Skip to content

evidence(OMN-14350): OCC fan-out companion for omnibase_infra #2258 (non-canonical ratchet gate) - #3922

Merged
jonahgabriel merged 5 commits into
devfrom
jonah/omn-14350-occ-infra-2258
Jul 11, 2026
Merged

jonahgabriel merged 5 commits into
devfrom
jonah/omn-14350-occ-infra-2258

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jul 11, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fan-out OCC evidence companion for OMN-14350 / omnibase_infra #2258 — the FIRST consumer of the omnibase_core canary ratchet (#1430).

Appends to the existing on-dev OMN-14350 contract (does not mutate the merged #1430 receipts):

  • dod-fanout-2258: PASS receipt binding chore(OMN-12765): backmerge OCC main evidence to dev #2258 head 52ee74920378c48e16a537bf4d03a18c0515e89d (independent adversarial verifier: pin=63635097 exact, ratchet hook resolves core@63635097 + PASSES vs infra 100-FQN allowlist, fail-closed proven through consumer wiring, --check-stale exit 0 day-one, clean-root minimal)
  • dod-occ-self-2258: OCC self-bind for this PR

The three merged #1430 receipts (dod-001/dod-deploy-assessment/dod-occ-self) are grandfathered (OMN-13888) — not re-hashed. Eligibility validator confirms #2258 eligible=true locally.

Draft to prevent premature auto-merge; #2258 resolves via headRefOid while open.

Evidence-Ticket: OMN-14350

Summary by CodeRabbit

  • Documentation
    • Clarified contract metadata for the canary validation gate and per-PR consumer fan-out tracking.
    • Added verification evidence covering pinned checks, allowlist resolution, deterministic eligibility, and fail-closed behavior.
  • Chores
    • Recorded successful validation receipts, including command results, execution details, and integrity checks.
    • Added a replacement record for superseded verification evidence.

@coderabbitai

coderabbitai Bot commented Jul 11, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The PR updates the OMN-14350 contract to document canary fan-out evidence and adds PASS command receipts for fan-out and OCC self-binding verification, including a superseding OCC receipt.

Changes

Ratchet evidence

Layer / File(s) Summary
Contract evidence definitions
contracts/OMN-14350.yaml
Updates the canary scope metadata and adds dod-fanout-2258 and dod-occ-self-2258 evidence entries with PASS checks.
Verification and supersession receipts
drift/dod_receipts/OMN-14350/...
Adds fan-out and OCC self-binding command receipts and records the superseding replacement for the prior OCC receipt.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately reflects the PR’s main change: adding an OMN-14350 OCC fan-out evidence companion for omnibase_infra #2258 and the ratchet gate context.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-14350-occ-infra-2258

Comment @coderabbitai help to get the list of available commands.

@jonahgabriel
jonahgabriel marked this pull request as ready for review July 11, 2026 11:03
@jonahgabriel
jonahgabriel merged commit afe5da2 into dev Jul 11, 2026
49 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-14350-occ-infra-2258 branch July 11, 2026 11:17

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@drift/dod_receipts/OMN-14350/dod-fanout-2258/command.yaml`:
- Around line 14-23: Update probe_stdout in the command receipt to contain only
the actual stdout produced by probe_command, which runs pre-commit run
no-noncanonical-lifecycle-classes --all-files. Remove the unrelated ls-tree,
fail-closed, --check-stale, and clean-root claims, or represent those checks in
separate receipts.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: cd54b8f8-ada3-41c6-8542-f6dedb3ad72f

📥 Commits

Reviewing files that changed from the base of the PR and between 15604f6 and 65ca4e8.

📒 Files selected for processing (4)
  • contracts/OMN-14350.yaml
  • drift/dod_receipts/OMN-14350/dod-fanout-2258/command.yaml
  • drift/dod_receipts/OMN-14350/dod-occ-pr-3920/command.supersede.0001.yaml
  • drift/dod_receipts/OMN-14350/dod-occ-self-2258/command.yaml

Comment on lines +14 to +23
probe_command: >-
cd omni_worktrees/OMN-14350/omnibase_infra && env -u PYTHONPATH uv run pre-commit run no-noncanonical-lifecycle-classes
--all-files
probe_stdout: |
pin: .pre-commit-config.yaml rev = 63635097705d832e0ee9c4811093efb31349105c (exact; #1430 squash-merge, ancestor of core dev; no @dev)
core@63635097 ls-tree: validator module + finding model + .pre-commit-hooks.yaml export (line 445) all present
ratchet hook (isolated env resolves core@63635097): Passed vs infra .onex_ratchets allowlist (100 FQNs)
fail-closed through consumer wiring: class FooService + BespokeDeployManager in infra src -> hook Failed (RED), both flagged with omnibase_infra.* FQNs
--check-stale against infra tree + 100-FQN allowlist: exit 0 (green day-one, no cleanup forced)
clean-root: validate_clean_root.py adds exactly .onex_ratchets (+3 lines, one dir, no wildcard); onex-validate-clean-root Passed

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail
files=$(rg --files --hidden \
  -g '.pre-commit-config.yaml' \
  -g '.pre-commit-hooks.yaml' \
  -g 'cron-tick-prompt.md')
rg -n -C 4 \
  'no-noncanonical-lifecycle-classes|--check-stale|validate_clean_root|onex-validate-clean-root' \
  $files

Repository: OmniNode-ai/onex_change_control

Length of output: 917


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Inspect the receipt file around the cited lines
wc -l drift/dod_receipts/OMN-14350/dod-fanout-2258/command.yaml
cat -n drift/dod_receipts/OMN-14350/dod-fanout-2258/command.yaml | sed -n '1,80p'

# Inspect the runbook section referenced by the original comment
wc -l docs/runbooks/cron-tick-prompt.md
cat -n docs/runbooks/cron-tick-prompt.md | sed -n '1,120p'

# Inspect any schema/model references for the receipt structure
rg -n "probe_command|probe_stdout|command.yaml|dod_receipts|cron-tick-prompt" -S .

Repository: OmniNode-ai/onex_change_control

Length of output: 50388


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "--- command.yaml ---"
cat -n drift/dod_receipts/OMN-14350/dod-fanout-2258/command.yaml | sed -n '1,80p'

echo "--- cron-tick-prompt.md ---"
cat -n docs/runbooks/cron-tick-prompt.md | sed -n '1,80p'

echo "--- nearby receipts with multi-line probe_stdout ---"
for f in \
  drift/dod_receipts/OMN-13341/dod-gate-fail-closed-proof/command.yaml \
  drift/dod_receipts/OMN-13341/dod-occ-pr-self/command.yaml \
  drift/dod_receipts/OMN-13085/dod-pre-commit-all-files/command.yaml \
  drift/dod_receipts/OMN-13201/pr-occ-2716/command.yaml
do
  echo "### $f"
  cat -n "$f" | sed -n '1,60p'
done

Repository: OmniNode-ai/onex_change_control

Length of output: 13236


Make probe_stdout literal output from probe_command
drift/dod_receipts/OMN-14350/dod-fanout-2258/command.yaml:14-23 — probe_command runs only pre-commit run no-noncanonical-lifecycle-classes --all-files, but probe_stdout includes extra ls-tree, fail-closed, --check-stale, and clean-root claims that were not produced by that command. Keep only the pre-commit stdout here, or move the other checks into separate receipts.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@drift/dod_receipts/OMN-14350/dod-fanout-2258/command.yaml` around lines 14 -
23, Update probe_stdout in the command receipt to contain only the actual stdout
produced by probe_command, which runs pre-commit run
no-noncanonical-lifecycle-classes --all-files. Remove the unrelated ls-tree,
fail-closed, --check-stale, and clean-root claims, or represent those checks in
separate receipts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant