Skip to content

fix(workflow): keep RC connector extras and fail sentinel on missing extras - #2011

Merged
FabioLeitao merged 3 commits into
mainfrom
fix/maestro-91-rc-extras-sentinel
Sep 28, 2026
Merged

FabioLeitao merged 3 commits into
mainfrom
fix/maestro-91-rc-extras-sentinel

Conversation

@FabioLeitao

@FabioLeitao FabioLeitao commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Two commits on fix/maestro-91-rc-extras-sentinel:

  1. b900f9c7 — maestro#91 (RC smoke + sentinel)

    • Host smoke prepare runs uv sync with --extra compressed plus the extras derived from the active --bench-config (scripts/rc_bench_extras.py list via optional_extra_for_target; RC v2 → nosql, v3 → mysql, nosql, postgres, shares).
    • rc_bench_extras.py verify fails the prepare when a distribution for those extras is missing after sync.
    • MongoDB and Redis connectors record scan_failures.reason=missing_optional_dependency when the nosql extra is absent (not unreachable).
    • benchmark_rc_sentinel_check.py fails on any missing_optional_dependency in the latest session before optional connector probes, so a closed lab port cannot yield SKIP + SENTINEL_OK while the tool is misconfigured.
  2. 5fa2bf8d — [P2][chore][tests] test_confirm_target_db_synthetic_data_contract quebrado desde maestro a3caa33 (compose exec → docker exec): check-all sai 1 no T14 #2010 (sibling-maestro contract test)

    • test_confirm_target_db_synthetic_data_contract now expects docker exec lab-postgres psql, docker exec lab-mariadb mariadb, and docker exec lab-mongodb mongosh, matching current Lab-MaestroCommon.ps1 (replacing stale docker compose exec -T / compose-file paths).

Real-run evidence (RC v2 config copy, sqlite under /tmp, Mongo probe port 27018 closed)

Scenario Outcome
Scan with pymongo blocked in-process scan_failures → missing_optional_dependency; sentinel → SENTINEL_FAIL, exit 1
Scan with pymongo present legitimate SKIP optional lab_mongo_lgpd; sentinel → SENTINEL_OK

Prepare path validated in a temp worktree: bootstrap sync derives --extra nosql for v2; v3 derives four extras; pruning to compressed only makes verify emit EXTRA_MISSING for pymongo/redis.

Test plan

  • Targeted pytest (sentinel, rc_bench_extras, connectors) + MAESTRO_ROOT=… pytest tests/test_maestro_scripts.py (82 passed)
  • ./scripts/check-all.sh — exit 0 (3174 passed)

Pendência declarada

  • Smoke real no T14 para fechar o loop operacional do maestro#91 no lab: depende de repor as imagens podman de smoke (postgres, mariadb, oracle-xe, mssql) após a limpeza de disco de 27/set — download com confirmação do operador na hora.

Follow-up (fora desta PR)

  • Espelho do uv sync derivado do config no engine/lab-completao-host-smoke.sh do maestro permanece adiado (repo privado / custo de CI).

Closes #2010

Refs DataBoar/maestro#91


Note

Low Risk
Changes affect RC/lab smoke tooling and failure classification for optional connectors; production scan paths only gain clearer failure reasons when extras are missing.

Overview
Fixes maestro#91, where host smoke ran uv sync --extra compressed only, pruned connector deps (e.g. pymongo), and RC sentinel treated missing extras like lab outages when optional probe ports were closed.

Host smoke prepare now derives optional extras from --bench-config targets via new scripts/rc_bench_extras.py (list / verify), passes them to uv sync alongside compressed, and fails prepare if distributions are still missing after sync.

MongoDB and Redis connectors record scan_failures with reason=missing_optional_dependency when the nosql extra is absent, instead of unreachable.

RC sentinel (benchmark_rc_sentinel_check.py) fails the latest completed session on any missing_optional_dependency before optional connector probes, so a closed lab port cannot yield SKIP + SENTINEL_OK.

Also updates #2010 maestro contract test expectations from docker compose exec -T to docker exec … psql/mariadb/mongosh to match current lab scripts.

Reviewed by Cursor Bugbot for commit 5fa2bf8. Bugbot is set up for automated code reviews on this repo. Configure here.

…extras

The baremetal host smoke ran `uv sync --extra compressed`. uv sync is
exact, so it pruned pymongo (extra nosql). The Mongo connector then
stored reason=unreachable, and the RC sentinel skipped the optional
Mongo rule on the closed probe port and ended SENTINEL_OK.

- Smoke prepare syncs compressed plus the extras the --bench-config
  targets need (scripts/rc_bench_extras.py list, from
  optional_extra_for_target), then `verify` fails the prepare when a
  distribution of those extras is missing.
- MongoDB and Redis connectors record missing_optional_dependency when
  the nosql extra is absent, like SMB and WebDAV already do.
- The sentinel fails on any missing_optional_dependency in the latest
  session before optional probes run.

Real runs, RC v2 config copy with sqlite under /tmp, port 27018 closed:
pymongo blocked -> scan_failures missing_optional_dependency ->
SENTINEL_FAIL (exit 1); pymongo present -> SKIP -> SENTINEL_OK.

Refs DataBoar/maestro#91
Refs DataBoar/maestro#92
Confirm-TargetDbSyntheticData in maestro now uses docker exec against
named lab containers (lab-postgres, lab-mariadb, lab-mongodb), not
docker compose exec -T. Update the three contract assertions so the
sibling-maestro gate matches Lab-MaestroCommon.ps1 again.

Refs #2010
@FabioLeitao

Copy link
Copy Markdown
Collaborator Author

bugbot run

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 5fa2bf8. Configure here.

CI on Python 3.12/3.14 runs without the nosql extra, so pymongo is
absent and MongoDBConnector.run() returns early on the missing-extra
guard (maestro#91). The dedup test stubs connect() but must assert
sampling behavior; mirror test_security and test_crypto_controls_audit
by patching _MONGO_AVAILABLE True for the run() call.

Refs #2011
@FabioLeitao
FabioLeitao merged commit ce04a72 into main Sep 28, 2026
28 checks passed
@FabioLeitao
FabioLeitao deleted the fix/maestro-91-rc-extras-sentinel branch September 28, 2026 20:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P2][chore][tests] test_confirm_target_db_synthetic_data_contract quebrado desde maestro a3caa33 (compose exec → docker exec): check-all sai 1 no T14

1 participant