You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Overall test coverage is strong across all metrics, with statements and line coverage both exceeding 90%. Branch coverage at 83.54% indicates good decision-path testing, though some edge cases remain uncovered.
🛡️ Security-Critical Path Status
Five files with CRITICAL coverage gaps requiring immediate attention:
File
Statements
Branches
Status
src/nvx/cleanup-registry.ts
42.80%
32.11%
🔴 CRITICAL
src/bounded-execution/finite-cardinality.ts
46.03%
35.29%
🔴 CRITICAL
src/bounded-execution/finite-schema.ts
49.77%
43.11%
🔴 CRITICAL
src/microvm/network-reservation.ts
51.50%
54.86%
🟡 LOW
src/cloud-hypervisor/host-enclave-executor.ts
51.67%
34.48%
🟡 LOW
Primary Concern: The three files in src/nvx/ and src/bounded-execution/ represent critical infrastructure for network isolation and resource bounding in microVM and enclave execution. Coverage gaps here directly impact security guarantees.
📋 Coverage Table
Top-Performing Files (Security-critical paths):
src/host-iptables.ts: High coverage for iptables rule generation
src/squid-config.ts: Strong coverage for domain ACL filtering
src/docker-manager.ts: Comprehensive coverage for container lifecycle management
Network reservation and microVM lifecycle (src/microvm/)
These represent newer infrastructure features added for unified enclaves and Cloud Hypervisor support, suggesting incomplete test harness buildout for these subsystems.
📅 Recent Source Changes (last 7 days)
Recent changes focused on:
Enclave infrastructure hardening and MCP gateway integration
Bounded execution framework for resource isolation
Cloud Hypervisor microVM backend refinement
Network reservation and cleanup registry improvements
Several of the low-coverage files were modified recently to support:
Dynamic repository delegation for enclaves
Resource limits for sandbox isolation
Multi-VM coordination
🔎 Notable Findings
Core firewall security modules remain well-tested: Host iptables rules, Squid configuration, and domain pattern matching all have strong coverage, protecting the primary security boundary.
Enclave/microVM subsystem is undertested: The three CRITICAL gaps in src/nvx/, src/bounded-execution/, and related files indicate that newer infrastructure for private repository enclaves and Cloud Hypervisor support needs significantly more test coverage before production hardening.
Branch coverage gap: While statements are at 90.54%, branches lag at 83.54%, indicating edge cases and error handling paths are less thoroughly tested. This is especially concerning in security-critical code.
Potential resource exhaustion risk: The src/bounded-execution/finite-*.ts files handle cardinality and schema validation for resource limits—undertested paths here could allow resource exhaustion attacks or bypass sandbox limits.
🎯 Recommendations
HIGH PRIORITY 🔴
Expand enclave subsystem tests — Focus on src/nvx/cleanup-registry.ts (42.80%), src/bounded-execution/finite-cardinality.ts (46.03%), and src/bounded-execution/finite-schema.ts (49.77%). These files control critical sandbox resource isolation; test coverage must reach ≥80% before MCP gateway integration rollout. Target: Add tests for cleanup workflows, cardinality enforcement, and schema validation error paths.
MEDIUM PRIORITY 🟡
Improve branch coverage for error handling — Branches lag statements by 7 percentage points (83.54% vs 90.54%). Prioritize error paths in host-iptables.ts, squid-config.ts, and docker-manager.ts. Add tests for: DNS resolution failures, Squid startup timeouts, Docker network conflicts, and capability drop edge cases.
LOW PRIORITY ⚪
Stabilize Cloud Hypervisor backend tests — src/cloud-hypervisor/host-enclave-executor.ts (51.67%) and src/microvm/network-reservation.ts (51.50%) need foundational test harness buildout. Not blocking the core firewall, but essential for preview-feature stability. Defer until enclave subsystem reaches 80%.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Overall Coverage
Overall test coverage is strong across all metrics, with statements and line coverage both exceeding 90%. Branch coverage at 83.54% indicates good decision-path testing, though some edge cases remain uncovered.
🛡️ Security-Critical Path Status
Five files with CRITICAL coverage gaps requiring immediate attention:
src/nvx/cleanup-registry.tssrc/bounded-execution/finite-cardinality.tssrc/bounded-execution/finite-schema.tssrc/microvm/network-reservation.tssrc/cloud-hypervisor/host-enclave-executor.tsPrimary Concern: The three files in
src/nvx/andsrc/bounded-execution/represent critical infrastructure for network isolation and resource bounding in microVM and enclave execution. Coverage gaps here directly impact security guarantees.📋 Coverage Table
Top-Performing Files (Security-critical paths):
src/host-iptables.ts: High coverage for iptables rule generationsrc/squid-config.ts: Strong coverage for domain ACL filteringsrc/docker-manager.ts: Comprehensive coverage for container lifecycle managementsrc/cli.ts: Well-tested main entry pointsrc/domain-patterns.ts: Pattern matching validation thoroughly testedLowest Coverage Files (Requiring attention):
src/nvx/cleanup-registry.ts— 42.80% statementssrc/bounded-execution/finite-cardinality.ts— 46.03% statementssrc/bounded-execution/finite-schema.ts— 49.77% statementssrc/microvm/network-reservation.ts— 51.50% statementssrc/cloud-hypervisor/host-enclave-executor.ts— 51.67% statements🔧 Function Audit
The audit reveals:
The untested functions are concentrated in:
src/nvx/,src/cloud-hypervisor/)src/bounded-execution/)src/microvm/)These represent newer infrastructure features added for unified enclaves and Cloud Hypervisor support, suggesting incomplete test harness buildout for these subsystems.
📅 Recent Source Changes (last 7 days)
Recent changes focused on:
Several of the low-coverage files were modified recently to support:
🔎 Notable Findings
Core firewall security modules remain well-tested: Host iptables rules, Squid configuration, and domain pattern matching all have strong coverage, protecting the primary security boundary.
Enclave/microVM subsystem is undertested: The three CRITICAL gaps in
src/nvx/,src/bounded-execution/, and related files indicate that newer infrastructure for private repository enclaves and Cloud Hypervisor support needs significantly more test coverage before production hardening.Branch coverage gap: While statements are at 90.54%, branches lag at 83.54%, indicating edge cases and error handling paths are less thoroughly tested. This is especially concerning in security-critical code.
Potential resource exhaustion risk: The
src/bounded-execution/finite-*.tsfiles handle cardinality and schema validation for resource limits—undertested paths here could allow resource exhaustion attacks or bypass sandbox limits.🎯 Recommendations
HIGH PRIORITY 🔴
src/nvx/cleanup-registry.ts(42.80%),src/bounded-execution/finite-cardinality.ts(46.03%), andsrc/bounded-execution/finite-schema.ts(49.77%). These files control critical sandbox resource isolation; test coverage must reach ≥80% before MCP gateway integration rollout. Target: Add tests for cleanup workflows, cardinality enforcement, and schema validation error paths.MEDIUM PRIORITY 🟡
host-iptables.ts,squid-config.ts, anddocker-manager.ts. Add tests for: DNS resolution failures, Squid startup timeouts, Docker network conflicts, and capability drop edge cases.LOW PRIORITY ⚪
src/cloud-hypervisor/host-enclave-executor.ts(51.67%) andsrc/microvm/network-reservation.ts(51.50%) need foundational test harness buildout. Not blocking the core firewall, but essential for preview-feature stability. Defer until enclave subsystem reaches 80%.All reactions