Skip to content

evidence(OMN-16041): promotion receipt on OCC main for omnibase_infra#2744 (v0.38.5) - #6490

Closed
jonahgabriel wants to merge 2 commits into
mainfrom
jonah/omn-16041-promotion-receipt-main
Closed

jonahgabriel wants to merge 2 commits into
mainfrom
jonah/omn-16041-promotion-receipt-main

Conversation

@jonahgabriel

Copy link
Copy Markdown
Contributor

OMN-16041 — promotion evidence on OCC main for omnibase_infra#2744 (v0.38.5 dev→main)

Net-new files only. This is the main-side half of the evidence for the omnibase_infra dev→main promotion OmniNode-ai/omnibase_infra#2744.

Why this targets main and not dev

The receipt gate runs in main-release policy mode for any PR whose base is main, and that mode rejects evidence that is not yet on OCC main. Verbatim, from the promotion PR's verify / verify run:

##[notice]receipt-gate target_branch=main policy_mode=main-release
##[error]RECEIPT GATE FAILED: main release policy requires merged OCC evidence.
Resolve Evidence-Source to an OCC commit on main before promotion or hotfix merge;
current evidence source kind is open-pr.

The dev-side companion is open as #6489. OCC dev is 3457 commits ahead of main, so a dev merge does not reach main in any useful timeframe — hence this direct main PR, matching the existing pattern for main-release evidence in this repo (#3595, #3732, #4394).

Why the contract file here is not a copy of the dev-side one

contracts/OMN-16041.yaml does not exist on main. Copying the dev-side file wholesale fails lint_contract_check_values on main, because that file also carries three autobind-generated entries with hardcoded PR numbers (gh pr view 1989 ..., gh pr view 6463 ...) which main's linter rejects as legacy-gh-pr. Those entries belong to the ticket's omniclaude-side work and have nothing to do with this promotion.

So this file carries only the promotion entry. That is not a loss of binding: contract_entry_sha256 hashes the entry plus a pinned header subset (ticket_id, schema_version), not the whole file, so the entry hash is identical on both branches — sha256:7274b75d…. Only contract_sha256 (a raw-byte digest) differs between the two, and each receipt copy carries the digest of the file it actually sits next to.

The probe

Reads three files from omnibase_infra at the exact promotion head 3dd848d31857669592f528958b9fd1bd45a7c0b2 via gh api .../contents/...?ref=<sha> — an immutable ref — and asserts:

  1. pyproject.toml declares version = "0.38.5" and pins omnibase-core==0.46.8, omnibase-spi==0.23.1, omnibase-compat==0.5.6 (all published; the currently-published omnibase-infra 0.36.1 pins omnibase-spi >=0.21,<0.22, which cannot resolve against the published 0.23.1 — that unresolvable pin chain is the defect this promotion exists to clear).
  2. Neither of the two hand-resolved runner-health handlers contains os.environ or os.getenv. Those two files were the promotion's only merge conflicts; this is the property that distinguishes the forward-port that was performed from the dev-wins resolution that check-env-reads rejects.

Fail-closed: a failed gh api fetch exits non-zero via || exit 1 rather than leaving an empty file that would trivially satisfy the absence half.

Recorded run — real output, exit 0:

MISSING: []
FORBIDDEN_PRESENT: []
OMN-16041-PROMOTION-PROBE-PASS: exact-head content confirms v0.38.5 with published core/spi/compat pins and zero env reads in the two forward-ported runner-health handlers

lint_contract_check_values.py → exit 0 on this branch. Hashes were recomputed after the repo's yamlfmt hook reflowed the contract, so they bind the landed bytes and not a pre-format draft.

@coderabbitai

coderabbitai Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: e1bb463e-6bc6-4816-bfb1-0b8411b87e75

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@jonahgabriel

Copy link
Copy Markdown
Contributor Author

Superseded by #6491 — same commit content, head renamed to hotfix/* so this repo's main-target-guard admits it (it accepts only dev or hotfix/* against main).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant