-
Notifications
You must be signed in to change notification settings - Fork 137
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[IAST] Safeguard Method Replace aspects with try/catch (#5841 -> v2) #5855
[IAST] Safeguard Method Replace aspects with try/catch (#5841 -> v2) #5855
Conversation
Covered all `AspectMethodReplace` aspects with try catch clauses to ensure no crash will bubble up to client, following new analyzer rules. Disabled some weird casts and processes to support some functions not present en NetCore 2.0, but present in 2.1 (netstandard2 assembly is loaded in netcore2.1 apps). Disabled some overloads receiving generic undefined arguments until proper callsite support is implemented. SSI will make the tracer enabled for a lot more of services when available. We must ensure we do not break any of them, and if so, that we provide a fast answer. Apply analyzer suggestions adding a try / catch clause in all `Methodreplace` aspects <!-- Fixes #{issue} --> <!--⚠️ Note: where possible, please obtain 2 approvals prior to merging. Unless CODEOWNERS specifies otherwise, for external teams it is typically best to have one review from a team member, and one review from apm-dotnet. Trivial changes do not require 2 reviews. -->
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks!
Execution-Time Benchmarks Report ⏱️Execution-time results for samples comparing the following branches/commits: Execution-time benchmarks measure the whole time it takes to execute a program. And are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are shown in red. The following thresholds were used for comparing the execution times:
Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard. Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph). gantt
title Execution time (ms) FakeDbCommand (.NET Framework 4.6.2)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5855) - mean (73ms) : 63, 84
. : milestone, 73,
master - mean (74ms) : 64, 84
. : milestone, 74,
section CallTarget+Inlining+NGEN
This PR (5855) - mean (1,027ms) : 1006, 1048
. : milestone, 1027,
master - mean (1,063ms) : 1041, 1084
. : milestone, 1063,
gantt
title Execution time (ms) FakeDbCommand (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5855) - mean (109ms) : 104, 114
. : milestone, 109,
master - mean (110ms) : 105, 115
. : milestone, 110,
section CallTarget+Inlining+NGEN
This PR (5855) - mean (717ms) : 695, 739
. : milestone, 717,
master - mean (747ms) : 727, 767
. : milestone, 747,
gantt
title Execution time (ms) FakeDbCommand (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5855) - mean (92ms) : 88, 97
. : milestone, 92,
master - mean (92ms) : 88, 96
. : milestone, 92,
section CallTarget+Inlining+NGEN
This PR (5855) - mean (665ms) : 644, 687
. : milestone, 665,
master - mean (703ms) : 684, 721
. : milestone, 703,
gantt
title Execution time (ms) HttpMessageHandler (.NET Framework 4.6.2)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5855) - mean (192ms) : 188, 196
. : milestone, 192,
master - mean (192ms) : 189, 196
. : milestone, 192,
section CallTarget+Inlining+NGEN
This PR (5855) - mean (1,123ms) : 1103, 1144
. : milestone, 1123,
master - mean (1,169ms) : 1139, 1200
. : milestone, 1169,
gantt
title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5855) - mean (276ms) : 273, 280
. : milestone, 276,
master - mean (275ms) : 271, 280
. : milestone, 275,
section CallTarget+Inlining+NGEN
This PR (5855) - mean (884ms) : 861, 906
. : milestone, 884,
master - mean (921ms) : 896, 947
. : milestone, 921,
gantt
title Execution time (ms) HttpMessageHandler (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5855) - mean (265ms) : 261, 268
. : milestone, 265,
master - mean (266ms) : 262, 270
. : milestone, 266,
section CallTarget+Inlining+NGEN
This PR (5855) - mean (872ms) : 853, 891
. : milestone, 872,
master - mean (905ms) : 883, 928
. : milestone, 905,
|
Datadog ReportBranch report: ✅ 0 Failed, 431846 Passed, 2660 Skipped, 26h 21m 59.68s Total Time New Flaky Tests (1)
⌛ Performance Regressions vs Default Branch (14)
|
Benchmarks Report for appsec 🐌Benchmarks for #5855 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.Asm.AppSecBodyBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecEncoderBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecWafBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Iast.StringAspectsBenchmark - Same speed ✔️ More allocations
|
Benchmark | Base Allocated | Diff Allocated | Change | Change % |
---|---|---|---|---|
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatBenchmark‑net472 | 59.06 KB | 62.02 KB | 2.97 KB | 5.03% |
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑netcoreapp3.1 | 254.01 KB | 263.6 KB | 9.59 KB | 3.78% |
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net6.0 | 254.2 KB | 256.54 KB | 2.34 KB | 0.92% |
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | StringConcatBenchmark |
net6.0 | 58.9μs | 779ns | 7.67μs | 0 | 0 | 0 | 43.44 KB |
master | StringConcatBenchmark |
netcoreapp3.1 | 61.5μs | 737ns | 7.25μs | 0 | 0 | 0 | 42.64 KB |
master | StringConcatBenchmark |
net472 | 37.5μs | 98.2ns | 354ns | 0 | 0 | 0 | 59.06 KB |
master | StringConcatAspectBenchmark |
net6.0 | 292μs | 5.72μs | 56.9μs | 0 | 0 | 0 | 254.2 KB |
master | StringConcatAspectBenchmark |
netcoreapp3.1 | 310μs | 5.17μs | 51.2μs | 0 | 0 | 0 | 254.01 KB |
master | StringConcatAspectBenchmark |
net472 | 280μs | 6.22μs | 60.6μs | 0 | 0 | 0 | 278.53 KB |
#5855 | StringConcatBenchmark |
net6.0 | 53.1μs | 222ns | 914ns | 0 | 0 | 0 | 43.44 KB |
#5855 | StringConcatBenchmark |
netcoreapp3.1 | 54.3μs | 240ns | 867ns | 0 | 0 | 0 | 42.64 KB |
#5855 | StringConcatBenchmark |
net472 | 38.3μs | 157ns | 565ns | 0 | 0 | 0 | 62.02 KB |
#5855 | StringConcatAspectBenchmark |
net6.0 | 309μs | 1.53μs | 6.49μs | 0 | 0 | 0 | 256.54 KB |
#5855 | StringConcatAspectBenchmark |
netcoreapp3.1 | 333μs | 1.31μs | 4.52μs | 0 | 0 | 0 | 263.6 KB |
#5855 | StringConcatAspectBenchmark |
net472 | 285μs | 5.98μs | 58.9μs | 0 | 0 | 0 | 278.53 KB |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Approving as we agreed #5841 was good, didn't re-review.
Summary of changes
Covered all
AspectMethodReplace
aspects with try catch clauses toensure no crash will bubble up to client, following new analyzer rules.
Disabled some weird casts and processes to support some functions not
present en NetCore 2.0, but present in 2.1 (netstandard2 assembly is
loaded in netcore2.1 apps).
Disabled some overloads receiving generic undefined arguments until
proper callsite support is implemented.
Reason for change
SSI will make the tracer enabled for a lot more of services when
available. We must ensure we do not break any of them, and if so, that
we provide a fast answer.
Implementation details
Apply analyzer suggestions adding a try / catch clause in all
Methodreplace
aspects