Repository navigation
fix(OMN-18812): re-run a preflight whose companion merged, in omnibase_infra - #4193
Conversation
…kwarg-parity reader resolves the consumer's TypedDict-typed splat omnimarket#2841 (OMN-18931) declared no_escalation on the consumer protocol and passes it as **_no_escalation_dispatch_kwargs(request), a module-level helper annotated to return a module-level TypedDict, so a released omnibase_infra port predating the keyword keeps working. The always-run consumer-kwarg-parity hook then failed 3 cases on every omnibase_infra commit: the protocol lacked the keyword (the implementation has accepted it since #4088), and the call-site reader failed closed on any splat. - ProtocolDelegationDispatchPort.dispatch gains no_escalation: bool = False. - The call-site reader resolves exactly that splat shape to the TypedDict's keys, records them as conditional (never counted as passed for direction 3), and still fails closed on every other splat. - A new assertion holds every keyword the call site can send, explicit or splatted, to what the protocol and implementation accept. Onex-Lane: kwarg-parity-fix-83 Onex-Session: 097bff177c7b49ccbb1b5aa566dacfd7
…e_infra Port of omniclaude's scheduled occ-companion-merge-heal (omniclaude#2270, #2272). Every 10 minutes, for each open PR whose occ-preflight failed and whose cited OCC companion has since merged, re-run the failed jobs of the runs whose own preflight-family job failed. Complements the OMN-18352 occ-preflight-heal, whose two triggers fire before the median companion merge. Ships with an incident replay (OMN-15547) over captured bytes of omnibase_infra#3999 and a discriminator over #4191. Onex-Lane: merge-throughput-fix-83 Onex-Session: b9c6fba9eb674fed93005a4db3f9e3d4
…fra#4193 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head a779b8042d921822c2d4306256fdffca1486face.
#11543) * evidence(OMN-18812): author OCC companion for OmniNode-ai/omnibase_infra#4193 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head a779b8042d921822c2d4306256fdffca1486face. * evidence(OMN-18812): self-bind OCC#11543 + rebind contract_sha256 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai>
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: qwen3-review, gpt-oss-review
Models failed: none
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 6
Nit-level findings suppressed: 0
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Below quorum: 6 finding(s) raised by one model only (OMN-18479)
These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.
- [MAJOR]
.github/workflows/occ-companion-merge-heal.yml(gpt-oss-review) — Concurrency group allows overlapping runs | The workflow setsconcurrency.cancel-in-progress: false, which permits multiple scheduled instances to run concurrently. Overlapping runs can read the sam - [MAJOR]
.github/workflows/occ-companion-merge-heal.yml(gpt-oss-review) — Workflow dispatch can be abused to trigger mass re‑runs | Theworkflow_dispatchinputpr-numberaccepts any integer, allowing any user with dispatch permission to specify arbitrary PR numbers. Thi - [MINOR]
plan(qwen3-review) — Untitled finding - [MINOR]
scripts/ci/occ_companion_merge_heal.py(gpt-oss-review) — Partial re‑run failures are silently ignored | Inmain()ofscripts/ci/occ_companion_merge_heal.py, if anygh run rerun --failedcall raises an exception, the error is recorded but the workflow - [MINOR]
src/omnibase_infra/runtime/protocols/protocol_delegation_dispatch_port.py(gpt-oss-review) — Signature change inRuntimeDelegationDispatchPort.dispatchmay break callers | The addition of theno_escalation: bool = Falsekeyword argument todispatchin `src/omnibase_infra/runtime/protoco - [MINOR]
scripts/ci/occ_companion_merge_heal.py(gpt-oss-review) — No rate‑limit handling for GitHub API calls | TheGhCliimplementation makes multiple GitHub API requests (listing PRs, fetching check runs, runs, jobs) without checking for HTTP 429 responses or re
✅ Hostile Reviewer — REVIEWEDCritical findings: 0
Semantics (OMN-17492 — the model finds, thread resolution gates)
Powered by omniintelligence.review_pairing.cli_review — multi-model adversarial review: qwen3-review (Qwen3.8-27B), gpt-oss-review (gpt-oss-120b) (OMN-8468/OMN-8524/OMN-17492) |
|
OCC autobind rebound this PR's evidence-source stamp line to The receipt gate's own eligibility validator, run against the change-control tree the gate pins for Reported by |
|
No OCC evidence companion was minted for this PR. this PR is already bound to OCC#11541; its evidence companion exists and nothing needs authoring To clear this: Nothing to do — the companion already exists. Reported by |
There was a problem hiding this comment.
Hostile Reviewer — adversarial findings (OMN-17492)
Models succeeded: qwen3-review, gpt-oss-review
Models failed: none
New finding threads: 3
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 6
Nit-level findings suppressed: 0
The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.
Below quorum: 6 finding(s) raised by one model only (OMN-18479)
These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.
- [MAJOR]
.github/workflows/occ-companion-merge-heal.yml(qwen3-review) — Workflow token passed to untrusted Python script | The workflow passesGH_TOKEN: ${{ secrets.GITHUB_TOKEN }}to therun:step, which executespython3 scripts/ci/occ_companion_merge_heal.py. The - [MAJOR]
.github/workflows/occ-companion-merge-heal.yml(gpt-oss-review) — Concurrent scheduled runs can duplicate re‑run attempts | The workflow uses a concurrency group withcancel-in-progress: false. When the schedule triggers a new run before the previous run finishes, - [MINOR]
scripts/ci/occ_companion_merge_heal.py(qwen3-review) — API cost of checking every open PR every 10 minutes | The workflow runs every 10 minutes and, for each open PR, makes multiple API calls:gh pr list,gh api .../check-runs,gh pr view(for the c - [MINOR]
tests/ci/test_occ_companion_merge_heal_omn18812.py(qwen3-review) — Missing test for the race condition | The tests do not cover the race condition where the companion is merged at the time of the check but closed before the rerun is issued. The tests use aStubGht - [MINOR]
scripts/ci/occ_companion_merge_heal.py(qwen3-review) — Missing handling ofghbinary not found | The script usessubprocess.runto call theghbinary, but it does not handle the case where theghbinary is not found. Thesubprocess.runcall will - [MINOR]
scripts/ci/occ_companion_merge_heal.py(gpt-oss-review) — Job‑name matcher may over‑match unrelated jobs | The functionis_preflight_job_nametreats any occurrence of the markers"occ-preflight"or"occ preflight"as a match. This substring check can i
Findings demoted from threads (anchor rejected)
-
[MAJOR] hostile-reviewer (qwen3-review)
Race condition between companion merge and rerun | The script reads the companion's state and, if merged, issues a rerun. However, there is a race condition: between the time the script reads the companion state as
MERGEDand the time it issues thegh run rerun --failed, the companion could be closed or reverted. The script'sdecide_companion_healfunction checks the companion state once, but the rerun is issued later inmain. If the companion is closed after the check but before the rerun, the reruResolve this thread when addressed — the
Hostile Review Thread Gateblocks while hostile-reviewer threads are unresolved (OMN-17492). -
[MAJOR] hostile-reviewer (gpt-oss-review)
Any GitHub API failure aborts the entire heal pass | The
collect_decisionsfunction calls multipleGhPortmethods (failed_preflight_check_count, companion_state, failed_runs, run_failed_on_preflight). If any of these raise aRuntimeErrordue to a non‑zero exit code or malformed JSON, the exception propagates tomain, which aborts the whole pass. A single PR with an unreadable companion or transient API error prevents healing of all other PRs. | Evidence: def collect_decisions(...):
for number, hResolve this thread when addressed — the
Hostile Review Thread Gateblocks while hostile-reviewer threads are unresolved (OMN-17492). -
[MAJOR] hostile-reviewer (gpt-oss-review)
Partial re‑run failures are silently ignored | In
main, after attempting to re‑run failed runs, the code only treats the pass as an error if all re‑run attempts fail (if failures and healed == 0). When some re‑runs succeed and others fail, the script exits with success, masking the failures and leaving some PRs still red. | Evidence: if failures and healed == 0:
print(f"::error::every re-run attempt failed: {'; '.join(failures)}")
return EXIT_ERROR | Fix: Change the condition toif failures:Resolve this thread when addressed — the
Hostile Review Thread Gateblocks while hostile-reviewer threads are unresolved (OMN-17492).
OMN-18812 follow-up 2: the companion-merge heal, ported to omnibase_infra
Merge order: this PR is stacked on omnibase_infra#4192 and lands after it. Its branch carries the single commit of #4192 (946239e), because this repo's always-run pre-commit hook
onex-delegation-dispatch-consumer-kwarg-parityis red on plaindevagainst current omnimarket, and #4192 is the fix for that. Once #4192 squash-merges, those two files are already ondevwith identical content, so the change in this PR is the last commit only (a779b80).Problem.
occ-preflight / eligibilitywaits 1500 s for the cited change-control companion and then fails closed. When the companion merges later, nothing in this repo re-runs the preflight. The existingocc-preflight-healhere listens topull_request: editedandworkflow_run: completed, and both of those fire before the median companion merges. So the PR stays red until a person or a drain lane typesgh run rerun --failed. omniclaude fixed this on 2026-09-19 with a scheduled heal (omniclaude#2270, #2272). That heal exists only in omniclaude.What this adds.
.github/workflows/occ-companion-merge-heal.yml,scripts/ci/occ_companion_merge_heal.pyandtests/ci/test_occ_companion_merge_heal_omn18812.py. The logic is unchanged from omniclaude at d9cfb4c6f. The only differences are a provenance paragraph in the workflow header,setup-pythonpinned to a commit SHA, twonoqacomments that the ruff config here reports as unused, and one compound test assertion split in two.tests/ci/test_incident_replay_omn18812.py, overtests/fixtures/omn18812/, registered intests/incident_replays/registry.yaml.gh apireads of a real stale red, compressed withgzip -n -9. The bytes are already public on the PRs they come from.No gate is weakened. The re-run executes the same validators against the merged companion and can still fail. A PR still cannot merge before its companion does. The heal is not a required check. It uses only the ambient
GITHUB_TOKEN(actions: writeon its one job), so no new credential is added.Proof
--repo OmniNode-ai/omnibase_infra --dry-run). It would re-run feat(OMN-19215): carry a lane-added backend's tier placement through the bifrost renderer #3999 (3 runs) and fix(OMN-15692): pin bump for msk-direct-broker-endpoint rule 5 [PARKED — land trigger is OMN-16459 HTTPS-ingest cutover; OMN-15534 resolved] #2658 (5 runs, companion OCC#6083 merged). It refused the 9 PRs whose companion is still open and the 4 whose body has no stamp.mypy --strictis clean. Pre-commit passed on the commit, including theincident-replay-coveragehook.Expected effect
The merge-throughput measurement for 2026-09-26 found 140 of 221 product merges bound to a companion. They averaged 2.44h from push to merge, against 0.92h for PRs without one: 212 extra PR-hours in one day. This heal caps the wait after a companion merges at the 10-minute schedule plus the re-run time.
Evidence-Ticket: OMN-18812
Evidence-Source: OCC#11541