Skip to content

OAK-12219-Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework (#2…#2982

Closed
reschke wants to merge 1 commit into
trunkfrom
OAK-12219-test
Closed

OAK-12219-Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework (#2…#2982
reschke wants to merge 1 commit into
trunkfrom
OAK-12219-test

Conversation

@reschke

@reschke reschke commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

…941)

Ai-Assisted-By: claude

EDIT: please ignore the osgi-it changes, I started with the wrong commit.

EDIT2: who can review this from an OSGi point of view?

@github-actions

Copy link
Copy Markdown

Commit-Check ❌

Commit rejected by Commit-Check.                                  
                                                                  
  (c).-.(c)    (c).-.(c)    (c).-.(c)    (c).-.(c)    (c).-.(c)  
   / ._. \      / ._. \      / ._. \      / ._. \      / ._. \   
 __\( C )/__  __\( H )/__  __\( E )/__  __\( C )/__  __\( K )/__ 
(_.-/'-'\-._)(_.-/'-'\-._)(_.-/'-'\-._)(_.-/'-'\-._)(_.-/'-'\-._)
   || E ||      || R ||      || R ||      || O ||      || R ||   
 _.' '-' '._  _.' '-' '._  _.' '-' '._  _.' '-' '._  _.' '-' '._ 
(.-./`-´\.-.)(.-./`-´\.-.)(.-./`-´\.-.)(.-./`-´\.-.)(.-./`-´\.-.)
 `-´     `-´  `-´     `-´  `-´     `-´  `-´     `-´  `-´     `-´ 
                                                                  
Commit rejected.                                                  
                                                                  
Type message check failed ==> OAK-12219-Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework (#2941)

Ai-Assisted-By: claude 
The commit message should follow Conventional Commits. See https://www.conventionalcommits.org
Suggest: Commit message does not match the required pattern

*/
static boolean getUseV12Value(Map<String, Object> config) {
if (System.getProperty(JVM_PROPERTY_V12_ENABLED) != null) {
boolean useV12 = Boolean.getBoolean(JVM_PROPERTY_V12_ENABLED);

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

use SystemPropertyProvider

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SystemPropertyProvider does not provide awarness on missing property, which I need for decision.

@reschke

reschke commented Jun 26, 2026

Copy link
Copy Markdown
Contributor Author

Q: the default is still V8?

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
66.6% Coverage on New Code (required ≥ 80%)
3.7% Duplication on New Code (required ≤ 3%)
B Reliability Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@joerghoh joerghoh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

a series of questions and suggestions. Nothing really critical, but worth to review.

if (StringUtils.isNotBlank(customBlobEndpoint)) {
// Use custom endpoint (e.g., for private endpoints)
// Ensure it starts with https:// if not already present
if (!customBlobEndpoint.startsWith("http://") && !customBlobEndpoint.startsWith("https://")) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wouldn't this allow also a http (non-encypted) url to be created?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we allow http:// passthrough for azurite tests; in production Azure enforces HTTPS at the service level. Moving azurite to https is possible but involves some extra work, not sure if it is worth:

  • Mounting TLS certs into the container
  • Configuring Netty to trust the self-signed cert across all test setups
  • Updating all three AzuriteDockerRule variants

.retryOptions(retryOptions)
.addPolicy(loggingPolicy);

HttpClient httpClient = new NettyAsyncHttpClientBuilder()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What is the overhead of creating this httpClient? Is this httpClient designed to be reused (like the Apache HttpClient?)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

addressed in #2989

String proxyHost = properties.getProperty(AzureConstantsV12.PROXY_HOST);
String proxyPort = properties.getProperty(AzureConstantsV12.PROXY_PORT);

if (!(Objects.toString(proxyHost, "").isEmpty() || Objects.toString(proxyPort, "").isEmpty())) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think that the logic is wrong; it should be AND instead of OR.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

it was correct but twisted expression, changed with StringUtils.isNoneBlank(proxyHost, proxyPort)
in #2989


private static final Logger log = LoggerFactory.getLogger(AzureDataStoreWrapper.class);

public static final String NAME = "org.apache.jackrabbit.oak.plugins.blob.datastore.AzureDataStore";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there any special reason not to use the full qualified class name?

(just found the answer to this in a comment below; you should move that comment here.)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

added comment in #2989

private StatisticsProvider statisticsProvider;
private ServiceRegistration<?> delegateReg;

static ServiceRegistration<?> registerService(ComponentContext context, AbstractSharedCachingDataStore service) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The method name is a bit too generic.

Suggested change
static ServiceRegistration<?> registerService(ComponentContext context, AbstractSharedCachingDataStore service) {
static ServiceRegistration<?> registerDataStoreService(ComponentContext context, AbstractSharedCachingDataStore service) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fixed in #2989

log.info("Azure SDK v12 flag: OSGi config {}={}", OSGI_CONFIG_V12_ENABLED, useV12);
return useV12;
}
log.info("Azure SDK v12 flag: not configured, using default (false)");

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
log.info("Azure SDK v12 flag: not configured, using default (false)");
log.info("Azure SDK v12 flag: not configured, falling back to v8 ");

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fixed in #2989


@Override
protected String[] getDescription() {
return new String[]{"type=AzureBlob"};

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is used in the context of the mbeans, is it visible there as well, what SDK version is active?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fixed in #2989

seropian added a commit to seropian/jackrabbit-oak that referenced this pull request Jul 3, 2026
Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code
seropian added a commit to seropian/jackrabbit-oak that referenced this pull request Jul 6, 2026
Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code
seropian added a commit to seropian/jackrabbit-oak that referenced this pull request Jul 6, 2026
Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code
reschke pushed a commit that referenced this pull request Jul 6, 2026
* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code
@seropian

seropian commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Q: the default is still V8?

Yes, default is V8, if no v12 property explicitly set to true.

seropian added a commit to seropian/jackrabbit-oak that referenced this pull request Jul 8, 2026
seropian added a commit to seropian/jackrabbit-oak that referenced this pull request Jul 8, 2026
Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code
seropian added a commit to seropian/jackrabbit-oak that referenced this pull request Jul 8, 2026
reschke added a commit that referenced this pull request Jul 8, 2026
)

* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (#3008) (#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)" (#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>
reschke added a commit that referenced this pull request Jul 8, 2026
* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (#3008) (#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)" (#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>
@reschke reschke closed this Jul 8, 2026
reschke added a commit that referenced this pull request Jul 8, 2026
* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (#3008) (#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)" (#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test

Ai-Assisted-By: claude

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>
reschke added a commit that referenced this pull request Jul 9, 2026
* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (#3008) (#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)" (#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test

Ai-Assisted-By: claude

* OAK-12219: fix SonarCloud issues on PR #2989

@deprecated(since/forRemoval) on deprecated classes, wrap bare rethrow
with context, remove unused vars, use assertNotSame, static Mockito
imports, remove unused fail import, rename `record` (restricted in
Java 16+), add missing assertions to no-assert tests.

Ai-Assisted-By: claude

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>
reschke added a commit that referenced this pull request Jul 9, 2026
* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (#3008) (#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)" (#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test

Ai-Assisted-By: claude

* OAK-12219: fix SonarCloud issues on PR #2989

@deprecated(since/forRemoval) on deprecated classes, wrap bare rethrow
with context, remove unused vars, use assertNotSame, static Mockito
imports, remove unused fail import, rename `record` (restricted in
Java 16+), add missing assertions to no-assert tests.

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test and renamed

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>
reschke added a commit that referenced this pull request Jul 13, 2026
* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (#3008) (#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)" (#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test

Ai-Assisted-By: claude

* OAK-12219: fix SonarCloud issues on PR #2989

@deprecated(since/forRemoval) on deprecated classes, wrap bare rethrow
with context, remove unused vars, use assertNotSame, static Mockito
imports, remove unused fail import, rename `record` (restricted in
Java 16+), add missing assertions to no-assert tests.

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test and renamed

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- addressed sonar findings.

Ai-Assisted-By: claude,cursor

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>
seropian added a commit to seropian/jackrabbit-oak that referenced this pull request Jul 20, 2026
Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor
seropian added a commit to seropian/jackrabbit-oak that referenced this pull request Jul 20, 2026
seropian added a commit to seropian/jackrabbit-oak that referenced this pull request Jul 20, 2026
…ache#3014)

* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (apache#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (apache#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (apache#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (apache#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (apache#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (apache#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (apache#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (apache#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (apache#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (apache#3008) (apache#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (apache#3001)" (apache#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR apache#2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR apache#2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR apache#2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from apache#2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from apache#2989

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

Ai-Assisted-By: claude,cursor
seropian added a commit to seropian/jackrabbit-oak that referenced this pull request Jul 20, 2026
…he#3015)

* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (apache#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (apache#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (apache#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (apache#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (apache#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (apache#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (apache#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (apache#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (apache#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (apache#3008) (apache#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (apache#3001)" (apache#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR apache#2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR apache#2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (apache#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR apache#2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from apache#2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from apache#2989

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

Ai-Assisted-By: cursor
reschke pushed a commit that referenced this pull request Jul 20, 2026
* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

Ai-Assisted-By: claude,cursor

* Oak 12219 - upgrade azure sdk v8 to v12 for oak blob azure   rework  (#3014)

* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (#3008) (#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)" (#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

Ai-Assisted-By: claude,cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* OAK-12219: fix SonarCloud issues on PR #2989

@deprecated(since/forRemoval) on deprecated classes, wrap bare rethrow
with context, remove unused vars, use assertNotSame, static Mockito
imports, remove unused fail import, rename `record` (restricted in
Java 16+), add missing assertions to no-assert tests.

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test and renamed

Ai-Assisted-By: cursor

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#3015)

* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin rule is lost (#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <patriquelegault@gmail.com>

* OAK-12303: Update mina-core dependency version to 2.1.15 (#3008) (#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)" (#3012)

This reverts commit 480eb14.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. cacheSize) into the DataStore returned by createDataStore(). When the class is package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache OSS.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

---------

Co-authored-by: Julian Reschke <julian.reschke@gmx.de>
Co-authored-by: Rishabh Kumar <rishabhdaim1991@gmail.com>
Co-authored-by: Julian Reschke <reschke@apache.org>
Co-authored-by: Thomas Mueller <thomasm@apache.org>
Co-authored-by: Benjamin Habegger <bhabegger@adobe.com>
Co-authored-by: Patrique Legault <patrique.legault@gmail.com>
Co-authored-by: patlego <patriquelegault@gmail.com>
Co-authored-by: Jose Antonio Insua <ungoliant@gmail.com>

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- addressed sonar findings.

Ai-Assisted-By: claude,cursor

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework - address PR #2989 review comments

- cap configured presigned URI expiry to the 7-day Azure user delegation
  key lifetime under service-principal auth, with a warning
- honor secondary-location failover in UtilsV12.getRetryOptions when no
  retry count is configured (use SDK default retries instead of dropping
  the secondary host)
- expand @deprecated javadoc on AbstractAzureDataStoreService and
  AzureDataStoreService to explain the replacement
- add tests for expiry capping (SP and non-SP) and secondary-location
  retry options

Ai-Assisted-By: cursor

* OAK-12219: Restore AbstractAzureDataStoreService deprecation javadoc after rebase

Co-authored-by: Cursor <cursoragent@cursor.com>

Ai-Assisted-By: cursor

* OAK-12219: Fix deprecated Azure service javadoc to describe OSGi activation config

Replace incorrect FT/runtime-toggle wording with activation-time selection via
JVM property, environment variable, or OSGi configuration.

Co-authored-by: Cursor <cursoragent@cursor.com>

Ai-Assisted-By: cursor
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants