Skip to content

Update instrumentation Gradle dependencies - #12747

Merged
gh-worker-dd-mergequeue-cf854d[bot] merged 3 commits into
masterfrom
ci/update-gradle-dependencies-instrumentation-20261005
Oct 5, 2026
Merged

gh-worker-dd-mergequeue-cf854d[bot] merged 3 commits into
masterfrom
ci/update-gradle-dependencies-instrumentation-20261005

Conversation

@dd-octo-sts

@dd-octo-sts dd-octo-sts Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

What Does This Do

This PR updates the Gradle dependency locks for instrumentations and their tests.

Motivation

Refresh Gradle dependencies to make sure to test latest versions of dependencies within their supported versions.

Dependency age policy

48h cooldown, reverted

Too new and no older eligible version exists, so the lockfiles were reverted to the baseline.

  • io.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations:2.32.0 is 2h away from meeting cooldown
  • org.eclipse.jetty.compression:jetty-compression-common:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.compression:jetty-compression-gzip:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-jakarta-client:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-jakarta-common:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-jakarta-server:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-servlet:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee10:jetty-ee10-annotations:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee10:jetty-ee10-plus:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee10:jetty-ee10-servlet:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee10:jetty-ee10-webapp:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee8.websocket:jetty-ee8-websocket-javax-client:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee8.websocket:jetty-ee8-websocket-javax-common:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee8.websocket:jetty-ee8-websocket-javax-server:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee8.websocket:jetty-ee8-websocket-servlet:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee8:jetty-ee8-annotations:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee8:jetty-ee8-nested:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee8:jetty-ee8-plus:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee8:jetty-ee8-security:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee8:jetty-ee8-servlet:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee8:jetty-ee8-webapp:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee9.websocket:jetty-ee9-websocket-jakarta-client:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee9.websocket:jetty-ee9-websocket-jakarta-common:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee9.websocket:jetty-ee9-websocket-jakarta-server:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee9.websocket:jetty-ee9-websocket-servlet:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee9:jetty-ee9-annotations:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee9:jetty-ee9-nested:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee9:jetty-ee9-plus:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee9:jetty-ee9-security:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee9:jetty-ee9-servlet:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee9:jetty-ee9-webapp:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.ee:jetty-ee-webapp:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.websocket:jetty-websocket-core-client:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.websocket:jetty-websocket-core-common:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty.websocket:jetty-websocket-core-server:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-alpn-client:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-annotations:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-client:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-http:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-io:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-jndi:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-plus:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-security:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-server:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-session:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-util:12.1.14 is 44h away from meeting cooldown
  • org.eclipse.jetty:jetty-xml:12.1.14 is 44h away from meeting cooldown

48h cooldown, updated to the previous version

Too new, so an older eligible version was used instead.

  • com.openai:openai-java-client-okhttp:4.76.0 is 29h away from meeting cooldown, updated to 4.75.1
  • com.openai:openai-java-core:4.76.0 is 29h away from meeting cooldown, updated to 4.75.1
  • com.openai:openai-java:4.76.0 is 29h away from meeting cooldown, updated to 4.75.1

Contributor Checklist

  • Update PR title if a code change is needed to support one of those new dependencies

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@dd-octo-sts
dd-octo-sts Bot requested a review from a team as a code owner October 5, 2026 14:38
@dd-octo-sts dd-octo-sts Bot added the tag: no release notes Changes to exclude from release notes label Oct 5, 2026
@dd-octo-sts
dd-octo-sts Bot removed the request for review from a team October 5, 2026 14:38
@dd-octo-sts dd-octo-sts Bot added the tag: dependencies Dependencies related changes label Oct 5, 2026
@dd-octo-sts
dd-octo-sts Bot requested a review from vandonr October 5, 2026 14:38
@dd-octo-sts dd-octo-sts Bot added tag: no release notes Changes to exclude from release notes tag: dependencies Dependencies related changes labels Oct 5, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cac0f660c6

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread dd-java-agent/instrumentation/cucumber-5.4/gradle.lockfile Outdated
@datadog-datadog-prod-us1-2

This comment has been minimized.

@datadog-datadog-prod-us1-2 datadog-datadog-prod-us1-2 Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bits Code Review: FAIL

Two critical dependency-upgrade problems are present: Cucumber 8.0.4 breaks the latest-dependency suite in two distinct ways — a compilation failure due to the removed io.cucumber.core.api.TypeRegistry API (junit-5-cucumber-5.4 module), and a Java 8 lane UnsupportedClassVersionError because Cucumber 8 and JUnit Platform 6.1.3 require Java 17 (cucumber-5.4 module). Separately, locking Vert.x to 5.2.0 breaks the HTTP/2 compatibility suite.

Open Bits AI session

🤖 Bits Code Review · Commit cac0f66 · @DataDog review to ask questions

Comment thread dd-java-agent/instrumentation/junit/junit-5/junit-5-cucumber-5.4/gradle.lockfile Outdated
Comment thread dd-java-agent/instrumentation/vertx/vertx-web/vertx-web-5.0/gradle.lockfile Outdated
Comment thread dd-java-agent/instrumentation/cucumber-5.4/gradle.lockfile Outdated
@dd-octo-sts

dd-octo-sts Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor Author

🟢 Java Benchmark SLOs — All performance SLOs passed

Suite Status
Startup 🟢 pass

SLO thresholds are defined here based on automatically generated metrics. A warning is raised when results are within 5% of the threshold.

PR vs. master results
Scenario Candidate master Δ (95% CI of mean)
startup:insecure-bank:iast:Agent 14.15 s 14.12 s [-0.6%; +1.0%] (no difference)
startup:insecure-bank:tracing:Agent 13.05 s 13.07 s [-0.8%; +0.4%] (no difference)
startup:petclinic:appsec:Agent 17.19 s 17.10 s [-0.5%; +1.5%] (no difference)
startup:petclinic:iast:Agent 17.03 s 16.96 s [-0.6%; +1.4%] (no difference)
startup:petclinic:profiling:Agent 16.60 s 16.98 s [-3.4%; -1.1%] (significantly better)
startup:petclinic:sca:Agent 16.49 s 16.85 s [-7.5%; +3.3%] (unstable)
startup:petclinic:tracing:Agent 16.27 s 16.08 s [+0.3%; +2.1%] (maybe worse)

Commit: a0432e8a · CI Pipeline · Benchmarking Platform UI


Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion.

@AlexeyKuznetsov-DD

Copy link
Copy Markdown
Contributor

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-10-05 17:45:45 UTC ℹ️ Start processing command /merge


2026-10-05 17:45:49 UTC ℹ️ MergeQueue: pull request added to the queue

The expected merge time in master is approximately 1h (p90).


2026-10-05 18:59:15 UTC ℹ️ MergeQueue: This merge request was merged

@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot merged commit 0b61714 into master Oct 5, 2026
607 checks passed
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot deleted the ci/update-gradle-dependencies-instrumentation-20261005 branch October 5, 2026 18:59
@github-actions github-actions Bot added this to the 1.67.0 milestone Oct 5, 2026
jandro996 added a commit that referenced this pull request Oct 6, 2026
Picks up the testCompileClasspath/testRuntimeClasspath scope widening for
javax.servlet:servlet-api, org.mockito:mockito-core (plus the new
mockito-junit-jupiter dependency), and the tomcat 5.5.12 artifacts
introduced upstream in #12747.
gh-worker-dd-mergequeue-cf854d Bot pushed a commit that referenced this pull request Oct 7, 2026
…12493)

Add block-outcome telemetry for Tomcat blocking enforcement failures

Report block_failure on appsec.waf.requests when Tomcat's blocking-commit
path fails to enforce a decided block, mirroring the Netty implementation
(#12316). Adds a shared TomcatBlockingHelper.tryCommitAndReport choke point
used by all Tomcat/GlassFish blocking-commit call sites (5.5/6.0/7.0), and
guards it against exceptions thrown by the registered BlockResponseFunction.

Split TomcatBlockingHelper to fix muzzle failures in block-outcome telemetry

Extract tryCommitAndReport()/reportBlockFailure(RequestContext) into a new
catalina-independent BlockFailureReporter class in tomcat-common, since
helperClassNames() injects the whole class and muzzle validates all its
references against every declared library version - including the
catalina-independent code path that doesn't need it.

Fix spring-webmvc test fixture clobbering Tomcat's real BlockResponseFunction

TestSpringBlockResponseFunction now delegates to the previously registered
BlockResponseFunction (Tomcat's own, in production tests) instead of
returning true/false unconditionally when RequestContextHolder is not yet
populated by Spring, fixing 10 latestDepTest failures exposed by the
tryCommitAndReport refactor.

Fix: do not report block_failure when GlassFishBlockingHelper has no fallback response

Guard the Servlet API fallback branch of tryBlock() so reportBlockFailure()
only fires when a response was actually available to commit through (i.e. a
commit was genuinely attempted). Previously it reported unconditionally
whenever the fallback commit failed, including the brf == null / fallbackResp
== null case where nothing was attempted at all.

Fix: propagate commit exceptions instead of swallowing them in BlockFailureReporter

Remove the catch(Exception) around brf.tryCommitBlockingResponse() in
tryCommitAndReport() so it matches the Netty reference implementation
(PR #12316), which only branches on the boolean return value.

Several call sites (CommitActionInstrumentation in 5.5/7.0,
ParsePartsInstrumentation, ParsedBodyParametersInstrumentation) rely on
their enclosing advice's suppress = Throwable.class to abort the whole
method when the commit throws, gating success-path side effects (closing
the connection, injecting a BlockingException, marking the segment
effectively blocked). Swallowing the exception inside tryCommitAndReport
made those side effects run unconditionally even when nothing was
actually committed to the client. Removing the catch restores the
pre-existing control flow; exception-based commit failures are now a
known gap not reported to block_failure telemetry, same as Netty.

Addresses Codex review comment on PR #12493.

Report block_failure for already-committed and write-failure branches in Tomcat

Follow-up to PR review comment r4067498401: TomcatBlockingHelper.commitBlockingResponse()
now reports block_failure when the response was already committed by something other than
us, and when writing the blocking response throws. Safe against false positives from
Tomcat's multiple per-request blocking evaluations via a new blockingResponseInitiated
guard on TomcatBlockResponseFunction, mirroring Netty's existing pattern.

Fix ambiguous tryCommitBlockingResponse mock after rebase

Master (#12519) added a default BlockResponseFunction.tryCommitBlockingResponse(RequestContext, RequestBlockingAction)
overload alongside the existing TraceSegment-based one, making bare any()
matchers ambiguous. Disambiguate with any(TraceSegment.class), matching
the overload GlassFishBlockingHelper actually invokes via BlockFailureReporter.

Restore manual helperClassNames override for muzzle-sensitive Tomcat7 modules

Master's automatic bytecode-based helper discovery (PR #12649) does not
resolve BlockFailureReporter as a dependency of GlassFishBlockingHelper or
ParsePartsInstrumentation$ParsePartsAdvice, causing muzzle to fail for
tomcat-catalina 7.0.0/9.0.1 and all glassfish-embedded-all versions with
"Missing class datadog.trace.instrumentation.tomcat.BlockFailureReporter".

Regenerate tomcat-common gradle.lockfile after third rebase onto master

Picks up the testCompileClasspath/testRuntimeClasspath scope widening for
javax.servlet:servlet-api, org.mockito:mockito-core (plus the new
mockito-junit-jupiter dependency), and the tomcat 5.5.12 artifacts
introduced upstream in #12747.

Co-authored-by: devflow.devflow-routing-intake <devflow.devflow-routing-intake@kubernetes.us1.ddbuild.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tag: dependencies Dependencies related changes tag: no release notes Changes to exclude from release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants