Repository navigation
fix(OMN-10789): add OCC contract and receipt for delegation compliance migration - #898
Conversation
…e migration Receipt gate on omniclaude PR #1557 fails with missing_contract for OMN-10789. Adds the contract and unit test receipt to unblock merge.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
✅ Files skipped from review due to trivial changes (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughA new change control contract for ticket OMN-10789 establishes database migration requirements for the ChangesMigration Contract & Test Evidence
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~4 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
contracts/OMN-10789.yaml (1)
23-25: ⚡ Quick winStrengthen receipt validation to reduce false-positive gate passes.
At Line 23–25, the check only asserts PASS status and ticket_id. Consider also asserting
evidence_item_id,check_type, andexit_code: 0so stale/mismatched receipts can’t satisfy the gate accidentally.Based on learnings: in this repository, receipt files are the accepted proof artifacts, so strengthening receipt-field assertions improves proof integrity without changing the proof model.Suggested hardening diff
- - check_type: command - check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml - && grep -q '^ticket_id: OMN-10789$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml" + - check_type: command + check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml + && grep -q '^ticket_id: OMN-10789$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml + && grep -q '^evidence_item_id: dod-unit-tests$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml + && grep -q '^check_type: command$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml + && grep -q '^exit_code: 0$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml"🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@contracts/OMN-10789.yaml` around lines 23 - 25, Update the receipt validation in the OMN-10789 check block (the check with check_type: command and its check_value) to assert additional fields so stale/mismatched receipts can't pass: extend the existing grep chain to also assert grep -q '^evidence_item_id: <EXPECTED_ID>$' (use the correct expected evidence_item_id value), grep -q '^check_type: command$' and grep -q '^exit_code: 0$' joined with &&, preserving the same command.yaml path; ensure the new patterns match exact field names and values and are added into the same check_value string.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@contracts/OMN-10789.yaml`:
- Around line 23-25: Update the receipt validation in the OMN-10789 check block
(the check with check_type: command and its check_value) to assert additional
fields so stale/mismatched receipts can't pass: extend the existing grep chain
to also assert grep -q '^evidence_item_id: <EXPECTED_ID>$' (use the correct
expected evidence_item_id value), grep -q '^check_type: command$' and grep -q
'^exit_code: 0$' joined with &&, preserving the same command.yaml path; ensure
the new patterns match exact field names and values and are added into the same
check_value string.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 67b1b1f3-4000-416b-a86f-2cc5be8236ef
📒 Files selected for processing (2)
contracts/OMN-10789.yamldrift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml
Receipt gate on OCC PR itself fails with pr_ticket_mismatch because existing receipt binds to omniclaude PR #1557. Adding dod-occ-pr-898 self-binding receipt and contract entry per the OCC receipt binding pattern.
… is net-new-only Second occurrence of the same autobind behaviour already corrected on OCC#6455: the Evidence-Source autobind for omninode_infra#898 rewrote the EXISTING per-ticket receipt drift/dod_receipts/OMN-15971/ dod-occ-evidence-admissibility-validator/command.yaml in place (+7/-8), repointing it at PR #898. A landed receipt is immutable evidence of the run that produced it; overwriting it destroys the earlier PR's proof and the OCC Append-Only Gate fails on exactly that. Restored to origin/dev content, pre-emptively rather than after the gate fired. Nothing is lost: the PR #898-specific evidence is carried by the three NET-NEW receipts this companion adds (dod-OmniNode-ai-omninode_infra-pr-898, -pr-898-ci, occ-self-bind-pr-6467). The companion is now additive-only: 1 append-only contract edit (contracts/OMN-15971.yaml, +18/-0) + 3 new files. That this recurred on a second, independently-minted companion makes it a reproducible autobind defect rather than a one-off — worth a follow-up against the autobind producer, not just repeated hand-correction.
…inode_infra#898 (#6467) * evidence(OMN-15971): author OCC companion for OmniNode-ai/omninode_infra#898 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 99bc1eabcf363907329a2343fe6c94e624c93ae4. * evidence(OMN-15971): self-bind OCC#6467 + rebind contract_sha256 * evidence(OMN-15971): restore shared admissibility receipt — companion is net-new-only Second occurrence of the same autobind behaviour already corrected on OCC#6455: the Evidence-Source autobind for omninode_infra#898 rewrote the EXISTING per-ticket receipt drift/dod_receipts/OMN-15971/ dod-occ-evidence-admissibility-validator/command.yaml in place (+7/-8), repointing it at PR #898. A landed receipt is immutable evidence of the run that produced it; overwriting it destroys the earlier PR's proof and the OCC Append-Only Gate fails on exactly that. Restored to origin/dev content, pre-emptively rather than after the gate fired. Nothing is lost: the PR #898-specific evidence is carried by the three NET-NEW receipts this companion adds (dod-OmniNode-ai-omninode_infra-pr-898, -pr-898-ci, occ-self-bind-pr-6467). The companion is now additive-only: 1 append-only contract edit (contracts/OMN-15971.yaml, +18/-0) + 3 new files. That this recurred on a second, independently-minted companion makes it a reproducible autobind defect rather than a one-off — worth a follow-up against the autobind producer, not just repeated hand-correction. --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai>
Summary
contracts/OMN-10789.yamlwith dod_evidence for the delegation_events compliance migrationdrift/dod_receipts/OMN-10789/dod-unit-tests/command.yamlreceipt bound to omniclaude PR chore(occ-deps): update rerun state after baa2c495 #1557drift/dod_receipts/OMN-10789/dod-occ-pr-898/command.yamlself-binding receipt for this OCC PRUnblocks receipt gate (
verify / verify) on omniclaude PR #1557.Evidence-Source: OCC#898
Evidence-Ticket: OMN-10789
OMN-10789
Summary by CodeRabbit