[Coverage Report] Test Coverage Report — 2026-09-25 #9024
Replies: 3 comments
Oracle Trace🔮 The ancient spirits stir: the smoke test agent walked this path, found the signs favorable, and left the run in balance. Warning Firewall blocked 13 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "android.clients.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
|
🔮 The ancient spirits stir: this smoke-test agent passed through these halls. The omens favor GitHub reads, file I/O, and local build; only the browser vision remained veiled. Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "msfeed25.pkgs.visualstudio.com"See Network Configuration for more information.
|
|
This discussion was automatically closed because it expired on 2026-10-02T22:43:18.035Z.
|
Uh oh!
There was an error while loading. Please reload this page.
Overall Coverage
The codebase demonstrates strong overall test coverage with 92–93% line coverage across 18,283 lines of source code. However, branch coverage at 84.2% indicates significant gaps in conditional path testing, particularly in error handling and edge cases.
🛡️ Security-Critical Path Status
host-iptables*.ts(6 files)docker-manager.tsdomain-patterns.tscli.tsCritical Finding:
src/cli.tshas only 50% branch coverage (1 of 2 branches), indicating that error or exit paths in the main entry point are not tested.📋 Coverage Table — Top Gaps
src/nvx/cleanup-registry.tssrc/bounded-execution/finite-cardinality.tssrc/bounded-execution/finite-schema.tssrc/cli.tssrc/microvm/network-reservation.tssrc/bounded-execution/finite-disclosure.ts🔧 Function Audit
Positive Coverage (100% or near):
host-iptables-*.tsfiles: network isolation fully testeddocker-manager.ts: container lifecycle management end-to-enddomain-utils.ts,domain-validation.ts: domain whitelisting logiccontainer-lifecycle.ts,container-startup-diagnostics.ts: lifecycle hooksdind-bootstrap.ts,dind-probe.ts: Docker-in-Docker detectiongithub-env.ts,host-identity.ts: host environment introspectionCoverage Gaps:
src/nvx/cleanup-registry.ts): Only 42.8% lines, 32.1% branches — cleanup routines lack branch coveragesrc/microvm/network-reservation.ts): 51% lines — error paths missingsrc/cli.ts): 50% branches — one branch entirely untested (likely error/exit path)📅 Recent Source Changes (last 7 days)
The presence of new low-coverage files (
src/nvx/,src/bounded-execution/,src/microvm/) suggests recent feature additions for:These features were likely added recently without comprehensive test coverage.
🔎 Notable Findings
NVX Feature Incompletely Tested: Three new enclave coordination files (
nvx/cleanup-registry.ts,bounded-execution/finite-*.ts) are barely covered (32–49%). These appear to be new security features added within the last release cycle. Immediate testing needed for cleanup correctness and constraint enforcement.CLI Entry Point Exposure:
src/cli.tsshows 50% branch coverage, meaning one critical code path (likely error or signal handling) is untested. Given the firewall's security role, CLI robustness is essential.Branch Coverage Gap: While line coverage is strong (92.6%), branch coverage lags at 84.2%, indicating that many conditional statements lack edge-case testing. Error paths, retry logic, and fallback handling are commonly overlooked.
Strong Security Foundations: Host iptables rules and container management have perfect (100%) coverage, indicating the core network isolation and lifecycle logic are well-tested.
🎯 Recommendations
Priority 1: CRITICAL — CLI Entry Point (HIGH urgency)
src/cli.tsto reach ≥95% branch coveragePriority 2: CRITICAL — NVX Feature Coverage (HIGH urgency)
src/nvx/cleanup-registry.ts,src/bounded-execution/finite-*.tsto ≥80% lines and branchesPriority 3: MEDIUM — Branch Coverage Expansion
src/microvm/network-reservation.ts,src/bounded-execution/finite-disclosure.tsReport Generated: 2026-09-25 22:40 UTC
Coverage Report Base:
coverage/coverage-summary.jsonTest Framework: Jest with Istanbul instrumentation
Baseline: All security-critical iptables and container management paths verified at 100% coverage ✅
All reactions