Repository navigation
feat: Complete Hook Node Protocol Integration and Production Readiness - #7
Conversation
…ning - Add comprehensive quality checks workflow (pytest, mypy, ruff) - Use continue-on-error strategy for existing technical debt - Provide visibility into 172+ mypy errors and pytest collection failures - Enable progressive hardening as issues are resolved - Establish foundation for preventing quality regressions Technical debt tracked: - Import path migration needed (omnibase_core.model.* → models.*) - Missing test dependencies (locust, testcontainers) - 50+ missing type annotations - 24 deprecated Pydantic validators Next: Fix import paths to enable pytest collection
MAJOR BREAKTHROUGH: Pytest collection now passes completely! ✅ Results Summary: - Before: 7 collection errors, 0 tests collected - After: 0 collection errors, 88 tests collected successfully ✅ Dependencies Added: - pytest-cov for coverage reporting - locust for load testing framework - testcontainers for integration testing - kafka-python for Kafka integration tests - Additional type stubs for mypy coverage ✅ Import Path Migration (Systematic): - Fixed omnibase_core.model.* → omnibase_core.models.* imports - Fixed omnibase_core.core_error_codes → omnibase_core.core.errors.onex_error - Fixed omnibase_core.onex_error → omnibase_core.core.errors.onex_error - Fixed test import paths from src.omnibase_infra.* to omnibase_infra.* - Added missing Any import to container.py ✅ Code Quality Foundation: - Applied ruff auto-fixes to enum files - Established CI pipeline with progressive hardening strategy - 88 tests now discoverable for validation Next: Validate CI pipeline reports and proceed with Pydantic V2 migration
- Add GitHub token authentication to checkout action - Configure global git URL rewriting for private repos - Resolves CI failures during dependency installation - Enables poetry to access omnibase_spi and omnibase_core private repos Fixes dependency access issue that was causing CI pipeline failures during 'poetry install' step.
- Replace GITHUB_TOKEN with OMNI_CI_PAT for cross-repository access - GITHUB_TOKEN is limited to current repository scope - OMNI_CI_PAT provides read access to omnibase_spi and omnibase_core - Requires manual creation of PAT secret in repository settings Addresses CI authentication failures during dependency installation.
PR Review: Hook Node Protocol IntegrationThis PR contains 256K additions across 184 files, which is too large for effective review. Critical Issues:
Strengths:
Recommendations:
Security Assessment:
Verdict: REQUEST CHANGES - Split PR and fix CI/CD first. Reviewed per ONEX Infrastructure Standards. |
🔍 Code Review: Hook Node Protocol Integration PR #7✅ Strengths & Accomplishments
🚨 Critical Issues Found
|
Comprehensive Code Review: PR #7 - Hook Node Protocol IntegrationExecutive SummaryThis substantial PR (184 files, 256K additions) implements a production-ready Hook Node for webhook notifications with excellent security, reliability, and observability features. The implementation demonstrates strong adherence to ONEX standards. ✅ Strengths1. Exceptional Security Implementation
2. ONEX Architecture Excellence
3. Production-Ready Features
|
🔍 ONEX Infrastructure PR Review: Hook Node Protocol IntegrationExecutive SummaryThis PR implements a production-ready Hook Node with excellent security and architecture compliance. However, the PR size (256K additions, 86 files) violates review best practices. Overall Score: 85/100 ✅ Conditionally Approved ✅ Excellent Compliance AreasStrong Typing & Models (100/100)
ONEX Architecture (95/100)
Security Implementation (100/100)Outstanding threat protection:
Production Readiness (95/100)
|
🔍 Pull Request Review: Hook Node Protocol IntegrationOverall Assessment: APPROVED ✅ - Production Ready (95/100)This is an excellent implementation that demonstrates strong adherence to ONEX architecture principles and production-grade engineering practices. 📊 Code Quality & ONEX Standards Compliance✅ Excellent Compliance
|
- Resolve all merge conflicts prioritizing hook PR changes - Update import paths: omnibase_core.models.core → omnibase_core.model.core - Adopt hook PR error handling patterns - Remove duplicate protocol definitions in favor of SPI versions - Integrate hook node implementation with Slack webhook functionality - Update CI permissions and validation patterns - Maintain ONEX compliance throughout merge
- Fix remaining conflict markers in container.py and event_bus_circuit_breaker.py - Ensure all files compile correctly - Complete merge resolution with hook PR prioritization
🔍 Code Review for PR #7: Hook Node Protocol IntegrationThank you for this comprehensive PR! I've reviewed the changes and have the following feedback: ✅ Strengths
🚨 Critical Issues1. Massive Ruff Report File (248MB+)The ruff_report.json file contains 248,151 lines of linting output and should NOT be committed:
2. Test Script in RepositoryThe test-pat-access.sh file appears to be a utility script that shouldn't be in version control:
|
CRITICAL fixes: - Add BLOCKER notice for omnibase_core 0.5.x dependency requirement - Update all NEW component structures to use flat directories (no v1_0_0) - Add projection vs event publishing distinction (persist to storage vs publish to Kafka) - Mark existing v1_0_0 directories as LEGACY with H1 migration reference MAJOR fixes: - Add Phase 1 dependency verification as [GATE] Task 1 - Add pre-implementation meeting requirements with decision checklist - Add RACI matrix placeholder format for names/dates assignment - Add explicit escalation timeline for contingency plan (Day 0 → Day 7+) - Verify A2a envelope canonicality and handler terminology in Global Constraint #7 - Add error sanitization acceptance criteria to E1 with CLAUDE.md references MINOR fixes: - Add F0 ↔ B2 interaction sequence diagram (projector before intent publish) - Add end-to-end orchestrator → reducer → effect flow diagram - Add F0 failure handling documentation (projector fails → no intent → DLQ) - Add B6 RuntimeTick configuration details (env var, min/max values) - Add pattern validator test requirements with known-bad test case names - Add circuit breaker and correlation ID acceptance criteria to E1 - Add comprehensive domain derivation examples (valid/invalid) to B1a - Add H1 v1_0_0 cutover strategy with deprecation milestones - Add G5a property-based testing sub-ticket - Add target import paths section labeled as post-0.5.x NITPICK fixes: - Add orchestrator state-reading invariant (projections only) - Add timeout handling details (RuntimeTick cadence, emitted_at markers) - Add concrete test examples for G1-G4 - Add "Requires 0.5.x" to all base class dependencies - Add timeline risk factor for decision resolution delay - Add PEP 604 type annotation convention note - Add B3 and E1 idempotency key strategies CLAUDE.md updates: - Add "NO VERSIONED DIRECTORIES" critical policy section - Update node structure pattern to show canonical (flat) vs legacy (v1_0_0) - Update registry naming conventions to reference flat structure
CRITICAL: - Add prominent BLOCKER notice with structured table format - Clarify projection persistence vs event publishing distinction - Add single envelope principle per architectural plane (A2a) - Add F0 terminology clarification section MAJOR: - Mark Section 9.1 open questions as CRITICAL blockers - Add Phase 1 Task 0 GATE for dependency verification - Complete RACI matrix with Tech Lead placeholders - Add pre-implementation meeting scheduling requirements - Add error sanitization references to E1 acceptance criteria - Enhance H1 blocking dependency on OMN-959 - Add performance benchmarking targets - Align ADR cross-references between documents MINOR: - Fix file path references to absolute paths - Add stakeholder communication plan for PR #52 rejection - Enhance escalation timeline with templates - Add domain derivation rule examples (B1a) - Add RuntimeTick configuration documentation (B6) - Add circuit breaker and correlation ID requirements NITPICK: - Add ProtocolProjectionReader clarification - Add base class version requirements table - Add ticket dependency visualization notes - Add versioning policy for design documents Cross-document consistency: - Align version references between HANDOFF and TICKET_PLAN - Add terminology alignment notes (Global Constraint #7) - Update DESIGN doc with cross-references
* docs: add canonical ONEX Runtime & Registration architecture plan Add comprehensive documentation for the ONEX Runtime and Two-Way Registration architecture refactor: Design Documents: - DESIGN_TWO_WAY_REGISTRATION_ARCHITECTURE.md: Canonical workflow architecture defining event-driven orchestration, pure reducer pattern, and isolated I/O effects (v2.1.0) - ONEX_RUNTIME_REGISTRATION_TICKET_PLAN.md: 31-ticket implementation plan across 8 sections (Foundation, Runtime, Orchestrator, Reducer, Effects, Projection, Testing, Migration) Current State Analysis (docs/as_is/): - Layering and terminology analysis - Node execution shapes documentation - Messaging and envelope patterns - Event bus and runtime dispatch shapes - Two-way registration trace - Interface crosswalk - Decision points and open questions Handoff Documentation: - HANDOFF_TWO_WAY_REGISTRATION_REFACTOR.md All 31 tickets have been created in Linear with proper dependencies, priorities, and acceptance criteria. Key tickets: - OMN-888: Registration Orchestrator (In Progress) - OMN-889: Registration Reducer (In Review) - OMN-890: Registry Effect (Done) * docs: address PR #56 review feedback Fix all 9 review issues from coderabbitai and Claude reviews: DESIGN_TWO_WAY_REGISTRATION_ARCHITECTURE.md (v2.1.1): - Clarify orchestrator's state-reading path (Section 8.1) - Add RuntimeTick cross-reference for timeout handling (Section 8.2) - Cross-link testing requirements to G1-G5 tickets (Section 12) ONEX_RUNTIME_REGISTRATION_TICKET_PLAN.md: - Clarify F0 ↔ B2 projector invocation sequence - Add explicit domain derivation rule for B1a - Clarify constraint 6 (versioned directories) with legacy migration note HANDOFF_TWO_WAY_REGISTRATION_REFACTOR.md: - Fix /workspace/omnibase_infra3/ paths to relative paths - Add "Decisions Required Before Phase 1" subsection - Add import paths for base classes in dependencies * docs: add decision process and import paths to handoff doc Address remaining PR #56 review feedback: - Section 7: Add expanded import paths with base classes, intent models, runtime, and SPI protocols - Section 7: Add version requirements (omnibase_core >= 0.5.0, omnibase_spi >= 0.4.0) - Section 7: Add expected method signatures for NodeRuntime and intent handlers - Section 9: Rename to "Open Questions and Decision Process" - Section 9.1: Add RACI matrix for blocking decisions with target dates - Section 9.2: Organize deferrable questions subsection * docs: clarify omnibase_core 0.5.x version requirements in handoff Address PR #56 review feedback (CodeRabbit critical issue): - Add prominent warning that refactor requires omnibase_core >= 0.5.0 - Add release status noting 0.5.3 is imminent (PR #216) - Update dependency table to show "Requires 0.5.x" status - Rename "Import Paths" to "Target Import Paths" with version notes - Add warning about legacy classes (NodeEffectLegacy, etc.) * docs: add parallelizable execution plan for ONEX Runtime tickets Wave-based execution plan mapping 31 tickets across 7 waves for maximum parallelization using 5 omnibase_core + 4 omnibase_infra repos. Includes: - Complete ticket code → Linear ID mapping (A1→OMN-931, B1→OMN-934, etc.) - 7 execution waves with dependency constraints - Critical path identification - Quick reference tables with Linear links * docs: add OMN-959 blocker ticket to parallel execution plan Created from PR #56 CodeRabbit review feedback identifying omnibase-core version dependency as prerequisite for Wave 1. * docs: enhance ticket plan with sequence diagrams, terminology, and test requirements - Add OMN-959 blocker reference to ticket plan header - Add terminology mapping (Node/Handler/Runtime) to global constraints - Add Pattern Validator specific test case names to A2 - Add canonical envelope principle and plane usage to A2a - Add F0 sequence diagram showing Orchestrator->Reducer->Effect flow - Clarify B2/F0 relationship for projection persistence - Update handoff and design docs with additional context * docs: address all PR #56 review feedback (critical/major/minor/nitpick) CRITICAL fixes: - Add BLOCKER notice for omnibase_core 0.5.x dependency requirement - Update all NEW component structures to use flat directories (no v1_0_0) - Add projection vs event publishing distinction (persist to storage vs publish to Kafka) - Mark existing v1_0_0 directories as LEGACY with H1 migration reference MAJOR fixes: - Add Phase 1 dependency verification as [GATE] Task 1 - Add pre-implementation meeting requirements with decision checklist - Add RACI matrix placeholder format for names/dates assignment - Add explicit escalation timeline for contingency plan (Day 0 → Day 7+) - Verify A2a envelope canonicality and handler terminology in Global Constraint #7 - Add error sanitization acceptance criteria to E1 with CLAUDE.md references MINOR fixes: - Add F0 ↔ B2 interaction sequence diagram (projector before intent publish) - Add end-to-end orchestrator → reducer → effect flow diagram - Add F0 failure handling documentation (projector fails → no intent → DLQ) - Add B6 RuntimeTick configuration details (env var, min/max values) - Add pattern validator test requirements with known-bad test case names - Add circuit breaker and correlation ID acceptance criteria to E1 - Add comprehensive domain derivation examples (valid/invalid) to B1a - Add H1 v1_0_0 cutover strategy with deprecation milestones - Add G5a property-based testing sub-ticket - Add target import paths section labeled as post-0.5.x NITPICK fixes: - Add orchestrator state-reading invariant (projections only) - Add timeout handling details (RuntimeTick cadence, emitted_at markers) - Add concrete test examples for G1-G4 - Add "Requires 0.5.x" to all base class dependencies - Add timeline risk factor for decision resolution delay - Add PEP 604 type annotation convention note - Add B3 and E1 idempotency key strategies CLAUDE.md updates: - Add "NO VERSIONED DIRECTORIES" critical policy section - Update node structure pattern to show canonical (flat) vs legacy (v1_0_0) - Update registry naming conventions to reference flat structure * docs: add minor enhancements for visualization, migration coordination, and future work Ticket Dependency Visualization: - Add Mermaid diagram with 8 subgraphs (A-H sections) - OMN-959 blocker highlighted with red styling - Cross-section dependencies visualized - Original text reference preserved Migration Coordination: - Add explicit H1 → OMN-959 dependency (BLOCKING) - Add H1a Migration Validation Gate ticket - Update dependency chain: OMN-959 → H1 → H1a → H2 Decision Process Timeline: - Add escalation path with day thresholds (1-2, 3-4, 5+ days) - Add default decisions as fallback for escalation - Add Wave 2 impact guidance for blocked decisions - Reference escalation path from timeline section Future Work Recommendations: - Add contract generation tooling validation tasks - Add performance benchmarking recommendations - Add documentation verification notes - Add additional testing patterns (chaos, load, fault injection) * docs: address PR #56 review feedback (all categories) - Add ADR placeholder references for blocking decisions (Command Source, Intent Topics, Reducer Invocation) - Add parallel execution plan with 6 waves including Wave 6 for H1 migration - Enhance E1 acceptance criteria with circuit breaker, error sanitization, and correlation ID requirements - Add cross-domain subscription configuration to B1a - Add concrete test examples for G1, G2, G3, G4 test tickets - Add Documentation Deliverables section with ADR, runbook, and migration guide references - Add stakeholder communication section for PR #52 disposition - Add feature flags and rollback strategy to H1 migration ticket - Add timeline assumptions and visualization notes sections - Enhance Target Import Paths with legacy class migration path - Add registry naming conventions appendix * docs: address PR #56 release-ready review (critical through nitpick) CRITICAL: - Add prominent BLOCKER notice with structured table format - Clarify projection persistence vs event publishing distinction - Add single envelope principle per architectural plane (A2a) - Add F0 terminology clarification section MAJOR: - Mark Section 9.1 open questions as CRITICAL blockers - Add Phase 1 Task 0 GATE for dependency verification - Complete RACI matrix with Tech Lead placeholders - Add pre-implementation meeting scheduling requirements - Add error sanitization references to E1 acceptance criteria - Enhance H1 blocking dependency on OMN-959 - Add performance benchmarking targets - Align ADR cross-references between documents MINOR: - Fix file path references to absolute paths - Add stakeholder communication plan for PR #52 rejection - Enhance escalation timeline with templates - Add domain derivation rule examples (B1a) - Add RuntimeTick configuration documentation (B6) - Add circuit breaker and correlation ID requirements NITPICK: - Add ProtocolProjectionReader clarification - Add base class version requirements table - Add ticket dependency visualization notes - Add versioning policy for design documents Cross-document consistency: - Align version references between HANDOFF and TICKET_PLAN - Add terminology alignment notes (Global Constraint #7) - Update DESIGN doc with cross-references * docs: address PR #56 release-ready review round 2 (all categories) HANDOFF Document: - Add RACI matrix template header clarifying placeholder values - Add decision timeline guidance (T-10 to T-0 days) - Add testing acceptance criteria formatting to Section 8 - Verify version references are consistent (Design 2.1.2) Ticket Plan Document (version 1.0.0 -> 1.1.0): - Add A2a envelope clarification (ONE ModelEnvelope for ALL planes) - Add H1 explicit BLOCKER notice for OMN-959 - Add E1 circuit breaker thread safety test requirements - Update test directory structure (tests/unit/, tests/integration/) - Expand H1a migration validation gate (pre/during/post phases) - Add A2a contract validation cross-reference to test sections - Add mermaid diagram OMN-959 red styling explanation All critical, major, minor, and nitpick issues addressed. * docs: address PR #56 release-ready review round 3 (all categories) CRITICAL fixes: - Fix version cross-references (1.0.0 → 1.1.0 in design doc) - Verify blocker warnings prominent - Clarify projection persistence vs event publishing MAJOR fixes: - Enhance RACI matrix with template population guidance - Add decision owners assignment requirement - Add target dates to blocking questions - Enhance escalation path with Wave 2 impact mitigation - Mark Phase 1 Task 0 as CRITICAL DEPENDENCY GATE - Enhance pre-implementation meeting requirements MINOR fixes: - Change absolute paths to relative paths for portability - Add ADR requirements with section references - Add operator runbook reference - Add developer migration guide reference - Expand domain derivation examples (24 valid, 8 invalid) - Document RuntimeTick configuration NITPICK fixes: - Clarify orchestrator state-reading path (5-step process) - Add timeout handling references - Enhance testing tables with inline acceptance criteria - Add base class version dependency table - Clarify versioning policy (MAJOR/MINOR/PATCH) - Add test structure examples with pytest code - Update timeline assumptions with escalation reference - Add ticket dependency visualization guidance
…ce creation Implement contract dependency materialization that reads contract.dependencies declarations and auto-creates live DI providers (asyncpg pools, Kafka producers, HTTP clients) without domain-specific boot code. New files: - DependencyMaterializer: scans contracts, creates shared resources via providers - Provider factories: ProviderPostgresPool, ProviderKafkaProducer, ProviderHttpClient - Config models (1 per file): postgres, kafka, http, materializer - EnumInfraResourceType: postgres_pool, kafka_producer, http_client - ModelMaterializedResources: immutable result container Key behaviors: - Resources deduplicated by type (one pool per connection config) - Required deps fail-fast; optional deps log + skip (Kafka optional per arch #7) - Lifecycle: created at startup, closed in reverse order at shutdown - 32 unit tests covering collection, materialization, deduplication, shutdown
…ce creation (#255) * feat(OMN-1976): Add DependencyMaterializer for contract-driven resource creation Implement contract dependency materialization that reads contract.dependencies declarations and auto-creates live DI providers (asyncpg pools, Kafka producers, HTTP clients) without domain-specific boot code. New files: - DependencyMaterializer: scans contracts, creates shared resources via providers - Provider factories: ProviderPostgresPool, ProviderKafkaProducer, ProviderHttpClient - Config models (1 per file): postgres, kafka, http, materializer - EnumInfraResourceType: postgres_pool, kafka_producer, http_client - ModelMaterializedResources: immutable result container Key behaviors: - Resources deduplicated by type (one pool per connection config) - Required deps fail-fast; optional deps log + skip (Kafka optional per arch #7) - Lifecycle: created at startup, closed in reverse order at shutdown - 32 unit tests covering collection, materialization, deduplication, shutdown * fix(review): [critical+major+minor] Security and concurrency fixes for DependencyMaterializer - Fixed: model_postgres_pool_config.py:26 - Password field now repr=False to prevent credential exposure in logs/repr - Fixed: provider_postgres_pool.py:55 - Use individual kwargs instead of DSN string to prevent credential leaks in tracebacks - Fixed: dependency_materializer.py:84 - Replace threading.Lock with asyncio.Lock to avoid blocking event loop - Fixed: dependency_materializer.py:163 - Narrow exception handling: ProtocolConfigurationError propagates directly, catch (OSError, TimeoutError) for infra failures - Fixed: dependency_materializer.py:310 - Replace ValueError with ProtocolConfigurationError per error hierarchy - Fixed: model_postgres_pool_config.py:26 - Added documentation warning for empty password field Review iteration: 1/10 * fix(review): [critical+major+minor] Race condition, env validation, and config hardening - Fixed: model_postgres_pool_config.py:49 - Removed unused dsn property that exposed password in plaintext - Fixed: dependency_materializer.py:138 - Eliminated TOCTOU race condition by holding asyncio.Lock for entire materialize loop - Fixed: model_postgres_pool_config.py:40 - Added try/except for env var int() parsing with clear error messages - Fixed: model_kafka_producer_config.py:43 - Same env var validation for float() parsing - Fixed: model_http_client_config.py:35 - Same env var validation for float() parsing - Fixed: All config models - Added from_attributes=True per CLAUDE.md Pydantic standards - Fixed: model_http_client_config.py:36 - Boolean env var parsing now accepts true/1/yes/on - Fixed: dependency_materializer.py:198 - Shutdown now falls back to _resource_by_type if _creation_order misses entries Review iteration: 2/10 * fix(review): [major+minor] Shutdown safety, pool size validation, exception narrowing - Fixed: dependency_materializer.py:198 - Shutdown now holds lock for entire close sequence, preventing races with concurrent materialize() - Fixed: model_postgres_pool_config.py:32 - Added model_validator ensuring min_size <= max_size - Fixed: dependency_materializer.py:251 - Narrowed _collect_infra_deps exception to (OSError, YAMLError, ProtocolConfigurationError) - Fixed: All config models - Sanitized error messages to use generic names instead of env var prefixes Review iteration: 3/10 * fix(review): [minor] Exception coverage and dependency conflict detection - Fixed: dependency_materializer.py:167 - Exception handling now catches library-specific errors (KafkaConnectionError, asyncpg.PostgresError) while letting programming bugs (TypeError, AttributeError, ImportError) propagate - Fixed: dependency_materializer.py:279 - Duplicate dependency names with conflicting types now log a warning Review iteration: 4/10 * fix(review): [minor] Acks type safety, __init__ exports, ConfigDict, and conflict detection - Use EnumKafkaAcks instead of raw str for acks field in ModelKafkaProducerConfig, call .to_aiokafka() in ProviderKafkaProducer to prevent ValueError with numeric acks - Add from_attributes=True to ModelMaterializedResources ConfigDict per project standard - Re-export 5 new models in runtime/models/__init__.py and DependencyMaterializer in runtime/__init__.py per project convention - Raise ProtocolConfigurationError on conflicting resource types for same dependency name instead of silently using first declaration - Add test_collect_raises_on_conflicting_types test Review iteration: 1/10 * fix(review): [critical+major+minor] PR #255 review fixes and test coverage - Fixed: dependency_materializer.py:167 - ImportError no longer blocks optional dep skip - Fixed: dependency_materializer.py - correlation_id threaded through all error contexts - Fixed: provider_kafka_producer.py:65 - try/except with best-effort cleanup on timeout - Added: docstrings across 7 files to meet 80% coverage threshold - Added: test for pool size bounds validator (_check_pool_size_bounds) - Added: tests for invalid env var parsing in from_env() methods - Added: test for Kafka producer timeout cleanup path Review iteration: 1/10 * fix(review): [major+minor] Error sanitization, close ordering, YAML size limit, test coverage Major fixes: - Sanitize exception messages to prevent credential leaks (M2) - Register close funcs after successful resource creation (M3) - Add YAML file size limit check consistent with HandlerPluginLoader (M4) Minor fixes: - Add warning log for non-dict YAML parsing (m7) - Fix version placeholder in ModelMaterializedResources (m9) Test coverage additions (11 new tests, 36 -> 47): - ModelHttpClientConfig.from_env() and invalid env values - ModelMaterializerConfig.from_env() aggregation - Non-dict dependency entries, missing name, non-dict YAML, empty YAML - Oversized contract rejection and skip behavior - Shutdown reverse-order verification - Failed create leaves no stale close function * feat(OMN-1976): Integrate DependencyMaterializer into RuntimeHostProcess lifecycle (r4) Wires the DependencyMaterializer into the runtime boot/shutdown sequence: Startup (start()): - Step 3.5: After contract discovery, before handler population - Creates shared infrastructure resources from contract.dependencies - Materialized resources merged into ModelResolvedDependencies for handlers Shutdown (stop()): - Step 2.4: After handler shutdown, before event bus close - Closes all materialized resources in reverse creation order Handler integration: - _resolve_handler_dependencies() merges materialized infra resources (postgres_pool, kafka_producer, http_client) alongside protocol deps - Handlers access both via resolved.get("pattern_store") etc. Tests (5 new, 52 total for materializer): - Full materialize-then-shutdown lifecycle - Materialized resources merge into ModelResolvedDependencies - No-op behavior without contract_paths - Idempotent shutdown
Update docstrings and documentation that referenced the old architecture constraint #7 ("Kafka is optional") to reference platform-wide rule #8 ("Kafka is required infrastructure"). Also add token documentation to CI handshake workflow. - provider_kafka_producer.py: rule #7 → rule #8 - event_bus_kafka.py: "graceful degradation" → "resilience against transient failures" - EVENT_BUS_OPERATIONS_RUNBOOK.md: same pattern - check-handshake.yml: document OMNIBASE_CORE_TOKEN requirement
* feat(OMN-2084): Add CI handshake enforcement workflow Add check-handshake.yml workflow that verifies the installed architecture handshake matches the omnibase_core source on push/PR to main. Follows the same pattern as omnibase_spi. Also refreshes the stale handshake to match omnibase_core v0.16.0. * fix(OMN-2084): Align Kafka references with platform-wide rule #8 Update docstrings and documentation that referenced the old architecture constraint #7 ("Kafka is optional") to reference platform-wide rule #8 ("Kafka is required infrastructure"). Also add token documentation to CI handshake workflow. - provider_kafka_producer.py: rule #7 → rule #8 - event_bus_kafka.py: "graceful degradation" → "resilience against transient failures" - EVENT_BUS_OPERATIONS_RUNBOOK.md: same pattern - check-handshake.yml: document OMNIBASE_CORE_TOKEN requirement * fix(OMN-2084): Align docstrings and docs with Kafka-required rule #8 - Remove stale "degraded mode" language from EventBusKafka.start() docstring - Clarify ProviderKafkaProducer propagates creation failures (required infra) - Enhance CI workflow checkout verify step with diagnostics - Add override note to runbook KAFKA_BOOTSTRAP_SERVERS default - Add ADR documenting Kafka-optional → Kafka-required policy reversal Review iteration: 1/10
Add migration-complete sentinel to prevent runtime services from starting before all forward migrations have been applied. Fixes the race where omniintelligence stamps a schema fingerprint before all tables exist (Audit Gap #7). - Add migration 037: adds migrations_complete column to db_metadata - Add check_migrations_complete.sh healthcheck script - Add migration-gate docker-compose service (runtime profile) - Update runtime services to depend on migration-gate instead of postgres - Add 14 unit tests validating sentinel, script, and compose integration
* feat(infra): add boot-order migration sentinel (OMN-3737) Add migration-complete sentinel to prevent runtime services from starting before all forward migrations have been applied. Fixes the race where omniintelligence stamps a schema fingerprint before all tables exist (Audit Gap #7). - Add migration 037: adds migrations_complete column to db_metadata - Add check_migrations_complete.sh healthcheck script - Add migration-gate docker-compose service (runtime profile) - Update runtime services to depend on migration-gate instead of postgres - Add 14 unit tests validating sentinel, script, and compose integration * fix(ci): ruff lint + schema fingerprint for OMN-3737 - Replace os.stat() with Path.stat() (PTH116) - Remove unused os import - Regenerate schema_fingerprint.sha256 for 23 migrations * fix(ci): increase migration-gate healthcheck interval to 10s (OMN-3737) The CI test_health_check_intervals_reasonable asserts all healthcheck intervals are >= 10s. The migration-gate sentinel had interval: 5s which tripped this assertion. Increase to 10s with 30 retries (still 5 min total window) and start_period 10s.
…-9034] Extracts audit logic from inline python3 HEREDOCs in the shell script into a testable Python lib so Check A / Check B / fix-payload can be exercised with dependency injection instead of bash-subprocess mocking that never worked. Thread-by-thread: - #1-5 (CodeQL unused locals): removed. The old tests created variables like `protection`, `commits_data`, `check_runs_data` and never asserted on them. New tests assert on audit_repo() return values directly. - #6 (cross-repo PAT): workflow now uses `secrets.CROSS_REPO_PAT || secrets.GITHUB_TOKEN` (matches env-parity.yml pattern) + preflight check step with ::warning:: when absent. Without the PAT, 9 sibling repos will [SKIP] — documented in workflow header. - #7 (pagination per_page=50): lib.PAGE_SIZE = 100 (GitHub API max). collect_seen_check_run_names now paginates until empty or short page. - #8 (mock doesn't intercept bash): audit logic lives in scripts/audit_branch_protection_lib.py with a GhCaller injection seam. Tests import the lib and pass fake `gh` callables — no subprocesses at unit-test time. - #9 (hardcoded /Volumes in test_rac_violation_detected): entire test removed as part of rewrite; no more subprocess.run + cwd=... - #10 (smoke-test returncode in (0,1)): new tests assert on explicit status/rac/orphan_contexts/message fields, not returncodes. Lib surface: parse_required_approving_review_count(protection_json) -> int parse_required_contexts(protection_json) -> list[str] build_fix_payload(protection_json) -> dict collect_seen_check_run_names(owner, repo, commits, gh) -> set[str] find_orphan_contexts(required, seen) -> list[str] audit_repo(owner, repo, gh, commits_to_scan=5) -> dict Shell script calls scripts/audit_branch_protection_lib_cli.py for the audit step and the --fix payload construction; the `gh api PUT` side effect stays in bash. Verification: uv run pytest tests/ci/test_branch_protection_audit.py -v = 19 passed in 0.19s shellcheck scripts/audit-branch-protection.sh = clean bash -n scripts/audit-branch-protection.sh = syntax ok uv run mypy scripts/audit_branch_protection_lib*.py = Success CI-matching pytest (split 1/15, -m "not slow and not chaos and not kafka") = 1346 passed, 2 env-dependent Postgres failures (no local Postgres)
* fix(ci): branch-protection-audit gate (OMN-9034) Adds periodic CI audit of branch protection settings across all OmniNode-ai repos. Catches two invariants that caused overnight failures: (A) non-zero required_approving_review_count that blocks the solo-dev merge workflow, and (B) orphaned required status check contexts that no CI job ever satisfies. - scripts/audit-branch-protection.sh — shellcheck-clean, MIT SPDX, --dry-run default, --fix mode for automated remediation - tests/ci/test_branch_protection_audit.py — 11 unit tests (pytest.mark.unit) covering clean/rac-violation/orphan-context/fix-mutation cases - .github/workflows/branch-protection-audit.yml — schedule 23 */4 * * * + workflow_dispatch; fails workflow on any violation (report-only, no --fix) - CLAUDE.md: ## Branch protection section documenting dry-run gate rule * fix(tests): remove hardcoded /Volumes path in test_clean_repo [OMN-9034] CI Split 1/15 failed with FileNotFoundError on '/Volumes/PRO-G40/Code/omni_worktrees/OMN-BP-AUDIT/omnibase_infra' because the prior commit baked the author's local worktree path into the test's subprocess cwd. Fix: resolve script + cwd relative to the test file via Path(__file__).resolve().parents[2], matching the pattern required by CLAUDE.md Rule 6 (no hardcoded absolute paths). Verified locally: uv run pytest tests/ci/test_branch_protection_audit.py = 11 passed in 6.01s. * fix(ci): resolve 10 CR/CodeQL threads on branch-protection-audit [OMN-9034] Extracts audit logic from inline python3 HEREDOCs in the shell script into a testable Python lib so Check A / Check B / fix-payload can be exercised with dependency injection instead of bash-subprocess mocking that never worked. Thread-by-thread: - #1-5 (CodeQL unused locals): removed. The old tests created variables like `protection`, `commits_data`, `check_runs_data` and never asserted on them. New tests assert on audit_repo() return values directly. - #6 (cross-repo PAT): workflow now uses `secrets.CROSS_REPO_PAT || secrets.GITHUB_TOKEN` (matches env-parity.yml pattern) + preflight check step with ::warning:: when absent. Without the PAT, 9 sibling repos will [SKIP] — documented in workflow header. - #7 (pagination per_page=50): lib.PAGE_SIZE = 100 (GitHub API max). collect_seen_check_run_names now paginates until empty or short page. - #8 (mock doesn't intercept bash): audit logic lives in scripts/audit_branch_protection_lib.py with a GhCaller injection seam. Tests import the lib and pass fake `gh` callables — no subprocesses at unit-test time. - #9 (hardcoded /Volumes in test_rac_violation_detected): entire test removed as part of rewrite; no more subprocess.run + cwd=... - #10 (smoke-test returncode in (0,1)): new tests assert on explicit status/rac/orphan_contexts/message fields, not returncodes. Lib surface: parse_required_approving_review_count(protection_json) -> int parse_required_contexts(protection_json) -> list[str] build_fix_payload(protection_json) -> dict collect_seen_check_run_names(owner, repo, commits, gh) -> set[str] find_orphan_contexts(required, seen) -> list[str] audit_repo(owner, repo, gh, commits_to_scan=5) -> dict Shell script calls scripts/audit_branch_protection_lib_cli.py for the audit step and the --fix payload construction; the `gh api PUT` side effect stays in bash. Verification: uv run pytest tests/ci/test_branch_protection_audit.py -v = 19 passed in 0.19s shellcheck scripts/audit-branch-protection.sh = clean bash -n scripts/audit-branch-protection.sh = syntax ok uv run mypy scripts/audit_branch_protection_lib*.py = Success CI-matching pytest (split 1/15, -m "not slow and not chaos and not kafka") = 1346 passed, 2 env-dependent Postgres failures (no local Postgres) --------- Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
* docs(OMN-9727): F2 — market node deployment runbook + gap inventory Documents the 7-phase path from omnimarket PR merge to consumer group subscription. Identifies 7 gaps; highest-leverage gap (deploy-agent probes wrong health ports 8000/8001 vs 8085/8086) filed as OMN-9728. dod_evidence: - file_exists: docs/runbooks/market-node-deployment.md - gap-closure ticket: OMN-9728 (.onex_state/f2-gap-closure-ticket.txt) * docs(OMN-9727): remove local paths + dod_evidence from runbook; use env-var refs Address hostile_reviewer findings OmniNode-ai#6 and OmniNode-ai#7: - Replace hardcoded IP/username in manual path with env-var references (INFRA_HOST, INFRA_USER, KAFKA_BOOTSTRAP_SERVERS from ~/.omnibase/.env) - Remove ephemeral dod_evidence block (local worktree paths) from permanent file * docs(OMN-9727): add language tags to fenced code blocks (MD040) Add explicit language tags (text/bash) to 3 unlabeled fenced code blocks flagged by markdownlint MD040 in market-node-deployment.md. * chore: trigger CI recheck after resolving CodeRabbit threads [OMN-9727] --------- Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
… infra per layering) (OmniNode-ai#1418) * feat(OMN-9755): concrete SPI default handler-contract loader in infra Moves file I/O to omnibase_infra per CLAUDE.md layering rule OmniNode-ai#7 (compat → core → spi → infra). YAML data files remain in omnibase_spi/contracts/defaults/ (declarative data, no I/O). Loader reads YAML via importlib.resources from the installed omnibase_spi package; ModelHandlerContract.model_validate() converts raw dict to typed contract. TemplateNotFoundError / TemplateParseError from omnibase_spi.exceptions propagate unchanged. Closes the purity violation in PR omnibase_spi#198 (closed in favor of this split). * test(OMN-9755): add integration test for SPI default contract loader Integration Test Coverage gate (hard since 2026-04-13) requires a file under tests/integration/. Adds 5 @pytest.mark.integration tests exercising the real importlib.resources package-read path against installed omnibase_spi. Closes OMN-9755. --------- Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
Summary
Complete Hook Node implementation with omnibase_spi protocol integration and production-ready Slack webhook functionality.
Key Changes
🔧 Protocol Integration
omnibase_spiprotocolsProtocolHttpClientandProtocolHttpResponsefromomnibase_spi.protocols.coreProtocolEventBusfromomnibase_spi.protocols.event_busEnumAuthType.BEARERinstead of string literalsEnumBackoffStrategy.EXPONENTIALfor retry policiesModelONEXContainerusage and import paths🔒 Security Implementation
🚀 Production Features
🧪 Testing & Validation
🏗️ ONEX Architecture Compliance
🔄 CI/CD Integration
Test Results
✅ Integration Testing
✅ Real-World Validation
Production Readiness
The Hook Node is now production-ready for:
Files Changed
Core Implementation
src/omnibase_infra/nodes/hook_node/v1_0_0/node.pysrc/omnibase_infra/nodes/hook_node/v1_0_0/registry/registry_hook_node.pysrc/omnibase_infra/nodes/hook_node/v1_0_0/contract.yamlModels & Configuration
src/omnibase_infra/models/notification/model_notification_*.pysrc/omnibase_infra/models/slack/model_slack_*.pysrc/omnibase_infra/enums/enum_slack_*.pysrc/omnibase_infra/integrations/slack_webhook_config.pyTesting & Validation
tests/integration/test_hook_node_integration.pytests/unit/test_hook_node.pytests/e2e/test_real_hook_node.pytests/models/test_webhook_models.pyCI/CD & Infrastructure
.github/workflows/quality-checks.ymlsrc/omnibase_infra/infrastructure/container.pyNext Steps
Hook Node Phase 1 is complete. Ready for infrastructure integration:
Compliance ✅