Skip to content

fix(ci): renew PHP FTP test certificate#4060

Merged
realFlowControl merged 3 commits into
masterfrom
florian/renew-php-ftp-test-certificate
Jul 25, 2026
Merged

fix(ci): renew PHP FTP test certificate#4060
realFlowControl merged 3 commits into
masterfrom
florian/renew-php-ftp-test-certificate

Conversation

@realFlowControl

@realFlowControl realFlowControl commented Jul 24, 2026

Copy link
Copy Markdown
Member

Description

PHP language tests started failing after the certificate bundled in ext/ftp/tests/cert.pem expired on 2026-07-23. This vendors the regenerated certificate from php/php-src#22873 and copies it into the final layer of every Bookworm PHP image.

This promotes Bookworm image version 10 to current, sets version 11 as next, and migrates all GitLab CI, GitHub Actions, Docker Compose, and debug-artifact consumers from bookworm-9 to the published bookworm-10 images.

Testing

  • Verified all 14 version-10 image manifests are available from the internal registry and Docker Hub for amd64 and arm64.
  • Verified all PHP CI generators parse and no tracked version-9 Bookworm consumer references remain.
  • Verified Docker Compose consumers resolve to version 10 and future image builds resolve to version 11.
  • Built the final certificate layer on datadog/dd-trace-ci:php-8.5_bookworm-9 for amd64.
  • Verified ext/standard/tests/streams/opendir-003.phpt passes with PHP 8.5 NTS and ZTS.
  • Verified the renewed certificate passes the same test with PHP 7.1 ZTS.

Reviewer checklist

  • Test coverage seems ok.
  • Appropriate labels assigned.

@datadog-official

datadog-official Bot commented Jul 24, 2026

Copy link
Copy Markdown

Pipelines  Tests

Unblock PR with BitsAI

⚠️ Warnings

🚦 10 Pipeline jobs failed

DataDog/apm-reliability/dd-trace-php | ASAN test_c with multiple observers: [8.4]   View in Datadog   GitLab

DataDog/apm-reliability/dd-trace-php | Extension Tea Tests: [7.2, nts]   View in Datadog   GitLab

DataDog/apm-reliability/dd-trace-php | benchmarks-tracer   View in Datadog   GitLab

View all 10 failed jobs.

ℹ️ Info

No other issues found (see more)

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 54.08% (+2.60%)

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 7c89821 | Docs | Datadog PR Page | Give us feedback!

@pr-commenter

pr-commenter Bot commented Jul 24, 2026

Copy link
Copy Markdown

Benchmarks [ tracer ]

Benchmark execution time: 2026-07-24 12:46:52

Comparing candidate commit 2ae702a in PR branch florian/renew-php-ftp-test-certificate with baseline commit 024fe4a in branch master.

Found 2 performance improvements and 0 performance regressions! Performance is the same for 192 metrics, 0 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

scenario:EmptyFileBench/benchEmptyFileBaseline-opcache

  • 🟩 execution_time [-823.882µs; -589.778µs] or [-24.485%; -17.527%]

scenario:EmptyFileBench/benchEmptyFileOverhead-opcache

  • 🟩 execution_time [-1044.268µs; -793.972µs] or [-29.161%; -22.171%]

@realFlowControl
realFlowControl marked this pull request as ready for review July 25, 2026 09:07
@realFlowControl
realFlowControl requested a review from a team as a code owner July 25, 2026 09:07
@realFlowControl
realFlowControl merged commit 39036dc into master Jul 25, 2026
2146 of 2157 checks passed
@realFlowControl
realFlowControl deleted the florian/renew-php-ftp-test-certificate branch July 25, 2026 15:03
@github-actions github-actions Bot added this to the 1.24.0 milestone Jul 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants