Repository navigation
receipt(OMN-13226): GitHub Action publisher for onex.evt.github.pr-merged.v1 - #2746
Conversation
|
Warning Review limit reached
More reviews will be available in 2 hours, 21 minutes, and 5 seconds. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits. 🚦 How do rate limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (4)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
…rged.v1 OCC receipt for omnimarket PR #1264. Registers T2 of the merge-triggered worktree reaper epic (OMN-13008): GHA pr-merged-publisher workflow, canonical topic onex.evt.github.pr-merged.v1, publisher script modelled on OMN-8917, contract stub + unit/golden-chain tests all green.
Adds dod-007 with rpk topic produce check_value to satisfy the deploy-gate requirement (OMN-8912). The publisher surface is the GHA workflow step; node_pr_merged_projection handler deferred to T3.
d7ff6e2 to
35703af
Compare
…erged publisher
- Rewrite contracts/OMN-13226.yaml modelled on OMN-13220 (3 dod_evidence items,
each check greps a PASS receipt; dod-002 carries 'rpk topic produce' deploy
evidence for the deploy-gate; pr-occ-binding satisfies eligibility pr_ticket_mismatch).
- Add drift/dod_receipts/OMN-13226/{dod-001-publisher-implementation,
dod-002-deploy-evidence,pr-occ-binding}/command.yaml (status PASS,
verifier!=runner, contract_sha256 bound to the rewritten contract).
- Remove stale dod-007 receipt (superseded).
Local proof: receipt-gate PASSED (3/3), OCC eligibility eligible=true,
Receipt Honesty + Receipt Hardening pre-commit gates pass.
…merge The seven omnibase_infra probes pinned ae1b6e75, a superseded head that no branch reaches after the branch was amended -- the contract claimed to read 'the pinned omnibase_infra head' while reading an orphaned commit. Repin to c8d6d214 (the live PR #2746 head). The edge-mirror probe is repinned from 31102820 to 8289023c after PR #904's branch was updated onto dev.
…2746 Every receipt in this ticket carried pr_number 2746 -- including the two whose checks read omninode_infra -- so no PASS receipt bound PR #904. That is what #904's occ-preflight and receipt gate report as pr_ticket_mismatch: 'no PASS receipt for one or more tickets binds to PR #904 or one of its commit SHAs'. The two omninode_infra items now bind #904, its branch, and its head; all twelve receipts are re-minted by executing their contract-declared check live against the rebound pins, with contract_entry_sha256 recomputed via omnibase_core.validation.validator_receipt_gate.
…+ omninode_infra#904 (#6496) * evidence(OMN-15952): OCC companion contract for the unattended renewal contract Binds the evidence for OmniNode-ai/omnibase_infra#2746 (the node contract that declares the renewal cycle) and OmniNode-ai/omninode_infra#904 (the onex-api mirror of the directive across an extra=forbid seam). Receipts follow in the next commit, once this PR's own number exists to self-bind against. * evidence(OMN-15952): receipts + self-bind for OCC#6496 Eleven receipts, all PASS, all probed live against the GitHub contents API at the producing head SHAs rather than against a local worktree -- the file this lane edited and the file the reviewer will read are then provably the same bytes. Six of the eleven are content assertions rather than PR-exists assertions: the renewal cycle present in the node contract's config block, the directive required (not optional) on the attach response, the renewal-mode enum having exactly one member, the renew-before-expiry invariant living in the model validator, assert_expiry_not_extended existing as a callable, and the edge mirror asserting field-set equality. A PR-exists receipt proves a branch was pushed; these prove what is in it. * evidence(OMN-15952): bind the self-bind receipt to OCC#6496's own commit occ-merge-eligibility rejected the PR with reason=pr_ticket_mismatch: it requires at least one PASS receipt bound to THIS PR or one of its commit SHAs, and all eleven receipts were bound to the producing omnibase_infra PR instead. The self-bind receipt now carries pr_number 6496, the OCC branch, and commit 2af48ba -- a commit of this PR, so the binding resolves against --pr-commit-sha. * evidence(OMN-15952): add the falsifiable deploy probe the ratchet requires deploy-gate rejected omnibase_infra#2746: OMN-15952 is not grandfathered and the contract declared no falsifiable deploy probe (OMN-14443). The deployed surface this ticket changes is the attach node's response shape -- a runtime image without the renewal directive serves an attach response with no renewal cycle, which is exactly the pre-OMN-15952 defect. The probe reads model_gateway_attach_response.py back from GitHub at the pinned omnibase_infra head and greps for the required field, so it goes RED the moment the field is absent or renamed. It reads a surface outside this repo, never a receipt or contract this PR authors. The live-cluster half -- docker exec against omninode-runtime, then a real attach -> expiry -> re-grant -> re-attach against deployed onex-api -- is the post-deploy acceptance test tracked on the ticket. It cannot run before the image exists, and claiming it here would be the vacuous evidence this ratchet exists to reject. * evidence(OMN-15952): put gh api in command position for the deploy probe The falsifiability parser reads the COMMAND POSITION, not the whole string. Wrapping the probe as a variable assignment put that in command position, so the parser saw ['gh', 'grep'] and rejected it as vacuous even though the call it could not see was a real gh-api readback. Rewritten in the exact form the gate's own error message blesses: gh api ... --jq .content | base64 -d | grep -q '<symbol>'. Same probe, same falsifiability, same PASS -- only the shell shape changed. Receipt regenerated against the new entry hash. * evidence(OMN-15952): rebind contract pins to the heads that actually merge The seven omnibase_infra probes pinned ae1b6e75, a superseded head that no branch reaches after the branch was amended -- the contract claimed to read 'the pinned omnibase_infra head' while reading an orphaned commit. Repin to c8d6d214 (the live PR #2746 head). The edge-mirror probe is repinned from 31102820 to 8289023c after PR #904's branch was updated onto dev. * evidence(OMN-15952): bind the omninode_infra evidence to PR #904, not #2746 Every receipt in this ticket carried pr_number 2746 -- including the two whose checks read omninode_infra -- so no PASS receipt bound PR #904. That is what #904's occ-preflight and receipt gate report as pr_ticket_mismatch: 'no PASS receipt for one or more tickets binds to PR #904 or one of its commit SHAs'. The two omninode_infra items now bind #904, its branch, and its head; all twelve receipts are re-minted by executing their contract-declared check live against the rebound pins, with contract_entry_sha256 recomputed via omnibase_core.validation.validator_receipt_gate.
OCC receipt for omnimarket PR #1264 (OMN-13226).
Registers T2 of the merge-triggered worktree reaper epic (OMN-13008):
GHA
pr-merged-publisherworkflow, canonical topiconex.evt.github.pr-merged.v1,publisher script modelled on OMN-8917, contract stub + unit/golden-chain tests all green.
Evidence-Source: 725d296
Evidence-Ticket: OMN-13226