Skip to content

fix(OMN-15703): bump stale omnimarket CI fallback pin (point-in-time mitigation) - #2657

Merged
jonahgabriel merged 1 commit into
devfrom
jonah/omn-15703-bump-stale-omnimarket-ci-pin
Aug 4, 2026
Merged

jonahgabriel merged 1 commit into
devfrom
jonah/omn-15703-bump-stale-omnimarket-ci-pin

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Aug 4, 2026 •

Copy link
Copy Markdown
Collaborator

What

Point-in-time mitigation for the recurring staleness vector flagged by OMN-15701 (infra#2656): bumps .github/workflows/ci.yml:2330's hardcoded omnimarket fallback pin, 4637e625 (2026-07-30) → 54356a831e3d8876c69373cac884a3df2a5653f7 (omnimarket dev HEAD as of 2026-08-03, includes both 8e27c27a and 485be549).

Why urgent

infra#2656 (OMN-15701) fixed the tenant_projection_writer grant reversion caused by this stale pin and merged to dev at 2026-08-04T18:40:34Z (commit 57c3e7e089) — but that PR's own pin-bump commit was pushed to its branch after the branch had already been merged/deleted, so it never landed. dev still carries the stale 4637e625 pin right now. Any subsequent omnibase_infra PR without an Omnimarket-Source-Ref: trailer that touches these contracts falls back to the stale pin and can silently reproduce the exact #2632 revert that caused the original onex-dev CrashLoopBackOff — before OMN-15703 (this ticket)'s structural fix lands.

Not a structural fix

This is a value bump, not a mechanism change — nothing advances this pin automatically when omnimarket dev moves again. The structural fix (live-resolve omnimarket dev HEAD at CI-run time, or fail loudly when the pin's staleness/divergence exceeds a threshold) is OMN-15703's own acceptance criteria and is not built here.

Verification

  • Governed pre-push impacted-test selector (OMN-13973): 1370 passed, 0 failed (196.42s).
  • ruff format / pre-commit: clean.

Refs: OMN-15701 (root cause + prior fix), OMN-15703 (this ticket, structural follow-up), OMN-15655 (umbrella)
Evidence-Ticket: OMN-15703

Summary by CodeRabbit

  • Chores
    • Updated the CI workflow’s fallback revision for application-database domain enforcement checks.

Evidence-Source: OCC#6076

…mitigation)

The application-database-domain-enforcement gate's hardcoded omnimarket
fallback (ci.yml:2330) was still 4637e625 (2026-07-30), which predates
both 8e27c27a (OMN-15423, omninode_internal -> public reclassification)
and 485be549 (OMN-15655, public -> tenant). OMN-15701 / infra#2656
regenerated the topology grant declarations against omnimarket dev HEAD
via an explicit Omnimarket-Source-Ref trailer, but that PR's own pin
bump did not land in the merge (branch was merged before the bump commit
was pushed) -- dev still carries the stale 4637e625 pin as of this PR.

Any infra PR without a trailer that touches these contracts falls back
to the stale pin and can silently re-revert the OMN-15701 fix, the same
way infra#2632 silently reverted infra#2634. Bumps the fallback pin to
54356a83 (omnimarket dev HEAD as of 2026-08-03, same SHA OMN-15701 used)
as a point-in-time mitigation. This is NOT a structural fix -- nothing
advances this pin automatically when omnimarket dev moves again; the
structural fix (live-resolve omnimarket dev HEAD, or fail loudly on
staleness) is OMN-15703's own AC, tracked in this same ticket.

Evidence-Ticket: OMN-15703
@coderabbitai

coderabbitai Bot commented Aug 4, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The CI workflow updates the omnimarket checkout fallback SHA used by the application-database domain enforcement job when the resolved ref is dev.

Changes

CI workflow update

Layer / File(s) Summary
Update omnimarket dev checkout fallback
.github/workflows/ci.yml
The workflow now uses commit 54356a831e3d8876c69373cac884a3df2a5653f7 instead of 4637e625c99ef17c190aa471a5e51b7f646c6dfd.

Estimated code review effort: 1 (Trivial) | ~2 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the stale omnimarket CI fallback pin update and matches the primary change.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-15703-bump-stale-omnimarket-ci-pin

Comment @coderabbitai help to get the list of available commands.

jonahgabriel added a commit to OmniNode-ai/onex_change_control that referenced this pull request Aug 4, 2026
Companion for OMN-15703 / infra#2657 (bump stale omnimarket CI fallback
pin, point-in-time mitigation for OMN-15701/OMN-15655). Content-bound
probe confirms the bumped pin is present at PR #2657 head and absent
(RED) at infra dev HEAD. Independently verified by probe-delta-0804
(runner != verifier).

Evidence-Ticket: OMN-15703
jonahgabriel added a commit to OmniNode-ai/onex_change_control that referenced this pull request Aug 4, 2026
#6076)

* evidence(OMN-15703): OCC companion for OmniNode-ai/omnibase_infra#2657

Companion for OMN-15703 / infra#2657 (bump stale omnimarket CI fallback
pin, point-in-time mitigation for OMN-15701/OMN-15655). Content-bound
probe confirms the bumped pin is present at PR #2657 head and absent
(RED) at infra dev HEAD. Independently verified by probe-delta-0804
(runner != verifier).

Evidence-Ticket: OMN-15703

* evidence(OMN-15703): add OCC self-bind receipt for PR #6076

Binds pr_number to this OCC PR's own number for the occ-preflight /
eligibility self-check, per the dual-binding pattern (code-side verify
binds commit_sha to the code PR head; OCC self-preflight binds
pr_number to the OCC PR).

Evidence-Ticket: OMN-15703
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

✅ Hostile Reviewer — PASSED

Blocking findings (critical): 0
Total findings: 0
Models succeeded: qwen3-review,qwen3-review-b


Gate semantics (pilot phase)

Verdict Meaning Blocks merge?
passed No critical findings No
blocked CRITICAL findings found Yes
degraded All models unavailable (infra) No (pilot)

Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)

@jonahgabriel
jonahgabriel merged commit d53e3cf into dev Aug 4, 2026
240 of 270 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-15703-bump-stale-omnimarket-ci-pin branch August 4, 2026 21:01
jonahgabriel added a commit that referenced this pull request Aug 5, 2026
… CI pin (#2659)

* fix(OMN-15703): live-resolve omnimarket dev HEAD instead of hardcoded pin

Replace the hardcoded fallback SHA in ci.yml's application-database-
domain-enforcement job with a live GitHub API resolution of
omnimarket's dev HEAD at CI-run time. The prior mechanism (a snapshot
SHA baked into ci.yml, most recently bumped by #2657) goes stale the
moment omnimarket dev advances again, silently reproducing the
OMN-15701 grant-reversion incident on any infra PR that lacks an
Omnimarket-Source-Ref trailer.

The new step fails loudly (non-zero exit, invalid-sha guard) rather
than falling back to a stale pin if the API resolution fails.

Refs: OMN-15701 (incident), OMN-15703 (this ticket), OMN-15655 (umbrella)
Evidence-Ticket: OMN-15703

* fix(OMN-15703): fork-guard the live-resolve omnimarket step's token

The Live-resolve omnimarket dev HEAD step hard-depended on
secrets.CROSS_REPO_PAT with no fork guard. Fork-triggered pull_request
runs receive no org secrets, so GH_TOKEN resolved empty, `gh api`
failed unauthenticated, and `set -euo pipefail` aborted the
application-database-domain-enforcement job before its dedicated
fork-lane proof step ("Enforce schema qualification in changed SQL
(public fork, fail closed)") ever ran.

omnimarket is a public repo, so github.token (always present,
including on fork PRs) is sufficient to read its commits API. Fall
back to it: `secrets.CROSS_REPO_PAT || github.token`. CROSS_REPO_PAT
stays preferred when present so same-repo/trusted runs keep using the
shared higher cross-repo rate-limit budget already used elsewhere in
this workflow. Fail-closed behavior is unchanged: SHA regex
validation, hard exit on resolution failure, no mutable-tag/latest/
dev-ref fallback.

Adds a workflow-shape regression test asserting the fallback is
present and CROSS_REPO_PAT is never used bare in this step.

OMN-15703
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant