diff --git a/qa/kind-isolation.toml b/qa/kind-isolation.toml index df555e2738..a92c5e0d83 100644 --- a/qa/kind-isolation.toml +++ b/qa/kind-isolation.toml @@ -1554,15 +1554,18 @@ drain = "none: BUSBAR-1.6.0.md grants this class. What this row holds is the N # Every core-neutral crate (BUSBAR-1.6.0.md:1994-1999: the kernel and its workflow crates, the # contract, the loader, the cleanliness crates, the composition root) names ZERO plugin-instance # vocabulary at DEV-GREEN. `kind-isolation:law0` holds each crate and axis to the count below, -# measured on predev f830faa691, re-armed at 41f2dc1f78 for the five cells predev grew meanwhile: a rise or a new cell is RED on both twins, a fall must lower the -# row in the same commit. scripts/verify-1.6.0-done.sh reads these rows: DONE is every count at 0. -# Sum today: 4463 hit(s) over 62 cell(s). +# measured on predev f830faa691, re-armed at 41f2dc1f78 for the five cells predev grew meanwhile, and +# re-armed again at 9c0a394771 to the measure of dc83ff1553, the SHA the row went live on (#597): it had armed +# RED, 18 findings, because the ceilings were nine hours older than the arming. Three cells grew after +# arming and are held at the arming measure, RED until drained. A rise or a new cell is RED on both +# twins, a fall must lower the row in the same commit. scripts/verify-1.6.0-done.sh reads these rows: DONE is every count at 0. +# Sum today: 4487 hit(s) over 60 cell(s). [[law0]] crate = "busbar" axis = "auth" -count = "46" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance. +4 for status row 120 (owner task): root/tests/connector.rs `the_pinned_mint_needs_are_operator_infrastructure` reads the pinned plugin's NEEDS by its crate path and its doc names the divergent pins, 2 hits each (package name + kind-qualified id); test-only, over the granted root -> auth dev edge" +count = "51" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance. +4 for status row 120 (owner task): root/tests/connector.rs `the_pinned_mint_needs_are_operator_infrastructure` reads the pinned plugin's NEEDS by its crate path and its doc names the divergent pins, 2 hits each (package name + kind-qualified id); test-only, over the granted root -> auth dev edge; RE-ARMED 46 -> 51 (Law 9, BUSBAR-1.6.0.md: it pins its ceiling at TODAY'S MEASURED VALUE): the row went live on predev at dc83ff1553 (#597) and measured 49 there; the 46 was f830faa691's, nine hours older than the arming, so the row armed red. 51 is predev 9c0a394771's measure, at or under the arming value (arming measure 49, plus status row 120 (#704, owner task) at its measured +2 of the +4 its cite approved)" [[law0]] crate = "busbar" @@ -1579,8 +1582,8 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar" axis = "instance:auth" -count = "22" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "24" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; RE-ARMED 22 -> 24 (Law 9, BUSBAR-1.6.0.md: it pins its ceiling at TODAY'S MEASURED VALUE): the row went live on predev at dc83ff1553 (#597) and measured 24 there; the 22 was f830faa691's, nine hours older than the arming, so the row armed red. 24 is predev 9c0a394771's measure, at or under the arming value" [[law0]] crate = "busbar" @@ -1591,8 +1594,8 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar" axis = "instance:secret" -count = "34" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "35" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; RE-ARMED 34 -> 35, the measure at the arming SHA dc83ff1553 (#597; Law 9). Predev 9c0a394771 measures 36: #560 (7b5f5d8be4) grew it after the row was live, invisible to a figure that counted findings. That excess is a Law 0 rise, so it stays RED until drained; this row does not raise to cover it" [[law0]] crate = "busbar" @@ -1603,8 +1606,8 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar" axis = "plane" -count = "798" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "822" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; RE-ARMED 798 -> 822 (Law 9, BUSBAR-1.6.0.md: it pins its ceiling at TODAY'S MEASURED VALUE): the row went live on predev at dc83ff1553 (#597) and measured 826 there; the 798 was f830faa691's, nine hours older than the arming, so the row armed red. 822 is predev 9c0a394771's measure, at or under the arming value" [[law0]] crate = "busbar" @@ -1615,20 +1618,20 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar" axis = "transport" -count = "215" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "208" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; LOWERED 215 -> 208, predev 9c0a394771's measure: the drain landed without giving its row back (Law 9: the ceiling ratchets down)" [[law0]] crate = "busbar" axis = "vendor" -count = "43" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "89" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; RE-ARMED 43 -> 89, the measure at the arming SHA dc83ff1553 (#597; Law 9). Predev 9c0a394771 measures 90: #663 (522ab201d5) grew it after the row was live, invisible to a figure that counted findings. That excess is a Law 0 rise, so it stays RED until drained; this row does not raise to cover it" [[law0]] crate = "busbar-contract" axis = "auth" -count = "4" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "6" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; RE-ARMED 4 -> 6 (Law 9, BUSBAR-1.6.0.md: it pins its ceiling at TODAY'S MEASURED VALUE): the row went live on predev at dc83ff1553 (#597) and measured 6 there; the 4 was f830faa691's, nine hours older than the arming, so the row armed red. 6 is predev 9c0a394771's measure, at or under the arming value" [[law0]] crate = "busbar-contract" @@ -1645,14 +1648,14 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar-contract" axis = "instance:export" -count = "14" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "15" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; RE-ARMED 14 -> 15 (Law 9, BUSBAR-1.6.0.md: it pins its ceiling at TODAY'S MEASURED VALUE): the row went live on predev at dc83ff1553 (#597) and measured 15 there; the 14 was f830faa691's, nine hours older than the arming, so the row armed red. 15 is predev 9c0a394771's measure, at or under the arming value" [[law0]] crate = "busbar-contract" axis = "instance:secret" -count = "128" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "133" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; RE-ARMED 128 -> 133 (Law 9, BUSBAR-1.6.0.md: it pins its ceiling at TODAY'S MEASURED VALUE): the row went live on predev at dc83ff1553 (#597) and measured 133 there; the 128 was f830faa691's, nine hours older than the arming, so the row armed red. 133 is predev 9c0a394771's measure, at or under the arming value" [[law0]] crate = "busbar-contract" @@ -1759,8 +1762,8 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar-kernel" axis = "auth" -count = "76" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "61" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; LOWERED 76 -> 61, predev 9c0a394771's measure: the drain landed without giving its row back (Law 9: the ceiling ratchets down)" [[law0]] crate = "busbar-kernel" @@ -1777,8 +1780,8 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar-kernel" axis = "instance:auth" -count = "11" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "8" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; LOWERED 11 -> 8, predev 9c0a394771's measure: the drain landed without giving its row back (Law 9: the ceiling ratchets down)" [[law0]] crate = "busbar-kernel" @@ -1801,8 +1804,8 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar-kernel" axis = "plane" -count = "1193" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "1175" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; LOWERED 1193 -> 1175, predev 9c0a394771's measure: the drain landed without giving its row back (Law 9: the ceiling ratchets down)" [[law0]] crate = "busbar-kernel" @@ -1819,8 +1822,8 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar-kernel" axis = "transport" -count = "288" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "286" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; LOWERED 288 -> 286, predev 9c0a394771's measure: the drain landed without giving its row back (Law 9: the ceiling ratchets down)" [[law0]] crate = "busbar-kernel-breaker" @@ -1852,18 +1855,6 @@ axis = "transport" count = "2" cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" -[[law0]] -crate = "busbar-kernel-identity" -axis = "auth" -count = "8" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" - -[[law0]] -crate = "busbar-kernel-identity" -axis = "instance:secret" -count = "2" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" - [[law0]] crate = "busbar-kernel-ledger" axis = "plane" @@ -1891,8 +1882,8 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar-plugin-loader" axis = "export" -count = "31" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "32" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; RE-ARMED 31 -> 32 (Law 9, BUSBAR-1.6.0.md: it pins its ceiling at TODAY'S MEASURED VALUE): the row went live on predev at dc83ff1553 (#597) and measured 32 there; the 31 was f830faa691's, nine hours older than the arming, so the row armed red. 32 is predev 9c0a394771's measure, at or under the arming value" [[law0]] crate = "busbar-plugin-loader" @@ -1915,8 +1906,8 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar-plugin-loader" axis = "plane" -count = "53" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "47" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; LOWERED 53 -> 47, predev 9c0a394771's measure: the drain landed without giving its row back (Law 9: the ceiling ratchets down)" [[law0]] crate = "busbar-plugin-loader" @@ -1927,5 +1918,6 @@ cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain [[law0]] crate = "busbar-plugin-loader" axis = "transport" -count = "185" -cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance" +count = "186" +cite = "measured on predev f830faa691 (ARCHITECT 2026-10-07, Law 9); the drain is THE DESIGN §1 / DoD item 2: core names no instance; RE-ARMED 185 -> 186, the measure at the arming SHA dc83ff1553 (#597; Law 9). Predev 9c0a394771 measures 190: #672 (757c6bab99) grew it after the row was live, invisible to a figure that counted findings. That excess is a Law 0 rise, so it stays RED until drained; this row does not raise to cover it" + diff --git a/xtask/src/gates/kind_isolation/matrix.rs b/xtask/src/gates/kind_isolation/matrix.rs index bfb2597ac3..ea424c082d 100644 --- a/xtask/src/gates/kind_isolation/matrix.rs +++ b/xtask/src/gates/kind_isolation/matrix.rs @@ -2603,11 +2603,14 @@ pub fn rule_law0( let reg = ®istry.law0; let mut ceilings: BTreeMap<(String, String), usize> = BTreeMap::new(); let mut offenders: Vec = Vec::new(); + // THE ROW'S FIGURE: hits off the ledger, summed over every finding (see [`law0_off`]). + let mut off = 0usize; for r in reg { if ceilings .insert((r.krate.clone(), r.axis.clone()), r.count) .is_some() { + off += 1; offenders.push(format!( "law0-duplicate\t{} / {}\ttwo `[[law0]]` rows for one crate and axis", r.krate, r.axis @@ -2619,6 +2622,7 @@ pub fn rule_law0( for key in &keys { let now = measured.get(key).copied().unwrap_or(0); let ceiling = ceilings.get(key).copied(); + off += law0_off(now, ceiling); match ceiling { None if now > 0 => offenders.push(format!( "law0-new\t{} \u{d7} {}\t{now} hit(s) in a NEUTRAL crate with no `[[law0]]` \ @@ -2660,7 +2664,7 @@ pub fn rule_law0( ROW_LAW0, "a neutral crate's Law 0 count is not its ceiling", format!( - "{} finding(s) over {} neutral crate(s): {}", + "{off} hit(s) off the [[law0]] ceilings, {} finding(s) over {} neutral crate(s): {}", offenders.len(), neutral.len(), offenders.join(" | ") @@ -2668,6 +2672,25 @@ pub fn rule_law0( ) } +/// How far one cell sits from its `[[law0]]` row, in HITS: above it (a rise), below it (slack the +/// ledger owes back), or the whole count when no row exists (a new leak). The FAIL row's detail +/// opens with the sum of these, and that leading number is the figure a base-relative verdict +/// compares (busbar-release `baseline::figure`). +/// +/// It was the FINDING COUNT, and a count of cells cannot see a cell grow: once a cell was off its +/// row, every further hit in it left the figure where it was. The row was armed red on predev +/// (dc83ff1553, #597: 18 findings), and four landings grew cells that were already off their rows +/// (#560 `busbar × instance:secret` 35 -> 36, #663 `busbar × vendor` 89 -> 90, #672 +/// `busbar-plugin-loader × transport` 186 -> 190) with the figure flat at 18, while a branch that +/// drained ONE at-ceiling cell read as 18 -> 19. Law 9 refuses every rise "from that moment"; a +/// figure in hits is the one that can. +fn law0_off(now: usize, ceiling: Option) -> usize { + match ceiling { + Some(c) => now.abs_diff(c), + None => now, + } +} + /// THE MATRIX ROW, AS THE GATE EMITS IT: a measured to-do list, not a gate (owner 2026-10-03). /// /// The row is measured on every run and its number is in the row's detail, but it never fails: a @@ -4590,6 +4613,155 @@ pub fn selftest<'a>( mod tests { use super::*; + fn neutral_kernel(name: &str) -> CrateInfo { + CrateInfo { + dir: format!("crates/{name}"), + manifest: format!("crates/{name}/Cargo.toml"), + name: name.to_string(), + kind: Some("kernel"), + family: Family::Neutral, + remainder: Vec::new(), + instance: None, + declared_keys: Vec::new(), + deps: Vec::new(), + dev_deps: Vec::new(), + ambiguous: Vec::new(), + pinned: None, + } + } + + fn law0_reg(rows: &[(&str, &str, usize)]) -> super::super::KindRegistry { + let mut reg = super::super::KindRegistry::default(); + for (krate, axis, count) in rows { + reg.law0.push(super::super::Law0Ceiling { + krate: (*krate).to_string(), + axis: (*axis).to_string(), + count: *count, + cite: "planted".to_string(), + }); + } + reg + } + + fn law0_counts_of(cells: &[(&str, &str, usize)]) -> Law0Counts { + cells + .iter() + .map(|(k, a, n)| (((*k).to_string(), (*a).to_string()), *n)) + .collect() + } + + /// The number a base-relative verdict reads off a FAIL row: the detail's leading count + /// (busbar-release `baseline::figure`; this detail carries no `(ceiling` marker). + fn figure_of(row: &Row) -> usize { + assert!( + !row.detail.contains("(ceiling"), + "a `(ceiling` marker would move the figure off the leading count: {}", + row.detail + ); + row.detail + .split_whitespace() + .next() + .and_then(|t| t.parse().ok()) + .unwrap_or_else(|| panic!("no leading figure in {}", row.detail)) + } + + /// THE LAW 0 FIGURE SEES A CELL GROW. RED with the figure as the finding count: a cell already + /// above its row that grows by one hit, and an at-ceiling cell drained to slack, both left the + /// count where a standing red put it (the four PRs that grew `busbar` and the loader with the + /// figure flat at 18; `busbar-kernel-wal × instance:secret` 1 -> 0 read as 18 -> 19 only + /// because it was a fresh cell). In hits, every move off the ledger raises the figure and + /// every move back lowers it. + #[test] + fn the_law0_figure_counts_hits_off_the_ledger_not_findings() { + let crates = vec![neutral_kernel("busbar-kernel")]; + let reg = law0_reg(&[ + ("busbar-kernel", "plane", 10), + ("busbar-kernel", "transport", 5), + ("busbar-kernel", "auth", 3), + ]); + let at = + |cells: &[(&str, &str, usize)]| rule_law0(&crates, ®, Some(&law0_counts_of(cells))); + + // The base: `plane` is 2 over its row, `transport` 1 under it, `auth` at it. + let base = at(&[ + ("busbar-kernel", "plane", 12), + ("busbar-kernel", "transport", 4), + ("busbar-kernel", "auth", 3), + ]); + assert_eq!(base.status, crate::ledger::Status::Fail); + assert_eq!(figure_of(&base), 3, "{}", base.detail); + + // A cell ALREADY over its row grows by one hit: same two findings, the figure rises. + let grown = at(&[ + ("busbar-kernel", "plane", 13), + ("busbar-kernel", "transport", 4), + ("busbar-kernel", "auth", 3), + ]); + assert_eq!(grown.detail.matches("law0-").count(), 2, "{}", grown.detail); + assert!( + figure_of(&grown) > figure_of(&base), + "a rise inside a cell already over its row must raise the figure: {} -> {}", + figure_of(&base), + figure_of(&grown) + ); + + // A new leak with no row counts its whole measure. + let leaked = at(&[ + ("busbar-kernel", "plane", 12), + ("busbar-kernel", "transport", 4), + ("busbar-kernel", "auth", 3), + ("busbar-kernel", "export", 2), + ]); + assert_eq!( + figure_of(&leaked), + figure_of(&base) + 2, + "{}", + leaked.detail + ); + + // A drain the ledger has not given back is slack: off the row, so the figure rises by the + // hits drained, and the row lowered to the measure takes them back out. + let drained = at(&[ + ("busbar-kernel", "plane", 12), + ("busbar-kernel", "transport", 4), + ("busbar-kernel", "auth", 1), + ]); + assert_eq!( + figure_of(&drained), + figure_of(&base) + 2, + "{}", + drained.detail + ); + let given_back = law0_reg(&[ + ("busbar-kernel", "plane", 10), + ("busbar-kernel", "transport", 5), + ("busbar-kernel", "auth", 1), + ]); + let lowered = rule_law0( + &crates, + &given_back, + Some(&law0_counts_of(&[ + ("busbar-kernel", "plane", 12), + ("busbar-kernel", "transport", 4), + ("busbar-kernel", "auth", 1), + ])), + ); + assert_eq!(figure_of(&lowered), figure_of(&base), "{}", lowered.detail); + + // Every cell at its row is the PASS row. + let clean = at(&[ + ("busbar-kernel", "plane", 10), + ("busbar-kernel", "transport", 5), + ("busbar-kernel", "auth", 3), + ]); + assert_eq!( + clean.status, + crate::ledger::Status::Pass, + "{}", + clean.detail + ); + } + #[test] fn a_nested_name_scores_once() { let plan = plan_of(&[