Skip to content
Mastering Claude

Home / Checking what it gives back

Checking what it gives back8 minPratique

What a check exempts disappears from its output

An exemption placed in a check for a good reason removes the exempted part from what the check judges: until that part has its own measure and its own limit, it can grow under a compliant verdict.

Take a typical case. A nightly check compares the disk usage of a project folder to a limit. Its rule exempts the cache/ subfolder, for a reason that held when it was created: its contents regenerate and can be emptied at any time, so it did not deserve an alert. Months later, the disk fills up while the check shows compliant every night.

A scope chosen, then forgotten

The lesson on where you look showed that a verification first finds what it looks at. Here a specific trait is added: the scope was decided once, written into the rule, then nobody rereads it, because the check's output does not mention it. A compliant verdict reads as a verdict on the folder, when it covers the folder minus its cache.

The following demonstration creates its own folder, writes the check, fills the exempted part, then measures the whole folder:

mkdir -p demo-exemption/project/cache demo-exemption/project/docs && cd demo-exemption
printf 'report one\n' > project/docs/report1.txt
printf 'report two\n' > project/docs/report2.txt
cat > check.sh << 'EOF'
#!/bin/sh
# Disk usage of project/, cache/ is exempted by the rule
LIMIT=5000
SIZE=$(find project -path project/cache -prune -o -type f -exec cat {} + | wc -c | tr -d ' ')
echo "Counted usage: $SIZE bytes (limit $LIMIT)"
if [ "$SIZE" -le "$LIMIT" ]; then echo "Verdict: compliant"; else echo "Verdict: over limit"; fi
EOF
sh check.sh
dd if=/dev/zero of=project/cache/index.bin bs=1024 count=50 2>/dev/null
sh check.sh
echo "Actual usage of project/: $(find project -type f -exec cat {} + | wc -c | tr -d ' ') bytes"
Counted usage: 22 bytes (limit 5000)
Verdict: compliant
Counted usage: 22 bytes (limit 5000)
Verdict: compliant
Actual usage of project/: 51222 bytes

The check walks project/ and all its subfolders, and it sets aside project/cache with the -prune option of find. Its verdict does not move when the cache receives a large file, while the measure of the whole folder, taken outside the check, shows that the cache carries most of the usage. 2>/dev/null hides the summary printed by dd. The sum by wc -c measures the contents of the files, not the blocks reserved on disk, which is enough for a gap of this size.

Giving the exempted part a limit

Removing the exemption would bring back the alerts the rule meant to avoid, since the cache always regenerates. But what justified it, negligible contents, no longer holds when the cache carries most of the usage. Displaying its size is not enough: a line under a verdict that stays compliant gets read as little as the rule does. The remedy keeps the cache out of the main limit and gives it its own limit, which weighs on the verdict. It also checks that the exempted folder exists, failing which find would find nothing and the check would show zero bytes. From the same folder:

cat > check.sh << 'EOF'
#!/bin/sh
# Disk usage of project/: cache/ leaves the main limit and gets its own limit
LIMIT=5000
CACHE_LIMIT=20000
SIZE=$(find project -path project/cache -prune -o -type f -exec cat {} + | wc -c | tr -d ' ')
echo "Counted usage: $SIZE bytes (limit $LIMIT)"
VERDICT=compliant
if [ "$SIZE" -gt "$LIMIT" ]; then VERDICT="over limit"; fi
if [ -d project/cache ]; then
  EXEMPT=$(find project/cache -type f -exec cat {} + | wc -c | tr -d ' ')
  echo "Exempted part: cache/ $EXEMPT bytes (own limit $CACHE_LIMIT)"
  if [ "$EXEMPT" -gt "$CACHE_LIMIT" ]; then VERDICT="exempted part over limit"; fi
else
  echo "Exempted part: cache/ not found, not measured"
  if [ "$VERDICT" = compliant ]; then VERDICT="to check"; fi
fi
echo "Verdict: $VERDICT"
EOF
sh check.sh
Counted usage: 22 bytes (limit 5000)
Exempted part: cache/ 51200 bytes (own limit 20000)
Verdict: exempted part over limit

The check now returns an overrun where it used to say compliant, and it names the part responsible. If cache/ disappears, it says so and returns "to check" rather than a reassuring zero.

Figure 1

What the verdict judges, layer by layer

Counted usage
All of project/ except cache/, compared to the limit: the only layer the verdict judges.
Exempted usage
The contents of cache/, set aside by the rule for a valid reason, which grows without changing the verdict.
Disk usage
The sum of the two layers and of the rest of the server, which the check never claimed to measure.
The verdict of the first check judges only the bottom layer; the exempted layer only weighs on it from the moment it gets its own limit.
Calibrate it yourself

A nightly check compares the disk usage of a project folder to a limit every night and leaves the cache subfolder out of its calculation, a rule set when it was created. Eleven months later, the server's disk is full. The check showed compliant every night. A measure of the whole folder, cache included, shows that the cache takes up most of it.

Write in one sentence what this situation establishes, and in one sentence what it does not establish.

What to remember
  • An exemption written into a check limits the scope of each of its verdicts, even when the output does not say so.
  • A compliant verdict covers the counted part and says nothing about the exempted part until that part is measured separately.
  • A measure of the whole folder, taken outside the check, reveals a gap that no rerun of the same check will show.
  • An exempted part that gets its own limit can change the verdict, which a simple information line under a compliant verdict does not.
  • A missing exempted folder must produce a warning, otherwise it measures as zero without anyone noticing.
Do this now

Open an automatic check that you use, find each exclusion written into its rule, and give each one its own measure and limit that can change the verdict, with an explicit message when the excluded part is missing.