Skip to content

Commit 1f2e2b3

Browse files
authored
Merge branch 'master' into alejandro.gonzalez/APPSEC-61873-3
2 parents 19ae772 + 081af53 commit 1f2e2b3

520 files changed

Lines changed: 2442 additions & 1985 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.gitlab-ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -406,7 +406,7 @@ config-inversion-linter:
406406
needs: []
407407
script:
408408
- ./gradlew --version
409-
- ./gradlew logEnvVarUsages checkEnvironmentVariablesUsage checkConfigStrings
409+
- ./gradlew checkConfigurations
410410

411411
test_published_artifacts:
412412
extends: .gradle_build
Lines changed: 145 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,145 @@
1+
package datadog.gradle.plugin.config
2+
3+
import com.github.javaparser.StaticJavaParser
4+
import com.github.javaparser.ast.Modifier
5+
import com.github.javaparser.ast.body.FieldDeclaration
6+
import com.github.javaparser.ast.body.VariableDeclarator
7+
import com.github.javaparser.ast.expr.Expression
8+
import com.github.javaparser.ast.expr.MethodCallExpr
9+
import com.github.javaparser.ast.expr.NameExpr
10+
import com.github.javaparser.ast.expr.StringLiteralExpr
11+
import org.gradle.api.Action
12+
import org.gradle.api.GradleException
13+
import org.gradle.api.Task
14+
import org.gradle.api.provider.Provider
15+
import org.gradle.api.tasks.SourceSetOutput
16+
import java.io.File
17+
18+
/** Validates that all config definitions in the config directory are documented in supported-configurations.json. */
19+
internal class RegularConfigCheckAction(
20+
private val mainSourceSetOutput: Provider<Provider<SourceSetOutput>>,
21+
private val generatedClassName: Provider<String>,
22+
private val extension: SupportedTracerConfigurations
23+
) : Action<Task> {
24+
override fun execute(task: Task) {
25+
val repoRoot = task.project.rootProject.projectDir.toPath()
26+
val configDir = repoRoot.resolve("dd-trace-api/src/main/java/datadog/trace/api/config").toFile()
27+
28+
if (!configDir.exists()) {
29+
throw GradleException("Config directory not found: ${configDir.absolutePath}")
30+
}
31+
32+
val configFields = loadConfigFields(mainSourceSetOutput.get().get(), generatedClassName.get())
33+
val supported = configFields.supported
34+
val aliasMapping = configFields.aliasMapping
35+
36+
val violations = buildList {
37+
configDir.listFiles()?.forEach { file ->
38+
val fileName = file.name
39+
extractStringConstants(file).forEach eachConstant@{ (fieldName, entry) ->
40+
if (fieldName.endsWith("_DEFAULT")) return@eachConstant
41+
val normalized = normalize(entry.value)
42+
if (normalized !in supported && normalized !in aliasMapping) {
43+
add("$fileName:${entry.line} -> Config '${entry.value}' normalizes to '$normalized' " +
44+
"which is missing from '${extension.jsonFile.get()}'")
45+
}
46+
}
47+
}
48+
}
49+
50+
if (violations.isNotEmpty()) {
51+
task.logger.error("\nFound config definitions not in '${extension.jsonFile.get()}':")
52+
violations.forEach { task.logger.lifecycle(it) }
53+
throw GradleException("Undocumented Environment Variables found. Please add the above Environment Variables to '${extension.jsonFile.get()}'.")
54+
} else {
55+
task.logger.info("All config strings are present in '${extension.jsonFile.get()}'.")
56+
}
57+
}
58+
}
59+
60+
/**
61+
* Validates that every `.ddprof.` config key used as a primary key in `DatadogProfilerConfig`'s
62+
* static helpers also has its async-translated form (`profiling.ddprof.*` → `profiling.async.*`)
63+
* documented in `supported-configurations.json`.
64+
*/
65+
internal class ProfilingConfigCheckAction(
66+
private val mainSourceSetOutput: Provider<Provider<SourceSetOutput>>,
67+
private val generatedClassName: Provider<String>,
68+
private val extension: SupportedTracerConfigurations
69+
) : Action<Task> {
70+
override fun execute(task: Task) {
71+
val repoRoot = task.project.rootProject.projectDir.toPath()
72+
73+
val constantMap = extractStringConstants(
74+
repoRoot.resolve("dd-trace-api/src/main/java/datadog/trace/api/config/ProfilingConfig.java").toFile()
75+
)
76+
77+
val configFields = loadConfigFields(mainSourceSetOutput.get().get(), generatedClassName.get())
78+
val supported = configFields.supported
79+
val aliasMapping = configFields.aliasMapping
80+
81+
val ddprofConfigFile = repoRoot.resolve(
82+
"dd-java-agent/agent-profiling/profiling-ddprof/src/main/java/com/datadog/profiling/ddprof/DatadogProfilerConfig.java"
83+
).toFile()
84+
val cu = StaticJavaParser.parse(ddprofConfigFile)
85+
86+
val helperMethodNames = setOf("getBoolean", "getInteger", "getLong", "getString")
87+
val violations = mutableListOf<String>()
88+
89+
cu.findAll(MethodCallExpr::class.java).forEach { call ->
90+
if (call.scope.isPresent) return@forEach
91+
if (call.nameAsString !in helperMethodNames) return@forEach
92+
val args = call.arguments
93+
if (args.size < 2 || args[0] !is NameExpr || (args[0] as NameExpr).nameAsString != "configProvider") return@forEach
94+
95+
val primaryKeyEntry = resolveConstant(args[1], constantMap) ?: return@forEach
96+
checkDocumented(primaryKeyEntry, supported, aliasMapping, call, violations, extension)
97+
}
98+
99+
if (violations.isNotEmpty()) {
100+
violations.forEach { task.logger.error(it) }
101+
throw GradleException("Undocumented configs found in DatadogProfilerConfig. Please add the above to '${extension.jsonFile.get()}'.")
102+
} else {
103+
task.logger.info("All DatadogProfilerConfig configs are documented.")
104+
}
105+
}
106+
}
107+
108+
internal data class ConstantEntry(val value: String, val line: Int)
109+
110+
internal fun extractStringConstants(file: File): Map<String, ConstantEntry> {
111+
val map = mutableMapOf<String, ConstantEntry>()
112+
StaticJavaParser.parse(file).findAll(VariableDeclarator::class.java).forEach { varDecl ->
113+
val field = varDecl.parentNode.map { it as? FieldDeclaration }.orElse(null) ?: return@forEach
114+
if (field.hasModifiers(Modifier.Keyword.PUBLIC, Modifier.Keyword.STATIC, Modifier.Keyword.FINAL)
115+
&& varDecl.typeAsString == "String") {
116+
val init = varDecl.initializer.orElse(null) as? StringLiteralExpr ?: return@forEach
117+
val line = varDecl.range.map { it.begin.line }.orElse(-1)
118+
map[varDecl.nameAsString] = ConstantEntry(init.value, line)
119+
}
120+
}
121+
return map
122+
}
123+
124+
internal fun resolveConstant(expr: Expression?, constantMap: Map<String, ConstantEntry>): ConstantEntry? = when (expr) {
125+
is StringLiteralExpr -> ConstantEntry(expr.value, -1)
126+
is NameExpr -> constantMap[expr.nameAsString]
127+
else -> null
128+
}
129+
130+
// Only check the async-translated form produced by DatadogProfilerConfig.normalizeKey.
131+
internal fun checkDocumented(
132+
entry: ConstantEntry,
133+
supported: Set<String>,
134+
aliasMapping: Map<String, String>,
135+
call: MethodCallExpr,
136+
violations: MutableList<String>,
137+
extension: SupportedTracerConfigurations
138+
) {
139+
if (!entry.value.contains(".ddprof.")) return
140+
val asyncNormalized = normalize(entry.value.replace(".ddprof.", ".async."))
141+
if (asyncNormalized !in supported && asyncNormalized !in aliasMapping) {
142+
val callLine = call.range.map { it.begin.line }.orElse(-1)
143+
violations.add("ProfilingConfig.java:${entry.line} (DatadogProfilerConfig.java:$callLine) -> '${entry.value}' (async form) → '$asyncNormalized' is missing from '${extension.jsonFile.get()}'")
144+
}
145+
}

buildSrc/src/main/kotlin/datadog/gradle/plugin/config/ConfigInversionLinter.kt

Lines changed: 76 additions & 72 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,12 @@
11
package datadog.gradle.plugin.config
22

3-
import com.github.javaparser.ParserConfiguration
4-
import com.github.javaparser.StaticJavaParser
5-
import com.github.javaparser.ast.CompilationUnit
63
import com.github.javaparser.ast.Modifier
7-
import com.github.javaparser.ast.body.FieldDeclaration
8-
import com.github.javaparser.ast.body.VariableDeclarator
9-
import com.github.javaparser.ast.expr.StringLiteralExpr
104
import com.github.javaparser.ast.nodeTypes.NodeWithModifiers
115
import org.gradle.api.GradleException
126
import org.gradle.api.Plugin
137
import org.gradle.api.Project
8+
import org.gradle.api.Task
9+
import org.gradle.api.tasks.TaskProvider
1410
import org.gradle.api.tasks.SourceSet
1511
import org.gradle.api.tasks.SourceSetContainer
1612
import org.gradle.kotlin.dsl.getByType
@@ -20,23 +16,32 @@ import java.nio.file.Path
2016
class ConfigInversionLinter : Plugin<Project> {
2117
override fun apply(target: Project) {
2218
val extension = target.extensions.create("supportedTracerConfigurations", SupportedTracerConfigurations::class.java)
23-
registerLogEnvVarUsages(target, extension)
24-
registerCheckEnvironmentVariablesUsage(target)
25-
registerCheckConfigStringsTask(target, extension)
19+
val logEnvVarUsages = registerLogEnvVarUsages(target, extension)
20+
val checkEnvVarUsage = registerCheckEnvironmentVariablesUsage(target)
21+
val checkConfigStrings = registerCheckConfigStringsTask(target, extension)
22+
val checkInstrumenterModule = registerCheckInstrumenterModuleConfigurations(target, extension)
23+
val checkDecoratorAnalytics = registerCheckDecoratorAnalyticsConfigurations(target, extension)
24+
25+
target.tasks.register("checkConfigurations") {
26+
group = "verification"
27+
description = "Runs all config inversion validation checks"
28+
dependsOn(logEnvVarUsages, checkEnvVarUsage, checkConfigStrings, checkInstrumenterModule, checkDecoratorAnalytics)
29+
}
2630
}
2731
}
2832

2933
// Data class for fields from generated class
30-
private data class LoadedConfigFields(
34+
data class LoadedConfigFields(
3135
val supported: Set<String>,
32-
val aliasMapping: Map<String, String> = emptyMap()
36+
val aliasMapping: Map<String, String> = emptyMap(),
37+
val aliases: Map<String, List<String>> = emptyMap()
3338
)
3439

3540
// Cache for fields from generated class
36-
private var cachedConfigFields: LoadedConfigFields? = null
41+
internal var cachedConfigFields: LoadedConfigFields? = null
3742

3843
// Helper function to load fields from the generated class
39-
private fun loadConfigFields(
44+
internal fun loadConfigFields(
4045
mainSourceSetOutput: org.gradle.api.file.FileCollection,
4146
generatedClassName: String
4247
): LoadedConfigFields {
@@ -55,18 +60,20 @@ private fun loadConfigFields(
5560

5661
@Suppress("UNCHECKED_CAST")
5762
val aliasMappingMap = clazz.getField("ALIAS_MAPPING").get(null) as Map<String, String>
58-
LoadedConfigFields(supportedSet, aliasMappingMap)
63+
@Suppress("UNCHECKED_CAST")
64+
val aliasesMap = clazz.getField("ALIASES").get(null) as Map<String, List<String>>
65+
LoadedConfigFields(supportedSet, aliasMappingMap, aliasesMap)
5966
}.also { cachedConfigFields = it }
6067
}
6168
}
6269

6370
/** Registers `logEnvVarUsages` (scan for DD_/OTEL_ tokens and fail if unsupported). */
64-
private fun registerLogEnvVarUsages(target: Project, extension: SupportedTracerConfigurations) {
71+
private fun registerLogEnvVarUsages(target: Project, extension: SupportedTracerConfigurations): TaskProvider<Task> {
6572
val ownerPath = extension.configOwnerPath
6673
val generatedFile = extension.className
6774

6875
// token check that uses the generated class instead of JSON
69-
target.tasks.register("logEnvVarUsages") {
76+
return target.tasks.register("logEnvVarUsages") {
7077
group = "verification"
7178
description = "Scan Java files for DD_/OTEL_ tokens and fail if unsupported (using generated constants)"
7279

@@ -127,8 +134,8 @@ private fun registerLogEnvVarUsages(target: Project, extension: SupportedTracerC
127134
}
128135

129136
/** Registers `checkEnvironmentVariablesUsage` (forbid EnvironmentVariables.get(...)). */
130-
private fun registerCheckEnvironmentVariablesUsage(project: Project) {
131-
project.tasks.register("checkEnvironmentVariablesUsage") {
137+
private fun registerCheckEnvironmentVariablesUsage(project: Project): TaskProvider<Task> {
138+
return project.tasks.register("checkEnvironmentVariablesUsage") {
132139
group = "verification"
133140
description = "Scans src/main/java for direct usages of EnvironmentVariables.get(...)"
134141

@@ -166,19 +173,19 @@ private fun registerCheckEnvironmentVariablesUsage(project: Project) {
166173
}
167174

168175
// Helper functions for checking Config Strings
169-
private fun normalize(configValue: String) =
176+
internal fun normalize(configValue: String) =
170177
"DD_" + configValue.uppercase().replace("-", "_").replace(".", "_")
171178

172179
// Checking "public" "static" "final"
173-
private fun NodeWithModifiers<*>.hasModifiers(vararg mods: Modifier.Keyword) =
180+
internal fun NodeWithModifiers<*>.hasModifiers(vararg mods: Modifier.Keyword) =
174181
mods.all { hasModifier(it) }
175182

176183
/** Registers `checkConfigStrings` to validate config definitions against documented supported configurations. */
177-
private fun registerCheckConfigStringsTask(project: Project, extension: SupportedTracerConfigurations) {
184+
private fun registerCheckConfigStringsTask(project: Project, extension: SupportedTracerConfigurations): TaskProvider<Task> {
178185
val ownerPath = extension.configOwnerPath
179186
val generatedFile = extension.className
180187

181-
project.tasks.register("checkConfigStrings") {
188+
return project.tasks.register("checkConfigStrings") {
182189
group = "verification"
183190
description = "Validates that all config definitions in `dd-trace-api/src/main/java/datadog/trace/api/config` exist in `metadata/supported-configurations.json`"
184191

@@ -190,61 +197,58 @@ private fun registerCheckConfigStringsTask(project: Project, extension: Supporte
190197
}
191198
inputs.files(mainSourceSetOutput)
192199

193-
doLast {
194-
val repoRoot: Path = project.rootProject.projectDir.toPath()
195-
val configDir = repoRoot.resolve("dd-trace-api/src/main/java/datadog/trace/api/config").toFile()
200+
doLast("regular-config-check", RegularConfigCheckAction(mainSourceSetOutput, generatedFile, extension))
201+
doLast("profiling-config-check", ProfilingConfigCheckAction(mainSourceSetOutput, generatedFile, extension))
202+
}
203+
}
196204

197-
if (!configDir.exists()) {
198-
throw GradleException("Config directory not found: ${configDir.absolutePath}")
199-
}
200205

201-
val configFields = loadConfigFields(mainSourceSetOutput.get().get(), generatedFile.get())
202-
val supported = configFields.supported
203-
val aliasMapping = configFields.aliasMapping
206+
/** Registers `checkInstrumenterModuleConfigurations` to verify each InstrumenterModule's integration name has proper entries in SUPPORTED and ALIASES. */
207+
private fun registerCheckInstrumenterModuleConfigurations(project: Project, extension: SupportedTracerConfigurations): TaskProvider<CheckInstrumenterModuleConfigTask> {
208+
val ownerPath = extension.configOwnerPath
209+
val generatedFile = extension.className
204210

205-
var parserConfig = ParserConfiguration()
206-
parserConfig.setLanguageLevel(ParserConfiguration.LanguageLevel.JAVA_8)
211+
return project.tasks.register("checkInstrumenterModuleConfigurations", CheckInstrumenterModuleConfigTask::class.java) {
212+
group = "verification"
213+
description = "Validates that InstrumenterModule integration names have corresponding entries in SUPPORTED and ALIASES"
207214

208-
StaticJavaParser.setConfiguration(parserConfig)
215+
mainSourceSetOutput.from(ownerPath.map {
216+
project.project(it)
217+
.extensions.getByType<SourceSetContainer>()
218+
.named(SourceSet.MAIN_SOURCE_SET_NAME)
219+
.map { main -> main.output }
220+
})
221+
instrumentationFiles.from(project.fileTree(project.rootProject.projectDir) {
222+
include("dd-java-agent/instrumentation/**/src/main/java/**/*.java")
223+
})
224+
generatedClassName.set(generatedFile)
225+
errorHeader.set("\nFound InstrumenterModule integration names with missing SUPPORTED/ALIASES entries:")
226+
errorMessage.set("InstrumenterModule integration names are missing from SUPPORTED or ALIASES in '${extension.jsonFile.get()}'.")
227+
successMessage.set("All InstrumenterModule integration names have proper SUPPORTED and ALIASES entries.")
228+
}
229+
}
209230

210-
val violations = buildList {
211-
configDir.listFiles()?.forEach { file ->
212-
val fileName = file.name
213-
val cu: CompilationUnit = StaticJavaParser.parse(file)
214-
215-
cu.findAll(VariableDeclarator::class.java).forEach { varDecl ->
216-
varDecl.parentNode
217-
.map { it as? FieldDeclaration }
218-
.ifPresent { field ->
219-
if (field.hasModifiers(Modifier.Keyword.PUBLIC, Modifier.Keyword.STATIC, Modifier.Keyword.FINAL) &&
220-
varDecl.typeAsString == "String") {
221-
222-
val fieldName = varDecl.nameAsString
223-
if (fieldName.endsWith("_DEFAULT")) return@ifPresent
224-
val init = varDecl.initializer.orElse(null) ?: return@ifPresent
225-
226-
if (init !is StringLiteralExpr) return@ifPresent
227-
val rawValue = init.value
228-
229-
val normalized = normalize(rawValue)
230-
if (normalized !in supported && normalized !in aliasMapping) {
231-
val line = varDecl.range.map { it.begin.line }.orElse(1)
232-
add("$fileName:$line -> Config '$rawValue' normalizes to '$normalized' " +
233-
"which is missing from '${extension.jsonFile.get()}'")
234-
}
235-
}
236-
}
237-
}
238-
}
239-
}
231+
/** Registers `checkDecoratorAnalyticsConfigurations` to verify each BaseDecorator subclass's instrumentationNames have proper analytics entries in SUPPORTED and ALIASES. */
232+
private fun registerCheckDecoratorAnalyticsConfigurations(project: Project, extension: SupportedTracerConfigurations): TaskProvider<CheckDecoratorAnalyticsConfigTask> {
233+
val ownerPath = extension.configOwnerPath
234+
val generatedFile = extension.className
240235

241-
if (violations.isNotEmpty()) {
242-
logger.error("\nFound config definitions not in '${extension.jsonFile.get()}':")
243-
violations.forEach { logger.lifecycle(it) }
244-
throw GradleException("Undocumented Environment Variables found. Please add the above Environment Variables to '${extension.jsonFile.get()}'.")
245-
} else {
246-
logger.info("All config strings are present in '${extension.jsonFile.get()}'.")
247-
}
248-
}
236+
return project.tasks.register("checkDecoratorAnalyticsConfigurations", CheckDecoratorAnalyticsConfigTask::class.java) {
237+
group = "verification"
238+
description = "Validates that Decorator instrumentationNames have corresponding analytics entries in SUPPORTED and ALIASES"
239+
240+
mainSourceSetOutput.from(ownerPath.map {
241+
project.project(it)
242+
.extensions.getByType<SourceSetContainer>()
243+
.named(SourceSet.MAIN_SOURCE_SET_NAME)
244+
.map { main -> main.output }
245+
})
246+
instrumentationFiles.from(project.fileTree(project.rootProject.projectDir) {
247+
include("dd-java-agent/instrumentation/**/src/main/java/**/*.java")
248+
})
249+
generatedClassName.set(generatedFile)
250+
errorHeader.set("\nFound Decorator instrumentationNames with missing analytics SUPPORTED/ALIASES entries:")
251+
errorMessage.set("Decorator instrumentationNames are missing analytics entries from SUPPORTED or ALIASES in '${extension.jsonFile.get()}'.")
252+
successMessage.set("All Decorator instrumentationNames have proper analytics SUPPORTED and ALIASES entries.")
249253
}
250254
}

0 commit comments

Comments
 (0)