Skip to content

ci(appsec): fix ddwaf circular import [backport 2.20]#12103

Merged
Yun-Kim merged 1 commit into
2.20from
backport-12013-to-2.20
Jan 27, 2025
Merged

ci(appsec): fix ddwaf circular import [backport 2.20]#12103
Yun-Kim merged 1 commit into
2.20from
backport-12013-to-2.20

Conversation

@github-actions

@github-actions github-actions Bot commented Jan 27, 2025

Copy link
Copy Markdown
Contributor

Backport 67e1c46 from #12013 to 2.20.

Fix the following CI failures: https://gitlab.ddbuild.io/DataDog/apm-reliability/dd-trace-py/-/jobs/774636553

Reproduction:

from ddtrace.appsec._metrics import _set_waf_init_metric

The fix here is to avoid importing ddwaf from ddtrace.appsec._processor in ddtrace.appsec._metrics. Instead we can import ddwaf directly from ddtrace.appsec._ddwaf.

This issue does not occur if the ddtrace.appsec._processor module is imported before ddtrace.appsec._metrics. This is why we do not see this error in most of our appsec tests. However the order of imports is not guaranteed by the slots check. This explains the flakiness in this job.

Checklist

  • PR author has checked that all the criteria below are met
  • The PR description includes an overview of the change
  • The PR description articulates the motivation for the change
  • The change includes tests OR the PR description describes a testing strategy
  • The PR description notes risks associated with the change, if any
  • Newly-added code is easy to change
  • The change follows the library release note guidelines
  • The change includes or references documentation updates if necessary
  • Backport labels are set (if applicable)

Reviewer Checklist

  • Reviewer has checked that all the criteria below are met
  • Title is accurate
  • All changes are related to the pull request's stated goal
  • Avoids breaking API changes
  • Testing strategy adequately addresses listed risks
  • Newly-added code is easy to change
  • Release note makes sense to a user of the library
  • If necessary, author has acknowledged and discussed the performance implications of this PR as reported in the benchmarks PR comment
  • Backport labels are set in a manner that is consistent with the release branch maintenance policy

Fix the following CI failures:
https://gitlab.ddbuild.io/DataDog/apm-reliability/dd-trace-py/-/jobs/774636553

Reproduction:
```
from ddtrace.appsec._metrics import _set_waf_init_metric
```

- `ddtrace/appsec/_metrics` defines
[_set_waf_init_metric](https://github.com/DataDog/dd-trace-py/blob/130b69b367e22311fa5fea7e3cc0910396e968c4/ddtrace/appsec/_metrics.py#L48-L49)
- `ddtrace/appsec/_metrics` imports
[ddtrace.appsec._proccessors](https://github.com/DataDog/dd-trace-py/blob/130b69b367e22311fa5fea7e3cc0910396e968c4/ddtrace/appsec/_metrics.py#L4-L5)
- `ddtrace.appsec._proccessors` imports
[_set_waf_init_metric](https://github.com/DataDog/dd-trace-py/blob/130b69b367e22311fa5fea7e3cc0910396e968c4/ddtrace/appsec/_processor.py#L443-L444)
- Boom: Circular import

The fix here is to avoid importing `ddwaf` from
`ddtrace.appsec._processor` in `ddtrace.appsec._metrics`. Instead we can
import ddwaf directly from `ddtrace.appsec._ddwaf`.

This issue does not occur if the `ddtrace.appsec._processor` module is
imported before `ddtrace.appsec._metrics`. This is why we do not see
this error in most of our appsec tests. However the order of imports is
not guaranteed by the slots check. This explains the flakiness in this
job.

## Checklist
- [x] PR author has checked that all the criteria below are met
- The PR description includes an overview of the change
- The PR description articulates the motivation for the change
- The change includes tests OR the PR description describes a testing
strategy
- The PR description notes risks associated with the change, if any
- Newly-added code is easy to change
- The change follows the [library release note
guidelines](https://ddtrace.readthedocs.io/en/stable/releasenotes.html)
- The change includes or references documentation updates if necessary
- Backport labels are set (if
[applicable](https://ddtrace.readthedocs.io/en/latest/contributing.html#backporting))

## Reviewer Checklist
- [x] Reviewer has checked that all the criteria below are met
- Title is accurate
- All changes are related to the pull request's stated goal
- Avoids breaking
[API](https://ddtrace.readthedocs.io/en/stable/versioning.html#interfaces)
changes
- Testing strategy adequately addresses listed risks
- Newly-added code is easy to change
- Release note makes sense to a user of the library
- If necessary, author has acknowledged and discussed the performance
implications of this PR as reported in the benchmarks PR comment
- Backport labels are set in a manner that is consistent with the
[release branch maintenance
policy](https://ddtrace.readthedocs.io/en/latest/contributing.html#backporting)

(cherry picked from commit 67e1c46)
@github-actions github-actions Bot requested a review from a team as a code owner January 27, 2025 16:25
@github-actions github-actions Bot added the changelog/no-changelog A changelog entry is not required for this PR. label Jan 27, 2025
@Yun-Kim Yun-Kim added changelog/no-changelog A changelog entry is not required for this PR. and removed changelog/no-changelog A changelog entry is not required for this PR. labels Jan 27, 2025
@Yun-Kim Yun-Kim closed this Jan 27, 2025
@Yun-Kim Yun-Kim reopened this Jan 27, 2025
@Yun-Kim Yun-Kim enabled auto-merge (squash) January 27, 2025 16:26
@github-actions

Copy link
Copy Markdown
Contributor Author

CODEOWNERS have been resolved as:

ddtrace/appsec/_metrics.py                                              @DataDog/asm-python

@pr-commenter

pr-commenter Bot commented Jan 27, 2025

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2025-01-27 17:05:40

Comparing candidate commit b3fbaa5 in PR branch backport-12013-to-2.20 with baseline commit fe4d74a in branch 2.20.

Found 0 performance improvements and 0 performance regressions! Performance is the same for 394 metrics, 2 unstable metrics.

@Yun-Kim Yun-Kim merged commit 3ff00cc into 2.20 Jan 27, 2025
@Yun-Kim Yun-Kim deleted the backport-12013-to-2.20 branch January 27, 2025 19:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

changelog/no-changelog A changelog entry is not required for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants