-
Notifications
You must be signed in to change notification settings - Fork 145
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[ASM][IAST] Insecure Auth Vulnerability #5148
Conversation
3601af3
to
6e20b4b
Compare
Datadog ReportBranch report: ✅ 0 Failed, 343746 Passed, 1585 Skipped, 40m 57.27s Wall Time New Flaky Tests (2)
|
Execution-Time Benchmarks Report ⏱️Execution-time results for samples comparing the following branches/commits: Execution-time benchmarks measure the whole time it takes to execute a program. And are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are shown in red. The following thresholds were used for comparing the execution times:
Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard. Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph). gantt
title Execution time (ms) FakeDbCommand (.NET Framework 4.6.2)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5148) - mean (75ms) : 65, 85
. : milestone, 75,
master - mean (74ms) : 66, 83
. : milestone, 74,
section CallTarget+Inlining+NGEN
This PR (5148) - mean (992ms) : 975, 1010
. : milestone, 992,
master - mean (982ms) : 960, 1003
. : milestone, 982,
gantt
title Execution time (ms) FakeDbCommand (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5148) - mean (111ms) : 108, 115
. : milestone, 111,
master - mean (111ms) : 108, 114
. : milestone, 111,
section CallTarget+Inlining+NGEN
This PR (5148) - mean (719ms) : 695, 743
. : milestone, 719,
master - mean (719ms) : 694, 744
. : milestone, 719,
gantt
title Execution time (ms) FakeDbCommand (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5148) - mean (96ms) : 93, 100
. : milestone, 96,
master - mean (94ms) : 91, 97
. : milestone, 94,
section CallTarget+Inlining+NGEN
This PR (5148) - mean (677ms) : 652, 702
. : milestone, 677,
master - mean (663ms) : 637, 690
. : milestone, 663,
gantt
title Execution time (ms) HttpMessageHandler (.NET Framework 4.6.2)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5148) - mean (188ms) : 182, 193
. : milestone, 188,
master - mean (187ms) : 183, 191
. : milestone, 187,
section CallTarget+Inlining+NGEN
This PR (5148) - mean (1,057ms) : 1030, 1084
. : milestone, 1057,
master - mean (1,058ms) : 1036, 1081
. : milestone, 1058,
gantt
title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5148) - mean (269ms) : 262, 276
. : milestone, 269,
master - mean (270ms) : 265, 275
. : milestone, 270,
section CallTarget+Inlining+NGEN
This PR (5148) - mean (867ms) : 838, 895
. : milestone, 867,
master - mean (869ms) : 845, 893
. : milestone, 869,
gantt
title Execution time (ms) HttpMessageHandler (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (5148) - mean (262ms) : 254, 270
. : milestone, 262,
master - mean (259ms) : 254, 263
. : milestone, 259,
section CallTarget+Inlining+NGEN
This PR (5148) - mean (855ms) : 829, 881
. : milestone, 855,
master - mean (852ms) : 827, 877
. : milestone, 852,
|
tracer/test/test-applications/security/Samples.Security.AspNetCore5/Views/Home/Index.cshtml
Show resolved
Hide resolved
tracer/test/Datadog.Trace.Security.IntegrationTests/IAST/AspNetCore5IastTests.cs
Outdated
Show resolved
Hide resolved
Throughput/Crank Report:zap:Throughput results for AspNetCoreSimpleController comparing the following branches/commits: Cases where throughput results for the PR are worse than latest master (5% drop or greater), results are shown in red. Note that these results are based on a single point-in-time result for each branch. For full results, see one of the many, many dashboards! gantt
title Throughput Linux x64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (5148) (10.860M) : 0, 10859609
master (10.893M) : 0, 10892968
benchmarks/2.9.0 (11.124M) : 0, 11124125
section Automatic
This PR (5148) (7.477M) : 0, 7477203
master (7.522M) : 0, 7521529
benchmarks/2.9.0 (8.268M) : 0, 8268275
section Trace stats
This PR (5148) (7.700M) : 0, 7699916
master (7.806M) : 0, 7805686
section Manual
This PR (5148) (9.327M) : 0, 9326826
master (9.658M) : 0, 9658144
section Manual + Automatic
This PR (5148) (6.980M) : 0, 6979655
master (7.098M) : 0, 7098256
section Version Conflict
This PR (5148) (6.310M) : 0, 6310121
master (6.310M) : 0, 6310095
gantt
title Throughput Linux arm64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (5148) (9.548M) : 0, 9547591
master (9.651M) : 0, 9650727
benchmarks/2.9.0 (9.557M) : 0, 9556831
section Automatic
This PR (5148) (6.736M) : 0, 6736240
master (6.600M) : 0, 6599809
section Trace stats
This PR (5148) (6.954M) : 0, 6953627
master (6.754M) : 0, 6754454
section Manual
This PR (5148) (8.234M) : 0, 8234196
master (8.257M) : 0, 8257074
section Manual + Automatic
This PR (5148) (6.186M) : 0, 6185801
master (6.172M) : 0, 6172419
section Version Conflict
This PR (5148) (5.730M) : 0, 5729626
master (5.673M) : 0, 5672633
gantt
title Throughput Windows x64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (5148) (10.078M) : 0, 10078301
master (10.018M) : 0, 10018234
benchmarks/2.9.0 (9.910M) : 0, 9909593
section Automatic
This PR (5148) (7.216M) : 0, 7215890
master (7.131M) : 0, 7131143
benchmarks/2.9.0 (7.464M) : 0, 7464259
section Trace stats
This PR (5148) (7.597M) : 0, 7596941
master (7.336M) : 0, 7335971
section Manual
This PR (5148) (8.975M) : 0, 8975041
master (8.746M) : 0, 8746129
section Manual + Automatic
This PR (5148) (6.971M) : 0, 6970609
master (6.918M) : 0, 6917981
section Version Conflict
This PR (5148) (6.286M) : 0, 6286235
master (6.154M) : 0, 6153577
gantt
title Throughput Linux x64 (ASM) (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (5148) (7.446M) : 0, 7446370
master (7.380M) : 0, 7379514
benchmarks/2.9.0 (7.908M) : 0, 7908237
section No attack
This PR (5148) (1.845M) : 0, 1844511
master (1.835M) : 0, 1835314
benchmarks/2.9.0 (3.212M) : 0, 3211779
section Attack
This PR (5148) (1.459M) : 0, 1459140
master (1.445M) : 0, 1445088
benchmarks/2.9.0 (2.469M) : 0, 2469017
section Blocking
This PR (5148) (3.189M) : 0, 3189157
master (3.116M) : 0, 3115952
section IAST default
This PR (5148) (6.421M) : 0, 6421433
master (6.260M) : 0, 6260201
section IAST full
This PR (5148) (5.648M) : 0, 5647961
master (5.569M) : 0, 5568945
section Base vuln
This PR (5148) (0.911M) : 0, 911324
master (0.942M) : 0, 942192
section IAST vuln
This PR (5148) (0.872M) : 0, 872414
master (0.877M) : 0, 876502
|
Benchmarks Report 🐌Benchmarks for #5148 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.ActivityBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AgentWriterBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecBodyBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecEncoderBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecWafBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AspNetCoreBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark - Same speed ✔️ More allocations
|
Benchmark | Base Allocated | Diff Allocated | Change | Change % |
---|---|---|---|---|
Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark.WriteAndFlushEnrichedTraces‑net6.0 | 41.42 KB | 41.75 KB | 333 B | 0.80% |
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | WriteAndFlushEnrichedTraces |
net6.0 | 534μs | 201ns | 724ns | 0.563 | 0 | 0 | 41.42 KB |
master | WriteAndFlushEnrichedTraces |
netcoreapp3.1 | 653μs | 864ns | 3.35μs | 0.322 | 0 | 0 | 41.92 KB |
master | WriteAndFlushEnrichedTraces |
net472 | 849μs | 3.34μs | 12.9μs | 8.45 | 2.53 | 0.422 | 53.24 KB |
#5148 | WriteAndFlushEnrichedTraces |
net6.0 | 548μs | 705ns | 2.73μs | 0.543 | 0 | 0 | 41.75 KB |
#5148 | WriteAndFlushEnrichedTraces |
netcoreapp3.1 | 647μs | 1.49μs | 5.79μs | 0.321 | 0 | 0 | 41.95 KB |
#5148 | WriteAndFlushEnrichedTraces |
net472 | 848μs | 3.62μs | 14.9μs | 8.45 | 2.53 | 0.422 | 53.23 KB |
Benchmarks.Trace.DbCommandBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | ExecuteNonQuery |
net6.0 | 1.02μs | 0.851ns | 3.3ns | 0.0107 | 0 | 0 | 776 B |
master | ExecuteNonQuery |
netcoreapp3.1 | 1.47μs | 1.45ns | 5.43ns | 0.0103 | 0 | 0 | 776 B |
master | ExecuteNonQuery |
net472 | 1.73μs | 0.953ns | 3.69ns | 0.117 | 0 | 0 | 738 B |
#5148 | ExecuteNonQuery |
net6.0 | 1.09μs | 1.1ns | 4.27ns | 0.0109 | 0 | 0 | 776 B |
#5148 | ExecuteNonQuery |
netcoreapp3.1 | 1.48μs | 0.442ns | 1.66ns | 0.0104 | 0 | 0 | 776 B |
#5148 | ExecuteNonQuery |
net472 | 1.69μs | 0.664ns | 2.3ns | 0.117 | 0 | 0 | 738 B |
Benchmarks.Trace.ElasticsearchBenchmark - Slower ⚠️ Same allocations ✔️
Slower ⚠️ in #5148
Benchmark
diff/base
Base Median (ns)
Diff Median (ns)
Modality
Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearch‑net6.0
1.168
1,138.62
1,329.88
Benchmark | diff/base | Base Median (ns) | Diff Median (ns) | Modality |
---|---|---|---|---|
Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearch‑net6.0 | 1.168 | 1,138.62 | 1,329.88 |
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | CallElasticsearch |
net6.0 | 1.14μs | 0.398ns | 1.49ns | 0.0132 | 0 | 0 | 944 B |
master | CallElasticsearch |
netcoreapp3.1 | 1.46μs | 0.551ns | 2.13ns | 0.013 | 0 | 0 | 944 B |
master | CallElasticsearch |
net472 | 2.45μs | 1.14ns | 4.41ns | 0.152 | 0 | 0 | 963 B |
master | CallElasticsearchAsync |
net6.0 | 1.32μs | 0.736ns | 2.85ns | 0.0132 | 0 | 0 | 920 B |
master | CallElasticsearchAsync |
netcoreapp3.1 | 1.61μs | 0.524ns | 1.96ns | 0.013 | 0 | 0 | 992 B |
master | CallElasticsearchAsync |
net472 | 2.63μs | 0.712ns | 2.76ns | 0.161 | 0 | 0 | 1.02 KB |
#5148 | CallElasticsearch |
net6.0 | 1.33μs | 0.661ns | 2.56ns | 0.0133 | 0 | 0 | 944 B |
#5148 | CallElasticsearch |
netcoreapp3.1 | 1.49μs | 0.451ns | 1.75ns | 0.0127 | 0 | 0 | 944 B |
#5148 | CallElasticsearch |
net472 | 2.54μs | 1.3ns | 4.86ns | 0.153 | 0 | 0 | 963 B |
#5148 | CallElasticsearchAsync |
net6.0 | 1.33μs | 0.901ns | 3.37ns | 0.0128 | 0 | 0 | 920 B |
#5148 | CallElasticsearchAsync |
netcoreapp3.1 | 1.65μs | 0.536ns | 2.08ns | 0.0132 | 0 | 0 | 992 B |
#5148 | CallElasticsearchAsync |
net472 | 2.57μs | 0.902ns | 3.37ns | 0.161 | 0 | 0 | 1.02 KB |
Benchmarks.Trace.GraphQLBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | ExecuteAsync |
net6.0 | 1.29μs | 2.03ns | 7.3ns | 0.013 | 0 | 0 | 920 B |
master | ExecuteAsync |
netcoreapp3.1 | 1.68μs | 3.9ns | 14.1ns | 0.0123 | 0 | 0 | 920 B |
master | ExecuteAsync |
net472 | 1.85μs | 0.732ns | 2.83ns | 0.14 | 0 | 0 | 883 B |
#5148 | ExecuteAsync |
net6.0 | 1.27μs | 0.987ns | 3.69ns | 0.0128 | 0 | 0 | 920 B |
#5148 | ExecuteAsync |
netcoreapp3.1 | 1.62μs | 1.04ns | 4.04ns | 0.0121 | 0 | 0 | 920 B |
#5148 | ExecuteAsync |
net472 | 1.78μs | 0.976ns | 3.65ns | 0.14 | 0 | 0 | 883 B |
Benchmarks.Trace.HttpClientBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | SendAsync |
net6.0 | 4.16μs | 1.35ns | 5.25ns | 0.0291 | 0 | 0 | 2.1 KB |
master | SendAsync |
netcoreapp3.1 | 5μs | 3.26ns | 12.6ns | 0.035 | 0 | 0 | 2.64 KB |
master | SendAsync |
net472 | 7.61μs | 3.14ns | 12.2ns | 0.524 | 0 | 0 | 3.31 KB |
#5148 | SendAsync |
net6.0 | 4.07μs | 1.86ns | 7.21ns | 0.0306 | 0 | 0 | 2.1 KB |
#5148 | SendAsync |
netcoreapp3.1 | 4.82μs | 3.16ns | 12.2ns | 0.0362 | 0 | 0 | 2.64 KB |
#5148 | SendAsync |
net472 | 7.68μs | 6.72ns | 26ns | 0.526 | 0.00384 | 0 | 3.31 KB |
Benchmarks.Trace.Iast.StringAspectsBenchmark - Same speed ✔️ More allocations ⚠️
More allocations ⚠️ in #5148
Benchmark
Base Allocated
Diff Allocated
Change
Change %
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net472
221.18 KB
226.62 KB
5.43 KB
2.46%
Fewer allocations 🎉 in #5148
Benchmark
Base Allocated
Diff Allocated
Change
Change %
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net6.0
215.6 KB
211.7 KB
-3.9 KB
-1.81%
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatBenchmark‑net472
62.46 KB
55.78 KB
-6.68 KB
-10.69%
Benchmark | Base Allocated | Diff Allocated | Change | Change % |
---|---|---|---|---|
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net472 | 221.18 KB | 226.62 KB | 5.43 KB | 2.46% |
Benchmark | Base Allocated | Diff Allocated | Change | Change % |
---|---|---|---|---|
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net6.0 | 215.6 KB | 211.7 KB | -3.9 KB | -1.81% |
Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatBenchmark‑net472 | 62.46 KB | 55.78 KB | -6.68 KB | -10.69% |
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | StringConcatBenchmark |
net6.0 | 50.8μs | 164ns | 615ns | 0 | 0 | 0 | 43.44 KB |
master | StringConcatBenchmark |
netcoreapp3.1 | 52μs | 183ns | 659ns | 0 | 0 | 0 | 42.64 KB |
master | StringConcatBenchmark |
net472 | 37.4μs | 87.3ns | 315ns | 0 | 0 | 0 | 62.46 KB |
master | StringConcatAspectBenchmark |
net6.0 | 277μs | 1.39μs | 9.35μs | 0 | 0 | 0 | 215.6 KB |
master | StringConcatAspectBenchmark |
netcoreapp3.1 | 277μs | 1.32μs | 8.15μs | 0 | 0 | 0 | 202.2 KB |
master | StringConcatAspectBenchmark |
net472 | 233μs | 2.59μs | 24.7μs | 0 | 0 | 0 | 221.18 KB |
#5148 | StringConcatBenchmark |
net6.0 | 58.5μs | 747ns | 7.4μs | 0 | 0 | 0 | 43.44 KB |
#5148 | StringConcatBenchmark |
netcoreapp3.1 | 51.8μs | 248ns | 960ns | 0 | 0 | 0 | 42.64 KB |
#5148 | StringConcatBenchmark |
net472 | 38.1μs | 120ns | 450ns | 0 | 0 | 0 | 55.78 KB |
#5148 | StringConcatAspectBenchmark |
net6.0 | 266μs | 1.38μs | 9.16μs | 0 | 0 | 0 | 211.7 KB |
#5148 | StringConcatAspectBenchmark |
netcoreapp3.1 | 282μs | 1.22μs | 7.79μs | 0 | 0 | 0 | 202.98 KB |
#5148 | StringConcatAspectBenchmark |
net472 | 245μs | 3.58μs | 34.7μs | 0 | 0 | 0 | 226.62 KB |
Benchmarks.Trace.ILoggerBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | EnrichedLog |
net6.0 | 1.4μs | 0.663ns | 2.48ns | 0.0218 | 0 | 0 | 1.58 KB |
master | EnrichedLog |
netcoreapp3.1 | 2.18μs | 0.583ns | 2.1ns | 0.0217 | 0 | 0 | 1.58 KB |
master | EnrichedLog |
net472 | 2.66μs | 1.57ns | 5.89ns | 0.239 | 0 | 0 | 1.51 KB |
#5148 | EnrichedLog |
net6.0 | 1.47μs | 0.958ns | 3.58ns | 0.0219 | 0 | 0 | 1.58 KB |
#5148 | EnrichedLog |
netcoreapp3.1 | 2.16μs | 1.08ns | 4.05ns | 0.0221 | 0 | 0 | 1.58 KB |
#5148 | EnrichedLog |
net472 | 2.53μs | 1.03ns | 3.98ns | 0.239 | 0 | 0 | 1.51 KB |
Benchmarks.Trace.Log4netBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | EnrichedLog |
net6.0 | 113μs | 184ns | 713ns | 0.0565 | 0 | 0 | 4.22 KB |
master | EnrichedLog |
netcoreapp3.1 | 119μs | 152ns | 590ns | 0.0591 | 0 | 0 | 4.22 KB |
master | EnrichedLog |
net472 | 148μs | 199ns | 771ns | 0.663 | 0.221 | 0 | 4.4 KB |
#5148 | EnrichedLog |
net6.0 | 112μs | 122ns | 458ns | 0.0557 | 0 | 0 | 4.22 KB |
#5148 | EnrichedLog |
netcoreapp3.1 | 118μs | 127ns | 477ns | 0.0587 | 0 | 0 | 4.22 KB |
#5148 | EnrichedLog |
net472 | 147μs | 122ns | 455ns | 0.66 | 0.22 | 0 | 4.4 KB |
Benchmarks.Trace.NLogBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | EnrichedLog |
net6.0 | 2.95μs | 8.8ns | 32.9ns | 0.0292 | 0 | 0 | 2.14 KB |
master | EnrichedLog |
netcoreapp3.1 | 4.05μs | 2.42ns | 9.06ns | 0.0284 | 0 | 0 | 2.14 KB |
master | EnrichedLog |
net472 | 4.72μs | 5.48ns | 21.2ns | 0.308 | 0 | 0 | 1.95 KB |
#5148 | EnrichedLog |
net6.0 | 3.15μs | 1.86ns | 7.2ns | 0.0298 | 0 | 0 | 2.14 KB |
#5148 | EnrichedLog |
netcoreapp3.1 | 4.28μs | 1.74ns | 6.76ns | 0.0279 | 0 | 0 | 2.14 KB |
#5148 | EnrichedLog |
net472 | 4.75μs | 2.51ns | 9.72ns | 0.31 | 0 | 0 | 1.95 KB |
Benchmarks.Trace.RedisBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | SendReceive |
net6.0 | 1.38μs | 0.856ns | 3.31ns | 0.0158 | 0 | 0 | 1.11 KB |
master | SendReceive |
netcoreapp3.1 | 1.75μs | 1.06ns | 3.96ns | 0.0157 | 0 | 0 | 1.11 KB |
master | SendReceive |
net472 | 1.98μs | 0.765ns | 2.86ns | 0.178 | 0 | 0 | 1.12 KB |
#5148 | SendReceive |
net6.0 | 1.4μs | 1.21ns | 4.68ns | 0.0154 | 0 | 0 | 1.11 KB |
#5148 | SendReceive |
netcoreapp3.1 | 1.71μs | 0.947ns | 3.67ns | 0.0154 | 0 | 0 | 1.11 KB |
#5148 | SendReceive |
net472 | 2.06μs | 2.12ns | 8.2ns | 0.178 | 0 | 0 | 1.12 KB |
Benchmarks.Trace.SerilogBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | EnrichedLog |
net6.0 | 2.9μs | 0.839ns | 3.25ns | 0.0209 | 0 | 0 | 1.54 KB |
master | EnrichedLog |
netcoreapp3.1 | 3.74μs | 1.47ns | 5.52ns | 0.0208 | 0 | 0 | 1.58 KB |
master | EnrichedLog |
net472 | 4.33μs | 1.85ns | 7.15ns | 0.313 | 0 | 0 | 1.97 KB |
#5148 | EnrichedLog |
net6.0 | 2.71μs | 0.99ns | 3.7ns | 0.0218 | 0 | 0 | 1.54 KB |
#5148 | EnrichedLog |
netcoreapp3.1 | 3.95μs | 1.02ns | 3.83ns | 0.0218 | 0 | 0 | 1.58 KB |
#5148 | EnrichedLog |
net472 | 4.24μs | 1.62ns | 6.29ns | 0.312 | 0 | 0 | 1.97 KB |
Benchmarks.Trace.SpanBenchmark - Faster 🎉 Same allocations ✔️
Faster 🎉 in #5148
Benchmark
base/diff
Base Median (ns)
Diff Median (ns)
Modality
Benchmarks.Trace.SpanBenchmark.StartFinishSpan‑netcoreapp3.1
1.129
726.78
643.68
Benchmarks.Trace.SpanBenchmark.StartFinishScope‑net6.0
1.121
596.99
532.55
Benchmark | base/diff | Base Median (ns) | Diff Median (ns) | Modality |
---|---|---|---|---|
Benchmarks.Trace.SpanBenchmark.StartFinishSpan‑netcoreapp3.1 | 1.129 | 726.78 | 643.68 | |
Benchmarks.Trace.SpanBenchmark.StartFinishScope‑net6.0 | 1.121 | 596.99 | 532.55 |
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | StartFinishSpan |
net6.0 | 461ns | 0.827ns | 3.2ns | 0.00759 | 0 | 0 | 544 B |
master | StartFinishSpan |
netcoreapp3.1 | 724ns | 1.98ns | 7.68ns | 0.00747 | 0 | 0 | 544 B |
master | StartFinishSpan |
net472 | 723ns | 1.66ns | 6.42ns | 0.0866 | 0 | 0 | 546 B |
master | StartFinishScope |
net6.0 | 597ns | 0.85ns | 3.29ns | 0.00927 | 0 | 0 | 664 B |
master | StartFinishScope |
netcoreapp3.1 | 773ns | 1.91ns | 7.41ns | 0.00881 | 0 | 0 | 664 B |
master | StartFinishScope |
net472 | 987ns | 1.82ns | 7.05ns | 0.0992 | 0 | 0 | 626 B |
#5148 | StartFinishSpan |
net6.0 | 459ns | 0.778ns | 3.01ns | 0.00757 | 0 | 0 | 544 B |
#5148 | StartFinishSpan |
netcoreapp3.1 | 644ns | 1.1ns | 4.26ns | 0.00716 | 0 | 0 | 544 B |
#5148 | StartFinishSpan |
net472 | 734ns | 1.68ns | 6.52ns | 0.0866 | 0 | 0 | 546 B |
#5148 | StartFinishScope |
net6.0 | 533ns | 0.985ns | 3.81ns | 0.00933 | 0 | 0 | 664 B |
#5148 | StartFinishScope |
netcoreapp3.1 | 787ns | 1.66ns | 6.45ns | 0.0086 | 0 | 0 | 664 B |
#5148 | StartFinishScope |
net472 | 998ns | 2.05ns | 7.95ns | 0.0995 | 0 | 0 | 626 B |
Benchmarks.Trace.TraceAnnotationsBenchmark - Slower ⚠️ Same allocations ✔️
Slower ⚠️ in #5148
Benchmark
diff/base
Base Median (ns)
Diff Median (ns)
Modality
Benchmarks.Trace.TraceAnnotationsBenchmark.RunOnMethodBegin‑net6.0
1.248
633.23
790.40
Faster 🎉 in #5148
Benchmark
base/diff
Base Median (ns)
Diff Median (ns)
Modality
Benchmarks.Trace.TraceAnnotationsBenchmark.RunOnMethodBegin‑netcoreapp3.1
1.192
1,032.46
866.17
Benchmark | diff/base | Base Median (ns) | Diff Median (ns) | Modality |
---|---|---|---|---|
Benchmarks.Trace.TraceAnnotationsBenchmark.RunOnMethodBegin‑net6.0 | 1.248 | 633.23 | 790.40 |
Benchmark | base/diff | Base Median (ns) | Diff Median (ns) | Modality |
---|---|---|---|---|
Benchmarks.Trace.TraceAnnotationsBenchmark.RunOnMethodBegin‑netcoreapp3.1 | 1.192 | 1,032.46 | 866.17 |
Raw results
Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
---|---|---|---|---|---|---|---|---|---|
master | RunOnMethodBegin |
net6.0 | 632ns | 1.01ns | 3.91ns | 0.00927 | 0 | 0 | 664 B |
master | RunOnMethodBegin |
netcoreapp3.1 | 1.03μs | 1.38ns | 5.34ns | 0.00878 | 0 | 0 | 664 B |
master | RunOnMethodBegin |
net472 | 1.08μs | 2.75ns | 10.7ns | 0.0995 | 0 | 0 | 626 B |
#5148 | RunOnMethodBegin |
net6.0 | 791ns | 1.01ns | 3.93ns | 0.00939 | 0 | 0 | 664 B |
#5148 | RunOnMethodBegin |
netcoreapp3.1 | 867ns | 1.69ns | 6.53ns | 0.00876 | 0 | 0 | 664 B |
#5148 | RunOnMethodBegin |
net472 | 1.08μs | 2.08ns | 8.05ns | 0.0994 | 0 | 0 | 626 B |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nice work. TY
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM in general, just some perf suggestions around handling StringValues
etc!
2c504ff
to
7e02c5a
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nice work 👍 Just one tiny suggestion 🙂
93fce56
to
4bfdecd
Compare
a9c18e8
to
2ce9f7b
Compare
Summary of changes
Reason for change
Detection of Insecure Auth Protocol vulnerability.
https://datadoghq.atlassian.net/wiki/spaces/APS/pages/3435364353/Insecure+Auth+Protocol
Implementation details
Basic
orDigest
scheme we report anINSECURE_AUTH_PROTOCOL
vulnerabilityThe evidence reported is:
Authorization: Basic
orAuthorization: Digest
Evidence redaction is not needed.
Test coverage
Integration tests with different Authorization header that are correct (with valid and valid but unusual format) to check if the vulnerability is triggered.