[Coverage Report] Test Coverage Report — 2026-09-25 #9020
Closed
Replies: 2 comments
|
🔮 The ancient spirits stir, and the smoke-test agent has passed this way. The oracle records a successful GitHub read, file check, and build rite; the browser omen remained veiled. Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "msfeed25.pkgs.visualstudio.com"See Network Configuration for more information.
|
0 replies
|
This discussion was automatically closed because it expired on 2026-10-02T22:01:49.700Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-09-25
Overall Coverage
The project maintains strong baseline test coverage across the codebase:
Summary: With 91.12% statement coverage and 89.17% function coverage, the codebase demonstrates mature test maturity. However, branch coverage at 84.2% indicates some untested conditional logic paths that warrant review for security-critical modules.
🛡️ Security-Critical Path Status
The following files are particularly important for network isolation, domain filtering, and container orchestration:
src/host-iptables.tssrc/squid-config.tssrc/domain-patterns.tssrc/docker-manager.tssrc/cli.tsKey Finding:
src/cli.tshas only 50% branch coverage despite 85.71% statement coverage, indicating missing tests for error paths and conditional branches in the main entry point.📋 Coverage Table
Critical Coverage Gaps (< 55% statement coverage):
src/nvx/cleanup-registry.tssrc/bounded-execution/finite-cardinality.tssrc/bounded-execution/finite-schema.tssrc/microvm/network-reservation.tssrc/bounded-execution/finite-disclosure.ts🔧 Function Audit
Key Observations:
NVX Registry Cleanup (
cleanup-registry.ts): 42.8% statement coverage with 32% branch coverage. This module handles registry cleanup and garbage collection—critical for preventing resource leaks in the container ecosystem.Bounded Execution Modules: Three modules in the
bounded-execution/family all fall below 50% statement coverage:finite-schema.ts(49.31%): Validates schema constraintsfinite-cardinality.ts(46.03%): Enforces cardinality limitsfinite-disclosure.ts(51.78% statements but only 11.42% branches): Data disclosure preventionMicroVM Network Reservation (51.08%): Handles network resource allocation for microVM backends. Branch coverage of 55% is slightly better but still below ideal.
Primary Entry Point (
cli.ts): Only 1 of 2 branches tested (50%). While statement coverage is 85.71%, missing branch tests suggest error handling paths are not validated.📅 Recent Source Changes (last 7 days)
Coverage analysis is based on the pre-computed test suite results as of 2026-09-25 21:56 UTC.
🔎 Notable Findings
Branch Coverage Gap in Entry Point: The CLI entry point (
src/cli.ts) has a 35-point gap between statement coverage (85.71%) and branch coverage (50%), indicating that conditional paths—particularly error handling—are not tested.Bounded-Execution Framework Undercover: Five files in the
bounded-execution/andnvx/namespaces show severe coverage gaps (< 55%). These modules enforce resource limits and prevent data disclosure, making them security-sensitive.Domain Filtering Solid: Core security-critical files like
src/domain-patterns.tsandsrc/docker-manager.tsmaintain 100% statement coverage, demonstrating good testing discipline for the primary firewall logic.Branch Coverage Variance: Overall branch coverage (84.2%) is 7 percentage points lower than statement coverage (91.12%), suggesting many files have untested conditional paths even where statements are covered.
🎯 Recommendations
cli.tserror paths and branches. Target: branch coverage ≥ 85%src/cli.tsfinite-schema.tsandfinite-cardinality.ts. Focus on constraint validation edge cases. Target: ≥ 70% statement coveragesrc/bounded-execution/finite-*.tscleanup-registry.ts. Target: ≥ 70% statement coveragesrc/nvx/cleanup-registry.tsdomain-patterns.tsto close 10.53% gapsrc/domain-patterns.tsmicrovm/network-reservation.tsbranch paths and add missing test casessrc/microvm/network-reservation.tsAll reactions