Repository navigation
ledger totals: the node prices its counted lines at read time, kept on the book and rebuilt from the chain (H6; on H3 + M10) - #689
Draft
MattJackson wants to merge 10 commits into
Draft
MattJackson wants to merge 10 commits into
MattJackson wants to merge 10 commits into
Conversation
…ept on the book and rebuilt from the chain GET /api/v1/admin/ledger/totals on a node answered the book's settled balance, a figure priced at settlement: NodeLedger::booked_lines returned nothing, so derived_totals_rows always fell back. A signed back-dated rate correction did not move the read until a restart re-derived the book (audit root-R1 #6; BUSBAR-1.6.0.md §7). Durability now keeps the counted lines (counts, arrived_ms, balance and window, fee count) for the windows the book holds, appended as each posting is journalled (settle_counted*, post_counts, recovered holds) and rebuilt from the chain by the same replay that rebuilds the book. The admin read prices them through totals_as_of at the card in force at each line's own arrival; it never replays the journal (M11). The book retires no window today, so neither do the lines. A figure with no counts behind it, a class nobody declared, or a line the card cannot price leaves the read on the book's balance, as derived_totals_rows documents. The reconciliation still reads the balance at its own vintage. NodeLedger reads the dated history off the book's own source (ROOT_CARD on a production node). ARCHITECT 2026-10-07 H6 retention ruling.
…e's and the register's prose say so
…efused balance's row is withheld whichever arm of the totals read priced it
MattJackson
enabled auto-merge
October 8, 2026 03:21
MattJackson
marked this pull request as draft
October 8, 2026 03:27
auto-merge was automatically disabled
October 8, 2026 03:27
Pull request was converted to draft
promote into
|
| gate | row | detail |
|---|---|---|
| construction | one-pick-site |
3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8 |
| kind-isolation | kind-isolation:deps |
3 finding(s), 93 shipped edge instance(s) over 30 class(es), 93 declaration(s); 56 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w |
| kind-isolation | kind-isolation:test-deps |
3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge |
| kind-isolation | kind-isolation:law0 |
12 hit(s) off the [[law0]] ceilings, 6 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular |
| kind-isolation | kind-isolation:law0-base |
1 hit(s) grown over the merge-base d7929b6, 1 cell(s): law0-grown busbar × instance:store 2 -> 3 hit(s) over the same cell at the merge-base d7929b6 (its '[[law0]]' row 2 there): this branch wrote 1 |
| kind-isolation-ship | kind-isolation:deps |
10 finding(s) over 93 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a |
| kind-isolation-ship | kind-isolation:test-deps |
10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship |
| kind-isolation-ship | kind-isolation:law0 |
12 hit(s) off the [[law0]] ceilings, 6 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular |
| kind-isolation-ship | kind-isolation:law0-base |
1 hit(s) grown over the merge-base d7929b6, 1 cell(s): law0-grown busbar × instance:store 2 -> 3 hit(s) over the same cell at the merge-base d7929b6 (its '[[law0]]' row 2 there): this branch wrote 1 |
| kind-isolation-ship | kind-isolation:faces |
2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is |
| kind-isolation-ship | kind-isolation:legacy-drain |
3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier) |
| ship-ready | ship-ready:ship-twin |
'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is |
| structure-lint | structure-lint:plane-dup:unledgered |
22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger |
Denied because (4)
- shard 1/4: gate:kind-isolation row kind-isolation:law0-base: red now, not red at base
- shard 1/4: gate:kind-isolation-ship row kind-isolation:law0-base: red now, not red at base
- shard 1/4: gate:kind-isolation row kind-isolation:law0: figure rose 11 -> 12
- shard 1/4: gate:kind-isolation-ship row kind-isolation:law0: figure rose 11 -> 12
Judged against base d7929b661: 2 new red, 2 worse, 3 standing (excused).
New reds: gate:kind-isolation row kind-isolation:law0-base: red now, not red at base, gate:kind-isolation-ship row kind-isolation:law0-base: red now, not red at base
tests passed: 24408, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/38090575924 . Artifact verdict-56788d02d37d264f23bb47f574ba0d41e54d9b72 (failures.json, junit.xml, raw.log; 90 days).
…ests; drop shipper-seam tests for the removed shipper API
… value predev's Option<Outcome> signature uses
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Money:
GET /admin/ledger/totalson a node prices its counted lines at read time, at the card in force at each line's own arrival. A signed back-dated correction moves the next read with no restart (audit root-R1 #6; BUSBAR-1.6.0.md section 7; ARCHITECT 2026-10-07 H6 retention ruling). Stacked on H3 (#687) and M10 (#688), both merged in. The first commit is labelledwip:; the proof below is what that label was waiting for, and the history is not rewritten (no force-push).What money behaviour changed
NodeLedger::booked_linesreturned nothing, soderived_totals_rowsalways fell back to the book's settled balance, priced at settlement. A back-dated correction did not move the read until a restart re-derived the book.Durabilitykeeps the counted lines (counts,arrived_ms, balance and window, fee count) for the windows the book holds.settle_counted*,post_counts, and recovered holds.totals_as_ofand never replays the journal (M11).NodeLedgerreads the dated history off the book's own source (ROOT_CARDin production).unconstructedregister and gate prose now say proven instance 2 (booked_lines) is fed.Known limits (no ruling needed)
Book::retain_fromhas no production caller), so the lines are kept for the life of the process: one line per counted unit, rebuilt from the whole chain at boot.How it was proven
Latchkey
cli-098c3bb9-d70e-4fef-8d31-f53592564de8ran on f767f88 (H3, M10 and predev 1c4e1f0 merged):-p busbar --all-targets -D warningspassed.busbar(bin and every integration target exceptledger_identity, which CI runs with the oracle clone): 1058 passed, 0 failed.h6_a_back_dated_correction_moves_the_node_totals_on_the_next_read_without_a_restarth6_the_node_totals_answer_the_same_bytes_before_and_after_a_restarth6_an_unpriceable_line_or_an_uncounted_figure_serves_the_balance_never_zeropasses both before and after, as intended.hopis the proof of record.Oracle verdict
Strict replay against golden/1.5.5 over the money, ledger, usage, billing and admin audit/verify cells, base predev 1c4e1f0 against this head:
admin.ops|GetLedgerTotalsfield set and render are unchanged; only the values a correction moves can move.