Skip to content

[debugger] Test PII redaction in log probe messages - #7471

Merged
watson merged 2 commits into
mainfrom
watson/log-line-pii
Aug 21, 2026
Merged

watson merged 2 commits into
mainfrom
watson/log-line-pii

Conversation

@watson

@watson watson commented Aug 6, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

Dynamic Instrumentation / Live Debugger already redacts PII in snapshots, but rendered log-probe messages use separate evaluation and serialization paths that can expose secrets or emit non-canonical placeholders. We need end-to-end coverage that verifies every sensitive expression emits the exact lowercase {redacted} placeholder and never includes the raw value.

Changes

  • Add separate rendered-message tests for sensitive identifiers and object members, whole-map rendering, literal map keys, computed map keys, and configured sensitive types.
  • Validate excluded identifiers and a non-sensitive control while checking every emitted message for raw-secret leakage.
  • Preserve existing workload locals and add the required password, map, and CustomPii fixtures across Java, Java OTel, Python, .NET, and Node.js weblogs.
  • Replace the shared hardcoded PII line number with language-specific mappings while preserving all existing downstream line-probe locations.
  • Record confirmed implementation bugs in DEBUG-5958, DEBUG-5959, DEBUG-5960, DEBUG-5961, DEBUG-5962, and DEBUG-5963.
  • Keep currently unimplemented Node.js and Ruby capabilities independently gated so they can be activated incrementally.

Validation

  • ./format.sh
  • Java: PII class, full expression-language class, and representative budget/snapshot line probes.
  • Python: PII class, full expression-language class, and representative budget/snapshot line probes.
  • .NET: PII class, full expression-language class, and representative budget/snapshot line probes.
  • Node.js and Ruby: existing excluded-identifiers coverage passes, with unsupported new capabilities skipped by manifests.

Workflow

  1. ⚠️ Create your PR as draft ⚠️
  2. Work on you PR until the CI passes
  3. Mark it as ready for review
    • Test logic is modified? -> Get a review from RFC owner.
    • Framework is modified, or non obvious usage of it -> get a review from R&P team

🚀 Once your PR is reviewed and the CI green, you can merge it!

🛟 #apm-shared-testing 🛟

Reviewer checklist

  • Anything but tests/ or manifests/ is modified ? I have the approval from R&P team
  • A docker base image is modified?
    • the relevant build-XXX-image label is present
  • A scenario is added, removed or renamed?

@github-actions

github-actions Bot commented Aug 6, 2026 •

Copy link
Copy Markdown
Contributor

CODEOWNERS have been resolved as:

manifests/dotnet.yml                                                    @DataDog/apm-dotnet @DataDog/asm-dotnet
manifests/java.yml                                                      @DataDog/asm-java @DataDog/apm-java
manifests/nodejs.yml                                                    @DataDog/dd-trace-js
manifests/python.yml                                                    @DataDog/apm-python @DataDog/asm-python
manifests/ruby.yml                                                      @DataDog/ruby-guild @DataDog/asm-ruby
tests/debugger/test_debugger_pii.py                                     @DataDog/debugger @DataDog/system-tests-core
tests/debugger/utils.py                                                 @DataDog/debugger @DataDog/system-tests-core
tests/debugger/utils/probes/pii_line.json                               @DataDog/debugger @DataDog/system-tests-core
tests/test_the_test/scenarios.json                                      @DataDog/system-tests-core
utils/build/docker/dotnet/weblog/Controllers/DebuggerController.cs      @DataDog/apm-dotnet @DataDog/asm-dotnet @DataDog/system-tests-core
utils/build/docker/java/spring-boot/src/main/java/com/datadoghq/system_tests/springboot/debugger/DebuggerController.java  @DataDog/apm-java @DataDog/asm-java @DataDog/system-tests-core
utils/build/docker/java_otel/spring-boot/src/main/java/com/datadoghq/system_tests/springboot/debugger/DebuggerController.java  @DataDog/opentelemetry @DataDog/system-tests-core
utils/build/docker/nodejs/express/debugger/index.js                     @DataDog/dd-trace-js @DataDog/system-tests-core
utils/build/docker/nodejs/express/debugger/pii.js                       @DataDog/dd-trace-js @DataDog/system-tests-core
utils/build/docker/nodejs/express4-typescript/debugger/index.ts         @DataDog/dd-trace-js @DataDog/system-tests-core
utils/build/docker/nodejs/express4-typescript/debugger/pii.ts           @DataDog/dd-trace-js @DataDog/system-tests-core
utils/build/docker/nodejs/fastify/debugger/index.js                     @DataDog/dd-trace-js @DataDog/system-tests-core
utils/build/docker/nodejs/fastify/debugger/pii.js                       @DataDog/dd-trace-js @DataDog/system-tests-core
utils/build/docker/python/flask/debugger/debugger_controller.py         @DataDog/apm-python @DataDog/asm-python @DataDog/system-tests-core
utils/build/docker/ruby/shared/rails/app/controllers/debugger_controller.rb  @DataDog/ruby-guild @DataDog/asm-ruby @DataDog/system-tests-core

@datadog-prod-us1-6

datadog-prod-us1-6 Bot commented Aug 6, 2026 •

Copy link
Copy Markdown

Tests

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 144e82e | Docs | View more details | Give us feedback!

@watson
watson force-pushed the watson/log-line-pii branch from 62e8050 to d1fe4f2 Compare August 6, 2026 11:39
@watson
watson marked this pull request as ready for review August 6, 2026 13:07
@watson
watson requested review from a team as code owners August 6, 2026 13:07
@watson
watson requested review from ZStriker19, avara1986, claponcet, dineshg13, dromanol and manuel-alvarez-alvarez and removed request for a team August 6, 2026 13:07

@datadog-prod-us1-6 datadog-prod-us1-6 Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Datadog Autotest: PASS

More details

The updated PII workloads and line-probe mappings resolve consistently across the enabled Java, .NET, Python, Ruby, and Node.js fixtures, and the new rendered-message checks cover the introduced secret shapes without exposing a diff-only regression.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Datadog Autotest · Commit d1fe4f2 · What is Autotest? · @DataDog review to ask questions · Any feedback? Reach out in #autotest

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d1fe4f2fb2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tests/debugger/test_debugger_pii.py Outdated
Comment thread tests/debugger/test_debugger_pii.py
Comment thread tests/debugger/test_debugger_pii.py
@datadog-prod-us1-6

datadog-prod-us1-6 Bot commented Aug 6, 2026 •

Copy link
Copy Markdown

View session in Datadog

Bits Code status: ✅ Done

Comment @DataDog to request changes

@watson
watson force-pushed the watson/log-line-pii branch from d1cae17 to cbe8dd1 Compare August 13, 2026 08:17
Add rendered-message coverage for sensitive identifiers, object members,
literal and computed map keys, configured types, excluded identifiers, and
a non-sensitive control.
Co-authored-by: Cursor <cursoragent@cursor.com>
@watson
watson force-pushed the watson/log-line-pii branch from cbe8dd1 to 144e82e Compare August 21, 2026 11:01
@watson
watson requested a review from a team as a code owner August 21, 2026 11:01

@datadog-prod-us1-6 datadog-prod-us1-6 Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Datadog Autotest: PASS

More details

The PII message tests use language-specific probe lines, check exact redaction, block raw secret values, and disable unsupported cases through manifests. No concrete defect appears in these changes.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Datadog Autotest · Commit 144e82e · What is Autotest? · @DataDog review to ask questions · Any feedback? Reach out in #autotest

@watson
watson merged commit 6fb53aa into main Aug 21, 2026
1400 of 1403 checks passed
@watson
watson deleted the watson/log-line-pii branch August 21, 2026 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants