Skip to content

chore(deps): bump github.com/opensearch-project/opensearch-go/v4 from 4.7.3 to 4.8.0 in /observability-logs-opensearch - #658

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/observability-logs-opensearch/github.com/opensearch-project/opensearch-go/v4-4.8.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/observability-logs-opensearch/github.com/opensearch-project/opensearch-go/v4-4.8.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/opensearch-project/opensearch-go/v4 from 4.7.3 to 4.8.0.

Release notes

Sourced from github.com/opensearch-project/opensearch-go/v4's releases.

V4.8.0

opensearch-go v4.8.0

CRITICAL UPGRADE RELEASE NOTE - v5 has substantially expanded error handling capabilities compared to v4.

v5.0.0 is out, and v4 is now in maintenance mode. v4.8.0 is a maintenance release: it backports fixes from main and does not add features. The v4 -> v5 upgrade changes runtime error-handling behavior and is NOT a drop-in replacement across major versions. If you use this client, read this now - even if you are only upgrading to v4.8.0.

v4 only returns transport-level errors; partial failures (e.g. failed bulk items, failed shards, unconfirmed replica writes) are reported inside the response body, not as Go error values. In v5, those partial failures are returned as errors by default. Code that compiles and passes against v4 can behave differently against v5 without any code change.

Upgrading between v4 releases (any <v4.8.0 to any v4.X.X) does not change the default error-handling semantics. See Error handling below for how to adopt the v5 behavior on v4 before you upgrade, and the v4 to v5 migration guide for the full API delta.

The v4 line covers development from December 2025 through September 2026 (v4.6.0 -> v4.8.0). Two themes dominate it: a reworked error-handling model that surfaces partial failures as typed Go errors, and a rewritten transport layer with an optional client-side router.

v4.8.0 is a maintenance release on top of v4.7.3. It backports transport fixes from main, removes the v5preview/opensearchapi package now that v5 has shipped, and raises the minimum Go version to 1.26.8. Three changes need a look before upgrading: the v5preview removal, transport error strings that now carry the request method and URL, and Perform/Stream no longer rewriting your *http.Request after the first attempt. Each is covered in Breaking and behavior changes in v4.8.0.

Full Changelog: opensearch-project/opensearch-go@v4.7.3...v4.8.0

4.8.0 Fixes


1. Error handling

Background

OpenSearch returns HTTP 200 for many operations that only partially succeed: bulk requests where some items fail, searches where some shards error, and writes where a replica fails to confirm. A 2xx status code does not mean the whole operation succeeded.

Before v4.7.0, only transport errors were returned as errors and any partial or shard-level failure required inspecting response fields by hand after every call. v4.7.0 added a model that turns partial failures into typed Go errors:

Error type Returned by
*PartialBulkError Bulk
*PartialSearchError Search, MSearch, SearchTemplate, Scroll.Get
*ShardFailureError Index, Document.Create, Document.Delete, Update
*MultiSearchItemError MSearch, MSearchTemplate (per sub-response)

Which categories are returned as errors is controlled by a per-category mask on Config.Errors. When a category is masked, the operation returns its response with a nil error even though the response body records failures, and the caller is responsible for inspecting it. When a category is not masked (the v5 default), the same partial failure is returned as one of the typed errors above, and the response is still fully populated alongside the error.

v4 -> v5 Migration Path

... (truncated)

Changelog

Sourced from github.com/opensearch-project/opensearch-go/v4's changelog.

[4.8.0]

Changed

  • Perform and Stream no longer rewrite the caller's *http.Request on every attempt. Previously the transport rewrote the request you handed it in place on each attempt -- URL.Scheme, URL.Host, URL.Path (prepending any connection base path), auth and signature headers, and sometimes URL.RawQuery -- so after a retried call it reflected the last node tried. The first attempt still resolves the node onto your request, which is safe because no goroutine holds it yet and keeps the common single-attempt path free of a copy; every retry works on its own copy, and so does the seed-URL fallback. Your request therefore now reflects the first node tried rather than the last. This is the fix for the data race described below, and it also stops a connection base path from stacking on retries (/prefix/prefix/_search). If you were reading the rewritten request to discover which node served a call, read it from the router observer's OnRoute event instead. See UPGRADING.md (#1121)
  • Perform and Stream now prefix the errors they return with the failing request's method and a credential-redacted URL, for example "GET" "https://host:9200/_search": context deadline exceeded. The wrap uses %w, so errors.Is/errors.As are unaffected and only the err.Error() text changes. Monitoring that matches a transport error by its exact message or a start-anchored pattern needs updating; a substring match on the underlying cause still works. See UPGRADING.md (#1119)

Removed

  • BREAKING: Remove the v5preview/opensearchapi/ package and its plugins/ subpackages. The generated API it previewed shipped as github.com/opensearch-project/opensearch-go/v5/opensearchapi in 5.0.0 and is maintained there. The two have drifted apart since, so switching takes more than an import-path edit: v5 multi-index Req types use Indices, for example, where v5preview used Index. make gen now regenerates only the internal/path builders, the gen-api target is gone, and the check-gen workflow no longer diffs v5preview/. Move to v5, fall back to v4's hand-written opensearchapi, or pin 4.7.3. See UPGRADING.md (#1171)

Fixed

  • cmd/osgen: fix the git-root check rejecting every output directory on Windows. git rev-parse --show-toplevel prints forward slashes there while filepath.Abs returns backslashes, so the prefix comparison in resolveGenRoot never matched and osgen api exited 1 after writing every file. The git root is now normalized with filepath.Clean where it is produced, so every caller sees a native path; on Linux and macOS it is a no-op for an already clean path (#1122, #1163)
  • opensearchtransport.ConnectionMetric.String() now renders dead_since/overloaded_since in UTC instead of the host's local timezone. The underlying timestamps are already UTC (nanoToTime forces .UTC()), and time.Stamp carries no zone marker, so converting to local time produced a wall-clock reading with nothing in the string to say which zone it belonged to -- two hosts printing the same instant disagreed. Both fields are exported and settable by a caller in any zone, so the format call normalizes with .UTC() rather than dropping the conversion and trusting the input. This also makes TestMetrics/String() deterministic: it previously matched a regex tolerant of any hour, and now asserts the exact string, including for a non-UTC input (#1155)
  • Fix DisableRetry being ignored for io.EOF, io.ErrUnexpectedEOF, and HTTP/2 stream resets (RST_STREAM). Status retries, 429, and net.Error honor DisableRetry, but these two paths set shouldRetry unconditionally, so with the default MaxRetries of 6 a DisableRetry: true client still retried a dropped connection up to seven times. A write that already landed can surface as EOF when the connection drops while the response is in flight, and retrying it duplicates the document. Both paths now honor DisableRetry, matching the documented "disable the retry behavior altogether" contract. The HTTP/2 drain mark is left in place: it is a connection-health signal, not a retry. (#1135)
  • Wrap transport errors from opensearchtransport's stream() with the request method and URL, so a bare error like unexpected EOF or context deadline exceeded can be correlated back to the failing request when several are in flight concurrently. Wrapped with %w, so errors.Is/errors.As still see through to the original cause. The URL has its userinfo and query string stripped first, since either can carry credentials (basic auth, a SigV4 presigned signature, or an API key passed as a query parameter); scheme, host, and path are enough to identify the request without risking a leak into logs or an error tracker. See the Changed entry above for the observable consequence (#1119)
  • Fix opensearchutil.BulkIndexer leaving an orphan NDJSON action line in the worker buffer when an item body fails to serialize. writeMeta commits the action line before writeBody reads the body, so a failed Read or Seek dropped the item from w.items but left its action line in w.buf. The next item's action/source pair landed after that orphan, and every later result paired with the wrong item. The worker now records the buffer length before serializing an item and truncates back to it on any serialize error. flush no longer pairs results when the response carries more items than the indexer serialized, which used to index w.items[i] past the end and panic (#1105)
  • Fix a data race between the retry loop and net/http's HTTP/2 transport. stream() reused one *http.Request across attempts and rewrote its URL and Header in place (setReqURL, setReqAuth, signRequest, adaptive max_concurrent_shard_requests injection). net/http encodes HTTP/2 request headers on a goroutine it spawns, and that goroutine reads the request's URL and Header -- so when an attempt was cancelled, RoundTrip returned while the encoder was still reading, and preparing the next attempt raced it. Reproduced under -race with an ordinary pattern: a caller context deadline expiring on an in-flight HTTP/2 request, followed by another request on the same client. Each retry now works on a copy, so nothing the transport may still be reading is ever mutated. See the Changed entry above for the observable consequence (#1121)
  • Fix timeout retries reusing a stalled HTTP/2 connection. RequestTimeout cancels the attempt context, which resets the HTTP/2 stream but leaves the ClientConn in http.Transport's pool, so with EnableRetryOnTimeout every retry was multiplexed onto the same (possibly black-holed) connection and DialContext never ran -- the failure mode after an Amazon OpenSearch Service blue/green cutover, where DNS already pointed at the replacement backend. A timeout now marks the node, and the next request to it carries Request.Close, which is how net/http is asked to retire a connection: it stops offering that connection to new requests, lets the streams already on it finish, and closes it once the last one does. The client closes no sockets itself, so a request multiplexed onto the same connection is never cut off. Two consequences are deliberate: net/http sets the flag after the stream is assigned, so the request carrying it still rides the stale connection and recovery lands on the one after it (with EnableRetryOnTimeout set the retry loop absorbs this, at the cost of a retry slot: recovering inside one call needs MaxRetries of at least 2, which the default of 6 satisfies); and the mark is per node, so a node with several pooled connections may retire a healthy one at the cost of a handshake. Only a timeout the client generates marks anything -- a caller's own expiring context deadline reports the same net.Error.Timeout() but implicates the caller, so the pool is left alone. The mark is not conditional on a retry following it, so with EnableRetryOnTimeout unset the request still fails but the stale connection is retired instead of inherited. The no-timeout default path is unchanged. See https://github.com/opensearch-project/opensearch-go/blob/v4.8.0/guides/retry_backoff.md (#1121)
  • Fix rendezvousTopK sorting the live connection list when shard placement is unknown. rankByHash sorts in place, and the empty-placement path (/_cat/shards not yet populated: first requests, a new index, or -cat_shards) aliased the caller's activeConns/sortedConns slice instead of copying into the pooled buffer the shard-names path already used. Concurrent Route() then raced with discovery, and the RTT-bucket order that rendezvous filling "MUST" preserve — rebuilt on health checks, not per request — was destroyed. Both branches now copy before ranking (#1090)
  • Fix Stream leaking the caller's request body once it has snapshotted it, for both the gzip path and the retry buffer. compress() only copies, and Stream then replaces req.Body with an io.NopCloser over the snapshot, so the body net/http closes after the round trip is the replacement rather than what the caller passed in. Nothing generated is affected -- opensearchapi wraps a byte slice in io.NopCloser, whose Close is a no-op -- but a caller handing Stream a body that owns a resource, such as an *os.File or a tracing wrapper, leaked it on every request. The close happens after the snapshot has fully consumed the body and before the first attempt, so no retry reads a closed body; a compress() error leaves the original attached and closed by net/http as before (#1150)

Dependencies

  • Raise the go directive from 1.26.0 to 1.26.8 in the root module and cmd/osgen to pick up the standard-library security fixes released since 1.26.0. Building against v4 now needs Go 1.26.8 or newer (#1171)
  • Bump github.com/aws/aws-sdk-go-v2/config from 1.33.4 to 1.33.5, github.com/tidwall/gjson from 1.18.0 to 1.19.0, and github.com/tidwall/match from 1.1.1 to 1.2.0 (#1171)
  • Bump golang.org/x/text from 0.40.0 to 0.42.0 and github.com/go-openapi/jsonpointer from 0.22.5 to 1.0.1 in cmd/osgen (#1171)
Commits
  • 161f33e chore(release): 4.8.0 (#1154)
  • e00ed8e chore(deps): bump codecov/codecov-action from 7.0.0 to 7.1.1 (#1167)
  • 67536bc chore!: remove v5preview/opensearchapi from v4 and update dependencies (#1171)
  • e793806 chore(deps): bump github.com/aws/aws-sdk-go-v2/credentials (#1168)
  • f94c011 fix(osgen): normalize the git root before the containment check on Windows (b...
  • 58969d7 fix(opensearchutil): drop orphan NDJSON action on serialize error (backport #...
  • 8a3f90e fix(opensearchtransport): wrap stream errors with request method and redacted...
  • e52e28d fix(opensearchtransport): honor DisableRetry for EOF and HTTP/2 stream errors...
  • a50d989 fix(opensearchtransport): close original request body after snapshot (backpor...
  • 84b4c6d fix(opensearchtransport): format dead_since/overloaded_since in UTC (backport...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/opensearch-project/opensearch-go/v4](https://github.com/opensearch-project/opensearch-go) from 4.7.3 to 4.8.0.
- [Release notes](https://github.com/opensearch-project/opensearch-go/releases)
- [Changelog](https://github.com/opensearch-project/opensearch-go/blob/v4.8.0/CHANGELOG.md)
- [Commits](opensearch-project/opensearch-go@v4.7.3...v4.8.0)

---
updated-dependencies:
- dependency-name: github.com/opensearch-project/opensearch-go/v4
  dependency-version: 4.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 6950d1bd-4a9f-45c5-bbf0-411851099eb9

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant