moves (the kernel's work book and the door's clock.now alike), and a store that refuses the next N settle writes.
…settled; an owed settle is made again until it lands

Finding 6 [HIGH] (plane-mcp audit), with finding 24 [LOW] in the same code.
BUSBAR-1.6.0.md line 389 (the mcp bullet: "the task store is host
records"), lines 199-202 ("Admission bounds live work; nothing evicts
it"), line 379 (the baseline is current predev behaviour: the tasks/*
answers on one node are unchanged).

Live task state is host records (door_tasks.rs, tool_tasks.rs):
- Every unit that moves a live task writes its live state - status, last
  update, inputRequests in order, answers, the upstream ask it is parked on
  (RelayPark), the round of its own asks - to the plane's task records in
  chunks (`{id}~/nnnn`, tool_tasks::live_parts), riding the write it makes
  anyway: the continuation's call (the far request), its park, the
  tasks/update ack.
- tasks/get, tasks/update and tasks/cancel resolve a task from the host's
  rows on every node and across a restart: work.find, then the live state
  (live handle) or the row and result chunks (settled handle). A live
  handle no longer answers "unknown" because this process holds nothing
  of it. What the instance holds is a cache of those rows plus its own
  halves (the run taken here, the unit running it, a settle owed).
- A task parked on its own ask round no longer waits in-process: the
  continuation ends with the handle live (as the relayed ask already did)
  and the tasks/update that answers the round, on whichever node, nests the
  resume (`resume: <round>`, its one-time claim `task-run:<id>/<round>`).
  Step::Wait, which only that wait used, is deleted.

Leftover live handles are settled (§1):
- Each live task is indexed under a digest of its caller with its run's
  lease (tool_tasks::Lease: taken at create, renewed with each call that
  goes out by the server's timeout plus RUN_LEASE_MS; 0 while parked on
  the caller). A task-creating call reads its caller's index and, before
  work.open, settles `cancelled` every live task no unit here runs whose
  lease lapsed or that nothing moved past the abandonment ceiling. From a
  submit, never a read or a timer.

Settles are no longer fire-and-forget:
- A settle that does not land (the create's sweep, a continuation the host
  would not nest, a failed retry nest, a cancel) leaves its task held
  unsettled; the next create's sweep settles it again until it lands. A
  landed settle strikes the task's live chunks and index row.

Finding 24: Task::deliver on a terminal task is a no-op (acknowledged,
nothing changed).

Judgment calls: work.find is scoped to the caller's principal, so a create
settles the leftover handles of its own caller only. A run's lease is the
only liveness the plane can read across processes; a run held past its
lease by another node is settled `cancelled` and that run's own settle is
then refused, as when tasks/cancel wins.

Unit tests (src/tests/tasks.rs): the live state reads back into the same
tasks/get answer; a shorter state over a longer one; the lease and the
abandonment rule; an update to a terminal task changes nothing.
…e, so the loader accepts it as a refused arrival

Spec: BUSBAR-1.6.0.md 199-201.
…d-frame lease skips the frame's rest; Frames reads a message once

Three plants, each failing on the unfixed tree by assertion (all compile against it):

- finding 5 [HIGH, SECURITY] (src/tests/tool_program.rs each_callers_ask_reaches_only_that_caller):
  two callers A and B on one stdio child, the child asks each for a sampling. The stand-in door
  keeps the child's line of relayed calls (`open`, arrival order). First-reader-wins
  (`peer.claim`) hands A's ask to B's exchange, which reads it first. Asserted: A's ask reaches
  only A, B's only B, neither is refused; an ask raised with no call in the line is refused once
  (`ask_unattributed`). Law 11 (spec 2125-2132): an ask is relayed down the session it belongs
  to, as-is.
- finding 13 [MEDIUM] (busbar-core-connector program_tests a_lease_opened_mid_frame_reads_from_the_next_frame):
  a lease opened while the program is part way through one frame reads that frame's rest as its
  first bytes. The test framer gains a `piece` knob so one frame arrives in several pieces, as the
  stdio line framer cuts a line its sink cannot hold.
- finding 14 [MEDIUM] (tests/alloc_gate.rs a_childs_message_read_in_small_pieces_is_parsed_once):
  a 2000-item message pushed in 64-byte pieces; Frames::push re-parses everything held per piece,
  so the allocation count is quadratic. Asserted: under 20 per item. The no-blocking rule (spec
  1276-1283): bounded work on the worker.
… tests stay deleted (finding 12); predev's refusal_words class table lived only in that unserved impl, so the xtask refusal-collapse scan drops its mcp row
…gotiator, through the door

tests/sessions.rs drives the MCP door over its own ABI under stand-in host services and a
stand-in connector (two upstreams: one that requires a session, one stateless) and asserts
THE DESIGN section 2 mcp bullet (docs/design/BUSBAR-1.6.0.md lines 379-390), finding 1 of the
plane-mcp audit:

- a 2025-06-18 initialize answers its revision and an Mcp-Session-Id of 128 bits; a request in
  that session is served and lowered (no stateless-only members);
- a session presented by another owner is 404 on POST and DELETE; the owner's DELETE ends it;
- a GET naming no revision opens the 2024-11-05 stream with its endpoint event, a message POSTed
  to the address is 202 and answered on the stream; a GET naming a revision, a plain GET and a
  DELETE with no session are 405;
- an upstream that refuses the stateless revision and requires initialize is reached by
  negotiation (and re-initialised when it forgets the session); a stateless upstream sees the
  stateless request exactly as the dialect builder writes it, with no handshake;
- subscribe stays for the old revisions (line 380): a 2025-06-18 session's resources/subscribe
  hears the announcing upstream's notifications/resources/updated on its GET stream.

Fails on the unfixed tree by assertion: every non-POST claim is refused 405 and initialize is
refused -32602.

src/tests/session_tests.rs plants finding 18: a push whose trim frees more than its own cost
underflows `cost - freed` (tool_sessions.rs push), a panic under overflow checks.
…oth directions; the session table's byte account never underflows

Finding 1 (plane-mcp, HIGH). THE DESIGN section 2, the mcp bullet (docs/design/BUSBAR-1.6.0.md
lines 379-390), wired on the served path through a new door child, src/door_sessions.rs:

- Inbound on the endpoint's three claims: a POST carrying the stateless marker, or naming neither
  a session nor initialize, is the stateless path untouched (adapt::classify_post); initialize
  opens a session in the revision negotiation picks (revision::negotiate; no revision config), its
  id 128 bits from the host's random.fill, bound to its owner {principal, credential} = the
  kernel's caller reference (derived from the key id) or "<ungoverned>"; any other owner, unknown,
  ended or expired id is 404 on every path (POST, GET, DELETE, the 2024-11-05 message address);
  a dispatched session method is raised (adapt::raise, with the header and parameter mirror) into
  the one dispatch and lowered after it (adapt::lower_result); an MCP-Protocol-Version that
  disagrees with the session is 400; DELETE ends the owner's session.
- GET: with a session, that session's event stream (resumed after Last-Event-ID from the table);
  with none and no MCP-Protocol-Version, the 2024-11-05 stream whose first event names the message
  address (adapt::endpoint_event), its answers delivered on the stream and its POSTs answered 202
  (revision::sessionless_get); a GET naming a revision, a GET accepting no event stream and a
  DELETE naming no session are 405 (lines 387-390). The streams are held as K6 sessions on the
  door's existing drive/tick machinery (door_listen).
- Sessions are this process's; per-owner session and byte quotas are tool_sessions::Bounds; the
  ungoverned chain's single owner isolates nothing, and the instance's first 2024-11-05 stream
  says so once as the declared diagnostic mcp-legacy-stream-ungoverned (lines 385-387).
- Subscribe stays for the old revisions (line 380, lane-lead ruling): a session's
  resources/subscribe, resources/unsubscribe and logging/setLevel are answered from its own state
  under a per-owner subscription cap; an upstream's notifications/resources/updated (on the event
  stream it answers a relayed call with, or from a stdio child) reaches every watching session's
  GET stream after the subscriber's entitlement is re-asked; its notifications/message reaches the
  caller's session past that session's level floor. initialize declares resources.subscribe and
  logging on every session revision.
- Outbound (client::negotiate on the served path): the walk's first hop is the stateless request
  byte for byte as before (the predev fence), or, to an upstream busbar holds a session with, that
  request lowered into it; a refusal moves the client ladder over the door's own connector
  (initialize, notifications/initialized, the lowered request), and a session the upstream forgot
  (404) is re-initialised once. Verify-on-call's tools/list negotiates the same way. An upstream
  that answered the stateless revision is remembered (tool_sessions::UpstreamTable) and never
  renegotiated; 401/403/407/429 are not revision signals. The ladder's last rung (the 2024-11-05
  event stream as a client) is not carried: an upstream that refuses both the stateless request and
  initialize fails the call with an upstream-failure answer naming the revision.
- The line carrier's initialize negotiates too (line.rs): a session revision a client asks for is
  answered in it and the carrier session's following lines are raised and lowered.
- The prose that claimed ONE revision is rewritten (codec.rs PROTOCOL_VERSION, checks.rs
  SUPPORTED_PROTOCOL_VERSIONS, which stays the stateless dispatch's data.supported so the stateless
  path's bytes do not move, door.rs 405 words, docs/mcp.md).

Finding 18 (LOW): tool_sessions push releases freed - cost when a trim frees more than the pushed
event cost, instead of underflowing cost - freed.

An unconfigured node claims no /mcp route, so its GET /mcp stays the 1.5.5 404.
…initialize negotiation (Era::Opened, the raised line) re-applied on L's carrier, which refuses logging/setLevel and resources/(un)subscribe with -32601 and declares neither in any revision it speaks; the subscription uri bound moves to door_sessions.rs, where the session revisions keep subscribe
…a lease reads whole frames; Frames reads each byte once

Finding 5 [HIGH, SECURITY]: a request over stdio names no call it serves (no related-request id on
the wire; the progress token is never echoed; the child numbers its own ids), so the door makes
attribution unambiguous by SERIALISING (lane-lead ruling): calls to a member whose grants let its
asks be relayed reach its child one at a time, in arrival order (door_program `Relaying` line,
`in_line`); a call behind waits (Step::Wait, woken when the call ahead leaves, or at its own
`timeout:` deadline, then answered as an upstream failure, never sent: `take_turn`). A call whose
asks went to its caller holds its place until its retry takes it up or the ask's state TTL lapses
(`ProgramRelay::hold`). The ask is the call's first in line (`first_in_line`, `Peer::owner`,
decided once by the first exchange to read it); an ask raised with no call in line is refused
once (`-32001` `ask_unattributed`). Law 11, spec 2125-2132.

Finding 13: busbar-core-connector program.rs: a lease opened mid-frame skips that frame's rest.
Finding 14: tool_program.rs Frames scans only new bytes and parses a value once, when whole
(spec 1276, 1283).
…pfix-tasks: the relayed task leg opens the retry's state from this branch's state argument and keeps ask's rule that a clock that cannot be read opens nothing
@MattJackson

Copy link
Copy Markdown
Collaborator Author

Merged up with #616 (ask) and #615 (sampling), which sit ahead of this PR in the predev merge queue and touch the same files (call.rs, purity.rs, door_tasks.rs), so this PR stays clean when they land. Resolutions: call.rs's settle doc says both an ask and a result are relayed; purity.rs keeps both source scans; the relayed task leg opens the retry's state and keeps ask's rule that an unreadable clock opens nothing.

Proof of the combined tree: Latchkey cli-af296ba4-4bea-4bc7-8d9b-22c41bf0b838 (every mcpfix group plus ask and sampling; identical on all touched paths to the bounds head): RED on 6d297d1 failed 3 of 3 by assertion; GREEN-EXIT=0 for fmt --check, clippy -p busbar-kernel -p busbar-llm -p busbar-plane-mcp --all-targets -D warnings, cargo test -p busbar-kernel / busbar-llm / busbar-plane-mcp, cargo build -p busbar --bin busbar, busbar plane_host_universal_purity and plane_node.

…e's bound session now expects the session revision its initialize asked for (2025-06-18, revision by negotiation, the sessions group), and the kind-isolation-ship selftest plants its short-circuit step in busbar-plane-a2a, which keeps a legacy Plane face (the mcp plane is a door plane only since finding 12)
@MattJackson MattJackson changed the title plane-mcp: bound an upstream answer, the uri dedupe, the refused unit and the per-owner subscription quota; a full unit table refuses instead of evicting (findings 7, 8, 9, 15) mcp: the MCP-FIX stack (plane-mcp findings 1-18, 24): passthrough, dest.judge, dead plane, line carrier, sessions, stdio, tasks, bounds Oct 8, 2026
@MattJackson
MattJackson marked this pull request as draft October 8, 2026 03:30
auto-merge was automatically disabled October 8, 2026 03:30

Pull request was converted to draft

@MattJackson

Copy link
Copy Markdown
Collaborator Author

Back to draft automatically: this branch contains #637 (lane-mcpfix-line), which is also ready. Two hops on the same code is duplicate spend (owner rule 2026-10-08). Mark this ready again after #637 merges.

@MattJackson

Copy link
Copy Markdown
Collaborator Author

Back to draft automatically: this branch contains #616 (lane-mcpfix-ask), which is also ready. Two hops on the same code is duplicate spend (owner rule 2026-10-08). Mark this ready again after #616 merges.

…ard and the door-plane conformance tests (predev's range predicate and old-plane tests are superseded here)
@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

promote into predev: DENY @a5e2f69ea: 0 failing test row(s), 11 DENY row(s)

Merge queue group e93a44457 (first in its group, so this PR's own red): it re-enters only with a new head.

DENY rows (11)

gate row detail
construction one-pick-site 3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8
kind-isolation kind-isolation:deps 3 finding(s), 93 shipped edge instance(s) over 30 class(es), 93 declaration(s); 56 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w
kind-isolation kind-isolation:test-deps 3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge
kind-isolation kind-isolation:law0 19 hit(s) off the [[law0]] ceilings, 9 finding(s) over 14 neutral crate(s): law0-rise busbar × auth 53 hit(s) against a ceiling of 51: this landing grew a neutral crate's instance vocabulary. Ceilings
kind-isolation-ship kind-isolation:deps 10 finding(s) over 93 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a
kind-isolation-ship kind-isolation:test-deps 10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship
kind-isolation-ship kind-isolation:law0 19 hit(s) off the [[law0]] ceilings, 9 finding(s) over 14 neutral crate(s): law0-rise busbar × auth 53 hit(s) against a ceiling of 51: this landing grew a neutral crate's instance vocabulary. Ceilings
kind-isolation-ship kind-isolation:faces 2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is
kind-isolation-ship kind-isolation:legacy-drain 3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier)
ship-ready ship-ready:ship-twin 'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is
structure-lint structure-lint:plane-dup:unledgered 22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger
Denied because (2)
  • shard 1/4: gate:kind-isolation row kind-isolation:law0: figure rose 16 -> 19
  • shard 1/4: gate:kind-isolation-ship row kind-isolation:law0: figure rose 16 -> 19

Judged against base 88ab406e1: 0 new red, 2 worse, 3 standing (excused).

Reused PASS by input key (1, 1 min not re-run)
step key produced by
build:deletion-matrix a4d42cfd340a56c6 476154864

tests passed: 24267, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/38058349590 . Artifact verdict-e93a44457fc4b97bcf5fa11216cb9b6acacda59f (failures.json, junit.xml, raw.log; 90 days).

…nce witness, rename the new cross-plane names

- linked-dropped-features:unified-deps (and its selftest): the `raw_value` feature busbar-plane-mcp
  switched on unified onto every plugin linking serde_json. `relayed` now locates the upstream's
  `result` bytes with the contract's span scanner (busbar_contract::spans::resolve_pointer) instead
  of a RawValue, and the feature is gone.
- kind-isolation(-ship):closure and :test-deps: tests/bounds.rs named busbar_plugin_loader, so the
  conformance-witness grant (the loader named by tests/conformance.rs alone) no longer held. The
  bounds battery moves into tests/conformance.rs as `mod bounds`, unchanged.
- kind-isolation(-ship):law0 (busbar-core-connector x transport 69 > 68): the new mid-frame test's
  doc named a transport instance; reworded.
- structure-lint:plane-dup:unledgered 27 -> 22: the five names this branch added to the mcp plane
  that other planes also declare are renamed: door_sessions `Arrived` -> `Inbound`, `table` ->
  `slots`, `error_body` -> `error_json`; tool_tasks `Lease` -> `TaskLease`; door_tasks `list` ->
  `list_records`.

Proved on Latchkey: gate kind-isolation and kind-isolation-ship (closure PASS, law0 18, test-deps
at base), gate linked-dropped-features PASS, gate structure-lint (plane-dup:unledgered 22, no other
row red), selftest linked-dropped-features PASS, cargo test -p busbar-plane-mcp bounds / relayed
PASS. xtask selftest_runs_every_registered_gates_red_proof no longer fails on
linked-dropped-features; on the Latchkey dev checkout it still reports construction, plane-purity
and config-schema unproven, each because that shallow checkout lacks git history (tags v1.5.3 /
v1.5.5 and a pinned commit do not resolve), which CI's full checkout has.
@MattJackson

Copy link
Copy Markdown
Collaborator Author

Closed: duplicate of #703 (the same MCP-FIX stack, landed from this draft as a clean carrier). Branch kept.

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a manual request Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant