Skip to content

#550: fix the merge-queue DENY its PR check did not judge - #737

Merged
MattJackson merged 16 commits into
predevfrom
lane-task-mgdeny-550
Oct 10, 2026
Merged

MattJackson merged 16 commits into
predevfrom
lane-task-mgdeny-550

Conversation

@MattJackson

Copy link
Copy Markdown
Collaborator

#550: fix the merge-queue DENY its PR check did not judge

… manifest (ARCHITECT ruling (b))

A networked plugin's declares.json states `needs` (the transport schemes its Statement's needs
name) for the conformance suite (the_declared_needs_are_the_statements) and the fleet render (its
conformance host). pack's --declares-file parsed the whole file into sign::Declares, whose
deny_unknown_fields refused `needs`, so store-mysql, store-postgres, store-valkey, secret-vault and
export-webhook could not pack. The needs belong to the Statement, so the manifest never carries
them: read_declares parses to a Value, checks `needs` is a list of known schemes (tcp, http,
https: the schemes a transport framer serves), removes it, and deserializes the rest into
Declares with deny_unknown_fields kept.

RED (pack_tests pack_cli_leaves_the_declares_needs_out_of_the_manifest): a declares file with
`needs` packs to a manifest whose declares has no needs; a `needs` that is not a list, holds a
non-string, or names a scheme no framer serves is refused; any other unknown key beside a
well-formed `needs` is still refused; each refusal writes no tarball. The test fails without the
change.
…cument; the root's linked rows read through it (ARCHITECT ruling (b), extended)

ORACLE-BURN measured a second refusal pack's fix did not cover: the root's linked_exports read a
linked export crate's DECLARES (include_str! of its declares.json) straight into sign::Declares,
so a binary linking export-webhook dev exited at boot on `needs`. door_breaker read a linked plane
door's linked-declares row the same way.

Declares::from_declares_json(&[u8]) (sign.rs, beside Declares) checks `needs` is a list of
DECLARES_NEED_SCHEMES (tcp, http, https), removes it, and reads the rest with deny_unknown_fields
kept. Every reader of a declares document uses it: pack's read_declares, linked_exports,
door_breaker, and the tests that read a linked sink's DECLARES. A signed manifest's `declares` is
not a declares document and still refuses `needs`.

Tests:
- declares_reader_tests: the reader drops a well-formed `needs` and refuses a malformed one (not a
  list, a non-string, a scheme no framer serves), any other unknown key beside it, and non-JSON; a
  signed manifest whose declares states `needs` is refused; and a scan of crates/ and xtask/
  refuses any serde_json::from_* that deserializes declares bytes into Declares outside the one
  reader (RED arm over the scanner's own forms; red on linked.rs and export_conformance_tests
  before this change).
- root linked a_linked_export_declares_stating_needs_boots: every real linked export door
  restated with `needs` reads to the same manifest section and links into the registry; a
  malformed `needs` refuses the rows by name. Red before this change.
- root serve a_plane_declares_stating_needs_still_reads_its_breaker_fact: the decisions door's row
  with `needs` beside its breaker fact reads the fact; a malformed `needs` is refused by row.
  Red before this change.
…o the needs-boots test has no row to restate (the hop's gate:test:no-default-features)
…(no vacuous pass without the feature) and restates the webhook sink's row, the one whose repo states needs
…er (the scan test caught the site predev added)
…n linked_axis_export_doors, so the root names no export instance (kind-isolation:law0 busbar x export back at its ceiling)
…e; tests use placeholder schemes (kind-isolation:law0 back at its ceilings)
@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

promote into predev: BOARD @0035f6732: 0 failing test row(s), 11 DENY row(s)

DENY rows (11)

gate row detail
construction one-pick-site 3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8
kind-isolation kind-isolation:deps 3 finding(s), 93 shipped edge instance(s) over 30 class(es), 93 declaration(s); 56 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w
kind-isolation kind-isolation:test-deps 3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge
kind-isolation kind-isolation:law0 11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular
kind-isolation-ship kind-isolation:deps 10 finding(s) over 93 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a
kind-isolation-ship kind-isolation:test-deps 10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship
kind-isolation-ship kind-isolation:law0 11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular
kind-isolation-ship kind-isolation:faces 2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is
kind-isolation-ship kind-isolation:legacy-drain 3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier)
ship-ready ship-ready:ship-twin 'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is
structure-lint structure-lint:plane-dup:unledgered 22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger

Judged against base 7290204b1: 0 new red, 0 worse, 5 standing (excused).

tests passed: 22966, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/38072651750 . Artifact verdict-0035f673247e1467335b5fc6fc665ef3c72ff704 (failures.json, junit.xml, raw.log; 90 days).

@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 10, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 10, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 10, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 10, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
Merged via the queue into predev with commit 90f3ecc Oct 10, 2026
8 checks passed
@MattJackson
MattJackson deleted the lane-task-mgdeny-550 branch October 10, 2026 19:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant