-
Notifications
You must be signed in to change notification settings - Fork 560
chore(appsec): tag spans with refreshed rc client id #19819
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -400,8 +400,15 @@ def finalize_asm_env(env: ASM_Environment) -> None: | |
| entry_span._set_attribute(APPSEC.EVENT_RULE_ERROR_COUNT, info.failed) | ||
| except Exception: | ||
| logger.debug("asm_context::finalize_asm_env::exception", extra=log_extra, exc_info=True) | ||
| if asm_config._rc_client_id is not None: | ||
| entry_span.set_tag(APPSEC.RC_CLIENT_ID, asm_config._rc_client_id) | ||
| if asm_config._rc_client_id_enabled: | ||
| from ddtrace.internal.remoteconfig.worker import remoteconfig_poller | ||
|
|
||
| # Fetch the current id from the RC client at span finalization. asm_config only | ||
| # tracks whether AppSec RC enabled tagging; mirroring the id there would go stale | ||
| # when runtime identity refresh rebuilds the RC client. | ||
| rc_client_id = remoteconfig_poller._client.id | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
In a forked worker, the runtime-ID callback renews Useful? React with 馃憤聽/ 馃憥.
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I think Codex鈥檚 comment makes sense. WDYT @P403n1x87? |
||
| if rc_client_id is not None: | ||
| entry_span.set_tag(APPSEC.RC_CLIENT_ID, rc_client_id) | ||
| waf_adresses = env.waf_addresses | ||
| req_headers = waf_adresses.get(SPAN_DATA_NAMES.REQUEST_HEADERS_NO_COOKIES, {}) | ||
| if req_headers: | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When an AppSec request is finalized with RC tagging enabled, this imports the worker inside the hot-path function to avoid an import-time dependency, leaving
_asm_request_contextstructurally coupled to the RC worker and even adding a test that enforces the workaround. Extract or inject a lightweight current-client-ID accessor instead; repository policy explicitly forbids leaving deferred imports in place to conceal import-graph problems.AGENTS.md reference: AGENTS.md:L20-L21
Useful? React with 馃憤聽/ 馃憥.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think Codex鈥檚 comment makes sense. WDYT @christophe-papazian?