You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Key finding: All primary security-critical paths have good coverage. The firewall's core egress filtering, container management, and network isolation features are well-tested.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
📊 Test Coverage Report — 2026-10-05
Overall Coverage
The AWF firewall codebase maintains excellent overall test coverage with strong metrics across all dimensions:
This represents a mature, well-tested security-critical project with comprehensive test coverage across its core infrastructure.
🛡️ Security-Critical Path Status
The firewall's critical network security and container management systems demonstrate strong coverage:
domain-patterns.ts,domain-utils.ts,domain-matchers.tshost-iptables*.ts(chain, rules, network, validation, cleanup)docker-manager.ts,container-lifecycle.tssquid-config.ts,squid/*.tscli.ts,cli-workflow.ts,cli-options.tsKey finding: All primary security-critical paths have good coverage. The firewall's core egress filtering, container management, and network isolation features are well-tested.
📋 Coverage by Module
🔧 Function Audit
Top 5 Lowest-Coverage Files (Critical Gaps):
🔴 CRITICAL —
src/nvx/cleanup-registry.ts🔴 CRITICAL —
src/bounded-execution/finite-cardinality.ts🟡 MEDIUM —
src/microvm/network-reservation.ts🟡 MEDIUM —
src/bounded-execution/finite-disclosure.ts🟡 MEDIUM —
src/bounded-execution/finite-schema.tsWell-Covered Components:
api-proxy-config.ts,api-proxy-config-domains.ts— Proxy configuration (94–100%)domain-validation.ts,domain-matchers.ts— Domain ACL logic (90–100%)host-iptables*.tssuite — Network isolation rules (85–100%)container-lifecycle.ts— Container orchestration (95%+)services/agent-environment/— Agent setup (99.58%)📅 Recent Source Changes (last 7 days)
Unable to retrieve git log due to sandbox limitations. Coverage data snapshot from 2026-10-05 reflects:
🔎 Notable Findings
Bounded Execution Subsystem Under-Tested:
bounded-execution/module (finite-cardinality, finite-disclosure, finite-schema) shows consistently low coverage (42–52% statements, 11–49% branches)NVX Registry Cleanup Lacks Coverage:
src/nvx/cleanup-registry.tshas only 42.8% statement coverage and 32.11% branch coverageOverall Quality Remains Excellent:
Inverse Relationship in Some Modules:
finite-disclosure.tsshow 51.78% statement coverage but only 11.42% branch coverage🎯 Recommendations
🔴 HIGH Priority (Address immediately in next sprint)
src/bounded-execution/finite-cardinality.tsCoverage🟠 HIGH Priority (Address soon)
2. Improve
src/nvx/cleanup-registry.tsCoverage🟡 MEDIUM Priority (Include in backlog)
3. Expand Branch Coverage in
bounded-execution/finite-disclosure.tsQuality Gate:
All reactions