Repository navigation
feat(OMN-14438): clean-ref deploy source + vendored-SHA assertion (RT-1/RT-2) - #2270
Conversation
…-1/RT-2) RT-1 (mechanical-release-trains plan §3, instance #3): the workspace build staged each sibling from the AMBIENT ${OMNI_HOME}/<repo> tree on .201 -- a detached/behind/dirty working copy -- so merging a PR never changed what got built and every "deployed" claim was unfalsifiable. A vendored-SHA manifest was emitted but nobody asserted it equaled the intended ref. This lands the fix at the root: - scripts/runtime_build/deploy_source_ref.py: `checkout` brings each sibling clone to a CLEAN checkout of a named ref (fetch --prune + checkout + reset --hard + clean -ffdx); `assert` HARD-ASSERTS the vendored-SHA manifest equals that ref for every sibling. Fails closed (exit 3/4). - stage_workspace.sh: runs the clean checkout before staging (when DEPLOY_REF is set) and the assertion after the VCS-provenance manifest is written. Unset DEPLOY_REF => legacy ambient build, loudly stamped unpinned + unasserted. - RT-2 cut-lab-ref.sh: one-command lab deploy wrapper (--ref/--hotpatch/--cut-tag, dev + stability-test lanes; prod refused). --hotpatch deploys a dirty tree deliberately, LABELLED (not laundered). DoD evidence (OMN-14438): - RED against EXISTS-but-WRONG: test_assert_red_on_exists_but_wrong_stale_sha and the stage_workspace e2e feed a REAL behind clone's stale SHA to the assertion, which goes RED (exit 4). Not a green-on-absence. - GREEN: manifest SHA == ref for every sibling after the clean checkout. - --hotpatch labels dirty deploys (hotpatch:true + dirty:true asserted). - 16 new tests pass; full tests/scripts/ (287) green; ruff+mypy+shellcheck+ pre-commit clean.
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 56 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (6)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
…046 (occ-preflight now green)
OMN-14438 — RT-1/RT-2: clean-ref deploy source + vendored-SHA assertion
Closes OMN-14438 (Train 1 / WS-RT, mechanical-release-trains plan §3).
Problem (instance #3, verified in the plan)
stage_workspace.shrsyncs each sibling from the ambient${OMNI_HOME}/<repo>working copy on.201— routinely detached, behind, and dirty — so merging a PR never changes what gets built and every "deployed" claim is unfalsifiable. A vendored-SHA manifest (sibling-vcs-provenance.json) is emitted but nobody asserts it equals the intended ref, so a behind/dirty clone silently leaks a stale SHA into the image (taxonomy Class 6 — the unreliable-narrator tree).Fix
scripts/runtime_build/deploy_source_ref.py(new, stdlib-only):checkout— before staging, brings each sibling clone to a clean checkout of a named ref (git fetch --prune+checkout+reset --hard+clean -ffdx) and writes an expected-refs manifest. Fails closed (exit 3) if the ref is unresolvable or the checkout does not land at the ref / leaves a dirty tree.assert— HARD-ASSERTS the vendored-SHA manifest equals that ref for every sibling. Fails closed (exit 4) on a stale/wrong SHA or an unlabelled dirty tree.scripts/runtime_build/stage_workspace.sh— runscheckoutbefore the pin preflight/staging (whenDEPLOY_REFset /DEPLOY_HOTPATCH=1) andassertafter the VCS-provenance manifest is written. UnsetDEPLOY_REF⇒ legacy ambient build, loudly stamped unpinned + unasserted (incremental rollout;cut-lab-refalways engages RT-1).scripts/runtime_build/cut-lab-ref.sh(RT-2, new) — one-command lab deploy wrapper:--ref <branch|tag|sha>,--hotpatch,--cut-tag(cutslab/<lane>/<utc>-<shortsha>), dev + stability-test lanes; prod refused (Train 2, grant-gated).--hotpatchdeploys a dirty tree deliberately, LABELLED (hotpatch:true+dirty:true), never laundered.Seams (field-by-field)
workspace/deploy-source-refs.json:{ ref_pinned: bool, repos: { <repo>: { path, ref, expected_sha (40-hex), head_sha, dirty: bool, hotpatch: bool } } }— written bycheckout, read byassert.workspace/sibling-vcs-provenance.json(existing, unchanged shape):{ siblings: { <repo>: { vcs_ref (40-hex), vcs_dirty: bool, vcs_branch } } }. The assertion joinssiblings[repo].vcs_ref == repos[repo].expected_shaandsiblings[repo].vcs_dirty ⇒ repos[repo].hotpatch.stage_workspace.sh:DEPLOY_REF(str, uniform ref),DEPLOY_HOTPATCH(0/1).cut-lab-ref.shexports these +BUILD_SOURCE=workspace+OMNIBASE_INFRA_COMPOSE_PROJECTintodeploy-runtime.sh(which propagates the exported env to thestage_workspace.shsubshell). Cross-boundary coverage:tests/scripts/test_stage_workspace_deploy_ref.pydrives the realstage_workspace.sh→deploy_source_ref.pyseam end-to-end.stage_workspace.shmaps every RT-1 failure (checkout or assert) to exit 4.dod_evidence
proof_class: code-only(build/CI green + real-git-tree tests; runtime readback is RT-4/RT-6, separate tickets).test_assert_red_on_exists_but_wrong_stale_sha— a real sibling clone that EXISTS and is a valid git tree but is BEHIND the intended ref (HEAD at an older commit); its actual HEAD SHA (read viagit rev-parse, not a hand-typed fake) is fed to the assertion →DeploySourceRefError(exit 4), and the stale SHA is named in the failure.test_stage_assert_command_goes_red_on_poisoned_provenance— the exact commandstage_workspace.shruns (deploy_source_ref.py assert) is invoked on real staged artifacts with the vendored SHA poisoned to the real behind commit → exit 4.test_unresolvable_deploy_ref_fails_build_closed—stage_workspace.shexits 4 and writes no provenance manifest.test_assert_red_on_unlabelled_dirty_tree— vendored SHA matches ref but tree is dirty and not a hot-patch → exit 4.test_clean_checkout_converts_wrong_tree_then_asserts_green— realclean_checkoutconverts the behind+dirty clone to the intended ref (untracked file removed), then assertion passes.test_deploy_ref_checks_out_behind_clone_and_asserts_green(e2e) — starting from a BEHIND clone,stage_workspace.shwithDEPLOY_REF=devvendors the NEW ref SHA (a no-op would have vendored the stale SHA), in-script assertion passes.--hotpatchlabels dirty:test_hotpatch_labels_dirty_and_passes— the patch is NOT laundered away, the manifest carrieshotpatch:true+dirty:true, and the labelled dirty tree passes the assertion.tests/scripts/(287) green;ruff+mypy+shellcheck+pre-commit runclean.Not in scope (owed, separate tickets)
RT-3 (trigger fail-closed), RT-4/RT-6 (deploy readback), the bus-trigger wiring. This PR is the deploy-source root fix only.
OCC companion: required for the omnibase_infra dev receipt-gate; per
feedback_no_self_authored_evidenceit is authored by the independent verifier, not this implementer.Evidence-Source: OCC#4046
Evidence-Commit: ffa6f1cc00bfb1aa989b3aba858f5f04c4dac084
Evidence-Ticket: OMN-14438