Skip to content

feat(OMN-14288): enforcement + merge-policy parity ratchet (report-only) - #2250

Merged
jonahgabriel merged 2 commits into
devfrom
jonah/omn-14288-required-context-parity-ratchet
Jul 10, 2026
Merged

jonahgabriel merged 2 commits into
devfrom
jonah/omn-14288-required-context-parity-ratchet

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jul 10, 2026 •

Copy link
Copy Markdown
Collaborator

OMN-14288 — enforcement + merge-policy parity ratchet (REPORT-ONLY)

Closes OMN-14288 (build phase; report-only). Head pinned to c0916ed2 (bound by the shared OCC companion onex_change_control#3837).

Makes the FULL per-repo dev branch-protection policy deterministic config-as-data,
asserted against live state by one parity ratchet — two dimensions in one manifest.

1. Enforcement dimension (load_bearing_gates[])

Closes the MISSING-direction hole: the existing branch-protection auditor only
checks the ORPHANED direction; it never checks whether a load-bearing gate
CLAUDE.md claims is enforced is actually in live required_status_checks. That
hole left deploy-gate + reject-skip unenforced on omnimarket/omniclaude dev
(contexts == ["CI Summary"]; both gates in separate workflow files, unreachable
via CI Summary's intra-workflow needs: closure). Adds MISSING,
NEEDS_CLOSURE, UNPROTECTED.

2. Merge-policy dimension (merge_policy: {queue, strict})

Records the DECIDED merge policy (queue disabled on all dev branches; strict
true on the two dashboards) and flags live drift: QUEUE_DRIFT / STRICT_DRIFT.
Rationale: a merge queue's only unique value is the merge_group
re-test-against-latest-base, which wedges the saturated self-hosted fleet; required
contexts fire on pull_request, so disabling the dev queue loses no enforcement
(strict is the lighter combine-breakage guard).

Files

  • scripts/enforcement_parity_manifest.yaml — one org-wide manifest,
    {repo → branch → {load_bearing_gates[], merge_policy}}.
  • scripts/audit_branch_protection_lib.py — PURE, unit-tested parity logic.
  • scripts/audit_required_context_parity_cli.py — thin gh/GraphQL/YAML CLI, REPORT-ONLY.
  • .github/workflows/branch-protection-audit.yml — non-blocking report-only step.
  • tests/ci/test_required_context_parity.py — unit tests incl. M1–M4 + drift regressions.

Live report (report-only)

Reproduces the confirmed MISSING findings — omnimarket + omniclaude deploy-gate
and reject-skip (M1–M4) — with omnibase_core/omnibase_infra clean and omnimarket
occ-preflight (needs_child) correctly COVERED via its aggregator's needs: closure.

FAST-FOLLOW (documented, intentionally not applied here)

At this pinned head the manifest records omnibase_spi.dev.merge_policy.strict: false
(its value when this head was authored). omnibase_spi has since been brought into the
decided policy (dev queue disabled + strict enabled, verified live), so the
report-only ratchet now emits a harmless spi STRICT_DRIFT report-only
false-positive
here. The strict: true manifest correction is deferred to the next
manifest touch (or the enforce-flip) on purpose: re-heading #2250 now would
staleify the shared OCC companion (onex_change_control#3837, bound to c0916ed2) and
force a re-author + re-queue through the saturated fleet — not worth it for a 1-line
report-only value.

Guardrails honored

dod_evidence

  • Parity + existing-auditor unit tests pass; ruff + mypy clean on the new modules.
  • Live report reproduces confirmed M1–M4; merge-policy drift detection exercised.

OCC companion: shared onex_change_control#3837, bound to this head c0916ed2. NOT self-authored (no-self-authored-evidence rule).

Do not merge/arm — Codex lands.


Evidence-Source: OCC#3837
Evidence-Ticket: OMN-14288

Evidence-Commit: bae37a0359453e36cf446447ce9dd741e31da6ac

Extend the branch-protection auditor (OMN-9034) to close the MISSING-direction
hole the enforcement-parity audit confirmed: the existing Check A/B only cover
the ORPHANED direction (a required context that no longer reports), never the
MISSING direction (a load-bearing gate CLAUDE.md CLAIMS is enforced but is
absent from live required_status_checks). That hole left deploy-gate +
reject-skip UNENFORCED on omnimarket/omniclaude dev (contexts=['CI Summary']).

