Repository navigation
fix(OMN-15617): remediation — silent-skip ordering + PATH word-split - #2652
Conversation
…d-split Addresses two adversarial-verify defects on PR #2651: - Reorder resolve_modern_bash() before the jq/flock tool-availability skip in test_runner_monitor_wedge_detection.py and test_runner_monitor_auto_bounce.py. Previously a missing jq (or flock) triggered pytest.skip() before the bash>=5 canary ran, so a host with the wrong interpreter AND a missing secondary tool would report green-by- absence instead of the RED the ticket's AC2 requires. - Fix scripts/ci/resolve_modern_bash.sh to build CANDIDATES as a bash-3.2- safe array instead of a space-joined string. The prior unquoted word-splitting silently dropped any interpreter path or PATH entry containing a space, risking a silent-wrong-answer resolution in the exact script whose purpose is to eliminate that failure mode. Verified: 102 passed / 4 skipped (flock-only, unrelated) under env -i PATH=/usr/bin:/bin; resolver returns exit 1 with pointed stderr and empty stdout when OMNIBASE_INFRA_MIN_BASH_MAJOR is set unreachably high (proves genuine fail-closed RED); resolver correctly resolves a space-containing OMNIBASE_INFRA_BASH_BIN path post-fix (previously would silently drop the fragment). Ticket: OMN-15617
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 45 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (3)
Comment |
#6054) * evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#2652 * evidence: OCC companion self-bind for #6054 * fix(OMN-15617): repair OCC 6054 receipt bindings --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai>
|
| Verdict | Meaning | Blocks merge? |
|---|---|---|
passed |
No critical findings | No |
blocked |
CRITICAL findings found | Yes |
degraded |
All models unavailable (infra) | No (pilot) |
Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)
AC#1 proof over plain non-interactive ssh (OMN-15617)Ran the full RED/GREEN/guard protocol over real non-interactive ssh ( RED control (detached worktree at GREEN (clean Guard proof (AC#2): Full command-by-command transcript posted on OMN-15617. Not merging/flipping anything here — proof only. |
OMN-15617 — remediation round 1: silent-skip ordering + PATH word-split
Follow-up to #2651, which merged to
dev(commit16b1d7a4, 2026-08-04T16:40:18Z)while this remediation was in flight — the adversarial-verify fixes below did
NOT make it into that merge. Operative consequence, stated plainly:
devis currently live-shipping the unfixed resolver form — confirmed livevia
git show origin/dev:scripts/ci/resolve_modern_bash.sh(CANDIDATES=""/unquoted
for _candidate in $CANDIDATESword-split, no array) andgit show origin/dev:tests/.../test_runner_monitor_wedge_detection.py(tool-skip loop still precedes
resolve_modern_bash()). This PR (#2652) isthe only carrier of both fixes and is currently CI-blocked (see below), so
there is no landed remediation on
devas of this report.Fixes
test_runner_monitor_wedge_detection.py,test_runner_monitor_auto_bounce.py):resolve_modern_bash()now runsBEFORE the
jq/flocktool-availabilitypytest.skip(). Previously amissing secondary tool short-circuited the bash>=5 canary via skip, so a
host with both the wrong interpreter AND a missing tool would report
green-by-absence instead of the RED ticket AC Add Claude Code GitHub Workflow #2 requires ("the canary
fails RED when bash resolves <5").
scripts/ci/resolve_modern_bash.sh):CANDIDATESis now a bash-3.2-safe array instead of a space-joined string iterated with
unquoted word-splitting. The prior form silently dropped any interpreter
path or
$PATHentry containing a space — a silent-wrong-answer mode inthe exact script whose purpose is eliminating that failure class.
