Skip to content

fix(stats): fix precedence for http endpoint (#2582) - #2587

Merged
VianneyRuhlmann merged 1 commit into
release/v44.0from
vianney/backport-http-endpoint-fix
Sep 29, 2026
Merged

VianneyRuhlmann merged 1 commit into
release/v44.0from
vianney/backport-http-endpoint-fix

Conversation

@VianneyRuhlmann

@VianneyRuhlmann VianneyRuhlmann commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Backport #2582 to v44.0

# What does this PR do?

Fixes a change from [!2323](https://github.com/DataDog/libdatadog/pull/2323/changes#r3909087863) which makes `http.route` take precedence over `http.endpoint`. This makes system-tests fail in dd-trace-py and doesn't seem to be the right default behavior.

# Motivation

This is currently preventing us from bumping libdatadog in dd-trace-py.

# Additional Notes

The OTLP semantics RFC doesn't mention this change, however if this is require this should be added behind a feature flag.

# How to test the change?

Describe here in detail how the change can be validated.


Co-authored-by: vianney.ruhlmann <vianney.ruhlmann@datadoghq.com>
@github-actions

Copy link
Copy Markdown
Contributor

📚 Documentation Check Results

⚠️ 924 documentation warning(s) found

📦 libdd-trace-stats - 924 warning(s)


Updated: 2026-09-29 14:29:55 UTC | Commit: 879b592 | missing-docs job results

@github-actions

Copy link
Copy Markdown
Contributor

🔒 Cargo Deny Results

⚠️ 1 issue(s) found, showing only errors (advisories, bans, sources)

📦 libdd-trace-stats - 1 error(s)

Show output
error[vulnerability]: TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries
    ┌─ /home/runner/work/libdatadog/libdatadog/Cargo.lock:222:1
    │
222 │ rustls 0.23.37 registry+https://github.com/rust-lang/crates.io-index
    │ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ security vulnerability detected
    │
    ├ ID: RUSTSEC-2026-0285
    ├ Advisory: https://rustsec.org/advisories/RUSTSEC-2026-0285
    ├ Rustls accepted TLS 1.3 handshake messages sent at the wrong encryption level
      when they followed a key-changing message in the same record. For example,
      a plaintext `EncryptedExtensions` message packed into the same record as the
      `ServerHello` was accepted.
      
      RFC 8446 section 5.1 requires that handshake messages do not span key changes,
      and that implementations terminate the connection with an "unexpected_message"
      alert if they do.
      
      The handshake transcript is still authenticated, so a network-position attacker
      cannot use this to alter or complete a handshake; the practical effect is that
      a peer could send handshake messages that should be encrypted in plaintext
      without rustls rejecting the connection.
      
      This is functionally the same bug as Go's
      [GO-2026-4340](https://pkg.go.dev/vuln/GO-2026-4340) (CVE-2025-61730).
    ├ Announcement: https://github.com/rustls/rustls/security/advisories/GHSA-2mjx-qc3c-rqvc
    ├ Solution: Upgrade to >=0.23.45 (try `cargo update -p rustls`)
    ├ rustls v0.23.37
      ├── hyper-rustls v0.27.7
      │   └── libdd-common v6.0.0
      │       ├── libdd-capabilities-impl v5.0.0
      │       │   ├── libdd-shared-runtime v4.0.0
      │       │   │   ├── libdd-telemetry v8.0.0
      │       │   │   │   └── libdd-trace-stats v9.0.0
      │       │   │   └── libdd-trace-stats v9.0.0 (*)
      │       │   ├── (dev) libdd-telemetry v8.0.0 (*)
      │       │   ├── libdd-trace-stats v9.0.0 (*)
      │       │   └── libdd-trace-utils v12.0.0
      │       │       ├── libdd-trace-obfuscation v8.0.0
      │       │       │   └── libdd-trace-stats v9.0.0 (*)
      │       │       ├── libdd-trace-stats v9.0.0 (*)
      │       │       └── (dev) libdd-trace-utils v12.0.0 (*)
      │       ├── libdd-dogstatsd-client v6.0.0
      │       │   └── libdd-trace-stats v9.0.0 (*)
      │       ├── libdd-shared-runtime v4.0.0 (*)
      │       ├── libdd-telemetry v8.0.0 (*)
      │       ├── libdd-trace-obfuscation v8.0.0 (*)
      │       ├── libdd-trace-stats v9.0.0 (*)
      │       └── libdd-trace-utils v12.0.0 (*)
      ├── libdd-common v6.0.0 (*)
      ├── rustls-platform-verifier v0.6.2
      │   └── libdd-common v6.0.0 (*)
      └── tokio-rustls v0.26.0
          ├── hyper-rustls v0.27.7 (*)
          └── libdd-common v6.0.0 (*)

advisories FAILED, bans ok, sources ok

Updated: 2026-09-29 14:31:49 UTC | Commit: 879b592 | dependency-check job results

@VianneyRuhlmann
VianneyRuhlmann marked this pull request as ready for review September 29, 2026 14:37
@VianneyRuhlmann
VianneyRuhlmann requested a review from a team as a code owner September 29, 2026 14:37
@VianneyRuhlmann
VianneyRuhlmann merged commit ff0247d into release/v44.0 Sep 29, 2026
62 of 72 checks passed
@VianneyRuhlmann
VianneyRuhlmann deleted the vianney/backport-http-endpoint-fix branch September 29, 2026 14:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant