Skip to content

xds: change cdsbalancer to use update from dependency manager - #8907

Merged
eshitachandwani merged 18 commits into
grpc:masterfrom
eshitachandwani:cdsbalancer_use_depmgr
Mar 2, 2026
Merged

xds: change cdsbalancer to use update from dependency manager#8907
eshitachandwani merged 18 commits into
grpc:masterfrom
eshitachandwani:cdsbalancer_use_depmgr

Conversation

@eshitachandwani

@eshitachandwani eshitachandwani commented Feb 16, 2026

Copy link
Copy Markdown
Member

This PR is part of A74 changes. This PR changes following:

  1. Changes the CDS balancer to use the CDS and EDS/DNS update from XDSConfig received by xds_resolver instead of starting its own CDS watchers.
  2. Remove cluster resolver completely
  3. CDS balancer creates the priority config and creates priority balancer as its child.
  4. Remove serializer from CDS balancer since it was there to serializer watcher updates and ClientConn updates, now that there are no watchers and clientConn updates are already serialized , serializer is no longer needed.
  5. Update tests in cdsbalancer package to check the priority config instead of cluster_resolver config.
  6. xds_resolver tracks reference counts for weighted cluster and cluster specifier plugin seperately. xds_resolver subscribes to the weighted cluster in dependency manager when referenced for first time and unsubscribes when references in xds_resolver go to zero.
  7. Incase of LDS/RDS resource error , we now directly send empty service config , instead of sending a complete service config with clusters that RPCs are still referenced to.
  8. Minor test fixes.

RELEASE NOTES:

  • xds:
    • Ambient errors for cluster resources are now logged exclusively in the dependency manager and are no longer propagated to Load Balancing (LB) policies.
    • When re-resolution is requested, all clusters of type LOGICAL_DNS will be re-resolved simultaneously, rather than only a single cluster.
    • Upon receipt of a listener or route resource error, all in-flight RPCs will now fail immediately.
    • Any error encountered during the creation or update of a priority configuration will now transition the channel to a TRANSIENT_FAILURE state.

@eshitachandwani eshitachandwani added this to the 1.80 Release milestone Feb 16, 2026
@eshitachandwani eshitachandwani added Type: Feature New features or improvements in behavior Area: xDS Includes everything xDS related, including LB policies used with xDS. labels Feb 16, 2026
@codecov

codecov Bot commented Feb 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 80.40000% with 49 lines in your changes missing coverage. Please review.
✅ Project coverage is 83.38%. Comparing base (944f058) to head (700015c).
⚠️ Report is 16 commits behind head on master.

Files with missing lines Patch % Lines
internal/xds/balancer/cdsbalancer/cdsbalancer.go 69.28% 30 Missing and 13 partials ⚠️
internal/xds/balancer/cdsbalancer/configbuilder.go 95.12% 2 Missing ⚠️
internal/xds/resolver/serviceconfig.go 90.00% 1 Missing and 1 partial ⚠️
internal/xds/xdsdepmgr/xds_dependency_manager.go 91.66% 1 Missing and 1 partial ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master    #8907      +/-   ##
==========================================
+ Coverage   80.74%   83.38%   +2.63%     
==========================================
  Files         416      410       -6     
  Lines       33434    32570     -864     
==========================================
+ Hits        26996    27157     +161     
+ Misses       4641     4038     -603     
+ Partials     1797     1375     -422     
Files with missing lines Coverage Δ
...ds/balancer/cdsbalancer/configbuilder_childname.go 100.00% <ø> (ø)
...rnal/xds/balancer/clustermanager/clustermanager.go 80.95% <100.00%> (+9.52%) ⬆️
internal/xds/resolver/xds_resolver.go 91.87% <100.00%> (+3.16%) ⬆️
internal/xds/balancer/cdsbalancer/configbuilder.go 91.94% <95.12%> (ø)
internal/xds/resolver/serviceconfig.go 86.39% <90.00%> (-1.76%) ⬇️
internal/xds/xdsdepmgr/xds_dependency_manager.go 88.27% <91.66%> (+18.96%) ⬆️
internal/xds/balancer/cdsbalancer/cdsbalancer.go 69.78% <69.28%> (-16.48%) ⬇️

... and 52 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Comment thread internal/xds/balancer/clusterimpl/tests/balancer_test.go Outdated
Comment thread internal/xds/xdsdepmgr/xds_dependency_manager.go
Comment thread internal/xds/xdsdepmgr/xds_dependency_manager.go
Comment thread internal/xds/xdsdepmgr/xds_dependency_manager.go
Comment thread internal/xds/balancer/cdsbalancer/cdsbalancer_test.go Outdated
Comment thread internal/xds/balancer/cdsbalancer/cdsbalancer_test.go Outdated
Comment thread internal/xds/balancer/cdsbalancer/cdsbalancer_test.go Outdated
Comment thread internal/xds/balancer/cdsbalancer/cdsbalancer_test.go Outdated
Comment thread internal/xds/balancer/cdsbalancer/cdsbalancer_test.go Outdated
@easwars easwars assigned eshitachandwani and unassigned easwars Feb 18, 2026
@eshitachandwani

Copy link
Copy Markdown
Member Author

Regarding all the comments talking about eating the error , we were doing that since that was the current behaviour of cluster resolver i.e. it was eating errors instead of returning the error or putting the channel in TF. After an offline discussion we have decided to change the behaviour and any error in CDS LB policy i.e. any error relating to CDS not liking the update is returned from UpdateClientConnState effectively effectively moving the particular channel in TF

@easwars easwars left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I see that you have replied saying "done" on a bunch of comments, but I don't see it being done. Are you missing some commits here?

Comment thread internal/xds/balancer/clusterimpl/tests/balancer_test.go Outdated
Comment thread internal/xds/resolver/xds_resolver.go Outdated
Comment thread internal/xds/xdsdepmgr/xds_dependency_manager.go
Comment thread internal/xds/xdsdepmgr/xds_dependency_manager.go
Comment thread internal/xds/xdsdepmgr/xds_dependency_manager_test.go
@easwars easwars assigned eshitachandwani and unassigned easwars Feb 24, 2026
@eshitachandwani

Copy link
Copy Markdown
Member Author

I see that you have replied saying "done" on a bunch of comments, but I don't see it being done. Are you missing some commits here?

I had pushed all the changes and can see the changes reflected in the PR. Can you please try again and let me know if the older and current changes are still not visibile.

@easwars easwars left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mostly LGTM at this point. Will make another pass shortly.

Comment thread internal/xds/balancer/cdsbalancer/cdsbalancer.go Outdated
Comment thread internal/xds/balancer/cdsbalancer/cdsbalancer.go Outdated
Comment thread internal/xds/balancer/cdsbalancer/cdsbalancer.go Outdated
Comment thread internal/xds/resolver/xds_resolver.go

@easwars easwars left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Just minor nits.

Comment on lines 111 to 112
// Start an xDS management server that pushes the EDS resource names onto a
// channel when requested.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This comment needs to be updated.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

Comment on lines +130 to +131
// Check if we have a request for both EDS resources. If so, fire
// the event to unblock the test.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: What this event signifies should ideally be documented at the place where the event is defined.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added.

watchers map[string]*watcherState // Set of watchers and associated state, keyed by cluster name.
lbCfg *lbConfig // Current load balancing configuration.
childLB balancer.Balancer // Child policy, built upon resolution of the cluster graph.
xdsClient xdsclient.XDSClient // xDS client to watch Cluster resources.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: Clarify in this comment that this is only for dynamic subscriptions.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is not needed for dynamic subscription but is passed so that cluster_impl can use it for Load reporting. Here it is mainly used to get nodeID. So removed the comment.

lbCfg *lbConfig // Current load balancing configuration.
childLB balancer.Balancer // Child policy, built upon resolution of the cluster graph.
xdsClient xdsclient.XDSClient // xDS client to watch Cluster resources.
clusterConfigs map[string]*xdsresource.ClusterResult // Map of cluster name to the last received result for that cluster.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: Keep these trialing comments short and sweet.

Something like:

  • Cluster name to the last received result for that cluster
  • Hostname to priority config for that leaf cluster
    ...
  • For dynamic cluster unsubscription
  • True if a dynamic cluster has been subscribed to

etc .. etc

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: Please remove mentions of the serializer as it does not exist anymore.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

@@ -168,16 +162,22 @@ type cdsBalancer struct {

xdsHIPtr *unsafe.Pointer // Accessed atomically.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It would be nice to state why this needs to be accessed atomically.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since this will move to clusterimpl, will change the comment there.

xdsClient xdsclient.XDSClient // xDS client to watch Cluster resources.
watchers map[string]*watcherState // Set of watchers and associated state, keyed by cluster name.
lbCfg *lbConfig // Current load balancing configuration.
childLB balancer.Balancer // Child policy, built upon resolution of the cluster graph.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also, it would be nice to state that all fields below are accessed only from methods on the balancer.Balancer interface. And because grpc guarantees that those methods will never be called concurrently, we don't need any extra serialization for accessing these fields.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

Comment on lines +133 to +134
sortedNames := make([]string, len(names))
copy(sortedNames, names)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this can be replaced with a single line if you use slices.Clone.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

names := req.GetResourceNames()
sortedNames := make([]string, len(names))
copy(sortedNames, names)
sort.Strings(sortedNames)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: Use slices.Sort here as well? gemini says its better than sort.Strings(). I know it doesn't matter here. But whatever.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

done.

const clusterName1 = clusterName + "-cluster-1"
const clusterName2 = clusterName + "-cluster-2"

gotEDSRequests := grpcsync.NewEvent()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This probably needs a better name, and a comment.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.

@easwars easwars assigned eshitachandwani and unassigned easwars Feb 27, 2026
@easwars

easwars commented Feb 27, 2026

Copy link
Copy Markdown
Contributor

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a significant and well-executed refactoring of the xDS implementation, primarily focusing on the CDS balancer. The core change involves centralizing resource watching logic within the dependency manager, which simplifies the CDS balancer by removing its responsibility for managing its own resource watchers. As part of this, the cluster_resolver balancer is completely removed, and the CDS balancer now uses the priority balancer as its child. The error handling for xDS resources has also been improved, making the system more robust. The tests have been thoroughly updated to reflect these architectural changes. My review includes one suggestion to improve the robustness of a test case.

Comment thread internal/xds/balancer/clusterimpl/tests/balancer_test.go
@eshitachandwani
eshitachandwani merged commit 1d4fa8a into grpc:master Mar 2, 2026
14 checks passed
This was referenced Apr 23, 2026
nschloe pushed a commit to live-clones/forgejo that referenced this pull request Jul 23, 2026
…/forgejo) (#13580)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.79.3` → `v1.82.1` | ![age](https://developer.mend.io/api/mc/badges/age/go/google.golang.org%2fgrpc/v1.82.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/google.golang.org%2fgrpc/v1.79.3/v1.82.1?slim=true) |

---

### gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
[GHSA-hrxh-6v49-42gf](GHSA-hrxh-6v49-42gf)

<details>
<summary>More information</summary>

#### Details
Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in:

- Authorization Bypass (Fail-Open) when translating xDS RBAC policies containing `Metadata` or `RequestedServerName` fields.
- Denial of Service (High CPU Consumption) due to an HTTP/2 Rapid Reset mitigation bypass during client-initiated stream resets.
- Denial of Service (Server Panic) when parsing crafted xDS RBAC policies containing `NOT` rules around unsupported fields.

##### Impact
_What kind of vulnerability is it? Who is impacted?_

##### xDS RBAC Authorization Bypass via `Metadata` & `RequestedServerName` matchers

- Affected Component: xDS RBAC
- Impact: When building policy matchers for gRPC RBAC from xDS configurations, unsupported `permission` and `principal` rules (specifically `Metadata` and `RequestedServerName`) were silently ignored and treated as no-ops.
  - If an authorization policy relied purely on these matchers for access control, treating those rules as no-ops effectively removed the restrictions.
- If these unsupported rules were nested inside logical `NOT` rules (`Permission_NotRule` / `Principal_NotId`) or multi-condition `OR/AND` rules, silently dropping them changed the boolean logic flow of the authorization engine.

As a result, policy evaluation decisions could fail open, allowing unauthorized clients to access protected gRPC services or resources.

##### HTTP/2 Rapid Reset Mitigation Bypass / Denial of Service via Stream Aborts

- Affected Component: HTTP/2 transport
- Impact: Earlier mitigations in grpc-go for HTTP/2 Rapid Reset only applied threshold checks to items that directly resulted in control frames being written back to the wire, such as `SETTINGS` ACKs or server-initiated `RST_STREAM`s.

When a client initiated a rapid flood of stream creation (`HEADERS`) immediately followed by stream termination `RST_STREAM`, items queued up in the control buffer without counting against the transport response frame threshold. An attacker can repeatedly trigger this flood sequence to bypass reader blocking, resulting in high CPU usage, and Denial of Service (DoS).

##### Denial of Service (Panic) in xDS RBAC Engine via Unsupported Fields inside NOT Rules

- Affected Component: xDS RBAC
- Impact: The xDS RBAC policy translators recursively generate matchers for nested rules. When a `NOT` rule wrapped an unsupported or unhandled field (such as `SourcedMetadata`), the recursive step returned an empty matcher. This could result in a runtime panic when the RBAC engine attempts to authorize an incoming request.

An attacker or misconfigured/malicious xDS management server delivering an LDS/RDS update containing a `NOT` rule around an unhandled field causes the gRPC server process to crash immediately (CWE-248 / Denial of Service).

##### Patches
_Has the problem been patched? What versions should users upgrade to?_

All three issues have been fixed in `master` and will be released in 1.82.1 shortly.

##### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_

If upgrading grpc-go immediately is not possible, apply the following workarounds based on your deployment architecture:

* For xDS RBAC Vulnerabilities & Panics: Ensure that upstream xDS management servers do not push RBAC policies containing `Metadata`, `RequestedServerName`, or `NOT` rules wrapping unsupported fields (such as `SourcedMetadata`) to grpc-go servers.
* For HTTP/2 Rapid Reset DOS: Configure upstream reverse proxies or load balancers (such as Envoy) with strict HTTP/2 `max_concurrent_streams` limits and active rate limiting on `RST_STREAM` frequency per connection.

##### Severity

  | Vulnerability | Qualitative Severity | Approximate CVSS v3.1 Score | Primary Impact |
  | :--- | :--- | :--- | :--- |
  | **xDS RBAC Authorization Bypass** | **High** | `8.2` | Unauthorized Access / Fail-Open |
  | **HTTP/2 Rapid Reset DOS Bypass** | **High** | `7.5` | High CPU Consumption / Denial of Service |
  | **xDS RBAC Engine Server Panic** | **Medium** | `5.9` | Process Crash / Denial of Service |

#### Severity
- CVSS Score: 8.8 / 10 (High)
- Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N`

#### References
- [https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf](https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf)
- [https://github.com/grpc/grpc-go/pull/9236](https://github.com/grpc/grpc-go/pull/9236)
- [https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935](https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935)
- [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go)
- [https://github.com/grpc/grpc-go/releases/tag/v1.82.1](https://github.com/grpc/grpc-go/releases/tag/v1.82.1)

This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-hrxh-6v49-42gf) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

### Release Notes

<details>
<summary>grpc/grpc-go (google.golang.org/grpc)</summary>

### [`v1.82.1`](https://github.com/grpc/grpc-go/releases/tag/v1.82.1): Release 1.82.1

[Compare Source](grpc/grpc-go@v1.82.0...v1.82.1)

### Security

- server: Stop reading from the connection when flooded by HTTP/2 frames.  The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`.
- xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields.  If present in a DENY rule, previously these would be ignored and fail-open.
- xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions.
- xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`.

### [`v1.82.0`](https://github.com/grpc/grpc-go/releases/tag/v1.82.0): Release 1.82.0

[Compare Source](grpc/grpc-go@v1.81.1...v1.82.0)

### Behavior Changes

- server: Remove support for `GRPC_GO_EXPERIMENTAL_DISABLE_STRICT_PATH_CHECKING` environment varibale. Strict incoming RPC path validation (which has been the default since `v1.79.3`) can no longer be disabled. ([#&#8203;9112](grpc/grpc-go#9112))
- transport: Add environment variable to change the default max header list size from `16MB` to `8KB`. This may be enabled by setting `GRPC_GO_EXPERIMENTAL_ENABLE_8KB_DEFAULT_HEADER_LIST_SIZE=true`. This will be enabled by default in a subsequent release. ([#&#8203;9019](grpc/grpc-go#9019))
- balancer: Load Balancing policy registry is now case-sensitive.  Set `GRPC_GO_EXPERIMENTAL_CASE_SENSITIVE_BALANCER_REGISTRIES=false` (and file an issue) to revert to case-insensitive behavior. ([#&#8203;9017](grpc/grpc-go#9017))

### New Features

- experimental/stats: Expose a new API, `NewContextWithLabelCallback`, to register a callback that is invoked when telemetry labels are added. ([#&#8203;8877](grpc/grpc-go#8877))
  - Special Thanks: [@&#8203;seth-epps](https://github.com/seth-epps)
- client: Return a portion of the response body in the error message, when the client receives an unexpected non-gRPC HTTP response, to make debugging easier. ([#&#8203;8929](grpc/grpc-go#8929))
  - Special Thanks: [@&#8203;chengxilo](https://github.com/chengxilo)
- server: Add environment variable `GRPC_GO_SERVER_GOROUTINE_LABELS` that controls setting `runtime/pprof.Labels` on goroutines spawned by the server. Set `GRPC_GO_SERVER_GOROUTINE_LABELS=grpc.method=true` to add the `grpc.method` label on goroutines spawned to handle incoming requests. ([#&#8203;9082](grpc/grpc-go#9082))
  - Special Thanks: [@&#8203;dfinkel](https://github.com/dfinkel)

### Bug Fixes

- xds/server: Fix a memory leak of HTTP filter instances occurring when route configurations are updated in-place during a Route Discovery Service (RDS) update. ([#&#8203;9138](grpc/grpc-go#9138))
- grpc: In the deprecated `gzip` Compressor (used via the deprecated `WithCompressor` dial option), enforce the `MaxRecvMsgSize` limit on the decompressed message buffer, preventing excessive memory allocation from highly compressed payloads. ([#&#8203;9114](grpc/grpc-go#9114))
  - Special Thanks: [@&#8203;evilgensec](https://github.com/evilgensec)
- stats/opentelemetry: Record retry attempts, `grpc.previous-rpc-attempts`, at the call level and not the attempt level. ([#&#8203;8923](grpc/grpc-go#8923))
- encoding: Ensure `Close()` is always called on readers returned from `Compressor.Decompress` if possible. ([#&#8203;9135](grpc/grpc-go#9135))
- channelz: Fix the `LastMessageSentTimestamp` and `LastMessageReceivedTimestamp` fields in `SocketMetrics` to ensure they contain correct timestamp values. ([#&#8203;9109](grpc/grpc-go#9109))

### [`v1.81.1`](https://github.com/grpc/grpc-go/releases/tag/v1.81.1): Release 1.81.1

[Compare Source](grpc/grpc-go@v1.81.0...v1.81.1)

