Skip to content

[php] Fix Laravel 11 builds and track client stats regression - #7915

Open
vpellan wants to merge 7 commits into
mainfrom
vpellan/fix-laravel11x-build
Open

vpellan wants to merge 7 commits into
mainfrom
vpellan/fix-laravel11x-build

Conversation

@vpellan

@vpellan vpellan commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Laravel 11 builds fail in both PHP dev and prod because Composer blocks every supported Laravel 11 release on advisory PKSA-d5tc-s1qs-h781 (CVE-2026-102279). Add the advisory to the test fixture’s existing exception list so Laravel 11 coverage can run again. This is a fixture exception, not a fix for the upstream vulnerability.

  • Refresh the shared PHP base-image locks and mirror entries required by the Composer change. Keep the existing image dependency model; the Dockerfile workaround has been reverted.
  • Exclude _dd.sdk.otlp_export from debugger exception-replay approval comparisons because this export-routing marker varies by tracer version.
  • Mark six failing stats methods as bug (APMAPI-2559) for PHP >=1.26.0-dev, preserving existing version and weblog declarations. PHP 1.25.1 remains covered normally.

The stats regression is tracked in APMAPI-2559. PHP’s pinned libdatadog rejects null obfuscation lists in the development Agent’s /info response, preventing client stats from starting. libdatadog #2586 contains the upstream fix; PHP must consume it and publish a fixed development artifact before removing or narrowing the markers. Fixing Laravel exposes these tests because the original build failure skipped the PHP end-to-end matrix.

Validation:

  • All 25 computed PHP base-image hashes match the restored lock.
  • Captured dev CI artifact replays: TRACE_STATS_COMPUTATION has 3 passed / 10 expected failures (5 existing, 5 newly tracked); resource-renaming tests in TRACING_CONFIG_NONDEFAULT_3 and APPSEC_BLOCKING each have 3 passed / 1 expected failure.
  • Released PHP 1.25.1 artifact replays: stats has 8 passed / 5 pre-existing expected failures; both resource-renaming runs have 4 passed. Manifest evaluation confirms all six new markers leave 1.25.1 and prior declarations unchanged across Laravel, Apache, and Symfony.
  • ./format.sh --check passes Python, import policy, YAML, manifest, redaction, and shell checks; local Node lint is blocked by the existing missing strip-bom dependency. git diff --check passes.
  • Debugger artifact replay has 3 passed / 5 skipped; four snapshot comparisons encounter exactly twice the expected snapshots in the saved artifact. Assertions and approval files were not relaxed to accommodate that replay limitation.
  • Full CI for the final revision is pending.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

CODEOWNERS have been resolved as:

manifests/php.yml                                                       @DataDog/system-tests-reviewers
mirror_images.lock.yaml                                                 @DataDog/system-tests-core
mirror_images.yaml                                                      @DataDog/system-tests-core
tests/debugger/test_debugger_exception_replay.py                        @DataDog/debugger
utils/build/docker/base-images.lock.json                                @DataDog/system-tests-reviewers
utils/build/docker/php/weblogs/laravel11x/composer.json                 @DataDog/system-tests-reviewers

@vpellan
vpellan marked this pull request as ready for review October 1, 2026 09:54
@vpellan
vpellan requested a review from a team as a code owner October 1, 2026 09:54
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T09:57:08.096091Z b41ed98 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@vpellan
vpellan enabled auto-merge (squash) October 1, 2026 09:57
@datadog-prod-us1-5

datadog-prod-us1-5 Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Pipelines  Tests

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 333 Pipeline jobs failed

Testing the test | System Tests (nodejs_lambda, prod) / End-to-end #1 / nodejs-alb-multi 1 — 🔄 Retry may pass, looks flaky

View more details · View in GitHub Actions

Testing the test | System Tests (python_lambda, prod) / End-to-end #1 / function-url 1 — 🔄 Retry may pass, looks flaky

View more details · View in GitHub Actions

Testing the test | System Tests (cpp_httpd, dev) / End-to-end #1 / httpd 1

View more details · View in GitHub Actions

View all 333 failed jobs.

⚠️ Warnings

🧪 3 Tests failed in 1 job

Testing the test | main — ❌ 3 tests failed

View more details · View in GitHub Actions

❌ tests.stats.test_stats.Test_Client_Stats_Future_Obfuscation_Version.test_no_obfuscation[symfony7x] from system_tests_suite   View in Datadog
AssertionError: Expected at least 4 distinct SQL stats entries because obfuscation was not applied client-side
assert 0 >= 4
 +  where 0 = len(set())

self = <tests.stats.test_stats.Test_Client_Stats_Future_Obfuscation_Version object at 0x7f4ee022e0c0>

    def test_no_obfuscation(self):
        """Test that the SDK does not obfuscate stats and does not send the obfuscation header
        when the agent reports an obfuscation_version higher than what the SDK supports (99).
    
...
❌ tests.stats.test_stats.Test_Client_Stats_Missing_Obfuscation_Version.test_no_obfuscation[symfony7x] from system_tests_suite   View in Datadog
AssertionError: Expected at least 4 distinct SQL stats entries because obfuscation was not applied client-side
assert 0 >= 4
 +  where 0 = len(set())

self = <tests.stats.test_stats.Test_Client_Stats_Missing_Obfuscation_Version object at 0x7fdd705954f0>

    def test_no_obfuscation(self):
        """Test that the SDK does not obfuscate stats and does not send the obfuscation header
    
        Validates:
...
❌ tests.stats.test_stats.Test_Client_Stats_Obfuscation_Version_Zero.test_no_obfuscation[symfony7x] from system_tests_suite   View in Datadog
AssertionError: Expected at least 4 distinct SQL stats entries because obfuscation was not applied client-side
assert 0 >= 4
 +  where 0 = len(set())

self = <tests.stats.test_stats.Test_Client_Stats_Obfuscation_Version_Zero object at 0x7f38e06d3770>

    def test_no_obfuscation(self):
        """Test that the SDK does not obfuscate stats and does not send the obfuscation header
        when the agent advertises obfuscation_version=0.
    
...

ℹ️ Info

No other issues found (see more)

❄️ No new flaky tests detected

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: ab5e8d7 | Docs | View more details | Give us feedback!

@vpellan
vpellan requested a review from a team as a code owner October 1, 2026 10:26
@vpellan vpellan changed the title fix(php): unblock Laravel 11 builds after new security advisory [php] fix(php): unblock Laravel 11 builds after new security advisory Oct 1, 2026
@vpellan
vpellan requested a review from a team as a code owner October 1, 2026 11:37
@vpellan vpellan changed the title [php] fix(php): unblock Laravel 11 builds after new security advisory [php] Fix Laravel builds, refresh image locks, and stabilize exception replay approvals Oct 1, 2026

@datadog-prod-us1-5 datadog-prod-us1-5 Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bits Code Review: PASS

More details

The advisory exception affects only the Laravel 11 fixture while retaining blocking for every unlisted Composer advisory; the accompanying generated image references remain internally consistent.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Bits Code Review · Commit 0283ad3 · @DataDog review to ask questions

@vpellan vpellan changed the title [php] Fix Laravel builds, refresh image locks, and stabilize exception replay approvals [php] Fix Laravel 11 builds without refreshing shared images Oct 1, 2026

@bwoebi bwoebi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utils/build/docker/php/weblogs/laravel11x/composer.json is the file in this repo, why do you edit it via dockerfile instead of just adjusting the file itself?

@vpellan

vpellan commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

utils/build/docker/php/weblogs/laravel11x/composer.json is the file in this repo, why do you edit it via dockerfile instead of just adjusting the file itself?

Yes I made changes on that file but it started to scope-creep, so I wanted to come back to the original scope but codex decided to push commits to the branch mid-prompt... I'm still working on it

@vpellan

vpellan commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Updating utils/build/docker/php/weblogs/laravel11x/composer.json uncovered issues with the latest agent that required more work than simply updating composer.json. I wanted to avoid that but it's real issue, still I'm working on it

@vpellan vpellan changed the title [php] Fix Laravel 11 builds without refreshing shared images [php] Fix Laravel 11 builds and track client stats regression Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants