[Coverage Report] Test Coverage Report — 2026-06-05 #4351
Replies: 5 comments
|
🔮 The ancient spirits stir, and the smoke test has crossed the threshold. A brief omen: the agent walked here, the run is in motion, and the firewall watches. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "registry.npmjs.org"See Network Configuration for more information.
|
|
🔮 The ancient spirits stir; the smoke test agent has passed through the GitHub veil and left this oracle-mark upon the discussion. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "registry.npmjs.org"See Network Configuration for more information.
|
|
🔮 The ancient spirits stir; the smoke test agent was here, and the omens are favorable. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "registry.npmjs.org"See Network Configuration for more information.
|
|
🔮 The ancient spirits stir; the smoke test agent was here, and the GitHub winds carried its footprint. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "registry.npmjs.org"See Network Configuration for more information.
|
|
This discussion was automatically closed because it expired on 2026-06-12T02:50:27.342Z.
|
Uh oh!
There was an error while loading. Please reload this page.
📊 Overall Coverage
100 test files · 151 source files · All thresholds passing ✅
🔴 Critical Gaps (< 50% statement coverage)
None. All 133 covered source files are above 50% statement coverage.
🟡 Low Coverage (50–79% statement coverage)
src/commands/validators/network-options.tsOne file in this range. The uncovered statements are in the warning-log branches for external Docker host detection (the
!dockerHostCheck.validanddindHintpaths that emitlogger.warncalls). All function-level entry points are exercised.🛡️ Security-Critical Path Status
src/host-iptables.ts(entry)src/host-iptables-rules.tssrc/host-iptables-shared.tssrc/host-iptables-cleanup.tssrc/squid-config.ts(entry)src/squid/config-generator.tssrc/squid/access-rules.tssrc/squid/domain-acl.tssrc/squid/policy-manifest.tssrc/docker-manager.tssrc/domain-patterns.tssrc/cli.tsAll primary security modules (
host-iptables,squid-config,docker-manager) are at or near 100%. No security-critical file has branch coverage below 70%.📋 Coverage Table (files not at 100%)
src/commands/validators/network-options.tssrc/services/agent-volumes/etc-mounts.tssrc/logs/audit-enricher.tssrc/artifact-preservation.tssrc/cli.tssrc/logs/log-parser.tssrc/squid/policy-manifest.tssrc/services/agent-volumes/docker-host-staging.tssrc/commands/logs-command-helpers.tssrc/commands/validators/log-and-limits.tssrc/services/doh-proxy-service.tssrc/services/host-path-prefix.tssrc/config-writer.tssrc/services/api-proxy-service.tssrc/services/agent-volumes/docker-socket.tssrc/logs/log-streamer.tssrc/diagnostic-collector.tssrc/commands/validators/agent-options.tssrc/services/agent-volumes/hosts-file.tssrc/services/agent-environment/environment-builder.tssrc/squid/ssl-bump.tssrc/ssl-bump.tssrc/host-env.tssrc/logs/log-aggregator.tssrc/upstream-proxy.tssrc/commands/main-action.tssrc/services/cli-proxy-service.tssrc/parsers/volume-parsers.tssrc/container-lifecycle.tssrc/services/agent-volumes/workspace-mounts.tssrc/container-cleanup.tssrc/services/agent-environment/env-passthrough.tssrc/commands/validators/config-assembly.tssrc/compose-sanitizer.tssrc/logs/log-formatter.tssrc/domain-patterns.tssrc/services/agent-service.tssrc/services/agent-volumes/home-strategy.tssrc/config-file.tssrc/rules.tssrc/compose-generator.tssrc/pid-tracker.tssrc/option-parsers.ts88 additional files are at 100% across all metrics.
🔍 Notable Findings
1.
src/logs/log-parser.ts— branch coverage 67.14% (47/70 branches)The log parser has a dense set of conditional branches for handling Squid log format variants (malformed lines, missing fields, timestamp edge cases). The uncovered ~23 branches likely correspond to error-recovery paths for unexpected log formats. Adding tests with malformed/truncated Squid access log lines would close this gap efficiently.
2.
src/squid/policy-manifest.ts— 3 uncovered functions (70% fn coverage)Three functions in the policy manifest module have zero coverage. These are likely helper/utility functions that support
generatePolicyManifest(). Given this file contributes to domain ACL decisions, covering these functions directly improves confidence in filtering correctness.3.
src/services/agent-volumes/etc-mounts.ts— branch coverage 67.85% (19/28 branches)This file controls which
/etcfiles are bind-mounted into the agent container (credential isolation). Uncovered branches are likely guard conditions around platform-specific paths and optional mounts. Missing test scenarios: bind mount path normalization when source paths don't exist, and the fallback paths when/etc/alternativesor/etc/ld.so.cacheare absent on the host.4.
src/services/agent-environment/environment-builder.ts— branch coverage 66.66% (4/6 branches)Only 4 of 6 branches covered in the environment variable assembly layer. The two uncovered branches likely represent edge cases in credential-stripping or API key injection when optional services (API proxy, DLP) are disabled. These are security-sensitive paths — credential leakage in the agent environment is a high-severity concern.
📈 Recommendations
High —
environment-builder.tsbranch gaps: Add tests for the 2 uncovered branches in the environment assembly path. These control whether sensitive variables (API keys, tokens) are included or stripped — the uncovered branches may represent conditions where credentials could unexpectedly leak into the agent.High —
etc-mounts.tsbranch coverage: Cover the missing/etcbind-mount guard branches. These govern credential isolation (preventing/etc/shadowand other sensitive files from reaching the agent). Specifically, add tests formissing host path → skip mountandpath normalization with DinD prefixscenarios.Medium —
policy-manifest.tsuncovered functions: Cover the 3 uncovered functions in the Squid policy manifest module to ensure all domain ACL generation paths are exercised. Uncovered ACL logic could silently allow or block domains in edge-case configurations.Low —
network-options.tsbranch coverage: Add tests for the external Docker host warning paths (!dockerHostCheck.validanddindHintconditions) to bring this validator to full coverage. Low risk, but improves diagnostics for ARC/DinD users.Generated by test-coverage-reporter workflow. Trigger:
push· Commit:843012dAll reactions