[Coverage Report] Test Coverage Report — 2026-09-25 #8994
Replies: 3 comments
|
🔮 The ancient spirits stir, and the oracle records a favorable omen. The smoke-test agent passed through this chamber, and the signs resolve to PASS. Warning Firewall blocked 12 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
|
🔮 The ancient spirits stir, and the smoke-test agent has passed through this hall. The omens are recorded; the oracle departs. Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "msfeed25.pkgs.visualstudio.com"See Network Configuration for more information.
|
|
This discussion was automatically closed because it expired on 2026-10-02T04:32:59.337Z.
|
Uh oh!
There was an error while loading. Please reload this page.
📊 Overall Coverage
Statements: 91.32% (17,034 / 18,652)
Branches: 84.56% (9,834 / 11,629)
Functions: 89.78% (2,567 / 2,859)
Lines: 92.78% (16,218 / 17,480)
Assessment: Strong overall coverage with branch coverage slightly below the 85% threshold. All security-critical domain filtering and iptables modules report 100% coverage.
🛡️ Security-Critical Path Status
src/host-iptables.tssrc/squid-config.tssrc/docker-manager.tssrc/domain-patterns.tssrc/domain-matchers.tssrc/host-iptables-rules.tssrc/host-iptables-shared.tssrc/cli.tsVerdict: Core security infrastructure (domain ACLs, iptables, proxy config) is fully tested. CLI main entry point has gaps.
📋 Coverage Table — Low-Coverage Files (<80%)
src/nvx/cleanup-registry.tssrc/bounded-execution/finite-cardinality.tssrc/bounded-execution/finite-schema.tssrc/microvm/network-reservation.tssrc/microvm/rootfs.tssrc/nvx/cleanup-store.tssrc/nvx/preflight.tssrc/microvm/workspace.tssrc/config-writer.tssrc/artifact-permissions.tssrc/artifact-preservation.tssrc/cli.tsNote: The "bounded-execution" modules (finite-cardinality, finite-schema) appear to be new or incomplete additions—they show 0 function coverage, suggesting they may not have been exercised by the test suite at all.
🔧 Function Audit
Untested/Undertested Functions
src/nvx/index.ts— 4.16% function coverage (48 total, 2 tested)src/cloud-hypervisor-runtime-backend.ts— 50% function coverage (6 total, 3 tested)src/nvx/manager.ts— 61.11% function coverage (36 total, 22 tested)src/nvx/launch-executor.ts— 79.24% function coverage (53 total, 42 tested)src/container-cleanup.ts— 80% function coverage (5 total, 4 tested)🔎 Notable Findings
📦 Bounded Execution Modules Are Untested
Three new modules (
finite-cardinality.ts,finite-schema.ts,finite-disclosure.ts) show <50% statement coverage and 0 direct function coverage. These appear to be recent additions for cardinality/disclosure enforcement and require comprehensive test coverage before production use.🔌 NVX (Enclave) Subsystem Has Significant Gaps
The
src/nvx/cleanup-registry.tsmodule (278 statements) is only 42.8% tested. Registry cleanup—critical for preventing resource leaks in repeated enclave runs—is poorly covered. Files likenvx/runtime-lifecycle.ts(79.81% statements, 64.7% branches) also show branch coverage gaps suggesting error path testing is inadequate.🛡️ CLI Entry Point Partially Untested
src/cli.tsshows 50% branch coverage despite 100% line/statement coverage. This typically indicates one conditional path (e.g., error handling, optional argument) is never executed in tests. The main entry point should have 100% branch coverage for reliability.✅ HTTP/HTTPS Filtering & Iptables Are Bulletproof
All host-iptables modules and Squid config generators show 100% coverage across statements, branches, and functions. Domain ACL enforcement, port blocking, and proxy redirection are thoroughly tested.
🎯 Recommendations
🔴 HIGH PRIORITY — Add tests for bounded-execution modules
src/bounded-execution/finite-cardinality.ts,src/bounded-execution/finite-schema.ts,src/bounded-execution/finite-disclosure.tsbounded-execution.test.ts) covering initialization, normal flow, edge cases, and error conditions. Target ≥90% statement and ≥85% branch coverage.🟠 HIGH PRIORITY — Improve NVX cleanup-registry coverage
src/nvx/cleanup-registry.ts(currently 42.8% statements)nvx.test.tsor createnvx-cleanup-registry.test.tswith scenarios: successful cleanup, missing registries, cleanup retries, concurrent cleanup, error recovery.🟡 MEDIUM PRIORITY — Complete CLI entry point error path coverage
src/cli.ts(50% branch coverage)Summary
Overall test coverage is strong (91.32% statements), with zero gaps in security-critical components (iptables, Squid ACLs, domain filtering). However, three critical areas need attention:
bounded-execution/) lack any meaningful test coveragenvx/) has inconsistent branch coverage, particularly in cleanup/resource managementAddressing these three areas will bring the codebase to production-ready standards and eliminate branches with low confidence.
All reactions