### Security

- xds/rbac: Fix a potential authorization bypass caused by incorrectly falling through URI/DNS SANs to Subject Distinguished Name (DN) when matching the authenticated principal name. With this fix, only the first non-empty identity source will be used, as per [gRFC A41](https://github.com/grpc/proposal/blob/master/A41-xds-rbac.md). ([#&#8203;9111](grpc/grpc-go#9111))
  - Special Thanks: [@&#8203;al4an444](https://github.com/al4an444)

### Bug Fixes

- otel: Segregate client and server RPC information used for metrics and traces, to avoid one overwriting the other. ([#&#8203;9081](grpc/grpc-go#9081))

### [`v1.81.0`](https://github.com/grpc/grpc-go/releases/tag/v1.81.0): Release 1.81.0

[Compare Source](grpc/grpc-go@v1.80.0...v1.81.0)

### Behavior Changes

- balancer/rls: Switch gauge metrics to asynchronous emission (once per collection cycle) to reduce telemetry noise and align with other gRPC language implementations. ([#&#8203;8808](grpc/grpc-go#8808))

### Dependencies

- Minimum supported Go version is now 1.25. ([#&#8203;8969](grpc/grpc-go#8969))

### Bug Fixes

- xds: Use the leaf cluster's security config for the TLS handshake instead of the aggregate cluster's config. ([#&#8203;8956](grpc/grpc-go#8956))
- transport: Send a `RST_STREAM` when receiving an `END_STREAM` when the stream is not already half-closed. ([#&#8203;8832](grpc/grpc-go#8832))
- xds: Fix ADS resource name validation to prevent a panic. ([#&#8203;8970](grpc/grpc-go#8970))

### New Features

- grpc/stats: Add support for custom labels in per-call metrics ([gRFC A108](https://github.com/grpc/proposal/blob/master/A108-otel-custom-per-call-label.md)). ([#&#8203;9008](grpc/grpc-go#9008))
- xds: Add support for Server Name Indication (SNI) and SAN validation ([gRFC A101](https://github.com/grpc/proposal/blob/master/A101-SNI-setting-and-SNI-SAN-validation.md)). Disabled by default. To enable, set `GRPC_EXPERIMENTAL_XDS_SNI=true` environment variable. ([#&#8203;9016](grpc/grpc-go#9016))
- xds: Add support to control which fields get propagated from ORCA backend metric reports to LRS load reports ([gRFC A85](https://github.com/grpc/proposal/blob/master/A85-lrs-custom-metrics-changes.md)). Disabled by default. To enable, set `GRPC_EXPERIMENTAL_XDS_ORCA_LRS_PROPAGATION=true`. ([#&#8203;9005](grpc/grpc-go#9005))
- xds: Add metrics to track xDS client connectivity and cached resource state ([gRFC A78](https://github.com/grpc/proposal/blob/master/A78-grpc-metrics-wrr-pf-xds.md)). ([#&#8203;8807](grpc/grpc-go#8807))
- stats/otel: Enhance `grpc.subchannel.disconnections` metric by adding disconnection reason to the `grpc.disconnect_error` label ([gRFC A94](https://github.com/grpc/proposal/blob/master/A94-subchannel-otel-metrics.md)). This provides granular insights into why subchannels are closing. ([#&#8203;8973](grpc/grpc-go#8973))
- mem: Add `mem.Buffer.Slice()` API to slice the buffer like a slice. ([#&#8203;8977](grpc/grpc-go#8977))
  - Special Thanks: [@&#8203;ash2k](https://github.com/ash2k)

### Performance Improvements

- alts: Pool read buffers to lower memory utilization when sockets are unreadable. ([#&#8203;8964](grpc/grpc-go#8964))
- transport: Pool HTTP/2 framer read buffers to reduce idle memory consumption. Currently limited to Linux for ALTS and non-encrypted transports (TCP, Unix). To disable, set `GRPC_GO_EXPERIMENTAL_HTTP_FRAMER_READ_BUFFER_POOLING=false` and report any issues. ([#&#8203;9032](grpc/grpc-go#9032))

### [`v1.80.0`](https://github.com/grpc/grpc-go/releases/tag/v1.80.0): Release 1.80.0

[Compare Source](grpc/grpc-go@v1.79.3...v1.80.0)

### Behavior Changes

- balancer: log a warning if a balancer is registered with uppercase letters, as balancer names should be lowercase. In a future release, balancer names will be treated as case-insensitive; see [#&#8203;5288](grpc/grpc-go#5288) for details. ([#&#8203;8837](grpc/grpc-go#8837))
- xds: update resource error handling and re-resolution logic ([#&#8203;8907](grpc/grpc-go#8907))
  - Re-resolve all `LOGICAL_DNS` clusters simultaneously when re-resolution is requested.
  - Fail all in-flight RPCs immediately upon receipt of listener or route resource errors, instead of allowing them to complete.

### Bug Fixes

- xds: support the LB policy configured in `LOGICAL_DNS` cluster resources instead of defaulting to `pick_first`. ([#&#8203;8733](grpc/grpc-go#8733))
- credentials/tls: perform per-RPC authority validation against the leaf certificate instead of the entire peer certificate chain. ([#&#8203;8831](grpc/grpc-go#8831))
- xds: enabling A76 ring hash endpoint keys no longer causes EDS resources with invalid proxy metadata to be NACKed when HTTP CONNECT (gRFC A86) is disabled. ([#&#8203;8875](grpc/grpc-go#8875))
- xds: validate that the sum of endpoint weights in a locality does not exceed the maximum `uint32` value. ([#&#8203;8899](grpc/grpc-go#8899))
  - Special Thanks: [@&#8203;RAVEYUS](https://github.com/RAVEYUS)
- xds: fix incorrect proto field access in the weighted round robin (WRR) configuration where `blackout_period` was used instead of `weight_expiration_period`. ([#&#8203;8915](grpc/grpc-go#8915))
  - Special Thanks: [@&#8203;gregbarasch](https://github.com/gregbarasch)
- xds/rbac: handle addresses with ports in IP matchers. ([#&#8203;8990](grpc/grpc-go#8990))

### New Features

- ringhash: enable gRFC A76 (endpoint hash keys and request hash headers) by default. ([#&#8203;8922](grpc/grpc-go#8922))

### Performance Improvements

- credentials/alts: pool write buffers to reduce memory allocations and usage. ([#&#8203;8919](grpc/grpc-go#8919))
- grpc: enable the use of pooled write buffers for buffering HTTP/2 frame writes by default. This reduces memory usage when connections are idle. Use the [WithSharedWriteBuffer](https://pkg.go.dev/google.golang.org/grpc#WithSharedWriteBuffer) dial option or the [SharedWriteBuffer](https://pkg.go.dev/google.golang.org/grpc#SharedWriteBuffer) server option to disable this feature. ([#&#8203;8957](grpc/grpc-go#8957))
- xds/priority: stop caching child LB policies removed from the configuration. This will help reduce memory and cpu usage when localities are constantly switching between priorities. ([#&#8203;8997](grpc/grpc-go#8997))
- mem: add a faster tiered buffer pool; use the experimental [mem.NewBinaryTieredBufferPool](https://pkg.go.dev/google.golang.org/grpc/mem@master#NewBinaryTieredBufferPool) function to create such pools. ([#&#8203;8775](grpc/grpc-go#8775))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzIuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI3Mi4wIiwidGFyZ2V0QnJhbmNoIjoidjE2LjAvZm9yZ2VqbyIsImxhYmVscyI6WyJkZXBlbmRlbmN5LXVwZ3JhZGUiLCJ0ZXN0L25vdC1uZWVkZWQiXX0=-->

Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/13580
Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area: xDS Includes everything xDS related, including LB policies used with xDS. Type: Feature New features or improvements in behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants