Skip to content

Restore decoder hardening and fix attribute units, packaging, and action pins - #34

Merged
edsiper merged 4 commits into
masterfrom
fix/review-codecs-packaging-actions
Sep 21, 2026
Merged

edsiper merged 4 commits into
masterfrom
fix/review-codecs-packaging-actions

Conversation

@edsiper

@edsiper edsiper commented Sep 20, 2026

Copy link
Copy Markdown
Member

Summary

Restore decoder checks missing from the compiled src/ implementations: reject null OTLP arguments and offsets beyond the input buffer before unpacking, and reject MessagePack binary lengths above the former 1 KiB limit before allocating. Resolve attribute units by their referenced string-table key, so sparse or reordered unit lists cannot assign units to the wrong attributes.

Fix standalone packaging by installing the generated public headers under CPROF_INSTALL_INCLUDEDIR and using the defined CPROF_VERSION_STR for CPack metadata. Pin the requested checkout, run-on-arch-action, and action-gh-release references to full commit SHAs matching their existing versions.

Regression tests cover invalid decoder arguments, binary-length boundaries, and sparse/reordered attribute units with invalid indexes. They reproduce the failures against the original implementations and pass with these fixes.

Validation

  • ./scripts/agent-verify.sh: all four CTest executables pass on the final PR branch.
  • Both codec test executables pass Valgrind with --leak-check=full --show-leak-kinds=all --errors-for-leak-kinds=all --error-exitcode=99.
  • cpack -G DEB: packages use the declared project version (0.2.1 on upstream master); the headers package contains both generated headers. A consumer compiled, linked, and ran against a staged installation.
  • actionlint -shellcheck= .github/workflows/build.yaml .github/workflows/packages.yaml .github/workflows/lint.yaml and git diff --check pass.
  • Fluent Bit b3d0bc46fe117cce15b8b5916379b771adc7ab4d builds with profiles enabled and the patched CProfiles code in an isolated worktree. Both flb-rt-in_opentelemetry and flb-rt-in_opentelemetry_routing pass.
  • Fluent Bit's pytest scenarios/in_forward/tests/test_in_forward_001.py -k profiles -q passes all three cases normally and with VALGRIND=1 VALGRIND_STRICT=1.
  • A temporary native-profile integration test passes normally and under strict Valgrind, preserving profile IDs, timestamps, sample attributes, and units through OTLP input → internal MessagePack → OTLP output. Its Sample field numbers match the pinned C protobuf bindings.

Compatibility and known limitations

No public API signatures, structure layouts, wire schemas, or dependency revisions change. Correct unit values are emitted; binary MessagePack fields over 1 KiB are rejected, restoring Fluent Bit's pre-upgrade limit.

Fluent Bit's internal OpenTelemetry suite passes 21/22 cases. opentelemetry_traces_otlp_json_roundtrip fails identically after rebuilding with the original CProfiles codec sources, confirming an existing failure. CPack also retains an existing warning about missing debian/conffiles, although both DEB packages are generated. Windows, macOS, RPM packaging, and hosted Actions were not run locally.

@edsiper
edsiper marked this pull request as ready for review September 21, 2026 02:05
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T02:09:10.067649Z 646d3c4 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 646d3c45a7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/cprof_encode_opentelemetry.c
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
@edsiper
edsiper force-pushed the fix/review-codecs-packaging-actions branch from 27ad6e0 to 7b3cfee Compare September 21, 2026 02:10
Match units by key occurrence so repeated dictionary entries retain their own units during OTLP round trips. Keep sparse and reordered key handling and cover sample references to repeated keys with distinct values and units.

Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
@edsiper
edsiper merged commit 02c0cbd into master Sep 21, 2026
20 of 21 checks passed
@edsiper
edsiper deleted the fix/review-codecs-packaging-actions branch September 21, 2026 02:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant