From 5da3df76bec6fcfc3e61e6c30d5c25ead05b275d Mon Sep 17 00:00:00 2001 From: fadwen <110697945+fadwen@users.noreply.github.com> Date: Mon, 5 Oct 2026 22:01:41 -0700 Subject: [PATCH] perf(validation): Collect moves its payload in one guest agent call, gzipped The payload went through 179 guest exec calls of 100,000 characters at about 6 seconds each, 25 minutes for one Collect. The device now gzips the JSON (13.4 MB to 380 KB) and the driver reads it with the agent's file-read call in one reply; scripts go in through file-write, 30,000 characters per call instead of 1,200. Both checked by SHA-256. Collect -Since keeps only the probe records from a time on. 3.9 minutes for the same run, 2 with -Since. REM-INSTALL-MODULE hangs for its 60-minute timeout every hour and held round 10's seven detections for 70 minutes; its assignment is removed, the policy stays. --- CHANGELOG.md | 10 +- Validation/Findings.md | 2 +- Validation/GuestAgent.ps1 | 131 +++++++++---- Validation/Invoke-LabGuestScript.ps1 | 22 +-- Validation/Invoke-ValidationRound.ps1 | 77 ++++---- Validation/README.md | 17 +- .../Unit/Invoke-ValidationRound.Tests.ps1 | 180 +++++++++++------- 7 files changed, 282 insertions(+), 157 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7cb3960..037fd0e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,7 +11,15 @@ release notes. ## [Unreleased] -Nothing yet. +### Changed + +- Validation kit: `Collect` moves its payload through the guest agent's file-read call in one + reply, gzipped on the device before base64, instead of 179 guest exec calls of 100,000 + characters; scripts go in through the agent's file-write call, 30,000 characters per call + instead of 1,200 (`Send-GuestFile`, `Receive-GuestFile` in `GuestAgent.ps1`). `Collect -Since` + keeps only the probe records written from that time on. The round-7 experiment + `REM-INSTALL-MODULE`, which hangs for its 60-minute timeout every hour and holds the lab's + remediation runner, is no longer assigned. ## [0.27.0] - 2026-10-05 diff --git a/Validation/Findings.md b/Validation/Findings.md index 1008528..e49a1b4 100644 --- a/Validation/Findings.md +++ b/Validation/Findings.md @@ -287,7 +287,7 @@ device, the agent restarted once to fetch them. |---|---|---|---| | Execution policy | Scripts run regardless of the device's execution policy (PS) | AgentExecutor launches every script as `powershell.exe -NoProfile -executionPolicy bypass -file