fix: drift AST scanners miscount coverage (#113) - #143
Merged
juemerson-at-purestorage merged 1 commit intoAug 21, 2026
Merged
juemerson-at-purestorage merged 1 commit into
juemerson-at-purestorage merged 1 commit into
Conversation
Two defects in tools/lib/PfbApiDriftTools.ps1, each moving coverage numbers in the wrong direction. No cmdlet source changes. 1. Get-PfbCentralInjectionSites only recognised a literal index, so the real $QueryParams[$script:PfbContextNamesKey] injection was invisible and the report claimed a 269-endpoint context_names gap for a shipped feature. New Get-PfbPrivateScriptConstant resolves $script: string-literal constants across Private/ (definitions only, single literals only, ambiguous names resolve to nothing), and injection records now carry KeySource. 2. Get-PfbModuleCalledEndpoints walked Public/ and Private/ with no provenance, so private helpers such as Resolve-PfbAdminLocality were credited as cmdlets covering an endpoint. Records now carry IsPublic and Get-PfbParameterCoverageGaps filters the cmdlet attribution list on it -- endpoint coverage still counts both, deliberately. systemicGaps 241 -> 240, parameterGaps 439 -> 358, partial confidence 61 -> 58. Deletes the context_names entry from docs/drift-annotations.json, corrects the four tests that hardcoded it as a live gap, and re-pins the per-file ExpectedSkips for the new PS7-gated tests. Closes dmann000#113 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
fix: drift AST scanners miscount coverage (#113)
Closes #113.
The drift report's two AST scanners each had a defect that moved coverage numbers in the wrong
direction. Both are in
tools/lib/PfbApiDriftTools.ps1; no cmdlet source changes.1. Variable-keyed central injection was invisible
Get-PfbCentralInjectionSitesonly recognised a literal index —$QueryParams['names'] = .... Thereal
context_namesinjection is written as$QueryParams[$script:PfbContextNamesKey] = ..., withthe key held in a
$script:constant in a different file from its use site, so the scanner sawnothing and the report claimed a 269-endpoint
context_namesgap for a feature that shipped inPhase 1.
New helper
Get-PfbPrivateScriptConstantmaps$script:Name = '<literal>'acrossPrivate/, builtonce for the whole directory because the definition and the use site cannot be resolved per-file.
Deliberately narrow, and the header says why:
VariablePath.UserPath, which retains thescript:prefix, so definition and useproduce identical strings;
$script:-scoped targets, and only single string literals;class as Report generators emit in filesystem order: a 10k-line phantom diff blocks the capability-map auto-PR #85;
Injection records now carry
KeySource(literalorconstant) so the two paths staydistinguishable in tests and in triage.
That last point is load-bearing and is asserted directly:
context_namesis detected in the realtree via its constant, and
allow_errors— defined as a constant but not centrally injected — isstill correctly absent. Getting either direction wrong is a regression, so both are pinned.
2. Private helpers were credited as public surface
Get-PfbModuleCalledEndpointswalkedPublic/andPrivate/into one list with no provenance, soa private helper that issues a request (
Resolve-PfbAdminLocality) was attributed as a cmdletcovering that endpoint. The file walk now carries
IsPublic, andGet-PfbParameterCoverageGapsfilters the cmdlet attribution list on it.Two scoping decisions, both commented in place:
-ne $false, not-eq $true, so hand-built records predating the field are notsilently reclassified as private;
Get-PfbEndpointCoverageGapsstill counts both, because an endpoint the module calls from aprivate helper is genuinely covered. Only the "which cmdlet" answer was wrong.
Effect on the committed report
systemicGapscontext_namesgone;allow_errorsintact at 118)parameterGapscontext_names)confidence=partialGET /adminsgapcmdletsGet-PfbAdmin,Resolve-PfbAdminLocalityGet-PfbAdminGET /adminsstays out ofuncoveredEndpoints, which is the point of the endpoint/cmdlet splitabove.
The
context_namesentry indocs/drift-annotations.jsonis deleted — it existed only to explainaway this defect, and an annotation that survives its cause becomes a permanent excuse. Four tests
hardcoded
context_namesas a live systemic gap; each now asserts the corrected state rather thanmerely dropping the name, and
tools/README.mdand the generator header useallow_errorsas therunning "architectural gap, zero cmdletCount" example, with
context_namesretained as a workedexample of the failure mode itself.
Tests/coverage-baseline.psd1re-pinsPfbApiDriftTools.Tests.ps18 → 12 for the new PS7-gatedtests (per-file
ExpectedSkips, from PR #135).The Task 6 aggregation-ratio invariant moved 55.72% → 39.97%, inside its existing
>0.30 / <0.60bounds. That is a re-verify, not a re-tune: the bounds were not touched.
Verification
files: pwsh 7 — 492 passed, 0 failed; Windows PowerShell 5.1 — 342 passed, 0 failed, 150
skipped. Containers healthy under both.
scripts/Assert-PfbDerivedArtifacts.ps1: all 11 checked artifacts up to date. Only thedrift-report pair moved.
tools/,Tests/,docs/andReports/only — nothing inPublic/,Private/,PureStorageFlashBladePowerShell.psd1or.psm1— so it cannot change what goes on the wire.Related
Filed while measuring the same accounting question from the other scanner
(
tools/lib/PfbCmdletParamTools.ps1), and not fixed here: #141 (the wire-name resolver missesthree assignment shapes, leaving 126 parameters skipped rather than measured) and #142 (two
genuine dead keys those skips were hiding). Same question, different file, no shared code — which is
why they are separate issues rather than part of this one.