Repository navigation
fix(OMN-15846): cross-DB disposition for 083/096/097 - #2719
Conversation
…_entries + tombstone 096/097
Re-audits the three unallowlisted cross-DB flat migrations that FATAL the
onex-dev k8s migrate Job in numeric order (083, then 096, then 097) now that
OMN-15846's classification-ordering fix stops their false "applied" ledger
rows (2026-07-28/2026-08-01) from masking the OMN-15819 UNDELIVERABLE path.
Live-verified 2026-08-10 via read-only SSM port-forward to onex-dev RDS
(omninode-dev-postgres):
- 083 (log_entries): to_regclass('public.log_entries') is NULL in both
omnibase_infra and omnidash_analytics. Genuinely undelivered and
deliverable -- node-owned replacement authored under
docker/migrations/forward/nodes/node_log_persistence_effect/ (vendored
from the omnimarket PR landing the canonical source), same content as the
flat file, delivered via the node-owned loop's role_omnidash connection.
083 itself gets a tombstone header, byte-unchanged below it.
- 096 (role_omnidash grants): pg_default_acl for omnidash_analytics/public
is empty -- this file's unconditional ALTER DEFAULT PRIVILEGES step never
executed. Also unneeded on RDS: role_omnidash already owns 89/90 tables
there (OMN-15335 two-owner-split migration-principal model), which
strictly subsumes this file's named grants. File's own header scopes its
FORCE-RLS rationale to the .201 lab lane specifically. Tombstoned, no
replacement authored; OMN-15355 (P1, In Review) is the tracked systematic
successor.
- 097 (app_dashboard CONNECT): app_dashboard's USAGE on schema public is
granted by pg_database_owner/omninodeadmin, not role_omnibase_infra -- this
file never delivered anything there either. The CONNECT gap it repairs is
latent on RDS today (PUBLIC's CONNECT has not been revoked). Tombstoned,
no replacement authored; OMN-15355 (explicit app_dashboard acceptance
criterion) is the tracked successor.
cross-database-flat-migrations.yaml: all three move from grandfathered (not
re-audited) to undeliverable (re-audited, with evidence). Manifest is now a
fully-audited closed ledger with zero grandfathered entries.
Also: flat-node-shape-parity.yaml (log_entries dual-producer, identical
shape), application-migrations.tsv (+1 row), schema_fingerprint.sha256
restamped for the 083/096/097 content edits, OMN-15376 shape-reconciliation
block in the new node migration, and test updates for all of the above.
Cites: OMN-15846, OMN-15819 (precedent), OMN-15335, OMN-15355, OMN-12131.
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 50 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (20)
Comment |
✅ Hostile Reviewer — PASSEDBlocking findings (critical): 0 Gate semantics (pilot phase)
Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524) |
…6 from OMN-15361 gate The node-owned log_entries migration now creates omninode_internal.log_entries (schema-qualified, matching the node's own db_io.db_tables[].schema and the node_projection_live_events precedent) instead of bare log_entries -- scripts/ci/check_application_database_sql.py (OMN-15361/OMN-15423 domain enforcement) requires new deployable SQL targets be schema-qualified against a declared topology domain. 083 and 096 are TOMBSTONED this same PR (undeliverable via the k8s Job) -- their append-only byte-unchanged-below-header convention means their pre-existing unqualified targets cannot be qualified in place. Both are the first PR to touch either file since this gate started linting changed files, so both need a _LEGACY_DEFAULT_SCHEMA_SQL_EXACT_PATHS entry (same bucket 099 already uses for its own untouched DO blocks). Verified locally: application_database_sql_gate=PASS against origin/dev, with omnimarket's paired branch (application-relation-ownership.yaml entry) as the ownership manifest.
…conciliation DO blocks Vendors the CodeRabbit-driven fixes from the paired omnimarket PR (schema- qualified INSERT, NOT NULL/PK/DEFAULT reconciliation). The new reconciliation DO blocks use EXECUTE format(...) for dynamic per-column SQL -- the same idiom node_projection_live_events/0000_create_live_events.sql already uses for its own OMN-15376 reconciliation -- which scripts/ci/check_application_database_sql.py cannot prove statically regardless of guarding/idempotency. Adds this file to the same _LEGACY_DEFAULT_SCHEMA_SQL_EXACT_PATHS bucket 099 already uses for the identical limitation.
…og_entries scripts/generate_application_database_table_grants.py --write, driven by node_log_persistence_effect's db_io.db_tables declaration (schema: omninode_internal). Adds omninode_runtime INSERT/SELECT/UPDATE on omninode_internal.log_entries across all 7 rendered profiles (judge/local/onex-dev/onex-prod/prod/stability-test/test) -- --check --prove now reports 45 PASS / 0 FAIL on every profile (was 44/1). Also vendors the paired omnimarket PR's matching migration-level GRANT (the physical counterpart to this declared grant).
…ibase_infra#2719 (#6345) * evidence(OMN-15846): author OCC companion for OmniNode-ai/omnibase_infra#2719 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 59cc54d33c57251b1f293e8ec4a27bfd32c2b587. * evidence(OMN-15846): self-bind OCC#6345 + rebind contract_sha256 * fix(OMN-15846): revert autobind's in-place edit of a pre-existing shared receipt (append-only) The occ-autobind tooling modified drift/dod_receipts/OMN-15846/dod-occ-evidence-admissibility-validator/command.yaml in place (updated commit_sha/run_timestamp/probe fields) rather than authoring a net-new file -- a real OCC Append-Only Gate violation (validator_occ_append_only), not a false positive. Reverted to the merge-base content. This companion's genuinely new evidence (dod-OmniNode-ai-omnibase_infra-pr-2719, dod-...-pr-2719-ci, occ-self-bind-pr-6345) is unaffected -- all three are net-new files/entries and do not depend on this shared receipt being re-stamped. --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai>
Summary
Re-audits the three unallowlisted cross-DB flat migrations that FATAL the onex-dev k8s migrate Job in numeric order (083, then 096, then 097) now that OMN-15846's classification-ordering fix (already merged,
omninode_infra#853) stops their false "applied" ledger rows from masking the OMN-15819 UNDELIVERABLE path. Deploy runs 31435444462 / 31438758510 both FATAL at 083.Live-verified 2026-08-10 via read-only SSM port-forward to onex-dev RDS (
omninode-dev-postgres):083_create_log_entries.sqlto_regclass('public.log_entries')NULL in bothomnibase_infraandomnidash_analytics. False "applied" row2026-07-28T22:53:47Z, checksum byte-identical to live content.096_grant_role_omnidash_omnidash_analytics.sqlpg_default_aclforomnidash_analytics/publicis empty — the file's unconditionalALTER DEFAULT PRIVILEGESnever ran.role_omnidashalready owns 89/90 tables there (OMN-15335 two-owner-split), which strictly subsumes this file's grants. File's own header scopes its rationale to the.201lab lane.097_grant_app_dashboard_connect_omnidash_analytics.sqlapp_dashboard's USAGE onpublicis granted bypg_database_owner/omninodeadmin, notrole_omnibase_infra. The CONNECT gap it repairs is latent (PUBLIC's CONNECT not yet revoked on this instance). OMN-15355 (P1, In Review, namesapp_dashboardexplicitly) is the tracked systematic successor.Changes
docker/migrations/forward/nodes/node_log_persistence_effect/0000_create_log_entries.sql— new, node-owned replacement, vendored byte-identical from omnimarket#2046 (companion PR).docker/migrations/forward/083_create_log_entries.sql,096_...sql,097_...sql— tombstone headers added, content below unchanged (append-only).docker/migrations/forward/cross-database-flat-migrations.yaml— all three movegrandfathered→undeliverablewith evidence citations. Zerograndfatheredentries remain.docker/migrations/forward/flat-node-shape-parity.yaml—log_entriesdual-producer entry (status: identical).docker/migrations/forward/_ledger/application-migrations.tsv— +1 row for the new node migration.docker/migrations/schema_fingerprint.sha256— restamped for the 083/096/097 content edits.tests/ci/test_flat_migration_no_foreign_connect_gate.py,tests/unit/scripts/validation/test_application_migration_manifest.py.Follow-up (not this PR)
omninode_infrato pick up this migration content and the correspondingTOMBSTONE_ALLOWLISTaddition for 083/096/097 ink8s/migrations/omnibase-infra-migrate.yaml(mirrors the chore(deps): update rich requirement from <14.0.0,>=13.7.0 to >=13.7.0,<15.0.0 #854 3-file pattern)..201stability lane checksum-sentinel ticket (separate finding, unrelated to this repo's changes) — filed against the platform, not this repo.Ticket
OMN-15846
Test plan
tests/ci/test_flat_migration_no_foreign_connect_gate.py(24/24)tests/ci/test_flat_node_migration_shape_parity.py(16/16)tests/unit/scripts/validation/test_application_migration_manifest.py(all passing, count bumped 98→99)tests/ci/test_node_migration_shape_reconciliation.py(OMN-15376 gate, new file passes)scripts/sync-node-migrations.sh --checkagainst omnimarket#2046 branch: in syncpython scripts/check_schema_fingerprint.py verify: OKOmnimarket-Source-Ref: jonah/omn-15846-log-entries-node-migration
Evidence-Ticket: OMN-15846
Evidence-Source: OCC#6345