Skip to content

Fix NullPointerException from activating a null span in scope manager (quick fix) - #12451

Merged
gh-worker-dd-mergequeue-cf854d[bot] merged 5 commits into
masterfrom
fix/websocket-null-span-npe
Oct 10, 2026
Merged

gh-worker-dd-mergequeue-cf854d[bot] merged 5 commits into
masterfrom
fix/websocket-null-span-npe

Conversation

@dougqh

@dougqh dougqh commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

What Does This Do

  • ContinuableScopeManager.activate now returns the existing INVALID_SCOPE (noop) sentinel when given a null span, instead of silently pushing a ContinuableScope with a null Context onto the scope stack.
  • TracingSendHandler.onResult (JSR-356 websocket async send instrumentation) skips activateSpan entirely when the websocket span is null, matching the existing null-check already used in TracingOutputStream.close() for the same HandlerContext.
  • Added ScopeManagerForkedTest#activatingNullSpanReturnsNoopScopeAndDoesNotCorruptStack, which reproduces the original bug: activating a null span returns a noop scope, and a subsequent real activation on the same thread no longer NPEs.

Motivation

Fixes a production NullPointerException surfaced via Datadog error tracking (issue 6d4f45fa-b461-11f0-8716-da7ad0900002) in ContinuableScopeManager.activate.

Root cause: HandlerContext.getWebsocketSpan() can race with HandlerContext.reset() clearing that field from another thread, so TracingSendHandler.onResult could call activateSpan with a null span. ContinuableScopeManager.activate had no guard for this — it pushed a ContinuableScope with a null Context. The corruption didn't throw immediately; it only surfaced as an NPE on the next activation on that thread, when top.context.with(span) dereferenced the poisoned null context. The pre-existing assert span != null never caught this in practice, since assertions are never enabled (-ea) in production JVMs.

Additional Notes

  • Low customer impact (11 total occurrences, single customer) and not a crash — the exception was already caught by the instrumentation's own exception guard — but it silently corrupted the scope stack for the affected thread, which is worse than the NPE itself.
  • ./gradlew :dd-trace-core:forkedTest --tests "datadog.trace.core.scopemanager.ScopeManagerForkedTest" passes.
  • ./gradlew spotlessApply produces no additional changes.

Contributor Checklist

Jira ticket: N/A — originated from Datadog Error Tracking issue 6d4f45fa-b461-11f0-8716-da7ad0900002

🤖 Generated with Claude Code

A null span passed to activateSpan() (e.g. from TracingSendHandler when
the websocket span was concurrently cleared by HandlerContext.reset())
was silently pushed as a scope with a null Context. The corrupted scope
only surfaced as an NPE on the *next* activation on that thread, when
`top.context.with(span)` dereferenced the null context. The existing
`assert span != null` never caught this since assertions are never
enabled (-ea) in production.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@dougqh dougqh added type: bug fix Bug fix comp: core Tracer core inst: websocket WebSocket Instrumentation tag: ai generated Largely based on code generated by an AI or LLM labels Sep 10, 2026
@datadog-prod-us1-5

This comment has been minimized.

@dd-octo-sts

dd-octo-sts Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

🟢 Java Benchmark SLOs — All performance SLOs passed

Suite Status
Startup 🟢 pass

SLO thresholds are defined here based on automatically generated metrics. A warning is raised when results are within 5% of the threshold.

PR vs. master results
Scenario Candidate master Δ (95% CI of mean)
startup:insecure-bank:iast:Agent 14.76 s 14.65 s [-0.2%; +1.6%] (no difference)
startup:insecure-bank:tracing:Agent 13.61 s 13.67 s [-1.2%; +0.3%] (no difference)
startup:petclinic:appsec:Agent 17.16 s 17.05 s [-0.2%; +1.5%] (no difference)
startup:petclinic:iast:Agent 17.04 s 16.93 s [-0.2%; +1.5%] (no difference)
startup:petclinic:profiling:Agent 16.80 s 16.80 s [-1.1%; +1.1%] (no difference)
startup:petclinic:sca:Agent 17.04 s 16.99 s [-0.6%; +1.2%] (no difference)
startup:petclinic:tracing:Agent 16.05 s 16.08 s [-1.1%; +0.8%] (no difference)

Commit: 51e86248 · CI Pipeline · Benchmarking Platform UI


Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion.

@dougqh dougqh changed the title Fix NullPointerException from activating a null span in scope manager Fix NullPointerException from activating a null span in scope manager (quick fix) Sep 15, 2026
@dougqh
dougqh marked this pull request as ready for review October 7, 2026 20:19
@dougqh
dougqh requested review from a team as code owners October 7, 2026 20:19
@dougqh
dougqh requested review from jordan-wong and mhlidd and removed request for a team October 7, 2026 20:19
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T20:21:53.284867Z 9624bfc Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@datadog-prod-us1-5 datadog-prod-us1-5 Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bits Code Review: PASS

More details

Null-span activation now leaves the scope stack untouched, preventing the poisoned context that caused subsequent activations to fail. The websocket callback’s error and cleanup paths remain compatible with a missing span.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Bits Code Review · Commit 9624bfc · @DataDog review to ask questions

@dougqh
dougqh requested review from amarziali and mcculls October 8, 2026 17:36
dougqh and others added 3 commits October 9, 2026 10:02
Per review: state the null case explicitly instead of relying on
try-with-resources skipping a null resource. Behavior is unchanged, since
onError and onFrameEnd both no-op without a span.

Also port the null-span scope manager test to ContextScope; AgentScope was
removed on master (#12557), so the test no longer compiled after the merge.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dougqh
dougqh requested a review from a team as a code owner October 9, 2026 19:09

@datadog-prod-us1-5 datadog-prod-us1-5 Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bits Code Review: PASS

More details

Null activation now returns before touching the scope stack, preventing corruption of subsequent activations. The websocket fallback preserves callback delivery when its span has been cleared.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Bits Code Review · Commit 51e8624

@dougqh
dougqh added this pull request to the merge queue Oct 9, 2026
@dd-octo-sts

dd-octo-sts Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-10-09 20:20:58 UTC ℹ️ Start processing command /merge


2026-10-09 20:21:01 UTC ℹ️ MergeQueue: pull request added to the queue

The expected merge time in master is approximately 1h (p90).


2026-10-09 22:21:29 UTC ❌ MergeQueue: The build pipeline has timeout

The merge request has been interrupted because the build 5666697513913241170 took longer than expected. The current limit for the base branch 'master' is 120 minutes.

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 9, 2026
@dougqh
dougqh added this pull request to the merge queue Oct 10, 2026
@dd-octo-sts

dd-octo-sts Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-10-10 01:43:18 UTC ℹ️ Start processing command /merge


2026-10-10 01:43:22 UTC ℹ️ MergeQueue: pull request added to the queue

The expected merge time in master is approximately 1h (p90).


2026-10-10 02:53:11 UTC ℹ️ MergeQueue: This merge request was merged

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 10, 2026
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot merged commit c0cf602 into master Oct 10, 2026
611 checks passed
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot deleted the fix/websocket-null-span-npe branch October 10, 2026 02:53
@github-actions github-actions Bot added this to the 1.68.0 milestone Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp: core Tracer core inst: websocket WebSocket Instrumentation tag: ai generated Largely based on code generated by an AI or LLM type: bug fix Bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants