Skip to content

test(scanner-storage): contract test + architecture doc (PR 8) - #125

Merged
0sm0s1z merged 1 commit into
mainfrom
feature/scanner-templates-fix-pr8
Apr 23, 2026
Merged

0sm0s1z merged 1 commit into
mainfrom
feature/scanner-templates-fix-pr8

Conversation

@0sm0s1z

@0sm0s1z 0sm0s1z commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Summary

Closes the PR 2-8 scanner-templates-fix sprint. Adds:

  • Contract test at `Sirius/testing/integration/scanner-storage/` (standalone Go module). Exercises every producer/consumer pair for agent templates and NSE scripts through the shared `go-api/sirius/store/templates` helpers. Pins canonical key shapes, JSON envelopes, the `.nse` canonicalization rule (the original PR 1 regression), and `WriteNseManifest` map-key canonicalization.
  • Architecture doc at `documentation/dev/architecture/README.scanner-storage.md` with `llm_context: high`. Documents producers/consumers, queues, key namespaces, record schemas, the helpers callers should be using, and the drift policy (any record-shape change must bump go-api, update the doc, and update the contract test in the same change set). Wired into the documentation index.

Companion PRs already merged for the sprint:

Test plan

  • `cd Sirius/testing/integration/scanner-storage && go test -v ./...` (6 tests, all pass)
  • `make lint-docs-quick` and `make lint-index` green

… doc (PR 8)

Adds Sirius/testing/integration/scanner-storage as a standalone Go module
that exercises every producer/consumer pair for templates and NSE scripts
through the shared go-api/sirius/store/templates helpers. The suite locks:

- canonical key shapes for template:standard|custom|meta:<id> and
  nse:script:<canonical-id>
- the JSON envelope for TemplateRecord and NseScriptRecord
- the canonicalization rule that strips .nse before lookup (the original
  PR 1 regression)
- WriteNseManifest canonicalizing its map keys

Documents the contract at documentation/dev/architecture/README.scanner-storage.md
(llm_context: high) so future sessions auto-load the schema. Also adds the
drift policy: any record-shape change must bump go-api, update the doc, and
update the contract test in the same change set.

Closes the PR 2-8 scanner-templates-fix sprint.
@github-actions

Copy link
Copy Markdown

PR Review Card

Changed surfaces

  • type:docs

Risk flags

  • No high-risk patterns detected by automation.

Required testing evidence

  • Documentation checklist (lint-docs, lint-index)

Reference checklist

  • documentation/dev/test/CHECKLIST.testing-by-type.md

Maintainer commands

  • /test health
  • /test integration
  • /test security auth-surface

@0sm0s1z
0sm0s1z merged commit e418f0e into main Apr 23, 2026
18 checks passed
@0sm0s1z
0sm0s1z deleted the feature/scanner-templates-fix-pr8 branch April 23, 2026 04:00

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0187330b90

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +165 to +166
against an in-memory KV. It runs as part of `make test-integration` and on every
PR via the Sirius CI Integration Test job.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Execute scanner-storage contract suite in integration CI

This section says the new contract suite runs via make test-integration and on every PR, but the integration runners do not invoke testing/integration/scanner-storage (checked testing/container-testing/test-integration.sh and the integration job in .github/workflows/ci.yml). As written, the test is effectively orphaned and schema drift can slip through CI despite the documented drift policy.

Useful? React with 👍 / 👎.

Created: now,
Updated: now,
VulnerabilityIDs: []string{"CVE-2026-0001"},
IsCustom: true,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Cover standard template path in pairwise contract test

TestContract_TemplateWriterReaderPairs always uses sampleTemplate(), which hardcodes IsCustom: true, so even the case labeled app-agent -> sirius-api exercises only template:custom:*. That misses the template:standard:* write/read path used by app-agent sync, so a regression in standard-key handling or fallback precedence would not be caught by this contract test.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant