Skip to content

Harden coverage, error paths, and package verification - #2

Merged
noah-ing merged 1 commit into
mainfrom
core-hardening-coverage-packaging
Aug 30, 2026
Merged

Harden coverage, error paths, and package verification#2
noah-ing merged 1 commit into
mainfrom
core-hardening-coverage-packaging

Conversation

@noah-ing

Copy link
Copy Markdown
Owner

Summary

  • enforce branch-enabled combined coverage in the authoritative Docker/CI smoke path, with an 85.00% floor chosen below the measured 85.66% baseline
  • regression-test generic broker and inventory failure paths, signed fail-closed denials, leakage boundaries, and honest post-invocation MCP failures
  • strengthen wheel/sdist verification with exact metadata, inventories, modes, RECORD integrity, forbidden-file exclusions, and an offline isolated wheel import

Verification

  • host: 145 passed; 15 Linux-only swtpm tests deselected; 88.20% branch-enabled combined coverage
  • clean no-cache Docker/Compose: 160 passed; zero skips/failures; 15 genuine real-swtpm tests; 90.33% coverage
  • Ruff lint/format, Mypy (13 source files), Bandit, pip-audit, detect-secrets, uv lock, Compose config, package build/verifier, and offline isolated wheel install/import passed
  • final independent source/security review: no actionable findings

Assurance boundary

This does not broaden the project claim. It does not establish bit reproducibility, hardware provenance, holder-key residency, TPM/agent co-location, agent execution, runtime integrity, safe behavior, or exactly-once business execution.

@noah-ing
noah-ing merged commit 9616660 into main Aug 30, 2026
2 checks passed
@noah-ing
noah-ing deleted the core-hardening-coverage-packaging branch August 30, 2026 15:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant