Download Latest Version 3.1.1 release source code.zip (19.7 MB) Google Add to Preferred Sources
Home / v3.1.1
Name Modified Size InfoDownloads / Week
Parent folder
3.1.1 release source code.tar.gz 2026-10-02 10.2 MB
3.1.1 release source code.zip 2026-10-02 19.7 MB
README.md 2026-10-02 12.8 kB
pinpoint-agent-3.1.1.tar.gz 2026-10-02 34.1 MB
pinpoint-batch-3.1.1-exec.jar 2026-10-02 250.2 MB
pinpoint-collector-3.1.1-exec.jar 2026-10-02 187.4 MB
pinpoint-collector-starter-3.1.1-exec.jar 2026-10-02 249.3 MB
pinpoint-web-3.1.1-exec.jar 2026-10-02 246.4 MB
pinpoint-web-starter-3.1.1-exec.jar 2026-10-02 246.5 MB
Totals: 9 Items   1.2 GB 0

Pinpoint 3.1.1 is a maintenance release of the 3.1.x line. It focuses on agent stability and overhead on reactive and coroutine workloads (Reactor / WebFlux / reactor-netty / Kotlin coroutines), Spring Framework 7 compatibility, and security hardening of the Web and Batch modules. There are no schema changes; collector and web can be upgraded in place from 3.1.0.

Highlights

Agent — Reactor megamorphic-dispatch remediation (JDK 21/25)

Backport of the master track that remediates the JIT megamorphic invokeinterface dispatch observed on reactive applications running on recent JDKs (C2 profile pollution across the generic reactor CoreSubscriber instrumentation).

  • The reactor AsyncContext carrier is unified into a single injected field, so the hot interceptors no longer go through polymorphic accessor lookups.
  • Each interceptor class now gets a generated monomorphic exception-guard wrapper instead of sharing one reflective guard. The code generation is enabled by default: properties # pinpoint.config (local / release profiles) profiler.interceptor.exception.guard.codegen=true # set false to fall back to the 3.1.0 guard
  • The generic reactor CoreSubscriber instrumentation can be switched off for a lightweight mode (profiler.reactor.subscriber.instrument=false, default true). Publisher-seam wrapping and scheduler-task tracing stay behind config gates that are off by default (profiler.reactor.trace.scheduler.task, profiler.reactor.trace.scheduler.task.periodic).
  • DefaultAsyncTraceContext / DefaultRecorderFactory no longer call the Guice Provider.get() chain on every trace request; the singleton factories are injected or memoized (#14210).

Agent — "Corrupted call stack" storms fixed and throttled

Three layers address the Corrupted call stack found ... call stack is empty log floods (and the CPU spikes that came with them) reported on reactor-netty / WebFlux services:

  • DefaultCallStack.peek() returns the disabled instance while overflowed frames are outstanding, instead of null, so a transaction that exceeds profiler.callstack.max.sequence no longer logs a stack dump per span event (#14310).
  • OnErrorSubscriberInterceptor (onErrorResume / onErrorReturn / onErrorMap / onErrorComplete) carries its TraceBlock from before() to after() instead of looking the AsyncContext up twice, which closed a frame nobody opened on every failing WebClient response (#14319).
  • The corrupted-call-stack WARN and stack dump are throttled to one per 3 s per trace type; suppressed dumps are counted and reported on the next emitted one, and skip the exception construction entirely.

Agent — Kotlin coroutines

ResumeWithInterceptor keeps the span event opened in before() and closes exactly that one in after(), so a nested Reactor callback swapping the current trace during BaseContinuationImpl.resumeWith(...) no longer leaves unbalanced blocks (previously surfacing as corrupted call stacks on the parent ChildTrace).

Agent — Spring Framework 7 compatibility

  • WebFlux and RestTemplate header adaptors no longer throw NoSuchMethodError on Spring Framework 7, where HttpHeaders stopped implementing MultiValueMap (#14278).
  • The RestTemplate plugin matches the new RestTemplate(Iterable<HttpMessageConverter<?>>) constructor, so RestTemplates built by Spring Boot 4 / Framework 7 are traced again.

Agent — Plugin fixes

  • Redisson: reactive command tracing works on Redisson 3.17+ and 3.19+ (ReactiveProxyBuilder callback signature changes); it had been silently inactive on modern versions.
  • reactor-netty / netty HTTP client: HttpClientRequestWrapper.toRemoteHost() and HttpClientHandlerRequestWithBodyInterceptor no longer cast a non-inet remote address (e.g. Unix domain sockets) to InetSocketAddress, which threw ClassCastException inside the interceptor.
  • Duplicate accessor member injection is skipped in ASMClass (#13962).
  • StringUtils.abbreviate no longer splits UTF-16 surrogate pairs (#14021).
  • Empty PAnnotationValue is returned for NullAnnotation instead of an NPE (#14154).
  • ExceptionChainSampler no longer fails on a non-positive throughput setting.
  • Removed the unused interceptor registry setting and bootstrap-interceptor jar references (#14008).

Web / Batch — Security hardening

  • Webhook SSRF validation (#13857): webhook URLs are resolved and validated before sending; URLs that resolve to loopback, link-local, multicast, or private ranges (10/8, 172.16/12, 192.168/16, 100.64/10, ...) are rejected. The webhook payload no longer includes the user group. See Upgrade notes.
  • Basic login (#13858, [#14103]): the JWT cookie is HttpOnly with configurable Secure / SameSite, the authentication recursion is fixed, and the JWT secret key is now required when basic login is enabled. See Upgrade notes.
  • NUL bytes are rejected in null-terminated buffer values (collector-side decoding).
  • gRPC mappers no longer cache protobuf builders in interface fields (shared across mapper instances and threads).

Upgrade notes

Agent

  • Default pinpoint.modules.uid.version is now v3 (254-character ApplicationName support, [#13715]). This matches the 3.1.0 collector/web. If the agent reports to a collector older than 3.1.0, set it back explicitly: properties pinpoint.modules.uid.version=v1
  • profiler.interceptor.exception.guard.codegen=true is the new default. Set it to false to restore the 3.1.0 behavior (a JVM restart is required).
  • profiler.interceptorregistry.size has been removed from pinpoint-root.config (no longer used).

Web

  • If pinpoint.modules.web.login=basicLogin, the web fails to start unless the JWT secret is configured: properties web.security.auth.jwt.secretkey=<generate-a-random-secret> # optional cookie attributes (defaults shown) #web.security.auth.jwt.cookie.http-only=true #web.security.auth.jwt.cookie.secure=false #web.security.auth.jwt.cookie.same-site=Lax
  • Webhooks targeting private network addresses are rejected in this version. If your alarm webhooks resolve into 10/8, 172.16/12 or 192.168/16, keep them on 3.1.0 or route them through a publicly resolvable host; a configurable host allowlist is available on master and planned for a later release.

Build

  • Minimum required Maven version is 3.7 (the bundled mvnw is unaffected).

Compatibility

Component Minimum Notes
Agent JDK 8+ verified on 8 / 11 / 17 / 21 / 25
Collector / Web / Batch JDK 17+
Collector for agent 3.1.1 3.1.0+ with the default uid.version=v3; see Upgrade notes for older collectors
HBase schema unchanged from 3.1.0

Downloads

Binaries are attached to this release:

What's Changed

Full Changelog: https://github.com/pinpoint-apm/pinpoint/compare/v3.1.0...v3.1.1

Source: README.md, updated 2026-10-02