Skip to content

Code Metrics

Generated: 2026-10-09 22:51 UTC


Lines of Code

Files Code Comment Blank Total
Source 92 23 897 5 297 1 418 30 612
Tests 109 35 948 2 877 2 423 41 248
Combined 201 59 845 8 174 3 841 71 860
  • Comment/code ratio: 22%
  • Test/source ratio: 150.4%
Source by module (click to expand)
Module Files Code Comment Blank
terok_sandbox/ 92 23 897 5 297 1 418
terok_sandbox/_util/ 13 749 327 115
terok_sandbox/_util/__init__.py — 26 3 4
terok_sandbox/_util/_apparmor.py — 123 50 17
terok_sandbox/_util/_fs.py — 23 13 2
terok_sandbox/_util/_logging.py — 29 12 2
terok_sandbox/_util/_naming.py — 7 9 3
terok_sandbox/_util/_net.py — 25 10 9
terok_sandbox/_util/_pidfile.py — 50 32 8
terok_sandbox/_util/_placement.py — 38 2 2
terok_sandbox/_util/_proc.py — 45 43 8
terok_sandbox/_util/_selinux.py — 245 83 44
terok_sandbox/_util/_subprocess_env.py — 18 16 3
terok_sandbox/_util/_systemctl.py — 96 40 8
terok_sandbox/_util/_templates.py — 24 14 5
terok_sandbox/commands/ 11 3 599 693 153
terok_sandbox/commands/__init__.py — 213 68 6
terok_sandbox/commands/_types.py — 12 8 1
terok_sandbox/commands/credentials.py — 645 178 40
terok_sandbox/commands/doctor.py — 73 20 15
terok_sandbox/commands/gate.py — 51 12 7
terok_sandbox/commands/launch.py — 245 20 3
terok_sandbox/commands/sandbox.py — 258 63 20
terok_sandbox/commands/shield.py — 113 75 5
terok_sandbox/commands/ssh.py — 729 29 21
terok_sandbox/commands/supervisor.py — 69 36 4
terok_sandbox/commands/vault.py — 1 191 184 31
terok_sandbox/gate/ 5 2 337 322 57
terok_sandbox/gate/hooks.py — 130 40 4
terok_sandbox/gate/mirror.py — 1 714 178 33
terok_sandbox/gate/server.py — 484 74 16
terok_sandbox/gate/tokens.py — 9 15 3
terok_sandbox/integrations/ 3 280 177 22
terok_sandbox/integrations/clearance.py — 13 27 2
terok_sandbox/integrations/shield.py — 267 140 19
terok_sandbox/resources/ 7 1 058 425 108
terok_sandbox/resources/apparmor/ 1 72 41 10
terok_sandbox/resources/bridges/ 2 171 180 26
terok_sandbox/resources/hooks/ 2 667 142 53
terok_sandbox/resources/hooks/_supervisor_state.py — 170 41 13
terok_sandbox/resources/hooks/supervisor_hook.py — 497 101 40
terok_sandbox/resources/selinux/ 1 70 34 12
terok_sandbox/resources/supervisor_wrapper.py — 78 28 7
terok_sandbox/runtime/ 7 3 303 456 143
terok_sandbox/runtime/__init__.py — 68 14 4
terok_sandbox/runtime/gpu.py — 535 55 27
terok_sandbox/runtime/krun.py — 252 66 7
terok_sandbox/runtime/krun_transport.py — 354 79 23
terok_sandbox/runtime/null.py — 375 66 23
terok_sandbox/runtime/podman.py — 1 425 131 38
terok_sandbox/runtime/protocol.py — 294 45 21
terok_sandbox/supervisor/ 7 1 730 349 86
terok_sandbox/supervisor/__init__.py — 25 9 1
terok_sandbox/supervisor/children.py — 465 112 21
terok_sandbox/supervisor/install.py — 326 31 9
terok_sandbox/supervisor/janitor.py — 258 58 27
terok_sandbox/supervisor/launcher.py — 44 22 2
terok_sandbox/supervisor/main.py — 286 73 17
terok_sandbox/supervisor/sidecar.py — 326 44 9
terok_sandbox/vault/ 19 4 959 1 399 410
terok_sandbox/vault/daemon/ 3 1 055 353 129
terok_sandbox/vault/daemon/__init__.py — 5 43 3
terok_sandbox/vault/daemon/audit.py — 120 5 4
terok_sandbox/vault/daemon/token_broker.py — 930 305 122
terok_sandbox/vault/ssh/ 4 958 240 82
terok_sandbox/vault/ssh/__init__.py — 2 21 1
terok_sandbox/vault/ssh/keypair.py — 427 127 22
terok_sandbox/vault/ssh/manager.py — 156 25 14
terok_sandbox/vault/ssh/signer.py — 373 67 45
terok_sandbox/vault/store/ 11 2 946 787 198
terok_sandbox/vault/store/db.py — 695 141 34
terok_sandbox/vault/store/encryption.py — 684 188 48
terok_sandbox/vault/store/kernel_keyring.py — 374 59 15
terok_sandbox/vault/store/migrations.py — 155 61 19
terok_sandbox/vault/store/recovery.py — 97 69 20
terok_sandbox/vault/store/session_cache.py — 89 23 4
terok_sandbox/vault/store/session_file.py — 62 61 4
terok_sandbox/vault/store/status.py — 283 65 16
terok_sandbox/vault/store/systemd_creds.py — 387 90 32
terok_sandbox/vault/store/tiers.py — 120 7 5
terok_sandbox/__init__.py — 487 66 8
terok_sandbox/__main__.py — 8 11 4
terok_sandbox/_exit_codes.py — 3 17 5
terok_sandbox/_setup.py — 457 71 16
terok_sandbox/_setup_manual.py — 198 54 8
terok_sandbox/_stage.py — 237 40 16
terok_sandbox/_yaml.py — 57 19 3
terok_sandbox/cli.py — 70 28 21
terok_sandbox/config.py — 588 74 30
terok_sandbox/config_schema.py — 606 31 23
terok_sandbox/diagnostics.py — 263 43 4
terok_sandbox/doctor.py — 360 67 27
terok_sandbox/launch.py — 652 209 46
terok_sandbox/operator_cli.py — 30 4 1
terok_sandbox/paths.py — 124 32 11
terok_sandbox/podman_args.py — 99 45 10
terok_sandbox/port_registry.py — 450 63 9
terok_sandbox/sandbox.py — 800 192 60
terok_sandbox/setup.py — 65 15 8
terok_sandbox/supervision.py — 328 68 14

Architecture

Module Dependency Graph

graph TD
    terok_sandbox.port_registry --> terok_sandbox.paths
    terok_sandbox.setup --> terok_sandbox.config
    terok_sandbox.setup --> terok_sandbox.integrations.shield
    terok_sandbox.setup --> terok_sandbox.supervisor
    terok_sandbox.config_schema --> terok_sandbox.paths
    terok_sandbox.config_schema --> terok_sandbox.podman_args
    terok_sandbox.config --> terok_sandbox.paths
    terok_sandbox.config --> terok_sandbox.podman_args
    terok_sandbox.config --> terok_sandbox.port_registry
    terok_sandbox.config --> terok_sandbox.vault.store.db
    terok_sandbox.config --> terok_sandbox.vault.store.encryption
    terok_sandbox.config --> terok_sandbox.config_schema
    terok_sandbox.doctor --> terok_sandbox._stage
    terok_sandbox.doctor --> terok_sandbox._util
    terok_sandbox.doctor --> terok_sandbox.config
    terok_sandbox.doctor --> terok_sandbox.paths
    terok_sandbox.doctor --> terok_sandbox.supervisor.sidecar
    terok_sandbox.doctor --> terok_sandbox.vault.daemon
    terok_sandbox.doctor --> terok_sandbox.vault.store.encryption
    terok_sandbox.doctor --> terok_sandbox.vault.store.recovery
    terok_sandbox.doctor --> terok_sandbox.vault.store.session_cache
    terok_sandbox.doctor --> terok_sandbox.vault.store.tiers
    terok_sandbox.vault --> terok_sandbox.vault.daemon.token_broker
    terok_sandbox.vault.store.db --> terok_sandbox.vault.store.migrations
    terok_sandbox.vault.store.db --> terok_sandbox.vault.store.encryption
    terok_sandbox.vault.store.db --> terok_sandbox.vault.store.tiers
    terok_sandbox.vault.store.encryption --> terok_sandbox.vault.store.session_cache
    terok_sandbox.vault.store.encryption --> terok_sandbox.vault.store.systemd_creds
    terok_sandbox.vault.store.encryption --> terok_sandbox.vault.store.tiers
    terok_sandbox.vault.store.session_cache --> terok_sandbox.vault.store.kernel_keyring
    terok_sandbox.vault.store.session_cache --> terok_sandbox.vault.store.session_file
    terok_sandbox.vault.store.session_file --> terok_sandbox.vault.store.kernel_keyring
    terok_sandbox.vault.store.recovery --> terok_sandbox._yaml
    terok_sandbox.vault.store.recovery --> terok_sandbox.config
    terok_sandbox.vault.store.recovery --> terok_sandbox.vault.store.encryption
    terok_sandbox.vault.store.recovery --> terok_sandbox.vault.store.tiers
    terok_sandbox.vault.store.status --> terok_sandbox.config
    terok_sandbox.vault.store.status --> terok_sandbox.vault.store.encryption
    terok_sandbox.vault.store.status --> terok_sandbox.vault.store.recovery
    terok_sandbox.vault.store.status --> terok_sandbox.vault.store.tiers
    terok_sandbox.vault.ssh.signer --> terok_sandbox.vault.store.db
    terok_sandbox.vault.ssh.signer --> terok_sandbox.vault.daemon.token_broker
    terok_sandbox.vault.daemon.token_broker --> terok_sandbox.vault.daemon
    terok_sandbox.vault.daemon.token_broker --> terok_sandbox.vault.daemon.audit
    terok_sandbox.vault.daemon.token_broker --> terok_sandbox.vault.store.db
    terok_sandbox.vault.daemon.token_broker --> terok_sandbox.vault.store.encryption
    terok_sandbox.vault.daemon.token_broker --> terok_sandbox.config
    terok_sandbox.gate --> terok_sandbox.gate.server
    terok_sandbox.runtime --> terok_sandbox.config_schema
    terok_sandbox.vault.ssh.manager --> terok_sandbox.vault.ssh.keypair
    terok_sandbox.gate.hooks --> terok_sandbox.gate.mirror
    terok_sandbox.sandbox --> terok_sandbox.setup
    terok_sandbox.sandbox --> terok_sandbox.integrations.shield
    terok_sandbox.commands --> terok_sandbox.setup
    terok_sandbox.commands --> terok_sandbox.commands.credentials
    terok_sandbox.commands --> terok_sandbox.commands.doctor
    terok_sandbox.commands --> terok_sandbox.commands.gate
    terok_sandbox.commands --> terok_sandbox.commands.launch
    terok_sandbox.commands --> terok_sandbox.commands.sandbox
    terok_sandbox.commands --> terok_sandbox.commands.shield
    terok_sandbox.commands --> terok_sandbox.commands.ssh
    terok_sandbox.commands --> terok_sandbox.commands.supervisor
    terok_sandbox.commands --> terok_sandbox.commands.vault
    terok_sandbox.commands.sandbox --> terok_sandbox.setup
    terok_sandbox.commands.sandbox --> terok_sandbox._setup
    terok_sandbox.commands.sandbox --> terok_sandbox._setup_manual
    terok_sandbox.commands.sandbox --> terok_sandbox.commands.credentials
    terok_sandbox.commands.vault --> terok_sandbox.commands.credentials
    terok_sandbox.commands.doctor --> terok_sandbox.launch
    terok_sandbox.commands.launch --> terok_sandbox.launch
    terok_sandbox.commands.supervisor --> terok_sandbox.supervisor
    terok_sandbox.supervisor --> terok_sandbox.resources.hooks._supervisor_state
    terok_sandbox.supervisor --> terok_sandbox.supervisor.main
    terok_sandbox.supervisor --> terok_sandbox.supervisor.sidecar
    terok_sandbox.supervisor --> terok_sandbox.integrations.shield
    terok_sandbox.supervisor --> terok_sandbox.paths
    terok_sandbox.supervisor.main --> terok_sandbox.supervisor.children
    terok_sandbox.supervisor.main --> terok_sandbox.supervisor.launcher
    terok_sandbox.supervisor.main --> terok_sandbox.supervisor.sidecar
    terok_sandbox.supervisor.children --> terok_sandbox.supervisor.sidecar
    terok_sandbox.supervisor.children --> terok_sandbox.integrations.clearance
    terok_sandbox.supervisor.children --> terok_sandbox.vault.daemon.token_broker
    terok_sandbox.supervisor.children --> terok_sandbox.vault.ssh.signer
    terok_sandbox.supervisor.children --> terok_sandbox.gate.hooks
    terok_sandbox.supervisor.children --> terok_sandbox.gate.server
    terok_sandbox.supervisor.children --> terok_sandbox._util._selinux
    terok_sandbox.supervision --> terok_sandbox.supervisor.sidecar
    terok_sandbox.launch --> terok_sandbox.setup
    terok_sandbox.launch --> terok_sandbox.sandbox
    terok_sandbox.launch --> terok_sandbox.integrations.shield
    terok_sandbox._setup --> terok_sandbox.integrations.shield
    terok_sandbox._setup --> terok_sandbox.integrations.clearance
    terok_sandbox._setup --> terok_sandbox.gate.server
    terok_sandbox._setup_manual --> terok_sandbox.setup
    terok_sandbox.cli --> terok_sandbox.commands
    terok_sandbox --> terok_sandbox._setup_manual
    terok_sandbox --> terok_sandbox.resources.hooks._supervisor_state
    terok_sandbox --> terok_sandbox.cli
    terok_sandbox --> terok_sandbox.commands
    terok_sandbox --> terok_sandbox.launch
    terok_sandbox --> terok_sandbox.sandbox
    terok_sandbox._util
    terok_sandbox.resources.hooks._supervisor_state
    terok_sandbox.podman_args
    terok_sandbox.paths
    terok_sandbox._stage
    terok_sandbox.vault.store
    terok_sandbox.vault.store.migrations
    terok_sandbox.vault.store.tiers
    terok_sandbox.vault.store.kernel_keyring
    terok_sandbox.vault.store.systemd_creds
    terok_sandbox.vault.ssh
    terok_sandbox.vault.daemon
    terok_sandbox.vault.daemon.audit
    terok_sandbox.gate.server
    terok_sandbox.integrations.shield
    terok_sandbox.integrations.clearance
    terok_sandbox.gate.tokens
    terok_sandbox.vault.ssh.keypair
    terok_sandbox.gate.mirror
    terok_sandbox.commands._types
    terok_sandbox.operator_cli
    terok_sandbox.commands.gate
    terok_sandbox.commands.shield
    terok_sandbox.commands.ssh
    terok_sandbox.commands.credentials
    terok_sandbox.supervisor.launcher
    terok_sandbox.supervisor.sidecar
    terok_sandbox._yaml
    terok_sandbox._exit_codes

Module Boundaries

63 modules, 101 dependency edges — all boundaries validated.

Module Summary

63 modules (click to expand)
Module Deps Description
terok_sandbox._util 0 Shared repo-local helpers (fs, logging, templates, naming conventions)
terok_sandbox.resources.hooks._supervisor_state 0 reads are one function.
terok_sandbox.podman_args 0 and the freeform-args validators shared by config parsing and launch.
terok_sandbox.paths 0 binders (vault_root, runtime_root, …).
terok_sandbox.port_registry 1 Shared port registry — depends on paths for configurable registry dir
terok_sandbox.setup 3 Sandbox-owned readiness composed downward.
terok_sandbox._stage 0 re-export.
terok_sandbox.config_schema 2 validation, composed by terok-executor and terok into the global config.
terok_sandbox.config 6 standalone sandbox and embedded (terok) paths share one validator.
terok_sandbox.doctor 10 Health check protocol + sandbox-level diagnostics
terok_sandbox.vault 1
terok_sandbox.vault.store 0 Vault.store — at-rest data layer.
terok_sandbox.vault.store.db 3
terok_sandbox.vault.store.migrations 0
terok_sandbox.vault.store.tiers 0 speak it.
terok_sandbox.vault.store.encryption 3
terok_sandbox.vault.store.session_cache 2 file where they don't.
terok_sandbox.vault.store.session_file 1 scope their cache identically.
terok_sandbox.vault.store.kernel_keyring 0 the kernel key-retention service, with no terok-* dependencies.
terok_sandbox.vault.store.recovery 4 WrongPassphraseError while walking the resolver chain.
terok_sandbox.vault.store.status 4 registry; receives SandboxConfig (default-fill cfg=None).
terok_sandbox.vault.store.systemd_creds 0
terok_sandbox.vault.ssh 0 Vault.ssh — keypair I/O + scope manager + agent protocol + sockets.
terok_sandbox.vault.ssh.signer 2
terok_sandbox.vault.daemon 0 Vault.daemon — the long-running process: lifecycle, broker, audit.
terok_sandbox.vault.daemon.token_broker 5
terok_sandbox.vault.daemon.audit 0
terok_sandbox.gate.server 0 only internal import is the SELinux socket-labelling helper (foundation).
terok_sandbox.gate 1 Gate package root
terok_sandbox.runtime 1 Container runtime
terok_sandbox.integrations.shield 0 Shield adapter (cross-package — terok_shield boundary)
terok_sandbox.integrations.clearance 0 Clearance adapter (cross-package — terok_clearance boundary)
terok_sandbox.gate.tokens 0 Gate token minter — no internal imports
terok_sandbox.vault.ssh.manager 1 and the keypair primitives.
terok_sandbox.vault.ssh.keypair 0
terok_sandbox.gate.mirror 0 Git gate mirror management
terok_sandbox.gate.hooks 1 the server only ever receives the resulting path as a plain value.
terok_sandbox.sandbox 2 Sandbox facade
terok_sandbox.commands 10 tuple; the package __init__ assembles COMMANDS from them.
terok_sandbox.commands._types 0 subsystem modules in the surface layer can all import from it.
terok_sandbox.operator_cli 0 so any layer composing operator hints can import it.
terok_sandbox.commands.sandbox 4
terok_sandbox.commands.gate 0
terok_sandbox.commands.shield 0
terok_sandbox.commands.vault 1 commands.sandbox reusing the credentials setup phase.
terok_sandbox.commands.ssh 0
terok_sandbox.commands.doctor 1
terok_sandbox.commands.credentials 0
terok_sandbox.commands.launch 1
terok_sandbox.commands.supervisor 1
terok_sandbox.supervisor 5 config/paths vocabulary both parent and children read.
terok_sandbox.supervisor.main 3 children; no service imports of its own.
terok_sandbox.supervisor.children 7 one process each.
terok_sandbox.supervisor.launcher 0 Child spawn mechanics (Direct + systemd-run scope) — stdlib only.
terok_sandbox.supervisor.sidecar 0 the parent and the children; stdlib only.
terok_sandbox.supervision 1 foundation sidecar-path resolver.
terok_sandbox._yaml 0 Round-trip YAML writer for setup-time config.yml edits.
terok_sandbox.launch 3 and shield rules in one place.
terok_sandbox._setup 3 gate / clearance.
terok_sandbox._setup_manual 1 probe/render inputs are all foundation (implicit).
terok_sandbox._exit_codes 0 API). Zero internal imports.
terok_sandbox.cli 1 CLI entry point — same-layer dep on commands
terok_sandbox 6 Package root — same-layer deps on surface peers

Test Coverage

Overall line coverage: 97.0% (9462/9755 statements).

Each rectangle is a source file. Area is proportional to the number of statements; colour encodes the coverage percentage (green = fully covered, red = uncovered). Files are grouped by the first 3 directory levels.

Cognitive Complexity

Threshold: 15 (functions above this are listed below)

  • Functions analyzed: 991
  • Median complexity: 1 · Average: 2.9 · Max: 52
  • Within threshold (15): 97% (962/991)
    0–  3 │ ██████████████████████████████ 731 (73.8%)
    4–  6 │ ██████                         141 (14.2%)
    7–  9 │ ██                              42 ( 4.2%)
   10– 12 │ █                               29 ( 2.9%)
   13– 15 │ █                               19 ( 1.9%) ◄ threshold
   16– 18 │                                 12 ( 1.2%)
   19– 21 │                                  8 ( 0.8%)
   22– 25 │                                  3 ( 0.3%)
   26+    │                                  6 ( 0.6%)

29 functions exceeding threshold:

Complexity Function File
52 _handle_request src/terok_sandbox/vault/daemon/token_broker.py
51 _stream_initial_logs src/terok_sandbox/runtime/podman.py
43 _handle_ssh_remove src/terok_sandbox/commands/ssh.py
38 _RouteTable::__init__ src/terok_sandbox/vault/daemon/token_broker.py
27 compose src/terok_sandbox/launch.py
27 PortRegistry::_claim_locked src/terok_sandbox/port_registry.py
22 _make_handler_class src/terok_sandbox/gate/server.py
22 PortRegistry::_resolve_service_ports_locked src/terok_sandbox/port_registry.py
22 _serve_agent_session src/terok_sandbox/vault/ssh/signer.py
21 make_stray_sidecar_check src/terok_sandbox/launch.py
21 Sandbox::run src/terok_sandbox/sandbox.py
20 _handle_sandbox_setup src/terok_sandbox/commands/sandbox.py
20 Sandbox::_build_cmd src/terok_sandbox/sandbox.py
19 _print_key_table src/terok_sandbox/commands/ssh.py
19 change_passphrase src/terok_sandbox/commands/vault.py
19 purge_passphrase_tiers src/terok_sandbox/commands/vault.py
19 _nvidia_args src/terok_sandbox/runtime/gpu.py
18 _run_component src/terok_sandbox/_setup_manual.py
18 provision_passphrase_tier src/terok_sandbox/commands/credentials.py
18 _handle_vault_list src/terok_sandbox/commands/vault.py
18 PortRegistry::_read_other_claims src/terok_sandbox/port_registry.py
17 GitGate::sync src/terok_sandbox/gate/mirror.py
17 _amd_args src/terok_sandbox/runtime/gpu.py
17 _intel_args src/terok_sandbox/runtime/gpu.py
17 PodmanContainer::_watch_stop src/terok_sandbox/runtime/podman.py
16 _handle_doctor src/terok_sandbox/commands/doctor.py
16 normalize_gpus src/terok_sandbox/config_schema.py
16 _spawn_supervisor src/terok_sandbox/resources/hooks/supervisor_hook.py
16 _listening_ports src/terok_sandbox/supervision.py

Dead Code Analysis

Confidence Location Issue
100% confidence src/terok_sandbox/cli.py:45 unused variable 'namespace'
100% confidence src/terok_sandbox/cli.py:47 unused variable 'option_string'

Docstring Coverage

  • Needed: 22; Found: 19; Missing: 3; Coverage: 86.4%
  • Needed: 8; Found: 7; Missing: 1; Coverage: 87.5%
  • Needed: 33; Found: 32; Missing: 1; Coverage: 97.0%
  • Needed: 19; Found: 17; Missing: 2; Coverage: 89.5%
  • Needed: 67; Found: 65; Missing: 2; Coverage: 97.0%
  • Needed: 28; Found: 27; Missing: 1; Coverage: 96.4%
  • Needed: 22; Found: 21; Missing: 1; Coverage: 95.5%
  • Needed: 27; Found: 26; Missing: 1; Coverage: 96.3%
  • Needed: 25; Found: 22; Missing: 3; Coverage: 88.0%
  • Needed: 13; Found: 11; Missing: 2; Coverage: 84.6%
  • Needed: 68; Found: 64; Missing: 4; Coverage: 94.1%
  • Needed: 86; Found: 79; Missing: 7; Coverage: 91.9%
  • Needed: 48; Found: 42; Missing: 6; Coverage: 87.5%
  • Needed: 38; Found: 36; Missing: 2; Coverage: 94.7%
  • Needed: 15; Found: 14; Missing: 1; Coverage: 93.3%
  • Needed: 49; Found: 48; Missing: 1; Coverage: 98.0%
  • Needed: 21; Found: 20; Missing: 1; Coverage: 95.2%
  • Needed: 45; Found: 44; Missing: 1; Coverage: 97.8%
  • Needed: 30; Found: 29; Missing: 1; Coverage: 96.7%
  • Needed: 1233 - Found: 1192 - Missing: 41
  • Total coverage: 96.7% - Grade: Excellent

Generated by scc, complexipy, vulture, tach, and docstr-coverage.