Release notes — 1.3.0
Released 2026-08-04 with DNS Conduit 1.3.0.
Performance documentation
- Performance section: Published same-host studies for runtime model, worker sizing, observability tax, and shutdown drain. See Performance.
- Performance test harness: An in-tree harness replays the published suite kinds against a Conduit binary. We recommend running it in your own environment to validate performance on your hardware before sizing — published figures are same-host comparisons, not capacity SLOs. See Reproduce against a binary.
- Directional findings: Short takeaways (for example sync vs
split_io, metrics scrape cost, drain policy under slow upstream) on the Performance overview.
Dataplane throughput and correctness
- Concurrent transaction slots: The shared transaction slot pool no longer holds one process-wide lock across policy work — distinct slots can progress concurrently (important under multi-worker
syncandsplit_io). - Sharded
split_iohandoff: Policy work queues (and reply routes) are partitioned by slot so ingress producers are not serialized on a single queue lock. See Runtime and concurrency and Dataplane runtime tuning. - Prompt
split_iopolicy wake: Whenpolicy_workersis smaller than the internal queue shard count, new and resumed work is handed to idle workers immediately instead of waiting up to about 100 ms for a steal poll — overlapping queries under thinsplit_iotopologies stay near one upstream RTT. See Runtime and concurrency and Dataplane runtime tuning. - Unique upstream DNS IDs: Outstanding forwards to the same backend use allocated demux IDs (client IDs restored on the reply), so colliding client query IDs no longer orphan in-flight waits under multi-client load.
- Event sink drop-oldest: When an event queue is full under
drop_oldest, Conduit drops one oldest event instead of draining the whole queue on the producer path.
Packaging and lab tooling
conduit-otlp-metrics-tracer: Ships in tarballs and packages as a local OTLP HTTP metrics receiver for smoke labs (not part of the production systemd service). See Install and run and OTLP metrics push smoke.- Container images: Release image builds refresh the base layer (
docker build --pull) and upgrade Debian packages at image build time so published images pick up current security fixes from the archive.
All changes in this release (automated pull request list).