Repository navigation
feat(OMN-18931): compose delegation evidence workflow - #3951
jonahgabriel wants to merge 7 commits into
Conversation
Vendor the approved OMN-18987 Market migration pair from 52f0ddd4ea05c52739c669a63e492be359cb9c20, derive the matching topology grants, and bind their checksum declarations.
…e-port-integration # Conflicts: # docker/migrations/forward/_ledger/application-migrations.tsv # tests/unit/scripts/validation/test_application_migration_manifest.py
|
No OCC evidence companion was minted for this PR. product PR is a draft; companion suppressed (F-17) Matched in the state: To clear this: Mark the PR ready for review. The ready_for_review trigger re-fires the born path and the companion mints then. Reported by |
…ption The prior merge commit (23b9de6) dropped 0044_restore_delegation_shadow_ comparisons.sql from fenced-node-migrations.yaml to resolve a local test_no_id_is_both_fenced_and_frozen contradiction against a fresh disjointness assumption. Verified on .201 (docker compose -f docker/legacy-rds-fixture/compose.yml up --build --abort-on-container-exit --exit-code-from proof) that this broke the real forward-migration runner's unclassified-FORCE-RLS guard: on a fresh database the migration is FATAL until it is classified in the fence manifest, regardless of any frozen declaration elsewhere. Restores the dev-side fence entry for 0044 verbatim, and instead pins a reviewed exception in test_no_id_is_both_fenced_and_frozen (_KNOWN_FENCED_AND_FROZEN) documenting why this one id is legitimately both: baseline-fenced (OMN-18987, pending the real restore via omnimarket#2699) and frozen (OMN-18693, already applied and checksum-bound on the a870 dogfood lane, a lane outside the baseline fence's release system). Re-ran docker compose -f docker/legacy-rds-fixture/compose.yml on .201 after the fix: proof-1 exited 0, fixture_status=PASS blocker=none.
…8931) # Conflicts: # tests/unit/scripts/validation/test_application_migration_manifest.py
…omnibase-path spelling - _write_issued_delegation_evidence took receipt and receipt_bytes as keyword-only, but run_receipt_mode calls receipt_bytes_callback(receipt, bytes) positionally, so every delegate run printed "receipt byte callback failed" and wrote no issued evidence. They are now positional; the bound context stays keyword-only. - OMN-19197 on dev renamed onex delegate --omni-home to --omnibase-path. The content-candidate refusal and its two tests still named the old flag. - The fault-route test module imported omnimarket at module scope, so its seven pure route-policy tests were a collection error wherever omnimarket is absent. The import is now local to the one test that reads the omnimarket package resource.
…, and infra unit tests stop importing omnimarket The bounded-route gate counted the dogfood topology's internal member (redpanda:9092) as a dogfood-owned broker. Every compose lane uses that name, and the .201 dev lane runtime bus reports environment local on redpanda:9092 (read from omninode-runtime today). Once omnimarket declares the dogfood topology, every RuntimeDelegationDispatchPort dispatch on that lane would have been refused as a bounded broker under an unexpected environment. Only a lane's declared external broker classifies a foreign environment now. The internal member still confirms a lane that names itself. The infra unit suite runs where omnimarket is not installed, so: - the route-scope wiring test spells its overlay here; - the committed-resource test is removed, because omnimarket pins those values in its own PR; - the two real-handler wiring modules, which load omnimarket contracts and models, are removed from this tree. Their source stays at 3822fb1, to be re-homed in omnimarket once an infra release carries this gate. Onex-Lane: drain-prereqs Onex-Session: 73316c887f924f5aa4bf5556c1ed651e
|
Takeover read-back (lane k1k6-takeover, 2026-09-24). This follows the operator ruling to take over the idle delegation-completion drafts. I read this PR in full at Disposition: not continued as one PR. It will be superseded by per-ticket PRs that credit this branch, and it stays draft until those exist. Why it cannot land as it is:
The split, in dependency order. Each new PR cites only its own ticket and credits this branch:
Once a K's superseding PR is open, its files come out of this branch. When the last one is open, this draft closes with a pointer to all of them. Nothing on this branch is deleted. |
|
K2 split out (lane k2-omn18929, 2026-09-24). This is part of the per-K supersession set out in the takeover read-back above. K2 (OMN-18929) is now in two draft PRs on its own ticket:
Correction to the read-back above. It listed
The response-contract carry itself landed on This draft stays open for the remaining Ks, per the plan above. |
|
Pointer from K3 (OMN-18930): the K3 files in this draft now continue in #4054, which credits this draft's commit These files were carried forward:
#4054 changes them in these ways:
The .201 dev-lane readback is in the #4054 body: A vs A2 read Left in this draft: the capture root, the K4 and K6 hunks, and the |
|
Pointer from K6 (OMN-18933): the K6 route-declaration files from this draft now continue in two draft PRs. Both credit this draft, commit
These files were not carried forward:
Those files stay in this draft for their own K lanes. This draft stays open until the last superseding PR exists. |
|
Superseded, recommend closing (lane infra-3951-salvage-split, OMN-18931). No part of this draft is left without a successor:
|
|
Closing as superseded, per the salvage split (ledger MSG 2026-09-24T23:18:56Z lane infra-3951-salvage-split). The listener-name fix is on dev through omnibase_infra#4056 (merged 22:51Z). The K1 infra wiring, the one unsuperseded part, is carried by omnibase_infra#4088 (head c3b0042, rebased on dev). Closed by runtime-train-83. |
…nce capture (K1 infra, salvaged from #3951) (#4088) * fix(OMN-19344): declare migration 0045's class so the declaration check passes on dev omnibase_infra#3945 added forward/nodes/node_projection_delegation/0045_terminal_construction_outcome_metrics.sql. omnibase_infra#4039 then merged the migration class gate with a declaration file written before 0045 existed. Since then the whole-tree Node Migration Declaration Check fails on dev (read on a7ea811), and every omnibase_infra PR inherits the red. The entry is the checker's own reading (check_migration_class.py --suggest): forward-only, CREATE OR REPLACE plus ALTER VIEW. Applied migration bytes are unchanged. Onex-Lane: k6-omn18933 Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8 * feat(OMN-18933): refuse a delegation before dispatch unless its bounded lane row agrees K6 of OMN-18925. On the dev lane and the authorized isolated lab (dogfood), the runtime delegation dispatch port now resolves the selected consumer contract against that lane's declared row (lane, broker, consumer, terminal route, repository owner) before the broker is constructed. A missing row, a broker mismatch, a consumer or owner mismatch, a route row on ci-bus or prod, or installed overlay bytes that disagree with the omnimarket wheel RECORD all refuse there, so nothing is published for the correlation. A lane is claimed by its name, by its declared (runtime_environment, internal listener) pair, or by its declared external broker. The .201 dev lane's runtime reports local on redpanda:9092, the listener every compose lane shares, so the caller's dev label is never the identity. The rebuild trigger's overlay model learns broker_topology.runtime_environment so omnimarket can declare it next. Carved from Codex draft omnibase_infra#3951 (bounded_delegation_routes.py, its two models, the addressed transport protocol, EventBusKafka.bootstrap_servers and their unit tests) and credited in each file. Onex-Lane: k6-omn18933 Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8 * perf(OMN-18933): read the packaged lane overlay once per process The installed wheel changes only with a redeploy, which restarts the runtime. Onex-Lane: k6-omn18933 Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8 * fix(OMN-18933): scope overlay refusals to bounded runtimes; strip broker credentials Self-review findings: a malformed or out-of-scope declaration on one lane, or an unreadable overlay, refused every runtime, including stability-test, judge, staging and prod, which the gate never covers. They now refuse only a runtime that claims a bounded lane; the rest log that the gate is not armed. EventBusKafka.bootstrap_servers returns the sanitized host list, as every other exposure in the class does, because the dispatch port logs it. Onex-Lane: k6-omn18933 Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8 * fix(OMN-18933): no new infra protocol; roundtrip-cover the route models CI (run 35993722160) refused two things: a new Protocol in omnibase_infra (protocol ownership: 117 > 116) and three models with no serialization disposition. The route gate now reads the transport's environment and bootstrap_servers attributes directly, so no protocol is added and an in-process bus (no broker address) resolves to None as before. The three K6 models get an explicit JSON roundtrip test and a disposition pointing at it. Onex-Lane: k6-omn18933 Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8 * test(OMN-18933): integration proof of the gate through the real port and Kafka bus identity The Integration Test Coverage gate (run 35995848620) requires a tests/integration test for a feature PR. This composes an unstarted EventBusKafka, the real RuntimeDelegationDispatchPort and the real validator: a mismatched row refuses before the broker exists, the declared row reaches the broker, and a runtime outside the gate dispatches untouched. Onex-Lane: k6-omn18933 Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8 * feat(OMN-18931): dogfood fault-pin admission and typed terminal-evidence capture, salvaged from #3951 The K1 infra half of omnibase_infra#3951, which no other PR carries: - dogfood_delegation_fault_routes: a backend pin is admitted only as a declared dogfood fault route (single hop, HTTP 429 or 503, 240s, no escalation), resolved from the packaged omnimarket lane overlay. The runtime is classified by the bounded route gate's own rule (claimed_bounded_lane), so the shared compose listener redpanda:9092 alone never claims dogfood. The route slug is held as backend_key, read from the overlay's backend_id key. - bounded_delegation_routes: the broker-identity checks are extracted, unchanged, into validate_bounded_lane_broker_identity, and the lane claim is exposed as claimed_bounded_lane, so the fault gate and the route gate share one rule. - RuntimeDelegationDispatchPort: backend_id and no_escalation go onto the wire only after that admission; an opt-in terminal-evidence sink receives the consumed terminal's raw envelope bytes, topic, partition and offset, bound to the actual dispatch tenant. - RuntimePatternBBroker: TerminalPayload keeps the raw envelope, partition and offset; dispatch_request takes an optional terminal observer. - handler_wiring: the consumer re-checks the pin before the delegation orchestrator's typed request leg runs. - render_bifrost_delegation_contract: the dogfood render appends the declared fault backends; no other lane renders one. - capture, bind and finalize evidence scripts, the K1-K6 runner, the fixed-status fault provider and its two dogfood-profile compose services. Stacked on omnibase_infra#4056 (OMN-18933), which carries the reworked bounded-route gate including the listener-name classification fix. Onex-Lane: infra-3951-salvage-split Onex-Session: a68655aa197947c585d16729ece58c2a * fix(OMN-18931): add no infra protocol; the evidence sink is a typed callable and the pin reads bus identity by attribute omnibase_infra's protocol-ownership ratchet admits no new Protocol, and the bounded route gate already reads environment and bootstrap_servers as plain attributes (OMN-18933). The two protocols carried over from #3951 are removed: the sink is DelegationTerminalEvidenceSink, a Callable alias, and the pin admission reads the bus identity the same way the route gate does. Version 0.38.58, past the published 0.38.57. Onex-Lane: infra-3951-salvage-split Onex-Session: a68655aa197947c585d16729ece58c2a * fix(OMN-18931): the salvaged scripts pass mypy --strict (no Any returned as int) Onex-Lane: infra-3951-salvage-split Onex-Session: a68655aa197947c585d16729ece58c2a * fix(OMN-18931): regenerate the runner image identity lock for the version bump The PR's pyproject.toml/uv.lock version bump (0.38.57 -> 0.38.58) feeds the shared CI env digest, so the recorded runner-image identity went stale. Regenerated via scripts/ci/runner_image_identity.py --mode generate. RED before: test_recorded_identity_matches_recomputed_identity and test_identity_uses_shared_env_digest_as_a_binding_component failed, lock recorded shared_env_digest 99110eda10a86b271a810b4f vs recomputed 105217eb63ab02cc12602770. GREEN after: both tests pass, full tests/ci/test_runner_image_identity.py (11/11) passes. Onex-Lane: infra-3951-salvage-split Onex-Session: a68655aa197947c585d16729ece58c2a * fix(OMN-18931): declare the two dogfood delegation-fault containers in the lane manifest and render tests The PR added dogfood-delegation-fault-429 and -503 to docker-compose.dogfood.yml without the lane-manifest entries the parity test requires, and without adding them to the dogfood render test's expected service and port sets. Both are long-running (kind: service, replicas: 1) and publish no host port. The manifest edit carries a read-only verified: attestation from the lab-200 host. Entries drafted through onex delegate (deployed dev lane, run f1c441ee-603a-4a2e-8b51-d1178e48942c, Qwen3.8-27B, cost 0). Onex-Lane: infra-3951-salvage-split Onex-Session: 2df5b14a70fb4fd89dc0cc4218139afe * fix(OMN-18931): vendored-pair ledger check tracks all three dod_verify_runs migrations OMN-19514 (#4102) added 0002_dod_verify_runs_delegation_correlation_id.sql to node_projection_dod_verdict's vendored set without updating this test's hardcoded two-file expectation, so test_the_vendored_pair_matches_the_checksum_the_ledger_records fails on dev itself (reproduced identically at origin/dev a6afd00, positive control) as well as on this PR's merged head. Extend the check to the current vendored set of three files instead of a fixed pair. Onex-Lane: infra-3951-salvage-split Onex-Session: a68655aa197947c585d16729ece58c2a * fix(OMN-18931): the OMN-19514 linter positive control retargets an undeclared schema, since public is the tenant schema after OMN-17887 Onex-Lane: infra-3951-salvage-split Onex-Session: a68655aa197947c585d16729ece58c2a * fix(OMN-18931): advance the Receipt Gate pin so attempt-scoped supersede receipts resolve The verify job on this PR returned nonpass_receipt for the two sibling proof keys of OMN-18931 (omnimarket#2840 and #2841). Both keys carry attempt-scoped supersession records on OCC dev, and the validator the gate ran could not see them: the caller pin aeaf3b16 selects a copy of receipt-gate.yml whose inner validator ref is still 37bd8519, where the supersede-suffix pattern excludes a dot. Reproduced locally against the same OCC tree and PR commits: - validator at 37bd8519: eligible=false, reason=nonpass_receipt, the same two keys the CI log names - validator at a03b1072 (the inner ref at 9cc9f035): eligible=true This repoints the caller at 9cc9f035 (omnibase_core#1740), the pin omnimarket already carries since omnimarket#2769 under OMN-19149. The receipt-gate.yml copy differs between the two pins only in that inner ref. Related: OMN-19149, OMN-19050 Onex-Lane: infra-3951-salvage-split Onex-Session: a68655aa197947c585d16729ece58c2a --------- Co-authored-by: onexbot-occ-writer[bot] <307849072+onexbot-occ-writer[bot]@users.noreply.github.com>
Summary
Compose the OMN-18931 delegation-evidence workflow with exact emitted receipt bytes, broker terminal/cursor provenance, projection binding, and the non-test K1–K6 evidence launcher. This also carries the approved OMN-18987 vendor migration topology/ledger reconciliation from the exact Market source pin below.
Changes
Test plan
pre-commit run --all-files— pass (delivery log53daf20c…f11dafb5).2a6fb51b…26cc6d5e).01e8b27d…0f76280b).f9d4d74b…0f50270).7a949dbf…1c6884).The locally installed
omnibase-core==0.47.20lacksno_escalation; two separate legacy port tests requiring that newer model field remain an external release dependency and are not represented as passing. No live K1–K6 runtime run or final composition proof is claimed by this draft.Runtime startup gate
auto_wiring/; final proof must load the real contract manifest, callwire_from_manifestwith production arguments, assert zero failures, and validate the approved runtime lane.Type safety checklist
except Exception.Strict-gate ordering
Related issues
52f0ddd4ea05c52739c669a63e492be359cb9c20Merge conflict clearing (dd-infra-3951, 2026-09-22)
Merged origin/dev (112d340) into this branch to clear a DIRTY/CONFLICTING mergeable
state. Two textual conflicts, both read in full on both sides before resolving:
docker/migrations/forward/_ledger/application-migrations.tsv: union of bothsides' appended declarations (prod-promotion-gate pair, the 0043z predecessor,
the 0044 restore), 209 rows total, matching origin/dev's own asserted count.
tests/unit/scripts/validation/test_application_migration_manifest.py: tookorigin/dev's fuller incremental-history comment and its
== 209assertion,which already narrates this branch's own OMN-18693 0044 restoration.
A third, non-textual conflict surfaced only via tests: origin/dev's very recent
e01596269(OMN-18987) added0044_restore_delegation_shadow_comparisons.sqltothe baseline operator fence (
fenced-node-migrations.yaml), while this branch's ownOMN-18693 lineage separately declares the same id frozen/ledger-bound in
shape-reconciliation-exemptions.yaml.test_no_id_is_both_fenced_and_frozenflagged the overlap. First attempt removed the fence entry; verified on
.201(
docker compose -f docker/legacy-rds-fixture/compose.yml up --build --abort-on-container-exit --exit-code-from proof) that this broke the forward-migration runner's unclassified-FORCE-RLS guard — FATAL on a fresh database,
"has never applied on this database. Classify it before it may run." Reverted to
keep the fence entry exactly as origin/dev has it, and instead pinned a reviewed,
documented exception (
_KNOWN_FENCED_AND_FROZEN) in the test, matching theexisting
_EXPECTED_FROZENpinning discipline. Re-ran the same.201proof afterthe fix:
proof-1exited 0,fixture_status=PASS blocker=none.Local focused tests after the full resolution (
uv run pytest, this host):tests/unit/scripts/validation/test_application_migration_manifest.py(20),tests/ci/test_node_migration_shape_reconciliation.py(264),tests/scripts/test_check_deployed_migration_tree_sync.py,tests/unit/runtime/test_dogfood_delegation_fault_provider_omn18931.py,tests/unit/runtime/test_dogfood_fault_consumer_callback_omn18931.py— 311 passed,1 pre-existing failure (the
no_escalationgap already noted above, unrelated tothe conflict, unchanged by the merge). New head:
91a843c90.Per RULING at
docs/tracking/ROLLING_WORK_LEDGER.md:3995and the orchestratorSTATUS row at
:5222, this PR stays DRAFT — omnibase_infradevis held behindomnibase_infra#3939(still DRAFT). Conflict cleared and checks watched to aterminal state; not flipped ready.
Drain pass (drain-prereqs, 2026-09-23), head
da6752438Prerequisites now built, in landing order:
broker_topology,delegation_routesanddelegation_fault_routes. ItsModelCiBusLaneisextra="forbid", so without this the omnimarket declaration would redci-bus-overlay-bindingon every infra PR, and the omnimarket parity gate refuses the declaring PR.broker_topology, the two fault routes and the dev/dogfooddelegation_routes, and force-includesconfig/ci_bus_lanes.yamlin the wheel atomnimarket/config/ci_bus_lanes.yaml, which is the resource this PR reads.no_escalation).Defect fixed here.
resolve_bounded_delegation_routecounted the dogfood topology's internal memberredpanda:9092as a dogfood-owned broker, and every compose lane uses that name. The .201 dev lane runtime bus resolves to environmentlocalonredpanda:9092. That was read fromomninode-runtimethroughModelKafkaEventBusConfig().apply_environment_overrides(), read-only. With omnimarket#2820 declared, everyRuntimeDelegationDispatchPort.dispatchon that lane would have been refused. Now only a lane's declared external broker classifies a foreign environment. The internal member still confirms a lane that names itself. The test that asserted the opposite is replaced bytest_shared_internal_listener_name_does_not_claim_another_lane[local|prod|stability-test], which was RED 3 failed before the fix and passes after it.Test failures cleared. The earlier 4 failed and 3 errors had two causes:
test_omn18933_handler_wiring_route_scope.pynow spells its overlay in this repo.test_committed_market_resource_is_the_dogfood_pin_authorityis removed, because omnimarket#2820 pins those values in its own test.test_dogfood_fault_public_wire_registration_omn18931.pyandtest_dogfood_fault_real_handler_wiring_omn18931.pyload omnimarket contracts and models, so they cannot run in this CI without an importorskip, which the skip-count ratchet refuses. They are removed from this tree, and their source is preserved at3822fb1c7.no_escalation), which is chore(deps): bump omnibase-core to 0.47.22 (OMN-18595) #3997.Results on the changed test set, with the omnimarket-importing tests already removed:
no_escalationcases.Still open:
ModelDelegateSkillRequesthas nobackend_id,no_escalationorrequested_timeout_seconds, and the public-wire test assumed they exist. They exist only in an uncommitted working tree, and no omnimarket PR carries them. The infra gate here is correct without them, but the delegate-skill path cannot request a fault cohort until they land.wire_from_manifestwith production arguments and a compose boot all need a runtime lane. The pre-PR slot entrypoint does not exist, and the .201 dev lane was out of scope for this pass, so it was not run.devin.