Repository navigation
fix(OMN-18024): retire the dev-system instance id from the preflight docstring - #3313
Conversation
…docstring The Exposed Identifier Gate (OMN-17320) runs --scope all and has been failing on every open omnibase_infra PR since 2026-09-08T05:41Z: entries=11 files_scanned=7186 findings=1 src/omnibase_infra/runtime/entrypoint_preflight.py:16:23: denylisted ec2-instance-id (entry=omn18024-ec2-dev-system ticket=OMN-18024) Two PRs landed 80 seconds apart and produced this with no textual conflict between them. #3268 (OMN-17372, merge 84211f7, 05:39:37Z) introduced this module, whose docstring cited the dev-system cluster by instance id while narrating a boot measurement. #3272 (OMN-18024, merge 308c314, 05:40:57Z) added that same id to the denylist. Neither PR could see the other: the gate is a whole-tree scan, so it only fails once both are on dev. The literal is dropped and the claim is kept, which is the first remedy the gate's own message offers. The instance id carried no information for a boot timing note -- naming the cluster is what the sentence needed. No annotation was added, no denylist entry was edited, and no allowlist was widened. Verified locally on this branch with the gate's own command: python3 scripts/validation/check_exposed_identifiers.py --mode blocking --scope all -> entries=11 files_scanned=7186 findings=0 The same command on this branch's parent (origin/dev, 34314a6) reports findings=1, which is the positive control for that zero. Refs OMN-18024, OMN-17320, OMN-17372
|
OCC autobind did not mint a companion for this PR: no changed-file candidate could be proven RED against the merge base, and emitting a PR-existence probe instead would be non-falsifiable evidence (OMN-15247). Hand-authored evidence is required. |
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Nit-level findings suppressed: 1
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Findings not anchored to a changed file
-
[MINOR] hostile-reviewer (glm-review)
Cluster identifier removed without replacement | The diff deletes the concrete cluster identifier 'i-06169517a92b45f86' and replaces it with the vague phrase 'the dev-system cluster'. The surrounding text retains other precise, identifying details (container name 'omninode-runtime', timestamp '21:34:27Z', the '.201 dev lane', measurement date). The redaction is therefore inconsistent: it removes one traceability anchor while leaving several others, so it neither fully anonymizes the environment nor preserve
Resolve this thread when addressed — the
Hostile Review Thread Gateblocks while hostile-reviewer threads are unresolved (OMN-17492).
|
| Surface | Meaning | Blocks merge? |
|---|---|---|
| Review threads | Per-finding, posted by the reviewer | No (informational) |
Hostile Review Thread Gate |
Deterministic: unresolved hostile-reviewer threads exist | Fails until resolved (not yet a required context) |
degraded verdict |
Fewer than 2 models succeeded (infra) | No |
Powered by omniintelligence.review_pairing.cli_review — multi-model adversarial review: qwen3-review, qwen3-review-b, glm-review (OMN-8468/OMN-8524/OMN-17492)
#8640) * evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#3313 * evidence: OCC companion self-bind for #8640 --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
Summary
Exposed Identifier Gate (OMN-17320)runs--scope alland has been failing on every openomnibase_infraPR since 2026-09-08T05:41Z:This PR drops the literal and keeps the claim, which is the first remedy the gate's own message offers. The instance id carried no information for a boot-timing note; naming the cluster is what the sentence needed.
How this happened
Two PRs landed 80 seconds apart and produced this with no textual conflict between them, so neither PR's own CI could have caught it:
84211f73f276c5fae1f99e5a65a441bd8baad4a4308c314003c7b2425751dc93da1137df568c61a6#3268 introduced
entrypoint_preflight.py, whose module docstring cited the dev-system cluster by instance id while narrating a boot measurement. #3272 added that same id to the denylist. The gate is a whole-tree scan, so it only reports a finding once both are ondev.Live confirmation that it blocks unrelated work:
omnibase_infra#3308and#3307(Dependabot workflow-pin bumps that touch neither file) both failCI Summarywith this gate as the failing producer.Verification
Run on this branch with the gate's own command:
The positive control for that zero: the identical command on this branch's parent (
origin/dev,34314a61b) reportsfindings=1at the line above. An empty result here is a real zero, not a sweep that failed to run.What this PR deliberately does not do
No exposed-identifier annotation was added, no denylist entry was edited, and no allowlist was widened. The identifier is removed, not exempted.
Ticket
Refs OMN-18024 (the denylist entry this residual belongs to), OMN-17320 (the gate), OMN-17372 (the docstring's origin).
Evidence-Ticket: OMN-18024
Evidence-Source: OCC#8640