The GitHub Actions job "Commit Check" on jackrabbit-oak.git/OAK-12219-test2 has 
failed.
Run started by GitHub user reschke (triggered by reschke).

Head commit for run:
a30816768da070260cb96599e9414c2e2c9bbc17 / Dikran Seropian 
<[email protected]>
Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#3049)

* OAK-12292: Candidate Release Notes

* [maven-release-plugin] prepare release jackrabbit-oak-2.4.0

* [maven-release-plugin] prepare for next development iteration

* Revert "[maven-release-plugin] prepare for next development iteration"

This reverts commit 78c17b812acc51d6cda7a67f6288521e975d6595.

* Revert "[maven-release-plugin] prepare release jackrabbit-oak-2.4.0"

This reverts commit 92860e0916a4628118b0584ab5005bc664ba749c.

* [maven-release-plugin] prepare release jackrabbit-oak-2.4.0

* [maven-release-plugin] prepare for next development iteration

* OAK-12312: oak-pojosr: remove unintended 
org.testcontainers.shaded.com.fasterxml.jackson import (#3024)

* OAK-12311: parent: jackson version - warn wrt non-LTS versions (#3023)

* OAK-12299 : precompute elementCount and currentWeight in PersistentDiskCache 
(#3004)

* Add draft project security threat-model document (#2923)

* Add draft project security threat-model document

Adds a draft project-level security threat-model document
(draft-THREAT-MODEL.md) at repo root, improving discoverability
for automated security scanners running against this repository.
The file follows the rubric format used by several other ASF
projects piloting security-model discoverability.

The "draft-" prefix signals this is a proposal for the PMC to
review, correct, or reject — not a finalised maintainer-blessed
model. Every claim carries a provenance tag (documented /
inferred / maintainer) so reviewers can see where each claim
originates; §14 collects open questions for the maintainers.

Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>

* Revise threat model per PMC review (Java 17, trust-boundary/XXE, oak-http, 
TarMK open)

Generated-by: Claude Code

---------

Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]>

* OAK-12314: Builds failing because request to https://www.slf4j.org/apidocs/ 
times out (#3030)

Removed the link.

* OAK-12295 : bump mongo version to 5.3.1 (#3031)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12295 : expanded range to include 5.2 to 5.4

* OAK-12315 : add removeRoot parameter to 
removeDescendantsAndSelfWithLeavesFirst() (#3032)

* OAK-12318 : bump testcontainers to 2.0.5 (#3035)

* OAK-12300: Remove ServiceListener after awaitServiceEvent completes (#3005)

The EventServiceListener was never removed from the BundleContext after
awaitServiceEvent completed (either successfully or via timeout). This caused:

1. Resource leaks - listeners accumulated across test runs
2. Test interference - listeners from previous tests continued receiving events
3. Intermittent test failures - unrelated service events could be captured,
   causing timeout errors when waiting for specific service events

Fix: Add try-finally block to ensure bundleContext.removeServiceListener()
is always called after the await completes, preventing listener accumulation
and cross-test event interference.

Co-authored-by: Copilot <[email protected]>

* OAK-12255: SystemPropertySupplier logSuccessAs can throw IAE (#2995)

* OAK-12239: Remove FT_PREFETCH_OAK-9780 and remove 'no prefetch' code path 
(#2934)

* OAK-12317 : bump aws sdk to next minor version 2.36.X (#3034)

* OAK-12319 : bump commons-io to 2.22.0 (#3036)

* OAK-12320 : bump commons-codec to 1.21.0 (#3037)

* docs: wire threat model for agent discoverability + rename to THREAT_MODEL.md 
(#3042)

Adds AGENTS.md (## Security pointer) + SECURITY.md wiring the
conventional AGENTS.md -> SECURITY.md -> THREAT_MODEL.md chain, and
renames the PMC-merged draft-THREAT-MODEL.md to the canonical
THREAT_MODEL.md (no longer a draft; matches the discoverable
convention). No model content changes.

Generated-by: Claude Code (Claude Opus 4.8)

* OAK-12326: Flacky test TokenCleanupTest#testBatchSizeLimitsCleanup (#3047)

* OAK-12325: Use heap based comparison of blob content (#3045)

* OAK-12323 : bump netty to 4.1.136.FINAL (#3040)

* Revert "OAK-12319 : bump commons-io to 2.22.0 (#3036)" (#3053)

This reverts commit edee3fb58817ceeb2e813a75bd51f336fa973709.

* OAK-12328: Update build.yml to use Java 21 for SonarQube Analysis (#3055)

done

* OAK-12316 : removed FT_NOCOCLEANUP_OAK-10660 feature toggle (#3033)

* OAK-12324 : bump metrics-core to 3.2.6 (#3041)

* OAK-12298: SystemPropertySupplier: document how to signal that property is 
not present (implies default value) (#3048)

* OAK-12321 : bump gson to 2.14.0 (#3038)

* OAK-12266: move fastQuerySize tests to oak-search for both backends (#2967) 
(#2988)

Relocate ResultSizeTest and WhiteboardResultSizeTest from oak-lucene into
oak-search as JCR-level CommonTests with Lucene and Elasticsearch subclasses,
so both backends exercise the fast query result size feature. The Lucene V1
index-format case remains Lucene-only in LuceneResultSizeTest.

Co-authored-by: Theia Vlad <[email protected]>
Co-authored-by: Theia Vlad <[email protected]>

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#3043)

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in 
getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch 
block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record 
getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for 
every URI.

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. 
cacheSize) into the DataStore returned by createDataStore(). When the class is 
package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the 
individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache 
OSS.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: move retryOptions into provider, drop 
getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

Ai-Assisted-By: claude,cursor

* Oak 12219 - upgrade azure sdk v8 to v12 for oak blob azure   rework  (#3014)

* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of 
bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for 
ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin 
rule is lost (#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. 
jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because 
propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property 
definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches 
after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / 
writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in 
FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <[email protected]>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <[email protected]>

* OAK-12303: Update mina-core dependency version to 2.1.15 (#3008) (#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <[email protected]>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)" (#3012)

This reverts commit 480eb1454028de792fe603b572def624b6a4cccd.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in 
getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch 
block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record 
getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for 
every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. 
cacheSize) into the DataStore returned by createDataStore(). When the class is 
package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the 
individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache 
OSS.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop 
getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

---------

Co-authored-by: Julian Reschke <[email protected]>
Co-authored-by: Rishabh Kumar <[email protected]>
Co-authored-by: Julian Reschke <[email protected]>
Co-authored-by: Thomas Mueller <[email protected]>
Co-authored-by: Benjamin Habegger <[email protected]>
Co-authored-by: Patrique Legault <[email protected]>
Co-authored-by: patlego <[email protected]>
Co-authored-by: Jose Antonio Insua <[email protected]>

Ai-Assisted-By: claude,cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* OAK-12219: fix SonarCloud issues on PR #2989

@Deprecated(since/forRemoval) on deprecated classes, wrap bare rethrow
with context, remove unused vars, use assertNotSame, static Mockito
imports, remove unused fail import, rename `record` (restricted in
Java 16+), add missing assertions to no-assert tests.

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test and renamed

Ai-Assisted-By: cursor

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#3015)

* OAK-12287: Update to Apache Parent POM to version 39

* OAK-12287: Update to Apache Parent POM to version 39 - revert removal of 
bundle-plugin version

* OAK-12289 : disabled blob id tracking for document node store (#2987)

* OAK-12289 : disabled blob id tracking for document node store

* OAK-12289 : fixed test case

* OAK-12259: oak-http: OakServlet mis-parses HTTP Basic credentials

* OAK-12293 : bump commons-io to 2.21.0 (#2997)

* OAK-12293 : bump commons-io to 2.22.0

* OAK-12293 : bump commons-io to 2.21.0

* OAK-12294 : bump commons-codec to 1.20.0 (#2998)

* OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)

* OAK-12295 : bump mongo-driver-sync to 5.3.1

* OAK-12295 : fixed the compilation issues

* OAK-12296 : bump testcontainers version to 2.0.3 (#3002)

* OAK-12296 : bump testcontainers version to 2.0.3

* OAK-12296 : fixed the junit 4 compatibility issues

* OAK-12296 : fixed compatibulity issues with Junit 4

* OAK-12296 : fixed compatibulity issues with ES tests

* OAK-12296 : incorporated review comments to use withEnv override for 
ElasticTestServer

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when… (#2949)

* OAK-12244: index nodes that gain a mixin rule, delete stale docs when mixin 
rule is lost (#2938)

When an existing node's applicable indexing rule changes at runtime (e.g. 
jcr:mixinTypes
added or removed), FulltextIndexEditor did not update the index because 
propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's property 
definitions.

Track wasIndexable (rule matched before) alongside isIndexable() (rule matches 
after).
In leave(), act on transitions:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocuments

Tests added:
- PropertyIndexCommonTest: two end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: two unit tests verifying writer.docs / 
writer.deletedPaths

* OAK-12244: fix mixin type changes not reflected in fulltext index (#2953)

Root cause: when a node gains or loses a mixin type at runtime,
FulltextIndexEditor did not update the index because propertiesChanged
was never set — jcr:mixinTypes is not normally listed in a rule's
property definitions.

