Repository navigation
feat(OMN-9470): workspace mode packages sibling repos with per-repo provenance - #1764
Conversation
|
Warning Review limit reached
More reviews will be available in 3 minutes and 37 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (9)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
|
||
| import json | ||
| import subprocess | ||
| import tempfile |
| import subprocess | ||
| import tempfile | ||
| from pathlib import Path | ||
| from unittest.mock import MagicMock, patch |
|
|
||
|
|
||
| def test_stage_workspace_missing_script_raises(tmp_path: Path) -> None: | ||
| executor = DeployExecutor() |
| ) | ||
|
|
||
| # Run the patched script in a subprocess with mocked distribution lookup | ||
| result = subprocess.run( |
…rovenance Implements BUILD_SOURCE=workspace so the runtime image installs omnibase_compat, onex_change_control, and omnimarket from staged local working trees instead of remote git/archive sources, and embeds a verifiable per-repo digest manifest. - scripts/runtime_build/stage_workspace.sh: rsync sibling repos from OMNI_HOME into workspace/sibling-repos/ before docker compose build - scripts/runtime_build/compute_workspace_provenance.py: SHA-256 digest each staged repo tree, verify local-path install, write /app/build-provenance.json - Dockerfile.runtime: COPY --if-present workspace staging; conditional install block (workspace=local path, release=git/archive); run provenance verifier; COPY manifest to runtime stage; add OCI label for manifest path - executor._compose_build: validate selector agreement before staging; call _stage_workspace for workspace mode; pass VCS_REF and BUILD_DATE build args - 12 new unit tests covering staging, provenance digest, manifest structure, build arg propagation, and Dockerfile contract assertions
319189e to
f39194f
Compare
OMN-9470 — Task 2: Workspace Mode Provenance
Part of epic OMN-9469 (Runtime Build Two-Phase Build Provenance Hardening). Task 1 (OMN-9471) established the BUILD_SOURCE selector contract. This task implements the workspace mode payload.
Summary
scripts/runtime_build/stage_workspace.sh— rsync sibling repos from OMNI_HOME into workspace/sibling-repos/ before docker compose buildscripts/runtime_build/compute_workspace_provenance.py— SHA-256 digest each staged repo tree, verify local-path install, write /app/build-provenance.json; fails build on mismatchdocker/Dockerfile.runtime— conditional sibling install block (workspace=local path, release=git/archive); runs provenance verifier; copies manifest to runtime stage; adds OCI labelscripts/deploy-agent/deploy_agent/executor.py— validates selector agreement before staging; calls _stage_workspace in workspace mode; passes VCS_REF and BUILD_DATE build argsTests
12 new unit tests covering staging, provenance digest mutation-sensitivity, manifest structure, build arg propagation, and Dockerfile contract assertions.
dod_evidence
Evidence-Ticket: OMN-9470
Evidence-Source: d9aa830b5b2c120c43683b93b6f711857d00c419