[IAST] Improve RestSharp SSRF detection#6060
Conversation
Execution-Time Benchmarks Report ⏱️Execution-time results for samples comparing the following branches/commits: Execution-time benchmarks measure the whole time it takes to execute a program. And are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are shown in red. The following thresholds were used for comparing the execution times:
Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard. Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph). gantt
title Execution time (ms) FakeDbCommand (.NET Framework 4.6.2)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6060) - mean (71ms) : 68, 74
. : milestone, 71,
master - mean (70ms) : 67, 72
. : milestone, 70,
section CallTarget+Inlining+NGEN
This PR (6060) - mean (1,111ms) : 1089, 1132
. : milestone, 1111,
master - mean (1,101ms) : 1080, 1122
. : milestone, 1101,
gantt
title Execution time (ms) FakeDbCommand (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6060) - mean (110ms) : 107, 113
. : milestone, 110,
master - mean (109ms) : 106, 111
. : milestone, 109,
section CallTarget+Inlining+NGEN
This PR (6060) - mean (776ms) : 758, 794
. : milestone, 776,
master - mean (768ms) : 751, 786
. : milestone, 768,
gantt
title Execution time (ms) FakeDbCommand (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6060) - mean (94ms) : 89, 98
. : milestone, 94,
master - mean (92ms) : 89, 94
. : milestone, 92,
section CallTarget+Inlining+NGEN
This PR (6060) - mean (732ms) : 712, 753
. : milestone, 732,
master - mean (724ms) : 707, 742
. : milestone, 724,
gantt
title Execution time (ms) HttpMessageHandler (.NET Framework 4.6.2)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6060) - mean (191ms) : 187, 194
. : milestone, 191,
master - mean (190ms) : 187, 194
. : milestone, 190,
section CallTarget+Inlining+NGEN
This PR (6060) - mean (1,198ms) : 1175, 1220
. : milestone, 1198,
master - mean (1,190ms) : 1169, 1211
. : milestone, 1190,
gantt
title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6060) - mean (277ms) : 273, 281
. : milestone, 277,
master - mean (276ms) : 271, 282
. : milestone, 276,
section CallTarget+Inlining+NGEN
This PR (6060) - mean (945ms) : 924, 966
. : milestone, 945,
master - mean (933ms) : 918, 949
. : milestone, 933,
gantt
title Execution time (ms) HttpMessageHandler (.NET 6)
dateFormat X
axisFormat %s
todayMarker off
section Baseline
This PR (6060) - mean (265ms) : 261, 269
. : milestone, 265,
master - mean (265ms) : 261, 269
. : milestone, 265,
section CallTarget+Inlining+NGEN
This PR (6060) - mean (927ms) : 910, 944
. : milestone, 927,
master - mean (922ms) : 905, 938
. : milestone, 922,
|
Benchmarks Report for appsec 🐌Benchmarks for #6060 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.Asm.AppSecBodyBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecEncoderBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Asm.AppSecWafBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.Iast.StringAspectsBenchmark - Same speed ✔️ Fewer allocations 🎉
|
| Benchmark | Base Allocated | Diff Allocated | Change | Change % |
|---|---|---|---|---|
| Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark‑net6.0 | 256.82 KB | 255.46 KB | -1.35 KB | -0.53% |
| Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatBenchmark‑net472 | 59.6 KB | 57.34 KB | -2.26 KB | -3.79% |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | StringConcatBenchmark |
net6.0 | 60.5μs | 803ns | 8.03μs | 0 | 0 | 0 | 43.44 KB |
| master | StringConcatBenchmark |
netcoreapp3.1 | 60.2μs | 873ns | 8.69μs | 0 | 0 | 0 | 42.64 KB |
| master | StringConcatBenchmark |
net472 | 37μs | 66.7ns | 250ns | 0 | 0 | 0 | 59.6 KB |
| master | StringConcatAspectBenchmark |
net6.0 | 316μs | 1.25μs | 4.33μs | 0 | 0 | 0 | 256.82 KB |
| master | StringConcatAspectBenchmark |
netcoreapp3.1 | 341μs | 1.64μs | 8.96μs | 0 | 0 | 0 | 253.41 KB |
| master | StringConcatAspectBenchmark |
net472 | 282μs | 6.1μs | 60.4μs | 0 | 0 | 0 | 278.53 KB |
| #6060 | StringConcatBenchmark |
net6.0 | 60.8μs | 876ns | 8.72μs | 0 | 0 | 0 | 43.44 KB |
| #6060 | StringConcatBenchmark |
netcoreapp3.1 | 52.4μs | 244ns | 978ns | 0 | 0 | 0 | 42.64 KB |
| #6060 | StringConcatBenchmark |
net472 | 37.1μs | 150ns | 635ns | 0 | 0 | 0 | 57.34 KB |
| #6060 | StringConcatAspectBenchmark |
net6.0 | 313μs | 1.77μs | 12μs | 0 | 0 | 0 | 255.46 KB |
| #6060 | StringConcatAspectBenchmark |
netcoreapp3.1 | 348μs | 2.02μs | 16.7μs | 0 | 0 | 0 | 252.82 KB |
| #6060 | StringConcatAspectBenchmark |
net472 | 279μs | 6.94μs | 66.9μs | 0 | 0 | 0 | 278.53 KB |
Throughput/Crank Report ⚡Throughput results for AspNetCoreSimpleController comparing the following branches/commits: Cases where throughput results for the PR are worse than latest master (5% drop or greater), results are shown in red. Note that these results are based on a single point-in-time result for each branch. For full results, see one of the many, many dashboards! gantt
title Throughput Linux x64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (6060) (10.907M) : 0, 10906875
master (10.985M) : 0, 10985482
benchmarks/2.9.0 (11.081M) : 0, 11080577
section Automatic
This PR (6060) (7.065M) : 0, 7065286
master (7.069M) : 0, 7068614
benchmarks/2.9.0 (7.732M) : 0, 7732233
section Trace stats
master (7.445M) : 0, 7444611
section Manual
master (10.788M) : 0, 10788136
section Manual + Automatic
This PR (6060) (6.543M) : 0, 6543421
master (6.507M) : 0, 6507289
section DD_TRACE_ENABLED=0
master (9.793M) : 0, 9793388
gantt
title Throughput Linux arm64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (6060) (9.376M) : 0, 9375715
master (9.540M) : 0, 9540100
benchmarks/2.9.0 (9.798M) : 0, 9798067
section Automatic
This PR (6060) (6.667M) : 0, 6667342
master (6.620M) : 0, 6620231
section Trace stats
master (6.802M) : 0, 6801791
section Manual
master (9.545M) : 0, 9545216
section Manual + Automatic
This PR (6060) (6.157M) : 0, 6156784
master (6.127M) : 0, 6126637
section DD_TRACE_ENABLED=0
master (8.654M) : 0, 8654022
gantt
title Throughput Windows x64 (Total requests)
dateFormat X
axisFormat %s
section Baseline
This PR (6060) (10.268M) : 0, 10268012
master (10.337M) : 0, 10337059
benchmarks/2.9.0 (10.067M) : 0, 10067315
section Automatic
This PR (6060) (6.687M) : 0, 6687022
master (6.596M) : 0, 6595628
benchmarks/2.9.0 (7.552M) : 0, 7552193
section Trace stats
master (7.428M) : 0, 7427719
section Manual
master (9.976M) : 0, 9976270
section Manual + Automatic
This PR (6060) (6.420M) : 0, 6420085
master (6.092M) : 0, 6091995
section DD_TRACE_ENABLED=0
master (9.372M) : 0, 9371961
|
Datadog ReportBranch report: ✅ 0 Failed, 483557 Passed, 3910 Skipped, 42h 18m 33.82s Total Time |
Benchmarks Report for tracer 🐌Benchmarks for #6060 compared to master:
The following thresholds were used for comparing the benchmark speeds:
Allocation changes below 0.5% are ignored. Benchmark detailsBenchmarks.Trace.ActivityBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AgentWriterBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.AspNetCoreBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark - Same speed ✔️ Same allocations ✔️Raw results
Benchmarks.Trace.DbCommandBenchmark - Slower
|
| Benchmark | diff/base | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.DbCommandBenchmark.ExecuteNonQuery‑net6.0 | 1.154 | 1,190.02 | 1,373.59 |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | ExecuteNonQuery |
net6.0 | 1.19μs | 1.21ns | 4.7ns | 0.0142 | 0 | 0 | 1.02 KB |
| master | ExecuteNonQuery |
netcoreapp3.1 | 1.71μs | 1.33ns | 5.14ns | 0.0138 | 0 | 0 | 1.02 KB |
| master | ExecuteNonQuery |
net472 | 2.03μs | 2.81ns | 10.9ns | 0.157 | 0 | 0 | 987 B |
| #6060 | ExecuteNonQuery |
net6.0 | 1.37μs | 1.85ns | 6.93ns | 0.0145 | 0 | 0 | 1.02 KB |
| #6060 | ExecuteNonQuery |
netcoreapp3.1 | 1.76μs | 1.69ns | 6.34ns | 0.0132 | 0 | 0 | 1.02 KB |
| #6060 | ExecuteNonQuery |
net472 | 2.16μs | 4.15ns | 15.5ns | 0.156 | 0 | 0 | 987 B |
Benchmarks.Trace.ElasticsearchBenchmark - Slower ⚠️ Same allocations ✔️
Slower ⚠️ in #6060
Benchmark
diff/base
Base Median (ns)
Diff Median (ns)
Modality
Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearch‑net6.0
1.156
1,143.06
1,320.87
Faster 🎉 in #6060
Benchmark
base/diff
Base Median (ns)
Diff Median (ns)
Modality
Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearchAsync‑net6.0
1.121
1,381.93
1,233.12
| Benchmark | diff/base | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearch‑net6.0 | 1.156 | 1,143.06 | 1,320.87 |
| Benchmark | base/diff | Base Median (ns) | Diff Median (ns) | Modality |
|---|---|---|---|---|
| Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearchAsync‑net6.0 | 1.121 | 1,381.93 | 1,233.12 |
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | CallElasticsearch |
net6.0 | 1.14μs | 0.499ns | 1.87ns | 0.0137 | 0 | 0 | 976 B |
| master | CallElasticsearch |
netcoreapp3.1 | 1.55μs | 0.933ns | 3.23ns | 0.0132 | 0 | 0 | 976 B |
| master | CallElasticsearch |
net472 | 2.55μs | 0.653ns | 2.44ns | 0.157 | 0 | 0 | 995 B |
| master | CallElasticsearchAsync |
net6.0 | 1.38μs | 1.84ns | 6.64ns | 0.0133 | 0 | 0 | 952 B |
| master | CallElasticsearchAsync |
netcoreapp3.1 | 1.58μs | 1.13ns | 4.39ns | 0.0135 | 0 | 0 | 1.02 KB |
| master | CallElasticsearchAsync |
net472 | 2.69μs | 1.1ns | 4.26ns | 0.167 | 0 | 0 | 1.05 KB |
| #6060 | CallElasticsearch |
net6.0 | 1.32μs | 1.29ns | 4.98ns | 0.0132 | 0 | 0 | 976 B |
| #6060 | CallElasticsearch |
netcoreapp3.1 | 1.59μs | 5.87ns | 22.7ns | 0.0132 | 0 | 0 | 976 B |
| #6060 | CallElasticsearch |
net472 | 2.44μs | 1.33ns | 5.14ns | 0.158 | 0 | 0 | 995 B |
| #6060 | CallElasticsearchAsync |
net6.0 | 1.24μs | 1.65ns | 6.41ns | 0.0133 | 0 | 0 | 952 B |
| #6060 | CallElasticsearchAsync |
netcoreapp3.1 | 1.68μs | 1.1ns | 4.12ns | 0.0135 | 0 | 0 | 1.02 KB |
| #6060 | CallElasticsearchAsync |
net472 | 2.56μs | 1.44ns | 5.38ns | 0.166 | 0 | 0 | 1.05 KB |
Benchmarks.Trace.GraphQLBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | ExecuteAsync |
net6.0 | 1.21μs | 1.85ns | 7.17ns | 0.0132 | 0 | 0 | 952 B |
| master | ExecuteAsync |
netcoreapp3.1 | 1.63μs | 0.708ns | 2.65ns | 0.013 | 0 | 0 | 952 B |
| master | ExecuteAsync |
net472 | 1.74μs | 0.634ns | 2.46ns | 0.145 | 0 | 0 | 915 B |
| #6060 | ExecuteAsync |
net6.0 | 1.31μs | 0.585ns | 2.27ns | 0.013 | 0 | 0 | 952 B |
| #6060 | ExecuteAsync |
netcoreapp3.1 | 1.59μs | 1.63ns | 6.3ns | 0.0127 | 0 | 0 | 952 B |
| #6060 | ExecuteAsync |
net472 | 1.83μs | 0.805ns | 3.12ns | 0.145 | 0 | 0 | 915 B |
Benchmarks.Trace.HttpClientBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | SendAsync |
net6.0 | 4.18μs | 1.75ns | 6.55ns | 0.0313 | 0 | 0 | 2.22 KB |
| master | SendAsync |
netcoreapp3.1 | 5.03μs | 2.52ns | 9.43ns | 0.0376 | 0 | 0 | 2.76 KB |
| master | SendAsync |
net472 | 7.83μs | 2.08ns | 8.06ns | 0.499 | 0 | 0 | 3.15 KB |
| #6060 | SendAsync |
net6.0 | 4.18μs | 6.03ns | 22.6ns | 0.0311 | 0 | 0 | 2.22 KB |
| #6060 | SendAsync |
netcoreapp3.1 | 5.04μs | 1.49ns | 5.56ns | 0.038 | 0 | 0 | 2.76 KB |
| #6060 | SendAsync |
net472 | 7.8μs | 2.71ns | 10.5ns | 0.499 | 0 | 0 | 3.15 KB |
Benchmarks.Trace.ILoggerBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 1.55μs | 0.553ns | 2.07ns | 0.0232 | 0 | 0 | 1.64 KB |
| master | EnrichedLog |
netcoreapp3.1 | 2.26μs | 1.38ns | 5.15ns | 0.0226 | 0 | 0 | 1.64 KB |
| master | EnrichedLog |
net472 | 2.61μs | 1.03ns | 3.85ns | 0.25 | 0 | 0 | 1.57 KB |
| #6060 | EnrichedLog |
net6.0 | 1.45μs | 0.621ns | 2.4ns | 0.0232 | 0 | 0 | 1.64 KB |
| #6060 | EnrichedLog |
netcoreapp3.1 | 2.26μs | 1.26ns | 4.72ns | 0.0214 | 0 | 0 | 1.64 KB |
| #6060 | EnrichedLog |
net472 | 2.51μs | 0.737ns | 2.85ns | 0.249 | 0 | 0 | 1.57 KB |
Benchmarks.Trace.Log4netBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 115μs | 121ns | 436ns | 0.0574 | 0 | 0 | 4.28 KB |
| master | EnrichedLog |
netcoreapp3.1 | 118μs | 195ns | 754ns | 0.0594 | 0 | 0 | 4.28 KB |
| master | EnrichedLog |
net472 | 146μs | 207ns | 773ns | 0.652 | 0.217 | 0 | 4.46 KB |
| #6060 | EnrichedLog |
net6.0 | 114μs | 172ns | 667ns | 0 | 0 | 0 | 4.28 KB |
| #6060 | EnrichedLog |
netcoreapp3.1 | 118μs | 137ns | 531ns | 0.0594 | 0 | 0 | 4.28 KB |
| #6060 | EnrichedLog |
net472 | 146μs | 178ns | 690ns | 0.655 | 0.218 | 0 | 4.46 KB |
Benchmarks.Trace.NLogBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 3.07μs | 7.39ns | 28.6ns | 0.0307 | 0 | 0 | 2.2 KB |
| master | EnrichedLog |
netcoreapp3.1 | 4.21μs | 1.21ns | 4.53ns | 0.0294 | 0 | 0 | 2.2 KB |
| master | EnrichedLog |
net472 | 5.05μs | 1.51ns | 5.83ns | 0.32 | 0 | 0 | 2.02 KB |
| #6060 | EnrichedLog |
net6.0 | 3.21μs | 1.31ns | 5.08ns | 0.0304 | 0 | 0 | 2.2 KB |
| #6060 | EnrichedLog |
netcoreapp3.1 | 4.24μs | 3.53ns | 13.7ns | 0.0294 | 0 | 0 | 2.2 KB |
| #6060 | EnrichedLog |
net472 | 5.01μs | 1.51ns | 5.86ns | 0.32 | 0 | 0 | 2.02 KB |
Benchmarks.Trace.RedisBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | SendReceive |
net6.0 | 1.37μs | 0.684ns | 2.56ns | 0.0158 | 0 | 0 | 1.14 KB |
| master | SendReceive |
netcoreapp3.1 | 1.77μs | 1.11ns | 4.01ns | 0.015 | 0 | 0 | 1.14 KB |
| master | SendReceive |
net472 | 2.09μs | 0.76ns | 2.94ns | 0.183 | 0 | 0 | 1.16 KB |
| #6060 | SendReceive |
net6.0 | 1.36μs | 0.636ns | 2.46ns | 0.0163 | 0 | 0 | 1.14 KB |
| #6060 | SendReceive |
netcoreapp3.1 | 1.77μs | 0.446ns | 1.67ns | 0.0159 | 0 | 0 | 1.14 KB |
| #6060 | SendReceive |
net472 | 2.03μs | 0.918ns | 3.56ns | 0.183 | 0.00102 | 0 | 1.16 KB |
Benchmarks.Trace.SerilogBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | EnrichedLog |
net6.0 | 2.71μs | 1.26ns | 4.73ns | 0.023 | 0 | 0 | 1.6 KB |
| master | EnrichedLog |
netcoreapp3.1 | 3.86μs | 1.18ns | 4.57ns | 0.0213 | 0 | 0 | 1.65 KB |
| master | EnrichedLog |
net472 | 4.38μs | 1.32ns | 4.94ns | 0.324 | 0 | 0 | 2.04 KB |
| #6060 | EnrichedLog |
net6.0 | 2.65μs | 1.37ns | 5.29ns | 0.0225 | 0 | 0 | 1.6 KB |
| #6060 | EnrichedLog |
netcoreapp3.1 | 3.88μs | 1.99ns | 7.69ns | 0.0211 | 0 | 0 | 1.65 KB |
| #6060 | EnrichedLog |
net472 | 4.32μs | 1.65ns | 6.38ns | 0.324 | 0 | 0 | 2.04 KB |
Benchmarks.Trace.SpanBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | StartFinishSpan |
net6.0 | 410ns | 0.216ns | 0.837ns | 0.00802 | 0 | 0 | 576 B |
| master | StartFinishSpan |
netcoreapp3.1 | 551ns | 0.557ns | 2.08ns | 0.00774 | 0 | 0 | 576 B |
| master | StartFinishSpan |
net472 | 683ns | 0.499ns | 1.93ns | 0.0918 | 0 | 0 | 578 B |
| master | StartFinishScope |
net6.0 | 545ns | 0.346ns | 1.34ns | 0.00982 | 0 | 0 | 696 B |
| master | StartFinishScope |
netcoreapp3.1 | 666ns | 0.358ns | 1.29ns | 0.00955 | 0 | 0 | 696 B |
| master | StartFinishScope |
net472 | 837ns | 0.921ns | 3.57ns | 0.104 | 0 | 0 | 658 B |
| #6060 | StartFinishSpan |
net6.0 | 416ns | 0.281ns | 1.09ns | 0.00812 | 0 | 0 | 576 B |
| #6060 | StartFinishSpan |
netcoreapp3.1 | 544ns | 0.476ns | 1.84ns | 0.00791 | 0 | 0 | 576 B |
| #6060 | StartFinishSpan |
net472 | 654ns | 0.843ns | 3.27ns | 0.0916 | 0 | 0 | 578 B |
| #6060 | StartFinishScope |
net6.0 | 555ns | 0.684ns | 2.65ns | 0.00975 | 0 | 0 | 696 B |
| #6060 | StartFinishScope |
netcoreapp3.1 | 680ns | 0.456ns | 1.64ns | 0.00923 | 0 | 0 | 696 B |
| #6060 | StartFinishScope |
net472 | 880ns | 0.542ns | 2.1ns | 0.104 | 0 | 0 | 658 B |
Benchmarks.Trace.TraceAnnotationsBenchmark - Same speed ✔️ Same allocations ✔️
Raw results
| Branch | Method | Toolchain | Mean | StdError | StdDev | Gen 0 | Gen 1 | Gen 2 | Allocated |
|---|---|---|---|---|---|---|---|---|---|
| master | RunOnMethodBegin |
net6.0 | 643ns | 0.362ns | 1.4ns | 0.00975 | 0 | 0 | 696 B |
| master | RunOnMethodBegin |
netcoreapp3.1 | 917ns | 0.414ns | 1.55ns | 0.00973 | 0 | 0 | 696 B |
| master | RunOnMethodBegin |
net472 | 1.07μs | 0.763ns | 2.96ns | 0.105 | 0 | 0 | 658 B |
| #6060 | RunOnMethodBegin |
net6.0 | 596ns | 0.365ns | 1.42ns | 0.0098 | 0 | 0 | 696 B |
| #6060 | RunOnMethodBegin |
netcoreapp3.1 | 954ns | 0.856ns | 3.32ns | 0.00957 | 0 | 0 | 696 B |
| #6060 | RunOnMethodBegin |
net472 | 1.06μs | 1.61ns | 6.25ns | 0.104 | 0 | 0 | 658 B |
ceae797 to
e896bcf
Compare
Snapshots difference summaryThe following differences have been observed in committed snapshots. It is meant to help the reviewer. 1 occurrences of : - "hash": -1837181716,
+ "hash": -636226626,
[...]
- "hash": 1990393425,
+ "hash": -60481650,
[...]
- "hash": 1170867602,
+ "hash": 990913114,
[...]
- "hash": -1837181716,
+ "hash": -636226626,
[...]
- "hash": 1990393425,
+ "hash": -60481650,
[...]
- "hash": 1170867602,
+ "hash": 990913114,
[...]
- "hash": -1837181716,
+ "hash": -636226626,
[...]
- "hash": 1990393425,
+ "hash": -60481650,
[...]
- "hash": 1170867602,
+ "hash": 990913114,
|
6fdfb66 to
99c81fb
Compare
Tests fix
Revert part of update package versions
Revert updatepackage versions
99c81fb to
e422bd0
Compare
bouwkast
left a comment
There was a problem hiding this comment.
So I didn't review much of this as most seems to fall underneath ASM but 👍
There was a problem hiding this comment.
@daniel-romano-DD
Could you add /tracer/src/Datadog.Trace/ClrProfiler/AutoInstrumentation/RestSharp/ @DataDog/asm-dotnet/
to the CODEOWNERS?
That way apm-idm-dotnet isn're required for this.
| MinimumVersion = "1.0.0", | ||
| MaximumVersion = "112.*.*", |
There was a problem hiding this comment.
Uh is this correct that we support v 1.0.0 up to 112 with this?
| MinimumVersion = "1.0.0", | ||
| MaximumVersion = "112.*.*", |
There was a problem hiding this comment.
Uh is this correct that we support v 1.0.0 up to 112 with this?
There was a problem hiding this comment.
True. first version is 104.0.0
| /// <param name="state">Calltarget state value</param> | ||
| /// <returns>CallTargetReturn</returns> | ||
| internal static CallTargetReturn<TReturn> OnMethodEnd<TTarget, TReturn>(TReturn returnValue, Exception exception, CallTargetState state) | ||
| { |
There was a problem hiding this comment.
NIT: Since the code of this method is the same as the one in UrlEncode2Integration.cs, it would probably make sense to create a common method that is called from both instrumentation points.
|
|
||
| public static object? PropagateResultWhenInputTainted(string? result, object? firstInput, object? secondInput = null, object? thirdInput = null, object? fourthInput = null) | ||
| [MethodImpl(MethodImplOptions.AggressiveInlining)] | ||
| private static bool TryPropagateWholeResult(string? result, object? input, out TaintedObjects? taintedObjects) |
There was a problem hiding this comment.
NIT: since this method does not propagate the result if it's different than the input, I would change the name of the method to avoid confusions.
| EndProject | ||
| Project("{9A19103F-16F7-4668-BE54-9A1E7A4F7556}") = "Samples.Debugger.AspNetCore5", "tracer\test\test-applications\debugger\Samples.Debugger.AspNetCore5\Samples.Debugger.AspNetCore5.csproj", "{3978A7D5-7B6E-4152-9C3A-5852F1F6E223}" | ||
| EndProject | ||
| Project("{2150E333-8FDC-42A3-9474-1A3956D46DE8}") = "Generated", "Generated", "{E1B0F72C-991A-409D-9266-DE5ED1BD940E}" |
There was a problem hiding this comment.
I guess that these changes are done automatically when compiling the solution?
Summary of changes
Improvements in the tainting of string.Replace and string.Format.
Improvements in escape functions.
Addition of SSRF secure mark.
Instrumentation of UrlEscape methods.
Reason for change
Inaccurate detection of SSRF in RestSharp queries have been reported.
Implementation details
Added a check to verify if the result string is the same as the original when tainting the whole string.
This happens in Replace and Format strings, when the function does not modify the input.
For instance
"text".Replace("1", "2")will return"text", but if"2"is tainted, the result would be also, and this was incorrect.Fixed the escape function to propagate the secure mark in the escaped function, and not in the origin, as was done until now.
Added a
CallTargetin theUrlEncodeto properly escape the result and propagate a secure mark for SSRF, for whenAddParameteris called with theencodeargument to true (by default).Test coverage
Added unit tests to check the new proper
Replaceand Format functionality, as well as theUrlEncodeand theRestSharpSSRF detectionOther details