Skip to content

fix(OMN-12987): deploy-runtime.sh sibling lock-pin preflight uses current --lock/--repo/--output interface - #1977

Merged
jonahgabriel merged 1 commit into
devfrom
jonah/omn-12987-deploy-runtime-caller-fix
Jun 14, 2026
Merged

jonahgabriel merged 1 commit into
devfrom
jonah/omn-12987-deploy-runtime-caller-fix

Conversation

@jonahgabriel

Copy link
Copy Markdown
Collaborator

Summary

The OMN-12987 sibling lock-pin preflight in scripts/deploy-runtime.sh called check_sibling_lock_pins.py with the removed --provenance-out flag. The script's interface changed under OMN-12977/12987 (the workspace-build sibling-pin recurrence ratchet) to require:

  • --lock (the omnimarket uv.lock pin authority, required)
  • repeatable --repo PACKAGE=PATH (the canonical clones the build vendors; at least one required)
  • --output (where to write the expected-vs-actual comparison JSON)

The stale caller meant EVERY workspace --execute deploy failed at argparse (the following arguments are required: --lock) before any build started. It blocked the clean stability-test rebuild; the dev redeploy only worked because it used a different build script.

Change

check_sibling_lock_pins() now builds guard_args with the current interface — behavior is identical:

  • --lock "${omni_home}/omnimarket/uv.lock" (same pin authority)
  • one --repo PACKAGE=PATH per vendored sibling: omnibase-infra, omnibase-core, omnibase-spi, omnibase-compat, onex-change-control (the valid set per DEFAULT_PACKAGE_REPO_DIRS)
  • --output "${provenance_out}" → the unchanged workspace/sibling-repos/.sibling-lock-pins.json destination (still rides into the build image the same way)
  • same fail-fast abort (Refusing to build a stale image)
  • honors ALLOW_SIBLING_PIN_DRIFT=1 → --allow-drift (the OMN-12977 explicit operator override)

Adds test_deploy_runtime_uses_current_lock_pin_preflight_interface: a permanent regression guard asserting the removed flag is gone and the current flags are wired, so the stale-flag invocation cannot return.

Tests / proof

uv run pytest tests/scripts/test_deploy_runtime_build_context.py tests/scripts/test_check_sibling_lock_pins.py -v → 14 passed.

RE-PROVE (non-mutating, against canonical clones):

  • old --provenance-out invocation → error: the following arguments are required: --lock (exit 2) — the bug.
  • corrected --lock/--repo/--output invocation → guard runs and aborts on real clone drift (exit 1, its job); no --provenance-out unrecognized, no stale-flag failure.
  • corrected + ALLOW_SIBLING_PIN_DRIFT=1 → --allow-drift → exit 0, comparison artifact written.

bash -n clean; ruff + pre-commit (--files) clean. No bypass / skip token. No live deploy/restart/topic/.201 mutation performed.

(Re-opened from #1976 on a ticket-named branch to satisfy the Receipt-Gate identity binding — same commit ba82d615.)

Evidence-Ticket: OMN-12987
Evidence-Source: OCC#2617

…rent --lock/--repo/--output interface

The OMN-12987 sibling lock-pin preflight in scripts/deploy-runtime.sh
called check_sibling_lock_pins.py with the removed --provenance-out flag.
The script's interface changed under OMN-12977/12987 (the workspace-build
sibling-pin recurrence ratchet) to require --lock (the omnimarket uv.lock
pin authority), repeatable --repo PACKAGE=PATH (the canonical clones the
build vendors), and --output (where to write the comparison JSON).

The stale caller meant EVERY workspace --execute deploy failed at argparse
("the following arguments are required: --lock") before any build started.
It blocked the clean stability-test rebuild; the dev redeploy only worked
because it used a different build script.

Fix: build guard_args with --lock ${OMNI_HOME}/omnimarket/uv.lock, one
--repo entry per vendored sibling (omnibase-infra/core/spi/compat,
onex-change-control), and --output to the existing comparison destination
(workspace/sibling-repos/.sibling-lock-pins.json). Behavior is identical:
same lock authority, same repo paths, same output destination, same
fail-fast abort. Honors ALLOW_SIBLING_PIN_DRIFT=1 -> --allow-drift, the
OMN-12977 explicit operator override.

Adds test_deploy_runtime_uses_current_lock_pin_preflight_interface: a
permanent regression guard asserting the removed flag is gone and the
current flags are wired, so the stale-flag invocation cannot return.

No bypass, no skip token. No live deploy/restart/mutation performed.

Refs OMN-12987, OMN-12977.
@coderabbitai

coderabbitai Bot commented Jun 14, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@jonahgabriel, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 1 hour, 11 minutes, and 41 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: baea76e9-716d-444c-8724-a1d079e4aa6d

📥 Commits

Reviewing files that changed from the base of the PR and between d703ca7 and ba82d61.

📒 Files selected for processing (2)
  • scripts/deploy-runtime.sh
  • tests/scripts/test_deploy_runtime_build_context.py
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-12987-deploy-runtime-caller-fix

Comment @coderabbitai help to get the list of available commands and usage tips.

@jonahgabriel
jonahgabriel added this pull request to the merge queue Jun 14, 2026
Merged via the queue into dev with commit 7bbb06e Jun 14, 2026
117 of 119 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-12987-deploy-runtime-caller-fix branch June 14, 2026 03:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant