Repository navigation
evidence(OMN-19981): hand-authored companion for omnidash#349 - #12362
Conversation
omnidash#349's OCC autobind cannot mint a companion (no candidate grammar reads TypeScript), so this hand-authors one. dod-omn19981-current-head-native-vitest-v3 supersedes v2, whose head pin (omnidash#346 head 752307696c73) and two-page tree check no longer describe the stacked #349. It pins #349 head e187e72187f3 in the checkout and on GitHub, requires exactly the six declared local pages, and runs the native page-contract Vitest (61 tests). It binds AC1 (each page names at least one exposure, all served) and AC2 (no hand-written SQL topic). Verified locally: - every check passes at e187e72; - negative control: with the Workflow contract from 3fe6d89 (no binding), 3 tests fail, including the AC1 test; - node_dod_verify --dry-run --execution-audience hosted (omnimarket dev e141812ea) marks v3 verified and v2 and its two predecessors superseded, 0 failed; - yamlfmt, the contamination ratchet, validate-contract-yaml, lint-contract-check-values and dod-evidence-required pass.
CI's receipt hardening refused the two hand-authored v3 receipts with [PROBE_CAPTURE]: probe_stdout must come from running probe_command, with a capture record. Both probes were rerun through check_receipt_hardening.py --capture-probe (dev 469cc55's copy) in a clean omnidash checkout at e187e72, so probe_stdout, exit_code, run_timestamp, duration_ms and the capture record now come from those runs. The test_passes probe is now runnable as written: the vitest run, then gh api repos/OmniNode-ai/omnidash/commits/e187e72… --jq .sha. Before, it had a trailing "at gh api …" phrase, and that phrase was the only place naming the omnidash repo. The repo hint is what COMMIT_SHA_EXISTS needs to resolve the omnidash commit. Verified locally with CI's own invocation (--paths-file0, --probe-capture-added-file0, --head-ref): exit 0. The same run on the uncaptured receipt fails with [PROBE_CAPTURE]. The contract is unchanged.
|
Close-out for onex_change_control#12362 (OMN-19981). Merged 2026-10-02T16:25:01Z, merge commit 648bb7f. It landed hand-authored evidence (v3 receipts) for omnidash#349, because OCC autobind posted that it could not mint a companion for it. Verified: 89 check-runs succeeded, 2 skipped, none failing (verify / verify run 37030707872, CI Summary run 37030709286). Read live 2026-10-04T15:48Z; no review comments, and the only comments are bot notices. Unblocks: Autobind later stood down on omnidash#349 and #346 in favour of this evidence (bot comment on #12496). Left on OMN-19981: In Review; Jonah was asked at 2026-10-04T09:33Z to review and move it to Done. The Workflow, Usage, Credentials and API Keys pages and AC3 (deleting the sqlite reader) are scoped to the 10/5 sprint by the ticket description. Thank you! |
OMN-19981
Opened as the onexbot-occ-writer App through the OMN-18327
dispatch path (.github/workflows/open-pr-as-writer-app.yml),
dispatched by @Patel230.
Change-control PRs on this repo's privileged surfaces are opened
as the App rather than under the shared human account: every lane
here commits as one person, so a human-authored PR on an owned
path is un-approvable by construction, which is what froze the
fleet behind OCC#9362 on 2026-09-13.
This workflow merges nothing. Every existing required check gates
this PR exactly as it gates any other.
Summary
Hand-authored OCC evidence for OmniNode-ai/omnidash#349 (OMN-19981). On #349, OCC autobind posted that "no changed-file candidate could be proven RED against the merge base", and that hand-authored evidence is required.
This appends
dod-omn19981-current-head-native-vitest-v3tocontracts/OMN-19981.yaml, with its two receipts. It supersedes v2, whose head pin (omnidash#346 head752307696c73) and two-page tree check no longer describe the stacked #349.What changed
One file edited,
contracts/OMN-19981.yaml(one evidence item appended; nothing else in the contract changed), and two receipts added underdrift/dod_receipts/OMN-19981/dod-omn19981-current-head-native-vitest-v3/(command.yaml,test_passes.yaml). No earlier item or receipt is edited or removed; the older items are retired by the append-only supersession.The evidence item
e187e72187f3, andgh pr view 349must independently report that head.api-keys,credentials,overview,runs,usage,workflow).npm test -- --run src/pages/local/pages.test.ts, 61 tests.origin/dev, where the reader's deletion is not merged yet.How it was verified
e187e72, run at 2026-10-02T15:03:33Z.3fe6d89(no binding), 3 tests fail, including the AC1 test.node_dod_verify --dry-run --execution-audience hosted(omnimarket deve141812ea) gives:dod-omn19981-overview-runs-native-vitestanddod-occ-diff-derived-behavior-proof-pr-344superseded;validate-contract-yaml,lint-contract-check-valuesanddod-evidence-requiredpass. The receipts carry the formatted contract's sha256 and the entry hash fromomnibase_core'scompute_contract_entry_sha256.Failure paths
n/a: this change writes evidence records (one contract item and two receipts), not a receipt-producing verdict path. The receipts it adds record PASS for checks that were run and their probe output; a later failure of any check makes
dod_verifyfail the item, not pass it vacuously (the negative control above shows the AC1 test failing).Open defects
none in this change. In the product: failed delegation runs reach the dashboard with a redacted cause, which needs OMN-19448 (recorded on omnidash#349).
Lab readback behind the product PR
omnidash#349 at
e187e72was read on the lakshman lane after 20 real deployed-lane delegations (2026-10-02, 15:19 to 15:27Z; 16 succeeded, 4 failed). Every run reacheddelegation.decisions.v1anddelegation.savings.v1asdata_source = real. At 15:28:30Z all 826 values the six pages render matched the API across 66 runs. The full readback is in #349's description.Local gates
--no-verify, noSKIP=, no--no-gpg-sign, nocore.hooksPathoverride. Every pre-commit and pre-push hook ran.Not in this change
origin/dev; AC4's proof is a Playwright screenshot this contract does not run.