Home / Checking what it gives back
What a check exempts disappears from its output
An exemption placed in a check for a good reason removes the exempted part from what the check judges: until that part has its own measure and its own limit, it can grow under a compliant verdict.
Take a typical case. A nightly check compares the disk usage of a project folder to a limit. Its rule exempts the cache/ subfolder, for a reason that held when it was created: its contents regenerate and can be emptied at any time, so it did not deserve an alert. Months later, the disk fills up while the check shows compliant every night.
A scope chosen, then forgotten
The lesson on where you look showed that a verification first finds what it looks at. Here a specific trait is added: the scope was decided once, written into the rule, then nobody rereads it, because the check's output does not mention it. A compliant verdict reads as a verdict on the folder, when it covers the folder minus its cache.
The following demonstration creates its own folder, writes the check, fills the exempted part, then measures the whole folder:
mkdir -p demo-exemption/project/cache demo-exemption/project/docs && cd demo-exemption
printf 'report one\n' > project/docs/report1.txt
printf 'report two\n' > project/docs/report2.txt
cat > check.sh << 'EOF'
#!/bin/sh
# Disk usage of project/, cache/ is exempted by the rule
LIMIT=5000
SIZE=$(find project -path project/cache -prune -o -type f -exec cat {} + | wc -c | tr -d ' ')
echo "Counted usage: $SIZE bytes (limit $LIMIT)"
if [ "$SIZE" -le "$LIMIT" ]; then echo "Verdict: compliant"; else echo "Verdict: over limit"; fi
EOF
sh check.sh
dd if=/dev/zero of=project/cache/index.bin bs=1024 count=50 2>/dev/null
sh check.sh
echo "Actual usage of project/: $(find project -type f -exec cat {} + | wc -c | tr -d ' ') bytes"
Counted usage: 22 bytes (limit 5000)
Verdict: compliant
Counted usage: 22 bytes (limit 5000)
Verdict: compliant
Actual usage of project/: 51222 bytes
The check walks project/ and all its subfolders, and it sets aside project/cache with the -prune option of find. Its verdict does not move when the cache receives a large file, while the measure of the whole folder, taken outside the check, shows that the cache carries most of the usage. 2>/dev/null hides the summary printed by dd. The sum by wc -c measures the contents of the files, not the blocks reserved on disk, which is enough for a gap of this size.
Giving the exempted part a limit
Removing the exemption would bring back the alerts the rule meant to avoid, since the cache always regenerates. But what justified it, negligible contents, no longer holds when the cache carries most of the usage. Displaying its size is not enough: a line under a verdict that stays compliant gets read as little as the rule does. The remedy keeps the cache out of the main limit and gives it its own limit, which weighs on the verdict. It also checks that the exempted folder exists, failing which find would find nothing and the check would show zero bytes. From the same folder:
cat > check.sh << 'EOF'
#!/bin/sh
# Disk usage of project/: cache/ leaves the main limit and gets its own limit
LIMIT=5000
CACHE_LIMIT=20000
SIZE=$(find project -path project/cache -prune -o -type f -exec cat {} + | wc -c | tr -d ' ')
echo "Counted usage: $SIZE bytes (limit $LIMIT)"
VERDICT=compliant
if [ "$SIZE" -gt "$LIMIT" ]; then VERDICT="over limit"; fi
if [ -d project/cache ]; then
EXEMPT=$(find project/cache -type f -exec cat {} + | wc -c | tr -d ' ')
echo "Exempted part: cache/ $EXEMPT bytes (own limit $CACHE_LIMIT)"
if [ "$EXEMPT" -gt "$CACHE_LIMIT" ]; then VERDICT="exempted part over limit"; fi
else
echo "Exempted part: cache/ not found, not measured"
if [ "$VERDICT" = compliant ]; then VERDICT="to check"; fi
fi
echo "Verdict: $VERDICT"
EOF
sh check.sh
Counted usage: 22 bytes (limit 5000)
Exempted part: cache/ 51200 bytes (own limit 20000)
Verdict: exempted part over limit
The check now returns an overrun where it used to say compliant, and it names the part responsible. If cache/ disappears, it says so and returns "to check" rather than a reassuring zero.
What the verdict judges, layer by layer
A nightly check compares the disk usage of a project folder to a limit every night and leaves the cache subfolder out of its calculation, a rule set when it was created. Eleven months later, the server's disk is full. The check showed compliant every night. A measure of the whole folder, cache included, shows that the cache takes up most of it.
Write in one sentence what this situation establishes, and in one sentence what it does not establish.
What this establishes: It establishes that the compliant verdicts covered the folder minus its cache, and that this cache now holds most of the folder's usage.
What this does not establish: It does not establish that the exemption was a mistake when it was set, nor that this folder filled the disk on its own: the measure covers the folder, and the disk also holds the rest of the server.
The three most common miscalibrations
- Too broad The compliant verdicts of the last eleven months were wrong, and the check has measured wrongly since its creation.
- Too narrow The only established fact is the cache's share of the folder on the day of the measure; the compliant verdicts shown every night say nothing about what they covered.
- Beside the point The situation establishes that the program that produces the cache stopped emptying it as it did at the start.
- An exemption written into a check limits the scope of each of its verdicts, even when the output does not say so.
- A compliant verdict covers the counted part and says nothing about the exempted part until that part is measured separately.
- A measure of the whole folder, taken outside the check, reveals a gap that no rerun of the same check will show.
- An exempted part that gets its own limit can change the verdict, which a simple information line under a compliant verdict does not.
- A missing exempted folder must produce a warning, otherwise it measures as zero without anyone noticing.
Open an automatic check that you use, find each exclusion written into its rule, and give each one its own measure and limit that can change the verdict, with an explicit message when the excluded part is missing.