feat!: Rename deprecated net. span attributes - #23301

Merged
s1gr1d merged 12 commits into
developfrom
sig/network-attributes
Aug 24, 2026
Merged

feat!: Rename deprecated net. span attributes#23301
s1gr1d merged 12 commits into
developfrom
sig/network-attributes

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Related to Linear: https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes

v10 attributev11 attribute
net.host.nameserver.address
net.host.ipnetwork.local.address
net.host.portnetwork.local.port
net.peer.nameserver.address
net.peer.ipnetwork.peer.address
net.peer.portnetwork.peer.port
net.transportnetwork.transport

@s1gr1d
s1gr1d requested review from a team as code ownersAugust 11, 2026 14:43
@s1gr1d
s1gr1d requested review from JPeer264 and mydea and removed request for a teamAugust 11, 2026 14:43
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run


String and regular-expression matching for `tracePropagationTargets` is now case-insensitive.

### Span attribute changes

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added all already existing entries regarding attribute changes under this heading.

Comment threaddev-packages/node-integration-tests/suites/tracing/mysql/test.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@github-actions

github-actionsBot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser30.3 kB--
@sentry/browser - with treeshaking flags28.47 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.81 kB--
@sentry/browser (incl. Tracing)48.61 kB+0.06%+27 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.61 kB+0.05%+21 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.48 kB+0.04%+20 B 🔺
@sentry/browser (incl. Tracing, Replay)88 kB+0.03%+19 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.38 kB+0.03%+20 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)92.72 kB+0.03%+21 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)105.42 kB+0.02%+20 B 🔺
@sentry/browser (incl. Feedback)47.65 kB--
@sentry/browser (incl. sendFeedback)35.13 kB--
@sentry/browser (incl. FeedbackAsync)40.28 kB--
@sentry/browser (incl. Metrics)31.24 kB--
@sentry/browser (incl. Logs)31.52 kB--
@sentry/browser (incl. Metrics & Logs)32.15 kB--
@sentry/react32.09 kB--
@sentry/react (incl. Tracing)50.79 kB+0.05%+23 B 🔺
@sentry/vue35.34 kB--
@sentry/vue (incl. Tracing)50.56 kB+0.05%+23 B 🔺
@sentry/svelte30.33 kB--
CDN Bundle31.61 kB--
CDN Bundle (incl. Tracing)48.91 kB+0.05%+20 B 🔺
CDN Bundle (incl. Logs, Metrics)33.8 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.84 kB+0.05%+22 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)74.31 kB--
CDN Bundle (incl. Tracing, Replay)86.5 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.33 kB+0.03%+20 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.21 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.15 kB+0.03%+22 B 🔺
CDN Bundle - uncompressed93.84 kB--
CDN Bundle (incl. Tracing) - uncompressed146.8 kB+0.04%+50 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed100.14 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.49 kB+0.04%+50 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed229.08 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.06 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.73 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.76 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.42 kB+0.02%+50 B 🔺
@sentry/nextjs (client)53.31 kB+0.04%+21 B 🔺
@sentry/sveltekit (client)49.02 kB+0.04%+18 B 🔺
@sentry/core/server65.51 kB+0.2%+130 B 🔺
@sentry/core/browser51.75 kB+0.06%+27 B 🔺
@sentry/node117.54 kB+0.09%+96 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing82.02 kB+0.06%+44 B 🔺
@sentry/aws-serverless91.44 kB+0.12%+102 B 🔺
@sentry/cloudflare (withSentry) - minified194.61 kB+0.08%+145 B 🔺
@sentry/cloudflare (withSentry)481.16 kB+0.06%+280 B 🔺

View base workflow run

@s1gr1d
s1gr1d marked this pull request as draft August 11, 2026 15:02
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@s1gr1d
s1gr1d marked this pull request as ready for review August 12, 2026 13:19
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Just got smol suggestions. Also the title should have a !

Comment threadpackages/server-utils/src/integrations/mysql.ts Outdated
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@s1gr1ds1gr1d changed the title feat: Rename deprecated net. span attributesfeat!: Rename deprecated net. span attributesAug 13, 2026
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
s1gr1dand others added 2 commits August 24, 2026 10:50
Develop landed the same `net.*` -> `server.*`/`network.*` rename for db and
messaging spans (#23422), plus a `db.*` rename (#23408) and a restructure of
the redis/mysql2/mongoose integrations, so that half of this branch is
superseded. Conflicts in `packages/server-utils` and the db/messaging test
assertions resolve to develop's version; the orchestrion e2e test apps develop
deleted in #23349 stay deleted. `docs/migration/v11-end-state.md` keeps this
branch's sectioned layout and `net.*` mapping table with develop's added
entries folded in.
The branch's own work - the HTTP server and client network attributes in
core, node, cloudflare and deno - is unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
newAttributes[SERVER_PORT] = localPort;
newAttributes[NETWORK_LOCAL_ADDRESS] = localAddress;
newAttributes[NETWORK_LOCAL_PORT] = localPort;
newAttributes[CLIENT_ADDRESS] = collectClientAddress ? remoteAddress : undefined;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

client.address should hold the real client address behind any intermediary like a proxy (per otel spec). Since client.address is an alias of http.client_ip, we could just do the same as with http.client_ip in line 186 (which will be removed in #23423) and set the IP from the x-forwarded-for header instead (and maybe keep the socket's address as a fallback)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied here: 6842701

@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 6842701. Configure here.

msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@s1gr1d
s1gr1d merged commit b9c864b into developAug 24, 2026
272 of 273 checks passed
@s1gr1d
s1gr1d deleted the sig/network-attributes branch August 24, 2026 11:09
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 pushed a commit that referenced this pull request Aug 25, 2026
Related to Linear:
https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes
| v10 attribute | v11 attribute |
| --------------- | ----------------------- |
| `net.host.name` | `server.address` |
| `net.host.ip` | `network.local.address` |
| `net.host.port` | `network.local.port` |
| `net.peer.name` | `server.address` |
| `net.peer.ip` | `network.peer.address` |
| `net.peer.port` | `network.peer.port` |
| `net.transport` | `network.transport` |
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 26, 2026
This PR covers the 1:1 renames and removals on HTTP spans. `http.target`
and the Node body size behavior change follow in stacked PRs.
| Old Attribute | New Attribute |
|---|---|
| `http.method` | `http.request.method` |
| `http.status_code` | `http.response.status_code` |
| `http.status_text` | `http.response.status_text` |
| `http.scheme` | `url.scheme` |
| `http.user_agent` | `user_agent.original` |
| `http.request_content_length` | `http.request.body.size` |
| `http.request_content_length_uncompressed` |
`http.request.body.decoded_size` |
| `http.response_content_length` | `http.response.body.size` |
| `http.response_content_length_uncompressed` |
`http.response.body.decoded_size`|
| `http.decoded_response_content_length` |
`http.response.body.decoded_size` |
| `http.response_transfer_size` | `http.response.size` |
| `url.same_origin` | `http.request.same_origin` |
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements (`server.address`,
`network.protocol.version` and `client.address`) are already being set
(introduced in
#23301).
part of #18895
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport` (#588)
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@s1gr1d@JPeer264@msonnb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat!: Rename deprecated net. span attributes - #23301

Merged
s1gr1d merged 12 commits into
developfrom
sig/network-attributes
Aug 24, 2026
Merged

feat!: Rename deprecated net. span attributes#23301
s1gr1d merged 12 commits into
developfrom
sig/network-attributes

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Related to Linear: https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes

v10 attributev11 attribute
net.host.nameserver.address
net.host.ipnetwork.local.address
net.host.portnetwork.local.port
net.peer.nameserver.address
net.peer.ipnetwork.peer.address
net.peer.portnetwork.peer.port
net.transportnetwork.transport

@s1gr1d
s1gr1d requested review from a team as code ownersAugust 11, 2026 14:43
@s1gr1d
s1gr1d requested review from JPeer264 and mydea and removed request for a teamAugust 11, 2026 14:43
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run


String and regular-expression matching for `tracePropagationTargets` is now case-insensitive.

### Span attribute changes

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added all already existing entries regarding attribute changes under this heading.

Comment threaddev-packages/node-integration-tests/suites/tracing/mysql/test.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@github-actions

github-actionsBot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser30.3 kB--
@sentry/browser - with treeshaking flags28.47 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.81 kB--
@sentry/browser (incl. Tracing)48.61 kB+0.06%+27 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.61 kB+0.05%+21 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.48 kB+0.04%+20 B 🔺
@sentry/browser (incl. Tracing, Replay)88 kB+0.03%+19 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.38 kB+0.03%+20 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)92.72 kB+0.03%+21 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)105.42 kB+0.02%+20 B 🔺
@sentry/browser (incl. Feedback)47.65 kB--
@sentry/browser (incl. sendFeedback)35.13 kB--
@sentry/browser (incl. FeedbackAsync)40.28 kB--
@sentry/browser (incl. Metrics)31.24 kB--
@sentry/browser (incl. Logs)31.52 kB--
@sentry/browser (incl. Metrics & Logs)32.15 kB--
@sentry/react32.09 kB--
@sentry/react (incl. Tracing)50.79 kB+0.05%+23 B 🔺
@sentry/vue35.34 kB--
@sentry/vue (incl. Tracing)50.56 kB+0.05%+23 B 🔺
@sentry/svelte30.33 kB--
CDN Bundle31.61 kB--
CDN Bundle (incl. Tracing)48.91 kB+0.05%+20 B 🔺
CDN Bundle (incl. Logs, Metrics)33.8 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.84 kB+0.05%+22 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)74.31 kB--
CDN Bundle (incl. Tracing, Replay)86.5 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.33 kB+0.03%+20 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.21 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.15 kB+0.03%+22 B 🔺
CDN Bundle - uncompressed93.84 kB--
CDN Bundle (incl. Tracing) - uncompressed146.8 kB+0.04%+50 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed100.14 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.49 kB+0.04%+50 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed229.08 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.06 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.73 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.76 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.42 kB+0.02%+50 B 🔺
@sentry/nextjs (client)53.31 kB+0.04%+21 B 🔺
@sentry/sveltekit (client)49.02 kB+0.04%+18 B 🔺
@sentry/core/server65.51 kB+0.2%+130 B 🔺
@sentry/core/browser51.75 kB+0.06%+27 B 🔺
@sentry/node117.54 kB+0.09%+96 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing82.02 kB+0.06%+44 B 🔺
@sentry/aws-serverless91.44 kB+0.12%+102 B 🔺
@sentry/cloudflare (withSentry) - minified194.61 kB+0.08%+145 B 🔺
@sentry/cloudflare (withSentry)481.16 kB+0.06%+280 B 🔺

View base workflow run

@s1gr1d
s1gr1d marked this pull request as draft August 11, 2026 15:02
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@s1gr1d
s1gr1d marked this pull request as ready for review August 12, 2026 13:19
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Just got smol suggestions. Also the title should have a !

Comment threadpackages/server-utils/src/integrations/mysql.ts Outdated
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@s1gr1ds1gr1d changed the title feat: Rename deprecated net. span attributesfeat!: Rename deprecated net. span attributesAug 13, 2026
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
s1gr1dand others added 2 commits August 24, 2026 10:50
Develop landed the same `net.*` -> `server.*`/`network.*` rename for db and
messaging spans (#23422), plus a `db.*` rename (#23408) and a restructure of
the redis/mysql2/mongoose integrations, so that half of this branch is
superseded. Conflicts in `packages/server-utils` and the db/messaging test
assertions resolve to develop's version; the orchestrion e2e test apps develop
deleted in #23349 stay deleted. `docs/migration/v11-end-state.md` keeps this
branch's sectioned layout and `net.*` mapping table with develop's added
entries folded in.
The branch's own work - the HTTP server and client network attributes in
core, node, cloudflare and deno - is unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
newAttributes[SERVER_PORT] = localPort;
newAttributes[NETWORK_LOCAL_ADDRESS] = localAddress;
newAttributes[NETWORK_LOCAL_PORT] = localPort;
newAttributes[CLIENT_ADDRESS] = collectClientAddress ? remoteAddress : undefined;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

client.address should hold the real client address behind any intermediary like a proxy (per otel spec). Since client.address is an alias of http.client_ip, we could just do the same as with http.client_ip in line 186 (which will be removed in #23423) and set the IP from the x-forwarded-for header instead (and maybe keep the socket's address as a fallback)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied here: 6842701

@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 6842701. Configure here.

msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@s1gr1d
s1gr1d merged commit b9c864b into developAug 24, 2026
272 of 273 checks passed
@s1gr1d
s1gr1d deleted the sig/network-attributes branch August 24, 2026 11:09
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 pushed a commit that referenced this pull request Aug 25, 2026
Related to Linear:
https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes
| v10 attribute | v11 attribute |
| --------------- | ----------------------- |
| `net.host.name` | `server.address` |
| `net.host.ip` | `network.local.address` |
| `net.host.port` | `network.local.port` |
| `net.peer.name` | `server.address` |
| `net.peer.ip` | `network.peer.address` |
| `net.peer.port` | `network.peer.port` |
| `net.transport` | `network.transport` |
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 26, 2026
This PR covers the 1:1 renames and removals on HTTP spans. `http.target`
and the Node body size behavior change follow in stacked PRs.
| Old Attribute | New Attribute |
|---|---|
| `http.method` | `http.request.method` |
| `http.status_code` | `http.response.status_code` |
| `http.status_text` | `http.response.status_text` |
| `http.scheme` | `url.scheme` |
| `http.user_agent` | `user_agent.original` |
| `http.request_content_length` | `http.request.body.size` |
| `http.request_content_length_uncompressed` |
`http.request.body.decoded_size` |
| `http.response_content_length` | `http.response.body.size` |
| `http.response_content_length_uncompressed` |
`http.response.body.decoded_size`|
| `http.decoded_response_content_length` |
`http.response.body.decoded_size` |
| `http.response_transfer_size` | `http.response.size` |
| `url.same_origin` | `http.request.same_origin` |
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements (`server.address`,
`network.protocol.version` and `client.address`) are already being set
(introduced in
#23301).
part of #18895
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport` (#588)
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@s1gr1d@JPeer264@msonnb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat!: Rename deprecated net. span attributes - #23301

Merged
s1gr1d merged 12 commits into
developfrom
sig/network-attributes
Aug 24, 2026
Merged

feat!: Rename deprecated net. span attributes#23301
s1gr1d merged 12 commits into
developfrom
sig/network-attributes

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Related to Linear: https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes

v10 attributev11 attribute
net.host.nameserver.address
net.host.ipnetwork.local.address
net.host.portnetwork.local.port
net.peer.nameserver.address
net.peer.ipnetwork.peer.address
net.peer.portnetwork.peer.port
net.transportnetwork.transport

@s1gr1d
s1gr1d requested review from a team as code ownersAugust 11, 2026 14:43
@s1gr1d
s1gr1d requested review from JPeer264 and mydea and removed request for a teamAugust 11, 2026 14:43
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run


String and regular-expression matching for `tracePropagationTargets` is now case-insensitive.

### Span attribute changes

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added all already existing entries regarding attribute changes under this heading.

Comment threaddev-packages/node-integration-tests/suites/tracing/mysql/test.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@github-actions

github-actionsBot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser30.3 kB--
@sentry/browser - with treeshaking flags28.47 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.81 kB--
@sentry/browser (incl. Tracing)48.61 kB+0.06%+27 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.61 kB+0.05%+21 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.48 kB+0.04%+20 B 🔺
@sentry/browser (incl. Tracing, Replay)88 kB+0.03%+19 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.38 kB+0.03%+20 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)92.72 kB+0.03%+21 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)105.42 kB+0.02%+20 B 🔺
@sentry/browser (incl. Feedback)47.65 kB--
@sentry/browser (incl. sendFeedback)35.13 kB--
@sentry/browser (incl. FeedbackAsync)40.28 kB--
@sentry/browser (incl. Metrics)31.24 kB--
@sentry/browser (incl. Logs)31.52 kB--
@sentry/browser (incl. Metrics & Logs)32.15 kB--
@sentry/react32.09 kB--
@sentry/react (incl. Tracing)50.79 kB+0.05%+23 B 🔺
@sentry/vue35.34 kB--
@sentry/vue (incl. Tracing)50.56 kB+0.05%+23 B 🔺
@sentry/svelte30.33 kB--
CDN Bundle31.61 kB--
CDN Bundle (incl. Tracing)48.91 kB+0.05%+20 B 🔺
CDN Bundle (incl. Logs, Metrics)33.8 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.84 kB+0.05%+22 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)74.31 kB--
CDN Bundle (incl. Tracing, Replay)86.5 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.33 kB+0.03%+20 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.21 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.15 kB+0.03%+22 B 🔺
CDN Bundle - uncompressed93.84 kB--
CDN Bundle (incl. Tracing) - uncompressed146.8 kB+0.04%+50 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed100.14 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.49 kB+0.04%+50 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed229.08 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.06 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.73 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.76 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.42 kB+0.02%+50 B 🔺
@sentry/nextjs (client)53.31 kB+0.04%+21 B 🔺
@sentry/sveltekit (client)49.02 kB+0.04%+18 B 🔺
@sentry/core/server65.51 kB+0.2%+130 B 🔺
@sentry/core/browser51.75 kB+0.06%+27 B 🔺
@sentry/node117.54 kB+0.09%+96 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing82.02 kB+0.06%+44 B 🔺
@sentry/aws-serverless91.44 kB+0.12%+102 B 🔺
@sentry/cloudflare (withSentry) - minified194.61 kB+0.08%+145 B 🔺
@sentry/cloudflare (withSentry)481.16 kB+0.06%+280 B 🔺

View base workflow run

@s1gr1d
s1gr1d marked this pull request as draft August 11, 2026 15:02
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@s1gr1d
s1gr1d marked this pull request as ready for review August 12, 2026 13:19
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Just got smol suggestions. Also the title should have a !

Comment threadpackages/server-utils/src/integrations/mysql.ts Outdated
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@s1gr1ds1gr1d changed the title feat: Rename deprecated net. span attributesfeat!: Rename deprecated net. span attributesAug 13, 2026
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
s1gr1dand others added 2 commits August 24, 2026 10:50
Develop landed the same `net.*` -> `server.*`/`network.*` rename for db and
messaging spans (#23422), plus a `db.*` rename (#23408) and a restructure of
the redis/mysql2/mongoose integrations, so that half of this branch is
superseded. Conflicts in `packages/server-utils` and the db/messaging test
assertions resolve to develop's version; the orchestrion e2e test apps develop
deleted in #23349 stay deleted. `docs/migration/v11-end-state.md` keeps this
branch's sectioned layout and `net.*` mapping table with develop's added
entries folded in.
The branch's own work - the HTTP server and client network attributes in
core, node, cloudflare and deno - is unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
newAttributes[SERVER_PORT] = localPort;
newAttributes[NETWORK_LOCAL_ADDRESS] = localAddress;
newAttributes[NETWORK_LOCAL_PORT] = localPort;
newAttributes[CLIENT_ADDRESS] = collectClientAddress ? remoteAddress : undefined;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

client.address should hold the real client address behind any intermediary like a proxy (per otel spec). Since client.address is an alias of http.client_ip, we could just do the same as with http.client_ip in line 186 (which will be removed in #23423) and set the IP from the x-forwarded-for header instead (and maybe keep the socket's address as a fallback)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied here: 6842701

@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 6842701. Configure here.

msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@s1gr1d
s1gr1d merged commit b9c864b into developAug 24, 2026
272 of 273 checks passed
@s1gr1d
s1gr1d deleted the sig/network-attributes branch August 24, 2026 11:09
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 pushed a commit that referenced this pull request Aug 25, 2026
Related to Linear:
https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes
| v10 attribute | v11 attribute |
| --------------- | ----------------------- |
| `net.host.name` | `server.address` |
| `net.host.ip` | `network.local.address` |
| `net.host.port` | `network.local.port` |
| `net.peer.name` | `server.address` |
| `net.peer.ip` | `network.peer.address` |
| `net.peer.port` | `network.peer.port` |
| `net.transport` | `network.transport` |
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 26, 2026
This PR covers the 1:1 renames and removals on HTTP spans. `http.target`
and the Node body size behavior change follow in stacked PRs.
| Old Attribute | New Attribute |
|---|---|
| `http.method` | `http.request.method` |
| `http.status_code` | `http.response.status_code` |
| `http.status_text` | `http.response.status_text` |
| `http.scheme` | `url.scheme` |
| `http.user_agent` | `user_agent.original` |
| `http.request_content_length` | `http.request.body.size` |
| `http.request_content_length_uncompressed` |
`http.request.body.decoded_size` |
| `http.response_content_length` | `http.response.body.size` |
| `http.response_content_length_uncompressed` |
`http.response.body.decoded_size`|
| `http.decoded_response_content_length` |
`http.response.body.decoded_size` |
| `http.response_transfer_size` | `http.response.size` |
| `url.same_origin` | `http.request.same_origin` |
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements (`server.address`,
`network.protocol.version` and `client.address`) are already being set
(introduced in
#23301).
part of #18895
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport` (#588)
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@s1gr1d@JPeer264@msonnb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat!: Rename deprecated net. span attributes - #23301

Merged
s1gr1d merged 12 commits into
developfrom
sig/network-attributes
Aug 24, 2026
Merged

feat!: Rename deprecated net. span attributes#23301
s1gr1d merged 12 commits into
developfrom
sig/network-attributes

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Related to Linear: https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes

v10 attributev11 attribute
net.host.nameserver.address
net.host.ipnetwork.local.address
net.host.portnetwork.local.port
net.peer.nameserver.address
net.peer.ipnetwork.peer.address
net.peer.portnetwork.peer.port
net.transportnetwork.transport

@s1gr1d
s1gr1d requested review from a team as code ownersAugust 11, 2026 14:43
@s1gr1d
s1gr1d requested review from JPeer264 and mydea and removed request for a teamAugust 11, 2026 14:43
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run


String and regular-expression matching for `tracePropagationTargets` is now case-insensitive.

### Span attribute changes

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added all already existing entries regarding attribute changes under this heading.

Comment threaddev-packages/node-integration-tests/suites/tracing/mysql/test.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@github-actions

github-actionsBot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser30.3 kB--
@sentry/browser - with treeshaking flags28.47 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.81 kB--
@sentry/browser (incl. Tracing)48.61 kB+0.06%+27 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.61 kB+0.05%+21 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.48 kB+0.04%+20 B 🔺
@sentry/browser (incl. Tracing, Replay)88 kB+0.03%+19 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.38 kB+0.03%+20 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)92.72 kB+0.03%+21 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)105.42 kB+0.02%+20 B 🔺
@sentry/browser (incl. Feedback)47.65 kB--
@sentry/browser (incl. sendFeedback)35.13 kB--
@sentry/browser (incl. FeedbackAsync)40.28 kB--
@sentry/browser (incl. Metrics)31.24 kB--
@sentry/browser (incl. Logs)31.52 kB--
@sentry/browser (incl. Metrics & Logs)32.15 kB--
@sentry/react32.09 kB--
@sentry/react (incl. Tracing)50.79 kB+0.05%+23 B 🔺
@sentry/vue35.34 kB--
@sentry/vue (incl. Tracing)50.56 kB+0.05%+23 B 🔺
@sentry/svelte30.33 kB--
CDN Bundle31.61 kB--
CDN Bundle (incl. Tracing)48.91 kB+0.05%+20 B 🔺
CDN Bundle (incl. Logs, Metrics)33.8 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.84 kB+0.05%+22 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)74.31 kB--
CDN Bundle (incl. Tracing, Replay)86.5 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.33 kB+0.03%+20 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.21 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.15 kB+0.03%+22 B 🔺
CDN Bundle - uncompressed93.84 kB--
CDN Bundle (incl. Tracing) - uncompressed146.8 kB+0.04%+50 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed100.14 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.49 kB+0.04%+50 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed229.08 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.06 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.73 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.76 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.42 kB+0.02%+50 B 🔺
@sentry/nextjs (client)53.31 kB+0.04%+21 B 🔺
@sentry/sveltekit (client)49.02 kB+0.04%+18 B 🔺
@sentry/core/server65.51 kB+0.2%+130 B 🔺
@sentry/core/browser51.75 kB+0.06%+27 B 🔺
@sentry/node117.54 kB+0.09%+96 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing82.02 kB+0.06%+44 B 🔺
@sentry/aws-serverless91.44 kB+0.12%+102 B 🔺
@sentry/cloudflare (withSentry) - minified194.61 kB+0.08%+145 B 🔺
@sentry/cloudflare (withSentry)481.16 kB+0.06%+280 B 🔺

View base workflow run

@s1gr1d
s1gr1d marked this pull request as draft August 11, 2026 15:02
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@s1gr1d
s1gr1d marked this pull request as ready for review August 12, 2026 13:19
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Just got smol suggestions. Also the title should have a !

Comment threadpackages/server-utils/src/integrations/mysql.ts Outdated
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@s1gr1ds1gr1d changed the title feat: Rename deprecated net. span attributesfeat!: Rename deprecated net. span attributesAug 13, 2026
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
s1gr1dand others added 2 commits August 24, 2026 10:50
Develop landed the same `net.*` -> `server.*`/`network.*` rename for db and
messaging spans (#23422), plus a `db.*` rename (#23408) and a restructure of
the redis/mysql2/mongoose integrations, so that half of this branch is
superseded. Conflicts in `packages/server-utils` and the db/messaging test
assertions resolve to develop's version; the orchestrion e2e test apps develop
deleted in #23349 stay deleted. `docs/migration/v11-end-state.md` keeps this
branch's sectioned layout and `net.*` mapping table with develop's added
entries folded in.
The branch's own work - the HTTP server and client network attributes in
core, node, cloudflare and deno - is unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
newAttributes[SERVER_PORT] = localPort;
newAttributes[NETWORK_LOCAL_ADDRESS] = localAddress;
newAttributes[NETWORK_LOCAL_PORT] = localPort;
newAttributes[CLIENT_ADDRESS] = collectClientAddress ? remoteAddress : undefined;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

client.address should hold the real client address behind any intermediary like a proxy (per otel spec). Since client.address is an alias of http.client_ip, we could just do the same as with http.client_ip in line 186 (which will be removed in #23423) and set the IP from the x-forwarded-for header instead (and maybe keep the socket's address as a fallback)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied here: 6842701

@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 6842701. Configure here.

msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@s1gr1d
s1gr1d merged commit b9c864b into developAug 24, 2026
272 of 273 checks passed
@s1gr1d
s1gr1d deleted the sig/network-attributes branch August 24, 2026 11:09
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 pushed a commit that referenced this pull request Aug 25, 2026
Related to Linear:
https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes
| v10 attribute | v11 attribute |
| --------------- | ----------------------- |
| `net.host.name` | `server.address` |
| `net.host.ip` | `network.local.address` |
| `net.host.port` | `network.local.port` |
| `net.peer.name` | `server.address` |
| `net.peer.ip` | `network.peer.address` |
| `net.peer.port` | `network.peer.port` |
| `net.transport` | `network.transport` |
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 26, 2026
This PR covers the 1:1 renames and removals on HTTP spans. `http.target`
and the Node body size behavior change follow in stacked PRs.
| Old Attribute | New Attribute |
|---|---|
| `http.method` | `http.request.method` |
| `http.status_code` | `http.response.status_code` |
| `http.status_text` | `http.response.status_text` |
| `http.scheme` | `url.scheme` |
| `http.user_agent` | `user_agent.original` |
| `http.request_content_length` | `http.request.body.size` |
| `http.request_content_length_uncompressed` |
`http.request.body.decoded_size` |
| `http.response_content_length` | `http.response.body.size` |
| `http.response_content_length_uncompressed` |
`http.response.body.decoded_size`|
| `http.decoded_response_content_length` |
`http.response.body.decoded_size` |
| `http.response_transfer_size` | `http.response.size` |
| `url.same_origin` | `http.request.same_origin` |
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements (`server.address`,
`network.protocol.version` and `client.address`) are already being set
(introduced in
#23301).
part of #18895
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport` (#588)
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@s1gr1d@JPeer264@msonnb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat!: Rename deprecated net. span attributes - #23301

Merged
s1gr1d merged 12 commits into
developfrom
sig/network-attributes
Aug 24, 2026
Merged

feat!: Rename deprecated net. span attributes#23301
s1gr1d merged 12 commits into
developfrom
sig/network-attributes

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Related to Linear: https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes

v10 attributev11 attribute
net.host.nameserver.address
net.host.ipnetwork.local.address
net.host.portnetwork.local.port
net.peer.nameserver.address
net.peer.ipnetwork.peer.address
net.peer.portnetwork.peer.port
net.transportnetwork.transport

@s1gr1d
s1gr1d requested review from a team as code ownersAugust 11, 2026 14:43
@s1gr1d
s1gr1d requested review from JPeer264 and mydea and removed request for a teamAugust 11, 2026 14:43
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run


String and regular-expression matching for `tracePropagationTargets` is now case-insensitive.

### Span attribute changes

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added all already existing entries regarding attribute changes under this heading.

Comment threaddev-packages/node-integration-tests/suites/tracing/mysql/test.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@github-actions

github-actionsBot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser30.3 kB--
@sentry/browser - with treeshaking flags28.47 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.81 kB--
@sentry/browser (incl. Tracing)48.61 kB+0.06%+27 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.61 kB+0.05%+21 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.48 kB+0.04%+20 B 🔺
@sentry/browser (incl. Tracing, Replay)88 kB+0.03%+19 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.38 kB+0.03%+20 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)92.72 kB+0.03%+21 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)105.42 kB+0.02%+20 B 🔺
@sentry/browser (incl. Feedback)47.65 kB--
@sentry/browser (incl. sendFeedback)35.13 kB--
@sentry/browser (incl. FeedbackAsync)40.28 kB--
@sentry/browser (incl. Metrics)31.24 kB--
@sentry/browser (incl. Logs)31.52 kB--
@sentry/browser (incl. Metrics & Logs)32.15 kB--
@sentry/react32.09 kB--
@sentry/react (incl. Tracing)50.79 kB+0.05%+23 B 🔺
@sentry/vue35.34 kB--
@sentry/vue (incl. Tracing)50.56 kB+0.05%+23 B 🔺
@sentry/svelte30.33 kB--
CDN Bundle31.61 kB--
CDN Bundle (incl. Tracing)48.91 kB+0.05%+20 B 🔺
CDN Bundle (incl. Logs, Metrics)33.8 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.84 kB+0.05%+22 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)74.31 kB--
CDN Bundle (incl. Tracing, Replay)86.5 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.33 kB+0.03%+20 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.21 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.15 kB+0.03%+22 B 🔺
CDN Bundle - uncompressed93.84 kB--
CDN Bundle (incl. Tracing) - uncompressed146.8 kB+0.04%+50 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed100.14 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.49 kB+0.04%+50 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed229.08 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.06 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.73 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.76 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.42 kB+0.02%+50 B 🔺
@sentry/nextjs (client)53.31 kB+0.04%+21 B 🔺
@sentry/sveltekit (client)49.02 kB+0.04%+18 B 🔺
@sentry/core/server65.51 kB+0.2%+130 B 🔺
@sentry/core/browser51.75 kB+0.06%+27 B 🔺
@sentry/node117.54 kB+0.09%+96 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing82.02 kB+0.06%+44 B 🔺
@sentry/aws-serverless91.44 kB+0.12%+102 B 🔺
@sentry/cloudflare (withSentry) - minified194.61 kB+0.08%+145 B 🔺
@sentry/cloudflare (withSentry)481.16 kB+0.06%+280 B 🔺

View base workflow run

@s1gr1d
s1gr1d marked this pull request as draft August 11, 2026 15:02
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@s1gr1d
s1gr1d marked this pull request as ready for review August 12, 2026 13:19
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Just got smol suggestions. Also the title should have a !

Comment threadpackages/server-utils/src/integrations/mysql.ts Outdated
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@s1gr1ds1gr1d changed the title feat: Rename deprecated net. span attributesfeat!: Rename deprecated net. span attributesAug 13, 2026
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
s1gr1dand others added 2 commits August 24, 2026 10:50
Develop landed the same `net.*` -> `server.*`/`network.*` rename for db and
messaging spans (#23422), plus a `db.*` rename (#23408) and a restructure of
the redis/mysql2/mongoose integrations, so that half of this branch is
superseded. Conflicts in `packages/server-utils` and the db/messaging test
assertions resolve to develop's version; the orchestrion e2e test apps develop
deleted in #23349 stay deleted. `docs/migration/v11-end-state.md` keeps this
branch's sectioned layout and `net.*` mapping table with develop's added
entries folded in.
The branch's own work - the HTTP server and client network attributes in
core, node, cloudflare and deno - is unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
newAttributes[SERVER_PORT] = localPort;
newAttributes[NETWORK_LOCAL_ADDRESS] = localAddress;
newAttributes[NETWORK_LOCAL_PORT] = localPort;
newAttributes[CLIENT_ADDRESS] = collectClientAddress ? remoteAddress : undefined;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

client.address should hold the real client address behind any intermediary like a proxy (per otel spec). Since client.address is an alias of http.client_ip, we could just do the same as with http.client_ip in line 186 (which will be removed in #23423) and set the IP from the x-forwarded-for header instead (and maybe keep the socket's address as a fallback)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied here: 6842701

@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 6842701. Configure here.

msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@s1gr1d
s1gr1d merged commit b9c864b into developAug 24, 2026
272 of 273 checks passed
@s1gr1d
s1gr1d deleted the sig/network-attributes branch August 24, 2026 11:09
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 pushed a commit that referenced this pull request Aug 25, 2026
Related to Linear:
https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes
| v10 attribute | v11 attribute |
| --------------- | ----------------------- |
| `net.host.name` | `server.address` |
| `net.host.ip` | `network.local.address` |
| `net.host.port` | `network.local.port` |
| `net.peer.name` | `server.address` |
| `net.peer.ip` | `network.peer.address` |
| `net.peer.port` | `network.peer.port` |
| `net.transport` | `network.transport` |
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 26, 2026
This PR covers the 1:1 renames and removals on HTTP spans. `http.target`
and the Node body size behavior change follow in stacked PRs.
| Old Attribute | New Attribute |
|---|---|
| `http.method` | `http.request.method` |
| `http.status_code` | `http.response.status_code` |
| `http.status_text` | `http.response.status_text` |
| `http.scheme` | `url.scheme` |
| `http.user_agent` | `user_agent.original` |
| `http.request_content_length` | `http.request.body.size` |
| `http.request_content_length_uncompressed` |
`http.request.body.decoded_size` |
| `http.response_content_length` | `http.response.body.size` |
| `http.response_content_length_uncompressed` |
`http.response.body.decoded_size`|
| `http.decoded_response_content_length` |
`http.response.body.decoded_size` |
| `http.response_transfer_size` | `http.response.size` |
| `url.same_origin` | `http.request.same_origin` |
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements (`server.address`,
`network.protocol.version` and `client.address`) are already being set
(introduced in
#23301).
part of #18895
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport` (#588)
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@s1gr1d@JPeer264@msonnb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat!: Rename deprecated net. span attributes - #23301

Merged
s1gr1d merged 12 commits into
developfrom
sig/network-attributes
Aug 24, 2026
Merged

feat!: Rename deprecated net. span attributes#23301
s1gr1d merged 12 commits into
developfrom
sig/network-attributes

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Related to Linear: https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes

v10 attributev11 attribute
net.host.nameserver.address
net.host.ipnetwork.local.address
net.host.portnetwork.local.port
net.peer.nameserver.address
net.peer.ipnetwork.peer.address
net.peer.portnetwork.peer.port
net.transportnetwork.transport

@s1gr1d
s1gr1d requested review from a team as code ownersAugust 11, 2026 14:43
@s1gr1d
s1gr1d requested review from JPeer264 and mydea and removed request for a teamAugust 11, 2026 14:43
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run


String and regular-expression matching for `tracePropagationTargets` is now case-insensitive.

### Span attribute changes

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added all already existing entries regarding attribute changes under this heading.

Comment threaddev-packages/node-integration-tests/suites/tracing/mysql/test.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@github-actions

github-actionsBot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser30.3 kB--
@sentry/browser - with treeshaking flags28.47 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.81 kB--
@sentry/browser (incl. Tracing)48.61 kB+0.06%+27 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.61 kB+0.05%+21 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.48 kB+0.04%+20 B 🔺
@sentry/browser (incl. Tracing, Replay)88 kB+0.03%+19 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.38 kB+0.03%+20 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)92.72 kB+0.03%+21 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)105.42 kB+0.02%+20 B 🔺
@sentry/browser (incl. Feedback)47.65 kB--
@sentry/browser (incl. sendFeedback)35.13 kB--
@sentry/browser (incl. FeedbackAsync)40.28 kB--
@sentry/browser (incl. Metrics)31.24 kB--
@sentry/browser (incl. Logs)31.52 kB--
@sentry/browser (incl. Metrics & Logs)32.15 kB--
@sentry/react32.09 kB--
@sentry/react (incl. Tracing)50.79 kB+0.05%+23 B 🔺
@sentry/vue35.34 kB--
@sentry/vue (incl. Tracing)50.56 kB+0.05%+23 B 🔺
@sentry/svelte30.33 kB--
CDN Bundle31.61 kB--
CDN Bundle (incl. Tracing)48.91 kB+0.05%+20 B 🔺
CDN Bundle (incl. Logs, Metrics)33.8 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.84 kB+0.05%+22 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)74.31 kB--
CDN Bundle (incl. Tracing, Replay)86.5 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.33 kB+0.03%+20 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.21 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.15 kB+0.03%+22 B 🔺
CDN Bundle - uncompressed93.84 kB--
CDN Bundle (incl. Tracing) - uncompressed146.8 kB+0.04%+50 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed100.14 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.49 kB+0.04%+50 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed229.08 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.06 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.73 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.76 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.42 kB+0.02%+50 B 🔺
@sentry/nextjs (client)53.31 kB+0.04%+21 B 🔺
@sentry/sveltekit (client)49.02 kB+0.04%+18 B 🔺
@sentry/core/server65.51 kB+0.2%+130 B 🔺
@sentry/core/browser51.75 kB+0.06%+27 B 🔺
@sentry/node117.54 kB+0.09%+96 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing82.02 kB+0.06%+44 B 🔺
@sentry/aws-serverless91.44 kB+0.12%+102 B 🔺
@sentry/cloudflare (withSentry) - minified194.61 kB+0.08%+145 B 🔺
@sentry/cloudflare (withSentry)481.16 kB+0.06%+280 B 🔺

View base workflow run

@s1gr1d
s1gr1d marked this pull request as draft August 11, 2026 15:02
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@s1gr1d
s1gr1d marked this pull request as ready for review August 12, 2026 13:19
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Just got smol suggestions. Also the title should have a !

Comment threadpackages/server-utils/src/integrations/mysql.ts Outdated
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@s1gr1ds1gr1d changed the title feat: Rename deprecated net. span attributesfeat!: Rename deprecated net. span attributesAug 13, 2026
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
s1gr1dand others added 2 commits August 24, 2026 10:50
Develop landed the same `net.*` -> `server.*`/`network.*` rename for db and
messaging spans (#23422), plus a `db.*` rename (#23408) and a restructure of
the redis/mysql2/mongoose integrations, so that half of this branch is
superseded. Conflicts in `packages/server-utils` and the db/messaging test
assertions resolve to develop's version; the orchestrion e2e test apps develop
deleted in #23349 stay deleted. `docs/migration/v11-end-state.md` keeps this
branch's sectioned layout and `net.*` mapping table with develop's added
entries folded in.
The branch's own work - the HTTP server and client network attributes in
core, node, cloudflare and deno - is unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
newAttributes[SERVER_PORT] = localPort;
newAttributes[NETWORK_LOCAL_ADDRESS] = localAddress;
newAttributes[NETWORK_LOCAL_PORT] = localPort;
newAttributes[CLIENT_ADDRESS] = collectClientAddress ? remoteAddress : undefined;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

client.address should hold the real client address behind any intermediary like a proxy (per otel spec). Since client.address is an alias of http.client_ip, we could just do the same as with http.client_ip in line 186 (which will be removed in #23423) and set the IP from the x-forwarded-for header instead (and maybe keep the socket's address as a fallback)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied here: 6842701

@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 6842701. Configure here.

msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@s1gr1d
s1gr1d merged commit b9c864b into developAug 24, 2026
272 of 273 checks passed
@s1gr1d
s1gr1d deleted the sig/network-attributes branch August 24, 2026 11:09
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 pushed a commit that referenced this pull request Aug 25, 2026
Related to Linear:
https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes
| v10 attribute | v11 attribute |
| --------------- | ----------------------- |
| `net.host.name` | `server.address` |
| `net.host.ip` | `network.local.address` |
| `net.host.port` | `network.local.port` |
| `net.peer.name` | `server.address` |
| `net.peer.ip` | `network.peer.address` |
| `net.peer.port` | `network.peer.port` |
| `net.transport` | `network.transport` |
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 26, 2026
This PR covers the 1:1 renames and removals on HTTP spans. `http.target`
and the Node body size behavior change follow in stacked PRs.
| Old Attribute | New Attribute |
|---|---|
| `http.method` | `http.request.method` |
| `http.status_code` | `http.response.status_code` |
| `http.status_text` | `http.response.status_text` |
| `http.scheme` | `url.scheme` |
| `http.user_agent` | `user_agent.original` |
| `http.request_content_length` | `http.request.body.size` |
| `http.request_content_length_uncompressed` |
`http.request.body.decoded_size` |
| `http.response_content_length` | `http.response.body.size` |
| `http.response_content_length_uncompressed` |
`http.response.body.decoded_size`|
| `http.decoded_response_content_length` |
`http.response.body.decoded_size` |
| `http.response_transfer_size` | `http.response.size` |
| `url.same_origin` | `http.request.same_origin` |
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements (`server.address`,
`network.protocol.version` and `client.address`) are already being set
(introduced in
#23301).
part of #18895
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport` (#588)
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@s1gr1d@JPeer264@msonnb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat!: Rename deprecated net. span attributes - #23301

Merged
s1gr1d merged 12 commits into
developfrom
sig/network-attributes
Aug 24, 2026
Merged

feat!: Rename deprecated net. span attributes#23301
s1gr1d merged 12 commits into
developfrom
sig/network-attributes

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Related to Linear: https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes

v10 attributev11 attribute
net.host.nameserver.address
net.host.ipnetwork.local.address
net.host.portnetwork.local.port
net.peer.nameserver.address
net.peer.ipnetwork.peer.address
net.peer.portnetwork.peer.port
net.transportnetwork.transport

@s1gr1d
s1gr1d requested review from a team as code ownersAugust 11, 2026 14:43
@s1gr1d
s1gr1d requested review from JPeer264 and mydea and removed request for a teamAugust 11, 2026 14:43
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run


String and regular-expression matching for `tracePropagationTargets` is now case-insensitive.

### Span attribute changes

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added all already existing entries regarding attribute changes under this heading.

Comment threaddev-packages/node-integration-tests/suites/tracing/mysql/test.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@github-actions

github-actionsBot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser30.3 kB--
@sentry/browser - with treeshaking flags28.47 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.81 kB--
@sentry/browser (incl. Tracing)48.61 kB+0.06%+27 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.61 kB+0.05%+21 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.48 kB+0.04%+20 B 🔺
@sentry/browser (incl. Tracing, Replay)88 kB+0.03%+19 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.38 kB+0.03%+20 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)92.72 kB+0.03%+21 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)105.42 kB+0.02%+20 B 🔺
@sentry/browser (incl. Feedback)47.65 kB--
@sentry/browser (incl. sendFeedback)35.13 kB--
@sentry/browser (incl. FeedbackAsync)40.28 kB--
@sentry/browser (incl. Metrics)31.24 kB--
@sentry/browser (incl. Logs)31.52 kB--
@sentry/browser (incl. Metrics & Logs)32.15 kB--
@sentry/react32.09 kB--
@sentry/react (incl. Tracing)50.79 kB+0.05%+23 B 🔺
@sentry/vue35.34 kB--
@sentry/vue (incl. Tracing)50.56 kB+0.05%+23 B 🔺
@sentry/svelte30.33 kB--
CDN Bundle31.61 kB--
CDN Bundle (incl. Tracing)48.91 kB+0.05%+20 B 🔺
CDN Bundle (incl. Logs, Metrics)33.8 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.84 kB+0.05%+22 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)74.31 kB--
CDN Bundle (incl. Tracing, Replay)86.5 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.33 kB+0.03%+20 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.21 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.15 kB+0.03%+22 B 🔺
CDN Bundle - uncompressed93.84 kB--
CDN Bundle (incl. Tracing) - uncompressed146.8 kB+0.04%+50 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed100.14 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.49 kB+0.04%+50 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed229.08 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.06 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.73 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.76 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.42 kB+0.02%+50 B 🔺
@sentry/nextjs (client)53.31 kB+0.04%+21 B 🔺
@sentry/sveltekit (client)49.02 kB+0.04%+18 B 🔺
@sentry/core/server65.51 kB+0.2%+130 B 🔺
@sentry/core/browser51.75 kB+0.06%+27 B 🔺
@sentry/node117.54 kB+0.09%+96 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing82.02 kB+0.06%+44 B 🔺
@sentry/aws-serverless91.44 kB+0.12%+102 B 🔺
@sentry/cloudflare (withSentry) - minified194.61 kB+0.08%+145 B 🔺
@sentry/cloudflare (withSentry)481.16 kB+0.06%+280 B 🔺

View base workflow run

@s1gr1d
s1gr1d marked this pull request as draft August 11, 2026 15:02
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@s1gr1d
s1gr1d marked this pull request as ready for review August 12, 2026 13:19
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Just got smol suggestions. Also the title should have a !

Comment threadpackages/server-utils/src/integrations/mysql.ts Outdated
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@s1gr1ds1gr1d changed the title feat: Rename deprecated net. span attributesfeat!: Rename deprecated net. span attributesAug 13, 2026
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
s1gr1dand others added 2 commits August 24, 2026 10:50
Develop landed the same `net.*` -> `server.*`/`network.*` rename for db and
messaging spans (#23422), plus a `db.*` rename (#23408) and a restructure of
the redis/mysql2/mongoose integrations, so that half of this branch is
superseded. Conflicts in `packages/server-utils` and the db/messaging test
assertions resolve to develop's version; the orchestrion e2e test apps develop
deleted in #23349 stay deleted. `docs/migration/v11-end-state.md` keeps this
branch's sectioned layout and `net.*` mapping table with develop's added
entries folded in.
The branch's own work - the HTTP server and client network attributes in
core, node, cloudflare and deno - is unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
newAttributes[SERVER_PORT] = localPort;
newAttributes[NETWORK_LOCAL_ADDRESS] = localAddress;
newAttributes[NETWORK_LOCAL_PORT] = localPort;
newAttributes[CLIENT_ADDRESS] = collectClientAddress ? remoteAddress : undefined;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

client.address should hold the real client address behind any intermediary like a proxy (per otel spec). Since client.address is an alias of http.client_ip, we could just do the same as with http.client_ip in line 186 (which will be removed in #23423) and set the IP from the x-forwarded-for header instead (and maybe keep the socket's address as a fallback)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied here: 6842701

@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 6842701. Configure here.

msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@s1gr1d
s1gr1d merged commit b9c864b into developAug 24, 2026
272 of 273 checks passed
@s1gr1d
s1gr1d deleted the sig/network-attributes branch August 24, 2026 11:09
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 pushed a commit that referenced this pull request Aug 25, 2026
Related to Linear:
https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes
| v10 attribute | v11 attribute |
| --------------- | ----------------------- |
| `net.host.name` | `server.address` |
| `net.host.ip` | `network.local.address` |
| `net.host.port` | `network.local.port` |
| `net.peer.name` | `server.address` |
| `net.peer.ip` | `network.peer.address` |
| `net.peer.port` | `network.peer.port` |
| `net.transport` | `network.transport` |
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 26, 2026
This PR covers the 1:1 renames and removals on HTTP spans. `http.target`
and the Node body size behavior change follow in stacked PRs.
| Old Attribute | New Attribute |
|---|---|
| `http.method` | `http.request.method` |
| `http.status_code` | `http.response.status_code` |
| `http.status_text` | `http.response.status_text` |
| `http.scheme` | `url.scheme` |
| `http.user_agent` | `user_agent.original` |
| `http.request_content_length` | `http.request.body.size` |
| `http.request_content_length_uncompressed` |
`http.request.body.decoded_size` |
| `http.response_content_length` | `http.response.body.size` |
| `http.response_content_length_uncompressed` |
`http.response.body.decoded_size`|
| `http.decoded_response_content_length` |
`http.response.body.decoded_size` |
| `http.response_transfer_size` | `http.response.size` |
| `url.same_origin` | `http.request.same_origin` |
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements (`server.address`,
`network.protocol.version` and `client.address`) are already being set
(introduced in
#23301).
part of #18895
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport` (#588)
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@s1gr1d@JPeer264@msonnb
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat!: Rename deprecated net. span attributes - #23301

Merged
s1gr1d merged 12 commits into
developfrom
sig/network-attributes
Aug 24, 2026
Merged

feat!: Rename deprecated net. span attributes#23301
s1gr1d merged 12 commits into
developfrom
sig/network-attributes

Conversation

@s1gr1d

Copy link
Copy Markdown
Member

Related to Linear: https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes

v10 attributev11 attribute
net.host.nameserver.address
net.host.ipnetwork.local.address
net.host.portnetwork.local.port
net.peer.nameserver.address
net.peer.ipnetwork.peer.address
net.peer.portnetwork.peer.port
net.transportnetwork.transport

@s1gr1d
s1gr1d requested review from a team as code ownersAugust 11, 2026 14:43
@s1gr1d
s1gr1d requested review from JPeer264 and mydea and removed request for a teamAugust 11, 2026 14:43
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run


String and regular-expression matching for `tracePropagationTargets` is now case-insensitive.

### Span attribute changes

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I added all already existing entries regarding attribute changes under this heading.

Comment threaddev-packages/node-integration-tests/suites/tracing/mysql/test.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@github-actions

github-actionsBot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

PathSize% ChangeChange
@sentry/browser30.3 kB--
@sentry/browser - with treeshaking flags28.47 kB--
@sentry/browser - with treeshaking flags tracing without tracing26.81 kB--
@sentry/browser (incl. Tracing)48.61 kB+0.06%+27 B 🔺
@sentry/browser (incl. Tracing + Span Streaming)48.61 kB+0.05%+21 B 🔺
@sentry/browser (incl. Tracing, Profiling)51.48 kB+0.04%+20 B 🔺
@sentry/browser (incl. Tracing, Replay)88 kB+0.03%+19 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags77.38 kB+0.03%+20 B 🔺
@sentry/browser (incl. Tracing, Replay with Canvas)92.72 kB+0.03%+21 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback)105.42 kB+0.02%+20 B 🔺
@sentry/browser (incl. Feedback)47.65 kB--
@sentry/browser (incl. sendFeedback)35.13 kB--
@sentry/browser (incl. FeedbackAsync)40.28 kB--
@sentry/browser (incl. Metrics)31.24 kB--
@sentry/browser (incl. Logs)31.52 kB--
@sentry/browser (incl. Metrics & Logs)32.15 kB--
@sentry/react32.09 kB--
@sentry/react (incl. Tracing)50.79 kB+0.05%+23 B 🔺
@sentry/vue35.34 kB--
@sentry/vue (incl. Tracing)50.56 kB+0.05%+23 B 🔺
@sentry/svelte30.33 kB--
CDN Bundle31.61 kB--
CDN Bundle (incl. Tracing)48.91 kB+0.05%+20 B 🔺
CDN Bundle (incl. Logs, Metrics)33.8 kB--
CDN Bundle (incl. Tracing, Logs, Metrics)50.84 kB+0.05%+22 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics)74.31 kB--
CDN Bundle (incl. Tracing, Replay)86.5 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics)88.33 kB+0.03%+20 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback)92.21 kB+0.03%+22 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics)94.15 kB+0.03%+22 B 🔺
CDN Bundle - uncompressed93.84 kB--
CDN Bundle (incl. Tracing) - uncompressed146.8 kB+0.04%+50 B 🔺
CDN Bundle (incl. Logs, Metrics) - uncompressed100.14 kB--
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed152.49 kB+0.04%+50 B 🔺
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed229.08 kB--
CDN Bundle (incl. Tracing, Replay) - uncompressed266.06 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed271.73 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed279.76 kB+0.02%+50 B 🔺
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed285.42 kB+0.02%+50 B 🔺
@sentry/nextjs (client)53.31 kB+0.04%+21 B 🔺
@sentry/sveltekit (client)49.02 kB+0.04%+18 B 🔺
@sentry/core/server65.51 kB+0.2%+130 B 🔺
@sentry/core/browser51.75 kB+0.06%+27 B 🔺
@sentry/node117.54 kB+0.09%+96 B 🔺
@sentry/node/import (ESM hook with diagnostics-channel injection)85.18 kB--
@sentry/node - without tracing82.02 kB+0.06%+44 B 🔺
@sentry/aws-serverless91.44 kB+0.12%+102 B 🔺
@sentry/cloudflare (withSentry) - minified194.61 kB+0.08%+145 B 🔺
@sentry/cloudflare (withSentry)481.16 kB+0.06%+280 B 🔺

View base workflow run

@s1gr1d
s1gr1d marked this pull request as draft August 11, 2026 15:02
@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@s1gr1d
s1gr1d marked this pull request as ready for review August 12, 2026 13:19
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Just got smol suggestions. Also the title should have a !

Comment threadpackages/server-utils/src/integrations/mysql.ts Outdated
Comment threadpackages/core/src/integrations/http/get-outgoing-span-data.ts Outdated
Comment threadpackages/deno/src/wrap-deno-request-handler.ts Outdated
@s1gr1ds1gr1d changed the title feat: Rename deprecated net. span attributesfeat!: Rename deprecated net. span attributesAug 13, 2026
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
s1gr1dand others added 2 commits August 24, 2026 10:50
Develop landed the same `net.*` -> `server.*`/`network.*` rename for db and
messaging spans (#23422), plus a `db.*` rename (#23408) and a restructure of
the redis/mysql2/mongoose integrations, so that half of this branch is
superseded. Conflicts in `packages/server-utils` and the db/messaging test
assertions resolve to develop's version; the orchestrion e2e test apps develop
deleted in #23349 stay deleted. `docs/migration/v11-end-state.md` keeps this
branch's sectioned layout and `net.*` mapping table with develop's added
entries folded in.
The branch's own work - the HTTP server and client network attributes in
core, node, cloudflare and deno - is unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
newAttributes[SERVER_PORT] = localPort;
newAttributes[NETWORK_LOCAL_ADDRESS] = localAddress;
newAttributes[NETWORK_LOCAL_PORT] = localPort;
newAttributes[CLIENT_ADDRESS] = collectClientAddress ? remoteAddress : undefined;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

client.address should hold the real client address behind any intermediary like a proxy (per otel spec). Since client.address is an alias of http.client_ip, we could just do the same as with http.client_ip in line 186 (which will be removed in #23423) and set the IP from the x-forwarded-for header instead (and maybe keep the socket's address as a fallback)

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied here: 6842701

@s1gr1d

Copy link
Copy Markdown
MemberAuthor

bugbot run

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 6842701. Configure here.

msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@s1gr1d
s1gr1d merged commit b9c864b into developAug 24, 2026
272 of 273 checks passed
@s1gr1d
s1gr1d deleted the sig/network-attributes branch August 24, 2026 11:09
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 24, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 pushed a commit that referenced this pull request Aug 25, 2026
Related to Linear:
https://linear.app/getsentry/issue/SDK-1348/align-network-span-attributes
| v10 attribute | v11 attribute |
| --------------- | ----------------------- |
| `net.host.name` | `server.address` |
| `net.host.ip` | `network.local.address` |
| `net.host.port` | `network.local.port` |
| `net.peer.name` | `server.address` |
| `net.peer.ip` | `network.peer.address` |
| `net.peer.port` | `network.peer.port` |
| `net.transport` | `network.transport` |
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. Scoped to the `http.*` attributes on HTTP spans; the `net.*`
attributes are migrated separately in #23301.
Straight renames: `http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.scheme` -> `url.scheme`, `http.user_agent` ->
`user_agent.original`, `http.response_content_length` ->
`http.response.body.size`, `http.response_transfer_size` -> `http.response.size`,
and `url.same_origin` -> `http.request.same_origin`.
`http.request_content_length`, `http.request_content_length_uncompressed`,
`http.response_content_length_uncompressed` and `http.status_text` are left
alone — they are not in `@sentry/conventions` at all, so they have no
replacement to move to.
Three cases needed more than a rename:
- `http.target` carried pathname *and* query, while `url.path` is the pathname
only. The core server span set neither `url.query` nor `url.fragment`, so
dropping `http.target` would have lost the query — it now sets both, which
the node server span already did.
- Consumers that matched on `http.target` were repointed at `url.path`: the
react-router low-quality-transaction filter and the TanStack Start tunnel-route
filter, both `ignoreSpans` rules against our own spans that would otherwise
have silently stopped matching. The Next.js readers keep `http.target` as a
fallback behind a `url.path` primary, since they also see spans from a user's
own OpenTelemetry instrumentation. All other read-side fallbacks are untouched
for the same reason.
- `http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
`no-unfiltered-url-attributes` no longer guards `http.target`: nothing sets it,
and its replacement `url.path` is a bare pathname with no query to filter.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 25, 2026
Part of the v11 migration away from attributes `@sentry/conventions` marks
deprecated. This PR covers the renames on HTTP spans, all of them 1:1 with no
behavior change. `http.target` and the Node body size behavior change follow in
stacked PRs; the `net.*` attributes are migrated separately in #23301.
`http.method` -> `http.request.method`, `http.status_code` ->
`http.response.status_code`, `http.status_text` -> `http.response.status_text`,
`http.scheme` -> `url.scheme`, `http.user_agent` -> `user_agent.original`,
`http.request_content_length` -> `http.request.body.size`,
`http.request_content_length_uncompressed` -> `http.request.body.decoded_size`,
`http.response_content_length` -> `http.response.body.size`,
`http.response_content_length_uncompressed` and
`http.decoded_response_content_length` -> `http.response.body.decoded_size`,
`http.response_transfer_size` -> `http.response.size`, and `url.same_origin` ->
`http.request.same_origin`.
The last two legacy response body size names meant the same thing — the decoded
response body size. Node HTTP spans used `http.response_content_length_uncompressed`,
browser resource spans used `http.decoded_response_content_length`.
Which of the encoded and decoded attribute an HTTP span sets is unchanged here:
the code still branches on whether a `content-encoding` header is present. That
branching is what the stacked body size PR addresses.
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements — `server.address`,
`network.protocol.version` and `client.address` — are introduced by #23301, so
setting them here too would mean two PRs writing the same keys with different
values.
`SanitizedRequestData`, the shape backing `http` breadcrumb data, now keys the
method as `http.request.method`.
Span attributes in the touched files are now imported from
`@sentry/conventions/attributes` rather than written as string literals. That is
what surfaced `url.same_origin` as deprecated; as a literal it was invisible.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
msonnb added a commit that referenced this pull request Aug 26, 2026
This PR covers the 1:1 renames and removals on HTTP spans. `http.target`
and the Node body size behavior change follow in stacked PRs.
| Old Attribute | New Attribute |
|---|---|
| `http.method` | `http.request.method` |
| `http.status_code` | `http.response.status_code` |
| `http.status_text` | `http.response.status_text` |
| `http.scheme` | `url.scheme` |
| `http.user_agent` | `user_agent.original` |
| `http.request_content_length` | `http.request.body.size` |
| `http.request_content_length_uncompressed` |
`http.request.body.decoded_size` |
| `http.response_content_length` | `http.response.body.size` |
| `http.response_content_length_uncompressed` |
`http.response.body.decoded_size`|
| `http.decoded_response_content_length` |
`http.response.body.decoded_size` |
| `http.response_transfer_size` | `http.response.size` |
| `url.same_origin` | `http.request.same_origin` |
`http.host`, `http.flavor` and `http.client_ip` are dropped without a
replacement being set here. Their replacements (`server.address`,
`network.protocol.version` and `client.address`) are already being set
(introduced in
#23301).
part of #18895
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 27, 2026
Three gaps that the alias symmetry test cannot catch, because it only seeds
a group from attributes that already carry a non-empty `alias` array:
- `net.peer.name` replaces onto `server.address` but was not part of that
alias group. It now joins it, like `http.host`, which is ambiguous in the
same way.
- `net.sock.peer.port` replaces onto `network.peer.port` and neither named
the other. The equivalent host pair already does.
- `net.transport` changes its values from `ip_tcp` and `ip_udp` to `tcp` and
`udp`, so it needs a transformation rather than a plain rename. Adds
`net_transport_to_network_transport`.
`net.host.port` and `net.peer.port` are left untouched: both correctly
replace onto `server.port`, while `network.local.port` and
`network.peer.port` descend from the `net.sock.*` attributes.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport`
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
JPeer264 added a commit to getsentry/sentry-conventions that referenced this pull request Aug 28, 2026
…transport` (#588)
`net.peer.name` replaces onto `server.address` and `net.sock.peer.port`
replaces onto `network.peer.port`, but neither pair named the other side.
Both alias groups are complete now.
`net.transport` changes its values on the replacement, from `ip_tcp` and
`ip_udp` to `tcp` and `udp`, so the old value cannot be copied over.
It moves from `_status: "backfill"` to `_status: null` and keeps
`network.transport` as the replacement.
Replaced by getsentry/sentry-javascript#23301
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@s1gr1d@JPeer264@msonnb