Repository navigation
Expand file tree
/
Copy pathcodecov.yml
More file actions
358 lines (318 loc) · 10.1 KB
/
Copy pathcodecov.yml
File metadata and controls
358 lines (318 loc) · 10.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
codecov:
require_ci_to_pass: true
coverage:
precision: 1
round: down
status:
project:
default:
target: auto
threshold: 1%
unit:
target: auto
flags:
- unit
integration:
target: auto
flags:
- integration
e2e:
target: auto
flags:
- e2e
python-sdk:
target: 90%
flags:
- python-sdk
typescript-sdk:
target: 90%
flags:
- typescript-sdk
patch:
default:
target: 90%
comment:
layout: "diff, flags, components, files"
behavior: default
require_changes: false
require_base: yes
require_head: yes
flags:
typescript-sdk:
paths:
- sdk/typescript/src/**
carryforward: true
python-sdk:
paths:
- sdk/python/capsem/**
carryforward: true
mcp-server:
paths:
- mcp/typescript/src/**
carryforward: true
unit:
paths:
- crates/**
- sdk/rust/src/**
- web/app/src/**
- build_system/release_site/scripts/**
- build_system/release_site/src/**
- build_system/builder/**
carryforward: true
integration:
paths:
- crates/**
carryforward: true
e2e:
paths:
- crates/**
carryforward: true
linux-unit:
paths:
- crates/**
- sdk/rust/src/**
carryforward: true
# Components tag code paths by functional service.
component_management:
default_rules:
statuses:
- type: project
target: auto
threshold: 2%
- type: patch
target: 90%
individual_components:
- component_id: typescript-sdk
name: TypeScript SDK
paths:
- sdk/typescript/src/**
- component_id: python-sdk
name: Python SDK
paths:
- sdk/python/capsem/**
# MITM HTTPS proxy, TLS, cert authority, domain/HTTP policy,
# AI traffic parsing (SSE, providers, pricing). All of net/
# except policy_config.
- component_id: network
name: Network
paths:
- crates/capsem-core/src/net/mod.rs
- crates/capsem-core/src/net/hostname.rs
- crates/capsem-core/src/net/ai_traffic/**
- crates/capsem-core/src/net/cert_authority.rs
- crates/capsem-core/src/net/decompress.rs
- crates/capsem-core/src/net/dns/**
- crates/capsem-core/src/net/interpreters/**
- crates/capsem-core/src/net/mitm_proxy/**
- crates/capsem-core/src/net/parsers/**
- crates/capsem-core/src/net/policy.rs
- crates/capsem-core/src/net/address_pool.rs
- crates/capsem-core/src/net/network_registry.rs
- crates/capsem-core/src/net/network_registry/**
# Policy engine and security-rule evaluation, settings registry, corp
# lockdown/MDM, and the credential broker's storage boundary.
- component_id: security
name: Security
paths:
- crates/capsem-core/src/net/policy_config/**
- crates/capsem-core/src/security_engine/**
- crates/capsem-core/src/credential_broker.rs
# MCP endpoint, builtin HTTP tools, MCP policy, FS monitor.
- component_id: tooling
name: Tooling
paths:
- crates/capsem-core/src/mcp/**
- crates/capsem-core/src/auditfs.rs
- crates/capsem-core/src/contained_fs.rs
- crates/capsem-core/src/fs_monitor.rs
- crates/capsem-core/src/bin/mcp_export.rs
# Logger DB, session index/maintenance, log layer, tracing bootstrap.
# Future: OTEL, reporting, SSH session recording.
- component_id: monitoring
name: Monitoring
paths:
- crates/capsem-archive/src/**
- crates/capsem-logger/src/**
- crates/capsem-telemetry/src/**
- crates/capsem-core/src/pty_log.rs
- crates/capsem-core/src/session/**
# Machine lifecycle, VM config, vsock manager, host-side lifecycle state
# machine. Hypervisor abstraction layer + platform backends.
- component_id: virtualization
name: Virtualization
paths:
- crates/capsem-core/src/vm/**
- crates/capsem-core/src/hypervisor/**
- crates/capsem-core/src/host_state.rs
- crates/capsem-core/src/container.rs
- crates/capsem-core/src/container/**
- component_id: port-router
name: Confined Port Router
paths:
- crates/capsem-router/src/**
# The private link between VMs: the frame codec and switch verdict, the
# service's switch host and the shared confined-child spawn, and the UDS
# client owners use to ask the service on their VM's behalf.
- component_id: private-network
name: Private Network
paths:
- crates/capsem-network/src/**
- crates/capsem-core/src/net/router_process.rs
- crates/capsem-core/src/net/switch_host.rs
- crates/capsem-core/src/net/switch_host/**
- crates/capsem-core/src/service_uds.rs
# Runtime half of the asset contract: manifest hash extraction plus the
# download/verify path that resolves recorded digests before boot.
# capsem-admin owns the generation half, under the `admin` component.
- component_id: assets
name: Assets
paths:
- crates/capsem-assets/src/**
# Shared gateway request, response, enum, and OpenAPI contracts.
- component_id: api
name: Gateway API
paths:
- crates/capsem-api/src/**
- component_id: rust-sdk
name: Rust SDK
paths:
- sdk/rust/src/**
# Pure settings, provider, profile, MCP, and security-rule contracts.
- component_id: config
name: Configuration
paths:
- crates/capsem-config/src/**
# Broker-owned runtime and durable credential storage. Telemetry and
# policy observation remain in the security component.
- component_id: credentials
name: Credentials
paths:
- crates/capsem-credentials/src/**
# Dependency-light host paths, telemetry bootstrap, IPC helpers, and
# bounded polling shared by utility processes.
- component_id: foundation
name: Host Foundation
paths:
- crates/capsem-foundation/src/**
# Cross-cutting capsem-core primitives every other component builds on:
# crate root, ~/.capsem path resolution, UDS helpers, IPC handshake and
# stream coalescing, backoff polling, shared macros.
- component_id: core
name: Core Platform
paths:
- crates/capsem-core/src/lib.rs
- crates/capsem-core/src/macros.rs
- crates/capsem-core/src/ipc_ext.rs
# In-VM agent binaries: PTY agent, net-proxy, MCP server
# relay, wire protocol.
- component_id: runtime
name: Runtime
paths:
- crates/capsem-agent/src/**
- crates/capsem-proto/src/**
# App shell: CLI/GUI wiring, boot, vsock wiring, session
# management. Evolves into orchestrator + API + auth.
- component_id: daemon
name: Daemon
paths:
- crates/capsem-app/src/**
# Service daemon: HTTP-over-UDS API, instance lifecycle,
# service-owned API surface.
- component_id: service
name: Service
paths:
- crates/capsem-service/src/**
# Per-VM process manager and lifecycle isolation.
- component_id: process
name: Process
paths:
- crates/capsem-process/src/**
# Admin/profile tooling: manifest generation, profile materialization,
# image build orchestration, and release asset validation.
- component_id: admin
name: Admin
paths:
- crates/capsem-admin/src/**
# CLI client: start, stop, exec, shell, list, status, delete.
- component_id: cli
name: CLI
paths:
- crates/capsem/src/**
# npm MCP server: AI agent tool gateway over stdio JSON-RPC.
- component_id: mcp-server
name: MCP Server
paths:
- mcp/typescript/src/**
# MCP aggregator binary.
- component_id: mcp-aggregator
name: MCP Aggregator
paths:
- crates/capsem-mcp-aggregator/src/**
# Built-in MCP subprocess binary.
- component_id: mcp-builtin
name: MCP Builtin
paths:
- crates/capsem-mcp-builtin/src/**
# TCP-to-UDS gateway: auth, proxy, status cache, terminal WebSocket.
- component_id: gateway
name: Gateway
paths:
- crates/capsem-gateway/src/**
# Terminal UI: profile/session control over the service API.
- component_id: tui
name: TUI
paths:
- crates/capsem-tui/src/**
# System tray host: menu wiring, gateway client, icon rendering.
- component_id: systray
name: System Tray
paths:
- crates/capsem-tray/src/**
# Companion-lifecycle primitives: parent-watch, singleton flock.
# Small library but load-bearing -- ensures capsem-gateway and
# capsem-tray never outlive their parent service.
- component_id: guard
name: Guard
paths:
- crates/capsem-guard/src/**
# Frontend: Astro + Svelte components, views, stores.
# Populated when vitest coverage is added to pipeline.
- component_id: ui
name: UI
paths:
- web/app/src/**
# Release site: Astro pages and release graph rendering helpers.
- component_id: release-site
name: Release Site
paths:
- build_system/release_site/scripts/**
- build_system/release_site/src/**
# Builder: Pydantic schema, config models, image builder.
- component_id: builder
name: Builder
paths:
- build_system/builder/**
# Local fixture server used for doctor, benchmark, recorder, and Ironbank proof.
- component_id: mock-server
name: Mock Server
paths:
- crates/capsem-mock-server/src/**
# Guest/host benchmark binary and protocol load generator.
- component_id: bench
name: Bench
paths:
- crates/capsem-bench/src/**
ignore:
- crates/*/tests/**
# `#[cfg(test)]` sibling modules and fixture helpers are assertions about
# product code, not product code a component owns.
- crates/*/src/**/tests.rs
- crates/*/src/**/*_tests.rs
- crates/*/src/**/tests/**
- crates/*/src/**/proptests.rs
- crates/*/src/**/test_support.rs
- crates/*/src/**/test_support/**
- crates/capsem-app/gen/**
- web/marketing/**
- web/docs/**
- guest/**