Skip to content

[AAP] API10 downstream request analysis#8232

Merged
andrewlock merged 27 commits into
masterfrom
dani/asm/API10
Apr 13, 2026
Merged

[AAP] API10 downstream request analysis#8232
andrewlock merged 27 commits into
masterfrom
dani/asm/API10

Conversation

@dromanol

Copy link
Copy Markdown
Contributor

Summary of changes

Implement needed changes to handle API10 (downstream request) vulnerability in RASP

Reason for change

Implementation details

Test coverage

Other details

@dd-trace-dotnet-ci-bot

dd-trace-dotnet-ci-bot Bot commented Feb 21, 2026

Copy link
Copy Markdown

Execution-Time Benchmarks Report ⏱️

Execution-time results for samples comparing This PR (8232) and master.

✅ No regressions detected - check the details below

Full Metrics Comparison

FakeDbCommand

Metric Master (Mean ± 95% CI) Current (Mean ± 95% CI) Change Status
.NET Framework 4.8 - Baseline
duration71.39 ± (71.35 - 71.69) ms72.06 ± (71.99 - 72.35) ms+0.9%✅⬆️
.NET Framework 4.8 - Bailout
duration75.97 ± (75.92 - 76.25) ms76.01 ± (75.98 - 76.36) ms+0.1%✅⬆️
.NET Framework 4.8 - CallTarget+Inlining+NGEN
duration1062.42 ± (1063.05 - 1069.02) ms1065.71 ± (1068.72 - 1076.64) ms+0.3%✅⬆️
.NET Core 3.1 - Baseline
process.internal_duration_ms22.14 ± (22.10 - 22.18) ms22.21 ± (22.17 - 22.26) ms+0.3%✅⬆️
process.time_to_main_ms82.69 ± (82.50 - 82.87) ms82.76 ± (82.56 - 82.96) ms+0.1%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed10.92 ± (10.91 - 10.92) MB10.91 ± (10.91 - 10.92) MB-0.0%
runtime.dotnet.threads.count12 ± (12 - 12)12 ± (12 - 12)+0.0%
.NET Core 3.1 - Bailout
process.internal_duration_ms22.13 ± (22.10 - 22.17) ms22.13 ± (22.09 - 22.17) ms+0.0%✅⬆️
process.time_to_main_ms84.10 ± (83.88 - 84.31) ms84.13 ± (83.92 - 84.34) ms+0.0%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed10.96 ± (10.95 - 10.96) MB10.94 ± (10.94 - 10.95) MB-0.1%
runtime.dotnet.threads.count13 ± (13 - 13)13 ± (13 - 13)+0.0%
.NET Core 3.1 - CallTarget+Inlining+NGEN
process.internal_duration_ms225.34 ± (224.22 - 226.47) ms223.89 ± (222.92 - 224.87) ms-0.6%
process.time_to_main_ms518.49 ± (517.34 - 519.63) ms519.44 ± (518.46 - 520.42) ms+0.2%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed48.46 ± (48.43 - 48.49) MB48.50 ± (48.48 - 48.53) MB+0.1%✅⬆️
runtime.dotnet.threads.count28 ± (28 - 28)28 ± (28 - 28)+0.0%
.NET 6 - Baseline
process.internal_duration_ms20.99 ± (20.96 - 21.03) ms20.91 ± (20.87 - 20.94) ms-0.4%
process.time_to_main_ms72.20 ± (72.02 - 72.37) ms72.02 ± (71.86 - 72.18) ms-0.2%
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed10.63 ± (10.63 - 10.63) MB10.64 ± (10.64 - 10.64) MB+0.1%✅⬆️
runtime.dotnet.threads.count10 ± (10 - 10)10 ± (10 - 10)+0.0%
.NET 6 - Bailout
process.internal_duration_ms20.81 ± (20.79 - 20.84) ms20.85 ± (20.82 - 20.89) ms+0.2%✅⬆️
process.time_to_main_ms72.29 ± (72.12 - 72.45) ms72.82 ± (72.66 - 72.98) ms+0.7%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed10.72 ± (10.72 - 10.73) MB10.75 ± (10.74 - 10.75) MB+0.2%✅⬆️
runtime.dotnet.threads.count11 ± (11 - 11)11 ± (11 - 11)+0.0%
.NET 6 - CallTarget+Inlining+NGEN
process.internal_duration_ms384.26 ± (382.35 - 386.17) ms386.48 ± (384.53 - 388.42) ms+0.6%✅⬆️
process.time_to_main_ms519.43 ± (518.52 - 520.33) ms519.82 ± (518.90 - 520.74) ms+0.1%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed49.91 ± (49.88 - 49.94) MB49.95 ± (49.92 - 49.98) MB+0.1%✅⬆️
runtime.dotnet.threads.count28 ± (28 - 28)28 ± (28 - 28)+0.1%✅⬆️
.NET 8 - Baseline
process.internal_duration_ms19.17 ± (19.14 - 19.20) ms19.34 ± (19.30 - 19.37) ms+0.9%✅⬆️
process.time_to_main_ms71.18 ± (71.04 - 71.32) ms71.88 ± (71.73 - 72.02) ms+1.0%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed7.71 ± (7.70 - 7.71) MB7.68 ± (7.68 - 7.69) MB-0.3%
runtime.dotnet.threads.count10 ± (10 - 10)10 ± (10 - 10)+0.0%
.NET 8 - Bailout
process.internal_duration_ms19.01 ± (18.98 - 19.05) ms19.33 ± (19.28 - 19.38) ms+1.7%✅⬆️
process.time_to_main_ms71.92 ± (71.77 - 72.07) ms72.83 ± (72.68 - 72.99) ms+1.3%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed7.74 ± (7.74 - 7.75) MB7.73 ± (7.72 - 7.73) MB-0.2%
runtime.dotnet.threads.count11 ± (11 - 11)11 ± (11 - 11)+0.0%
.NET 8 - CallTarget+Inlining+NGEN
process.internal_duration_ms305.31 ± (303.20 - 307.41) ms303.90 ± (301.63 - 306.16) ms-0.5%
process.time_to_main_ms476.74 ± (475.90 - 477.57) ms479.49 ± (478.80 - 480.19) ms+0.6%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed37.08 ± (37.06 - 37.10) MB37.07 ± (37.05 - 37.09) MB-0.0%
runtime.dotnet.threads.count27 ± (27 - 27)27 ± (27 - 27)+0.0%✅⬆️

HttpMessageHandler

Metric Master (Mean ± 95% CI) Current (Mean ± 95% CI) Change Status
.NET Framework 4.8 - Baseline
duration190.88 ± (190.80 - 191.52) ms201.49 ± (201.09 - 201.88) ms+5.6%✅⬆️
.NET Framework 4.8 - Bailout
duration194.55 ± (194.52 - 194.87) ms205.08 ± (204.85 - 205.43) ms+5.4%✅⬆️
.NET Framework 4.8 - CallTarget+Inlining+NGEN
duration1136.55 ± (1137.88 - 1143.80) ms1180.51 ± (1182.53 - 1189.66) ms+3.9%✅⬆️
.NET Core 3.1 - Baseline
process.internal_duration_ms185.18 ± (184.88 - 185.48) ms195.23 ± (194.91 - 195.56) ms+5.4%✅⬆️
process.time_to_main_ms79.73 ± (79.57 - 79.88) ms84.49 ± (84.29 - 84.69) ms+6.0%✅⬆️
runtime.dotnet.exceptions.count3 ± (3 - 3)3 ± (3 - 3)+0.0%
runtime.dotnet.mem.committed16.13 ± (16.10 - 16.15) MB16.03 ± (16.00 - 16.06) MB-0.6%
runtime.dotnet.threads.count20 ± (19 - 20)20 ± (19 - 20)-0.0%
.NET Core 3.1 - Bailout
process.internal_duration_ms184.85 ± (184.65 - 185.04) ms194.92 ± (194.66 - 195.19) ms+5.5%✅⬆️
process.time_to_main_ms81.05 ± (80.95 - 81.15) ms85.73 ± (85.55 - 85.90) ms+5.8%✅⬆️
runtime.dotnet.exceptions.count3 ± (3 - 3)3 ± (3 - 3)+0.0%
runtime.dotnet.mem.committed16.15 ± (16.10 - 16.20) MB16.11 ± (16.09 - 16.14) MB-0.3%
runtime.dotnet.threads.count21 ± (20 - 21)21 ± (20 - 21)-0.1%
.NET Core 3.1 - CallTarget+Inlining+NGEN
process.internal_duration_ms391.78 ± (390.52 - 393.03) ms404.64 ± (403.19 - 406.09) ms+3.3%✅⬆️
process.time_to_main_ms505.19 ± (504.19 - 506.20) ms528.35 ± (527.01 - 529.69) ms+4.6%✅⬆️
runtime.dotnet.exceptions.count3 ± (3 - 3)3 ± (3 - 3)+0.0%
runtime.dotnet.mem.committed58.71 ± (58.50 - 58.91) MB59.30 ± (59.25 - 59.35) MB+1.0%✅⬆️
runtime.dotnet.threads.count30 ± (30 - 30)30 ± (29 - 30)-0.1%
.NET 6 - Baseline
process.internal_duration_ms190.44 ± (190.13 - 190.75) ms200.79 ± (200.46 - 201.12) ms+5.4%✅⬆️
process.time_to_main_ms69.75 ± (69.60 - 69.91) ms73.53 ± (73.31 - 73.74) ms+5.4%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed15.93 ± (15.76 - 16.11) MB16.38 ± (16.35 - 16.40) MB+2.8%✅⬆️
runtime.dotnet.threads.count18 ± (18 - 18)19 ± (19 - 19)+7.2%✅⬆️
.NET 6 - Bailout
process.internal_duration_ms189.27 ± (189.05 - 189.49) ms198.87 ± (198.60 - 199.14) ms+5.1%✅⬆️
process.time_to_main_ms70.60 ± (70.53 - 70.67) ms74.18 ± (74.06 - 74.31) ms+5.1%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed15.92 ± (15.75 - 16.09) MB16.43 ± (16.40 - 16.46) MB+3.2%✅⬆️
runtime.dotnet.threads.count19 ± (19 - 19)20 ± (20 - 20)+7.2%✅⬆️
.NET 6 - CallTarget+Inlining+NGEN
process.internal_duration_ms598.10 ± (595.54 - 600.66) ms601.06 ± (598.20 - 603.93) ms+0.5%✅⬆️
process.time_to_main_ms508.25 ± (507.47 - 509.02) ms529.83 ± (528.60 - 531.06) ms+4.2%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed61.49 ± (61.39 - 61.59) MB61.96 ± (61.87 - 62.04) MB+0.8%✅⬆️
runtime.dotnet.threads.count30 ± (30 - 30)31 ± (30 - 31)+0.8%✅⬆️
.NET 8 - Baseline
process.internal_duration_ms187.58 ± (187.30 - 187.86) ms198.23 ± (197.87 - 198.59) ms+5.7%✅⬆️
process.time_to_main_ms69.00 ± (68.86 - 69.13) ms72.98 ± (72.82 - 73.14) ms+5.8%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed11.77 ± (11.75 - 11.80) MB11.73 ± (11.71 - 11.75) MB-0.4%
runtime.dotnet.threads.count18 ± (18 - 18)18 ± (18 - 18)+0.8%✅⬆️
.NET 8 - Bailout
process.internal_duration_ms186.96 ± (186.71 - 187.20) ms197.71 ± (197.46 - 197.96) ms+5.8%✅⬆️
process.time_to_main_ms70.09 ± (70.01 - 70.17) ms74.03 ± (73.90 - 74.16) ms+5.6%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed11.60 ± (11.49 - 11.72) MB11.74 ± (11.72 - 11.76) MB+1.2%✅⬆️
runtime.dotnet.threads.count18 ± (18 - 19)19 ± (19 - 19)+5.6%✅⬆️
.NET 8 - CallTarget+Inlining+NGEN
process.internal_duration_ms516.44 ± (513.77 - 519.11) ms520.89 ± (517.82 - 523.96) ms+0.9%✅⬆️
process.time_to_main_ms468.89 ± (468.23 - 469.55) ms489.57 ± (488.71 - 490.43) ms+4.4%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed50.68 ± (50.65 - 50.71) MB50.71 ± (50.67 - 50.74) MB+0.1%✅⬆️
runtime.dotnet.threads.count30 ± (30 - 30)30 ± (30 - 30)-0.1%
Comparison explanation

Execution-time benchmarks measure the whole time it takes to execute a program, and are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are highlighted in **red**. The following thresholds were used for comparing the execution times:

  • Welch test with statistical test for significance of 5%
  • Only results indicating a difference greater than 5% and 5 ms are considered.

Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard.

Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph).

Duration charts
FakeDbCommand (.NET Framework 4.8)
gantt
    title Execution time (ms) FakeDbCommand (.NET Framework 4.8)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8232) - mean (72ms)  : 70, 75
    master - mean (72ms)  : 69, 74

    section Bailout
    This PR (8232) - mean (76ms)  : 73, 79
    master - mean (76ms)  : 75, 78

    section CallTarget+Inlining+NGEN
    This PR (8232) - mean (1,073ms)  : 1016, 1130
    master - mean (1,066ms)  : 1023, 1110

Loading
FakeDbCommand (.NET Core 3.1)
gantt
    title Execution time (ms) FakeDbCommand (.NET Core 3.1)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8232) - mean (112ms)  : 108, 115
    master - mean (111ms)  : 108, 115

    section Bailout
    This PR (8232) - mean (113ms)  : 110, 115
    master - mean (113ms)  : 110, 116

    section CallTarget+Inlining+NGEN
    This PR (8232) - mean (784ms)  : 762, 806
    master - mean (783ms)  : 763, 803

Loading
FakeDbCommand (.NET 6)
gantt
    title Execution time (ms) FakeDbCommand (.NET 6)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8232) - mean (99ms)  : 96, 102
    master - mean (99ms)  : 95, 103

    section Bailout
    This PR (8232) - mean (100ms)  : 97, 102
    master - mean (99ms)  : 97, 102

    section CallTarget+Inlining+NGEN
    This PR (8232) - mean (936ms)  : 906, 966
    master - mean (931ms)  : 903, 960

Loading
FakeDbCommand (.NET 8)
gantt
    title Execution time (ms) FakeDbCommand (.NET 8)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8232) - mean (99ms)  : 96, 102
    master - mean (98ms)  : 95, 101

    section Bailout
    This PR (8232) - mean (100ms)  : 97, 102
    master - mean (98ms)  : 96, 100

    section CallTarget+Inlining+NGEN
    This PR (8232) - mean (813ms)  : 780, 847
    master - mean (811ms)  : 778, 844

Loading
HttpMessageHandler (.NET Framework 4.8)
gantt
    title Execution time (ms) HttpMessageHandler (.NET Framework 4.8)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8232) - mean (201ms)  : 198, 205
    master - mean (191ms)  : 188, 195

    section Bailout
    This PR (8232) - mean (205ms)  : 202, 208
    master - mean (195ms)  : 193, 196

    section CallTarget+Inlining+NGEN
    This PR (8232) - mean (1,186ms)  : 1134, 1238
    master - mean (1,141ms)  : 1097, 1185

Loading
HttpMessageHandler (.NET Core 3.1)
gantt
    title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8232) - mean (289ms)  : 285, 294
    master - mean (273ms)  : 269, 277

    section Bailout
    This PR (8232) - mean (290ms)  : crit, 286, 293
    master - mean (274ms)  : 271, 277

    section CallTarget+Inlining+NGEN
    This PR (8232) - mean (962ms)  : 940, 984
    master - mean (925ms)  : 905, 944

Loading
HttpMessageHandler (.NET 6)
gantt
    title Execution time (ms) HttpMessageHandler (.NET 6)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8232) - mean (283ms)  : 278, 289
    master - mean (268ms)  : 265, 272

    section Bailout
    This PR (8232) - mean (282ms)  : 278, 285
    master - mean (268ms)  : 265, 270

    section CallTarget+Inlining+NGEN
    This PR (8232) - mean (1,162ms)  : 1129, 1194
    master - mean (1,136ms)  : 1093, 1179

Loading
HttpMessageHandler (.NET 8)
gantt
    title Execution time (ms) HttpMessageHandler (.NET 8)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8232) - mean (281ms)  : 276, 286
    master - mean (267ms)  : 262, 271

    section Bailout
    This PR (8232) - mean (282ms)  : crit, 277, 286
    master - mean (266ms)  : 263, 270

    section CallTarget+Inlining+NGEN
    This PR (8232) - mean (1,042ms)  : 991, 1093
    master - mean (1,018ms)  : 979, 1058

Loading

@dromanol dromanol changed the title [AAP] API10 initial implementation [AAP] API10 downstream request analysis Mar 6, 2026
Comment thread tracer/src/Datadog.Trace/Datadog.Trace.csproj Outdated
Comment thread tracer/test/Datadog.Trace.Security.IntegrationTests/RASP/AspNetCore5Rasp.cs Outdated
Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/HttpClient/IHttpContent.cs Outdated
Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/HttpClient/IHttpRequestMessage.cs Outdated
Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/HttpClient/IMediaTypeHeaderValue.cs Outdated
Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs Outdated
Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs Outdated
Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs Outdated
Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs Outdated
{
State state = new(MaxElements);
return ReadValue(jsonReader, ref state, 0);
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's very likely we're only going to load partial data given how we're loading the stream, which means we're very likely to throw, and this is very likely to always return null after doing a bunch of expensive work... not sure there's a good solution to that currently, other than you buffering the whole request

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Discussed offline - because we bail if we have a "full" buffer, then this shouldn't be the case

@github-actions

github-actions Bot commented Mar 9, 2026

Copy link
Copy Markdown
Contributor

Snapshots difference summary

The following differences have been observed in committed snapshots. It is meant to help the reviewer.
The diff is simplistic, so please check some files anyway while we improve it.

2 occurrences of :

-      _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-932-110","name":"OS command injection exploit","tags":{"category":"vulnerability_trigger","type":"command_injection"}},"rule_matches":[{"operator":"cmdi_detector","operator_value":"","parameters":[{"address":null,"highlight":["/bin/rebootCommand"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+      _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-932-110","name":"OS command injection exploit","tags":{"category":"vulnerability_trigger","type":"command_injection"}},"rule_matches":[{"operator":"cmdi_detector","operator_value":"","parameters":[{"address":null,"highlight":["/bin/rebootCommand"],"key_path":null,"value":null}]}],"security_response_id":"Guid_2","span_id": XXX}]},

2 occurrences of :

-      _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-932-100","name":"Shell command injection exploit","tags":{"category":"vulnerability_trigger","type":"command_injection"}},"rule_matches":[{"operator":"shi_detector","operator_value":"","parameters":[{"address":null,"highlight":[";evilCommand"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+      _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-932-100","name":"Shell command injection exploit","tags":{"category":"vulnerability_trigger","type":"command_injection"}},"rule_matches":[{"operator":"shi_detector","operator_value":"","parameters":[{"address":null,"highlight":[";evilCommand"],"key_path":null,"value":null}]}],"security_response_id":"Guid_2","span_id": XXX}]},

2 occurrences of :

-      _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-001-001","name":"Path traversal attack","tags":{"category":"vulnerability_trigger","type":"lfi"}},"rule_matches":[{"operator":"lfi_detector","operator_value":"","parameters":[{"address":null,"highlight":["/etc/password"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+      _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-001-001","name":"Path traversal attack","tags":{"category":"vulnerability_trigger","type":"lfi"}},"rule_matches":[{"operator":"lfi_detector","operator_value":"","parameters":[{"address":null,"highlight":["/etc/password"],"key_path":null,"value":null}]}],"security_response_id":"Guid_2","span_id": XXX}]},

2 occurrences of :

-      _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-002-001","name":"Server-side request forgery","tags":{"category":"vulnerability_trigger","type":"ssrf"}},"rule_matches":[{"operator":"ssrf_detector","operator_value":"","parameters":[{"address":null,"highlight":["127.0.0.1"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+      _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-002-001","name":"Server-side request forgery","tags":{"category":"vulnerability_trigger","type":"ssrf"}},"rule_matches":[{"operator":"ssrf_detector","operator_value":"","parameters":[{"address":null,"highlight":["127.0.0.1"],"key_path":null,"value":null}]}],"security_response_id":"Guid_2","span_id": XXX}]},

2 occurrences of :

-      _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-942-100","name":"SQL injection exploit","tags":{"category":"vulnerability_trigger","type":"sql_injection"}},"rule_matches":[{"operator":"sqli_detector","operator_value":"","parameters":[{"address":null,"highlight":["' or '1'='1"],"key_path":null,"value":null}]}],"span_id": XXX}]},
+      _dd.appsec.json: {"triggers":[{"rule":{"id":"rasp-942-100","name":"SQL injection exploit","tags":{"category":"vulnerability_trigger","type":"sql_injection"}},"rule_matches":[{"operator":"sqli_detector","operator_value":"","parameters":[{"address":null,"highlight":["' or '1'='1"],"key_path":null,"value":null}]}],"security_response_id":"Guid_2","span_id": XXX}]},

5 occurrences of :

-    },
-    MetaStruct: {
-      appsec: ,
-      iast: ,
-      _dd.stack: 

1 occurrences of :

-    },
-    MetaStruct: {
-      iast: ,
-      _dd.stack: 

@pr-commenter

pr-commenter Bot commented Mar 10, 2026

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-04-13 17:30:49

Comparing candidate commit 5ddcd72 in PR branch dani/asm/API10 with baseline commit 58f22e8 in branch master.

Found 27 performance improvements and 44 performance regressions! Performance is the same for 209 metrics, 8 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

scenario:Benchmarks.Trace.ActivityBenchmark.StartStopWithChild net6.0

  • 🟩 throughput [+8318.858op/s; +10600.597op/s] or [+6.992%; +8.910%]

scenario:Benchmarks.Trace.AgentWriterBenchmark.WriteAndFlushEnrichedTraces net472

  • 🟥 execution_time [+314.775ms; +316.917ms] or [+156.202%; +157.265%]

scenario:Benchmarks.Trace.AgentWriterBenchmark.WriteAndFlushEnrichedTraces net6.0

  • 🟥 execution_time [+379.903ms; +382.966ms] or [+300.147%; +302.567%]

scenario:Benchmarks.Trace.AgentWriterBenchmark.WriteAndFlushEnrichedTraces netcoreapp3.1

  • 🟥 execution_time [+397.503ms; +400.185ms] or [+351.775%; +354.149%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.AllCycleMoreComplexBody net472

  • 🟥 allocated_mem [+1.308KB; +1.308KB] or [+27.529%; +27.541%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.AllCycleMoreComplexBody net6.0

  • 🟥 allocated_mem [+471 bytes; +472 bytes] or [+9.977%; +9.987%]
  • 🟩 execution_time [-16.271ms; -12.103ms] or [-7.599%; -5.653%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.AllCycleMoreComplexBody netcoreapp3.1

  • 🟥 allocated_mem [+1.272KB; +1.272KB] or [+27.502%; +27.510%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.AllCycleSimpleBody net472

  • 🟥 allocated_mem [+1.307KB; +1.307KB] or [+105.746%; +105.759%]
  • 🟥 throughput [-229780.777op/s; -226881.168op/s] or [-23.462%; -23.166%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.AllCycleSimpleBody net6.0

  • 🟥 allocated_mem [+471 bytes; +472 bytes] or [+38.558%; +38.566%]
  • 🟩 execution_time [-26.401ms; -21.548ms] or [-11.774%; -9.609%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.AllCycleSimpleBody netcoreapp3.1

  • 🟥 allocated_mem [+1.272KB; +1.272KB] or [+105.292%; +105.304%]
  • 🟥 throughput [-133040.437op/s; -117112.764op/s] or [-19.115%; -16.827%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.ObjectExtractorMoreComplexBody net6.0

  • 🟩 throughput [+10312.205op/s; +13227.547op/s] or [+6.561%; +8.416%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.ObjectExtractorMoreComplexBody netcoreapp3.1

  • 🟩 throughput [+7166.936op/s; +9825.161op/s] or [+5.709%; +7.827%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.ObjectExtractorSimpleBody net6.0

  • 🟩 throughput [+364032.979op/s; +391103.404op/s] or [+12.138%; +13.041%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.ObjectExtractorSimpleBody netcoreapp3.1

  • 🟩 execution_time [-19.409ms; -15.039ms] or [-8.947%; -6.932%]
  • 🟩 throughput [+230161.847op/s; +285271.289op/s] or [+9.136%; +11.323%]

scenario:Benchmarks.Trace.Asm.AppSecEncoderBenchmark.EncodeArgs net472

  • 🟥 execution_time [+298.942ms; +299.641ms] or [+149.371%; +149.720%]

scenario:Benchmarks.Trace.Asm.AppSecEncoderBenchmark.EncodeArgs net6.0

  • 🟥 execution_time [+298.909ms; +302.151ms] or [+150.740%; +152.376%]

scenario:Benchmarks.Trace.Asm.AppSecEncoderBenchmark.EncodeArgs netcoreapp3.1

  • 🟥 execution_time [+299.997ms; +302.730ms] or [+151.115%; +152.492%]

scenario:Benchmarks.Trace.Asm.AppSecEncoderBenchmark.EncodeLegacyArgs net472

  • 🟥 execution_time [+297.430ms; +298.176ms] or [+146.086%; +146.452%]

scenario:Benchmarks.Trace.Asm.AppSecEncoderBenchmark.EncodeLegacyArgs net6.0

  • 🟥 execution_time [+294.546ms; +296.798ms] or [+143.993%; +145.094%]

scenario:Benchmarks.Trace.Asm.AppSecEncoderBenchmark.EncodeLegacyArgs netcoreapp3.1

  • 🟥 execution_time [+300.170ms; +302.081ms] or [+150.025%; +150.980%]

scenario:Benchmarks.Trace.Asm.AppSecWafBenchmark.RunWafRealisticBenchmarkWithAttack net6.0

  • 🟥 execution_time [+23.046µs; +48.501µs] or [+7.357%; +15.484%]
  • 🟥 throughput [-435.414op/s; -229.196op/s] or [-13.573%; -7.145%]

scenario:Benchmarks.Trace.AspNetCoreBenchmark.SendRequest net472

  • 🟥 execution_time [+299.739ms; +300.406ms] or [+149.601%; +149.933%]

scenario:Benchmarks.Trace.AspNetCoreBenchmark.SendRequest net6.0

  • 🟩 throughput [+926.182op/s; +1075.725op/s] or [+7.611%; +8.839%]

scenario:Benchmarks.Trace.AspNetCoreBenchmark.SendRequest netcoreapp3.1

  • 🟩 throughput [+676.449op/s; +874.260op/s] or [+6.548%; +8.463%]

scenario:Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark.WriteAndFlushEnrichedTraces net472

  • 🟥 throughput [-505.144op/s; -443.151op/s] or [-45.771%; -40.154%]

scenario:Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark.WriteAndFlushEnrichedTraces net6.0

  • 🟥 throughput [-742.304op/s; -658.886op/s] or [-49.512%; -43.948%]

scenario:Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark.WriteAndFlushEnrichedTraces netcoreapp3.1

  • 🟥 execution_time [+351.549ms; +360.015ms] or [+210.267%; +215.331%]
  • 🟥 throughput [-443.275op/s; -407.837op/s] or [-30.865%; -28.397%]

scenario:Benchmarks.Trace.CharSliceBenchmark.OriginalCharSlice net6.0

  • 🟩 execution_time [-153.823µs; -118.392µs] or [-7.792%; -5.997%]
  • 🟩 throughput [+33.892op/s; +43.499op/s] or [+6.690%; +8.587%]

scenario:Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearch net472

  • 🟥 execution_time [+303.778ms; +305.170ms] or [+152.977%; +153.678%]

scenario:Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearch net6.0

  • 🟥 execution_time [+303.073ms; +310.316ms] or [+151.871%; +155.500%]

scenario:Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearch netcoreapp3.1

  • 🟥 execution_time [+301.766ms; +304.909ms] or [+151.595%; +153.173%]

scenario:Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearchAsync net472

  • 🟥 execution_time [+303.080ms; +304.491ms] or [+152.196%; +152.905%]

scenario:Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearchAsync net6.0

  • 🟥 execution_time [+298.255ms; +299.792ms] or [+147.474%; +148.234%]

scenario:Benchmarks.Trace.ElasticsearchBenchmark.CallElasticsearchAsync netcoreapp3.1

  • 🟥 execution_time [+300.930ms; +308.280ms] or [+152.524%; +156.250%]

scenario:Benchmarks.Trace.GraphQLBenchmark.ExecuteAsync net472

  • 🟥 execution_time [+301.207ms; +302.751ms] or [+151.179%; +151.954%]

scenario:Benchmarks.Trace.GraphQLBenchmark.ExecuteAsync net6.0

  • 🟥 execution_time [+299.900ms; +302.217ms] or [+149.472%; +150.627%]
  • 🟩 throughput [+54407.136op/s; +59386.579op/s] or [+10.803%; +11.792%]

scenario:Benchmarks.Trace.GraphQLBenchmark.ExecuteAsync netcoreapp3.1

  • 🟥 execution_time [+300.542ms; +303.047ms] or [+149.517%; +150.763%]

scenario:Benchmarks.Trace.ILoggerBenchmark.EnrichedLog net472

  • 🟥 throughput [-13741.383op/s; -12661.683op/s] or [-5.526%; -5.092%]

scenario:Benchmarks.Trace.ILoggerBenchmark.EnrichedLog net6.0

  • 🟩 execution_time [-16.355ms; -12.713ms] or [-7.605%; -5.912%]
  • 🟩 throughput [+18866.089op/s; +25580.394op/s] or [+5.175%; +7.017%]

scenario:Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark net6.0

  • 🟩 allocated_mem [-25.542KB; -25.521KB] or [-9.317%; -9.309%]

scenario:Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatAspectBenchmark netcoreapp3.1

  • 🟩 allocated_mem [-15.381KB; -15.365KB] or [-5.607%; -5.601%]

scenario:Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatBenchmark net6.0

  • 🟥 execution_time [+5.780µs; +9.831µs] or [+13.661%; +23.238%]
  • 🟥 throughput [-4489.686op/s; -2729.083op/s] or [-18.900%; -11.489%]

scenario:Benchmarks.Trace.Iast.StringAspectsBenchmark.StringConcatBenchmark netcoreapp3.1

  • 🟩 throughput [+2073.075op/s; +3493.142op/s] or [+12.719%; +21.432%]

scenario:Benchmarks.Trace.Log4netBenchmark.EnrichedLog net472

  • 🟥 execution_time [+301.771ms; +303.027ms] or [+152.532%; +153.167%]

scenario:Benchmarks.Trace.Log4netBenchmark.EnrichedLog net6.0

  • 🟥 execution_time [+302.233ms; +304.483ms] or [+153.836%; +154.981%]

scenario:Benchmarks.Trace.Log4netBenchmark.EnrichedLog netcoreapp3.1

  • 🟥 execution_time [+298.916ms; +300.888ms] or [+149.644%; +150.632%]

scenario:Benchmarks.Trace.RedisBenchmark.SendReceive net6.0

  • 🟩 throughput [+47749.939op/s; +51455.134op/s] or [+9.038%; +9.739%]

scenario:Benchmarks.Trace.SerilogBenchmark.EnrichedLog net472

  • 🟥 execution_time [+298.706ms; +300.590ms] or [+148.878%; +149.817%]

scenario:Benchmarks.Trace.SerilogBenchmark.EnrichedLog net6.0

  • 🟥 execution_time [+302.084ms; +303.367ms] or [+151.692%; +152.337%]

scenario:Benchmarks.Trace.SerilogBenchmark.EnrichedLog netcoreapp3.1

  • 🟥 execution_time [+305.046ms; +307.147ms] or [+154.700%; +155.765%]

scenario:Benchmarks.Trace.SingleSpanAspNetCoreBenchmark.SingleSpanAspNetCore net472

  • 🟥 execution_time [+299.030ms; +299.595ms] or [+149.158%; +149.440%]
  • 🟩 throughput [+61330624.447op/s; +61559066.361op/s] or [+44.665%; +44.831%]

scenario:Benchmarks.Trace.SingleSpanAspNetCoreBenchmark.SingleSpanAspNetCore net6.0

  • 🟩 throughput [+1000.346op/s; +1187.780op/s] or [+7.733%; +9.182%]

scenario:Benchmarks.Trace.SingleSpanAspNetCoreBenchmark.SingleSpanAspNetCore netcoreapp3.1

  • 🟥 execution_time [+299.400ms; +300.309ms] or [+149.334%; +149.787%]

scenario:Benchmarks.Trace.SpanBenchmark.StartFinishScope net6.0

  • 🟩 throughput [+102614.447op/s; +110161.308op/s] or [+9.581%; +10.285%]

scenario:Benchmarks.Trace.SpanBenchmark.StartFinishScope netcoreapp3.1

  • 🟩 throughput [+46851.254op/s; +66433.010op/s] or [+5.423%; +7.689%]

scenario:Benchmarks.Trace.SpanBenchmark.StartFinishSpan net6.0

  • 🟩 throughput [+84932.855op/s; +115268.480op/s] or [+6.574%; +8.922%]

scenario:Benchmarks.Trace.SpanBenchmark.StartFinishSpan netcoreapp3.1

  • 🟩 throughput [+77760.858op/s; +86795.773op/s] or [+7.723%; +8.620%]

scenario:Benchmarks.Trace.SpanBenchmark.StartFinishTwoScopes net6.0

  • 🟩 throughput [+58363.712op/s; +63127.705op/s] or [+10.598%; +11.463%]

scenario:Benchmarks.Trace.TraceAnnotationsBenchmark.RunOnMethodBegin net6.0

  • 🟩 throughput [+82342.047op/s; +99875.121op/s] or [+9.200%; +11.159%]

Comment thread tracer/src/Datadog.Trace/AppSec/AppSecRequestContext.cs
Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs Outdated
var contentType = content.Headers?.ContentType?.MediaType;
if (contentType is "application/json")
{
await content.LoadIntoBufferAsync().ConfigureAwait(false);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looking at the framework code, this scares me. By default, it looks like LoadIntoBufferAsync() loads int.MaxValue bytes when you don't provide a max buffer size. Would need to check properly, but if so, that's a hell of an allocation. We should probably pass in the bodySizeLimit here at the very least (which is still huge, but still).

Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs Outdated
@dromanol
dromanol marked this pull request as ready for review March 11, 2026 12:44
@dromanol
dromanol requested review from a team as code owners March 11, 2026 12:44
@dromanol
dromanol marked this pull request as draft March 11, 2026 12:48

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bb5b8093c3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tracer/src/Datadog.Trace/AppSec/Security.cs Outdated
Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs Outdated
@dromanol
dromanol marked this pull request as ready for review March 12, 2026 09:38

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7bb14d101f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs
Comment thread tracer/src/Datadog.Trace/AppSec/AppSecRequestContext.cs

internal bool RaspEnabled => _settings.RaspEnabled && AppsecEnabled;

internal long ApiSecurityMaxDownstreamRequestBodyAnalysis => _settings.ApiSecurityMaxDownstreamRequestBodyAnalysis;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not sure to understand why is it declared as a long but _settings.ApiSecurityMaxDownstreamRequestBodyAnalysis is an int.

_waf = waf;
_configurationState = configurationState ?? new ConfigurationState(_settings, telemetry, _waf is null);
LifetimeManager.Instance.AddShutdownTask(RunShutdown);
_downstreamSampler = downstreamSampler ?? new DownstreamSampler(_settings.ApiSecurityMaxDownstreamRequestBodyAnalysis);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DownstreamSampler is taking a double and clamps the value for the sample rate. Is it expected that _settings.ApiSecurityMaxDownstreamRequestBodyAnalysis (an int) is passed as argument here?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well seen. It's ApiSecurityDownstreamBodyAnalysisSampleRate

Comment on lines +31 to +38
if (rate < 0.5)
{
return (long)(rate * max) + long.MinValue;
}
else if (rate < 1.0)
{
return (long)((rate * max) + long.MinValue);
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AFAICT, both of these branches are the same? 🤔

Also, are we considering overflow correctly here? 🤔 Should this be checked or unchecked?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same thing. Fixing it

@andrewlock andrewlock left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Getting close! 😄

Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs
}

var rootSpan = Tracer.Instance.InternalActiveScope?.Root?.Span;
rootSpan??= Tracer.Instance.InternalActiveScope?.Root?.Span;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I guess we can/should fix it in a follow up PR?

var value = enumerator.Current.Value;
if (!headersDic.TryAdd(currentKey, value))
{
Log.Warning("Header {Key} couldn't be added as argument to the waf", currentKey);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should probably remove it before merging

{
try
{
_processDownstreamRequest = false;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My point is, you're always running this method, even if we're not in a callsite scenario, right? Because in those cases _processDownstreamRequest==false

Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs Outdated
public void Parse_PrimitiveNull_ReturnsNull()
{
var json = @"null";
var result = BodyParser.Parse(json);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AFACIT these tests all test the "string json" path, whereas AFAICT we only use the stream version. Maybe we should just delete the string API entirely, and always call the stream version here?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed. Removed the overload and migrated tests to use the Stream version

Comment on lines +17 to +18
[Fact]
public void Parse_NullString_ReturnsNull()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think you should have some tests for invalid cases, e.g. invalid JSON of various forms

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added some

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're still not parsing any invalid JSON though right? 🤔 I think you could do something as simple as

Suggested change
[Fact]
public void Parse_NullString_ReturnsNull()
[Theory]
[InlineData("""{"name":"test","age":30""")]
[InlineData("""{"name":"test","age":""")]
[InlineData("""{"name":"test","age" """)]
[InlineData("""{"name":"test",""")]
public void Parse_TruncatedString_ReturnsNull(string json)
{
BodyParser.Parse(json).Should.BeNull();
ParseBody(json).Should().BeNull();
}
[Fact]
public void Parse_NullString_ReturnsNull()

var wafArgs = new Dictionary<string, object>();

// Use reflection to call the private AddBody method
var method = typeof(RaspModule).GetMethod("AddBody", System.Reflection.BindingFlags.NonPublic | System.Reflection.BindingFlags.Static);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just make the method public and mark it with [TestingOnly] - this reflection is horribly fragile 😅

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, did not know that trick

}

[Fact]
public void AddBody_InvalidJson_DoesNotAddBody()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think there are a couple of key cases missing here, namely proper "streaming" responses, e.g. chunked encoding. I think we really should add those test cases to be confident it's always behaving as expected (where the content length can't be detected up front)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added some chunked HttpContent tests


if (body is not null)
{
request.Content = new StringContent(body, Encoding.UTF8, contentType ?? "application/json");

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Using StringContent is unfortunately not a good test for real life - it knows the content size up front, which will not be the case for many responses.

@dromanol
dromanol force-pushed the dani/asm/API10 branch 2 times, most recently from 823f2f0 to 7cbf4b4 Compare March 17, 2026 15:24
Comment on lines +17 to +18
[Fact]
public void Parse_NullString_ReturnsNull()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're still not parsing any invalid JSON though right? 🤔 I think you could do something as simple as

Suggested change
[Fact]
public void Parse_NullString_ReturnsNull()
[Theory]
[InlineData("""{"name":"test","age":30""")]
[InlineData("""{"name":"test","age":""")]
[InlineData("""{"name":"test","age" """)]
[InlineData("""{"name":"test",""")]
public void Parse_TruncatedString_ReturnsNull(string json)
{
BodyParser.Parse(json).Should.BeNull();
ParseBody(json).Should().BeNull();
}
[Fact]
public void Parse_NullString_ReturnsNull()

Comment thread tracer/src/Datadog.Trace/AppSec/SecuritySettings.cs Outdated
Comment thread tracer/test/Datadog.Trace.Security.Unit.Tests/RASP/RaspModuleDownstreamTests.cs Outdated

@andrewlock andrewlock left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM once tests pass

Comment thread tracer/test/Datadog.Trace.Security.Unit.Tests/RASP/RaspModuleDownstreamTests.cs Outdated
Comment thread tracer/src/Datadog.Trace/AppSec/Rasp/RaspModule.cs
Comment thread tracer/test/Datadog.Trace.Security.Unit.Tests/RASP/RaspModuleDownstreamTests.cs Outdated
@andrewlock
andrewlock enabled auto-merge (squash) April 13, 2026 16:26
@andrewlock
andrewlock merged commit 7f212c3 into master Apr 13, 2026
141 checks passed
@andrewlock
andrewlock deleted the dani/asm/API10 branch April 13, 2026 17:31
@github-actions github-actions Bot added this to the vNext-v3 milestone Apr 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants