Skip to content

feat(OMN-19215): carry a lane-added backend's tier placement through the bifrost renderer - #3999

Merged
jonahgabriel merged 8 commits into
devfrom
jonah/omn-19215-placement-passthrough
Sep 28, 2026
Merged

jonahgabriel merged 8 commits into
devfrom
jonah/omn-19215-placement-passthrough

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

OMN-19215, design (B), omnibase_infra half. The routing authority in omnimarket (OmniNode-ai/omnimarket#2803) mirrors a bifrost backend that declares a placement into its routing tier, after the rungs it backs. This PR carries that placement from the lane overlay into the rendered contract.

  • Schema. ModelBifrostLaneBackendPlacement {tier, fallback_for, max_context_tokens} and an optional placement on ModelBifrostLaneBackendBinding. Only a backend the lane ADDS may carry one (a base-declared rung is already in the ladder), and a placement offering more context than the backend's context_window is refused naming the backend. Tier and rung names are checked by the routing authority against the ladder it loads.
  • Renderer. _added_backend_entry writes placement when present and writes nothing new when absent, so every committed overlay without a placement renders byte-identical.
  • Dev overlay (second commit). Places local-omnipc2-chat in the local tier behind local-coder and local-heavy-reasoning, 32768 context (llama.cpp's per-slot window). It answers only when the .201 rung is unavailable or already tried.

Sequencing

The dev-overlay commit must reach the lane only after omnimarket#2803 is released into the dev lane image: an omnimarket without that change refuses the placement key and the lane's delegation config would fail to load. Lab proof on the .201 dev lane (AC2: a test-scoped run whose rendered contract binds local-coder to a closed port answered by .202, plus an unmodified control answered by .201) runs after the M4 streak window closes. Nothing here is deployed before then.

Tests

  • tests/unit/runtime/test_bifrost_lane_overlay_placement_omn19215.py (9): pass-through, no key when absent, context-window refusal naming the backend at the model and at the render (ProtocolConfigurationError), base-backend refusal, four malformed placements. Three were RED before the change (the binding refused the key as an extra field).
  • tests/integration/runtime/test_dev_overlay_places_omnipc2_omn19215.py (2): the committed dev overlay renders the placement intact, every rung it names is bound in the same render, and a copy with an oversized placement is refused leaving no artifact.
  • tests/unit/models/test_model_serialization_roundtrip.py: the new model has a factory and the binding factory now carries a placement.
  • Renderer, served-model probe fixture, added-backend, parameter-count, lane-overlay CI and committed-lab-overlay render suites: 151 passed with the dev overlay change applied. mypy --strict clean on the changed modules.

Landing after M4

The orchestrator's M4 fence that kept this PR in draft has lifted (M4 was met 2026-09-23). This section records what landing requires.

Merge order (OMN-19215): 1) omnimarket#2803 merges to dev first (the routing-authority half this PR's renderer output depends on). 2) release-on-merge.yml auto-cuts the omnimarket release carrying that change. 3) this PR merges, consuming that published version in the dev-lane runtime image. 4) the AC2 lab pair (below) runs on the .201 dev lane.

Release cut required between omnimarket#2803 and this PR: the omnimarket auto-release from step 2 above. This PR's dev-overlay commit places local-omnipc2-chat with a placement key that only an omnimarket built from #2803 or later accepts; landing this PR's overlay commit against an older omnimarket would fail contract load on the lane.

Lab proof needed on the .201 dev lane after M4 (not run today — .201 is fenced): AC2 — a test-scoped run whose rendered contract binds local-coder to a closed port answered by .202, plus an unmodified control answered by .201, exercised through the deployed dev-lane onex-api container.

M4 probes to re-run after landing: C13, C14, C29 — this PR changes what the rendered delegation contract offers on the customer-local delegation path that those probes exercise.

.202 back in routing (2026-09-27)

The stop-using-.202 pause on this PR is released: operator RULING 2026-09-27T20:32:19Z lane=omnipc2-routing-restore (ledger:11849, "ok, looks fine I think. put it back into routing"), RELEASE rows ledger:11850, 11851 and 11855. .202 was rebuilt on its boot NVMe.

Serving profile reconciled, no change needed. .202 now serves Qwen3.8-27B-MTP-Q3_K_M.gguf with a q8_0 KV cache through a systemd drop-in (profile in the internal planning corpus). Read live 2026-09-27T20:3xZ: GET .202:8000/v1/models id and alias Qwen3.8-27B, meta.n_ctx 32768, ftype Q3_K - Medium; /props total_slots 4; /slots n_ctx 32768 on each of 4 slots; the unit still runs -c 32768 --parallel 4 --kv-unified exactly as before the rebuild. From inside omninode-runtime-effects on the .201 dev lane, GET .202:8000/v1/models returns 200 with Qwen3.8-27B, and a real chat completion to .202 returns model: Qwen3.8-27B. This PR encodes the served id, the 32768 window and the four-slot limit, all unchanged; it encodes no model file, quant or KV type. Only the quant (IQ4_XS to Q3_K_M) and KV type (f16 to q8_0) changed, which no identity or health probe here checks.

Lab proof

Hotpatch proof on the .201 dev lane, 2026-09-27 11:46-12:04Z (lab lease rows 2026-09-27T11:46:09Z and 12:04:16Z, lane delegation-fix-omnipc2-202-disk-and-routing-83, result PASS, restored=yes): omnibase_infra#4134 (whose commits include every commit of this PR) and omnimarket#2913 were patched into omninode-runtime and omninode-runtime-effects, the dev overlay rendered in-container, and six onex delegate runs on kafka/dev/deployed-lane completed on local Qwen3.8-27B with 0 escalations. .202 was down then, so .202-hashed runs retried onto .201. That lane also checked offline that the released omnimarket loads this PR's render (it writes no mode key). This PR's fallback-only render was not separately run on the lane.

Lab pass still owed, with .202 live. Path: (1) the lab-pool proof on the head before it lands; (2) the compose-dev lab receipt keyed by the merged sha on the .201 dev lane; (3) AC2 through onex-api on the .201 dev lane: a test-scoped rendered contract binding local-coder to a closed port is answered by .202, and an unmodified control by .201.

Order with omnibase_infra#4134. #4134 contains every commit of this PR plus spread mode. This PR can land first, because the released omnimarket already loads its render, and it puts .202 into the local tier as a fallback now; #4134 then lands after the omnimarket release carrying omnimarket#2913. If the drain prefers one PR, #4134 supersedes this one.

Branch updated from dev 2026-09-27; the dev-overlay placement test now matches the current dev overlay (local-embedding declared, the removed ds-v4-flash entry dropped) and passes mypy --strict (commit 45d719c). Focused suites green locally at that head: 103 passed; ruff, mypy and pre-commit clean on the changed file.

Lab pool readback (OMN-18893)

LAB PROOF PASS: omnibase_infra#3999 head 45d719ce11 on lab-105 (192.168.86.105), isolated project omnibase-infra-local, 2026-09-27T22:33:55Z to 2026-09-27T22:51:29Z
  ok   head_matches
  ok   stack_built
  ok   image_identity
  ok   health_8085
  ok   health_8086
  ok   migration_gate_healthy
  ok   no_wiring_failures
  ok   focused_tests
  note: omnibase-infra-local-omninode-runtime: 27 contract(s) fail to wire at dev too (base control)
  note: omnibase-infra-local-runtime-effects: 7 contract(s) fail to wire at dev too (base control)
  note: base control run at dev on the same host
  restored=yes (containers=0 volumes=0 networks=0 images=0 listeners=0 workdir=gone, snapshot-diff=0)
  method: scripts/runtime_build/prepr_runtime_pool.py (OMN-18893)
  ledger: RELEASE re=<your HOLD id> surface=105-runtime result=PASS restored=yes

Evidence-Ticket: OMN-19215
Evidence-Source: OCC#10983

…ugh to the rendered contract

The lane overlay binding accepts an optional placement {tier, fallback_for,
max_context_tokens} on an ADDED backend only, refuses one larger than the
backend's context_window, and the renderer passes it through unchanged. The
routing authority in omnimarket mirrors the backend into that tier after the
rungs it backs. An added backend with no placement renders exactly as before.

Onex-Lane: pc2-delegation-load
Onex-Session: 94b52a596fd34760ac199e09d09305b1
…ier behind the two .201 rungs

Held: merge only after the omnimarket placement change is released into the dev
lane image, since an older omnimarket refuses the placement key.

Onex-Lane: pc2-delegation-load
Onex-Session: 94b52a596fd34760ac199e09d09305b1
@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

No OCC evidence companion was minted for this PR.

product PR is a draft; companion suppressed (F-17)

Matched in the state: draft

To clear this: Mark the PR ready for review. The ready_for_review trigger re-fires the born path and the companion mints then.

Reported by node_occ_companion_effect (decline code pr_draft, OMN-16665). This decision was made against the PR's LIVE state at compute time, not at publish time — a green publisher job only means the command reached the broker.

…h ProtocolConfigurationError

Onex-Lane: pc2-delegation-load
Onex-Session: 94b52a596fd34760ac199e09d09305b1
…s intact, and an oversized one is refused

Onex-Lane: pc2-delegation-load
Onex-Session: 94b52a596fd34760ac199e09d09305b1
@jonahgabriel
jonahgabriel marked this pull request as ready for review September 23, 2026 20:25
@jonahgabriel
jonahgabriel enabled auto-merge (squash) September 23, 2026 20:25
jonahgabriel pushed a commit to OmniNode-ai/onex_change_control that referenced this pull request Sep 23, 2026
#10983)

* evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#3999

* evidence: OCC companion self-bind for #10983

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
@jonahgabriel
jonahgabriel marked this pull request as draft September 23, 2026 20:36
@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

✅ Hostile Reviewer — REVIEWED

Critical findings: 0
Major findings: 5
Total findings: 10
Models succeeded: qwen3-review,gpt-oss-review
Models unavailable: none

Action required: findings were posted as review threads. Address or reject each one, then resolve its thread — the Hostile Review Thread Gate fails while hostile-reviewer threads are unresolved (OMN-17492).


Semantics (OMN-17492 — the model finds, thread resolution gates)

Surface Meaning Blocks merge?
Review threads Per-finding, posted by the reviewer No (informational)
Hostile Review Thread Gate Deterministic: unresolved hostile-reviewer threads exist Fails until resolved (not yet a required context)
degraded verdict Fewer than 2 models succeeded (infra) Fails this job with a named reason

Powered by omniintelligence.review_pairing.cli_review — multi-model adversarial review: qwen3-review (Qwen3.8-27B), gpt-oss-review (gpt-oss-120b) (OMN-8468/OMN-8524/OMN-17492)

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: glm-review
Models failed: codex
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 7
Nit-level findings suppressed: 1

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 7 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_binding.py (_validate_binding) (glm-review) — context_window comparison assumes non-optional field | The new validation compares self.placement.max_context_tokens > self.context_window. The diff does not show context_window's type; if it is Optio
  • [MINOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_placement.py (glm-review) — fallback_for may list the backend itself | Nothing in the new validation prevents placement.fallback_for from containing binding.backend_key. The routing authority mirrors the backend into the named t
  • [MINOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_placement.py (glm-review) — Duplicate entries in fallback_for are not rejected | fallback_for is only constrained to min_length=1. A tuple like ("local-coder", "local-coder") passes validation and would be passed through verbati
  • [MINOR] tests/unit/runtime/test_bifrost_lane_overlay_placement_omn19215.py (glm-review) — No boundary test for max_context_tokens == context_window | The validation uses strict greater-than, so equality is legal. Both the unit and integration suites test only strictly-oversized values bein
  • [MINOR] src/omnibase_infra/runtime/render_bifrost_delegation_contract.py (glm-review) — Cross-checks deferred to another package leave a render-time gap | The renderer passes tier and fallback_for through unvalidated, deferring rung-name checks to the omnimarket routing authority. Until
  • [MINOR] tests/integration/runtime/test_dev_overlay_places_omnipc2_omn19215.py (glm-review) — Integration test couples to file paths and overlay contents | The integration test reads the committed dev overlay from a repo-relative path and hard-codes backend IDs, env var names, and the placed b
  • [MINOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_placement.py (glm-review) — max_context_tokens unconstrained against max_tokens | The validation checks placement.max_context_tokens against context_window only. A placement offering more context than the backend's declared max_

@jonahgabriel

Copy link
Copy Markdown
Collaborator Author

Lab readback, .201 dev lane, 2026-09-27 (OMN-19215 stack, with .202 down)

Lane delegation-fix-omnipc2-202-disk-and-routing-83. The hotpatch window ran from 11:46:09Z to 12:04:16Z; this lane's ledger rows carry both stamps.

What ran. I hotpatched omnimarket#2913 at aba970c69 (7 files, merged cleanly onto the lane's omnimarket 655b57e) and omnibase_infra#4134 at b6b141b00 (the renderer, the binding model, the placement model and the enum, on the lane's 889afaa1c) into omninode-runtime and omninode-runtime-effects. Before patching, every original file hashed equal to those base commits. I then re-rendered the bifrost contract inside each container from #4134's docker/lane-overlays/dev.bifrost.yaml. The rendered file carries placement: {tier: local, fallback_for: [local-coder, local-heavy-reasoning], max_context_tokens: 32768, mode: spread}. Its sha256 is bf181ea5b798fc79…, byte-identical to an offline render with the same code.

Condition. .202 is down. Its /data disk failed and llama-server cannot load its model (OMN-19863), so :8000 refuses connections.

Result. I made six onex delegate "Reply with exactly the word: pong" --bus kafka --lane dev --locus deployed-lane runs. Every one completed with pong, provider local, model Qwen3.8-27B and 0 escalations. The group index is SHA-256 of the correlation id, and it predicted the runtime log's delegation spread: pick in all six cases:

run correlation spread pick (runtime log) attempts exec ms
a7f52bf3 8dce28b9 local-omnipc2-chat, then local-heavy-reasoning 2 (1st: [Errno 111] Connection refused) 3918
fa5640bb b50f5519 local-omnipc2-chat, then local-heavy-reasoning 2 (same) 2951
14463add 0e1b2bfd local-omnipc2-chat, then local-heavy-reasoning 2 (same) 3365
fd665c92 b1c8bcfa local-heavy-reasoning 1 3265
b656ad55 37aca0a1 local-heavy-reasoning 1 3374
828af182 7e949072 local-heavy-reasoning 1 3554

A dead spread peer costs one refused connection and a same-tier sibling retry, not a failed delegation. So .202 does not need to come out of the overlay while its disk is out.

Restore. The originals went back at 11:53:18Z. The deploy agent then recreated both containers from image 889afaa1c at 11:56:20Z. Readback: all 8 patched files and the rendered contract (6b5c5ba09018) match their pre-hotpatch hashes, and the 3 added files are absent. Control run fbdcfd22 completed on local Qwen with 1 attempt and 0 delegation spread: lines.

Ordering hazard, measured. The lane's released omnimarket (0.4.245, the dev lane's current install) refuses the contract #4134 renders: placement.mode: Extra inputs are not permitted, so every delegation would fail to load its routing config. #4134's "Landing order required" (omnimarket#2913 released into the dev-lane image first) is therefore load-bearing, not advisory. #3999 alone renders no mode key and is safe against the current image.

Not proven here. These runs did not prove .202 answering (OMN-19215 AC2). That waits on OMN-19863. The receipts cannot show which host answered: both attempts carry the model-derived backend_id, and the refused attempt's failure_class is null. That is OMN-19234.

jonahgabriel and others added 2 commits September 27, 2026 16:44
…es the current dev overlay

omnibase_infra#4207 (OMN-17099) bound local-embedding in the dev overlay, and
omnibase_infra#4005 (OMN-19251) removed local-ds-v4-flash from it. After dev was
merged in, the minimal base contract this test writes still declared ds-v4-flash
(a KeyError on the served-id lookup) and not local-embedding (the render refused
it as an undeclared added backend). Declare the three base backends the overlay
binds today, as omnibase_infra#4134 does, and type _dev_overlay's return so the
file passes mypy --strict. The file is now byte-identical to #4134's.

Onex-Lane: pc2-delegation-load
Onex-Session: 94b52a596fd34760ac199e09d09305b1
@jonahgabriel
jonahgabriel marked this pull request as ready for review September 27, 2026 21:13
@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

OCC autobind rebound this PR's evidence-source stamp line to OCC#11059.

The receipt gate's own eligibility validator, run against the change-control tree the gate pins for OCC#11059, returned eligible for head 45d719ce11bab95bd70657cbe94792f0c607f174. The body now carries exactly one stamp line. Displaced: OCC#10983.

Reported by occ_companion_emitter (OMN-18853).

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: qwen3-review, gpt-oss-review
Models failed: none
New finding threads: 2
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 9
Nit-level findings suppressed: 2

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 9 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_binding.py (qwen3-review) — Placement validation bypassed when context_window is None | The validator in _validate_binding checks self.placement.max_context_tokens > self.context_window. If context_window is None (the field is o
  • [MAJOR] tests/unit/runtime/test_bifrost_lane_overlay_placement_omn19215.py (qwen3-review) — No test for placement with context_window omitted | The unit test file test_bifrost_lane_overlay_placement_omn19215.py covers oversized placement, missing rungs, empty tier, zero context, and unknown
  • [MAJOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_binding.py, src/omnibase_infra/runtime/render_bifrost_delegation_contract.py (gpt-oss-review) — Placement field introduces backward‑compatible contract change | ModelBifrostLaneBackendBinding now includes an optional placement attribute that is rendered into the delegation contract. Existing con
  • [MAJOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_binding.py, tests/integration/runtime/test_dev_overlay_places_omnipc2_omn19215.py (gpt-oss-review) — Inconsistent exception type for placement validation | ModelBifrostLaneBackendBinding._validate_binding raises ValueError when placement constraints are violated, while render_bifrost_delegation_contr
  • [MAJOR] tests/unit/runtime/test_bifrost_lane_overlay_placement_omn19215.py, src/omnibase_infra/runtime/models/model_bifrost_lane_backend_binding.py (gpt-oss-review) — Unit test assumes placement validation is performed by Pydantic, but model raises ValueError | The unit test test_a_placement_larger_than_the_context_window_fails_naming_the_backend expects a Validati
  • [MAJOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_placement.py, src/omnibase_infra/runtime/models/model_bifrost_lane_backend_binding.py (gpt-oss-review) — Placement fallback_for references are not validated against existing backends | The new placement model only validates tier, fallback_for length, and max_context_tokens. It does not verify that each e
  • [MINOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_placement.py (qwen3-review) — Tier name in placement is not validated against known tiers | The placement.tier field is a free-form string with min_length=1. The docstring says the routing authority checks tier names against the l
  • [MINOR] tests/integration/runtime/test_dev_overlay_places_omnipc2_omn19215.py (qwen3-review) — Integration test depends on the committed dev overlay file | test_dev_overlay_places_omnipc2_omn19215.py reads the actual docker/lane-overlays/dev.bifrost.yaml file. This couples the test to a mutable
  • [MINOR] tests/integration/runtime/test_dev_overlay_places_omnipc2_omn19215.py (qwen3-review) — Negative-control test asserts target does not exist but renderer may write partial output | The test asserts not target.exists() after the renderer raises ProtocolConfigurationError. This is only corr

Findings demoted from threads (anchor rejected)

  • [MINOR] hostile-reviewer (qwen3-review)

    fallback_for references not validated against the overlay's own backends | The placement's fallback_for tuple names backends that the routing authority will mirror into the tier. The renderer passes these names through without checking that they correspond to backends actually present in the rendered contract. The integration test asserts this post-hoc, but the renderer itself does not validate. A typo in a rung name will silently produce a rendered contract that the routing authority must reject, shifting

    Resolve this thread when addressed — the Hostile Review Thread Gate blocks while hostile-reviewer threads are unresolved (OMN-17492).

  • [MINOR] hostile-reviewer (gpt-oss-review)

    Use of assert for runtime validation | The function _added_backend_entry relies on assert statements to guarantee required fields (provider, tier, credential). In production, asserts may be disabled, causing silent acceptance of invalid data and later failures. | Evidence: src/omnibase_infra/runtime/render_bifrost_delegation_contract.py: lines containing "assert binding.provider is not None", "assert binding.tier is not None", "assert binding.credential is not None". | Fix: Replace asserts with explicit che

    Resolve this thread when addressed — the Hostile Review Thread Gate blocks while hostile-reviewer threads are unresolved (OMN-17492).

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: qwen3-review, gpt-oss-review
Models failed: none
New finding threads: 2
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 7
Nit-level findings suppressed: 1

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 7 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] src/omnibase_infra/runtime/render_bifrost_delegation_contract.py (qwen3-review) — No validation that fallback_for rungs exist in the rendered contract | The placement model accepts arbitrary strings for fallback_for. The unit test `test_a_base_backend_cannot_be_given_a_placement_
  • [MAJOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_placement.py (qwen3-review) — No validation that placement.tier matches the backend's own tier | A backend can declare tier: "local" while its placement says tier: "cheap_cloud". The model does not enforce that the placement t
  • [MINOR] src/omnibase_infra/runtime/render_bifrost_delegation_contract.py (qwen3-review) — Placement data is passed through without sanitization or allowlist | The model_dump(mode="json") call on the placement object passes the tier and fallback_for strings directly into the rendered cont
  • [MINOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_placement.py (qwen3-review) — No test for placement with duplicate rung names in fallback_for | The fallback_for field is a tuple, so duplicates are possible: fallback_for: ("local-coder", "local-coder"). No test covers this c
  • [MINOR] tests/integration/runtime/test_dev_overlay_places_omnipc2_omn19215.py (qwen3-review) — Integration test negative control mutates the real overlay in memory | The test test_an_oversized_placement_in_the_dev_overlay_is_refused loads the real dev overlay, mutates the placement in memory,
  • [MINOR] src/omnibase_infra/runtime/render_bifrost_delegation_contract.py (qwen3-review) — No test for placement on a serving backend (serving=True) | The _added_backend_entry function sets endpoint_url to None when binding.serving is True. A placement on a serving backend would be
  • [MINOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_binding.py (gpt-oss-review) — Inconsistent exception type for placement errors | When placement validation fails, the code raises a generic ValueError. The rendering pipeline and tests expect ProtocolConfigurationError (or Validat

Findings demoted from threads (anchor rejected)

  • [MAJOR] hostile-reviewer (qwen3-review)

    Placement validation only fires for added backends, not base-declared ones | The _validate_binding method guards the placement check with if self.placement is not None: but the inner logic only raises when not declared. However, the context-window check (self.placement.max_context_tokens > self.context_window) is nested inside the if self.placement is not None block but is NOT guarded by the declared check. This means a base-declared backend that somehow carries a placement (which the first check

    Resolve this thread when addressed — the Hostile Review Thread Gate blocks while hostile-reviewer threads are unresolved (OMN-17492).

  • [MAJOR] hostile-reviewer (gpt-oss-review)

    Placement validation method never executed | The ModelBifrostLaneBackendBinding class defines a private validate_binding method that checks placement constraints, but it is not registered with Pydantic's validation lifecycle (e.g., via @model_validator). Consequently, the constraints on placement (added‑backend requirement and context‑window limit) are never enforced at model instantiation, allowing invalid configurations to pass through to rendering. | Evidence: In src/omnibase_infra/runtime/models/model

    Resolve this thread when addressed — the Hostile Review Thread Gate blocks while hostile-reviewer threads are unresolved (OMN-17492).

…I Summary external-sweep false reds)

CI Summary read RED on two contexts that no later attempt of run 36350898404
ever re-posts: the bare unresolved 'Tests (Split ${{ matrix.split }}/...)'
(cancelled during attempt 1, 21:13:29Z, ci-watch class D2) and the bare
'deploy-gate' (skipped, from the pre-ready-flip push run at 21:09:56Z, also
D2). The compound 'deploy-gate / deploy-gate' is green and every real test
shard (Split 1/15..15/15) plus CI Tests Gate are green. Per pr-land/ci-watch
class D2, no rerun clears an orphaned bare-name context; only a fresh head
does.

Onex-Lane: pc2-delegation-load
Onex-Session: 94b52a596fd34760ac199e09d09305b1
@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

OCC autobind rebound this PR's evidence-source stamp line to OCC#10983.

The receipt gate's own eligibility validator, run against the change-control tree the gate pins for OCC#10983, returned eligible for head 180fa9ec7b43d4399c9be5282fd4ee9b0ce5c059. The body now carries exactly one stamp line. Displaced: OCC#11059.

Reported by occ_companion_emitter (OMN-18853).

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: qwen3-review, gpt-oss-review
Models failed: none
New finding threads: 2
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 7
Nit-level findings suppressed: 1

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 7 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] src/omnibase_infra/runtime/render_bifrost_delegation_contract.py (qwen3-review) — No validation that fallback_for rungs reference backends in the same overlay | The placement's fallback_for field is a free-form tuple of strings. The renderer passes it through to the rendered contra
  • [MAJOR] tests/integration/runtime/test_dev_overlay_places_omnipc2_omn19215.py (qwen3-review) — Integration test negative control mutates the real overlay file in memory but writes a poisoned copy | test_an_oversized_placement_in_the_dev_overlay_is_refused loads the real dev overlay, mutates the
  • [MAJOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_placement.py (gpt-oss-review) — fallback_for length validation ineffective | ModelBifrostLaneBackendPlacement defines fallback_for as a tuple with Field(min_length=1). Pydantic's min_length constraint applies to strings, not sequenc
  • [MINOR] src/omnibase_infra/runtime/models/model_bifrost_lane_backend_placement.py (qwen3-review) — Placement tier and fallback_for are unvalidated free strings at the model level | ModelBifrostLaneBackendPlacement.tier is a str with min_length=1, and fallback_for is a tuple of strings with min_leng
  • [MINOR] tests/unit/runtime/test_bifrost_lane_overlay_placement_omn19215.py (qwen3-review) — No test for placement on a backend that is not declared and not added (i.e., a base backend re-bound by the lane) | The unit test test_a_base_backend_cannot_be_given_a_placement_by_a_lane covers the c
  • [MINOR] docker/lane-overlays/dev.bifrost.yaml (qwen3-review) — Dev overlay comment references 'the two .201 rungs it backs' but the fallback_for list has two entries | The YAML comment says 'placed in the local tier after the two .201 rungs it backs'. The fallbac
  • [MINOR] src/omnibase_infra/runtime/render_bifrost_delegation_contract.py (gpt-oss-review) — Unnecessary type‑annotated variable in render function | render_bifrost_delegation_contract introduces a variable annotation 'entry: dict[object, object] = {...}' before populating the backend entry.

Findings demoted from threads (anchor rejected)

  • [MAJOR] hostile-reviewer (qwen3-review)

    Placement validation only fires for declared backends, not for all backends | The context-window check in _validate_binding is gated behind 'if self.placement is not None' inside the 'if declared:' block. This means a base-declared backend that carries a placement will raise the 'not an added backend' error, but the context-window check is never reached for it. More critically, the check 'self.placement.max_context_tokens > self.context_window' is only evaluated when 'declared' is True. If a lane-added back

    Resolve this thread when addressed — the Hostile Review Thread Gate blocks while hostile-reviewer threads are unresolved (OMN-17492).

  • [MAJOR] hostile-reviewer (gpt-oss-review)

    Inconsistent exception type for placement validation errors | ModelBifrostLaneBackendBinding._validate_binding raises ValueError when a placement is supplied for a non‑added backend or when placement.max_context_tokens exceeds the backend's context_window. The rendering pipeline and tests expect ProtocolConfigurationError (or ValidationError) for configuration problems. Raising ValueError may propagate as an uncaught exception, breaking error‑handling contracts and leading to unexpected failure modes. | Evi

    Resolve this thread when addressed — the Hostile Review Thread Gate blocks while hostile-reviewer threads are unresolved (OMN-17492).

@jonahgabriel
jonahgabriel added this pull request to the merge queue Sep 28, 2026
Merged via the queue into dev with commit 7f88ed3 Sep 28, 2026
165 of 172 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-19215-placement-passthrough branch September 28, 2026 01:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant