Skip to content

test(e2e): add Odoo consumer overlay to the Constellation Docker rail - #298

Merged
cryptoxdog merged 16 commits into
mainfrom
claude/odoo-gate-sdk-integration-yg6osh
Sep 28, 2026
Merged

cryptoxdog merged 16 commits into
mainfrom
claude/odoo-gate-sdk-integration-yg6osh

Conversation

@cryptoxdog

Copy link
Copy Markdown
Collaborator

Problem

test(e2e): add Odoo consumer overlay to the Constellation Docker rail (+6 more commits below)

Adds tests/e2e/constellation_odoo: a compose overlay on Constellation.Gate's release-set rail that puts a real Odoo 19 (IB-Odoo_19 image, plasticos_gate / plasticos_enrichment / plasticos_matching installed by Odoo) on a network shared with Gate only, admits exactly one consumer key id (odoo-e2e) into Gate's keyring, and drives Odoo -> Gate -> EIE -> Gate -> Odoo from inside the real registry. Adversarial probes cover unsigned, unknown-key, forged, self-registration and direct-bypass attempts, plus authorization-gap probes.

Closes #

Fix

  • test(e2e): add Odoo consumer overlay to the Constellation Docker rail
  • test(e2e): Odoo rail — schema migration step, relay-aware checks, fix probes
  • test(e2e): publish Odoo rail + Gate rail baseline results and report
  • fix(e2e): Odoo rail kernel pass — verdict exit, provenance assertion, doc truth
  • test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • style(e2e): normalize EOF/trailing whitespace in published evidence
  • fix(e2e): YAML-safe redaction placeholder

Risk

  • Low — additive, reversible, no data or contract change — n/a — not this change
  • Medium — touches shared code, config, or a public interface
  • High — breaking change, migration, IAM/network, or irreversible — n/a — not this change

Blast radius: measured paths in Changes by intent
Rollback: revert this PR

Evidence

gate-receipt.json present: schema=l9.pr_gate_receipt.v2 content_digest=3168739776 passed_at=2026-09-26T18:58:43Z
L4 receipt present: phase=release_authorized tree_digest=bc2dbc927b1640ff38bf3683fb4cebe017080c82a1d7c084d73a09b4ed6608cf kernel_evidence=evidenced

Gates

  • Regression test added that fails without this fix — n/a — not this change
  • No secrets, tokens, or customer data in code, tests, fixtures, or logs
  • semgrep clean, or findings triaged below — n/a — not this change
  • New IAM / workflow permissions are least privilege and enumerated — n/a — not this change
  • Third-party actions pinned to a full commit SHA — n/a — not this change
  • Public interface change is documented and versioned — n/a — not this change
  • Observability exists for the new path (metric, log, trace, or alert) — n/a — not this change

Reviewer focus

See Changes by intent and Protected-root (if any additive_only path).

Changes by intent

Added

  • tests/e2e/constellation_odoo/FINAL_ODOO_E2E_REPORT.md — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/README.md — fix(e2e): Odoo rail kernel pass — verdict exit, provenance assertion, doc truth
  • tests/e2e/constellation_odoo/compose.eie-deterministic.yml — test(e2e): add Odoo consumer overlay to the Constellation Docker rail
  • tests/e2e/constellation_odoo/compose.odoo.yml — fix(e2e): Odoo rail kernel pass — verdict exit, provenance assertion, doc truth
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/assertions.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/assertions.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/compose_config.yml — fix(e2e): YAML-safe redaction placeholder
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/container_state.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/ceg_to_eie.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/eie_to_ceg.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/isolation.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/main.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/neo4j_state.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/outage.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/recovery.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/registry_during_outage.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/gate_registry.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/health_snapshot.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/image_provenance.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/image_revisions.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/ceg.log.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/eie.log.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/gate.log.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/neo4j.log.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/sdk_lock.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/sdk_provenance.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/secret_scan.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/source_revisions.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/workspace_status.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/assertions.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/assertions.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/compose_config.yml — fix(e2e): YAML-safe redaction placeholder
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/container_state.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/ceg_to_eie.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/eie_to_ceg.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/isolation.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/main.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/neo4j_state.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/outage.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/recovery.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/registry_during_outage.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/gate_registry.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/health_snapshot.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/image_provenance.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/image_revisions.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/ceg.log.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/eie.log.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/gate.log.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/neo4j.log.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/sdk_lock.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/sdk_provenance.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/secret_scan.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/source_revisions.json — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/workspace_status.txt — test(e2e): publish Odoo rail + Gate rail baseline results and report
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/assertions.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/boot_state.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/compose_config.yml — fix(e2e): YAML-safe redaction placeholder
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/container_state.json — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/eie_business_profile.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/eie_migrations.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/isolation.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/neo4j_odoo_authz_probe.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_adversarial.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_adversarial.raw.txt — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_business.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_business.raw.txt — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_configure.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_configure.raw.txt — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_match.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_match.raw.txt — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_transport.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_transport.raw.txt — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/gate_registry.json — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/image_provenance.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/ceg.log.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/eie.log.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/gate.log.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/neo4j.log.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/odoo.log.txt — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/registry_wait.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/registry_wait_business.txt — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/secret_scan.json — test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/source_revisions.json — style(e2e): normalize EOF/trailing whitespace in published evidence
  • tests/e2e/constellation_odoo/scripts/assert_odoo_evidence.py — test(e2e): Odoo rail — schema migration step, relay-aware checks, fix probes
  • tests/e2e/constellation_odoo/scripts/build_images_odoo.sh — test(e2e): Odoo rail — schema migration step, relay-aware checks, fix probes
  • tests/e2e/constellation_odoo/scripts/gen_env_odoo.sh — test(e2e): add Odoo consumer overlay to the Constellation Docker rail
  • tests/e2e/constellation_odoo/scripts/odoo_driver.py — fix(e2e): Odoo rail kernel pass — verdict exit, provenance assertion, doc truth
  • tests/e2e/constellation_odoo/scripts/redact_odoo.py — fix(e2e): YAML-safe redaction placeholder
  • tests/e2e/constellation_odoo/scripts/run_odoo_e2e.sh — fix(e2e): Odoo rail kernel pass — verdict exit, provenance assertion, doc truth

Modified

  • n/a

Deleted

  • n/a

Files touched

  • A tests/e2e/constellation_odoo/FINAL_ODOO_E2E_REPORT.md
  • A tests/e2e/constellation_odoo/README.md
  • A tests/e2e/constellation_odoo/compose.eie-deterministic.yml
  • A tests/e2e/constellation_odoo/compose.odoo.yml
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/assertions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/assertions.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/compose_config.yml
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/container_state.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/ceg_to_eie.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/eie_to_ceg.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/isolation.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/main.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/neo4j_state.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/outage.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/recovery.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/registry_during_outage.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/gate_registry.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/health_snapshot.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/image_provenance.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/image_revisions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/ceg.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/eie.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/gate.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/neo4j.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/sdk_lock.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/sdk_provenance.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/secret_scan.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/source_revisions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/workspace_status.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/assertions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/assertions.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/compose_config.yml
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/container_state.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/ceg_to_eie.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/eie_to_ceg.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/isolation.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/main.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/neo4j_state.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/outage.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/recovery.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/registry_during_outage.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/gate_registry.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/health_snapshot.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/image_provenance.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/image_revisions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/ceg.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/eie.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/gate.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/neo4j.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/sdk_lock.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/sdk_provenance.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/secret_scan.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/source_revisions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/workspace_status.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/assertions.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/boot_state.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/compose_config.yml
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/container_state.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/eie_business_profile.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/eie_migrations.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/isolation.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/neo4j_odoo_authz_probe.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_adversarial.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_adversarial.raw.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_business.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_business.raw.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_configure.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_configure.raw.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_match.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_match.raw.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_transport.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_transport.raw.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/gate_registry.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/image_provenance.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/ceg.log.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/eie.log.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/gate.log.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/neo4j.log.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/odoo.log.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/registry_wait.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/registry_wait_business.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/secret_scan.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/source_revisions.json
  • A tests/e2e/constellation_odoo/scripts/assert_odoo_evidence.py
  • A tests/e2e/constellation_odoo/scripts/build_images_odoo.sh
  • A tests/e2e/constellation_odoo/scripts/gen_env_odoo.sh
  • A tests/e2e/constellation_odoo/scripts/odoo_driver.py
  • A tests/e2e/constellation_odoo/scripts/redact_odoo.py
  • A tests/e2e/constellation_odoo/scripts/run_odoo_e2e.sh

Commits

  • test(e2e): add Odoo consumer overlay to the Constellation Docker rail
  • test(e2e): Odoo rail — schema migration step, relay-aware checks, fix probes
  • test(e2e): publish Odoo rail + Gate rail baseline results and report
  • fix(e2e): Odoo rail kernel pass — verdict exit, provenance assertion, doc truth
  • test(e2e): republish Odoo rail evidence from the post-kernel run 20260926T184524Z
  • style(e2e): normalize EOF/trailing whitespace in published evidence
  • fix(e2e): YAML-safe redaction placeholder

Test plan

  • make pr local gate receipt present
  • L4 release receipt present (release_authorized)
  • CI green — not measured by open_pr_after_gate.sh — do not treat as verified

Changed files

  • A tests/e2e/constellation_odoo/FINAL_ODOO_E2E_REPORT.md
  • A tests/e2e/constellation_odoo/README.md
  • A tests/e2e/constellation_odoo/compose.eie-deterministic.yml
  • A tests/e2e/constellation_odoo/compose.odoo.yml
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/assertions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/assertions.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/compose_config.yml
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/container_state.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/ceg_to_eie.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/eie_to_ceg.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/isolation.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/main.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/neo4j_state.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/outage.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/recovery.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/flows/registry_during_outage.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/gate_registry.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/health_snapshot.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/image_provenance.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/image_revisions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/ceg.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/eie.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/gate.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/logs/neo4j.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/sdk_lock.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/sdk_provenance.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/secret_scan.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/source_revisions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T181056Z-pristine-heads/workspace_status.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/assertions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/assertions.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/compose_config.yml
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/container_state.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/ceg_to_eie.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/eie_to_ceg.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/isolation.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/main.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/neo4j_state.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/outage.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/recovery.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/flows/registry_during_outage.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/gate_registry.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/health_snapshot.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/image_provenance.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/image_revisions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/ceg.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/eie.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/gate.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/logs/neo4j.log.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/sdk_lock.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/sdk_provenance.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/secret_scan.txt
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/source_revisions.json
  • A tests/e2e/constellation_odoo/results/gate-rail-baseline/20260926T182720Z-eie-accommodated/workspace_status.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/assertions.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/boot_state.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/compose_config.yml
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/container_state.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/eie_business_profile.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/eie_migrations.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/isolation.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/neo4j_odoo_authz_probe.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_adversarial.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_adversarial.raw.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_business.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_business.raw.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_configure.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_configure.raw.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_match.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_match.raw.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_transport.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/flows/odoo_transport.raw.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/gate_registry.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/image_provenance.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/ceg.log.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/eie.log.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/gate.log.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/neo4j.log.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/logs/odoo.log.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/registry_wait.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/registry_wait_business.txt
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/secret_scan.json
  • A tests/e2e/constellation_odoo/results/odoo-rail/20260926T184524Z/source_revisions.json
  • A tests/e2e/constellation_odoo/scripts/assert_odoo_evidence.py
  • A tests/e2e/constellation_odoo/scripts/build_images_odoo.sh
  • A tests/e2e/constellation_odoo/scripts/gen_env_odoo.sh
  • A tests/e2e/constellation_odoo/scripts/odoo_driver.py
  • A tests/e2e/constellation_odoo/scripts/redact_odoo.py
  • A tests/e2e/constellation_odoo/scripts/run_odoo_e2e.sh

Generated by Claude Code

Adds tests/e2e/constellation_odoo: a compose overlay on Constellation.Gate's
release-set rail that puts a real Odoo 19 (IB-Odoo_19 image, plasticos_gate /
plasticos_enrichment / plasticos_matching installed by Odoo) on a network
shared with Gate only, admits exactly one consumer key id (odoo-e2e) into
Gate's keyring, and drives Odoo -> Gate -> EIE -> Gate -> Odoo from inside
the real registry. Adversarial probes cover unsigned, unknown-key, forged,
self-registration and direct-bypass attempts, plus authorization-gap probes.

No product code in any repository is modified.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
… probes

- run EIE's documented alembic migration as an explicit deploy step
- accommodate EIE's missing sqlalchemy[asyncio] and alembic dependencies,
  probed and labelled on the image, never silently
- assert Gate authority on the return leg by its re-signature (the relayed
  response keeps the worker's source_node)
- add O_F1 (EIE empty result reported completed), O_M1/M2 (Odoo vs CEG
  match_direction), O_P1 (Odoo request + target schema reaches writeback)
- README documenting topology, consumer admission and deviations

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
- FINAL_ODOO_E2E_REPORT.md: diagnosis of Odoo consumer admission, per-check
  results, findings (Gate authz gaps, Odoo<->EIE/CEG contract defects, EIE
  packaging defects) and proposed fixes, none applied
- results/: redacted evidence bundles for run 20260926T183719Z (Odoo rail,
  16/17 mandatory) and the Gate rail at pristine heads (FAIL, EIE does not
  boot) and with the EIE accommodation (21/21); secret scan PASS

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
… doc truth

- run_odoo_e2e.sh: capture the verdict status explicitly; set -e + pipefail
  aborted on a FAIL verdict before the bundle path was printed
- odoo_driver.py: O_P1 now requires one ADR-012 provenance row per written
  field; O_B3 reads provenance through the real model
- README: O_T1 documents Gate's relay semantics (re-signature, worker
  source_node); deviations list alembic + the migration deploy step
- compose.odoo.yml: yamllint colon spacing

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
…0926T184524Z

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
A leading '*' in the placeholder made redacted compose_config.yml parse as an
undefined YAML alias (check-yaml). Placeholder is now REDACTED-BY-L9-E2E and
the published compose_config.yml files are normalized; secret scan re-run PASS.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T19:02:30.000667Z c233197 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

❌ PR Too Large
Reviewable additions: 2663
Limit: 1000 added lines
(deletions: 5; total churn 2668 is warn-only)
Action Required: Break into smaller, atomic PRs

📋 Best Practices for Large Changes

  1. Refactoring + Features: Separate into 2 PRs
  2. Multiple Features: One PR per feature
  3. Database + Code: Separate migration from logic
  4. Generated Code: Exclude it from reviewable-size accounting

🚫 This PR is blocked until reviewable size limits are met.

@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

L9 Audit Harness Report

  • Generated: 2026-09-27T02:46:25.175492+00:00
  • Repo root: /home/runner/work/Cognitive.Engine.Graphs/Cognitive.Engine.Graphs
  • Overall result: ✅ PASSED
  • Exit code: 0

Step Results

Step Status Exit Code Notes
Architecture Audit ✅ Passed 0
Spec Coverage ✅ Passed 0
Contract Wiring ✅ Passed 0

Architecture Audit Findings

Severity Count
🔴 CRITICAL 0
🟠 HIGH 0
🟡 MEDIUM 17
🔵 LOW 0

See artifacts/audit_report.md for full details.

Spec Coverage

  • ✅ Implemented: 37
  • ⚠️ Partial: 9
  • ❌ Missing: 0
  • Total features: 46
Category Implemented Partial Missing Total
gates 10 0 0 10
scoring 7 0 0 7
v1.1_node 2 0 0 2
v1.1_edge 2 0 0 2
v1.1_action 0 2 0 2
v1.1_scoring 1 1 0 2
action_handler 0 6 0 6
gds_algorithm 5 0 0 5
research_pattern 10 0 0 10

See artifacts/coverage_report.md for full details.

Next Steps

All checks passed. Safe to merge.

Comment thread tests/e2e/constellation_odoo/scripts/run_odoo_e2e.sh Fixed
Comment thread tests/e2e/constellation_odoo/scripts/run_odoo_e2e.sh Fixed
Comment thread tests/e2e/constellation_odoo/scripts/redact_odoo.py Fixed
- replace print() with sys.stdout/sys.stderr writes in the three rail scripts
  (terminology-guard forbids \bprint\( in Python)
- pack each redacted evidence bundle into one deterministic .tar.gz and add
  results/SUMMARY.md with verbatim verdicts + sha256, taking the PR from 89
  files to 14; secret scan PASS on the tarballs and their unpacked contents

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC

Copy link
Copy Markdown
Collaborator Author

Status after 5b79660

  • Check Terminology Consistency is fixed. print( is replaced with sys.stdout/sys.stderr writes in the three rail scripts.
  • Enforce PR Policies still blocks. The file count is fixed: the evidence is packed into one redacted .tar.gz per run, which takes the PR from 89 files to 14. The PR is still +1686 added lines against the 1000-line cap in .github/pr_review_config.yaml. The harness alone is about 1550 lines, most of it scripts/odoo_driver.py at 610.

I'm not changing the threshold or the policy. The proposed resolution is a bottom-up stack of two PRs, each under 1000 lines:

  1. This PR keeps the overlay, env/build/redact/assert scripts, orchestrator and README (about 770 lines).
  2. A stacked PR adds scripts/odoo_driver.py, FINAL_ODOO_E2E_REPORT.md and results/ (about 920 lines).

That needs one additional branch, which is waiting on the owner's go-ahead. Everything else that has reported is green or still running.


Generated by Claude Code

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c233197e50

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tests/e2e/constellation_odoo/scripts/assert_odoo_evidence.py Outdated
Gate keeps its routing table in memory and its health monitor only probes
nodes already registered. CEG registered once at startup, so after a Gate
restart it stayed unroutable: on the Constellation Docker rail, restarting
Gate left the registry with enrichment-engine only and every match returned
404 until CEG itself restarted. The docstring claim that Gate would discover
the node on its health poll was false and is corrected.

GraphLifecycle now re-runs the existing register_from_env() every
gate_reregistration_interval_seconds (300, matching EIE) behind the
gate_reregistration_enabled flag (default on, hardening; FEATURE_GATES §17)
and cancels the task on shutdown.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
- Gate scopes the Odoo key to converge + match (L9_KEY_ALLOWED_ACTIONS_JSON);
  O_G1 (consumer invoking CEG sync) is now mandatory ENFORCED
- GATE_RESTART_RECOVERY: restart Gate and require EIE and CEG to re-register
  on their own, then re-run the Odoo match phase through the recovered Gate
- EIE migrations now run from its entrypoint; the rail step is an idempotent
  check

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
- results: add after-fix bundles (odoo 20260926T191817Z, gate 20260926T192218Z,
  pristine images, no accommodation); keep the two before-fix bundles; drop
  the superseded EIE-accommodated baseline; SUMMARY.md regenerated
- report §7: applied fixes with commits and a before/after table
- README: EIE deviations resolved at EIE c199c52

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
Address review on #298:
- assert_odoo_evidence: mandatory PROVENANCE_images_and_sdk row; image
  revision must equal the recorded source head and all images must carry
  the same known SDK commit (Codex P1)
- run_odoo_e2e: registry probe writes to a file before parsing (Scorecard
  downloadThenRun)
- redact_odoo: document the intentional JSONDecodeError fallthrough

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
L9E2E_SDK_PARTICIPATION=1 mode for the Odoo rail:

- build_images_odoo.sh sdk-participation: Gate_SDK checkout HEAD installed
  into every image (labelled io.l9.e2e.sdk_overlay), EIE/CEG adoption diffs
  applied as a labelled layer (their own registration loops removed, SDK
  participation on), and l9e2e/sdk-node:local from examples/minimal_node
- compose.sdk-participation.yml: the minimal node on a Gate-only network
- mandatory P_SDK_NODE_ACTIVE/ROUTABLE/RECOVERY (Gate outage drops readiness
  to 503 and it recovers with no node code) and Odoo consumer_sdk checks
  C_ADMISSION_RECEIPT, C_REQUIRED_ACTION_MISSING,
  C_ADMISSION_UNKNOWN_KEY_REJECTED, C_TYPED_403
- provenance requires every image to carry the Gate_SDK head in this mode

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
Odoo rail in SDK participation mode (run 20260927T022821Z), every image on
Gate_SDK eaac6a8, EIE/CEG running on SDK participation with their own
registration loops removed, plus the zero-code sdk-minimal-node:

- P_SDK_NODE_ACTIVE / ROUTABLE / RECOVERY: all three nodes active; the
  minimal node routable through Gate; with Gate down all go 503 degraded and
  recover to 200 active when it returns, with no node code
- C_ADMISSION_RECEIPT / REQUIRED_ACTION_MISSING / UNKNOWN_KEY_REJECTED /
  TYPED_403: Odoo's own config + GateClient.activate() learns its grant
  (converge, match) and gets typed refusals
- all 20 previous mandatory checks still PASS; secret scan PASS

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
trailing-whitespace / end-of-file-fixer stripped the single-space blank
context lines of tests/e2e/constellation_odoo/patches/*.diff, which corrupts
a unified diff. Exclude .diff/.patch data files from those two hooks only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LM9xC9uVBfvnHKRK9jJEyC
@sonarqubecloud

Copy link
Copy Markdown

@cryptoxdog
cryptoxdog merged commit ffa5ac1 into main Sep 28, 2026
56 of 57 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants