-
Notifications
You must be signed in to change notification settings - Fork 151
[DO NOT MERGE][2/x] feat(ssi): IIS injection can be disabled #7586
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: dmehala/add-policy-engine
Are you sure you want to change the base?
[DO NOT MERGE][2/x] feat(ssi): IIS injection can be disabled #7586
Conversation
Rules for NOT instrumenting application pools are now supported by the policy engine.
Execution-Time Benchmarks Report ⏱️Execution-time results for samples comparing the following branches/commits: Execution-time benchmarks measure the whole time it takes to execute a program. And are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are shown in red. The following thresholds were used for comparing the execution times:
Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard. Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph). gantt
title Execution time (ms) FakeDbCommand (.NET Framework 4.8)
dateFormat X
axisFormat %s
todayMarker off
section Bailout
This PR (7586) - mean (72ms) : 71, 73
. : milestone, 72,
master - mean (72ms) : 71, 73
. : milestone, 72,
section Baseline
This PR (7586) - mean (68ms) : 66, 71
. : milestone, 68,
master - mean (68ms) : 65, 71
. : milestone, 68,
section CallTarget+Inlining+NGEN
This PR (7586) - mean (1,049ms) : 1000, 1097
. : milestone, 1049,
master - mean (1,044ms) : 1011, 1076
. : milestone, 1044,
gantt
title Execution time (ms) FakeDbCommand (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Bailout
This PR (7586) - mean (106ms) : 105, 108
. : milestone, 106,
master - mean (106ms) : 105, 108
. : milestone, 106,
section Baseline
This PR (7586) - mean (106ms) : 104, 108
. : milestone, 106,
master - mean (106ms) : 104, 108
. : milestone, 106,
section CallTarget+Inlining+NGEN
This PR (7586) - mean (747ms) : 718, 777
. : milestone, 747,
master - mean (746ms) : 727, 764
. : milestone, 746,
gantt
title Execution time (ms) FakeDbCommand (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Bailout
This PR (7586) - mean (101ms) : 99, 102
. : milestone, 101,
master - mean (100ms) : 100, 101
. : milestone, 100,
section Baseline
This PR (7586) - mean (100ms) : 97, 103
. : milestone, 100,
master - mean (100ms) : 98, 103
. : milestone, 100,
section CallTarget+Inlining+NGEN
This PR (7586) - mean (773ms) : 732, 814
. : milestone, 773,
master - mean (775ms) : 723, 827
. : milestone, 775,
gantt
title Execution time (ms) FakeDbCommand (.NET 8)
dateFormat X
axisFormat %s
todayMarker off
section Bailout
This PR (7586) - mean (93ms) : 92, 94
. : milestone, 93,
master - mean (93ms) : 92, 94
. : milestone, 93,
section Baseline
This PR (7586) - mean (92ms) : 90, 94
. : milestone, 92,
master - mean (92ms) : 89, 95
. : milestone, 92,
section CallTarget+Inlining+NGEN
This PR (7586) - mean (658ms) : 643, 672
. : milestone, 658,
master - mean (664ms) : 649, 678
. : milestone, 664,
gantt
title Execution time (ms) HttpMessageHandler (.NET Framework 4.8)
dateFormat X
axisFormat %s
todayMarker off
section Bailout
This PR (7586) - mean (203ms) : 196, 209
. : milestone, 203,
master - mean (200ms) : 197, 204
. : milestone, 200,
section Baseline
This PR (7586) - mean (199ms) : 192, 207
. : milestone, 199,
master - mean (200ms) : 189, 211
. : milestone, 200,
section CallTarget+Inlining+NGEN
This PR (7586) - mean (1,183ms) : 1123, 1244
. : milestone, 1183,
master - mean (1,199ms) : 1130, 1268
. : milestone, 1199,
gantt
title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Bailout
This PR (7586) - mean (287ms) : 279, 295
. : milestone, 287,
master - mean (286ms) : 277, 296
. : milestone, 286,
section Baseline
This PR (7586) - mean (285ms) : 277, 294
. : milestone, 285,
master - mean (283ms) : 275, 291
. : milestone, 283,
section CallTarget+Inlining+NGEN
This PR (7586) - mean (945ms) : 903, 987
. : milestone, 945,
master - mean (950ms) : 902, 998
. : milestone, 950,
gantt
title Execution time (ms) HttpMessageHandler (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Bailout
This PR (7586) - mean (288ms) : 280, 297
. : milestone, 288,
master - mean (289ms) : 277, 301
. : milestone, 289,
section Baseline
This PR (7586) - mean (287ms) : 280, 295
. : milestone, 287,
master - mean (288ms) : 280, 296
. : milestone, 288,
section CallTarget+Inlining+NGEN
This PR (7586) - mean (998ms) : 937, 1059
. : milestone, 998,
master - mean (1,011ms) : 953, 1069
. : milestone, 1011,
gantt
title Execution time (ms) HttpMessageHandler (.NET 8)
dateFormat X
axisFormat %s
todayMarker off
section Bailout
This PR (7586) - mean (275ms) : 269, 282
. : milestone, 275,
master - mean (276ms) : 267, 285
. : milestone, 276,
section Baseline
This PR (7586) - mean (277ms) : 268, 285
. : milestone, 277,
master - mean (278ms) : 269, 287
. : milestone, 278,
section CallTarget+Inlining+NGEN
This PR (7586) - mean (864ms) : 842, 886
. : milestone, 864,
master - mean (875ms) : 847, 902
. : milestone, 875,
|
|
|
||
auto maybe_error = plcs::evaluate_buffer_from_file(GetPoliciesPath()); | ||
if (maybe_error) { | ||
Log::Error("CorProfiler::Initialize: An error occured while evaluating workload selection (reason: ", *maybe_error, ")"); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: aren't we missing identation here?
Log::Error("CorProfiler::Initialize: An error occured while evaluating workload selection (reason: ", *maybe_error, ")"); | ||
return E_FAIL; | ||
plcs::register_action(plcs::Action::INJECT_DENY, [&injection_status](plcs::Result eval_result, const std::vector<const char*>&, const char* desc) -> std::optional<plcs::Error> { | ||
if (injection_status == InjectionStatus::DENY) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We should update the status only if it's unknown, the first rule that fires a Deny or an Allow wins.
|
||
plcs::register_action(plcs::Action::INJECT_ALLOW, [&injection_status](plcs::Result eval_result, const std::vector<const char*>&, const char* desc) -> std::optional<plcs::Error> { | ||
if (injection_status == InjectionStatus::ALLOW) | ||
{ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Idem here, we should update only if the status is Unknown
|
||
if (isIis) { | ||
if (injection_status == InjectionStatus::DENY) { | ||
return CORPROF_E_PROFILER_CANCEL_ACTIVATION; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We can have the log "CorProfiler::Initialize: Instrumentation denied due to workload selection." here, it's even more true than for the case below where deny is the default behavior.
Summary of changes
The policy engine now supports rules for excluding application pools from instrumentation
Reason for change
Implementation details
Test coverage
Other details