Skip to content

chore(deps): bump crossbeam-epoch to 0.9.20 for RUSTSEC-2026-0204 - #2038

Merged
gh-worker-dd-mergequeue-cf854d[bot] merged 1 commit into
mainfrom
jszwedko/bump-crossbeam-epoch
Jul 6, 2026
Merged

chore(deps): bump crossbeam-epoch to 0.9.20 for RUSTSEC-2026-0204#2038
gh-worker-dd-mergequeue-cf854d[bot] merged 1 commit into
mainfrom
jszwedko/bump-crossbeam-epoch

Conversation

@jszwedko

@jszwedko jszwedko commented Jul 6, 2026

Copy link
Copy Markdown
Collaborator

Summary

crossbeam-epoch 0.9.18 is flagged by RUSTSEC-2026-0204 — an invalid pointer dereference in the fmt::Pointer impl for Atomic/Shared — which fails check-deny on main (and every release branch carrying the same lockfile entry). This bumps it to 0.9.20, a semver-compatible, lockfile-only update.

Test plan

  • make check-deny passes (advisories: 0 errors).

🤖 Generated with Claude Code

crossbeam-epoch 0.9.18 is flagged by RUSTSEC-2026-0204 (invalid pointer
dereference in the fmt::Pointer impl for Atomic/Shared), failing check-deny.
Bump to 0.9.20, a semver-compatible lockfile-only update.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
@jszwedko
jszwedko requested a review from a team as a code owner July 6, 2026 22:40
This was referenced Jul 6, 2026
@pr-commenter

pr-commenter Bot commented Jul 6, 2026

Copy link
Copy Markdown

Binary Size Analysis (Agent Data Plane)

Baseline: f841338 · Comparison: 2c4784d · diff
Analysis Configuration: stripped binaries · Pass/Fail Threshold: +5%
Sizes: 41.59 MiB (baseline) vs 41.58 MiB (comparison)
Size Change: -6.23 KiB (-0.01%)

✅ Binary size difference within threshold

Changes by Module
Module File Size Symbols
core -15.39 KiB 15706
anon.d35bf39ab8c1a6f621834974fe00c369.0.llvm.18152056829563145063 -9.82 KiB 1
anon.be335b4178c675fc5a781e0038551649.10.llvm.7165110530784916814 +9.73 KiB 1
anon.cb1c7a03f5127e535d16c7a29d228157.350.llvm.2382326088780022718 -8.04 KiB 1
anon.2c699cd2bc375ec6bf1e76cf38ba4c28.127.llvm.16766060192987788512 +8.03 KiB 1
hashbrown -4.43 KiB 1577
anon.e47cdb04075bf925ec7a3615d2843456.209.llvm.8867417804926716551 -4.30 KiB 1
anon.62b1870d645ed7c8303ed1d921763efa.30.llvm.11853482047238330255 +4.30 KiB 1
anon.403feca523e520f7eda92afc23d1934b.42.llvm.14669999808706122602 +4.17 KiB 1
anon.122d08581a1227880b36542f3c021e03.7.llvm.16111821345713007611 -4.16 KiB 1
anon.44f086e97dad6c4e56580257a2d83ed3.1033.llvm.5606743650612900122 +3.98 KiB 1
alloc +3.89 KiB 2956
anon.f05579d214bd720560ee0207fdeaa44b.110.llvm.10277623636693697842 -3.89 KiB 1
anon.7dd07664c190a378f94d2ce314773356.157.llvm.16684009593226997390 +3.78 KiB 1
anon.8dc588bb37061571a41a5004abbad7c7.404.llvm.15392843726178276514 -3.78 KiB 1
saluki_io::net::client +3.73 KiB 98
saluki_io::net::util -3.65 KiB 176
anon.919fffbe4b4f9b04e9cca685c2af340b.292.llvm.10468395429607765463 -3.37 KiB 1
anon.ef9645ef2105b3ddfb9b52be71e5aeaa.292.llvm.6369597819485409528 +3.37 KiB 1
anon.45595fb42bd516485df2a7ac4f012d3d.2.llvm.14894368341491595010 +3.05 KiB 1
Detailed Symbol Changes
    FILE SIZE        VM SIZE    
 --------------  -------------- 
  [NEW] +56.8Ki  [NEW] +56.7Ki    saluki_components::common::datadog::io::run_endpoint_io_loop::_{{closure}}::h95c7bd1d8b1af8e3
  [NEW] +50.9Ki  [NEW] +50.8Ki    agent_data_plane::cli::run::handle_run_command::_{{closure}}::h3fdfe4a2e102559b
  [NEW] +38.4Ki  [NEW] +38.2Ki    _<saluki_components::forwarders::otlp::OtlpForwarder as saluki_core::components::forwarders::Forwarder>::run::_{{closure}}::ha61624e7981c520a
  [NEW] +32.2Ki  [NEW] +32.0Ki    agent_data_plane::internal::env::workload::RemoteAgentWorkloadProvider::from_configuration::_{{closure}}::hf78409ceae4e4460
  [NEW] +29.8Ki  [NEW] +29.7Ki    agent_data_plane::cli::dogstatsd::handle_dogstatsd_command::_{{closure}}::h3ce4b80ccbb18329
  [NEW] +29.0Ki  [NEW] +28.8Ki    saluki_components::sources::otlp::metrics::translator::OtlpMetricsTranslator::translate_metrics::hfbcf00b04bd2e4ac
  [NEW] +28.5Ki  [NEW] +28.3Ki    _<saluki_components::transforms::aggregate::Aggregate as saluki_core::components::transforms::Transform>::run::_{{closure}}::he88e3023b962ccbd
  [NEW] +28.4Ki  [NEW] +28.1Ki    _<saluki_components::sources::dogstatsd::_::<impl serde_core::de::Deserialize for saluki_components::sources::dogstatsd::DogStatsDConfiguration>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::h4c49c37c7ea42162
  [NEW] +27.4Ki  [NEW] +27.3Ki    agent_data_plane::cli::run::create_topology::_{{closure}}::hd787758920181c28
  [NEW] +26.2Ki  [NEW] +26.0Ki    saluki_components::sources::dogstatsd::drive_stream::_{{closure}}::ha68c2a5c2faedfff
  -0.0% -6.02Ki  -0.0% -2.72Ki    [55104 Others]
  [DEL] -26.1Ki  [DEL] -26.0Ki    saluki_components::sources::dogstatsd::drive_stream::_{{closure}}::hf2a7285100794345
  [DEL] -27.4Ki  [DEL] -27.3Ki    agent_data_plane::cli::run::create_topology::_{{closure}}::h6f97e85962982383
  [DEL] -28.4Ki  [DEL] -28.1Ki    _<saluki_components::sources::dogstatsd::_::<impl serde_core::de::Deserialize for saluki_components::sources::dogstatsd::DogStatsDConfiguration>::deserialize::__Visitor as serde_core::de::Visitor>::visit_map::hfc578ba92a99992a
  [DEL] -28.5Ki  [DEL] -28.3Ki    _<saluki_components::transforms::aggregate::Aggregate as saluki_core::components::transforms::Transform>::run::_{{closure}}::h72e4b09fd816d94f
  [DEL] -29.0Ki  [DEL] -28.9Ki    saluki_components::sources::otlp::metrics::translator::OtlpMetricsTranslator::translate_metrics::hf07d893fd553f53b
  [DEL] -29.8Ki  [DEL] -29.7Ki    agent_data_plane::cli::dogstatsd::handle_dogstatsd_command::_{{closure}}::h84db3f7ad161eab2
  [DEL] -32.2Ki  [DEL] -32.0Ki    agent_data_plane::internal::env::workload::RemoteAgentWorkloadProvider::from_configuration::_{{closure}}::h8f52da0975f9b0ef
  [DEL] -38.3Ki  [DEL] -38.1Ki    _<saluki_components::forwarders::otlp::OtlpForwarder as saluki_core::components::forwarders::Forwarder>::run::_{{closure}}::h3cd6ee67f0471508
  [DEL] -50.9Ki  [DEL] -50.8Ki    agent_data_plane::cli::run::handle_run_command::_{{closure}}::h83501a7881036c5f
  [DEL] -57.1Ki  [DEL] -57.0Ki    saluki_components::common::datadog::io::run_endpoint_io_loop::_{{closure}}::h54fbb73bb30184e6
  -0.0% -6.23Ki  -0.0% -2.93Ki    TOTAL

@pr-commenter

pr-commenter Bot commented Jul 6, 2026

Copy link
Copy Markdown

Regression Detector (Agent Data Plane)

Run ID: bf92a1e8-d2b5-4174-affd-80af84efe30f
Baseline: f841338f · Comparison: 2c4784d6 · diff

Optimization Goals: ✅ No significant changes detected

Fine details of change detection per experiment (5)

Experiments configured erratic: true are tagged (ignored) and skipped when determining which experiments regressed or improved. Experiments which are detected as erratic at runtime are tagged (erratic) to flag that the run's sample dispersion was high, but their regression / improvement signal still counts.

experiment goal Δ mean % links
quality_gates_rss_dsd_ultraheavy memory ⚪ +0.16 metrics profiles logs
quality_gates_rss_dsd_heavy memory ⚪ +0.15 metrics profiles logs
quality_gates_rss_idle memory ⚪ +0.11 metrics profiles logs
quality_gates_rss_dsd_low memory ⚪ -0.17 metrics profiles logs
quality_gates_rss_dsd_medium memory ⚪ -0.48 metrics profiles logs
Bounds Checks: ✅ Passed (5)
experiment check replicates observed links
quality_gates_rss_dsd_heavy memory_usage 10/10 ✅ 132 MiB ≤ 140 MiB metrics profiles logs
quality_gates_rss_dsd_low memory_usage 10/10 ✅ 43.2 MiB ≤ 50 MiB metrics profiles logs
quality_gates_rss_dsd_medium memory_usage 10/10 ✅ 64.8 MiB ≤ 75 MiB metrics profiles logs
quality_gates_rss_dsd_ultraheavy memory_usage 10/10 ✅ 192 MiB ≤ 200 MiB metrics profiles logs
quality_gates_rss_idle memory_usage 10/10 ✅ 29.1 MiB ≤ 40 MiB metrics profiles logs
Explanation

A change is flagged as a regression when |Δ mean %| > 5.00% in the regressing direction for its optimization goal AND SMP marks the experiment as a regression (is_regression: true). Improvements use the matching criteria for the improving direction. Experiments configured erratic: true (tagged (ignored)) are skipped outright; experiments detected as erratic at runtime (tagged (erratic)) still count, since that flag describes sample dispersion rather than directional certainty. The Δ mean % cell is colored accordingly: 🟢 = improvement, 🔴 = regression, ⚪ = neutral. Reduction in CPU or memory is an improvement; reduction in ingress throughput is a regression.

@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot merged commit 437cfc2 into main Jul 6, 2026
85 checks passed
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot deleted the jszwedko/bump-crossbeam-epoch branch July 6, 2026 23:27
gh-worker-dd-mergequeue-cf854d Bot pushed a commit that referenced this pull request Jul 7, 2026
## Summary

Release-prep PR for **ADP 1.2.3** on `releases/1.2.x`. Bumps the version and bundles four fixes. Because 1.2.x is on Rust 1.96.0 (same as `main`), the `fetch_update` fix could be cherry-picked directly rather than needing the `#[allow(deprecated)]` workaround used on 1.1.0.

1. **Honor `site` when `dd_url` equals the default-derived URL** — corresponds to #2028 (`7ec65f2`). The Core Agent's config stream sends `dd_url` at its schema default (`https://app.datadoghq.com`) for every configuration, even when the operator only set `site`, so ADP routed all traffic to the US1 intake and `site` was effectively ignored (#1965). A `dd_url` equal to the default-derived URL is now filtered to `None` at deserialization, letting `site` determine the endpoint. `set_dd_url` bypasses serde and is unaffected. Adapted to the 1.2.x code (no `configured_primary_endpoint`), so the change is confined to the `dd_url` deserializer plus tests.

2. **Unblock the nightly `generate-api-docs` build** — cherry-pick of #2007 (`917e05f`). Newer nightly toolchains deprecate `Atomic*::fetch_update`; under `#![deny(warnings)]`, `cargo +nightly doc` turns that into a hard error. Since 1.2.x uses the 1.96.0 toolchain (where `try_update` is stable), the three call sites switch to `try_update`, matching `main`. (The `fixed_size.rs` hunk from the original commit was dropped — that method doesn't exist on 1.2.x and has no `fetch_update` to fix.)

3. **Update `anyhow`** — cherry-pick of #1945 (`bc51393`). Bumps `anyhow` 1.0.102 → 1.0.103 in `Cargo.lock` to unblock `check deny`. (The `2a7be76` hash is the gh-pages docs artifact for that PR; `bc51393` is the source commit.)

4. **Bump `crossbeam-epoch` to 0.9.20** — fresh fix for RUSTSEC-2026-0204. `crossbeam-epoch 0.9.18` (an invalid pointer dereference in the `fmt::Pointer` impl for `Atomic`/`Shared`) fails `check-deny`. This is a repo-wide issue; the equivalent fix for `main` is #2038. Applied directly here (semver-compatible, lockfile-only bump) rather than cherry-picked, since it landed on the release branches in parallel with the main PR.

Plus a `chore(dev): Bump ADP to 1.2.3` commit updating `bin/agent-data-plane/Cargo.toml` and the lockfile.

## Test plan

- New unit tests for the `dd_url`/`site` resolution (default filtered → `None`; explicit override wins; `set_dd_url` never filtered; end-to-end `build_primary_endpoint` for both cases).
- `make check-deny` passes with the crossbeam-epoch bump.
- `cargo check` passes for the affected crates on the pinned `1.96.0` toolchain, including the `try_update` call sites.

Fixes #1965.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: webern <matt.briggs@datadoghq.com>
Co-authored-by: jesse.szwedko <jesse.szwedko@datadoghq.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants