Skip to content

zstd: fix arm64 asm frame offsets placing locals on the saved LR slot - #1176

Merged
klauspost merged 1 commit into
klauspost:masterfrom
honeycombio:lizf.arm64-sp-frame
Jul 30, 2026
Merged

klauspost merged 1 commit into
klauspost:masterfrom
honeycombio:lizf.arm64-sp-frame

Conversation

@lizthegrey

@lizthegrey lizthegrey commented Jul 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The generated arm64 zstd decoder assembly places every function local 8 bytes too low, so local 0 lands on the saved link register slot. Present since v1.19.0.

This does not corrupt decoded data and cannot produce wrong output. Every local shifts by the same amount, so loads and stores agree — which is exactly why the test suite and fuzzing never caught it.

It also cannot crash any current Go runtime — the original description of this PR overstated the severity as urgent/crash-capable; see the impact section below for the verified mechanics, and the PR comments for the correction history. The present-day impact is confined to best-effort unwinders: corrupted CPU-profile samples and wrong debugger/core-dump backtraces through these frames on arm64. It is still worth fixing promptly: the frame layout is simply wrong, and it becomes a GC fatal error if the runtime ever starts async-preempting assembly functions (an open TODO in runtime/preempt.go).

Impact (verified against go1.26.5 runtime source and disassembly)

Three mechanisms bound the blast radius:

  1. Normal execution never reads the clobbered slot. All four functions are leaves, and Go's arm64 leaf epilogue (ADD $24, RSP, R29; ADD $32, RSP, RSP; RET) never reloads R30 from the stack — the return address stays live in the register for the whole call. RET is unaffected. (If the epilogue did reload LR, this would have been a 100%-reproducible crash on every decode and caught within hours of the v1.19.0 release.)
  2. Precise unwinders can never observe the frame. GC stack scanning, stack growth, runtime.Stack, and goroutine profiles only look at goroutines stopped at safe points, and isAsyncSafePoint (runtime/preempt.go:450) returns false for any FuncFlagAsm function — the runtime spins until the goroutine leaves the assembly. These functions make no calls, so no panic or safepoint can occur inside them either. This is a hard exclusion, not a probability.
  3. The only readers fail soft. SIGPROF tracebacks land at arbitrary PCs and do read the saved-LR slot (runtime/traceback.go:372-374 loads it from frame.sp for an established innermost frame), as does frame-pointer unwinding ([R29+8] is the same slot). Both are best-effort: the garbage PC fails findfunc and the sample truncates. No throw.

Net effect today: arm64 CPU profiles of zstd-decode-heavy processes contain samples that truncate at, or show a bogus caller above, sequenceDecs_*; out-of-process debuggers and core-dump analysis cannot unwind past these frames. That is the whole present-day impact — and the full explanation of why nothing has been reported in the wild since v1.19.0 shipped.

Root cause

x86 and arm64 store the return address in different places:

  • x86: CALL pushes it before the callee runs, so it sits above the frame and local 0 is at SP+0.
  • arm64: BL leaves it in the link register and the callee spills it to the bottom of its own frame, so 0(RSP) is the saved LR and locals begin at 8(RSP).

The avo arm64 lowering renamed the pseudo stack pointer to RSP and passed avo's (x86-relative) displacement through unchanged, inheriting x86's layout.

Evidence

Disassembled probe functions at two frame sizes:

arm64  TEXT $8-16:   MOVD.W R30, -32(RSP)     <- saved LR at 0(RSP)
                     local-8(SP)  -> 8(RSP)   <- assembler's local 0
                     (RSP)        -> 0(RSP)   <- what we emitted

arm64  TEXT $64-16:  local 0 -> 8(RSP), local 56 -> 64(RSP)

The +8 does not depend on frame size. For contrast, on amd64 TEXT $8-16 emits SUBQ $8,SP and (SP) really is local 0.

Affected functions

function frame offsets before after
sequenceDecs_decode_arm64 $8 0 8
sequenceDecs_decode_56_arm64 $8 0 8
sequenceDecs_decodeSync_arm64 $64 0–56 8–64
sequenceDecs_decodeSync_safe_arm64 $64 0–56 8–64

All post-fix offsets sit inside their frame's local area ([8, 8+framesize)).

The change

Shifts pseudo-SP displacements by 8 in the lowering, so the regenerated assembly is a mechanical +8 on every local access and nothing else — reviewable by pattern rather than by reading the whole file. The avo pin moves from a4dbeac to e315f25, which contains only this fix (branched off the currently-pinned commit).

amd64 output is unchanged.

Why this one changes the .s when the other lowering work does not

Worth stating explicitly, because it is the opposite of what the companion PR shows. Every other change to the arm64 lowering has been verified by regenerating zstd and huff0 and getting byte-identical output — that is the standing check that a printer change cannot affect shipped code.

That check deliberately cannot apply here, because the current bytes are the bug. A fix that left seqdec_arm64.s unchanged would mean the fix had not taken effect. So the diff is the point, and the way to review it is that its shape is uniform:

  • 148 changed lines, and every one carries an (RSP) operand — nothing else in the file moves
  • across the four functions, all 78 frame accesses shift by exactly +8
  • no instruction added, removed, or reordered; no operand other than the displacement differs
  • every resulting offset lands inside its frame's local area, [8, 8+framesize)
$ git diff master -- zstd/seqdec_arm64.s | grep '^[+-]' | grep -v '^[+-][+-]' | grep -vc '(RSP)'
0

One reviewing note, because it caught me: do not try to verify this by pairing the - and + lines in order. git renders the change compactly — a run of stores at 8,16,24 becoming 16,24,32 shows only the removed 8 and the added 32, with 16 and 24 as unchanged context — so a naive pairing appears to show a +24 jump. Comparing the full offset list per function before and after is the check that actually holds:

sequenceDecs_decode_arm64:          3 accesses, every offset +8
sequenceDecs_decode_56_arm64:       3 accesses, every offset +8
sequenceDecs_decodeSync_arm64:     36 accesses, every offset +8
sequenceDecs_decodeSync_safe_arm64: 36 accesses, every offset +8

The generate (zstd) CI job is the independent confirmation: it regenerates from the pinned avo and fails on any drift, so the checked-in assembly is exactly what e315f25 produces.

Testing

  • go test ./zstd/ passes on arm64 (Neoverse N1) and amd64.
  • Frame layout verified by disassembly at two frame sizes, as above.
  • Impact analysis verified against the go1.26.5 runtime: leaf epilogue disassembly of the shipped functions, runtime/preempt.go async-safe-point rules, and runtime/traceback.go LR-machine unwind path.

Relationship to #1175

Found while auditing the avo arm64 lowering, and split out deliberately so it can land on its own — it is a bug fix against released versions, and should not queue behind a larger hardening change.

The two do overlap in one file: #1175 also touches zstd/seqdec_arm64.s. #1175 should rebase onto this, not the other way round. Its own diff to that file is byte-identical apart from picking up this same fix, so after a rebase the frame change appears once, here.

Summary by CodeRabbit

  • Bug Fixes
    • Improved ARM64 decoding reliability by reorganizing internal temporary storage and updating related value handling.
    • Updated the ARM64 decoding dependency to a newer revision for improved compatibility and stability.

The generated arm64 decoder assembly places every function local 8 bytes
too low, so local 0 lands on the saved link register.

x86 and arm64 put the return address in different places. On x86, CALL
pushes it before the callee runs, so it sits above the frame and local 0
is at SP+0. On arm64, BL leaves it in the link register and the callee
spills it to the BOTTOM of its own frame, so 0(RSP) is the saved LR and
locals start at 8(RSP). The avo arm64 lowering renamed the pseudo stack
pointer to RSP and passed the displacement through unchanged, inheriting
x86's layout.

Verified by disassembling probe functions at two frame sizes: for both
TEXT $8 and TEXT $64 the assembler places pseudo-SP local 0 at 8(RSP),
while the prologue's MOVD.W R30, -N(RSP) puts the saved LR at 0(RSP).
The 8-byte offset does not depend on frame size.

Affected: sequenceDecs_decode_arm64, sequenceDecs_decode_56_arm64,
sequenceDecs_decodeSync_arm64 and sequenceDecs_decodeSync_safe_arm64,
all present since v1.19.0.

Scope: this does NOT corrupt decoded data and cannot produce wrong
output. Every local shifts by the same 8 bytes, so loads and stores
agree and the arithmetic is self-consistent; that is why the test suite
and fuzzing never caught it. These are leaf functions, so the link
register is still live in R30 and RET works. What breaks is the unwind
path only: GC stack scanning, panics and profiling read the return
address from 0(RSP) and find decoder state there.

The fix shifts pseudo-SP displacements by 8 in the lowering, so the
regenerated assembly is a mechanical +8 on every local access and
nothing else. zstd tests pass on arm64 (Neoverse N1).
@coderabbitai

coderabbitai Bot commented Jul 25, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Updates the AVO replacement pin and remaps stack spill/reload offsets across ARM64 sequence decoder routines, including synchronous safe and non-safe paths and their validation and error handling.

Changes

ARM64 decoder updates

Layer / File(s) Summary
AVO pin and base decoder spills
zstd/_generate/go.mod, zstd/seqdec_arm64.s
Updates the AVO replacement version and moves temporary spills in the base and decode_56 ARM64 decoder routines.
Synchronous decoder stack layout
zstd/seqdec_arm64.s
Reorganizes stack slots in sequenceDecs_decodeSync_arm64 and updates state reloads, bounds checks, match copying, and error returns.
Safe synchronous decoder alignment
zstd/seqdec_arm64.s
Applies the corresponding stack-slot remapping to sequenceDecs_decodeSync_safe_arm64, including validation, copying, and error paths.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately and concisely summarizes the arm64 zstd stack-frame offset fix described by the changes.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

lizthegrey added a commit to honeycombio/compress that referenced this pull request Jul 25, 2026
Carries the frame-offset fix that is in flight separately as klauspost#1176, so
this branch validates against a printer that has it; expect a rebase
once that lands. The only change to generated assembly is that fix -- a
mechanical +8 on every local access in seqdec_arm64.s, with every offset
landing inside its frame's local area. huff0 and the amd64 output are
untouched, which is the evidence that round seven's other fixes are not
reachable from these generators.

Those others: the three-operand SHL/SHR forms are rejected (they are
SHLD/SHRD, a different instruction whose destination is the third
operand); preprocessor directives are normalized so "# else" is
recognized, since Go's assembler tokenizes the '#' separately and a
missed #else drops BOTH arms; and the mixed-comment check moved into
the preprocessor evaluator, deleting a second stateless opinion about
directive ownership that had already disagreed with the authoritative
one.
@lizthegrey

lizthegrey commented Jul 25, 2026 •

Copy link
Copy Markdown
Contributor Author

Note

Rescinded 2026-07-29. The crash scenario this comment assumes cannot occur on current Go runtimes; impact is limited to CPU-profile samples and debugger backtraces. See the severity correction. Struck through, retained for history.

One release-policy question this raises, which is yours to decide, @klauspost — flagging it rather than assuming either way.

The bug is in v1.19.0 and v1.19.1 (absent from v1.18.x), so retract is worth considering. I have deliberately not added one to this PR, because it does not look like it meets the bar this project has used:

retracted reason
v1.14.1–v1.14.3 data corruption in flate BestCompression (#503)
v1.18.1 #1114

Both are wrong-output bugs. This one is not: decoded data is correct on every input, which is exactly why the test suite and fuzzing never caught it. The failure is confined to stack unwinding — GC scanning, panics, profiling — on arm64 only, and only while one of the four affected frames is live.

My read is that a patch release is worth cutting sooner than the next feature release, since sarama and vitess both pin v1.19.x, but that retraction would be disproportionate and disruptive for a bug that cannot produce wrong output. Happy to add the retract block if you disagree — it is a two-line change and I would rather you decide it than inherit my judgement of the severity.

Postscript (unstruck): the conclusion survives the severity correction — no retract, and a patch release ahead of the next feature release is still worthwhile, now for profiling/debugging fidelity rather than crash risk.

@lizthegrey

lizthegrey commented Jul 25, 2026 •

Copy link
Copy Markdown
Contributor Author

Note

Rescinded 2026-07-29. The crash scenario this comment assumes cannot occur on current Go runtimes; impact is limited to CPU-profile samples and debugger backtraces. See the severity correction. Struck through, retained for history.

If you arrived here from a crash

Adding the symptom vocabulary, because the failure does not look like a compress bug from the outside — it looks like a Go runtime bug, and that is where it would naturally be reported.

A corrupted saved link register only matters when something walks the stack, so the crash surfaces inside the runtime's unwinder rather than in decoding. Plausible shapes, on linux/arm64 or darwin/arm64 only:

fatal error: traceback stuck
runtime: traceback stuck. pc=... sp=...
runtime: unexpected return pc for ...
fatal error: unexpected signal during runtime execution

with runtime.gentraceback, runtime.(*unwinder).next, runtime.tracebackPCs, runtime.scanstack, runtime.scanobject, runtime.sigprof or runtime.doRecordGoroutineProfile on the stack, and zstd decoding somewhere in the interrupted goroutine — typically sequenceDecs_decode_arm64 or sequenceDecs_decodeSync_arm64.

Most likely trigger is a continuous CPU profiler (Datadog, Pyroscope, pprof), because SIGPROF interrupts arbitrary code and unwinds immediately. GC stack scanning is a less likely trigger, since hand-written assembly is generally not async-preemptible, so the collector will usually not stop a goroutine inside these frames.

Two caveats, stated plainly: I have not reproduced a crash from this — the diagnosis is from the frame layout, which is verified by disassembly. And a traceback stuck on arm64 is not automatically this bug; golang/go#62086 collects several unrelated causes, and at least one report there is on a compress version predating this code entirely.

If you hit something matching the above on v1.19.0 or v1.19.1 with zstd decoding on arm64, a stack dump on this PR would be genuinely useful — it would turn a reasoned diagnosis into a confirmed one.

@lizthegrey

lizthegrey commented Jul 25, 2026 •

Copy link
Copy Markdown
Contributor Author

Note

Rescinded 2026-07-29. The crash scenario this comment assumes cannot occur on current Go runtimes; impact is limited to CPU-profile samples and debugger backtraces. See the severity correction. Struck through, retained for history.

Exposure is still small, but that depends on release timing

Audited the significant zstd dependents to see who has actually picked this up. The window is narrow — v1.19.0 is dated 2026-06-30 and v1.19.1 is days old — so only four projects have shipped it inside a tagged release:

shipped release requires
open-telemetry/opentelemetry-collector v0.157.0 v1.19.0
apache/arrow-go v18.7.0 v1.19.0
IBM/sarama v1.60.0 v1.19.0
anchore/syft v1.49.0 v1.19.0

(Verified by reading go.mod at each tag, not inferred.)

Everything else I found on v1.19.x is HEAD-only and would absorb it at its next release: containerd, moby, buildkit, tailscale, talos, soci-snapshotter, VictoriaMetrics, ch-go, google/go-containerregistry, vitess, mimir, iceberg-go, gitea.

Which is the argument for cutting a patch release sooner rather than folding this into the next feature release: most of the exposure has not happened yet and a fast v1.19.2 prevents it outright. The four above are the only ones that would need to re-release.

Two caveats so this is not read as more precise than it is:

  • These are declared requirements. Minimal version selection can still pull v1.19.x into a build whose own go.mod asks for v1.18.x, if any other dependency requires it — I did not compute transitive resolution.
  • ~~opentelemetry-collector-contrib was not enumerated (~200 modules); one sampled component had it indirectly in v0.157.0, so contrib coverage is inferred.~~

One useful negative: nats-io/nats-server requires v1.19.0 but uses only s2, so it is unaffected despite matching on version. Matching the version alone overstates the blast radius — the zstd decode path is the thing that matters.

@lizthegrey lizthegrey changed the title zstd: URGENT - arm64 asm locals overwrite the saved link register zstd: fix arm64 asm frame offsets placing locals on the saved LR slot Jul 29, 2026
@lizthegrey

lizthegrey commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor Author

Severity correction — this is not urgent, and I have retitled and rewritten the description accordingly.

The original title/body claimed this could crash any arm64 process that decodes zstd while something walks its stack (GC, panic, profiling). After tracing the actual runtime behavior, that was wrong. Verified against the shipped binaries and the go1.26.5 runtime source:

  1. Normal execution never reads the clobbered slot. All four functions are leaves; the arm64 leaf epilogue is ADD $24, RSP, R29; ADD $32, RSP, RSP; RET — R30 is never reloaded from the stack.
  2. GC scanning, stack growth, runtime.Stack, and goroutine profiles can never observe these frames. isAsyncSafePoint (runtime/preempt.go:450) refuses to preempt inside any FuncFlagAsm function, and the functions make no calls, so precise unwinders only ever run after the frame is gone. Structural exclusion, not luck.
  3. The only readers — SIGPROF tracebacks and frame-pointer unwinds — fail soft. The garbage "return address" fails symbolization and the sample truncates. No throw.

So the real, present-day impact is: corrupted/truncated CPU-profile samples and broken debugger/core-dump backtraces through sequenceDecs_* on arm64. That also fully explains why nothing was reported in the wild since v1.19.0 — a crash was never possible, not merely unlikely. The latent risk that keeps this worth fixing promptly is the TODO directly below preempt.go:450: if the runtime ever starts async-preempting assembly, this frame layout becomes a GC fatal error.

The fix itself is unchanged. I have also closed the downstream heads-up issues I filed with the same correction: IBM/sarama#3684, open-telemetry/opentelemetry-collector#15660, apache/arrow-go#1016.

The original framing was out of an abundance of caution — clobbering a saved return address warranted treating as urgent until the runtime mechanics proved otherwise.

@klauspost

Copy link
Copy Markdown
Owner

ok, good analysis, merging for now. afk for the moment, so will release early next week.

@klauspost
klauspost merged commit 69c9db4 into klauspost:master Jul 30, 2026
29 checks passed
lizthegrey added a commit to honeycombio/compress that referenced this pull request Jul 30, 2026
Generated assembly is unchanged, byte for byte. The frame-offset fix this
round originally carried landed separately as klauspost#1176 and is already in the
base; regenerating against this pin reproduces it exactly, which is the
check that the two arrived at the same answer rather than merely at
compatible ones.

Round seven's other fixes are not reachable from these generators: the
three-operand SHL/SHR forms are rejected (they are SHLD/SHRD, a different
instruction whose destination is the third operand); preprocessor
directives are normalized so "# else" is recognized, since Go's assembler
tokenizes the '#' separately and a missed #else drops BOTH arms; and the
mixed-comment check moved into the preprocessor evaluator, deleting a
second stateless opinion about directive ownership that had already
disagreed with the authoritative one.
nschloe pushed a commit to live-clones/forgejo that referenced this pull request Aug 7, 2026
…804)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/klauspost/compress](https://github.com/klauspost/compress) | `v1.19.1` → `v1.19.2` | ![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fklauspost%2fcompress/v1.19.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fklauspost%2fcompress/v1.19.1/v1.19.2?slim=true) |

---

### Release Notes

<details>
<summary>klauspost/compress (github.com/klauspost/compress)</summary>

### [`v1.19.2`](https://github.com/klauspost/compress/releases/tag/v1.19.2)

[Compare Source](klauspost/compress@v1.19.1...v1.19.2)

#### What's Changed

- huff0: add arm64 assembly for Decompress4X/1X via avo lowering by [@&#8203;lizthegrey](https://github.com/lizthegrey) in [#&#8203;1172](klauspost/compress#1172)
- zstd: Re-enable unsafe decodeSync memory copies ([#&#8203;1168](klauspost/compress#1168)) by [@&#8203;lizthegrey](https://github.com/lizthegrey) in [#&#8203;1171](klauspost/compress#1171)
- zstd: fix arm64 asm frame offsets placing locals on the saved LR slot by [@&#8203;lizthegrey](https://github.com/lizthegrey) in [#&#8203;1176](klauspost/compress#1176)
- zstd: avoid racing MaxDecodedSize write on shared dict litEnc by [@&#8203;zanarellidev](https://github.com/zanarellidev) in [#&#8203;1182](klauspost/compress#1182)
- zstd: keep BuildDict recent-offsets positive and loadable by [@&#8203;zanarellidev](https://github.com/zanarellidev) in [#&#8203;1184](klauspost/compress#1184)
- zstd: handle zero-literal BuildDict corpus by [@&#8203;cyphercodes](https://github.com/cyphercodes) in [#&#8203;1178](klauspost/compress#1178)
- zstd: don't clear the registered dictionary when decoding past the window by [@&#8203;sueun-dev](https://github.com/sueun-dev) in [#&#8203;1177](klauspost/compress#1177)

#### New Contributors

- [@&#8203;zanarellidev](https://github.com/zanarellidev) made their first contribution in [#&#8203;1183](klauspost/compress#1183)
- [@&#8203;cyphercodes](https://github.com/cyphercodes) made their first contribution in [#&#8203;1178](klauspost/compress#1178)
- [@&#8203;sueun-dev](https://github.com/sueun-dev) made their first contribution in [#&#8203;1177](klauspost/compress#1177)

**Full Changelog**: <klauspost/compress@v1.19.1...v1.19.2>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC43LjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC43LjIiLCJ0YXJnZXRCcmFuY2giOiJmb3JnZWpvIiwibGFiZWxzIjpbImRlcGVuZGVuY3ktdXBncmFkZSIsInRlc3Qvbm90LW5lZWRlZCJdfQ==-->

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13804
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
klauspost added a commit that referenced this pull request Aug 7, 2026
…OVWQZX (#1175)

* zstd, huff0: regenerate arm64 assembly with the improved avo lowering

No source or algorithm change: the same generators, re-run against a
lowering that emits better arm64. Two improvements account for it.

128-bit moves now use FMOVQ, which takes a base+displacement operand
directly, where the previous VLD1/VST1 needed the address materialized into
a scratch register first. And scalar accesses fold base+index into the
instruction when arm64 permits it (the index shift must equal log2 of the
access width, and no displacement may be present), with a cache so a run of
accesses sharing a base and index computes the address once. x86 folds
base+index+displacement into a single instruction and the generators lean on
that heavily, so this recovers much of what the lowering used to pay per
access.

seqdec_arm64.s and decompress_arm64.s together shed about 90 lines. The
amd64 assembly is byte-identical.

Measured on Neoverse N1 (Ampere, go1.26, -count 6, every result p<0.03):

  Decoder_DecodeAll geomean            -1.53%
    html.zst                           -2.29%
    plrabn12.txt.zst                   -2.19%
    lcet10.txt.zst                     -2.11%
    kppkn.gtb.zst                      -2.08%
    alice29.txt.zst                    -2.02%
  huff0 Decompress geomean             -0.81%
    Decompress4X/twain                 -2.81%

Inputs that are not sequence-bound (fireworks.jpeg, html_x_4) are unchanged,
as expected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* zstd, huff0: bump the pinned avo to pick up thirteen lowering fixes

Generated output is unchanged -- regenerating against this pin reproduces
every .s file byte for byte, which also confirms none of the fixed bugs was
reachable from these generators. The pin still matters: it is what the next
regeneration uses.

Three review passes over the lowering found thirteen ways it could emit
plausible-looking but wrong arm64. About half are wrong values: byte extends
reading the wrong field from a high-byte source, a 32-bit conditional move
losing x86's unconditional zero-extension, a negative 32-bit immediate
sign-extending across all 64 bits, BEXTR clobbering its own staged control
field with a memory source, and compare/test/multiply loading eight bytes for
a four-byte memory operand, which can fault at a page boundary.

The rest are cases where the two architectures disagree about what a flag
means, and the lowering now refuses to translate rather than emit something
plausible: carry conditions after additions and after logical ops (both
invert), carry read across INC/DEC (which preserve it on x86 but not once
lowered), ADC after anything but a compare or subtract, a signed sub-word
compare whose consumer sits past a flag-transparent instruction, and the
XOR-self zeroing shortcut, which dropped the zero flag x86 sets there.

The last round also resolves the GOAMD64 conditionals before the flag
analyses run, so those see exactly the instructions that will be emitted --
otherwise a producer inside a dead arm could absorb a mark a live one needed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* zstd, huff0: narrow two table loads to MOVWQZX, and bump the pinned avo

The avo bump carries seven lowering fixes from a fourth review pass (see
the fork's log). One of them matters here: a 16-bit load into a register
lowered to a zero-extending arm64 load, where x86 preserves the upper 48
bits. Nothing in this repository was miscompiled by that -- at all forty
affected sites the destination's upper bits are dead, so zero-extending
was harmless as applied -- but the printer cannot know that, and an avo
program that did depend on those bits would have gotten wrong code.

Making the lowering exact costs an instruction on every 16-bit load, and
that instruction reads the destination it writes, which turns an
independent load in huff0's innermost decode loop into a loop-carried
dependency: measured +11.74% geomean on Decompress4X on Neoverse N1, up
to +19% (p=0.000, n=12). zstd's DecodeAll paid a smaller +0.73%.

So this asks for what the code actually wants. Every one of these sites
loads a table entry and then reads only its low bits, so none of them
needs the surrounding register preserved; MOVWQZX says that, and lowers
back to a single folded load. This is belt and suspenders -- there was no
bug here to fix -- it just keeps the general safety fix from costing
anything where preservation was never wanted.

It is also simply the better x86 encoding, which is worth having on its
own: MOVZX avoids the 66h operand-size prefix and the partial-register
merge dependency, the same hazard that cost 11.74% on arm64. On amd64
huff0 Decompress4X that is -7.59% geomean, up to -14.10% (p=0.000, n=12,
Ryzen 5 5600X).

Net effect on generated code: huff0/decompress_arm64.s and
zstd/seqdec_arm64.s are byte-identical to before, zstd/fse_decoder_arm64.s
loses two instructions to folded addressing, and the amd64 files pick up
the faster encoding. The two changes land together because the pin bump
alone would regress arm64 until the generators were narrowed.

* zstd, huff0: bump the pinned avo for the round-five lowering fixes

Generated assembly is unchanged, byte for byte. None of this round's
bugs was reachable from these generators: they emit only GOAMD64
directives, which the lowering resolves and removes, so the state that
was leaking across foreign preprocessor arms had nothing to leak past.
The pin moves anyway so the committed assembly corresponds to a printer
we would be willing to point at other code.

* zstd, huff0: bump the pinned avo for the round-six lowering fixes

Generated assembly is unchanged, byte for byte. The 64-bit immediate
sign-extension bug this picks up needs a Q-width immediate with bit 31
set, which neither of these generators emits -- s2's does, which is why
it was worth finding.

* zstd, huff0: bump the pinned avo for the round-seven lowering fixes

Generated assembly is unchanged, byte for byte. The frame-offset fix this
round originally carried landed separately as #1176 and is already in the
base; regenerating against this pin reproduces it exactly, which is the
check that the two arrived at the same answer rather than merely at
compatible ones.

Round seven's other fixes are not reachable from these generators: the
three-operand SHL/SHR forms are rejected (they are SHLD/SHRD, a different
instruction whose destination is the third operand); preprocessor
directives are normalized so "# else" is recognized, since Go's assembler
tokenizes the '#' separately and a missed #else drops BOTH arms; and the
mixed-comment check moved into the preprocessor evaluator, deleting a
second stateless opinion about directive ownership that had already
disagreed with the authoritative one.

* zstd, huff0: bump the pinned avo for the round-eight lowering changes

The address cache is gone from the lowering. It let a second access to
the same base and index reuse the register the first one computed, and
it had to be invalidated at every boundary the printer does not
otherwise model -- two of the silent miscompiles found in review were
missing invalidations rather than missing lowerings.

Measured here, it was worth two instructions: seqdec_arm64.s and
huff0/decompress_arm64.s are byte-identical without it, and
fse_decoder_arm64.s gains two ADDs in buildDtable, which runs once per
block. Most accesses fold base+index into the instruction and never
materialize an address at all, so there was rarely anything to cache.

Round eight's review found no new lowering bugs, so the rest is
housekeeping: dead code removed, a confusing panic given a real message.

* zstd, huff0: bump the pinned avo for the round-nine lowering fixes

Generated assembly is unchanged, byte for byte. None of round nine's
bugs is reachable from these generators: the CMN boundary case needs a
compare against INT32_MIN written as a signed immediate, and the two
directive-coupling holes need directives, which neither generator emits.

* zstd, huff0: bump the pinned avo for the round-ten and -eleven changes

Generated assembly is unchanged, byte for byte, including across the
removal of the lowering's preprocessor-directive support -- neither of
these generators emits a directive, which is most of why that support
was removed.

Also picks up shift counts at or above the operand width being masked
the way x86 masks them, rather than passing through to an arm64
immediate form that rejects them, and 64-bit immediates written unsigned
with the top bit set being read as the bit pattern amd64 wraps them to
rather than refused.

* zstd, huff0: bump the pinned avo for the round-eleven guard fixes

Generated assembly unchanged, byte for byte. Both fixes are to the guard
that refuses preprocessor directives, which neither of these generators
emits.

* zstd, huff0: bump the pinned avo for the round-twelve guard fixes

The only change to generated assembly is one build-tag line per file:
the original constraint is now bracketed before the arm64 term is
ANDed onto it. That is a no-op for these three -- every constraint here
is a pure AND chain -- but without it a constraint containing || would
have parsed as "(arm64 && ...) || ..." and pulled the arm64 assembly
into non-arm64 builds.

Instructions are byte-identical. Verified building and testing both
architectures.

* zstd, huff0: bump the pinned avo for the label-name guard

Generated assembly unchanged, byte for byte.

* zstd, huff0: bump the pinned avo for the round-thirteen hardening

Generated assembly unchanged, byte for byte. Round thirteen found no
miscompiles; the changes make flag transparency, instruction suffixes,
branch targets and the one-line output invariant into properties this
printer checks itself rather than ones that held because a separate tool
happened to reject the alternative.

* zstd, huff0: bump the pinned avo for the round-fourteen enforcement

Generated assembly unchanged, byte for byte. The lowering now checks both
directions of the flag contract at generation time: an instruction claimed
flag-neutral must emit no flag-writers, and one marked as a producer must
emit exactly one.

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Klaus Post <klauspost@gmail.com>
mergify Bot added a commit to ArcadeData/arcadedb that referenced this pull request Aug 9, 2026
…p ci]

Bumps the go-modules group in /e2e-go with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [github.com/klauspost/compress](https://github.com/klauspost/compress) | `1.19.1` | `1.19.2` |
| [github.com/moby/go-archive](https://github.com/moby/go-archive) | `0.3.2` | `0.3.3` |
| [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp](https://github.com/open-telemetry/opentelemetry-go-contrib) | `0.69.0` | `0.70.0` |
| [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` |
| [go.opentelemetry.io/otel/metric](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` |
| [go.opentelemetry.io/otel/trace](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` |
Updates `github.com/klauspost/compress` from 1.19.1 to 1.19.2
Release notes

*Sourced from [github.com/klauspost/compress's releases](https://github.com/klauspost/compress/releases).*

> v1.19.2
> -------
>
> What's Changed
> --------------
>
> * huff0: add arm64 assembly for Decompress4X/1X via avo lowering by [`@​lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1172](https://redirect.github.com/klauspost/compress/pull/1172)
> * zstd: Re-enable unsafe decodeSync memory copies ([#1168](https://redirect.github.com/klauspost/compress/issues/1168)) by [`@​lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1171](https://redirect.github.com/klauspost/compress/pull/1171)
> * zstd: fix arm64 asm frame offsets placing locals on the saved LR slot by [`@​lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1176](https://redirect.github.com/klauspost/compress/pull/1176)
> * zstd: avoid racing MaxDecodedSize write on shared dict litEnc by [`@​zanarellidev`](https://github.com/zanarellidev) in [klauspost/compress#1182](https://redirect.github.com/klauspost/compress/pull/1182)
> * zstd: keep BuildDict recent-offsets positive and loadable by [`@​zanarellidev`](https://github.com/zanarellidev) in [klauspost/compress#1184](https://redirect.github.com/klauspost/compress/pull/1184)
> * zstd: handle zero-literal BuildDict corpus by [`@​cyphercodes`](https://github.com/cyphercodes) in [klauspost/compress#1178](https://redirect.github.com/klauspost/compress/pull/1178)
> * zstd: don't clear the registered dictionary when decoding past the window by [`@​sueun-dev`](https://github.com/sueun-dev) in [klauspost/compress#1177](https://redirect.github.com/klauspost/compress/pull/1177)
>
> New Contributors
> ----------------
>
> * [`@​zanarellidev`](https://github.com/zanarellidev) made their first contribution in [klauspost/compress#1183](https://redirect.github.com/klauspost/compress/pull/1183)
> * [`@​cyphercodes`](https://github.com/cyphercodes) made their first contribution in [klauspost/compress#1178](https://redirect.github.com/klauspost/compress/pull/1178)
> * [`@​sueun-dev`](https://github.com/sueun-dev) made their first contribution in [klauspost/compress#1177](https://redirect.github.com/klauspost/compress/pull/1177)
>
> **Full Changelog**: <https://github.com/klauspost/compress/compare/v1.19.1...v1.19.2>


Commits

* [`c3b3439`](https://github.com/klauspost/compress/commit/c3b3439a48196b5082c63252bfb8633d0a2faad4) zstd: don't clear the registered dictionary when decoding past the window ([#1](https://redirect.github.com/klauspost/compress/issues/1)...
* [`9874bc9`](https://github.com/klauspost/compress/commit/9874bc9073f350ce462becb84f9a23c3e828d03f) fix(zstd): handle zero-literal BuildDict corpus ([#1178](https://redirect.github.com/klauspost/compress/issues/1178))
* [`71bb6fd`](https://github.com/klauspost/compress/commit/71bb6fd9ddbfbb2ca6612542a916c766a866bfb3) zstd: keep BuildDict recent-offsets positive and loadable ([#1184](https://redirect.github.com/klauspost/compress/issues/1184))
* [`3d4dacb`](https://github.com/klauspost/compress/commit/3d4dacbaa9faca75caacc35b6d75731a81a92c6b) zstd: avoid racing MaxDecodedSize write on shared dict litEnc ([#1182](https://redirect.github.com/klauspost/compress/issues/1182))
* [`3ceaa81`](https://github.com/klauspost/compress/commit/3ceaa81409aabe39c71821b936155b33471c78d8) build(deps): bump the github-actions group with 5 updates ([#1185](https://redirect.github.com/klauspost/compress/issues/1185))
* [`72cb4d3`](https://github.com/klauspost/compress/commit/72cb4d3e8e743bea5d1ba40896ad55214a1844e4) chore: add OpenSSF Scorecard GitHub Action ([#1183](https://redirect.github.com/klauspost/compress/issues/1183))
* [`69c9db4`](https://github.com/klauspost/compress/commit/69c9db420ae55bfcdfbef564805e2646206545f7) zstd: fix arm64 asm locals overwriting the saved link register ([#1176](https://redirect.github.com/klauspost/compress/issues/1176))
* [`117430d`](https://github.com/klauspost/compress/commit/117430d3b0e3c39c14d32fe7c90652149a78e609) zstd: Re-enable unsafe decodeSync memory copies ([#1168](https://redirect.github.com/klauspost/compress/issues/1168)) ([#1171](https://redirect.github.com/klauspost/compress/issues/1171))
* [`c73af0c`](https://github.com/klauspost/compress/commit/c73af0c12cc767386af8388f30d5aa7428e6dfc8) huff0: add arm64 assembly for Decompress4X/1X via avo lowering ([#1172](https://redirect.github.com/klauspost/compress/issues/1172))
* See full diff in [compare view](https://github.com/klauspost/compress/compare/v1.19.1...v1.19.2)
  
Updates `github.com/moby/go-archive` from 0.3.2 to 0.3.3
Release notes

*Sourced from [github.com/moby/go-archive's releases](https://github.com/moby/go-archive/releases).*

> v0.3.3
> ------
>
> What's Changed
> --------------
>
> * Fix a regression introduced in v0.3.0 that caused archive extraction to reject hardlinks with absolute targets, as produced by
>   some image builders. Absolute hardlink targets are now resolved relative to the extraction root, while paths that escape the root
>   remain rejected. [moby/go-archive#100](https://redirect.github.com/moby/go-archive/pull/100)
> * Fix a regression introduced in v0.3.0 that caused archive extraction to fail when applying permissions to device nodes, including
>   nodes on `nodev` filesystems and `dev/ptmx`. Device nodes are now referenced without opening the underlying device before applying
>   their mode. [moby/go-archive#103](https://redirect.github.com/moby/go-archive/pull/103)
> * Set close-on-exec on file descriptors used by the Linux permission fallback to prevent them from leaking into child processes.
>   [moby/go-archive#104](https://redirect.github.com/moby/go-archive/pull/104)
>
> **Full Changelog**: <https://github.com/moby/go-archive/compare/v0.3.2...v0.3.3>


Commits

* [`ae9e219`](https://github.com/moby/go-archive/commit/ae9e219f7104d91e262055a29bae1f9753106981) Merge pull request [#104](https://redirect.github.com/moby/go-archive/issues/104) from thaJeztah/use\_O\_CLOEXEC
* [`98ff1da`](https://github.com/moby/go-archive/commit/98ff1dac11141c20bf7975ee1243fbe5031c2684) archive: set close-on-exec for chmod fallback descriptors
* [`1e8dfbc`](https://github.com/moby/go-archive/commit/1e8dfbc6ec14614f009716c5ec04b6d104168201) Merge pull request [#103](https://redirect.github.com/moby/go-archive/issues/103) from thaJeztah/fix\_chmod\_fallback
* [`e738eed`](https://github.com/moby/go-archive/commit/e738eed524c260a613bea37a47349e0f7d0a45a6) archive: keep procfs file alive during fchmodat
* [`2d863f5`](https://github.com/moby/go-archive/commit/2d863f57793b7e2340cfca8f9a94a2d55cf7e68e) archive: preserve procfs access during chroot extraction
* [`89653ed`](https://github.com/moby/go-archive/commit/89653edcda61f24e83ae2aa485f57cf762c59568) archive: fix chmod fallback for device nodes on nodev mounts
* [`f37d413`](https://github.com/moby/go-archive/commit/f37d413855106b6c4f5cc3c063013869b6294e7d) Merge pull request [#106](https://redirect.github.com/moby/go-archive/issues/106) from thaJeztah/fallback\_no\_read
* [`4ffc915`](https://github.com/moby/go-archive/commit/4ffc91517ffd9b77b11efd91768b5d6d4303a3b6) archive: test chmod fallback without read permission
* [`9af1c40`](https://github.com/moby/go-archive/commit/9af1c40d9b972e82affd0b3ed3beb3f5d4d5f5d2) Merge pull request [#105](https://redirect.github.com/moby/go-archive/issues/105) from thaJeztah/test\_chrooted\_chmod\_fallback
* [`3daca2a`](https://github.com/moby/go-archive/commit/3daca2abcac72471e1424cc840e7c5711937ade9) archive: test chmod fallback without procfs in chroot
* Additional commits viewable in [compare view](https://github.com/moby/go-archive/compare/v0.3.2...v0.3.3)
  
Updates `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` from 0.69.0 to 0.70.0
Release notes

*Sourced from [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp's releases](https://github.com/open-telemetry/opentelemetry-go-contrib/releases).*

> Release v1.45.0/v2.5.2/v0.70.0/v0.37.2/v0.25.0/v0.20.0/v0.16.2/v0.17.0
> ----------------------------------------------------------------------
>
> Overview
> --------
>
> ### Added
>
> * Add `go.opentelemetry.io/contrib/detectors/ibmcloud/vpc`, a new resource detector for IBM Cloud VPC virtual server instances, ported from `github.com/open-telemetry/opentelemetry-collector-contrib/processor/resourcedetectionprocessor/internal/ibmcloud/vpc`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `cloud.availability_zone`, `cloud.account.id`, `cloud.resource_id`, `host.id`, `host.image.id`, `host.image.name`, `host.name`, and `host.type`. ([#9011](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9011))
> * Add `go.opentelemetry.io/contrib/detectors/k8sapi`, a new resource detector that queries the Kubernetes API. Detects `k8s.node.name` and `k8s.node.uid` when `K8S_NODE_NAME` is set via the downward API, and `k8s.cluster.uid` derived from the kube-system namespace UID (works on any Kubernetes distribution). ([#9108](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9108))
> * Add new `elasticbeanstalk` resource detector for AWS Elastic Beanstalk, ported from `processor/resourcedetectionprocessor/internal/aws/elasticbeanstalk` in opentelemetry-collector-contrib. ([#8993](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8993))
> * The resource created by `go.opentelemetry.io/contrib/otelconf` now includes [default SDK attributes](https://pkg.go.dev/go.opentelemetry.io/otel/sdk/resource#Default). ([#8990](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8990))
> * Add support for the `aws.ecs` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#8915](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8915))
> * Add support for the `aws.eks` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9138](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9138))
> * Add support for the `azure.vm` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9074](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9074))
> * Add support for the `gcp` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9137](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9137))
> * Add `go.opentelemetry.io/contrib/detectors/azure/azureappservice`, a new resource detector for Azure App Service. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `azure.app_service.instance.id`, and `deployment.environment.name` from the `WEBSITE_*` and `REGION_NAME` environment variables. ([#9289](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9289))
> * Add `azurecontainerapps` resource detector for Azure Container Apps. ([#8939](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8939))
> * Add `go.opentelemetry.io/contrib/detectors/azure/azurefunctions`, a new resource detector for Azure Functions. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `faas.instance`, and `deployment.environment.name` from the `FUNCTIONS_*`, `WEBSITE_*`, `CONTAINER_NAME`, and `REGION_NAME` environment variables. ([#9290](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9290))
> * Add `NewResourceDetector` along with the `WithAttributeFilter` and `WithTagKeyFilter` options in `go.opentelemetry.io/contrib/detectors/azure/azurevm`. `WithAttributeFilter` restricts the returned resource to the attributes the filter accepts. `WithTagKeyFilter` opts in to `azure.tag.<name>` attributes for the VM tags whose keys satisfy the provided predicate; no VM tags are emitted without it. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162))
> * Add `go.opentelemetry.io/contrib/detectors/vultr` — a new resource detector for Vultr Cloud Compute instances, ported from `processor/resourcedetectionprocessor/internal/vultr` in `opentelemetry-collector-contrib`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `host.id`, and `host.name`. ([#8995](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8995))
>
> ### Changed
>
> * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.43.0`, including updates across instrumentation and detector modules.
>   See [semantic-conventions v1.43.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.43.0) for complete details. ([#9337](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9337))
> * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.42.0`, including updates across instrumentation and detector modules.
>   See [semantic-conventions v1.42.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.42.0) for complete details. ([#9196](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9196))
> * Use direct normalized-key lookups in `Carrier.Get` and `Carrier.Keys` in `go.opentelemetry.io/contrib/propagators/envcar`. ([#9112](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9112))
> * Update log bridge conversions to use attribute key-values instead of the removed log key-values in `go.opentelemetry.io/contrib/bridges/otellogr`, `go.opentelemetry.io/contrib/bridges/otellogrus`, `go.opentelemetry.io/contrib/bridges/otelslog`, and `go.opentelemetry.io/contrib/bridges/otelzap`. ([#9180](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9180))
> * The `Version()` function in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux` has been replaced by `const Version`. ([#9076](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9076))
> * Set `error.type` attribute instead of adding `exception` span events in `go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin`. ([#8977](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8977))
> * Prefer the gRPC dial target over the resolved peer IP for the `server.address` and `server.port` attributes in `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc`. ([#8904](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8904))
> * The detector in `go.opentelemetry.io/contrib/detectors/azure/azurevm` now also detects `cloud.account.id`, `cloud.availability_zone`, `azure.vm.name`, `azure.vm.size`, `azure.vm.scaleset.name`, and `azure.resource_group.name`, and prefers `osProfile.computerName` for `host.name` (falling back to the VM name), reconciling it with the collector-contrib Azure resource detector. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162))
>
> ### Fixed
>
> * Fix Prometheus reader resource label filter configuration in `go.opentelemetry.io/contrib/otelconf/v0.2.0`. ([#9062](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9062))
> * Apply `resource.detection/development.attributes.included` and `excluded` filtering to resource detector attributes in `go.opentelemetry.io/contrib/otelconf/x`. ([#9131](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9131))
> * Honor the context configured with `WithContext` when constructing resources in `go.opentelemetry.io/contrib/otelconf` and `go.opentelemetry.io/contrib/otelconf/x`. ([#9160](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9160))
> * Handle nil response bodies from custom `RoundTripper` implementations in `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` without panicking. ([#9184](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9184))
> * Fix incorrect (overestimated) sum calculation for runtime histograms in `go.opentelemetry.io/contrib/instrumentation/runtime`. ([#9063](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9063))
> * Fix `Severity.UnmarshalText` round trip for positive `FATAL` offsets above the named range in `go.opentelemetry.io/contrib/processors/minsev`. ([#9197](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9197))
> * Reduce binary size by fetching ConfigMaps via `rest.HTTPClientFor` instead of the Kubernetes clientset in `go.opentelemetry.io/contrib/detectors/aws/eks`. ([#9284](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9284))
> * `TextMapPropagator` in `go.opentelemetry.io/contrib/propagators/autoprop` returns the no-op propagator for empty input, matching the behavior of `none`. An unknown `OTEL_PROPAGATORS` value still returns an error with a nil propagator so `NewTextMapPropagator` falls back to the default TraceContext and Baggage propagators instead of disabling propagation. ([#9163](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9163))
> * Preserve error-valued attributes nested in a group as grouped attributes instead of silently dropping them in `go.opentelemetry.io/contrib/bridges/otelslog`. ([#9238](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9238))
> * Fix a data race in `go.opentelemetry.io/contrib/bridges/otelslog` where concurrent `Handle` calls could corrupt each other's log attributes because `kvBuffer.KeyValues` returned a slice aliasing a shared buffer. ([#9229](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9229))
> * Avoid a panic in `go.opentelemetry.io/contrib/bridges/otelzap` when a malformed error field contains a nil or non-error value. ([#9068](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9068))
> * Use `azure.container_app.instance.id` instead of `service.instance.id` for the replica name detected by `go.opentelemetry.io/contrib/detectors/azure/azurecontainerapps`. ([#9208](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9208))
> * Preserve the underlying metadata errors returned with partial resources from `go.opentelemetry.io/contrib/detectors/gcp`. ([#9069](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9069))
> * Copy `MultipartForm` back to the request `otelmux.Middleware` was given after the wrapped handler returns, so `net/http` can find and remove the temp files `ParseMultipartForm` created on the context-derived request copy, when `otelmux.Middleware` wraps a handler directly, in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux`. This does not cover a handler panic, nor the common `router.Use(...)` integration, where `gorilla/mux`'s own routing step makes an additional request copy the middleware cannot write back through; see [gorilla/mux#777](https://redirect.github.com/gorilla/mux/pull/777). ([#9361](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9361))
> * Report the `b3` header from `Fields()` for the default `B3Unspecified` single-header injection encoding, matching what `Inject` writes, in `go.opentelemetry.io/contrib/propagators/b3`. ([#9273](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9273))
> * Fix `go.opentelemetry.io/contrib/propagators/aws/xray` producing deterministic trace and span IDs when the seed read from `crypto/rand` silently failed, by switching to `math/rand/v2`'s concurrency-safe top-level generator. ([#9359](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9359))

... (truncated)


Changelog

*Sourced from [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp's changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md).*

> [1.45.0/2.5.2/0.70.0/0.37.2/0.25.0/0.20.0/0.16.2/0.17.0] - 2026-08-03
> ---------------------------------------------------------------------
>
> ### Added
>
> * Add `go.opentelemetry.io/contrib/detectors/ibmcloud/vpc`, a new resource detector for IBM Cloud VPC virtual server instances, ported from `github.com/open-telemetry/opentelemetry-collector-contrib/processor/resourcedetectionprocessor/internal/ibmcloud/vpc`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `cloud.availability_zone`, `cloud.account.id`, `cloud.resource_id`, `host.id`, `host.image.id`, `host.image.name`, `host.name`, and `host.type`. ([#9011](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9011))
> * Add `go.opentelemetry.io/contrib/detectors/k8sapi`, a new resource detector that queries the Kubernetes API. Detects `k8s.node.name` and `k8s.node.uid` when `K8S_NODE_NAME` is set via the downward API, and `k8s.cluster.uid` derived from the kube-system namespace UID (works on any Kubernetes distribution). ([#9108](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9108))
> * Add new `elasticbeanstalk` resource detector for AWS Elastic Beanstalk, ported from `processor/resourcedetectionprocessor/internal/aws/elasticbeanstalk` in opentelemetry-collector-contrib. ([#8993](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8993))
> * The resource created by `go.opentelemetry.io/contrib/otelconf` now includes [default SDK attributes](https://pkg.go.dev/go.opentelemetry.io/otel/sdk/resource#Default). ([#8990](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8990))
> * Add support for the `aws.ecs` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#8915](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8915))
> * Add support for the `aws.eks` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9138](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9138))
> * Add support for the `azure.vm` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9074](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9074))
> * Add support for the `gcp` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9137](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9137))
> * Add `go.opentelemetry.io/contrib/detectors/azure/azureappservice`, a new resource detector for Azure App Service. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `azure.app_service.instance.id`, and `deployment.environment.name` from the `WEBSITE_*` and `REGION_NAME` environment variables. ([#9289](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9289))
> * Add `azurecontainerapps` resource detector for Azure Container Apps. ([#8939](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8939))
> * Add `go.opentelemetry.io/contrib/detectors/azure/azurefunctions`, a new resource detector for Azure Functions. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `faas.instance`, and `deployment.environment.name` from the `FUNCTIONS_*`, `WEBSITE_*`, `CONTAINER_NAME`, and `REGION_NAME` environment variables. ([#9290](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9290))
> * Add `NewResourceDetector` along with the `WithAttributeFilter` and `WithTagKeyFilter` options in `go.opentelemetry.io/contrib/detectors/azure/azurevm`. `WithAttributeFilter` restricts the returned resource to the attributes the filter accepts. `WithTagKeyFilter` opts in to `azure.tag.<name>` attributes for the VM tags whose keys satisfy the provided predicate; no VM tags are emitted without it. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162))
> * Add `go.opentelemetry.io/contrib/detectors/vultr` — a new resource detector for Vultr Cloud Compute instances, ported from `processor/resourcedetectionprocessor/internal/vultr` in `opentelemetry-collector-contrib`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `host.id`, and `host.name`. ([#8995](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8995))
>
> ### Changed
>
> * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.43.0`, including updates across instrumentation and detector modules.
>   See [semantic-conventions v1.43.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.43.0) for complete details. ([#9337](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9337))
> * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.42.0`, including updates across instrumentation and detector modules.
>   See [semantic-conventions v1.42.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.42.0) for complete details. ([#9196](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9196))
> * Use direct normalized-key lookups in `Carrier.Get` and `Carrier.Keys` in `go.opentelemetry.io/contrib/propagators/envcar`. ([#9112](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9112))
> * Update log bridge conversions to use attribute key-values instead of the removed log key-values in `go.opentelemetry.io/contrib/bridges/otellogr`, `go.opentelemetry.io/contrib/bridges/otellogrus`, `go.opentelemetry.io/contrib/bridges/otelslog`, and `go.opentelemetry.io/contrib/bridges/otelzap`. ([#9180](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9180))
> * The `Version()` function in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux` has been replaced by `const Version`. ([#9076](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9076))
> * Set `error.type` attribute instead of adding `exception` span events in `go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin`. ([#8977](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8977))
> * Prefer the gRPC dial target over the resolved peer IP for the `server.address` and `server.port` attributes in `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc`. ([#8904](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8904))
> * The detector in `go.opentelemetry.io/contrib/detectors/azure/azurevm` now also detects `cloud.account.id`, `cloud.availability_zone`, `azure.vm.name`, `azure.vm.size`, `azure.vm.scaleset.name`, and `azure.resource_group.name`, and prefers `osProfile.computerName` for `host.name` (falling back to the VM name), reconciling it with the collector-contrib Azure resource detector. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162))
>
> ### Fixed
>
> * Fix Prometheus reader resource label filter configuration in `go.opentelemetry.io/contrib/otelconf/v0.2.0`. ([#9062](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9062))
> * Apply `resource.detection/development.attributes.included` and `excluded` filtering to resource detector attributes in `go.opentelemetry.io/contrib/otelconf/x`. ([#9131](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9131))
> * Honor the context configured with `WithContext` when constructing resources in `go.opentelemetry.io/contrib/otelconf` and `go.opentelemetry.io/contrib/otelconf/x`. ([#9160](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9160))
> * Handle nil response bodies from custom `RoundTripper` implementations in `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` without panicking. ([#9184](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9184))
> * Fix incorrect (overestimated) sum calculation for runtime histograms in `go.opentelemetry.io/contrib/instrumentation/runtime`. ([#9063](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9063))
> * Fix `Severity.UnmarshalText` round trip for positive `FATAL` offsets above the named range in `go.opentelemetry.io/contrib/processors/minsev`. ([#9197](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9197))
> * Reduce binary size by fetching ConfigMaps via `rest.HTTPClientFor` instead of the Kubernetes clientset in `go.opentelemetry.io/contrib/detectors/aws/eks`. ([#9284](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9284))
> * `TextMapPropagator` in `go.opentelemetry.io/contrib/propagators/autoprop` returns the no-op propagator for empty input, matching the behavior of `none`. An unknown `OTEL_PROPAGATORS` value still returns an error with a nil propagator so `NewTextMapPropagator` falls back to the default TraceContext and Baggage propagators instead of disabling propagation. ([#9163](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9163))
> * Preserve error-valued attributes nested in a group as grouped attributes instead of silently dropping them in `go.opentelemetry.io/contrib/bridges/otelslog`. ([#9238](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9238))
> * Fix a data race in `go.opentelemetry.io/contrib/bridges/otelslog` where concurrent `Handle` calls could corrupt each other's log attributes because `kvBuffer.KeyValues` returned a slice aliasing a shared buffer. ([#9229](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9229))
> * Avoid a panic in `go.opentelemetry.io/contrib/bridges/otelzap` when a malformed error field contains a nil or non-error value. ([#9068](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9068))
> * Use `azure.container_app.instance.id` instead of `service.instance.id` for the replica name detected by `go.opentelemetry.io/contrib/detectors/azure/azurecontainerapps`. ([#9208](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9208))
> * Preserve the underlying metadata errors returned with partial resources from `go.opentelemetry.io/contrib/detectors/gcp`. ([#9069](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9069))
> * Copy `MultipartForm` back to the request `otelmux.Middleware` was given after the wrapped handler returns, so `net/http` can find and remove the temp files `ParseMultipartForm` created on the context-derived request copy, when `otelmux.Middleware` wraps a handler directly, in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux`. This does not cover a handler panic, nor the common `router.Use(...)` integration, where `gorilla/mux`'s own routing step makes an additional request copy the middleware cannot write back through; see [gorilla/mux#777](https://redirect.github.com/gorilla/mux/pull/777). ([#9361](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9361))
> * Report the `b3` header from `Fields()` for the default `B3Unspecified` single-header injection encoding, matching what `Inject` writes, in `go.opentelemetry.io/contrib/propagators/b3`. ([#9273](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9273))
> * Fix `go.opentelemetry.io/contrib/propagators/aws/xray` producing deterministic trace and span IDs when the seed read from `crypto/rand` silently failed, by switching to `math/rand/v2`'s concurrency-safe top-level generator. ([#9359](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9359))
> * Strip connection number suffix from connection ID in `go.opentelemetry.io/contrib/instrumentation/go.mongodb.org/mongo-driver/v2/mongo/otelmongo` to prevent unbounded metric cardinality. ([#9352](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9352))

... (truncated)


Commits

* [`c8a87a6`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/c8a87a60ba1b3374fd16df11fc3eeae6c41abbc9) Release v1.45.0/v2.5.2/v0.70.0/v0.37.2/v0.25.0/v0.20.0/v0.16.2/v0.17.0 ([#9413](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9413))
* [`cde125c`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/cde125c563f232eb6b423a208d375f8e53ae2557) fix(deps): update aws-sdk-go-v2 monorepo ([#9384](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9384))
* [`88572a7`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/88572a7662d00e805777ed96932d532316c13787) chore(deps): update googleapis to 6ac0973 ([#9409](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9409))
* [`e4f511a`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/e4f511a0f3cc2b09b87cb164427b49dfd2e14f7d) chore(deps): update github/codeql-action action to v4.37.5 ([#9410](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9410))
* [`265eb0b`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/265eb0b5fe0682801fd8177aec74ce8769c5a0a4) fix(deps): update go.opentelemetry.io/otel digest to 48db2c6 ([#9317](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9317))
* [`941ba46`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/941ba46979c59dca89d26040ed919870283e36e9) chore(deps): update github.com/charmbracelet/ultraviolet digest to 8b69304 (#...
* [`ededd3b`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/ededd3b571ad562351a0afe09682774a6f48d63e) chore(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 ([#9406](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9406))
* [`7c6e819`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/7c6e819d4eb26eede10e98c424adb76304025fda) fix(deps): update module github.com/atombender/go-jsonschema to v0.24.1 ([#9405](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9405))
* [`ec1e544`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/ec1e544a0d6883126198c3fc3a7d62fc8db29195) chore(deps): update github.com/lufia/plan9stats digest to 341c2f0 ([#9403](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9403))
* [`5d7e16a`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/5d7e16aa1138a5446a648dd92ebc42031c93e327) chore(deps): update github.com/golangci/rowserrcheck digest to d2031e3 ([#9402](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9402))
* Additional commits viewable in [compare view](https://github.com/open-telemetry/opentelemetry-go-contrib/compare/zpages/v0.69.0...zpages/v0.70.0)
  
Updates `go.opentelemetry.io/otel` from 1.44.0 to 1.45.0
Changelog

*Sourced from [go.opentelemetry.io/otel's changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md).*

> [1.45.0/0.67.0/0.21.0/0.0.18] - 2026-08-03
> ------------------------------------------
>
> ### Added
>
> * Add experimental observability metrics to `BatchProcessor` in `go.opentelemetry.io/otel/sdk/log`. ([#7124](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/7124))
> * Add the experimental `WithUnsafeAttributes` no-copy attribute option to `go.opentelemetry.io/otel/metric/x` for future performance improvements. This API is a work in progress. ([#8251](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8251))
> * Add `Map` and `MapValue` functions for the new `MAP` attribute type in `go.opentelemetry.io/otel/attribute`. ([#8445](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8445))
> * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlptrace`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453))
> * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlplog`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453))
> * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453))
> * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/zipkin`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453))
> * Apply `AttributeValueLengthLimit` recursively to values contained in `attribute.MAP` attributes in `go.opentelemetry.io/otel/sdk/trace`. ([#8454](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8454))
> * Remove duplicate keys from `attribute.MAP` values in `go.opentelemetry.io/otel/sdk/resource` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471))
> * Remove duplicate keys by default from `attribute.MAP` values in instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/log` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471))
> * Remove duplicate keys by default from `attribute.MAP` values in span, event, link, and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/trace` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471))
> * Remove duplicate keys by default from `attribute.MAP` values in measurement and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/metric` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471))
> * Extend `WithAllowKeyDuplication` in `go.opentelemetry.io/otel/sdk/log` to disable duplicate-key removal in `attribute.MAP` values for instrumentation scope attributes. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471))
> * Add the `go.opentelemetry.io/otel/semconv/v1.42.0` package.
>   The package contains semantic conventions from the `v1.42.0` version of the OpenTelemetry Semantic Conventions.
>   See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.42.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.41.0`. ([#8484](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8484))
> * Add `WithoutPanicRecording` as a `TracerProviderOption` in `go.opentelemetry.io/otel/sdk/trace` to disable exception event recording for panics. ([#8532](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8532))
> * Add the `go.opentelemetry.io/otel/semconv/v1.43.0` package.
>   The package contains semantic conventions from the `v1.43.0` version of the OpenTelemetry Semantic Conventions.
>   See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.43.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.42.0`. ([#8628](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8628))
>
> ### Changed
>
> * `HistogramReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` now uses a time-unbiased sampling algorithm for exemplars. ([#8306](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8306))
> * ⚠️ **Breaking Change:** Use `go.opentelemetry.io/otel/attribute.Value` and `go.opentelemetry.io/otel/attribute.KeyValue` for log bodies and attributes in `go.opentelemetry.io/otel/log`, `go.opentelemetry.io/otel/log/logtest`, `go.opentelemetry.io/otel/sdk/log`, and `go.opentelemetry.io/otel/sdk/log/logtest`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490))
> * Encode log bodies and attributes as `go.opentelemetry.io/otel/attribute.Value` JSON in `go.opentelemetry.io/otel/exporters/stdout/stdoutlog`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490))
> * Improve the performance of hashing `BOOLSLICE`, `INT64SLICE`, `FLOAT64SLICE`, and `STRINGSLICE` attribute values by avoiding reflection for short slices in `go.opentelemetry.io/otel/attribute`. ([#8511](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8511))
> * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_METRICS_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538))
> * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_TRACES_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538))
>
> ### Deprecated
>
> * Deprecate `WithExportBufferSize` in `go.opentelemetry.io/otel/sdk/log`. The option remains available for source compatibility but no longer affects behavior; `BatchProcessor` no longer maintains a separate export-request buffer. ([#8620](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8620))
>
> ### Removed
>
> * ⚠️ **Breaking Change:** Remove `Kind`, `Value`, `KeyValue`, their constructors, and attribute conversion helpers from `go.opentelemetry.io/otel/log`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490))
> * ⚠️ **Breaking Change:** Remove the `AttributeValueLengthLimit` and `AttributeCountLimit` fields from `RecordFactory` in `go.opentelemetry.io/otel/sdk/log/logtest`; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. ([#8556](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8556))
>
> ### Fixed
>
> * Apply TLS certificates configured through environment variables to gRPC connections in `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc`.
> * Prevent panics in `go.opentelemetry.io/otel/bridge/opentracing` when OpenTracing baggage is propagated concurrently with `Span.SetBaggageItem`.
> * Fix an off-by-one error in `FixedSizeReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` that prevented the first exemplar from being sampled after the reservoir was filled. ([#8309](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8309))
> * Interpret HTTP `Retry-After` header values as seconds instead of nanoseconds when retrying OTLP HTTP exports in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp`, `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp`, and `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp`. ([#8383](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8383))
> * Fix a memory leak in the `Reservoir` implementation in `go.opentelemetry.io/otel/sdk/metric/exemplar`, where storing the full `context.Context` pinned large objects such as gRPC transport buffers. ([#8389](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8389))

... (truncated)


Commits

* [`93a693e`](https://github.com/open-telemetry/opentelemetry-go/commit/93a693edeed0e07ce5ebd1dfe67af42d1e2055d8) Release v1.45.0 ([#8693](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8693))
* [`c65d435`](https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c) Merge commit from fork
* [`223f9fd`](https://github.com/open-telemetry/opentelemetry-go/commit/223f9fdce4e4a85d6ee2155c6a140f236db72c8b) sdk/metric: remove obsolete randomFloat64 TODO ([#8685](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8685))
* [`06272bc`](https://github.com/open-telemetry/opentelemetry-go/commit/06272bc491566efb2c581c8a52e4986cfcccec5b) fix(deps): update googleapis to 6ac0973 ([#8694](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8694))
* [`a4f238f`](https://github.com/open-telemetry/opentelemetry-go/commit/a4f238f57646197d124edcf67baf4cd6ea6d0a9f) chore(deps): update github.com/charmbracelet/ultraviolet digest to 8b69304 (#...
* [`37140e7`](https://github.com/open-telemetry/opentelemetry-go/commit/37140e78821d3cb29a33d4b601ca4645b80ceebd) chore(deps): update codspeedhq/action action to v5.0.2 ([#8690](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8690))
* [`cef0855`](https://github.com/open-telemetry/opentelemetry-go/commit/cef0855960bce4385c7d58c40e846573c190d826) chore(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 ([#8689](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8689))
* [`e814a72`](https://github.com/open-telemetry/opentelemetry-go/commit/e814a7281f2d52a6440c3269e139145e62801a16) Merge commit from fork
* [`bfd8eb7`](https://github.com/open-telemetry/opentelemetry-go/commit/bfd8eb7f85d3364fdde9ad1a408df98be30acadb) chore(deps): update github.com/golangci/rowserrcheck digest to d2031e3 ([#8687](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8687))
* [`48db2c6`](https://github.com/open-telemetry/opentelemetry-go/commit/48db2c659c3b138f971273cd91ea0bcb647768e1) chore(deps): update github/codeql-action action to v4.37.5 ([#8692](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8692))
* Additional commits viewable in [compare view](https://github.com/open-telemetry/opentelemetry-go/compare/v1.44.0...v1.45.0)
  
Updates `go.opentelemetry.io/otel/metric` from 1.44.0 to 1.45.0
Changelog

*Sourced from [go.opentelemetry.io/otel/metric's changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md).*

> [1.45.0/0.67.0/0.21.0/0.0.18] - 2026-08-03
> ------------------------------------------
>
> ### Added
>
> * Add experimental observability metrics to `BatchProcessor` in `go.opentelemetry.io/otel/sdk/log`. ([#7124](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/7124))
> * Add the experimental `WithUnsafeAttributes` no-copy attribute option to `go.opentelemetry.io/otel/metric/x` for future performance improvements. This API is a work in progress. ([#8251](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8251))
> * Add `Map` and `MapValue` functions for the new `MAP` attribute type in `go.opentelemetry.io/otel/attribute`. ([#8445](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8445))
> * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlptrace`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453))
> * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlplog`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453))
> * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453))
> * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/zipkin`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453))
> * Apply `AttributeValueLengthLimit` recursively to values contained in `attribute.MAP` attributes in `go.opentelemetry.io/otel/sdk/trace`. ([#8454](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8454))
> * Remove duplicate keys from `attribute.MAP` values in `go.opentelemetry.io/otel/sdk/resource` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471))
> * Remove duplicate keys by default from `attribute.MAP` values in instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/log` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471))
> * Remove duplicate keys by default from `attribute.MAP` values in span, event, link, and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/trace` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471))
> * Remove duplicate keys by default from `attribute.MAP` values in measurement and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/metric` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471))
> * Extend `WithAllowKeyDuplication` in `go.opentelemetry.io/otel/sdk/log` to disable duplicate-key removal in `attribute.MAP` values for instrumentation scope attributes. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471))
> * Add the `go.opentelemetry.io/otel/semconv/v1.42.0` package.
>   The package contains semantic conventions from the `v1.42.0` version of the OpenTelemetry Semantic Conventions.
>   See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.42.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.41.0`. ([#8484](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8484))
> * Add `WithoutPanicRecording` as a `TracerProviderOption` in `go.opentelemetry.io/otel/sdk/trace` to disable exception event recording for panics. ([#8532](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8532))
> * Add the `go.opentelemetry.io/otel/semconv/v1.43.0` package.
>   The package contains semantic conventions from the `v1.43.0` version of the OpenTelemetry Semantic Conventions.
>   See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.43.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.42.0`. ([#8628](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8628))
>
> ### Changed
>
> * `HistogramReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` now uses a time-unbiased sampling algorithm for exemplars. ([#8306](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8306))
> * ⚠️ **Breaking Change:** Use `go.opentelemetry.io/otel/attribute.Value` and `go.opentelemetry.io/otel/attribute.KeyValue` for log bodies and attributes in `go.opentelemetry.io/otel/log`, `go.opentelemetry.io/otel/log/logtest`, `go.opentelemetry.io/otel/sdk/log`, and `go.opentelemetry.io/otel/sdk/log/logtest`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490))
> * Encode log bodies and attributes as `go.opentelemetry.io/otel/attribute.Value` JSON in `go.opentelemetry.io/otel/exporters/stdout/stdoutlog`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490))
> * Improve the performance of hashing `BOOLSLICE`, `INT64SLICE`, `FLOAT64SLICE`, and `STRINGSLICE` attribute values by avoiding reflection for short slices in `go.opentelemetry.io/otel/attribute`. ([#8511](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8511))
> * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_METRICS_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538))
> * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_TRACES_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538))
>
> ### Deprecated
>
> * Deprecate `WithExportBufferSize` in `go.opentelemetry.io/otel/sdk/log`. The option remains available for source compatibility but no longer affects behavior; `BatchProcessor` no longer maintains a separate export-request buffer. ([#8620](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8620))
>
> ### Removed
>
> * ⚠️ **Breaking Change:** Remove `Kind`, `Value`, `KeyValue`, their constructors, and attribute conversion helpers from `go.opentelemetry.io/otel/log`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490))
> * ⚠️ **Breaking Change:** Remove the `AttributeValueLengthLimit` and `AttributeCountLimit` fields from `RecordFactory` in `go.opentelemetry.io/otel/sdk/log/logtest`; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. ([#8556](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8556))
>
> ### Fixed
>
> * Apply TLS certificates configured through environment variables to gRPC connections in `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc`.
> * Prevent panics in `go.opentelemetry.io/otel/bridge/opentracing` when OpenTracing baggage is propagated concurrently with `Span.SetBaggageItem`.
> * Fix an off-by-one error in `FixedSizeReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` that prevented the first exemplar from being sampled after the reservoir was filled. ([#8309](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8309))
> * Interpret HTTP `Retry-After` header values as seconds instead of nanoseconds when retrying OTLP HTTP exports in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp`, `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp`, and `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp`. ([#8383](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8383))
> * Fix a memory leak in the `Reservo...
>   _Description has been truncated_`
@lizthegrey
lizthegrey deleted the lizf.arm64-sp-frame branch August 31, 2026 12:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants