Repository navigation
kind-isolation:law0: the figure is hits off the ceilings; the ledger re-arms at the SHA the row went live on - #725
Conversation
…d the ledger re-arms at the SHA the row went live on The row armed RED on predev at dc83ff1 (#597, 18 findings): its ceilings were measured at f830faa, nine hours before it landed. Its figure was the finding COUNT, so with 18 standing findings a cell already off its row could grow without moving it (#560 busbar x instance:secret 35 -> 36, #663 busbar x vendor 89 -> 90, #672 busbar-plugin-loader x transport 186 -> 190), and any branch that moved one at-ceiling cell read as 18 -> 19 on both twins. The FAIL detail now opens with the hits off the ledger (|now - ceiling| summed, a new leak's whole count), the number a base-relative verdict compares. The seven cells that sat above their row at the arming SHA are re-armed to predev's measure, at or under the arming measure (Law 9: the ceiling is today's measured value on the day the instrument arms); the eight slack cells are lowered to predev's measure; the three cells grown after arming are held at the arming measure and stay RED until drained.
|
Architect ruling: the 7 ceiling raises are Law 9 (BUSBAR-1.6.0.md l.2077: a newly-armed instrument pins its ceiling at TODAY'S MEASURED VALUE): the row was armed at dc83ff1 with ceilings measured 9h earlier at f830faa, so the arming-day measure is the ceiling. Each raised cell is set at or under its arming measure; busbar x auth carries the owner-signed +4 for row 120 (#704). The three cells that grew after arming (#560 #663 #672) stay held at the arming value. Approved as is. |
promote into
|
| gate | row | detail |
|---|---|---|
| construction | one-pick-site |
3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8 |
| kind-isolation | kind-isolation:deps |
3 finding(s), 94 shipped edge instance(s) over 31 class(es), 94 declaration(s); 57 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w |
| kind-isolation | kind-isolation:test-deps |
3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge |
| kind-isolation | kind-isolation:law0 |
6 hit(s) off the [[law0]] ceilings, 3 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 36 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabulary |
| kind-isolation-ship | kind-isolation:deps |
11 finding(s) over 94 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a |
| kind-isolation-ship | kind-isolation:test-deps |
10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship |
| kind-isolation-ship | kind-isolation:law0 |
6 hit(s) off the [[law0]] ceilings, 3 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 36 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabulary |
| kind-isolation-ship | kind-isolation:faces |
2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is |
| kind-isolation-ship | kind-isolation:legacy-drain |
3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier) |
| ship-ready | ship-ready:ship-twin |
'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is |
| structure-lint | structure-lint:plane-dup:unledgered |
22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger |
Judged against base 6ca8584fc: 0 new red, 0 worse, 5 standing (excused).
Reused PASS by input key (1, 0 min not re-run)
| step | key | produced by |
|---|---|---|
| build:deletion-matrix | 1f23d41a5acd2eca |
6ca8584fc |
tests passed: 24139, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/38028951060 . Artifact verdict-457b90e77e6ab2b0d46504b314802f82f019d4ab (failures.json, junit.xml, raw.log; 90 days).
Deleting the kernel's dead ask-state seal (K2-H3) drains four plane hits from busbar-kernel: the two crate::mcp::roots doc links and the two \x6dcp seal domains (the decoded scanner reads them as mcp). The re-armed ledger (#725) pinned the row at predev's 1175, so the drain read as 4 hits of law0 slack (figure 29 -> 33 on kind-isolation and kind-isolation-ship). Not proved on Latchkey: the run budget is spent (RUN_CAP); reasoned from the CI verdict and the deleted source, and the PR's CI is the proof.
…sured; law0 ledger left at predev - crates/busbar/src/root/tests/door_steps.rs: the forwarding HostServices double's work_settle lacked predev's `unit: Option<u64>`, which broke every build/clippy/test row (E0050/E0061). - xtask population FLOOR 941 -> 940 and tracing SCAN_FLOOR 971 -> 970: this landing retires the plane-mcp legacy tool plane (tool_plane.rs and outputschema.rs out, door_sessions.rs in), a reviewed removal of one non-test file from both walks. Both floors were pinned at predev's exact count, so blocking-ffi, response-header, settings-leak and tracing (and their selftests) refused the tree as below floor. seal_witness was already re-armed for the same removal on this branch. - qa/kind-isolation.toml back to predev's bytes: lowering the busbar x transport [[law0]] row (208 -> 207) armed kind-isolation:law0, which is red on predev by design (#725) over cells this branch does not touch (busbar x instance:secret/plane/vendor, busbar-plugin-loader x transport rises, busbar-kernel x plane slack). Without the edit the row's figure stays at its base value and the one-hit drain shows as law0-slack, to be given back once the row can be armed; law0-base still refuses any grown cell. Not run on Latchkey: the dev run budget (RUN_CAP) is spent; reasoned from the failing CI output, and the PR's CI is the proof.
The shared red:
gate:kind-isolation row kind-isolation:law0: figure rose 18 -> 19Root cause (measured).
kind-isolation:law0landed on predev at dc83ff1 (#597) already RED with 18 findings: its[[law0]]ceilings were measured at f830faa, nine hours before it landed. The turnstile let it through because the candidate changed the gate's code and table, so the base was re-measured with the candidate's code against the base's ledger, which had no[[law0]]rows: 60law0-newfindings at base, 18 at the candidate, scored as "figure fell". Every predev landing since then measures exactly 18 (checked against all 73 queue landings from dc83ff1 to 9c0a394).The row's figure was the FINDING COUNT. With 18 standing findings:
busbar x instance:secret35 -> 36), row 134: the single-process declared_credentials flake (header=api-keyapi-key) is a shared auth-instance envelope; busbar-auth-header keeps it per thread #663 (busbar x vendor89 -> 90) and fleet sans-IO: drivers are tests-only and net-banned; store SDK Wire::close and the host identity #672 (busbar-plugin-loader x transport186 -> 190) all landed with the figure flat at 18;busbar-kernel-wal x instance:secret1 -> 0 slack, plugin-loader conformance suite: Statement-mismatch, wrong-kind (every kind), undeclared-need and cross-instance connection RED arms #611busbar-plugin-loader x instance:secret111 -> 113, mcp tasks: the task store is host records; leftover live handles are settled; an owed settle is made again until it lands (plane-mcp findings 6, 24) #660/mcp: the MCP-FIX stack (plane-mcp findings 1-18, 24): passthrough, dest.judge, dead plane, line carrier, sessions, stdio, tasks, bounds #673/mcp: the MCP-FIX stack (plane-mcp findings 1-18, 24) #703busbar-core-connector x transport68 -> 69), but nothing in the deny line says which cell is theirs.This change.
rule_law0: the FAIL detail now opens with the hits off the ledger (sum of |now - ceiling|, and a new leak's whole count). That is the leading number busbar-releasebaseline::figurecompares, so a rise inside a cell that is already off its row raises the figure. Test:the_law0_figure_counts_hits_off_the_ledger_not_findings. Its RED arm is the old count detail, where the grown cell leaves the figure at 2 -> 2.qa/kind-isolation.toml[[law0]]re-armed per Law 9 (BUSBAR-1.6.0.md: an instrument "pins its ceiling at TODAY'S MEASURED VALUE and refuses every rise from that moment"; the day the instrument armed is dc83ff1):After this change predev's law0 row carries 3 findings, 6 hits off, and each finding is named in its cite. A branch that has merged predev sees only its own cells.