[quality] cover mint projected-token loader and advisory file-path ref parsers - #5044
Conversation
…f parsers readFileTrimmed (pkg/mint/tokenreview.go) was at 20%: the rotation re-read, whitespace trim, and missing-file branches were untested even though this loader is what keeps the mint authenticating itself after the kubelet rotates the projected ServiceAccount token. Now 100%. NewInClusterTokenReviewAuthenticator was at 50%: only the missing-env refusal was covered. The CA-bundle branch is now tested hermetically on both plain hosts (absent bundle must refuse, naming the CA) and real pods (present bundle must construct without network I/O). Now 87.5%. splitFilePathRef / isFilePathRef (pkg/advisory/advisory.go) were only reached through the happy VerifyFindingPaths flow; edge branches (non-numeric suffix, trailing/leading colon, gh-/#-refs) are now pinned directly. Both now 100%. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Changelog: this PR changes code but does not touch If it is user-visible — a feature, a fix an operator would notice, a This is a reminder, not a gate; it never blocks a merge. |
|
Thank you for your contribution! Your PR has been merged. Check out what's new:
Stay connected: Slack #kubestellar-dev | Multi-Cluster Survey |
Test Improvement
Adds two test files, no production code changes:
src/pkg/mint/tokenreview_loader_test.go— coversreadFileTrimmed(20% → 100%): token rotation re-read, whitespace trim, missing-file error propagation; and the CA-bundle branch ofNewInClusterTokenReviewAuthenticator(50% → 87.5%), hermetic on both plain hosts and in-cluster pods.src/pkg/advisory/filepathref_test.go— direct branch coverage forsplitFilePathRefandisFilePathRef(50% → 100%): non-numeric colon suffix, trailing/leading colon, gh-N and repo#N refs.Claimed ground
Files/functions:
src/pkg/mint/tokenreview.go(readFileTrimmed,NewInClusterTokenReviewAuthenticator) andsrc/pkg/advisory/advisory.go(splitFilePathRef,isFilePathRef) — disjoint from open PRs #5036 (config.go provenance test) and #4032 (proxy auth injection).Verification
go test ./pkg/mint/ ./pkg/advisory/— ok, 94.4% / 94.6%.Beads: 83e05ac8-728, fe21ab38-f60.
Filed by quality agent (hold-gated mode). Human review required.
— hive: agent=quality backend=copilot model=claude-fable-5