Skip to content

fix(OMN-15846): cross-DB disposition for 083/096/097 - #2719

Merged
jonahgabriel merged 4 commits into
devfrom
jonah/omn-15846-crossdb-083-096-097-disposition
Aug 11, 2026
Merged

jonahgabriel merged 4 commits into
devfrom
jonah/omn-15846-crossdb-083-096-097-disposition

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Aug 11, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Re-audits the three unallowlisted cross-DB flat migrations that FATAL the onex-dev k8s migrate Job in numeric order (083, then 096, then 097) now that OMN-15846's classification-ordering fix (already merged, omninode_infra #853) stops their false "applied" ledger rows from masking the OMN-15819 UNDELIVERABLE path. Deploy runs 31435444462 / 31438758510 both FATAL at 083.

Live-verified 2026-08-10 via read-only SSM port-forward to onex-dev RDS (omninode-dev-postgres):

File Disposition Evidence
083_create_log_entries.sql undeliverable, node-owned replacement authored to_regclass('public.log_entries') NULL in both omnibase_infra and omnidash_analytics. False "applied" row 2026-07-28T22:53:47Z, checksum byte-identical to live content.
096_grant_role_omnidash_omnidash_analytics.sql undeliverable, tombstoned (no replacement needed) pg_default_acl for omnidash_analytics/public is empty — the file's unconditional ALTER DEFAULT PRIVILEGES never ran. role_omnidash already owns 89/90 tables there (OMN-15335 two-owner-split), which strictly subsumes this file's grants. File's own header scopes its rationale to the .201 lab lane.
097_grant_app_dashboard_connect_omnidash_analytics.sql undeliverable, tombstoned (no replacement needed) app_dashboard's USAGE on public is granted by pg_database_owner/omninodeadmin, not role_omnibase_infra. The CONNECT gap it repairs is latent (PUBLIC's CONNECT not yet revoked on this instance). OMN-15355 (P1, In Review, names app_dashboard explicitly) is the tracked systematic successor.

Changes

  • docker/migrations/forward/nodes/node_log_persistence_effect/0000_create_log_entries.sql — new, node-owned replacement, vendored byte-identical from omnimarket#2046 (companion PR).
  • docker/migrations/forward/083_create_log_entries.sql, 096_...sql, 097_...sql — tombstone headers added, content below unchanged (append-only).
  • docker/migrations/forward/cross-database-flat-migrations.yaml — all three move grandfathered → undeliverable with evidence citations. Zero grandfathered entries remain.
  • docker/migrations/forward/flat-node-shape-parity.yaml — log_entries dual-producer entry (status: identical).
  • docker/migrations/forward/_ledger/application-migrations.tsv — +1 row for the new node migration.
  • docker/migrations/schema_fingerprint.sha256 — restamped for the 083/096/097 content edits.
  • Test updates: tests/ci/test_flat_migration_no_foreign_connect_gate.py, tests/unit/scripts/validation/test_application_migration_manifest.py.

Follow-up (not this PR)

  • Image rebuild + repin in omninode_infra to pick up this migration content and the corresponding TOMBSTONE_ALLOWLIST addition for 083/096/097 in k8s/migrations/omnibase-infra-migrate.yaml (mirrors the chore(deps): update rich requirement from <14.0.0,>=13.7.0 to >=13.7.0,<15.0.0 #854 3-file pattern).
  • .201 stability lane checksum-sentinel ticket (separate finding, unrelated to this repo's changes) — filed against the platform, not this repo.

Ticket

OMN-15846

Test plan

  • tests/ci/test_flat_migration_no_foreign_connect_gate.py (24/24)
  • tests/ci/test_flat_node_migration_shape_parity.py (16/16)
  • tests/unit/scripts/validation/test_application_migration_manifest.py (all passing, count bumped 98→99)
  • tests/ci/test_node_migration_shape_reconciliation.py (OMN-15376 gate, new file passes)
  • scripts/sync-node-migrations.sh --check against omnimarket#2046 branch: in sync
  • python scripts/check_schema_fingerprint.py verify: OK
  • Full local suite via pre-push governed selector (escalated to full corpus given shared-manifest changes): 25343 passed, 45 skipped, 0 failed

Omnimarket-Source-Ref: jonah/omn-15846-log-entries-node-migration
Evidence-Ticket: OMN-15846
Evidence-Source: OCC#6345

…_entries + tombstone 096/097

Re-audits the three unallowlisted cross-DB flat migrations that FATAL the
onex-dev k8s migrate Job in numeric order (083, then 096, then 097) now that
OMN-15846's classification-ordering fix stops their false "applied" ledger
rows (2026-07-28/2026-08-01) from masking the OMN-15819 UNDELIVERABLE path.

Live-verified 2026-08-10 via read-only SSM port-forward to onex-dev RDS
(omninode-dev-postgres):

- 083 (log_entries): to_regclass('public.log_entries') is NULL in both
  omnibase_infra and omnidash_analytics. Genuinely undelivered and
  deliverable -- node-owned replacement authored under
  docker/migrations/forward/nodes/node_log_persistence_effect/ (vendored
  from the omnimarket PR landing the canonical source), same content as the
  flat file, delivered via the node-owned loop's role_omnidash connection.
  083 itself gets a tombstone header, byte-unchanged below it.

- 096 (role_omnidash grants): pg_default_acl for omnidash_analytics/public
  is empty -- this file's unconditional ALTER DEFAULT PRIVILEGES step never
  executed. Also unneeded on RDS: role_omnidash already owns 89/90 tables
  there (OMN-15335 two-owner-split migration-principal model), which
  strictly subsumes this file's named grants. File's own header scopes its
  FORCE-RLS rationale to the .201 lab lane specifically. Tombstoned, no
  replacement authored; OMN-15355 (P1, In Review) is the tracked systematic
  successor.

- 097 (app_dashboard CONNECT): app_dashboard's USAGE on schema public is
  granted by pg_database_owner/omninodeadmin, not role_omnibase_infra -- this
  file never delivered anything there either. The CONNECT gap it repairs is
  latent on RDS today (PUBLIC's CONNECT has not been revoked). Tombstoned,
  no replacement authored; OMN-15355 (explicit app_dashboard acceptance
  criterion) is the tracked successor.

cross-database-flat-migrations.yaml: all three move from grandfathered (not
re-audited) to undeliverable (re-audited, with evidence). Manifest is now a
fully-audited closed ledger with zero grandfathered entries.

Also: flat-node-shape-parity.yaml (log_entries dual-producer, identical
shape), application-migrations.tsv (+1 row), schema_fingerprint.sha256
restamped for the 083/096/097 content edits, OMN-15376 shape-reconciliation
block in the new node migration, and test updates for all of the above.

Cites: OMN-15846, OMN-15819 (precedent), OMN-15335, OMN-15355, OMN-12131.
@coderabbitai

coderabbitai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 50 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 1865219f-6fc1-4e89-be7b-979e53624efd

📥 Commits

Reviewing files that changed from the base of the PR and between fd4a84b and a0df885.

⛔ Files ignored due to path filters (1)
  • docker/migrations/forward/_ledger/application-migrations.tsv is excluded by !**/*.tsv
📒 Files selected for processing (20)
  • docker/catalog/database-topology/judge.yaml
  • docker/catalog/database-topology/local.yaml
  • docker/catalog/database-topology/onex-dev.yaml
  • docker/catalog/database-topology/onex-prod.yaml
  • docker/catalog/database-topology/prod.yaml
  • docker/catalog/database-topology/stability-test.yaml
  • docker/catalog/database-topology/test.yaml
  • docker/migrations/forward/083_create_log_entries.sql
  • docker/migrations/forward/096_grant_role_omnidash_omnidash_analytics.sql
  • docker/migrations/forward/097_grant_app_dashboard_connect_omnidash_analytics.sql
  • docker/migrations/forward/cross-database-flat-migrations.yaml
  • docker/migrations/forward/flat-node-shape-parity.yaml
  • docker/migrations/forward/nodes/node_log_persistence_effect/0000_create_log_entries.sql
  • docker/migrations/schema_fingerprint.sha256
  • scripts/ci/check_application_database_sql.py
  • src/omnibase_infra/topology/instances/local.yaml
  • src/omnibase_infra/topology/instances/onex-dev.yaml
  • src/omnibase_infra/topology/instances/onex-prod.yaml
  • tests/ci/test_flat_migration_no_foreign_connect_gate.py
  • tests/unit/scripts/validation/test_application_migration_manifest.py

