Skip to content

fix(OMN-18024): retire the dev-system instance id from the preflight docstring - #3313

Merged
jonahgabriel merged 1 commit into
devfrom
jonah/omn-18024-retire-ec2-id-from-preflight-docstring
Sep 8, 2026
Merged

jonahgabriel merged 1 commit into
devfrom
jonah/omn-18024-retire-ec2-id-from-preflight-docstring

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Sep 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Exposed Identifier Gate (OMN-17320) runs --scope all and has been failing on every open omnibase_infra PR since 2026-09-08T05:41Z:

exposed-id-gate: mode=blocking scope=all entries=11 files_scanned=7186 findings=1
  src/omnibase_infra/runtime/entrypoint_preflight.py:16:23: denylisted
  ec2-instance-id (entry=omn18024-ec2-dev-system ticket=OMN-18024)

This PR drops the literal and keeps the claim, which is the first remedy the gate's own message offers. The instance id carried no information for a boot-timing note; naming the cluster is what the sentence needed.

How this happened

Two PRs landed 80 seconds apart and produced this with no textual conflict between them, so neither PR's own CI could have caught it:

PR Ticket Merge At
#3268 OMN-17372 84211f73f276c5fae1f99e5a65a441bd8baad4a4 2026-09-08T05:39:37Z
#3272 OMN-18024 308c314003c7b2425751dc93da1137df568c61a6 2026-09-08T05:40:57Z

#3268 introduced entrypoint_preflight.py, whose module docstring cited the dev-system cluster by instance id while narrating a boot measurement. #3272 added that same id to the denylist. The gate is a whole-tree scan, so it only reports a finding once both are on dev.

Live confirmation that it blocks unrelated work: omnibase_infra#3308 and #3307 (Dependabot workflow-pin bumps that touch neither file) both fail CI Summary with this gate as the failing producer.

Verification

Run on this branch with the gate's own command:

python3 scripts/validation/check_exposed_identifiers.py --mode blocking --scope all
-> exposed-id-gate: mode=blocking scope=all entries=11 files_scanned=7186 findings=0

The positive control for that zero: the identical command on this branch's parent (origin/dev, 34314a61b) reports findings=1 at the line above. An empty result here is a real zero, not a sweep that failed to run.

What this PR deliberately does not do

No exposed-identifier annotation was added, no denylist entry was edited, and no allowlist was widened. The identifier is removed, not exempted.

Ticket

Refs OMN-18024 (the denylist entry this residual belongs to), OMN-17320 (the gate), OMN-17372 (the docstring's origin).

Evidence-Ticket: OMN-18024
Evidence-Source: OCC#8640

…docstring

The Exposed Identifier Gate (OMN-17320) runs --scope all and has been failing on
every open omnibase_infra PR since 2026-09-08T05:41Z:

  entries=11 files_scanned=7186 findings=1
  src/omnibase_infra/runtime/entrypoint_preflight.py:16:23: denylisted
  ec2-instance-id (entry=omn18024-ec2-dev-system ticket=OMN-18024)

Two PRs landed 80 seconds apart and produced this with no textual conflict
between them. #3268 (OMN-17372, merge 84211f7,
05:39:37Z) introduced this module, whose docstring cited the dev-system cluster
by instance id while narrating a boot measurement. #3272 (OMN-18024, merge
308c314, 05:40:57Z) added that same id to the
denylist. Neither PR could see the other: the gate is a whole-tree scan, so it
only fails once both are on dev.

The literal is dropped and the claim is kept, which is the first remedy the
gate's own message offers. The instance id carried no information for a boot
timing note -- naming the cluster is what the sentence needed. No annotation was
added, no denylist entry was edited, and no allowlist was widened.

Verified locally on this branch with the gate's own command:
  python3 scripts/validation/check_exposed_identifiers.py --mode blocking --scope all
  -> entries=11 files_scanned=7186 findings=0
The same command on this branch's parent (origin/dev, 34314a6) reports
findings=1, which is the positive control for that zero.

Refs OMN-18024, OMN-17320, OMN-17372
@jonahgabriel jonahgabriel added the ci:ready Full CI runs on this PR (OMN-15731 label-gated CI pilot) label Sep 8, 2026
@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

OCC autobind did not mint a companion for this PR: no changed-file candidate could be proven RED against the merge base, and emitting a PR-existence probe instead would be non-falsifiable evidence (OMN-15247). Hand-authored evidence is required.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Nit-level findings suppressed: 1

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Findings not anchored to a changed file

  • [MINOR] hostile-reviewer (glm-review)

    Cluster identifier removed without replacement | The diff deletes the concrete cluster identifier 'i-06169517a92b45f86' and replaces it with the vague phrase 'the dev-system cluster'. The surrounding text retains other precise, identifying details (container name 'omninode-runtime', timestamp '21:34:27Z', the '.201 dev lane', measurement date). The redaction is therefore inconsistent: it removes one traceability anchor while leaving several others, so it neither fully anonymizes the environment nor preserve

    Resolve this thread when addressed — the Hostile Review Thread Gate blocks while hostile-reviewer threads are unresolved (OMN-17492).

@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

⚠️ Hostile Reviewer — DEGRADED (informational)

Critical findings: 0
Major findings: 0
Total findings: 2
Models succeeded: glm-review

Note: Fewer than 2 reviewer models succeeded. Degraded results are informational (OMN-8468/OMN-8524) and do not block merge. Error: cli_review exit 2 (fewer than 2 models succeeded — partial/total outage)


Semantics (OMN-17492 — the model finds, thread resolution gates)

Surface Meaning Blocks merge?
Review threads Per-finding, posted by the reviewer No (informational)
Hostile Review Thread Gate Deterministic: unresolved hostile-reviewer threads exist Fails until resolved (not yet a required context)
degraded verdict Fewer than 2 models succeeded (infra) No

Powered by omniintelligence.review_pairing.cli_review — multi-model adversarial review: qwen3-review, qwen3-review-b, glm-review (OMN-8468/OMN-8524/OMN-17492)

jonahgabriel pushed a commit to OmniNode-ai/onex_change_control that referenced this pull request Sep 8, 2026
#8640)

* evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#3313

* evidence: OCC companion self-bind for #8640

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
@jonahgabriel
jonahgabriel merged commit 1d784b6 into dev Sep 8, 2026
152 of 201 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-18024-retire-ec2-id-from-preflight-docstring branch September 8, 2026 06:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:ready Full CI runs on this PR (OMN-15731 label-gated CI pilot)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant