Skip IDS reads when no rule matches name and occurrence - #26
Open
chupakobra6 wants to merge 1 commit into
Open
chupakobra6 wants to merge 1 commit into
chupakobra6 wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related to #10.
find_matching_rules()loads every populated IDS occurrence before checking whether any selected rule can use it. A rule targeting onlycore_profiles:3therefore also reads unrelated data, and an unrelated load error can stop that validation.Select candidates by IDS name and occurrence before calling
DBEntry.get(). Keep version filtering after loading: withautoconvert=False, a stored IDS can have a different DD version from the entry's factory. Additional inputs to cross-IDS rules still load on demand, and wildcard rules retain their existing behavior. Document these loading boundaries.Validation:
develop, 13 of these cases fail; all pass with this change.22eb4cd): 287 passed, 3 expected skips on each of Linux arm64/Python 3.10–3.14.The benefit is avoiding unnecessary reads in filtered workloads. Generic wildcard rules can still require every IDS; this does not accelerate reads that are actually needed or claim to resolve the complete performance problem in #10.