Repository navigation
[Coverage Report] Test Coverage Report — 2026-10-03 #9423
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-10-10T17:40:15.707Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-10-03
Overall Coverage
Aggregate Results:
The codebase maintains strong overall coverage with statements and lines both above 91%. However, branch coverage lags at 85.01%, indicating some conditional logic paths are not exercised by tests.
🛡️ Security-Critical Path Status
Key Insight: Network isolation rules (iptables) and Squid proxy config are fully covered. However,
src/cli.ts(main entry point) has weak branch coverage at 50%, anddomain-patterns.tshas 11% untested branch paths.📋 Coverage Table
Critical Files with Gaps:
🔧 Function Audit
Fully Tested (Security-Critical):
host-iptables-rules.ts: All 9 functions at 100%host-iptables-shared.ts: All 15 functions at 100%squid-config.ts: All 2 functions at 100%domain-patterns.ts: All 3 functions at 100% (functions level; branches lag)domain-matchers.ts: 4/4 functions (98.14% statements)domain-validation.ts: 5/5 functions at 100%domain-utils.ts: 10/10 functions at 100%docker-manager.ts: 15/15 functions at 100%Partially Tested (Emerging Features):
src/bounded-execution/finite-cardinality.ts: 46.03% statements (1+ functions untested)src/nvx/cleanup-registry.ts: 42.8% statements (multiple functions unreached)src/microvm/network-reservation.ts: 51.5% statements (half-tested)📅 Recent Source Changes (last 7 days)
Note: Git log review is not available in this automation context. Coverage metrics reflect the tip of the current branch at test time (2026-10-03 17:35 UTC).
Detected Unmerged Feature Branches:
The presence of
src/bounded-execution/,src/nvx/, andsrc/microvm/modules with < 60% coverage suggests active development on experimental subsystems. These are candidates for:🔎 Notable Findings
Main CLI Entry Point Underexercised —
src/cli.tshas only 50% branch coverage (1 of 2 branches tested). The main orchestration flow (config generation → container startup → cleanup) lacks adequate scenario testing, particularly for error paths and signal handling.Conditional Domain Matching Gaps —
src/domain-patterns.tsreaches 100% statements but only 89.47% branches. Missing tests for edge cases in subdomain matching, wildcard handling, or normalization (2 branch paths untested).Critical Feature Incomplete — Three modules (
bounded-execution,nvx,microvm) have statement coverage < 55%. These should not ship to production without test expansion. Thenvx/cleanup-registry.tsmodule is only 42.8% covered — registration cleanup logic is mostly untested.Strong Iptables & Proxy Security Coverage — Host network isolation rules and Squid proxy config generation are 100% covered, providing high confidence in the L3/L4 and L7 enforcement layers.
🎯 Recommendations
Priority 1 (HIGH) — Stabilize Main CLI Logic
src/cli.tsPriority 2 (HIGH) — Harden Bounded-Execution Module
src/bounded-execution/finite-cardinality.ts,src/bounded-execution/finite-schema.tsPriority 3 (MEDIUM) — Cover Emerging Features Before Merge
src/nvx/cleanup-registry.ts,src/microvm/network-reservation.ts[WIP]or.skip()to relevant tests until readyCoverage Data Sourced: 2026-10-03T17:35:24Z
Report Generated: Coverage Reporter automation
All reactions