# Behavioral coverage The shared contract is `harness/contract.go`, with 66 reviewed Django captures in `fixtures/contract/`. Every case checks HTTP status, relevant headers, body, all five application tables, and their identity sequences. Each case starts from the same small fixture. Admin is deliberately excluded. | Endpoint | Covered behavior | | --- | --- | | GET posts | Published filtering, date order, equal-date ties, nested authors/tags | | GET search | Case folding, empty/no-match queries, literal `%` and `_`, Unicode, missing/repeated argument | | GET by-tag | Matching posts, empty tag, missing tag, unpublished filtering | | GET detail | Nested comments/authors/tags, draft visibility, saved counter/timestamp, missing/invalid/negative/plus/decimal/underscored IDs | | GET user | Counts, missing/invalid/overflow IDs | | GET find | Exact email match, case sensitivity, missing argument, duplicate-email 500 | | POST post | Defaults, empty text, Unicode, ignored extra fields, integer coercions, duplicates, missing author, partial failure, overlong title, required/null/wrong types | | POST comment | Success, draft, missing author/post/both, required fields, invalid path | | Request handling | DELETE/HEAD/OPTIONS, scalar/array/string bodies, malformed JSON and Unicode error offsets | Full-data verification adds all six read endpoints over 100,000 posts and 500,000 comments. It compares normalized complete response hashes and starting table fingerprints, not a prefix of each response. See `full-equivalence.json`. Normalization preserves contents and duplicates. Tags may reorder; only equal-date groups may reorder in chronological collections. Generated clocks must fall inside the request window. Sequence values, persisted partial writes, and stable error text are not erased. Tests for the normalizer reject changed contents and broken ordering. ## Limits This is characterization of a finite set of observations, not proof for every malformed input or concurrent interleaving. The preserved counter race is documented in `known-bugs.md`; concurrent tests must not demand a particular lost-update count. OpenAPI/docs assets are retained, but browser rendering is not part of these 66 cases. Python line/branch coverage and Go statement coverage are separate diagnostics. Their percentages are not directly comparable. Neither includes Django admin.