Skip to content

Conversation

@cedricvanrompay-datadog
Copy link
Member

@cedricvanrompay-datadog cedricvanrompay-datadog commented Jan 6, 2026

Summary of changes

We use the CI Identities system for authentication in Windows CI jobs.

We also:

  • update the Windows code signing tool
  • anticipate the renewal of the Windows code signing certificate

Reason for change

The CI Identities allows finer-grained authentication than the existing systems, and give Windows CI Jobs access to Vault (for retrieving secrets for instance).

Implementation details

Test coverage

Other details

@github-actions github-actions bot added the area:builds project files, build scripts, pipelines, versioning, releases, packages label Jan 6, 2026
@pr-commenter
Copy link

pr-commenter bot commented Jan 7, 2026

Benchmarks

Benchmark execution time: 2026-01-09 15:52:03

Comparing candidate commit 7d6fb50 in PR branch cedric.vanrompay/sint-4550-use-ci-identities with baseline commit 36d351c in branch master.

Found 11 performance improvements and 5 performance regressions! Performance is the same for 159 metrics, 11 unstable metrics.

scenario:Benchmarks.Trace.ActivityBenchmark.StartStopWithChild net472

  • 🟥 execution_time [+11.101ms; +15.527ms] or [+5.499%; +7.691%]
  • 🟥 throughput [-21298.241op/s; -20374.020op/s] or [-32.455%; -31.046%]

scenario:Benchmarks.Trace.ActivityBenchmark.StartStopWithChild net6.0

  • 🟥 throughput [-7281.051op/s; -5221.658op/s] or [-7.304%; -5.238%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.AllCycleMoreComplexBody net6.0

  • 🟩 execution_time [-17.837ms; -11.892ms] or [-8.402%; -5.602%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.ObjectExtractorMoreComplexBody netcoreapp3.1

  • 🟩 execution_time [-81.082ms; -76.621ms] or [-41.191%; -38.925%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.ObjectExtractorSimpleBody net6.0

  • 🟥 execution_time [+17.256ms; +23.925ms] or [+8.759%; +12.143%]
  • 🟩 throughput [+162863.346op/s; +263615.092op/s] or [+5.659%; +9.159%]

scenario:Benchmarks.Trace.Asm.AppSecBodyBenchmark.ObjectExtractorSimpleBody netcoreapp3.1

  • 🟥 execution_time [+17.525ms; +23.420ms] or [+8.896%; +11.888%]

scenario:Benchmarks.Trace.Asm.AppSecEncoderBenchmark.EncodeLegacyArgs netcoreapp3.1

  • 🟩 execution_time [-23.310ms; -22.628ms] or [-11.444%; -11.109%]

scenario:Benchmarks.Trace.CIVisibilityProtocolWriterBenchmark.WriteAndFlushEnrichedTraces net472

  • 🟩 execution_time [-26.690ms; -18.081ms] or [-12.533%; -8.490%]
  • 🟩 throughput [+176.239op/s; +223.338op/s] or [+18.035%; +22.854%]

scenario:Benchmarks.Trace.CharSliceBenchmark.OriginalCharSlice net6.0

  • 🟩 execution_time [-163.605µs; -154.835µs] or [-7.736%; -7.321%]
  • 🟩 throughput [+37.450op/s; +39.547op/s] or [+7.920%; +8.363%]

scenario:Benchmarks.Trace.Log4netBenchmark.EnrichedLog net472

  • 🟩 execution_time [-15.198ms; -14.946ms] or [-7.564%; -7.438%]

scenario:Benchmarks.Trace.SerilogBenchmark.EnrichedLog netcoreapp3.1

  • 🟩 throughput [+9839.876op/s; +12452.910op/s] or [+5.894%; +7.460%]

scenario:Benchmarks.Trace.SpanBenchmark.StartFinishSpan net6.0

  • 🟩 execution_time [-27.199ms; -21.752ms] or [-12.248%; -9.795%]

Comment on lines -113 to -114
// dd-wcs will return 0 even if there are errors
if (line.StartsWith("ERROR:", StringComparison.OrdinalIgnoreCase))
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I take it this is no longer the case, and the sign tool returns an error now if it fails for any reason? Just checking because this was a cause of releasing unsigned artifacts and causing an incident previously 😅

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previous signing tool had many issues so we re-wrote it entirely, and I am pretty confident it should exit with a non-zero status if there is any problem: https://github.com/DataDog/windows-code-signer/blob/ee081a1e9d092654c24a037a3e5c524b6f5cc52e/cmd/windows-code-signer/windows-code-signer.go#L21

Was the signature verification step added after the incident? I would expect it to catch any missing signature.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Was the signature verification step added after the incident? I would expect it to catch any missing signature.

Yes, it was 🙂

@dd-trace-dotnet-ci-bot
Copy link

dd-trace-dotnet-ci-bot bot commented Jan 9, 2026

Execution-Time Benchmarks Report ⏱️

Execution-time results for samples comparing This PR (8033) and master.

✅ No regressions detected - check the details below

Full Metrics Comparison

FakeDbCommand

Metric Master (Mean ± 95% CI) Current (Mean ± 95% CI) Change Status
.NET Framework 4.8 - Baseline
duration68.28 ± (68.24 - 68.46) ms68.48 ± (68.47 - 68.66) ms+0.3%✅⬆️
.NET Framework 4.8 - Bailout
duration72.04 ± (71.98 - 72.19) ms72.34 ± (72.26 - 72.46) ms+0.4%✅⬆️
.NET Framework 4.8 - CallTarget+Inlining+NGEN
duration1003.51 ± (1008.36 - 1016.96) ms1005.83 ± (1007.42 - 1013.00) ms+0.2%✅⬆️
.NET Core 3.1 - Baseline
process.internal_duration_ms21.93 ± (21.90 - 21.96) ms21.82 ± (21.79 - 21.86) ms-0.5%
process.time_to_main_ms78.68 ± (78.54 - 78.83) ms78.70 ± (78.55 - 78.85) ms+0.0%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed10.91 ± (10.91 - 10.92) MB10.92 ± (10.92 - 10.92) MB+0.1%✅⬆️
runtime.dotnet.threads.count12 ± (12 - 12)12 ± (12 - 12)+0.0%
.NET Core 3.1 - Bailout
process.internal_duration_ms21.96 ± (21.93 - 21.98) ms21.83 ± (21.80 - 21.86) ms-0.6%
process.time_to_main_ms79.92 ± (79.82 - 80.03) ms79.88 ± (79.78 - 79.97) ms-0.1%
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed10.95 ± (10.95 - 10.96) MB10.95 ± (10.95 - 10.96) MB-0.0%
runtime.dotnet.threads.count13 ± (13 - 13)13 ± (13 - 13)+0.0%
.NET Core 3.1 - CallTarget+Inlining+NGEN
process.internal_duration_ms240.41 ± (236.40 - 244.42) ms241.05 ± (236.91 - 245.20) ms+0.3%✅⬆️
process.time_to_main_ms471.14 ± (470.56 - 471.72) ms473.00 ± (472.44 - 473.55) ms+0.4%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed48.21 ± (48.19 - 48.24) MB48.17 ± (48.15 - 48.19) MB-0.1%
runtime.dotnet.threads.count28 ± (28 - 28)28 ± (28 - 28)+0.1%✅⬆️
.NET 6 - Baseline
process.internal_duration_ms20.59 ± (20.56 - 20.63) ms20.68 ± (20.65 - 20.71) ms+0.4%✅⬆️
process.time_to_main_ms67.81 ± (67.72 - 67.90) ms68.22 ± (68.11 - 68.33) ms+0.6%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed10.61 ± (10.60 - 10.61) MB10.64 ± (10.64 - 10.64) MB+0.3%✅⬆️
runtime.dotnet.threads.count10 ± (10 - 10)10 ± (10 - 10)+0.0%
.NET 6 - Bailout
process.internal_duration_ms20.59 ± (20.56 - 20.62) ms20.50 ± (20.48 - 20.52) ms-0.5%
process.time_to_main_ms68.97 ± (68.92 - 69.03) ms69.01 ± (68.95 - 69.07) ms+0.1%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed10.70 ± (10.69 - 10.71) MB10.73 ± (10.72 - 10.74) MB+0.3%✅⬆️
runtime.dotnet.threads.count11 ± (11 - 11)11 ± (11 - 11)+0.0%
.NET 6 - CallTarget+Inlining+NGEN
process.internal_duration_ms245.31 ± (243.02 - 247.60) ms246.35 ± (244.61 - 248.10) ms+0.4%✅⬆️
process.time_to_main_ms441.05 ± (440.60 - 441.49) ms441.61 ± (441.18 - 442.05) ms+0.1%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed48.62 ± (48.59 - 48.65) MB48.65 ± (48.62 - 48.68) MB+0.1%✅⬆️
runtime.dotnet.threads.count28 ± (28 - 28)28 ± (28 - 28)+0.6%✅⬆️
.NET 8 - Baseline
process.internal_duration_ms18.79 ± (18.77 - 18.82) ms18.90 ± (18.86 - 18.93) ms+0.6%✅⬆️
process.time_to_main_ms67.19 ± (67.06 - 67.32) ms67.44 ± (67.31 - 67.57) ms+0.4%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed7.66 ± (7.65 - 7.67) MB7.69 ± (7.68 - 7.70) MB+0.3%✅⬆️
runtime.dotnet.threads.count10 ± (10 - 10)10 ± (10 - 10)+0.0%
.NET 8 - Bailout
process.internal_duration_ms18.77 ± (18.74 - 18.80) ms18.92 ± (18.88 - 18.95) ms+0.8%✅⬆️
process.time_to_main_ms68.19 ± (68.13 - 68.26) ms68.52 ± (68.46 - 68.59) ms+0.5%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed7.74 ± (7.73 - 7.75) MB7.72 ± (7.71 - 7.73) MB-0.2%
runtime.dotnet.threads.count11 ± (11 - 11)11 ± (11 - 11)+0.0%
.NET 8 - CallTarget+Inlining+NGEN
process.internal_duration_ms179.66 ± (178.64 - 180.69) ms179.02 ± (178.11 - 179.92) ms-0.4%
process.time_to_main_ms425.83 ± (425.27 - 426.39) ms426.22 ± (425.47 - 426.96) ms+0.1%✅⬆️
runtime.dotnet.exceptions.count0 ± (0 - 0)0 ± (0 - 0)+0.0%
runtime.dotnet.mem.committed36.32 ± (36.29 - 36.36) MB36.33 ± (36.30 - 36.35) MB+0.0%✅⬆️
runtime.dotnet.threads.count27 ± (27 - 27)27 ± (27 - 27)-0.1%

HttpMessageHandler

Metric Master (Mean ± 95% CI) Current (Mean ± 95% CI) Change Status
.NET Framework 4.8 - Baseline
duration192.24 ± (192.19 - 192.86) ms193.34 ± (193.54 - 194.48) ms+0.6%✅⬆️
.NET Framework 4.8 - Bailout
duration196.06 ± (195.93 - 196.52) ms196.40 ± (196.46 - 197.02) ms+0.2%✅⬆️
.NET Framework 4.8 - CallTarget+Inlining+NGEN
duration1106.58 ± (1107.42 - 1114.03) ms1113.13 ± (1115.04 - 1122.61) ms+0.6%✅⬆️
.NET Core 3.1 - Baseline
process.internal_duration_ms187.71 ± (187.29 - 188.13) ms188.94 ± (188.50 - 189.39) ms+0.7%✅⬆️
process.time_to_main_ms80.65 ± (80.40 - 80.90) ms80.70 ± (80.43 - 80.96) ms+0.1%✅⬆️
runtime.dotnet.exceptions.count3 ± (3 - 3)3 ± (3 - 3)+0.0%
runtime.dotnet.mem.committed16.04 ± (16.01 - 16.07) MB16.05 ± (16.02 - 16.08) MB+0.0%✅⬆️
runtime.dotnet.threads.count20 ± (20 - 20)20 ± (19 - 20)-0.3%
.NET Core 3.1 - Bailout
process.internal_duration_ms186.97 ± (186.59 - 187.34) ms187.40 ± (187.12 - 187.68) ms+0.2%✅⬆️
process.time_to_main_ms81.60 ± (81.47 - 81.74) ms81.82 ± (81.68 - 81.95) ms+0.3%✅⬆️
runtime.dotnet.exceptions.count3 ± (3 - 3)3 ± (3 - 3)+0.0%
runtime.dotnet.mem.committed16.15 ± (16.12 - 16.17) MB16.13 ± (16.10 - 16.15) MB-0.1%
runtime.dotnet.threads.count21 ± (21 - 21)21 ± (21 - 21)+0.1%✅⬆️
.NET Core 3.1 - CallTarget+Inlining+NGEN
process.internal_duration_ms416.55 ± (412.99 - 420.12) ms422.32 ± (419.23 - 425.40) ms+1.4%✅⬆️
process.time_to_main_ms473.71 ± (472.97 - 474.45) ms475.50 ± (474.95 - 476.04) ms+0.4%✅⬆️
runtime.dotnet.exceptions.count3 ± (3 - 3)3 ± (3 - 3)+0.0%
runtime.dotnet.mem.committed58.67 ± (58.55 - 58.79) MB58.82 ± (58.73 - 58.92) MB+0.3%✅⬆️
runtime.dotnet.threads.count29 ± (29 - 30)29 ± (29 - 30)+0.1%✅⬆️
.NET 6 - Baseline
process.internal_duration_ms191.77 ± (191.49 - 192.06) ms192.80 ± (192.41 - 193.19) ms+0.5%✅⬆️
process.time_to_main_ms69.41 ± (69.23 - 69.59) ms69.79 ± (69.58 - 70.00) ms+0.5%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed16.13 ± (15.99 - 16.26) MB16.33 ± (16.23 - 16.44) MB+1.3%✅⬆️
runtime.dotnet.threads.count18 ± (18 - 18)19 ± (19 - 19)+3.2%✅⬆️
.NET 6 - Bailout
process.internal_duration_ms192.13 ± (191.75 - 192.51) ms191.48 ± (191.25 - 191.71) ms-0.3%
process.time_to_main_ms70.76 ± (70.63 - 70.90) ms70.67 ± (70.57 - 70.76) ms-0.1%
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed16.12 ± (15.97 - 16.26) MB16.05 ± (15.90 - 16.20) MB-0.4%
runtime.dotnet.threads.count20 ± (20 - 20)19 ± (19 - 20)-2.7%
.NET 6 - CallTarget+Inlining+NGEN
process.internal_duration_ms448.86 ± (445.83 - 451.90) ms454.99 ± (452.22 - 457.76) ms+1.4%✅⬆️
process.time_to_main_ms444.43 ± (443.93 - 444.93) ms448.61 ± (447.97 - 449.24) ms+0.9%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed58.26 ± (58.14 - 58.38) MB58.07 ± (57.94 - 58.19) MB-0.3%
runtime.dotnet.threads.count30 ± (29 - 30)29 ± (29 - 30)-0.2%
.NET 8 - Baseline
process.internal_duration_ms189.97 ± (189.69 - 190.25) ms192.43 ± (192.04 - 192.83) ms+1.3%✅⬆️
process.time_to_main_ms68.82 ± (68.67 - 68.97) ms70.17 ± (69.95 - 70.39) ms+2.0%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed11.74 ± (11.71 - 11.77) MB11.80 ± (11.77 - 11.82) MB+0.5%✅⬆️
runtime.dotnet.threads.count18 ± (18 - 18)18 ± (18 - 18)+0.1%✅⬆️
.NET 8 - Bailout
process.internal_duration_ms189.50 ± (189.23 - 189.78) ms194.94 ± (194.44 - 195.44) ms+2.9%✅⬆️
process.time_to_main_ms69.80 ± (69.70 - 69.90) ms72.14 ± (71.94 - 72.35) ms+3.4%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed11.82 ± (11.79 - 11.85) MB11.81 ± (11.80 - 11.83) MB-0.1%
runtime.dotnet.threads.count19 ± (19 - 19)19 ± (19 - 19)+0.5%✅⬆️
.NET 8 - CallTarget+Inlining+NGEN
process.internal_duration_ms364.80 ± (363.41 - 366.20) ms368.91 ± (367.61 - 370.21) ms+1.1%✅⬆️
process.time_to_main_ms429.22 ± (428.43 - 430.00) ms434.61 ± (433.89 - 435.33) ms+1.3%✅⬆️
runtime.dotnet.exceptions.count4 ± (4 - 4)4 ± (4 - 4)+0.0%
runtime.dotnet.mem.committed47.91 ± (47.88 - 47.94) MB48.08 ± (48.05 - 48.11) MB+0.4%✅⬆️
runtime.dotnet.threads.count29 ± (29 - 29)29 ± (29 - 29)+0.1%✅⬆️
Comparison explanation

Execution-time benchmarks measure the whole time it takes to execute a program, and are intended to measure the one-off costs. Cases where the execution time results for the PR are worse than latest master results are highlighted in **red**. The following thresholds were used for comparing the execution times:

  • Welch test with statistical test for significance of 5%
  • Only results indicating a difference greater than 5% and 5 ms are considered.

Note that these results are based on a single point-in-time result for each branch. For full results, see the dashboard.

Graphs show the p99 interval based on the mean and StdDev of the test run, as well as the mean value of the run (shown as a diamond below the graph).

Duration charts
FakeDbCommand (.NET Framework 4.8)
gantt
    title Execution time (ms) FakeDbCommand (.NET Framework 4.8)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8033) - mean (69ms)  : 67, 70
    master - mean (68ms)  : 67, 70

    section Bailout
    This PR (8033) - mean (72ms)  : 71, 73
    master - mean (72ms)  : 71, 73

    section CallTarget+Inlining+NGEN
    This PR (8033) - mean (1,010ms)  : 970, 1050
    master - mean (1,013ms)  : 949, 1076

Loading
FakeDbCommand (.NET Core 3.1)
gantt
    title Execution time (ms) FakeDbCommand (.NET Core 3.1)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8033) - mean (106ms)  : 103, 108
    master - mean (106ms)  : 104, 108

    section Bailout
    This PR (8033) - mean (107ms)  : 106, 108
    master - mean (107ms)  : 106, 108

    section CallTarget+Inlining+NGEN
    This PR (8033) - mean (738ms)  : 674, 803
    master - mean (737ms)  : 679, 796

Loading
FakeDbCommand (.NET 6)
gantt
    title Execution time (ms) FakeDbCommand (.NET 6)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8033) - mean (94ms)  : 92, 96
    master - mean (93ms)  : 91, 95

    section Bailout
    This PR (8033) - mean (94ms)  : 93, 95
    master - mean (94ms)  : 93, 95

    section CallTarget+Inlining+NGEN
    This PR (8033) - mean (714ms)  : 685, 743
    master - mean (711ms)  : 674, 747

Loading
FakeDbCommand (.NET 8)
gantt
    title Execution time (ms) FakeDbCommand (.NET 8)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8033) - mean (93ms)  : 90, 95
    master - mean (92ms)  : 89, 95

    section Bailout
    This PR (8033) - mean (93ms)  : 92, 95
    master - mean (93ms)  : 92, 94

    section CallTarget+Inlining+NGEN
    This PR (8033) - mean (634ms)  : 619, 650
    master - mean (633ms)  : 619, 646

Loading
HttpMessageHandler (.NET Framework 4.8)
gantt
    title Execution time (ms) HttpMessageHandler (.NET Framework 4.8)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8033) - mean (194ms)  : 188, 200
    master - mean (193ms)  : 189, 196

    section Bailout
    This PR (8033) - mean (197ms)  : 194, 200
    master - mean (196ms)  : 193, 199

    section CallTarget+Inlining+NGEN
    This PR (8033) - mean (1,119ms)  : 1065, 1173
    master - mean (1,111ms)  : 1063, 1158

Loading
HttpMessageHandler (.NET Core 3.1)
gantt
    title Execution time (ms) HttpMessageHandler (.NET Core 3.1)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8033) - mean (278ms)  : 272, 284
    master - mean (277ms)  : 270, 283

    section Bailout
    This PR (8033) - mean (278ms)  : 273, 282
    master - mean (277ms)  : 273, 280

    section CallTarget+Inlining+NGEN
    This PR (8033) - mean (927ms)  : 875, 978
    master - mean (921ms)  : 870, 973

Loading
HttpMessageHandler (.NET 6)
gantt
    title Execution time (ms) HttpMessageHandler (.NET 6)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8033) - mean (271ms)  : 265, 277
    master - mean (269ms)  : 265, 274

    section Bailout
    This PR (8033) - mean (270ms)  : 267, 273
    master - mean (271ms)  : 266, 276

    section CallTarget+Inlining+NGEN
    This PR (8033) - mean (935ms)  : 894, 975
    master - mean (921ms)  : 871, 971

Loading
HttpMessageHandler (.NET 8)
gantt
    title Execution time (ms) HttpMessageHandler (.NET 8)
    dateFormat  x
    axisFormat %Q
    todayMarker off
    section Baseline
    This PR (8033) - mean (273ms)  : 267, 278
    master - mean (269ms)  : 264, 273

    section Bailout
    This PR (8033) - mean (277ms)  : 267, 286
    master - mean (269ms)  : 264, 273

    section CallTarget+Inlining+NGEN
    This PR (8033) - mean (834ms)  : 803, 864
    master - mean (825ms)  : 803, 846

Loading

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:builds project files, build scripts, pipelines, versioning, releases, packages

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants