Skip to content

Route debugger exploration builds through repository proxies - #12590

Open
bric3 wants to merge 2 commits into
masterfrom
codex/fix-exploration-test-repository-proxy
Open

bric3 wants to merge 2 commits into
masterfrom
codex/fix-exploration-test-repository-proxy

Conversation

@bric3

@bric3 bric3 commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

What Does This Do

Routes Maven and Gradle builds launched by debugger exploration tests through the configured repository proxies. Each job generates Maven mirror settings and installs the existing Gradle repository init script in its user home.

Motivation

Exploration jobs build third-party projects directly and do not extend the shared Gradle build job. The repository proxy variables were therefore present but never translated into configuration understood by Maven or Gradle.

This left exploration jobs able to contact Maven Central directly and fail with HTTP 429 responses, as seen in job 2061570544.

Additional Notes

The change covers the Maven-based suites and the Gradle-based OkHttp runtime job. The manually rebuilt exploration-test image is unchanged.

Contributor Checklist

@bric3 bric3 added type: bug fix Bug fix tag: no release notes Changes to exclude from release notes comp: debugger Dynamic Instrumentation tag: ai generated Largely based on code generated by an AI or LLM labels Sep 21, 2026
@bric3
bric3 requested a review from jpbempel September 21, 2026 14:57
@bric3
bric3 marked this pull request as ready for review September 21, 2026 14:57
@bric3
bric3 requested review from a team as code owners September 21, 2026 14:57
@bric3
bric3 requested review from dougqh and randomanderson and removed request for a team September 21, 2026 14:57
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-22T10:57:45.696100Z b14d757 Draft marked ready
🔒 Security Review Completed 2026-09-22T10:59:40.720096Z b14d757 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@bric3
bric3 marked this pull request as draft September 21, 2026 15:02
@datadog-datadog-prod-us1-2

This comment has been minimized.

Comment thread .gitlab/exploration-tests.yml Outdated
@dd-octo-sts

dd-octo-sts Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

🟢 Java Benchmark SLOs — All performance SLOs passed

Suite Status
Startup 🟢 pass

SLO thresholds are defined here based on automatically generated metrics. A warning is raised when results are within 5% of the threshold.

PR vs. master results
Scenario Candidate master Δ (95% CI of mean)
startup:insecure-bank:iast:Agent 13.97 s 13.95 s [-0.6%; +1.0%] (no difference)
startup:insecure-bank:tracing:Agent 12.93 s 12.97 s [-1.2%; +0.6%] (no difference)
startup:petclinic:appsec:Agent 16.94 s 16.74 s [+0.1%; +2.2%] (maybe worse)
startup:petclinic:iast:Agent 16.89 s 16.53 s [-2.1%; +6.5%] (no difference)
startup:petclinic:profiling:Agent 16.79 s 16.79 s [-1.3%; +1.2%] (no difference)
startup:petclinic:sca:Agent 16.94 s 16.76 s [+0.1%; +2.1%] (maybe worse)
startup:petclinic:tracing:Agent 15.70 s 16.16 s [-7.2%; +1.6%] (no difference)

Commit: b14d757e · CI Pipeline · Benchmarking Platform UI


Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion.

@bric3
bric3 force-pushed the codex/fix-exploration-test-repository-proxy branch from 5a1cb32 to 68ed60e Compare September 21, 2026 15:18
@bric3 bric3 changed the title Route debugger exploration tests through repository proxies Route debugger exploration Maven builds through repository proxy Sep 21, 2026

@datadog-datadog-prod-us1-2 datadog-datadog-prod-us1-2 Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Autotest was unable to complete this review. View session

Please try again by commenting @autotest review.

@pr-commenter

pr-commenter Bot commented Sep 21, 2026

Copy link
Copy Markdown

Debugger benchmarks

Parameters

Baseline Candidate
baseline_or_candidate baseline candidate
ci_job_date 1790004889 1790005216
end_time 2026-09-21T15:36:19 2026-09-21T15:41:46
git_branch master codex/fix-exploration-test-repository-proxy
git_commit_sha 2cfe4bc 68ed60e
start_time 2026-09-21T15:34:50 2026-09-21T15:40:17
See matching parameters
Baseline Candidate
ci_job_id 2063344017 2063344017
ci_pipeline_id 138902481 138902481
cpu_model Intel(R) Xeon(R) Platinum 8175M CPU @ 2.50GHz Intel(R) Xeon(R) Platinum 8175M CPU @ 2.50GHz
git_commit_date 1790003885 1790003885

Summary

Found 5 performance improvements and 0 performance regressions! Performance is the same for 5 metrics, 5 unstable metrics.

scenario Δ mean agg_http_req_duration_min Δ mean agg_http_req_duration_p50 Δ mean agg_http_req_duration_p75 Δ mean agg_http_req_duration_p99 Δ mean throughput
scenario:loop better
[-568.358µs; -471.849µs] or [-7.062%; -5.863%]
better
[-576.196µs; -478.619µs] or [-7.098%; -5.896%]
better
[-572.006µs; -473.595µs] or [-7.015%; -5.808%]
better
[-586.841µs; -452.443µs] or [-7.108%; -5.480%]
better
[+6.853op/s; +8.985op/s] or [+5.619%; +7.368%]
See unchanged results
scenario Δ mean agg_http_req_duration_min Δ mean agg_http_req_duration_p50 Δ mean agg_http_req_duration_p75 Δ mean agg_http_req_duration_p99 Δ mean throughput
scenario:noprobe same unstable
[-20.499µs; +25.949µs] or [-5.752%; +7.281%]
unstable
[-30.071µs; +35.036µs] or [-8.121%; +9.462%]
unstable
[-20.440µs; +208.144µs] or [-1.793%; +18.257%]
same
scenario:basic same same same unstable
[-61.058µs; +241.305µs] or [-6.182%; +24.432%]
unstable
[-95.363op/s; +196.373op/s] or [-4.291%; +8.837%]
Request duration reports for reports
gantt
    title reports - request duration [CI 0.99] : candidate=None, baseline=None
    dateFormat X
    axisFormat %s
section baseline
noprobe (356.392 µs) : 335, 378
.   : milestone, 356,
basic (346.873 µs) : 330, 364
.   : milestone, 347,
loop (8.117 ms) : 8054, 8181
.   : milestone, 8117,
section candidate
noprobe (359.118 µs) : 336, 382
.   : milestone, 359,
basic (336.546 µs) : 329, 344
.   : milestone, 337,
loop (7.59 ms) : 7581, 7598
.   : milestone, 7590,
Loading
  • baseline results
Scenario Request median duration [CI 0.99]
noprobe 356.392 µs [335.053 µs, 377.732 µs]
basic 346.873 µs [329.916 µs, 363.829 µs]
loop 8.117 ms [8.054 ms, 8.181 ms]
  • candidate results
Scenario Request median duration [CI 0.99]
noprobe 359.118 µs [336.371 µs, 381.864 µs]
basic 336.546 µs [329.389 µs, 343.703 µs]
loop 7.59 ms [7.581 ms, 7.598 ms]

@jpbempel jpbempel left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. thanks for fixing that!

@bric3
bric3 force-pushed the codex/fix-exploration-test-repository-proxy branch from 68ed60e to 4ebc1ed Compare September 21, 2026 16:02
@bric3 bric3 changed the title Route debugger exploration Maven builds through repository proxy Route debugger exploration builds through repository proxies Sep 22, 2026
@bric3
bric3 force-pushed the codex/fix-exploration-test-repository-proxy branch from f0c9cdf to 944f291 Compare September 22, 2026 09:15
@bric3
bric3 force-pushed the codex/fix-exploration-test-repository-proxy branch from 944f291 to b14d757 Compare September 22, 2026 09:40
@bric3
bric3 marked this pull request as ready for review September 22, 2026 10:54

@datadog-datadog-prod-us1-2 datadog-datadog-prod-us1-2 Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bits Code Review: PASS

More details

The exploration jobs now configure the Maven mirror, Maven Wrapper URL, and Gradle proxy before each build. No concrete failure mode is present in the changed paths.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Bits Code Review · Commit b14d757 · @DataDog review to ask questions

@jpbempel
jpbempel enabled auto-merge September 22, 2026 11:28
@jpbempel
jpbempel added this pull request to the merge queue Sep 22, 2026
@dd-octo-sts

dd-octo-sts Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Sep 22, 2026

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-09-22 12:12:04 UTC ℹ️ Start processing command /merge


2026-09-22 12:12:08 UTC ℹ️ MergeQueue: pull request added to the queue

The expected merge time in master is approximately 1h (p90).


2026-09-22 13:26:49 UTCMergeQueue: The build pipeline contains failing jobs for this merge request

Build pipeline has failing jobs for f5b1a23:

⚠️ Do NOT retry failed jobs directly (why?).

What to do next?

  • Investigate the failures and when ready, re-add your pull request to the queue!
  • If your PR checks are green, try to rebase/merge. It might be because the CI run is a bit old.
  • Any question, go check the FAQ.
Details

Since those jobs are not marked as being allowed to fail, the pipeline will most likely fail.
Therefore, and to allow other builds to be processed, this merge request has been rejected and the pipeline got canceled.

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 22, 2026
@jpbempel

Copy link
Copy Markdown
Member

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Sep 22, 2026

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-09-22 15:12:29 UTC ℹ️ Start processing command /merge


2026-09-22 15:12:33 UTC ℹ️ MergeQueue: pull request added to the queue

The expected merge time in master is approximately 1h (p90).


2026-09-22 15:32:45 UTCMergeQueue: The build pipeline contains failing jobs for this merge request

Build pipeline has failing jobs for 935b915:

⚠️ Do NOT retry failed jobs directly (why?).

What to do next?

  • Investigate the failures and when ready, re-add your pull request to the queue!
  • If your PR checks are green, try to rebase/merge. It might be because the CI run is a bit old.
  • Any question, go check the FAQ.
Details

Since those jobs are not marked as being allowed to fail, the pipeline will most likely fail.
Therefore, and to allow other builds to be processed, this merge request has been rejected and the pipeline got canceled.

@jpbempel

Copy link
Copy Markdown
Member

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Sep 22, 2026

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-09-22 15:33:47 UTC ℹ️ Start processing command /merge


2026-09-22 15:33:52 UTC ℹ️ MergeQueue: pull request added to the queue

The expected merge time in master is approximately 1h (p90).


2026-09-22 16:07:39 UTCMergeQueue: The build pipeline contains failing jobs for this merge request

Build pipeline has failing jobs for bb6a72a:

⚠️ Do NOT retry failed jobs directly (why?).

What to do next?

  • Investigate the failures and when ready, re-add your pull request to the queue!
  • If your PR checks are green, try to rebase/merge. It might be because the CI run is a bit old.
  • Any question, go check the FAQ.
Details

Since those jobs are not marked as being allowed to fail, the pipeline will most likely fail.
Therefore, and to allow other builds to be processed, this merge request has been rejected and the pipeline got canceled.

@dougqh dougqh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude found a couple small issues, I'll leave those to your discretion

@dougqh dougqh left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Generated with Claude Code

Approving — leaving the two notes below to your discretion.

@@ -34,6 +34,25 @@ build-exploration-tests-image:
- when: manual
allow_failure: true
before_script:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This proxy routing is only added to .common-exploration-tests's before_script, not to build-exploration-tests-image (the image-build job above), which still resolves dependencies directly against the public internet. That job's Dockerfile runs mvn verify -DskipTests=true (jsoup/jackson/jackson-databind) and ./gradlew dependencies (okhttp) with no proxy configured at all (dd-java-agent/agent-debugger/exploration-tests/Dockerfile.exploration-tests). If direct access to Maven Central / Gradle Plugin Portal is what motivated this PR (unreliable/blocked egress), image builds will keep failing or flaking exactly as before, while only the downstream test-execution job is fixed — an incomplete fix for the stated goal of "routing exploration builds through repository proxies."

🤖 Generated with Claude Code

<mirror>
<id>env-proxy</id>
<mirrorOf>*</mirrorOf>
<url>${MAVEN_REPOSITORY_PROXY}</url>

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The generated ~/.m2/settings.xml interpolates ${MAVEN_REPOSITORY_PROXY} into an XML document unescaped inside a heredoc. If MAVEN_REPOSITORY_PROXY is ever changed to a URL containing & (e.g. a query-string-based proxy endpoint) without being percent-encoded, the generated settings.xml becomes malformed XML and Maven fails to parse it, breaking every exploration-tests job silently until someone diagnoses the generated file. Currently benign only because the configured value has no &.

🤖 Generated with Claude Code

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp: debugger Dynamic Instrumentation tag: ai generated Largely based on code generated by an AI or LLM tag: no release notes Changes to exclude from release notes type: bug fix Bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants