Skip to content

ledger views and verify refuse per balance, not the read (M10) - #729

Closed
MattJackson wants to merge 12 commits into
predevfrom
lane-task-draft-688-per-balance-refusal
Closed

MattJackson wants to merge 12 commits into
predevfrom
lane-task-draft-688-per-balance-refusal

Conversation

@MattJackson

Copy link
Copy Markdown
Collaborator

ledger views and verify refuse per balance, not the read (M10)

…holds its own row, never the read

One refused counts row (#42) used to fail GET /admin/ledger/totals, /admin/ledger/reconciliation
and /admin/verify whole (Store, 503). A refused row is rebuilt from the chain at every boot and an
undeclared refusal stays refused through any card, so that hid every other row and every other
verify finding for the life of the journal (audit root-R1 #10).

The refusal is now per balance and window. LedgerView::refused_balances (off
Durability::refused_balances, the same RefusedCounts Durability::settled_read refuses with) names
each balance with no figure: its window, the lane that served the unit, and the refusal. The
totals and reconciliation views withhold the bucket-day row such a balance folds into (the priced
remainder would be the silent zero #42 forbids) and name it under a new `refused` list; every other
row is served, and reconciliation's `holds` is false while any row is withheld. GET /admin/verify
reports each as a `refused counts:` finding and still runs and reports every other check (§7: the
integrity verifiers are wired into the verify surface). Each read asks for the refusals after it
reads its rows, so the race can only withhold a row, never serve a short one.

The two response types gain `refused` (LedgerRefusedBalance) in the typed contract and the
committed openapi.json; both routes are 1.6.0-additive (the 1.5.5 recording is the router's 404),
so no 1.5.5-pinned body moves. The 503 descriptions now name only the out-of-range figure refusal
that remains, and the admin-bodies note for GetLedgerTotals says what the row does.
# Conflicts:
#	crates/busbar-core-admin/src/v1/json/openapi.json.gz
…he removed shipper; drive_borrowed's journal refusal returns None under predev's Option<Outcome>
Clean merge: predev touched neither the admin surface (openapi.json and .gz unchanged), cells.json nor any LedgerView implementer; refused_balances keeps its empty default and NodeLedger's override.

Supersedes #688.
@MattJackson
MattJackson enabled auto-merge October 10, 2026 06:37
@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

promote into predev: BOARD @9783f9f62: 0 failing test row(s), 11 DENY row(s)

DENY rows (11)

gate row detail
construction one-pick-site 3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8
kind-isolation kind-isolation:deps 3 finding(s), 93 shipped edge instance(s) over 30 class(es), 93 declaration(s); 56 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w
kind-isolation kind-isolation:test-deps 3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge
kind-isolation kind-isolation:law0 11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular
kind-isolation-ship kind-isolation:deps 10 finding(s) over 93 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a
kind-isolation-ship kind-isolation:test-deps 10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship
kind-isolation-ship kind-isolation:law0 11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular
kind-isolation-ship kind-isolation:faces 2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is
kind-isolation-ship kind-isolation:legacy-drain 3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier)
ship-ready ship-ready:ship-twin 'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is
structure-lint structure-lint:plane-dup:unledgered 22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger

Judged against base 4f36b9739: 0 new red, 0 worse, 5 standing (excused).

Reused PASS by input key (1, 1 min not re-run)
step key produced by
build:deletion-matrix 01ce8ea6bdbce5b6 5cf1ff24b

tests passed: 24281, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/38061225893 . Artifact verdict-9783f9f6220cebfaf410d71e6749a7cfb0bb28f5 (failures.json, junit.xml, raw.log; 90 days).

@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 10, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 10, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@MattJackson

Copy link
Copy Markdown
Collaborator Author

Closed: duplicate of #739 (identical diff, already ahead in the queue).

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a manual request Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant