Skip to content

Create profiler snapshot and JFR CLI temp files under configured tempdir - #12484

Merged
gh-worker-dd-mergequeue-cf854d[bot] merged 2 commits into
masterfrom
reshmi/scp-1361-snapshot-tempdir
Sep 14, 2026
Merged

gh-worker-dd-mergequeue-cf854d[bot] merged 2 commits into
masterfrom
reshmi/scp-1361-snapshot-tempdir

Conversation

@anandreshmi46

@anandreshmi46 anandreshmi46 commented Sep 14, 2026 •

Copy link
Copy Markdown
Collaborator

What Does This Do

Routes profiler snapshot files and the jfr-cli helper's scratch file through TempLocationManager-backed locations instead of the JVM default temp directory:

  • DatadogProfilerRecording.snapshot() now creates its file via DatadogProfiler.newSnapshotFile(), which reuses the profiler's existing recordingsPath (the same directory already used for regular recordings).
  • JfrCliHelper.invokeOn() now creates its scratch recording file under a jfr-cli subdirectory obtained from TempLocationManager.getInstance().getTempDir(...), instead of File.createTempFile(...)

Motivation

Snapshot files and the jfr-cli helper's scratch file were created via Files.createTempFile()/File.createTempFile() with no directory argument, which falls back to the JVM default java.io.tmpdir (/tmp). On hardened K8s pods with a read-only root filesystem and only a custom tempdir mounted (dd.profiling.tempdir / FlightRecorderOptions repository), this throws:

FileSystemException: Read-only file system

Both now go through TempLocationManager-backed locations: snapshots reuse DatadogProfiler's recordingsPath (same dir as regular recordings), and the jfr-cli helper gets its own subdirectory under the managed temp dir.

Fixes SCP-1361

Additional Notes

  • Added a regression assertion in DatadogProfilerRecordingTest#testSnapshot verifying the snapshot file's parent directory matches the main recording file's parent (i.e. it no longer lands in the JVM default temp dir).
  • ./gradlew :dd-java-agent:agent-profiling:profiling-ddprof:test :dd-java-agent:agent-profiling:profiling-uploader:test passes.
  • spotlessApply, /techdebt, and /perf-review all came back clean — no further changes needed.

Contributor Checklist

Jira ticket: SCP-1361

Snapshot files and the jfr-cli helper's scratch file were created via
Files.createTempFile()/File.createTempFile() with no directory argument,
which falls back to the JVM default java.io.tmpdir (/tmp). On hardened
K8s pods with a read-only root filesystem and only a custom tempdir
mounted (dd.profiling.tempdir / FlightRecorderOptions repository), this
throws FileSystemException: Read-only file system.

Both now go through TempLocationManager-backed locations: snapshots
reuse DatadogProfiler's recordingsPath (same dir as regular recordings),
and the jfr-cli helper gets its own subdirectory under the managed temp
dir.

Fixes SCP-1361.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@anandreshmi46
anandreshmi46 requested a review from a team as a code owner September 14, 2026 12:27
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T12:30:26.567117Z 74a8927 PR opened
🔒 Security Review ✅ Completed 2026-09-14T12:31:15.816559Z 74a8927 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@dd-octo-sts dd-octo-sts Bot added the tag: ai generated Largely based on code generated by an AI or LLM label Sep 14, 2026
@dd-octo-sts

dd-octo-sts Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Hi! 👋 Thanks for your pull request! 🎉

To help us review it, please make sure to:

  • Add at least one type, and one component or instrumentation label to the pull request

If you need help, please check our contributing guidelines.

@datadog-prod-us1-5 datadog-prod-us1-5 Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Datadog Autotest: PASS

More details

Both temporary-file paths now use managed profiling directories. Cleanup still removes the JFR CLI scratch file, and the static review found no concrete failure.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Datadog Autotest · Commit 74a8927 · What is Autotest? · @DataDog review to ask questions · Any feedback? Reach out in #autotest

@datadog-prod-us1-5

This comment has been minimized.

@anandreshmi46
anandreshmi46 requested review from jard-io and jbachorik and removed request for jard-io September 14, 2026 12:34
@dd-octo-sts

dd-octo-sts Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

🟢 Java Benchmark SLOs — All performance SLOs passed

Suite Status
Startup 🟢 pass

SLO thresholds are defined here based on automatically generated metrics. A warning is raised when results are within 5% of the threshold.

PR vs. master results
Scenario Candidate master Δ (95% CI of mean)
startup:insecure-bank:iast:Agent 14.86 s 14.71 s [+0.1%; +1.9%] (maybe worse)
startup:insecure-bank:tracing:Agent 13.70 s 13.60 s [-0.2%; +1.7%] (no difference)
startup:petclinic:appsec:Agent 17.02 s 16.58 s [-1.8%; +7.1%] (no difference)
startup:petclinic:iast:Agent 16.99 s 17.04 s [-1.2%; +0.6%] (no difference)
startup:petclinic:profiling:Agent 16.70 s 16.91 s [-2.2%; -0.3%] (maybe better)
startup:petclinic:sca:Agent 16.89 s 16.75 s [-0.2%; +1.8%] (no difference)
startup:petclinic:tracing:Agent 16.17 s 16.04 s [-0.0%; +1.6%] (no difference)

Commit: 7b2587f3 · CI Pipeline · Benchmarking Platform UI


Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion.

@jbachorik jbachorik left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks for fixing this!

@anandreshmi46
anandreshmi46 added this pull request to the merge queue Sep 14, 2026
@dd-octo-sts

dd-octo-sts Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-09-14 16:00:58 UTC ℹ️ Start processing command /merge


2026-09-14 16:01:03 UTC ℹ️ MergeQueue: pull request added to the queue

The expected merge time in master is approximately 1h (p90).


2026-09-14 16:58:17 UTC ℹ️ MergeQueue: This merge request was merged

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 14, 2026
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot merged commit bd66fb5 into master Sep 14, 2026
603 checks passed
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot deleted the reshmi/scp-1361-snapshot-tempdir branch September 14, 2026 16:58
@github-actions github-actions Bot added this to the 1.67.0 milestone Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp: profiling Profiling tag: ai generated Largely based on code generated by an AI or LLM type: bug fix Bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants