Skip to content

fix(OMN-18812): re-run a preflight whose companion merged, in omnibase_infra - #4193

Merged
jonahgabriel merged 3 commits into
devfrom
jonah/omn-18812-companion-merge-heal-omnibase-infra
Sep 27, 2026
Merged

jonahgabriel merged 3 commits into
devfrom
jonah/omn-18812-companion-merge-heal-omnibase-infra

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

OMN-18812 follow-up 2: the companion-merge heal, ported to omnibase_infra

Merge order: this PR is stacked on omnibase_infra#4192 and lands after it. Its branch carries the single commit of #4192 (946239e), because this repo's always-run pre-commit hook onex-delegation-dispatch-consumer-kwarg-parity is red on plain dev against current omnimarket, and #4192 is the fix for that. Once #4192 squash-merges, those two files are already on dev with identical content, so the change in this PR is the last commit only (a779b80).

Problem. occ-preflight / eligibility waits 1500 s for the cited change-control companion and then fails closed. When the companion merges later, nothing in this repo re-runs the preflight. The existing occ-preflight-heal here listens to pull_request: edited and workflow_run: completed, and both of those fire before the median companion merges. So the PR stays red until a person or a drain lane types gh run rerun --failed. omniclaude fixed this on 2026-09-19 with a scheduled heal (omniclaude#2270, #2272). That heal exists only in omniclaude.

What this adds.

  • The same heal, copied: .github/workflows/occ-companion-merge-heal.yml, scripts/ci/occ_companion_merge_heal.py and tests/ci/test_occ_companion_merge_heal_omn18812.py. The logic is unchanged from omniclaude at d9cfb4c6f. The only differences are a provenance paragraph in the workflow header, setup-python pinned to a commit SHA, two noqa comments that the ruff config here reports as unused, and one compound test assertion split in two.
  • The incident replay that the incident-replay coverage gate here requires for a new guard: tests/ci/test_incident_replay_omn18812.py, over tests/fixtures/omn18812/, registered in tests/incident_replays/registry.yaml.
    • The fixtures are verbatim gh api reads of a real stale red, compressed with gzip -n -9. The bytes are already public on the PRs they come from.
    • The incident is omnibase_infra#3999. Its preflight and OCC Companion Merged Gate failed at 18:02–18:46Z on 2026-09-23, its companion OCC#10983 merged at 20:35:00Z, and it was still red when captured three days later.
    • The replay drives the real guard. The guard must select exactly the three runs whose own preflight-family job failed (35898373010, 35898372640, 35898371776) and leave alone the three runs that failed for other reasons.
    • The discriminator is omnibase_infra#4191, whose companion OCC#11538 was open at capture. The guard must refuse it without reading a single run.
    • Both directions are mutation-proved. Removing the merged-companion precondition turns the discriminator red, and matching every failed job instead of only the preflight family turns the incident case red.

No gate is weakened. The re-run executes the same validators against the merged companion and can still fail. A PR still cannot merge before its companion does. The heal is not a required check. It uses only the ambient GITHUB_TOKEN (actions: write on its one job), so no new credential is added.

Proof

Expected effect

The merge-throughput measurement for 2026-09-26 found 140 of 221 product merges bound to a companion. They averaged 2.44h from push to merge, against 0.92h for PRs without one: 212 extra PR-hours in one day. This heal caps the wait after a companion merges at the 10-minute schedule plus the re-run time.

Evidence-Ticket: OMN-18812
Evidence-Source: OCC#11541

…kwarg-parity reader resolves the consumer's TypedDict-typed splat

omnimarket#2841 (OMN-18931) declared no_escalation on the consumer protocol and
passes it as **_no_escalation_dispatch_kwargs(request), a module-level helper
annotated to return a module-level TypedDict, so a released omnibase_infra port
predating the keyword keeps working. The always-run consumer-kwarg-parity hook
then failed 3 cases on every omnibase_infra commit: the protocol lacked the
keyword (the implementation has accepted it since #4088), and the call-site
reader failed closed on any splat.

- ProtocolDelegationDispatchPort.dispatch gains no_escalation: bool = False.
- The call-site reader resolves exactly that splat shape to the TypedDict's
  keys, records them as conditional (never counted as passed for direction 3),
  and still fails closed on every other splat.
- A new assertion holds every keyword the call site can send, explicit or
  splatted, to what the protocol and implementation accept.

Onex-Lane: kwarg-parity-fix-83
Onex-Session: 097bff177c7b49ccbb1b5aa566dacfd7
…e_infra

Port of omniclaude's scheduled occ-companion-merge-heal (omniclaude#2270,
#2272). Every 10 minutes, for each open PR whose occ-preflight failed and
whose cited OCC companion has since merged, re-run the failed jobs of the
runs whose own preflight-family job failed. Complements the OMN-18352
occ-preflight-heal, whose two triggers fire before the median companion
merge. Ships with an incident replay (OMN-15547) over captured bytes of
omnibase_infra#3999 and a discriminator over #4191.

Onex-Lane: merge-throughput-fix-83
Onex-Session: b9c6fba9eb674fed93005a4db3f9e3d4
onexbot-occ-writer Bot pushed a commit to OmniNode-ai/onex_change_control that referenced this pull request Sep 26, 2026
…fra#4193

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head a779b8042d921822c2d4306256fdffca1486face.
jonahgabriel pushed a commit to OmniNode-ai/onex_change_control that referenced this pull request Sep 26, 2026
#11543)

* evidence(OMN-18812): author OCC companion for OmniNode-ai/omnibase_infra#4193

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head a779b8042d921822c2d4306256fdffca1486face.

* evidence(OMN-18812): self-bind OCC#11543 + rebind contract_sha256

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: qwen3-review, gpt-oss-review
Models failed: none
New finding threads: 0
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 6
Nit-level findings suppressed: 0

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 6 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] .github/workflows/occ-companion-merge-heal.yml (gpt-oss-review) — Concurrency group allows overlapping runs | The workflow sets concurrency.cancel-in-progress: false, which permits multiple scheduled instances to run concurrently. Overlapping runs can read the sam
  • [MAJOR] .github/workflows/occ-companion-merge-heal.yml (gpt-oss-review) — Workflow dispatch can be abused to trigger mass re‑runs | The workflow_dispatch input pr-number accepts any integer, allowing any user with dispatch permission to specify arbitrary PR numbers. Thi
  • [MINOR] plan (qwen3-review) — Untitled finding
  • [MINOR] scripts/ci/occ_companion_merge_heal.py (gpt-oss-review) — Partial re‑run failures are silently ignored | In main() of scripts/ci/occ_companion_merge_heal.py, if any gh run rerun --failed call raises an exception, the error is recorded but the workflow
  • [MINOR] src/omnibase_infra/runtime/protocols/protocol_delegation_dispatch_port.py (gpt-oss-review) — Signature change in RuntimeDelegationDispatchPort.dispatch may break callers | The addition of the no_escalation: bool = False keyword argument to dispatch in `src/omnibase_infra/runtime/protoco
  • [MINOR] scripts/ci/occ_companion_merge_heal.py (gpt-oss-review) — No rate‑limit handling for GitHub API calls | The GhCli implementation makes multiple GitHub API requests (listing PRs, fetching check runs, runs, jobs) without checking for HTTP 429 responses or re

@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

✅ Hostile Reviewer — REVIEWED

Critical findings: 0
Major findings: 5
Total findings: 9
Models succeeded: qwen3-review,gpt-oss-review
Models unavailable: none

Action required: findings were posted as review threads. Address or reject each one, then resolve its thread — the Hostile Review Thread Gate fails while hostile-reviewer threads are unresolved (OMN-17492).


Semantics (OMN-17492 — the model finds, thread resolution gates)

Surface Meaning Blocks merge?
Review threads Per-finding, posted by the reviewer No (informational)
Hostile Review Thread Gate Deterministic: unresolved hostile-reviewer threads exist Fails until resolved (not yet a required context)
degraded verdict Fewer than 2 models succeeded (infra) Fails this job with a named reason

Powered by omniintelligence.review_pairing.cli_review — multi-model adversarial review: qwen3-review (Qwen3.8-27B), gpt-oss-review (gpt-oss-120b) (OMN-8468/OMN-8524/OMN-17492)

@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

OCC autobind rebound this PR's evidence-source stamp line to OCC#11541.

The receipt gate's own eligibility validator, run against the change-control tree the gate pins for OCC#11541, returned eligible for head 74689c81ee6a2cfba4e62fdae27410b208add64d. The body now carries exactly one stamp line. Displaced: OCC#11543.

Reported by occ_companion_emitter (OMN-18853).

@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

No OCC evidence companion was minted for this PR.

this PR is already bound to OCC#11541; its evidence companion exists and nothing needs authoring

To clear this: Nothing to do — the companion already exists.

Reported by node_occ_companion_effect (decline code already_bound, OMN-16665). This decision was made against the PR's LIVE state at compute time, not at publish time — a green publisher job only means the command reached the broker.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hostile Reviewer — adversarial findings (OMN-17492)

Models succeeded: qwen3-review, gpt-oss-review
Models failed: none
New finding threads: 3
Deduped (already posted on this PR): 0
Below quorum (one model only, reported not threaded): 6
Nit-level findings suppressed: 0

The model is the FINDER, never the gate: merge is gated only by the
deterministic Hostile Review Thread Gate, which blocks while
hostile-reviewer threads are unresolved. Resolve each thread after
addressing (or rejecting, with a reply) its finding.

Below quorum: 6 finding(s) raised by one model only (OMN-18479)

These are reported and NOT dropped, but they get no thread and do not block: a single model's finding no other model reproduced is not evidence enough to stop a merge. Read them; act on them if they are right.

  • [MAJOR] .github/workflows/occ-companion-merge-heal.yml (qwen3-review) — Workflow token passed to untrusted Python script | The workflow passes GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} to the run: step, which executes python3 scripts/ci/occ_companion_merge_heal.py. The
  • [MAJOR] .github/workflows/occ-companion-merge-heal.yml (gpt-oss-review) — Concurrent scheduled runs can duplicate re‑run attempts | The workflow uses a concurrency group with cancel-in-progress: false. When the schedule triggers a new run before the previous run finishes,
  • [MINOR] scripts/ci/occ_companion_merge_heal.py (qwen3-review) — API cost of checking every open PR every 10 minutes | The workflow runs every 10 minutes and, for each open PR, makes multiple API calls: gh pr list, gh api .../check-runs, gh pr view (for the c
  • [MINOR] tests/ci/test_occ_companion_merge_heal_omn18812.py (qwen3-review) — Missing test for the race condition | The tests do not cover the race condition where the companion is merged at the time of the check but closed before the rerun is issued. The tests use a StubGh t
  • [MINOR] scripts/ci/occ_companion_merge_heal.py (qwen3-review) — Missing handling of gh binary not found | The script uses subprocess.run to call the gh binary, but it does not handle the case where the gh binary is not found. The subprocess.run call will
  • [MINOR] scripts/ci/occ_companion_merge_heal.py (gpt-oss-review) — Job‑name matcher may over‑match unrelated jobs | The function is_preflight_job_name treats any occurrence of the markers "occ-preflight" or "occ preflight" as a match. This substring check can i

Findings demoted from threads (anchor rejected)

  • [MAJOR] hostile-reviewer (qwen3-review)

    Race condition between companion merge and rerun | The script reads the companion's state and, if merged, issues a rerun. However, there is a race condition: between the time the script reads the companion state as MERGED and the time it issues the gh run rerun --failed, the companion could be closed or reverted. The script's decide_companion_heal function checks the companion state once, but the rerun is issued later in main. If the companion is closed after the check but before the rerun, the reru

    Resolve this thread when addressed — the Hostile Review Thread Gate blocks while hostile-reviewer threads are unresolved (OMN-17492).

  • [MAJOR] hostile-reviewer (gpt-oss-review)

    Any GitHub API failure aborts the entire heal pass | The collect_decisions function calls multiple GhPort methods (failed_preflight_check_count, companion_state, failed_runs, run_failed_on_preflight). If any of these raise a RuntimeError due to a non‑zero exit code or malformed JSON, the exception propagates to main, which aborts the whole pass. A single PR with an unreadable companion or transient API error prevents healing of all other PRs. | Evidence: def collect_decisions(...):
    for number, h

    Resolve this thread when addressed — the Hostile Review Thread Gate blocks while hostile-reviewer threads are unresolved (OMN-17492).

  • [MAJOR] hostile-reviewer (gpt-oss-review)

    Partial re‑run failures are silently ignored | In main, after attempting to re‑run failed runs, the code only treats the pass as an error if all re‑run attempts fail (if failures and healed == 0). When some re‑runs succeed and others fail, the script exits with success, masking the failures and leaving some PRs still red. | Evidence: if failures and healed == 0:
    print(f"::error::every re-run attempt failed: {'; '.join(failures)}")
    return EXIT_ERROR | Fix: Change the condition to if failures:

    Resolve this thread when addressed — the Hostile Review Thread Gate blocks while hostile-reviewer threads are unresolved (OMN-17492).

@jonahgabriel
jonahgabriel added this pull request to the merge queue Sep 27, 2026
Merged via the queue into dev with commit 41b993b Sep 27, 2026
155 of 162 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-18812-companion-merge-heal-omnibase-infra branch September 27, 2026 03:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant