Skip to content

feat(OMN-18931): compose delegation evidence workflow - #3951

Closed
jonahgabriel wants to merge 7 commits into
devfrom
codex/omn-18925-capture-port-integration
Closed

jonahgabriel wants to merge 7 commits into
devfrom
codex/omn-18925-capture-port-integration

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Compose the OMN-18931 delegation-evidence workflow with exact emitted receipt bytes, broker terminal/cursor provenance, projection binding, and the non-test K1–K6 evidence launcher. This also carries the approved OMN-18987 vendor migration topology/ledger reconciliation from the exact Market source pin below.

Changes

  • Preserve the original K1–K6 integration paths and add typed terminal-evidence capture, binding, finalization, and an executable composition command.
  • Retain raw receipt and terminal artifacts, reject contradictory tenant/correlation evidence, and fail evidence collection safely without changing ordinary delegation results.
  • Declare and render the two authoritative Market vendor table grants; retain the documented residual topology bounds and immutable 0044 bytes.
  • Repair source-hook compatibility for Git fixture isolation, protocol/model separation, SPDX metadata, and provider-label validation.

Test plan

  • pre-commit run --all-files — pass (delivery log 53daf20c…f11dafb5).
  • Targeted migration manifest/topology checks — 101 passed (log 2a6fb51b…26cc6d5e).
  • Strict mypy for the repaired CLI and dispatch-port files plus issued-evidence and final-port tests — 14 passed (log 01e8b27d…0f76280b).
  • Exact new-branch pre-push hook selection — mypy, architecture, and deploy-scope DoD passed (log f9d4d74b…0f50270).
  • Normal canonical push pre-push hooks passed (log 7a949dbf…1c6884).

The locally installed omnibase-core==0.47.20 lacks no_escalation; two separate legacy port tests requiring that newer model field remain an external release dependency and are not represented as passing. No live K1–K6 runtime run or final composition proof is claimed by this draft.

Runtime startup gate

  • Pending composed-runtime proof: this PR touches auto_wiring/; final proof must load the real contract manifest, call wire_from_manifest with production arguments, assert zero failures, and validate the approved runtime lane.

Type safety checklist

  • No new metadata string-literal access on Pydantic model fields.
  • No new untyped metadata fields.
  • No new bare except Exception.
  • Added metadata keys use existing typed models.
  • No required compose environment variable change.

Strict-gate ordering

  • No new blocking gate.

Related issues

  • OMN-18931
  • OMN-18987
  • Node-Migration-Source-SHA: 52f0ddd4ea05c52739c669a63e492be359cb9c20

Merge conflict clearing (dd-infra-3951, 2026-09-22)

Merged origin/dev (112d340) into this branch to clear a DIRTY/CONFLICTING mergeable
state. Two textual conflicts, both read in full on both sides before resolving:

  • docker/migrations/forward/_ledger/application-migrations.tsv: union of both
    sides' appended declarations (prod-promotion-gate pair, the 0043z predecessor,
    the 0044 restore), 209 rows total, matching origin/dev's own asserted count.
  • tests/unit/scripts/validation/test_application_migration_manifest.py: took
    origin/dev's fuller incremental-history comment and its == 209 assertion,
    which already narrates this branch's own OMN-18693 0044 restoration.

A third, non-textual conflict surfaced only via tests: origin/dev's very recent
e01596269 (OMN-18987) added 0044_restore_delegation_shadow_comparisons.sql to
the baseline operator fence (fenced-node-migrations.yaml), while this branch's own
OMN-18693 lineage separately declares the same id frozen/ledger-bound in
shape-reconciliation-exemptions.yaml. test_no_id_is_both_fenced_and_frozen
flagged the overlap. First attempt removed the fence entry; verified on .201
(docker compose -f docker/legacy-rds-fixture/compose.yml up --build --abort-on-container-exit --exit-code-from proof) that this broke the forward-
migration runner's unclassified-FORCE-RLS guard — FATAL on a fresh database,
"has never applied on this database. Classify it before it may run." Reverted to
keep the fence entry exactly as origin/dev has it, and instead pinned a reviewed,
documented exception (_KNOWN_FENCED_AND_FROZEN) in the test, matching the
existing _EXPECTED_FROZEN pinning discipline. Re-ran the same .201 proof after
the fix: proof-1 exited 0, fixture_status=PASS blocker=none.

Local focused tests after the full resolution (uv run pytest, this host):
tests/unit/scripts/validation/test_application_migration_manifest.py (20),
tests/ci/test_node_migration_shape_reconciliation.py (264),
tests/scripts/test_check_deployed_migration_tree_sync.py,
tests/unit/runtime/test_dogfood_delegation_fault_provider_omn18931.py,
tests/unit/runtime/test_dogfood_fault_consumer_callback_omn18931.py — 311 passed,
1 pre-existing failure (the no_escalation gap already noted above, unrelated to
the conflict, unchanged by the merge). New head: 91a843c90.

Per RULING at docs/tracking/ROLLING_WORK_LEDGER.md:3995 and the orchestrator
STATUS row at :5222, this PR stays DRAFT — omnibase_infra dev is held behind
omnibase_infra#3939 (still DRAFT). Conflict cleared and checks watched to a
terminal state; not flipped ready.


Drain pass (drain-prereqs, 2026-09-23), head da6752438

Prerequisites now built, in landing order:

  1. omnibase_infra#4030 (non-runtime). The rebuild-trigger publisher learns broker_topology, delegation_routes and delegation_fault_routes. Its ModelCiBusLane is extra="forbid", so without this the omnimarket declaration would red ci-bus-overlay-binding on every infra PR, and the omnimarket parity gate refuses the declaring PR.
  2. omnimarket#2820 (runtime). It declares the dogfood broker_topology, the two fault routes and the dev/dogfood delegation_routes, and force-includes config/ci_bus_lanes.yaml in the wheel at omnimarket/config/ci_bus_lanes.yaml, which is the resource this PR reads.
  3. omnibase_infra#3997 (runtime, Core 0.47.22 for no_escalation).
  4. This PR.

Defect fixed here. resolve_bounded_delegation_route counted the dogfood topology's internal member redpanda:9092 as a dogfood-owned broker, and every compose lane uses that name. The .201 dev lane runtime bus resolves to environment local on redpanda:9092. That was read from omninode-runtime through ModelKafkaEventBusConfig().apply_environment_overrides(), read-only. With omnimarket#2820 declared, every RuntimeDelegationDispatchPort.dispatch on that lane would have been refused. Now only a lane's declared external broker classifies a foreign environment. The internal member still confirms a lane that names itself. The test that asserted the opposite is replaced by test_shared_internal_listener_name_does_not_claim_another_lane[local|prod|stability-test], which was RED 3 failed before the fix and passes after it.

Test failures cleared. The earlier 4 failed and 3 errors had two causes:

  • Three modules imported omnimarket, which the infra unit suite never installs.
    • test_omn18933_handler_wiring_route_scope.py now spells its overlay in this repo.
    • test_committed_market_resource_is_the_dogfood_pin_authority is removed, because omnimarket#2820 pins those values in its own test.
    • test_dogfood_fault_public_wire_registration_omn18931.py and test_dogfood_fault_real_handler_wiring_omn18931.py load omnimarket contracts and models, so they cannot run in this CI without an importorskip, which the skip-count ratchet refuses. They are removed from this tree, and their source is preserved at 3822fb1c7.
  • The other 3 need Core 0.47.22 (no_escalation), which is chore(deps): bump omnibase-core to 0.47.22 (OMN-18595) #3997.

Results on the changed test set, with the omnimarket-importing tests already removed:

  • CI-like env (Core 0.47.20, no omnimarket): 829 passed, 3 failed, all three the no_escalation cases.
  • Same set with Core 0.47.22: 832 passed.
  • With the omnimarket#2820 wheel also installed non-editable, and the two removed wiring modules still present: 832 passed and 5 failed, which is what led to the removals. The failures were:
    • three read the omnimarket checkout path;
    • one used a delegate-skill request field Market dev does not have (below);
    • the committed-resource test.

Still open:

  • Market delegate-skill wire. On omnimarket dev, ModelDelegateSkillRequest has no backend_id, no_escalation or requested_timeout_seconds, and the public-wire test assumed they exist. They exist only in an uncommitted working tree, and no omnimarket PR carries them. The infra gate here is correct without them, but the delegate-skill path cannot request a fault cohort until they land.
  • Runtime startup gate (the checkbox above). Real manifest, wire_from_manifest with production arguments and a compose boot all need a runtime lane. The pre-PR slot entrypoint does not exist, and the .201 dev lane was out of scope for this pass, so it was not run.
  • Re-homing the two composed wiring tests into omnimarket, once an infra release carries this gate.
  • Stays draft until chore(deps): bump omnibase-core to 0.47.22 (OMN-18595) #3997 merges, then merge dev in.

Vendor the approved OMN-18987 Market migration pair from 52f0ddd4ea05c52739c669a63e492be359cb9c20, derive the matching topology grants, and bind their checksum declarations.
…e-port-integration

# Conflicts:
#	docker/migrations/forward/_ledger/application-migrations.tsv
#	tests/unit/scripts/validation/test_application_migration_manifest.py
@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

No OCC evidence companion was minted for this PR.

product PR is a draft; companion suppressed (F-17)

Matched in the state: draft

To clear this: Mark the PR ready for review. The ready_for_review trigger re-fires the born path and the companion mints then.

Reported by node_occ_companion_effect (decline code pr_draft, OMN-16665). This decision was made against the PR's LIVE state at compute time, not at publish time — a green publisher job only means the command reached the broker.

…ption

The prior merge commit (23b9de6) dropped 0044_restore_delegation_shadow_
comparisons.sql from fenced-node-migrations.yaml to resolve a local
test_no_id_is_both_fenced_and_frozen contradiction against a fresh
disjointness assumption. Verified on .201 (docker compose -f
docker/legacy-rds-fixture/compose.yml up --build --abort-on-container-exit
--exit-code-from proof) that this broke the real forward-migration runner's
unclassified-FORCE-RLS guard: on a fresh database the migration is FATAL
until it is classified in the fence manifest, regardless of any frozen
declaration elsewhere.

Restores the dev-side fence entry for 0044 verbatim, and instead pins a
reviewed exception in test_no_id_is_both_fenced_and_frozen
(_KNOWN_FENCED_AND_FROZEN) documenting why this one id is legitimately both:
baseline-fenced (OMN-18987, pending the real restore via omnimarket#2699)
and frozen (OMN-18693, already applied and checksum-bound on the a870
dogfood lane, a lane outside the baseline fence's release system).

Re-ran docker compose -f docker/legacy-rds-fixture/compose.yml on .201
after the fix: proof-1 exited 0, fixture_status=PASS blocker=none.
…8931)

# Conflicts:
#	tests/unit/scripts/validation/test_application_migration_manifest.py
…omnibase-path spelling

- _write_issued_delegation_evidence took receipt and receipt_bytes as
  keyword-only, but run_receipt_mode calls receipt_bytes_callback(receipt,
  bytes) positionally, so every delegate run printed "receipt byte callback
  failed" and wrote no issued evidence. They are now positional; the
  bound context stays keyword-only.
- OMN-19197 on dev renamed onex delegate --omni-home to --omnibase-path. The
  content-candidate refusal and its two tests still named the old flag.
- The fault-route test module imported omnimarket at module scope, so its
  seven pure route-policy tests were a collection error wherever omnimarket
  is absent. The import is now local to the one test that reads the
  omnimarket package resource.
…, and infra unit tests stop importing omnimarket

The bounded-route gate counted the dogfood topology's internal member
(redpanda:9092) as a dogfood-owned broker. Every compose lane uses that name,
and the .201 dev lane runtime bus reports environment local on redpanda:9092
(read from omninode-runtime today). Once omnimarket declares the dogfood
topology, every RuntimeDelegationDispatchPort dispatch on that lane would have
been refused as a bounded broker under an unexpected environment. Only a
lane's declared external broker classifies a foreign environment now. The
internal member still confirms a lane that names itself.

The infra unit suite runs where omnimarket is not installed, so:
- the route-scope wiring test spells its overlay here;
- the committed-resource test is removed, because omnimarket pins those
  values in its own PR;
- the two real-handler wiring modules, which load omnimarket contracts and
  models, are removed from this tree. Their source stays at 3822fb1, to be
  re-homed in omnimarket once an infra release carries this gate.

Onex-Lane: drain-prereqs
Onex-Session: 73316c887f924f5aa4bf5556c1ed651e
@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Takeover read-back (lane k1k6-takeover, 2026-09-24). This follows the operator ruling to take over the idle delegation-completion drafts. I read this PR in full at da6752438: 65 files, +8 k lines.

Disposition: not continued as one PR. It will be superseded by per-ticket PRs that credit this branch, and it stays draft until those exist.

Why it cannot land as it is:

  • It carries at least five tickets' work in one diff:
    • K2 response-contract dispatch port: service_delegation_dispatch_port.py and the handler compat test;
    • K3 cohort key: models/delegation/model_delegation_cohort_key.py and its family, validate_delegation_cohort_keys.py, test_delegation_stable_cohort_key_omn18925.py;
    • K4 fault routes: dogfood_delegation_fault_routes.py, the fault provider, the compose dogfood file;
    • K6 bounded routes: bounded_delegation_routes.py, model_bounded_*, the handler-wiring route scope;
    • the evidence capture root: capture_, bind_, finalize_ and run_k1_k6_delegation_evidence.py.
  • It also carries unrelated host-reconcile and onex-wrapper-floor work: reconcile-host.sh, reconcile_verify_movement.py, reconcile-workspace-venvs.sh, scripts/onex, install-node-skill-package.sh, and their omn17307 / omn17309 tests.
  • Change control binds one ticket per PR, so this shape cannot get a companion that proves any single K.
  • The body's own runtime startup gate is unchecked.

The split, in dependency order. Each new PR cites only its own ticket and credits this branch:

  1. K1 is open as omnimarket#2829 (draft, stacked on omnimarket#2819). It does not need anything from this branch.
  2. K6 bounded routes, infra. Blocked in Linear by K2, which is blocked by the integration-seam epic (Backlog).
  3. K2 dispatch port, infra. Same blocker.
  4. K3 cohort key, infra. Blocked by K2.
  5. K4 fault routes, infra. Blocked by K1. It needs omnimarket#2820 and the Market delegate-skill request fields (backend_id, no_escalation, requested_timeout_seconds), which exist only as uncommitted work.
  6. Capture composition root. It lands last, once the K parents it composes exist.
  7. The host-reconcile and wrapper-floor files go to their own tickets' PRs, or back to their owners.

Once a K's superseding PR is open, its files come out of this branch. When the last one is open, this draft closes with a pointer to all of them. Nothing on this branch is deleted.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

K2 split out (lane k2-omn18929, 2026-09-24). This is part of the per-K supersession set out in the takeover read-back above.

K2 (OMN-18929) is now in two draft PRs on its own ticket:

  • omnibase_infra#4045 runs the dispatch port through the real Pattern-B broker. It proves the contract hash is identical from the published bytes to the consumer decode, and that failed, misrouted and absent terminals never read as success.
  • omnimarket#2836 is the consumer-side seam golden: the contract reaches the quality gate, and a violation publishes only the failed terminal.

Correction to the read-back above. It listed service_delegation_dispatch_port.py and the handler compat test as K2 files. This branch's diff to those files has no response-contract change. What it changes there is:

  • the K4 fault pin (backend_id, no_escalation);
  • K6 bounded-route admission;
  • the evidence-capture terminal sink.

The response-contract carry itself landed on dev through the OMN-15504 timeout-wire change (f29250be2). So no file moves out of this branch for K2, and those hunks stay here for K4, K6 and the capture root. The K2 code a Codex session wrote was an uncommitted consumer seam golden (lane codex-delegation-response-contract-k2). It is carried unchanged in omnimarket#2836 and credited there.

This draft stays open for the remaining Ks, per the plan above.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Pointer from K3 (OMN-18930): the K3 files in this draft now continue in #4054, which credits this draft's commit 76d817671.

These files were carried forward:

  • src/omnibase_infra/models/delegation/*: the cohort key, first-hop identity, provider policy and retry bounds models
  • scripts/validate_delegation_cohort_keys.py
  • tests/ci/test_delegation_stable_cohort_key_omn18925.py
  • tests/fixtures/delegation/offset489_incomplete_cohort_key.json

#4054 changes them in these ways:

  • The build identity is typed: full source revision, image digest and build-provenance hash.
  • The provider policy names its sources explicitly: routing tiers, backend config, task-class contracts, and an overlay or an explicit None.
  • The first-hop fields are renamed to backend and model. The draft needed two UUID-type pattern exemptions for backend_id and model_id; the rename removes both.
  • scripts/assemble_delegation_cohort_key.py is added. It builds a key from a terminal receipt plus a contemporaneous runtime readback.

The .201 dev-lane readback is in the #4054 body: A vs A2 read SAME_COHORT, and A vs B read CROSS_COHORT: build_identity.

Left in this draft: the capture root, the K4 and K6 hunks, and the models/__init__.py and validation_exemptions.yaml edits. #4054 does not re-export the models from omnibase_infra.models and adds no exemption. If this draft is later reduced to K4/K6, the K3 files can be dropped from it.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Pointer from K6 (OMN-18933): the K6 route-declaration files from this draft now continue in two draft PRs. Both credit this draft, commit 76d817671 onward:

  • feat(OMN-18933): refuse a delegation before dispatch unless its bounded lane row agrees #4056 (infra half). Carried forward:
    • runtime/bounded_delegation_routes.py, reworked. It claims the .201 dev lane by its runtime pair (local, redpanda:9092), adds a vendor/manifest RECORD binding, and refuses on a bad declaration only for bounded runtimes.
    • model_bounded_delegation_route.py and model_bounded_lane_broker_topology.py, moved under runtime/models/. The topology model gains runtime_environment.
    • protocol_addressed_broker_transport.py, moved under runtime/protocols/.
    • EventBusKafka.bootstrap_servers, which now returns the sanitized host list.
    • The dispatch-port call before broker construction.
    • tests/unit/runtime/test_bounded_delegation_routes.py.
  • feat(OMN-18933): declare the bounded dev and isolated-lab delegation route rows omnimarket#2842 (market half). The delegation_routes rows and broker_topology on dev and dogfood, plus the wheel force-include, now targeting omnimarket/config/.

These files were not carried forward:

  • tests/unit/runtime/test_omn18933_handler_wiring_route_scope.py and the handler_wiring.py pre-dispatch guard. That guard binds the dogfood fault routes (K4, dogfood_delegation_fault_routes), not the K6 route rows.
  • The terminal-evidence sink and observer changes in service_delegation_dispatch_port.py and service_pattern_b_broker.py. They belong to the capture root.
  • backend_id / no_escalation. That is the K4 fault pin.

Those files stay in this draft for their own K lanes. This draft stays open until the last superseding PR exists.

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Superseded, recommend closing (lane infra-3951-salvage-split, OMN-18931). No part of this draft is left without a successor:

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Closing as superseded, per the salvage split (ledger MSG 2026-09-24T23:18:56Z lane infra-3951-salvage-split). The listener-name fix is on dev through omnibase_infra#4056 (merged 22:51Z). The K1 infra wiring, the one unsuperseded part, is carried by omnibase_infra#4088 (head c3b0042, rebased on dev). Closed by runtime-train-83.

jonahgabriel added a commit that referenced this pull request Sep 26, 2026
…nce capture (K1 infra, salvaged from #3951) (#4088)

* fix(OMN-19344): declare migration 0045's class so the declaration check passes on dev

omnibase_infra#3945 added forward/nodes/node_projection_delegation/0045_terminal_construction_outcome_metrics.sql.
omnibase_infra#4039 then merged the migration class gate with a declaration file written before 0045 existed.
Since then the whole-tree Node Migration Declaration Check fails on dev (read on a7ea811), and every omnibase_infra PR inherits the red.

The entry is the checker's own reading (check_migration_class.py --suggest): forward-only, CREATE OR REPLACE plus ALTER VIEW.
Applied migration bytes are unchanged.

Onex-Lane: k6-omn18933
Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8

* feat(OMN-18933): refuse a delegation before dispatch unless its bounded lane row agrees

K6 of OMN-18925. On the dev lane and the authorized isolated lab (dogfood), the runtime delegation
dispatch port now resolves the selected consumer contract against that lane's declared row (lane, broker,
consumer, terminal route, repository owner) before the broker is constructed. A missing row, a broker
mismatch, a consumer or owner mismatch, a route row on ci-bus or prod, or installed overlay bytes that
disagree with the omnimarket wheel RECORD all refuse there, so nothing is published for the correlation.

A lane is claimed by its name, by its declared (runtime_environment, internal listener) pair, or by its
declared external broker. The .201 dev lane's runtime reports local on redpanda:9092, the listener every
compose lane shares, so the caller's dev label is never the identity. The rebuild trigger's overlay model
learns broker_topology.runtime_environment so omnimarket can declare it next.

Carved from Codex draft omnibase_infra#3951 (bounded_delegation_routes.py, its two models, the addressed
transport protocol, EventBusKafka.bootstrap_servers and their unit tests) and credited in each file.

Onex-Lane: k6-omn18933
Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8

* perf(OMN-18933): read the packaged lane overlay once per process

The installed wheel changes only with a redeploy, which restarts the runtime.

Onex-Lane: k6-omn18933
Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8

* fix(OMN-18933): scope overlay refusals to bounded runtimes; strip broker credentials

Self-review findings: a malformed or out-of-scope declaration on one lane, or an unreadable overlay,
refused every runtime, including stability-test, judge, staging and prod, which the gate never covers.
They now refuse only a runtime that claims a bounded lane; the rest log that the gate is not armed.
EventBusKafka.bootstrap_servers returns the sanitized host list, as every other exposure in the class
does, because the dispatch port logs it.

Onex-Lane: k6-omn18933
Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8

* fix(OMN-18933): no new infra protocol; roundtrip-cover the route models

CI (run 35993722160) refused two things: a new Protocol in omnibase_infra (protocol ownership: 117 > 116)
and three models with no serialization disposition. The route gate now reads the transport's
environment and bootstrap_servers attributes directly, so no protocol is added and an in-process bus
(no broker address) resolves to None as before. The three K6 models get an explicit JSON roundtrip test
and a disposition pointing at it.

Onex-Lane: k6-omn18933
Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8

* test(OMN-18933): integration proof of the gate through the real port and Kafka bus identity

The Integration Test Coverage gate (run 35995848620) requires a tests/integration test for a feature
PR. This composes an unstarted EventBusKafka, the real RuntimeDelegationDispatchPort and the real
validator: a mismatched row refuses before the broker exists, the declared row reaches the broker, and
a runtime outside the gate dispatches untouched.

Onex-Lane: k6-omn18933
Onex-Session: 58cf36df4fd1452589e6d5ee00c357d8

* feat(OMN-18931): dogfood fault-pin admission and typed terminal-evidence capture, salvaged from #3951

The K1 infra half of omnibase_infra#3951, which no other PR carries:

- dogfood_delegation_fault_routes: a backend pin is admitted only as a
  declared dogfood fault route (single hop, HTTP 429 or 503, 240s, no
  escalation), resolved from the packaged omnimarket lane overlay. The
  runtime is classified by the bounded route gate's own rule
  (claimed_bounded_lane), so the shared compose listener redpanda:9092 alone
  never claims dogfood. The route slug is held as backend_key, read from the
  overlay's backend_id key.
- bounded_delegation_routes: the broker-identity checks are extracted,
  unchanged, into validate_bounded_lane_broker_identity, and the lane claim
  is exposed as claimed_bounded_lane, so the fault gate and the route gate
  share one rule.
- RuntimeDelegationDispatchPort: backend_id and no_escalation go onto the
  wire only after that admission; an opt-in terminal-evidence sink receives
  the consumed terminal's raw envelope bytes, topic, partition and offset,
  bound to the actual dispatch tenant.
- RuntimePatternBBroker: TerminalPayload keeps the raw envelope, partition
  and offset; dispatch_request takes an optional terminal observer.
- handler_wiring: the consumer re-checks the pin before the delegation
  orchestrator's typed request leg runs.
- render_bifrost_delegation_contract: the dogfood render appends the
  declared fault backends; no other lane renders one.
- capture, bind and finalize evidence scripts, the K1-K6 runner, the
  fixed-status fault provider and its two dogfood-profile compose services.

Stacked on omnibase_infra#4056 (OMN-18933), which carries the reworked
bounded-route gate including the listener-name classification fix.

Onex-Lane: infra-3951-salvage-split
Onex-Session: a68655aa197947c585d16729ece58c2a

* fix(OMN-18931): add no infra protocol; the evidence sink is a typed callable and the pin reads bus identity by attribute

omnibase_infra's protocol-ownership ratchet admits no new Protocol, and the
bounded route gate already reads environment and bootstrap_servers as plain
attributes (OMN-18933). The two protocols carried over from #3951 are removed:
the sink is DelegationTerminalEvidenceSink, a Callable alias, and the pin
admission reads the bus identity the same way the route gate does. Version
0.38.58, past the published 0.38.57.

Onex-Lane: infra-3951-salvage-split
Onex-Session: a68655aa197947c585d16729ece58c2a

* fix(OMN-18931): the salvaged scripts pass mypy --strict (no Any returned as int)

Onex-Lane: infra-3951-salvage-split
Onex-Session: a68655aa197947c585d16729ece58c2a

* fix(OMN-18931): regenerate the runner image identity lock for the version bump

The PR's pyproject.toml/uv.lock version bump (0.38.57 -> 0.38.58) feeds the
shared CI env digest, so the recorded runner-image identity went stale.
Regenerated via scripts/ci/runner_image_identity.py --mode generate.

RED before: test_recorded_identity_matches_recomputed_identity and
test_identity_uses_shared_env_digest_as_a_binding_component failed, lock
recorded shared_env_digest 99110eda10a86b271a810b4f vs recomputed
105217eb63ab02cc12602770.

GREEN after: both tests pass, full tests/ci/test_runner_image_identity.py
(11/11) passes.

Onex-Lane: infra-3951-salvage-split
Onex-Session: a68655aa197947c585d16729ece58c2a

* fix(OMN-18931): declare the two dogfood delegation-fault containers in the lane manifest and render tests

The PR added dogfood-delegation-fault-429 and -503 to docker-compose.dogfood.yml
without the lane-manifest entries the parity test requires, and without adding
them to the dogfood render test's expected service and port sets. Both are
long-running (kind: service, replicas: 1) and publish no host port. The manifest
edit carries a read-only verified: attestation from the lab-200 host.

Entries drafted through onex delegate (deployed dev lane, run
f1c441ee-603a-4a2e-8b51-d1178e48942c, Qwen3.8-27B, cost 0).

Onex-Lane: infra-3951-salvage-split
Onex-Session: 2df5b14a70fb4fd89dc0cc4218139afe

* fix(OMN-18931): vendored-pair ledger check tracks all three dod_verify_runs migrations

OMN-19514 (#4102) added 0002_dod_verify_runs_delegation_correlation_id.sql
to node_projection_dod_verdict's vendored set without updating this test's
hardcoded two-file expectation, so test_the_vendored_pair_matches_the_checksum_the_ledger_records
fails on dev itself (reproduced identically at origin/dev a6afd00, positive
control) as well as on this PR's merged head. Extend the check to the current
vendored set of three files instead of a fixed pair.

Onex-Lane: infra-3951-salvage-split
Onex-Session: a68655aa197947c585d16729ece58c2a

* fix(OMN-18931): the OMN-19514 linter positive control retargets an undeclared schema, since public is the tenant schema after OMN-17887

Onex-Lane: infra-3951-salvage-split
Onex-Session: a68655aa197947c585d16729ece58c2a

* fix(OMN-18931): advance the Receipt Gate pin so attempt-scoped supersede receipts resolve

The verify job on this PR returned nonpass_receipt for the two sibling
proof keys of OMN-18931 (omnimarket#2840 and #2841). Both keys carry
attempt-scoped supersession records on OCC dev, and the validator the
gate ran could not see them: the caller pin aeaf3b16 selects a copy of
receipt-gate.yml whose inner validator ref is still 37bd8519, where the
supersede-suffix pattern excludes a dot.

Reproduced locally against the same OCC tree and PR commits:
- validator at 37bd8519: eligible=false, reason=nonpass_receipt, the
  same two keys the CI log names
- validator at a03b1072 (the inner ref at 9cc9f035): eligible=true

This repoints the caller at 9cc9f035 (omnibase_core#1740), the pin
omnimarket already carries since omnimarket#2769 under OMN-19149. The
receipt-gate.yml copy differs between the two pins only in that inner
ref.

Related: OMN-19149, OMN-19050
Onex-Lane: infra-3951-salvage-split
Onex-Session: a68655aa197947c585d16729ece58c2a

---------

Co-authored-by: onexbot-occ-writer[bot] <307849072+onexbot-occ-writer[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant