Skip to content

feat(OMN-9470): workspace mode packages sibling repos with per-repo provenance - #1764

Merged
jonahgabriel merged 3 commits into
devfrom
jonah/omn-9470-task-2-workspace-provenance
May 26, 2026
Merged

jonahgabriel merged 3 commits into
devfrom
jonah/omn-9470-task-2-workspace-provenance

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented May 26, 2026 •

Copy link
Copy Markdown
Collaborator

OMN-9470 — Task 2: Workspace Mode Provenance

Part of epic OMN-9469 (Runtime Build Two-Phase Build Provenance Hardening). Task 1 (OMN-9471) established the BUILD_SOURCE selector contract. This task implements the workspace mode payload.

Summary

  • scripts/runtime_build/stage_workspace.sh — rsync sibling repos from OMNI_HOME into workspace/sibling-repos/ before docker compose build
  • scripts/runtime_build/compute_workspace_provenance.py — SHA-256 digest each staged repo tree, verify local-path install, write /app/build-provenance.json; fails build on mismatch
  • docker/Dockerfile.runtime — conditional sibling install block (workspace=local path, release=git/archive); runs provenance verifier; copies manifest to runtime stage; adds OCI label
  • scripts/deploy-agent/deploy_agent/executor.py — validates selector agreement before staging; calls _stage_workspace in workspace mode; passes VCS_REF and BUILD_DATE build args

Tests

12 new unit tests covering staging, provenance digest mutation-sensitivity, manifest structure, build arg propagation, and Dockerfile contract assertions.

dod_evidence

  • 93 unit tests passing (1 pre-existing unrelated failure)
  • All pre-commit hooks pass

Evidence-Ticket: OMN-9470
Evidence-Source: d9aa830b5b2c120c43683b93b6f711857d00c419

@coderabbitai

coderabbitai Bot commented May 26, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@jonahgabriel, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 3 minutes and 37 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 73b5fd67-1f29-4998-a560-5e4ca12397e7

📥 Commits

Reviewing files that changed from the base of the PR and between c049b45 and f39194f.

📒 Files selected for processing (9)
  • .gitignore
  • docker/Dockerfile.runtime
  • scripts/deploy-agent/deploy_agent/executor.py
  • scripts/deploy-agent/tests/unit/test_executor_build_source.py
  • scripts/deploy-agent/tests/unit/test_executor_workspace_provenance.py
  • scripts/runtime_build/compute_workspace_provenance.py
  • scripts/runtime_build/stage_workspace.sh
  • scripts/validation/validate_clean_root.py
  • workspace/sibling-repos/.gitkeep
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-9470-task-2-workspace-provenance

Comment @coderabbitai help to get the list of available commands and usage tips.

@jonahgabriel
jonahgabriel enabled auto-merge (squash) May 26, 2026 14:53

import json
import subprocess
import tempfile
import subprocess
import tempfile
from pathlib import Path
from unittest.mock import MagicMock, patch


def test_stage_workspace_missing_script_raises(tmp_path: Path) -> None:
executor = DeployExecutor()
)

# Run the patched script in a subprocess with mocked distribution lookup
result = subprocess.run(
…rovenance

Implements BUILD_SOURCE=workspace so the runtime image installs omnibase_compat,
onex_change_control, and omnimarket from staged local working trees instead of
remote git/archive sources, and embeds a verifiable per-repo digest manifest.

- scripts/runtime_build/stage_workspace.sh: rsync sibling repos from OMNI_HOME
  into workspace/sibling-repos/ before docker compose build
- scripts/runtime_build/compute_workspace_provenance.py: SHA-256 digest each
  staged repo tree, verify local-path install, write /app/build-provenance.json
- Dockerfile.runtime: COPY --if-present workspace staging; conditional install
  block (workspace=local path, release=git/archive); run provenance verifier;
  COPY manifest to runtime stage; add OCI label for manifest path
- executor._compose_build: validate selector agreement before staging; call
  _stage_workspace for workspace mode; pass VCS_REF and BUILD_DATE build args
- 12 new unit tests covering staging, provenance digest, manifest structure,
  build arg propagation, and Dockerfile contract assertions
@jonahgabriel
jonahgabriel force-pushed the jonah/omn-9470-task-2-workspace-provenance branch from 319189e to f39194f Compare May 26, 2026 16:41
@jonahgabriel
jonahgabriel added this pull request to the merge queue May 26, 2026
Merged via the queue into dev with commit be5f7e5 May 26, 2026
20 of 22 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-9470-task-2-workspace-provenance branch May 26, 2026 16:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants