Conversation
Renamed gnmap output spoonmap_output.gnmap
Add GitHub Action: Qwiet preZero Static Analysis
|
Closing this as unmergeable (GitHub already reports it as conflicting), but two of the three things in here were real and one of them I'm implementing now — thanks for it, and apologies for the four-year silence. Taking the parts separately: The The gnmap output is still missing and worth having — I'm adding it, but not the way it's done here. This uses one shared The ShiftLeft SAST additions I'm going to decline. ShiftLeft has since become Qwiet AI and the CDN/CLI flow this workflow depends on is gone; it also requires a The remaining ~20 lines are trailing-whitespace normalisation, which is most of what makes this conflict now. Filing the gnmap piece as its own issue and linking the implementing PR to it. |
Closes #36. Originally proposed in PR #11 (Feb 2021), closed as unmergeable. Each port's banner pass now writes nmap_results/portN.gnmap via -oG, and those are merged into spoonmap_output.gnmap after the workers join. Why not #11's approach: it pointed every port at one shared -oG file with --append-output. That was safe when nmap ran serially, but nmap_scan() now runs five concurrent workers, so five processes would interleave their appends into a plausible-looking but corrupt host list — the worst outcome for a format whose whole purpose is machine consumption. One file per port gives each a single writer. Merged, not concatenated: a host open on three ports is scanned by three nmap runs and so appears in three files, but grepable output is one line per host. Concatenating would make anything counting lines over-count hosts and would disagree with spoonmap_output.xml/.json, which merge the same hosts. Hosts are ordered by _ip_sort_key() and port entries numerically, so the file is stable across runs and diffable between scans. Two consistency details: - _quarantine_failed_output() now renames the sibling .gnmap too. Otherwise a port excluded from spoonmap_output.xml would still contribute its partial hosts to spoonmap_output.gnmap, leaving the greppable artifact the more optimistic of the two about what was actually scanned. - Ports holding an .xml with no .gnmap — what a resume from before this feature looks like — are named in a warning instead of being silently absent. An artifact that quietly covers less than the run did is a coverage claim the scan never made. port{N}_sql.xml is excluded from that check, since _scan_extra_sql_ports() writes it with no -oG and it is not a gap. Adding .gnmap to nmap_results/ is safe for existing readers: all three that scan the directory filter on an .xml extension, and _parse_result_xml() returns None for anything else. spoonmap_output.gnmap is registered in _RESULT_FILES so --cleanup removes it. The parser was verified against real nmap 7.99 -oG output, not just a fixture: tab-separated fields, the 'Status: Up' line emitted alongside the ports line, the trailing 'Ignored State' field, and the comment header/footer. 939 tests pass (32 new), 100% coverage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Closes #36. Originally proposed in PR #11 (Feb 2021), closed as unmergeable. Each port's banner pass now writes nmap_results/portN.gnmap via -oG, and those are merged into spoonmap_output.gnmap after the workers join. Why not #11's approach: it pointed every port at one shared -oG file with --append-output. That was safe when nmap ran serially, but nmap_scan() now runs five concurrent workers, so five processes would interleave their appends into a plausible-looking but corrupt host list — the worst outcome for a format whose whole purpose is machine consumption. One file per port gives each a single writer. Merged, not concatenated: a host open on three ports is scanned by three nmap runs and so appears in three files, but grepable output is one line per host. Concatenating would make anything counting lines over-count hosts and would disagree with spoonmap_output.xml/.json, which merge the same hosts. Hosts are ordered by _ip_sort_key() and port entries numerically, so the file is stable across runs and diffable between scans. Two consistency details: - _quarantine_failed_output() now renames the sibling .gnmap too. Otherwise a port excluded from spoonmap_output.xml would still contribute its partial hosts to spoonmap_output.gnmap, leaving the greppable artifact the more optimistic of the two about what was actually scanned. - Ports holding an .xml with no .gnmap — what a resume from before this feature looks like — are named in a warning instead of being silently absent. An artifact that quietly covers less than the run did is a coverage claim the scan never made. port{N}_sql.xml is excluded from that check, since _scan_extra_sql_ports() writes it with no -oG and it is not a gap. Adding .gnmap to nmap_results/ is safe for existing readers: all three that scan the directory filter on an .xml extension, and _parse_result_xml() returns None for anything else. spoonmap_output.gnmap is registered in _RESULT_FILES so --cleanup removes it. The parser was verified against real nmap 7.99 -oG output, not just a fixture: tab-separated fields, the 'Status: Up' line emitted alongside the ports line, the trailing 'Ignored State' field, and the comment header/footer. 939 tests pass (32 new), 100% coverage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Added output file spoonmap_output.gnmap and fixed a bug where nmap wouldn't run if an output directory was specified and spoonmap wasn't run from that directory.