Repository navigation
ledger views and verify refuse per balance: a refused counts row withholds its own row, never the read (M10; on H3) - #688
MattJackson wants to merge 18 commits into
Conversation
…nd the shipping seam move The shipping seam the store adapter implements and the log ships through moves into busbar_contract::ship: Shipper<R> and ShipError, over ShippedRecord (a record's identity alone). The log's Record and its framing stay in busbar-kernel-wal; Record implements ShippedRecord, and the log's own shippers and boxes name Shipper<Record>. durable.rs and its tests move unchanged from busbar-kernel-wal (which never used it) into busbar-plugin-loader, host-only machinery no plugin image links, so its temp-name counter stays one per process. busbar-kernel re-exports it from the loader, so every crate::durable / busbar_kernel::durable call site is unchanged, and the root's keyset names busbar_kernel::durable (the root names the loader only in root/loader.rs). The structure-lint choke-point owner and class test follow the file. crates/plugin-loader/Cargo.toml now names no busbar-kernel-* crate (Part 2 #33: plugin infrastructure is one crate atop the one contract crate). The dead busbar-plugin-loader -> busbar-kernel-wal [[dep]] row is struck, and both kind-isolation gates gain a RED plant that grows a loader -> busbar-kernel-ledger edge back: the per-push gate refuses it as unlisted-dep-edge, the ship twin as a tcb ship-edge.
…edge # Conflicts: # Cargo.lock
…red store and resumes it at boot The root's journal now writes each record through the configured store's v3 record_put slot under the journal schema, keyed (node, node_seq, part) big-endian so record_scan returns chain order, on a host-owned bounded write-behind lane that never calls the store under the book's lock. With no data directory the boot reads the chain back (record_scan) and resumes it (Journal::memory_resumed), and the dated rate-card history, the amendment journal and the older audit window rebuild whenever the chain has a durable source (keeps_chain), not only on a disk. A refused record stays at the head of the lane and is re-offered; a full lane turns the journal's batch away (the log retains it) and the node fails closed: a new money-bearing unit answers 503 with the reason, and the journal keeps every record at its bound (retaining_at_bound). amend_rate_history and commit_upgrade answer 200 only once the store acknowledged their record, 503 with the reason otherwise. A configured store with no record slots refuses the boot by name. The store adapter's shipping shim (acknowledged every batch, kept a count) and the stale STORE_ABI_WITH_NEW_OPS constant are removed, with the prose that described them. ARCHITECT 2026-10-07 H3 ruling (a)-(e); BUSBAR-1.6.0.md THE DESIGN §7, §11.2, §11.11 R4; Appendix B Q-STORE = (B).
…he configured store With no data directory the deployment keyset is minted once into the store's record slots (busbar.keyset.v1), read back on every boot and by every node on that store, and its fingerprint is sealed in a Bootstrap record on each chain; a chain whose Bootstrap the store cannot yield refuses the boot. With a data directory the store supplies the key a first boot adopts, and a minted key is kept there too. A resumed chain now verifies under the key the boot holds. Each node takes a stable id from the store's node registry (busbar.node.v1, keyed by host name), minted on the host's first boot and read back on every later one; journal records are keyed by it instead of 0, so two nodes on one store never overwrite each other. A data directory's chain keeps the identity it was written under (Journal::in_directory_adopting). There is no node_id config key: adding one changes the frozen config-schema snapshot. /admin/verify walks every chain the store keeps (every registered node and this one), verifying each journal chain and its audit records, signatures included, against the deployment keyset. ARCHITECT 2026-10-07 H3 ruling, follow-up (1)-(2).
…holds its own row, never the read One refused counts row (#42) used to fail GET /admin/ledger/totals, /admin/ledger/reconciliation and /admin/verify whole (Store, 503). A refused row is rebuilt from the chain at every boot and an undeclared refusal stays refused through any card, so that hid every other row and every other verify finding for the life of the journal (audit root-R1 #10). The refusal is now per balance and window. LedgerView::refused_balances (off Durability::refused_balances, the same RefusedCounts Durability::settled_read refuses with) names each balance with no figure: its window, the lane that served the unit, and the refusal. The totals and reconciliation views withhold the bucket-day row such a balance folds into (the priced remainder would be the silent zero #42 forbids) and name it under a new `refused` list; every other row is served, and reconciliation's `holds` is false while any row is withheld. GET /admin/verify reports each as a `refused counts:` finding and still runs and reports every other check (§7: the integrity verifiers are wired into the verify surface). Each read asks for the refusals after it reads its rows, so the race can only withhold a row, never serve a short one. The two response types gain `refused` (LedgerRefusedBalance) in the typed contract and the committed openapi.json; both routes are 1.6.0-additive (the 1.5.5 recording is the router's 404), so no 1.5.5-pinned body moves. The 503 descriptions now name only the out-of-range figure refusal that remains, and the admin-bodies note for GetLedgerTotals says what the row does.
…he store's single-use claim first The store ABI has no compare-and-set, so two first boots racing on an empty store could each keep their own keyset (two signing keys for one deployment) or their own node id for one host (two chains for one host). Its one atomic step is redeem_plane_token, a single-use test-and-set; minting now redeems a claim on it first, as oauth_as's store does (ARCHITECT 2026-10-07 H3 ruling). - keep_keyset: the boot the store answers first on `keyset:deployment` mints and keeps; every other boot waits for the winner's write and takes it, and refuses if nothing was kept in time. - node_id: one minter per host (`host:<name>`), and each minted id is claimed for good (`node-id:<id>`) before it is kept, so no two hosts hold one id. - A minting claim lapses after 120 s, so a winner that died before it kept anything strands the store for at most that long; a later boot claims again. Known limit, documented in store_identity: a host whose name changes on every restart mints a new id each boot, and its predecessor's chain is walked and verified but its open holds are not recovered. RED: a_first_boot_that_lost_the_keyset_claim_takes_the_winners_key, a_lost_keyset_claim_with_nothing_kept_refuses_until_the_claim_lapses, a_first_boot_that_lost_the_host_claim_takes_the_winners_node_id, every_minted_node_id_is_held_by_its_claim (each fails with the claim answered without redeeming).
…28-h3-journal-store
# Conflicts: # crates/busbar-core-admin/src/v1/json/openapi.json.gz
…e recovery-verb cell's memory governance carries the record slots H3's boot book keeps its journal in
… pass, so a boot crossing a second boundary never finds it lapsed early
…n cannot push it out (a store may re-stamp a token's expiry on every redemption)
Pull request was converted to draft
promote into
|
| crate | test | step | first panic |
|---|---|---|---|
| `` | nextest xtask::cli::selftest_runs_every_registered_gates_red_proof |
test:workspace | |
| `` | nextest busbar-kernel::root_key_spelling::no_production_source_spells_a_kind_s_root_key_beyond_its_armed_count |
test:workspace | |
| `` | xtask selftest abi-location |
test:xtask-selftest | |
busbar |
compile error |
build:workspace-compile | did not compile, with no rustc error in the output: busbar (bin "busbar") (2 error(s)) |
| `` | check rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
build:workspace-compile | |
| `` | check rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
build:workspace-compile | |
root_key_spelling |
no_production_source_spells_a_kind_s_root_key_beyond_its_armed_count |
test:core-duplex-ws | crates/busbar-kernel/tests/root_key_spelling.rs:142:5: crates/busbar/src/root/durability/store_chain.rs: 1 quoted root key(s), none armed — read it from Kind::verb() |
-p busbar-kernel --test root_key_spelling |
test target failed |
test:core-duplex-ws | |
busbar |
compile error |
test:single-plane-mcp | did not compile, with no rustc error in the output: busbar (bin "busbar" test) (1 error(s)) |
| `` | clippy rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-mcp | |
| `` | clippy rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-mcp | |
| `` | test rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-mcp | |
| `` | test rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-mcp | |
root_key_spelling |
no_production_source_spells_a_kind_s_root_key_beyond_its_armed_count |
test:timing | crates/busbar-kernel/tests/root_key_spelling.rs:142:5: crates/busbar/src/root/durability/store_chain.rs: 1 quoted root key(s), none armed — read it from Kind::verb() |
-p busbar-kernel --test root_key_spelling |
test target failed |
test:timing | |
busbar |
compile error |
test:single-plane-a2a | did not compile, with no rustc error in the output: busbar (bin "busbar" test) (1 error(s)) |
| `` | clippy rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-a2a | |
| `` | clippy rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-a2a | |
| `` | test rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-a2a | |
| `` | test rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-a2a | |
| `` | clippy rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-llm | |
| `` | clippy rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-llm | |
| `` | test rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-llm | |
| `` | test rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-llm | |
busbar |
compile error |
test:single-plane-voice | did not compile, with no rustc error in the output: busbar (bin "busbar" test) (1 error(s)) |
| `` | clippy rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-voice | |
| `` | clippy rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-voice | |
| `` | test rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-voice | |
| `` | test rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-voice | |
busbar |
compile error |
test:single-plane-decision | did not compile, with no rustc error in the output: busbar (bin "busbar" test) (1 error(s)) |
| `` | clippy rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-decision | |
| `` | clippy rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-decision | |
| `` | test rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-decision | |
| `` | test rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:single-plane-decision | |
busbar |
compile error |
test:no-default-features | did not compile, with no rustc error in the output: busbar (bin "busbar" test) (1 error(s)) |
| `` | clippy rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:no-default-features | |
| `` | clippy rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs |
test:no-default-features | |
| `` | test rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs |
test:no-default-features |
DENY rows (12)
| gate | row | detail |
|---|---|---|
| construction | one-pick-site |
3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8 |
| abi-location | abi-location:ledger |
STALE row (no such shape in the tree — strike it in the draining commit): version-const crates/plugin-loader/src/store_adapter.rs STORE_ABI_WITH_NEW_OPS |
| kind-isolation | kind-isolation:deps |
3 finding(s), 93 shipped edge instance(s) over 30 class(es), 93 declaration(s); 56 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w |
| kind-isolation | kind-isolation:test-deps |
3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge |
| kind-isolation | kind-isolation:law0 |
20 finding(s) over 14 neutral crate(s): law0-rise busbar × auth 51 hit(s) against a ceiling of 46: this landing grew a neutral crate's instance vocabulary. Ceilings only fall (measured on predev f830f |
| kind-isolation-ship | kind-isolation:deps |
10 finding(s) over 93 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a |
| kind-isolation-ship | kind-isolation:test-deps |
10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship |
| kind-isolation-ship | kind-isolation:law0 |
20 finding(s) over 14 neutral crate(s): law0-rise busbar × auth 51 hit(s) against a ceiling of 46: this landing grew a neutral crate's instance vocabulary. Ceilings only fall (measured on predev f830f |
| kind-isolation-ship | kind-isolation:faces |
2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is |
| kind-isolation-ship | kind-isolation:legacy-drain |
3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier) |
| ship-ready | ship-ready:ship-twin |
'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is |
| structure-lint | structure-lint:plane-dup:unledgered |
22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger |
Denied because (15)
- shard 1/4: gate:abi-location: green at base, red now (abi-location:ledger)
- shard 1/4: gate:build:workspace-compile: green at base, red now (check: compile busbar, check: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, check: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs)
- shard 1/4: gate:test:core-duplex-ws: green at base, red now (test: root_key_spelling (tests/root_key_spelling.rs)::no_production_source_spells_a_kind_s_root_key_beyond_its_armed_count, test: target -p busbar-kernel --test root_key_spelling)
- shard 1/4: gate:test:single-plane-mcp: green at base, red now (clippy: compile busbar, clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc error
- shard 1/4: gate:test:workspace: green at base, red now (nextest: xtask::cli::selftest_runs_every_registered_gates_red_proof)
- shard 1/4: gate:kind-isolation row kind-isolation:law0: figure rose 18 -> 20
- shard 1/4: gate:kind-isolation-ship row kind-isolation:law0: figure rose 18 -> 20
- shard 2/4: gate:test:single-plane-a2a: green at base, red now (clippy: compile busbar, clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc error
- shard 2/4: gate:test:timing: green at base, red now (test: root_key_spelling (tests/root_key_spelling.rs)::no_production_source_spells_a_kind_s_root_key_beyond_its_armed_count, test: target -p busbar-kernel --test root_key_spelling)
- shard 4/4: gate:test:no-default-features: green at base, red now (clippy: compile busbar, clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc er
- shard 4/4: gate:test:single-plane-decision: green at base, red now (clippy: compile busbar, clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc
- shard 4/4: gate:test:single-plane-llm: green at base, red now (clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'ACK_DE
- shard 4/4: gate:test:single-plane-voice: green at base, red now (clippy: compile busbar, clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc err
- shard 4/4: gate:test:workspace: green at base, red now (nextest: busbar-kernel::root_key_spelling::no_production_source_spells_a_kind_s_root_key_beyond_its_armed_count)
- shard 4/4: gate:test:xtask-selftest: green at base, red now (xtask: selftest abi-location)
Judged against base abc07fea9: 13 new red, 2 worse, 3 standing (excused).
New reds: gate:abi-location: green at base, red now (abi-location:ledger), gate:build:workspace-compile: green at base, red now (check: compile busbar, check: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, check: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs), gate:test:core-duplex-ws: green at base, red now (test: root_key_spelling (tests/root_key_spelling.rs)::no_production_source_spells_a_kind_s_root_key_beyond_its_armed_count, test: target -p busbar-kernel --test root_key_spelling), gate:test:single-plane-mcp: green at base, red now (clippy: compile busbar, clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs), gate:test:workspace: green at base, red now (nextest: xtask::cli::selftest_runs_every_registered_gates_red_proof), gate:test:single-plane-a2a: green at base, red now (clippy: compile busbar, clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs), gate:test:timing: green at base, red now (test: root_key_spelling (tests/root_key_spelling.rs)::no_production_source_spells_a_kind_s_root_key_beyond_its_armed_count, test: target -p busbar-kernel --test root_key_spelling), gate:test:no-default-features: green at base, red now (clippy: compile busbar, clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs), gate:test:single-plane-decision: green at base, red now (clippy: compile busbar, clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs), gate:test:single-plane-llm: green at base, red now (clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs), gate:test:single-plane-voice: green at base, red now (clippy: compile busbar, clippy: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, clippy: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'ACK_DEADLINE' @ crates/busbar/src/root/durability/mod.rs, test: rustc error: unused import: 'walk_stored_chains' @ crates/busbar/src/root/durability/mod.rs), gate:test:workspace: green at base, red now (nextest: busbar-kernel::root_key_spelling::no_production_source_spells_a_kind_s_root_key_beyond_its_armed_count), gate:test:xtask-selftest: green at base, red now (xtask: selftest abi-location)
tests passed: 13021, failed: 2. Run: https://github.com/GetBusbar/busbar/actions/runs/38022428397 . Artifact verdict-fcfe880db8c027f334141e4e533fd4e00aedeb26 (failures.json, junit.xml, raw.log; 90 days).
…he removed shipper; drive_borrowed's journal refusal returns None under predev's Option<Outcome>
Money: the ledger views and
/admin/verifyrefuse per balance. A refused counts row withholds its own row, never the whole read (audit root-R1 #10). Stacked on H3 (#687, which carries #549); this PR lands both.What money behaviour changed
GET /admin/ledger/totals,/admin/ledger/reconciliationand/admin/verifywhole (Store, 503). A refused row is rebuilt from the chain at every boot, so this hid every other row and every other verify finding for the life of the journal.LedgerView::refused_balancesnames each balance with no figure: its window, the lane that served the unit, and the refusal.refusedlist. Every other row is served, and reconciliation'sholdsis false while any row is withheld.GET /admin/verifyreports each refused balance as arefused counts:finding, and still runs and reports every other check.Rulings applied (ARCHITECT 2026-10-07)
settled_readstays unwired. Its figure is settled plus unreconciled, and the views read settled only.refusedlist on the totals and reconciliation responses is accepted. Both routes are 1.6.0-additive (the 1.5.5 recording is the router's 404), so no 1.5.5-pinned body moves. A clean book's body carries"refused":[]. The typed contract and the committedopenapi.jsonand.gzcarryLedgerRefusedBalance.cells.jsonwhytext and theadmin-bodies.jsonnote for GetLedgerTotals are accepted as edited.How it was proven
Latchkey
cli-23aba32fran on addc1af (H3 merged):-p busbar-core-admin -p busbar --all-targets -D warningspassed.busbar-core-admin: 424 passed, 0 failed.busbar --features openapi-schema) pass, so the committedopenapi.jsonis the generated one. The.gzwas regenerated from the merged JSON.a_refused_counts_row_withholds_its_row_and_totals_answers_every_other_rowa_refused_counts_row_withholds_its_row_and_reconciliation_measures_every_other_rowverify_names_a_refused_balance_and_every_other_findingbusbarin that job: 1053 passed, 2 failed.an_unpresentable_static_credential_logs_its_builders_own_line, a log-capture cell that passed in every other run of this stack and is not touched here.cli-098c3bb9on the H6 head (f767f88, which contains this PR's code):busbar1058 passed, 0 failed.hopis the proof of record.Oracle verdict
Strict replay against golden/1.5.5 over the money, ledger, usage, billing and admin audit/verify cells, base predev 1c4e1f0: