Commit 428b50e
Add server.request.body.files_content AppSec address for Vert.x 3/4/5 (#11724)
feat(appsec): fire server.request.body.files_content for Vert.x 3/4/5
Extends RoutingContextFilenamesAdvice in vertx-web-3.4, vertx-web-4.0,
and vertx-web-5.0 to also collect and fire the requestFilesContent()
IG callback alongside the existing requestFilesFilenames() callback.
Content is read from disk using FileInputStream and MultipartContentDecoder
since Vert.x BodyHandler always persists uploads to disk. The filenames
callback fires first; the content callback only fires if filenames did
not trigger a block (sequential guard).
Muzzle references are updated to include uploadedFileName() and
contentType() on FileUpload. Tests enable testBodyFilesContent() for
all three Vert.x versions.
fix(appsec): use Vert.x FileUpload.charSet() when decoding file content
FileUpload.contentType() in Vert.x returns only the MIME type without
the charset parameter. charSet() exposes it separately. Combine both
into a full content-type string before passing to
MultipartContentDecoder.readInputStream so extractCharset finds the
declared charset instead of falling back to the JVM default.
Add charSet() to FILE_UPLOAD_REF muzzle references in all three
Vert.x modules.
fix(appsec): extract FileUploadHelper to fix muzzle validation for Vert.x 3/4/5
Private static helpers in @advice classes generate INVOKESTATIC references to
the advice class itself. Muzzle resolves the advice class by name and validates
all its INVOKESTATIC targets against the library classpath, which does not
contain our advice classes, causing "Missing class" failures.
Extract readUploadContent and commitBlockingResponse into FileUploadHelper per
module and declare each in helperClassNames() so ByteBuddy injects them into
the target classloader and muzzle validates their references normally.
fix: make FileUploadHelper public and fix max files limit test for Vert.x 3/4/5
Helper classes injected via helperClassNames() are loaded into the app
classloader. When package-private, they cause IllegalAccessError from
instrumented classes in different packages within the same unnamed module.
The max files limit test also needed an override because Vert.x 3.4 returns
fileUploads() as a HashSet, whose iteration order depends on identity hash codes.
Adding helperClassNames() shifts object allocation counts and therefore hash
codes, changing which file is excluded. The override checks the count of
inspected files instead of which specific file was excluded.
style: replace em-dashes with colons in test comments
fix: skip ordering-dependent max files limit test for Vert.x HashSet
fileUploads() returns a HashSet in Vert.x so iteration order is JVM-
version-dependent. Add testBodyFilesContentOrdering() flag (defaults
true) to HttpServerTest to allow skipping the specific-file assertion.
Vert.x subclasses return false and add a count-based test instead.
fix: skip files_content test in VertxRxCircuitBreakerHttpServerForkedTest
The circuit breaker test server does not configure BodyHandler for the
multipart endpoint, so fileUploads() is never populated and the files_content
instrumentation does not fire. Consistent with the existing testBodyFilenames()
override in the same class.
Co-authored-by: devflow.devflow-routing-intake <devflow.devflow-routing-intake@kubernetes.us1.ddbuild.io>1 parent b848caf commit 428b50e
15 files changed
Lines changed: 467 additions & 66 deletions
File tree
- dd-java-agent
- instrumentation-testing/src/main/groovy/datadog/trace/agent/test/base
- instrumentation/vertx
- vertx-rx-3.5/src/test/groovy/server
- vertx-web
- vertx-web-3.4/src
- main/java/datadog/trace/instrumentation/vertx_3_4/server
- test/groovy/server
- vertx-web-4.0/src
- latestDepTest/groovy/server
- main/java/datadog/trace/instrumentation/vertx_4_0/server
- test/groovy/server
- vertx-web-5.0/src
- main/java/datadog/trace/instrumentation/vertx_5_0/server
- test/groovy/server
Lines changed: 6 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
387 | 387 | | |
388 | 388 | | |
389 | 389 | | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
390 | 395 | | |
391 | 396 | | |
392 | 397 | | |
| |||
1767 | 1772 | | |
1768 | 1773 | | |
1769 | 1774 | | |
1770 | | - | |
| 1775 | + | |
1771 | 1776 | | |
1772 | 1777 | | |
1773 | 1778 | | |
| |||
Lines changed: 5 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
47 | 52 | | |
48 | 53 | | |
49 | 54 | | |
| |||
Lines changed: 51 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
Lines changed: 37 additions & 21 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
6 | 5 | | |
7 | 6 | | |
8 | | - | |
| 7 | + | |
9 | 8 | | |
10 | 9 | | |
11 | 10 | | |
| |||
38 | 37 | | |
39 | 38 | | |
40 | 39 | | |
41 | | - | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
42 | 54 | | |
43 | 55 | | |
44 | | - | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
45 | 60 | | |
46 | 61 | | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
47 | 70 | | |
48 | | - | |
49 | | - | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
50 | 76 | | |
51 | 77 | | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | | - | |
| 78 | + | |
56 | 79 | | |
57 | 80 | | |
58 | 81 | | |
59 | | - | |
60 | | - | |
61 | | - | |
62 | | - | |
63 | | - | |
64 | | - | |
65 | | - | |
66 | | - | |
67 | | - | |
68 | | - | |
69 | | - | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
70 | 86 | | |
71 | 87 | | |
72 | 88 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
21 | 24 | | |
22 | 25 | | |
23 | 26 | | |
24 | 27 | | |
25 | 28 | | |
26 | 29 | | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
27 | 35 | | |
28 | 36 | | |
29 | 37 | | |
| |||
Lines changed: 42 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
3 | 4 | | |
| 5 | + | |
4 | 6 | | |
5 | 7 | | |
6 | 8 | | |
| |||
10 | 12 | | |
11 | 13 | | |
12 | 14 | | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
13 | 19 | | |
14 | 20 | | |
15 | 21 | | |
| |||
87 | 93 | | |
88 | 94 | | |
89 | 95 | | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
90 | 132 | | |
91 | 133 | | |
92 | 134 | | |
| |||
Lines changed: 42 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
3 | 4 | | |
| 5 | + | |
4 | 6 | | |
5 | 7 | | |
6 | 8 | | |
| |||
10 | 12 | | |
11 | 13 | | |
12 | 14 | | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
13 | 19 | | |
14 | 20 | | |
15 | 21 | | |
| |||
82 | 88 | | |
83 | 89 | | |
84 | 90 | | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
85 | 127 | | |
86 | 128 | | |
87 | 129 | | |
| |||
Lines changed: 51 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
0 commit comments