- scripts/audit_branch_protection_lib.py: add PURE, unit-tested parity logic
  (normalize_context_forms with reusable-context fuzzy-leaf matching,
  is_gate_directly_required, compute_needs_closure, evaluate_gate_parity,
  evaluate_manifest_parity). No yaml/network deps so existing Check A/B tests
  keep running under bare python3.
- scripts/enforcement_parity_manifest.yaml: single machine-asserted org-wide
  manifest {repo -> branch -> load_bearing_gates[]}, coverage=direct|needs_child.
  Replaces the per-repo honor-system .github/required-checks.yaml.
- scripts/audit_required_context_parity_cli.py: thin gh/YAML I/O CLI, REPORT-ONLY
  (never mutates branch protection, always exit 0; --fail-on-findings reserved
  for the future enforcing gate).
- .github/workflows/branch-protection-audit.yml: non-blocking report-only step.
- tests/ci/test_required_context_parity.py: unit tests incl. a regression class
  pinning the confirmed M1-M4 findings.

Live report reproduces M1-M4 (omnimarket+omniclaude deploy-gate+reject-skip
MISSING) with core/infra clean and omnimarket occ-preflight covered via
needs-closure. Does NOT mutate branch protection; does NOT flip to enforcing.
@coderabbitai

coderabbitai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 14 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 675a7e75-e1bb-48de-8a20-6a607e9d068e

📥 Commits

Reviewing files that changed from the base of the PR and between 6981665 and c0916ed.

📒 Files selected for processing (6)
  • .github/workflows/branch-protection-audit.yml
  • CLAUDE.md
  • scripts/audit_branch_protection_lib.py
  • scripts/audit_required_context_parity_cli.py
  • scripts/enforcement_parity_manifest.yaml
  • tests/ci/test_required_context_parity.py
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-14288-required-context-parity-ratchet

Comment @coderabbitai help to get the list of available commands.

…-only)

Fold the deterministic merge policy into the same config-as-data manifest the
required-context ratchet already uses — one manifest asserts enforcement AND
merge policy. Still REPORT-ONLY; no branch-protection mutation.

- scripts/enforcement_parity_manifest.yaml: schema is now
  {repo -> branch -> {load_bearing_gates[], merge_policy{queue,strict}}}. Records
  the DECIDED policy: queue=disabled on ALL dev branches; strict=true on the two
  dashboards (omnidash, omnibase_compat), recorded as-is elsewhere. Adds the four
  merge-policy-only dev repos (onex_change_control, omnidash, omnibase_compat,
  omnibase_spi). Live values verified 2026-07-10.
- scripts/audit_branch_protection_lib.py: add PARITY_QUEUE_DRIFT / PARITY_STRICT_DRIFT
  + pure evaluate_merge_policy_parity(); integrate into evaluate_manifest_parity.
- scripts/audit_required_context_parity_cli.py: fetch live strict (from
  required_status_checks.strict) + live merge-queue state (parameterized GraphQL
  mergeQueue(branch:)); render a MERGE-POLICY drift block.
- tests: add merge-policy unit tests + a regression pinning the live-verified
  omnibase_spi QUEUE_DRIFT (spi dev still has a queue vs the decided disabled).
- CLAUDE.md: document both dimensions + the merge-queue rationale.

Live report (report-only): 4 MISSING (M1-M4) + 1 QUEUE_DRIFT (omnibase_spi dev
still has a live merge queue against the decided queue=disabled policy) — the
merge-policy dimension caught real drift the "all disabled" belief had missed.
Remediating spi's queue is a separate operator/admin action; this ratchet does
not mutate branch protection.
@jonahgabriel jonahgabriel changed the title feat(OMN-14288): required-context parity ratchet (report-only) feat(OMN-14288): enforcement + merge-policy parity ratchet (report-only) Jul 10, 2026
@jonahgabriel
jonahgabriel force-pushed the jonah/omn-14288-required-context-parity-ratchet branch from 09c3b66 to c0916ed Compare July 10, 2026 19:22
@jonahgabriel
jonahgabriel merged commit 3cbb95a into dev Jul 10, 2026
339 of 510 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-14288-required-context-parity-ratchet branch July 10, 2026 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant