Repository navigation
evidence(OMN-15255): deploy-scope falsifiable probe for the composite runner readiness classifier - #5159
Conversation
… readiness classifier omnibase_infra#2500 touches runtime paths, so the OMN-8912 deploy gate requires a dod_evidence item whose exit status depends on the state of the deployed system. The probe reads the product source over the GitHub contents API at the pinned product commit and asserts the conjunction classifier is present. Falsifiability was verified in the same session by running the identical probe against ref=dev: exit 1 (absent) vs exit 0 (present) at 4bc8caf03 — it is not a self-read of this receipt or contract. Append-only: one new dod_evidence entry + one new receipt directory. No existing entry modified.
📝 WalkthroughWalkthroughAdds two OMN-15255 ChangesOMN-15255 evidence verification
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
occ-preflight rejected #5159 with reason pr_ticket_mismatch: no PASS receipt bound to PR #5159 or one of its commit SHAs. The deploy-probe receipt binds to product PR #2500, not to this OCC PR, so the companion needs its own self-bind — the same entry the autobind mints for machine-generated companions (occ-self-bind-pr-5147). Append-only: one new entry + one new receipt directory.
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@contracts/OMN-15255.yaml`:
- Around line 46-48: Replace both live GitHub API check_value commands in the
contract checks with local grep checks against their corresponding committed
receipt files, using the required '^status: PASS$' pattern documented by
contract_compliance_check.py. Keep the validation hermetic and leave GitHub
probes out of the contract runner.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 55eb6790-caaf-45b5-8f31-1c6a8f6390ad
📒 Files selected for processing (3)
contracts/OMN-15255.yamldrift/dod_receipts/OMN-15255/dod-deploy-runner-readiness-composite/command.yamldrift/dod_receipts/OMN-15255/occ-self-bind-pr-5159/command.yaml
| check_value: >- | ||
| gh api 'repos/OmniNode-ai/omnibase_infra/contents/src/omnibase_infra/nodes/node_runner_fleet_health_compute/handlers/handler_runner_fleet_health_evaluate.py?ref=4bc8caf03' | ||
| --jq .content | base64 -d | grep -q 'def _evaluate_readiness_signals' |
There was a problem hiding this comment.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
Keep contract checks hermetic by verifying the committed receipts.
These check_value commands perform live GitHub API calls during contract validation. The contract runner executes them in CI, where external network access is unavailable or intentionally rejected. Replace both commands with grep -q '^status: PASS$' against their corresponding committed receipt files; the GitHub probes should remain out-of-band only.
src/onex_change_control/scripts/contract_compliance_check.py:70-140 documents this required receipt-grep pattern.
Proposed fix
- check_value: >-
- gh api 'repos/OmniNode-ai/omnibase_infra/contents/src/omnibase_infra/nodes/node_runner_fleet_health_compute/handlers/handler_runner_fleet_health_evaluate.py?ref=4bc8caf03'
- --jq .content | base64 -d | grep -q 'def _evaluate_readiness_signals'
+ check_value: >-
+ grep -q '^status: PASS$'
+ "$CONTRACT_REPO_DIR/drift/dod_receipts/OMN-15255/dod-deploy-runner-readiness-composite/command.yaml"
- check_value: "gh pr view 5159 --repo OmniNode-ai/onex_change_control --json number,state"
+ check_value: >-
+ grep -q '^status: PASS$'
+ "$CONTRACT_REPO_DIR/drift/dod_receipts/OMN-15255/occ-self-bind-pr-5159/command.yaml"Also applies to: 55-55
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@contracts/OMN-15255.yaml` around lines 46 - 48, Replace both live GitHub API
check_value commands in the contract checks with local grep checks against their
corresponding committed receipt files, using the required '^status: PASS$'
pattern documented by contract_compliance_check.py. Keep the validation hermetic
and leave GitHub probes out of the contract runner.
Why
omnibase_infra#2500touches runtime paths (node_runner_fleet_health_compute+node_runner_health_snapshot_effect), so the OMN-8912 deploy gate fails closed with:This adds that probe. Same shape and same rationale as OCC#5117 did for OMN-15233.
The probe is falsifiable — verified both directions in-session
4bc8caf03(product head)357:def _evaluate_readiness_signals(devIt reads the product source over the GitHub contents API. It does not grep this receipt, this contract, or anything else authored by the same PR — the rejected pattern the gate calls out explicitly.
Append-only
One new
dod_evidenceentry + one new receipt directory. No existing entry modified, so every prior receipt'scontract_entry_sha256stays valid.scripts/validation/check_receipt_hardening.py— exit 0pre-commit run --files <both>— all Passed/Skipped, including Receipt Honesty Gate, Contract Substance Floor, Receipt Hardening Gate, Evidence-Commit SHA Existence GateKnown follow-up: re-pin after merge
The probe pins the product branch head
4bc8caf03because #2500 has not merged. Perreference_never_pin_a_feature_branch_head, this should be re-pinned to the squash commit ondevonce #2500 lands — the same re-pin OMN-15217 did on #5141. Pinningdevtoday would be correctly RED and would wedge the gate.Merge stays Codex's. No merge, no
--auto, no draft.Summary by CodeRabbit
Documentation
Chores