Add IpAddressObfuscationUtil for use with client-side-stats#8418
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f00d1b65a5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
BenchmarksBenchmark execution time: 2026-04-14 11:13:59 Comparing candidate commit f0895ac in PR branch Found 0 performance improvements and 1 performance regressions! Performance is the same for 26 metrics, 0 unstable metrics, 87 known flaky benchmarks.
|
Execution-Time Benchmarks Report ⏱️Execution-time results for samples comparing This PR (8418) and master.
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Metric | Master (Mean ± 95% CI) | Current (Mean ± 95% CI) | Change | Status |
|---|---|---|---|---|
| .NET Framework 4.8 - Baseline | ||||
| duration | 190.29 ± (190.30 - 190.99) ms | 208.17 ± (207.73 - 208.78) ms | +9.4% | ❌⬆️ |
| .NET Framework 4.8 - Bailout | ||||
| duration | 193.46 ± (193.52 - 193.92) ms | 211.17 ± (211.03 - 211.54) ms | +9.2% | ❌⬆️ |
| .NET Framework 4.8 - CallTarget+Inlining+NGEN | ||||
| duration | 1139.43 ± (1138.81 - 1144.75) ms | 1207.36 ± (1207.21 - 1214.94) ms | +6.0% | ❌⬆️ |
Full Metrics Comparison
FakeDbCommand
| Metric | Master (Mean ± 95% CI) | Current (Mean ± 95% CI) | Change | Status |
|---|---|---|---|---|
| .NET Framework 4.8 - Baseline | ||||
| duration | 72.00 ± (71.93 - 72.25) ms | 71.82 ± (71.84 - 72.12) ms | -0.2% | ✅ |
| .NET Framework 4.8 - Bailout | ||||
| duration | 75.72 ± (75.64 - 76.02) ms | 75.52 ± (75.36 - 75.72) ms | -0.3% | ✅ |
| .NET Framework 4.8 - CallTarget+Inlining+NGEN | ||||
| duration | 1069.15 ± (1071.14 - 1080.01) ms | 1070.62 ± (1070.06 - 1076.80) ms | +0.1% | ✅⬆️ |
| .NET Core 3.1 - Baseline | ||||
| process.internal_duration_ms | 22.29 ± (22.26 - 22.32) ms | 22.14 ± (22.11 - 22.17) ms | -0.7% | ✅ |
| process.time_to_main_ms | 83.82 ± (83.62 - 84.01) ms | 82.75 ± (82.57 - 82.94) ms | -1.3% | ✅ |
| runtime.dotnet.exceptions.count | 0 ± (0 - 0) | 0 ± (0 - 0) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 10.92 ± (10.92 - 10.93) MB | 10.92 ± (10.91 - 10.92) MB | -0.1% | ✅ |
| runtime.dotnet.threads.count | 12 ± (12 - 12) | 12 ± (12 - 12) | +0.0% | ✅ |
| .NET Core 3.1 - Bailout | ||||
| process.internal_duration_ms | 22.31 ± (22.27 - 22.34) ms | 22.01 ± (21.98 - 22.04) ms | -1.3% | ✅ |
| process.time_to_main_ms | 85.12 ± (84.96 - 85.29) ms | 83.96 ± (83.77 - 84.16) ms | -1.4% | ✅ |
| runtime.dotnet.exceptions.count | 0 ± (0 - 0) | 0 ± (0 - 0) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 10.96 ± (10.96 - 10.97) MB | 10.94 ± (10.93 - 10.94) MB | -0.2% | ✅ |
| runtime.dotnet.threads.count | 13 ± (13 - 13) | 13 ± (13 - 13) | +0.0% | ✅ |
| .NET Core 3.1 - CallTarget+Inlining+NGEN | ||||
| process.internal_duration_ms | 227.08 ± (225.83 - 228.34) ms | 225.67 ± (224.47 - 226.88) ms | -0.6% | ✅ |
| process.time_to_main_ms | 518.37 ± (517.13 - 519.61) ms | 520.18 ± (518.83 - 521.54) ms | +0.3% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 0 ± (0 - 0) | 0 ± (0 - 0) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 48.42 ± (48.39 - 48.45) MB | 48.44 ± (48.41 - 48.47) MB | +0.0% | ✅⬆️ |
| runtime.dotnet.threads.count | 28 ± (28 - 28) | 28 ± (28 - 28) | +0.0% | ✅ |
| .NET 6 - Baseline | ||||
| process.internal_duration_ms | 21.04 ± (21.00 - 21.08) ms | 20.97 ± (20.94 - 21.01) ms | -0.3% | ✅ |
| process.time_to_main_ms | 72.40 ± (72.24 - 72.56) ms | 72.10 ± (71.94 - 72.26) ms | -0.4% | ✅ |
| runtime.dotnet.exceptions.count | 0 ± (0 - 0) | 0 ± (0 - 0) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 10.63 ± (10.63 - 10.63) MB | 10.62 ± (10.61 - 10.62) MB | -0.1% | ✅ |
| runtime.dotnet.threads.count | 10 ± (10 - 10) | 10 ± (10 - 10) | +0.0% | ✅ |
| .NET 6 - Bailout | ||||
| process.internal_duration_ms | 21.00 ± (20.97 - 21.04) ms | 20.91 ± (20.88 - 20.94) ms | -0.4% | ✅ |
| process.time_to_main_ms | 73.79 ± (73.63 - 73.95) ms | 73.23 ± (73.10 - 73.37) ms | -0.8% | ✅ |
| runtime.dotnet.exceptions.count | 0 ± (0 - 0) | 0 ± (0 - 0) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 10.68 ± (10.68 - 10.69) MB | 10.75 ± (10.74 - 10.75) MB | +0.6% | ✅⬆️ |
| runtime.dotnet.threads.count | 11 ± (11 - 11) | 11 ± (11 - 11) | +0.0% | ✅ |
| .NET 6 - CallTarget+Inlining+NGEN | ||||
| process.internal_duration_ms | 385.43 ± (383.54 - 387.32) ms | 385.58 ± (383.34 - 387.82) ms | +0.0% | ✅⬆️ |
| process.time_to_main_ms | 517.75 ± (516.81 - 518.69) ms | 521.79 ± (520.70 - 522.89) ms | +0.8% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 0 ± (0 - 0) | 0 ± (0 - 0) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 50.08 ± (50.05 - 50.11) MB | 50.08 ± (50.05 - 50.11) MB | -0.0% | ✅ |
| runtime.dotnet.threads.count | 28 ± (28 - 28) | 28 ± (28 - 28) | +0.1% | ✅⬆️ |
| .NET 8 - Baseline | ||||
| process.internal_duration_ms | 19.18 ± (19.14 - 19.21) ms | 19.22 ± (19.19 - 19.25) ms | +0.2% | ✅⬆️ |
| process.time_to_main_ms | 71.25 ± (71.08 - 71.42) ms | 71.34 ± (71.19 - 71.48) ms | +0.1% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 0 ± (0 - 0) | 0 ± (0 - 0) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 7.69 ± (7.68 - 7.70) MB | 7.68 ± (7.68 - 7.69) MB | -0.1% | ✅ |
| runtime.dotnet.threads.count | 10 ± (10 - 10) | 10 ± (10 - 10) | +0.0% | ✅ |
| .NET 8 - Bailout | ||||
| process.internal_duration_ms | 19.17 ± (19.13 - 19.20) ms | 19.19 ± (19.16 - 19.22) ms | +0.1% | ✅⬆️ |
| process.time_to_main_ms | 72.34 ± (72.21 - 72.48) ms | 72.26 ± (72.16 - 72.36) ms | -0.1% | ✅ |
| runtime.dotnet.exceptions.count | 0 ± (0 - 0) | 0 ± (0 - 0) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 7.73 ± (7.72 - 7.74) MB | 7.74 ± (7.73 - 7.74) MB | +0.1% | ✅⬆️ |
| runtime.dotnet.threads.count | 11 ± (11 - 11) | 11 ± (11 - 11) | +0.0% | ✅ |
| .NET 8 - CallTarget+Inlining+NGEN | ||||
| process.internal_duration_ms | 306.20 ± (303.93 - 308.48) ms | 303.61 ± (301.22 - 306.01) ms | -0.8% | ✅ |
| process.time_to_main_ms | 478.84 ± (477.97 - 479.70) ms | 481.49 ± (480.78 - 482.21) ms | +0.6% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 0 ± (0 - 0) | 0 ± (0 - 0) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 37.11 ± (37.09 - 37.14) MB | 37.09 ± (37.07 - 37.12) MB | -0.1% | ✅ |
| runtime.dotnet.threads.count | 27 ± (27 - 27) | 27 ± (27 - 27) | -0.4% | ✅ |
HttpMessageHandler
| Metric | Master (Mean ± 95% CI) | Current (Mean ± 95% CI) | Change | Status |
|---|---|---|---|---|
| .NET Framework 4.8 - Baseline | ||||
| duration | 190.29 ± (190.30 - 190.99) ms | 208.17 ± (207.73 - 208.78) ms | +9.4% | ❌⬆️ |
| .NET Framework 4.8 - Bailout | ||||
| duration | 193.46 ± (193.52 - 193.92) ms | 211.17 ± (211.03 - 211.54) ms | +9.2% | ❌⬆️ |
| .NET Framework 4.8 - CallTarget+Inlining+NGEN | ||||
| duration | 1139.43 ± (1138.81 - 1144.75) ms | 1207.36 ± (1207.21 - 1214.94) ms | +6.0% | ❌⬆️ |
| .NET Core 3.1 - Baseline | ||||
| process.internal_duration_ms | 185.20 ± (184.92 - 185.49) ms | 199.05 ± (198.74 - 199.37) ms | +7.5% | ✅⬆️ |
| process.time_to_main_ms | 79.54 ± (79.37 - 79.70) ms | 85.86 ± (85.63 - 86.09) ms | +7.9% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 3 ± (3 - 3) | 3 ± (3 - 3) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 16.18 ± (16.16 - 16.21) MB | 16.00 ± (15.97 - 16.03) MB | -1.1% | ✅ |
| runtime.dotnet.threads.count | 20 ± (20 - 20) | 20 ± (19 - 20) | -0.1% | ✅ |
| .NET Core 3.1 - Bailout | ||||
| process.internal_duration_ms | 184.57 ± (184.34 - 184.81) ms | 198.88 ± (198.61 - 199.16) ms | +7.8% | ✅⬆️ |
| process.time_to_main_ms | 80.97 ± (80.86 - 81.09) ms | 87.21 ± (86.97 - 87.45) ms | +7.7% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 3 ± (3 - 3) | 3 ± (3 - 3) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 16.16 ± (16.07 - 16.26) MB | 16.08 ± (16.06 - 16.10) MB | -0.5% | ✅ |
| runtime.dotnet.threads.count | 21 ± (20 - 21) | 21 ± (20 - 21) | +0.1% | ✅⬆️ |
| .NET Core 3.1 - CallTarget+Inlining+NGEN | ||||
| process.internal_duration_ms | 392.10 ± (390.63 - 393.58) ms | 408.47 ± (407.01 - 409.93) ms | +4.2% | ✅⬆️ |
| process.time_to_main_ms | 504.22 ± (503.13 - 505.31) ms | 538.20 ± (536.55 - 539.84) ms | +6.7% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 3 ± (3 - 3) | 3 ± (3 - 3) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 58.64 ± (58.42 - 58.86) MB | 59.24 ± (59.19 - 59.30) MB | +1.0% | ✅⬆️ |
| runtime.dotnet.threads.count | 30 ± (30 - 30) | 30 ± (30 - 30) | +0.3% | ✅⬆️ |
| .NET 6 - Baseline | ||||
| process.internal_duration_ms | 189.67 ± (189.36 - 189.98) ms | 203.73 ± (203.27 - 204.20) ms | +7.4% | ✅⬆️ |
| process.time_to_main_ms | 69.29 ± (69.14 - 69.45) ms | 74.51 ± (74.25 - 74.77) ms | +7.5% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 4 ± (4 - 4) | 4 ± (4 - 4) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 15.86 ± (15.68 - 16.03) MB | 16.33 ± (16.30 - 16.35) MB | +3.0% | ✅⬆️ |
| runtime.dotnet.threads.count | 18 ± (18 - 18) | 19 ± (19 - 19) | +7.9% | ✅⬆️ |
| .NET 6 - Bailout | ||||
| process.internal_duration_ms | 188.26 ± (188.11 - 188.41) ms | 203.70 ± (203.39 - 204.01) ms | +8.2% | ✅⬆️ |
| process.time_to_main_ms | 70.24 ± (70.19 - 70.30) ms | 75.89 ± (75.70 - 76.08) ms | +8.0% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 4 ± (4 - 4) | 4 ± (4 - 4) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 16.00 ± (15.83 - 16.17) MB | 16.33 ± (16.30 - 16.36) MB | +2.1% | ✅⬆️ |
| runtime.dotnet.threads.count | 19 ± (18 - 19) | 20 ± (20 - 20) | +7.9% | ✅⬆️ |
| .NET 6 - CallTarget+Inlining+NGEN | ||||
| process.internal_duration_ms | 594.85 ± (591.84 - 597.87) ms | 598.04 ± (595.72 - 600.36) ms | +0.5% | ✅⬆️ |
| process.time_to_main_ms | 508.09 ± (507.18 - 508.99) ms | 538.79 ± (537.64 - 539.95) ms | +6.0% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 4 ± (4 - 4) | 4 ± (4 - 4) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 61.67 ± (61.58 - 61.77) MB | 61.75 ± (61.65 - 61.85) MB | +0.1% | ✅⬆️ |
| runtime.dotnet.threads.count | 30 ± (30 - 30) | 31 ± (31 - 31) | +1.0% | ✅⬆️ |
| .NET 8 - Baseline | ||||
| process.internal_duration_ms | 185.99 ± (185.74 - 186.25) ms | 202.25 ± (201.80 - 202.69) ms | +8.7% | ✅⬆️ |
| process.time_to_main_ms | 68.37 ± (68.25 - 68.49) ms | 74.78 ± (74.50 - 75.06) ms | +9.4% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 4 ± (4 - 4) | 4 ± (4 - 4) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 11.72 ± (11.65 - 11.79) MB | 11.66 ± (11.63 - 11.68) MB | -0.5% | ✅ |
| runtime.dotnet.threads.count | 18 ± (18 - 18) | 19 ± (19 - 19) | +3.5% | ✅⬆️ |
| .NET 8 - Bailout | ||||
| process.internal_duration_ms | 185.71 ± (185.49 - 185.92) ms | 201.51 ± (201.23 - 201.79) ms | +8.5% | ✅⬆️ |
| process.time_to_main_ms | 69.62 ± (69.56 - 69.69) ms | 75.77 ± (75.57 - 75.97) ms | +8.8% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 4 ± (4 - 4) | 4 ± (4 - 4) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 11.67 ± (11.58 - 11.77) MB | 11.73 ± (11.71 - 11.75) MB | +0.5% | ✅⬆️ |
| runtime.dotnet.threads.count | 19 ± (18 - 19) | 20 ± (20 - 20) | +6.3% | ✅⬆️ |
| .NET 8 - CallTarget+Inlining+NGEN | ||||
| process.internal_duration_ms | 521.08 ± (518.52 - 523.65) ms | 522.50 ± (518.30 - 526.70) ms | +0.3% | ✅⬆️ |
| process.time_to_main_ms | 466.62 ± (465.98 - 467.26) ms | 497.17 ± (496.24 - 498.09) ms | +6.5% | ✅⬆️ |
| runtime.dotnet.exceptions.count | 4 ± (4 - 4) | 4 ± (4 - 4) | +0.0% | ✅ |
| runtime.dotnet.mem.committed | 50.75 ± (50.72 - 50.78) MB | 50.79 ± (50.74 - 50.83) MB | +0.1% | ✅⬆️ |
| runtime.dotnet.threads.count | 30 ± (30 - 30) | 30 ± (30 - 30) | +0.5% | ✅⬆️ |
Comparison explanation
Execution-time benchmarks measure the whole time it takes to execute a program, and are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are highlighted in **red**. The following thresholds were used for comparing the execution times:
- Welch test with statistical test for significance of 5%
- Only results indicating a difference greater than 5% and 5 ms are considered.
Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard.
Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph).
Duration charts
FakeDbCommand (.NET Framework 4.8)
gantt
title Execution time (ms) FakeDbCommand (.NET Framework 4.8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8418) - mean (72ms) : 70, 74
master - mean (72ms) : 70, 74
section Bailout
This PR (8418) - mean (76ms) : 74, 77
master - mean (76ms) : 74, 78
section CallTarget+Inlining+NGEN
This PR (8418) - mean (1,073ms) : 1024, 1123
master - mean (1,076ms) : 1010, 1141
FakeDbCommand (.NET Core 3.1)
gantt
title Execution time (ms) FakeDbCommand (.NET Core 3.1)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8418) - mean (111ms) : 108, 115
master - mean (114ms) : 110, 117
section Bailout
This PR (8418) - mean (113ms) : 109, 116
master - mean (115ms) : 112, 118
section CallTarget+Inlining+NGEN
This PR (8418) - mean (784ms) : 765, 803
master - mean (784ms) : 764, 805
FakeDbCommand (.NET 6)
gantt
title Execution time (ms) FakeDbCommand (.NET 6)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8418) - mean (99ms) : 95, 103
master - mean (100ms) : 96, 103
section Bailout
This PR (8418) - mean (100ms) : 98, 103
master - mean (101ms) : 98, 104
section CallTarget+Inlining+NGEN
This PR (8418) - mean (936ms) : 903, 969
master - mean (932ms) : 899, 964
FakeDbCommand (.NET 8)
gantt
title Execution time (ms) FakeDbCommand (.NET 8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8418) - mean (98ms) : 95, 101
master - mean (98ms) : 94, 103
section Bailout
This PR (8418) - mean (99ms) : 97, 101
master - mean (99ms) : 97, 101
section CallTarget+Inlining+NGEN
This PR (8418) - mean (819ms) : 773, 864
master - mean (814ms) : 781, 848
HttpMessageHandler (.NET Framework 4.8)
gantt
title Execution time (ms) HttpMessageHandler (.NET Framework 4.8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8418) - mean (208ms) : 202, 214
master - mean (191ms) : 187, 194
section Bailout
This PR (8418) - mean (211ms) : crit, 209, 214
master - mean (194ms) : 192, 196
section CallTarget+Inlining+NGEN
This PR (8418) - mean (1,211ms) : crit, 1155, 1267
master - mean (1,142ms) : 1100, 1184
HttpMessageHandler (.NET Core 3.1)
gantt
title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8418) - mean (294ms) : 290, 298
master - mean (273ms) : 269, 277
section Bailout
This PR (8418) - mean (295ms) : crit, 292, 299
master - mean (273ms) : 270, 276
section CallTarget+Inlining+NGEN
This PR (8418) - mean (975ms) : 952, 999
master - mean (924ms) : 895, 953
HttpMessageHandler (.NET 6)
gantt
title Execution time (ms) HttpMessageHandler (.NET 6)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8418) - mean (287ms) : 281, 293
master - mean (267ms) : 262, 272
section Bailout
This PR (8418) - mean (288ms) : crit, 284, 292
master - mean (266ms) : 264, 268
section CallTarget+Inlining+NGEN
This PR (8418) - mean (1,165ms) : 1133, 1198
master - mean (1,133ms) : 1090, 1176
HttpMessageHandler (.NET 8)
gantt
title Execution time (ms) HttpMessageHandler (.NET 8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8418) - mean (288ms) : 279, 296
master - mean (264ms) : 261, 267
section Bailout
This PR (8418) - mean (287ms) : crit, 283, 292
master - mean (265ms) : 261, 268
section CallTarget+Inlining+NGEN
This PR (8418) - mean (1,054ms) : 990, 1118
master - mean (1,019ms) : 980, 1058
There was a problem hiding this comment.
Pull request overview
Adds an IP address quantization utility to obfuscate peer-tag IPs (reducing stats cardinality) and ports the corresponding unit tests from the Go agent.
Changes:
- Introduces
IpAddressObfuscationUtilto detect/obfuscate IPs (with scheme/prefix handling) and deduplicate entries. - Adds unit tests covering a variety of IPv4/IPv6/hostname formats and comma-separated peer lists.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.
| File | Description |
|---|---|
| tracer/src/Datadog.Trace/Processors/IpAddressObfuscationUtil.cs | Implements IP detection + obfuscation + deduplication logic for peer tags |
| tracer/test/Datadog.Trace.Tests/TraceProcessors/IpAddressObfuscationUtilTests.cs | Adds ported test cases validating expected quantization behavior |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
f00d1b6 to
77f3510
Compare
8c15dbe to
46be799
Compare
77f3510 to
536d246
Compare
536d246 to
a44d3e6
Compare
| #if NETCOREAPP | ||
| return ushort.TryParse(s, out _); | ||
| #else | ||
| if (s.Length == 0) |
There was a problem hiding this comment.
NIT: In the !NETCOREAPP case, we are accepting as valid port values > 64k
There was a problem hiding this comment.
Good catch. I think that's maybe something we should just live with, as it seems like more hassle (allocation) than it's worth to try to handle it? 🤔 An "easy" fix would be to reject s.Length > 5 too 🤔 That way we would still be allowing 65,535 - 99,999, which are not valid, but we would reject anything bigger. Seems like a reasonable trade off to me, wdyt?
There was a problem hiding this comment.
I made that change here: f0895ac, I think it's probably good enough TBH
a44d3e6 to
f0895ac
Compare
bouwkast
left a comment
There was a problem hiding this comment.
I didn't do a super thorough review of it compared to the go version, but looks good to me
## Summary of changes Updates the existing client-side-stats implementation to match version 1.2.0 [as defined in the RFC](https://datadoghq.atlassian.net/wiki/spaces/APM/pages/6378947571/Client-Side+Stats+v1.2.0) and as [implemented in the agent](https://github.com/DataDog/datadog-agent/blob/c1d67a906f4c594654600760da1eea4c8037471a/pkg/proto/datadog/trace/stats.proto#L83). ## Reason for change Our implementation is severely lagging the latest implementation in the agent. This hasn't been a big deal, as it's not documented and not enabled by default, but we'd like to fix the implementation to make it usable. ## Implementation details This was driven almost entirely by 🤖, by comparing our existing implementation to the RFC, and also taking the agent/go implementation as the canonical implementation. > Implementing this in .NET highlighted a number of missing aspects in the RFC, which I've raised elsewhere, and aim to get incorporated into the RFC. At a high level, the PR contains the following changes: - Stats Wire Format & Serialization - **Added new aggregation dimensions**: `SpanKind`, `IsTraceRoot` (as Trilean), `HTTPMethod`, `HTTPEndpoint`, `GRPCStatusCode`, `ServiceSource`, `PeerTags` to both the aggregation key and the msgpack wire format - **Fixed `GRPCStatusCode` type**: Changed from `int` to `string` to match Go agent's wire format (agent was returning 400 Bad Request in system tests) - **gRPC status code extraction**: Checks 4 tag names in priority order (`rpc.grpc.status_code`, `grpc.code`, `rpc.grpc.status.code`, `grpc.status.code`) - **Stochastic rounding**: `Hits`, `Errors`, `Duration`, `TopLevelHits` accumulated as `double` (weighted by sampling rate) then rounded probabilistically to `int64` for serialization - **Duration weighting**: Durations are now multiplied by sampling weight (`1/rate`), matching Go agent behavior - **Default env**: Serializes `"unknown-env"` when environment is not configured - **`git_commit_sha`**: Added as optional field in stats payload - **`Service`**: Added as top-level field in stats payload - **Empty bucket suppression**: `HasHits()` check prevents sending payloads with zero-hit buckets (stale keys retained for sketch reuse) - Bucket Timing - **10-second alignment**: Bucket `Start` timestamps aligned to 10-second boundaries (`ts - ts % 10_000_000_000`) matching Go tracer's `alignTs` - **Removed unused `StartTime`** property (only `Start` as aligned nanoseconds) - Agent Discovery (`/info` Endpoint) - **`peer_tags`**: Parsed, sorted, deduplicated; used for peer tag extraction on client/producer/consumer spans - **`span_kinds_stats_computed`**: Parsed to override eligible span kinds - **`obfuscation_version`**: Parsed for obfuscation negotiation - **Trace filters**: Parsed `filter_tags`, `filter_tags_regex`, `ignore_resources` from `/info` - Trace Filtering - **`TraceFilter` implementation**: Evaluates agent-configured filters (exact tags, regex tags, resource patterns) against root spans before stats computation - **Tag-only filters**: Handles filter entries that match on tag key presence without a specific value - SQL Obfuscation - **Operator splitters**: Added `* / = < > ! & ^ % ~ ? @ : #` as token splitters (matching Go agent's `go-sqllexer` `isOperator()`) so queries like `WHERE id='1'` are properly obfuscated - **Whitespace normalization**: Post-processing pass adds spaces around comparison operators (`=`, `<`, `>`, `!`) adjacent to `?` placeholders, matching Go agent's normalizer output (e.g., `id='1'` → `id = ?`) - **Obfuscation gating**: Only runs when `obfuscation_version` is negotiated with agent; sends `Datadog-Obfuscation-Version` header - Peer Tags - **IP quantization**: Peer tag values run through `IpAddressObfuscationUtil.QuantizePeerIpAddresses()` replacing non-allowed IPs with `"blocked-ip-address"` - **Base service handling**: Internal/missing-kind spans with non-default service name use `_dd.base_service:{serviceName}` as sole peer tag - **FNV-1a hashing**: Peer tags hashed with null-byte separators for aggregation key - Other - **No retries for stats**: Stats sends are fire-and-forget (retry limit = 0) - **Synthetics detection**: Uses `StartsWith("synthetics")` prefix matching (not exact match) - **Mock agent updates**: Test mock agent returns `obfuscation_version` in `/info` response ## Test coverage There's a _lot_ going on in this PR, because we were so far behind. I _could_ split this into implementing individual features, but there would be a lot of duplication between PRs, and it didn't seem like it would be that easy to track. At least with this big bang we can compare directly against the system tests etc. The existing system tests for stats computation were checked, and made to pass (which identified a number of hidden expectations which will be added to the RFC). I'll create a PR to enable these in the system-tests repo ## Other details Part of a stack - #8417 - #8418 There are still some _theoretical_ gaps between the go implementation and the .NET implementation, but I _think_ these are non-issues in _most_ cases: | Area | Gap | Impact | |------|-----|--------| | gRPC status code normalization | Go agent normalizes string statuses (e.g., `"CANCELLED"` → `"1"`); .NET passes raw tag value | Stats mismatch if gRPC library uses string-form status codes | | HTTP status code tags | Go agent checks both `http.status_code` and `http.response.status_code` (OTel convention); .NET only checks `http.status_code` | OTel spans using newer convention would get `0` in .NET | | Duration precision truncation | Go agent uses float bit masking; .NET uses integer shifting — both target ~10 bits but may produce slightly different values | Minor histogram differences | | SQL obfuscation | Go agent uses full tokenizer + normalizer; .NET uses character-level splitter with targeted normalization around comparison operators only | Complex SQL with unusual formatting may produce different resource strings | | `HTTP_method` / `HTTP_endpoint` | .NET always populates from span tags; Go agent only populates from newer OTel pipeline paths | Creates different aggregation keys — Go groups all methods/routes together in default path | | `_top_level` metric | Go checks both `_top_level` and `_dd.top_level`; .NET only checks `_dd.top_level` | Spans using older metric name would be missed by .NET | | `span_derived_primary_tags` | Still in Go agent code but implemented in v1.3.0 RFC, which was reverted; removed from .NET | No current impact; may need to re-add if spec reverts back | There is another big elephant in the room, which is perf. The peer tags, in particular, currently requires a _bunch_ of allocation. I'd rather defer trying to fight against that to another PR if possible, unless anyone has some clear ideas 😄 Another aspect I'm not sure about is how this interacts with @zacharycmontoya's recent work to publish OTLP stats. I took a random guess and fought the refactoring, but need to verify it. --------- Co-authored-by: Claude Opus 4.6 (1M context) <[email protected]> Co-authored-by: Lucas Pimentel <[email protected]>
## Summary of changes Extracts `ContainsSpanId` from `TraceChunkModel` to `SpanCollection` ## Reason for change I need to find a given span in a `SpanCollection` for client-side-stats. The algorithm used by `TraceChunkModel` does it "properly" (by stating from the last span when looking for a root span), so it seems to make sense to move this method to `SpanCollection`. Additionally, this essentially hides some of the internals about the `SpanCollection` type, so seems like a better place for it anyway. ## Implementation details - Move the `IndexOf()` method from `TraceChunkModel` to `SpanCollection` - Switch it to `Contains()` instead, seeing as the index is never actually used AFAICT. It's easy to switch it back later if we _do_ need it. ## Test coverage Added some unit tests for the method ## Other details Part of a stack - #8417 - #8418 - #8420
## Summary of changes Updates the processing pipeline for client side stats ## Reason for change The bulk of the CSS 1.2.0 work was done in #8420, but the span-processing pipeline wasn't the same as the Go agent: | Step | Go Agent | .NET Tracer | | ---- | --------- | -------------------------------------- | | 1 | Normalize | Normalize + Obfuscate (`ProcessTrace`) | | 2 | Filter | Filter + Sample (`ShouldKeepTrace`) | | 3 | Obfuscate | | | 4 | Sample | | | 5 | Stats | Stats (`AddRange`) | ## Implementation details The difference was mostly due to the way we had separate `ProcessTrace()` and `ShouldKeepTrace()` methods. By merging them, we can encapsulate the pipeline, and ensure that we mirror the way the Go agent processes traces. Additionally, there are two different mechanisms for dropping spans now - p0drops and "trace filtering", so added a new metric tag `reason:trace_filter` for it. Additionally, made some small optimizations: - No need for an array of `ITraceProcessor` when it only contains one - Updated `TraceFilter` algorithm to correctly look for local trace root, starting from last span - Made `_statsAggregator` non-null in `AgentWriter` to eliminate a bunch of null checks ## Test coverage Covered by existing tests. ## Other details Part of a stack: - #8417 - #8418 - #8420 - #8435
## Summary of changes Improves the performance of peer-tag hash calculation for "fast path" cases (where there's an existing bucket) ## Reason for change We have to calculate the hash of all peer tags as part of client-side-stats bucketing calculations, which involves encoding them as utf-8. Additionally, when we _send_ the buckets, we have to send the tags as utf-8. In the initial CSS 1.2.0 implementation, we encoded the tags every-time we ran a calculation, which would allocate for every span that had peer tags, generally quite expensive. In this PR, we switch to doing the encoding twice: once with a zero-allocation implementation (amortized 0 on .NET Framework) to calculate the hash, and then, _if_ we need the "real" encoded tags, then we do that encoding again. ## Implementation details - Split the peer tags work in two, once to calculate the peer tags hash, once to get the actual tags as `key:value` - In the hash-calculation stage, we can use `stackalloc` for .NET Core, and array pool implementation for .NET Framework etc - As additional optimizations, we also - Pre-encode the peer tag _keys_ to utf-8, so that we only need to do those once for the hash calculation. - Pass key details from `BuildKey` to `GetEncodedPeerTags` (i.e. is this a "base service" only tag, if so, what's the tag value, otherwise how big does the peer tag list need to be) - If client-side stats is disabled, don't bother doing all the pre-calculation (or for trace filters) There are some possible future optimizations, _not_ implemented in this PR: - Track which tags require IP quantization to avoid re-doing it. (Maybe we should allow-list the quantization anyway, so that it only applies to specific tags? Or alternatively, block list?) - Instead of doing the encoding of `tag:value`, allow writing the pre-computed `byte[]` to `MessagePackBinary` and appending the `value`. This is doable, but requires updating the `MessagePackBinary` implementation to support it, so I considered it out of scope for now ## Test coverage Mostly covered by existing tests, but added some additional unit tests that directly compare the hashing to values used in Go agent tests. Additionally did some benchmarking. The key thing is that the `ClientSpanWithPeerTags` path is zero-allocation (and it's nice that the slow-path is still lower allocation than before, even if it's slower over all) | Method | Runtime | Mean | Error | Allocated | | -------------------------------------------------- | ------------------ | ----------: | ---------: | --------: | | BuildKey_SimpleSpan_Before | .NET 10.0 | 44.34 ns | 0.906 ns | - | | BuildKey_SimpleSpan_After | .NET 10.0 | 39.17 ns | 0.445 ns | - | | BuildKey_SimpleSpan_Before | .NET 6.0 | 93.13 ns | 1.837 ns | - | | BuildKey_SimpleSpan_After | .NET 6.0 | 87.56 ns | 0.839 ns | - | | BuildKey_SimpleSpan_Before | .NET Core 3.1 | 192.53 ns | 2.572 ns | - | | BuildKey_SimpleSpan_After | .NET Core 3.1 | 217.32 ns | 4.362 ns | - | | BuildKey_SimpleSpan_Before | .NET Framework 4.8 | 131.98 ns | 2.621 ns | - | | BuildKey_SimpleSpan_After | .NET Framework 4.8 | 175.20 ns | 7.647 ns | - | | | | | | | | BuildKey_ClientSpanNoPeerTags_Before | .NET 10.0 | 160.62 ns | 2.622 ns | - | | BuildKey_ClientSpanNoPeerTags_After | .NET 10.0 | 151.27 ns | 1.995 ns | - | | BuildKey_ClientSpanNoPeerTags_Before | .NET 6.0 | 243.62 ns | 3.199 ns | - | | BuildKey_ClientSpanNoPeerTags_After | .NET 6.0 | 232.55 ns | 2.975 ns | - | | BuildKey_ClientSpanNoPeerTags_Before | .NET Core 3.1 | 550.47 ns | 9.998 ns | - | | BuildKey_ClientSpanNoPeerTags_After | .NET Core 3.1 | 680.42 ns | 10.022 ns | - | | BuildKey_ClientSpanNoPeerTags_Before | .NET Framework 4.8 | 442.88 ns | 8.854 ns | - | | BuildKey_ClientSpanNoPeerTags_After | .NET Framework 4.8 | 682.12 ns | 13.468 ns | - | | | | | | | | BuildKey_ClientSpanWithPeerTags_Before | .NET 10.0 | 800.82 ns | 15.062 ns | 840 B | | BuildKey_ClientSpanWithPeerTags_After | .NET 10.0 | 575.04 ns | 5.604 ns | - | | BuildKey_ClientSpanWithPeerTags_Before | .NET 6.0 | 1,076.07 ns | 13.124 ns | 840 B | | BuildKey_ClientSpanWithPeerTags_After | .NET 6.0 | 1,440.26 ns | 28.755 ns | - | | BuildKey_ClientSpanWithPeerTags_Before | .NET Core 3.1 | 1,531.27 ns | 13.509 ns | 840 B | | BuildKey_ClientSpanWithPeerTags_After | .NET Core 3.1 | 1,774.35 ns | 89.601 ns | - | | BuildKey_ClientSpanWithPeerTags_Before | .NET Framework 4.8 | 1,682.15 ns | 17.082 ns | 859 B | | BuildKey_ClientSpanWithPeerTags_After | .NET Framework 4.8 | 2,040.90 ns | 162.895 ns | - | | | | | | | | BuildKey_ClientSpanWithPeerTags_GetEncodedPeerTags | .NET 10.0 | 1,141.85 ns | 9.980 ns | 760 B | | BuildKey_ClientSpanWithPeerTags_GetEncodedPeerTags | .NET 6.0 | 2,720.55 ns | 53.097 ns | 760 B | | BuildKey_ClientSpanWithPeerTags_GetEncodedPeerTags | .NET Core 3.1 | 3,534.28 ns | 141.234 ns | 760 B | | BuildKey_ClientSpanWithPeerTags_GetEncodedPeerTags | .NET Framework 4.8 | 3,438.80 ns | 84.352 ns | 778 B | <details><summary>Details</summary> <p> ```csharp // <copyright file="StatsAggregatorBenchmark.cs" company="Datadog"> // Unless explicitly stated otherwise all files in this repository are licensed under the Apache 2 License. // This product includes software developed at Datadog (https://www.datadoghq.com/). Copyright 2017 Datadog, Inc. // </copyright> using System; using System.Collections.Generic; using System.Threading.Tasks; using BenchmarkDotNet.Attributes; using Datadog.Trace; using Datadog.Trace.Agent; using Datadog.Trace.Agent.DiscoveryService; using Datadog.Trace.Configuration; using Datadog.Trace.Tagging; namespace Benchmarks.Trace; /// <summary> /// StatsAggregator.BuildKey benchmarks /// </summary> [MemoryDiagnoser] [BenchmarkCategory(Constants.TracerCategory)] public class StatsAggregatorBenchmark { private static readonly List<StatsAggregator.PeerTagKey> PeerTagKeys = [ new("_dd.base_service"), new("aws.queue.name"), new("aws.queue.url"), new("aws.s3.bucket"), new("aws.stream.name"), new("bucketname"), new("db.couchbase.seed.nodes"), new("db.hostname"), new("db.instance"), new("db.system"), new("messaging.destination"), new("messaging.kafka.bootstrap.servers"), new("messaging.rabbitmq.exchange"), new("messaging.system"), new("network.destination.name"), new("peer.hostname"), new("peer.service"), new("server.address"), new("topic"), ]; private StatsAggregator _aggregator; private Span _simpleSpan; private Span _clientSpanNoPeerTags; private Span _clientSpanWithPeerTags; private StatsAggregationKey _key; private List<byte[]> _encoded; [GlobalSetup] public void GlobalSetup() { _aggregator = new StatsAggregator( new NoOpApi(), new TracerSettings(), NullDiscoveryService.Instance, isOtlp: false); var now = DateTimeOffset.UtcNow; // Simple span: no span kind, no peer tags — exercises the "internal" fast path _simpleSpan = CreateSpan(now, "web-service", "web.request", "GET /api/users", "web"); // Client span with SpanKind but no matching peer tags — iterates peer tag keys but finds nothing var clientTags = new HttpTags { HttpMethod = "GET", HttpStatusCode = "200" }; _clientSpanNoPeerTags = CreateSpan(now, "web-service", "http.request", "GET /api/orders", "http", clientTags); // Client span with several peer tags set — the most expensive path var peerTags = new HttpTags { HttpMethod = "POST", HttpStatusCode = "200" }; _clientSpanWithPeerTags = CreateSpan(now, "web-service", "http.request", "POST /api/data", "http", peerTags); _clientSpanWithPeerTags.Tags.SetTag("peer.service", "remote-service"); _clientSpanWithPeerTags.Tags.SetTag("db.instance", "i-1234"); _clientSpanWithPeerTags.Tags.SetTag("db.system", "postgres"); _clientSpanWithPeerTags.Tags.SetTag("server.address", "db.example.com"); _clientSpanWithPeerTags.Tags.SetTag("network.destination.name", "db.example.com"); } [GlobalCleanup] public void GlobalCleanup() { _aggregator.DisposeAsync().GetAwaiter().GetResult(); var value = _key; var encoded = _encoded; } /// <summary> /// BuildKey for a simple span with no span kind (internal fast-path, no peer tag iteration). /// </summary> [Benchmark] public void BuildKey_SimpleSpan() { _key = _aggregator.BuildKey(_simpleSpan, PeerTagKeys, out _); } /// <summary> /// BuildKey for a client span that has no matching peer tags (iterates all peer tag keys, finds none). /// </summary> [Benchmark] public void BuildKey_ClientSpanNoPeerTags() { _key = _aggregator.BuildKey(_clientSpanNoPeerTags, PeerTagKeys, out _); } /// <summary> /// BuildKey for a client span with several peer tags set (UTF-8 encoding + FNV hashing). /// </summary> [Benchmark] public void BuildKey_ClientSpanWithPeerTags() { _key = _aggregator.BuildKey(_clientSpanWithPeerTags, PeerTagKeys, out var results); } /// <summary> /// BuildKey for a client span with several peer tags set (UTF-8 encoding + FNV hashing). /// </summary> [Benchmark] public void BuildKey_ClientSpanWithPeerTags_GetEncodedPeerTags() { _key = _aggregator.BuildKey(_clientSpanWithPeerTags, PeerTagKeys, out var results); _encoded = StatsAggregator.GetEncodedPeerTags(_clientSpanWithPeerTags, PeerTagKeys, in results); } private static Span CreateSpan(DateTimeOffset start, string serviceName, string operationName, string resourceName, string type, ITags tags = null) { var tracer = Benchmarks.Trace.Asm.EmptyDatadogTracer.Instance; var traceContext = new TraceContext(tracer); var context = new SpanContext(null, traceContext, serviceName); var span = new Span(context, start, tags); span.OperationName = operationName; span.ResourceName = resourceName; span.Type = type; return span; } private sealed class NoOpApi : IApi { public TracesEncoding TracesEncoding => TracesEncoding.DatadogV0_4; public Task<bool> Ping() => Task.FromResult(true); public Task<bool> SendTracesAsync(ArraySegment<byte> traces, int numberOfTraces, bool statsComputationEnabled, long numberOfDroppedP0Traces, long numberOfDroppedP0Spans, bool apmTracingEnabled = true) => Task.FromResult(true); public Task<bool> SendStatsAsync(StatsBuffer stats, long bucketDuration, int tracerObfuscationVersion) => Task.FromResult(true); } } ``` </p> </details> ## Other details Part of a stack: - #8417 - #8418 - #8420 - #8435 - #8436 - #8444
## Summary of changes Removes the minimum-agent version check from the client-side-stats check ## Reason for change We didn't have it before, which means people who previously had stats, suddenly won't have them. Also other agents (like bottlecap etc) don't have the version. And we haven't figured out how to handle that yet. While CSS is off by default, this seems like the best option to take. ## Implementation details Remove the code that is checking for CSS support. ## Test coverage Covered by existing (and removed a test for the behaviour) ## Other details Follows on from - #8417 - #8418 - #8420 - #8435 - #8436 - #8444 - #8445
Summary of changes
Adds the
IpAddressObfuscationUtilhelper for use by client-side statsReason for change
It's not part of the RFC, but the agent does quantization of IPaddresses, which could appear in peer tags (which are used for stats calculations). Without this quantization, we would end up with an explosion of buckets
Implementation details
Used 🤖 to port the implementation from the Go agent, including the tests. Then iterated on it repeatedly to try to bring the allocations down as low as possible.
Test coverage
Grabbed the quantization unit tests from the agent
Other details
Pre-requisite for client-side-stats improvements. Part of a stack:
charhelpers likeIsAsciiHexDigit#8417