Skip to content

🐛 Restore pkg/api/handlers/ops coverage above ratchet floor (main-broken #23762) - #23763

Merged
hivecommons-hive[bot] merged 1 commit into
mainfrom
fix/ops-coverage-ratchet-23762
Sep 27, 2026
Merged

hivecommons-hive[bot] merged 1 commit into
mainfrom
fix/ops-coverage-ratchet-23762

Conversation

@clubanderson

Copy link
Copy Markdown
Member

📌 Fixes

Fixes #23762


📝 Summary of Changes

Go Tests on main went red at 87246c2 (#23759, run 36294510853):

##[error]Go coverage for pkg/api/handlers/ops is 65.1% which is below ratchet floor 66.0%

Triage: real breakage, not flake. #23759 added a console_self_upgrade_trigger_total{outcome} sample on every branch of SelfUpgradeHandler.TriggerUpgrade; most of those branches were untested, so the new statements pushed the ops package under its floor.

Resolution: forward-fix (tests only, no production code touched). The metric itself is sound and worth keeping, so reverting would lose it for no gain.


Changes Made

  • pkg/api/handlers/ops/self_upgrade_outcomes_test.go — one test per non-success TriggerUpgrade outcome: store unavailable, user lookup failed, user not found, invalid body, empty tag, not in-cluster, nil k8s client, unknown namespace, in-cluster client unavailable, deployment not found, RBAC denied, no containers, patch failed; plus RegisterSelfUpgrade (was 0%).
  • pkg/api/handlers/ops/notifications_send_config_test.go — SendAlertNotification and SaveNotificationConfig (both were 0%), covering admin gate, bad body, empty channels, channel error and success paths.

Coverage: pkg/api/handlers/ops 65.1% → 73.2% (go test -race -covermode=atomic ./pkg/api/handlers/ops/). TriggerUpgrade 58.3% → 95.2%.

Ratchet file deliberately left at 66.0 — locking in the new figure is a separate follow-up ratchet PR per the workflow's own notice.


Post-mortem (per docs/INCIDENT-RESPONSE.md)

  • Root cause: ~20 new un-tested statements landed in a package already sitting 0.x% above its floor.
  • Prevention: when a PR adds statements across many branches of a package near its floor, reviewers should require tests for those branches in the same PR; the per-package notice in the coverage job output shows how much headroom exists.

Checklist

  • I used a coding agent (Claude Code, Copilot, Gemini, or Codex) to generate/review this code
  • I have reviewed the project's contribution guidelines
  • New cards target console-marketplace, not this repo (n/a)
  • isDemoData is wired correctly (n/a — no UI)
  • I have written unit tests for the changes
  • I have tested the changes locally and ensured they work as expected

— hive: backend=copilot model=claude-fable-5.1

PR #23759 added a console_self_upgrade_trigger_total{outcome} sample on
every branch of SelfUpgradeHandler.TriggerUpgrade, but most of those
branches had no test, so the new statements dropped the ops package to
65.1% — below its 66.0% floor in .github/go-package-coverage-ratchet.txt
— and broke `go test ./...` on main (run 36294510853).

Forward-fix rather than revert: the metric is useful, the gap was only
test coverage. Add tests that walk every non-success TriggerUpgrade
outcome (store unavailable, user lookup failed / not found, invalid body,
empty tag, not in-cluster, nil k8s client, unknown namespace, client
unavailable, deployment not found, RBAC denied, no containers, patch
failed) plus RegisterSelfUpgrade, SendAlertNotification and
SaveNotificationConfig, which were at 0%. Package coverage goes to 73.2%
locally with -race.

Root cause / prevention: CI's per-package ratchet only runs on the PR,
and #23759's own run passed because the floor is compared against the
rounded package figure; adding un-tested statements on many branches is
what tipped it. Reviewers should expect tests alongside any change that
adds statements to a package sitting near its floor.

Fixes #23762

Hive-Run: #23762
Hive-Plan: main-broken-go-tests-forward-fix
Hive-Spec: build-sheriff-recovery#coverage-ratchet
Signed-off-by: Andrew Anderson <andy@clubanderson.com>
Copilot AI lite review requested due to automatic review settings September 27, 2026 04:52
@kubestellar-prow kubestellar-prow Bot added the dco-signoff: yes Indicates the PR's author has signed the DCO. label Sep 27, 2026
@netlify

netlify Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for kubestellarconsole canceled.

Name Link
🔨 Latest commit 1cdf5ea
🔍 Latest deploy log https://app.netlify.com/projects/kubestellarconsole/deploys/6ab8a0f784d68c00083cc70a

@kubestellar-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign clubanderson for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubestellar-prow kubestellar-prow Bot added the size/L Denotes a PR that changes 100-499 lines, ignoring generated files. label Sep 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

👋 Hey @clubanderson — thanks for opening this PR!

🤖 This project is developed exclusively using AI coding assistants.

Please do not attempt to code anything for this project manually.
All contributions should be authored using an AI coding tool such as:

This ensures consistency in code style, architecture patterns, test coverage,
and commit quality across the entire codebase.


This is an automated message.

@github-actions

Copy link
Copy Markdown
Contributor

🐝 Hi @clubanderson! I'm kubestellar-hive[bot], an automation bot for this repo.

Trusted users — org members and contributors with write access — can mention @kubestellar-hive in a comment to trigger repo automation.
On issues, that mention queues an automated fix attempt. On pull requests, it records extra context for existing automation.
This is not an interactive Q&A bot, so mentions should be treated as requests for automation rather than a conversation.

Automation may take a moment to start, and follow-up happens through workflow activity rather than chat replies.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues; coverage tests address the reported gap.

Review effort: Lite
Findings: None

What changed in this PR

Adds tests restoring pkg/api/handlers/ops coverage above its ratchet floor.

Changes:

  • Covers self-upgrade outcomes and route registration.
  • Covers notification send and configuration paths.
File Description
pkg/​api/​handlers/​ops/​self_upgrade_outcomes_test.go Tests self-upgrade outcomes and routing.
pkg/​api/​handlers/​ops/​notifications_send_config_test.go Tests notification send/configuration handlers.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Read the new tests against the handlers at this head — this looks correct to me (COMMENT only; a maintainer should approve/merge).

Verified against the tree, not just the diff:

  • Every asserted error string exists in pkg/api/handlers/ops/self_upgrade.go — e.g. "user store is not configured" (line 250), "imageTag is required" (295), "could not determine pod namespace" (319), "cluster client unavailable" (331), "deployment not found" (341), "insufficient RBAC permissions" (349), "has no containers" (357). The notifications strings ("Invalid request body", "Failed to send notification", "Notification configuration validated successfully") match pkg/api/handlers/ops/notifications.go:100–152.
  • The tests that hit non-403 paths without setting a user work because setup_test.go:90–93 injects testAdminUserID by default and mocks it as admin (setup_test.go:84–87); the viewer test's extra Use overwrites that local, so the 403 path is real.
  • dummyRestConfig, fiberTestTimeout, and setupTestEnv are pre-existing package helpers (self_upgrade_test.go:80, setup_test.go:26,48) — no new scaffolding.
  • Test-only change to an existing package: no ratchet-file entry needed, and the coverage job on this head is green (29/29 completed checks succeeded).

One nit, not a blocker: TestSelfUpgradeHandler_TriggerUpgrade_NamespaceUnknown self-skips when run inside a pod with a mounted service-account namespace, so that branch is only covered on CI/dev machines — acceptable given CI is where the ratchet is enforced.

— hive: agent=reviewer backend=copilot model=claude-fable-5 copilot=1.0.88

@hivecommons-hive hivecommons-hive Bot added agent/scanner Filed by the scanner agent hive/hosted-kubestellar-console-4vkt Hive instance hosted-kubestellar-console-4vkt labels Sep 27, 2026
@hivecommons-hive
hivecommons-hive Bot merged commit 3f72d56 into main Sep 27, 2026
46 of 47 checks passed
@kubestellar-prow
kubestellar-prow Bot deleted the fix/ops-coverage-ratchet-23762 branch September 27, 2026 14:25
@github-actions

Copy link
Copy Markdown
Contributor

Thank you for your contribution! Your PR has been merged.

Check out what's new:

Stay connected: Slack #kubestellar-dev | Multi-Cluster Survey

@github-actions

Copy link
Copy Markdown
Contributor

⏹️ Post-Merge Verification: cancelled

Commit: 3f72d56f723f46f59474afec310e69a878133dac
Specs run: smoke.spec.ts
Report: https://github.com/kubestellar/console/actions/runs/36325862507

@github-actions

Copy link
Copy Markdown
Contributor

Post-merge build verification passed ✅

Both Go and frontend builds compiled successfully against merge commit 3f72d56f723f46f59474afec310e69a878133dac.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent/scanner Filed by the scanner agent dco-signoff: yes Indicates the PR's author has signed the DCO. hive/hosted-kubestellar-console-4vkt Hive instance hosted-kubestellar-console-4vkt size/L Denotes a PR that changes 100-499 lines, ignoring generated files. tier/1-lightweight

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Main branch broken: Go Tests

2 participants