Bump Bazel to 9.2.0 for remote cache and Windows fixes - #53619
Conversation
### What does this PR do? Bump the pinned Bazel version from 9.1.1 to 9.2.0 and refresh MODULE.bazel.lock accordingly (bazel mod deps). ### Motivation Bazel 9.2.0 (2026-07-13) ships three fixes this repo has been working around over the past month: - bazelbuild/bazel#29984 (mine) fixes the 8dot3/MAX_PATH launcher failure that #52500 works around with a bazel.bat preflight check. - bazelbuild/bazel#30182 (mine) embeds an asInvoker UAC manifest in the Windows launcher stub, fixing the installer-detection error 740 that #52061 and #53591 work around via __COMPAT_LAYER=RunAsInvoker. - bazelbuild/bazel#30193 closes the tree-artifact action-rewinding gap flagged as an open caveat in #53356. The root cache-eviction issue, bazelbuild/bazel#27929, is still open upstream, so #53434 (disabling --disk_cache in CI) should stay in place pending its own re-test. Also worth noting, though not tied to a specific incident here: - bazelbuild/bazel#29898 enables TCP keepalive by default for gRPC connections, which could reduce idle-connection drops of the kind behind the Windows Docker DNS flakiness in #52407. - bazelbuild/bazel#29885 removes the gRPC response message-size cap from the remote executor/cache, relevant given this repo's buildbarn-backed remote cache and RBE lost-input history. - bazelbuild/bazel#30194 stops env var changes from triggering full package reloads in external repos, relevant given the long --repo_env list in .bazelrc and mixed interactive/IDE bazel invocations. - bazelbuild/bazel#29807 fixes a Bazel-9-only RepoMappingManifest CPU regression, a straight perf win independent of any incident. ### Describe how you validated your changes bazel version reports 9.2.0 after bazelisk re-bootstraps. bazel build //pkg/config/schema/... completes successfully. bazel shutdown followed by bazel mod deps --lockfile_mode=refresh leaves MODULE.bazel.lock unchanged, matching the exact check the bazel:mod-deps CI lint job runs. ### Additional Notes None of the .bazelrc UAC/8dot3 workarounds (#52500, #52061, #53591) are removed here; each needs its own re-verification on the Windows VM before being reverted as a follow-up.
Files inventory check summaryFile checks results against ancestor 84c4b65e: Results for datadog-agent_7.83.0~devel.git.86.d1c518c.pipeline.124468253-1_amd64.deb:No change detected |
Static quality checks✅ Please find below the results from static quality gates 33 successful checks with minimal change (< 2 KiB)
|
Regression DetectorRegression Detector ResultsMetrics dashboard Baseline: 0f59341 Optimization Goals: ✅ No significant changes detected
|
| perf | experiment | goal | Δ mean % | Δ mean % CI | trials | links |
|---|---|---|---|---|---|---|
| ➖ | quality_gate_logs | % cpu utilization | +3.14 | [+2.12, +4.16] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle | memory utilization | +0.41 | [+0.35, +0.46] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_no_fs_load | memory utilization | +0.13 | [+0.04, +0.22] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_mean_fs_load | memory utilization | +0.05 | [+0.01, +0.09] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_idle_all_features | memory utilization | -0.22 | [-0.29, -0.15] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_security_idle | memory utilization | -0.34 | [-0.40, -0.28] | 1 | Logs bounds checks dashboard |
| ➖ | quality_gate_metrics_logs | memory utilization | -0.34 | [-0.59, -0.10] | 1 | Logs bounds checks dashboard |
Bounds Checks: ✅ Passed
| perf | experiment | bounds_check_name | replicates_passed | observed_value | links |
|---|---|---|---|---|---|
| ✅ | quality_gate_idle | intake_connections | 10/10 | 3 ≤ 4 | bounds checks dashboard |
| ✅ | quality_gate_idle | memory_usage | 10/10 | 146.43MiB ≤ 154MiB | bounds checks dashboard |
| ✅ | quality_gate_idle | total_bytes_received | 10/10 | 731.15KiB ≤ 819.20KiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | intake_connections | 10/10 | 3 ≤ 4 | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | memory_usage | 10/10 | 494.15MiB ≤ 495MiB | bounds checks dashboard |
| ✅ | quality_gate_idle_all_features | total_bytes_received | 10/10 | 1.12MiB ≤ 1.25MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | intake_connections | 10/10 | 4 ≤ 6 | bounds checks dashboard |
| ✅ | quality_gate_logs | memory_usage | 10/10 | 184.05MiB ≤ 195MiB | bounds checks dashboard |
| ✅ | quality_gate_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_logs | total_bytes_received | 10/10 | 264.39MiB ≤ 292MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | cpu_usage | 10/10 | 355.12 ≤ 2000 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | intake_connections | 10/10 | 3 ≤ 6 | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | memory_usage | 10/10 | 393.74MiB ≤ 430MiB | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | missed_bytes | 10/10 | 0B = 0B | bounds checks dashboard |
| ✅ | quality_gate_metrics_logs | total_bytes_received | 10/10 | 0.94GiB ≤ 1.04GiB | bounds checks dashboard |
| ✅ | quality_gate_security_idle | cpu_usage | 10/10 | 38.53 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_security_idle | memory_usage | 10/10 | 299.55MiB ≤ 330MiB | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | cpu_usage | 10/10 | 74.42 ≤ 80 | bounds checks dashboard |
| ✅ | quality_gate_security_mean_fs_load | memory_usage | 10/10 | 279.16MiB ≤ 310MiB | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | cpu_usage | 10/10 | 35.56 ≤ 40 | bounds checks dashboard |
| ✅ | quality_gate_security_no_fs_load | memory_usage | 10/10 | 288.76MiB ≤ 320MiB | bounds checks dashboard |
Explanation
Confidence level: 90.00%
Effect size tolerance: |Δ mean %| ≥ 5.00%
Performance changes are noted in the perf column of each table:
- ✅ = significantly better comparison variant performance
- ❌ = significantly worse comparison variant performance
- ➖ = no significant change in performance
A regression test is an A/B test of target performance in a repeatable rig, where "performance" is measured as "comparison variant minus baseline variant" for an optimization goal (e.g., ingress throughput). Due to intrinsic variability in measuring that goal, we can only estimate its mean value for each experiment; we report uncertainty in that value as a 90.00% confidence interval denoted "Δ mean % CI".
For each experiment, we decide whether a change in performance is a "regression" -- a change worth investigating further -- if all of the following criteria are true:
-
Its estimated |Δ mean %| ≥ 5.00%, indicating the change is big enough to merit a closer look.
-
Its 90.00% confidence interval "Δ mean % CI" does not contain zero, indicating that if our statistical model is accurate, there is at least a 90.00% chance there is a difference in performance between baseline and comparison variants.
-
Its configuration does not mark it "erratic".
Replicate Execution Details
We run multiple replicates for each experiment/variant. However, we allow replicates to be automatically retried if there are any failures, up to 8 times, at which point the replicate is marked dead and we are unable to run analysis for the entire experiment. We call each of these attempts at running replicates a replicate execution. This section lists all replicate executions that failed due to the target crashing or being oom killed.
Note: In the below tables we bucket failures by experiment, variant, and failure type. For each of these buckets we list out the replicate indexes that failed with an annotation signifying how many times said replicate failed with the given failure mode. In the below example the baseline variant of the experiment named experiment_with_failures had two replicates that failed by oom kills. Replicate 0, which failed 8 executions, and replicate 1 which failed 6 executions, all with the same failure mode.
| Experiment | Variant | Replicates | Failure | Logs | Debug Dashboard |
|---|---|---|---|---|---|
| experiment_with_failures | baseline | 0 (x8) 1 (x6) | Oom killed | Debug Dashboard |
The debug dashboard links will take you to a debugging dashboard specifically designed to investigate replicate execution failures.
❌ Retried Profiling Replicate Execution Failures (ddprof)
Note: Profiling replicas may still be executing. See the debug dashboard for up to date status.
| Experiment | Variant | Replicates | Failure | Debug Dashboard |
|---|---|---|---|---|
| quality_gate_idle | baseline | 10 | Oom killed | Debug Dashboard |
| quality_gate_idle_all_features | baseline | 10 | Oom killed | Debug Dashboard |
| quality_gate_idle_all_features | comparison | 10 | Oom killed | Debug Dashboard |
| quality_gate_logs | baseline | 10 | Oom killed | Debug Dashboard |
| quality_gate_logs | comparison | 10 | Oom killed | Debug Dashboard |
| quality_gate_metrics_logs | baseline | 10 | Oom killed | Debug Dashboard |
| quality_gate_metrics_logs | comparison | 10 | Oom killed | Debug Dashboard |
| quality_gate_security_idle | baseline | 10 | Oom killed | Debug Dashboard |
| quality_gate_security_no_fs_load | baseline | 10 | Crashed (exit code: 134) | Debug Dashboard |
| quality_gate_security_no_fs_load | comparison | 10 | Oom killed | Debug Dashboard |
CI Pass/Fail Decision
✅ Passed. All Quality Gates passed.
- quality_gate_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check missed_bytes: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_metrics_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check intake_connections: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check total_bytes_received: 10/10 replicas passed. Gate passed.
- quality_gate_idle_all_features, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_mean_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_idle, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check memory_usage: 10/10 replicas passed. Gate passed.
- quality_gate_security_no_fs_load, bounds check cpu_usage: 10/10 replicas passed. Gate passed.
695123c
into
main
|
Backport evaluation: View Slack thread |
|
This usually happens when the cherry-pick has merge conflicts and needs manual resolution. To backport manually, run: git fetch
git worktree add .worktrees/backport-7.82.x 7.82.x
cd .worktrees/backport-7.82.x
git switch --create backport-53619-to-7.82.x
git cherry-pick -x --mainline 1 695123cb8f59c89b370b6f1e6908ca02bf78144c
git push --set-upstream origin backport-53619-to-7.82.xWorkflow logs: https://github.com/DataDog/datadog-agent/actions/runs/32467791018 |
…xes (#53619) (#55228) Bump the pinned Bazel version from 9.1.1 to 9.2.0 and refresh `MODULE.bazel.lock` accordingly. Bazel 9.2.0 ships fixes this repo has been working around over the past month. Our contributions: - bazelbuild/bazel#29984, which should remove the need for temporary countermeasures we had to come up with: - DataDog/datadog-agent-buildimages#1212 (alas ineffective), - DataDog/datadog-agent-buildimages#1215 (effective), - #52500, - bazelbuild/bazel#30182, which should remove the need for: - #52061, - #53591. - bazelbuild/bazel#29791, - bazelbuild/bazel#29868, - bazelbuild/bazel#29885, - bazelbuild/bazel#30193, a caveat mentioned in: - #53356. Also worth noting, though not tied to a specific incident here: - bazelbuild/bazel#29807, - bazelbuild/bazel#29898, - bazelbuild/bazel#30194. `bazel version` reports 9.2.0 after `bazelisk` re-bootstraps. `bazel build //pkg/config/schema/...` completes successfully. `bazel shutdown` followed by `bazel mod deps --lockfile_mode=refresh` leaves `MODULE.bazel.lock` unchanged. None of the .bazelrc UAC/8dot3 workarounds (DataDog/datadog-agent-buildimages#1215, #52500, #52061, #53591) are removed here. Each needs its own re-verification on Windows before being reverted as follow-ups. (cherry picked from commit 695123c) <!--Please give us some feedback on your experience writing this PR ! https://app.datadoghq.com/forms/43db4c02-6837-400c-8083-692e141b1b88 !--> ### What does this PR do? ### Motivation ### Describe how you validated your changes ### Additional Notes Co-authored-by: rdesgroppes <rdesgroppes@gmail.com> Co-authored-by: ali.benabdallah <ali.benabdallah@datadoghq.com>
What does this PR do?
Bump the pinned Bazel version from 9.1.1 to 9.2.0 and refresh
MODULE.bazel.lockaccordingly.Motivation
Bazel 9.2.0 ships fixes this repo has been working around over the past month.
Windows issues
Our contributions:
bazel.batearly if 8.3 short names are disabled in Windows #52500,asInvokerUAC manifest in the Windows launcher stub" (https://github.com/bazelbuild/bazel/pull/30043) bazelbuild/bazel#30182, which should remove the need for:bazel run *install*for non-admin Windows users #52061,Caching issues
Lost inputs no longer available remotely#53356.Others
Also worth noting, though not tied to a specific incident here:
Describe how you validated your changes
bazel versionreports 9.2.0 afterbazeliskre-bootstraps.bazel build //pkg/config/schema/...completes successfully.bazel shutdownfollowed bybazel mod deps --lockfile_mode=refreshleavesMODULE.bazel.lockunchanged.Additional Notes
None of the .bazelrc UAC/8dot3 workarounds (DataDog/datadog-agent-buildimages#1215, #52500, #52061, #53591) are removed here.
Each needs its own re-verification on Windows before being reverted as follow-ups.