Fix: track wasIndexable (rule matched before) alongside isIndexable()
(rule matches after). In leave(), act on the indexing-rule transition:
- !wasIndexable && isIndexable(): node gained a rule → addOrUpdate
- wasIndexable && !isIndexable(): node lost a rule → deleteDocument

Split FulltextIndexWriter into two explicit operations:
- deleteDocumentTree(path): node physically removed; cascade is correct
- deleteDocument(path): node lost indexability at runtime; exact only

The original deleteDocuments used a PrefixQuery that cascaded to all
descendants; in the mixin-loss branch this was a bug — children carrying
their own mixin types were incorrectly evicted from the index.

Additional changes:
- Snapshot FT_OAK_12244_DISABLE once per commit cycle in 
FulltextIndexEditorContext
  as typeChangeTrackingEnabled so enter() and leave() always agree
- Skip getApplicableIndexingRule(before) on the hot path via hasNodeTypeChange
  guard when neither jcr:primaryType nor jcr:mixinTypes changed
- Register FT_OAK_12244 toggle in ElasticIndexProviderService
- Reuse CommitFailedException code 5 for the deleteDocument error path

Tests:
- PropertyIndexCommonTest: end-to-end integration tests (all backends)
- LuceneIndexEditor2Test: unit tests verifying writer.docs / writer.deletedPaths
- Verified: 1245 tests, 0 failures in oak-lucene

---------

Co-authored-by: Benjamin Habegger <[email protected]>

* OAK-12282 : defining a fixed bound for the AbstractDiskCache (#2978)

* OAK-12282 defining a fixed bound for the AbstractDiskCache
---------

Co-authored-by: patlego <[email protected]>

* OAK-12303: Update mina-core dependency version to 2.1.15 (#3008) (#3010)

ack @telegrapher

Co-authored-by: Jose Antonio Insua <[email protected]>

* Revert "OAK-12295 : bump mongo-driver-sync to 5.3.1 (#3001)" (#3012)

This reverts commit 480eb1454028de792fe603b572def624b6a4cccd.

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- Sonar fixes

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- pin jackson version to the one in AEM to prevent transitive dep download.

Ai-Assisted-By: claude

* OAK-12219: fix Sonar annotations from PR #2989 CI run

AzureBlobStoreBackendV12:
- RuntimeException -> IllegalStateException in 
getMetadataRecord/getAllMetadataRecords/deleteAllMetadataRecords
- chain DataStoreException (not unwrapped IOException cause) in write() catch 
block
- .collect(Collectors.toList()) -> .toList() in commitBlocksAndGetSize
- instanceof pattern matching for BlobStorageException in completeHttpUpload
- nested ternary -> if-else for operation string in presigned URI error log
- return new byte[0] instead of null in readMetadataBytes; update caller check

RegressionCSOV8Test:
- swap assertEquals args to (actual, expected) order per Sonar S3415

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

Ai-Assisted-By: claude-code

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record 
getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2992)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- removed oak-run-commons dependency on azure sdk v8 from oak-blob-cloud-azure

Ai-Assisted-By: claude

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- cached the UserDelegationKey to avoid repeated calls to get it from Azure for 
every URI.

Ai-Assisted-By: claude

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. 
cacheSize) into the DataStore returned by createDataStore(). When the class is 
package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the 
individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* Remove internal service reference from comment

Drop 'e.g. oak-repository-service' — internal detail, not relevant to Apache 
OSS.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude-code

* OAK-12219: cache HttpClient in AzureBlobContainerProviderV12

Build the Netty HTTP client once at construction instead of on every
getBlobContainer() call. Also drops dead Properties threading and
duplicate proxy/connection-string overloads in UtilsV12.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude-code

* OAK-12219: replace wildcard imports with explicit imports

Ai-Assisted-By: claude-code

* OAK-12219: move retryOptions into provider, drop 
getBlobContainerFromServicePrincipals

retryOptions is now a field built at construction instead of passed
per-call. Service-principal auth reuses the cached BlobServiceClient
instead of rebuilding a client on every call.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude-code

* OAK-12219: address remaining PR #2982 review comments

Use SystemPropertySupplier for the JVM-property override (reschke),
rename registerService to registerDataStoreService (joerghoh), and
match the suggested "falling back to v8" log wording.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

Ai-Assisted-By: claude,claude-code

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2982

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed comments from #2989

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed compilation fail because of misplaced comment

---------

Co-authored-by: Julian Reschke <[email protected]>
Co-authored-by: Rishabh Kumar <[email protected]>
Co-authored-by: Julian Reschke <[email protected]>
Co-authored-by: Thomas Mueller <[email protected]>
Co-authored-by: Benjamin Habegger <[email protected]>
Co-authored-by: Patrique Legault <[email protected]>
Co-authored-by: patlego <[email protected]>
Co-authored-by: Jose Antonio Insua <[email protected]>

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- addressed sonar findings.

Ai-Assisted-By: claude,cursor

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework - address 
PR #2989 review comments

- cap configured presigned URI expiry to the 7-day Azure user delegation
  key lifetime under service-principal auth, with a warning
- honor secondary-location failover in UtilsV12.getRetryOptions when no
  retry count is configured (use SDK default retries instead of dropping
  the secondary host)
- expand @deprecated javadoc on AbstractAzureDataStoreService and
  AzureDataStoreService to explain the replacement
- add tests for expiry capping (SP and non-SP) and secondary-location
  retry options

Ai-Assisted-By: cursor

* OAK-12219: Restore AbstractAzureDataStoreService deprecation javadoc after 
rebase

Co-authored-by: Cursor <[email protected]>

Ai-Assisted-By: cursor

* OAK-12219: Fix deprecated Azure service javadoc to describe OSGi activation 
config

Replace incorrect FT/runtime-toggle wording with activation-time selection via
JVM property, environment variable, or OSGi configuration.

Co-authored-by: Cursor <[email protected]>

Ai-Assisted-By: cursor

* OAK-12219: raise unit-test coverage on new V12 code to clear Sonar gate

PR #2989 failed the quality gate at 67.9% coverage on new code (need 80%).
The Azure ITs that cover blob CRUD don't run in CI, so the new V12 classes
were largely uncovered. Add mock-based unit tests (Mockito mocks the Azure
BlobContainerClient/BlockBlobClient chain) so the SDK-call paths are covered
without a live Azurite endpoint.

New/expanded tests:
- AzureBlobStoreBackendV12MockTest (new): read/getRecord/exists/deleteRecord
  success + 404 + storage-error paths; metadata get/exists/delete; init()
  config parsing (concurrent-request clamping, secondary location, presigned
  URI config); getAllIdentifiers/getAllRecords meta+no-dash filtering;
  getAllMetadataRecords success; write exists/missing/length-collision;
  addMetadataRecord(File); initiateHttpUpload arg validation; data record 
getters
- AzureHttpRequestLoggingPolicyV12Test (new): verbose on/off process() paths
- AzureDataStoreWrapperTest: createDataStore v8/v12, getDescription, init
  delegation, 3-arg upload, statistics provider getter/setter
- AzureBlobContainerProviderV12Test: service-principal credential branch,
  getEndpointUrl variants

Blended new-code coverage (line+branch) on the new files now ~82% locally.

Also make getOrCreateReferenceKey tolerate a null from a readMetadataBytes
override (production returns empty array; test subclasses may return null).

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* Oak 12219 upgrade azure sdk v8 to v12 for oak blob azure   rework  (#2994)

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed automated code review findings

Ai-Assisted-By: claude-code

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- PropertiesUtil.populate() uses reflection to inject config properties (e.g. 
cacheSize) into the DataStore returned by createDataStore(). When the class is 
package-private, Java's reflection access control
    blocks it because the caller is in a different package — even if the 
individual setter methods are public. Making the class itself public fixes that

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob upload/download related constants that control memory and streaming 
behavior

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fix blob block size, prevent size zero

Ai-Assisted-By: claude

Ai-Assisted-By: claude-code

Ai-Assisted-By: cursor

* OAK-12219: fix SonarCloud issues on PR #2989

@Deprecated(since/forRemoval) on deprecated classes, wrap bare rethrow
with context, remove unused vars, use assertNotSame, static Mockito
imports, remove unused fail import, rename `record` (restricted in
Java 16+), add missing assertions to no-assert tests.

Ai-Assisted-By: claude

Ai-Assisted-By: cursor

* OAK-12219: Upgrade Azure SDK V8 to V12 for oak-blob-azure - rework
- fixed test and renamed

Ai-Assisted-By: cursor

* OAK-12326: Fix compilation failure in test

---------

Co-authored-by: Julian Reschke <[email protected]>
Co-authored-by: Julian Reschke <[email protected]>
Co-authored-by: Nuno Santos <[email protected]>
Co-authored-by: Jarek Potiuk <[email protected]>
Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]>
Co-authored-by: mbaedke <[email protected]>
Co-authored-by: Rishabh Kumar <[email protected]>
Co-authored-by: Copilot <[email protected]>
Co-authored-by: Thomas Mueller <[email protected]>
Co-authored-by: Theia Vlad <[email protected]>
Co-authored-by: Theia Vlad <[email protected]>

Report URL: https://github.com/apache/jackrabbit-oak/actions/runs/30332513460

With regards,
GitHub Actions via GitBox


Reply via email to