Repository navigation
feat(OMN-14667): port WS7 CI<->pre-commit byte-match parity gate to omnibase_infra - #2318
Conversation
…mnibase_infra WS7 fan-out #3 of the OMN-14655 canary. Adds the fail-loud meta-gate + pin-parity ratchet over .pre-commit-config.yaml, wired as BOTH local pre-commit hooks and a STANDALONE, unconditional CI workflow (.github/workflows/precommit-parity-gate.yml) with NO needs: occ-preflight and NO paths filter. OMN-14666 canary lesson: on omnimarket#1783 the parity job shared a run with occ-preflight and needs:-ed it, so an occ-preflight failure SKIPPED the byte-match proof on attempt 1; in omnibase_infra every ci.yml job already needs occ-preflight, so a standalone workflow is the only shape structurally immune to that coupling. Fixes two live pre-existing false-greens the fail-loud gate caught: check_no_cloud_bus_wrapper.sh exited 0 when its check was unresolvable (DRIFT-2), and default_install_hook_types omitted commit-msg so the commit-msg hook never installed locally (DRIFT-2a). pin-parity enforces the verified-matching check-canonical-inference pair (pre-commit rev == canonical-inference-gate.yml core SHA 940d2f2); a live url-authority DRIFT-3 (be4f954 vs 8a53a06) is documented and left unenforced pending SHA convergence. Local skips (env-only, not in this diff, evaluated correctly against pinned deps in CI): onex-validate-imports (repo's own ci: skip: list; worktree venv core lacks runtime_fanout_resolver) and onex-check-node-migration-sync (local omnimarket clone is ahead of the pinned dep).
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 1 minute Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (7)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
…ibase_infra#2318 (#4267) * evidence(OMN-14667): author OCC companion for OmniNode-ai/omnibase_infra#2318 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 0af51fa14b1401c91d0f7187b7836684b2f3d25a. * evidence(OMN-14667): self-bind OCC#4267 + rebind contract_sha256 * evidence(OMN-14667): normalize OCC 4267 checks --------- Co-authored-by: omnimarket-bot <bot@omninode.ai>
…ibase_infra#2318 (#4268) * evidence(OMN-14667): author OCC companion for OmniNode-ai/omnibase_infra#2318 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head f49d4d8fb50c796ada91fa8deb04e372240ca0ac. * evidence(OMN-14667): self-bind OCC#4268 + rebind contract_sha256 * evidence(OMN-14667): normalize OCC 4268 self-bind --------- Co-authored-by: omnimarket-bot <bot@omninode.ai>
OMN-14667 — WS7 fan-out #3: CI↔pre-commit byte-match parity gate → omnibase_infra
DRAFT pending operator go for WS7 fan-out continuation.
Ports the OMN-14655 canary (merged on omnimarket#1783 / omniclaude#1904) to
omnibase_infra: two meta-gates over.pre-commit-config.yaml, wired as both local pre-commit hooks and a standalone, unconditional CI workflow.What landed
scripts/validation/validate_precommit_fail_loud.py— fail-loud meta-gate: hard-rejects the exit-0-on-missing-path / WARN-SKIP-degrade shape (a skipped gate must be byte-indistinguishable from a failing one) + anystages:valuedefault_install_hook_typesdoes not install (DRIFT-2 / DRIFT-2a).scripts/validation/validate_precommit_pin_parity.py— pin-parity ratchet, adapted to infra's layout: infra pins each validator's core SHA in a dedicated gate workflow (not oneci.yml), soPIN_PAIRSnames the specific CI workflow per pair for a strict 1:1 comparison (a flat all-workflow scan would cross-contaminate infra's multiple per-validator pins)..github/workflows/precommit-parity-gate.yml— standalone CI job running both scripts..pre-commit-config.yaml— two new local hooks +default_install_hook_types: [pre-commit, pre-push, commit-msg].Unconditional-by-design (OMN-14666 canary lesson)
On omnimarket#1783 the parity job shared a run with
occ-preflightandneeds:-ed it, so an occ-preflight failure SKIPPED the byte-match proof on attempt 1 — a skip-then-vacuous-green window in the very gate meant to kill false-greens; only a manual rerun made it fire.Key finding for infra: the task's premise ("no ci.yml job needs occ-preflight") is false —
ci.ymldefines its ownocc-preflightjob (~line 58) and every arch gate (fingerprint-check,demo-loop-gate,arch-invariants,lint, …) declaresneeds: occ-preflight. So placing the parity gate as a ci.yml job would put it one careless edit from that exact coupling. This PR instead uses a standalone workflow with NOneeds:and NOpaths:filter — the only shape structurally immune to occ-preflight coupling. It fires on every PR tomain/devand passes/fails purely on its own byte-match evidence.Proof-of-life (no seeded break needed)
The fail-loud gate caught two live pre-existing false-greens, both fixed here:
scripts/check_no_cloud_bus_wrapper.shexited0when its check script was unresolvable (DRIFT-2 — a gate that can't run passing as if it succeeded). → nowexit 1.default_install_hook_typesomittedcommit-msg, soreject-deploy-gate-skip-token-commit-msg(stages:[commit-msg]) never installed locally (DRIFT-2a). → addedcommit-msg.sync-node-migrations.sh's reviewedSYNC_NODE_MIGRATIONS_SKIP_UNRESOLVABLE=1escape hatch (OMN-13062, default path isexit 2) is annotated# fail-loud-ok:.pin-parity enforces the verified-matching
check-canonical-inferencepair (pre-commitrev==canonical-inference-gate.ymlcore SHA940d2f2…). A live url-authority DRIFT-3 (check-url-authoritypre-commitbe4f954…vsurl-authority-gate.yml8a53a06…, samevalidator_url_authority) is documented in the script and left unenforced pending SHA convergence (adding it now would either red the gate or require a risky out-of-scope core-SHA bump).dod_evidence
precommit-fail-loud-meta-gate+precommit-pin-parityboth Passed underpre-commit run; both scripts exit 0 standalone; ruff format/check + mypy clean.gh pr checks.onex-validate-imports(repo's ownci: skip:list; worktree venv core lacksruntime_fanout_resolver) andonex-check-node-migration-sync(local omnimarket clone ahead of the pinned dep).Closes OMN-14667.
Evidence-Ticket: OMN-14667
Evidence-Source: OCC#4268
Evidence-Ticket: OMN-14667
Evidence-Source: OCC#4268
Evidence-Commit: 36f7f002bd1c42de477438e00b7bcb3f0af86e57
Evidence-Head: f49d4d8