[Coverage Report] Test Coverage Report — 2026-09-09 #8366
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-09-16T23:46:23.326Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-09-09
Overall Coverage
Total Covered: 14,156 of 15,267 statements
The project maintains strong baseline coverage at 92.72%, well above typical industry standards. However, targeted analysis reveals critical gaps in security-sensitive and newer modules.
🛡️ Security-Critical Path Status
logger.ts)squid-config.ts)host-iptables.ts)cli-workflow.ts)src/bounded-execution/finite-disclosure.ts)docker-manager.ts)cli.ts)Key Finding: Three critical files fall far below safe thresholds.
finite-disclosure.tsis particularly concerning due to low branch coverage (25.89%), indicating incomplete handling of conditional logic paths.📋 Coverage Table
✅ Fully Covered (100%)
logger.tssquid-config.tscli-workflow.tsapi-proxy-config-domains.tshost-iptables.tsenclave/runtime-preflight.tsmicrovm/rootfs.ts🔴 Critical Gaps (<50%)
bounded-execution/finite-disclosure.tsmicrovm/network-reservation.tscommands/validators/config-assembly.tsdocker-manager.tscli.ts🔧 Function Audit
Critical Functions Needing Test Coverage:
src/bounded-execution/finite-disclosure.ts(38.12% statements, 25.89% branches)src/docker-manager.ts(18% statements, 22.22% branches)src/cli.ts(0% coverage)src/commands/validators/config-assembly.ts(73.68% statements, 25% branches)📅 Recent Source Changes (last 7 days)
6 commits affecting
src/in the last 7 days:f895fca— refactor: centralize agent sandbox path policy (refactor: centralize agent sandbox path policy #8334)153a5d0— fix: configure dynamic enclave smoke guard (fix: configure dynamic enclave smoke guard #8324)e015efd— test: add end-to-end security coverage for dynamic repository enclaves (test: add end-to-end security coverage for dynamic repository enclaves #8307)8a3de88— fix: send delegation TTLs in seconds (fix: send delegation TTLs in seconds #8292)bff2b29— feat: run dynamic agent enclaves with repository-scoped GitHub MCP identities (feat: run dynamic agent enclaves with repository-scoped GitHub MCP identities #8276)ced9163— Enforce Squid proxy egress on Docker sbx daemon in smoke workflows (Enforce Squid proxy egress on Docker sbx daemon in smoke workflows #8252)Notable: Recent work has focused on enclave features and sandbox policy, but no corresponding test coverage improvements for critical path files (
docker-manager.ts,cli.ts,finite-disclosure.ts).🔎 Notable Findings
Paradox: Global coverage is 92.72% (excellent), but security-critical modules fall to 0–38%. This reflects selective test focus on stable utility functions rather than orchestration logic.
Branch Coverage Blindspot: Multiple files with >70% statement coverage have <50% branch coverage (
finite-disclosure.ts: 38.12% stmt but only 25.89% branches). Branch testing is consistently weaker than statement testing, indicating insufficient handling of conditional logic.Newer Features Undertested: Enclave, microVM, and bounded-execution modules (added in recent commits) have lower coverage, suggesting they were implemented before comprehensive test suites were created.
Container Lifecycle Risk: The largest and most security-sensitive module (
docker-manager.ts, 3,900+ LOC) has 18% coverage with only 4% function coverage, making runtime behavior largely untested.🎯 Recommendations
🔴 HIGH Priority
Add unit tests for
src/bounded-execution/finite-disclosure.tsIncrease
src/docker-manager.tscoverage to >60%🟡 MEDIUM Priority
src/commands/validators/config-assembly.ts🟢 LOW Priority
src/host-iptables.tsSummary
The codebase maintains excellent global coverage (92.72%) but exhibits a coverage concentration problem: stable utility modules (logger, squid-config) are fully tested, while critical orchestration and newer security modules are undertested. The most urgent action is raising branch coverage in
finite-disclosure.ts(25.89% → >85%) to ensure disclosure boundaries are enforced across all code paths, followed by establishing baseline tests fordocker-manager.tscontainer lifecycle functions.Recommended next step: Prioritize the three HIGH/MEDIUM items above for the next sprint.
All reactions