comtihon/mongodb-erlang
67.7
Adequate · 23 September 2026
3.4k
lines of production code
Erlang
primary language
5
measurements over time
What this system is
This system is an Erlang-based MongoDB driver that manages database connections, authentication, and query execution. It implements the MongoDB wire protocol to handle topology discovery, connection pooling, and cursor management. The codebase includes utilities for documentation generation, local environment setup, and comprehensive test coverage for protocol and authentication logic.
How it got here
2010 — Erlang driver refactoring and modernization
4 changes.
The project underwent a significant architectural overhaul, migrating from hardcoded metadata to build-time generation and refactoring the internal structure to support the MongoDB 6.0+ wire protocol. Legacy modules were removed in favor of modern Erlang patterns like mvar and gen\_server, while the codebase was initialized with standard tooling and dependency configurations.
2011–2014 — Architecture and documentation overhaul
4 changes.
This period focused on restructuring the codebase by isolating connection, authentication, and cursor management into dedicated modules, while introducing new supervision and state management components. The team also automated documentation generation and added support for modern cryptographic APIs and DNS SRV records.
2015–2021 — Modern client architecture and test coverage
4 changes.
This period focused on modernizing the Erlang MongoDB driver by introducing a new client API and robust topology management for server discovery and selection. The implementation was supported by comprehensive test suites covering authentication, protocol detection, and error handling, alongside updated installation scripts for compatibility with MongoDB 6.0+.
Features
Added documentation generation and cleanup scripts
Added shell scripts to automate documentation generation and cleanup. The new 'gen\_docs' script uses Erlang's edoc to generate HTML documentation from source code comments, while 'clear\_docs' removes generated HTML files and related assets. Additionally, a 'design.md' document was added to explain the architecture of the Erlang MongoDB driver, including design decisions around BSON representation, state management via 'var' and 'gen\_server', and the 'DB action' pattern for database operations.
doc · medium confidence
Initial project setup and dependency configuration
The repository has been initialized with essential configuration files, including a \.gitignore\ to exclude build artifacts and logs, a \Makefile\ to automate building, testing, and documentation generation, and a \rebar.config\ specifying dependencies on \bson\, \pbkdf2\, and \poolboy\. Additionally, \docker-compose.yml\ files are provided to spin up local MongoDB instances for testing, and a \LICENSE\ file establishes the Apache 2.0 terms.
(repo-wide) · high confidence
Introduce new Erlang MongoDB client API modules
Added three new Erlang modules to the API layer: mc\_worker\_api, which provides a standalone client interface for MongoDB operations like connect, insert, update, and find; mongo\_api, which acts as a helper API wrapping mc\_worker\_api with topology and transaction support; and mongoc, which manages the connection topology, read preferences, and query transformations. These modules replace or supplement the previous interface, introducing support for write concerns, read preferences, and modern MongoDB protocol features.
src/api · high confidence
Introduce new internal supervision and state management modules
Added three new internal modules to the application: mc\_super\_sup, which defines a new supervisor tree for managing worker processes; mc\_worker\_pid\_info, which provides an ETS-backed registry to track and retrieve metadata about worker processes, including automatic protocol type detection; and mongo\_id\_server, which manages global counters for generating unique request IDs and object IDs.
src/main · medium confidence
Introduce server monitoring, selection, and topology management for MongoDB connections
The mongoc add-on now includes core modules for monitoring individual MongoDB servers (mc\_monitor), managing connection pools (mc\_pool\_sup), handling server selection logic (mc\_selecting\_logics), and maintaining the overall topology state (mc\_topology, mc\_topology\_logics). This adds the capability to discover server roles (primary, secondary, mongos, standalone), select the best server for a given read preference, and dynamically update the topology as servers join or leave the cluster.
src/mongoc · high confidence
Architecture
Introduce dedicated modules for connection management, authentication, and cursor handling
The connection layer has been restructured into dedicated modules: mc\_auth\_logic handles authentication (including SCRAM-SHA-1 and legacy CR mechanisms), mc\_connection\_man manages the connection lifecycle and request routing, mc\_cursor implements cursor state management, and mc\_worker\_logic encapsulates protocol encoding and response decoding. This refactoring isolates core connection and authentication logic into separate files to improve maintainability and clarity.
src/connection · high confidence
Behavioural changes
Add MongoDB SRV record support and modernize crypto API usage
Added support for DNS SRV lookups to discover MongoDB seed hosts, including validation that endpoints belong to the same base domain. Updated the codebase to use strong random bytes for generating nonces and to conditionally use the modern crypto:mac API in OTP 23+, falling back to the legacy crypto:hmac API for older Erlang/OTP versions.
src/support · medium confidence
Migration from .app to .app.src for Erlang application metadata
The Erlang application metadata file mongodb.app has been removed in favor of using a .app.src template. This change allows the application's version number and other metadata to be generated during the build process rather than being hardcoded in the source code, which is a standard practice for managing versioning and build-time substitutions in Erlang projects.
ebin · medium confidence
Refactored MongoDB driver architecture and removed legacy modules
The driver's internal structure has been significantly refactored. Legacy modules including \mongodb\_app\, \mongo\_connect\, \mongo\_cursor\, \mongo\_protocol\, and \mongo\_query\ have been removed. The application metadata is now defined in \mongodb.app.src\, and the application module has been renamed to \mongo\_app\. This change aligns with the broader refactoring of the driver to use \mvar\ and \gen\_server\ for connection and cursor management, replacing the previous \gen\_server\ and \var\-based implementations.
src · high confidence
Refactored header files to support MongoDB 6.0+ wire protocol and modernized type definitions
The \include\ directory now contains three header files that define the internal types and records for the MongoDB Erlang driver. \mongo\_types.hrl\ introduces modernized type aliases (e.g., \cursorid\, \selector\, \projector\) and a comprehensive \arg()\ type for connection options. \mongoc.hrl\ defines the \mc\_server\ and \topology\_state\ records, along with \readmode\ and \readpref\ types, supporting the new topology and connection pooling architecture. \mongo\_protocol.hrl\ is significantly expanded to support the MongoDB 6.0+ wire protocol, adding \op\msg\\*\ records for the new message format, updating existing records like \insert\ and \update\ to use the new type aliases, and adding an \ensure\_index\ record. These changes enable the driver to handle modern MongoDB features and improve type safety.
include · high confidence
Updated MongoDB installation and startup scripts for Debian 12 and MongoDB 6.0+ compatibility
The scripts/install\_mongo\_debian.sh script was added to handle MongoDB installation on Debian systems, specifically adding support for Debian 12 (Bookworm) by switching to Ubuntu 22.04 packages for MongoDB versions 6.0 and 7.0, while maintaining support for older Debian versions using Buster packages. Additionally, new scripts were added to start MongoDB in various configurations: a single node (start\_mongo\_single\_node.sh), a replica set cluster (start\_mongo\_cluster.sh), and an authenticated single node (start\_mongo\_auth.sh). These scripts ensure compatibility with MongoDB 6.0+ by using the 'mongosh' client when available, and configure authentication and replica set initialization for testing purposes.
scripts · medium confidence
Test coverage
Expanded test coverage for authentication, protocol detection, and error handling
Added comprehensive Common Test (CT) suites and EUnit tests to validate MongoDB driver behavior. New tests in \test/auth\_SUITE.erl\ and \test/buildinfo\_auth\_SUITE.erl\ verify authentication flows, including handling of rejected pre-auth buildInfo responses. Tests in \test/protocol\_detection\_SUITE.erl\ and \test/op\_msg\_auth\_source\_SUITE.erl\ confirm automatic and forced protocol selection (op\_msg vs legacy) and correct handling of the \auth\_source\ parameter. Additional suites (\test/error\_handling\_SUITE.erl\, \test/batchsize\_behavior\_SUITE.erl\, \test/bson\_format\_SUITE.erl\, \test/property\_SUITE.erl\) ensure graceful failure on connection errors, correct batch size behavior, BSON document manipulation, and property-based invariants for the API.
test · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 71 → 68 (-3.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 95 → 96 (+1.0)
- Architecture 100 → 90 (-10.4)
- Maturity 65 → 65 (+0.2)
- Readiness 64 → 59 (-5.5)
- Security 80 → 81 (+1.3)
Resolved (8)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
- complexity unreadable for .erl, .hrl — churn × complexity hotspots could not be measured
New (31)
- Coverage not measured — no coverage collector is wired up
- Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)
- Documentation: no architecture or design documentation (README.md)
- Duplicated block (6 lines × 2) (src/connection/mc_worker.erl)
- Floating source dependency: poolboy
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 11 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
comtihon/mongodb-erlang was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b17302e7f4f128cf2113a665a5d300b66829cd5d — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.