Repository navigation
Restore decoder hardening and fix attribute units, packaging, and action pins - #34
Merged
Merged
Conversation
edsiper
marked this pull request as ready for review
September 21, 2026 02:05
edsiper
requested review from
celalettin1286,
niedbalski and
patrick-stephens
as code owners
September 21, 2026 02:05
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 646d3c45a7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
edsiper
force-pushed
the
fix/review-codecs-packaging-actions
branch
from
September 21, 2026 02:10
27ad6e0 to
7b3cfee
Compare
Match units by key occurrence so repeated dictionary entries retain their own units during OTLP round trips. Keep sparse and reordered key handling and cover sample references to repeated keys with distinct values and units. Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Restore decoder checks missing from the compiled
src/implementations: reject null OTLP arguments and offsets beyond the input buffer before unpacking, and reject MessagePack binary lengths above the former 1 KiB limit before allocating. Resolve attribute units by their referenced string-table key, so sparse or reordered unit lists cannot assign units to the wrong attributes.Fix standalone packaging by installing the generated public headers under
CPROF_INSTALL_INCLUDEDIRand using the definedCPROF_VERSION_STRfor CPack metadata. Pin the requested checkout, run-on-arch-action, and action-gh-release references to full commit SHAs matching their existing versions.Regression tests cover invalid decoder arguments, binary-length boundaries, and sparse/reordered attribute units with invalid indexes. They reproduce the failures against the original implementations and pass with these fixes.
Validation
./scripts/agent-verify.sh: all four CTest executables pass on the final PR branch.--leak-check=full --show-leak-kinds=all --errors-for-leak-kinds=all --error-exitcode=99.cpack -G DEB: packages use the declared project version (0.2.1 on upstream master); the headers package contains both generated headers. A consumer compiled, linked, and ran against a staged installation.actionlint -shellcheck= .github/workflows/build.yaml .github/workflows/packages.yaml .github/workflows/lint.yamlandgit diff --checkpass.b3d0bc46fe117cce15b8b5916379b771adc7ab4dbuilds with profiles enabled and the patched CProfiles code in an isolated worktree. Bothflb-rt-in_opentelemetryandflb-rt-in_opentelemetry_routingpass.pytest scenarios/in_forward/tests/test_in_forward_001.py -k profiles -qpasses all three cases normally and withVALGRIND=1 VALGRIND_STRICT=1.Compatibility and known limitations
No public API signatures, structure layouts, wire schemas, or dependency revisions change. Correct unit values are emitted; binary MessagePack fields over 1 KiB are rejected, restoring Fluent Bit's pre-upgrade limit.
Fluent Bit's internal OpenTelemetry suite passes 21/22 cases.
opentelemetry_traces_otlp_json_roundtripfails identically after rebuilding with the original CProfiles codec sources, confirming an existing failure. CPack also retains an existing warning about missingdebian/conffiles, although both DEB packages are generated. Windows, macOS, RPM packaging, and hosted Actions were not run locally.