Repository navigation
fix(OMN-15703): bump stale omnimarket CI fallback pin (point-in-time mitigation) - #2657
Merged
Merged
Conversation
…mitigation) The application-database-domain-enforcement gate's hardcoded omnimarket fallback (ci.yml:2330) was still 4637e625 (2026-07-30), which predates both 8e27c27a (OMN-15423, omninode_internal -> public reclassification) and 485be549 (OMN-15655, public -> tenant). OMN-15701 / infra#2656 regenerated the topology grant declarations against omnimarket dev HEAD via an explicit Omnimarket-Source-Ref trailer, but that PR's own pin bump did not land in the merge (branch was merged before the bump commit was pushed) -- dev still carries the stale 4637e625 pin as of this PR. Any infra PR without a trailer that touches these contracts falls back to the stale pin and can silently re-revert the OMN-15701 fix, the same way infra#2632 silently reverted infra#2634. Bumps the fallback pin to 54356a83 (omnimarket dev HEAD as of 2026-08-03, same SHA OMN-15701 used) as a point-in-time mitigation. This is NOT a structural fix -- nothing advances this pin automatically when omnimarket dev moves again; the structural fix (live-resolve omnimarket dev HEAD, or fail loudly on staleness) is OMN-15703's own AC, tracked in this same ticket. Evidence-Ticket: OMN-15703
📝 WalkthroughWalkthroughThe CI workflow updates the ChangesCI workflow update
Estimated code review effort: 1 (Trivial) | ~2 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
jonahgabriel
added a commit
to OmniNode-ai/onex_change_control
that referenced
this pull request
Aug 4, 2026
Companion for OMN-15703 / infra#2657 (bump stale omnimarket CI fallback pin, point-in-time mitigation for OMN-15701/OMN-15655). Content-bound probe confirms the bumped pin is present at PR #2657 head and absent (RED) at infra dev HEAD. Independently verified by probe-delta-0804 (runner != verifier). Evidence-Ticket: OMN-15703
jonahgabriel
added a commit
to OmniNode-ai/onex_change_control
that referenced
this pull request
Aug 4, 2026
#6076) * evidence(OMN-15703): OCC companion for OmniNode-ai/omnibase_infra#2657 Companion for OMN-15703 / infra#2657 (bump stale omnimarket CI fallback pin, point-in-time mitigation for OMN-15701/OMN-15655). Content-bound probe confirms the bumped pin is present at PR #2657 head and absent (RED) at infra dev HEAD. Independently verified by probe-delta-0804 (runner != verifier). Evidence-Ticket: OMN-15703 * evidence(OMN-15703): add OCC self-bind receipt for PR #6076 Binds pr_number to this OCC PR's own number for the occ-preflight / eligibility self-check, per the dual-binding pattern (code-side verify binds commit_sha to the code PR head; OCC self-preflight binds pr_number to the OCC PR). Evidence-Ticket: OMN-15703
Contributor
✅ Hostile Reviewer — PASSEDBlocking findings (critical): 0 Gate semantics (pilot phase)
Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524) |
2 of 3 tasks
jonahgabriel
added a commit
that referenced
this pull request
Aug 5, 2026
… CI pin (#2659) * fix(OMN-15703): live-resolve omnimarket dev HEAD instead of hardcoded pin Replace the hardcoded fallback SHA in ci.yml's application-database- domain-enforcement job with a live GitHub API resolution of omnimarket's dev HEAD at CI-run time. The prior mechanism (a snapshot SHA baked into ci.yml, most recently bumped by #2657) goes stale the moment omnimarket dev advances again, silently reproducing the OMN-15701 grant-reversion incident on any infra PR that lacks an Omnimarket-Source-Ref trailer. The new step fails loudly (non-zero exit, invalid-sha guard) rather than falling back to a stale pin if the API resolution fails. Refs: OMN-15701 (incident), OMN-15703 (this ticket), OMN-15655 (umbrella) Evidence-Ticket: OMN-15703 * fix(OMN-15703): fork-guard the live-resolve omnimarket step's token The Live-resolve omnimarket dev HEAD step hard-depended on secrets.CROSS_REPO_PAT with no fork guard. Fork-triggered pull_request runs receive no org secrets, so GH_TOKEN resolved empty, `gh api` failed unauthenticated, and `set -euo pipefail` aborted the application-database-domain-enforcement job before its dedicated fork-lane proof step ("Enforce schema qualification in changed SQL (public fork, fail closed)") ever ran. omnimarket is a public repo, so github.token (always present, including on fork PRs) is sufficient to read its commits API. Fall back to it: `secrets.CROSS_REPO_PAT || github.token`. CROSS_REPO_PAT stays preferred when present so same-repo/trusted runs keep using the shared higher cross-repo rate-limit budget already used elsewhere in this workflow. Fail-closed behavior is unchanged: SHA regex validation, hard exit on resolution failure, no mutable-tag/latest/ dev-ref fallback. Adds a workflow-shape regression test asserting the fallback is present and CROSS_REPO_PAT is never used bare in this step. OMN-15703
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Point-in-time mitigation for the recurring staleness vector flagged by OMN-15701 (infra#2656): bumps
.github/workflows/ci.yml:2330's hardcoded omnimarket fallback pin,4637e625(2026-07-30) →54356a831e3d8876c69373cac884a3df2a5653f7(omnimarket dev HEAD as of 2026-08-03, includes both8e27c27aand485be549).Why urgent
infra#2656 (OMN-15701) fixed the
tenant_projection_writergrant reversion caused by this stale pin and merged to dev at2026-08-04T18:40:34Z(commit57c3e7e089) — but that PR's own pin-bump commit was pushed to its branch after the branch had already been merged/deleted, so it never landed.devstill carries the stale4637e625pin right now. Any subsequent omnibase_infra PR without anOmnimarket-Source-Ref:trailer that touches these contracts falls back to the stale pin and can silently reproduce the exact #2632 revert that caused the original onex-dev CrashLoopBackOff — before OMN-15703 (this ticket)'s structural fix lands.Not a structural fix
This is a value bump, not a mechanism change — nothing advances this pin automatically when omnimarket dev moves again. The structural fix (live-resolve omnimarket dev HEAD at CI-run time, or fail loudly when the pin's staleness/divergence exceeds a threshold) is OMN-15703's own acceptance criteria and is not built here.
Verification
ruff format/ pre-commit: clean.Refs: OMN-15701 (root cause + prior fix), OMN-15703 (this ticket, structural follow-up), OMN-15655 (umbrella)
Evidence-Ticket: OMN-15703
Summary by CodeRabbit
Evidence-Source: OCC#6076