Repository navigation
fix(OMN-13670): surgical main hotfix — re-apply OMN-13654 dep floors + OMN-13666 entrypoint tolerance (emergency prod recovery) - #2128
Merged
Conversation
…+ OMN-13666 entrypoint tolerance EMERGENCY PROD RECOVERY — OMN-13670 operator-authorized. NOT a normal dev->main promotion. OMN-13654: Bump pyjwt>=2.13.0, python-multipart>=0.0.30, starlette>=1.3.1 as explicit security-floor constraints in pyproject.toml. Relocks uv.lock (pyjwt 2.13.0, python-multipart 0.0.32, starlette 1.3.1). Resolves 5 HIGH CVEs that have been blocking build-and-push-runtime.yml since 2026-06-07 with Trivy exit-code 1. OMN-13666: Runtime entrypoint now treats PRIMARY (omnibase_infra) stamp as REQUIRED (failure aborts boot, exit 1) and SECONDARY (omniintelligence) stamp as BEST-EFFORT (failure logs WARNING, boot continues). Resolves the prod crash-loop where "permission denied for table db_metadata" on the omniintelligence DB was bringing all 7 prod runtime deployments to 0/1.
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
This was referenced Jun 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Context
EMERGENCY PROD RECOVERY — OMN-13670 (operator-authorized).
This is NOT a normal feature->dev->main promotion. This is a surgical hotfix applying only two already-reviewed-and-merged changes (dev PRs #2115 + #2124) directly to main, because:
build-and-push-runtime.yml) has been red since 2026-06-07 (5 HIGH CVEs block Trivy gate → ECR push never completes → no fresh prod image can be built).The prod re-pin (re-tagging ECR digest + restarting containers) follows separately and is OMN-13418-gated (requires fresh CODEOWNERS-approved prod promotion grant). This PR does NOT deploy, restart, or touch any cluster.
Changes
OMN-13654 — CVE dep floors + relock
pyproject.tomladds explicit security-floor constraints matching the existing pyjwt CVE-2026-32597 pattern:uv lockresolves: pyjwt 2.13.0, python-multipart 0.0.32, starlette 1.3.1. Trivy gate passes 0 HIGH/CRITICAL at these versions.DoD evidence (dod-001):
grep -q 'pyjwt>=2.13.0' pyproject.toml && grep -q 'python-multipart>=0.0.30' pyproject.toml && grep -q 'starlette>=1.3.1' pyproject.toml— passes.OMN-13666 — entrypoint stamp tolerance
docker/entrypoint-runtime.shintroduces a principled required-vs-best-effort stamp policy:omnibase_infra): stamp is REQUIRED — failure aborts boot (exit 1) so a NULL/stale-fingerprint kernel never starts silently.omniintelligence): stamp is BEST-EFFORT — failure logsWARNINGand boot continues. The runtime DB user legitimately lacks write permission on another service'sdb_metadatatable.New test file
tests/unit/docker/test_runtime_entrypoint_stamp_tolerance.pyprovides 7 behavioral + static tests covering all policy branches.DoD evidence (dod-001): static source guard:
stamp_fingerprint "omnibase_infra" "${OMNIBASE_INFRA_DB_URL}" "required"andstamp_fingerprint "omniintelligence" "${OMNIINTELLIGENCE_DB_URL}" "optional"both present.dod_evidence
Evidence-Ticket: OMN-13670
Evidence-Source: d605ea7966a73452c0210c917e23833f988762ae
Evidence-Class: hotfix
Active-Hotfix-PR: #2128
hotfix-evidence: OCC-3224
backmerge: #2124 (dev-equivalent entrypoint tolerance already merged; OMN-13654 dep floors merged via #2115)
Local gate results (2026-06-27):
uv run ruff format src/ tests/ && uv run ruff check --fix src/ tests/— 0 issuesuv run mypy src/ --strict— "Success: no issues found in 2442 source files"uv run pytest tests/unit/docker/test_runtime_entrypoint_stamp_tolerance.py -q— 7 passeduv run pytest tests/unit/docker/ tests/unit/runtime/ tests/unit/migrations/ -q— 5013 passed, 9 skipped, 0 failed (CI-mode: without OMNI_HOME)pre-commit run --files <changed-files>— all hooks pass (using OMNIMARKET_SRC=omnimarket@main, which is the correct comparison base for a main-targeting hotfix)Reconciliation Note
These hotfix commits are equivalent to dev PRs #2115 (OMN-13654) and #2124 (OMN-13666), which have already merged to dev. The changes were re-applied against the current main HEAD (commit
7200315b7) rather than cherry-picked, to avoid dragging any dev-state alongside.When the eventual full dev->main promotion lands (post-OMN-13418-approved prod re-pin), the dep floors and entrypoint changes will already be present on main. The promotion's merge will be clean: the dep version floor expressions are identical on both branches, and the entrypoint function signature and call sites are byte-for-byte equivalent.
Migration vendor tree: The
node-migration-syncCI check compares against omnimarket dev. The vendored tree in main is in sync with omnimarket main (verified locally:OMNIMARKET_SRC=<omnimarket@main> bash scripts/sync-node-migrations.sh --check→ "in sync"). The node-migration-sync workflow will show a non-fatal diff (omnimarket dev has progressed since the last main promotion) — this is expected for any main-targeting PR during a period where dev leads.node-migration-syncis NOT a required status check for main merge.Post-merge
Prod re-pin (ECR retag + container restart) follows as a separate step, OMN-13418-gated with fresh CODEOWNERS-approved grant.