[Coverage Report] Test Coverage Report — 2026-09-25 #9013
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-10-02T21:09:44.431Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-09-25
Overall Coverage
Status: ✅ Overall coverage remains strong at 91-93% across key metrics. Branch coverage is the lowest metric at 84.23%, indicating edge cases and conditional logic paths need additional testing.
🛡️ Security-Critical Path Status
Security-critical modules show excellent coverage:
host-iptables.tsdomain-patterns.tssquid-config.tsdocker-manager.tshost-iptables-rules.tshost-iptables-shared.ts✅ Core security paths are fully covered. Network isolation (iptables), domain filtering (squid-config), and container orchestration (docker-manager) all meet 100% line coverage.
📋 Coverage Table
Lowest 25 Files by Line Coverage (excluding test utilities):
nvx/cleanup-registry.tsbounded-execution/finite-cardinality.tsbounded-execution/finite-schema.tsmicrovm/network-reservation.tsbounded-execution/finite-disclosure.tsmicrovm/rootfs.tsenclave/runtime-preflight.tsnvx/preflight.tsnvx/manager.tscommands/build-config.tsnvx/one-shot-adapter.tscloud-hypervisor/virtiofsd.tsnvx/cleanup-store.tsenclave/github-gateway.tsnvx/cleanup-record.ts🔧 Function Audit
Function Coverage Gaps (functions < 80% coverage):
nvx/cleanup-registry.tscloud-hypervisor/launcher.tsnvx/index.tsnvx/manager.tsbounded-execution/finite-disclosure.tsnvx/runtime-backend.tscloud-hypervisor/preflight.tsnvx/preflight.ts📅 Recent Source Changes (last 7 days)
Based on git history:
src/nvx/(multiple files related to NVX KVM testing)Key observation: Recent NVX smoke test fixes suggest testing infrastructure changes but coverage gaps in
nvx/cleanup-registry.ts(41%) andnvx/preflight.ts(72%) indicate incomplete test harness coverage.🔎 Notable Findings
🔴 NVX Cleanup Registry (41% coverage): The
nvx/cleanup-registry.tsmodule—responsible for cleaning up NVX microVM artifacts—has the lowest coverage in the codebase. This is critical for resource cleanup and could lead to orphaned resources if paths aren't tested.🔴 Bounded Execution Schema Validation (49-53% coverage): The
bounded-execution/finite-*.tsmodules (cardinality, schema, disclosure) have 50% coverage with extremely low branch coverage (11-42%). These enforce constraints on agent output and error disclosure—security-critical functions that need comprehensive testing.✅ Security Core is Solid: All primary security modules (
host-iptables-*,squid-config,domain-patterns) maintain 100% line coverage and 89-100% branch coverage, indicating strong test discipline for network/filtering layers.🟡 Branch Coverage Lag: While line coverage is 92.64%, branch coverage is only 84.23%—an 8.4 percentage point gap. This suggests many conditional/error paths are not exercised by tests, particularly in NVX and bounded-execution modules.
🎯 Recommendations
HIGH PRIORITY
Fix
nvx/cleanup-registry.ts(41% → 80%+)Improve
bounded-execution/finite-schema.ts(52.84% → 80%+)MEDIUM PRIORITY
LOW PRIORITY
📌 Next Steps
nvx/cleanup-registry.ts,bounded-execution/finite-schema.ts)Report Generated: 2026-09-25 21:07:37 UTC
Coverage Suite: Jest with istanbul coverage reporter
Thresholds: Lines ≥92%, Branches ≥84% (current baselines)
All reactions