Skip to content

Fix go tests to maintain order of the log output#38

Merged
jcstorms1 merged 20 commits into
mainfrom
storms/fix-go-tests
Nov 23, 2021
Merged

Fix go tests to maintain order of the log output#38
jcstorms1 merged 20 commits into
mainfrom
storms/fix-go-tests

Conversation

@jcstorms1

@jcstorms1 jcstorms1 commented Nov 9, 2021

Copy link
Copy Markdown
Contributor

Originally the handler contained logs and metrics leading to a single binary, but we did not sort the log output of the integration test. This led to constant changes in the integration test output. Trying to use sort when normalizing the logs resulted in unordered log lines. I went back to a separated metric and log binary which is also in line with the other tests.

@jcstorms1
jcstorms1 requested a review from a team as a code owner November 9, 2021 19:24
Comment thread integration_tests/serverless.yml Outdated
Comment thread integration_tests/serverless.yml Outdated
Comment thread integration_tests/src/go-tests/with-ddlambda/main.go
@nhinsch

nhinsch commented Nov 9, 2021

Copy link
Copy Markdown
Contributor

Looks like the tests are failing in CI (could be related to this PR, might be a pre-existing issue). What is causing those failures and is it possible to fix them in this PR?

@nhinsch nhinsch left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Per Slack message, I think this is now in a place where it's ready to be merged (we will then move the tests to the agent repo).

Comment thread integration_tests/run.sh

now=$(date +"%r")
echo "Sleeping $LOGS_WAIT_SECONDS seconds to wait for logs to appear in CloudWatch..."
echo "This should be done in 10 minutes from $now"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This message is a nice touch, I think it improves the user experience of running the tests.

@jcstorms1
jcstorms1 merged commit 989abfc into main Nov 23, 2021
@jcstorms1
jcstorms1 deleted the storms/fix-go-tests branch November 23, 2021 14:28
jchrostek-dd added a commit that referenced this pull request Apr 15, 2026
## Summary

Resolves all **24 open Dependabot security alerts** (2 critical, 6 high,
14 medium, 2 low) across three ecosystems by updating vulnerable
dependencies in test infrastructure.

**Note:** All affected dependencies are in test infrastructure
(`integration-tests/`, `local_tests/`), not the production Rust
extension (`bottlecap/`).

## Changes

### npm (`integration-tests/`)
- **axios** `^1.6.7` → `^1.15.0` — fixes SSRF bypass via NO_PROXY
hostname normalization (CVE-2025-62718, critical)

### Go (`local_tests/golang/`)
- **golang.org/x/net** `v0.2.0` → `v0.52.0` — fixes 8 alerts: HTTP/2
rapid reset, uncontrolled resource consumption, XSS, IPv6 zone ID proxy
bypass, excessive memory growth, stream cancellation, improper text
rendering
- **google.golang.org/grpc** `v1.50.1` → `v1.80.0` — fixes 2 alerts:
authorization bypass via missing leading slash (CVE-2026-33186,
critical), HTTP/2 rapid reset
- **google.golang.org/protobuf** `v1.28.1` → `v1.36.11` — fixes infinite
loop in protojson.Unmarshal
- **github.com/golang/glog** `v1.0.0` → `v1.2.5` — fixes insecure
temporary file usage

### Python (`local_tests/serverless-init/`)
- **Flask** `2.1.2` → `3.1.3` — fixes session cookie disclosure, missing
Vary:Cookie header
- **Werkzeug** `2.2.2` → `3.1.8` — fixes 9 alerts: debugger RCE,
safe_join Windows device name bypasses, multipart form DoS, resource
exhaustion, nameless cookie bypass

## Reviewer Notes

⚠️ **Go minimum version**: The `go` directive in
`local_tests/golang/go.mod` was auto-upgraded from `go 1.22` to `go
1.25.0` (required by `golang.org/x/net v0.52.0`). This only affects the
test Lambda function, not CI build toolchains for the main extension.

⚠️ **Flask/Werkzeug major version jump**: Flask 2.x → 3.x and Werkzeug
2.x → 3.x are major version bumps. The test app (`app.py`) uses minimal
Flask APIs and was reviewed for compatibility. However, `ddtrace==1.4.1`
compatibility with Flask 3.x should be verified in CI.

## Alert Breakdown

| Severity | Count | Alerts |
|----------|-------|--------|
| Critical | 2 | #128 (axios SSRF), #104 (gRPC auth bypass) |
| High | 6 | #52, #43, #40, #38, #37, #20 |
| Medium | 14 | #88, #74, #73, #70, #68, #65, #60, #59, #53, #51, #49,
#45, #41, #36 |
| Low | 2 | #89, #39 |

Co-authored-by: Claude Opus 4.6 (1M context) <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants