-
Notifications
You must be signed in to change notification settings - Fork 137
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix how security settings are read #5317
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks!
Datadog ReportBranch report: ✅ 0 Failed, 331511 Passed, 1619 Skipped, 41m 33.24s Wall Time |
Execution-Time Benchmarks Report ⏱️Execution-time results for samples comparing the following branches/commits: Execution-time benchmarks measure the whole time it takes to execute a program. And are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are shown in red. The following thresholds were used for comparing the execution times:
Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard. Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph). gantt
title Execution time (ms) FakeDbCommand (.NET Framework 4.6.2)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5317) - mean (74ms) : 65, 82
. : milestone, 74,
master - mean (73ms) : 64, 82
. : milestone, 73,
section CallTarget+Inlining+NGEN
This PR (5317) - mean (1,004ms) : 984, 1024
. : milestone, 1004,
master - mean (1,002ms) : 980, 1024
. : milestone, 1002,
gantt
title Execution time (ms) FakeDbCommand (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5317) - mean (110ms) : 107, 113
. : milestone, 110,
master - mean (110ms) : 106, 114
. : milestone, 110,
section CallTarget+Inlining+NGEN
This PR (5317) - mean (724ms) : 702, 747
. : milestone, 724,
master - mean (718ms) : 697, 738
. : milestone, 718,
gantt
title Execution time (ms) FakeDbCommand (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5317) - mean (93ms) : 91, 96
. : milestone, 93,
master - mean (94ms) : 90, 97
. : milestone, 94,
section CallTarget+Inlining+NGEN
This PR (5317) - mean (678ms) : 652, 704
. : milestone, 678,
master - mean (680ms) : 661, 699
. : milestone, 680,
gantt
title Execution time (ms) HttpMessageHandler (.NET Framework 4.6.2)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5317) - mean (188ms) : 184, 191
. : milestone, 188,
master - mean (188ms) : 185, 191
. : milestone, 188,
section CallTarget+Inlining+NGEN
This PR (5317) - mean (1,079ms) : 1056, 1102
. : milestone, 1079,
master - mean (1,078ms) : 1060, 1097
. : milestone, 1078,
gantt
title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5317) - mean (270ms) : 266, 275
. : milestone, 270,
master - mean (271ms) : 267, 275
. : milestone, 271,
section CallTarget+Inlining+NGEN
This PR (5317) - mean (870ms) : 846, 893
. : milestone, 870,
master - mean (872ms) : 849, 894
. : milestone, 872,
gantt
title Execution time (ms) HttpMessageHandler (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5317) - mean (261ms) : 256, 265
. : milestone, 261,
master - mean (261ms) : 257, 265
. : milestone, 261,
section CallTarget+Inlining+NGEN
This PR (5317) - mean (852ms) : 830, 874
. : milestone, 852,
master - mean (856ms) : 830, 882
. : milestone, 856,
|
Benchmarks Report for tracer 🐌Benchmarks for #5317 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.ActivityBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AgentWriterBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AspNetCoreBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.DbCommandBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.ElasticsearchBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.GraphQLBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.HttpClientBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.ILoggerBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Log4netBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.NLogBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.RedisBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.SerilogBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.SpanBenchmark - Faster 🎉 Same allocations ✔️
|
Benchmark | base/diff | Base Median (ns) | Diff Median (ns) | Modality |
---|---|---|---|---|
Benchmarks.Trace.SpanBenchmark.StartFinishScope‑net472 | 1.119 | 1,053.19 | 941.16 |
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | StartFinishSpan |
net6.0 | 483ns | 0.807ns | 3.02ns | 0.00761 | 0 | 0 | 552 B |
master | StartFinishSpan |
netcoreapp3.1 | 710ns | 0.615ns | 2.38ns | 0.00752 | 0 | 0 | 552 B |
master | StartFinishSpan |
net472 | 782ns | 0.396ns | 1.53ns | 0.0878 | 0 | 0 | 554 B |
master | StartFinishScope |
net6.0 | 620ns | 0.915ns | 3.55ns | 0.00928 | 0 | 0 | 672 B |
master | StartFinishScope |
netcoreapp3.1 | 840ns | 0.78ns | 3.02ns | 0.00918 | 0 | 0 | 672 B |
master | StartFinishScope |
net472 | 1.05μs | 1.14ns | 4.28ns | 0.101 | 0 | 0 | 634 B |
#5317 | StartFinishSpan |
net6.0 | 514ns | 0.415ns | 1.61ns | 0.00773 | 0 | 0 | 552 B |
#5317 | StartFinishSpan |
netcoreapp3.1 | 727ns | 0.756ns | 2.93ns | 0.00736 | 0 | 0 | 552 B |
#5317 | StartFinishSpan |
net472 | 806ns | 0.609ns | 2.36ns | 0.0877 | 0 | 0 | 554 B |
#5317 | StartFinishScope |
net6.0 | 607ns | 0.223ns | 0.836ns | 0.00941 | 0 | 0 | 672 B |
#5317 | StartFinishScope |
netcoreapp3.1 | 916ns | 0.641ns | 2.4ns | 0.00896 | 0 | 0 | 672 B |
#5317 | StartFinishScope |
net472 | 940ns | 2.3ns | 8.92ns | 0.1 | 0 | 0 | 634 B |
Benchmarks.Trace.TraceAnnotationsBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | RunOnMethodBegin |
net6.0 | 683ns | 0.781ns | 3.03ns | 0.00958 | 0 | 0 | 672 B |
master | RunOnMethodBegin |
netcoreapp3.1 | 955ns | 0.782ns | 3.03ns | 0.00911 | 0 | 0 | 672 B |
master | RunOnMethodBegin |
net472 | 1.17μs | 1.6ns | 5.76ns | 0.1 | 0 | 0 | 634 B |
#5317 | RunOnMethodBegin |
net6.0 | 693ns | 0.566ns | 2.19ns | 0.00946 | 0 | 0 | 672 B |
#5317 | RunOnMethodBegin |
netcoreapp3.1 | 1μs | 0.713ns | 2.76ns | 0.00902 | 0 | 0 | 672 B |
#5317 | RunOnMethodBegin |
net472 | 1.06μs | 1.65ns | 6.38ns | 0.101 | 0 | 0 | 634 B |
Benchmarks Report for appsec 🐌Benchmarks for #5317 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.Asm.AppSecBodyBenchmark - Faster 🎉 Same allocations ✔️
|
Benchmark | base/diff | Base Median (ns) | Diff Median (ns) | Modality |
---|---|---|---|---|
Benchmarks.Trace.Asm.AppSecBodyBenchmark.ObjectExtractorMoreComplexBody‑net472 | 1.193 | 4,530.78 | 3,799.06 | |
Benchmarks.Trace.Asm.AppSecBodyBenchmark.AllCycleMoreComplexBody‑net472 | 1.152 | 5,087.57 | 4,415.25 |
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | AllCycleSimpleBody |
net6.0 | 561ns | 0.417ns | 1.56ns | 0.0153 | 0 | 0 | 1.08 KB |
master | AllCycleSimpleBody |
netcoreapp3.1 | 785ns | 0.428ns | 1.48ns | 0.0145 | 0 | 0 | 1.06 KB |
master | AllCycleSimpleBody |
net472 | 667ns | 0.314ns | 1.22ns | 0.175 | 0.000331 | 0 | 1.1 KB |
master | AllCycleMoreComplexBody |
net6.0 | 3.59μs | 2.91ns | 10.9ns | 0.0647 | 0 | 0 | 4.58 KB |
master | AllCycleMoreComplexBody |
netcoreapp3.1 | 4.58μs | 2.66ns | 9.96ns | 0.0618 | 0 | 0 | 4.48 KB |
master | AllCycleMoreComplexBody |
net472 | 5.09μs | 2.55ns | 9.86ns | 0.731 | 0.00764 | 0 | 4.61 KB |
master | ObjectExtractorSimpleBody |
net6.0 | 147ns | 0.134ns | 0.518ns | 0.00394 | 0 | 0 | 280 B |
master | ObjectExtractorSimpleBody |
netcoreapp3.1 | 203ns | 0.116ns | 0.433ns | 0.00368 | 0 | 0 | 272 B |
master | ObjectExtractorSimpleBody |
net472 | 171ns | 0.311ns | 1.21ns | 0.0446 | 0 | 0 | 281 B |
master | ObjectExtractorMoreComplexBody |
net6.0 | 2.99μs | 2.67ns | 10.3ns | 0.0525 | 0 | 0 | 3.78 KB |
master | ObjectExtractorMoreComplexBody |
netcoreapp3.1 | 4.09μs | 9.52ns | 36.9ns | 0.0505 | 0 | 0 | 3.69 KB |
master | ObjectExtractorMoreComplexBody |
net472 | 4.53μs | 2.06ns | 7.41ns | 0.601 | 0.00452 | 0 | 3.8 KB |
#5317 | AllCycleSimpleBody |
net6.0 | 547ns | 0.408ns | 1.47ns | 0.0151 | 0 | 0 | 1.08 KB |
#5317 | AllCycleSimpleBody |
netcoreapp3.1 | 754ns | 0.505ns | 1.89ns | 0.0148 | 0 | 0 | 1.06 KB |
#5317 | AllCycleSimpleBody |
net472 | 669ns | 0.256ns | 0.993ns | 0.174 | 0.000334 | 0 | 1.1 KB |
#5317 | AllCycleMoreComplexBody |
net6.0 | 3.56μs | 1.95ns | 7.29ns | 0.0643 | 0 | 0 | 4.58 KB |
#5317 | AllCycleMoreComplexBody |
netcoreapp3.1 | 4.72μs | 2.66ns | 10.3ns | 0.0615 | 0 | 0 | 4.48 KB |
#5317 | AllCycleMoreComplexBody |
net472 | 4.41μs | 6.71ns | 26ns | 0.732 | 0.00874 | 0 | 4.61 KB |
#5317 | ObjectExtractorSimpleBody |
net6.0 | 140ns | 0.0893ns | 0.346ns | 0.00398 | 0 | 0 | 280 B |
#5317 | ObjectExtractorSimpleBody |
netcoreapp3.1 | 205ns | 0.135ns | 0.521ns | 0.00375 | 0 | 0 | 272 B |
#5317 | ObjectExtractorSimpleBody |
net472 | 167ns | 0.141ns | 0.547ns | 0.0446 | 0 | 0 | 281 B |
#5317 | ObjectExtractorMoreComplexBody |
net6.0 | 2.99μs | 1.63ns | 6.32ns | 0.0525 | 0 | 0 | 3.78 KB |
#5317 | ObjectExtractorMoreComplexBody |
netcoreapp3.1 | 3.9μs | 1.44ns | 5.19ns | 0.0489 | 0 | 0 | 3.69 KB |
#5317 | ObjectExtractorMoreComplexBody |
net472 | 3.8μs | 2.78ns | 10.8ns | 0.602 | 0.0057 | 0 | 3.8 KB |
Benchmarks.Trace.Asm.AppSecWafBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | RunWafRealisticBenchmark |
net6.0 | 191μs | 43.7ns | 169ns | 0.0956 | 0 | 0 | 6.51 KB |
master | RunWafRealisticBenchmark |
netcoreapp3.1 | 201μs | 164ns | 615ns | 0 | 0 | 0 | 6.49 KB |
master | RunWafRealisticBenchmark |
net472 | 225μs | 371ns | 1.44μs | 0.996 | 0 | 0 | 6.59 KB |
master | RunWafRealisticBenchmarkWithAttack |
net6.0 | 124μs | 42.5ns | 165ns | 0 | 0 | 0 | 4.15 KB |
master | RunWafRealisticBenchmarkWithAttack |
netcoreapp3.1 | 133μs | 279ns | 1.08μs | 0 | 0 | 0 | 4.15 KB |
master | RunWafRealisticBenchmarkWithAttack |
net472 | 145μs | 114ns | 413ns | 0.661 | 0 | 0 | 4.19 KB |
#5317 | RunWafRealisticBenchmark |
net6.0 | 191μs | 374ns | 1.45μs | 0.0941 | 0 | 0 | 6.51 KB |
#5317 | RunWafRealisticBenchmark |
netcoreapp3.1 | 204μs | 525ns | 2.03μs | 0 | 0 | 0 | 6.49 KB |
#5317 | RunWafRealisticBenchmark |
net472 | 223μs | 219ns | 790ns | 1 | 0 | 0 | 6.59 KB |
#5317 | RunWafRealisticBenchmarkWithAttack |
net6.0 | 124μs | 53.1ns | 206ns | 0 | 0 | 0 | 4.15 KB |
#5317 | RunWafRealisticBenchmarkWithAttack |
netcoreapp3.1 | 135μs | 384ns | 1.49μs | 0 | 0 | 0 | 4.15 KB |
#5317 | RunWafRealisticBenchmarkWithAttack |
net472 | 146μs | 149ns | 579ns | 0.653 | 0 | 0 | 4.19 KB |
Benchmarks.Trace.Iast.StringAspectsBenchmark - Same speed ✔️ More allocations ⚠️
More allocations ⚠️ in #5317
Benchmark
Base Allocated
Diff Allocated
Change
Change %
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑netcoreapp3.1
204.09 KB
210.27 KB
6.18 KB
3.03%
Fewer allocations 🎉 in #5317
Benchmark
Base Allocated
Diff Allocated
Change
Change %
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net6.0
204.98 KB
202.59 KB
-2.39 KB
-1.17%
Benchmark | Base Allocated | Diff Allocated | Change | Change % |
---|---|---|---|---|
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑netcoreapp3.1 | 204.09 KB | 210.27 KB | 6.18 KB | 3.03% |
Benchmark | Base Allocated | Diff Allocated | Change | Change % |
---|---|---|---|---|
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net6.0 | 204.98 KB | 202.59 KB | -2.39 KB | -1.17% |
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | StringConcatBenchmark |
net6.0 | 60.7μs | 625ns | 6.13μs | 0 | 0 | 0 | 43.44 KB |
master | StringConcatBenchmark |
netcoreapp3.1 | 54μs | 162ns | 582ns | 0 | 0 | 0 | 42.64 KB |
master | StringConcatBenchmark |
net472 | 38.2μs | 170ns | 636ns | 0 | 0 | 0 | 59.22 KB |
master | StringConcatAspectBenchmark |
net6.0 | 278μs | 4.54μs | 43.6μs | 0 | 0 | 0 | 204.98 KB |
master | StringConcatAspectBenchmark |
netcoreapp3.1 | 308μs | 1.27μs | 4.74μs | 0 | 0 | 0 | 204.09 KB |
master | StringConcatAspectBenchmark |
net472 | 258μs | 3.75μs | 35.7μs | 0 | 0 | 0 | 221.18 KB |
#5317 | StringConcatBenchmark |
net6.0 | 63.2μs | 770ns | 7.5μs | 0 | 0 | 0 | 43.44 KB |
#5317 | StringConcatBenchmark |
netcoreapp3.1 | 53.6μs | 268ns | 1.11μs | 0 | 0 | 0 | 42.64 KB |
#5317 | StringConcatBenchmark |
net472 | 38.6μs | 85.8ns | 309ns | 0 | 0 | 0 | 59.07 KB |
#5317 | StringConcatAspectBenchmark |
net6.0 | 283μs | 1.34μs | 6.3μs | 0 | 0 | 0 | 202.59 KB |
#5317 | StringConcatAspectBenchmark |
netcoreapp3.1 | 308μs | 1.53μs | 6.86μs | 0 | 0 | 0 | 210.27 KB |
#5317 | StringConcatAspectBenchmark |
net472 | 275μs | 5.86μs | 56.8μs | 0 | 0 | 0 | 221.18 KB |
Throughput/Crank Report:zap:Throughput results for AspNetCoreSimpleController comparing the following branches/commits: Cases where throughput results for the PR are worse than latest master (5% drop or greater), results are shown in red. Note that these results are based on a single point-in-time result for each branch. For full results, see one of the many, many dashboards! gantt
title Throughput Linux x64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (5317) (11.146M) : 0, 11145816
master (11.096M) : 0, 11096138
benchmarks/2.9.0 (10.743M) : 0, 10743092
section Automatic
This PR (5317) (7.600M) : 0, 7600208
master (7.482M) : 0, 7481686
benchmarks/2.9.0 (7.823M) : 0, 7823252
section Trace stats
This PR (5317) (8.021M) : 0, 8020895
master (7.944M) : 0, 7944133
section Manual
This PR (5317) (9.768M) : 0, 9767525
master (9.429M) : 0, 9429044
section Manual + Automatic
This PR (5317) (7.216M) : 0, 7215831
master (6.975M) : 0, 6975116
section Version Conflict
This PR (5317) (6.576M) : 0, 6576162
master (6.384M) : 0, 6383585
gantt
title Throughput Linux arm64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (5317) (9.752M) : 0, 9751942
master (9.571M) : 0, 9570993
benchmarks/2.9.0 (9.656M) : 0, 9656465
section Automatic
This PR (5317) (6.589M) : 0, 6589083
master (6.470M) : 0, 6469945
section Trace stats
This PR (5317) (6.888M) : 0, 6887802
master (7.095M) : 0, 7095354
section Manual
This PR (5317) (8.182M) : 0, 8182086
master (8.040M) : 0, 8039576
section Manual + Automatic
This PR (5317) (6.141M) : 0, 6141051
master (6.260M) : 0, 6259761
section Version Conflict
This PR (5317) (5.746M) : 0, 5746125
master (5.905M) : 0, 5905251
gantt
title Throughput Windows x64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (5317) (9.839M) : 0, 9839405
master (10.013M) : 0, 10013130
benchmarks/2.9.0 (9.967M) : 0, 9967407
section Automatic
This PR (5317) (6.962M) : 0, 6962237
master (7.046M) : 0, 7046320
benchmarks/2.9.0 (7.375M) : 0, 7374511
section Trace stats
This PR (5317) (7.336M) : 0, 7336450
master (7.437M) : 0, 7437175
section Manual
This PR (5317) (8.653M) : 0, 8652791
master (8.864M) : 0, 8864242
section Manual + Automatic
This PR (5317) (6.644M) : 0, 6644271
master (6.834M) : 0, 6834408
section Version Conflict
This PR (5317) (6.174M) : 0, 6174424
master (6.123M) : 0, 6122721
gantt
title Throughput Linux x64 (ASM) (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (5317) (21.553M) : 0, 21552930
section No attack
This PR (5317) (21.544M) : 0, 21544011
section Attack
This PR (5317) (21.544M) : 0, 21544139
section Blocking
This PR (5317) (21.568M) : 0, 21568108
section IAST default
This PR (5317) (21.549M) : 0, 21549399
section IAST full
This PR (5317) (21.568M) : 0, 21567637
section Base vuln
This PR (5317) (21.472M) : 0, 21472064
section IAST vuln
This PR (5317) (21.413M) : 0, 21413414
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I was just implementing the config values for the RASP stacktrace reporting. This PR was helpful to avoid adding more GetValueOrDefaults :)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍
Summary of changes
The link function
GetValueOrDefault()
should not be used, the library core API has functions with defaults built in.