Skip to content

span: preserve unknown int32 status codes and bump to v0.7.3 - #100

Open
edsiper wants to merge 1 commit into
masterfrom
fix/preserve-unknown-span-status
Open

edsiper wants to merge 1 commit into
masterfrom
fix/preserve-unknown-span-status

Conversation

@edsiper

@edsiper edsiper commented Sep 30, 2026

Copy link
Copy Markdown
Member

a049bdf restricted span status codes to 0–2. After Fluent Bit imported CTraces v0.7.2, OTLP Protobuf ingestion rejected received statuses such as INT32_MIN, -1, 3, and INT32_MAX. This change preserves all signed 32-bit status codes and their messages through updates and forwarding, while retaining null checks, allocation failure atomicity, decoder limits, int32 type/range validation, and cleanup.

The OTLP schema defines Unset (0), Ok (1), and Error (2), but uses proto3. Proto3 enums are open and preserve unknown enum integers. These transport requirements are distinct from the instrumentation API's status and description rules; received telemetry is preserved rather than rewritten using instrumentation semantics.

Changes:

  • Remove the semantic-code whitelist from the setter and MessagePack decoder; retain int32 validation and allocate-before-replace behavior.
  • Audit the pinned Protobuf bindings and codecs: Protobuf and MessagePack encode numeric status values directly. There is no standalone JSON codec or text decoder. Preserve full messages in text output using the existing SDS formatter, fixing fixed-buffer truncation.
  • Replace the obsolete status-3 rejection expectation with coverage for known/unknown statuses, signed boundaries, null/empty/long messages, self-assignment, repeated updates, forwarding through both formats, malformed/out-of-range MessagePack input, and recovery after rejection.
  • Add Linux GNU/Clang allocation fault injection for the setter, both decoders, and Protobuf status encoding, with cleanup/recovery assertions.
  • Bump CMakeLists.txt from 0.7.2 to 0.7.3. Public signatures, struct layouts, status constants, and wire fields are unchanged.

Validation:

  • Regression first reproduced against the previous production code: status 3 rejected and long status messages truncated in text.
  • scripts/agent-test.sh -R 'ctr-test-(span|status|decoding|opentelemetry|protobuf)': 5/5 passed.
  • scripts/agent-verify.sh: 7/7 passed, including shell syntax checks, after the version bump.
  • Valgrind 3.23.0 on ctr-test-{status,span,decoding,opentelemetry,protobuf} with --no-exec --leak-check=full --show-leak-kinds=all --errors-for-leak-kinds=all --error-exitcode=99 --track-origins=yes: all passed; zero errors and zero bytes left allocated.
  • Clang 18.1.3 with -fsanitize=address,undefined -fno-sanitize=function -fno-omit-frame-pointer; leak detection and halt-on-error enabled: 7/7 passed. CTR_BUILD_DIR=build/status-asan scripts/agent-verify.sh also passed after the version bump.
  • git diff --check: passed.

Strict Clang function-type UBSan is blocked by existing mismatched callback types: protobuf-c.c:3416 invokes generated typed initializers through void (*)(ProtobufCMessage *), and older test functions trigger the check at Acutest's callback invocation. A direct strict run of the new status test reproduced the dependency finding. Only function-type instrumentation was disabled for the successful sanitizer run; dependency sources were left untouched.

Fluent Bit's bundled copy was not modified, and consumer integration tests were not run. Fluent Bit should vendor this CTraces correction; its JSON caller changes and downstream interoperability validation remain separate consumer work.

Preserve proto3 open enum integers and received status messages through the setter and MessagePack decoder without weakening allocation or input validation. Cover cross-format forwarding, int32 boundaries, malformed inputs, and allocation failure recovery. Avoid truncating long status messages in text output and bump the patch version to 0.7.3.

Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant