Repository navigation
feat(OMN-16773): schedule the delegation chain canary so a dead chain is caught in hours, not weeks - #2940
feat(OMN-16773): schedule the delegation chain canary so a dead chain is caught in hours, not weeks#2940jonahgabriel wants to merge 4 commits into
Conversation
|
Warning Review limit reachedNext included review available in 21 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 131 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (20)
Comment |
|
| Verdict | Meaning | Blocks merge? |
|---|---|---|
passed |
No critical findings | No |
blocked |
CRITICAL findings found | Yes |
degraded |
All models unavailable (infra) | No (pilot) |
Powered by omniintelligence.review_pairing.cli_review — multi-model adversarial review (OMN-8468/OMN-8524)
#7328) * evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#2940 * evidence: OCC companion self-bind for #7328 --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
8c150e6 to
676c87a
Compare
… is caught in hours
The 13-class delegation matrix existed only as a recorded MANUAL recipe.
Nothing ran it. An omnimarket contract change on 2026-08-23 (OMN-15631)
gave node_delegation_routing_reducer a db_io block, the runtime's
_prepare_handler_wiring selected the projection dispatch arm on
db_io.db_tables alone, and every delegation began quarantining. The chain
stayed dead four days until a human fired the recipe by hand while closing
an unrelated ticket (OMN-16767).
delegation-seam-gate.yml was green throughout, correctly: it drives the
seam over InMemoryTransport, where the wiring is constructed by the test.
No in-memory seam test can observe a DEPLOYED wiring arm picking the wrong
path. This closes that gap by firing a real delegation at the real deployed
ingress on a schedule.
- node_chain_canary_effect (EFFECT_GENERIC): POST {probe_url}/skill with
command_name=node_delegate_skill_orchestrator and a per-run correlation
id minted in the handler and NOT settable by the caller; asserts a
terminal inside a declared budget; then scans the quarantine sink tail
for that same correlation id.
- Verdicts are ranked, not collapsed. QUARANTINED outranks TERMINAL_MISSING
because both are true in the OMN-16767 incident and only the first names
the defect. SKIPPED_NOT_CONFIGURED is never reported as CLEAN, and a
configured-but-unrunnable quarantine check fails closed.
- chain-canary.yml: every 2h on omnibase-deploy (the one runner with the
host-gateway alias that can reach the lane's published ports), receipt
into the job summary, non-zero exit on any non-GREEN verdict.
- tests/ci/test_chain_canary_workflow.py is the PR-time guard: the canary
has no pull_request trigger (it publishes a real command onto the lane),
so nothing else would notice its wiring rotting.
Two defects in the quarantine leg were found by running it live rather
than by reasoning about it, and both are recorded at their fix sites:
partitions_for_topic() returns None for a topic the consumer never
subscribed to even when topics() lists it, and aiokafka surfaces
CancelledError out of consumer.stop().
Dev lane only. No claim is made about stability-test, judge, or prod.
…parity fixture Two CI gates caught the same omission from opposite directions. `Handler Contract Compliance` and `imperative-contract-guard` both reported handler_chain_canary as `hybrid`/`undeclared transport KAFKA`: the contract declared only `metadata.transport_type: http` (the /skill ingress POST) while the handler also speaks Kafka for the correlation-scoped quarantine tail scan. Declared on the handler_routing entry rather than via `event_bus.subscribe_topics`, because a declared subscribe topic is how the runtime auto-wires a live consumer and a canary must never become a subscriber on the sink it only samples on demand. node_kafka_replay_compute sets the same precedent: KAFKA declared, event_bus topic lists left empty. `dispatch-parity-gate` reported the committed baseline fixture stale: the corpus grew by exactly this node's contract (137 -> 138). Regenerated with the harness the gate's own error message names. The diff is the +1 contract, the timestamp, and an omnibase-core 0.46.11 -> 0.46.13 pin that dev had already moved independently.
…to dev A concurrent rebase of this branch onto the new dev tip (eb05eee) resolved the tests/fixtures/dispatch_parity/baseline-selection-v2.json conflict by taking dev's side, which silently dropped the regeneration this branch needs: dev's baseline has contracts_discovered=139 and no chain_canary route, while this branch adds one contract. Regenerated with the command the gate's own failure message names: uv run python -m tests.fixtures.dispatch_parity.harness --out <fixture> corpus: 140 contracts, 115 dispatchers, 119 routes, 106 topics, 1042 probes 140 = dev's 139 + this node's contract, which is the whole diff.
3637b25 to
73b53a7
Compare
|
Closed as superseded by #2955 with the same repaired head and ticket-named branch for Receipt Gate identity binding. |
Pull request was closed
OMN-16773 — the delegation chain gets a canary
The 13-class delegation matrix existed only as a recorded manual recipe. Nothing ran it.
On 2026-08-23 an omnimarket contract change gave
node_delegation_routing_reduceradb_ioblock; the runtime's_prepare_handler_wiringselects the projection dispatch arm ondb_io.db_tablesalone, so a typed def-B handler began receiving a raw dict and every delegation went to the platform quarantine sink. The chain was dead for four days and was discovered on 2026-08-27 only because a human happened to fire the recipe by hand while closing an unrelated ticket (OMN-16767). The quarantine sink was at ~8,878,924 records at that moment, watched by nothing.delegation-seam-gate.yml(OMN-14771) was green throughout, and correctly so. It drives the delegation seam end-to-end overInMemoryTransport, where the wiring is constructed by the test. No in-memory seam test can observe a deployed wiring arm choosing the wrong dispatch path. That gate proves the seam is right in the tree; this one proves the chain is alive in the lane. Neither substitutes for the other.What lands
node_chain_canary_effect(EFFECT_GENERIC, omnibase_infra) — fires ONE delegation through the recorded recipe (POST {probe_url}/skill,command_name=node_delegate_skill_orchestrator, payload shape fromomnidash/server/routes.ts:216-234, task class fromomnidash/shared/contracts/delegation-task-types.json), asserts a terminal inside a declared budget, then scans the quarantine sink tail for that run's own correlation id.chain-canary.yml— every 2h onomnibase-deploy, receipt into the job summary, non-zero exit on any non-GREEN verdict.tests/ci/test_chain_canary_workflow.py— the PR-time guard. The canary has nopull_requesttrigger (it publishes a real command onto the lane), so nothing else would notice its wiring rotting.Design decisions worth reviewing
QUARANTINEDoutranksTERMINAL_MISSINGbecause in the OMN-16767 incident both are true and only the first names the defect. A canary reporting "timed out" there would have sent someone to look at latency instead of the dispatch seam.SKIPPED_NOT_CONFIGUREDis never reported asCLEAN, and a configured-but-unrunnable quarantine check fails the run. The entire reason this ticket exists is that a check nobody ran looked exactly like a check that passed.ok=truewith no terminal is RED (OMN-16027:publish_envelope()is fail-open, so a cheerful accept proves nothing).probe_urlis required with no default (Rule 8). A canary that guesses its own target can report green about a lane nobody meant to probe.Live evidence — the canary works, and its first result is RED
Run against the
.201dev lane 2026-08-27 (lane serving0.38.11, the pre-fix rev; OMN-16767's fix#2937is still OPEN/BLOCKED):{"verdict": "terminal_missing", "success": false, "detail": "no terminal event inside the 45000 ms budget after 46409 ms: ingress returned ok=false (dispatch_timeout: Local runtime ingress timed out after 45000 ms)", "probe_correlation_id": "da4834a2-7b26-4134-a482-c4f7cdc0388f", "ingress_error_code": "dispatch_timeout", "terminal_event": "", "quarantine_status": "clean", "quarantine_records_scanned": 300}That RED is the deliverable. A red canary on a known-dead chain is the product working.
Correlation-exact broker trace across four probes, posted in full to OMN-16767 — it also shows the failure has moved one hop earlier since the 15:32Z reproduction: all four probes reached
onex.cmd.omnimarket.delegate-skill.v1(offsets 20-23), none reacheddelegation-routing-request.v1, zero terminals, and the quarantine HWM did not advance by a single record (8,878,933 before and after). The orchestrator is no longer consuming its command topic at all. The canary reportedterminal_missing+cleanrather than falsely claimingquarantined— the verdict discrimination is doing real work.Two defects in the quarantine leg were found by running it live rather than by reasoning about it, and both are documented at their fix sites:
partitions_for_topic()returnsNonefor a topic the consumer never subscribed to, even whentopics()lists it — the scan fail-closed on a topic that plainly existed at 8.9M records.aiokafkasurfacesCancelledErrorout ofconsumer.stop(); catching onlyExceptionlet it escape and destroyed an otherwise complete scan result.Scope
Dev lane only (
omnibase-infra, the pre-authorized fully-mutable test platform). No claim is made aboutstability-test,judge, orprod, and the workflow must not be pointed at them without its own ticket — the probe publishes a real delegation command, which is a lane mutation.Two allowlist entries, both with precedent
scripts/check-env-reads.sh— third instance of the documented "RuntimeLocal single-shot compute path has no config-prefetch/overlay seam for a node's own kill switch" case, alongsidenode_evidence_autoclose_sweep_effect(OMN-16106) andnode_sync_revert_watchdog_effect(OMN-16536). The comment flags that three instances of one rationale means the matcher should learn the shape rather than take a fourth path.scripts/ci/infra-node-allowlist.txt— lane and runner topology are infra-exclusive, not a portable omnimarket business-domain capability.Deliberately not in this PR
hook-event-capturegateway entry is currently re-fenced, and OMN-16690's own body states it is un-fenced "only when this ticket is deployed AND the canary shows a row". OMN-16690 is still In Progress. The fence blocks the probe, so it is not built here.Pre-push evidence note (stated, not hidden)
The governed selector escalated to a full suite on
reason=test_infrastructure(this PR adds test files) and refused to run it locally at 1.25x-core load. Its PREFERRED remediation — let GitHub-hosted CI run the full suite on this sha, then re-push — is structurally unavailable for a new branch: noci.ymlrun can exist for a sha that has never been pushed. The.201gate-runner has capacity but its container has nosshclient, so the push cannot originate there. A single-use, sha-bound, receipted override grant was minted and consumed (prepush_override_consumed, contextdegraded-capacity: heavy fail-closed full-suite escalation, nonce6ac205ce211f, head8c150e622cff) so the escalated suite ran here rather than being skipped. It ran green: 24,002 passed / 40 skipped on the escalated pass, plus 8,014 passed / 52 skipped / 1 xfailed on the impacted-subset pass (tests/gates/ tests/nodes/ tests/unit/). No--no-verify, no skip token, no bypass flag. The over-escalation class is already filed as OMN-16745; the new-branch bootstrap gap is a residual worth its own ticket.Ticket: OMN-16773
Evidence-Ticket: OMN-16773
Evidence-Source: OCC#7328