zstd: Re-enable unsafe decodeSync memory copies (#1168) - #1171
Conversation
decodeSyncSimple has hardcoded `const useSafe = true` since klauspost#644 (2022), making the faster `sequenceDecs_decodeSync_{amd64,bmi2,arm64}` asm variants dead code that nothing calls. The klauspost#644 comment cites "rare, random crashes with fuzz testing" from the extended (16-byte-block) copies. Those copies were only the amplifier. The root cause was an unguarded bitReader overread in updateLength that produced out-of-range match offsets/lengths; it was fixed three days later in klauspost#645, which also added the Go fuzz corpus that has guarded this path ever since. With the source of the bad values gone and the +compressedBlockOverAlloc (16-byte) slack present on every output/literal buffer today, the dynamic useSafe guard — identical in shape to the still-active one in executeSimple — is sound. Restore the dynamic selection. On arm64 (Cortex-A72) DecodeAll improves by +8.7% geomean throughput (n=6, p=0.002), up to +16% on text. Because a stray 15-byte overrun lands in an adjacent live allocation, neither -race nor plain fuzzing can observe it; add a CGO+clang asan fuzz job over FuzzDecodeAll/FuzzDecAllNoBMI2 on amd64+arm64 so any future maxSyncLen/allocation regression is caught deterministically. Validated on amd64 and arm64: full test suite; asm-vs-noasm differential fuzz (byte-identical output); and asan over the decode corpus plus 2.4M mutation execs with no reports. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthrough
Changeszstd decode safety and validation
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant sequenceDecs
participant decodeSyncSimple
participant decodeSyncAsm
participant outputBuffer
sequenceDecs->>decodeSyncSimple: provide buffer capacities and sync length
decodeSyncSimple->>decodeSyncSimple: select safe or extended-copy mode
decodeSyncSimple->>decodeSyncAsm: decode sequences with selected mode
decodeSyncAsm->>outputBuffer: copy literals and matches
Possibly related issues
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🧹 Nitpick comments (1)
.github/workflows/go.yml (1)
199-200: 🔒 Security & Privacy | 🔵 Trivial | 💤 Low valueSet
persist-credentials: falseinactions/checkout.To improve security hygiene and prevent credential persistence through GitHub Actions artifacts, it's recommended to set
persist-credentials: falsewhen checking out the code, especially in jobs running tests or fuzzing.🛠️ Proposed fix
- name: Checkout code uses: actions/checkout@v7.0.0 + with: + persist-credentials: false🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/go.yml around lines 199 - 200, Update the actions/checkout step in the workflow to set persist-credentials to false, while preserving the existing checkout action version and job behavior.Source: Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In @.github/workflows/go.yml:
- Around line 199-200: Update the actions/checkout step in the workflow to set
persist-credentials to false, while preserving the existing checkout action
version and job behavior.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro
Run ID: aea2c5ea-523c-4459-8a3e-85056a82d8fb
📒 Files selected for processing (2)
.github/workflows/go.ymlzstd/seqdec_asm.go
|
the irony: "enable unsafe, it's safe now!" crashes on fuzz failure on the very first CI build. |
The per-sequence space check in executeSingleTriple (used by the sync decoder's inlined execute) requires only outPos+ll+ml <= cap(s.out). The unsafe extended copies, however, write in 16-byte blocks and overrun the logical end of a run by up to compressedBlockOverAlloc-1 (15) bytes. When a stream's decoded length lands within the 16-byte over-allocation slack -- e.g. a malformed frame whose declared content size is a few bytes below what its sequences actually produce -- the check passes but the final block copy writes past cap(s.out). The overrun is at most 15 bytes and Go's size-class rounding places it in slop that -race and -asan do not poison, so it corrupts an adjacent live allocation only intermittently, surfacing later as a crash in the garbage collector rather than at the write. That is exactly the 'rare, random crashes with fuzz testing' klauspost#644 disabled the unsafe path for in 2022; it was never the bitReader overread fixed in klauspost#645, but this missing copy margin. Reserve compressedBlockOverAlloc in the space check on the unsafe (non-safe) path only, so the overrun stays within cap(s.out); a well-formed decode ends at cap-16 and is unaffected, while an over-producing stream now errors with error_not_enough_space instead of corrupting memory. The safe copies are bounds-exact and keep the tight check. amd64 asm gains one ADDQ per unsafe variant; the safe variants are unchanged. TestDecodeSyncUnsafeOOB drives the unsafe asm with real captured sequences into a canary-guarded buffer sized to model the under-reported case; it fails (canary overwritten past cap) on the unpatched asm and passes here, on amd64 and arm64. Validated additionally with the full zstd suite and FuzzDecodeAll (default and -tags=nounsafe) on go1.25 + go1.26, both arches. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Pushed a fix for the arm64 CI crash ( Root cause — not the bitReader overread, but a missing copy margin. The per-sequence space check in Fix — reserve Repro/regression — Since asan can't see this overrun class, the |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@zstd/seqdec_oob_test.go`:
- Around line 101-115: Update the test around decodeSyncSimple so it explicitly
exercises the unsafe copy path rather than only confirming assembly dispatch.
Invoke decodeSyncAsm with useSafe=false, or otherwise instrument the selection
to verify unsafe mode was chosen, while preserving the existing canary
validation and asmPaths assertion.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro
Run ID: 8d0c1be3-0c2c-4d69-b654-fa172e4d0900
📒 Files selected for processing (4)
zstd/_generate/gen.gozstd/seqdec_amd64.szstd/seqdec_arm64.szstd/seqdec_oob_test.go
Review feedback on the regression test: it verified only that the asm path was dispatched, relying implicitly on the buffer geometry to select the unsafe (extended-copy) variant. If the useSafe conditions or the test harness allocation ever changed, the test could silently degrade into exercising the bounds-exact safe copies while still passing. Extract decodeSyncSimple's selection into useSafeDecodeSync() (pure refactor, no behavior change) and have the test call the same helper to fail loudly if its buffer sizing would select the safe variant. The canary validation and asm-path assertion are unchanged; the test still fails via the canary against the unpatched assembly on both architectures. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Klaus's review on klauspost#1171 pointed out the compressedBlockOverAlloc margin can be folded into the existing LEAQ displacement instead of a separate ADDQ. Saves one instruction per unsafe variant on amd64/bmi2; the safe path (addMargin=0) and arm64 codegen are unaffected in substance.
|
Done in 47ea5b1 — folded |
…804) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [github.com/klauspost/compress](https://github.com/klauspost/compress) | `v1.19.1` → `v1.19.2` |  |  | --- ### Release Notes <details> <summary>klauspost/compress (github.com/klauspost/compress)</summary> ### [`v1.19.2`](https://github.com/klauspost/compress/releases/tag/v1.19.2) [Compare Source](klauspost/compress@v1.19.1...v1.19.2) #### What's Changed - huff0: add arm64 assembly for Decompress4X/1X via avo lowering by [@​lizthegrey](https://github.com/lizthegrey) in [#​1172](klauspost/compress#1172) - zstd: Re-enable unsafe decodeSync memory copies ([#​1168](klauspost/compress#1168)) by [@​lizthegrey](https://github.com/lizthegrey) in [#​1171](klauspost/compress#1171) - zstd: fix arm64 asm frame offsets placing locals on the saved LR slot by [@​lizthegrey](https://github.com/lizthegrey) in [#​1176](klauspost/compress#1176) - zstd: avoid racing MaxDecodedSize write on shared dict litEnc by [@​zanarellidev](https://github.com/zanarellidev) in [#​1182](klauspost/compress#1182) - zstd: keep BuildDict recent-offsets positive and loadable by [@​zanarellidev](https://github.com/zanarellidev) in [#​1184](klauspost/compress#1184) - zstd: handle zero-literal BuildDict corpus by [@​cyphercodes](https://github.com/cyphercodes) in [#​1178](klauspost/compress#1178) - zstd: don't clear the registered dictionary when decoding past the window by [@​sueun-dev](https://github.com/sueun-dev) in [#​1177](klauspost/compress#1177) #### New Contributors - [@​zanarellidev](https://github.com/zanarellidev) made their first contribution in [#​1183](klauspost/compress#1183) - [@​cyphercodes](https://github.com/cyphercodes) made their first contribution in [#​1178](klauspost/compress#1178) - [@​sueun-dev](https://github.com/sueun-dev) made their first contribution in [#​1177](klauspost/compress#1177) **Full Changelog**: <klauspost/compress@v1.19.1...v1.19.2> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`) - Automerge - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC43LjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC43LjIiLCJ0YXJnZXRCcmFuY2giOiJmb3JnZWpvIiwibGFiZWxzIjpbImRlcGVuZGVuY3ktdXBncmFkZSIsInRlc3Qvbm90LW5lZWRlZCJdfQ==--> Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13804 Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
…p ci] Bumps the go-modules group in /e2e-go with 6 updates: | Package | From | To | | --- | --- | --- | | [github.com/klauspost/compress](https://github.com/klauspost/compress) | `1.19.1` | `1.19.2` | | [github.com/moby/go-archive](https://github.com/moby/go-archive) | `0.3.2` | `0.3.3` | | [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp](https://github.com/open-telemetry/opentelemetry-go-contrib) | `0.69.0` | `0.70.0` | | [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | | [go.opentelemetry.io/otel/metric](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | | [go.opentelemetry.io/otel/trace](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | Updates `github.com/klauspost/compress` from 1.19.1 to 1.19.2 Release notes *Sourced from [github.com/klauspost/compress's releases](https://github.com/klauspost/compress/releases).* > v1.19.2 > ------- > > What's Changed > -------------- > > * huff0: add arm64 assembly for Decompress4X/1X via avo lowering by [`@lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1172](https://redirect.github.com/klauspost/compress/pull/1172) > * zstd: Re-enable unsafe decodeSync memory copies ([#1168](https://redirect.github.com/klauspost/compress/issues/1168)) by [`@lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1171](https://redirect.github.com/klauspost/compress/pull/1171) > * zstd: fix arm64 asm frame offsets placing locals on the saved LR slot by [`@lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1176](https://redirect.github.com/klauspost/compress/pull/1176) > * zstd: avoid racing MaxDecodedSize write on shared dict litEnc by [`@zanarellidev`](https://github.com/zanarellidev) in [klauspost/compress#1182](https://redirect.github.com/klauspost/compress/pull/1182) > * zstd: keep BuildDict recent-offsets positive and loadable by [`@zanarellidev`](https://github.com/zanarellidev) in [klauspost/compress#1184](https://redirect.github.com/klauspost/compress/pull/1184) > * zstd: handle zero-literal BuildDict corpus by [`@cyphercodes`](https://github.com/cyphercodes) in [klauspost/compress#1178](https://redirect.github.com/klauspost/compress/pull/1178) > * zstd: don't clear the registered dictionary when decoding past the window by [`@sueun-dev`](https://github.com/sueun-dev) in [klauspost/compress#1177](https://redirect.github.com/klauspost/compress/pull/1177) > > New Contributors > ---------------- > > * [`@zanarellidev`](https://github.com/zanarellidev) made their first contribution in [klauspost/compress#1183](https://redirect.github.com/klauspost/compress/pull/1183) > * [`@cyphercodes`](https://github.com/cyphercodes) made their first contribution in [klauspost/compress#1178](https://redirect.github.com/klauspost/compress/pull/1178) > * [`@sueun-dev`](https://github.com/sueun-dev) made their first contribution in [klauspost/compress#1177](https://redirect.github.com/klauspost/compress/pull/1177) > > **Full Changelog**: <https://github.com/klauspost/compress/compare/v1.19.1...v1.19.2> Commits * [`c3b3439`](https://github.com/klauspost/compress/commit/c3b3439a48196b5082c63252bfb8633d0a2faad4) zstd: don't clear the registered dictionary when decoding past the window ([#1](https://redirect.github.com/klauspost/compress/issues/1)... * [`9874bc9`](https://github.com/klauspost/compress/commit/9874bc9073f350ce462becb84f9a23c3e828d03f) fix(zstd): handle zero-literal BuildDict corpus ([#1178](https://redirect.github.com/klauspost/compress/issues/1178)) * [`71bb6fd`](https://github.com/klauspost/compress/commit/71bb6fd9ddbfbb2ca6612542a916c766a866bfb3) zstd: keep BuildDict recent-offsets positive and loadable ([#1184](https://redirect.github.com/klauspost/compress/issues/1184)) * [`3d4dacb`](https://github.com/klauspost/compress/commit/3d4dacbaa9faca75caacc35b6d75731a81a92c6b) zstd: avoid racing MaxDecodedSize write on shared dict litEnc ([#1182](https://redirect.github.com/klauspost/compress/issues/1182)) * [`3ceaa81`](https://github.com/klauspost/compress/commit/3ceaa81409aabe39c71821b936155b33471c78d8) build(deps): bump the github-actions group with 5 updates ([#1185](https://redirect.github.com/klauspost/compress/issues/1185)) * [`72cb4d3`](https://github.com/klauspost/compress/commit/72cb4d3e8e743bea5d1ba40896ad55214a1844e4) chore: add OpenSSF Scorecard GitHub Action ([#1183](https://redirect.github.com/klauspost/compress/issues/1183)) * [`69c9db4`](https://github.com/klauspost/compress/commit/69c9db420ae55bfcdfbef564805e2646206545f7) zstd: fix arm64 asm locals overwriting the saved link register ([#1176](https://redirect.github.com/klauspost/compress/issues/1176)) * [`117430d`](https://github.com/klauspost/compress/commit/117430d3b0e3c39c14d32fe7c90652149a78e609) zstd: Re-enable unsafe decodeSync memory copies ([#1168](https://redirect.github.com/klauspost/compress/issues/1168)) ([#1171](https://redirect.github.com/klauspost/compress/issues/1171)) * [`c73af0c`](https://github.com/klauspost/compress/commit/c73af0c12cc767386af8388f30d5aa7428e6dfc8) huff0: add arm64 assembly for Decompress4X/1X via avo lowering ([#1172](https://redirect.github.com/klauspost/compress/issues/1172)) * See full diff in [compare view](https://github.com/klauspost/compress/compare/v1.19.1...v1.19.2) Updates `github.com/moby/go-archive` from 0.3.2 to 0.3.3 Release notes *Sourced from [github.com/moby/go-archive's releases](https://github.com/moby/go-archive/releases).* > v0.3.3 > ------ > > What's Changed > -------------- > > * Fix a regression introduced in v0.3.0 that caused archive extraction to reject hardlinks with absolute targets, as produced by > some image builders. Absolute hardlink targets are now resolved relative to the extraction root, while paths that escape the root > remain rejected. [moby/go-archive#100](https://redirect.github.com/moby/go-archive/pull/100) > * Fix a regression introduced in v0.3.0 that caused archive extraction to fail when applying permissions to device nodes, including > nodes on `nodev` filesystems and `dev/ptmx`. Device nodes are now referenced without opening the underlying device before applying > their mode. [moby/go-archive#103](https://redirect.github.com/moby/go-archive/pull/103) > * Set close-on-exec on file descriptors used by the Linux permission fallback to prevent them from leaking into child processes. > [moby/go-archive#104](https://redirect.github.com/moby/go-archive/pull/104) > > **Full Changelog**: <https://github.com/moby/go-archive/compare/v0.3.2...v0.3.3> Commits * [`ae9e219`](https://github.com/moby/go-archive/commit/ae9e219f7104d91e262055a29bae1f9753106981) Merge pull request [#104](https://redirect.github.com/moby/go-archive/issues/104) from thaJeztah/use\_O\_CLOEXEC * [`98ff1da`](https://github.com/moby/go-archive/commit/98ff1dac11141c20bf7975ee1243fbe5031c2684) archive: set close-on-exec for chmod fallback descriptors * [`1e8dfbc`](https://github.com/moby/go-archive/commit/1e8dfbc6ec14614f009716c5ec04b6d104168201) Merge pull request [#103](https://redirect.github.com/moby/go-archive/issues/103) from thaJeztah/fix\_chmod\_fallback * [`e738eed`](https://github.com/moby/go-archive/commit/e738eed524c260a613bea37a47349e0f7d0a45a6) archive: keep procfs file alive during fchmodat * [`2d863f5`](https://github.com/moby/go-archive/commit/2d863f57793b7e2340cfca8f9a94a2d55cf7e68e) archive: preserve procfs access during chroot extraction * [`89653ed`](https://github.com/moby/go-archive/commit/89653edcda61f24e83ae2aa485f57cf762c59568) archive: fix chmod fallback for device nodes on nodev mounts * [`f37d413`](https://github.com/moby/go-archive/commit/f37d413855106b6c4f5cc3c063013869b6294e7d) Merge pull request [#106](https://redirect.github.com/moby/go-archive/issues/106) from thaJeztah/fallback\_no\_read * [`4ffc915`](https://github.com/moby/go-archive/commit/4ffc91517ffd9b77b11efd91768b5d6d4303a3b6) archive: test chmod fallback without read permission * [`9af1c40`](https://github.com/moby/go-archive/commit/9af1c40d9b972e82affd0b3ed3beb3f5d4d5f5d2) Merge pull request [#105](https://redirect.github.com/moby/go-archive/issues/105) from thaJeztah/test\_chrooted\_chmod\_fallback * [`3daca2a`](https://github.com/moby/go-archive/commit/3daca2abcac72471e1424cc840e7c5711937ade9) archive: test chmod fallback without procfs in chroot * Additional commits viewable in [compare view](https://github.com/moby/go-archive/compare/v0.3.2...v0.3.3) Updates `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` from 0.69.0 to 0.70.0 Release notes *Sourced from [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp's releases](https://github.com/open-telemetry/opentelemetry-go-contrib/releases).* > Release v1.45.0/v2.5.2/v0.70.0/v0.37.2/v0.25.0/v0.20.0/v0.16.2/v0.17.0 > ---------------------------------------------------------------------- > > Overview > -------- > > ### Added > > * Add `go.opentelemetry.io/contrib/detectors/ibmcloud/vpc`, a new resource detector for IBM Cloud VPC virtual server instances, ported from `github.com/open-telemetry/opentelemetry-collector-contrib/processor/resourcedetectionprocessor/internal/ibmcloud/vpc`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `cloud.availability_zone`, `cloud.account.id`, `cloud.resource_id`, `host.id`, `host.image.id`, `host.image.name`, `host.name`, and `host.type`. ([#9011](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9011)) > * Add `go.opentelemetry.io/contrib/detectors/k8sapi`, a new resource detector that queries the Kubernetes API. Detects `k8s.node.name` and `k8s.node.uid` when `K8S_NODE_NAME` is set via the downward API, and `k8s.cluster.uid` derived from the kube-system namespace UID (works on any Kubernetes distribution). ([#9108](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9108)) > * Add new `elasticbeanstalk` resource detector for AWS Elastic Beanstalk, ported from `processor/resourcedetectionprocessor/internal/aws/elasticbeanstalk` in opentelemetry-collector-contrib. ([#8993](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8993)) > * The resource created by `go.opentelemetry.io/contrib/otelconf` now includes [default SDK attributes](https://pkg.go.dev/go.opentelemetry.io/otel/sdk/resource#Default). ([#8990](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8990)) > * Add support for the `aws.ecs` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#8915](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8915)) > * Add support for the `aws.eks` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9138](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9138)) > * Add support for the `azure.vm` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9074](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9074)) > * Add support for the `gcp` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9137](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9137)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azureappservice`, a new resource detector for Azure App Service. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `azure.app_service.instance.id`, and `deployment.environment.name` from the `WEBSITE_*` and `REGION_NAME` environment variables. ([#9289](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9289)) > * Add `azurecontainerapps` resource detector for Azure Container Apps. ([#8939](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8939)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azurefunctions`, a new resource detector for Azure Functions. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `faas.instance`, and `deployment.environment.name` from the `FUNCTIONS_*`, `WEBSITE_*`, `CONTAINER_NAME`, and `REGION_NAME` environment variables. ([#9290](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9290)) > * Add `NewResourceDetector` along with the `WithAttributeFilter` and `WithTagKeyFilter` options in `go.opentelemetry.io/contrib/detectors/azure/azurevm`. `WithAttributeFilter` restricts the returned resource to the attributes the filter accepts. `WithTagKeyFilter` opts in to `azure.tag.<name>` attributes for the VM tags whose keys satisfy the provided predicate; no VM tags are emitted without it. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > * Add `go.opentelemetry.io/contrib/detectors/vultr` — a new resource detector for Vultr Cloud Compute instances, ported from `processor/resourcedetectionprocessor/internal/vultr` in `opentelemetry-collector-contrib`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `host.id`, and `host.name`. ([#8995](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8995)) > > ### Changed > > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.43.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.43.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.43.0) for complete details. ([#9337](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9337)) > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.42.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.42.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.42.0) for complete details. ([#9196](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9196)) > * Use direct normalized-key lookups in `Carrier.Get` and `Carrier.Keys` in `go.opentelemetry.io/contrib/propagators/envcar`. ([#9112](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9112)) > * Update log bridge conversions to use attribute key-values instead of the removed log key-values in `go.opentelemetry.io/contrib/bridges/otellogr`, `go.opentelemetry.io/contrib/bridges/otellogrus`, `go.opentelemetry.io/contrib/bridges/otelslog`, and `go.opentelemetry.io/contrib/bridges/otelzap`. ([#9180](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9180)) > * The `Version()` function in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux` has been replaced by `const Version`. ([#9076](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9076)) > * Set `error.type` attribute instead of adding `exception` span events in `go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin`. ([#8977](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8977)) > * Prefer the gRPC dial target over the resolved peer IP for the `server.address` and `server.port` attributes in `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc`. ([#8904](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8904)) > * The detector in `go.opentelemetry.io/contrib/detectors/azure/azurevm` now also detects `cloud.account.id`, `cloud.availability_zone`, `azure.vm.name`, `azure.vm.size`, `azure.vm.scaleset.name`, and `azure.resource_group.name`, and prefers `osProfile.computerName` for `host.name` (falling back to the VM name), reconciling it with the collector-contrib Azure resource detector. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > > ### Fixed > > * Fix Prometheus reader resource label filter configuration in `go.opentelemetry.io/contrib/otelconf/v0.2.0`. ([#9062](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9062)) > * Apply `resource.detection/development.attributes.included` and `excluded` filtering to resource detector attributes in `go.opentelemetry.io/contrib/otelconf/x`. ([#9131](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9131)) > * Honor the context configured with `WithContext` when constructing resources in `go.opentelemetry.io/contrib/otelconf` and `go.opentelemetry.io/contrib/otelconf/x`. ([#9160](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9160)) > * Handle nil response bodies from custom `RoundTripper` implementations in `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` without panicking. ([#9184](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9184)) > * Fix incorrect (overestimated) sum calculation for runtime histograms in `go.opentelemetry.io/contrib/instrumentation/runtime`. ([#9063](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9063)) > * Fix `Severity.UnmarshalText` round trip for positive `FATAL` offsets above the named range in `go.opentelemetry.io/contrib/processors/minsev`. ([#9197](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9197)) > * Reduce binary size by fetching ConfigMaps via `rest.HTTPClientFor` instead of the Kubernetes clientset in `go.opentelemetry.io/contrib/detectors/aws/eks`. ([#9284](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9284)) > * `TextMapPropagator` in `go.opentelemetry.io/contrib/propagators/autoprop` returns the no-op propagator for empty input, matching the behavior of `none`. An unknown `OTEL_PROPAGATORS` value still returns an error with a nil propagator so `NewTextMapPropagator` falls back to the default TraceContext and Baggage propagators instead of disabling propagation. ([#9163](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9163)) > * Preserve error-valued attributes nested in a group as grouped attributes instead of silently dropping them in `go.opentelemetry.io/contrib/bridges/otelslog`. ([#9238](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9238)) > * Fix a data race in `go.opentelemetry.io/contrib/bridges/otelslog` where concurrent `Handle` calls could corrupt each other's log attributes because `kvBuffer.KeyValues` returned a slice aliasing a shared buffer. ([#9229](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9229)) > * Avoid a panic in `go.opentelemetry.io/contrib/bridges/otelzap` when a malformed error field contains a nil or non-error value. ([#9068](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9068)) > * Use `azure.container_app.instance.id` instead of `service.instance.id` for the replica name detected by `go.opentelemetry.io/contrib/detectors/azure/azurecontainerapps`. ([#9208](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9208)) > * Preserve the underlying metadata errors returned with partial resources from `go.opentelemetry.io/contrib/detectors/gcp`. ([#9069](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9069)) > * Copy `MultipartForm` back to the request `otelmux.Middleware` was given after the wrapped handler returns, so `net/http` can find and remove the temp files `ParseMultipartForm` created on the context-derived request copy, when `otelmux.Middleware` wraps a handler directly, in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux`. This does not cover a handler panic, nor the common `router.Use(...)` integration, where `gorilla/mux`'s own routing step makes an additional request copy the middleware cannot write back through; see [gorilla/mux#777](https://redirect.github.com/gorilla/mux/pull/777). ([#9361](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9361)) > * Report the `b3` header from `Fields()` for the default `B3Unspecified` single-header injection encoding, matching what `Inject` writes, in `go.opentelemetry.io/contrib/propagators/b3`. ([#9273](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9273)) > * Fix `go.opentelemetry.io/contrib/propagators/aws/xray` producing deterministic trace and span IDs when the seed read from `crypto/rand` silently failed, by switching to `math/rand/v2`'s concurrency-safe top-level generator. ([#9359](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9359)) ... (truncated) Changelog *Sourced from [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp's changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md).* > [1.45.0/2.5.2/0.70.0/0.37.2/0.25.0/0.20.0/0.16.2/0.17.0] - 2026-08-03 > --------------------------------------------------------------------- > > ### Added > > * Add `go.opentelemetry.io/contrib/detectors/ibmcloud/vpc`, a new resource detector for IBM Cloud VPC virtual server instances, ported from `github.com/open-telemetry/opentelemetry-collector-contrib/processor/resourcedetectionprocessor/internal/ibmcloud/vpc`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `cloud.availability_zone`, `cloud.account.id`, `cloud.resource_id`, `host.id`, `host.image.id`, `host.image.name`, `host.name`, and `host.type`. ([#9011](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9011)) > * Add `go.opentelemetry.io/contrib/detectors/k8sapi`, a new resource detector that queries the Kubernetes API. Detects `k8s.node.name` and `k8s.node.uid` when `K8S_NODE_NAME` is set via the downward API, and `k8s.cluster.uid` derived from the kube-system namespace UID (works on any Kubernetes distribution). ([#9108](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9108)) > * Add new `elasticbeanstalk` resource detector for AWS Elastic Beanstalk, ported from `processor/resourcedetectionprocessor/internal/aws/elasticbeanstalk` in opentelemetry-collector-contrib. ([#8993](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8993)) > * The resource created by `go.opentelemetry.io/contrib/otelconf` now includes [default SDK attributes](https://pkg.go.dev/go.opentelemetry.io/otel/sdk/resource#Default). ([#8990](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8990)) > * Add support for the `aws.ecs` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#8915](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8915)) > * Add support for the `aws.eks` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9138](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9138)) > * Add support for the `azure.vm` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9074](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9074)) > * Add support for the `gcp` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9137](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9137)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azureappservice`, a new resource detector for Azure App Service. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `azure.app_service.instance.id`, and `deployment.environment.name` from the `WEBSITE_*` and `REGION_NAME` environment variables. ([#9289](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9289)) > * Add `azurecontainerapps` resource detector for Azure Container Apps. ([#8939](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8939)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azurefunctions`, a new resource detector for Azure Functions. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `faas.instance`, and `deployment.environment.name` from the `FUNCTIONS_*`, `WEBSITE_*`, `CONTAINER_NAME`, and `REGION_NAME` environment variables. ([#9290](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9290)) > * Add `NewResourceDetector` along with the `WithAttributeFilter` and `WithTagKeyFilter` options in `go.opentelemetry.io/contrib/detectors/azure/azurevm`. `WithAttributeFilter` restricts the returned resource to the attributes the filter accepts. `WithTagKeyFilter` opts in to `azure.tag.<name>` attributes for the VM tags whose keys satisfy the provided predicate; no VM tags are emitted without it. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > * Add `go.opentelemetry.io/contrib/detectors/vultr` — a new resource detector for Vultr Cloud Compute instances, ported from `processor/resourcedetectionprocessor/internal/vultr` in `opentelemetry-collector-contrib`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `host.id`, and `host.name`. ([#8995](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8995)) > > ### Changed > > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.43.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.43.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.43.0) for complete details. ([#9337](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9337)) > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.42.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.42.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.42.0) for complete details. ([#9196](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9196)) > * Use direct normalized-key lookups in `Carrier.Get` and `Carrier.Keys` in `go.opentelemetry.io/contrib/propagators/envcar`. ([#9112](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9112)) > * Update log bridge conversions to use attribute key-values instead of the removed log key-values in `go.opentelemetry.io/contrib/bridges/otellogr`, `go.opentelemetry.io/contrib/bridges/otellogrus`, `go.opentelemetry.io/contrib/bridges/otelslog`, and `go.opentelemetry.io/contrib/bridges/otelzap`. ([#9180](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9180)) > * The `Version()` function in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux` has been replaced by `const Version`. ([#9076](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9076)) > * Set `error.type` attribute instead of adding `exception` span events in `go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin`. ([#8977](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8977)) > * Prefer the gRPC dial target over the resolved peer IP for the `server.address` and `server.port` attributes in `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc`. ([#8904](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8904)) > * The detector in `go.opentelemetry.io/contrib/detectors/azure/azurevm` now also detects `cloud.account.id`, `cloud.availability_zone`, `azure.vm.name`, `azure.vm.size`, `azure.vm.scaleset.name`, and `azure.resource_group.name`, and prefers `osProfile.computerName` for `host.name` (falling back to the VM name), reconciling it with the collector-contrib Azure resource detector. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > > ### Fixed > > * Fix Prometheus reader resource label filter configuration in `go.opentelemetry.io/contrib/otelconf/v0.2.0`. ([#9062](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9062)) > * Apply `resource.detection/development.attributes.included` and `excluded` filtering to resource detector attributes in `go.opentelemetry.io/contrib/otelconf/x`. ([#9131](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9131)) > * Honor the context configured with `WithContext` when constructing resources in `go.opentelemetry.io/contrib/otelconf` and `go.opentelemetry.io/contrib/otelconf/x`. ([#9160](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9160)) > * Handle nil response bodies from custom `RoundTripper` implementations in `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` without panicking. ([#9184](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9184)) > * Fix incorrect (overestimated) sum calculation for runtime histograms in `go.opentelemetry.io/contrib/instrumentation/runtime`. ([#9063](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9063)) > * Fix `Severity.UnmarshalText` round trip for positive `FATAL` offsets above the named range in `go.opentelemetry.io/contrib/processors/minsev`. ([#9197](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9197)) > * Reduce binary size by fetching ConfigMaps via `rest.HTTPClientFor` instead of the Kubernetes clientset in `go.opentelemetry.io/contrib/detectors/aws/eks`. ([#9284](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9284)) > * `TextMapPropagator` in `go.opentelemetry.io/contrib/propagators/autoprop` returns the no-op propagator for empty input, matching the behavior of `none`. An unknown `OTEL_PROPAGATORS` value still returns an error with a nil propagator so `NewTextMapPropagator` falls back to the default TraceContext and Baggage propagators instead of disabling propagation. ([#9163](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9163)) > * Preserve error-valued attributes nested in a group as grouped attributes instead of silently dropping them in `go.opentelemetry.io/contrib/bridges/otelslog`. ([#9238](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9238)) > * Fix a data race in `go.opentelemetry.io/contrib/bridges/otelslog` where concurrent `Handle` calls could corrupt each other's log attributes because `kvBuffer.KeyValues` returned a slice aliasing a shared buffer. ([#9229](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9229)) > * Avoid a panic in `go.opentelemetry.io/contrib/bridges/otelzap` when a malformed error field contains a nil or non-error value. ([#9068](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9068)) > * Use `azure.container_app.instance.id` instead of `service.instance.id` for the replica name detected by `go.opentelemetry.io/contrib/detectors/azure/azurecontainerapps`. ([#9208](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9208)) > * Preserve the underlying metadata errors returned with partial resources from `go.opentelemetry.io/contrib/detectors/gcp`. ([#9069](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9069)) > * Copy `MultipartForm` back to the request `otelmux.Middleware` was given after the wrapped handler returns, so `net/http` can find and remove the temp files `ParseMultipartForm` created on the context-derived request copy, when `otelmux.Middleware` wraps a handler directly, in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux`. This does not cover a handler panic, nor the common `router.Use(...)` integration, where `gorilla/mux`'s own routing step makes an additional request copy the middleware cannot write back through; see [gorilla/mux#777](https://redirect.github.com/gorilla/mux/pull/777). ([#9361](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9361)) > * Report the `b3` header from `Fields()` for the default `B3Unspecified` single-header injection encoding, matching what `Inject` writes, in `go.opentelemetry.io/contrib/propagators/b3`. ([#9273](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9273)) > * Fix `go.opentelemetry.io/contrib/propagators/aws/xray` producing deterministic trace and span IDs when the seed read from `crypto/rand` silently failed, by switching to `math/rand/v2`'s concurrency-safe top-level generator. ([#9359](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9359)) > * Strip connection number suffix from connection ID in `go.opentelemetry.io/contrib/instrumentation/go.mongodb.org/mongo-driver/v2/mongo/otelmongo` to prevent unbounded metric cardinality. ([#9352](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9352)) ... (truncated) Commits * [`c8a87a6`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/c8a87a60ba1b3374fd16df11fc3eeae6c41abbc9) Release v1.45.0/v2.5.2/v0.70.0/v0.37.2/v0.25.0/v0.20.0/v0.16.2/v0.17.0 ([#9413](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9413)) * [`cde125c`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/cde125c563f232eb6b423a208d375f8e53ae2557) fix(deps): update aws-sdk-go-v2 monorepo ([#9384](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9384)) * [`88572a7`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/88572a7662d00e805777ed96932d532316c13787) chore(deps): update googleapis to 6ac0973 ([#9409](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9409)) * [`e4f511a`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/e4f511a0f3cc2b09b87cb164427b49dfd2e14f7d) chore(deps): update github/codeql-action action to v4.37.5 ([#9410](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9410)) * [`265eb0b`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/265eb0b5fe0682801fd8177aec74ce8769c5a0a4) fix(deps): update go.opentelemetry.io/otel digest to 48db2c6 ([#9317](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9317)) * [`941ba46`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/941ba46979c59dca89d26040ed919870283e36e9) chore(deps): update github.com/charmbracelet/ultraviolet digest to 8b69304 (#... * [`ededd3b`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/ededd3b571ad562351a0afe09682774a6f48d63e) chore(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 ([#9406](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9406)) * [`7c6e819`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/7c6e819d4eb26eede10e98c424adb76304025fda) fix(deps): update module github.com/atombender/go-jsonschema to v0.24.1 ([#9405](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9405)) * [`ec1e544`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/ec1e544a0d6883126198c3fc3a7d62fc8db29195) chore(deps): update github.com/lufia/plan9stats digest to 341c2f0 ([#9403](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9403)) * [`5d7e16a`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/5d7e16aa1138a5446a648dd92ebc42031c93e327) chore(deps): update github.com/golangci/rowserrcheck digest to d2031e3 ([#9402](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9402)) * Additional commits viewable in [compare view](https://github.com/open-telemetry/opentelemetry-go-contrib/compare/zpages/v0.69.0...zpages/v0.70.0) Updates `go.opentelemetry.io/otel` from 1.44.0 to 1.45.0 Changelog *Sourced from [go.opentelemetry.io/otel's changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md).* > [1.45.0/0.67.0/0.21.0/0.0.18] - 2026-08-03 > ------------------------------------------ > > ### Added > > * Add experimental observability metrics to `BatchProcessor` in `go.opentelemetry.io/otel/sdk/log`. ([#7124](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/7124)) > * Add the experimental `WithUnsafeAttributes` no-copy attribute option to `go.opentelemetry.io/otel/metric/x` for future performance improvements. This API is a work in progress. ([#8251](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8251)) > * Add `Map` and `MapValue` functions for the new `MAP` attribute type in `go.opentelemetry.io/otel/attribute`. ([#8445](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8445)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlptrace`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlplog`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/zipkin`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Apply `AttributeValueLengthLimit` recursively to values contained in `attribute.MAP` attributes in `go.opentelemetry.io/otel/sdk/trace`. ([#8454](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8454)) > * Remove duplicate keys from `attribute.MAP` values in `go.opentelemetry.io/otel/sdk/resource` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/log` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in span, event, link, and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/trace` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in measurement and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/metric` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Extend `WithAllowKeyDuplication` in `go.opentelemetry.io/otel/sdk/log` to disable duplicate-key removal in `attribute.MAP` values for instrumentation scope attributes. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Add the `go.opentelemetry.io/otel/semconv/v1.42.0` package. > The package contains semantic conventions from the `v1.42.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.42.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.41.0`. ([#8484](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8484)) > * Add `WithoutPanicRecording` as a `TracerProviderOption` in `go.opentelemetry.io/otel/sdk/trace` to disable exception event recording for panics. ([#8532](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8532)) > * Add the `go.opentelemetry.io/otel/semconv/v1.43.0` package. > The package contains semantic conventions from the `v1.43.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.43.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.42.0`. ([#8628](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8628)) > > ### Changed > > * `HistogramReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` now uses a time-unbiased sampling algorithm for exemplars. ([#8306](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8306)) > * ⚠️ **Breaking Change:** Use `go.opentelemetry.io/otel/attribute.Value` and `go.opentelemetry.io/otel/attribute.KeyValue` for log bodies and attributes in `go.opentelemetry.io/otel/log`, `go.opentelemetry.io/otel/log/logtest`, `go.opentelemetry.io/otel/sdk/log`, and `go.opentelemetry.io/otel/sdk/log/logtest`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Encode log bodies and attributes as `go.opentelemetry.io/otel/attribute.Value` JSON in `go.opentelemetry.io/otel/exporters/stdout/stdoutlog`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Improve the performance of hashing `BOOLSLICE`, `INT64SLICE`, `FLOAT64SLICE`, and `STRINGSLICE` attribute values by avoiding reflection for short slices in `go.opentelemetry.io/otel/attribute`. ([#8511](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8511)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_METRICS_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_TRACES_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > > ### Deprecated > > * Deprecate `WithExportBufferSize` in `go.opentelemetry.io/otel/sdk/log`. The option remains available for source compatibility but no longer affects behavior; `BatchProcessor` no longer maintains a separate export-request buffer. ([#8620](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8620)) > > ### Removed > > * ⚠️ **Breaking Change:** Remove `Kind`, `Value`, `KeyValue`, their constructors, and attribute conversion helpers from `go.opentelemetry.io/otel/log`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * ⚠️ **Breaking Change:** Remove the `AttributeValueLengthLimit` and `AttributeCountLimit` fields from `RecordFactory` in `go.opentelemetry.io/otel/sdk/log/logtest`; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. ([#8556](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8556)) > > ### Fixed > > * Apply TLS certificates configured through environment variables to gRPC connections in `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc`. > * Prevent panics in `go.opentelemetry.io/otel/bridge/opentracing` when OpenTracing baggage is propagated concurrently with `Span.SetBaggageItem`. > * Fix an off-by-one error in `FixedSizeReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` that prevented the first exemplar from being sampled after the reservoir was filled. ([#8309](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8309)) > * Interpret HTTP `Retry-After` header values as seconds instead of nanoseconds when retrying OTLP HTTP exports in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp`, `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp`, and `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp`. ([#8383](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8383)) > * Fix a memory leak in the `Reservoir` implementation in `go.opentelemetry.io/otel/sdk/metric/exemplar`, where storing the full `context.Context` pinned large objects such as gRPC transport buffers. ([#8389](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8389)) ... (truncated) Commits * [`93a693e`](https://github.com/open-telemetry/opentelemetry-go/commit/93a693edeed0e07ce5ebd1dfe67af42d1e2055d8) Release v1.45.0 ([#8693](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8693)) * [`c65d435`](https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c) Merge commit from fork * [`223f9fd`](https://github.com/open-telemetry/opentelemetry-go/commit/223f9fdce4e4a85d6ee2155c6a140f236db72c8b) sdk/metric: remove obsolete randomFloat64 TODO ([#8685](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8685)) * [`06272bc`](https://github.com/open-telemetry/opentelemetry-go/commit/06272bc491566efb2c581c8a52e4986cfcccec5b) fix(deps): update googleapis to 6ac0973 ([#8694](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8694)) * [`a4f238f`](https://github.com/open-telemetry/opentelemetry-go/commit/a4f238f57646197d124edcf67baf4cd6ea6d0a9f) chore(deps): update github.com/charmbracelet/ultraviolet digest to 8b69304 (#... * [`37140e7`](https://github.com/open-telemetry/opentelemetry-go/commit/37140e78821d3cb29a33d4b601ca4645b80ceebd) chore(deps): update codspeedhq/action action to v5.0.2 ([#8690](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8690)) * [`cef0855`](https://github.com/open-telemetry/opentelemetry-go/commit/cef0855960bce4385c7d58c40e846573c190d826) chore(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 ([#8689](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8689)) * [`e814a72`](https://github.com/open-telemetry/opentelemetry-go/commit/e814a7281f2d52a6440c3269e139145e62801a16) Merge commit from fork * [`bfd8eb7`](https://github.com/open-telemetry/opentelemetry-go/commit/bfd8eb7f85d3364fdde9ad1a408df98be30acadb) chore(deps): update github.com/golangci/rowserrcheck digest to d2031e3 ([#8687](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8687)) * [`48db2c6`](https://github.com/open-telemetry/opentelemetry-go/commit/48db2c659c3b138f971273cd91ea0bcb647768e1) chore(deps): update github/codeql-action action to v4.37.5 ([#8692](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8692)) * Additional commits viewable in [compare view](https://github.com/open-telemetry/opentelemetry-go/compare/v1.44.0...v1.45.0) Updates `go.opentelemetry.io/otel/metric` from 1.44.0 to 1.45.0 Changelog *Sourced from [go.opentelemetry.io/otel/metric's changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md).* > [1.45.0/0.67.0/0.21.0/0.0.18] - 2026-08-03 > ------------------------------------------ > > ### Added > > * Add experimental observability metrics to `BatchProcessor` in `go.opentelemetry.io/otel/sdk/log`. ([#7124](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/7124)) > * Add the experimental `WithUnsafeAttributes` no-copy attribute option to `go.opentelemetry.io/otel/metric/x` for future performance improvements. This API is a work in progress. ([#8251](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8251)) > * Add `Map` and `MapValue` functions for the new `MAP` attribute type in `go.opentelemetry.io/otel/attribute`. ([#8445](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8445)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlptrace`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlplog`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/zipkin`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Apply `AttributeValueLengthLimit` recursively to values contained in `attribute.MAP` attributes in `go.opentelemetry.io/otel/sdk/trace`. ([#8454](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8454)) > * Remove duplicate keys from `attribute.MAP` values in `go.opentelemetry.io/otel/sdk/resource` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/log` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in span, event, link, and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/trace` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in measurement and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/metric` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Extend `WithAllowKeyDuplication` in `go.opentelemetry.io/otel/sdk/log` to disable duplicate-key removal in `attribute.MAP` values for instrumentation scope attributes. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Add the `go.opentelemetry.io/otel/semconv/v1.42.0` package. > The package contains semantic conventions from the `v1.42.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.42.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.41.0`. ([#8484](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8484)) > * Add `WithoutPanicRecording` as a `TracerProviderOption` in `go.opentelemetry.io/otel/sdk/trace` to disable exception event recording for panics. ([#8532](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8532)) > * Add the `go.opentelemetry.io/otel/semconv/v1.43.0` package. > The package contains semantic conventions from the `v1.43.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.43.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.42.0`. ([#8628](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8628)) > > ### Changed > > * `HistogramReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` now uses a time-unbiased sampling algorithm for exemplars. ([#8306](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8306)) > * ⚠️ **Breaking Change:** Use `go.opentelemetry.io/otel/attribute.Value` and `go.opentelemetry.io/otel/attribute.KeyValue` for log bodies and attributes in `go.opentelemetry.io/otel/log`, `go.opentelemetry.io/otel/log/logtest`, `go.opentelemetry.io/otel/sdk/log`, and `go.opentelemetry.io/otel/sdk/log/logtest`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Encode log bodies and attributes as `go.opentelemetry.io/otel/attribute.Value` JSON in `go.opentelemetry.io/otel/exporters/stdout/stdoutlog`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Improve the performance of hashing `BOOLSLICE`, `INT64SLICE`, `FLOAT64SLICE`, and `STRINGSLICE` attribute values by avoiding reflection for short slices in `go.opentelemetry.io/otel/attribute`. ([#8511](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8511)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_METRICS_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_TRACES_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > > ### Deprecated > > * Deprecate `WithExportBufferSize` in `go.opentelemetry.io/otel/sdk/log`. The option remains available for source compatibility but no longer affects behavior; `BatchProcessor` no longer maintains a separate export-request buffer. ([#8620](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8620)) > > ### Removed > > * ⚠️ **Breaking Change:** Remove `Kind`, `Value`, `KeyValue`, their constructors, and attribute conversion helpers from `go.opentelemetry.io/otel/log`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * ⚠️ **Breaking Change:** Remove the `AttributeValueLengthLimit` and `AttributeCountLimit` fields from `RecordFactory` in `go.opentelemetry.io/otel/sdk/log/logtest`; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. ([#8556](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8556)) > > ### Fixed > > * Apply TLS certificates configured through environment variables to gRPC connections in `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc`. > * Prevent panics in `go.opentelemetry.io/otel/bridge/opentracing` when OpenTracing baggage is propagated concurrently with `Span.SetBaggageItem`. > * Fix an off-by-one error in `FixedSizeReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` that prevented the first exemplar from being sampled after the reservoir was filled. ([#8309](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8309)) > * Interpret HTTP `Retry-After` header values as seconds instead of nanoseconds when retrying OTLP HTTP exports in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp`, `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp`, and `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp`. ([#8383](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8383)) > * Fix a memory leak in the `Reservo... > _Description has been truncated_`
Closes #1168 by taking option 2 (root-cause + re-enable with regression coverage).
Background
(*sequenceDecs).decodeSyncSimplehas hadconst useSafe = truehardcoded since #644 (2022-07-17), so thesequenceDecs_decodeSync_{amd64,bmi2,arm64}asm variants are generated and shipped but never called. #644's comment blames "rare, random crashes with fuzz testing" from the extended (16-byte-block) memory copies.There were two defects, not one
The extended copies overrun the end of a literal run or match by up to 15 bytes by design, relying on correct decoded offsets/lengths and 16 bytes (
compressedBlockOverAlloc) of slack on the output/literal buffers. Two independent bugs could break that contract:1. The bitReader overread (fixed in 2022). An unguarded
bitReaderoverread inupdateLengthproduced out-of-range match offsets/lengths, with only debug-only asserts to catch them. Fixed three days after the disable in #645 (4b4f3c9), which added runtime overread guards and introduced the Go fuzz corpus. This PR's first commit restored the dynamicuseSafeselection on that basis.2. A missing margin in the space check (found and fixed in this PR). The original analysis above missed a case, and this PR's own arm64 CI caught it: a SIGSEGV in
runtime.scanobject— the GC tripping over corrupted heap. The per-sequence space check requires onlyoutPos+ll+ml <= cap(s.out), with no margin for the copies' 15-byte overrun. A well-formed decode ends atcap-16and the overrun lands in slack — but a malformed frame whose declared content size is a few bytes below what its sequences actually produce ends inside the slack: the check passes, and the final block copy writes pastcap(s.out).This, not the overread, is the likely source of #644's "rare, random" crashes: the ≤15-byte overrun lands in size-class slop that neither
-racenor-asanpoisons, so it only intermittently corrupts an adjacent live object and surfaces much later as a GC crash rather than at the faulting write.The fix reserves
compressedBlockOverAllocin the space check on the unsafe path only (oneADDQper unsafe variant; the bounds-exact safe variants keep the tight check). Well-formed streams are unaffected; an over-producing stream now returnserror_not_enough_spaceinstead of corrupting memory.Regression coverage
TestDecodeSyncUnsafeOOB— the guard that actually catches this class. It drives the unsafe asm with real captured sequences into a canary-guarded buffer carved from a larger backing array, sized to model the under-reporting case, and asserts (via the extracteduseSafeDecodeSync()helper) that the unsafe variant is really selected. It fails on the unpatched assembly (canary overwritten pastcap) and passes with the fix, on amd64 and arm64.fuzz-zstd-asanCI job (CGO+clang, amd64+arm64) overFuzzDecodeAll/FuzzDecAllNoBMI2. Caveat learned the hard way: asan does not see sub-size-class slice overruns (they land in unpoisoned slop), so it guards gross overruns and allocation regressions, not this ≤15-byte class — that's what the canary test is for.Validation (amd64 + arm64/Cortex-A72, go1.25 + go1.26)
zstdtest suite, all build-tag combos, both architectures.-tags=nounsafe).Performance
BenchmarkDecoder_DecodeAllon arm64 (Cortex-A72), n=6, p=0.002:Summary by CodeRabbit
decodeSyncsafety by dynamically selecting between safer and optimized copy behavior based on output/literals geometry.