Repository navigation
p4-fleet-doors: suite connection table, networked plugin conformance, exact pin-check, declared needs = Statement - #491
Merged
Merged
Conversation
… shipped closure is mysql_common 0.35 + url + percent-encoding over the host's connector; the mysql driver (28, minimal-rust) and ulid are test-only (busbar-store-mysql#15, 314e07aac3)
… ONCE (ARCHITECT ruling 5): the kept rows' descriptions match the repos' own Cargo.toml descriptions (env-var / file source as a droppable plugin, { env: VAR } / { file: /path }); the second, PLUGIN-TEMPLATE copies go. plugin-registry-check.sh: the six duplicate repo/alias/crate findings are gone, nothing new
…RCHITECT ruling 2026-10-05, the postgres parity ruling) A line both locks hold: the plugin's version is busbar's, byte-equal (drift stays RED). A line busbar's lock holds no version of is a different crate to Cargo: allowed only as .github/fleet/deps.toml [parity-lines] declares it for that plugin repo (crate, line, repos, use shipped|tests-only, reason); undeclared is RED by name. A declaration never exempts an advisory: plugin-ci's cargo-deny step also writes its advisory verdict as JSON lines and the gate is RED on a declared line it refused; the blocking deny check is unchanged. RED arms (plugin-gates selftest + unit tests): drift within a line (also beside a declared line), an undeclared extra line, a line declared for another repo, a declared extra line carrying an advisory; GREEN: the declared extra line. Declared: busbar-store-postgres's sha2 0.11 / digest 0.11 / block-buffer 0.12 / crypto-common 0.2 / const-oid 0.10 (shipped, postgres-protocol >= 0.6.11 SCRAM; 0.6.10 carries RUSTSEC-2026-0179/0180) and wasi 0.14 (tests-only, the independent postgres test client). store-postgres p4-fleet-doors' lock against this tree: 0 findings (was 6).
… (ARCHITECT, SUITE CONNECTIONS) A plugin whose Statement declares a need the test table serves (tcp: host:port, unix:/path) is bound, on the linked and the dropped-in leg alike, to a TcpConns of its own over the leg dispatcher's conn waker (Subject::conns / Subject::bind), so a networked store, auth or secret dials the real local endpoint its conformance.json settings name, through the host connector's slots. Every kind's script and the RED arms bind through Subject::bind. A door that declares no need is bound with no table, exactly as before. A door declaring a need over a scheme the table does not serve (http, https: the connector's framing) also keeps the bind with no table, as before, rather than being refused at bind as UnservedScheme. upgrade_secure is refused: the table names no TLS library. tcp_conns is compiled under `conformance` too: std + busbar-contract only, and a plugin names this crate only as a dev-dependency, so nothing reaches a shipped closure. Tests (conformance_suite_tests.rs, suite_conns, over the loader's dispatcher test door restated): no need -> no table; http / tcp+http -> no table; tcp -> a table that dials a real local listener under the declared need (RED with the table withheld: fails at the conns().expect).
… process's connector (Q-P4-3 (1)) AuthRows::load bound every auth door with `conns: None`, so a serving networked auth door (ldap's tcp need) was handed no connector and could never dial. AuthRows gains with_conns (a fn read when an instance opens, the hook axis's pattern, so installing the axis never pins the connector before the boot builds it); load takes `serving`: the open path binds over the table, the fact reads (operator, one reader per credential kind) bind with none. The root's auth_axis hands it root::connector::the(). Test (auth_door_tests): the judge door restated with one tcp need (tests/needs_restated.rs, the suite's restate pattern, no fixture), opened through AuthRows::with_conns, declares its need on the table (TcpConns::declarations). RED with the serving bind's table withheld: the table is never read (panics at "the table was read"); GREEN after.
…orked door with no table is refused by name (Q-P4-3 (2)) Bind::conns is now a ConnTable, stated at every call site: - Host(table): the host's one connection table (as before when Some). - Probe: a probe or check bind, only validated or read for its facts; a declared need is not declared and no table is handed, and it is not refused. Marked at the hook axis's probe (hook_door.rs), the export axis's probe/check (export_axis.rs), and the auth axis's fact reads. - NoNeeds: a bind to serve with no table. A door whose Statement declares a need, bound so, is refused at bind with LoadError::NoConnectionTable, "plugin '<name>' declares <n> connection need(s) and was bound with no connection table", never bound to fail at its first dial. ConnTable::serving(Option) names an axis's serving bind over the table it may hold. Every production `conns: None` is now explicit: transport doors (root/doors.rs) are NoNeeds (a framer declares no need); OutboundAuths takes a ConnTable (main: Host; its documented no-grant mode is NoNeeds, a networked row will not load and is passed over); DoorStoreAxis and boot::load_planes/LoadRequest take a ConnTable (root: Host); the secret, hook, export and auth serving binds use ConnTable::serving; the kernel's test store axis is NoNeeds. Tests that serve a networked door they never let dial say so: Probe (plane_driver, plane_rider, the routing-only serve_door row, plane-llm and auth-oauth conformance); library probes in tests/common are Probe; export_axis_tests opens the otlp sink over an inert table (needs_restated::Inert: declares everything, opens nothing). RED/GREEN (conn_services_tests): a_serving_bind_of_a_networked_door_with_no_table_is_refused_by_name fails with the NoNeeds refusal arm disabled and passes with it; a_probe_bind_with_no_table_binds_and_a_door_with_no_need_serves_with_none passes both ways.
…onnection table is refused by name (Q-P4-3 (3))
conformance_suite! emits red_a_networked_door_with_no_connection_table_is_refused
(conformance::red_no_table): a door that declares a need is bound to serve with no table
(ConnTable::NoNeeds), linked and dropped in, and must be refused with
LoadError::NoConnectionTable naming the plugin; a door that declares none is restated with one tcp
need (as red_ready restates its ready; no fixture) and bound linked. GREEN twins: the same door
bound as a Probe binds, and the honest door binds over the suite's own table (Subject::bind).
plugin-ci.yml's conformance step requires the new test by name (suite=).
RED/GREEN on the in-tree subject (busbar-plane-decisions --test conformance): with the loader's
NoNeeds refusal disabled the arm fails ("a networked door serving with no connection table is
refused: ()"); with it, all 6 arms pass.
… -> framer, with test trust anchors for the host's TLS (Q-P4-4) busbar-core-connector gains a `conformance` feature (optional deps: busbar-plugin-loader with `conformance`, the linked busbar-transport-tcp and busbar-transport-http rows, serde_json; never a default, never named by a shipped build) and conformance::host: THIS crate's Connector composed as the root composes the process's one: the tcp and http framer doors loaded through the one loader and opened by the root's own adapter (root/doors.rs, mounted verbatim, as build.rs mounts it), the crate's own TLS with the default outbound trust plus the suite's test anchors (PEM), the deployment's destination guard with loopback allowlisted, the leg dispatcher's conn waker. The suite reaches it by injection: busbar-plugin-loader cannot name the connector (connector -> kernel -> plugin-loader would be a cycle), so Subject gains `host: Option<Host>` and `anchors: Option<String>`, and conformance_suite! takes optional `host:` and `tls:` arguments. A plugin repo names busbar-core-connector (feature `conformance`) as a dev-dependency only; the anchors go to the HOST connector, never to the plugin. With a host, every need over any scheme it serves binds over it (Subject::conns); without one, the TcpConns table serves plain tcp as before, and `tls:` without `host:` is refused with a message naming the fix. Tests (busbar-core-connector --features conformance --test conformance_host): - an http need reaches a local HTTP listener through the host's framer (GET /v1/probe framed by the http door over the tcp carrier; one head, body "hello"); - a TLS upgrade on a tcp stream verifies against the suite's test CA and round-trips; - RED: the same upgrade with the anchors withheld is refused; - the suite binds a door declaring an http need over the host (ConnTable::Host, not refused as unserved); without the host it binds as a probe.
…umes, hold a networked door to its resumes (Q-P4-5)
The dispatcher counts RESUME re-invocations (FLAG_RESUME: the same op re-entered on its ticket after
PENDING; THE DESIGN §11.2 Ready | Pending(wake), A.3 "Resume") apart from first invocations:
Instance::resumes beside Instance::crossings (which still counts every crossing, so every existing
total stays). The suite's Recorder reads both (Counts): Step::crossed is first invocations, the
pinned count ("one op = one crossing", however often it pends), and Step::resumes is reported in
every comparator message, never pinned (a real backend's waits are the network's). The ready step
and the store's open pin one first invocation each (`ready_crossings` is no longer read).
A networked door (its needs SERVED by the suite's table, so it dials a real endpoint) must resume:
each step conformance.json names in `dialing_steps` resumed at least once, or, naming none, at least
one step of the fold did (conformance::resumed, run per leg in both_ways). The two folds are still
compared step for step on label, answer and first-invocation count; resumes are shown, not compared
(they are timing). BUSBAR_CONFORMANCE_RED=count still fails with "crossing(s), pinned".
RED/GREEN:
- ready_tests a_ready_that_pends_serves_after_its_wake: one first invocation and one resume; with the
resume count removed it fails ("the resume").
- conformance_suite_tests red_a_networked_fold_whose_dialing_step_never_resumed_is_refused and
resumes_are_never_pinned_a_moved_first_invocation_count_still_fails.
- busbar-plane-decisions --test conformance green (6/6); its RED run (BUSBAR_CONFORMANCE_RED=count)
fails "step 'facts': 0 crossing(s), pinned 1 (0 resume(s); ...)".
…umed, never one raw crossing (Q-P4-6) A store that connects in its connect step answers PENDING from `open`; one raw, ticket-less crossing cannot open it (the host FAULTs a ticket-less PENDING). red_ready now opens the restated door as the kernel does: a store through LoadedStore::open (which awaits `ready` inside it, so the failing ready refuses the store's open with the plugin's text, in one open and one ready first invocation); every other kind through conformance::open_resumed, `open` submitted on a ticket of the leg dispatcher's and resumed on its wake until it answers (the frame the suite's `open` builds, PlaneOpenIn for a plane). RED/GREEN (conformance_suite_tests resumed_open): the dispatch test door restated with an `open` that pends once in its connect step: a raw `open` answers FAULT; open_resumed answers READY in one first invocation and one resume. busbar-plane-decisions --test conformance stays green (6/6).
…he only kind the shipped schemas hold (Q-P4-7) The store script's put_credential / put_key_with_credential wrote kind "generic", which a schema-constrained store (store-postgres, 1.5.5's schema) refuses; its lookups asked for "generic". Both now use conformance::store::CREDENTIAL_KIND = "sigv4" (abi::cold PutCredential: "today only kind: sigv4"). No schema change. RED/GREEN (conformance_suite_tests the_store_script_writes_the_only_credential_kind_the_shipped_schemas_hold): with "generic" restored it fails (left "generic", right "sigv4"); passes after.
…lled per leg and per run (Q-P4-8)
`{fold}` anywhere in conformance.json's settings is replaced, inside the settings bytes only (no new
inputs key; Subject::settings_in / Leg::settings), by a namespace no other fold uses:
bbconf_<pid>_<leg>_<n> (the process, so CI's debug, release and RED runs differ; the leg; a counter
of the process's, so parallel folds differ), [a-z0-9_] only, a valid schema name or key prefix as it
stands. Each kind's fold opens over its leg's own (Leg::settings); red_ready over a "suite" one.
Settings that name no placeholder are byte-identical to before.
The store ABI offers no op that drops a namespace, so the suite leaves it: documented on FOLD, a
plugin's settings name a throwaway backend (a test database or a key space it may litter).
RED/GREEN (conformance_suite_tests fold_namespace): red_two_parallel_folds_never_share_a_namespace
(the two legs, and 8 parallel folds of one leg, never share a namespace; each names the pid and its
leg) fails with the substitution disabled and passes after;
settings_without_the_placeholder_are_unchanged.
… it), keep the neutral `host:` seam; the store's credential kind is the plugin's (gate fixes for Q-P4-4 and Q-P4-7) The gates TSV against 5489d5f refused 445f44a's host connector in busbar-core-connector: - kind-isolation:deps / :test-deps: busbar-core-connector -> busbar-plugin-loader is a cleanliness -> plugin-tooling edge the architecture does not grant (an optional dependency is scored as a shipped edge); - kind-isolation:build-inputs: mounting busbar's root/doors.rs into the connector is a crate reached without a dependency edge; - instance-noun-neutrality:tcp/http/undocumented: the connector named the linked tcp and http transport rows. So the host's implementation is withdrawn (busbar-core-connector's `conformance` feature, module and test, and the Cargo.lock lines) pending the ARCHITECT's choice of its home; 445f44a stays in history as the working reference (its 4 tests passed: http need through the framer, TLS against test anchors, RED with anchors withheld, the suite binding over the host). Kept, gate-neutral: the suite's injection seam (conformance::Host, Subject::with_host / with_anchors, conformance_suite!'s optional `host:` and `tls:` arguments), with its docs and its refusal text no longer naming the connector crate (kind-isolation:vocab), and a test of the seam with a host handed in (a_host_connector_handed_in_serves_every_need_and_takes_the_anchors: an http need binds over the host, the host is handed the anchors; with no host it binds as a probe; anchors with no host are refused by name). c1-literals:literal: the loader may not spell an auth style, so the store script no longer spells the credential kind: it is the plugin's conformance.json `store.credential_kind` (required, refused by name when absent; `sigv4` for 1.5.5's shipped schemas). Test: the_store_script_writes_the_credential_kind_the_plugin_names. instance-noun-neutrality:postgres: the fold-namespace test's sample URL no longer names a store.
… dialled here) binds as a Probe (Q-P4-3 follow-up) The serve and money rows bound the test plane with ConnTable::NoNeeds after c36f8af; it declares a need, so the loader now refuses that serving bind with no table (9 rows red on Latchkey). These rows never reach the plane's far end, so they bind it as a probe, as the routing-only serve_door row does. cargo test -p busbar --bin busbar -- root::serve: 23 passed.
…eate, drop)` (Q-P4-8, store-postgres)
A backend that never creates a namespace on demand (Postgres: `search_path={fold}` alone fails at
migrate, "no schema has been selected to create in") names hooks the PLUGIN implements with its own
test client (CREATE SCHEMA / DROP SCHEMA ... CASCADE), as a macro argument, never a conformance.json
key:
busbar_plugin_loader::conformance_suite! {
door: <path>, cdylib: <expr>, inputs: <expr>,
host: <path>, // optional (Q-P4-4 seam)
tls: <expr>, // optional
namespace: (<create path>, <drop path>), // optional, each fn(&str, &[u8])
}
(optional arguments in that order). Each hook is called with the fold's namespace (what `{fold}` was
filled with) and the fold's filled settings. Subject::fold_settings(tag) / Leg::settings(s) return a
FoldSettings guard: `create` runs when it is made (before the fold's open: both legs, red_ready's
"red" fold, every per-run CI fold), `drop` when it goes (the fold's end, its failure included: a drop
during unwinding is caught, never an abort). Without the argument nothing is called and the settings
are filled exactly as before.
Tests (conformance_suite_tests namespace_hooks):
- a_hook_made_namespace_is_created_and_dropped_once_per_fold: created once before the fold, dropped
once after; 4 parallel folds get 4 distinct namespaces, each created and dropped once; a failing
fold's namespace is still dropped; the hooks get the filled settings. RED with the drop hook not
called: fails.
- without_hooks_a_fold_is_filled_and_nothing_is_called.
The macro with host:, tls: and namespace: compiles (checked on busbar-plane-decisions' target).
…plugin repo's conformance host (ARCHITECT Q-P4-9) The host adapter lives in the plugin repo (Q-P4-9 (d)); its TLS far end and test CA stay busbar's, so the plugin names no TLS library even in a test. busbar-core-connector's test_support (ServerTls, StdServerSession, the fixture servers) is now compiled under cfg(test) OR the new `test-support` feature, and gains private_ca() (a test CA as PEM, the anchors a suite's tls: names, and a localhost leaf + key as DER). The feature adds no crate edge: rcgen is already a dependency; `rcgen/pem` is the feature the crate's own dev-dependencies already turn on.
… does, on a ticket, write-behind, resumed (Q-P4-6 for export) A networked export sink (a webhook POSTing through the host connector) waits on the network in deliver: a ticket-less raw crossing cannot carry its PENDING (the host FAULTs it), so the suite never reached the far end. The export script's deliver steps now submit on a ticket of the leg dispatcher's in the WriteBehind class with no deadline, as export_door's flusher offers a batch, and the op is resumed on its wake; conformance::on_ticket is the shared submit (open_resumed uses it too). A sink that answers at once answers the same: one first invocation, no resume.
…tBusbar repo at its own rev passes (Q-P4-9) The lock check matched every source starting with https://github.com/GetBusbar/busbar, so a networked plugin's conformance host (rendered by the fleet template, ARCHITECT Q-P4-9) was refused for its dev-dependency transport framers (busbar-transport-tcp/-http, their own repos at the revs busbar links). The match is now busbar's own source exactly (`<SRC>?`). Selftest case added (13): another GetBusbar repo in the lock at its own rev passes. RED before: busbar-export-webhook p4-conf-host's lock is refused by the old check; GREEN after.
…bar's own lock at the pin records (ARCHITECT ruling on Q-P4-9 pin-check) The framers a networked plugin's conformance host takes as dev-dependencies (GetBusbar/ busbar-transport-*, their own repos) are pinned, not just let through: each such source in the plugin's Cargo.lock must equal the source busbar's Cargo.lock at the pin records for that crate (PIN_CHECK_BUSBAR_LOCK, default the Cargo.lock of the busbar checkout the script sits in; the pin job's sparse checkout carries it). A framer busbar does not link, or one at another rev, is refused; no busbar lock to hold it to is refused. Selftest 15 cases: a framer at busbar's rev passes, at another rev is refused, one busbar does not link is refused.
…ws do, on a ticket, resumed (Q-P4-6 for secret) A networked secret (a vault read through the host's framed exchange) waits on the network in resolve: a ticket-less crossing cannot carry its PENDING (the host FAULTs it). The secret script's resolve steps now submit on a ticket of the leg dispatcher's (Call class, the host's call deadline) and read the material from the frame the op hands back (conformance::on_ticket_frame; on_ticket is its outcome-only form). A secret that answers at once answers the same: one first invocation.
…s (ARCHITECT ruling: one truth) The fleet render reads declares.json `needs` (the transport schemes) to give a networked plugin its conformance host; the Statement's needs are the runtime truth. conformance_suite! emits the_declared_needs_are_the_statements: the repo's declares.json (at the workspace root or one directory below the plugin crate's) must name exactly the schemes the door's Statement's needs name (conformance::declared_needs_are over conformance::need_schemes). A crate with no declares file (one inside busbar's own tree) is not held to it; plugin-ci's declares step refuses a plugin repo without one. plugin-ci.yml's suite= list requires the new test. RED (conformance_suite_tests red_declares_needs_that_are_not_the_statements_are_refused): a declares file naming a scheme the Statement does not, missing one it does, or with no `needs` for a networked Statement is refused; the Statement's schemes in any order pass.
MattJackson
enabled auto-merge
October 6, 2026 16:17
MattJackson
force-pushed
the
lane-p4-fleet-doors
branch
from
October 6, 2026 16:27
af1919a to
98b3ce3
Compare
MattJackson
added a commit
that referenced
this pull request
Oct 6, 2026
promote into
|
| crate | test | step | first panic |
|---|---|---|---|
| `` | nextest xtask::cli::selftest_runs_every_registered_gates_red_proof |
test:workspace | |
transport_dropped_in_serves |
a_dropped_in_transport_registers_through_the_one_fold_and_serves |
test:dropped-in-tcp-transport | crates/busbar/tests/transport_dropped_in_serves.rs:168:13: busbar exited (ExitStatus(unix_wait_status(512))) before serving; log: |
-p busbar --test transport_dropped_in_serves |
test target failed |
test:dropped-in-tcp-transport |
DENY rows (12)
| gate | row | detail |
|---|---|---|
| construction | one-pick-site |
3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8 |
| kind-isolation | kind-isolation:deps |
4 finding(s), 78 shipped edge instance(s) over 28 class(es), 78 declaration(s); 62 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> plugin-tooling busbar-core-admin -> busbar-plugin-l |
| kind-isolation | kind-isolation:test-deps |
5 finding(s), 36 test edge instance(s) over 19 class(es), 36 declaration(s); 22 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge |
| kind-isolation-ship | kind-isolation:deps |
16 finding(s) over 78 shipped edge(s): ship-edge cleanliness -> plugin-tooling busbar-core-admin -> busbar-plugin-loader is 'not-allowed': the architecture grants no cleanliness -> plugin-tooling edge |
| kind-isolation-ship | kind-isolation:test-deps |
13 finding(s) over 36 test edge(s): ship-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is 'not-allowed': the architecture grants no cleanliness -> legacy edge, and the ship criterion is t |
| kind-isolation-ship | kind-isolation:faces |
4 finding(s) over 31 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Store' 2 time(s) in shipped source — the entry face of kind 'store'. A trait implementation is a claim |
| kind-isolation-ship | kind-isolation:testkit |
2 finding(s) over 12 crate(s): battery-ignored crates/busbar-plane-decisions busbar-plane-decisions carries a tests/conformance.rs whose every entry is '#[ignore]'d (or which has none). 'cargo test' |
| kind-isolation-ship | kind-isolation:legacy-drain |
5 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier) |
| kind-isolation-ship | kind-isolation:control-path |
74 finding(s) over 3 control surface(s): upstream crates/busbar-core-admin/src/admin_codec/meta.rs:84 busbar-core-admin names 'egress' — a control surface has no upstream to reach, so the vocabulary o |
| ship-ready | ship-ready:ship-twin |
'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is |
| instance-noun-neutrality | instance-noun-neutrality:voice |
tracked known-debt census — 8: crates/busbar-plane-llm/src/codec/gemini/handler.rs×7 [cross-plugin] | crates/busbar-plane-llm/src/codec/gemini/tests/handler_tests.rs×2 [cross-plugin] | crates/busbar |
| structure-lint | structure-lint:plane-dup:unledgered |
24 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs mcp:crates/busbar-mcp/src/mcp/config.rs voice:crate |
Judged against base 214678af5: 0 new red, 0 worse, 8 standing (excused).
tests passed: 24560, failed: 1. Run: https://github.com/GetBusbar/busbar/actions/runs/37561174695 . Artifact verdict-ae39775b3df6737762b87d22402686a6744b2600 (failures.json, junit.xml, raw.log; 90 days).
github-merge-queue
Bot
removed this pull request from the merge queue due to a conflict with the base branch
Oct 6, 2026
# Conflicts: # crates/plugin-loader/src/export_axis.rs
MattJackson
enabled auto-merge
October 6, 2026 18:38
…ors: dispatch re-exports both ConnTable and the member-secret resolver; the SEAM probe binds (plane probe, carriers test) state ConnTable::Probe
MattJackson
enabled auto-merge
October 7, 2026 02:16
MattJackson
added a commit
that referenced
this pull request
Oct 7, 2026
…e binds follow serve_door.rs into its new name serve_tests.rs
MattJackson
added a commit
that referenced
this pull request
Oct 7, 2026
…core-admin keeps neither edge — not the ledger (#471: money through busbar_kernel::cost) nor the loader (D4: plugin admission through busbar_kernel::plugin_admission); manifest_schema takes the settings-schema text (#471) and its docs name the kernel paths D4 moved them to; the usage tests and the cost-facade witness read the contract at core-admin's v1; the matrix's parallel readings (#516's tree) pass the registry D4's instance census reads
MattJackson
added a commit
that referenced
this pull request
Oct 7, 2026
# Conflicts: # xtask/src/fleet/registry.rs
MattJackson
added a commit
that referenced
this pull request
Oct 7, 2026
MattJackson
added a commit
that referenced
this pull request
Oct 7, 2026
…cher runtime) into p4-oidc-repin. The auth axis keeps predev's config-name match (#508) and this lane's held table; the conformance auth script is the credential-login one (9ec4844); bind_far falls back to the leg's own table (Subject::bind) when the inputs name no far ends, and the auth conformance red arm expects the refusal #491 states for a networked door bound with no table, as lane-p4-ldap integrated them
MattJackson
added a commit
that referenced
this pull request
Oct 7, 2026
…ays deleted (predev's secret-hygiene edits to it go with it); DoorFacts/TransportFacts carry upgrades and status rows; ConnTable binds (#491) in the streaming tests and served-door cells; DATA_CARRIER stays for the 4l framed stream; RELEASE_REF e133afa5c0 (contains 1869c0032e); teller-steps --root-legs finds a path-mounted test module; declared_classes reads the streaming door's BILLABLE_CLASSES
MattJackson
added a commit
that referenced
this pull request
Oct 7, 2026
#491 makes a bind's connection table explicit)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fleet lane for P4. Every commit implements a ruling (Q-P4-2..10, pin-check option 1).
needsmust equal the plugin's Statement (one truth), with a RED arm.Plugin repos already on their door through this: postgres #20/#21 (sslmode through host TLS) and webhook #13.
Proof at 98b3ce3 (predev c162c71 merged in):