Skip to content

fix(OMN-10789): add OCC contract and receipt for delegation compliance migration - #898

Merged
jonahgabriel merged 2 commits into
mainfrom
jonah/omn-10789-occ-evidence
May 10, 2026
Merged

jonahgabriel merged 2 commits into
mainfrom
jonah/omn-10789-occ-evidence

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented May 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds contracts/OMN-10789.yaml with dod_evidence for the delegation_events compliance migration
  • Adds drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml receipt bound to omniclaude PR chore(occ-deps): update rerun state after baa2c495 #1557
  • Adds drift/dod_receipts/OMN-10789/dod-occ-pr-898/command.yaml self-binding receipt for this OCC PR

Unblocks receipt gate (verify / verify) on omniclaude PR #1557.

Evidence-Source: OCC#898
Evidence-Ticket: OMN-10789

OMN-10789

Summary by CodeRabbit

  • Chores
    • Added a database migration that introduces two new integer columns to delegation events with sensible defaults to support compliance tracking.
  • Tests
    • Added unit-test coverage validating migration, defaults, upsert/write behavior (7 passing tests) and CI validation receipts, plus an automated receipt for an associated PR verification.

Review Change Stack

…e migration

Receipt gate on omniclaude PR #1557 fails with missing_contract for OMN-10789.
Adds the contract and unit test receipt to unblock merge.
@coderabbitai

coderabbitai Bot commented May 10, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: e7caecf2-aaf2-4bdc-b2f3-672cbcd5acf4

📥 Commits

Reviewing files that changed from the base of the PR and between 98ee93f and 4c8d05b.

📒 Files selected for processing (2)
  • contracts/OMN-10789.yaml
  • drift/dod_receipts/OMN-10789/dod-occ-pr-898/command.yaml
✅ Files skipped from review due to trivial changes (1)
  • drift/dod_receipts/OMN-10789/dod-occ-pr-898/command.yaml
🚧 Files skipped from review as they are similar to previous changes (1)
  • contracts/OMN-10789.yaml

📝 Walkthrough

Walkthrough

A new change control contract for ticket OMN-10789 establishes database migration requirements for the delegation_events table, adding two integer columns (tokens_to_compliance and compliance_attempts) with configured defaults. The contract includes safety bypass policy and references a test receipt documenting seven passing unit tests that validate the migration behavior across fresh install, upgrade, and CRUD scenarios.

Changes

Migration Contract & Test Evidence

Layer / File(s) Summary
Contract Definition
contracts/OMN-10789.yaml
Contract metadata, schema version, and migration summary describing new INTEGER columns on delegation_events with defaults and stated test coverage.
Safety Policy
contracts/OMN-10789.yaml
Emergency bypass setting configured as disabled with empty justification.
Proof of Compliance
contracts/OMN-10789.yaml, drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml
DoD evidence references the unit test receipt; test receipt records PASS status from pytest tests/delegation/test_compliance_migration.py -v with 7 passing tests, exit code 0, and provenance metadata (timestamp, commit SHA, PR 1557).

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~4 minutes

Poem

🐰 New columns hop into delegation_events,
Seven tests pass without a fuss or relent—
Contract sealed, bypass off, compliance in sight,
Migrations are smooth when test receipts shine bright! ✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: adding an OCC contract and receipt for the OMN-10789 delegation compliance migration, which directly aligns with the changeset content.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-10789-occ-evidence

Comment @coderabbitai help to get the list of available commands and usage tips.

@jonahgabriel
jonahgabriel enabled auto-merge (squash) May 10, 2026 02:59

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
contracts/OMN-10789.yaml (1)

23-25: ⚡ Quick win

Strengthen receipt validation to reduce false-positive gate passes.

At Line 23–25, the check only asserts PASS status and ticket_id. Consider also asserting evidence_item_id, check_type, and exit_code: 0 so stale/mismatched receipts can’t satisfy the gate accidentally.

Suggested hardening diff
-      - check_type: command
-        check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml
-          && grep -q '^ticket_id: OMN-10789$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml"
+      - check_type: command
+        check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml
+          && grep -q '^ticket_id: OMN-10789$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml
+          && grep -q '^evidence_item_id: dod-unit-tests$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml
+          && grep -q '^check_type: command$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml
+          && grep -q '^exit_code: 0$' drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml"
Based on learnings: in this repository, receipt files are the accepted proof artifacts, so strengthening receipt-field assertions improves proof integrity without changing the proof model.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@contracts/OMN-10789.yaml` around lines 23 - 25, Update the receipt validation
in the OMN-10789 check block (the check with check_type: command and its
check_value) to assert additional fields so stale/mismatched receipts can't
pass: extend the existing grep chain to also assert grep -q '^evidence_item_id:
<EXPECTED_ID>$' (use the correct expected evidence_item_id value), grep -q
'^check_type: command$' and grep -q '^exit_code: 0$' joined with &&, preserving
the same command.yaml path; ensure the new patterns match exact field names and
values and are added into the same check_value string.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@contracts/OMN-10789.yaml`:
- Around line 23-25: Update the receipt validation in the OMN-10789 check block
(the check with check_type: command and its check_value) to assert additional
fields so stale/mismatched receipts can't pass: extend the existing grep chain
to also assert grep -q '^evidence_item_id: <EXPECTED_ID>$' (use the correct
expected evidence_item_id value), grep -q '^check_type: command$' and grep -q
'^exit_code: 0$' joined with &&, preserving the same command.yaml path; ensure
the new patterns match exact field names and values and are added into the same
check_value string.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 67b1b1f3-4000-416b-a86f-2cc5be8236ef

📥 Commits

Reviewing files that changed from the base of the PR and between 2407011 and 98ee93f.

📒 Files selected for processing (2)
  • contracts/OMN-10789.yaml
  • drift/dod_receipts/OMN-10789/dod-unit-tests/command.yaml

Receipt gate on OCC PR itself fails with pr_ticket_mismatch because existing
receipt binds to omniclaude PR #1557. Adding dod-occ-pr-898 self-binding receipt
and contract entry per the OCC receipt binding pattern.
@jonahgabriel
jonahgabriel merged commit 3b7c92e into main May 10, 2026
31 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-10789-occ-evidence branch May 10, 2026 03:04
jonahgabriel added a commit that referenced this pull request Aug 14, 2026
… is net-new-only

Second occurrence of the same autobind behaviour already corrected on
OCC#6455: the Evidence-Source autobind for omninode_infra#898 rewrote the
EXISTING per-ticket receipt drift/dod_receipts/OMN-15971/
dod-occ-evidence-admissibility-validator/command.yaml in place (+7/-8),
repointing it at PR #898. A landed receipt is immutable evidence of the run
that produced it; overwriting it destroys the earlier PR's proof and the OCC
Append-Only Gate fails on exactly that.

Restored to origin/dev content, pre-emptively rather than after the gate
fired. Nothing is lost: the PR #898-specific evidence is carried by the three
NET-NEW receipts this companion adds (dod-OmniNode-ai-omninode_infra-pr-898,
-pr-898-ci, occ-self-bind-pr-6467). The companion is now additive-only:
1 append-only contract edit (contracts/OMN-15971.yaml, +18/-0) + 3 new files.

That this recurred on a second, independently-minted companion makes it a
reproducible autobind defect rather than a one-off — worth a follow-up
against the autobind producer, not just repeated hand-correction.
jonahgabriel added a commit that referenced this pull request Aug 14, 2026
…inode_infra#898 (#6467)

* evidence(OMN-15971): author OCC companion for OmniNode-ai/omninode_infra#898

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 99bc1eabcf363907329a2343fe6c94e624c93ae4.

* evidence(OMN-15971): self-bind OCC#6467 + rebind contract_sha256

* evidence(OMN-15971): restore shared admissibility receipt — companion is net-new-only

Second occurrence of the same autobind behaviour already corrected on
OCC#6455: the Evidence-Source autobind for omninode_infra#898 rewrote the
EXISTING per-ticket receipt drift/dod_receipts/OMN-15971/
dod-occ-evidence-admissibility-validator/command.yaml in place (+7/-8),
repointing it at PR #898. A landed receipt is immutable evidence of the run
that produced it; overwriting it destroys the earlier PR's proof and the OCC
Append-Only Gate fails on exactly that.

Restored to origin/dev content, pre-emptively rather than after the gate
fired. Nothing is lost: the PR #898-specific evidence is carried by the three
NET-NEW receipts this companion adds (dod-OmniNode-ai-omninode_infra-pr-898,
-pr-898-ci, occ-self-bind-pr-6467). The companion is now additive-only:
1 append-only contract edit (contracts/OMN-15971.yaml, +18/-0) + 3 new files.

That this recurred on a second, independently-minted companion makes it a
reproducible autobind defect rather than a one-off — worth a follow-up
against the autobind producer, not just repeated hand-correction.

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant