From d6d7b140e148ebbb3a84fce3478b7c85bee6dbae Mon Sep 17 00:00:00 2001 From: Thiago Lugarini Date: Tue, 18 Aug 2026 17:21:31 -0300 Subject: [PATCH] perf(validate): read the cycle already run instead of running another one MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The shortfall accounting launched a second full scan just to read three counters. On the container's real WordPress a full scan costs about eight minutes, and three checks added in one day each doing that took `make validate-engines` from roughly a quarter of an hour to nearly an hour. That matters more than it looks. A validation nobody has an hour for is one that stops being run, and this script's whole value is that it gets run before trusting a scan. Slowness is how it fails in practice — not by being wrong. The counters were already on screen. Since #92 the text report prints each engine's gaps and notes on their own lines, and $scan_output was captured forty lines earlier in the same section. Same cycle, same numbers, no second walk. unknown_rule is deliberately not counted as an excuse for a shortfall: the finding it describes IS in the report, so it explains nothing about one that is missing. Verified against a realistic sample rather than assumed — outside_requested_scope=853 plus vanished_before_hashing=2 sums to 855, and the unknown_rule=260 on the same line stays out of it. Six full scans, now five. The remaining pair in the evasion section is inherent: comparing the terminal against the JSON needs one invocation of each. --- docker/validate-engines.sh | 18 ++++++++++++++---- 1 file changed, 14 insertions(+), 4 deletions(-) diff --git a/docker/validate-engines.sh b/docker/validate-engines.sh index 31608f5..d880f53 100644 --- a/docker/validate-engines.sh +++ b/docker/validate-engines.sh @@ -499,12 +499,22 @@ elif [[ "${n_amw:-0}" -gt 0 ]]; then if [[ "$shortfall" -le 0 ]]; then ok "the orchestrator saw everything AMWScan saw on its own ($orch_amw of $n_amw)" else - scope_json=$(sentinelhost scan --config "$CFG" --full --json 2>/dev/null || true) + # Read from the cycle already run above, rather than running another one. + # + # This used to launch a second full scan just to read three counters. On a real + # WordPress each one costs about eight minutes, and three checks added in one day + # each doing that took `make validate-engines` from a quarter of an hour to nearly an + # hour — long enough that a person stops running it, which is the only way this script + # actually fails. + # + # The counters are in $scan_output already: since #92 the text report prints the + # engine's notes and gaps on their own lines. Same cycle, same numbers, no second walk. + excused_src="$scan_output" # State the evidence before interpreting it: an empty read is not an accounted zero. - if [[ -z "$scope_json" ]]; then - fail "the orchestrator saw $orch_amw of AMWScan's $n_amw and the JSON could not be read to explain the $shortfall missing" + if [[ -z "$excused_src" ]]; then + fail "the orchestrator saw $orch_amw of AMWScan's $n_amw and the cycle output could not be read to explain the $shortfall missing" else - excused=$(printf '%s' "$scope_json" | grep -oE '"(outside_requested_scope|vanished_before_hashing|forged_report_path)":[[:space:]]*[0-9]+' | grep -oE '[0-9]+$' | awk '{t+=$1} END {print t+0}') + excused=$(printf '%s' "$excused_src" | grep -oE '(outside_requested_scope|vanished_before_hashing|forged_report_path)=[0-9]+' | grep -oE '[0-9]+$' | awk '{t+=$1} END {print t+0}') echo " AMWScan alone: $n_amw orchestrator: $orch_amw accounted for: $excused" if [[ "$shortfall" -le "$excused" ]]; then ok "the $shortfall AMWScan finding(s) the orchestrator did not take are accounted for"