# Code Review Report ## Scope - Reviewed Python sources under `src/vlm/`, tests under `tests/`, and docs (`README.md`, `AGENTS.md`). - Executed test runs on February 9, 2026: - `pytest -q` - `pytest -q --ignore=tests/test_executor.py --ignore=tests/test_quarantine.py` ## Summary - Found 4 actionable issues: 2 high-priority functional problems, 1 medium-priority data correctness issue, and 1 low-priority observability issue. - Markdown docs are generally clear; no blocking doc defects were found. ## Findings ### P1 - CLI startup fails when log path is not writable - Files: `src/vlm/logging_config.py:63`, `src/vlm/logging_config.py:87` - `setup_logging()` unconditionally creates the log directory and rotating file handler. - In restricted environments, this raises `PermissionError` and aborts CLI initialization (including read-only commands like `--help`). - Impact: broad command/test failure in CI/sandbox/service-user contexts. ### P1 - Test imports use wrong module path - Files: - `tests/test_executor.py:13` - `tests/test_executor.py:14` - `tests/test_quarantine.py:8` - `tests/test_quarantine.py:9` - `tests/test_quarantine.py:10` - Tests import `src.vlm...` instead of package imports `vlm...`, causing collection failure (`ModuleNotFoundError: No module named 'src'`). ### P2 - Timestamp conversion is incorrect for naive datetimes - Files: `src/vlm/scanner.py:148`, `src/vlm/scanner.py:379`, `src/vlm/scanner.py:437` - Naive local timestamps are later relabeled as UTC via `replace(tzinfo=timezone.utc)` instead of converted. - Impact: exported timestamps can be shifted by local timezone offset. ### P3 - Scan error counter is dead code - Files: `src/vlm/scanner.py:53`, `src/vlm/scanner.py:64` - `error_count` is initialized/reported but never incremented. - Impact: scan summary underreports error conditions. ## Test Evidence - `pytest -q` failed at collection due to `src.vlm` imports in two test files. - `pytest -q --ignore=tests/test_executor.py --ignore=tests/test_quarantine.py` reported 34 failures, dominated by logging startup failure: - `PermissionError: [Errno 1] Operation not permitted: '/Users/windy/.vlm/logs/vlm.log'` ## Recommended Fix Order 1. Make logging setup fault-tolerant (fallback to console-only logging). 2. Correct test imports to `vlm...`. 3. Fix timezone handling for inventory timestamps. 4. Wire scan exception paths to increment `error_count`.