Skip to content

receipt(OMN-13226): GitHub Action publisher for onex.evt.github.pr-merged.v1 - #2746

Merged
jonahgabriel merged 4 commits into
devfrom
jonahgabriel/omn-13226-occ-receipt
Jun 18, 2026
Merged

jonahgabriel merged 4 commits into
devfrom
jonahgabriel/omn-13226-occ-receipt

Conversation

@jonahgabriel

Copy link
Copy Markdown
Contributor

OCC receipt for omnimarket PR #1264 (OMN-13226).

Registers T2 of the merge-triggered worktree reaper epic (OMN-13008):
GHA pr-merged-publisher workflow, canonical topic onex.evt.github.pr-merged.v1,
publisher script modelled on OMN-8917, contract stub + unit/golden-chain tests all green.

Evidence-Source: 725d296
Evidence-Ticket: OMN-13226

@coderabbitai

coderabbitai Bot commented Jun 18, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@jonahgabriel, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 2 hours, 21 minutes, and 5 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 2bbe9332-9ac2-44bd-bab2-a965bcb0d98d

📥 Commits

Reviewing files that changed from the base of the PR and between a56001a and 994b5bf.

📒 Files selected for processing (4)
  • contracts/OMN-13226.yaml
  • drift/dod_receipts/OMN-13226/dod-001-publisher-implementation/command.yaml
  • drift/dod_receipts/OMN-13226/dod-002-deploy-evidence/command.yaml
  • drift/dod_receipts/OMN-13226/pr-occ-binding/command.yaml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonahgabriel/omn-13226-occ-receipt

Comment @coderabbitai help to get the list of available commands and usage tips.

…rged.v1

OCC receipt for omnimarket PR #1264. Registers T2 of the merge-triggered
worktree reaper epic (OMN-13008): GHA pr-merged-publisher workflow,
canonical topic onex.evt.github.pr-merged.v1, publisher script modelled
on OMN-8917, contract stub + unit/golden-chain tests all green.
Adds dod-007 with rpk topic produce check_value to satisfy the
deploy-gate requirement (OMN-8912). The publisher surface is the
GHA workflow step; node_pr_merged_projection handler deferred to T3.
@jonahgabriel
jonahgabriel force-pushed the jonahgabriel/omn-13226-occ-receipt branch from d7ff6e2 to 35703af Compare June 18, 2026 15:02
…erged publisher

- Rewrite contracts/OMN-13226.yaml modelled on OMN-13220 (3 dod_evidence items,
  each check greps a PASS receipt; dod-002 carries 'rpk topic produce' deploy
  evidence for the deploy-gate; pr-occ-binding satisfies eligibility pr_ticket_mismatch).
- Add drift/dod_receipts/OMN-13226/{dod-001-publisher-implementation,
  dod-002-deploy-evidence,pr-occ-binding}/command.yaml (status PASS,
  verifier!=runner, contract_sha256 bound to the rewritten contract).
- Remove stale dod-007 receipt (superseded).

Local proof: receipt-gate PASSED (3/3), OCC eligibility eligible=true,
Receipt Honesty + Receipt Hardening pre-commit gates pass.
@jonahgabriel
jonahgabriel added this pull request to the merge queue Jun 18, 2026
Merged via the queue into dev with commit a1d578a Jun 18, 2026
37 checks passed
@jonahgabriel
jonahgabriel deleted the jonahgabriel/omn-13226-occ-receipt branch June 18, 2026 15:36
jonahgabriel added a commit that referenced this pull request Aug 14, 2026
…merge

The seven omnibase_infra probes pinned ae1b6e75, a superseded head that no
branch reaches after the branch was amended -- the contract claimed to read
'the pinned omnibase_infra head' while reading an orphaned commit. Repin to
c8d6d214 (the live PR #2746 head). The edge-mirror probe is repinned from
31102820 to 8289023c after PR #904's branch was updated onto dev.
jonahgabriel added a commit that referenced this pull request Aug 14, 2026
…2746

Every receipt in this ticket carried pr_number 2746 -- including the two whose
checks read omninode_infra -- so no PASS receipt bound PR #904. That is what
#904's occ-preflight and receipt gate report as pr_ticket_mismatch: 'no PASS
receipt for one or more tickets binds to PR #904 or one of its commit SHAs'.

The two omninode_infra items now bind #904, its branch, and its head; all
twelve receipts are re-minted by executing their contract-declared check live
against the rebound pins, with contract_entry_sha256 recomputed via
omnibase_core.validation.validator_receipt_gate.
jonahgabriel added a commit that referenced this pull request Aug 14, 2026
…+ omninode_infra#904 (#6496)

* evidence(OMN-15952): OCC companion contract for the unattended renewal contract

Binds the evidence for OmniNode-ai/omnibase_infra#2746 (the node contract that
declares the renewal cycle) and OmniNode-ai/omninode_infra#904 (the onex-api
mirror of the directive across an extra=forbid seam).

Receipts follow in the next commit, once this PR's own number exists to
self-bind against.

* evidence(OMN-15952): receipts + self-bind for OCC#6496

Eleven receipts, all PASS, all probed live against the GitHub contents API at
the producing head SHAs rather than against a local worktree -- the file this
lane edited and the file the reviewer will read are then provably the same
bytes.

Six of the eleven are content assertions rather than PR-exists assertions:
the renewal cycle present in the node contract's config block, the directive
required (not optional) on the attach response, the renewal-mode enum having
exactly one member, the renew-before-expiry invariant living in the model
validator, assert_expiry_not_extended existing as a callable, and the edge
mirror asserting field-set equality. A PR-exists receipt proves a branch was
pushed; these prove what is in it.

* evidence(OMN-15952): bind the self-bind receipt to OCC#6496's own commit

occ-merge-eligibility rejected the PR with reason=pr_ticket_mismatch: it
requires at least one PASS receipt bound to THIS PR or one of its commit
SHAs, and all eleven receipts were bound to the producing omnibase_infra PR
instead. The self-bind receipt now carries pr_number 6496, the OCC branch,
and commit 2af48ba -- a commit of this PR,
so the binding resolves against --pr-commit-sha.

* evidence(OMN-15952): add the falsifiable deploy probe the ratchet requires

deploy-gate rejected omnibase_infra#2746: OMN-15952 is not grandfathered and
the contract declared no falsifiable deploy probe (OMN-14443).

The deployed surface this ticket changes is the attach node's response shape --
a runtime image without the renewal directive serves an attach response with no
renewal cycle, which is exactly the pre-OMN-15952 defect. The probe reads
model_gateway_attach_response.py back from GitHub at the pinned omnibase_infra
head and greps for the required field, so it goes RED the moment the field is
absent or renamed. It reads a surface outside this repo, never a receipt or
contract this PR authors.

The live-cluster half -- docker exec against omninode-runtime, then a real
attach -> expiry -> re-grant -> re-attach against deployed onex-api -- is the
post-deploy acceptance test tracked on the ticket. It cannot run before the
image exists, and claiming it here would be the vacuous evidence this ratchet
exists to reject.

* evidence(OMN-15952): put gh api in command position for the deploy probe

The falsifiability parser reads the COMMAND POSITION, not the whole string.
Wrapping the probe as a variable assignment put that in command position, so
the parser saw ['gh', 'grep'] and rejected it as vacuous even though the call
it could not see was a real gh-api readback. Rewritten in the exact form the
gate's own error message blesses: gh api ... --jq .content | base64 -d |
grep -q '<symbol>'.

Same probe, same falsifiability, same PASS -- only the shell shape changed.
Receipt regenerated against the new entry hash.

* evidence(OMN-15952): rebind contract pins to the heads that actually merge

The seven omnibase_infra probes pinned ae1b6e75, a superseded head that no
branch reaches after the branch was amended -- the contract claimed to read
'the pinned omnibase_infra head' while reading an orphaned commit. Repin to
c8d6d214 (the live PR #2746 head). The edge-mirror probe is repinned from
31102820 to 8289023c after PR #904's branch was updated onto dev.

* evidence(OMN-15952): bind the omninode_infra evidence to PR #904, not #2746

Every receipt in this ticket carried pr_number 2746 -- including the two whose
checks read omninode_infra -- so no PASS receipt bound PR #904. That is what
#904's occ-preflight and receipt gate report as pr_ticket_mismatch: 'no PASS
receipt for one or more tickets binds to PR #904 or one of its commit SHAs'.

The two omninode_infra items now bind #904, its branch, and its head; all
twelve receipts are re-minted by executing their contract-declared check live
against the rebound pins, with contract_entry_sha256 recomputed via
omnibase_core.validation.validator_receipt_gate.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant