Evidence ledger 24 sources Checked 09 Oct 2026

Evidence ledger

One row per claim in Changing what the services stand on: ten years of ByteDance, read from its own repositories: who published it, what grade it carries, when it was written, when the link was last checked, and the quote or figure it rests on. Nothing in the guide is cited from memory, so anything not in this table is not in the guide.

Field guide: Changing what the services stand on: ten years of ByteDance, read from its own repositories Research date: 2026-10-09. Every URL below was fetched in this session on 2026-10-09.

Hunt constraint, stated up front

This session's egress policy permitted github.com, raw.githubusercontent.com, proxy.golang.org, index.crates.io, pypi.org and apache.org, and refused every engineering-blog, conference-video, preprint and digital-library host tried (cloudwego.io, bytedance.github.io, infoq.com, usenix.org, arxiv.org, medium.com, web.archive.org, among others: CONNECT returned 403 from the egress proxy). The guide is therefore built from the repository record and the package registries, with no engineering-blog, talk or paper tier at all. That absence is recorded in the guide rather than papered over, and the two tiers it costs (talk, paper) are empty on purpose.

Ledger

# Org Title Tier Published Checked URL Claim taken from it Supporting quote or figure
1 ByteDance / CloudWeGo cloudwego/netpoll README source n/d (repo, main) 2026-10-09 https://github.com/cloudwego/netpoll Netpoll exists to replace Go's net for RPC, for stated reasons of goroutine cost and missing liveness check "Go's standard library net is designed for blocking I/O APIs, so that the RPC framework can only follow the One Conn One Goroutine design. It will waste a lot of cost for context switching... Besides, net.Conn has no API to check Alive, so it is difficult to make an efficient connection pool"
2 ByteDance / CloudWeGo cloudwego/netpoll README, Features source n/d (repo, main) 2026-10-09 https://github.com/cloudwego/netpoll The replacement narrows the platform surface "Unsupported - Windows (operating system)"
3 ByteDance / CloudWeGo netpoll docs/reference/explain.md, "DATA RACE EXPLAIN" source n/d (repo, main) 2026-10-09 https://raw.githubusercontent.com/cloudwego/netpoll/main/docs/reference/explain.md The substitution ships code that hides itself from the race detector "Netpoll declare different files by //+build !race and //+build race to avoid DATA RACE detection in some code. The reason is that the epoll uses unsafe.Pointer to access the struct pointer, in order to improve performance. This operation is beyond the detection range of the race detector"
4 ByteDance / CloudWeGo netpoll docs/reference/design_en.md source n/d (repo, main) 2026-10-09 https://raw.githubusercontent.com/cloudwego/netpoll/main/docs/reference/design_en.md The design document the README links to is empty File content is the single line "# TODO"
5 ByteDance / CloudWeGo cloudwego/kitex README source n/d (repo, develop) 2026-10-09 https://github.com/cloudwego/kitex Kitex is built on the replacement, not on the standard library "Kitex integrates Netpoll, a high-performance network library, which offers significant performance advantage over go net."
6 ByteDance / CloudWeGo kitex pkg/remote/trans/gonet/trans_server.go source 2022 (copyright) 2026-10-09 https://raw.githubusercontent.com/cloudwego/kitex/develop/pkg/remote/trans/gonet/trans_server.go Kitex keeps a standard-library transport beside the replacement "// Package gonet contains server and client implementation for go net."
7 ByteDance / CloudWeGo kitex PR #1767, "optimize: new implementation of gonet transport" source opened 2025-04-23, closed 2025-06-09, unmerged 2026-10-09 https://github.com/cloudwego/kitex/pull/1767 An attempt to rebuild the standard-library transport free of the replacement was closed unmerged with no stated reason Review comment: "利用 bufiox 来替换 netpoll" (use bufiox to replace netpoll); PR closed 2025-06-09, not merged; Codecov patch coverage ~59.03%
8 ByteDance / CloudWeGo kitex PR #585, "feat: proxyless support via xDS api" source opened 2022-08-05, closed 2022-08-23, unmerged 2026-10-09 https://github.com/cloudwego/kitex/pull/585 The service-mesh-compatible control-plane integration was built, milestoned, then dropped "add xds module to manage xDS resources retrieved from control plane. Support traffic route, timeout config and service discovery based on xDS."; added to v0.4.0 milestone 2022-08-19, removed 2022-08-22, closed without comment
9 ByteDance / CloudWeGo cloudwego/hertz README source n/d (repo, main) 2026-10-09 https://github.com/cloudwego/hertz The HTTP framework is a fork of a third-party server, not of the standard library "It was originally a fork of fasthttp and inspired by gin, echo and combined with the internal requirements in ByteDance."
10 GitHub Advisory DB GHSA-c9qr-f6c8-rgxf, "Hertz contains path traversal via normalizePath function" (CVE-2022-40082) postmortem 2022-09-29 2026-10-09 https://github.com/advisories/GHSA-c9qr-f6c8-rgxf The forked HTTP server carried a path-traversal defect in the request-normalisation path "Versions of Hertz prior to 0.3.1 contain a path traversal vulnerability via the normalizePath function. This issue has been patched in 0.3.1."; High, CVSS 7.5, CWE-22, package github.com/cloudwego/hertz (Go)
11 ByteDance bytedance/sonic README, Requirement source n/d (repo, main) 2026-10-09 https://github.com/bytedance/sonic The replacement carries explicit toolchain bounds and tells users to disable a linker check "Go: 1.18~1.27 - Notice: Go1.24.0 is not supported due to the issue; please use a higher Go version or pass the build flag -ldflags=\"-checklinkname=0\""
12 ByteDance bytedance/sonic compat.go build tag source 2021 (copyright) 2026-10-09 https://raw.githubusercontent.com/bytedance/sonic/main/compat.go The fast path switches itself off above a hard-coded Go version and silently delegates to the standard library "//go:build (!amd64 && !arm64)
13 ByteDance bytedance/sonic issue #660, "Incompatible with Go 1.23, which doesn't allow //go:linkname to internal symbols, including to runtime package" postmortem opened 2024-06-25, closed 2024-07-16 2026-10-09 https://github.com/bytedance/sonic/issues/660 Go 1.23's linkname restriction broke the library, including a linkname into the package it replaces Reporter stefanb: linker error "invalid reference to encoding/json.safeSet" on Go 1.23 rc1; "Go 1.23 no longer allows //go:linkname * runtime.* link instructioins"; contributor AsterDY: "We are handling this. Please wait for a while"
14 ByteDance bytedance/sonic issue #738, "go 1.24 build failed: link: github.com/bytedance/sonic/loader: invalid reference to runtime.lastmoduledatap" postmortem opened 2025-02-12, closed 2025-03-08 2026-10-09 https://github.com/bytedance/sonic/issues/738 A removed runtime symbol broke the build, and the recommended workaround was to disable the linker check "It seems Go teams removes the //go:linkname on runtime.lastmoduledatap"; maintainer liuq19: "maybe you can try the branch feat/go1.24 and add compile flags -ldflags=-checklinkname=0"
15 ByteDance bytedance/sonic issue #895, "Build with Go 1.26 fails: internal/rt/stubs.go: undefined: GoMapIterator" postmortem opened 2025-12-28, closed 2026-01-23 2026-10-09 https://github.com/bytedance/sonic/issues/895 The same class of breakage recurred on a later Go release Issue title as published
16 ByteDance bytedance/sonic issue #363, "sonic 1.18 crash in test with -race" postmortem opened 2023-02-15, closed 2023-02-20 2026-10-09 https://github.com/bytedance/sonic/issues/363 The replacement crashed the test suite under the race detector, inside the JIT "checkptr: converted pointer straddles multiple allocations" in internal/rt.(*StackMapBuilder).Build during decoder.init(); second reporter modest0: tests "run without errors when the -race flag is not used"
17 ByteDance bytedance/sonic issue #177, "Support go 1.18beta1" source 2022-01-28, closed as wontfix 2026-10-09 https://github.com/bytedance/sonic/issues/177 New Go versions are a support event for this library, and some were refused Issue title as published; state "Closed (wontfix)"
18 Go project golang/go issue #67401, "cmd/link: lock down future uses of linkname" adr opened 2024-05-15, closed 2025-02-26, milestone Go1.23 2026-10-09 https://github.com/golang/go/issues/67401 Upstream deliberately closed the seam that this class of substitution reaches through, and left a flag as the escape hatch "all //go:linkname usage must be in the Handshake form: both sides must agree to use linkname for a given symbol"; "Introduce a new -checklinkname=1 flag to cmd/link that requires the Handshake form for symbols in the standard library"
19 Go project golang/go issue #71672, "runtime: add linkname runtime.lastmoduledatap back for cloudwego/sonic" postmortem opened 2025-02-12, closed 2025-02-18 2026-10-09 https://github.com/golang/go/issues/71672 Upstream restored a removed internal symbol and backported it because the substitution had become load-bearing for the ecosystem "Sonic has used this link for two years and just removed the link codes to sonic/loader since go1.23."; ianlancetaylor: "Please backport to the 1.24 branch."; AsterDY: "sonic is dependent over 1w+ repos"; fix commit "runtime: add some linknames back for github.com/bytedance/sonic"
20 Go project go1.25.0 source, src/runtime/malloc.go source 2025 (release tag go1.25.0) 2026-10-09 https://github.com/golang/go/blob/go1.25.0/src/runtime/malloc.go The upstream runtime names this company's packages in its source as a compatibility constraint on the allocator "mallocgc should be an internal detail, but widely used packages access it using linkname. Notable members of the hall of shame include: // - github.com/bytedance/gopkg // - github.com/bytedance/sonic // - github.com/cloudwego/frugal"
21 Go project go1.25.0 source, src/runtime/stubs.go source 2025 (release tag go1.25.0) 2026-10-09 https://github.com/golang/go/blob/go1.25.0/src/runtime/stubs.go The same constraint covers memory-movement primitives and reaches a second CloudWeGo package "memmove should be an internal detail, but widely used packages access it using linkname. Notable members of the hall of shame include: // - github.com/bytedance/sonic // - github.com/cloudwego/dynamicgo"; noescape lists "github.com/bytedance/gopkg"
22 Go project go1.25.0 source, src/runtime/slice.go source 2025 (release tag go1.25.0) 2026-10-09 https://github.com/golang/go/blob/go1.25.0/src/runtime/slice.go Slice growth is pinned by the same dependency "growslice should be an internal detail... Notable members of the hall of shame include: // - github.com/bytedance/sonic // - github.com/chenzhuoyu/iasm // - github.com/cloudwego/dynamicgo"; reflect_growslice lists "github.com/cloudwego/dynamicgo"
23 ByteDance / CloudWeGo cloudwego/frugal releases source v0.1.0 2022-05-16 to v0.3.1 2025-11-07 2026-10-09 https://github.com/cloudwego/frugal/releases The most aggressive substitution was capped, made optional, disabled by default, then deleted v0.2.0: "feat(jit): go1.23 for the last supported version"; v0.2.2: "feat: add NoJIT option"; v0.2.4: "refactor: disable JIT by default"; v0.3.0: "refactor: rm JIT code & clear CI"
24 Go module proxy github.com/cloudwego/frugal version timestamps source queried 2026-10-09 2026-10-09 https://proxy.golang.org/github.com/cloudwego/frugal/@v/v0.3.0.info Dates for the JIT retreat: shipped 2022-05-16, capped 2024-08-08, optional 2024-11-28, off by default 2025-01-09, deleted 2025-09-09 v0.1.0 Time 2022-05-16; v0.2.0 2024-08-08; v0.2.2 2024-11-28; v0.2.4 2025-01-09; v0.3.0 2025-09-09
25 ByteDance / CloudWeGo cloudwego/frugal README benchmark casestudy n/d (repo, main; go1.23.6) 2026-10-09 https://github.com/cloudwego/frugal What the substitution bought, measured by its own author "Frugal is about 2.5x to 3.7x faster than Apache Thrift (TBinaryProtocol)"; Marshal medium 3669 ns/op vs 9343 ns/op on Intel Xeon Gold 5118
26 ByteDance / CloudWeGo cloudwego/prutal README source n/d (repo, main; first release 2025-03-19) 2026-10-09 https://github.com/cloudwego/prutal The next-generation replacement is pure Go, is explicit about what it does not implement, and says it is not production-ready "Prutal is a pure Go alternative to protocol buffers"; "Since Prutal is NOT yet ready for production use..."; "❌ Opaque API ... field presence lives in a bitmap the runtime does not maintain"; "❌ Clone / Merge / Equal"
27 ByteDance / CloudWeGo cloudwego/base64x source first release 2024-04-01 2026-10-09 https://github.com/cloudwego/base64x The substitution pattern is applied to a third standard-library package Repository description: "High performance drop-in replacement of the encoding/base64 library."
28 ByteDance / CloudWeGo cloudwego/localsession source first release 2023-07-24 2026-10-09 https://github.com/cloudwego/localsession The company needed goroutine-scoped context, which the language does not provide Repository description: "transparently transmit context within or between goroutines"
29 ByteDance / CloudWeGo cloudwego/runtimex source first release 2024-05-13 2026-10-09 https://github.com/cloudwego/runtimex Reaching into runtime internals became a packaged capability of its own Repository description: "Runtimex package help to expose Go Runtime internals representation safely."
30 ByteDance / CloudWeGo cloudwego/shmipc-go README benchmark casestudy first release 2023-04-20; last 2024-08-26 2026-10-09 https://github.com/cloudwego/shmipc-go Bypassing the kernel for co-located processes wins on large packets and loses on small ones "the performance of small packet scenarios is comparable and the performance of large packet scenarios is significantly improved"; 64B: shmipc 7740 ns/op vs uds 5523 ns/op; 4KB: 660.78 MB/s vs 343.44 MB/s; 4MB: 2686.46 MB/s
31 ByteDance bytedance/monoio README source n/d (repo, master) 2026-10-09 https://github.com/bytedance/monoio The Rust attempt states its own compatibility cost in the README "we've enabled some unstable Rust features, and we've designed a whole new IO abstraction, which unfortunately may cause some compatibility problems"; "unlike on work-stealing runtimes such as Tokio"
32 ByteDance bytedance/monoio docs/en/benchmark.md casestudy 2021-12-01 2026-10-09 https://raw.githubusercontent.com/bytedance/monoio/master/docs/en/benchmark.md Measured on ByteDance's own production network, and honest about where the model loses "Our test is carried out on the ByteDance production network"; "In the case of a single core and very few connections, Monoio's latency will be higher than Tokio"; "under 4 cores, the peak performance is about twice that of Tokio; under 16 cores, it is close to 3 times"
33 ByteDance / KubeWharf kubewharf/kubebrain README adr n/d (repo, main) 2026-10-09 https://github.com/kubewharf/kubebrain etcd was replaced because of a stated node ceiling, and the replacement is an interface substitution rather than a new store "its official stable operation scale is limited to 5K nodes. This is sufficient for most application scenarios, but still insufficient for applications with millions of machine nodes"; "KubeBrain is a component that implements the storage server interface required by the API Server... it does not actually store the data"
34 ByteDance / KubeWharf kubewharf/kubebrain README, TODO source n/d (repo, main) 2026-10-09 https://github.com/kubewharf/kubebrain The published replacement for the cluster's consensus store has consistency and Jepsen testing as open TODO items Unchecked TODO entries: "[ ] Guarantee consistence in critical cases"; "[ ] Jepsen Test"
35 ByteDance / KubeWharf kubewharf/kubebrain docs/benchmark.md casestudy n/d (repo, main) 2026-10-09 https://raw.githubusercontent.com/kubewharf/kubebrain/main/docs/benchmark.md The replacement beats etcd on reads and writes and loses on deletes, by its author's measurement "KubeBrain on TiKV can outperform etcd in read and write performance, while deletion performance needs to be further optimized"; 300 etcd clients, 70-byte keys, 512-byte values, 3-node clusters
36 ByteDance / KubeWharf kubewharf/godel-scheduler README source n/d (repo, main) 2026-10-09 https://github.com/kubewharf/godel-scheduler The scheduler is a substitute whose interface is deliberately not identical, and it is bounded to a narrow Kubernetes range "serving as a potential substitute for the Kubernetes scheduler... Although the framework interface deviates slightly from that of the Kubernetes scheduler"; "Gödel supports Kubernetes versions from 1.21.4 up to 1.24.6. Using lower or higher Kubernetes versions may cause compatibility issues."
37 ByteDance / KubeWharf kubewharf/kubeadmiral README source n/d (repo, main) 2026-10-09 https://github.com/kubewharf/kubeadmiral The federation layer is a continuation of an upstream project, keeping the native API, bounded to Kubernetes 1.16-1.24 "developed from Kubernetes Federation v2"; "providing compatibility with the Kubernetes native API"; "KubeAdmiral supports Kubernetes versions from 1.16 up to 1.24."
38 Go module proxy sigs.k8s.io/kubefed version list source queried 2026-10-09 2026-10-09 https://proxy.golang.org/sigs.k8s.io/kubefed/@v/v0.10.0.info The upstream that KubeAdmiral continues stopped releasing in 2022 v0.10.0 Time "2022-08-10T09:56:30Z"; no later version in the proxy's list
39 ByteDance / KubeWharf kubewharf/katalyst-core README source first release 2023-02-27; latest v0.5.52 2026-08-31 2026-10-09 https://github.com/kubewharf/katalyst-core The utilisation and cost work is only installable on the company's patched Kubernetes "Katalyst runs on a KubeWharf enhanced kubernetes cluster"; "Since KubeWharf enhanced kubernetes is developed based on specific versions of upstream Kubernetes and maintains API compatibility with corresponding Kubernetes versions, if you wish to run other components (e.g. operators), please note its compatibility"
40 ByteDance / KubeWharf kubewharf/enhanced-k8s README source n/d (repo, main; last updated 2024-10-25) 2026-10-09 https://github.com/kubewharf/enhanced-k8s The published distribution is pinned to one 2022 Kubernetes patch release Release table: "1.24
41 ByteDance / KubeWharf kubewharf/kubernetes branch list source branches last updated 2024-10-28 to 2025-09-12 2026-10-09 https://github.com/kubewharf/kubernetes/branches/all The fork is alive on newer bases, but on a differently named line from the published distribution Branches: "kubewharf-1.24.6
42 ByteDance / KubeWharf kubewharf/kubegateway README source n/d (repo, main) 2026-10-09 https://github.com/kubewharf/kubegateway A dedicated L7 proxy was built in front of the API server, with a stated connection-convergence result "a layer 7 load balancing proxy specifically designed and customized for HTTP2 flow for kube-apiserver"; "more than 1,000 nodes"; "It converges the number of TCP connections on a single kube-apiserver instance by at least an order of magnitude"
43 ByteDance / KubeWharf kubewharf/kubegateway docs/en/design.md adr n/d (repo, main) 2026-10-09 https://raw.githubusercontent.com/kubewharf/kubegateway/main/docs/en/design.md The proxy's control plane is itself an API-server clone, so existing clients need no new SDK "The control plane of KubeGateway is equivalent to a complete kube-apiserver"; "you can use client-go to make configuration changes directly without additional SDK"
44 ByteDance / KubeWharf kubewharf/malachite source archived; last updated 2023-05-15 2026-10-09 https://github.com/kubewharf/malachite The only publicly archived component of the platform is the one written in C Repository listed as "Public archive", language C, no description
45 Kubernetes kubernetes/kubernetes release v1.24.17 source 2023-08-23 2026-10-09 https://github.com/kubernetes/kubernetes/releases/tag/v1.24.17 The last patch of the release line the published distribution is pinned to shipped in 2023 Tag v1.24.17; module-proxy Time 2023-08-23
46 Kubernetes kubernetes/kubernetes latest release source 2026-09-23 2026-10-09 https://github.com/kubernetes/kubernetes/releases/latest Upstream is thirteen minor versions ahead of the pinned base Tag v1.37.1, marked "Latest"; module-proxy Time 2026-09-23; pinned base v1.24.6 Time 2022-09-21
47 Go module proxy first-release timestamps for the CloudWeGo modules source queried 2026-10-09 2026-10-09 https://proxy.golang.org/github.com/cloudwego/netpoll/@v/v0.0.1.info The public timeline: netpoll 2021-06-23, kitex 2021-07-09, sonic v1.0.0 2021-12-31, hertz 2022-05-31, frugal 2022-05-16, dynamicgo 2023-05-08, base64x 2024-04-01, prutal 2025-03-19, eino 2024-12-11 netpoll v0.0.1 Time "2021-06-23"; kitex v0.0.1 "2021-07-09"; hertz v0.0.1 "2022-05-31"; sonic v1.0.0 "2021-12-31"; eino v0.3.0 "2024-12-11"
48 ByteDance / CloudWeGo cloudwego/volo README source n/d (repo, main) 2026-10-09 https://github.com/cloudwego/volo The second attempt at the same stack was made in a different language, and the company declines to compare it with the first "it is very unfair to compare the performance with the Go framework, so we will not focus on comparing the performance of Volo and Kitex"
49 ByteDance / CloudWeGo cloudwego/eino README source first release 2024-12-11 2026-10-09 https://github.com/cloudwego/eino The 2025-26 addition is a product-layer framework, not another layer substitution "Eino is an LLM application development framework in Golang. It draws from LangChain, Google ADK, and other open-source frameworks"
50 Go package index pkg.go.dev entry for github.com/bytedance/sonic source n/d (generated) 2026-10-09 https://pkg.go.dev/github.com/bytedance/sonic The fallback is documented, and byte compatibility with the standard library is a non-default config "On non-sonic-supporting environment, the implementation will fall back to encoding/json."; "Sonic DOES NOT ensure to support all environments, due to the difficulty of developing high-performance codes."; "ConfigDefault is the default config of APIs, aiming at efficiency and safety"; "ConfigStd is the standard config of APIs, aiming at being compatible with encoding/json"
51 ByteDance / CloudWeGo cloudwego org profile README vendor n/d 2026-10-09 https://github.com/cloudwego/.github The company's own framing of the set "CloudWeGo is an open-source middleware set launched by ByteDance that can be used to quickly build enterprise-class cloud native and AI native architectures."

Tier mix

Tier Count
source 33
postmortem 6
casestudy 5
adr 3
vendor 1
blog 0
talk 0
paper 0

Distinct hosts: github.com, raw.githubusercontent.com, proxy.golang.org, pkg.go.dev. The page's own link check reports four distinct hosts, which trips the breadth warning in verify.mjs. The warning is accepted: with every other host refused at the proxy, widening the hunt was not available, and inventing citations to satisfy a counter would be worse. Organisations represented: ByteDance (CloudWeGo), ByteDance (KubeWharf), the Go project, the Kubernetes project, Kubernetes SIG Multicluster (KubeFed, as the forked upstream), GitHub's advisory database.

Where the record runs out

  • No company-published incident reviews. ByteDance publishes no public postmortems for these systems. Every incident in the guide is an upstream or downstream breakage thread, which means the record covers the substitutions' effect on other people's builds and says nothing about what they did inside ByteDance's own production.
  • No talks and no papers. Both tiers are empty because every host that carries them was refused by this session's egress policy, not because the material does not exist.
  • No cost figures of any kind. Nothing in the repository record prices any of this work, so the guide has no unit economics and does not pretend to.
  • Scale is asserted, not measured. "Widely used inside ByteDance" appears in several READMEs with no service count, QPS or fleet size attached, so the guide uses only the numbers the repositories actually state.