J4 / UPGRADES
← All practice results

p2-02-laravel

Public GitHub evidence ↗

# P2-02 — Laravel RealWorld: GREEN (legacy-hop practice scope)

Source: `gothinkster/laravel-realworld-example-app` @ `e45c37c8a5f57131c9d239f1fc104c227e66b6ee`. Owned fork `j4groupfounders/laravel-realworld-example-app`, branch `j4/p2-upgrade`.

**Laravel 5.5.45 → 6.20.45**, locked. This is an intermediate EOL major hop, **not** a supported-production destination. Pre-registered in harness commit `5df3a66322ff3e20f79098b08c340682535525a2` before the upgrade branch.

## Acceptance

- All **56 project tests** pass before and after the upgrade. Screening counted 60 annotations, but the real runner count is 56; use the latter. All assertions remain intact; only PHPUnit setup return-type signatures change. No new skips or removals.
- Migrated isolated MySQL database; real HTTP server boots. Five unchanged snapshots: tags 200, articles 200, unauthorized user 401, nonexistent route 404, malformed login 422. Same status, content-type and normalized-body hashes.
- Exact resolved composer.lock committed and verified with composer install, not just a floating resolver run.
- Five independent route mutations: project tests **5/5**, project tests + harness **5/5**. Each mutation restored after checks; detection gate satisfied for this scoped fault set.
- Zero human edits. No upstream PRs/issues/messages, no paid services.

## Baseline repairs

1. Port Travis to public Linux Actions and use Composer 1 for the historical locked update-helper plugin.
2. Project tests use DatabaseMigrations and remove tables when rolling back; recreate the empty schema before independent HTTP probes. This fixes harness fixture lifecycle, not app logic.

## Upgrade changes and real regressions caught

- PHP 7.2 → 7.4; Laravel 6.20.45 and compatible JWT/CORS/Tinker/dev-tool dependencies. Remove obsolete Composer optimize hooks.
- PHPUnit 8 setup methods require `: void`; no assertion changes. Replace removed global string helpers with `Illuminate\Support\Str` equivalents.
- First upgrade run fatals because FormRequest::validationData is now public. Match visibility in all affected request classes.
- Next run executes 56 tests: 54 pass, login and password-update fail. PHP 7.4 changed password_get_info algo from integer to string/null; old `=== 0` condition stopped hashing plaintext. Use stable `algoName === unknown` detection. Existing tests catch this security-relevant compatibility regression; no test was relaxed.
- After repair, all 56 tests and all five differential probes pass; final job repeats them plus the seeded faults.

## CI ledger

| Run | Branch | Outcome | Job-min |
|---|---|---|---:|
| [37532996392](https://github.com/j4groupfounders/laravel-realworld-example-app/actions/runs/37532996392) | j4/p2-baseline | failure | 0.600 |
| [37533200238](https://github.com/j4groupfounders/laravel-realworld-example-app/actions/runs/37533200238) | j4/p2-baseline | failure | 1.950 |
| [37533546810](https://github.com/j4groupfounders/laravel-realworld-example-app/actions/runs/37533546810) | j4/p2-baseline | success | 2.017 |
| [37533950709](https://github.com/j4groupfounders/laravel-realworld-example-app/actions/runs/37533950709) | j4/p2-upgrade | failure | 1.550 |
| [37534379396](https://github.com/j4groupfounders/laravel-realworld-example-app/actions/runs/37534379396) | j4/p2-upgrade | failure | 1.000 |
| [37534636855](https://github.com/j4groupfounders/laravel-realworld-example-app/actions/runs/37534636855) | j4/p2-upgrade | success | 1.050 |
| [37534938568](https://github.com/j4groupfounders/laravel-realworld-example-app/actions/runs/37534938568) | j4/p2-upgrade | success | 2.783 |

Total: **7 CI runs, 10.950 actual job minutes**. Terminal verified SHA `17a295de91f9c1ef5201508321b35f8ad2e906c6`; wall time from preregistration is in batch results.

## Limits

- Empty-DB unauthenticated snapshots; no authenticated HTTP fixture replay, fixed-clock scenario or full route/line coverage claim. Existing project tests exercise authenticated CRUD and password updates, but that is not a substitute for full differential replay.
- Five faults are output/status mutations, not comprehensive business-boundary or token-expiry coverage. If project tests detect a fault already, combined detection is not claimed as new harness value.
- EOL destination requires a later supported-version upgrade before any real delivery. Model token/cost telemetry not exposed; no estimate is presented as measured.