From 9a23395bc69f33c6085384f82198d76a2dd1d711 Mon Sep 17 00:00:00 2001 From: Evgeny Kiriyak <224408464+evkir@users.noreply.github.com> Date: Sun, 20 Sep 2026 10:58:57 +0300 Subject: [PATCH] test(config): the guard reader is asserted where its answers differ Codecov named one uncovered line in the previous commit: the branch that recognises a word for yes. Covering it took one loop. Proving it took a second one, in a different place, and the difference is the point. strict_scope defaults to True, so on that flag the yes branch and the fallthrough to the default return the same answer. A reader that recognised no word for yes at all would have passed every assertion about CYBERAI_STRICT_SCOPE, including the new loop that executes the line. Measured, not reasoned: with the branch deleted the suite stayed green, and the mutant survived a run whose coverage report showed the line executed. The assertion that kills it is on _env_guard_bool with a default of False, where yes and the default disagree. The matching no-branch mutant is killed four times over, since a flag defaulting to on already separates those. A covered line is not a tested one. The branch was both at once for an hour. --- tests/unit/test_strict_scope.py | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/tests/unit/test_strict_scope.py b/tests/unit/test_strict_scope.py index 6071c163..42c9c371 100644 --- a/tests/unit/test_strict_scope.py +++ b/tests/unit/test_strict_scope.py @@ -98,6 +98,15 @@ def test_only_a_named_word_turns_the_refusal_off( monkeypatch.setenv("CYBERAI_STRICT_SCOPE", noise) assert CyberAIConfig.from_env().strict_scope is True, noise + # Saying yes out loud is a third answer, not the absence of the other two. + # Coverage caught this branch unexecuted: every assertion above lands on + # off or on the default, so a reader that never recognised a word for yes + # would have passed them all. An operator who writes the variable to turn + # the guard back on has to be answered. + for word in ("1", "true", "yes", "on", "ON", " 1 "): + monkeypatch.setenv("CYBERAI_STRICT_SCOPE", word) + assert CyberAIConfig.from_env().strict_scope is True, word + def test_the_ordinary_flag_reader_is_left_as_it_was( monkeypatch: pytest.MonkeyPatch, @@ -113,6 +122,18 @@ def test_the_ordinary_flag_reader_is_left_as_it_was( assert _env_bool("CYBERAI_TEST_FLAG", True) is False assert _env_guard_bool("CYBERAI_TEST_FLAG", True) is True + # Asserted against a default of False, which is the only way this says + # anything. strict_scope defaults to True, so a reader that recognised no + # word for yes would answer True for "1" by falling through to the + # default and every assertion about that flag would still pass -- the + # branch was covered and unproven at once. Here the two answers differ. + for word in ("1", "true", "yes", "on"): + monkeypatch.setenv("CYBERAI_TEST_FLAG", word) + assert _env_guard_bool("CYBERAI_TEST_FLAG", False) is True, word + for word in ("0", "false", "no", "off"): + monkeypatch.setenv("CYBERAI_TEST_FLAG", word) + assert _env_guard_bool("CYBERAI_TEST_FLAG", True) is False, word + def test_the_orchestrator_hands_the_flag_to_the_validator() -> None: """The link the other tests cannot see.