archive: resolve absolute hardlink targets within extraction root (fixes #99) - #100
Conversation
The CVE-2026-17106 hardening rejects hardlink entries whose target is an absolute path. Some image builders (e.g. kaniko) write hardlink targets as absolute paths, so layers of such images fail to extract with "invalid hardlink target" since v0.3.0 (Docker 29.7.0). Resolve absolute hardlink targets relative to the extraction root with chroot-like semantics, matching how absolute symlink targets are handled since 4f6cd58 and how pre-v0.3.0 extraction behaved. The root is stripped from the original linkname rather than the cleaned one, so targets like "/../victim" are not collapsed against "/" but keep failing the filepath.IsLocal check, and the resolved target then passes through resolveArchivePath confined to the os.Root extraction root. Signed-off-by: Yannik Sembritzki <yannik@sembritzki.org>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #100 +/- ##
==========================================
- Coverage 65.81% 65.27% -0.54%
==========================================
Files 42 44 +2
Lines 2039 2327 +288
==========================================
+ Hits 1342 1519 +177
- Misses 519 595 +76
- Partials 178 213 +35 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
| func TestUntarAbsoluteHardlink(t *testing.T) { | ||
| dest := t.TempDir() | ||
|
|
||
| var buf bytes.Buffer | ||
| tw := tar.NewWriter(&buf) | ||
| assert.NilError(t, tw.WriteHeader(&tar.Header{ |
There was a problem hiding this comment.
Maybe we could use a table-test for this one, so that we can add other cases; asked my LLM to produce some that could be interesting;
/usr/bin/foo -> usr/bin/foo
//usr/bin/foo -> usr/bin/foo
/../victim -> reject
/foo/../../victim -> reject
/ -> reject
../victim -> reject
There was a problem hiding this comment.
🟢 Ready to approve
The change aligns hardlink handling with existing absolute-path semantics for entries and symlinks while maintaining containment guarantees, and includes a targeted regression test.
This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.
Pull request overview
This PR restores compatibility with container images that encode hardlink targets as absolute paths by resolving those targets relative to the extraction root (chroot-like semantics), while preserving existing safety checks to prevent path escapes.
Changes:
- Update hardlink-target resolution to accept absolute POSIX targets by stripping the leading
/from the original linkname before validation. - Add a regression test ensuring absolute hardlink targets extract correctly and produce a real hardlink (same inode).
File summaries
| File | Description |
|---|---|
| archive.go | Resolves absolute hardlink targets relative to the extraction root while still rejecting escape attempts via filepath.IsLocal and resolveArchivePath. |
| archive_test.go | Adds coverage for extracting an absolute hardlink target and verifying it results in a true hardlink. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Lite
We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.
…p ci] Bumps the go-modules group in /e2e-go with 6 updates: | Package | From | To | | --- | --- | --- | | [github.com/klauspost/compress](https://github.com/klauspost/compress) | `1.19.1` | `1.19.2` | | [github.com/moby/go-archive](https://github.com/moby/go-archive) | `0.3.2` | `0.3.3` | | [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp](https://github.com/open-telemetry/opentelemetry-go-contrib) | `0.69.0` | `0.70.0` | | [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | | [go.opentelemetry.io/otel/metric](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | | [go.opentelemetry.io/otel/trace](https://github.com/open-telemetry/opentelemetry-go) | `1.44.0` | `1.45.0` | Updates `github.com/klauspost/compress` from 1.19.1 to 1.19.2 Release notes *Sourced from [github.com/klauspost/compress's releases](https://github.com/klauspost/compress/releases).* > v1.19.2 > ------- > > What's Changed > -------------- > > * huff0: add arm64 assembly for Decompress4X/1X via avo lowering by [`@lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1172](https://redirect.github.com/klauspost/compress/pull/1172) > * zstd: Re-enable unsafe decodeSync memory copies ([#1168](https://redirect.github.com/klauspost/compress/issues/1168)) by [`@lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1171](https://redirect.github.com/klauspost/compress/pull/1171) > * zstd: fix arm64 asm frame offsets placing locals on the saved LR slot by [`@lizthegrey`](https://github.com/lizthegrey) in [klauspost/compress#1176](https://redirect.github.com/klauspost/compress/pull/1176) > * zstd: avoid racing MaxDecodedSize write on shared dict litEnc by [`@zanarellidev`](https://github.com/zanarellidev) in [klauspost/compress#1182](https://redirect.github.com/klauspost/compress/pull/1182) > * zstd: keep BuildDict recent-offsets positive and loadable by [`@zanarellidev`](https://github.com/zanarellidev) in [klauspost/compress#1184](https://redirect.github.com/klauspost/compress/pull/1184) > * zstd: handle zero-literal BuildDict corpus by [`@cyphercodes`](https://github.com/cyphercodes) in [klauspost/compress#1178](https://redirect.github.com/klauspost/compress/pull/1178) > * zstd: don't clear the registered dictionary when decoding past the window by [`@sueun-dev`](https://github.com/sueun-dev) in [klauspost/compress#1177](https://redirect.github.com/klauspost/compress/pull/1177) > > New Contributors > ---------------- > > * [`@zanarellidev`](https://github.com/zanarellidev) made their first contribution in [klauspost/compress#1183](https://redirect.github.com/klauspost/compress/pull/1183) > * [`@cyphercodes`](https://github.com/cyphercodes) made their first contribution in [klauspost/compress#1178](https://redirect.github.com/klauspost/compress/pull/1178) > * [`@sueun-dev`](https://github.com/sueun-dev) made their first contribution in [klauspost/compress#1177](https://redirect.github.com/klauspost/compress/pull/1177) > > **Full Changelog**: <https://github.com/klauspost/compress/compare/v1.19.1...v1.19.2> Commits * [`c3b3439`](https://github.com/klauspost/compress/commit/c3b3439a48196b5082c63252bfb8633d0a2faad4) zstd: don't clear the registered dictionary when decoding past the window ([#1](https://redirect.github.com/klauspost/compress/issues/1)... * [`9874bc9`](https://github.com/klauspost/compress/commit/9874bc9073f350ce462becb84f9a23c3e828d03f) fix(zstd): handle zero-literal BuildDict corpus ([#1178](https://redirect.github.com/klauspost/compress/issues/1178)) * [`71bb6fd`](https://github.com/klauspost/compress/commit/71bb6fd9ddbfbb2ca6612542a916c766a866bfb3) zstd: keep BuildDict recent-offsets positive and loadable ([#1184](https://redirect.github.com/klauspost/compress/issues/1184)) * [`3d4dacb`](https://github.com/klauspost/compress/commit/3d4dacbaa9faca75caacc35b6d75731a81a92c6b) zstd: avoid racing MaxDecodedSize write on shared dict litEnc ([#1182](https://redirect.github.com/klauspost/compress/issues/1182)) * [`3ceaa81`](https://github.com/klauspost/compress/commit/3ceaa81409aabe39c71821b936155b33471c78d8) build(deps): bump the github-actions group with 5 updates ([#1185](https://redirect.github.com/klauspost/compress/issues/1185)) * [`72cb4d3`](https://github.com/klauspost/compress/commit/72cb4d3e8e743bea5d1ba40896ad55214a1844e4) chore: add OpenSSF Scorecard GitHub Action ([#1183](https://redirect.github.com/klauspost/compress/issues/1183)) * [`69c9db4`](https://github.com/klauspost/compress/commit/69c9db420ae55bfcdfbef564805e2646206545f7) zstd: fix arm64 asm locals overwriting the saved link register ([#1176](https://redirect.github.com/klauspost/compress/issues/1176)) * [`117430d`](https://github.com/klauspost/compress/commit/117430d3b0e3c39c14d32fe7c90652149a78e609) zstd: Re-enable unsafe decodeSync memory copies ([#1168](https://redirect.github.com/klauspost/compress/issues/1168)) ([#1171](https://redirect.github.com/klauspost/compress/issues/1171)) * [`c73af0c`](https://github.com/klauspost/compress/commit/c73af0c12cc767386af8388f30d5aa7428e6dfc8) huff0: add arm64 assembly for Decompress4X/1X via avo lowering ([#1172](https://redirect.github.com/klauspost/compress/issues/1172)) * See full diff in [compare view](https://github.com/klauspost/compress/compare/v1.19.1...v1.19.2) Updates `github.com/moby/go-archive` from 0.3.2 to 0.3.3 Release notes *Sourced from [github.com/moby/go-archive's releases](https://github.com/moby/go-archive/releases).* > v0.3.3 > ------ > > What's Changed > -------------- > > * Fix a regression introduced in v0.3.0 that caused archive extraction to reject hardlinks with absolute targets, as produced by > some image builders. Absolute hardlink targets are now resolved relative to the extraction root, while paths that escape the root > remain rejected. [moby/go-archive#100](https://redirect.github.com/moby/go-archive/pull/100) > * Fix a regression introduced in v0.3.0 that caused archive extraction to fail when applying permissions to device nodes, including > nodes on `nodev` filesystems and `dev/ptmx`. Device nodes are now referenced without opening the underlying device before applying > their mode. [moby/go-archive#103](https://redirect.github.com/moby/go-archive/pull/103) > * Set close-on-exec on file descriptors used by the Linux permission fallback to prevent them from leaking into child processes. > [moby/go-archive#104](https://redirect.github.com/moby/go-archive/pull/104) > > **Full Changelog**: <https://github.com/moby/go-archive/compare/v0.3.2...v0.3.3> Commits * [`ae9e219`](https://github.com/moby/go-archive/commit/ae9e219f7104d91e262055a29bae1f9753106981) Merge pull request [#104](https://redirect.github.com/moby/go-archive/issues/104) from thaJeztah/use\_O\_CLOEXEC * [`98ff1da`](https://github.com/moby/go-archive/commit/98ff1dac11141c20bf7975ee1243fbe5031c2684) archive: set close-on-exec for chmod fallback descriptors * [`1e8dfbc`](https://github.com/moby/go-archive/commit/1e8dfbc6ec14614f009716c5ec04b6d104168201) Merge pull request [#103](https://redirect.github.com/moby/go-archive/issues/103) from thaJeztah/fix\_chmod\_fallback * [`e738eed`](https://github.com/moby/go-archive/commit/e738eed524c260a613bea37a47349e0f7d0a45a6) archive: keep procfs file alive during fchmodat * [`2d863f5`](https://github.com/moby/go-archive/commit/2d863f57793b7e2340cfca8f9a94a2d55cf7e68e) archive: preserve procfs access during chroot extraction * [`89653ed`](https://github.com/moby/go-archive/commit/89653edcda61f24e83ae2aa485f57cf762c59568) archive: fix chmod fallback for device nodes on nodev mounts * [`f37d413`](https://github.com/moby/go-archive/commit/f37d413855106b6c4f5cc3c063013869b6294e7d) Merge pull request [#106](https://redirect.github.com/moby/go-archive/issues/106) from thaJeztah/fallback\_no\_read * [`4ffc915`](https://github.com/moby/go-archive/commit/4ffc91517ffd9b77b11efd91768b5d6d4303a3b6) archive: test chmod fallback without read permission * [`9af1c40`](https://github.com/moby/go-archive/commit/9af1c40d9b972e82affd0b3ed3beb3f5d4d5f5d2) Merge pull request [#105](https://redirect.github.com/moby/go-archive/issues/105) from thaJeztah/test\_chrooted\_chmod\_fallback * [`3daca2a`](https://github.com/moby/go-archive/commit/3daca2abcac72471e1424cc840e7c5711937ade9) archive: test chmod fallback without procfs in chroot * Additional commits viewable in [compare view](https://github.com/moby/go-archive/compare/v0.3.2...v0.3.3) Updates `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` from 0.69.0 to 0.70.0 Release notes *Sourced from [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp's releases](https://github.com/open-telemetry/opentelemetry-go-contrib/releases).* > Release v1.45.0/v2.5.2/v0.70.0/v0.37.2/v0.25.0/v0.20.0/v0.16.2/v0.17.0 > ---------------------------------------------------------------------- > > Overview > -------- > > ### Added > > * Add `go.opentelemetry.io/contrib/detectors/ibmcloud/vpc`, a new resource detector for IBM Cloud VPC virtual server instances, ported from `github.com/open-telemetry/opentelemetry-collector-contrib/processor/resourcedetectionprocessor/internal/ibmcloud/vpc`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `cloud.availability_zone`, `cloud.account.id`, `cloud.resource_id`, `host.id`, `host.image.id`, `host.image.name`, `host.name`, and `host.type`. ([#9011](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9011)) > * Add `go.opentelemetry.io/contrib/detectors/k8sapi`, a new resource detector that queries the Kubernetes API. Detects `k8s.node.name` and `k8s.node.uid` when `K8S_NODE_NAME` is set via the downward API, and `k8s.cluster.uid` derived from the kube-system namespace UID (works on any Kubernetes distribution). ([#9108](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9108)) > * Add new `elasticbeanstalk` resource detector for AWS Elastic Beanstalk, ported from `processor/resourcedetectionprocessor/internal/aws/elasticbeanstalk` in opentelemetry-collector-contrib. ([#8993](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8993)) > * The resource created by `go.opentelemetry.io/contrib/otelconf` now includes [default SDK attributes](https://pkg.go.dev/go.opentelemetry.io/otel/sdk/resource#Default). ([#8990](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8990)) > * Add support for the `aws.ecs` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#8915](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8915)) > * Add support for the `aws.eks` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9138](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9138)) > * Add support for the `azure.vm` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9074](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9074)) > * Add support for the `gcp` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9137](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9137)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azureappservice`, a new resource detector for Azure App Service. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `azure.app_service.instance.id`, and `deployment.environment.name` from the `WEBSITE_*` and `REGION_NAME` environment variables. ([#9289](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9289)) > * Add `azurecontainerapps` resource detector for Azure Container Apps. ([#8939](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8939)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azurefunctions`, a new resource detector for Azure Functions. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `faas.instance`, and `deployment.environment.name` from the `FUNCTIONS_*`, `WEBSITE_*`, `CONTAINER_NAME`, and `REGION_NAME` environment variables. ([#9290](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9290)) > * Add `NewResourceDetector` along with the `WithAttributeFilter` and `WithTagKeyFilter` options in `go.opentelemetry.io/contrib/detectors/azure/azurevm`. `WithAttributeFilter` restricts the returned resource to the attributes the filter accepts. `WithTagKeyFilter` opts in to `azure.tag.<name>` attributes for the VM tags whose keys satisfy the provided predicate; no VM tags are emitted without it. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > * Add `go.opentelemetry.io/contrib/detectors/vultr` — a new resource detector for Vultr Cloud Compute instances, ported from `processor/resourcedetectionprocessor/internal/vultr` in `opentelemetry-collector-contrib`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `host.id`, and `host.name`. ([#8995](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8995)) > > ### Changed > > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.43.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.43.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.43.0) for complete details. ([#9337](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9337)) > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.42.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.42.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.42.0) for complete details. ([#9196](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9196)) > * Use direct normalized-key lookups in `Carrier.Get` and `Carrier.Keys` in `go.opentelemetry.io/contrib/propagators/envcar`. ([#9112](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9112)) > * Update log bridge conversions to use attribute key-values instead of the removed log key-values in `go.opentelemetry.io/contrib/bridges/otellogr`, `go.opentelemetry.io/contrib/bridges/otellogrus`, `go.opentelemetry.io/contrib/bridges/otelslog`, and `go.opentelemetry.io/contrib/bridges/otelzap`. ([#9180](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9180)) > * The `Version()` function in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux` has been replaced by `const Version`. ([#9076](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9076)) > * Set `error.type` attribute instead of adding `exception` span events in `go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin`. ([#8977](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8977)) > * Prefer the gRPC dial target over the resolved peer IP for the `server.address` and `server.port` attributes in `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc`. ([#8904](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8904)) > * The detector in `go.opentelemetry.io/contrib/detectors/azure/azurevm` now also detects `cloud.account.id`, `cloud.availability_zone`, `azure.vm.name`, `azure.vm.size`, `azure.vm.scaleset.name`, and `azure.resource_group.name`, and prefers `osProfile.computerName` for `host.name` (falling back to the VM name), reconciling it with the collector-contrib Azure resource detector. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > > ### Fixed > > * Fix Prometheus reader resource label filter configuration in `go.opentelemetry.io/contrib/otelconf/v0.2.0`. ([#9062](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9062)) > * Apply `resource.detection/development.attributes.included` and `excluded` filtering to resource detector attributes in `go.opentelemetry.io/contrib/otelconf/x`. ([#9131](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9131)) > * Honor the context configured with `WithContext` when constructing resources in `go.opentelemetry.io/contrib/otelconf` and `go.opentelemetry.io/contrib/otelconf/x`. ([#9160](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9160)) > * Handle nil response bodies from custom `RoundTripper` implementations in `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` without panicking. ([#9184](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9184)) > * Fix incorrect (overestimated) sum calculation for runtime histograms in `go.opentelemetry.io/contrib/instrumentation/runtime`. ([#9063](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9063)) > * Fix `Severity.UnmarshalText` round trip for positive `FATAL` offsets above the named range in `go.opentelemetry.io/contrib/processors/minsev`. ([#9197](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9197)) > * Reduce binary size by fetching ConfigMaps via `rest.HTTPClientFor` instead of the Kubernetes clientset in `go.opentelemetry.io/contrib/detectors/aws/eks`. ([#9284](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9284)) > * `TextMapPropagator` in `go.opentelemetry.io/contrib/propagators/autoprop` returns the no-op propagator for empty input, matching the behavior of `none`. An unknown `OTEL_PROPAGATORS` value still returns an error with a nil propagator so `NewTextMapPropagator` falls back to the default TraceContext and Baggage propagators instead of disabling propagation. ([#9163](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9163)) > * Preserve error-valued attributes nested in a group as grouped attributes instead of silently dropping them in `go.opentelemetry.io/contrib/bridges/otelslog`. ([#9238](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9238)) > * Fix a data race in `go.opentelemetry.io/contrib/bridges/otelslog` where concurrent `Handle` calls could corrupt each other's log attributes because `kvBuffer.KeyValues` returned a slice aliasing a shared buffer. ([#9229](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9229)) > * Avoid a panic in `go.opentelemetry.io/contrib/bridges/otelzap` when a malformed error field contains a nil or non-error value. ([#9068](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9068)) > * Use `azure.container_app.instance.id` instead of `service.instance.id` for the replica name detected by `go.opentelemetry.io/contrib/detectors/azure/azurecontainerapps`. ([#9208](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9208)) > * Preserve the underlying metadata errors returned with partial resources from `go.opentelemetry.io/contrib/detectors/gcp`. ([#9069](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9069)) > * Copy `MultipartForm` back to the request `otelmux.Middleware` was given after the wrapped handler returns, so `net/http` can find and remove the temp files `ParseMultipartForm` created on the context-derived request copy, when `otelmux.Middleware` wraps a handler directly, in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux`. This does not cover a handler panic, nor the common `router.Use(...)` integration, where `gorilla/mux`'s own routing step makes an additional request copy the middleware cannot write back through; see [gorilla/mux#777](https://redirect.github.com/gorilla/mux/pull/777). ([#9361](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9361)) > * Report the `b3` header from `Fields()` for the default `B3Unspecified` single-header injection encoding, matching what `Inject` writes, in `go.opentelemetry.io/contrib/propagators/b3`. ([#9273](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9273)) > * Fix `go.opentelemetry.io/contrib/propagators/aws/xray` producing deterministic trace and span IDs when the seed read from `crypto/rand` silently failed, by switching to `math/rand/v2`'s concurrency-safe top-level generator. ([#9359](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9359)) ... (truncated) Changelog *Sourced from [go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp's changelog](https://github.com/open-telemetry/opentelemetry-go-contrib/blob/main/CHANGELOG.md).* > [1.45.0/2.5.2/0.70.0/0.37.2/0.25.0/0.20.0/0.16.2/0.17.0] - 2026-08-03 > --------------------------------------------------------------------- > > ### Added > > * Add `go.opentelemetry.io/contrib/detectors/ibmcloud/vpc`, a new resource detector for IBM Cloud VPC virtual server instances, ported from `github.com/open-telemetry/opentelemetry-collector-contrib/processor/resourcedetectionprocessor/internal/ibmcloud/vpc`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `cloud.availability_zone`, `cloud.account.id`, `cloud.resource_id`, `host.id`, `host.image.id`, `host.image.name`, `host.name`, and `host.type`. ([#9011](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9011)) > * Add `go.opentelemetry.io/contrib/detectors/k8sapi`, a new resource detector that queries the Kubernetes API. Detects `k8s.node.name` and `k8s.node.uid` when `K8S_NODE_NAME` is set via the downward API, and `k8s.cluster.uid` derived from the kube-system namespace UID (works on any Kubernetes distribution). ([#9108](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9108)) > * Add new `elasticbeanstalk` resource detector for AWS Elastic Beanstalk, ported from `processor/resourcedetectionprocessor/internal/aws/elasticbeanstalk` in opentelemetry-collector-contrib. ([#8993](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8993)) > * The resource created by `go.opentelemetry.io/contrib/otelconf` now includes [default SDK attributes](https://pkg.go.dev/go.opentelemetry.io/otel/sdk/resource#Default). ([#8990](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8990)) > * Add support for the `aws.ecs` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#8915](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8915)) > * Add support for the `aws.eks` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9138](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9138)) > * Add support for the `azure.vm` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9074](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9074)) > * Add support for the `gcp` resource detector in `go.opentelemetry.io/contrib/otelconf/x`. ([#9137](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9137)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azureappservice`, a new resource detector for Azure App Service. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `azure.app_service.instance.id`, and `deployment.environment.name` from the `WEBSITE_*` and `REGION_NAME` environment variables. ([#9289](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9289)) > * Add `azurecontainerapps` resource detector for Azure Container Apps. ([#8939](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8939)) > * Add `go.opentelemetry.io/contrib/detectors/azure/azurefunctions`, a new resource detector for Azure Functions. Detects `cloud.*`, `service.name`, `azure.resource_group.name`, `faas.instance`, and `deployment.environment.name` from the `FUNCTIONS_*`, `WEBSITE_*`, `CONTAINER_NAME`, and `REGION_NAME` environment variables. ([#9290](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9290)) > * Add `NewResourceDetector` along with the `WithAttributeFilter` and `WithTagKeyFilter` options in `go.opentelemetry.io/contrib/detectors/azure/azurevm`. `WithAttributeFilter` restricts the returned resource to the attributes the filter accepts. `WithTagKeyFilter` opts in to `azure.tag.<name>` attributes for the VM tags whose keys satisfy the provided predicate; no VM tags are emitted without it. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > * Add `go.opentelemetry.io/contrib/detectors/vultr` — a new resource detector for Vultr Cloud Compute instances, ported from `processor/resourcedetectionprocessor/internal/vultr` in `opentelemetry-collector-contrib`. Detects `cloud.provider`, `cloud.platform`, `cloud.region`, `host.id`, and `host.name`. ([#8995](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8995)) > > ### Changed > > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.43.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.43.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.43.0) for complete details. ([#9337](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9337)) > * Upgrade `go.opentelemetry.io/otel/semconv` to `v1.42.0`, including updates across instrumentation and detector modules. > See [semantic-conventions v1.42.0 release](https://github.com/open-telemetry/semantic-conventions/releases/tag/v1.42.0) for complete details. ([#9196](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9196)) > * Use direct normalized-key lookups in `Carrier.Get` and `Carrier.Keys` in `go.opentelemetry.io/contrib/propagators/envcar`. ([#9112](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9112)) > * Update log bridge conversions to use attribute key-values instead of the removed log key-values in `go.opentelemetry.io/contrib/bridges/otellogr`, `go.opentelemetry.io/contrib/bridges/otellogrus`, `go.opentelemetry.io/contrib/bridges/otelslog`, and `go.opentelemetry.io/contrib/bridges/otelzap`. ([#9180](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9180)) > * The `Version()` function in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux` has been replaced by `const Version`. ([#9076](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9076)) > * Set `error.type` attribute instead of adding `exception` span events in `go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin`. ([#8977](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8977)) > * Prefer the gRPC dial target over the resolved peer IP for the `server.address` and `server.port` attributes in `go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc`. ([#8904](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/8904)) > * The detector in `go.opentelemetry.io/contrib/detectors/azure/azurevm` now also detects `cloud.account.id`, `cloud.availability_zone`, `azure.vm.name`, `azure.vm.size`, `azure.vm.scaleset.name`, and `azure.resource_group.name`, and prefers `osProfile.computerName` for `host.name` (falling back to the VM name), reconciling it with the collector-contrib Azure resource detector. ([#9162](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9162)) > > ### Fixed > > * Fix Prometheus reader resource label filter configuration in `go.opentelemetry.io/contrib/otelconf/v0.2.0`. ([#9062](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9062)) > * Apply `resource.detection/development.attributes.included` and `excluded` filtering to resource detector attributes in `go.opentelemetry.io/contrib/otelconf/x`. ([#9131](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9131)) > * Honor the context configured with `WithContext` when constructing resources in `go.opentelemetry.io/contrib/otelconf` and `go.opentelemetry.io/contrib/otelconf/x`. ([#9160](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9160)) > * Handle nil response bodies from custom `RoundTripper` implementations in `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` without panicking. ([#9184](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9184)) > * Fix incorrect (overestimated) sum calculation for runtime histograms in `go.opentelemetry.io/contrib/instrumentation/runtime`. ([#9063](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9063)) > * Fix `Severity.UnmarshalText` round trip for positive `FATAL` offsets above the named range in `go.opentelemetry.io/contrib/processors/minsev`. ([#9197](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9197)) > * Reduce binary size by fetching ConfigMaps via `rest.HTTPClientFor` instead of the Kubernetes clientset in `go.opentelemetry.io/contrib/detectors/aws/eks`. ([#9284](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9284)) > * `TextMapPropagator` in `go.opentelemetry.io/contrib/propagators/autoprop` returns the no-op propagator for empty input, matching the behavior of `none`. An unknown `OTEL_PROPAGATORS` value still returns an error with a nil propagator so `NewTextMapPropagator` falls back to the default TraceContext and Baggage propagators instead of disabling propagation. ([#9163](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9163)) > * Preserve error-valued attributes nested in a group as grouped attributes instead of silently dropping them in `go.opentelemetry.io/contrib/bridges/otelslog`. ([#9238](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9238)) > * Fix a data race in `go.opentelemetry.io/contrib/bridges/otelslog` where concurrent `Handle` calls could corrupt each other's log attributes because `kvBuffer.KeyValues` returned a slice aliasing a shared buffer. ([#9229](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9229)) > * Avoid a panic in `go.opentelemetry.io/contrib/bridges/otelzap` when a malformed error field contains a nil or non-error value. ([#9068](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9068)) > * Use `azure.container_app.instance.id` instead of `service.instance.id` for the replica name detected by `go.opentelemetry.io/contrib/detectors/azure/azurecontainerapps`. ([#9208](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9208)) > * Preserve the underlying metadata errors returned with partial resources from `go.opentelemetry.io/contrib/detectors/gcp`. ([#9069](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9069)) > * Copy `MultipartForm` back to the request `otelmux.Middleware` was given after the wrapped handler returns, so `net/http` can find and remove the temp files `ParseMultipartForm` created on the context-derived request copy, when `otelmux.Middleware` wraps a handler directly, in `go.opentelemetry.io/contrib/instrumentation/github.com/gorilla/mux/otelmux`. This does not cover a handler panic, nor the common `router.Use(...)` integration, where `gorilla/mux`'s own routing step makes an additional request copy the middleware cannot write back through; see [gorilla/mux#777](https://redirect.github.com/gorilla/mux/pull/777). ([#9361](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9361)) > * Report the `b3` header from `Fields()` for the default `B3Unspecified` single-header injection encoding, matching what `Inject` writes, in `go.opentelemetry.io/contrib/propagators/b3`. ([#9273](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9273)) > * Fix `go.opentelemetry.io/contrib/propagators/aws/xray` producing deterministic trace and span IDs when the seed read from `crypto/rand` silently failed, by switching to `math/rand/v2`'s concurrency-safe top-level generator. ([#9359](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9359)) > * Strip connection number suffix from connection ID in `go.opentelemetry.io/contrib/instrumentation/go.mongodb.org/mongo-driver/v2/mongo/otelmongo` to prevent unbounded metric cardinality. ([#9352](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9352)) ... (truncated) Commits * [`c8a87a6`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/c8a87a60ba1b3374fd16df11fc3eeae6c41abbc9) Release v1.45.0/v2.5.2/v0.70.0/v0.37.2/v0.25.0/v0.20.0/v0.16.2/v0.17.0 ([#9413](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9413)) * [`cde125c`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/cde125c563f232eb6b423a208d375f8e53ae2557) fix(deps): update aws-sdk-go-v2 monorepo ([#9384](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9384)) * [`88572a7`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/88572a7662d00e805777ed96932d532316c13787) chore(deps): update googleapis to 6ac0973 ([#9409](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9409)) * [`e4f511a`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/e4f511a0f3cc2b09b87cb164427b49dfd2e14f7d) chore(deps): update github/codeql-action action to v4.37.5 ([#9410](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9410)) * [`265eb0b`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/265eb0b5fe0682801fd8177aec74ce8769c5a0a4) fix(deps): update go.opentelemetry.io/otel digest to 48db2c6 ([#9317](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9317)) * [`941ba46`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/941ba46979c59dca89d26040ed919870283e36e9) chore(deps): update github.com/charmbracelet/ultraviolet digest to 8b69304 (#... * [`ededd3b`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/ededd3b571ad562351a0afe09682774a6f48d63e) chore(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 ([#9406](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9406)) * [`7c6e819`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/7c6e819d4eb26eede10e98c424adb76304025fda) fix(deps): update module github.com/atombender/go-jsonschema to v0.24.1 ([#9405](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9405)) * [`ec1e544`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/ec1e544a0d6883126198c3fc3a7d62fc8db29195) chore(deps): update github.com/lufia/plan9stats digest to 341c2f0 ([#9403](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9403)) * [`5d7e16a`](https://github.com/open-telemetry/opentelemetry-go-contrib/commit/5d7e16aa1138a5446a648dd92ebc42031c93e327) chore(deps): update github.com/golangci/rowserrcheck digest to d2031e3 ([#9402](https://redirect.github.com/open-telemetry/opentelemetry-go-contrib/issues/9402)) * Additional commits viewable in [compare view](https://github.com/open-telemetry/opentelemetry-go-contrib/compare/zpages/v0.69.0...zpages/v0.70.0) Updates `go.opentelemetry.io/otel` from 1.44.0 to 1.45.0 Changelog *Sourced from [go.opentelemetry.io/otel's changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md).* > [1.45.0/0.67.0/0.21.0/0.0.18] - 2026-08-03 > ------------------------------------------ > > ### Added > > * Add experimental observability metrics to `BatchProcessor` in `go.opentelemetry.io/otel/sdk/log`. ([#7124](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/7124)) > * Add the experimental `WithUnsafeAttributes` no-copy attribute option to `go.opentelemetry.io/otel/metric/x` for future performance improvements. This API is a work in progress. ([#8251](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8251)) > * Add `Map` and `MapValue` functions for the new `MAP` attribute type in `go.opentelemetry.io/otel/attribute`. ([#8445](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8445)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlptrace`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlplog`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/zipkin`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Apply `AttributeValueLengthLimit` recursively to values contained in `attribute.MAP` attributes in `go.opentelemetry.io/otel/sdk/trace`. ([#8454](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8454)) > * Remove duplicate keys from `attribute.MAP` values in `go.opentelemetry.io/otel/sdk/resource` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/log` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in span, event, link, and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/trace` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in measurement and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/metric` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Extend `WithAllowKeyDuplication` in `go.opentelemetry.io/otel/sdk/log` to disable duplicate-key removal in `attribute.MAP` values for instrumentation scope attributes. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Add the `go.opentelemetry.io/otel/semconv/v1.42.0` package. > The package contains semantic conventions from the `v1.42.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.42.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.41.0`. ([#8484](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8484)) > * Add `WithoutPanicRecording` as a `TracerProviderOption` in `go.opentelemetry.io/otel/sdk/trace` to disable exception event recording for panics. ([#8532](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8532)) > * Add the `go.opentelemetry.io/otel/semconv/v1.43.0` package. > The package contains semantic conventions from the `v1.43.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.43.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.42.0`. ([#8628](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8628)) > > ### Changed > > * `HistogramReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` now uses a time-unbiased sampling algorithm for exemplars. ([#8306](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8306)) > * ⚠️ **Breaking Change:** Use `go.opentelemetry.io/otel/attribute.Value` and `go.opentelemetry.io/otel/attribute.KeyValue` for log bodies and attributes in `go.opentelemetry.io/otel/log`, `go.opentelemetry.io/otel/log/logtest`, `go.opentelemetry.io/otel/sdk/log`, and `go.opentelemetry.io/otel/sdk/log/logtest`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Encode log bodies and attributes as `go.opentelemetry.io/otel/attribute.Value` JSON in `go.opentelemetry.io/otel/exporters/stdout/stdoutlog`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Improve the performance of hashing `BOOLSLICE`, `INT64SLICE`, `FLOAT64SLICE`, and `STRINGSLICE` attribute values by avoiding reflection for short slices in `go.opentelemetry.io/otel/attribute`. ([#8511](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8511)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_METRICS_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_TRACES_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > > ### Deprecated > > * Deprecate `WithExportBufferSize` in `go.opentelemetry.io/otel/sdk/log`. The option remains available for source compatibility but no longer affects behavior; `BatchProcessor` no longer maintains a separate export-request buffer. ([#8620](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8620)) > > ### Removed > > * ⚠️ **Breaking Change:** Remove `Kind`, `Value`, `KeyValue`, their constructors, and attribute conversion helpers from `go.opentelemetry.io/otel/log`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * ⚠️ **Breaking Change:** Remove the `AttributeValueLengthLimit` and `AttributeCountLimit` fields from `RecordFactory` in `go.opentelemetry.io/otel/sdk/log/logtest`; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. ([#8556](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8556)) > > ### Fixed > > * Apply TLS certificates configured through environment variables to gRPC connections in `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc`. > * Prevent panics in `go.opentelemetry.io/otel/bridge/opentracing` when OpenTracing baggage is propagated concurrently with `Span.SetBaggageItem`. > * Fix an off-by-one error in `FixedSizeReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` that prevented the first exemplar from being sampled after the reservoir was filled. ([#8309](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8309)) > * Interpret HTTP `Retry-After` header values as seconds instead of nanoseconds when retrying OTLP HTTP exports in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp`, `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp`, and `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp`. ([#8383](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8383)) > * Fix a memory leak in the `Reservoir` implementation in `go.opentelemetry.io/otel/sdk/metric/exemplar`, where storing the full `context.Context` pinned large objects such as gRPC transport buffers. ([#8389](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8389)) ... (truncated) Commits * [`93a693e`](https://github.com/open-telemetry/opentelemetry-go/commit/93a693edeed0e07ce5ebd1dfe67af42d1e2055d8) Release v1.45.0 ([#8693](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8693)) * [`c65d435`](https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c) Merge commit from fork * [`223f9fd`](https://github.com/open-telemetry/opentelemetry-go/commit/223f9fdce4e4a85d6ee2155c6a140f236db72c8b) sdk/metric: remove obsolete randomFloat64 TODO ([#8685](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8685)) * [`06272bc`](https://github.com/open-telemetry/opentelemetry-go/commit/06272bc491566efb2c581c8a52e4986cfcccec5b) fix(deps): update googleapis to 6ac0973 ([#8694](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8694)) * [`a4f238f`](https://github.com/open-telemetry/opentelemetry-go/commit/a4f238f57646197d124edcf67baf4cd6ea6d0a9f) chore(deps): update github.com/charmbracelet/ultraviolet digest to 8b69304 (#... * [`37140e7`](https://github.com/open-telemetry/opentelemetry-go/commit/37140e78821d3cb29a33d4b601ca4645b80ceebd) chore(deps): update codspeedhq/action action to v5.0.2 ([#8690](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8690)) * [`cef0855`](https://github.com/open-telemetry/opentelemetry-go/commit/cef0855960bce4385c7d58c40e846573c190d826) chore(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 ([#8689](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8689)) * [`e814a72`](https://github.com/open-telemetry/opentelemetry-go/commit/e814a7281f2d52a6440c3269e139145e62801a16) Merge commit from fork * [`bfd8eb7`](https://github.com/open-telemetry/opentelemetry-go/commit/bfd8eb7f85d3364fdde9ad1a408df98be30acadb) chore(deps): update github.com/golangci/rowserrcheck digest to d2031e3 ([#8687](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8687)) * [`48db2c6`](https://github.com/open-telemetry/opentelemetry-go/commit/48db2c659c3b138f971273cd91ea0bcb647768e1) chore(deps): update github/codeql-action action to v4.37.5 ([#8692](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8692)) * Additional commits viewable in [compare view](https://github.com/open-telemetry/opentelemetry-go/compare/v1.44.0...v1.45.0) Updates `go.opentelemetry.io/otel/metric` from 1.44.0 to 1.45.0 Changelog *Sourced from [go.opentelemetry.io/otel/metric's changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md).* > [1.45.0/0.67.0/0.21.0/0.0.18] - 2026-08-03 > ------------------------------------------ > > ### Added > > * Add experimental observability metrics to `BatchProcessor` in `go.opentelemetry.io/otel/sdk/log`. ([#7124](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/7124)) > * Add the experimental `WithUnsafeAttributes` no-copy attribute option to `go.opentelemetry.io/otel/metric/x` for future performance improvements. This API is a work in progress. ([#8251](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8251)) > * Add `Map` and `MapValue` functions for the new `MAP` attribute type in `go.opentelemetry.io/otel/attribute`. ([#8445](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8445)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlptrace`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlplog`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Support `MAP` attributes in `go.opentelemetry.io/otel/exporters/zipkin`. ([#8453](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8453)) > * Apply `AttributeValueLengthLimit` recursively to values contained in `attribute.MAP` attributes in `go.opentelemetry.io/otel/sdk/trace`. ([#8454](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8454)) > * Remove duplicate keys from `attribute.MAP` values in `go.opentelemetry.io/otel/sdk/resource` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/log` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in span, event, link, and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/trace` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Remove duplicate keys by default from `attribute.MAP` values in measurement and instrumentation scope attributes in `go.opentelemetry.io/otel/sdk/metric` using last-value-wins semantics. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Extend `WithAllowKeyDuplication` in `go.opentelemetry.io/otel/sdk/log` to disable duplicate-key removal in `attribute.MAP` values for instrumentation scope attributes. ([#8471](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8471)) > * Add the `go.opentelemetry.io/otel/semconv/v1.42.0` package. > The package contains semantic conventions from the `v1.42.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.42.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.41.0`. ([#8484](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8484)) > * Add `WithoutPanicRecording` as a `TracerProviderOption` in `go.opentelemetry.io/otel/sdk/trace` to disable exception event recording for panics. ([#8532](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8532)) > * Add the `go.opentelemetry.io/otel/semconv/v1.43.0` package. > The package contains semantic conventions from the `v1.43.0` version of the OpenTelemetry Semantic Conventions. > See the [migration documentation](https://github.com/open-telemetry/opentelemetry-go/blob/main/semconv/v1.43.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.42.0`. ([#8628](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8628)) > > ### Changed > > * `HistogramReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` now uses a time-unbiased sampling algorithm for exemplars. ([#8306](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8306)) > * ⚠️ **Breaking Change:** Use `go.opentelemetry.io/otel/attribute.Value` and `go.opentelemetry.io/otel/attribute.KeyValue` for log bodies and attributes in `go.opentelemetry.io/otel/log`, `go.opentelemetry.io/otel/log/logtest`, `go.opentelemetry.io/otel/sdk/log`, and `go.opentelemetry.io/otel/sdk/log/logtest`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Encode log bodies and attributes as `go.opentelemetry.io/otel/attribute.Value` JSON in `go.opentelemetry.io/otel/exporters/stdout/stdoutlog`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * Improve the performance of hashing `BOOLSLICE`, `INT64SLICE`, `FLOAT64SLICE`, and `STRINGSLICE` attribute values by avoiding reflection for short slices in `go.opentelemetry.io/otel/attribute`. ([#8511](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8511)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_METRICS_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/metrics"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > * ⚠️ **Breaking Change:** `WithEndpointURL` in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp` no longer appends the default signal path when an endpoint URL has no path, making the behavior consistent with `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` and with setting the endpoint through `OTEL_EXPORTER_OTLP_TRACES_ENDPOINT`. If the URL has no path component, the root path (`/`) is used. Use `WithEndpointURL(url.JoinPath(endpoint, "/v1/traces"))` to preserve the previous behavior. ([#8538](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8538)) > > ### Deprecated > > * Deprecate `WithExportBufferSize` in `go.opentelemetry.io/otel/sdk/log`. The option remains available for source compatibility but no longer affects behavior; `BatchProcessor` no longer maintains a separate export-request buffer. ([#8620](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8620)) > > ### Removed > > * ⚠️ **Breaking Change:** Remove `Kind`, `Value`, `KeyValue`, their constructors, and attribute conversion helpers from `go.opentelemetry.io/otel/log`. ([#8490](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8490)) > * ⚠️ **Breaking Change:** Remove the `AttributeValueLengthLimit` and `AttributeCountLimit` fields from `RecordFactory` in `go.opentelemetry.io/otel/sdk/log/logtest`; records produced by the factory now keep attribute limits disabled so test code can append exact attributes. ([#8556](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8556)) > > ### Fixed > > * Apply TLS certificates configured through environment variables to gRPC connections in `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc`. > * Prevent panics in `go.opentelemetry.io/otel/bridge/opentracing` when OpenTracing baggage is propagated concurrently with `Span.SetBaggageItem`. > * Fix an off-by-one error in `FixedSizeReservoir` in `go.opentelemetry.io/otel/sdk/metric/exemplar` that prevented the first exemplar from being sampled after the reservoir was filled. ([#8309](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8309)) > * Interpret HTTP `Retry-After` header values as seconds instead of nanoseconds when retrying OTLP HTTP exports in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp`, `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp`, and `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp`. ([#8383](https://redirect.github.com/open-telemetry/opentelemetry-go/issues/8383)) > * Fix a memory leak in the `Reservo... > _Description has been truncated_`
resolveHardlinkTargetrejects absolute hardlink targets — kaniko-built images fail to pull with "invalid hardlink target" since v0.3.0 (Docker 29.7.0) #99The CVE-2026-17106 hardening rejects hardlink entries whose target is an absolute path. Some image builders (e.g. kaniko) write hardlink targets as absolute paths, so layers of such images fail to extract with "invalid hardlink target" since v0.3.0 (Docker 29.7.0).
Resolve absolute hardlink targets relative to the extraction root with chroot-like semantics, matching how absolute symlink targets are handled since 4f6cd58 and how pre-v0.3.0 extraction behaved. The root is stripped from the original linkname rather than the cleaned one, so targets like "/../victim" are not collapsed against "/" but keep failing the filepath.IsLocal check, and the resolved target then passes through resolveArchivePath confined to the os.Root extraction root.