From 18181f3c31fa5c1fbf2178820cb4de9f66b5bc05 Mon Sep 17 00:00:00 2001 From: Pratik Mankawde <3397372+pratikmankawde@users.noreply.github.com> Date: Wed, 23 Sep 2026 18:08:58 +0100 Subject: [PATCH] docs(telemetry): Drop the remaining account-hashing claims --- OpenTelemetryPlan/03-implementation-strategy.md | 2 +- OpenTelemetryPlan/05-configuration-reference.md | 17 ++++++++--------- docker/telemetry/TESTING.md | 16 ++++------------ include/xrpl/telemetry/Recording.h | 3 +-- 4 files changed, 14 insertions(+), 24 deletions(-) diff --git a/OpenTelemetryPlan/03-implementation-strategy.md b/OpenTelemetryPlan/03-implementation-strategy.md index 5eb5750905..ea82406cad 100644 --- a/OpenTelemetryPlan/03-implementation-strategy.md +++ b/OpenTelemetryPlan/03-implementation-strategy.md @@ -27,7 +27,7 @@ include/xrpl/telemetry/ # libxrpl layer: tracing SDK wrapper ├── DeterministicIdGenerator.h # trace_id from txHash / prevLedgerHash ├── TraceContextPropagator.h # protobuf TraceContext inject/extract (P2P) ├── TraceContextValidation.h # Validation of peer-supplied trace context -├── Redaction.h # redactAccount() — unconditional address hashing +├── Redaction.h # redactAccount() — hashing helper, applied to no span └── GetObjectMetricNames.h # getobject_* metric name constants src/libxrpl/telemetry/ diff --git a/OpenTelemetryPlan/05-configuration-reference.md b/OpenTelemetryPlan/05-configuration-reference.md index efd053f26d..8ff8d68c3a 100644 --- a/OpenTelemetryPlan/05-configuration-reference.md +++ b/OpenTelemetryPlan/05-configuration-reference.md @@ -235,11 +235,11 @@ The authoritative collector config lives in the repo at `docker/telemetry/otel-c `docker/telemetry/otel-collector-config.yaml` is the base config used by the local stack and by CI. It carries **three** pipelines, not one: -| Pipeline | Receivers | Processors | Exporters | -| --------- | ---------------------- | ---------------------------------------------------------------- | ------------------------------------------ | -| `traces` | `otlp` | `resource/tier`, `resource/stripsdk`, `attributes/hash`, `batch` | `debug`, `otlp_grpc/tempo`, `span_metrics` | -| `metrics` | `otlp`, `span_metrics` | `resource/tier`, `resource/stripsdk`, `batch` | `prometheus` | -| `logs` | `file_log` | `resource/logs`, `resource/tier`, `resource/stripsdk`, `batch` | `otlp_http/loki` | +| Pipeline | Receivers | Processors | Exporters | +| --------- | ---------------------- | -------------------------------------------------------------- | ------------------------------------------ | +| `traces` | `otlp` | `resource/tier`, `resource/stripsdk`, `batch` | `debug`, `otlp_grpc/tempo`, `span_metrics` | +| `metrics` | `otlp`, `span_metrics` | `resource/tier`, `resource/stripsdk`, `batch` | `prometheus` | +| `logs` | `file_log` | `resource/logs`, `resource/tier`, `resource/stripsdk`, `batch` | `otlp_http/loki` | Component detail: @@ -253,8 +253,8 @@ Component detail: `xrpl.network.type` only when absent); `resource/stripsdk` (drops the `telemetry.sdk.*` attributes); `resource/logs` (`action: upsert` on `service.name` and `job` — only the former becomes a Loki stream label, see - the known issue in §5.8.5); `attributes/hash` (hashes - `pathfind_source_account` and `pathfind_dest_account`). + the known issue in §5.8.5). No processor hashes or drops span attributes: + account addresses are public identifiers and are stored as emitted. - **Connector.** `span_metrics` with `namespace: "span"` (`otel-collector-config.yaml:114`) — this is why the derived RED metrics are `span_calls_total` / `span_duration_milliseconds_*`. The connector's own @@ -280,8 +280,7 @@ Component detail: Deliberately absent from the base config — do not document them as present: no `memory_limiter`, no `tail_sampling`, no Elastic APM exporter, and no -`tx_account` attribute rule (the hashed keys are the two `pathfind_*_account` -ones). +attribute hashing or redaction rule (account addresses are emitted raw). ### 5.5.2 Production Configuration diff --git a/docker/telemetry/TESTING.md b/docker/telemetry/TESTING.md index 8c4568bb0e..cb9387db17 100644 --- a/docker/telemetry/TESTING.md +++ b/docker/telemetry/TESTING.md @@ -745,7 +745,6 @@ Differences that change what you will see: | Pipelines | 3: `traces`, `metrics`, `logs` | 5: `traces/metrics`, `traces/store`, `metrics/local`, `metrics/cloud`, `logs` | | Trace sampling | none — 100% of spans reach Tempo | `tail_sampling` keeps **0.5%** (one `probabilistic` policy, `decision_wait: 10s`) on `traces/store` | | `debug` exporter | present on `traces` | dropped | -| `attributes/hash` | present on `traces` | **omitted** | | Cloud metric labels | n/a | `transform/cloudlabels` on `metrics/cloud` only | Consequences worth knowing before you debug against the cloud stack: @@ -756,17 +755,10 @@ Consequences worth knowing before you debug against the cloud stack: pipeline, so `span_*` rates stay exact while only ~1 trace in 200 is retrievable by trace ID. A trace you can see in a metric may not exist in Tempo. -- **The same account carries a different token on each config.** No raw account - address leaves the node: the path-finding handlers under - `src/xrpld/rpc/handlers/orderbook/` pass both accounts through - `redactAccount()` first, which is a prefix of the address's SHA-512Half digest - (contract in `include/xrpl/telemetry/Redaction.h`). The base config's - `attributes/hash` processor then hashes that token a second time; no cloud - pipeline has it. The token is deterministic, so one account stays correlatable - across nodes and restarts — but only within one config. A trace stored while - the collector ran the base config must not be joined against a trace stored - under the cloud config, because the same account appears under two different - tokens. +- **Account addresses read the same on both configs.** Neither config hashes + or drops the `pathfind_*_account` or `tx_*` account attributes: an address is + a public ledger identifier and is stored as the node emitted it, so a trace + from the base stack joins a trace from the cloud stack by account. ### Step 4: Verify data reaches Grafana Cloud diff --git a/include/xrpl/telemetry/Recording.h b/include/xrpl/telemetry/Recording.h index 6567728872..1050682e2c 100644 --- a/include/xrpl/telemetry/Recording.h +++ b/include/xrpl/telemetry/Recording.h @@ -55,8 +55,7 @@ * // Edge case -- an expensive value still needs a block guard, * // because arguments are evaluated even when the method is a no-op. * if constexpr (telemetry::kEnabled) - * span.setAttribute( - * pathfind_span::attr::sourceAccount, redactAccount(account)); + * span.setAttribute(tx_span::attr::txHash, to_string(txId)); * @endcode */