Bug fixes
Security bulletin NR18-06:
Fixes issue introduced in 2.8.0 where the agent may have captured all transaction attributes, even with High-security mode enabled on the account. This may have included sensitive data attached to transactions.
Removed support for agent attributes include/exclude rules.
These will be coming back in Node Agent v3.0.0. The fix for the above security bulletin required a backwards incompatible change to our attributes.
Fixed bug in Bluebird instrumentation.
Some methods were not instrumented correctly. This would cause a problem if a function was passed to these methods.
Special thanks to Andreas Lind (@papandreou) for helping us find this bug.
Note
This release is deprecated due to an issue where the agent may capture transaction attributes regardless of agent settings. If you are using this release, upgrade your agent to agent version 2.9.1 or higher. For more information, see Security Bulletin NR18-06.
Improvements
Added the
WebFrameworkShim#savePossibleTransactionNamemethod.This method may be used to mark the current running middleware as a potential responder.
savePossibleTransactionNameshould be used if a middleware can't be determined to be a terminal middleware while it executes, but may be responsible for responding after execution has finished.Fixed
dns.resolveresults assertion.Expanded
async_hookstests around maintain transaction context.Added Koa to metric naming objects.
Added
callbackprop tomiddlewareWithPromiseRecorderreturn spec.While we aren't actually wrapping any callback, this is a workaround that gives us access to the active segment. This ensures that all segments inside Koa transaction traces are named correctly, particularly in cases when transaction context may be lost.
Updated
afterprop inmiddlewareWithPromiseRecorderreturn spec to settxInfo.errorHandled = truein cases when there is no error.Because Koa has no concept of errorware in the same sense as Express or Connect (
(err, req, res, next)), the agent now assumes if a middleware resolves, any error that may have occurred can be marked as handled.
Fixes
- Added check for
parentSegmentinasync_hooksinstrumentation, to help ensure that transaction context is maintained.
Note
This release is deprecated due to an issue where the agent may capture transaction attributes regardless of agent settings. If you are using this release, upgrade your agent to agent version 2.9.1 or higher. For more information, see Security Bulletin NR18-06.
New features
Added instrumentation support for MongoDB version 3.
Version 3 of mongodb is now supported. Previously datastore host information (instance metrics) was incorrectly captured by the agent with
mongodbv3. This has been fixed and all features should be functional now.
Improvements
Updated documentation for
apdex_tsetting and removed environment variable.This was never configurable on client side and the documentation was misleading.
Documented environment variables for
slow_sqlconfigurations.Thanks to Olivier Tassinari (@oliviertassinari) for the update!
Updated
hapi/hapi-pre-17/package.jsonto runerrors.tap.jsin more versions.Added internal cache to unwrapped core modules for agent use.
Improved logging around environment facts gathering.
Bug fixes
Enable certain agent attributes when high-security mode is enabled.
During the switch from the old
capture_params/ignored_paramsto the new attribute include/exclude rules, high-security mode was over-zealous in what attributes it disallowed. This has been trimmed back to be in line with other agents.
Notes
Changed
attributes.enabledtotrueby default.In the previous version we defaulted this to
falseto maintain parity withcapture_paramswhich defaulted tofalse. However, this is a invalid parity becauseattribute.enabledcontrols more attributes thancapture_params.
Improvements
Removed unnecessary checks around
Timer.unref()calls.unrefhas been supported since Node v0.9, meaning it will always be present in timers set by the agent (with 0.10 being the earliest supported version).Added a split in the node versions for the
mysql2andcassandraversioned tests.As of
mysql2v1.3.1 andcassandrav3.4.0 the minimum supported version of Node is 4.Replaced as many instances of
{}as possible withObject.create(null).Removed extraneous logger arg in
addCustomAttributecall.
Bug fixes
The agent will no longer generate browser data for ignored transactions.
Expanded Hapi instrumentation to support route
prehandlers.This is a Hapi route config option that was previously uninstrumented, causing transaction names to become invalid. This expanded instrumentation ensures that all additional handlers are wrapped and associated with the main route.
新機能
includeおよびexcludeルールによるエージェント属性のフィルタリングを追加しました。
エージェント属性は、きめ細かい包含および除外ルールを使用して制御できるようになりました。以下で説明するこれらのルールは、
capture_paramsおよびignored_paramsを置き換えます。attributes.excludeが明示的に設定されていない限り、ignored_paramsにリストされているすべての属性は内部的にattributes.excludeに移行されます。ルート設定と各宛先に、3つの新しい設定プロパティが追加されました(宛先については後述します)。これらの新しい設定は次のとおりです:
attributes.enabled- 宛先に対する属性の収集を有効にします。attributes.include- 含める属性またはワイルドカードルールのリスト。attributes.exclude- 除外する属性またはワイルドカードルールのリスト。
インクルードルールとエクスクルードルールは、完全一致ルール(たとえば
request.headers.contentLength)、または属性キーの先頭のみに一致するワイルドカードルール(たとえばrequest.headers.*は任意のリクエストヘッダーに一致します)にすることができます。これらのルールは、設定のルートでグローバルに、または特定の宛先に対して指定できます。これらの宛先は次のとおりです:
transaction_tracer- トランザクショントレース属性を制御します。transaction_events- トランザクションイベント属性を制御します。error_collector- エラーイベントの属性を制御します。browser_monitoring- ブラウザ/RUMトランザクション属性を制御します。
addCustomParameterをaddCustomAttributeに名前変更しました。addCustomParameterメソッドは非推奨となり、エージェントの将来のリリースで削除される予定です。addCustomAttributeメソッドは、そのドロップイン代替手段です。エージェント属性のフィルタリングにキャッシュを追加しました。
属性ルールの適用によるオーバーヘッドを最小限に抑えるため、エージェントは特定の属性キーと宛先のフィルタリング結果をキャッシュします。キャッシュはデフォルトで1,000個の宛先とキーのペアに制限されていますが、
attributes.filter_cache_limitで設定できます。このキャッシュにより、キャッシュのヒットに対するフィルタールールの適用が10倍向上します。設定オプションに
allow_all_headersを追加し、httpの計装を更新しました。trueに設定すると、エージェントはすべてのリクエストヘッダーを収集します。この収集は、エージェント属性の包含および除外ルールに従います。デフォルトの除外ルールセットはnewrelic.jsで提供されています。これらのルールは、すべてのCookieと認証ヘッダーを除外します。セグメントをopaqueとしてフラグ付けできるようになり、内部セグメントがトランザクショントレースから除外されるようになりました。
改良点
監視オーバーヘッドを抑えるため、エージェント属性に制限を追加しました。
属性のキーと値は、それぞれ255バイトに制限されています。255バイトを超えるキーは破棄され、警告メッセージがログに記録されます。255バイトを超える値は、マルチバイトUTF-8エンコーディングを考慮して255バイトに切り捨てられます。カスタムアトリビュートは、トランザクションごとに64個に制限されています。64番目を超える属性は、暗黙的に無視されます。
コレクター接続失敗のログメッセージにエラーを追加しました。
request_uri属性の名前をrequest.uriに変更しました。これにより、属性名が他のすべてのリクエスト属性と一致するようになります。
https-proxy-agentの依存関係を^0.3.5から^0.3.6に更新しました。インストゥルメントされたモジュールのほとんどのマイナーバージョンが期待どおりに動作することを確認するため、該当する場合はバージョン管理されたテストを更新しました。
Mongoドライバーのv1ラインのテストが停止する問題を修正しました。
Hapi 404トランザクションが正しく名前付けされたメトリクスになることを検証するテストを追加しました。
Hapiの計装は正しく機能していましたが、この特定のケースに対するテストがありませんでした。
バグ修正
crypto.DEFAULT_ENCODINGが変更されたときに、エージェントがクラッシュすることはなくなります。以前は、エージェントは
hash.digest()の結果がBufferのインスタンスであると想定していました。crypto.DEFAULT_ENCODINGが変更されると、hash.digest()は文字列を返し、エージェントはクラッシュしていました。エージェントは、処理を進める前に値がBufferインスタンスであることを確認するようになりました。process.config.variables.node_prefixが欠落している場合のエラーを修正しました。process.config.variables.node_prefixがfalseyの場合(これはelectronを使用している場合に発生する可能性があり、この問題https://support.newrelic.com/s/hubtopic/aAX8W0000008ZMO/new-relic-on-electron-nodejsにつながります)lib/environment.jsのgetGlobalPackages関数は、エラーになるべきではないときにエラーを返します。修正を提供してくれたJarred Filmer(@BrighTide)に感謝します!
Improvements
- Added regression test for promise instrumentation and stack overflows.
Bug fixes
Fixed naming bug in Restify instrumentation regarding parameters to
next.The instrumentation previously considered any truthy value passed to
nextto be an error. It is possible to pass a string or boolean tonextin Restify to control further routing of the request. This would cause the middleware's mounting path to be erroneously appended to the transaction name.Fixed access to
bluebird.coroutine.addYieldHandler.This was accidentally not copied by our instrumentation making access to the function fail. This has been resolved and tests expanded to ensure no other properties were missed.
New features
Added
transaction_tracer.hide_internalsconfiguration.This configuration controls the enumerability of the internal properties of the agent. Making these properties non-enumerable can have an impact on the performance of the agent. Disabling this option may decrease agent overhead.
Improvements
Refactored promise instrumentation.
This new instrumentation is far more performant than the previous and maintains a more sensible trace structure under a wider range of sequences.
Added concurrent environment scanning, limited to 2 reads at a time.
This improves the performance of dependency scanning at agent startup, allowing the agent to connect to our services more quickly.
Refactored instrumentation tests to run against wide range of module versions.
Instrumentation tests will be run against all supported major versions of every instrumented module. For releases, we will test against every supported minor version of the modules. This vastly improves our test coverage and should reduce the instances of regressions for specific versions of modules.
Added tests for all of bluebird's promise methods.
These tests ensure that we 100% instrument bluebird. Some gaps in instrumentation were found and fixed. Anyone using bluebird should upgrade.
Bug fixes
Fixed a crashing error in the hapi instrumentation.
When recording the execution of an extension listening to a server event (for example, 'onPreStart') the agent would crash due to the lack of a
rawproperty on the first argument passed to the extension handler. The agent now checks the event before wrapping the extension handler and checks for the existence of therawproperty before attempting to dereference off of it.Fixed an incompatibility with the npm module
mimic-response.The agent's HTTP instrumentation previously did not play well with the way
mimic-responsecopied properties from anhttp.IncomingMessage. This caused modules that relied on that process, such asgot, to hang.Fixed naming rule testing tool to use same url scrubbing as the agent itself.
New features
Added hapi v17 instrumentation
Hapi v17 added support for promise-based middleware which broke transaction tracking in the agent. This caused issues in naming, as the agent will name the transaction after the path to the middleware that responded to a request.
Added instrumentation for
vision@5Due to the way
visionis mounted to the hapi server when using hapi v17.x, the agent's instrumentation would not pick up on the middleware being mounted. This new instrumentation now correctly times rendering done in thevisionmiddleware.Added
unwrapOncemethod to shim objectThis new method can be used to unwrap a single layer of instrumentation.
unwrapOnceis useful in cases where multiple instrumentations wrap the same method and unwrapping of the top level is required.Added
isErrorWarechecks aroundnameState.appendPath/nameState.popPathcalls to avoid doubling up paths in transaction namesPreviously, the agent would append its transaction name with the path fragment where an error handler middleware was mounted. The extraneous path fragment will now be omitted, and the transaction will be named properly after the middleware that threw the error.
Added support for
pg6 on Node 5 or higher
Improvements
- Added
parentproperty to webframework-shim segment description - Refactored existing hapi instrumentation for different
server.ext()invocations - Refactored webframework-shim
_recordMiddlewareto construct different segment descriptions for callback- or promise-based middleware - Updated
node-postgres@^6versioned tests to avoid deprecation warning on direct moduleconnectandendcalls - Fixed running domain tests on Node 9.3.0.
- Improved logging for CAT headers and transaction name-state management.
- All
json-safe-stringifycalls now wrapped intry/catch - Removed
lib/util/safe-json
Bug fixes
- Fixed creating supportability metric when mysql2 goes uninstrumented.
- Added a
segmentStack.popto the middlewareafterin cases when an error is caught and there is no next handler - Fixed determining parents for middleware segments when transaction state is lost and reinstated
- Added check to
_recordMiddlewareto avoid prepending a slash if originalrouteis an array - Changed logic in http instrumentation to attach
response.statusto the transaction as a string - Updated
startWebTransactionandstartBackgroundTransactionto add nested transactions as segments to parent transactions
Notes
- Added Peter Svetlichny to the contributors list!
Improvements
- Optimized
NameState#getPath. - Optimized
shim.record. - Optimized
shim.recordMiddleware. - Upgraded
eslintto v4.
Bug fixes
- Fixed parsing SQL for queries containing newlines.