Skip to content

expfmt: reject invalid UTF-8 and a trailing CR in OpenMetrics 2.0 metadata - #998

Merged
bwplotka merged 1 commit into
prometheus:mainfrom
Rohilalala:fix/om2-reject-invalid-text
Sep 27, 2026
Merged

bwplotka merged 1 commit into
prometheus:mainfrom
Rohilalala:fix/om2-reject-invalid-text

Conversation

@Rohilalala

Copy link
Copy Markdown
Contributor

MetricFamilyToOpenMetrics20 wrote a metric name, HELP or UNIT that is not valid UTF-8, and a HELP that ends in a carriage return. The spec requires UTF-8, and "Line endings MUST be signalled with line feed (\n) and MUST NOT contain carriage returns (\r)". The Prometheus OpenMetrics 2.0 parser (model/textparse/openmetrics2parse.go) rejects the whole exposition in both cases:

# HELP foo abc\r          ->  unexpected carriage return in HELP: "abc\r"
# HELP foo \x98           ->  help text "\x98" is not a valid utf8 string

Both now return an error, as raw newlines in the name and unit already do. A carriage return inside HELP is still written, since the spec and the parser allow it.

Found by encoding families with MetricFamilyToOpenMetrics20 and parsing the output with the Prometheus OpenMetrics 2.0 parser.

Not changed: label names and values are not checked for UTF-8. Checking them on every series made encoding about 17% slower in a benchmark, and client_golang already rejects invalid UTF-8 label values. The OpenMetrics 1.0 and text encoders are unchanged.

…adata

MetricFamilyToOpenMetrics20 wrote a metric name, HELP or UNIT that is
not valid UTF-8, and a HELP ending in a carriage return, which makes the
line end in "\r\n". OpenMetrics 2.0 requires UTF-8 and forbids \r in
line endings, and the Prometheus OpenMetrics 2.0 parser rejects the whole
exposition in both cases. Return an error instead, as for raw newlines in
the name and unit.

Signed-off-by: Aditya <205600203+Rohilalala@users.noreply.github.com>

@bwplotka bwplotka left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@bwplotka
bwplotka merged commit 8d1b388 into prometheus:main Sep 27, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants