test(scanner-storage): contract test + architecture doc (PR 8) - #125
Conversation
… doc (PR 8) Adds Sirius/testing/integration/scanner-storage as a standalone Go module that exercises every producer/consumer pair for templates and NSE scripts through the shared go-api/sirius/store/templates helpers. The suite locks: - canonical key shapes for template:standard|custom|meta:<id> and nse:script:<canonical-id> - the JSON envelope for TemplateRecord and NseScriptRecord - the canonicalization rule that strips .nse before lookup (the original PR 1 regression) - WriteNseManifest canonicalizing its map keys Documents the contract at documentation/dev/architecture/README.scanner-storage.md (llm_context: high) so future sessions auto-load the schema. Also adds the drift policy: any record-shape change must bump go-api, update the doc, and update the contract test in the same change set. Closes the PR 2-8 scanner-templates-fix sprint.
PR Review CardChanged surfaces
Risk flags
Required testing evidence
Reference checklist
Maintainer commands
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0187330b90
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| against an in-memory KV. It runs as part of `make test-integration` and on every | ||
| PR via the Sirius CI Integration Test job. |
There was a problem hiding this comment.
Execute scanner-storage contract suite in integration CI
This section says the new contract suite runs via make test-integration and on every PR, but the integration runners do not invoke testing/integration/scanner-storage (checked testing/container-testing/test-integration.sh and the integration job in .github/workflows/ci.yml). As written, the test is effectively orphaned and schema drift can slip through CI despite the documented drift policy.
Useful? React with 👍 / 👎.
| Created: now, | ||
| Updated: now, | ||
| VulnerabilityIDs: []string{"CVE-2026-0001"}, | ||
| IsCustom: true, |
There was a problem hiding this comment.
Cover standard template path in pairwise contract test
TestContract_TemplateWriterReaderPairs always uses sampleTemplate(), which hardcodes IsCustom: true, so even the case labeled app-agent -> sirius-api exercises only template:custom:*. That misses the template:standard:* write/read path used by app-agent sync, so a regression in standard-key handling or fallback precedence would not be caught by this contract test.
Useful? React with 👍 / 👎.
Summary
Closes the PR 2-8 scanner-templates-fix sprint. Adds:
Companion PRs already merged for the sprint:
Test plan