Code Metrics¶
Generated: 2026-09-29 06:33 UTC
Lines of Code¶
| Files | Code | Comment | Blank | Total | |
|---|---|---|---|---|---|
| Source | 64 | 8 302 | 2 191 | 687 | 11 180 |
| Tests | 104 | 17 884 | 1 860 | 1 977 | 21 721 |
| Combined | 168 | 26 186 | 4 051 | 2 664 | 32 901 |
- Comment/code ratio: 26%
- Test/source ratio: 215.4%
Source by module (click to expand)
| Module | Files | Code | Comment | Blank |
|---|---|---|---|---|
terok_shield/ |
64 | 8 302 | 2 191 | 687 |
terok_shield/cli/ |
3 | 475 | 63 | 28 |
terok_shield/cli/__main__.py |
— | 8 | 11 | 2 |
terok_shield/cli/main.py |
— | 467 | 43 | 25 |
terok_shield/dns/ |
4 | 583 | 145 | 34 |
terok_shield/dns/apparmor.py |
— | 34 | 38 | 4 |
terok_shield/dns/dnsmasq.py |
— | 314 | 74 | 26 |
terok_shield/dns/resolver.py |
— | 235 | 25 | 3 |
terok_shield/hooks/ |
4 | 1 112 | 317 | 76 |
terok_shield/hooks/install.py |
— | 314 | 37 | 32 |
terok_shield/hooks/mode.py |
— | 774 | 251 | 39 |
terok_shield/hooks/reader_install.py |
— | 24 | 21 | 4 |
terok_shield/nft/ |
3 | 657 | 138 | 35 |
terok_shield/nft/constants.py |
— | 33 | 45 | 12 |
terok_shield/nft/rules.py |
— | 624 | 85 | 22 |
terok_shield/podman_info/ |
5 | 169 | 131 | 36 |
terok_shield/podman_info/__init__.py |
— | 19 | 15 | 3 |
terok_shield/podman_info/_conf.py |
— | 13 | 13 | 1 |
terok_shield/podman_info/hooks_dir.py |
— | 42 | 38 | 4 |
terok_shield/podman_info/info.py |
— | 55 | 41 | 17 |
terok_shield/podman_info/network.py |
— | 40 | 24 | 11 |
terok_shield/resources/ |
13 | 2 078 | 355 | 162 |
terok_shield/resources/examples/ |
7 | 101 | 3 | 24 |
terok_shield/resources/_oci_state.py |
— | 489 | 62 | 27 |
terok_shield/resources/nflog_reader.py |
— | 901 | 145 | 49 |
terok_shield/resources/nft_hook.py |
— | 177 | 59 | 29 |
terok_shield/resources/reader_hook.py |
— | 269 | 65 | 24 |
terok_shield/resources/shield_probe.py |
— | 141 | 18 | 8 |
terok_shield/verbs/ |
6 | 390 | 105 | 13 |
terok_shield/verbs/__init__.py |
— | 10 | 8 | 1 |
terok_shield/verbs/_common.py |
— | 51 | 16 | 7 |
terok_shield/verbs/control.py |
— | 159 | 19 | 2 |
terok_shield/verbs/launch.py |
— | 54 | 14 | 1 |
terok_shield/verbs/observe.py |
— | 82 | 26 | 1 |
terok_shield/verbs/stream.py |
— | 34 | 22 | 1 |
terok_shield/watchers/ |
6 | 355 | 146 | 50 |
terok_shield/watchers/__init__.py |
— | 12 | 14 | 3 |
terok_shield/watchers/_event.py |
— | 29 | 17 | 7 |
terok_shield/watchers/audit_log.py |
— | 41 | 16 | 9 |
terok_shield/watchers/dns_log.py |
— | 64 | 26 | 16 |
terok_shield/watchers/domain_cache.py |
— | 20 | 17 | 9 |
terok_shield/watchers/nflog.py |
— | 189 | 56 | 6 |
terok_shield/__init__.py |
— | 418 | 97 | 21 |
terok_shield/_confine.py |
— | 33 | 19 | 4 |
terok_shield/_hub_events.py |
— | 100 | 54 | 9 |
terok_shield/_wire_sanitize.py |
— | 41 | 23 | 6 |
terok_shield/audit.py |
— | 50 | 37 | 12 |
terok_shield/commands.py |
— | 115 | 8 | 2 |
terok_shield/config.py |
— | 218 | 78 | 21 |
terok_shield/config_file.py |
— | 37 | 24 | 2 |
terok_shield/container.py |
— | 162 | 31 | 4 |
terok_shield/paths.py |
— | 34 | 20 | 3 |
terok_shield/policy.py |
— | 177 | 27 | 10 |
terok_shield/prereqs.py |
— | 29 | 34 | 14 |
terok_shield/profiles.py |
— | 45 | 44 | 13 |
terok_shield/run.py |
— | 262 | 28 | 15 |
terok_shield/simple_clearance.py |
— | 239 | 47 | 38 |
terok_shield/state.py |
— | 395 | 123 | 30 |
terok_shield/subprocess_env.py |
— | 15 | 15 | 2 |
terok_shield/util.py |
— | 21 | 6 | 8 |
terok_shield/validation.py |
— | 22 | 37 | 13 |
terok_shield/watch.py |
— | 70 | 39 | 26 |
Architecture¶
Module Dependency Graph¶
graph TD
terok_shield.podman_info --> terok_shield.nft.constants
terok_shield.state --> terok_shield.config
terok_shield.state --> terok_shield.policy
terok_shield.state --> terok_shield.resources._oci_state
terok_shield._hub_events --> terok_shield._wire_sanitize
terok_shield._hub_events --> terok_shield.validation
terok_shield.dns.apparmor --> terok_shield.dns.dnsmasq
terok_shield.hooks.install --> terok_shield.hooks.reader_install
terok_shield.hooks.mode --> terok_shield.dns.apparmor
terok_shield.hooks.mode --> terok_shield.dns.dnsmasq
terok_shield.hooks.mode --> terok_shield.hooks.install
terok_shield.hooks.mode --> terok_shield.nft.rules
terok_shield --> terok_shield.audit
terok_shield --> terok_shield.profiles
terok_shield --> terok_shield.watchers
terok_shield.cli --> terok_shield.config_file
terok_shield.config
terok_shield.util
terok_shield.validation
terok_shield.policy
terok_shield.resources._oci_state
terok_shield.paths
terok_shield.run
terok_shield.prereqs
terok_shield._wire_sanitize
terok_shield.nft
terok_shield.nft.constants
terok_shield.nft.rules
terok_shield.dns
terok_shield.dns.resolver
terok_shield.dns.dnsmasq
terok_shield.hooks
terok_shield.hooks.reader_install
terok_shield.audit
terok_shield.profiles
terok_shield.watchers
terok_shield.config_file
Module Boundaries¶
29 modules, 16 dependency edges — all boundaries validated.
Module Summary¶
29 modules (click to expand)
| Module | Deps | Description |
|---|---|---|
terok_shield.config |
0 | |
terok_shield.util |
0 | |
terok_shield.validation |
0 | |
terok_shield.podman_info |
1 | |
terok_shield.policy |
0 | Unified +/- policy line format — stdlib-only parser, importable anywhere |
terok_shield.resources._oci_state |
0 | package side imports its bundle filenames and process matching from it |
terok_shield.state |
3 | Per-container state bundle layout — imports host-wide path constants |
terok_shield.paths |
0 | Host-wide filesystem paths (reader script, hook entrypoint filename) |
terok_shield.run |
0 | Subprocess helpers — zero internal deps |
terok_shield.prereqs |
0 | (terok-sandbox aggregator, operator diagnostics). Uses the shared terok-util host tool lookup. |
terok_shield._hub_events |
2 | Hub event emitter — stdlib-only client for the terok-clearance unix ingester |
terok_shield._wire_sanitize |
0 | bypasses the package) can mirror the function inline. |
terok_shield.nft |
0 | nft domain package |
terok_shield.nft.constants |
0 | Security boundary — literals only, no dependencies |
terok_shield.nft.rules |
0 | Security boundary — only stdlib + nft.constants |
terok_shield.dns |
0 | dns domain package |
terok_shield.dns.resolver |
0 | DNS resolution and caching |
terok_shield.dns.dnsmasq |
0 | dnsmasq lifecycle — config generation, launch, cleanup |
terok_shield.dns.apparmor |
1 | AppArmor confinement probe + dnsmasq-tier selection |
terok_shield.hooks |
0 | hooks domain package |
terok_shield.hooks.install |
1 | the OCI hook needs (entrypoint, both hook-JSON pairs, reader script). |
terok_shield.hooks.reader_install |
0 | NFLOG reader resource installer |
terok_shield.hooks.mode |
4 | Hook mode — OCI hooks, per-container netns |
terok_shield.audit |
0 | Audit logging — no internal deps |
terok_shield.profiles |
0 | Profile loading |
terok_shield.watchers |
0 | Watchers — event-stream classes |
terok_shield |
3 | Package root — public API facade |
terok_shield.config_file |
0 | pull in pydantic; the sole importer is cli/main.py. |
terok_shield.cli |
1 |
Test Coverage¶
Overall line coverage: 99.2% (3965/3977 statements).
Each rectangle is a source file. Area is proportional to the number of statements; colour encodes the coverage percentage (green = fully covered, red = uncovered). Files are grouped by the first 3 directory levels.
Cognitive Complexity¶
Threshold: 15 (functions above this are listed below)
- Functions analyzed: 484
- Median complexity: 1.0 · Average: 2.4 · Max: 15
- Within threshold (15): 100% (484/484)
0– 3 │ ██████████████████████████████ 363 (75.0%)
4– 6 │ ██████ 74 (15.3%)
7– 9 │ ██ 26 ( 5.4%)
10– 12 │ █ 17 ( 3.5%)
13– 15 │ 4 ( 0.8%) ◄ threshold
All functions are within the cognitive complexity threshold of 15.
Dead Code Analysis¶
No dead code found at 80% confidence threshold.
Docstring Coverage¶
- Needed: 20; Found: 18; Missing: 2; Coverage: 90.0%
- Needed: 590 - Found: 588 - Missing: 2
- Total coverage: 99.7% - Grade: Excellent
Generated by scc, complexipy, vulture, tach, and docstr-coverage.