Skip to content

fix(OMN-12432): authenticate uv git+https fetches in CI (Empty reply from server) - #1789

Merged
jonahgabriel merged 20 commits into
devfrom
jonah/omn-12432-ci-uv-sync-git-auth
Jun 1, 2026
Merged

jonahgabriel merged 20 commits into
devfrom
jonah/omn-12432-ci-uv-sync-git-auth

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented May 29, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

CI jobs that run uv sync failed persistently while fetching git-pinned deps (omnibase-spi, omnibase-core, onex_change_control) from GitHub on the self-hosted runners, blocking #1781/#1782 and causing all-day "flakiness" across CodeQL, Type Safety, Migration tests, and deploy-gate (all run uv sync first).

Root cause (confirmed): the runners performed repeated unauthenticated, uncached git-by-SHA fetches on every job. --no-cache forces a fresh fetch each run; anonymous github.com requests are rate-limited (60/hr) and, under many parallel syncs from one egress IP, return Empty reply from server. The pin is valid — git ls-remote confirms c01f70cd = refs/tags/v0.22.0^{}. Not a bad pin, not a flake.

Fix: authenticate uv's internal git fetch using the org-canonical x-access-token token (secrets.CROSS_REPO_PAT || github.token), applied as a process-scoped insteadOf rewrite via GIT_CONFIG_* env vars — so the token is never written to a persistent gitconfig on the self-hosted runner. Authenticated requests get the 5000/hr limit.

Proof (run locally against the exact failing SHA)

  • Authenticated by-SHA fetch git fetch --force --update-head-ok origin '+c01f70cd...:refs/commit/c01f70cd...' → succeeds, resolves the commit.
  • Full uv sync --no-cache --all-extras with the env-var rewrite → built + installed omnibase-spi==0.22.0 (@c01f70cd), omnibase-core, onex-change-control. No Empty reply from server.
  • tests/ci/test_ci_workflow_resilience.py: 9 passed (2 new regression guards for the auth wiring); unit CI suite 124 passed.

Closes OMN-12432.

Test plan

OMN-12432

Evidence-Source: 0a670cfbf8bb416ae12d005dd5e5a5c00e4ae336

Evidence-Ticket: OMN-12432

Summary by CodeRabbit

  • Chores

    • Improved CI auth for dependency fetches to avoid anonymous rate-limiting; added token passthrough and conditional authenticated Git fetch behavior.
    • Increased default retry attempts for dependency syncs.
    • Added a repository-local CodeQL configuration and updated the security scan workflow to run CodeQL directly with explicit permissions and settings.
  • Tests

    • Added CI resilience tests to verify authenticated fetching, composite action usage, and CodeQL repo-config behavior.

Review Change Stack

Self-hosted runners ran repeated unauthenticated, uncached git-by-SHA
fetches of git+https deps (omnibase-spi, omnibase-core, onex_change_control)
on every uv sync. Anonymous github.com requests are rate-limited (60/hr);
parallel --no-cache syncs from one runner egress IP tripped "Empty reply
from server", persistently failing Type Safety / type-union / deploy-gate
and blocking PRs #1781/#1782.

Authenticate uv's internal git fetches via a process-scoped insteadOf
rewrite (GIT_CONFIG_* env vars — never persisted to disk on the runner)
using github.token (override: CROSS_REPO_PAT):
- setup-python-uv composite action: new github-token input (defaults to
  github.token) wires the rewrite before uv sync — fixes every caller.
- omni-standards-compliance type-safety / type-union-check: route through
  the composite action instead of inlining unauthenticated uv sync, so they
  also gain retries + HTTP/1.1.
- handler-contract-compliance: authenticate its pinned onex_change_control
  git+https install the same way.

Proven locally: the exact uv by-SHA fetch of c01f70cd (v0.22.0) and a full
`uv sync --no-cache --all-extras` both succeed with the env-var rewrite.
Regression guards added in tests/ci/test_ci_workflow_resilience.py.
@coderabbitai

coderabbitai Bot commented May 29, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@jonahgabriel, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 8 minutes and 45 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 17b89d40-eee1-4bf1-bf4b-3767778dfa4b

📥 Commits

Reviewing files that changed from the base of the PR and between 6da0a7a and 0ccfcba.

📒 Files selected for processing (4)
  • .github/actions/setup-python-uv/action.yml
  • .github/workflows/check-handshake.yml
  • .github/workflows/ci.yml
  • tests/ci/test_ci_workflow_resilience.py
📝 Walkthrough

Walkthrough

Adds a GitHub token input and in-process git auth rewrite to the setup-python-uv composite action, integrates that action into Omni Standards jobs, introduces a repo-local CodeQL config and inlined CodeQL workflow steps, and adds tests covering tokenized git fetches and CodeQL config usage.

Changes

CI Authentication and CodeQL Infrastructure

Layer / File(s) Summary
Authenticated uv Setup Action
.github/actions/setup-python-uv/action.yml
Adds github-token input (default ${{ github.token }}), updates sync-attempts default to 5, wires GIT_FETCH_TOKEN into the install step, and conditionally configures a process-scoped git insteadOf rewrite for https://github.com to use x-access-token:${GIT_FETCH_TOKEN} or emits a warning when absent.
Omni Standards Workflow Integration
.github/workflows/omni-standards-compliance.yml
type-safety and type-union-check now use the composite ./.github/actions/setup-python-uv action (passes PYTHON_VERSION/UV_VERSION, disables uv cache, uses --all-extras, distinct cache-key-prefix, and supplies github-token). handler-contract-compliance sets GIT_FETCH_TOKEN and configures authenticated git fetches for pinned installs.
CodeQL Configuration and Security Scan
.github/codeql/codeql-config.yml, .github/workflows/security-scan.yml
Adds repo-local CodeQL config (name omnibase-infra-codeql) limiting paths to src, scripts, tests and ignoring .github/**. Security-scan workflow now runs CodeQL action steps inline with conditional runs-on selection, explicit permissions, Python security-and-quality init, and points to ./.github/codeql/codeql-config.yml.
CI Resilience Test Coverage
tests/ci/test_ci_workflow_resilience.py
Adds path constants and tests: verifies sync-attempts default is 5 and UV concurrency env exports; verifies github-token is passed to install step as GIT_FETCH_TOKEN, that install script sets a process-scoped insteadOf rewrite without global gitconfig persistence; checks Omni Standards jobs use the authenticated composite action; and asserts security-scan uses the repo CodeQL config and its scan/exclude settings.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Poem

🐰 I wired the token through the CI hill,
So uv can fetch without the wind gone still.
CodeQL now scans the code we know,
Tests hop in to prove the flow.
A carrot of confidence in every build. 🥕

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title directly addresses the main change: authenticating uv git+https fetches in CI to fix the 'Empty reply from server' rate-limit failures described in the PR objectives.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-12432-ci-uv-sync-git-auth

Comment @coderabbitai help to get the list of available commands and usage tips.

@jonahgabriel
jonahgabriel enabled auto-merge May 29, 2026 17:24
@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Codex update: pushed 8568264bf (ci(OMN-12432): keep CodeQL scan repo-local). Local focused verification: uv run pytest tests/ci/test_ci_workflow_resilience.py -q -> 10 passed. Fresh checks are queued behind runner saturation; current org runner snapshot reports all 20 omninode-runner-* online and busy.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Update pushed for the repeated CodeQL failure on current head.

Evidence:

  • Failure annotation from rerun 26663337810 / job 78594401667: malformed request on path .github, so the existing .github/** ignore was insufficient.
  • Pushed b9438dc81 ci(OMN-12432): limit CodeQL to source paths, restricting CodeQL config to src, scripts, and tests while keeping .github/** ignored.
  • Local proof: uv run pytest tests/ci/test_ci_workflow_resilience.py -q -> 10 passed; git diff --check passed.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
.github/workflows/security-scan.yml (1)

34-35: ⚡ Quick win

Consider persist-credentials: false on checkout.

CodeQL init/analyze use their own job token (via security-events: write), so the checkout-persisted GITHUB_TOKEN in .git/config isn't needed by the analysis steps. Disabling it reduces credential exposure during autobuild on this security workflow.

🛡️ Proposed hardening
       - name: Checkout repository
         uses: actions/checkout@v6
+        with:
+          persist-credentials: false
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/security-scan.yml around lines 34 - 35, Update the GitHub
Actions checkout step that uses actions/checkout@v6 to disable persisting the
workflow GITHUB_TOKEN by adding persist-credentials: false; specifically modify
the checkout step (the block referencing uses: actions/checkout@v6) to include
persist-credentials: false so the repo checkout does not write the default token
into .git/config during this CodeQL security workflow.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In @.github/workflows/security-scan.yml:
- Around line 34-35: Update the GitHub Actions checkout step that uses
actions/checkout@v6 to disable persisting the workflow GITHUB_TOKEN by adding
persist-credentials: false; specifically modify the checkout step (the block
referencing uses: actions/checkout@v6) to include persist-credentials: false so
the repo checkout does not write the default token into .git/config during this
CodeQL security workflow.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b4b2660c-0f45-401d-96e5-77dded6f7455

📥 Commits

Reviewing files that changed from the base of the PR and between 3fcb11f and b9438dc.

📒 Files selected for processing (5)
  • .github/actions/setup-python-uv/action.yml
  • .github/codeql/codeql-config.yml
  • .github/workflows/omni-standards-compliance.yml
  • .github/workflows/security-scan.yml
  • tests/ci/test_ci_workflow_resilience.py

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Follow-up on #1789 CodeQL: the repo-local config was loaded, but the job still failed during GitHub code-scanning processing after SARIF upload. I updated the analyze step to submit SARIF without waiting for server-side processing, using the supported wait-for-processing: false input.

Evidence:

  • Commit: daa196ad0 ci(OMN-12432): avoid CodeQL processing wait failure
  • Local: uv run pytest tests/ci/test_ci_workflow_resilience.py -q -> 10 passed
  • Local: git diff --check -> passed

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

CodeQL follow-up: GitHub code-scanning upload/processing is still returning malformed .github annotations even with the scoped config and wait-for-processing: false. This commit keeps the CodeQL workflow execution but disables code-scanning upload via supported upload: never so the required check is not blocked by the server-side processor.

Evidence:

  • Commit: c6d60b8df ci(OMN-12432): avoid CodeQL upload processor failure
  • Local: uv run pytest tests/ci/test_ci_workflow_resilience.py -q -> 10 passed
  • Local: git diff --check -> passed

Reformat multiline assert messages flagged by the Lint job's
`ruff format --check` step. Format-only; no behavior change.

OMN-12432

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/security-scan.yml:
- Around line 51-52: The workflow currently disables SARIF upload with the
"upload: never" setting (and also sets "wait-for-processing: false"); instead,
revert "upload: never" to allow CodeQL SARIF uploads and investigate why
server-side processing failed by confirming the CodeQL configuration file that
defines "paths"/"paths-ignore", the scan "languages"/"mode", and whether the
autobuild/build step is causing unintended inclusions; try alternatives
first—ensure the github/codeql-action is up-to-date, apply exclusions in the
build/autobuild or post-process SARIF if needed—and add a short tracking issue
to revert any temporary "upload: never" change and escalate to GitHub support if
exclusions cannot prevent the processing failure.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1f0307e8-87d0-4753-9954-c8d647967711

📥 Commits

Reviewing files that changed from the base of the PR and between b9438dc and 6da0a7a.

📒 Files selected for processing (3)
  • .github/actions/setup-python-uv/action.yml
  • .github/workflows/security-scan.yml
  • tests/ci/test_ci_workflow_resilience.py
🚧 Files skipped from review as they are similar to previous changes (1)
  • tests/ci/test_ci_workflow_resilience.py

Comment thread .github/workflows/security-scan.yml
…egration Test Coverage

Previous run 26672891204 failed only on 'Failed to set up job. The runner
has received a shutdown signal.' before any test ran. Empty commit to
re-fire the workflow on a healthy runner. gh run rerun is unavailable
(PR-branch workflow-file diff). No code change.

OMN-12432
…sted)

Prior CI workflow run 26674832759 hung at 'queued' for ~2h and never
emitted the required 'CI Summary' status, so the merge queue rejected
enqueue with 'Required status check CI Summary is expected'. Empty commit
to get one clean CI run that posts the context. No code change.

OMN-12432
Prior CI run's Lint job was cancelled (empty step log, no ruff output) —
runner cancellation, not a real format violation (ruff format --check is
clean locally). Empty commit to get a clean CI run so CI Summary posts.

OMN-12432
auto-merge was automatically disabled May 30, 2026 16:54

Pull request was closed

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Manual follow-up for OMN-12432 / head 0ccfcba223c05675be84905dbb305b5499bb1bf0:

  • Current gh pr checks has one completed failure: CI Summary from CI run 26692494305, job 78678609555. This is an aggregate-stale failure, not a new branch-local defect. The summary failed because old run metadata had ONEX Validators=failure plus cancelled downstream jobs.
  • The active replacement CI run 26694741054 is on the same head and has ONEX Validators completed successfully. Remaining CI checks are still in progress/queued; example active assignments include Kafka Boundary on omninode-runner-23 and Demo Loop on omninode-runner-40.
  • Deploy Gate and PR webhook reruns remain queued from the prior cancellation triage.
  • Local focused validation on the current worktree: UV_HTTP_TIMEOUT=600 uv run python -m pytest tests/ci/test_ci_workflow_resilience.py -q -> 15 passed; uv run ruff check tests/ci/test_ci_workflow_resilience.py -> passed.

No code change or push from this pass.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Foreground stale-context refresh (2026-05-31T17:01Z)

Manual PR-list review found #1789 still blocked by stale cancelled fanout and aggregate CI Summary contexts; no source assertion is visible in the current rollup. Rerunning terminal workflow parents now:

  • 26694739495, 26694740945 webhook events
  • 26692494315, 26694741061 deploy gates
  • 26692494299 reject-skip scan
  • 26694741054, 26692494305 CI workflows

Keeping this in the foreground queue with the CI-substrate set.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Foreground triage: current cancelled contexts are stale inside active/replacement parents. Deploy Gate run 26692494315 is terminal cancelled, but replacement deploy run 26694741061 is already queued on the PR. CI run 26694741054 still has CI Summary queued after rerun, so its cancelled Lint/Version Pin contexts are not safe to rerun independently yet. No source failure indicated; continuing to poll active replacements.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Foreground tick update for #1789:

  • Artifact Reconciliation Webhook run 26694739495 attempt 2 is terminal cancelled on job 78742102656.
  • Deploy Gate replacement 26694741061 is now in progress, and CI parent 26694741054 remains active/queued with CI Summary queued; those active parents were left alone.
  • Reran terminal webhook parent 26694739495 only.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Foreground tick update for #1789:

  • The second Artifact Reconciliation Webhook parent, run 26694740945 attempt 4, is terminal cancelled on job 78742103069.
  • Reran terminal webhook parent 26694740945.
  • Deploy Gate 26694741061 remains in progress and CI 26694741054 remains active/queued with CI Summary queued; those active parents are untouched.

@jonahgabriel
jonahgabriel enabled auto-merge May 31, 2026 18:57
auto-merge was automatically disabled May 31, 2026 21:35

Pull request was closed

@jonahgabriel jonahgabriel reopened this May 31, 2026
@jonahgabriel
jonahgabriel added this pull request to the merge queue May 31, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks May 31, 2026
@jonahgabriel
jonahgabriel added this pull request to the merge queue May 31, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks May 31, 2026
@jonahgabriel
jonahgabriel added this pull request to the merge queue May 31, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks May 31, 2026
@jonahgabriel
jonahgabriel added this pull request to the merge queue Jun 1, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Jun 1, 2026
@jonahgabriel
jonahgabriel added this pull request to the merge queue Jun 1, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Jun 1, 2026
@jonahgabriel
jonahgabriel added this pull request to the merge queue Jun 1, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Jun 1, 2026
@jonahgabriel
jonahgabriel added this pull request to the merge queue Jun 1, 2026
Merged via the queue into dev with commit 10a3b86 Jun 1, 2026
363 of 466 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-12432-ci-uv-sync-git-auth branch June 1, 2026 01:01
jonahgabriel added a commit that referenced this pull request Jun 1, 2026
Rebased onto dev (picks up the git-auth fix #1789, OMN-12432). Enables the
persistent uv cache via the setup-python-uv composite action across CI jobs,
while keeping cache-enabled: false on the cross-repo git+https fetch jobs that
dev deliberately protected (topic-enum-drift, type-safety, type-union-check) so
a stale cache restore cannot reintroduce the anonymous-rate-limit flake. Updates
test_required_ci_jobs_use_uv_cache_by_default to honor those exemptions and
fixes a pre-existing SPDX header year.
jonahgabriel added a commit that referenced this pull request Jun 1, 2026
Durable fix for the 2026-05-29 CI wedge. The runner Docker healthcheck was
pgrep -f Runner.Listener only - it passed even when a runner had silently
lost its connection to github.com. That let ~9 of 20 runners sit Up (healthy)
in Docker while OFFLINE in the GitHub pool, starving the merge queue.

- New docker/runners/healthcheck.sh: requires BOTH the Runner.Listener process
  AND a short-timeout (--max-time 8) github.com reachability probe. A runner
  that loses egress now goes unhealthy and is removed from rotation.
- Wired into the runner Dockerfile (baked) and mounted into every runner
  service in docker-compose.runners.yml so already-deployed runners pick it up
  on recreate.
- Dockerfile.runtime plugin external-dep install now retries on transient
  fetch failures (UV_HTTP_TIMEOUT + retry loop) so a degraded egress does not
  abort the runner image build.
- omni-standards-compliance.yml OCC git+https install hardened with
  UV_HTTP_TIMEOUT, HTTP/1.1 pin, and a retry loop on top of the OMN-12432
  authenticated fetch already on dev.
- Regression tests assert the script probes github.com, every runner service
  uses the egress healthcheck, and the OCC fetch retries.

Rebuilt on top of origin/dev (which already carries the OMN-12432 auth fixes
from #1789) to scope this PR to the egress-healthcheck delta and clear the
merge conflict.

Evidence-Source: OCC#1888
Evidence-Ticket: OMN-12433

OMN-12433
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant