Repository navigation
Update instrumentation Gradle dependencies - #12747
gh-worker-dd-mergequeue-cf854d[bot] merged 3 commits into
Conversation
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cac0f660c6
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
This comment has been minimized.
This comment has been minimized.
There was a problem hiding this comment.
Two critical dependency-upgrade problems are present: Cucumber 8.0.4 breaks the latest-dependency suite in two distinct ways — a compilation failure due to the removed io.cucumber.core.api.TypeRegistry API (junit-5-cucumber-5.4 module), and a Java 8 lane UnsupportedClassVersionError because Cucumber 8 and JUnit Platform 6.1.3 require Java 17 (cucumber-5.4 module). Separately, locking Vert.x to 5.2.0 breaks the HTTP/2 compatibility suite.
🤖 Bits Code Review · Commit cac0f66 · @DataDog review to ask questions
🟢 Java Benchmark SLOs — All performance SLOs passed
PR vs. master results
Commit: Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion. |
|
/merge |
|
View all feedbacks in Devflow UI.
The expected merge time in
|
Picks up the testCompileClasspath/testRuntimeClasspath scope widening for javax.servlet:servlet-api, org.mockito:mockito-core (plus the new mockito-junit-jupiter dependency), and the tomcat 5.5.12 artifacts introduced upstream in #12747.
…12493) Add block-outcome telemetry for Tomcat blocking enforcement failures Report block_failure on appsec.waf.requests when Tomcat's blocking-commit path fails to enforce a decided block, mirroring the Netty implementation (#12316). Adds a shared TomcatBlockingHelper.tryCommitAndReport choke point used by all Tomcat/GlassFish blocking-commit call sites (5.5/6.0/7.0), and guards it against exceptions thrown by the registered BlockResponseFunction. Split TomcatBlockingHelper to fix muzzle failures in block-outcome telemetry Extract tryCommitAndReport()/reportBlockFailure(RequestContext) into a new catalina-independent BlockFailureReporter class in tomcat-common, since helperClassNames() injects the whole class and muzzle validates all its references against every declared library version - including the catalina-independent code path that doesn't need it. Fix spring-webmvc test fixture clobbering Tomcat's real BlockResponseFunction TestSpringBlockResponseFunction now delegates to the previously registered BlockResponseFunction (Tomcat's own, in production tests) instead of returning true/false unconditionally when RequestContextHolder is not yet populated by Spring, fixing 10 latestDepTest failures exposed by the tryCommitAndReport refactor. Fix: do not report block_failure when GlassFishBlockingHelper has no fallback response Guard the Servlet API fallback branch of tryBlock() so reportBlockFailure() only fires when a response was actually available to commit through (i.e. a commit was genuinely attempted). Previously it reported unconditionally whenever the fallback commit failed, including the brf == null / fallbackResp == null case where nothing was attempted at all. Fix: propagate commit exceptions instead of swallowing them in BlockFailureReporter Remove the catch(Exception) around brf.tryCommitBlockingResponse() in tryCommitAndReport() so it matches the Netty reference implementation (PR #12316), which only branches on the boolean return value. Several call sites (CommitActionInstrumentation in 5.5/7.0, ParsePartsInstrumentation, ParsedBodyParametersInstrumentation) rely on their enclosing advice's suppress = Throwable.class to abort the whole method when the commit throws, gating success-path side effects (closing the connection, injecting a BlockingException, marking the segment effectively blocked). Swallowing the exception inside tryCommitAndReport made those side effects run unconditionally even when nothing was actually committed to the client. Removing the catch restores the pre-existing control flow; exception-based commit failures are now a known gap not reported to block_failure telemetry, same as Netty. Addresses Codex review comment on PR #12493. Report block_failure for already-committed and write-failure branches in Tomcat Follow-up to PR review comment r4067498401: TomcatBlockingHelper.commitBlockingResponse() now reports block_failure when the response was already committed by something other than us, and when writing the blocking response throws. Safe against false positives from Tomcat's multiple per-request blocking evaluations via a new blockingResponseInitiated guard on TomcatBlockResponseFunction, mirroring Netty's existing pattern. Fix ambiguous tryCommitBlockingResponse mock after rebase Master (#12519) added a default BlockResponseFunction.tryCommitBlockingResponse(RequestContext, RequestBlockingAction) overload alongside the existing TraceSegment-based one, making bare any() matchers ambiguous. Disambiguate with any(TraceSegment.class), matching the overload GlassFishBlockingHelper actually invokes via BlockFailureReporter. Restore manual helperClassNames override for muzzle-sensitive Tomcat7 modules Master's automatic bytecode-based helper discovery (PR #12649) does not resolve BlockFailureReporter as a dependency of GlassFishBlockingHelper or ParsePartsInstrumentation$ParsePartsAdvice, causing muzzle to fail for tomcat-catalina 7.0.0/9.0.1 and all glassfish-embedded-all versions with "Missing class datadog.trace.instrumentation.tomcat.BlockFailureReporter". Regenerate tomcat-common gradle.lockfile after third rebase onto master Picks up the testCompileClasspath/testRuntimeClasspath scope widening for javax.servlet:servlet-api, org.mockito:mockito-core (plus the new mockito-junit-jupiter dependency), and the tomcat 5.5.12 artifacts introduced upstream in #12747. Co-authored-by: devflow.devflow-routing-intake <devflow.devflow-routing-intake@kubernetes.us1.ddbuild.io>
What Does This Do
This PR updates the Gradle dependency locks for instrumentations and their tests.
Motivation
Refresh Gradle dependencies to make sure to test latest versions of dependencies within their supported versions.
Dependency age policy
48h cooldown, reverted
Too new and no older eligible version exists, so the lockfiles were reverted to the baseline.
io.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations:2.32.0is 2h away from meeting cooldownorg.eclipse.jetty.compression:jetty-compression-common:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.compression:jetty-compression-gzip:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-jakarta-client:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-jakarta-common:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-jakarta-server:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-servlet:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee10:jetty-ee10-annotations:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee10:jetty-ee10-plus:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee10:jetty-ee10-servlet:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee10:jetty-ee10-webapp:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee8.websocket:jetty-ee8-websocket-javax-client:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee8.websocket:jetty-ee8-websocket-javax-common:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee8.websocket:jetty-ee8-websocket-javax-server:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee8.websocket:jetty-ee8-websocket-servlet:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee8:jetty-ee8-annotations:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee8:jetty-ee8-nested:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee8:jetty-ee8-plus:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee8:jetty-ee8-security:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee8:jetty-ee8-servlet:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee8:jetty-ee8-webapp:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee9.websocket:jetty-ee9-websocket-jakarta-client:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee9.websocket:jetty-ee9-websocket-jakarta-common:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee9.websocket:jetty-ee9-websocket-jakarta-server:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee9.websocket:jetty-ee9-websocket-servlet:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee9:jetty-ee9-annotations:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee9:jetty-ee9-nested:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee9:jetty-ee9-plus:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee9:jetty-ee9-security:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee9:jetty-ee9-servlet:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee9:jetty-ee9-webapp:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.ee:jetty-ee-webapp:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.websocket:jetty-websocket-core-client:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.websocket:jetty-websocket-core-common:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty.websocket:jetty-websocket-core-server:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-alpn-client:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-annotations:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-client:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-http:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-io:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-jndi:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-plus:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-security:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-server:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-session:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-util:12.1.14is 44h away from meeting cooldownorg.eclipse.jetty:jetty-xml:12.1.14is 44h away from meeting cooldown48h cooldown, updated to the previous version
Too new, so an older eligible version was used instead.
com.openai:openai-java-client-okhttp:4.76.0is 29h away from meeting cooldown, updated to4.75.1com.openai:openai-java-core:4.76.0is 29h away from meeting cooldown, updated to4.75.1com.openai:openai-java:4.76.0is 29h away from meeting cooldown, updated to4.75.1Contributor Checklist