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

✅ Hostile Reviewer — PASSED

Blocking findings (critical): 0
Total findings: 0
Models succeeded: qwen3-review,qwen3-review-b


Gate semantics (pilot phase)

Verdict Meaning Blocks merge?
passed No critical findings No
blocked CRITICAL findings found Yes
degraded All models unavailable (infra) No (pilot)

Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)

…6 from OMN-15361 gate

The node-owned log_entries migration now creates omninode_internal.log_entries
(schema-qualified, matching the node's own db_io.db_tables[].schema and the
node_projection_live_events precedent) instead of bare log_entries --
scripts/ci/check_application_database_sql.py (OMN-15361/OMN-15423 domain
enforcement) requires new deployable SQL targets be schema-qualified against
a declared topology domain.

083 and 096 are TOMBSTONED this same PR (undeliverable via the k8s Job) --
their append-only byte-unchanged-below-header convention means their
pre-existing unqualified targets cannot be qualified in place. Both are the
first PR to touch either file since this gate started linting changed files,
so both need a _LEGACY_DEFAULT_SCHEMA_SQL_EXACT_PATHS entry (same bucket
099 already uses for its own untouched DO blocks).

Verified locally: application_database_sql_gate=PASS against origin/dev,
with omnimarket's paired branch (application-relation-ownership.yaml entry)
as the ownership manifest.
…conciliation DO blocks

Vendors the CodeRabbit-driven fixes from the paired omnimarket PR (schema-
qualified INSERT, NOT NULL/PK/DEFAULT reconciliation). The new reconciliation
DO blocks use EXECUTE format(...) for dynamic per-column SQL -- the same
idiom node_projection_live_events/0000_create_live_events.sql already uses
for its own OMN-15376 reconciliation -- which scripts/ci/check_application_database_sql.py
cannot prove statically regardless of guarding/idempotency. Adds this file to
the same _LEGACY_DEFAULT_SCHEMA_SQL_EXACT_PATHS bucket 099 already uses for
the identical limitation.
…og_entries

scripts/generate_application_database_table_grants.py --write, driven by
node_log_persistence_effect's db_io.db_tables declaration (schema:
omninode_internal). Adds omninode_runtime INSERT/SELECT/UPDATE on
omninode_internal.log_entries across all 7 rendered profiles
(judge/local/onex-dev/onex-prod/prod/stability-test/test) -- --check --prove
now reports 45 PASS / 0 FAIL on every profile (was 44/1). Also vendors the
paired omnimarket PR's matching migration-level GRANT (the physical
counterpart to this declared grant).
jonahgabriel added a commit to OmniNode-ai/onex_change_control that referenced this pull request Aug 11, 2026
…ibase_infra#2719 (#6345)

* evidence(OMN-15846): author OCC companion for OmniNode-ai/omnibase_infra#2719

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 59cc54d33c57251b1f293e8ec4a27bfd32c2b587.

* evidence(OMN-15846): self-bind OCC#6345 + rebind contract_sha256

* fix(OMN-15846): revert autobind's in-place edit of a pre-existing shared receipt (append-only)

The occ-autobind tooling modified drift/dod_receipts/OMN-15846/dod-occ-evidence-admissibility-validator/command.yaml
in place (updated commit_sha/run_timestamp/probe fields) rather than
authoring a net-new file -- a real OCC Append-Only Gate violation
(validator_occ_append_only), not a false positive. Reverted to the
merge-base content. This companion's genuinely new evidence
(dod-OmniNode-ai-omnibase_infra-pr-2719, dod-...-pr-2719-ci,
occ-self-bind-pr-6345) is unaffected -- all three are net-new files/entries
and do not depend on this shared receipt being re-stamped.

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>
@jonahgabriel
jonahgabriel merged commit 404f8c7 into dev Aug 11, 2026
200 of 203 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-15846-crossdb-083-096-097-disposition branch August 11, 2026 03:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant