[Coverage Report] Test Coverage Report — 2026-09-25 #8996
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-10-02T04:58:46.219Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-09-25
Overall Coverage
The project maintains strong test coverage across the codebase:
Overall Assessment: The project achieves 90%+ coverage on statements and lines, indicating comprehensive test coverage.
🛡️ Security-Critical Path Status
Core security-critical files maintain excellent coverage:
src/squid-config.tssrc/docker-manager.tssrc/domain-patterns.tssrc/cli.tsFinding: The primary firewall and network isolation logic is well-tested. Domain validation and CLI orchestration logic have solid coverage.
📋 Coverage Table
Directory-Level Coverage
src/src/bounded-execution/src/cloud-hypervisor/src/commands/src/config/src/enclave/src/logs/src/microvm/src/nvx/src/parsers/src/routing/src/services/🔧 Function Audit
🟡 MEDIUM CONCERNS (50–79% Coverage)
📅 Recent Source Changes (last 7 days)
Unable to retrieve recent commit history due to system constraints. Last coverage measurement taken on 2026-09-25 at 04:53 UTC.
🔎 Notable Findings
Bounded-Execution Module Systematically Under-tested: All three files (
finite-schema.ts,finite-cardinality.ts,finite-disclosure.ts) show <50% statement coverage. These modules implement critical cardinality bounds and disclosure controls for agent confinement, and they deserve dedicated test expansion.NVX Cleanup Registry Missing Error Path Coverage:
src/nvx/cleanup-registry.tsat 42.8% statements suggests cleanup error handling, rollback scenarios, and edge cases in executor state removal are largely untested.Finite-Disclosure Branch Coverage Critically Low: At 11.42%, this indicates the disclosure-limiting conditional logic is almost entirely untested. Given the security sensitivity of info disclosure in agent sandboxing, this is a priority gap.
Core Firewall & CLI: Excellent Coverage: The primary egress filtering (
squid-config.ts,domain-patterns.ts) and orchestration (cli.ts,docker-manager.ts) achieve 100% or near-100% coverage, validating the main security-critical paths.🎯 Recommendations
🔴 HIGH PRIORITY
Expand
src/bounded-execution/test suite (~3–5 new test files recommended)Add error and recovery path tests for
src/nvx/cleanup-registry.ts🟡 MEDIUM PRIORITY
Improve
src/microvm/network-reservation.tstest coverage to 75%+Strengthen routing module tests (
src/routing/) to 85%+⚪ LOW PRIORITY
Summary: Firewall security paths are well-protected; focus expansion efforts on bounded-execution isolation logic and NVX cleanup resilience. Aiming for 85%+ branch coverage across critical modules within the next sprint.
All reactions