Skip to content

fix(OMN-14350): CI-enforce non-canonical ratchet (dedicated workflow) - #2259

Merged
jonahgabriel merged 3 commits into
devfrom
jonah/omn-14350-infra-ci-enforce
Jul 11, 2026
Merged

jonahgabriel merged 3 commits into
devfrom
jonah/omn-14350-infra-ci-enforce

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jul 11, 2026 •

Copy link
Copy Markdown
Collaborator

OMN-14350 — CI-enforce the non-canonical ratchet (omnibase_infra, fix-forward)

Follow-up to the merged fan-out: the ratchet was pre-commit-hook-only and omnibase_infra runs pre-commit by-changed-files / by-id in CI, so the hook never ran on the merge path (Rule-#5 gap; a missing gate shows no red check, so nothing blocked the original merge). This adds the dedicated blocking .github/workflows/noncanonical-lifecycle-gate.yml job — the same one already CI-green on market/claude/spi/compat — so the ratchet is a real merge gate.

dod_evidence

  • Job runs uv run --no-project --with 'omnibase-core @ git+...@63635097705d832e0ee9c4811093efb31349105c' python -m ...no_noncanonical... --check-stale on pull_request, no OCC dependency; proven green on 4 sibling repos.
  • Locally validated green (env -u PYTHONPATH) against this repo's frozen allowlist.
  • Stale HOLD-placeholder comment dropped.

Closes OMN-14350 (CI-enforcement follow-up).

Summary by CodeRabbit

  • CI Improvements
    • Added an automated check to prevent non-canonical lifecycle classes from being introduced.
    • The check now runs as a required part of the continuous integration success criteria.
    • Updated development tooling guidance to reflect the new validation and merge-gating process.

Evidence-Source: OCC#3931
Evidence-Commit: d8b547b6ed70deae40fb70b9a6be2b2b492cb5c6
Evidence-Ticket: OMN-14350

Add the dedicated blocking noncanonical-lifecycle-gate.yml (uniform with
market/claude/spi/compat) so the ratchet is a real merge-gating CI check, not
just an advisory pre-commit hook. Drop the now-stale HOLD-placeholder comment
(SHA pinned, PR live). Pinned to core dev @63635097705d832e0ee9c4811093efb31349105c.
@coderabbitai

coderabbitai Bot commented Jul 11, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds an unconditional CI job for noncanonical lifecycle-class validation, pins its Python and uv toolchain dependencies, updates related pre-commit guidance, and includes the job in strict CI Summary gate evaluation.

Changes

Noncanonical lifecycle validation

Layer / File(s) Summary
Strict lifecycle gate integration
.github/workflows/ci.yml, .pre-commit-config.yaml, scripts/ci/ci_summary_gate.py
The CI workflow runs the pinned validator with a frozen allowlist, pre-commit guidance documents the pinned revision and workflow gate, and strict gate evaluation requires the new job to complete successfully.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title captures the main change: enforcing the non-canonical ratchet in CI, though "dedicated workflow" is slightly broader than the implementation.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-14350-infra-ci-enforce

Comment @coderabbitai help to get the list of available commands.

… gate)

The standalone noncanonical-lifecycle-gate.yml ran green but GATED NOTHING — it
wasn't in required_status_checks and CI Summary (the required gate) didn't depend
on it (separate workflow = separate run, invisible to the CI Summary poller).

Move the ratchet INTO ci.yml as a job + register it in
scripts/ci/ci_summary_gate.py STRICT_GATE_JOBS so CI Summary WAITS for it and
requires success — a red ratchet now fails the required 'CI Summary' check.
Chose STRICT_GATE_JOBS over the default-deny sweep because the sweep only
inspects COMPLETED jobs: a fast ratchet finishing after the slow gates could let
CI Summary pass before the ratchet reports (race). Strict = no race.

Delete the now-redundant standalone workflow. gate-script unit tests pass (21).

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
.github/workflows/ci.yml (1)

1545-1574: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win

Pin the remaining actions in this job
actions/setup-python@v6 and astral-sh/setup-uv@v7 are still tag-pinned; pin them to release SHAs like actions/checkout in the same job.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml around lines 1545 - 1574, Pin the remaining
third-party actions in the no-noncanonical-lifecycle-classes job to immutable
release commit SHAs. Update the actions/setup-python and astral-sh/setup-uv uses
entries, preserving their current release versions as comments and leaving the
checkout step unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.pre-commit-config.yaml:
- Around line 72-74: Update the comment in the pre-commit configuration to
reference the ratchet’s integration in ci.yml, specifically the
no-noncanonical-lifecycle-classes job and its STRICT_GATE_JOBS registration in
ci_summary_gate.py, instead of the removed standalone workflow file.

---

Nitpick comments:
In @.github/workflows/ci.yml:
- Around line 1545-1574: Pin the remaining third-party actions in the
no-noncanonical-lifecycle-classes job to immutable release commit SHAs. Update
the actions/setup-python and astral-sh/setup-uv uses entries, preserving their
current release versions as comments and leaving the checkout step unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 175fb8bd-f169-491c-baab-3978cc341347

📥 Commits

Reviewing files that changed from the base of the PR and between fe64bce and 5ae367a.

📒 Files selected for processing (3)
  • .github/workflows/ci.yml
  • .pre-commit-config.yaml
  • scripts/ci/ci_summary_gate.py

Comment thread .pre-commit-config.yaml Outdated
@jonahgabriel
jonahgabriel merged commit 0519560 into dev Jul 11, 2026
124 of 126 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-14350-infra-ci-enforce branch July 11, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant