Skip to content

Add the option to use go -race #52

Merged
jcstorms1 merged 2 commits into
mainfrom
storms/add-go-race-detection
Feb 10, 2022
Merged

Add the option to use go -race #52
jcstorms1 merged 2 commits into
mainfrom
storms/add-go-race-detection

Conversation

@jcstorms1

Copy link
Copy Markdown
Contributor

Created a secondary docker file, Docker.race.build, that will be used when RACE_DETECTION_ENABLED is set as true. It can be enabled with integration tests from the agent repo or when running the binary and layer build script individually.

@jcstorms1
jcstorms1 requested a review from a team as a code owner February 9, 2022 18:17
tar --exclude=.git -czf $ROOT_DIR/scripts/.src/datadog-agent.tgz datadog-agent
cd $ROOT_DIR

# Make sure to use the right build file if we want race detection enabled

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: I don't think you need this comment (code speaks for itself)

@nhinsch nhinsch left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good 👍

@jcstorms1
jcstorms1 merged commit 4e9b1e5 into main Feb 10, 2022
@jcstorms1
jcstorms1 deleted the storms/add-go-race-detection branch February 10, 2022 15:21
jchrostek-dd added a commit that referenced this pull request Apr 15, 2026
## Summary

Resolves all **24 open Dependabot security alerts** (2 critical, 6 high,
14 medium, 2 low) across three ecosystems by updating vulnerable
dependencies in test infrastructure.

**Note:** All affected dependencies are in test infrastructure
(`integration-tests/`, `local_tests/`), not the production Rust
extension (`bottlecap/`).

## Changes

### npm (`integration-tests/`)
- **axios** `^1.6.7` → `^1.15.0` — fixes SSRF bypass via NO_PROXY
hostname normalization (CVE-2025-62718, critical)

### Go (`local_tests/golang/`)
- **golang.org/x/net** `v0.2.0` → `v0.52.0` — fixes 8 alerts: HTTP/2
rapid reset, uncontrolled resource consumption, XSS, IPv6 zone ID proxy
bypass, excessive memory growth, stream cancellation, improper text
rendering
- **google.golang.org/grpc** `v1.50.1` → `v1.80.0` — fixes 2 alerts:
authorization bypass via missing leading slash (CVE-2026-33186,
critical), HTTP/2 rapid reset
- **google.golang.org/protobuf** `v1.28.1` → `v1.36.11` — fixes infinite
loop in protojson.Unmarshal
- **github.com/golang/glog** `v1.0.0` → `v1.2.5` — fixes insecure
temporary file usage

### Python (`local_tests/serverless-init/`)
- **Flask** `2.1.2` → `3.1.3` — fixes session cookie disclosure, missing
Vary:Cookie header
- **Werkzeug** `2.2.2` → `3.1.8` — fixes 9 alerts: debugger RCE,
safe_join Windows device name bypasses, multipart form DoS, resource
exhaustion, nameless cookie bypass

## Reviewer Notes

⚠️ **Go minimum version**: The `go` directive in
`local_tests/golang/go.mod` was auto-upgraded from `go 1.22` to `go
1.25.0` (required by `golang.org/x/net v0.52.0`). This only affects the
test Lambda function, not CI build toolchains for the main extension.

⚠️ **Flask/Werkzeug major version jump**: Flask 2.x → 3.x and Werkzeug
2.x → 3.x are major version bumps. The test app (`app.py`) uses minimal
Flask APIs and was reviewed for compatibility. However, `ddtrace==1.4.1`
compatibility with Flask 3.x should be verified in CI.

## Alert Breakdown

| Severity | Count | Alerts |
|----------|-------|--------|
| Critical | 2 | #128 (axios SSRF), #104 (gRPC auth bypass) |
| High | 6 | #52, #43, #40, #38, #37, #20 |
| Medium | 14 | #88, #74, #73, #70, #68, #65, #60, #59, #53, #51, #49,
#45, #41, #36 |
| Low | 2 | #89, #39 |

Co-authored-by: Claude Opus 4.6 (1M context) <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants