Repository navigation
Expand file tree
/
Copy pathsonar-project.properties
More file actions
721 lines (658 loc) · 44.8 KB
/
Copy pathsonar-project.properties
File metadata and controls
721 lines (658 loc) · 44.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
sonar.projectKey=ghbvf_gocell
sonar.organization=ghbvf
sonar.projectName=gocell
sonar.sources=framework/kernel,framework/runtime,adapters,corecells,cmd,framework/pkg,examples,tests
sonar.tests=framework/kernel,framework/runtime,adapters,corecells,cmd,framework/pkg,examples,tests
sonar.test.inclusions=**/*_test.go
sonar.go.coverage.reportPaths=coverage-merged.out
# --- Coverage exclusions ---
#
# outboxtest is a conformance-suite helper package (like go-test's
# testing/iotest) executed by adapter integration tests (RabbitMQ, in-memory
# bus) under -tags=integration. The default build-test job only exercises it
# via fakePubSub shims (see kernel/outbox/outboxtest/helpers_test.go), so
# in-package line coverage does not reflect the package's real exercise
# surface. The kernel coverage gate in .github/workflows/_build-lint.yml
# already skips outboxtest/celltest (via the `/[a-z0-9_]+test$` helper
# exemption regex) with the same rationale; mirror that here to keep
# SonarCloud's new-code metric honest.
#
# runtime/outbox/outboxtest/ is the public in-memory Store + Store conformance
# suite for runtime/outbox. FakeStore is exercised by unit tests (bootstrap,
# relay, etc.) and counts toward those packages' own coverage; however, the
# store_conformance.go suite functions themselves are only called from integration
# tests (adapters/postgres/outbox_store_integration_test.go,
# adapters/rabbitmq/conformance_test.go). The CI integration-test step runs
# without -coverpkg=./... so coverage for the outboxtest package itself is never
# attributed back to suite.go. Same conformance-suite exclusion pattern as
# kernel/outbox/outboxtest above.
#
# runtime/auth/session/storetest/bench.go follows the same conformance-suite
# exclusion principle: NewBenchProtocol / BenchFactory / Bench / mixed concurrent
# benchmark bodies are exercised only by `go test -bench=.` against PG and mem
# backends (adapters/postgres/session_store_integration_test.go +
# runtime/auth/session/mem/store_test.go), not by `go test -count=1` runs that
# feed coverage into Sonar. This mirrors the existing
# kernel/outbox/outboxtest/** exclusion above (PR-V1-PG-STARTUP-HARDEN baseline).
#
# runtime/audit/ledger/storetest/ is a Protocol-driven conformance-suite helper
# (NewTestProtocol / NewEntryFixture / Run) exercised only by backend-specific
# tests (runtime/audit/ledger/mem/store_test.go and future PG integration tests
# under -tags=integration). The default `go test -count=1` run does not exercise
# this package directly; cross-package line hits do not attribute back to suite.go.
# Same conformance-suite exclusion pattern as runtime/auth/session/storetest
# and kernel/outbox/outboxtest above.
#
# runtime/distlock/locktest/conformance.go borrows the same conformance-suite
# exclusion principle but applies only to Sonar — the CI kernel coverage gate
# at .github/workflows/_build-lint.yml parses coverage-shard-kernel.out
# (awk over the per-shard atomic profile) and never reaches runtime/distlock/,
# so there is no in-CI gate to mirror; the
# Sonar exclusion stands alone. Rationale: RunDriverTTLConformance / conformC5
# / conformC6 only run against real backends (adapters/redis integration
# tests) because FakeDriver wired with FakeClock cannot exercise wall-clock
# TTL expiry. Excluded at file level (not package level) so FakeDriver /
# FakeClock in-package unit coverage still counts toward Sonar metrics.
#
# corecells/accesscore/internal/ports/conformance/ is the UserRepository
# conformance suite shared by mem and PG implementations
# (corecells/accesscore/internal/mem/user_repo_conformance_test.go and
# corecells/accesscore/internal/adapters/postgres/user_repo_conformance_integration_test.go).
# Same conformance-suite pattern as outboxtest / celltest / storetest above:
# the helpers are exercised by tests in *other* packages, but per-shard CI
# runs go test *without* -coverpkg=./... (see _build-lint.yml §"-coverpkg=./...
# was previously used here but dropped"), so cross-package line hits never
# attribute back to conformance.go. Excluded at package level — the package
# contains only the conformance suite, no sibling production code.
#
# kernel/command/commandtest/conformance.go follows the same conformance-suite
# exclusion principle as kernel/outbox/outboxtest/**. RunQueueConformance is the
# acceptance test suite for command.Queue/ActiveScanner implementations; its
# error-path branches (t.Fatalf calls after GetCommand/Dequeue/Ack/ScanActive)
# only fire when the underlying store returns unexpected errors — conditions that
# never occur in the InMemQueue unit tests but are exercised by the PG adapter
# integration tests (adapters/postgres/command_queue_integration_test.go).
# Per-shard CI runs go test without -coverpkg=./..., so cross-package line hits
# from the PG integration shard never attribute back to conformance.go.
# Excluded at file level — inmem.go and other helpers in the same package
# are not excluded and continue to count toward Sonar coverage.
#
# runtime/observability/healthz/healthztest/ is the Aggregator conformance-suite
# helper (RunAggregatorConformance + FakeAggregator). Same conformance-suite
# exclusion pattern as kernel/outbox/outboxtest/** above: RunAggregatorConformance
# is exercised only from OTHER packages' tests (runtime/observability/healthz/
# aggregator_test.go and future postgres/otel adapter conformance tests), and
# FakeAggregator is the shared cell-test double exercised by cells/* tests; per-
# shard CI runs go test without -coverpkg=./..., so cross-package line hits never
# attribute back to conformance.go. Excluded at package level — the package is
# pure test-helper, no sibling production code.
#
# kernel/persistence/persistencetest/ is the after-commit hook conformance suite
# (RunAfterCommitConformance + RunAfterCommitNestedConformance). Same
# conformance-suite exclusion pattern as kernel/outbox/outboxtest/** above: the
# suite functions are called only from OTHER packages' tests — the five TxRunner
# implementations (kernel/outbox, corecells/accesscore/internal/mem,
# corecells/configcore/internal/testutil, examples/todoorder, adapters/postgres) —
# and per-shard CI runs go test without -coverpkg=./..., so cross-package line
# hits never attribute back to conformance.go. Excluded at package level — the
# package is pure test-helper, no sibling production code.
#
# kernel/saga/sagajournaltest/ is the saga Journal conformance suite
# (RunConformanceSuite + NewInstanceFixture / NewStepEvent). Same conformance-suite
# exclusion pattern as kernel/persistence/persistencetest/** above: the suite is
# exercised by an in-package self-test (conformance_test.go, mem backend) and by
# future PG integration tests (PR-04). Its error-path branches — the t.Fatalf /
# t.Error guards after every Journal call — only fire on backend faults the
# in-memory backend never produces, so they are structurally unreachable from the
# coverage-feeding run. Excluded at package level — the package is pure test-helper,
# no sibling production code.
#
# kernel/reconcile/reconciletest/ is the LeaderElector + fencing conformance suite
# (RunLeaderConformance / RunFencingConformance) plus the Fake* helpers
# (FakeLeaderElector / FakeLeaseBackend / FakeReconciler / FakeTrigger /
# FakeFencedRepository). Same conformance-suite exclusion pattern as kernel/saga/
# sagajournaltest/** above: the suites + fakes are exercised only from OTHER
# packages' tests (adapters/redis + adapters/postgres reconcile elector tests,
# kernel/reconcile leader/loop tests), so per-shard CI runs (go test without
# -coverpkg=./...) never attribute those cross-package line hits back to
# conformance.go / fake.go — they show 0% new-code coverage despite being fully
# exercised. The reconcile PRODUCTION code (loop.go / leader.go / fenced.go /
# recovery.go + the redis/postgres adapters) is NOT excluded and carries its own
# unit + integration coverage. Excluded at package level — pure test-helper, no
# sibling production code.
#
# kernel/webhook/webhooktest/ is the sign↔verify conformance suite
# (RunSignerVerifierConformance + VerifierFactory) for webhook.Signer/Verifier
# implementations. Same conformance-suite exclusion pattern as kernel/outbox/
# outboxtest/** above: the suite is invoked only from OTHER packages' tests
# (kernel/webhook/conformance_test.go, external webhook_test package; future
# Signer/Verifier implementations add sibling calls), so its line hits attribute
# to the caller package, not back to conformance.go. Per-shard CI runs go test
# without -coverpkg=./..., and the kernel coverage gate in
# .github/workflows/_build-lint.yml already skips it via the `/[a-z0-9_]+test$`
# helper-package regex; mirror that here for SonarCloud new-code honesty. Excluded
# at package level — the package is pure test-helper, no sibling production code.
#
# runtime/observability/metrics/metricstest/ is the Collector conformance suite
# (RunCollectorConformance + CollectorHarness/CollectorObserver). Same
# conformance-suite exclusion pattern as kernel/saga/sagajournaltest/** above:
# conformance.go is published as a plain .go file (not _test.go) so caller
# packages can import it, but its assertion bodies are exercised only from OTHER
# packages' tests (runtime/observability/metrics/{inmemory,provider}_conformance_test.go,
# and future Collector implementations add sibling calls). Per-shard CI runs go
# test without -coverpkg=./..., so cross-package line hits never attribute back to
# conformance.go. Excluded at package level — the package is pure test-helper, no
# sibling production code.
#
# runtime/http/idempotency/idempotencytest/ is the idempotency.Store conformance
# suite (RunConformanceSuite + marshal_helper), same conformance-suite exclusion
# pattern as kernel/outbox/outboxtest/** above: conformance.go is a plain .go file
# (not _test.go) imported by caller packages, exercised only from OTHER packages'
# tests (runtime/http/idempotency/conformance_mem_test.go for MemStore and
# adapters/redis/http_idempotency_conformance_test.go under -tags=integration for
# the Redis store). Per-shard CI runs go test without -coverpkg=./..., so
# cross-package line hits never attribute back to it. Pure test-helper, no sibling
# production code.
#
# Cross-platform stubs and Windows-only code are excluded from Sonar coverage:
# - *_windows.go files compile only on Windows, where the os-smoke matrix runs
# them but does not feed coverage into Sonar (Linux is the Sonar baseline).
# - *_unsupported.go files are stubs for !unix && !windows (or
# !linux && !darwin && !windows) targets that no GitHub runner exercises.
# Including them in the coverage denominator would make the new-code
# coverage gate impossible to satisfy.
# - platform_supported.go is a one-line `return nil` whose only call site
# (cells/accesscore/cell_init.go::Init) is exercised by the unix tests, but
# Sonar's go cover ingestion does not count single-statement function
# bodies toward coverage. It pairs with platform_unsupported.go (excluded
# above for build-tag reasons), so excluding both keeps the V-A15 platform
# guard pair symmetric in the coverage report.
#
# cmd/gocell/main.go is the governance/codegen CLI's thin entry point: it installs
# the redacting slog seal (→ os.Stderr, #1432 C1) then calls os.Exit(
# app.RunWithSignal(...)). os.Exit makes main() unreachable from unit tests, so its
# lines can never accrue coverage. The one meaningful invariant (the seal writes to
# os.Stderr, NOT stdout, so machine output is not corrupted) is locked by
# cmd/gocell/main_seal_test.go::TestMainSealsLogsToStderr — line coverage adds
# nothing. Analogous to the **/examples/** entry-point exclusion below.
sonar.exclusions=\
**/*_gen.go,\
**/testdata/**,\
generated/**,\
vendor/**
sonar.coverage.exclusions=\
**/kernel/outbox/outboxtest/**,\
**/runtime/outbox/outboxtest/**,\
**/runtime/observability/healthz/healthztest/**,\
**/kernel/cell/celltest/**,\
**/kernel/command/commandtest/conformance.go,\
**/runtime/auth/refresh/storetest/**,\
**/runtime/auth/session/storetest/**,\
**/runtime/audit/ledger/storetest/**,\
**/runtime/distlock/locktest/conformance.go,\
**/corecells/accesscore/internal/ports/conformance/**,\
**/corecells/registrycore/internal/ports/conformance/**,\
**/kernel/persistence/persistencetest/**,\
**/kernel/projection/projectiontest/**,\
**/kernel/reconcile/reconciletest/**,\
**/kernel/saga/sagajournaltest/**,\
**/kernel/webhook/webhooktest/**,\
**/runtime/http/idempotency/idempotencytest/**,\
**/runtime/observability/metrics/metricstest/**,\
**/tests/testutil/**,\
**/examples/**,\
**/cmd/gocell/main.go,\
**/cells/accesscore/initialadmin/credfile_security_windows.go,\
**/cells/accesscore/initialadmin/path_default_windows.go,\
**/cells/accesscore/initialadmin/path_default_unsupported.go,\
**/cells/accesscore/initialadmin/bootstrap_unsupported.go,\
**/cells/accesscore/initialadmin/credfile_unsupported.go,\
**/cells/accesscore/initialadmin/sweep_unsupported.go,\
**/cells/accesscore/initialadmin/lifecycle_unsupported.go,\
**/cells/accesscore/initialadmin/platform_supported.go,\
**/cells/accesscore/initialadmin/platform_unsupported.go,\
**/runtime/shutdown/signals_windows.go,\
**/runtime/shutdown/signals_other.go
# --- Duplication (CPD) exclusions ---
#
# Test code and test-support conformance suites are exempt from the copy-paste /
# duplication gate. Table-driven and parallel-scenario tests are idiomatic Go and
# inherently repetitive (each self/device/tenant/all RowScope case, each handler
# request→assert block, each stub repo method shares structure with its siblings);
# DRY-ing them past a point trades readability for no maintenance benefit —
# duplicated TEST scenarios are not the production copy-paste hazard CPD targets.
#
# - **/*_test.go — unit/integration test files.
# - conformance suites (e.g. ports/conformance, **/*test/) — non-_test.go
# Protocol-driven suites RUN ONLY by tests (RunUserRepoConformance etc.),
# test-support code by nature. These are ALREADY treated as test-support by
# sonar.coverage.exclusions above (same dirs); CPD mirrors that classification.
#
# This is consistent with the established test-file rule relaxations below (go:S100
# / S2068 / S5659 / S117 / S1192 / S1186 / S1313 all ignored on **/*_test.go):
# test code follows different quality norms. PRODUCTION duplication stays fully
# gated (e.g. mem/repo, adapter, service code is NOT excluded).
sonar.cpd.exclusions=\
**/*_test.go,\
**/corecells/accesscore/internal/ports/conformance/**,\
**/corecells/registrycore/internal/ports/conformance/**
# --- Rule exclusions for Go conventions ---
# go:S100 — Go test naming convention uses underscores: TestXxx_Yyy_Zzz
# go:S2068 — Test files use "password" / DSN as test data, not real credentials
# go:S5659 — Tests use HMAC to sign JWTs for speed; production uses RS256
# go:S117 — Go naming allows abbreviations like dbURL, httpReq
# go:S1192 — Table-driven tests intentionally repeat string literals for readability
# go:S1186 — Empty func(){} in test tables are idiomatic Go noop handlers
sonar.issue.ignore.multicriteria=e1,e2,e3,e4,e5,e6,e7,e8,e9,e10,e11,e12,e13,e14,e15,e16,e17,e18,e19,e20,e21,e22,e23,e24,e25,e26,e27,e28,e29,e30,e31,e32,e33,e34,e35,e36,e37,e38,e39,e40,e41,e42,e43,e44,e45,e46,e47,e48,e49,e50,e51,e52,e53,e54,e55,e56,e57
sonar.issue.ignore.multicriteria.e1.ruleKey=go:S100
sonar.issue.ignore.multicriteria.e1.resourceKey=**/*_test.go
sonar.issue.ignore.multicriteria.e2.ruleKey=go:S2068
sonar.issue.ignore.multicriteria.e2.resourceKey=**/*_test.go
sonar.issue.ignore.multicriteria.e3.ruleKey=go:S5659
sonar.issue.ignore.multicriteria.e3.resourceKey=**/*_test.go
sonar.issue.ignore.multicriteria.e4.ruleKey=go:S117
sonar.issue.ignore.multicriteria.e4.resourceKey=**/*_test.go
sonar.issue.ignore.multicriteria.e5.ruleKey=go:S1192
sonar.issue.ignore.multicriteria.e5.resourceKey=**/*_test.go
sonar.issue.ignore.multicriteria.e6.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e6.resourceKey=**/*_test.go
# plsql:VarcharUsageCheck — false positive, no PL/SQL in this Go project
sonar.issue.ignore.multicriteria.e7.ruleKey=plsql:VarcharUsageCheck
sonar.issue.ignore.multicriteria.e7.resourceKey=**/*.sql
# go:S2068 — docker-compose files in examples/ use dev-only passwords
sonar.issue.ignore.multicriteria.e8.ruleKey=go:S2068
sonar.issue.ignore.multicriteria.e8.resourceKey=**/examples/**
# go:S1313 — Test files use hardcoded IPs (RFC 5737/3849 documentation ranges)
# as test fixtures for proxy trust, CIDR matching, XFF parsing, etc.
sonar.issue.ignore.multicriteria.e9.ruleKey=go:S1313
sonar.issue.ignore.multicriteria.e9.resourceKey=**/*_test.go
# go:S1186 — kernel/auth/auth_plan.go sealed interface marker methods are
# empty by design: each `func (T) listenerAuthOK() {}` is the
# unexported seal that closes the ListenerAuth enumeration so
# external packages cannot implement it. The body never runs;
# godoc above every marker explains the seal pattern. Same idiom
# as kubernetes/apiserver pkg/authentication/authenticator/interfaces.go.
sonar.issue.ignore.multicriteria.e10.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e10.resourceKey=**/kernel/auth/auth_plan.go
# go:S1186 — cells/accesscore/initialadmin/lifecycle_unsupported.go With* /
# Bind stubs are intentionally empty no-ops on !unix && !windows
# builds. The whole file is reachable only when
# WithInitialAdminBootstrap is configured for an unsupported GOOS,
# and PlatformSupported() / cell.Init returns
# ErrCellPlatformUnsupported before any of these options is
# invoked. File-level godoc explains the seal pattern; per-line
# nested comments would 8x duplicate that for zero new context.
# Same justification model as e10 (auth_plan.go sealed markers).
sonar.issue.ignore.multicriteria.e11.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e11.resourceKey=**/cells/accesscore/initialadmin/lifecycle_unsupported.go
# docker:S6470 — tests/e2e/Dockerfile.* must `COPY . .` to feed `go build` the
# full module (go.mod + tools/pg-migrate + cmd/corebundle + all
# transitive imports). The repo-root .dockerignore narrows the
# context (.git, .claude, docs/, worktrees/, bak/, *.env,
# coverage*.out filtered), and the multi-stage build discards
# the build-stage filesystem so only the compiled binary
# crosses into the runtime image. Privileged-user concerns
# (S6471) are addressed at the file level via `USER gocell`.
sonar.issue.ignore.multicriteria.e12.ruleKey=docker:S6470
sonar.issue.ignore.multicriteria.e12.resourceKey=**/tests/e2e/Dockerfile.*
# go:S3776 — generated *_gen.go files carry //nolint:gocognit on Init because
# subscribe-fan-out complexity is intrinsic to the cell's contract
# surface and not refactorable without changing the codegen model.
sonar.issue.ignore.multicriteria.e13.ruleKey=go:S3776
sonar.issue.ignore.multicriteria.e13.resourceKey=**/*_gen.go
# go:S1186 — corecells/accesscore/internal/domain/admin.go sealed marker method
# sealedEffectiveAdminCounter() is intentionally empty by design:
# it is the unexported marker that closes the EffectiveAdminCounter
# interface so external packages cannot implement it. The body
# never runs; godoc above the marker explains the seal pattern.
# Same idiom as e10 (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e14.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e14.resourceKey=**/corecells/accesscore/internal/domain/admin.go
# godre:S8196 — corecells/accesscore/internal/domain/admin.go EffectiveAdminCounterImpl
# keeps the "Impl" suffix on purpose to distinguish the raw
# structural interface (what concrete RoleRepositories satisfy)
# from the sealed wrapper EffectiveAdminCounter (what
# NewLastAdminGuard accepts). Renaming the raw interface to a
# naked "-er" form would collide with the sealed wrapper's name;
# the seal contract requires both. Same pattern as
# kernel/persistence.{TxRunner, CellTxManager}.
sonar.issue.ignore.multicriteria.e15.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e15.resourceKey=**/corecells/accesscore/internal/domain/admin.go
# plsql:S1192 — PL/SQL migration files repeat SQL identifiers ('admin', 'active',
# 'users', 'role_assignments') by structural necessity: these are
# table/column-value contracts, not magic numbers. Replacing with
# PL/pgSQL CONSTANT decls would scatter the identifier across DECLARE
# blocks without improving clarity. Migration files are also
# append-only (CLAUDE.md §"数据库迁移"), so the repetition is fixed
# at write time and never refactored.
sonar.issue.ignore.multicriteria.e16.ruleKey=plsql:S1192
sonar.issue.ignore.multicriteria.e16.resourceKey=**/adapters/postgres/migrations/*.sql
# go:S1186 — corecells/accesscore/internal/authzmutate/mutation.go sealed Mutation
# interface marker methods (mutationOK()) are intentionally empty:
# the unexported marker closes the Mutation enumeration so external
# packages cannot satisfy the interface. The 5 remaining variants
# (LockUser / SuspendUser / ActivateUser / RequirePasswordReset /
# ClearPasswordReset) each carry a no-body mutationOK() for this
# sole purpose. The body never runs; the package godoc and ADR §A10
# + archtest AUTHZ-MUTATION-APPLY-FUNNEL-01 document the seal
# pattern. Same idiom as e10 (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e17.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e17.resourceKey=**/corecells/accesscore/internal/authzmutate/mutation.go
# go:S1186 — kernel/observability/metrics/nop.go contains the null-object nop
# provider (NopProvider, nopCounter, nopHistogram, nopGauge).
# All empty method bodies are deliberate no-ops: NopProvider implements
# the Provider/Counter/Histogram/Gauge contracts without recording
# anything, matching the null-object pattern. The bodies execute but
# perform no operations; per-method nested comments would duplicate
# the file-level godoc for zero new context. Same justification model
# as e10/e11/e17.
sonar.issue.ignore.multicriteria.e18.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e18.resourceKey=**/kernel/observability/metrics/nop.go
# go:S1186 — kernel/outbox/cell_marker.go sealed-interface marker methods
# (sealedCellPublisher / sealedCellWriter) are intentionally empty:
# the unexported methods close the CellPublisher/CellWriter
# enumerations so external packages cannot implement them. The
# bodies never run; godoc above every marker explains the seal
# pattern. Same idiom as e10 (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e19.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e19.resourceKey=**/kernel/outbox/cell_marker.go
# go:S1186 — kernel/persistence/cell_marker.go sealed-interface marker method
# (sealedCellTxManager) is intentionally empty by design: it is the
# unexported marker that closes the CellTxManager interface so
# external packages cannot implement it. The body never runs; godoc
# above the marker explains the seal pattern. Same idiom as e10.
sonar.issue.ignore.multicriteria.e20.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e20.resourceKey=**/kernel/persistence/cell_marker.go
# godre:S8196 — kernel/command/registrar.go QueueRegistrar intentionally keeps
# the "Registrar" suffix to express the injection-direction role
# (a Cell receives its Queue via RegisterCommandQueue). Renaming to
# a naked "-er" form (e.g. CommandQueueRegisterer) would obscure
# the registry pattern and collide with the runtime discovery
# phase naming. Same justification model as e15 (admin.go).
sonar.issue.ignore.multicriteria.e21.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e21.resourceKey=**/kernel/command/registrar.go
# godre:S8196 — kernel/observability/metrics/metrics.go Histogram is a domain
# term for the metric instrument type, not a general interface name.
# Renaming to "Observer" or "Histogramer" would lose the Prometheus/
# OTel domain alignment (ref: prom/client_golang histogram.go).
# Same justification model as e15.
sonar.issue.ignore.multicriteria.e22.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e22.resourceKey=**/kernel/observability/metrics/metrics.go
# go:S1186 — runtime/config/watcher_metrics.go NoopWatcherCollector
# methods are intentionally empty: the struct is a nop metrics provider used when
# no metrics backend is configured. All three methods (RecordEvent,
# RecordLastEventTimestamp, RecordDebounceCoalesced) discard their arguments by
# design. WatcherCollector already uses the Go -er suffix convention so no
# godre:S8196 exclusion is needed.
sonar.issue.ignore.multicriteria.e23.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e23.resourceKey=**/runtime/config/watcher_metrics.go
# go:S1186 — runtime/auth/session/protocol.go sealed-interface marker methods
# fingerprintModeOK() and orderingModelOK() are intentionally empty: the
# unexported marker method is what implements the sealed interface (FingerprintMode
# / OrderingModel) and closes the enumeration to external packages. The body
# never runs. Pattern mirrors kernel/auth/auth_plan.go (e10).
sonar.issue.ignore.multicriteria.e24.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e24.resourceKey=**/runtime/auth/session/protocol.go
# godre:S8196 — runtime/auth/session/protocol.go FingerprintMode / OrderingModel
# interface names intentionally do not use the Go -er suffix convention: these
# are sealed discriminated-union marker interfaces (zero methods visible outside
# the package), not behavior-description interfaces. The pattern mirrors
# kernel/auth/auth_plan.go ListenerAuth and admin.go EffectiveAdminCounterImpl
# (e15). An -er name would misrepresent the role of these interfaces.
sonar.issue.ignore.multicriteria.e25.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e25.resourceKey=**/runtime/auth/session/protocol.go
# go:S1186 — runtime/state/cas/protocol.go ConflictPolicy sealed interface.
# conflictPolicyOK() is intentionally empty — same sealed-marker pattern as
# e24 (runtime/auth/session/protocol.go). The body never runs; presence of the
# unexported marker method is the entire implementation contract.
sonar.issue.ignore.multicriteria.e26.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e26.resourceKey=**/runtime/state/cas/protocol.go
