Skip to content

evidence(OMN-16239): OCC companion for OmniNode-ai/omnibase_infra#2803 - #6722

Merged
jonahgabriel merged 3 commits into
devfrom
jonah/omn-16239-occ-companion
Aug 20, 2026
Merged

jonahgabriel merged 3 commits into
devfrom
jonah/omn-16239-occ-companion

Conversation

@jonahgabriel

Copy link
Copy Markdown
Contributor

OCC evidence companion for OmniNode-ai/omnibase_infra#2803 (OMN-16239).

What the product PR fixes

ProjectionTableTarget carried the raw contract schema straight into the schema-qualified SQL built by _execute_upsert/_execute_query, while the grant check ran the same declaration through physical_grant_schema_for_table(). For every relation still under the OMN-15359 relocation bridge the two disagreed — grant validation passed against the physical schema while the statement that actually executed named the declared one.

Verified live on the stability-test omnidash_analytics (2026-08-19, read-only information_schema probe): there is no tenant schema at all, and omninode_internal holds exactly one relation (live_events, migration 099) against 71 in public. A scan of every db_io.db_tables declaration across four repos found 39 node contracts that were emitting SQL against schemas resolving nowhere.

The fix resolves the physical schema exactly once in _resolve_projection_database_target and feeds both the grant check (threaded in as grant_schema, replacing its own second resolution) and the emitted SQL from that single value.

Evidence

Four entries, each a single-command probe pinned to an immutable git blob (single-pipe form, no nested command substitution — avoids the OMN-15710 quote-naive terminal-segment parser residual):

Entry Probe Actual stdout
...-pr-2803 PR exists / state {"number":2803,"state":"OPEN"}
...-pr-2803-red-before buggy INSERT INTO "{target.schema}" at merge-base fa3c706fa 1
...-pr-2803-green-after target.physical_schema at head 9356a4e7f 4
...-pr-2803-regr-test regression test asserts the physical-schema INSERT at head 1

This is a genuine differential, not a same-state re-read. The green-after probe was counter-checked against the merge-base blob and returns 0 there — the identifier does not exist pre-fix at all. Locally the new regression test is 5 failed / 1 passed at fa3c706fa and 6 passed at 9356a4e7f.

Every probe above was executed and its real stdout recorded in the receipt; no expected value was assumed. One prediction was corrected in the process: the green-after count was initially written as 2 and the actual run returned 4, so the contract now enumerates all four sites (physical_schemas property :1973, INSERT :2776, SELECT :2800, debug log :3234).

Why hand-authored

The born-path call-occ-autobind run for this PR (32228344745) sat QUEUED for over an hour while the omnibase_infra queue depth grew from 192 to 247 — the canonical occ_companion_emitter was not converging, so the product PR's occ-preflight / eligibility and verify / verify were both failing at "Resolve Evidence-Source" with no path forward. Follows the operator-authorized hand-authored-companion pattern established on occ#6633 / occ#6640.

If autobind later fires and mints a duplicate, this companion is the earlier one and the duplicate should be superseded rather than both merged.

Hand-authored companion with a real RED-before/GREEN-after differential: the
pre-fix buggy form present (1) at merge-base fa3c706fa and the fixed
target.physical_schema present (4) at head 9356a4e7f, counter-checked as 0 at
the merge-base so the pair is a genuine differential rather than a same-state
re-read. Every probe was executed and its actual stdout recorded.

Authored rather than waiting on the born-path emitter: call-occ-autobind run
32228344745 sat QUEUED over an hour while the infra queue grew 192 -> 247.
@coderabbitai

coderabbitai Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your current included review allowance is based on your included PR review attempts over the past 7 days.

Next review available in: 1 minute

Limit details: You’ve used the included review currently available. Your 120 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

Wait for the limit to reset, then comment @coderabbitai review or push new commits to the PR.

An organization admin can change what happens after included review limits in Billing.

How do review limits work?

CodeRabbit enforces per-developer PR review limits within each organization.

For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 02b3db7e-25d1-48de-8a1d-f02cfd2a1e8a

📥 Commits

Reviewing files that changed from the base of the PR and between c3a008a and 9de8d47.

📒 Files selected for processing (6)
  • contracts/OMN-16239.yaml
  • drift/dod_receipts/OMN-16239/dod-OmniNode-ai-omnibase_infra-pr-2803-green-after/command.yaml
  • drift/dod_receipts/OMN-16239/dod-OmniNode-ai-omnibase_infra-pr-2803-red-before/command.yaml
  • drift/dod_receipts/OMN-16239/dod-OmniNode-ai-omnibase_infra-pr-2803-regr-test/command.yaml
  • drift/dod_receipts/OMN-16239/dod-OmniNode-ai-omnibase_infra-pr-2803/command.yaml
  • drift/dod_receipts/OMN-16239/occ-self-bind-pr-6722/command.yaml

Comment @coderabbitai help to get the list of available commands.

Adds the self-bind entry occ-preflight's merge-eligibility validator needs
(every other entry binds to omnibase_infra#2803, not to this OCC PR), and
rebinds all five receipts to the post-yamlfmt contract bytes.
@jonahgabriel
jonahgabriel enabled auto-merge (squash) August 19, 2026 08:07
jonahgabriel added a commit that referenced this pull request Aug 19, 2026
Contract Compliance Check reported 3/5 PASS, 1 WARN, 1 BLOCK. Both
findings are this companion's own content, not repo-wide noise, so both
are fixed here rather than waived.

BLOCK -- dod-omn16249-producer-injected-keys. The probe fetched
handler_wiring.py through the contents API's default JSON+base64
representation and died mid-transfer: "stream error: stream ID 1;
CANCEL; received from peer" after ~15s. That file is 371,665 bytes,
which base64 inflates to ~495KB wrapped in a JSON string. Switched to
"Accept: application/vnd.github.raw", which streams the file directly
and completes in well under a second. Re-run verbatim: exit 0, output 4.
The match pattern now anchors on the assignment operator so it counts
injection SITES rather than incidental mentions of the same keys.

WARN -- occ-self-bind-pr-6725. The checker classified the probe INERT:
"no admissible probe in command position ... proves nothing", because a
bare gh pr view is not one of the admissible probe verbs. Switched to
gh api, which is admissible and asserts the same fact against the live
API. Re-run verbatim: exit 0, output "6725 open".

Both probes were re-executed by this lane, not edited to match a desired
result, and the runner field now names the lane that actually ran them.
All five contract_entry_sha256 values recomputed and verified;
validate-yaml passes.

The producer description is a literal block scalar, not folded: the
OMN-15479 yamlfmt-contamination gate correctly rejected the folded form
once the description carried an internal newline.

The remaining reds (no-noncanonical-lifecycle-classes, reason-graph,
tests+coverage shadow) sit outside CI Summary's gating set and are
shared with the unrelated #6722, so they are repo-wide.

Refs OMN-16249.
jonahgabriel added a commit that referenced this pull request Aug 19, 2026
…6725)

* evidence(OMN-16249): OCC companion for OmniNode-ai/omnimarket#2109

OCC companion contract + receipts for OmniNode-ai/omnimarket PR #2109 (matches
the projection injected-key seam across the infra/market boundary). No OCC
companion or contract existed for this ticket.

Net-new contract `contracts/OMN-16249.yaml` + 4 PASS receipts:
- dod-OmniNode-ai-omnimarket-pr-2109 -- live PR existence/head/scope probe
- dod-omn16249-producer-injected-keys -- omnibase_infra's handler_wiring.py
  at the pinned rev injects exactly the 4 documented keys (_db, _event_type,
  _topic, _envelope_id), verified via the GitHub contents API against the
  immutable ref
- dod-omn16249-consumer-widened-key-set -- omnimarket's handler_shim.py at
  the PR head declares RUNTIME_INJECTED_KEYS as the matching 4-key frozenset
- dod-omn16249-fail-closed-drift-guard-and-tests -- differential proof,
  live-executed on the .200 gate host: the seam regression suite (19 passed)
  and an independent live introspection of the installed omnibase_infra
  module reproducing the same 4-key set

Self-bind entry to follow in a second commit once this PR's number is known
(established pattern -- see OCC#6677/OMN-16170, OCC#6702/OMN-16089).

Cites: OMN-16249

* evidence(OMN-16249): self-bind OCC companion PR #6723

Appends occ-self-bind-pr-6723 to contracts/OMN-16249.yaml + its PASS receipt,
binding this companion to its own OCC PR number now that it is known. The
four prior dod_evidence entries are unchanged (append-only, per-entry hash
verified stable).

Cites: OMN-16249

* evidence(OMN-16249): correct fabricated commit_sha in the self-bind receipt

The self-bind receipt recorded commit_sha 3f35bfa939ddb6da... which does
not exist in this repository — 'git cat-file -t' fails on it. It shares
only the first 10 hex characters with the real companion commit
(3f35bfa...), a prefix match that cannot occur by chance, so the
value was a real short prefix with an invented remainder rather than a
stale or mis-copied SHA.

A receipt asserting PASS against a commit that does not exist is exactly
the class of unverifiable evidence receipts exist to prevent. Corrected to
the actual parent commit and re-verified with git cat-file.

The other four receipts' cross-repo SHAs were audited and are genuine:
8b66eaa3... is omnimarket#2109's real head, and 6fdbba6d... is a real
omnibase_infra commit (the OMN-14498 #2672 merge).

Refs OMN-16249.

* evidence(OMN-16249): rebind self-bind receipt to OCC#6725

PR #6723's CI run never materialized into jobs — status pending, zero
jobs, updated_at frozen at creation, reproduced across three head SHAs
and four re-trigger attempts while other OCC PRs expanded 30 jobs
normally. The stall was bound to that PR's identity, so this branch is
opened as a fresh PR rather than retried a fifth time.

Rebinds the self-bind evidence item and receipt from #6723 to #6725 and
recomputes contract_entry_sha256 for the changed entry. The probe was
re-executed against the new PR, not edited: 'gh pr view 6725 --json
number,state' returns {"number":6725,"state":"OPEN"} verbatim.

All five receipts re-verified against their contract entries with
omnibase_core compute_contract_entry_sha256 — all match.

Refs OMN-16249.

* evidence(OMN-16249): fix the two Contract Compliance findings on #6725

Contract Compliance Check reported 3/5 PASS, 1 WARN, 1 BLOCK. Both
findings are this companion's own content, not repo-wide noise, so both
are fixed here rather than waived.

BLOCK -- dod-omn16249-producer-injected-keys. The probe fetched
handler_wiring.py through the contents API's default JSON+base64
representation and died mid-transfer: "stream error: stream ID 1;
CANCEL; received from peer" after ~15s. That file is 371,665 bytes,
which base64 inflates to ~495KB wrapped in a JSON string. Switched to
"Accept: application/vnd.github.raw", which streams the file directly
and completes in well under a second. Re-run verbatim: exit 0, output 4.
The match pattern now anchors on the assignment operator so it counts
injection SITES rather than incidental mentions of the same keys.

WARN -- occ-self-bind-pr-6725. The checker classified the probe INERT:
"no admissible probe in command position ... proves nothing", because a
bare gh pr view is not one of the admissible probe verbs. Switched to
gh api, which is admissible and asserts the same fact against the live
API. Re-run verbatim: exit 0, output "6725 open".

Both probes were re-executed by this lane, not edited to match a desired
result, and the runner field now names the lane that actually ran them.
All five contract_entry_sha256 values recomputed and verified;
validate-yaml passes.

The producer description is a literal block scalar, not folded: the
OMN-15479 yamlfmt-contamination gate correctly rejected the folded form
once the description carried an internal newline.

The remaining reds (no-noncanonical-lifecycle-classes, reason-graph,
tests+coverage shadow) sit outside CI Summary's gating set and are
shared with the unrelated #6722, so they are repo-wide.

Refs OMN-16249.
@jonahgabriel
jonahgabriel merged commit 1133155 into dev Aug 20, 2026
101 of 102 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-16239-occ-companion branch August 20, 2026 10:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant