You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Failure reason: Expected service name mismatch in orchestrator test (non-critical)
6,632 tests passed, 7 skipped
No security-critical test failures
🔎 Notable Findings
High-risk artifact: bounded-execution/ subsystem is critically under-tested (avg 58% stmts, 45% branches). This path is foundational for resource-limit validation and disclosure filtering — essential for security gates preventing unbounded output leaks.
Registry cleanup gap: nvx/cleanup-registry.ts (42.8% stmts) handles artifact lifecycle in cloud-hypervisor backend. Undertesting this increases risk of resource exhaustion or stale artifact leaks.
API proxy sidecar integration incomplete: src/services/api-proxy-env-config.test.ts failing due to orchestrator test setup — suggests API proxy credential injection path may need hardening.
Network isolation partially validated: src/host-iptables.ts and src/squid-config.ts are 100% covered, but routing layer (routing/bootstrap.ts 68.27% branch) has low conditional coverage — some network initialization paths untested.
🎯 Recommendations
HIGH Priority — Fix within 1–2 sprints:
Increase bounded-execution/finite-schema.ts branch coverage to ≥80% — Add test cases for:
All schema validation edge cases (empty, nested, circular refs)
Boundary conditions (max cardinality, max disclosure depth)
Error handling paths (malformed input, type mismatches)
Expected outcome: Ensure resource limits and disclosure gates cannot be bypassed
Audit and test nvx/cleanup-registry.ts artifact lifecycle — Add integration tests for:
Expected outcome: Better CLI test harness for future developers
Summary: 91.29% overall statement coverage is healthy, but bounded-execution and nvx subsystems are critical gaps that require dedicated test hardening sprints. The security-critical core (iptables, squid, domain validation) is excellently tested at 100%.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-10-02
Overall Coverage Metrics (全项目)
Test Status: 413 passed, 1 failed, 414 total test suites | 6632 passed, 7 skipped, 6640 total tests
🛡️ Security-Critical Path Status
The following security-critical modules have EXCELLENT coverage:
📋 Coverage Table — Top Modules
🚨 CRITICAL Coverage Gaps
Three modules fall below 50% statement coverage and require immediate attention:
🔧 Remaining Module Audit
Strong Coverage (≥95%):
src/diagnostics.ts(98.85% stmts, 98.11% branch)src/topology.ts(98.95% stmts, 94.87% branch)src/domain-sanitizer.ts(97.14% stmts, 93.33% branch)src/cloud-hypervisor/setup-identity.ts(98.48% stmts, 97.72% branch)src/cloud-hypervisor/setup-process.ts(94.68% stmts, 89.83% branch)Coverage Gaps (70–80%):
src/routing/bootstrap.ts(79.8% stmts, 68.27% branch) — routing initialization undertestedsrc/cloud-hypervisor/vmm-identity.ts(75.86% stmts, 70.76% branch) — VM identity setup missing test casessrc/cloud-hypervisor/artifact-verifier.ts(82.45% stmts, 66.05% branch) — artifact verification logic has low branch coveragesrc/cloud-hypervisor/manager-start.ts(80.83% stmts, 65% branch) — microVM manager startup path barely half-covered on branchesConcerning Patterns:
bounded-execution/directory average: 58.27% stmts, 45.29% branch — entire subsystem is undertested📅 Test Status Summary
src/services/api-proxy-env-config.test.ts🔎 Notable Findings
High-risk artifact:
bounded-execution/subsystem is critically under-tested (avg 58% stmts, 45% branches). This path is foundational for resource-limit validation and disclosure filtering — essential for security gates preventing unbounded output leaks.Registry cleanup gap:
nvx/cleanup-registry.ts(42.8% stmts) handles artifact lifecycle in cloud-hypervisor backend. Undertesting this increases risk of resource exhaustion or stale artifact leaks.API proxy sidecar integration incomplete:
src/services/api-proxy-env-config.test.tsfailing due to orchestrator test setup — suggests API proxy credential injection path may need hardening.Network isolation partially validated:
src/host-iptables.tsandsrc/squid-config.tsare 100% covered, but routing layer (routing/bootstrap.ts68.27% branch) has low conditional coverage — some network initialization paths untested.🎯 Recommendations
HIGH Priority — Fix within 1–2 sprints:
Increase
bounded-execution/finite-schema.tsbranch coverage to ≥80% — Add test cases for:Audit and test
nvx/cleanup-registry.tsartifact lifecycle — Add integration tests for:MEDIUM Priority — Address within 1–2 months:
3. Close
finite-disclosure.tsbranch coverage gap (11.42% → ≥75%):routing/bootstrap.ts(68.27% branch):LOW Priority — Backlog:
5. Reduce
cli.tsbranch coverage gap (50% → ≥85%):Summary: 91.29% overall statement coverage is healthy, but bounded-execution and nvx subsystems are critical gaps that require dedicated test hardening sprints. The security-critical core (iptables, squid, domain validation) is excellently tested at 100%.
All reactions