Skip to content

ci(OMN-14172): roll out integration silent-skip guard to omnibase_infra - #2242

Merged
jonahgabriel merged 4 commits into
devfrom
jonah/omn-14172-infra-silent-skip-rollout
Jul 9, 2026
Merged

jonahgabriel merged 4 commits into
devfrom
jonah/omn-14172-infra-silent-skip-rollout

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jul 9, 2026 •

Copy link
Copy Markdown
Collaborator

OMN-14172 — integration silent-skip guard rollout to omnibase_infra

Rolls out the integration silent-skip false-green guard (canary landed in
omnimarket #1652, MERGED) to the next queue repo, omnibase_infra. This is
enforcement-not-detection: the CI gate + pre-commit hook ship in the same PR
(Operating Rule #5).

What a silent-skip false-green is

An @pytest.mark.integration real-DB test that self-skips because Postgres looks
absent turns the required Tests job green while the real-DB assertion never
ran
. In omnibase_infra the analogous real-DB proof is the OMN-9041 UUID-cast
regression guard
(test_registration_storage_postgres_uuid_cast.py) — a
production crash a silent Postgres-absent skip would have hidden.

Changes

  • scripts/ci/check_integration_skips.py — fail-closed stdlib+yaml gate copied
    from the canary; infra-adapted --selftest fixtures (case-a PASS / case-b RED)
    use infra's real curated test IDs + verbatim skip strings.
  • scripts/ci/integration_skip_guard.yaml — calibrated for omnibase_infra
    (see calibration evidence below).
  • .github/workflows/ci.yml — new integration-guard job: provisions
    postgres:16-alpine (mirrors migration-integration), applies all migrations
    (scripts/run-migrations.py), exports OMNIBASE_INFRA_DB_URL + POSTGRES_*,
    runs the curated Postgres-only proofs with --junitxml, then enforces
    check_integration_skips.py (fail-closed).
  • scripts/ci/ci_summary_gate.py — added the job's display name to
    SKIPPABLE_GATE_JOBS so it BLOCKS via the existing CI Summary
    umbrella required context (same tier as migration-integration; the
    default-deny sweep also fails CI Summary on any non-success/skipped result).
  • .pre-commit-config.yaml — integration-skip-guard hook (--selftest, no DB).
  • tests/ci/test_check_integration_skips.py — case-a PASS + case-b RED
    regression proofs plus full Postgres-absence-vocabulary coverage.

Calibration (grep evidence)

The canonical PostgresConfig.from_env() (tests/helpers/util_postgres.py)
reads only OMNIBASE_INFRA_DB_URL; other conftests read
POSTGRES_HOST/PORT/PASSWORD/USER/DATABASE. The job exports both conventions.

required_services.postgres.missing_skip_patterns covers the full Postgres-absence
skip vocabulary grepped from tests/, e.g.:

  • PostgreSQL integration tests skipped — test_postgres_repository_runtime_integration.py:124
  • PostgreSQL not available — test_registration_storage_postgres_uuid_cast.py:76, dlq/conftest.py:212, snapshot/...:35/87
  • PostgreSQL not configured / not reachable — ledger/conftest.py:61, injection_effectiveness/conftest.py:78/86
  • Database not configured / Database not reachable — runtime/test_projector_shell_database.py:145/157
  • No database URL configured — verification/test_registration_contract_verify.py:50

Explicitly allowlisted (not provisioned by this job, never a false-green):
Kafka/Redpanda broker, Consul, Vault, Qdrant, Valkey, live-LLM SLO probes,
Docker-in-Docker, and the catalog-data skip postgres manifest not found in catalog (test_catalog_extra_networks.py:80) which names "postgres" but is not
a service absence.

Curated executor set (curated_test_paths, mirrors the omnimarket 2-proof
canary): both are Postgres-only and self-contained against a freshly-migrated DB
— test_postgres_repository_runtime_integration.py creates its own table;
test_registration_storage_postgres_uuid_cast.py uses the migration-created
registration_projections table.

Local proof

  • check_integration_skips.py --selftest → SELFTEST PASSED (case-a PASS,
    case-b RED, 3 violations).
  • Explicit case-a junit → gate PASS (exit 0); explicit case-b junit
    (both curated proofs silently skip) → gate RED (exit 1).
  • tests/ci/test_check_integration_skips.py → 12 passed;
    test_ci_summary_gate.py + test_ci_workflow_resilience.py → 64 passed
    (ci.yml + gate-list changes don't break workflow-structure tests).
  • ruff format (unchanged) + ruff check (clean) + mypy (3 files, clean) +
    pre-commit run --files <changed> → all Passed (SPDX, yamlfmt, new hook).

Deferred to operator/Codex (do NOT do in this PR)

  • Required-context registration is DEFERRED. No new branch-protection
    required status context is registered here — the job blocks via the existing
    CI Summary umbrella. The operator/Codex should register/confirm once the job
    proves green on real PRs. (scripts/audit-branch-protection.sh --repo omnibase_infra --dry-run already reports a pre-existing Check-B FAIL for
    CI Summary / Handler Contract Compliance / verify / verify /
    call-reject-skip-token contexts not appearing on the last-5 commits — this PR
    does not touch branch protection and does not add to that set.)
    Evidence-Source: OCC#3748
    Evidence-Ticket: OMN-14172

  • Central OCC evidence merged in onex_change_control#3748 for the refreshed omnibase_infra rollout head and superseded legacy whole-file receipts with per-entry bindings.

Closes OMN-14172

Summary by CodeRabbit

  • New Features

    • Added a new CI and pre-commit check to catch integration tests that silently skip when required services are unavailable.
    • Added a curated Postgres integration run in CI to verify key database-backed tests actually execute.
  • Bug Fixes

    • Improved protection against false-green test results by failing builds when too few integration tests run or when required-service skips are detected.
    • Updated a live Postgres integration test setup to auto-create the schema for better reliability.

Enforcement-not-detection rollout of the OMN-14172 silent-skip false-green
guard (omnimarket canary #1652, MERGED) to omnibase_infra — CI gate +
pre-commit hook ship in the same PR (Operating Rule #5):

- scripts/ci/check_integration_skips.py + integration_skip_guard.yaml,
  calibrated for infra's real Postgres-absence skip vocabulary (grepped
  from tests/); allowlists Kafka/Consul/Vault/Qdrant/live/catalog skips
- new `integration-guard` CI job: provisions postgres:16-alpine (mirrors
  migration-integration), applies all migrations, exports OMNIBASE_INFRA_DB_URL
  + POSTGRES_* env, runs the curated Postgres-only proofs with --junitxml,
  then enforces check_integration_skips.py (fail-closed)
- wired BLOCKING via ci_summary_gate.py SKIPPABLE_GATE_JOBS (the CI Summary
  umbrella required context); NO new branch-protection required context is
  registered here — deferred to operator/Codex once green on real PRs
- integration-skip-guard pre-commit hook (--selftest, no DB needed)
- tests/ci/test_check_integration_skips.py: case-(a) PASS + case-(b) RED
  regression proof plus full-vocabulary coverage

OCC companion owed: omnibase_infra verify/receipt-gate needs
Evidence-Source: OCC#<n> (Codex authors).
@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 29 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: b4ea6e8b-ec13-42bf-a695-09e9da265859

📥 Commits

Reviewing files that changed from the base of the PR and between 99fe3ca and 2e84846.

📒 Files selected for processing (3)
  • .github/workflows/ci.yml
  • .pre-commit-config.yaml
  • scripts/ci/integration_skip_guard.yaml
📝 Walkthrough

Walkthrough

Adds a CI "Integration Silent-Skip Guard" that parses JUnit XML to detect false-green silent skips of provisioned services, backed by a new config YAML and Python script with self-tests. Wires the guard into the CI workflow, pre-commit hooks, and CI summary gate; adds unit tests and a minor Postgres test fixture change.

Changes

Integration Silent-Skip Guard

Layer / File(s) Summary
Guard configuration and data models
scripts/ci/integration_skip_guard.yaml, scripts/ci/check_integration_skips.py
Defines silent_skip_allowed, curated Postgres test paths, minimum executed threshold, required-service missing-skip regex patterns, and allowed optional skip patterns; adds SkipRecord, GuardConfig, ReportStats dataclasses with GuardConfig.load().
Core evaluation logic
scripts/ci/check_integration_skips.py
Implements parse_junit (JUnit aggregation), classify_skip (skip-reason matching), evaluate (violation detection incl. under-collection), run_gate (execution/reporting), synthetic self-test fixtures, selftest(), and main() CLI with fail-closed exit codes.
Unit tests for guard logic
tests/ci/test_check_integration_skips.py
Covers provisioned vs silent-skip scenarios, Kafka/catalog non-false-green cases, all Postgres absence strings, zero-collection, missing report, strict-mode unclassified skips, and embedded selftest.
CI/pre-commit/gate wiring
.github/workflows/ci.yml, .pre-commit-config.yaml, scripts/ci/ci_summary_gate.py, tests/integration/handlers/test_registration_storage_postgres_uuid_cast.py
Adds a new blocking CI job provisioning Postgres and running the curated integration proof plus guard check; adds a pre-commit selftest hook; registers the new gate name as skippable in SKIPPABLE_GATE_JOBS; enables auto_create_schema=True in the curated Postgres UUID cast test fixture.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Sequence Diagram(s)

sequenceDiagram
  participant CIWorkflow as CI Workflow
  participant Postgres as Postgres Service
  participant IntegrationTests as Curated Integration Tests
  participant GuardScript as check_integration_skips.py
  participant CISummary as CI Summary Gate

  CIWorkflow->>Postgres: provision + run migrations
  CIWorkflow->>IntegrationTests: run curated Postgres tests, produce JUnit XML
  IntegrationTests-->>CIWorkflow: JUnit report
  CIWorkflow->>GuardScript: run_gate(junit report, config)
  GuardScript->>GuardScript: parse_junit, classify_skip, evaluate
  GuardScript-->>CIWorkflow: exit code 0/1/2 + JUnit artifact
  CIWorkflow->>CISummary: report job conclusion
  CISummary->>CISummary: check SKIPPABLE_GATE_JOBS for guard job
Loading

Possibly related PRs

  • OmniNode-ai/omnibase_infra#2229: Both PRs add new named CI jobs to scripts/ci/ci_summary_gate.py's gate-evaluation configuration.
  • OmniNode-ai/omnibase_infra#2230: Both PRs modify scripts/ci/ci_summary_gate.py, with the retrieved PR introducing the fail-closed evaluator and SKIPPABLE_GATE_JOBS list that this PR extends.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the main change: rolling out the integration silent-skip guard to omnibase_infra.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-14172-infra-silent-skip-rollout

Comment @coderabbitai help to get the list of available commands.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Temporarily closing/reopening to refresh stale OCC-preflight pull_request payloads after central Evidence-Source OCC#3746 merged; head SHA unchanged.

@jonahgabriel jonahgabriel reopened this Jul 9, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.pre-commit-config.yaml:
- Around line 825-826: The `files` pattern in the pre-commit config has
unintended leading spaces in the alternation branches, so only the first path
matches correctly. Update the regex in the `files` entry to remove the spaces
after each `|` while keeping the same targets, so the hook matches
`scripts/ci/check_integration_skips.py`,
`scripts/ci/integration_skip_guard.yaml`,
`tests/ci/test_check_integration_skips.py`, `.github/workflows/ci.yml`,
`tests/integration/runtime/db/test_postgres_repository_runtime_integration.py`,
and `tests/integration/handlers/test_registration_storage_postgres_uuid_cast.py`
as intended.

In `@scripts/ci/integration_skip_guard.yaml`:
- Around line 34-41: The integration-guard workflow selection is missing the
second curated Postgres proof, so it only runs the registration storage test.
Update the curated test selection in the ci workflow to stay in sync with
scripts/ci/integration_skip_guard.yaml and include
test_postgres_repository_runtime_integration alongside
test_registration_storage_postgres_uuid_cast, using the existing
integration-guard step as the reference point.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: d59bc6c2-1247-4f81-8327-7f5c3609ce6d

📥 Commits

Reviewing files that changed from the base of the PR and between 0c8a9d6 and 99fe3ca.

📒 Files selected for processing (7)
  • .github/workflows/ci.yml
  • .pre-commit-config.yaml
  • scripts/ci/check_integration_skips.py
  • scripts/ci/ci_summary_gate.py
  • scripts/ci/integration_skip_guard.yaml
  • tests/ci/test_check_integration_skips.py
  • tests/integration/handlers/test_registration_storage_postgres_uuid_cast.py

Comment thread .pre-commit-config.yaml Outdated
Comment thread scripts/ci/integration_skip_guard.yaml
@jonahgabriel
jonahgabriel merged commit 5f12933 into dev Jul 9, 2026
124 of 128 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-14172-infra-silent-skip-rollout branch July 9, 2026 08:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant