zstd: fix arm64 asm frame offsets placing locals on the saved LR slot - #1176
Conversation
The generated arm64 decoder assembly places every function local 8 bytes too low, so local 0 lands on the saved link register. x86 and arm64 put the return address in different places. On x86, CALL pushes it before the callee runs, so it sits above the frame and local 0 is at SP+0. On arm64, BL leaves it in the link register and the callee spills it to the BOTTOM of its own frame, so 0(RSP) is the saved LR and locals start at 8(RSP). The avo arm64 lowering renamed the pseudo stack pointer to RSP and passed the displacement through unchanged, inheriting x86's layout. Verified by disassembling probe functions at two frame sizes: for both TEXT $8 and TEXT $64 the assembler places pseudo-SP local 0 at 8(RSP), while the prologue's MOVD.W R30, -N(RSP) puts the saved LR at 0(RSP). The 8-byte offset does not depend on frame size. Affected: sequenceDecs_decode_arm64, sequenceDecs_decode_56_arm64, sequenceDecs_decodeSync_arm64 and sequenceDecs_decodeSync_safe_arm64, all present since v1.19.0. Scope: this does NOT corrupt decoded data and cannot produce wrong output. Every local shifts by the same 8 bytes, so loads and stores agree and the arithmetic is self-consistent; that is why the test suite and fuzzing never caught it. These are leaf functions, so the link register is still live in R30 and RET works. What breaks is the unwind path only: GC stack scanning, panics and profiling read the return address from 0(RSP) and find decoder state there. The fix shifts pseudo-SP displacements by 8 in the lowering, so the regenerated assembly is a mechanical +8 on every local access and nothing else. zstd tests pass on arm64 (Neoverse N1).
📝 WalkthroughWalkthroughUpdates the AVO replacement pin and remaps stack spill/reload offsets across ARM64 sequence decoder routines, including synchronous safe and non-safe paths and their validation and error handling. ChangesARM64 decoder updates
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Carries the frame-offset fix that is in flight separately as klauspost#1176, so this branch validates against a printer that has it; expect a rebase once that lands. The only change to generated assembly is that fix -- a mechanical +8 on every local access in seqdec_arm64.s, with every offset landing inside its frame's local area. huff0 and the amd64 output are untouched, which is the evidence that round seven's other fixes are not reachable from these generators. Those others: the three-operand SHL/SHR forms are rejected (they are SHLD/SHRD, a different instruction whose destination is the third operand); preprocessor directives are normalized so "# else" is recognized, since Go's assembler tokenizes the '#' separately and a missed #else drops BOTH arms; and the mixed-comment check moved into the preprocessor evaluator, deleting a second stateless opinion about directive ownership that had already disagreed with the authoritative one.
|
Note Rescinded 2026-07-29. The crash scenario this comment assumes cannot occur on current Go runtimes; impact is limited to CPU-profile samples and debugger backtraces. See the severity correction. Struck through, retained for history.
Postscript (unstruck): the conclusion survives the severity correction — no |
|
Note Rescinded 2026-07-29. The crash scenario this comment assumes cannot occur on current Go runtimes; impact is limited to CPU-profile samples and debugger backtraces. See the severity correction. Struck through, retained for history.
|
|
Note Rescinded 2026-07-29. The crash scenario this comment assumes cannot occur on current Go runtimes; impact is limited to CPU-profile samples and debugger backtraces. See the severity correction. Struck through, retained for history.
|
open-telemetry/opentelemetry-collector v0.157.0 |
|
apache/arrow-go v18.7.0 |
|
IBM/sarama v1.60.0 |
|
anchore/syft v1.49.0 |
(Verified by reading go.mod at each tag, not inferred.)
Everything else I found on v1.19.x is HEAD-only and would absorb it at its next release: containerd, moby, buildkit, tailscale, talos, soci-snapshotter, VictoriaMetrics, ch-go, google/go-containerregistry, vitess, mimir, iceberg-go, gitea.
Which is the argument for cutting a patch release sooner rather than folding this into the next feature release: most of the exposure has not happened yet and a fast v1.19.2 prevents it outright. The four above are the only ones that would need to re-release.
Two caveats so this is not read as more precise than it is:
These are declared requirements. Minimal version selection can still pull v1.19.x into a build whose owngo.modasks for v1.18.x, if any other dependency requires it — I did not compute transitive resolution.- ~~
opentelemetry-collector-contribwas not enumerated (~200 modules); one sampled component had it indirectly in v0.157.0, so contrib coverage is inferred.~~
One useful negative: nats-io/nats-server requires v1.19.0 but uses only s2, so it is unaffected despite matching on version. Matching the version alone overstates the blast radius — the zstd decode path is the thing that matters.
|
Severity correction — this is not urgent, and I have retitled and rewritten the description accordingly. The original title/body claimed this could crash any arm64 process that decodes zstd while something walks its stack (GC, panic, profiling). After tracing the actual runtime behavior, that was wrong. Verified against the shipped binaries and the go1.26.5 runtime source:
So the real, present-day impact is: corrupted/truncated CPU-profile samples and broken debugger/core-dump backtraces through The fix itself is unchanged. I have also closed the downstream heads-up issues I filed with the same correction: IBM/sarama#3684, open-telemetry/opentelemetry-collector#15660, apache/arrow-go#1016. The original framing was out of an abundance of caution — clobbering a saved return address warranted treating as urgent until the runtime mechanics proved otherwise. |
|
ok, good analysis, merging for now. afk for the moment, so will release early next week. |
Generated assembly is unchanged, byte for byte. The frame-offset fix this round originally carried landed separately as klauspost#1176 and is already in the base; regenerating against this pin reproduces it exactly, which is the check that the two arrived at the same answer rather than merely at compatible ones. Round seven's other fixes are not reachable from these generators: the three-operand SHL/SHR forms are rejected (they are SHLD/SHRD, a different instruction whose destination is the third operand); preprocessor directives are normalized so "# else" is recognized, since Go's assembler tokenizes the '#' separately and a missed #else drops BOTH arms; and the mixed-comment check moved into the preprocessor evaluator, deleting a second stateless opinion about directive ownership that had already disagreed with the authoritative one.
…804) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [github.com/klauspost/compress](https://github.com/klauspost/compress) | `v1.19.1` → `v1.19.2` |  |  | --- ### Release Notes <details> <summary>klauspost/compress (github.com/klauspost/compress)</summary> ### [`v1.19.2`](https://github.com/klauspost/compress/releases/tag/v1.19.2) [Compare Source](klauspost/compress@v1.19.1...v1.19.2) #### What's Changed - huff0: add arm64 assembly for Decompress4X/1X via avo lowering by [@​lizthegrey](https://github.com/lizthegrey) in [#​1172](klauspost/compress#1172) - zstd: Re-enable unsafe decodeSync memory copies ([#​1168](klauspost/compress#1168)) by [@​lizthegrey](https://github.com/lizthegrey) in [#​1171](klauspost/compress#1171) - zstd: fix arm64 asm frame offsets placing locals on the saved LR slot by [@​lizthegrey](https://github.com/lizthegrey) in [#​1176](klauspost/compress#1176) - zstd: avoid racing MaxDecodedSize write on shared dict litEnc by [@​zanarellidev](https://github.com/zanarellidev) in [#​1182](klauspost/compress#1182) - zstd: keep BuildDict recent-offsets positive and loadable by [@​zanarellidev](https://github.com/zanarellidev) in [#​1184](klauspost/compress#1184) - zstd: handle zero-literal BuildDict corpus by [@​cyphercodes](https://github.com/cyphercodes) in [#​1178](klauspost/compress#1178) - zstd: don't clear the registered dictionary when decoding past the window by [@​sueun-dev](https://github.com/sueun-dev) in [#​1177](klauspost/compress#1177) #### New Contributors - [@​zanarellidev](https://github.com/zanarellidev) made their first contribution in [#​1183](klauspost/compress#1183) - [@​cyphercodes](https://github.com/cyphercodes) made their first contribution in [#​1178](klauspost/compress#1178) - [@​sueun-dev](https://github.com/sueun-dev) made their first contribution in [#​1177](klauspost/compress#1177) **Full Changelog**: <klauspost/compress@v1.19.1...v1.19.2> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`) - Automerge - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC43LjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC43LjIiLCJ0YXJnZXRCcmFuY2giOiJmb3JnZWpvIiwibGFiZWxzIjpbImRlcGVuZGVuY3ktdXBncmFkZSIsInRlc3Qvbm90LW5lZWRlZCJdfQ==--> Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13804 Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
…OVWQZX (#1175) * zstd, huff0: regenerate arm64 assembly with the improved avo lowering No source or algorithm change: the same generators, re-run against a lowering that emits better arm64. Two improvements account for it. 128-bit moves now use FMOVQ, which takes a base+displacement operand directly, where the previous VLD1/VST1 needed the address materialized into a scratch register first. And scalar accesses fold base+index into the instruction when arm64 permits it (the index shift must equal log2 of the access width, and no displacement may be present), with a cache so a run of accesses sharing a base and index computes the address once. x86 folds base+index+displacement into a single instruction and the generators lean on that heavily, so this recovers much of what the lowering used to pay per access. seqdec_arm64.s and decompress_arm64.s together shed about 90 lines. The amd64 assembly is byte-identical. Measured on Neoverse N1 (Ampere, go1.26, -count 6, every result p<0.03): Decoder_DecodeAll geomean -1.53% html.zst -2.29% plrabn12.txt.zst -2.19% lcet10.txt.zst -2.11% kppkn.gtb.zst -2.08% alice29.txt.zst -2.02% huff0 Decompress geomean -0.81% Decompress4X/twain -2.81% Inputs that are not sequence-bound (fireworks.jpeg, html_x_4) are unchanged, as expected. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * zstd, huff0: bump the pinned avo to pick up thirteen lowering fixes Generated output is unchanged -- regenerating against this pin reproduces every .s file byte for byte, which also confirms none of the fixed bugs was reachable from these generators. The pin still matters: it is what the next regeneration uses. Three review passes over the lowering found thirteen ways it could emit plausible-looking but wrong arm64. About half are wrong values: byte extends reading the wrong field from a high-byte source, a 32-bit conditional move losing x86's unconditional zero-extension, a negative 32-bit immediate sign-extending across all 64 bits, BEXTR clobbering its own staged control field with a memory source, and compare/test/multiply loading eight bytes for a four-byte memory operand, which can fault at a page boundary. The rest are cases where the two architectures disagree about what a flag means, and the lowering now refuses to translate rather than emit something plausible: carry conditions after additions and after logical ops (both invert), carry read across INC/DEC (which preserve it on x86 but not once lowered), ADC after anything but a compare or subtract, a signed sub-word compare whose consumer sits past a flag-transparent instruction, and the XOR-self zeroing shortcut, which dropped the zero flag x86 sets there. The last round also resolves the GOAMD64 conditionals before the flag analyses run, so those see exactly the instructions that will be emitted -- otherwise a producer inside a dead arm could absorb a mark a live one needed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * zstd, huff0: narrow two table loads to MOVWQZX, and bump the pinned avo The avo bump carries seven lowering fixes from a fourth review pass (see the fork's log). One of them matters here: a 16-bit load into a register lowered to a zero-extending arm64 load, where x86 preserves the upper 48 bits. Nothing in this repository was miscompiled by that -- at all forty affected sites the destination's upper bits are dead, so zero-extending was harmless as applied -- but the printer cannot know that, and an avo program that did depend on those bits would have gotten wrong code. Making the lowering exact costs an instruction on every 16-bit load, and that instruction reads the destination it writes, which turns an independent load in huff0's innermost decode loop into a loop-carried dependency: measured +11.74% geomean on Decompress4X on Neoverse N1, up to +19% (p=0.000, n=12). zstd's DecodeAll paid a smaller +0.73%. So this asks for what the code actually wants. Every one of these sites loads a table entry and then reads only its low bits, so none of them needs the surrounding register preserved; MOVWQZX says that, and lowers back to a single folded load. This is belt and suspenders -- there was no bug here to fix -- it just keeps the general safety fix from costing anything where preservation was never wanted. It is also simply the better x86 encoding, which is worth having on its own: MOVZX avoids the 66h operand-size prefix and the partial-register merge dependency, the same hazard that cost 11.74% on arm64. On amd64 huff0 Decompress4X that is -7.59% geomean, up to -14.10% (p=0.000, n=12, Ryzen 5 5600X). Net effect on generated code: huff0/decompress_arm64.s and zstd/seqdec_arm64.s are byte-identical to before, zstd/fse_decoder_arm64.s loses two instructions to folded addressing, and the amd64 files pick up the faster encoding. The two changes land together because the pin bump alone would regress arm64 until the generators were narrowed. * zstd, huff0: bump the pinned avo for the round-five lowering fixes Generated assembly is unchanged, byte for byte. None of this round's bugs was reachable from these generators: they emit only GOAMD64 directives, which the lowering resolves and removes, so the state that was leaking across foreign preprocessor arms had nothing to leak past. The pin moves anyway so the committed assembly corresponds to a printer we would be willing to point at other code. * zstd, huff0: bump the pinned avo for the round-six lowering fixes Generated assembly is unchanged, byte for byte. The 64-bit immediate sign-extension bug this picks up needs a Q-width immediate with bit 31 set, which neither of these generators emits -- s2's does, which is why it was worth finding. * zstd, huff0: bump the pinned avo for the round-seven lowering fixes Generated assembly is unchanged, byte for byte. The frame-offset fix this round originally carried landed separately as #1176 and is already in the base; regenerating against this pin reproduces it exactly, which is the check that the two arrived at the same answer rather than merely at compatible ones. Round seven's other fixes are not reachable from these generators: the three-operand SHL/SHR forms are rejected (they are SHLD/SHRD, a different instruction whose destination is the third operand); preprocessor directives are normalized so "# else" is recognized, since Go's assembler tokenizes the '#' separately and a missed #else drops BOTH arms; and the mixed-comment check moved into the preprocessor evaluator, deleting a second stateless opinion about directive ownership that had already disagreed with the authoritative one. * zstd, huff0: bump the pinned avo for the round-eight lowering changes The address cache is gone from the lowering. It let a second access to the same base and index reuse the register the first one computed, and it had to be invalidated at every boundary the printer does not otherwise model -- two of the silent miscompiles found in review were missing invalidations rather than missing lowerings. Measured here, it was worth two instructions: seqdec_arm64.s and huff0/decompress_arm64.s are byte-identical without it, and fse_decoder_arm64.s gains two ADDs in buildDtable, which runs once per block. Most accesses fold base+index into the instruction and never materialize an address at all, so there was rarely anything to cache. Round eight's review found no new lowering bugs, so the rest is housekeeping: dead code removed, a confusing panic given a real message. * zstd, huff0: bump the pinned avo for the round-nine lowering fixes Generated assembly is unchanged, byte for byte. None of round nine's bugs is reachable from these generators: the CMN boundary case needs a compare against INT32_MIN written as a signed immediate, and the two directive-coupling holes need directives, which neither generator emits. * zstd, huff0: bump the pinned avo for the round-ten and -eleven changes Generated assembly is unchanged, byte for byte, including across the removal of the lowering's preprocessor-directive support -- neither of these generators emits a directive, which is most of why that support was removed. Also picks up shift counts at or above the operand width being masked the way x86 masks them, rather than passing through to an arm64 immediate form that rejects them, and 64-bit immediates written unsigned with the top bit set being read as the bit pattern amd64 wraps them to rather than refused. * zstd, huff0: bump the pinned avo for the round-eleven guard fixes Generated assembly unchanged, byte for byte. Both fixes are to the guard that refuses preprocessor directives, which neither of these generators emits. * zstd, huff0: bump the pinned avo for the round-twelve guard fixes The only change to generated assembly is one build-tag line per file: the original constraint is now bracketed before the arm64 term is ANDed onto it. That is a no-op for these three -- every constraint here is a pure AND chain -- but without it a constraint containing || would have parsed as "(arm64 && ...) || ..." and pulled the arm64 assembly into non-arm64 builds. Instructions are byte-identical. Verified building and testing both architectures. * zstd, huff0: bump the pinned avo for the label-name guard Generated assembly unchanged, byte for byte. * zstd, huff0: bump the pinned avo for the round-thirteen hardening Generated assembly unchanged, byte for byte. Round thirteen found no miscompiles; the changes make flag transparency, instruction suffixes, branch targets and the one-line output invariant into properties this printer checks itself rather than ones that held because a separate tool happened to reject the alternative. * zstd, huff0: bump the pinned avo for the round-fourteen enforcement Generated assembly unchanged, byte for byte. The lowering now checks both directions of the flag contract at generation time: an instruction claimed flag-neutral must emit no flag-writers, and one marked as a producer must emit exactly one. --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Klaus Post <klauspost@gmail.com>
…p ci] Bumps the go-modules group in /e2e-go with 6 updates: | Package | From | To | | --- | --- | --- | | [github.com/klauspost/compress](https://github.com/klauspost/compress) | `1.19.1` | `1.19.2` | | [github.com/moby/go-archive](https://github.com/moby/go-archive) | `0.3.2` | `0.3.3` | | [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp](https://github.com/open-telemetry/opentelemetry-go-contrib) | `0.69.0` | `0.70.0` | | [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | | [go.opentelemetry.io/otel/metric](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | | [go.opentelemetry.io/otel/trace](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | Updates `github.com/klauspost/compress` from 1.19.1 to 1.19.2 Release notes *Sourced from [github.com/klauspost/compress's releases](https://github.com/klauspost/compress/releases).* > v1.19.2 > ------- > > What's Changed > -------------- > > * huff0: add arm64 assembly for Decompress4X/1X via avo lowering by [`@lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1172](https://redirect.github.com/klauspost/compress/pull/1172) > * zstd: Re-enable unsafe decodeSync memory copies ([#1168](https://redirect.github.com/klauspost/compress/issues/1168)) by [`@lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1171](https://redirect.github.com/klauspost/compress/pull/1171) > * zstd: fix arm64 asm frame offsets placing locals on the saved LR slot by [`@lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1176](https://redirect.github.com/klauspost/compress/pull/1176) > * zstd: avoid racing MaxDecodedSize write on shared dict litEnc by [`@zanarellidev`](https://github.com/zanarellidev) in [klauspost/compress#1182](https://redirect.github.com/klauspost/compress/pull/1182) > * zstd: keep BuildDict recent-offsets positive and loadable by [`@zanarellidev`](https://github.com/zanarellidev) in [klauspost/compress#1184](https://redirect.github.com/klauspost/compress/pull/1184) > * zstd: handle zero-literal BuildDict corpus by [`@cyphercodes`](https://github.com/cyphercodes) in [klauspost/compress#1178](https://redirect.github.com/klauspost/compress/pull/1178) > * zstd: don't clear the registered dictionary when decoding past the window by [`@sueun-dev`](https://github.com/sueun-dev) in [klauspost/compress#1177](https://redirect.github.com/klauspost/compress/pull/1177) > > New Contributors > ---------------- > > * [`@zanarellidev`](https://github.com/zanarellidev) made their first contribution in [klauspost/compress#1183](https://redirect.github.com/klauspost/compress/pull/1183) > * [`@cyphercodes`](https://github.com/cyphercodes) made their first contribution in [klauspost/compress#1178](https://redirect.github.com/klauspost/compress/pull/1178) > * [`@sueun-dev`](https://github.com/sueun-dev) made their first contribution in [klauspost/compress#1177](https://redirect.github.com/klauspost/compress/pull/1177) > > **Full Changelog**: <https://github.com/klauspost/compress/compare/v1.19.1...v1.19.2> Commits * [`c3b3439`](https://github.com/klauspost/compress/commit/c3b3439a48196b5082c63252bfb8633d0a2faad4) zstd: don't clear the registered dictionary when decoding past the window ([#1](https://redirect.github.com/klauspost/compress/issues/1)... * [`9874bc9`](https://github.com/klauspost/compress/commit/9874bc9073f350ce462becb84f9a23c3e828d03f) fix(zstd): handle zero-literal BuildDict corpus ([#1178](https://redirect.github.com/klauspost/compress/issues/1178)) * [`71bb6fd`](https://github.com/klauspost/compress/commit/71bb6fd9ddbfbb2ca6612542a916c766a866bfb3) zstd: keep BuildDict recent-offsets positive and loadable ([#1184](https://redirect.github.com/klauspost/compress/issues/1184)) * [`3d4dacb`](https://github.com/klauspost/compress/commit/3d4dacbaa9faca75caacc35b6d75731a81a92c6b) zstd: avoid racing MaxDecodedSize write on shared dict litEnc ([#1182](https://redirect.github.com/klauspost/compress/issues/1182)) * [`3ceaa81`](https://github.com/klauspost/compress/commit/3ceaa81409aabe39c71821b936155b33471c78d8) build(deps): bump the github-actions group with 5 updates ([#1185](https://redirect.github.com/klauspost/compress/issues/1185)) * [`72cb4d3`](https://github.com/klauspost/compress/commit/72cb4d3e8e743bea5d1ba40896ad55214a1844e4) chore: add OpenSSF Scorecard GitHub Action ([#1183](https://redirect.github.com/klauspost/compress/issues/1183)) * [`69c9db4`](https://github.com/klauspost/compress/commit/69c9db420ae55bfcdfbef564805e2646206545f7) zstd: fix arm64 asm locals overwriting the saved link register ([#1176](https://redirect.github.com/klauspost/compress/issues/1176)) * [`117430d`](https://github.com/klauspost/compress/commit/117430d3b0e3c39c14d32fe7c90652149a78e609) zstd: Re-enable unsafe decodeSync memory copies ([#1168](https://redirect.github.com/klauspost/compress/issues/1168)) ([#1171](https://redirect.github.com/klauspost/compress/issues/1171)) * [`c73af0c`](https://github.com/klauspost/compress/commit/c73af0c12cc767386af8388f30d5aa7428e6dfc8) huff0: add arm64 assembly for Decompress4X/1X via avo lowering ([#1172](https://redirect.github.com/klauspost/compress/issues/1172)) * See full diff in [compare view](https://github.com/klauspost/compress/compare/v1.19.1...v1.19.2) Updates `github.com/moby/go-archive` from 0.3.2 to 0.3.3 Release notes *Sourced from [github.com/moby/go-archive's releases](https://github.com/moby/go-archive/releases).* > v0.3.3 > ------ > > What's Changed > -------------- > > * Fix a regression introduced in v0.3.0 that caused archive extraction to reject hardlinks with absolute targets, as produced by > some image builders. Absolute hardlink targets are now resolved relative to the extraction root, while paths that escape the root > remain rejected. [moby/go-archive#100](https://redirect.github.com/moby/go-archive/pull/100) > * Fix a regression introduced in v0.3.0 that caused archive extraction to fail when applying permissions to device nodes, including > nodes on `nodev` filesystems and `dev/ptmx`. Device nodes are now referenced without opening the underlying device before applying > their mode. [moby/go-archive#103](https://redirect.github.com/moby/go-archive/pull/103) > * Set close-on-exec on file descriptors used by the Linux permission fallback to prevent them from leaking into child processes. > [moby/go-archive#104](https://redirect.github.com/moby/go-archive/pull/104) > > **Full Changelog**: <https://github.com/moby/go-archive/compare/v0.3.2...v0.3.3> Commits * [`ae9e219`](https://github.com/moby/go-archive/commit/ae9e219f7104d91e262055a29bae1f9753106981) Merge pull request [#104](https://redirect.github.com/moby/go-archive/issues/104) from thaJeztah/use\_O\_CLOEXEC * [`98ff1da`](https://github.com/moby/go-archive/commit/98ff1dac11141c20bf7975ee1243fbe5031c2684) archive: set close-on-exec for chmod fallback descriptors * [`1e8dfbc`](https://github.com/moby/go-archive/commit/1e8dfbc6ec14614f009716c5ec04b6d104168201) Merge pull request [#103](https://redirect.github.com/moby/go-archive/issues/103) from thaJeztah/fix\_chmod\_fallback * [`e738eed`](https://github.com/moby/go-archive/commit/e738eed524c260a613bea37a47349e0f7d0a45a6) archive: keep procfs file alive during fchmodat * [`2d863f5`](https://github.com/moby/go-archive/commit/2d863f57793b7e2340cfca8f9a94a2d55cf7e68e) archive: preserve procfs access during chroot extraction * [`89653ed`](https://github.com/moby/go-archive/commit/89653edcda61f24e83ae2aa485f57cf762c59568) archive: fix chmod fallback for device nodes on nodev mounts * [`f37d413`](https://github.com/moby/go-archive/commit/f37d413855106b6c4f5cc3c063013869b6294e7d) Merge pull request [#106](https://redirect.github.com/moby/go-archive/issues/106) from thaJeztah/fallback\_no\_read * [`4ffc915`](https://github.com/moby/go-archive/commit/4ffc91517ffd9b77b11efd91768b5d6d4303a3b6) archive: test chmod fallback without read permission * [`9af1c40`](https://github.com/moby/go-archive/commit/9af1c40d9b972e82affd0b3ed3beb3f5d4d5f5d2) Merge pull request [#105](https://redirect.github.com/moby/go-archive/issues/105) from thaJeztah/test\_chrooted\_chmod\_fallback * [`3daca2a`](https://github.com/moby/go-archive/commit/3daca2abcac72471e1424cc840e7c5711937ade9) archive: test chmod fallback without procfs in chroot * Additional commits viewable in [compare view](https://github.com/moby/go-archive/compare/v0.3.2...v0.3.3) Updates `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` from 0.69.0 to 0.70.0 Release notes *Sourced from [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp's releases](https://github.com/open-telemetry/opentelemetry-go-contrib/releases).* > Release v1.45.0/v2.5.2/v0.70.0/v0.37.2/v0.25.0/v0.20.0/v0.16.2/v0.17.0 > ---------------------------------------------------------------------- > > Overview > -------- > > ### Added > > * Add `go.opentelemetry.io/contrib/detectors/ibmcloud/vpc`, a new resource detector for IBM Cloud VPC virtual server instances, ported from `github.com/open-telemetry/opentelemetry-collector-contrib/processor/resourcedetectionprocessor/internal/ibmcloud/vpc`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `cloud.availability_zone`, `cloud.account.id`, `cloud.resource_id`, `host.id`, `host.image.id`, `host.image.name`, `host.name`, and `host.type`. ([#9011](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9011)) > * Add `go.opentelemetry.io/contrib/detectors/k8sapi`, a new resource detector that queries the Kubernetes API. Detects `k8s.node.name` and `k8s.node.uid` when `K8S_NODE_NAME` is set via the downward API, and `k8s.cluster.uid` derived from the kube-system namespace UID (works on any Kubernetes distribution). ([#9108](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9108)) > * Add new `elasticbeanstalk` resource detector for AWS Elastic Beanstalk, ported from `processor/resourcedetectionprocessor/internal/aws/elasticbeanstalk` in opentelemetry-collector-contrib. ([#8993](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8993)) > * The resource created by `go.opentelemetry.io/contrib/otelconf` now includes [default SDK attributes](https://pkg.go.dev/go.opentelemetry.io/otel/sdk/resource#Default). ([#8990](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8990)) > * Add support for the `aws.ecs` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#8915](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8915)) > * Add support for the `aws.eks` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9138](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9138)) > * Add support for the `azure.vm` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9074](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9074)) > * Add support for the `gcp` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9137](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9137)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azureappservice`, a new resource detector for Azure App Service. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `azure.app_service.instance.id`, and `deployment.environment.name` from the `WEBSITE_*` and `REGION_NAME` environment variables. ([#9289](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9289)) > * Add `azurecontainerapps` resource detector for Azure Container Apps. ([#8939](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8939)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azurefunctions`, a new resource detector for Azure Functions. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `faas.instance`, and `deployment.environment.name` from the `FUNCTIONS_*`, `WEBSITE_*`, `CONTAINER_NAME`, and `REGION_NAME` environment variables. ([#9290](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9290)) > * Add `NewResourceDetector` along with the `WithAttributeFilter` and `WithTagKeyFilter` options in `go.opentelemetry.io/contrib/detectors/azure/azurevm`. `WithAttributeFilter` restricts the returned resource to the attributes the filter accepts. `WithTagKeyFilter` opts in to `azure.tag.<name>` attributes for the VM tags whose keys satisfy the provided predicate; no VM tags are emitted without it. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > * Add `go.opentelemetry.io/contrib/detectors/vultr` — a new resource detector for Vultr Cloud Compute instances, ported from `processor/resourcedetectionprocessor/internal/vultr` in `opentelemetry-collector-contrib`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `host.id`, and `host.name`. ([#8995](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8995)) > > ### Changed > > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.43.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.43.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.43.0) for complete details. ([#9337](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9337)) > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.42.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.42.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.42.0) for complete details. ([#9196](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9196)) > * Use direct normalized-key lookups in `Carrier.Get` and `Carrier.Keys` in `go.opentelemetry.io/contrib/propagators/envcar`. ([#9112](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9112)) > * Update log bridge conversions to use attribute key-values instead of the removed log key-values in `go.opentelemetry.io/contrib/bridges/otellogr`, `go.opentelemetry.io/contrib/bridges/otellogrus`, `go.opentelemetry.io/contrib/bridges/otelslog`, and `go.opentelemetry.io/contrib/bridges/otelzap`. ([#9180](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9180)) > * The `Version()` function in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux` has been replaced by `const Version`. ([#9076](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9076)) > * Set `error.type` attribute instead of adding `exception` span events in `go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin`. ([#8977](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8977)) > * Prefer the gRPC dial target over the resolved peer IP for the `server.address` and `server.port` attributes in `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc`. ([#8904](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8904)) > * The detector in `go.opentelemetry.io/contrib/detectors/azure/azurevm` now also detects `cloud.account.id`, `cloud.availability_zone`, `azure.vm.name`, `azure.vm.size`, `azure.vm.scaleset.name`, and `azure.resource_group.name`, and prefers `osProfile.computerName` for `host.name` (falling back to the VM name), reconciling it with the collector-contrib Azure resource detector. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > > ### Fixed > > * Fix Prometheus reader resource label filter configuration in `go.opentelemetry.io/contrib/otelconf/v0.2.0`. ([#9062](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9062)) > * Apply `resource.detection/development.attributes.included` and `excluded` filtering to resource detector attributes in `go.opentelemetry.io/contrib/otelconf/x`. ([#9131](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9131)) > * Honor the context configured with `WithContext` when constructing resources in `go.opentelemetry.io/contrib/otelconf` and `go.opentelemetry.io/contrib/otelconf/x`. ([#9160](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9160)) > * Handle nil response bodies from custom `RoundTripper` implementations in `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` without panicking. ([#9184](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9184)) > * Fix incorrect (overestimated) sum calculation for runtime histograms in `go.opentelemetry.io/contrib/instrumentation/runtime`. ([#9063](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9063)) > * Fix `Severity.UnmarshalText` round trip for positive `FATAL` offsets above the named range in `go.opentelemetry.io/contrib/processors/minsev`. ([#9197](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9197)) > * Reduce binary size by fetching ConfigMaps via `rest.HTTPClientFor` instead of the Kubernetes clientset in `go.opentelemetry.io/contrib/detectors/aws/eks`. ([#9284](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9284)) > * `TextMapPropagator` in `go.opentelemetry.io/contrib/propagators/autoprop` returns the no-op propagator for empty input, matching the behavior of `none`. An unknown `OTEL_PROPAGATORS` value still returns an error with a nil propagator so `NewTextMapPropagator` falls back to the default TraceContext and Baggage propagators instead of disabling propagation. ([#9163](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9163)) > * Preserve error-valued attributes nested in a group as grouped attributes instead of silently dropping them in `go.opentelemetry.io/contrib/bridges/otelslog`. ([#9238](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9238)) > * Fix a data race in `go.opentelemetry.io/contrib/bridges/otelslog` where concurrent `Handle` calls could corrupt each other's log attributes because `kvBuffer.KeyValues` returned a slice aliasing a shared buffer. ([#9229](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9229)) > * Avoid a panic in `go.opentelemetry.io/contrib/bridges/otelzap` when a malformed error field contains a nil or non-error value. ([#9068](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9068)) > * Use `azure.container_app.instance.id` instead of `service.instance.id` for the replica name detected by `go.opentelemetry.io/contrib/detectors/azure/azurecontainerapps`. ([#9208](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9208)) > * Preserve the underlying metadata errors returned with partial resources from `go.opentelemetry.io/contrib/detectors/gcp`. ([#9069](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9069)) > * Copy `MultipartForm` back to the request `otelmux.Middleware` was given after the wrapped handler returns, so `net/http` can find and remove the temp files `ParseMultipartForm` created on the context-derived request copy, when `otelmux.Middleware` wraps a handler directly, in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux`. This does not cover a handler panic, nor the common `router.Use(...)` integration, where `gorilla/mux`'s own routing step makes an additional request copy the middleware cannot write back through; see [gorilla/mux#777](https://redirect.github.com/gorilla/mux/pull/777). ([#9361](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9361)) > * Report the `b3` header from `Fields()` for the default `B3Unspecified` single-header injection encoding, matching what `Inject` writes, in `go.opentelemetry.io/contrib/propagators/b3`. ([#9273](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9273)) > * Fix `go.opentelemetry.io/contrib/propagators/aws/xray` producing deterministic trace and span IDs when the seed read from `crypto/rand` silently failed, by switching to `math/rand/v2`'s concurrency-safe top-level generator. ([#9359](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9359)) ... (truncated) Changelog *Sourced from [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp's changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md).* > [1.45.0/2.5.2/0.70.0/0.37.2/0.25.0/0.20.0/0.16.2/0.17.0] - 2026-08-03 > --------------------------------------------------------------------- > > ### Added > > * Add `go.opentelemetry.io/contrib/detectors/ibmcloud/vpc`, a new resource detector for IBM Cloud VPC virtual server instances, ported from `github.com/open-telemetry/opentelemetry-collector-contrib/processor/resourcedetectionprocessor/internal/ibmcloud/vpc`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `cloud.availability_zone`, `cloud.account.id`, `cloud.resource_id`, `host.id`, `host.image.id`, `host.image.name`, `host.name`, and `host.type`. ([#9011](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9011)) > * Add `go.opentelemetry.io/contrib/detectors/k8sapi`, a new resource detector that queries the Kubernetes API. Detects `k8s.node.name` and `k8s.node.uid` when `K8S_NODE_NAME` is set via the downward API, and `k8s.cluster.uid` derived from the kube-system namespace UID (works on any Kubernetes distribution). ([#9108](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9108)) > * Add new `elasticbeanstalk` resource detector for AWS Elastic Beanstalk, ported from `processor/resourcedetectionprocessor/internal/aws/elasticbeanstalk` in opentelemetry-collector-contrib. ([#8993](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8993)) > * The resource created by `go.opentelemetry.io/contrib/otelconf` now includes [default SDK attributes](https://pkg.go.dev/go.opentelemetry.io/otel/sdk/resource#Default). ([#8990](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8990)) > * Add support for the `aws.ecs` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#8915](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8915)) > * Add support for the `aws.eks` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9138](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9138)) > * Add support for the `azure.vm` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9074](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9074)) > * Add support for the `gcp` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9137](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9137)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azureappservice`, a new resource detector for Azure App Service. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `azure.app_service.instance.id`, and `deployment.environment.name` from the `WEBSITE_*` and `REGION_NAME` environment variables. ([#9289](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9289)) > * Add `azurecontainerapps` resource detector for Azure Container Apps. ([#8939](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8939)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azurefunctions`, a new resource detector for Azure Functions. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `faas.instance`, and `deployment.environment.name` from the `FUNCTIONS_*`, `WEBSITE_*`, `CONTAINER_NAME`, and `REGION_NAME` environment variables. ([#9290](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9290)) > * Add `NewResourceDetector` along with the `WithAttributeFilter` and `WithTagKeyFilter` options in `go.opentelemetry.io/contrib/detectors/azure/azurevm`. `WithAttributeFilter` restricts the returned resource to the attributes the filter accepts. `WithTagKeyFilter` opts in to `azure.tag.<name>` attributes for the VM tags whose keys satisfy the provided predicate; no VM tags are emitted without it. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > * Add `go.opentelemetry.io/contrib/detectors/vultr` — a new resource detector for Vultr Cloud Compute instances, ported from `processor/resourcedetectionprocessor/internal/vultr` in `opentelemetry-collector-contrib`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `host.id`, and `host.name`. ([#8995](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8995)) > > ### Changed > > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.43.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.43.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.43.0) for complete details. ([#9337](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9337)) > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.42.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.42.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.42.0) for complete details. ([#9196](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9196)) > * Use direct normalized-key lookups in `Carrier.Get` and `Carrier.Keys` in `go.opentelemetry.io/contrib/propagators/envcar`. ([#9112](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9112)) > * Update log bridge conversions to use attribute key-values instead of the removed log key-values in `go.opentelemetry.io/contrib/bridges/otellogr`, `go.opentelemetry.io/contrib/bridges/otellogrus`, `go.opentelemetry.io/contrib/bridges/otelslog`, and `go.opentelemetry.io/contrib/bridges/otelzap`. ([#9180](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9180)) > * The `Version()` function in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux` has been replaced by `const Version`. ([#9076](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9076)) > * Set `error.type` attribute instead of adding `exception` span events in `go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin`. ([#8977](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8977)) > * Prefer the gRPC dial target over the resolved peer IP for the `server.address` and `server.port` attributes in `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc`. ([#8904](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8904)) > * The detector in `go.opentelemetry.io/contrib/detectors/azure/azurevm` now also detects `cloud.account.id`, `cloud.availability_zone`, `azure.vm.name`, `azure.vm.size`, `azure.vm.scaleset.name`, and `azure.resource_group.name`, and prefers `osProfile.computerName` for `host.name` (falling back to the VM name), reconciling it with the collector-contrib Azure resource detector. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > > ### Fixed > > * Fix Prometheus reader resource label filter configuration in `go.opentelemetry.io/contrib/otelconf/v0.2.0`. ([#9062](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9062)) > * Apply `resource.detection/development.attributes.included` and `excluded` filtering to resource detector attributes in `go.opentelemetry.io/contrib/otelconf/x`. ([#9131](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9131)) > * Honor the context configured with `WithContext` when constructing resources in `go.opentelemetry.io/contrib/otelconf` and `go.opentelemetry.io/contrib/otelconf/x`. ([#9160](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9160)) > * Handle nil response bodies from custom `RoundTripper` implementations in `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` without panicking. ([#9184](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9184)) > * Fix incorrect (overestimated) sum calculation for runtime histograms in `go.opentelemetry.io/contrib/instrumentation/runtime`. ([#9063](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9063)) > * Fix `Severity.UnmarshalText` round trip for positive `FATAL` offsets above the named range in `go.opentelemetry.io/contrib/processors/minsev`. ([#9197](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9197)) > * Reduce binary size by fetching ConfigMaps via `rest.HTTPClientFor` instead of the Kubernetes clientset in `go.opentelemetry.io/contrib/detectors/aws/eks`. ([#9284](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9284)) > * `TextMapPropagator` in `go.opentelemetry.io/contrib/propagators/autoprop` returns the no-op propagator for empty input, matching the behavior of `none`. An unknown `OTEL_PROPAGATORS` value still returns an error with a nil propagator so `NewTextMapPropagator` falls back to the default TraceContext and Baggage propagators instead of disabling propagation. ([#9163](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9163)) > * Preserve error-valued attributes nested in a group as grouped attributes instead of silently dropping them in `go.opentelemetry.io/contrib/bridges/otelslog`. ([#9238](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9238)) > * Fix a data race in `go.opentelemetry.io/contrib/bridges/otelslog` where concurrent `Handle` calls could corrupt each other's log attributes because `kvBuffer.KeyValues` returned a slice aliasing a shared buffer. ([#9229](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9229)) > * Avoid a panic in `go.opentelemetry.io/contrib/bridges/otelzap` when a malformed error field contains a nil or non-error value. ([#9068](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9068)) > * Use `azure.container_app.instance.id` instead of `service.instance.id` for the replica name detected by `go.opentelemetry.io/contrib/detectors/azure/azurecontainerapps`. ([#9208](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9208)) > * Preserve the underlying metadata errors returned with partial resources from `go.opentelemetry.io/contrib/detectors/gcp`. ([#9069](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9069)) > * Copy `MultipartForm` back to the request `otelmux.Middleware` was given after the wrapped handler returns, so `net/http` can find and remove the temp files `ParseMultipartForm` created on the context-derived request copy, when `otelmux.Middleware` wraps a handler directly, in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux`. This does not cover a handler panic, nor the common `router.Use(...)` integration, where `gorilla/mux`'s own routing step makes an additional request copy the middleware cannot write back through; see [gorilla/mux#777](https://redirect.github.com/gorilla/mux/pull/777). ([#9361](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9361)) > * Report the `b3` header from `Fields()` for the default `B3Unspecified` single-header injection encoding, matching what `Inject` writes, in `go.opentelemetry.io/contrib/propagators/b3`. ([#9273](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9273)) > * Fix `go.opentelemetry.io/contrib/propagators/aws/xray` producing deterministic trace and span IDs when the seed read from `crypto/rand` silently failed, by switching to `math/rand/v2`'s concurrency-safe top-level generator. ([#9359](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9359)) > * Strip connection number suffix from connection ID in `go.opentelemetry.io/contrib/instrumentation/go.mongodb.org/mongo-driver/v2/mongo/otelmongo` to prevent unbounded metric cardinality. ([#9352](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9352)) ... (truncated) Commits * [`c8a87a6`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/c8a87a60ba1b3374fd16df11fc3eeae6c41abbc9) Release v1.45.0/v2.5.2/v0.70.0/v0.37.2/v0.25.0/v0.20.0/v0.16.2/v0.17.0 ([#9413](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9413)) * [`cde125c`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/cde125c563f232eb6b423a208d375f8e53ae2557) fix(deps): update aws-sdk-go-v2 monorepo ([#9384](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9384)) * [`88572a7`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/88572a7662d00e805777ed96932d532316c13787) chore(deps): update googleapis to 6ac0973 ([#9409](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9409)) * [`e4f511a`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/e4f511a0f3cc2b09b87cb164427b49dfd2e14f7d) chore(deps): update github/codeql-action action to v4.37.5 ([#9410](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9410)) * [`265eb0b`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/265eb0b5fe0682801fd8177aec74ce8769c5a0a4) fix(deps): update go.opentelemetry.io/otel digest to 48db2c6 ([#9317](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9317)) * [`941ba46`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/941ba46979c59dca89d26040ed919870283e36e9) chore(deps): update github.com/charmbracelet/ultraviolet digest to 8b69304 (#... * [`ededd3b`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/ededd3b571ad562351a0afe09682774a6f48d63e) chore(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 ([#9406](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9406)) * [`7c6e819`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/7c6e819d4eb26eede10e98c424adb76304025fda) fix(deps): update module github.com/atombender/go-jsonschema to v0.24.1 ([#9405](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9405)) * [`ec1e544`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/ec1e544a0d6883126198c3fc3a7d62fc8db29195) chore(deps): update github.com/lufia/plan9stats digest to 341c2f0 ([#9403](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9403)) * [`5d7e16a`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/5d7e16aa1138a5446a648dd92ebc42031c93e327) chore(deps): update github.com/golangci/rowserrcheck digest to d2031e3 ([#9402](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9402)) * Additional commits viewable in [compare view](https://github.com/open-telemetry/opentelemetry-go-contrib/compare/zpages/v0.69.0...zpages/v0.70.0) Updates `go.opentelemetry.io/otel` from 1.44.0 to 1.45.0 Changelog *Sourced from [go.opentelemetry.io/otel's changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md).* > [1.45.0/0.67.0/0.21.0/0.0.18] - 2026-08-03 > ------------------------------------------ > > ### Added > > * Add experimental observability metrics to `BatchProcessor` in `go.opentelemetry.io/otel/sdk/log`. ([#7124](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/7124)) > * Add the experimental `WithUnsafeAttributes` no-copy attribute option to `go.opentelemetry.io/otel/metric/x` for future performance improvements. This API is a work in progress. ([#8251](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8251)) > * Add `Map` and `MapValue` functions for the new `MAP` attribute type in `go.opentelemetry.io/otel/attribute`. ([#8445](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8445)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlptrace`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlplog`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/zipkin`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Apply `AttributeValueLengthLimit` recursively to values contained in `attribute.MAP` attributes in `go.opentelemetry.io/otel/sdk/trace`. ([#8454](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8454)) > * Remove duplicate keys from `attribute.MAP` values in `go.opentelemetry.io/otel/sdk/resource` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/log` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in span, event, link, and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/trace` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in measurement and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/metric` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Extend `WithAllowKeyDuplication` in `go.opentelemetry.io/otel/sdk/log` to disable duplicate-key removal in `attribute.MAP` values for instrumentation scope attributes. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Add the `go.opentelemetry.io/otel/semconv/v1.42.0` package. > The package contains semantic conventions from the `v1.42.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.42.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.41.0`. ([#8484](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8484)) > * Add `WithoutPanicRecording` as a `TracerProviderOption` in `go.opentelemetry.io/otel/sdk/trace` to disable exception event recording for panics. ([#8532](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8532)) > * Add the `go.opentelemetry.io/otel/semconv/v1.43.0` package. > The package contains semantic conventions from the `v1.43.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.43.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.42.0`. ([#8628](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8628)) > > ### Changed > > * `HistogramReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` now uses a time-unbiased sampling algorithm for exemplars. ([#8306](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8306)) > * ⚠️ **Breaking Change:** Use `go.opentelemetry.io/otel/attribute.Value` and `go.opentelemetry.io/otel/attribute.KeyValue` for log bodies and attributes in `go.opentelemetry.io/otel/log`, `go.opentelemetry.io/otel/log/logtest`, `go.opentelemetry.io/otel/sdk/log`, and `go.opentelemetry.io/otel/sdk/log/logtest`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Encode log bodies and attributes as `go.opentelemetry.io/otel/attribute.Value` JSON in `go.opentelemetry.io/otel/exporters/stdout/stdoutlog`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Improve the performance of hashing `BOOLSLICE`, `INT64SLICE`, `FLOAT64SLICE`, and `STRINGSLICE` attribute values by avoiding reflection for short slices in `go.opentelemetry.io/otel/attribute`. ([#8511](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8511)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_METRICS_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_TRACES_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > > ### Deprecated > > * Deprecate `WithExportBufferSize` in `go.opentelemetry.io/otel/sdk/log`. The option remains available for source compatibility but no longer affects behavior; `BatchProcessor` no longer maintains a separate export-request buffer. ([#8620](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8620)) > > ### Removed > > * ⚠️ **Breaking Change:** Remove `Kind`, `Value`, `KeyValue`, their constructors, and attribute conversion helpers from `go.opentelemetry.io/otel/log`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * ⚠️ **Breaking Change:** Remove the `AttributeValueLengthLimit` and `AttributeCountLimit` fields from `RecordFactory` in `go.opentelemetry.io/otel/sdk/log/logtest`; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. ([#8556](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8556)) > > ### Fixed > > * Apply TLS certificates configured through environment variables to gRPC connections in `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc`. > * Prevent panics in `go.opentelemetry.io/otel/bridge/opentracing` when OpenTracing baggage is propagated concurrently with `Span.SetBaggageItem`. > * Fix an off-by-one error in `FixedSizeReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` that prevented the first exemplar from being sampled after the reservoir was filled. ([#8309](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8309)) > * Interpret HTTP `Retry-After` header values as seconds instead of nanoseconds when retrying OTLP HTTP exports in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp`, `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp`, and `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp`. ([#8383](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8383)) > * Fix a memory leak in the `Reservoir` implementation in `go.opentelemetry.io/otel/sdk/metric/exemplar`, where storing the full `context.Context` pinned large objects such as gRPC transport buffers. ([#8389](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8389)) ... (truncated) Commits * [`93a693e`](https://github.com/open-telemetry/opentelemetry-go/commit/93a693edeed0e07ce5ebd1dfe67af42d1e2055d8) Release v1.45.0 ([#8693](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8693)) * [`c65d435`](https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c) Merge commit from fork * [`223f9fd`](https://github.com/open-telemetry/opentelemetry-go/commit/223f9fdce4e4a85d6ee2155c6a140f236db72c8b) sdk/metric: remove obsolete randomFloat64 TODO ([#8685](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8685)) * [`06272bc`](https://github.com/open-telemetry/opentelemetry-go/commit/06272bc491566efb2c581c8a52e4986cfcccec5b) fix(deps): update googleapis to 6ac0973 ([#8694](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8694)) * [`a4f238f`](https://github.com/open-telemetry/opentelemetry-go/commit/a4f238f57646197d124edcf67baf4cd6ea6d0a9f) chore(deps): update github.com/charmbracelet/ultraviolet digest to 8b69304 (#... * [`37140e7`](https://github.com/open-telemetry/opentelemetry-go/commit/37140e78821d3cb29a33d4b601ca4645b80ceebd) chore(deps): update codspeedhq/action action to v5.0.2 ([#8690](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8690)) * [`cef0855`](https://github.com/open-telemetry/opentelemetry-go/commit/cef0855960bce4385c7d58c40e846573c190d826) chore(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 ([#8689](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8689)) * [`e814a72`](https://github.com/open-telemetry/opentelemetry-go/commit/e814a7281f2d52a6440c3269e139145e62801a16) Merge commit from fork * [`bfd8eb7`](https://github.com/open-telemetry/opentelemetry-go/commit/bfd8eb7f85d3364fdde9ad1a408df98be30acadb) chore(deps): update github.com/golangci/rowserrcheck digest to d2031e3 ([#8687](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8687)) * [`48db2c6`](https://github.com/open-telemetry/opentelemetry-go/commit/48db2c659c3b138f971273cd91ea0bcb647768e1) chore(deps): update github/codeql-action action to v4.37.5 ([#8692](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8692)) * Additional commits viewable in [compare view](https://github.com/open-telemetry/opentelemetry-go/compare/v1.44.0...v1.45.0) Updates `go.opentelemetry.io/otel/metric` from 1.44.0 to 1.45.0 Changelog *Sourced from [go.opentelemetry.io/otel/metric's changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md).* > [1.45.0/0.67.0/0.21.0/0.0.18] - 2026-08-03 > ------------------------------------------ > > ### Added > > * Add experimental observability metrics to `BatchProcessor` in `go.opentelemetry.io/otel/sdk/log`. ([#7124](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/7124)) > * Add the experimental `WithUnsafeAttributes` no-copy attribute option to `go.opentelemetry.io/otel/metric/x` for future performance improvements. This API is a work in progress. ([#8251](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8251)) > * Add `Map` and `MapValue` functions for the new `MAP` attribute type in `go.opentelemetry.io/otel/attribute`. ([#8445](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8445)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlptrace`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlplog`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/zipkin`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Apply `AttributeValueLengthLimit` recursively to values contained in `attribute.MAP` attributes in `go.opentelemetry.io/otel/sdk/trace`. ([#8454](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8454)) > * Remove duplicate keys from `attribute.MAP` values in `go.opentelemetry.io/otel/sdk/resource` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/log` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in span, event, link, and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/trace` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in measurement and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/metric` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Extend `WithAllowKeyDuplication` in `go.opentelemetry.io/otel/sdk/log` to disable duplicate-key removal in `attribute.MAP` values for instrumentation scope attributes. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Add the `go.opentelemetry.io/otel/semconv/v1.42.0` package. > The package contains semantic conventions from the `v1.42.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.42.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.41.0`. ([#8484](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8484)) > * Add `WithoutPanicRecording` as a `TracerProviderOption` in `go.opentelemetry.io/otel/sdk/trace` to disable exception event recording for panics. ([#8532](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8532)) > * Add the `go.opentelemetry.io/otel/semconv/v1.43.0` package. > The package contains semantic conventions from the `v1.43.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.43.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.42.0`. ([#8628](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8628)) > > ### Changed > > * `HistogramReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` now uses a time-unbiased sampling algorithm for exemplars. ([#8306](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8306)) > * ⚠️ **Breaking Change:** Use `go.opentelemetry.io/otel/attribute.Value` and `go.opentelemetry.io/otel/attribute.KeyValue` for log bodies and attributes in `go.opentelemetry.io/otel/log`, `go.opentelemetry.io/otel/log/logtest`, `go.opentelemetry.io/otel/sdk/log`, and `go.opentelemetry.io/otel/sdk/log/logtest`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Encode log bodies and attributes as `go.opentelemetry.io/otel/attribute.Value` JSON in `go.opentelemetry.io/otel/exporters/stdout/stdoutlog`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Improve the performance of hashing `BOOLSLICE`, `INT64SLICE`, `FLOAT64SLICE`, and `STRINGSLICE` attribute values by avoiding reflection for short slices in `go.opentelemetry.io/otel/attribute`. ([#8511](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8511)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_METRICS_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_TRACES_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > > ### Deprecated > > * Deprecate `WithExportBufferSize` in `go.opentelemetry.io/otel/sdk/log`. The option remains available for source compatibility but no longer affects behavior; `BatchProcessor` no longer maintains a separate export-request buffer. ([#8620](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8620)) > > ### Removed > > * ⚠️ **Breaking Change:** Remove `Kind`, `Value`, `KeyValue`, their constructors, and attribute conversion helpers from `go.opentelemetry.io/otel/log`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * ⚠️ **Breaking Change:** Remove the `AttributeValueLengthLimit` and `AttributeCountLimit` fields from `RecordFactory` in `go.opentelemetry.io/otel/sdk/log/logtest`; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. ([#8556](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8556)) > > ### Fixed > > * Apply TLS certificates configured through environment variables to gRPC connections in `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc`. > * Prevent panics in `go.opentelemetry.io/otel/bridge/opentracing` when OpenTracing baggage is propagated concurrently with `Span.SetBaggageItem`. > * Fix an off-by-one error in `FixedSizeReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` that prevented the first exemplar from being sampled after the reservoir was filled. ([#8309](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8309)) > * Interpret HTTP `Retry-After` header values as seconds instead of nanoseconds when retrying OTLP HTTP exports in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp`, `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp`, and `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp`. ([#8383](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8383)) > * Fix a memory leak in the `Reservo... > _Description has been truncated_`
Summary
The generated arm64 zstd decoder assembly places every function local 8 bytes too low, so local 0 lands on the saved link register slot. Present since v1.19.0.
This does not corrupt decoded data and cannot produce wrong output. Every local shifts by the same amount, so loads and stores agree — which is exactly why the test suite and fuzzing never caught it.
It also cannot crash any current Go runtime — the original description of this PR overstated the severity as urgent/crash-capable; see the impact section below for the verified mechanics, and the PR comments for the correction history. The present-day impact is confined to best-effort unwinders: corrupted CPU-profile samples and wrong debugger/core-dump backtraces through these frames on arm64. It is still worth fixing promptly: the frame layout is simply wrong, and it becomes a GC fatal error if the runtime ever starts async-preempting assembly functions (an open TODO in
runtime/preempt.go).Impact (verified against go1.26.5 runtime source and disassembly)
Three mechanisms bound the blast radius:
ADD $24, RSP, R29; ADD $32, RSP, RSP; RET) never reloads R30 from the stack — the return address stays live in the register for the whole call.RETis unaffected. (If the epilogue did reload LR, this would have been a 100%-reproducible crash on every decode and caught within hours of the v1.19.0 release.)runtime.Stack, and goroutine profiles only look at goroutines stopped at safe points, andisAsyncSafePoint(runtime/preempt.go:450) returns false for anyFuncFlagAsmfunction — the runtime spins until the goroutine leaves the assembly. These functions make no calls, so no panic or safepoint can occur inside them either. This is a hard exclusion, not a probability.runtime/traceback.go:372-374loads it fromframe.spfor an established innermost frame), as does frame-pointer unwinding ([R29+8]is the same slot). Both are best-effort: the garbage PC failsfindfuncand the sample truncates. No throw.Net effect today: arm64 CPU profiles of zstd-decode-heavy processes contain samples that truncate at, or show a bogus caller above,
sequenceDecs_*; out-of-process debuggers and core-dump analysis cannot unwind past these frames. That is the whole present-day impact — and the full explanation of why nothing has been reported in the wild since v1.19.0 shipped.Root cause
x86 and arm64 store the return address in different places:
CALLpushes it before the callee runs, so it sits above the frame and local 0 is atSP+0.BLleaves it in the link register and the callee spills it to the bottom of its own frame, so0(RSP)is the saved LR and locals begin at8(RSP).The avo arm64 lowering renamed the pseudo stack pointer to
RSPand passed avo's (x86-relative) displacement through unchanged, inheriting x86's layout.Evidence
Disassembled probe functions at two frame sizes:
The +8 does not depend on frame size. For contrast, on amd64
TEXT $8-16emitsSUBQ $8,SPand(SP)really is local 0.Affected functions
sequenceDecs_decode_arm64$8sequenceDecs_decode_56_arm64$8sequenceDecs_decodeSync_arm64$64sequenceDecs_decodeSync_safe_arm64$64All post-fix offsets sit inside their frame's local area (
[8, 8+framesize)).The change
Shifts pseudo-SP displacements by 8 in the lowering, so the regenerated assembly is a mechanical +8 on every local access and nothing else — reviewable by pattern rather than by reading the whole file. The avo pin moves from
a4dbeactoe315f25, which contains only this fix (branched off the currently-pinned commit).amd64output is unchanged.Why this one changes the
.swhen the other lowering work does notWorth stating explicitly, because it is the opposite of what the companion PR shows. Every other change to the arm64 lowering has been verified by regenerating
zstdandhuff0and getting byte-identical output — that is the standing check that a printer change cannot affect shipped code.That check deliberately cannot apply here, because the current bytes are the bug. A fix that left
seqdec_arm64.sunchanged would mean the fix had not taken effect. So the diff is the point, and the way to review it is that its shape is uniform:(RSP)operand — nothing else in the file moves[8, 8+framesize)One reviewing note, because it caught me: do not try to verify this by pairing the
-and+lines in order. git renders the change compactly — a run of stores at8,16,24becoming16,24,32shows only the removed8and the added32, with16and24as unchanged context — so a naive pairing appears to show a +24 jump. Comparing the full offset list per function before and after is the check that actually holds:The
generate (zstd)CI job is the independent confirmation: it regenerates from the pinned avo and fails on any drift, so the checked-in assembly is exactly whate315f25produces.Testing
go test ./zstd/passes on arm64 (Neoverse N1) and amd64.runtime/preempt.goasync-safe-point rules, andruntime/traceback.goLR-machine unwind path.Relationship to #1175
Found while auditing the avo arm64 lowering, and split out deliberately so it can land on its own — it is a bug fix against released versions, and should not queue behind a larger hardening change.
The two do overlap in one file: #1175 also touches
zstd/seqdec_arm64.s. #1175 should rebase onto this, not the other way round. Its own diff to that file is byte-identical apart from picking up this same fix, so after a rebase the frame change appears once, here.Summary by CodeRabbit