The keycloak project ended with four open questions that design could not
settle. A two-VM lab was built to answer them by measurement, and this is
that material: 26 experiments, 125 raw command outputs, 22 browser captures.
Follows the import procedure in README.md.
source/ the originating repository verbatim — 78 documents, 28 SVGs,
8 manifests, plus .source-revision recording the commit
final/ the SSOT
document.md 729 lines written from the 29 experiment documents, not
concatenated: what was predicted, what was measured, and
where the measurement itself was wrong
evidence/raw 125 outputs, flattened to <experiment>__<file> because
the originals collided (01-baseline.txt appeared three
times) and the audit only globs the top level
evidence/meta one per raw file; command and exitCode are null and the
README says why rather than inventing them
evidence/browser 22 captures
assets/ three diagrams through techviz
.techviz/ their VizSpecs
A separate project rather than an addition to keycloak: the B-layer answers
that project's four questions, but the A, C and D layers are about cluster
failure, SSO and operations, and one document.md should hold one subject.
The four question records there can point here through 관계.
Recorded rather than papered over: only three of the 28 diagrams were
remade. The repository forbids hand-drawn SVG and forbids titles inside the
canvas; all 28 originals carry both, so converting them is redrawing, not
reformatting. They stay in source/ and the gap is written into the document.
verify-pipeline.py passes. audit-records.py reports no issues.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
414 lines
25 KiB
Plaintext
414 lines
25 KiB
Plaintext
Sub-scope 11 (mongo) testkit + architecture/rs/release/compat tests + performance lane
|
|
revision=a24ece9cf797f7ea647e33bf846b115208ed1ba5
|
|
generatedAt=2026-08-30T00:33:51+00:00
|
|
|
|
=== OWNED FILES ===
|
|
969d169073092559909a40533c5a9cfd1cdb0333 mongoPerformanceTest/java/dev/caskeleton/adapter/outbound/mongo/performance/MongoResourceBudgetLaneTest.java 194
|
|
4356aa23d0cc30c838199d55140f678c2241dd5f testkit/java/dev/caskeleton/adapter/outbound/mongo/architecture/MongoCollectionProfile.java 23
|
|
58acdd2ff79fffadac374fa0d595de29cf6cd73a testkit/java/dev/caskeleton/adapter/outbound/mongo/architecture/MongoOperation.java 23
|
|
952aacfc01dcabf149f062be47a76b24fa1bb77c testkit/java/dev/caskeleton/adapter/outbound/mongo/architecture/MongoRepositoryArchitectureRules.java 70
|
|
d15787c0a7a6f2a33f01ffd1018fb790a5a9ee07 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/arch/MongoAccessRules.java 83
|
|
6a712168e2429962d09662dc817536c1d462a652 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/arch/MongoAdvancedRules.java 140
|
|
9334ecc25ef041df422aab97e0d697c582a7bf0b testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/atlas/MongoAtlasCapabilityContractSuite.java 85
|
|
3c600c7512402c62fd07bad355f88b384934f108 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/atlas/MongoAtlasLocalContainer.java 55
|
|
d462535cb7955e676cab62809325aaa64b0d3d53 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/compat/MongoStableContractSuite.java 88
|
|
1a00293b475591efec09f51fa70f1472f4d812f6 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/compat/MongoVersionCapabilityReport.java 94
|
|
e323742f3777b214a9f4bc7aba5b01cbf3602c69 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/compat/MongoVersionMatrix.java 41
|
|
6d49ff04c6d40f2cda26e8c69ed7db0cdadc4181 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/failover/MongoFailoverScenario.java 68
|
|
0537852c605074f7b6bf8ff0942ee6fa3f45eeae testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/failover/MongoNetworkFaultController.java 33
|
|
80a0de8b1b3b3f1d4009cecc371580c9166e7f1f testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/failover/MongoPrimaryController.java 23
|
|
b6d323c64f80f0248f5bb2cbd2c0a76fe4a8da24 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/failover/MongoProxiedReplicaSetNode.java 142
|
|
77b587ce9995c3bd12e5d36a800578db8a40082c testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/failover/MongoThreeNodeReplicaSet.java 281
|
|
5fa768acfe364d1e15fe3021ca0cbc0f30988bda testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/failover/ToxiproxyMongoNetworkFaultController.java 170
|
|
c964bd9addd5bea5a4aee9375822eeffae8e1554 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/mapping/MongoBsonSnapshot.java 118
|
|
c258c5d68aa99f1bf0c971da85e4ebc5cbda5a16 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/mapping/MongoBsonSnapshotAssert.java 82
|
|
a363dbcdbeb575c9e3e493cc28254497bfd1be7e testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/mapping/MongoRoundTripContract.java 75
|
|
31f7d619870f171ac035703f65087865e1af02e5 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/migration/MongoBackfillRestartFixture.java 73
|
|
f45e22860de899345218ea8802523d14837475e9 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/migration/MongoMigrationContractSuite.java 75
|
|
d23251965eb60a9f7c7d6af4d729e3943375325e testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/migration/MongoMigrationSnapshotFixture.java 54
|
|
86c786872ea7711f5f76d225038e56fa3c8c4871 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/performance/MongoChaosGate.java 94
|
|
bf51484f712cdc4ab1ceb922c686ac2cb23de6b1 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/performance/MongoPerformanceGate.java 69
|
|
954ee45c4335cdf26b6cde35d00c327e379d5a16 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/performance/MongoResourceBudgetReport.java 46
|
|
272260d8c4a1d6802bb29d7ec1ffefbb2a212c09 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/release/MongoReleaseContract.java 41
|
|
c68191b601d9fa8a4b2f353d7294532ed5efe174 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/release/MongoReleaseEvidence.java 54
|
|
a8bb6a2e07d4f1857d7a9dcef9b2003726e9fa8a testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/release/MongoReleaseEvidenceVerifier.java 96
|
|
ea2e9f9bd21d68c68e196cd880de318ae19ac731 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/rs/MongoAuthenticatedReplicaSetContainer.java 201
|
|
64dbc66f3ac1b24f813fc9372dd980906fb916bc testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/rs/MongoReplicaSetContract.java 59
|
|
12e0a6c6fe1f4363f1f71ced94f0b47c8271772c testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/rs/MongoReplicaSetFixture.java 60
|
|
6d3e32302676f8e8da2cd476cc065a3dbca5fda9 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/rs/MongoSingleReplicaSetContainer.java 91
|
|
3402a220b53bfd3489e47148d0c09ec1991e17b9 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/rs/MongoTlsReplicaSetContainer.java 206
|
|
8f88be92b489389f509b4971e283200f891e0382 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/sharded/MongoChunkMigrationController.java 23
|
|
4f129fc2920e5ee6c3c9bde5286ef0873d7547b8 testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/sharded/MongoShardingContractSuite.java 100
|
|
4d0c4aa5219949785bf93b1c29c52f742e4a3402 test/java/dev/caskeleton/adapter/outbound/mongo/MongoNamespaceContractTest.java 111
|
|
d5d295ca11cab21f4e760cbe76713531172e1471 test/java/dev/caskeleton/adapter/outbound/mongo/MongoPersistenceConfigTest.java 83
|
|
a6fa3c4fe07ba96c2da7391ace1d5b07904d3d2b test/java/dev/caskeleton/adapter/outbound/mongo/architecture/MongoAccessRulesTest.java 85
|
|
84a6b3efe5d29ee96e7ae9db53af99dbac80f94e test/java/dev/caskeleton/adapter/outbound/mongo/architecture/MongoAdvancedRulesTest.java 101
|
|
7eef04f1a6c79eaa0738eb4cfc2f56980addc12a test/java/dev/caskeleton/adapter/outbound/mongo/architecture/MongoModuleBoundaryTest.java 371
|
|
4dff114b6288d2887fc9bab7757bf84828168312 test/java/dev/caskeleton/adapter/outbound/mongo/architecture/MongoRepositoryArchitectureRulesTest.java 43
|
|
32e6fa486f95f7a87001603312e73058b2901693 test/java/dev/caskeleton/adapter/outbound/mongo/compat/MongoVersionCompatibilityLaneTest.java 155
|
|
a39ee76fa5239708f6805fc33bee33bb55076c8b test/java/dev/caskeleton/adapter/outbound/mongo/release/MongoReleaseEvidenceVerifierTest.java 136
|
|
7672b70b7cbd73e139fcbe3173537bd222f38772 test/java/dev/caskeleton/adapter/outbound/mongo/rs/MongoSingleReplicaSetContainerTest.java 111
|
|
c0dfd07b5eb219f07ccbc3d6199250b9f6b4dd12 test/java/dev/caskeleton/adapter/outbound/mongo/rs/MongoThreeNodeReplicaSetTest.java 37
|
|
8d84d6c9f950e7b64aab30c0caa1c228c600aba3 test/java/dev/caskeleton/adapter/outbound/mongo/testkit/compat/MongoVersionMatrixTest.java 74
|
|
cab451aa87ceedf9cf3c65a5f9da523d8089875e test/java/dev/caskeleton/adapter/outbound/mongo/testkit/performance/MongoReleaseEvidenceTest.java 95
|
|
f640940e08141c256e148e525efeee4de7a2f5e5 test/java/dev/caskeleton/adapter/outbound/mongo/testkit/sharded/MongoShardingContractSuiteTest.java 64
|
|
|
|
testkit: 35
|
|
performance: 1
|
|
test: 13
|
|
testkit LOC: 3036 total
|
|
|
|
=== 8.1 reachability: which testkit types have no consumer at all ===
|
|
MongoAtlasCapabilityContractSuite consumers: test=1 testkit=1
|
|
MongoAtlasLocalContainer consumers: test=0 testkit=0
|
|
MongoChunkMigrationController consumers: test=0 testkit=0
|
|
MongoPrimaryController consumers: test=0 testkit=1
|
|
MongoNetworkFaultController consumers: test=0 testkit=2
|
|
MongoProxiedReplicaSetNode consumers: test=1 testkit=0
|
|
ToxiproxyMongoNetworkFaultController consumers: test=0 testkit=1
|
|
MongoThreeNodeReplicaSet consumers: test=1 testkit=0
|
|
MongoRoundTripContract consumers: test=0 testkit=0
|
|
MongoBsonSnapshotAssert consumers: test=1 testkit=0
|
|
MongoBsonSnapshot consumers: test=1 testkit=2
|
|
MongoBackfillRestartFixture consumers: test=1 testkit=0
|
|
MongoMigrationContractSuite consumers: test=1 testkit=0
|
|
MongoMigrationSnapshotFixture consumers: test=2 testkit=1
|
|
MongoReplicaSetFixture consumers: test=1 testkit=0
|
|
MongoAuthenticatedReplicaSetContainer consumers: test=1 testkit=0
|
|
MongoTlsReplicaSetContainer consumers: test=1 testkit=0
|
|
MongoShardingContractSuite consumers: test=1 testkit=0
|
|
MongoStableContractSuite consumers: test=1 testkit=0
|
|
MongoVersionCapabilityReport consumers: test=2 testkit=0
|
|
MongoVersionMatrix consumers: test=2 testkit=1
|
|
MongoChaosGate consumers: test=2 testkit=0
|
|
MongoPerformanceGate consumers: test=2 testkit=0
|
|
MongoResourceBudgetReport consumers: test=2 testkit=1
|
|
MongoReleaseContract consumers: test=1 testkit=2
|
|
MongoReleaseEvidence consumers: test=2 testkit=1
|
|
MongoReleaseEvidenceVerifier consumers: test=1 testkit=0
|
|
MongoAccessRules consumers: test=1 testkit=0
|
|
MongoAdvancedRules consumers: test=1 testkit=0
|
|
MongoRepositoryArchitectureRules consumers: test=2 testkit=1
|
|
MongoSingleReplicaSetContainer consumers: test=4 testkit=3
|
|
MongoReplicaSetContract consumers: test=1 testkit=1
|
|
MongoFailoverScenario consumers: test=2 testkit=1
|
|
|
|
=== 8.2 two coverage gates in one testkit: one counts, one cannot ===
|
|
$ grep -n 'public MongoStableContractReport run' -A 24 adapter/outbound/persistence-mongo/src/testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/compat/MongoStableContractSuite.java
|
|
37: public MongoStableContractReport run(
|
|
38- String version, Predicate<MongoReplicaSetContract> contractRunner) {
|
|
39- Objects.requireNonNull(version, "version");
|
|
40- Objects.requireNonNull(contractRunner, "contractRunner");
|
|
41- if (!matrix.certifies(version)) {
|
|
42- throw new IllegalArgumentException(
|
|
43- "version " + version + " is not one of the certified lanes " + matrix.stableVersions());
|
|
44- }
|
|
45-
|
|
46- List<String> failures = new ArrayList<>();
|
|
47- Set<MongoReplicaSetContract> executed = new LinkedHashSet<>();
|
|
48- for (MongoReplicaSetContract contract : MongoReplicaSetContract.all()) {
|
|
49- executed.add(contract);
|
|
50- if (!contractRunner.test(contract)) {
|
|
51- failures.add(version + '/' + contract.name());
|
|
52- }
|
|
53- }
|
|
54- Set<MongoReplicaSetContract> missing = new LinkedHashSet<>(MongoReplicaSetContract.all());
|
|
55- missing.removeAll(executed);
|
|
56- missing.forEach(contract -> failures.add(version + '/' + contract.name() + " (not executed)"));
|
|
57- return new MongoStableContractReport(version, List.copyOf(failures), Set.copyOf(executed));
|
|
58- }
|
|
59-
|
|
60- /**
|
|
61- * What one lane's run produced.
|
|
exit=0
|
|
|
|
$ grep -n 'public MongoChaosReport report' -A 18 adapter/outbound/persistence-mongo/src/testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/performance/MongoChaosGate.java
|
|
51: public MongoChaosReport report() {
|
|
52- List<String> failures =
|
|
53- executed.entrySet().stream()
|
|
54- .filter(entry -> !Boolean.TRUE.equals(entry.getValue()))
|
|
55- .map(entry -> entry.getKey().name())
|
|
56- .toList();
|
|
57- List<String> missing =
|
|
58- MongoFailoverScenario.all().stream()
|
|
59- .filter(scenario -> !executed.containsKey(scenario))
|
|
60- .map(scenario -> scenario.name() + " (not executed)")
|
|
61- .toList();
|
|
62- return new MongoChaosReport(
|
|
63- java.util.stream.Stream.concat(failures.stream(), missing.stream()).toList(),
|
|
64- businessBodyRetriesAfterUnknownCommit,
|
|
65- lostChangeEvents,
|
|
66- duplicateProjections);
|
|
67- }
|
|
68-
|
|
69- /**
|
|
exit=0
|
|
|
|
=== 8.2b what the two suites' certified()/passed() actually assert ===
|
|
$ grep -n 'public boolean certified' -A 4 adapter/outbound/persistence-mongo/src/testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/compat/MongoStableContractSuite.java
|
|
77: public boolean certified() {
|
|
78- return failures.isEmpty() && executed.containsAll(MongoReplicaSetContract.all());
|
|
79- }
|
|
80-
|
|
81- /** The evidence categories this run covered. */
|
|
exit=0
|
|
|
|
$ grep -n 'public boolean passed' -A 6 adapter/outbound/persistence-mongo/src/testkit/java/dev/caskeleton/adapter/outbound/mongo/testkit/performance/MongoChaosGate.java
|
|
88: public boolean passed() {
|
|
89- return failures.isEmpty()
|
|
90- && businessBodyRetriesAfterUnknownCommit == 0
|
|
91- && lostChangeEvents == 0;
|
|
92- }
|
|
93- }
|
|
94-}
|
|
exit=0
|
|
|
|
$ grep -n 'stableContractsRunOnEverySupportedLane' -A 12 adapter/outbound/persistence-mongo/src/test/java/dev/caskeleton/adapter/outbound/mongo/testkit/compat/MongoVersionMatrixTest.java
|
|
20: void stableContractsRunOnEverySupportedLane(String version) {
|
|
21- MongoStableContractSuite.MongoStableContractReport report =
|
|
22- MongoStableContractSuite.standard().run(version, contract -> true);
|
|
23-
|
|
24- assertThat(report.failures()).isEmpty();
|
|
25- assertThat(report.certified()).isTrue();
|
|
26- assertThat(report.executed()).containsAll(MongoReplicaSetContract.all());
|
|
27- }
|
|
28-
|
|
29- @Test
|
|
30- void aFailedContractIsReportedWithItsLane() {
|
|
31- MongoStableContractSuite.MongoStableContractReport report =
|
|
32- MongoStableContractSuite.standard()
|
|
exit=0
|
|
|
|
$ grep -n 'aScenarioThatNeverRanIsAFailure' -A 10 adapter/outbound/persistence-mongo/src/test/java/dev/caskeleton/adapter/outbound/mongo/testkit/performance/MongoReleaseEvidenceTest.java
|
|
34: void aScenarioThatNeverRanIsAFailureRatherThanASilence() {
|
|
35- MongoChaosGate gate = new MongoChaosGate();
|
|
36- gate.record(MongoFailoverScenario.PRIMARY_KILL, true);
|
|
37-
|
|
38- assertThat(gate.report().failures())
|
|
39- .anyMatch(failure -> failure.endsWith("(not executed)"))
|
|
40- .anyMatch(failure -> failure.startsWith("OPLOG_HISTORY_LOSS"));
|
|
41- }
|
|
42-
|
|
43- @Test
|
|
44- void duplicateProjectionsAreExpectedRatherThanFatal() {
|
|
exit=0
|
|
|
|
=== 8.3 the release contract list: where is it declared? ===
|
|
$ git grep -rn 'new MongoReleaseContract' -- . | head -20
|
|
adapter/outbound/persistence-mongo/src/test/java/dev/caskeleton/adapter/outbound/mongo/release/MongoReleaseEvidenceVerifierTest.java:33: new MongoReleaseContract(
|
|
adapter/outbound/persistence-mongo/src/test/java/dev/caskeleton/adapter/outbound/mongo/release/MongoReleaseEvidenceVerifierTest.java:109: () -> new MongoReleaseContract("X", "d", "task", "Class", "sharded", 0))
|
|
exit=0
|
|
|
|
$ ls ../scripts 2>/dev/null | head -30
|
|
run-compose-runtime-smoke.sh
|
|
verify-compose-profile-contracts.sh
|
|
verify-httpclient-docs.py
|
|
verify-mongodb-advanced.sh
|
|
verify-mongodb-platform.sh
|
|
exit=0
|
|
|
|
$ grep -rln 'MongoReleaseEvidenceVerifier\|MongoReleaseContract' ../scripts ../docs ../.github 2>/dev/null | head
|
|
../scripts/verify-mongodb-advanced.sh
|
|
../docs/superpowers/plans/evidence/2026-08-15-wave6-final/task1-check.log
|
|
exit=0
|
|
|
|
=== 8.4 lanes: definitions, tags, and the performance lane's place ===
|
|
$ sed -n '85,150p' adapter/outbound/persistence-mongo/build.gradle
|
|
//
|
|
// `mongodb-contract` is excluded here too. It was not, and `check` depends on both `test` and
|
|
// `mongoStableContractTest`, so every one of the 382 hermetic contract tests ran twice on a fresh
|
|
// build — once in each task. The two lanes are now disjoint by construction, and
|
|
// `MongoTestLaneDisjointnessTest` asserts it against the JUnit XML rather than trusting this
|
|
// comment.
|
|
tasks.named('test', Test) {
|
|
useJUnitPlatform {
|
|
excludeTags 'quarantine',
|
|
'mongodb-contract',
|
|
'mongodb-replicaset',
|
|
'mongodb-failover',
|
|
'mongodb-migration',
|
|
'mongodb-compatibility',
|
|
'mongodb-security-integration'
|
|
}
|
|
}
|
|
|
|
// Six lanes, declared rather than assembled. `ca.strict-test-lane` owns testClassesDirs, classpath,
|
|
// tag selection, failOnNoDiscoveredTests and the up-to-date refusal — the five lines that used to be
|
|
// copied once per lane here and again in four other leaves.
|
|
strictTestLanes {
|
|
lane('mongoReplicaSetTest') {
|
|
tag = 'mongodb-replicaset'
|
|
description = 'Single-node replica set contract lane: mapping, atomic write, transaction, ' +
|
|
'change stream (design §29).'
|
|
customize = { test -> applyMongoImageSelection(test) }
|
|
}
|
|
lane('mongoFailoverTest') {
|
|
tag = 'mongodb-failover'
|
|
description = 'Three-node replica set failover lane: primary kill, partition, unknown ' +
|
|
'commit, resume (design §29).'
|
|
customize = { test -> applyMongoImageSelection(test) }
|
|
}
|
|
lane('mongoMigrationTest') {
|
|
tag = 'mongodb-migration'
|
|
description = 'Migration lane: empty / N-1 / oldest-supported snapshots, lock, checkpoint ' +
|
|
'restart (design §12).'
|
|
customize = { test -> applyMongoImageSelection(test) }
|
|
}
|
|
lane('mongoCompatibilityTest') {
|
|
tag = 'mongodb-compatibility'
|
|
description = 'MongoDB 7.0 compatibility and 8.0 primary certification matrix (design §30).'
|
|
customize = { test -> applyMongoImageSelection(test) }
|
|
}
|
|
lane('mongoSecurityIntegrationTest') {
|
|
tag = 'mongodb-security-integration'
|
|
description = 'RBAC, TLS, injection and redaction release gate against a real server ' +
|
|
'(design §26).'
|
|
customize = { test -> applyMongoImageSelection(test) }
|
|
}
|
|
|
|
// Driven by its own source set rather than a tag: for this shape the source set is the
|
|
// selection, so the convention asks for no tag.
|
|
lane('mongoPerformanceTest') {
|
|
sourceSet = 'mongoPerformanceTest'
|
|
description = 'Certifies contention, aggregation spill, pagination and pool resource ' +
|
|
'bounds (design §29).'
|
|
customize = { test ->
|
|
applyMongoImageSelection(test)
|
|
// Assertions on by default. They defaulted to false, so the lane measured numbers and
|
|
// compared them to nothing — a performance gate whose bounds are never evaluated is a
|
|
// report, and the release evidence called it a certification.
|
|
test.systemProperty 'performance.assertions.enabled',
|
|
(project.findProperty('performance.assertions.enabled') ?: 'true').toString()
|
|
}
|
|
exit=0
|
|
|
|
$ grep -rn 'mongoPerformanceTest\|mongoFailoverTest\|mongoSecurityIntegrationTest' ../.github 2>/dev/null | head -20
|
|
exit=0
|
|
|
|
|
|
=== 8.3b where the release contract list actually lives ===
|
|
$ grep -n 'MongoReleaseEvidenceVerifier\|MongoReleaseContract\|contract' ../scripts/verify-mongodb-advanced.sh | head -30
|
|
5:# Advanced capabilities are opt-in modules. This script verifies the contracts that can be verified
|
|
54:# Every Advanced refusal contract: disabled capability refuses construction, CSFLE/QE cannot share a
|
|
58:echo "=== [failure] Advanced contract tests"
|
|
88:# The selector names the contract's class. `--tests '*Shard*'` was satisfied by the hermetic
|
|
90:# connection. Which classes count is `src/config/mongodb/release-contracts.json`, and
|
|
91:# MongoReleaseEvidenceVerifier checks the JUnit XML rather than the exit code.
|
|
93: # Not promoted. `mongoShardedTest` is declared in release-contracts.json under
|
|
94: # experimental_contracts and is registered by no build file, so invoking it here could only ever
|
|
100: echo " See experimental_contracts in src/config/mongodb/release-contracts.json." >&2
|
|
108:# contract is satisfied by a lane that ran against the deployment it names, which is why this
|
|
150:echo "verifiable contracts: PASSED"
|
|
exit=0
|
|
|
|
$ wc -l ../scripts/verify-mongodb-platform.sh ../scripts/verify-mongodb-advanced.sh
|
|
177 ../scripts/verify-mongodb-platform.sh
|
|
164 ../scripts/verify-mongodb-advanced.sh
|
|
341 total
|
|
exit=0
|
|
|
|
=== 8.4b CI wiring for the mongo lanes ===
|
|
$ ls -1 ../.github/workflows 2>/dev/null
|
|
ci-quality-gates.yml
|
|
dependency-vulnerability.yml
|
|
fileserver-nightly.yml
|
|
fileserver-pr.yml
|
|
fileserver-release.yml
|
|
httpclient-contract.yml
|
|
httpclient-nightly.yml
|
|
httpclient-release.yml
|
|
jpa-next-hibernate8.yml
|
|
jpa-next-jpa4.yml
|
|
jpa-next-postgresql19.yml
|
|
jpa-nightly.yml
|
|
jpa-pr.yml
|
|
jpa-r2-evidence.yml
|
|
jpa-release.yml
|
|
link-check.yml
|
|
messaging-certification.yml
|
|
notification-platform.yml
|
|
object-storage-qualification.yml
|
|
redis-sdk-topology.yml
|
|
web-advanced-nightly.yml
|
|
web-advanced-release.yml
|
|
web-nightly.yml
|
|
web-pr.yml
|
|
web-release.yml
|
|
websocket-advanced-nightly.yml
|
|
websocket-pr.yml
|
|
websocket-release.yml
|
|
exit=0
|
|
|
|
$ grep -rn 'mongo' ../.github/workflows 2>/dev/null | head -20
|
|
exit=0
|
|
|
|
=== 8.4c the build.gradle hermetic-count claim vs measured (cross-ref sub-scope 01) ===
|
|
$ grep -n '382 hermetic\|311 of 313' adapter/outbound/persistence-mongo/build.gradle
|
|
87:// `mongoStableContractTest`, so every one of the 382 hermetic contract tests ran twice on a fresh
|
|
exit=0
|
|
|
|
=== 8.2c the dead branch, stated plainly ===
|
|
MongoStableContractSuite.run: 'executed' is filled unconditionally inside the loop over
|
|
MongoReplicaSetContract.all() (line 49), so 'missing' (lines 54-56) is always empty and
|
|
report.certified()'s executed.containsAll(all()) (line 78) is always true. The class
|
|
javadoc says 'a missing contract is a failure here'; no input can produce that failure.
|
|
MongoChaosGate.report() in the same testkit does the same job correctly: 'executed' is a
|
|
map filled only by explicit record(scenario, passed) calls, so a scenario nobody recorded
|
|
shows up as '(not executed)'. Its test proves it by recording one of thirteen scenarios.
|
|
The contract suite's equivalent test passes 'contract -> true' for every contract and then
|
|
asserts executed contains all of them, which is true by construction.
|
|
$ git status --short | wc -l
|
|
0
|
|
exit=0
|
|
|
|
|
|
=== 8.3c the canonical release-contract list ===
|
|
$ ls -l config/mongodb/ 2>&1
|
|
total 4
|
|
-rw-rw-r-- 1 ubuntu ubuntu 3769 Aug 19 16:30 release-contracts.json
|
|
exit=0
|
|
|
|
$ python3 -c "
|
|
import json;d=json.load(open('config/mongodb/release-contracts.json'))
|
|
print('top-level keys:', list(d.keys()))
|
|
for k,v in d.items():
|
|
if isinstance(v,list):
|
|
print(k, 'count=', len(v))
|
|
for c in v: print(' ', c.get('id'), c.get('task'), c.get('className'), 'topology=' + str(c.get('topology')), 'min=' + str(c.get('minimumExecuted')))
|
|
"
|
|
top-level keys: ['contracts', 'experimental_contracts', 'note']
|
|
contracts count= 3
|
|
MONGO-REL-001 mongoStableContractTest dev.caskeleton.adapter.outbound.mongo.architecture.MongoModuleBoundaryTest topology=none min=1
|
|
MONGO-REL-002 mongoStableContractTest dev.caskeleton.adapter.outbound.mongo.architecture.MongoAdvancedRulesTest topology=none min=5
|
|
MONGO-REL-003 mongoStableContractTest dev.caskeleton.adapter.outbound.mongo.transaction.retry.MongoTransactionRetryCoordinatorTest topology=none min=3
|
|
experimental_contracts count= 3
|
|
MONGO-REL-010 mongoShardedTest dev.caskeleton.adapter.outbound.mongo.advanced.sharding.MongoShardedTopologyContractTest topology=sharded min=1
|
|
MONGO-REL-011 mongoAtlasTest dev.caskeleton.adapter.outbound.mongo.advanced.search.MongoAtlasContractTest topology=atlas min=1
|
|
MONGO-REL-012 mongoKmsTest dev.caskeleton.adapter.outbound.mongo.advanced.encryption.MongoKmsContractTest topology=kms min=1
|
|
exit=0
|
|
|
|
$ grep -rn 'release-contracts.json' -- . | grep -v Binary | head
|
|
grep: ./.gradle/9.0.0/executionHistory/executionHistory.bin: binary file matches
|
|
grep: ./app-bootstrap/build/classes/java/test/dev/caskeleton/bootstrap/registry/ReleaseManifestTaskExistenceTest.class: binary file matches
|
|
grep: ./app-bootstrap/build/classes/java/sampleOffTest/dev/caskeleton/bootstrap/registry/ReleaseManifestTaskExistenceTest.class: binary file matches
|
|
./app-bootstrap/src/test/java/dev/caskeleton/bootstrap/registry/ReleaseManifestTaskExistenceTest.java:51: blockingTaskNamesIn(root.resolve("src/config/mongodb/release-contracts.json"));
|
|
./adapter/outbound/persistence-mongo/build.gradle:210: def manifest = rootProject.file('../src/config/mongodb/release-contracts.json')
|
|
./adapter/outbound/persistence-mongo/CLAUDE.md:92:`scripts/verify-mongodb-platform.sh` and `src/config/mongodb/release-contracts.json` drive. A second
|
|
exit=0
|
|
|
|
$ grep -n 'mongoShardedTest' ../scripts/verify-mongodb-advanced.sh
|
|
93: # Not promoted. `mongoShardedTest` is declared in release-contracts.json under
|
|
99: echo " MONGODB_SHARDED_URI was set but mongoShardedTest does not exist." >&2
|
|
exit=0
|
|
|
|
$ grep -rn 'mongoShardedTest' adapter/outbound/persistence-mongo/build.gradle build.gradle settings.gradle 2>/dev/null
|
|
exit=1
|
|
|
|
=== 8.4d there is no MongoDB CI workflow ===
|
|
26 workflow files exist under .github/workflows and none of them mentions mongo
|
|
(grep -rn 'mongo' ../.github/workflows -> no matches).
|
|
The sibling JPA leaf has seven: jpa-pr, jpa-nightly, jpa-release, jpa-r2-evidence and
|
|
three jpa-next-* forward-compatibility workflows.
|
|
So the six declared mongo lanes - all of which are excluded from the default 'test' task
|
|
and all of which need a container - run only when somebody invokes them by hand.
|