Repository navigation
fix(OMN-12987): deploy-runtime.sh sibling lock-pin preflight uses current --lock/--repo/--output interface - #1977
Conversation
…rent --lock/--repo/--output interface
The OMN-12987 sibling lock-pin preflight in scripts/deploy-runtime.sh
called check_sibling_lock_pins.py with the removed --provenance-out flag.
The script's interface changed under OMN-12977/12987 (the workspace-build
sibling-pin recurrence ratchet) to require --lock (the omnimarket uv.lock
pin authority), repeatable --repo PACKAGE=PATH (the canonical clones the
build vendors), and --output (where to write the comparison JSON).
The stale caller meant EVERY workspace --execute deploy failed at argparse
("the following arguments are required: --lock") before any build started.
It blocked the clean stability-test rebuild; the dev redeploy only worked
because it used a different build script.
Fix: build guard_args with --lock ${OMNI_HOME}/omnimarket/uv.lock, one
--repo entry per vendored sibling (omnibase-infra/core/spi/compat,
onex-change-control), and --output to the existing comparison destination
(workspace/sibling-repos/.sibling-lock-pins.json). Behavior is identical:
same lock authority, same repo paths, same output destination, same
fail-fast abort. Honors ALLOW_SIBLING_PIN_DRIFT=1 -> --allow-drift, the
OMN-12977 explicit operator override.
Adds test_deploy_runtime_uses_current_lock_pin_preflight_interface: a
permanent regression guard asserting the removed flag is gone and the
current flags are wired, so the stale-flag invocation cannot return.
No bypass, no skip token. No live deploy/restart/mutation performed.
Refs OMN-12987, OMN-12977.
|
Warning Review limit reached
More reviews will be available in 1 hour, 11 minutes, and 41 seconds. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Summary
The OMN-12987 sibling lock-pin preflight in
scripts/deploy-runtime.shcalledcheck_sibling_lock_pins.pywith the removed--provenance-outflag. The script's interface changed under OMN-12977/12987 (the workspace-build sibling-pin recurrence ratchet) to require:--lock(the omnimarketuv.lockpin authority, required)--repo PACKAGE=PATH(the canonical clones the build vendors; at least one required)--output(where to write the expected-vs-actual comparison JSON)The stale caller meant EVERY workspace
--executedeploy failed at argparse (the following arguments are required: --lock) before any build started. It blocked the clean stability-test rebuild; the dev redeploy only worked because it used a different build script.Change
check_sibling_lock_pins()now buildsguard_argswith the current interface — behavior is identical:--lock "${omni_home}/omnimarket/uv.lock"(same pin authority)--repo PACKAGE=PATHper vendored sibling:omnibase-infra,omnibase-core,omnibase-spi,omnibase-compat,onex-change-control(the valid set perDEFAULT_PACKAGE_REPO_DIRS)--output "${provenance_out}"→ the unchangedworkspace/sibling-repos/.sibling-lock-pins.jsondestination (still rides into the build image the same way)Refusing to build a stale image)ALLOW_SIBLING_PIN_DRIFT=1→--allow-drift(the OMN-12977 explicit operator override)Adds
test_deploy_runtime_uses_current_lock_pin_preflight_interface: a permanent regression guard asserting the removed flag is gone and the current flags are wired, so the stale-flag invocation cannot return.Tests / proof
uv run pytest tests/scripts/test_deploy_runtime_build_context.py tests/scripts/test_check_sibling_lock_pins.py -v→ 14 passed.RE-PROVE (non-mutating, against canonical clones):
--provenance-outinvocation →error: the following arguments are required: --lock(exit 2) — the bug.--lock/--repo/--outputinvocation → guard runs and aborts on real clone drift (exit 1, its job); no--provenance-out unrecognized, no stale-flag failure.ALLOW_SIBLING_PIN_DRIFT=1→--allow-drift→ exit 0, comparison artifact written.bash -nclean; ruff + pre-commit (--files) clean. No bypass / skip token. No live deploy/restart/topic/.201 mutation performed.(Re-opened from #1976 on a ticket-named branch to satisfy the Receipt-Gate identity binding — same commit
ba82d615.)Evidence-Ticket: OMN-12987
Evidence-Source: OCC#2617