Potential errors#
Potential errors of the tool, derived from the use cases with the HazOp guide words invalid, changed, more and less applied to inputs, outputs and actions. The dangerous direction for a coverage tool is always more coverage than real: an error in that direction hides a verification gap. Errors towards less coverage cost effort but no safety.
Tool impact is high when the error can make a violated structural-coverage requirement go undetected. Detection before qualification describes what a user could notice without the mitigations; the last column lists the tool requirements and constraints of use that mitigate the error.
Id |
Error |
Impact |
Detection |
Mitigation |
|---|---|---|---|---|
ERR-01 |
An in-scope file is silently missing from the report (the scope aspect
misses a dependency, a |
high |
weak |
Transitive in-workspace sou... (tool_req__coverage_scope_transitive), Baseline objects accompany ... (tool_req__coverage_scope_baseline_objects), Untested in-scope files app... (tool_req__coverage_report_baseline_zero), CSTR-02, CSTR-08 |
ERR-02 |
A line or branch is reported covered although it was never executed (stale profile data, wrong object, wrong test merged, clashing instrumentation of shared objects). |
high |
none |
Per-test profiles are merge... (tool_req__coverage_merge_profraw), One merged profile for all ... (tool_req__coverage_report_merged_profile), Ground-truth validation (tool_req__coverage_validation_ground_truth), CSTR-05 |
ERR-03 |
The gate passes although the threshold is not met (rounding, parsing, unset or malformed threshold, tool failure mistaken for a pass). |
high |
none |
Threshold from the environment (tool_req__coverage_gate_threshold), Unrounded comparison (tool_req__coverage_gate_unrounded), Exit codes (tool_req__coverage_gate_exit_codes), Broken input yields no verdict (tool_req__coverage_gate_no_verdict), CSTR-10 |
ERR-04 |
A justification is applied to the wrong lines, to a file with the same name, or a stale marker is counted as covered. |
high |
weak |
In-code markers (tool_req__coverage_just_markers), Unknown marker ids do not j... (tool_req__coverage_just_unknown_id), Stale justifications are re... (tool_req__coverage_eff_stale), Justifications match files ... (tool_req__coverage_eff_path_match), CSTR-07 |
ERR-05 |
The effective metric overstates coverage (justified and covered lines double counted, rounding up). |
medium |
weak |
Effective coverage metric (tool_req__coverage_eff_metric), Branch-only justifications (tool_req__coverage_eff_branch_only) |
ERR-06 |
Path normalisation maps two source files onto one record. |
medium |
weak |
Report paths are workspace-... (tool_req__coverage_report_relative_paths), Justifications match files ... (tool_req__coverage_eff_path_match) |
ERR-07 |
A Rust rlib is skipped, so its crate appears complete by absence. |
high |
none |
Baseline archives are reduc... (tool_req__coverage_report_rlib_expansion), Ground-truth validation (tool_req__coverage_validation_ground_truth), CSTR-08 |
ERR-08 |
The wrong toolchain wins resolution; gcov data is silently mixed in or dropped. |
high |
weak |
Broken input yields no verdict (tool_req__coverage_gate_no_verdict), CSTR-01, CSTR-03, CSTR-04 |
ERR-09 |
The report is regenerated from stale data or unpinned tool versions. |
low |
good |
Artifacts tree (tool_req__coverage_artifacts), CSTR-06, CSTR-09 |
ERR-10 |
Coverage is reported too low (false gaps). |
none |
good |
Informational; costs review effort only. |
ERR-11 |
gcov backend: a test’s counters are lost or attributed to the wrong file (transport from the target fails silently, per-test records merged with the wrong semantics, the baseline overwrites test data). |
high |
weak |
gcov backend merges per-tes... (tool_req__coverage_gcov_merge), gcov backend baseline from ... (tool_req__coverage_gcov_baseline), Ground-truth validation (tool_req__coverage_validation_ground_truth), CSTR-11 |
ERR-12 |
gcov backend: an in-scope translation unit has no counters and no notes file is found, so it disappears instead of showing 0 %. |
high |
weak |
gcno notes files accompany ... (tool_req__coverage_scope_gcno), gcov backend baseline from ... (tool_req__coverage_gcov_baseline), In-scope files without any ... (tool_req__coverage_report_unmapped), CSTR-08 |
ERR-13 |
Both backends: Bazel’s guessed |
low (coverage is under-reported, the safe direction; costs review effort and hides the real state on QNX) |
good |
Instrumentation filter hint (tool_req__coverage_instrumentation_hint), Ground-truth validation (tool_req__coverage_validation_ground_truth), user manual step 4 (the filter line) |
Classification#
Tool impact: yes. An error in the more coverage than real direction lets a violation of the structural-coverage verification requirement go undetected. Tool error detection before qualification: no for ERR-02, ERR-03 and ERR-07; weak for ERR-11 and ERR-12 (a lost per-test record on QNX is only noticed by comparing against the Linux report); ERR-13 under-reports and is detected by the reporters’ warning and the integration test. The expected tool confidence level is therefore TCL LOW, and the qualification method of the S-CORE process, validation of the software tool, applies. The evaluation itself is recorded in the Tool Verification Report.