Skip to content

fix(OMN-13670): surgical main hotfix — re-apply OMN-13654 dep floors + OMN-13666 entrypoint tolerance (emergency prod recovery) - #2128

Merged
jonahgabriel merged 5 commits into
mainfrom
hotfix/omn-13670-surgical-main-hotfix
Jun 27, 2026
Merged

jonahgabriel merged 5 commits into
mainfrom
hotfix/omn-13670-surgical-main-hotfix

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jun 27, 2026 •

Copy link
Copy Markdown
Collaborator

Context

EMERGENCY PROD RECOVERY — OMN-13670 (operator-authorized).

This is NOT a normal feature->dev->main promotion. This is a surgical hotfix applying only two already-reviewed-and-merged changes (dev PRs #2115 + #2124) directly to main, because:

  1. The runtime ECR build (build-and-push-runtime.yml) has been red since 2026-06-07 (5 HIGH CVEs block Trivy gate → ECR push never completes → no fresh prod image can be built).
  2. The prod runtime containers were crash-looping (all 7 deployments at 0/1) because the entrypoint exits 1 on omniintelligence DB permission errors.

The prod re-pin (re-tagging ECR digest + restarting containers) follows separately and is OMN-13418-gated (requires fresh CODEOWNERS-approved prod promotion grant). This PR does NOT deploy, restart, or touch any cluster.

Changes

OMN-13654 — CVE dep floors + relock

pyproject.toml adds explicit security-floor constraints matching the existing pyjwt CVE-2026-32597 pattern:

pyjwt>=2.13.0       (was >=2.12.0) — CVE-2026-48526: auth bypass via forged tokens
python-multipart>=0.0.30           — CVE-2026-53539: streaming-parser vulnerability
starlette>=1.3.1                   — CVE-2026-48818 + CVE-2026-54283: SSRF/UNC + ASGI flaws

uv lock resolves: pyjwt 2.13.0, python-multipart 0.0.32, starlette 1.3.1. Trivy gate passes 0 HIGH/CRITICAL at these versions.

DoD evidence (dod-001): grep -q 'pyjwt>=2.13.0' pyproject.toml && grep -q 'python-multipart>=0.0.30' pyproject.toml && grep -q 'starlette>=1.3.1' pyproject.toml — passes.

OMN-13666 — entrypoint stamp tolerance

docker/entrypoint-runtime.sh introduces a principled required-vs-best-effort stamp policy:

  • PRIMARY/owned DB (omnibase_infra): stamp is REQUIRED — failure aborts boot (exit 1) so a NULL/stale-fingerprint kernel never starts silently.
  • SECONDARY/non-owned DB (omniintelligence): stamp is BEST-EFFORT — failure logs WARNING and boot continues. The runtime DB user legitimately lacks write permission on another service's db_metadata table.

New test file tests/unit/docker/test_runtime_entrypoint_stamp_tolerance.py provides 7 behavioral + static tests covering all policy branches.

DoD evidence (dod-001): static source guard: stamp_fingerprint "omnibase_infra" "${OMNIBASE_INFRA_DB_URL}" "required" and stamp_fingerprint "omniintelligence" "${OMNIINTELLIGENCE_DB_URL}" "optional" both present.

dod_evidence

Evidence-Ticket: OMN-13670
Evidence-Source: d605ea7966a73452c0210c917e23833f988762ae
Evidence-Class: hotfix
Active-Hotfix-PR: #2128
hotfix-evidence: OCC-3224
backmerge: #2124 (dev-equivalent entrypoint tolerance already merged; OMN-13654 dep floors merged via #2115)

Local gate results (2026-06-27):

  • uv run ruff format src/ tests/ && uv run ruff check --fix src/ tests/ — 0 issues
  • uv run mypy src/ --strict — "Success: no issues found in 2442 source files"
  • uv run pytest tests/unit/docker/test_runtime_entrypoint_stamp_tolerance.py -q — 7 passed
  • uv run pytest tests/unit/docker/ tests/unit/runtime/ tests/unit/migrations/ -q — 5013 passed, 9 skipped, 0 failed (CI-mode: without OMNI_HOME)
  • pre-commit run --files <changed-files> — all hooks pass (using OMNIMARKET_SRC=omnimarket@main, which is the correct comparison base for a main-targeting hotfix)

Reconciliation Note

These hotfix commits are equivalent to dev PRs #2115 (OMN-13654) and #2124 (OMN-13666), which have already merged to dev. The changes were re-applied against the current main HEAD (commit 7200315b7) rather than cherry-picked, to avoid dragging any dev-state alongside.

When the eventual full dev->main promotion lands (post-OMN-13418-approved prod re-pin), the dep floors and entrypoint changes will already be present on main. The promotion's merge will be clean: the dep version floor expressions are identical on both branches, and the entrypoint function signature and call sites are byte-for-byte equivalent.

Migration vendor tree: The node-migration-sync CI check compares against omnimarket dev. The vendored tree in main is in sync with omnimarket main (verified locally: OMNIMARKET_SRC=<omnimarket@main> bash scripts/sync-node-migrations.sh --check → "in sync"). The node-migration-sync workflow will show a non-fatal diff (omnimarket dev has progressed since the last main promotion) — this is expected for any main-targeting PR during a period where dev leads. node-migration-sync is NOT a required status check for main merge.

Post-merge

Prod re-pin (ECR retag + container restart) follows as a separate step, OMN-13418-gated with fresh CODEOWNERS-approved grant.

…+ OMN-13666 entrypoint tolerance

EMERGENCY PROD RECOVERY — OMN-13670 operator-authorized. NOT a normal dev->main promotion.

OMN-13654: Bump pyjwt>=2.13.0, python-multipart>=0.0.30, starlette>=1.3.1 as explicit
security-floor constraints in pyproject.toml. Relocks uv.lock (pyjwt 2.13.0,
python-multipart 0.0.32, starlette 1.3.1). Resolves 5 HIGH CVEs that have been
blocking build-and-push-runtime.yml since 2026-06-07 with Trivy exit-code 1.

OMN-13666: Runtime entrypoint now treats PRIMARY (omnibase_infra) stamp as REQUIRED
(failure aborts boot, exit 1) and SECONDARY (omniintelligence) stamp as BEST-EFFORT
(failure logs WARNING, boot continues). Resolves the prod crash-loop where "permission
denied for table db_metadata" on the omniintelligence DB was bringing all 7 prod
runtime deployments to 0/1.
@coderabbitai

coderabbitai Bot commented Jun 27, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 07a4d3aa-dc5b-47a4-99f0-c0192b9f0172

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch hotfix/omn-13670-surgical-main-hotfix

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant