Skip to content

Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure rework #3049

Open
seropian wants to merge 36 commits into
apache:OAK-12219-test2from
seropian:OAK-12219-Upgrade-Azure-SDK-V8-to-V12-for-oak-blob-azure---rework-
Open

Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure rework #3049
seropian wants to merge 36 commits into
apache:OAK-12219-test2from
seropian:OAK-12219-Upgrade-Azure-SDK-V8-to-V12-for-oak-blob-azure---rework-

Conversation

@seropian

Copy link
Copy Markdown
Contributor

No description provided.

reschke and others added 30 commits July 8, 2026 10:12
* Add draft project security threat-model document

Adds a draft project-level security threat-model document
(draft-THREAT-MODEL.md) at repo root, improving discoverability
for automated security scanners running against this repository.
The file follows the rubric format used by several other ASF
projects piloting security-model discoverability.

The "draft-" prefix signals this is a proposal for the PMC to
review, correct, or reject — not a finalised maintainer-blessed
model. Every claim carries a provenance tag (documented /
inferred / maintainer) so reviewers can see where each claim
originates; §14 collects open questions for the maintainers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Revise threat model per PMC review (Java 17, trust-boundary/XXE, oak-http, TarMK open)

Generated-by: Claude Code

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* OAK-12295 : bump mongo-driver-sync to 5.3.1 (apache#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12295 : expanded range to include 5.2 to 5.4
…pache#3005)

The EventServiceListener was never removed from the BundleContext after
awaitServiceEvent completed (either successfully or via timeout). This caused:

1. Resource leaks - listeners accumulated across test runs
2. Test interference - listeners from previous tests continued receiving events
3. Intermittent test failures - unrelated service events could be captured,
   causing timeout errors when waiting for specific service events

Fix: Add try-finally block to ensure bundleContext.removeServiceListener()
is always called after the await completes, preventing listener accumulation
and cross-test event interference.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…MODEL.md (apache#3042)

Adds AGENTS.md (## Security pointer) + SECURITY.md wiring the
conventional AGENTS.md -> SECURITY.md -> THREAT_MODEL.md chain, and
renames the PMC-merged draft-THREAT-MODEL.md to the canonical
THREAT_MODEL.md (no longer a draft; matches the discoverable
convention). No model content changes.

Generated-by: Claude Code (Claude Opus 4.8)
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude
…he#3043)

* OAK-12219: fix Sonar annotations from PR apache#2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR apache#2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: address remaining PR apache#2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from apache#2982

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from apache#2989

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

Ai-Assisted-By: claude,cursor

* Oak 12219 - upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#3014)

* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (apache#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (apache#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (apache#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (apache#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (apache#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (apache#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (apache#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (apache#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (apache#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (apache#3008) (apache#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (apache#3001)" (apache#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR apache#2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR apache#2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR apache#2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from apache#2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from apache#2989

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

Ai-Assisted-By: claude,cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* OAK-12219: fix SonarCloud issues on PR apache#2989

@deprecated(since/forRemoval) on deprecated classes, wrap bare rethrow
with context, remove unused vars, use assertNotSame, static Mockito
imports, remove unused fail import, rename `record` (restricted in
Java 16+), add missing assertions to no-assert tests.

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test and renamed

Ai-Assisted-By: cursor

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#3015)

* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (apache#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (apache#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (apache#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (apache#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (apache#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (apache#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (apache#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (apache#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (apache#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (apache#3008) (apache#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (apache#3001)" (apache#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR apache#2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR apache#2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR apache#2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from apache#2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from apache#2989

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- addressed sonar findings.

Ai-Assisted-By: claude,cursor

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework - address PR apache#2989 review comments

- cap configured presigned URI expiry to the 7-day Azure user delegation
  key lifetime under service-principal auth, with a warning
- honor secondary-location failover in UtilsV12.getRetryOptions when no
  retry count is configured (use SDK default retries instead of dropping
  the secondary host)
- expand @deprecated javadoc on AbstractAzureDataStoreService and
  AzureDataStoreService to explain the replacement
- add tests for expiry capping (SP and non-SP) and secondary-location
  retry options

Ai-Assisted-By: cursor

* OAK-12219: Restore AbstractAzureDataStoreService deprecation javadoc after rebase

Co-authored-by: Cursor <cursoragent@cursor.com>

Ai-Assisted-By: cursor

* OAK-12219: Fix deprecated Azure service javadoc to describe OSGi activation config

Replace incorrect FT/runtime-toggle wording with activation-time selection via
JVM property, environment variable, or OSGi configuration.

Co-authored-by: Cursor <cursoragent@cursor.com>

Ai-Assisted-By: cursor
seropian added 6 commits July 21, 2026 10:33
PR apache#2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

Ai-Assisted-By: cursor
…he#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor
@deprecated(since/forRemoval) on deprecated classes, wrap bare rethrow
with context, remove unused vars, use assertNotSame, static Mockito
imports, remove unused fail import, rename `record` (restricted in
Java 16+), add missing assertions to no-assert tests.

Ai-Assisted-By: claude

Ai-Assisted-By: cursor
- fixed test and renamed

Ai-Assisted-By: cursor
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants