Skip to content

feat(data-pipeline)!: Obfuscate v04 spans in agentless context - #2418

Merged
gh-worker-dd-mergequeue-cf854d[bot] merged 17 commits into
mainfrom
paullgdc/obfuscation/v04_span
Aug 31, 2026
Merged

gh-worker-dd-mergequeue-cf854d[bot] merged 17 commits into
mainfrom
paullgdc/obfuscation/v04_span

Conversation

@paullegranddc

@paullegranddc paullegranddc commented Aug 25, 2026 •

Copy link
Copy Markdown
Collaborator

What does this PR do?

  • Add a function to obfuscate v04 span
  • Hook the obfuscation configuration in the trace exporter
  • Force obfuscation if agentless is enabled
  • Use the agent default values for the span obfuscation configuration

@github-actions

github-actions Bot commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

Clippy Allow Annotation Report

Tracked Clippy allow annotations changed vs main: ⚠️ +1 (4 → 5)

Rule Base PR Δ
unwrap_used 4 5 ⚠️ +1
By file and crate

By file

File Base PR Δ
libdd-trace-obfuscation/src/replacer.rs 1 2 ⚠️ +1

By crate

Crate Base PR Δ
libdd-trace-obfuscation 3 4 ⚠️ +1

About This Report

This report tracks Clippy allow annotations for specific rules, showing how they've changed in this PR. Decreasing the number of these annotations generally improves code quality. Panic-inducing macros in particular should be avoided. In the future, this report may become a PR-blocking quality gate.

@datadog-datadog-prod-us1-2

datadog-datadog-prod-us1-2 Bot commented Aug 25, 2026 •

Copy link
Copy Markdown

Tests

✅ All CI checks and tests passed.

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
• Patch Coverage: 83.55%
• Overall Coverage: 76.77% (+0.10%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 79b13e5 | Docs | View more details | Give us feedback!

@paullegranddc
paullegranddc marked this pull request as ready for review August 25, 2026 23:47
@paullegranddc
paullegranddc requested review from a team as code owners August 25, 2026 23:47

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 637c473170

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread libdd-data-pipeline/src/trace_exporter/mod.rs Outdated
@pr-commenter

pr-commenter Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Benchmarks

Comparison

Benchmark execution time: 2026-08-31 13:14:41

Comparing candidate commit 79b13e5 in PR branch paullgdc/obfuscation/v04_span with baseline commit 9fb27ea in branch main.

Found 15 performance improvements and 10 performance regressions! Performance is the same for 143 metrics, 10 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

scenario:alloc_free/system/256

  • 🟩 execution_time [-1.105ns; -1.044ns] or [-7.182%; -6.788%]

scenario:alloc_free/system/4096

  • 🟥 execution_time [+13.845ns; +14.056ns] or [+15.117%; +15.347%]

scenario:credit_card/is_card_number/ 378282246310005

  • 🟩 execution_time [-5.106µs; -4.948µs] or [-6.950%; -6.735%]
  • 🟩 throughput [+984435.886op/s; +1013645.537op/s] or [+7.232%; +7.446%]

scenario:credit_card/is_card_number/378282246310005

  • 🟩 execution_time [-5.045µs; -4.928µs] or [-7.204%; -7.038%]
  • 🟩 throughput [+1082450.826op/s; +1106261.144op/s] or [+7.580%; +7.747%]

scenario:credit_card/is_card_number/37828224631000521389798

  • 🟩 execution_time [-6.593µs; -6.561µs] or [-12.595%; -12.535%]
  • 🟩 throughput [+2738246.124op/s; +2752559.922op/s] or [+14.334%; +14.408%]

scenario:credit_card/is_card_number/x371413321323331

  • 🟥 execution_time [+802.561ns; +805.525ns] or [+13.263%; +13.312%]
  • 🟥 throughput [-19419286.285op/s; -19348231.815op/s] or [-11.751%; -11.708%]

scenario:credit_card/is_card_number_no_luhn/ 378282246310005

  • 🟩 execution_time [-5.238µs; -5.192µs] or [-8.912%; -8.834%]
  • 🟩 throughput [+1649670.332op/s; +1663304.491op/s] or [+9.696%; +9.776%]

scenario:credit_card/is_card_number_no_luhn/378282246310005

  • 🟩 execution_time [-5.170µs; -5.127µs] or [-9.317%; -9.240%]
  • 🟩 throughput [+1835796.333op/s; +1850117.437op/s] or [+10.187%; +10.266%]

scenario:credit_card/is_card_number_no_luhn/37828224631000521389798

  • 🟩 execution_time [-6.615µs; -6.585µs] or [-12.637%; -12.578%]
  • 🟩 throughput [+2749001.119op/s; +2762996.995op/s] or [+14.390%; +14.464%]

scenario:credit_card/is_card_number_no_luhn/x371413321323331

  • 🟥 execution_time [+802.325ns; +805.004ns] or [+13.262%; +13.306%]
  • 🟥 throughput [-19414989.049op/s; -19349507.575op/s] or [-11.746%; -11.706%]

scenario:datadog_sample_span/tag_rule_matching/wall_time

  • 🟥 execution_time [+15.057ns; +15.271ns] or [+4.623%; +4.689%]

scenario:profiler_attached/fast_path_system/4096

  • 🟩 execution_time [-9.148ns; -8.968ns] or [-8.725%; -8.553%]

scenario:profiler_attached/slow_path_system/4096

  • 🟥 execution_time [+8.429ns; +8.550ns] or [+5.753%; +5.835%]

scenario:redis/obfuscate_redis_string

  • 🟩 execution_time [-2.972µs; -2.491µs] or [-8.843%; -7.414%]

scenario:tags/replace_trace_tags

  • 🟥 execution_time [+193.100ns; +200.978ns] or [+8.009%; +8.335%]

scenario:trace_buffer/2_senders/no_delay

  • 🟥 execution_time [+80.180µs; +94.949µs] or [+5.545%; +6.567%]
  • 🟥 throughput [-77122.405op/s; -65119.692op/s] or [-6.191%; -5.228%]

Candidate

Omitted due to size.

Baseline

Omitted due to size.

@paullegranddc
paullegranddc requested review from a team as code owners August 26, 2026 14:33
@paullegranddc

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ad70e61397

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread libdd-data-pipeline/Cargo.toml Outdated
Comment thread libdd-data-pipeline-ffi/src/trace_exporter.rs
Comment thread libdd-trace-obfuscation/src/obfuscate.rs

@ichinaski ichinaski left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's somewhat unclear how much on parity this approach is with the Trace Agent obfuscation config. We should document this somewhere, and also test the schemas are the same.

I also don't fully understand why we want to keep 2 separate implementations here, one for protobuf, the other for raw spans (using JSON endpoint). These 2 paths look also inconsistent at first glance (pb implementation being more complex and more tested).

Comment thread libdd-data-pipeline-ffi/src/trace_exporter.rs
Comment thread libdd-data-pipeline/src/trace_exporter/mod.rs Outdated
Comment thread libdd-data-pipeline/Cargo.toml Outdated
Comment thread libdd-trace-obfuscation/src/obfuscation_config.rs
@paullegranddc

Copy link
Copy Markdown
Collaborator Author

I also don't fully understand why we want to keep 2 separate implementations here, one for protobuf, the other for raw spans (using JSON endpoint). These 2 paths look also inconsistent at first glance (pb implementation being more complex and more tested).

The protobuf span struct is obsolete and used only by serverless for their extension. I cannot remove the obfuscate method though as I don't want to break their extension completely.

If we ever want to send protobuf spans to the intake APM clients using libdatadog, we will do it by adding a protobuf serializer to the v1 span struct.
The paths are from what I can tell consistent and I have added tests that run the same cases against both functions.

@bwoebi bwoebi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not too happy that it double obfuscates common operations, which have already been obfuscated once for stats computation.
But that's a future optimization, not a blocker. The implementation looks right to me: trivially obfuscating every span, and avoiding reallocating/copying for stuff which clearly doesn't need to be obfuscated.

Comment thread libdd-trace-obfuscation/src/obfuscate.rs

@ekump ekump left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A few things that need fixing, but not blocking. Please create Jira tickets for any follow up work.

Comment thread libdd-data-pipeline-ffi/src/trace_exporter.rs
Comment thread libdd-data-pipeline-ffi/src/trace_exporter.rs
Comment thread libdd-data-pipeline-ffi/src/trace_exporter.rs
Comment thread libdd-data-pipeline-ffi/src/trace_exporter.rs
Comment thread libdd-data-pipeline-ffi/src/trace_exporter.rs
Comment thread libdd-trace-obfuscation/src/obfuscation_config.rs
Comment thread libdd-trace-obfuscation/src/sql.rs
@paullegranddc

Copy link
Copy Markdown
Collaborator Author

/merge

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-08-31 12:28:48 UTC ℹ️ Start processing command /merge


2026-08-31 12:28:56 UTC ℹ️ MergeQueue: Pull request is not mergeable yet

It will be processed automatically as soon as GitHub reports it as mergeable. View in MergeQueue UI.

  • Run /code blockers to see what is blocking it.
  • Run /remove to cancel it.

2026-08-31 14:04:17 UTC ℹ️ MergeQueue: merge request added to the queue

The expected merge time in main is approximately 49m (p90).


2026-08-31 14:43:09 UTC ℹ️ MergeQueue: This merge request was merged

@paullegranddc

Copy link
Copy Markdown
Collaborator Author

/code blockers

@gh-worker-devflow-routing-ef8351

gh-worker-devflow-routing-ef8351 Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

View all feedbacks in Devflow UI.

2026-08-31 13:54:11 UTC ℹ️ Start processing command /code blockers


2026-08-31 13:54:12 UTC ℹ️ Devflow:

Checking merge blockers for #2418...


2026-08-31 13:54:17 UTC ℹ️ Devflow: /code blockers

Detected 1 merge blocker(s) to address:

🟠 Pending

@morrisonlevi morrisonlevi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I looked only at the libdd-profiling-ffi/Cargo.toml changes, which are fine.

@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot merged commit 0265610 into main Aug 31, 2026
123 checks passed
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot deleted the paullgdc/obfuscation/v04_span branch August 31, 2026 14:43
paullegranddc added a commit that referenced this pull request Sep 8, 2026
#2472)

# Motivation
Credit-card obfuscation only checked the single `card.number` tag, but
the trace-agent scans all span meta attributes (with an explicit
skip-list)

# Changes

* Replace the single `TAG_CARD_NUMBER` fast-path in `obfuscate_pb_span`
and `obfuscate_v04_span` with a full scan of all `span.meta` entries
* Skip keys in the built-in skip-list (`should_obfuscate_cc_key`) and
the user-configured `keep_values` set

Followup for #2418
hoolioh added a commit that referenced this pull request Sep 8, 2026
…ker, libdd-data-pipeline, li... (#2482)

# Release proposal for libdd-capabilities-impl, libdd-crashtracker,
libdd-data-pipeline, libdd-ddsketch, libdd-ffe, libdd-http-client,
libdd-ipc, libdd-library-config, libdd-live-debugger,
libdd-otel-thread-ctx, libdd-remote-config, libdd-shared-runtime,
libdd-telemetry, libdd-trace-utils, libdd-tracer-flare and their
dependencies

This PR contains version bumps based on public API changes and commits
since last release.


### ⚠️ Crates left out of this proposal affected by its major
bumps

These publishable workspace crates are not part of this release but
their dependency requirement was rewritten on this branch while their
published version still requires the old major. If they are a dependency
on your deployment not including them in the release could result in
duplicate packages or symbol incompatibility.

- `libdd-common` `5.2.0` → `6.0.0` affects: `libdd-profiling`,
`libdd-sampling`
- `libdd-trace-utils` `11.0.0` → `12.0.0` affects: `libdd-sampling`

## libdd-capabilities
**Next version:** `3.0.1`
**Semver bump:** `patch`
**Tag:** `libdd-capabilities-v3.0.1`

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- feat: do not entirely disable connection pooling for periodic
connections (#2440)

## libdd-common
**Next version:** `6.0.0`
**Semver bump:** `major`
**Tag:** `libdd-common-v6.0.0`

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- feat: do not entirely disable connection pooling for periodic
connections (#2440)
- feat(data-pipeline)!: add agentless stats export (#2309)
- feat(data-pipeline): add runtime-independent agentless sending (#2389)
- feat(common)!: add HTTPS_PROXY support for hyper_backend (#2421)

## libdd-ipc-macros
**Next version:** `1.0.1`
**Semver bump:** `patch`
**Tag:** `libdd-ipc-macros-v1.0.1`

### Commits

- feat(sidecar)!: support appsec helper-rust integration with sidecar
(#2310)

## libdd-otel-thread-ctx
**Next version:** `1.1.0`
**Semver bump:** `minor`
**Tag:** `libdd-otel-thread-ctx-v1.1.0`

### Commits

- feat(otel-thread-ctx): add update-and-attach operation (#2443)

## libdd-tinybytes
**Next version:** `1.1.3`
**Semver bump:** `patch`
**Tag:** `libdd-tinybytes-v1.1.3`

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)

## libdd-capabilities-impl
**Next version:** `5.0.0`
**Semver bump:** `major`
**Tag:** `libdd-capabilities-impl-v5.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.1.1 → ^6.0.0

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- feat: do not entirely disable connection pooling for periodic
connections (#2440)
- feat(data-pipeline): add runtime-independent agentless sending (#2389)

## libdd-http-client
**Next version:** `2.0.0`
**Semver bump:** `major`
**Tag:** `libdd-http-client-v2.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.1.1 → ^6.0.0

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- feat(data-pipeline): add runtime-independent agentless sending (#2389)
- feat(common)!: add HTTPS_PROXY support for hyper_backend (#2421)

## libdd-remote-config
**Next version:** `5.0.0`
**Semver bump:** `major`
**Tag:** `libdd-remote-config-v5.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0

### Commits

- fix(remote-config): refresh fetcher identity (#2469)
- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- fix(remote-config): reuse injected sleep capability (#2429)

## libdd-shared-runtime
**Next version:** `4.0.0`
**Semver bump:** `major`
**Tag:** `libdd-shared-runtime-v4.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0

### Commits

- fix(shared-runtime): allow disabling worker fork restart (#2464)

## libdd-trace-utils
**Next version:** `12.0.0`
**Semver bump:** `major`
**Tag:** `libdd-trace-utils-v12.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0

### Commits

- feat(trace-utils): add v1-native JSON log encoder brick (#2371)
- feat(trace-utils): add v1-native agentless JSON encoder brick (#2370)
- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- fix(trace-stats): read OTel HTTP names for the status and method
dimensions (#2323)
- feat(data-pipeline): emit native trace export telemetry (#2338)
- feat(data-pipeline)!: add agentless stats export (#2309)
- fix(trace-utils): use vec map dedup when serializing (#2422)
- feat(data-pipeline): add runtime-independent agentless sending (#2389)
- fix(compression): align zstd behavior across targets (#2400)
- feat(trace-utils)!: add from owned to SpanText (#2403)

## libdd-ffe
**Next version:** `2.0.0`
**Semver bump:** `major`
**Tag:** `libdd-ffe-v2.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.1.1 → ^6.0.0
- `libdd-remote-config`: ^3.0.0 → ^4.1.0
- `libdd-trace-protobuf`: ^4.0.1 → ^5.0.0

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- feat(ffe): support arbitrary semver core parts (#2413)
- feat(ffe)!: send the split serial id on exposure events [EX-3425]
(#2402)
- feat(ffe): expose observeFullEvaluationData config-level FFI getter
(#2373)
- fix(ffe): report rejected flags as parse errors (#2339)
- test: skip/shorten slow miri jobs (#2331)

## libdd-dogstatsd-client
**Next version:** `6.0.0`
**Semver bump:** `major`
**Tag:** `libdd-dogstatsd-client-v6.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)

## libdd-telemetry
**Next version:** `8.0.0`
**Semver bump:** `major`
**Tag:** `libdd-telemetry-v8.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- refactor(telemetry): avoid doing two separate http requests in stop
telemetry (#2435)

## libdd-trace-obfuscation
**Next version:** `8.0.0`
**Semver bump:** `major`
**Tag:** `libdd-trace-obfuscation-v8.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0
- `libdd-trace-utils`: ^11.0.0 → ^12.0.0

### Commits

- fix(trace-obfuscation): scan all span meta for credit-card obfuscation
(#2472)
- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- feat(data-pipeline)!: Obfuscate v04 spans in agentless context (#2418)

## libdd-tracer-flare
**Next version:** `3.0.0`
**Semver bump:** `major`
**Tag:** `libdd-tracer-flare-v3.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0
- `libdd-trace-utils`: ^11.0.0 → ^12.0.0

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)

## libdd-crashtracker
**Next version:** `3.0.0`
**Semver bump:** `major`
**Tag:** `libdd-crashtracker-v3.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- fix(crashtracking): filter out frames above faulting frame (#2428)
- feat(sidecar)!: support appsec helper-rust integration with sidecar
(#2310)
- chore(crashtracking): use RAII remote ptrace API (#2416)
- chore(crashtracking): bump libdd-libunwind-sys to v1.0.3 (#2414)

## libdd-data-pipeline-core
**Next version:** `1.0.0`
**Semver bump:** `major`
**Tag:** `libdd-data-pipeline-core-v1.0.0`

**Warning:** this is an initial release. Please verify that the version
and commits included are correct.


## libdd-trace-stats
**Next version:** `9.0.0`
**Semver bump:** `major`
**Tag:** `libdd-trace-stats-v9.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0
- `libdd-trace-obfuscation`: ^7.0.0 → ^8.0.0
- `libdd-trace-utils`: ^11.0.0 → ^12.0.0

### Commits

- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- fix(trace-stats): read OTel HTTP names for the status and method
dimensions (#2323)
- feat(data-pipeline)!: add agentless stats export (#2309)
- feat(trace-utils)!: add from owned to SpanText (#2403)

## libdd-data-pipeline
**Next version:** `10.0.0`
**Semver bump:** `major`
**Tag:** `libdd-data-pipeline-v10.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0
- `libdd-trace-obfuscation`: ^7.0.0 → ^8.0.0
- `libdd-trace-stats`: ^8.0.0 → ^9.0.0
- `libdd-trace-utils`: ^11.0.0 → ^12.0.0

### Commits

- feat(trace-utils): add v1-native JSON log encoder brick (#2371)
- chore: prepare crate for publishing (#2466)
- refactor: migrate HTTP & networking deps to workspace level (phase
4bis) (#2350)
- fix(trace-stats): read OTel HTTP names for the status and method
dimensions (#2323)
- fix(data-pipeline): pass obfuscation config to OTLP stats (#2444)
- feat(data-pipeline): emit native trace export telemetry (#2338)
- feat(data-pipeline): add fork-safe OTLP gRPC trace transport (#2273)
- feat(data-pipeline)!: add agentless stats export (#2309)
- feat(data-pipeline)!: Obfuscate v04 spans in agentless context (#2418)
- feat(data-pipeline): add runtime-independent agentless sending (#2389)
- feat(trace-utils)!: add from owned to SpanText (#2403)

## libdd-ipc
**Next version:** `2.0.0`
**Semver bump:** `major`
**Tag:** `libdd-ipc-v2.0.0`

### ⚠️ major bump forced due to:

- `libdd-common`: ^5.2.0 → ^6.0.0
- `libdd-trace-stats`: ^8.0.0 → ^9.0.0

### Commits

- fix(ipc): drop the signal feature from libdd-ipc (#2431)

## libdd-live-debugger
**Next version:** `1.0.0`
**Semver bump:** `major`
**Tag:** `libdd-live-debugger-v1.0.0`

**Warning:** this is an initial release. Please verify that the version
and commits included are correct.


[EX-3425]:
https://datadoghq.atlassian.net/browse/EX-3425?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: hoolioh <107922352+hoolioh@users.noreply.github.com>
paullegranddc added a commit that referenced this pull request Sep 9, 2026
…uscation config once (#2474)

# Motivation

PR #2418 added agentless FFI config setters with two issues flagged in
review:
* the endpoint setter mutated the handle before validating both inputs
* the obfuscation config JSON was parsed twice (once in the setter,
again in the builder)
* The setters also lacked test coverage.

# Changes
* FFI setters modify config atomically
* Store the parsed ObfuscationConfig on TraceExporterConfig instead of
the raw JSON string
* Add tests for set_agentless_endpoint, set_agentless_timeout, and
set_obfuscation_config
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants