Repository navigation
docs(OMN-15125): first dated Aug-5 readiness/rollback packet — NO-GO - #2669
Conversation
… NO-GO First real instance of the OMN-15125 GO/NO-GO packet (the template was never filled before). Fills all 15 fields with real content or an explicit, proven BLOCKED marker -- no placeholder, no invented value: - source_digest / previous_digest / amd64_manifest: live, ECR-verified (round-4 vs round-3 candidate tuple; round-3 = the prior pin in the build lineage, not a live kubectl-rollout-history readback -- caveated). - vulnerability_result: LIVE finding, 4 CRITICAL / 12 HIGH on the round-4 image (describe-image-scan-findings is authoritative; describe-images' imageScanStatus field disagrees and returns null for the same digest -- discrepancy flagged, not silently resolved). - a6_thresholds_with_live_samples: 5/5 loaded, 0/5 live-sampled -- counted as unloaded per the manifest's own definition. - reconciled_blocker_graph: live list_issues(parentId=OMN-14724) readback, surfaces two real tensions not present in any prior instance -- B2 (worker capacity) canceled today with no successor, and B11/B12 marked Done in Linear while their own cited evidence artifacts (runbook Sec 3.4, this session's RDS reachability probe) don't independently confirm. - dated_chain_with_slack: negative slack -- the gating pin PRs (omninode_infra#818/#819) are open with a live, non-flake test conflict. - t20_handoff: searched and genuinely not found under docs/plans or docs/handoff -- recorded as absent, not force-fit to an adjacent artifact. - config_hash / policy_hash / b12_psql_readback / teardown_readback / executable_rollback (dry-run half): BLOCKED, same k8s/RDS access gap as the sibling OMN-15123/15124 round-4 packets, each with proof not assertion. - plan_row_binding: RESOLVED, same 2026-08-04 plan-governor fix as the sibling tickets, re-confirmed live here. go_no_go_decision: NO-GO for tonight's window, stated as the mechanical conclusion the template's own rule requires when the three gating fields carry real (if gapped) content -- not an operator override, and not silently deferred. Cross-checked against docs/tracking/2026-08-05-beta- blocking-axis-register.md (same-day EOD refresh) -- no contradiction found. Seam test 13/13 green. Zero AWS/k8s mutation -- every command run was a read-only describe/list/get/manifest-inspect. No merge (Codex lands). OMN-15125
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 14 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (5)
Comment |
|
OCC autobind did not mint a companion for this PR: no changed-file candidate could be proven RED against the merge base, and emitting a PR-existence probe instead would be non-falsifiable evidence (OMN-15247). Hand-authored evidence is required. |
✅ Hostile Reviewer — PASSEDBlocking findings (critical): 0 Gate semantics (pilot phase)
Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524) |
…TERNAL_CONTEXTS OMN-13873 shipped `Dep Provenance Gate` (dep-provenance-gate.yml) but its own DoD item "required on infra dev/main branch protection" was never fulfilled live: the context reports on every PR (no job-level `if:`) but blocks nothing on dev or main today. Measured per ci_summary_gate.py's own admission rule: 16/16 present, 16/16 green over the last 16 merged omnibase_infra dev PRs (#2646-#2669, 2026-08-04T16:56Z -> 2026-08-07T01:08Z, started_at <= mergedAt). Re-verified against the SAME #2546-#2567 golden-fixture window already pinned by test_ci_summary_gate.py: also 16/16 present, 16/16 green. Both windows agree, so the context is folded into EXPECTED_EXTERNAL_CONTEXTS and the existing fixture rows, closing it fail-closed on dev via the sole required `CI Summary` umbrella (code path per CLAUDE.md rule 10 — no branch-protection API mutation in this PR). Also bundles a pre-existing, unrelated node-migration vendor-sync drift fix (scripts/sync-node-migrations.sh output) that was already red on dev HEAD before this change and blocked the pre-commit gate for this PR (no-pre-existing-excuse policy).
…TERNAL_CONTEXTS (#2684) * fix(OMN-15737): admit Dep Provenance Gate into CI Summary EXPECTED_EXTERNAL_CONTEXTS OMN-13873 shipped `Dep Provenance Gate` (dep-provenance-gate.yml) but its own DoD item "required on infra dev/main branch protection" was never fulfilled live: the context reports on every PR (no job-level `if:`) but blocks nothing on dev or main today. Measured per ci_summary_gate.py's own admission rule: 16/16 present, 16/16 green over the last 16 merged omnibase_infra dev PRs (#2646-#2669, 2026-08-04T16:56Z -> 2026-08-07T01:08Z, started_at <= mergedAt). Re-verified against the SAME #2546-#2567 golden-fixture window already pinned by test_ci_summary_gate.py: also 16/16 present, 16/16 green. Both windows agree, so the context is folded into EXPECTED_EXTERNAL_CONTEXTS and the existing fixture rows, closing it fail-closed on dev via the sole required `CI Summary` umbrella (code path per CLAUDE.md rule 10 — no branch-protection API mutation in this PR). Also bundles a pre-existing, unrelated node-migration vendor-sync drift fix (scripts/sync-node-migrations.sh output) that was already red on dev HEAD before this change and blocked the pre-commit gate for this PR (no-pre-existing-excuse policy). * fix(OMN-15737): preserve original 1-space indent in fixture json The previous commit's json.dump reformatted the whole fixture file (2-space indent vs the file's original 1-space convention), producing an 8000-line diff noise. Re-dump with indent=1 to match the existing style; diff is now scoped to the actual added rows. * fix(OMN-15737): declare the 2 newly-vendored node migrations in the manifest test_application_migration_manifest.py caught what the bundled vendor-sync fix (previous commit) missed: adding node_canary_score_reducer/0003 and node_projection_registration/0004 to the vendor tree without a matching declaration in docker/migrations/forward/_ledger/application-migrations.tsv left the manifest incomplete (94 declared vs 96 on disk). Domain classification follows the established, already-committed pattern for each node rather than inventing new policy: - node_canary_score_reducer/0003 (capability_scores tenant_id TEXT->UUID): domain=tenant, continuing sibling 0002's tenant domain for the same already-tenant-classified column. - node_projection_registration/0004 (node_service_registry NO FORCE RLS): domain=omninode_internal, matching the file's own inline OMN-15336 item-4 domain corroboration (contract.yaml db_io.schema=omninode_internal, 2026-08-02 operator ruling, OMN-15656 grants-derivation correction). Full impacted suite (scripts/ci/tests, scripts/tests, tests/ci, tests/scripts, tests/unit/scripts) re-run green: 3011 passed, 5 skipped. * fix(OMN-15737): dedupe stale vendor-migration TSV rows introduced by dev rebase The OMN-15732 deadlock-fix rebase auto-merged two intermediate commits' TSV additions for node_canary_score_reducer/0003 and node_projection_registration/0004 with stale checksums, alongside dev's already-correct rows for the same files (dev holds the adjudicated single-file 0003 since 211e81e). Take dev's TSV wholesale -- this PR has no legitimate TSV diff of its own.
Summary
First real, dated instance of the OMN-15125 Aug-5 GO/NO-GO packet (previously only the unfilled template existed). Fills all 15 manifest fields with either real live evidence or an explicit, proven BLOCKED marker — no placeholder values.
Highlights:
source_digest/previous_digest/amd64_manifest: live ECR-verified round-4 vs round-3 candidate tuple (round-3 = prior build-lineage pin, not a livekubectl rollout historyreadback — caveated as such).vulnerability_result: 4 CRITICAL / 12 HIGH findings on the round-4 image, live-verified viadescribe-image-scan-findings— flags a discrepancy wheredescribe-images'imageScanStatusfield returnsnullfor the same digest.a6_thresholds_with_live_samples: 5/5 thresholds loaded and wired, 0/5 have ever fired against a real soak (counted as unloaded per the manifest's own rule).reconciled_blocker_graph: livelist_issues(parentId=OMN-14724)readback surfaces two unresolved tensions — B2 (worker capacity) canceled today with no successor, and B11/B12 marked Done in Linear while their own cited evidence (runbook §3.4, this session's own RDS-unreachable probe) doesn't independently confirm.dated_chain_with_slack: negative slack — the gating pin PRsomninode_infra#818/#819are open with a live, non-flake test-assertion conflict.t20_handoff: searched and genuinely not found — recorded absent rather than force-fit.go_no_go_decision: NO-GO for tonight's window — the mechanical conclusion the template's own rule requires once the three gating fields carry real content, cross-checked against the same-daydocs/tracking/2026-08-05-beta-blocking-axis-register.mdEOD refresh (no contradiction found).Zero AWS/k8s mutation — every command run was a read-only
describe/list/get/manifest inspect.Ticket
OMN-15125 (parent epic OMN-14724). dod_evidence: this PR is the first substantive evidence packet for OMN-15125, not a closure — the decision it records is NO-GO, and several fields remain BLOCKED (see the packet's own field table). Do not read this PR as satisfying the ticket's acceptance criteria in full.
Test plan
tests/ci/test_managed_staging_proof_kit_seam.py— 13/13 passedEvidence-Source: OCC#6147
Evidence-Ticket: OMN-15125