Skip to content

evidence(OMN-19981): hand-authored companion for omnidash#349 - #12362

Merged
jonahgabriel merged 3 commits into
devfrom
lakshman/OMN-19981-evidence-e187e72
Oct 2, 2026
Merged

jonahgabriel merged 3 commits into
devfrom
lakshman/OMN-19981-evidence-e187e72

Conversation

@onexbot-occ-writer

@onexbot-occ-writer onexbot-occ-writer Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

OMN-19981

Opened as the onexbot-occ-writer App through the OMN-18327
dispatch path (.github/workflows/open-pr-as-writer-app.yml),
dispatched by @Patel230.

Change-control PRs on this repo's privileged surfaces are opened
as the App rather than under the shared human account: every lane
here commits as one person, so a human-authored PR on an owned
path is un-approvable by construction, which is what froze the
fleet behind OCC#9362 on 2026-09-13.

This workflow merges nothing. Every existing required check gates
this PR exactly as it gates any other.

Summary

Hand-authored OCC evidence for OmniNode-ai/omnidash#349 (OMN-19981). On #349, OCC autobind posted that "no changed-file candidate could be proven RED against the merge base", and that hand-authored evidence is required.

This appends dod-omn19981-current-head-native-vitest-v3 to contracts/OMN-19981.yaml, with its two receipts. It supersedes v2, whose head pin (omnidash#346 head 752307696c73) and two-page tree check no longer describe the stacked #349.

What changed

One file edited, contracts/OMN-19981.yaml (one evidence item appended; nothing else in the contract changed), and two receipts added under drift/dod_receipts/OMN-19981/dod-omn19981-current-head-native-vitest-v3/ (command.yaml, test_passes.yaml). No earlier item or receipt is edited or removed; the older items are retired by the append-only supersession.

The evidence item

  • Pins the reviewed head twice: the tested checkout must equal chore(OMN-9586, OMN-9587): add receipt gate contracts and PASS receipts for omnibase_core#892 #349 head e187e72187f3, and gh pr view 349 must independently report that head.
  • Tree check: exactly the six declared local pages (api-keys, credentials, overview, runs, usage, workflow).
  • Native Vitest: npm test -- --run src/pages/local/pages.test.ts, 61 tests.
  • Binds:
    • AC1: each page names at least one exposure, and every exposure is marked ok in the served catalogue.
    • AC2: no page names a topic the server reader answers by hand-written SQL.
  • Not bound:
    • AC3: its falsifier reads origin/dev, where the reader's deletion is not merged yet.
    • AC4: the Playwright screenshot.

How it was verified

  • All four checks pass at e187e72, run at 2026-10-02T15:03:33Z.
  • Negative control: with the Workflow contract from 3fe6d89 (no binding), 3 tests fail, including the AC1 test.
  • dod_verify: node_dod_verify --dry-run --execution-audience hosted (omnimarket dev e141812ea) gives:
    • v3 verified;
    • v2, dod-omn19981-overview-runs-native-vitest and dod-occ-diff-derived-behavior-proof-pr-344 superseded;
    • 0 failed.
  • Hooks: yamlfmt (stable on a second pass), the yamlfmt contamination ratchet, validate-contract-yaml, lint-contract-check-values and dod-evidence-required pass. The receipts carry the formatted contract's sha256 and the entry hash from omnibase_core's compute_contract_entry_sha256.

Failure paths

n/a: this change writes evidence records (one contract item and two receipts), not a receipt-producing verdict path. The receipts it adds record PASS for checks that were run and their probe output; a later failure of any check makes dod_verify fail the item, not pass it vacuously (the negative control above shows the AC1 test failing).

Open defects

none in this change. In the product: failed delegation runs reach the dashboard with a redacted cause, which needs OMN-19448 (recorded on omnidash#349).

Lab readback behind the product PR

omnidash#349 at e187e72 was read on the lakshman lane after 20 real deployed-lane delegations (2026-10-02, 15:19 to 15:27Z; 16 succeeded, 4 failed). Every run reached delegation.decisions.v1 and delegation.savings.v1 as data_source = real. At 15:28:30Z all 826 values the six pages render matched the API across 66 runs. The full readback is in #349's description.

Local gates

  • No gate was bypassed — no --no-verify, no SKIP=, no --no-gpg-sign, no core.hooksPath override. Every pre-commit and pre-push hook ran.
  • Any hook that failed was fixed at the input, not worked around.

Not in this change

  • AC3 and AC4 bindings: AC3 can only be proved once the reader deletion merges to origin/dev; AC4's proof is a Playwright screenshot this contract does not run.
  • Any change to omnidash itself; that is omnidash#349.

Patel230 and others added 2 commits October 2, 2026 20:35
omnidash#349's OCC autobind cannot mint a companion (no candidate grammar
reads TypeScript), so this hand-authors one.

dod-omn19981-current-head-native-vitest-v3 supersedes v2, whose head pin
(omnidash#346 head 752307696c73) and two-page tree check no longer
describe the stacked #349. It pins #349 head e187e72187f3 in the checkout
and on GitHub, requires exactly the six declared local pages, and runs the
native page-contract Vitest (61 tests). It binds AC1 (each page names at
least one exposure, all served) and AC2 (no hand-written SQL topic).

Verified locally:
- every check passes at e187e72;
- negative control: with the Workflow contract from 3fe6d89 (no binding),
  3 tests fail, including the AC1 test;
- node_dod_verify --dry-run --execution-audience hosted (omnimarket dev
  e141812ea) marks v3 verified and v2 and its two predecessors
  superseded, 0 failed;
- yamlfmt, the contamination ratchet, validate-contract-yaml,
  lint-contract-check-values and dod-evidence-required pass.
@jonahgabriel
jonahgabriel enabled auto-merge (squash) October 2, 2026 15:19
CI's receipt hardening refused the two hand-authored v3 receipts with
[PROBE_CAPTURE]: probe_stdout must come from running probe_command, with a
capture record. Both probes were rerun through
check_receipt_hardening.py --capture-probe (dev 469cc55's copy) in a
clean omnidash checkout at e187e72, so probe_stdout, exit_code,
run_timestamp, duration_ms and the capture record now come from those
runs.

The test_passes probe is now runnable as written: the vitest run, then
gh api repos/OmniNode-ai/omnidash/commits/e187e72… --jq .sha. Before, it
had a trailing "at gh api …" phrase, and that phrase was the only place
naming the omnidash repo. The repo hint is what COMMIT_SHA_EXISTS needs to
resolve the omnidash commit.

Verified locally with CI's own invocation (--paths-file0,
--probe-capture-added-file0, --head-ref): exit 0. The same run on the
uncaptured receipt fails with [PROBE_CAPTURE]. The contract is unchanged.
@jonahgabriel
jonahgabriel merged commit 648bb7f into dev Oct 2, 2026
90 checks passed
@jonahgabriel
jonahgabriel deleted the lakshman/OMN-19981-evidence-e187e72 branch October 2, 2026 16:25
@Patel230

Patel230 commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Close-out for onex_change_control#12362 (OMN-19981). Merged 2026-10-02T16:25:01Z, merge commit 648bb7f. It landed hand-authored evidence (v3 receipts) for omnidash#349, because OCC autobind posted that it could not mint a companion for it.

Verified: 89 check-runs succeeded, 2 skipped, none failing (verify / verify run 37030707872, CI Summary run 37030709286). Read live 2026-10-04T15:48Z; no review comments, and the only comments are bot notices.

Unblocks: Autobind later stood down on omnidash#349 and #346 in favour of this evidence (bot comment on #12496).

Left on OMN-19981: In Review; Jonah was asked at 2026-10-04T09:33Z to review and move it to Done. The Workflow, Usage, Credentials and API Keys pages and AC3 (deleting the sqlite reader) are scoped to the 10/5 sprint by the ticket description.

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants