Skip to content

fix(OMN-16296): drop onex_change_control from compute_workspace_provenance.py - #2837

Merged
github-actions[bot] merged 2 commits into
devfrom
jonah/omn-16296-provenance-script-parity
Aug 22, 2026
Merged

github-actions[bot] merged 2 commits into
devfrom
jonah/omn-16296-provenance-script-parity

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Aug 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

#2822 removed onex_change_control from stage_workspace.sh, sibling_clone_manifest.sh, and check_sibling_lock_pins.py, but missed compute_workspace_provenance.py — the script that runs inside Dockerfile.runtime's builder stage. Since stage_workspace.sh no longer stages a sibling-repos/onex_change_control directory, the builder stage now fails identically to the original OMN-16296 symptom, one step later:

Missing sibling repo: /workspace/sibling-repos/onex_change_control

This PR removes the stale entry from both places it appears in compute_workspace_provenance.py: WORKSPACE_PACKAGES (the per-sibling content-parity proof loop) and the siblings dict feeding the OMN-12989 pin-comparison block. Also removes the same stale entry from resolve_workspace_pins.py's SIBLING_DISTRIBUTIONS (unused, but documented as mirroring WORKSPACE_PACKAGES — left stale it would drift silently) and updates two test fixtures that still expected onex_change_control in the manifest.

Scripts/tests-only change — no runtime or contract surface touched.

Why now

Blocked on infra dev publishing ahead of the last released version (the pyproject-version-vs-published-version release-identity gate) — dev now carries 0.38.9 (tip 559ee46), so this rebases and passes cleanly.

Refs OMN-16296, OMN-16375 (unblocks build-workspace-candidate-runtime's provenance step).

Test plan

  • uv run pytest tests/scripts/test_check_sibling_lock_pins.py tests/scripts/test_stage_workspace_vcs_provenance.py -q — 18 passed
  • uv run pytest tests/scripts/test_check_release_identity.py -q — 15 passed
  • Governed pre-push selector (OMN-13973) escalated to full suite — 1723 passed, 6 skipped
  • ruff format/check clean, pre-commit clean

Evidence-Ticket: OMN-16296
Evidence-Source: OCC#6861

Summary by CodeRabbit

  • Chores
    • Removed an obsolete sibling repository from workspace provisioning and version-pin validation.
  • Tests
    • Updated workspace provenance and manifest validation scenarios to reflect the current set of sibling repositories.

…nance.py

#2822 removed onex_change_control from stage_workspace.sh,
sibling_clone_manifest.sh, and check_sibling_lock_pins.py, but missed
compute_workspace_provenance.py -- the script that runs inside
Dockerfile.runtime's builder stage. Since stage_workspace.sh no longer
stages a sibling-repos/onex_change_control directory, the builder stage
now fails identically to the original OMN-16296 symptom, one step later:

    Missing sibling repo: /workspace/sibling-repos/onex_change_control

Removes the stale entry from both places it appears in this file:
WORKSPACE_PACKAGES (the per-sibling content-parity proof loop) and the
siblings dict feeding the OMN-12989 pin-comparison block. Also removes
the same stale entry from resolve_workspace_pins.py's SIBLING_DISTRIBUTIONS
(unused, but documented as mirroring WORKSPACE_PACKAGES -- left stale it
reproduces the same drift this ticket exists to close) and trims the two
test fixtures that built a synthetic sibling-repos tree matching the old
four/three-sibling set.

Tests: tests/scripts/test_check_sibling_lock_pins.py,
tests/scripts/test_compute_workspace_provenance_content_parity.py,
tests/scripts/test_stage_workspace_vcs_provenance.py,
tests/unit/scripts/test_check_sibling_lock_pins.py,
tests/unit/scripts/test_resolve_workspace_pins.py -- 80 passed. Full
tests/scripts + tests/unit/scripts -- 1640 passed / 6 skipped (macOS-only
GNU-realpath skips, OMN-15134) / 1 pre-existing failure unrelated to this
diff (test_fresh_deploy_fitness_gates.py::test_release_identity_passes_when_version_ahead,
reproduces identically on clean dev tip before this change -- a
pyproject-version-vs-published-version gate, not a scripts/tests-only PR
concern). ruff format/check clean; pre-commit clean.

Refs OMN-16296, OMN-16375.
@coderabbitai

coderabbitai Bot commented Aug 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your current included review allowance is based on your included PR review attempts over the past 7 days.

Next review available in: 31 minutes

Limit details: You’ve used the included review currently available. Your 119 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

Wait for the limit to reset, then comment @coderabbitai review or push new commits to the PR.

An organization admin can change what happens after included review limits in Billing.

How do review limits work?

CodeRabbit enforces per-developer PR review limits within each organization.

For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: ed7869bd-4a57-400c-ac0f-3691a835f160

📥 Commits

Reviewing files that changed from the base of the PR and between 139f222 and 7ca6003.

📒 Files selected for processing (1)
  • scripts/deploy-agent/tests/unit/test_executor_workspace_provenance.py

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 69a7aa17-d57b-4601-b7a6-cd928036f920

📥 Commits

Reviewing files that changed from the base of the PR and between 559ee46 and 139f222.

📒 Files selected for processing (4)
  • scripts/runtime_build/compute_workspace_provenance.py
  • scripts/runtime_build/resolve_workspace_pins.py
  • tests/scripts/test_check_sibling_lock_pins.py
  • tests/scripts/test_stage_workspace_vcs_provenance.py
💤 Files with no reviewable changes (3)
  • scripts/runtime_build/compute_workspace_provenance.py
  • tests/scripts/test_stage_workspace_vcs_provenance.py
  • scripts/runtime_build/resolve_workspace_pins.py

Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


📝 Walkthrough

Walkthrough

The workspace provenance and pin-resolution scripts no longer track onex_change_control. Related tests now create sibling repository fixtures without that repository.

Changes

Workspace sibling removal

Layer / File(s) Summary
Update provenance and pin mappings
scripts/runtime_build/compute_workspace_provenance.py, scripts/runtime_build/resolve_workspace_pins.py
The workspace package map, lock-pin comparison inputs, and sibling distribution map exclude onex_change_control.
Align provenance test fixtures
tests/scripts/test_check_sibling_lock_pins.py, tests/scripts/test_stage_workspace_vcs_provenance.py
Synthetic sibling repository layouts no longer include onex_change_control.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to 139f2

This PR removes stale workspace references and updates the affected test fixtures; no actionable merge-blocking risk remains after normal checks and review.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the primary change: removing the stale onex_change_control reference from compute_workspace_provenance.py.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-16296-provenance-script-parity

Comment @coderabbitai help to get the list of available commands.

@github-actions
github-actions Bot enabled auto-merge (squash) August 22, 2026 00:30
@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

OCC autobind did not mint a companion for this PR: no changed-file candidate could be proven RED against the merge base, and emitting a PR-existence probe instead would be non-falsifiable evidence (OMN-15247). Hand-authored evidence is required.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Hostile Reviewer — PASSED

Blocking findings (critical): 0
Total findings: 0
Models succeeded: qwen3-review,qwen3-review-b


Gate semantics (pilot phase)

Verdict Meaning Blocks merge?
passed No critical findings No
blocked CRITICAL findings found Yes
degraded All models unavailable (infra) No (pilot)

Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)

jonahgabriel pushed a commit to OmniNode-ai/onex_change_control that referenced this pull request Aug 22, 2026
#6861)

* evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#2837

* evidence: OCC companion self-bind for #6861

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
scripts/deploy-agent has its own standalone uv sub-project with a
duplicate test file exercising compute_workspace_provenance.py
(scripts/deploy-agent/tests/unit/test_executor_workspace_provenance.py,
wired into CI as "Deploy Agent Tests (OMN-15378)" -- a separate pytest
root from tests/scripts/, so it wasn't covered by the targeted-test run
in 139f222).

test_provenance_script_passes_with_valid_local_installs staged three
sibling dirs (omnibase_compat, onex_change_control, omnimarket) and
asserted the manifest recorded 3 proofs -- both now stale after
onex_change_control was dropped from WORKSPACE_PACKAGES. Trims the
staged dir to the two siblings the script's proof loop still walks and
updates the assertion to match (2 proofs).

Tests: uv run --project scripts/deploy-agent --extra dev pytest
scripts/deploy-agent/tests -q --tb=short -- 198 passed, 8 skipped.

Refs OMN-16296, OMN-16375.
@github-actions
github-actions Bot merged commit e3cb996 into dev Aug 22, 2026
103 checks passed
@github-actions
github-actions Bot deleted the jonah/omn-16296-provenance-script-parity branch August 22, 2026 01:06
github-actions Bot pushed a commit that referenced this pull request Aug 27, 2026
… contract-compliance (#2926)

`ci.yml`'s `contract-compliance` step met an empty `PR_NUMBER` with `exit 0`.
That was a vacuous pass on a required gate: "Contract Compliance Check" is a
GATE_JOBS entry in `scripts/ci/ci_summary_gate.py`, and CI Summary is this
repo's sole required branch-protection context, so the umbrella poller counted
a run that evaluated zero DoD check_values as a *provable* pass. Unlike a red
gate, a green one that checked nothing never prompts investigation.

Scope correction against the ticket body, which claimed "every dev push":
`on.push.branches` here is `[main]`, so this never fired on a dev commit. The
two live fail-open events are push-to-main (release-synced fast-forwards) and
merge_group -- the latter unexercised today (no registry repo has a queue on
dev as of 2026-08-24) but a latent bypass of the sole required context the
instant a queue returns, with zero further code change.

The fix is resolution, not narrowing. Excluding push/merge_group with a
job-level `if:` would publish a `skipped` check run, which branch protection
counts as passing -- the OMN-14863 skip-vector class. So the job keeps running
on all three events and `scripts/ci/resolve_contract_compliance_pr.py` answers
which PR's check_values apply: the event's own number on pull_request (no API
call, behaviourally identical to pre-fix), the `pr-<n>-` segment of the
gh-readonly-queue ref on merge_group (no API call), or the merged source PR of
the pushed commit via `gh api repos/{repo}/commits/{sha}/pulls`. Anything
unresolved -- including a transient gh failure -- exits 1.

Verified live against the real API before landing: dev 8ce11d5 -> #2923, and
the three most recent main commits -> #2837/#2823/#2835, so the push path now
evaluates a real scope rather than going spuriously red. An all-zero SHA exits
1 with no stdout.

Ships with the OMN-15547 incident replay its own default-deny rule demands:
two verbatim `gh api` captures under tests/fixtures/omn16508/ -- the empty
association list GitHub really returns for a commit no merged PR produced
(6d7090d, head of closed-unmerged #2890), which the guard must reject, and a
21KB merged-PR response (5b904d8 -> #2378) as the control that stops a
hard-wired `return None` from replaying the incident while failing every
legitimate push-to-main closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant