Skip to content

feat(OMN-14667): port WS7 CI<->pre-commit byte-match parity gate to omnibase_infra - #2318

Merged
jonahgabriel merged 2 commits into
devfrom
jonah/omn-14667-precommit-parity-gate
Jul 16, 2026
Merged

jonahgabriel merged 2 commits into
devfrom
jonah/omn-14667-precommit-parity-gate

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jul 16, 2026 •

Copy link
Copy Markdown
Collaborator

OMN-14667 — WS7 fan-out #3: CI↔pre-commit byte-match parity gate → omnibase_infra

DRAFT pending operator go for WS7 fan-out continuation.

Ports the OMN-14655 canary (merged on omnimarket#1783 / omniclaude#1904) to omnibase_infra: two meta-gates over .pre-commit-config.yaml, wired as both local pre-commit hooks and a standalone, unconditional CI workflow.

What landed

  • scripts/validation/validate_precommit_fail_loud.py — fail-loud meta-gate: hard-rejects the exit-0-on-missing-path / WARN-SKIP-degrade shape (a skipped gate must be byte-indistinguishable from a failing one) + any stages: value default_install_hook_types does not install (DRIFT-2 / DRIFT-2a).
  • scripts/validation/validate_precommit_pin_parity.py — pin-parity ratchet, adapted to infra's layout: infra pins each validator's core SHA in a dedicated gate workflow (not one ci.yml), so PIN_PAIRS names the specific CI workflow per pair for a strict 1:1 comparison (a flat all-workflow scan would cross-contaminate infra's multiple per-validator pins).
  • .github/workflows/precommit-parity-gate.yml — standalone CI job running both scripts.
  • .pre-commit-config.yaml — two new local hooks + default_install_hook_types: [pre-commit, pre-push, commit-msg].

Unconditional-by-design (OMN-14666 canary lesson)

On omnimarket#1783 the parity job shared a run with occ-preflight and needs:-ed it, so an occ-preflight failure SKIPPED the byte-match proof on attempt 1 — a skip-then-vacuous-green window in the very gate meant to kill false-greens; only a manual rerun made it fire.

Key finding for infra: the task's premise ("no ci.yml job needs occ-preflight") is false — ci.yml defines its own occ-preflight job (~line 58) and every arch gate (fingerprint-check, demo-loop-gate, arch-invariants, lint, …) declares needs: occ-preflight. So placing the parity gate as a ci.yml job would put it one careless edit from that exact coupling. This PR instead uses a standalone workflow with NO needs: and NO paths: filter — the only shape structurally immune to occ-preflight coupling. It fires on every PR to main/dev and passes/fails purely on its own byte-match evidence.

Proof-of-life (no seeded break needed)

The fail-loud gate caught two live pre-existing false-greens, both fixed here:

  1. scripts/check_no_cloud_bus_wrapper.sh exited 0 when its check script was unresolvable (DRIFT-2 — a gate that can't run passing as if it succeeded). → now exit 1.
  2. default_install_hook_types omitted commit-msg, so reject-deploy-gate-skip-token-commit-msg (stages:[commit-msg]) never installed locally (DRIFT-2a). → added commit-msg.

sync-node-migrations.sh's reviewed SYNC_NODE_MIGRATIONS_SKIP_UNRESOLVABLE=1 escape hatch (OMN-13062, default path is exit 2) is annotated # fail-loud-ok:.

pin-parity enforces the verified-matching check-canonical-inference pair (pre-commit rev == canonical-inference-gate.yml core SHA 940d2f2…). A live url-authority DRIFT-3 (check-url-authority pre-commit be4f954… vs url-authority-gate.yml 8a53a06…, same validator_url_authority) is documented in the script and left unenforced pending SHA convergence (adding it now would either red the gate or require a risky out-of-scope core-SHA bump).

dod_evidence

  • Local: precommit-fail-loud-meta-gate + precommit-pin-parity both Passed under pre-commit run; both scripts exit 0 standalone; ruff format/check + mypy clean.
  • CI: the standalone Precommit Parity Gate job runs unconditionally on this PR (no occ-preflight dep, no paths filter) — see gh pr checks.
  • Local hook skips were env-only, not in this diff, evaluated correctly against pinned deps in CI: onex-validate-imports (repo's own ci: skip: list; worktree venv core lacks runtime_fanout_resolver) and onex-check-node-migration-sync (local omnimarket clone ahead of the pinned dep).

Closes OMN-14667.

Evidence-Ticket: OMN-14667
Evidence-Source: OCC#4268

Evidence-Ticket: OMN-14667
Evidence-Source: OCC#4268
Evidence-Commit: 36f7f002bd1c42de477438e00b7bcb3f0af86e57
Evidence-Head: f49d4d8

…mnibase_infra

WS7 fan-out #3 of the OMN-14655 canary. Adds the fail-loud meta-gate +
pin-parity ratchet over .pre-commit-config.yaml, wired as BOTH local
pre-commit hooks and a STANDALONE, unconditional CI workflow
(.github/workflows/precommit-parity-gate.yml) with NO needs: occ-preflight
and NO paths filter. OMN-14666 canary lesson: on omnimarket#1783 the parity
job shared a run with occ-preflight and needs:-ed it, so an occ-preflight
failure SKIPPED the byte-match proof on attempt 1; in omnibase_infra every
ci.yml job already needs occ-preflight, so a standalone workflow is the only
shape structurally immune to that coupling.

Fixes two live pre-existing false-greens the fail-loud gate caught:
check_no_cloud_bus_wrapper.sh exited 0 when its check was unresolvable
(DRIFT-2), and default_install_hook_types omitted commit-msg so the
commit-msg hook never installed locally (DRIFT-2a). pin-parity enforces the
verified-matching check-canonical-inference pair (pre-commit rev ==
canonical-inference-gate.yml core SHA 940d2f2); a live url-authority DRIFT-3
(be4f954 vs 8a53a06) is documented and left unenforced pending SHA convergence.

Local skips (env-only, not in this diff, evaluated correctly against pinned
deps in CI): onex-validate-imports (repo's own ci: skip: list; worktree venv
core lacks runtime_fanout_resolver) and onex-check-node-migration-sync (local
omnimarket clone is ahead of the pinned dep).
@coderabbitai

coderabbitai Bot commented Jul 16, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 1 minute

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 69c67eec-c2f5-4a48-bcd4-3ed891a9a98a

📥 Commits

Reviewing files that changed from the base of the PR and between 1616118 and f49d4d8.

📒 Files selected for processing (7)
  • .github/workflows/precommit-parity-gate.yml
  • .pre-commit-config.yaml
  • docker/migrations/forward/nodes/node_merge_state_projection/0001_create_merge_state_transitions.sql
  • scripts/check_no_cloud_bus_wrapper.sh
  • scripts/sync-node-migrations.sh
  • scripts/validation/validate_precommit_fail_loud.py
  • scripts/validation/validate_precommit_pin_parity.py
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-14667-precommit-parity-gate

Comment @coderabbitai help to get the list of available commands.

jonahgabriel added a commit to OmniNode-ai/onex_change_control that referenced this pull request Jul 16, 2026
…ibase_infra#2318 (#4267)

* evidence(OMN-14667): author OCC companion for OmniNode-ai/omnibase_infra#2318

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 0af51fa14b1401c91d0f7187b7836684b2f3d25a.

* evidence(OMN-14667): self-bind OCC#4267 + rebind contract_sha256

* evidence(OMN-14667): normalize OCC 4267 checks

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
@jonahgabriel
jonahgabriel marked this pull request as ready for review July 16, 2026 11:38
jonahgabriel added a commit to OmniNode-ai/onex_change_control that referenced this pull request Jul 16, 2026
…ibase_infra#2318 (#4268)

* evidence(OMN-14667): author OCC companion for OmniNode-ai/omnibase_infra#2318

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head f49d4d8fb50c796ada91fa8deb04e372240ca0ac.

* evidence(OMN-14667): self-bind OCC#4268 + rebind contract_sha256

* evidence(OMN-14667): normalize OCC 4268 self-bind

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
@jonahgabriel
jonahgabriel merged commit 59bc970 into dev Jul 16, 2026
153 of 169 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-14667-precommit-parity-gate branch July 16, 2026 11:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant