[Coverage Report] Test Coverage Report — 2026-06-05 #4350
Replies: 3 comments
|
🔮 The ancient spirits stir, and the smoke test agent has passed through these halls. The omens are favorable. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "registry.npmjs.org"See Network Configuration for more information.
|
|
🔮 The ancient spirits stir: the smoke test agent was here, and the firewall held its watch. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "registry.npmjs.org"See Network Configuration for more information.
|
|
This discussion was automatically closed because it expired on 2026-06-12T00:34:50.271Z.
|
Uh oh!
There was an error while loading. Please reload this page.
Overall Coverage
Test suite: 113 suites, 2,389 tests — 1 failing (flaky DNS test, see below)
🔴 Critical Gaps (< 50% statement coverage)
None — all files exceed 50% statement coverage.
🟡 Low Coverage (50–79% statement coverage)
src/commands/validators/network-options.tsThis file has only one exported function (
validateNetworkOptions). The uncovered statements and branches are the warning-emission paths for:DOCKER_HOSTconfigurationsdindHintflag)These are hard to exercise in unit tests without mocking the Docker environment detection helpers.
🛡️ Security-Critical Path Status
src/host-iptables.tssrc/squid-config.tssrc/docker-manager.tssrc/domain-patterns.tssrc/cli.tssrc/cli.ts's 50% branch coverage is explained by the top-levelif (require.main === module)guard — this branch is never exercised in unit tests (by design), so the metric is expected rather than a real gap.📋 Full Coverage Table
All files (sorted by statement coverage, lowest first)
src/commands/validators/network-options.tssrc/services/agent-volumes/etc-mounts.tssrc/logs/audit-enricher.tssrc/services/agent-volumes/hosts-file.tssrc/artifact-preservation.tssrc/cli.tssrc/logs/log-parser.tssrc/squid/policy-manifest.tssrc/services/agent-volumes/docker-host-staging.tssrc/commands/logs-command-helpers.tssrc/config-writer.tssrc/commands/validators/log-and-limits.tssrc/services/doh-proxy-service.tssrc/services/host-path-prefix.tssrc/services/api-proxy-service.tssrc/services/agent-volumes/docker-socket.tssrc/logs/log-streamer.tssrc/diagnostic-collector.tssrc/commands/validators/agent-options.tssrc/services/agent-environment/environment-builder.tssrc/squid/ssl-bump.tssrc/ssl-bump.tssrc/host-env.tssrc/services/agent-volumes/workspace-mounts.tssrc/logs/log-aggregator.tssrc/upstream-proxy.tssrc/commands/main-action.tssrc/services/cli-proxy-service.tssrc/parsers/volume-parsers.tssrc/container-lifecycle.tssrc/container-cleanup.tssrc/domain-patterns.tssrc/host-iptables-rules.tssrc/host-iptables.tssrc/squid-config.tssrc/docker-manager.ts🔍 Notable Findings
1.
src/logs/log-parser.ts— 67.1% branch coverageThe Squid log parser has many nested conditional branches for parsing IPv6 addresses, port extraction, and handling edge cases in CONNECT tunnel entries. Several uncovered branches are IPv6-specific (
rawDest.startsWith('[')) and timestamp fallback paths (obj.tsnumeric fallback). These cover real production log formats that could silently mis-parse.2.
src/services/agent-volumes/etc-mounts.ts— 67.8% branch coverageThe
/etcbind-mount staging code has uncovered branches for the case wherepasswd/groupfiles don't contain the current UID/GID (fileHasPasswdUid/fileHasGroupGidreturning false). These are security-relevant paths that handle credential isolation for the agent container.3.
src/logs/audit-enricher.ts— 74.1% branch coverage (new file, added last 7 days)The
enrichWithPolicyRulesandcomputeRuleStatsfunctions have uncovered branches for regex-based ACL rules, therule.aclName === 'all'deny case, and theunknownHits > 0summary path. Thetransaction-end-before-headerserror URL skip is also untested.4. Flaky test:
agent-volumes-mounts.test.tsOne test failed:
should pre-resolve allowed domains into chroot-hosts file. The test hardcodes IP addresses forgithub.com(140.82.121.4) that didn't match the DNS response at test time (140.82.116.3). This is a DNS flakiness issue — the test should use a mock DNS resolver rather than doing live resolution.📈 Recommendations
High — Fix flaky DNS test in
src/services/agent-volumes-mounts.test.ts: mockdns.resolve4instead of doing live resolution. The test will fail whenever GitHub's DNS round-robin returns a different IP than the hardcoded value.High — Add IPv6 log-parsing tests to
src/logs/log-parser.ts: add test cases with IPv6 destination addresses (e.g.[2606:4700::1]:443) and numerictstimestamp fallback paths. These cover real Squid production log output.Medium — Add tests for
src/logs/audit-enricher.tsedge cases: regex ACL rules, theaclName === 'all'deny path, and thetransaction-end-before-headersskip. This file was added in the last 7 days.Low — Cover
src/services/agent-volumes/etc-mounts.tsUID/GID mismatch branches: test the case where the stagedpasswd/groupfile doesn't contain the current user's UID/GID entry (security-relevant isolation path).Generated by test-coverage-reporter workflow. Trigger:
push. Run ID: 26987734842All reactions