You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Observation: Recent changes focus on Cloud Hypervisor enclave expansion, but cleanup-registry and finite-cardinality modules remain significantly undertested.
🔎 Notable Findings
Enclave Cleanup Crisis (42.8% coverage) — The cleanup-registry.ts module manages artifact tracking and cleanup lifecycle. With only 42.8% statement coverage and 32% branch coverage, edge cases like partial cleanup failure, registry corruption, and cleanup-on-timeout are likely untested.
Cardinality Enforcement Gap (46.03% coverage) — The finite-cardinality.ts module prevents unbounded resource consumption in bounded execution. Missing 54% of statements suggests insufficient testing of:
Cardinality enforcement at limits
Rollback when limits exceeded
State consistency across concurrent attempts
Disclosure Control Branch Famine (11.42% branch coverage) — The finite-disclosure.ts module enforces information disclosure limits. With only 11.42% branch coverage despite 51.78% statement coverage, the vast majority of conditional logic (error paths, truncation, boundary conditions) is untested. This is a high-priority audit target.
Strong Foundation in Network Isolation — Core security modules (host-iptables, squid-config, domain-patterns) maintain >85% coverage, indicating robust confidence in network-level access control.
🎯 Recommendations
🔴 HIGH Priority — Cardinality & Cleanup Safety
Issue:finite-cardinality.ts and cleanup-registry.ts combined guard against resource exhaustion and artifact leakage — both <50% coverage.
Action:
Add comprehensive cardinality enforcement tests:
At-limit scenarios (cardinality == limit)
Over-limit attempts with rollback verification
Concurrent cardinality checks for race conditions
Add cleanup-registry lifecycle tests:
Successful cleanup (happy path) + state verification
Summary: Prioritize fixing CRITICAL gaps in enclave cleanup (42.8%) and cardinality (46.03%) within the next sprint to reduce risk of resource-exhaustion and artifact-leakage vulnerabilities. Medium-priority disclosure control should follow immediately after.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2025-10-02
Overall Coverage
The gh-aw-firewall project maintains strong overall test coverage:
🛡️ Security-Critical Path Status
Excellent coverage in core network-isolation modules:
src/host-iptables.tssrc/squid-config.tssrc/domain-patterns.tssrc/cli.tssrc/nvx/cleanup-registry.tssrc/bounded-execution/finite-cardinality.tssrc/bounded-execution/finite-schema.tssrc/microvm/network-reservation.tssrc/bounded-execution/finite-disclosure.ts📋 Coverage Table
Top 5 Lowest-Coverage Files:
src/nvx/cleanup-registry.tssrc/bounded-execution/finite-cardinality.tssrc/bounded-execution/finite-schema.tssrc/microvm/network-reservation.tssrc/bounded-execution/finite-disclosure.ts🔧 Function Audit
Total Functions: 3,220 defined / 2,877 covered (89.34%)
📅 Recent Source Changes (last 7 days)
test(cloud-hypervisor): expand host executor coverage (#9383)— Enclave executor test expansion[Test Coverage] src/docker-manager.ts (#9368)— Docker lifecycle coverage improvementsfeat: implement host-side Cloud Hypervisor enclave executor (#9376)— New enclave feature (untested)Document AWF threat model and GitHub egress limits (#9355)— Security posture documentationfeat(api-proxy): ordered fallback models on 5xx, timeout (#9356)— Fallback routing (test coverage unclear)Observation: Recent changes focus on Cloud Hypervisor enclave expansion, but cleanup-registry and finite-cardinality modules remain significantly undertested.
🔎 Notable Findings
Enclave Cleanup Crisis (42.8% coverage) — The
cleanup-registry.tsmodule manages artifact tracking and cleanup lifecycle. With only 42.8% statement coverage and 32% branch coverage, edge cases like partial cleanup failure, registry corruption, and cleanup-on-timeout are likely untested.Cardinality Enforcement Gap (46.03% coverage) — The
finite-cardinality.tsmodule prevents unbounded resource consumption in bounded execution. Missing 54% of statements suggests insufficient testing of:Disclosure Control Branch Famine (11.42% branch coverage) — The
finite-disclosure.tsmodule enforces information disclosure limits. With only 11.42% branch coverage despite 51.78% statement coverage, the vast majority of conditional logic (error paths, truncation, boundary conditions) is untested. This is a high-priority audit target.Strong Foundation in Network Isolation — Core security modules (host-iptables, squid-config, domain-patterns) maintain >85% coverage, indicating robust confidence in network-level access control.
🎯 Recommendations
🔴 HIGH Priority — Cardinality & Cleanup Safety
Issue:
finite-cardinality.tsandcleanup-registry.tscombined guard against resource exhaustion and artifact leakage — both <50% coverage.Action:
Add comprehensive cardinality enforcement tests:
Add cleanup-registry lifecycle tests:
Effort: ~4–6 hours | Impact: Security-critical resource-limiting mechanism fully validated
🟠 MEDIUM Priority — Disclosure Control Edge Cases
Issue:
finite-disclosure.tshas critically weak branch coverage (11.42%), leaving >88% of conditional logic untested.Action:
Audit source code for all
if/elseandswitchstatementsAdd missing branch tests for:
Target minimum 70% branch coverage before next release
Effort: ~3–4 hours | Impact: Disclosure-limiting security boundary fully validated
🟡 LOW Priority — Network Reservation Planning
Issue:
network-reservation.ts(51.5% statements) lacks test coverage for network conflict and exhaustion scenarios.Action:
Effort: ~2–3 hours | Impact: Microvm network orchestration robustness
Summary: Prioritize fixing CRITICAL gaps in enclave cleanup (42.8%) and cardinality (46.03%) within the next sprint to reduce risk of resource-exhaustion and artifact-leakage vulnerabilities. Medium-priority disclosure control should follow immediately after.
All reactions