fix: say whether a sample was examined or excluded

The summary counted every sample that was not vulnerable as clean, which
included files a stage had excluded before any analysis ran. On a real
driver pack that put 950 files that are not kernel drivers, and were never
looked at, in the same count as drivers that were analysed and came back
clear.

Those are now separate: 'Clear' means analysed all the way through with
nothing flagged, and 'Filtered out' means a stage excluded it, naming the
stage that did so.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
416rehman
2026-07-25 10:19:57 -06:00
co-authored by Claude Opus 5
parent 1ff9f7c79e
commit a2b471ec4d
2 changed files with 10 additions and 10 deletions
+7 -7
View File
@@ -64,16 +64,16 @@ _BUCKET_LABELS = {
BUCKET_SUSPICIOUS: "Needs review",
BUCKET_FAILED: "Errored",
BUCKET_UNASSESSED: "Not assessed",
BUCKET_FILTERED: "Set aside",
BUCKET_CLEAN: "No findings",
BUCKET_FILTERED: "Filtered out",
BUCKET_CLEAN: "Clear",
}
_BUCKET_HELP = {
BUCKET_VULNERABLE: "an assessment stage concluded these are vulnerable",
BUCKET_SUSPICIOUS: "findings exist but no assessment confirmed them",
BUCKET_FAILED: "a stage errored, so these were never fully analysed",
BUCKET_UNASSESSED: "assessed but the verdict could not be classified",
BUCKET_FILTERED: "a stage excluded these, so later stages never saw them",
BUCKET_CLEAN: "analysed to the end and nothing was flagged",
BUCKET_FILTERED: "a stage excluded these, so the later stages never saw them",
BUCKET_CLEAN: "analysed all the way through and nothing was flagged",
}
# keys worth promoting into the summary table when a pipeline declares no columns
@@ -872,8 +872,8 @@ def render_index(payload: dict[str, Any], out_dir: Path, *, table_limit: int = 5
("pos", n_pos, "vulnerable"),
("rev", n_rev, "needs review"),
("err", n_err, "errored"),
("ok", n_ok, "no findings"),
("set", n_set, "set aside"),
("ok", n_ok, "clear"),
("set", n_set, "filtered out"),
)
)
@@ -939,7 +939,7 @@ def render_index(payload: dict[str, Any], out_dir: Path, *, table_limit: int = 5
f"{n:,} at {_esc(k)}" for k, n in sorted(by_stage.items(), key=lambda kv: -kv[1])
)
sections += (
f"<section><div class='shead q'><h2>Set aside</h2>"
f"<section><div class='shead q'><h2>Filtered out</h2>"
f"<span class='n'>{n_set:,}</span>"
f"<span class='of'>{_esc(_BUCKET_HELP[BUCKET_FILTERED])}</span></div>"
f"<p class='aside'>These were excluded before the analysis finished, so they are "
+3 -3
View File
@@ -344,7 +344,7 @@ class TestPipelineAgnostic:
assert f["line"] == 88
class TestSetAsideIsNotCalledClean:
class TestFilteredOutIsNotCalledClear:
"""a sample a stage excluded was never analysed to the end, so it must not be
counted alongside ones that were analysed and had nothing flagged."""
@@ -384,6 +384,6 @@ class TestSetAsideIsNotCalledClean:
def test_the_page_does_not_call_them_clean(self, tmp_path):
out = render_index(collect(self._run(tmp_path)), tmp_path)
assert "no findings" in out
assert "Set aside" in out
assert "clear" in out
assert "Filtered out" in out
assert "not a judgement" in out