[ASM] Activate api sec by default#6043
Conversation
Datadog ReportBranch report: ✅ 0 Failed, 363153 Passed, 2052 Skipped, 16h 45m 24.84s Total Time |
Execution-Time Benchmarks Report ⏱️Execution-time results for samples comparing the following branches/commits: Execution-time benchmarks measure the whole time it takes to execute a program. And are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are shown in red. The following thresholds were used for comparing the execution times:
Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard. Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph). gantt
title Execution time (ms) FakeDbCommand (.NET Framework 4.6.2)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6043) - mean (71ms) : 66, 77
. : milestone, 71,
master - mean (71ms) : 68, 74
. : milestone, 71,
section CallTarget+Inlining+NGEN
This PR (6043) - mean (1,107ms) : 1081, 1133
. : milestone, 1107,
master - mean (1,120ms) : 1092, 1147
. : milestone, 1120,
gantt
title Execution time (ms) FakeDbCommand (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6043) - mean (110ms) : 106, 113
. : milestone, 110,
master - mean (109ms) : 106, 112
. : milestone, 109,
section CallTarget+Inlining+NGEN
This PR (6043) - mean (775ms) : 759, 790
. : milestone, 775,
master - mean (773ms) : 756, 790
. : milestone, 773,
gantt
title Execution time (ms) FakeDbCommand (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6043) - mean (93ms) : 90, 96
. : milestone, 93,
master - mean (94ms) : 90, 98
. : milestone, 94,
section CallTarget+Inlining+NGEN
This PR (6043) - mean (733ms) : 716, 751
. : milestone, 733,
master - mean (735ms) : 719, 751
. : milestone, 735,
gantt
title Execution time (ms) HttpMessageHandler (.NET Framework 4.6.2)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6043) - mean (190ms) : 187, 193
. : milestone, 190,
master - mean (190ms) : 188, 193
. : milestone, 190,
section CallTarget+Inlining+NGEN
This PR (6043) - mean (1,196ms) : 1179, 1213
. : milestone, 1196,
master - mean (1,201ms) : 1180, 1222
. : milestone, 1201,
gantt
title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6043) - mean (276ms) : 271, 280
. : milestone, 276,
master - mean (276ms) : 272, 280
. : milestone, 276,
section CallTarget+Inlining+NGEN
This PR (6043) - mean (937ms) : 913, 960
. : milestone, 937,
master - mean (944ms) : 927, 961
. : milestone, 944,
gantt
title Execution time (ms) HttpMessageHandler (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6043) - mean (264ms) : 261, 268
. : milestone, 264,
master - mean (265ms) : 261, 268
. : milestone, 265,
section CallTarget+Inlining+NGEN
This PR (6043) - mean (924ms) : 908, 941
. : milestone, 924,
master - mean (927ms) : 906, 949
. : milestone, 927,
|
Snapshots difference summaryThe following differences have been observed in committed snapshots. It is meant to help the reviewer. 1 occurrences of : + "_dd.appsec.s.req.params": "H4sIAAAAAAAAA4uuVkrOzyspys/JSS1Ssoq2iNVRSkwuyczPA3NqYwH+CR9jIQAAAA==",
+ "_dd.appsec.s.res.body": "H4sIAAAAAAAAA4u2iAUA8YntnQMAAAA=",
+ "_dd.appsec.s.req.headers": "H4sIAAAAAAAAA4WOMQ6AIBAE/3I1FHaGrxCKixAkQSBwhYbwdzUWNhDqnd1ZWeHkGgl1tDxhNoG40yCklKtSrII3AcTSFAPKuJlCSKYb/zOEtkyQgkfyLjzK7GJ2dI2N36mZ8iVHx/dYev2mbkdocaj9AAAA",
+ "_dd.appsec.s.res.headers": "H4sIAAAAAAAAA4uuVkrOzytJzSvRLaksSFWyio6OtoiN1alWyknNU7IyrI2tjQUAcaAU2yQAAAA=",
1 occurrences of : + "_dd.appsec.s.res.body": "H4sIAAAAAAAAA4u2iAUA8YntnQMAAAA=",
+ "_dd.appsec.s.req.headers": "H4sIAAAAAAAAA4WOMQrAIBDA/uKsQ7fiVw6Ho4oVrIp3Q4v491JcLc4JJNAEVzwcMbITGgB2Y2QT0SWht27kwAWrSzzlt7LIaLNXjJ4WCuFVYkhelRpyDfws/NFVwa7S3+SfdmaarXfzAg6PMlH9AAAA",
+ "_dd.appsec.s.res.headers": "H4sIAAAAAAAAA4uuVkrOzytJzSvRLaksSFWyio6OtoiN1alWyknNU7IyrI2tjQUAcaAU2yQAAAA=",
|
Benchmarks Report for appsec 🐌Benchmarks for #6043 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.Asm.AppSecBodyBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecEncoderBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecWafBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Iast.StringAspectsBenchmark - Faster 🎉 More allocations
|
| Benchmark | base/diff | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatBenchmark‑netcoreapp3.1 | 1.151 | 61,400.00 | 53,350.00 | several? |
| Benchmark | Base Allocated | Diff Allocated | Change | Change % |
|---|---|---|---|---|
| Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net6.0 | 252.99 KB | 257.82 KB | 4.83 KB | 1.91% |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | StringConcatBenchmark |
net6.0 | 59.4μs | 793ns | 7.89μs | 0 | 0 | 0 | 43.44 KB |
| master | StringConcatBenchmark |
netcoreapp3.1 | 61.9μs | 721ns | 7.18μs | 0 | 0 | 0 | 42.64 KB |
| master | StringConcatBenchmark |
net472 | 38.8μs | 194ns | 911ns | 0 | 0 | 0 | 57.26 KB |
| master | StringConcatAspectBenchmark |
net6.0 | 281μs | 5.86μs | 56.8μs | 0 | 0 | 0 | 252.99 KB |
| master | StringConcatAspectBenchmark |
netcoreapp3.1 | 341μs | 1.79μs | 11.7μs | 0 | 0 | 0 | 254.22 KB |
| master | StringConcatAspectBenchmark |
net472 | 279μs | 5.71μs | 55.4μs | 0 | 0 | 0 | 278.53 KB |
| #6043 | StringConcatBenchmark |
net6.0 | 59.9μs | 821ns | 8.21μs | 0 | 0 | 0 | 43.44 KB |
| #6043 | StringConcatBenchmark |
netcoreapp3.1 | 53.3μs | 241ns | 871ns | 0 | 0 | 0 | 42.64 KB |
| #6043 | StringConcatBenchmark |
net472 | 36.8μs | 93.5ns | 350ns | 0 | 0 | 0 | 57.16 KB |
| #6043 | StringConcatAspectBenchmark |
net6.0 | 313μs | 922ns | 3.19μs | 0 | 0 | 0 | 257.82 KB |
| #6043 | StringConcatAspectBenchmark |
netcoreapp3.1 | 337μs | 1.86μs | 11.2μs | 0 | 0 | 0 | 253.49 KB |
| #6043 | StringConcatAspectBenchmark |
net472 | 268μs | 5.11μs | 49.2μs | 0 | 0 | 0 | 278.53 KB |
Throughput/Crank Report ⚡Throughput results for AspNetCoreSimpleController comparing the following branches/commits: Cases where throughput results for the PR are worse than latest master (5% drop or greater), results are shown in red. Note that these results are based on a single point-in-time result for each branch. For full results, see one of the many, many dashboards! gantt
title Throughput Linux x64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (6043) (11.050M) : 0, 11049981
master (11.173M) : 0, 11173302
benchmarks/2.9.0 (11.081M) : 0, 11080577
section Automatic
This PR (6043) (7.340M) : 0, 7339795
master (7.279M) : 0, 7278664
benchmarks/2.9.0 (7.732M) : 0, 7732233
section Trace stats
master (7.532M) : 0, 7531539
section Manual
master (11.083M) : 0, 11082902
section Manual + Automatic
This PR (6043) (6.729M) : 0, 6729367
master (6.710M) : 0, 6709924
section DD_TRACE_ENABLED=0
master (10.153M) : 0, 10153208
gantt
title Throughput Linux arm64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (6043) (9.526M) : 0, 9525542
master (9.398M) : 0, 9398448
benchmarks/2.9.0 (9.798M) : 0, 9798067
section Automatic
This PR (6043) (6.442M) : 0, 6442291
master (6.529M) : 0, 6529082
section Trace stats
master (6.958M) : 0, 6957848
section Manual
master (9.566M) : 0, 9566040
section Manual + Automatic
This PR (6043) (6.004M) : 0, 6003771
master (6.221M) : 0, 6221012
section DD_TRACE_ENABLED=0
master (8.922M) : 0, 8921736
gantt
title Throughput Windows x64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (6043) (10.176M) : 0, 10175820
master (10.147M) : 0, 10147192
benchmarks/2.9.0 (10.067M) : 0, 10067315
section Automatic
This PR (6043) (6.776M) : 0, 6775798
master (6.895M) : 0, 6894968
benchmarks/2.9.0 (7.552M) : 0, 7552193
section Trace stats
master (7.434M) : 0, 7433935
section Manual
master (10.142M) : 0, 10142136
section Manual + Automatic
This PR (6043) (6.352M) : 0, 6352087
master (6.402M) : 0, 6401740
section DD_TRACE_ENABLED=0
master (9.547M) : 0, 9547292
|
Benchmarks Report for tracer 🐌Benchmarks for #6043 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.ActivityBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AgentWriterBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AspNetCoreBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.DbCommandBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.ElasticsearchBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.GraphQLBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.HttpClientBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.ILoggerBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Log4netBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.NLogBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.RedisBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.SerilogBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.SpanBenchmark - Faster 🎉 Same allocations ✔️
|
| Benchmark | base/diff | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.SpanBenchmark.StartFinishScope‑net6.0 | 1.167 | 562.50 | 481.92 |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | StartFinishSpan |
net6.0 | 394ns | 0.307ns | 1.19ns | 0.00809 | 0 | 0 | 576 B |
| master | StartFinishSpan |
netcoreapp3.1 | 586ns | 0.486ns | 1.82ns | 0.00781 | 0 | 0 | 576 B |
| master | StartFinishSpan |
net472 | 691ns | 0.492ns | 1.84ns | 0.0918 | 0 | 0 | 578 B |
| master | StartFinishScope |
net6.0 | 562ns | 0.32ns | 1.24ns | 0.00992 | 0 | 0 | 696 B |
| master | StartFinishScope |
netcoreapp3.1 | 711ns | 0.979ns | 3.79ns | 0.00953 | 0 | 0 | 696 B |
| master | StartFinishScope |
net472 | 887ns | 0.782ns | 3.03ns | 0.104 | 0 | 0 | 658 B |
| #6043 | StartFinishSpan |
net6.0 | 392ns | 0.192ns | 0.743ns | 0.00806 | 0 | 0 | 576 B |
| #6043 | StartFinishSpan |
netcoreapp3.1 | 612ns | 1.43ns | 5.55ns | 0.00788 | 0 | 0 | 576 B |
| #6043 | StartFinishSpan |
net472 | 652ns | 0.607ns | 2.35ns | 0.0916 | 0 | 0 | 578 B |
| #6043 | StartFinishScope |
net6.0 | 482ns | 0.334ns | 1.29ns | 0.00985 | 0 | 0 | 696 B |
| #6043 | StartFinishScope |
netcoreapp3.1 | 692ns | 0.382ns | 1.43ns | 0.00932 | 0 | 0 | 696 B |
| #6043 | StartFinishScope |
net472 | 904ns | 1.78ns | 6.89ns | 0.104 | 0 | 0 | 658 B |
Benchmarks.Trace.TraceAnnotationsBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | RunOnMethodBegin |
net6.0 | 603ns | 0.259ns | 1ns | 0.00982 | 0 | 0 | 696 B |
| master | RunOnMethodBegin |
netcoreapp3.1 | 996ns | 2.82ns | 10.6ns | 0.00945 | 0 | 0 | 696 B |
| master | RunOnMethodBegin |
net472 | 1.14μs | 1.24ns | 4.8ns | 0.105 | 0 | 0 | 658 B |
| #6043 | RunOnMethodBegin |
net6.0 | 604ns | 0.404ns | 1.57ns | 0.00992 | 0 | 0 | 696 B |
| #6043 | RunOnMethodBegin |
netcoreapp3.1 | 925ns | 0.761ns | 2.95ns | 0.00921 | 0 | 0 | 696 B |
| #6043 | RunOnMethodBegin |
net472 | 1.11μs | 0.637ns | 2.47ns | 0.104 | 0 | 0 | 658 B |
cdd933f to
985903a
Compare
985903a to
aa7b009
Compare
aa7b009 to
924b6fa
Compare
## Summary of changes Activate api security by default ## Reason for change https://docs.google.com/document/d/1BbF-ZQHG9seaaik578WFCb1PEs-SmKq34PHg5sG3q6s/edit#heading=h.d3npy38hknxa ## Implementation details Had to ignore the tags in the system tests as Gzip bytes results in different values under linux/windows Maybe future: implement in the test agent some normalization for api security tags. ## Test coverage ## Other details <!-- Fixes #{issue} --> <!--⚠️ Note: where possible, please obtain 2 approvals prior to merging. Unless CODEOWNERS specifies otherwise, for external teams it is typically best to have one review from a team member, and one review from apm-dotnet. Trivial changes do not require 2 reviews. -->
Summary of changes
Activate api security by default
Reason for change
https://docs.google.com/document/d/1BbF-ZQHG9seaaik578WFCb1PEs-SmKq34PHg5sG3q6s/edit#heading=h.d3npy38hknxa
Implementation details
Had to ignore the tags in the system tests as Gzip bytes results in different values under linux/windows
Maybe future: implement in the test agent some normalization for api security tags.
Test coverage
Other details