[Coverage Report] Test Coverage Report — 2026-09-25 #9009
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-10-02T15:51:42.958Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-09-25
Overall Coverage
Summary: The codebase maintains strong test coverage above the 80% threshold across most metrics, with all categories exceeding baseline standards. Branch coverage (84.22%) represents the lowest metric, indicating some complex conditional logic remains untested.
🛡️ Security-Critical Path Status
Three security-critical components show CRITICAL coverage gaps:
src/nvx/cleanup-registry.tssrc/bounded-execution/finite-cardinality.tssrc/bounded-execution/finite-schema.tsThese files are responsible for:
All three files have statement coverage below 50% and branch coverage below 45%, indicating many code paths remain untested.
📋 Coverage Table — Low Coverage Files (<70%)
🔧 Function Audit
Functions with 0% coverage or stub-only implementation:
src/nvx/index.tssrc/nvx/cleanup-registry.tssrc/nvx/confinement.tssrc/bounded-execution/finite-schema.tssrc/microvm/rootfs.tsHigh-coverage success examples:
src/microvm/guest-protocol.ts: 100% coverage (security-critical IPC protocol)src/microvm/infrastructure.ts: 100% coverage (network and resource setup)src/nvx/runtime-validation.ts: 98.78% coverage (runtime constraint validation)src/nvx/filesystem-write-policy.ts: 96.84% coverage (write permission enforcement)📅 Recent Source Changes (last 7 days)
Recent commits affecting major source areas:
Impact on coverage: Recent NVX microVM backend changes (commit #8983) likely increased complexity in
src/nvx/*.tsandsrc/microvm/*.tsfiles. Task-level routing (#8985) may have introduced new code paths in bounded execution modules.🔎 Notable Findings
Branch coverage debt concentrated in 3 files: The critical 42.8%, 46.03%, and 49.31% statement-level coverage files all show severe branch coverage gaps (32%, 35%, 42% respectively). These are complex control-flow modules that require comprehensive branch testing.
Bounded execution module is partially tested:
finite-disclosure.tshas only 11.42% branch coverage despite 51.78% statement coverage, suggesting its conditional logic is largely unexercised. This module is critical for resource disclosure control.NVX artifact registry cleanup is largely untested:
cleanup-registry.tshas only 100/242 lines covered, affecting 59 functions. This cleanup logic is essential for preventing resource leaks in artifact staging and microVM lifecycle management.High-quality security modules exist as reference: Modules like
runtime-validation.ts(98.78%),filesystem-write-policy.ts(96.84%), andguest-protocol.ts(100%) demonstrate that robust test coverage is achievable and should serve as benchmarks for missing test coverage in sister modules.🎯 Recommendations
🔴 HIGH — Stabilize Security-Critical Path
Priority: Immediate (Sprint Current)
Action: Expand test suite for
src/nvx/cleanup-registry.tsto reach 80%+ statement and branch coverageAction: Add comprehensive branch tests for
src/bounded-execution/finite-disclosure.ts(currently 11.42% branch coverage)🟠 MEDIUM — Close Known Coverage Gaps
Priority: Next Sprint
Action: Improve
src/bounded-execution/finite-cardinality.tsandfinite-schema.tsto 70%+ coverageAction: Increase
src/microvm/network-reservation.tsbranch coverage from 55% to 75%+🟡 LOW — Establish Test Quality Baseline
Priority: Backlog (Future Sprints)
Action: Document test coverage strategy and minimum thresholds (recommend: 80% statements, 75% branches)
Action: Use
src/microvm/guest-protocol.ts(100%) as reference implementation for writing new testsNext Review: Post-implementation of HIGH-priority fixes. Target coverage after remediation: 85%+ statements, 78%+ branches across all critical files.
All reactions