Seams
scripts/ci/resolve_modern_bash.sh,tests/unit/observability/runner_health/test_runner_monitor_wedge_detection.py,tests/unit/observability/runner_health/test_runner_monitor_auto_bounce.py— same three seams #2651 declared (OMNIBASE_INFRA_BASH_BIN, the resolver's stdout/stderr/exit contract,_resolve_modern_bash.py::resolve_modern_bash()import) are unchanged; no new seam introducedtry_candidate/bash_major_versionlogic in the resolver is unchanged, only theCANDIDATEScontainer type (string → array)Verification
resolve_modern_bash()executes(and passes, proving bash>=5 resolves) even on this host's pre-existing
missing-
flockgap, before that tool-skip fires — the skip no longermasks the canary.
OMNIBASE_INFRA_MIN_BASH_MAJOR=99 bash scripts/ci/resolve_modern_bash.sh→ exit 1, pointed stderr, empty stdout.OMNIBASE_INFRA_BASH_BIN="/tmp/bash test dir/bash"now resolves correctly post-fix (pre-fix would silently drop the
space-split fragment and fall through to a different candidate).
CI status (live, re-verified 2026-08-04 ~17:35Z UTC)
Six checks currently fail on this PR, all downstream of one root cause
(OCC-eligibility class), plus one adversarial gate unrelated to this diff:
verify / verify(job 92073754869, step "Run OCC Eligibility")occ_commit_sharesolves to198a738a(companion #6047, bound to PR #2651),reason: pr_ticket_mismatch,eligible: falseocc-preflight / eligibility(×2 job instances)call-reject-skip-token / occ-preflight / eligibilityCI SummaryHostile Review GateCorrection to round-1 report: the round-1 enumeration ("5 fail") omitted
verify / verify— six checks fail, not five. Its failing step and payloadwere pulled directly from the job log and confirm it is the same
OCC-eligibility class as the other four, not a distinct defect.
OCC companion status: #6054 (
OmniNode-ai/onex_change_control#6054,bot-authored
app/onexbot-occ-writer, correctly bound to this PR per its ownbody) is OPEN, not yet merged to OCC main. At round-1 report time it showed
three failing gates (
OCC Append-Only Gate,Pre-commit,Supersession Binding Ratchet (OMN-15459)). Re-verified live just now:all three are now green (
OCC Append-Only Gatesuccess,Supersession Binding Ratchet (OMN-15459)success,Pre-commitsuccess — confirmed viagh api .../check-runs), self-resolved by the bot without action from thislane. The remaining blocker on
verify / verify/occ-preflight / eligibilityis structural, not a defect in #6054: eligibility is evaluatedagainst OCC main, and #6054 has not merged there yet, so no PASS receipt
bound to PR #2652 exists on OCC main. Merging OCC PRs is outside this lane's
authority (bot/Codex-owned); this PR cannot flip eligibility green on its
own.
.200live validation — still blocked, and a residual gap disclosedssh -o BatchMode=yes -o ConnectTimeout=8 stickybeatz-studiostill returnsPermission denied (publickey,password,keyboard-interactive)for thissession's identity (re-verified 2026-08-04). Same disclosed gap as #2651,
unchanged by this PR. AC #1 ("a clean-dev run of the 15 monitor.sh tests
passes over plain non-interactive ssh with no per-lane PATH surgery") is
NOT met by this PR — no run against
stickybeatz-studioexists from anysession to date. The fix demonstrably fires on this Mac only; per the
ticket's own OMN-13980 precedent warning, a canary that only fires off-target
does not close the ticket.
Residual gap: the ticket's Fix section offered two options — PATH
correction in the ssh non-login shell init on
.200itself, OR an explicitinterpreter pin in the affected test harness. This PR takes the harness-pin
route (permitted by the ticket), which fixes
resolve_modern_bash.shconsumers but leaves
.200's ssh non-interactive PATH itself unchanged. AnyOTHER bash>=4 consumer invoked over non-interactive ssh on
.200(outsidethis resolver's call sites) remains exposed to the same wrong-interpreter
failure mode this ticket targets. Neither this PR body nor the round-1
report previously stated that residual; stating it now.
Ticket: OMN-15617
Evidence-Ticket: OMN-15617
Evidence-Source: OCC#6057