Repository navigation
fix(OMN-18296): declare the delegation completion bound and make the client wait for it - #2510
Conversation
…client wait for it
✅ Hostile Reviewer — PASSEDBlocking findings (critical/error): 0 Gate semantics
Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8524) |
…nimarket#2510 The declared checks were executed for real in the OmniNode-ai/omnimarket checkout at the PR head by the product-repo OCC receipt runner, and the results written append-only into this companion. Producer-minted PENDING receipts are superseded by a net-new record; no existing receipt was edited. Ticket: OMN-16859 (AC3b)
|
No OCC evidence companion was minted for this PR. this PR is already bound to OCC#9332; its evidence companion exists and nothing needs authoring To clear this: Nothing to do — the companion already exists. Reported by |
✅ Architectural Review — PASSEDErrors: 0 What this checks
No architectural violations found. Static architectural lint — no model inference (OMN-14176). |
…2510 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 3861abc6dc7a2c99ea9701e47818d6e2b66f51f1.
…nimarket#2510 The declared checks were executed for real in the OmniNode-ai/omnimarket checkout at the PR head by the product-repo OCC receipt runner, and the results written append-only into this companion. Producer-minted PENDING receipts are superseded by a net-new record; no existing receipt was edited. Ticket: OMN-16859 (AC3b)
…imarket#2510 (#9332) * evidence(OMN-18296): author OCC companion for OmniNode-ai/omnimarket#2510 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 3861abc6dc7a2c99ea9701e47818d6e2b66f51f1. * evidence(OMN-18296): self-bind OCC#9332 + rebind contract_sha256 * evidence(OMN-16859): executed test_passes receipts for OmniNode-ai/omnimarket#2510 The declared checks were executed for real in the OmniNode-ai/omnimarket checkout at the PR head by the product-repo OCC receipt runner, and the results written append-only into this companion. Producer-minted PENDING receipts are superseded by a net-new record; no existing receipt was edited. Ticket: OMN-16859 (AC3b) --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> Co-authored-by: onexbot-occ-writer[bot] <onexbot-occ-writer[bot]@users.noreply.github.com>
…imarket#2510 (#9332) * evidence(OMN-18296): author OCC companion for OmniNode-ai/omnimarket#2510 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 3861abc6dc7a2c99ea9701e47818d6e2b66f51f1. * evidence(OMN-18296): self-bind OCC#9332 + rebind contract_sha256 * evidence(OMN-16859): executed test_passes receipts for OmniNode-ai/omnimarket#2510 The declared checks were executed for real in the OmniNode-ai/omnimarket checkout at the PR head by the product-repo OCC receipt runner, and the results written append-only into this companion. Producer-minted PENDING receipts are superseded by a net-new record; no existing receipt was edited. Ticket: OMN-16859 (AC3b) --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> Co-authored-by: onexbot-occ-writer[bot] <onexbot-occ-writer[bot]@users.noreply.github.com>
Closes OMN-18296 (Urgent, child of OMN-18168). Paired with OmniNode-ai/omnibase_infra#3479, which enforces the bound this PR declares.
The defect
Cloud delegation
16eafedc-199c-44c2-a2cb-b9e535839bb9was submitted to the lab lane at 2026-09-13T09:55:04Z. At 09:57:40Z theomninode-runtime-effectspod was recreated with that delegation's inference command in flight. Read-only probe of the lab:gateway_workflowsstatus='published',completed_at NULL, correlationa2fe0848-4b4b-462e-b633-c5f9559afee5delegation_workflow_statestate='ROUTED',in_flight=t,pending_emissionsempty, last advanced 09:55:04.27Zdelegation-inference-request.v1inference-response.v1The inference call was lost with the process and its offset was already committed, so the command was never redelivered and no response of either kind will ever arrive.
Nothing bounded the resulting wedge, and the two numbers that governed the run were unrelated to each other and neither was a contract: the runtime's give-up TTL was an environment-variable default in omnibase_infra (900s) and this client's patience was a hardcoded 300s CLI default. A caller therefore abandoned a delegation the platform was still willing to finish, and could not distinguish that from one the platform had silently stopped working on.
What changed
The contract declares the bound (
node_delegation_orchestrator/contract.yaml).completion_boundcarriesmax_wall_seconds, the restart policy, and the failure class and code the terminal must name. One declaration, read by the runtime that enforces it and by the client that waits for it, so the two cannot drift.A typed failure class for the cause.
EnumDelegationFailureClass.RUNTIME_RESTART_DURING_DELEGATION. Deliberately distinct fromTIMEOUT, which is a provider that took too long to answer a call we can still see; here no call is outstanding at all.The codec builds the terminal.
StateIoCodec.build_abandoned_terminalturns an abandoneddelegation_workflow_staterow into aModelDelegationFailedpayload. omnibase_infra owns the bus, the envelope id and the topic; this method owns the only thing infra cannot know, which is this node's business shape.The values are the honest ones. No content, so
contentis empty; no verdict, soquality_passedis false and the score is 0.0; no answer from any provider, so no tokens are claimed.latency_msis the real elapsed wall time, because how long the customer waited is true and useful even when nothing came back.model_usedreports"none"where routing never selected one rather than attributing a call that was never made. A row whose payload does not decode is returned asNoneand left alone rather than closed out on a guess.terminal_failure_reasonis composed from the contract's own vocabulary token into the shape the gateway's attribution grammar actually parses, soruntime_restart_during_delegationreachesgateway_workflows.terminal_failure_classasRuntimeRestartDuringDelegationErrorwith its code, instead of arriving as an unexplained failure.The client reads the same bound.
--timeoutnow defaults to the contract'smax_wall_secondsrather than 300.poll_until_terminaltakes adeadline_source, and the typedTIMEOUT_EXCEEDEDerror distinguishes the two cases: a caller-chosen budget running out means wait longer, and the platform's own declared bound running out means the runtime owed a terminal and did not deliver one. The customer's next move differs, so the error must not merge them. A caller who passes--timeoutstill gets the previous wording unchanged.read_declared_completion_boundrefuses rather than falling back to a built-in number. A silent fallback is how this client came to be waiting 300 seconds for a 900 second platform in the first place.dod_evidence
RED first.
tests/unit/delegation/test_omn18296_completion_bound.pyrun against unmodifiedsrc/:GREEN.
test_cli_cloud.pygainstest_an_unset_timeout_waits_for_the_contract_declared_bound, which drives the real CLI end to end and asserts the poll deadline equals the contract's declared value and that the deadline names its source. Its fake transport gained the new keyword; no assertion in any existing test was changed.The codec was additionally validated against the real abandoned row, read out of the lab's
delegation_workflow_stateand fed throughbuild_abandoned_terminalunmodified. It produced a validModelDelegationFailedcarryingtask_type=summarization, the routed model, the real elapsed latency, andterminal_failure_reasonthat the gateway's grammar parses intoRuntimeRestartDuringDelegationError/ONEX_MARKET_DELEGATION_RUNTIME_RESTART. The committed fixture is a synthetic row of the same shape, so no customer prompt text enters the repository.ruff format,ruff checkandmypy --strictclean on every file touched.Honest gap. AC1's lab proof — delete the runtime pod mid-flight and read a terminal back within the bound — needs both this PR and the omnibase_infra one live on the lane, so it cannot be obtained from either PR alone.
16eafedcis stillpublishedand will not self-heal; closing it out requires the deployed runtime to carry the enforcement half.Evidence-Ticket: OMN-18296
Evidence-Source: OCC#9332