[Appsec] Add comments and refs to help out codex reviews when libddwaf is involved#8831
Conversation
f1d63c4 to
8db07b1
Compare
Execution-Time Benchmarks Report ⏱️Execution-time results for samples comparing This PR (8831) and master. ✅ No regressions detected - check the details below Full Metrics ComparisonFakeDbCommand
HttpMessageHandler
Comparison explanationExecution-time benchmarks measure the whole time it takes to execute a program, and are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are highlighted in **red**. The following thresholds were used for comparing the execution times:
Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard. Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph). Duration chartsFakeDbCommand (.NET Framework 4.8)gantt
title Execution time (ms) FakeDbCommand (.NET Framework 4.8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8831) - mean (70ms) : 68, 72
master - mean (72ms) : 68, 76
section Bailout
This PR (8831) - mean (74ms) : 73, 76
master - mean (77ms) : 74, 81
section CallTarget+Inlining+NGEN
This PR (8831) - mean (1,081ms) : 1033, 1129
master - mean (1,081ms) : 1037, 1125
FakeDbCommand (.NET Core 3.1)gantt
title Execution time (ms) FakeDbCommand (.NET Core 3.1)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8831) - mean (110ms) : 107, 112
master - mean (113ms) : 107, 118
section Bailout
This PR (8831) - mean (110ms) : 108, 113
master - mean (112ms) : 107, 117
section CallTarget+Inlining+NGEN
This PR (8831) - mean (779ms) : 754, 805
master - mean (778ms) : 756, 801
FakeDbCommand (.NET 6)gantt
title Execution time (ms) FakeDbCommand (.NET 6)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8831) - mean (97ms) : 94, 99
master - mean (98ms) : 93, 103
section Bailout
This PR (8831) - mean (97ms) : 96, 99
master - mean (98ms) : 96, 99
section CallTarget+Inlining+NGEN
This PR (8831) - mean (938ms) : 899, 977
master - mean (935ms) : 896, 974
FakeDbCommand (.NET 8)gantt
title Execution time (ms) FakeDbCommand (.NET 8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8831) - mean (99ms) : 94, 104
master - mean (96ms) : 91, 102
section Bailout
This PR (8831) - mean (98ms) : 93, 103
master - mean (100ms) : 95, 105
section CallTarget+Inlining+NGEN
This PR (8831) - mean (814ms) : 770, 859
master - mean (813ms) : 777, 850
HttpMessageHandler (.NET Framework 4.8)gantt
title Execution time (ms) HttpMessageHandler (.NET Framework 4.8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8831) - mean (202ms) : 198, 206
master - mean (201ms) : 197, 205
section Bailout
This PR (8831) - mean (204ms) : 200, 207
master - mean (205ms) : 202, 207
section CallTarget+Inlining+NGEN
This PR (8831) - mean (1,215ms) : 1166, 1264
master - mean (1,203ms) : 1165, 1242
HttpMessageHandler (.NET Core 3.1)gantt
title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8831) - mean (292ms) : 284, 300
master - mean (290ms) : 283, 297
section Bailout
This PR (8831) - mean (292ms) : 286, 298
master - mean (290ms) : 286, 294
section CallTarget+Inlining+NGEN
This PR (8831) - mean (979ms) : 956, 1002
master - mean (972ms) : 945, 998
HttpMessageHandler (.NET 6)gantt
title Execution time (ms) HttpMessageHandler (.NET 6)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8831) - mean (284ms) : 278, 291
master - mean (281ms) : 275, 286
section Bailout
This PR (8831) - mean (285ms) : 280, 290
master - mean (279ms) : 271, 288
section CallTarget+Inlining+NGEN
This PR (8831) - mean (1,177ms) : 1125, 1229
master - mean (1,161ms) : 1130, 1191
HttpMessageHandler (.NET 8)gantt
title Execution time (ms) HttpMessageHandler (.NET 8)
dateFormat x
axisFormat %Q
todayMarker off
section Baseline
This PR (8831) - mean (284ms) : 277, 292
master - mean (280ms) : 274, 286
section Bailout
This PR (8831) - mean (285ms) : 279, 291
master - mean (279ms) : 273, 286
section CallTarget+Inlining+NGEN
This PR (8831) - mean (1,053ms) : 1006, 1100
master - mean (1,044ms) : 998, 1089
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
BenchmarksBenchmark execution time: 2026-06-29 13:03:24 Comparing candidate commit 4be0af0 in PR branch Found 0 performance improvements and 0 performance regressions! Performance is the same for 72 metrics, 0 unstable metrics, 61 known flaky benchmarks, 65 flaky benchmarks without significant changes.
|
3d1b9d4 to
494db83
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 494db83fa1
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
…resses lock Add XML doc comments on Waf and Context linking to the libddwaf source so AI-assisted reviewers can navigate to the native implementation, and inline comments explaining non-obvious constraints: - Waf.cs: link to libddwaf waf.hpp; document why ddwaf_destroy is safe after the write lock is released (ddwaf_context_init copies the ruleset shared_ptr, so existing contexts hold an independent reference) - Waf.cs: restore GetKnownAddresses to EnterWriteLock. ddwaf_known_addresses is explicitly documented as not thread-safe (see libddwaf c-api/api.md#L144); its root_addresses vector is lazily populated without synchronization, so a read lock (which allows concurrent callers) causes an AccessViolationException - Context.cs: link to libddwaf context.hpp; document why pwPersistentArgs must not be disposed before the end of the context lifecycle - RaspWafTests.cs: add regression test for concurrent GetKnownAddresses calls
494db83 to
40b071f
Compare
Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
Summary of changes
Fixing waf locks giving errors:

Comments added to
Waf.csandContext.csto guide AI-assisted code reviews — linking to the relevant libddwaf native source files so reviewers can navigate to the C++ implementation, and explaining non-obvious invariants that an AI reviewer would otherwise misread as bugs.Specifically:
Waf.cs: link to libddwafwaf.hpp; explain whyddwaf_destroyis safe to call after releasing the write lock (contexts hold an independentshared_ptrto the ruleset)Waf.cs: document thatGetKnownAddressesmust use a write lock —ddwaf_known_addressesis explicitly not thread-safe, itsroot_addressesvector is lazily populated without synchronization, so a read lock (which allows concurrent callers) causes anAccessViolationExceptionContext.cs: link to libddwafcontext.hpp; document whypwPersistentArgsmust not be disposed before end of the context lifecycleThe lock fix (
GetKnownAddressesreverted fromEnterReadLockback toEnterWriteLock) is included here because it was introduced by an AI reviewer misreading the intent of the code — exactly the class of mistake the comments are meant to prevent.Reason for change
AI reviewers (Codex, Claude, etc.) were suggesting wrong changes to the locking strategy in the WAF interop code without understanding the native library's thread-safety constraints. The comments make those constraints explicit and link to the canonical source.
Test coverage
Existing test
GivenWafInstance_WhenGetKnownAddressesInParallel_ThenResultIsOkcovers the concurrent-access scenario and would have caught (and did catch) the read-lock regression.