Skip to content

perf(rules): optimize ruleset scope partitioning - #3183

Open
tryhard-26 wants to merge 1 commit into
mandiant:masterfrom
tryhard-26:perf/optimization-fix
Open

tryhard-26 wants to merge 1 commit into
mandiant:masterfrom
tryhard-26:perf/optimization-fix

Conversation

@tryhard-26

@tryhard-26 tryhard-26 commented Oct 2, 2026 •

Copy link
Copy Markdown

during ruleset initialization in capa.rules, _get_rules_for_scope was called separately for all 8 scopes. inside that loop, it iterated over every non-subscope rule and invoked get_rules_and_dependencies, which rebuilt index_rules_by_namespace and the rule dictionary from scratch on every call. across the default 1,054 rule files (1,397 rules in memory), this triggered 8,440 redundant namespace index builds and repeated full dependency traversals, followed by 8 separate topologically_order_rules sorts on the same rule set. this created an o(scopes * rules^2) bottleneck that added roughly 3.5 seconds of overhead to every ruleset instantiation.

this change adds _get_rules_by_scope to traverse the dependency graph and topologically sort reachable rules in a single pass across all scopes, then slices each scope from that pre-ordered list. get_rules_and_dependencies and topologically_order_rules now accept optional pre-indexed namespace and name mappings to avoid redundant dictionary allocations.

benchmarked across the default 1,054 rule files (1,397 rules in memory) in an identical harness:

metric before after speedup
scope rule partitioning 3,540.5 ms 7.5 ms 472.1x
total ruleset init 3,580.8 ms 46.7 ms 76.7x

a new regression test verifies that per-scope rule membership and topological dependency order invariants hold across the full ruleset.

  • No CHANGELOG update needed

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please add bug fixes, new features, breaking changes and anything else you think is worthwhile mentioning to the master (unreleased) section of CHANGELOG.md. If no CHANGELOG update is needed add the following to the PR description: [x] No CHANGELOG update needed

@github-actions
github-actions Bot dismissed their stale review October 2, 2026 07:10

CHANGELOG updated or no update needed, thanks! 😄

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant