Skip to content

evidence(OMN-15255): deploy-scope falsifiable probe for the composite runner readiness classifier - #5159

Merged
jonahgabriel merged 2 commits into
devfrom
jonah/omn-15255-deploy-evidence
Jul 27, 2026
Merged

jonahgabriel merged 2 commits into
devfrom
jonah/omn-15255-deploy-evidence

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

Why

omnibase_infra#2500 touches runtime paths (node_runner_fleet_health_compute + node_runner_health_snapshot_effect), so the OMN-8912 deploy gate fails closed with:

DEPLOY GATE FAILED: PR touches runtime paths but no cited ticket has deploy DoD evidence. Tickets found but declaring no falsifiable deploy probe: ['OMN-15255']

This adds that probe. Same shape and same rationale as OCC#5117 did for OMN-15233.

The probe is falsifiable — verified both directions in-session

gh api 'repos/OmniNode-ai/omnibase_infra/contents/.../handler_runner_fleet_health_evaluate.py?ref=4bc8caf03' \
  --jq .content | base64 -d | grep -q 'def _evaluate_readiness_signals'
ref exit
4bc8caf03 (product head) 0 — 357:def _evaluate_readiness_signals(
dev 1 — absent

It reads the product source over the GitHub contents API. It does not grep this receipt, this contract, or anything else authored by the same PR — the rejected pattern the gate calls out explicitly.

Append-only

One new dod_evidence entry + one new receipt directory. No existing entry modified, so every prior receipt's contract_entry_sha256 stays valid.

  • scripts/validation/check_receipt_hardening.py — exit 0
  • pre-commit run --files <both> — all Passed/Skipped, including Receipt Honesty Gate, Contract Substance Floor, Receipt Hardening Gate, Evidence-Commit SHA Existence Gate

Known follow-up: re-pin after merge

The probe pins the product branch head 4bc8caf03 because #2500 has not merged. Per reference_never_pin_a_feature_branch_head, this should be re-pinned to the squash commit on dev once #2500 lands — the same re-pin OMN-15217 did on #5141. Pinning dev today would be correctly RED and would wedge the gate.

Merge stays Codex's. No merge, no --auto, no draft.

Summary by CodeRabbit

  • Documentation

    • Added deployment readiness verification records tied to a pinned repository revision.
    • Added a recorded check for the self-binding pull request state.
    • Included verification outcomes, timestamps, commit references, and execution details for auditability.
  • Chores

    • Added structured evidence receipts documenting successful validation checks.

… readiness classifier

omnibase_infra#2500 touches runtime paths, so the OMN-8912 deploy gate requires a
dod_evidence item whose exit status depends on the state of the deployed system.

The probe reads the product source over the GitHub contents API at the pinned
product commit and asserts the conjunction classifier is present. Falsifiability
was verified in the same session by running the identical probe against ref=dev:
exit 1 (absent) vs exit 0 (present) at 4bc8caf03 — it is not a self-read of this
receipt or contract.

Append-only: one new dod_evidence entry + one new receipt directory. No existing
entry modified.
@coderabbitai

coderabbitai Bot commented Jul 27, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds two OMN-15255 dod_evidence contract entries and matching PASS command receipts: one verifies a pinned readiness function in repository contents, and the other verifies the state of OCC self-bind PR 5159.

Changes

OMN-15255 evidence verification

Layer / File(s) Summary
Evidence contract declarations
contracts/OMN-15255.yaml
Adds deploy-readiness and OCC self-bind command evidence definitions.
Recorded command receipts
drift/dod_receipts/OMN-15255/.../command.yaml
Records the pinned readiness probe and PR 5159 state probe with PASS results, outputs, hashes, and execution metadata.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested labels: occ:machine-minted

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: adding a falsifiable deploy-scope evidence probe for the runner readiness classifier.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-15255-deploy-evidence

Comment @coderabbitai help to get the list of available commands.

occ-preflight rejected #5159 with reason pr_ticket_mismatch: no PASS receipt bound
to PR #5159 or one of its commit SHAs. The deploy-probe receipt binds to product
PR #2500, not to this OCC PR, so the companion needs its own self-bind — the same
entry the autobind mints for machine-generated companions (occ-self-bind-pr-5147).

Append-only: one new entry + one new receipt directory.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@contracts/OMN-15255.yaml`:
- Around line 46-48: Replace both live GitHub API check_value commands in the
contract checks with local grep checks against their corresponding committed
receipt files, using the required '^status: PASS$' pattern documented by
contract_compliance_check.py. Keep the validation hermetic and leave GitHub
probes out of the contract runner.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 55eb6790-caaf-45b5-8f31-1c6a8f6390ad

📥 Commits

Reviewing files that changed from the base of the PR and between 1cac905 and 5af7102.

📒 Files selected for processing (3)
  • contracts/OMN-15255.yaml
  • drift/dod_receipts/OMN-15255/dod-deploy-runner-readiness-composite/command.yaml
  • drift/dod_receipts/OMN-15255/occ-self-bind-pr-5159/command.yaml

Comment thread contracts/OMN-15255.yaml
Comment on lines +46 to +48
check_value: >-
gh api 'repos/OmniNode-ai/omnibase_infra/contents/src/omnibase_infra/nodes/node_runner_fleet_health_compute/handlers/handler_runner_fleet_health_evaluate.py?ref=4bc8caf03'
--jq .content | base64 -d | grep -q 'def _evaluate_readiness_signals'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

Keep contract checks hermetic by verifying the committed receipts.

These check_value commands perform live GitHub API calls during contract validation. The contract runner executes them in CI, where external network access is unavailable or intentionally rejected. Replace both commands with grep -q '^status: PASS$' against their corresponding committed receipt files; the GitHub probes should remain out-of-band only.

src/onex_change_control/scripts/contract_compliance_check.py:70-140 documents this required receipt-grep pattern.

Proposed fix
-        check_value: >-
-          gh api 'repos/OmniNode-ai/omnibase_infra/contents/src/omnibase_infra/nodes/node_runner_fleet_health_compute/handlers/handler_runner_fleet_health_evaluate.py?ref=4bc8caf03'
-          --jq .content | base64 -d | grep -q 'def _evaluate_readiness_signals'
+        check_value: >-
+          grep -q '^status: PASS$'
+          "$CONTRACT_REPO_DIR/drift/dod_receipts/OMN-15255/dod-deploy-runner-readiness-composite/command.yaml"

-        check_value: "gh pr view 5159 --repo OmniNode-ai/onex_change_control --json number,state"
+        check_value: >-
+          grep -q '^status: PASS$'
+          "$CONTRACT_REPO_DIR/drift/dod_receipts/OMN-15255/occ-self-bind-pr-5159/command.yaml"

Also applies to: 55-55

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@contracts/OMN-15255.yaml` around lines 46 - 48, Replace both live GitHub API
check_value commands in the contract checks with local grep checks against their
corresponding committed receipt files, using the required '^status: PASS$'
pattern documented by contract_compliance_check.py. Keep the validation hermetic
and leave GitHub probes out of the contract runner.

@jonahgabriel
jonahgabriel merged commit 8b30577 into dev Jul 27, 2026
62 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-15255-deploy-evidence branch July 27, 2026 18:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant