You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 8320c0f
Browse filesBrowse the repository at this point in the historyBrowse files
test: prove subprocess and production coverage (Fixes#534) (#562)
Make coverage evidence demonstrate real server execution and expose
production gaps without changing existing whole-workspace regression
gates.
- Compare exact idle/info child profiles and require positive execution
in the real handler, transport dispatch, and response writer after
graceful shutdown.
- Add production/test and changed-line diagnostics with conservative
accounting for LLVM summary entries without unique source lines.
- Require profile proof and reporting in Linux/Windows PR and baseline
jobs; add native macOS coverage measured against the exact base on the
same runner.
- Document classification, branch-instrumentation limits, and artifact
semantics.
Validation: 76 Python tests, 19 Windows native cases, workspace
formatting/Clippy, and independent review pass. Actual Windows LLVM
profiles prove all three execution witnesses increase from 0 to 1.
Hosted macOS validation and quality inspection remain pending; no
signing/release services run.
Fixes#534
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copy file name to clipboardExpand all lines: .github/skills/rust-coding-skill/SKILL.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -102,3 +102,5 @@ Do not execute freshly written scripts as concurrent Unix subprocess fixtures: s
102
102
For real-pipe EOF/EPIPE tests, create the pipe inside an isolated test subprocess when other test threads spawn children. Unix `CLOEXEC` closes descriptors at exec, not fork: a concurrent child can temporarily retain a reader, allowing the only write to succeed before the final reader disappears. A readiness handshake alone does not prevent this race. Keep the operation's measured deadline separate from setup, and make an outer fixture deadline cover readiness, waits both before and after forced termination, reader joins, and fallback `Drop` cleanup.
103
103
104
104
Use a per-worktree Cargo target directory when validating stacked changes so native fixtures cannot execute another worktree's stale binary. On WSL, run timing-sensitive Linux binaries from the native Linux filesystem rather than a Windows mount, where page faults can stall in filesystem RPC. When launching instrumented PET with `env_clear()`, retain `LLVM_PROFILE_FILE` exactly so child coverage reaches the collector instead of an uncollected default profile.
105
+
106
+
LLVM LCOV summaries are not necessarily counts of unique `DA` source entries: a native export can have `LF=191`, `LH=173`, 181 mapped lines, and 177 positive mapped lines. Do not reject valid exports using summary/source equality or silently drop unmapped entries; preserve the raw exact-base gate and follow the conservative supplemental accounting documented in [Quality snapshots](../../../docs/QUALITY_SNAPSHOTS.md#production-focused-and-subprocess-evidence). Prove subprocess collection with exact-PID profiles and isolated idle/request counter differences, not a whole-workspace percentage increase.
Copy file name to clipboardExpand all lines: docs/QUALITY_SNAPSHOTS.md
+55Lines changed: 55 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -113,6 +113,61 @@ for the new client clocks.
113
113
114
114
Linux and Windows line and function coverage are compared with the exact base commit. A decrease greater than 0.01 percentage points blocks the pull request. Coverage artifacts and comments remain available for inspection even when the comparison fails.
115
115
116
+
### Production-focused and subprocess evidence
117
+
118
+
The raw workspace percentages still include inline tests and retain the same exact-base
119
+
0.01 percentage-point line/function gate. Supplemental `production-coverage/report.md` and
120
+
schema-1 `details.json` separate executable production/test lines, list uncovered production
121
+
lines, and intersect added/modified Rust lines with executable production lines. Changed files
122
+
without instrumentation are listed explicitly, never assumed covered. These diagnostics do not
123
+
introduce a fabricated baseline, change the raw denominator, or replace regression protection.
124
+
125
+
Classification excludes integration-test/benchmark directories and Rust items explicitly marked
126
+
`#[cfg(test)]` or `#[test]`, including inline modules and test-only helper functions. Nested
127
+
`all`/`any` predicates are also excluded when they require `test`: `all(test, unix)` is test-only,
128
+
but `any(test, unix)` is not. It masks
129
+
strings, raw/byte strings, characters, and nested comments before matching item boundaries.
130
+
Helpers outside those boundaries and unsupported conditional predicates remain conservatively in the
131
+
production category; this is a source-focused diagnostic, not full Rust conditional-compilation
132
+
analysis. Invalid/missing LCOV, missing source, inconsistent hit summaries, and source-line
133
+
mismatches fail the reporting step. LLVM summaries can include more entries in `LF`/`LH`
134
+
than the unique `DA` source lines (observed in real Windows exports). That deficit is reported
135
+
per file (including unmatched summary hits) and conservatively retained as uncovered production
136
+
in mixed source files, or uncovered tests in integration-test/benchmark files. It is never dropped
137
+
from the denominator or silently assigned coverage.
138
+
Changed lines without `DA` records are listed separately in JSON, including non-executable syntax;
139
+
they are not silently considered covered.
140
+
Native macOS also demonstrates `LH` below the number of positive unique `DA` entries. Reports
141
+
retain this deficit and deduct `max(positive DA + unmapped LF - LH, 0)` from each covered
142
+
production/test/changed subtotal (clamped at zero). This accounts for hits that could belong to
143
+
unmapped entries instead of a mapped subset. These subtotals are lower bounds; the report does
144
+
not pretend to locate the discrepancy on a particular source line. Raw LCOV and the exact-base gate remain intact.
145
+
146
+
Every coverage job opts into `normal_shutdown_records_pid_unique_server_profiles` through
147
+
`PET_SUBPROCESS_COVERAGE_PROOF`. The test requires cargo-llvm-cov's absolute, PID-unique output
148
+
pattern, launches idle and known-`info` PET subprocesses, closes stdin, and requires successful
149
+
bounded exit and nonempty profiles for those exact child PIDs. The raw profiles stay in the normal
150
+
cargo-llvm-cov collection directory and are included in the workspace report. The verifier also
151
+
merges each child's profiles separately with the matching Rust LLVM tools and proves zero idle
152
+
versus positive `info` execution at the real handler, transport dispatch, and response writer.
153
+
The uploaded `subprocess-coverage/proof.json` and isolated LCOV exports retain that evidence;
154
+
a killed child, missing profile, or absent execution witness fails rather than appearing covered.
0 commit comments