diff --git a/contracts/OMN-10171.yaml b/contracts/OMN-10171.yaml index 2ed9753ef88..6b76e2ad4e9 100644 --- a/contracts/OMN-10171.yaml +++ b/contracts/OMN-10171.yaml @@ -37,3 +37,19 @@ dod_evidence: check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-10171/dod-occ-pr-972/command.yaml && grep -q '^ticket_id: \"OMN-10171\"$' drift/dod_receipts/OMN-10171/dod-occ-pr-972/command.yaml && grep -q '^pr_number: 972$' drift/dod_receipts/OMN-10171/dod-occ-pr-972/command.yaml" + - id: "dod-omniclaude-pr-1573" + description: "omniclaude PR #1573 replaces validate_skill_backing_node.py with an omnibase_core invocation + shim." + source: "manual" + checks: + - check_type: "command" + check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-10171/dod-omniclaude-pr-1573/command.yaml + && grep -q '^pr_number: 1573$' drift/dod_receipts/OMN-10171/dod-omniclaude-pr-1573/command.yaml" + - id: "dod-occ-pr-974" + description: "OCC PR #974 carries the OMN-10171 omniclaude receipt needed by omniclaude PR #1573." + source: "manual" + checks: + - check_type: "command" + check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-10171/dod-occ-pr-974/command.yaml + && grep -q '^ticket_id: OMN-10171$' drift/dod_receipts/OMN-10171/dod-occ-pr-974/command.yaml + && grep -q '^pr_number: 974$' drift/dod_receipts/OMN-10171/dod-occ-pr-974/command.yaml" diff --git a/contracts/OMN-10492.yaml b/contracts/OMN-10492.yaml new file mode 100644 index 00000000000..218cd0229f7 --- /dev/null +++ b/contracts/OMN-10492.yaml @@ -0,0 +1,40 @@ +--- +schema_version: '1.0.0' +ticket_id: OMN-10492 +title: Replace raw Postgres probe with runtime HTTP health check in system_status +summary: >- + The check_database_health sub-skill described probing Postgres directly from the Mac, which violates + the architecture rule that the Mac must never connect to Postgres directly. Replace the raw psql/psycopg2 + probe with an HTTP GET against the runtime health endpoint (http://192.168.86.201:8085/health), overridable + via OMNINODE_RUNTIME_HEALTH_URL. Update SKILL.md to reflect the HTTP-based data path (Mac -> runtime + health endpoint -> Postgres) and add unit tests asserting no psql/psycopg2 usage. +is_seam_ticket: false +interface_change: false +interfaces_touched: [] +evidence_requirements: + - kind: ci + description: >- + omniclaude PR #1571 removes raw psql/psycopg2 probing from check_database_health and probes the + runtime health endpoint over HTTP instead. + command: >- + gh pr diff 1571 --repo OmniNode-ai/omniclaude | grep -q 'requests.get' +emergency_bypass: + enabled: false + justification: '' + follow_up_ticket_id: '' +dod_evidence: + - id: dod-001 + description: >- + omniclaude PR #1571 present and open — replaces raw Postgres probe with runtime HTTP health check + in check_database_health/_lib/execute.py + source: manual + checks: + - check_type: command + check_value: TARGET_PR=1571; gh pr diff ${TARGET_PR} --repo OmniNode-ai/omniclaude | grep -q 'requests.get' + - id: dod-occ-pr + description: Self-binding receipt for this OCC PR. + source: generated + checks: + - check_type: command + check_value: "gh pr view ${PR_NUMBER} --repo OmniNode-ai/onex_change_control --json state -q '.state' + | grep -q OPEN" diff --git a/contracts/OMN-9906.yaml b/contracts/OMN-9906.yaml index 9269ca9cfbe..d04d5d1f122 100644 --- a/contracts/OMN-9906.yaml +++ b/contracts/OMN-9906.yaml @@ -36,3 +36,21 @@ dod_evidence: check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-9906/dod-occ-pr-972/command.yaml && grep -q '^ticket_id: \"OMN-9906\"$' drift/dod_receipts/OMN-9906/dod-occ-pr-972/command.yaml && grep -q '^pr_number: 972$' drift/dod_receipts/OMN-9906/dod-occ-pr-972/command.yaml" + - id: "dod-omniclaude-pr-1572" + description: "omniclaude PR #1572 migrates the worktree and team-lead guards to the ONEX_HOOKS_MASK + WORKTREE_GUARD bit gate." + source: "manual" + checks: + - check_type: "command" + check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-9906/dod-omniclaude-pr-1572/command.yaml + && grep -q '^ticket_id: OMN-9906$' drift/dod_receipts/OMN-9906/dod-omniclaude-pr-1572/command.yaml + && grep -q 'TEAM_LEAD_GUARD' drift/dod_receipts/OMN-9906/dod-omniclaude-pr-1572/command.yaml + && grep -q '^pr_number: 1572$' drift/dod_receipts/OMN-9906/dod-omniclaude-pr-1572/command.yaml" + - id: "dod-occ-pr-974" + description: "OCC PR #974 carries the OMN-9906 omniclaude receipt needed by omniclaude PR #1572." + source: "manual" + checks: + - check_type: "command" + check_value: "grep -q '^status: PASS$' drift/dod_receipts/OMN-9906/dod-occ-pr-974/command.yaml + && grep -q '^ticket_id: OMN-9906$' drift/dod_receipts/OMN-9906/dod-occ-pr-974/command.yaml && + grep -q '^pr_number: 974$' drift/dod_receipts/OMN-9906/dod-occ-pr-974/command.yaml" diff --git a/drift/dod_receipts/OMN-10171/dod-occ-pr-974/command.yaml b/drift/dod_receipts/OMN-10171/dod-occ-pr-974/command.yaml new file mode 100644 index 00000000000..91c68adb686 --- /dev/null +++ b/drift/dod_receipts/OMN-10171/dod-occ-pr-974/command.yaml @@ -0,0 +1,19 @@ +--- +schema_version: "1.0.0" +ticket_id: OMN-10171 +evidence_item_id: dod-occ-pr-974 +check_type: command +check_value: "gh pr view ${PR_NUMBER} --repo OmniNode-ai/onex_change_control --json state -q '.state' + | grep -q OPEN" +status: PASS +run_timestamp: "2026-05-13T01:27:50Z" +commit_sha: 6d7a46be +runner: jonah-local +verifier: jonahgabriel +probe_command: "gh pr view 974 --repo OmniNode-ai/onex_change_control --json number,state -q '.'" +probe_stdout: | + {"number":974,"state":"OPEN"} +actual_output: "PASS: OCC PR #974 is OPEN on branch jonah/omn-occ-bind-overnight." +exit_code: 0 +pr_number: 974 +contract_sha256: "sha256:3dbe953a41f97df0ca6c9155f808a7350dcee9612fd6e6596667dc8d02edd9c1" diff --git a/drift/dod_receipts/OMN-10171/dod-occ-pr/command.yaml b/drift/dod_receipts/OMN-10171/dod-occ-pr/command.yaml new file mode 100644 index 00000000000..903b4520723 --- /dev/null +++ b/drift/dod_receipts/OMN-10171/dod-occ-pr/command.yaml @@ -0,0 +1,19 @@ +--- +schema_version: "1.0.0" +ticket_id: OMN-10171 +evidence_item_id: dod-occ-pr +check_type: command +check_value: "gh pr view ${PR_NUMBER} --repo OmniNode-ai/onex_change_control --json state -q '.state' + | grep -q OPEN" +status: PASS +run_timestamp: "2026-05-13T01:27:50Z" +commit_sha: 6d7a46be +runner: jonah-local +verifier: jonahgabriel +probe_command: "gh pr view 974 --repo OmniNode-ai/onex_change_control --json number,state -q '.'" +probe_stdout: | + {"number":974,"state":"OPEN"} +actual_output: "PASS: OCC PR #974 is OPEN on branch jonah/omn-occ-bind-overnight." +exit_code: 0 +pr_number: 974 +contract_sha256: "sha256:3dbe953a41f97df0ca6c9155f808a7350dcee9612fd6e6596667dc8d02edd9c1" diff --git a/drift/dod_receipts/OMN-10171/dod-omniclaude-pr-1573/command.yaml b/drift/dod_receipts/OMN-10171/dod-omniclaude-pr-1573/command.yaml new file mode 100644 index 00000000000..80948a39171 --- /dev/null +++ b/drift/dod_receipts/OMN-10171/dod-omniclaude-pr-1573/command.yaml @@ -0,0 +1,19 @@ +--- +schema_version: "1.0.0" +ticket_id: OMN-10171 +evidence_item_id: dod-omniclaude-pr-1573 +check_type: command +check_value: gh pr diff 1573 --repo OmniNode-ai/omniclaude | grep -q 'pre-commit invocation shim' +status: PASS +run_timestamp: "2026-05-13T01:26:17Z" +commit_sha: 06f7d5b2dd1ad94eb0f41c8bd3f73692042bbec6 +runner: omn-10171-local-runner +verifier: jonahgabriel +probe_command: gh pr diff 1573 --repo OmniNode-ai/omniclaude | grep 'pre-commit invocation shim' +probe_stdout: | + +"""validate_skill_backing_node -- pre-commit invocation shim (OMN-10171, SEAM-2). +actual_output: >- + FOUND: validate_skill_backing_node.py reduced to a pre-commit invocation shim delegating to omnibase_core + (-405 lines). omniclaude PR #1573 open, targeting main. +exit_code: 0 +pr_number: 1573 diff --git a/drift/dod_receipts/OMN-10492/dod-001/command.yaml b/drift/dod_receipts/OMN-10492/dod-001/command.yaml new file mode 100644 index 00000000000..0a20b69be48 --- /dev/null +++ b/drift/dod_receipts/OMN-10492/dod-001/command.yaml @@ -0,0 +1,19 @@ +--- +schema_version: "1.0.0" +ticket_id: OMN-10492 +evidence_item_id: dod-001 +check_type: command +check_value: gh pr diff 1571 --repo OmniNode-ai/omniclaude | grep -q 'requests.get' +status: PASS +run_timestamp: "2026-05-13T01:22:47Z" +commit_sha: d73053ebe7e4bca63ddf5fb9f08c50f4c446d0f1 +runner: omn-10492-local-runner +verifier: jonahgabriel +probe_command: gh pr diff 1571 --repo OmniNode-ai/omniclaude | grep 'requests.get' +probe_stdout: | + + resp = requests.get(_RUNTIME_HEALTH_URL, timeout=_TIMEOUT_S) +actual_output: >- + FOUND: check_database_health/_lib/execute.py probes the runtime health endpoint over HTTP via requests.get() + instead of raw psql/psycopg2. omniclaude PR #1571 open, targeting main. +exit_code: 0 +pr_number: 1571 diff --git a/drift/dod_receipts/OMN-10492/dod-occ-pr/command.yaml b/drift/dod_receipts/OMN-10492/dod-occ-pr/command.yaml new file mode 100644 index 00000000000..2261cf517d7 --- /dev/null +++ b/drift/dod_receipts/OMN-10492/dod-occ-pr/command.yaml @@ -0,0 +1,19 @@ +--- +schema_version: "1.0.0" +ticket_id: OMN-10492 +evidence_item_id: dod-occ-pr +check_type: command +check_value: "gh pr view ${PR_NUMBER} --repo OmniNode-ai/onex_change_control --json state -q '.state' + | grep -q OPEN" +status: PASS +run_timestamp: "2026-05-13T01:24:30Z" +commit_sha: 09c8df92 +runner: jonah-local +verifier: jonahgabriel +probe_command: "gh pr view 974 --repo OmniNode-ai/onex_change_control --json number,state -q '.'" +probe_stdout: | + {"number":974,"state":"OPEN"} +actual_output: "PASS: OCC PR #974 is OPEN on branch jonah/omn-occ-bind-overnight." +exit_code: 0 +pr_number: 974 +contract_sha256: "sha256:be91fa35e64a167fdc29efe6fabf555926c210ab9b6a59968c7d6353856c5168" diff --git a/drift/dod_receipts/OMN-9906/dod-occ-pr-974/command.yaml b/drift/dod_receipts/OMN-9906/dod-occ-pr-974/command.yaml new file mode 100644 index 00000000000..735246e3293 --- /dev/null +++ b/drift/dod_receipts/OMN-9906/dod-occ-pr-974/command.yaml @@ -0,0 +1,19 @@ +--- +schema_version: "1.0.0" +ticket_id: OMN-9906 +evidence_item_id: dod-occ-pr-974 +check_type: command +check_value: "gh pr view ${PR_NUMBER} --repo OmniNode-ai/onex_change_control --json state -q '.state' + | grep -q OPEN" +status: PASS +run_timestamp: "2026-05-13T01:27:50Z" +commit_sha: 6d7a46be +runner: jonah-local +verifier: jonahgabriel +probe_command: "gh pr view 974 --repo OmniNode-ai/onex_change_control --json number,state -q '.'" +probe_stdout: | + {"number":974,"state":"OPEN"} +actual_output: "PASS: OCC PR #974 is OPEN on branch jonah/omn-occ-bind-overnight." +exit_code: 0 +pr_number: 974 +contract_sha256: "sha256:885e0af24a0aa76e420f4b71880eeced9b4887ae6f9d2b77bdaf7e55eba571cd" diff --git a/drift/dod_receipts/OMN-9906/dod-occ-pr/command.yaml b/drift/dod_receipts/OMN-9906/dod-occ-pr/command.yaml new file mode 100644 index 00000000000..7c5bae3384f --- /dev/null +++ b/drift/dod_receipts/OMN-9906/dod-occ-pr/command.yaml @@ -0,0 +1,19 @@ +--- +schema_version: "1.0.0" +ticket_id: OMN-9906 +evidence_item_id: dod-occ-pr +check_type: command +check_value: "gh pr view ${PR_NUMBER} --repo OmniNode-ai/onex_change_control --json state -q '.state' + | grep -q OPEN" +status: PASS +run_timestamp: "2026-05-13T01:27:50Z" +commit_sha: 6d7a46be +runner: jonah-local +verifier: jonahgabriel +probe_command: "gh pr view 974 --repo OmniNode-ai/onex_change_control --json number,state -q '.'" +probe_stdout: | + {"number":974,"state":"OPEN"} +actual_output: "PASS: OCC PR #974 is OPEN on branch jonah/omn-occ-bind-overnight." +exit_code: 0 +pr_number: 974 +contract_sha256: "sha256:885e0af24a0aa76e420f4b71880eeced9b4887ae6f9d2b77bdaf7e55eba571cd" diff --git a/drift/dod_receipts/OMN-9906/dod-omniclaude-pr-1572/command.yaml b/drift/dod_receipts/OMN-9906/dod-omniclaude-pr-1572/command.yaml new file mode 100644 index 00000000000..edb2cd9b491 --- /dev/null +++ b/drift/dod_receipts/OMN-9906/dod-omniclaude-pr-1572/command.yaml @@ -0,0 +1,24 @@ +--- +schema_version: "1.0.0" +ticket_id: OMN-9906 +evidence_item_id: dod-omniclaude-pr-1572 +check_type: command +check_value: >- + gh pr diff 1572 --repo OmniNode-ai/omniclaude | grep -q 'onex_hook_gate WORKTREE_GUARD' && gh pr diff + 1572 --repo OmniNode-ai/omniclaude | grep -q 'onex_hook_gate TEAM_LEAD_GUARD' +status: PASS +run_timestamp: "2026-05-13T01:26:17Z" +commit_sha: 168ce4f4a19a3621625ea2565457135c5120c402 +runner: omn-9906-local-runner +verifier: jonahgabriel +probe_command: >- + gh pr diff 1572 --repo OmniNode-ai/omniclaude | grep -E 'onex_hook_gate (WORKTREE_GUARD|TEAM_LEAD_GUARD)' +probe_stdout: | + + if declare -F onex_hook_gate >/dev/null 2>&1 && ! onex_hook_gate WORKTREE_GUARD; then + +if declare -F onex_hook_gate >/dev/null 2>&1 && ! onex_hook_gate TEAM_LEAD_GUARD; then +actual_output: >- + FOUND: pre_tool_use_bash_guard.sh now gates worktree enforcement on the ONEX_HOOKS_MASK WORKTREE_GUARD + bit via onex_hook_gate, and pre_tool_use_team_lead_guard.sh now gates team-lead enforcement on the TEAM_LEAD_GUARD + bit. omniclaude PR #1572 open, targeting main. +exit_code: 0 +pr_number: 1572