Skip to content

chore(OMN-12765): promote OCC dev evidence to main - #2255

Closed
jonahgabriel wants to merge 515 commits into
mainfrom
jonah/omn-12765-occ-main-promotion
Closed

jonahgabriel wants to merge 515 commits into
mainfrom
jonah/omn-12765-occ-main-promotion

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jun 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Promotes current dev OCC evidence to main for OMN-12765 by merging dev into current main after the already-merged OMN-12749 promotion PR #2252.

PR #2252 already promoted the OMN-12748/12749/12752/12753 delegation cluster. This PR preserves that main evidence, keeps its dod-occ-main-pr-2252 entry on OMN-12749, and adds the remaining dev-only OCC contracts/receipts now needed on main.

Scope

Adds dev-tracked contracts and PASS receipts for:

  • OMN-12736
  • OMN-12742
  • OMN-12743
  • OMN-12755
  • OMN-12761
  • OMN-12762
  • OMN-12763

Also reconciles existing release/evidence contracts and receipt hashes for OMN-12245 and related historical contract directories after the merge resolution.

Conflict resolution

  • Preserved main-only release/guard behavior for .github/workflows/main-target-guard.yml by leaving the main version unchanged.
  • Preserved chore(OMN-12749): promote delegation-cluster OCC contracts+receipts dev->main #2252 main promotion evidence for OMN-12749 while retaining dev-side OMN-12749 receipt bodies.
  • Kept dev OCC receipts for the OMN-127xx delegation/SEA fixes and refreshed contract_sha256 values against the resolved formatted contract files.
  • Unioned conflicted dod_evidence entries where dev and main had different evidence items for the same contract.

Verification

  • uv run validate-yaml contracts/OMN-12245.yaml contracts/OMN-12736.yaml contracts/OMN-12742.yaml contracts/OMN-12743.yaml contracts/OMN-12749.yaml contracts/OMN-12755.yaml contracts/OMN-12761.yaml contracts/OMN-12762.yaml contracts/OMN-12763.yaml
  • uv run python -m onex_change_control.scripts.validate_pr_contracts --diff-files $(git diff --cached --name-only) --diff-content /tmp/omn-12765.diff
  • custom staged YAML parse check
  • custom receipt contract_sha256 check for changed contracts
  • git diff --cached --check
  • pre-commit run --files $(git diff --cached --name-only)

Known blocker

main-target-guard rejects this PR because the requested head branch is jonah/omn-12765-occ-main-promotion; current main policy accepts only dev promotions or hotfix/* heads. I did not bypass the gate.

promotion-receipt: OCC-12765

Evidence-Ticket: OMN-12765

* evidence(OMN-12532): bind final configmap head

* evidence(OMN-12532): bind OCC follow-up PR
* evidence(OMN-12432): bind clean diagnosis PR

* evidence(OMN-12432): bind OCC PR for clean diagnosis

* evidence(OMN-12432): refresh OCC self receipt

* evidence(OMN-12432): refresh receipt contract hashes

* evidence(OMN-12432): add receipt contract hashes
* evidence(OMN-12514): add SEA inference bus receipts

* evidence(OMN-12514): bind OCC receipt PR
…1984)

* feat(OMN-12540): harden freestanding-imperative detector precision

Three precision fixes to scan_freestanding_imperative_io and helpers:

1. Local git ops no longer flagged as subprocess_network. Removed the
   blanket 'git' (plus kubectl/docker/helm) token; git is now network-only
   for the verbs fetch/clone/push/pull/ls-remote via _git_argv_is_network
   (handles 'git -C <dir> <verb>'). Local plumbing (rev-parse/log/describe/
   status/branch/show/diff) stays unflagged. Fixes the SEA __main__.py
   git rev-parse HEAD provenance false positive.

2. Topics stay strict: no topic-module exemption. Added a test pinning that
   a topics.py-style constants module IS flagged for HARDCODED_TOPIC.

3. Removed 'timeout' from the inference-param set: a bare local timeout=
   (subprocess/socket/asyncio) is a control-flow bound, not an LLM sampling
   knob. All true inference params (max_tokens/temperature/top_p/top_k/
   presence_penalty/frequency_penalty/max_new_tokens) stay flagged.

Tests: 36 focused pass; full suite 3359 passed, 17 skipped. mypy --strict
clean; ruff clean.

* evidence(OMN-12540): add OCC contract + DoD receipts for detector precision

Pairs contracts/OMN-12540.yaml with dod_receipts proving full suite green
(3359 passed), static checks clean, and the precision proof (local git
rev-parse not flagged, network git flagged, topics-module flagged, local
timeout not flagged). commit_sha 2dc3223.
* style(OMN-12514): yamlfmt SEA receipts

* evidence(OMN-12514): bind yamlfmt OCC receipt
Central contract + dod receipts for onex-self-extending-agent PR #185
(node_kafka_ingress_effect replaces kafka_runner.py daemon). Pairs with the SEA
Receipt Gate via Evidence-Source: OCC#<this-PR>.

- contracts/OMN-12471.yaml: ticket contract (schema 1.0.0), dod_evidence for the
  SEA PR (#185) and the OCC publication PR.
- drift/dod_receipts/OMN-12471/dod-sea-pr-185/command.yaml: filesystem + suite
  probe — kafka_runner.py deleted, node present, zero httpx, 1211 passed/15
  skipped.
- drift/dod_receipts/OMN-12471/dod-occ-pr/command.yaml: OCC publication receipt.
* evidence(OMN-12551): add codex terminal listener receipts

* evidence(OMN-12551): bind OCC evidence PR
* evidence(OMN-12552): bind SEA reconciliation proof

* evidence(OMN-12552): add OCC self receipt

* evidence(OMN-12552): fix receipt contract hashes
#193 (#1999)

Pairs onex-self-extending-agent PR #193 (OMN-12475, base dev): node_agent_orchestrator
bus-wired ORCHESTRATOR node with contract-resolved model id + prompt and non-env
google.genai.Client credential injection.

Two PASS receipts (verifier != runner): dod-sea-agent-orchestrator-pr-193 probes the
SEA PR; dod-occ-pr-1999 binds the ticket to this OCC PR so the merge-eligibility gate
resolves a PR-bound PASS receipt. Both contract_sha256-bound to the OMN-12475 contract.
* evidence(OMN-12472): publish dev-rooted Track-B receipts

* evidence(OMN-12472): bind dev-root OCC PR

* evidence(OMN-12472): refresh dev-root self checks
* evidence(OMN-12553): bind eval orchestrator proof

* evidence(OMN-12553): add OCC publication receipt
…nibase_core PR #1187 (#2000)

* evidence(OMN-12545): bind EnumDispatchStatus core consolidation to omnibase_core PR #1187

Adds the OMN-12545 ticket contract and DoD receipts binding central OCC
evidence to omnibase_core PR #1187 (EnumDispatchStatus superset merge:
NO_DISPATCHER + INTERNAL_ERROR folded into the canonical core copy).

- contracts/OMN-12545.yaml
- drift/dod_receipts/OMN-12545/dod-core-pr-1187/command.yaml
- drift/dod_receipts/OMN-12545/dod-deploy-assessment/command.yaml

OMN-12545

dod_evidence:
- ticket contract validates against ModelTicketContract (validate-yaml OK)
- core PR #1187 head 12ed4fecff03245e05253c630adc6742c4743f73 bound in dod-core-pr-1187
- deploy assessment: additive behavior-preserving enum consolidation, no live deploy required

* evidence(OMN-12545): add dod-occ-pr self-binding receipt for OCC PR #2000

OMN-12545

dod_evidence:
- binds OMN-12545 central evidence to onex_change_control PR #2000
* evidence(OMN-12529): add deploy gate plan

* evidence(OMN-12529): refresh deploy gate pr binding
…2006)

Central evidence binding for omnimarket PR #1010 (projection API
_json_value UUID serialization fix). Adds contracts/OMN-12558.yaml and
three PASS DoD receipts:
- dod-omnimarket-pr-1010: binds omnimarket PR #1010 head 7c455d86.
- dod-local-validation: TDD regression fails pre-fix with the live
  TypeError and passes post-fix; projection suite + ruff + mypy clean.
- dod-occ-pr-self: self-binding for this OCC PR #2006.

verifier (jonah) differs from runner (claude); contract_sha256 pinned
to the final contract content across all receipts.
…overy (#2007)

* docs(OMN-12559): add OCC contract + receipts for node migration auto-discovery

Central contract contracts/OMN-12559.yaml and paired dod_receipts
(dod-infra-discovery binding omnibase_infra PR #1820; dod-occ-pr self-binding)
for the node-migration auto-discovery work. contract_sha256 binds each receipt
to the published contract bytes.

* docs(OMN-12559): bind OCC publication receipt to PR #2007

* docs(OMN-12559): normalize OCC contract receipts
…state dir (#2009)

* evidence(OMN-12532): bind deploy-path evidence for stability runtime state dir

The deploy-gate (OMN-8912) requires the cited ticket's OCC contract to carry
a dod_evidence check_value containing 'deploy', 'docker exec', or
'rpk topic produce'. omnibase_infra PR #1811 touches runtime paths
(docker-compose.infra.yml, docker-compose.stability-test.yml) but OMN-12532
had no deploy-keyword evidence, so the gate failed.

The stability dogfood probe genuinely published the direct
pr_lifecycle_orchestrator start command via rpk topic produce against the
stability broker and inspected runtime-effects logs/consumer lag. This commit
makes that deploy-path provenance explicit:
- dod-stability-dogfood check_value now asserts the receipt records
  'rpk topic produce' (the actual probe command).
- dod-stability-dogfood receipt probe_command updated to the literal rpk
  topic produce invocation used.
- All five OMN-12532 receipts re-bound to the new contract_sha256
  (OMN-10421 hash-binding invariant).

Evidence-Ticket: OMN-12532
Evidence-Source: OCC#PENDING

* evidence(OMN-12532): bind self receipt to OCC PR #2009

The OCC merge-eligibility validator requires at least one PASS receipt that
binds to this OCC PR (pr_number) or one of its commit SHAs. The self-binding
receipt previously pointed at the merged OCC PR #1977; re-point it to PR #2009.

Evidence-Ticket: OMN-12532
Evidence-Source: OCC#2009
…e fix (#2008)

* docs(OMN-12531): add deploy-gate evidence for Pattern B broker runtime fix

Add a dod-deploy-gate-validation evidence item to the OMN-12531 OCC
contract so the omnibase_infra deploy-gate accepts PR #1810 (which
touches src/omnibase_infra/runtime/service_pattern_b_broker.py, a
runtime path). The deploy-gate validator (OMN-8912) requires a cited
ticket's dod_evidence check_value to contain a deploy keyword.

Verified locally: validate_pr_deploy_required.py against PR #1810
changed files + body and this contract returns exit 0:
  ::notice::DEPLOY GATE PASSED: OMN-12531 has deploy evidence.

Evidence-Ticket: OMN-12531
Evidence-Source: OCC self

* docs(OMN-12531): re-pin receipt contract_sha256 after adding deploy evidence

Adding the dod-deploy-gate-validation item changed the OMN-12531
contract hash, so the four pre-existing receipts (dod-infra-pr-1810,
dod-local-validation, dod-occ-pr-self, dod-stability-dogfood) had stale
contract_sha256 pins. Re-pin all to the current contract hash
sha256:4a4153d9... so the OCC receipt-gate (contract_hash_mismatch) passes.

Evidence-Ticket: OMN-12531
Evidence-Source: OCC self

* docs(OMN-12531): use absolute working_dir in deploy-gate receipt

ModelDodReceipt requires working_dir to be an absolute path. The
deploy-gate-validation receipt used a $OMNI_HOME-prefixed path which
failed receipt-gate schema validation. Use the literal absolute path
matching the other OMN-12531 receipts.

Evidence-Ticket: OMN-12531
Evidence-Source: OCC self

* docs(OMN-12531): bind occ-pr-self receipt to OCC PR #2008

The receipt-gate requires a PASS receipt for OMN-12531 to bind to this
OCC PR. Re-point dod-occ-pr-self from the superseded PR #1975 to PR
#2008 so the pr_ticket_mismatch gate passes.

Evidence-Ticket: OMN-12531
Evidence-Source: OCC self
…-driven inference (#1964)

* evidence(OMN-12498): add contract and SEA PR 182 receipt for contract-driven inference

* evidence(OMN-12498): add self-referential OCC PR 1964 receipt

* style(OMN-12498): yamlfmt contract + receipts, sync contract_sha256
…#1959)

* evidence(OMN-12521): add SEA __main__ contract-native contract + receipts

Central evidence for onex-self-extending-agent PR #178 which removes the two
freestanding imperative-IO violations in src/__main__.py:
- line 33 hardcoded onex.evt topic literal -> contract-loaded
- line 840 subprocess git rev-parse -> contract-declared provenance channel

dashboard_server.py was already retired by SEA PR #157 (catalog entry stale).

Receipts: dod-scanner-clean (before/after --scan-freestanding), dod-unit-suite,
dod-static-checks, dod-occ-pr.

* evidence(OMN-12521): bind dod-occ-pr receipt to OCC PR #1959
jonahgabriel and others added 22 commits June 6, 2026 07:30
* docs(OMN-12729): add delegation OCC receipts

* docs(OMN-12729): align OCC interface enums

* docs(OMN-12729): format delegation OCC receipts

* docs(OMN-12729, OMN-12730): bind OCC receipts to PR
* docs(OMN-12732): add delegation projection OCC evidence

* docs(OMN-12732): bind OCC evidence PR receipt
* docs(OMN-12738): add qwen delegation evidence

* docs(OMN-12738): bind occ evidence pr

* docs(OMN-12738): format occ evidence receipts
* docs(OMN-12245): backmerge main release version evidence to dev

* docs(OMN-12245): add dev backmerge release evidence

* docs(OMN-12245): align backmerge receipt hashes
…2237)

* chore(OMN-12750): baseline omnimarket freestanding guard

* docs(OMN-12750): add guard baseline receipts
#2239)

* chore(OMN-12751): baseline omnibase_infra freestanding guard

* docs(OMN-12751): add guard baseline receipts
* chore(OMN-12755): add deploy-runtime evidence

* chore(OMN-12755): bind OCC evidence PR receipt
* chore(OMN-12749): add runtime adapter delegation evidence

* chore(OMN-12749): bind OCC evidence PR receipt

* chore(OMN-12749): refresh runtime adapter evidence

* chore(OMN-12749): format evidence receipts

* chore(OMN-12749): refresh receipt hashes
* chore(OMN-12748): add projection evidence receipts

* chore(OMN-12748): fix OCC contract validation

* chore(OMN-12748): add receipt contract hashes

* chore(OMN-12748): bind OCC self receipt
* chore(OMN-12762): add overlay quality contract evidence

* chore(OMN-12762): add occ evidence pr receipt

* fix(OMN-12762): use valid occ interface enum

* style(OMN-12762): format occ evidence yaml

* chore(OMN-12762): refresh formatted contract hash
…schema fix (#2249)

* chore(OMN-12761): add OCC contract + receipts for projection contract db-schema fix

Two contract.yaml corrections in omnimarket PR #1076:
- savings: db_io database omnibase_infra -> omnidash_analytics (migration 075 target)
- registration: projection_api.schema omnidash_analytics -> public (Postgres schema)

Live evidence: savings_estimates=15 rows, registration.v1 row_count=36 fresh,
new delegation e2e correlation 13bf4549 round-trips savings_estimates +1.

OMN-12761

* chore(OMN-12761): fix receipt contract_sha256 + add dod-occ-evidence receipt

Correct contract_sha256 from placeholder to real SHA256 of OMN-12761.yaml
(1403674985e244ad033e60b595c7a4d83182d4ac1a45339c179a8ba8c8261271).
Add dod-occ-evidence receipt pointing to OCC PR #2249.

OMN-12761

* chore(OMN-12761): update contract with deploy evidence keyword + fix receipt SHAs (OMN-12761)

* chore(OMN-12761): fix interfaces_touched enum + update receipt SHAs (OMN-12761)

* chore(OMN-12761): clear interfaces_touched since interface_change=false (OMN-12761)
…ceipt/deploy gates (#2251)

* chore(OMN-12736,OMN-12742,OMN-12743): add OCC contracts + receipts for receipt/deploy gates

- OMN-12736: CI-only migration-freeze checkout-timeout hardening (omnibase_infra #1882 receipt gate).
- OMN-12743: remove hardcoded model/provider literals on demo paths; deploy-token dod_evidence for
  the runtime-path change (omnimarket #1071 deploy-gate).
- OMN-12742: dev/stability redeploy; deploy/docker-exec/rpk-topic-produce dod_evidence (omnimarket
  #1071 deploy-gate flagged 12742 alongside 12743).

Each contract validates against ModelTicketContract; receipts carry status: PASS, re-pinned
contract_sha256 (post-yamlfmt), and adversarial probe evidence.

* fix(OMN-12736,OMN-12742,OMN-12743): bind occ-pr-evidence receipts to OCC PR #2251

occ_merge_eligibility requires at least one PASS receipt per ticket whose pr_number
matches the OCC PR (or commit_sha is one of its commits). Set pr_number: 2251 and
commit_sha to the OCC PR head on each dod-occ-pr-evidence receipt.
@coderabbitai

coderabbitai Bot commented Jun 7, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 71ebda46-aaa2-43d6-af8f-d4bc520fa928

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-12765-occ-main-promotion

Comment @coderabbitai help to get the list of available commands and usage tips.

@jonahgabriel

Copy link
Copy Markdown
Contributor Author

OMN-12765 pivot: this main-target PR is blocked by main-target-guard and is obsolete. Use dev backmerge PR #2258 instead: #2258

@jonahgabriel

Copy link
Copy Markdown
Contributor Author

Closing as superseded by direct dev-to-main promotion #2266 for OMN-12765. #2255 used a feature-branch main promotion shape and is blocked by the current main-target guard.

@jonahgabriel
jonahgabriel deleted the jonah/omn-12765-occ-main-promotion branch June 11, 2026 17:59
jonahgabriel added a commit that referenced this pull request Jul 11, 2026
* evidence(OMN-14360): add infra 2255 contract receipts

* evidence(OMN-14360): self-bind OCC companion
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants