chainsaw coverage

Inspect install-coverage measurements (opt-in)

Inspect install-coverage measurements (opt-in)

SubcommandWhat it does
chainsaw coverage bypassTriage ingested bypass-detection reports
    chainsaw coverage bypass confirmConfirm a bypass report (records intent; quarantine on confirm)
    chainsaw coverage bypass dismissDismiss a bypass report as a false alarm (30d suppression)
    chainsaw coverage bypass listList bypass reports above the confidence threshold
chainsaw coverage expectedManage the admin-declared expected install surface
    chainsaw coverage expected addDeclare a client as part of the expected install surface
    chainsaw coverage expected listList declared expected install sources
    chainsaw coverage expected removeRemove a declared expected source by id
chainsaw coverage silentList declared sources with no traffic in the window
chainsaw coverage summaryShow tracked install sources for a window (default 7d)
chainsaw coverage [command]

View tracked install sources, ecosystem breakdown, and clients that have gone silent. Coverage is an opt-in measurement feature — it is purely informational and never blocks installs.

The coverage gate applies to summary, silent and expected: those read /api/coverage/, so when the server has not enabled coverage they print “coverage is not enabled” and stop. “coverage bypass” is NOT behind that gate — it reads /api/bypass/, which is always served, so bypass triage works on a deployment with coverage switched off.

chainsaw coverage bypass

Triage ingested bypass-detection reports

chainsaw coverage bypass [command]

Reads and writes /api/bypass/*, which sits OUTSIDE the coverage gate: bypass triage works even when the server has coverage disabled. Grouped under coverage because a detected bypass is the sharpest form of a coverage hole, not because it shares the gate.

chainsaw coverage bypass confirm

Confirm a bypass report (records intent; quarantine on confirm)

chainsaw coverage bypass confirm <id>

Posts to /api/bypass/reports/{id}/confirm. Not subject to the coverage gate — this works on a server with coverage disabled.

chainsaw coverage bypass dismiss

Dismiss a bypass report as a false alarm (30d suppression)

chainsaw coverage bypass dismiss <id>

Posts to /api/bypass/reports/{id}/dismiss. Not subject to the coverage gate — this works on a server with coverage disabled.

chainsaw coverage bypass list

List bypass reports above the confidence threshold

chainsaw coverage bypass list [flags]

Reads /api/bypass/reports. Not subject to the coverage gate — this works on a server with coverage disabled.

Flags
FlagTypeDefaultDescription
--include-dismissedbool—Include dismissed-and-still-suppressed rows
--jsonbool—Output as JSON
--min-confidencefloat640.7Confidence threshold (0..1)

The global flags apply here too.

chainsaw coverage expected

Manage the admin-declared expected install surface

chainsaw coverage expected [command]

Reads and writes /api/coverage/expected, the admin-declared list of client patterns that SHOULD be installing through chainsaw. Declarative metadata only: nothing here blocks an install. Subject to the coverage gate — prints “coverage is not enabled” when the server has coverage off.

chainsaw coverage expected add

Declare a client as part of the expected install surface

chainsaw coverage expected add <client-pattern> [flags]

Writes to /api/coverage/expected so the pattern can be reported silent when it stops sending traffic. Subject to the coverage gate — prints “coverage is not enabled” when the server has coverage off.

Flags
FlagTypeDefaultDescription
--active-within-daysint7Expected active window for this source

The global flags apply here too.

chainsaw coverage expected list

List declared expected install sources

chainsaw coverage expected list [flags]

Reads /api/coverage/expected. Subject to the coverage gate — prints “coverage is not enabled” when the server has coverage off.

Flags
FlagTypeDefaultDescription
--jsonbool—Output as JSON

The global flags apply here too.

chainsaw coverage expected remove

Remove a declared expected source by id

chainsaw coverage expected remove <id> [flags]

Removes a declared expected install source. Coverage stops counting it as expected, so it can no longer be reported silent. Prompts for confirmation (naming the client pattern, which is what coverage expected add needs to restore it); use –yes to skip the prompt. Subject to the coverage gate — prints “coverage is not enabled” when the server has coverage off.

Flags
FlagTypeDefaultDescription
--yesbool—Skip confirmation prompt (required on non-TTY)

The global flags apply here too.

chainsaw coverage silent

List declared sources with no traffic in the window

chainsaw coverage silent [flags]

Reads /api/coverage/silent: declared expected sources that sent no traffic inside the window. Subject to the coverage gate — prints “coverage is not enabled” when the server has coverage off.

Flags

FlagTypeDefaultDescription
--jsonbool—Output as JSON
--windowstring7dWindow: 7d or 30d

The global flags apply here too.

chainsaw coverage summary

Show tracked install sources for a window (default 7d)

chainsaw coverage summary [flags]

Reads /api/coverage/summary: the install sources seen in the window and their ecosystem breakdown. Subject to the coverage gate — prints “coverage is not enabled” when the server has coverage off.

Flags

FlagTypeDefaultDescription
--jsonbool—Output as JSON
--windowstring7dWindow: 7d or 30d

The global flags apply here too.