Managed desktop coverage evidence

Managed desktop coverage evidence

Tracking: #853 and PR #861. Measured Rust source: `5519f3b98aa09db35de42b43cab1f5a65a54393e`, 2026-09-14. The implementation and remaining integration remain separate from this automated coverage gate.

Result

The 80% production-line / 75% mapped-branch-outcome gate is not met. Instrumented tests passed: 1033 library tests and 1073 binary tests. Each suite ignored the same existing live OpenSSH fixture; a separate instrumented run of that fixture passed (one test). This includes the legacy SSH/PTY unit suite, controlled HTTPS/mTLS integration and local SSH certificate/forwarding negatives. It does not establish authenticated RDP, deployed issuer propagation, full Cockpit, multi-user isolation or distributed worker cancellation.

Production moduleLinesBranch outcomesGate
`desktop_admission.rs`387/408 (94.85%)81/120 (67.50%)unmet
`desktop_enrollment.rs`273/284 (96.13%)60/78 (76.92%)pass
`desktop_grants.rs`179/184 (97.28%)21/26 (80.77%)pass
`desktop_keycloak.rs`277/293 (94.54%)90/128 (70.31%)unmet
`desktop_startup.rs`126/134 (94.03%)28/40 (70.00%)unmet
`http/desktop.rs`138/142 (97.18%)28/36 (77.78%)pass
`http/tls_listener.rs`101/175 (57.71%)11/18 (61.11%)unmet
`http/server.rs`381/1423 (26.77%)13/64 (20.31%)unmet
`ssh_gateway.rs`254/296 (85.81%)27/40 (67.50%)unmet
`main.rs`227/1302 (17.43%)35/214 (16.36%)unmet

These are whole production modules, including existing HTTP/startup code. They are not an average over only new lines. The HTTP module now includes both discovery and authenticated provisioning enrollment, and meets both targets. The enrollment store now meets both targets as well. Earlier discovery-only coverage at `95fd780` was 100% / 95%; the current table measures the expanded module. New tests cover workload-role and Create-action checks, fresh membership, owner-field injection, concurrent revision updates, foreign ownership/workspaces and expired queued writes. The controlled HTTPS/mTLS fixture creates its enrollment through the configured endpoint. Branch gaps remain in admission bindings, identity/configuration validation and storage failure handling. The larger HTTP/server and main modules also have substantial unexecuted production code. High line coverage in new modules does not satisfy the branch target or replace missing endpoint/enrollment integration.

Method and limitations

Tooling: cargo-llvm-cov 0.9.1; rustc 1.100.0-nightly `809936eac` from the dated `nightly-2026-09-13` toolchain; bundled LLVM 23.1. The default stable compiler was not changed. The nightly installer reported a rustup-location error after installing its components; direct compiler and component checks proved the dated toolchain and LLVM tools usable.

Branch coverage is experimental and requires nightly. The report checker reads executable line counts from LCOV and branch mappings from LLVM JSON. It excludes code at and after each selected file's final `#[cfg(test)]` module boundary, including inline tests. Separate test files are not selected. Missing records remain unmeasured; duplicate/truncated LCOV records and unsupported JSON mappings fail.

For branches, it merges matching source coordinates across library/binary and generic instantiations, marks each outcome covered if any instance executed it, and retains conditions with both outcomes unexecuted. LLVM LCOV and summary exports omit some of these explicit mappings: for example main has 214 mapped outcomes but 62 LCOV outcomes. This report uses the larger explicit denominator and does not claim the more optimistic exporter percentage as a passing gate. Three checker tests cover exclusion, thresholds, missing data, duplicate/truncated input and merging of unexecuted mappings.

During the earlier baseline measurement, full LCOV function export crashed in LLVM after the live SSH test passed. The current run used JSON export and passed. Exporting the same saved profiles with `--skip-functions` succeeded; JSON export also succeeded. No passing test was reclassified as failing, and no profile was discarded to avoid the exporter failure. Two earlier live-command attempts were rejected by the CLI before execution (filter placement, then incompatible `--no-clean`/`--no-report` flags).

The provisioning implementation initially failed compilation on UUID serde support and then an incomplete DTO conversion. Explicit UUID parsing/string serialization fixed those checks. A superseded in-flight coverage run preceded the final monotonic-expiry refinement; it is not used in this table. The final stable library run, binary check, formatting and documentation checks passed alongside the final instrumented runs above.

Reproduce

Use the dated toolchain with its `llvm-tools-preview` component and cargo-llvm-cov 0.9.1. The live fixture requires the prerequisites documented in the admission implementation. An occupied port 3389 must fail the fixture; do not stop an existing service.

cargo +nightly-2026-09-13 llvm-cov --manifest-path management/Cargo.toml --lib --bin agentic-mgmt --branch --json --output-path /tmp/desktop-853-coverage.json
cargo +nightly-2026-09-13 llvm-cov --manifest-path management/Cargo.toml --lib --branch --no-clean --json --output-path /tmp/desktop-853-coverage-final.json -- live_desktop_certificates --ignored --nocapture
cargo +nightly-2026-09-13 llvm-cov report --manifest-path management/Cargo.toml --branch --lcov --skip-functions --output-path /tmp/desktop-853-coverage.lcov
python3 scripts/test-desktop-coverage-report.py
python3 scripts/desktop-coverage-report.py /tmp/desktop-853-coverage.lcov --branches-json /tmp/desktop-853-coverage-final.json --json /tmp/desktop-853-production-coverage.json --check

The checker currently exits 1, as expected for unmet targets. The reproduction uses JSON for the live-run export to avoid the observed LCOV function-export crash. Reports can be regenerated from the existing profiles without repeating tests while source and instrumentation remain unchanged.

Retained local evidence

These hashes identify local files, not published CI artifacts. Fixture listener process groups were stopped/reaped and temporary files removed by the fixture; port 3389 was checked free before the live run. No deployed service, realm, credential or guest was changed.

File under `/tmp/`SHA-256
`desktop-853-provisioning-final-coverage.log``b058a92b733bbb5b114b55aeae11478c7b037a7bb3430d610410e9b20b84471f`
`desktop-853-provisioning-ssh.log``44a55cf7c8ea874c8405b603f820a29ab37c4da8fbf82659cea817a01a9e1c0f`
`desktop-853-provisioning-coverage.lcov``8f34e04f416331183976b49c005b44e1c1e5a3a58bb8ff998dbb89462d70a9e9`
`desktop-853-provisioning-coverage-final.json``eadf85de2b6bcde83a46165bba63a1a5d0be422f9480742b05016dc344638fd9`
`desktop-853-provisioning-production-coverage.json``9eadf1801266c7968ef2b4610468ddc40e92a7c7dc33b99b490a073a74a3cf4d`

Binary check: `/tmp/desktop-853-provisioning-final-bin.log`, SHA-256 `0f988eb1dcb891a71d980c05be799aaa432c38f46ec5b94deb10a091bbe71537`.