Skip to content

contract(OMN-10797): condition evaluator quoted-literal LHS support - #904

Merged
jonahgabriel merged 2 commits into
mainfrom
jonah/omn-10797-occ-contract
May 10, 2026
Merged

jonahgabriel merged 2 commits into
mainfrom
jonah/omn-10797-occ-contract

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented May 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds the OCC contract and DoD receipts for OMN-10797 — a fix to the condition evaluator on omnibase_infra so that the LHS of in / not in / == may be a quoted string literal in addition to a bareword state key. The interactive onboarding policy uses LHS literals like "llm_inference" in selected_local_services; the OMN-10779 evaluator was treating every LHS as a state key and raising ConditionEvaluationError: Unknown state key: 'llm_inference'.

This unblocks the failing Tests (Split 2/15) job that is gating omnibase_infra #1554 (OMN-10790 — delegation model compliance fields).

Changes

  • contracts/OMN-10797.yaml — ticket contract with two evidence items
  • drift/dod_receipts/OMN-10797/dod-unit-tests/command.yaml — receipt for the 49 passing condition_evaluator tests (unit + integration)
  • drift/dod_receipts/OMN-10797/dod-occ-pr/command.yaml — self-binding receipt for this OCC PR

Downstream PR

omnibase_infra #1557 (jonah/omn-10797-condition-eval-literal-lhs) — implementation. Will reference this OCC PR via Evidence-Source: OCC#<num> once merged.

Summary by CodeRabbit

  • Documentation
    • Added contract and validation records for condition evaluator enhancements supporting quoted literals in interactive onboarding policies.
    • Documented passing unit and integration test results confirming feature functionality.

Review Change Stack

Adds the OCC contract and DoD receipts for the omnibase_infra fix at
OMN-10797: condition evaluator now accepts a quoted-string literal on
the LHS of `in` / `not in` / `==`. Unblocks the failing
``Tests (Split 2/15)`` job that was gating OMN-10790 (#1554).

- contracts/OMN-10797.yaml — ticket contract with two evidence items
- drift/dod_receipts/OMN-10797/dod-unit-tests/command.yaml — receipt
  for the 49 passing condition_evaluator tests (unit + integration)
- drift/dod_receipts/OMN-10797/dod-occ-pr/command.yaml — self-binding
  receipt for this OCC PR
@coderabbitai

coderabbitai Bot commented May 10, 2026 •

Copy link
Copy Markdown

Warning

Rate limit exceeded

@jonahgabriel has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 5 minutes and 54 seconds before requesting another review.

You’ve run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: e0730ca0-77f3-4f36-a3d5-7da00b311c3b

📥 Commits

Reviewing files that changed from the base of the PR and between 4f3d183 and 92467c0.

📒 Files selected for processing (1)
  • drift/dod_receipts/OMN-10797/dod-occ-pr/command.yaml
📝 Walkthrough

Walkthrough

This pull request introduces a new contract file for ticket OMN-10797 and two supporting DOD (Duty of Due Diligence) evidence receipts. The contract defines metadata and policy for extending the condition evaluator's LHS grammar to support quoted literals, disables emergency bypass, and references two command-based validation checks: one confirming OCC PR receipt existence and another verifying 49 passing unit and integration tests.

Changes

OMN-10797 Contract & Evidence

Layer / File(s) Summary
Contract Metadata
contracts/OMN-10797.yaml
Schema version, ticket identifiers, descriptive title and summary for condition evaluator grammar work, and interface change flags are defined.
Contract Policy & Evidence References
contracts/OMN-10797.yaml
Emergency bypass is disabled with no justification, and two DOD evidence items are introduced with command-based checks referencing receipt files.
DOD Receipts
drift/dod_receipts/OMN-10797/dod-occ-pr/command.yaml, drift/dod_receipts/OMN-10797/dod-unit-tests/command.yaml
OCC PR receipt records a grep command validating status: PASS with commit SHA and provenance; unit tests receipt captures uv run pytest execution with 49 passing tests, timestamps, runner metadata, and exit code 0.

Estimated Code Review Effort

🎯 1 (Trivial) | ⏱️ ~4 minutes

Poem

🐰 A contract takes shape, with evidence in tow,
Quoted literals bloom where conditions now grow,
Tests pass, receipts gleam, all forty-nine strong,
The condition evaluator hops merrily along! 🌟

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'contract(OMN-10797): condition evaluator quoted-literal LHS support' directly and clearly summarizes the main change: adding an OCC contract for OMN-10797 that documents support for quoted literals in the condition evaluator's LHS grammar.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch jonah/omn-10797-occ-contract

Comment @coderabbitai help to get the list of available commands and usage tips.

@jonahgabriel
jonahgabriel enabled auto-merge (squash) May 10, 2026 06:46
@jonahgabriel
jonahgabriel merged commit ea5ec97 into main May 10, 2026
28 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-10797-occ-contract branch May 10, 2026 06:48
jonahgabriel added a commit that referenced this pull request Aug 14, 2026
…merge

The seven omnibase_infra probes pinned ae1b6e75, a superseded head that no
branch reaches after the branch was amended -- the contract claimed to read
'the pinned omnibase_infra head' while reading an orphaned commit. Repin to
c8d6d214 (the live PR #2746 head). The edge-mirror probe is repinned from
31102820 to 8289023c after PR #904's branch was updated onto dev.
jonahgabriel added a commit that referenced this pull request Aug 14, 2026
…2746

Every receipt in this ticket carried pr_number 2746 -- including the two whose
checks read omninode_infra -- so no PASS receipt bound PR #904. That is what
#904's occ-preflight and receipt gate report as pr_ticket_mismatch: 'no PASS
receipt for one or more tickets binds to PR #904 or one of its commit SHAs'.

The two omninode_infra items now bind #904, its branch, and its head; all
twelve receipts are re-minted by executing their contract-declared check live
against the rebound pins, with contract_entry_sha256 recomputed via
omnibase_core.validation.validator_receipt_gate.
jonahgabriel added a commit that referenced this pull request Aug 14, 2026
…+ omninode_infra#904 (#6496)

* evidence(OMN-15952): OCC companion contract for the unattended renewal contract

Binds the evidence for OmniNode-ai/omnibase_infra#2746 (the node contract that
declares the renewal cycle) and OmniNode-ai/omninode_infra#904 (the onex-api
mirror of the directive across an extra=forbid seam).

Receipts follow in the next commit, once this PR's own number exists to
self-bind against.

* evidence(OMN-15952): receipts + self-bind for OCC#6496

Eleven receipts, all PASS, all probed live against the GitHub contents API at
the producing head SHAs rather than against a local worktree -- the file this
lane edited and the file the reviewer will read are then provably the same
bytes.

Six of the eleven are content assertions rather than PR-exists assertions:
the renewal cycle present in the node contract's config block, the directive
required (not optional) on the attach response, the renewal-mode enum having
exactly one member, the renew-before-expiry invariant living in the model
validator, assert_expiry_not_extended existing as a callable, and the edge
mirror asserting field-set equality. A PR-exists receipt proves a branch was
pushed; these prove what is in it.

* evidence(OMN-15952): bind the self-bind receipt to OCC#6496's own commit

occ-merge-eligibility rejected the PR with reason=pr_ticket_mismatch: it
requires at least one PASS receipt bound to THIS PR or one of its commit
SHAs, and all eleven receipts were bound to the producing omnibase_infra PR
instead. The self-bind receipt now carries pr_number 6496, the OCC branch,
and commit 2af48ba -- a commit of this PR,
so the binding resolves against --pr-commit-sha.

* evidence(OMN-15952): add the falsifiable deploy probe the ratchet requires

deploy-gate rejected omnibase_infra#2746: OMN-15952 is not grandfathered and
the contract declared no falsifiable deploy probe (OMN-14443).

The deployed surface this ticket changes is the attach node's response shape --
a runtime image without the renewal directive serves an attach response with no
renewal cycle, which is exactly the pre-OMN-15952 defect. The probe reads
model_gateway_attach_response.py back from GitHub at the pinned omnibase_infra
head and greps for the required field, so it goes RED the moment the field is
absent or renamed. It reads a surface outside this repo, never a receipt or
contract this PR authors.

The live-cluster half -- docker exec against omninode-runtime, then a real
attach -> expiry -> re-grant -> re-attach against deployed onex-api -- is the
post-deploy acceptance test tracked on the ticket. It cannot run before the
image exists, and claiming it here would be the vacuous evidence this ratchet
exists to reject.

* evidence(OMN-15952): put gh api in command position for the deploy probe

The falsifiability parser reads the COMMAND POSITION, not the whole string.
Wrapping the probe as a variable assignment put that in command position, so
the parser saw ['gh', 'grep'] and rejected it as vacuous even though the call
it could not see was a real gh-api readback. Rewritten in the exact form the
gate's own error message blesses: gh api ... --jq .content | base64 -d |
grep -q '<symbol>'.

Same probe, same falsifiability, same PASS -- only the shell shape changed.
Receipt regenerated against the new entry hash.

* evidence(OMN-15952): rebind contract pins to the heads that actually merge

The seven omnibase_infra probes pinned ae1b6e75, a superseded head that no
branch reaches after the branch was amended -- the contract claimed to read
'the pinned omnibase_infra head' while reading an orphaned commit. Repin to
c8d6d214 (the live PR #2746 head). The edge-mirror probe is repinned from
31102820 to 8289023c after PR #904's branch was updated onto dev.

* evidence(OMN-15952): bind the omninode_infra evidence to PR #904, not #2746

Every receipt in this ticket carried pr_number 2746 -- including the two whose
checks read omninode_infra -- so no PASS receipt bound PR #904. That is what
#904's occ-preflight and receipt gate report as pr_ticket_mismatch: 'no PASS
receipt for one or more tickets binds to PR #904 or one of its commit SHAs'.

The two omninode_infra items now bind #904, its branch, and its head; all
twelve receipts are re-minted by executing their contract-declared check live
against the rebound pins, with contract_entry_sha256 recomputed via
omnibase_core.validation.validator_receipt_gate.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant