Repository navigation
Conversation
Oracle: a second ':' after the port (EZConnect :server_type, IPv6 literals, EZConnect Plus ?params) or a protocol prefix other than ldap:// (tcp://, tcps://) was read as host:port:sid, so a non-numeric segment was parsed as the port and threw NumberFormatException. The service form now strips the optional :server_type and /instance_name suffixes, any <proto>:// prefix is skipped, ?params are dropped, and port parsing no longer throws. jTDS: the port and database separators were searched across the whole URL remainder from an offset derived from the type name, so a ':' or '/' in a property value threw StringIndexOutOfBoundsException and short host names lost their port. The address is now split at ';', then '/', then ':'. In both cases the exception was caught in parse(), dropping host, port and instance from DB spans. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add Numbers.parseNonNegativeInt(CharSequence[, start, end]), which returns -1 for empty, non-digit, signed or overflowing input instead of throwing, and parses a range in place without a substring. Route every port parse in JDBCConnectionUrlParser through it. This removes the catch-and-ignore NumberFormatException blocks, and the sites that let the exception escape to parse()'s catch-all (MODIFIED_URL_LIKE, DERBY, the regex-matched ORACLE_AT_DESCRIPTION / MARIA_ADDRESS ports) now keep host and instance when the port is malformed instead of discarding the whole URL. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tils Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Mirrors LongStringUtils naming. It lives in internal-api rather than next to LongStringUtils in dd-trace-api so the published API jar does not grow. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
RequestURIDataAdapter split the client-supplied Host header on its last ':'
and ran Integer.parseInt on the rest, so a malformed port, or an IPv6 host
without a port ("[::1]"), threw from the constructor. HttpServerDecorator
catches that around url(request), which skipped http.url, http.hostname,
the URL resource name and the AppSec request URI callback for the request.
Add HostHeader (internal-api) to split host and port without throwing,
treating ':' inside an IPv6 literal as part of the host, and use it in the
Play 2.3, 2.4 and 2.6 adapters. A missing or malformed port is reported as 0,
as a missing port already was.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Contributor
🟢 Java Benchmark SLOs — All performance SLOs passed
PR vs. master results
Commit: Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What Does This Do
Parses the port in Play's
Hostheader without throwing.RequestURIDataAdapter(Play 2.3, 2.4, 2.6) splitrequest.host()on its last:and calledInteger.parseInton the remainder, with no catch. Any malformed port threw from the constructor, and so did a bracketed IPv6 host with no port ([::1], where the last:sits inside the brackets).HostHeadertointernal-api(datadog.trace.bootstrap.instrumentation.api). It splitshost,host:port,[ipv6]and[ipv6]:portwithout throwing, usingIntStringUtils.parseNonNegativeIntfor the port.0, which is what a missing port already produced.Motivation
The
Hostheader comes from the client.HttpServerDecorator.onRequestcallsurl(request)inside atry { ... } catch (Exception), so the exception didn't reach the application, but it skipped everything after it in that block:http.urlandhttp.hostnamecallIGCallbackURI, which passes the request URI to AppSecSo a request with a malformed
Hostport produced a server span without URL tags, and its URI was never passed to AppSec.Additional Notes
IntStringUtils. I'll retarget this tomasteronce Fix Oracle and jTDS JDBC URL parsing failures (quick fix) #12780 merges.HostHeaderTest(JUnit 5,@TableTest) covers the split, including IPv6, empty, non-numeric, negative and overflowing ports.Hostheader yet. The existing Play server tests are Groovy, and the adapter is now a two-line delegation toHostHeader.LambdaEventParser.stripPortduplicatesHostHeader.host. I left it alone here because it's on a different branch of the stack.🤖 Generated with Claude Code