Repository navigation
chore(release)(OMN-12245): backmerge onex_change_control v0.5.1 version bump to dev - #2230
Conversation
📝 WalkthroughWalkthroughActions and workflows add retry/backoff and new flags/permissions; a new main-target guard validates PR targeting rules. OCC rerun PRs retarget to dev. Pre-commit hooks and ignore rules adjust. Allowlist configs update. Contracts standardize evidence grep paths to drift/dod_receipts across many tickets. ChangesCI guard hardening and contract receipt path normalization
Estimated code review effort🎯 4 (Complex) | ⏱️ ~75 minutes Possibly related PRs
Poem
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
|
d3aa9d9 to
8d4c211
Compare
| try: return json.loads(line) | ||
| except Exception: found={"raw":line[:2000]} | ||
| return found | ||
| open("/tmp/omn12294-cid.txt","w").write(CID) |
| break | ||
| time.sleep(6) | ||
| for name,_ in HOPS: print(f"HOP {name}: {'FOUND' if results[name]['found'] else 'MISSING'}",flush=True) | ||
| open("/tmp/omn12294-proof-result.json","w").write(json.dumps({"correlation_id":CID,"started_at":NOW, |
| without a live broker. This is the same injection seam the shipped tests use. | ||
| """ | ||
|
|
||
| async def start(self) -> None: ... |
| """ | ||
|
|
||
| async def start(self) -> None: ... | ||
| async def close(self) -> None: ... |
| async def close(self) -> None: ... | ||
| async def arm_response( | ||
| self, *, response_topic: str, correlation_id: str | ||
| ) -> None: ... |
| ) -> None: ... | ||
| async def publish( | ||
| self, topic: str, key: bytes | None, value: bytes, headers: object = None | ||
| ) -> None: ... |
There was a problem hiding this comment.
Actionable comments posted: 4
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/ci.yml (1)
169-188:⚠️ Potential issue | 🟠 Major | ⚡ Quick winScope token permissions for
imperative-contract-guard.Line 169 defines a job that has no explicit
permissions, so it inherits repository defaults. This guard only needs repository read access; default broader scopes increase blast radius unnecessarily.Suggested fix
imperative-contract-guard: name: Imperative Contract Guard + permissions: + contents: read runs-on: >- ${{ (github.event_name == 'pull_request' &&🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/ci.yml around lines 169 - 188, The imperative-contract-guard job is missing explicit GitHub Actions permissions and currently inherits broad repo defaults; add a minimal permissions block to the imperative-contract-guard job (the job with name "Imperative Contract Guard") to restrict it to repository read-only access (e.g., set permissions to contents: read) placed at the job level above steps so the validate step ("Validate imperative contract guard wiring") runs with least privilege.Source: Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/main-target-guard.yml:
- Around line 10-23: The workflow is missing an explicit permissions block, so
add a least-privilege permissions declaration at the top level of the workflow
(for the workflow that defines the on: pull_request and job main-target-guard)
by inserting a permissions: none stanza to ensure the run has no token scopes;
this targets the workflow containing the main-target-guard job and the
pull_request trigger so the job runs without GitHub token permissions.
In @.pre-commit-config.yaml:
- Around line 139-146: The hook "check-imperative-contracts-freestanding" can be
skipped because it has pass_filenames: false and is restricted by types:
[python]; update the hook config for id: check-imperative-contracts-freestanding
to ensure it always executes (e.g., add always_run: true) so freestanding
allowlist/contract-only commits still invoke the check even when no Python files
are staged; keep pass_filenames: false if desired but ensure always_run is
present to avoid the guard bypass.
In `@contracts/OMN-10487.yaml`:
- Around line 41-49: The grep checks use an absolute variable prefix in
contracts/OMN-10487.yaml (check id "dod-rerun-state-pr-target") but the new
entry "dod-004" in contracts/OMN-10485.yaml uses a relative path; update
OMN-10485.yaml so its command checks (the "dod-004" check_value and any
evidence_requirement command checks) prepend $CONTRACT_REPO_DIR to the
.github/workflows/... paths (matching the pattern used in
"dod-rerun-state-pr-target") to standardize path usage across contracts.
In `@contracts/OMN-11068.yaml`:
- Line 54: The check_value entries use a templated command ("gh pr view
${PR_NUMBER} --repo ${REPO} --json state,title") which allows any PR to pass;
replace the variable PR substitution with the specific PR IDs required by the
DoD descriptions: update the check_value that currently uses that template for
PR `#1765` to "gh pr view 1765 --repo ${REPO} --json state,title" and similarly
update the other check_value to "gh pr view 1715 --repo ${REPO} --json
state,title" so the checks are bound to the exact PRs; keep the ${REPO} token if
repo should remain variable.
---
Outside diff comments:
In @.github/workflows/ci.yml:
- Around line 169-188: The imperative-contract-guard job is missing explicit
GitHub Actions permissions and currently inherits broad repo defaults; add a
minimal permissions block to the imperative-contract-guard job (the job with
name "Imperative Contract Guard") to restrict it to repository read-only access
(e.g., set permissions to contents: read) placed at the job level above steps so
the validate step ("Validate imperative contract guard wiring") runs with least
privilege.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: ae3f70bc-b85f-4717-abf1-1515fb508a6e
📒 Files selected for processing (300)
.github/actions/validate-boundaries/action.yml.github/actions/validate-contract/action.yml.github/workflows/call-occ-preflight.yml.github/workflows/ci.yml.github/workflows/imperative-contract-guard.yml.github/workflows/main-target-guard.yml.github/workflows/occ-rerun-downstream.yml.gitignore.pre-commit-config.yamlallowlists/omniintelligence.yamlallowlists/omnimarket.yamlallowlists/omnimemory.yamlallowlists/onex_change_control.yamlcontracts/OMN-10143.yamlcontracts/OMN-10151.yamlcontracts/OMN-10207.yamlcontracts/OMN-10278.yamlcontracts/OMN-10316.yamlcontracts/OMN-10353.yamlcontracts/OMN-10377.yamlcontracts/OMN-10409.yamlcontracts/OMN-10424.yamlcontracts/OMN-10475.yamlcontracts/OMN-10483.yamlcontracts/OMN-10485.yamlcontracts/OMN-10487.yamlcontracts/OMN-10489.yamlcontracts/OMN-10490.yamlcontracts/OMN-10491.yamlcontracts/OMN-10500.yamlcontracts/OMN-10512.yamlcontracts/OMN-10518.yamlcontracts/OMN-10519.yamlcontracts/OMN-10520.yamlcontracts/OMN-10521.yamlcontracts/OMN-10535.yamlcontracts/OMN-10539.yamlcontracts/OMN-10540.yamlcontracts/OMN-10541.yamlcontracts/OMN-10542.yamlcontracts/OMN-10543.yamlcontracts/OMN-10544.yamlcontracts/OMN-10546.yamlcontracts/OMN-10547.yamlcontracts/OMN-10548.yamlcontracts/OMN-10552.yamlcontracts/OMN-10554.yamlcontracts/OMN-10561.yamlcontracts/OMN-10563.yamlcontracts/OMN-10564.yamlcontracts/OMN-10565.yamlcontracts/OMN-10566.yamlcontracts/OMN-10567.yamlcontracts/OMN-10569.yamlcontracts/OMN-10570.yamlcontracts/OMN-10572.yamlcontracts/OMN-10579.yamlcontracts/OMN-10580.yamlcontracts/OMN-10581.yamlcontracts/OMN-10584.yamlcontracts/OMN-10586.yamlcontracts/OMN-10587.yamlcontracts/OMN-10588.yamlcontracts/OMN-10589.yamlcontracts/OMN-10591.yamlcontracts/OMN-10592.yamlcontracts/OMN-10593.yamlcontracts/OMN-10602.yamlcontracts/OMN-10604.yamlcontracts/OMN-10605.yamlcontracts/OMN-10606.yamlcontracts/OMN-10607.yamlcontracts/OMN-10608.yamlcontracts/OMN-10609.yamlcontracts/OMN-10610.yamlcontracts/OMN-10611.yamlcontracts/OMN-10612.yamlcontracts/OMN-10613.yamlcontracts/OMN-10614.yamlcontracts/OMN-10615.yamlcontracts/OMN-10616.yamlcontracts/OMN-10617.yamlcontracts/OMN-10618.yamlcontracts/OMN-10619.yamlcontracts/OMN-10620.yamlcontracts/OMN-10621.yamlcontracts/OMN-10622.yamlcontracts/OMN-10626.yamlcontracts/OMN-10635.yamlcontracts/OMN-10636.yamlcontracts/OMN-10638.yamlcontracts/OMN-10640.yamlcontracts/OMN-10641.yamlcontracts/OMN-10644.yamlcontracts/OMN-10645.yamlcontracts/OMN-10648.yamlcontracts/OMN-10649.yamlcontracts/OMN-10650.yamlcontracts/OMN-10653.yamlcontracts/OMN-10655.yamlcontracts/OMN-10656.yamlcontracts/OMN-10657.yamlcontracts/OMN-10661.yamlcontracts/OMN-10665.yamlcontracts/OMN-10669.yamlcontracts/OMN-10670.yamlcontracts/OMN-10675.yamlcontracts/OMN-10676.yamlcontracts/OMN-10688.yamlcontracts/OMN-10689.yamlcontracts/OMN-10691.yamlcontracts/OMN-10692.yamlcontracts/OMN-10693.yamlcontracts/OMN-10694.yamlcontracts/OMN-10695.yamlcontracts/OMN-10696.yamlcontracts/OMN-10697.yamlcontracts/OMN-10698.yamlcontracts/OMN-10705.yamlcontracts/OMN-10715.yamlcontracts/OMN-10717.yamlcontracts/OMN-10718.yamlcontracts/OMN-10720.yamlcontracts/OMN-10721.yamlcontracts/OMN-10722.yamlcontracts/OMN-10723.yamlcontracts/OMN-10724.yamlcontracts/OMN-10725.yamlcontracts/OMN-10726.yamlcontracts/OMN-10727.yamlcontracts/OMN-10728.yamlcontracts/OMN-10729.yamlcontracts/OMN-10730.yamlcontracts/OMN-10731.yamlcontracts/OMN-10733.yamlcontracts/OMN-10734.yamlcontracts/OMN-10736.yamlcontracts/OMN-10737.yamlcontracts/OMN-10741.yamlcontracts/OMN-10742.yamlcontracts/OMN-10743.yamlcontracts/OMN-10744.yamlcontracts/OMN-10745.yamlcontracts/OMN-10748.yamlcontracts/OMN-10749.yamlcontracts/OMN-10750.yamlcontracts/OMN-10753.yamlcontracts/OMN-10754.yamlcontracts/OMN-10755.yamlcontracts/OMN-10768.yamlcontracts/OMN-10769.yamlcontracts/OMN-10771.yamlcontracts/OMN-10773.yamlcontracts/OMN-10778.yamlcontracts/OMN-10779.yamlcontracts/OMN-10780.yamlcontracts/OMN-10782.yamlcontracts/OMN-10783.yamlcontracts/OMN-10784.yamlcontracts/OMN-10786.yamlcontracts/OMN-10790.yamlcontracts/OMN-10791.yamlcontracts/OMN-10796.yamlcontracts/OMN-10799.yamlcontracts/OMN-10800.yamlcontracts/OMN-10810.yamlcontracts/OMN-10811.yamlcontracts/OMN-10813.yamlcontracts/OMN-10814.yamlcontracts/OMN-10815.yamlcontracts/OMN-10816.yamlcontracts/OMN-10817.yamlcontracts/OMN-10818.yamlcontracts/OMN-10819.yamlcontracts/OMN-10820.yamlcontracts/OMN-10822.yamlcontracts/OMN-10824.yamlcontracts/OMN-10835.yamlcontracts/OMN-10836.yamlcontracts/OMN-10837.yamlcontracts/OMN-10846.yamlcontracts/OMN-10847.yamlcontracts/OMN-10848.yamlcontracts/OMN-10859.yamlcontracts/OMN-10862.yamlcontracts/OMN-10866.yamlcontracts/OMN-10868.yamlcontracts/OMN-10870.yamlcontracts/OMN-10871.yamlcontracts/OMN-10872.yamlcontracts/OMN-10873.yamlcontracts/OMN-10874.yamlcontracts/OMN-10889.yamlcontracts/OMN-10895.yamlcontracts/OMN-10963.yamlcontracts/OMN-10964.yamlcontracts/OMN-10966.yamlcontracts/OMN-10972.yamlcontracts/OMN-10978.yamlcontracts/OMN-10983.yamlcontracts/OMN-11012.yamlcontracts/OMN-11065.yamlcontracts/OMN-11068.yamlcontracts/OMN-11070.yamlcontracts/OMN-11080.yamlcontracts/OMN-11083.yamlcontracts/OMN-11088.yamlcontracts/OMN-11104.yamlcontracts/OMN-11116.yamlcontracts/OMN-11130.yamlcontracts/OMN-11131.yamlcontracts/OMN-11137.yamlcontracts/OMN-11138.yamlcontracts/OMN-11139.yamlcontracts/OMN-11140.yamlcontracts/OMN-11141.yamlcontracts/OMN-11142.yamlcontracts/OMN-11143.yamlcontracts/OMN-11144.yamlcontracts/OMN-11149.yamlcontracts/OMN-11150.yamlcontracts/OMN-11151.yamlcontracts/OMN-11152.yamlcontracts/OMN-11153.yamlcontracts/OMN-11154.yamlcontracts/OMN-11155.yamlcontracts/OMN-11156.yamlcontracts/OMN-11157.yamlcontracts/OMN-11158.yamlcontracts/OMN-11159.yamlcontracts/OMN-11160.yamlcontracts/OMN-11166.yamlcontracts/OMN-11168.yamlcontracts/OMN-11169.yamlcontracts/OMN-11170.yamlcontracts/OMN-11171.yamlcontracts/OMN-11173.yamlcontracts/OMN-11174.yamlcontracts/OMN-11176.yamlcontracts/OMN-11177.yamlcontracts/OMN-11183.yamlcontracts/OMN-11184.yamlcontracts/OMN-11185.yamlcontracts/OMN-11189.yamlcontracts/OMN-11194.yamlcontracts/OMN-11202.yamlcontracts/OMN-11203.yamlcontracts/OMN-11206.yamlcontracts/OMN-11227.yamlcontracts/OMN-11228.yamlcontracts/OMN-11231.yamlcontracts/OMN-11234.yamlcontracts/OMN-11241.yamlcontracts/OMN-11243.yamlcontracts/OMN-11246.yamlcontracts/OMN-11247.yamlcontracts/OMN-11249.yamlcontracts/OMN-11261.yamlcontracts/OMN-11262.yamlcontracts/OMN-11266.yamlcontracts/OMN-11267.yamlcontracts/OMN-11268.yamlcontracts/OMN-11269.yamlcontracts/OMN-11270.yamlcontracts/OMN-11271.yamlcontracts/OMN-11272.yamlcontracts/OMN-11273.yamlcontracts/OMN-11274.yamlcontracts/OMN-11276.yamlcontracts/OMN-11277.yamlcontracts/OMN-11278.yamlcontracts/OMN-11279.yamlcontracts/OMN-11280.yamlcontracts/OMN-11282.yamlcontracts/OMN-11283.yamlcontracts/OMN-11284.yamlcontracts/OMN-11285.yamlcontracts/OMN-11292.yamlcontracts/OMN-11294.yamlcontracts/OMN-11297.yamlcontracts/OMN-11298.yamlcontracts/OMN-11299.yamlcontracts/OMN-11301.yamlcontracts/OMN-11330.yamlcontracts/OMN-11331.yamlcontracts/OMN-11346.yamlcontracts/OMN-11348.yamlcontracts/OMN-11350.yamlcontracts/OMN-11354.yamlcontracts/OMN-11379.yamlcontracts/OMN-11381.yamlcontracts/OMN-11382.yamlcontracts/OMN-11384.yamlcontracts/OMN-11385.yamlcontracts/OMN-11386.yamlcontracts/OMN-11413.yamlcontracts/OMN-11420.yamlcontracts/OMN-11421.yamlcontracts/OMN-11423.yamlcontracts/OMN-11424.yaml
| - id: check-imperative-contracts-freestanding | ||
| name: Imperative contract guard with freestanding reachability | ||
| language: system | ||
| entry: >- | ||
| uv run check-imperative-contracts --repo-root . --allowlists-dir allowlists --scan-freestanding | ||
| pass_filenames: false | ||
| types: [python] | ||
| stages: [pre-commit] |
There was a problem hiding this comment.
Freestanding imperative-contract guard can be skipped on non-Python commits.
Line 145 restricts execution to Python-typed staged files; with pass_filenames: false and no always_run, this hook may not run on allowlist/contract-only commits, which creates a guard bypass.
Suggested fix
- id: check-imperative-contracts-freestanding
name: Imperative contract guard with freestanding reachability
language: system
entry: >-
uv run check-imperative-contracts --repo-root . --allowlists-dir allowlists --scan-freestanding
pass_filenames: false
- types: [python]
+ always_run: true
stages: [pre-commit]📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| - id: check-imperative-contracts-freestanding | |
| name: Imperative contract guard with freestanding reachability | |
| language: system | |
| entry: >- | |
| uv run check-imperative-contracts --repo-root . --allowlists-dir allowlists --scan-freestanding | |
| pass_filenames: false | |
| types: [python] | |
| stages: [pre-commit] | |
| - id: check-imperative-contracts-freestanding | |
| name: Imperative contract guard with freestanding reachability | |
| language: system | |
| entry: >- | |
| uv run check-imperative-contracts --repo-root . --allowlists-dir allowlists --scan-freestanding | |
| pass_filenames: false | |
| always_run: true | |
| stages: [pre-commit] |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.pre-commit-config.yaml around lines 139 - 146, The hook
"check-imperative-contracts-freestanding" can be skipped because it has
pass_filenames: false and is restricted by types: [python]; update the hook
config for id: check-imperative-contracts-freestanding to ensure it always
executes (e.g., add always_run: true) so freestanding allowlist/contract-only
commits still invoke the check even when no Python files are staged; keep
pass_filenames: false if desired but ensure always_run is present to avoid the
guard bypass.
| - id: "dod-rerun-state-pr-target" | ||
| description: "OCC rerun-state automation opens dev-targeted PRs without suppressing CI." | ||
| source: "manual" | ||
| checks: | ||
| - check_type: "command" | ||
| check_value: >- | ||
| grep -q -- '--base dev' "$CONTRACT_REPO_DIR/.github/workflows/occ-rerun-downstream.yml" && ! | ||
| grep -q '\\[skip ci\\]' "$CONTRACT_REPO_DIR/.github/workflows/occ-rerun-downstream.yml" && grep | ||
| -q 'Evidence-Ticket: OMN-10487' "$CONTRACT_REPO_DIR/.github/workflows/occ-rerun-downstream.yml" |
There was a problem hiding this comment.
Path prefix inconsistency with OMN-10485.yaml dod-004.
This entry uses $CONTRACT_REPO_DIR/.github/workflows/occ-rerun-downstream.yml (lines 47-49) while the newly added dod-004 in contracts/OMN-10485.yaml line 70 uses a relative path .github/workflows/call-occ-preflight.yml without the $CONTRACT_REPO_DIR prefix. Given that this PR is described as standardizing contract evidence grep paths, this inconsistency should be resolved.
🔧 Suggested fix for OMN-10485.yaml to match this pattern
In contracts/OMN-10485.yaml line 70, update to use the $CONTRACT_REPO_DIR prefix:
- grep -q '^ pull-requests: read$' .github/workflows/call-occ-preflight.yml
+ grep -q '^ pull-requests: read$' "$CONTRACT_REPO_DIR/.github/workflows/call-occ-preflight.yml"Similarly, if the evidence_requirement at line 23 of OMN-10485.yaml is intended to run as a command check (not just documentation), consider adding the prefix there as well.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@contracts/OMN-10487.yaml` around lines 41 - 49, The grep checks use an
absolute variable prefix in contracts/OMN-10487.yaml (check id
"dod-rerun-state-pr-target") but the new entry "dod-004" in
contracts/OMN-10485.yaml uses a relative path; update OMN-10485.yaml so its
command checks (the "dod-004" check_value and any evidence_requirement command
checks) prepend $CONTRACT_REPO_DIR to the .github/workflows/... paths (matching
the pattern used in "dod-rerun-state-pr-target") to standardize path usage
across contracts.
| status: "verified" | ||
| checks: | ||
| - check_type: "command" | ||
| check_value: "gh pr view ${PR_NUMBER} --repo ${REPO} --json state,title" |
There was a problem hiding this comment.
Pin the PR identity in the new DoD checks.
Line 54 and Line 62 currently succeed for whatever ${PR_NUMBER}/${REPO} are injected, but the descriptions require binding to specific PRs (#1765 and #1715). This weakens evidence integrity and can produce false-positive verification.
Suggested fix
- check_value: "gh pr view ${PR_NUMBER} --repo ${REPO} --json state,title"
+ check_value: "gh pr view 1765 --repo OmniNode-ai/omnibase_infra --json number,state,title -q '.number == 1765'"
...
- check_value: "gh pr view ${PR_NUMBER} --repo ${REPO} --json state,title"
+ check_value: "gh pr view 1715 --repo OmniNode-ai/onex_change_control --json number,state,title -q '.number == 1715'"Also applies to: 62-62
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@contracts/OMN-11068.yaml` at line 54, The check_value entries use a templated
command ("gh pr view ${PR_NUMBER} --repo ${REPO} --json state,title") which
allows any PR to pass; replace the variable PR substitution with the specific PR
IDs required by the DoD descriptions: update the check_value that currently uses
that template for PR `#1765` to "gh pr view 1765 --repo ${REPO} --json
state,title" and similarly update the other check_value to "gh pr view 1715
--repo ${REPO} --json state,title" so the checks are bound to the exact PRs;
keep the ${REPO} token if repo should remain variable.
8d4c211 to
1ba80de
Compare
…ersion-release-onex_change_control
Evidence-Ticket: OMN-12245
Evidence-Source: OCC#2231
Backmerge companion for main release-version PR #2228 so dev retains the v0.5.1 release metadata after main release publication.
Summary by CodeRabbit
New Features
Improvements
Updates