Chapter 08Lesson 05~165 minutes

Checkpoint Lab — Language Analysis, Sensors, SCM Data, and Source-Code Indexing

Create a governed indexing dossier: predict the exact mixed-source file set, prove it from scanner evidence, inject one reversible scope or SCM defect, repair the cause, and preserve the evidence chain.

Checkpoint labPredictionsEvidence packetFailure injectionGovernance

Learning objectives

  • Predict source/test/index/language/SCM outcomes before running analysis.
  • Capture exact revision, scanner/runtime, effective scope, indexed files, sensor evidence and report/task status.
  • Inject and diagnose one reversible exclusion or shallow-SCM defect without changing unrelated policy.
  • Prove the repair independently with scanner and server evidence.
  • Produce a reusable scope-governance dossier and revoke credentials safely.

1. Checkpoint scenario and assumptions

Operate only on the disposable academy-sonarqube-p08 project and synthetic repository from Lesson 2. Record Community Build 26.9.0.129388, Scanner CLI 8.1.0.6389, Git version, scanner JRE mode, exact project key, and whether any external analyzer/report import is enabled. The mandatory lab uses no commercial feature, CI provider, third-party plugin, Kubernetes, identity provider, or production database change.

Stop conditions: stop if SONAR_HOST_URL is not loopback/private lab infrastructure, if the project key is not the disposable academy key, if the token scope cannot be verified, or if cleanup commands would affect a shared project/server volume.

2. Preflight inventory

cd sonar-p08
pwd
git status --short
git rev-parse HEAD | tee evidence-revision.txt
git rev-parse --is-shallow-repository | tee evidence-shallow.txt
git ls-files | sort | tee evidence-tracked-files.txt
git status --ignored --short | tee evidence-ignored-files.txt
sonar-scanner --version | tee evidence-scanner-version.txt
sed -E '/token|password|secret/Id' sonar-project.properties | tee evidence-project-properties.txt

If the working tree is dirty, either commit the intended lab change or record why it is dirty before analysis. Do not silently scan unrecorded source mutations.

3. Write predictions before execution

Prediction Expected state Independent proof
P1 source roots Only src and infra are initial source roots debug Project configuration + indexed paths
P2 test root tests is test scope and disjoint from source debug indexed test paths; no duplicate-index error
P3 generated filter src/generated/** is excluded if Lesson 2 config remains effective exclusions + absent path in indexing evidence
P4 custom suffix src/helper.academy is recognized as Python if suffix override remains Python/language debug evidence
P5 SCM Full clone provides normal SCM/blame attempt shallow=false + scanner SCM log
P6 report lifecycle successful scanner upload creates report-task.txt; CE/gate remain separate task file + CE API/UI + gate API/UI

4. Execute the controlled good run

read -rsp 'Project-analysis token: ' SONAR_TOKEN; echo
export SONAR_TOKEN SONAR_HOST_URL='http://127.0.0.1:9000'
sonar-scanner -X -Dsonar.host.url="$SONAR_HOST_URL" 2>&1 | tee evidence-good-debug.log
cp .scannerwork/report-task.txt evidence-good-report-task.txt
grep -Ei 'project configuration|indexed|excluded|included|sensor|language|scm|blame'   evidence-good-debug.log | tee evidence-good-scope-summary.txt

Extract ceTaskId from the task file and preserve the terminal Compute Engine status before recording any gate result. If scanner upload fails, do not fabricate CE/gate evidence.

5. Inject exactly one reversible defect

Choose one of these paths, not both, so the causal variable stays clear.

Option A — exclusion defect

cp sonar-project.properties sonar-project.properties.good
printf '
sonar.exclusions=src/**
' >> sonar-project.properties
sonar-scanner -X -Dsonar.host.url="$SONAR_HOST_URL" 2>&1 | tee evidence-broken-exclusion.log || true

Prediction: most owned Python source disappears while infra and tests follow their own scopes. Preserve the indexed-file/measure change.

Option B — shallow-SCM defect

cd ..
rm -rf sonar-p08-shallow
git clone --depth 1 "file://$PWD/sonar-p08" sonar-p08-shallow
cd sonar-p08-shallow
git rev-parse --is-shallow-repository | tee evidence-broken-shallow.txt
sonar-scanner -X -Dsonar.host.url="$SONAR_HOST_URL" 2>&1 | tee evidence-broken-scm.log || true

Prediction: SCM/blame evidence is degraded/skipped and analysis may fail. Preserve the actual result.

6. Repair the exact defect

Repair A

mv sonar-project.properties.good sonar-project.properties
sonar-scanner -X -Dsonar.host.url="$SONAR_HOST_URL" 2>&1 | tee evidence-repaired.log
cp .scannerwork/report-task.txt evidence-repaired-report-task.txt

Repair B

git fetch --unshallow 2>/dev/null || git fetch --depth=2147483647
git rev-parse --is-shallow-repository | tee evidence-repaired-shallow.txt
sonar-scanner -X -Dsonar.host.url="$SONAR_HOST_URL" 2>&1 | tee evidence-repaired.log
cp .scannerwork/report-task.txt evidence-repaired-report-task.txt

Do not compensate by changing project key, lowering the Quality Gate, granting admin credentials, deleting logs/cache, disabling TLS, editing database/search state, or globally disabling SCM.

7. Required evidence packet

manifest.md — Community Build/scanner/Git/JRE versions, project key, assumptions
revision.txt — exact analyzed revision(s)
workspace.txt — base directory, tracked/ignored/shallow state
scope-config.txt — sanitized effective source/test/filter/suffix settings
good-debug.log — complete sanitized scanner debug log
good-scope-summary.txt — indexing/language/sensor/SCM evidence
good-report-task.txt — report/task correlation metadata
ce-good.json / UI record — terminal Compute Engine state
gate-good.json / UI record — separate policy state
broken-*.log — original injected defect evidence
repaired-*.log + task/CE evidence — independent repair proof
credentials.md — token type/scope/owner/expiry/revocation metadata only
governance.md — exclusion/suffix/SCM rationale and rollback
limitations.md — external-report, CI, commercial and monorepo paths not executed

8. Verification checklist

  • Exact source revision and project key are recorded.
  • Source and test scopes are disjoint and proved from logs.
  • Indexed-file evidence matches the predicted roots and exclusions.
  • Custom suffix behavior is recorded or explicitly absent if reverted.
  • SCM shallow/full state is independently recorded.
  • Sensor/report warnings are preserved rather than hidden.
  • Each successful upload is correlated to its own Compute Engine task.
  • Gate state is recorded separately from scanner/CE success.
  • The broken evidence remains available after repair.
  • No token value or proprietary source appears in the packet.

9. Guarded cleanup and rollback

  1. Revoke the disposable project-analysis token and prove the token is no longer usable for a harmless authenticated project request.
  2. Unset SONAR_TOKEN.
  3. Restore the known-good sonar-project.properties if Option A was used.
  4. Delete only the shallow clone/fixture after the evidence packet is complete.
  5. Delete the disposable Sonar project only if no later chapter will reuse it.
  6. Leave shared scanner caches and server/database/search volumes untouched.

10. What Chapter 08 adds to the operating model

You can now define analysis scope as a governed, evidence-backed contract: exact base directory, source/test roots, filters, language mapping, generated/vendor policy, SCM state, sensor/report inputs, scanner report/task and downstream policy state. Chapter 09 can therefore teach rules and quality profiles against a known analyzed file set instead of debating findings from an unknown scope.

Knowledge check

What must be predicted before the checkpoint scan?

Why inject only one defect at a time?

What is the correct repair for the over-broad exclusion option?

Why keep scanner, CE and gate evidence in separate files?

What should remain after credential cleanup?

Next lesson

From known scope to known rules

Chapter 09 builds on this verified file/sensor/SCM model to teach rules, quality profiles, activation, inheritance, customization and rule-governance evidence.

Official references and version notes

Version and compatibility note

Rechecked on 2026-09-07. Mandatory labs target local/private SonarQube Community Build 26.9.0.129388 with standalone SonarScanner CLI 8.1.0.6389. JRE auto-provisioning remains enabled; current scanner guidance requires Java 11 to launch CLI 7.2+ when provisioning is enabled, while environments that disable provisioning must supply a currently supported Java runtime (Java 21 is the safe current baseline). The mixed-source fixture uses languages supported by Community Build and does not require commercial analyzers, third-party plugins, CI providers, enterprise identity, branch/PR analysis, or external databases beyond the already running disposable lab server. Re-check language and scanner requirements before future runs because analyzer/runtime support evolves.

Keep the academy open

Support free, practical DevOps education.

Every lesson is designed to remain readable in a browser, downloadable from GitHub, and usable without a paid learning platform. Contributions help expand and maintain the curriculum.

Ethereum / ERC-20
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0Send only Ethereum/ERC-20 compatible assets to this address.