-
Notifications
You must be signed in to change notification settings - Fork 476
ci(iast): fix flaky test #15749
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ci(iast): fix flaky test #15749
Conversation
|
|
Performance SLOsComparing candidate avara1986/APPSEC-60297_reduce_flakyness (341f33e) with baseline main (f8b72bc) 📈 Performance Regressions (3 suites)📈 iastaspects - 118/118✅ add_aspectTime: ✅ 17.898µs (SLO: <20.000µs 📉 -10.5%) vs baseline: 📈 +20.2% Memory: ✅ 42.939MB (SLO: <43.250MB 🟡 -0.7%) vs baseline: +4.6% ✅ add_inplace_aspectTime: ✅ 14.846µs (SLO: <20.000µs 📉 -25.8%) vs baseline: -0.3% Memory: ✅ 42.979MB (SLO: <43.250MB 🟡 -0.6%) vs baseline: +4.7% ✅ add_inplace_noaspectTime: ✅ 0.339µs (SLO: <10.000µs 📉 -96.6%) vs baseline: +0.7% Memory: ✅ 42.998MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +5.0% ✅ add_noaspectTime: ✅ 0.548µs (SLO: <10.000µs 📉 -94.5%) vs baseline: +1.0% Memory: ✅ 42.979MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.9% ✅ bytearray_aspectTime: ✅ 17.958µs (SLO: <30.000µs 📉 -40.1%) vs baseline: ~same Memory: ✅ 43.057MB (SLO: <43.500MB 🟡 -1.0%) vs baseline: +5.1% ✅ bytearray_extend_aspectTime: ✅ 23.902µs (SLO: <30.000µs 📉 -20.3%) vs baseline: ~same Memory: ✅ 42.979MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.9% ✅ bytearray_extend_noaspectTime: ✅ 2.746µs (SLO: <10.000µs 📉 -72.5%) vs baseline: ~same Memory: ✅ 42.920MB (SLO: <43.500MB 🟡 -1.3%) vs baseline: +5.0% ✅ bytearray_noaspectTime: ✅ 1.468µs (SLO: <10.000µs 📉 -85.3%) vs baseline: -0.1% Memory: ✅ 42.959MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.7% ✅ bytes_aspectTime: ✅ 16.633µs (SLO: <20.000µs 📉 -16.8%) vs baseline: -0.1% Memory: ✅ 42.979MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.8% ✅ bytes_noaspectTime: ✅ 1.425µs (SLO: <10.000µs 📉 -85.8%) vs baseline: +1.4% Memory: ✅ 43.018MB (SLO: <43.500MB 🟡 -1.1%) vs baseline: +5.0% ✅ bytesio_aspectTime: ✅ 55.366µs (SLO: <70.000µs 📉 -20.9%) vs baseline: -0.2% Memory: ✅ 42.998MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +5.0% ✅ bytesio_noaspectTime: ✅ 3.288µs (SLO: <10.000µs 📉 -67.1%) vs baseline: -0.3% Memory: ✅ 43.037MB (SLO: <43.500MB 🟡 -1.1%) vs baseline: +4.8% ✅ capitalize_aspectTime: ✅ 14.688µs (SLO: <20.000µs 📉 -26.6%) vs baseline: +0.1% Memory: ✅ 42.979MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.8% ✅ capitalize_noaspectTime: ✅ 2.584µs (SLO: <10.000µs 📉 -74.2%) vs baseline: -1.3% Memory: ✅ 42.920MB (SLO: <43.500MB 🟡 -1.3%) vs baseline: +4.6% ✅ casefold_aspectTime: ✅ 14.657µs (SLO: <20.000µs 📉 -26.7%) vs baseline: +0.1% Memory: ✅ 42.959MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.9% ✅ casefold_noaspectTime: ✅ 3.157µs (SLO: <10.000µs 📉 -68.4%) vs baseline: -0.9% Memory: ✅ 42.939MB (SLO: <43.500MB 🟡 -1.3%) vs baseline: +4.7% ✅ decode_aspectTime: ✅ 15.496µs (SLO: <30.000µs 📉 -48.3%) vs baseline: -0.9% Memory: ✅ 43.096MB (SLO: <43.500MB 🟡 -0.9%) vs baseline: +5.2% ✅ decode_noaspectTime: ✅ 1.626µs (SLO: <10.000µs 📉 -83.7%) vs baseline: +1.1% Memory: ✅ 43.116MB (SLO: <43.500MB 🟡 -0.9%) vs baseline: +5.1% ✅ encode_aspectTime: ✅ 18.165µs (SLO: <30.000µs 📉 -39.4%) vs baseline: 📈 +22.7% Memory: ✅ 42.998MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.8% ✅ encode_noaspectTime: ✅ 1.503µs (SLO: <10.000µs 📉 -85.0%) vs baseline: -0.9% Memory: ✅ 43.037MB (SLO: <43.500MB 🟡 -1.1%) vs baseline: +5.0% ✅ format_aspectTime: ✅ 170.949µs (SLO: <200.000µs 📉 -14.5%) vs baseline: -0.1% Memory: ✅ 43.057MB (SLO: <43.250MB 🟡 -0.4%) vs baseline: +4.6% ✅ format_map_aspectTime: ✅ 191.015µs (SLO: <200.000µs -4.5%) vs baseline: ~same Memory: ✅ 43.155MB (SLO: <43.500MB 🟡 -0.8%) vs baseline: +4.9% ✅ format_map_noaspectTime: ✅ 3.793µs (SLO: <10.000µs 📉 -62.1%) vs baseline: ~same Memory: ✅ 42.939MB (SLO: <43.250MB 🟡 -0.7%) vs baseline: +4.7% ✅ format_noaspectTime: ✅ 3.182µs (SLO: <10.000µs 📉 -68.2%) vs baseline: -0.2% Memory: ✅ 42.959MB (SLO: <43.250MB 🟡 -0.7%) vs baseline: +4.5% ✅ index_aspectTime: ✅ 15.272µs (SLO: <20.000µs 📉 -23.6%) vs baseline: -0.5% Memory: ✅ 42.959MB (SLO: <43.250MB 🟡 -0.7%) vs baseline: +4.9% ✅ index_noaspectTime: ✅ 0.466µs (SLO: <10.000µs 📉 -95.3%) vs baseline: -0.4% Memory: ✅ 43.077MB (SLO: <43.500MB 🟡 -1.0%) vs baseline: +5.0% ✅ join_aspectTime: ✅ 17.079µs (SLO: <20.000µs 📉 -14.6%) vs baseline: -0.5% Memory: ✅ 42.900MB (SLO: <43.500MB 🟡 -1.4%) vs baseline: +4.7% ✅ join_noaspectTime: ✅ 1.544µs (SLO: <10.000µs 📉 -84.6%) vs baseline: -1.9% Memory: ✅ 42.959MB (SLO: <43.250MB 🟡 -0.7%) vs baseline: +4.8% ✅ ljust_aspectTime: ✅ 20.693µs (SLO: <30.000µs 📉 -31.0%) vs baseline: -0.6% Memory: ✅ 43.096MB (SLO: <43.250MB 🟡 -0.4%) vs baseline: +5.0% ✅ ljust_noaspectTime: ✅ 2.723µs (SLO: <10.000µs 📉 -72.8%) vs baseline: ~same Memory: ✅ 43.018MB (SLO: <43.250MB 🟡 -0.5%) vs baseline: +5.0% ✅ lower_aspectTime: ✅ 17.906µs (SLO: <30.000µs 📉 -40.3%) vs baseline: -0.1% Memory: ✅ 42.959MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +5.0% ✅ lower_noaspectTime: ✅ 2.427µs (SLO: <10.000µs 📉 -75.7%) vs baseline: -0.5% Memory: ✅ 42.979MB (SLO: <43.250MB 🟡 -0.6%) vs baseline: +4.9% ✅ lstrip_aspectTime: ✅ 17.624µs (SLO: <20.000µs 📉 -11.9%) vs baseline: -0.5% Memory: ✅ 42.959MB (SLO: <43.250MB 🟡 -0.7%) vs baseline: +4.8% ✅ lstrip_noaspectTime: ✅ 1.859µs (SLO: <10.000µs 📉 -81.4%) vs baseline: ~same Memory: ✅ 42.998MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.9% ✅ modulo_aspectTime: ✅ 165.851µs (SLO: <200.000µs 📉 -17.1%) vs baseline: -0.3% Memory: ✅ 43.155MB (SLO: <43.500MB 🟡 -0.8%) vs baseline: +5.1% ✅ modulo_aspect_for_bytearray_bytearrayTime: ✅ 179.848µs (SLO: <200.000µs 📉 -10.1%) vs baseline: +3.1% Memory: ✅ 43.155MB (SLO: <43.500MB 🟡 -0.8%) vs baseline: +4.9% ✅ modulo_aspect_for_bytesTime: ✅ 169.311µs (SLO: <200.000µs 📉 -15.3%) vs baseline: ~same Memory: ✅ 43.155MB (SLO: <43.500MB 🟡 -0.8%) vs baseline: +5.0% ✅ modulo_aspect_for_bytes_bytearrayTime: ✅ 172.669µs (SLO: <200.000µs 📉 -13.7%) vs baseline: +0.6% Memory: ✅ 43.116MB (SLO: <43.500MB 🟡 -0.9%) vs baseline: +4.7% ✅ modulo_noaspectTime: ✅ 3.660µs (SLO: <10.000µs 📉 -63.4%) vs baseline: -0.4% Memory: ✅ 42.959MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.9% ✅ replace_aspectTime: ✅ 211.511µs (SLO: <300.000µs 📉 -29.5%) vs baseline: -0.1% Memory: ✅ 43.155MB (SLO: <44.000MB 🟡 -1.9%) vs baseline: +4.8% ✅ replace_noaspectTime: ✅ 2.906µs (SLO: <10.000µs 📉 -70.9%) vs baseline: -0.2% Memory: ✅ 42.959MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.7% ✅ repr_aspectTime: ✅ 1.412µs (SLO: <10.000µs 📉 -85.9%) vs baseline: -0.7% Memory: ✅ 42.880MB (SLO: <43.500MB 🟡 -1.4%) vs baseline: +4.6% ✅ repr_noaspectTime: ✅ 0.523µs (SLO: <10.000µs 📉 -94.8%) vs baseline: -0.4% Memory: ✅ 42.979MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.9% ✅ rstrip_aspectTime: ✅ 19.010µs (SLO: <30.000µs 📉 -36.6%) vs baseline: +0.2% Memory: ✅ 43.037MB (SLO: <43.500MB 🟡 -1.1%) vs baseline: +4.8% ✅ rstrip_noaspectTime: ✅ 2.026µs (SLO: <10.000µs 📉 -79.7%) vs baseline: +4.7% Memory: ✅ 43.057MB (SLO: <43.500MB 🟡 -1.0%) vs baseline: +5.0% ✅ slice_aspectTime: ✅ 15.855µs (SLO: <20.000µs 📉 -20.7%) vs baseline: ~same Memory: ✅ 42.939MB (SLO: <43.500MB 🟡 -1.3%) vs baseline: +4.9% ✅ slice_noaspectTime: ✅ 0.597µs (SLO: <10.000µs 📉 -94.0%) vs baseline: -0.5% Memory: ✅ 42.920MB (SLO: <43.500MB 🟡 -1.3%) vs baseline: +4.7% ✅ stringio_aspectTime: ✅ 54.028µs (SLO: <80.000µs 📉 -32.5%) vs baseline: +0.5% Memory: ✅ 42.939MB (SLO: <43.500MB 🟡 -1.3%) vs baseline: +4.7% ✅ stringio_noaspectTime: ✅ 3.677µs (SLO: <10.000µs 📉 -63.2%) vs baseline: +0.6% Memory: ✅ 42.939MB (SLO: <43.500MB 🟡 -1.3%) vs baseline: +4.9% ✅ strip_aspectTime: ✅ 17.587µs (SLO: <20.000µs 📉 -12.1%) vs baseline: -0.4% Memory: ✅ 42.979MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.8% ✅ strip_noaspectTime: ✅ 1.852µs (SLO: <10.000µs 📉 -81.5%) vs baseline: -1.6% Memory: ✅ 42.979MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +5.0% ✅ swapcase_aspectTime: ✅ 18.404µs (SLO: <30.000µs 📉 -38.7%) vs baseline: -0.2% Memory: ✅ 42.920MB (SLO: <43.500MB 🟡 -1.3%) vs baseline: +4.7% ✅ swapcase_noaspectTime: ✅ 2.841µs (SLO: <10.000µs 📉 -71.6%) vs baseline: +0.5% Memory: ✅ 42.979MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.7% ✅ title_aspectTime: ✅ 18.241µs (SLO: <30.000µs 📉 -39.2%) vs baseline: -0.3% Memory: ✅ 42.920MB (SLO: <43.000MB 🟡 -0.2%) vs baseline: +4.7% ✅ title_noaspectTime: ✅ 2.690µs (SLO: <10.000µs 📉 -73.1%) vs baseline: +0.2% Memory: ✅ 43.018MB (SLO: <43.500MB 🟡 -1.1%) vs baseline: +4.8% ✅ translate_aspectTime: ✅ 24.202µs (SLO: <30.000µs 📉 -19.3%) vs baseline: 📈 +18.8% Memory: ✅ 42.998MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.9% ✅ translate_noaspectTime: ✅ 4.319µs (SLO: <10.000µs 📉 -56.8%) vs baseline: -0.2% Memory: ✅ 42.939MB (SLO: <43.500MB 🟡 -1.3%) vs baseline: +4.6% ✅ upper_aspectTime: ✅ 17.916µs (SLO: <30.000µs 📉 -40.3%) vs baseline: -0.5% Memory: ✅ 42.959MB (SLO: <43.500MB 🟡 -1.2%) vs baseline: +4.5% ✅ upper_noaspectTime: ✅ 2.446µs (SLO: <10.000µs 📉 -75.5%) vs baseline: -0.3% Memory: ✅ 42.939MB (SLO: <43.500MB 🟡 -1.3%) vs baseline: +4.7% 📈 iastaspectsospath - 24/24✅ ospathbasename_aspectTime: ✅ 5.169µs (SLO: <10.000µs 📉 -48.3%) vs baseline: 📈 +21.5% Memory: ✅ 41.347MB (SLO: <43.500MB -5.0%) vs baseline: +4.7% ✅ ospathbasename_noaspectTime: ✅ 4.266µs (SLO: <10.000µs 📉 -57.3%) vs baseline: -1.0% Memory: ✅ 41.386MB (SLO: <43.500MB -4.9%) vs baseline: +4.9% ✅ ospathjoin_aspectTime: ✅ 6.272µs (SLO: <10.000µs 📉 -37.3%) vs baseline: -0.2% Memory: ✅ 41.386MB (SLO: <43.500MB -4.9%) vs baseline: +4.8% ✅ ospathjoin_noaspectTime: ✅ 6.308µs (SLO: <10.000µs 📉 -36.9%) vs baseline: +0.1% Memory: ✅ 41.425MB (SLO: <43.500MB -4.8%) vs baseline: +4.8% ✅ ospathnormcase_aspectTime: ✅ 3.565µs (SLO: <10.000µs 📉 -64.3%) vs baseline: ~same Memory: ✅ 41.445MB (SLO: <43.500MB -4.7%) vs baseline: +5.1% ✅ ospathnormcase_noaspectTime: ✅ 3.578µs (SLO: <10.000µs 📉 -64.2%) vs baseline: -0.7% Memory: ✅ 41.465MB (SLO: <43.500MB -4.7%) vs baseline: +4.8% ✅ ospathsplit_aspectTime: ✅ 4.886µs (SLO: <10.000µs 📉 -51.1%) vs baseline: -1.0% Memory: ✅ 41.425MB (SLO: <43.500MB -4.8%) vs baseline: +5.0% ✅ ospathsplit_noaspectTime: ✅ 4.951µs (SLO: <10.000µs 📉 -50.5%) vs baseline: -1.3% Memory: ✅ 41.425MB (SLO: <43.500MB -4.8%) vs baseline: +5.1% ✅ ospathsplitdrive_aspectTime: ✅ 3.736µs (SLO: <10.000µs 📉 -62.6%) vs baseline: -0.3% Memory: ✅ 41.366MB (SLO: <43.500MB -4.9%) vs baseline: +4.8% ✅ ospathsplitdrive_noaspectTime: ✅ 0.744µs (SLO: <10.000µs 📉 -92.6%) vs baseline: +0.4% Memory: ✅ 41.406MB (SLO: <43.500MB -4.8%) vs baseline: +4.9% ✅ ospathsplitext_aspectTime: ✅ 4.636µs (SLO: <10.000µs 📉 -53.6%) vs baseline: +0.1% Memory: ✅ 41.445MB (SLO: <43.500MB -4.7%) vs baseline: +5.0% ✅ ospathsplitext_noaspectTime: ✅ 4.612µs (SLO: <10.000µs 📉 -53.9%) vs baseline: -0.2% Memory: ✅ 41.406MB (SLO: <43.500MB -4.8%) vs baseline: +5.0% 📈 telemetryaddmetric - 30/30✅ 1-count-metric-1-timesTime: ✅ 3.415µs (SLO: <20.000µs 📉 -82.9%) vs baseline: 📈 +15.0% Memory: ✅ 34.839MB (SLO: <35.500MB 🟡 -1.9%) vs baseline: +4.8% ✅ 1-count-metrics-100-timesTime: ✅ 201.049µs (SLO: <220.000µs -8.6%) vs baseline: +0.4% Memory: ✅ 34.819MB (SLO: <35.500MB 🟡 -1.9%) vs baseline: +4.4% ✅ 1-distribution-metric-1-timesTime: ✅ 3.321µs (SLO: <20.000µs 📉 -83.4%) vs baseline: ~same Memory: ✅ 34.937MB (SLO: <35.500MB 🟡 -1.6%) vs baseline: +4.9% ✅ 1-distribution-metrics-100-timesTime: ✅ 216.143µs (SLO: <230.000µs -6.0%) vs baseline: +0.9% Memory: ✅ 34.819MB (SLO: <35.500MB 🟡 -1.9%) vs baseline: +4.7% ✅ 1-gauge-metric-1-timesTime: ✅ 2.183µs (SLO: <20.000µs 📉 -89.1%) vs baseline: +0.1% Memory: ✅ 34.937MB (SLO: <35.500MB 🟡 -1.6%) vs baseline: +5.0% ✅ 1-gauge-metrics-100-timesTime: ✅ 136.404µs (SLO: <150.000µs -9.1%) vs baseline: -0.9% Memory: ✅ 34.898MB (SLO: <35.500MB 🟡 -1.7%) vs baseline: +4.9% ✅ 1-rate-metric-1-timesTime: ✅ 3.139µs (SLO: <20.000µs 📉 -84.3%) vs baseline: -0.1% Memory: ✅ 34.839MB (SLO: <35.500MB 🟡 -1.9%) vs baseline: +4.5% ✅ 1-rate-metrics-100-timesTime: ✅ 213.410µs (SLO: <250.000µs 📉 -14.6%) vs baseline: +0.4% Memory: ✅ 34.859MB (SLO: <35.500MB 🟡 -1.8%) vs baseline: +4.9% ✅ 100-count-metrics-100-timesTime: ✅ 19.904ms (SLO: <22.000ms -9.5%) vs baseline: ~same Memory: ✅ 34.918MB (SLO: <35.500MB 🟡 -1.6%) vs baseline: +5.0% ✅ 100-distribution-metrics-100-timesTime: ✅ 2.225ms (SLO: <2.550ms 📉 -12.7%) vs baseline: -2.3% Memory: ✅ 34.937MB (SLO: <35.500MB 🟡 -1.6%) vs baseline: +5.1% ✅ 100-gauge-metrics-100-timesTime: ✅ 1.403ms (SLO: <1.550ms -9.5%) vs baseline: +0.7% Memory: ✅ 34.878MB (SLO: <35.500MB 🟡 -1.8%) vs baseline: +4.6% ✅ 100-rate-metrics-100-timesTime: ✅ 2.177ms (SLO: <2.550ms 📉 -14.6%) vs baseline: ~same Memory: ✅ 34.780MB (SLO: <35.500MB -2.0%) vs baseline: +4.5% ✅ flush-1-metricTime: ✅ 4.657µs (SLO: <20.000µs 📉 -76.7%) vs baseline: +0.4% Memory: ✅ 35.173MB (SLO: <35.500MB 🟡 -0.9%) vs baseline: +4.7% ✅ flush-100-metricsTime: ✅ 173.419µs (SLO: <250.000µs 📉 -30.6%) vs baseline: ~same Memory: ✅ 35.252MB (SLO: <35.500MB 🟡 -0.7%) vs baseline: +4.7% ✅ flush-1000-metricsTime: ✅ 2.158ms (SLO: <2.500ms 📉 -13.7%) vs baseline: -0.5% Memory: ✅ 36.137MB (SLO: <36.500MB 🟡 -1.0%) vs baseline: +5.0% 🟡 Near SLO Breach (15 suites)🟡 coreapiscenario - 10/10 (1 unstable)
|
The urlparse function was imported inside the async function view_iast_ssrf_secure, which caused a race condition in multiprocess mode where: - The IAST validator wrapper for urlparse is set up at module startup - But importing inside a function can bypass or inconsistently apply the wrapper - This caused the secure mark to not be applied reliably, leading to false SSRF vulnerability reports Flaky tests IDs: DD_1PGYGI DD_ONKXDT DD_U2V880 DD_954GJO DD_O236KS (cherry picked from commit 381404b)
The urlparse function was imported inside the async function view_iast_ssrf_secure, which caused a race condition in multiprocess mode where: - The IAST validator wrapper for urlparse is set up at module startup - But importing inside a function can bypass or inconsistently apply the wrapper - This caused the secure mark to not be applied reliably, leading to false SSRF vulnerability reports Flaky tests IDs: DD_1PGYGI DD_ONKXDT DD_U2V880 DD_954GJO DD_O236KS (cherry picked from commit 381404b)
The urlparse function was imported inside the async function view_iast_ssrf_secure, which caused a race condition in multiprocess mode where: - The IAST validator wrapper for urlparse is set up at module startup - But importing inside a function can bypass or inconsistently apply the wrapper - This caused the secure mark to not be applied reliably, leading to false SSRF vulnerability reports Flaky tests IDs: DD_1PGYGI DD_ONKXDT DD_U2V880 DD_954GJO DD_O236KS (cherry picked from commit 381404b)
The urlparse function was imported inside the async function view_iast_ssrf_secure, which caused a race condition in multiprocess mode where: - The IAST validator wrapper for urlparse is set up at module startup - But importing inside a function can bypass or inconsistently apply the wrapper - This caused the secure mark to not be applied reliably, leading to false SSRF vulnerability reports Flaky tests IDs: DD_1PGYGI DD_ONKXDT DD_U2V880 DD_954GJO DD_O236KS (cherry picked from commit 381404b) Signed-off-by: Alberto Vara <[email protected]>
The urlparse function was imported inside the async function view_iast_ssrf_secure, which caused a race condition in multiprocess mode where: - The IAST validator wrapper for urlparse is set up at module startup - But importing inside a function can bypass or inconsistently apply the wrapper - This caused the secure mark to not be applied reliably, leading to false SSRF vulnerability reports Flaky tests IDs: DD_1PGYGI DD_ONKXDT DD_U2V880 DD_954GJO DD_O236KS (cherry picked from commit 381404b) Signed-off-by: Alberto Vara <[email protected]>
The urlparse function was imported inside the async function view_iast_ssrf_secure, which caused a race condition in multiprocess mode where: - The IAST validator wrapper for urlparse is set up at module startup - But importing inside a function can bypass or inconsistently apply the wrapper - This caused the secure mark to not be applied reliably, leading to false SSRF vulnerability reports Flaky tests IDs: DD_1PGYGI DD_ONKXDT DD_U2V880 DD_954GJO DD_O236KS (cherry picked from commit 381404b) Signed-off-by: Alberto Vara <[email protected]>
Backport 381404b from #15749 to 4.1. The urlparse function was imported inside the async function view_iast_ssrf_secure, which caused a race condition in multiprocess mode where: - The IAST validator wrapper for urlparse is set up at module startup - But importing inside a function can bypass or inconsistently apply the wrapper - This caused the secure mark to not be applied reliably, leading to false SSRF vulnerability reports Flaky tests IDs: DD_1PGYGI DD_ONKXDT DD_U2V880 DD_954GJO DD_O236KS Signed-off-by: Alberto Vara <[email protected]> Co-authored-by: Alberto Vara <[email protected]>
Backport 381404b from #15749 to 3.19. The urlparse function was imported inside the async function view_iast_ssrf_secure, which caused a race condition in multiprocess mode where: - The IAST validator wrapper for urlparse is set up at module startup - But importing inside a function can bypass or inconsistently apply the wrapper - This caused the secure mark to not be applied reliably, leading to false SSRF vulnerability reports Flaky tests IDs: DD_1PGYGI DD_ONKXDT DD_U2V880 DD_954GJO DD_O236KS Signed-off-by: Alberto Vara <[email protected]> Co-authored-by: Alberto Vara <[email protected]>
Backport 381404b from #15749 to 4.0. The urlparse function was imported inside the async function view_iast_ssrf_secure, which caused a race condition in multiprocess mode where: - The IAST validator wrapper for urlparse is set up at module startup - But importing inside a function can bypass or inconsistently apply the wrapper - This caused the secure mark to not be applied reliably, leading to false SSRF vulnerability reports Flaky tests IDs: DD_1PGYGI DD_ONKXDT DD_U2V880 DD_954GJO DD_O236KS Signed-off-by: Alberto Vara <[email protected]> Co-authored-by: Alberto Vara <[email protected]>
The urlparse function was imported inside the async function view_iast_ssrf_secure, which caused a race condition in multiprocess mode where:
Flaky tests IDs: DD_1PGYGI DD_ONKXDT DD_U2V880 DD_954GJO DD_O236KS