Skip to content

Code Metrics

Generated: 2026-09-29 06:33 UTC


Lines of Code

Files Code Comment Blank Total
Source 64 8 302 2 191 687 11 180
Tests 104 17 884 1 860 1 977 21 721
Combined 168 26 186 4 051 2 664 32 901
  • Comment/code ratio: 26%
  • Test/source ratio: 215.4%
Source by module (click to expand)
Module Files Code Comment Blank
terok_shield/ 64 8 302 2 191 687
terok_shield/cli/ 3 475 63 28
terok_shield/cli/__main__.py — 8 11 2
terok_shield/cli/main.py — 467 43 25
terok_shield/dns/ 4 583 145 34
terok_shield/dns/apparmor.py — 34 38 4
terok_shield/dns/dnsmasq.py — 314 74 26
terok_shield/dns/resolver.py — 235 25 3
terok_shield/hooks/ 4 1 112 317 76
terok_shield/hooks/install.py — 314 37 32
terok_shield/hooks/mode.py — 774 251 39
terok_shield/hooks/reader_install.py — 24 21 4
terok_shield/nft/ 3 657 138 35
terok_shield/nft/constants.py — 33 45 12
terok_shield/nft/rules.py — 624 85 22
terok_shield/podman_info/ 5 169 131 36
terok_shield/podman_info/__init__.py — 19 15 3
terok_shield/podman_info/_conf.py — 13 13 1
terok_shield/podman_info/hooks_dir.py — 42 38 4
terok_shield/podman_info/info.py — 55 41 17
terok_shield/podman_info/network.py — 40 24 11
terok_shield/resources/ 13 2 078 355 162
terok_shield/resources/examples/ 7 101 3 24
terok_shield/resources/_oci_state.py — 489 62 27
terok_shield/resources/nflog_reader.py — 901 145 49
terok_shield/resources/nft_hook.py — 177 59 29
terok_shield/resources/reader_hook.py — 269 65 24
terok_shield/resources/shield_probe.py — 141 18 8
terok_shield/verbs/ 6 390 105 13
terok_shield/verbs/__init__.py — 10 8 1
terok_shield/verbs/_common.py — 51 16 7
terok_shield/verbs/control.py — 159 19 2
terok_shield/verbs/launch.py — 54 14 1
terok_shield/verbs/observe.py — 82 26 1
terok_shield/verbs/stream.py — 34 22 1
terok_shield/watchers/ 6 355 146 50
terok_shield/watchers/__init__.py — 12 14 3
terok_shield/watchers/_event.py — 29 17 7
terok_shield/watchers/audit_log.py — 41 16 9
terok_shield/watchers/dns_log.py — 64 26 16
terok_shield/watchers/domain_cache.py — 20 17 9
terok_shield/watchers/nflog.py — 189 56 6
terok_shield/__init__.py — 418 97 21
terok_shield/_confine.py — 33 19 4
terok_shield/_hub_events.py — 100 54 9
terok_shield/_wire_sanitize.py — 41 23 6
terok_shield/audit.py — 50 37 12
terok_shield/commands.py — 115 8 2
terok_shield/config.py — 218 78 21
terok_shield/config_file.py — 37 24 2
terok_shield/container.py — 162 31 4
terok_shield/paths.py — 34 20 3
terok_shield/policy.py — 177 27 10
terok_shield/prereqs.py — 29 34 14
terok_shield/profiles.py — 45 44 13
terok_shield/run.py — 262 28 15
terok_shield/simple_clearance.py — 239 47 38
terok_shield/state.py — 395 123 30
terok_shield/subprocess_env.py — 15 15 2
terok_shield/util.py — 21 6 8
terok_shield/validation.py — 22 37 13
terok_shield/watch.py — 70 39 26

Architecture

Module Dependency Graph

graph TD
    terok_shield.podman_info --> terok_shield.nft.constants
    terok_shield.state --> terok_shield.config
    terok_shield.state --> terok_shield.policy
    terok_shield.state --> terok_shield.resources._oci_state
    terok_shield._hub_events --> terok_shield._wire_sanitize
    terok_shield._hub_events --> terok_shield.validation
    terok_shield.dns.apparmor --> terok_shield.dns.dnsmasq
    terok_shield.hooks.install --> terok_shield.hooks.reader_install
    terok_shield.hooks.mode --> terok_shield.dns.apparmor
    terok_shield.hooks.mode --> terok_shield.dns.dnsmasq
    terok_shield.hooks.mode --> terok_shield.hooks.install
    terok_shield.hooks.mode --> terok_shield.nft.rules
    terok_shield --> terok_shield.audit
    terok_shield --> terok_shield.profiles
    terok_shield --> terok_shield.watchers
    terok_shield.cli --> terok_shield.config_file
    terok_shield.config
    terok_shield.util
    terok_shield.validation
    terok_shield.policy
    terok_shield.resources._oci_state
    terok_shield.paths
    terok_shield.run
    terok_shield.prereqs
    terok_shield._wire_sanitize
    terok_shield.nft
    terok_shield.nft.constants
    terok_shield.nft.rules
    terok_shield.dns
    terok_shield.dns.resolver
    terok_shield.dns.dnsmasq
    terok_shield.hooks
    terok_shield.hooks.reader_install
    terok_shield.audit
    terok_shield.profiles
    terok_shield.watchers
    terok_shield.config_file

Module Boundaries

29 modules, 16 dependency edges — all boundaries validated.

Module Summary

29 modules (click to expand)
Module Deps Description
terok_shield.config 0
terok_shield.util 0
terok_shield.validation 0
terok_shield.podman_info 1
terok_shield.policy 0 Unified +/- policy line format — stdlib-only parser, importable anywhere
terok_shield.resources._oci_state 0 package side imports its bundle filenames and process matching from it
terok_shield.state 3 Per-container state bundle layout — imports host-wide path constants
terok_shield.paths 0 Host-wide filesystem paths (reader script, hook entrypoint filename)
terok_shield.run 0 Subprocess helpers — zero internal deps
terok_shield.prereqs 0 (terok-sandbox aggregator, operator diagnostics). Uses the shared terok-util host tool lookup.
terok_shield._hub_events 2 Hub event emitter — stdlib-only client for the terok-clearance unix ingester
terok_shield._wire_sanitize 0 bypasses the package) can mirror the function inline.
terok_shield.nft 0 nft domain package
terok_shield.nft.constants 0 Security boundary — literals only, no dependencies
terok_shield.nft.rules 0 Security boundary — only stdlib + nft.constants
terok_shield.dns 0 dns domain package
terok_shield.dns.resolver 0 DNS resolution and caching
terok_shield.dns.dnsmasq 0 dnsmasq lifecycle — config generation, launch, cleanup
terok_shield.dns.apparmor 1 AppArmor confinement probe + dnsmasq-tier selection
terok_shield.hooks 0 hooks domain package
terok_shield.hooks.install 1 the OCI hook needs (entrypoint, both hook-JSON pairs, reader script).
terok_shield.hooks.reader_install 0 NFLOG reader resource installer
terok_shield.hooks.mode 4 Hook mode — OCI hooks, per-container netns
terok_shield.audit 0 Audit logging — no internal deps
terok_shield.profiles 0 Profile loading
terok_shield.watchers 0 Watchers — event-stream classes
terok_shield 3 Package root — public API facade
terok_shield.config_file 0 pull in pydantic; the sole importer is cli/main.py.
terok_shield.cli 1

Test Coverage

Overall line coverage: 99.2% (3965/3977 statements).

Each rectangle is a source file. Area is proportional to the number of statements; colour encodes the coverage percentage (green = fully covered, red = uncovered). Files are grouped by the first 3 directory levels.

Cognitive Complexity

Threshold: 15 (functions above this are listed below)

  • Functions analyzed: 484
  • Median complexity: 1.0 · Average: 2.4 · Max: 15
  • Within threshold (15): 100% (484/484)
    0–  3 │ ██████████████████████████████ 363 (75.0%)
    4–  6 │ ██████                          74 (15.3%)
    7–  9 │ ██                              26 ( 5.4%)
   10– 12 │ █                               17 ( 3.5%)
   13– 15 │                                  4 ( 0.8%) ◄ threshold

All functions are within the cognitive complexity threshold of 15.

Dead Code Analysis

No dead code found at 80% confidence threshold.

Docstring Coverage

  • Needed: 20; Found: 18; Missing: 2; Coverage: 90.0%
  • Needed: 590 - Found: 588 - Missing: 2
  • Total coverage: 99.7% - Grade: Excellent

Generated by scc, complexipy, vulture, tach, and docstr-coverage.