# godre:S8196 — runtime/state/cas/protocol.go ConflictPolicy interface name
# does not need an -er suffix: it is a sealed discriminated-union marker
# interface (zero exported methods), not a behavior-description interface.
# Same justification as e25 (runtime/auth/session/protocol.go).
sonar.issue.ignore.multicriteria.e27.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e27.resourceKey=**/runtime/state/cas/protocol.go
# go:S1186 — runtime/observability/tracingtest/tracer.go simpleSpan.End() is
# intentionally empty: it is a no-op because the in-process test tracer does
# not persist or export spans. The package godoc explains the deliberate
# propagation asymmetry (B2-A-20) — End is a required Span interface method
# that has no meaningful implementation for the stdlib test fixture.
sonar.issue.ignore.multicriteria.e28.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e28.resourceKey=**/runtime/observability/tracingtest/tracer.go
# go:S1186 — runtime/audit/ledger/protocol.go sealed RestartRecoveryMode /
# IdempotencyMode marker methods (restartRecoveryModeOK /
# idempotencyModeOK) are intentionally empty by design: each
# `func (T) xModeOK() {}` is the unexported seal that closes the
# enumeration so external packages cannot implement it. The body
# never runs; godoc above every marker explains the seal pattern.
# Same idiom as e10 (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e29.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e29.resourceKey=**/runtime/audit/ledger/protocol.go
# godre:S8196 — runtime/audit/ledger/protocol.go RestartRecoveryMode /
# IdempotencyMode sealed interfaces use descriptive names (not
# -er suffix) because they represent protocol variant enumerations,
# not single-method functional roles. Renaming to RestartRecoveryModeer
# / IdempotencyModeer would be grammatically incorrect and misleading.
# Same justification as e15 (EffectiveAdminCounterImpl).
sonar.issue.ignore.multicriteria.e30.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e30.resourceKey=**/runtime/audit/ledger/protocol.go
# go:S1186 — runtime/eventrouter/router_observability.go NopEventCollector
# method bodies are intentionally empty no-ops: the struct is the
# default when no metrics backend is wired, and all 5 methods are
# defined only to satisfy the EventCollector interface. The bodies
# never run meaningful logic; each method godoc explains the
# no-op intent. Same idiom as e10 (production sealed-interface
# marker — kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e31.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e31.resourceKey=**/runtime/eventrouter/router_observability.go
# godre:S8196 — pkg/securecookie/securecookie.go Clock interface uses the
# idiomatic Go name "Clock" (not "Clocker") by convention: the
# Clock interface is the established name across the Go ecosystem
# (k8s/apimachinery, go-kit, etc.) for a wall-clock abstraction.
# The single method Now() does not map naturally to "Nower".
# Same justification as e15 (admin.go EffectiveAdminCounterImpl).
sonar.issue.ignore.multicriteria.e32.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e32.resourceKey=**/pkg/securecookie/securecookie.go
# go:S3776 — runtime/observability/healthz/healthztest/conformance.go
# RunAggregatorConformance inlines 13 t.Run sub-tests as one
# cohesive contract narrative ("one function = full contract"),
# already carrying //nolint:gocognit for the same reason. Splitting
# each sub-test into a top-level helper would fragment the
# single-source-of-truth conformance suite without reducing real
# complexity. Same intrinsic-complexity justification as e13
# (generated *_gen.go Init fan-out).
sonar.issue.ignore.multicriteria.e33.ruleKey=go:S3776
sonar.issue.ignore.multicriteria.e33.resourceKey=**/runtime/observability/healthz/healthztest/conformance.go
# godre:S8196 — kernel/healthz/probe.go ProbeSet is a domain term for a
# collection of probes exposed by one owner (e.g. outbox.DirectEmitter
# exposes one probe per cell), not a single-method behavior interface.
# Its method Probes() []Probe returns the set; renaming to "Prober"
# or "Probeser" would lose the domain meaning and collide with the
# existing RepoProber. Same justification as e22 (metrics.Histogram)
# and e15 (EffectiveAdminCounterImpl).
sonar.issue.ignore.multicriteria.e34.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e34.resourceKey=**/kernel/healthz/probe.go
# go:S1186 — internal/pgexec/pgexec.go (4 production copies under
# adapters/postgres, adapters/postgres/saga, corecells/accesscore/.../postgres,
# examples/iotdevice/.../postgres; the glob also matches an
# archtest_fixture-tagged copy under tools/, which is outside
# sonar.sources) seal the PGExecutor interface via
# the unexported sealPGExecutor() marker method, intentionally empty:
# it closes the enumeration so external packages cannot implement
# PGExecutor (only the package-private pgExecutor satisfies it, routed
# through pgexec.ExecDirect). The body never runs; file godoc explains
# the seal pattern. Same idiom as e10 (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e35.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e35.resourceKey=**/internal/pgexec/pgexec.go
# go:S1186 — pkg/errcode/details.go publicValue() marker methods (publicString /
# publicInt / publicBool / publicDuration / publicTime) are
# intentionally empty: publicValue is a sealed marker interface whose
# sole unexported method closes the PublicDetail.value type set so
# wire-unsafe types are compile-time unexpressible. The bodies never
# run; package godoc + DETAILS-SEALED-FIELD-FROZEN-01 archtest document
# the seal. Same idiom as e10 (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e36.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e36.resourceKey=**/pkg/errcode/details.go
# go:S1186 — runtime/saga/executor/observer.go NopObserver method bodies
# (ObserveOutcome / ObserveRetry / ObserveHeartbeatFailure) are
# intentionally empty no-ops: NopObserver is the zero-cost default
# Observer used when no observer is wired, discarding all arguments by
# design. Same null-object justification model as e18
# (kernel/observability/metrics/nop.go) and e31 (NopEventCollector).
sonar.issue.ignore.multicriteria.e37.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e37.resourceKey=**/runtime/saga/executor/observer.go
# go:S1186 — kernel/healthz/probe.go isHealthzProbe() sealed marker method is
# intentionally empty: the unexported marker closes the Probe
# interface so external packages cannot forge a healthz probe (probes
# must be built via healthz.NewProbe). The body never runs; godoc
# explains the seal. Same idiom as e10 (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e38.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e38.resourceKey=**/kernel/healthz/probe.go
# go:S1186 — kernel/healthz/ctxsafe.go isHealthzProbe() sealed marker method on
# the ctx-safe probe wrapper is intentionally empty for the same seal
# reason as e38 (probe.go): it closes the Probe interface. The body
# never runs. Same idiom as e10 (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e39.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e39.resourceKey=**/kernel/healthz/ctxsafe.go
# go:S1186 — kernel/projection/cell_marker.go sealedCellCheckpointStore() marker
# method is intentionally empty: the unexported marker closes the
# CellCheckpointStore interface so external packages cannot implement
# it. The body never runs; godoc explains the seal pattern. Same idiom
# as e19/e20 (kernel/outbox + kernel/persistence cell_marker.go).
sonar.issue.ignore.multicriteria.e40.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e40.resourceKey=**/kernel/projection/cell_marker.go
# go:S1186 — kernel/webhook/signer.go sealed() marker method is intentionally
# empty: the unexported marker closes the Signer interface so external
# packages cannot supply an alternate webhook signer. The body never
# runs; godoc explains the seal. Same idiom as e10
# (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e41.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e41.resourceKey=**/kernel/webhook/signer.go
# go:S1186 — kernel/webhook/verifier.go sealed() marker method is intentionally
# empty for the same seal reason as e41 (signer.go): it closes the
# Verifier interface. The body never runs. Same idiom as e10.
sonar.issue.ignore.multicriteria.e42.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e42.resourceKey=**/kernel/webhook/verifier.go
# go:S1186 — pkg/pgrepoapproved/pgrepoapproved.go approvedExecDirect() marker
# method is intentionally empty: the unexported marker closes the
# Approval interface so only pgrepoapproved-issued tokens can authorize
# raw ExecDirect. The body never runs; file godoc documents the seal +
# funnel. Same idiom as e10 (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e43.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e43.resourceKey=**/pkg/pgrepoapproved/pgrepoapproved.go
# go:S1186 — runtime/auth/credentialfence/fencetoken.go isCredentialFenceToken()
# marker method is intentionally empty: the unexported marker closes
# the FenceToken interface so a credential fence token cannot be forged
# outside the package. The body never runs; godoc documents the seal +
# caller restriction. Same idiom as e10 (kernel/auth/auth_plan.go).
sonar.issue.ignore.multicriteria.e44.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e44.resourceKey=**/runtime/auth/credentialfence/fencetoken.go
# go:S1186 — adapters/mqtt/connection.go noopCollector method bodies
# (RecordReconnect / RecordSubscribeFailure) are intentionally empty
# no-ops: noopCollector is the null-object default MQTT metrics
# collector used when no metrics backend is wired, discarding all
# arguments by design. Same null-object justification model as e18
# (kernel/observability/metrics/nop.go) and e23 (NoopWatcherCollector).
sonar.issue.ignore.multicriteria.e45.ruleKey=go:S1186
sonar.issue.ignore.multicriteria.e45.resourceKey=**/adapters/mqtt/connection.go
# godre:S8196 — kernel/webhook/source.go SourceStore is a domain concept (a
# registry that resolves a SourceID), not a single-method verb role.
# An -er form (SourceStorer) is nonsensical and loses the "store"
# domain meaning. Same justification as e22 (metrics.Histogram) and e34
# (healthz.ProbeSet).
sonar.issue.ignore.multicriteria.e46.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e46.resourceKey=**/kernel/webhook/source.go
# godre:S8196 — runtime/audit/ledger/query_store.go QueryStore is a domain
# concept (read-side aggregator store with a Query capability),
# parallel to the audit Store; renaming to "Querier" would break the
# Store analogy and lose domain meaning. Same justification as e46
# (SourceStore) and e22 (metrics.Histogram).
sonar.issue.ignore.multicriteria.e47.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e47.resourceKey=**/runtime/audit/ledger/query_store.go
# godre:S8196 — pkg/pgrepoapproved/pgrepoapproved.go Approval is a sealed marker
# interface (closed by the unexported approvedExecDirect() method),
# not a behavior contract. An -er name (Approver) would mislead that
# external types may implement it, defeating the seal. Same
# justification model as e25/e27 (sealed marker interfaces).
sonar.issue.ignore.multicriteria.e48.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e48.resourceKey=**/pkg/pgrepoapproved/pgrepoapproved.go
# godre:S8196 — runtime/auth/credentialfence/fencetoken.go FenceToken is a sealed
# marker interface (closed by isCredentialFenceToken()), expressing a
# capability proof, not a verb role. An -er suffix would misrepresent
# it as externally implementable. Same justification as e48 (Approval)
# and e25 (session protocol sealed markers).
sonar.issue.ignore.multicriteria.e49.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e49.resourceKey=**/runtime/auth/credentialfence/fencetoken.go
# godre:S8196 — runtime/saga/executor/retry_policy.go jitterSource is an
# unexported package-internal interface whose method Int64N mirrors
# math/rand.Rand.Int64N (a source of jitter values). An -er form
# (jitterSourcer) is nonsensical; unexported internal contracts have no
# external naming pressure. Same justification as e22 (domain term).
sonar.issue.ignore.multicriteria.e50.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e50.resourceKey=**/runtime/saga/executor/retry_policy.go
# godre:S8242 — kernel/cell/base.go BaseCell.shutdownCtx is an intentional
# lifecycle field, not a smuggled request context: it is created in
# Start() and canceled in Stop(), and goroutines spawned by the cell
# use it (instead of context.Background()) so they observe cell
# shutdown. Passing it per-call would defeat the cell-owned cancel
# signal. Documented in the field godoc (base.go).
sonar.issue.ignore.multicriteria.e51.ruleKey=godre:S8242
sonar.issue.ignore.multicriteria.e51.resourceKey=**/kernel/cell/base.go
# godre:S8242 — kernel/governance/validate.go Validator.runCtx holds the context
# for the current run() invocation, read by ctx-bound rule detection
# closures (VERIFY-06). run() overwrites it per invocation; the field
# is the deliberate single-read channel for detect funcs that cannot
# receive ctx as a parameter through the rule-table indirection.
sonar.issue.ignore.multicriteria.e52.ruleKey=godre:S8242
sonar.issue.ignore.multicriteria.e52.resourceKey=**/kernel/governance/validate.go
# godre:S8242 — runtime/bootstrap/bootstrap.go ownerCtx is the long-lived
# assembly-runtime owner context (derived from runCtx before
# lifecycle.Start) handed to every lifecycle hook's OnStart, so workers
# respond to ownerCancel before lifecycle.Stop drains them. This is the
# controller-runtime owner-context pattern; passing it per-call would
# break the shutdown ordering. Documented in field godoc + ADR
# 202605102000-adr-lifecycle-hook-ctx-semantics.md.
sonar.issue.ignore.multicriteria.e53.ruleKey=godre:S8242
sonar.issue.ignore.multicriteria.e53.resourceKey=**/runtime/bootstrap/bootstrap.go
# godre:S8242 — runtime/bootstrap/lifecycle.go workCtx is the per-invocation
# OnStart context (child of the bootstrap ownerCtx) handed to every
# hook; workCancel is invoked BEFORE the LIFO rollback on partial Start
# failure so a failed hook's already-spawned goroutine is torn down
# before sibling OnStop. Written once under the Start goroutine, then
# read-only. Essential for correct rollback semantics (review P1-2);
# documented in field godoc + ADR 202605102000.
sonar.issue.ignore.multicriteria.e54.ruleKey=godre:S8242
sonar.issue.ignore.multicriteria.e54.resourceKey=**/runtime/bootstrap/lifecycle.go
# godre:S8188 — runtime/saga/executor/executor.go heartbeat/step cancel funcs
# (stopHB at executeInner/RunWithHeartbeat, cancel at buildStepCtx) are
# not leaked: stopHB is always invoked via stopAndJoin() on every
# return path or a deferred cleanup, and buildStepCtx returns a wrapper
# closure (timer.Stop + cancel) that its caller (runAttempt) owns and
# defers. The rule's "defer immediately after creation" heuristic does
# not fit a cancel func that is intentionally handed to the caller /
# joined with the heartbeat goroutine.
sonar.issue.ignore.multicriteria.e55.ruleKey=godre:S8188
sonar.issue.ignore.multicriteria.e55.resourceKey=**/runtime/saga/executor/executor.go
# go:S1313 — kernel/webhook/ssrf.go ssrfBlockedCIDRStrings is a deliberate SSRF
# dial-time blocklist: every entry is a hardcoded reserved/private
# CIDR by design (RFC1918 / loopback / link-local / CGNAT / NAT64 /
# multicast / documentation, etc.). The "is this hardcoded IP safe"
# hotspot is inverted here — enumerating the unsafe ranges IS the
# security control. The list is cross-checked against
# testdata/webhook-ssrf-deny.yaml by a drift guard and documented in
# ADR 202605312300-1159-adr-webhook-ssrf-policy.md. Same false-positive
# justification as e9 (S1313 in test fixtures), scoped to the one
# production file that owns the blocklist.
sonar.issue.ignore.multicriteria.e56.ruleKey=go:S1313
sonar.issue.ignore.multicriteria.e56.resourceKey=**/kernel/webhook/ssrf.go
# godre:S8196 — examples/orderfulfillment/run.go CellModule is a domain term that
# mirrors the cellmodules-layer composition.CellModule contract (the
# modules_gen.go interface a demo composition root binds), not a
# single-method -er behavior role. Its method ID() string has no
# natural -er form ("IDer" is meaningless), and renaming would break
# the parallel with the real composition.CellModule the example
# teaches. Same domain-term justification as e46 (SourceStore) / e47
# (QueryStore) / e15 (EffectiveAdminCounterImpl).
sonar.issue.ignore.multicriteria.e57.ruleKey=godre:S8196
sonar.issue.ignore.multicriteria.e57.resourceKey=**/examples/orderfulfillment/run.go