Skip to content

Commit 10c3f85

Browse files
authored
Merge pull request #180 from thanos/coverage
Coverage
2 parents dc2dc1a + b733cd2 commit 10c3f85

6 files changed

Lines changed: 136 additions & 27 deletions

File tree

‎.github/workflows/coverage.yml‎

Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
name: Code Coverage
2+
3+
on:
4+
push:
5+
branches: [ main, master ]
6+
pull_request:
7+
branches: [ main, master ]
8+
workflow_dispatch:
9+
10+
jobs:
11+
coverage:
12+
name: Code Coverage
13+
runs-on: ubuntu-latest
14+
15+
strategy:
16+
matrix:
17+
feature-set:
18+
- ""
19+
- "--features ml-kem"
20+
- "--features post-quantum"
21+
- "--features ml-kem,post-quantum"
22+
23+
steps:
24+
- name: Checkout code
25+
uses: actions/checkout@v4
26+
27+
- name: Install Rust
28+
uses: dtolnay/rust-toolchain@stable
29+
with:
30+
components: rustfmt, clippy
31+
32+
- name: Install cargo-tarpaulin
33+
run: cargo install cargo-tarpaulin --locked
34+
35+
- name: Run tests with coverage
36+
run: |
37+
if [ -z "${{ matrix.feature-set }}" ]; then
38+
cargo tarpaulin \
39+
--out Xml \
40+
--out Html \
41+
--output-dir coverage \
42+
--timeout 300 \
43+
--fail-under 80
44+
else
45+
cargo tarpaulin \
46+
--features ${{ matrix.feature-set }} \
47+
--out Xml \
48+
--out Html \
49+
--output-dir coverage \
50+
--timeout 300 \
51+
--fail-under 80
52+
fi
53+
54+
- name: Upload coverage to Codecov
55+
uses: codecov/codecov-action@v4
56+
with:
57+
files: ./coverage/cobertura.xml
58+
flags: ${{ matrix.feature-set || 'default' }}
59+
name: codecov-${{ matrix.feature-set || 'default' }}
60+
fail_ci_if_error: false
61+
62+
- name: Upload coverage artifacts
63+
uses: actions/upload-artifact@v4
64+
if: always()
65+
with:
66+
name: coverage-report-${{ matrix.feature-set || 'default' }}
67+
path: coverage/
68+
retention-days: 30
69+

‎.gitignore‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,3 +29,14 @@ Thumbs.db
2929

3030
# Test artifacts
3131
test-results/
32+
BRANCH_WORK_SUMMARY.md
33+
COMPARISON.md
34+
COVERAGE_ANALYSIS.md
35+
COVERAGE_GAPS_ANALYSIS.md
36+
COVERAGE_IMPROVEMENTS.md
37+
COVERAGE_TESTS_ADDED.md
38+
FIXES.md
39+
IMPLEMENTATION.md
40+
NEXT_STEPS.md
41+
README_COVERAGE.md
42+
src/NOTES.md

‎Cargo.toml‎

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,35 @@ authors = ["thanos vassilakis"]
66
license = "MIT"
77
description = "Rust implementation of Bottle protocol - layered message containers with encryption and signatures"
88
repository = "https://github.com/thanos/rust-bottle"
9+
readme = "README.md"
10+
keywords = ["cryptography", "encryption", "signature", "bottle", "protocol", "security", "privacy"]
11+
categories = ["cryptography", "encoding", "authentication"]
12+
exclude = [
13+
"patches/",
14+
"target/",
15+
"coverage/",
16+
"API.md",
17+
"BRANCH_WORK_SUMMARY.md",
18+
"COMPARISON.md",
19+
"COVERAGE_ANALYSIS.md",
20+
"COVERAGE_GAPS_ANALYSIS.md",
21+
"COVERAGE_IMPROVEMENTS.md",
22+
"COVERAGE_TESTS_ADDED.md",
23+
"FIXES.md",
24+
"IMPLEMENTATION.md",
25+
"NEXT_STEPS.md",
26+
"POST_QUANTUM.md",
27+
"PQC_FEATURE_FLAG.md",
28+
"README_COVERAGE.md",
29+
"scripts/",
30+
"tarpaulin.toml",
31+
"build_rs_cov.profraw",
32+
"src/NOTES.md",
33+
".gitignore",
34+
".git/",
35+
".idea/",
36+
".vscode/",
37+
]
938

1039
[dependencies]
1140
# Cryptographic primitives

‎POST_QUANTUM.md‎

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -401,25 +401,25 @@ ml-kem = ["pqcrypto-kyber"]
401401

402402
### macOS/ARM (AArch64)
403403

404-
- **ML-DSA**: ✅ Works (uses clean dilithium2/3/5 implementations)
405-
- **SLH-DSA**: ✅ Works (uses clean sphincsshake256 implementations)
406-
- **ML-KEM**: ❌ Compilation fails due to `pqcrypto-kyber` v0.5 bug
404+
- **ML-DSA**: Works (uses clean dilithium2/3/5 implementations)
405+
- **SLH-DSA**: Works (uses clean sphincsshake256 implementations)
406+
- **ML-KEM**: Compilation fails due to `pqcrypto-kyber` v0.5 bug
407407

408408
**Issue**: `pqcrypto-kyber` v0.5.0 has a bug where AVX2 FFI functions are referenced even on AArch64, causing compilation failures. The crate should automatically use the "clean" (generic/portable) implementation on AArch64, but the bug prevents this.
409409

410410
**Workaround**: Use only the `post-quantum` feature (signatures only) on macOS/ARM, or wait for a fix in `pqcrypto-kyber`.
411411

412412
### x86/x86_64
413413

414-
- **ML-DSA**: ✅ Works
415-
- **SLH-DSA**: ✅ Works
416-
- **ML-KEM**: ✅ Works (uses AVX2-optimized implementation if available)
414+
- **ML-DSA**: Works
415+
- **SLH-DSA**: Works
416+
- **ML-KEM**: Works (uses AVX2-optimized implementation if available)
417417

418418
### Other Platforms
419419

420-
- **ML-DSA**: ✅ Should work (uses clean implementations)
421-
- **SLH-DSA**: ✅ Should work (uses clean implementations)
422-
- **ML-KEM**: ⚠️ May have issues depending on platform
420+
- **ML-DSA**: Should work (uses clean implementations)
421+
- **SLH-DSA**: Should work (uses clean implementations)
422+
- **ML-KEM**: May have issues depending on platform
423423

424424
## Known Limitations
425425

‎scripts/coverage.sh‎

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44

55
set -e
66

7-
echo "🔍 Running code coverage analysis for rust-bottle"
7+
echo "Running code coverage analysis for rust-bottle"
88
echo ""
99

1010
# Colors for output
@@ -14,7 +14,7 @@ NC='\033[0m' # No Color
1414

1515
# Check if cargo-tarpaulin is installed
1616
if ! command -v cargo-tarpaulin &> /dev/null; then
17-
echo "❌ cargo-tarpaulin is not installed"
17+
echo "ERROR: cargo-tarpaulin is not installed"
1818
echo " Install it with: cargo install cargo-tarpaulin"
1919
exit 1
2020
fi
@@ -35,7 +35,7 @@ run_coverage() {
3535
local features=$1
3636
local feature_name=${features:-"default"}
3737

38-
echo -e "${YELLOW}📊 Running coverage with features: ${feature_name}${NC}"
38+
echo -e "${YELLOW}Running coverage with features: ${feature_name}${NC}"
3939

4040
if [ -z "$features" ]; then
4141
cargo tarpaulin \
@@ -57,10 +57,10 @@ run_coverage() {
5757
fi
5858

5959
if [ $? -eq 0 ]; then
60-
echo -e "${GREEN}✅ Coverage passed for ${feature_name}${NC}"
60+
echo -e "${GREEN}Coverage passed for ${feature_name}${NC}"
6161
echo ""
6262
else
63-
echo -e "❌ Coverage failed for ${feature_name}"
63+
echo -e "ERROR: Coverage failed for ${feature_name}"
6464
echo ""
6565
return 1
6666
fi
@@ -75,32 +75,32 @@ for features in "${FEATURES[@]}"; do
7575
done
7676

7777
# Generate summary
78-
echo "📈 Coverage Summary"
78+
echo "Coverage Summary"
7979
echo "=================="
8080
echo ""
8181
for features in "${FEATURES[@]}"; do
8282
feature_name=${features:-"default"}
8383
if [ -f "coverage/${feature_name}/cobertura.xml" ]; then
84-
echo "✅ ${feature_name}: Report generated"
84+
echo "SUCCESS: ${feature_name}: Report generated"
8585
echo " HTML: coverage/${feature_name}/tarpaulin-report.html"
8686
echo " XML: coverage/${feature_name}/cobertura.xml"
8787
else
88-
echo "❌ ${feature_name}: No report generated"
88+
echo "ERROR: ${feature_name}: No report generated"
8989
fi
9090
echo ""
9191
done
9292

9393
# Open the default coverage report if on macOS
9494
if [[ "$OSTYPE" == "darwin"* ]] && [ -f "coverage/default/tarpaulin-report.html" ]; then
95-
echo "🌐 Opening coverage report in browser..."
95+
echo "Opening coverage report in browser..."
9696
open "coverage/default/tarpaulin-report.html"
9797
fi
9898

9999
if [ $FAILED -eq 1 ]; then
100-
echo "⚠️ Some coverage runs failed. Check the output above for details."
100+
echo "WARNING: Some coverage runs failed. Check the output above for details."
101101
exit 1
102102
else
103-
echo -e "${GREEN}✅ All coverage reports generated successfully!${NC}"
103+
echo -e "${GREEN}All coverage reports generated successfully!${NC}"
104104
exit 0
105105
fi
106106

‎tests/coverage_test.rs‎

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -2895,16 +2895,13 @@ fn test_decrypt_aes_gcm_success() {
28952895
// ============================================================================
28962896
// Kyber1024 Module Coverage Tests (patches/pqcrypto-kyber-0.5.0/src/kyber1024.rs)
28972897
// ============================================================================
2898-
// NOTE: These tests are commented out because pqcrypto_kyber is not available as a dependency.
2899-
// The kyber1024 module is in the patches directory and may not be directly accessible.
2900-
// To enable these tests:
2901-
// 1. Add pqcrypto-kyber as a dependency (or path dependency to patches/pqcrypto-kyber-0.5.0)
2902-
// 2. Uncomment the tests below
2898+
// NOTE: These tests require the "pqcrypto-kyber" feature to be enabled.
2899+
// To run these tests: cargo test --features pqcrypto-kyber --test coverage
29032900
//
29042901
// Lines to cover: 120-125, 127, 129, 134-139, 141, 157-159, 161-166, 169, 172,
29052902
// 178-180, 182-186, 188, 191, 206-213, 216, 218, 224-228, 230
29062903

2907-
/*
2904+
#[cfg(feature = "pqcrypto-kyber")]
29082905
#[test]
29092906
fn test_kyber1024_keypair_portable() {
29102907
// Test lines 120-125, 127, 129: keypair_portable function
@@ -2977,6 +2974,7 @@ fn test_kyber1024_decapsulate_portable() {
29772974
assert_eq!(ss2.as_bytes().len(), kyber1024::shared_secret_bytes());
29782975
}
29792976

2977+
#[cfg(feature = "pqcrypto-kyber")]
29802978
#[test]
29812979
fn test_kyber1024_keypair_multiple_times() {
29822980
// Test to ensure keypair_portable is exercised multiple times
@@ -2996,6 +2994,7 @@ fn test_kyber1024_keypair_multiple_times() {
29962994
}
29972995
}
29982996

2997+
#[cfg(feature = "pqcrypto-kyber")]
29992998
#[test]
30002999
fn test_kyber1024_encapsulate_decapsulate_round_trip() {
30013000
// Comprehensive test to exercise all portable functions
@@ -3023,6 +3022,7 @@ fn test_kyber1024_encapsulate_decapsulate_round_trip() {
30233022
}
30243023
}
30253024

3025+
#[cfg(feature = "pqcrypto-kyber")]
30263026
#[test]
30273027
fn test_kyber1024_from_bytes_error_paths() {
30283028
// Test error paths in from_bytes (part of the simple_struct macro)
@@ -3047,6 +3047,7 @@ fn test_kyber1024_from_bytes_error_paths() {
30473047
assert!(result4.is_err());
30483048
}
30493049

3050+
#[cfg(feature = "pqcrypto-kyber")]
30503051
#[test]
30513052
fn test_kyber1024_from_bytes_success() {
30523053
// Test successful from_bytes paths
@@ -3078,5 +3079,4 @@ fn test_kyber1024_from_bytes_success() {
30783079
// But we can verify the size is correct
30793080
assert_eq!(ss.as_bytes().len(), ss_expected.as_bytes().len());
30803081
}
3081-
*/
30823082

0 commit comments

Comments
 (0)