-
Notifications
You must be signed in to change notification settings - Fork 292
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add trace injection for prepared statements in Postgres #7940
base: master
Are you sure you want to change the base?
Conversation
BenchmarksStartupParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 51 metrics, 12 unstable metrics. Startup time reports for insecure-bankgantt
title insecure-bank - global startup overhead: candidate=1.43.0-SNAPSHOT~f2f7b8f01c, baseline=1.43.0-SNAPSHOT~270a82d63a
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.101 s) : 0, 1100833
Total [baseline] (8.65 s) : 0, 8650359
Agent [candidate] (1.091 s) : 0, 1091369
Total [candidate] (8.659 s) : 0, 8659444
section iast
Agent [baseline] (1.227 s) : 0, 1227105
Total [baseline] (9.243 s) : 0, 9243060
Agent [candidate] (1.226 s) : 0, 1225703
Total [candidate] (9.284 s) : 0, 9284373
section iast_HARDCODED_SECRET_DISABLED
Agent [baseline] (1.231 s) : 0, 1231252
Total [baseline] (9.22 s) : 0, 9219774
Agent [candidate] (1.219 s) : 0, 1219352
Total [candidate] (9.224 s) : 0, 9223640
section iast_TELEMETRY_OFF
Agent [baseline] (1.215 s) : 0, 1215356
Total [baseline] (9.197 s) : 0, 9197239
Agent [candidate] (1.216 s) : 0, 1215562
Total [candidate] (9.199 s) : 0, 9199370
gantt
title insecure-bank - break down per module: candidate=1.43.0-SNAPSHOT~f2f7b8f01c, baseline=1.43.0-SNAPSHOT~270a82d63a
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (698.608 ms) : 0, 698608
BytebuddyAgent [candidate] (693.998 ms) : 0, 693998
GlobalTracer [baseline] (321.282 ms) : 0, 321282
GlobalTracer [candidate] (318.076 ms) : 0, 318076
AppSec [baseline] (55.0 ms) : 0, 55000
AppSec [candidate] (54.779 ms) : 0, 54779
Remote Config [baseline] (693.488 µs) : 0, 693
Remote Config [candidate] (702.259 µs) : 0, 702
Telemetry [baseline] (11.36 ms) : 0, 11360
Telemetry [candidate] (10.015 ms) : 0, 10015
section iast
BytebuddyAgent [baseline] (815.76 ms) : 0, 815760
BytebuddyAgent [candidate] (814.531 ms) : 0, 814531
GlobalTracer [baseline] (309.701 ms) : 0, 309701
GlobalTracer [candidate] (308.905 ms) : 0, 308905
AppSec [baseline] (56.739 ms) : 0, 56739
AppSec [candidate] (58.006 ms) : 0, 58006
Remote Config [baseline] (622.271 µs) : 0, 622
Remote Config [candidate] (644.695 µs) : 0, 645
Telemetry [baseline] (7.573 ms) : 0, 7573
Telemetry [candidate] (7.632 ms) : 0, 7632
IAST [baseline] (22.822 ms) : 0, 22822
IAST [candidate] (22.118 ms) : 0, 22118
section iast_HARDCODED_SECRET_DISABLED
BytebuddyAgent [baseline] (820.998 ms) : 0, 820998
BytebuddyAgent [candidate] (809.961 ms) : 0, 809961
GlobalTracer [baseline] (309.111 ms) : 0, 309111
GlobalTracer [candidate] (307.785 ms) : 0, 307785
AppSec [baseline] (57.952 ms) : 0, 57952
AppSec [candidate] (57.158 ms) : 0, 57158
Remote Config [baseline] (642.387 µs) : 0, 642
Remote Config [candidate] (1.435 ms) : 0, 1435
Telemetry [baseline] (7.532 ms) : 0, 7532
Telemetry [candidate] (7.563 ms) : 0, 7563
IAST [baseline] (21.067 ms) : 0, 21067
IAST [candidate] (21.651 ms) : 0, 21651
section iast_TELEMETRY_OFF
BytebuddyAgent [baseline] (807.012 ms) : 0, 807012
BytebuddyAgent [candidate] (807.215 ms) : 0, 807215
GlobalTracer [baseline] (307.465 ms) : 0, 307465
GlobalTracer [candidate] (307.345 ms) : 0, 307345
AppSec [baseline] (57.829 ms) : 0, 57829
AppSec [candidate] (57.05 ms) : 0, 57050
Remote Config [baseline] (622.86 µs) : 0, 623
Remote Config [candidate] (622.809 µs) : 0, 623
Telemetry [baseline] (7.436 ms) : 0, 7436
Telemetry [candidate] (7.399 ms) : 0, 7399
IAST [baseline] (21.19 ms) : 0, 21190
IAST [candidate] (22.152 ms) : 0, 22152
Startup time reports for petclinicgantt
title petclinic - global startup overhead: candidate=1.43.0-SNAPSHOT~f2f7b8f01c, baseline=1.43.0-SNAPSHOT~270a82d63a
dateFormat X
axisFormat %s
section tracing
Agent [baseline] (1.096 s) : 0, 1095681
Total [baseline] (10.477 s) : 0, 10476940
Agent [candidate] (1.089 s) : 0, 1088839
Total [candidate] (10.462 s) : 0, 10462011
section appsec
Agent [baseline] (1.226 s) : 0, 1225798
Total [baseline] (10.755 s) : 0, 10755025
Agent [candidate] (1.232 s) : 0, 1232159
Total [candidate] (10.72 s) : 0, 10719984
section iast
Agent [baseline] (1.217 s) : 0, 1217442
Total [baseline] (10.93 s) : 0, 10929890
Agent [candidate] (1.22 s) : 0, 1220289
Total [candidate] (10.977 s) : 0, 10977070
section profiling
Agent [baseline] (1.298 s) : 0, 1297890
Total [baseline] (10.83 s) : 0, 10830315
Agent [candidate] (1.289 s) : 0, 1288804
Total [candidate] (10.829 s) : 0, 10828993
gantt
title petclinic - break down per module: candidate=1.43.0-SNAPSHOT~f2f7b8f01c, baseline=1.43.0-SNAPSHOT~270a82d63a
dateFormat X
axisFormat %s
section tracing
BytebuddyAgent [baseline] (696.001 ms) : 0, 696001
BytebuddyAgent [candidate] (692.1 ms) : 0, 692100
GlobalTracer [baseline] (319.576 ms) : 0, 319576
GlobalTracer [candidate] (317.742 ms) : 0, 317742
AppSec [baseline] (54.944 ms) : 0, 54944
AppSec [candidate] (54.521 ms) : 0, 54521
Remote Config [baseline] (706.601 µs) : 0, 707
Remote Config [candidate] (680.6 µs) : 0, 681
Telemetry [baseline] (10.727 ms) : 0, 10727
Telemetry [candidate] (10.041 ms) : 0, 10041
section appsec
BytebuddyAgent [baseline] (711.089 ms) : 0, 711089
BytebuddyAgent [candidate] (714.567 ms) : 0, 714567
GlobalTracer [baseline] (315.499 ms) : 0, 315499
GlobalTracer [candidate] (316.896 ms) : 0, 316896
AppSec [baseline] (167.432 ms) : 0, 167432
AppSec [candidate] (168.483 ms) : 0, 168483
Remote Config [baseline] (634.844 µs) : 0, 635
Remote Config [candidate] (644.472 µs) : 0, 644
Telemetry [baseline] (7.532 ms) : 0, 7532
Telemetry [candidate] (7.864 ms) : 0, 7864
IAST [baseline] (19.741 ms) : 0, 19741
IAST [candidate] (19.749 ms) : 0, 19749
section iast
BytebuddyAgent [baseline] (809.118 ms) : 0, 809118
BytebuddyAgent [candidate] (813.611 ms) : 0, 813611
GlobalTracer [baseline] (307.313 ms) : 0, 307313
GlobalTracer [candidate] (306.244 ms) : 0, 306244
AppSec [baseline] (56.443 ms) : 0, 56443
AppSec [candidate] (57.855 ms) : 0, 57855
Remote Config [baseline] (636.831 µs) : 0, 637
Remote Config [candidate] (600.484 µs) : 0, 600
Telemetry [baseline] (8.403 ms) : 0, 8403
Telemetry [candidate] (7.392 ms) : 0, 7392
IAST [baseline] (21.769 ms) : 0, 21769
IAST [candidate] (20.77 ms) : 0, 20770
section profiling
BytebuddyAgent [baseline] (691.579 ms) : 0, 691579
BytebuddyAgent [candidate] (687.483 ms) : 0, 687483
GlobalTracer [baseline] (404.152 ms) : 0, 404152
GlobalTracer [candidate] (401.52 ms) : 0, 401520
AppSec [baseline] (55.652 ms) : 0, 55652
AppSec [candidate] (55.358 ms) : 0, 55358
Remote Config [baseline] (688.028 µs) : 0, 688
Remote Config [candidate] (684.693 µs) : 0, 685
Telemetry [baseline] (11.871 ms) : 0, 11871
Telemetry [candidate] (13.481 ms) : 0, 13481
ProfilingAgent [baseline] (94.672 ms) : 0, 94672
ProfilingAgent [candidate] (91.096 ms) : 0, 91096
Profiling [baseline] (94.695 ms) : 0, 94695
Profiling [candidate] (91.119 ms) : 0, 91119
LoadParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 11 metrics, 15 unstable metrics. DacapoParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 11 metrics, 1 unstable metrics. Execution time for tomcatgantt
title tomcat - execution time [CI 0.99] : candidate=1.43.0-SNAPSHOT~f2f7b8f01c, baseline=1.43.0-SNAPSHOT~270a82d63a
dateFormat X
axisFormat %s
section baseline
no_agent (1.466 ms) : 1454, 1477
. : milestone, 1466,
appsec (2.346 ms) : 2304, 2387
. : milestone, 2346,
iast (2.08 ms) : 2028, 2132
. : milestone, 2080,
iast_GLOBAL (2.133 ms) : 2080, 2186
. : milestone, 2133,
profiling (1.951 ms) : 1909, 1993
. : milestone, 1951,
tracing (1.932 ms) : 1891, 1972
. : milestone, 1932,
section candidate
no_agent (1.464 ms) : 1453, 1475
. : milestone, 1464,
appsec (2.336 ms) : 2295, 2377
. : milestone, 2336,
iast (2.092 ms) : 2039, 2144
. : milestone, 2092,
iast_GLOBAL (2.123 ms) : 2070, 2175
. : milestone, 2123,
profiling (2.44 ms) : 2249, 2630
. : milestone, 2440,
tracing (1.92 ms) : 1880, 1959
. : milestone, 1920,
Execution time for biojavagantt
title biojava - execution time [CI 0.99] : candidate=1.43.0-SNAPSHOT~f2f7b8f01c, baseline=1.43.0-SNAPSHOT~270a82d63a
dateFormat X
axisFormat %s
section baseline
no_agent (14.935 s) : 14935000, 14935000
. : milestone, 14935000,
appsec (15.014 s) : 15014000, 15014000
. : milestone, 15014000,
iast (18.6 s) : 18600000, 18600000
. : milestone, 18600000,
iast_GLOBAL (18.243 s) : 18243000, 18243000
. : milestone, 18243000,
profiling (15.469 s) : 15469000, 15469000
. : milestone, 15469000,
tracing (14.98 s) : 14980000, 14980000
. : milestone, 14980000,
section candidate
no_agent (14.886 s) : 14886000, 14886000
. : milestone, 14886000,
appsec (14.954 s) : 14954000, 14954000
. : milestone, 14954000,
iast (18.766 s) : 18766000, 18766000
. : milestone, 18766000,
iast_GLOBAL (18.03 s) : 18030000, 18030000
. : milestone, 18030000,
profiling (14.889 s) : 14889000, 14889000
. : milestone, 14889000,
tracing (14.873 s) : 14873000, 14873000
. : milestone, 14873000,
|
df70fd0
to
2a45328
Compare
@@ -107,6 +107,7 @@ public class InstrumentationTags { | |||
public static final String TWILIO_STATUS = "twilio.status"; | |||
public static final String TWILIO_PARENT_SID = "twilio.parentSid"; | |||
public static final String DBM_TRACE_INJECTED = "_dd.dbm_trace_injected"; | |||
public static final String TIME_MS = "dd.instrumentation.time_ms"; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
TIME_MS
is too vague as a constant name, it should be INSTRUMENTATION_TIME_MS
} | ||
final String traceParent = DECORATE.traceParent(span, priority); | ||
if (traceParent == null | ||
|| !traceParent.matches("^00-[a-f0-9]{32}-[a-f0-9]{16}-[a-f0-9]{2}$")) { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this can be precompiled since in this way it looks pretty inefficient
} finally { | ||
span.setTag(DBM_TRACE_INJECTED, true); | ||
final long elapsed = System.currentTimeMillis() - startTime; | ||
span.setTag("dd.instrumentation.time_ms", elapsed); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this should be in a constant (i.e InstrumentationTags
can be a good place for it)
} catch (SQLException e) { | ||
throw e; | ||
} | ||
} catch (Exception e) { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This can be widen to Throwable
throw e; | ||
} | ||
} catch (Exception e) { | ||
log.debug( |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If the statement execution above fails I think that will be catched by the SQLException
case. Is this log never printed?
try (Statement statement = connection.createStatement()) { | ||
statement.execute(sql.toString()); | ||
} catch (SQLException e) { | ||
throw e; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Do you really want to throw this by our code? I think it should silently swapped and something printed
What Does This Do
Adding trace injection for prepared statements in Postgres.
Motivation
90% of APM/DBM correlation attempts for Postgres involve prepared statements, but we can't retrieve execution plans for these. Injecting trace context into prepared statements will greatly improve the success rate.
Additional Notes
It's not possible to inject trace context into comments for prepared statements. Instead, the tracer sets the application_name with the trace parent, which the Agent samples via
pg_stat_activity.application_name
, and the backend parses.Disadvantages:
These drawbacks will be noted in the public documentation.
The feature is disabled by default and can be enabled by setting
dd.dbm.trace_prepared_statements
totrue
.Contributor Checklist
type:
and (comp:
orinst:
) labels in addition to any usefull labelsclose
,fix
or any linking keywords when referencing an issue.Use
solves
instead, and assign the PR milestone to the issueJira ticket: [PROJ-IDENT]