mirror of
https://github.com/jesseduffield/lazydocker.git
synced 2026-07-25 08:31:03 +00:00
fix:
Fulcio allocates excessive memory during token parsing CNA Plugins Portmap nftables backend can intercept non-local traffic golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read
This commit is contained in:
parent
1a54c93806
commit
9a43a5e1e1
227 changed files with 21860 additions and 30618 deletions
53
go.mod
53
go.mod
|
|
@ -1,6 +1,6 @@
|
||||||
module github.com/christophe-duc/lazypodman
|
module github.com/christophe-duc/lazypodman
|
||||||
|
|
||||||
go 1.24.2
|
go 1.25.0
|
||||||
|
|
||||||
require (
|
require (
|
||||||
github.com/OpenPeeDeeP/xdg v0.2.1-0.20190312153938-4ba9e1eb294c
|
github.com/OpenPeeDeeP/xdg v0.2.1-0.20190312153938-4ba9e1eb294c
|
||||||
|
|
@ -49,7 +49,7 @@ require (
|
||||||
github.com/containerd/stargz-snapshotter/estargz v0.17.0 // indirect
|
github.com/containerd/stargz-snapshotter/estargz v0.17.0 // indirect
|
||||||
github.com/containerd/typeurl/v2 v2.2.3 // indirect
|
github.com/containerd/typeurl/v2 v2.2.3 // indirect
|
||||||
github.com/containernetworking/cni v1.3.0 // indirect
|
github.com/containernetworking/cni v1.3.0 // indirect
|
||||||
github.com/containernetworking/plugins v1.8.0 // indirect
|
github.com/containernetworking/plugins v1.9.0 // indirect
|
||||||
github.com/containers/buildah v1.42.2 // indirect
|
github.com/containers/buildah v1.42.2 // indirect
|
||||||
github.com/containers/conmon v2.0.20+incompatible // indirect
|
github.com/containers/conmon v2.0.20+incompatible // indirect
|
||||||
github.com/containers/libtrust v0.0.0-20230121012942-c1716e8a8d01 // indirect
|
github.com/containers/libtrust v0.0.0-20230121012942-c1716e8a8d01 // indirect
|
||||||
|
|
@ -72,10 +72,11 @@ require (
|
||||||
github.com/felixge/httpsnoop v1.0.4 // indirect
|
github.com/felixge/httpsnoop v1.0.4 // indirect
|
||||||
github.com/fsnotify/fsnotify v1.9.0 // indirect
|
github.com/fsnotify/fsnotify v1.9.0 // indirect
|
||||||
github.com/fsouza/go-dockerclient v1.12.2 // indirect
|
github.com/fsouza/go-dockerclient v1.12.2 // indirect
|
||||||
github.com/go-jose/go-jose/v4 v4.0.5 // indirect
|
github.com/go-jose/go-jose/v4 v4.1.3 // indirect
|
||||||
github.com/go-logr/logr v1.4.3 // indirect
|
github.com/go-logr/logr v1.4.3 // indirect
|
||||||
github.com/go-logr/stdr v1.2.2 // indirect
|
github.com/go-logr/stdr v1.2.2 // indirect
|
||||||
github.com/go-ole/go-ole v1.3.0 // indirect
|
github.com/go-ole/go-ole v1.3.0 // indirect
|
||||||
|
github.com/go-playground/universal-translator v0.18.1 // indirect
|
||||||
github.com/godbus/dbus/v5 v5.1.1-0.20241109141217-c266b19b28e9 // indirect
|
github.com/godbus/dbus/v5 v5.1.1-0.20241109141217-c266b19b28e9 // indirect
|
||||||
github.com/gogo/protobuf v1.3.2 // indirect
|
github.com/gogo/protobuf v1.3.2 // indirect
|
||||||
github.com/golang/protobuf v1.5.4 // indirect
|
github.com/golang/protobuf v1.5.4 // indirect
|
||||||
|
|
@ -95,7 +96,6 @@ require (
|
||||||
github.com/klauspost/compress v1.18.0 // indirect
|
github.com/klauspost/compress v1.18.0 // indirect
|
||||||
github.com/klauspost/pgzip v1.2.6 // indirect
|
github.com/klauspost/pgzip v1.2.6 // indirect
|
||||||
github.com/kr/fs v0.1.0 // indirect
|
github.com/kr/fs v0.1.0 // indirect
|
||||||
github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec // indirect
|
|
||||||
github.com/lufia/plan9stats v0.0.0-20240909124753-873cd0166683 // indirect
|
github.com/lufia/plan9stats v0.0.0-20240909124753-873cd0166683 // indirect
|
||||||
github.com/manifoldco/promptui v0.9.0 // indirect
|
github.com/manifoldco/promptui v0.9.0 // indirect
|
||||||
github.com/mattn/go-shellwords v1.0.12 // indirect
|
github.com/mattn/go-shellwords v1.0.12 // indirect
|
||||||
|
|
@ -131,17 +131,16 @@ require (
|
||||||
github.com/seccomp/libseccomp-golang v0.11.1 // indirect
|
github.com/seccomp/libseccomp-golang v0.11.1 // indirect
|
||||||
github.com/secure-systems-lab/go-securesystemslib v0.9.1 // indirect
|
github.com/secure-systems-lab/go-securesystemslib v0.9.1 // indirect
|
||||||
github.com/shirou/gopsutil/v4 v4.25.9 // indirect
|
github.com/shirou/gopsutil/v4 v4.25.9 // indirect
|
||||||
github.com/sigstore/fulcio v1.7.1 // indirect
|
github.com/sigstore/fulcio v1.8.3 // indirect
|
||||||
github.com/sigstore/protobuf-specs v0.4.1 // indirect
|
github.com/sigstore/protobuf-specs v0.5.0 // indirect
|
||||||
github.com/sigstore/sigstore v1.9.5 // indirect
|
github.com/sigstore/sigstore v1.10.0 // indirect
|
||||||
github.com/skeema/knownhosts v1.3.2 // indirect
|
github.com/skeema/knownhosts v1.3.2 // indirect
|
||||||
github.com/smallstep/pkcs7 v0.1.1 // indirect
|
github.com/smallstep/pkcs7 v0.1.1 // indirect
|
||||||
github.com/spf13/cobra v1.10.1 // indirect
|
github.com/spf13/cobra v1.10.2 // indirect
|
||||||
github.com/spf13/pflag v1.0.10 // indirect
|
github.com/spf13/pflag v1.0.10 // indirect
|
||||||
github.com/stefanberger/go-pkcs11uri v0.0.0-20230803200340-78284954bff6 // indirect
|
github.com/stefanberger/go-pkcs11uri v0.0.0-20230803200340-78284954bff6 // indirect
|
||||||
github.com/sylabs/sif/v2 v2.22.0 // indirect
|
github.com/sylabs/sif/v2 v2.22.0 // indirect
|
||||||
github.com/tchap/go-patricia/v2 v2.3.3 // indirect
|
github.com/tchap/go-patricia/v2 v2.3.3 // indirect
|
||||||
github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
|
|
||||||
github.com/tklauser/go-sysconf v0.3.15 // indirect
|
github.com/tklauser/go-sysconf v0.3.15 // indirect
|
||||||
github.com/tklauser/numcpus v0.10.0 // indirect
|
github.com/tklauser/numcpus v0.10.0 // indirect
|
||||||
github.com/ulikunitz/xz v0.5.15 // indirect
|
github.com/ulikunitz/xz v0.5.15 // indirect
|
||||||
|
|
@ -151,23 +150,23 @@ require (
|
||||||
github.com/vishvananda/netns v0.0.5 // indirect
|
github.com/vishvananda/netns v0.0.5 // indirect
|
||||||
github.com/yusufpapurcu/wmi v1.2.4 // indirect
|
github.com/yusufpapurcu/wmi v1.2.4 // indirect
|
||||||
go.etcd.io/bbolt v1.4.3 // indirect
|
go.etcd.io/bbolt v1.4.3 // indirect
|
||||||
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
|
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
|
||||||
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 // indirect
|
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 // indirect
|
||||||
go.opentelemetry.io/otel v1.36.0 // indirect
|
go.opentelemetry.io/otel v1.38.0 // indirect
|
||||||
go.opentelemetry.io/otel/metric v1.36.0 // indirect
|
go.opentelemetry.io/otel/metric v1.38.0 // indirect
|
||||||
go.opentelemetry.io/otel/trace v1.36.0 // indirect
|
go.opentelemetry.io/otel/trace v1.38.0 // indirect
|
||||||
go.podman.io/image/v5 v5.38.0 // indirect
|
go.podman.io/image/v5 v5.38.0 // indirect
|
||||||
go.podman.io/storage v1.61.0 // indirect
|
go.podman.io/storage v1.61.0 // indirect
|
||||||
go.yaml.in/yaml/v2 v2.4.2 // indirect
|
go.yaml.in/yaml/v2 v2.4.3 // indirect
|
||||||
golang.org/x/crypto v0.43.0 // indirect
|
golang.org/x/crypto v0.45.0 // indirect
|
||||||
golang.org/x/mod v0.28.0 // indirect
|
golang.org/x/mod v0.29.0 // indirect
|
||||||
golang.org/x/net v0.45.0 // indirect
|
golang.org/x/net v0.47.0 // indirect
|
||||||
golang.org/x/sync v0.17.0 // indirect
|
golang.org/x/sync v0.18.0 // indirect
|
||||||
golang.org/x/time v0.11.0 // indirect
|
golang.org/x/time v0.14.0 // indirect
|
||||||
google.golang.org/genproto/googleapis/api v0.0.0-20250414145226-207652e42e2e // indirect
|
google.golang.org/genproto/googleapis/api v0.0.0-20251022142026-3a174f9686a8 // indirect
|
||||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20250414145226-207652e42e2e // indirect
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20251103181224-f26f9409b101 // indirect
|
||||||
google.golang.org/grpc v1.72.2 // indirect
|
google.golang.org/grpc v1.77.0 // indirect
|
||||||
google.golang.org/protobuf v1.36.9 // indirect
|
google.golang.org/protobuf v1.36.10 // indirect
|
||||||
gopkg.in/fsnotify.v1 v1.4.7 // indirect
|
gopkg.in/fsnotify.v1 v1.4.7 // indirect
|
||||||
gopkg.in/inf.v0 v0.9.1 // indirect
|
gopkg.in/inf.v0 v0.9.1 // indirect
|
||||||
gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7 // indirect
|
gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7 // indirect
|
||||||
|
|
@ -190,8 +189,8 @@ require (
|
||||||
github.com/rivo/uniseg v0.4.7 // indirect
|
github.com/rivo/uniseg v0.4.7 // indirect
|
||||||
github.com/xo/terminfo v0.0.0-20210125001918-ca9a967f8778 // indirect
|
github.com/xo/terminfo v0.0.0-20210125001918-ca9a967f8778 // indirect
|
||||||
golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0 // indirect
|
golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0 // indirect
|
||||||
golang.org/x/sys v0.37.0 // indirect
|
golang.org/x/sys v0.38.0 // indirect
|
||||||
golang.org/x/term v0.36.0 // indirect
|
golang.org/x/term v0.37.0 // indirect
|
||||||
golang.org/x/text v0.30.0 // indirect
|
golang.org/x/text v0.31.0 // indirect
|
||||||
gopkg.in/yaml.v3 v3.0.1 // indirect
|
gopkg.in/yaml.v3 v3.0.1 // indirect
|
||||||
)
|
)
|
||||||
|
|
|
||||||
146
go.sum
146
go.sum
|
|
@ -57,8 +57,8 @@ github.com/containerd/typeurl/v2 v2.2.3 h1:yNA/94zxWdvYACdYO8zofhrTVuQY73fFU1y++
|
||||||
github.com/containerd/typeurl/v2 v2.2.3/go.mod h1:95ljDnPfD3bAbDJRugOiShd/DlAAsxGtUBhJxIn7SCk=
|
github.com/containerd/typeurl/v2 v2.2.3/go.mod h1:95ljDnPfD3bAbDJRugOiShd/DlAAsxGtUBhJxIn7SCk=
|
||||||
github.com/containernetworking/cni v1.3.0 h1:v6EpN8RznAZj9765HhXQrtXgX+ECGebEYEmnuFjskwo=
|
github.com/containernetworking/cni v1.3.0 h1:v6EpN8RznAZj9765HhXQrtXgX+ECGebEYEmnuFjskwo=
|
||||||
github.com/containernetworking/cni v1.3.0/go.mod h1:Bs8glZjjFfGPHMw6hQu82RUgEPNGEaBb9KS5KtNMnJ4=
|
github.com/containernetworking/cni v1.3.0/go.mod h1:Bs8glZjjFfGPHMw6hQu82RUgEPNGEaBb9KS5KtNMnJ4=
|
||||||
github.com/containernetworking/plugins v1.8.0 h1:WjGbV/0UQyo8A4qBsAh6GaDAtu1hevxVxsEuqtBqUFk=
|
github.com/containernetworking/plugins v1.9.0 h1:Mg3SXBdRGkdXyFC4lcwr6u2ZB2SDeL6LC3U+QrEANuQ=
|
||||||
github.com/containernetworking/plugins v1.8.0/go.mod h1:JG3BxoJifxxHBhG3hFyxyhid7JgRVBu/wtooGEvWf1c=
|
github.com/containernetworking/plugins v1.9.0/go.mod h1:JG3BxoJifxxHBhG3hFyxyhid7JgRVBu/wtooGEvWf1c=
|
||||||
github.com/containers/buildah v1.42.2 h1:be4mKtMOtvuW3R1TYWP+MupxzCaq6PRn7+m1iZH9YbE=
|
github.com/containers/buildah v1.42.2 h1:be4mKtMOtvuW3R1TYWP+MupxzCaq6PRn7+m1iZH9YbE=
|
||||||
github.com/containers/buildah v1.42.2/go.mod h1:SDA+ClXamnZPV7GBS2uKY0dfXKfvTykSUA+kJWa1mNg=
|
github.com/containers/buildah v1.42.2/go.mod h1:SDA+ClXamnZPV7GBS2uKY0dfXKfvTykSUA+kJWa1mNg=
|
||||||
github.com/containers/conmon v2.0.20+incompatible h1:YbCVSFSCqFjjVwHTPINGdMX1F6JXHGTUje2ZYobNrkg=
|
github.com/containers/conmon v2.0.20+incompatible h1:YbCVSFSCqFjjVwHTPINGdMX1F6JXHGTUje2ZYobNrkg=
|
||||||
|
|
@ -127,8 +127,8 @@ github.com/gdamore/tcell/v2 v2.7.4/go.mod h1:dSXtXTSK0VsW1biw65DZLZ2NKr7j0qP/0J7
|
||||||
github.com/go-errors/errors v1.0.2/go.mod h1:psDX2osz5VnTOnFWbDeWwS7yejl+uV3FEWEp4lssFEs=
|
github.com/go-errors/errors v1.0.2/go.mod h1:psDX2osz5VnTOnFWbDeWwS7yejl+uV3FEWEp4lssFEs=
|
||||||
github.com/go-errors/errors v1.5.1 h1:ZwEMSLRCapFLflTpT7NKaAc7ukJ8ZPEjzlxt8rPN8bk=
|
github.com/go-errors/errors v1.5.1 h1:ZwEMSLRCapFLflTpT7NKaAc7ukJ8ZPEjzlxt8rPN8bk=
|
||||||
github.com/go-errors/errors v1.5.1/go.mod h1:sIVyrIiJhuEF+Pj9Ebtd6P/rEYROXFi3BopGUQ5a5Og=
|
github.com/go-errors/errors v1.5.1/go.mod h1:sIVyrIiJhuEF+Pj9Ebtd6P/rEYROXFi3BopGUQ5a5Og=
|
||||||
github.com/go-jose/go-jose/v4 v4.0.5 h1:M6T8+mKZl/+fNNuFHvGIzDz7BTLQPIounk/b9dw3AaE=
|
github.com/go-jose/go-jose/v4 v4.1.3 h1:CVLmWDhDVRa6Mi/IgCgaopNosCaHz7zrMeF9MlZRkrs=
|
||||||
github.com/go-jose/go-jose/v4 v4.0.5/go.mod h1:s3P1lRrkT8igV8D9OjyL4WRyHvjB6a4JSllnOrmmBOA=
|
github.com/go-jose/go-jose/v4 v4.1.3/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
|
||||||
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
|
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
|
||||||
github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI=
|
github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI=
|
||||||
github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
|
github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
|
||||||
|
|
@ -145,8 +145,6 @@ github.com/go-playground/validator/v10 v10.4.1 h1:pH2c5ADXtd66mxoE0Zm9SUhxE20r7a
|
||||||
github.com/go-playground/validator/v10 v10.4.1/go.mod h1:nlOn6nFhuKACm19sB/8EGNn9GlaMV7XkbRSipzJ0Ii4=
|
github.com/go-playground/validator/v10 v10.4.1/go.mod h1:nlOn6nFhuKACm19sB/8EGNn9GlaMV7XkbRSipzJ0Ii4=
|
||||||
github.com/go-task/slim-sprig/v3 v3.0.0 h1:sUs3vkvUymDpBKi3qH1YSqBQk9+9D/8M2mN1vB6EwHI=
|
github.com/go-task/slim-sprig/v3 v3.0.0 h1:sUs3vkvUymDpBKi3qH1YSqBQk9+9D/8M2mN1vB6EwHI=
|
||||||
github.com/go-task/slim-sprig/v3 v3.0.0/go.mod h1:W848ghGpv3Qj3dhTPRyJypKRiqCdHZiAzKg9hl15HA8=
|
github.com/go-task/slim-sprig/v3 v3.0.0/go.mod h1:W848ghGpv3Qj3dhTPRyJypKRiqCdHZiAzKg9hl15HA8=
|
||||||
github.com/go-test/deep v1.1.1 h1:0r/53hagsehfO4bzD2Pgr/+RgHqhmf+k1Bpse2cTu1U=
|
|
||||||
github.com/go-test/deep v1.1.1/go.mod h1:5C2ZWiW0ErCdrYzpqxLbTX7MG14M9iiw8DgHncVwcsE=
|
|
||||||
github.com/goccy/go-yaml v1.11.0 h1:n7Z+zx8S9f9KgzG6KtQKf+kwqXZlLNR2F6018Dgau54=
|
github.com/goccy/go-yaml v1.11.0 h1:n7Z+zx8S9f9KgzG6KtQKf+kwqXZlLNR2F6018Dgau54=
|
||||||
github.com/goccy/go-yaml v1.11.0/go.mod h1:H+mJrWtjPTJAHvRbV09MCK9xYwODM+wRTVFFTWckfng=
|
github.com/goccy/go-yaml v1.11.0/go.mod h1:H+mJrWtjPTJAHvRbV09MCK9xYwODM+wRTVFFTWckfng=
|
||||||
github.com/godbus/dbus/v5 v5.1.1-0.20241109141217-c266b19b28e9 h1:Kzr9J0S0V2PRxiX6B6xw1kWjzsIyjLO2Ibi4fNTaYBM=
|
github.com/godbus/dbus/v5 v5.1.1-0.20241109141217-c266b19b28e9 h1:Kzr9J0S0V2PRxiX6B6xw1kWjzsIyjLO2Ibi4fNTaYBM=
|
||||||
|
|
@ -176,8 +174,8 @@ github.com/gorilla/mux v1.8.1 h1:TuBL49tXwgrFYWhqrNgrUNEY92u81SPhu7sTdzQEiWY=
|
||||||
github.com/gorilla/mux v1.8.1/go.mod h1:AKf9I4AEqPTmMytcMc0KkNouC66V3BtZ4qD5fmWSiMQ=
|
github.com/gorilla/mux v1.8.1/go.mod h1:AKf9I4AEqPTmMytcMc0KkNouC66V3BtZ4qD5fmWSiMQ=
|
||||||
github.com/gorilla/schema v1.4.1 h1:jUg5hUjCSDZpNGLuXQOgIWGdlgrIdYvgQ0wZtdK1M3E=
|
github.com/gorilla/schema v1.4.1 h1:jUg5hUjCSDZpNGLuXQOgIWGdlgrIdYvgQ0wZtdK1M3E=
|
||||||
github.com/gorilla/schema v1.4.1/go.mod h1:Dg5SSm5PV60mhF2NFaTV1xuYYj8tV8NOPRo4FggUMnM=
|
github.com/gorilla/schema v1.4.1/go.mod h1:Dg5SSm5PV60mhF2NFaTV1xuYYj8tV8NOPRo4FggUMnM=
|
||||||
github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3 h1:5ZPtiqj0JL5oKWmcsq4VMaAW5ukBEgSGXEN89zeH1Jo=
|
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.3 h1:NmZ1PKzSTQbuGHw9DGPFomqkkLWMC+vZCkfs+FHv1Vg=
|
||||||
github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3/go.mod h1:ndYquD05frm2vACXE1nsccT4oJzjhw2arTS2cpUD1PI=
|
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.3/go.mod h1:zQrxl1YP88HQlA6i9c63DSVPFklWpGX4OWAc9bFuaH4=
|
||||||
github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
|
github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
|
||||||
github.com/hashicorp/errwrap v1.1.0 h1:OxrOeh75EUXMY8TBjag2fzXGZ40LB6IKw45YeGUDY2I=
|
github.com/hashicorp/errwrap v1.1.0 h1:OxrOeh75EUXMY8TBjag2fzXGZ40LB6IKw45YeGUDY2I=
|
||||||
github.com/hashicorp/errwrap v1.1.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
|
github.com/hashicorp/errwrap v1.1.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
|
||||||
|
|
@ -203,8 +201,6 @@ github.com/jesseduffield/yaml v0.0.0-20190702115811-b900b7e08b56 h1:33wSxJWU/f2T
|
||||||
github.com/jesseduffield/yaml v0.0.0-20190702115811-b900b7e08b56/go.mod h1:FZJBwOhE+RXz8EVZfY+xnbCw2cVOwxlK3/aIi581z/s=
|
github.com/jesseduffield/yaml v0.0.0-20190702115811-b900b7e08b56/go.mod h1:FZJBwOhE+RXz8EVZfY+xnbCw2cVOwxlK3/aIi581z/s=
|
||||||
github.com/jinzhu/copier v0.4.0 h1:w3ciUoD19shMCRargcpm0cm91ytaBhDvuRpz1ODO/U8=
|
github.com/jinzhu/copier v0.4.0 h1:w3ciUoD19shMCRargcpm0cm91ytaBhDvuRpz1ODO/U8=
|
||||||
github.com/jinzhu/copier v0.4.0/go.mod h1:DfbEm0FYsaqBcKcFuvmOZb218JkPGtvSHsKg8S8hyyg=
|
github.com/jinzhu/copier v0.4.0/go.mod h1:DfbEm0FYsaqBcKcFuvmOZb218JkPGtvSHsKg8S8hyyg=
|
||||||
github.com/jmhodges/clock v1.2.0 h1:eq4kys+NI0PLngzaHEe7AmPT90XMGIEySD1JfV1PDIs=
|
|
||||||
github.com/jmhodges/clock v1.2.0/go.mod h1:qKjhA7x7u/lQpPB1XAqX1b1lCI/w3/fNuYpI/ZjLynI=
|
|
||||||
github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnrnM=
|
github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnrnM=
|
||||||
github.com/json-iterator/go v1.1.12/go.mod h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo=
|
github.com/json-iterator/go v1.1.12/go.mod h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo=
|
||||||
github.com/kevinburke/ssh_config v1.4.0 h1:6xxtP5bZ2E4NF5tuQulISpTO2z8XbtH8cg1PWkxoFkQ=
|
github.com/kevinburke/ssh_config v1.4.0 h1:6xxtP5bZ2E4NF5tuQulISpTO2z8XbtH8cg1PWkxoFkQ=
|
||||||
|
|
@ -223,8 +219,6 @@ github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY=
|
||||||
github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE=
|
github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE=
|
||||||
github.com/leodido/go-urn v1.2.0 h1:hpXL4XnriNwQ/ABnpepYM/1vCLWNDfUNts8dX3xTG6Y=
|
github.com/leodido/go-urn v1.2.0 h1:hpXL4XnriNwQ/ABnpepYM/1vCLWNDfUNts8dX3xTG6Y=
|
||||||
github.com/leodido/go-urn v1.2.0/go.mod h1:+8+nEpDfqqsY+g338gtMEUOtuK+4dEMhiQEgxpxOKII=
|
github.com/leodido/go-urn v1.2.0/go.mod h1:+8+nEpDfqqsY+g338gtMEUOtuK+4dEMhiQEgxpxOKII=
|
||||||
github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec h1:2tTW6cDth2TSgRbAhD7yjZzTQmcN25sDRPEeinR51yQ=
|
|
||||||
github.com/letsencrypt/boulder v0.0.0-20240620165639-de9c06129bec/go.mod h1:TmwEoGCwIti7BCeJ9hescZgRtatxRE+A72pCoPfmcfk=
|
|
||||||
github.com/lucasb-eyer/go-colorful v1.2.0 h1:1nnpGOrhyZZuNyfu1QjKiUICQ74+3FNCN69Aj6K7nkY=
|
github.com/lucasb-eyer/go-colorful v1.2.0 h1:1nnpGOrhyZZuNyfu1QjKiUICQ74+3FNCN69Aj6K7nkY=
|
||||||
github.com/lucasb-eyer/go-colorful v1.2.0/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0=
|
github.com/lucasb-eyer/go-colorful v1.2.0/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0=
|
||||||
github.com/lufia/plan9stats v0.0.0-20240909124753-873cd0166683 h1:7UMa6KCCMjZEMDtTVdcGu0B1GmmC7QJKiCCjyTAWQy0=
|
github.com/lufia/plan9stats v0.0.0-20240909124753-873cd0166683 h1:7UMa6KCCMjZEMDtTVdcGu0B1GmmC7QJKiCCjyTAWQy0=
|
||||||
|
|
@ -321,20 +315,20 @@ github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55 h1:o4JXh1EVt
|
||||||
github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55/go.mod h1:OmDBASR4679mdNQnz2pUhc2G8CO2JrUAVFDRBDP/hJE=
|
github.com/power-devops/perfstat v0.0.0-20240221224432-82ca36839d55/go.mod h1:OmDBASR4679mdNQnz2pUhc2G8CO2JrUAVFDRBDP/hJE=
|
||||||
github.com/proglottis/gpgme v0.1.5 h1:KCGyOw8sQ+SI96j6G8D8YkOGn+1TwbQTT9/zQXoVlz0=
|
github.com/proglottis/gpgme v0.1.5 h1:KCGyOw8sQ+SI96j6G8D8YkOGn+1TwbQTT9/zQXoVlz0=
|
||||||
github.com/proglottis/gpgme v0.1.5/go.mod h1:5LoXMgpE4bttgwwdv9bLs/vwqv3qV7F4glEEZ7mRKrM=
|
github.com/proglottis/gpgme v0.1.5/go.mod h1:5LoXMgpE4bttgwwdv9bLs/vwqv3qV7F4glEEZ7mRKrM=
|
||||||
github.com/prometheus/client_golang v1.22.0 h1:rb93p9lokFEsctTys46VnV1kLCDpVZ0a/Y92Vm0Zc6Q=
|
github.com/prometheus/client_golang v1.23.2 h1:Je96obch5RDVy3FDMndoUsjAhG5Edi49h0RJWRi/o0o=
|
||||||
github.com/prometheus/client_golang v1.22.0/go.mod h1:R7ljNsLXhuQXYZYtw6GAE9AZg8Y7vEW5scdCXrWRXC0=
|
github.com/prometheus/client_golang v1.23.2/go.mod h1:Tb1a6LWHB3/SPIzCoaDXI4I8UHKeFTEQ1YCr+0Gyqmg=
|
||||||
github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk=
|
github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk=
|
||||||
github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE=
|
github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE=
|
||||||
github.com/prometheus/common v0.63.0 h1:YR/EIY1o3mEFP/kZCD7iDMnLPlGyuU2Gb3HIcXnA98k=
|
github.com/prometheus/common v0.67.4 h1:yR3NqWO1/UyO1w2PhUvXlGQs/PtFmoveVO0KZ4+Lvsc=
|
||||||
github.com/prometheus/common v0.63.0/go.mod h1:VVFF/fBIoToEnWRVkYoXEkq3R3paCoxG9PXP74SnV18=
|
github.com/prometheus/common v0.67.4/go.mod h1:gP0fq6YjjNCLssJCQp0yk4M8W6ikLURwkdd/YKtTbyI=
|
||||||
github.com/prometheus/procfs v0.15.1 h1:YagwOFzUgYfKKHX6Dr+sHT7km/hxC76UB0learggepc=
|
github.com/prometheus/procfs v0.16.1 h1:hZ15bTNuirocR6u0JZ6BAHHmwS1p8B4P6MRqxtzMyRg=
|
||||||
github.com/prometheus/procfs v0.15.1/go.mod h1:fB45yRUv8NstnjriLhBQLuOUt+WW4BsoGhij/e3PBqk=
|
github.com/prometheus/procfs v0.16.1/go.mod h1:teAbpZRB1iIAJYREa1LsoWUXykVXA1KlTmWl8x/U+Is=
|
||||||
github.com/rivo/uniseg v0.2.0/go.mod h1:J6wj4VEh+S6ZtnVlnTBMWIodfgj8LQOQFoIToxlJtxc=
|
github.com/rivo/uniseg v0.2.0/go.mod h1:J6wj4VEh+S6ZtnVlnTBMWIodfgj8LQOQFoIToxlJtxc=
|
||||||
github.com/rivo/uniseg v0.4.3/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88=
|
github.com/rivo/uniseg v0.4.3/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88=
|
||||||
github.com/rivo/uniseg v0.4.7 h1:WUdvkW8uEhrYfLC4ZzdpI2ztxP1I582+49Oc5Mq64VQ=
|
github.com/rivo/uniseg v0.4.7 h1:WUdvkW8uEhrYfLC4ZzdpI2ztxP1I582+49Oc5Mq64VQ=
|
||||||
github.com/rivo/uniseg v0.4.7/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88=
|
github.com/rivo/uniseg v0.4.7/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88=
|
||||||
github.com/rogpeppe/go-internal v1.13.1 h1:KvO1DLK/DRN07sQ1LQKScxyZJuNnedQ5/wKSR38lUII=
|
github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ=
|
||||||
github.com/rogpeppe/go-internal v1.13.1/go.mod h1:uMEvuHeurkdAXX61udpOXGD/AzZDWNMNyH2VO9fmH0o=
|
github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc=
|
||||||
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
|
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
|
||||||
github.com/samber/lo v1.31.0 h1:Sfa+/064Tdo4SvlohQUQzBhgSer9v/coGvKQI/XLWAM=
|
github.com/samber/lo v1.31.0 h1:Sfa+/064Tdo4SvlohQUQzBhgSer9v/coGvKQI/XLWAM=
|
||||||
github.com/samber/lo v1.31.0/go.mod h1:HLeWcJRRyLKp3+/XBJvOrerCQn9mhdKMHyd7IRlgeQ8=
|
github.com/samber/lo v1.31.0/go.mod h1:HLeWcJRRyLKp3+/XBJvOrerCQn9mhdKMHyd7IRlgeQ8=
|
||||||
|
|
@ -352,20 +346,20 @@ github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3 h1:n661drycOFuPLCN
|
||||||
github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3/go.mod h1:A0bzQcvG0E7Rwjx0REVgAGH58e96+X0MeOfepqsbeW4=
|
github.com/sergi/go-diff v1.3.2-0.20230802210424-5b0b94c5c0d3/go.mod h1:A0bzQcvG0E7Rwjx0REVgAGH58e96+X0MeOfepqsbeW4=
|
||||||
github.com/shirou/gopsutil/v4 v4.25.9 h1:JImNpf6gCVhKgZhtaAHJ0serfFGtlfIlSC08eaKdTrU=
|
github.com/shirou/gopsutil/v4 v4.25.9 h1:JImNpf6gCVhKgZhtaAHJ0serfFGtlfIlSC08eaKdTrU=
|
||||||
github.com/shirou/gopsutil/v4 v4.25.9/go.mod h1:gxIxoC+7nQRwUl/xNhutXlD8lq+jxTgpIkEf3rADHL8=
|
github.com/shirou/gopsutil/v4 v4.25.9/go.mod h1:gxIxoC+7nQRwUl/xNhutXlD8lq+jxTgpIkEf3rADHL8=
|
||||||
github.com/sigstore/fulcio v1.7.1 h1:RcoW20Nz49IGeZyu3y9QYhyyV3ZKQ85T+FXPKkvE+aQ=
|
github.com/sigstore/fulcio v1.8.3 h1:zkuAkRHbD53hhYGlBHHeAW4NRDrrTiDHumAbcfSyyFw=
|
||||||
github.com/sigstore/fulcio v1.7.1/go.mod h1:7lYY+hsd8Dt+IvKQRC+KEhWpCZ/GlmNvwIa5JhypMS8=
|
github.com/sigstore/fulcio v1.8.3/go.mod h1:YxP7TTdn9H5Gg+dXOsu61X36LLYxT2ZuvODhWelMNwA=
|
||||||
github.com/sigstore/protobuf-specs v0.4.1 h1:5SsMqZbdkcO/DNHudaxuCUEjj6x29tS2Xby1BxGU7Zc=
|
github.com/sigstore/protobuf-specs v0.5.0 h1:F8YTI65xOHw70NrvPwJ5PhAzsvTnuJMGLkA4FIkofAY=
|
||||||
github.com/sigstore/protobuf-specs v0.4.1/go.mod h1:+gXR+38nIa2oEupqDdzg4qSBT0Os+sP7oYv6alWewWc=
|
github.com/sigstore/protobuf-specs v0.5.0/go.mod h1:+gXR+38nIa2oEupqDdzg4qSBT0Os+sP7oYv6alWewWc=
|
||||||
github.com/sigstore/sigstore v1.9.5 h1:Wm1LT9yF4LhQdEMy5A2JeGRHTrAWGjT3ubE5JUSrGVU=
|
github.com/sigstore/sigstore v1.10.0 h1:lQrmdzqlR8p9SCfWIpFoGUqdXEzJSZT2X+lTXOMPaQI=
|
||||||
github.com/sigstore/sigstore v1.9.5/go.mod h1:VtxgvGqCmEZN9X2zhFSOkfXxvKUjpy8RpUW39oCtoII=
|
github.com/sigstore/sigstore v1.10.0/go.mod h1:Ygq+L/y9Bm3YnjpJTlQrOk/gXyrjkpn3/AEJpmk1n9Y=
|
||||||
github.com/sirupsen/logrus v1.9.3 h1:dueUQJ1C2q9oE3F7wvmSGAaVtTmUizReu6fjN8uqzbQ=
|
github.com/sirupsen/logrus v1.9.3 h1:dueUQJ1C2q9oE3F7wvmSGAaVtTmUizReu6fjN8uqzbQ=
|
||||||
github.com/sirupsen/logrus v1.9.3/go.mod h1:naHLuLoDiP4jHNo9R0sCBMtWGeIprob74mVsIT4qYEQ=
|
github.com/sirupsen/logrus v1.9.3/go.mod h1:naHLuLoDiP4jHNo9R0sCBMtWGeIprob74mVsIT4qYEQ=
|
||||||
github.com/skeema/knownhosts v1.3.2 h1:EDL9mgf4NzwMXCTfaxSD/o/a5fxDw/xL9nkU28JjdBg=
|
github.com/skeema/knownhosts v1.3.2 h1:EDL9mgf4NzwMXCTfaxSD/o/a5fxDw/xL9nkU28JjdBg=
|
||||||
github.com/skeema/knownhosts v1.3.2/go.mod h1:bEg3iQAuw+jyiw+484wwFJoKSLwcfd7fqRy+N0QTiow=
|
github.com/skeema/knownhosts v1.3.2/go.mod h1:bEg3iQAuw+jyiw+484wwFJoKSLwcfd7fqRy+N0QTiow=
|
||||||
github.com/smallstep/pkcs7 v0.1.1 h1:x+rPdt2W088V9Vkjho4KtoggyktZJlMduZAtRHm68LU=
|
github.com/smallstep/pkcs7 v0.1.1 h1:x+rPdt2W088V9Vkjho4KtoggyktZJlMduZAtRHm68LU=
|
||||||
github.com/smallstep/pkcs7 v0.1.1/go.mod h1:dL6j5AIz9GHjVEBTXtW+QliALcgM19RtXaTeyxI+AfA=
|
github.com/smallstep/pkcs7 v0.1.1/go.mod h1:dL6j5AIz9GHjVEBTXtW+QliALcgM19RtXaTeyxI+AfA=
|
||||||
github.com/spf13/cobra v1.10.1 h1:lJeBwCfmrnXthfAupyUTzJ/J4Nc1RsHC/mSRU2dll/s=
|
github.com/spf13/cobra v1.10.2 h1:DMTTonx5m65Ic0GOoRY2c16WCbHxOOw6xxezuLaBpcU=
|
||||||
github.com/spf13/cobra v1.10.1/go.mod h1:7SmJGaTHFVBY0jW4NXGluQoLvhqFQM+6XSKD+P4XaB0=
|
github.com/spf13/cobra v1.10.2/go.mod h1:7C1pvHqHw5A4vrJfjNwvOdzYu0Gml16OCs2GRiTUUS4=
|
||||||
github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
|
github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
|
||||||
github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk=
|
github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk=
|
||||||
github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
|
github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
|
||||||
|
|
@ -391,8 +385,6 @@ github.com/tchap/go-patricia/v2 v2.3.3 h1:xfNEsODumaEcCcY3gI0hYPZ/PcpVv5ju6RMAhg
|
||||||
github.com/tchap/go-patricia/v2 v2.3.3/go.mod h1:VZRHKAb53DLaG+nA9EaYYiaEx6YztwDlLElMsnSHD4k=
|
github.com/tchap/go-patricia/v2 v2.3.3/go.mod h1:VZRHKAb53DLaG+nA9EaYYiaEx6YztwDlLElMsnSHD4k=
|
||||||
github.com/thoas/go-funk v0.9.1 h1:O549iLZqPpTUQ10ykd26sZhzD+rmR5pWhuElrhbC20M=
|
github.com/thoas/go-funk v0.9.1 h1:O549iLZqPpTUQ10ykd26sZhzD+rmR5pWhuElrhbC20M=
|
||||||
github.com/thoas/go-funk v0.9.1/go.mod h1:+IWnUfUmFO1+WVYQWQtIJHeRRdaIyyYglZN7xzUPe4Q=
|
github.com/thoas/go-funk v0.9.1/go.mod h1:+IWnUfUmFO1+WVYQWQtIJHeRRdaIyyYglZN7xzUPe4Q=
|
||||||
github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 h1:e/5i7d4oYZ+C1wj2THlRK+oAhjeS/TRQwMfkIuet3w0=
|
|
||||||
github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399/go.mod h1:LdwHTNJT99C5fTAzDz0ud328OgXz+gierycbcIx2fRs=
|
|
||||||
github.com/tklauser/go-sysconf v0.3.15 h1:VE89k0criAymJ/Os65CSn1IXaol+1wrsFHEB8Ol49K4=
|
github.com/tklauser/go-sysconf v0.3.15 h1:VE89k0criAymJ/Os65CSn1IXaol+1wrsFHEB8Ol49K4=
|
||||||
github.com/tklauser/go-sysconf v0.3.15/go.mod h1:Dmjwr6tYFIseJw7a3dRLJfsHAMXZ3nEnL/aZY+0IuI4=
|
github.com/tklauser/go-sysconf v0.3.15/go.mod h1:Dmjwr6tYFIseJw7a3dRLJfsHAMXZ3nEnL/aZY+0IuI4=
|
||||||
github.com/tklauser/numcpus v0.10.0 h1:18njr6LDBk1zuna922MgdjQuJFjrdppsZG60sHGfjso=
|
github.com/tklauser/numcpus v0.10.0 h1:18njr6LDBk1zuna922MgdjQuJFjrdppsZG60sHGfjso=
|
||||||
|
|
@ -422,26 +414,26 @@ github.com/yusufpapurcu/wmi v1.2.4 h1:zFUKzehAFReQwLys1b/iSMl+JQGSCSjtVqQn9bBrPo
|
||||||
github.com/yusufpapurcu/wmi v1.2.4/go.mod h1:SBZ9tNy3G9/m5Oi98Zks0QjeHVDvuK0qfxQmPyzfmi0=
|
github.com/yusufpapurcu/wmi v1.2.4/go.mod h1:SBZ9tNy3G9/m5Oi98Zks0QjeHVDvuK0qfxQmPyzfmi0=
|
||||||
go.etcd.io/bbolt v1.4.3 h1:dEadXpI6G79deX5prL3QRNP6JB8UxVkqo4UPnHaNXJo=
|
go.etcd.io/bbolt v1.4.3 h1:dEadXpI6G79deX5prL3QRNP6JB8UxVkqo4UPnHaNXJo=
|
||||||
go.etcd.io/bbolt v1.4.3/go.mod h1:tKQlpPaYCVFctUIgFKFnAlvbmB3tpy1vkTnDWohtc0E=
|
go.etcd.io/bbolt v1.4.3/go.mod h1:tKQlpPaYCVFctUIgFKFnAlvbmB3tpy1vkTnDWohtc0E=
|
||||||
go.opentelemetry.io/auto/sdk v1.1.0 h1:cH53jehLUN6UFLY71z+NDOiNJqDdPRaXzTel0sJySYA=
|
go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64=
|
||||||
go.opentelemetry.io/auto/sdk v1.1.0/go.mod h1:3wSPjt5PWp2RhlCcmmOial7AvC4DQqZb7a7wCow3W8A=
|
go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y=
|
||||||
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0 h1:F7Jx+6hwnZ41NSFTO5q4LYDtJRXBf2PD0rNBkeB/lus=
|
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 h1:RbKq8BG0FI8OiXhBfcRtqqHcZcka+gU3cskNuf05R18=
|
||||||
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.61.0/go.mod h1:UHB22Z8QsdRDrnAtX4PntOl36ajSxcdUMt1sF7Y6E7Q=
|
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0/go.mod h1:h06DGIukJOevXaj/xrNjhi/2098RZzcLTbc0jDAUbsg=
|
||||||
go.opentelemetry.io/otel v1.36.0 h1:UumtzIklRBY6cI/lllNZlALOF5nNIzJVb16APdvgTXg=
|
go.opentelemetry.io/otel v1.38.0 h1:RkfdswUDRimDg0m2Az18RKOsnI8UDzppJAtj01/Ymk8=
|
||||||
go.opentelemetry.io/otel v1.36.0/go.mod h1:/TcFMXYjyRNh8khOAO9ybYkqaDBb/70aVwkNML4pP8E=
|
go.opentelemetry.io/otel v1.38.0/go.mod h1:zcmtmQ1+YmQM9wrNsTGV/q/uyusom3P8RxwExxkZhjM=
|
||||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.35.0 h1:1fTNlAIJZGWLP5FVu0fikVry1IsiUnXjf7QFvoNN3Xw=
|
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.38.0 h1:GqRJVj7UmLjCVyVJ3ZFLdPRmhDUp2zFmQe3RHIOsw24=
|
||||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.35.0/go.mod h1:zjPK58DtkqQFn+YUMbx0M2XV3QgKU0gS9LeGohREyK4=
|
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.38.0/go.mod h1:ri3aaHSmCTVYu2AWv44YMauwAQc0aqI9gHKIcSbI1pU=
|
||||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.35.0 h1:xJ2qHD0C1BeYVTLLR9sX12+Qb95kfeD/byKj6Ky1pXg=
|
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.35.0 h1:xJ2qHD0C1BeYVTLLR9sX12+Qb95kfeD/byKj6Ky1pXg=
|
||||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.35.0/go.mod h1:u5BF1xyjstDowA1R5QAO9JHzqK+ublenEW/dyqTjBVk=
|
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.35.0/go.mod h1:u5BF1xyjstDowA1R5QAO9JHzqK+ublenEW/dyqTjBVk=
|
||||||
go.opentelemetry.io/otel/metric v1.36.0 h1:MoWPKVhQvJ+eeXWHFBOPoBOi20jh6Iq2CcCREuTYufE=
|
go.opentelemetry.io/otel/metric v1.38.0 h1:Kl6lzIYGAh5M159u9NgiRkmoMKjvbsKtYRwgfrA6WpA=
|
||||||
go.opentelemetry.io/otel/metric v1.36.0/go.mod h1:zC7Ks+yeyJt4xig9DEw9kuUFe5C3zLbVjV2PzT6qzbs=
|
go.opentelemetry.io/otel/metric v1.38.0/go.mod h1:kB5n/QoRM8YwmUahxvI3bO34eVtQf2i4utNVLr9gEmI=
|
||||||
go.opentelemetry.io/otel/sdk v1.36.0 h1:b6SYIuLRs88ztox4EyrvRti80uXIFy+Sqzoh9kFULbs=
|
go.opentelemetry.io/otel/sdk v1.38.0 h1:l48sr5YbNf2hpCUj/FoGhW9yDkl+Ma+LrVl8qaM5b+E=
|
||||||
go.opentelemetry.io/otel/sdk v1.36.0/go.mod h1:+lC+mTgD+MUWfjJubi2vvXWcVxyr9rmlshZni72pXeY=
|
go.opentelemetry.io/otel/sdk v1.38.0/go.mod h1:ghmNdGlVemJI3+ZB5iDEuk4bWA3GkTpW+DOoZMYBVVg=
|
||||||
go.opentelemetry.io/otel/sdk/metric v1.36.0 h1:r0ntwwGosWGaa0CrSt8cuNuTcccMXERFwHX4dThiPis=
|
go.opentelemetry.io/otel/sdk/metric v1.38.0 h1:aSH66iL0aZqo//xXzQLYozmWrXxyFkBJ6qT5wthqPoM=
|
||||||
go.opentelemetry.io/otel/sdk/metric v1.36.0/go.mod h1:qTNOhFDfKRwX0yXOqJYegL5WRaW376QbB7P4Pb0qva4=
|
go.opentelemetry.io/otel/sdk/metric v1.38.0/go.mod h1:dg9PBnW9XdQ1Hd6ZnRz689CbtrUp0wMMs9iPcgT9EZA=
|
||||||
go.opentelemetry.io/otel/trace v1.36.0 h1:ahxWNuqZjpdiFAyrIoQ4GIiAIhxAunQR6MUoKrsNd4w=
|
go.opentelemetry.io/otel/trace v1.38.0 h1:Fxk5bKrDZJUH+AMyyIXGcFAPah0oRcT+LuNtJrmcNLE=
|
||||||
go.opentelemetry.io/otel/trace v1.36.0/go.mod h1:gQ+OnDZzrybY4k4seLzPAWNwVBBVlF2szhehOBB/tGA=
|
go.opentelemetry.io/otel/trace v1.38.0/go.mod h1:j1P9ivuFsTceSWe1oY+EeW3sc+Pp42sO++GHkg4wwhs=
|
||||||
go.opentelemetry.io/proto/otlp v1.5.0 h1:xJvq7gMzB31/d406fB8U5CBdyQGw4P399D1aQWU/3i4=
|
go.opentelemetry.io/proto/otlp v1.7.1 h1:gTOMpGDb0WTBOP8JaO72iL3auEZhVmAQg4ipjOVAtj4=
|
||||||
go.opentelemetry.io/proto/otlp v1.5.0/go.mod h1:keN8WnHxOy8PG0rQZjJJ5A2ebUoafqWp0eVQ4yIXvJ4=
|
go.opentelemetry.io/proto/otlp v1.7.1/go.mod h1:b2rVh6rfI/s2pHWNlB7ILJcRALpcNDzKhACevjI+ZnE=
|
||||||
go.podman.io/common v0.66.1 h1:zDyd4HhVgQAN8LupBHCnhtM3FEOJ9DwmThjulXZq2qA=
|
go.podman.io/common v0.66.1 h1:zDyd4HhVgQAN8LupBHCnhtM3FEOJ9DwmThjulXZq2qA=
|
||||||
go.podman.io/common v0.66.1/go.mod h1:aNd2a0S7pY+fx1X5kpQYuF4hbwLU8ZOccuVrhu7h1Xc=
|
go.podman.io/common v0.66.1/go.mod h1:aNd2a0S7pY+fx1X5kpQYuF4hbwLU8ZOccuVrhu7h1Xc=
|
||||||
go.podman.io/image/v5 v5.38.0 h1:aUKrCANkPvze1bnhLJsaubcfz0d9v/bSDLnwsXJm6G4=
|
go.podman.io/image/v5 v5.38.0 h1:aUKrCANkPvze1bnhLJsaubcfz0d9v/bSDLnwsXJm6G4=
|
||||||
|
|
@ -450,8 +442,8 @@ go.podman.io/storage v1.61.0 h1:5hD/oyRYt1f1gxgvect+8syZBQhGhV28dCw2+CZpx0Q=
|
||||||
go.podman.io/storage v1.61.0/go.mod h1:A3UBK0XypjNZ6pghRhuxg62+2NIm5lcUGv/7XyMhMUI=
|
go.podman.io/storage v1.61.0/go.mod h1:A3UBK0XypjNZ6pghRhuxg62+2NIm5lcUGv/7XyMhMUI=
|
||||||
go.uber.org/automaxprocs v1.6.0 h1:O3y2/QNTOdbF+e/dpXNNW7Rx2hZ4sTIPyybbxyNqTUs=
|
go.uber.org/automaxprocs v1.6.0 h1:O3y2/QNTOdbF+e/dpXNNW7Rx2hZ4sTIPyybbxyNqTUs=
|
||||||
go.uber.org/automaxprocs v1.6.0/go.mod h1:ifeIMSnPZuznNm6jmdzmU3/bfk01Fe2fotchwEFJ8r8=
|
go.uber.org/automaxprocs v1.6.0/go.mod h1:ifeIMSnPZuznNm6jmdzmU3/bfk01Fe2fotchwEFJ8r8=
|
||||||
go.yaml.in/yaml/v2 v2.4.2 h1:DzmwEr2rDGHl7lsFgAHxmNz/1NlQ7xLIrlN2h5d1eGI=
|
go.yaml.in/yaml/v2 v2.4.3 h1:6gvOSjQoTB3vt1l+CU+tSyi/HOjfOjRLJ4YwYZGwRO0=
|
||||||
go.yaml.in/yaml/v2 v2.4.2/go.mod h1:081UH+NErpNdqlCXm3TtEran0rJZGxAYx9hb/ELlsPU=
|
go.yaml.in/yaml/v2 v2.4.3/go.mod h1:zSxWcmIDjOzPXpjlTTbAsKokqkDNAVtZO0WOMiT90s8=
|
||||||
go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
|
go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
|
||||||
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
|
go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
|
||||||
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
|
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
|
||||||
|
|
@ -463,8 +455,8 @@ golang.org/x/crypto v0.19.0/go.mod h1:Iy9bg/ha4yyC70EfRS8jz+B6ybOBKMaSxLj6P6oBDf
|
||||||
golang.org/x/crypto v0.23.0/go.mod h1:CKFgDieR+mRhux2Lsu27y0fO304Db0wZe70UKqHu0v8=
|
golang.org/x/crypto v0.23.0/go.mod h1:CKFgDieR+mRhux2Lsu27y0fO304Db0wZe70UKqHu0v8=
|
||||||
golang.org/x/crypto v0.30.0/go.mod h1:kDsLvtWBEx7MV9tJOj9bnXsPbxwJQ6csT/x4KIN4Ssk=
|
golang.org/x/crypto v0.30.0/go.mod h1:kDsLvtWBEx7MV9tJOj9bnXsPbxwJQ6csT/x4KIN4Ssk=
|
||||||
golang.org/x/crypto v0.31.0/go.mod h1:kDsLvtWBEx7MV9tJOj9bnXsPbxwJQ6csT/x4KIN4Ssk=
|
golang.org/x/crypto v0.31.0/go.mod h1:kDsLvtWBEx7MV9tJOj9bnXsPbxwJQ6csT/x4KIN4Ssk=
|
||||||
golang.org/x/crypto v0.43.0 h1:dduJYIi3A3KOfdGOHX8AVZ/jGiyPa3IbBozJ5kNuE04=
|
golang.org/x/crypto v0.45.0 h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=
|
||||||
golang.org/x/crypto v0.43.0/go.mod h1:BFbav4mRNlXJL4wNeejLpWxB7wMbc79PdRGhWKncxR0=
|
golang.org/x/crypto v0.45.0/go.mod h1:XTGrrkGJve7CYK7J8PEww4aY7gM3qMCElcJQ8n8JdX4=
|
||||||
golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0 h1:R84qjqJb5nVJMxqWYb3np9L5ZsaDtB+a39EqjV0JSUM=
|
golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0 h1:R84qjqJb5nVJMxqWYb3np9L5ZsaDtB+a39EqjV0JSUM=
|
||||||
golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0/go.mod h1:S9Xr4PYopiDyqSyp5NjCrhFrqg6A5zA2E/iPHPhqnS8=
|
golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0/go.mod h1:S9Xr4PYopiDyqSyp5NjCrhFrqg6A5zA2E/iPHPhqnS8=
|
||||||
golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
||||||
|
|
@ -474,8 +466,8 @@ golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
|
||||||
golang.org/x/mod v0.12.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
|
golang.org/x/mod v0.12.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
|
||||||
golang.org/x/mod v0.15.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
|
golang.org/x/mod v0.15.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
|
||||||
golang.org/x/mod v0.17.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
|
golang.org/x/mod v0.17.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
|
||||||
golang.org/x/mod v0.28.0 h1:gQBtGhjxykdjY9YhZpSlZIsbnaE2+PgjfLWUQTnoZ1U=
|
golang.org/x/mod v0.29.0 h1:HV8lRxZC4l2cr3Zq1LvtOsi/ThTgWnUk/y64QSs8GwA=
|
||||||
golang.org/x/mod v0.28.0/go.mod h1:yfB/L0NOf/kmEbXjzCPOx1iK1fRutOydrCMsqRhEBxI=
|
golang.org/x/mod v0.29.0/go.mod h1:NyhrlYXJ2H4eJiRy/WDBO6HMqZQ6q9nk4JzS3NuCK+w=
|
||||||
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
|
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
|
||||||
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
||||||
golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
||||||
|
|
@ -487,8 +479,8 @@ golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg=
|
||||||
golang.org/x/net v0.15.0/go.mod h1:idbUs1IY1+zTqbi8yxTbhexhEEk5ur9LInksu6HrEpk=
|
golang.org/x/net v0.15.0/go.mod h1:idbUs1IY1+zTqbi8yxTbhexhEEk5ur9LInksu6HrEpk=
|
||||||
golang.org/x/net v0.21.0/go.mod h1:bIjVDfnllIU7BJ2DNgfnXvpSvtn8VRwhlsaeUTyUS44=
|
golang.org/x/net v0.21.0/go.mod h1:bIjVDfnllIU7BJ2DNgfnXvpSvtn8VRwhlsaeUTyUS44=
|
||||||
golang.org/x/net v0.25.0/go.mod h1:JkAGAh7GEvH74S6FOH42FLoXpXbE/aqXSrIQjXgsiwM=
|
golang.org/x/net v0.25.0/go.mod h1:JkAGAh7GEvH74S6FOH42FLoXpXbE/aqXSrIQjXgsiwM=
|
||||||
golang.org/x/net v0.45.0 h1:RLBg5JKixCy82FtLJpeNlVM0nrSqpCRYzVU1n8kj0tM=
|
golang.org/x/net v0.47.0 h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=
|
||||||
golang.org/x/net v0.45.0/go.mod h1:ECOoLqd5U3Lhyeyo/QDCEVQ4sNgYsqvCZ722XogGieY=
|
golang.org/x/net v0.47.0/go.mod h1:/jNxtkgq5yWUGYkaZGqo27cfGZ1c5Nen03aYrrKpVRU=
|
||||||
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||||
golang.org/x/sync v0.0.0-20190911185100-cd5d95a43a6e/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
golang.org/x/sync v0.0.0-20190911185100-cd5d95a43a6e/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||||
golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||||
|
|
@ -498,8 +490,8 @@ golang.org/x/sync v0.3.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y=
|
||||||
golang.org/x/sync v0.6.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
|
golang.org/x/sync v0.6.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
|
||||||
golang.org/x/sync v0.7.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
|
golang.org/x/sync v0.7.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
|
||||||
golang.org/x/sync v0.10.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
|
golang.org/x/sync v0.10.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
|
||||||
golang.org/x/sync v0.17.0 h1:l60nONMj9l5drqw6jlhIELNv9I0A4OFgRsG9k2oT9Ug=
|
golang.org/x/sync v0.18.0 h1:kr88TuHDroi+UVf+0hZnirlk8o8T+4MrK6mr60WkH/I=
|
||||||
golang.org/x/sync v0.17.0/go.mod h1:9KTHXmSnoGruLpwFjVSX0lNNA75CykiMECbovNTZqGI=
|
golang.org/x/sync v0.18.0/go.mod h1:9KTHXmSnoGruLpwFjVSX0lNNA75CykiMECbovNTZqGI=
|
||||||
golang.org/x/sys v0.0.0-20181122145206-62eef0e2fa9b/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
golang.org/x/sys v0.0.0-20181122145206-62eef0e2fa9b/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||||
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||||
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||||
|
|
@ -525,8 +517,8 @@ golang.org/x/sys v0.12.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||||
golang.org/x/sys v0.17.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
|
golang.org/x/sys v0.17.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
|
||||||
golang.org/x/sys v0.20.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
|
golang.org/x/sys v0.20.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
|
||||||
golang.org/x/sys v0.28.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
|
golang.org/x/sys v0.28.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
|
||||||
golang.org/x/sys v0.37.0 h1:fdNQudmxPjkdUTPnLn5mdQv7Zwvbvpaxqs831goi9kQ=
|
golang.org/x/sys v0.38.0 h1:3yZWxaJjBmCWXqhN1qh02AkOnCQ1poK6oF+a7xWL6Gc=
|
||||||
golang.org/x/sys v0.37.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
|
golang.org/x/sys v0.38.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
|
||||||
golang.org/x/telemetry v0.0.0-20240228155512-f48c80bd79b2/go.mod h1:TeRTkGYfJXctD9OcfyVLyj2J3IxLnKwHJR8f4D8a3YE=
|
golang.org/x/telemetry v0.0.0-20240228155512-f48c80bd79b2/go.mod h1:TeRTkGYfJXctD9OcfyVLyj2J3IxLnKwHJR8f4D8a3YE=
|
||||||
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
|
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
|
||||||
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
|
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
|
||||||
|
|
@ -536,8 +528,8 @@ golang.org/x/term v0.12.0/go.mod h1:owVbMEjm3cBLCHdkQu9b1opXd4ETQWc3BhuQGKgXgvU=
|
||||||
golang.org/x/term v0.17.0/go.mod h1:lLRBjIVuehSbZlaOtGMbcMncT+aqLLLmKrsjNrUguwk=
|
golang.org/x/term v0.17.0/go.mod h1:lLRBjIVuehSbZlaOtGMbcMncT+aqLLLmKrsjNrUguwk=
|
||||||
golang.org/x/term v0.20.0/go.mod h1:8UkIAJTvZgivsXaD6/pH6U9ecQzZ45awqEOzuCvwpFY=
|
golang.org/x/term v0.20.0/go.mod h1:8UkIAJTvZgivsXaD6/pH6U9ecQzZ45awqEOzuCvwpFY=
|
||||||
golang.org/x/term v0.27.0/go.mod h1:iMsnZpn0cago0GOrHO2+Y7u7JPn5AylBrcoWkElMTSM=
|
golang.org/x/term v0.27.0/go.mod h1:iMsnZpn0cago0GOrHO2+Y7u7JPn5AylBrcoWkElMTSM=
|
||||||
golang.org/x/term v0.36.0 h1:zMPR+aF8gfksFprF/Nc/rd1wRS1EI6nDBGyWAvDzx2Q=
|
golang.org/x/term v0.37.0 h1:8EGAD0qCmHYZg6J17DvsMy9/wJ7/D/4pV/wfnld5lTU=
|
||||||
golang.org/x/term v0.36.0/go.mod h1:Qu394IJq6V6dCBRgwqshf3mPF85AqzYEzofzRdZkWss=
|
golang.org/x/term v0.37.0/go.mod h1:5pB4lxRNYYVZuTLmy8oR2BH8dflOR+IbTYFD8fi3254=
|
||||||
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
|
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
|
||||||
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
|
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
|
||||||
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
|
golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
|
||||||
|
|
@ -547,10 +539,10 @@ golang.org/x/text v0.13.0/go.mod h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE=
|
||||||
golang.org/x/text v0.14.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU=
|
golang.org/x/text v0.14.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU=
|
||||||
golang.org/x/text v0.15.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU=
|
golang.org/x/text v0.15.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU=
|
||||||
golang.org/x/text v0.21.0/go.mod h1:4IBbMaMmOPCJ8SecivzSH54+73PCFmPWxNTLm+vZkEQ=
|
golang.org/x/text v0.21.0/go.mod h1:4IBbMaMmOPCJ8SecivzSH54+73PCFmPWxNTLm+vZkEQ=
|
||||||
golang.org/x/text v0.30.0 h1:yznKA/E9zq54KzlzBEAWn1NXSQ8DIp/NYMy88xJjl4k=
|
golang.org/x/text v0.31.0 h1:aC8ghyu4JhP8VojJ2lEHBnochRno1sgL6nEi9WGFGMM=
|
||||||
golang.org/x/text v0.30.0/go.mod h1:yDdHFIX9t+tORqspjENWgzaCVXgk0yYnYuSZ8UzzBVM=
|
golang.org/x/text v0.31.0/go.mod h1:tKRAlv61yKIjGGHX/4tP1LTbc13YSec1pxVEWXzfoeM=
|
||||||
golang.org/x/time v0.11.0 h1:/bpjEDfN9tkoN/ryeYHnv5hcMlc8ncjMcM4XBk5NWV0=
|
golang.org/x/time v0.14.0 h1:MRx4UaLrDotUKUdCIqzPC48t1Y9hANFKIRpNx+Te8PI=
|
||||||
golang.org/x/time v0.11.0/go.mod h1:CDIdPxbZBQxdj6cxyCIdrNogrJKMJ7pr37NYpMcMDSg=
|
golang.org/x/time v0.14.0/go.mod h1:eL/Oa2bBBK0TkX57Fyni+NgnyQQN4LitPmob2Hjnqw4=
|
||||||
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
|
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
|
||||||
golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo=
|
golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo=
|
||||||
golang.org/x/tools v0.0.0-20200619180055-7c47624df98f/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE=
|
golang.org/x/tools v0.0.0-20200619180055-7c47624df98f/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE=
|
||||||
|
|
@ -559,21 +551,23 @@ golang.org/x/tools v0.1.12/go.mod h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc
|
||||||
golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU=
|
golang.org/x/tools v0.6.0/go.mod h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU=
|
||||||
golang.org/x/tools v0.13.0/go.mod h1:HvlwmtVNQAhOuCjW7xxvovg8wbNq7LwfXh/k7wXUl58=
|
golang.org/x/tools v0.13.0/go.mod h1:HvlwmtVNQAhOuCjW7xxvovg8wbNq7LwfXh/k7wXUl58=
|
||||||
golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d/go.mod h1:aiJjzUbINMkxbQROHiO6hDPo2LHcIPhhQsa9DLh0yGk=
|
golang.org/x/tools v0.21.1-0.20240508182429-e35e4ccd0d2d/go.mod h1:aiJjzUbINMkxbQROHiO6hDPo2LHcIPhhQsa9DLh0yGk=
|
||||||
golang.org/x/tools v0.37.0 h1:DVSRzp7FwePZW356yEAChSdNcQo6Nsp+fex1SUW09lE=
|
golang.org/x/tools v0.38.0 h1:Hx2Xv8hISq8Lm16jvBZ2VQf+RLmbd7wVUsALibYI/IQ=
|
||||||
golang.org/x/tools v0.37.0/go.mod h1:MBN5QPQtLMHVdvsbtarmTNukZDdgwdwlO5qGacAzF0w=
|
golang.org/x/tools v0.38.0/go.mod h1:yEsQ/d/YK8cjh0L6rZlY8tgtlKiBNTL14pGDJPJpYQs=
|
||||||
golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||||
golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||||
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||||
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 h1:go1bK/D/BFZV2I8cIQd1NKEZ+0owSTG1fDTci4IqFcE=
|
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 h1:go1bK/D/BFZV2I8cIQd1NKEZ+0owSTG1fDTci4IqFcE=
|
||||||
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||||
google.golang.org/genproto/googleapis/api v0.0.0-20250414145226-207652e42e2e h1:UdXH7Kzbj+Vzastr5nVfccbmFsmYNygVLSPk1pEfDoY=
|
gonum.org/v1/gonum v0.16.0 h1:5+ul4Swaf3ESvrOnidPp4GZbzf0mxVQpDCYUQE7OJfk=
|
||||||
google.golang.org/genproto/googleapis/api v0.0.0-20250414145226-207652e42e2e/go.mod h1:085qFyf2+XaZlRdCgKNCIZ3afY2p4HHZdoIRpId8F4A=
|
gonum.org/v1/gonum v0.16.0/go.mod h1:fef3am4MQ93R2HHpKnLk4/Tbh/s0+wqD5nfa6Pnwy4E=
|
||||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20250414145226-207652e42e2e h1:ztQaXfzEXTmCBvbtWYRhJxW+0iJcz2qXfd38/e9l7bA=
|
google.golang.org/genproto/googleapis/api v0.0.0-20251022142026-3a174f9686a8 h1:mepRgnBZa07I4TRuomDE4sTIYieg/osKmzIf4USdWS4=
|
||||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20250414145226-207652e42e2e/go.mod h1:qQ0YXyHHx3XkvlzUtpXDkS29lDSafHMZBAZDc03LQ3A=
|
google.golang.org/genproto/googleapis/api v0.0.0-20251022142026-3a174f9686a8/go.mod h1:fDMmzKV90WSg1NbozdqrE64fkuTv6mlq2zxo9ad+3yo=
|
||||||
google.golang.org/grpc v1.72.2 h1:TdbGzwb82ty4OusHWepvFWGLgIbNo1/SUynEN0ssqv8=
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20251103181224-f26f9409b101 h1:tRPGkdGHuewF4UisLzzHHr1spKw92qLM98nIzxbC0wY=
|
||||||
google.golang.org/grpc v1.72.2/go.mod h1:wH5Aktxcg25y1I3w7H69nHfXdOG3UiadoBtjh3izSDM=
|
google.golang.org/genproto/googleapis/rpc v0.0.0-20251103181224-f26f9409b101/go.mod h1:7i2o+ce6H/6BluujYR+kqX3GKH+dChPTQU19wjRPiGk=
|
||||||
google.golang.org/protobuf v1.36.9 h1:w2gp2mA27hUeUzj9Ex9FBjsBm40zfaDtEWow293U7Iw=
|
google.golang.org/grpc v1.77.0 h1:wVVY6/8cGA6vvffn+wWK5ToddbgdU3d8MNENr4evgXM=
|
||||||
google.golang.org/protobuf v1.36.9/go.mod h1:fuxRtAxBytpl4zzqUh6/eyUujkJdNiuEkXntxiD/uRU=
|
google.golang.org/grpc v1.77.0/go.mod h1:z0BY1iVj0q8E1uSQCjL9cppRj+gnZjzDnzV0dHhrNig=
|
||||||
|
google.golang.org/protobuf v1.36.10 h1:AYd7cD/uASjIL6Q9LiTjz8JLcrh/88q5UObnmY3aOOE=
|
||||||
|
google.golang.org/protobuf v1.36.10/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
|
||||||
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
||||||
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk=
|
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk=
|
||||||
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q=
|
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q=
|
||||||
|
|
|
||||||
96
vendor/github.com/go-jose/go-jose/v4/CHANGELOG.md
generated
vendored
96
vendor/github.com/go-jose/go-jose/v4/CHANGELOG.md
generated
vendored
|
|
@ -1,96 +0,0 @@
|
||||||
# v4.0.4
|
|
||||||
|
|
||||||
## Fixed
|
|
||||||
|
|
||||||
- Reverted "Allow unmarshalling JSONWebKeySets with unsupported key types" as a
|
|
||||||
breaking change. See #136 / #137.
|
|
||||||
|
|
||||||
# v4.0.3
|
|
||||||
|
|
||||||
## Changed
|
|
||||||
|
|
||||||
- Allow unmarshalling JSONWebKeySets with unsupported key types (#130)
|
|
||||||
- Document that OpaqueKeyEncrypter can't be implemented (for now) (#129)
|
|
||||||
- Dependency updates
|
|
||||||
|
|
||||||
# v4.0.2
|
|
||||||
|
|
||||||
## Changed
|
|
||||||
|
|
||||||
- Improved documentation of Verify() to note that JSONWebKeySet is a supported
|
|
||||||
argument type (#104)
|
|
||||||
- Defined exported error values for missing x5c header and unsupported elliptic
|
|
||||||
curves error cases (#117)
|
|
||||||
|
|
||||||
# v4.0.1
|
|
||||||
|
|
||||||
## Fixed
|
|
||||||
|
|
||||||
- An attacker could send a JWE containing compressed data that used large
|
|
||||||
amounts of memory and CPU when decompressed by `Decrypt` or `DecryptMulti`.
|
|
||||||
Those functions now return an error if the decompressed data would exceed
|
|
||||||
250kB or 10x the compressed size (whichever is larger). Thanks to
|
|
||||||
Enze Wang@Alioth and Jianjun Chen@Zhongguancun Lab (@zer0yu and @chenjj)
|
|
||||||
for reporting.
|
|
||||||
|
|
||||||
# v4.0.0
|
|
||||||
|
|
||||||
This release makes some breaking changes in order to more thoroughly
|
|
||||||
address the vulnerabilities discussed in [Three New Attacks Against JSON Web
|
|
||||||
Tokens][1], "Sign/encrypt confusion", "Billion hash attack", and "Polyglot
|
|
||||||
token".
|
|
||||||
|
|
||||||
## Changed
|
|
||||||
|
|
||||||
- Limit JWT encryption types (exclude password or public key types) (#78)
|
|
||||||
- Enforce minimum length for HMAC keys (#85)
|
|
||||||
- jwt: match any audience in a list, rather than requiring all audiences (#81)
|
|
||||||
- jwt: accept only Compact Serialization (#75)
|
|
||||||
- jws: Add expected algorithms for signatures (#74)
|
|
||||||
- Require specifying expected algorithms for ParseEncrypted,
|
|
||||||
ParseSigned, ParseDetached, jwt.ParseEncrypted, jwt.ParseSigned,
|
|
||||||
jwt.ParseSignedAndEncrypted (#69, #74)
|
|
||||||
- Usually there is a small, known set of appropriate algorithms for a program
|
|
||||||
to use and it's a mistake to allow unexpected algorithms. For instance the
|
|
||||||
"billion hash attack" relies in part on programs accepting the PBES2
|
|
||||||
encryption algorithm and doing the necessary work even if they weren't
|
|
||||||
specifically configured to allow PBES2.
|
|
||||||
- Revert "Strip padding off base64 strings" (#82)
|
|
||||||
- The specs require base64url encoding without padding.
|
|
||||||
- Minimum supported Go version is now 1.21
|
|
||||||
|
|
||||||
## Added
|
|
||||||
|
|
||||||
- ParseSignedCompact, ParseSignedJSON, ParseEncryptedCompact, ParseEncryptedJSON.
|
|
||||||
- These allow parsing a specific serialization, as opposed to ParseSigned and
|
|
||||||
ParseEncrypted, which try to automatically detect which serialization was
|
|
||||||
provided. It's common to require a specific serialization for a specific
|
|
||||||
protocol - for instance JWT requires Compact serialization.
|
|
||||||
|
|
||||||
[1]: https://i.blackhat.com/BH-US-23/Presentations/US-23-Tervoort-Three-New-Attacks-Against-JSON-Web-Tokens.pdf
|
|
||||||
|
|
||||||
# v3.0.2
|
|
||||||
|
|
||||||
## Fixed
|
|
||||||
|
|
||||||
- DecryptMulti: handle decompression error (#19)
|
|
||||||
|
|
||||||
## Changed
|
|
||||||
|
|
||||||
- jwe/CompactSerialize: improve performance (#67)
|
|
||||||
- Increase the default number of PBKDF2 iterations to 600k (#48)
|
|
||||||
- Return the proper algorithm for ECDSA keys (#45)
|
|
||||||
|
|
||||||
## Added
|
|
||||||
|
|
||||||
- Add Thumbprint support for opaque signers (#38)
|
|
||||||
|
|
||||||
# v3.0.1
|
|
||||||
|
|
||||||
## Fixed
|
|
||||||
|
|
||||||
- Security issue: an attacker specifying a large "p2c" value can cause
|
|
||||||
JSONWebEncryption.Decrypt and JSONWebEncryption.DecryptMulti to consume large
|
|
||||||
amounts of CPU, causing a DoS. Thanks to Matt Schwager (@mschwager) for the
|
|
||||||
disclosure and to Tom Tervoort for originally publishing the category of attack.
|
|
||||||
https://i.blackhat.com/BH-US-23/Presentations/US-23-Tervoort-Three-New-Attacks-Against-JSON-Web-Tokens.pdf
|
|
||||||
76
vendor/github.com/go-jose/go-jose/v4/README.md
generated
vendored
76
vendor/github.com/go-jose/go-jose/v4/README.md
generated
vendored
|
|
@ -3,7 +3,6 @@
|
||||||
[](https://pkg.go.dev/github.com/go-jose/go-jose/v4)
|
[](https://pkg.go.dev/github.com/go-jose/go-jose/v4)
|
||||||
[](https://pkg.go.dev/github.com/go-jose/go-jose/v4/jwt)
|
[](https://pkg.go.dev/github.com/go-jose/go-jose/v4/jwt)
|
||||||
[](https://raw.githubusercontent.com/go-jose/go-jose/master/LICENSE)
|
[](https://raw.githubusercontent.com/go-jose/go-jose/master/LICENSE)
|
||||||
[](https://github.com/go-jose/go-jose/actions)
|
|
||||||
|
|
||||||
Package jose aims to provide an implementation of the Javascript Object Signing
|
Package jose aims to provide an implementation of the Javascript Object Signing
|
||||||
and Encryption set of standards. This includes support for JSON Web Encryption,
|
and Encryption set of standards. This includes support for JSON Web Encryption,
|
||||||
|
|
@ -29,17 +28,20 @@ libraries in other languages.
|
||||||
|
|
||||||
### Versions
|
### Versions
|
||||||
|
|
||||||
[Version 4](https://github.com/go-jose/go-jose)
|
The forthcoming Version 5 will be released with several breaking API changes,
|
||||||
([branch](https://github.com/go-jose/go-jose/tree/main),
|
and will require Golang's `encoding/json/v2`, which is currently requires
|
||||||
[doc](https://pkg.go.dev/github.com/go-jose/go-jose/v4), [releases](https://github.com/go-jose/go-jose/releases)) is the current stable version:
|
Go 1.25 built with GOEXPERIMENT=jsonv2.
|
||||||
|
|
||||||
|
Version 4 is the current stable version:
|
||||||
|
|
||||||
import "github.com/go-jose/go-jose/v4"
|
import "github.com/go-jose/go-jose/v4"
|
||||||
|
|
||||||
The old [square/go-jose](https://github.com/square/go-jose) repo contains the prior v1 and v2 versions, which
|
It supports at least the current and previous Golang release. Currently it
|
||||||
are still useable but not actively developed anymore.
|
requires Golang 1.24.
|
||||||
|
|
||||||
Version 3, in this repo, is still receiving security fixes but not functionality
|
Version 3 is only receiving critical security updates. Migration to Version 4 is recommended.
|
||||||
updates.
|
|
||||||
|
Versions 1 and 2 are obsolete, but can be found in the old repository, [square/go-jose](https://github.com/square/go-jose).
|
||||||
|
|
||||||
### Supported algorithms
|
### Supported algorithms
|
||||||
|
|
||||||
|
|
@ -47,36 +49,36 @@ See below for a table of supported algorithms. Algorithm identifiers match
|
||||||
the names in the [JSON Web Algorithms](https://dx.doi.org/10.17487/RFC7518)
|
the names in the [JSON Web Algorithms](https://dx.doi.org/10.17487/RFC7518)
|
||||||
standard where possible. The Godoc reference has a list of constants.
|
standard where possible. The Godoc reference has a list of constants.
|
||||||
|
|
||||||
Key encryption | Algorithm identifier(s)
|
| Key encryption | Algorithm identifier(s) |
|
||||||
:------------------------- | :------------------------------
|
|:-----------------------|:-----------------------------------------------|
|
||||||
RSA-PKCS#1v1.5 | RSA1_5
|
| RSA-PKCS#1v1.5 | RSA1_5 |
|
||||||
RSA-OAEP | RSA-OAEP, RSA-OAEP-256
|
| RSA-OAEP | RSA-OAEP, RSA-OAEP-256 |
|
||||||
AES key wrap | A128KW, A192KW, A256KW
|
| AES key wrap | A128KW, A192KW, A256KW |
|
||||||
AES-GCM key wrap | A128GCMKW, A192GCMKW, A256GCMKW
|
| AES-GCM key wrap | A128GCMKW, A192GCMKW, A256GCMKW |
|
||||||
ECDH-ES + AES key wrap | ECDH-ES+A128KW, ECDH-ES+A192KW, ECDH-ES+A256KW
|
| ECDH-ES + AES key wrap | ECDH-ES+A128KW, ECDH-ES+A192KW, ECDH-ES+A256KW |
|
||||||
ECDH-ES (direct) | ECDH-ES<sup>1</sup>
|
| ECDH-ES (direct) | ECDH-ES<sup>1</sup> |
|
||||||
Direct encryption | dir<sup>1</sup>
|
| Direct encryption | dir<sup>1</sup> |
|
||||||
|
|
||||||
<sup>1. Not supported in multi-recipient mode</sup>
|
<sup>1. Not supported in multi-recipient mode</sup>
|
||||||
|
|
||||||
Signing / MAC | Algorithm identifier(s)
|
| Signing / MAC | Algorithm identifier(s) |
|
||||||
:------------------------- | :------------------------------
|
|:------------------|:------------------------|
|
||||||
RSASSA-PKCS#1v1.5 | RS256, RS384, RS512
|
| RSASSA-PKCS#1v1.5 | RS256, RS384, RS512 |
|
||||||
RSASSA-PSS | PS256, PS384, PS512
|
| RSASSA-PSS | PS256, PS384, PS512 |
|
||||||
HMAC | HS256, HS384, HS512
|
| HMAC | HS256, HS384, HS512 |
|
||||||
ECDSA | ES256, ES384, ES512
|
| ECDSA | ES256, ES384, ES512 |
|
||||||
Ed25519 | EdDSA<sup>2</sup>
|
| Ed25519 | EdDSA<sup>2</sup> |
|
||||||
|
|
||||||
<sup>2. Only available in version 2 of the package</sup>
|
<sup>2. Only available in version 2 of the package</sup>
|
||||||
|
|
||||||
Content encryption | Algorithm identifier(s)
|
| Content encryption | Algorithm identifier(s) |
|
||||||
:------------------------- | :------------------------------
|
|:-------------------|:--------------------------------------------|
|
||||||
AES-CBC+HMAC | A128CBC-HS256, A192CBC-HS384, A256CBC-HS512
|
| AES-CBC+HMAC | A128CBC-HS256, A192CBC-HS384, A256CBC-HS512 |
|
||||||
AES-GCM | A128GCM, A192GCM, A256GCM
|
| AES-GCM | A128GCM, A192GCM, A256GCM |
|
||||||
|
|
||||||
Compression | Algorithm identifiers(s)
|
| Compression | Algorithm identifiers(s) |
|
||||||
:------------------------- | -------------------------------
|
|:-------------------|--------------------------|
|
||||||
DEFLATE (RFC 1951) | DEF
|
| DEFLATE (RFC 1951) | DEF |
|
||||||
|
|
||||||
### Supported key types
|
### Supported key types
|
||||||
|
|
||||||
|
|
@ -85,12 +87,12 @@ library, and can be passed to corresponding functions such as `NewEncrypter` or
|
||||||
`NewSigner`. Each of these keys can also be wrapped in a JWK if desired, which
|
`NewSigner`. Each of these keys can also be wrapped in a JWK if desired, which
|
||||||
allows attaching a key id.
|
allows attaching a key id.
|
||||||
|
|
||||||
Algorithm(s) | Corresponding types
|
| Algorithm(s) | Corresponding types |
|
||||||
:------------------------- | -------------------------------
|
|:------------------|--------------------------------------------------------------------------------------------------------------------------------------|
|
||||||
RSA | *[rsa.PublicKey](https://pkg.go.dev/crypto/rsa/#PublicKey), *[rsa.PrivateKey](https://pkg.go.dev/crypto/rsa/#PrivateKey)
|
| RSA | *[rsa.PublicKey](https://pkg.go.dev/crypto/rsa/#PublicKey), *[rsa.PrivateKey](https://pkg.go.dev/crypto/rsa/#PrivateKey) |
|
||||||
ECDH, ECDSA | *[ecdsa.PublicKey](https://pkg.go.dev/crypto/ecdsa/#PublicKey), *[ecdsa.PrivateKey](https://pkg.go.dev/crypto/ecdsa/#PrivateKey)
|
| ECDH, ECDSA | *[ecdsa.PublicKey](https://pkg.go.dev/crypto/ecdsa/#PublicKey), *[ecdsa.PrivateKey](https://pkg.go.dev/crypto/ecdsa/#PrivateKey) |
|
||||||
EdDSA<sup>1</sup> | [ed25519.PublicKey](https://pkg.go.dev/crypto/ed25519#PublicKey), [ed25519.PrivateKey](https://pkg.go.dev/crypto/ed25519#PrivateKey)
|
| EdDSA<sup>1</sup> | [ed25519.PublicKey](https://pkg.go.dev/crypto/ed25519#PublicKey), [ed25519.PrivateKey](https://pkg.go.dev/crypto/ed25519#PrivateKey) |
|
||||||
AES, HMAC | []byte
|
| AES, HMAC | []byte |
|
||||||
|
|
||||||
<sup>1. Only available in version 2 or later of the package</sup>
|
<sup>1. Only available in version 2 or later of the package</sup>
|
||||||
|
|
||||||
|
|
|
||||||
20
vendor/github.com/go-jose/go-jose/v4/crypter.go
generated
vendored
20
vendor/github.com/go-jose/go-jose/v4/crypter.go
generated
vendored
|
|
@ -286,6 +286,10 @@ func makeJWERecipient(alg KeyAlgorithm, encryptionKey interface{}) (recipientKey
|
||||||
return newSymmetricRecipient(alg, encryptionKey)
|
return newSymmetricRecipient(alg, encryptionKey)
|
||||||
case string:
|
case string:
|
||||||
return newSymmetricRecipient(alg, []byte(encryptionKey))
|
return newSymmetricRecipient(alg, []byte(encryptionKey))
|
||||||
|
case JSONWebKey:
|
||||||
|
recipient, err := makeJWERecipient(alg, encryptionKey.Key)
|
||||||
|
recipient.keyID = encryptionKey.KeyID
|
||||||
|
return recipient, err
|
||||||
case *JSONWebKey:
|
case *JSONWebKey:
|
||||||
recipient, err := makeJWERecipient(alg, encryptionKey.Key)
|
recipient, err := makeJWERecipient(alg, encryptionKey.Key)
|
||||||
recipient.keyID = encryptionKey.KeyID
|
recipient.keyID = encryptionKey.KeyID
|
||||||
|
|
@ -450,13 +454,9 @@ func (obj JSONWebEncryption) Decrypt(decryptionKey interface{}) ([]byte, error)
|
||||||
return nil, errors.New("go-jose/go-jose: too many recipients in payload; expecting only one")
|
return nil, errors.New("go-jose/go-jose: too many recipients in payload; expecting only one")
|
||||||
}
|
}
|
||||||
|
|
||||||
critical, err := headers.getCritical()
|
err := headers.checkNoCritical()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, fmt.Errorf("go-jose/go-jose: invalid crit header")
|
return nil, err
|
||||||
}
|
|
||||||
|
|
||||||
if len(critical) > 0 {
|
|
||||||
return nil, fmt.Errorf("go-jose/go-jose: unsupported crit header")
|
|
||||||
}
|
}
|
||||||
|
|
||||||
key, err := tryJWKS(decryptionKey, obj.Header)
|
key, err := tryJWKS(decryptionKey, obj.Header)
|
||||||
|
|
@ -523,13 +523,9 @@ func (obj JSONWebEncryption) Decrypt(decryptionKey interface{}) ([]byte, error)
|
||||||
func (obj JSONWebEncryption) DecryptMulti(decryptionKey interface{}) (int, Header, []byte, error) {
|
func (obj JSONWebEncryption) DecryptMulti(decryptionKey interface{}) (int, Header, []byte, error) {
|
||||||
globalHeaders := obj.mergedHeaders(nil)
|
globalHeaders := obj.mergedHeaders(nil)
|
||||||
|
|
||||||
critical, err := globalHeaders.getCritical()
|
err := globalHeaders.checkNoCritical()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return -1, Header{}, nil, fmt.Errorf("go-jose/go-jose: invalid crit header")
|
return -1, Header{}, nil, err
|
||||||
}
|
|
||||||
|
|
||||||
if len(critical) > 0 {
|
|
||||||
return -1, Header{}, nil, fmt.Errorf("go-jose/go-jose: unsupported crit header")
|
|
||||||
}
|
}
|
||||||
|
|
||||||
key, err := tryJWKS(decryptionKey, obj.Header)
|
key, err := tryJWKS(decryptionKey, obj.Header)
|
||||||
|
|
|
||||||
19
vendor/github.com/go-jose/go-jose/v4/jwe.go
generated
vendored
19
vendor/github.com/go-jose/go-jose/v4/jwe.go
generated
vendored
|
|
@ -274,7 +274,7 @@ func validateAlgEnc(headers rawHeader, keyAlgorithms []KeyAlgorithm, contentEncr
|
||||||
if alg != "" && !containsKeyAlgorithm(keyAlgorithms, alg) {
|
if alg != "" && !containsKeyAlgorithm(keyAlgorithms, alg) {
|
||||||
return fmt.Errorf("unexpected key algorithm %q; expected %q", alg, keyAlgorithms)
|
return fmt.Errorf("unexpected key algorithm %q; expected %q", alg, keyAlgorithms)
|
||||||
}
|
}
|
||||||
if alg != "" && !containsContentEncryption(contentEncryption, enc) {
|
if enc != "" && !containsContentEncryption(contentEncryption, enc) {
|
||||||
return fmt.Errorf("unexpected content encryption algorithm %q; expected %q", enc, contentEncryption)
|
return fmt.Errorf("unexpected content encryption algorithm %q; expected %q", enc, contentEncryption)
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
|
|
@ -288,11 +288,20 @@ func ParseEncryptedCompact(
|
||||||
keyAlgorithms []KeyAlgorithm,
|
keyAlgorithms []KeyAlgorithm,
|
||||||
contentEncryption []ContentEncryption,
|
contentEncryption []ContentEncryption,
|
||||||
) (*JSONWebEncryption, error) {
|
) (*JSONWebEncryption, error) {
|
||||||
// Five parts is four separators
|
var parts [5]string
|
||||||
if strings.Count(input, ".") != 4 {
|
var ok bool
|
||||||
return nil, fmt.Errorf("go-jose/go-jose: compact JWE format must have five parts")
|
|
||||||
|
for i := range 4 {
|
||||||
|
parts[i], input, ok = strings.Cut(input, ".")
|
||||||
|
if !ok {
|
||||||
|
return nil, errors.New("go-jose/go-jose: compact JWE format must have five parts")
|
||||||
|
}
|
||||||
}
|
}
|
||||||
parts := strings.SplitN(input, ".", 5)
|
// Validate that the last part does not contain more dots
|
||||||
|
if strings.ContainsRune(input, '.') {
|
||||||
|
return nil, errors.New("go-jose/go-jose: compact JWE format must have five parts")
|
||||||
|
}
|
||||||
|
parts[4] = input
|
||||||
|
|
||||||
rawProtected, err := base64.RawURLEncoding.DecodeString(parts[0])
|
rawProtected, err := base64.RawURLEncoding.DecodeString(parts[0])
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
|
||||||
59
vendor/github.com/go-jose/go-jose/v4/jwk.go
generated
vendored
59
vendor/github.com/go-jose/go-jose/v4/jwk.go
generated
vendored
|
|
@ -175,6 +175,8 @@ func (k JSONWebKey) MarshalJSON() ([]byte, error) {
|
||||||
}
|
}
|
||||||
|
|
||||||
// UnmarshalJSON reads a key from its JSON representation.
|
// UnmarshalJSON reads a key from its JSON representation.
|
||||||
|
//
|
||||||
|
// Returns ErrUnsupportedKeyType for unrecognized or unsupported "kty" header values.
|
||||||
func (k *JSONWebKey) UnmarshalJSON(data []byte) (err error) {
|
func (k *JSONWebKey) UnmarshalJSON(data []byte) (err error) {
|
||||||
var raw rawJSONWebKey
|
var raw rawJSONWebKey
|
||||||
err = json.Unmarshal(data, &raw)
|
err = json.Unmarshal(data, &raw)
|
||||||
|
|
@ -228,7 +230,7 @@ func (k *JSONWebKey) UnmarshalJSON(data []byte) (err error) {
|
||||||
}
|
}
|
||||||
key, err = raw.symmetricKey()
|
key, err = raw.symmetricKey()
|
||||||
case "OKP":
|
case "OKP":
|
||||||
if raw.Crv == "Ed25519" && raw.X != nil {
|
if raw.Crv == "Ed25519" {
|
||||||
if raw.D != nil {
|
if raw.D != nil {
|
||||||
key, err = raw.edPrivateKey()
|
key, err = raw.edPrivateKey()
|
||||||
if err == nil {
|
if err == nil {
|
||||||
|
|
@ -238,17 +240,27 @@ func (k *JSONWebKey) UnmarshalJSON(data []byte) (err error) {
|
||||||
key, err = raw.edPublicKey()
|
key, err = raw.edPublicKey()
|
||||||
keyPub = key
|
keyPub = key
|
||||||
}
|
}
|
||||||
} else {
|
|
||||||
return fmt.Errorf("go-jose/go-jose: unknown curve %s'", raw.Crv)
|
|
||||||
}
|
}
|
||||||
default:
|
case "":
|
||||||
return fmt.Errorf("go-jose/go-jose: unknown json web key type '%s'", raw.Kty)
|
// kty MUST be present
|
||||||
|
err = fmt.Errorf("go-jose/go-jose: missing json web key type")
|
||||||
}
|
}
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if key == nil {
|
||||||
|
// RFC 7517:
|
||||||
|
// 5. JWK Set Format
|
||||||
|
// ...
|
||||||
|
// Implementations SHOULD ignore JWKs within a JWK Set that use "kty"
|
||||||
|
// (key type) values that are not understood by them, that are missing
|
||||||
|
// required members, or for which values are out of the supported
|
||||||
|
// ranges.
|
||||||
|
return ErrUnsupportedKeyType
|
||||||
|
}
|
||||||
|
|
||||||
if certPub != nil && keyPub != nil {
|
if certPub != nil && keyPub != nil {
|
||||||
if !reflect.DeepEqual(certPub, keyPub) {
|
if !reflect.DeepEqual(certPub, keyPub) {
|
||||||
return errors.New("go-jose/go-jose: invalid JWK, public keys in key and x5c fields do not match")
|
return errors.New("go-jose/go-jose: invalid JWK, public keys in key and x5c fields do not match")
|
||||||
|
|
@ -581,10 +593,10 @@ func fromEcPublicKey(pub *ecdsa.PublicKey) (*rawJSONWebKey, error) {
|
||||||
|
|
||||||
func (key rawJSONWebKey) edPrivateKey() (ed25519.PrivateKey, error) {
|
func (key rawJSONWebKey) edPrivateKey() (ed25519.PrivateKey, error) {
|
||||||
var missing []string
|
var missing []string
|
||||||
switch {
|
if key.D == nil {
|
||||||
case key.D == nil:
|
|
||||||
missing = append(missing, "D")
|
missing = append(missing, "D")
|
||||||
case key.X == nil:
|
}
|
||||||
|
if key.X == nil {
|
||||||
missing = append(missing, "X")
|
missing = append(missing, "X")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -611,19 +623,21 @@ func (key rawJSONWebKey) edPublicKey() (ed25519.PublicKey, error) {
|
||||||
|
|
||||||
func (key rawJSONWebKey) rsaPrivateKey() (*rsa.PrivateKey, error) {
|
func (key rawJSONWebKey) rsaPrivateKey() (*rsa.PrivateKey, error) {
|
||||||
var missing []string
|
var missing []string
|
||||||
switch {
|
if key.N == nil {
|
||||||
case key.N == nil:
|
|
||||||
missing = append(missing, "N")
|
missing = append(missing, "N")
|
||||||
case key.E == nil:
|
}
|
||||||
|
if key.E == nil {
|
||||||
missing = append(missing, "E")
|
missing = append(missing, "E")
|
||||||
case key.D == nil:
|
}
|
||||||
|
if key.D == nil {
|
||||||
missing = append(missing, "D")
|
missing = append(missing, "D")
|
||||||
case key.P == nil:
|
}
|
||||||
|
if key.P == nil {
|
||||||
missing = append(missing, "P")
|
missing = append(missing, "P")
|
||||||
case key.Q == nil:
|
}
|
||||||
|
if key.Q == nil {
|
||||||
missing = append(missing, "Q")
|
missing = append(missing, "Q")
|
||||||
}
|
}
|
||||||
|
|
||||||
if len(missing) > 0 {
|
if len(missing) > 0 {
|
||||||
return nil, fmt.Errorf("go-jose/go-jose: invalid RSA private key, missing %s value(s)", strings.Join(missing, ", "))
|
return nil, fmt.Errorf("go-jose/go-jose: invalid RSA private key, missing %s value(s)", strings.Join(missing, ", "))
|
||||||
}
|
}
|
||||||
|
|
@ -698,8 +712,19 @@ func (key rawJSONWebKey) ecPrivateKey() (*ecdsa.PrivateKey, error) {
|
||||||
return nil, fmt.Errorf("go-jose/go-jose: unsupported elliptic curve '%s'", key.Crv)
|
return nil, fmt.Errorf("go-jose/go-jose: unsupported elliptic curve '%s'", key.Crv)
|
||||||
}
|
}
|
||||||
|
|
||||||
if key.X == nil || key.Y == nil || key.D == nil {
|
var missing []string
|
||||||
return nil, fmt.Errorf("go-jose/go-jose: invalid EC private key, missing x/y/d values")
|
if key.X == nil {
|
||||||
|
missing = append(missing, "X")
|
||||||
|
}
|
||||||
|
if key.Y == nil {
|
||||||
|
missing = append(missing, "Y")
|
||||||
|
}
|
||||||
|
if key.D == nil {
|
||||||
|
missing = append(missing, "D")
|
||||||
|
}
|
||||||
|
|
||||||
|
if len(missing) > 0 {
|
||||||
|
return nil, fmt.Errorf("go-jose/go-jose: invalid EC private key, missing %s value(s)", strings.Join(missing, ", "))
|
||||||
}
|
}
|
||||||
|
|
||||||
// The length of this octet string MUST be the full size of a coordinate for
|
// The length of this octet string MUST be the full size of a coordinate for
|
||||||
|
|
|
||||||
74
vendor/github.com/go-jose/go-jose/v4/jws.go
generated
vendored
74
vendor/github.com/go-jose/go-jose/v4/jws.go
generated
vendored
|
|
@ -75,7 +75,14 @@ type Signature struct {
|
||||||
original *rawSignatureInfo
|
original *rawSignatureInfo
|
||||||
}
|
}
|
||||||
|
|
||||||
// ParseSigned parses a signed message in JWS Compact or JWS JSON Serialization.
|
// ParseSigned parses a signed message in JWS Compact or JWS JSON Serialization. Validation fails if
|
||||||
|
// the JWS is signed with an algorithm that isn't in the provided list of signature algorithms.
|
||||||
|
// Applications should decide for themselves which signature algorithms are acceptable. If you're
|
||||||
|
// not sure which signature algorithms your application might receive, consult the documentation of
|
||||||
|
// the program which provides them or the protocol that you are implementing. You can also try
|
||||||
|
// getting an example JWS and decoding it with a tool like https://jwt.io to see what its "alg"
|
||||||
|
// header parameter indicates. The signature on the JWS does not get validated during parsing. Call
|
||||||
|
// Verify() after parsing to validate the signature and obtain the payload.
|
||||||
//
|
//
|
||||||
// https://datatracker.ietf.org/doc/html/rfc7515#section-7
|
// https://datatracker.ietf.org/doc/html/rfc7515#section-7
|
||||||
func ParseSigned(
|
func ParseSigned(
|
||||||
|
|
@ -90,7 +97,14 @@ func ParseSigned(
|
||||||
return parseSignedCompact(signature, nil, signatureAlgorithms)
|
return parseSignedCompact(signature, nil, signatureAlgorithms)
|
||||||
}
|
}
|
||||||
|
|
||||||
// ParseSignedCompact parses a message in JWS Compact Serialization.
|
// ParseSignedCompact parses a message in JWS Compact Serialization. Validation fails if the JWS is
|
||||||
|
// signed with an algorithm that isn't in the provided list of signature algorithms. Applications
|
||||||
|
// should decide for themselves which signature algorithms are acceptable.If you're not sure which
|
||||||
|
// signature algorithms your application might receive, consult the documentation of the program
|
||||||
|
// which provides them or the protocol that you are implementing. You can also try getting an
|
||||||
|
// example JWS and decoding it with a tool like https://jwt.io to see what its "alg" header
|
||||||
|
// parameter indicates. The signature on the JWS does not get validated during parsing. Call
|
||||||
|
// Verify() after parsing to validate the signature and obtain the payload.
|
||||||
//
|
//
|
||||||
// https://datatracker.ietf.org/doc/html/rfc7515#section-7.1
|
// https://datatracker.ietf.org/doc/html/rfc7515#section-7.1
|
||||||
func ParseSignedCompact(
|
func ParseSignedCompact(
|
||||||
|
|
@ -101,6 +115,15 @@ func ParseSignedCompact(
|
||||||
}
|
}
|
||||||
|
|
||||||
// ParseDetached parses a signed message in compact serialization format with detached payload.
|
// ParseDetached parses a signed message in compact serialization format with detached payload.
|
||||||
|
// Validation fails if the JWS is signed with an algorithm that isn't in the provided list of
|
||||||
|
// signature algorithms. Applications should decide for themselves which signature algorithms are
|
||||||
|
// acceptable. If you're not sure which signature algorithms your application might receive, consult
|
||||||
|
// the documentation of the program which provides them or the protocol that you are implementing.
|
||||||
|
// You can also try getting an example JWS and decoding it with a tool like https://jwt.io to see
|
||||||
|
// what its "alg" header parameter indicates. The signature on the JWS does not get validated during
|
||||||
|
// parsing. Call Verify() after parsing to validate the signature and obtain the payload.
|
||||||
|
//
|
||||||
|
// https://datatracker.ietf.org/doc/html/rfc7515#appendix-F
|
||||||
func ParseDetached(
|
func ParseDetached(
|
||||||
signature string,
|
signature string,
|
||||||
payload []byte,
|
payload []byte,
|
||||||
|
|
@ -181,6 +204,25 @@ func containsSignatureAlgorithm(haystack []SignatureAlgorithm, needle SignatureA
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ErrUnexpectedSignatureAlgorithm is returned when the signature algorithm in
|
||||||
|
// the JWS header does not match one of the expected algorithms.
|
||||||
|
type ErrUnexpectedSignatureAlgorithm struct {
|
||||||
|
// Got is the signature algorithm found in the JWS header.
|
||||||
|
Got SignatureAlgorithm
|
||||||
|
expected []SignatureAlgorithm
|
||||||
|
}
|
||||||
|
|
||||||
|
func (e *ErrUnexpectedSignatureAlgorithm) Error() string {
|
||||||
|
return fmt.Sprintf("unexpected signature algorithm %q; expected %q", e.Got, e.expected)
|
||||||
|
}
|
||||||
|
|
||||||
|
func newErrUnexpectedSignatureAlgorithm(got SignatureAlgorithm, expected []SignatureAlgorithm) error {
|
||||||
|
return &ErrUnexpectedSignatureAlgorithm{
|
||||||
|
Got: got,
|
||||||
|
expected: expected,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// sanitized produces a cleaned-up JWS object from the raw JSON.
|
// sanitized produces a cleaned-up JWS object from the raw JSON.
|
||||||
func (parsed *rawJSONWebSignature) sanitized(signatureAlgorithms []SignatureAlgorithm) (*JSONWebSignature, error) {
|
func (parsed *rawJSONWebSignature) sanitized(signatureAlgorithms []SignatureAlgorithm) (*JSONWebSignature, error) {
|
||||||
if len(signatureAlgorithms) == 0 {
|
if len(signatureAlgorithms) == 0 {
|
||||||
|
|
@ -236,8 +278,7 @@ func (parsed *rawJSONWebSignature) sanitized(signatureAlgorithms []SignatureAlgo
|
||||||
|
|
||||||
alg := SignatureAlgorithm(signature.Header.Algorithm)
|
alg := SignatureAlgorithm(signature.Header.Algorithm)
|
||||||
if !containsSignatureAlgorithm(signatureAlgorithms, alg) {
|
if !containsSignatureAlgorithm(signatureAlgorithms, alg) {
|
||||||
return nil, fmt.Errorf("go-jose/go-jose: unexpected signature algorithm %q; expected %q",
|
return nil, newErrUnexpectedSignatureAlgorithm(alg, signatureAlgorithms)
|
||||||
alg, signatureAlgorithms)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if signature.header != nil {
|
if signature.header != nil {
|
||||||
|
|
@ -285,8 +326,7 @@ func (parsed *rawJSONWebSignature) sanitized(signatureAlgorithms []SignatureAlgo
|
||||||
|
|
||||||
alg := SignatureAlgorithm(obj.Signatures[i].Header.Algorithm)
|
alg := SignatureAlgorithm(obj.Signatures[i].Header.Algorithm)
|
||||||
if !containsSignatureAlgorithm(signatureAlgorithms, alg) {
|
if !containsSignatureAlgorithm(signatureAlgorithms, alg) {
|
||||||
return nil, fmt.Errorf("go-jose/go-jose: unexpected signature algorithm %q; expected %q",
|
return nil, newErrUnexpectedSignatureAlgorithm(alg, signatureAlgorithms)
|
||||||
alg, signatureAlgorithms)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if obj.Signatures[i].header != nil {
|
if obj.Signatures[i].header != nil {
|
||||||
|
|
@ -321,35 +361,43 @@ func (parsed *rawJSONWebSignature) sanitized(signatureAlgorithms []SignatureAlgo
|
||||||
return obj, nil
|
return obj, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const tokenDelim = "."
|
||||||
|
|
||||||
// parseSignedCompact parses a message in compact format.
|
// parseSignedCompact parses a message in compact format.
|
||||||
func parseSignedCompact(
|
func parseSignedCompact(
|
||||||
input string,
|
input string,
|
||||||
payload []byte,
|
payload []byte,
|
||||||
signatureAlgorithms []SignatureAlgorithm,
|
signatureAlgorithms []SignatureAlgorithm,
|
||||||
) (*JSONWebSignature, error) {
|
) (*JSONWebSignature, error) {
|
||||||
// Three parts is two separators
|
protected, s, ok := strings.Cut(input, tokenDelim)
|
||||||
if strings.Count(input, ".") != 2 {
|
if !ok { // no period found
|
||||||
|
return nil, fmt.Errorf("go-jose/go-jose: compact JWS format must have three parts")
|
||||||
|
}
|
||||||
|
claims, sig, ok := strings.Cut(s, tokenDelim)
|
||||||
|
if !ok { // only one period found
|
||||||
|
return nil, fmt.Errorf("go-jose/go-jose: compact JWS format must have three parts")
|
||||||
|
}
|
||||||
|
if strings.ContainsRune(sig, '.') { // too many periods found
|
||||||
return nil, fmt.Errorf("go-jose/go-jose: compact JWS format must have three parts")
|
return nil, fmt.Errorf("go-jose/go-jose: compact JWS format must have three parts")
|
||||||
}
|
}
|
||||||
parts := strings.SplitN(input, ".", 3)
|
|
||||||
|
|
||||||
if parts[1] != "" && payload != nil {
|
if claims != "" && payload != nil {
|
||||||
return nil, fmt.Errorf("go-jose/go-jose: payload is not detached")
|
return nil, fmt.Errorf("go-jose/go-jose: payload is not detached")
|
||||||
}
|
}
|
||||||
|
|
||||||
rawProtected, err := base64.RawURLEncoding.DecodeString(parts[0])
|
rawProtected, err := base64.RawURLEncoding.DecodeString(protected)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
if payload == nil {
|
if payload == nil {
|
||||||
payload, err = base64.RawURLEncoding.DecodeString(parts[1])
|
payload, err = base64.RawURLEncoding.DecodeString(claims)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
signature, err := base64.RawURLEncoding.DecodeString(parts[2])
|
signature, err := base64.RawURLEncoding.DecodeString(sig)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
|
||||||
33
vendor/github.com/go-jose/go-jose/v4/shared.go
generated
vendored
33
vendor/github.com/go-jose/go-jose/v4/shared.go
generated
vendored
|
|
@ -77,6 +77,9 @@ var (
|
||||||
|
|
||||||
// ErrUnsupportedEllipticCurve indicates unsupported or unknown elliptic curve has been found.
|
// ErrUnsupportedEllipticCurve indicates unsupported or unknown elliptic curve has been found.
|
||||||
ErrUnsupportedEllipticCurve = errors.New("go-jose/go-jose: unsupported/unknown elliptic curve")
|
ErrUnsupportedEllipticCurve = errors.New("go-jose/go-jose: unsupported/unknown elliptic curve")
|
||||||
|
|
||||||
|
// ErrUnsupportedCriticalHeader is returned when a header is marked critical but not supported by go-jose.
|
||||||
|
ErrUnsupportedCriticalHeader = errors.New("go-jose/go-jose: unsupported critical header")
|
||||||
)
|
)
|
||||||
|
|
||||||
// Key management algorithms
|
// Key management algorithms
|
||||||
|
|
@ -167,8 +170,8 @@ const (
|
||||||
)
|
)
|
||||||
|
|
||||||
// supportedCritical is the set of supported extensions that are understood and processed.
|
// supportedCritical is the set of supported extensions that are understood and processed.
|
||||||
var supportedCritical = map[string]bool{
|
var supportedCritical = map[string]struct{}{
|
||||||
headerB64: true,
|
headerB64: {},
|
||||||
}
|
}
|
||||||
|
|
||||||
// rawHeader represents the JOSE header for JWE/JWS objects (used for parsing).
|
// rawHeader represents the JOSE header for JWE/JWS objects (used for parsing).
|
||||||
|
|
@ -346,6 +349,32 @@ func (parsed rawHeader) getCritical() ([]string, error) {
|
||||||
return q, nil
|
return q, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// checkNoCritical verifies there are no critical headers present.
|
||||||
|
func (parsed rawHeader) checkNoCritical() error {
|
||||||
|
if _, ok := parsed[headerCritical]; ok {
|
||||||
|
return ErrUnsupportedCriticalHeader
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// checkSupportedCritical verifies there are no unsupported critical headers.
|
||||||
|
// Supported headers are passed in as a set: map of names to empty structs
|
||||||
|
func (parsed rawHeader) checkSupportedCritical(supported map[string]struct{}) error {
|
||||||
|
crit, err := parsed.getCritical()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, name := range crit {
|
||||||
|
if _, ok := supported[name]; !ok {
|
||||||
|
return ErrUnsupportedCriticalHeader
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
// getS2C extracts parsed "p2c" from the raw JSON.
|
// getS2C extracts parsed "p2c" from the raw JSON.
|
||||||
func (parsed rawHeader) getP2C() (int, error) {
|
func (parsed rawHeader) getP2C() (int, error) {
|
||||||
v := parsed[headerP2C]
|
v := parsed[headerP2C]
|
||||||
|
|
|
||||||
44
vendor/github.com/go-jose/go-jose/v4/signing.go
generated
vendored
44
vendor/github.com/go-jose/go-jose/v4/signing.go
generated
vendored
|
|
@ -404,15 +404,23 @@ func (obj JSONWebSignature) DetachedVerify(payload []byte, verificationKey inter
|
||||||
}
|
}
|
||||||
|
|
||||||
signature := obj.Signatures[0]
|
signature := obj.Signatures[0]
|
||||||
headers := signature.mergedHeaders()
|
|
||||||
critical, err := headers.getCritical()
|
if signature.header != nil {
|
||||||
if err != nil {
|
// Per https://www.rfc-editor.org/rfc/rfc7515.html#section-4.1.11,
|
||||||
return err
|
// 4.1.11. "crit" (Critical) Header Parameter
|
||||||
|
// "When used, this Header Parameter MUST be integrity
|
||||||
|
// protected; therefore, it MUST occur only within the JWS
|
||||||
|
// Protected Header."
|
||||||
|
err = signature.header.checkNoCritical()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, name := range critical {
|
if signature.protected != nil {
|
||||||
if !supportedCritical[name] {
|
err = signature.protected.checkSupportedCritical(supportedCritical)
|
||||||
return ErrCryptoFailure
|
if err != nil {
|
||||||
|
return err
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -421,6 +429,7 @@ func (obj JSONWebSignature) DetachedVerify(payload []byte, verificationKey inter
|
||||||
return ErrCryptoFailure
|
return ErrCryptoFailure
|
||||||
}
|
}
|
||||||
|
|
||||||
|
headers := signature.mergedHeaders()
|
||||||
alg := headers.getSignatureAlgorithm()
|
alg := headers.getSignatureAlgorithm()
|
||||||
err = verifier.verifyPayload(input, signature.Signature, alg)
|
err = verifier.verifyPayload(input, signature.Signature, alg)
|
||||||
if err == nil {
|
if err == nil {
|
||||||
|
|
@ -469,14 +478,22 @@ func (obj JSONWebSignature) DetachedVerifyMulti(payload []byte, verificationKey
|
||||||
|
|
||||||
outer:
|
outer:
|
||||||
for i, signature := range obj.Signatures {
|
for i, signature := range obj.Signatures {
|
||||||
headers := signature.mergedHeaders()
|
if signature.header != nil {
|
||||||
critical, err := headers.getCritical()
|
// Per https://www.rfc-editor.org/rfc/rfc7515.html#section-4.1.11,
|
||||||
if err != nil {
|
// 4.1.11. "crit" (Critical) Header Parameter
|
||||||
continue
|
// "When used, this Header Parameter MUST be integrity
|
||||||
|
// protected; therefore, it MUST occur only within the JWS
|
||||||
|
// Protected Header."
|
||||||
|
err = signature.header.checkNoCritical()
|
||||||
|
if err != nil {
|
||||||
|
continue outer
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, name := range critical {
|
if signature.protected != nil {
|
||||||
if !supportedCritical[name] {
|
// Check for only supported critical headers
|
||||||
|
err = signature.protected.checkSupportedCritical(supportedCritical)
|
||||||
|
if err != nil {
|
||||||
continue outer
|
continue outer
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
@ -486,6 +503,7 @@ outer:
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
|
||||||
|
headers := signature.mergedHeaders()
|
||||||
alg := headers.getSignatureAlgorithm()
|
alg := headers.getSignatureAlgorithm()
|
||||||
err = verifier.verifyPayload(input, signature.Signature, alg)
|
err = verifier.verifyPayload(input, signature.Signature, alg)
|
||||||
if err == nil {
|
if err == nil {
|
||||||
|
|
|
||||||
13
vendor/github.com/go-jose/go-jose/v4/symmetric.go
generated
vendored
13
vendor/github.com/go-jose/go-jose/v4/symmetric.go
generated
vendored
|
|
@ -21,6 +21,7 @@ import (
|
||||||
"crypto/aes"
|
"crypto/aes"
|
||||||
"crypto/cipher"
|
"crypto/cipher"
|
||||||
"crypto/hmac"
|
"crypto/hmac"
|
||||||
|
"crypto/pbkdf2"
|
||||||
"crypto/rand"
|
"crypto/rand"
|
||||||
"crypto/sha256"
|
"crypto/sha256"
|
||||||
"crypto/sha512"
|
"crypto/sha512"
|
||||||
|
|
@ -30,8 +31,6 @@ import (
|
||||||
"hash"
|
"hash"
|
||||||
"io"
|
"io"
|
||||||
|
|
||||||
"golang.org/x/crypto/pbkdf2"
|
|
||||||
|
|
||||||
josecipher "github.com/go-jose/go-jose/v4/cipher"
|
josecipher "github.com/go-jose/go-jose/v4/cipher"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -330,7 +329,10 @@ func (ctx *symmetricKeyCipher) encryptKey(cek []byte, alg KeyAlgorithm) (recipie
|
||||||
|
|
||||||
// derive key
|
// derive key
|
||||||
keyLen, h := getPbkdf2Params(alg)
|
keyLen, h := getPbkdf2Params(alg)
|
||||||
key := pbkdf2.Key(ctx.key, salt, ctx.p2c, keyLen, h)
|
key, err := pbkdf2.Key(h, string(ctx.key), salt, ctx.p2c, keyLen)
|
||||||
|
if err != nil {
|
||||||
|
return recipientInfo{}, nil
|
||||||
|
}
|
||||||
|
|
||||||
// use AES cipher with derived key
|
// use AES cipher with derived key
|
||||||
block, err := aes.NewCipher(key)
|
block, err := aes.NewCipher(key)
|
||||||
|
|
@ -432,7 +434,10 @@ func (ctx *symmetricKeyCipher) decryptKey(headers rawHeader, recipient *recipien
|
||||||
|
|
||||||
// derive key
|
// derive key
|
||||||
keyLen, h := getPbkdf2Params(alg)
|
keyLen, h := getPbkdf2Params(alg)
|
||||||
key := pbkdf2.Key(ctx.key, salt, p2c, keyLen, h)
|
key, err := pbkdf2.Key(h, string(ctx.key), salt, p2c, keyLen)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
// use AES cipher with derived key
|
// use AES cipher with derived key
|
||||||
block, err := aes.NewCipher(key)
|
block, err := aes.NewCipher(key)
|
||||||
|
|
|
||||||
375
vendor/github.com/letsencrypt/boulder/LICENSE.txt
generated
vendored
375
vendor/github.com/letsencrypt/boulder/LICENSE.txt
generated
vendored
|
|
@ -1,375 +0,0 @@
|
||||||
Copyright 2016 ISRG. All rights reserved.
|
|
||||||
|
|
||||||
Mozilla Public License Version 2.0
|
|
||||||
==================================
|
|
||||||
|
|
||||||
1. Definitions
|
|
||||||
--------------
|
|
||||||
|
|
||||||
1.1. "Contributor"
|
|
||||||
means each individual or legal entity that creates, contributes to
|
|
||||||
the creation of, or owns Covered Software.
|
|
||||||
|
|
||||||
1.2. "Contributor Version"
|
|
||||||
means the combination of the Contributions of others (if any) used
|
|
||||||
by a Contributor and that particular Contributor's Contribution.
|
|
||||||
|
|
||||||
1.3. "Contribution"
|
|
||||||
means Covered Software of a particular Contributor.
|
|
||||||
|
|
||||||
1.4. "Covered Software"
|
|
||||||
means Source Code Form to which the initial Contributor has attached
|
|
||||||
the notice in Exhibit A, the Executable Form of such Source Code
|
|
||||||
Form, and Modifications of such Source Code Form, in each case
|
|
||||||
including portions thereof.
|
|
||||||
|
|
||||||
1.5. "Incompatible With Secondary Licenses"
|
|
||||||
means
|
|
||||||
|
|
||||||
(a) that the initial Contributor has attached the notice described
|
|
||||||
in Exhibit B to the Covered Software; or
|
|
||||||
|
|
||||||
(b) that the Covered Software was made available under the terms of
|
|
||||||
version 1.1 or earlier of the License, but not also under the
|
|
||||||
terms of a Secondary License.
|
|
||||||
|
|
||||||
1.6. "Executable Form"
|
|
||||||
means any form of the work other than Source Code Form.
|
|
||||||
|
|
||||||
1.7. "Larger Work"
|
|
||||||
means a work that combines Covered Software with other material, in
|
|
||||||
a separate file or files, that is not Covered Software.
|
|
||||||
|
|
||||||
1.8. "License"
|
|
||||||
means this document.
|
|
||||||
|
|
||||||
1.9. "Licensable"
|
|
||||||
means having the right to grant, to the maximum extent possible,
|
|
||||||
whether at the time of the initial grant or subsequently, any and
|
|
||||||
all of the rights conveyed by this License.
|
|
||||||
|
|
||||||
1.10. "Modifications"
|
|
||||||
means any of the following:
|
|
||||||
|
|
||||||
(a) any file in Source Code Form that results from an addition to,
|
|
||||||
deletion from, or modification of the contents of Covered
|
|
||||||
Software; or
|
|
||||||
|
|
||||||
(b) any new file in Source Code Form that contains any Covered
|
|
||||||
Software.
|
|
||||||
|
|
||||||
1.11. "Patent Claims" of a Contributor
|
|
||||||
means any patent claim(s), including without limitation, method,
|
|
||||||
process, and apparatus claims, in any patent Licensable by such
|
|
||||||
Contributor that would be infringed, but for the grant of the
|
|
||||||
License, by the making, using, selling, offering for sale, having
|
|
||||||
made, import, or transfer of either its Contributions or its
|
|
||||||
Contributor Version.
|
|
||||||
|
|
||||||
1.12. "Secondary License"
|
|
||||||
means either the GNU General Public License, Version 2.0, the GNU
|
|
||||||
Lesser General Public License, Version 2.1, the GNU Affero General
|
|
||||||
Public License, Version 3.0, or any later versions of those
|
|
||||||
licenses.
|
|
||||||
|
|
||||||
1.13. "Source Code Form"
|
|
||||||
means the form of the work preferred for making modifications.
|
|
||||||
|
|
||||||
1.14. "You" (or "Your")
|
|
||||||
means an individual or a legal entity exercising rights under this
|
|
||||||
License. For legal entities, "You" includes any entity that
|
|
||||||
controls, is controlled by, or is under common control with You. For
|
|
||||||
purposes of this definition, "control" means (a) the power, direct
|
|
||||||
or indirect, to cause the direction or management of such entity,
|
|
||||||
whether by contract or otherwise, or (b) ownership of more than
|
|
||||||
fifty percent (50%) of the outstanding shares or beneficial
|
|
||||||
ownership of such entity.
|
|
||||||
|
|
||||||
2. License Grants and Conditions
|
|
||||||
--------------------------------
|
|
||||||
|
|
||||||
2.1. Grants
|
|
||||||
|
|
||||||
Each Contributor hereby grants You a world-wide, royalty-free,
|
|
||||||
non-exclusive license:
|
|
||||||
|
|
||||||
(a) under intellectual property rights (other than patent or trademark)
|
|
||||||
Licensable by such Contributor to use, reproduce, make available,
|
|
||||||
modify, display, perform, distribute, and otherwise exploit its
|
|
||||||
Contributions, either on an unmodified basis, with Modifications, or
|
|
||||||
as part of a Larger Work; and
|
|
||||||
|
|
||||||
(b) under Patent Claims of such Contributor to make, use, sell, offer
|
|
||||||
for sale, have made, import, and otherwise transfer either its
|
|
||||||
Contributions or its Contributor Version.
|
|
||||||
|
|
||||||
2.2. Effective Date
|
|
||||||
|
|
||||||
The licenses granted in Section 2.1 with respect to any Contribution
|
|
||||||
become effective for each Contribution on the date the Contributor first
|
|
||||||
distributes such Contribution.
|
|
||||||
|
|
||||||
2.3. Limitations on Grant Scope
|
|
||||||
|
|
||||||
The licenses granted in this Section 2 are the only rights granted under
|
|
||||||
this License. No additional rights or licenses will be implied from the
|
|
||||||
distribution or licensing of Covered Software under this License.
|
|
||||||
Notwithstanding Section 2.1(b) above, no patent license is granted by a
|
|
||||||
Contributor:
|
|
||||||
|
|
||||||
(a) for any code that a Contributor has removed from Covered Software;
|
|
||||||
or
|
|
||||||
|
|
||||||
(b) for infringements caused by: (i) Your and any other third party's
|
|
||||||
modifications of Covered Software, or (ii) the combination of its
|
|
||||||
Contributions with other software (except as part of its Contributor
|
|
||||||
Version); or
|
|
||||||
|
|
||||||
(c) under Patent Claims infringed by Covered Software in the absence of
|
|
||||||
its Contributions.
|
|
||||||
|
|
||||||
This License does not grant any rights in the trademarks, service marks,
|
|
||||||
or logos of any Contributor (except as may be necessary to comply with
|
|
||||||
the notice requirements in Section 3.4).
|
|
||||||
|
|
||||||
2.4. Subsequent Licenses
|
|
||||||
|
|
||||||
No Contributor makes additional grants as a result of Your choice to
|
|
||||||
distribute the Covered Software under a subsequent version of this
|
|
||||||
License (see Section 10.2) or under the terms of a Secondary License (if
|
|
||||||
permitted under the terms of Section 3.3).
|
|
||||||
|
|
||||||
2.5. Representation
|
|
||||||
|
|
||||||
Each Contributor represents that the Contributor believes its
|
|
||||||
Contributions are its original creation(s) or it has sufficient rights
|
|
||||||
to grant the rights to its Contributions conveyed by this License.
|
|
||||||
|
|
||||||
2.6. Fair Use
|
|
||||||
|
|
||||||
This License is not intended to limit any rights You have under
|
|
||||||
applicable copyright doctrines of fair use, fair dealing, or other
|
|
||||||
equivalents.
|
|
||||||
|
|
||||||
2.7. Conditions
|
|
||||||
|
|
||||||
Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted
|
|
||||||
in Section 2.1.
|
|
||||||
|
|
||||||
3. Responsibilities
|
|
||||||
-------------------
|
|
||||||
|
|
||||||
3.1. Distribution of Source Form
|
|
||||||
|
|
||||||
All distribution of Covered Software in Source Code Form, including any
|
|
||||||
Modifications that You create or to which You contribute, must be under
|
|
||||||
the terms of this License. You must inform recipients that the Source
|
|
||||||
Code Form of the Covered Software is governed by the terms of this
|
|
||||||
License, and how they can obtain a copy of this License. You may not
|
|
||||||
attempt to alter or restrict the recipients' rights in the Source Code
|
|
||||||
Form.
|
|
||||||
|
|
||||||
3.2. Distribution of Executable Form
|
|
||||||
|
|
||||||
If You distribute Covered Software in Executable Form then:
|
|
||||||
|
|
||||||
(a) such Covered Software must also be made available in Source Code
|
|
||||||
Form, as described in Section 3.1, and You must inform recipients of
|
|
||||||
the Executable Form how they can obtain a copy of such Source Code
|
|
||||||
Form by reasonable means in a timely manner, at a charge no more
|
|
||||||
than the cost of distribution to the recipient; and
|
|
||||||
|
|
||||||
(b) You may distribute such Executable Form under the terms of this
|
|
||||||
License, or sublicense it under different terms, provided that the
|
|
||||||
license for the Executable Form does not attempt to limit or alter
|
|
||||||
the recipients' rights in the Source Code Form under this License.
|
|
||||||
|
|
||||||
3.3. Distribution of a Larger Work
|
|
||||||
|
|
||||||
You may create and distribute a Larger Work under terms of Your choice,
|
|
||||||
provided that You also comply with the requirements of this License for
|
|
||||||
the Covered Software. If the Larger Work is a combination of Covered
|
|
||||||
Software with a work governed by one or more Secondary Licenses, and the
|
|
||||||
Covered Software is not Incompatible With Secondary Licenses, this
|
|
||||||
License permits You to additionally distribute such Covered Software
|
|
||||||
under the terms of such Secondary License(s), so that the recipient of
|
|
||||||
the Larger Work may, at their option, further distribute the Covered
|
|
||||||
Software under the terms of either this License or such Secondary
|
|
||||||
License(s).
|
|
||||||
|
|
||||||
3.4. Notices
|
|
||||||
|
|
||||||
You may not remove or alter the substance of any license notices
|
|
||||||
(including copyright notices, patent notices, disclaimers of warranty,
|
|
||||||
or limitations of liability) contained within the Source Code Form of
|
|
||||||
the Covered Software, except that You may alter any license notices to
|
|
||||||
the extent required to remedy known factual inaccuracies.
|
|
||||||
|
|
||||||
3.5. Application of Additional Terms
|
|
||||||
|
|
||||||
You may choose to offer, and to charge a fee for, warranty, support,
|
|
||||||
indemnity or liability obligations to one or more recipients of Covered
|
|
||||||
Software. However, You may do so only on Your own behalf, and not on
|
|
||||||
behalf of any Contributor. You must make it absolutely clear that any
|
|
||||||
such warranty, support, indemnity, or liability obligation is offered by
|
|
||||||
You alone, and You hereby agree to indemnify every Contributor for any
|
|
||||||
liability incurred by such Contributor as a result of warranty, support,
|
|
||||||
indemnity or liability terms You offer. You may include additional
|
|
||||||
disclaimers of warranty and limitations of liability specific to any
|
|
||||||
jurisdiction.
|
|
||||||
|
|
||||||
4. Inability to Comply Due to Statute or Regulation
|
|
||||||
---------------------------------------------------
|
|
||||||
|
|
||||||
If it is impossible for You to comply with any of the terms of this
|
|
||||||
License with respect to some or all of the Covered Software due to
|
|
||||||
statute, judicial order, or regulation then You must: (a) comply with
|
|
||||||
the terms of this License to the maximum extent possible; and (b)
|
|
||||||
describe the limitations and the code they affect. Such description must
|
|
||||||
be placed in a text file included with all distributions of the Covered
|
|
||||||
Software under this License. Except to the extent prohibited by statute
|
|
||||||
or regulation, such description must be sufficiently detailed for a
|
|
||||||
recipient of ordinary skill to be able to understand it.
|
|
||||||
|
|
||||||
5. Termination
|
|
||||||
--------------
|
|
||||||
|
|
||||||
5.1. The rights granted under this License will terminate automatically
|
|
||||||
if You fail to comply with any of its terms. However, if You become
|
|
||||||
compliant, then the rights granted under this License from a particular
|
|
||||||
Contributor are reinstated (a) provisionally, unless and until such
|
|
||||||
Contributor explicitly and finally terminates Your grants, and (b) on an
|
|
||||||
ongoing basis, if such Contributor fails to notify You of the
|
|
||||||
non-compliance by some reasonable means prior to 60 days after You have
|
|
||||||
come back into compliance. Moreover, Your grants from a particular
|
|
||||||
Contributor are reinstated on an ongoing basis if such Contributor
|
|
||||||
notifies You of the non-compliance by some reasonable means, this is the
|
|
||||||
first time You have received notice of non-compliance with this License
|
|
||||||
from such Contributor, and You become compliant prior to 30 days after
|
|
||||||
Your receipt of the notice.
|
|
||||||
|
|
||||||
5.2. If You initiate litigation against any entity by asserting a patent
|
|
||||||
infringement claim (excluding declaratory judgment actions,
|
|
||||||
counter-claims, and cross-claims) alleging that a Contributor Version
|
|
||||||
directly or indirectly infringes any patent, then the rights granted to
|
|
||||||
You by any and all Contributors for the Covered Software under Section
|
|
||||||
2.1 of this License shall terminate.
|
|
||||||
|
|
||||||
5.3. In the event of termination under Sections 5.1 or 5.2 above, all
|
|
||||||
end user license agreements (excluding distributors and resellers) which
|
|
||||||
have been validly granted by You or Your distributors under this License
|
|
||||||
prior to termination shall survive termination.
|
|
||||||
|
|
||||||
************************************************************************
|
|
||||||
* *
|
|
||||||
* 6. Disclaimer of Warranty *
|
|
||||||
* ------------------------- *
|
|
||||||
* *
|
|
||||||
* Covered Software is provided under this License on an "as is" *
|
|
||||||
* basis, without warranty of any kind, either expressed, implied, or *
|
|
||||||
* statutory, including, without limitation, warranties that the *
|
|
||||||
* Covered Software is free of defects, merchantable, fit for a *
|
|
||||||
* particular purpose or non-infringing. The entire risk as to the *
|
|
||||||
* quality and performance of the Covered Software is with You. *
|
|
||||||
* Should any Covered Software prove defective in any respect, You *
|
|
||||||
* (not any Contributor) assume the cost of any necessary servicing, *
|
|
||||||
* repair, or correction. This disclaimer of warranty constitutes an *
|
|
||||||
* essential part of this License. No use of any Covered Software is *
|
|
||||||
* authorized under this License except under this disclaimer. *
|
|
||||||
* *
|
|
||||||
************************************************************************
|
|
||||||
|
|
||||||
************************************************************************
|
|
||||||
* *
|
|
||||||
* 7. Limitation of Liability *
|
|
||||||
* -------------------------- *
|
|
||||||
* *
|
|
||||||
* Under no circumstances and under no legal theory, whether tort *
|
|
||||||
* (including negligence), contract, or otherwise, shall any *
|
|
||||||
* Contributor, or anyone who distributes Covered Software as *
|
|
||||||
* permitted above, be liable to You for any direct, indirect, *
|
|
||||||
* special, incidental, or consequential damages of any character *
|
|
||||||
* including, without limitation, damages for lost profits, loss of *
|
|
||||||
* goodwill, work stoppage, computer failure or malfunction, or any *
|
|
||||||
* and all other commercial damages or losses, even if such party *
|
|
||||||
* shall have been informed of the possibility of such damages. This *
|
|
||||||
* limitation of liability shall not apply to liability for death or *
|
|
||||||
* personal injury resulting from such party's negligence to the *
|
|
||||||
* extent applicable law prohibits such limitation. Some *
|
|
||||||
* jurisdictions do not allow the exclusion or limitation of *
|
|
||||||
* incidental or consequential damages, so this exclusion and *
|
|
||||||
* limitation may not apply to You. *
|
|
||||||
* *
|
|
||||||
************************************************************************
|
|
||||||
|
|
||||||
8. Litigation
|
|
||||||
-------------
|
|
||||||
|
|
||||||
Any litigation relating to this License may be brought only in the
|
|
||||||
courts of a jurisdiction where the defendant maintains its principal
|
|
||||||
place of business and such litigation shall be governed by laws of that
|
|
||||||
jurisdiction, without reference to its conflict-of-law provisions.
|
|
||||||
Nothing in this Section shall prevent a party's ability to bring
|
|
||||||
cross-claims or counter-claims.
|
|
||||||
|
|
||||||
9. Miscellaneous
|
|
||||||
----------------
|
|
||||||
|
|
||||||
This License represents the complete agreement concerning the subject
|
|
||||||
matter hereof. If any provision of this License is held to be
|
|
||||||
unenforceable, such provision shall be reformed only to the extent
|
|
||||||
necessary to make it enforceable. Any law or regulation which provides
|
|
||||||
that the language of a contract shall be construed against the drafter
|
|
||||||
shall not be used to construe this License against a Contributor.
|
|
||||||
|
|
||||||
10. Versions of the License
|
|
||||||
---------------------------
|
|
||||||
|
|
||||||
10.1. New Versions
|
|
||||||
|
|
||||||
Mozilla Foundation is the license steward. Except as provided in Section
|
|
||||||
10.3, no one other than the license steward has the right to modify or
|
|
||||||
publish new versions of this License. Each version will be given a
|
|
||||||
distinguishing version number.
|
|
||||||
|
|
||||||
10.2. Effect of New Versions
|
|
||||||
|
|
||||||
You may distribute the Covered Software under the terms of the version
|
|
||||||
of the License under which You originally received the Covered Software,
|
|
||||||
or under the terms of any subsequent version published by the license
|
|
||||||
steward.
|
|
||||||
|
|
||||||
10.3. Modified Versions
|
|
||||||
|
|
||||||
If you create software not governed by this License, and you want to
|
|
||||||
create a new license for such software, you may create and use a
|
|
||||||
modified version of this License if you rename the license and remove
|
|
||||||
any references to the name of the license steward (except to note that
|
|
||||||
such modified license differs from this License).
|
|
||||||
|
|
||||||
10.4. Distributing Source Code Form that is Incompatible With Secondary
|
|
||||||
Licenses
|
|
||||||
|
|
||||||
If You choose to distribute Source Code Form that is Incompatible With
|
|
||||||
Secondary Licenses under the terms of this version of the License, the
|
|
||||||
notice described in Exhibit B of this License must be attached.
|
|
||||||
|
|
||||||
Exhibit A - Source Code Form License Notice
|
|
||||||
-------------------------------------------
|
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
||||||
|
|
||||||
If it is not possible or desirable to put the notice in a particular
|
|
||||||
file, then You may include the notice in a location (such as a LICENSE
|
|
||||||
file in a relevant directory) where a recipient would be likely to look
|
|
||||||
for such a notice.
|
|
||||||
|
|
||||||
You may add additional accurate notices of copyright ownership.
|
|
||||||
|
|
||||||
Exhibit B - "Incompatible With Secondary Licenses" Notice
|
|
||||||
---------------------------------------------------------
|
|
||||||
|
|
||||||
This Source Code Form is "Incompatible With Secondary Licenses", as
|
|
||||||
defined by the Mozilla Public License, v. 2.0.
|
|
||||||
41
vendor/github.com/letsencrypt/boulder/core/challenges.go
generated
vendored
41
vendor/github.com/letsencrypt/boulder/core/challenges.go
generated
vendored
|
|
@ -1,41 +0,0 @@
|
||||||
package core
|
|
||||||
|
|
||||||
import "fmt"
|
|
||||||
|
|
||||||
func newChallenge(challengeType AcmeChallenge, token string) Challenge {
|
|
||||||
return Challenge{
|
|
||||||
Type: challengeType,
|
|
||||||
Status: StatusPending,
|
|
||||||
Token: token,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// HTTPChallenge01 constructs a http-01 challenge.
|
|
||||||
func HTTPChallenge01(token string) Challenge {
|
|
||||||
return newChallenge(ChallengeTypeHTTP01, token)
|
|
||||||
}
|
|
||||||
|
|
||||||
// DNSChallenge01 constructs a dns-01 challenge.
|
|
||||||
func DNSChallenge01(token string) Challenge {
|
|
||||||
return newChallenge(ChallengeTypeDNS01, token)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TLSALPNChallenge01 constructs a tls-alpn-01 challenge.
|
|
||||||
func TLSALPNChallenge01(token string) Challenge {
|
|
||||||
return newChallenge(ChallengeTypeTLSALPN01, token)
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewChallenge constructs a challenge of the given kind. It returns an
|
|
||||||
// error if the challenge type is unrecognized.
|
|
||||||
func NewChallenge(kind AcmeChallenge, token string) (Challenge, error) {
|
|
||||||
switch kind {
|
|
||||||
case ChallengeTypeHTTP01:
|
|
||||||
return HTTPChallenge01(token), nil
|
|
||||||
case ChallengeTypeDNS01:
|
|
||||||
return DNSChallenge01(token), nil
|
|
||||||
case ChallengeTypeTLSALPN01:
|
|
||||||
return TLSALPNChallenge01(token), nil
|
|
||||||
default:
|
|
||||||
return Challenge{}, fmt.Errorf("unrecognized challenge type %q", kind)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
14
vendor/github.com/letsencrypt/boulder/core/interfaces.go
generated
vendored
14
vendor/github.com/letsencrypt/boulder/core/interfaces.go
generated
vendored
|
|
@ -1,14 +0,0 @@
|
||||||
package core
|
|
||||||
|
|
||||||
import (
|
|
||||||
"github.com/letsencrypt/boulder/identifier"
|
|
||||||
)
|
|
||||||
|
|
||||||
// PolicyAuthority defines the public interface for the Boulder PA
|
|
||||||
// TODO(#5891): Move this interface to a more appropriate location.
|
|
||||||
type PolicyAuthority interface {
|
|
||||||
WillingToIssue([]string) error
|
|
||||||
ChallengesFor(identifier.ACMEIdentifier) ([]Challenge, error)
|
|
||||||
ChallengeTypeEnabled(AcmeChallenge) bool
|
|
||||||
CheckAuthz(*Authorization) error
|
|
||||||
}
|
|
||||||
505
vendor/github.com/letsencrypt/boulder/core/objects.go
generated
vendored
505
vendor/github.com/letsencrypt/boulder/core/objects.go
generated
vendored
|
|
@ -1,505 +0,0 @@
|
||||||
package core
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto"
|
|
||||||
"encoding/base64"
|
|
||||||
"encoding/json"
|
|
||||||
"fmt"
|
|
||||||
"hash/fnv"
|
|
||||||
"net"
|
|
||||||
"strings"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/go-jose/go-jose/v4"
|
|
||||||
"golang.org/x/crypto/ocsp"
|
|
||||||
|
|
||||||
"github.com/letsencrypt/boulder/identifier"
|
|
||||||
"github.com/letsencrypt/boulder/probs"
|
|
||||||
"github.com/letsencrypt/boulder/revocation"
|
|
||||||
)
|
|
||||||
|
|
||||||
// AcmeStatus defines the state of a given authorization
|
|
||||||
type AcmeStatus string
|
|
||||||
|
|
||||||
// These statuses are the states of authorizations, challenges, and registrations
|
|
||||||
const (
|
|
||||||
StatusUnknown = AcmeStatus("unknown") // Unknown status; the default
|
|
||||||
StatusPending = AcmeStatus("pending") // In process; client has next action
|
|
||||||
StatusProcessing = AcmeStatus("processing") // In process; server has next action
|
|
||||||
StatusReady = AcmeStatus("ready") // Order is ready for finalization
|
|
||||||
StatusValid = AcmeStatus("valid") // Object is valid
|
|
||||||
StatusInvalid = AcmeStatus("invalid") // Validation failed
|
|
||||||
StatusRevoked = AcmeStatus("revoked") // Object no longer valid
|
|
||||||
StatusDeactivated = AcmeStatus("deactivated") // Object has been deactivated
|
|
||||||
)
|
|
||||||
|
|
||||||
// AcmeResource values identify different types of ACME resources
|
|
||||||
type AcmeResource string
|
|
||||||
|
|
||||||
// The types of ACME resources
|
|
||||||
const (
|
|
||||||
ResourceNewReg = AcmeResource("new-reg")
|
|
||||||
ResourceNewAuthz = AcmeResource("new-authz")
|
|
||||||
ResourceNewCert = AcmeResource("new-cert")
|
|
||||||
ResourceRevokeCert = AcmeResource("revoke-cert")
|
|
||||||
ResourceRegistration = AcmeResource("reg")
|
|
||||||
ResourceChallenge = AcmeResource("challenge")
|
|
||||||
ResourceAuthz = AcmeResource("authz")
|
|
||||||
ResourceKeyChange = AcmeResource("key-change")
|
|
||||||
)
|
|
||||||
|
|
||||||
// AcmeChallenge values identify different types of ACME challenges
|
|
||||||
type AcmeChallenge string
|
|
||||||
|
|
||||||
// These types are the available challenges
|
|
||||||
const (
|
|
||||||
ChallengeTypeHTTP01 = AcmeChallenge("http-01")
|
|
||||||
ChallengeTypeDNS01 = AcmeChallenge("dns-01")
|
|
||||||
ChallengeTypeTLSALPN01 = AcmeChallenge("tls-alpn-01")
|
|
||||||
)
|
|
||||||
|
|
||||||
// IsValid tests whether the challenge is a known challenge
|
|
||||||
func (c AcmeChallenge) IsValid() bool {
|
|
||||||
switch c {
|
|
||||||
case ChallengeTypeHTTP01, ChallengeTypeDNS01, ChallengeTypeTLSALPN01:
|
|
||||||
return true
|
|
||||||
default:
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// OCSPStatus defines the state of OCSP for a domain
|
|
||||||
type OCSPStatus string
|
|
||||||
|
|
||||||
// These status are the states of OCSP
|
|
||||||
const (
|
|
||||||
OCSPStatusGood = OCSPStatus("good")
|
|
||||||
OCSPStatusRevoked = OCSPStatus("revoked")
|
|
||||||
// Not a real OCSP status. This is a placeholder we write before the
|
|
||||||
// actual precertificate is issued, to ensure we never return "good" before
|
|
||||||
// issuance succeeds, for BR compliance reasons.
|
|
||||||
OCSPStatusNotReady = OCSPStatus("wait")
|
|
||||||
)
|
|
||||||
|
|
||||||
var OCSPStatusToInt = map[OCSPStatus]int{
|
|
||||||
OCSPStatusGood: ocsp.Good,
|
|
||||||
OCSPStatusRevoked: ocsp.Revoked,
|
|
||||||
OCSPStatusNotReady: -1,
|
|
||||||
}
|
|
||||||
|
|
||||||
// DNSPrefix is attached to DNS names in DNS challenges
|
|
||||||
const DNSPrefix = "_acme-challenge"
|
|
||||||
|
|
||||||
type RawCertificateRequest struct {
|
|
||||||
CSR JSONBuffer `json:"csr"` // The encoded CSR
|
|
||||||
}
|
|
||||||
|
|
||||||
// Registration objects represent non-public metadata attached
|
|
||||||
// to account keys.
|
|
||||||
type Registration struct {
|
|
||||||
// Unique identifier
|
|
||||||
ID int64 `json:"id,omitempty" db:"id"`
|
|
||||||
|
|
||||||
// Account key to which the details are attached
|
|
||||||
Key *jose.JSONWebKey `json:"key"`
|
|
||||||
|
|
||||||
// Contact URIs
|
|
||||||
Contact *[]string `json:"contact,omitempty"`
|
|
||||||
|
|
||||||
// Agreement with terms of service
|
|
||||||
Agreement string `json:"agreement,omitempty"`
|
|
||||||
|
|
||||||
// InitialIP is the IP address from which the registration was created
|
|
||||||
InitialIP net.IP `json:"initialIp"`
|
|
||||||
|
|
||||||
// CreatedAt is the time the registration was created.
|
|
||||||
CreatedAt *time.Time `json:"createdAt,omitempty"`
|
|
||||||
|
|
||||||
Status AcmeStatus `json:"status"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// ValidationRecord represents a validation attempt against a specific URL/hostname
|
|
||||||
// and the IP addresses that were resolved and used.
|
|
||||||
type ValidationRecord struct {
|
|
||||||
// SimpleHTTP only
|
|
||||||
URL string `json:"url,omitempty"`
|
|
||||||
|
|
||||||
// Shared
|
|
||||||
Hostname string `json:"hostname,omitempty"`
|
|
||||||
Port string `json:"port,omitempty"`
|
|
||||||
AddressesResolved []net.IP `json:"addressesResolved,omitempty"`
|
|
||||||
AddressUsed net.IP `json:"addressUsed,omitempty"`
|
|
||||||
// AddressesTried contains a list of addresses tried before the `AddressUsed`.
|
|
||||||
// Presently this will only ever be one IP from `AddressesResolved` since the
|
|
||||||
// only retry is in the case of a v6 failure with one v4 fallback. E.g. if
|
|
||||||
// a record with `AddressesResolved: { 127.0.0.1, ::1 }` were processed for
|
|
||||||
// a challenge validation with the IPv6 first flag on and the ::1 address
|
|
||||||
// failed but the 127.0.0.1 retry succeeded then the record would end up
|
|
||||||
// being:
|
|
||||||
// {
|
|
||||||
// ...
|
|
||||||
// AddressesResolved: [ 127.0.0.1, ::1 ],
|
|
||||||
// AddressUsed: 127.0.0.1
|
|
||||||
// AddressesTried: [ ::1 ],
|
|
||||||
// ...
|
|
||||||
// }
|
|
||||||
AddressesTried []net.IP `json:"addressesTried,omitempty"`
|
|
||||||
// ResolverAddrs is the host:port of the DNS resolver(s) that fulfilled the
|
|
||||||
// lookup for AddressUsed. During recursive A and AAAA lookups, a record may
|
|
||||||
// instead look like A:host:port or AAAA:host:port
|
|
||||||
ResolverAddrs []string `json:"resolverAddrs,omitempty"`
|
|
||||||
// UsedRSAKEX is a *temporary* addition to the validation record, so we can
|
|
||||||
// see how many servers that we reach out to during HTTP-01 and TLS-ALPN-01
|
|
||||||
// validation are only willing to negotiate RSA key exchange mechanisms. The
|
|
||||||
// field is not included in the serialized json to avoid cluttering the
|
|
||||||
// database and log lines.
|
|
||||||
// TODO(#7321): Remove this when we have collected sufficient data.
|
|
||||||
UsedRSAKEX bool `json:"-"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// Challenge is an aggregate of all data needed for any challenges.
|
|
||||||
//
|
|
||||||
// Rather than define individual types for different types of
|
|
||||||
// challenge, we just throw all the elements into one bucket,
|
|
||||||
// together with the common metadata elements.
|
|
||||||
type Challenge struct {
|
|
||||||
// Type is the type of challenge encoded in this object.
|
|
||||||
Type AcmeChallenge `json:"type"`
|
|
||||||
|
|
||||||
// URL is the URL to which a response can be posted. Required for all types.
|
|
||||||
URL string `json:"url,omitempty"`
|
|
||||||
|
|
||||||
// Status is the status of this challenge. Required for all types.
|
|
||||||
Status AcmeStatus `json:"status,omitempty"`
|
|
||||||
|
|
||||||
// Validated is the time at which the server validated the challenge. Required
|
|
||||||
// if status is valid.
|
|
||||||
Validated *time.Time `json:"validated,omitempty"`
|
|
||||||
|
|
||||||
// Error contains the error that occurred during challenge validation, if any.
|
|
||||||
// If set, the Status must be "invalid".
|
|
||||||
Error *probs.ProblemDetails `json:"error,omitempty"`
|
|
||||||
|
|
||||||
// Token is a random value that uniquely identifies the challenge. It is used
|
|
||||||
// by all current challenges (http-01, tls-alpn-01, and dns-01).
|
|
||||||
Token string `json:"token,omitempty"`
|
|
||||||
|
|
||||||
// ProvidedKeyAuthorization used to carry the expected key authorization from
|
|
||||||
// the RA to the VA. However, since this field is never presented to the user
|
|
||||||
// via the ACME API, it should not be on this type.
|
|
||||||
//
|
|
||||||
// Deprecated: use vapb.PerformValidationRequest.ExpectedKeyAuthorization instead.
|
|
||||||
// TODO(#7514): Remove this.
|
|
||||||
ProvidedKeyAuthorization string `json:"keyAuthorization,omitempty"`
|
|
||||||
|
|
||||||
// Contains information about URLs used or redirected to and IPs resolved and
|
|
||||||
// used
|
|
||||||
ValidationRecord []ValidationRecord `json:"validationRecord,omitempty"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// ExpectedKeyAuthorization computes the expected KeyAuthorization value for
|
|
||||||
// the challenge.
|
|
||||||
func (ch Challenge) ExpectedKeyAuthorization(key *jose.JSONWebKey) (string, error) {
|
|
||||||
if key == nil {
|
|
||||||
return "", fmt.Errorf("Cannot authorize a nil key")
|
|
||||||
}
|
|
||||||
|
|
||||||
thumbprint, err := key.Thumbprint(crypto.SHA256)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
|
|
||||||
return ch.Token + "." + base64.RawURLEncoding.EncodeToString(thumbprint), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// RecordsSane checks the sanity of a ValidationRecord object before sending it
|
|
||||||
// back to the RA to be stored.
|
|
||||||
func (ch Challenge) RecordsSane() bool {
|
|
||||||
if ch.ValidationRecord == nil || len(ch.ValidationRecord) == 0 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
switch ch.Type {
|
|
||||||
case ChallengeTypeHTTP01:
|
|
||||||
for _, rec := range ch.ValidationRecord {
|
|
||||||
// TODO(#7140): Add a check for ResolverAddress == "" only after the
|
|
||||||
// core.proto change has been deployed.
|
|
||||||
if rec.URL == "" || rec.Hostname == "" || rec.Port == "" || rec.AddressUsed == nil ||
|
|
||||||
len(rec.AddressesResolved) == 0 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
case ChallengeTypeTLSALPN01:
|
|
||||||
if len(ch.ValidationRecord) > 1 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
if ch.ValidationRecord[0].URL != "" {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
// TODO(#7140): Add a check for ResolverAddress == "" only after the
|
|
||||||
// core.proto change has been deployed.
|
|
||||||
if ch.ValidationRecord[0].Hostname == "" || ch.ValidationRecord[0].Port == "" ||
|
|
||||||
ch.ValidationRecord[0].AddressUsed == nil || len(ch.ValidationRecord[0].AddressesResolved) == 0 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
case ChallengeTypeDNS01:
|
|
||||||
if len(ch.ValidationRecord) > 1 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
// TODO(#7140): Add a check for ResolverAddress == "" only after the
|
|
||||||
// core.proto change has been deployed.
|
|
||||||
if ch.ValidationRecord[0].Hostname == "" {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
default: // Unsupported challenge type
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
// CheckPending ensures that a challenge object is pending and has a token.
|
|
||||||
// This is used before offering the challenge to the client, and before actually
|
|
||||||
// validating a challenge.
|
|
||||||
func (ch Challenge) CheckPending() error {
|
|
||||||
if ch.Status != StatusPending {
|
|
||||||
return fmt.Errorf("challenge is not pending")
|
|
||||||
}
|
|
||||||
|
|
||||||
if !looksLikeAToken(ch.Token) {
|
|
||||||
return fmt.Errorf("token is missing or malformed")
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// StringID is used to generate a ID for challenges associated with new style authorizations.
|
|
||||||
// This is necessary as these challenges no longer have a unique non-sequential identifier
|
|
||||||
// in the new storage scheme. This identifier is generated by constructing a fnv hash over the
|
|
||||||
// challenge token and type and encoding the first 4 bytes of it using the base64 URL encoding.
|
|
||||||
func (ch Challenge) StringID() string {
|
|
||||||
h := fnv.New128a()
|
|
||||||
h.Write([]byte(ch.Token))
|
|
||||||
h.Write([]byte(ch.Type))
|
|
||||||
return base64.RawURLEncoding.EncodeToString(h.Sum(nil)[0:4])
|
|
||||||
}
|
|
||||||
|
|
||||||
// Authorization represents the authorization of an account key holder
|
|
||||||
// to act on behalf of a domain. This struct is intended to be used both
|
|
||||||
// internally and for JSON marshaling on the wire. Any fields that should be
|
|
||||||
// suppressed on the wire (e.g., ID, regID) must be made empty before marshaling.
|
|
||||||
type Authorization struct {
|
|
||||||
// An identifier for this authorization, unique across
|
|
||||||
// authorizations and certificates within this instance.
|
|
||||||
ID string `json:"id,omitempty" db:"id"`
|
|
||||||
|
|
||||||
// The identifier for which authorization is being given
|
|
||||||
Identifier identifier.ACMEIdentifier `json:"identifier,omitempty" db:"identifier"`
|
|
||||||
|
|
||||||
// The registration ID associated with the authorization
|
|
||||||
RegistrationID int64 `json:"regId,omitempty" db:"registrationID"`
|
|
||||||
|
|
||||||
// The status of the validation of this authorization
|
|
||||||
Status AcmeStatus `json:"status,omitempty" db:"status"`
|
|
||||||
|
|
||||||
// The date after which this authorization will be no
|
|
||||||
// longer be considered valid. Note: a certificate may be issued even on the
|
|
||||||
// last day of an authorization's lifetime. The last day for which someone can
|
|
||||||
// hold a valid certificate based on an authorization is authorization
|
|
||||||
// lifetime + certificate lifetime.
|
|
||||||
Expires *time.Time `json:"expires,omitempty" db:"expires"`
|
|
||||||
|
|
||||||
// An array of challenges objects used to validate the
|
|
||||||
// applicant's control of the identifier. For authorizations
|
|
||||||
// in process, these are challenges to be fulfilled; for
|
|
||||||
// final authorizations, they describe the evidence that
|
|
||||||
// the server used in support of granting the authorization.
|
|
||||||
//
|
|
||||||
// There should only ever be one challenge of each type in this
|
|
||||||
// slice and the order of these challenges may not be predictable.
|
|
||||||
Challenges []Challenge `json:"challenges,omitempty" db:"-"`
|
|
||||||
|
|
||||||
// https://datatracker.ietf.org/doc/html/rfc8555#page-29
|
|
||||||
//
|
|
||||||
// wildcard (optional, boolean): This field MUST be present and true
|
|
||||||
// for authorizations created as a result of a newOrder request
|
|
||||||
// containing a DNS identifier with a value that was a wildcard
|
|
||||||
// domain name. For other authorizations, it MUST be absent.
|
|
||||||
// Wildcard domain names are described in Section 7.1.3.
|
|
||||||
//
|
|
||||||
// This is not represented in the database because we calculate it from
|
|
||||||
// the identifier stored in the database. Unlike the identifier returned
|
|
||||||
// as part of the authorization, the identifier we store in the database
|
|
||||||
// can contain an asterisk.
|
|
||||||
Wildcard bool `json:"wildcard,omitempty" db:"-"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// FindChallengeByStringID will look for a challenge matching the given ID inside
|
|
||||||
// this authorization. If found, it will return the index of that challenge within
|
|
||||||
// the Authorization's Challenges array. Otherwise it will return -1.
|
|
||||||
func (authz *Authorization) FindChallengeByStringID(id string) int {
|
|
||||||
for i, c := range authz.Challenges {
|
|
||||||
if c.StringID() == id {
|
|
||||||
return i
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
|
|
||||||
// SolvedBy will look through the Authorizations challenges, returning the type
|
|
||||||
// of the *first* challenge it finds with Status: valid, or an error if no
|
|
||||||
// challenge is valid.
|
|
||||||
func (authz *Authorization) SolvedBy() (AcmeChallenge, error) {
|
|
||||||
if len(authz.Challenges) == 0 {
|
|
||||||
return "", fmt.Errorf("Authorization has no challenges")
|
|
||||||
}
|
|
||||||
for _, chal := range authz.Challenges {
|
|
||||||
if chal.Status == StatusValid {
|
|
||||||
return chal.Type, nil
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return "", fmt.Errorf("Authorization not solved by any challenge")
|
|
||||||
}
|
|
||||||
|
|
||||||
// JSONBuffer fields get encoded and decoded JOSE-style, in base64url encoding
|
|
||||||
// with stripped padding.
|
|
||||||
type JSONBuffer []byte
|
|
||||||
|
|
||||||
// MarshalJSON encodes a JSONBuffer for transmission.
|
|
||||||
func (jb JSONBuffer) MarshalJSON() (result []byte, err error) {
|
|
||||||
return json.Marshal(base64.RawURLEncoding.EncodeToString(jb))
|
|
||||||
}
|
|
||||||
|
|
||||||
// UnmarshalJSON decodes a JSONBuffer to an object.
|
|
||||||
func (jb *JSONBuffer) UnmarshalJSON(data []byte) (err error) {
|
|
||||||
var str string
|
|
||||||
err = json.Unmarshal(data, &str)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
*jb, err = base64.RawURLEncoding.DecodeString(strings.TrimRight(str, "="))
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// Certificate objects are entirely internal to the server. The only
|
|
||||||
// thing exposed on the wire is the certificate itself.
|
|
||||||
type Certificate struct {
|
|
||||||
ID int64 `db:"id"`
|
|
||||||
RegistrationID int64 `db:"registrationID"`
|
|
||||||
|
|
||||||
Serial string `db:"serial"`
|
|
||||||
Digest string `db:"digest"`
|
|
||||||
DER []byte `db:"der"`
|
|
||||||
Issued time.Time `db:"issued"`
|
|
||||||
Expires time.Time `db:"expires"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// CertificateStatus structs are internal to the server. They represent the
|
|
||||||
// latest data about the status of the certificate, required for generating new
|
|
||||||
// OCSP responses and determining if a certificate has been revoked.
|
|
||||||
type CertificateStatus struct {
|
|
||||||
ID int64 `db:"id"`
|
|
||||||
|
|
||||||
Serial string `db:"serial"`
|
|
||||||
|
|
||||||
// status: 'good' or 'revoked'. Note that good, expired certificates remain
|
|
||||||
// with status 'good' but don't necessarily get fresh OCSP responses.
|
|
||||||
Status OCSPStatus `db:"status"`
|
|
||||||
|
|
||||||
// ocspLastUpdated: The date and time of the last time we generated an OCSP
|
|
||||||
// response. If we have never generated one, this has the zero value of
|
|
||||||
// time.Time, i.e. Jan 1 1970.
|
|
||||||
OCSPLastUpdated time.Time `db:"ocspLastUpdated"`
|
|
||||||
|
|
||||||
// revokedDate: If status is 'revoked', this is the date and time it was
|
|
||||||
// revoked. Otherwise it has the zero value of time.Time, i.e. Jan 1 1970.
|
|
||||||
RevokedDate time.Time `db:"revokedDate"`
|
|
||||||
|
|
||||||
// revokedReason: If status is 'revoked', this is the reason code for the
|
|
||||||
// revocation. Otherwise it is zero (which happens to be the reason
|
|
||||||
// code for 'unspecified').
|
|
||||||
RevokedReason revocation.Reason `db:"revokedReason"`
|
|
||||||
|
|
||||||
LastExpirationNagSent time.Time `db:"lastExpirationNagSent"`
|
|
||||||
|
|
||||||
// NotAfter and IsExpired are convenience columns which allow expensive
|
|
||||||
// queries to quickly filter out certificates that we don't need to care about
|
|
||||||
// anymore. These are particularly useful for the expiration mailer and CRL
|
|
||||||
// updater. See https://github.com/letsencrypt/boulder/issues/1864.
|
|
||||||
NotAfter time.Time `db:"notAfter"`
|
|
||||||
IsExpired bool `db:"isExpired"`
|
|
||||||
|
|
||||||
// Note: this is not an issuance.IssuerNameID because that would create an
|
|
||||||
// import cycle between core and issuance.
|
|
||||||
// Note2: This field used to be called `issuerID`. We keep the old name in
|
|
||||||
// the DB, but update the Go field name to be clear which type of ID this
|
|
||||||
// is.
|
|
||||||
IssuerNameID int64 `db:"issuerID"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// FQDNSet contains the SHA256 hash of the lowercased, comma joined dNSNames
|
|
||||||
// contained in a certificate.
|
|
||||||
type FQDNSet struct {
|
|
||||||
ID int64
|
|
||||||
SetHash []byte
|
|
||||||
Serial string
|
|
||||||
Issued time.Time
|
|
||||||
Expires time.Time
|
|
||||||
}
|
|
||||||
|
|
||||||
// SCTDERs is a convenience type
|
|
||||||
type SCTDERs [][]byte
|
|
||||||
|
|
||||||
// CertDER is a convenience type that helps differentiate what the
|
|
||||||
// underlying byte slice contains
|
|
||||||
type CertDER []byte
|
|
||||||
|
|
||||||
// SuggestedWindow is a type exposed inside the RenewalInfo resource.
|
|
||||||
type SuggestedWindow struct {
|
|
||||||
Start time.Time `json:"start"`
|
|
||||||
End time.Time `json:"end"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// IsWithin returns true if the given time is within the suggested window,
|
|
||||||
// inclusive of the start time and exclusive of the end time.
|
|
||||||
func (window SuggestedWindow) IsWithin(now time.Time) bool {
|
|
||||||
return !now.Before(window.Start) && now.Before(window.End)
|
|
||||||
}
|
|
||||||
|
|
||||||
// RenewalInfo is a type which is exposed to clients which query the renewalInfo
|
|
||||||
// endpoint specified in draft-aaron-ari.
|
|
||||||
type RenewalInfo struct {
|
|
||||||
SuggestedWindow SuggestedWindow `json:"suggestedWindow"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// RenewalInfoSimple constructs a `RenewalInfo` object and suggested window
|
|
||||||
// using a very simple renewal calculation: calculate a point 2/3rds of the way
|
|
||||||
// through the validity period, then give a 2-day window around that. Both the
|
|
||||||
// `issued` and `expires` timestamps are expected to be UTC.
|
|
||||||
func RenewalInfoSimple(issued time.Time, expires time.Time) RenewalInfo {
|
|
||||||
validity := expires.Add(time.Second).Sub(issued)
|
|
||||||
renewalOffset := validity / time.Duration(3)
|
|
||||||
idealRenewal := expires.Add(-renewalOffset)
|
|
||||||
return RenewalInfo{
|
|
||||||
SuggestedWindow: SuggestedWindow{
|
|
||||||
Start: idealRenewal.Add(-24 * time.Hour),
|
|
||||||
End: idealRenewal.Add(24 * time.Hour),
|
|
||||||
},
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// RenewalInfoImmediate constructs a `RenewalInfo` object with a suggested
|
|
||||||
// window in the past. Per the draft-ietf-acme-ari-01 spec, clients should
|
|
||||||
// attempt to renew immediately if the suggested window is in the past. The
|
|
||||||
// passed `now` is assumed to be a timestamp representing the current moment in
|
|
||||||
// time.
|
|
||||||
func RenewalInfoImmediate(now time.Time) RenewalInfo {
|
|
||||||
oneHourAgo := now.Add(-1 * time.Hour)
|
|
||||||
return RenewalInfo{
|
|
||||||
SuggestedWindow: SuggestedWindow{
|
|
||||||
Start: oneHourAgo,
|
|
||||||
End: oneHourAgo.Add(time.Minute * 30),
|
|
||||||
},
|
|
||||||
}
|
|
||||||
}
|
|
||||||
383
vendor/github.com/letsencrypt/boulder/core/util.go
generated
vendored
383
vendor/github.com/letsencrypt/boulder/core/util.go
generated
vendored
|
|
@ -1,383 +0,0 @@
|
||||||
package core
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto"
|
|
||||||
"crypto/ecdsa"
|
|
||||||
"crypto/rand"
|
|
||||||
"crypto/rsa"
|
|
||||||
"crypto/sha256"
|
|
||||||
"crypto/x509"
|
|
||||||
"encoding/base64"
|
|
||||||
"encoding/hex"
|
|
||||||
"encoding/pem"
|
|
||||||
"errors"
|
|
||||||
"expvar"
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
"math/big"
|
|
||||||
mrand "math/rand"
|
|
||||||
"os"
|
|
||||||
"path"
|
|
||||||
"reflect"
|
|
||||||
"regexp"
|
|
||||||
"sort"
|
|
||||||
"strings"
|
|
||||||
"time"
|
|
||||||
"unicode"
|
|
||||||
|
|
||||||
"github.com/go-jose/go-jose/v4"
|
|
||||||
"google.golang.org/protobuf/types/known/durationpb"
|
|
||||||
"google.golang.org/protobuf/types/known/timestamppb"
|
|
||||||
)
|
|
||||||
|
|
||||||
const Unspecified = "Unspecified"
|
|
||||||
|
|
||||||
// Package Variables Variables
|
|
||||||
|
|
||||||
// BuildID is set by the compiler (using -ldflags "-X core.BuildID $(git rev-parse --short HEAD)")
|
|
||||||
// and is used by GetBuildID
|
|
||||||
var BuildID string
|
|
||||||
|
|
||||||
// BuildHost is set by the compiler and is used by GetBuildHost
|
|
||||||
var BuildHost string
|
|
||||||
|
|
||||||
// BuildTime is set by the compiler and is used by GetBuildTime
|
|
||||||
var BuildTime string
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
expvar.NewString("BuildID").Set(BuildID)
|
|
||||||
expvar.NewString("BuildTime").Set(BuildTime)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Random stuff
|
|
||||||
|
|
||||||
type randSource interface {
|
|
||||||
Read(p []byte) (n int, err error)
|
|
||||||
}
|
|
||||||
|
|
||||||
// RandReader is used so that it can be replaced in tests that require
|
|
||||||
// deterministic output
|
|
||||||
var RandReader randSource = rand.Reader
|
|
||||||
|
|
||||||
// RandomString returns a randomly generated string of the requested length.
|
|
||||||
func RandomString(byteLength int) string {
|
|
||||||
b := make([]byte, byteLength)
|
|
||||||
_, err := io.ReadFull(RandReader, b)
|
|
||||||
if err != nil {
|
|
||||||
panic(fmt.Sprintf("Error reading random bytes: %s", err))
|
|
||||||
}
|
|
||||||
return base64.RawURLEncoding.EncodeToString(b)
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewToken produces a random string for Challenges, etc.
|
|
||||||
func NewToken() string {
|
|
||||||
return RandomString(32)
|
|
||||||
}
|
|
||||||
|
|
||||||
var tokenFormat = regexp.MustCompile(`^[\w-]{43}$`)
|
|
||||||
|
|
||||||
// looksLikeAToken checks whether a string represents a 32-octet value in
|
|
||||||
// the URL-safe base64 alphabet.
|
|
||||||
func looksLikeAToken(token string) bool {
|
|
||||||
return tokenFormat.MatchString(token)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Fingerprints
|
|
||||||
|
|
||||||
// Fingerprint256 produces an unpadded, URL-safe Base64-encoded SHA256 digest
|
|
||||||
// of the data.
|
|
||||||
func Fingerprint256(data []byte) string {
|
|
||||||
d := sha256.New()
|
|
||||||
_, _ = d.Write(data) // Never returns an error
|
|
||||||
return base64.RawURLEncoding.EncodeToString(d.Sum(nil))
|
|
||||||
}
|
|
||||||
|
|
||||||
type Sha256Digest [sha256.Size]byte
|
|
||||||
|
|
||||||
// KeyDigest produces the SHA256 digest of a provided public key.
|
|
||||||
func KeyDigest(key crypto.PublicKey) (Sha256Digest, error) {
|
|
||||||
switch t := key.(type) {
|
|
||||||
case *jose.JSONWebKey:
|
|
||||||
if t == nil {
|
|
||||||
return Sha256Digest{}, errors.New("cannot compute digest of nil key")
|
|
||||||
}
|
|
||||||
return KeyDigest(t.Key)
|
|
||||||
case jose.JSONWebKey:
|
|
||||||
return KeyDigest(t.Key)
|
|
||||||
default:
|
|
||||||
keyDER, err := x509.MarshalPKIXPublicKey(key)
|
|
||||||
if err != nil {
|
|
||||||
return Sha256Digest{}, err
|
|
||||||
}
|
|
||||||
return sha256.Sum256(keyDER), nil
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// KeyDigestB64 produces a padded, standard Base64-encoded SHA256 digest of a
|
|
||||||
// provided public key.
|
|
||||||
func KeyDigestB64(key crypto.PublicKey) (string, error) {
|
|
||||||
digest, err := KeyDigest(key)
|
|
||||||
if err != nil {
|
|
||||||
return "", err
|
|
||||||
}
|
|
||||||
return base64.StdEncoding.EncodeToString(digest[:]), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// KeyDigestEquals determines whether two public keys have the same digest.
|
|
||||||
func KeyDigestEquals(j, k crypto.PublicKey) bool {
|
|
||||||
digestJ, errJ := KeyDigestB64(j)
|
|
||||||
digestK, errK := KeyDigestB64(k)
|
|
||||||
// Keys that don't have a valid digest (due to marshalling problems)
|
|
||||||
// are never equal. So, e.g. nil keys are not equal.
|
|
||||||
if errJ != nil || errK != nil {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return digestJ == digestK
|
|
||||||
}
|
|
||||||
|
|
||||||
// PublicKeysEqual determines whether two public keys are identical.
|
|
||||||
func PublicKeysEqual(a, b crypto.PublicKey) (bool, error) {
|
|
||||||
switch ak := a.(type) {
|
|
||||||
case *rsa.PublicKey:
|
|
||||||
return ak.Equal(b), nil
|
|
||||||
case *ecdsa.PublicKey:
|
|
||||||
return ak.Equal(b), nil
|
|
||||||
default:
|
|
||||||
return false, fmt.Errorf("unsupported public key type %T", ak)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// SerialToString converts a certificate serial number (big.Int) to a String
|
|
||||||
// consistently.
|
|
||||||
func SerialToString(serial *big.Int) string {
|
|
||||||
return fmt.Sprintf("%036x", serial)
|
|
||||||
}
|
|
||||||
|
|
||||||
// StringToSerial converts a string into a certificate serial number (big.Int)
|
|
||||||
// consistently.
|
|
||||||
func StringToSerial(serial string) (*big.Int, error) {
|
|
||||||
var serialNum big.Int
|
|
||||||
if !ValidSerial(serial) {
|
|
||||||
return &serialNum, fmt.Errorf("invalid serial number %q", serial)
|
|
||||||
}
|
|
||||||
_, err := fmt.Sscanf(serial, "%036x", &serialNum)
|
|
||||||
return &serialNum, err
|
|
||||||
}
|
|
||||||
|
|
||||||
// ValidSerial tests whether the input string represents a syntactically
|
|
||||||
// valid serial number, i.e., that it is a valid hex string between 32
|
|
||||||
// and 36 characters long.
|
|
||||||
func ValidSerial(serial string) bool {
|
|
||||||
// Originally, serial numbers were 32 hex characters long. We later increased
|
|
||||||
// them to 36, but we allow the shorter ones because they exist in some
|
|
||||||
// production databases.
|
|
||||||
if len(serial) != 32 && len(serial) != 36 {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
_, err := hex.DecodeString(serial)
|
|
||||||
return err == nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// GetBuildID identifies what build is running.
|
|
||||||
func GetBuildID() (retID string) {
|
|
||||||
retID = BuildID
|
|
||||||
if retID == "" {
|
|
||||||
retID = Unspecified
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// GetBuildTime identifies when this build was made
|
|
||||||
func GetBuildTime() (retID string) {
|
|
||||||
retID = BuildTime
|
|
||||||
if retID == "" {
|
|
||||||
retID = Unspecified
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// GetBuildHost identifies the building host
|
|
||||||
func GetBuildHost() (retID string) {
|
|
||||||
retID = BuildHost
|
|
||||||
if retID == "" {
|
|
||||||
retID = Unspecified
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// IsAnyNilOrZero returns whether any of the supplied values are nil, or (if not)
|
|
||||||
// if any of them is its type's zero-value. This is useful for validating that
|
|
||||||
// all required fields on a proto message are present.
|
|
||||||
func IsAnyNilOrZero(vals ...interface{}) bool {
|
|
||||||
for _, val := range vals {
|
|
||||||
switch v := val.(type) {
|
|
||||||
case nil:
|
|
||||||
return true
|
|
||||||
case bool:
|
|
||||||
if !v {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case string:
|
|
||||||
if v == "" {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case []string:
|
|
||||||
if len(v) == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case byte:
|
|
||||||
// Byte is an alias for uint8 and will cover that case.
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case []byte:
|
|
||||||
if len(v) == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case int:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case int8:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case int16:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case int32:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case int64:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case uint:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case uint16:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case uint32:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case uint64:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case float32:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case float64:
|
|
||||||
if v == 0 {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case time.Time:
|
|
||||||
if v.IsZero() {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case *timestamppb.Timestamp:
|
|
||||||
if v == nil || v.AsTime().IsZero() {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
case *durationpb.Duration:
|
|
||||||
if v == nil || v.AsDuration() == time.Duration(0) {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
default:
|
|
||||||
if reflect.ValueOf(v).IsZero() {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
// UniqueLowerNames returns the set of all unique names in the input after all
|
|
||||||
// of them are lowercased. The returned names will be in their lowercased form
|
|
||||||
// and sorted alphabetically.
|
|
||||||
func UniqueLowerNames(names []string) (unique []string) {
|
|
||||||
nameMap := make(map[string]int, len(names))
|
|
||||||
for _, name := range names {
|
|
||||||
nameMap[strings.ToLower(name)] = 1
|
|
||||||
}
|
|
||||||
|
|
||||||
unique = make([]string, 0, len(nameMap))
|
|
||||||
for name := range nameMap {
|
|
||||||
unique = append(unique, name)
|
|
||||||
}
|
|
||||||
sort.Strings(unique)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// HashNames returns a hash of the names requested. This is intended for use
|
|
||||||
// when interacting with the orderFqdnSets table and rate limiting.
|
|
||||||
func HashNames(names []string) []byte {
|
|
||||||
names = UniqueLowerNames(names)
|
|
||||||
hash := sha256.Sum256([]byte(strings.Join(names, ",")))
|
|
||||||
return hash[:]
|
|
||||||
}
|
|
||||||
|
|
||||||
// LoadCert loads a PEM certificate specified by filename or returns an error
|
|
||||||
func LoadCert(filename string) (*x509.Certificate, error) {
|
|
||||||
certPEM, err := os.ReadFile(filename)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
block, _ := pem.Decode(certPEM)
|
|
||||||
if block == nil {
|
|
||||||
return nil, fmt.Errorf("no data in cert PEM file %q", filename)
|
|
||||||
}
|
|
||||||
cert, err := x509.ParseCertificate(block.Bytes)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
return cert, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// retryJitter is used to prevent bunched retried queries from falling into lockstep
|
|
||||||
const retryJitter = 0.2
|
|
||||||
|
|
||||||
// RetryBackoff calculates a backoff time based on number of retries, will always
|
|
||||||
// add jitter so requests that start in unison won't fall into lockstep. Because of
|
|
||||||
// this the returned duration can always be larger than the maximum by a factor of
|
|
||||||
// retryJitter. Adapted from
|
|
||||||
// https://github.com/grpc/grpc-go/blob/v1.11.3/backoff.go#L77-L96
|
|
||||||
func RetryBackoff(retries int, base, max time.Duration, factor float64) time.Duration {
|
|
||||||
if retries == 0 {
|
|
||||||
return 0
|
|
||||||
}
|
|
||||||
backoff, fMax := float64(base), float64(max)
|
|
||||||
for backoff < fMax && retries > 1 {
|
|
||||||
backoff *= factor
|
|
||||||
retries--
|
|
||||||
}
|
|
||||||
if backoff > fMax {
|
|
||||||
backoff = fMax
|
|
||||||
}
|
|
||||||
// Randomize backoff delays so that if a cluster of requests start at
|
|
||||||
// the same time, they won't operate in lockstep.
|
|
||||||
backoff *= (1 - retryJitter) + 2*retryJitter*mrand.Float64()
|
|
||||||
return time.Duration(backoff)
|
|
||||||
}
|
|
||||||
|
|
||||||
// IsASCII determines if every character in a string is encoded in
|
|
||||||
// the ASCII character set.
|
|
||||||
func IsASCII(str string) bool {
|
|
||||||
for _, r := range str {
|
|
||||||
if r > unicode.MaxASCII {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
|
|
||||||
func Command() string {
|
|
||||||
return path.Base(os.Args[0])
|
|
||||||
}
|
|
||||||
95
vendor/github.com/letsencrypt/boulder/goodkey/blocked.go
generated
vendored
95
vendor/github.com/letsencrypt/boulder/goodkey/blocked.go
generated
vendored
|
|
@ -1,95 +0,0 @@
|
||||||
package goodkey
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto"
|
|
||||||
"crypto/sha256"
|
|
||||||
"encoding/base64"
|
|
||||||
"encoding/hex"
|
|
||||||
"errors"
|
|
||||||
"os"
|
|
||||||
|
|
||||||
"github.com/letsencrypt/boulder/core"
|
|
||||||
"github.com/letsencrypt/boulder/strictyaml"
|
|
||||||
)
|
|
||||||
|
|
||||||
// blockedKeys is a type for maintaining a map of SHA256 hashes
|
|
||||||
// of SubjectPublicKeyInfo's that should be considered blocked.
|
|
||||||
// blockedKeys are created by using loadBlockedKeysList.
|
|
||||||
type blockedKeys map[core.Sha256Digest]bool
|
|
||||||
|
|
||||||
var ErrWrongDecodedSize = errors.New("not enough bytes decoded for sha256 hash")
|
|
||||||
|
|
||||||
// blocked checks if the given public key is considered administratively
|
|
||||||
// blocked based on a SHA256 hash of the SubjectPublicKeyInfo.
|
|
||||||
// Important: blocked should not be called except on a blockedKeys instance
|
|
||||||
// returned from loadBlockedKeysList.
|
|
||||||
// function should not be used until after `loadBlockedKeysList` has returned.
|
|
||||||
func (b blockedKeys) blocked(key crypto.PublicKey) (bool, error) {
|
|
||||||
hash, err := core.KeyDigest(key)
|
|
||||||
if err != nil {
|
|
||||||
// the bool result should be ignored when err is != nil but to be on the
|
|
||||||
// paranoid side return true anyway so that a key we can't compute the
|
|
||||||
// digest for will always be blocked even if a caller foolishly discards the
|
|
||||||
// err result.
|
|
||||||
return true, err
|
|
||||||
}
|
|
||||||
return b[hash], nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// loadBlockedKeysList creates a blockedKeys object that can be used to check if
|
|
||||||
// a key is blocked. It creates a lookup map from a list of
|
|
||||||
// SHA256 hashes of SubjectPublicKeyInfo's in the input YAML file
|
|
||||||
// with the expected format:
|
|
||||||
//
|
|
||||||
// blocked:
|
|
||||||
// - cuwGhNNI6nfob5aqY90e7BleU6l7rfxku4X3UTJ3Z7M=
|
|
||||||
// <snipped>
|
|
||||||
// - Qebc1V3SkX3izkYRGNJilm9Bcuvf0oox4U2Rn+b4JOE=
|
|
||||||
//
|
|
||||||
// If no hashes are found in the input YAML an error is returned.
|
|
||||||
func loadBlockedKeysList(filename string) (*blockedKeys, error) {
|
|
||||||
yamlBytes, err := os.ReadFile(filename)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
var list struct {
|
|
||||||
BlockedHashes []string `yaml:"blocked"`
|
|
||||||
BlockedHashesHex []string `yaml:"blockedHashesHex"`
|
|
||||||
}
|
|
||||||
err = strictyaml.Unmarshal(yamlBytes, &list)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
if len(list.BlockedHashes) == 0 && len(list.BlockedHashesHex) == 0 {
|
|
||||||
return nil, errors.New("no blocked hashes in YAML")
|
|
||||||
}
|
|
||||||
|
|
||||||
blockedKeys := make(blockedKeys, len(list.BlockedHashes)+len(list.BlockedHashesHex))
|
|
||||||
for _, b64Hash := range list.BlockedHashes {
|
|
||||||
decoded, err := base64.StdEncoding.DecodeString(b64Hash)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
if len(decoded) != sha256.Size {
|
|
||||||
return nil, ErrWrongDecodedSize
|
|
||||||
}
|
|
||||||
var sha256Digest core.Sha256Digest
|
|
||||||
copy(sha256Digest[:], decoded[0:sha256.Size])
|
|
||||||
blockedKeys[sha256Digest] = true
|
|
||||||
}
|
|
||||||
for _, hexHash := range list.BlockedHashesHex {
|
|
||||||
decoded, err := hex.DecodeString(hexHash)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
if len(decoded) != sha256.Size {
|
|
||||||
return nil, ErrWrongDecodedSize
|
|
||||||
}
|
|
||||||
var sha256Digest core.Sha256Digest
|
|
||||||
copy(sha256Digest[:], decoded[0:sha256.Size])
|
|
||||||
blockedKeys[sha256Digest] = true
|
|
||||||
}
|
|
||||||
return &blockedKeys, nil
|
|
||||||
}
|
|
||||||
460
vendor/github.com/letsencrypt/boulder/goodkey/good_key.go
generated
vendored
460
vendor/github.com/letsencrypt/boulder/goodkey/good_key.go
generated
vendored
|
|
@ -1,460 +0,0 @@
|
||||||
package goodkey
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"crypto"
|
|
||||||
"crypto/ecdsa"
|
|
||||||
"crypto/elliptic"
|
|
||||||
"crypto/rsa"
|
|
||||||
"errors"
|
|
||||||
"fmt"
|
|
||||||
"math/big"
|
|
||||||
"sync"
|
|
||||||
|
|
||||||
"github.com/letsencrypt/boulder/core"
|
|
||||||
|
|
||||||
"github.com/titanous/rocacheck"
|
|
||||||
)
|
|
||||||
|
|
||||||
// To generate, run: primes 2 752 | tr '\n' ,
|
|
||||||
var smallPrimeInts = []int64{
|
|
||||||
2, 3, 5, 7, 11, 13, 17, 19, 23, 29, 31, 37, 41, 43, 47,
|
|
||||||
53, 59, 61, 67, 71, 73, 79, 83, 89, 97, 101, 103, 107,
|
|
||||||
109, 113, 127, 131, 137, 139, 149, 151, 157, 163, 167,
|
|
||||||
173, 179, 181, 191, 193, 197, 199, 211, 223, 227, 229,
|
|
||||||
233, 239, 241, 251, 257, 263, 269, 271, 277, 281, 283,
|
|
||||||
293, 307, 311, 313, 317, 331, 337, 347, 349, 353, 359,
|
|
||||||
367, 373, 379, 383, 389, 397, 401, 409, 419, 421, 431,
|
|
||||||
433, 439, 443, 449, 457, 461, 463, 467, 479, 487, 491,
|
|
||||||
499, 503, 509, 521, 523, 541, 547, 557, 563, 569, 571,
|
|
||||||
577, 587, 593, 599, 601, 607, 613, 617, 619, 631, 641,
|
|
||||||
643, 647, 653, 659, 661, 673, 677, 683, 691, 701, 709,
|
|
||||||
719, 727, 733, 739, 743, 751,
|
|
||||||
}
|
|
||||||
|
|
||||||
// singleton defines the object of a Singleton pattern
|
|
||||||
var (
|
|
||||||
smallPrimesSingleton sync.Once
|
|
||||||
smallPrimesProduct *big.Int
|
|
||||||
)
|
|
||||||
|
|
||||||
type Config struct {
|
|
||||||
// AllowedKeys enables or disables specific key algorithms and sizes. If
|
|
||||||
// nil, defaults to just those keys allowed by the Let's Encrypt CPS.
|
|
||||||
AllowedKeys *AllowedKeys
|
|
||||||
// WeakKeyFile is the path to a JSON file containing truncated modulus hashes
|
|
||||||
// of known weak RSA keys. If this config value is empty, then RSA modulus
|
|
||||||
// hash checking will be disabled.
|
|
||||||
WeakKeyFile string
|
|
||||||
// BlockedKeyFile is the path to a YAML file containing base64-encoded SHA256
|
|
||||||
// hashes of PKIX Subject Public Keys that should be blocked. If this config
|
|
||||||
// value is empty, then blocked key checking will be disabled.
|
|
||||||
BlockedKeyFile string
|
|
||||||
// FermatRounds is an integer number of rounds of Fermat's factorization
|
|
||||||
// method that should be performed to attempt to detect keys whose modulus can
|
|
||||||
// be trivially factored because the two factors are very close to each other.
|
|
||||||
// If this config value is empty (0), no factorization will be attempted.
|
|
||||||
FermatRounds int
|
|
||||||
}
|
|
||||||
|
|
||||||
// AllowedKeys is a map of six specific key algorithm and size combinations to
|
|
||||||
// booleans indicating whether keys of that type are considered good.
|
|
||||||
type AllowedKeys struct {
|
|
||||||
// Baseline Requirements, Section 6.1.5 requires key size >= 2048 and a multiple
|
|
||||||
// of 8 bits: https://github.com/cabforum/servercert/blob/main/docs/BR.md#615-key-sizes
|
|
||||||
// Baseline Requirements, Section 6.1.1.3 requires that we reject any keys which
|
|
||||||
// have a known method to easily compute their private key, such as Debian Weak
|
|
||||||
// Keys. Our enforcement mechanism relies on enumerating all Debian Weak Keys at
|
|
||||||
// common key sizes, so we restrict all issuance to those common key sizes.
|
|
||||||
RSA2048 bool
|
|
||||||
RSA3072 bool
|
|
||||||
RSA4096 bool
|
|
||||||
// Baseline Requirements, Section 6.1.5 requires that ECDSA keys be valid
|
|
||||||
// points on the NIST P-256, P-384, or P-521 elliptic curves.
|
|
||||||
ECDSAP256 bool
|
|
||||||
ECDSAP384 bool
|
|
||||||
ECDSAP521 bool
|
|
||||||
}
|
|
||||||
|
|
||||||
// LetsEncryptCPS encodes the five key algorithms and sizes allowed by the Let's
|
|
||||||
// Encrypt CPS CV-SSL Subscriber Certificate Profile: RSA 2048, RSA 3076, RSA
|
|
||||||
// 4096, ECDSA 256 and ECDSA P384.
|
|
||||||
// https://github.com/letsencrypt/cp-cps/blob/main/CP-CPS.md#dv-ssl-subscriber-certificate
|
|
||||||
// If this is ever changed, the CP/CPS MUST be changed first.
|
|
||||||
func LetsEncryptCPS() AllowedKeys {
|
|
||||||
return AllowedKeys{
|
|
||||||
RSA2048: true,
|
|
||||||
RSA3072: true,
|
|
||||||
RSA4096: true,
|
|
||||||
ECDSAP256: true,
|
|
||||||
ECDSAP384: true,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// ErrBadKey represents an error with a key. It is distinct from the various
|
|
||||||
// ways in which an ACME request can have an erroneous key (BadPublicKeyError,
|
|
||||||
// BadCSRError) because this library is used to check both JWS signing keys and
|
|
||||||
// keys in CSRs.
|
|
||||||
var ErrBadKey = errors.New("")
|
|
||||||
|
|
||||||
func badKey(msg string, args ...interface{}) error {
|
|
||||||
return fmt.Errorf("%w%s", ErrBadKey, fmt.Errorf(msg, args...))
|
|
||||||
}
|
|
||||||
|
|
||||||
// BlockedKeyCheckFunc is used to pass in the sa.BlockedKey functionality to KeyPolicy,
|
|
||||||
// rather than storing a full sa.SQLStorageAuthority. This allows external
|
|
||||||
// users who don’t want to import all of boulder/sa, and makes testing
|
|
||||||
// significantly simpler.
|
|
||||||
// On success, the function returns a boolean which is true if the key is blocked.
|
|
||||||
type BlockedKeyCheckFunc func(ctx context.Context, keyHash []byte) (bool, error)
|
|
||||||
|
|
||||||
// KeyPolicy determines which types of key may be used with various boulder
|
|
||||||
// operations.
|
|
||||||
type KeyPolicy struct {
|
|
||||||
allowedKeys AllowedKeys
|
|
||||||
weakRSAList *WeakRSAKeys
|
|
||||||
blockedList *blockedKeys
|
|
||||||
fermatRounds int
|
|
||||||
blockedCheck BlockedKeyCheckFunc
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewPolicy returns a key policy based on the given configuration, with sane
|
|
||||||
// defaults. If the config's AllowedKeys is nil, the LetsEncryptCPS AllowedKeys
|
|
||||||
// is used. If the config's WeakKeyFile or BlockedKeyFile paths are empty, those
|
|
||||||
// checks are disabled. If the config's FermatRounds is 0, Fermat Factorization
|
|
||||||
// is disabled.
|
|
||||||
func NewPolicy(config *Config, bkc BlockedKeyCheckFunc) (KeyPolicy, error) {
|
|
||||||
if config == nil {
|
|
||||||
config = &Config{}
|
|
||||||
}
|
|
||||||
kp := KeyPolicy{
|
|
||||||
blockedCheck: bkc,
|
|
||||||
}
|
|
||||||
if config.AllowedKeys == nil {
|
|
||||||
kp.allowedKeys = LetsEncryptCPS()
|
|
||||||
} else {
|
|
||||||
kp.allowedKeys = *config.AllowedKeys
|
|
||||||
}
|
|
||||||
if config.WeakKeyFile != "" {
|
|
||||||
keyList, err := LoadWeakRSASuffixes(config.WeakKeyFile)
|
|
||||||
if err != nil {
|
|
||||||
return KeyPolicy{}, err
|
|
||||||
}
|
|
||||||
kp.weakRSAList = keyList
|
|
||||||
}
|
|
||||||
if config.BlockedKeyFile != "" {
|
|
||||||
blocked, err := loadBlockedKeysList(config.BlockedKeyFile)
|
|
||||||
if err != nil {
|
|
||||||
return KeyPolicy{}, err
|
|
||||||
}
|
|
||||||
kp.blockedList = blocked
|
|
||||||
}
|
|
||||||
if config.FermatRounds < 0 {
|
|
||||||
return KeyPolicy{}, fmt.Errorf("Fermat factorization rounds cannot be negative: %d", config.FermatRounds)
|
|
||||||
}
|
|
||||||
kp.fermatRounds = config.FermatRounds
|
|
||||||
return kp, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// GoodKey returns true if the key is acceptable for both TLS use and account
|
|
||||||
// key use (our requirements are the same for either one), according to basic
|
|
||||||
// strength and algorithm checking. GoodKey only supports pointers: *rsa.PublicKey
|
|
||||||
// and *ecdsa.PublicKey. It will reject non-pointer types.
|
|
||||||
// TODO: Support JSONWebKeys once go-jose migration is done.
|
|
||||||
func (policy *KeyPolicy) GoodKey(ctx context.Context, key crypto.PublicKey) error {
|
|
||||||
// Early rejection of unacceptable key types to guard subsequent checks.
|
|
||||||
switch t := key.(type) {
|
|
||||||
case *rsa.PublicKey, *ecdsa.PublicKey:
|
|
||||||
break
|
|
||||||
default:
|
|
||||||
return badKey("unsupported key type %T", t)
|
|
||||||
}
|
|
||||||
// If there is a blocked list configured then check if the public key is one
|
|
||||||
// that has been administratively blocked.
|
|
||||||
if policy.blockedList != nil {
|
|
||||||
if blocked, err := policy.blockedList.blocked(key); err != nil {
|
|
||||||
return fmt.Errorf("error checking blocklist for key: %v", key)
|
|
||||||
} else if blocked {
|
|
||||||
return badKey("public key is forbidden")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if policy.blockedCheck != nil {
|
|
||||||
digest, err := core.KeyDigest(key)
|
|
||||||
if err != nil {
|
|
||||||
return badKey("%w", err)
|
|
||||||
}
|
|
||||||
exists, err := policy.blockedCheck(ctx, digest[:])
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
} else if exists {
|
|
||||||
return badKey("public key is forbidden")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
switch t := key.(type) {
|
|
||||||
case *rsa.PublicKey:
|
|
||||||
return policy.goodKeyRSA(t)
|
|
||||||
case *ecdsa.PublicKey:
|
|
||||||
return policy.goodKeyECDSA(t)
|
|
||||||
default:
|
|
||||||
return badKey("unsupported key type %T", key)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// GoodKeyECDSA determines if an ECDSA pubkey meets our requirements
|
|
||||||
func (policy *KeyPolicy) goodKeyECDSA(key *ecdsa.PublicKey) (err error) {
|
|
||||||
// Check the curve.
|
|
||||||
//
|
|
||||||
// The validity of the curve is an assumption for all following tests.
|
|
||||||
err = policy.goodCurve(key.Curve)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
// Key validation routine adapted from NIST SP800-56A § 5.6.2.3.2.
|
|
||||||
// <http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar2.pdf>
|
|
||||||
//
|
|
||||||
// Assuming a prime field since a) we are only allowing such curves and b)
|
|
||||||
// crypto/elliptic only supports prime curves. Where this assumption
|
|
||||||
// simplifies the code below, it is explicitly stated and explained. If ever
|
|
||||||
// adapting this code to support non-prime curves, refer to NIST SP800-56A §
|
|
||||||
// 5.6.2.3.2 and adapt this code appropriately.
|
|
||||||
params := key.Params()
|
|
||||||
|
|
||||||
// SP800-56A § 5.6.2.3.2 Step 1.
|
|
||||||
// Partial check of the public key for an invalid range in the EC group:
|
|
||||||
// Verify that key is not the point at infinity O.
|
|
||||||
// This code assumes that the point at infinity is (0,0), which is the
|
|
||||||
// case for all supported curves.
|
|
||||||
if isPointAtInfinityNISTP(key.X, key.Y) {
|
|
||||||
return badKey("key x, y must not be the point at infinity")
|
|
||||||
}
|
|
||||||
|
|
||||||
// SP800-56A § 5.6.2.3.2 Step 2.
|
|
||||||
// "Verify that x_Q and y_Q are integers in the interval [0,p-1] in the
|
|
||||||
// case that q is an odd prime p, or that x_Q and y_Q are bit strings
|
|
||||||
// of length m bits in the case that q = 2**m."
|
|
||||||
//
|
|
||||||
// Prove prime field: ASSUMED.
|
|
||||||
// Prove q != 2: ASSUMED. (Curve parameter. No supported curve has q == 2.)
|
|
||||||
// Prime field && q != 2 => q is an odd prime p
|
|
||||||
// Therefore "verify that x, y are in [0, p-1]" satisfies step 2.
|
|
||||||
//
|
|
||||||
// Therefore verify that both x and y of the public key point have the unique
|
|
||||||
// correct representation of an element in the underlying field by verifying
|
|
||||||
// that x and y are integers in [0, p-1].
|
|
||||||
if key.X.Sign() < 0 || key.Y.Sign() < 0 {
|
|
||||||
return badKey("key x, y must not be negative")
|
|
||||||
}
|
|
||||||
|
|
||||||
if key.X.Cmp(params.P) >= 0 || key.Y.Cmp(params.P) >= 0 {
|
|
||||||
return badKey("key x, y must not exceed P-1")
|
|
||||||
}
|
|
||||||
|
|
||||||
// SP800-56A § 5.6.2.3.2 Step 3.
|
|
||||||
// "If q is an odd prime p, verify that (y_Q)**2 === (x_Q)***3 + a*x_Q + b (mod p).
|
|
||||||
// If q = 2**m, verify that (y_Q)**2 + (x_Q)*(y_Q) == (x_Q)**3 + a*(x_Q)*2 + b in
|
|
||||||
// the finite field of size 2**m.
|
|
||||||
// (Ensures that the public key is on the correct elliptic curve.)"
|
|
||||||
//
|
|
||||||
// q is an odd prime p: proven/assumed above.
|
|
||||||
// a = -3 for all supported curves.
|
|
||||||
//
|
|
||||||
// Therefore step 3 is satisfied simply by showing that
|
|
||||||
// y**2 === x**3 - 3*x + B (mod P).
|
|
||||||
//
|
|
||||||
// This proves that the public key is on the correct elliptic curve.
|
|
||||||
// But in practice, this test is provided by crypto/elliptic, so use that.
|
|
||||||
if !key.Curve.IsOnCurve(key.X, key.Y) {
|
|
||||||
return badKey("key point is not on the curve")
|
|
||||||
}
|
|
||||||
|
|
||||||
// SP800-56A § 5.6.2.3.2 Step 4.
|
|
||||||
// "Verify that n*Q == Ø.
|
|
||||||
// (Ensures that the public key has the correct order. Along with check 1,
|
|
||||||
// ensures that the public key is in the correct range in the correct EC
|
|
||||||
// subgroup, that is, it is in the correct EC subgroup and is not the
|
|
||||||
// identity element.)"
|
|
||||||
//
|
|
||||||
// Ensure that public key has the correct order:
|
|
||||||
// verify that n*Q = Ø.
|
|
||||||
//
|
|
||||||
// n*Q = Ø iff n*Q is the point at infinity (see step 1).
|
|
||||||
ox, oy := key.Curve.ScalarMult(key.X, key.Y, params.N.Bytes())
|
|
||||||
if !isPointAtInfinityNISTP(ox, oy) {
|
|
||||||
return badKey("public key does not have correct order")
|
|
||||||
}
|
|
||||||
|
|
||||||
// End of SP800-56A § 5.6.2.3.2 Public Key Validation Routine.
|
|
||||||
// Key is valid.
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// Returns true iff the point (x,y) on NIST P-256, NIST P-384 or NIST P-521 is
|
|
||||||
// the point at infinity. These curves all have the same point at infinity
|
|
||||||
// (0,0). This function must ONLY be used on points on curves verified to have
|
|
||||||
// (0,0) as their point at infinity.
|
|
||||||
func isPointAtInfinityNISTP(x, y *big.Int) bool {
|
|
||||||
return x.Sign() == 0 && y.Sign() == 0
|
|
||||||
}
|
|
||||||
|
|
||||||
// GoodCurve determines if an elliptic curve meets our requirements.
|
|
||||||
func (policy *KeyPolicy) goodCurve(c elliptic.Curve) (err error) {
|
|
||||||
// Simply use a whitelist for now.
|
|
||||||
params := c.Params()
|
|
||||||
switch {
|
|
||||||
case policy.allowedKeys.ECDSAP256 && params == elliptic.P256().Params():
|
|
||||||
return nil
|
|
||||||
case policy.allowedKeys.ECDSAP384 && params == elliptic.P384().Params():
|
|
||||||
return nil
|
|
||||||
case policy.allowedKeys.ECDSAP521 && params == elliptic.P521().Params():
|
|
||||||
return nil
|
|
||||||
default:
|
|
||||||
return badKey("ECDSA curve %v not allowed", params.Name)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// GoodKeyRSA determines if a RSA pubkey meets our requirements
|
|
||||||
func (policy *KeyPolicy) goodKeyRSA(key *rsa.PublicKey) error {
|
|
||||||
modulus := key.N
|
|
||||||
|
|
||||||
err := policy.goodRSABitLen(key)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
if policy.weakRSAList != nil && policy.weakRSAList.Known(key) {
|
|
||||||
return badKey("key is on a known weak RSA key list")
|
|
||||||
}
|
|
||||||
|
|
||||||
// Rather than support arbitrary exponents, which significantly increases
|
|
||||||
// the size of the key space we allow, we restrict E to the defacto standard
|
|
||||||
// RSA exponent 65537. There is no specific standards document that specifies
|
|
||||||
// 65537 as the 'best' exponent, but ITU X.509 Annex C suggests there are
|
|
||||||
// notable merits for using it if using a fixed exponent.
|
|
||||||
//
|
|
||||||
// The CABF Baseline Requirements state:
|
|
||||||
// The CA SHALL confirm that the value of the public exponent is an
|
|
||||||
// odd number equal to 3 or more. Additionally, the public exponent
|
|
||||||
// SHOULD be in the range between 2^16 + 1 and 2^256-1.
|
|
||||||
//
|
|
||||||
// By only allowing one exponent, which fits these constraints, we satisfy
|
|
||||||
// these requirements.
|
|
||||||
if key.E != 65537 {
|
|
||||||
return badKey("key exponent must be 65537")
|
|
||||||
}
|
|
||||||
|
|
||||||
// The modulus SHOULD also have the following characteristics: an odd
|
|
||||||
// number, not the power of a prime, and have no factors smaller than 752.
|
|
||||||
// TODO: We don't yet check for "power of a prime."
|
|
||||||
if checkSmallPrimes(modulus) {
|
|
||||||
return badKey("key divisible by small prime")
|
|
||||||
}
|
|
||||||
// Check for weak keys generated by Infineon hardware
|
|
||||||
// (see https://crocs.fi.muni.cz/public/papers/rsa_ccs17)
|
|
||||||
if rocacheck.IsWeak(key) {
|
|
||||||
return badKey("key generated by vulnerable Infineon-based hardware")
|
|
||||||
}
|
|
||||||
// Check if the key can be easily factored via Fermat's factorization method.
|
|
||||||
if policy.fermatRounds > 0 {
|
|
||||||
err := checkPrimeFactorsTooClose(modulus, policy.fermatRounds)
|
|
||||||
if err != nil {
|
|
||||||
return badKey("key generated with factors too close together: %w", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (policy *KeyPolicy) goodRSABitLen(key *rsa.PublicKey) error {
|
|
||||||
// See comment on AllowedKeys above.
|
|
||||||
modulusBitLen := key.N.BitLen()
|
|
||||||
switch {
|
|
||||||
case modulusBitLen == 2048 && policy.allowedKeys.RSA2048:
|
|
||||||
return nil
|
|
||||||
case modulusBitLen == 3072 && policy.allowedKeys.RSA3072:
|
|
||||||
return nil
|
|
||||||
case modulusBitLen == 4096 && policy.allowedKeys.RSA4096:
|
|
||||||
return nil
|
|
||||||
default:
|
|
||||||
return badKey("key size not supported: %d", modulusBitLen)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Returns true iff integer i is divisible by any of the primes in smallPrimes.
|
|
||||||
//
|
|
||||||
// Short circuits; execution time is dependent on i. Do not use this on secret
|
|
||||||
// values.
|
|
||||||
//
|
|
||||||
// Rather than checking each prime individually (invoking Mod on each),
|
|
||||||
// multiply the primes together and let GCD do our work for us: if the
|
|
||||||
// GCD between <key> and <product of primes> is not one, we know we have
|
|
||||||
// a bad key. This is substantially faster than checking each prime
|
|
||||||
// individually.
|
|
||||||
func checkSmallPrimes(i *big.Int) bool {
|
|
||||||
smallPrimesSingleton.Do(func() {
|
|
||||||
smallPrimesProduct = big.NewInt(1)
|
|
||||||
for _, prime := range smallPrimeInts {
|
|
||||||
smallPrimesProduct.Mul(smallPrimesProduct, big.NewInt(prime))
|
|
||||||
}
|
|
||||||
})
|
|
||||||
|
|
||||||
// When the GCD is 1, i and smallPrimesProduct are coprime, meaning they
|
|
||||||
// share no common factors. When the GCD is not one, it is the product of
|
|
||||||
// all common factors, meaning we've identified at least one small prime
|
|
||||||
// which invalidates i as a valid key.
|
|
||||||
|
|
||||||
var result big.Int
|
|
||||||
result.GCD(nil, nil, i, smallPrimesProduct)
|
|
||||||
return result.Cmp(big.NewInt(1)) != 0
|
|
||||||
}
|
|
||||||
|
|
||||||
// Returns an error if the modulus n is able to be factored into primes p and q
|
|
||||||
// via Fermat's factorization method. This method relies on the two primes being
|
|
||||||
// very close together, which means that they were almost certainly not picked
|
|
||||||
// independently from a uniform random distribution. Basically, if we can factor
|
|
||||||
// the key this easily, so can anyone else.
|
|
||||||
func checkPrimeFactorsTooClose(n *big.Int, rounds int) error {
|
|
||||||
// Pre-allocate some big numbers that we'll use a lot down below.
|
|
||||||
one := big.NewInt(1)
|
|
||||||
bb := new(big.Int)
|
|
||||||
|
|
||||||
// Any odd integer is equal to a difference of squares of integers:
|
|
||||||
// n = a^2 - b^2 = (a + b)(a - b)
|
|
||||||
// Any RSA public key modulus is equal to a product of two primes:
|
|
||||||
// n = pq
|
|
||||||
// Here we try to find values for a and b, since doing so also gives us the
|
|
||||||
// prime factors p = (a + b) and q = (a - b).
|
|
||||||
|
|
||||||
// We start with a close to the square root of the modulus n, to start with
|
|
||||||
// two candidate prime factors that are as close together as possible and
|
|
||||||
// work our way out from there. Specifically, we set a = ceil(sqrt(n)), the
|
|
||||||
// first integer greater than the square root of n. Unfortunately, big.Int's
|
|
||||||
// built-in square root function takes the floor, so we have to add one to get
|
|
||||||
// the ceil.
|
|
||||||
a := new(big.Int)
|
|
||||||
a.Sqrt(n).Add(a, one)
|
|
||||||
|
|
||||||
// We calculate b2 to see if it is a perfect square (i.e. b^2), and therefore
|
|
||||||
// b is an integer. Specifically, b2 = a^2 - n.
|
|
||||||
b2 := new(big.Int)
|
|
||||||
b2.Mul(a, a).Sub(b2, n)
|
|
||||||
|
|
||||||
for range rounds {
|
|
||||||
// To see if b2 is a perfect square, we take its square root, square that,
|
|
||||||
// and check to see if we got the same result back.
|
|
||||||
bb.Sqrt(b2).Mul(bb, bb)
|
|
||||||
if b2.Cmp(bb) == 0 {
|
|
||||||
// b2 is a perfect square, so we've found integer values of a and b,
|
|
||||||
// and can easily compute p and q as their sum and difference.
|
|
||||||
bb.Sqrt(bb)
|
|
||||||
p := new(big.Int).Add(a, bb)
|
|
||||||
q := new(big.Int).Sub(a, bb)
|
|
||||||
return fmt.Errorf("public modulus n = pq factored into p: %s; q: %s", p, q)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Set up the next iteration by incrementing a by one and recalculating b2.
|
|
||||||
a.Add(a, one)
|
|
||||||
b2.Mul(a, a).Sub(b2, n)
|
|
||||||
}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
66
vendor/github.com/letsencrypt/boulder/goodkey/weak.go
generated
vendored
66
vendor/github.com/letsencrypt/boulder/goodkey/weak.go
generated
vendored
|
|
@ -1,66 +0,0 @@
|
||||||
package goodkey
|
|
||||||
|
|
||||||
// This file defines a basic method for testing if a given RSA public key is on one of
|
|
||||||
// the Debian weak key lists and is therefore considered compromised. Instead of
|
|
||||||
// directly loading the hash suffixes from the individual lists we flatten them all
|
|
||||||
// into a single JSON list using cmd/weak-key-flatten for ease of use.
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/rsa"
|
|
||||||
"crypto/sha1"
|
|
||||||
"encoding/hex"
|
|
||||||
"encoding/json"
|
|
||||||
"fmt"
|
|
||||||
"os"
|
|
||||||
)
|
|
||||||
|
|
||||||
type truncatedHash [10]byte
|
|
||||||
|
|
||||||
type WeakRSAKeys struct {
|
|
||||||
suffixes map[truncatedHash]struct{}
|
|
||||||
}
|
|
||||||
|
|
||||||
func LoadWeakRSASuffixes(path string) (*WeakRSAKeys, error) {
|
|
||||||
f, err := os.ReadFile(path)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
var suffixList []string
|
|
||||||
err = json.Unmarshal(f, &suffixList)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
wk := &WeakRSAKeys{suffixes: make(map[truncatedHash]struct{})}
|
|
||||||
for _, suffix := range suffixList {
|
|
||||||
err := wk.addSuffix(suffix)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return wk, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (wk *WeakRSAKeys) addSuffix(str string) error {
|
|
||||||
var suffix truncatedHash
|
|
||||||
decoded, err := hex.DecodeString(str)
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
if len(decoded) != 10 {
|
|
||||||
return fmt.Errorf("unexpected suffix length of %d", len(decoded))
|
|
||||||
}
|
|
||||||
copy(suffix[:], decoded)
|
|
||||||
wk.suffixes[suffix] = struct{}{}
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (wk *WeakRSAKeys) Known(key *rsa.PublicKey) bool {
|
|
||||||
// Hash input is in the format "Modulus={upper-case hex of modulus}\n"
|
|
||||||
hash := sha1.Sum([]byte(fmt.Sprintf("Modulus=%X\n", key.N.Bytes())))
|
|
||||||
var suffix truncatedHash
|
|
||||||
copy(suffix[:], hash[10:])
|
|
||||||
_, present := wk.suffixes[suffix]
|
|
||||||
return present
|
|
||||||
}
|
|
||||||
32
vendor/github.com/letsencrypt/boulder/identifier/identifier.go
generated
vendored
32
vendor/github.com/letsencrypt/boulder/identifier/identifier.go
generated
vendored
|
|
@ -1,32 +0,0 @@
|
||||||
// The identifier package defines types for RFC 8555 ACME identifiers.
|
|
||||||
package identifier
|
|
||||||
|
|
||||||
// IdentifierType is a named string type for registered ACME identifier types.
|
|
||||||
// See https://tools.ietf.org/html/rfc8555#section-9.7.7
|
|
||||||
type IdentifierType string
|
|
||||||
|
|
||||||
const (
|
|
||||||
// DNS is specified in RFC 8555 for DNS type identifiers.
|
|
||||||
DNS = IdentifierType("dns")
|
|
||||||
)
|
|
||||||
|
|
||||||
// ACMEIdentifier is a struct encoding an identifier that can be validated. The
|
|
||||||
// protocol allows for different types of identifier to be supported (DNS
|
|
||||||
// names, IP addresses, etc.), but currently we only support RFC 8555 DNS type
|
|
||||||
// identifiers for domain names.
|
|
||||||
type ACMEIdentifier struct {
|
|
||||||
// Type is the registered IdentifierType of the identifier.
|
|
||||||
Type IdentifierType `json:"type"`
|
|
||||||
// Value is the value of the identifier. For a DNS type identifier it is
|
|
||||||
// a domain name.
|
|
||||||
Value string `json:"value"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// DNSIdentifier is a convenience function for creating an ACMEIdentifier with
|
|
||||||
// Type DNS for a given domain name.
|
|
||||||
func DNSIdentifier(domain string) ACMEIdentifier {
|
|
||||||
return ACMEIdentifier{
|
|
||||||
Type: DNS,
|
|
||||||
Value: domain,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
343
vendor/github.com/letsencrypt/boulder/probs/probs.go
generated
vendored
343
vendor/github.com/letsencrypt/boulder/probs/probs.go
generated
vendored
|
|
@ -1,343 +0,0 @@
|
||||||
package probs
|
|
||||||
|
|
||||||
import (
|
|
||||||
"fmt"
|
|
||||||
"net/http"
|
|
||||||
|
|
||||||
"github.com/letsencrypt/boulder/identifier"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
// Error types that can be used in ACME payloads. These are sorted in the
|
|
||||||
// same order as they are defined in RFC8555 Section 6.7. We do not implement
|
|
||||||
// the `compound`, `externalAccountRequired`, or `userActionRequired` errors,
|
|
||||||
// because we have no path that would return them.
|
|
||||||
AccountDoesNotExistProblem = ProblemType("accountDoesNotExist")
|
|
||||||
AlreadyRevokedProblem = ProblemType("alreadyRevoked")
|
|
||||||
BadCSRProblem = ProblemType("badCSR")
|
|
||||||
BadNonceProblem = ProblemType("badNonce")
|
|
||||||
BadPublicKeyProblem = ProblemType("badPublicKey")
|
|
||||||
BadRevocationReasonProblem = ProblemType("badRevocationReason")
|
|
||||||
BadSignatureAlgorithmProblem = ProblemType("badSignatureAlgorithm")
|
|
||||||
CAAProblem = ProblemType("caa")
|
|
||||||
// ConflictProblem is a problem type that is not defined in RFC8555.
|
|
||||||
ConflictProblem = ProblemType("conflict")
|
|
||||||
ConnectionProblem = ProblemType("connection")
|
|
||||||
DNSProblem = ProblemType("dns")
|
|
||||||
InvalidContactProblem = ProblemType("invalidContact")
|
|
||||||
MalformedProblem = ProblemType("malformed")
|
|
||||||
OrderNotReadyProblem = ProblemType("orderNotReady")
|
|
||||||
RateLimitedProblem = ProblemType("rateLimited")
|
|
||||||
RejectedIdentifierProblem = ProblemType("rejectedIdentifier")
|
|
||||||
ServerInternalProblem = ProblemType("serverInternal")
|
|
||||||
TLSProblem = ProblemType("tls")
|
|
||||||
UnauthorizedProblem = ProblemType("unauthorized")
|
|
||||||
UnsupportedContactProblem = ProblemType("unsupportedContact")
|
|
||||||
UnsupportedIdentifierProblem = ProblemType("unsupportedIdentifier")
|
|
||||||
|
|
||||||
ErrorNS = "urn:ietf:params:acme:error:"
|
|
||||||
)
|
|
||||||
|
|
||||||
// ProblemType defines the error types in the ACME protocol
|
|
||||||
type ProblemType string
|
|
||||||
|
|
||||||
// ProblemDetails objects represent problem documents
|
|
||||||
// https://tools.ietf.org/html/draft-ietf-appsawg-http-problem-00
|
|
||||||
type ProblemDetails struct {
|
|
||||||
Type ProblemType `json:"type,omitempty"`
|
|
||||||
Detail string `json:"detail,omitempty"`
|
|
||||||
// HTTPStatus is the HTTP status code the ProblemDetails should probably be sent
|
|
||||||
// as.
|
|
||||||
HTTPStatus int `json:"status,omitempty"`
|
|
||||||
// SubProblems are optional additional per-identifier problems. See
|
|
||||||
// RFC 8555 Section 6.7.1: https://tools.ietf.org/html/rfc8555#section-6.7.1
|
|
||||||
SubProblems []SubProblemDetails `json:"subproblems,omitempty"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// SubProblemDetails represents sub-problems specific to an identifier that are
|
|
||||||
// related to a top-level ProblemDetails.
|
|
||||||
// See RFC 8555 Section 6.7.1: https://tools.ietf.org/html/rfc8555#section-6.7.1
|
|
||||||
type SubProblemDetails struct {
|
|
||||||
ProblemDetails
|
|
||||||
Identifier identifier.ACMEIdentifier `json:"identifier"`
|
|
||||||
}
|
|
||||||
|
|
||||||
func (pd *ProblemDetails) Error() string {
|
|
||||||
return fmt.Sprintf("%s :: %s", pd.Type, pd.Detail)
|
|
||||||
}
|
|
||||||
|
|
||||||
// WithSubProblems returns a new ProblemsDetails instance created by adding the
|
|
||||||
// provided subProbs to the existing ProblemsDetail.
|
|
||||||
func (pd *ProblemDetails) WithSubProblems(subProbs []SubProblemDetails) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: pd.Type,
|
|
||||||
Detail: pd.Detail,
|
|
||||||
HTTPStatus: pd.HTTPStatus,
|
|
||||||
SubProblems: append(pd.SubProblems, subProbs...),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Helper functions which construct the basic RFC8555 Problem Documents, with
|
|
||||||
// the Type already set and the Details supplied by the caller.
|
|
||||||
|
|
||||||
// AccountDoesNotExist returns a ProblemDetails representing an
|
|
||||||
// AccountDoesNotExistProblem error
|
|
||||||
func AccountDoesNotExist(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: AccountDoesNotExistProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// AlreadyRevoked returns a ProblemDetails with a AlreadyRevokedProblem and a 400 Bad
|
|
||||||
// Request status code.
|
|
||||||
func AlreadyRevoked(detail string, a ...any) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: AlreadyRevokedProblem,
|
|
||||||
Detail: fmt.Sprintf(detail, a...),
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// BadCSR returns a ProblemDetails representing a BadCSRProblem.
|
|
||||||
func BadCSR(detail string, a ...any) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: BadCSRProblem,
|
|
||||||
Detail: fmt.Sprintf(detail, a...),
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// BadNonce returns a ProblemDetails with a BadNonceProblem and a 400 Bad
|
|
||||||
// Request status code.
|
|
||||||
func BadNonce(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: BadNonceProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// BadPublicKey returns a ProblemDetails with a BadPublicKeyProblem and a 400 Bad
|
|
||||||
// Request status code.
|
|
||||||
func BadPublicKey(detail string, a ...any) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: BadPublicKeyProblem,
|
|
||||||
Detail: fmt.Sprintf(detail, a...),
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// BadRevocationReason returns a ProblemDetails representing
|
|
||||||
// a BadRevocationReasonProblem
|
|
||||||
func BadRevocationReason(detail string, a ...any) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: BadRevocationReasonProblem,
|
|
||||||
Detail: fmt.Sprintf(detail, a...),
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// BadSignatureAlgorithm returns a ProblemDetails with a BadSignatureAlgorithmProblem
|
|
||||||
// and a 400 Bad Request status code.
|
|
||||||
func BadSignatureAlgorithm(detail string, a ...any) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: BadSignatureAlgorithmProblem,
|
|
||||||
Detail: fmt.Sprintf(detail, a...),
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// CAA returns a ProblemDetails representing a CAAProblem
|
|
||||||
func CAA(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: CAAProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusForbidden,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Connection returns a ProblemDetails representing a ConnectionProblem
|
|
||||||
// error
|
|
||||||
func Connection(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: ConnectionProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// DNS returns a ProblemDetails representing a DNSProblem
|
|
||||||
func DNS(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: DNSProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// InvalidContact returns a ProblemDetails representing an InvalidContactProblem.
|
|
||||||
func InvalidContact(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: InvalidContactProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Malformed returns a ProblemDetails with a MalformedProblem and a 400 Bad
|
|
||||||
// Request status code.
|
|
||||||
func Malformed(detail string, a ...any) *ProblemDetails {
|
|
||||||
if len(a) > 0 {
|
|
||||||
detail = fmt.Sprintf(detail, a...)
|
|
||||||
}
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: MalformedProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// OrderNotReady returns a ProblemDetails representing a OrderNotReadyProblem
|
|
||||||
func OrderNotReady(detail string, a ...any) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: OrderNotReadyProblem,
|
|
||||||
Detail: fmt.Sprintf(detail, a...),
|
|
||||||
HTTPStatus: http.StatusForbidden,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// RateLimited returns a ProblemDetails representing a RateLimitedProblem error
|
|
||||||
func RateLimited(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: RateLimitedProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusTooManyRequests,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// RejectedIdentifier returns a ProblemDetails with a RejectedIdentifierProblem and a 400 Bad
|
|
||||||
// Request status code.
|
|
||||||
func RejectedIdentifier(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: RejectedIdentifierProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// ServerInternal returns a ProblemDetails with a ServerInternalProblem and a
|
|
||||||
// 500 Internal Server Failure status code.
|
|
||||||
func ServerInternal(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: ServerInternalProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusInternalServerError,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TLS returns a ProblemDetails representing a TLSProblem error
|
|
||||||
func TLS(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: TLSProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Unauthorized returns a ProblemDetails with an UnauthorizedProblem and a 403
|
|
||||||
// Forbidden status code.
|
|
||||||
func Unauthorized(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: UnauthorizedProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusForbidden,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// UnsupportedContact returns a ProblemDetails representing an
|
|
||||||
// UnsupportedContactProblem
|
|
||||||
func UnsupportedContact(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: UnsupportedContactProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// UnsupportedIdentifier returns a ProblemDetails representing an
|
|
||||||
// UnsupportedIdentifierProblem
|
|
||||||
func UnsupportedIdentifier(detail string, a ...any) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: UnsupportedIdentifierProblem,
|
|
||||||
Detail: fmt.Sprintf(detail, a...),
|
|
||||||
HTTPStatus: http.StatusBadRequest,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Additional helper functions that return variations on MalformedProblem with
|
|
||||||
// different HTTP status codes set.
|
|
||||||
|
|
||||||
// Canceled returns a ProblemDetails with a MalformedProblem and a 408 Request
|
|
||||||
// Timeout status code.
|
|
||||||
func Canceled(detail string, a ...any) *ProblemDetails {
|
|
||||||
if len(a) > 0 {
|
|
||||||
detail = fmt.Sprintf(detail, a...)
|
|
||||||
}
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: MalformedProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusRequestTimeout,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Conflict returns a ProblemDetails with a ConflictProblem and a 409 Conflict
|
|
||||||
// status code.
|
|
||||||
func Conflict(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: ConflictProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusConflict,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// ContentLengthRequired returns a ProblemDetails representing a missing
|
|
||||||
// Content-Length header error
|
|
||||||
func ContentLengthRequired() *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: MalformedProblem,
|
|
||||||
Detail: "missing Content-Length header",
|
|
||||||
HTTPStatus: http.StatusLengthRequired,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// InvalidContentType returns a ProblemDetails suitable for a missing
|
|
||||||
// ContentType header, or an incorrect ContentType header
|
|
||||||
func InvalidContentType(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: MalformedProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusUnsupportedMediaType,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// MethodNotAllowed returns a ProblemDetails representing a disallowed HTTP
|
|
||||||
// method error.
|
|
||||||
func MethodNotAllowed() *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: MalformedProblem,
|
|
||||||
Detail: "Method not allowed",
|
|
||||||
HTTPStatus: http.StatusMethodNotAllowed,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// NotFound returns a ProblemDetails with a MalformedProblem and a 404 Not Found
|
|
||||||
// status code.
|
|
||||||
func NotFound(detail string) *ProblemDetails {
|
|
||||||
return &ProblemDetails{
|
|
||||||
Type: MalformedProblem,
|
|
||||||
Detail: detail,
|
|
||||||
HTTPStatus: http.StatusNotFound,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
72
vendor/github.com/letsencrypt/boulder/revocation/reasons.go
generated
vendored
72
vendor/github.com/letsencrypt/boulder/revocation/reasons.go
generated
vendored
|
|
@ -1,72 +0,0 @@
|
||||||
package revocation
|
|
||||||
|
|
||||||
import (
|
|
||||||
"fmt"
|
|
||||||
"sort"
|
|
||||||
"strings"
|
|
||||||
|
|
||||||
"golang.org/x/crypto/ocsp"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Reason is used to specify a certificate revocation reason
|
|
||||||
type Reason int
|
|
||||||
|
|
||||||
// ReasonToString provides a map from reason code to string
|
|
||||||
var ReasonToString = map[Reason]string{
|
|
||||||
ocsp.Unspecified: "unspecified",
|
|
||||||
ocsp.KeyCompromise: "keyCompromise",
|
|
||||||
ocsp.CACompromise: "cACompromise",
|
|
||||||
ocsp.AffiliationChanged: "affiliationChanged",
|
|
||||||
ocsp.Superseded: "superseded",
|
|
||||||
ocsp.CessationOfOperation: "cessationOfOperation",
|
|
||||||
ocsp.CertificateHold: "certificateHold",
|
|
||||||
// 7 is unused
|
|
||||||
ocsp.RemoveFromCRL: "removeFromCRL",
|
|
||||||
ocsp.PrivilegeWithdrawn: "privilegeWithdrawn",
|
|
||||||
ocsp.AACompromise: "aAcompromise",
|
|
||||||
}
|
|
||||||
|
|
||||||
// UserAllowedReasons contains the subset of Reasons which users are
|
|
||||||
// allowed to use
|
|
||||||
var UserAllowedReasons = map[Reason]struct{}{
|
|
||||||
ocsp.Unspecified: {},
|
|
||||||
ocsp.KeyCompromise: {},
|
|
||||||
ocsp.Superseded: {},
|
|
||||||
ocsp.CessationOfOperation: {},
|
|
||||||
}
|
|
||||||
|
|
||||||
// AdminAllowedReasons contains the subset of Reasons which admins are allowed
|
|
||||||
// to use. Reasons not found here will soon be forbidden from appearing in CRLs
|
|
||||||
// or OCSP responses by root programs.
|
|
||||||
var AdminAllowedReasons = map[Reason]struct{}{
|
|
||||||
ocsp.Unspecified: {},
|
|
||||||
ocsp.KeyCompromise: {},
|
|
||||||
ocsp.Superseded: {},
|
|
||||||
ocsp.CessationOfOperation: {},
|
|
||||||
ocsp.PrivilegeWithdrawn: {},
|
|
||||||
}
|
|
||||||
|
|
||||||
// UserAllowedReasonsMessage contains a string describing a list of user allowed
|
|
||||||
// revocation reasons. This is useful when a revocation is rejected because it
|
|
||||||
// is not a valid user supplied reason and the allowed values must be
|
|
||||||
// communicated. This variable is populated during package initialization.
|
|
||||||
var UserAllowedReasonsMessage = ""
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
// Build a slice of ints from the allowed reason codes.
|
|
||||||
// We want a slice because iterating `UserAllowedReasons` will change order
|
|
||||||
// and make the message unpredictable and cumbersome for unit testing.
|
|
||||||
// We use []ints instead of []Reason to use `sort.Ints` without fuss.
|
|
||||||
var allowed []int
|
|
||||||
for reason := range UserAllowedReasons {
|
|
||||||
allowed = append(allowed, int(reason))
|
|
||||||
}
|
|
||||||
sort.Ints(allowed)
|
|
||||||
|
|
||||||
var reasonStrings []string
|
|
||||||
for _, reason := range allowed {
|
|
||||||
reasonStrings = append(reasonStrings, fmt.Sprintf("%s (%d)",
|
|
||||||
ReasonToString[Reason(reason)], reason))
|
|
||||||
}
|
|
||||||
UserAllowedReasonsMessage = strings.Join(reasonStrings, ", ")
|
|
||||||
}
|
|
||||||
46
vendor/github.com/letsencrypt/boulder/strictyaml/yaml.go
generated
vendored
46
vendor/github.com/letsencrypt/boulder/strictyaml/yaml.go
generated
vendored
|
|
@ -1,46 +0,0 @@
|
||||||
// Package strictyaml provides a strict YAML unmarshaller based on `go-yaml/yaml`
|
|
||||||
package strictyaml
|
|
||||||
|
|
||||||
import (
|
|
||||||
"bytes"
|
|
||||||
"errors"
|
|
||||||
"fmt"
|
|
||||||
"io"
|
|
||||||
|
|
||||||
"gopkg.in/yaml.v3"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Unmarshal takes a byte array and an interface passed by reference. The
|
|
||||||
// d.Decode will read the next YAML-encoded value from its input and store it in
|
|
||||||
// the value pointed to by yamlObj. Any config keys from the incoming YAML
|
|
||||||
// document which do not correspond to expected keys in the config struct will
|
|
||||||
// result in errors.
|
|
||||||
//
|
|
||||||
// TODO(https://github.com/go-yaml/yaml/issues/639): Replace this function with
|
|
||||||
// yaml.Unmarshal once a more ergonomic way to set unmarshal options is added
|
|
||||||
// upstream.
|
|
||||||
func Unmarshal(b []byte, yamlObj interface{}) error {
|
|
||||||
r := bytes.NewReader(b)
|
|
||||||
|
|
||||||
d := yaml.NewDecoder(r)
|
|
||||||
d.KnownFields(true)
|
|
||||||
|
|
||||||
// d.Decode will mutate yamlObj
|
|
||||||
err := d.Decode(yamlObj)
|
|
||||||
|
|
||||||
if err != nil {
|
|
||||||
// io.EOF is returned when the YAML document is empty.
|
|
||||||
if errors.Is(err, io.EOF) {
|
|
||||||
return fmt.Errorf("unmarshalling YAML, bytes cannot be nil: %w", err)
|
|
||||||
}
|
|
||||||
return fmt.Errorf("unmarshalling YAML: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
// As bytes are read by the decoder, the length of the byte buffer should
|
|
||||||
// decrease. If it doesn't, there's a problem.
|
|
||||||
if r.Len() != 0 {
|
|
||||||
return fmt.Errorf("yaml object of size %d bytes had %d bytes of unexpected unconsumed trailers", r.Size(), r.Len())
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
18
vendor/github.com/sigstore/fulcio/pkg/certificate/extensions.go
generated
vendored
18
vendor/github.com/sigstore/fulcio/pkg/certificate/extensions.go
generated
vendored
|
|
@ -53,6 +53,7 @@ var (
|
||||||
OIDBuildTrigger = asn1.ObjectIdentifier{1, 3, 6, 1, 4, 1, 57264, 1, 20}
|
OIDBuildTrigger = asn1.ObjectIdentifier{1, 3, 6, 1, 4, 1, 57264, 1, 20}
|
||||||
OIDRunInvocationURI = asn1.ObjectIdentifier{1, 3, 6, 1, 4, 1, 57264, 1, 21}
|
OIDRunInvocationURI = asn1.ObjectIdentifier{1, 3, 6, 1, 4, 1, 57264, 1, 21}
|
||||||
OIDSourceRepositoryVisibilityAtSigning = asn1.ObjectIdentifier{1, 3, 6, 1, 4, 1, 57264, 1, 22}
|
OIDSourceRepositoryVisibilityAtSigning = asn1.ObjectIdentifier{1, 3, 6, 1, 4, 1, 57264, 1, 22}
|
||||||
|
OIDDeploymentEnvironment = asn1.ObjectIdentifier{1, 3, 6, 1, 4, 1, 57264, 1, 23}
|
||||||
)
|
)
|
||||||
|
|
||||||
// Extensions contains all custom x509 extensions defined by Fulcio
|
// Extensions contains all custom x509 extensions defined by Fulcio
|
||||||
|
|
@ -132,6 +133,9 @@ type Extensions struct {
|
||||||
|
|
||||||
// Source repository visibility at the time of signing the certificate.
|
// Source repository visibility at the time of signing the certificate.
|
||||||
SourceRepositoryVisibilityAtSigning string `json:"SourceRepositoryVisibilityAtSigning,omitempty" yaml:"source-repository-visibility-at-signing,omitempty"` // 1.3.6.1.4.1.57264.1.22
|
SourceRepositoryVisibilityAtSigning string `json:"SourceRepositoryVisibilityAtSigning,omitempty" yaml:"source-repository-visibility-at-signing,omitempty"` // 1.3.6.1.4.1.57264.1.22
|
||||||
|
|
||||||
|
// Deployment target for a workflow or job
|
||||||
|
DeploymentEnvironment string `json:"DeploymentEnvironment,omitempty" yaml:"deployment-environment,omitempty"` // 1.3.6.1.4.1.57264.1.23
|
||||||
}
|
}
|
||||||
|
|
||||||
func (e Extensions) Render() ([]pkix.Extension, error) {
|
func (e Extensions) Render() ([]pkix.Extension, error) {
|
||||||
|
|
@ -334,6 +338,16 @@ func (e Extensions) Render() ([]pkix.Extension, error) {
|
||||||
Value: val,
|
Value: val,
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
if e.DeploymentEnvironment != "" {
|
||||||
|
val, err := asn1.MarshalWithParams(e.DeploymentEnvironment, "utf8")
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
exts = append(exts, pkix.Extension{
|
||||||
|
Id: OIDDeploymentEnvironment,
|
||||||
|
Value: val,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
return exts, nil
|
return exts, nil
|
||||||
}
|
}
|
||||||
|
|
@ -417,6 +431,10 @@ func ParseExtensions(ext []pkix.Extension) (Extensions, error) {
|
||||||
if err := ParseDERString(e.Value, &out.SourceRepositoryVisibilityAtSigning); err != nil {
|
if err := ParseDERString(e.Value, &out.SourceRepositoryVisibilityAtSigning); err != nil {
|
||||||
return Extensions{}, err
|
return Extensions{}, err
|
||||||
}
|
}
|
||||||
|
case e.Id.Equal(OIDDeploymentEnvironment):
|
||||||
|
if err := ParseDERString(e.Value, &out.DeploymentEnvironment); err != nil {
|
||||||
|
return Extensions{}, err
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
76
vendor/github.com/sigstore/protobuf-specs/gen/pb-go/common/v1/sigstore_common.pb.go
generated
vendored
76
vendor/github.com/sigstore/protobuf-specs/gen/pb-go/common/v1/sigstore_common.pb.go
generated
vendored
|
|
@ -15,7 +15,7 @@
|
||||||
// Code generated by protoc-gen-go. DO NOT EDIT.
|
// Code generated by protoc-gen-go. DO NOT EDIT.
|
||||||
// versions:
|
// versions:
|
||||||
// protoc-gen-go v1.36.5
|
// protoc-gen-go v1.36.5
|
||||||
// protoc v5.29.4
|
// protoc v6.30.2
|
||||||
// source: sigstore_common.proto
|
// source: sigstore_common.proto
|
||||||
|
|
||||||
package v1
|
package v1
|
||||||
|
|
@ -112,7 +112,8 @@ func (HashAlgorithm) EnumDescriptor() ([]byte, []int) {
|
||||||
// opinionated options instead of allowing every possible permutation.
|
// opinionated options instead of allowing every possible permutation.
|
||||||
//
|
//
|
||||||
// Any changes to this enum MUST be reflected in the algorithm registry.
|
// Any changes to this enum MUST be reflected in the algorithm registry.
|
||||||
// See: docs/algorithm-registry.md
|
//
|
||||||
|
// See: <https://github.com/sigstore/architecture-docs/blob/main/algorithm-registry.md>
|
||||||
//
|
//
|
||||||
// To avoid the possibility of contradicting formats such as PKCS1 with
|
// To avoid the possibility of contradicting formats such as PKCS1 with
|
||||||
// ED25519 the valid permutations are listed as a linear set instead of a
|
// ED25519 the valid permutations are listed as a linear set instead of a
|
||||||
|
|
@ -159,8 +160,9 @@ const (
|
||||||
PublicKeyDetails_PKIX_ECDSA_P521_SHA_256 PublicKeyDetails = 20
|
PublicKeyDetails_PKIX_ECDSA_P521_SHA_256 PublicKeyDetails = 20
|
||||||
// LMS and LM-OTS
|
// LMS and LM-OTS
|
||||||
//
|
//
|
||||||
// These keys and signatures may be used by private Sigstore
|
// These algorithms are deprecated and should not be used.
|
||||||
// deployments, but are not currently supported by the public
|
// Keys and signatures MAY be used by private Sigstore
|
||||||
|
// deployments, but will not be supported by the public
|
||||||
// good instance.
|
// good instance.
|
||||||
//
|
//
|
||||||
// USER WARNING: LMS and LM-OTS are both stateful signature schemes.
|
// USER WARNING: LMS and LM-OTS are both stateful signature schemes.
|
||||||
|
|
@ -170,8 +172,26 @@ const (
|
||||||
// MUST NOT be used for more than one signature per LM-OTS key.
|
// MUST NOT be used for more than one signature per LM-OTS key.
|
||||||
// If you cannot maintain these invariants, you MUST NOT use these
|
// If you cannot maintain these invariants, you MUST NOT use these
|
||||||
// schemes.
|
// schemes.
|
||||||
PublicKeyDetails_LMS_SHA256 PublicKeyDetails = 14
|
//
|
||||||
|
// Deprecated: Marked as deprecated in sigstore_common.proto.
|
||||||
|
PublicKeyDetails_LMS_SHA256 PublicKeyDetails = 14
|
||||||
|
// Deprecated: Marked as deprecated in sigstore_common.proto.
|
||||||
PublicKeyDetails_LMOTS_SHA256 PublicKeyDetails = 15
|
PublicKeyDetails_LMOTS_SHA256 PublicKeyDetails = 15
|
||||||
|
// ML-DSA
|
||||||
|
//
|
||||||
|
// These ML_DSA_65 and ML-DSA_87 algorithms are the pure variants that
|
||||||
|
// take data to sign rather than the prehash variants (HashML-DSA), which
|
||||||
|
// take digests. While considered quantum-resistant, their usage
|
||||||
|
// involves tradeoffs in that signatures and keys are much larger, and
|
||||||
|
// this makes deployments more costly.
|
||||||
|
//
|
||||||
|
// USER WARNING: ML_DSA_65 and ML_DSA_87 are experimental algorithms.
|
||||||
|
// In the future they MAY be used by private Sigstore deployments, but
|
||||||
|
// they are not yet fully functional. This warning will be removed when
|
||||||
|
// these algorithms are widely supported by Sigstore clients and servers,
|
||||||
|
// but care should still be taken for production environments.
|
||||||
|
PublicKeyDetails_ML_DSA_65 PublicKeyDetails = 21 // See NIST FIPS 204
|
||||||
|
PublicKeyDetails_ML_DSA_87 PublicKeyDetails = 22
|
||||||
)
|
)
|
||||||
|
|
||||||
// Enum value maps for PublicKeyDetails.
|
// Enum value maps for PublicKeyDetails.
|
||||||
|
|
@ -198,6 +218,8 @@ var (
|
||||||
20: "PKIX_ECDSA_P521_SHA_256",
|
20: "PKIX_ECDSA_P521_SHA_256",
|
||||||
14: "LMS_SHA256",
|
14: "LMS_SHA256",
|
||||||
15: "LMOTS_SHA256",
|
15: "LMOTS_SHA256",
|
||||||
|
21: "ML_DSA_65",
|
||||||
|
22: "ML_DSA_87",
|
||||||
}
|
}
|
||||||
PublicKeyDetails_value = map[string]int32{
|
PublicKeyDetails_value = map[string]int32{
|
||||||
"PUBLIC_KEY_DETAILS_UNSPECIFIED": 0,
|
"PUBLIC_KEY_DETAILS_UNSPECIFIED": 0,
|
||||||
|
|
@ -221,6 +243,8 @@ var (
|
||||||
"PKIX_ECDSA_P521_SHA_256": 20,
|
"PKIX_ECDSA_P521_SHA_256": 20,
|
||||||
"LMS_SHA256": 14,
|
"LMS_SHA256": 14,
|
||||||
"LMOTS_SHA256": 15,
|
"LMOTS_SHA256": 15,
|
||||||
|
"ML_DSA_65": 21,
|
||||||
|
"ML_DSA_87": 22,
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -1134,7 +1158,7 @@ var file_sigstore_common_proto_rawDesc = string([]byte{
|
||||||
0x48, 0x41, 0x32, 0x5f, 0x33, 0x38, 0x34, 0x10, 0x02, 0x12, 0x0c, 0x0a, 0x08, 0x53, 0x48, 0x41,
|
0x48, 0x41, 0x32, 0x5f, 0x33, 0x38, 0x34, 0x10, 0x02, 0x12, 0x0c, 0x0a, 0x08, 0x53, 0x48, 0x41,
|
||||||
0x32, 0x5f, 0x35, 0x31, 0x32, 0x10, 0x03, 0x12, 0x0c, 0x0a, 0x08, 0x53, 0x48, 0x41, 0x33, 0x5f,
|
0x32, 0x5f, 0x35, 0x31, 0x32, 0x10, 0x03, 0x12, 0x0c, 0x0a, 0x08, 0x53, 0x48, 0x41, 0x33, 0x5f,
|
||||||
0x32, 0x35, 0x36, 0x10, 0x04, 0x12, 0x0c, 0x0a, 0x08, 0x53, 0x48, 0x41, 0x33, 0x5f, 0x33, 0x38,
|
0x32, 0x35, 0x36, 0x10, 0x04, 0x12, 0x0c, 0x0a, 0x08, 0x53, 0x48, 0x41, 0x33, 0x5f, 0x33, 0x38,
|
||||||
0x34, 0x10, 0x05, 0x2a, 0xe9, 0x04, 0x0a, 0x10, 0x50, 0x75, 0x62, 0x6c, 0x69, 0x63, 0x4b, 0x65,
|
0x34, 0x10, 0x05, 0x2a, 0x8f, 0x05, 0x0a, 0x10, 0x50, 0x75, 0x62, 0x6c, 0x69, 0x63, 0x4b, 0x65,
|
||||||
0x79, 0x44, 0x65, 0x74, 0x61, 0x69, 0x6c, 0x73, 0x12, 0x22, 0x0a, 0x1e, 0x50, 0x55, 0x42, 0x4c,
|
0x79, 0x44, 0x65, 0x74, 0x61, 0x69, 0x6c, 0x73, 0x12, 0x22, 0x0a, 0x1e, 0x50, 0x55, 0x42, 0x4c,
|
||||||
0x49, 0x43, 0x5f, 0x4b, 0x45, 0x59, 0x5f, 0x44, 0x45, 0x54, 0x41, 0x49, 0x4c, 0x53, 0x5f, 0x55,
|
0x49, 0x43, 0x5f, 0x4b, 0x45, 0x59, 0x5f, 0x44, 0x45, 0x54, 0x41, 0x49, 0x4c, 0x53, 0x5f, 0x55,
|
||||||
0x4e, 0x53, 0x50, 0x45, 0x43, 0x49, 0x46, 0x49, 0x45, 0x44, 0x10, 0x00, 0x12, 0x19, 0x0a, 0x11,
|
0x4e, 0x53, 0x50, 0x45, 0x43, 0x49, 0x46, 0x49, 0x45, 0x44, 0x10, 0x00, 0x12, 0x19, 0x0a, 0x11,
|
||||||
|
|
@ -1170,25 +1194,27 @@ var file_sigstore_common_proto_rawDesc = string([]byte{
|
||||||
0x44, 0x53, 0x41, 0x5f, 0x50, 0x33, 0x38, 0x34, 0x5f, 0x53, 0x48, 0x41, 0x5f, 0x32, 0x35, 0x36,
|
0x44, 0x53, 0x41, 0x5f, 0x50, 0x33, 0x38, 0x34, 0x5f, 0x53, 0x48, 0x41, 0x5f, 0x32, 0x35, 0x36,
|
||||||
0x10, 0x13, 0x1a, 0x02, 0x08, 0x01, 0x12, 0x1f, 0x0a, 0x17, 0x50, 0x4b, 0x49, 0x58, 0x5f, 0x45,
|
0x10, 0x13, 0x1a, 0x02, 0x08, 0x01, 0x12, 0x1f, 0x0a, 0x17, 0x50, 0x4b, 0x49, 0x58, 0x5f, 0x45,
|
||||||
0x43, 0x44, 0x53, 0x41, 0x5f, 0x50, 0x35, 0x32, 0x31, 0x5f, 0x53, 0x48, 0x41, 0x5f, 0x32, 0x35,
|
0x43, 0x44, 0x53, 0x41, 0x5f, 0x50, 0x35, 0x32, 0x31, 0x5f, 0x53, 0x48, 0x41, 0x5f, 0x32, 0x35,
|
||||||
0x36, 0x10, 0x14, 0x1a, 0x02, 0x08, 0x01, 0x12, 0x0e, 0x0a, 0x0a, 0x4c, 0x4d, 0x53, 0x5f, 0x53,
|
0x36, 0x10, 0x14, 0x1a, 0x02, 0x08, 0x01, 0x12, 0x12, 0x0a, 0x0a, 0x4c, 0x4d, 0x53, 0x5f, 0x53,
|
||||||
0x48, 0x41, 0x32, 0x35, 0x36, 0x10, 0x0e, 0x12, 0x10, 0x0a, 0x0c, 0x4c, 0x4d, 0x4f, 0x54, 0x53,
|
0x48, 0x41, 0x32, 0x35, 0x36, 0x10, 0x0e, 0x1a, 0x02, 0x08, 0x01, 0x12, 0x14, 0x0a, 0x0c, 0x4c,
|
||||||
0x5f, 0x53, 0x48, 0x41, 0x32, 0x35, 0x36, 0x10, 0x0f, 0x22, 0x04, 0x08, 0x15, 0x10, 0x32, 0x2a,
|
0x4d, 0x4f, 0x54, 0x53, 0x5f, 0x53, 0x48, 0x41, 0x32, 0x35, 0x36, 0x10, 0x0f, 0x1a, 0x02, 0x08,
|
||||||
0x6f, 0x0a, 0x1a, 0x53, 0x75, 0x62, 0x6a, 0x65, 0x63, 0x74, 0x41, 0x6c, 0x74, 0x65, 0x72, 0x6e,
|
0x01, 0x12, 0x0d, 0x0a, 0x09, 0x4d, 0x4c, 0x5f, 0x44, 0x53, 0x41, 0x5f, 0x36, 0x35, 0x10, 0x15,
|
||||||
0x61, 0x74, 0x69, 0x76, 0x65, 0x4e, 0x61, 0x6d, 0x65, 0x54, 0x79, 0x70, 0x65, 0x12, 0x2d, 0x0a,
|
0x12, 0x0d, 0x0a, 0x09, 0x4d, 0x4c, 0x5f, 0x44, 0x53, 0x41, 0x5f, 0x38, 0x37, 0x10, 0x16, 0x22,
|
||||||
0x29, 0x53, 0x55, 0x42, 0x4a, 0x45, 0x43, 0x54, 0x5f, 0x41, 0x4c, 0x54, 0x45, 0x52, 0x4e, 0x41,
|
0x04, 0x08, 0x17, 0x10, 0x32, 0x2a, 0x6f, 0x0a, 0x1a, 0x53, 0x75, 0x62, 0x6a, 0x65, 0x63, 0x74,
|
||||||
0x54, 0x49, 0x56, 0x45, 0x5f, 0x4e, 0x41, 0x4d, 0x45, 0x5f, 0x54, 0x59, 0x50, 0x45, 0x5f, 0x55,
|
0x41, 0x6c, 0x74, 0x65, 0x72, 0x6e, 0x61, 0x74, 0x69, 0x76, 0x65, 0x4e, 0x61, 0x6d, 0x65, 0x54,
|
||||||
0x4e, 0x53, 0x50, 0x45, 0x43, 0x49, 0x46, 0x49, 0x45, 0x44, 0x10, 0x00, 0x12, 0x09, 0x0a, 0x05,
|
0x79, 0x70, 0x65, 0x12, 0x2d, 0x0a, 0x29, 0x53, 0x55, 0x42, 0x4a, 0x45, 0x43, 0x54, 0x5f, 0x41,
|
||||||
0x45, 0x4d, 0x41, 0x49, 0x4c, 0x10, 0x01, 0x12, 0x07, 0x0a, 0x03, 0x55, 0x52, 0x49, 0x10, 0x02,
|
0x4c, 0x54, 0x45, 0x52, 0x4e, 0x41, 0x54, 0x49, 0x56, 0x45, 0x5f, 0x4e, 0x41, 0x4d, 0x45, 0x5f,
|
||||||
0x12, 0x0e, 0x0a, 0x0a, 0x4f, 0x54, 0x48, 0x45, 0x52, 0x5f, 0x4e, 0x41, 0x4d, 0x45, 0x10, 0x03,
|
0x54, 0x59, 0x50, 0x45, 0x5f, 0x55, 0x4e, 0x53, 0x50, 0x45, 0x43, 0x49, 0x46, 0x49, 0x45, 0x44,
|
||||||
0x42, 0x7c, 0x0a, 0x1c, 0x64, 0x65, 0x76, 0x2e, 0x73, 0x69, 0x67, 0x73, 0x74, 0x6f, 0x72, 0x65,
|
0x10, 0x00, 0x12, 0x09, 0x0a, 0x05, 0x45, 0x4d, 0x41, 0x49, 0x4c, 0x10, 0x01, 0x12, 0x07, 0x0a,
|
||||||
0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x2e, 0x63, 0x6f, 0x6d, 0x6d, 0x6f, 0x6e, 0x2e, 0x76, 0x31,
|
0x03, 0x55, 0x52, 0x49, 0x10, 0x02, 0x12, 0x0e, 0x0a, 0x0a, 0x4f, 0x54, 0x48, 0x45, 0x52, 0x5f,
|
||||||
0x42, 0x0b, 0x43, 0x6f, 0x6d, 0x6d, 0x6f, 0x6e, 0x50, 0x72, 0x6f, 0x74, 0x6f, 0x50, 0x01, 0x5a,
|
0x4e, 0x41, 0x4d, 0x45, 0x10, 0x03, 0x42, 0x7c, 0x0a, 0x1c, 0x64, 0x65, 0x76, 0x2e, 0x73, 0x69,
|
||||||
0x36, 0x67, 0x69, 0x74, 0x68, 0x75, 0x62, 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x73, 0x69, 0x67, 0x73,
|
0x67, 0x73, 0x74, 0x6f, 0x72, 0x65, 0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x2e, 0x63, 0x6f, 0x6d,
|
||||||
0x74, 0x6f, 0x72, 0x65, 0x2f, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2d, 0x73, 0x70,
|
0x6d, 0x6f, 0x6e, 0x2e, 0x76, 0x31, 0x42, 0x0b, 0x43, 0x6f, 0x6d, 0x6d, 0x6f, 0x6e, 0x50, 0x72,
|
||||||
0x65, 0x63, 0x73, 0x2f, 0x67, 0x65, 0x6e, 0x2f, 0x70, 0x62, 0x2d, 0x67, 0x6f, 0x2f, 0x63, 0x6f,
|
0x6f, 0x74, 0x6f, 0x50, 0x01, 0x5a, 0x36, 0x67, 0x69, 0x74, 0x68, 0x75, 0x62, 0x2e, 0x63, 0x6f,
|
||||||
0x6d, 0x6d, 0x6f, 0x6e, 0x2f, 0x76, 0x31, 0xea, 0x02, 0x14, 0x53, 0x69, 0x67, 0x73, 0x74, 0x6f,
|
0x6d, 0x2f, 0x73, 0x69, 0x67, 0x73, 0x74, 0x6f, 0x72, 0x65, 0x2f, 0x70, 0x72, 0x6f, 0x74, 0x6f,
|
||||||
0x72, 0x65, 0x3a, 0x3a, 0x43, 0x6f, 0x6d, 0x6d, 0x6f, 0x6e, 0x3a, 0x3a, 0x56, 0x31, 0x62, 0x06,
|
0x62, 0x75, 0x66, 0x2d, 0x73, 0x70, 0x65, 0x63, 0x73, 0x2f, 0x67, 0x65, 0x6e, 0x2f, 0x70, 0x62,
|
||||||
0x70, 0x72, 0x6f, 0x74, 0x6f, 0x33,
|
0x2d, 0x67, 0x6f, 0x2f, 0x63, 0x6f, 0x6d, 0x6d, 0x6f, 0x6e, 0x2f, 0x76, 0x31, 0xea, 0x02, 0x14,
|
||||||
|
0x53, 0x69, 0x67, 0x73, 0x74, 0x6f, 0x72, 0x65, 0x3a, 0x3a, 0x43, 0x6f, 0x6d, 0x6d, 0x6f, 0x6e,
|
||||||
|
0x3a, 0x3a, 0x56, 0x31, 0x62, 0x06, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x33,
|
||||||
})
|
})
|
||||||
|
|
||||||
var (
|
var (
|
||||||
|
|
|
||||||
54
vendor/github.com/sigstore/sigstore/pkg/cryptoutils/publickey.go
generated
vendored
54
vendor/github.com/sigstore/sigstore/pkg/cryptoutils/publickey.go
generated
vendored
|
|
@ -16,7 +16,6 @@
|
||||||
package cryptoutils
|
package cryptoutils
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
|
||||||
"crypto"
|
"crypto"
|
||||||
"crypto/ecdsa"
|
"crypto/ecdsa"
|
||||||
"crypto/ed25519"
|
"crypto/ed25519"
|
||||||
|
|
@ -29,8 +28,6 @@ import (
|
||||||
"encoding/pem"
|
"encoding/pem"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
|
||||||
"github.com/letsencrypt/boulder/goodkey"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
const (
|
const (
|
||||||
|
|
@ -133,54 +130,3 @@ func genErrMsg(first, second crypto.PublicKey, keyType string) string {
|
||||||
}
|
}
|
||||||
return fmt.Sprintf("%s (%s, %s)", msg, hex.EncodeToString(firstSKID), hex.EncodeToString(secondSKID))
|
return fmt.Sprintf("%s (%s, %s)", msg, hex.EncodeToString(firstSKID), hex.EncodeToString(secondSKID))
|
||||||
}
|
}
|
||||||
|
|
||||||
// ValidatePubKey validates the parameters of an RSA, ECDSA, or ED25519 public key.
|
|
||||||
func ValidatePubKey(pub crypto.PublicKey) error {
|
|
||||||
// goodkey policy enforces:
|
|
||||||
// * RSA
|
|
||||||
// * Size of key: 2048 <= size <= 4096, size % 8 = 0
|
|
||||||
// * Exponent E = 65537 (Default exponent for OpenSSL and Golang)
|
|
||||||
// * Small primes check for modulus
|
|
||||||
// * Weak keys generated by Infineon hardware (see https://crocs.fi.muni.cz/public/papers/rsa_ccs17)
|
|
||||||
// * Key is easily factored with Fermat's factorization method
|
|
||||||
// * EC
|
|
||||||
// * Public key Q is not the identity element (Ø)
|
|
||||||
// * Public key Q's x and y are within [0, p-1]
|
|
||||||
// * Public key Q is on the curve
|
|
||||||
// * Public key Q's order matches the subgroups (nQ = Ø)
|
|
||||||
allowedKeys := &goodkey.AllowedKeys{
|
|
||||||
RSA2048: true,
|
|
||||||
RSA3072: true,
|
|
||||||
RSA4096: true,
|
|
||||||
ECDSAP256: true,
|
|
||||||
ECDSAP384: true,
|
|
||||||
ECDSAP521: true,
|
|
||||||
}
|
|
||||||
cfg := &goodkey.Config{
|
|
||||||
FermatRounds: 100,
|
|
||||||
AllowedKeys: allowedKeys,
|
|
||||||
}
|
|
||||||
p, err := goodkey.NewPolicy(cfg, nil)
|
|
||||||
if err != nil {
|
|
||||||
// Should not occur, only chances to return errors are if fermat rounds
|
|
||||||
// are <0 or when loading blocked/weak keys from disk (not used here)
|
|
||||||
return errors.New("unable to initialize key policy")
|
|
||||||
}
|
|
||||||
|
|
||||||
switch pk := pub.(type) {
|
|
||||||
case *rsa.PublicKey:
|
|
||||||
// ctx is unused
|
|
||||||
return p.GoodKey(context.Background(), pub)
|
|
||||||
case *ecdsa.PublicKey:
|
|
||||||
// ctx is unused
|
|
||||||
return p.GoodKey(context.Background(), pub)
|
|
||||||
case ed25519.PublicKey:
|
|
||||||
return validateEd25519Key(pk)
|
|
||||||
}
|
|
||||||
return errors.New("unsupported public key type")
|
|
||||||
}
|
|
||||||
|
|
||||||
// No validations currently, ED25519 supports only one key size.
|
|
||||||
func validateEd25519Key(_ ed25519.PublicKey) error {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
|
||||||
34
vendor/github.com/sigstore/sigstore/pkg/cryptoutils/safestring.go
generated
vendored
Normal file
34
vendor/github.com/sigstore/sigstore/pkg/cryptoutils/safestring.go
generated
vendored
Normal file
|
|
@ -0,0 +1,34 @@
|
||||||
|
//
|
||||||
|
// Copyright 2025 The Sigstore Authors.
|
||||||
|
//
|
||||||
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||||
|
// you may not use this file except in compliance with the License.
|
||||||
|
// You may obtain a copy of the License at
|
||||||
|
//
|
||||||
|
// http://www.apache.org/licenses/LICENSE-2.0
|
||||||
|
//
|
||||||
|
// Unless required by applicable law or agreed to in writing, software
|
||||||
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||||
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
|
// See the License for the specific language governing permissions and
|
||||||
|
// limitations under the License.
|
||||||
|
|
||||||
|
package cryptoutils
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/rand"
|
||||||
|
"encoding/base64"
|
||||||
|
)
|
||||||
|
|
||||||
|
// GenerateRandomURLSafeString generates a cryptographically secure random
|
||||||
|
// URL-safe string with the specified number of bits of entropy.
|
||||||
|
func GenerateRandomURLSafeString(entropyLength uint) string {
|
||||||
|
if entropyLength == 0 {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
// Round up to the nearest byte to ensure minimum entropy is met
|
||||||
|
entropyBytes := (entropyLength + 7) / 8
|
||||||
|
b := make([]byte, entropyBytes)
|
||||||
|
_, _ = rand.Read(b)
|
||||||
|
return base64.RawURLEncoding.EncodeToString(b)
|
||||||
|
}
|
||||||
3
vendor/github.com/sigstore/sigstore/pkg/cryptoutils/sans.go
generated
vendored
3
vendor/github.com/sigstore/sigstore/pkg/cryptoutils/sans.go
generated
vendored
|
|
@ -132,6 +132,9 @@ func UnmarshalOtherNameSAN(exts []pkix.Extension) (string, error) {
|
||||||
// and OtherName SANs
|
// and OtherName SANs
|
||||||
func GetSubjectAlternateNames(cert *x509.Certificate) []string {
|
func GetSubjectAlternateNames(cert *x509.Certificate) []string {
|
||||||
sans := []string{}
|
sans := []string{}
|
||||||
|
if cert == nil {
|
||||||
|
return sans
|
||||||
|
}
|
||||||
sans = append(sans, cert.DNSNames...)
|
sans = append(sans, cert.DNSNames...)
|
||||||
sans = append(sans, cert.EmailAddresses...)
|
sans = append(sans, cert.EmailAddresses...)
|
||||||
for _, ip := range cert.IPAddresses {
|
for _, ip := range cert.IPAddresses {
|
||||||
|
|
|
||||||
8
vendor/github.com/sigstore/sigstore/pkg/signature/message.go
generated
vendored
8
vendor/github.com/sigstore/sigstore/pkg/signature/message.go
generated
vendored
|
|
@ -55,10 +55,10 @@ func ComputeDigestForSigning(rawMessage io.Reader, defaultHashFunc crypto.Hash,
|
||||||
if hashedWith != crypto.Hash(0) && len(digest) != hashedWith.Size() {
|
if hashedWith != crypto.Hash(0) && len(digest) != hashedWith.Size() {
|
||||||
err = errors.New("unexpected length of digest for hash function specified")
|
err = errors.New("unexpected length of digest for hash function specified")
|
||||||
}
|
}
|
||||||
return
|
return digest, hashedWith, err
|
||||||
}
|
}
|
||||||
digest, err = hashMessage(rawMessage, hashedWith)
|
digest, err = hashMessage(rawMessage, hashedWith)
|
||||||
return
|
return digest, hashedWith, err
|
||||||
}
|
}
|
||||||
|
|
||||||
// ComputeDigestForVerifying calculates the digest value for the specified message using a hash function selected by the following process:
|
// ComputeDigestForVerifying calculates the digest value for the specified message using a hash function selected by the following process:
|
||||||
|
|
@ -81,10 +81,10 @@ func ComputeDigestForVerifying(rawMessage io.Reader, defaultHashFunc crypto.Hash
|
||||||
if hashedWith != crypto.Hash(0) && len(digest) != hashedWith.Size() {
|
if hashedWith != crypto.Hash(0) && len(digest) != hashedWith.Size() {
|
||||||
err = errors.New("unexpected length of digest for hash function specified")
|
err = errors.New("unexpected length of digest for hash function specified")
|
||||||
}
|
}
|
||||||
return
|
return digest, hashedWith, err
|
||||||
}
|
}
|
||||||
digest, err = hashMessage(rawMessage, hashedWith)
|
digest, err = hashMessage(rawMessage, hashedWith)
|
||||||
return
|
return digest, hashedWith, err
|
||||||
}
|
}
|
||||||
|
|
||||||
func hashMessage(rawMessage io.Reader, hashFunc crypto.Hash) ([]byte, error) {
|
func hashMessage(rawMessage io.Reader, hashFunc crypto.Hash) ([]byte, error) {
|
||||||
|
|
|
||||||
3
vendor/github.com/sigstore/sigstore/pkg/signature/signer.go
generated
vendored
3
vendor/github.com/sigstore/sigstore/pkg/signature/signer.go
generated
vendored
|
|
@ -31,9 +31,6 @@ import (
|
||||||
|
|
||||||
"github.com/sigstore/sigstore/pkg/cryptoutils"
|
"github.com/sigstore/sigstore/pkg/cryptoutils"
|
||||||
"github.com/sigstore/sigstore/pkg/signature/options"
|
"github.com/sigstore/sigstore/pkg/signature/options"
|
||||||
|
|
||||||
// these ensure we have the implementations loaded
|
|
||||||
_ "golang.org/x/crypto/sha3"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// Signer creates digital signatures over a message using a specified key pair
|
// Signer creates digital signatures over a message using a specified key pair
|
||||||
|
|
|
||||||
7
vendor/github.com/spf13/cobra/.golangci.yml
generated
vendored
7
vendor/github.com/spf13/cobra/.golangci.yml
generated
vendored
|
|
@ -57,3 +57,10 @@ linters:
|
||||||
- common-false-positives
|
- common-false-positives
|
||||||
- legacy
|
- legacy
|
||||||
- std-error-handling
|
- std-error-handling
|
||||||
|
settings:
|
||||||
|
govet:
|
||||||
|
# Disable buildtag check to allow dual build tag syntax (both //go:build and // +build).
|
||||||
|
# This is necessary for Go 1.15 compatibility since //go:build was introduced in Go 1.17.
|
||||||
|
# This can be removed once Cobra requires Go 1.17 or higher.
|
||||||
|
disable:
|
||||||
|
- buildtag
|
||||||
|
|
|
||||||
12
vendor/github.com/spf13/cobra/command.go
generated
vendored
12
vendor/github.com/spf13/cobra/command.go
generated
vendored
|
|
@ -557,7 +557,7 @@ func (c *Command) FlagErrorFunc() (f func(*Command, error) error) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
var minUsagePadding = 25
|
const minUsagePadding = 25
|
||||||
|
|
||||||
// UsagePadding return padding for the usage.
|
// UsagePadding return padding for the usage.
|
||||||
func (c *Command) UsagePadding() int {
|
func (c *Command) UsagePadding() int {
|
||||||
|
|
@ -567,7 +567,7 @@ func (c *Command) UsagePadding() int {
|
||||||
return c.parent.commandsMaxUseLen
|
return c.parent.commandsMaxUseLen
|
||||||
}
|
}
|
||||||
|
|
||||||
var minCommandPathPadding = 11
|
const minCommandPathPadding = 11
|
||||||
|
|
||||||
// CommandPathPadding return padding for the command path.
|
// CommandPathPadding return padding for the command path.
|
||||||
func (c *Command) CommandPathPadding() int {
|
func (c *Command) CommandPathPadding() int {
|
||||||
|
|
@ -577,7 +577,7 @@ func (c *Command) CommandPathPadding() int {
|
||||||
return c.parent.commandsMaxCommandPathLen
|
return c.parent.commandsMaxCommandPathLen
|
||||||
}
|
}
|
||||||
|
|
||||||
var minNamePadding = 11
|
const minNamePadding = 11
|
||||||
|
|
||||||
// NamePadding returns padding for the name.
|
// NamePadding returns padding for the name.
|
||||||
func (c *Command) NamePadding() int {
|
func (c *Command) NamePadding() int {
|
||||||
|
|
@ -1939,7 +1939,7 @@ type tmplFunc struct {
|
||||||
fn func(io.Writer, interface{}) error
|
fn func(io.Writer, interface{}) error
|
||||||
}
|
}
|
||||||
|
|
||||||
var defaultUsageTemplate = `Usage:{{if .Runnable}}
|
const defaultUsageTemplate = `Usage:{{if .Runnable}}
|
||||||
{{.UseLine}}{{end}}{{if .HasAvailableSubCommands}}
|
{{.UseLine}}{{end}}{{if .HasAvailableSubCommands}}
|
||||||
{{.CommandPath}} [command]{{end}}{{if gt (len .Aliases) 0}}
|
{{.CommandPath}} [command]{{end}}{{if gt (len .Aliases) 0}}
|
||||||
|
|
||||||
|
|
@ -2039,7 +2039,7 @@ func defaultUsageFunc(w io.Writer, in interface{}) error {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
var defaultHelpTemplate = `{{with (or .Long .Short)}}{{. | trimTrailingWhitespaces}}
|
const defaultHelpTemplate = `{{with (or .Long .Short)}}{{. | trimTrailingWhitespaces}}
|
||||||
|
|
||||||
{{end}}{{if or .Runnable .HasSubCommands}}{{.UsageString}}{{end}}`
|
{{end}}{{if or .Runnable .HasSubCommands}}{{.UsageString}}{{end}}`
|
||||||
|
|
||||||
|
|
@ -2061,7 +2061,7 @@ func defaultHelpFunc(w io.Writer, in interface{}) error {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
var defaultVersionTemplate = `{{with .DisplayName}}{{printf "%s " .}}{{end}}{{printf "version %s" .Version}}
|
const defaultVersionTemplate = `{{with .DisplayName}}{{printf "%s " .}}{{end}}{{printf "version %s" .Version}}
|
||||||
`
|
`
|
||||||
|
|
||||||
// defaultVersionFunc is equivalent to executing defaultVersionTemplate. The two should be changed in sync.
|
// defaultVersionFunc is equivalent to executing defaultVersionTemplate. The two should be changed in sync.
|
||||||
|
|
|
||||||
22
vendor/github.com/titanous/rocacheck/LICENSE
generated
vendored
22
vendor/github.com/titanous/rocacheck/LICENSE
generated
vendored
|
|
@ -1,22 +0,0 @@
|
||||||
MIT License
|
|
||||||
|
|
||||||
Copyright (c) 2017, Jonathan Rudenberg
|
|
||||||
Copyright (c) 2017, CRoCS, EnigmaBridge Ltd.
|
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
|
||||||
of this software and associated documentation files (the "Software"), to deal
|
|
||||||
in the Software without restriction, including without limitation the rights
|
|
||||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
|
||||||
copies of the Software, and to permit persons to whom the Software is
|
|
||||||
furnished to do so, subject to the following conditions:
|
|
||||||
|
|
||||||
The above copyright notice and this permission notice shall be included in all
|
|
||||||
copies or substantial portions of the Software.
|
|
||||||
|
|
||||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
|
||||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
|
||||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
|
||||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
|
||||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
|
||||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
||||||
SOFTWARE.
|
|
||||||
7
vendor/github.com/titanous/rocacheck/README.md
generated
vendored
7
vendor/github.com/titanous/rocacheck/README.md
generated
vendored
|
|
@ -1,7 +0,0 @@
|
||||||
# rocacheck [](https://godoc.org/github.com/titanous/rocacheck)
|
|
||||||
|
|
||||||
Package rocacheck is a Go implementation of the [key fingerprint
|
|
||||||
algorithm](https://github.com/crocs-muni/roca) that checks if an RSA key was
|
|
||||||
generated by broken Infineon code and is vulnerable to factorization via the
|
|
||||||
[Return of Coppersmith's Attack
|
|
||||||
(ROCA)](https://crocs.fi.muni.cz/public/papers/rsa_ccs17) / CVE-2017-15361.
|
|
||||||
52
vendor/github.com/titanous/rocacheck/rocacheck.go
generated
vendored
52
vendor/github.com/titanous/rocacheck/rocacheck.go
generated
vendored
|
|
@ -1,52 +0,0 @@
|
||||||
// Package rocacheck checks if a key was generated by broken Infineon code and
|
|
||||||
// is vulnerable to factorization via the Return of Coppersmith's Attack (ROCA)
|
|
||||||
// / CVE-2017-15361.
|
|
||||||
package rocacheck
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/rsa"
|
|
||||||
"math/big"
|
|
||||||
)
|
|
||||||
|
|
||||||
type test struct {
|
|
||||||
Prime *big.Int
|
|
||||||
Fingerprints map[int64]struct{}
|
|
||||||
}
|
|
||||||
|
|
||||||
var tests = make([]test, 17)
|
|
||||||
|
|
||||||
func init() {
|
|
||||||
bigOne := big.NewInt(1)
|
|
||||||
n := &big.Int{}
|
|
||||||
// relations table from https://github.com/crocs-muni/roca/pull/40
|
|
||||||
for i, r := range [][2]int64{
|
|
||||||
{2, 11}, {6, 13}, {8, 17}, {9, 19}, {3, 37}, {26, 53}, {20, 61},
|
|
||||||
{35, 71}, {24, 73}, {13, 79}, {6, 97}, {51, 103}, {53, 107},
|
|
||||||
{54, 109}, {42, 127}, {50, 151}, {78, 157},
|
|
||||||
} {
|
|
||||||
fps := make(map[int64]struct{})
|
|
||||||
bp := big.NewInt(r[1])
|
|
||||||
br := big.NewInt(r[0])
|
|
||||||
for j := int64(0); j < r[1]; j++ {
|
|
||||||
if n.Exp(big.NewInt(j), br, bp).Cmp(bigOne) == 0 {
|
|
||||||
fps[j] = struct{}{}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
tests[i] = test{
|
|
||||||
Prime: big.NewInt(r[1]),
|
|
||||||
Fingerprints: fps,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// IsWeak returns true if a RSA public key is vulnerable to Return of
|
|
||||||
// Coppersmith's Attack (ROCA).
|
|
||||||
func IsWeak(k *rsa.PublicKey) bool {
|
|
||||||
tmp := &big.Int{}
|
|
||||||
for _, t := range tests {
|
|
||||||
if _, ok := t.Fingerprints[tmp.Mod(k.N, t.Prime).Int64()]; !ok {
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
2
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/id.go
generated
vendored
2
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/id.go
generated
vendored
|
|
@ -82,7 +82,7 @@ func marshalJSON(id []byte) ([]byte, error) {
|
||||||
}
|
}
|
||||||
|
|
||||||
// unmarshalJSON inflates trace id from hex string, possibly enclosed in quotes.
|
// unmarshalJSON inflates trace id from hex string, possibly enclosed in quotes.
|
||||||
func unmarshalJSON(dst []byte, src []byte) error {
|
func unmarshalJSON(dst, src []byte) error {
|
||||||
if l := len(src); l >= 2 && src[0] == '"' && src[l-1] == '"' {
|
if l := len(src); l >= 2 && src[0] == '"' && src[l-1] == '"' {
|
||||||
src = src[1 : l-1]
|
src = src[1 : l-1]
|
||||||
}
|
}
|
||||||
|
|
|
||||||
2
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/number.go
generated
vendored
2
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/number.go
generated
vendored
|
|
@ -41,7 +41,7 @@ func (i *protoInt64) UnmarshalJSON(data []byte) error {
|
||||||
// strings or integers.
|
// strings or integers.
|
||||||
type protoUint64 uint64
|
type protoUint64 uint64
|
||||||
|
|
||||||
// Int64 returns the protoUint64 as a uint64.
|
// Uint64 returns the protoUint64 as a uint64.
|
||||||
func (i *protoUint64) Uint64() uint64 { return uint64(*i) }
|
func (i *protoUint64) Uint64() uint64 { return uint64(*i) }
|
||||||
|
|
||||||
// UnmarshalJSON decodes both strings and integers.
|
// UnmarshalJSON decodes both strings and integers.
|
||||||
|
|
|
||||||
70
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/span.go
generated
vendored
70
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/span.go
generated
vendored
|
|
@ -10,6 +10,7 @@ import (
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
|
"math"
|
||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -151,8 +152,8 @@ func (s Span) MarshalJSON() ([]byte, error) {
|
||||||
}{
|
}{
|
||||||
Alias: Alias(s),
|
Alias: Alias(s),
|
||||||
ParentSpanID: parentSpanId,
|
ParentSpanID: parentSpanId,
|
||||||
StartTime: uint64(startT),
|
StartTime: uint64(startT), // nolint:gosec // >0 checked above.
|
||||||
EndTime: uint64(endT),
|
EndTime: uint64(endT), // nolint:gosec // >0 checked above.
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -201,11 +202,13 @@ func (s *Span) UnmarshalJSON(data []byte) error {
|
||||||
case "startTimeUnixNano", "start_time_unix_nano":
|
case "startTimeUnixNano", "start_time_unix_nano":
|
||||||
var val protoUint64
|
var val protoUint64
|
||||||
err = decoder.Decode(&val)
|
err = decoder.Decode(&val)
|
||||||
s.StartTime = time.Unix(0, int64(val.Uint64()))
|
v := int64(min(val.Uint64(), math.MaxInt64)) //nolint:gosec // Overflow checked.
|
||||||
|
s.StartTime = time.Unix(0, v)
|
||||||
case "endTimeUnixNano", "end_time_unix_nano":
|
case "endTimeUnixNano", "end_time_unix_nano":
|
||||||
var val protoUint64
|
var val protoUint64
|
||||||
err = decoder.Decode(&val)
|
err = decoder.Decode(&val)
|
||||||
s.EndTime = time.Unix(0, int64(val.Uint64()))
|
v := int64(min(val.Uint64(), math.MaxInt64)) //nolint:gosec // Overflow checked.
|
||||||
|
s.EndTime = time.Unix(0, v)
|
||||||
case "attributes":
|
case "attributes":
|
||||||
err = decoder.Decode(&s.Attrs)
|
err = decoder.Decode(&s.Attrs)
|
||||||
case "droppedAttributesCount", "dropped_attributes_count":
|
case "droppedAttributesCount", "dropped_attributes_count":
|
||||||
|
|
@ -248,13 +251,20 @@ func (s *Span) UnmarshalJSON(data []byte) error {
|
||||||
type SpanFlags int32
|
type SpanFlags int32
|
||||||
|
|
||||||
const (
|
const (
|
||||||
|
// SpanFlagsTraceFlagsMask is a mask for trace-flags.
|
||||||
|
//
|
||||||
// Bits 0-7 are used for trace flags.
|
// Bits 0-7 are used for trace flags.
|
||||||
SpanFlagsTraceFlagsMask SpanFlags = 255
|
SpanFlagsTraceFlagsMask SpanFlags = 255
|
||||||
// Bits 8 and 9 are used to indicate that the parent span or link span is remote.
|
// SpanFlagsContextHasIsRemoteMask is a mask for HAS_IS_REMOTE status.
|
||||||
// Bit 8 (`HAS_IS_REMOTE`) indicates whether the value is known.
|
//
|
||||||
// Bit 9 (`IS_REMOTE`) indicates whether the span or link is remote.
|
// Bits 8 and 9 are used to indicate that the parent span or link span is
|
||||||
|
// remote. Bit 8 (`HAS_IS_REMOTE`) indicates whether the value is known.
|
||||||
SpanFlagsContextHasIsRemoteMask SpanFlags = 256
|
SpanFlagsContextHasIsRemoteMask SpanFlags = 256
|
||||||
// SpanFlagsContextHasIsRemoteMask indicates the Span is remote.
|
// SpanFlagsContextIsRemoteMask is a mask for IS_REMOTE status.
|
||||||
|
//
|
||||||
|
// Bits 8 and 9 are used to indicate that the parent span or link span is
|
||||||
|
// remote. Bit 9 (`IS_REMOTE`) indicates whether the span or link is
|
||||||
|
// remote.
|
||||||
SpanFlagsContextIsRemoteMask SpanFlags = 512
|
SpanFlagsContextIsRemoteMask SpanFlags = 512
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -263,26 +273,30 @@ const (
|
||||||
type SpanKind int32
|
type SpanKind int32
|
||||||
|
|
||||||
const (
|
const (
|
||||||
// Indicates that the span represents an internal operation within an application,
|
// SpanKindInternal indicates that the span represents an internal
|
||||||
// as opposed to an operation happening at the boundaries. Default value.
|
// operation within an application, as opposed to an operation happening at
|
||||||
|
// the boundaries.
|
||||||
SpanKindInternal SpanKind = 1
|
SpanKindInternal SpanKind = 1
|
||||||
// Indicates that the span covers server-side handling of an RPC or other
|
// SpanKindServer indicates that the span covers server-side handling of an
|
||||||
// remote network request.
|
// RPC or other remote network request.
|
||||||
SpanKindServer SpanKind = 2
|
SpanKindServer SpanKind = 2
|
||||||
// Indicates that the span describes a request to some remote service.
|
// SpanKindClient indicates that the span describes a request to some
|
||||||
|
// remote service.
|
||||||
SpanKindClient SpanKind = 3
|
SpanKindClient SpanKind = 3
|
||||||
// Indicates that the span describes a producer sending a message to a broker.
|
// SpanKindProducer indicates that the span describes a producer sending a
|
||||||
// Unlike CLIENT and SERVER, there is often no direct critical path latency relationship
|
// message to a broker. Unlike SpanKindClient and SpanKindServer, there is
|
||||||
// between producer and consumer spans. A PRODUCER span ends when the message was accepted
|
// often no direct critical path latency relationship between producer and
|
||||||
// by the broker while the logical processing of the message might span a much longer time.
|
// consumer spans. A SpanKindProducer span ends when the message was
|
||||||
|
// accepted by the broker while the logical processing of the message might
|
||||||
|
// span a much longer time.
|
||||||
SpanKindProducer SpanKind = 4
|
SpanKindProducer SpanKind = 4
|
||||||
// Indicates that the span describes consumer receiving a message from a broker.
|
// SpanKindConsumer indicates that the span describes a consumer receiving
|
||||||
// Like the PRODUCER kind, there is often no direct critical path latency relationship
|
// a message from a broker. Like SpanKindProducer, there is often no direct
|
||||||
// between producer and consumer spans.
|
// critical path latency relationship between producer and consumer spans.
|
||||||
SpanKindConsumer SpanKind = 5
|
SpanKindConsumer SpanKind = 5
|
||||||
)
|
)
|
||||||
|
|
||||||
// Event is a time-stamped annotation of the span, consisting of user-supplied
|
// SpanEvent is a time-stamped annotation of the span, consisting of user-supplied
|
||||||
// text description and key-value pairs.
|
// text description and key-value pairs.
|
||||||
type SpanEvent struct {
|
type SpanEvent struct {
|
||||||
// time_unix_nano is the time the event occurred.
|
// time_unix_nano is the time the event occurred.
|
||||||
|
|
@ -312,7 +326,7 @@ func (e SpanEvent) MarshalJSON() ([]byte, error) {
|
||||||
Time uint64 `json:"timeUnixNano,omitempty"`
|
Time uint64 `json:"timeUnixNano,omitempty"`
|
||||||
}{
|
}{
|
||||||
Alias: Alias(e),
|
Alias: Alias(e),
|
||||||
Time: uint64(t),
|
Time: uint64(t), //nolint:gosec // >0 checked above
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -347,7 +361,8 @@ func (se *SpanEvent) UnmarshalJSON(data []byte) error {
|
||||||
case "timeUnixNano", "time_unix_nano":
|
case "timeUnixNano", "time_unix_nano":
|
||||||
var val protoUint64
|
var val protoUint64
|
||||||
err = decoder.Decode(&val)
|
err = decoder.Decode(&val)
|
||||||
se.Time = time.Unix(0, int64(val.Uint64()))
|
v := int64(min(val.Uint64(), math.MaxInt64)) //nolint:gosec // Overflow checked.
|
||||||
|
se.Time = time.Unix(0, v)
|
||||||
case "name":
|
case "name":
|
||||||
err = decoder.Decode(&se.Name)
|
err = decoder.Decode(&se.Name)
|
||||||
case "attributes":
|
case "attributes":
|
||||||
|
|
@ -365,10 +380,11 @@ func (se *SpanEvent) UnmarshalJSON(data []byte) error {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// A pointer from the current span to another span in the same trace or in a
|
// SpanLink is a reference from the current span to another span in the same
|
||||||
// different trace. For example, this can be used in batching operations,
|
// trace or in a different trace. For example, this can be used in batching
|
||||||
// where a single batch handler processes multiple requests from different
|
// operations, where a single batch handler processes multiple requests from
|
||||||
// traces or when the handler receives a request from a different project.
|
// different traces or when the handler receives a request from a different
|
||||||
|
// project.
|
||||||
type SpanLink struct {
|
type SpanLink struct {
|
||||||
// A unique identifier of a trace that this linked span is part of. The ID is a
|
// A unique identifier of a trace that this linked span is part of. The ID is a
|
||||||
// 16-byte array.
|
// 16-byte array.
|
||||||
|
|
|
||||||
10
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/status.go
generated
vendored
10
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/status.go
generated
vendored
|
|
@ -3,17 +3,19 @@
|
||||||
|
|
||||||
package telemetry
|
package telemetry
|
||||||
|
|
||||||
|
// StatusCode is the status of a Span.
|
||||||
|
//
|
||||||
// For the semantics of status codes see
|
// For the semantics of status codes see
|
||||||
// https://github.com/open-telemetry/opentelemetry-specification/blob/main/specification/trace/api.md#set-status
|
// https://github.com/open-telemetry/opentelemetry-specification/blob/main/specification/trace/api.md#set-status
|
||||||
type StatusCode int32
|
type StatusCode int32
|
||||||
|
|
||||||
const (
|
const (
|
||||||
// The default status.
|
// StatusCodeUnset is the default status.
|
||||||
StatusCodeUnset StatusCode = 0
|
StatusCodeUnset StatusCode = 0
|
||||||
// The Span has been validated by an Application developer or Operator to
|
// StatusCodeOK is used when the Span has been validated by an Application
|
||||||
// have completed successfully.
|
// developer or Operator to have completed successfully.
|
||||||
StatusCodeOK StatusCode = 1
|
StatusCodeOK StatusCode = 1
|
||||||
// The Span contains an error.
|
// StatusCodeError is used when the Span contains an error.
|
||||||
StatusCodeError StatusCode = 2
|
StatusCodeError StatusCode = 2
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
|
||||||
4
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/traces.go
generated
vendored
4
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/traces.go
generated
vendored
|
|
@ -71,7 +71,7 @@ func (td *Traces) UnmarshalJSON(data []byte) error {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// A collection of ScopeSpans from a Resource.
|
// ResourceSpans is a collection of ScopeSpans from a Resource.
|
||||||
type ResourceSpans struct {
|
type ResourceSpans struct {
|
||||||
// The resource for the spans in this message.
|
// The resource for the spans in this message.
|
||||||
// If this field is not set then no resource info is known.
|
// If this field is not set then no resource info is known.
|
||||||
|
|
@ -128,7 +128,7 @@ func (rs *ResourceSpans) UnmarshalJSON(data []byte) error {
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// A collection of Spans produced by an InstrumentationScope.
|
// ScopeSpans is a collection of Spans produced by an InstrumentationScope.
|
||||||
type ScopeSpans struct {
|
type ScopeSpans struct {
|
||||||
// The instrumentation scope information for the spans in this message.
|
// The instrumentation scope information for the spans in this message.
|
||||||
// Semantically when InstrumentationScope isn't set, it is equivalent with
|
// Semantically when InstrumentationScope isn't set, it is equivalent with
|
||||||
|
|
|
||||||
14
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/value.go
generated
vendored
14
vendor/go.opentelemetry.io/auto/sdk/internal/telemetry/value.go
generated
vendored
|
|
@ -1,8 +1,6 @@
|
||||||
// Copyright The OpenTelemetry Authors
|
// Copyright The OpenTelemetry Authors
|
||||||
// SPDX-License-Identifier: Apache-2.0
|
// SPDX-License-Identifier: Apache-2.0
|
||||||
|
|
||||||
//go:generate stringer -type=ValueKind -trimprefix=ValueKind
|
|
||||||
|
|
||||||
package telemetry
|
package telemetry
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
|
@ -23,7 +21,7 @@ import (
|
||||||
// A zero value is valid and represents an empty value.
|
// A zero value is valid and represents an empty value.
|
||||||
type Value struct {
|
type Value struct {
|
||||||
// Ensure forward compatibility by explicitly making this not comparable.
|
// Ensure forward compatibility by explicitly making this not comparable.
|
||||||
noCmp [0]func() //nolint: unused // This is indeed used.
|
noCmp [0]func() //nolint:unused // This is indeed used.
|
||||||
|
|
||||||
// num holds the value for Int64, Float64, and Bool. It holds the length
|
// num holds the value for Int64, Float64, and Bool. It holds the length
|
||||||
// for String, Bytes, Slice, Map.
|
// for String, Bytes, Slice, Map.
|
||||||
|
|
@ -92,7 +90,7 @@ func IntValue(v int) Value { return Int64Value(int64(v)) }
|
||||||
|
|
||||||
// Int64Value returns a [Value] for an int64.
|
// Int64Value returns a [Value] for an int64.
|
||||||
func Int64Value(v int64) Value {
|
func Int64Value(v int64) Value {
|
||||||
return Value{num: uint64(v), any: ValueKindInt64}
|
return Value{num: uint64(v), any: ValueKindInt64} //nolint:gosec // Raw value conv.
|
||||||
}
|
}
|
||||||
|
|
||||||
// Float64Value returns a [Value] for a float64.
|
// Float64Value returns a [Value] for a float64.
|
||||||
|
|
@ -164,7 +162,7 @@ func (v Value) AsInt64() int64 {
|
||||||
// this will return garbage.
|
// this will return garbage.
|
||||||
func (v Value) asInt64() int64 {
|
func (v Value) asInt64() int64 {
|
||||||
// Assumes v.num was a valid int64 (overflow not checked).
|
// Assumes v.num was a valid int64 (overflow not checked).
|
||||||
return int64(v.num) // nolint: gosec
|
return int64(v.num) //nolint:gosec // Bounded.
|
||||||
}
|
}
|
||||||
|
|
||||||
// AsBool returns the value held by v as a bool.
|
// AsBool returns the value held by v as a bool.
|
||||||
|
|
@ -309,13 +307,13 @@ func (v Value) String() string {
|
||||||
return v.asString()
|
return v.asString()
|
||||||
case ValueKindInt64:
|
case ValueKindInt64:
|
||||||
// Assumes v.num was a valid int64 (overflow not checked).
|
// Assumes v.num was a valid int64 (overflow not checked).
|
||||||
return strconv.FormatInt(int64(v.num), 10) // nolint: gosec
|
return strconv.FormatInt(int64(v.num), 10) //nolint:gosec // Bounded.
|
||||||
case ValueKindFloat64:
|
case ValueKindFloat64:
|
||||||
return strconv.FormatFloat(v.asFloat64(), 'g', -1, 64)
|
return strconv.FormatFloat(v.asFloat64(), 'g', -1, 64)
|
||||||
case ValueKindBool:
|
case ValueKindBool:
|
||||||
return strconv.FormatBool(v.asBool())
|
return strconv.FormatBool(v.asBool())
|
||||||
case ValueKindBytes:
|
case ValueKindBytes:
|
||||||
return fmt.Sprint(v.asBytes())
|
return string(v.asBytes())
|
||||||
case ValueKindMap:
|
case ValueKindMap:
|
||||||
return fmt.Sprint(v.asMap())
|
return fmt.Sprint(v.asMap())
|
||||||
case ValueKindSlice:
|
case ValueKindSlice:
|
||||||
|
|
@ -343,7 +341,7 @@ func (v *Value) MarshalJSON() ([]byte, error) {
|
||||||
case ValueKindInt64:
|
case ValueKindInt64:
|
||||||
return json.Marshal(struct {
|
return json.Marshal(struct {
|
||||||
Value string `json:"intValue"`
|
Value string `json:"intValue"`
|
||||||
}{strconv.FormatInt(int64(v.num), 10)})
|
}{strconv.FormatInt(int64(v.num), 10)}) //nolint:gosec // Raw value conv.
|
||||||
case ValueKindFloat64:
|
case ValueKindFloat64:
|
||||||
return json.Marshal(struct {
|
return json.Marshal(struct {
|
||||||
Value float64 `json:"doubleValue"`
|
Value float64 `json:"doubleValue"`
|
||||||
|
|
|
||||||
25
vendor/go.opentelemetry.io/auto/sdk/span.go
generated
vendored
25
vendor/go.opentelemetry.io/auto/sdk/span.go
generated
vendored
|
|
@ -6,6 +6,7 @@ package sdk
|
||||||
import (
|
import (
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"math"
|
||||||
"reflect"
|
"reflect"
|
||||||
"runtime"
|
"runtime"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
@ -16,7 +17,7 @@ import (
|
||||||
|
|
||||||
"go.opentelemetry.io/otel/attribute"
|
"go.opentelemetry.io/otel/attribute"
|
||||||
"go.opentelemetry.io/otel/codes"
|
"go.opentelemetry.io/otel/codes"
|
||||||
semconv "go.opentelemetry.io/otel/semconv/v1.26.0"
|
semconv "go.opentelemetry.io/otel/semconv/v1.37.0"
|
||||||
"go.opentelemetry.io/otel/trace"
|
"go.opentelemetry.io/otel/trace"
|
||||||
"go.opentelemetry.io/otel/trace/noop"
|
"go.opentelemetry.io/otel/trace/noop"
|
||||||
|
|
||||||
|
|
@ -85,7 +86,12 @@ func (s *span) SetAttributes(attrs ...attribute.KeyValue) {
|
||||||
limit := maxSpan.Attrs
|
limit := maxSpan.Attrs
|
||||||
if limit == 0 {
|
if limit == 0 {
|
||||||
// No attributes allowed.
|
// No attributes allowed.
|
||||||
s.span.DroppedAttrs += uint32(len(attrs))
|
n := int64(len(attrs))
|
||||||
|
if n > 0 {
|
||||||
|
s.span.DroppedAttrs += uint32( //nolint:gosec // Bounds checked.
|
||||||
|
min(n, math.MaxUint32),
|
||||||
|
)
|
||||||
|
}
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -121,8 +127,13 @@ func (s *span) SetAttributes(attrs ...attribute.KeyValue) {
|
||||||
// convCappedAttrs converts up to limit attrs into a []telemetry.Attr. The
|
// convCappedAttrs converts up to limit attrs into a []telemetry.Attr. The
|
||||||
// number of dropped attributes is also returned.
|
// number of dropped attributes is also returned.
|
||||||
func convCappedAttrs(limit int, attrs []attribute.KeyValue) ([]telemetry.Attr, uint32) {
|
func convCappedAttrs(limit int, attrs []attribute.KeyValue) ([]telemetry.Attr, uint32) {
|
||||||
|
n := len(attrs)
|
||||||
if limit == 0 {
|
if limit == 0 {
|
||||||
return nil, uint32(len(attrs))
|
var out uint32
|
||||||
|
if n > 0 {
|
||||||
|
out = uint32(min(int64(n), math.MaxUint32)) //nolint:gosec // Bounds checked.
|
||||||
|
}
|
||||||
|
return nil, out
|
||||||
}
|
}
|
||||||
|
|
||||||
if limit < 0 {
|
if limit < 0 {
|
||||||
|
|
@ -130,8 +141,12 @@ func convCappedAttrs(limit int, attrs []attribute.KeyValue) ([]telemetry.Attr, u
|
||||||
return convAttrs(attrs), 0
|
return convAttrs(attrs), 0
|
||||||
}
|
}
|
||||||
|
|
||||||
limit = min(len(attrs), limit)
|
if n < 0 {
|
||||||
return convAttrs(attrs[:limit]), uint32(len(attrs) - limit)
|
n = 0
|
||||||
|
}
|
||||||
|
|
||||||
|
limit = min(n, limit)
|
||||||
|
return convAttrs(attrs[:limit]), uint32(n - limit) //nolint:gosec // Bounds checked.
|
||||||
}
|
}
|
||||||
|
|
||||||
func convAttrs(attrs []attribute.KeyValue) []telemetry.Attr {
|
func convAttrs(attrs []attribute.KeyValue) []telemetry.Attr {
|
||||||
|
|
|
||||||
29
vendor/go.opentelemetry.io/auto/sdk/tracer.go
generated
vendored
29
vendor/go.opentelemetry.io/auto/sdk/tracer.go
generated
vendored
|
|
@ -5,6 +5,7 @@ package sdk
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"math"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"go.opentelemetry.io/otel/trace"
|
"go.opentelemetry.io/otel/trace"
|
||||||
|
|
@ -21,15 +22,20 @@ type tracer struct {
|
||||||
|
|
||||||
var _ trace.Tracer = tracer{}
|
var _ trace.Tracer = tracer{}
|
||||||
|
|
||||||
func (t tracer) Start(ctx context.Context, name string, opts ...trace.SpanStartOption) (context.Context, trace.Span) {
|
func (t tracer) Start(
|
||||||
var psc trace.SpanContext
|
ctx context.Context,
|
||||||
|
name string,
|
||||||
|
opts ...trace.SpanStartOption,
|
||||||
|
) (context.Context, trace.Span) {
|
||||||
|
var psc, sc trace.SpanContext
|
||||||
sampled := true
|
sampled := true
|
||||||
span := new(span)
|
span := new(span)
|
||||||
|
|
||||||
// Ask eBPF for sampling decision and span context info.
|
// Ask eBPF for sampling decision and span context info.
|
||||||
t.start(ctx, span, &psc, &sampled, &span.spanContext)
|
t.start(ctx, span, &psc, &sampled, &sc)
|
||||||
|
|
||||||
span.sampled.Store(sampled)
|
span.sampled.Store(sampled)
|
||||||
|
span.spanContext = sc
|
||||||
|
|
||||||
ctx = trace.ContextWithSpan(ctx, span)
|
ctx = trace.ContextWithSpan(ctx, span)
|
||||||
|
|
||||||
|
|
@ -58,7 +64,13 @@ func (t *tracer) start(
|
||||||
// start is used for testing.
|
// start is used for testing.
|
||||||
var start = func(context.Context, *span, *trace.SpanContext, *bool, *trace.SpanContext) {}
|
var start = func(context.Context, *span, *trace.SpanContext, *bool, *trace.SpanContext) {}
|
||||||
|
|
||||||
func (t tracer) traces(name string, cfg trace.SpanConfig, sc, psc trace.SpanContext) (*telemetry.Traces, *telemetry.Span) {
|
var intToUint32Bound = min(math.MaxInt, math.MaxUint32)
|
||||||
|
|
||||||
|
func (t tracer) traces(
|
||||||
|
name string,
|
||||||
|
cfg trace.SpanConfig,
|
||||||
|
sc, psc trace.SpanContext,
|
||||||
|
) (*telemetry.Traces, *telemetry.Span) {
|
||||||
span := &telemetry.Span{
|
span := &telemetry.Span{
|
||||||
TraceID: telemetry.TraceID(sc.TraceID()),
|
TraceID: telemetry.TraceID(sc.TraceID()),
|
||||||
SpanID: telemetry.SpanID(sc.SpanID()),
|
SpanID: telemetry.SpanID(sc.SpanID()),
|
||||||
|
|
@ -73,11 +85,16 @@ func (t tracer) traces(name string, cfg trace.SpanConfig, sc, psc trace.SpanCont
|
||||||
|
|
||||||
links := cfg.Links()
|
links := cfg.Links()
|
||||||
if limit := maxSpan.Links; limit == 0 {
|
if limit := maxSpan.Links; limit == 0 {
|
||||||
span.DroppedLinks = uint32(len(links))
|
n := len(links)
|
||||||
|
if n > 0 {
|
||||||
|
bounded := max(min(n, intToUint32Bound), 0)
|
||||||
|
span.DroppedLinks = uint32(bounded) //nolint:gosec // Bounds checked.
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
if limit > 0 {
|
if limit > 0 {
|
||||||
n := max(len(links)-limit, 0)
|
n := max(len(links)-limit, 0)
|
||||||
span.DroppedLinks = uint32(n)
|
bounded := min(n, intToUint32Bound)
|
||||||
|
span.DroppedLinks = uint32(bounded) //nolint:gosec // Bounds checked.
|
||||||
links = links[n:]
|
links = links[n:]
|
||||||
}
|
}
|
||||||
span.Links = convLinks(links)
|
span.Links = convLinks(links)
|
||||||
|
|
|
||||||
30
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/LICENSE
generated
vendored
30
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/LICENSE
generated
vendored
|
|
@ -199,3 +199,33 @@
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
See the License for the specific language governing permissions and
|
See the License for the specific language governing permissions and
|
||||||
limitations under the License.
|
limitations under the License.
|
||||||
|
|
||||||
|
--------------------------------------------------------------------------------
|
||||||
|
|
||||||
|
Copyright 2009 The Go Authors.
|
||||||
|
|
||||||
|
Redistribution and use in source and binary forms, with or without
|
||||||
|
modification, are permitted provided that the following conditions are
|
||||||
|
met:
|
||||||
|
|
||||||
|
* Redistributions of source code must retain the above copyright
|
||||||
|
notice, this list of conditions and the following disclaimer.
|
||||||
|
* Redistributions in binary form must reproduce the above
|
||||||
|
copyright notice, this list of conditions and the following disclaimer
|
||||||
|
in the documentation and/or other materials provided with the
|
||||||
|
distribution.
|
||||||
|
* Neither the name of Google LLC nor the names of its
|
||||||
|
contributors may be used to endorse or promote products derived from
|
||||||
|
this software without specific prior written permission.
|
||||||
|
|
||||||
|
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||||
|
"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||||
|
LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
|
||||||
|
A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
||||||
|
OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
||||||
|
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
|
||||||
|
LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
||||||
|
DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
||||||
|
THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
||||||
|
(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
|
||||||
|
OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||||
4
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/client.go
generated
vendored
4
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/client.go
generated
vendored
|
|
@ -18,7 +18,7 @@ var DefaultClient = &http.Client{Transport: NewTransport(http.DefaultTransport)}
|
||||||
|
|
||||||
// Get is a convenient replacement for http.Get that adds a span around the request.
|
// Get is a convenient replacement for http.Get that adds a span around the request.
|
||||||
func Get(ctx context.Context, targetURL string) (resp *http.Response, err error) {
|
func Get(ctx context.Context, targetURL string) (resp *http.Response, err error) {
|
||||||
req, err := http.NewRequestWithContext(ctx, http.MethodGet, targetURL, nil)
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, targetURL, http.NoBody)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
@ -27,7 +27,7 @@ func Get(ctx context.Context, targetURL string) (resp *http.Response, err error)
|
||||||
|
|
||||||
// Head is a convenient replacement for http.Head that adds a span around the request.
|
// Head is a convenient replacement for http.Head that adds a span around the request.
|
||||||
func Head(ctx context.Context, targetURL string) (resp *http.Response, err error) {
|
func Head(ctx context.Context, targetURL string) (resp *http.Response, err error) {
|
||||||
req, err := http.NewRequestWithContext(ctx, http.MethodHead, targetURL, nil)
|
req, err := http.NewRequestWithContext(ctx, http.MethodHead, targetURL, http.NoBody)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
|
||||||
3
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/config.go
generated
vendored
3
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/config.go
generated
vendored
|
|
@ -8,9 +8,8 @@ import (
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptrace"
|
"net/http/httptrace"
|
||||||
|
|
||||||
"go.opentelemetry.io/otel/attribute"
|
|
||||||
|
|
||||||
"go.opentelemetry.io/otel"
|
"go.opentelemetry.io/otel"
|
||||||
|
"go.opentelemetry.io/otel/attribute"
|
||||||
"go.opentelemetry.io/otel/metric"
|
"go.opentelemetry.io/otel/metric"
|
||||||
"go.opentelemetry.io/otel/propagation"
|
"go.opentelemetry.io/otel/propagation"
|
||||||
"go.opentelemetry.io/otel/trace"
|
"go.opentelemetry.io/otel/trace"
|
||||||
|
|
|
||||||
6
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/handler.go
generated
vendored
6
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/handler.go
generated
vendored
|
|
@ -8,13 +8,13 @@ import (
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/felixge/httpsnoop"
|
"github.com/felixge/httpsnoop"
|
||||||
|
|
||||||
"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/request"
|
|
||||||
"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv"
|
|
||||||
"go.opentelemetry.io/otel"
|
"go.opentelemetry.io/otel"
|
||||||
"go.opentelemetry.io/otel/attribute"
|
"go.opentelemetry.io/otel/attribute"
|
||||||
"go.opentelemetry.io/otel/propagation"
|
"go.opentelemetry.io/otel/propagation"
|
||||||
"go.opentelemetry.io/otel/trace"
|
"go.opentelemetry.io/otel/trace"
|
||||||
|
|
||||||
|
"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/request"
|
||||||
|
"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv"
|
||||||
)
|
)
|
||||||
|
|
||||||
// middleware is an http middleware which wraps the next handler in a span.
|
// middleware is an http middleware which wraps the next handler in a span.
|
||||||
|
|
|
||||||
179
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv/env.go
generated
vendored
179
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv/env.go
generated
vendored
|
|
@ -10,13 +10,13 @@ import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
"net/http"
|
"net/http"
|
||||||
"os"
|
|
||||||
"strings"
|
"strings"
|
||||||
"sync"
|
"sync"
|
||||||
|
|
||||||
"go.opentelemetry.io/otel/attribute"
|
"go.opentelemetry.io/otel/attribute"
|
||||||
"go.opentelemetry.io/otel/codes"
|
"go.opentelemetry.io/otel/codes"
|
||||||
"go.opentelemetry.io/otel/metric"
|
"go.opentelemetry.io/otel/metric"
|
||||||
|
"go.opentelemetry.io/otel/semconv/v1.37.0/httpconv"
|
||||||
)
|
)
|
||||||
|
|
||||||
// OTelSemConvStabilityOptIn is an environment variable.
|
// OTelSemConvStabilityOptIn is an environment variable.
|
||||||
|
|
@ -32,17 +32,9 @@ type ResponseTelemetry struct {
|
||||||
}
|
}
|
||||||
|
|
||||||
type HTTPServer struct {
|
type HTTPServer struct {
|
||||||
duplicate bool
|
requestBodySizeHistogram httpconv.ServerRequestBodySize
|
||||||
|
responseBodySizeHistogram httpconv.ServerResponseBodySize
|
||||||
// Old metrics
|
requestDurationHistogram httpconv.ServerRequestDuration
|
||||||
requestBytesCounter metric.Int64Counter
|
|
||||||
responseBytesCounter metric.Int64Counter
|
|
||||||
serverLatencyMeasure metric.Float64Histogram
|
|
||||||
|
|
||||||
// New metrics
|
|
||||||
requestBodySizeHistogram metric.Int64Histogram
|
|
||||||
responseBodySizeHistogram metric.Int64Histogram
|
|
||||||
requestDurationHistogram metric.Float64Histogram
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// RequestTraceAttrs returns trace attributes for an HTTP request received by a
|
// RequestTraceAttrs returns trace attributes for an HTTP request received by a
|
||||||
|
|
@ -62,20 +54,10 @@ type HTTPServer struct {
|
||||||
// If the primary server name is not known, server should be an empty string.
|
// If the primary server name is not known, server should be an empty string.
|
||||||
// The req Host will be used to determine the server instead.
|
// The req Host will be used to determine the server instead.
|
||||||
func (s HTTPServer) RequestTraceAttrs(server string, req *http.Request, opts RequestTraceAttrsOpts) []attribute.KeyValue {
|
func (s HTTPServer) RequestTraceAttrs(server string, req *http.Request, opts RequestTraceAttrsOpts) []attribute.KeyValue {
|
||||||
attrs := CurrentHTTPServer{}.RequestTraceAttrs(server, req, opts)
|
return CurrentHTTPServer{}.RequestTraceAttrs(server, req, opts)
|
||||||
if s.duplicate {
|
|
||||||
return OldHTTPServer{}.RequestTraceAttrs(server, req, attrs)
|
|
||||||
}
|
|
||||||
return attrs
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s HTTPServer) NetworkTransportAttr(network string) []attribute.KeyValue {
|
func (s HTTPServer) NetworkTransportAttr(network string) []attribute.KeyValue {
|
||||||
if s.duplicate {
|
|
||||||
return []attribute.KeyValue{
|
|
||||||
OldHTTPServer{}.NetworkTransportAttr(network),
|
|
||||||
CurrentHTTPServer{}.NetworkTransportAttr(network),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return []attribute.KeyValue{
|
return []attribute.KeyValue{
|
||||||
CurrentHTTPServer{}.NetworkTransportAttr(network),
|
CurrentHTTPServer{}.NetworkTransportAttr(network),
|
||||||
}
|
}
|
||||||
|
|
@ -85,11 +67,7 @@ func (s HTTPServer) NetworkTransportAttr(network string) []attribute.KeyValue {
|
||||||
//
|
//
|
||||||
// If any of the fields in the ResponseTelemetry are not set the attribute will be omitted.
|
// If any of the fields in the ResponseTelemetry are not set the attribute will be omitted.
|
||||||
func (s HTTPServer) ResponseTraceAttrs(resp ResponseTelemetry) []attribute.KeyValue {
|
func (s HTTPServer) ResponseTraceAttrs(resp ResponseTelemetry) []attribute.KeyValue {
|
||||||
attrs := CurrentHTTPServer{}.ResponseTraceAttrs(resp)
|
return CurrentHTTPServer{}.ResponseTraceAttrs(resp)
|
||||||
if s.duplicate {
|
|
||||||
return OldHTTPServer{}.ResponseTraceAttrs(resp, attrs)
|
|
||||||
}
|
|
||||||
return attrs
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Route returns the attribute for the route.
|
// Route returns the attribute for the route.
|
||||||
|
|
@ -133,42 +111,28 @@ type MetricData struct {
|
||||||
|
|
||||||
var (
|
var (
|
||||||
metricAddOptionPool = &sync.Pool{
|
metricAddOptionPool = &sync.Pool{
|
||||||
New: func() interface{} {
|
New: func() any {
|
||||||
return &[]metric.AddOption{}
|
return &[]metric.AddOption{}
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
metricRecordOptionPool = &sync.Pool{
|
metricRecordOptionPool = &sync.Pool{
|
||||||
New: func() interface{} {
|
New: func() any {
|
||||||
return &[]metric.RecordOption{}
|
return &[]metric.RecordOption{}
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
|
|
||||||
func (s HTTPServer) RecordMetrics(ctx context.Context, md ServerMetricData) {
|
func (s HTTPServer) RecordMetrics(ctx context.Context, md ServerMetricData) {
|
||||||
if s.requestDurationHistogram != nil && s.requestBodySizeHistogram != nil && s.responseBodySizeHistogram != nil {
|
attributes := CurrentHTTPServer{}.MetricAttributes(md.ServerName, md.Req, md.StatusCode, md.AdditionalAttributes)
|
||||||
attributes := CurrentHTTPServer{}.MetricAttributes(md.ServerName, md.Req, md.StatusCode, md.AdditionalAttributes)
|
o := metric.WithAttributeSet(attribute.NewSet(attributes...))
|
||||||
o := metric.WithAttributeSet(attribute.NewSet(attributes...))
|
recordOpts := metricRecordOptionPool.Get().(*[]metric.RecordOption)
|
||||||
recordOpts := metricRecordOptionPool.Get().(*[]metric.RecordOption)
|
*recordOpts = append(*recordOpts, o)
|
||||||
*recordOpts = append(*recordOpts, o)
|
s.requestBodySizeHistogram.Inst().Record(ctx, md.RequestSize, *recordOpts...)
|
||||||
s.requestBodySizeHistogram.Record(ctx, md.RequestSize, *recordOpts...)
|
s.responseBodySizeHistogram.Inst().Record(ctx, md.ResponseSize, *recordOpts...)
|
||||||
s.responseBodySizeHistogram.Record(ctx, md.ResponseSize, *recordOpts...)
|
s.requestDurationHistogram.Inst().Record(ctx, md.ElapsedTime/1000.0, o)
|
||||||
s.requestDurationHistogram.Record(ctx, md.ElapsedTime/1000.0, o)
|
*recordOpts = (*recordOpts)[:0]
|
||||||
*recordOpts = (*recordOpts)[:0]
|
metricRecordOptionPool.Put(recordOpts)
|
||||||
metricRecordOptionPool.Put(recordOpts)
|
|
||||||
}
|
|
||||||
|
|
||||||
if s.duplicate && s.requestBytesCounter != nil && s.responseBytesCounter != nil && s.serverLatencyMeasure != nil {
|
|
||||||
attributes := OldHTTPServer{}.MetricAttributes(md.ServerName, md.Req, md.StatusCode, md.AdditionalAttributes)
|
|
||||||
o := metric.WithAttributeSet(attribute.NewSet(attributes...))
|
|
||||||
addOpts := metricAddOptionPool.Get().(*[]metric.AddOption)
|
|
||||||
*addOpts = append(*addOpts, o)
|
|
||||||
s.requestBytesCounter.Add(ctx, md.RequestSize, *addOpts...)
|
|
||||||
s.responseBytesCounter.Add(ctx, md.ResponseSize, *addOpts...)
|
|
||||||
s.serverLatencyMeasure.Record(ctx, md.ElapsedTime, o)
|
|
||||||
*addOpts = (*addOpts)[:0]
|
|
||||||
metricAddOptionPool.Put(addOpts)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// hasOptIn returns true if the comma-separated version string contains the
|
// hasOptIn returns true if the comma-separated version string contains the
|
||||||
|
|
@ -183,61 +147,55 @@ func hasOptIn(version, optIn string) bool {
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewHTTPServer(meter metric.Meter) HTTPServer {
|
func NewHTTPServer(meter metric.Meter) HTTPServer {
|
||||||
env := strings.ToLower(os.Getenv(OTelSemConvStabilityOptIn))
|
server := HTTPServer{}
|
||||||
duplicate := hasOptIn(env, "http/dup")
|
|
||||||
server := HTTPServer{
|
var err error
|
||||||
duplicate: duplicate,
|
server.requestBodySizeHistogram, err = httpconv.NewServerRequestBodySize(meter)
|
||||||
}
|
handleErr(err)
|
||||||
server.requestBodySizeHistogram, server.responseBodySizeHistogram, server.requestDurationHistogram = CurrentHTTPServer{}.createMeasures(meter)
|
|
||||||
if duplicate {
|
server.responseBodySizeHistogram, err = httpconv.NewServerResponseBodySize(meter)
|
||||||
server.requestBytesCounter, server.responseBytesCounter, server.serverLatencyMeasure = OldHTTPServer{}.createMeasures(meter)
|
handleErr(err)
|
||||||
}
|
|
||||||
|
server.requestDurationHistogram, err = httpconv.NewServerRequestDuration(
|
||||||
|
meter,
|
||||||
|
metric.WithExplicitBucketBoundaries(
|
||||||
|
0.005, 0.01, 0.025, 0.05, 0.075, 0.1,
|
||||||
|
0.25, 0.5, 0.75, 1, 2.5, 5, 7.5, 10,
|
||||||
|
),
|
||||||
|
)
|
||||||
|
handleErr(err)
|
||||||
return server
|
return server
|
||||||
}
|
}
|
||||||
|
|
||||||
type HTTPClient struct {
|
type HTTPClient struct {
|
||||||
duplicate bool
|
requestBodySize httpconv.ClientRequestBodySize
|
||||||
|
requestDuration httpconv.ClientRequestDuration
|
||||||
// old metrics
|
|
||||||
requestBytesCounter metric.Int64Counter
|
|
||||||
responseBytesCounter metric.Int64Counter
|
|
||||||
latencyMeasure metric.Float64Histogram
|
|
||||||
|
|
||||||
// new metrics
|
|
||||||
requestBodySize metric.Int64Histogram
|
|
||||||
requestDuration metric.Float64Histogram
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func NewHTTPClient(meter metric.Meter) HTTPClient {
|
func NewHTTPClient(meter metric.Meter) HTTPClient {
|
||||||
env := strings.ToLower(os.Getenv(OTelSemConvStabilityOptIn))
|
client := HTTPClient{}
|
||||||
duplicate := hasOptIn(env, "http/dup")
|
|
||||||
client := HTTPClient{
|
var err error
|
||||||
duplicate: duplicate,
|
client.requestBodySize, err = httpconv.NewClientRequestBodySize(meter)
|
||||||
}
|
handleErr(err)
|
||||||
client.requestBodySize, client.requestDuration = CurrentHTTPClient{}.createMeasures(meter)
|
|
||||||
if duplicate {
|
client.requestDuration, err = httpconv.NewClientRequestDuration(
|
||||||
client.requestBytesCounter, client.responseBytesCounter, client.latencyMeasure = OldHTTPClient{}.createMeasures(meter)
|
meter,
|
||||||
}
|
metric.WithExplicitBucketBoundaries(0.005, 0.01, 0.025, 0.05, 0.075, 0.1, 0.25, 0.5, 0.75, 1, 2.5, 5, 7.5, 10),
|
||||||
|
)
|
||||||
|
handleErr(err)
|
||||||
|
|
||||||
return client
|
return client
|
||||||
}
|
}
|
||||||
|
|
||||||
// RequestTraceAttrs returns attributes for an HTTP request made by a client.
|
// RequestTraceAttrs returns attributes for an HTTP request made by a client.
|
||||||
func (c HTTPClient) RequestTraceAttrs(req *http.Request) []attribute.KeyValue {
|
func (c HTTPClient) RequestTraceAttrs(req *http.Request) []attribute.KeyValue {
|
||||||
attrs := CurrentHTTPClient{}.RequestTraceAttrs(req)
|
return CurrentHTTPClient{}.RequestTraceAttrs(req)
|
||||||
if c.duplicate {
|
|
||||||
return OldHTTPClient{}.RequestTraceAttrs(req, attrs)
|
|
||||||
}
|
|
||||||
return attrs
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// ResponseTraceAttrs returns metric attributes for an HTTP request made by a client.
|
// ResponseTraceAttrs returns metric attributes for an HTTP request made by a client.
|
||||||
func (c HTTPClient) ResponseTraceAttrs(resp *http.Response) []attribute.KeyValue {
|
func (c HTTPClient) ResponseTraceAttrs(resp *http.Response) []attribute.KeyValue {
|
||||||
attrs := CurrentHTTPClient{}.ResponseTraceAttrs(resp)
|
return CurrentHTTPClient{}.ResponseTraceAttrs(resp)
|
||||||
if c.duplicate {
|
|
||||||
return OldHTTPClient{}.ResponseTraceAttrs(resp, attrs)
|
|
||||||
}
|
|
||||||
return attrs
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c HTTPClient) Status(code int) (codes.Code, string) {
|
func (c HTTPClient) Status(code int) (codes.Code, string) {
|
||||||
|
|
@ -277,47 +235,14 @@ func (c HTTPClient) MetricOptions(ma MetricAttributes) map[string]MetricOpts {
|
||||||
addOptions: set,
|
addOptions: set,
|
||||||
}
|
}
|
||||||
|
|
||||||
if c.duplicate {
|
|
||||||
attributes := OldHTTPClient{}.MetricAttributes(ma.Req, ma.StatusCode, ma.AdditionalAttributes)
|
|
||||||
set := metric.WithAttributeSet(attribute.NewSet(attributes...))
|
|
||||||
opts["old"] = MetricOpts{
|
|
||||||
measurement: set,
|
|
||||||
addOptions: set,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return opts
|
return opts
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s HTTPClient) RecordMetrics(ctx context.Context, md MetricData, opts map[string]MetricOpts) {
|
func (s HTTPClient) RecordMetrics(ctx context.Context, md MetricData, opts map[string]MetricOpts) {
|
||||||
if s.requestBodySize == nil || s.requestDuration == nil {
|
s.requestBodySize.Inst().Record(ctx, md.RequestSize, opts["new"].MeasurementOption())
|
||||||
// This will happen if an HTTPClient{} is used instead of NewHTTPClient().
|
s.requestDuration.Inst().Record(ctx, md.ElapsedTime/1000, opts["new"].MeasurementOption())
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
s.requestBodySize.Record(ctx, md.RequestSize, opts["new"].MeasurementOption())
|
|
||||||
s.requestDuration.Record(ctx, md.ElapsedTime/1000, opts["new"].MeasurementOption())
|
|
||||||
|
|
||||||
if s.duplicate {
|
|
||||||
s.requestBytesCounter.Add(ctx, md.RequestSize, opts["old"].AddOptions())
|
|
||||||
s.latencyMeasure.Record(ctx, md.ElapsedTime, opts["old"].MeasurementOption())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s HTTPClient) RecordResponseSize(ctx context.Context, responseData int64, opts map[string]MetricOpts) {
|
|
||||||
if s.responseBytesCounter == nil {
|
|
||||||
// This will happen if an HTTPClient{} is used instead of NewHTTPClient().
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
s.responseBytesCounter.Add(ctx, responseData, opts["old"].AddOptions())
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s HTTPClient) TraceAttributes(host string) []attribute.KeyValue {
|
func (s HTTPClient) TraceAttributes(host string) []attribute.KeyValue {
|
||||||
attrs := CurrentHTTPClient{}.TraceAttributes(host)
|
return CurrentHTTPClient{}.TraceAttributes(host)
|
||||||
if s.duplicate {
|
|
||||||
return OldHTTPClient{}.TraceAttributes(host, attrs)
|
|
||||||
}
|
|
||||||
|
|
||||||
return attrs
|
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -5,10 +5,11 @@ package semconv // import "go.opentelemetry.io/contrib/instrumentation/net/http/
|
||||||
|
|
||||||
// Generate semconv package:
|
// Generate semconv package:
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/bench_test.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=bench_test.go
|
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/bench_test.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=bench_test.go
|
||||||
|
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/common_test.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=common_test.go
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/env.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=env.go
|
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/env.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=env.go
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/env_test.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=env_test.go
|
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/env_test.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=env_test.go
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/httpconv.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=httpconv.go
|
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/httpconv.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=httpconv.go
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/httpconv_test.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=httpconv_test.go
|
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/httpconv_test.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=httpconv_test.go
|
||||||
|
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/httpconvtest_test.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=httpconvtest_test.go
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/util.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=util.go
|
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/util.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=util.go
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/util_test.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=util_test.go
|
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/util_test.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=util_test.go
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconv/v1.20.0.go.tmpl "--data={ \"pkg\": \"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp\" }" --out=v1.20.0.go
|
|
||||||
|
|
|
||||||
|
|
@ -17,9 +17,7 @@ import (
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
"go.opentelemetry.io/otel/attribute"
|
"go.opentelemetry.io/otel/attribute"
|
||||||
"go.opentelemetry.io/otel/metric"
|
semconvNew "go.opentelemetry.io/otel/semconv/v1.37.0"
|
||||||
"go.opentelemetry.io/otel/metric/noop"
|
|
||||||
semconvNew "go.opentelemetry.io/otel/semconv/v1.26.0"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
type RequestTraceAttrsOpts struct {
|
type RequestTraceAttrsOpts struct {
|
||||||
|
|
@ -196,7 +194,7 @@ func (n CurrentHTTPServer) method(method string) (attribute.KeyValue, attribute.
|
||||||
return semconvNew.HTTPRequestMethodGet, orig
|
return semconvNew.HTTPRequestMethodGet, orig
|
||||||
}
|
}
|
||||||
|
|
||||||
func (n CurrentHTTPServer) scheme(https bool) attribute.KeyValue { // nolint:revive
|
func (n CurrentHTTPServer) scheme(https bool) attribute.KeyValue { //nolint:revive // ignore linter
|
||||||
if https {
|
if https {
|
||||||
return semconvNew.URLScheme("https")
|
return semconvNew.URLScheme("https")
|
||||||
}
|
}
|
||||||
|
|
@ -247,36 +245,6 @@ func (n CurrentHTTPServer) Route(route string) attribute.KeyValue {
|
||||||
return semconvNew.HTTPRoute(route)
|
return semconvNew.HTTPRoute(route)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (n CurrentHTTPServer) createMeasures(meter metric.Meter) (metric.Int64Histogram, metric.Int64Histogram, metric.Float64Histogram) {
|
|
||||||
if meter == nil {
|
|
||||||
return noop.Int64Histogram{}, noop.Int64Histogram{}, noop.Float64Histogram{}
|
|
||||||
}
|
|
||||||
|
|
||||||
var err error
|
|
||||||
requestBodySizeHistogram, err := meter.Int64Histogram(
|
|
||||||
semconvNew.HTTPServerRequestBodySizeName,
|
|
||||||
metric.WithUnit(semconvNew.HTTPServerRequestBodySizeUnit),
|
|
||||||
metric.WithDescription(semconvNew.HTTPServerRequestBodySizeDescription),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
|
|
||||||
responseBodySizeHistogram, err := meter.Int64Histogram(
|
|
||||||
semconvNew.HTTPServerResponseBodySizeName,
|
|
||||||
metric.WithUnit(semconvNew.HTTPServerResponseBodySizeUnit),
|
|
||||||
metric.WithDescription(semconvNew.HTTPServerResponseBodySizeDescription),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
requestDurationHistogram, err := meter.Float64Histogram(
|
|
||||||
semconvNew.HTTPServerRequestDurationName,
|
|
||||||
metric.WithUnit(semconvNew.HTTPServerRequestDurationUnit),
|
|
||||||
metric.WithDescription(semconvNew.HTTPServerRequestDurationDescription),
|
|
||||||
metric.WithExplicitBucketBoundaries(0.005, 0.01, 0.025, 0.05, 0.075, 0.1, 0.25, 0.5, 0.75, 1, 2.5, 5, 7.5, 10),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
|
|
||||||
return requestBodySizeHistogram, responseBodySizeHistogram, requestDurationHistogram
|
|
||||||
}
|
|
||||||
|
|
||||||
func (n CurrentHTTPServer) MetricAttributes(server string, req *http.Request, statusCode int, additionalAttributes []attribute.KeyValue) []attribute.KeyValue {
|
func (n CurrentHTTPServer) MetricAttributes(server string, req *http.Request, statusCode int, additionalAttributes []attribute.KeyValue) []attribute.KeyValue {
|
||||||
num := len(additionalAttributes) + 3
|
num := len(additionalAttributes) + 3
|
||||||
var host string
|
var host string
|
||||||
|
|
@ -472,30 +440,6 @@ func (n CurrentHTTPClient) method(method string) (attribute.KeyValue, attribute.
|
||||||
return semconvNew.HTTPRequestMethodGet, orig
|
return semconvNew.HTTPRequestMethodGet, orig
|
||||||
}
|
}
|
||||||
|
|
||||||
func (n CurrentHTTPClient) createMeasures(meter metric.Meter) (metric.Int64Histogram, metric.Float64Histogram) {
|
|
||||||
if meter == nil {
|
|
||||||
return noop.Int64Histogram{}, noop.Float64Histogram{}
|
|
||||||
}
|
|
||||||
|
|
||||||
var err error
|
|
||||||
requestBodySize, err := meter.Int64Histogram(
|
|
||||||
semconvNew.HTTPClientRequestBodySizeName,
|
|
||||||
metric.WithUnit(semconvNew.HTTPClientRequestBodySizeUnit),
|
|
||||||
metric.WithDescription(semconvNew.HTTPClientRequestBodySizeDescription),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
|
|
||||||
requestDuration, err := meter.Float64Histogram(
|
|
||||||
semconvNew.HTTPClientRequestDurationName,
|
|
||||||
metric.WithUnit(semconvNew.HTTPClientRequestDurationUnit),
|
|
||||||
metric.WithDescription(semconvNew.HTTPClientRequestDurationDescription),
|
|
||||||
metric.WithExplicitBucketBoundaries(0.005, 0.01, 0.025, 0.05, 0.075, 0.1, 0.25, 0.5, 0.75, 1, 2.5, 5, 7.5, 10),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
|
|
||||||
return requestBodySize, requestDuration
|
|
||||||
}
|
|
||||||
|
|
||||||
func (n CurrentHTTPClient) MetricAttributes(req *http.Request, statusCode int, additionalAttributes []attribute.KeyValue) []attribute.KeyValue {
|
func (n CurrentHTTPClient) MetricAttributes(req *http.Request, statusCode int, additionalAttributes []attribute.KeyValue) []attribute.KeyValue {
|
||||||
num := len(additionalAttributes) + 2
|
num := len(additionalAttributes) + 2
|
||||||
var h string
|
var h string
|
||||||
|
|
|
||||||
|
|
@ -14,7 +14,7 @@ import (
|
||||||
|
|
||||||
"go.opentelemetry.io/otel"
|
"go.opentelemetry.io/otel"
|
||||||
"go.opentelemetry.io/otel/attribute"
|
"go.opentelemetry.io/otel/attribute"
|
||||||
semconvNew "go.opentelemetry.io/otel/semconv/v1.26.0"
|
semconvNew "go.opentelemetry.io/otel/semconv/v1.37.0"
|
||||||
)
|
)
|
||||||
|
|
||||||
// SplitHostPort splits a network address hostport of the form "host",
|
// SplitHostPort splits a network address hostport of the form "host",
|
||||||
|
|
@ -53,10 +53,10 @@ func SplitHostPort(hostport string) (host string, port int) {
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
return host, int(p) // nolint: gosec // Byte size checked 16 above.
|
return host, int(p) //nolint:gosec // Byte size checked 16 above.
|
||||||
}
|
}
|
||||||
|
|
||||||
func requiredHTTPPort(https bool, port int) int { // nolint:revive
|
func requiredHTTPPort(https bool, port int) int { //nolint:revive // ignore linter
|
||||||
if https {
|
if https {
|
||||||
if port > 0 && port != 443 {
|
if port > 0 && port != 443 {
|
||||||
return port
|
return port
|
||||||
|
|
|
||||||
|
|
@ -1,273 +0,0 @@
|
||||||
// Code generated by gotmpl. DO NOT MODIFY.
|
|
||||||
// source: internal/shared/semconv/v120.0.go.tmpl
|
|
||||||
|
|
||||||
// Copyright The OpenTelemetry Authors
|
|
||||||
// SPDX-License-Identifier: Apache-2.0
|
|
||||||
|
|
||||||
package semconv // import "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv"
|
|
||||||
|
|
||||||
import (
|
|
||||||
"errors"
|
|
||||||
"io"
|
|
||||||
"net/http"
|
|
||||||
"slices"
|
|
||||||
|
|
||||||
"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconvutil"
|
|
||||||
"go.opentelemetry.io/otel/attribute"
|
|
||||||
"go.opentelemetry.io/otel/metric"
|
|
||||||
"go.opentelemetry.io/otel/metric/noop"
|
|
||||||
semconv "go.opentelemetry.io/otel/semconv/v1.20.0"
|
|
||||||
)
|
|
||||||
|
|
||||||
type OldHTTPServer struct{}
|
|
||||||
|
|
||||||
// RequestTraceAttrs returns trace attributes for an HTTP request received by a
|
|
||||||
// server.
|
|
||||||
//
|
|
||||||
// The server must be the primary server name if it is known. For example this
|
|
||||||
// would be the ServerName directive
|
|
||||||
// (https://httpd.apache.org/docs/2.4/mod/core.html#servername) for an Apache
|
|
||||||
// server, and the server_name directive
|
|
||||||
// (http://nginx.org/en/docs/http/ngx_http_core_module.html#server_name) for an
|
|
||||||
// nginx server. More generically, the primary server name would be the host
|
|
||||||
// header value that matches the default virtual host of an HTTP server. It
|
|
||||||
// should include the host identifier and if a port is used to route to the
|
|
||||||
// server that port identifier should be included as an appropriate port
|
|
||||||
// suffix.
|
|
||||||
//
|
|
||||||
// If the primary server name is not known, server should be an empty string.
|
|
||||||
// The req Host will be used to determine the server instead.
|
|
||||||
func (o OldHTTPServer) RequestTraceAttrs(server string, req *http.Request, attrs []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
return semconvutil.HTTPServerRequest(server, req, semconvutil.HTTPServerRequestOptions{}, attrs)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (o OldHTTPServer) NetworkTransportAttr(network string) attribute.KeyValue {
|
|
||||||
return semconvutil.NetTransport(network)
|
|
||||||
}
|
|
||||||
|
|
||||||
// ResponseTraceAttrs returns trace attributes for telemetry from an HTTP response.
|
|
||||||
//
|
|
||||||
// If any of the fields in the ResponseTelemetry are not set the attribute will be omitted.
|
|
||||||
func (o OldHTTPServer) ResponseTraceAttrs(resp ResponseTelemetry, attributes []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
if resp.ReadBytes > 0 {
|
|
||||||
attributes = append(attributes, semconv.HTTPRequestContentLength(int(resp.ReadBytes)))
|
|
||||||
}
|
|
||||||
if resp.ReadError != nil && !errors.Is(resp.ReadError, io.EOF) {
|
|
||||||
// This is not in the semantic conventions, but is historically provided
|
|
||||||
attributes = append(attributes, attribute.String("http.read_error", resp.ReadError.Error()))
|
|
||||||
}
|
|
||||||
if resp.WriteBytes > 0 {
|
|
||||||
attributes = append(attributes, semconv.HTTPResponseContentLength(int(resp.WriteBytes)))
|
|
||||||
}
|
|
||||||
if resp.StatusCode > 0 {
|
|
||||||
attributes = append(attributes, semconv.HTTPStatusCode(resp.StatusCode))
|
|
||||||
}
|
|
||||||
if resp.WriteError != nil && !errors.Is(resp.WriteError, io.EOF) {
|
|
||||||
// This is not in the semantic conventions, but is historically provided
|
|
||||||
attributes = append(attributes, attribute.String("http.write_error", resp.WriteError.Error()))
|
|
||||||
}
|
|
||||||
|
|
||||||
return attributes
|
|
||||||
}
|
|
||||||
|
|
||||||
// Route returns the attribute for the route.
|
|
||||||
func (o OldHTTPServer) Route(route string) attribute.KeyValue {
|
|
||||||
return semconv.HTTPRoute(route)
|
|
||||||
}
|
|
||||||
|
|
||||||
// HTTPStatusCode returns the attribute for the HTTP status code.
|
|
||||||
// This is a temporary function needed by metrics. This will be removed when MetricsRequest is added.
|
|
||||||
func HTTPStatusCode(status int) attribute.KeyValue {
|
|
||||||
return semconv.HTTPStatusCode(status)
|
|
||||||
}
|
|
||||||
|
|
||||||
// Server HTTP metrics.
|
|
||||||
const (
|
|
||||||
serverRequestSize = "http.server.request.size" // Incoming request bytes total
|
|
||||||
serverResponseSize = "http.server.response.size" // Incoming response bytes total
|
|
||||||
serverDuration = "http.server.duration" // Incoming end to end duration, milliseconds
|
|
||||||
)
|
|
||||||
|
|
||||||
func (h OldHTTPServer) createMeasures(meter metric.Meter) (metric.Int64Counter, metric.Int64Counter, metric.Float64Histogram) {
|
|
||||||
if meter == nil {
|
|
||||||
return noop.Int64Counter{}, noop.Int64Counter{}, noop.Float64Histogram{}
|
|
||||||
}
|
|
||||||
var err error
|
|
||||||
requestBytesCounter, err := meter.Int64Counter(
|
|
||||||
serverRequestSize,
|
|
||||||
metric.WithUnit("By"),
|
|
||||||
metric.WithDescription("Measures the size of HTTP request messages."),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
|
|
||||||
responseBytesCounter, err := meter.Int64Counter(
|
|
||||||
serverResponseSize,
|
|
||||||
metric.WithUnit("By"),
|
|
||||||
metric.WithDescription("Measures the size of HTTP response messages."),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
|
|
||||||
serverLatencyMeasure, err := meter.Float64Histogram(
|
|
||||||
serverDuration,
|
|
||||||
metric.WithUnit("ms"),
|
|
||||||
metric.WithDescription("Measures the duration of inbound HTTP requests."),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
|
|
||||||
return requestBytesCounter, responseBytesCounter, serverLatencyMeasure
|
|
||||||
}
|
|
||||||
|
|
||||||
func (o OldHTTPServer) MetricAttributes(server string, req *http.Request, statusCode int, additionalAttributes []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
n := len(additionalAttributes) + 3
|
|
||||||
var host string
|
|
||||||
var p int
|
|
||||||
if server == "" {
|
|
||||||
host, p = SplitHostPort(req.Host)
|
|
||||||
} else {
|
|
||||||
// Prioritize the primary server name.
|
|
||||||
host, p = SplitHostPort(server)
|
|
||||||
if p < 0 {
|
|
||||||
_, p = SplitHostPort(req.Host)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
hostPort := requiredHTTPPort(req.TLS != nil, p)
|
|
||||||
if hostPort > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
protoName, protoVersion := netProtocol(req.Proto)
|
|
||||||
if protoName != "" {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
if protoVersion != "" {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
|
|
||||||
if statusCode > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
|
|
||||||
attributes := slices.Grow(additionalAttributes, n)
|
|
||||||
attributes = append(attributes,
|
|
||||||
semconv.HTTPMethod(standardizeHTTPMethod(req.Method)),
|
|
||||||
o.scheme(req.TLS != nil),
|
|
||||||
semconv.NetHostName(host))
|
|
||||||
|
|
||||||
if hostPort > 0 {
|
|
||||||
attributes = append(attributes, semconv.NetHostPort(hostPort))
|
|
||||||
}
|
|
||||||
if protoName != "" {
|
|
||||||
attributes = append(attributes, semconv.NetProtocolName(protoName))
|
|
||||||
}
|
|
||||||
if protoVersion != "" {
|
|
||||||
attributes = append(attributes, semconv.NetProtocolVersion(protoVersion))
|
|
||||||
}
|
|
||||||
|
|
||||||
if statusCode > 0 {
|
|
||||||
attributes = append(attributes, semconv.HTTPStatusCode(statusCode))
|
|
||||||
}
|
|
||||||
return attributes
|
|
||||||
}
|
|
||||||
|
|
||||||
func (o OldHTTPServer) scheme(https bool) attribute.KeyValue { // nolint:revive
|
|
||||||
if https {
|
|
||||||
return semconv.HTTPSchemeHTTPS
|
|
||||||
}
|
|
||||||
return semconv.HTTPSchemeHTTP
|
|
||||||
}
|
|
||||||
|
|
||||||
type OldHTTPClient struct{}
|
|
||||||
|
|
||||||
func (o OldHTTPClient) RequestTraceAttrs(req *http.Request, attrs []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
return semconvutil.HTTPClientRequest(req, attrs)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (o OldHTTPClient) ResponseTraceAttrs(resp *http.Response, attrs []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
return semconvutil.HTTPClientResponse(resp, attrs)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (o OldHTTPClient) MetricAttributes(req *http.Request, statusCode int, additionalAttributes []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
/* The following semantic conventions are returned if present:
|
|
||||||
http.method string
|
|
||||||
http.status_code int
|
|
||||||
net.peer.name string
|
|
||||||
net.peer.port int
|
|
||||||
*/
|
|
||||||
|
|
||||||
n := 2 // method, peer name.
|
|
||||||
var h string
|
|
||||||
if req.URL != nil {
|
|
||||||
h = req.URL.Host
|
|
||||||
}
|
|
||||||
var requestHost string
|
|
||||||
var requestPort int
|
|
||||||
for _, hostport := range []string{h, req.Header.Get("Host")} {
|
|
||||||
requestHost, requestPort = SplitHostPort(hostport)
|
|
||||||
if requestHost != "" || requestPort > 0 {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
port := requiredHTTPPort(req.URL != nil && req.URL.Scheme == "https", requestPort)
|
|
||||||
if port > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
|
|
||||||
if statusCode > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
|
|
||||||
attributes := slices.Grow(additionalAttributes, n)
|
|
||||||
attributes = append(attributes,
|
|
||||||
semconv.HTTPMethod(standardizeHTTPMethod(req.Method)),
|
|
||||||
semconv.NetPeerName(requestHost),
|
|
||||||
)
|
|
||||||
|
|
||||||
if port > 0 {
|
|
||||||
attributes = append(attributes, semconv.NetPeerPort(port))
|
|
||||||
}
|
|
||||||
|
|
||||||
if statusCode > 0 {
|
|
||||||
attributes = append(attributes, semconv.HTTPStatusCode(statusCode))
|
|
||||||
}
|
|
||||||
return attributes
|
|
||||||
}
|
|
||||||
|
|
||||||
// Client HTTP metrics.
|
|
||||||
const (
|
|
||||||
clientRequestSize = "http.client.request.size" // Incoming request bytes total
|
|
||||||
clientResponseSize = "http.client.response.size" // Incoming response bytes total
|
|
||||||
clientDuration = "http.client.duration" // Incoming end to end duration, milliseconds
|
|
||||||
)
|
|
||||||
|
|
||||||
func (o OldHTTPClient) createMeasures(meter metric.Meter) (metric.Int64Counter, metric.Int64Counter, metric.Float64Histogram) {
|
|
||||||
if meter == nil {
|
|
||||||
return noop.Int64Counter{}, noop.Int64Counter{}, noop.Float64Histogram{}
|
|
||||||
}
|
|
||||||
requestBytesCounter, err := meter.Int64Counter(
|
|
||||||
clientRequestSize,
|
|
||||||
metric.WithUnit("By"),
|
|
||||||
metric.WithDescription("Measures the size of HTTP request messages."),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
|
|
||||||
responseBytesCounter, err := meter.Int64Counter(
|
|
||||||
clientResponseSize,
|
|
||||||
metric.WithUnit("By"),
|
|
||||||
metric.WithDescription("Measures the size of HTTP response messages."),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
|
|
||||||
latencyMeasure, err := meter.Float64Histogram(
|
|
||||||
clientDuration,
|
|
||||||
metric.WithUnit("ms"),
|
|
||||||
metric.WithDescription("Measures the duration of outbound HTTP requests."),
|
|
||||||
)
|
|
||||||
handleErr(err)
|
|
||||||
|
|
||||||
return requestBytesCounter, responseBytesCounter, latencyMeasure
|
|
||||||
}
|
|
||||||
|
|
||||||
// TraceAttributes returns attributes for httptrace.
|
|
||||||
func (c OldHTTPClient) TraceAttributes(host string, attrs []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
return append(attrs, semconv.NetHostName(host))
|
|
||||||
}
|
|
||||||
|
|
@ -1,10 +0,0 @@
|
||||||
// Copyright The OpenTelemetry Authors
|
|
||||||
// SPDX-License-Identifier: Apache-2.0
|
|
||||||
|
|
||||||
package semconvutil // import "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconvutil"
|
|
||||||
|
|
||||||
// Generate semconvutil package:
|
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconvutil/httpconv_test.go.tmpl "--data={}" --out=httpconv_test.go
|
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconvutil/httpconv.go.tmpl "--data={}" --out=httpconv.go
|
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconvutil/netconv_test.go.tmpl "--data={}" --out=netconv_test.go
|
|
||||||
//go:generate gotmpl --body=../../../../../../internal/shared/semconvutil/netconv.go.tmpl "--data={}" --out=netconv.go
|
|
||||||
|
|
@ -1,594 +0,0 @@
|
||||||
// Code generated by gotmpl. DO NOT MODIFY.
|
|
||||||
// source: internal/shared/semconvutil/httpconv.go.tmpl
|
|
||||||
|
|
||||||
// Copyright The OpenTelemetry Authors
|
|
||||||
// SPDX-License-Identifier: Apache-2.0
|
|
||||||
|
|
||||||
// Package semconvutil provides OpenTelemetry semantic convention utilities.
|
|
||||||
package semconvutil // import "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconvutil"
|
|
||||||
|
|
||||||
import (
|
|
||||||
"fmt"
|
|
||||||
"net/http"
|
|
||||||
"slices"
|
|
||||||
"strings"
|
|
||||||
|
|
||||||
"go.opentelemetry.io/otel/attribute"
|
|
||||||
"go.opentelemetry.io/otel/codes"
|
|
||||||
semconv "go.opentelemetry.io/otel/semconv/v1.20.0"
|
|
||||||
)
|
|
||||||
|
|
||||||
type HTTPServerRequestOptions struct {
|
|
||||||
// If set, this is used as value for the "http.client_ip" attribute.
|
|
||||||
HTTPClientIP string
|
|
||||||
}
|
|
||||||
|
|
||||||
// HTTPClientResponse returns trace attributes for an HTTP response received by a
|
|
||||||
// client from a server. It will return the following attributes if the related
|
|
||||||
// values are defined in resp: "http.status.code",
|
|
||||||
// "http.response_content_length".
|
|
||||||
//
|
|
||||||
// This does not add all OpenTelemetry required attributes for an HTTP event,
|
|
||||||
// it assumes ClientRequest was used to create the span with a complete set of
|
|
||||||
// attributes. If a complete set of attributes can be generated using the
|
|
||||||
// request contained in resp. For example:
|
|
||||||
//
|
|
||||||
// HTTPClientResponse(resp, ClientRequest(resp.Request)))
|
|
||||||
func HTTPClientResponse(resp *http.Response, attrs []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
return hc.ClientResponse(resp, attrs)
|
|
||||||
}
|
|
||||||
|
|
||||||
// HTTPClientRequest returns trace attributes for an HTTP request made by a client.
|
|
||||||
// The following attributes are always returned: "http.url", "http.method",
|
|
||||||
// "net.peer.name". The following attributes are returned if the related values
|
|
||||||
// are defined in req: "net.peer.port", "user_agent.original",
|
|
||||||
// "http.request_content_length".
|
|
||||||
func HTTPClientRequest(req *http.Request, attrs []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
return hc.ClientRequest(req, attrs)
|
|
||||||
}
|
|
||||||
|
|
||||||
// HTTPClientRequestMetrics returns metric attributes for an HTTP request made by a client.
|
|
||||||
// The following attributes are always returned: "http.method", "net.peer.name".
|
|
||||||
// The following attributes are returned if the
|
|
||||||
// related values are defined in req: "net.peer.port".
|
|
||||||
func HTTPClientRequestMetrics(req *http.Request) []attribute.KeyValue {
|
|
||||||
return hc.ClientRequestMetrics(req)
|
|
||||||
}
|
|
||||||
|
|
||||||
// HTTPClientStatus returns a span status code and message for an HTTP status code
|
|
||||||
// value received by a client.
|
|
||||||
func HTTPClientStatus(code int) (codes.Code, string) {
|
|
||||||
return hc.ClientStatus(code)
|
|
||||||
}
|
|
||||||
|
|
||||||
// HTTPServerRequest returns trace attributes for an HTTP request received by a
|
|
||||||
// server.
|
|
||||||
//
|
|
||||||
// The server must be the primary server name if it is known. For example this
|
|
||||||
// would be the ServerName directive
|
|
||||||
// (https://httpd.apache.org/docs/2.4/mod/core.html#servername) for an Apache
|
|
||||||
// server, and the server_name directive
|
|
||||||
// (http://nginx.org/en/docs/http/ngx_http_core_module.html#server_name) for an
|
|
||||||
// nginx server. More generically, the primary server name would be the host
|
|
||||||
// header value that matches the default virtual host of an HTTP server. It
|
|
||||||
// should include the host identifier and if a port is used to route to the
|
|
||||||
// server that port identifier should be included as an appropriate port
|
|
||||||
// suffix.
|
|
||||||
//
|
|
||||||
// If the primary server name is not known, server should be an empty string.
|
|
||||||
// The req Host will be used to determine the server instead.
|
|
||||||
//
|
|
||||||
// The following attributes are always returned: "http.method", "http.scheme",
|
|
||||||
// "http.target", "net.host.name". The following attributes are returned if
|
|
||||||
// they related values are defined in req: "net.host.port", "net.sock.peer.addr",
|
|
||||||
// "net.sock.peer.port", "user_agent.original", "http.client_ip".
|
|
||||||
func HTTPServerRequest(server string, req *http.Request, opts HTTPServerRequestOptions, attrs []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
return hc.ServerRequest(server, req, opts, attrs)
|
|
||||||
}
|
|
||||||
|
|
||||||
// HTTPServerRequestMetrics returns metric attributes for an HTTP request received by a
|
|
||||||
// server.
|
|
||||||
//
|
|
||||||
// The server must be the primary server name if it is known. For example this
|
|
||||||
// would be the ServerName directive
|
|
||||||
// (https://httpd.apache.org/docs/2.4/mod/core.html#servername) for an Apache
|
|
||||||
// server, and the server_name directive
|
|
||||||
// (http://nginx.org/en/docs/http/ngx_http_core_module.html#server_name) for an
|
|
||||||
// nginx server. More generically, the primary server name would be the host
|
|
||||||
// header value that matches the default virtual host of an HTTP server. It
|
|
||||||
// should include the host identifier and if a port is used to route to the
|
|
||||||
// server that port identifier should be included as an appropriate port
|
|
||||||
// suffix.
|
|
||||||
//
|
|
||||||
// If the primary server name is not known, server should be an empty string.
|
|
||||||
// The req Host will be used to determine the server instead.
|
|
||||||
//
|
|
||||||
// The following attributes are always returned: "http.method", "http.scheme",
|
|
||||||
// "net.host.name". The following attributes are returned if they related
|
|
||||||
// values are defined in req: "net.host.port".
|
|
||||||
func HTTPServerRequestMetrics(server string, req *http.Request) []attribute.KeyValue {
|
|
||||||
return hc.ServerRequestMetrics(server, req)
|
|
||||||
}
|
|
||||||
|
|
||||||
// HTTPServerStatus returns a span status code and message for an HTTP status code
|
|
||||||
// value returned by a server. Status codes in the 400-499 range are not
|
|
||||||
// returned as errors.
|
|
||||||
func HTTPServerStatus(code int) (codes.Code, string) {
|
|
||||||
return hc.ServerStatus(code)
|
|
||||||
}
|
|
||||||
|
|
||||||
// httpConv are the HTTP semantic convention attributes defined for a version
|
|
||||||
// of the OpenTelemetry specification.
|
|
||||||
type httpConv struct {
|
|
||||||
NetConv *netConv
|
|
||||||
|
|
||||||
HTTPClientIPKey attribute.Key
|
|
||||||
HTTPMethodKey attribute.Key
|
|
||||||
HTTPRequestContentLengthKey attribute.Key
|
|
||||||
HTTPResponseContentLengthKey attribute.Key
|
|
||||||
HTTPRouteKey attribute.Key
|
|
||||||
HTTPSchemeHTTP attribute.KeyValue
|
|
||||||
HTTPSchemeHTTPS attribute.KeyValue
|
|
||||||
HTTPStatusCodeKey attribute.Key
|
|
||||||
HTTPTargetKey attribute.Key
|
|
||||||
HTTPURLKey attribute.Key
|
|
||||||
UserAgentOriginalKey attribute.Key
|
|
||||||
}
|
|
||||||
|
|
||||||
var hc = &httpConv{
|
|
||||||
NetConv: nc,
|
|
||||||
|
|
||||||
HTTPClientIPKey: semconv.HTTPClientIPKey,
|
|
||||||
HTTPMethodKey: semconv.HTTPMethodKey,
|
|
||||||
HTTPRequestContentLengthKey: semconv.HTTPRequestContentLengthKey,
|
|
||||||
HTTPResponseContentLengthKey: semconv.HTTPResponseContentLengthKey,
|
|
||||||
HTTPRouteKey: semconv.HTTPRouteKey,
|
|
||||||
HTTPSchemeHTTP: semconv.HTTPSchemeHTTP,
|
|
||||||
HTTPSchemeHTTPS: semconv.HTTPSchemeHTTPS,
|
|
||||||
HTTPStatusCodeKey: semconv.HTTPStatusCodeKey,
|
|
||||||
HTTPTargetKey: semconv.HTTPTargetKey,
|
|
||||||
HTTPURLKey: semconv.HTTPURLKey,
|
|
||||||
UserAgentOriginalKey: semconv.UserAgentOriginalKey,
|
|
||||||
}
|
|
||||||
|
|
||||||
// ClientResponse returns attributes for an HTTP response received by a client
|
|
||||||
// from a server. The following attributes are returned if the related values
|
|
||||||
// are defined in resp: "http.status.code", "http.response_content_length".
|
|
||||||
//
|
|
||||||
// This does not add all OpenTelemetry required attributes for an HTTP event,
|
|
||||||
// it assumes ClientRequest was used to create the span with a complete set of
|
|
||||||
// attributes. If a complete set of attributes can be generated using the
|
|
||||||
// request contained in resp. For example:
|
|
||||||
//
|
|
||||||
// ClientResponse(resp, ClientRequest(resp.Request))
|
|
||||||
func (c *httpConv) ClientResponse(resp *http.Response, attrs []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
/* The following semantic conventions are returned if present:
|
|
||||||
http.status_code int
|
|
||||||
http.response_content_length int
|
|
||||||
*/
|
|
||||||
var n int
|
|
||||||
if resp.StatusCode > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
if resp.ContentLength > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
if n == 0 {
|
|
||||||
return attrs
|
|
||||||
}
|
|
||||||
|
|
||||||
attrs = slices.Grow(attrs, n)
|
|
||||||
if resp.StatusCode > 0 {
|
|
||||||
attrs = append(attrs, c.HTTPStatusCodeKey.Int(resp.StatusCode))
|
|
||||||
}
|
|
||||||
if resp.ContentLength > 0 {
|
|
||||||
attrs = append(attrs, c.HTTPResponseContentLengthKey.Int(int(resp.ContentLength)))
|
|
||||||
}
|
|
||||||
return attrs
|
|
||||||
}
|
|
||||||
|
|
||||||
// ClientRequest returns attributes for an HTTP request made by a client. The
|
|
||||||
// following attributes are always returned: "http.url", "http.method",
|
|
||||||
// "net.peer.name". The following attributes are returned if the related values
|
|
||||||
// are defined in req: "net.peer.port", "user_agent.original",
|
|
||||||
// "http.request_content_length", "user_agent.original".
|
|
||||||
func (c *httpConv) ClientRequest(req *http.Request, attrs []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
/* The following semantic conventions are returned if present:
|
|
||||||
http.method string
|
|
||||||
user_agent.original string
|
|
||||||
http.url string
|
|
||||||
net.peer.name string
|
|
||||||
net.peer.port int
|
|
||||||
http.request_content_length int
|
|
||||||
*/
|
|
||||||
|
|
||||||
/* The following semantic conventions are not returned:
|
|
||||||
http.status_code This requires the response. See ClientResponse.
|
|
||||||
http.response_content_length This requires the response. See ClientResponse.
|
|
||||||
net.sock.family This requires the socket used.
|
|
||||||
net.sock.peer.addr This requires the socket used.
|
|
||||||
net.sock.peer.name This requires the socket used.
|
|
||||||
net.sock.peer.port This requires the socket used.
|
|
||||||
http.resend_count This is something outside of a single request.
|
|
||||||
net.protocol.name The value is the Request is ignored, and the go client will always use "http".
|
|
||||||
net.protocol.version The value in the Request is ignored, and the go client will always use 1.1 or 2.0.
|
|
||||||
*/
|
|
||||||
n := 3 // URL, peer name, proto, and method.
|
|
||||||
var h string
|
|
||||||
if req.URL != nil {
|
|
||||||
h = req.URL.Host
|
|
||||||
}
|
|
||||||
peer, p := firstHostPort(h, req.Header.Get("Host"))
|
|
||||||
port := requiredHTTPPort(req.URL != nil && req.URL.Scheme == "https", p)
|
|
||||||
if port > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
useragent := req.UserAgent()
|
|
||||||
if useragent != "" {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
if req.ContentLength > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
|
|
||||||
attrs = slices.Grow(attrs, n)
|
|
||||||
attrs = append(attrs, c.method(req.Method))
|
|
||||||
|
|
||||||
var u string
|
|
||||||
if req.URL != nil {
|
|
||||||
// Remove any username/password info that may be in the URL.
|
|
||||||
userinfo := req.URL.User
|
|
||||||
req.URL.User = nil
|
|
||||||
u = req.URL.String()
|
|
||||||
// Restore any username/password info that was removed.
|
|
||||||
req.URL.User = userinfo
|
|
||||||
}
|
|
||||||
attrs = append(attrs, c.HTTPURLKey.String(u))
|
|
||||||
|
|
||||||
attrs = append(attrs, c.NetConv.PeerName(peer))
|
|
||||||
if port > 0 {
|
|
||||||
attrs = append(attrs, c.NetConv.PeerPort(port))
|
|
||||||
}
|
|
||||||
|
|
||||||
if useragent != "" {
|
|
||||||
attrs = append(attrs, c.UserAgentOriginalKey.String(useragent))
|
|
||||||
}
|
|
||||||
|
|
||||||
if l := req.ContentLength; l > 0 {
|
|
||||||
attrs = append(attrs, c.HTTPRequestContentLengthKey.Int64(l))
|
|
||||||
}
|
|
||||||
|
|
||||||
return attrs
|
|
||||||
}
|
|
||||||
|
|
||||||
// ClientRequestMetrics returns metric attributes for an HTTP request made by a client. The
|
|
||||||
// following attributes are always returned: "http.method", "net.peer.name".
|
|
||||||
// The following attributes are returned if the related values
|
|
||||||
// are defined in req: "net.peer.port".
|
|
||||||
func (c *httpConv) ClientRequestMetrics(req *http.Request) []attribute.KeyValue {
|
|
||||||
/* The following semantic conventions are returned if present:
|
|
||||||
http.method string
|
|
||||||
net.peer.name string
|
|
||||||
net.peer.port int
|
|
||||||
*/
|
|
||||||
|
|
||||||
n := 2 // method, peer name.
|
|
||||||
var h string
|
|
||||||
if req.URL != nil {
|
|
||||||
h = req.URL.Host
|
|
||||||
}
|
|
||||||
peer, p := firstHostPort(h, req.Header.Get("Host"))
|
|
||||||
port := requiredHTTPPort(req.URL != nil && req.URL.Scheme == "https", p)
|
|
||||||
if port > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
|
|
||||||
attrs := make([]attribute.KeyValue, 0, n)
|
|
||||||
attrs = append(attrs, c.method(req.Method), c.NetConv.PeerName(peer))
|
|
||||||
|
|
||||||
if port > 0 {
|
|
||||||
attrs = append(attrs, c.NetConv.PeerPort(port))
|
|
||||||
}
|
|
||||||
|
|
||||||
return attrs
|
|
||||||
}
|
|
||||||
|
|
||||||
// ServerRequest returns attributes for an HTTP request received by a server.
|
|
||||||
//
|
|
||||||
// The server must be the primary server name if it is known. For example this
|
|
||||||
// would be the ServerName directive
|
|
||||||
// (https://httpd.apache.org/docs/2.4/mod/core.html#servername) for an Apache
|
|
||||||
// server, and the server_name directive
|
|
||||||
// (http://nginx.org/en/docs/http/ngx_http_core_module.html#server_name) for an
|
|
||||||
// nginx server. More generically, the primary server name would be the host
|
|
||||||
// header value that matches the default virtual host of an HTTP server. It
|
|
||||||
// should include the host identifier and if a port is used to route to the
|
|
||||||
// server that port identifier should be included as an appropriate port
|
|
||||||
// suffix.
|
|
||||||
//
|
|
||||||
// If the primary server name is not known, server should be an empty string.
|
|
||||||
// The req Host will be used to determine the server instead.
|
|
||||||
//
|
|
||||||
// The following attributes are always returned: "http.method", "http.scheme",
|
|
||||||
// "http.target", "net.host.name". The following attributes are returned if they
|
|
||||||
// related values are defined in req: "net.host.port", "net.sock.peer.addr",
|
|
||||||
// "net.sock.peer.port", "user_agent.original", "http.client_ip",
|
|
||||||
// "net.protocol.name", "net.protocol.version".
|
|
||||||
func (c *httpConv) ServerRequest(server string, req *http.Request, opts HTTPServerRequestOptions, attrs []attribute.KeyValue) []attribute.KeyValue {
|
|
||||||
/* The following semantic conventions are returned if present:
|
|
||||||
http.method string
|
|
||||||
http.scheme string
|
|
||||||
net.host.name string
|
|
||||||
net.host.port int
|
|
||||||
net.sock.peer.addr string
|
|
||||||
net.sock.peer.port int
|
|
||||||
user_agent.original string
|
|
||||||
http.client_ip string
|
|
||||||
net.protocol.name string Note: not set if the value is "http".
|
|
||||||
net.protocol.version string
|
|
||||||
http.target string Note: doesn't include the query parameter.
|
|
||||||
*/
|
|
||||||
|
|
||||||
/* The following semantic conventions are not returned:
|
|
||||||
http.status_code This requires the response.
|
|
||||||
http.request_content_length This requires the len() of body, which can mutate it.
|
|
||||||
http.response_content_length This requires the response.
|
|
||||||
http.route This is not available.
|
|
||||||
net.sock.peer.name This would require a DNS lookup.
|
|
||||||
net.sock.host.addr The request doesn't have access to the underlying socket.
|
|
||||||
net.sock.host.port The request doesn't have access to the underlying socket.
|
|
||||||
|
|
||||||
*/
|
|
||||||
n := 4 // Method, scheme, proto, and host name.
|
|
||||||
var host string
|
|
||||||
var p int
|
|
||||||
if server == "" {
|
|
||||||
host, p = splitHostPort(req.Host)
|
|
||||||
} else {
|
|
||||||
// Prioritize the primary server name.
|
|
||||||
host, p = splitHostPort(server)
|
|
||||||
if p < 0 {
|
|
||||||
_, p = splitHostPort(req.Host)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
hostPort := requiredHTTPPort(req.TLS != nil, p)
|
|
||||||
if hostPort > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
peer, peerPort := splitHostPort(req.RemoteAddr)
|
|
||||||
if peer != "" {
|
|
||||||
n++
|
|
||||||
if peerPort > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
}
|
|
||||||
useragent := req.UserAgent()
|
|
||||||
if useragent != "" {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
|
|
||||||
// For client IP, use, in order:
|
|
||||||
// 1. The value passed in the options
|
|
||||||
// 2. The value in the X-Forwarded-For header
|
|
||||||
// 3. The peer address
|
|
||||||
clientIP := opts.HTTPClientIP
|
|
||||||
if clientIP == "" {
|
|
||||||
clientIP = serverClientIP(req.Header.Get("X-Forwarded-For"))
|
|
||||||
if clientIP == "" {
|
|
||||||
clientIP = peer
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if clientIP != "" {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
|
|
||||||
var target string
|
|
||||||
if req.URL != nil {
|
|
||||||
target = req.URL.Path
|
|
||||||
if target != "" {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
}
|
|
||||||
protoName, protoVersion := netProtocol(req.Proto)
|
|
||||||
if protoName != "" && protoName != "http" {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
if protoVersion != "" {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
|
|
||||||
attrs = slices.Grow(attrs, n)
|
|
||||||
|
|
||||||
attrs = append(attrs, c.method(req.Method))
|
|
||||||
attrs = append(attrs, c.scheme(req.TLS != nil))
|
|
||||||
attrs = append(attrs, c.NetConv.HostName(host))
|
|
||||||
|
|
||||||
if hostPort > 0 {
|
|
||||||
attrs = append(attrs, c.NetConv.HostPort(hostPort))
|
|
||||||
}
|
|
||||||
|
|
||||||
if peer != "" {
|
|
||||||
// The Go HTTP server sets RemoteAddr to "IP:port", this will not be a
|
|
||||||
// file-path that would be interpreted with a sock family.
|
|
||||||
attrs = append(attrs, c.NetConv.SockPeerAddr(peer))
|
|
||||||
if peerPort > 0 {
|
|
||||||
attrs = append(attrs, c.NetConv.SockPeerPort(peerPort))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if useragent != "" {
|
|
||||||
attrs = append(attrs, c.UserAgentOriginalKey.String(useragent))
|
|
||||||
}
|
|
||||||
|
|
||||||
if clientIP != "" {
|
|
||||||
attrs = append(attrs, c.HTTPClientIPKey.String(clientIP))
|
|
||||||
}
|
|
||||||
|
|
||||||
if target != "" {
|
|
||||||
attrs = append(attrs, c.HTTPTargetKey.String(target))
|
|
||||||
}
|
|
||||||
|
|
||||||
if protoName != "" && protoName != "http" {
|
|
||||||
attrs = append(attrs, c.NetConv.NetProtocolName.String(protoName))
|
|
||||||
}
|
|
||||||
if protoVersion != "" {
|
|
||||||
attrs = append(attrs, c.NetConv.NetProtocolVersion.String(protoVersion))
|
|
||||||
}
|
|
||||||
|
|
||||||
return attrs
|
|
||||||
}
|
|
||||||
|
|
||||||
// ServerRequestMetrics returns metric attributes for an HTTP request received
|
|
||||||
// by a server.
|
|
||||||
//
|
|
||||||
// The server must be the primary server name if it is known. For example this
|
|
||||||
// would be the ServerName directive
|
|
||||||
// (https://httpd.apache.org/docs/2.4/mod/core.html#servername) for an Apache
|
|
||||||
// server, and the server_name directive
|
|
||||||
// (http://nginx.org/en/docs/http/ngx_http_core_module.html#server_name) for an
|
|
||||||
// nginx server. More generically, the primary server name would be the host
|
|
||||||
// header value that matches the default virtual host of an HTTP server. It
|
|
||||||
// should include the host identifier and if a port is used to route to the
|
|
||||||
// server that port identifier should be included as an appropriate port
|
|
||||||
// suffix.
|
|
||||||
//
|
|
||||||
// If the primary server name is not known, server should be an empty string.
|
|
||||||
// The req Host will be used to determine the server instead.
|
|
||||||
//
|
|
||||||
// The following attributes are always returned: "http.method", "http.scheme",
|
|
||||||
// "net.host.name". The following attributes are returned if they related
|
|
||||||
// values are defined in req: "net.host.port".
|
|
||||||
func (c *httpConv) ServerRequestMetrics(server string, req *http.Request) []attribute.KeyValue {
|
|
||||||
/* The following semantic conventions are returned if present:
|
|
||||||
http.scheme string
|
|
||||||
http.route string
|
|
||||||
http.method string
|
|
||||||
http.status_code int
|
|
||||||
net.host.name string
|
|
||||||
net.host.port int
|
|
||||||
net.protocol.name string Note: not set if the value is "http".
|
|
||||||
net.protocol.version string
|
|
||||||
*/
|
|
||||||
|
|
||||||
n := 3 // Method, scheme, and host name.
|
|
||||||
var host string
|
|
||||||
var p int
|
|
||||||
if server == "" {
|
|
||||||
host, p = splitHostPort(req.Host)
|
|
||||||
} else {
|
|
||||||
// Prioritize the primary server name.
|
|
||||||
host, p = splitHostPort(server)
|
|
||||||
if p < 0 {
|
|
||||||
_, p = splitHostPort(req.Host)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
hostPort := requiredHTTPPort(req.TLS != nil, p)
|
|
||||||
if hostPort > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
protoName, protoVersion := netProtocol(req.Proto)
|
|
||||||
if protoName != "" {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
if protoVersion != "" {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
|
|
||||||
attrs := make([]attribute.KeyValue, 0, n)
|
|
||||||
|
|
||||||
attrs = append(attrs, c.methodMetric(req.Method))
|
|
||||||
attrs = append(attrs, c.scheme(req.TLS != nil))
|
|
||||||
attrs = append(attrs, c.NetConv.HostName(host))
|
|
||||||
|
|
||||||
if hostPort > 0 {
|
|
||||||
attrs = append(attrs, c.NetConv.HostPort(hostPort))
|
|
||||||
}
|
|
||||||
if protoName != "" {
|
|
||||||
attrs = append(attrs, c.NetConv.NetProtocolName.String(protoName))
|
|
||||||
}
|
|
||||||
if protoVersion != "" {
|
|
||||||
attrs = append(attrs, c.NetConv.NetProtocolVersion.String(protoVersion))
|
|
||||||
}
|
|
||||||
|
|
||||||
return attrs
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *httpConv) method(method string) attribute.KeyValue {
|
|
||||||
if method == "" {
|
|
||||||
return c.HTTPMethodKey.String(http.MethodGet)
|
|
||||||
}
|
|
||||||
return c.HTTPMethodKey.String(method)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *httpConv) methodMetric(method string) attribute.KeyValue {
|
|
||||||
method = strings.ToUpper(method)
|
|
||||||
switch method {
|
|
||||||
case http.MethodConnect, http.MethodDelete, http.MethodGet, http.MethodHead, http.MethodOptions, http.MethodPatch, http.MethodPost, http.MethodPut, http.MethodTrace:
|
|
||||||
default:
|
|
||||||
method = "_OTHER"
|
|
||||||
}
|
|
||||||
return c.HTTPMethodKey.String(method)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *httpConv) scheme(https bool) attribute.KeyValue { // nolint:revive
|
|
||||||
if https {
|
|
||||||
return c.HTTPSchemeHTTPS
|
|
||||||
}
|
|
||||||
return c.HTTPSchemeHTTP
|
|
||||||
}
|
|
||||||
|
|
||||||
func serverClientIP(xForwardedFor string) string {
|
|
||||||
if idx := strings.Index(xForwardedFor, ","); idx >= 0 {
|
|
||||||
xForwardedFor = xForwardedFor[:idx]
|
|
||||||
}
|
|
||||||
return xForwardedFor
|
|
||||||
}
|
|
||||||
|
|
||||||
func requiredHTTPPort(https bool, port int) int { // nolint:revive
|
|
||||||
if https {
|
|
||||||
if port > 0 && port != 443 {
|
|
||||||
return port
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
if port > 0 && port != 80 {
|
|
||||||
return port
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return -1
|
|
||||||
}
|
|
||||||
|
|
||||||
// Return the request host and port from the first non-empty source.
|
|
||||||
func firstHostPort(source ...string) (host string, port int) {
|
|
||||||
for _, hostport := range source {
|
|
||||||
host, port = splitHostPort(hostport)
|
|
||||||
if host != "" || port > 0 {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
// ClientStatus returns a span status code and message for an HTTP status code
|
|
||||||
// value received by a client.
|
|
||||||
func (c *httpConv) ClientStatus(code int) (codes.Code, string) {
|
|
||||||
if code < 100 || code >= 600 {
|
|
||||||
return codes.Error, fmt.Sprintf("Invalid HTTP status code %d", code)
|
|
||||||
}
|
|
||||||
if code >= 400 {
|
|
||||||
return codes.Error, ""
|
|
||||||
}
|
|
||||||
return codes.Unset, ""
|
|
||||||
}
|
|
||||||
|
|
||||||
// ServerStatus returns a span status code and message for an HTTP status code
|
|
||||||
// value returned by a server. Status codes in the 400-499 range are not
|
|
||||||
// returned as errors.
|
|
||||||
func (c *httpConv) ServerStatus(code int) (codes.Code, string) {
|
|
||||||
if code < 100 || code >= 600 {
|
|
||||||
return codes.Error, fmt.Sprintf("Invalid HTTP status code %d", code)
|
|
||||||
}
|
|
||||||
if code >= 500 {
|
|
||||||
return codes.Error, ""
|
|
||||||
}
|
|
||||||
return codes.Unset, ""
|
|
||||||
}
|
|
||||||
|
|
@ -1,214 +0,0 @@
|
||||||
// Code generated by gotmpl. DO NOT MODIFY.
|
|
||||||
// source: internal/shared/semconvutil/netconv.go.tmpl
|
|
||||||
|
|
||||||
// Copyright The OpenTelemetry Authors
|
|
||||||
// SPDX-License-Identifier: Apache-2.0
|
|
||||||
|
|
||||||
package semconvutil // import "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconvutil"
|
|
||||||
|
|
||||||
import (
|
|
||||||
"net"
|
|
||||||
"strconv"
|
|
||||||
"strings"
|
|
||||||
|
|
||||||
"go.opentelemetry.io/otel/attribute"
|
|
||||||
semconv "go.opentelemetry.io/otel/semconv/v1.20.0"
|
|
||||||
)
|
|
||||||
|
|
||||||
// NetTransport returns a trace attribute describing the transport protocol of the
|
|
||||||
// passed network. See the net.Dial for information about acceptable network
|
|
||||||
// values.
|
|
||||||
func NetTransport(network string) attribute.KeyValue {
|
|
||||||
return nc.Transport(network)
|
|
||||||
}
|
|
||||||
|
|
||||||
// netConv are the network semantic convention attributes defined for a version
|
|
||||||
// of the OpenTelemetry specification.
|
|
||||||
type netConv struct {
|
|
||||||
NetHostNameKey attribute.Key
|
|
||||||
NetHostPortKey attribute.Key
|
|
||||||
NetPeerNameKey attribute.Key
|
|
||||||
NetPeerPortKey attribute.Key
|
|
||||||
NetProtocolName attribute.Key
|
|
||||||
NetProtocolVersion attribute.Key
|
|
||||||
NetSockFamilyKey attribute.Key
|
|
||||||
NetSockPeerAddrKey attribute.Key
|
|
||||||
NetSockPeerPortKey attribute.Key
|
|
||||||
NetSockHostAddrKey attribute.Key
|
|
||||||
NetSockHostPortKey attribute.Key
|
|
||||||
NetTransportOther attribute.KeyValue
|
|
||||||
NetTransportTCP attribute.KeyValue
|
|
||||||
NetTransportUDP attribute.KeyValue
|
|
||||||
NetTransportInProc attribute.KeyValue
|
|
||||||
}
|
|
||||||
|
|
||||||
var nc = &netConv{
|
|
||||||
NetHostNameKey: semconv.NetHostNameKey,
|
|
||||||
NetHostPortKey: semconv.NetHostPortKey,
|
|
||||||
NetPeerNameKey: semconv.NetPeerNameKey,
|
|
||||||
NetPeerPortKey: semconv.NetPeerPortKey,
|
|
||||||
NetProtocolName: semconv.NetProtocolNameKey,
|
|
||||||
NetProtocolVersion: semconv.NetProtocolVersionKey,
|
|
||||||
NetSockFamilyKey: semconv.NetSockFamilyKey,
|
|
||||||
NetSockPeerAddrKey: semconv.NetSockPeerAddrKey,
|
|
||||||
NetSockPeerPortKey: semconv.NetSockPeerPortKey,
|
|
||||||
NetSockHostAddrKey: semconv.NetSockHostAddrKey,
|
|
||||||
NetSockHostPortKey: semconv.NetSockHostPortKey,
|
|
||||||
NetTransportOther: semconv.NetTransportOther,
|
|
||||||
NetTransportTCP: semconv.NetTransportTCP,
|
|
||||||
NetTransportUDP: semconv.NetTransportUDP,
|
|
||||||
NetTransportInProc: semconv.NetTransportInProc,
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *netConv) Transport(network string) attribute.KeyValue {
|
|
||||||
switch network {
|
|
||||||
case "tcp", "tcp4", "tcp6":
|
|
||||||
return c.NetTransportTCP
|
|
||||||
case "udp", "udp4", "udp6":
|
|
||||||
return c.NetTransportUDP
|
|
||||||
case "unix", "unixgram", "unixpacket":
|
|
||||||
return c.NetTransportInProc
|
|
||||||
default:
|
|
||||||
// "ip:*", "ip4:*", and "ip6:*" all are considered other.
|
|
||||||
return c.NetTransportOther
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Host returns attributes for a network host address.
|
|
||||||
func (c *netConv) Host(address string) []attribute.KeyValue {
|
|
||||||
h, p := splitHostPort(address)
|
|
||||||
var n int
|
|
||||||
if h != "" {
|
|
||||||
n++
|
|
||||||
if p > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if n == 0 {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
attrs := make([]attribute.KeyValue, 0, n)
|
|
||||||
attrs = append(attrs, c.HostName(h))
|
|
||||||
if p > 0 {
|
|
||||||
attrs = append(attrs, c.HostPort(p))
|
|
||||||
}
|
|
||||||
return attrs
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *netConv) HostName(name string) attribute.KeyValue {
|
|
||||||
return c.NetHostNameKey.String(name)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *netConv) HostPort(port int) attribute.KeyValue {
|
|
||||||
return c.NetHostPortKey.Int(port)
|
|
||||||
}
|
|
||||||
|
|
||||||
func family(network, address string) string {
|
|
||||||
switch network {
|
|
||||||
case "unix", "unixgram", "unixpacket":
|
|
||||||
return "unix"
|
|
||||||
default:
|
|
||||||
if ip := net.ParseIP(address); ip != nil {
|
|
||||||
if ip.To4() == nil {
|
|
||||||
return "inet6"
|
|
||||||
}
|
|
||||||
return "inet"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return ""
|
|
||||||
}
|
|
||||||
|
|
||||||
// Peer returns attributes for a network peer address.
|
|
||||||
func (c *netConv) Peer(address string) []attribute.KeyValue {
|
|
||||||
h, p := splitHostPort(address)
|
|
||||||
var n int
|
|
||||||
if h != "" {
|
|
||||||
n++
|
|
||||||
if p > 0 {
|
|
||||||
n++
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if n == 0 {
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
attrs := make([]attribute.KeyValue, 0, n)
|
|
||||||
attrs = append(attrs, c.PeerName(h))
|
|
||||||
if p > 0 {
|
|
||||||
attrs = append(attrs, c.PeerPort(p))
|
|
||||||
}
|
|
||||||
return attrs
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *netConv) PeerName(name string) attribute.KeyValue {
|
|
||||||
return c.NetPeerNameKey.String(name)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *netConv) PeerPort(port int) attribute.KeyValue {
|
|
||||||
return c.NetPeerPortKey.Int(port)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *netConv) SockPeerAddr(addr string) attribute.KeyValue {
|
|
||||||
return c.NetSockPeerAddrKey.String(addr)
|
|
||||||
}
|
|
||||||
|
|
||||||
func (c *netConv) SockPeerPort(port int) attribute.KeyValue {
|
|
||||||
return c.NetSockPeerPortKey.Int(port)
|
|
||||||
}
|
|
||||||
|
|
||||||
// splitHostPort splits a network address hostport of the form "host",
|
|
||||||
// "host%zone", "[host]", "[host%zone], "host:port", "host%zone:port",
|
|
||||||
// "[host]:port", "[host%zone]:port", or ":port" into host or host%zone and
|
|
||||||
// port.
|
|
||||||
//
|
|
||||||
// An empty host is returned if it is not provided or unparsable. A negative
|
|
||||||
// port is returned if it is not provided or unparsable.
|
|
||||||
func splitHostPort(hostport string) (host string, port int) {
|
|
||||||
port = -1
|
|
||||||
|
|
||||||
if strings.HasPrefix(hostport, "[") {
|
|
||||||
addrEnd := strings.LastIndex(hostport, "]")
|
|
||||||
if addrEnd < 0 {
|
|
||||||
// Invalid hostport.
|
|
||||||
return
|
|
||||||
}
|
|
||||||
if i := strings.LastIndex(hostport[addrEnd:], ":"); i < 0 {
|
|
||||||
host = hostport[1:addrEnd]
|
|
||||||
return
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
if i := strings.LastIndex(hostport, ":"); i < 0 {
|
|
||||||
host = hostport
|
|
||||||
return
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
host, pStr, err := net.SplitHostPort(hostport)
|
|
||||||
if err != nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
p, err := strconv.ParseUint(pStr, 10, 16)
|
|
||||||
if err != nil {
|
|
||||||
return
|
|
||||||
}
|
|
||||||
return host, int(p) // nolint: gosec // Bitsize checked to be 16 above.
|
|
||||||
}
|
|
||||||
|
|
||||||
func netProtocol(proto string) (name string, version string) {
|
|
||||||
name, version, _ = strings.Cut(proto, "/")
|
|
||||||
switch name {
|
|
||||||
case "HTTP":
|
|
||||||
name = "http"
|
|
||||||
case "QUIC":
|
|
||||||
name = "quic"
|
|
||||||
case "SPDY":
|
|
||||||
name = "spdy"
|
|
||||||
default:
|
|
||||||
name = strings.ToLower(name)
|
|
||||||
}
|
|
||||||
return name, version
|
|
||||||
}
|
|
||||||
60
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/transport.go
generated
vendored
60
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/transport.go
generated
vendored
|
|
@ -11,14 +11,14 @@ import (
|
||||||
"sync/atomic"
|
"sync/atomic"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/request"
|
|
||||||
"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv"
|
|
||||||
"go.opentelemetry.io/otel"
|
"go.opentelemetry.io/otel"
|
||||||
"go.opentelemetry.io/otel/attribute"
|
"go.opentelemetry.io/otel/attribute"
|
||||||
"go.opentelemetry.io/otel/codes"
|
"go.opentelemetry.io/otel/codes"
|
||||||
"go.opentelemetry.io/otel/propagation"
|
"go.opentelemetry.io/otel/propagation"
|
||||||
|
|
||||||
"go.opentelemetry.io/otel/trace"
|
"go.opentelemetry.io/otel/trace"
|
||||||
|
|
||||||
|
"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/request"
|
||||||
|
"go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Transport implements the http.RoundTripper interface and wraps
|
// Transport implements the http.RoundTripper interface and wraps
|
||||||
|
|
@ -129,6 +129,37 @@ func (t *Transport) RoundTrip(r *http.Request) (*http.Response, error) {
|
||||||
t.propagators.Inject(ctx, propagation.HeaderCarrier(r.Header))
|
t.propagators.Inject(ctx, propagation.HeaderCarrier(r.Header))
|
||||||
|
|
||||||
res, err := t.rt.RoundTrip(r)
|
res, err := t.rt.RoundTrip(r)
|
||||||
|
|
||||||
|
// Defer metrics recording function to record the metrics on error or no error.
|
||||||
|
defer func() {
|
||||||
|
metricAttributes := semconv.MetricAttributes{
|
||||||
|
Req: r,
|
||||||
|
AdditionalAttributes: append(labeler.Get(), t.metricAttributesFromRequest(r)...),
|
||||||
|
}
|
||||||
|
|
||||||
|
if err == nil {
|
||||||
|
metricAttributes.StatusCode = res.StatusCode
|
||||||
|
}
|
||||||
|
|
||||||
|
metricOpts := t.semconv.MetricOptions(metricAttributes)
|
||||||
|
|
||||||
|
metricData := semconv.MetricData{
|
||||||
|
RequestSize: bw.BytesRead(),
|
||||||
|
}
|
||||||
|
|
||||||
|
if err == nil {
|
||||||
|
readRecordFunc := func(int64) {}
|
||||||
|
res.Body = newWrappedBody(span, readRecordFunc, res.Body)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Use floating point division here for higher precision (instead of Millisecond method).
|
||||||
|
elapsedTime := float64(time.Since(requestStartTime)) / float64(time.Millisecond)
|
||||||
|
|
||||||
|
metricData.ElapsedTime = elapsedTime
|
||||||
|
|
||||||
|
t.semconv.RecordMetrics(ctx, metricData, metricOpts)
|
||||||
|
}()
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
// set error type attribute if the error is part of the predefined
|
// set error type attribute if the error is part of the predefined
|
||||||
// error types.
|
// error types.
|
||||||
|
|
@ -141,35 +172,14 @@ func (t *Transport) RoundTrip(r *http.Request) (*http.Response, error) {
|
||||||
|
|
||||||
span.SetStatus(codes.Error, err.Error())
|
span.SetStatus(codes.Error, err.Error())
|
||||||
span.End()
|
span.End()
|
||||||
|
|
||||||
return res, err
|
return res, err
|
||||||
}
|
}
|
||||||
|
|
||||||
// metrics
|
|
||||||
metricOpts := t.semconv.MetricOptions(semconv.MetricAttributes{
|
|
||||||
Req: r,
|
|
||||||
StatusCode: res.StatusCode,
|
|
||||||
AdditionalAttributes: append(labeler.Get(), t.metricAttributesFromRequest(r)...),
|
|
||||||
})
|
|
||||||
|
|
||||||
// For handling response bytes we leverage a callback when the client reads the http response
|
|
||||||
readRecordFunc := func(n int64) {
|
|
||||||
t.semconv.RecordResponseSize(ctx, n, metricOpts)
|
|
||||||
}
|
|
||||||
|
|
||||||
// traces
|
// traces
|
||||||
span.SetAttributes(t.semconv.ResponseTraceAttrs(res)...)
|
span.SetAttributes(t.semconv.ResponseTraceAttrs(res)...)
|
||||||
span.SetStatus(t.semconv.Status(res.StatusCode))
|
span.SetStatus(t.semconv.Status(res.StatusCode))
|
||||||
|
|
||||||
res.Body = newWrappedBody(span, readRecordFunc, res.Body)
|
|
||||||
|
|
||||||
// Use floating point division here for higher precision (instead of Millisecond method).
|
|
||||||
elapsedTime := float64(time.Since(requestStartTime)) / float64(time.Millisecond)
|
|
||||||
|
|
||||||
t.semconv.RecordMetrics(ctx, semconv.MetricData{
|
|
||||||
RequestSize: bw.BytesRead(),
|
|
||||||
ElapsedTime: elapsedTime,
|
|
||||||
}, metricOpts)
|
|
||||||
|
|
||||||
return res, nil
|
return res, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
2
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/version.go
generated
vendored
2
vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/version.go
generated
vendored
|
|
@ -5,6 +5,6 @@ package otelhttp // import "go.opentelemetry.io/contrib/instrumentation/net/http
|
||||||
|
|
||||||
// Version is the current release version of the otelhttp instrumentation.
|
// Version is the current release version of the otelhttp instrumentation.
|
||||||
func Version() string {
|
func Version() string {
|
||||||
return "0.61.0"
|
return "0.63.0"
|
||||||
// This string is updated by the pre_release.sh script during release
|
// This string is updated by the pre_release.sh script during release
|
||||||
}
|
}
|
||||||
|
|
|
||||||
3
vendor/go.opentelemetry.io/otel/.clomonitor.yml
generated
vendored
Normal file
3
vendor/go.opentelemetry.io/otel/.clomonitor.yml
generated
vendored
Normal file
|
|
@ -0,0 +1,3 @@
|
||||||
|
exemptions:
|
||||||
|
- check: artifacthub_badge
|
||||||
|
reason: "Artifact Hub doesn't support Go packages"
|
||||||
1
vendor/go.opentelemetry.io/otel/.codespellignore
generated
vendored
1
vendor/go.opentelemetry.io/otel/.codespellignore
generated
vendored
|
|
@ -7,3 +7,4 @@ ans
|
||||||
nam
|
nam
|
||||||
valu
|
valu
|
||||||
thirdparty
|
thirdparty
|
||||||
|
addOpt
|
||||||
|
|
|
||||||
34
vendor/go.opentelemetry.io/otel/.golangci.yml
generated
vendored
34
vendor/go.opentelemetry.io/otel/.golangci.yml
generated
vendored
|
|
@ -10,6 +10,7 @@ linters:
|
||||||
- depguard
|
- depguard
|
||||||
- errcheck
|
- errcheck
|
||||||
- errorlint
|
- errorlint
|
||||||
|
- gocritic
|
||||||
- godot
|
- godot
|
||||||
- gosec
|
- gosec
|
||||||
- govet
|
- govet
|
||||||
|
|
@ -66,8 +67,6 @@ linters:
|
||||||
desc: Do not use cross-module internal packages.
|
desc: Do not use cross-module internal packages.
|
||||||
- pkg: go.opentelemetry.io/otel/internal/internaltest
|
- pkg: go.opentelemetry.io/otel/internal/internaltest
|
||||||
desc: Do not use cross-module internal packages.
|
desc: Do not use cross-module internal packages.
|
||||||
- pkg: go.opentelemetry.io/otel/internal/matchers
|
|
||||||
desc: Do not use cross-module internal packages.
|
|
||||||
otlp-internal:
|
otlp-internal:
|
||||||
files:
|
files:
|
||||||
- '!**/exporters/otlp/internal/**/*.go'
|
- '!**/exporters/otlp/internal/**/*.go'
|
||||||
|
|
@ -88,6 +87,18 @@ linters:
|
||||||
deny:
|
deny:
|
||||||
- pkg: go.opentelemetry.io/otel/exporters/otlp/otlptrace/internal
|
- pkg: go.opentelemetry.io/otel/exporters/otlp/otlptrace/internal
|
||||||
desc: Do not use cross-module internal packages.
|
desc: Do not use cross-module internal packages.
|
||||||
|
gocritic:
|
||||||
|
disabled-checks:
|
||||||
|
- appendAssign
|
||||||
|
- commentedOutCode
|
||||||
|
- dupArg
|
||||||
|
- hugeParam
|
||||||
|
- importShadow
|
||||||
|
- preferDecodeRune
|
||||||
|
- rangeValCopy
|
||||||
|
- unnamedResult
|
||||||
|
- whyNoLint
|
||||||
|
enable-all: true
|
||||||
godot:
|
godot:
|
||||||
exclude:
|
exclude:
|
||||||
# Exclude links.
|
# Exclude links.
|
||||||
|
|
@ -169,7 +180,10 @@ linters:
|
||||||
- fmt.Print
|
- fmt.Print
|
||||||
- fmt.Printf
|
- fmt.Printf
|
||||||
- fmt.Println
|
- fmt.Println
|
||||||
|
- name: unused-parameter
|
||||||
|
- name: unused-receiver
|
||||||
- name: unnecessary-stmt
|
- name: unnecessary-stmt
|
||||||
|
- name: use-any
|
||||||
- name: useless-break
|
- name: useless-break
|
||||||
- name: var-declaration
|
- name: var-declaration
|
||||||
- name: var-naming
|
- name: var-naming
|
||||||
|
|
@ -190,6 +204,10 @@ linters:
|
||||||
- legacy
|
- legacy
|
||||||
- std-error-handling
|
- std-error-handling
|
||||||
rules:
|
rules:
|
||||||
|
- linters:
|
||||||
|
- revive
|
||||||
|
path: schema/v.*/types/.*
|
||||||
|
text: avoid meaningless package names
|
||||||
# TODO: Having appropriate comments for exported objects helps development,
|
# TODO: Having appropriate comments for exported objects helps development,
|
||||||
# even for objects in internal packages. Appropriate comments for all
|
# even for objects in internal packages. Appropriate comments for all
|
||||||
# exported objects should be added and this exclusion removed.
|
# exported objects should be added and this exclusion removed.
|
||||||
|
|
@ -222,10 +240,6 @@ linters:
|
||||||
- linters:
|
- linters:
|
||||||
- gosec
|
- gosec
|
||||||
text: 'G402: TLS MinVersion too low.'
|
text: 'G402: TLS MinVersion too low.'
|
||||||
paths:
|
|
||||||
- third_party$
|
|
||||||
- builtin$
|
|
||||||
- examples$
|
|
||||||
issues:
|
issues:
|
||||||
max-issues-per-linter: 0
|
max-issues-per-linter: 0
|
||||||
max-same-issues: 0
|
max-same-issues: 0
|
||||||
|
|
@ -235,14 +249,12 @@ formatters:
|
||||||
- goimports
|
- goimports
|
||||||
- golines
|
- golines
|
||||||
settings:
|
settings:
|
||||||
|
gofumpt:
|
||||||
|
extra-rules: true
|
||||||
goimports:
|
goimports:
|
||||||
local-prefixes:
|
local-prefixes:
|
||||||
- go.opentelemetry.io
|
- go.opentelemetry.io/otel
|
||||||
golines:
|
golines:
|
||||||
max-len: 120
|
max-len: 120
|
||||||
exclusions:
|
exclusions:
|
||||||
generated: lax
|
generated: lax
|
||||||
paths:
|
|
||||||
- third_party$
|
|
||||||
- builtin$
|
|
||||||
- examples$
|
|
||||||
|
|
|
||||||
3
vendor/go.opentelemetry.io/otel/.lycheeignore
generated
vendored
3
vendor/go.opentelemetry.io/otel/.lycheeignore
generated
vendored
|
|
@ -2,5 +2,8 @@ http://localhost
|
||||||
http://jaeger-collector
|
http://jaeger-collector
|
||||||
https://github.com/open-telemetry/opentelemetry-go/milestone/
|
https://github.com/open-telemetry/opentelemetry-go/milestone/
|
||||||
https://github.com/open-telemetry/opentelemetry-go/projects
|
https://github.com/open-telemetry/opentelemetry-go/projects
|
||||||
|
# Weaver model URL for semantic-conventions repository.
|
||||||
|
https?:\/\/github\.com\/open-telemetry\/semantic-conventions\/archive\/refs\/tags\/[^.]+\.zip\[[^]]+]
|
||||||
file:///home/runner/work/opentelemetry-go/opentelemetry-go/libraries
|
file:///home/runner/work/opentelemetry-go/opentelemetry-go/libraries
|
||||||
file:///home/runner/work/opentelemetry-go/opentelemetry-go/manual
|
file:///home/runner/work/opentelemetry-go/opentelemetry-go/manual
|
||||||
|
http://4.3.2.1:78/user/123
|
||||||
149
vendor/go.opentelemetry.io/otel/CHANGELOG.md
generated
vendored
149
vendor/go.opentelemetry.io/otel/CHANGELOG.md
generated
vendored
|
|
@ -11,6 +11,148 @@ This project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.htm
|
||||||
<!-- Released section -->
|
<!-- Released section -->
|
||||||
<!-- Don't change this section unless doing release -->
|
<!-- Don't change this section unless doing release -->
|
||||||
|
|
||||||
|
## [1.38.0/0.60.0/0.14.0/0.0.13] 2025-08-29
|
||||||
|
|
||||||
|
This release is the last to support [Go 1.23].
|
||||||
|
The next release will require at least [Go 1.24].
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Add native histogram exemplar support in `go.opentelemetry.io/otel/exporters/prometheus`. (#6772)
|
||||||
|
- Add template attribute functions to the `go.opentelmetry.io/otel/semconv/v1.34.0` package. (#6939)
|
||||||
|
- `ContainerLabel`
|
||||||
|
- `DBOperationParameter`
|
||||||
|
- `DBSystemParameter`
|
||||||
|
- `HTTPRequestHeader`
|
||||||
|
- `HTTPResponseHeader`
|
||||||
|
- `K8SCronJobAnnotation`
|
||||||
|
- `K8SCronJobLabel`
|
||||||
|
- `K8SDaemonSetAnnotation`
|
||||||
|
- `K8SDaemonSetLabel`
|
||||||
|
- `K8SDeploymentAnnotation`
|
||||||
|
- `K8SDeploymentLabel`
|
||||||
|
- `K8SJobAnnotation`
|
||||||
|
- `K8SJobLabel`
|
||||||
|
- `K8SNamespaceAnnotation`
|
||||||
|
- `K8SNamespaceLabel`
|
||||||
|
- `K8SNodeAnnotation`
|
||||||
|
- `K8SNodeLabel`
|
||||||
|
- `K8SPodAnnotation`
|
||||||
|
- `K8SPodLabel`
|
||||||
|
- `K8SReplicaSetAnnotation`
|
||||||
|
- `K8SReplicaSetLabel`
|
||||||
|
- `K8SStatefulSetAnnotation`
|
||||||
|
- `K8SStatefulSetLabel`
|
||||||
|
- `ProcessEnvironmentVariable`
|
||||||
|
- `RPCConnectRPCRequestMetadata`
|
||||||
|
- `RPCConnectRPCResponseMetadata`
|
||||||
|
- `RPCGRPCRequestMetadata`
|
||||||
|
- `RPCGRPCResponseMetadata`
|
||||||
|
- Add `ErrorType` attribute helper function to the `go.opentelmetry.io/otel/semconv/v1.34.0` package. (#6962)
|
||||||
|
- Add `WithAllowKeyDuplication` in `go.opentelemetry.io/otel/sdk/log` which can be used to disable deduplication for log records. (#6968)
|
||||||
|
- Add `WithCardinalityLimit` option to configure the cardinality limit in `go.opentelemetry.io/otel/sdk/metric`. (#6996, #7065, #7081, #7164, #7165, #7179)
|
||||||
|
- Add `Clone` method to `Record` in `go.opentelemetry.io/otel/log` that returns a copy of the record with no shared state. (#7001)
|
||||||
|
- Add experimental self-observability span and batch span processor metrics in `go.opentelemetry.io/otel/sdk/trace`.
|
||||||
|
Check the `go.opentelemetry.io/otel/sdk/trace/internal/x` package documentation for more information. (#7027, #6393, #7209)
|
||||||
|
- The `go.opentelemetry.io/otel/semconv/v1.36.0` package.
|
||||||
|
The package contains semantic conventions from the `v1.36.0` version of the OpenTelemetry Semantic Conventions.
|
||||||
|
See the [migration documentation](./semconv/v1.36.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.34.0.`(#7032, #7041)
|
||||||
|
- Add support for configuring Prometheus name translation using `WithTranslationStrategy` option in `go.opentelemetry.io/otel/exporters/prometheus`. The current default translation strategy when UTF-8 mode is enabled is `NoUTF8EscapingWithSuffixes`, but a future release will change the default strategy to `UnderscoreEscapingWithSuffixes` for compliance with the specification. (#7111)
|
||||||
|
- Add experimental self-observability log metrics in `go.opentelemetry.io/otel/sdk/log`.
|
||||||
|
Check the `go.opentelemetry.io/otel/sdk/log/internal/x` package documentation for more information. (#7121)
|
||||||
|
- Add experimental self-observability trace exporter metrics in `go.opentelemetry.io/otel/exporters/stdout/stdouttrace`.
|
||||||
|
Check the `go.opentelemetry.io/otel/exporters/stdout/stdouttrace/internal/x` package documentation for more information. (#7133)
|
||||||
|
- Support testing of [Go 1.25]. (#7187)
|
||||||
|
- The `go.opentelemetry.io/otel/semconv/v1.37.0` package.
|
||||||
|
The package contains semantic conventions from the `v1.37.0` version of the OpenTelemetry Semantic Conventions.
|
||||||
|
See the [migration documentation](./semconv/v1.37.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.36.0.`(#7254)
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Optimize `TraceIDFromHex` and `SpanIDFromHex` in `go.opentelemetry.io/otel/sdk/trace`. (#6791)
|
||||||
|
- Change `AssertEqual` in `go.opentelemetry.io/otel/log/logtest` to accept `TestingT` in order to support benchmarks and fuzz tests. (#6908)
|
||||||
|
- Change `DefaultExemplarReservoirProviderSelector` in `go.opentelemetry.io/otel/sdk/metric` to use `runtime.GOMAXPROCS(0)` instead of `runtime.NumCPU()` for the `FixedSizeReservoirProvider` default size. (#7094)
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- `SetBody` method of `Record` in `go.opentelemetry.io/otel/sdk/log` now deduplicates key-value collections (`log.Value` of `log.KindMap` from `go.opentelemetry.io/otel/log`). (#7002)
|
||||||
|
- Fix `go.opentelemetry.io/otel/exporters/prometheus` to not append a suffix if it's already present in metric name. (#7088)
|
||||||
|
- Fix the `go.opentelemetry.io/otel/exporters/stdout/stdouttrace` self-observability component type and name. (#7195)
|
||||||
|
- Fix partial export count metric in `go.opentelemetry.io/otel/exporters/stdout/stdouttrace`. (#7199)
|
||||||
|
|
||||||
|
### Deprecated
|
||||||
|
|
||||||
|
- Deprecate `WithoutUnits` and `WithoutCounterSuffixes` options, preferring `WithTranslationStrategy` instead. (#7111)
|
||||||
|
- Deprecate support for `OTEL_GO_X_CARDINALITY_LIMIT` environment variable in `go.opentelemetry.io/otel/sdk/metric`. Use `WithCardinalityLimit` option instead. (#7166)
|
||||||
|
|
||||||
|
## [0.59.1] 2025-07-21
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- Retract `v0.59.0` release of `go.opentelemetry.io/otel/exporters/prometheus` module which appends incorrect unit suffixes. (#7046)
|
||||||
|
- Change `go.opentelemetry.io/otel/exporters/prometheus` to no longer deduplicate suffixes when UTF8 is enabled.
|
||||||
|
It is recommended to disable unit and counter suffixes in the exporter, and manually add suffixes if you rely on the existing behavior. (#7044)
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Fix `go.opentelemetry.io/otel/exporters/prometheus` to properly handle unit suffixes when the unit is in brackets.
|
||||||
|
E.g. `{spans}`. (#7044)
|
||||||
|
|
||||||
|
## [1.37.0/0.59.0/0.13.0] 2025-06-25
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- The `go.opentelemetry.io/otel/semconv/v1.33.0` package.
|
||||||
|
The package contains semantic conventions from the `v1.33.0` version of the OpenTelemetry Semantic Conventions.
|
||||||
|
See the [migration documentation](./semconv/v1.33.0/MIGRATION.md) for information on how to upgrade from `go.opentelemetry.io/otel/semconv/v1.32.0.`(#6799)
|
||||||
|
- The `go.opentelemetry.io/otel/semconv/v1.34.0` package.
|
||||||
|
The package contains semantic conventions from the `v1.34.0` version of the OpenTelemetry Semantic Conventions. (#6812)
|
||||||
|
- Add metric's schema URL as `otel_scope_schema_url` label in `go.opentelemetry.io/otel/exporters/prometheus`. (#5947)
|
||||||
|
- Add metric's scope attributes as `otel_scope_[attribute]` labels in `go.opentelemetry.io/otel/exporters/prometheus`. (#5947)
|
||||||
|
- Add `EventName` to `EnabledParameters` in `go.opentelemetry.io/otel/log`. (#6825)
|
||||||
|
- Add `EventName` to `EnabledParameters` in `go.opentelemetry.io/otel/sdk/log`. (#6825)
|
||||||
|
- Changed handling of `go.opentelemetry.io/otel/exporters/prometheus` metric renaming to add unit suffixes when it doesn't match one of the pre-defined values in the unit suffix map. (#6839)
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
|
||||||
|
- The semantic conventions have been upgraded from `v1.26.0` to `v1.34.0` in `go.opentelemetry.io/otel/bridge/opentracing`. (#6827)
|
||||||
|
- The semantic conventions have been upgraded from `v1.26.0` to `v1.34.0` in `go.opentelemetry.io/otel/exporters/zipkin`. (#6829)
|
||||||
|
- The semantic conventions have been upgraded from `v1.26.0` to `v1.34.0` in `go.opentelemetry.io/otel/metric`. (#6832)
|
||||||
|
- The semantic conventions have been upgraded from `v1.26.0` to `v1.34.0` in `go.opentelemetry.io/otel/sdk/resource`. (#6834)
|
||||||
|
- The semantic conventions have been upgraded from `v1.26.0` to `v1.34.0` in `go.opentelemetry.io/otel/sdk/trace`. (#6835)
|
||||||
|
- The semantic conventions have been upgraded from `v1.26.0` to `v1.34.0` in `go.opentelemetry.io/otel/trace`. (#6836)
|
||||||
|
- `Record.Resource` now returns `*resource.Resource` instead of `resource.Resource` in `go.opentelemetry.io/otel/sdk/log`. (#6864)
|
||||||
|
- Retry now shows error cause for context timeout in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc`, `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc`, `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc`, `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp`, `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp`, `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp`. (#6898)
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Stop stripping trailing slashes from configured endpoint URL in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc`. (#6710)
|
||||||
|
- Stop stripping trailing slashes from configured endpoint URL in `go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp`. (#6710)
|
||||||
|
- Stop stripping trailing slashes from configured endpoint URL in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc`. (#6710)
|
||||||
|
- Stop stripping trailing slashes from configured endpoint URL in `go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp`. (#6710)
|
||||||
|
- Validate exponential histogram scale range for Prometheus compatibility in `go.opentelemetry.io/otel/exporters/prometheus`. (#6822)
|
||||||
|
- Context cancellation during metric pipeline produce does not corrupt data in `go.opentelemetry.io/otel/sdk/metric`. (#6914)
|
||||||
|
|
||||||
|
### Removed
|
||||||
|
|
||||||
|
- `go.opentelemetry.io/otel/exporters/prometheus` no longer exports `otel_scope_info` metric. (#6770)
|
||||||
|
|
||||||
|
## [0.12.2] 2025-05-22
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- Retract `v0.12.0` release of `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc` module that contains invalid dependencies. (#6804)
|
||||||
|
- Retract `v0.12.0` release of `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp` module that contains invalid dependencies. (#6804)
|
||||||
|
- Retract `v0.12.0` release of `go.opentelemetry.io/otel/exporters/stdout/stdoutlog` module that contains invalid dependencies. (#6804)
|
||||||
|
|
||||||
|
## [0.12.1] 2025-05-21
|
||||||
|
|
||||||
|
### Fixes
|
||||||
|
|
||||||
|
- Use the proper dependency version of `go.opentelemetry.io/otel/sdk/log/logtest` in `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc`. (#6800)
|
||||||
|
- Use the proper dependency version of `go.opentelemetry.io/otel/sdk/log/logtest` in `go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp`. (#6800)
|
||||||
|
- Use the proper dependency version of `go.opentelemetry.io/otel/sdk/log/logtest` in `go.opentelemetry.io/otel/exporters/stdout/stdoutlog`. (#6800)
|
||||||
|
|
||||||
## [1.36.0/0.58.0/0.12.0] 2025-05-20
|
## [1.36.0/0.58.0/0.12.0] 2025-05-20
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|
@ -3288,7 +3430,11 @@ It contains api and sdk for trace and meter.
|
||||||
- CircleCI build CI manifest files.
|
- CircleCI build CI manifest files.
|
||||||
- CODEOWNERS file to track owners of this project.
|
- CODEOWNERS file to track owners of this project.
|
||||||
|
|
||||||
[Unreleased]: https://github.com/open-telemetry/opentelemetry-go/compare/v1.36.0...HEAD
|
[Unreleased]: https://github.com/open-telemetry/opentelemetry-go/compare/v1.38.0...HEAD
|
||||||
|
[1.38.0/0.60.0/0.14.0/0.0.13]: https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.38.0
|
||||||
|
[1.37.0/0.59.0/0.13.0]: https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.37.0
|
||||||
|
[0.12.2]: https://github.com/open-telemetry/opentelemetry-go/releases/tag/log/v0.12.2
|
||||||
|
[0.12.1]: https://github.com/open-telemetry/opentelemetry-go/releases/tag/log/v0.12.1
|
||||||
[1.36.0/0.58.0/0.12.0]: https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.36.0
|
[1.36.0/0.58.0/0.12.0]: https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.36.0
|
||||||
[1.35.0/0.57.0/0.11.0]: https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.35.0
|
[1.35.0/0.57.0/0.11.0]: https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.35.0
|
||||||
[1.34.0/0.56.0/0.10.0]: https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.34.0
|
[1.34.0/0.56.0/0.10.0]: https://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.34.0
|
||||||
|
|
@ -3381,6 +3527,7 @@ It contains api and sdk for trace and meter.
|
||||||
|
|
||||||
<!-- Released section ended -->
|
<!-- Released section ended -->
|
||||||
|
|
||||||
|
[Go 1.25]: https://go.dev/doc/go1.25
|
||||||
[Go 1.24]: https://go.dev/doc/go1.24
|
[Go 1.24]: https://go.dev/doc/go1.24
|
||||||
[Go 1.23]: https://go.dev/doc/go1.23
|
[Go 1.23]: https://go.dev/doc/go1.23
|
||||||
[Go 1.22]: https://go.dev/doc/go1.22
|
[Go 1.22]: https://go.dev/doc/go1.22
|
||||||
|
|
|
||||||
2
vendor/go.opentelemetry.io/otel/CODEOWNERS
generated
vendored
2
vendor/go.opentelemetry.io/otel/CODEOWNERS
generated
vendored
|
|
@ -12,6 +12,6 @@
|
||||||
# https://help.github.com/en/articles/about-code-owners
|
# https://help.github.com/en/articles/about-code-owners
|
||||||
#
|
#
|
||||||
|
|
||||||
* @MrAlias @XSAM @dashpole @pellared @dmathieu
|
* @MrAlias @XSAM @dashpole @pellared @dmathieu @flc1125
|
||||||
|
|
||||||
CODEOWNERS @MrAlias @pellared @dashpole @XSAM @dmathieu
|
CODEOWNERS @MrAlias @pellared @dashpole @XSAM @dmathieu
|
||||||
|
|
|
||||||
72
vendor/go.opentelemetry.io/otel/CONTRIBUTING.md
generated
vendored
72
vendor/go.opentelemetry.io/otel/CONTRIBUTING.md
generated
vendored
|
|
@ -109,10 +109,9 @@ A PR is considered **ready to merge** when:
|
||||||
|
|
||||||
This is not enforced through automation, but needs to be validated by the
|
This is not enforced through automation, but needs to be validated by the
|
||||||
maintainer merging.
|
maintainer merging.
|
||||||
* The qualified approvals need to be from [Approver]s/[Maintainer]s
|
* At least one of the qualified approvals need to be from an
|
||||||
affiliated with different companies. Two qualified approvals from
|
[Approver]/[Maintainer] affiliated with a different company than the author
|
||||||
[Approver]s or [Maintainer]s affiliated with the same company counts as a
|
of the PR.
|
||||||
single qualified approval.
|
|
||||||
* PRs introducing changes that have already been discussed and consensus
|
* PRs introducing changes that have already been discussed and consensus
|
||||||
reached only need one qualified approval. The discussion and resolution
|
reached only need one qualified approval. The discussion and resolution
|
||||||
needs to be linked to the PR.
|
needs to be linked to the PR.
|
||||||
|
|
@ -193,6 +192,35 @@ should have `go test -bench` output in their description.
|
||||||
should have [`benchstat`](https://pkg.go.dev/golang.org/x/perf/cmd/benchstat)
|
should have [`benchstat`](https://pkg.go.dev/golang.org/x/perf/cmd/benchstat)
|
||||||
output in their description.
|
output in their description.
|
||||||
|
|
||||||
|
## Dependencies
|
||||||
|
|
||||||
|
This project uses [Go Modules] for dependency management. All modules will use
|
||||||
|
`go.mod` to explicitly list all direct and indirect dependencies, ensuring a
|
||||||
|
clear dependency graph. The `go.sum` file for each module will be committed to
|
||||||
|
the repository and used to verify the integrity of downloaded modules,
|
||||||
|
preventing malicious tampering.
|
||||||
|
|
||||||
|
This project uses automated dependency update tools (i.e. dependabot,
|
||||||
|
renovatebot) to manage updates to dependencies. This ensures that dependencies
|
||||||
|
are kept up-to-date with the latest security patches and features and are
|
||||||
|
reviewed before being merged. If you would like to propose a change to a
|
||||||
|
dependency it should be done through a pull request that updates the `go.mod`
|
||||||
|
file and includes a description of the change.
|
||||||
|
|
||||||
|
See the [versioning and compatibility](./VERSIONING.md) policy for more details
|
||||||
|
about dependency compatibility.
|
||||||
|
|
||||||
|
[Go Modules]: https://pkg.go.dev/cmd/go#hdr-Modules__module_versions__and_more
|
||||||
|
|
||||||
|
### Environment Dependencies
|
||||||
|
|
||||||
|
This project does not partition dependencies based on the environment (i.e.
|
||||||
|
`development`, `staging`, `production`).
|
||||||
|
|
||||||
|
Only the dependencies explicitly included in the released modules have be
|
||||||
|
tested and verified to work with the released code. No other guarantee is made
|
||||||
|
about the compatibility of other dependencies.
|
||||||
|
|
||||||
## Documentation
|
## Documentation
|
||||||
|
|
||||||
Each (non-internal, non-test) package must be documented using
|
Each (non-internal, non-test) package must be documented using
|
||||||
|
|
@ -234,6 +262,10 @@ For a non-comprehensive but foundational overview of these best practices
|
||||||
the [Effective Go](https://golang.org/doc/effective_go.html) documentation
|
the [Effective Go](https://golang.org/doc/effective_go.html) documentation
|
||||||
is an excellent starting place.
|
is an excellent starting place.
|
||||||
|
|
||||||
|
We also recommend following the
|
||||||
|
[Go Code Review Comments](https://go.dev/wiki/CodeReviewComments)
|
||||||
|
that collects common comments made during reviews of Go code.
|
||||||
|
|
||||||
As a convenience for developers building this project the `make precommit`
|
As a convenience for developers building this project the `make precommit`
|
||||||
will format, lint, validate, and in some cases fix the changes you plan to
|
will format, lint, validate, and in some cases fix the changes you plan to
|
||||||
submit. This check will need to pass for your changes to be able to be
|
submit. This check will need to pass for your changes to be able to be
|
||||||
|
|
@ -587,6 +619,10 @@ See also:
|
||||||
|
|
||||||
### Testing
|
### Testing
|
||||||
|
|
||||||
|
We allow using [`testify`](https://github.com/stretchr/testify) even though
|
||||||
|
it is seen as non-idiomatic according to
|
||||||
|
the [Go Test Comments](https://go.dev/wiki/TestComments#assert-libraries) page.
|
||||||
|
|
||||||
The tests should never leak goroutines.
|
The tests should never leak goroutines.
|
||||||
|
|
||||||
Use the term `ConcurrentSafe` in the test name when it aims to verify the
|
Use the term `ConcurrentSafe` in the test name when it aims to verify the
|
||||||
|
|
@ -641,20 +677,28 @@ should be canceled.
|
||||||
|
|
||||||
## Approvers and Maintainers
|
## Approvers and Maintainers
|
||||||
|
|
||||||
|
### Maintainers
|
||||||
|
|
||||||
|
- [Damien Mathieu](https://github.com/dmathieu), Elastic ([GPG](https://keys.openpgp.org/search?q=5A126B972A81A6CE443E5E1B408B8E44F0873832))
|
||||||
|
- [David Ashpole](https://github.com/dashpole), Google ([GPG](https://keys.openpgp.org/search?q=C0D1BDDCAAEAE573673085F176327DA4D864DC70))
|
||||||
|
- [Robert Pająk](https://github.com/pellared), Splunk ([GPG](https://keys.openpgp.org/search?q=CDAD3A60476A3DE599AA5092E5F7C35A4DBE90C2))
|
||||||
|
- [Sam Xie](https://github.com/XSAM), Splunk ([GPG](https://keys.openpgp.org/search?q=AEA033782371ABB18EE39188B8044925D6FEEBEA))
|
||||||
|
- [Tyler Yahn](https://github.com/MrAlias), Splunk ([GPG](https://keys.openpgp.org/search?q=0x46B0F3E1A8B1BA5A))
|
||||||
|
|
||||||
|
For more information about the maintainer role, see the [community repository](https://github.com/open-telemetry/community/blob/main/guides/contributor/membership.md#maintainer).
|
||||||
|
|
||||||
|
### Approvers
|
||||||
|
|
||||||
|
- [Flc](https://github.com/flc1125), Independent
|
||||||
|
|
||||||
|
For more information about the approver role, see the [community repository](https://github.com/open-telemetry/community/blob/main/guides/contributor/membership.md#approver).
|
||||||
|
|
||||||
### Triagers
|
### Triagers
|
||||||
|
|
||||||
- [Alex Kats](https://github.com/akats7), Capital One
|
- [Alex Kats](https://github.com/akats7), Capital One
|
||||||
- [Cheng-Zhen Yang](https://github.com/scorpionknifes), Independent
|
- [Cheng-Zhen Yang](https://github.com/scorpionknifes), Independent
|
||||||
|
|
||||||
### Approvers
|
For more information about the triager role, see the [community repository](https://github.com/open-telemetry/community/blob/main/guides/contributor/membership.md#triager).
|
||||||
|
|
||||||
### Maintainers
|
|
||||||
|
|
||||||
- [Damien Mathieu](https://github.com/dmathieu), Elastic
|
|
||||||
- [David Ashpole](https://github.com/dashpole), Google
|
|
||||||
- [Robert Pająk](https://github.com/pellared), Splunk
|
|
||||||
- [Sam Xie](https://github.com/XSAM), Cisco/AppDynamics
|
|
||||||
- [Tyler Yahn](https://github.com/MrAlias), Splunk
|
|
||||||
|
|
||||||
### Emeritus
|
### Emeritus
|
||||||
|
|
||||||
|
|
@ -666,6 +710,8 @@ should be canceled.
|
||||||
- [Josh MacDonald](https://github.com/jmacd)
|
- [Josh MacDonald](https://github.com/jmacd)
|
||||||
- [Liz Fong-Jones](https://github.com/lizthegrey)
|
- [Liz Fong-Jones](https://github.com/lizthegrey)
|
||||||
|
|
||||||
|
For more information about the emeritus role, see the [community repository](https://github.com/open-telemetry/community/blob/main/guides/contributor/membership.md#emeritus-maintainerapprovertriager).
|
||||||
|
|
||||||
### Become an Approver or a Maintainer
|
### Become an Approver or a Maintainer
|
||||||
|
|
||||||
See the [community membership document in OpenTelemetry community
|
See the [community membership document in OpenTelemetry community
|
||||||
|
|
|
||||||
30
vendor/go.opentelemetry.io/otel/LICENSE
generated
vendored
30
vendor/go.opentelemetry.io/otel/LICENSE
generated
vendored
|
|
@ -199,3 +199,33 @@
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
See the License for the specific language governing permissions and
|
See the License for the specific language governing permissions and
|
||||||
limitations under the License.
|
limitations under the License.
|
||||||
|
|
||||||
|
--------------------------------------------------------------------------------
|
||||||
|
|
||||||
|
Copyright 2009 The Go Authors.
|
||||||
|
|
||||||
|
Redistribution and use in source and binary forms, with or without
|
||||||
|
modification, are permitted provided that the following conditions are
|
||||||
|
met:
|
||||||
|
|
||||||
|
* Redistributions of source code must retain the above copyright
|
||||||
|
notice, this list of conditions and the following disclaimer.
|
||||||
|
* Redistributions in binary form must reproduce the above
|
||||||
|
copyright notice, this list of conditions and the following disclaimer
|
||||||
|
in the documentation and/or other materials provided with the
|
||||||
|
distribution.
|
||||||
|
* Neither the name of Google LLC nor the names of its
|
||||||
|
contributors may be used to endorse or promote products derived from
|
||||||
|
this software without specific prior written permission.
|
||||||
|
|
||||||
|
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||||
|
"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||||
|
LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
|
||||||
|
A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
||||||
|
OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
||||||
|
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
|
||||||
|
LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
||||||
|
DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
||||||
|
THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
||||||
|
(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
|
||||||
|
OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||||
9
vendor/go.opentelemetry.io/otel/Makefile
generated
vendored
9
vendor/go.opentelemetry.io/otel/Makefile
generated
vendored
|
|
@ -34,9 +34,6 @@ $(TOOLS)/%: $(TOOLS_MOD_DIR)/go.mod | $(TOOLS)
|
||||||
MULTIMOD = $(TOOLS)/multimod
|
MULTIMOD = $(TOOLS)/multimod
|
||||||
$(TOOLS)/multimod: PACKAGE=go.opentelemetry.io/build-tools/multimod
|
$(TOOLS)/multimod: PACKAGE=go.opentelemetry.io/build-tools/multimod
|
||||||
|
|
||||||
SEMCONVGEN = $(TOOLS)/semconvgen
|
|
||||||
$(TOOLS)/semconvgen: PACKAGE=go.opentelemetry.io/build-tools/semconvgen
|
|
||||||
|
|
||||||
CROSSLINK = $(TOOLS)/crosslink
|
CROSSLINK = $(TOOLS)/crosslink
|
||||||
$(TOOLS)/crosslink: PACKAGE=go.opentelemetry.io/build-tools/crosslink
|
$(TOOLS)/crosslink: PACKAGE=go.opentelemetry.io/build-tools/crosslink
|
||||||
|
|
||||||
|
|
@ -71,7 +68,7 @@ GOVULNCHECK = $(TOOLS)/govulncheck
|
||||||
$(TOOLS)/govulncheck: PACKAGE=golang.org/x/vuln/cmd/govulncheck
|
$(TOOLS)/govulncheck: PACKAGE=golang.org/x/vuln/cmd/govulncheck
|
||||||
|
|
||||||
.PHONY: tools
|
.PHONY: tools
|
||||||
tools: $(CROSSLINK) $(GOLANGCI_LINT) $(MISSPELL) $(GOCOVMERGE) $(STRINGER) $(PORTO) $(SEMCONVGEN) $(VERIFYREADMES) $(MULTIMOD) $(SEMCONVKIT) $(GOTMPL) $(GORELEASE)
|
tools: $(CROSSLINK) $(GOLANGCI_LINT) $(MISSPELL) $(GOCOVMERGE) $(STRINGER) $(PORTO) $(VERIFYREADMES) $(MULTIMOD) $(SEMCONVKIT) $(GOTMPL) $(GORELEASE)
|
||||||
|
|
||||||
# Virtualized python tools via docker
|
# Virtualized python tools via docker
|
||||||
|
|
||||||
|
|
@ -284,7 +281,7 @@ semconv-generate: $(SEMCONVKIT)
|
||||||
docker run --rm \
|
docker run --rm \
|
||||||
-u $(DOCKER_USER) \
|
-u $(DOCKER_USER) \
|
||||||
--env HOME=/tmp/weaver \
|
--env HOME=/tmp/weaver \
|
||||||
--mount 'type=bind,source=$(PWD)/semconv,target=/home/weaver/templates/registry/go,readonly' \
|
--mount 'type=bind,source=$(PWD)/semconv/templates,target=/home/weaver/templates,readonly' \
|
||||||
--mount 'type=bind,source=$(PWD)/semconv/${TAG},target=/home/weaver/target' \
|
--mount 'type=bind,source=$(PWD)/semconv/${TAG},target=/home/weaver/target' \
|
||||||
--mount 'type=bind,source=$(HOME)/.weaver,target=/tmp/weaver/.weaver' \
|
--mount 'type=bind,source=$(HOME)/.weaver,target=/tmp/weaver/.weaver' \
|
||||||
$(WEAVER_IMAGE) registry generate \
|
$(WEAVER_IMAGE) registry generate \
|
||||||
|
|
@ -293,7 +290,7 @@ semconv-generate: $(SEMCONVKIT)
|
||||||
--param tag=$(TAG) \
|
--param tag=$(TAG) \
|
||||||
go \
|
go \
|
||||||
/home/weaver/target
|
/home/weaver/target
|
||||||
$(SEMCONVKIT) -output "$(SEMCONVPKG)/$(TAG)" -tag "$(TAG)"
|
$(SEMCONVKIT) -semconv "$(SEMCONVPKG)" -tag "$(TAG)"
|
||||||
|
|
||||||
.PHONY: gorelease
|
.PHONY: gorelease
|
||||||
gorelease: $(OTEL_GO_MOD_DIRS:%=gorelease/%)
|
gorelease: $(OTEL_GO_MOD_DIRS:%=gorelease/%)
|
||||||
|
|
|
||||||
8
vendor/go.opentelemetry.io/otel/README.md
generated
vendored
8
vendor/go.opentelemetry.io/otel/README.md
generated
vendored
|
|
@ -7,6 +7,7 @@
|
||||||
[](https://scorecard.dev/viewer/?uri=github.com/open-telemetry/opentelemetry-go)
|
[](https://scorecard.dev/viewer/?uri=github.com/open-telemetry/opentelemetry-go)
|
||||||
[](https://www.bestpractices.dev/projects/9996)
|
[](https://www.bestpractices.dev/projects/9996)
|
||||||
[](https://issues.oss-fuzz.com/issues?q=project:opentelemetry-go)
|
[](https://issues.oss-fuzz.com/issues?q=project:opentelemetry-go)
|
||||||
|
[](https://app.fossa.com/projects/custom%2B162%2Fgithub.com%2Fopen-telemetry%2Fopentelemetry-go?ref=badge_shield&issueType=license)
|
||||||
[](https://cloud-native.slack.com/archives/C01NPAXACKT)
|
[](https://cloud-native.slack.com/archives/C01NPAXACKT)
|
||||||
|
|
||||||
OpenTelemetry-Go is the [Go](https://golang.org/) implementation of [OpenTelemetry](https://opentelemetry.io/).
|
OpenTelemetry-Go is the [Go](https://golang.org/) implementation of [OpenTelemetry](https://opentelemetry.io/).
|
||||||
|
|
@ -52,18 +53,25 @@ Currently, this project supports the following environments.
|
||||||
|
|
||||||
| OS | Go Version | Architecture |
|
| OS | Go Version | Architecture |
|
||||||
|----------|------------|--------------|
|
|----------|------------|--------------|
|
||||||
|
| Ubuntu | 1.25 | amd64 |
|
||||||
| Ubuntu | 1.24 | amd64 |
|
| Ubuntu | 1.24 | amd64 |
|
||||||
| Ubuntu | 1.23 | amd64 |
|
| Ubuntu | 1.23 | amd64 |
|
||||||
|
| Ubuntu | 1.25 | 386 |
|
||||||
| Ubuntu | 1.24 | 386 |
|
| Ubuntu | 1.24 | 386 |
|
||||||
| Ubuntu | 1.23 | 386 |
|
| Ubuntu | 1.23 | 386 |
|
||||||
|
| Ubuntu | 1.25 | arm64 |
|
||||||
| Ubuntu | 1.24 | arm64 |
|
| Ubuntu | 1.24 | arm64 |
|
||||||
| Ubuntu | 1.23 | arm64 |
|
| Ubuntu | 1.23 | arm64 |
|
||||||
|
| macOS 13 | 1.25 | amd64 |
|
||||||
| macOS 13 | 1.24 | amd64 |
|
| macOS 13 | 1.24 | amd64 |
|
||||||
| macOS 13 | 1.23 | amd64 |
|
| macOS 13 | 1.23 | amd64 |
|
||||||
|
| macOS | 1.25 | arm64 |
|
||||||
| macOS | 1.24 | arm64 |
|
| macOS | 1.24 | arm64 |
|
||||||
| macOS | 1.23 | arm64 |
|
| macOS | 1.23 | arm64 |
|
||||||
|
| Windows | 1.25 | amd64 |
|
||||||
| Windows | 1.24 | amd64 |
|
| Windows | 1.24 | amd64 |
|
||||||
| Windows | 1.23 | amd64 |
|
| Windows | 1.23 | amd64 |
|
||||||
|
| Windows | 1.25 | 386 |
|
||||||
| Windows | 1.24 | 386 |
|
| Windows | 1.24 | 386 |
|
||||||
| Windows | 1.23 | 386 |
|
| Windows | 1.23 | 386 |
|
||||||
|
|
||||||
|
|
|
||||||
23
vendor/go.opentelemetry.io/otel/RELEASING.md
generated
vendored
23
vendor/go.opentelemetry.io/otel/RELEASING.md
generated
vendored
|
|
@ -112,6 +112,29 @@ It is critical you make sure the version you push upstream is correct.
|
||||||
Finally create a Release for the new `<new tag>` on GitHub.
|
Finally create a Release for the new `<new tag>` on GitHub.
|
||||||
The release body should include all the release notes from the Changelog for this release.
|
The release body should include all the release notes from the Changelog for this release.
|
||||||
|
|
||||||
|
### Sign the Release Artifact
|
||||||
|
|
||||||
|
To ensure we comply with CNCF best practices, we need to sign the release artifact.
|
||||||
|
The tarball attached to the GitHub release needs to be signed with your GPG key.
|
||||||
|
|
||||||
|
Follow [these steps] to sign the release artifact and upload it to GitHub.
|
||||||
|
You can use [this script] to verify the contents of the tarball before signing it.
|
||||||
|
|
||||||
|
Be sure to use the correct GPG key when signing the release artifact.
|
||||||
|
|
||||||
|
```terminal
|
||||||
|
gpg --local-user <key-id> --armor --detach-sign opentelemetry-go-<version>.tar.gz
|
||||||
|
```
|
||||||
|
|
||||||
|
You can verify the signature with:
|
||||||
|
|
||||||
|
```terminal
|
||||||
|
gpg --verify opentelemetry-go-<version>.tar.gz.asc opentelemetry-go-<version>.tar.gz
|
||||||
|
```
|
||||||
|
|
||||||
|
[these steps]: https://wiki.debian.org/Creating%20signed%20GitHub%20releases
|
||||||
|
[this script]: https://github.com/MrAlias/attest-sh
|
||||||
|
|
||||||
## Post-Release
|
## Post-Release
|
||||||
|
|
||||||
### Contrib Repository
|
### Contrib Repository
|
||||||
|
|
|
||||||
203
vendor/go.opentelemetry.io/otel/SECURITY-INSIGHTS.yml
generated
vendored
Normal file
203
vendor/go.opentelemetry.io/otel/SECURITY-INSIGHTS.yml
generated
vendored
Normal file
|
|
@ -0,0 +1,203 @@
|
||||||
|
header:
|
||||||
|
schema-version: "1.0.0"
|
||||||
|
expiration-date: "2026-08-04T00:00:00.000Z"
|
||||||
|
last-updated: "2025-08-04"
|
||||||
|
last-reviewed: "2025-08-04"
|
||||||
|
commit-hash: 69e81088ad40f45a0764597326722dea8f3f00a8
|
||||||
|
project-url: https://github.com/open-telemetry/opentelemetry-go
|
||||||
|
project-release: "v1.37.0"
|
||||||
|
changelog: https://github.com/open-telemetry/opentelemetry-go/blob/69e81088ad40f45a0764597326722dea8f3f00a8/CHANGELOG.md
|
||||||
|
license: https://github.com/open-telemetry/opentelemetry-go/blob/69e81088ad40f45a0764597326722dea8f3f00a8/LICENSE
|
||||||
|
|
||||||
|
project-lifecycle:
|
||||||
|
status: active
|
||||||
|
bug-fixes-only: false
|
||||||
|
core-maintainers:
|
||||||
|
- https://github.com/dmathieu
|
||||||
|
- https://github.com/dashpole
|
||||||
|
- https://github.com/pellared
|
||||||
|
- https://github.com/XSAM
|
||||||
|
- https://github.com/MrAlias
|
||||||
|
release-process: |
|
||||||
|
See https://github.com/open-telemetry/opentelemetry-go/blob/69e81088ad40f45a0764597326722dea8f3f00a8/RELEASING.md
|
||||||
|
|
||||||
|
contribution-policy:
|
||||||
|
accepts-pull-requests: true
|
||||||
|
accepts-automated-pull-requests: true
|
||||||
|
automated-tools-list:
|
||||||
|
- automated-tool: dependabot
|
||||||
|
action: allowed
|
||||||
|
comment: Automated dependency updates are accepted.
|
||||||
|
- automated-tool: renovatebot
|
||||||
|
action: allowed
|
||||||
|
comment: Automated dependency updates are accepted.
|
||||||
|
- automated-tool: opentelemetrybot
|
||||||
|
action: allowed
|
||||||
|
comment: Automated OpenTelemetry actions are accepted.
|
||||||
|
contributing-policy: https://github.com/open-telemetry/opentelemetry-go/blob/69e81088ad40f45a0764597326722dea8f3f00a8/CONTRIBUTING.md
|
||||||
|
code-of-conduct: https://github.com/open-telemetry/.github/blob/ffa15f76b65ec7bcc41f6a0b277edbb74f832206/CODE_OF_CONDUCT.md
|
||||||
|
|
||||||
|
documentation:
|
||||||
|
- https://pkg.go.dev/go.opentelemetry.io/otel
|
||||||
|
- https://opentelemetry.io/docs/instrumentation/go/
|
||||||
|
|
||||||
|
distribution-points:
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/bridge/opencensus
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/bridge/opencensus/test
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/bridge/opentracing
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/stdout/stdoutmetric
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/stdout/stdouttrace
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/zipkin
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/metric
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/sdk
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/sdk/metric
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/trace
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/prometheus
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/log
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/log/logtest
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/sdk/log
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/sdk/log/logtest
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/exporters/stdout/stdoutlog
|
||||||
|
- pkg:golang/go.opentelemetry.io/otel/schema
|
||||||
|
|
||||||
|
security-artifacts:
|
||||||
|
threat-model:
|
||||||
|
threat-model-created: false
|
||||||
|
comment: |
|
||||||
|
No formal threat model created yet.
|
||||||
|
self-assessment:
|
||||||
|
self-assessment-created: false
|
||||||
|
comment: |
|
||||||
|
No formal self-assessment yet.
|
||||||
|
|
||||||
|
security-testing:
|
||||||
|
- tool-type: sca
|
||||||
|
tool-name: Dependabot
|
||||||
|
tool-version: latest
|
||||||
|
tool-url: https://github.com/dependabot
|
||||||
|
tool-rulesets:
|
||||||
|
- built-in
|
||||||
|
integration:
|
||||||
|
ad-hoc: false
|
||||||
|
ci: true
|
||||||
|
before-release: true
|
||||||
|
comment: |
|
||||||
|
Automated dependency updates.
|
||||||
|
- tool-type: sast
|
||||||
|
tool-name: golangci-lint
|
||||||
|
tool-version: latest
|
||||||
|
tool-url: https://github.com/golangci/golangci-lint
|
||||||
|
tool-rulesets:
|
||||||
|
- built-in
|
||||||
|
integration:
|
||||||
|
ad-hoc: false
|
||||||
|
ci: true
|
||||||
|
before-release: true
|
||||||
|
comment: |
|
||||||
|
Static analysis in CI.
|
||||||
|
- tool-type: fuzzing
|
||||||
|
tool-name: OSS-Fuzz
|
||||||
|
tool-version: latest
|
||||||
|
tool-url: https://github.com/google/oss-fuzz
|
||||||
|
tool-rulesets:
|
||||||
|
- default
|
||||||
|
integration:
|
||||||
|
ad-hoc: false
|
||||||
|
ci: false
|
||||||
|
before-release: false
|
||||||
|
comment: |
|
||||||
|
OpenTelemetry Go is integrated with OSS-Fuzz for continuous fuzz testing. See https://github.com/google/oss-fuzz/tree/f0f9b221190c6063a773bea606d192ebfc3d00cf/projects/opentelemetry-go for more details.
|
||||||
|
- tool-type: sast
|
||||||
|
tool-name: CodeQL
|
||||||
|
tool-version: latest
|
||||||
|
tool-url: https://github.com/github/codeql
|
||||||
|
tool-rulesets:
|
||||||
|
- default
|
||||||
|
integration:
|
||||||
|
ad-hoc: false
|
||||||
|
ci: true
|
||||||
|
before-release: true
|
||||||
|
comment: |
|
||||||
|
CodeQL static analysis is run in CI for all commits and pull requests to detect security vulnerabilities in the Go source code. See https://github.com/open-telemetry/opentelemetry-go/blob/d5b5b059849720144a03ca5c87561bfbdb940119/.github/workflows/codeql-analysis.yml for workflow details.
|
||||||
|
- tool-type: sca
|
||||||
|
tool-name: govulncheck
|
||||||
|
tool-version: latest
|
||||||
|
tool-url: https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck
|
||||||
|
tool-rulesets:
|
||||||
|
- default
|
||||||
|
integration:
|
||||||
|
ad-hoc: false
|
||||||
|
ci: true
|
||||||
|
before-release: true
|
||||||
|
comment: |
|
||||||
|
govulncheck is run in CI to detect known vulnerabilities in Go modules and code paths. See https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/.github/workflows/ci.yml for workflow configuration.
|
||||||
|
|
||||||
|
security-assessments:
|
||||||
|
- auditor-name: 7ASecurity
|
||||||
|
auditor-url: https://7asecurity.com
|
||||||
|
auditor-report: https://7asecurity.com/reports/pentest-report-opentelemetry.pdf
|
||||||
|
report-year: 2023
|
||||||
|
comment: |
|
||||||
|
This independent penetration test by 7ASecurity covered OpenTelemetry repositories including opentelemetry-go. The assessment focused on codebase review, threat modeling, and vulnerability identification. See the report for details of findings and recommendations applicable to opentelemetry-go. No critical vulnerabilities were found for this repository.
|
||||||
|
|
||||||
|
security-contacts:
|
||||||
|
- type: email
|
||||||
|
value: cncf-opentelemetry-security@lists.cncf.io
|
||||||
|
primary: true
|
||||||
|
- type: website
|
||||||
|
value: https://github.com/open-telemetry/opentelemetry-go/security/policy
|
||||||
|
primary: false
|
||||||
|
|
||||||
|
vulnerability-reporting:
|
||||||
|
accepts-vulnerability-reports: true
|
||||||
|
email-contact: cncf-opentelemetry-security@lists.cncf.io
|
||||||
|
security-policy: https://github.com/open-telemetry/opentelemetry-go/security/policy
|
||||||
|
comment: |
|
||||||
|
Security issues should be reported via email or GitHub security policy page.
|
||||||
|
|
||||||
|
dependencies:
|
||||||
|
third-party-packages: true
|
||||||
|
dependencies-lists:
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/bridge/opencensus/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/bridge/opencensus/test/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/bridge/opentracing/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/otlp/otlplog/otlploggrpc/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/otlp/otlplog/otlploghttp/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/otlp/otlpmetric/otlpmetricgrpc/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/otlp/otlpmetric/otlpmetrichttp/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/otlp/otlptrace/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/otlp/otlptrace/otlptracegrpc/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/otlp/otlptrace/otlptracehttp/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/prometheus/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/stdout/stdoutlog/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/stdout/stdoutmetric/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/stdout/stdouttrace/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/exporters/zipkin/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/internal/tools/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/log/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/log/logtest/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/metric/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/schema/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/sdk/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/sdk/log/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/sdk/log/logtest/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/sdk/metric/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/trace/go.mod
|
||||||
|
- https://github.com/open-telemetry/opentelemetry-go/blob/v1.37.0/trace/internal/telemetry/test/go.mod
|
||||||
|
dependencies-lifecycle:
|
||||||
|
policy-url: https://github.com/open-telemetry/opentelemetry-go/blob/69e81088ad40f45a0764597326722dea8f3f00a8/CONTRIBUTING.md
|
||||||
|
comment: |
|
||||||
|
Dependency lifecycle managed via go.mod and renovatebot.
|
||||||
|
env-dependencies-policy:
|
||||||
|
policy-url: https://github.com/open-telemetry/opentelemetry-go/blob/69e81088ad40f45a0764597326722dea8f3f00a8/CONTRIBUTING.md
|
||||||
|
comment: |
|
||||||
|
See contributing policy for environment usage.
|
||||||
12
vendor/go.opentelemetry.io/otel/attribute/encoder.go
generated
vendored
12
vendor/go.opentelemetry.io/otel/attribute/encoder.go
generated
vendored
|
|
@ -78,7 +78,7 @@ func DefaultEncoder() Encoder {
|
||||||
defaultEncoderOnce.Do(func() {
|
defaultEncoderOnce.Do(func() {
|
||||||
defaultEncoderInstance = &defaultAttrEncoder{
|
defaultEncoderInstance = &defaultAttrEncoder{
|
||||||
pool: sync.Pool{
|
pool: sync.Pool{
|
||||||
New: func() interface{} {
|
New: func() any {
|
||||||
return &bytes.Buffer{}
|
return &bytes.Buffer{}
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
|
@ -96,11 +96,11 @@ func (d *defaultAttrEncoder) Encode(iter Iterator) string {
|
||||||
for iter.Next() {
|
for iter.Next() {
|
||||||
i, keyValue := iter.IndexedAttribute()
|
i, keyValue := iter.IndexedAttribute()
|
||||||
if i > 0 {
|
if i > 0 {
|
||||||
_, _ = buf.WriteRune(',')
|
_ = buf.WriteByte(',')
|
||||||
}
|
}
|
||||||
copyAndEscape(buf, string(keyValue.Key))
|
copyAndEscape(buf, string(keyValue.Key))
|
||||||
|
|
||||||
_, _ = buf.WriteRune('=')
|
_ = buf.WriteByte('=')
|
||||||
|
|
||||||
if keyValue.Value.Type() == STRING {
|
if keyValue.Value.Type() == STRING {
|
||||||
copyAndEscape(buf, keyValue.Value.AsString())
|
copyAndEscape(buf, keyValue.Value.AsString())
|
||||||
|
|
@ -122,14 +122,14 @@ func copyAndEscape(buf *bytes.Buffer, val string) {
|
||||||
for _, ch := range val {
|
for _, ch := range val {
|
||||||
switch ch {
|
switch ch {
|
||||||
case '=', ',', escapeChar:
|
case '=', ',', escapeChar:
|
||||||
_, _ = buf.WriteRune(escapeChar)
|
_ = buf.WriteByte(escapeChar)
|
||||||
}
|
}
|
||||||
_, _ = buf.WriteRune(ch)
|
_, _ = buf.WriteRune(ch)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Valid returns true if this encoder ID was allocated by
|
// Valid reports whether this encoder ID was allocated by
|
||||||
// `NewEncoderID`. Invalid encoder IDs will not be cached.
|
// [NewEncoderID]. Invalid encoder IDs will not be cached.
|
||||||
func (id EncoderID) Valid() bool {
|
func (id EncoderID) Valid() bool {
|
||||||
return id.value != 0
|
return id.value != 0
|
||||||
}
|
}
|
||||||
|
|
|
||||||
8
vendor/go.opentelemetry.io/otel/attribute/filter.go
generated
vendored
8
vendor/go.opentelemetry.io/otel/attribute/filter.go
generated
vendored
|
|
@ -15,8 +15,8 @@ type Filter func(KeyValue) bool
|
||||||
//
|
//
|
||||||
// If keys is empty a deny-all filter is returned.
|
// If keys is empty a deny-all filter is returned.
|
||||||
func NewAllowKeysFilter(keys ...Key) Filter {
|
func NewAllowKeysFilter(keys ...Key) Filter {
|
||||||
if len(keys) <= 0 {
|
if len(keys) == 0 {
|
||||||
return func(kv KeyValue) bool { return false }
|
return func(KeyValue) bool { return false }
|
||||||
}
|
}
|
||||||
|
|
||||||
allowed := make(map[Key]struct{}, len(keys))
|
allowed := make(map[Key]struct{}, len(keys))
|
||||||
|
|
@ -34,8 +34,8 @@ func NewAllowKeysFilter(keys ...Key) Filter {
|
||||||
//
|
//
|
||||||
// If keys is empty an allow-all filter is returned.
|
// If keys is empty an allow-all filter is returned.
|
||||||
func NewDenyKeysFilter(keys ...Key) Filter {
|
func NewDenyKeysFilter(keys ...Key) Filter {
|
||||||
if len(keys) <= 0 {
|
if len(keys) == 0 {
|
||||||
return func(kv KeyValue) bool { return true }
|
return func(KeyValue) bool { return true }
|
||||||
}
|
}
|
||||||
|
|
||||||
forbid := make(map[Key]struct{}, len(keys))
|
forbid := make(map[Key]struct{}, len(keys))
|
||||||
|
|
|
||||||
16
vendor/go.opentelemetry.io/otel/attribute/internal/attribute.go
generated
vendored
16
vendor/go.opentelemetry.io/otel/attribute/internal/attribute.go
generated
vendored
|
|
@ -12,7 +12,7 @@ import (
|
||||||
)
|
)
|
||||||
|
|
||||||
// BoolSliceValue converts a bool slice into an array with same elements as slice.
|
// BoolSliceValue converts a bool slice into an array with same elements as slice.
|
||||||
func BoolSliceValue(v []bool) interface{} {
|
func BoolSliceValue(v []bool) any {
|
||||||
var zero bool
|
var zero bool
|
||||||
cp := reflect.New(reflect.ArrayOf(len(v), reflect.TypeOf(zero))).Elem()
|
cp := reflect.New(reflect.ArrayOf(len(v), reflect.TypeOf(zero))).Elem()
|
||||||
reflect.Copy(cp, reflect.ValueOf(v))
|
reflect.Copy(cp, reflect.ValueOf(v))
|
||||||
|
|
@ -20,7 +20,7 @@ func BoolSliceValue(v []bool) interface{} {
|
||||||
}
|
}
|
||||||
|
|
||||||
// Int64SliceValue converts an int64 slice into an array with same elements as slice.
|
// Int64SliceValue converts an int64 slice into an array with same elements as slice.
|
||||||
func Int64SliceValue(v []int64) interface{} {
|
func Int64SliceValue(v []int64) any {
|
||||||
var zero int64
|
var zero int64
|
||||||
cp := reflect.New(reflect.ArrayOf(len(v), reflect.TypeOf(zero))).Elem()
|
cp := reflect.New(reflect.ArrayOf(len(v), reflect.TypeOf(zero))).Elem()
|
||||||
reflect.Copy(cp, reflect.ValueOf(v))
|
reflect.Copy(cp, reflect.ValueOf(v))
|
||||||
|
|
@ -28,7 +28,7 @@ func Int64SliceValue(v []int64) interface{} {
|
||||||
}
|
}
|
||||||
|
|
||||||
// Float64SliceValue converts a float64 slice into an array with same elements as slice.
|
// Float64SliceValue converts a float64 slice into an array with same elements as slice.
|
||||||
func Float64SliceValue(v []float64) interface{} {
|
func Float64SliceValue(v []float64) any {
|
||||||
var zero float64
|
var zero float64
|
||||||
cp := reflect.New(reflect.ArrayOf(len(v), reflect.TypeOf(zero))).Elem()
|
cp := reflect.New(reflect.ArrayOf(len(v), reflect.TypeOf(zero))).Elem()
|
||||||
reflect.Copy(cp, reflect.ValueOf(v))
|
reflect.Copy(cp, reflect.ValueOf(v))
|
||||||
|
|
@ -36,7 +36,7 @@ func Float64SliceValue(v []float64) interface{} {
|
||||||
}
|
}
|
||||||
|
|
||||||
// StringSliceValue converts a string slice into an array with same elements as slice.
|
// StringSliceValue converts a string slice into an array with same elements as slice.
|
||||||
func StringSliceValue(v []string) interface{} {
|
func StringSliceValue(v []string) any {
|
||||||
var zero string
|
var zero string
|
||||||
cp := reflect.New(reflect.ArrayOf(len(v), reflect.TypeOf(zero))).Elem()
|
cp := reflect.New(reflect.ArrayOf(len(v), reflect.TypeOf(zero))).Elem()
|
||||||
reflect.Copy(cp, reflect.ValueOf(v))
|
reflect.Copy(cp, reflect.ValueOf(v))
|
||||||
|
|
@ -44,7 +44,7 @@ func StringSliceValue(v []string) interface{} {
|
||||||
}
|
}
|
||||||
|
|
||||||
// AsBoolSlice converts a bool array into a slice into with same elements as array.
|
// AsBoolSlice converts a bool array into a slice into with same elements as array.
|
||||||
func AsBoolSlice(v interface{}) []bool {
|
func AsBoolSlice(v any) []bool {
|
||||||
rv := reflect.ValueOf(v)
|
rv := reflect.ValueOf(v)
|
||||||
if rv.Type().Kind() != reflect.Array {
|
if rv.Type().Kind() != reflect.Array {
|
||||||
return nil
|
return nil
|
||||||
|
|
@ -57,7 +57,7 @@ func AsBoolSlice(v interface{}) []bool {
|
||||||
}
|
}
|
||||||
|
|
||||||
// AsInt64Slice converts an int64 array into a slice into with same elements as array.
|
// AsInt64Slice converts an int64 array into a slice into with same elements as array.
|
||||||
func AsInt64Slice(v interface{}) []int64 {
|
func AsInt64Slice(v any) []int64 {
|
||||||
rv := reflect.ValueOf(v)
|
rv := reflect.ValueOf(v)
|
||||||
if rv.Type().Kind() != reflect.Array {
|
if rv.Type().Kind() != reflect.Array {
|
||||||
return nil
|
return nil
|
||||||
|
|
@ -70,7 +70,7 @@ func AsInt64Slice(v interface{}) []int64 {
|
||||||
}
|
}
|
||||||
|
|
||||||
// AsFloat64Slice converts a float64 array into a slice into with same elements as array.
|
// AsFloat64Slice converts a float64 array into a slice into with same elements as array.
|
||||||
func AsFloat64Slice(v interface{}) []float64 {
|
func AsFloat64Slice(v any) []float64 {
|
||||||
rv := reflect.ValueOf(v)
|
rv := reflect.ValueOf(v)
|
||||||
if rv.Type().Kind() != reflect.Array {
|
if rv.Type().Kind() != reflect.Array {
|
||||||
return nil
|
return nil
|
||||||
|
|
@ -83,7 +83,7 @@ func AsFloat64Slice(v interface{}) []float64 {
|
||||||
}
|
}
|
||||||
|
|
||||||
// AsStringSlice converts a string array into a slice into with same elements as array.
|
// AsStringSlice converts a string array into a slice into with same elements as array.
|
||||||
func AsStringSlice(v interface{}) []string {
|
func AsStringSlice(v any) []string {
|
||||||
rv := reflect.ValueOf(v)
|
rv := reflect.ValueOf(v)
|
||||||
if rv.Type().Kind() != reflect.Array {
|
if rv.Type().Kind() != reflect.Array {
|
||||||
return nil
|
return nil
|
||||||
|
|
|
||||||
7
vendor/go.opentelemetry.io/otel/attribute/iterator.go
generated
vendored
7
vendor/go.opentelemetry.io/otel/attribute/iterator.go
generated
vendored
|
|
@ -25,8 +25,8 @@ type oneIterator struct {
|
||||||
attr KeyValue
|
attr KeyValue
|
||||||
}
|
}
|
||||||
|
|
||||||
// Next moves the iterator to the next position. Returns false if there are no
|
// Next moves the iterator to the next position.
|
||||||
// more attributes.
|
// Next reports whether there are more attributes.
|
||||||
func (i *Iterator) Next() bool {
|
func (i *Iterator) Next() bool {
|
||||||
i.idx++
|
i.idx++
|
||||||
return i.idx < i.Len()
|
return i.idx < i.Len()
|
||||||
|
|
@ -106,7 +106,8 @@ func (oi *oneIterator) advance() {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Next returns true if there is another attribute available.
|
// Next moves the iterator to the next position.
|
||||||
|
// Next reports whether there is another attribute available.
|
||||||
func (m *MergeIterator) Next() bool {
|
func (m *MergeIterator) Next() bool {
|
||||||
if m.one.done && m.two.done {
|
if m.one.done && m.two.done {
|
||||||
return false
|
return false
|
||||||
|
|
|
||||||
2
vendor/go.opentelemetry.io/otel/attribute/key.go
generated
vendored
2
vendor/go.opentelemetry.io/otel/attribute/key.go
generated
vendored
|
|
@ -117,7 +117,7 @@ func (k Key) StringSlice(v []string) KeyValue {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Defined returns true for non-empty keys.
|
// Defined reports whether the key is not empty.
|
||||||
func (k Key) Defined() bool {
|
func (k Key) Defined() bool {
|
||||||
return len(k) != 0
|
return len(k) != 0
|
||||||
}
|
}
|
||||||
|
|
|
||||||
2
vendor/go.opentelemetry.io/otel/attribute/kv.go
generated
vendored
2
vendor/go.opentelemetry.io/otel/attribute/kv.go
generated
vendored
|
|
@ -13,7 +13,7 @@ type KeyValue struct {
|
||||||
Value Value
|
Value Value
|
||||||
}
|
}
|
||||||
|
|
||||||
// Valid returns if kv is a valid OpenTelemetry attribute.
|
// Valid reports whether kv is a valid OpenTelemetry attribute.
|
||||||
func (kv KeyValue) Valid() bool {
|
func (kv KeyValue) Valid() bool {
|
||||||
return kv.Key.Defined() && kv.Value.Type() != INVALID
|
return kv.Key.Defined() && kv.Value.Type() != INVALID
|
||||||
}
|
}
|
||||||
|
|
|
||||||
20
vendor/go.opentelemetry.io/otel/attribute/set.go
generated
vendored
20
vendor/go.opentelemetry.io/otel/attribute/set.go
generated
vendored
|
|
@ -31,11 +31,11 @@ type (
|
||||||
|
|
||||||
// Distinct is a unique identifier of a Set.
|
// Distinct is a unique identifier of a Set.
|
||||||
//
|
//
|
||||||
// Distinct is designed to be ensures equivalence stability: comparisons
|
// Distinct is designed to ensure equivalence stability: comparisons will
|
||||||
// will return the save value across versions. For this reason, Distinct
|
// return the same value across versions. For this reason, Distinct should
|
||||||
// should always be used as a map key instead of a Set.
|
// always be used as a map key instead of a Set.
|
||||||
Distinct struct {
|
Distinct struct {
|
||||||
iface interface{}
|
iface any
|
||||||
}
|
}
|
||||||
|
|
||||||
// Sortable implements sort.Interface, used for sorting KeyValue.
|
// Sortable implements sort.Interface, used for sorting KeyValue.
|
||||||
|
|
@ -70,7 +70,7 @@ func (d Distinct) reflectValue() reflect.Value {
|
||||||
return reflect.ValueOf(d.iface)
|
return reflect.ValueOf(d.iface)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Valid returns true if this value refers to a valid Set.
|
// Valid reports whether this value refers to a valid Set.
|
||||||
func (d Distinct) Valid() bool {
|
func (d Distinct) Valid() bool {
|
||||||
return d.iface != nil
|
return d.iface != nil
|
||||||
}
|
}
|
||||||
|
|
@ -120,7 +120,7 @@ func (l *Set) Value(k Key) (Value, bool) {
|
||||||
return Value{}, false
|
return Value{}, false
|
||||||
}
|
}
|
||||||
|
|
||||||
// HasValue tests whether a key is defined in this set.
|
// HasValue reports whether a key is defined in this set.
|
||||||
func (l *Set) HasValue(k Key) bool {
|
func (l *Set) HasValue(k Key) bool {
|
||||||
if l == nil {
|
if l == nil {
|
||||||
return false
|
return false
|
||||||
|
|
@ -155,7 +155,7 @@ func (l *Set) Equivalent() Distinct {
|
||||||
return l.equivalent
|
return l.equivalent
|
||||||
}
|
}
|
||||||
|
|
||||||
// Equals returns true if the argument set is equivalent to this set.
|
// Equals reports whether the argument set is equivalent to this set.
|
||||||
func (l *Set) Equals(o *Set) bool {
|
func (l *Set) Equals(o *Set) bool {
|
||||||
return l.Equivalent() == o.Equivalent()
|
return l.Equivalent() == o.Equivalent()
|
||||||
}
|
}
|
||||||
|
|
@ -344,7 +344,7 @@ func computeDistinct(kvs []KeyValue) Distinct {
|
||||||
|
|
||||||
// computeDistinctFixed computes a Distinct for small slices. It returns nil
|
// computeDistinctFixed computes a Distinct for small slices. It returns nil
|
||||||
// if the input is too large for this code path.
|
// if the input is too large for this code path.
|
||||||
func computeDistinctFixed(kvs []KeyValue) interface{} {
|
func computeDistinctFixed(kvs []KeyValue) any {
|
||||||
switch len(kvs) {
|
switch len(kvs) {
|
||||||
case 1:
|
case 1:
|
||||||
return [1]KeyValue(kvs)
|
return [1]KeyValue(kvs)
|
||||||
|
|
@ -373,7 +373,7 @@ func computeDistinctFixed(kvs []KeyValue) interface{} {
|
||||||
|
|
||||||
// computeDistinctReflect computes a Distinct using reflection, works for any
|
// computeDistinctReflect computes a Distinct using reflection, works for any
|
||||||
// size input.
|
// size input.
|
||||||
func computeDistinctReflect(kvs []KeyValue) interface{} {
|
func computeDistinctReflect(kvs []KeyValue) any {
|
||||||
at := reflect.New(reflect.ArrayOf(len(kvs), keyValueType)).Elem()
|
at := reflect.New(reflect.ArrayOf(len(kvs), keyValueType)).Elem()
|
||||||
for i, keyValue := range kvs {
|
for i, keyValue := range kvs {
|
||||||
*(at.Index(i).Addr().Interface().(*KeyValue)) = keyValue
|
*(at.Index(i).Addr().Interface().(*KeyValue)) = keyValue
|
||||||
|
|
@ -387,7 +387,7 @@ func (l *Set) MarshalJSON() ([]byte, error) {
|
||||||
}
|
}
|
||||||
|
|
||||||
// MarshalLog is the marshaling function used by the logging system to represent this Set.
|
// MarshalLog is the marshaling function used by the logging system to represent this Set.
|
||||||
func (l Set) MarshalLog() interface{} {
|
func (l Set) MarshalLog() any {
|
||||||
kvs := make(map[string]string)
|
kvs := make(map[string]string)
|
||||||
for _, kv := range l.ToSlice() {
|
for _, kv := range l.ToSlice() {
|
||||||
kvs[string(kv.Key)] = kv.Value.Emit()
|
kvs[string(kv.Key)] = kv.Value.Emit()
|
||||||
|
|
|
||||||
8
vendor/go.opentelemetry.io/otel/attribute/value.go
generated
vendored
8
vendor/go.opentelemetry.io/otel/attribute/value.go
generated
vendored
|
|
@ -22,7 +22,7 @@ type Value struct {
|
||||||
vtype Type
|
vtype Type
|
||||||
numeric uint64
|
numeric uint64
|
||||||
stringly string
|
stringly string
|
||||||
slice interface{}
|
slice any
|
||||||
}
|
}
|
||||||
|
|
||||||
const (
|
const (
|
||||||
|
|
@ -199,8 +199,8 @@ func (v Value) asStringSlice() []string {
|
||||||
|
|
||||||
type unknownValueType struct{}
|
type unknownValueType struct{}
|
||||||
|
|
||||||
// AsInterface returns Value's data as interface{}.
|
// AsInterface returns Value's data as any.
|
||||||
func (v Value) AsInterface() interface{} {
|
func (v Value) AsInterface() any {
|
||||||
switch v.Type() {
|
switch v.Type() {
|
||||||
case BOOL:
|
case BOOL:
|
||||||
return v.AsBool()
|
return v.AsBool()
|
||||||
|
|
@ -262,7 +262,7 @@ func (v Value) Emit() string {
|
||||||
func (v Value) MarshalJSON() ([]byte, error) {
|
func (v Value) MarshalJSON() ([]byte, error) {
|
||||||
var jsonVal struct {
|
var jsonVal struct {
|
||||||
Type string
|
Type string
|
||||||
Value interface{}
|
Value any
|
||||||
}
|
}
|
||||||
jsonVal.Type = v.Type().String()
|
jsonVal.Type = v.Type().String()
|
||||||
jsonVal.Value = v.AsInterface()
|
jsonVal.Value = v.AsInterface()
|
||||||
|
|
|
||||||
4
vendor/go.opentelemetry.io/otel/baggage/baggage.go
generated
vendored
4
vendor/go.opentelemetry.io/otel/baggage/baggage.go
generated
vendored
|
|
@ -812,7 +812,7 @@ var safeKeyCharset = [utf8.RuneSelf]bool{
|
||||||
// validateBaggageName checks if the string is a valid OpenTelemetry Baggage name.
|
// validateBaggageName checks if the string is a valid OpenTelemetry Baggage name.
|
||||||
// Baggage name is a valid, non-empty UTF-8 string.
|
// Baggage name is a valid, non-empty UTF-8 string.
|
||||||
func validateBaggageName(s string) bool {
|
func validateBaggageName(s string) bool {
|
||||||
if len(s) == 0 {
|
if s == "" {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -828,7 +828,7 @@ func validateBaggageValue(s string) bool {
|
||||||
|
|
||||||
// validateKey checks if the string is a valid W3C Baggage key.
|
// validateKey checks if the string is a valid W3C Baggage key.
|
||||||
func validateKey(s string) bool {
|
func validateKey(s string) bool {
|
||||||
if len(s) == 0 {
|
if s == "" {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
4
vendor/go.opentelemetry.io/otel/codes/codes.go
generated
vendored
4
vendor/go.opentelemetry.io/otel/codes/codes.go
generated
vendored
|
|
@ -67,7 +67,7 @@ func (c *Code) UnmarshalJSON(b []byte) error {
|
||||||
return errors.New("nil receiver passed to UnmarshalJSON")
|
return errors.New("nil receiver passed to UnmarshalJSON")
|
||||||
}
|
}
|
||||||
|
|
||||||
var x interface{}
|
var x any
|
||||||
if err := json.Unmarshal(b, &x); err != nil {
|
if err := json.Unmarshal(b, &x); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
@ -102,5 +102,5 @@ func (c *Code) MarshalJSON() ([]byte, error) {
|
||||||
if !ok {
|
if !ok {
|
||||||
return nil, fmt.Errorf("invalid code: %d", *c)
|
return nil, fmt.Errorf("invalid code: %d", *c)
|
||||||
}
|
}
|
||||||
return []byte(fmt.Sprintf("%q", str)), nil
|
return fmt.Appendf(nil, "%q", str), nil
|
||||||
}
|
}
|
||||||
|
|
|
||||||
4
vendor/go.opentelemetry.io/otel/dependencies.Dockerfile
generated
vendored
4
vendor/go.opentelemetry.io/otel/dependencies.Dockerfile
generated
vendored
|
|
@ -1,4 +1,4 @@
|
||||||
# This is a renovate-friendly source of Docker images.
|
# This is a renovate-friendly source of Docker images.
|
||||||
FROM python:3.13.3-slim-bullseye@sha256:9e3f9243e06fd68eb9519074b49878eda20ad39a855fac51aaffb741de20726e AS python
|
FROM python:3.13.6-slim-bullseye@sha256:e98b521460ee75bca92175c16247bdf7275637a8faaeb2bcfa19d879ae5c4b9a AS python
|
||||||
FROM otel/weaver:v0.15.0@sha256:1cf1c72eaed57dad813c2e359133b8a15bd4facf305aae5b13bdca6d3eccff56 AS weaver
|
FROM otel/weaver:v0.17.1@sha256:32523b5e44fb44418786347e9f7dde187d8797adb6d57a2ee99c245346c3cdfe AS weaver
|
||||||
FROM avtodev/markdown-lint:v1@sha256:6aeedc2f49138ce7a1cd0adffc1b1c0321b841dc2102408967d9301c031949ee AS markdown
|
FROM avtodev/markdown-lint:v1@sha256:6aeedc2f49138ce7a1cd0adffc1b1c0321b841dc2102408967d9301c031949ee AS markdown
|
||||||
|
|
|
||||||
8
vendor/go.opentelemetry.io/otel/internal/global/internal_logging.go
generated
vendored
8
vendor/go.opentelemetry.io/otel/internal/global/internal_logging.go
generated
vendored
|
|
@ -41,22 +41,22 @@ func GetLogger() logr.Logger {
|
||||||
|
|
||||||
// Info prints messages about the general state of the API or SDK.
|
// Info prints messages about the general state of the API or SDK.
|
||||||
// This should usually be less than 5 messages a minute.
|
// This should usually be less than 5 messages a minute.
|
||||||
func Info(msg string, keysAndValues ...interface{}) {
|
func Info(msg string, keysAndValues ...any) {
|
||||||
GetLogger().V(4).Info(msg, keysAndValues...)
|
GetLogger().V(4).Info(msg, keysAndValues...)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Error prints messages about exceptional states of the API or SDK.
|
// Error prints messages about exceptional states of the API or SDK.
|
||||||
func Error(err error, msg string, keysAndValues ...interface{}) {
|
func Error(err error, msg string, keysAndValues ...any) {
|
||||||
GetLogger().Error(err, msg, keysAndValues...)
|
GetLogger().Error(err, msg, keysAndValues...)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Debug prints messages about all internal changes in the API or SDK.
|
// Debug prints messages about all internal changes in the API or SDK.
|
||||||
func Debug(msg string, keysAndValues ...interface{}) {
|
func Debug(msg string, keysAndValues ...any) {
|
||||||
GetLogger().V(8).Info(msg, keysAndValues...)
|
GetLogger().V(8).Info(msg, keysAndValues...)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Warn prints messages about warnings in the API or SDK.
|
// Warn prints messages about warnings in the API or SDK.
|
||||||
// Not an error but is likely more important than an informational event.
|
// Not an error but is likely more important than an informational event.
|
||||||
func Warn(msg string, keysAndValues ...interface{}) {
|
func Warn(msg string, keysAndValues ...any) {
|
||||||
GetLogger().V(1).Info(msg, keysAndValues...)
|
GetLogger().V(1).Info(msg, keysAndValues...)
|
||||||
}
|
}
|
||||||
|
|
|
||||||
1
vendor/go.opentelemetry.io/otel/internal/global/trace.go
generated
vendored
1
vendor/go.opentelemetry.io/otel/internal/global/trace.go
generated
vendored
|
|
@ -26,6 +26,7 @@ import (
|
||||||
"sync/atomic"
|
"sync/atomic"
|
||||||
|
|
||||||
"go.opentelemetry.io/auto/sdk"
|
"go.opentelemetry.io/auto/sdk"
|
||||||
|
|
||||||
"go.opentelemetry.io/otel/attribute"
|
"go.opentelemetry.io/otel/attribute"
|
||||||
"go.opentelemetry.io/otel/codes"
|
"go.opentelemetry.io/otel/codes"
|
||||||
"go.opentelemetry.io/otel/trace"
|
"go.opentelemetry.io/otel/trace"
|
||||||
|
|
|
||||||
30
vendor/go.opentelemetry.io/otel/metric/LICENSE
generated
vendored
30
vendor/go.opentelemetry.io/otel/metric/LICENSE
generated
vendored
|
|
@ -199,3 +199,33 @@
|
||||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||||
See the License for the specific language governing permissions and
|
See the License for the specific language governing permissions and
|
||||||
limitations under the License.
|
limitations under the License.
|
||||||
|
|
||||||
|
--------------------------------------------------------------------------------
|
||||||
|
|
||||||
|
Copyright 2009 The Go Authors.
|
||||||
|
|
||||||
|
Redistribution and use in source and binary forms, with or without
|
||||||
|
modification, are permitted provided that the following conditions are
|
||||||
|
met:
|
||||||
|
|
||||||
|
* Redistributions of source code must retain the above copyright
|
||||||
|
notice, this list of conditions and the following disclaimer.
|
||||||
|
* Redistributions in binary form must reproduce the above
|
||||||
|
copyright notice, this list of conditions and the following disclaimer
|
||||||
|
in the documentation and/or other materials provided with the
|
||||||
|
distribution.
|
||||||
|
* Neither the name of Google LLC nor the names of its
|
||||||
|
contributors may be used to endorse or promote products derived from
|
||||||
|
this software without specific prior written permission.
|
||||||
|
|
||||||
|
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||||
|
"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||||
|
LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
|
||||||
|
A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
||||||
|
OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
||||||
|
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
|
||||||
|
LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
||||||
|
DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
||||||
|
THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
||||||
|
(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
|
||||||
|
OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||||
6
vendor/go.opentelemetry.io/otel/propagation/baggage.go
generated
vendored
6
vendor/go.opentelemetry.io/otel/propagation/baggage.go
generated
vendored
|
|
@ -20,7 +20,7 @@ type Baggage struct{}
|
||||||
var _ TextMapPropagator = Baggage{}
|
var _ TextMapPropagator = Baggage{}
|
||||||
|
|
||||||
// Inject sets baggage key-values from ctx into the carrier.
|
// Inject sets baggage key-values from ctx into the carrier.
|
||||||
func (b Baggage) Inject(ctx context.Context, carrier TextMapCarrier) {
|
func (Baggage) Inject(ctx context.Context, carrier TextMapCarrier) {
|
||||||
bStr := baggage.FromContext(ctx).String()
|
bStr := baggage.FromContext(ctx).String()
|
||||||
if bStr != "" {
|
if bStr != "" {
|
||||||
carrier.Set(baggageHeader, bStr)
|
carrier.Set(baggageHeader, bStr)
|
||||||
|
|
@ -30,7 +30,7 @@ func (b Baggage) Inject(ctx context.Context, carrier TextMapCarrier) {
|
||||||
// Extract returns a copy of parent with the baggage from the carrier added.
|
// Extract returns a copy of parent with the baggage from the carrier added.
|
||||||
// If carrier implements [ValuesGetter] (e.g. [HeaderCarrier]), Values is invoked
|
// If carrier implements [ValuesGetter] (e.g. [HeaderCarrier]), Values is invoked
|
||||||
// for multiple values extraction. Otherwise, Get is called.
|
// for multiple values extraction. Otherwise, Get is called.
|
||||||
func (b Baggage) Extract(parent context.Context, carrier TextMapCarrier) context.Context {
|
func (Baggage) Extract(parent context.Context, carrier TextMapCarrier) context.Context {
|
||||||
if multiCarrier, ok := carrier.(ValuesGetter); ok {
|
if multiCarrier, ok := carrier.(ValuesGetter); ok {
|
||||||
return extractMultiBaggage(parent, multiCarrier)
|
return extractMultiBaggage(parent, multiCarrier)
|
||||||
}
|
}
|
||||||
|
|
@ -38,7 +38,7 @@ func (b Baggage) Extract(parent context.Context, carrier TextMapCarrier) context
|
||||||
}
|
}
|
||||||
|
|
||||||
// Fields returns the keys who's values are set with Inject.
|
// Fields returns the keys who's values are set with Inject.
|
||||||
func (b Baggage) Fields() []string {
|
func (Baggage) Fields() []string {
|
||||||
return []string{baggageHeader}
|
return []string{baggageHeader}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
4
vendor/go.opentelemetry.io/otel/propagation/propagation.go
generated
vendored
4
vendor/go.opentelemetry.io/otel/propagation/propagation.go
generated
vendored
|
|
@ -20,7 +20,7 @@ type TextMapCarrier interface {
|
||||||
// must never be done outside of a new major release.
|
// must never be done outside of a new major release.
|
||||||
|
|
||||||
// Set stores the key-value pair.
|
// Set stores the key-value pair.
|
||||||
Set(key string, value string)
|
Set(key, value string)
|
||||||
// DO NOT CHANGE: any modification will not be backwards compatible and
|
// DO NOT CHANGE: any modification will not be backwards compatible and
|
||||||
// must never be done outside of a new major release.
|
// must never be done outside of a new major release.
|
||||||
|
|
||||||
|
|
@ -88,7 +88,7 @@ func (hc HeaderCarrier) Values(key string) []string {
|
||||||
}
|
}
|
||||||
|
|
||||||
// Set stores the key-value pair.
|
// Set stores the key-value pair.
|
||||||
func (hc HeaderCarrier) Set(key string, value string) {
|
func (hc HeaderCarrier) Set(key, value string) {
|
||||||
http.Header(hc).Set(key, value)
|
http.Header(hc).Set(key, value)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
6
vendor/go.opentelemetry.io/otel/propagation/trace_context.go
generated
vendored
6
vendor/go.opentelemetry.io/otel/propagation/trace_context.go
generated
vendored
|
|
@ -36,7 +36,7 @@ var (
|
||||||
)
|
)
|
||||||
|
|
||||||
// Inject injects the trace context from ctx into carrier.
|
// Inject injects the trace context from ctx into carrier.
|
||||||
func (tc TraceContext) Inject(ctx context.Context, carrier TextMapCarrier) {
|
func (TraceContext) Inject(ctx context.Context, carrier TextMapCarrier) {
|
||||||
sc := trace.SpanContextFromContext(ctx)
|
sc := trace.SpanContextFromContext(ctx)
|
||||||
if !sc.IsValid() {
|
if !sc.IsValid() {
|
||||||
return
|
return
|
||||||
|
|
@ -77,7 +77,7 @@ func (tc TraceContext) Extract(ctx context.Context, carrier TextMapCarrier) cont
|
||||||
return trace.ContextWithRemoteSpanContext(ctx, sc)
|
return trace.ContextWithRemoteSpanContext(ctx, sc)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (tc TraceContext) extract(carrier TextMapCarrier) trace.SpanContext {
|
func (TraceContext) extract(carrier TextMapCarrier) trace.SpanContext {
|
||||||
h := carrier.Get(traceparentHeader)
|
h := carrier.Get(traceparentHeader)
|
||||||
if h == "" {
|
if h == "" {
|
||||||
return trace.SpanContext{}
|
return trace.SpanContext{}
|
||||||
|
|
@ -151,6 +151,6 @@ func extractPart(dst []byte, h *string, n int) bool {
|
||||||
}
|
}
|
||||||
|
|
||||||
// Fields returns the keys who's values are set with Inject.
|
// Fields returns the keys who's values are set with Inject.
|
||||||
func (tc TraceContext) Fields() []string {
|
func (TraceContext) Fields() []string {
|
||||||
return []string{traceparentHeader, tracestateHeader}
|
return []string{traceparentHeader, tracestateHeader}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
3
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/README.md
generated
vendored
3
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/README.md
generated
vendored
|
|
@ -1,3 +0,0 @@
|
||||||
# Semconv v1.20.0
|
|
||||||
|
|
||||||
[](https://pkg.go.dev/go.opentelemetry.io/otel/semconv/v1.20.0)
|
|
||||||
1198
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/attribute_group.go
generated
vendored
1198
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/attribute_group.go
generated
vendored
File diff suppressed because it is too large
Load diff
9
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/doc.go
generated
vendored
9
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/doc.go
generated
vendored
|
|
@ -1,9 +0,0 @@
|
||||||
// Copyright The OpenTelemetry Authors
|
|
||||||
// SPDX-License-Identifier: Apache-2.0
|
|
||||||
|
|
||||||
// Package semconv implements OpenTelemetry semantic conventions.
|
|
||||||
//
|
|
||||||
// OpenTelemetry semantic conventions are agreed standardized naming
|
|
||||||
// patterns for OpenTelemetry things. This package represents the conventions
|
|
||||||
// as of the v1.20.0 version of the OpenTelemetry specification.
|
|
||||||
package semconv // import "go.opentelemetry.io/otel/semconv/v1.20.0"
|
|
||||||
188
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/event.go
generated
vendored
188
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/event.go
generated
vendored
|
|
@ -1,188 +0,0 @@
|
||||||
// Copyright The OpenTelemetry Authors
|
|
||||||
// SPDX-License-Identifier: Apache-2.0
|
|
||||||
|
|
||||||
// Code generated from semantic convention specification. DO NOT EDIT.
|
|
||||||
|
|
||||||
package semconv // import "go.opentelemetry.io/otel/semconv/v1.20.0"
|
|
||||||
|
|
||||||
import "go.opentelemetry.io/otel/attribute"
|
|
||||||
|
|
||||||
// This semantic convention defines the attributes used to represent a feature
|
|
||||||
// flag evaluation as an event.
|
|
||||||
const (
|
|
||||||
// FeatureFlagKeyKey is the attribute Key conforming to the
|
|
||||||
// "feature_flag.key" semantic conventions. It represents the unique
|
|
||||||
// identifier of the feature flag.
|
|
||||||
//
|
|
||||||
// Type: string
|
|
||||||
// RequirementLevel: Required
|
|
||||||
// Stability: stable
|
|
||||||
// Examples: 'logo-color'
|
|
||||||
FeatureFlagKeyKey = attribute.Key("feature_flag.key")
|
|
||||||
|
|
||||||
// FeatureFlagProviderNameKey is the attribute Key conforming to the
|
|
||||||
// "feature_flag.provider_name" semantic conventions. It represents the
|
|
||||||
// name of the service provider that performs the flag evaluation.
|
|
||||||
//
|
|
||||||
// Type: string
|
|
||||||
// RequirementLevel: Recommended
|
|
||||||
// Stability: stable
|
|
||||||
// Examples: 'Flag Manager'
|
|
||||||
FeatureFlagProviderNameKey = attribute.Key("feature_flag.provider_name")
|
|
||||||
|
|
||||||
// FeatureFlagVariantKey is the attribute Key conforming to the
|
|
||||||
// "feature_flag.variant" semantic conventions. It represents the sHOULD be
|
|
||||||
// a semantic identifier for a value. If one is unavailable, a stringified
|
|
||||||
// version of the value can be used.
|
|
||||||
//
|
|
||||||
// Type: string
|
|
||||||
// RequirementLevel: Recommended
|
|
||||||
// Stability: stable
|
|
||||||
// Examples: 'red', 'true', 'on'
|
|
||||||
// Note: A semantic identifier, commonly referred to as a variant, provides
|
|
||||||
// a means
|
|
||||||
// for referring to a value without including the value itself. This can
|
|
||||||
// provide additional context for understanding the meaning behind a value.
|
|
||||||
// For example, the variant `red` maybe be used for the value `#c05543`.
|
|
||||||
//
|
|
||||||
// A stringified version of the value can be used in situations where a
|
|
||||||
// semantic identifier is unavailable. String representation of the value
|
|
||||||
// should be determined by the implementer.
|
|
||||||
FeatureFlagVariantKey = attribute.Key("feature_flag.variant")
|
|
||||||
)
|
|
||||||
|
|
||||||
// FeatureFlagKey returns an attribute KeyValue conforming to the
|
|
||||||
// "feature_flag.key" semantic conventions. It represents the unique identifier
|
|
||||||
// of the feature flag.
|
|
||||||
func FeatureFlagKey(val string) attribute.KeyValue {
|
|
||||||
return FeatureFlagKeyKey.String(val)
|
|
||||||
}
|
|
||||||
|
|
||||||
// FeatureFlagProviderName returns an attribute KeyValue conforming to the
|
|
||||||
// "feature_flag.provider_name" semantic conventions. It represents the name of
|
|
||||||
// the service provider that performs the flag evaluation.
|
|
||||||
func FeatureFlagProviderName(val string) attribute.KeyValue {
|
|
||||||
return FeatureFlagProviderNameKey.String(val)
|
|
||||||
}
|
|
||||||
|
|
||||||
// FeatureFlagVariant returns an attribute KeyValue conforming to the
|
|
||||||
// "feature_flag.variant" semantic conventions. It represents the sHOULD be a
|
|
||||||
// semantic identifier for a value. If one is unavailable, a stringified
|
|
||||||
// version of the value can be used.
|
|
||||||
func FeatureFlagVariant(val string) attribute.KeyValue {
|
|
||||||
return FeatureFlagVariantKey.String(val)
|
|
||||||
}
|
|
||||||
|
|
||||||
// RPC received/sent message.
|
|
||||||
const (
|
|
||||||
// MessageTypeKey is the attribute Key conforming to the "message.type"
|
|
||||||
// semantic conventions. It represents the whether this is a received or
|
|
||||||
// sent message.
|
|
||||||
//
|
|
||||||
// Type: Enum
|
|
||||||
// RequirementLevel: Optional
|
|
||||||
// Stability: stable
|
|
||||||
MessageTypeKey = attribute.Key("message.type")
|
|
||||||
|
|
||||||
// MessageIDKey is the attribute Key conforming to the "message.id"
|
|
||||||
// semantic conventions. It represents the mUST be calculated as two
|
|
||||||
// different counters starting from `1` one for sent messages and one for
|
|
||||||
// received message.
|
|
||||||
//
|
|
||||||
// Type: int
|
|
||||||
// RequirementLevel: Optional
|
|
||||||
// Stability: stable
|
|
||||||
// Note: This way we guarantee that the values will be consistent between
|
|
||||||
// different implementations.
|
|
||||||
MessageIDKey = attribute.Key("message.id")
|
|
||||||
|
|
||||||
// MessageCompressedSizeKey is the attribute Key conforming to the
|
|
||||||
// "message.compressed_size" semantic conventions. It represents the
|
|
||||||
// compressed size of the message in bytes.
|
|
||||||
//
|
|
||||||
// Type: int
|
|
||||||
// RequirementLevel: Optional
|
|
||||||
// Stability: stable
|
|
||||||
MessageCompressedSizeKey = attribute.Key("message.compressed_size")
|
|
||||||
|
|
||||||
// MessageUncompressedSizeKey is the attribute Key conforming to the
|
|
||||||
// "message.uncompressed_size" semantic conventions. It represents the
|
|
||||||
// uncompressed size of the message in bytes.
|
|
||||||
//
|
|
||||||
// Type: int
|
|
||||||
// RequirementLevel: Optional
|
|
||||||
// Stability: stable
|
|
||||||
MessageUncompressedSizeKey = attribute.Key("message.uncompressed_size")
|
|
||||||
)
|
|
||||||
|
|
||||||
var (
|
|
||||||
// sent
|
|
||||||
MessageTypeSent = MessageTypeKey.String("SENT")
|
|
||||||
// received
|
|
||||||
MessageTypeReceived = MessageTypeKey.String("RECEIVED")
|
|
||||||
)
|
|
||||||
|
|
||||||
// MessageID returns an attribute KeyValue conforming to the "message.id"
|
|
||||||
// semantic conventions. It represents the mUST be calculated as two different
|
|
||||||
// counters starting from `1` one for sent messages and one for received
|
|
||||||
// message.
|
|
||||||
func MessageID(val int) attribute.KeyValue {
|
|
||||||
return MessageIDKey.Int(val)
|
|
||||||
}
|
|
||||||
|
|
||||||
// MessageCompressedSize returns an attribute KeyValue conforming to the
|
|
||||||
// "message.compressed_size" semantic conventions. It represents the compressed
|
|
||||||
// size of the message in bytes.
|
|
||||||
func MessageCompressedSize(val int) attribute.KeyValue {
|
|
||||||
return MessageCompressedSizeKey.Int(val)
|
|
||||||
}
|
|
||||||
|
|
||||||
// MessageUncompressedSize returns an attribute KeyValue conforming to the
|
|
||||||
// "message.uncompressed_size" semantic conventions. It represents the
|
|
||||||
// uncompressed size of the message in bytes.
|
|
||||||
func MessageUncompressedSize(val int) attribute.KeyValue {
|
|
||||||
return MessageUncompressedSizeKey.Int(val)
|
|
||||||
}
|
|
||||||
|
|
||||||
// The attributes used to report a single exception associated with a span.
|
|
||||||
const (
|
|
||||||
// ExceptionEscapedKey is the attribute Key conforming to the
|
|
||||||
// "exception.escaped" semantic conventions. It represents the sHOULD be
|
|
||||||
// set to true if the exception event is recorded at a point where it is
|
|
||||||
// known that the exception is escaping the scope of the span.
|
|
||||||
//
|
|
||||||
// Type: boolean
|
|
||||||
// RequirementLevel: Optional
|
|
||||||
// Stability: stable
|
|
||||||
// Note: An exception is considered to have escaped (or left) the scope of
|
|
||||||
// a span,
|
|
||||||
// if that span is ended while the exception is still logically "in
|
|
||||||
// flight".
|
|
||||||
// This may be actually "in flight" in some languages (e.g. if the
|
|
||||||
// exception
|
|
||||||
// is passed to a Context manager's `__exit__` method in Python) but will
|
|
||||||
// usually be caught at the point of recording the exception in most
|
|
||||||
// languages.
|
|
||||||
//
|
|
||||||
// It is usually not possible to determine at the point where an exception
|
|
||||||
// is thrown
|
|
||||||
// whether it will escape the scope of a span.
|
|
||||||
// However, it is trivial to know that an exception
|
|
||||||
// will escape, if one checks for an active exception just before ending
|
|
||||||
// the span,
|
|
||||||
// as done in the [example above](#recording-an-exception).
|
|
||||||
//
|
|
||||||
// It follows that an exception may still escape the scope of the span
|
|
||||||
// even if the `exception.escaped` attribute was not set or set to false,
|
|
||||||
// since the event might have been recorded at a time where it was not
|
|
||||||
// clear whether the exception will escape.
|
|
||||||
ExceptionEscapedKey = attribute.Key("exception.escaped")
|
|
||||||
)
|
|
||||||
|
|
||||||
// ExceptionEscaped returns an attribute KeyValue conforming to the
|
|
||||||
// "exception.escaped" semantic conventions. It represents the sHOULD be set to
|
|
||||||
// true if the exception event is recorded at a point where it is known that
|
|
||||||
// the exception is escaping the scope of the span.
|
|
||||||
func ExceptionEscaped(val bool) attribute.KeyValue {
|
|
||||||
return ExceptionEscapedKey.Bool(val)
|
|
||||||
}
|
|
||||||
10
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/http.go
generated
vendored
10
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/http.go
generated
vendored
|
|
@ -1,10 +0,0 @@
|
||||||
// Copyright The OpenTelemetry Authors
|
|
||||||
// SPDX-License-Identifier: Apache-2.0
|
|
||||||
|
|
||||||
package semconv // import "go.opentelemetry.io/otel/semconv/v1.20.0"
|
|
||||||
|
|
||||||
// HTTP scheme attributes.
|
|
||||||
var (
|
|
||||||
HTTPSchemeHTTP = HTTPSchemeKey.String("http")
|
|
||||||
HTTPSchemeHTTPS = HTTPSchemeKey.String("https")
|
|
||||||
)
|
|
||||||
2060
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/resource.go
generated
vendored
2060
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/resource.go
generated
vendored
File diff suppressed because it is too large
Load diff
9
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/schema.go
generated
vendored
9
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/schema.go
generated
vendored
|
|
@ -1,9 +0,0 @@
|
||||||
// Copyright The OpenTelemetry Authors
|
|
||||||
// SPDX-License-Identifier: Apache-2.0
|
|
||||||
|
|
||||||
package semconv // import "go.opentelemetry.io/otel/semconv/v1.20.0"
|
|
||||||
|
|
||||||
// SchemaURL is the schema URL that matches the version of the semantic conventions
|
|
||||||
// that this package defines. Semconv packages starting from v1.4.0 must declare
|
|
||||||
// non-empty schema URL in the form https://opentelemetry.io/schemas/<version>
|
|
||||||
const SchemaURL = "https://opentelemetry.io/schemas/1.20.0"
|
|
||||||
2599
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/trace.go
generated
vendored
2599
vendor/go.opentelemetry.io/otel/semconv/v1.20.0/trace.go
generated
vendored
File diff suppressed because it is too large
Load diff
3
vendor/go.opentelemetry.io/otel/semconv/v1.26.0/README.md
generated
vendored
3
vendor/go.opentelemetry.io/otel/semconv/v1.26.0/README.md
generated
vendored
|
|
@ -1,3 +0,0 @@
|
||||||
# Semconv v1.26.0
|
|
||||||
|
|
||||||
[](https://pkg.go.dev/go.opentelemetry.io/otel/semconv/v1.26.0)
|
|
||||||
8996
vendor/go.opentelemetry.io/otel/semconv/v1.26.0/attribute_group.go
generated
vendored
8996
vendor/go.opentelemetry.io/otel/semconv/v1.26.0/attribute_group.go
generated
vendored
File diff suppressed because it is too large
Load diff
9
vendor/go.opentelemetry.io/otel/semconv/v1.26.0/exception.go
generated
vendored
9
vendor/go.opentelemetry.io/otel/semconv/v1.26.0/exception.go
generated
vendored
|
|
@ -1,9 +0,0 @@
|
||||||
// Copyright The OpenTelemetry Authors
|
|
||||||
// SPDX-License-Identifier: Apache-2.0
|
|
||||||
|
|
||||||
package semconv // import "go.opentelemetry.io/otel/semconv/v1.26.0"
|
|
||||||
|
|
||||||
const (
|
|
||||||
// ExceptionEventName is the name of the Span event representing an exception.
|
|
||||||
ExceptionEventName = "exception"
|
|
||||||
)
|
|
||||||
1307
vendor/go.opentelemetry.io/otel/semconv/v1.26.0/metric.go
generated
vendored
1307
vendor/go.opentelemetry.io/otel/semconv/v1.26.0/metric.go
generated
vendored
File diff suppressed because it is too large
Load diff
41
vendor/go.opentelemetry.io/otel/semconv/v1.37.0/MIGRATION.md
generated
vendored
Normal file
41
vendor/go.opentelemetry.io/otel/semconv/v1.37.0/MIGRATION.md
generated
vendored
Normal file
|
|
@ -0,0 +1,41 @@
|
||||||
|
<!-- Generated. DO NOT MODIFY. -->
|
||||||
|
# Migration from v1.36.0 to v1.37.0
|
||||||
|
|
||||||
|
The `go.opentelemetry.io/otel/semconv/v1.37.0` package should be a drop-in replacement for `go.opentelemetry.io/otel/semconv/v1.36.0` with the following exceptions.
|
||||||
|
|
||||||
|
## Removed
|
||||||
|
|
||||||
|
The following declarations have been removed.
|
||||||
|
Refer to the [OpenTelemetry Semantic Conventions documentation] for deprecation instructions.
|
||||||
|
|
||||||
|
If the type is not listed in the documentation as deprecated, it has been removed in this version due to lack of applicability or use.
|
||||||
|
If you use any of these non-deprecated declarations in your Go application, please [open an issue] describing your use-case.
|
||||||
|
|
||||||
|
- `ContainerRuntime`
|
||||||
|
- `ContainerRuntimeKey`
|
||||||
|
- `GenAIOpenAIRequestServiceTierAuto`
|
||||||
|
- `GenAIOpenAIRequestServiceTierDefault`
|
||||||
|
- `GenAIOpenAIRequestServiceTierKey`
|
||||||
|
- `GenAIOpenAIResponseServiceTier`
|
||||||
|
- `GenAIOpenAIResponseServiceTierKey`
|
||||||
|
- `GenAIOpenAIResponseSystemFingerprint`
|
||||||
|
- `GenAIOpenAIResponseSystemFingerprintKey`
|
||||||
|
- `GenAISystemAWSBedrock`
|
||||||
|
- `GenAISystemAnthropic`
|
||||||
|
- `GenAISystemAzureAIInference`
|
||||||
|
- `GenAISystemAzureAIOpenAI`
|
||||||
|
- `GenAISystemCohere`
|
||||||
|
- `GenAISystemDeepseek`
|
||||||
|
- `GenAISystemGCPGemini`
|
||||||
|
- `GenAISystemGCPGenAI`
|
||||||
|
- `GenAISystemGCPVertexAI`
|
||||||
|
- `GenAISystemGroq`
|
||||||
|
- `GenAISystemIBMWatsonxAI`
|
||||||
|
- `GenAISystemKey`
|
||||||
|
- `GenAISystemMistralAI`
|
||||||
|
- `GenAISystemOpenAI`
|
||||||
|
- `GenAISystemPerplexity`
|
||||||
|
- `GenAISystemXai`
|
||||||
|
|
||||||
|
[OpenTelemetry Semantic Conventions documentation]: https://github.com/open-telemetry/semantic-conventions
|
||||||
|
[open an issue]: https://github.com/open-telemetry/opentelemetry-go/issues/new?template=Blank+issue
|
||||||
3
vendor/go.opentelemetry.io/otel/semconv/v1.37.0/README.md
generated
vendored
Normal file
3
vendor/go.opentelemetry.io/otel/semconv/v1.37.0/README.md
generated
vendored
Normal file
|
|
@ -0,0 +1,3 @@
|
||||||
|
# Semconv v1.37.0
|
||||||
|
|
||||||
|
[](https://pkg.go.dev/go.opentelemetry.io/otel/semconv/v1.37.0)
|
||||||
Some files were not shown because too many files have changed in this diff Show more
Loading…
Add table
Reference in a new issue