Repository navigation
feat: archive legacy documentation and code patterns (286 files) - #9
Closed
jonahgabriel wants to merge 1 commit into
Closed
jonahgabriel wants to merge 1 commit into
jonahgabriel wants to merge 1 commit into
Conversation
Archive 235 files to improve repository maintainability: - Legacy documentation files (README.md, templates, guides) - Deprecated infrastructure components and patterns - Outdated docker configurations and deployment files - Legacy database migrations and scripts - Archived testing and integration files This cleanup reduces the main codebase surface area and improves focus on current ONEX standards and architecture patterns. Organized in archive/ directory for historical reference. Files can be restored if needed for legacy compatibility.
Contributor
|
Code Review - Archive Cleanup PR #9 Overall Assessment: APPROVED This PR successfully archives 286 legacy files to improve maintainability and prepare for model migration. Reduces main PR from 473 to 187 files (60% reduction). STRENGTHS:
AREAS TO ADDRESS:
SECURITY REVIEW:
ACTION ITEMS:
Ready to merge after addressing archive README. Great work on reducing complexity! |
5 tasks done
jonahgabriel
added a commit
that referenced
this pull request
Apr 17, 2026
…-9034] Extracts audit logic from inline python3 HEREDOCs in the shell script into a testable Python lib so Check A / Check B / fix-payload can be exercised with dependency injection instead of bash-subprocess mocking that never worked. Thread-by-thread: - #1-5 (CodeQL unused locals): removed. The old tests created variables like `protection`, `commits_data`, `check_runs_data` and never asserted on them. New tests assert on audit_repo() return values directly. - #6 (cross-repo PAT): workflow now uses `secrets.CROSS_REPO_PAT || secrets.GITHUB_TOKEN` (matches env-parity.yml pattern) + preflight check step with ::warning:: when absent. Without the PAT, 9 sibling repos will [SKIP] — documented in workflow header. - #7 (pagination per_page=50): lib.PAGE_SIZE = 100 (GitHub API max). collect_seen_check_run_names now paginates until empty or short page. - #8 (mock doesn't intercept bash): audit logic lives in scripts/audit_branch_protection_lib.py with a GhCaller injection seam. Tests import the lib and pass fake `gh` callables — no subprocesses at unit-test time. - #9 (hardcoded /Volumes in test_rac_violation_detected): entire test removed as part of rewrite; no more subprocess.run + cwd=... - #10 (smoke-test returncode in (0,1)): new tests assert on explicit status/rac/orphan_contexts/message fields, not returncodes. Lib surface: parse_required_approving_review_count(protection_json) -> int parse_required_contexts(protection_json) -> list[str] build_fix_payload(protection_json) -> dict collect_seen_check_run_names(owner, repo, commits, gh) -> set[str] find_orphan_contexts(required, seen) -> list[str] audit_repo(owner, repo, gh, commits_to_scan=5) -> dict Shell script calls scripts/audit_branch_protection_lib_cli.py for the audit step and the --fix payload construction; the `gh api PUT` side effect stays in bash. Verification: uv run pytest tests/ci/test_branch_protection_audit.py -v = 19 passed in 0.19s shellcheck scripts/audit-branch-protection.sh = clean bash -n scripts/audit-branch-protection.sh = syntax ok uv run mypy scripts/audit_branch_protection_lib*.py = Success CI-matching pytest (split 1/15, -m "not slow and not chaos and not kafka") = 1346 passed, 2 env-dependent Postgres failures (no local Postgres)
github-merge-queue Bot
pushed a commit
that referenced
this pull request
Apr 17, 2026
* fix(ci): branch-protection-audit gate (OMN-9034) Adds periodic CI audit of branch protection settings across all OmniNode-ai repos. Catches two invariants that caused overnight failures: (A) non-zero required_approving_review_count that blocks the solo-dev merge workflow, and (B) orphaned required status check contexts that no CI job ever satisfies. - scripts/audit-branch-protection.sh — shellcheck-clean, MIT SPDX, --dry-run default, --fix mode for automated remediation - tests/ci/test_branch_protection_audit.py — 11 unit tests (pytest.mark.unit) covering clean/rac-violation/orphan-context/fix-mutation cases - .github/workflows/branch-protection-audit.yml — schedule 23 */4 * * * + workflow_dispatch; fails workflow on any violation (report-only, no --fix) - CLAUDE.md: ## Branch protection section documenting dry-run gate rule * fix(tests): remove hardcoded /Volumes path in test_clean_repo [OMN-9034] CI Split 1/15 failed with FileNotFoundError on '/Volumes/PRO-G40/Code/omni_worktrees/OMN-BP-AUDIT/omnibase_infra' because the prior commit baked the author's local worktree path into the test's subprocess cwd. Fix: resolve script + cwd relative to the test file via Path(__file__).resolve().parents[2], matching the pattern required by CLAUDE.md Rule 6 (no hardcoded absolute paths). Verified locally: uv run pytest tests/ci/test_branch_protection_audit.py = 11 passed in 6.01s. * fix(ci): resolve 10 CR/CodeQL threads on branch-protection-audit [OMN-9034] Extracts audit logic from inline python3 HEREDOCs in the shell script into a testable Python lib so Check A / Check B / fix-payload can be exercised with dependency injection instead of bash-subprocess mocking that never worked. Thread-by-thread: - #1-5 (CodeQL unused locals): removed. The old tests created variables like `protection`, `commits_data`, `check_runs_data` and never asserted on them. New tests assert on audit_repo() return values directly. - #6 (cross-repo PAT): workflow now uses `secrets.CROSS_REPO_PAT || secrets.GITHUB_TOKEN` (matches env-parity.yml pattern) + preflight check step with ::warning:: when absent. Without the PAT, 9 sibling repos will [SKIP] — documented in workflow header. - #7 (pagination per_page=50): lib.PAGE_SIZE = 100 (GitHub API max). collect_seen_check_run_names now paginates until empty or short page. - #8 (mock doesn't intercept bash): audit logic lives in scripts/audit_branch_protection_lib.py with a GhCaller injection seam. Tests import the lib and pass fake `gh` callables — no subprocesses at unit-test time. - #9 (hardcoded /Volumes in test_rac_violation_detected): entire test removed as part of rewrite; no more subprocess.run + cwd=... - #10 (smoke-test returncode in (0,1)): new tests assert on explicit status/rac/orphan_contexts/message fields, not returncodes. Lib surface: parse_required_approving_review_count(protection_json) -> int parse_required_contexts(protection_json) -> list[str] build_fix_payload(protection_json) -> dict collect_seen_check_run_names(owner, repo, commits, gh) -> set[str] find_orphan_contexts(required, seen) -> list[str] audit_repo(owner, repo, gh, commits_to_scan=5) -> dict Shell script calls scripts/audit_branch_protection_lib_cli.py for the audit step and the --fix payload construction; the `gh api PUT` side effect stays in bash. Verification: uv run pytest tests/ci/test_branch_protection_audit.py -v = 19 passed in 0.19s shellcheck scripts/audit-branch-protection.sh = clean bash -n scripts/audit-branch-protection.sh = syntax ok uv run mypy scripts/audit_branch_protection_lib*.py = Success CI-matching pytest (split 1/15, -m "not slow and not chaos and not kafka") = 1346 passed, 2 env-dependent Postgres failures (no local Postgres) --------- Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
jonahgabriel
added a commit
that referenced
this pull request
May 18, 2026
…ecutor - gate/__init__.py: switch to eager top-level imports so __all__ names are statically visible to CodeQL (closes CodeQL "explicit export not defined" findings 1-8). Eager imports are fine here because the stacked-core branch dependency is now satisfied by the pinned PR #1088 head SHA, removing the need for lazy loading. - gate/signer.py: gate `AbstractContextManager` import behind TYPE_CHECKING so CodeQL stops flagging it as unused while keeping the runtime-string cast valid (closes CodeQL "unused import" #9). - gate/executor.py: add `redact_if_secret_bearing()` public helper so the validator path can scrub secret-bearing strings. - gate/validator_registry.py: redact secret-bearing previews before writing them to receipts; drop raw exception text in failure receipts in favor of the exception class name (closes CR threads 13, 14). - gate/action_verify.py: drop raw exception text from decision reasons and add a 10s timeout to `git cat-file` (closes CR threads 11, 12).
jonahgabriel
added a commit
that referenced
this pull request
May 20, 2026
* feat(gate): add omnigate check executor * feat(OMN-11143): add OmniGate Sigstore signer (#1630) * feat(OMN-11143): add OmniGate Sigstore signer * feat(OMN-11144): add OmniGate PR verifier action (#1631) Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com> --------- Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com> * test(OMN-11142): add integration coverage for OmniGate executor Adds tests/integration/gate/test_omnigate_executor_integration.py and pins omnibase-core to PR #1088 head SHA (OmniGate models) until that branch lands in a tagged release. The new integration test exercises the real bash -eo pipefail subprocess path, real stdout/stderr capture, real secret-pattern scanning, and the validator-registry composition path — none of which the unit suite covers because it patches subprocess.run. Pin will revert to a tagged omnibase-core release after PR #1088 merges. * fix(OMN-11142): resolve CodeRabbit and CodeQL findings on OmniGate executor - gate/__init__.py: switch to eager top-level imports so __all__ names are statically visible to CodeQL (closes CodeQL "explicit export not defined" findings 1-8). Eager imports are fine here because the stacked-core branch dependency is now satisfied by the pinned PR #1088 head SHA, removing the need for lazy loading. - gate/signer.py: gate `AbstractContextManager` import behind TYPE_CHECKING so CodeQL stops flagging it as unused while keeping the runtime-string cast valid (closes CodeQL "unused import" #9). - gate/executor.py: add `redact_if_secret_bearing()` public helper so the validator path can scrub secret-bearing strings. - gate/validator_registry.py: redact secret-bearing previews before writing them to receipts; drop raw exception text in failure receipts in favor of the exception class name (closes CR threads 13, 14). - gate/action_verify.py: drop raw exception text from decision reasons and add a 10s timeout to `git cat-file` (closes CR threads 11, 12). * chore: retrigger receipt-gate with updated PR body (Evidence-Source: OCC#1121) * ci(OMN-11142): retrigger CI after transient runner network failures * fix(OMN-11142): remove redundant casts in OmniGate gate module mypy --strict flagged two [redundant-cast] errors in PR 1626: - signer.py: canonical_receipt_payload already returns bytes; cast removed. - validator_registry.py: EntryPoint.load() can be called directly without casting entry_point through EntryPoint first. Cleans up newly unused imports (EntryPoint, cast) in validator_registry. Evidence-Source: OCC#1121 Evidence-Ticket: OMN-11142 * fix(OMN-11142): use sigstore Bundle.from_json and advance core pin Replace removed sigstore.verify.VerificationMaterials with sigstore.models.Bundle.from_json (removed in sigstore>=4.0.0; the verify path would have raised KeyError at runtime). Update signer mocks to the new module path. Advance omnibase_core pin to a rev that ships the omnibase_core.gate module (receipt_canonical), which resolves the mypy no-any-return on serialize_for_signing and lets the gate unit tests import. Register the new gate module in the test-selection adjacency map so test_every_src_module_has_adjacency_entry passes. * test: allow omnigate validator callable protocol --------- Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
jonahgabriel
added a commit
that referenced
this pull request
May 20, 2026
* feat(gate): add omnigate check executor * feat(OMN-11143): add OmniGate Sigstore signer (#1630) * feat(OMN-11143): add OmniGate Sigstore signer * feat(OMN-11144): add OmniGate PR verifier action (#1631) Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com> --------- Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com> * test(OMN-11142): add integration coverage for OmniGate executor Adds tests/integration/gate/test_omnigate_executor_integration.py and pins omnibase-core to PR #1088 head SHA (OmniGate models) until that branch lands in a tagged release. The new integration test exercises the real bash -eo pipefail subprocess path, real stdout/stderr capture, real secret-pattern scanning, and the validator-registry composition path — none of which the unit suite covers because it patches subprocess.run. Pin will revert to a tagged omnibase-core release after PR #1088 merges. * fix(OMN-11142): resolve CodeRabbit and CodeQL findings on OmniGate executor - gate/__init__.py: switch to eager top-level imports so __all__ names are statically visible to CodeQL (closes CodeQL "explicit export not defined" findings 1-8). Eager imports are fine here because the stacked-core branch dependency is now satisfied by the pinned PR #1088 head SHA, removing the need for lazy loading. - gate/signer.py: gate `AbstractContextManager` import behind TYPE_CHECKING so CodeQL stops flagging it as unused while keeping the runtime-string cast valid (closes CodeQL "unused import" #9). - gate/executor.py: add `redact_if_secret_bearing()` public helper so the validator path can scrub secret-bearing strings. - gate/validator_registry.py: redact secret-bearing previews before writing them to receipts; drop raw exception text in failure receipts in favor of the exception class name (closes CR threads 13, 14). - gate/action_verify.py: drop raw exception text from decision reasons and add a 10s timeout to `git cat-file` (closes CR threads 11, 12). * chore: retrigger receipt-gate with updated PR body (Evidence-Source: OCC#1121) * ci(OMN-11142): retrigger CI after transient runner network failures * fix(OMN-11142): remove redundant casts in OmniGate gate module mypy --strict flagged two [redundant-cast] errors in PR 1626: - signer.py: canonical_receipt_payload already returns bytes; cast removed. - validator_registry.py: EntryPoint.load() can be called directly without casting entry_point through EntryPoint first. Cleans up newly unused imports (EntryPoint, cast) in validator_registry. Evidence-Source: OCC#1121 Evidence-Ticket: OMN-11142 * fix(OMN-11142): use sigstore Bundle.from_json and advance core pin Replace removed sigstore.verify.VerificationMaterials with sigstore.models.Bundle.from_json (removed in sigstore>=4.0.0; the verify path would have raised KeyError at runtime). Update signer mocks to the new module path. Advance omnibase_core pin to a rev that ships the omnibase_core.gate module (receipt_canonical), which resolves the mypy no-any-return on serialize_for_signing and lets the gate unit tests import. Register the new gate module in the test-selection adjacency map so test_every_src_module_has_adjacency_entry passes. * test: allow omnigate validator callable protocol --------- Co-authored-by: jonahgabriel <jonahgabriel@users.noreply.github.com>
2 of 4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🧹 Archive Cleanup - Phase 1 of Model Migration PR Split
PURPOSE: This PR reduces the model migration PR from 473 to ~187 files by archiving legacy content.
📊 Archive Summary
🗂️ Archive Categories
Legacy Documentation (57 files)
Deprecated Infrastructure (229 files)
🎯 Strategic Benefits
For Reviewers:
For Maintainability:
For Future Development:
🔄 Follow-up PRs
After this cleanup, the remaining model migration will be split into:
✅ Validation
This cleanup establishes the foundation for manageable, reviewable domain-specific PRs in the model migration effort.