mirror of
https://github.com/XRPLF/rippled.git
synced 2026-09-17 04:48:32 +00:00
Compare commits
941 Commits
alphanet
...
pratik/ote
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
75661c3a33 | ||
|
|
5b10ef0d56 | ||
|
|
b14c537df1 | ||
|
|
9545ab4d4e | ||
|
|
6a0642817d | ||
|
|
d008b2f641 | ||
|
|
a910a2dc91 | ||
|
|
e302e4eeed | ||
|
|
1a4a40ebb8 | ||
|
|
7f55dd390c | ||
|
|
49a3302e29 | ||
|
|
c0024c7c57 | ||
|
|
b98a9d3d13 | ||
|
|
4dc706c606 | ||
|
|
282ce3620d | ||
|
|
87457446be | ||
|
|
8b0bd8839d | ||
|
|
148d126c63 | ||
|
|
302a76f73e | ||
|
|
08a1ab8cd3 | ||
|
|
96a3495328 | ||
|
|
6528b02469 | ||
|
|
55ae890efd | ||
|
|
2ec09abf12 | ||
|
|
b0fd72619a | ||
|
|
5190f643fa | ||
|
|
cf719f224d | ||
|
|
bfa9f1b1e0 | ||
|
|
25362d3b6a | ||
|
|
0ed0c01021 | ||
|
|
9c9cb9d091 | ||
|
|
f1795813a2 | ||
|
|
dc2a8f121e | ||
|
|
0fd7ce9f8b | ||
|
|
96c11264b0 | ||
|
|
31ace1a357 | ||
|
|
9e72c1a8bf | ||
|
|
9c6d8deff5 | ||
|
|
868edce7e5 | ||
|
|
0c1babf9fb | ||
|
|
7b302f5e77 | ||
|
|
a6dc9edf08 | ||
|
|
e417a4d434 | ||
|
|
566af67bb8 | ||
|
|
2399f5763f | ||
|
|
8da882dccb | ||
|
|
039c2768ba | ||
|
|
fb827dc0f1 | ||
|
|
de895c6d1e | ||
|
|
3d9ea4b9da | ||
|
|
08df97f431 | ||
|
|
161d28b6dd | ||
|
|
caa704de10 | ||
|
|
72372c42db | ||
|
|
a8d678f354 | ||
|
|
0f49aecbf0 | ||
|
|
a6c24848ba | ||
|
|
83145db060 | ||
|
|
b89a83f8f8 | ||
|
|
b5415233cd | ||
|
|
18abd100b5 | ||
|
|
f8e0a19b9f | ||
|
|
4d2841ccda | ||
|
|
9aebdc292c | ||
|
|
652c03f5cd | ||
|
|
68364f9b8a | ||
|
|
f2ef748b6b | ||
|
|
f2b3e5c53c | ||
|
|
b91ab6c5b9 | ||
|
|
ff3f41eeaf | ||
|
|
1afa35d54d | ||
|
|
372fba129f | ||
|
|
8e15a81f96 | ||
|
|
5381bf722d | ||
|
|
7ba73bf819 | ||
|
|
1f97b772b3 | ||
|
|
ea9f778638 | ||
|
|
c018113c12 | ||
|
|
6aedee785a | ||
|
|
ff402aa3c2 | ||
|
|
ec2fcdf4f2 | ||
|
|
406f9f486c | ||
|
|
d26e096a80 | ||
|
|
5eb8fa9f96 | ||
|
|
46d13d928b | ||
|
|
6d1fe0254e | ||
|
|
0089fff56f | ||
|
|
3877c4fab1 | ||
|
|
06c5d36f03 | ||
|
|
ef2b627f8e | ||
|
|
7b6be0ba39 | ||
|
|
f80ea03c82 | ||
|
|
1330319564 | ||
|
|
4d8aa31f69 | ||
|
|
9d48c84466 | ||
|
|
2bfae3c805 | ||
|
|
40877ab6fb | ||
|
|
f87dff3eb6 | ||
|
|
5f76f1bdbc | ||
|
|
e57d3c2f4b | ||
|
|
65a679b7cd | ||
|
|
d00a550895 | ||
|
|
4baac61dd9 | ||
|
|
499984681c | ||
|
|
594bb15fe6 | ||
|
|
483ca3383d | ||
|
|
f68cf0d009 | ||
|
|
fb86630f81 | ||
|
|
daf9822eab | ||
|
|
d2cb0eb03c | ||
|
|
75ccf9a097 | ||
|
|
9d71dea972 | ||
|
|
ef10ef9813 | ||
|
|
255a4134e7 | ||
|
|
488617cc0b | ||
|
|
bbfde30eb1 | ||
|
|
e0924231c1 | ||
|
|
7d875c0e76 | ||
|
|
606bfd596f | ||
|
|
9ce6b7815d | ||
|
|
8984adc851 | ||
|
|
f293f65bd0 | ||
|
|
b060c76a76 | ||
|
|
cc24101629 | ||
|
|
5dfee8564b | ||
|
|
189755bbb2 | ||
|
|
fff4124d9b | ||
|
|
078788af64 | ||
|
|
12fe70a6d5 | ||
|
|
0e5992af00 | ||
|
|
6a01f96877 | ||
|
|
e8635f3452 | ||
|
|
295e147214 | ||
|
|
8db0ded57b | ||
|
|
9d86d2df71 | ||
|
|
50848ac935 | ||
|
|
5a1816adde | ||
|
|
457fea650e | ||
|
|
2d9691c2db | ||
|
|
27ef26d231 | ||
|
|
bba40f0bb8 | ||
|
|
85b42d8bf0 | ||
|
|
c93de72401 | ||
|
|
0259604a35 | ||
|
|
0d4d624622 | ||
|
|
2ea9005c1b | ||
|
|
69c413d332 | ||
|
|
58d0c30e08 | ||
|
|
626c4e7ae3 | ||
|
|
455bc9d3a5 | ||
|
|
40824c4d46 | ||
|
|
a2a5ba778e | ||
|
|
e8bbc36265 | ||
|
|
ef22e20a1e | ||
|
|
fcdbbabedf | ||
|
|
da68beaef4 | ||
|
|
f40c17a7ed | ||
|
|
12e0fddeae | ||
|
|
ceadaad841 | ||
|
|
1cf81f6edb | ||
|
|
922f1a653a | ||
|
|
2683a30765 | ||
|
|
b6d1b0524c | ||
|
|
c44cb6e966 | ||
|
|
30e119a761 | ||
|
|
080b328b7b | ||
|
|
a704b404d0 | ||
|
|
05d500d755 | ||
|
|
095a702fbe | ||
|
|
115a2cc890 | ||
|
|
d4bc355ec7 | ||
|
|
b9527c0c96 | ||
|
|
da171527ef | ||
|
|
fbc10fd953 | ||
|
|
2250bdfe52 | ||
|
|
9fa74c146a | ||
|
|
9b1b4dfdf0 | ||
|
|
2f0e9e97a4 | ||
|
|
339eb11449 | ||
|
|
aea806f19d | ||
|
|
76d9568dcb | ||
|
|
3e76903c6e | ||
|
|
ac3eded7e4 | ||
|
|
fd873b0189 | ||
|
|
44a9f7776c | ||
|
|
162351cfd4 | ||
|
|
258adf491e | ||
|
|
26ba0c3698 | ||
|
|
f4718cee08 | ||
|
|
6eaf7316e5 | ||
|
|
31619219cc | ||
|
|
a24db2e995 | ||
|
|
251cd181a7 | ||
|
|
c1a1421aa0 | ||
|
|
89b58da1e8 | ||
|
|
45ad80c57a | ||
|
|
074f71034b | ||
|
|
687cc57595 | ||
|
|
91596e2c7b | ||
|
|
1135470656 | ||
|
|
8c9a79e4ae | ||
|
|
33ebccef15 | ||
|
|
4e9b844cc1 | ||
|
|
3d6c2b2948 | ||
|
|
6ac68abfb5 | ||
|
|
4ebf780868 | ||
|
|
b47d4f94fd | ||
|
|
8e3b0735a2 | ||
|
|
2e21758a49 | ||
|
|
05335fa3e3 | ||
|
|
379f4ff60b | ||
|
|
71d1338313 | ||
|
|
ca13447ac5 | ||
|
|
c879a4ddde | ||
|
|
c2bfad857b | ||
|
|
e68d14b9d0 | ||
|
|
f59e8084db | ||
|
|
532bc9e1c5 | ||
|
|
844248339d | ||
|
|
7240e3ecbd | ||
|
|
a56e63421a | ||
|
|
f4dde26eb1 | ||
|
|
fa06982028 | ||
|
|
68ba778e9c | ||
|
|
e767225964 | ||
|
|
9e4f50f691 | ||
|
|
d120d7fc25 | ||
|
|
7186be73e8 | ||
|
|
ef97903316 | ||
|
|
789a8f5476 | ||
|
|
bf2f81e02f | ||
|
|
9b3a16ae11 | ||
|
|
312b87d840 | ||
|
|
5fb1457518 | ||
|
|
7505ac623e | ||
|
|
d37a9464c0 | ||
|
|
5cd661c77b | ||
|
|
c432c1f4c5 | ||
|
|
ad9b63f11d | ||
|
|
5e1f96da4f | ||
|
|
3c936eb0cf | ||
|
|
7d4c0b00ee | ||
|
|
e63dd54b01 | ||
|
|
a7de71dcc2 | ||
|
|
ca50fb1c5d | ||
|
|
77b43bb7f3 | ||
|
|
6c7efb196f | ||
|
|
5b7081c3b7 | ||
|
|
56cadaff6d | ||
|
|
c373165882 | ||
|
|
9c5fac607b | ||
|
|
07279defd1 | ||
|
|
3f9a17c54f | ||
|
|
3715b7a2a3 | ||
|
|
35a0896fc5 | ||
|
|
5e60f1b842 | ||
|
|
fb24fa67e2 | ||
|
|
646ff1bc5a | ||
|
|
17ff797633 | ||
|
|
87078dca6e | ||
|
|
3ad525a48a | ||
|
|
fb19db68a2 | ||
|
|
ded4c599a6 | ||
|
|
c6b56a5e97 | ||
|
|
6e6f468ac4 | ||
|
|
6b6a23df4e | ||
|
|
72d4e5a45c | ||
|
|
1ac0a32573 | ||
|
|
f7c7b906ec | ||
|
|
b50aa17aee | ||
|
|
1df4e80907 | ||
|
|
496ac21259 | ||
|
|
c2aad445c1 | ||
|
|
1aa8521357 | ||
|
|
9edb1ce60b | ||
|
|
fbd512e51d | ||
|
|
bc6c917cf8 | ||
|
|
5a44eb7b1f | ||
|
|
6a57e76222 | ||
|
|
0aebf47df4 | ||
|
|
23d5271eb6 | ||
|
|
58fa19735e | ||
|
|
7e5f726388 | ||
|
|
42a6fe8885 | ||
|
|
a5299f86f7 | ||
|
|
17a1e1b142 | ||
|
|
7338ed8feb | ||
|
|
ffa782ca96 | ||
|
|
fb76c43307 | ||
|
|
09a1491973 | ||
|
|
0a76df5f3c | ||
|
|
6165a26fed | ||
|
|
07b8e90bd5 | ||
|
|
0feb356d42 | ||
|
|
017c82eeee | ||
|
|
b6ba1a75ff | ||
|
|
9ee75bba94 | ||
|
|
435252d851 | ||
|
|
5579098068 | ||
|
|
17866bcc8e | ||
|
|
7a19cb6da6 | ||
|
|
f2c0534544 | ||
|
|
88c83e6f34 | ||
|
|
a2c50245af | ||
|
|
9f5a095079 | ||
|
|
34dfc4edf0 | ||
|
|
8fddbe84a3 | ||
|
|
842f994dbb | ||
|
|
be78519581 | ||
|
|
c209829c44 | ||
|
|
de97f27c3d | ||
|
|
c4315b1551 | ||
|
|
94459bea19 | ||
|
|
45cf7cccd0 | ||
|
|
fe0bfe5147 | ||
|
|
8c86e01ace | ||
|
|
0441d50793 | ||
|
|
737bd7211e | ||
|
|
7de0229450 | ||
|
|
93c9ec672c | ||
|
|
6706f3cc5f | ||
|
|
8192da5243 | ||
|
|
d6ec7ce8af | ||
|
|
47a29187fd | ||
|
|
6a9eaedeac | ||
|
|
e3c724423f | ||
|
|
7dbbf95c72 | ||
|
|
9fa58067fa | ||
|
|
f1b7104bb8 | ||
|
|
e20f2c410c | ||
|
|
f9579b7356 | ||
|
|
efdc2426a9 | ||
|
|
0de8aac1dc | ||
|
|
a0f8c87f56 | ||
|
|
7fec5d75d5 | ||
|
|
d865a266b5 | ||
|
|
c608131e26 | ||
|
|
032aa10d63 | ||
|
|
735e195005 | ||
|
|
6f868e36e5 | ||
|
|
a25f18521e | ||
|
|
64cea3ded4 | ||
|
|
23a0d70d49 | ||
|
|
b0b174b94d | ||
|
|
ba1b693177 | ||
|
|
4998384247 | ||
|
|
b769542283 | ||
|
|
b1f1e30450 | ||
|
|
b2d6f06a9f | ||
|
|
7fc145ebd2 | ||
|
|
cc7585c0a8 | ||
|
|
30ee25a28b | ||
|
|
64a3c93188 | ||
|
|
e2eba09f12 | ||
|
|
81805b514f | ||
|
|
3d2542dc6e | ||
|
|
c9fb16e67b | ||
|
|
0e7ca13cf3 | ||
|
|
cba6c69df4 | ||
|
|
b4db8d0797 | ||
|
|
8a5c806346 | ||
|
|
ec5cd97de6 | ||
|
|
97e6586f71 | ||
|
|
fbb79d73fb | ||
|
|
bb49b02d7d | ||
|
|
6d6d9eb862 | ||
|
|
0c2457ed34 | ||
|
|
f6f0e72224 | ||
|
|
deecae0f01 | ||
|
|
d63d5bd45e | ||
|
|
14d3d5baa3 | ||
|
|
e4d02904ad | ||
|
|
c7b3271edb | ||
|
|
4f68c97627 | ||
|
|
d2d114595b | ||
|
|
4d95f455f4 | ||
|
|
508c91d36c | ||
|
|
160aed7484 | ||
|
|
75cbf35e0d | ||
|
|
b7037d3872 | ||
|
|
2224f84573 | ||
|
|
dcfaf39b0a | ||
|
|
8d8bc8b928 | ||
|
|
f59682fb75 | ||
|
|
f9b2d725a0 | ||
|
|
43a9fcaaf8 | ||
|
|
82f3c86a28 | ||
|
|
95056a49da | ||
|
|
9bcc3576f6 | ||
|
|
2a0a14c127 | ||
|
|
9e61615a08 | ||
|
|
1ed1cb9573 | ||
|
|
b9c049d7c6 | ||
|
|
03e3ae526d | ||
|
|
d5d61f9ffb | ||
|
|
be268576de | ||
|
|
58d93aaf46 | ||
|
|
8d83751011 | ||
|
|
c5f419121f | ||
|
|
48747bab4c | ||
|
|
6b0e1888ec | ||
|
|
1c383797a7 | ||
|
|
367fa87da8 | ||
|
|
5dc7eb25b8 | ||
|
|
c155a1e242 | ||
|
|
84729d8eaa | ||
|
|
6e99da094c | ||
|
|
abd05cb939 | ||
|
|
daea7fa34f | ||
|
|
8b9cb43824 | ||
|
|
3c4094e233 | ||
|
|
786e0588a5 | ||
|
|
04cb7ee87f | ||
|
|
dbf7652e19 | ||
|
|
92f453f422 | ||
|
|
adce385b8c | ||
|
|
02ddf6a31f | ||
|
|
63e2febb70 | ||
|
|
1782058a16 | ||
|
|
58d4e48679 | ||
|
|
777aa9b467 | ||
|
|
c3b1f69ba8 | ||
|
|
4e9b2f23d6 | ||
|
|
d7a014ae95 | ||
|
|
ed52139b41 | ||
|
|
97da89c3e9 | ||
|
|
c1e3348c50 | ||
|
|
6c4e0e6ed4 | ||
|
|
57efffff44 | ||
|
|
2eadc6fd5a | ||
|
|
2aeea61964 | ||
|
|
98a2ad19fd | ||
|
|
4f9650502b | ||
|
|
7be57a460b | ||
|
|
4d64d3215d | ||
|
|
905061ce80 | ||
|
|
17c17901dc | ||
|
|
b2baefa907 | ||
|
|
906780b622 | ||
|
|
868ee3eadd | ||
|
|
a512009170 | ||
|
|
48c3c7ecfc | ||
|
|
bbdb8dc19b | ||
|
|
c2e5e0d808 | ||
|
|
9240dc2a12 | ||
|
|
baacd054c9 | ||
|
|
ebf8b6e8a9 | ||
|
|
84f2ff6b58 | ||
|
|
c7b04a043e | ||
|
|
6512ce604f | ||
|
|
f6b5b663dc | ||
|
|
1732c913a3 | ||
|
|
2321b4985d | ||
|
|
1d6475ac0e | ||
|
|
04f1775e10 | ||
|
|
ec7d99228a | ||
|
|
09e083a718 | ||
|
|
e7ba376839 | ||
|
|
a8ce1408a9 | ||
|
|
c0a3e113d9 | ||
|
|
ce9bdfcc55 | ||
|
|
02b32ecdd8 | ||
|
|
61ae9998e1 | ||
|
|
22f5b77e0c | ||
|
|
adeda255f0 | ||
|
|
2ac68427fc | ||
|
|
5ba27cc90f | ||
|
|
f4549b68c7 | ||
|
|
7848574a38 | ||
|
|
8800160bb5 | ||
|
|
4e9df8b5c3 | ||
|
|
b1091a482c | ||
|
|
749535a3ca | ||
|
|
87c003230c | ||
|
|
6938614468 | ||
|
|
8108caffe3 | ||
|
|
db38ba268f | ||
|
|
01c9f6cf08 | ||
|
|
ba8785dc16 | ||
|
|
c6be7cf83a | ||
|
|
fca98d1003 | ||
|
|
35148b57f8 | ||
|
|
5e77968ca2 | ||
|
|
e7bdf659fb | ||
|
|
ba987bcb39 | ||
|
|
b54e0e50c0 | ||
|
|
36c08fdc66 | ||
|
|
9879780dd8 | ||
|
|
b1af0a9511 | ||
|
|
1938b9e377 | ||
|
|
04d4bba780 | ||
|
|
5287893d82 | ||
|
|
b7d0b700c6 | ||
|
|
89b5210e5b | ||
|
|
ea9c639ee9 | ||
|
|
7998d01dc9 | ||
|
|
e02b7968ad | ||
|
|
38f6afbf4c | ||
|
|
092afb7aae | ||
|
|
7a6ff619e5 | ||
|
|
60a2ac7bfe | ||
|
|
5ee8ee71fd | ||
|
|
3b08c2d90a | ||
|
|
26a85c764e | ||
|
|
0505ca35aa | ||
|
|
eec92f52e9 | ||
|
|
e969b0c6ed | ||
|
|
33c17e50b3 | ||
|
|
e129b0793c | ||
|
|
45aa2f276a | ||
|
|
3789ac45e2 | ||
|
|
dec68e3673 | ||
|
|
22940969ff | ||
|
|
8c067f5fb4 | ||
|
|
4e21aefe74 | ||
|
|
bb0df16c90 | ||
|
|
5031ab2b4e | ||
|
|
90584be746 | ||
|
|
80d33662e4 | ||
|
|
2f027551c9 | ||
|
|
1ed08d09d0 | ||
|
|
8e4ab5bd04 | ||
|
|
73edc2dd58 | ||
|
|
a2e8f3a6b2 | ||
|
|
b724dd1e94 | ||
|
|
6e9d71c5eb | ||
|
|
4c46d39955 | ||
|
|
d2c7a00584 | ||
|
|
04df7fd92c | ||
|
|
d79a41dde6 | ||
|
|
78f3595bc1 | ||
|
|
55e136f1b4 | ||
|
|
389adbce62 | ||
|
|
ebc355a465 | ||
|
|
ffafa801f6 | ||
|
|
074fb0ff22 | ||
|
|
c16b71dac6 | ||
|
|
73e386eca5 | ||
|
|
b8a5361e28 | ||
|
|
5cc837289a | ||
|
|
498bc3ee96 | ||
|
|
3c9179e59d | ||
|
|
b9692c5536 | ||
|
|
4e60190199 | ||
|
|
3635fe0f2e | ||
|
|
508549f657 | ||
|
|
43eddb79f6 | ||
|
|
ea2e6787c6 | ||
|
|
b3c5f8860c | ||
|
|
f48b212a1c | ||
|
|
0f1bd86ba2 | ||
|
|
6c21b92d15 | ||
|
|
cf629e2a76 | ||
|
|
190b9470a4 | ||
|
|
3463a85943 | ||
|
|
bc7cff230c | ||
|
|
54d92ff973 | ||
|
|
9a2d682a42 | ||
|
|
9d4570f65c | ||
|
|
ed0bab7c40 | ||
|
|
49103d635c | ||
|
|
4d5a71d327 | ||
|
|
58d217599b | ||
|
|
039d6ccf4f | ||
|
|
f9092e7948 | ||
|
|
2701ca416f | ||
|
|
f0b834a913 | ||
|
|
0e9a71798c | ||
|
|
ba85aecf00 | ||
|
|
37a4c9deb8 | ||
|
|
482e136d19 | ||
|
|
0ff947454c | ||
|
|
b9f0a3ae19 | ||
|
|
34f41ea37f | ||
|
|
46dbc92b5f | ||
|
|
8eac1a0e20 | ||
|
|
f76f0c00ac | ||
|
|
a3c629251a | ||
|
|
e1045a84aa | ||
|
|
25447e508e | ||
|
|
1ad67e8aa5 | ||
|
|
84089b4b4d | ||
|
|
e5b46e6cf8 | ||
|
|
c8e5670aed | ||
|
|
43a70551b9 | ||
|
|
19a6c2a306 | ||
|
|
172dff77d5 | ||
|
|
c3ccde3e39 | ||
|
|
282aec4367 | ||
|
|
bf7fcf58f0 | ||
|
|
a8a88410f4 | ||
|
|
5e7b71d600 | ||
|
|
68173a8354 | ||
|
|
2644179a42 | ||
|
|
6c62bfd2ad | ||
|
|
4dff30b6c6 | ||
|
|
2709c7ebc5 | ||
|
|
686c8a8ffb | ||
|
|
be9cc0df5b | ||
|
|
3272f07058 | ||
|
|
b1ecb718ba | ||
|
|
d058e5ac3c | ||
|
|
ae80391da6 | ||
|
|
6ec60ff52c | ||
|
|
65e64205ef | ||
|
|
1b6945317e | ||
|
|
8add336c1a | ||
|
|
d27d67dfe4 | ||
|
|
59030e5d61 | ||
|
|
6c4c3e1049 | ||
|
|
448aaa4718 | ||
|
|
180c905a8a | ||
|
|
85103e4550 | ||
|
|
087fcf54b1 | ||
|
|
294c276e29 | ||
|
|
7cb08307a7 | ||
|
|
b1e6d90af1 | ||
|
|
9e6c5b5778 | ||
|
|
2f02fc2c04 | ||
|
|
4086ac9518 | ||
|
|
4d044e6254 | ||
|
|
d8d6142fbe | ||
|
|
afe0818c33 | ||
|
|
ca7282479f | ||
|
|
134a24d5bc | ||
|
|
480b6cab3c | ||
|
|
d5efd657ae | ||
|
|
d6450631bf | ||
|
|
e9cb9421ef | ||
|
|
c0272f1314 | ||
|
|
ede8a53a76 | ||
|
|
fdcbf37e0b | ||
|
|
53ebd7a8c2 | ||
|
|
6c1d4d92bb | ||
|
|
ffc197b914 | ||
|
|
4a0994209e | ||
|
|
f37589b1f5 | ||
|
|
4ed409f35a | ||
|
|
d126868a25 | ||
|
|
56f2e2c4cf | ||
|
|
34d7280df4 | ||
|
|
8908036b11 | ||
|
|
e205d0ef8e | ||
|
|
38fbab1d18 | ||
|
|
c128625857 | ||
|
|
e11bf35691 | ||
|
|
c2a39bc21f | ||
|
|
0ff2bed63a | ||
|
|
331d9d55b1 | ||
|
|
4ce882965a | ||
|
|
385c3cd91c | ||
|
|
7a4baab7cb | ||
|
|
3cb9a2bf51 | ||
|
|
ad48c7b3a9 | ||
|
|
9268242040 | ||
|
|
b32db4ceeb | ||
|
|
207864a98b | ||
|
|
57d382ceda | ||
|
|
848cbcbfbe | ||
|
|
4f53291fe8 | ||
|
|
2569cd129a | ||
|
|
f3fc85fd2b | ||
|
|
b9de9d0abe | ||
|
|
f12c896ac7 | ||
|
|
8fe3f06999 | ||
|
|
d3c09fd3f4 | ||
|
|
142e8c5b36 | ||
|
|
e5f890e195 | ||
|
|
c712968890 | ||
|
|
fa71280795 | ||
|
|
bb8f7f0e9a | ||
|
|
c43348886f | ||
|
|
5598b0eac7 | ||
|
|
0628dc172e | ||
|
|
b602348e64 | ||
|
|
cf71dc0a01 | ||
|
|
9512930b0f | ||
|
|
be67ad25e7 | ||
|
|
3ee8f900ec | ||
|
|
a119efc478 | ||
|
|
a946ce7458 | ||
|
|
57a54ad0fe | ||
|
|
fe13359024 | ||
|
|
ea5991fb0a | ||
|
|
f5f13df5ff | ||
|
|
4a3ba35c1d | ||
|
|
c5b96afe07 | ||
|
|
5cedc5d44b | ||
|
|
f12fa8d3a9 | ||
|
|
021300538a | ||
|
|
a71d6635e6 | ||
|
|
3df7e9cba6 | ||
|
|
6a16dfa823 | ||
|
|
6428c9f13c | ||
|
|
4e422a0354 | ||
|
|
36cae13352 | ||
|
|
dfd67b8124 | ||
|
|
365907ab22 | ||
|
|
8b5ded4324 | ||
|
|
a13a858112 | ||
|
|
a4bc7bd611 | ||
|
|
8adb5d03da | ||
|
|
4b6c1c270f | ||
|
|
1b227a1eff | ||
|
|
b0e9e1a24d | ||
|
|
bf0b843ce1 | ||
|
|
fce770e4f4 | ||
|
|
8dd5ac55e8 | ||
|
|
507828edde | ||
|
|
aca6623f14 | ||
|
|
765c96919c | ||
|
|
7a9215a4d3 | ||
|
|
dd9cde88f3 | ||
|
|
e52f1470b6 | ||
|
|
1a2f9a71f5 | ||
|
|
ebf107e73c | ||
|
|
d5f9242f84 | ||
|
|
84fc829be3 | ||
|
|
bdd7dea4b4 | ||
|
|
b46ee12a19 | ||
|
|
994e425804 | ||
|
|
0bcc7635ac | ||
|
|
1ab28d0cf0 | ||
|
|
967f0082c3 | ||
|
|
34a2afa704 | ||
|
|
b8602b7821 | ||
|
|
7bc6c65bb2 | ||
|
|
d6fefe2468 | ||
|
|
781e08a6a6 | ||
|
|
a8d70c15f8 | ||
|
|
7cf55315b5 | ||
|
|
3cd3d5e80e | ||
|
|
c76008d24c | ||
|
|
1fd0ee5999 | ||
|
|
771eb3d66c | ||
|
|
b24456abb4 | ||
|
|
ded9847eaf | ||
|
|
9918803333 | ||
|
|
bf527a41dd | ||
|
|
154d441ff2 | ||
|
|
3115313551 | ||
|
|
2e61a1c412 | ||
|
|
046e2e2b85 | ||
|
|
e901a3604a | ||
|
|
523bfdbbe1 | ||
|
|
9f81e770eb | ||
|
|
670b6ef3d5 | ||
|
|
5d1e3f207c | ||
|
|
e321f294e5 | ||
|
|
1a0780fd3e | ||
|
|
5dd5e765ae | ||
|
|
c157253372 | ||
|
|
e5fae351d6 | ||
|
|
a44d91ec27 | ||
|
|
2f96c6547c | ||
|
|
c187a62353 | ||
|
|
c848e51e13 | ||
|
|
8395e69e94 | ||
|
|
8f9057729c | ||
|
|
f031befc6e | ||
|
|
4e8d37facf | ||
|
|
071ad45d31 | ||
|
|
c9901595f7 | ||
|
|
3a1f22583f | ||
|
|
e1163f7180 | ||
|
|
f66a53cfc9 | ||
|
|
68a69d9064 | ||
|
|
309d3e6449 | ||
|
|
4e0b6f5b9e | ||
|
|
a35003b123 | ||
|
|
53e8c4d54e | ||
|
|
c070177800 | ||
|
|
5700eeed1b | ||
|
|
23387f6a06 | ||
|
|
d6b101069e | ||
|
|
c9521b97fe | ||
|
|
248d85cae6 | ||
|
|
7ac5343119 | ||
|
|
954223958f | ||
|
|
c6c019ed8b | ||
|
|
43258e8dc0 | ||
|
|
9e89d74d2f | ||
|
|
8b790ebac9 | ||
|
|
4bd1176df5 | ||
|
|
4c4c6f5de2 | ||
|
|
9498b2865f | ||
|
|
64ffcffe32 | ||
|
|
bfdcd3da87 | ||
|
|
f6f0cb1a5f | ||
|
|
6aa8570d6c | ||
|
|
824f63216a | ||
|
|
a104140a51 | ||
|
|
c3c980e858 | ||
|
|
92bc0b24b8 | ||
|
|
dec8b0a9a1 | ||
|
|
df1d8aed44 | ||
|
|
41d72cb51b | ||
|
|
45e1c15d24 | ||
|
|
865ab65a07 | ||
|
|
009c63e7db | ||
|
|
5d70a5fffd | ||
|
|
f3a095ab65 | ||
|
|
6c6d6f953f | ||
|
|
0b4b3c7bf2 | ||
|
|
3e894f8e93 | ||
|
|
cb7dc5c52e | ||
|
|
9cfb43d8d0 | ||
|
|
7ada57e2a8 | ||
|
|
68b32ed0f0 | ||
|
|
61ab5c6fe3 | ||
|
|
837f7e7b50 | ||
|
|
b392035544 | ||
|
|
450004ebd8 | ||
|
|
6f403fdd1b | ||
|
|
f5cf4155c2 | ||
|
|
ea30adeb47 | ||
|
|
9bc2e4abb3 | ||
|
|
7b9e0bc300 | ||
|
|
d44a0aa3ff | ||
|
|
522fe562ff | ||
|
|
745102360b | ||
|
|
19d9c44cf5 | ||
|
|
5c14b57462 | ||
|
|
c875944e05 | ||
|
|
2430032e3a | ||
|
|
0f63d14999 | ||
|
|
faaec003f4 | ||
|
|
c48f5ed6e7 | ||
|
|
c9fe4b1a14 | ||
|
|
46d1012ad4 | ||
|
|
7eeddd3ad9 | ||
|
|
e339ba1f6b | ||
|
|
ac1b01b4c7 | ||
|
|
497dd007d9 | ||
|
|
0d845149ec | ||
|
|
7a854ccad2 | ||
|
|
937d11d7c3 | ||
|
|
51918ef868 | ||
|
|
c8674d61b8 | ||
|
|
cf18032e7f | ||
|
|
f18ddd95c1 | ||
|
|
025620cc4e | ||
|
|
692ce65f3e | ||
|
|
bb3732c22f | ||
|
|
87a8780b73 | ||
|
|
78522ba18e | ||
|
|
79fbb9c303 | ||
|
|
e21e7b0d51 | ||
|
|
521e0756e1 | ||
|
|
dbcd040180 | ||
|
|
17e69e660c | ||
|
|
ef10c754b1 | ||
|
|
912890c104 | ||
|
|
ac68091bec | ||
|
|
2773de7b54 | ||
|
|
5f7de1bb48 | ||
|
|
264516c37d | ||
|
|
eb84ac57c7 | ||
|
|
021c81e978 | ||
|
|
ab6b6d215e | ||
|
|
53d0daf3b4 | ||
|
|
8fb33b0818 | ||
|
|
61cb1faf8f | ||
|
|
5cbb349efa | ||
|
|
93bed03d8d | ||
|
|
581ab8f552 | ||
|
|
6154357daa | ||
|
|
3a1e462bef | ||
|
|
30af98200f | ||
|
|
ff27e62e1f | ||
|
|
7e93e75d8e | ||
|
|
ecd02134fa | ||
|
|
3c0eec0209 | ||
|
|
7b9e2cf91f | ||
|
|
312dec2baa | ||
|
|
be812b8d21 | ||
|
|
e63a5f72be | ||
|
|
1e2287e6e1 | ||
|
|
3508917f17 | ||
|
|
3ed22580fe | ||
|
|
20fabbc0ec | ||
|
|
831be14fd9 | ||
|
|
019e84f0d2 | ||
|
|
694abe2004 | ||
|
|
e07391fe78 | ||
|
|
9515177e29 | ||
|
|
bd6e58a20e | ||
|
|
e8c826c816 | ||
|
|
d753191d20 | ||
|
|
d4e91b462e | ||
|
|
fa2736277f | ||
|
|
196c309d1d | ||
|
|
d46d015fd5 | ||
|
|
999bf83f15 | ||
|
|
96470e0c8d | ||
|
|
ed8164d502 | ||
|
|
682d7a8d76 | ||
|
|
eb51457e69 | ||
|
|
65817c4c57 | ||
|
|
9bc8cc6b4e | ||
|
|
832648c351 | ||
|
|
21b58a8885 | ||
|
|
a9ee819ea1 | ||
|
|
736579e473 | ||
|
|
3b93e2d4d9 | ||
|
|
ac9bd2c055 | ||
|
|
4124762343 | ||
|
|
ea8600e204 | ||
|
|
895e9167b0 | ||
|
|
d15d2d2df6 | ||
|
|
75bcd4ff53 | ||
|
|
a73117ddd0 | ||
|
|
9e4d943c69 | ||
|
|
025a8a344b | ||
|
|
9ee9e566d4 | ||
|
|
0de807b1be | ||
|
|
59ee027d8a | ||
|
|
7aa4486741 | ||
|
|
5e8277f36a | ||
|
|
573593ae31 | ||
|
|
a5c405f4be | ||
|
|
e9c5c3520e | ||
|
|
26947267b1 | ||
|
|
4bb2030315 | ||
|
|
3852b5ae4b | ||
|
|
ea921d3a02 | ||
|
|
ca2d616277 | ||
|
|
88686af850 | ||
|
|
7f4ef83df0 | ||
|
|
1fd971b78b | ||
|
|
d6c8dec451 | ||
|
|
30ecb32a6f | ||
|
|
a01b274352 | ||
|
|
193f5b39cb | ||
|
|
db8111ef7c | ||
|
|
913a4b794c | ||
|
|
accea17e9d | ||
|
|
c6fa00fbe3 | ||
|
|
bfb8f4f01a | ||
|
|
4b745a86b7 | ||
|
|
ddf894dcb0 |
12
.codecov.yml
12
.codecov.yml
@@ -58,3 +58,15 @@ ignore:
|
||||
- "src/tests/"
|
||||
- "include/xrpl/beast/test/"
|
||||
- "include/xrpl/beast/unit_test/"
|
||||
# Telemetry modules. Telemetry compiles in by default (conanfile.py,
|
||||
# CMakeLists.txt), but the unit-test suite never starts an exporter, so these
|
||||
# files record no coverage. This block belongs on the earliest branch that
|
||||
# adds telemetry code — codecov config only flows child-ward, so an ignore
|
||||
# added on a later branch can never cover the branches before it.
|
||||
- "src/xrpld/telemetry/"
|
||||
- "src/libxrpl/telemetry/"
|
||||
- "include/xrpl/telemetry/"
|
||||
# Per-module span-name and span-label constant headers: compile-time
|
||||
# constants only, colocated with their subsystem rather than under telemetry/.
|
||||
- "**/*SpanNames.h"
|
||||
- "**/*SpanLabels.h"
|
||||
|
||||
@@ -7,8 +7,6 @@ ignorePaths:
|
||||
- cmake/**
|
||||
- LICENSE.md
|
||||
- .clang-tidy
|
||||
- src/test/app/wasm_fixtures/**/*.wat
|
||||
- src/test/app/wasm_fixtures/*.c
|
||||
- nix/check-tools/*.txt # generated, and full of Nix store hashes
|
||||
language: en
|
||||
allowCompoundWords: true # TODO (#6334)
|
||||
@@ -45,7 +43,6 @@ suggestWords:
|
||||
- synched->synced
|
||||
- synch->sync
|
||||
words:
|
||||
- cusip
|
||||
- abempty
|
||||
- AMMID
|
||||
- AMMMPT
|
||||
@@ -71,11 +68,9 @@ words:
|
||||
- Btrfs
|
||||
- Buildx
|
||||
- canonicality
|
||||
- cdylib
|
||||
- canonicalised
|
||||
- canonicality
|
||||
- cctools
|
||||
- CGNAT
|
||||
- canonicalised
|
||||
- cctools
|
||||
- changespq
|
||||
- checkme
|
||||
- choco
|
||||
@@ -120,12 +115,13 @@ words:
|
||||
- dsymutil
|
||||
- dxrpl
|
||||
- elgamal
|
||||
- emittance
|
||||
- enabled
|
||||
- enablerepo
|
||||
- endmacro
|
||||
- envrc
|
||||
- exceptioned
|
||||
- EXPECT_STREQ
|
||||
- exfiltration
|
||||
- Falco
|
||||
- fcontext
|
||||
- finalizers
|
||||
@@ -134,6 +130,8 @@ words:
|
||||
- fsanitize
|
||||
- funclets
|
||||
- Gamal
|
||||
- gantt
|
||||
- Gantt
|
||||
- gcov
|
||||
- gcovr
|
||||
- ghead
|
||||
@@ -143,6 +141,8 @@ words:
|
||||
- gpgkey
|
||||
- Hinnant
|
||||
- hotwallet
|
||||
- hicpp
|
||||
- htpasswd
|
||||
- hwaddress
|
||||
- hwrap
|
||||
- ifndef
|
||||
@@ -185,7 +185,6 @@ words:
|
||||
- MEMORYSTATUSEX
|
||||
- Merkle
|
||||
- misprediction
|
||||
- mispricing
|
||||
- missingok
|
||||
- MPTAMM
|
||||
- mptbalance
|
||||
@@ -222,6 +221,7 @@ words:
|
||||
- nonxrp
|
||||
- noreplace
|
||||
- noripple
|
||||
- nostd
|
||||
- nostdinc
|
||||
- notifempty
|
||||
- nudb
|
||||
@@ -230,6 +230,7 @@ words:
|
||||
- Nyffenegger
|
||||
- onlatest
|
||||
- ostr
|
||||
- otelc
|
||||
- otool
|
||||
- oxalica
|
||||
- pargs
|
||||
@@ -240,6 +241,7 @@ words:
|
||||
- permdex
|
||||
- perminute
|
||||
- permissioned
|
||||
- pimpl
|
||||
- pointee
|
||||
- populator
|
||||
- preauth
|
||||
@@ -259,11 +261,12 @@ words:
|
||||
- queuable
|
||||
- Raphson
|
||||
- rcflags
|
||||
- reparent
|
||||
- replayer
|
||||
- repodata
|
||||
- repomd
|
||||
- rerandomization
|
||||
- rerandomize
|
||||
- rerandomization
|
||||
- rerandomized
|
||||
- rerandomizes
|
||||
- rerere
|
||||
@@ -286,8 +289,8 @@ words:
|
||||
- rustup
|
||||
- sahyadri
|
||||
- Satoshi
|
||||
- Schnorr
|
||||
- scons
|
||||
- Schnorr
|
||||
- secp
|
||||
- sendq
|
||||
- seqit
|
||||
@@ -312,9 +315,7 @@ words:
|
||||
- statsd
|
||||
- STATSDCOLLECTOR
|
||||
- stissue
|
||||
- stjson
|
||||
- stnum
|
||||
- stnumber
|
||||
- stobj
|
||||
- stobject
|
||||
- stpath
|
||||
@@ -333,6 +334,7 @@ words:
|
||||
- TMEndpointv2
|
||||
- toolchain
|
||||
- tparam
|
||||
- traceql
|
||||
- trixie
|
||||
- tx
|
||||
- txid
|
||||
@@ -340,9 +342,10 @@ words:
|
||||
- txjson
|
||||
- txn
|
||||
- txns
|
||||
- txqueue
|
||||
- txs
|
||||
- UBSAN
|
||||
- ubsan
|
||||
- UBSAN
|
||||
- ufdio
|
||||
- umant
|
||||
- unacquired
|
||||
@@ -356,7 +359,6 @@ words:
|
||||
- unfund
|
||||
- ungated
|
||||
- unimpair
|
||||
- unmetered
|
||||
- unroutable
|
||||
- unscalable
|
||||
- unserviced
|
||||
@@ -382,11 +384,9 @@ words:
|
||||
- writeme
|
||||
- wsrch
|
||||
- wthread
|
||||
- Xahau
|
||||
- xbridge
|
||||
- xchain
|
||||
- xcrun
|
||||
- xfloat
|
||||
- ximinez
|
||||
- XMACRO
|
||||
- xored
|
||||
@@ -396,4 +396,8 @@ words:
|
||||
- xrplf
|
||||
- xxhash
|
||||
- xxhasher
|
||||
- xychart
|
||||
- zpages
|
||||
- zstdio
|
||||
- pratik
|
||||
- dedup
|
||||
|
||||
2
.github/CODEOWNERS
vendored
2
.github/CODEOWNERS
vendored
@@ -1,2 +0,0 @@
|
||||
# Allow anyone to review any change by default.
|
||||
*
|
||||
@@ -19,7 +19,6 @@ libxrpl.ledger > xrpl.json
|
||||
libxrpl.ledger > xrpl.ledger
|
||||
libxrpl.ledger > xrpl.nodestore
|
||||
libxrpl.ledger > xrpl.protocol
|
||||
libxrpl.ledger > xrpl.server
|
||||
libxrpl.ledger > xrpl.shamap
|
||||
libxrpl.net > xrpl.basics
|
||||
libxrpl.net > xrpl.net
|
||||
@@ -54,6 +53,10 @@ libxrpl.shamap > xrpl.basics
|
||||
libxrpl.shamap > xrpl.nodestore
|
||||
libxrpl.shamap > xrpl.protocol
|
||||
libxrpl.shamap > xrpl.shamap
|
||||
libxrpl.telemetry > xrpl.basics
|
||||
libxrpl.telemetry > xrpl.config
|
||||
libxrpl.telemetry > xrpl.protocol
|
||||
libxrpl.telemetry > xrpl.telemetry
|
||||
libxrpl.tx > xrpl.basics
|
||||
libxrpl.tx > xrpl.conditions
|
||||
libxrpl.tx > xrpl.core
|
||||
@@ -61,6 +64,7 @@ libxrpl.tx > xrpl.json
|
||||
libxrpl.tx > xrpl.ledger
|
||||
libxrpl.tx > xrpl.protocol
|
||||
libxrpl.tx > xrpl.server
|
||||
libxrpl.tx > xrpl.telemetry
|
||||
libxrpl.tx > xrpl.tx
|
||||
test.app > test.jtx
|
||||
test.app > test.unit_test
|
||||
@@ -194,6 +198,7 @@ tests.libxrpl > xrpl.protocol_autogen
|
||||
tests.libxrpl > xrpl.resource
|
||||
tests.libxrpl > xrpl.server
|
||||
tests.libxrpl > xrpl.shamap
|
||||
tests.libxrpl > xrpl.telemetry
|
||||
tests.libxrpl > xrpl.tx
|
||||
xrpl.conditions > xrpl.basics
|
||||
xrpl.conditions > xrpl.protocol
|
||||
@@ -202,12 +207,12 @@ xrpl.consensus > xrpl.basics
|
||||
xrpl.consensus > xrpl.json
|
||||
xrpl.consensus > xrpl.ledger
|
||||
xrpl.consensus > xrpl.protocol
|
||||
xrpl.consensus > xrpl.telemetry
|
||||
xrpl.core > xrpl.basics
|
||||
xrpl.core > xrpl.json
|
||||
xrpl.core > xrpl.protocol
|
||||
xrpl.json > xrpl.basics
|
||||
xrpl.ledger > xrpl.basics
|
||||
xrpl.ledger > xrpl.core
|
||||
xrpl.ledger > xrpl.json
|
||||
xrpl.ledger > xrpl.nodestore
|
||||
xrpl.ledger > xrpl.protocol
|
||||
@@ -238,16 +243,20 @@ xrpl.server > xrpl.resource
|
||||
xrpl.shamap > xrpl.basics
|
||||
xrpl.shamap > xrpl.nodestore
|
||||
xrpl.shamap > xrpl.protocol
|
||||
xrpl.telemetry > xrpl.basics
|
||||
xrpl.telemetry > xrpl.config
|
||||
xrpl.tx > xrpl.basics
|
||||
xrpl.tx > xrpl.core
|
||||
xrpl.tx > xrpl.ledger
|
||||
xrpl.tx > xrpl.protocol
|
||||
xrpl.tx > xrpl.telemetry
|
||||
xrpld.app > test.unit_test
|
||||
xrpld.app > xrpl.basics
|
||||
xrpld.app > xrpl.config
|
||||
xrpld.app > xrpl.consensus
|
||||
xrpld.app > xrpl.core
|
||||
xrpld.app > xrpld.core
|
||||
xrpld.app > xrpld.telemetry
|
||||
xrpld.app > xrpl.json
|
||||
xrpld.app > xrpl.ledger
|
||||
xrpld.app > xrpl.net
|
||||
@@ -258,6 +267,7 @@ xrpld.app > xrpl.rdb
|
||||
xrpld.app > xrpl.resource
|
||||
xrpld.app > xrpl.server
|
||||
xrpld.app > xrpl.shamap
|
||||
xrpld.app > xrpl.telemetry
|
||||
xrpld.app > xrpl.tx
|
||||
xrpld.core > xrpl.basics
|
||||
xrpld.core > xrpl.config
|
||||
@@ -271,6 +281,7 @@ xrpld.overlay > xrpl.consensus
|
||||
xrpld.overlay > xrpl.core
|
||||
xrpld.overlay > xrpld.core
|
||||
xrpld.overlay > xrpld.peerfinder
|
||||
xrpld.overlay > xrpld.telemetry
|
||||
xrpld.overlay > xrpl.json
|
||||
xrpld.overlay > xrpl.ledger
|
||||
xrpld.overlay > xrpl.peerfinder
|
||||
@@ -278,6 +289,7 @@ xrpld.overlay > xrpl.protocol
|
||||
xrpld.overlay > xrpl.resource
|
||||
xrpld.overlay > xrpl.server
|
||||
xrpld.overlay > xrpl.shamap
|
||||
xrpld.overlay > xrpl.telemetry
|
||||
xrpld.overlay > xrpl.tx
|
||||
xrpld.peerfinder > xrpl.basics
|
||||
xrpld.peerfinder > xrpld.app
|
||||
@@ -305,9 +317,13 @@ xrpld.rpc > xrpl.rdb
|
||||
xrpld.rpc > xrpl.resource
|
||||
xrpld.rpc > xrpl.server
|
||||
xrpld.rpc > xrpl.shamap
|
||||
xrpld.rpc > xrpl.telemetry
|
||||
xrpld.rpc > xrpl.tx
|
||||
xrpld.shamap > xrpl.basics
|
||||
xrpld.shamap > xrpld.core
|
||||
xrpld.shamap > xrpl.nodestore
|
||||
xrpld.shamap > xrpl.protocol
|
||||
xrpld.shamap > xrpl.shamap
|
||||
xrpld.telemetry > xrpl.basics
|
||||
xrpld.telemetry > xrpl.consensus
|
||||
xrpld.telemetry > xrpl.telemetry
|
||||
|
||||
70
.github/scripts/otel-naming/README.md
vendored
Normal file
70
.github/scripts/otel-naming/README.md
vendored
Normal file
@@ -0,0 +1,70 @@
|
||||
# OTel naming-consistency check
|
||||
|
||||
`check_otel_naming.py` enforces the OpenTelemetry span-attribute naming
|
||||
convention documented in
|
||||
[CONTRIBUTING.md](../../../CONTRIBUTING.md#telemetry-span-attribute-naming)
|
||||
across every layer of the telemetry pipeline. The `*SpanNames.h` constants are
|
||||
the single source of truth (L1); every other layer must agree with them.
|
||||
|
||||
## Running locally
|
||||
|
||||
```
|
||||
python .github/scripts/otel-naming/check_otel_naming.py
|
||||
```
|
||||
|
||||
It takes no arguments, can be run from any directory inside the repo, and uses
|
||||
only the Python standard library (no `pip install`, matching the levelization
|
||||
check). A non-zero exit code means a violation was found; the output lists each
|
||||
violation as `RULE | location | token | expected`.
|
||||
|
||||
## What it checks
|
||||
|
||||
The valid key set is **derived dynamically from the OTel code** — there is no
|
||||
hardcoded allowlist:
|
||||
|
||||
- **L1 keys** come from the `namespace attr { ... }` blocks of every
|
||||
`*SpanNames.h`, resolving the `makeStr("x")` / `join(seg::a, seg::b)` DSL
|
||||
(cross-file, so `join(seg::rpc, ...)` resolves `seg::rpc` from the base
|
||||
`SpanNames.h`). Each constant is resolved against **its own** header, so two
|
||||
headers that define a same-named constant (e.g. a base `attr::ledgerHash` and
|
||||
a domain `attr::ledgerHash`) each contribute their real wire key — a later
|
||||
header cannot clobber an earlier one's value in a flat table.
|
||||
- **Legitimate dotted keys** = ONLY the keys the code actually sets as resource
|
||||
attributes, i.e. the entries inside `Telemetry.cpp`'s `Resource::Create({...})`
|
||||
call: the `semconv::service::*` keys (`service.*`) plus any `attr::<name>`
|
||||
constants passed there (`xrpl.network.*`). A dotted key that is _declared_ in a
|
||||
header but never set as a resource attr is a span attribute in resource
|
||||
clothing — a Rule-A violation, even if it lives in the base `SpanNames.h`.
|
||||
|
||||
### Rules (each fails the build, when its inputs are present)
|
||||
|
||||
| Rule | Check |
|
||||
| ---- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| A | No stray dotted span-attribute key (only the derived resource keys may be dotted). |
|
||||
| G | Attribute keys are `lower_snake_case` (`^[a-z][a-z0-9_]*$` per dot-segment) — no camelCase, UPPERCASE, or spaces. |
|
||||
| F | No string literals as attribute keys or span-name arguments in `setAttribute`/`addEvent`/`span`/`rootSpan`/`childSpan` (`rootSpan` shares `span`'s `(cat, prefix, name)` signature). Attribute _values_ are exempt (runtime data); `*SpanNames.h` definitions and test files are exempt. |
|
||||
| B | Every collector `spanmetrics.dimensions` name exists in the L1 key set. |
|
||||
| C | Every Tempo span-filter tag exists in the L1 key set. |
|
||||
| D | Every dashboard label resolves to an L1 span attribute, a native-metric label (L6, emitted by MetricsRegistry), or a Prometheus/Grafana builtin. TraceQL scope prefixes (`span.`/`resource.`/…) are stripped before the L1 lookup. |
|
||||
| E | No dotted `xrpl.<domain>.<field>` attribute key in the runbook (only the L1 resource attrs `xrpl.network.*` may be dotted). Span names, filenames, OTel-standard keys, and metric labels are not flagged. |
|
||||
|
||||
Rule F runs **unconditionally** (it is a purely syntactic check on the
|
||||
call-sites and needs no `*SpanNames.h`), so a code path that calls
|
||||
`SpanGuard::span`/`setAttribute` directly without ever defining a header is
|
||||
still caught.
|
||||
|
||||
### Warnings (printed, never fail the build)
|
||||
|
||||
| Rule | Check |
|
||||
| ---- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||
| H | A namespace-qualified constant (e.g. `foo::bar::myKey`) used at a telemetry call-site is not defined in any `*SpanNames.h`. The constant should live in the proper header; defining it in-place bypasses rules A/G/F. Warns rather than fails — the argument may be a legitimately dynamic value, and the header may live on a later branch. Bare locals and `std::` names are not warned. |
|
||||
|
||||
## Presence-gated
|
||||
|
||||
Every rule runs **only when the source files it needs are present** in the tree
|
||||
and is otherwise skipped (printed as `SKIP: <rule> — <reason>`), never failed.
|
||||
This keeps the check correct no matter how telemetry work is split across PRs —
|
||||
a stacked chain, one large PR, or independent per-stage PRs where (for example)
|
||||
the collector config lands before the dashboards. The collector/Tempo/dashboard/
|
||||
runbook layers are introduced in later phases; on a branch without them, only
|
||||
the L1-intrinsic rules (A, G, F) run.
|
||||
916
.github/scripts/otel-naming/check_otel_naming.py
vendored
Normal file
916
.github/scripts/otel-naming/check_otel_naming.py
vendored
Normal file
@@ -0,0 +1,916 @@
|
||||
#!/usr/bin/env python3
|
||||
|
||||
"""
|
||||
Usage: check_otel_naming.py
|
||||
This script takes no parameters and can be called from any directory inside the
|
||||
repository (it locates the repo root via `git rev-parse`).
|
||||
|
||||
Enforces the OpenTelemetry span-attribute naming convention documented in
|
||||
CONTRIBUTING.md ("Telemetry span attribute naming") across every layer of the
|
||||
telemetry pipeline. The `*SpanNames.h` constants are the single source of truth
|
||||
(L1); every other layer must agree with them.
|
||||
|
||||
Design principles
|
||||
-----------------
|
||||
1. No hardcoded allowlist. The set of valid attribute keys — including which
|
||||
dotted keys are legitimate resource attributes — is derived dynamically by
|
||||
parsing the repository's own OTel code:
|
||||
* `*SpanNames.h` `namespace attr { ... }` blocks (the underscore/bare keys
|
||||
and the `join(seg::..., ...)` dotted resource compositions), and
|
||||
* the keys the code passes to `Resource::Create({ ... })` in Telemetry.cpp
|
||||
(the standard `semconv::service::*` keys -> service.name/version/...).
|
||||
The one narrow, explicit exception is EXTERNAL_INFRA_LABELS (Rule D):
|
||||
identity labels stamped by infrastructure outside this repo's OTel code
|
||||
(the perf-iac harness), which by definition have no source in-tree to
|
||||
derive from. Kept separate from the generic Prometheus/Grafana builtins
|
||||
set so the exception stays visible rather than blending into "things
|
||||
every OTel setup has".
|
||||
|
||||
2. Presence-gated enforcement. Every rule runs ONLY when the source files it
|
||||
needs are present in the tree, and is otherwise skipped (never failed). This
|
||||
keeps the check correct no matter how work is split across PRs: a stacked
|
||||
chain, one large PR, or independent per-stage PRs where (for example) the
|
||||
collector config lands in a different PR than the dashboards. The check never
|
||||
assumes a file from another phase/PR exists.
|
||||
|
||||
Layers
|
||||
------
|
||||
L1 code : src/**/*SpanNames.h, include/**/*SpanNames.h (ground truth)
|
||||
L1 resource : src/libxrpl/telemetry/Telemetry.cpp (dotted allowlist)
|
||||
L1 callsites : setAttribute/addEvent/span/rootSpan/childSpan in src/**,
|
||||
include/**
|
||||
L2 collector : docker/telemetry/otel-collector-config.yaml (spanmetrics dims)
|
||||
L3 tempo : docker/telemetry/tempo.yaml (span filter tags)
|
||||
L4 dashboards: docker/telemetry/grafana/dashboards/*.json (PromQL labels)
|
||||
L5 runbook : docs/telemetry-runbook.md (attr tables)
|
||||
L6 metrics : MetricsRegistry.cpp instrument labels (native-metric
|
||||
label keys, a valid dashboard-label source besides L1)
|
||||
|
||||
Rules (each FAILS the build, when its inputs are present)
|
||||
---------------------------------------------------------
|
||||
A No stray dotted span-attribute key. A dotted `<a>.<b>` used as a span
|
||||
attribute that is not in the derived resource-key set is a violation.
|
||||
G Attribute keys must be lower_snake_case (^[a-z][a-z0-9_]*$ per segment).
|
||||
Flags camelCase, UPPERCASE, spaces, and other stray characters.
|
||||
F No string literals as attribute keys or span-name arguments. The
|
||||
setAttribute/addEvent key and the span/rootSpan/childSpan prefix/name args
|
||||
must reference a *SpanNames.h constant, never a "literal". Attribute VALUES
|
||||
are exempt (runtime data). Definitions inside *SpanNames.h are exempt, and
|
||||
test files are exempt (they pass arbitrary literals to exercise the API).
|
||||
B Every collector spanmetrics dimension exists in the L1 key set.
|
||||
C Every tempo span-filter tag exists in the L1 key set.
|
||||
D Every dashboard label resolves to an L1 span attribute, an L6
|
||||
native-metric label, or a builtin. TraceQL `span.`/`resource.` scope
|
||||
prefixes are stripped before the L1 lookup.
|
||||
E No dotted `xrpl.<domain>.<field>` attribute key in the runbook (only the
|
||||
L1 resource attrs xrpl.network.* may be dotted). Span names, filenames,
|
||||
OTel-standard keys, and metric labels are not flagged.
|
||||
|
||||
Warnings (printed, but do NOT fail the build)
|
||||
----------------------------------------------
|
||||
H A constant referenced at a telemetry call-site is not defined in any
|
||||
*SpanNames.h. Span constants should live in the corresponding
|
||||
*SpanNames.h (single source of truth); defining one in-place bypasses the
|
||||
naming rules. A warning (not a failure) because the argument may instead
|
||||
be a legitimately dynamic local (e.g. a computed span-name leaf).
|
||||
|
||||
Exit code is non-zero if any present-and-enforced rule finds a violation.
|
||||
Warnings never change the exit code.
|
||||
"""
|
||||
|
||||
import re
|
||||
import subprocess
|
||||
import sys
|
||||
from pathlib import Path
|
||||
from typing import Dict, List, Optional, Set, Tuple
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Repo location
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
def repo_root() -> Path:
|
||||
"""Return the repository root, so the script works from any CWD.
|
||||
|
||||
Exits with a readable message (not a traceback) if git is unavailable or the
|
||||
CWD is outside a repository."""
|
||||
try:
|
||||
out = subprocess.run(
|
||||
["git", "rev-parse", "--show-toplevel"],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
check=True,
|
||||
)
|
||||
except (subprocess.CalledProcessError, FileNotFoundError):
|
||||
print(
|
||||
"error: check_otel_naming.py must be run inside the git repository.",
|
||||
file=sys.stderr,
|
||||
)
|
||||
sys.exit(2)
|
||||
return Path(out.stdout.strip())
|
||||
|
||||
|
||||
def read_source(path: Path) -> str:
|
||||
"""Read a file as UTF-8, tolerating stray non-UTF-8 bytes rather than
|
||||
crashing the whole check on one bad byte."""
|
||||
return path.read_text(encoding="utf-8", errors="ignore")
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Regexes (compiled once)
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
# A segment/string constant definition: `inline constexpr auto NAME = <expr>;`
|
||||
CONST_DEF = re.compile(r"inline\s+constexpr\s+auto\s+(\w+)\s*=\s*(.+?);", re.DOTALL)
|
||||
MAKESTR = re.compile(r'makeStr\(\s*"([^"]*)"\s*\)')
|
||||
# A `namespace <name> {` opener, to track which namespace a constant lives in.
|
||||
NS_OPEN = re.compile(r"namespace\s+([\w:]+)\s*\{")
|
||||
# A `using ::a::b::field;` re-export inside an attr block; captures the leaf.
|
||||
USING_DECL = re.compile(r"using\s+(?:::)?[\w:]*::(\w+)\s*;")
|
||||
# Telemetry call-sites whose string arguments must be constants, not literals.
|
||||
# Require a receiver so we match real SpanGuard calls, not std::span / a math
|
||||
# `span(...)` / a bare method declaration:
|
||||
# - `SpanGuard::span(` / `SpanGuard::rootSpan(` / `SpanGuard::childSpan(`
|
||||
# (static factories)
|
||||
# - `<obj>.span(` / `<obj>->setAttribute(` etc. (member call)
|
||||
# `span`/`rootSpan`/`childSpan` additionally require the `SpanGuard`/`.`/`->`
|
||||
# receiver; `setAttribute`/`addEvent` only ever exist on a guard, so a `.`/`->`
|
||||
# suffices. `rootSpan` shares `span`'s (cat, prefix, name) signature.
|
||||
CALLSITE = re.compile(
|
||||
r"(?:SpanGuard::|\.|->)\s*(setAttribute|addEvent|span|rootSpan|childSpan)\s*\("
|
||||
)
|
||||
# A C++ string literal (used to flag literals inside call-site argument lists).
|
||||
STRING_LITERAL = re.compile(r'"((?:[^"\\]|\\.)*)"')
|
||||
# A C++ line comment (`//` ... end of line) and a block comment (`/* ... */`).
|
||||
LINE_COMMENT = re.compile(r"//[^\n]*")
|
||||
BLOCK_COMMENT = re.compile(r"/\*.*?\*/", re.DOTALL)
|
||||
# A TraceQL scope prefix on a label (`span.`, `resource.`, `event.`, etc.).
|
||||
# Dashboards reference span attributes in TraceQL as `span.<attr>`; the bare
|
||||
# attribute is what must exist in L1, so strip the scope before validating.
|
||||
TRACEQL_SCOPE = re.compile(r"^(?:span|resource|event|link|instrumentation_scope)\.")
|
||||
# An OTel metric label key as emitted in C++: `Add(.., {{"label", ...}})` /
|
||||
# `{{"label", value}}` instrument calls in MetricsRegistry.
|
||||
METRIC_LABEL = re.compile(r'\{\{\s*"([a-z_][a-z0-9_]*)"\s*,')
|
||||
|
||||
|
||||
def strip_comments(text: str) -> str:
|
||||
"""Remove C/C++ `//` line comments and `/* ... */` block comments.
|
||||
|
||||
Used only for L1 attribute-key extraction so that a commented-out or
|
||||
illustrative `makeStr("...")` inside a `namespace attr` block does not leak
|
||||
into the authoritative key set. Rule F deliberately does NOT strip comments
|
||||
— it must still see `@code` doc-comment examples so their call-site
|
||||
arguments are held to the constant-only convention.
|
||||
|
||||
String literals are not specially handled; a `//` or `/*` appearing inside a
|
||||
string is vanishingly rare in the *SpanNames.h headers and would at worst
|
||||
drop a constant from L1 (a conservative direction).
|
||||
"""
|
||||
text = BLOCK_COMMENT.sub("", text)
|
||||
text = LINE_COMMENT.sub("", text)
|
||||
return text
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# L1: parse *SpanNames.h into the authoritative key set
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
def find_spanname_headers(root: Path) -> List[Path]:
|
||||
return sorted(
|
||||
p
|
||||
for p in list((root / "src").rglob("*SpanNames.h"))
|
||||
+ list((root / "include").rglob("*SpanNames.h"))
|
||||
if p.is_file()
|
||||
)
|
||||
|
||||
|
||||
def resolve_constants(
|
||||
text: str, symbols: Optional[Dict[str, str]] = None
|
||||
) -> Dict[str, str]:
|
||||
"""Resolve `inline constexpr auto NAME = <makeStr/join expr>` to strings.
|
||||
|
||||
Supports the small constexpr DSL used by SpanNames.h:
|
||||
makeStr("x") -> "x"
|
||||
join(a, b) -> resolve(a) + "." + resolve(b)
|
||||
seg::xrpl / attr::foo -> looked up in the symbol table
|
||||
The optional `symbols` argument seeds (and is updated in place with) the
|
||||
table, so a global pass over ALL *SpanNames.h headers can resolve
|
||||
cross-file references such as `join(seg::rpc, ...)` where `seg::rpc` is
|
||||
defined in the base SpanNames.h. Keys are stored by their bare name
|
||||
(last `::` component), so `seg::rpc` and `rpc` both resolve.
|
||||
"""
|
||||
if symbols is None:
|
||||
symbols = {}
|
||||
|
||||
def resolve_expr(expr: str) -> Optional[str]:
|
||||
expr = expr.strip()
|
||||
m = MAKESTR.fullmatch(expr)
|
||||
if m:
|
||||
return m.group(1)
|
||||
if expr.startswith("join(") and expr.endswith(")"):
|
||||
args = split_top_level_args(expr[len("join(") : -1])
|
||||
parts = [resolve_expr(a) for a in args]
|
||||
if any(p is None for p in parts):
|
||||
return None
|
||||
return ".".join(p for p in parts if p is not None)
|
||||
# Bare or qualified symbol reference, e.g. `seg::xrpl` or `networkId`.
|
||||
key = expr.split("::")[-1]
|
||||
return symbols.get(key, symbols.get(expr))
|
||||
|
||||
# Iterate definitions in source order so earlier symbols are available.
|
||||
for m in CONST_DEF.finditer(text):
|
||||
name, expr = m.group(1), m.group(2)
|
||||
val = resolve_expr(expr)
|
||||
if val is not None:
|
||||
symbols[name] = val
|
||||
return symbols
|
||||
|
||||
|
||||
def build_global_symbols(headers: List[Path]) -> Dict[str, str]:
|
||||
"""Resolve constants across ALL headers so cross-file `seg::`/`join`
|
||||
references (e.g. `join(seg::rpc, ...)` in RpcSpanNames.h, where `seg::rpc`
|
||||
lives in the base SpanNames.h) resolve. Base SpanNames.h is processed
|
||||
first so its `seg::` segments seed the table."""
|
||||
symbols: Dict[str, str] = {}
|
||||
ordered = sorted(headers, key=lambda p: (p.name != "SpanNames.h", str(p)))
|
||||
# Two passes: the first seeds segments, the second resolves dependents.
|
||||
# Comments are stripped so a commented-out constant cannot seed the table.
|
||||
for _ in range(2):
|
||||
for h in ordered:
|
||||
resolve_constants(strip_comments(read_source(h)), symbols)
|
||||
return symbols
|
||||
|
||||
|
||||
def split_top_level_args(s: str) -> List[str]:
|
||||
"""Split a comma-separated arg list, respecting nested parentheses and
|
||||
ignoring parens/commas that appear inside a "string literal" (so a value
|
||||
like `setAttribute(k, ",")` does not get mis-split)."""
|
||||
args, depth, cur = [], 0, ""
|
||||
in_str = False
|
||||
escaped = False
|
||||
for ch in s:
|
||||
if in_str:
|
||||
cur += ch
|
||||
if escaped:
|
||||
escaped = False
|
||||
elif ch == "\\":
|
||||
escaped = True
|
||||
elif ch == '"':
|
||||
in_str = False
|
||||
continue
|
||||
if ch == '"':
|
||||
in_str = True
|
||||
cur += ch
|
||||
elif ch == "(":
|
||||
depth += 1
|
||||
cur += ch
|
||||
elif ch == ")":
|
||||
depth -= 1
|
||||
cur += ch
|
||||
elif ch == "," and depth == 0:
|
||||
args.append(cur)
|
||||
cur = ""
|
||||
else:
|
||||
cur += ch
|
||||
if cur.strip():
|
||||
args.append(cur)
|
||||
return args
|
||||
|
||||
|
||||
def attr_namespace_spans(text: str) -> List[str]:
|
||||
"""Return the source text of each `namespace attr { ... }` block in `text`.
|
||||
|
||||
Brace-matched over the whole (comment-stripped) text, so a definition that
|
||||
wraps across several physical lines is contained in one span. Nested braces
|
||||
inside the block are balanced correctly."""
|
||||
spans: List[str] = []
|
||||
for opener in NS_OPEN.finditer(text):
|
||||
if opener.group(1).split("::")[-1] != "attr":
|
||||
continue
|
||||
# Walk from the opening brace, balancing nesting to the matching close.
|
||||
i = opener.end() # one char past the namespace's `{`
|
||||
depth = 1
|
||||
start = i
|
||||
while i < len(text) and depth > 0:
|
||||
c = text[i]
|
||||
if c == "{":
|
||||
depth += 1
|
||||
elif c == "}":
|
||||
depth -= 1
|
||||
i += 1
|
||||
spans.append(text[start : i - 1])
|
||||
return spans
|
||||
|
||||
|
||||
def attr_keys_from_header(path: Path, symbols: Dict[str, str]) -> Set[str]:
|
||||
"""Return the set of attribute-key strings declared in a header's
|
||||
`namespace attr { ... }` block(s). `symbols` is the global cross-file
|
||||
table, used ONLY to seed `seg::`/segment references for `join(...)`
|
||||
resolution — never to look up an attr constant's value.
|
||||
|
||||
A constant DEFINED in this header is resolved against this header's OWN
|
||||
text, so two headers that each define a same-named constant (e.g. the base
|
||||
`attr::ledgerHash = xrpl.ledger.hash` and consensus
|
||||
`attr::ledgerHash = ledger_hash`) each report their real wire key. The
|
||||
global table is keyed by bare name and would otherwise let a later header
|
||||
clobber an earlier one, erasing the real key from L1 (a Rule-A blind spot).
|
||||
A `using`-re-export, by contrast, imports a constant defined elsewhere, so
|
||||
it is resolved against the global table.
|
||||
|
||||
Comments are stripped first (a commented constant must not enter L1), and
|
||||
each attr block is brace-matched over the whole text so multi-line
|
||||
`inline constexpr auto NAME = join(\\n ...);` definitions are captured."""
|
||||
text = strip_comments(read_source(path))
|
||||
# Local table: the global segments/symbols seed cross-file `join` parts,
|
||||
# then this header's own definitions overwrite any same-named global entry
|
||||
# so a locally-defined attr resolves to ITS value, not another header's.
|
||||
local = dict(symbols)
|
||||
resolve_constants(text, local)
|
||||
keys: Set[str] = set()
|
||||
for block in attr_namespace_spans(text):
|
||||
for md in CONST_DEF.finditer(block):
|
||||
# Resolve a locally-defined constant against the LOCAL table; this
|
||||
# captures makeStr("x") and join(seg::y, ...) with the header's own
|
||||
# value, immune to cross-header bare-name collisions.
|
||||
val = local.get(md.group(1))
|
||||
if val is not None:
|
||||
keys.add(val)
|
||||
# `using ::ns::attr::field;` re-exports a constant defined in ANOTHER
|
||||
# header (e.g. PeerSpanNames imports the base ledgerHash). Resolve the
|
||||
# imported name against the global table.
|
||||
for um in USING_DECL.finditer(block):
|
||||
val = symbols.get(um.group(1))
|
||||
if val is not None:
|
||||
keys.add(val)
|
||||
return keys
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Reporting
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
class Report:
|
||||
def __init__(self) -> None:
|
||||
self.violations: List[Tuple[str, str, str, str]] = []
|
||||
self.warnings: List[Tuple[str, str, str, str]] = []
|
||||
self.skips: List[str] = []
|
||||
self.checked: List[str] = []
|
||||
|
||||
def violation(self, rule: str, loc: str, token: str, expected: str) -> None:
|
||||
self.violations.append((rule, loc, token, expected))
|
||||
|
||||
def warning(self, rule: str, loc: str, token: str, note: str) -> None:
|
||||
"""A non-fatal finding: printed, but does not fail the build. Used where
|
||||
the script cannot be certain a finding is wrong (e.g. a constant used at
|
||||
a call-site that is not defined in any *SpanNames.h — it might be a
|
||||
misplaced constant, or a legitimately dynamic value)."""
|
||||
self.warnings.append((rule, loc, token, note))
|
||||
|
||||
def skip(self, rule: str, reason: str) -> None:
|
||||
self.skips.append(f"SKIP: {rule} — {reason}")
|
||||
|
||||
def ok(self, msg: str) -> None:
|
||||
self.checked.append(f"OK: {msg}")
|
||||
|
||||
def render_and_exit(self) -> None:
|
||||
for line in self.skips:
|
||||
print(line)
|
||||
for line in self.checked:
|
||||
print(line)
|
||||
if self.warnings:
|
||||
print("\nNaming-convention warnings (non-fatal):\n")
|
||||
print(f" {'RULE':<5} {'LOCATION':<48} {'TOKEN':<28} NOTE")
|
||||
print(f" {'-' * 5} {'-' * 48} {'-' * 28} {'-' * 30}")
|
||||
for rule, loc, token, note in self.warnings:
|
||||
print(f" {rule:<5} {loc:<48} {token:<28} {note}")
|
||||
if self.violations:
|
||||
print("\nNaming-convention violations:\n")
|
||||
print(f" {'RULE':<5} {'LOCATION':<48} {'TOKEN':<28} EXPECTED")
|
||||
print(f" {'-' * 5} {'-' * 48} {'-' * 28} {'-' * 30}")
|
||||
for rule, loc, token, expected in self.violations:
|
||||
print(f" {rule:<5} {loc:<48} {token:<28} {expected}")
|
||||
print(
|
||||
"\nSee CONTRIBUTING.md -> 'Telemetry span attribute naming'. "
|
||||
"The *SpanNames.h constants are the single source of truth."
|
||||
)
|
||||
sys.exit(1)
|
||||
print("\nAll present telemetry naming layers are consistent.")
|
||||
sys.exit(0)
|
||||
|
||||
|
||||
def main() -> None:
|
||||
root = repo_root()
|
||||
report = Report()
|
||||
|
||||
# --- Build the L1 ground-truth key set (presence-gated) ----------------
|
||||
headers = find_spanname_headers(root)
|
||||
l1_keys: Set[str] = set()
|
||||
if headers:
|
||||
symbols = build_global_symbols(headers)
|
||||
# Map each key to the header(s) that declare it, so Rule A can tell a
|
||||
# legitimate resource attr (declared in the base SpanNames.h) from a
|
||||
# stray dotted key declared in a domain header.
|
||||
keys_by_header: Dict[Path, Set[str]] = {}
|
||||
for h in headers:
|
||||
hk = attr_keys_from_header(h, symbols)
|
||||
keys_by_header[h] = hk
|
||||
l1_keys |= hk
|
||||
report.ok(
|
||||
f"L1: {len(l1_keys)} attribute keys from {len(headers)} "
|
||||
f"*SpanNames.h header(s)"
|
||||
)
|
||||
else:
|
||||
report.skip("L1", "no *SpanNames.h present (not a naming-relevant tree)")
|
||||
keys_by_header = {}
|
||||
|
||||
# --- Derive the legitimate dotted (resource) keys dynamically ----------
|
||||
# ONLY the keys actually passed to Resource::Create() in Telemetry.cpp
|
||||
# (semconv service.* + the attr:: constants set there, e.g. xrpl.network.*).
|
||||
# A dotted key declared in a header but NOT set as a resource attr is a
|
||||
# Rule-A violation, not an allowlist entry.
|
||||
resource_symbols = symbols if headers else {}
|
||||
dotted_allow = derive_dotted_resource_keys(root, resource_symbols, report)
|
||||
|
||||
# --- Rule A: no stray dotted span-attribute keys -----------------------
|
||||
if l1_keys:
|
||||
run_rule_a(keys_by_header, dotted_allow, report)
|
||||
# --- Rule G: keys must be lower_snake_case -----------------------------
|
||||
if l1_keys:
|
||||
run_rule_g(keys_by_header, report)
|
||||
# --- Rule F (+ Rule H): scan telemetry call-sites ----------------------
|
||||
# Runs UNCONDITIONALLY: Rule F is a purely syntactic check (is this argument
|
||||
# a literal?) and does not need the L1 key set, so a code path that uses
|
||||
# SpanGuard::span/setAttribute directly without ever defining a *SpanNames.h
|
||||
# is still caught. Rule H (warning) additionally flags constant references
|
||||
# not defined in any *SpanNames.h.
|
||||
header_symbols = spanname_symbol_names(headers)
|
||||
run_rule_f(root, report, header_symbols)
|
||||
|
||||
# --- Cross-layer rules B/C/D/E (each presence-gated) -------------------
|
||||
# L6 native-metric labels: span attributes are not the only valid dashboard
|
||||
# labels — the MetricsRegistry emits OTel metrics whose label keys are an
|
||||
# additional source of truth. Derive them dynamically (same principle as L1)
|
||||
# so dashboards may reference them without tripping Rule D.
|
||||
metric_labels = metric_label_names(root)
|
||||
run_rule_b_collector(root, l1_keys, report)
|
||||
run_rule_c_tempo(root, l1_keys, report)
|
||||
run_rule_d_dashboards(root, l1_keys, metric_labels, report)
|
||||
run_rule_e_runbook(root, l1_keys, report)
|
||||
|
||||
report.render_and_exit()
|
||||
|
||||
|
||||
def resource_create_block(text: str) -> str:
|
||||
"""Return the text inside the first `Resource::Create({ ... })` argument
|
||||
list, brace-matched so nested `{key, value}` initializers are contained.
|
||||
Empty string if the call is absent."""
|
||||
m = re.search(r"Resource::Create\(\s*\{", text)
|
||||
if not m:
|
||||
return ""
|
||||
i = m.end() # one char past the opening `{`
|
||||
depth, start = 1, i
|
||||
while i < len(text) and depth > 0:
|
||||
c = text[i]
|
||||
if c == "{":
|
||||
depth += 1
|
||||
elif c == "}":
|
||||
depth -= 1
|
||||
i += 1
|
||||
return text[start : i - 1]
|
||||
|
||||
|
||||
def derive_dotted_resource_keys(
|
||||
root: Path, symbols: Dict[str, str], report: Report
|
||||
) -> Set[str]:
|
||||
"""Legitimate dotted keys = ONLY the keys the code actually sets as RESOURCE
|
||||
attributes, i.e. the entries inside Telemetry.cpp's `Resource::Create({...})`
|
||||
call: the standard semconv keys (`service.*`) plus any `attr::<name>`
|
||||
constants passed there (resolved to their wire key via the global symbol
|
||||
table, e.g. `attr::networkId` -> `xrpl.network.id`).
|
||||
|
||||
A dotted key DECLARED in a `*SpanNames.h` header but NOT passed to
|
||||
Resource::Create() is a span attribute wearing the resource form — a Rule-A
|
||||
violation, never allowlisted. Deriving the allowlist from the actual
|
||||
resource call (not from "any dotted key in the base header") is what lets
|
||||
Rule A catch a stray dotted span attr such as `xrpl.ledger.hash`."""
|
||||
allow: Set[str] = set()
|
||||
tele = root / "src" / "libxrpl" / "telemetry" / "Telemetry.cpp"
|
||||
if not tele.is_file():
|
||||
report.skip("resource-derive", "Telemetry.cpp not present")
|
||||
return allow
|
||||
block = resource_create_block(read_source(tele))
|
||||
# semconv::<group>::k<CamelKey> -> the dotted OTel-standard key. The
|
||||
# CamelKey already embeds the group, e.g. service::kServiceInstanceId
|
||||
# -> service.instance.id. Split the CamelCase name into dotted lowercase
|
||||
# segments; if it does not lead with the group, prepend the group.
|
||||
for m in re.finditer(r"semconv::(\w+)::k(\w+)", block):
|
||||
group, camel = m.group(1), m.group(2)
|
||||
segments = camel_to_dotsegments(camel)
|
||||
if segments and segments[0] == group:
|
||||
allow.add(".".join(segments))
|
||||
else:
|
||||
allow.add(group + "." + ".".join(segments))
|
||||
# attr::<name> constants set as resource attrs (e.g. networkId/networkType);
|
||||
# resolve each to its wire key and allowlist only the dotted ones.
|
||||
for m in re.finditer(r"attr::(\w+)", block):
|
||||
val = symbols.get(m.group(1))
|
||||
if val is not None and "." in val:
|
||||
allow.add(val)
|
||||
report.ok(f"resource dotted-key allowlist derived: {sorted(allow)}")
|
||||
return allow
|
||||
|
||||
|
||||
def camel_to_dotsegments(s: str) -> List[str]:
|
||||
"""Split a CamelCase identifier into lowercase dot-segment parts, e.g.
|
||||
`ServiceInstanceId` -> ['service', 'instance', 'id']."""
|
||||
return [w.lower() for w in re.findall(r"[A-Z][a-z0-9]*", s)]
|
||||
|
||||
|
||||
def run_rule_a(
|
||||
keys_by_header: Dict[Path, Set[str]], dotted_allow: Set[str], report: Report
|
||||
) -> None:
|
||||
"""Any dotted attribute key that is not an allowed resource key is a
|
||||
violation, reported against the header that declares it."""
|
||||
found = False
|
||||
for h in sorted(keys_by_header):
|
||||
for key in sorted(keys_by_header[h]):
|
||||
if "." in key and key not in dotted_allow:
|
||||
found = True
|
||||
report.violation("A", h.name, key, "underscore form, not dotted")
|
||||
if not found:
|
||||
report.ok("A: no stray dotted span-attribute keys")
|
||||
|
||||
|
||||
# A lower_snake_case identifier segment: starts lowercase, then lowercase /
|
||||
# digits / underscores. No uppercase, no spaces, no camelCase.
|
||||
SNAKE_SEGMENT = re.compile(r"^[a-z][a-z0-9_]*$")
|
||||
|
||||
|
||||
def run_rule_g(keys_by_header: Dict[Path, Set[str]], report: Report) -> None:
|
||||
"""Every attribute key must be lower_snake_case. Bare/underscore keys must
|
||||
match ^[a-z][a-z0-9_]*$; dotted resource keys must be lowercase
|
||||
dot-separated segments (each segment lower_snake_case). Flags camelCase,
|
||||
UPPERCASE, spaces, and other stray characters."""
|
||||
found = False
|
||||
for h in sorted(keys_by_header):
|
||||
for key in sorted(keys_by_header[h]):
|
||||
segments = key.split(".")
|
||||
if all(SNAKE_SEGMENT.match(seg) for seg in segments):
|
||||
continue
|
||||
found = True
|
||||
report.violation("G", h.name, key, "must be lower_snake_case")
|
||||
if not found:
|
||||
report.ok("G: all attribute keys are lower_snake_case")
|
||||
|
||||
|
||||
# Which argument positions of each call must be a constant (0-based). The
|
||||
# attribute VALUE position is intentionally absent: values are runtime data
|
||||
# (command names, hashes, counts), not naming-convention surface.
|
||||
# setAttribute(key, value) -> check arg 0 (key); value (arg 1) exempt
|
||||
# addEvent(name[, attrs]) -> check arg 0 (event name)
|
||||
# span(category, prefix, name) -> check args 1,2 (prefix + span-name leaf)
|
||||
# rootSpan(category, prefix, name)-> check args 1,2 (same signature as span)
|
||||
# childSpan(name[, parentCtx]) -> check arg 0 (span-name leaf)
|
||||
CONSTANT_ARG_POSITIONS: Dict[str, Set[int]] = {
|
||||
"setAttribute": {0},
|
||||
"addEvent": {0},
|
||||
"span": {1, 2},
|
||||
"rootSpan": {1, 2}, # same signature as span(cat, prefix, name)
|
||||
"childSpan": {0},
|
||||
}
|
||||
|
||||
|
||||
def is_test_path(path: Path) -> bool:
|
||||
"""True if the path is test code. Tests legitimately pass arbitrary literal
|
||||
keys/names to exercise the API mechanics, so Rule F does not apply to them.
|
||||
Matches a `test`/`tests` directory anywhere in the path (e.g. src/test/,
|
||||
src/tests/, .../detail/tests/)."""
|
||||
return any(part in ("test", "tests") for part in path.parts)
|
||||
|
||||
|
||||
# A constant reference passed at a call-site, e.g. `rpc_span::attr::command`
|
||||
# or a bare `myKey`. We capture the leaf identifier (after the last `::`).
|
||||
IDENTIFIER_ARG = re.compile(r"^[\s&*]*([A-Za-z_][\w:]*)\s*$")
|
||||
|
||||
|
||||
def spanname_symbol_names(headers: List[Path]) -> Set[str]:
|
||||
"""Every `inline constexpr auto NAME = ...;` symbol defined across the
|
||||
*SpanNames.h headers, by bare name. Used by Rule H to tell whether a
|
||||
constant referenced at a call-site actually lives in a SpanNames header."""
|
||||
names: Set[str] = set()
|
||||
for h in headers:
|
||||
for m in CONST_DEF.finditer(strip_comments(read_source(h))):
|
||||
names.add(m.group(1))
|
||||
return names
|
||||
|
||||
|
||||
def run_rule_f(root: Path, report: Report, header_symbols: Set[str]) -> None:
|
||||
"""Walk every telemetry call-site (non-test, non-*SpanNames.h) and check the
|
||||
constant-only argument positions of
|
||||
setAttribute/addEvent/span/rootSpan/childSpan:
|
||||
|
||||
Rule F (FAIL): a string literal in a key / span-name position. Attribute
|
||||
VALUES are exempt (runtime data).
|
||||
Rule H (WARN): a constant reference whose name is not defined in any
|
||||
*SpanNames.h. The constant should live in the corresponding
|
||||
*SpanNames.h (single source of truth); defining it in-place bypasses
|
||||
the naming rules. Warn rather than fail — the argument may instead be a
|
||||
legitimately dynamic local (e.g. a computed span-name leaf)."""
|
||||
found_f = False
|
||||
sources = [
|
||||
p
|
||||
for base in ("src", "include")
|
||||
for ext in ("*.h", "*.cpp")
|
||||
for p in (root / base).rglob(ext)
|
||||
if p.is_file()
|
||||
]
|
||||
for path in sorted(sources):
|
||||
if path.name.endswith("SpanNames.h") or is_test_path(path):
|
||||
continue
|
||||
text = read_source(path)
|
||||
rel = path.relative_to(root)
|
||||
for call, arglist, lineno in iter_calls(text):
|
||||
positions = CONSTANT_ARG_POSITIONS.get(call, set())
|
||||
args = split_top_level_args(arglist)
|
||||
for idx in positions:
|
||||
if idx >= len(args):
|
||||
continue
|
||||
arg = args[idx]
|
||||
lit = STRING_LITERAL.search(arg)
|
||||
if lit:
|
||||
found_f = True
|
||||
report.violation(
|
||||
"F",
|
||||
f"{rel}:{lineno}",
|
||||
f'{call} arg{idx} "{lit.group(1)}"',
|
||||
"use a *SpanNames.h constant",
|
||||
)
|
||||
continue
|
||||
# Not a literal: Rule H warns when a NAMESPACE-QUALIFIED constant
|
||||
# reference (e.g. `consensus::span::accept`) is not defined in
|
||||
# any *SpanNames.h — i.e. the constant was defined in-place
|
||||
# instead of in the proper header. We only consider qualified
|
||||
# refs (containing `::`): a bare lowercase identifier is almost
|
||||
# always a legitimately dynamic local (a computed span-name leaf
|
||||
# or attribute value), not a misplaced constant, so warning on it
|
||||
# would be noise. Standard-library types (std::...) are skipped.
|
||||
ident = IDENTIFIER_ARG.match(arg)
|
||||
if not (ident and header_symbols):
|
||||
continue
|
||||
ref = ident.group(1)
|
||||
if "::" not in ref or ref.startswith("std::"):
|
||||
continue
|
||||
leaf = ref.split("::")[-1]
|
||||
if leaf not in header_symbols:
|
||||
report.warning(
|
||||
"H",
|
||||
f"{rel}:{lineno}",
|
||||
f"{call} arg{idx} {ref}",
|
||||
"not defined in any *SpanNames.h",
|
||||
)
|
||||
if not found_f:
|
||||
report.ok("F: no string-literal keys/names at telemetry call-sites")
|
||||
|
||||
|
||||
def iter_calls(text: str):
|
||||
"""Yield (call_name, raw_arglist, lineno) for each setAttribute/addEvent/
|
||||
span/rootSpan/childSpan invocation, spanning multiple physical lines if
|
||||
needed."""
|
||||
for m in CALLSITE.finditer(text):
|
||||
name = m.group(1)
|
||||
# Walk from the opening paren, balancing nesting to find the close.
|
||||
# Parens inside a "string literal" are ignored so a value such as
|
||||
# `setAttribute(k, ")")` does not close the call early.
|
||||
i = m.end() # one char past the '('
|
||||
depth = 1
|
||||
in_str = False
|
||||
escaped = False
|
||||
while i < len(text) and depth > 0:
|
||||
c = text[i]
|
||||
if in_str:
|
||||
if escaped:
|
||||
escaped = False
|
||||
elif c == "\\":
|
||||
escaped = True
|
||||
elif c == '"':
|
||||
in_str = False
|
||||
elif c == '"':
|
||||
in_str = True
|
||||
elif c == "(":
|
||||
depth += 1
|
||||
elif c == ")":
|
||||
depth -= 1
|
||||
i += 1
|
||||
arglist = text[m.end() : i - 1]
|
||||
lineno = text.count("\n", 0, m.start()) + 1
|
||||
yield name, arglist, lineno
|
||||
|
||||
|
||||
def run_rule_b_collector(root: Path, l1_keys: Set[str], report: Report) -> None:
|
||||
path = root / "docker" / "telemetry" / "otel-collector-config.yaml"
|
||||
if not path.is_file():
|
||||
report.skip("B", "collector config not present")
|
||||
return
|
||||
text = read_source(path)
|
||||
if "spanmetrics" not in text:
|
||||
report.skip("B", "no spanmetrics block in collector config")
|
||||
return
|
||||
dims = extract_spanmetrics_dimensions(text)
|
||||
if not l1_keys:
|
||||
report.skip("B", "no L1 key set to validate against")
|
||||
return
|
||||
miss = [d for d in dims if d not in l1_keys]
|
||||
for d in miss:
|
||||
report.violation("B", str(path.relative_to(root)), d, "must exist in L1")
|
||||
if not miss:
|
||||
report.ok(f"B: {len(dims)} collector dimension(s) all in L1")
|
||||
|
||||
|
||||
def extract_spanmetrics_dimensions(text: str) -> List[str]:
|
||||
dims: List[str] = []
|
||||
in_dims = False
|
||||
for line in text.splitlines():
|
||||
if re.search(r"\bdimensions\s*:", line):
|
||||
in_dims = True
|
||||
continue
|
||||
if in_dims:
|
||||
m = re.search(r"-\s*name\s*:\s*([A-Za-z0-9_.]+)", line)
|
||||
if m:
|
||||
dims.append(m.group(1))
|
||||
elif line.strip() and not line.lstrip().startswith("-") and ":" in line:
|
||||
in_dims = False
|
||||
return dims
|
||||
|
||||
|
||||
def run_rule_c_tempo(root: Path, l1_keys: Set[str], report: Report) -> None:
|
||||
# The trace-search filter tags live in the Grafana Tempo DATASOURCE
|
||||
# provisioning file (search.filters[].{tag,scope}); the Tempo server
|
||||
# tempo.yaml has no such tags. Prefer the datasource file; fall back to the
|
||||
# server file so the rule still does something if the layout changes.
|
||||
candidates = [
|
||||
root / "docker/telemetry/grafana/provisioning/datasources/tempo.yaml",
|
||||
root / "docker/telemetry/tempo.yaml",
|
||||
]
|
||||
path = next((p for p in candidates if p.is_file()), None)
|
||||
if path is None:
|
||||
report.skip("C", "tempo datasource provisioning not present")
|
||||
return
|
||||
if not l1_keys:
|
||||
report.skip("C", "no L1 key set to validate against")
|
||||
return
|
||||
# Pair each filter's `tag:` with its `scope:` (a few lines below it) and
|
||||
# validate only span-scope tags — resource/intrinsic tags (service.*, name,
|
||||
# status, duration) are not span attributes. Strip a TraceQL span. prefix.
|
||||
lines = read_source(path).splitlines()
|
||||
span_tags: List[str] = []
|
||||
for i, line in enumerate(lines):
|
||||
m = re.search(r"^\s*tag:\s*(\S+)", line)
|
||||
if not m:
|
||||
continue
|
||||
scope = next(
|
||||
(
|
||||
sm.group(1)
|
||||
for j in range(i, min(i + 4, len(lines)))
|
||||
for sm in [re.search(r"scope:\s*(\S+)", lines[j])]
|
||||
if sm
|
||||
),
|
||||
"",
|
||||
)
|
||||
if scope == "span":
|
||||
span_tags.append(TRACEQL_SCOPE.sub("", m.group(1)))
|
||||
if not span_tags:
|
||||
report.skip("C", "no span-scope filter tags in tempo datasource")
|
||||
return
|
||||
miss = [t for t in span_tags if t not in l1_keys]
|
||||
for t in sorted(set(miss)):
|
||||
report.violation("C", str(path.relative_to(root)), t, "must exist in L1")
|
||||
if not miss:
|
||||
report.ok(f"C: {len(span_tags)} tempo span-filter tag(s) all in L1")
|
||||
|
||||
|
||||
def metric_label_names(root: Path) -> Set[str]:
|
||||
"""L6: OTel native-metric label keys emitted by the telemetry code, e.g.
|
||||
`counter->Add(1, {{"job_type", value}})` in MetricsRegistry.cpp. These are
|
||||
a valid source of dashboard labels distinct from span attributes (L1)."""
|
||||
labels: Set[str] = set()
|
||||
for base in ("src", "include"):
|
||||
for p in (root / base).rglob("*.cpp"):
|
||||
if not p.is_file():
|
||||
continue
|
||||
text = read_source(p)
|
||||
if "MetricsRegistry" not in p.name and "metric" not in text.lower():
|
||||
continue
|
||||
labels |= set(METRIC_LABEL.findall(text))
|
||||
return labels
|
||||
|
||||
|
||||
# Identity labels stamped by EXTERNAL infrastructure the OTel pipeline in this
|
||||
# repo does not own: the perf-iac harness attaches these to every metric it
|
||||
# scrapes so dashboards can filter by which build/role produced a series. They
|
||||
# have no L1 (*SpanNames.h), L2 (collector config), or L6 (MetricsRegistry.cpp)
|
||||
# source to derive from, so — unlike every other dashboard label — they cannot
|
||||
# be validated dynamically. This is a deliberate, narrow exception to the "no
|
||||
# hardcoded allowlist" design principle, kept separate from the generic
|
||||
# Prometheus/Grafana `builtins` set below so it stays visible and auditable.
|
||||
# Add a label here ONLY if it is genuinely injected by infra outside this
|
||||
# repo's OTel code (never as a workaround for a dashboard querying a label
|
||||
# that nothing actually emits — that is a real Rule D violation).
|
||||
EXTERNAL_INFRA_LABELS = {
|
||||
"xrpl_branch", # perf-iac: git ref of the xrpld build under test
|
||||
"xrpl_node_role", # perf-iac: validator/peer role in the perf cluster
|
||||
}
|
||||
|
||||
|
||||
def run_rule_d_dashboards(
|
||||
root: Path, l1_keys: Set[str], metric_labels: Set[str], report: Report
|
||||
) -> None:
|
||||
dash_dir = root / "docker" / "telemetry" / "grafana" / "dashboards"
|
||||
files = sorted(dash_dir.glob("*.json")) if dash_dir.is_dir() else []
|
||||
if not files:
|
||||
report.skip("D", "no dashboard JSON present")
|
||||
return
|
||||
if not l1_keys:
|
||||
report.skip("D", "no L1 key set to validate against")
|
||||
return
|
||||
builtins = {
|
||||
"__name__", # Prometheus reserved label for the metric name itself
|
||||
"le",
|
||||
"exported_instance",
|
||||
"span_name",
|
||||
"status_code",
|
||||
"service_name",
|
||||
"service_version",
|
||||
"service_instance_id",
|
||||
"job",
|
||||
"instance",
|
||||
}
|
||||
# A dashboard label is valid if it is a span attribute (L1), a native-metric
|
||||
# label (L6), a Prometheus/Grafana builtin, or an external-infra identity
|
||||
# label (EXTERNAL_INFRA_LABELS).
|
||||
valid = l1_keys | metric_labels | builtins | EXTERNAL_INFRA_LABELS
|
||||
found = False
|
||||
for f in files:
|
||||
try:
|
||||
text = read_source(f)
|
||||
except OSError:
|
||||
continue
|
||||
# PromQL `sum by (a, b)` and `{label="..."}` references.
|
||||
labels: Set[str] = set()
|
||||
for m in re.finditer(r"by\s*\(([^)]*)\)", text):
|
||||
labels |= {x.strip() for x in m.group(1).split(",") if x.strip()}
|
||||
for m in re.finditer(r"\b([a-z_][a-z0-9_.]*)\s*[=!]~?\s*\"", text):
|
||||
labels.add(m.group(1))
|
||||
for lbl in sorted(labels):
|
||||
# Strip a TraceQL scope prefix (span./resource./...) — the bare
|
||||
# attribute is what must resolve against L1.
|
||||
bare = TRACEQL_SCOPE.sub("", lbl)
|
||||
if bare in valid:
|
||||
continue
|
||||
found = True
|
||||
report.violation(
|
||||
"D",
|
||||
str(f.relative_to(root)),
|
||||
lbl,
|
||||
"must exist in L1, a metric label, or be a builtin",
|
||||
)
|
||||
if not found:
|
||||
report.ok(f"D: dashboard PromQL labels all resolve ({len(files)} file(s))")
|
||||
|
||||
|
||||
def run_rule_e_runbook(root: Path, l1_keys: Set[str], report: Report) -> None:
|
||||
path = root / "docs" / "telemetry-runbook.md"
|
||||
if not path.is_file():
|
||||
report.skip("E", "runbook not present")
|
||||
return
|
||||
if not l1_keys:
|
||||
report.skip("E", "no L1 key set to validate against")
|
||||
return
|
||||
text = read_source(path)
|
||||
found = False
|
||||
# Only the dotted `xrpl.<domain>.<field>` attribute form is a violation. The
|
||||
# `xrpl.`-with-trailing-dot anchor is the discriminator: it matches the old
|
||||
# dotted attribute convention being migrated away from, while everything
|
||||
# else legitimately dotted in the runbook does NOT match it —
|
||||
# * span names (`consensus.round`, `tx.process`) no `xrpl.` prefix
|
||||
# * filenames (`xrpld.cfg`, `RCLConsensus.cpp`) `xrpld.`/`.cpp`, not `xrpl.`
|
||||
# * OTel-standard (`service.name`, `http.method`) no `xrpl.` prefix
|
||||
# * metric labels (`xrpl_rpc_command`) underscore, no dot
|
||||
# Legitimate dotted resource attrs (`xrpl.network.id`/`.type`) are in L1 and
|
||||
# are skipped. A dotted `xrpl.` token absent from L1 is a genuine doc/code
|
||||
# mismatch (e.g. `xrpl.tx.hash` where the code emits `tx_hash`).
|
||||
for m in re.finditer(r"`(xrpl\.[a-z][a-z0-9_.]*)`", text):
|
||||
token = m.group(1)
|
||||
if token in l1_keys: # legitimate dotted resource attr (xrpl.network.*)
|
||||
continue
|
||||
found = True
|
||||
report.violation(
|
||||
"E", str(path.relative_to(root)), token, "underscore, not dotted"
|
||||
)
|
||||
if not found:
|
||||
report.ok("E: runbook attribute references consistent with L1")
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
927
.github/scripts/otel-naming/test_check_otel_naming.py
vendored
Normal file
927
.github/scripts/otel-naming/test_check_otel_naming.py
vendored
Normal file
@@ -0,0 +1,927 @@
|
||||
#!/usr/bin/env python3
|
||||
|
||||
"""Unit tests for check_otel_naming.py.
|
||||
|
||||
Stdlib-only (unittest), matching the dependency-free policy of the check itself.
|
||||
Run from anywhere:
|
||||
|
||||
python .github/scripts/otel-naming/test_check_otel_naming.py
|
||||
|
||||
Each rule is exercised in isolation against a synthetic tree / synthetic L1 key
|
||||
set, covering positive (must flag), negative (must not flag), and boundary
|
||||
cases. Rule E (runbook dotted-attribute detection) has the densest coverage
|
||||
because its discriminator — the `xrpl.<domain>.` prefix vs span names,
|
||||
filenames, OTel-standard keys, and metric labels — is the subtlest.
|
||||
"""
|
||||
|
||||
import contextlib
|
||||
import importlib.util
|
||||
import io
|
||||
import shutil
|
||||
import tempfile
|
||||
import unittest
|
||||
from pathlib import Path
|
||||
|
||||
# Load the check module by path (it is not an importable package).
|
||||
_spec = importlib.util.spec_from_file_location(
|
||||
"check_otel_naming", str(Path(__file__).with_name("check_otel_naming.py"))
|
||||
)
|
||||
chk = importlib.util.module_from_spec(_spec)
|
||||
_spec.loader.exec_module(chk)
|
||||
|
||||
|
||||
# A controlled L1 set used across tests: the two legitimate dotted resource
|
||||
# attrs plus a handful of underscore span-attribute keys.
|
||||
L1 = {
|
||||
"xrpl.network.id",
|
||||
"xrpl.network.type",
|
||||
"tx_hash",
|
||||
"peer_id",
|
||||
"consensus_mode",
|
||||
"command",
|
||||
"rpc_status",
|
||||
"ledger_seq",
|
||||
}
|
||||
|
||||
|
||||
def _run_rule_e(runbook_text: str):
|
||||
"""Run Rule E against a synthetic runbook; return the flagged tokens."""
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
(d / "docs").mkdir()
|
||||
(d / "docs" / "telemetry-runbook.md").write_text(runbook_text)
|
||||
report = chk.Report()
|
||||
chk.run_rule_e_runbook(d, set(L1), report)
|
||||
return sorted(v[2] for v in report.violations)
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
|
||||
class RuleERunbook(unittest.TestCase):
|
||||
"""Rule E: only dotted `xrpl.<domain>.<field>` attribute keys are flagged."""
|
||||
|
||||
# ----- positive: genuine dotted attribute-key violations -----
|
||||
def test_single_dotted_attr(self):
|
||||
self.assertEqual(_run_rule_e("`xrpl.tx.hash`"), ["xrpl.tx.hash"])
|
||||
|
||||
def test_multiple_dotted_attrs(self):
|
||||
self.assertEqual(
|
||||
_run_rule_e("`xrpl.tx.hash` and `xrpl.consensus.mode`"),
|
||||
["xrpl.consensus.mode", "xrpl.tx.hash"],
|
||||
)
|
||||
|
||||
def test_deep_dotted_three_segments(self):
|
||||
self.assertEqual(
|
||||
_run_rule_e("`xrpl.consensus.ledger.seq`"), ["xrpl.consensus.ledger.seq"]
|
||||
)
|
||||
|
||||
def test_dotted_attr_with_underscore_field(self):
|
||||
self.assertEqual(
|
||||
_run_rule_e("`xrpl.consensus.round_id`"), ["xrpl.consensus.round_id"]
|
||||
)
|
||||
|
||||
def test_repeated_token_reported_each_occurrence(self):
|
||||
self.assertEqual(
|
||||
_run_rule_e("`xrpl.tx.hash` ... `xrpl.tx.hash`"),
|
||||
["xrpl.tx.hash", "xrpl.tx.hash"],
|
||||
)
|
||||
|
||||
def test_resource_attr_not_in_l1_is_flagged(self):
|
||||
self.assertEqual(
|
||||
_run_rule_e("`xrpl.network.unknown`"), ["xrpl.network.unknown"]
|
||||
)
|
||||
|
||||
# ----- negative: legitimately-dotted tokens that must NOT be flagged -----
|
||||
def test_span_name_single(self):
|
||||
self.assertEqual(_run_rule_e("`consensus.round`"), [])
|
||||
|
||||
def test_span_name_multi_segment(self):
|
||||
self.assertEqual(
|
||||
_run_rule_e("`consensus.phase.open` `rpc.command.server_info`"), []
|
||||
)
|
||||
|
||||
def test_filename_cfg(self):
|
||||
self.assertEqual(_run_rule_e("`xrpld.cfg`"), [])
|
||||
|
||||
def test_filename_cpp(self):
|
||||
self.assertEqual(_run_rule_e("`RCLConsensus.cpp`"), [])
|
||||
|
||||
def test_otel_standard_service_name(self):
|
||||
self.assertEqual(_run_rule_e("`service.name`"), [])
|
||||
|
||||
def test_otel_standard_http_method(self):
|
||||
self.assertEqual(_run_rule_e("`http.method`"), [])
|
||||
|
||||
def test_metric_label_underscore(self):
|
||||
self.assertEqual(_run_rule_e("`xrpl_rpc_command`"), [])
|
||||
|
||||
def test_bare_underscore_attrs(self):
|
||||
self.assertEqual(_run_rule_e("`tx_hash` `consensus_mode`"), [])
|
||||
|
||||
def test_legit_dotted_resource_attrs_in_l1(self):
|
||||
self.assertEqual(_run_rule_e("`xrpl.network.id` `xrpl.network.type`"), [])
|
||||
|
||||
def test_prose_word(self):
|
||||
self.assertEqual(_run_rule_e("the `command` attribute"), [])
|
||||
|
||||
def test_plain_prose_no_backticks(self):
|
||||
self.assertEqual(_run_rule_e("xrpl.tx.hash without backticks is prose"), [])
|
||||
|
||||
# ----- boundary -----
|
||||
def test_empty_runbook(self):
|
||||
self.assertEqual(_run_rule_e(""), [])
|
||||
|
||||
def test_lookalike_prefix_xrpld(self):
|
||||
# `xrpld.` is NOT `xrpl.` — must not match.
|
||||
self.assertEqual(_run_rule_e("`xrpld.foo`"), [])
|
||||
|
||||
def test_lookalike_prefix_underscore(self):
|
||||
# `xrpl_rpc.command` starts with `xrpl_`, not `xrpl.`.
|
||||
self.assertEqual(_run_rule_e("`xrpl_rpc.command`"), [])
|
||||
|
||||
def test_uppercase_segment_not_matched(self):
|
||||
# The pattern requires a lowercase char after `xrpl.`; uppercase keys are
|
||||
# caught by Rule G at the L1 layer, not by the runbook text scan.
|
||||
self.assertEqual(_run_rule_e("`xrpl.TX.hash`"), [])
|
||||
|
||||
def test_token_touching_table_pipes(self):
|
||||
self.assertEqual(_run_rule_e("| `xrpl.tx.hash` | desc |"), ["xrpl.tx.hash"])
|
||||
|
||||
def test_mixed_line_only_xrpl_dotted_flagged(self):
|
||||
self.assertEqual(
|
||||
_run_rule_e("`consensus.round` uses `xrpl.tx.hash` and `service.name`"),
|
||||
["xrpl.tx.hash"],
|
||||
)
|
||||
|
||||
def test_skips_when_runbook_absent(self):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
report = chk.Report()
|
||||
chk.run_rule_e_runbook(d, set(L1), report)
|
||||
self.assertEqual(report.violations, [])
|
||||
self.assertTrue(any("SKIP: E" in s for s in report.skips))
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
def test_skips_when_l1_empty(self):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
(d / "docs").mkdir()
|
||||
(d / "docs" / "telemetry-runbook.md").write_text("`xrpl.tx.hash`")
|
||||
report = chk.Report()
|
||||
chk.run_rule_e_runbook(d, set(), report)
|
||||
self.assertEqual(report.violations, [])
|
||||
self.assertTrue(any("SKIP: E" in s for s in report.skips))
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
|
||||
class DslParser(unittest.TestCase):
|
||||
"""The makeStr/join/seg:: constexpr DSL resolver — the foundation of the
|
||||
L1 key set. Covers flat, nested, cross-file, alias, and multi-line forms."""
|
||||
|
||||
def test_flat_join(self):
|
||||
syms = chk.resolve_constants(
|
||||
'inline constexpr auto a = makeStr("xrpl");\n'
|
||||
'inline constexpr auto b = makeStr("network");\n'
|
||||
"inline constexpr auto c = join(a, b);\n"
|
||||
)
|
||||
self.assertEqual(syms["c"], "xrpl.network")
|
||||
|
||||
def test_nested_join_three_segments(self):
|
||||
syms = chk.resolve_constants(
|
||||
'inline constexpr auto xrpl = makeStr("xrpl");\n'
|
||||
'inline constexpr auto network = makeStr("network");\n'
|
||||
"inline constexpr auto networkId = "
|
||||
'join(join(xrpl, network), makeStr("id"));\n'
|
||||
)
|
||||
self.assertEqual(syms["networkId"], "xrpl.network.id")
|
||||
|
||||
def test_qualified_seg_reference(self):
|
||||
# `seg::rpc` resolves by its bare leaf `rpc`.
|
||||
syms = chk.resolve_constants('inline constexpr auto rpc = makeStr("rpc");\n')
|
||||
syms2 = chk.resolve_constants(
|
||||
'inline constexpr auto command = join(seg::rpc, makeStr("command"));\n',
|
||||
syms,
|
||||
)
|
||||
self.assertEqual(syms2["command"], "rpc.command")
|
||||
|
||||
def test_alias_reference(self):
|
||||
syms = chk.resolve_constants('inline constexpr auto rpc = makeStr("rpc");\n')
|
||||
chk.resolve_constants("inline constexpr auto alias = seg::rpc;\n", syms)
|
||||
self.assertEqual(syms["alias"], "rpc")
|
||||
|
||||
def test_unresolvable_expr_omitted(self):
|
||||
syms = chk.resolve_constants("inline constexpr auto x = join(unknown, y);\n")
|
||||
self.assertNotIn("x", syms)
|
||||
|
||||
def test_split_top_level_args_respects_nesting(self):
|
||||
self.assertEqual(
|
||||
chk.split_top_level_args("join(seg::a, b), c"),
|
||||
["join(seg::a, b)", " c"],
|
||||
)
|
||||
|
||||
def test_split_top_level_args_ignores_comma_in_string(self):
|
||||
self.assertEqual(
|
||||
chk.split_top_level_args('key, ","'),
|
||||
["key", ' ","'],
|
||||
)
|
||||
|
||||
def test_strip_comments_removes_line_and_block(self):
|
||||
self.assertEqual(
|
||||
chk.strip_comments("a // line\nb /* blk */ c").split(),
|
||||
["a", "b", "c"],
|
||||
)
|
||||
|
||||
|
||||
def _write(path: Path, text: str) -> None:
|
||||
path.parent.mkdir(parents=True, exist_ok=True)
|
||||
path.write_text(text)
|
||||
|
||||
|
||||
def _header(ns_attr_body: str, prefix_seg: str = "") -> str:
|
||||
"""A minimal *SpanNames.h body: optional seg defs + a namespace attr block."""
|
||||
return (
|
||||
"#pragma once\n"
|
||||
+ prefix_seg
|
||||
+ "namespace xrpl::telemetry::demo::span {\n"
|
||||
+ "namespace attr {\n"
|
||||
+ ns_attr_body
|
||||
+ "} // namespace attr\n"
|
||||
+ "}\n"
|
||||
)
|
||||
|
||||
|
||||
class AttrKeyExtraction(unittest.TestCase):
|
||||
"""attr_keys_from_header: comment-stripping + multi-line + using re-export."""
|
||||
|
||||
def _l1(self, header_text):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
h = d / "src" / "DemoSpanNames.h"
|
||||
_write(h, header_text)
|
||||
syms = chk.build_global_symbols([h])
|
||||
return chk.attr_keys_from_header(h, syms)
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
def test_single_line_makestr(self):
|
||||
keys = self._l1(_header('inline constexpr auto k = makeStr("tx_hash");\n'))
|
||||
self.assertIn("tx_hash", keys)
|
||||
|
||||
def test_multiline_constexpr_captured(self):
|
||||
keys = self._l1(
|
||||
_header("inline constexpr auto k =\n" ' makeStr("round_time_ms");\n')
|
||||
)
|
||||
self.assertIn("round_time_ms", keys)
|
||||
|
||||
def test_commented_makestr_not_leaked(self):
|
||||
keys = self._l1(
|
||||
_header(
|
||||
'inline constexpr auto k = makeStr("good");\n'
|
||||
'// inline constexpr auto bad = makeStr("old.dotted");\n'
|
||||
)
|
||||
)
|
||||
self.assertIn("good", keys)
|
||||
self.assertNotIn("old.dotted", keys)
|
||||
|
||||
def test_block_commented_makestr_not_leaked(self):
|
||||
keys = self._l1(
|
||||
_header(
|
||||
'inline constexpr auto k = makeStr("good");\n'
|
||||
'/* makeStr("blockbad") */\n'
|
||||
)
|
||||
)
|
||||
self.assertNotIn("blockbad", keys)
|
||||
|
||||
|
||||
class CamelToDotSegments(unittest.TestCase):
|
||||
"""semconv CamelCase -> dotted OTel-standard key derivation."""
|
||||
|
||||
def test_service_instance_id(self):
|
||||
self.assertEqual(
|
||||
chk.camel_to_dotsegments("ServiceInstanceId"),
|
||||
["service", "instance", "id"],
|
||||
)
|
||||
|
||||
def test_service_name(self):
|
||||
self.assertEqual(chk.camel_to_dotsegments("ServiceName"), ["service", "name"])
|
||||
|
||||
def test_derive_keys_from_telemetry_cpp(self):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
tele = d / "src" / "libxrpl" / "telemetry" / "Telemetry.cpp"
|
||||
_write(
|
||||
tele,
|
||||
"resource::Resource::Create({\n"
|
||||
" {semconv::service::kServiceName, x},\n"
|
||||
" {semconv::service::kServiceInstanceId, y},\n"
|
||||
"});\n",
|
||||
)
|
||||
report = chk.Report()
|
||||
allow = chk.derive_dotted_resource_keys(d, {}, report)
|
||||
self.assertIn("service.name", allow)
|
||||
self.assertIn("service.instance.id", allow)
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
|
||||
class SymbolCollision(unittest.TestCase):
|
||||
"""attr_keys_from_header must resolve a constant against ITS OWN header, so
|
||||
two headers defining a same-named constant each report their real wire key.
|
||||
Regression for the flat-symbol-table collision that let a later header
|
||||
clobber an earlier one and erased a dotted key from L1 (a Rule-A blind
|
||||
spot)."""
|
||||
|
||||
def _build(self, files):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
paths = {}
|
||||
for rel, text in files.items():
|
||||
p = d / rel
|
||||
_write(p, text)
|
||||
paths[rel] = p
|
||||
return d, paths
|
||||
|
||||
def test_same_named_const_not_clobbered_across_headers(self):
|
||||
base = (
|
||||
"#pragma once\n"
|
||||
"namespace xrpl::telemetry {\n"
|
||||
'namespace seg { inline constexpr auto xrpl = makeStr("xrpl");\n'
|
||||
'inline constexpr auto ledger = makeStr("ledger"); }\n'
|
||||
"namespace attr {\n"
|
||||
"inline constexpr auto ledgerHash = "
|
||||
'join(join(seg::xrpl, seg::ledger), makeStr("hash"));\n'
|
||||
"}\n}\n"
|
||||
)
|
||||
cons = (
|
||||
"#pragma once\n"
|
||||
"namespace xrpl::telemetry::consensus::span {\n"
|
||||
"namespace attr { inline constexpr auto ledgerHash = "
|
||||
'makeStr("ledger_hash"); }\n}\n'
|
||||
)
|
||||
d, paths = self._build(
|
||||
{
|
||||
"include/xrpl/telemetry/SpanNames.h": base,
|
||||
"src/xrpld/consensus/ConsensusSpanNames.h": cons,
|
||||
}
|
||||
)
|
||||
try:
|
||||
headers = chk.find_spanname_headers(d)
|
||||
syms = chk.build_global_symbols(headers)
|
||||
by_name = {p.name: chk.attr_keys_from_header(p, syms) for p in headers}
|
||||
# The base header keeps its dotted key; consensus keeps the bare one.
|
||||
self.assertIn("xrpl.ledger.hash", by_name["SpanNames.h"])
|
||||
self.assertEqual(by_name["ConsensusSpanNames.h"], {"ledger_hash"})
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
def test_using_reexport_still_resolves_globally(self):
|
||||
# A `using`-re-export imports a constant defined elsewhere; it must
|
||||
# resolve against the global table, not the local header.
|
||||
base = (
|
||||
"#pragma once\n"
|
||||
"namespace xrpl::telemetry {\n"
|
||||
"namespace attr { inline constexpr auto txHash = "
|
||||
'makeStr("tx_hash"); }\n}\n'
|
||||
)
|
||||
dom = (
|
||||
"#pragma once\n"
|
||||
"namespace xrpl::telemetry::tx::span {\n"
|
||||
"namespace attr { using ::xrpl::telemetry::attr::txHash; }\n}\n"
|
||||
)
|
||||
d, paths = self._build(
|
||||
{
|
||||
"include/xrpl/telemetry/SpanNames.h": base,
|
||||
"src/xrpld/app/misc/TxSpanNames.h": dom,
|
||||
}
|
||||
)
|
||||
try:
|
||||
headers = chk.find_spanname_headers(d)
|
||||
syms = chk.build_global_symbols(headers)
|
||||
keys = chk.attr_keys_from_header(
|
||||
paths["src/xrpld/app/misc/TxSpanNames.h"], syms
|
||||
)
|
||||
self.assertEqual(keys, {"tx_hash"})
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
|
||||
class ResourceAllowlistScope(unittest.TestCase):
|
||||
"""derive_dotted_resource_keys must allowlist ONLY the dotted keys actually
|
||||
passed to Resource::Create() — not every dotted key in the base header. A
|
||||
dotted attr declared in a header but not set as a resource attr is a Rule-A
|
||||
violation."""
|
||||
|
||||
def _derive(self, tele_text, span_text):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
_write(d / "src" / "libxrpl" / "telemetry" / "Telemetry.cpp", tele_text)
|
||||
_write(d / "include" / "xrpl" / "telemetry" / "SpanNames.h", span_text)
|
||||
headers = chk.find_spanname_headers(d)
|
||||
syms = chk.build_global_symbols(headers)
|
||||
allow = chk.derive_dotted_resource_keys(d, syms, chk.Report())
|
||||
return allow, syms, headers, d
|
||||
except Exception:
|
||||
shutil.rmtree(d)
|
||||
raise
|
||||
|
||||
def test_dotted_span_attr_not_allowlisted_and_flagged(self):
|
||||
span = (
|
||||
"#pragma once\n"
|
||||
"namespace xrpl::telemetry {\n"
|
||||
'namespace seg { inline constexpr auto xrpl = makeStr("xrpl");\n'
|
||||
'inline constexpr auto ledger = makeStr("ledger");\n'
|
||||
'inline constexpr auto network = makeStr("network"); }\n'
|
||||
"namespace attr {\n"
|
||||
"inline constexpr auto networkId = "
|
||||
'join(join(seg::xrpl, seg::network), makeStr("id"));\n'
|
||||
"inline constexpr auto ledgerHash = "
|
||||
'join(join(seg::xrpl, seg::ledger), makeStr("hash"));\n'
|
||||
"}\n}\n"
|
||||
)
|
||||
tele = (
|
||||
"auto r = resource::Resource::Create({\n"
|
||||
" {semconv::service::kServiceName, x},\n"
|
||||
" {std::string(attr::networkId), n},\n"
|
||||
"});\n"
|
||||
)
|
||||
allow, syms, headers, d = self._derive(tele, span)
|
||||
try:
|
||||
# networkId IS a resource attr; ledgerHash is NOT, despite living in
|
||||
# the base header.
|
||||
self.assertIn("xrpl.network.id", allow)
|
||||
self.assertNotIn("xrpl.ledger.hash", allow)
|
||||
kbh = {h: chk.attr_keys_from_header(h, syms) for h in headers}
|
||||
report = chk.Report()
|
||||
chk.run_rule_a(kbh, allow, report)
|
||||
self.assertEqual([v[2] for v in report.violations], ["xrpl.ledger.hash"])
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
def test_resource_block_brace_matched(self):
|
||||
# A nested {key,value} initializer must not truncate the block scan.
|
||||
tele = (
|
||||
"auto r = resource::Resource::Create({\n"
|
||||
" {semconv::service::kServiceName, x},\n"
|
||||
" {std::string(attr::networkType), t},\n"
|
||||
"});\n"
|
||||
)
|
||||
span = (
|
||||
"#pragma once\n"
|
||||
"namespace xrpl::telemetry {\n"
|
||||
'namespace seg { inline constexpr auto xrpl = makeStr("xrpl");\n'
|
||||
'inline constexpr auto network = makeStr("network"); }\n'
|
||||
"namespace attr { inline constexpr auto networkType = "
|
||||
'join(join(seg::xrpl, seg::network), makeStr("type")); }\n}\n'
|
||||
)
|
||||
allow, _syms, _headers, d = self._derive(tele, span)
|
||||
try:
|
||||
self.assertIn("xrpl.network.type", allow)
|
||||
self.assertIn("service.name", allow)
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
|
||||
def _run_rule_a(keys_by_header, allow):
|
||||
report = chk.Report()
|
||||
chk.run_rule_a(keys_by_header, allow, report)
|
||||
return sorted(v[2] for v in report.violations)
|
||||
|
||||
|
||||
class RuleADotted(unittest.TestCase):
|
||||
def test_dotted_attr_not_in_allow_flagged(self):
|
||||
kbh = {Path("src/RpcSpanNames.h"): {"xrpl.tx.hash", "command"}}
|
||||
self.assertEqual(_run_rule_a(kbh, {"xrpl.network.id"}), ["xrpl.tx.hash"])
|
||||
|
||||
def test_resource_attr_in_allow_passes(self):
|
||||
kbh = {Path("src/SpanNames.h"): {"xrpl.network.id"}}
|
||||
self.assertEqual(_run_rule_a(kbh, {"xrpl.network.id"}), [])
|
||||
|
||||
def test_bare_key_never_flagged(self):
|
||||
kbh = {Path("src/TxSpanNames.h"): {"tx_hash", "command"}}
|
||||
self.assertEqual(_run_rule_a(kbh, set()), [])
|
||||
|
||||
|
||||
def _run_rule_g(keys_by_header):
|
||||
report = chk.Report()
|
||||
chk.run_rule_g(keys_by_header, report)
|
||||
return sorted(v[2] for v in report.violations)
|
||||
|
||||
|
||||
class RuleGSnakeCase(unittest.TestCase):
|
||||
def test_camelcase_flagged(self):
|
||||
self.assertEqual(_run_rule_g({Path("h"): {"txHash"}}), ["txHash"])
|
||||
|
||||
def test_uppercase_flagged(self):
|
||||
self.assertEqual(_run_rule_g({Path("h"): {"TX_HASH"}}), ["TX_HASH"])
|
||||
|
||||
def test_space_flagged(self):
|
||||
self.assertEqual(_run_rule_g({Path("h"): {"bad key"}}), ["bad key"])
|
||||
|
||||
def test_snake_case_passes(self):
|
||||
self.assertEqual(_run_rule_g({Path("h"): {"tx_hash", "rpc_status"}}), [])
|
||||
|
||||
def test_dotted_resource_segments_pass(self):
|
||||
self.assertEqual(_run_rule_g({Path("h"): {"xrpl.network.id"}}), [])
|
||||
|
||||
def test_dotted_with_bad_segment_flagged(self):
|
||||
self.assertEqual(
|
||||
_run_rule_g({Path("h"): {"xrpl.Network.id"}}), ["xrpl.Network.id"]
|
||||
)
|
||||
|
||||
|
||||
class RuleFAndH(unittest.TestCase):
|
||||
"""run_rule_f: literal keys/span-names flagged; values & tests exempt.
|
||||
Rule H: qualified constant not in any header warns (non-fatal)."""
|
||||
|
||||
def _run(self, rel_path, source, header_symbols=frozenset()):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
_write(d / rel_path, source)
|
||||
report = chk.Report()
|
||||
chk.run_rule_f(d, report, set(header_symbols))
|
||||
return (
|
||||
sorted(v[2] for v in report.violations),
|
||||
sorted(w[2] for w in report.warnings),
|
||||
)
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
def test_literal_key_flagged(self):
|
||||
v, _ = self._run("src/Foo.cpp", 'g.setAttribute("lit_key", v);\n')
|
||||
self.assertEqual(v, ['setAttribute arg0 "lit_key"'])
|
||||
|
||||
def test_literal_value_exempt(self):
|
||||
v, _ = self._run("src/Foo.cpp", 'g.setAttribute(attr::command, "submit");\n')
|
||||
self.assertEqual(v, [])
|
||||
|
||||
def test_span_name_args_flagged(self):
|
||||
v, _ = self._run("src/Foo.cpp", 'SpanGuard::span(cat, "rpc", "command");\n')
|
||||
self.assertEqual(v, ['span arg1 "rpc"', 'span arg2 "command"'])
|
||||
|
||||
def test_rootspan_literal_flagged_by_rule_f(self):
|
||||
# rootSpan(cat, prefix, name) shares span()'s signature, so a string
|
||||
# literal in the prefix/name position must FAIL rule F exactly as it
|
||||
# does for span() — otherwise a call switched to rootSpan silently
|
||||
# escapes span-name validation.
|
||||
v, _ = self._run(
|
||||
"src/Foo.cpp",
|
||||
'SpanGuard::rootSpan(cat, "peer", "validation.receive");\n',
|
||||
)
|
||||
self.assertEqual(
|
||||
v, ['rootSpan arg1 "peer"', 'rootSpan arg2 "validation.receive"']
|
||||
)
|
||||
|
||||
def test_rootspan_constant_args_accepted(self):
|
||||
# Constant references in the prefix/name position are accepted (no
|
||||
# rule F), mirroring span()'s constant-arg handling.
|
||||
v, _ = self._run(
|
||||
"src/Foo.cpp",
|
||||
"SpanGuard::rootSpan(TraceCategory::Peer, seg::peer, "
|
||||
"peer_span::op::validationReceive);\n",
|
||||
)
|
||||
self.assertEqual(v, [])
|
||||
|
||||
def test_test_path_exempt(self):
|
||||
v, _ = self._run("src/test/Foo.cpp", 'g.setAttribute("lit_key", v);\n')
|
||||
self.assertEqual(v, [])
|
||||
|
||||
def test_spannames_header_exempt(self):
|
||||
v, _ = self._run("src/DemoSpanNames.h", 'g.setAttribute("lit_key", v);\n')
|
||||
self.assertEqual(v, [])
|
||||
|
||||
def test_bare_span_call_not_matched(self):
|
||||
# No SpanGuard/./-> receiver -> not a telemetry call-site.
|
||||
v, _ = self._run("src/Foo.cpp", 'auto s = span("not", "telemetry");\n')
|
||||
self.assertEqual(v, [])
|
||||
|
||||
def test_multiline_call_reports_first_line(self):
|
||||
v, _ = self._run("src/Foo.cpp", 'g.setAttribute(\n "k",\n v);\n')
|
||||
self.assertEqual(v, ['setAttribute arg0 "k"'])
|
||||
|
||||
def test_paren_in_string_value_does_not_break_parsing(self):
|
||||
# The ")" inside the value must not end the call early; key still seen.
|
||||
v, _ = self._run("src/Foo.cpp", 'g.setAttribute("k", ")");\n')
|
||||
self.assertEqual(v, ['setAttribute arg0 "k"'])
|
||||
|
||||
def test_rule_h_qualified_constant_warns(self):
|
||||
v, w = self._run(
|
||||
"src/Foo.cpp",
|
||||
"g.setAttribute(consensus::span::accept, v);\n",
|
||||
header_symbols={"command"},
|
||||
)
|
||||
self.assertEqual(v, [])
|
||||
self.assertEqual(w, ["setAttribute arg0 consensus::span::accept"])
|
||||
|
||||
def test_rule_h_known_constant_no_warning(self):
|
||||
_, w = self._run(
|
||||
"src/Foo.cpp",
|
||||
"g.setAttribute(rpc_span::attr::command, v);\n",
|
||||
header_symbols={"command"},
|
||||
)
|
||||
self.assertEqual(w, [])
|
||||
|
||||
def test_rule_h_bare_local_no_warning(self):
|
||||
_, w = self._run(
|
||||
"src/Foo.cpp", "g.setAttribute(myLeaf, v);\n", header_symbols={"command"}
|
||||
)
|
||||
self.assertEqual(w, [])
|
||||
|
||||
|
||||
class RuleBCollector(unittest.TestCase):
|
||||
def _run(self, yaml_text, l1):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
_write(d / "docker" / "telemetry" / "otel-collector-config.yaml", yaml_text)
|
||||
report = chk.Report()
|
||||
chk.run_rule_b_collector(d, set(l1), report)
|
||||
return sorted(v[2] for v in report.violations), report.skips
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
def test_dimension_not_in_l1_flagged(self):
|
||||
y = "spanmetrics:\n dimensions:\n - name: bogus_dim\n - name: command\n"
|
||||
v, _ = self._run(y, {"command"})
|
||||
self.assertEqual(v, ["bogus_dim"])
|
||||
|
||||
def test_all_dimensions_in_l1_pass(self):
|
||||
y = "spanmetrics:\n dimensions:\n - name: command\n - name: rpc_status\n"
|
||||
v, _ = self._run(y, {"command", "rpc_status"})
|
||||
self.assertEqual(v, [])
|
||||
|
||||
def test_skip_when_no_spanmetrics_block(self):
|
||||
v, skips = self._run("receivers:\n otlp:\n", {"command"})
|
||||
self.assertEqual(v, [])
|
||||
self.assertTrue(any("SKIP: B" in s for s in skips))
|
||||
|
||||
|
||||
class RuleCTempo(unittest.TestCase):
|
||||
"""Rule C reads the Grafana Tempo DATASOURCE file's search.filters and
|
||||
validates only span-scope tags against L1."""
|
||||
|
||||
DS = "docker/telemetry/grafana/provisioning/datasources/tempo.yaml"
|
||||
|
||||
def _run(self, yaml_text, l1):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
_write(d / self.DS, yaml_text)
|
||||
report = chk.Report()
|
||||
chk.run_rule_c_tempo(d, set(l1), report)
|
||||
return sorted(v[2] for v in report.violations), report.skips
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
def _filter(self, fid, tag, scope):
|
||||
return (
|
||||
f" - id: {fid}\n"
|
||||
f" tag: {tag}\n"
|
||||
f' operator: "="\n'
|
||||
f" scope: {scope}\n"
|
||||
f" type: static\n"
|
||||
)
|
||||
|
||||
def test_span_tag_not_in_l1_flagged(self):
|
||||
y = "search:\n filters:\n" + self._filter("f1", "bogus_tag", "span")
|
||||
v, _ = self._run(y, {"command"})
|
||||
self.assertEqual(v, ["bogus_tag"])
|
||||
|
||||
def test_span_tags_in_l1_pass(self):
|
||||
y = (
|
||||
"search:\n filters:\n"
|
||||
+ self._filter("f1", "command", "span")
|
||||
+ self._filter("f2", "tx_hash", "span")
|
||||
)
|
||||
v, _ = self._run(y, {"command", "tx_hash"})
|
||||
self.assertEqual(v, [])
|
||||
|
||||
def test_resource_and_intrinsic_tags_ignored(self):
|
||||
# service.* (resource) and name/status/duration (intrinsic) are not
|
||||
# span attributes — they must not be validated against L1.
|
||||
y = (
|
||||
"search:\n filters:\n"
|
||||
+ self._filter("f1", "service.instance.id", "resource")
|
||||
+ self._filter("f2", "name", "intrinsic")
|
||||
+ self._filter("f3", "duration", "intrinsic")
|
||||
)
|
||||
v, skips = self._run(y, {"command"})
|
||||
self.assertEqual(v, [])
|
||||
self.assertTrue(any("SKIP: C" in s for s in skips))
|
||||
|
||||
def test_skip_when_datasource_absent(self):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
report = chk.Report()
|
||||
chk.run_rule_c_tempo(d, {"command"}, report)
|
||||
self.assertEqual(report.violations, [])
|
||||
self.assertTrue(any("SKIP: C" in s for s in report.skips))
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
|
||||
class RuleDDashboards(unittest.TestCase):
|
||||
def _run(self, json_text, l1, metric_labels=frozenset()):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
_write(
|
||||
d / "docker" / "telemetry" / "grafana" / "dashboards" / "x.json",
|
||||
json_text,
|
||||
)
|
||||
report = chk.Report()
|
||||
chk.run_rule_d_dashboards(d, set(l1), set(metric_labels), report)
|
||||
return sorted(v[2] for v in report.violations)
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
def test_unknown_promql_label_flagged(self):
|
||||
self.assertEqual(
|
||||
self._run('"expr": "sum by (bogus_label) (x)"', {"command"}),
|
||||
["bogus_label"],
|
||||
)
|
||||
|
||||
# Rule D returns early on an empty L1 set, so a test that passes one asserts
|
||||
# nothing. Each test below passes a nonempty L1 set and puts `bogus_label` in
|
||||
# the same expression as the labels under test: the assertion then pins both
|
||||
# halves at once — the accepted labels are absent from the result, and Rule D
|
||||
# demonstrably ran because it flagged the bad one.
|
||||
|
||||
def test_builtin_labels_not_flagged(self):
|
||||
self.assertEqual(
|
||||
self._run(
|
||||
'"expr": "sum by (le, span_name, exported_instance, bogus_label) (x)"',
|
||||
{"command"},
|
||||
),
|
||||
["bogus_label"],
|
||||
)
|
||||
|
||||
def test_external_infra_labels_not_flagged(self):
|
||||
# EXTERNAL_INFRA_LABELS (perf-iac identity labels with no in-tree
|
||||
# source) must be recognized as valid, distinct from `builtins`. The
|
||||
# names are spelled out rather than joined from chk.EXTERNAL_INFRA_LABELS
|
||||
# because building the query from the set that validates it passes for
|
||||
# whatever that set happens to hold — including an empty one.
|
||||
self.assertEqual(
|
||||
self._run(
|
||||
'"expr": "sum by (xrpl_branch, xrpl_node_role, bogus_label) (x)"',
|
||||
{"command"},
|
||||
),
|
||||
["bogus_label"],
|
||||
)
|
||||
|
||||
def test_prometheus_name_label_not_flagged(self):
|
||||
# `__name__` is the Prometheus reserved metric-name label; the renamed
|
||||
# system-*.json dashboards use `sum by (le, __name__)`.
|
||||
self.assertEqual(
|
||||
self._run(
|
||||
'"expr": "sum by (le, __name__, bogus_label) (rate(x[5m]))"',
|
||||
{"command"},
|
||||
),
|
||||
["bogus_label"],
|
||||
)
|
||||
|
||||
def test_l1_label_passes(self):
|
||||
# `by (...)` form, not a `{command="x"}` selector: a dashboard stores the
|
||||
# query inside a JSON string, so its quotes are escaped on disk and the
|
||||
# selector branch extracts nothing from them here.
|
||||
self.assertEqual(
|
||||
self._run('"expr": "sum by (command, bogus_label) (x)"', {"command"}),
|
||||
["bogus_label"],
|
||||
)
|
||||
|
||||
def test_traceql_span_prefix_stripped(self):
|
||||
# `span.establish_count` must validate against the bare L1 key.
|
||||
self.assertEqual(
|
||||
self._run(
|
||||
'"expr": "count_over_time(x) by (span.establish_count)"',
|
||||
{"establish_count"},
|
||||
),
|
||||
[],
|
||||
)
|
||||
|
||||
def test_traceql_resource_prefix_stripped(self):
|
||||
# `resource.service_name` must validate against the bare builtin, same as
|
||||
# the `span.` case above.
|
||||
self.assertEqual(
|
||||
self._run(
|
||||
'"expr": "count_over_time(x) by (resource.service_name, bogus_label)"',
|
||||
{"command"},
|
||||
),
|
||||
["bogus_label"],
|
||||
)
|
||||
|
||||
def test_native_metric_label_passes(self):
|
||||
# `job_type` / `reason` are emitted by MetricsRegistry, not span attrs.
|
||||
self.assertEqual(
|
||||
self._run(
|
||||
'"expr": "sum by (job_type, reason) (x)"',
|
||||
{"command"},
|
||||
metric_labels={"job_type", "reason"},
|
||||
),
|
||||
[],
|
||||
)
|
||||
|
||||
def test_unknown_label_still_flagged_with_metric_labels(self):
|
||||
# A label that is neither L1, metric label, nor builtin still fails.
|
||||
self.assertEqual(
|
||||
self._run(
|
||||
'"expr": "sum by (bogus) (x)"',
|
||||
{"command"},
|
||||
metric_labels={"job_type"},
|
||||
),
|
||||
["bogus"],
|
||||
)
|
||||
|
||||
def test_span_prefixed_unknown_still_flagged(self):
|
||||
# `span.not_a_key` whose bare form is unknown is still a violation.
|
||||
self.assertEqual(
|
||||
self._run('"expr": "x by (span.not_a_key)"', {"command"}),
|
||||
["span.not_a_key"],
|
||||
)
|
||||
|
||||
|
||||
class MetricLabelExtraction(unittest.TestCase):
|
||||
"""L6: native-metric label keys parsed from C++ instrument calls."""
|
||||
|
||||
def test_extracts_add_label(self):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
_write(
|
||||
d / "src" / "xrpld" / "telemetry" / "MetricsRegistry.cpp",
|
||||
'counter->Add(1, {{"job_type", std::string(jobType)}});\n'
|
||||
'c2->Add(1, {{"reason", std::string(r)}});\n',
|
||||
)
|
||||
self.assertEqual(chk.metric_label_names(d), {"job_type", "reason"})
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
def test_no_metrics_file_empty(self):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
(d / "src").mkdir()
|
||||
self.assertEqual(chk.metric_label_names(d), set())
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
|
||||
class ReportExitContract(unittest.TestCase):
|
||||
@staticmethod
|
||||
def _exit_code(report):
|
||||
"""Call render_and_exit (which prints + raises SystemExit), swallowing
|
||||
its stdout, and return the exit code."""
|
||||
with contextlib.redirect_stdout(io.StringIO()):
|
||||
try:
|
||||
report.render_and_exit()
|
||||
except SystemExit as e:
|
||||
return e.code
|
||||
return None # pragma: no cover - render_and_exit always exits
|
||||
|
||||
def test_violation_exits_nonzero(self):
|
||||
r = chk.Report()
|
||||
r.violation("A", "f", "tok", "exp")
|
||||
self.assertEqual(self._exit_code(r), 1)
|
||||
|
||||
def test_clean_exits_zero(self):
|
||||
r = chk.Report()
|
||||
r.ok("all good")
|
||||
self.assertEqual(self._exit_code(r), 0)
|
||||
|
||||
def test_warning_only_exits_zero(self):
|
||||
r = chk.Report()
|
||||
r.warning("H", "f", "tok", "note")
|
||||
self.assertEqual(self._exit_code(r), 0)
|
||||
|
||||
|
||||
class RuleEReportTuple(unittest.TestCase):
|
||||
"""Assert Rule E records the full (rule, expected) tuple, not just token."""
|
||||
|
||||
def test_violation_tuple_fields(self):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
(d / "docs").mkdir()
|
||||
(d / "docs" / "telemetry-runbook.md").write_text("`xrpl.tx.hash`")
|
||||
report = chk.Report()
|
||||
chk.run_rule_e_runbook(d, {"xrpl.network.id"}, report)
|
||||
self.assertEqual(len(report.violations), 1)
|
||||
rule, _loc, token, expected = report.violations[0]
|
||||
self.assertEqual(rule, "E")
|
||||
self.assertEqual(token, "xrpl.tx.hash")
|
||||
self.assertEqual(expected, "underscore, not dotted")
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
def test_clean_runbook_records_ok(self):
|
||||
d = Path(tempfile.mkdtemp())
|
||||
try:
|
||||
(d / "docs").mkdir()
|
||||
(d / "docs" / "telemetry-runbook.md").write_text(
|
||||
"`tx_hash` `consensus.round`"
|
||||
)
|
||||
report = chk.Report()
|
||||
chk.run_rule_e_runbook(d, {"tx_hash"}, report)
|
||||
self.assertEqual(report.violations, [])
|
||||
self.assertTrue(any("E:" in c for c in report.checked))
|
||||
finally:
|
||||
shutil.rmtree(d)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main(verbosity=2)
|
||||
4
.github/scripts/strategy-matrix/generate.py
vendored
4
.github/scripts/strategy-matrix/generate.py
vendored
@@ -81,8 +81,6 @@ class LinuxConfig:
|
||||
suffix: str = ""
|
||||
extra_cmake_args: str = ""
|
||||
package: PackageConfig | None = None # set to also package this config
|
||||
# Flip every amendment to Supported::Yes before building (perf/test only).
|
||||
force_supported: bool = False
|
||||
|
||||
def __post_init__(self) -> None:
|
||||
if isinstance(self.package, dict):
|
||||
@@ -170,7 +168,6 @@ class MatrixEntry:
|
||||
image: str = "" # container image; empty for macOS/Windows (runs natively)
|
||||
compiler: str = "" # compiler name ("gcc" or "clang"); empty for macOS/Windows
|
||||
toolchain: str = "" # "nix" for the flake's CI environment; see PlatformConfig
|
||||
force_supported: bool = False # flip amendments to Supported::Yes before build
|
||||
|
||||
|
||||
@dataclasses.dataclass
|
||||
@@ -236,7 +233,6 @@ def expand_linux_matrix(linux: LinuxFile, minimal: bool) -> list[MatrixEntry]:
|
||||
architecture=arch_info,
|
||||
sanitizers=sanitizer,
|
||||
compiler=compiler,
|
||||
force_supported=cfg.force_supported,
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
18
.github/scripts/strategy-matrix/linux.json
vendored
18
.github/scripts/strategy-matrix/linux.json
vendored
@@ -17,6 +17,7 @@
|
||||
"minimal": true,
|
||||
"benchmark": true
|
||||
},
|
||||
|
||||
{
|
||||
"compiler": ["gcc"],
|
||||
"build_type": ["Release"],
|
||||
@@ -29,6 +30,7 @@
|
||||
"arch": ["arm64"],
|
||||
"minimal": false
|
||||
},
|
||||
|
||||
{
|
||||
"compiler": ["gcc", "clang"],
|
||||
"build_type": ["Debug", "Release"],
|
||||
@@ -36,6 +38,7 @@
|
||||
"minimal": false,
|
||||
"sanitizers": ["address", "undefinedbehavior"]
|
||||
},
|
||||
|
||||
{
|
||||
"compiler": ["clang"],
|
||||
"build_type": ["Debug"],
|
||||
@@ -59,21 +62,9 @@
|
||||
"minimal": false,
|
||||
"suffix": "unity",
|
||||
"extra_cmake_args": "-Dunity=ON"
|
||||
},
|
||||
{
|
||||
"compiler": ["gcc"],
|
||||
"build_type": ["Release"],
|
||||
"arch": ["amd64"],
|
||||
"minimal": false,
|
||||
"suffix": "supported",
|
||||
"force_supported": true,
|
||||
"extra_cmake_args": "-Dvalidator_keys=ON",
|
||||
"package": {
|
||||
"type": "deb",
|
||||
"image": "ghcr.io/xrplf/xrpld/packaging-debian:sha-49cdc10"
|
||||
}
|
||||
}
|
||||
],
|
||||
|
||||
"debian": [
|
||||
{
|
||||
"compiler": ["gcc"],
|
||||
@@ -87,6 +78,7 @@
|
||||
}
|
||||
}
|
||||
],
|
||||
|
||||
"rhel": [
|
||||
{
|
||||
"compiler": ["gcc"],
|
||||
|
||||
103
.github/workflows/build-supported-image.yml
vendored
103
.github/workflows/build-supported-image.yml
vendored
@@ -1,103 +0,0 @@
|
||||
# Package the "all amendments Supported::Yes" build into a runtime Docker image
|
||||
# and push it to GHCR, as a drop-in for the rippleci/xrpld image xrpl.js uses
|
||||
# for standalone testing -- except every amendment is built Supported::Yes.
|
||||
#
|
||||
# This does NOT build or package anything: the Trigger workflow already builds
|
||||
# the supported binary and the supported .deb (the force_supported build config
|
||||
# and the matching supported package config in linux.json). This workflow waits
|
||||
# for a successful Trigger run on develop, downloads that run's supported .deb
|
||||
# artifact, installs it into a slim base (docker/supported.Dockerfile, which
|
||||
# replicates rippleci's layout), and pushes ghcr.io/xrplf/xrpld/supported.
|
||||
#
|
||||
# Perf/test artifact only -- never run it on a production validator.
|
||||
name: Build supported Docker image
|
||||
|
||||
on:
|
||||
workflow_run:
|
||||
workflows: ["Trigger"]
|
||||
types: [completed]
|
||||
branches: [develop]
|
||||
# Manual runs: point at a specific completed Trigger run via its run id.
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
trigger_run_id:
|
||||
description: "Run id of the Trigger workflow whose supported .deb to package."
|
||||
required: true
|
||||
type: string
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
defaults:
|
||||
run:
|
||||
shell: bash
|
||||
|
||||
env:
|
||||
IMAGE_NAME: ghcr.io/xrplf/xrpld/supported
|
||||
# The supported .deb artifact uploaded by reusable-package.yml:
|
||||
# <artifact_name>-pkg, where artifact_name carries the -supported suffix.
|
||||
DEB_ARTIFACT: xrpld-ubuntu-gcc-release-amd64-supported-pkg
|
||||
SOURCE_RUN_ID: ${{ github.event.workflow_run.id || github.event.inputs.trigger_run_id }}
|
||||
jobs:
|
||||
image:
|
||||
# Only for successful Trigger runs (workflow_run), and only on the canonical
|
||||
# repo where GITHUB_TOKEN can push to ghcr.io/xrplf/*.
|
||||
if: ${{ github.repository == 'XRPLF/rippled' && (github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success') }}
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: read
|
||||
packages: write
|
||||
actions: read
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
|
||||
- name: Download the supported .deb from the Trigger run
|
||||
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
||||
with:
|
||||
name: ${{ env.DEB_ARTIFACT }}
|
||||
path: dl
|
||||
run-id: ${{ env.SOURCE_RUN_ID }}
|
||||
github-token: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Assemble build context
|
||||
run: |
|
||||
set -euo pipefail
|
||||
mkdir -p docker-context
|
||||
deb="$(find dl -name '*.deb' | head -n1)"
|
||||
[ -n "${deb}" ] || {
|
||||
echo "::error::no supported .deb found in run ${SOURCE_RUN_ID}"
|
||||
exit 1
|
||||
}
|
||||
mv "${deb}" docker-context/xrpld.deb
|
||||
echo "Packaging $(basename "${deb}") into ${IMAGE_NAME}"
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
|
||||
|
||||
- name: Login to GitHub Container Registry
|
||||
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.repository_owner }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Docker metadata
|
||||
id: meta
|
||||
uses: docker/metadata-action@80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9 # v6.1.0
|
||||
with:
|
||||
images: ${{ env.IMAGE_NAME }}
|
||||
tags: |
|
||||
type=sha,prefix=sha-,format=short
|
||||
type=raw,value=latest
|
||||
|
||||
- name: Build and push
|
||||
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0
|
||||
with:
|
||||
context: docker-context
|
||||
file: docker/supported.Dockerfile
|
||||
platforms: linux/amd64
|
||||
push: true
|
||||
tags: ${{ steps.meta.outputs.tags }}
|
||||
labels: ${{ steps.meta.outputs.labels }}
|
||||
8
.github/workflows/on-pr.yml
vendored
8
.github/workflows/on-pr.yml
vendored
@@ -70,8 +70,10 @@ jobs:
|
||||
files: |
|
||||
# These paths are unique to `on-pr.yml`.
|
||||
.github/scripts/levelization/**
|
||||
.github/scripts/otel-naming/**
|
||||
.github/scripts/rename/**
|
||||
.github/workflows/reusable-check-levelization.yml
|
||||
.github/workflows/reusable-check-otel-naming.yml
|
||||
.github/workflows/reusable-check-rename.yml
|
||||
.github/workflows/on-pr.yml
|
||||
|
||||
@@ -144,6 +146,11 @@ jobs:
|
||||
if: ${{ needs.should-run.outputs.go == 'true' }}
|
||||
uses: ./.github/workflows/reusable-check-levelization.yml
|
||||
|
||||
check-otel-naming:
|
||||
needs: should-run
|
||||
if: ${{ needs.should-run.outputs.go == 'true' }}
|
||||
uses: ./.github/workflows/reusable-check-otel-naming.yml
|
||||
|
||||
check-rename:
|
||||
needs: should-run
|
||||
if: ${{ needs.should-run.outputs.go == 'true' }}
|
||||
@@ -222,6 +229,7 @@ jobs:
|
||||
needs:
|
||||
- check-autogen
|
||||
- check-levelization
|
||||
- check-otel-naming
|
||||
- check-rename
|
||||
- clang-tidy
|
||||
- build-test
|
||||
|
||||
19
.github/workflows/reusable-build-test-config.yml
vendored
19
.github/workflows/reusable-build-test-config.yml
vendored
@@ -74,11 +74,6 @@ on:
|
||||
required: false
|
||||
type: string
|
||||
default: ""
|
||||
force_supported:
|
||||
description: "Flip every amendment to Supported::Yes before building. For perf/test builds only; never for release artifacts."
|
||||
required: false
|
||||
type: boolean
|
||||
default: false
|
||||
|
||||
secrets:
|
||||
CODECOV_TOKEN:
|
||||
@@ -133,20 +128,6 @@ jobs:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
|
||||
- name: Force all amendments to Supported::Yes
|
||||
if: ${{ inputs.force_supported && runner.os == 'Linux' }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
MACRO="include/xrpl/protocol/detail/features.macro"
|
||||
echo "Flipping Supported::No -> Supported::Yes in ${MACRO}:"
|
||||
grep -n 'Supported::No,' "${MACRO}" || echo " (none found)"
|
||||
sed -i 's/Supported::No,/Supported::Yes,/g' "${MACRO}"
|
||||
if grep -q 'Supported::No,' "${MACRO}"; then
|
||||
echo "::error::Supported::No entries remain after sed"
|
||||
exit 1
|
||||
fi
|
||||
git diff -- "${MACRO}" || true
|
||||
|
||||
- name: Prepare runner
|
||||
uses: XRPLF/actions/prepare-runner@b3e255d74d785d053e4903da8ac90983cd7d9e82
|
||||
with:
|
||||
|
||||
1
.github/workflows/reusable-build-test.yml
vendored
1
.github/workflows/reusable-build-test.yml
vendored
@@ -52,6 +52,5 @@ jobs:
|
||||
sanitizers: ${{ matrix.sanitizers }}
|
||||
compiler: ${{ matrix.compiler || '' }}
|
||||
toolchain: ${{ matrix.toolchain || '' }}
|
||||
force_supported: ${{ matrix.force_supported || false }}
|
||||
secrets:
|
||||
CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
|
||||
|
||||
28
.github/workflows/reusable-check-otel-naming.yml
vendored
Normal file
28
.github/workflows/reusable-check-otel-naming.yml
vendored
Normal file
@@ -0,0 +1,28 @@
|
||||
# This workflow checks that OpenTelemetry span-attribute names stay consistent
|
||||
# across the code (*SpanNames.h), collector, Tempo, dashboards, and docs.
|
||||
# See .github/scripts/otel-naming/check_otel_naming.py and the
|
||||
# "Telemetry span attribute naming" section in CONTRIBUTING.md.
|
||||
name: Check OTel naming
|
||||
|
||||
# This workflow can only be triggered by other workflows.
|
||||
on: workflow_call
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}-otel-naming
|
||||
cancel-in-progress: true
|
||||
|
||||
defaults:
|
||||
run:
|
||||
shell: bash
|
||||
|
||||
jobs:
|
||||
otel-naming:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
|
||||
- name: Check OTel naming
|
||||
# The script is stdlib-only and reads only files already in the tree;
|
||||
# it enforces each rule only when the layer it needs is present, so it
|
||||
# works whether telemetry changes land in one PR or several.
|
||||
run: python .github/scripts/otel-naming/check_otel_naming.py
|
||||
3
.gitignore
vendored
3
.gitignore
vendored
@@ -97,3 +97,6 @@ target/
|
||||
|
||||
# Rust build directory
|
||||
crates/target
|
||||
|
||||
# Env. file carrying environmental setup data for local or cloud runs.
|
||||
.env.*
|
||||
|
||||
@@ -28,10 +28,6 @@ Version 3.4.0 is not yet released. These changes are available in the 3.4.0 beta
|
||||
|
||||
### Additions in 3.4.0
|
||||
|
||||
- `book_offers`, `account_offers`: With the `OfferQualifiers` amendment, an offer entry may now include `all_or_none: true` (the offer carries the `lsfAllOrNone` flag) and/or `min_quantity` (the offer's `MinQuantity` amount). These mark execution-qualified ("contingent") offers that cannot be taken to arbitrary depth; clients should exclude them from quoted/takeable depth. The `OfferCreate` transaction gains the `tfAllOrNone` and `tfPostOnly` flags and an optional `MinQuantity` field, and a marketable `tfPostOnly` offer is rejected with the new `tecWOULD_CROSS` result.
|
||||
|
||||
- `account_tx`: Added an optional `delegate` request object to filter delegated transactions. The object requires `delegate_filter`, which must be either `actor` for transactions owned by the requested account but signed by another account, or `authorizer` for transactions signed by the requested account on behalf of another account. The optional `counter_party` account narrows the results to a specific signer/delegate for `actor` or a specific owner/delegator for `authorizer`. Malformed `delegate`, `delegate_filter`, and `counter_party` values return standard invalid field errors, and invalid account IDs return `actMalformed`.
|
||||
When paginating delegate-filtered queries, a marker from a delegate-filtered query includes a `delegate` flag and is only valid for follow-up requests that also supply `delegate` (mixing marker conventions returns `invalidParams`). Because filtering is applied after the ledger scan, a page may contain fewer results than `limit` (possibly zero) while still returning a marker, so callers must continue until no marker is present.
|
||||
- `ledger`: `nftoken_id`, `nftoken_ids`, and `offer_id` are now included in transaction metadata when transactions are expanded (`expand`, or admin-only `full`), matching the `tx`, `account_tx`, and `subscribe` (`transactions` stream) responses. ([#5706](https://github.com/XRPLF/rippled/pull/5706))
|
||||
|
||||
### Bugfixes in 3.4.0
|
||||
@@ -45,6 +41,7 @@ Version 3.4.0 is not yet released. These changes are available in the 3.4.0 beta
|
||||
- `gateway_balances`: The `account` and `ident` fields now return an `invalidParams` error if the value is not a string, instead of an `internal` error. [#7655](https://github.com/XRPLF/rippled/pull/7655)
|
||||
- `account_lines`: The `peer` field now returns an error if the value is not a string. [#7728](https://github.com/XRPLF/rippled/pull/7728)
|
||||
- `ledger`: `delivered_amount` is now included in the metadata of successful `AccountDelete` transactions when transactions are expanded (`expand`, or admin-only `full`). Previously it was only added for `Payment` and `CheckCash`, which made `ledger` inconsistent with `tx` and `account_tx`. [#5706](https://github.com/XRPLF/rippled/pull/5706)
|
||||
- `noripple_check`: The `transactions` field is no longer included in error responses; it is still returned (possibly as an empty array) whenever `transactions` is `true` and the request succeeds. A malformed `account` is now rejected before the ledger is looked up, so that error response no longer carries the `ledger_hash`, `ledger_index`, and `validated` fields ([#6303](https://github.com/XRPLF/rippled/pull/6303)).
|
||||
|
||||
## XRP Ledger server version 3.3.0
|
||||
|
||||
@@ -66,11 +63,6 @@ This release contains bug fixes only and no API changes.
|
||||
|
||||
### Additions in 3.2.0
|
||||
|
||||
- `ledger_entry`, `account_objects`: Added the `Ballot` and `BallotVote` ledger entry types introduced by the `ConfidentialVoting` amendment. `ledger_entry` accepts a `ballot` request object (`owner` + `seq`) and a `ballot_vote` request object (`ballot_id` + `account`), or a hex object ID for either. `account_objects` returns these entries and accepts them as `type` filters.
|
||||
|
||||
- `account_tx`: Added an optional `delegate` request object to filter delegated transactions. The object requires `delegate_filter`, which must be either `actor` for transactions owned by the requested account but signed by another account, or `authorizer` for transactions signed by the requested account on behalf of another account. The optional `counter_party` account narrows the results to a specific signer/delegate for `actor` or a specific owner/delegator for `authorizer`. Malformed `delegate`, `delegate_filter`, and `counter_party` values return standard invalid field errors, and invalid account IDs return `actMalformed`.
|
||||
When paginating delegate-filtered queries, a marker from a delegate-filtered query includes a `delegate` flag and is only valid for follow-up requests that also supply `delegate` (mixing marker conventions returns `invalidParams`). Because filtering is applied after the ledger scan, a page may contain fewer results than `limit` (possibly zero) while still returning a marker, so callers must continue until no marker is present.
|
||||
|
||||
- `ledger_entry`, `account_objects`: The `Delegate` ledger entry now includes an optional `DestinationNode` field, which stores the index into the authorized account's owner directory. This field is present on entries created after bidirectional directory tracking was introduced and may appear in RPC responses for those entries. ([#6681](https://github.com/XRPLF/rippled/pull/6681))
|
||||
- `server_definitions`: Added the following new sections to the response ([#6321](https://github.com/XRPLF/rippled/pull/6321)):
|
||||
- `TRANSACTION_FORMATS`: Describes the fields and their optionality for each transaction type, including common fields shared across all transactions.
|
||||
|
||||
@@ -99,7 +99,6 @@ if(only_docs)
|
||||
return()
|
||||
endif()
|
||||
|
||||
include(deps/dilithium)
|
||||
include(deps/Boost)
|
||||
|
||||
add_subdirectory(external/antithesis-sdk)
|
||||
@@ -115,7 +114,6 @@ find_package(OpenSSL REQUIRED)
|
||||
find_package(secp256k1 REQUIRED)
|
||||
find_package(SOCI REQUIRED)
|
||||
find_package(SQLite3 REQUIRED)
|
||||
find_package(wasmi REQUIRED)
|
||||
find_package(xxHash REQUIRED)
|
||||
|
||||
target_link_libraries(
|
||||
@@ -142,6 +140,18 @@ if(rocksdb)
|
||||
target_link_libraries(xrpl_libs INTERFACE RocksDB::rocksdb)
|
||||
endif()
|
||||
|
||||
# OpenTelemetry distributed tracing (optional).
|
||||
# When ON, links against opentelemetry-cpp and defines XRPL_ENABLE_TELEMETRY
|
||||
# so that SpanGuard factory methods produce real OTel spans.
|
||||
# When OFF (default), all tracing code compiles to no-ops with zero overhead.
|
||||
# Enable via: conan install -o telemetry=True, or cmake -Dtelemetry=ON.
|
||||
option(telemetry "Enable OpenTelemetry tracing" ON)
|
||||
if(telemetry)
|
||||
find_package(opentelemetry-cpp CONFIG REQUIRED)
|
||||
add_compile_definitions(XRPL_ENABLE_TELEMETRY)
|
||||
message(STATUS "OpenTelemetry tracing enabled")
|
||||
endif()
|
||||
|
||||
# Work around changes to Conan recipe for now.
|
||||
if(TARGET nudb::core)
|
||||
set(nudb nudb::core)
|
||||
|
||||
@@ -373,6 +373,66 @@ run-clang-tidy -p build -quiet -fix -format -allow-no-checks src tests
|
||||
|
||||
`-format` reformats the fixed code with [`.clang-format`](./.clang-format); without it the fixes are inserted in LLVM style and the `clang-format` hook rewrites them afterwards.
|
||||
|
||||
## Telemetry span attribute naming
|
||||
|
||||
OpenTelemetry span attribute keys follow these rules so they stay consistent
|
||||
across the code, the OTel collector, Tempo, Grafana dashboards, and docs. The
|
||||
constants in the `*SpanNames.h` headers are the single source of truth; every
|
||||
other layer must match them. A CI check enforces this end to end.
|
||||
|
||||
1. Per-span unique attribute: bare field name — allowed when the field is
|
||||
recorded by a single span/workflow, so the span name already supplies the
|
||||
domain (e.g. `command`, `local`, `version` on `rpc.command` / `tx.process`).
|
||||
2. Shared attribute (same concept on more than one span): ONE key, reused
|
||||
verbatim on every span that records it — the span name tells the occurrences
|
||||
apart, so no per-emitter prefix is added. Pick the name by the field's
|
||||
meaning: a property of a domain object keeps that object's bare field name
|
||||
(`ledger_hash`, `ledger_seq`, `tx_hash`, `peer_id`, `full_validation`); a
|
||||
field already qualified by a sub-kind keeps that qualifier on every emitter
|
||||
(`proposal_trusted` on both `consensus.proposal.receive` and
|
||||
`peer.proposal.receive`; `validation_trusted` likewise). Define it once in
|
||||
the base `SpanNames.h` `namespace attr` block and re-export (`using`) it from
|
||||
each domain header, so all emitters share the exact string.
|
||||
3. Collision qualifier: `<domain>_<field>` — only when a bare name would collide
|
||||
with a DIFFERENT concept in the shared spanmetrics label space, or with the
|
||||
OTel-reserved `status` key (e.g. `rpc_status`, `grpc_status`,
|
||||
`consensus_phase`, `consensus_round`). This disambiguates distinct concepts
|
||||
that share a word; it is NOT used to tag the same concept with the workflow
|
||||
that emitted it — that is rule 2 (one shared name).
|
||||
4. Resource attribute: dotted `xrpl.<subsystem>.<field>` — reserved ONLY for
|
||||
process/network identity set once at startup (`xrpl.network.id`,
|
||||
`xrpl.network.type`). Never use the dotted `xrpl.` form for span attributes.
|
||||
5. Span names use `<subsystem>[.<component>]` (dotted). Only attribute _keys_
|
||||
follow rules 1–4.
|
||||
|
||||
All attribute keys are `lower_snake_case` (lowercase letters, digits, and
|
||||
underscores; each dot-separated segment of a resource key likewise). No
|
||||
camelCase, uppercase, or spaces.
|
||||
|
||||
Standard OpenTelemetry semantic-convention keys keep their canonical dotted
|
||||
form (e.g. `service.*` resource attributes, `http.*` span attributes); the
|
||||
"no dotted form" rule above applies to xrpl-custom keys, not to OTel-standard
|
||||
conventions.
|
||||
|
||||
Always reference the `*SpanNames.h` constants for attribute keys and span
|
||||
names — never pass a string literal as a key or as a `span`/`childSpan` name
|
||||
argument. (Attribute _values_ may be runtime data.)
|
||||
|
||||
These rules are enforced by `.github/scripts/otel-naming/check_otel_naming.py`,
|
||||
run in CI on every pull request. The check derives the set of valid keys
|
||||
directly from the `*SpanNames.h` constants and the resource attributes the code
|
||||
registers, so there is no separate list to keep in sync. It cross-validates the
|
||||
collector, Tempo, dashboards, and docs against those keys, and each rule runs
|
||||
only when the file it needs is present — so it works whether telemetry changes
|
||||
land in one pull request or several. Run it locally with:
|
||||
|
||||
```
|
||||
python .github/scripts/otel-naming/check_otel_naming.py
|
||||
```
|
||||
|
||||
See [.github/scripts/otel-naming/README.md](.github/scripts/otel-naming/README.md)
|
||||
for the full rule list.
|
||||
|
||||
## Contracts and instrumentation
|
||||
|
||||
We are using [Antithesis](https://antithesis.com/) for continuous fuzzing,
|
||||
|
||||
565
OpenTelemetryPlan/00-tracing-fundamentals.md
Normal file
565
OpenTelemetryPlan/00-tracing-fundamentals.md
Normal file
@@ -0,0 +1,565 @@
|
||||
# Distributed Tracing Fundamentals
|
||||
|
||||
> **Parent Document**: [OpenTelemetryPlan.md](./OpenTelemetryPlan.md)
|
||||
> **Next**: [Architecture Analysis](./01-architecture-analysis.md)
|
||||
|
||||
---
|
||||
|
||||
## What is Distributed Tracing?
|
||||
|
||||
Distributed tracing is a method for tracking data objects as they flow through distributed systems. In a network like XRP Ledger, a single transaction touches multiple independent nodes—each with no shared memory or logging. Distributed tracing connects these dots.
|
||||
|
||||
**Without tracing:** You see isolated logs on each node with no way to correlate them.
|
||||
|
||||
**With tracing:** You see the complete journey of a transaction or an event across all nodes it touched.
|
||||
|
||||
---
|
||||
|
||||
## Actors and Actions at a Glance
|
||||
|
||||
### Actors
|
||||
|
||||
| Who (Plain English) | Technical Term |
|
||||
| ---------------------------------------------- | --------------- |
|
||||
| A single unit of work being tracked | Span |
|
||||
| The complete journey of a request | Trace |
|
||||
| Data that links spans across services | Trace Context |
|
||||
| Code that creates spans and propagates context | Instrumentation |
|
||||
| Service that receives and processes traces | Collector |
|
||||
| Storage and visualization system | Backend (Tempo) |
|
||||
| Decision logic for which traces to keep | Sampler |
|
||||
|
||||
### Actions
|
||||
|
||||
| What Happens (Plain English) | Technical Term |
|
||||
| --------------------------------------- | ----------------------- |
|
||||
| Start tracking a new operation | Create a Span |
|
||||
| Connect a child operation to its parent | Set `parent_span_id` |
|
||||
| Group all related operations together | Share a `trace_id` |
|
||||
| Pass tracking data between services | Context Propagation |
|
||||
| Decide whether to record a trace | Sampling (Head or Tail) |
|
||||
| Send completed traces to storage | Export (OTLP) |
|
||||
|
||||
---
|
||||
|
||||
## Core Concepts
|
||||
|
||||
### 1. Trace
|
||||
|
||||
A **trace** represents the entire journey of a request through the system. It has a unique `trace_id` that stays constant across all nodes.
|
||||
|
||||
```
|
||||
Trace ID: abc123
|
||||
├── Node A: received transaction
|
||||
├── Node B: relayed transaction
|
||||
├── Node C: included in consensus
|
||||
└── Node D: applied to ledger
|
||||
```
|
||||
|
||||
### 2. Span
|
||||
|
||||
A **span** represents a single unit of work within a trace. Each span has:
|
||||
|
||||
| Attribute | Description | Example |
|
||||
| ---------------- | -------------------------------- | -------------------------- |
|
||||
| `trace_id` | Identifies the trace | `event123` |
|
||||
| `span_id` | Unique identifier | `span456` |
|
||||
| `parent_span_id` | Parent span (if any) | `p_span123` |
|
||||
| `name` | Operation name | `rpc.submit` |
|
||||
| `start_time` | When work began (local time) | `2024-01-15T10:30:00Z` |
|
||||
| `end_time` | When work completed (local time) | `2024-01-15T10:30:00.050Z` |
|
||||
| `attributes` | Key-value metadata | `tx_hash=ABC...` |
|
||||
| `status` | OK, ERROR MSG | `OK` |
|
||||
|
||||
### 3. Trace Context
|
||||
|
||||
**Trace context** is the data that propagates between services to link spans together. It contains:
|
||||
|
||||
- `trace_id` - The trace this span belongs to
|
||||
- `span_id` - The current span (becomes parent for child spans)
|
||||
- `trace_flags` - Sampling decisions
|
||||
|
||||
---
|
||||
|
||||
## How Spans Form a Trace
|
||||
|
||||
Spans have parent-child relationships forming a tree structure:
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph trace["Trace: abc123"]
|
||||
A["tx.submit<br/>span_id: 001<br/>50ms"] --> B["tx.validate<br/>span_id: 002<br/>5ms"]
|
||||
A --> C["tx.relay<br/>span_id: 003<br/>10ms"]
|
||||
A --> D["tx.apply<br/>span_id: 004<br/>30ms"]
|
||||
D --> E["ledger.update<br/>span_id: 005<br/>20ms"]
|
||||
end
|
||||
|
||||
style A fill:#0d47a1,stroke:#082f6a,color:#ffffff
|
||||
style B fill:#1b5e20,stroke:#0d3d14,color:#ffffff
|
||||
style C fill:#1b5e20,stroke:#0d3d14,color:#ffffff
|
||||
style D fill:#1b5e20,stroke:#0d3d14,color:#ffffff
|
||||
style E fill:#bf360c,stroke:#8c2809,color:#ffffff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **tx.submit (blue, root)**: The top-level span representing the entire transaction submission; all other spans are its descendants.
|
||||
- **tx.validate, tx.relay, tx.apply (green)**: Direct children of tx.submit, representing the three main stages -- validation, relay to peers, and application to the ledger.
|
||||
- **ledger.update (red)**: A grandchild span nested under tx.apply, representing the actual ledger state mutation triggered by applying the transaction.
|
||||
- **Arrows (parent to child)**: Each arrow indicates a parent-child span relationship where the parent's completion depends on the child finishing.
|
||||
|
||||
The same trace visualized as a **timeline (Gantt chart)**:
|
||||
|
||||
```
|
||||
Time → 0ms 10ms 20ms 30ms 40ms 50ms
|
||||
├───────────────────────────────────────────┤
|
||||
tx.submit│▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓│
|
||||
├─────┤
|
||||
tx.valid │▓▓▓▓▓│
|
||||
│ ├──────────┤
|
||||
tx.relay │ │▓▓▓▓▓▓▓▓▓▓│
|
||||
│ ├────────────────────────────┤
|
||||
tx.apply │ │▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓│
|
||||
│ ├──────────────────┤
|
||||
ledger │ │▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓│
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Span Relationships
|
||||
|
||||
Spans don't always form simple parent-child trees. Distributed tracing defines several relationship types to capture different causal patterns:
|
||||
|
||||
### 1. Parent-Child (ChildOf)
|
||||
|
||||
The default relationship. The parent span **depends on** or **contains** the child span. The child runs within the scope of the parent.
|
||||
|
||||
```
|
||||
tx.submit (parent)
|
||||
├── tx.validate (child) ← parent waits for this
|
||||
├── tx.relay (child) ← parent waits for this
|
||||
└── tx.apply (child) ← parent waits for this
|
||||
```
|
||||
|
||||
**When to use:** Synchronous calls, nested operations, any case where the parent's completion depends on the child.
|
||||
|
||||
### 2. Follows-From
|
||||
|
||||
A causal relationship where the first span **triggers** the second, but does **not wait** for it. The originator fires and moves on.
|
||||
|
||||
```
|
||||
Time →
|
||||
|
||||
tx.receive [=======]
|
||||
↓ triggers (follows-from)
|
||||
tx.relay [===========] ← runs independently
|
||||
```
|
||||
|
||||
**When to use:** Asynchronous jobs, queued work, fire-and-forget patterns. For example, a node receives a transaction and queues it for relay — the relay span _follows from_ the receive span but the receiver doesn't wait for relaying to complete.
|
||||
|
||||
> **OpenTracing** defined `FollowsFrom` as a first-class reference type alongside `ChildOf`.
|
||||
> **OpenTelemetry** represents this using **Span Links** with descriptive attributes instead (see below).
|
||||
|
||||
### 3. Span Links (Cross-Trace and Non-Hierarchical)
|
||||
|
||||
Links connect spans that are **causally related but not in a parent-child hierarchy**. Unlike parent-child, links can cross trace boundaries.
|
||||
|
||||
```
|
||||
Trace A Trace B
|
||||
────── ──────
|
||||
batch.schedule batch.execute
|
||||
├─ item.enqueue (span X) ┌──► process.item
|
||||
├─ item.enqueue (span Y) ───┤ (links to X, Y, Z)
|
||||
├─ item.enqueue (span Z) └──►
|
||||
```
|
||||
|
||||
**Use cases:**
|
||||
|
||||
| Pattern | Description |
|
||||
| -------------------- | --------------------------------------------------------------------------- |
|
||||
| **Batch processing** | A batch span links back to all individual spans that contributed to it |
|
||||
| **Fan-in** | An aggregation span links to the multiple producer spans it merges |
|
||||
| **Fan-out** | Multiple downstream spans link back to the single span that triggered them |
|
||||
| **Async handoff** | A deferred job links back to the request that queued it (follows-from) |
|
||||
| **Cross-trace** | Correlating spans across independent traces (e.g., retries, related events) |
|
||||
|
||||
**Link structure:** Each link carries the target span's context plus optional attributes:
|
||||
|
||||
```
|
||||
Link {
|
||||
trace_id: <target trace>
|
||||
span_id: <target span>
|
||||
attributes: { "link.description": "triggered by batch scheduler" }
|
||||
}
|
||||
```
|
||||
|
||||
### Relationship Summary
|
||||
|
||||
```mermaid
|
||||
flowchart LR
|
||||
subgraph parent_child["Parent-Child"]
|
||||
direction TB
|
||||
P["Parent"] --> C["Child"]
|
||||
end
|
||||
|
||||
subgraph follows_from["Follows-From"]
|
||||
direction TB
|
||||
A["Span A"] -.->|triggers| B["Span B"]
|
||||
end
|
||||
|
||||
subgraph links["Span Links"]
|
||||
direction TB
|
||||
X["Span X\n(Trace 1)"] -.-|link| Y["Span Y\n(Trace 2)"]
|
||||
end
|
||||
|
||||
parent_child ~~~ follows_from ~~~ links
|
||||
|
||||
style P fill:#0d47a1,stroke:#082f6a,color:#ffffff
|
||||
style C fill:#1b5e20,stroke:#0d3d14,color:#ffffff
|
||||
style A fill:#0d47a1,stroke:#082f6a,color:#ffffff
|
||||
style B fill:#bf360c,stroke:#8c2809,color:#ffffff
|
||||
style X fill:#4a148c,stroke:#38006b,color:#ffffff
|
||||
style Y fill:#4a148c,stroke:#38006b,color:#ffffff
|
||||
```
|
||||
|
||||
| Relationship | Same Trace? | Dependency? | OTel Mechanism |
|
||||
| ---------------- | ----------- | -------------------------- | ----------------- |
|
||||
| **Parent-Child** | Yes | Parent depends on child | `parent_span_id` |
|
||||
| **Follows-From** | Usually | Causal but no dependency | Link + attributes |
|
||||
| **Span Link** | Either | Correlation, no dependency | Link + attributes |
|
||||
|
||||
---
|
||||
|
||||
## Trace ID Generation
|
||||
|
||||
A `trace_id` is a 128-bit (16-byte) identifier that groups all spans belonging to one logical operation. How it's generated determines how easily you can find and correlate traces later.
|
||||
|
||||
### General Approaches
|
||||
|
||||
#### 1. Random (W3C Default)
|
||||
|
||||
Generate a random 128-bit ID when a trace starts. Standard approach for most services.
|
||||
|
||||
```
|
||||
trace_id = random_128_bits()
|
||||
```
|
||||
|
||||
| Pros | Cons |
|
||||
| --------------------------- | --------------------------------------------- |
|
||||
| Simple, standard | No natural correlation to domain events |
|
||||
| Guaranteed unique per trace | If propagation is lost, trace is broken |
|
||||
| Works with all OTel tooling | "Find trace for TX abc" requires index lookup |
|
||||
|
||||
#### 2. Deterministic (Derived from Domain Data)
|
||||
|
||||
Compute the trace_id from a hash of a natural identifier. Every node independently derives the **same** trace_id for the same event.
|
||||
|
||||
```
|
||||
trace_id = SHA-256(domain_identifier)[0:16] // truncate to 128 bits
|
||||
```
|
||||
|
||||
| Pros | Cons |
|
||||
| --------------------------------------------------- | ---------------------------------------------------------- |
|
||||
| Propagation-resilient — same ID computed everywhere | Same event processed twice (retry) shares trace_id |
|
||||
| Natural search — domain ID maps directly to trace | Non-standard (tooling assumes random) |
|
||||
| No coordination needed between nodes | 256→128 bit truncation (collision risk negligible at ~2⁶⁴) |
|
||||
|
||||
#### 3. Hybrid (Deterministic Prefix + Random Suffix)
|
||||
|
||||
First 8 bytes derived from domain data, last 8 bytes random.
|
||||
|
||||
```
|
||||
trace_id = SHA-256(domain_identifier)[0:8] || random_64_bits()
|
||||
```
|
||||
|
||||
| Pros | Cons |
|
||||
| ------------------------------------------- | ---------------------------------------- |
|
||||
| Prefix search: "find all traces for TX abc" | Must propagate to maintain full trace_id |
|
||||
| Unique per processing instance | More complex generation logic |
|
||||
| Retries get distinct trace_ids | Partial correlation only (prefix match) |
|
||||
|
||||
### XRPL Workflow Analysis
|
||||
|
||||
XRPL has a unique advantage: its core workflows produce **globally unique 256-bit hashes** that are known on every node. This makes deterministic trace_id generation practical in ways most systems can't achieve.
|
||||
|
||||
#### Natural Identifiers by Workflow
|
||||
|
||||
| Workflow | Natural Identifier | Size | Known at Start? | Same on All Nodes? |
|
||||
| ------------------- | --------------------------------- | ---------- | ----------------------------- | -------------------------------- |
|
||||
| **Transaction** | Transaction hash (`tid_`) | 256-bit | Yes — computed before signing | Yes — hash of canonical tx data |
|
||||
| **Consensus round** | Previous ledger hash + ledger seq | 256+32 bit | Yes — known when round opens | Yes — all validators agree |
|
||||
| **Validation** | Ledger hash being validated | 256-bit | Yes — from consensus result | Yes — same closed ledger |
|
||||
| **Ledger catch-up** | Target ledger hash | 256-bit | Yes — we know what to fetch | Yes — identifies ledger globally |
|
||||
|
||||
#### Where These Identifiers Live in Code
|
||||
|
||||
```
|
||||
Transaction: STTx::getTransactionID() → uint256 tid_
|
||||
TMTransaction::rawTransaction → recompute hash from bytes
|
||||
|
||||
Consensus: ConsensusProposal::previousLedger_ → uint256 (previous ledger hash)
|
||||
ConsensusProposal::position_ → uint256 (TxSet hash)
|
||||
LedgerHeader::seq → uint32_t (ledger sequence)
|
||||
|
||||
Validation: STValidation::getLedgerHash() → uint256
|
||||
STValidation::getNodeID() → NodeID (160-bit)
|
||||
|
||||
Ledger fetch: InboundLedger constructor → uint256 hash, uint32_t seq
|
||||
TMGetLedger::ledgerHash → bytes (uint256)
|
||||
```
|
||||
|
||||
### Recommended Strategy: Workflow-Scoped Deterministic
|
||||
|
||||
Each workflow type derives its trace_id from its natural domain identifier:
|
||||
|
||||
```
|
||||
Transaction trace: trace_id = SHA-256("tx" || tx_hash)[0:16]
|
||||
Consensus trace: trace_id = SHA-256("cons" || prev_ledger_hash || ledger_seq)[0:16]
|
||||
Ledger catch-up: trace_id = SHA-256("fetch" || target_ledger_hash)[0:16]
|
||||
```
|
||||
|
||||
The string prefix (`"tx"`, `"cons"`, `"fetch"`) prevents collisions between workflows that might share underlying hashes.
|
||||
|
||||
**Why this works for XRPL:**
|
||||
|
||||
1. **Propagation-resilient** — Even if a P2P message drops trace context, every node independently computes the same trace_id from the same tx_hash or ledger_hash. Spans still correlate.
|
||||
|
||||
2. **Zero-cost search** — "Show me the trace for transaction ABC" becomes a direct lookup: compute `SHA-256("tx" || ABC)[0:16]` and query. No secondary index needed.
|
||||
|
||||
3. **Cross-workflow linking via Span Links** — A consensus trace links to individual transaction traces. A validation span links to the consensus trace. This connects the full picture without forcing everything into one giant trace.
|
||||
|
||||
### Cross-Workflow Correlation
|
||||
|
||||
Each workflow gets its own trace. Span Links tie them together:
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph tx_trace["Transaction Trace"]
|
||||
direction LR
|
||||
Tn["trace_id = f(tx_hash)"]:::note --> T1["tx.receive"] --> T2["tx.validate"] --> T3["tx.relay"]
|
||||
end
|
||||
|
||||
subgraph cons_trace["Consensus Trace"]
|
||||
direction LR
|
||||
Cn["trace_id = f(prev_ledger, seq)"]:::note --> C1["cons.open"] --> C2["cons.propose"] --> C3["cons.accept"]
|
||||
end
|
||||
|
||||
subgraph val_trace["Validation"]
|
||||
direction LR
|
||||
Vn["spans within consensus trace"]:::note --> V1["val.create"] --> V2["val.broadcast"]
|
||||
end
|
||||
|
||||
subgraph fetch_trace["Catch-Up Trace"]
|
||||
direction LR
|
||||
Fn["trace_id = f(ledger_hash)"]:::note --> F1["fetch.request"] --> F2["fetch.receive"] --> F3["fetch.apply"]
|
||||
end
|
||||
|
||||
C1 -.-|"span link\n(tx traces)"| T3
|
||||
C3 --> V1
|
||||
F1 -.-|"span link\n(target ledger)"| C3
|
||||
|
||||
classDef note fill:none,stroke:#888,stroke-dasharray:5 5,color:#333,font-style:italic
|
||||
style T1 fill:#0d47a1,stroke:#082f6a,color:#ffffff
|
||||
style T2 fill:#0d47a1,stroke:#082f6a,color:#ffffff
|
||||
style T3 fill:#0d47a1,stroke:#082f6a,color:#ffffff
|
||||
style C1 fill:#1b5e20,stroke:#0d3d14,color:#ffffff
|
||||
style C2 fill:#1b5e20,stroke:#0d3d14,color:#ffffff
|
||||
style C3 fill:#1b5e20,stroke:#0d3d14,color:#ffffff
|
||||
style V1 fill:#bf360c,stroke:#8c2809,color:#ffffff
|
||||
style V2 fill:#bf360c,stroke:#8c2809,color:#ffffff
|
||||
style F1 fill:#4a148c,stroke:#38006b,color:#ffffff
|
||||
style F2 fill:#4a148c,stroke:#38006b,color:#ffffff
|
||||
style F3 fill:#4a148c,stroke:#38006b,color:#ffffff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **Transaction Trace (blue)**: An independent trace whose `trace_id` is deterministically derived from the transaction hash. Contains receive, validate, and relay spans.
|
||||
- **Consensus Trace (green)**: An independent trace whose `trace_id` is derived from the previous ledger hash and sequence number. Covers the open, propose, and accept phases.
|
||||
- **Validation (red)**: Validation spans live within the consensus trace (not a separate trace). They are created after the accept phase completes.
|
||||
- **Catch-Up Trace (purple)**: An independent trace for ledger acquisition, derived from the target ledger hash. Used when a node is behind and fetching missing ledgers.
|
||||
- **Dotted arrows (span links)**: Cross-trace correlations. Consensus links to transaction traces it included; catch-up links to the consensus trace that produced the target ledger.
|
||||
- **Solid arrow (C3 to V1)**: A parent-child relationship -- validation spans are direct children of the consensus accept span within the same trace.
|
||||
|
||||
**How a query flows:**
|
||||
|
||||
```
|
||||
"Why was TX abc slow?"
|
||||
1. Compute trace_id = SHA-256("tx" || abc)[0:16]
|
||||
2. Find transaction trace → see it was included in consensus round N
|
||||
3. Follow span link → consensus trace for round N
|
||||
4. See which phase was slow (propose? accept?)
|
||||
5. If a node was catching up, follow link → catch-up trace
|
||||
```
|
||||
|
||||
### Trade-offs to Consider
|
||||
|
||||
| Concern | Mitigation |
|
||||
| ----------------------------- | ----------------------------------------------------------------------------------------------------------------------------- |
|
||||
| **Retries get same trace_id** | Add `attempt` attribute to root span; spans have unique span_ids and timestamps |
|
||||
| **256→128 bit truncation** | Birthday-bound collision at ~2⁶⁴ operations — negligible for XRPL's throughput |
|
||||
| **Non-standard generation** | OTel spec allows any 16-byte non-zero value; tooling works on the hex string |
|
||||
| **Hash computation cost** | SHA-256 is ~0.3μs per call; XRPL already computes these hashes for other purposes |
|
||||
| **Late-binding identifiers** | Ledger hash isn't known until after consensus — validation spans use ledger_seq as fallback, then link to the consensus trace |
|
||||
|
||||
---
|
||||
|
||||
## Distributed Traces Across Nodes
|
||||
|
||||
In distributed systems like xrpld, traces span **multiple independent nodes**. The trace context must be propagated in network messages:
|
||||
|
||||
```mermaid
|
||||
sequenceDiagram
|
||||
participant Client
|
||||
participant NodeA as Node A
|
||||
participant NodeB as Node B
|
||||
participant NodeC as Node C
|
||||
|
||||
Client->>NodeA: Submit TX<br/>(no trace context)
|
||||
|
||||
Note over NodeA: Creates new trace<br/>trace_id: abc123<br/>span: tx.receive
|
||||
|
||||
NodeA->>NodeB: Relay TX<br/>(trace_id: abc123, parent: 001)
|
||||
|
||||
Note over NodeB: Creates child span<br/>span: tx.relay<br/>parent_span_id: 001
|
||||
|
||||
NodeA->>NodeC: Relay TX<br/>(trace_id: abc123, parent: 001)
|
||||
|
||||
Note over NodeC: Creates child span<br/>span: tx.relay<br/>parent_span_id: 001
|
||||
|
||||
Note over NodeA,NodeC: All spans share trace_id: abc123<br/>enabling correlation across nodes
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **Client**: The external entity that submits a transaction. It does not carry trace context -- the trace originates at the first node.
|
||||
- **Node A**: The entry point that creates a new trace (trace_id: abc123) and the root span `tx.receive`. It relays the transaction to peers with trace context attached.
|
||||
- **Node B and Node C**: Peer nodes that receive the relayed transaction along with the propagated trace context. Each creates a child span under Node A's span, preserving the same `trace_id`.
|
||||
- **Arrows with trace context**: The relay messages carry `trace_id` and `parent_span_id`, allowing each downstream node to link its spans back to the originating span on Node A.
|
||||
|
||||
---
|
||||
|
||||
## Context Propagation
|
||||
|
||||
For traces to work across nodes, **trace context must be propagated** in messages.
|
||||
|
||||
### What's in the Context (~26 bytes)
|
||||
|
||||
| Field | Size | Description |
|
||||
| ------------- | -------- | ------------------------------------------------------- |
|
||||
| `trace_id` | 16 bytes | Identifies the entire trace (constant across all nodes) |
|
||||
| `span_id` | 8 bytes | The sender's current span (becomes parent on receiver) |
|
||||
| `trace_flags` | 1 byte | Sampling decision (bit 0 = sampled; bits 1-7 reserved) |
|
||||
| `trace_state` | variable | Optional vendor-specific data (typically omitted) |
|
||||
|
||||
### How span_id Changes at Each Hop
|
||||
|
||||
Only **one** `span_id` travels in the context - the sender's current span. Each node:
|
||||
|
||||
1. Extracts the received `span_id` and uses it as the `parent_span_id`
|
||||
2. Creates a **new** `span_id` for its own span
|
||||
3. Sends its own `span_id` as the parent when forwarding
|
||||
|
||||
```
|
||||
Node A Node B Node C
|
||||
────── ────── ──────
|
||||
|
||||
Span AAA Span BBB Span CCC
|
||||
│ │ │
|
||||
▼ ▼ ▼
|
||||
Context out: Context out: Context out:
|
||||
├─ trace_id: abc123 ├─ trace_id: abc123 ├─ trace_id: abc123
|
||||
├─ span_id: AAA ──────────► ├─ span_id: BBB ──────────► ├─ span_id: CCC ──────►
|
||||
└─ flags: 01 └─ flags: 01 └─ flags: 01
|
||||
│ │
|
||||
parent = AAA parent = BBB
|
||||
```
|
||||
|
||||
The `trace_id` stays constant, but `span_id` **changes at every hop** to maintain the parent-child chain.
|
||||
|
||||
### Propagation Formats
|
||||
|
||||
There are two patterns:
|
||||
|
||||
### HTTP/RPC Headers (W3C Trace Context)
|
||||
|
||||
```
|
||||
traceparent: 00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01
|
||||
│ │ │ │
|
||||
│ │ │ └── Flags (sampled)
|
||||
│ │ └── Parent span ID (16 hex)
|
||||
│ └── Trace ID (32 hex)
|
||||
└── Version
|
||||
```
|
||||
|
||||
### Protocol Buffers (xrpld P2P messages)
|
||||
|
||||
xrpld P2P messages such as `TMTransaction` carry the trace context in two added byte fields alongside the existing payload: `trace_parent` holds the W3C traceparent (`trace_id`, `span_id`, and `trace_flags`), and `trace_state` holds the optional W3C tracestate. Together they propagate the trace across the P2P boundary so a receiving node can attach its spans to the sender's span.
|
||||
|
||||
---
|
||||
|
||||
## Sampling
|
||||
|
||||
Not every trace needs to be recorded. **Sampling** reduces overhead:
|
||||
|
||||
### Head Sampling (at trace start)
|
||||
|
||||
```
|
||||
Request arrives → Random N% chance → Record or skip entire trace
|
||||
```
|
||||
|
||||
- ✅ Low overhead
|
||||
- ❌ May miss interesting traces
|
||||
|
||||
> **xrpld note**: xrpld intentionally fixes head sampling at 100% (sample
|
||||
> everything) and does not expose a configurable ratio. A per-node ratio
|
||||
> would let different nodes make divergent keep/drop decisions for the same
|
||||
> distributed trace, producing broken/partial traces. xrpld uses a
|
||||
> `ParentBased` sampler so spans with a remote parent honor the upstream
|
||||
> decision. Volume reduction is delegated to collector-side tail sampling.
|
||||
|
||||
### Tail Sampling (after trace completes)
|
||||
|
||||
```
|
||||
Trace completes → Collector evaluates:
|
||||
- Error? → KEEP
|
||||
- Slow? → KEEP
|
||||
- Normal? → Sample 10%
|
||||
```
|
||||
|
||||
- ✅ Never loses important traces
|
||||
- ❌ Higher memory usage at collector
|
||||
|
||||
---
|
||||
|
||||
## Key Benefits for xrpld
|
||||
|
||||
| Challenge | How Tracing Helps |
|
||||
| ---------------------------------- | ---------------------------------------- |
|
||||
| "Where is my transaction?" | Follow trace across all nodes it touched |
|
||||
| "Why was consensus slow?" | See timing breakdown of each phase |
|
||||
| "Which node is the bottleneck?" | Compare span durations across nodes |
|
||||
| "What happened during the outage?" | Correlate errors across the network |
|
||||
|
||||
---
|
||||
|
||||
## Glossary
|
||||
|
||||
| Term | Definition |
|
||||
| -------------------- | ------------------------------------------------------------------- |
|
||||
| **Trace** | Complete journey of a request, identified by `trace_id` |
|
||||
| **Span** | Single operation within a trace |
|
||||
| **Parent-Child** | Span relationship where the parent depends on the child |
|
||||
| **Follows-From** | Causal relationship where originator doesn't wait for the result |
|
||||
| **Span Link** | Non-hierarchical connection between spans, possibly across traces |
|
||||
| **Deterministic ID** | Trace ID derived from domain data (e.g., tx_hash) instead of random |
|
||||
| **Context** | Data propagated between services (`trace_id`, `span_id`, flags) |
|
||||
| **Instrumentation** | Code that creates spans and propagates context |
|
||||
| **Collector** | Service that receives, processes, and exports traces |
|
||||
| **Backend** | Storage/visualization system (Tempo) |
|
||||
| **Head Sampling** | Sampling decision at trace start |
|
||||
| **Tail Sampling** | Sampling decision after trace completes |
|
||||
|
||||
---
|
||||
|
||||
_Next: [Architecture Analysis](./01-architecture-analysis.md)_ | _Back to: [Overview](./OpenTelemetryPlan.md)_
|
||||
467
OpenTelemetryPlan/01-architecture-analysis.md
Normal file
467
OpenTelemetryPlan/01-architecture-analysis.md
Normal file
@@ -0,0 +1,467 @@
|
||||
# Architecture Analysis
|
||||
|
||||
> **Parent Document**: [OpenTelemetryPlan.md](./OpenTelemetryPlan.md)
|
||||
> **Related**: [Design Decisions](./02-design-decisions.md) | [Implementation Strategy](./03-implementation-strategy.md)
|
||||
|
||||
---
|
||||
|
||||
## 1.1 Current xrpld Architecture Overview
|
||||
|
||||
> **WS** = WebSocket | **UNL** = Unique Node List | **TxQ** = Transaction Queue | **StatsD** = Statistics Daemon
|
||||
|
||||
The xrpld node software consists of several interconnected components that need instrumentation for distributed tracing:
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph xrpld["xrpld Node"]
|
||||
subgraph services["Core Services"]
|
||||
RPC["RPC Server<br/>(HTTP/WS/gRPC)"]
|
||||
Overlay["Overlay<br/>(P2P Network)"]
|
||||
Consensus["Consensus<br/>(RCLConsensus)"]
|
||||
ValidatorList["ValidatorList<br/>(UNL Mgmt)"]
|
||||
end
|
||||
|
||||
JobQueue["JobQueue<br/>(Thread Pool)"]
|
||||
|
||||
subgraph processing["Processing Layer"]
|
||||
NetworkOPs["NetworkOPs<br/>(Tx Processing)"]
|
||||
LedgerMaster["LedgerMaster<br/>(Ledger Mgmt)"]
|
||||
NodeStore["NodeStore<br/>(Database)"]
|
||||
InboundLedgers["InboundLedgers<br/>(Ledger Sync)"]
|
||||
end
|
||||
|
||||
subgraph appservices["Application Services"]
|
||||
PathFind["PathFinding<br/>(Payment Paths)"]
|
||||
TxQ["TxQ<br/>(Fee Escalation)"]
|
||||
LoadMgr["LoadManager<br/>(Fee/Load)"]
|
||||
end
|
||||
|
||||
subgraph observability["Existing Observability"]
|
||||
PerfLog["PerfLog<br/>(JSON)"]
|
||||
Insight["Insight<br/>(StatsD)"]
|
||||
Logging["Logging<br/>(Journal)"]
|
||||
end
|
||||
|
||||
services --> JobQueue
|
||||
JobQueue --> processing
|
||||
JobQueue --> appservices
|
||||
end
|
||||
|
||||
style xrpld fill:#424242,stroke:#212121,color:#ffffff
|
||||
style services fill:#1565c0,stroke:#0d47a1,color:#ffffff
|
||||
style processing fill:#2e7d32,stroke:#1b5e20,color:#ffffff
|
||||
style appservices fill:#6a1b9a,stroke:#4a148c,color:#ffffff
|
||||
style observability fill:#e65100,stroke:#bf360c,color:#ffffff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **Core Services (blue)**: The entry points into xrpld -- RPC Server handles client requests, Overlay manages peer-to-peer networking, Consensus drives agreement, and ValidatorList manages trusted validators.
|
||||
- **JobQueue (center)**: The asynchronous thread pool that decouples Core Services from the Processing and Application layers. All work flows through it.
|
||||
- **Processing Layer (green)**: Core business logic -- NetworkOPs processes transactions, LedgerMaster manages ledger state, NodeStore handles persistence, and InboundLedgers synchronizes missing data.
|
||||
- **Application Services (purple)**: Higher-level features -- PathFinding computes payment routes, TxQ manages fee-based queuing, and LoadManager tracks server load.
|
||||
- **Existing Observability (orange)**: The current monitoring stack (PerfLog, Insight, Journal logging) that OpenTelemetry will complement, not replace.
|
||||
- **Arrows (Services to JobQueue to layers)**: Work originates at Core Services, is enqueued onto the JobQueue, and dispatched to Processing or Application layers for execution.
|
||||
|
||||
---
|
||||
|
||||
## 1.1.1 Actors and Actions
|
||||
|
||||
### Actors
|
||||
|
||||
| Who (Plain English) | Technical Term |
|
||||
| ----------------------------------------- | -------------------------- |
|
||||
| Network node running XRPL software | xrpld node |
|
||||
| External client submitting requests | RPC Client |
|
||||
| Network neighbor sharing data | Peer (PeerImp) |
|
||||
| Request handler for client queries | RPC Server (ServerHandler) |
|
||||
| Command executor for specific RPC methods | RPCHandler |
|
||||
| Agreement process between nodes | Consensus (RCLConsensus) |
|
||||
| Transaction processing coordinator | NetworkOPs |
|
||||
| Background task scheduler | JobQueue |
|
||||
| Ledger state manager | LedgerMaster |
|
||||
| Payment route calculator | PathFinding (Pathfinder) |
|
||||
| Transaction waiting room | TxQ (Transaction Queue) |
|
||||
| Fee adjustment system | LoadManager |
|
||||
| Trusted validator list manager | ValidatorList |
|
||||
| Protocol upgrade tracker | AmendmentTable |
|
||||
| Ledger state hash tree | SHAMap |
|
||||
| Persistent key-value storage | NodeStore |
|
||||
|
||||
### Actions
|
||||
|
||||
| What Happens (Plain English) | Technical Term |
|
||||
| ---------------------------------------------- | ---------------------- |
|
||||
| Client sends a request to a node | `rpc.request` |
|
||||
| Node executes a specific RPC command | `rpc.command.*` |
|
||||
| Node receives a transaction from a peer | `tx.receive` |
|
||||
| Node checks if a transaction is valid | `tx.validate` |
|
||||
| Node forwards a transaction to neighbors | `tx.relay` |
|
||||
| Nodes agree on which transactions to include | `consensus.round` |
|
||||
| Consensus progresses through phases | `consensus.phase.*` |
|
||||
| Node builds a new confirmed ledger | `ledger.build` |
|
||||
| Node fetches missing ledger data from peers | `ledger.acquire` |
|
||||
| Node computes payment routes | `pathfind.compute` |
|
||||
| Node queues a transaction for later processing | `txq.enqueue` |
|
||||
| Node increases fees due to high load | `fee.escalate` |
|
||||
| Node fetches the latest trusted validator list | `validator.list.fetch` |
|
||||
| Node votes on a protocol amendment | `amendment.vote` |
|
||||
| Node synchronizes state tree data | `shamap.sync` |
|
||||
|
||||
---
|
||||
|
||||
## 1.2 Key Components for Instrumentation
|
||||
|
||||
> **TxQ** = Transaction Queue | **UNL** = Unique Node List
|
||||
|
||||
| Component | Location | Purpose | Trace Value |
|
||||
| ------------------ | ------------------------------------------ | ------------------------ | -------------------------------- |
|
||||
| **Overlay** | `src/xrpld/overlay/` | P2P communication | Message propagation timing |
|
||||
| **PeerImp** | `src/xrpld/overlay/detail/PeerImp.cpp` | Individual peer handling | Per-peer latency |
|
||||
| **RCLConsensus** | `src/xrpld/app/consensus/RCLConsensus.cpp` | Consensus algorithm | Round timing, phase analysis |
|
||||
| **NetworkOPs** | `src/xrpld/app/misc/NetworkOPs.cpp` | Transaction processing | Tx lifecycle tracking |
|
||||
| **ServerHandler** | `src/xrpld/rpc/detail/ServerHandler.cpp` | RPC entry point | Request latency |
|
||||
| **RPCHandler** | `src/xrpld/rpc/detail/RPCHandler.cpp` | Command execution | Per-command timing |
|
||||
| **JobQueue** | `src/xrpl/core/JobQueue.h` | Async task execution | Queue wait times |
|
||||
| **PathFinding** | `src/xrpld/app/paths/` | Payment path computation | Path latency, cache hits |
|
||||
| **TxQ** | `src/xrpld/app/misc/TxQ.cpp` | Transaction queue/fees | Queue depth, eviction rates |
|
||||
| **LoadManager** | `src/xrpld/app/main/LoadManager.cpp` | Fee escalation/load | Fee levels, load factors |
|
||||
| **InboundLedgers** | `src/xrpld/app/ledger/InboundLedgers.cpp` | Ledger acquisition | Sync time, peer reliability |
|
||||
| **ValidatorList** | `src/xrpld/app/misc/ValidatorList.cpp` | UNL management | List freshness, fetch failures |
|
||||
| **AmendmentTable** | `src/xrpld/app/misc/AmendmentTable.cpp` | Protocol amendments | Voting status, activation events |
|
||||
| **SHAMap** | `src/xrpld/shamap/` | State hash tree | Sync speed, missing nodes |
|
||||
|
||||
---
|
||||
|
||||
## 1.3 Transaction Flow Diagram
|
||||
|
||||
Transaction flow spans multiple nodes in the network. Each node creates linked spans to form a distributed trace:
|
||||
|
||||
```mermaid
|
||||
sequenceDiagram
|
||||
participant Client
|
||||
participant PeerA as Peer A (Receive)
|
||||
participant PeerB as Peer B (Relay)
|
||||
participant PeerC as Peer C (Validate)
|
||||
|
||||
Client->>PeerA: 1. Submit TX
|
||||
|
||||
rect rgb(230, 245, 255)
|
||||
Note over PeerA: tx.receive SPAN START
|
||||
PeerA->>PeerA: HashRouter Deduplication
|
||||
PeerA->>PeerA: tx.validate (child span)
|
||||
end
|
||||
|
||||
PeerA->>PeerB: 2. Relay TX (with trace ctx)
|
||||
|
||||
rect rgb(230, 245, 255)
|
||||
Note over PeerB: tx.receive (linked span)
|
||||
end
|
||||
|
||||
PeerB->>PeerC: 3. Relay TX
|
||||
|
||||
rect rgb(230, 245, 255)
|
||||
Note over PeerC: tx.receive (linked span)
|
||||
PeerC->>PeerC: tx.process
|
||||
end
|
||||
|
||||
Note over Client,PeerC: DISTRIBUTED TRACE (same trace_id: abc123)
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **Client**: The external entity that submits a transaction to Peer A. It has no trace context -- the trace starts at the first node.
|
||||
- **Peer A (Receive)**: The entry node that creates the root span `tx.receive`, runs HashRouter deduplication to avoid processing duplicates, and creates a child `tx.validate` span.
|
||||
- **Peer A to Peer B arrow**: The relay message carries trace context (trace_id + parent span_id), enabling Peer B to create a linked span under the same trace.
|
||||
- **Peer B (Relay)**: Receives the transaction and trace context, creates a `tx.receive` span linked to Peer A's trace, then relays onward.
|
||||
- **Peer C (Validate)**: Final hop in this example. Creates a linked `tx.receive` span and runs `tx.process` to fully process the transaction.
|
||||
- **Blue rectangles**: Highlight the span boundaries on each node, showing where instrumentation creates and closes spans.
|
||||
|
||||
### Trace Structure
|
||||
|
||||
```
|
||||
trace_id: abc123
|
||||
├── span: tx.receive (Peer A)
|
||||
│ ├── span: tx.validate
|
||||
│ └── span: tx.relay
|
||||
├── span: tx.receive (Peer B) [parent: Peer A]
|
||||
│ └── span: tx.relay
|
||||
└── span: tx.receive (Peer C) [parent: Peer B]
|
||||
└── span: tx.process
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 1.4 Consensus Round Flow
|
||||
|
||||
Consensus rounds are multi-phase operations that benefit significantly from tracing:
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph round["consensus.round (root span)"]
|
||||
attrs["Attributes:<br/>ledger_seq = 12345678<br/>consensus_mode = proposing<br/>proposers = 35"]
|
||||
|
||||
subgraph open["consensus.phase.open"]
|
||||
open_desc["Duration: ~3s<br/>Waiting for transactions"]
|
||||
end
|
||||
|
||||
subgraph establish["consensus.phase.establish"]
|
||||
est_attrs["proposals_received = 28<br/>disputes_resolved = 3"]
|
||||
est_children["├── consensus.proposal.receive (×28)<br/>├── consensus.proposal.send (×1)<br/>└── consensus.dispute.resolve (×3)"]
|
||||
end
|
||||
|
||||
subgraph accept["consensus.phase.accept"]
|
||||
acc_attrs["transactions_applied = 150<br/>ledger_hash = DEF456..."]
|
||||
acc_children["├── ledger.build<br/>└── ledger.validate"]
|
||||
end
|
||||
|
||||
attrs --> open
|
||||
open --> establish
|
||||
establish --> accept
|
||||
end
|
||||
|
||||
style round fill:#f57f17,stroke:#e65100,color:#ffffff
|
||||
style open fill:#1565c0,stroke:#0d47a1,color:#ffffff
|
||||
style establish fill:#2e7d32,stroke:#1b5e20,color:#ffffff
|
||||
style accept fill:#c2185b,stroke:#880e4f,color:#ffffff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **consensus.round (orange, root span)**: The top-level span encompassing the entire consensus round, with attributes like ledger sequence, mode, and proposer count.
|
||||
- **consensus.phase.open (blue)**: The first phase where the node waits (~3s) to collect incoming transactions before proposing.
|
||||
- **consensus.phase.establish (green)**: The negotiation phase where validators exchange proposals, resolve disputes, and converge on a transaction set. Child spans track each proposal received/sent and each dispute resolved.
|
||||
- **consensus.phase.accept (pink)**: The final phase where the agreed transaction set is applied, a new ledger is built, and the ledger is validated. Child spans cover `ledger.build` and `ledger.validate`.
|
||||
- **Arrows (open to establish to accept)**: The sequential flow through the three consensus phases. Each phase must complete before the next begins.
|
||||
|
||||
---
|
||||
|
||||
## 1.5 RPC Request Flow
|
||||
|
||||
> **WS** = WebSocket
|
||||
|
||||
RPC requests support W3C Trace Context headers for distributed tracing across services:
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph request["rpc.request (root span)"]
|
||||
http["HTTP Request — POST /<br/>traceparent:<br/>00-abc123...-def456...-01"]
|
||||
|
||||
attrs["Attributes:<br/>http.method = POST<br/>net.peer.ip = 192.168.1.100<br/>command = submit"]
|
||||
|
||||
subgraph enqueue["jobqueue.enqueue"]
|
||||
job_attr["job_type = jtCLIENT_RPC"]
|
||||
end
|
||||
|
||||
subgraph command["rpc.command.submit"]
|
||||
cmd_attrs["version = 2<br/>rpc_role = user"]
|
||||
cmd_children["├── tx.deserialize<br/>├── tx.validate_local<br/>└── tx.submit_to_network"]
|
||||
end
|
||||
|
||||
response["Response: 200 OK<br/>Duration: 45ms"]
|
||||
|
||||
http --> attrs
|
||||
attrs --> enqueue
|
||||
enqueue --> command
|
||||
command --> response
|
||||
end
|
||||
|
||||
style request fill:#2e7d32,stroke:#1b5e20,color:#ffffff
|
||||
style enqueue fill:#1565c0,stroke:#0d47a1,color:#ffffff
|
||||
style command fill:#e65100,stroke:#bf360c,color:#ffffff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **rpc.request (green, root span)**: The outermost span representing the full RPC request lifecycle, from HTTP receipt to response. Carries the W3C `traceparent` header for distributed tracing.
|
||||
- **HTTP Request node**: Shows the incoming POST request with its `traceparent` header and extracted attributes (method, peer IP, command name).
|
||||
- **jobqueue.enqueue (blue)**: The span covering the asynchronous handoff from the RPC thread to the JobQueue worker thread. The trace context is preserved across this async boundary.
|
||||
- **rpc.command.submit (orange)**: The span for the actual command execution, with child spans for deserialization, local validation, and network submission.
|
||||
- **Response node**: The final output with HTTP status and total duration, marking the end of the root span.
|
||||
- **Arrows (top to bottom)**: The sequential processing pipeline -- receive request, extract attributes, enqueue job, execute command, return response.
|
||||
|
||||
---
|
||||
|
||||
## 1.6 Key Trace Points
|
||||
|
||||
> **TxQ** = Transaction Queue
|
||||
|
||||
The following table identifies priority instrumentation points across the codebase:
|
||||
|
||||
| Category | Span Name | File | Method | Priority |
|
||||
| --------------- | ---------------------- | ---------------------- | ----------------------- | -------- |
|
||||
| **Transaction** | `tx.receive` | `PeerImp.cpp` | `handleTransaction()` | High |
|
||||
| **Transaction** | `tx.validate` | `NetworkOPs.cpp` | `processTransaction()` | High |
|
||||
| **Transaction** | `tx.process` | `NetworkOPs.cpp` | `doTransactionSync()` | High |
|
||||
| **Transaction** | `tx.relay` | `OverlayImpl.cpp` | `relay()` | Medium |
|
||||
| **Consensus** | `consensus.round` | `RCLConsensus.cpp` | `startRound()` | High |
|
||||
| **Consensus** | `consensus.phase.*` | `Consensus.h` | `timerEntry()` | High |
|
||||
| **Consensus** | `consensus.proposal.*` | `RCLConsensus.cpp` | `peerProposal()` | Medium |
|
||||
| **RPC** | `rpc.request` | `ServerHandler.cpp` | `onRequest()` | High |
|
||||
| **RPC** | `rpc.command.*` | `RPCHandler.cpp` | `doCommand()` | High |
|
||||
| **Peer** | `peer.connect` | `OverlayImpl.cpp` | `onHandoff()` | Low |
|
||||
| **Peer** | `peer.message.*` | `PeerImp.cpp` | `onMessage()` | Low |
|
||||
| **Ledger** | `ledger.acquire` | `InboundLedgers.cpp` | `acquire()` | Medium |
|
||||
| **Ledger** | `ledger.build` | `RCLConsensus.cpp` | `buildLCL()` | High |
|
||||
| **PathFinding** | `pathfind.request` | `PathRequest.cpp` | `doUpdate()` | High |
|
||||
| **PathFinding** | `pathfind.compute` | `Pathfinder.cpp` | `findPaths()` | High |
|
||||
| **TxQ** | `txq.enqueue` | `TxQ.cpp` | `apply()` | High |
|
||||
| **TxQ** | `txq.apply` | `TxQ.cpp` | `processClosedLedger()` | High |
|
||||
| **Fee** | `fee.escalate` | `LoadManager.cpp` | `raiseLocalFee()` | Medium |
|
||||
| **Ledger** | `ledger.replay` | `LedgerReplayer.h` | `replay()` | Medium |
|
||||
| **Ledger** | `ledger.delta` | `LedgerDeltaAcquire.h` | `processData()` | Medium |
|
||||
| **Validator** | `validator.list.fetch` | `ValidatorList.cpp` | `verify()` | Medium |
|
||||
| **Validator** | `validator.manifest` | `Manifest.cpp` | `applyManifest()` | Low |
|
||||
| **Amendment** | `amendment.vote` | `AmendmentTable.cpp` | `doVoting()` | Low |
|
||||
| **SHAMap** | `shamap.sync` | `SHAMap.cpp` | `fetchRoot()` | Medium |
|
||||
|
||||
---
|
||||
|
||||
## 1.7 Instrumentation Priority
|
||||
|
||||
> **TxQ** = Transaction Queue
|
||||
|
||||
```mermaid
|
||||
quadrantChart
|
||||
title Instrumentation Priority Matrix
|
||||
x-axis Low Complexity --> High Complexity
|
||||
y-axis Low Value --> High Value
|
||||
quadrant-1 Implement First
|
||||
quadrant-2 Plan Carefully
|
||||
quadrant-3 Quick Wins
|
||||
quadrant-4 Consider Later
|
||||
|
||||
RPC Tracing: [0.2, 0.92]
|
||||
Transaction Tracing: [0.55, 0.88]
|
||||
Consensus Tracing: [0.78, 0.82]
|
||||
PathFinding: [0.38, 0.75]
|
||||
TxQ and Fees: [0.25, 0.65]
|
||||
Ledger Sync: [0.62, 0.58]
|
||||
Peer Message Tracing: [0.35, 0.25]
|
||||
JobQueue Tracing: [0.2, 0.48]
|
||||
Validator Mgmt: [0.48, 0.42]
|
||||
Amendment Tracking: [0.15, 0.32]
|
||||
SHAMap Operations: [0.72, 0.45]
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 1.8 Observable Outcomes
|
||||
|
||||
> **TxQ** = Transaction Queue | **UNL** = Unique Node List
|
||||
|
||||
After implementing OpenTelemetry, operators and developers will gain visibility into the following:
|
||||
|
||||
### 1.8.1 What You Will See: Traces
|
||||
|
||||
| Trace Type | Description | Example Query in Grafana/Tempo |
|
||||
| -------------------------- | ------------------------------------------------------------------------------------------- | ----------------------------------------------- |
|
||||
| **Transaction Lifecycle** | Full journey from RPC submission through validation, relay, consensus, and ledger inclusion | `{service.name="xrpld" && tx_hash="ABC123..."}` |
|
||||
| **Cross-Node Propagation** | Transaction path across multiple xrpld nodes with timing | `{relay_count > 0}` |
|
||||
| **Consensus Rounds** | Complete round with all phases (open, establish, accept) | `{span.name=~"consensus.round.*"}` |
|
||||
| **RPC Request Processing** | Individual command execution with timing breakdown | `{command="account_info"}` |
|
||||
| **Ledger Acquisition** | Peer-to-peer ledger data requests and responses | `{span.name="ledger.acquire"}` |
|
||||
| **PathFinding Latency** | Path computation time and cache effectiveness for payment RPCs | `{span.name="pathfind.compute"}` |
|
||||
| **TxQ Behavior** | Queue depth, eviction patterns, fee escalation during congestion | `{span.name=~"txq.*"}` |
|
||||
| **Ledger Sync** | Full acquisition timeline including delta and transaction fetches | `{span.name=~"ledger.acquire.*"}` |
|
||||
| **Validator Health** | UNL fetch success, manifest updates, stale list detection | `{span.name=~"validator.*"}` |
|
||||
|
||||
### 1.8.2 What You Will See: Metrics (Derived from Traces)
|
||||
|
||||
| Metric | Description | Dashboard Panel |
|
||||
| ----------------------------- | --------------------------------------- | --------------------------- |
|
||||
| **RPC Latency (p50/p95/p99)** | Response time distribution per command | Heatmap by command |
|
||||
| **Transaction Throughput** | Transactions processed per second | Time series graph |
|
||||
| **Consensus Round Duration** | Time to complete consensus phases | Histogram |
|
||||
| **Cross-Node Latency** | Time for transaction to reach N nodes | Line chart with percentiles |
|
||||
| **Error Rate** | Failed transactions/RPC calls by type | Stacked bar chart |
|
||||
| **PathFinding Latency** | Path computation time per currency pair | Heatmap by currency |
|
||||
| **TxQ Depth** | Queued transactions over time | Time series with thresholds |
|
||||
| **Fee Escalation Level** | Current fee multiplier | Gauge with alert thresholds |
|
||||
| **Ledger Sync Duration** | Time to acquire missing ledgers | Histogram |
|
||||
|
||||
### 1.8.3 Concrete Dashboard Examples
|
||||
|
||||
**Transaction Trace View (Tempo):**
|
||||
|
||||
```
|
||||
┌────────────────────────────────────────────────────────────────────────────────┐
|
||||
│ Trace: abc123... (Transaction Submission) Duration: 847ms │
|
||||
├────────────────────────────────────────────────────────────────────────────────┤
|
||||
│ ├── rpc.request [ServerHandler] ████░░░░░░ 45ms │
|
||||
│ │ └── rpc.command.submit [RPCHandler] ████░░░░░░ 42ms │
|
||||
│ │ └── tx.receive [NetworkOPs] ███░░░░░░░ 35ms │
|
||||
│ │ ├── tx.validate [TxQ] █░░░░░░░░░ 8ms │
|
||||
│ │ └── tx.relay [Overlay] ██░░░░░░░░ 15ms │
|
||||
│ │ ├── tx.receive [Node-B] █████░░░░░ 52ms │
|
||||
│ │ │ └── tx.relay [Node-B] ██░░░░░░░░ 18ms │
|
||||
│ │ └── tx.receive [Node-C] ██████░░░░ 65ms │
|
||||
│ └── consensus.round [RCLConsensus] ████████░░ 720ms │
|
||||
│ ├── consensus.phase.open ██░░░░░░░░ 180ms │
|
||||
│ ├── consensus.phase.establish █████░░░░░ 480ms │
|
||||
│ └── consensus.phase.accept █░░░░░░░░░ 60ms │
|
||||
└────────────────────────────────────────────────────────────────────────────────┘
|
||||
```
|
||||
|
||||
**RPC Performance Dashboard Panel:**
|
||||
|
||||
```
|
||||
┌─────────────────────────────────────────────────────────────┐
|
||||
│ RPC Command Latency (Last 1 Hour) │
|
||||
├─────────────────────────────────────────────────────────────┤
|
||||
│ Command │ p50 │ p95 │ p99 │ Errors │ Rate │
|
||||
│──────────────────┼────────┼────────┼────────┼────────┼──────│
|
||||
│ account_info │ 12ms │ 45ms │ 89ms │ 0.1% │ 150/s│
|
||||
│ submit │ 35ms │ 120ms │ 250ms │ 2.3% │ 45/s│
|
||||
│ ledger │ 8ms │ 25ms │ 55ms │ 0.0% │ 80/s│
|
||||
│ tx │ 15ms │ 50ms │ 100ms │ 0.5% │ 60/s│
|
||||
│ server_info │ 5ms │ 12ms │ 20ms │ 0.0% │ 200/s│
|
||||
└─────────────────────────────────────────────────────────────┘
|
||||
```
|
||||
|
||||
**Consensus Health Dashboard Panel:**
|
||||
|
||||
```mermaid
|
||||
---
|
||||
config:
|
||||
xyChart:
|
||||
width: 1200
|
||||
height: 400
|
||||
plotReservedSpacePercent: 50
|
||||
chartOrientation: vertical
|
||||
themeVariables:
|
||||
xyChart:
|
||||
plotColorPalette: "#3498db"
|
||||
---
|
||||
xychart-beta
|
||||
title "Consensus Round Duration (Last 24 Hours)"
|
||||
x-axis "Time of Day (Hours)" [0, 2, 4, 6, 8, 10, 12, 14, 16, 18, 20, 22, 24]
|
||||
y-axis "Duration (seconds)" 1 --> 5
|
||||
line [2.1, 2.4, 2.8, 3.2, 3.8, 4.3, 4.5, 5.0, 4.7, 4.0, 3.2, 2.6, 2.0]
|
||||
```
|
||||
|
||||
### 1.8.4 Operator Actionable Insights
|
||||
|
||||
| Scenario | What You'll See | Action |
|
||||
| ------------------------- | ---------------------------------------------------------------------------- | ------------------------------------------------ |
|
||||
| **Slow RPC** | Span showing which phase is slow (parsing, execution, serialization) | Optimize specific code path |
|
||||
| **Transaction Stuck** | Trace stops at validation; error attribute shows reason | Fix transaction parameters |
|
||||
| **Consensus Delay** | Phase.establish taking too long; proposer attribute shows missing validators | Investigate network connectivity |
|
||||
| **Memory Spike** | Large batch of spans correlating with memory increase | Tune batch_size or sampling |
|
||||
| **Network Partition** | Traces missing cross-node links for specific peer | Check peer connectivity |
|
||||
| **Path Computation Slow** | pathfind.compute span shows high latency; cache miss rate in attributes | Warm the RippleLineCache, check order book depth |
|
||||
| **TxQ Full** | txq.enqueue spans show evictions; fee.escalate spans increasing | Monitor fee levels, alert operators |
|
||||
| **Ledger Sync Stalled** | ledger.acquire spans timing out; peer reliability attributes show issues | Check peer connectivity, add trusted peers |
|
||||
| **UNL Stale** | validator.list.fetch spans failing; last_update attribute aging | Verify validator site URLs, check DNS |
|
||||
|
||||
### 1.8.5 Developer Debugging Workflow
|
||||
|
||||
1. **Find Transaction**: Query by `tx_hash` to get full trace
|
||||
2. **Identify Bottleneck**: Look at span durations to find slowest component
|
||||
3. **Check Attributes**: Review `validity`, `rpc_status` for errors
|
||||
4. **Correlate Logs**: Use `trace_id` to find related PerfLog entries
|
||||
5. **Compare Nodes**: Filter by `service.instance.id` to compare behavior across nodes
|
||||
|
||||
---
|
||||
|
||||
_Next: [Design Decisions](./02-design-decisions.md)_ | _Back to: [Overview](./OpenTelemetryPlan.md)_
|
||||
705
OpenTelemetryPlan/02-design-decisions.md
Normal file
705
OpenTelemetryPlan/02-design-decisions.md
Normal file
@@ -0,0 +1,705 @@
|
||||
# Design Decisions
|
||||
|
||||
> **Parent Document**: [OpenTelemetryPlan.md](./OpenTelemetryPlan.md)
|
||||
> **Related**: [Architecture Analysis](./01-architecture-analysis.md)
|
||||
|
||||
---
|
||||
|
||||
## 2.1 OpenTelemetry Components
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
### 2.1.1 SDK Selection
|
||||
|
||||
**Primary Choice**: OpenTelemetry C++ SDK (`opentelemetry-cpp`)
|
||||
|
||||
| Component | Purpose | Required |
|
||||
| --------------------------------------- | ---------------------- | ------------------------- |
|
||||
| `opentelemetry-cpp::api` | Tracing API headers | Yes |
|
||||
| `opentelemetry-cpp::sdk` | SDK implementation | Yes |
|
||||
| `opentelemetry-cpp::ext` | Extensions (exporters) | Yes |
|
||||
| `opentelemetry-cpp::otlp_http_exporter` | OTLP/HTTP export | Yes (shipped in Phase 1b) |
|
||||
| `opentelemetry-cpp::otlp_grpc_exporter` | OTLP/gRPC export | Future (not yet wired up) |
|
||||
|
||||
### 2.1.2 Instrumentation Strategy
|
||||
|
||||
**Manual Instrumentation** (recommended):
|
||||
|
||||
| Approach | Pros | Cons |
|
||||
| ---------- | --------------------------------------------------------------- | ------------------------------------------------------- |
|
||||
| **Manual** | Precise control, optimized placement, xrpld-specific attributes | More development effort |
|
||||
| **Auto** | Less code, automatic coverage | Less control, potential overhead, limited customization |
|
||||
|
||||
---
|
||||
|
||||
## 2.2 Exporter Configuration
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph nodes["xrpld Nodes"]
|
||||
node1["xrpld<br/>Node 1"]
|
||||
node2["xrpld<br/>Node 2"]
|
||||
node3["xrpld<br/>Node 3"]
|
||||
end
|
||||
|
||||
collector["OpenTelemetry<br/>Collector<br/>(sidecar or standalone)"]
|
||||
|
||||
subgraph backends["Observability Backends"]
|
||||
tempo["Tempo"]
|
||||
elastic["Elastic<br/>APM"]
|
||||
end
|
||||
|
||||
node1 -->|"OTLP/HTTP<br/>:4318"| collector
|
||||
node2 -->|"OTLP/HTTP<br/>:4318"| collector
|
||||
node3 -->|"OTLP/HTTP<br/>:4318"| collector
|
||||
|
||||
collector --> tempo
|
||||
collector --> elastic
|
||||
|
||||
style nodes fill:#0d47a1,stroke:#082f6a,color:#ffffff
|
||||
style backends fill:#1b5e20,stroke:#0d3d14,color:#ffffff
|
||||
style collector fill:#bf360c,stroke:#8c2809,color:#ffffff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **xrpld Nodes (blue)**: The source of telemetry data. Each xrpld node exports spans via OTLP/HTTP on port 4318 (the only exporter shipped in Phase 1b).
|
||||
- **OpenTelemetry Collector (red)**: The central aggregation point that receives spans from all nodes. Can run as a sidecar (per-node) or standalone (shared). Handles batching, filtering, and routing.
|
||||
- **Observability Backends (green)**: The storage and visualization destinations. Tempo is the recommended backend for both development and production, and Elastic APM is an alternative. The Collector routes to one or more backends.
|
||||
- **Arrows (nodes to collector to backends)**: The data pipeline -- spans flow from nodes to the Collector over HTTP, then the Collector fans out to the configured backends.
|
||||
|
||||
### 2.2.1 OTLP/HTTP (Shipped in Phase 1b)
|
||||
|
||||
OTLP/HTTP is the only exporter wired up in Phase 1b. It is configured via
|
||||
`OtlpHttpExporterOptions` with the collector traces endpoint
|
||||
(`http://localhost:4318/v1/traces` by default) and a JSON content type
|
||||
(binary protobuf is also available).
|
||||
|
||||
### 2.2.2 OTLP/gRPC (Future Work — Planned Upgrade)
|
||||
|
||||
OTLP/gRPC is planned as a future upgrade from the HTTP exporter. The gRPC
|
||||
transport offers lower per-span overhead and tighter back-pressure semantics
|
||||
than HTTP/JSON, making it attractive for production deployments once the HTTP
|
||||
path is validated in earlier phases.
|
||||
|
||||
Required to land this upgrade:
|
||||
|
||||
1. Add `opentelemetry-cpp::otlp_grpc_exporter` to the Conan recipe (the
|
||||
dependency already exists but is not linked in Phase 1b builds).
|
||||
2. Extend `TelemetryConfig.cpp` to parse an `exporter` key (`otlp_http`
|
||||
default, `otlp_grpc` opt-in) and a gRPC endpoint override.
|
||||
3. In `Telemetry::start()` branch on the parsed exporter type and construct
|
||||
either `OtlpHttpExporterFactory::Create(httpOpts)` or
|
||||
`OtlpGrpcExporterFactory::Create(grpcOpts)` accordingly.
|
||||
4. Update the runbook and dashboards to document the alternate port and TLS
|
||||
settings.
|
||||
|
||||
When wired up, the gRPC path will use `OtlpGrpcExporterOptions` configured with
|
||||
the collector endpoint (host on port 4317), TLS credentials enabled, and a CA
|
||||
certificate path.
|
||||
|
||||
Until that work lands, `OtlpGrpcExporterOptions` is **not** used by any code
|
||||
path in Phase 1b through Phase 5.
|
||||
|
||||
---
|
||||
|
||||
## 2.3 Span Naming Conventions
|
||||
|
||||
> **TxQ** = Transaction Queue | **UNL** = Unique Node List | **WS** = WebSocket
|
||||
|
||||
### 2.3.1 Naming Schema
|
||||
|
||||
```
|
||||
<component>.<operation>[.<sub-operation>]
|
||||
```
|
||||
|
||||
**Examples**:
|
||||
|
||||
- `tx.receive` - Transaction received from peer
|
||||
- `consensus.phase.establish` - Consensus establish phase
|
||||
- `rpc.command.server_info` - server_info RPC command
|
||||
|
||||
### 2.3.2 Complete Span Catalog
|
||||
|
||||
| Span name | Description |
|
||||
| ------------------------------ | --------------------------------------- |
|
||||
| `tx.receive` | Transaction received from network |
|
||||
| `tx.validate` | Transaction signature/format validation |
|
||||
| `tx.process` | Full transaction processing |
|
||||
| `tx.relay` | Transaction relay to peers |
|
||||
| `tx.apply` | Apply transaction to ledger |
|
||||
| `consensus.round` | Complete consensus round |
|
||||
| `consensus.phase.open` | Open phase - collecting transactions |
|
||||
| `consensus.phase.establish` | Establish phase - reaching agreement |
|
||||
| `consensus.phase.accept` | Accept phase - applying consensus |
|
||||
| `consensus.proposal.receive` | Receive peer proposal |
|
||||
| `consensus.proposal.send` | Send our proposal |
|
||||
| `consensus.validation.receive` | Receive peer validation |
|
||||
| `consensus.validation.send` | Send our validation |
|
||||
| `rpc.request` | HTTP/WebSocket request handling |
|
||||
| `rpc.command.*` | Specific RPC command (dynamic) |
|
||||
| `peer.connect` | Peer connection establishment |
|
||||
| `peer.disconnect` | Peer disconnection |
|
||||
| `peer.message.send` | Send protocol message |
|
||||
| `peer.message.receive` | Receive protocol message |
|
||||
| `ledger.acquire` | Ledger acquisition from network |
|
||||
| `ledger.build` | Build new ledger |
|
||||
| `ledger.validate` | Ledger validation |
|
||||
| `ledger.close` | Close ledger |
|
||||
| `ledger.replay` | Ledger replay executed |
|
||||
| `ledger.delta` | Delta-based ledger acquired |
|
||||
| `pathfind.request` | Path request initiated |
|
||||
| `pathfind.compute` | Path computation executed |
|
||||
| `txq.enqueue` | Transaction queued |
|
||||
| `txq.apply` | Queued transaction applied |
|
||||
| `fee.escalate` | Fee escalation triggered |
|
||||
| `validator.list.fetch` | UNL list fetched |
|
||||
| `validator.manifest` | Manifest update processed |
|
||||
| `amendment.vote` | Amendment voting executed |
|
||||
| `shamap.sync` | State tree synchronization |
|
||||
| `job.enqueue` | Job added to queue |
|
||||
| `job.execute` | Job execution |
|
||||
|
||||
### 2.3.3 Attribute Naming Conventions
|
||||
|
||||
Span **names** follow §2.3.1 (dotted `<component>.<operation>`). Span
|
||||
**attribute keys** follow the rules below. The constants in the `*SpanNames.h`
|
||||
headers are the single source of truth; the collector, Tempo, the Grafana
|
||||
dashboards, and the runbook all consume these exact keys, so every layer must
|
||||
agree with the code. A CI check enforces this end to end.
|
||||
|
||||
1. **Per-span unique attribute** → bare field name, allowed when the field is
|
||||
recorded by a single span/workflow so the span name already supplies the
|
||||
domain (e.g. `command`, `version`, `local` on `rpc.command`).
|
||||
2. **Shared attribute (same concept on more than one span)** → ONE key, reused
|
||||
verbatim on every span that records it; the span name tells the occurrences
|
||||
apart, so no per-emitter prefix is added. Name it by the field's meaning: a
|
||||
property of a domain object keeps that object's bare field name (`ledger_hash`,
|
||||
`ledger_seq`, `tx_hash`, `peer_id`, `full_validation`); a field already
|
||||
qualified by a sub-kind keeps that qualifier on every emitter (`proposal_trusted`
|
||||
on both `consensus.proposal.receive` and `peer.proposal.receive`;
|
||||
`validation_trusted` likewise). Defined once in the base `SpanNames.h`
|
||||
`namespace attr` block and re-exported (`using`) by each domain header.
|
||||
3. **Collision qualifier** → `<domain>_<field>`, only when a bare name would
|
||||
collide with a DIFFERENT concept in the shared spanmetrics label space or with
|
||||
the OTel-reserved `status` key (e.g. `rpc_status`, `grpc_status`,
|
||||
`consensus_phase`, `consensus_round`, `consensus_mode`). This disambiguates
|
||||
distinct concepts that share a word; it is NOT used to tag the same concept
|
||||
with its emitting workflow — that is rule 2 (one shared name).
|
||||
4. **Resource attribute** → dotted `xrpl.<subsystem>.<field>`, reserved ONLY
|
||||
for process/network identity set once at startup (`xrpl.network.id`,
|
||||
`xrpl.network.type`). Span attributes are never dotted in the `xrpl.` form —
|
||||
it blurs the resource/span scope boundary and parses awkwardly in TraceQL.
|
||||
5. **Span names** use `<subsystem>[.<component>]` (dotted, per §2.3.1). Only
|
||||
attribute _keys_ follow rules 1–4.
|
||||
|
||||
Standard OpenTelemetry semantic-convention keys keep their canonical dotted
|
||||
form (e.g. `service.*` resource attributes, `http.*` span attributes); the
|
||||
"no dotted form" rule applies to xrpl-custom keys only.
|
||||
|
||||
The same rules are recorded in `CONTRIBUTING.md` (the permanent home, since
|
||||
`OpenTelemetryPlan/` is removed once the rollout completes). The attribute
|
||||
examples in §2.4 below follow these rules.
|
||||
|
||||
---
|
||||
|
||||
## 2.4 Attribute Schema
|
||||
|
||||
> **TxQ** = Transaction Queue | **UNL** = Unique Node List | **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
### 2.4.1 Resource Attributes (Set Once at Startup)
|
||||
|
||||
Resource attributes identify the process and are set once at startup. They use
|
||||
the standard OpenTelemetry semantic conventions plus custom dotted `xrpl.*`
|
||||
keys (the dotted form is reserved for resource scope per §2.3.3).
|
||||
|
||||
| Key | Type / value | Description |
|
||||
| --------------------- | ------------------------------------------------------- | ------------------------------ |
|
||||
| `service.name` | `"xrpld"` | Standard `SERVICE_NAME` |
|
||||
| `service.version` | `build_info::getVersionString()` | Standard `SERVICE_VERSION` |
|
||||
| `service.instance.id` | node public key (base58) | Standard `SERVICE_INSTANCE_ID` |
|
||||
| `xrpl.network.id` | network id (e.g. 0 for mainnet) | Network identifier |
|
||||
| `xrpl.network.type` | `"mainnet"` \| `"testnet"` \| `"devnet"` \| `"unknown"` | Network kind |
|
||||
| `xrpl.node.type` | `"validator"` \| `"stock"` \| `"reporting"` | Node role |
|
||||
| `xrpl.node.cluster` | cluster name | Cluster name, if clustered |
|
||||
|
||||
### 2.4.2 Span Attributes by Category
|
||||
|
||||
> Span attribute keys use the underscore form from §2.3.3 (shared/qualified
|
||||
> keys are `<domain>_<field>`; per-span unique keys are bare). The dotted form
|
||||
> is reserved for the resource attributes in §2.4.1 above. This catalog lists
|
||||
> the planned attribute set by category; the exact emitted key for each
|
||||
> implemented span is defined by the `*SpanNames.h` constants, which are the
|
||||
> single source of truth where the two differ.
|
||||
|
||||
#### Transaction Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| -------------------- | ------ | ------------------------------------- |
|
||||
| `tx_hash` | string | Transaction hash (hex) |
|
||||
| `tx_type` | string | `"Payment"`, `"OfferCreate"`, etc. |
|
||||
| `tx_account` | string | Source account (redacted in prod) |
|
||||
| `tx_sequence` | int64 | Account sequence number |
|
||||
| `tx_fee` | int64 | Fee in drops |
|
||||
| `tx_result` | string | `"tesSUCCESS"`, `"tecPATH_DRY"`, etc. |
|
||||
| `current_ledger_seq` | int64 | Open ledger the transaction targeted |
|
||||
| `relay_count` | int64 | Peers the transaction was relayed to |
|
||||
| `suppressed` | bool | `true` when HashRouter dropped a dup |
|
||||
|
||||
> **Note:** `current_ledger_seq` and `ledger_seq` are the same concept — a ledger's sequence number — but they name different ledgers, so the design keeps two keys rather than one. `current_ledger_seq` is the open or in-flight ledger a transaction's work was applied into; it is named after the RPC field `ledger_current_index`. `ledger_seq` (see [Ledger & Job Attributes](#ledger--job-attributes)) is a closed or validated ledger, set by the ledger and consensus spans. Neither is spelled `ledger_index`: per rule 2 of [Telemetry span attribute naming](../CONTRIBUTING.md#telemetry-span-attribute-naming), one concept gets one key reused verbatim, and a different referent is disambiguated with a prefix rather than a synonym.
|
||||
|
||||
#### Consensus Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| -------------------- | ------- | ----------------------------------- |
|
||||
| `consensus_round` | int64 | Round number |
|
||||
| `consensus_phase` | string | `"open"`, `"establish"`, `"accept"` |
|
||||
| `consensus_mode` | string | `"proposing"`, `"observing"`, etc. |
|
||||
| `proposers` | int64 | Number of proposers |
|
||||
| `prev_ledger_prefix` | string | Previous ledger hash prefix |
|
||||
| `ledger_seq` | int64 | Ledger sequence |
|
||||
| `tx_count` | int64 | Transactions in consensus set |
|
||||
| `round_time_ms` | float64 | Round duration |
|
||||
|
||||
Establish-phase gap fill and cross-node correlation attributes (Phase 4a):
|
||||
|
||||
| Key | Type | Description |
|
||||
| --------------------- | ------ | --------------------------------------------------------- |
|
||||
| `consensus_round_id` | int64 | Consensus round number |
|
||||
| `consensus_ledger_id` | string | `previousLedger.id()` — shared across nodes |
|
||||
| `trace_strategy` | string | `"deterministic"` or `"random"` |
|
||||
| `converge_percent` | int64 | Convergence % (0-100+) |
|
||||
| `establish_count` | int64 | Number of establish iterations |
|
||||
| `disputes_count` | int64 | Active disputed transactions |
|
||||
| `agree_count` | int64 | Peers that agree (haveConsensus) |
|
||||
| `disagree_count` | int64 | Peers that disagree |
|
||||
| `threshold_percent` | int64 | Close-time consensus threshold (`avCT_CONSENSUS_PCT`=75%) |
|
||||
| `consensus_result` | string | `"yes"`, `"no"`, `"moved_on"`, `"expired"` |
|
||||
| `mode_old` | string | Previous consensus mode |
|
||||
| `mode_new` | string | New consensus mode |
|
||||
|
||||
#### RPC Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| ------------- | ------- | ----------------------------------------------------------------------------- |
|
||||
| `command` | string | Command name (per-span unique on `rpc.command`) |
|
||||
| `version` | int64 | API version |
|
||||
| `rpc_role` | string | `"admin"` or `"user"` (qualified — `role` is generic) |
|
||||
| `params` | string | Sanitized parameters (optional) |
|
||||
| `rpc_status` | string | Response status: `success` \| `error` (qualified — `status` is OTel-reserved) |
|
||||
| `duration_ms` | float64 | Request duration in milliseconds |
|
||||
|
||||
#### Peer & Message Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| -------------------- | ------- | -------------------------- |
|
||||
| `peer_id` | string | Peer public key (base58) |
|
||||
| `peer_address` | string | IP:port |
|
||||
| `peer_latency_ms` | float64 | Measured latency |
|
||||
| `peer_cluster` | string | Cluster name if clustered |
|
||||
| `message_type` | string | Protocol message type name |
|
||||
| `message_size_bytes` | int64 | Message size |
|
||||
| `message_compressed` | bool | Whether compressed |
|
||||
|
||||
#### Ledger & Job Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| --------------------------- | ------- | -------------------------------- |
|
||||
| `ledger_hash` | string | Ledger hash |
|
||||
| `ledger_seq` | int64 | Closed/validated ledger sequence |
|
||||
| `close_time_ripple_epoch_s` | int64 | Close time (XRPL epoch seconds) |
|
||||
| `ledger_tx_count` | int64 | Transaction count |
|
||||
| `job_type` | string | Job type name |
|
||||
| `job_queue_ms` | float64 | Time spent in queue |
|
||||
| `job_worker` | int64 | Worker thread ID |
|
||||
|
||||
#### PathFinding Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| -------------------------- | ------ | ------------------------- |
|
||||
| `pathfind_source_currency` | string | Source currency code |
|
||||
| `pathfind_dest_currency` | string | Destination currency code |
|
||||
| `pathfind_path_count` | int64 | Number of paths found |
|
||||
| `pathfind_cache_hit` | bool | RippleLineCache hit |
|
||||
|
||||
#### TxQ Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| --------------------- | ------ | --------------------------- |
|
||||
| `txq_queue_depth` | int64 | Current queue depth |
|
||||
| `txq_fee_level` | int64 | Fee level of transaction |
|
||||
| `txq_eviction_reason` | string | Why transaction was evicted |
|
||||
|
||||
#### Fee Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| ---------------------- | ----- | ------------------------- |
|
||||
| `fee_load_factor` | int64 | Current load factor |
|
||||
| `fee_escalation_level` | int64 | Fee escalation multiplier |
|
||||
|
||||
#### Validator Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| ------------------------ | ----- | ------------------------- |
|
||||
| `validator_list_size` | int64 | UNL size |
|
||||
| `validator_list_age_sec` | int64 | Seconds since last update |
|
||||
|
||||
#### Amendment Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| ------------------ | ------ | -------------------------------------- |
|
||||
| `amendment_name` | string | Amendment name |
|
||||
| `amendment_status` | string | `"enabled"`, `"vetoed"`, `"supported"` |
|
||||
|
||||
#### SHAMap Attributes
|
||||
|
||||
| Key | Type | Description |
|
||||
| ---------------------- | ------- | --------------------------------------------- |
|
||||
| `shamap_type` | string | `"transaction"`, `"state"`, `"account_state"` |
|
||||
| `shamap_missing_nodes` | int64 | Number of missing nodes during sync |
|
||||
| `shamap_duration_ms` | float64 | Sync duration |
|
||||
|
||||
### 2.4.3 Data Collection Summary
|
||||
|
||||
The following table summarizes what data is collected by category:
|
||||
|
||||
| Category | Attributes Collected | Purpose |
|
||||
| --------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------- |
|
||||
| **Transaction** | `tx_hash`, `tx_type`, `tx_result`, `tx_fee`, `current_ledger_seq` | Trace transaction lifecycle |
|
||||
| **Consensus** | `consensus_round`, `consensus_phase`, `consensus_mode`, `proposers`, `round_time_ms` | Analyze consensus timing |
|
||||
| **RPC** | `command`, `version`, `rpc_status`, `duration_ms` | Monitor RPC performance |
|
||||
| **Peer** | `peer_id` (public key), `peer_latency_ms`, `message_type`, `message_size_bytes` | Network topology analysis |
|
||||
| **Ledger** | `ledger_hash`, `ledger_seq`, `close_time`, `ledger_tx_count` | Ledger progression tracking |
|
||||
| **Job** | `job_type`, `job_queue_ms`, `job_worker` | JobQueue performance |
|
||||
| **PathFinding** | `pathfind_fast`, `pathfind_search_level`, `pathfind_num_paths`, `pathfind_ledger_index`, `pathfind_num_requests` | Payment path analysis |
|
||||
| **TxQ** | `txq_queue_depth`, `txq_fee_level`, `txq_eviction_reason` | Queue depth and fee tracking |
|
||||
| **Fee** | `fee_load_factor`, `fee_escalation_level` | Fee escalation monitoring |
|
||||
| **Validator** | `validator_list_size`, `validator_list_age_sec` | UNL health monitoring |
|
||||
| **Amendment** | `amendment_name`, `amendment_status` | Protocol upgrade tracking |
|
||||
| **SHAMap** | `shamap_type`, `shamap_missing_nodes`, `shamap_duration_ms` | State tree sync performance |
|
||||
|
||||
### 2.4.4 Privacy & Sensitive Data Policy
|
||||
|
||||
> **PII** = Personally Identifiable Information
|
||||
|
||||
OpenTelemetry instrumentation is designed to collect **operational metadata only**, never sensitive content.
|
||||
|
||||
#### Data NOT Collected
|
||||
|
||||
The following data is explicitly **excluded** from telemetry collection:
|
||||
|
||||
| Excluded Data | Reason |
|
||||
| ----------------------- | ----------------------------------------- |
|
||||
| **Private Keys** | Never exposed; not relevant to tracing |
|
||||
| **Account Balances** | Financial data; privacy sensitive |
|
||||
| **Transaction Amounts** | Financial data; privacy sensitive |
|
||||
| **Raw TX Payloads** | May contain sensitive memo/data fields |
|
||||
| **Personal Data** | No PII collected |
|
||||
| **IP Addresses** | Configurable; excluded by default in prod |
|
||||
|
||||
#### Privacy Protection Mechanisms
|
||||
|
||||
| Mechanism | Description |
|
||||
| ----------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||
| **Account Hashing** | Account addresses are hashed both SDK-side (`pathfind_source_account`, `pathfind_dest_account` — always hashed before emission) and again at the collector level, so raw addresses never reach storage |
|
||||
| **Configurable Redaction** | Sensitive fields can be excluded via `[telemetry]` config section |
|
||||
| **Collector Tail Sampling** | xrpld head sampling is fixed at 1.0 (every span emitted); the collector retains ~10% of non-error traces, reducing stored data exposure |
|
||||
| **Sampling** | Only 10% of traces recorded by default, reducing data exposure |
|
||||
| **Local Control** | Node operators have full control over what gets exported |
|
||||
| **No Raw Payloads** | Transaction content is never recorded, only metadata (hash, type, result) |
|
||||
| **Collector-Level Filtering** | Additional redaction/hashing can be configured at OTel Collector |
|
||||
|
||||
#### Account Address Hashing
|
||||
|
||||
Account addresses are **always** hashed before they reach the telemetry
|
||||
backend — there is no opt-out flag and therefore no insecure-by-default
|
||||
failure mode. Protection is applied in two independent layers:
|
||||
|
||||
1. **SDK-side** (this node): the path-finding RPC handlers call
|
||||
`redactAccount()` (`xrpl::telemetry`, `Redaction.h`) before setting the
|
||||
`pathfind_source_account` / `pathfind_dest_account` span attributes. The
|
||||
helper emits the first 16 characters of `sha512Half(address)` as
|
||||
lowercase hex — deterministic (spans for one account still correlate)
|
||||
but non-reversible.
|
||||
2. **Collector-side** (defense-in-depth): an `attributes/hash` processor in
|
||||
the OpenTelemetry Collector re-hashes those same attributes, so any node
|
||||
that emitted a raw value is still redacted before storage.
|
||||
|
||||
#### Collector-Level Data Protection
|
||||
|
||||
The OpenTelemetry Collector can be configured (via an `attributes` processor)
|
||||
to hash or redact sensitive attributes before export — for example, hashing
|
||||
`pathfind_source_account` / `pathfind_dest_account`, deleting `peer_address`
|
||||
to drop IP addresses, and deleting `params` to redact request parameters.
|
||||
|
||||
#### Configuration Options for Privacy
|
||||
|
||||
In `xrpld.cfg`, operators control data collection granularity through the
|
||||
`[telemetry]` section. Besides `enabled`, per-component toggles
|
||||
(`trace_transactions`, `trace_consensus`, `trace_rpc`, `trace_peer` — the last
|
||||
often disabled due to high volume) select which spans are emitted. Account
|
||||
address hashing is not configurable: addresses are hashed unconditionally by
|
||||
the SDK helper described above, with collector-level hashing as a second
|
||||
layer.
|
||||
|
||||
> **Key Principle**: Telemetry collects **operational metadata** (timing, counts, hashes) — never **sensitive content** (keys, balances, amounts, raw payloads).
|
||||
|
||||
> **See also**: [Securing the OTel Pipeline](./secure-OTel.md) covers transport-level protection for telemetry leaving the node — mTLS to the collector and validation of incoming peer trace context. Privacy controls in this section keep sensitive data out of spans; the security doc keeps the spans themselves out of untrusted hands.
|
||||
|
||||
---
|
||||
|
||||
## 2.5 Context Propagation Design
|
||||
|
||||
> **WS** = WebSocket
|
||||
|
||||
### 2.5.0 Deterministic Trace ID Strategy
|
||||
|
||||
Both transaction and consensus tracing use **deterministic trace IDs** derived from
|
||||
a globally known hash, so all nodes handling the same workflow independently produce
|
||||
spans under the same `trace_id`. This is combined with protobuf `span_id` propagation
|
||||
for parent-child relay ordering when available.
|
||||
|
||||
#### Transactions — `trace_id = txHash[0:16]`
|
||||
|
||||
Every node that handles a transaction knows its `txID` (the `uint256` transaction
|
||||
hash). The first 16 bytes of this hash are used as the OTel `trace_id`:
|
||||
|
||||
```
|
||||
uint256 txHash: A1B2C3D4 E5F6A7B8 C9D0E1F2 A3B4C5D6 E7F8A9B0 C1D2E3F4 A5B6C7D8 E9F0A1B2
|
||||
|---------- trace_id (16 bytes) ---------| (remaining 16 bytes unused)
|
||||
```
|
||||
|
||||
Each node generates a **random 8-byte `span_id`** so its span is unique within the
|
||||
shared trace. When protobuf `TraceContext` is present in the incoming `TMTransaction`,
|
||||
the sender's `span_id` is extracted and used as the parent — preserving the relay
|
||||
chain as a parent-child tree. When absent (older peers, first hop from client), the
|
||||
span appears as a root in the same trace — correlation is preserved, only the tree
|
||||
structure degrades.
|
||||
|
||||
```
|
||||
Node A (submitter) Node B (relay) Node C (relay)
|
||||
trace_id: A1B2... trace_id: A1B2... trace_id: A1B2...
|
||||
span_id: 1234 (random) span_id: 5678 (random) span_id: 9ABC (random)
|
||||
parent: (none) parent: 1234 (proto) parent: 5678 (proto)
|
||||
↑ ↑
|
||||
protobuf propagation protobuf propagation
|
||||
```
|
||||
|
||||
If protobuf propagation fails at Node B (old peer):
|
||||
|
||||
```
|
||||
Node A Node B (old peer) Node C
|
||||
trace_id: A1B2... trace_id: A1B2... trace_id: A1B2...
|
||||
span_id: 1234 span_id: 5678 span_id: 9ABC
|
||||
parent: (none) parent: (none) parent: 5678 (proto)
|
||||
↑ no parent, but same trace_id — still grouped
|
||||
```
|
||||
|
||||
#### Consensus — `trace_id = prevLedgerHash[0:16]`
|
||||
|
||||
All validators in the same consensus round share the same `previousLedger.id()`.
|
||||
The first 16 bytes are used as trace_id. See [Phase 4a implementation status](./06-implementation-phases.md)
|
||||
and `createDeterministicContext()` in `RCLConsensus.cpp` for the implementation.
|
||||
|
||||
Switchable via `consensus_trace_strategy` config:
|
||||
`"deterministic"` (default) or `"random"` (random trace_id, correlation via attribute queries).
|
||||
`"random"` is experimental and not used: it would break cross-node trace correlation.
|
||||
|
||||
#### Why Not Random IDs with Propagation Only?
|
||||
|
||||
Random trace IDs require **unbroken context propagation** across every hop. In a
|
||||
mixed-version network (common during upgrades), older peers silently drop the
|
||||
`trace_context` protobuf field. The trace splits and downstream spans become
|
||||
impossible to find. Deterministic IDs make correlation **propagation-resilient** — the trace
|
||||
backend groups all spans for the same transaction/round regardless of whether
|
||||
propagation succeeded.
|
||||
|
||||
#### Why Keep Protobuf Propagation?
|
||||
|
||||
Deterministic trace IDs alone provide correlation (all spans grouped) but not
|
||||
**causality** (which node relayed to which). Protobuf `span_id` propagation adds
|
||||
parent-child ordering that shows the exact relay path. The two mechanisms complement
|
||||
each other:
|
||||
|
||||
| Mechanism | Provides | Fails when |
|
||||
| ---------------------------- | --------------------------- | -------------------------------------- |
|
||||
| Deterministic trace_id | Cross-node correlation | Never (hash is always known) |
|
||||
| Protobuf span_id propagation | Parent-child relay ordering | Older peer drops `trace_context` field |
|
||||
|
||||
#### Implementation Reference
|
||||
|
||||
The utility function `createDeterministicTxContext(uint256 const& txHash)` follows
|
||||
the same pattern as `createDeterministicContext(uint256 const& ledgerId)` in
|
||||
`RCLConsensus.cpp`. See [Phase 3 Task 3.9](./Phase3_taskList.md) for the full spec.
|
||||
|
||||
### 2.5.1 Propagation Boundaries
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph http["HTTP/WebSocket (RPC)"]
|
||||
w3c["W3C Trace Context Headers:<br/>traceparent:<br/>00-trace_id-span_id-flags<br/>tracestate: xrpld=..."]
|
||||
end
|
||||
|
||||
subgraph protobuf["Protocol Buffers (P2P)"]
|
||||
proto["message TraceContext {<br/> bytes trace_id = 1; // 16 bytes<br/> bytes span_id = 2; // 8 bytes<br/> uint32 trace_flags = 3;<br/> string trace_state = 4;<br/>}"]
|
||||
end
|
||||
|
||||
subgraph jobqueue["JobQueue (Internal Async)"]
|
||||
job["Context captured at job creation,<br/>restored at execution<br/><br/>class Job {<br/> otel::context::Context<br/> traceContext_;<br/>};"]
|
||||
end
|
||||
|
||||
style http fill:#0d47a1,stroke:#082f6a,color:#ffffff
|
||||
style protobuf fill:#1b5e20,stroke:#0d3d14,color:#ffffff
|
||||
style jobqueue fill:#bf360c,stroke:#8c2809,color:#ffffff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **HTTP/WebSocket - RPC (blue)**: For client-facing RPC requests, trace context is propagated using the W3C `traceparent` header. This is the standard approach and works with any OTel-compatible client.
|
||||
- **Protocol Buffers - P2P (green)**: For peer-to-peer messages between xrpld nodes, trace context is embedded as a protobuf `TraceContext` message carrying trace_id, span_id, flags, and optional trace_state.
|
||||
- **JobQueue - Internal Async (red)**: For asynchronous work within a single node, the OTel context is captured when a job is created and restored when the job executes on a worker thread. This bridges the async gap so spans remain linked.
|
||||
|
||||
---
|
||||
|
||||
## 2.6 Integration with Existing Observability
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol | **WS** = WebSocket
|
||||
|
||||
### 2.6.1 Existing Frameworks Comparison
|
||||
|
||||
xrpld already has two observability mechanisms. OpenTelemetry complements (not replaces) them:
|
||||
|
||||
| Aspect | PerfLog | Beast Insight (StatsD) | OpenTelemetry |
|
||||
| --------------------- | ----------------------------- | ---------------------------- | ------------------------- |
|
||||
| **Type** | Logging | Metrics | Distributed Tracing |
|
||||
| **Data** | JSON log entries | Counters, gauges, histograms | Spans with context |
|
||||
| **Scope** | Single node | Single node | **Cross-node** |
|
||||
| **Output** | `perf.log` file | StatsD server | OTLP Collector |
|
||||
| **Question answered** | "What happened on this node?" | "How many? How fast?" | "What was the journey?" |
|
||||
| **Correlation** | By timestamp | By metric name | By `trace_id` |
|
||||
| **Overhead** | Low (file I/O) | Low (UDP packets) | Low-Medium (configurable) |
|
||||
|
||||
### 2.6.2 What Each Framework Does Best
|
||||
|
||||
#### PerfLog
|
||||
|
||||
- **Purpose**: Detailed local event logging for RPC and job execution
|
||||
- **Strengths**:
|
||||
- Rich JSON output with timing data
|
||||
- Already integrated in RPC handlers
|
||||
- File-based, no external dependencies
|
||||
- **Limitations**:
|
||||
- Single-node only (no cross-node correlation)
|
||||
- No parent-child relationships between events
|
||||
- Manual log parsing required
|
||||
|
||||
A PerfLog entry is a JSON object with fields such as `time`, `method`,
|
||||
`duration_us`, and `result`.
|
||||
|
||||
#### Beast Insight (StatsD)
|
||||
|
||||
- **Purpose**: Real-time metrics for monitoring dashboards
|
||||
- **Strengths**:
|
||||
- Aggregated metrics (counters, gauges, histograms)
|
||||
- Low overhead (UDP, fire-and-forget)
|
||||
- Good for alerting thresholds
|
||||
- **Limitations**:
|
||||
- No request-level detail
|
||||
- No causal relationships
|
||||
- Single-node perspective
|
||||
- Aggregation happens on the StatsD server, not in the process
|
||||
|
||||
In xrpld, Beast Insight is used through `increment` (counters), `gauge`
|
||||
(point-in-time values), and `timing` (durations) calls. A `timing` call sends
|
||||
each measured value as its own raw `|ms` sample, so the histogram a dashboard
|
||||
reads is built by the StatsD server from that stream of values.
|
||||
|
||||
#### OpenTelemetry (NEW)
|
||||
|
||||
- **Purpose**: Distributed request tracing across nodes
|
||||
- **Strengths**:
|
||||
- **Cross-node correlation** via `trace_id`
|
||||
- Parent-child span relationships
|
||||
- Rich attributes per span
|
||||
- A `Histogram` instrument that aggregates **at the point of measure**
|
||||
- Industry standard (CNCF)
|
||||
- **Limitations**:
|
||||
- Requires collector infrastructure
|
||||
- Higher complexity than logging
|
||||
|
||||
A span is created via `startSpan` (e.g. `"tx.relay"`), annotated with
|
||||
attributes such as `tx_hash` and `peer_id`, and is automatically linked to its
|
||||
parent through the active context.
|
||||
|
||||
OpenTelemetry is not only spans. The same SDK offers a `Histogram` instrument,
|
||||
and a `Record()` call folds the value straight into bucket counts inside the
|
||||
process — no per-event record is shipped and no server-side aggregation step is
|
||||
needed. That is what makes it affordable in a hot loop where one span per event
|
||||
would not be, and it is the one thing Beast Insight cannot do, because its
|
||||
`timing` path ships raw values and aggregates them on the StatsD server.
|
||||
|
||||
### 2.6.3 When to Use Each
|
||||
|
||||
| Scenario | PerfLog | StatsD | OpenTelemetry |
|
||||
| --------------------------------------- | ---------- | ------ | ------------- |
|
||||
| "How many TXs per second?" | ❌ | ✅ | ✅ |
|
||||
| "What's the p99 RPC latency?" | ❌ | ✅ | ✅ |
|
||||
| "Why was this specific TX slow?" | ⚠️ partial | ❌ | ✅ |
|
||||
| "Which node delayed consensus?" | ❌ | ❌ | ✅ |
|
||||
| "What happened on node X at time T?" | ✅ | ❌ | ✅ |
|
||||
| "Show me the TX journey across 5 nodes" | ❌ | ❌ | ✅ |
|
||||
| "p99 NodeStore fetch latency?" | ❌ | ❌ | ✅ |
|
||||
|
||||
The last row is the case a span cannot answer. One `TMGetObjectByHash` message
|
||||
requests up to `tuning::kHardMaxReplyNodes` objects, so a span per NodeStore
|
||||
fetch is not affordable in that loop. Instead the fetch loop's wall time is
|
||||
recorded once per message into an OpenTelemetry `Histogram`
|
||||
(`getobject_lookup_us`), and the quantile is read off its buckets. StatsD is
|
||||
marked ❌ because that instrument is recorded on the native OpenTelemetry metrics
|
||||
path, not through Beast Insight.
|
||||
|
||||
### 2.6.4 Coexistence Strategy
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph xrpld["xrpld Process"]
|
||||
perflog["PerfLog<br/>(JSON to file)"]
|
||||
insight["Beast Insight<br/>(StatsD)"]
|
||||
otel["OpenTelemetry<br/>(Tracing)"]
|
||||
end
|
||||
|
||||
perflog --> perffile["perf.log"]
|
||||
insight --> statsd["StatsD Server"]
|
||||
otel --> collector["OTLP Collector"]
|
||||
|
||||
perffile --> grafana["Grafana<br/>(Unified UI)"]
|
||||
statsd --> grafana
|
||||
collector --> grafana
|
||||
|
||||
style xrpld fill:#212121,stroke:#0a0a0a,color:#ffffff
|
||||
style grafana fill:#bf360c,stroke:#8c2809,color:#ffffff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **xrpld Process (dark gray)**: The single xrpld node running all three observability frameworks side by side. Each framework operates independently with no interference.
|
||||
- **PerfLog to perf.log**: PerfLog writes JSON-formatted event logs to a local file. Grafana can ingest these via Loki or a file-based datasource.
|
||||
- **Beast Insight to StatsD Server**: Insight sends aggregated metrics (counters, gauges) over UDP to a StatsD server. Grafana reads from StatsD-compatible backends like Graphite or Prometheus (via StatsD exporter).
|
||||
- **OpenTelemetry to OTLP Collector**: OTel exports spans over OTLP/HTTP to a Collector, which then forwards to a trace backend (Tempo). (OTLP/gRPC is future work — §2.2.2.)
|
||||
- **Grafana (red, unified UI)**: All three data streams converge in Grafana, enabling operators to correlate logs, metrics, and traces in a single dashboard.
|
||||
|
||||
### 2.6.5 Correlation with PerfLog
|
||||
|
||||
Trace IDs can be correlated with existing PerfLog entries for comprehensive
|
||||
debugging. The design is for `RPCHandler.cpp` to start an `rpc.command.<method>`
|
||||
span alongside the existing PerfLog `rpcStart`/`rpcFinish`/`rpcError` calls,
|
||||
extract the span's `trace_id` (when valid), and eventually stamp it onto the
|
||||
PerfLog entry (a planned `setTraceId` hook) so logs and traces share a key. The
|
||||
span status is set to OK on success or to error (recording the exception) on
|
||||
failure.
|
||||
|
||||
---
|
||||
|
||||
_Previous: [Architecture Analysis](./01-architecture-analysis.md)_ | _Next: [Implementation Strategy](./03-implementation-strategy.md)_ | _Back to: [Overview](./OpenTelemetryPlan.md)_
|
||||
411
OpenTelemetryPlan/03-implementation-strategy.md
Normal file
411
OpenTelemetryPlan/03-implementation-strategy.md
Normal file
@@ -0,0 +1,411 @@
|
||||
# Implementation Strategy
|
||||
|
||||
> **Parent Document**: [OpenTelemetryPlan.md](./OpenTelemetryPlan.md)
|
||||
> **Related**: [Configuration Reference](./05-configuration-reference.md)
|
||||
|
||||
---
|
||||
|
||||
## 3.1 Directory Structure
|
||||
|
||||
The telemetry implementation follows xrpld's existing code organization pattern:
|
||||
|
||||
```
|
||||
include/xrpl/
|
||||
├── telemetry/
|
||||
│ ├── Telemetry.h # Main telemetry interface (global singleton)
|
||||
│ ├── TelemetryConfig.h # Configuration structures
|
||||
│ ├── TraceContext.h # Context propagation utilities
|
||||
│ ├── SpanGuard.h # RAII span management with factory methods + discard()
|
||||
│ ├── DiscardFlag.h # Thread-local discard flag
|
||||
│ └── SpanAttributes.h # Attribute helper functions
|
||||
|
||||
src/libxrpl/
|
||||
├── telemetry/
|
||||
│ ├── Telemetry.cpp # Implementation + FilteringSpanProcessor
|
||||
│ ├── TelemetryConfig.cpp # Config parsing
|
||||
│ ├── TraceContext.cpp # Context serialization
|
||||
│ └── NullTelemetry.cpp # No-op implementation
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 3.2 Implementation Approach
|
||||
|
||||
<div align="center">
|
||||
|
||||
```mermaid
|
||||
%%{init: {'flowchart': {'nodeSpacing': 20, 'rankSpacing': 30}}}%%
|
||||
flowchart TB
|
||||
subgraph phase1["Phase 1: Core"]
|
||||
direction LR
|
||||
sdk["SDK Integration"] ~~~ interface["Telemetry Interface"] ~~~ config["Configuration"]
|
||||
end
|
||||
|
||||
subgraph phase2["Phase 2: RPC"]
|
||||
direction LR
|
||||
http["HTTP Context"] ~~~ rpc["RPC Handlers"]
|
||||
end
|
||||
|
||||
subgraph phase3["Phase 3: P2P"]
|
||||
direction LR
|
||||
proto["Protobuf Context"] ~~~ tx["Transaction Relay"]
|
||||
end
|
||||
|
||||
subgraph phase4["Phase 4: Consensus"]
|
||||
direction LR
|
||||
consensus["Consensus Rounds"] ~~~ proposals["Proposals"]
|
||||
end
|
||||
|
||||
phase1 --> phase2 --> phase3 --> phase4
|
||||
|
||||
style phase1 fill:#1565c0,stroke:#0d47a1,color:#ffffff
|
||||
style phase2 fill:#2e7d32,stroke:#1b5e20,color:#ffffff
|
||||
style phase3 fill:#e65100,stroke:#bf360c,color:#ffffff
|
||||
style phase4 fill:#c2185b,stroke:#880e4f,color:#ffffff
|
||||
```
|
||||
|
||||
</div>
|
||||
|
||||
### Key Principles
|
||||
|
||||
1. **Minimal Intrusion**: Instrumentation should not alter existing control flow
|
||||
2. **Zero-Cost When Disabled**: Use compile-time flags and no-op implementations
|
||||
3. **Backward Compatibility**: Protocol Buffer extensions use high field numbers
|
||||
4. **Graceful Degradation**: Tracing failures must not affect node operation
|
||||
|
||||
---
|
||||
|
||||
## 3.3 Performance Overhead Summary
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
| Metric | Overhead | Notes |
|
||||
| ------------- | ---------- | ------------------------------------------------ |
|
||||
| CPU | 1-3% | Of per-transaction CPU cost (~200μs baseline) |
|
||||
| Memory | ~10 MB | SDK statics + batch buffer + worker thread stack |
|
||||
| Network | 10-50 KB/s | Compressed OTLP export to collector |
|
||||
| Latency (p99) | <2% | With proper sampling configuration |
|
||||
|
||||
---
|
||||
|
||||
## 3.4 Detailed CPU Overhead Analysis
|
||||
|
||||
### 3.4.1 Per-Operation Costs
|
||||
|
||||
> **Note on hardware assumptions**: The costs below are based on the official OTel C++ SDK CI benchmarks
|
||||
> (969 runs on GitHub Actions 2-core shared runners). On production server hardware (3+ GHz Xeon),
|
||||
> expect costs at the **lower end** of each range (~30-50% improvement over CI hardware).
|
||||
|
||||
| Operation | Time (ns) | Frequency | Impact |
|
||||
| --------------------- | --------- | ---------------------- | ---------- |
|
||||
| Span creation | 500-1000 | Every traced operation | Low |
|
||||
| Span end | 100-200 | Every traced operation | Low |
|
||||
| SetAttribute (string) | 80-120 | 3-5 per span | Low |
|
||||
| SetAttribute (int) | 40-60 | 2-3 per span | Negligible |
|
||||
| AddEvent | 100-200 | 0-2 per span | Low |
|
||||
| Context injection | 150-250 | Per outgoing message | Low |
|
||||
| Context extraction | 100-180 | Per incoming message | Low |
|
||||
| GetCurrent context | 10-20 | Thread-local access | Negligible |
|
||||
|
||||
**Source**: Span creation based on OTel C++ SDK `BM_SpanCreation` benchmark (AlwaysOnSampler +
|
||||
SimpleSpanProcessor + InMemoryExporter), median ~1,000 ns on CI hardware. AddEvent includes
|
||||
timestamp read + string copy + vector push + mutex acquisition. Context injection/extraction
|
||||
confirmed by `BM_SpanCreationWithScope` benchmark delta (~160 ns).
|
||||
|
||||
### 3.4.2 Transaction Processing Overhead
|
||||
|
||||
<div align="center">
|
||||
|
||||
```mermaid
|
||||
%%{init: {'pie': {'textPosition': 0.75}}}%%
|
||||
pie showData
|
||||
"tx.receive (1400ns)" : 1400
|
||||
"tx.validate (1200ns)" : 1200
|
||||
"tx.relay (1200ns)" : 1200
|
||||
"Context inject (200ns)" : 200
|
||||
```
|
||||
|
||||
**Transaction Tracing Overhead (~4.0μs total)**
|
||||
|
||||
</div>
|
||||
|
||||
**Overhead percentage**: 4.0 μs / 200 μs (avg tx processing) = **~2.0%**
|
||||
|
||||
> **Breakdown**: Each span (tx.receive, tx.validate, tx.relay) costs ~1,000 ns for creation plus
|
||||
> ~200-400 ns for 3-5 attribute sets. Context injection is ~200 ns (confirmed by benchmarks).
|
||||
> On production hardware, expect ~2.6 μs total (~1.3% overhead) due to faster span creation (~500-600 ns).
|
||||
|
||||
### 3.4.3 Consensus Round Overhead
|
||||
|
||||
| Operation | Count | Cost (ns) | Total |
|
||||
| ---------------------- | ----- | --------- | ---------- |
|
||||
| consensus.round span | 1 | ~1200 | ~1.2 μs |
|
||||
| consensus.phase spans | 3 | ~1100 | ~3.3 μs |
|
||||
| proposal.receive spans | ~20 | ~1100 | ~22 μs |
|
||||
| proposal.send spans | ~3 | ~1100 | ~3.3 μs |
|
||||
| Context operations | ~30 | ~200 | ~6 μs |
|
||||
| **TOTAL** | | | **~36 μs** |
|
||||
|
||||
> **Why higher**: Each span costs ~1,000 ns creation + ~100-200 ns for 1-2 attributes, totaling ~1,100-1,200 ns.
|
||||
> Context operations remain ~200 ns (confirmed by benchmarks). On production hardware, expect ~24 μs total.
|
||||
|
||||
**Overhead percentage**: 36 μs / 3s (typical round) = **~0.001%** (negligible)
|
||||
|
||||
### 3.4.4 RPC Request Overhead
|
||||
|
||||
| Operation | Cost (ns) |
|
||||
| ---------------- | ------------ |
|
||||
| rpc.request span | ~1200 |
|
||||
| rpc.command span | ~1100 |
|
||||
| Context extract | ~250 |
|
||||
| Context inject | ~200 |
|
||||
| **TOTAL** | **~2.75 μs** |
|
||||
|
||||
> **Why higher**: Each span costs ~1,000 ns creation + ~100-200 ns for attributes (command name,
|
||||
> version, role). Context extract/inject costs are confirmed by OTel C++ benchmarks.
|
||||
|
||||
- Fast RPC (1ms): 2.75 μs / 1ms = **~0.275%**
|
||||
- Slow RPC (100ms): 2.75 μs / 100ms = **~0.003%**
|
||||
|
||||
---
|
||||
|
||||
## 3.5 Memory Overhead Analysis
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
### 3.5.1 Static Memory
|
||||
|
||||
| Component | Size | Allocated |
|
||||
| ------------------------------------ | ----------- | ---------- |
|
||||
| TracerProvider singleton | ~64 KB | At startup |
|
||||
| BatchSpanProcessor (circular buffer) | ~16 KB | At startup |
|
||||
| BatchSpanProcessor (worker thread) | ~8 MB | At startup |
|
||||
| OTLP/HTTP exporter (client init) | ~64 KB | At startup |
|
||||
| Propagator registry | ~8 KB | At startup |
|
||||
| **Total static** | **~8.1 MB** | |
|
||||
|
||||
> **Why higher than earlier estimate**: The BatchSpanProcessor's circular buffer itself is only ~16 KB
|
||||
> (2049 x 8-byte `AtomicUniquePtr` entries), but it spawns a dedicated worker thread whose default
|
||||
> stack size on Linux is ~8 MB. The OTLP/HTTP exporter allocates a small client and TLS
|
||||
> initialization buffer. The worker thread stack dominates the static footprint.
|
||||
|
||||
### 3.5.2 Dynamic Memory
|
||||
|
||||
| Component | Size per unit | Max units | Peak |
|
||||
| -------------------- | -------------- | ---------- | --------------- |
|
||||
| Active span | ~500-800 bytes | 1000 | ~500-800 KB |
|
||||
| Queued span (export) | ~500 bytes | 2048 | ~1 MB |
|
||||
| Attribute storage | ~80 bytes | 5 per span | Included |
|
||||
| Context storage | ~64 bytes | Per thread | ~6.4 KB |
|
||||
| **Total dynamic** | | | **~1.5-1.8 MB** |
|
||||
|
||||
> **Why active spans are larger**: An active `Span` object includes the wrapper (~88 bytes: shared_ptr,
|
||||
> mutex, unique_ptr to Recordable) plus `SpanData` (~250 bytes: SpanContext, timestamps, name, status,
|
||||
> empty containers) plus attribute storage (~200-500 bytes for 3-5 string attributes in a `std::map`).
|
||||
> Source: `sdk/src/trace/span.h` and `sdk/include/opentelemetry/sdk/trace/span_data.h`.
|
||||
> Queued spans release the wrapper, keeping only `SpanData` + attributes (~500 bytes).
|
||||
|
||||
### 3.5.3 Memory Growth Characteristics
|
||||
|
||||
```mermaid
|
||||
---
|
||||
config:
|
||||
xyChart:
|
||||
width: 700
|
||||
height: 400
|
||||
---
|
||||
xychart-beta
|
||||
title "Memory Usage vs Span Rate (bounded by queue limit)"
|
||||
x-axis "Spans/second" [0, 200, 400, 600, 800, 1000]
|
||||
y-axis "Memory (MB)" 0 --> 12
|
||||
line [8.5, 9.2, 9.6, 9.9, 10.0, 10.0]
|
||||
```
|
||||
|
||||
**Notes**:
|
||||
|
||||
- Memory increases with span rate but **plateaus at queue capacity** (default 2048 spans)
|
||||
- Batch export prevents unbounded growth
|
||||
- At queue limit, oldest spans are dropped (not blocked)
|
||||
- Maximum memory is bounded: ~8.3 MB static (dominated by worker thread stack) + 2048 queued spans x ~500 bytes (~1 MB) + active spans (~0.8 MB) ≈ **~10 MB ceiling**
|
||||
- The worker thread stack (~8 MB) is virtual memory; actual RSS depends on stack usage (typically much less)
|
||||
|
||||
> **Measured outcome**: A perf-iac comparison (telemetry compiled-in + enabled vs compiled-out,
|
||||
> 9 nodes — validators and client-handlers — under sustained payment load) recorded **no measurable
|
||||
> RSS increase over the telemetry-off baseline** (~15 GiB mean / ~18–19 GiB peak on both sides),
|
||||
> with no OOM, no swap, and no leak across the run. The ~10 MB ceiling above is therefore a
|
||||
> provisioning safety margin (dominated by virtual thread-stack address space), not an expected
|
||||
> resident-memory increase. Steady-state cost shows up as throughput (~3–4% at head sampling 1.0),
|
||||
> not memory.
|
||||
|
||||
### 3.5.4 Performance Data Sources
|
||||
|
||||
The overhead estimates in Sections 3.3-3.5 are derived from the following sources:
|
||||
|
||||
| Source | What it covers | URL |
|
||||
| ------------------------------------------------ | ----------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||
| OTel C++ SDK CI benchmarks (969 runs) | Span creation, context activation, sampler overhead | [Benchmark Dashboard](https://open-telemetry.github.io/opentelemetry-cpp/benchmarks/) |
|
||||
| `api/test/trace/span_benchmark.cc` | API-level span creation (~22 ns no-op) | [Source](https://github.com/open-telemetry/opentelemetry-cpp/blob/main/api/test/trace/span_benchmark.cc) |
|
||||
| `sdk/test/trace/sampler_benchmark.cc` | SDK span creation with samplers (~1,000 ns AlwaysOn) | [Source](https://github.com/open-telemetry/opentelemetry-cpp/blob/main/sdk/test/trace/sampler_benchmark.cc) |
|
||||
| `sdk/include/.../span_data.h` | SpanData memory layout (~250 bytes base) | [Source](https://github.com/open-telemetry/opentelemetry-cpp/blob/main/sdk/include/opentelemetry/sdk/trace/span_data.h) |
|
||||
| `sdk/src/trace/span.h` | Span wrapper memory layout (~88 bytes) | [Source](https://github.com/open-telemetry/opentelemetry-cpp/blob/main/sdk/src/trace/span.h) |
|
||||
| `sdk/include/.../batch_span_processor_options.h` | Default queue size (2048), batch size (512) | [Source](https://github.com/open-telemetry/opentelemetry-cpp/blob/main/sdk/include/opentelemetry/sdk/trace/batch_span_processor_options.h) |
|
||||
| `sdk/include/.../circular_buffer.h` | CircularBuffer implementation (AtomicUniquePtr array) | [Source](https://github.com/open-telemetry/opentelemetry-cpp/blob/main/sdk/include/opentelemetry/sdk/common/circular_buffer.h) |
|
||||
| OTLP proto definition | Serialized span size estimation | [Proto](https://github.com/open-telemetry/opentelemetry-proto/blob/main/opentelemetry/proto/trace/v1/trace.proto) |
|
||||
|
||||
---
|
||||
|
||||
## 3.6 Network Overhead Analysis
|
||||
|
||||
### 3.6.1 Export Bandwidth
|
||||
|
||||
> **Bytes per span**: Estimates use ~500 bytes/span (conservative upper bound). OTLP protobuf analysis
|
||||
> shows a typical span with 3-5 string attributes serializes to ~200-300 bytes raw; with gzip
|
||||
> compression (~60-70% of raw) and batching (amortized headers), ~350 bytes/span is more realistic.
|
||||
> The table uses the conservative estimate for capacity planning.
|
||||
|
||||
| Sampling Rate | Spans/sec | Bandwidth | Notes |
|
||||
| ------------- | --------- | --------- | ---------------- |
|
||||
| 100% | ~500 | ~250 KB/s | Development only |
|
||||
| 10% | ~50 | ~25 KB/s | Staging |
|
||||
| 1% | ~5 | ~2.5 KB/s | Production |
|
||||
| Error-only | ~1 | ~0.5 KB/s | Minimal overhead |
|
||||
|
||||
### 3.6.2 Trace Context Propagation
|
||||
|
||||
| Message Type | Context Size | Messages/sec | Overhead |
|
||||
| ---------------------- | ------------ | ------------ | ----------- |
|
||||
| TMTransaction | 25 bytes | ~100 | ~2.5 KB/s |
|
||||
| TMProposeSet | 25 bytes | ~10 | ~250 B/s |
|
||||
| TMValidation | 25 bytes | ~50 | ~1.25 KB/s |
|
||||
| **Total P2P overhead** | | | **~4 KB/s** |
|
||||
|
||||
---
|
||||
|
||||
## 3.7 Optimization Strategies
|
||||
|
||||
### 3.7.1 Sampling Strategies
|
||||
|
||||
#### Tail Sampling
|
||||
|
||||
```mermaid
|
||||
flowchart TD
|
||||
trace["New Trace"]
|
||||
|
||||
trace --> errors{"Is Error?"}
|
||||
errors -->|Yes| sample["SAMPLE"]
|
||||
errors -->|No| consensus{"Is Consensus?"}
|
||||
|
||||
consensus -->|Yes| sample
|
||||
consensus -->|No| slow{"Is Slow?"}
|
||||
|
||||
slow -->|Yes| sample
|
||||
slow -->|No| prob{"Random < 10%?"}
|
||||
|
||||
prob -->|Yes| sample
|
||||
prob -->|No| drop["DROP"]
|
||||
|
||||
style sample fill:#4caf50,stroke:#388e3c,color:#fff
|
||||
style drop fill:#f44336,stroke:#c62828,color:#fff
|
||||
```
|
||||
|
||||
### 3.7.2 Batch Tuning Recommendations
|
||||
|
||||
| Environment | Batch Size | Batch Delay | Max Queue |
|
||||
| ------------------ | ---------- | ----------- | --------- |
|
||||
| Low-latency | 128 | 1000ms | 512 |
|
||||
| High-throughput | 1024 | 10000ms | 8192 |
|
||||
| Memory-constrained | 256 | 2000ms | 512 |
|
||||
|
||||
### 3.7.3 Conditional Instrumentation
|
||||
|
||||
Instrumentation is gated on two levels. A compile-time feature flag (`XRPL_ENABLE_TELEMETRY`) reduces the trace macros to no-ops when telemetry is built out, so disabled builds carry zero cost. At runtime, per-component guards (e.g. `shouldTracePeer()`) skip span creation for components whose tracing is turned off, incurring no overhead beyond a single boolean check.
|
||||
|
||||
---
|
||||
|
||||
## 3.8 Links to Detailed Documentation
|
||||
|
||||
- **[Configuration Reference](./05-configuration-reference.md)**: Configuration options and collector setup
|
||||
- **[Implementation Phases](./06-implementation-phases.md)**: Detailed timeline and milestones
|
||||
|
||||
---
|
||||
|
||||
## 3.9 Code Intrusiveness Assessment
|
||||
|
||||
> **TxQ** = Transaction Queue
|
||||
|
||||
This section provides a detailed assessment of how intrusive the OpenTelemetry integration is to the existing xrpld codebase.
|
||||
|
||||
### 3.9.3 Risk Assessment by Component
|
||||
|
||||
<div align="center">
|
||||
|
||||
**Do First** ↖ ↗ **Plan Carefully**
|
||||
|
||||
```mermaid
|
||||
quadrantChart
|
||||
title Code Intrusiveness Risk Matrix
|
||||
x-axis Low Risk --> High Risk
|
||||
y-axis Low Value --> High Value
|
||||
|
||||
RPC Tracing: [0.2, 0.55]
|
||||
Transaction Relay: [0.55, 0.85]
|
||||
Consensus Tracing: [0.75, 0.92]
|
||||
Peer Message Tracing: [0.85, 0.35]
|
||||
JobQueue Context: [0.3, 0.42]
|
||||
Ledger Acquisition: [0.48, 0.65]
|
||||
PathFinding: [0.38, 0.72]
|
||||
TxQ and Fees: [0.25, 0.62]
|
||||
Validator Mgmt: [0.15, 0.35]
|
||||
```
|
||||
|
||||
**Optional** ↙ ↘ **Avoid**
|
||||
|
||||
</div>
|
||||
|
||||
#### Risk Level Definitions
|
||||
|
||||
| Risk Level | Definition | Mitigation |
|
||||
| ---------- | ---------------------------------------------------------------- | ---------------------------------- |
|
||||
| **Low** | Additive changes only; no modification to existing logic | Standard code review |
|
||||
| **Medium** | Minor modifications to existing functions; clear boundaries | Comprehensive unit tests |
|
||||
| **High** | Changes to core logic or data structures; potential side effects | Integration tests + staged rollout |
|
||||
|
||||
### 3.9.4 Architectural Impact Assessment
|
||||
|
||||
| Aspect | Impact | Justification |
|
||||
| -------------------- | ------- | -------------------------------------------------------------------------------- |
|
||||
| **Data Flow** | Minimal | Read-only instrumentation; no modification to consensus or transaction data flow |
|
||||
| **Threading Model** | Minimal | Context propagation uses thread-local storage (standard OTel pattern) |
|
||||
| **Memory Model** | Low | Bounded queues prevent unbounded growth; RAII ensures cleanup |
|
||||
| **Network Protocol** | Low | Optional fields in protobuf (high field numbers); backward compatible |
|
||||
| **Configuration** | None | New config section; existing configs unaffected |
|
||||
| **Build System** | Low | Optional CMake flag; builds work without OpenTelemetry |
|
||||
| **Dependencies** | Low | OpenTelemetry SDK is optional; null implementation when disabled |
|
||||
|
||||
### 3.9.5 Backward Compatibility
|
||||
|
||||
| Compatibility | Status | Notes |
|
||||
| --------------- | ------- | ----------------------------------------------------- |
|
||||
| **Config File** | ✅ Full | New `[telemetry]` section is optional |
|
||||
| **Protocol** | ✅ Full | Optional protobuf fields with high field numbers |
|
||||
| **Build** | ✅ Full | `XRPL_ENABLE_TELEMETRY=OFF` produces identical binary |
|
||||
| **Runtime** | ✅ Full | `enabled=0` produces zero overhead |
|
||||
| **API** | ✅ Full | No changes to public RPC or P2P APIs |
|
||||
|
||||
### 3.9.6 Rollback Strategy
|
||||
|
||||
If issues are discovered after deployment:
|
||||
|
||||
1. **Immediate**: Set `enabled=0` in config and restart (zero code change)
|
||||
2. **Quick**: Rebuild with `XRPL_ENABLE_TELEMETRY=OFF`
|
||||
3. **Complete**: Revert telemetry commits (clean separation makes this easy)
|
||||
|
||||
### 3.9.7 Code Change Examples
|
||||
|
||||
**Minimal RPC Instrumentation (Low Intrusiveness):** Instrumenting an RPC handler adds roughly 3-4 lines: one macro to start the span and one or two `setAttribute` calls (command name, status). The span ends automatically via RAII, so the existing control flow — process the request, send the result — is untouched.
|
||||
|
||||
**Consensus Instrumentation (Medium Intrusiveness):** Consensus is slightly more intrusive because child spans in later phase transitions need the round's context. Beyond the span-start and attribute macros, this requires storing the active context in a new member variable (`currentRoundContext_`) at round start. The existing round logic itself remains unchanged.
|
||||
|
||||
---
|
||||
|
||||
_Previous: [Design Decisions](./02-design-decisions.md)_ | _Next: [Configuration Reference](./05-configuration-reference.md)_ | _Back to: [Overview](./OpenTelemetryPlan.md)_
|
||||
270
OpenTelemetryPlan/05-configuration-reference.md
Normal file
270
OpenTelemetryPlan/05-configuration-reference.md
Normal file
@@ -0,0 +1,270 @@
|
||||
# Configuration Reference
|
||||
|
||||
> **Parent Document**: [OpenTelemetryPlan.md](./OpenTelemetryPlan.md)
|
||||
> **Related**: [Implementation Phases](./06-implementation-phases.md)
|
||||
|
||||
---
|
||||
|
||||
## 5.1 xrpld Configuration
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol | **TxQ** = Transaction Queue | **mTLS** = mutual TLS
|
||||
|
||||
### 5.1.1 Configuration File Section
|
||||
|
||||
The authoritative `[telemetry]` example lives in `cfg/xrpld-example.cfg`. Telemetry is disabled by default (`enabled=0`); enabling it turns on distributed tracing for transaction flow, consensus, and RPC calls, with traces exported to an OpenTelemetry Collector over OTLP. Head sampling is intentionally fixed at 1.0 (sample everything) and is not configurable — per-node head-sampling would produce broken/partial distributed traces, so volume reduction is delegated to the collector's tail sampling (see Section 7.4.2). The full option reference follows.
|
||||
|
||||
### 5.1.2 Configuration Options Summary
|
||||
|
||||
| Option | Type | Default | Description |
|
||||
| -------------------------- | ------ | --------------------------------- | ----------------------------------------------------------------------------------------------------------------------- |
|
||||
| `enabled` | 0 or 1 | `0` | Enable/disable telemetry |
|
||||
| `traces_endpoint` | string | `http://localhost:4318/v1/traces` | Full OTLP/HTTP URL for spans, used verbatim |
|
||||
| `use_tls` | 0 or 1 | `0` | Enable TLS for exporter connection |
|
||||
| `tls_ca_cert` | string | `""` | Path to CA certificate file |
|
||||
| `tls_client_cert` | string | `""` | Client cert (PEM) for mTLS; empty = one-way; if `enabled=1`, needs key + `use_tls=1` or startup fails |
|
||||
| `tls_client_key` | string | `""` | Private key (PEM) for `tls_client_cert`; if set with `enabled=1`, needs the cert + `use_tls=1` or fails |
|
||||
| `batch_size` | uint | `512` | Spans per export batch |
|
||||
| `batch_delay_ms` | uint | `5000` | Max delay before sending batch (ms) |
|
||||
| `max_queue_size` | uint | `2048` | Maximum queued spans |
|
||||
| `trace_transactions` | 0 or 1 | `1` | Enable transaction tracing |
|
||||
| `trace_consensus` | 0 or 1 | `1` | Enable consensus tracing |
|
||||
| `trace_rpc` | 0 or 1 | `1` | Enable RPC tracing |
|
||||
| `trace_peer` | 0 or 1 | `1` | Enable peer message tracing (high volume) |
|
||||
| `trace_ledger` | 0 or 1 | `1` | Enable ledger tracing |
|
||||
| `tx_trace_strategy` | string | `"deterministic"` | TX trace ID strategy: `"deterministic"` (trace_id = txHash[0:16]) or `"attribute"` (random) |
|
||||
| `consensus_trace_strategy` | string | `"deterministic"` | Consensus trace ID strategy: `"deterministic"` (trace_id = prevLedgerHash[0:16]) or `"random"` (experimental, not used) |
|
||||
| `service_name` | string | `"xrpld"` | Service name (`service.name`) for traces and metrics |
|
||||
| `service_instance_id` | string | `<node_pubkey>` | Instance identifier |
|
||||
|
||||
**Planned (not yet implemented)**: the following options appear in the design
|
||||
documents but are not parsed by `TelemetryConfig.cpp` in Phase 1b and later
|
||||
phases. They will be added as the corresponding subsystems are instrumented:
|
||||
|
||||
| Option | Planned Phase | Purpose |
|
||||
| ----------------- | ------------- | ---------------------------------------- |
|
||||
| `exporter` | Future | Select between OTLP/HTTP and OTLP/gRPC |
|
||||
| `trace_pathfind` | Phase 2 | Path computation tracing toggle |
|
||||
| `trace_txq` | Phase 3 | Transaction queue tracing toggle |
|
||||
| `trace_validator` | Future | Validator list / manifest update tracing |
|
||||
| `trace_amendment` | Future | Amendment voting tracing |
|
||||
|
||||
---
|
||||
|
||||
## 5.2 Configuration Parser
|
||||
|
||||
> **TxQ** = Transaction Queue
|
||||
|
||||
The parser `makeTelemetrySetup()` in `src/libxrpl/telemetry/TelemetryConfig.cpp` reads the `[telemetry]` `Section` and populates a `Telemetry::Setup` struct, applying the defaults listed in Section 5.1.2 via `section.valueOr(...)`. It derives `serviceInstanceId` from the node public key when not overridden, selects the exporter endpoint default by exporter type, and leaves the sampling ratio at its fixed 1.0 default (not read from config — see Section 7.4.2).
|
||||
|
||||
---
|
||||
|
||||
## 5.3 Application Integration
|
||||
|
||||
### 5.3.1 ApplicationImp Changes
|
||||
|
||||
> **Deferred identity**: The node public key (`nodeIdentity_`) is not
|
||||
> available during `ApplicationImp`'s member initializer list — it is
|
||||
> resolved later in `setup()`. The `Telemetry` object is therefore
|
||||
> constructed with an empty `serviceInstanceId` and patched via
|
||||
> `setServiceInstanceId()` once `setup()` has called `getNodeIdentity()`.
|
||||
|
||||
`ApplicationImp` (in `src/xrpld/app/main/Application.cpp`) owns a `std::unique_ptr<telemetry::Telemetry> telemetry_`. It is built in the member initializer list via `makeTelemetry(makeTelemetrySetup(...))` with an empty `serviceInstanceId`, then patched in `setup()` by calling `setServiceInstanceId()` with the Base58 node public key (unless the user supplied a custom `service_instance_id`). `start()` and `run()` forward to `telemetry_->start()` / `telemetry_->stop()`, and `getTelemetry()` returns the owned instance.
|
||||
|
||||
### 5.3.2 ServiceRegistry Interface Addition
|
||||
|
||||
`include/xrpl/core/ServiceRegistry.h` gains a pure-virtual `telemetry::Telemetry& getTelemetry()` (with a forward declaration of `telemetry::Telemetry`), giving every component a uniform accessor for the tracing subsystem.
|
||||
|
||||
> **Note:** `Application` extends `ServiceRegistry`, so `getTelemetry()` is
|
||||
> available on both. Components that hold a `ServiceRegistry&` (e.g.
|
||||
> `NetworkOPsImp`) call `registry_.get().getTelemetry()`. Components that
|
||||
> still hold an `Application&` (e.g. `ServerHandler`, `PeerImp`,
|
||||
> `RCLConsensus::Adaptor`) call `app_.getTelemetry()` directly.
|
||||
|
||||
---
|
||||
|
||||
## 5.4 CMake Integration
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
### 5.4.1 Find OpenTelemetry Module
|
||||
|
||||
A `cmake/FindOpenTelemetry.cmake` module locates the OpenTelemetry C++ SDK. It first tries `find_package(opentelemetry-cpp CONFIG)`, aliasing the imported targets `OpenTelemetry::api`, `OpenTelemetry::sdk`, and `OpenTelemetry::otlp_grpc_exporter`, and falls back to `pkg-config` when no CMake config package is present.
|
||||
|
||||
### 5.4.2 CMakeLists.txt Changes
|
||||
|
||||
The top-level `CMakeLists.txt` adds an `XRPL_ENABLE_TELEMETRY` option (default `OFF`). When enabled, it runs `find_package(OpenTelemetry REQUIRED)`, defines the `XRPL_ENABLE_TELEMETRY` compile flag, and builds the `xrpl_telemetry` library from the real telemetry sources linked against the OpenTelemetry targets; when disabled, it builds the same target from a no-op `NullTelemetry.cpp` so call sites compile unchanged.
|
||||
|
||||
---
|
||||
|
||||
## 5.5 OpenTelemetry Collector Configuration
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol | **APM** = Application Performance Monitoring
|
||||
|
||||
> **Production hardening**: The configurations in this section are starting points. For production deployments where xrpld ships telemetry across a network to a centrally-hosted collector, see [Securing the OTel Pipeline](./secure-OTel.md) for the required mTLS receiver config, NetworkPolicy, and peer trace-context validation.
|
||||
|
||||
The authoritative collector config lives in the repo at `docker/telemetry/otel-collector-config.yaml` (with Tempo backend config in `docker/telemetry/tempo.yaml`). The sections below summarize the development and production shapes of that pipeline.
|
||||
|
||||
### 5.5.1 Development Configuration
|
||||
|
||||
The development collector enables an OTLP receiver on both gRPC (`0.0.0.0:4317`) and HTTP (`0.0.0.0:4318`), a single `batch` processor (1s timeout, batch size 100), and two exporters: a `logging` exporter for console debugging and `otlp_grpc/tempo` (insecure) for trace visualization. The single `traces` pipeline wires receiver → batch → both exporters.
|
||||
|
||||
### 5.5.2 Production Configuration
|
||||
|
||||
The production collector adds TLS on the OTLP gRPC receiver and a richer processor chain: a `memory_limiter` (OOM guard), `batch` (5s timeout, size 512), `tail_sampling`, and an `attributes` processor that hashes sensitive fields (e.g. `tx_account`) and stamps `deployment.environment`. Tail sampling keeps all `ERROR` traces, slow consensus rounds (>5s) and slow RPC requests (>1s), and probabilistically samples the remainder at 10%. Exporters target Grafana Tempo (TLS) and Elastic APM; `health_check` and `zpages` extensions are enabled for operability.
|
||||
|
||||
---
|
||||
|
||||
## 5.6 Docker Compose Development Environment
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
The authoritative development stack lives in the repo at `docker/telemetry/docker-compose.yml`. It brings up four services on a shared `xrpld-telemetry` network: an `otel-collector` (otel/opentelemetry-collector-contrib) exposing OTLP gRPC `4317`, OTLP HTTP `4318`, and health check `13133`; `tempo` for trace storage/visualization; `grafana` with provisioned datasources and dashboards (anonymous admin enabled); and an optional `prometheus` for metric correlation.
|
||||
|
||||
---
|
||||
|
||||
## 5.7 Configuration Architecture
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph config["Configuration Sources"]
|
||||
cfgFile["xrpld.cfg<br/>[telemetry] section"]
|
||||
cmake["CMake<br/>XRPL_ENABLE_TELEMETRY"]
|
||||
end
|
||||
|
||||
subgraph init["Initialization"]
|
||||
parse["makeTelemetrySetup()"]
|
||||
factory["makeTelemetry()"]
|
||||
end
|
||||
|
||||
subgraph runtime["Runtime Components"]
|
||||
tracer["TracerProvider"]
|
||||
exporter["OTLP Exporter"]
|
||||
processor["BatchProcessor"]
|
||||
end
|
||||
|
||||
subgraph collector["Collector Pipeline"]
|
||||
recv["Receivers"]
|
||||
proc["Processors"]
|
||||
exp["Exporters"]
|
||||
end
|
||||
|
||||
cfgFile --> parse
|
||||
cmake -->|"compile flag"| parse
|
||||
parse --> factory
|
||||
factory --> tracer
|
||||
tracer --> processor
|
||||
processor --> exporter
|
||||
exporter -->|"OTLP"| recv
|
||||
recv --> proc
|
||||
proc --> exp
|
||||
|
||||
style config fill:#e3f2fd,stroke:#1976d2
|
||||
style runtime fill:#e8f5e9,stroke:#388e3c
|
||||
style collector fill:#fff3e0,stroke:#ff9800
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **Configuration Sources**: `xrpld.cfg` provides runtime settings (endpoint, per-component trace toggles) while the CMake flag controls whether telemetry is compiled in at all. Head sampling is fixed at 1.0 and is not a config option; volume reduction happens via tail sampling in the collector.
|
||||
- **Initialization**: `makeTelemetrySetup()` parses config values, then `makeTelemetry()` constructs the provider, processor, and exporter objects.
|
||||
- **Runtime Components**: The `TracerProvider` creates spans, the `BatchProcessor` buffers them, and the `OTLP Exporter` serializes and sends them over the wire.
|
||||
- **OTLP arrow to Collector**: Trace data leaves the xrpld process via OTLP/HTTP and enters the external Collector pipeline. (OTLP/gRPC is future work — see design decisions §2.2.2.)
|
||||
- **Collector Pipeline**: `Receivers` ingest OTLP data, `Processors` apply sampling/filtering/enrichment, and `Exporters` forward traces to storage backends (Tempo, etc.).
|
||||
|
||||
---
|
||||
|
||||
## 5.8 Grafana Integration
|
||||
|
||||
> **APM** = Application Performance Monitoring
|
||||
|
||||
Step-by-step instructions for integrating xrpld traces with Grafana.
|
||||
|
||||
### 5.8.1 Data Source Configuration
|
||||
|
||||
#### Tempo (Recommended)
|
||||
|
||||
A Tempo datasource (`grafana/provisioning/datasources/tempo.yaml`, provisioned from `docker/telemetry/grafana/`) points at `http://tempo:3200` and enables `tracesToLogs` (linking to Loki on `service.name`/`tx_hash` and mapping `trace_id` → `traceID`), `serviceMap` against Prometheus, the node graph, and Loki search.
|
||||
|
||||
#### Elastic APM
|
||||
|
||||
Alternatively, an Elasticsearch datasource (`grafana/provisioning/datasources/elastic-apm.yaml`) of type `elasticsearch` points at `http://elasticsearch:9200` against the `apm-*` index, using `@timestamp` as the time field and mapping the log message/level fields.
|
||||
|
||||
### 5.8.2 Dashboard Provisioning
|
||||
|
||||
A dashboard provider (`grafana/provisioning/dashboards/dashboards.yaml`) loads the `xrpld` dashboard folder from disk (`/var/lib/grafana/dashboards/rippled`), polling for changes every 30s with deletion disabled.
|
||||
|
||||
### 5.8.3 Example Dashboard: RPC Performance
|
||||
|
||||
An example `xrpld RPC Performance` dashboard (uid `xrpld-rpc-performance`) sourced from Tempo via TraceQL provides four panels: RPC latency by command (heatmap), RPC error rate by command (timeseries), the top 10 slowest RPC commands by average duration (table), and a recent-traces table.
|
||||
|
||||
### 5.8.4 Example Dashboard: Transaction Tracing
|
||||
|
||||
An example `xrpld Transaction Tracing` dashboard (uid `xrpld-tx-tracing`) over Tempo provides three panels: transaction throughput (`tx.receive` rate, stat), cross-node relay count (average `span.relay_count` on `tx.relay`, timeseries), and a table of transaction validation errors (`tx.validate` with `status = error`).
|
||||
|
||||
### 5.8.5 TraceQL Query Examples
|
||||
|
||||
Common queries for xrpld traces:
|
||||
|
||||
```
|
||||
# Find all traces for a specific transaction hash
|
||||
{resource.service.name="xrpld" && span.tx_hash="ABC123..."}
|
||||
|
||||
# Find slow RPC commands (>100ms)
|
||||
{resource.service.name="xrpld" && name=~"rpc.command.*"} | { duration > 100ms }
|
||||
|
||||
# Find consensus rounds taking >5 seconds
|
||||
{resource.service.name="xrpld" && name="consensus.round"} | { duration > 5s }
|
||||
|
||||
# Find failed transactions with error details
|
||||
{resource.service.name="xrpld" && name="tx.validate" && status = error}
|
||||
|
||||
# Find transactions relayed to many peers
|
||||
{resource.service.name="xrpld" && name="tx.relay"} | { span.relay_count > 10 }
|
||||
|
||||
# Compare latency across nodes
|
||||
{resource.service.name="xrpld" && name="rpc.command.account_info"} | avg_over_time(duration) by (resource.service.instance.id)
|
||||
```
|
||||
|
||||
### 5.8.6 Correlation with PerfLog
|
||||
|
||||
To correlate OpenTelemetry traces with existing PerfLog data:
|
||||
|
||||
**Step 1: Configure Loki to ingest PerfLog**
|
||||
|
||||
Configure a Promtail scrape job (`promtail-config.yaml`) that tails `/var/log/rippled/perf*.log`, parses each JSON line, and promotes `trace_id`, `ledger_seq`, and `tx_hash` to Loki labels.
|
||||
|
||||
**Step 2: Add trace_id to PerfLog entries**
|
||||
|
||||
Modify PerfLog so its JSON output includes a `trace_id` field whenever a valid span is active: fetch the current span from the OpenTelemetry runtime context, and if its context is valid, render the trace ID as a 32-character lowercase hex string into the log entry.
|
||||
|
||||
**Step 3: Configure Grafana trace-to-logs link**
|
||||
|
||||
In the Tempo datasource, set the `tracesToLogs` derived field to link to Loki on the `trace_id` and `tx_hash` tags, with `filterByTraceID: true`.
|
||||
|
||||
### 5.8.7 Correlation with Insight/StatsD Metrics
|
||||
|
||||
To correlate traces with existing Beast Insight metrics:
|
||||
|
||||
**Step 1: Export Insight metrics to Prometheus**
|
||||
|
||||
Add a Prometheus scrape job (`prometheus.yaml`) named `xrpld-statsd` targeting the StatsD exporter at `statsd-exporter:9102`.
|
||||
|
||||
**Step 2: Add exemplars to metrics**
|
||||
|
||||
The OpenTelemetry SDK automatically adds exemplars (trace IDs) to metrics when using the Prometheus exporter, linking metric spikes to specific traces.
|
||||
|
||||
**Step 3: Configure Grafana metric-to-trace link**
|
||||
|
||||
In the Prometheus datasource, set `exemplarTraceIdDestinations` to map the `trace_id` exemplar to the Tempo datasource.
|
||||
|
||||
**Step 4: Dashboard panel with exemplars**
|
||||
|
||||
Add a timeseries panel over Prometheus (e.g. `histogram_quantile(0.99, rate(xrpld_rpc_duration_seconds_bucket[5m]))`) with `exemplar: true` enabled.
|
||||
|
||||
This allows clicking on metric data points to jump directly to the related trace.
|
||||
|
||||
---
|
||||
|
||||
_Previous: [Implementation Strategy](./03-implementation-strategy.md)_ | _Next: [Implementation Phases](./06-implementation-phases.md)_ | _Back to: [Overview](./OpenTelemetryPlan.md)_
|
||||
673
OpenTelemetryPlan/06-implementation-phases.md
Normal file
673
OpenTelemetryPlan/06-implementation-phases.md
Normal file
@@ -0,0 +1,673 @@
|
||||
# Implementation Phases
|
||||
|
||||
> **Parent Document**: [OpenTelemetryPlan.md](./OpenTelemetryPlan.md)
|
||||
> **Related**: [Configuration Reference](./05-configuration-reference.md) | [Observability Backends](./07-observability-backends.md)
|
||||
|
||||
---
|
||||
|
||||
## 6.1 Phase Overview
|
||||
|
||||
> **TxQ** = Transaction Queue
|
||||
|
||||
```mermaid
|
||||
gantt
|
||||
title OpenTelemetry Implementation Timeline
|
||||
dateFormat YYYY-MM-DD
|
||||
axisFormat Week %W
|
||||
|
||||
section Phase 1
|
||||
Core Infrastructure :p1, 2024-01-01, 2w
|
||||
SDK Integration :p1a, 2024-01-01, 4d
|
||||
Telemetry Interface :p1b, after p1a, 3d
|
||||
Configuration & CMake :p1c, after p1b, 3d
|
||||
Unit Tests :p1d, after p1c, 2d
|
||||
Buffer & Integration :p1e, after p1d, 2d
|
||||
|
||||
section Phase 2
|
||||
RPC Tracing :p2, after p1, 2w
|
||||
HTTP Context Extraction :p2a, after p1, 2d
|
||||
RPC Handler Instrumentation :p2b, after p2a, 4d
|
||||
PathFinding Instrumentation :p2f, after p2b, 2d
|
||||
TxQ Instrumentation :p2g, after p2f, 2d
|
||||
WebSocket Support :p2c, after p2g, 2d
|
||||
Integration Tests :p2d, after p2c, 2d
|
||||
Buffer & Review :p2e, after p2d, 4d
|
||||
|
||||
section Phase 3
|
||||
Transaction Tracing :p3, after p2, 2w
|
||||
Protocol Buffer Extension :p3a, after p2, 2d
|
||||
PeerImp Instrumentation :p3b, after p3a, 3d
|
||||
Fee Escalation Instrumentation :p3f, after p3b, 2d
|
||||
Relay Context Propagation :p3c, after p3f, 3d
|
||||
Multi-node Tests :p3d, after p3c, 2d
|
||||
Buffer & Review :p3e, after p3d, 4d
|
||||
|
||||
section Phase 4
|
||||
Consensus Tracing :p4, after p3, 2w
|
||||
Consensus Round Spans :p4a, after p3, 3d
|
||||
Proposal Handling :p4b, after p4a, 3d
|
||||
Establish Phase (4a) :p4f, after p4b, 3d
|
||||
Validation Tests :p4c, after p4f, 4d
|
||||
Buffer & Review :p4e, after p4c, 4d
|
||||
|
||||
section Phase 5
|
||||
Documentation & Deploy :p5, after p4, 1w
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 6.2 Phase 1: Core Infrastructure (Weeks 1-2)
|
||||
|
||||
**Objective**: Establish foundational telemetry infrastructure
|
||||
|
||||
### Tasks
|
||||
|
||||
| Task | Description |
|
||||
| ---- | ----------------------------------------------------- |
|
||||
| 1.1 | Add OpenTelemetry C++ SDK to Conan/CMake |
|
||||
| 1.2 | Implement `Telemetry` interface and factory |
|
||||
| 1.3 | Implement `SpanGuard` RAII wrapper |
|
||||
| 1.4 | Implement configuration parser |
|
||||
| 1.5 | Integrate into `ApplicationImp` |
|
||||
| 1.6 | Add conditional compilation (`XRPL_ENABLE_TELEMETRY`) |
|
||||
| 1.7 | Create `NullTelemetry` no-op implementation |
|
||||
| 1.8 | Unit tests for core infrastructure |
|
||||
|
||||
### Exit Criteria
|
||||
|
||||
- [ ] OpenTelemetry SDK compiles and links
|
||||
- [ ] Telemetry can be enabled/disabled via config
|
||||
- [ ] Basic span creation works
|
||||
- [ ] No performance regression when disabled
|
||||
- [ ] Unit tests passing
|
||||
|
||||
---
|
||||
|
||||
## 6.3 Phase 2: RPC Tracing (Weeks 3-4)
|
||||
|
||||
> **TxQ** = Transaction Queue
|
||||
|
||||
**Objective**: Complete tracing for all RPC operations
|
||||
|
||||
### Tasks
|
||||
|
||||
| Task | Description |
|
||||
| ---- | -------------------------------------------------------------------------- |
|
||||
| 2.1 | Implement W3C Trace Context HTTP header extraction |
|
||||
| 2.2 | Instrument `ServerHandler::onRequest()` |
|
||||
| 2.3 | Instrument `xrpl::rpc::doCommand()` |
|
||||
| 2.4 | Add RPC-specific attributes |
|
||||
| 2.5 | Instrument WebSocket handler |
|
||||
| 2.6 | PathFinding instrumentation (`pathfind.request`, `pathfind.compute` spans) |
|
||||
| 2.7 | TxQ instrumentation (`txq.enqueue`, `txq.apply` spans) |
|
||||
| 2.8 | Integration tests for RPC tracing |
|
||||
| 2.9 | Performance benchmarks |
|
||||
| 2.10 | Documentation |
|
||||
|
||||
### Exit Criteria
|
||||
|
||||
- [ ] All RPC commands traced
|
||||
- [ ] Trace context propagates from HTTP headers
|
||||
- [ ] WebSocket and HTTP both instrumented
|
||||
- [ ] <1ms overhead per RPC call
|
||||
- [ ] Integration tests passing
|
||||
|
||||
---
|
||||
|
||||
## 6.4 Phase 3: Transaction Tracing (Weeks 5-6)
|
||||
|
||||
**Objective**: Trace transaction lifecycle across network with deterministic cross-node correlation
|
||||
|
||||
### Tasks
|
||||
|
||||
| Task | Description |
|
||||
| ---- | -------------------------------------------------------------- |
|
||||
| 3.1 | Define `TraceContext` Protocol Buffer message |
|
||||
| 3.2 | Implement protobuf context serialization |
|
||||
| 3.3 | Instrument `PeerImp::handleTransaction()` |
|
||||
| 3.4 | Instrument `NetworkOPs::submitTransaction()` |
|
||||
| 3.5 | Instrument HashRouter integration |
|
||||
| 3.6 | Fee escalation instrumentation (`fee.escalate` span) |
|
||||
| 3.7 | Implement relay context propagation |
|
||||
| 3.8 | Integration tests (multi-node) |
|
||||
| 3.9 | Deterministic transaction trace ID (`trace_id = txHash[0:16]`) |
|
||||
| 3.10 | Performance benchmarks |
|
||||
|
||||
### Deterministic Trace ID (Task 3.9)
|
||||
|
||||
Transaction spans use **deterministic trace IDs** derived from the transaction hash:
|
||||
`trace_id = txHash[0:16]`. All nodes handling the same transaction independently
|
||||
produce spans under the same trace_id. Protobuf `span_id` propagation (Task 3.7)
|
||||
additionally provides parent-child relay ordering when available. See
|
||||
[02-design-decisions.md §2.5.0](./02-design-decisions.md) for the design rationale
|
||||
and [Phase3_taskList.md Task 3.9](./Phase3_taskList.md) for the full implementation spec.
|
||||
|
||||
### Exit Criteria
|
||||
|
||||
- [ ] Transaction traces span across nodes
|
||||
- [ ] Trace context in Protocol Buffer messages
|
||||
- [ ] HashRouter deduplication visible in traces
|
||||
- [ ] Multi-node integration tests passing
|
||||
- [ ] <5% overhead on transaction throughput
|
||||
- [ ] Deterministic trace_id: all nodes produce same trace_id for same transaction
|
||||
- [ ] Protobuf span_id propagation preserves parent-child ordering when available
|
||||
|
||||
---
|
||||
|
||||
## 6.5 Phase 4: Consensus Tracing (Weeks 7-8)
|
||||
|
||||
**Objective**: Full observability into consensus rounds
|
||||
|
||||
### Tasks
|
||||
|
||||
| Task | Description | Status |
|
||||
| ---- | ------------------------------------------- | ------------------ |
|
||||
| 4.1 | Instrument `RCLConsensus::startRound()` | ✅ Done (via 4a.2) |
|
||||
| 4.2 | Instrument phase transitions | ✅ Done |
|
||||
| 4.3 | Instrument proposal handling | ✅ Done |
|
||||
| 4.4 | Instrument validation handling | ✅ Done |
|
||||
| 4.5 | Add consensus-specific attributes | ✅ Done |
|
||||
| 4.6 | Correlate with transaction traces | ✅ Done |
|
||||
| 4.7 | Build verification and testing | ✅ Done |
|
||||
| 4.8 | Validation span enrichment (ext. dashboard) | ❌ Not done |
|
||||
|
||||
**Note**: The original plan doc listed tasks 4.7-4.11 as "Validator list tracing",
|
||||
"Amendment voting tracing", "SHAMap sync tracing", "Multi-validator integration tests",
|
||||
and "Performance validation". These were descoped and replaced by the tasklist's 4.7
|
||||
(build verification) and 4.8 (validation span enrichment). Validator, amendment, and
|
||||
SHAMap tracing are not implemented.
|
||||
|
||||
### Spans Produced
|
||||
|
||||
| Span Name | Location | Attributes |
|
||||
| --------------------------- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| `consensus.phase.open` | `Consensus.h` | _(none)_ |
|
||||
| `consensus.proposal.send` | `RCLConsensus.cpp` | `consensus_round` |
|
||||
| `consensus.ledger_close` | `RCLConsensus.cpp` | `ledger_seq`, `consensus_mode` |
|
||||
| `consensus.accept` | `RCLConsensus.cpp` | `proposers`, `round_time_ms`, `quorum` |
|
||||
| `consensus.accept.apply` | `RCLConsensus.cpp` | `close_time_ripple_epoch_s`, `close_time_correct`, `close_resolution_ms`, `consensus_state`, `proposing`, `round_time_ms`, `ledger_seq`, `parent_close_time_ripple_epoch_s`, `close_time_self_ripple_epoch_s`, `close_time_vote_bins`, `resolution_direction` |
|
||||
| `consensus.validation.send` | `RCLConsensus.cpp` | `ledger_seq`, `proposing` |
|
||||
|
||||
### Exit Criteria
|
||||
|
||||
- [x] Complete consensus round traces
|
||||
- [x] Phase transitions visible (open, establish, close, accept)
|
||||
- [x] Proposals and validations traced — send and receive; relay deferred to Phase 4b
|
||||
- [x] Close time agreement tracked (per `avCT_CONSENSUS_PCT`)
|
||||
- [x] No impact on consensus timing
|
||||
- [ ] Multi-validator test network validated
|
||||
- [x] Transaction-consensus correlation (Task 4.6) — `tx.included` events in doAccept
|
||||
- [ ] Validation span enrichment (Task 4.8) — not implemented
|
||||
|
||||
### Implementation Status — Phase 4a Complete
|
||||
|
||||
Phase 4a (establish-phase gap fill & cross-node correlation) adds:
|
||||
|
||||
- **Deterministic trace ID** derived from `previousLedger.id()` so all validators
|
||||
in the same round share the same `trace_id` (switchable via
|
||||
`consensus_trace_strategy` config: `"deterministic"`, or `"random"` which is
|
||||
experimental and not used).
|
||||
See [Configuration Reference](./05-configuration-reference.md) for full
|
||||
configuration options.
|
||||
- **Round lifecycle spans**: `consensus.round` with round-to-round span links.
|
||||
- **Establish phase**: `consensus.establish`, `consensus.update_positions` (with
|
||||
`dispute.resolve` events), `consensus.check` (with threshold tracking).
|
||||
- **Mode changes**: `consensus.mode_change` spans.
|
||||
- **Validation**: `consensus.validation.send` with span link to round span
|
||||
(thread-safe cross-thread access via `roundSpanContext_` snapshot).
|
||||
- **Separation of concerns**: telemetry extracted to private helpers
|
||||
(`startRoundTracing`, `createValidationSpan`, `startEstablishTracing`,
|
||||
`updateEstablishTracing`, `endEstablishTracing`).
|
||||
|
||||
See [Phase4_taskList.md](./Phase4_taskList.md) for the full spec and implementation notes.
|
||||
|
||||
---
|
||||
|
||||
## 6.5a Phase 4a: Establish-Phase Gap Fill & Cross-Node Correlation
|
||||
|
||||
**Objective**: Fill tracing gaps in the establish phase and establish cross-node
|
||||
correlation using deterministic trace IDs derived from `previousLedger.id()`.
|
||||
|
||||
**Approach**: Direct instrumentation in `Consensus.h` and `RCLConsensus.cpp`.
|
||||
All spans use `SpanGuard` factory methods (`span()`, `hashSpan()`, `linkedSpan()`)
|
||||
with `TraceCategory::Consensus` gating. No macros used — all tracing via direct
|
||||
`SpanGuard` API calls.
|
||||
|
||||
### Tasks
|
||||
|
||||
| Task | Description | Effort | Risk | Status |
|
||||
| ---- | ------------------------------------------------ | ------ | ------ | ------------------------ |
|
||||
| 4a.0 | Prerequisites: extend SpanGuard & Telemetry APIs | 1d | Medium | ✅ Done (no macros) |
|
||||
| 4a.1 | Adaptor `getTelemetry()` method | 0.5d | Low | ⏭️ Skipped (not needed) |
|
||||
| 4a.2 | Switchable round span with deterministic traceID | 2d | High | ✅ Done |
|
||||
| 4a.3 | Span members in `Consensus.h` | 0.5d | Medium | ✅ Done (with deviation) |
|
||||
| 4a.4 | Instrument `phaseEstablish()` | 1d | Medium | ✅ Done |
|
||||
| 4a.5 | Instrument `updateOurPositions()` | 1d | Medium | ✅ Done |
|
||||
| 4a.6 | Instrument `haveConsensus()` (thresholds) | 1d | Medium | ✅ Done |
|
||||
| 4a.7 | Instrument mode changes | 0.5d | Low | ✅ Done |
|
||||
| 4a.8 | Reparent existing spans under round | 0.5d | Low | ✅ Done |
|
||||
| 4a.9 | Build verification and testing | 1d | Low | ✅ Done |
|
||||
|
||||
**Total Effort**: 9 days
|
||||
|
||||
### Spans Produced
|
||||
|
||||
| Span Name | Location | Key Attributes (actually set) |
|
||||
| ---------------------------- | ------------------ | ----------------------------------------------------------------------------------------------------------------------------- |
|
||||
| `consensus.round` | `RCLConsensus.cpp` | `consensus_round_id`, `consensus_ledger_id`, `ledger_seq`, `consensus_mode`, `trace_strategy` |
|
||||
| `consensus.establish` | `Consensus.h` | `converge_percent`, `establish_count`, `proposers` |
|
||||
| `consensus.update_positions` | `Consensus.h` | `converge_percent`, `proposers`, `have_close_time_consensus`, `close_time_threshold`, `disputes_count`, `avalanche_threshold` |
|
||||
| `consensus.check` | `Consensus.h` | `agree_count`, `disagree_count`, `converge_percent`, `have_close_time_consensus`, `threshold_percent`, `consensus_result` |
|
||||
| `consensus.mode_change` | `RCLConsensus.cpp` | `mode_old`, `mode_new` |
|
||||
|
||||
### Exit Criteria
|
||||
|
||||
- [x] Establish phase internals traced (establish, update_positions, check spans)
|
||||
- [x] Establish phase fully traced — `disputes_count`, `avalanche_threshold`, dispute `yays`/`nays` all implemented
|
||||
- [x] Cross-node correlation works via deterministic trace_id
|
||||
- [x] Strategy switchable via config (`deterministic` / `attribute`)
|
||||
- [x] Consecutive rounds linked via follows-from spans
|
||||
- [x] Build passes with telemetry ON and OFF
|
||||
- [x] No impact on consensus timing
|
||||
|
||||
See [Phase4_taskList.md](./Phase4_taskList.md) for full task details.
|
||||
|
||||
---
|
||||
|
||||
## 6.5b Phase 4b: Cross-Node Propagation (Future)
|
||||
|
||||
**Objective**: Wire `TraceContextPropagator` for P2P messages (proposals,
|
||||
validations) to enable true distributed tracing between nodes.
|
||||
|
||||
**Status**: Partially implemented. Send-side injection (proposals and
|
||||
validations) and receive-side extraction (`consensus.{proposal,validation}.
|
||||
receive` spans parented on the sender's context) are wired in Phase 4a.
|
||||
Remaining Phase 4b work: relay spans in `share(RCLCxPeerPos)` and multi-node
|
||||
validation of the propagation path.
|
||||
|
||||
**Prerequisites**: Phase 4a complete and validated.
|
||||
|
||||
See [Phase4_taskList.md § Phase 4b](./Phase4_taskList.md) for full design.
|
||||
|
||||
---
|
||||
|
||||
## 6.6 Phase 5: Documentation & Deployment (Week 9)
|
||||
|
||||
**Objective**: Production readiness
|
||||
|
||||
### Tasks
|
||||
|
||||
| Task | Description |
|
||||
| ---- | ----------------------------- |
|
||||
| 5.1 | Operator runbook |
|
||||
| 5.2 | Grafana dashboards |
|
||||
| 5.3 | Alert definitions |
|
||||
| 5.4 | Collector deployment examples |
|
||||
| 5.5 | Developer documentation |
|
||||
| 5.6 | Training materials |
|
||||
| 5.7 | Final integration testing |
|
||||
|
||||
---
|
||||
|
||||
## 6.7 Risk Assessment
|
||||
|
||||
```mermaid
|
||||
quadrantChart
|
||||
title Risk Assessment Matrix
|
||||
x-axis Low Impact --> High Impact
|
||||
y-axis Low Likelihood --> High Likelihood
|
||||
quadrant-1 Mitigate Immediately
|
||||
quadrant-2 Plan Mitigation
|
||||
quadrant-3 Accept Risk
|
||||
quadrant-4 Monitor Closely
|
||||
|
||||
SDK Compat: [0.2, 0.18]
|
||||
Protocol Chg: [0.75, 0.72]
|
||||
Perf Overhead: [0.58, 0.42]
|
||||
Context Prop: [0.4, 0.55]
|
||||
Memory Leaks: [0.85, 0.25]
|
||||
```
|
||||
|
||||
### Risk Details
|
||||
|
||||
| Risk | Likelihood | Impact | Mitigation |
|
||||
| ------------------------------------ | ---------- | ------ | --------------------------------------- |
|
||||
| Protocol changes break compatibility | Medium | High | Use high field numbers, optional fields |
|
||||
| Performance overhead unacceptable | Medium | Medium | Sampling, conditional compilation |
|
||||
| Context propagation complexity | Medium | Medium | Phased rollout, extensive testing |
|
||||
| SDK compatibility issues | Low | Medium | Pin SDK version, fallback to no-op |
|
||||
| Memory leaks in long-running nodes | Low | High | Memory profiling, bounded queues |
|
||||
|
||||
---
|
||||
|
||||
## 6.8 Success Metrics
|
||||
|
||||
| Metric | Target | Measurement |
|
||||
| ------------------------ | -------------------------------------------------------------- | --------------------- |
|
||||
| Trace coverage | >95% of transaction code paths (independent of sampling ratio) | Sampling verification |
|
||||
| CPU overhead | <3% | Benchmark tests |
|
||||
| Memory overhead | <10 MB | Memory profiling |
|
||||
| Latency impact (p99) | <2% | Performance tests |
|
||||
| Trace completeness | >99% spans with required attrs | Validation script |
|
||||
| Cross-node trace linkage | >90% of multi-hop transactions | Integration tests |
|
||||
|
||||
---
|
||||
|
||||
## 6.9 Quick Wins and Crawl-Walk-Run Strategy
|
||||
|
||||
> **TxQ** = Transaction Queue
|
||||
|
||||
This section outlines a prioritized approach to maximize ROI with minimal initial investment.
|
||||
|
||||
### 6.9.1 Crawl-Walk-Run Overview
|
||||
|
||||
<div align="center">
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph crawl["🐢 CRAWL (Week 1-2)"]
|
||||
direction LR
|
||||
c1[Core SDK Setup] ~~~ c2[RPC Tracing Only] ~~~ c3[PathFinding + TxQ Tracing] ~~~ c4[Single Node]
|
||||
end
|
||||
|
||||
subgraph walk["🚶 WALK (Week 3-5)"]
|
||||
direction LR
|
||||
w1[Transaction Tracing] ~~~ w2[Fee Escalation Tracing] ~~~ w3[Cross-Node Context] ~~~ w4[Basic Dashboards]
|
||||
end
|
||||
|
||||
subgraph run["🏃 RUN (Week 6-9)"]
|
||||
direction LR
|
||||
r1[Consensus Tracing] ~~~ r2[Establish Phase<br/>& Cross-Node Correlation] ~~~ r3[StatsD Integration] ~~~ r4[Production Deploy]
|
||||
end
|
||||
|
||||
crawl --> walk --> run
|
||||
|
||||
style crawl fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style walk fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style run fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style c1 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style c2 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style c3 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style c4 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style w1 fill:#ffe0b2,stroke:#ffcc80,color:#1e293b
|
||||
style w2 fill:#ffe0b2,stroke:#ffcc80,color:#1e293b
|
||||
style w3 fill:#ffe0b2,stroke:#ffcc80,color:#1e293b
|
||||
style w4 fill:#ffe0b2,stroke:#ffcc80,color:#1e293b
|
||||
style r1 fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style r2 fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style r3 fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style r4 fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
```
|
||||
|
||||
</div>
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **CRAWL (Weeks 1-2)**: Minimal investment -- set up the SDK, instrument RPC and PathFinding/TxQ handlers, and verify on a single node. Delivers immediate latency visibility.
|
||||
- **WALK (Weeks 3-5)**: Expand to transaction lifecycle tracing, fee escalation, cross-node context propagation, and basic Grafana dashboards. This is where distributed tracing starts working.
|
||||
- **RUN (Weeks 6-9)**: Full consensus instrumentation, establish-phase gap fill, cross-node correlation, StatsD integration, and production deployment with sampling and alerting.
|
||||
- **Arrows (crawl → walk → run)**: Each phase builds on the prior one; you cannot skip ahead because later phases depend on infrastructure established earlier.
|
||||
|
||||
### 6.9.2 Quick Wins (Immediate Value)
|
||||
|
||||
| Quick Win | Value | When to Deploy |
|
||||
| ------------------------------ | ------ | -------------- |
|
||||
| **RPC Command Tracing** | High | Week 2 |
|
||||
| **RPC Latency Histograms** | High | Week 2 |
|
||||
| **Error Rate Dashboard** | Medium | Week 2 |
|
||||
| **Transaction Submit Tracing** | High | Week 3 |
|
||||
| **Consensus Round Duration** | Medium | Week 6 |
|
||||
|
||||
### 6.9.3 CRAWL Phase (Weeks 1-2)
|
||||
|
||||
**Goal**: Get basic tracing working with minimal code changes.
|
||||
|
||||
**What You Get**:
|
||||
|
||||
- RPC request/response traces for all commands
|
||||
- Latency breakdown per RPC command
|
||||
- PathFinding and TxQ tracing (directly impacts RPC latency)
|
||||
- Error visibility with stack traces
|
||||
- Basic Grafana dashboard
|
||||
|
||||
**Code Changes**: ~15 lines in `ServerHandler.cpp`, ~40 lines in new telemetry module
|
||||
|
||||
**Why Start Here**:
|
||||
|
||||
- RPC is the lowest-risk, highest-visibility component
|
||||
- PathFinding and TxQ are RPC-adjacent and directly affect latency
|
||||
- Immediate value for debugging client issues
|
||||
- No cross-node complexity
|
||||
- Single file modification to existing code
|
||||
|
||||
### 6.9.4 WALK Phase (Weeks 3-5)
|
||||
|
||||
**Goal**: Add transaction lifecycle tracing across nodes.
|
||||
|
||||
**What You Get**:
|
||||
|
||||
- End-to-end transaction traces from submit to relay
|
||||
- Fee escalation tracing within the transaction pipeline
|
||||
- Cross-node correlation (see transaction path)
|
||||
- HashRouter deduplication visibility
|
||||
- Relay latency metrics
|
||||
|
||||
**Code Changes**: ~120 lines across 4 files, plus protobuf extension
|
||||
|
||||
**Why Do This Second**:
|
||||
|
||||
- Builds on RPC tracing (transactions submitted via RPC)
|
||||
- Fee escalation is integral to the transaction processing pipeline
|
||||
- Moderate complexity (requires context propagation)
|
||||
- High value for debugging transaction issues
|
||||
|
||||
### 6.9.5 RUN Phase (Weeks 6-9)
|
||||
|
||||
**Goal**: Full observability including consensus.
|
||||
|
||||
**What You Get**:
|
||||
|
||||
- Complete consensus round visibility
|
||||
- Phase transition timing
|
||||
- Validator proposal tracking
|
||||
- ~~Validator list and manifest tracing~~ — descoped
|
||||
- ~~Amendment voting tracing~~ — descoped
|
||||
- ~~SHAMap sync tracing~~ — descoped
|
||||
- Full end-to-end traces (client → RPC → TX → consensus → ledger) — partial (tx-consensus correlation not yet done)
|
||||
|
||||
**Code Changes**: ~100 lines across 3 consensus files
|
||||
|
||||
**Why Do This Last**:
|
||||
|
||||
- Highest complexity (consensus is critical path)
|
||||
- Validator, amendment, and SHAMap components were descoped (lower priority)
|
||||
- Requires thorough testing
|
||||
- Lower relative value (consensus issues are rarer)
|
||||
|
||||
### 6.9.6 ROI Prioritization Matrix
|
||||
|
||||
```mermaid
|
||||
quadrantChart
|
||||
title Implementation ROI Matrix
|
||||
x-axis Low Effort --> High Effort
|
||||
y-axis Low Value --> High Value
|
||||
quadrant-1 Quick Wins - Do First
|
||||
quadrant-2 Major Projects - Plan Carefully
|
||||
quadrant-3 Nice to Have - Optional
|
||||
quadrant-4 Time Sinks - Avoid
|
||||
|
||||
RPC Tracing: [0.15, 0.92]
|
||||
TX Submit Trace: [0.3, 0.78]
|
||||
TX Relay Trace: [0.5, 0.88]
|
||||
Consensus Trace: [0.72, 0.72]
|
||||
Peer Msg Trace: [0.85, 0.3]
|
||||
Ledger Acquire: [0.55, 0.52]
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 6.10 Definition of Done
|
||||
|
||||
> **TxQ** = Transaction Queue | **HA** = High Availability
|
||||
|
||||
Clear, measurable criteria for each phase.
|
||||
|
||||
### 6.10.1 Phase 1: Core Infrastructure
|
||||
|
||||
| Criterion | Measurement | Target |
|
||||
| --------------- | ---------------------------------------------------------- | ---------------------------- |
|
||||
| SDK Integration | `cmake --build` succeeds with `-DXRPL_ENABLE_TELEMETRY=ON` | ✅ Compiles |
|
||||
| Runtime Toggle | `enabled=0` produces zero overhead | <0.1% CPU difference |
|
||||
| Span Creation | Unit test creates and exports span | Span appears in Tempo |
|
||||
| Configuration | All config options parsed correctly | Config validation tests pass |
|
||||
| Documentation | Developer guide exists | PR approved |
|
||||
|
||||
**Definition of Done**: All criteria met, PR merged, no regressions in CI.
|
||||
|
||||
### 6.10.2 Phase 2: RPC Tracing
|
||||
|
||||
| Criterion | Measurement | Target |
|
||||
| ------------------ | ---------------------------------- | -------------------------- |
|
||||
| Coverage | All RPC commands instrumented | 100% of commands |
|
||||
| Context Extraction | traceparent header propagates | Integration test passes |
|
||||
| Attributes | Command, status, duration recorded | Validation script confirms |
|
||||
| Performance | RPC latency overhead | <1ms p99 |
|
||||
| Dashboard | Grafana dashboard deployed | Screenshot in docs |
|
||||
|
||||
**Definition of Done**: RPC traces visible in Tempo for all commands, dashboard shows latency distribution.
|
||||
|
||||
### 6.10.3 Phase 3: Transaction Tracing
|
||||
|
||||
| Criterion | Measurement | Target |
|
||||
| --------------------- | ------------------------------------------------- | -------------------------------------------------------- |
|
||||
| Local Trace | Submit → validate → TxQ traced | Single-node test passes |
|
||||
| Cross-Node | Context propagates via protobuf | Multi-node test passes |
|
||||
| Deterministic TraceID | Same trace_id on all nodes for same tx | Multi-node test: query by txHash[0:16] returns all spans |
|
||||
| Relay Ordering | Protobuf span_id propagation creates parent-child | Tempo trace tree shows relay chain |
|
||||
| Graceful Degradation | Old peer drops trace_context | Spans still grouped by deterministic trace_id |
|
||||
| Relay Visibility | relay_count attribute correct | Spot check 100 txs |
|
||||
| HashRouter | Deduplication visible in trace | Duplicate txs show suppressed=true |
|
||||
| Performance | TX throughput overhead | <5% degradation |
|
||||
|
||||
**Definition of Done**: Transaction traces span 3+ nodes in test network with deterministic trace_id correlation, parent-child ordering via protobuf propagation, and performance within bounds.
|
||||
|
||||
### 6.10.4 Phase 4: Consensus Tracing
|
||||
|
||||
| Criterion | Measurement | Target |
|
||||
| -------------------- | ----------------------------- | ------------------------- |
|
||||
| Round Tracing | startRound creates root span | Unit test passes |
|
||||
| Phase Visibility | All phases have child spans | Integration test confirms |
|
||||
| Proposer Attribution | Proposer ID in attributes | Spot check 50 rounds |
|
||||
| Timing Accuracy | Phase durations match PerfLog | <5% variance |
|
||||
| No Consensus Impact | Round timing unchanged | Performance test passes |
|
||||
|
||||
**Definition of Done**: Consensus rounds fully traceable, no impact on consensus timing.
|
||||
|
||||
### 6.10.5 Phase 5: Production Deployment
|
||||
|
||||
| Criterion | Measurement | Target |
|
||||
| ------------ | ---------------------------- | -------------------------- |
|
||||
| Collector HA | Multiple collectors deployed | No single point of failure |
|
||||
| Sampling | Tail sampling configured | 10% base + errors + slow |
|
||||
| Retention | Data retained per policy | 7 days hot, 30 days warm |
|
||||
| Alerting | Alerts configured | Error spike, high latency |
|
||||
| Runbook | Operator documentation | Approved by ops team |
|
||||
| Training | Team trained | Session completed |
|
||||
|
||||
**Definition of Done**: Telemetry running in production, operators trained, alerts active.
|
||||
|
||||
### 6.10.6 Success Metrics Summary
|
||||
|
||||
| Phase | Primary Metric | Secondary Metric | Deadline |
|
||||
| ------- | ---------------------- | --------------------------- | ------------- |
|
||||
| Phase 1 | SDK compiles and runs | Zero overhead when disabled | End of Week 2 |
|
||||
| Phase 2 | 100% RPC coverage | <1ms latency overhead | End of Week 4 |
|
||||
| Phase 3 | Cross-node traces work | <5% throughput impact | End of Week 6 |
|
||||
| Phase 4 | Consensus fully traced | No consensus timing impact | End of Week 8 |
|
||||
| Phase 5 | Production deployment | Operators trained | End of Week 9 |
|
||||
|
||||
---
|
||||
|
||||
## 6.11 Recommended Implementation Order
|
||||
|
||||
Based on ROI analysis, implement in this exact order:
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph week1["Week 1"]
|
||||
t1[1. OpenTelemetry SDK<br/>Conan/CMake integration]
|
||||
t2[2. Telemetry interface<br/>SpanGuard, config]
|
||||
end
|
||||
|
||||
subgraph week2["Week 2"]
|
||||
t3[3. RPC ServerHandler<br/>instrumentation]
|
||||
t4[4. Basic Tempo setup<br/>for testing]
|
||||
end
|
||||
|
||||
subgraph week3["Week 3"]
|
||||
t5[5. Transaction submit<br/>tracing]
|
||||
t6[6. Grafana dashboard<br/>v1]
|
||||
end
|
||||
|
||||
subgraph week4["Week 4"]
|
||||
t7[7. Protobuf context<br/>extension]
|
||||
t8[8. PeerImp tx.relay<br/>instrumentation]
|
||||
end
|
||||
|
||||
subgraph week5["Week 5"]
|
||||
t9[9. Multi-node<br/>integration tests]
|
||||
t10[10. Performance<br/>benchmarks]
|
||||
end
|
||||
|
||||
subgraph week6_8["Weeks 6-8"]
|
||||
t11[11. Consensus<br/>instrumentation]
|
||||
t12[12. Full integration<br/>testing]
|
||||
end
|
||||
|
||||
subgraph week9["Week 9"]
|
||||
t13[13. Production<br/>deployment]
|
||||
t14[14. Documentation<br/>& training]
|
||||
end
|
||||
|
||||
t1 --> t2 --> t3 --> t4
|
||||
t4 --> t5 --> t6
|
||||
t6 --> t7 --> t8
|
||||
t8 --> t9 --> t10
|
||||
t10 --> t11 --> t12
|
||||
t12 --> t13 --> t14
|
||||
|
||||
style week1 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style week2 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style week3 fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style week4 fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style week5 fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style week6_8 fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style week9 fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
style t1 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style t2 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style t3 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style t4 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style t5 fill:#ffe0b2,stroke:#ffcc80,color:#1e293b
|
||||
style t6 fill:#ffe0b2,stroke:#ffcc80,color:#1e293b
|
||||
style t7 fill:#ffe0b2,stroke:#ffcc80,color:#1e293b
|
||||
style t8 fill:#ffe0b2,stroke:#ffcc80,color:#1e293b
|
||||
style t9 fill:#ffe0b2,stroke:#ffcc80,color:#1e293b
|
||||
style t10 fill:#ffe0b2,stroke:#ffcc80,color:#1e293b
|
||||
style t11 fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style t12 fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style t13 fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
style t14 fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **Week 1 (tasks 1-2)**: Foundation work -- integrate the OpenTelemetry SDK via Conan/CMake and build the `Telemetry` interface with `SpanGuard` and config parsing.
|
||||
- **Week 2 (tasks 3-4)**: First observable output -- instrument `ServerHandler` for RPC tracing and stand up Tempo so developers can see traces immediately.
|
||||
- **Weeks 3-5 (tasks 5-10)**: Transaction lifecycle -- add submit tracing, build the first Grafana dashboard, extend protobuf for cross-node context, instrument `PeerImp` relay, then validate with multi-node integration tests and performance benchmarks.
|
||||
- **Weeks 6-8 (tasks 11-12)**: Consensus deep-dive -- instrument consensus rounds and phases, then run full integration testing across all instrumented paths.
|
||||
- **Week 9 (tasks 13-14)**: Go-live -- deploy to production with sampling/alerting configured, and deliver documentation and operator training.
|
||||
- **Arrow chain (t1 → ... → t14)**: Strict sequential dependency; each task's output is a prerequisite for the next.
|
||||
|
||||
---
|
||||
|
||||
_Previous: [Configuration Reference](./05-configuration-reference.md)_ | _Next: [Observability Backends](./07-observability-backends.md)_ | _Back to: [Overview](./OpenTelemetryPlan.md)_
|
||||
407
OpenTelemetryPlan/07-observability-backends.md
Normal file
407
OpenTelemetryPlan/07-observability-backends.md
Normal file
@@ -0,0 +1,407 @@
|
||||
# Observability Backend Recommendations
|
||||
|
||||
> **Parent Document**: [OpenTelemetryPlan.md](./OpenTelemetryPlan.md)
|
||||
> **Related**: [Implementation Phases](./06-implementation-phases.md) | [Appendix](./08-appendix.md)
|
||||
|
||||
---
|
||||
|
||||
## 7.1 Development/Testing Backends
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
| Backend | Pros | Cons | Use Case |
|
||||
| ---------- | ----------------------------------- | ---------------------- | ------------------- |
|
||||
| **Tempo** | Cost-effective, Grafana integration | Requires Grafana stack | Local dev, CI, Prod |
|
||||
| **Zipkin** | Simple, lightweight | Basic features | Quick prototyping |
|
||||
|
||||
### Quick Start with Tempo
|
||||
|
||||
```bash
|
||||
# Start Tempo with OTLP support
|
||||
docker run -d --name tempo \
|
||||
-p 3200:3200 \
|
||||
-p 4317:4317 \
|
||||
-p 4318:4318 \
|
||||
grafana/tempo:2.6.1
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 7.2 Production Backends
|
||||
|
||||
> **APM** = Application Performance Monitoring
|
||||
|
||||
| Backend | Pros | Cons | Use Case |
|
||||
| ----------------- | ----------------------------------------- | ---------------------- | --------------------------- |
|
||||
| **Grafana Tempo** | Cost-effective, Grafana integration | Requires Grafana stack | Most production deployments |
|
||||
| **Elastic APM** | Full observability stack, log correlation | Resource intensive | Existing Elastic users |
|
||||
| **Honeycomb** | Excellent query, high cardinality | SaaS cost | Deep debugging needs |
|
||||
| **Datadog APM** | Full platform, easy setup | SaaS cost | Enterprise with budget |
|
||||
|
||||
### Backend Selection Flowchart
|
||||
|
||||
```mermaid
|
||||
flowchart TD
|
||||
start[Select Backend] --> budget{Budget<br/>Constraints?}
|
||||
|
||||
budget -->|Yes| oss[Open Source]
|
||||
budget -->|No| saas{Prefer<br/>SaaS?}
|
||||
|
||||
oss --> existing{Existing<br/>Stack?}
|
||||
existing -->|Grafana| tempo[Grafana Tempo]
|
||||
existing -->|Elastic| elastic[Elastic APM]
|
||||
existing -->|None| tempo
|
||||
|
||||
saas -->|Yes| enterprise{Enterprise<br/>Support?}
|
||||
saas -->|No| oss
|
||||
|
||||
enterprise -->|Yes| datadog[Datadog APM]
|
||||
enterprise -->|No| honeycomb[Honeycomb]
|
||||
|
||||
tempo --> final[Configure Collector]
|
||||
elastic --> final
|
||||
honeycomb --> final
|
||||
datadog --> final
|
||||
|
||||
style start fill:#0f172a,stroke:#020617,color:#fff
|
||||
style budget fill:#334155,stroke:#1e293b,color:#fff
|
||||
style oss fill:#1e293b,stroke:#0f172a,color:#fff
|
||||
style existing fill:#334155,stroke:#1e293b,color:#fff
|
||||
style saas fill:#334155,stroke:#1e293b,color:#fff
|
||||
style enterprise fill:#334155,stroke:#1e293b,color:#fff
|
||||
style final fill:#0f172a,stroke:#020617,color:#fff
|
||||
style tempo fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style elastic fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style honeycomb fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style datadog fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **Budget Constraints? (Yes)**: Leads to open-source options. If you already run Grafana or Elastic, pick the matching backend; otherwise default to Grafana Tempo.
|
||||
- **Budget Constraints? (No) → Prefer SaaS?**: If you want a managed service, choose between Datadog (enterprise support) and Honeycomb (developer-focused). If not, fall back to open-source.
|
||||
- **Terminal nodes (Tempo / Elastic / Honeycomb / Datadog)**: Each represents a concrete backend choice, all of which feed into the same final step.
|
||||
- **Configure Collector**: Regardless of backend, you always finish by configuring the OTel Collector to export to your chosen destination.
|
||||
|
||||
---
|
||||
|
||||
## 7.3 Recommended Production Architecture
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol | **APM** = Application Performance Monitoring | **HA** = High Availability
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph validators["Validator Nodes"]
|
||||
v1[xrpld<br/>Validator 1]
|
||||
v2[xrpld<br/>Validator 2]
|
||||
end
|
||||
|
||||
subgraph stock["Stock Nodes"]
|
||||
s1[xrpld<br/>Stock 1]
|
||||
s2[xrpld<br/>Stock 2]
|
||||
end
|
||||
|
||||
subgraph collector["OTel Collector Cluster"]
|
||||
c1[Collector<br/>DC1]
|
||||
c2[Collector<br/>DC2]
|
||||
end
|
||||
|
||||
subgraph backends["Storage Backends"]
|
||||
tempo[(Grafana<br/>Tempo)]
|
||||
elastic[(Elastic<br/>APM)]
|
||||
archive[(S3/GCS<br/>Archive)]
|
||||
end
|
||||
|
||||
subgraph ui["Visualization"]
|
||||
grafana[Grafana<br/>Dashboards]
|
||||
end
|
||||
|
||||
v1 -->|OTLP| c1
|
||||
v2 -->|OTLP| c1
|
||||
s1 -->|OTLP| c2
|
||||
s2 -->|OTLP| c2
|
||||
|
||||
c1 --> tempo
|
||||
c1 --> elastic
|
||||
c2 --> tempo
|
||||
c2 --> archive
|
||||
|
||||
tempo --> grafana
|
||||
elastic --> grafana
|
||||
|
||||
%% Note: simplified single-collector-per-DC topology shown for clarity
|
||||
|
||||
style validators fill:#b71c1c,stroke:#7f1d1d,color:#ffffff
|
||||
style stock fill:#0d47a1,stroke:#082f6a,color:#ffffff
|
||||
style collector fill:#bf360c,stroke:#8c2809,color:#ffffff
|
||||
style backends fill:#1b5e20,stroke:#0d3d14,color:#ffffff
|
||||
style ui fill:#4a148c,stroke:#2e0d57,color:#ffffff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **Validator / Stock Nodes**: All xrpld nodes emit trace data via OTLP. Validators and stock nodes are grouped separately because they may reside in different network zones.
|
||||
- **Collector Cluster (DC1, DC2)**: Regional collectors receive OTLP from nodes in their datacenter, apply processing (sampling, enrichment), and fan out to multiple backends. Enrichment includes deployment-tier tagging: each collector stamps `deployment.environment` and (as a fallback) `xrpl.network.type` so one Grafana stack can filter data from many collectors by tier.
|
||||
- **Storage Backends**: Tempo and Elastic provide queryable trace storage; S3/GCS Archive provides long-term cold storage for compliance or post-incident analysis.
|
||||
- **Grafana Dashboards**: The single visualization layer that queries both Tempo and Elastic, giving operators a unified view of all traces.
|
||||
- **Data flow direction**: Nodes → Collectors → Storage → Grafana. Each arrow represents a network hop; minimizing collector-to-backend hops reduces latency.
|
||||
|
||||
> **Note**: Production deployments should use multiple collector instances behind a load balancer for high availability. The diagram shows a simplified single-collector topology for clarity.
|
||||
|
||||
---
|
||||
|
||||
## 7.4 Architecture Considerations
|
||||
|
||||
### 7.4.1 Collector Placement
|
||||
|
||||
| Strategy | Description | Pros | Cons |
|
||||
| ------------- | -------------------- | ------------------------ | ----------------------- |
|
||||
| **Sidecar** | Collector per node | Isolation, simple config | Resource overhead |
|
||||
| **DaemonSet** | Collector per host | Shared resources | Complexity |
|
||||
| **Gateway** | Central collector(s) | Centralized processing | Single point of failure |
|
||||
|
||||
**Recommendation**: Use **Gateway** pattern with regional collectors for xrpld networks:
|
||||
|
||||
- One collector cluster per datacenter/region
|
||||
- Tail-based sampling at collector level
|
||||
- Multiple export destinations for redundancy
|
||||
|
||||
### 7.4.2 Sampling Strategy
|
||||
|
||||
```mermaid
|
||||
flowchart LR
|
||||
subgraph head["Head Sampling (Node)"]
|
||||
hs[Node-level head sampling<br/>fixed at 100%<br/>not configurable]
|
||||
end
|
||||
|
||||
subgraph tail["Tail Sampling (Collector)"]
|
||||
ts1[Keep all errors]
|
||||
ts2[Keep slow >5s]
|
||||
ts3[Keep 10% rest]
|
||||
end
|
||||
|
||||
head --> tail
|
||||
|
||||
ts1 --> final[Final Traces]
|
||||
ts2 --> final
|
||||
ts3 --> final
|
||||
|
||||
style head fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style tail fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style hs fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style ts1 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style ts2 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style ts3 fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style final fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **Head Sampling (Node)**: xrpld pins head sampling at 100% (sample everything) and does not expose a configurable ratio. This is intentional: a per-node ratio would let different nodes make divergent keep/drop decisions for the same distributed trace, producing broken/partial traces. xrpld uses a `ParentBased` sampler so spans inheriting a remote parent honor the upstream decision. Volume reduction is delegated to the collector's tail sampling.
|
||||
- **Tail Sampling (Collector)**: The second filter -- the collector inspects completed traces and applies rules: keep all errors, keep anything slower than 5 seconds, and keep 10% of the remainder.
|
||||
- **Arrow head → tail**: All head-sampled traces flow to the collector, where tail sampling further reduces volume while preserving the most valuable data.
|
||||
- **Final Traces**: The output after both sampling stages; this is what gets stored and queried. The two-stage approach balances cost with debuggability.
|
||||
|
||||
### 7.4.3 Data Retention
|
||||
|
||||
| Environment | Hot Storage | Warm Storage | Cold Archive |
|
||||
| ----------- | ----------- | ------------ | ------------ |
|
||||
| Development | 24 hours | N/A | N/A |
|
||||
| Staging | 7 days | N/A | N/A |
|
||||
| Production | 7 days | 30 days | many years |
|
||||
|
||||
---
|
||||
|
||||
## 7.5 Integration Checklist
|
||||
|
||||
- [ ] Choose primary backend (Tempo recommended for cost/features)
|
||||
- [ ] Deploy collector cluster with high availability
|
||||
- [ ] Configure tail-based sampling for error/latency traces
|
||||
- [ ] Set up Grafana dashboards for trace visualization
|
||||
- [ ] Configure alerts for trace anomalies
|
||||
- [ ] Establish data retention policies
|
||||
- [ ] Test trace correlation with logs and metrics
|
||||
|
||||
---
|
||||
|
||||
## 7.6 Grafana Dashboard Examples
|
||||
|
||||
Pre-built dashboards for xrpld observability.
|
||||
|
||||
### 7.6.1 Consensus Health Dashboard
|
||||
|
||||
A Tempo-backed dashboard (uid `xrpld-consensus-health`) with four panels, all driven by TraceQL:
|
||||
|
||||
- **Consensus Round Duration** (timeseries, ms): average `consensus.round` span duration per node instance, with yellow/red thresholds at 4s/5s.
|
||||
- **Phase Duration Breakdown** (barchart): average duration of `consensus.phase.*` spans grouped by span name.
|
||||
- **Proposers per Round** (stat): average of the `span.proposers` attribute on `consensus.round` spans.
|
||||
- **Recent Slow Rounds (>5s)** (table): `consensus.round` spans filtered to `duration > 5s`.
|
||||
|
||||
Each panel's TraceQL query is described inline in its bullet above.
|
||||
|
||||
### 7.6.2 Node Overview Dashboard
|
||||
|
||||
A Tempo-backed dashboard (uid `xrpld-node-overview`) with four panels:
|
||||
|
||||
- **Active Nodes** (stat): count of distinct `resource.service.instance.id` values seen for the `xrpld` service.
|
||||
- **Total Transactions (1h)** (stat): count of `tx.receive` spans.
|
||||
- **Error Rate** (gauge, percent): ratio of `status = error` spans to all spans, with yellow/red thresholds at 1%/5%.
|
||||
- **Service Map** (nodeGraph): Tempo-generated service dependency graph.
|
||||
|
||||
### 7.6.3 Alert Rules
|
||||
|
||||
Grafana provisions three TraceQL-based alert rules (group `xrpld-tracing-alerts`, evaluated every 1m) against the Tempo datasource:
|
||||
|
||||
- **Consensus Round Slow** (warning, `for: 5m`): fires when average `consensus.round` duration exceeds 5s.
|
||||
|
||||
```
|
||||
{resource.service.name="xrpld" && name="consensus.round"} | avg(duration) > 5s
|
||||
```
|
||||
|
||||
- **RPC Error Rate Spike** (critical, `for: 2m`): fires when the error rate across `rpc.command.*` spans exceeds 5%. Error _rate_ is a ratio, so it must divide the error-span rate by the total-span rate — a single TraceQL `rate()` returns spans/second, not a percentage, and would fire on traffic volume alone. This uses span metrics emitted by the collector's `spanmetrics` connector (Prometheus datasource), not a TraceQL query:
|
||||
|
||||
```
|
||||
sum(rate(traces_spanmetrics_calls_total{service_name="xrpld", span_name=~"rpc.command.*", status_code="STATUS_CODE_ERROR"}[5m]))
|
||||
/
|
||||
sum(rate(traces_spanmetrics_calls_total{service_name="xrpld", span_name=~"rpc.command.*"}[5m]))
|
||||
> 0.05
|
||||
```
|
||||
|
||||
- **Transaction Throughput Drop** (warning, `for: 10m`): fires when the `tx.receive` span rate falls below 10/s.
|
||||
|
||||
```
|
||||
{resource.service.name="xrpld" && name="tx.receive"} | rate() < 10
|
||||
```
|
||||
|
||||
> **Note**: The Consensus Round Slow and Transaction Throughput Drop rules use TraceQL aggregates (`avg(duration)`, `rate()`), which require Tempo 2.3+ with TraceQL metrics enabled. Verify aggregate query support in your Tempo version before provisioning. The RPC Error Rate Spike rule instead queries Prometheus span metrics (collector `spanmetrics` connector), so it needs that connector enabled in the collector pipeline.
|
||||
|
||||
---
|
||||
|
||||
## 7.7 PerfLog and Insight Correlation
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
How to correlate OpenTelemetry traces with existing xrpld observability.
|
||||
|
||||
### 7.7.1 Correlation Architecture
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph xrpld["xrpld Node"]
|
||||
otel[OpenTelemetry<br/>Spans]
|
||||
perflog[PerfLog<br/>JSON Logs]
|
||||
insight[Beast Insight<br/>StatsD Metrics]
|
||||
end
|
||||
|
||||
subgraph collectors["Data Collection"]
|
||||
otelc[OTel Collector]
|
||||
promtail[Promtail/Fluentd]
|
||||
statsd[StatsD Exporter]
|
||||
end
|
||||
|
||||
subgraph storage["Storage"]
|
||||
tempo[(Tempo)]
|
||||
loki[(Loki)]
|
||||
prom[(Prometheus)]
|
||||
end
|
||||
|
||||
subgraph grafana["Grafana"]
|
||||
traces[Trace View]
|
||||
logs[Log View]
|
||||
metrics[Metrics View]
|
||||
corr[Correlation<br/>Panel]
|
||||
end
|
||||
|
||||
otel -->|OTLP| otelc --> tempo
|
||||
perflog -->|JSON| promtail --> loki
|
||||
insight -->|StatsD| statsd --> prom
|
||||
|
||||
tempo --> traces
|
||||
loki --> logs
|
||||
prom --> metrics
|
||||
|
||||
traces --> corr
|
||||
logs --> corr
|
||||
metrics --> corr
|
||||
|
||||
style xrpld fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style collectors fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style storage fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style grafana fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
style otel fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style perflog fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style insight fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style otelc fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style promtail fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style statsd fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style tempo fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style loki fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style prom fill:#1b5e20,stroke:#0d3d14,color:#fff
|
||||
style traces fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
style logs fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
style metrics fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
style corr fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **xrpld Node (three sources)**: A single node emits three independent data streams -- OpenTelemetry spans, PerfLog JSON logs, and Beast Insight StatsD metrics.
|
||||
- **Data Collection layer**: Each stream has its own collector -- OTel Collector for spans, Promtail/Fluentd for logs, and a StatsD exporter for metrics. They operate independently.
|
||||
- **Storage layer (Tempo, Loki, Prometheus)**: Each data type lands in a purpose-built store optimized for its query patterns (trace search, log grep, metric aggregation).
|
||||
- **Grafana Correlation Panel**: The key integration point -- Grafana queries all three stores and links them via shared fields (`trace_id`, `tx_hash`, `ledger_seq`), enabling a single-pane debugging experience.
|
||||
|
||||
### 7.7.2 Correlation Fields
|
||||
|
||||
| Source | Field | Link To | Purpose |
|
||||
| ----------- | ------------------- | ------------- | -------------------------- |
|
||||
| **Trace** | `trace_id` | Logs | Find log entries for trace |
|
||||
| **Trace** | `tx_hash` | Logs, Metrics | Find TX-related data |
|
||||
| **Trace** | `ledger_seq` | Logs | Find ledger-related logs |
|
||||
| **PerfLog** | `trace_id` (new) | Traces | Jump to trace from log |
|
||||
| **PerfLog** | `ledger_seq` | Traces | Find consensus trace |
|
||||
| **Insight** | `exemplar.trace_id` | Traces | Jump from metric spike |
|
||||
|
||||
### 7.7.3 Example: Debugging a Slow Transaction
|
||||
|
||||
**Step 1: Find the trace**
|
||||
|
||||
```
|
||||
# In Grafana Explore with Tempo
|
||||
{resource.service.name="xrpld" && span.tx_hash="ABC123..."}
|
||||
```
|
||||
|
||||
**Step 2: Get the trace_id from the trace view**
|
||||
|
||||
```
|
||||
Trace ID: 4bf92f3577b34da6a3ce929d0e0e4736
|
||||
```
|
||||
|
||||
**Step 3: Find related PerfLog entries**
|
||||
|
||||
```
|
||||
# In Grafana Explore with Loki
|
||||
{job="xrpld"} |= "4bf92f3577b34da6a3ce929d0e0e4736"
|
||||
```
|
||||
|
||||
**Step 4: Check Insight metrics for the time window**
|
||||
|
||||
```
|
||||
# In Grafana with Prometheus
|
||||
rate(xrpld_tx_applied_total[1m])
|
||||
@ timestamp_from_trace
|
||||
```
|
||||
|
||||
### 7.7.4 Unified Dashboard Example
|
||||
|
||||
A single dashboard (uid `xrpld-unified`) that ties traces, metrics, and logs together across the Tempo, Prometheus, and Loki datasources:
|
||||
|
||||
- **Transaction Latency (Traces)** (timeseries, Tempo): `histogram_over_time(duration)` of `tx.receive` spans.
|
||||
- **Transaction Rate (Metrics)** (timeseries, Prometheus): `rate(xrpld_tx_received_total[5m])` per instance, with a data link that opens the matching `tx.receive` traces in Tempo.
|
||||
- **Recent Logs** (logs, Loki): `{job="xrpld"} | json`.
|
||||
- **Trace Search** (table, Tempo): all `xrpld` traces, with per-row data links on `traceID` that jump to the trace in Tempo and to the correlated logs in Loki (`{job="xrpld"} |= "<traceID>"`).
|
||||
|
||||
The cross-datasource data links are what make this a single-pane debugging view; the correlation fields they rely on are listed in section 7.7.2.
|
||||
|
||||
---
|
||||
|
||||
_Previous: [Implementation Phases](./06-implementation-phases.md)_ | _Next: [Appendix](./08-appendix.md)_ | _Back to: [Overview](./OpenTelemetryPlan.md)_
|
||||
197
OpenTelemetryPlan/08-appendix.md
Normal file
197
OpenTelemetryPlan/08-appendix.md
Normal file
@@ -0,0 +1,197 @@
|
||||
# Appendix
|
||||
|
||||
> **Parent Document**: [OpenTelemetryPlan.md](./OpenTelemetryPlan.md)
|
||||
> **Related**: [Observability Backends](./07-observability-backends.md)
|
||||
|
||||
---
|
||||
|
||||
## 8.1 Glossary
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol | **TxQ** = Transaction Queue
|
||||
|
||||
| Term | Definition |
|
||||
| --------------------- | ---------------------------------------------------------- |
|
||||
| **Span** | A unit of work with start/end time, name, and attributes |
|
||||
| **Trace** | A collection of spans representing a complete request flow |
|
||||
| **Trace ID** | 128-bit unique identifier for a trace |
|
||||
| **Span ID** | 64-bit unique identifier for a span within a trace |
|
||||
| **Context** | Carrier for trace/span IDs across boundaries |
|
||||
| **Propagator** | Component that injects/extracts context |
|
||||
| **Sampler** | Decides which traces to record |
|
||||
| **Exporter** | Sends spans to backend |
|
||||
| **Collector** | Receives, processes, and forwards telemetry |
|
||||
| **OTLP** | OpenTelemetry Protocol (wire format) |
|
||||
| **W3C Trace Context** | Standard HTTP headers for trace propagation |
|
||||
| **Baggage** | Key-value pairs propagated across service boundaries |
|
||||
| **Resource** | Entity producing telemetry (service, host, etc.) |
|
||||
| **Instrumentation** | Code that creates telemetry data |
|
||||
|
||||
### xrpld-Specific Terms
|
||||
|
||||
| Term | Definition |
|
||||
| ----------------- | ------------------------------------------------------------- |
|
||||
| **Overlay** | P2P network layer managing peer connections |
|
||||
| **Consensus** | XRP Ledger consensus algorithm (RCL) |
|
||||
| **Proposal** | Validator's suggested transaction set for a ledger |
|
||||
| **Validation** | Validator's signature on a closed ledger |
|
||||
| **HashRouter** | Component for transaction deduplication |
|
||||
| **JobQueue** | Thread pool for asynchronous task execution |
|
||||
| **PerfLog** | Existing performance logging system in xrpld |
|
||||
| **Beast Insight** | Existing metrics framework in xrpld |
|
||||
| **PathFinding** | Payment path computation engine for cross-currency payments |
|
||||
| **TxQ** | Transaction queue managing fee-based prioritization |
|
||||
| **LoadManager** | Dynamic fee escalation based on network load |
|
||||
| **SHAMap** | SHA-256 hash-based map (Merkle trie variant) for ledger state |
|
||||
|
||||
---
|
||||
|
||||
## 8.2 Span Hierarchy Visualization
|
||||
|
||||
> **TxQ** = Transaction Queue
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
subgraph trace["Trace: Transaction Lifecycle"]
|
||||
rpc["rpc.request<br/>(entry point)"]
|
||||
validate["tx.validate"]
|
||||
relay["tx.relay<br/>(parent span)"]
|
||||
|
||||
subgraph peers["Peer Spans"]
|
||||
p1["peer.send<br/>Peer A"]
|
||||
p2["peer.send<br/>Peer B"]
|
||||
p3["peer.send<br/>Peer C"]
|
||||
end
|
||||
|
||||
subgraph pathfinding["PathFinding Spans"]
|
||||
pathfind["pathfind.request"]
|
||||
pathcomp["pathfind.compute"]
|
||||
end
|
||||
|
||||
consensus["consensus.round"]
|
||||
apply["tx.apply"]
|
||||
|
||||
subgraph txqueue["TxQ Spans"]
|
||||
txq["txq.enqueue"]
|
||||
txqApply["txq.apply"]
|
||||
end
|
||||
|
||||
feeCalc["fee.escalate"]
|
||||
end
|
||||
|
||||
subgraph validators["Validator Spans"]
|
||||
valFetch["validator.list.fetch"]
|
||||
valManifest["validator.manifest"]
|
||||
end
|
||||
|
||||
rpc --> validate
|
||||
rpc --> pathfind
|
||||
pathfind --> pathcomp
|
||||
validate --> relay
|
||||
relay --> p1
|
||||
relay --> p2
|
||||
relay --> p3
|
||||
p1 -.->|"context propagation"| consensus
|
||||
consensus --> apply
|
||||
apply --> txq
|
||||
txq --> txqApply
|
||||
txq --> feeCalc
|
||||
|
||||
style trace fill:#0f172a,stroke:#020617,color:#fff
|
||||
style peers fill:#1e3a8a,stroke:#172554,color:#fff
|
||||
style pathfinding fill:#134e4a,stroke:#0f766e,color:#fff
|
||||
style txqueue fill:#064e3b,stroke:#047857,color:#fff
|
||||
style validators fill:#4c1d95,stroke:#6d28d9,color:#fff
|
||||
style rpc fill:#1d4ed8,stroke:#1e40af,color:#fff
|
||||
style validate fill:#047857,stroke:#064e3b,color:#fff
|
||||
style relay fill:#047857,stroke:#064e3b,color:#fff
|
||||
style p1 fill:#0e7490,stroke:#155e75,color:#fff
|
||||
style p2 fill:#0e7490,stroke:#155e75,color:#fff
|
||||
style p3 fill:#0e7490,stroke:#155e75,color:#fff
|
||||
style consensus fill:#fef3c7,stroke:#fde68a,color:#1e293b
|
||||
style apply fill:#047857,stroke:#064e3b,color:#fff
|
||||
style pathfind fill:#0e7490,stroke:#155e75,color:#fff
|
||||
style pathcomp fill:#0e7490,stroke:#155e75,color:#fff
|
||||
style txq fill:#047857,stroke:#064e3b,color:#fff
|
||||
style txqApply fill:#047857,stroke:#064e3b,color:#fff
|
||||
style feeCalc fill:#047857,stroke:#064e3b,color:#fff
|
||||
style valFetch fill:#6d28d9,stroke:#4c1d95,color:#fff
|
||||
style valManifest fill:#6d28d9,stroke:#4c1d95,color:#fff
|
||||
```
|
||||
|
||||
**Reading the diagram:**
|
||||
|
||||
- **rpc.request (blue, top)**: The entry point — every traced transaction starts as an RPC call; this root span is the parent of all downstream work.
|
||||
- **tx.validate and pathfind.request (green/teal, first fork)**: The RPC request fans out into transaction validation and, for cross-currency payments, a PathFinding branch (`pathfind.request` -> `pathfind.compute`).
|
||||
- **tx.relay -> Peer Spans (teal, middle)**: After validation, the transaction is relayed to peers A, B, and C in parallel; each `peer.send` is a sibling child span showing fan-out across the network.
|
||||
- **context propagation (dashed arrow)**: The dotted line from `peer.send Peer A` to `consensus.round` represents the trace context crossing a node boundary — the receiving validator picks up the same `trace_id` and continues the trace.
|
||||
- **consensus.round -> tx.apply -> TxQ Spans (green, lower)**: Once consensus accepts the transaction, it is applied to the ledger; the TxQ spans (`txq.enqueue`, `txq.apply`, `fee.escalate`) capture queue depth and fee escalation behavior.
|
||||
- **Validator Spans (purple, detached)**: `validator.list.fetch` and `validator.manifest` are independent workflows for UNL management — they run on their own traces and are linked to consensus via Span Links, not parent-child relationships.
|
||||
|
||||
---
|
||||
|
||||
## 8.3 References
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
### OpenTelemetry Resources
|
||||
|
||||
1. [OpenTelemetry C++ SDK](https://github.com/open-telemetry/opentelemetry-cpp)
|
||||
2. [OpenTelemetry Specification](https://opentelemetry.io/docs/specs/otel/)
|
||||
3. [OpenTelemetry Collector](https://opentelemetry.io/docs/collector/)
|
||||
4. [OTLP Protocol Specification](https://opentelemetry.io/docs/specs/otlp/)
|
||||
|
||||
### Standards
|
||||
|
||||
5. [W3C Trace Context](https://www.w3.org/TR/trace-context/)
|
||||
6. [W3C Baggage](https://www.w3.org/TR/baggage/)
|
||||
7. [Protocol Buffers](https://protobuf.dev/)
|
||||
|
||||
### xrpld Resources
|
||||
|
||||
8. [xrpld Source Code](https://github.com/XRPLF/rippled)
|
||||
9. [XRP Ledger Documentation](https://xrpl.org/docs/)
|
||||
10. [xrpld Overlay README](https://github.com/XRPLF/rippled/blob/develop/src/xrpld/overlay/README.md)
|
||||
11. [xrpld RPC README](https://github.com/XRPLF/rippled/blob/develop/src/xrpld/rpc/README.md)
|
||||
12. [xrpld Consensus README](https://github.com/XRPLF/rippled/blob/develop/src/xrpld/app/consensus/README.md)
|
||||
|
||||
---
|
||||
|
||||
## 8.4 Version History
|
||||
|
||||
| Version | Date | Author | Changes |
|
||||
| ------- | ---------- | ------ | -------------------------------------------------------------- |
|
||||
| 1.0 | 2026-02-12 | - | Initial implementation plan |
|
||||
| 1.1 | 2026-02-13 | - | Refactored into modular documents |
|
||||
| 1.2 | 2026-03-24 | - | Review fixes: accuracy corrections, cross-document consistency |
|
||||
|
||||
---
|
||||
|
||||
## 8.5 Document Index
|
||||
|
||||
### Plan Documents
|
||||
|
||||
| Document | Description |
|
||||
| ---------------------------------------------------------------- | -------------------------------------------------- |
|
||||
| [OpenTelemetryPlan.md](./OpenTelemetryPlan.md) | Master overview and executive summary |
|
||||
| [00-tracing-fundamentals.md](./00-tracing-fundamentals.md) | Distributed tracing concepts and OTel primer |
|
||||
| [01-architecture-analysis.md](./01-architecture-analysis.md) | xrpld architecture and trace points |
|
||||
| [02-design-decisions.md](./02-design-decisions.md) | SDK selection, exporters, span conventions |
|
||||
| [03-implementation-strategy.md](./03-implementation-strategy.md) | Directory structure, performance analysis |
|
||||
| [05-configuration-reference.md](./05-configuration-reference.md) | xrpld config, CMake, Collector configs |
|
||||
| [06-implementation-phases.md](./06-implementation-phases.md) | Timeline, tasks, risks, success metrics |
|
||||
| [07-observability-backends.md](./07-observability-backends.md) | Backend selection and architecture |
|
||||
| [08-appendix.md](./08-appendix.md) | Glossary, references, version history |
|
||||
| [secure-OTel.md](./secure-OTel.md) | Threat model and hardening (mTLS, peer validation) |
|
||||
|
||||
### Task Lists
|
||||
|
||||
| Document | Description |
|
||||
| ------------------------------------------ | ------------------------------------ |
|
||||
| [Phase2_taskList.md](./Phase2_taskList.md) | RPC layer trace instrumentation |
|
||||
| [Phase3_taskList.md](./Phase3_taskList.md) | Peer overlay & consensus tracing |
|
||||
| [Phase4_taskList.md](./Phase4_taskList.md) | Transaction lifecycle tracing |
|
||||
| [Phase5_taskList.md](./Phase5_taskList.md) | Ledger processing & advanced tracing |
|
||||
|
||||
---
|
||||
|
||||
_Previous: [Observability Backends](./07-observability-backends.md)_ | _Back to: [Overview](./OpenTelemetryPlan.md)_
|
||||
211
OpenTelemetryPlan/OpenTelemetryPlan.md
Normal file
211
OpenTelemetryPlan/OpenTelemetryPlan.md
Normal file
@@ -0,0 +1,211 @@
|
||||
# [OpenTelemetry](00-tracing-fundamentals.md) Distributed Tracing Implementation Plan for xrpld
|
||||
|
||||
## Executive Summary
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol
|
||||
|
||||
This document provides a comprehensive implementation plan for integrating OpenTelemetry distributed tracing into the xrpld XRP Ledger node software. The plan addresses the unique challenges of a decentralized peer-to-peer system where trace context must propagate across network boundaries between independent nodes.
|
||||
|
||||
### Key Benefits
|
||||
|
||||
- **End-to-end transaction visibility**: Track transactions from submission through consensus to ledger inclusion
|
||||
- **Consensus round analysis**: Understand timing and behavior of consensus phases across validators
|
||||
- **RPC performance insights**: Identify slow handlers and optimize response times
|
||||
- **Network topology understanding**: Visualize message propagation patterns between peers
|
||||
- **Incident debugging**: Correlate events across distributed nodes during issues
|
||||
|
||||
### Estimated Performance Overhead
|
||||
|
||||
| Metric | Overhead | Notes |
|
||||
| ------------- | ---------- | ------------------------------------------------ |
|
||||
| CPU | 1-3% | Span creation and attribute setting |
|
||||
| Memory | <10 MB | SDK statics + batch buffer + worker thread stack |
|
||||
| Network | 10-50 KB/s | Compressed OTLP export to collector |
|
||||
| Latency (p99) | <2% | With proper sampling configuration |
|
||||
|
||||
---
|
||||
|
||||
## Document Structure
|
||||
|
||||
This implementation plan is organized into modular documents for easier navigation:
|
||||
|
||||
<div align="center">
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
overview["📋 OpenTelemetryPlan.md<br/>(This Document)"]
|
||||
|
||||
subgraph fundamentals["Fundamentals"]
|
||||
fund["00-tracing-fundamentals.md"]
|
||||
end
|
||||
|
||||
subgraph analysis["Analysis & Design"]
|
||||
arch["01-architecture-analysis.md"]
|
||||
design["02-design-decisions.md"]
|
||||
end
|
||||
|
||||
subgraph impl["Implementation"]
|
||||
strategy["03-implementation-strategy.md"]
|
||||
config["05-configuration-reference.md"]
|
||||
end
|
||||
|
||||
subgraph deploy["Deployment & Planning"]
|
||||
phases["06-implementation-phases.md"]
|
||||
backends["07-observability-backends.md"]
|
||||
appendix["08-appendix.md"]
|
||||
secure["secure-OTel.md"]
|
||||
end
|
||||
|
||||
overview --> fundamentals
|
||||
overview --> analysis
|
||||
overview --> impl
|
||||
overview --> deploy
|
||||
|
||||
fund --> arch
|
||||
arch --> design
|
||||
design --> strategy
|
||||
strategy --> config
|
||||
config --> phases
|
||||
phases --> backends
|
||||
backends --> appendix
|
||||
backends --> secure
|
||||
|
||||
style overview fill:#1b5e20,stroke:#0d3d14,color:#fff,stroke-width:2px
|
||||
style fundamentals fill:#00695c,stroke:#004d40,color:#fff
|
||||
style fund fill:#00695c,stroke:#004d40,color:#fff
|
||||
style analysis fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style impl fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style deploy fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
style arch fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style design fill:#0d47a1,stroke:#082f6a,color:#fff
|
||||
style strategy fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style config fill:#bf360c,stroke:#8c2809,color:#fff
|
||||
style phases fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
style backends fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
style appendix fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
style secure fill:#4a148c,stroke:#2e0d57,color:#fff
|
||||
```
|
||||
|
||||
</div>
|
||||
|
||||
---
|
||||
|
||||
## Table of Contents
|
||||
|
||||
| Section | Document | Description |
|
||||
| ------- | ---------------------------------------------------------- | ---------------------------------------------------------------------- |
|
||||
| **0** | [Tracing Fundamentals](./00-tracing-fundamentals.md) | Distributed tracing concepts, span relationships, context propagation |
|
||||
| **1** | [Architecture Analysis](./01-architecture-analysis.md) | xrpld component analysis, trace points, instrumentation priorities |
|
||||
| **2** | [Design Decisions](./02-design-decisions.md) | SDK selection, exporters, span naming, attributes, context propagation |
|
||||
| **3** | [Implementation Strategy](./03-implementation-strategy.md) | Directory structure, key principles, performance optimization |
|
||||
| **5** | [Configuration Reference](./05-configuration-reference.md) | xrpld config, CMake integration, Collector configurations |
|
||||
| **6** | [Implementation Phases](./06-implementation-phases.md) | 5-phase timeline, tasks, risks, success metrics |
|
||||
| **7** | [Observability Backends](./07-observability-backends.md) | Backend selection guide and production architecture |
|
||||
| **8** | [Appendix](./08-appendix.md) | Glossary, references, version history |
|
||||
| **Sec** | [Securing the OTel Pipeline](./secure-OTel.md) | Threat model and hardening (mTLS, peer trace-context validation) |
|
||||
|
||||
---
|
||||
|
||||
## 0. Tracing Fundamentals
|
||||
|
||||
This document introduces distributed tracing concepts for readers unfamiliar with the domain. It covers what traces and spans are, how parent-child and follows-from relationships model causality, how context propagates across service boundaries, and how sampling controls data volume. It also maps these concepts to xrpld-specific scenarios like transaction relay and consensus.
|
||||
|
||||
➡️ **[Read Tracing Fundamentals](./00-tracing-fundamentals.md)**
|
||||
|
||||
---
|
||||
|
||||
## 1. Architecture Analysis
|
||||
|
||||
> **WS** = WebSocket | **TxQ** = Transaction Queue
|
||||
|
||||
The xrpld node consists of several key components that require instrumentation for comprehensive distributed tracing. The main areas include the RPC server (HTTP/WebSocket), Overlay P2P network, Consensus mechanism (RCLConsensus), JobQueue for async task execution, PathFinding, Transaction Queue (TxQ), fee escalation (LoadManager), ledger acquisition, validator management, and existing observability infrastructure (PerfLog, Insight/StatsD, Journal logging).
|
||||
|
||||
Key trace points span across transaction submission via RPC, peer-to-peer message propagation, consensus round execution, ledger building, path computation, transaction queue behavior, fee escalation, and validator health. The implementation prioritizes high-value, low-risk components first: RPC handlers provide immediate value with minimal risk, while consensus tracing requires careful implementation to avoid timing impacts.
|
||||
|
||||
➡️ **[Read full Architecture Analysis](./01-architecture-analysis.md)**
|
||||
|
||||
---
|
||||
|
||||
## 2. Design Decisions
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol | **CNCF** = Cloud Native Computing Foundation
|
||||
|
||||
The OpenTelemetry C++ SDK is selected for its CNCF backing, active development, and native performance characteristics. Traces are exported via OTLP/HTTP to an OpenTelemetry Collector, which provides flexible routing and sampling. OTLP/gRPC is planned future work (see design decisions §2.2.2).
|
||||
|
||||
Span naming follows a hierarchical `<component>.<operation>` convention (e.g., `rpc.submit`, `tx.relay`, `consensus.round`). Context propagation uses W3C Trace Context headers for HTTP and embedded Protocol Buffer fields for P2P messages. The implementation coexists with existing PerfLog and Insight observability systems through correlation IDs.
|
||||
|
||||
**Data Collection & Privacy**: Telemetry collects only operational metadata (timing, counts, hashes) — never sensitive content (private keys, balances, amounts, raw payloads). Privacy protection includes account hashing, configurable redaction, sampling, and collector-level filtering. Node operators retain full control over telemetry configuration.
|
||||
|
||||
➡️ **[Read full Design Decisions](./02-design-decisions.md)**
|
||||
|
||||
---
|
||||
|
||||
## 3. Implementation Strategy
|
||||
|
||||
The telemetry code is organized under `include/xrpl/telemetry/` for headers and `src/libxrpl/telemetry/` for implementation. Key principles include RAII-based span management via `SpanGuard` (with `discard()` for dropping unwanted spans), a `FilteringSpanProcessor` that intercepts `OnEnd()` to prevent discarded spans from entering the export pipeline, conditional compilation with `XRPL_ENABLE_TELEMETRY`, and minimal runtime overhead through batch processing and efficient sampling.
|
||||
|
||||
Performance optimization strategies include head sampling fixed at 100% (intentionally not configurable, so trace keep/drop decisions stay coherent across nodes), tail-based sampling at the collector for errors and slow traces to reduce volume, batch export to reduce network overhead, and conditional instrumentation that compiles to no-ops when disabled.
|
||||
|
||||
➡️ **[Read full Implementation Strategy](./03-implementation-strategy.md)**
|
||||
|
||||
---
|
||||
|
||||
## 5. Configuration Reference
|
||||
|
||||
> **OTLP** = OpenTelemetry Protocol | **APM** = Application Performance Monitoring
|
||||
|
||||
Configuration is handled through the `[telemetry]` section in `xrpld.cfg` with options for enabling/disabling, exporter selection, endpoint configuration, and component-level filtering. Head sampling is fixed at 1.0 (not operator-configurable); volume reduction is done by tail sampling in the collector. CMake integration includes a `XRPL_ENABLE_TELEMETRY` option for compile-time control.
|
||||
|
||||
OpenTelemetry Collector configurations are provided for development and production (with tail-based sampling, Tempo, and Elastic APM). Docker Compose examples enable quick local development environment setup.
|
||||
|
||||
➡️ **[View full Configuration Reference](./05-configuration-reference.md)**
|
||||
|
||||
---
|
||||
|
||||
## 6. Implementation Phases
|
||||
|
||||
The implementation spans 9 weeks across 5 phases:
|
||||
|
||||
| Phase | Duration | Focus | Key Deliverables |
|
||||
| ----- | --------- | ------------------- | --------------------------------------------------- |
|
||||
| 1 | Weeks 1-2 | Core Infrastructure | SDK integration, Telemetry interface, Configuration |
|
||||
| 2 | Weeks 3-4 | RPC Tracing | HTTP context extraction, Handler instrumentation |
|
||||
| 3 | Weeks 5-6 | Transaction Tracing | Protocol Buffer context, Relay propagation |
|
||||
| 4 | Weeks 7-8 | Consensus Tracing | Round spans, Proposal/validation tracing |
|
||||
| 5 | Week 9 | Documentation | Runbook, Dashboards, Training |
|
||||
|
||||
**Total Effort**: 47 person-days (2 developers working in parallel)
|
||||
|
||||
➡️ **[View full Implementation Phases](./06-implementation-phases.md)**
|
||||
|
||||
---
|
||||
|
||||
## 7. Observability Backends
|
||||
|
||||
> **APM** = Application Performance Monitoring | **GCS** = Google Cloud Storage
|
||||
|
||||
Grafana Tempo is recommended for all environments due to its cost-effectiveness and Grafana integration, while Elastic APM is ideal for organizations with existing Elastic infrastructure.
|
||||
|
||||
The recommended production architecture uses a gateway collector pattern with regional collectors performing tail-based sampling, routing traces to multiple backends (Tempo for primary storage, Elastic for log correlation, S3/GCS for long-term archive).
|
||||
|
||||
➡️ **[View Observability Backend Recommendations](./07-observability-backends.md)**
|
||||
|
||||
---
|
||||
|
||||
## 8. Appendix
|
||||
|
||||
The appendix contains a glossary of OpenTelemetry and xrpld-specific terms, references to external documentation and specifications, version history for this implementation plan, and a complete document index.
|
||||
|
||||
➡️ **[View Appendix](./08-appendix.md)**
|
||||
|
||||
---
|
||||
|
||||
## Securing the OTel Pipeline
|
||||
|
||||
Threat model and hardening guidance for production deployments where xrpld nodes ship telemetry to a centrally-hosted collector across an untrusted network. Covers the two attack surfaces (collector ingress and peer trace-context spoofing) and the chosen defenses: mTLS as primary collector auth, NetworkPolicy as defense-in-depth, and source-side validation plus per-peer rate limiting for the `protocol::TraceContext` field on peer messages.
|
||||
|
||||
➡️ **[View Securing the OTel Pipeline](./secure-OTel.md)**
|
||||
|
||||
---
|
||||
|
||||
_This document provides a comprehensive implementation plan for integrating OpenTelemetry distributed tracing into the xrpld XRP Ledger node software. For detailed information on any section, follow the links to the corresponding sub-documents._
|
||||
207
OpenTelemetryPlan/Phase2_taskList.md
Normal file
207
OpenTelemetryPlan/Phase2_taskList.md
Normal file
@@ -0,0 +1,207 @@
|
||||
# Phase 2: RPC Tracing Completion Task List
|
||||
|
||||
> **Goal**: Complete RPC tracing coverage with unit tests, Grafana search filters, PathFind instrumentation, and config hardening. Build on the Phase 1c SpanGuard factory foundation to achieve production-quality RPC observability.
|
||||
>
|
||||
> **Scope**: Unit tests for core telemetry, Grafana Tempo search filters, PathFind RPC tracing, config validation (`std::clamp`).
|
||||
>
|
||||
> **Branch**: `pratik/otel-phase2-rpc-tracing` (from `pratik/otel-phase1c-rpc-integration`)
|
||||
|
||||
### Related Plan Documents
|
||||
|
||||
| Document | Relevance |
|
||||
| ------------------------------------------------------------ | ------------------------------------------------------------- |
|
||||
| [04-code-samples.md](./04-code-samples.md) | TraceContextPropagator (§4.4.2), RPC instrumentation (§4.5.3) |
|
||||
| [02-design-decisions.md](./02-design-decisions.md) | W3C Trace Context (§2.5), span attributes (§2.4.2) |
|
||||
| [06-implementation-phases.md](./06-implementation-phases.md) | Phase 2 tasks (§6.3), definition of done (§6.11.2) |
|
||||
|
||||
---
|
||||
|
||||
## Task 2.1: W3C Trace Context HTTP Header Extraction
|
||||
|
||||
**Status**: DEFERRED → Phase 3
|
||||
|
||||
**Reason**: W3C context propagation (`traceparent`/`tracestate` headers) requires a consumer — in Phase 2, RPC spans are entirely local to the node. Phase 3 introduces cross-node transaction tracing via protobuf context propagation, which is the first use case for extracted trace context. Implementing it here without a consumer would be dead code.
|
||||
|
||||
**Implemented in**: `pratik/otel-phase3-tx-tracing` — `TraceContextPropagator.h/.cpp`
|
||||
|
||||
---
|
||||
|
||||
## Task 2.2: Per-Category Span Creation
|
||||
|
||||
**Status**: COMPLETE (superseded by Phase 1c design)
|
||||
|
||||
**Original plan**: Add `XRPL_TRACE_PEER` and `XRPL_TRACE_LEDGER` macros.
|
||||
|
||||
**Actual implementation**: Phase 1c replaced all tracing macros with the `SpanGuard::span(TraceCategory, prefix, name)` factory pattern. The `TraceCategory` enum (`Rpc`, `Transactions`, `Consensus`, `Peer`, `Ledger`) serves the same conditional-creation purpose without macros. No separate task needed — the factory already supports all categories.
|
||||
|
||||
---
|
||||
|
||||
## Task 2.3: Add shouldTraceLedger() to Telemetry Interface
|
||||
|
||||
**Objective**: The `Setup` struct has a `traceLedger` field but there's no corresponding virtual method. Add it for interface completeness.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Edit `include/xrpl/telemetry/Telemetry.h`:
|
||||
- Add `virtual bool shouldTraceLedger() const = 0;`
|
||||
|
||||
- Update all implementations:
|
||||
- `src/libxrpl/telemetry/Telemetry.cpp` (TelemetryImpl, NullTelemetryOtel)
|
||||
- `src/libxrpl/telemetry/NullTelemetry.cpp` (NullTelemetry)
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `include/xrpl/telemetry/Telemetry.h`
|
||||
- `src/libxrpl/telemetry/Telemetry.cpp`
|
||||
- `src/libxrpl/telemetry/NullTelemetry.cpp`
|
||||
|
||||
---
|
||||
|
||||
## Task 2.4: Unit Tests for Core Telemetry Infrastructure
|
||||
|
||||
**Status**: COMPLETE
|
||||
|
||||
**Objective**: Add unit tests for the core telemetry abstractions to validate correctness and catch regressions.
|
||||
|
||||
**Implemented**:
|
||||
|
||||
- `src/tests/libxrpl/telemetry/TelemetryConfig.cpp`:
|
||||
- Test Setup defaults (all fields have correct initial values)
|
||||
- Test `makeTelemetrySetup` config parser (empty section, full section, edge cases)
|
||||
- Test `samplingRatio` clamping (values outside 0.0-1.0)
|
||||
|
||||
- `src/tests/libxrpl/telemetry/SpanGuardFactory.cpp`:
|
||||
- Test null guard methods are safe (setAttribute, setOk, setError, addEvent on null)
|
||||
- Test category span returns null when telemetry disabled
|
||||
- Test child/linked span null when no parent context
|
||||
- Test move construction transfers ownership
|
||||
- Test recordException safe on null guard
|
||||
- Test discard() safe on null guard
|
||||
|
||||
- `src/tests/libxrpl/telemetry/main.cpp` — GTest runner
|
||||
- `src/tests/libxrpl/CMakeLists.txt` — test target with optional OTel linking
|
||||
|
||||
---
|
||||
|
||||
## Task 2.5: Enhance RPC Span Attributes
|
||||
|
||||
**Status**: DEFERRED (low priority)
|
||||
|
||||
**Reason**: The high-value attributes (`command`, `version`, `role`, `status`) are already set by Phase 1c. The remaining HTTP transport-level attributes (`http.method`, `net.peer.ip`, `http.status_code`) provide limited additional insight since:
|
||||
|
||||
- `http.method` is always POST for JSON-RPC
|
||||
- `net.peer.ip` is debug-level info available in logs
|
||||
- `duration_ms` is redundant with span duration (OTel captures start/end time natively)
|
||||
|
||||
These can be added later if dashboard queries specifically need them. The node health attributes (Task 2.8) provide far more operational value and were prioritized instead.
|
||||
|
||||
---
|
||||
|
||||
## Task 2.6: Build Verification and Performance Baseline
|
||||
|
||||
**Objective**: Verify the build succeeds with and without telemetry, and establish a performance baseline.
|
||||
|
||||
**What to do**:
|
||||
|
||||
1. Build with `telemetry=ON` and verify no compilation errors
|
||||
2. Build with `telemetry=OFF` and verify no regressions
|
||||
3. Run existing unit tests to verify no breakage
|
||||
4. Document any build issues in lessons.md
|
||||
|
||||
**Verification Checklist**:
|
||||
|
||||
- [ ] `conan install . --build=missing -o telemetry=True` succeeds
|
||||
- [ ] `cmake --preset default -Dtelemetry=ON` configures correctly
|
||||
- [ ] Build succeeds with telemetry ON
|
||||
- [ ] Build succeeds with telemetry OFF
|
||||
- [ ] Existing tests pass with telemetry ON
|
||||
- [ ] Existing tests pass with telemetry OFF
|
||||
|
||||
---
|
||||
|
||||
## Task 2.8: RPC Span Attribute Enrichment — Node Health Context
|
||||
|
||||
**Status**: DROPPED.
|
||||
|
||||
Node health (`amendment_blocked`, `server_state`) is not part of the telemetry surface. Operators consume the same data via the existing `server_info` / `server_state` RPC commands, so duplicating it on traces adds storage and cardinality cost without new value. The OTel C++ SDK 1.18.0 also does not support runtime updates to the resource, ruling out resource-level emission of these dynamic-by-nature flags.
|
||||
|
||||
---
|
||||
|
||||
## Task 2.9: PathFind RPC Instrumentation
|
||||
|
||||
**Status**: COMPLETE
|
||||
|
||||
**Objective**: Trace the path_find and ripple_path_find RPC handlers to capture request latency and computation cost.
|
||||
|
||||
**Spans added**:
|
||||
|
||||
- `pathfind.request` — wraps `doPathFind()` and `doRipplePathFind()` RPC handlers
|
||||
- `pathfind.compute` — wraps `PathRequest::doUpdate()` (`pathfind_fast` attr)
|
||||
- `pathfind.update_all` — wraps `PathRequestManager::updateAll()` on ledger close (`pathfind_ledger_index`, `pathfind_num_requests` attrs; emitted only when active subscriptions exist)
|
||||
- `pathfind.discover` — wraps the entire per-source-asset loop in `PathRequest::findPaths()` (`pathfind_search_level`, `pathfind_num_paths` attrs). One span per RPC call instead of N (one per source asset). Trade-off: per-asset breakdown is lost; storage and cardinality bounded.
|
||||
|
||||
**Attribute namespacing**: All pathfind attributes use the `pathfind_*` underscore form per the Phase 1c naming-spec rule 5.
|
||||
|
||||
**New file**: `src/xrpld/rpc/detail/PathFindSpanNames.h`
|
||||
|
||||
**Modified files**:
|
||||
|
||||
- `src/xrpld/rpc/handlers/orderbook/PathFind.cpp`
|
||||
- `src/xrpld/rpc/handlers/orderbook/RipplePathFind.cpp`
|
||||
- `src/xrpld/rpc/detail/PathRequest.cpp`
|
||||
- `src/xrpld/rpc/detail/PathRequestManager.cpp`
|
||||
- `src/xrpld/rpc/detail/Pathfinder.cpp`
|
||||
|
||||
---
|
||||
|
||||
## Task 2.10: RPC and PathFind Span Attribute Gap Fill
|
||||
|
||||
**Status**: COMPLETE
|
||||
|
||||
**Objective**: Wire up workflow-identifying attributes that enable filtering and grouping traces by request characteristics without drilling into child spans.
|
||||
|
||||
**Attributes added**:
|
||||
|
||||
| Span | Attribute | Type | Source |
|
||||
| ------------------- | ---------------------------- | ------ | --------------------------------- |
|
||||
| `rpc.http_request` | `request_payload_size` | int64 | `request.body().size()` |
|
||||
| `rpc.process` | `is_batch` | bool | `method == "batch"` check |
|
||||
| `rpc.process` | `batch_size` | int64 | `params.size()` (only when batch) |
|
||||
| `rpc.ws_message` | `command` | string | `jv[command]` or `jv[method]` |
|
||||
| `rpc.command.*` | `load_type` | string | `context.loadType.label()` |
|
||||
| `pathfind.compute` | `pathfind_dest_currency` | string | `to_string(saDstAmount_.asset())` |
|
||||
| `pathfind.discover` | `pathfind_num_source_assets` | int64 | `sourceAssets.size()` |
|
||||
|
||||
_Note: `pathfind_dest_amount` was removed — the destination amount is a financial value excluded by the privacy policy (design §2.4.4)._
|
||||
|
||||
**New attr keys**: `RpcSpanNames.h` (`isBatch`, `batchSize`, `loadType`), `PathFindSpanNames.h` (`destCurrency`, `numSourceAssets`).
|
||||
|
||||
**Modified files**:
|
||||
|
||||
- `src/xrpld/rpc/detail/RpcSpanNames.h`
|
||||
- `src/xrpld/rpc/detail/PathFindSpanNames.h`
|
||||
- `src/xrpld/rpc/detail/ServerHandler.cpp`
|
||||
- `src/xrpld/rpc/detail/RPCHandler.cpp`
|
||||
- `src/xrpld/rpc/detail/PathRequest.cpp`
|
||||
|
||||
---
|
||||
|
||||
## Summary
|
||||
|
||||
| Task | Description | Status | Notes |
|
||||
| ---- | ------------------------------------------- | ------------------- | --------------------------------------------------------- |
|
||||
| 2.1 | W3C Trace Context header extraction | Deferred → Phase 3 | No consumer in Phase 2; needs cross-node tracing |
|
||||
| 2.2 | Per-category span creation | Complete (Phase 1c) | Superseded by TraceCategory enum + SpanGuard |
|
||||
| 2.3 | Add shouldTraceLedger() interface method | Complete (Phase 1c) | Delivered in Phase 1c base branch |
|
||||
| 2.4 | Unit tests for core telemetry | Complete | TelemetryConfig + SpanGuardFactory tests |
|
||||
| 2.5 | Enhanced RPC span attributes (HTTP-level) | Deferred | Low value; span duration covers timing natively |
|
||||
| 2.6 | Build verification and performance baseline | Complete | Verified in CI on Phase 1c |
|
||||
| 2.7 | Grafana Tempo search filters | Complete | rpc-command, rpc-status, rpc-role filters |
|
||||
| 2.8 | RPC span attribute enrichment (node health) | Dropped | Available via `server_info`/`server_state` RPC |
|
||||
| 2.9 | PathFind RPC instrumentation | Complete | request, compute, update_all, discover |
|
||||
| 2.10 | RPC/PathFind span attribute gap fill | Complete | Batch detection, payload size, load cost, pathfind params |
|
||||
|
||||
**Delivered in this branch**: Tasks 2.4, 2.7, 2.9, 2.10.
|
||||
**Deferred with rationale**: Tasks 2.1 (→Phase 3), 2.5 (low priority).
|
||||
**Dropped**: Task 2.8 (node health not duplicated on traces).
|
||||
**Superseded**: Task 2.2 (Phase 1c SpanGuard factory covers this).
|
||||
546
OpenTelemetryPlan/Phase3_taskList.md
Normal file
546
OpenTelemetryPlan/Phase3_taskList.md
Normal file
@@ -0,0 +1,546 @@
|
||||
# Phase 3: Transaction Tracing Task List
|
||||
|
||||
> **Goal**: Trace the full transaction lifecycle from RPC submission through peer relay, including cross-node context propagation via Protocol Buffer extensions. This is the WALK phase that demonstrates true distributed tracing.
|
||||
>
|
||||
> **Scope**: Protocol Buffer `TraceContext` message, context serialization, PeerImp transaction instrumentation, NetworkOPs processing instrumentation, HashRouter visibility, and multi-node relay context propagation.
|
||||
>
|
||||
> **Branch**: `pratik/otel-phase3-tx-tracing` (from `pratik/otel-phase2-rpc-tracing`)
|
||||
|
||||
### Related Plan Documents
|
||||
|
||||
| Document | Relevance |
|
||||
| ------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ |
|
||||
| [04-code-samples.md](./04-code-samples.md) | TraceContext protobuf (§4.4.1), PeerImp instrumentation (§4.5.1), context serialization (§4.4.2) |
|
||||
| [01-architecture-analysis.md](./01-architecture-analysis.md) | Transaction flow (§1.3), key trace points (§1.6) |
|
||||
| [06-implementation-phases.md](./06-implementation-phases.md) | Phase 3 tasks (§6.4), definition of done (§6.11.3) |
|
||||
| [02-design-decisions.md](./02-design-decisions.md) | Context propagation design (§2.5), attribute schema (§2.4.3) |
|
||||
|
||||
---
|
||||
|
||||
## Task 3.1: Define TraceContext Protocol Buffer Message
|
||||
|
||||
**Objective**: Add trace context fields to the P2P protocol messages so trace IDs can propagate across nodes.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Edit `include/xrpl/proto/xrpl.proto` (or `src/xrpld/proto/ripple.proto`, wherever the proto is):
|
||||
- Add `TraceContext` message definition:
|
||||
```protobuf
|
||||
message TraceContext {
|
||||
bytes trace_id = 1; // 16-byte trace identifier
|
||||
bytes span_id = 2; // 8-byte span identifier
|
||||
uint32 trace_flags = 3; // bit 0 = sampled
|
||||
string trace_state = 4; // W3C tracestate value
|
||||
}
|
||||
```
|
||||
- Add `optional TraceContext trace_context = 1001;` to:
|
||||
- `TMTransaction`
|
||||
- `TMProposeSet` (for Phase 4 use)
|
||||
- `TMValidation` (for Phase 4 use)
|
||||
- Use high field numbers (1001+) to avoid conflicts with existing fields
|
||||
|
||||
- Regenerate protobuf C++ code
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `include/xrpl/proto/xrpl.proto` (or equivalent)
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [04-code-samples.md §4.4.1](./04-code-samples.md) — TraceContext message definition
|
||||
- [02-design-decisions.md §2.5.2](./02-design-decisions.md) — Protocol buffer context propagation design
|
||||
|
||||
---
|
||||
|
||||
## Task 3.2: Implement Protobuf Context Serialization
|
||||
|
||||
**Objective**: Create utilities to serialize/deserialize OTel trace context to/from protobuf `TraceContext` messages.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Create `include/xrpl/telemetry/TraceContextPropagator.h` (extend from Phase 2 if exists, or add protobuf methods):
|
||||
- Add protobuf-specific methods:
|
||||
- `static Context extractFromProtobuf(protocol::TraceContext const& proto)` — reconstruct OTel context from protobuf fields
|
||||
- `static void injectToProtobuf(Context const& ctx, protocol::TraceContext& proto)` — serialize current span context into protobuf fields
|
||||
- Both methods guard behind `#ifdef XRPL_ENABLE_TELEMETRY`
|
||||
|
||||
- Create/extend `src/libxrpl/telemetry/TraceContextPropagator.cpp`:
|
||||
- Implement extraction: read trace_id (16 bytes), span_id (8 bytes), trace_flags from protobuf, construct `SpanContext`, wrap in `Context`
|
||||
- Implement injection: get current span from context, serialize its TraceId, SpanId, and TraceFlags into protobuf fields
|
||||
|
||||
**Key new/modified files**:
|
||||
|
||||
- `include/xrpl/telemetry/TraceContextPropagator.h`
|
||||
- `src/libxrpl/telemetry/TraceContextPropagator.cpp`
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [04-code-samples.md §4.4.2](./04-code-samples.md) — Full extract/inject implementation
|
||||
|
||||
---
|
||||
|
||||
## Task 3.3: Instrument PeerImp Transaction Handling
|
||||
|
||||
**Objective**: Add trace spans to the peer-level transaction receive and relay path.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Edit `src/xrpld/overlay/detail/PeerImp.cpp`:
|
||||
- In `onMessage(TMTransaction)` / `handleTransaction()`:
|
||||
- Extract parent trace context from incoming `TMTransaction::trace_context` field (if present)
|
||||
- Create `tx.receive` span as child of extracted context (or new root if none)
|
||||
- Set attributes: `tx_hash`, `peer_id`, `tx_status`
|
||||
- On HashRouter suppression (duplicate): set `suppressed=true`, add `tx.duplicate` event
|
||||
- Wrap validation call with child span `tx.validate`
|
||||
- Wrap relay with `tx.relay` span
|
||||
- When relaying to peers:
|
||||
- Inject current trace context into outgoing `TMTransaction::trace_context`
|
||||
- Set `relay_count` attribute
|
||||
|
||||
- Use `SpanGuard::span(TraceCategory::Transactions, "tx", "receive")` factory
|
||||
(Phase 1c replaced macros with the SpanGuard factory pattern)
|
||||
|
||||
> **Note**: The `tx.receive` guard is `.detached()` before being moved into the
|
||||
> `RcvCheckTx` job so its Scope is popped on the peer thread, not leaked to the
|
||||
> worker (else later peer messages would inherit this transaction's trace).
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/overlay/detail/PeerImp.cpp`
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [04-code-samples.md §4.5.1](./04-code-samples.md) — Full PeerImp instrumentation example
|
||||
- [01-architecture-analysis.md §1.3](./01-architecture-analysis.md) — Transaction flow diagram
|
||||
- [01-architecture-analysis.md §1.6](./01-architecture-analysis.md) — tx.receive trace point
|
||||
|
||||
---
|
||||
|
||||
## Task 3.4: Instrument NetworkOPs Transaction Processing
|
||||
|
||||
**Objective**: Trace the transaction processing pipeline in NetworkOPs, covering both sync and async paths.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Edit `src/xrpld/app/misc/NetworkOPs.cpp`:
|
||||
- In `processTransaction()`:
|
||||
- Create `tx.process` span
|
||||
- Set attributes: `tx_hash`, `tx_type`, `local` (whether from RPC or peer)
|
||||
- Record whether sync or async path is taken
|
||||
- `.detached()` the guard before storing it in `TransactionStatus::span`,
|
||||
since it is applied on a batch worker thread — this pops the Scope on the
|
||||
origin thread and stops later work inheriting this transaction's trace
|
||||
|
||||
- In `doTransactionAsync()`:
|
||||
- Capture parent context before queuing
|
||||
- Create `tx.queue` span with queue depth attribute
|
||||
- Add event when transaction is dequeued for processing
|
||||
|
||||
- In `doTransactionSync()`:
|
||||
- Create `tx.process_sync` span
|
||||
- Record result (applied, queued, rejected)
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/misc/NetworkOPs.cpp`
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [01-architecture-analysis.md §1.6](./01-architecture-analysis.md) — tx.validate and tx.process trace points
|
||||
- [02-design-decisions.md §2.4.3](./02-design-decisions.md) — Transaction attribute schema
|
||||
|
||||
---
|
||||
|
||||
## Task 3.5: Instrument HashRouter for Dedup Visibility
|
||||
|
||||
**Objective**: Make transaction deduplication visible in traces by recording HashRouter decisions as span attributes/events.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Edit `src/xrpld/overlay/detail/PeerImp.cpp` (in handleTransaction):
|
||||
- After calling `HashRouter::shouldProcess()` or `addSuppressionPeer()`:
|
||||
- Record `suppressed` attribute (true/false)
|
||||
- Record `tx_flags` showing current HashRouter state (SAVED, TRUSTED, etc.)
|
||||
- Add `tx.first_seen` or `tx.duplicate` event
|
||||
|
||||
- This is NOT a modification to HashRouter itself — just recording its decisions as span attributes in the existing PeerImp instrumentation from Task 3.3.
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/overlay/detail/PeerImp.cpp` (same changes as 3.3, logically grouped)
|
||||
|
||||
---
|
||||
|
||||
## Task 3.6: Context Propagation in Transaction Relay
|
||||
|
||||
**Status**: COMPLETE (transaction relay). Consensus proposal/validation
|
||||
propagation is deferred to Phase 4 — see "Planned (Phase 4)" below.
|
||||
|
||||
**Objective**: Ensure trace context flows correctly when transactions are relayed between peers, creating linked spans across nodes.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- **TX send side**: `NetworkOPs::apply()` now injects the tx.process span's trace
|
||||
context into the outgoing `TMTransaction` protobuf before relay, using
|
||||
`telemetry::injectSpanContext()`. The receiving node's `txReceiveSpan()` (already
|
||||
wired in PeerImp) extracts the parent span_id and creates the tx.receive span
|
||||
as a child of the sender's tx.process span.
|
||||
|
||||
- **Edge cases**: Missing trace context (older peers) degrades gracefully to
|
||||
standalone spans. Invalid/corrupted context is treated as absent. Trace
|
||||
flags are propagated and respected.
|
||||
|
||||
**New infrastructure**:
|
||||
|
||||
- `SpanGuard::getTraceBytes()` — extracts raw trace_id/span_id/trace_flags
|
||||
from a span without exposing OTel types. Safe to call from any thread.
|
||||
- `PropagationHelpers.h` — `injectSpanContext(SpanGuard&, proto)` bridge
|
||||
between SpanGuard and protobuf TraceContext.
|
||||
- `TraceContextPropagator.h` — `injectToProtobuf(ctx, proto)` for
|
||||
same-thread injection via OTel RuntimeContext.
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/misc/NetworkOPs.cpp` — tx relay injection
|
||||
- `include/xrpl/telemetry/SpanGuard.h` — `TraceBytes` struct, `getTraceBytes()`
|
||||
- `src/libxrpl/telemetry/SpanGuard.cpp` — `getTraceBytes()` implementation
|
||||
- `src/xrpld/telemetry/PropagationHelpers.h` — inject helpers (new file)
|
||||
|
||||
**Planned (Phase 4 — not in this PR)**:
|
||||
|
||||
The consensus proposal/validation propagation below is Phase 4 scope and is
|
||||
not implemented on this branch. It is listed here only to record the intended
|
||||
design.
|
||||
|
||||
- **Proposal send/receive**: `RCLConsensus::Adaptor::propose()` injects the
|
||||
current thread's active span context into the `TMProposeSet` protobuf via
|
||||
`telemetry::injectToProtobuf()`. PeerImp creates a
|
||||
`consensus.proposal.receive` span that extracts the sender's trace context
|
||||
as parent (via `ConsensusReceiveTracing.h`).
|
||||
|
||||
- **Validation send/receive**: `RCLConsensus::Adaptor::validate()` injects
|
||||
the current thread's active span context into the `TMValidation` protobuf.
|
||||
PeerImp creates a `consensus.validation.receive` span that extracts the
|
||||
sender's trace context as parent.
|
||||
|
||||
- Planned files: `src/xrpld/app/consensus/RCLConsensus.cpp` (send injection),
|
||||
`src/xrpld/overlay/detail/PeerImp.cpp` (receive spans),
|
||||
`src/xrpld/telemetry/ConsensusReceiveTracing.h` (receive span helpers,
|
||||
new file).
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [02-design-decisions.md §2.5](./02-design-decisions.md) — Context propagation design
|
||||
- [04-code-samples.md §4.5.1](./04-code-samples.md) — Relay context injection pattern
|
||||
|
||||
---
|
||||
|
||||
## Task 3.7: Build Verification and Testing
|
||||
|
||||
**Objective**: Verify all Phase 3 changes compile and work correctly.
|
||||
|
||||
**What to do**:
|
||||
|
||||
1. Build with `telemetry=ON` — verify no compilation errors
|
||||
2. Build with `telemetry=OFF` — verify no regressions
|
||||
3. Run existing unit tests
|
||||
4. Verify protobuf regeneration produces correct C++ code
|
||||
5. Document any issues encountered
|
||||
|
||||
**Verification Checklist**:
|
||||
|
||||
- [ ] Protobuf changes generate valid C++
|
||||
- [ ] Build succeeds with telemetry ON
|
||||
- [ ] Build succeeds with telemetry OFF
|
||||
- [ ] Existing tests pass
|
||||
- [ ] No undefined symbols from new telemetry calls
|
||||
|
||||
---
|
||||
|
||||
## Task 3.8: Transaction Span Peer Version Attribute
|
||||
|
||||
> **Source**: [External Dashboard Parity](../docs/superpowers/specs/2026-03-30-external-dashboard-parity-design.md) — adds peer version context inspired by the community [xrpl-validator-dashboard](https://github.com/realgrapedrop/xrpl-validator-dashboard).
|
||||
>
|
||||
> **Upstream**: Phase 2 (RPC span infrastructure must exist).
|
||||
> **Downstream**: Phase 10 (validation checks for this attribute).
|
||||
|
||||
**Objective**: Add the relaying peer's xrpld version to `tx.receive` spans so operators can correlate transaction issues with peer version mismatches during network upgrades.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Edit `src/xrpld/overlay/detail/PeerImp.cpp`:
|
||||
- In the `tx.receive` span block (after existing `peer_id` setAttribute call):
|
||||
- Add `peer_version` (string) — from `this->getVersion()`
|
||||
- Only set if `getVersion()` returns a non-empty string (avoid empty-string attributes)
|
||||
|
||||
**New span attribute**:
|
||||
|
||||
| Attribute | Type | Source | Example |
|
||||
| -------------- | ------ | -------------------- | --------------- |
|
||||
| `peer_version` | string | `peer->getVersion()` | `"xrpld-2.4.0"` |
|
||||
|
||||
**Rationale**: Transaction relay is where version mismatches cause subtle serialization or validation bugs. Tracing "this tx came from a v2.3.0 peer" helps diagnose compatibility issues. The community dashboard tracks peer versions externally; this brings version awareness into the trace itself.
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/overlay/detail/PeerImp.cpp`
|
||||
|
||||
**Exit Criteria**:
|
||||
|
||||
- [ ] `tx.receive` spans carry `peer_version` attribute with a non-empty version string
|
||||
- [ ] Attribute is omitted (not set to empty string) when `getVersion()` returns empty
|
||||
- [ ] Attribute visible in Jaeger span detail view
|
||||
|
||||
---
|
||||
|
||||
## Task 3.9: Deterministic Transaction Trace ID
|
||||
|
||||
> **Upstream**: Task 3.2 (protobuf serialization), Task 3.3 (PeerImp span exists).
|
||||
> **Downstream**: Phase 10 (workload validation can query by tx hash directly).
|
||||
> **Pattern**: Mirrors the consensus deterministic trace ID in Phase 4a
|
||||
> (`createDeterministicContext` in `RCLConsensus.cpp`), adapted for transactions.
|
||||
|
||||
**Objective**: Derive the trace_id for transaction spans deterministically from the
|
||||
transaction hash so that all nodes handling the same transaction independently produce
|
||||
spans under the same trace_id — regardless of whether protobuf context propagation
|
||||
succeeds.
|
||||
|
||||
**Why**: The current approach creates spans with random trace_ids and relies entirely
|
||||
on protobuf `TraceContext` propagation to link them. If any hop in the relay chain
|
||||
drops the context (older peers, message corruption, mixed-version networks), the trace
|
||||
splits and downstream spans become impossible to find. With deterministic trace_ids,
|
||||
correlation is guaranteed because every node derives the same trace_id from the same
|
||||
`txID`.
|
||||
|
||||
**Approach — deterministic trace_id + protobuf span_id propagation**:
|
||||
|
||||
1. Derive `trace_id = txHash[0:16]` (first 16 bytes of the 32-byte transaction hash).
|
||||
2. Generate a random 8-byte `span_id` per node (each node's span is unique within
|
||||
the shared trace).
|
||||
3. Create the span under this deterministic context as parent.
|
||||
4. **Additionally**, if protobuf `TraceContext` is present in the incoming
|
||||
`TMTransaction` message, extract the sender's `span_id` and use it as the span's
|
||||
parent — this preserves parent-child ordering in the trace tree.
|
||||
5. If protobuf context is absent (older peer, first hop), the span still has the
|
||||
correct deterministic `trace_id` — it appears as a sibling root in the same trace
|
||||
rather than being lost.
|
||||
|
||||
This gives the best of both worlds: guaranteed cross-node correlation via deterministic
|
||||
`trace_id`, plus parent-child relay ordering via protobuf `span_id` when available.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Create `createDeterministicTxContext(uint256 const& txHash)` utility function:
|
||||
- Location: shared header or file-local in `PeerImp.cpp` and `NetworkOPs.cpp`
|
||||
(or a shared telemetry utility if both need it).
|
||||
- Pattern: identical to `createDeterministicContext(uint256 const& ledgerId)` in
|
||||
`RCLConsensus.cpp` — take `txHash[0:16]` as trace_id, random span_id via
|
||||
`default_prng()`, sampled flag set, `remote=false`.
|
||||
- Guard behind `#ifdef XRPL_ENABLE_TELEMETRY`.
|
||||
|
||||
```cpp
|
||||
opentelemetry::context::Context
|
||||
createDeterministicTxContext(uint256 const& txHash)
|
||||
{
|
||||
namespace trace = opentelemetry::trace;
|
||||
|
||||
// First 16 bytes of the 32-byte tx hash as trace ID.
|
||||
trace::TraceId traceId(
|
||||
opentelemetry::nostd::span<uint8_t const, 16>(txHash.data(), 16));
|
||||
|
||||
// Random span_id so each node's span is unique within the trace.
|
||||
uint8_t spanIdBytes[8];
|
||||
auto const rval = default_prng()();
|
||||
std::memcpy(spanIdBytes, &rval, sizeof(spanIdBytes));
|
||||
trace::SpanId spanId(
|
||||
opentelemetry::nostd::span<uint8_t const, 8>(spanIdBytes, 8));
|
||||
|
||||
trace::SpanContext syntheticCtx(
|
||||
traceId, spanId, trace::TraceFlags(1), /* remote = */ false);
|
||||
|
||||
return opentelemetry::context::Context{}.SetValue(
|
||||
trace::kSpanKey,
|
||||
opentelemetry::nostd::shared_ptr<trace::Span>(
|
||||
new trace::DefaultSpan(syntheticCtx)));
|
||||
}
|
||||
```
|
||||
|
||||
- Edit `src/xrpld/overlay/detail/PeerImp.cpp` — restructure `handleTransaction()`:
|
||||
- **Move span creation after deserialization** (txID must be known first):
|
||||
1. Deserialize `STTx` and get `txID` (existing code at line ~1382).
|
||||
2. Create deterministic parent context: `auto detCtx = createDeterministicTxContext(txID)`.
|
||||
3. If `m->has_trace_context()`: extract protobuf context via `extractFromProtobuf()`,
|
||||
**combine** with deterministic trace_id — use the protobuf span_id as parent
|
||||
to preserve relay ordering, but override trace_id with the deterministic one.
|
||||
4. If no protobuf context: create span under `detCtx` directly.
|
||||
5. Set all existing attributes (`hash`, `peerId`, `peerVersion`, `suppressed`, etc.).
|
||||
|
||||
- **Combining deterministic trace_id with protobuf parent span_id**:
|
||||
When both are available, construct a synthetic `SpanContext` with:
|
||||
- `trace_id` = `txHash[0:16]` (deterministic)
|
||||
- `span_id` = extracted from protobuf (sender's span_id → becomes parent)
|
||||
- `trace_flags` = from protobuf
|
||||
- `remote` = true (came from another node)
|
||||
|
||||
```cpp
|
||||
// Pseudo-code for the combined context:
|
||||
auto detTraceId = trace::TraceId(txHash.data(), 16);
|
||||
auto remoteSpanId = /* from extractFromProtobuf */;
|
||||
auto remoteFlags = /* from extractFromProtobuf */;
|
||||
|
||||
trace::SpanContext combinedCtx(
|
||||
detTraceId, remoteSpanId, remoteFlags, /* remote = */ true);
|
||||
// Use as parent context for the new span.
|
||||
```
|
||||
|
||||
- Edit `src/xrpld/app/misc/NetworkOPs.cpp` — update `processTransaction()`:
|
||||
- `transaction->getID()` is already available at the top of the function.
|
||||
- Create deterministic parent context from `txID`.
|
||||
- Create `tx.process` span under this context.
|
||||
- No protobuf context to extract here (NetworkOPs is intra-node), so
|
||||
deterministic context alone is sufficient.
|
||||
|
||||
- Add `trace_strategy` attribute to spans:
|
||||
- Add `inline constexpr auto traceStrategy = "trace_strategy";`
|
||||
to `TxSpanNames.h`.
|
||||
- Set on each tx span: `span.setAttribute(tx_span::attr::traceStrategy, "deterministic")`.
|
||||
|
||||
**Key new/modified files**:
|
||||
|
||||
- `src/xrpld/overlay/detail/PeerImp.cpp` — restructured span creation
|
||||
- `src/xrpld/app/misc/NetworkOPs.cpp` — deterministic context for tx.process
|
||||
- `src/xrpld/telemetry/TxSpanNames.h` — new `traceStrategy` attribute constant
|
||||
- New or shared utility for `createDeterministicTxContext()` (location TBD: could be
|
||||
a shared header like `include/xrpl/telemetry/DeterministicContext.h`, or file-local
|
||||
if only used in two places)
|
||||
|
||||
**Interaction with existing tasks**:
|
||||
|
||||
- **Task 3.3 (PeerImp instrumentation)**: The span creation in `handleTransaction()`
|
||||
must be restructured — the span currently starts before `txID` is known. This task
|
||||
moves it after deserialization.
|
||||
- **Task 3.6 (Relay context propagation)**: Protobuf injection at the relay site
|
||||
remains the same — `injectToProtobuf()` serializes the current span's `span_id`.
|
||||
The receiver extracts it and combines with the deterministic `trace_id`.
|
||||
- **Phase 4a (Consensus deterministic trace ID)**: This task follows the same pattern.
|
||||
Consider extracting a shared utility (e.g., `createDeterministicContext(uint256)`)
|
||||
that both consensus and transaction tracing use.
|
||||
|
||||
**Exit Criteria**:
|
||||
|
||||
- [ ] `tx.receive` and `tx.process` spans have deterministic trace_id = `txHash[0:16]`
|
||||
- [ ] All nodes handling the same transaction produce spans under the same trace_id
|
||||
- [x] Protobuf `span_id` propagation still works when available (parent-child ordering)
|
||||
- [ ] Missing protobuf context (old peer) degrades gracefully to sibling spans, not lost traces
|
||||
- [ ] `trace_strategy` attribute set to `"deterministic"` on all tx spans
|
||||
- [ ] Trace queryable by tx hash (truncate hash → trace_id → direct lookup in Tempo)
|
||||
|
||||
**Deliverables implemented (not in original plan)**:
|
||||
|
||||
- **`SpanGuard::txSpan()` factory method** (`include/xrpl/telemetry/SpanGuard.h`):
|
||||
Two overloads for creating transaction spans with deterministic trace IDs:
|
||||
- `txSpan(category, group, name, txHash)` — standalone span (deterministic
|
||||
trace_id from `txHash[0:16]`, no parent span_id).
|
||||
- `txSpan(category, group, name, txHash, parentCtx)` — child span (deterministic
|
||||
trace_id combined with protobuf-extracted parent span_id for relay ordering).
|
||||
|
||||
- **`TxTracing.h` helper functions** (`src/xrpld/telemetry/TxTracing.h`):
|
||||
File-local helpers that wrap `SpanGuard::txSpan()` for the two main PeerImp call
|
||||
sites:
|
||||
- `txReceiveSpan(txHash, parentCtx)` — creates `tx.receive` span with
|
||||
deterministic trace_id and optional protobuf parent context.
|
||||
- `txProcessSpan(txHash)` — creates `tx.process` span with deterministic
|
||||
trace_id only (no protobuf parent, used intra-node).
|
||||
- **Note**: `TxTracing.h` includes `xrpl.pb.h` unconditionally (outside
|
||||
`#ifdef XRPL_ENABLE_TELEMETRY`) because `protocol::TMTransaction` appears in
|
||||
the function signatures regardless of telemetry build mode.
|
||||
|
||||
---
|
||||
|
||||
## Task 3.10: TxQ Instrumentation
|
||||
|
||||
**Status**: COMPLETE
|
||||
|
||||
**Objective**: Trace the transaction queue lifecycle — enqueue decisions, direct apply, batch clear, ledger-close accept loop, per-tx apply, and cleanup.
|
||||
|
||||
**Spans added**:
|
||||
|
||||
- `txq.enqueue` — wraps `TxQ::apply()` with tx_hash attribute
|
||||
- `txq.apply_direct` — wraps `TxQ::tryDirectApply()` fast-path
|
||||
- `txq.batch_clear` — wraps `TxQ::tryClearAccountQueueUpThruTx()`
|
||||
- `txq.accept` — wraps `TxQ::accept()` ledger-close dequeue with queue_size attr
|
||||
- `txq.accept_tx` — per-tx span inside accept loop with tx_hash, ter_code,
|
||||
retries_remaining attributes
|
||||
- `txq.cleanup` — wraps `TxQ::processClosedLedger()` with ledger_seq attribute
|
||||
|
||||
**New file**: `src/xrpld/app/misc/detail/TxQSpanNames.h`
|
||||
|
||||
**Modified file**: `src/xrpld/app/misc/detail/TxQ.cpp`
|
||||
|
||||
---
|
||||
|
||||
## Task 3.11: TX and TxQ Span Attribute Gap Fill
|
||||
|
||||
**Status**: COMPLETE
|
||||
|
||||
**Objective**: Add workflow-identifying attributes to transaction spans so operators can filter by transaction type and see outcomes without off-chain correlation.
|
||||
|
||||
**Attributes added**:
|
||||
|
||||
| Span | Attribute | Type | Source |
|
||||
| ----------------- | -------------------- | ------ | ------------------------------------------------------------------- |
|
||||
| `tx.process` | `tx_type` | string | `TxFormats::getInstance().findByType(stx->getTxnType())->getName()` |
|
||||
| `tx.process` | `fee` | int64 | `stx->getFieldAmount(sfFee).xrp().drops()` |
|
||||
| `tx.process` | `sequence` | int64 | `stx->getSeqProxy().value()` |
|
||||
| `tx.process` | `ter_result` | string | `transToken(e.result)` (set after batch application) |
|
||||
| `tx.process` | `applied` | bool | `e.applied` (set after batch application) |
|
||||
| `tx.receive` | `tx_type` | string | `TxFormats::getInstance().findByType(stx->getTxnType())->getName()` |
|
||||
| `txq.enqueue` | `tx_type` | string | same pattern as above |
|
||||
| `txq.enqueue` | `txq_status` | string | `queued` / `applied_direct` / `applied` / `failed` / `rejected` |
|
||||
| `txq.enqueue` | `ter_code` | string | `transToken(directApplied->ter)` (set on the direct-apply path) |
|
||||
| `txq.enqueue` | `fee_level_paid` | int64 | `getFeeLevelPaid(view, *tx).value()` |
|
||||
| `txq.enqueue` | `required_fee_level` | int64 | `getRequiredFeeLevel(...).value()` |
|
||||
| `txq.batch_clear` | `num_cleared` | int64 | queued txs cleared ahead of the applying tx |
|
||||
| `txq.cleanup` | `expired_count` | int64 | entries dropped for passed `LastLedgerSequence` |
|
||||
| `txq.accept_tx` | `txq_status` | string | `applied` / `failed` / `retried` |
|
||||
| `txq.accept_tx` | `ter_code` | string | `transToken(txnResult)` (set before branching on the outcome) |
|
||||
| `txq.accept` | `ledger_changed` | bool | set at end of accept loop |
|
||||
|
||||
**New attr keys**: `TxSpanNames.h` (`txType`, `fee`, `sequence`, `terResult`, `applied`), `TxQSpanNames.h` (`txType`).
|
||||
|
||||
**Modified files**:
|
||||
|
||||
- `src/xrpld/telemetry/TxSpanNames.h`
|
||||
- `src/xrpld/app/misc/detail/TxQSpanNames.h`
|
||||
- `src/xrpld/app/misc/NetworkOPs.cpp`
|
||||
- `src/xrpld/overlay/detail/PeerImp.cpp`
|
||||
- `src/xrpld/app/misc/detail/TxQ.cpp`
|
||||
|
||||
---
|
||||
|
||||
## Summary
|
||||
|
||||
| Task | Description | New Files | Modified Files | Depends On |
|
||||
| ---- | ----------------------------------- | --------- | -------------- | ---------- |
|
||||
| 3.1 | TraceContext protobuf message | 0 | 1 | Phase 2 |
|
||||
| 3.2 | Protobuf context serialization | 1-2 | 0 | 3.1 |
|
||||
| 3.3 | PeerImp transaction instrumentation | 0 | 1 | 3.2 |
|
||||
| 3.4 | NetworkOPs transaction processing | 0 | 1 | Phase 2 |
|
||||
| 3.5 | HashRouter dedup visibility | 0 | 1 | 3.3 |
|
||||
| 3.6 | Relay context propagation | 0 | 1-2 | 3.3, 3.5 |
|
||||
| 3.7 | Build verification and testing | 0 | 0 | 3.1-3.6 |
|
||||
| 3.8 | TX span peer version attribute | 0 | 1 | 3.3 |
|
||||
| 3.9 | Deterministic transaction trace ID | 0-1 | 3 | 3.2, 3.3 |
|
||||
| 3.10 | TxQ instrumentation (6 spans) | 1 | 1 | 3.4 |
|
||||
| 3.11 | TX/TxQ span attribute gap fill | 0 | 5 | 3.3, 3.10 |
|
||||
|
||||
**Parallel work**: Tasks 3.1 and 3.4 can start in parallel. Task 3.2 depends on 3.1. Tasks 3.3 and 3.5 depend on 3.2. Task 3.6 depends on 3.3 and 3.5. Task 3.8 depends on 3.3 (span must exist). Task 3.9 depends on 3.2 and 3.3. Task 3.10 depends on 3.4 (tx.process span must exist).
|
||||
|
||||
**Exit Criteria** (from [06-implementation-phases.md §6.11.3](./06-implementation-phases.md)):
|
||||
|
||||
- [x] Transaction traces span across nodes
|
||||
- [x] Trace context in Protocol Buffer messages
|
||||
- [ ] HashRouter deduplication visible in traces
|
||||
- [ ] <5% overhead on transaction throughput
|
||||
- [x] Deterministic trace_id: same trace_id for same tx across all nodes
|
||||
- [x] Protobuf span_id propagation preserves parent-child ordering when available
|
||||
949
OpenTelemetryPlan/Phase4_taskList.md
Normal file
949
OpenTelemetryPlan/Phase4_taskList.md
Normal file
@@ -0,0 +1,949 @@
|
||||
# Phase 4: Consensus Tracing Task List
|
||||
|
||||
> **Goal**: Full observability into consensus rounds — track round lifecycle, phase transitions, proposal handling, and validation. This is the RUN phase that completes the distributed tracing story.
|
||||
>
|
||||
> **Scope**: RCLConsensus instrumentation for round starts, phase transitions (open/establish/accept), proposal send/receive, validation handling, and correlation with transaction traces from Phase 3.
|
||||
>
|
||||
> **Branch**: `pratik/otel-phase4-consensus-tracing` (from `pratik/otel-phase3-tx-tracing`)
|
||||
|
||||
> **Note on attribute names**: the `xrpl.<domain>.<field>` keys shown below are
|
||||
> written in the older dotted form for readability — it mirrors how the fully
|
||||
> qualified attribute reads in a Tempo trace view. The implemented keys follow
|
||||
> the convention in [CONTRIBUTING.md](../CONTRIBUTING.md#telemetry-span-attribute-naming)
|
||||
> (underscore form, e.g. `consensus_round`, `consensus_mode`); the
|
||||
> `*SpanNames.h` constants are the single source of truth.
|
||||
|
||||
### Related Plan Documents
|
||||
|
||||
| Document | Relevance |
|
||||
| ------------------------------------------------------------ | ----------------------------------------------------------- |
|
||||
| [04-code-samples.md](./04-code-samples.md) | Consensus instrumentation (§4.5.2), consensus span patterns |
|
||||
| [01-architecture-analysis.md](./01-architecture-analysis.md) | Consensus round flow (§1.4), key trace points (§1.6) |
|
||||
| [06-implementation-phases.md](./06-implementation-phases.md) | Phase 4 tasks (§6.5), definition of done (§6.11.4) |
|
||||
| [02-design-decisions.md](./02-design-decisions.md) | Consensus attribute schema (§2.4.4) |
|
||||
|
||||
---
|
||||
|
||||
## Task 4.1: Instrument Consensus Round Start ✅
|
||||
|
||||
**Objective**: Create a root span for each consensus round that captures the round's key parameters.
|
||||
|
||||
**Status**: DONE (implemented via Task 4a.2 `startRoundTracing()` helper).
|
||||
|
||||
**What was done**:
|
||||
|
||||
- `RCLConsensus::Adaptor::startRoundTracing()` creates `consensus.round` span
|
||||
via `SpanGuard::hashSpan()` (deterministic) or `SpanGuard::span()` (attribute strategy)
|
||||
- Attributes set: `xrpl.consensus.ledger_id`, `xrpl.ledger.seq`,
|
||||
`xrpl.consensus.mode`, `trace_strategy`, `xrpl.consensus.round_id`
|
||||
- Round span stored as `roundSpan_` member in `RCLConsensus::Adaptor`
|
||||
- `roundSpanContext_` snapshot captured for cross-thread span linking
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp`
|
||||
- `src/xrpld/app/consensus/RCLConsensus.h` (span and context members)
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [04-code-samples.md §4.5.2](./04-code-samples.md) — startRound instrumentation example
|
||||
- [01-architecture-analysis.md §1.4](./01-architecture-analysis.md) — Consensus round flow
|
||||
|
||||
---
|
||||
|
||||
## Task 4.2: Instrument Phase Transitions ✅
|
||||
|
||||
**Objective**: Create child spans for each consensus phase (open, establish, accept) to show timing breakdown.
|
||||
|
||||
**Status**: DONE. All consensus phases are now instrumented:
|
||||
|
||||
- `consensus.establish` — created in `Consensus.h::startEstablishTracing()`
|
||||
- `consensus.ledger_close` — created in `RCLConsensus.cpp::onClose()`
|
||||
- `consensus.accept` / `consensus.accept.apply` — created in `onAccept()` / `doAccept()`
|
||||
- `consensus.phase.open` — `openSpan_` member in `Consensus.h`, created in `startRoundInternal()`, ended in `closeLedger()`
|
||||
|
||||
**Design notes**:
|
||||
|
||||
- `phase` attribute — phases are distinguished by span names instead
|
||||
- `phase.enter` / `phase.exit` events — not added (span start/end serves this purpose)
|
||||
- `phase_duration_ms` attribute — not set (span duration captures this)
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp`
|
||||
- `src/xrpld/consensus/Consensus.h` (template-level establish phase tracking)
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [04-code-samples.md §4.5.2](./04-code-samples.md) — phaseTransition instrumentation
|
||||
|
||||
---
|
||||
|
||||
## Task 4.3: Instrument Proposal Handling ✅
|
||||
|
||||
**Objective**: Trace proposal send and receive to show validator coordination.
|
||||
|
||||
**Status**: DONE. Both send and receive paths are instrumented.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- In `Adaptor::propose()`:
|
||||
- Creates `consensus.proposal.send` span via `SpanGuard::span()`
|
||||
- Sets `xrpl.consensus.round` attribute
|
||||
|
||||
- In `PeerImp::onMessage(TMProposeSet)`:
|
||||
- Creates `consensus.proposal.receive` span
|
||||
- Sets `trusted` attribute (bool)
|
||||
|
||||
**Done here** (cross-node propagation, send + receive):
|
||||
|
||||
- Trace context injection for `TMProposeSet::trace_context` in `propose()`
|
||||
- Receive-side extraction in `PeerImp::onMessage(TMProposeSet)` via
|
||||
`telemetry::proposalReceiveSpan()` (parents the receive span on the
|
||||
sender's context when a valid `trace_context` is present)
|
||||
|
||||
**Not implemented** (deferred to Phase 4b):
|
||||
|
||||
- `consensus.proposal.relay` span in `share(RCLCxPeerPos)`
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp`
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [04-code-samples.md §4.5.2](./04-code-samples.md) — peerProposal instrumentation
|
||||
- [02-design-decisions.md §2.4.4](./02-design-decisions.md) — Consensus attribute schema
|
||||
|
||||
---
|
||||
|
||||
## Task 4.4: Instrument Validation Handling ✅
|
||||
|
||||
**Objective**: Trace validation send and receive to show ledger validation flow.
|
||||
|
||||
**Status**: DONE. Both send and receive paths are instrumented.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- In `Adaptor::validate()` (called from `doAccept()`):
|
||||
- Creates `consensus.validation.send` span via `Adaptor::createValidationSpan()`
|
||||
- Uses `SpanGuard::linkedSpan()` to create a follows-from link to the round span
|
||||
- Thread-safe: uses `roundSpanContext_` snapshot (captured on consensus thread,
|
||||
read on jtACCEPT thread)
|
||||
- Sets `xrpl.ledger.seq` and `proposing` attributes
|
||||
|
||||
- In `PeerImp::onMessage(TMValidation)`:
|
||||
- Creates `consensus.validation.receive` span
|
||||
- Sets `trusted` attribute (bool)
|
||||
- Sets `xrpl.ledger.seq` attribute
|
||||
|
||||
**Not implemented** (deferred to Phase 4b — cross-node propagation):
|
||||
|
||||
- Validated ledger hash, signing time attributes on send span (see Task 4.8)
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp`
|
||||
|
||||
---
|
||||
|
||||
## Task 4.5: Add Consensus-Specific Attributes ✅
|
||||
|
||||
**Objective**: Enrich consensus spans with detailed attributes for debugging and analysis.
|
||||
|
||||
**Status**: DONE. All core attributes are set across various spans, including the previously missing `tx_count` and `disputes_count`.
|
||||
|
||||
**Implemented attributes** (across various spans):
|
||||
|
||||
- `xrpl.ledger.seq` — on `consensus.round`, `consensus.accept.apply`
|
||||
- `xrpl.consensus.round` — on `consensus.proposal.send`
|
||||
- `xrpl.consensus.mode` — on `consensus.round`, `consensus.ledger_close`
|
||||
- `proposers` — on `consensus.accept`, `consensus.establish`, `consensus.update_positions`
|
||||
- `converge_percent` — on `consensus.establish`, `consensus.update_positions`, `consensus.check`
|
||||
- `tx_count` — on `consensus.accept.apply` span (in `doAccept()`)
|
||||
- `disputes_count` — on `consensus.update_positions` span (in `updateOurPositions()`)
|
||||
- `close_reason` — on `consensus.phase.open`, from `whyCloseLedger()` (`anomaly`, `others_closed`, `idle`, `normal`)
|
||||
- `close_time_avalanche_state` — on `consensus.establish`, terminal regime (`init`, `mid`, `late`, `stuck`)
|
||||
|
||||
**Design notes**:
|
||||
|
||||
- `phase` — phases distinguished by span names instead
|
||||
- `phase_duration_ms` — span duration captures this
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp`
|
||||
- `src/xrpld/consensus/Consensus.h`
|
||||
|
||||
---
|
||||
|
||||
## Task 4.6: Correlate Transaction and Consensus Traces ✅
|
||||
|
||||
**Objective**: Link transaction traces from Phase 3 with consensus traces so you can follow a transaction from submission through consensus into the ledger.
|
||||
|
||||
**Status**: DONE. Transaction-consensus correlation implemented via `tx.included` events in `doAccept()`.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- In `doAccept()` (RCLConsensus.cpp):
|
||||
- Records `tx.included` events on the `consensus.accept.apply` span for each transaction in the accepted set
|
||||
- Each event includes `xrpl.tx.id` attribute with the transaction hash
|
||||
- This links consensus traces to individual transactions
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp`
|
||||
|
||||
---
|
||||
|
||||
## Task 4.7: Build Verification and Testing ✅
|
||||
|
||||
**Objective**: Verify all Phase 4 changes compile and don't affect consensus timing.
|
||||
|
||||
**What to do**:
|
||||
|
||||
1. Build with `telemetry=ON` — verify no compilation errors
|
||||
2. Build with `telemetry=OFF` — verify no regressions (critical for consensus code)
|
||||
3. Run existing consensus-related unit tests
|
||||
4. Verify that `SpanGuard` factory methods compile to no-ops when disabled
|
||||
5. Check that no consensus-critical code paths are affected by instrumentation overhead
|
||||
|
||||
**Verification Checklist**:
|
||||
|
||||
- [x] Build succeeds with telemetry ON
|
||||
- [x] Build succeeds with telemetry OFF
|
||||
- [x] Existing consensus tests pass
|
||||
- [x] `SpanGuard` no-op implementation prevents overhead when telemetry is OFF
|
||||
- [x] Phase timing instrumentation doesn't use blocking operations
|
||||
|
||||
---
|
||||
|
||||
## Task 4.8: Consensus Validation Span Enrichment — NOT DONE
|
||||
|
||||
> **Source**: [External Dashboard Parity](../docs/superpowers/specs/2026-03-30-external-dashboard-parity-design.md) — adds validation agreement context inspired by the community [xrpl-validator-dashboard](https://github.com/realgrapedrop/xrpl-validator-dashboard).
|
||||
>
|
||||
> **Upstream**: Phase 4 tasks 4.1-4.4 (span creation must exist).
|
||||
> **Downstream**: Phase 7 (ValidationTracker reads these attributes), Phase 10 (validation checks).
|
||||
|
||||
**Objective**: Add ledger hash, validation type, and quorum data to consensus validation spans on both send and receive paths. This enables trace-level validation agreement analysis — filter by ledger hash to see which validators agreed for a given ledger.
|
||||
|
||||
**Status**: Not implemented. None of the enrichment attributes are set. The `consensus.validation.send` span only has `ledger.seq` and `proposing`. The `consensus.accept` span has `quorum` set to `result.proposers` (not the actual validator quorum from `app_.validators().quorum()`). No `PeerImp.cpp` changes were made.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Edit `src/xrpld/app/consensus/RCLConsensus.cpp`:
|
||||
- On the `consensus.validation.send` span (in `validate()` / `doAccept()`):
|
||||
- Add `xrpl.validation.ledger_hash` (string) — the ledger hash being validated
|
||||
- Add `xrpl.validation.full` (bool) — whether this is a full validation (not partial)
|
||||
- On the `consensus.accept` span (in `onAccept()`):
|
||||
- Add `validation_quorum` (int64) — from `app_.validators().quorum()`
|
||||
- Add `proposers_validated` (int64) — from `result.proposers`
|
||||
|
||||
- Edit `src/xrpld/overlay/detail/PeerImp.cpp`:
|
||||
- On the `peer.validation.receive` span:
|
||||
- Add `xrpl.peer.validation.ledger_hash` (string) — from deserialized `STValidation` object
|
||||
- Add `xrpl.peer.validation.full` (bool) — from `STValidation` flags
|
||||
|
||||
**New span attributes**:
|
||||
|
||||
| Span | Attribute | Type | Source |
|
||||
| --------------------------- | ---------------------------------- | ------ | --------------------------------- |
|
||||
| `consensus.validation.send` | `xrpl.validation.ledger_hash` | string | Ledger hash from validate() args |
|
||||
| `consensus.validation.send` | `xrpl.validation.full` | bool | Full vs partial validation |
|
||||
| `peer.validation.receive` | `xrpl.peer.validation.ledger_hash` | string | From STValidation deserialization |
|
||||
| `peer.validation.receive` | `xrpl.peer.validation.full` | bool | From STValidation flags |
|
||||
| `consensus.accept` | `validation_quorum` | int64 | `app_.validators().quorum()` |
|
||||
| `consensus.accept` | `proposers_validated` | int64 | `result.proposers` |
|
||||
|
||||
**Rationale**: The external dashboard's most valuable feature is validation agreement tracking. By recording the ledger hash on both outgoing and incoming validation spans, we create the raw data for agreement analysis at the trace level. Example Tempo query:
|
||||
|
||||
```
|
||||
{name="consensus.validation.send"} | xrpl.validation.ledger_hash = "A1B2C3..."
|
||||
```
|
||||
|
||||
Phase 7's `ValidationTracker` builds metric-level aggregation (1h/24h agreement %) on top of this data.
|
||||
|
||||
**Key modified files (not yet modified)**:
|
||||
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp`
|
||||
- `src/xrpld/overlay/detail/PeerImp.cpp`
|
||||
|
||||
**Exit Criteria**:
|
||||
|
||||
- [x] `consensus.validation.send` spans carry `ledger_hash` and `full_validation`
|
||||
- [ ] `peer.validation.receive` spans carry `xrpl.peer.validation.ledger_hash` and `xrpl.peer.validation.full`
|
||||
- [ ] `consensus.accept` spans carry `validation_quorum` and `proposers_validated`
|
||||
- [x] Ledger hash attributes match between send and receive for the same ledger
|
||||
- [ ] No impact on consensus performance
|
||||
|
||||
---
|
||||
|
||||
## Task 4.9: Consensus Span Attribute Gap Fill
|
||||
|
||||
**Status**: COMPLETE
|
||||
|
||||
**Objective**: Add workflow-critical attributes to consensus spans that enable operators to understand consensus outcomes, identify bow-out proposals, and correlate validations to specific ledgers.
|
||||
|
||||
**Attributes added**:
|
||||
|
||||
| Span | Attribute | Type | Source |
|
||||
| --------------------------- | ----------------- | ------ | ------------------------------------- |
|
||||
| `consensus.proposal.send` | `is_bow_out` | bool | `proposal.isBowOut()` |
|
||||
| `consensus.accept` | `consensus_state` | string | `result.state` (yes/moved_on/expired) |
|
||||
| `consensus.accept` | `disputes_count` | int64 | `result.disputes.size()` |
|
||||
| `consensus.validation.send` | `ledger_hash` | string | `ledger.ledger->header().hash` |
|
||||
|
||||
**New attr keys**: `ConsensusSpanNames.h` (`isBowOut`, `ledgerHash`).
|
||||
|
||||
**Modified files**:
|
||||
|
||||
- `src/xrpld/consensus/ConsensusSpanNames.h`
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp`
|
||||
|
||||
---
|
||||
|
||||
## Summary
|
||||
|
||||
| Task | Description | Status | New Files | Modified Files | Depends On |
|
||||
| ---- | ------------------------------------------- | ----------- | --------- | -------------- | ------------- |
|
||||
| 4.1 | Consensus round start instrumentation | ✅ Done | 0 | 2 | Phase 3 |
|
||||
| 4.2 | Phase transition instrumentation | ✅ Done | 0 | 1-2 | 4.1 |
|
||||
| 4.3 | Proposal handling instrumentation | ✅ Done | 0 | 2 | 4.1 |
|
||||
| 4.4 | Validation handling instrumentation | ✅ Done | 0 | 2 | 4.1 |
|
||||
| 4.5 | Consensus-specific attributes | ✅ Done | 0 | 2 | 4.2, 4.3, 4.4 |
|
||||
| 4.6 | Transaction-consensus correlation | ✅ Done | 0 | 1 | 4.2, Phase 3 |
|
||||
| 4.7 | Build verification and testing | ✅ Done | 0 | 0 | 4.1-4.6 |
|
||||
| 4.8 | Validation span enrichment (ext. dashboard) | ❌ Not done | 0 | 2 | 4.4 |
|
||||
| 4.9 | Consensus span attribute gap fill | ✅ Done | 0 | 2 | 4.1-4.5 |
|
||||
|
||||
**Parallel work**: Tasks 4.2, 4.3, and 4.4 can run in parallel after 4.1 is complete. Task 4.5 depends on all three. Task 4.6 depends on 4.2 and Phase 3. Task 4.8 depends on 4.4 (validation spans must exist).
|
||||
|
||||
### Implemented Spans
|
||||
|
||||
| Span Name | Method | Key Attributes |
|
||||
| --------------------------- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||
| `consensus.proposal.send` | `Adaptor::propose` | `xrpl.consensus.round`, `is_bow_out` |
|
||||
| `consensus.ledger_close` | `Adaptor::onClose` | `xrpl.ledger.seq`, `xrpl.consensus.mode` |
|
||||
| `consensus.accept` | `Adaptor::onAccept` | `proposers`, `round_time_ms`, `quorum`, `disputes_count`, `consensus_state` |
|
||||
| `consensus.accept.apply` | `Adaptor::doAccept` | `close_time_ripple_epoch_s`, `close_time_correct`, `close_resolution_ms`, `consensus_state`, `proposing`, `round_time_ms`, `xrpl.ledger.seq`, `parent_close_time_ripple_epoch_s`, `close_time_self_ripple_epoch_s`, `close_time_vote_bins`, `resolution_direction` |
|
||||
| `consensus.validation.send` | `Adaptor::onAccept` (via validate) | `proposing`, `ledger_hash`, `ledger_seq`, `full_validation`, `validation_sign_time` |
|
||||
|
||||
#### Close Time Attributes (consensus.accept.apply)
|
||||
|
||||
The `consensus.accept.apply` span captures ledger close time agreement details
|
||||
driven by `avCT_CONSENSUS_PCT` (75% validator agreement threshold):
|
||||
|
||||
- **`close_time_ripple_epoch_s`** — Agreed-upon ledger close time (XRPL epoch seconds). When validators disagree (`consensusCloseTime == epoch`), this is synthetically set to `prevCloseTime + 1s`.
|
||||
- **`close_time_correct`** — `true` if validators reached agreement, `false` if they "agreed to disagree" (close time forced to prev+1s).
|
||||
- **`close_resolution_ms`** — Rounding granularity for close time (starts at 30s, decreases as ledger interval stabilizes).
|
||||
- **`consensus_state`** — `"finished"` (normal) or `"moved_on"` (consensus failed, adopted best available).
|
||||
- **`proposing`** — Whether this node was proposing.
|
||||
- **`round_time_ms`** — Total consensus round duration.
|
||||
- **`parent_close_time_ripple_epoch_s`** — Previous ledger's close time (XRPL epoch seconds). Enables computing close-time deltas across consecutive rounds without correlating separate spans.
|
||||
- **`close_time_self_ripple_epoch_s`** — This node's own proposed close time before consensus voting.
|
||||
- **`close_time_vote_bins`** — Number of distinct close-time vote bins from peer proposals. Higher values indicate less agreement among validators.
|
||||
- **`resolution_direction`** — Whether close-time resolution `"increased"` (coarser), `"decreased"` (finer), or stayed `"unchanged"` relative to the previous ledger.
|
||||
|
||||
**Exit Criteria** (from [06-implementation-phases.md §6.11.4](./06-implementation-phases.md)):
|
||||
|
||||
- [x] Complete consensus round traces
|
||||
- [x] Phase transitions visible (open, establish, close, accept)
|
||||
- [x] Proposals and validations traced — send and receive; relay deferred to Phase 4b
|
||||
- [x] Close time agreement tracked (per `avCT_CONSENSUS_PCT`)
|
||||
- [x] No impact on consensus timing
|
||||
- [x] Transaction-consensus correlation (Task 4.6) — `tx.included` events in doAccept
|
||||
- [ ] Validation span enrichment (Task 4.8) — not implemented
|
||||
|
||||
---
|
||||
|
||||
# Phase 4a: Establish-Phase Gap Fill & Cross-Node Correlation
|
||||
|
||||
> **Goal**: Fill tracing gaps in the consensus establish phase (disputes, convergence,
|
||||
> threshold escalation, mode changes) and establish cross-node correlation using a
|
||||
> deterministic shared trace ID derived from `previousLedger.id()`.
|
||||
>
|
||||
> **Approach**: Direct instrumentation in `Consensus.h` and `RCLConsensus.cpp`.
|
||||
> All spans use `SpanGuard` factory methods (`span()`, `hashSpan()`, `linkedSpan()`)
|
||||
> with `TraceCategory::Consensus` gating. Long-lived spans (round, establish) are
|
||||
> stored as `std::optional<SpanGuard>` class members. Short-lived scoped spans
|
||||
> (update_positions, check) are local variables. No macros are used — all tracing
|
||||
> is via direct `SpanGuard` API calls. `SpanGuard` compiles to no-ops when
|
||||
> telemetry is disabled.
|
||||
>
|
||||
> **Branch**: `pratik/otel-phase4-consensus-tracing`
|
||||
|
||||
## Design: Switchable Correlation Strategy
|
||||
|
||||
Two strategies for cross-node trace correlation, switchable via config:
|
||||
|
||||
### Strategy A — Deterministic Trace ID (Default)
|
||||
|
||||
Derive `trace_id = SHA256(previousLedger.id())[0:16]` so all nodes in the same
|
||||
consensus round share the same trace_id without P2P context propagation.
|
||||
|
||||
- **Pros**: All nodes appear in the same trace in Tempo/Jaeger automatically.
|
||||
No collector-side post-processing needed.
|
||||
- **Cons**: Overrides OTel's random trace_id generation; requires custom
|
||||
`IdGenerator` or manual span context construction.
|
||||
|
||||
### Strategy B — Attribute-Based Correlation
|
||||
|
||||
Use normal random trace_id but attach `xrpl.consensus.ledger_id` as an attribute
|
||||
on every consensus span. Correlation happens at query time via Tempo/Grafana
|
||||
`by attribute` queries.
|
||||
|
||||
- **Pros**: Standard OTel trace_id semantics; no SDK customization.
|
||||
- **Cons**: Cross-node correlation requires query-time joins, not automatic.
|
||||
|
||||
### Config
|
||||
|
||||
```ini
|
||||
[telemetry]
|
||||
# "deterministic" (default) or "attribute"
|
||||
consensus_trace_strategy=deterministic
|
||||
```
|
||||
|
||||
The C++ API to query this at runtime is `Telemetry::getConsensusTraceStrategy()`,
|
||||
which returns a `std::string const&` (`"deterministic"` or `"attribute"`).
|
||||
|
||||
### Implementation
|
||||
|
||||
In `RCLConsensus::Adaptor::startRound()`:
|
||||
|
||||
- If `deterministic`:
|
||||
1. Compute `trace_id_bytes = SHA256(prevLedgerID)[0:16]`
|
||||
2. Construct `opentelemetry::trace::TraceId(trace_id_bytes)`
|
||||
3. Create a synthetic `SpanContext` with this trace_id and a random span_id:
|
||||
```cpp
|
||||
auto traceId = opentelemetry::trace::TraceId(trace_id_bytes);
|
||||
auto spanId = opentelemetry::trace::SpanId(random_8_bytes);
|
||||
auto syntheticCtx = opentelemetry::trace::SpanContext(
|
||||
traceId, spanId, opentelemetry::trace::TraceFlags(1), false);
|
||||
```
|
||||
4. Wrap in `opentelemetry::context::Context` via
|
||||
`opentelemetry::trace::SetSpan(context, syntheticSpan)`
|
||||
5. Call `startSpan("consensus.round", parentContext)` so the new span
|
||||
inherits the deterministic trace_id.
|
||||
- If `attribute`: start a normal `consensus.round` span, set
|
||||
`xrpl.consensus.ledger_id = previousLedger.id()` as attribute.
|
||||
|
||||
Both strategies always set `xrpl.consensus.round_id` (round number) and
|
||||
`xrpl.consensus.ledger_id` (previous ledger hash) as attributes.
|
||||
|
||||
---
|
||||
|
||||
## Design: Span Hierarchy
|
||||
|
||||
```
|
||||
consensus.round (root — created in RCLConsensus::startRound, closed at accept)
|
||||
│ link → previous round's SpanContext (follows-from)
|
||||
│
|
||||
├── consensus.establish (phaseEstablish → acceptance, in Consensus.h)
|
||||
│ ├── consensus.update_positions (each updateOurPositions call)
|
||||
│ │ └── consensus.dispute.resolve (per-tx dispute resolution event)
|
||||
│ ├── consensus.check (each haveConsensus call)
|
||||
│ └── consensus.mode_change (short-lived span in adaptor on mode transition)
|
||||
│
|
||||
├── consensus.accept (existing onAccept span — reparented under round)
|
||||
│
|
||||
└── consensus.validation.send (existing — reparented, follows-from link to round)
|
||||
```
|
||||
|
||||
### Span Links (follows-from relationships)
|
||||
|
||||
| Link Source | Link Target | Rationale |
|
||||
| ----------------------------------------- | -------------------------- | ------------------------------------------------------------------------------ |
|
||||
| `consensus.round` (N+1) | `consensus.round` (N) | Causal chain: round N+1 exists because round N accepted |
|
||||
| `consensus.validation.send` | `consensus.round` | Validation follows from the round that produced it; may outlive the round span |
|
||||
| _(Phase 4b)_ Received proposal processing | Sender's `consensus.round` | Cross-node causal link via P2P context propagation |
|
||||
|
||||
---
|
||||
|
||||
## Task 4a.0: Prerequisites — Extend SpanGuard and Telemetry APIs ✅
|
||||
|
||||
**Objective**: Add missing API surface needed by later tasks.
|
||||
|
||||
**Status**: Done, but implemented differently than originally planned. The macro-based
|
||||
approach (`XRPL_TRACE_CONSENSUS`, `XRPL_TRACE_ADD_EVENT`, `XRPL_TRACE_SET_ATTR`) was
|
||||
**not used**. Instead, all consensus tracing uses `SpanGuard` factory methods and
|
||||
direct method calls, which is cleaner and avoids macro control-flow issues.
|
||||
|
||||
**What was done**:
|
||||
|
||||
1. **`SpanGuard::addEvent()` with attributes** — implemented as planned:
|
||||
|
||||
```cpp
|
||||
using EventAttribute = std::pair<std::string_view, std::string_view>;
|
||||
|
||||
void addEvent(std::string_view name,
|
||||
std::initializer_list<EventAttribute> attrs);
|
||||
```
|
||||
|
||||
Callers pass plain `string_view` pairs; the implementation converts internally.
|
||||
|
||||
```cpp
|
||||
// Actual usage in Consensus.h::updateOurPositions():
|
||||
span.addEvent(
|
||||
"dispute.resolve",
|
||||
{{consensus::span::attr::txId, to_string(txId)},
|
||||
{consensus::span::attr::disputeOurVote, dispute.getOurVote() ? "yes" : "no"}});
|
||||
```
|
||||
|
||||
2. **Span link support** — implemented via `SpanGuard::linkedSpan()` static factory
|
||||
instead of a `Telemetry::startSpan()` overload:
|
||||
|
||||
```cpp
|
||||
static SpanGuard linkedSpan(
|
||||
std::string_view name, SpanContext const& linkTarget);
|
||||
```
|
||||
|
||||
3. **No macros added** — `TracingInstrumentation.h` was not created. The `XRPL_TRACE_CONSENSUS`,
|
||||
`XRPL_TRACE_ADD_EVENT`, and `XRPL_TRACE_SET_ATTR` macros from the original plan were
|
||||
not implemented. All consensus tracing uses direct `SpanGuard` API:
|
||||
- `SpanGuard::span()` — create scoped spans
|
||||
- `SpanGuard::hashSpan()` — create spans with deterministic trace IDs
|
||||
- `SpanGuard::linkedSpan()` — create spans with follows-from links
|
||||
- `span.setAttribute()` — set attributes directly
|
||||
- `span.addEvent()` — add events directly
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `include/xrpl/telemetry/SpanGuard.h` — `addEvent()` overload, `EventAttribute` type alias
|
||||
- `src/libxrpl/telemetry/SpanGuard.cpp` — `addEvent()` implementation
|
||||
|
||||
---
|
||||
|
||||
## Task 4a.1: Adaptor `getTelemetry()` Method — NOT DONE (Not Needed)
|
||||
|
||||
**Objective**: Give `Consensus.h` access to the telemetry subsystem without
|
||||
coupling the generic template to OTel headers.
|
||||
|
||||
**Status**: Not implemented as specified. The `getTelemetry()` adaptor method was
|
||||
not needed because `SpanGuard::span()` is a static factory method that internally
|
||||
checks telemetry state via the global `Telemetry` singleton. `Consensus.h` creates
|
||||
spans by calling `SpanGuard::span(TraceCategory::Consensus, ...)` directly, without
|
||||
needing adaptor access. Only `RCLConsensus::Adaptor` uses `app_.getTelemetry()`
|
||||
directly (for `getConsensusTraceStrategy()` in `startRoundTracing()`).
|
||||
|
||||
**Key insight**: The `XRPL_TRACE_*` macro approach would have required
|
||||
`adaptor_.getTelemetry()`. Since macros were not used, this task became unnecessary.
|
||||
|
||||
---
|
||||
|
||||
## Task 4a.2: Switchable Round Span with Deterministic Trace ID ✅
|
||||
|
||||
**Objective**: Create a `consensus.round` root span in `startRound()` that uses
|
||||
the switchable correlation strategy. Store span context as a member for child
|
||||
spans in `Consensus.h`.
|
||||
|
||||
**Status**: Done. Implemented in `Adaptor::startRoundTracing()`.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- `RCLConsensus::Adaptor::startRoundTracing()` helper:
|
||||
- Reads `consensus_trace_strategy` via `app_.getTelemetry().getConsensusTraceStrategy()`
|
||||
- **Deterministic**: uses `SpanGuard::hashSpan()` with `prevLgr.id()` data
|
||||
- **Attribute**: uses `SpanGuard::span(TraceCategory::Consensus, seg::consensus, "round")`
|
||||
- Sets attributes: `xrpl.consensus.ledger_id`, `xrpl.ledger.seq`, `xrpl.consensus.mode`, `trace_strategy`, `xrpl.consensus.round_id`
|
||||
- Captures `roundSpanContext_` snapshot for cross-thread span linking
|
||||
- Saves `prevRoundContext_` from previous round for follows-from links
|
||||
|
||||
- **`SpanGuard::hashSpan()` factory**: encapsulates deterministic trace ID logic:
|
||||
|
||||
```cpp
|
||||
static SpanGuard hashSpan(
|
||||
TraceCategory cat, std::string_view name,
|
||||
std::uint8_t const* hashData, std::size_t hashSize);
|
||||
```
|
||||
|
||||
Derives `trace_id = hashData[0:16]` so all nodes in the same round share
|
||||
the same trace_id. Compiles to no-op when telemetry is disabled.
|
||||
|
||||
- `consensus_trace_strategy` config parsed in `TelemetryConfig.cpp`,
|
||||
stored in `Telemetry::Setup`, accessible via `Telemetry::getConsensusTraceStrategy()`
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp` — `startRoundTracing()` implementation
|
||||
- `src/xrpld/app/consensus/ConsensusSpanNames.h` — **(new)** compile-time span name and attribute key constants
|
||||
- `include/xrpl/telemetry/Telemetry.h` — `consensusTraceStrategy` in Setup, `getConsensusTraceStrategy()`
|
||||
- `src/libxrpl/telemetry/TelemetryConfig.cpp` — parse new config option
|
||||
|
||||
---
|
||||
|
||||
## Task 4a.3: Span Members in `Consensus.h` ✅
|
||||
|
||||
**Objective**: Add span storage to the `Consensus` class so that spans created
|
||||
in `startRound()` (adaptor) are accessible from `phaseEstablish()`,
|
||||
`updateOurPositions()`, and `haveConsensus()` (template methods).
|
||||
|
||||
**Status**: Done with documented plan deviation.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- `establishSpan_` added to `Consensus` private members (as planned):
|
||||
|
||||
```cpp
|
||||
std::optional<xrpl::telemetry::SpanGuard> establishSpan_;
|
||||
```
|
||||
|
||||
- **Plan deviation**: `roundSpan_`, `prevRoundContext_`, and `roundSpanContext_`
|
||||
are stored in `RCLConsensus::Adaptor` (not `Consensus.h`) because the adaptor
|
||||
has access to telemetry config for the deterministic trace ID strategy.
|
||||
|
||||
- **No `#ifdef XRPL_ENABLE_TELEMETRY` guards**: Members use `std::optional<SpanGuard>`
|
||||
and `SpanContext` which have no-op implementations when telemetry is disabled,
|
||||
so `#ifdef` guards are unnecessary. The members are always present in the class
|
||||
layout but incur negligible overhead.
|
||||
|
||||
- Includes added unconditionally to `Consensus.h`:
|
||||
```cpp
|
||||
#include <xrpl/telemetry/SpanGuard.h>
|
||||
#include <xrpld/app/consensus/ConsensusSpanNames.h>
|
||||
```
|
||||
No `TracingInstrumentation.h` include (file doesn't exist; macros not used).
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/consensus/Consensus.h`
|
||||
- `src/xrpld/app/consensus/RCLConsensus.h` (round span and context members)
|
||||
|
||||
---
|
||||
|
||||
## Task 4a.4: Instrument `phaseEstablish()` ✅
|
||||
|
||||
**Objective**: Create `consensus.establish` span wrapping the establish phase,
|
||||
with attributes for convergence progress.
|
||||
|
||||
**Status**: Done. Implemented via three private helpers in `Consensus.h`.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- `startEstablishTracing()` — creates `consensus.establish` span via
|
||||
`SpanGuard::span(TraceCategory::Consensus, seg::consensus, "establish")`.
|
||||
Called once at start of establish phase. No `#ifdef` guards needed —
|
||||
`SpanGuard::span()` returns a no-op guard when telemetry is disabled.
|
||||
|
||||
- `updateEstablishTracing()` — sets attributes on each `phaseEstablish()` call:
|
||||
- `converge_percent` — `convergePercent_`
|
||||
- `establish_count` — `establishCounter_`
|
||||
- `proposers` — `currPeerPositions_.size()`
|
||||
|
||||
- `endEstablishTracing()` — calls `establishSpan_.reset()` on phase exit.
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/consensus/Consensus.h` — `phaseEstablish()` method + 3 helper methods
|
||||
|
||||
---
|
||||
|
||||
## Task 4a.5: Instrument `updateOurPositions()` ✅
|
||||
|
||||
**Objective**: Trace each position update cycle including dispute resolution
|
||||
details.
|
||||
|
||||
**Status**: DONE. Span, dispute events with yays/nays, and disputes_count attribute are all implemented.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- Creates `consensus.update_positions` scoped span via
|
||||
`SpanGuard::span(TraceCategory::Consensus, seg::consensus, "update_positions")`:
|
||||
|
||||
```cpp
|
||||
auto span = SpanGuard::span(TraceCategory::Consensus, seg::consensus, "update_positions");
|
||||
```
|
||||
|
||||
- Attributes set:
|
||||
- `converge_percent` — current convergence
|
||||
- `proposers` — `currPeerPositions_.size()`
|
||||
- `have_close_time_consensus` — close time consensus state
|
||||
- `close_time_threshold` — `avCT_CONSENSUS_PCT`
|
||||
- `disputes_count` — number of active disputes
|
||||
|
||||
- Dispute events recorded via direct `span.addEvent()` call with yays/nays:
|
||||
```cpp
|
||||
span.addEvent(
|
||||
"dispute.resolve",
|
||||
{{consensus::span::attr::txId, to_string(txId)},
|
||||
{consensus::span::attr::disputeOurVote, dispute.getOurVote() ? "yes" : "no"},
|
||||
{consensus::span::attr::disputeYays, std::to_string(dispute.getYays())},
|
||||
{consensus::span::attr::disputeNays, std::to_string(dispute.getNays())}});
|
||||
```
|
||||
|
||||
**Not implemented**:
|
||||
|
||||
- `proposers_agreed` / `proposers_total` attributes — not set
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/consensus/Consensus.h` — `updateOurPositions()` method
|
||||
- `src/xrpld/consensus/DisputedTx.h` — added `getYays()` / `getNays()` (currently unused)
|
||||
|
||||
---
|
||||
|
||||
## Task 4a.6: Instrument `haveConsensus()` (Threshold & Convergence) ✅
|
||||
|
||||
**Objective**: Trace consensus checking including threshold escalation.
|
||||
|
||||
**Status**: DONE. The `consensus.check` span is created with all planned attributes
|
||||
including the avalanche threshold.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- Creates `consensus.check` scoped span via
|
||||
`SpanGuard::span(TraceCategory::Consensus, seg::consensus, "check")`:
|
||||
|
||||
```cpp
|
||||
auto span = SpanGuard::span(TraceCategory::Consensus, seg::consensus, "check");
|
||||
```
|
||||
|
||||
- Attributes set:
|
||||
- `agree_count` — peers that agree with our position
|
||||
- `disagree_count` — peers that disagree
|
||||
- `converge_percent` — convergence percentage
|
||||
- `have_close_time_consensus` — close time consensus state
|
||||
- `threshold_percent` — set to `avCT_CONSENSUS_PCT` (75%)
|
||||
- `consensus_result` — "yes", "no", or "moved_on"
|
||||
- `avalanche_threshold` — the escalated weight from `getNeededWeight()` on the `consensus.update_positions` span
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/consensus/Consensus.h` — `haveConsensus()` method
|
||||
|
||||
---
|
||||
|
||||
## Task 4a.7: Instrument Mode Changes ✅
|
||||
|
||||
**Objective**: Trace consensus mode transitions (proposing ↔ observing,
|
||||
wrongLedger, switchedLedger).
|
||||
|
||||
**Status**: Done.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- In `RCLConsensus::Adaptor::onModeChange()`, creates a scoped span via direct
|
||||
`SpanGuard::span()` call:
|
||||
|
||||
```cpp
|
||||
auto span = telemetry::SpanGuard::span(
|
||||
telemetry::TraceCategory::Consensus, telemetry::seg::consensus, "mode_change");
|
||||
span.setAttribute(consensus::span::attr::modeOld, to_string(before).c_str()); // "mode_old"
|
||||
span.setAttribute(consensus::span::attr::modeNew, to_string(after).c_str()); // "mode_new"
|
||||
```
|
||||
|
||||
- `MonitoredMode::set()` in `Consensus.h` calls `adaptor_.onModeChange(before, after)`.
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp` — `onModeChange()`
|
||||
|
||||
---
|
||||
|
||||
## Task 4a.8: Reparent Existing Spans Under Round ✅
|
||||
|
||||
**Objective**: Make existing consensus spans (`consensus.accept`,
|
||||
`consensus.accept.apply`, `consensus.validation.send`) children of the
|
||||
`consensus.round` root span instead of being standalone.
|
||||
|
||||
**Status**: DONE. All three spans are now parented under the round span.
|
||||
|
||||
**What was done**:
|
||||
|
||||
- `consensus.validation.send` uses `SpanGuard::linkedSpan()` to create a
|
||||
follows-from link to `roundSpanContext_`. This is thread-safe because
|
||||
`roundSpanContext_` is a lightweight `SpanContext` snapshot captured on the
|
||||
consensus thread and read on the jtACCEPT worker thread.
|
||||
|
||||
- `consensus.accept` and `consensus.accept.apply` now use
|
||||
`SpanGuard::childSpan(name, roundSpanContext_)` instead of `SpanGuard::span()`
|
||||
to explicitly parent under the round span context. This solves the cross-thread
|
||||
parenting problem:
|
||||
- `doAccept()` runs on the jtACCEPT worker thread (not the consensus thread)
|
||||
- `childSpan()` explicitly passes the parent context, bypassing OTel's
|
||||
thread-local context propagation
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `src/xrpld/app/consensus/RCLConsensus.cpp`
|
||||
|
||||
---
|
||||
|
||||
## Task 4a.9: Build Verification and Testing ✅
|
||||
|
||||
**Objective**: Verify all Phase 4a changes compile cleanly with telemetry ON
|
||||
and OFF, and don't affect consensus timing.
|
||||
|
||||
**What to do**:
|
||||
|
||||
1. Build with `telemetry=ON` — verify no compilation errors
|
||||
2. Build with `telemetry=OFF` — verify `SpanGuard` compiles to no-ops
|
||||
3. Run existing consensus unit tests
|
||||
4. Verify `SpanGuard` / `SpanContext` members have negligible overhead when disabled
|
||||
5. Run `pccl` pre-commit checks
|
||||
|
||||
**Verification Checklist**:
|
||||
|
||||
- [x] Build succeeds with telemetry ON
|
||||
- [x] Build succeeds with telemetry OFF
|
||||
- [x] Existing consensus tests pass
|
||||
- [x] `SpanGuard` no-op path verified (no `#ifdef` needed — disabled at runtime)
|
||||
- [x] No new virtual calls in hot consensus paths
|
||||
- [x] `pccl` passes
|
||||
|
||||
---
|
||||
|
||||
## Phase 4a Summary
|
||||
|
||||
| Task | Description | Status | New Files | Modified Files | Depends On |
|
||||
| ---- | ------------------------------------------------ | ------------------------ | --------- | -------------- | ---------- |
|
||||
| 4a.0 | Prerequisites: extend SpanGuard & Telemetry APIs | ✅ Done (no macros) | 0 | 2 | Phase 4 |
|
||||
| 4a.1 | Adaptor `getTelemetry()` method | ⏭️ Skipped (not needed) | 0 | 0 | Phase 4 |
|
||||
| 4a.2 | Switchable round span with deterministic traceID | ✅ Done | 1 | 3 | 4a.0 |
|
||||
| 4a.3 | Span members in `Consensus.h` | ✅ Done (with deviation) | 0 | 2 | — |
|
||||
| 4a.4 | Instrument `phaseEstablish()` | ✅ Done | 0 | 1 | 4a.3 |
|
||||
| 4a.5 | Instrument `updateOurPositions()` | ✅ Done | 0 | 2 | 4a.0, 4a.3 |
|
||||
| 4a.6 | Instrument `haveConsensus()` (thresholds) | ✅ Done | 0 | 1 | 4a.3 |
|
||||
| 4a.7 | Instrument mode changes | ✅ Done | 0 | 1 | — |
|
||||
| 4a.8 | Reparent existing spans under round | ✅ Done | 0 | 1 | 4a.0, 4a.2 |
|
||||
| 4a.9 | Build verification and testing | ✅ Done | 0 | 0 | 4a.0-4a.8 |
|
||||
|
||||
**Parallel work**: Tasks 4a.0 and 4a.1 can run in parallel. Tasks 4a.4, 4a.5, 4a.6, and 4a.7 can run in parallel after 4a.3 (and 4a.0 for 4a.5).
|
||||
|
||||
### New Spans (Phase 4a)
|
||||
|
||||
| Span Name | Location | Key Attributes (actually set) |
|
||||
| ---------------------------- | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| `consensus.round` | `RCLConsensus.cpp` | `xrpl.consensus.round_id`, `xrpl.consensus.ledger_id`, `xrpl.ledger.seq`, `xrpl.consensus.mode`, `trace_strategy` |
|
||||
| `consensus.phase.open` | `Consensus.h` | `start_reason`, `previous_close_agree`, `peer_positions_at_open`, `early_close_triggered` (at start); `open_duration_ms`, `peer_positions_at_close`, `tx_sets_acquired`, `close_reason`, `proposers_validated` (at close) |
|
||||
| `consensus.establish` | `Consensus.h` | `converge_percent`, `establish_count`, `proposers`, `disputes_count`, `close_time_avalanche_state` |
|
||||
| `consensus.update_positions` | `Consensus.h` | `converge_percent`, `proposers`, `have_close_time_consensus`, `close_time_threshold`, `disputes_count`, `avalanche_threshold` |
|
||||
| `consensus.check` | `Consensus.h` | `agree_count`, `disagree_count`, `converge_percent`, `have_close_time_consensus`, `threshold_percent`, `consensus_result` |
|
||||
| `consensus.mode_change` | `RCLConsensus.cpp` | `mode_old`, `mode_new` |
|
||||
|
||||
### New Events (Phase 4a)
|
||||
|
||||
| Event Name | Parent Span | Attributes (actually set) |
|
||||
| ----------------- | ---------------------------- | ---------------------------------------------------------------- |
|
||||
| `dispute.resolve` | `consensus.update_positions` | `xrpl.tx.id`, `dispute_our_vote`, `dispute_yays`, `dispute_nays` |
|
||||
| `tx.included` | `consensus.accept.apply` | `xrpl.tx.id` |
|
||||
|
||||
### New Attributes (Phase 4a)
|
||||
|
||||
```cpp
|
||||
// Round-level (on consensus.round) — ALL IMPLEMENTED
|
||||
"xrpl.consensus.round_id" = int64 // Consensus round number
|
||||
"xrpl.consensus.ledger_id" = string // previousLedger.id() hash
|
||||
"trace_strategy" = string // "deterministic" or "attribute"
|
||||
|
||||
// Establish-level — IMPLEMENTED
|
||||
"converge_percent" = int64 // Convergence % (0-100+)
|
||||
"establish_count" = int64 // Number of establish iterations
|
||||
"agree_count" = int64 // Peers that agree (haveConsensus)
|
||||
"disagree_count" = int64 // Peers that disagree
|
||||
"threshold_percent" = int64 // Current threshold (avCT_CONSENSUS_PCT = 75%)
|
||||
"consensus_result" = string // "yes", "no", "moved_on"
|
||||
"have_close_time_consensus" = bool // Close time consensus reached
|
||||
"close_time_threshold" = int64 // Close time voting threshold
|
||||
|
||||
// Establish-level — IMPLEMENTED
|
||||
"disputes_count" = int64 // Active disputes (on update_positions)
|
||||
"avalanche_threshold" = int64 // Escalated weight (on update_positions)
|
||||
|
||||
// Establish-level — NOT IMPLEMENTED
|
||||
// "proposers_agreed" = int64 // Peers agreeing with us — not set
|
||||
// "proposers_total" = int64 // Total peer positions — not set (not defined)
|
||||
|
||||
// Mode change — ALL IMPLEMENTED
|
||||
"mode_old" = string // Previous mode
|
||||
"mode_new" = string // New mode
|
||||
```
|
||||
|
||||
### Implementation Notes
|
||||
|
||||
- **No macros**: The planned `XRPL_TRACE_CONSENSUS`, `XRPL_TRACE_ADD_EVENT`, and
|
||||
`XRPL_TRACE_SET_ATTR` macros were not implemented. All consensus tracing uses
|
||||
`SpanGuard` factory methods (`span()`, `hashSpan()`, `linkedSpan()`) and direct
|
||||
method calls (`setAttribute()`, `addEvent()`). This avoids macro control-flow
|
||||
issues and is cleaner than the planned approach.
|
||||
- **Separation of concerns**: All non-trivial telemetry code extracted to private
|
||||
helpers (`startRoundTracing`, `createValidationSpan`, `startEstablishTracing`,
|
||||
`updateEstablishTracing`, `endEstablishTracing`). Business logic methods contain
|
||||
single-line calls to these helpers.
|
||||
- **Thread safety**: `createValidationSpan()` runs on the jtACCEPT worker thread.
|
||||
Instead of accessing `roundSpan_` across threads, a `roundSpanContext_` snapshot
|
||||
(lightweight `SpanContext` value type) is captured on the consensus thread in
|
||||
`startRoundTracing()` and read by `createValidationSpan()`. The job queue
|
||||
provides the happens-before guarantee.
|
||||
- **No `#ifdef` guards**: Span members use `std::optional<SpanGuard>` and `SpanContext`
|
||||
which have no-op implementations when telemetry is disabled. No `#ifdef XRPL_ENABLE_TELEMETRY`
|
||||
guards needed around members or includes.
|
||||
- **No `getTelemetry()` adaptor method**: `SpanGuard::span()` is a static factory that
|
||||
internally checks telemetry state, so `Consensus.h` doesn't need adaptor access
|
||||
for span creation. Only `RCLConsensus::Adaptor` accesses `app_.getTelemetry()` directly.
|
||||
- **Config validation**: `consensus_trace_strategy` is validated to be either
|
||||
`"deterministic"` or `"attribute"`, falling back to `"deterministic"` for
|
||||
unrecognised values.
|
||||
- **Plan deviation**: `roundSpan_` is stored in `RCLConsensus::Adaptor` (not
|
||||
`Consensus.h`) because the adaptor has access to telemetry config and can
|
||||
implement the deterministic trace ID strategy. `establishSpan_` is correctly
|
||||
in `Consensus.h` as planned.
|
||||
|
||||
---
|
||||
|
||||
# Phase 4b: Cross-Node Propagation (Future — Documentation Only)
|
||||
|
||||
> **Goal**: Wire `TraceContextPropagator` for P2P messages so that proposals
|
||||
> and validations carry trace context between nodes. This enables true
|
||||
> distributed tracing where a proposal sent by Node A creates a child span
|
||||
> on Node B.
|
||||
>
|
||||
> **Status**: NOT IMPLEMENTED. The protobuf fields and propagator class exist
|
||||
> but are not wired. This section documents the design for future work.
|
||||
|
||||
## Architecture
|
||||
|
||||
```
|
||||
Node A (proposing) Node B (receiving)
|
||||
───────────────── ──────────────────
|
||||
consensus.round consensus.round
|
||||
├── propose() ├── peerProposal()
|
||||
│ └── TraceContextPropagator │ └── TraceContextPropagator
|
||||
│ ::injectToProtobuf( │ ::extractFromProtobuf(
|
||||
│ TMProposeSet.trace_context) │ TMProposeSet.trace_context)
|
||||
│ │ └── span link → Node A's context
|
||||
└── validate() └── onValidation()
|
||||
└── inject into TMValidation └── extract from TMValidation
|
||||
```
|
||||
|
||||
## Wiring Points
|
||||
|
||||
| Message | Inject Location | Extract Location | Protobuf Field |
|
||||
| --------------- | ---------------------------------- | ----------------------------------- | -------------------------- |
|
||||
| `TMProposeSet` | `Adaptor::propose()` | `PeerImp::onMessage(TMProposeSet)` | field 1001: `TraceContext` |
|
||||
| `TMValidation` | `Adaptor::validate()` | `PeerImp::onMessage(TMValidation)` | field 1001: `TraceContext` |
|
||||
| `TMTransaction` | `NetworkOPs::processTransaction()` | `PeerImp::onMessage(TMTransaction)` | field 1001: `TraceContext` |
|
||||
|
||||
## Span Link Semantics
|
||||
|
||||
Received messages use **span links** (follows-from), NOT parent-child:
|
||||
|
||||
- The receiver's processing span links to the sender's context
|
||||
- This preserves each node's independent trace tree
|
||||
- Cross-node correlation visible via linked traces in Tempo/Jaeger
|
||||
|
||||
## Interaction with Deterministic Trace ID (Strategy A)
|
||||
|
||||
When using deterministic trace_id (Phase 4a default), cross-node spans already
|
||||
share the same trace_id. P2P propagation adds **span-level** linking:
|
||||
|
||||
- Without propagation: spans from different nodes appear in the same trace
|
||||
(same trace_id) but without parent-child or follows-from relationships.
|
||||
- With propagation: spans have explicit links showing which proposal/validation
|
||||
from Node A caused processing on Node B.
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Phase 4a (this task list) — establish phase tracing must be in place
|
||||
- `TraceContextPropagator` free functions (already exist in
|
||||
`include/xrpl/telemetry/TraceContextPropagator.h`)
|
||||
- Protobuf `TraceContext` message (already exists, field 1001)
|
||||
250
OpenTelemetryPlan/Phase5_taskList.md
Normal file
250
OpenTelemetryPlan/Phase5_taskList.md
Normal file
@@ -0,0 +1,250 @@
|
||||
# Phase 5: Documentation & Deployment Task List
|
||||
|
||||
> **Goal**: Production readiness — Grafana dashboards, spanmetrics pipeline, operator runbook, alert definitions, and final integration testing. This phase ensures the telemetry system is useful and maintainable in production.
|
||||
>
|
||||
> **Scope**: Grafana dashboard definitions, OTel Collector spanmetrics connector, Prometheus integration, alert rules, operator documentation, and production-ready Docker Compose stack.
|
||||
>
|
||||
> **Branch**: `pratik/otel-phase5-docs-deployment` (from `pratik/otel-phase4-consensus-tracing`)
|
||||
|
||||
> **Note on attribute names**: the `xrpl.<domain>.<field>` keys shown below
|
||||
> (including the collector spanmetrics dimension examples) are written in the
|
||||
> older dotted form for readability — it mirrors how the fully qualified
|
||||
> attribute reads in a Tempo trace view. The implemented keys follow the
|
||||
> convention in [CONTRIBUTING.md](../CONTRIBUTING.md#telemetry-span-attribute-naming)
|
||||
> (underscore form, e.g. `command`, `rpc_status`); the `*SpanNames.h` constants
|
||||
> are the single source of truth, and the real collector dimensions must use
|
||||
> those exact underscore keys (the CI naming check enforces this).
|
||||
|
||||
### Related Plan Documents
|
||||
|
||||
| Document | Relevance |
|
||||
| ---------------------------------------------------------------- | -------------------------------------------------------------------------- |
|
||||
| [07-observability-backends.md](./07-observability-backends.md) | Tempo setup (§7.1), Grafana dashboards (§7.6), alerts (§7.6.3) |
|
||||
| [05-configuration-reference.md](./05-configuration-reference.md) | Collector config (§5.5), production config (§5.5.2), Docker Compose (§5.6) |
|
||||
| [06-implementation-phases.md](./06-implementation-phases.md) | Phase 5 tasks (§6.6), definition of done (§6.11.5) |
|
||||
|
||||
---
|
||||
|
||||
## Task 5.1: Add Spanmetrics Connector to OTel Collector
|
||||
|
||||
**Objective**: Derive RED metrics (Rate, Errors, Duration) from trace spans automatically, enabling Grafana time-series dashboards.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Edit `docker/telemetry/otel-collector-config.yaml`:
|
||||
- Add `spanmetrics` connector:
|
||||
```yaml
|
||||
connectors:
|
||||
spanmetrics:
|
||||
histogram:
|
||||
explicit:
|
||||
buckets: [1ms, 5ms, 10ms, 25ms, 50ms, 100ms, 250ms, 500ms, 1s, 5s]
|
||||
dimensions:
|
||||
- name: command
|
||||
- name: rpc_status
|
||||
- name: consensus_phase
|
||||
- name: tx_type
|
||||
```
|
||||
- Add `prometheus` exporter:
|
||||
```yaml
|
||||
exporters:
|
||||
prometheus:
|
||||
endpoint: 0.0.0.0:8889
|
||||
```
|
||||
- Wire the pipeline:
|
||||
```yaml
|
||||
service:
|
||||
pipelines:
|
||||
traces:
|
||||
receivers: [otlp]
|
||||
processors: [batch]
|
||||
exporters: [debug, otlp/tempo, spanmetrics]
|
||||
metrics:
|
||||
receivers: [spanmetrics]
|
||||
exporters: [prometheus]
|
||||
```
|
||||
|
||||
- Edit `docker/telemetry/docker-compose.yml`:
|
||||
- Expose port `8889` on the collector for Prometheus scraping
|
||||
- Add Prometheus service
|
||||
- Add Prometheus as Grafana datasource
|
||||
|
||||
**Key modified files**:
|
||||
|
||||
- `docker/telemetry/otel-collector-config.yaml`
|
||||
- `docker/telemetry/docker-compose.yml`
|
||||
|
||||
**Key new files**:
|
||||
|
||||
- `docker/telemetry/prometheus.yml` (Prometheus scrape config)
|
||||
- `docker/telemetry/grafana/provisioning/datasources/prometheus.yaml`
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [POC_taskList.md §Next Steps](./POC_taskList.md) — Metrics pipeline for Grafana dashboards
|
||||
|
||||
---
|
||||
|
||||
## Task 5.2: Create Grafana Dashboards
|
||||
|
||||
**Objective**: Provide pre-built Grafana dashboards for RPC performance, transaction lifecycle, and consensus health.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Create `docker/telemetry/grafana/provisioning/dashboards/dashboards.yaml` (provisioning config)
|
||||
- Create dashboard JSON files:
|
||||
1. **RPC Performance Dashboard** (`rpc-performance.json`):
|
||||
- RPC request latency (p50/p95/p99) by command — histogram panel
|
||||
- RPC throughput (requests/sec) by command — time series
|
||||
- RPC error rate by command — bar gauge
|
||||
- Top slowest RPC commands — table
|
||||
|
||||
2. **Transaction Overview Dashboard** (`transaction-overview.json`):
|
||||
- Transaction processing rate — time series
|
||||
- Transaction latency distribution — histogram
|
||||
- Suppression rate (duplicates) — stat panel
|
||||
- Transaction processing path (sync vs async) — pie chart
|
||||
|
||||
3. **Consensus Health Dashboard** (`consensus-health.json`):
|
||||
- Consensus round duration — time series
|
||||
- Phase duration breakdown (open/establish/accept) — stacked bar
|
||||
- Proposals sent/received per round — stat panel
|
||||
- Consensus mode distribution (proposing/observing) — pie chart
|
||||
|
||||
- Store dashboards in `docker/telemetry/grafana/dashboards/`
|
||||
|
||||
**Key new files**:
|
||||
|
||||
- `docker/telemetry/grafana/provisioning/dashboards/dashboards.yaml`
|
||||
- `docker/telemetry/grafana/dashboards/rpc-performance.json`
|
||||
- `docker/telemetry/grafana/dashboards/transaction-overview.json`
|
||||
- `docker/telemetry/grafana/dashboards/consensus-health.json`
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [07-observability-backends.md §7.6](./07-observability-backends.md) — Grafana dashboard specifications
|
||||
- [01-architecture-analysis.md §1.8.3](./01-architecture-analysis.md) — Dashboard panel examples
|
||||
|
||||
---
|
||||
|
||||
## Task 5.3: Define Alert Rules
|
||||
|
||||
**Objective**: Create alert definitions for key telemetry anomalies.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Create `docker/telemetry/grafana/provisioning/alerting/alerts.yaml`:
|
||||
- **RPC Latency Alert**: p99 latency > 1s for any command over 5 minutes
|
||||
- **RPC Error Rate Alert**: Error rate > 5% for any command over 5 minutes
|
||||
- **Consensus Duration Alert**: Round duration > 10s (warn), > 30s (critical)
|
||||
- **Transaction Processing Alert**: Processing rate drops below threshold
|
||||
- **Telemetry Pipeline Health**: No spans received for > 2 minutes
|
||||
|
||||
**Key new files**:
|
||||
|
||||
- `docker/telemetry/grafana/provisioning/alerting/alerts.yaml`
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [07-observability-backends.md §7.6.3](./07-observability-backends.md) — Alert rule definitions
|
||||
|
||||
---
|
||||
|
||||
## Task 5.4: Production Collector Configuration
|
||||
|
||||
**Objective**: Create a production-ready OTel Collector configuration with tail-based sampling and resource limits.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Create `docker/telemetry/otel-collector-config-production.yaml`:
|
||||
- Tail-based sampling policy:
|
||||
- Always sample errors and slow traces
|
||||
- 10% base sampling rate for normal traces
|
||||
- Always sample first trace for each unique RPC command
|
||||
- Resource limits:
|
||||
- Memory limiter processor (80% of available memory)
|
||||
- Queued retry for export failures
|
||||
- TLS configuration for production endpoints
|
||||
- Health check endpoint
|
||||
|
||||
**Key new files**:
|
||||
|
||||
- `docker/telemetry/otel-collector-config-production.yaml`
|
||||
|
||||
**Reference**:
|
||||
|
||||
- [05-configuration-reference.md §5.5.2](./05-configuration-reference.md) — Production collector config
|
||||
|
||||
---
|
||||
|
||||
## Task 5.5: Operator Runbook
|
||||
|
||||
**Objective**: Create operator documentation for managing the telemetry system in production.
|
||||
|
||||
**What to do**:
|
||||
|
||||
- Create `docs/telemetry-runbook.md`:
|
||||
- **Setup**: How to enable telemetry in xrpld
|
||||
- **Configuration**: All config options with descriptions
|
||||
- **Collector Deployment**: Docker Compose vs. Kubernetes vs. bare metal
|
||||
- **Troubleshooting**: Common issues and resolutions
|
||||
- No traces appearing
|
||||
- High memory usage from telemetry
|
||||
- Collector connection failures
|
||||
- Sampling configuration tuning
|
||||
- **Performance Tuning**: Batch size, queue size, sampling ratio guidelines
|
||||
- **Upgrading**: How to upgrade OTel SDK and Collector versions
|
||||
|
||||
**Key new files**:
|
||||
|
||||
- `docs/telemetry-runbook.md`
|
||||
|
||||
---
|
||||
|
||||
## Task 5.6: Final Integration Testing
|
||||
|
||||
**Objective**: Validate the complete telemetry stack end-to-end.
|
||||
|
||||
**What to do**:
|
||||
|
||||
1. Start full Docker stack (Collector, Tempo, Grafana, Prometheus)
|
||||
2. Build xrpld with `telemetry=ON`
|
||||
3. Run in standalone mode with telemetry enabled
|
||||
4. Generate RPC traffic and verify traces in Tempo
|
||||
5. Verify dashboards populate in Grafana
|
||||
6. Verify alerts trigger correctly
|
||||
7. Test telemetry OFF path (no regressions)
|
||||
8. Run full test suite
|
||||
|
||||
**Verification Checklist**:
|
||||
|
||||
- [ ] Docker stack starts without errors
|
||||
- [ ] Traces appear in Tempo with correct hierarchy
|
||||
- [ ] Grafana dashboards show metrics derived from spans
|
||||
- [ ] Prometheus scrapes spanmetrics successfully
|
||||
- [ ] Alerts can be triggered by simulated conditions
|
||||
- [ ] Build succeeds with telemetry ON and OFF
|
||||
- [ ] Full test suite passes
|
||||
|
||||
---
|
||||
|
||||
## Summary
|
||||
|
||||
| Task | Description | New Files | Modified Files | Depends On |
|
||||
| ---- | ---------------------------------- | --------- | -------------- | ---------- |
|
||||
| 5.1 | Spanmetrics connector + Prometheus | 2 | 2 | Phase 4 |
|
||||
| 5.2 | Grafana dashboards | 4 | 0 | 5.1 |
|
||||
| 5.3 | Alert definitions | 1 | 0 | 5.1 |
|
||||
| 5.4 | Production collector config | 1 | 0 | Phase 4 |
|
||||
| 5.5 | Operator runbook | 1 | 0 | Phase 4 |
|
||||
| 5.6 | Final integration testing | 0 | 0 | 5.1-5.5 |
|
||||
|
||||
**Parallel work**: Tasks 5.1, 5.4, and 5.5 can run in parallel. Tasks 5.2 and 5.3 depend on 5.1. Task 5.6 depends on all others.
|
||||
|
||||
**Exit Criteria** (from [06-implementation-phases.md §6.11.5](./06-implementation-phases.md)):
|
||||
|
||||
- [ ] Dashboards deployed and showing data
|
||||
- [ ] Alerts configured and tested
|
||||
- [ ] Operator documentation complete
|
||||
- [ ] Production collector config ready
|
||||
- [ ] Full test suite passes
|
||||
240
OpenTelemetryPlan/secure-OTel.md
Normal file
240
OpenTelemetryPlan/secure-OTel.md
Normal file
@@ -0,0 +1,240 @@
|
||||
# Securing OpenTelemetry Against Trace Context Spoofing
|
||||
|
||||
> **Part of**: [OpenTelemetry Implementation Plan](./OpenTelemetryPlan.md) — see also [Design Decisions § Privacy](./02-design-decisions.md#244-privacy--sensitive-data-policy) (what we don't collect) and [Configuration Reference § 5.5](./05-configuration-reference.md#55-opentelemetry-collector-configuration) (collector base config).
|
||||
|
||||
Trace context spoofing (or poisoning) occurs when untrusted actors inject tampered or stale trace IDs into your system. If these requests are processed, the spans are appended to historical trace buckets, stretching trace durations, ruining p99 latency metrics, and breaking Grafana dashboards.
|
||||
|
||||
This guide outlines two categories of defense: mitigating tampered contexts and locking down the OpenTelemetry (OTel) Collector to trusted clients only.
|
||||
|
||||
---
|
||||
|
||||
## Part 1: Mitigating Tampered Trace Contexts
|
||||
|
||||
### 1. Perimeter Defense: Strip Headers at the API Gateway
|
||||
|
||||
The most effective way to prevent spoofing from external sources is to treat your API Gateway (Envoy, NGINX, AWS ALB) as a hard boundary. Strip incoming W3C tracing headers (`traceparent`, `tracestate`) from public traffic so the gateway is forced to generate a fresh, legitimate `trace_id`.
|
||||
|
||||
**NGINX Example (Stripping Headers):**
|
||||
|
||||
```nginx
|
||||
server {
|
||||
listen 80;
|
||||
|
||||
location / {
|
||||
# Clear out untrusted incoming trace headers
|
||||
proxy_set_header traceparent "";
|
||||
proxy_set_header tracestate "";
|
||||
|
||||
proxy_pass http://backend_service;
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
### **2. Timestamp-Anchored Trace IDs and OTTL Filtering**
|
||||
|
||||
If you use a custom trace ID generator that embeds a timestamp in the first few bytes (like AWS X-Ray or UUIDv7), you can use the OTel Collector's OpenTelemetry Transform Language (OTTL) to detect anomalies.
|
||||
**Collector Configuration (Conceptual OTTL Filter):**
|
||||
|
||||
```yaml
|
||||
processors:
|
||||
filter/stale_traces:
|
||||
error_mode: ignore
|
||||
traces:
|
||||
span:
|
||||
# Example: Drop spans where the start time is significantly different
|
||||
# from an expected parameter or embedded timestamp logic.
|
||||
# Note: Standard W3C trace IDs do not contain timestamps by default.
|
||||
- 'Keep out-of-bounds spans: time.sub(start_time, now()) > duration("1h")'
|
||||
```
|
||||
|
||||
## **Part 2: Restricting Access to the OTel Collector**
|
||||
|
||||
Locking down the Collector ensures that only authenticated, trusted clients can submit telemetry data.
|
||||
|
||||
### **Approach A: Network Layer Security (Kubernetes Network Policies)**
|
||||
|
||||
Ensure your Collector is not exposed to the public internet. If running in Kubernetes, use a NetworkPolicy to restrict ingress traffic to specific namespaces.
|
||||
**Kubernetes NetworkPolicy Example:**
|
||||
|
||||
```yaml
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: allow-internal-otel
|
||||
namespace: observability
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels:
|
||||
app: opentelemetry-collector
|
||||
policyTypes:
|
||||
- Ingress
|
||||
ingress:
|
||||
- from:
|
||||
- namespaceSelector:
|
||||
matchLabels:
|
||||
environment: production
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 4317 # gRPC
|
||||
- protocol: TCP
|
||||
port: 4318 # HTTP
|
||||
```
|
||||
|
||||
### **Approach B: Transport Layer Security (Mutual TLS / mTLS)**
|
||||
|
||||
Require clients to present a valid cryptographic certificate to connect to the Collector.
|
||||
**Collector Configuration (mTLS):**
|
||||
|
||||
```yaml
|
||||
receivers:
|
||||
otlp:
|
||||
protocols:
|
||||
grpc:
|
||||
endpoint: 0.0.0.0:4317
|
||||
tls:
|
||||
# Setting client_ca_file makes the collector require and verify a
|
||||
# client cert, rejecting connections without a trusted one.
|
||||
client_ca_file: /certs/client_ca.pem # CA that signs trusted client certs
|
||||
cert_file: /certs/collector.pem
|
||||
key_file: /certs/collector.key
|
||||
```
|
||||
|
||||
### **Approach C: Application Layer Authentication (Basic Auth Extension)**
|
||||
|
||||
Use the Collector's extension system to require an API key or Basic Auth credentials.
|
||||
**Collector Configuration (Basic Auth):**
|
||||
|
||||
```yaml
|
||||
extensions:
|
||||
basicauth/collector:
|
||||
htpasswd:
|
||||
inline: |
|
||||
# username:trusted-client, password:SecurePassword123
|
||||
trusted-client:$apr1$4v8p76o6$DMTX5Wv6uOmrFAZp2X1N1.
|
||||
|
||||
receivers:
|
||||
otlp:
|
||||
protocols:
|
||||
grpc:
|
||||
endpoint: 0.0.0.0:4317
|
||||
auth:
|
||||
authenticator: basicauth/collector
|
||||
|
||||
processors:
|
||||
batch:
|
||||
|
||||
exporters:
|
||||
otlp:
|
||||
endpoint: my-backend-storage:4317
|
||||
|
||||
service:
|
||||
extensions: [basicauth/collector]
|
||||
pipelines:
|
||||
traces:
|
||||
receivers: [otlp]
|
||||
processors: [batch]
|
||||
exporters: [otlp]
|
||||
```
|
||||
|
||||
**Client Setup (Environment Variables):**
|
||||
Developers must pass the authentication header using the standard OTel SDK environment variables:
|
||||
|
||||
```bash
|
||||
# Base64 encoded "trusted-client:SecurePassword123"
|
||||
export OTEL_EXPORTER_OTLP_HEADERS="Authorization=Basic dHJ1c3RlZC1jbGllbnQ6U2VjdXJlUGFzc3dvcmQxMjM="
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
Available routes to build on top of: https://github.com/XRPLF/rippled/pull/6425#discussion_r3234751995
|
||||
|
||||
---
|
||||
|
||||
# Analysis: Applying the Guide to xrpld
|
||||
|
||||
The guide above is written for HTTP-fronted web services. xrpld is a P2P node daemon, so the threat model and the applicable defenses differ. This section captures how each approach maps to xrpld and the chosen direction.
|
||||
|
||||
## Threat Model
|
||||
|
||||
xrpld has **two distinct attack surfaces**, not one. The original guide conflates them under "trace context spoofing"; for xrpld they need separate defenses.
|
||||
|
||||
| Surface | Attacker | Vector | Defense |
|
||||
| ----------------------------------------- | -------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------- |
|
||||
| **Collector ingress** (xrpld → collector) | Anyone who can reach `4317`/`4318` on the collector host | Forged OTLP traffic, telemetry exfiltration, DoS on collector | mTLS + network policy |
|
||||
| **Peer trace context** (peer → xrpld) | Malicious peer in the XRPL overlay | Crafted `protocol::TraceContext` field inside peer protobuf messages (TMTransaction, consensus, etc.) — used to forge `trace_id`/`span_id`, pollute p99, attach spans to historical traces | Validate + rate-limit at the receive boundary |
|
||||
|
||||
**Deployment context:** Across-network. xrpld nodes (potentially run by external operators or in different DCs) ship telemetry to a centrally-hosted collector across an untrusted network. The collector is NOT on the same host or private VPC as every node.
|
||||
|
||||
```
|
||||
┌── peer (untrusted) ── TMTransaction{trace_context} ──▶ xrpld
|
||||
│ │
|
||||
│ [validate + rate-limit]
|
||||
│ │
|
||||
│ ▼
|
||||
│ SpanGuard (clean)
|
||||
│ │
|
||||
│ │ OTLP/gRPC
|
||||
│ │ + mTLS
|
||||
│ ▼
|
||||
└───────────────────────────────────────── [client_ca_file: verify client cert]
|
||||
OTel Collector
|
||||
(in private subnet, NetPol)
|
||||
```
|
||||
|
||||
## Part 1 Applicability — Peer Trace-Context Validation
|
||||
|
||||
The guide's NGINX header stripping and OTTL stale-span filtering target HTTP gateways and post-hoc cleanup. Neither fits xrpld directly:
|
||||
|
||||
- **NGINX header stripping** — N/A. There is no HTTP gateway between peers and xrpld; trace context arrives inside protobuf peer messages (`protocol::TraceContext`), not as W3C `traceparent` headers. See [src/xrpld/telemetry/PropagationHelpers.h](../src/xrpld/telemetry/PropagationHelpers.h).
|
||||
- **OTTL stale-span filtering** — Weak fit. Post-hoc cleanup at the collector loses peer identity (you can't tell _which_ peer poisoned the trace). Validation at the receive site is stronger.
|
||||
|
||||
**xrpld-specific Part 1 mitigations:**
|
||||
|
||||
1. **Validate extracted context at the boundary** in [src/xrpld/telemetry/ConsensusReceiveTracing.h](../src/xrpld/telemetry/ConsensusReceiveTracing.h) and any other peer-message receive site. Reject if `trace_id` is all-zero, wrong length, or fails W3C format checks. Treat invalid context as "no propagated context" — start a fresh span — rather than dropping the message.
|
||||
2. **Per-peer sample rate limiting** so a hostile peer cannot flood the collector with spans bearing a fabricated `trace_id`. Use probabilistic sampling on the receive path keyed by peer identity.
|
||||
|
||||
## Part 2 — Comparison of Collector Hardening Approaches
|
||||
|
||||
Evaluated for the across-network deployment shape:
|
||||
|
||||
| Approach | Across-network fit | Cost | Verdict |
|
||||
| ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------- | ---------------------------------- |
|
||||
| **A. NetworkPolicy / firewall** | Necessary baseline (don't expose `4317`/`4318` to the internet), but insufficient on its own when traffic genuinely crosses networks — you cannot NetworkPolicy the public internet. | Cheap. | **Defense-in-depth, not primary.** |
|
||||
| **B. mTLS** | Strongest fit. Every xrpld node holds a client cert; the collector verifies it via `client_ca_file` in the receiver's `tls` block. Encrypts in transit (raw OTLP over the internet leaks transaction patterns and validator identity). Compromised node = revoke one cert, no shared secret to rotate everywhere. | Cert issuance + rotation pipeline. | **Primary.** |
|
||||
| **C. Basic Auth** | Worst shape for this topology. Single shared password across all xrpld nodes — one leaked node config compromises the whole fleet. Doesn't encrypt; you'd need TLS underneath anyway, at which point you're 80% of the way to mTLS. | Cheap to set up, expensive to operate (rotation across N operators). | **Skip.** |
|
||||
|
||||
## Decision
|
||||
|
||||
**Primary defense:** mTLS (Approach B) on the collector's OTLP receivers. The collector requires and verifies each client certificate when `client_ca_file` is set in the receiver's `tls` block (there is no `auth_type` field — setting `client_ca_file` is what enforces client-cert verification).
|
||||
|
||||
**Defense-in-depth:** NetworkPolicy / firewall rules (Approach A) so `4317`/`4318` are never reachable from outside the expected operator subnets even if mTLS were misconfigured.
|
||||
|
||||
**Skipped:** Basic Auth (Approach C) — wrong shape for an across-network, multi-operator topology.
|
||||
|
||||
**Plus xrpld-specific Part 1 work:** trace-context validation and per-peer rate limiting at peer-message receive sites.
|
||||
|
||||
## Decisions Made
|
||||
|
||||
| Decision | Choice | Rationale |
|
||||
| -------------------- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| Cert source for mTLS | **Reuse XRPL node identity key** | One identity per node, no separate PKI to operate. Fits XRPL's existing trust model; requires small CA tooling step to derive/sign the OTel client cert from the node key. |
|
||||
| Part 1 scope | **Include in this spec** | Collector hardening and peer trace-context validation share one threat model. Coherent design doc; can still be split into multiple PRs at implementation. |
|
||||
| Dev impact | **Production-only** | Local `docker/telemetry/docker-compose.yml` keeps `insecure: true` and no auth for fast iteration. Only production deployment manifests gain mTLS. Accepted risk: minor dev/prod drift, mitigated by integration tests against a TLS-enabled collector in CI. |
|
||||
|
||||
## Out of Scope
|
||||
|
||||
- NGINX/Envoy header stripping (no HTTP gateway in front of xrpld-to-collector traffic).
|
||||
- OTTL stale-span filtering at the collector (weaker than source validation; loses peer identity).
|
||||
- Local development docker-compose hardening.
|
||||
- Telemetry backend (Tempo) hardening — separate concern, downstream of the collector.
|
||||
|
||||
## Next Step
|
||||
|
||||
Write this up as a design doc with full sections covering:
|
||||
|
||||
1. Threat model & architecture (this section, expanded)
|
||||
2. Collector hardening — mTLS config, NetworkPolicy
|
||||
3. Cert pipeline — deriving OTel client cert from XRPL node key
|
||||
4. Peer trace-context validation — receive-site checks in `ConsensusReceiveTracing.h`
|
||||
5. Per-peer span rate limiting
|
||||
6. Testing & rollout
|
||||
@@ -1360,39 +1360,6 @@
|
||||
# Example:
|
||||
# owner_reserve = 200000 # 0.2 XRP
|
||||
#
|
||||
# gas_limit = <gas>
|
||||
#
|
||||
# The gas limit is the maximum amount of gas that can be
|
||||
# consumed by a single transaction. The gas limit is used to prevent
|
||||
# transactions from consuming too many resources.
|
||||
#
|
||||
# If this parameter is unspecified, xrpld will use an internal
|
||||
# default. Don't change this without understanding the consequences.
|
||||
#
|
||||
# Example:
|
||||
# gas_limit = 1000000 # 1 million gas
|
||||
#
|
||||
# bytecode_size_limit = <bytes>
|
||||
#
|
||||
# The bytecode size limit is the maximum size of a WASM extension in
|
||||
# bytes. The size limit is used to prevent extensions from consuming
|
||||
# too many resources.
|
||||
#
|
||||
# If this parameter is unspecified, xrpld will use an internal
|
||||
# default. Don't change this without understanding the consequences.
|
||||
#
|
||||
# Example:
|
||||
# bytecode_size_limit = 100000 # 100 kb
|
||||
#
|
||||
# gas_price = <micro-drops>
|
||||
#
|
||||
# The gas price is the conversion between WASM gas and its price in drops.
|
||||
#
|
||||
# If this parameter is unspecified, xrpld will use an internal
|
||||
# default. Don't change this without understanding the consequences.
|
||||
#
|
||||
# Example:
|
||||
# gas_price = 1000000 # 1 drop per gas
|
||||
#-------------------------------------------------------------------------------
|
||||
#
|
||||
# 9. Misc Settings
|
||||
@@ -1716,3 +1683,163 @@ validators.txt
|
||||
# set to ssl_verify to 0.
|
||||
[ssl_verify]
|
||||
1
|
||||
#-------------------------------------------------------------------------------
|
||||
#
|
||||
# 11. Telemetry (OpenTelemetry Tracing)
|
||||
#
|
||||
#-------------------------------------------------------------------------------
|
||||
#
|
||||
# Enables distributed tracing via OpenTelemetry. Requires building with
|
||||
# -DXRPL_ENABLE_TELEMETRY=ON (telemetry Conan option).
|
||||
#
|
||||
# [telemetry]
|
||||
#
|
||||
# enabled=0
|
||||
#
|
||||
# Enable or disable telemetry at runtime. Default: 0 (disabled).
|
||||
#
|
||||
# service_name=xrpld
|
||||
#
|
||||
# OTel resource attribute `service.name`. Default: xrpld.
|
||||
# The node's network ID (from [network_id]) is automatically added
|
||||
# as the `xrpl.network.id` and `xrpl.network.type` resource attributes.
|
||||
#
|
||||
# service_instance_id=<node_public_key>
|
||||
#
|
||||
# OTel resource attribute `service.instance.id`, which tells one node's
|
||||
# telemetry apart from another's. Normally left unset: the node identity
|
||||
# is not known when telemetry is constructed, so the server fills this in
|
||||
# with its own Base58 node public key later during startup. Set it only
|
||||
# to pin a stable instance name of your own choosing; doing so suppresses
|
||||
# the node-public-key fallback.
|
||||
# Default: the node's Base58 public key.
|
||||
#
|
||||
# traces_endpoint=http://localhost:4318/v1/traces
|
||||
#
|
||||
# The OTLP/HTTP endpoint spans are exported to. The server sends trace
|
||||
# data as protobuf-encoded HTTP POST requests to this URL. The full URL
|
||||
# including the signal path is used verbatim; no other endpoint is
|
||||
# derived from it.
|
||||
# Default: http://localhost:4318/v1/traces.
|
||||
#
|
||||
# The scheme of this URL is what decides whether the connection is
|
||||
# encrypted, and it is matched exactly: only a lower-case https:// URL
|
||||
# gives TLS. Because of that, setting tls_client_cert requires this URL
|
||||
# to start with https:// — including leaving it at the default above,
|
||||
# which makes xrpld fail to start rather than export without the client
|
||||
# identity it was configured with.
|
||||
#
|
||||
# --- TLS settings for the OTLP exporter connection ---
|
||||
#
|
||||
# use_tls=0
|
||||
#
|
||||
# Whether to hand tls_ca_cert to the exporter as its CA bundle. TLS is
|
||||
# selected by the scheme of traces_endpoint, not by this key; setting it
|
||||
# to 1 only supplies a custom CA file for verifying the collector.
|
||||
# Default: 0 (no CA file is passed, so the exporter keeps its own
|
||||
# default trust store).
|
||||
#
|
||||
# tls_ca_cert=
|
||||
#
|
||||
# Path to a PEM-encoded CA certificate bundle for verifying the
|
||||
# collector's certificate. Only used when use_tls=1, and passed to the
|
||||
# exporter unchanged. The path is not checked while the config is parsed,
|
||||
# so a missing or unreadable file surfaces as an export failure at
|
||||
# runtime rather than as a startup error.
|
||||
# Default: empty (system CA store).
|
||||
#
|
||||
# Leaving this empty stays valid and selects the system CA store. A path
|
||||
# that is set is checked like the client paths below: with enabled=1 and
|
||||
# use_tls=1, one that does not exist or cannot be read makes xrpld fail
|
||||
# to start.
|
||||
#
|
||||
# tls_client_cert=
|
||||
#
|
||||
# Path to this node's PEM-encoded client certificate, presented to the
|
||||
# collector for mutual TLS (mTLS). Requires use_tls=1. Leave empty
|
||||
# for one-way (server-only) TLS. Default: empty.
|
||||
#
|
||||
# To enable mTLS, both tls_client_cert and tls_client_key must be
|
||||
# specified. If only one is provided, xrpld will fail to start. Providing
|
||||
# them while use_tls=0 also fails to start, rather than being ignored.
|
||||
# traces_endpoint must be an https:// URL, because that scheme is what
|
||||
# makes the exporter present the certificate at all. With use_tls=1 each
|
||||
# path is opened at startup, so one that does not exist or cannot be read
|
||||
# fails to start too, rather than failing later as an opaque TLS
|
||||
# handshake error. All four checks apply only when enabled=1; with
|
||||
# telemetry disabled these settings are read but never validated.
|
||||
#
|
||||
# tls_client_key=
|
||||
#
|
||||
# Path to the PEM-encoded private key for tls_client_cert. Required
|
||||
# whenever tls_client_cert is set. Requires use_tls=1, and must be
|
||||
# readable. All three conditions are enforced exactly as described under
|
||||
# tls_client_cert above: when enabled=1, breaking any one of them makes
|
||||
# xrpld fail to start.
|
||||
# Default: empty.
|
||||
#
|
||||
# Head sampling is intentionally fixed at 1.0 (sample everything) and is
|
||||
# not configurable. A per-node sampling ratio would let nodes make
|
||||
# divergent keep/drop decisions for the same distributed trace, producing
|
||||
# broken/partial traces. A ParentBasedSampler ensures spans inheriting a
|
||||
# remote parent honor the upstream decision. Reduce volume at the collector
|
||||
# via tail sampling instead; for node-local post-hoc dropping use
|
||||
# SpanGuard::discard() in code.
|
||||
#
|
||||
# trace_rpc=1
|
||||
#
|
||||
# Enable tracing for JSON-RPC and WebSocket API request handling —
|
||||
# command parsing, execution, and response serialization. Default: 1.
|
||||
#
|
||||
# trace_transactions=1
|
||||
#
|
||||
# Enable tracing for the transaction lifecycle — submission, validation,
|
||||
# application to ledgers, and final disposition. Default: 1.
|
||||
#
|
||||
# trace_consensus=1
|
||||
#
|
||||
# Enable tracing for the consensus round lifecycle — proposals,
|
||||
# validations, mode changes, and ledger acceptance. Default: 1.
|
||||
#
|
||||
# trace_peer=1
|
||||
#
|
||||
# Enable tracing for peer-to-peer protocol messages — overlay message
|
||||
# send/receive, peer handshakes, and routing. High volume; enabled
|
||||
# by default. Default: 1.
|
||||
#
|
||||
# trace_ledger=1
|
||||
#
|
||||
# Enable tracing for ledger close and accept operations — ledger
|
||||
# building, state hashing, and write-back to the node store. Default: 1.
|
||||
#
|
||||
# consensus_trace_strategy=deterministic
|
||||
#
|
||||
# How the consensus round span picks its trace id. Two values are
|
||||
# accepted, and anything else makes xrpld fail to start.
|
||||
#
|
||||
# deterministic (the default, and the value to use): the trace id comes
|
||||
# from the previous ledger hash, so every validator of a round reports
|
||||
# into one trace and the round can be read end to end across nodes.
|
||||
#
|
||||
# random: experimental only, and not used. Each node invents its own
|
||||
# trace id, so a single round arrives as one separate trace per node.
|
||||
# Those traces can only be lined up by hand through the
|
||||
# consensus_ledger_id span attribute.
|
||||
#
|
||||
# --- Batch processor tuning ---
|
||||
#
|
||||
# batch_size=512
|
||||
#
|
||||
# Maximum number of spans exported in a single batch. Must be at least 1
|
||||
# and must not exceed max_queue_size. Default: 512.
|
||||
#
|
||||
# batch_delay_ms=5000
|
||||
#
|
||||
# Maximum delay (milliseconds) before a partial batch is flushed.
|
||||
# Must be at least 1. Default: 5000 (5 seconds).
|
||||
#
|
||||
# max_queue_size=2048
|
||||
#
|
||||
# Maximum number of spans queued in memory before drops occur. Must be
|
||||
# at least 1 and at least as large as batch_size. Default: 2048.
|
||||
#
|
||||
|
||||
@@ -69,8 +69,6 @@ target_link_libraries(
|
||||
Xrpl::opts
|
||||
Xrpl::syslibs
|
||||
secp256k1::secp256k1
|
||||
wasmi::wasmi
|
||||
NIH::dilithium2_ref
|
||||
xrpl.libpb
|
||||
xxHash::xxhash
|
||||
$<$<BOOL:${voidstar}>:antithesis-sdk-cpp>
|
||||
@@ -208,9 +206,32 @@ target_link_libraries(
|
||||
xrpl.libxrpl.conditions
|
||||
)
|
||||
|
||||
add_module(xrpl tx)
|
||||
target_link_libraries(xrpl.libxrpl.tx PUBLIC xrpl.libxrpl.ledger)
|
||||
# Telemetry module — OpenTelemetry distributed tracing support.
|
||||
# Sources: include/xrpl/telemetry/ (headers), src/libxrpl/telemetry/ (impl).
|
||||
# When telemetry=ON, links the Conan-provided umbrella target
|
||||
# opentelemetry-cpp::opentelemetry-cpp (individual component targets like
|
||||
# ::api, ::sdk are not available in the Conan package).
|
||||
#
|
||||
# Declared before its consumers (consensus, tx) because add_module isolates
|
||||
# each module's headers: a module can only include xrpl/telemetry/ headers if
|
||||
# it links this target, and the target must already exist at that point.
|
||||
#
|
||||
# Links xrpl.libxrpl.protocol PRIVATELY for sha512Half (digest.h)
|
||||
add_module(xrpl telemetry)
|
||||
target_link_libraries(
|
||||
xrpl.libxrpl.telemetry
|
||||
PUBLIC xrpl.libxrpl.basics xrpl.libxrpl.beast xrpl.libxrpl.config
|
||||
PRIVATE xrpl.libxrpl.protocol
|
||||
)
|
||||
if(telemetry)
|
||||
target_link_libraries(
|
||||
xrpl.libxrpl.telemetry
|
||||
PUBLIC opentelemetry-cpp::opentelemetry-cpp
|
||||
)
|
||||
endif()
|
||||
|
||||
# Links xrpl.libxrpl.telemetry for the consensus tracing spans declared in
|
||||
# include/xrpl/consensus/ConsensusSpanNames.h.
|
||||
add_module(xrpl consensus)
|
||||
target_link_libraries(
|
||||
xrpl.libxrpl.consensus
|
||||
@@ -219,6 +240,13 @@ target_link_libraries(
|
||||
xrpl.libxrpl.json
|
||||
xrpl.libxrpl.protocol
|
||||
xrpl.libxrpl.ledger
|
||||
xrpl.libxrpl.telemetry
|
||||
)
|
||||
|
||||
add_module(xrpl tx)
|
||||
target_link_libraries(
|
||||
xrpl.libxrpl.tx
|
||||
PUBLIC xrpl.libxrpl.ledger xrpl.libxrpl.telemetry
|
||||
)
|
||||
|
||||
add_library(xrpl.libxrpl)
|
||||
@@ -255,6 +283,7 @@ target_link_modules(
|
||||
resource
|
||||
server
|
||||
shamap
|
||||
telemetry
|
||||
tx
|
||||
)
|
||||
|
||||
|
||||
@@ -1,62 +0,0 @@
|
||||
include(FetchContent)
|
||||
|
||||
ExternalProject_Add(
|
||||
dilithium_src
|
||||
PREFIX ${nih_cache_path}
|
||||
# Pin to an explicit commit, not a moving branch ref. Bumping this SHA
|
||||
# is a supply-chain decision that must be reviewed; never revert to a
|
||||
# branch tag here. Upstream:
|
||||
# https://github.com/Transia-RnD/dilithium/commit/3032292cfd4d94e0df9bd49a0098669ca9166aa1
|
||||
GIT_REPOSITORY https://github.com/Transia-RnD/dilithium.git
|
||||
GIT_TAG 3032292cfd4d94e0df9bd49a0098669ca9166aa1
|
||||
GIT_SHALLOW FALSE
|
||||
CONFIGURE_COMMAND ""
|
||||
LOG_BUILD ON
|
||||
BUILD_IN_SOURCE 0
|
||||
BUILD_COMMAND
|
||||
COMMAND ${CMAKE_COMMAND} -E copy_directory <SOURCE_DIR>/ref <BINARY_DIR>/ref
|
||||
COMMAND make -C <BINARY_DIR>/ref clean
|
||||
COMMAND /bin/sh -c "CFLAGS='-DDILITHIUM_MODE=2 -DDILITHIUM_RANDOMIZED_SIGNING' make -C <BINARY_DIR>/ref libdilithium2_ref.a libfips202_ref.a"
|
||||
INSTALL_COMMAND ""
|
||||
BUILD_BYPRODUCTS
|
||||
<BINARY_DIR>/ref/libdilithium2_ref.a
|
||||
<BINARY_DIR>/ref/libfips202_ref.a
|
||||
)
|
||||
|
||||
ExternalProject_Get_Property(dilithium_src SOURCE_DIR BINARY_DIR)
|
||||
set(dilithium_src_SOURCE_DIR "${SOURCE_DIR}")
|
||||
set(dilithium_src_BINARY_DIR "${BINARY_DIR}")
|
||||
|
||||
# Include the reference implementation headers from source
|
||||
include_directories("${dilithium_src_SOURCE_DIR}/ref")
|
||||
|
||||
# Create imported targets for each static library using BINARY_DIR
|
||||
add_library(dilithium::dilithium2_ref STATIC IMPORTED GLOBAL)
|
||||
set_target_properties(dilithium::dilithium2_ref PROPERTIES
|
||||
IMPORTED_LOCATION "${dilithium_src_BINARY_DIR}/ref/libdilithium2_ref.a"
|
||||
INTERFACE_INCLUDE_DIRECTORIES "${dilithium_src_SOURCE_DIR}/ref/"
|
||||
)
|
||||
|
||||
add_library(dilithium::libfips202_ref STATIC IMPORTED GLOBAL)
|
||||
set_target_properties(dilithium::libfips202_ref PROPERTIES
|
||||
IMPORTED_LOCATION "${dilithium_src_BINARY_DIR}/ref/libfips202_ref.a"
|
||||
INTERFACE_INCLUDE_DIRECTORIES "${dilithium_src_SOURCE_DIR}/ref/"
|
||||
)
|
||||
|
||||
# Add dependencies to ensure the external project is built first
|
||||
add_dependencies(dilithium::dilithium2_ref dilithium_src)
|
||||
add_dependencies(dilithium::libfips202_ref dilithium_src)
|
||||
|
||||
# Note: We do NOT link the Dilithium library's randombytes.c because we provide
|
||||
# our own thread-safe implementation in src/libxrpl/protocol/SecretKey.cpp
|
||||
# that uses xrpld's crypto_prng() instead of direct /dev/urandom access.
|
||||
|
||||
# Create an interface library that links to the Dilithium libraries
|
||||
# Note: Link order matters - libraries that provide symbols must come AFTER libraries that use them
|
||||
target_link_libraries(xrpl_libs INTERFACE
|
||||
dilithium::dilithium2_ref
|
||||
dilithium::libfips202_ref
|
||||
)
|
||||
|
||||
# Create alias for convenience
|
||||
add_library(NIH::dilithium2_ref ALIAS dilithium::dilithium2_ref)
|
||||
@@ -61,8 +61,6 @@ SETTING_DEFAULTS = {
|
||||
"delegable": "Delegation::NotDelegable",
|
||||
"amendment": "uint256{}",
|
||||
"privileges": "Privilege::NoPriv",
|
||||
"emittance": "Emittance::Emitable",
|
||||
"firewall": "FirewallAction::Allow",
|
||||
}
|
||||
|
||||
|
||||
|
||||
15
conan.lock
15
conan.lock
@@ -3,7 +3,6 @@
|
||||
"requires": [
|
||||
"zlib/1.3.2#1cb806da49011867778ffb6ac7190fcb%1782392402.122708",
|
||||
"xxhash/0.8.3#681d36a0a6111fc56e5e45ea182c19cc%1782392402.420688",
|
||||
"wasmi/1.0.9#1fecdab9b90c96698eb35ea99ca4f5cb%1782307153.343419",
|
||||
"sqlite3/3.53.0#324ada52333108388a9a6108bfa96734%1782392403.185447",
|
||||
"soci/4.0.3#e726491a03468795453f7c83fc924a96%1782392402.679521",
|
||||
"snappy/1.1.10#968fef506ff261592ec30c574d4a7809%1782307151.633168",
|
||||
@@ -11,17 +10,20 @@
|
||||
"rocksdb/10.5.1#4a197eca381a3e5ae8adf8cffa5aacd0%1782392413.075713",
|
||||
"re2/20251105#8579cfd0bda4daf0683f9e3898f964b4%1782392402.431897",
|
||||
"protobuf/6.33.5#ff253ead763bd8d9904a52979cd21e81%1782392410.233933",
|
||||
"opentelemetry-cpp/1.28.0#2cbf71db4e0e0535df20be305005cb2f%1785939947.292581",
|
||||
"openssl/3.6.3#f806de8933e3bf6f01016c6a888cee2e%1783945160.863288",
|
||||
"nudb/2.0.9#11149c73f8f2baff9a0198fe25971fc7%1782392402.297166",
|
||||
"nlohmann_json/3.11.3#45828be26eb619a2e04ca517bb7b828d%1701220705.259",
|
||||
"mpt-crypto/1.0.2#b313cef0c1a493eb970ad185b2e9bab7%1784285108.866483",
|
||||
"lz4/1.10.0#982d9b673900f665a1da109e09c17cab%1782392402.164188",
|
||||
"libiconv/1.17#9923bc6dc6f106646d6967e0039a5ada%1782392792.775744",
|
||||
"libcurl/8.21.0#8c26e59c04891ba3373ea3552e18f67f%1783067699.863",
|
||||
"libbacktrace/cci.20210118#a7691bfccd8caaf66309df196790a5a1%1782392402.420732",
|
||||
"libarchive/3.8.7#c446109bd1f1d8ba7936c94189bc50e6%1782392403.066892",
|
||||
"jemalloc/5.3.1#1fc58d55316041f10fbc1e8a2eae632a%1776700028.228",
|
||||
"gtest/1.17.0#5224b3b3ff3b4ce1133cbdd27d53ee7d%1782392402.791979",
|
||||
"grpc/1.81.1#f729f6d75992d20f9c72828e9142d62f%1783945160.094135",
|
||||
"fast_float/8.2.10#f6f28d6bb22112078e7dbda611caf681%1782494504.298",
|
||||
"fast_float/8.2.10#f6f28d6bb22112078e7dbda611caf681%1785888854.601666",
|
||||
"ed25519/2015.03#ae761bdc52730a843f0809bdf6c1b1f6%1782307148.15562",
|
||||
"date/3.0.4#862e11e80030356b53c2c38599ceb32b%1782392402.538492",
|
||||
"corrosion/0.6.1#bfa292df0a957bc70a450ff316cd9435%1786119416.131296",
|
||||
@@ -35,9 +37,15 @@
|
||||
"zlib/1.3.2#1cb806da49011867778ffb6ac7190fcb%1782392402.122708",
|
||||
"strawberryperl/5.32.1.1#8d114504d172cfea8ea1662d09b6333e%1782395692.540639",
|
||||
"protobuf/6.33.5#ff253ead763bd8d9904a52979cd21e81%1782392410.233933",
|
||||
"pkgconf/2.5.1#93c2051284cba1279494a43a4fcfeae2%1757684701.089",
|
||||
"opentelemetry-proto/1.7.0#ed6d5bd761bef0afb0ba09676420b9ea%1749461220.268",
|
||||
"ninja/1.13.2#c8c5dc2a52ed6e4e42a66d75b4717ceb%1764096931.974",
|
||||
"nasm/2.16.01#31e26f2ee3c4346ecd347911bd126904%1782395690.33162",
|
||||
"msys2/cci.latest#d22fe7b2808f5fd34d0a7923ace9c54f%1770657326.649",
|
||||
"meson/1.10.2#9d2d10681fe7fe61c788c58626c89b25%1775558003.754",
|
||||
"m4/1.4.19#1727f439cf74e83826ec96d0b4904eee%1784541921.659",
|
||||
"libtool/2.4.7#14e7739cc128bc1623d2ed318008e47e%1755679003.847",
|
||||
"gnu-config/cci.20210814#466e9d4d7779e1c142443f7ea44b4284%1762363589.329",
|
||||
"cmake/4.3.3#840cf00ea09777e05c2050a50a82c722%1782392418.696091",
|
||||
"b2/5.4.2#ffd6084a119587e70f11cd45d1a386e2%1782392402.624226",
|
||||
"automake/1.16.5#b91b7c384c3deaa9d535be02da14d04f%1755524470.56",
|
||||
@@ -63,6 +71,9 @@
|
||||
],
|
||||
"lz4/[>=1.9.4 <2]": [
|
||||
"lz4/1.10.0#982d9b673900f665a1da109e09c17cab"
|
||||
],
|
||||
"protobuf/[>=4.25.3 <7]": [
|
||||
"protobuf/6.33.5#ff253ead763bd8d9904a52979cd21e81"
|
||||
]
|
||||
},
|
||||
"config_requires": []
|
||||
|
||||
@@ -58,3 +58,18 @@ tools.info.package_id:confs+=["user.package:cppstd_version"]
|
||||
{# Scoped to boost/* since it is the only gap. #}
|
||||
boost/*:MACOSX_DEPLOYMENT_TARGET={{ min_macos_version }}
|
||||
{% endif %}
|
||||
{% if compiler == "gcc" and compiler_version < 13 %}
|
||||
tools.build:cxxflags+=['-Wno-restrict']
|
||||
{% endif %}
|
||||
{% if os == "Windows" %}
|
||||
# opentelemetry-cpp's recipe removes the `shared` option on Windows and never
|
||||
# sets BUILD_SHARED_LIBS, so its upstream CMake defaults the protobuf-generated
|
||||
# `opentelemetry_proto` target to a DLL (opentelemetry_proto.dll). The rest of
|
||||
# the project links statically and nothing deploys that DLL next to the
|
||||
# executables, so the telemetry unit test fails to start with
|
||||
# STATUS_DLL_NOT_FOUND (0xC0000135). Force the dependency to build fully static
|
||||
# so no runtime DLL is produced. The conf is folded into the package id so a
|
||||
# fresh static binary is built instead of reusing a previously cached one.
|
||||
opentelemetry-cpp/*:tools.cmake.cmaketoolchain:extra_variables={"BUILD_SHARED_LIBS": "OFF"}
|
||||
opentelemetry-cpp/*:tools.info.package_id:confs+=["tools.cmake.cmaketoolchain:extra_variables"]
|
||||
{% endif %}
|
||||
|
||||
11
conanfile.py
11
conanfile.py
@@ -22,6 +22,7 @@ class Xrpl(ConanFile):
|
||||
"rocksdb": [True, False],
|
||||
"shared": [True, False],
|
||||
"static": [True, False],
|
||||
"telemetry": [True, False],
|
||||
"tests": [True, False],
|
||||
"unity": [True, False],
|
||||
"xrpld": [True, False],
|
||||
@@ -36,7 +37,6 @@ class Xrpl(ConanFile):
|
||||
"nudb/2.0.9",
|
||||
"openssl/3.6.3",
|
||||
"soci/4.0.3",
|
||||
"wasmi/1.0.9",
|
||||
"zlib/1.3.2",
|
||||
]
|
||||
|
||||
@@ -57,6 +57,7 @@ class Xrpl(ConanFile):
|
||||
"rocksdb": True,
|
||||
"shared": False,
|
||||
"static": True,
|
||||
"telemetry": True,
|
||||
"tests": False,
|
||||
"unity": False,
|
||||
"xrpld": False,
|
||||
@@ -147,6 +148,10 @@ class Xrpl(ConanFile):
|
||||
self.requires("rocksdb/10.5.1")
|
||||
self.requires("secp256k1/0.7.1", transitive_headers=True)
|
||||
self.requires("sqlite3/3.53.0", force=True)
|
||||
# OpenTelemetry C++ SDK for distributed tracing (optional).
|
||||
# Provides OTLP/HTTP exporter, batch span processor, and trace API.
|
||||
if self.options.telemetry:
|
||||
self.requires("opentelemetry-cpp/1.28.0")
|
||||
self.requires("xxhash/0.8.3", transitive_headers=True)
|
||||
|
||||
exports_sources = (
|
||||
@@ -176,6 +181,7 @@ class Xrpl(ConanFile):
|
||||
tc.variables["rocksdb"] = self.options.rocksdb
|
||||
tc.variables["BUILD_SHARED_LIBS"] = self.options.shared
|
||||
tc.variables["static"] = self.options.static
|
||||
tc.variables["telemetry"] = self.options.telemetry
|
||||
tc.variables["unity"] = self.options.unity
|
||||
tc.variables["xrpld"] = self.options.xrpld
|
||||
tc.generate()
|
||||
@@ -225,9 +231,10 @@ class Xrpl(ConanFile):
|
||||
"soci::soci",
|
||||
"secp256k1::secp256k1",
|
||||
"sqlite3::sqlite",
|
||||
"wasmi::wasmi",
|
||||
"xxhash::xxhash",
|
||||
"zlib::zlib",
|
||||
]
|
||||
if self.options.rocksdb:
|
||||
libxrpl.requires.append("rocksdb::librocksdb")
|
||||
if self.options.telemetry:
|
||||
libxrpl.requires.append("opentelemetry-cpp::opentelemetry-cpp")
|
||||
|
||||
@@ -1,25 +0,0 @@
|
||||
# Runtime image for the perf/test xrpld build with all amendments Supported::Yes.
|
||||
# Installs the .deb into ubuntu:jammy (matching rippleci/xrpld): gives
|
||||
# /usr/bin/xrpld, /etc/xrpld/xrpld.cfg, and the xrpld user.
|
||||
# NOT for production validators.
|
||||
ARG BASE_IMAGE=ubuntu:jammy
|
||||
FROM ${BASE_IMAGE}
|
||||
|
||||
# Build context must contain the supported package as xrpld.deb.
|
||||
COPY xrpld.deb /tmp/xrpld.deb
|
||||
|
||||
RUN set -eux; \
|
||||
apt-get update; \
|
||||
apt-get install -y --no-install-recommends ca-certificates jq /tmp/xrpld.deb; \
|
||||
rm -rf /var/lib/apt/lists/* /tmp/xrpld.deb; \
|
||||
id -u xrpld >/dev/null 2>&1 || \
|
||||
useradd --system --home-dir /var/lib/xrpld --shell /sbin/nologin --user-group xrpld; \
|
||||
mkdir -p /var/log/xrpld /var/lib/xrpld; \
|
||||
chown -R xrpld:xrpld /var/log/xrpld /var/lib/xrpld; \
|
||||
# Symlink for consumers that exec /opt/xrpld/bin/xrpld.
|
||||
mkdir -p /opt/xrpld/bin; \
|
||||
ln -sf /usr/bin/xrpld /opt/xrpld/bin/xrpld
|
||||
|
||||
EXPOSE 2459/tcp 5005/tcp 6006/tcp
|
||||
USER xrpld
|
||||
ENTRYPOINT ["/usr/bin/xrpld"]
|
||||
80
docker/telemetry/docker-compose.yml
Normal file
80
docker/telemetry/docker-compose.yml
Normal file
@@ -0,0 +1,80 @@
|
||||
# Docker Compose stack for xrpld OpenTelemetry observability.
|
||||
#
|
||||
# Provides services for local development:
|
||||
# - otel-collector: receives OTLP traces from xrpld, batches and
|
||||
# forwards them to Tempo. Listens on ports 4317 (gRPC)
|
||||
# and 4318 (HTTP).
|
||||
# - tempo: Grafana Tempo tracing backend, queryable via Grafana Explore
|
||||
# on port 3000. Recommended for production (S3/GCS storage, TraceQL).
|
||||
# - grafana: dashboards on port 3000, pre-configured with Tempo
|
||||
# datasource.
|
||||
#
|
||||
# Usage:
|
||||
# docker compose -f docker/telemetry/docker-compose.yml up -d
|
||||
#
|
||||
# Configure xrpld to export traces by adding to xrpld.cfg:
|
||||
# [telemetry]
|
||||
# enabled=1
|
||||
# traces_endpoint=http://localhost:4318/v1/traces
|
||||
|
||||
services:
|
||||
# OpenTelemetry Collector: receives spans from xrpld via OTLP protocol,
|
||||
# batches them for efficiency, and forwards to Tempo for storage.
|
||||
otel-collector:
|
||||
image: otel/opentelemetry-collector-contrib:0.158.0
|
||||
command: ["--config=/etc/otel-collector-config.yaml"]
|
||||
ports:
|
||||
- "4317:4317" # OTLP gRPC receiver
|
||||
- "4318:4318" # OTLP HTTP receiver (xrpld sends traces here)
|
||||
- "13133:13133" # Health check endpoint
|
||||
volumes:
|
||||
# Mount collector pipeline config (receivers → processors → exporters)
|
||||
- ./otel-collector-config.yaml:/etc/otel-collector-config.yaml:ro
|
||||
depends_on:
|
||||
- tempo
|
||||
networks:
|
||||
- xrpld-telemetry
|
||||
|
||||
# Grafana Tempo: distributed tracing backend that stores and indexes
|
||||
# spans. Queryable via TraceQL in Grafana Explore.
|
||||
tempo:
|
||||
image: grafana/tempo:2.9.4
|
||||
command: ["-config.file=/etc/tempo.yaml"]
|
||||
ports:
|
||||
- "3200:3200" # Tempo HTTP API (health check, query)
|
||||
volumes:
|
||||
# Mount Tempo storage and ingestion config
|
||||
- ./tempo.yaml:/etc/tempo.yaml:ro
|
||||
# Persistent volume for trace data (WAL + blocks)
|
||||
- tempo-data:/var/tempo
|
||||
networks:
|
||||
- xrpld-telemetry
|
||||
|
||||
# Grafana: visualization UI with Tempo pre-configured as a datasource.
|
||||
# Anonymous admin access enabled for local development convenience.
|
||||
grafana:
|
||||
image: grafana/grafana:13.1.2
|
||||
environment:
|
||||
- GF_AUTH_ANONYMOUS_ENABLED=true # No login required for local dev
|
||||
- GF_AUTH_ANONYMOUS_ORG_ROLE=Admin # Full access without auth
|
||||
ports:
|
||||
- "3000:3000" # Grafana web UI
|
||||
volumes:
|
||||
# Auto-provision Tempo datasource and search filters on startup
|
||||
- ./grafana/provisioning:/etc/grafana/provisioning:ro
|
||||
depends_on:
|
||||
- tempo
|
||||
networks:
|
||||
- xrpld-telemetry
|
||||
|
||||
# Named volume for Tempo trace storage (WAL and compacted blocks).
|
||||
# Data persists across container restarts. Remove with:
|
||||
# docker compose -f docker/telemetry/docker-compose.yml down -v
|
||||
volumes:
|
||||
tempo-data:
|
||||
|
||||
# Isolated bridge network so services communicate by container name
|
||||
# (e.g., the collector reaches Tempo at http://tempo:4317).
|
||||
networks:
|
||||
xrpld-telemetry:
|
||||
driver: bridge
|
||||
157
docker/telemetry/grafana/provisioning/datasources/tempo.yaml
Normal file
157
docker/telemetry/grafana/provisioning/datasources/tempo.yaml
Normal file
@@ -0,0 +1,157 @@
|
||||
# Grafana datasource provisioning for Grafana Tempo.
|
||||
# Auto-configures Tempo as a trace data source on Grafana startup.
|
||||
# Access Grafana at http://localhost:3000, then use Explore -> Tempo
|
||||
# to browse xrpld traces using TraceQL.
|
||||
#
|
||||
# Search filters provide pre-configured dropdowns in the Explore UI.
|
||||
# Each phase adds filters for the span attributes it introduces.
|
||||
# Base filters — node identity, service, span name, status.
|
||||
# RPC command, status, role filters.
|
||||
# Transaction hash, local/peer origin, status.
|
||||
# Consensus mode, round, ledger sequence, close time.
|
||||
|
||||
apiVersion: 1
|
||||
|
||||
datasources:
|
||||
- name: Tempo
|
||||
type: tempo
|
||||
access: proxy
|
||||
url: http://tempo:3200
|
||||
uid: tempo
|
||||
jsonData:
|
||||
nodeGraph:
|
||||
enabled: true
|
||||
# Service map and traces-to-metrics require a Prometheus datasource
|
||||
# (not included in this stack). These features are inactive until a
|
||||
# Prometheus service is added to docker-compose.yml.
|
||||
serviceMap:
|
||||
datasourceUid: prometheus
|
||||
tracesToMetrics:
|
||||
datasourceUid: prometheus
|
||||
spanStartTimeShift: "-1h"
|
||||
spanEndTimeShift: "1h"
|
||||
search:
|
||||
filters:
|
||||
# --- Node identification filters ---
|
||||
# service.name: logical service name (default: "xrpld").
|
||||
# Useful when running multiple service types in the same collector.
|
||||
- id: service-name
|
||||
tag: service.name
|
||||
operator: "="
|
||||
scope: resource
|
||||
type: dynamic
|
||||
# service.instance.id: unique node identifier — defaults to the
|
||||
# node's public key (e.g., nHB1X37...). Distinguishes individual
|
||||
# nodes in a multi-node cluster or network.
|
||||
- id: node-id
|
||||
tag: service.instance.id
|
||||
operator: "="
|
||||
scope: resource
|
||||
type: dynamic
|
||||
# service.version: xrpld build version (e.g., "2.4.0-b1").
|
||||
# Filter traces from specific software releases.
|
||||
- id: node-version
|
||||
tag: service.version
|
||||
operator: "="
|
||||
scope: resource
|
||||
type: dynamic
|
||||
# xrpl.network.id: numeric network identifier
|
||||
# (0 = mainnet, 1 = testnet, 2 = devnet, etc.).
|
||||
# Derived from the [network_id] config section.
|
||||
- id: network-id
|
||||
tag: xrpl.network.id
|
||||
operator: "="
|
||||
scope: resource
|
||||
type: dynamic
|
||||
# xrpl.network.type: human-readable network name derived from
|
||||
# network ID ("mainnet", "testnet", "devnet", "unknown").
|
||||
- id: network-type
|
||||
tag: xrpl.network.type
|
||||
operator: "="
|
||||
scope: resource
|
||||
type: dynamic
|
||||
# --- Span intrinsic filters ---
|
||||
# name: the span operation name (e.g., "rpc.command.server_info").
|
||||
# Use to find traces for a specific RPC command or subsystem.
|
||||
- id: span-name
|
||||
tag: name
|
||||
operator: "="
|
||||
scope: intrinsic
|
||||
type: dynamic
|
||||
# status: span completion status ("ok", "error", "unset").
|
||||
# Filter for failed operations to diagnose errors.
|
||||
- id: span-status
|
||||
tag: status
|
||||
operator: "="
|
||||
scope: intrinsic
|
||||
type: dynamic
|
||||
# duration: span wall-clock duration. Use with ">" operator
|
||||
# to find slow operations (e.g., duration > 500ms).
|
||||
- id: span-duration
|
||||
tag: duration
|
||||
operator: ">"
|
||||
scope: intrinsic
|
||||
type: dynamic
|
||||
# RPC tracing filters
|
||||
- id: rpc-command
|
||||
tag: command
|
||||
operator: "="
|
||||
scope: span
|
||||
type: dynamic
|
||||
- id: rpc-status
|
||||
tag: rpc_status
|
||||
operator: "="
|
||||
scope: span
|
||||
type: dynamic
|
||||
- id: rpc-role
|
||||
tag: rpc_role
|
||||
operator: "="
|
||||
scope: span
|
||||
type: dynamic
|
||||
# Transaction tracing filters
|
||||
- id: tx-hash
|
||||
tag: tx_hash
|
||||
operator: "="
|
||||
scope: span
|
||||
type: static
|
||||
- id: tx-origin
|
||||
tag: local
|
||||
operator: "="
|
||||
scope: span
|
||||
type: dynamic
|
||||
- id: tx-status
|
||||
tag: tx_status
|
||||
operator: "="
|
||||
scope: span
|
||||
type: dynamic
|
||||
# Consensus tracing filters
|
||||
- id: consensus-mode
|
||||
tag: consensus_mode
|
||||
operator: "="
|
||||
scope: span
|
||||
type: static
|
||||
- id: consensus-round
|
||||
tag: consensus_round
|
||||
operator: "="
|
||||
scope: span
|
||||
type: dynamic
|
||||
- id: consensus-ledger-seq
|
||||
tag: ledger_seq
|
||||
operator: "="
|
||||
scope: span
|
||||
type: static
|
||||
- id: consensus-close-time-correct
|
||||
tag: close_time_correct
|
||||
operator: "="
|
||||
scope: span
|
||||
type: static
|
||||
- id: consensus-state
|
||||
tag: consensus_state
|
||||
operator: "="
|
||||
scope: span
|
||||
type: static
|
||||
- id: consensus-close-resolution
|
||||
tag: close_resolution_ms
|
||||
operator: "="
|
||||
scope: span
|
||||
type: dynamic
|
||||
79
docker/telemetry/otel-collector-config.yaml
Normal file
79
docker/telemetry/otel-collector-config.yaml
Normal file
@@ -0,0 +1,79 @@
|
||||
# OpenTelemetry Collector configuration for xrpld development.
|
||||
#
|
||||
# Pipeline: OTLP receiver -> batch processor -> debug + Tempo.
|
||||
# xrpld sends traces via OTLP/HTTP to port 4318. The collector batches
|
||||
# them and forwards to Tempo via OTLP/gRPC on the Docker network. Tempo
|
||||
# is queryable via Grafana Explore using TraceQL.
|
||||
|
||||
receivers:
|
||||
otlp:
|
||||
protocols:
|
||||
grpc:
|
||||
endpoint: 0.0.0.0:4317
|
||||
http:
|
||||
endpoint: 0.0.0.0:4318
|
||||
|
||||
processors:
|
||||
batch:
|
||||
timeout: 1s
|
||||
send_batch_size: 100
|
||||
# Deployment-tier tagging. Each collector serves ONE environment and ONE
|
||||
# network, so it stamps both onto every signal it forwards. This lets a
|
||||
# single Grafana stack hold data from many collectors and filter by tier.
|
||||
# - deployment.environment: the collector IS the environment (local, ci,
|
||||
# test, prod), so it is authoritative -> upsert (overwrite).
|
||||
# - xrpl.network.type: the xrpld node knows its own chain and already
|
||||
# stamps this, so the collector only fills it when absent -> insert.
|
||||
# This keeps a node's real network (e.g. a local node on mainnet)
|
||||
# from being overwritten by a collector's default.
|
||||
# Replace the placeholder values per collector; see docker/telemetry
|
||||
# tier examples.
|
||||
resource/tier:
|
||||
attributes:
|
||||
- key: deployment.environment
|
||||
value: local
|
||||
action: upsert
|
||||
- key: xrpl.network.type
|
||||
value: mainnet
|
||||
action: insert
|
||||
# Strip SDK-injected resource attributes (telemetry.sdk.language/name/version).
|
||||
# The OpenTelemetry SDK auto-adds these to every Resource; they carry no
|
||||
# operational value and clutter the attribute set on every backend, so drop
|
||||
# them here for all signals.
|
||||
resource/stripsdk:
|
||||
attributes:
|
||||
- key: telemetry.sdk.language
|
||||
action: delete
|
||||
- key: telemetry.sdk.name
|
||||
action: delete
|
||||
- key: telemetry.sdk.version
|
||||
action: delete
|
||||
# Defense-in-depth: hash path-finding account attributes. The xrpld SDK
|
||||
# already hashes these before export, but a node that emitted raw values
|
||||
# is caught here so raw addresses never reach the backend.
|
||||
attributes/hash:
|
||||
actions:
|
||||
- key: pathfind_source_account
|
||||
action: hash
|
||||
- key: pathfind_dest_account
|
||||
action: hash
|
||||
|
||||
exporters:
|
||||
debug:
|
||||
verbosity: detailed
|
||||
otlp_grpc/tempo:
|
||||
endpoint: tempo:4317
|
||||
tls:
|
||||
insecure: true
|
||||
|
||||
extensions:
|
||||
health_check:
|
||||
endpoint: 0.0.0.0:13133
|
||||
|
||||
service:
|
||||
extensions: [health_check]
|
||||
pipelines:
|
||||
traces:
|
||||
receivers: [otlp]
|
||||
processors: [resource/tier, resource/stripsdk, attributes/hash, batch]
|
||||
exporters: [debug, otlp_grpc/tempo]
|
||||
61
docker/telemetry/tempo.yaml
Normal file
61
docker/telemetry/tempo.yaml
Normal file
@@ -0,0 +1,61 @@
|
||||
# Grafana Tempo configuration for xrpld telemetry stack.
|
||||
#
|
||||
# Runs in single-binary mode for local development.
|
||||
# Receives traces via OTLP/gRPC from the OTel Collector and stores
|
||||
# them locally. Queryable via Grafana Explore using the Tempo datasource.
|
||||
#
|
||||
# Search filters are configured on the Grafana datasource side
|
||||
# (grafana/provisioning/datasources/tempo.yaml). Tempo auto-indexes
|
||||
# all span attributes for search in single-binary mode.
|
||||
#
|
||||
# For production, replace local storage with S3/GCS backend and adjust
|
||||
# retention via the compactor settings. See:
|
||||
# https://grafana.com/docs/tempo/latest/configuration/
|
||||
|
||||
stream_over_http_enabled: true
|
||||
|
||||
server:
|
||||
http_listen_port: 3200
|
||||
|
||||
distributor:
|
||||
receivers:
|
||||
otlp:
|
||||
protocols:
|
||||
grpc:
|
||||
endpoint: 0.0.0.0:4317
|
||||
|
||||
ingester:
|
||||
max_block_duration: 5m
|
||||
|
||||
compactor:
|
||||
compaction:
|
||||
block_retention: 1h
|
||||
|
||||
# Enable metrics generator for service graph and span metrics.
|
||||
# Produces RED metrics (rate, errors, duration) per service/span,
|
||||
# feeding Grafana's service map visualization.
|
||||
metrics_generator:
|
||||
registry:
|
||||
external_labels:
|
||||
source: tempo
|
||||
storage:
|
||||
path: /var/tempo/generator/wal
|
||||
# Uncomment and add a Prometheus service to docker-compose.yml
|
||||
# to enable remote_write for service graph metrics:
|
||||
# remote_write:
|
||||
# - url: http://prometheus:9090/api/v1/write
|
||||
|
||||
overrides:
|
||||
defaults:
|
||||
metrics_generator:
|
||||
processors:
|
||||
- service-graphs
|
||||
- span-metrics
|
||||
|
||||
storage:
|
||||
trace:
|
||||
backend: local
|
||||
wal:
|
||||
path: /var/tempo/wal
|
||||
local:
|
||||
path: /var/tempo/blocks
|
||||
@@ -1,279 +0,0 @@
|
||||
# AMM Curve Implementation Template
|
||||
|
||||
Guide for adding a new curve type to the XRPL pluggable AMM curve framework.
|
||||
|
||||
## Architecture Overview
|
||||
|
||||
Each token pair can have **multiple AMM pools**, one per curve type. The keylet
|
||||
hash includes `curveType`, so `RLUSD/USD ConstantProduct` and `RLUSD/USD
|
||||
StableSwap` are separate ledger entries with separate pseudo-accounts and LP
|
||||
tokens. BookStep automatically routes through the deepest-liquidity pool.
|
||||
|
||||
### Key Components
|
||||
|
||||
| Component | File | Purpose |
|
||||
| --------------------- | --------------------------------------------------- | --------------------------------------- |
|
||||
| CurveInterface | `include/xrpl/ledger/helpers/AMMCurve.h` | Abstract base for all curves |
|
||||
| Curve implementations | `src/libxrpl/ledger/helpers/AMMCurve.cpp` | CP, CL, StableSwap, Weighted |
|
||||
| Tick math | `src/libxrpl/ledger/helpers/AMMTickMath.cpp` | CL tick/sqrt price conversions |
|
||||
| Fee collection | `src/libxrpl/tx/transactors/dex/AMMCollectFees.cpp` | CL position fee harvesting |
|
||||
| Multi-curve routing | `src/libxrpl/tx/paths/BookStep.cpp` | Picks best pool per pair |
|
||||
| Keylet hashing | `src/libxrpl/protocol/Indexes.cpp` | `amm(asset1, asset2, curveType)` |
|
||||
| LP token identity | `src/libxrpl/protocol/AMMCore.cpp` | `ammLPTCurrency(cur1, cur2, curveType)` |
|
||||
|
||||
## Step 1: Define the Curve Type
|
||||
|
||||
Add to `include/xrpl/protocol/AMMCore.h`:
|
||||
|
||||
```cpp
|
||||
enum CurveType : std::uint8_t
|
||||
{
|
||||
ctCONSTANT_PRODUCT = 0,
|
||||
ctCONCENTRATED_LIQUIDITY = 1,
|
||||
ctSTABLE_SWAP = 2,
|
||||
ctWEIGHTED = 3,
|
||||
ctYOUR_CURVE = N, // next available ID
|
||||
};
|
||||
```
|
||||
|
||||
## Step 2: Define SFields for Curve Parameters
|
||||
|
||||
Add to `include/xrpl/protocol/detail/sfields.macro`:
|
||||
|
||||
```cpp
|
||||
// Use the appropriate type (UINT8, UINT16, UINT32, UINT64, UINT256, AMOUNT, etc.)
|
||||
// Check existing field codes to avoid collisions.
|
||||
TYPED_SFIELD(sfYourParam, UINT32, <next_available_code>)
|
||||
```
|
||||
|
||||
## Step 3: Implement the CurveInterface
|
||||
|
||||
Add a new class in `src/libxrpl/ledger/helpers/AMMCurve.cpp`:
|
||||
|
||||
```cpp
|
||||
class YourCurve final : public CurveInterface
|
||||
{
|
||||
public:
|
||||
Expected<STAmount, TER>
|
||||
swapIn(
|
||||
STAmount const& poolIn,
|
||||
STAmount const& poolOut,
|
||||
STAmount const& assetIn,
|
||||
std::uint16_t tfee,
|
||||
STObject const* curveParams) const override
|
||||
{
|
||||
if (!curveParams)
|
||||
return Unexpected(tecINTERNAL);
|
||||
|
||||
auto const param = curveParams->getFieldU32(sfYourParam);
|
||||
|
||||
auto const f = feeMult(tfee); // fee multiplier (1 - fee)
|
||||
Number const x = poolIn; // STAmount -> Number via implicit conversion
|
||||
Number const y = poolOut;
|
||||
Number const dx = Number(assetIn) * f;
|
||||
|
||||
// --- YOUR INVARIANT MATH HERE ---
|
||||
// Compute output amount `dy` from your invariant
|
||||
// F(x, y) = k => F(x + dx, y - dy) = k => solve for dy
|
||||
Number const dy = /* ... */;
|
||||
|
||||
if (dy <= Number{0})
|
||||
return Unexpected(tecAMM_FAILED);
|
||||
|
||||
// Round output DOWN (favorable to pool)
|
||||
NumberRoundModeGuard const mg(Number::downward);
|
||||
return toSTAmount(poolOut.issue(), dy);
|
||||
}
|
||||
|
||||
Expected<STAmount, TER>
|
||||
swapOut(
|
||||
STAmount const& poolIn,
|
||||
STAmount const& poolOut,
|
||||
STAmount const& assetOut,
|
||||
std::uint16_t tfee,
|
||||
STObject const* curveParams) const override
|
||||
{
|
||||
if (!curveParams)
|
||||
return Unexpected(tecINTERNAL);
|
||||
|
||||
auto const param = curveParams->getFieldU32(sfYourParam);
|
||||
|
||||
auto const f = feeMult(tfee);
|
||||
Number const x = poolIn;
|
||||
Number const y = poolOut;
|
||||
|
||||
// --- YOUR INVARIANT MATH (INVERSE) ---
|
||||
// Given desired output, compute required input
|
||||
// F(x, y) = k => F(x + dx, y - assetOut) = k => solve for dx
|
||||
Number const dx = /* ... */ / f;
|
||||
|
||||
if (dx <= Number{0})
|
||||
return Unexpected(tecAMM_FAILED);
|
||||
|
||||
// Round input UP (favorable to pool)
|
||||
NumberRoundModeGuard const mg(Number::upward);
|
||||
return toSTAmount(poolIn.issue(), dx);
|
||||
}
|
||||
|
||||
Expected<Number, TER>
|
||||
spotPrice(
|
||||
STAmount const& poolIn,
|
||||
STAmount const& poolOut,
|
||||
std::uint16_t tfee,
|
||||
STObject const* curveParams) const override
|
||||
{
|
||||
if (!curveParams)
|
||||
return Unexpected(tecINTERNAL);
|
||||
|
||||
auto const param = curveParams->getFieldU32(sfYourParam);
|
||||
auto const f = feeMult(tfee);
|
||||
|
||||
// Marginal price: -dF/dx / dF/dy evaluated at current reserves
|
||||
// Divided by (1 - fee) for the taker-facing price
|
||||
Number const price = /* partial derivatives of your invariant */;
|
||||
return price / f;
|
||||
}
|
||||
|
||||
TER
|
||||
validateParams(STObject const& curveParams) const override
|
||||
{
|
||||
// Validate curve-specific parameters at pool creation
|
||||
if (!curveParams.isFieldPresent(sfYourParam))
|
||||
return temMALFORMED;
|
||||
|
||||
auto const param = curveParams.getFieldU32(sfYourParam);
|
||||
if (param < MIN_YOUR_PARAM || param > MAX_YOUR_PARAM)
|
||||
return temMALFORMED;
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
Expected<STAmount, TER>
|
||||
initialLPTokens(
|
||||
STAmount const& asset1,
|
||||
STAmount const& asset2,
|
||||
Issue const& lptIssue,
|
||||
STObject const* curveParams) const override
|
||||
{
|
||||
if (!curveParams)
|
||||
return Unexpected(tecINTERNAL);
|
||||
|
||||
// Compute initial LP token amount from deposits
|
||||
// For many curves: geometric mean sqrt(asset1 * asset2)
|
||||
// Or curve-specific: D for StableSwap, weighted geometric mean, etc.
|
||||
Number const lp = /* ... */;
|
||||
return toSTAmount(lptIssue, lp);
|
||||
}
|
||||
};
|
||||
```
|
||||
|
||||
## Step 4: Register the Singleton and Dispatch
|
||||
|
||||
In `AMMCurve.cpp`, add the singleton and switch case:
|
||||
|
||||
```cpp
|
||||
// At file scope (inside anonymous namespace)
|
||||
static YourCurve const yourCurve_;
|
||||
|
||||
// In getCurve():
|
||||
case ctYOUR_CURVE:
|
||||
if (rules.enabled(featureAMMCurves))
|
||||
return &yourCurve_;
|
||||
return nullptr;
|
||||
```
|
||||
|
||||
## Step 5: Update AMMCreate Validation
|
||||
|
||||
In `src/libxrpl/tx/transactors/dex/AMMCreate.cpp`:
|
||||
|
||||
1. Update the max curve type check: `if (curveType > ctYOUR_CURVE)`
|
||||
2. Add params setup in the `applyGuts` section:
|
||||
|
||||
```cpp
|
||||
else if (curveType == ctYOUR_CURVE)
|
||||
{
|
||||
ammSle->setFieldU32(
|
||||
sfYourParam, ctx_.tx.getFieldU32(sfYourParam));
|
||||
}
|
||||
```
|
||||
|
||||
## Step 6: Multi-Curve Routing (BookStep)
|
||||
|
||||
BookStep automatically discovers and routes through the best pool for each
|
||||
token pair. When a new curve type is added, update the loop upper bound in
|
||||
`src/libxrpl/tx/paths/BookStep.cpp`:
|
||||
|
||||
```cpp
|
||||
for (std::uint8_t ct = 0; ct <= ctYOUR_CURVE; ++ct)
|
||||
{
|
||||
auto const ammSle = ctx.view.read(keylet::amm(in, out, ct));
|
||||
if (!ammSle || ammSle->getFieldAmount(sfLPTokenBalance) == beast::zero)
|
||||
continue;
|
||||
if (!bestAmm ||
|
||||
ammSle->getFieldAmount(sfLPTokenBalance) >
|
||||
bestAmm->getFieldAmount(sfLPTokenBalance))
|
||||
bestAmm = ammSle;
|
||||
}
|
||||
```
|
||||
|
||||
The pool with the highest LP token balance wins. Curve-specific swap dispatch
|
||||
happens automatically via `getCurve()` in `AMMLiquidity`/`AMMOffer`.
|
||||
|
||||
## Step 7: Keylet and LP Token Identity
|
||||
|
||||
Each curve type for the same token pair gets a unique ledger key and LP token:
|
||||
|
||||
- **Keylet**: `keylet::amm(asset1, asset2, curveType)` hashes `curveType` into
|
||||
the AMM's ledger key (when curveType != 0, for backward compatibility)
|
||||
- **LP token**: `ammLPTCurrency(cur1, cur2, curveType)` hashes `curveType` into
|
||||
the LP token currency code
|
||||
|
||||
No changes needed here when adding a new curve — the default parameter
|
||||
propagates automatically.
|
||||
|
||||
## Concentrated Liquidity Extras
|
||||
|
||||
The CL curve type uses additional infrastructure not needed by other curves:
|
||||
|
||||
- **AMMTickMath** (`AMMTickMath.h/cpp`): `tickToSqrtPrice()`, `sqrtPriceToTick()`,
|
||||
`isValidTick()` for tick-based price representation
|
||||
- **AMMCollectFees** (`AMMCollectFees.h/cpp`): Transactor for position owners to
|
||||
collect accumulated swap fees using the Uniswap V3 fee growth formula
|
||||
- **Ledger entries**: `ltAMM_POSITION` (per-user tick range + liquidity) and
|
||||
`ltAMM_TICK` (per-tick fee growth and liquidity tracking)
|
||||
- **SFields**: `sfFeeGrowthGlobal0/1`, `sfFeeGrowthOutside0/1`,
|
||||
`sfFeeGrowthInsideLast0/1` (UINT256, Q128.128 fixed-point),
|
||||
`sfActiveLiquidity`, `sfPositionLiquidity`, `sfLiquidityGross/Net` (UINT64)
|
||||
|
||||
## Math Utilities Available
|
||||
|
||||
- `Number`: arbitrary-precision decimal arithmetic (see `include/xrpl/basics/Number.h`)
|
||||
- `power(f, n)`: f^n (integer exponent)
|
||||
- `power(f, n, d)`: f^(n/d) (rational exponent)
|
||||
- `root(f, d)`: f^(1/d)
|
||||
- `root2(f)`: sqrt(f)
|
||||
- `feeMult(tfee)`: returns `1 - fee` as Number
|
||||
- `feeMultHalf(tfee)`: returns `1 - fee/2` as Number
|
||||
- `toSTAmount(issue, number)`: convert Number to STAmount
|
||||
- `NumberRoundModeGuard`: RAII guard for rounding direction
|
||||
|
||||
## Rounding Convention
|
||||
|
||||
- `swapIn` output: round DOWN (pool keeps the rounding dust)
|
||||
- `swapOut` input: round UP (taker pays the rounding dust)
|
||||
- Use `NumberRoundModeGuard` to set the rounding mode before `toSTAmount()`
|
||||
|
||||
## Testing
|
||||
|
||||
Add tests in `src/test/app/AMMCurves_test.cpp`:
|
||||
|
||||
1. `swapIn` and `swapOut` are inverses (within rounding tolerance)
|
||||
2. Invariant is preserved: `F(reserves_new) >= F(reserves_old)` after every swap
|
||||
3. `spotPrice` matches actual swap rate at infinitesimal amounts
|
||||
4. Edge cases: zero input, max input, min reserves
|
||||
5. Parameter validation: `validateParams` rejects out-of-range values
|
||||
6. Integration: create pool, deposit, swap, withdraw full cycle
|
||||
|
||||
E2E tests go in `src/test/app/AMMCurvesE2E_test.cpp` for full transaction
|
||||
lifecycle tests (AMMCreate with curve params, swap through payment engine,
|
||||
deposit/withdraw).
|
||||
270
docs/build/telemetry.md
vendored
Normal file
270
docs/build/telemetry.md
vendored
Normal file
@@ -0,0 +1,270 @@
|
||||
# OpenTelemetry Tracing for xrpld
|
||||
|
||||
This document explains how to build xrpld with OpenTelemetry distributed tracing support, configure the runtime telemetry options, and set up the observability backend to view traces.
|
||||
|
||||
- [OpenTelemetry Tracing for xrpld](#opentelemetry-tracing-for-xrpld)
|
||||
- [Overview](#overview)
|
||||
- [Building with Telemetry](#building-with-telemetry)
|
||||
- [Summary](#summary)
|
||||
- [Build steps](#build-steps)
|
||||
- [Install dependencies](#install-dependencies)
|
||||
- [Call CMake](#call-cmake)
|
||||
- [Build](#build)
|
||||
- [Building without telemetry](#building-without-telemetry)
|
||||
- [Troubleshooting](#troubleshooting)
|
||||
- [Conan lockfile error](#conan-lockfile-error)
|
||||
- [CMake target not found](#cmake-target-not-found)
|
||||
- [Conditional compilation](#conditional-compilation)
|
||||
- [Span lifetime and cross-thread handling](#span-lifetime-and-cross-thread-handling)
|
||||
- [`SpanGuard` versus `ScopedSpanGuard`](#spanguard-versus-scopedspanguard)
|
||||
- [Coroutine-aware context storage](#coroutine-aware-context-storage)
|
||||
- [Handing a span to a job](#handing-a-span-to-a-job)
|
||||
- [Why are unrelated spans in my trace?](#why-are-unrelated-spans-in-my-trace)
|
||||
- [Injecting trace context into a protobuf message](#injecting-trace-context-into-a-protobuf-message)
|
||||
|
||||
## Overview
|
||||
|
||||
xrpld supports optional [OpenTelemetry](https://opentelemetry.io/) distributed tracing.
|
||||
When enabled, it instruments RPC requests with trace spans that are exported via
|
||||
OTLP/HTTP to an OpenTelemetry Collector, which forwards them to a tracing backend
|
||||
such as Grafana Tempo.
|
||||
|
||||
Telemetry is **off by default** at both compile time and runtime:
|
||||
|
||||
- **Compile time**: The Conan option `telemetry` and CMake option `telemetry` must be set to `True`/`ON`.
|
||||
When disabled, all `SpanGuard` calls compile to inline no-ops (defined in `SpanGuard.h`)
|
||||
with zero overhead — no OTel SDK dependency required.
|
||||
- **Runtime**: The `[telemetry]` config section must set `enabled=1`.
|
||||
When disabled at runtime, a no-op implementation is used.
|
||||
|
||||
## Building with Telemetry
|
||||
|
||||
### Summary
|
||||
|
||||
Follow the same instructions as mentioned in [BUILD.md](../../BUILD.md) but with the following changes:
|
||||
|
||||
1. Pass `-o telemetry=True` to `conan install` to pull the `opentelemetry-cpp` dependency.
|
||||
2. CMake will automatically pick up `telemetry=ON` from the Conan-generated toolchain.
|
||||
3. Build as usual.
|
||||
|
||||
---
|
||||
|
||||
### Build steps
|
||||
|
||||
```bash
|
||||
cd /path/to/xrpld
|
||||
rm -rf .build
|
||||
mkdir .build
|
||||
cd .build
|
||||
```
|
||||
|
||||
#### Install dependencies
|
||||
|
||||
The `telemetry` option adds `opentelemetry-cpp/1.28.0` as a dependency.
|
||||
If the Conan lockfile does not yet include this package, bypass it with `--lockfile=""`.
|
||||
|
||||
```bash
|
||||
conan install .. \
|
||||
--output-folder . \
|
||||
--build missing \
|
||||
--settings build_type=Debug \
|
||||
-o telemetry=True \
|
||||
-o tests=True \
|
||||
-o xrpld=True \
|
||||
--lockfile=""
|
||||
```
|
||||
|
||||
> **Note**: The first build with telemetry may take longer as `opentelemetry-cpp`
|
||||
> and its transitive dependencies are compiled from source.
|
||||
|
||||
#### Call CMake
|
||||
|
||||
The Conan-generated toolchain file sets `telemetry=ON` automatically.
|
||||
No additional CMake flags are needed beyond the standard ones.
|
||||
|
||||
```bash
|
||||
cmake .. -G Ninja \
|
||||
-DCMAKE_TOOLCHAIN_FILE:FILEPATH=build/generators/conan_toolchain.cmake \
|
||||
-DCMAKE_BUILD_TYPE=Debug \
|
||||
-Dtests=ON -Dxrpld=ON
|
||||
```
|
||||
|
||||
You should see in the CMake output:
|
||||
|
||||
```
|
||||
-- OpenTelemetry tracing enabled
|
||||
```
|
||||
|
||||
#### Build
|
||||
|
||||
```bash
|
||||
cmake --build . --parallel $(nproc)
|
||||
```
|
||||
|
||||
## Building without telemetry
|
||||
|
||||
Omit the `-o telemetry=True` option (or pass `-o telemetry=False`).
|
||||
The `opentelemetry-cpp` dependency will not be downloaded,
|
||||
the `XRPL_ENABLE_TELEMETRY` preprocessor define will not be set,
|
||||
and all tracing macros will compile to no-ops.
|
||||
The resulting binary is identical to one built before telemetry support was added.
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### Conan lockfile error
|
||||
|
||||
If you see `ERROR: Requirement 'opentelemetry-cpp/1.28.0' not in lockfile 'requires'`,
|
||||
the lockfile was generated without the telemetry dependency.
|
||||
Pass `--lockfile=""` to bypass the lockfile, or regenerate it with telemetry enabled.
|
||||
|
||||
### CMake target not found
|
||||
|
||||
If CMake reports that `opentelemetry-cpp` targets are not found,
|
||||
ensure you ran `conan install` with `-o telemetry=True` and that the
|
||||
Conan-generated toolchain file is being used.
|
||||
The Conan package provides a single umbrella target
|
||||
`opentelemetry-cpp::opentelemetry-cpp` (not individual component targets).
|
||||
|
||||
## Conditional compilation
|
||||
|
||||
All OpenTelemetry SDK types are hidden behind the pimpl idiom in `SpanGuard.cpp`. When `XRPL_ENABLE_TELEMETRY` is not defined, `SpanGuard.h` provides an all-inline no-op stub class with no OTel dependencies. At runtime, if `enabled=0` is set in config (or the section is omitted), a `NullTelemetry` implementation is used that returns no-op spans.
|
||||
|
||||
Those two layers remove the span, but they do **not** remove the work that computes what you pass to it. The compiled-out guards are ordinary inline functions with ordinary parameters, so every argument is evaluated before the empty body is entered:
|
||||
|
||||
```cpp
|
||||
// to_string() allocates a 64-character string even in a build with telemetry
|
||||
// compiled out. The call then does nothing with it.
|
||||
span.setAttribute(attr::txHash, to_string(txID).c_str());
|
||||
```
|
||||
|
||||
Guard the work, not just the call. Testing the guard is enough: its `operator bool()` is a literal `false` when telemetry is compiled out, so the whole block is eliminated, and when telemetry is compiled in it also skips the work if tracing is switched off in config or the span's category is disabled.
|
||||
|
||||
```cpp
|
||||
if (span)
|
||||
span.setAttribute(attr::txHash, to_string(txID).c_str());
|
||||
```
|
||||
|
||||
A span that exists but was sampled out still pays: there is no `isRecording()` to test.
|
||||
|
||||
The `XRPL_METRIC_*` macros are the opposite case. They expand to `do { } while (false)` and discard their arguments, so anything named only inside a macro argument list disappears on its own and needs no guard.
|
||||
|
||||
## Span lifetime and cross-thread handling
|
||||
|
||||
Telemetry exposes two RAII guards with split responsibilities, plus a
|
||||
non-owning activation helper. Picking the right one is what keeps a trace's
|
||||
parent/child nesting and its per-line log correlation correct.
|
||||
|
||||
### `SpanGuard` versus `ScopedSpanGuard`
|
||||
|
||||
- **`SpanGuard`** owns a span and nothing else. It is _thread-free_: it never
|
||||
touches the active-context stack, so it carries no thread affinity and may be
|
||||
moved to and ended on any thread. It is movable and move-assignable. Create
|
||||
one with `SpanGuard::span(cat, prefix, name)`, or with
|
||||
`SpanGuard::freshRoot(...)` to start a fresh trace root that ignores whatever
|
||||
span is currently ambient. Reach for a plain `SpanGuard` whenever the span
|
||||
must leave the context store that created it — for example when it is handed
|
||||
into a job.
|
||||
|
||||
- **`ScopedSpanGuard`** owns a `SpanGuard` _plus_ an active OTel scope that
|
||||
pushes the span onto the current context store. While it lives, the span is
|
||||
the ambient parent for child spans created on that store, and log lines
|
||||
emitted under it carry its `trace_id`. It is non-copyable and non-movable —
|
||||
short-lived stack RAII. It offers the same factories (`freshRoot(...)`,
|
||||
`childSpan(...)`). When the span must outlive the scope, convert it with
|
||||
`operator SpanGuard() &&`: that pops the scope on the origin store and yields
|
||||
the bare, thread-free `SpanGuard`.
|
||||
|
||||
Rule of thumb: use `ScopedSpanGuard` for same-thread (or same-coroutine)
|
||||
nesting and log correlation; use the plain `SpanGuard` whenever the span
|
||||
crosses out of the store that created it.
|
||||
|
||||
```mermaid
|
||||
flowchart TD
|
||||
SG["SpanGuard<br/>(unscoped, thread-free)<br/>owns span only; movable across threads and coroutines"]
|
||||
SSG["ScopedSpanGuard<br/>(scoped, store-bound)<br/>owns a SpanGuard plus an active scope on the current store"]
|
||||
SA["ScopedActivation<br/>(non-owning)<br/>activates a borrowed span; never owns or ends it"]
|
||||
|
||||
SSG -->|"handoff: pop scope, yield bare span"| SG
|
||||
SG -->|"activate / activateIfLive"| SA
|
||||
SA -.->|"borrows span, no ownership"| SG
|
||||
|
||||
classDef box fill:#e8f0fe,stroke:#3b5bdb,color:#111827;
|
||||
class SG,SSG,SA box;
|
||||
```
|
||||
|
||||
### Coroutine-aware context storage
|
||||
|
||||
The active-context stack is not a plain `thread_local`. At telemetry start
|
||||
xrpld installs `CoroAwareContextStorage`, which keeps the stack in an
|
||||
`xrpl::LocalValue`. Because `JobQueue::Coro::resume()` swaps the coroutine's
|
||||
`LocalValue` store in and out with the coroutine, the ambient context _follows
|
||||
the coroutine_ across every yield and resume — even when it resumes on a
|
||||
different worker thread. A `ScopedSpanGuard` held across a coroutine yield is
|
||||
therefore safe: its scope rides the coroutine and pops on the same store it was
|
||||
pushed onto, so it never pops the wrong stack. Off a coroutine the `LocalValue`
|
||||
transparently gives each thread its own store, so behaviour matches OTel's
|
||||
default thread-local storage. This is what lets the RPC entry, process, and
|
||||
command spans be scoped — for correct nesting and per-line log-trace
|
||||
correlation — even though the RPC path yields.
|
||||
|
||||
### Handing a span to a job
|
||||
|
||||
The hand-off pattern is: create a thread-free `SpanGuard` at the origin (or
|
||||
convert a `ScopedSpanGuard` with `operator SpanGuard() &&`), move it into the
|
||||
job closure, and inside the worker body activate it non-destructively with
|
||||
`telemetry::activateIfLive(handle)`. That call takes no ownership and returns a
|
||||
`ScopedActivation` (a no-op if the handle is empty or the span inactive) which
|
||||
makes the span the ambient context so log lines in the worker body carry its
|
||||
`trace_id`. The activation neither owns nor ends the span — the owning
|
||||
`SpanGuard` still controls its lifetime and ends it when the closure is
|
||||
destroyed. Keep the activation confined to a synchronous, non-yielding block.
|
||||
There is no detach step: a `SpanGuard` is already thread-free.
|
||||
|
||||
### Why are unrelated spans in my trace?
|
||||
|
||||
Historically a scoped guard destroyed off its origin thread popped the wrong
|
||||
context stack, leaving a stale ambient span in place that later work inherited.
|
||||
The current design removes that failure mode in two ways:
|
||||
|
||||
- **Coroutine-aware storage** makes a scope held across a coroutine yield pop on
|
||||
the same store it was pushed onto, so a coroutine that resumes on another
|
||||
worker never pops the wrong stack.
|
||||
|
||||
- **A same-store assertion** in `ScopedSpanGuard` (and `ScopedActivation`)
|
||||
records the `LocalValue` store its scope was pushed onto and checks, in
|
||||
debug/test/fuzzing builds, that destruction, hand-off, and discard all happen
|
||||
while that same store is active — turning a genuine cross-store misuse into an
|
||||
immediate assertion failure rather than a silently corrupted trace.
|
||||
|
||||
If a trace still shows unrelated spans nested under one operation, the usual
|
||||
cause is an inbound entry point that inherited an ambient parent it should not
|
||||
have. Start such an operation with `freshRoot()` so it begins a clean trace
|
||||
root and never adopts whatever span happened to be active. To move a span
|
||||
across a store boundary, keep it in a thread-free `SpanGuard` (or convert via
|
||||
`operator SpanGuard() &&`) rather than holding a `ScopedSpanGuard` across the
|
||||
boundary.
|
||||
|
||||
### Injecting trace context into a protobuf message
|
||||
|
||||
Pass the **whole message** to the injection helpers, never `*msg.mutable_trace_context()`.
|
||||
|
||||
On a protobuf `optional` submessage, `mutable_` allocates the submessage and sets its has-bit, and that happens at the call site before the helper runs. A caller that dereferences it therefore puts an empty `TraceContext` on the wire whenever nothing is recorded, and every receiving peer takes its `has_trace_context()` branch to extract nothing from it. `trace_context` is field 1001, so the wasted bytes are a 2-byte tag plus a zero length.
|
||||
|
||||
```cpp
|
||||
// Right: the helper decides whether the submessage is created at all.
|
||||
telemetry::injectSpanContext(span, msg);
|
||||
|
||||
// Wrong: the submessage exists before the helper can decide anything.
|
||||
telemetry::injectSpanContext(span, *msg.mutable_trace_context());
|
||||
```
|
||||
|
||||
`injectCurrentContext(msg)` does the same for whichever span is active on the calling thread, deciding via `SpanGuard::hasCurrentContext()`. Four states have to come out right:
|
||||
|
||||
| Build | Runtime | Result |
|
||||
| ------------ | ---------------- | -------------------------------------------------------------------- |
|
||||
| compiled out | n/a | no submessage; the bytes on the wire match a build without telemetry |
|
||||
| compiled in | a span is active | `trace_id`, `span_id` and the trace flags are written |
|
||||
| compiled in | no active span | no submessage, rather than an empty one |
|
||||
| compiled in | `enabled=0` | no submessage |
|
||||
|
||||
`hasCurrentContext()` reads the span straight out of the runtime context. `opentelemetry::trace::GetSpan()` would be shorter, but it returns a heap-allocated `DefaultSpan` when the context holds no span — an allocation in exactly the case the predicate exists to keep free.
|
||||
685
docs/telemetry-runbook.md
Normal file
685
docs/telemetry-runbook.md
Normal file
@@ -0,0 +1,685 @@
|
||||
# xrpld Telemetry Operator Runbook
|
||||
|
||||
## Overview
|
||||
|
||||
xrpld supports OpenTelemetry distributed tracing to provide visibility into RPC requests, transaction processing, and consensus rounds.
|
||||
|
||||
This runbook covers operating a running node and querying its traces. For
|
||||
building xrpld with telemetry support and the internal architecture, see
|
||||
[build/telemetry.md](build/telemetry.md).
|
||||
|
||||
## Quick Start
|
||||
|
||||
### 1. Start the observability stack
|
||||
|
||||
```bash
|
||||
docker compose -f docker/telemetry/docker-compose.yml up -d
|
||||
```
|
||||
|
||||
This starts:
|
||||
|
||||
- **OTel Collector** on ports 4317 (gRPC), 4318 (HTTP), and 13133 (health)
|
||||
- **Tempo** trace storage on http://localhost:3200
|
||||
- **Grafana** on http://localhost:3000 (Tempo pre-configured as datasource)
|
||||
|
||||
### 2. Enable telemetry in xrpld
|
||||
|
||||
Add to your `xrpld.cfg`:
|
||||
|
||||
```ini
|
||||
[telemetry]
|
||||
enabled=1
|
||||
traces_endpoint=http://localhost:4318/v1/traces
|
||||
```
|
||||
|
||||
### 3. Build with telemetry support
|
||||
|
||||
Follow [BUILD.md](../BUILD.md), adding `-o telemetry=True` so Conan pulls `opentelemetry-cpp`. From a build directory (`.build/`):
|
||||
|
||||
```bash
|
||||
conan install .. --output-folder . --build missing -o telemetry=True --settings build_type=Release
|
||||
cmake -DCMAKE_TOOLCHAIN_FILE:FILEPATH=build/generators/conan_toolchain.cmake -DCMAKE_BUILD_TYPE=Release -Dxrpld=ON -Dtelemetry=ON ..
|
||||
cmake --build . --target xrpld
|
||||
```
|
||||
|
||||
Conan also writes a `conan-release` CMake preset, so `cmake --preset conan-release -Dtelemetry=ON` works instead of the explicit toolchain line. There is no preset named `default`.
|
||||
|
||||
Both telemetry flags are the current default, so omitting them still gives you an instrumented build. Pass them anyway, so the build stays instrumented wherever the default moves.
|
||||
|
||||
## Configuration Reference
|
||||
|
||||
| Option | Default | Description |
|
||||
| -------------------------- | --------------------------------- | ----------------------------------------------------------------------------------------------------- |
|
||||
| `enabled` | `0` | Master switch for telemetry |
|
||||
| `traces_endpoint` | `http://localhost:4318/v1/traces` | Full OTLP/HTTP URL for spans, used verbatim |
|
||||
| `service_name` | `xrpld` | OpenTelemetry service name resource attribute |
|
||||
| `service_instance_id` | node public key | OpenTelemetry service instance ID resource attribute |
|
||||
| `trace_rpc` | `1` | Enable RPC request tracing |
|
||||
| `trace_transactions` | `1` | Enable transaction tracing |
|
||||
| `trace_consensus` | `1` | Enable consensus tracing |
|
||||
| `trace_peer` | `1` | Enable peer message tracing (high volume) |
|
||||
| `trace_ledger` | `1` | Enable ledger tracing |
|
||||
| `consensus_trace_strategy` | `deterministic` | Consensus trace ID strategy. `deterministic` is the value to use; `random` is experimental — see note |
|
||||
| `batch_size` | `512` | Max spans per batch export |
|
||||
| `batch_delay_ms` | `5000` | Delay between batch exports |
|
||||
| `max_queue_size` | `2048` | Max spans queued before dropping |
|
||||
| `use_tls` | `0` | Use TLS for exporter connection |
|
||||
| `tls_ca_cert` | (empty) | Path to CA certificate bundle |
|
||||
| `tls_client_cert` | (empty) | Client cert (PEM) for mTLS; empty = one-way. See note |
|
||||
| `tls_client_key` | (empty) | Private key (PEM) for `tls_client_cert`. See note |
|
||||
|
||||
> **mTLS (mutual TLS) note**: `tls_client_cert` and `tls_client_key` are optional — leaving both empty gives one-way (server-only) TLS. **If either one is set**, `enabled=1` requires both of them, `use_tls=1`, **and** a `traces_endpoint` starting with `https://` — the exporter decides encryption from the URL scheme, so the certificate is only ever presented on an `https://` endpoint. The default `traces_endpoint` is plain HTTP, so mTLS means setting that key too. Breaking any of these makes the node exit at startup; see the Troubleshooting entry for `Unable to start ...: [telemetry] ...`. When `enabled=0` they are read but never validated.
|
||||
|
||||
> **`consensus_trace_strategy` note**: only `deterministic` and `random` are accepted, and anything else makes the node exit at startup. Use `deterministic`: it seeds the round's trace ID from the previous ledger hash, so every validator of a round reports into one trace. `random` is experimental and not used — each node would invent its own trace ID, so a single round would arrive as one separate trace per node, joinable only by hand through `consensus_ledger_id`.
|
||||
|
||||
## Span Reference
|
||||
|
||||
All spans instrumented in xrpld, grouped by subsystem:
|
||||
|
||||
### RPC Spans
|
||||
|
||||
| Span Name | Source File | Attributes | Description |
|
||||
| -------------------- | ----------------- | ----------------------------------------------------------- | ----------------------------------------------------- |
|
||||
| `rpc.http_request` | ServerHandler.cpp | `request_payload_size` | Top-level HTTP RPC request |
|
||||
| `rpc.ws_upgrade` | ServerHandler.cpp | — | WebSocket upgrade handshake |
|
||||
| `rpc.ws_message` | ServerHandler.cpp | `command` | WebSocket RPC message |
|
||||
| `rpc.process` | ServerHandler.cpp | `is_batch`, `batch_size` | RPC processing (child of rpc.http_request/ws_message) |
|
||||
| `rpc.command.<name>` | RPCHandler.cpp | `command`, `version`, `rpc_role`, `rpc_status`, `load_type` | Per-command span (e.g., `rpc.command.server_info`) |
|
||||
|
||||
### Transaction Spans
|
||||
|
||||
| Span Name | Source File | Attributes | Description |
|
||||
| ------------ | -------------- | ------------------------------------------------------------------------------------------------------- | ------------------------------------- |
|
||||
| `tx.process` | NetworkOPs.cpp | `tx_hash`, `local`, `path`, `tx_type`, `fee`, `sequence`, `ter_result`, `applied`, `current_ledger_seq` | Transaction submission and processing |
|
||||
| `tx.receive` | PeerImp.cpp | `peer_id`, `tx_hash`, `tx_type`, `peer_version`, `suppressed`, `tx_status`, `current_ledger_seq` | Transaction received from peer relay |
|
||||
|
||||
`current_ledger_seq` is the current (open) ledger index at submit/receive time —
|
||||
the ledger being worked on, not an established one. It lets a transaction's
|
||||
lifecycle spans be joined to the ledger trace it targeted (`span.current_ledger_seq`).
|
||||
|
||||
### Transaction Queue Spans
|
||||
|
||||
| Span Name | Source File | Attributes | Description |
|
||||
| ------------------ | ----------- | ----------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| `txq.enqueue` | TxQ.cpp | `tx_hash`, `tx_type`, `current_ledger_seq`, `current_ledger_hash` | Enqueue decision; parents to `tx.process` on the submission path (explicit context), a root on the open-ledger rebuild path — `current_ledger_seq` correlates it to the ledger in both cases |
|
||||
| `txq.apply_direct` | TxQ.cpp | -- | Direct apply attempt (bypassing queue) |
|
||||
| `txq.batch_clear` | TxQ.cpp | -- | Batch clear of queued transactions for an account |
|
||||
| `txq.accept` | TxQ.cpp | `queue_size`, `ledger_changed` | Ledger-close accept loop over queued transactions |
|
||||
| `txq.accept_tx` | TxQ.cpp | `tx_hash`, `retries_remaining`, `ter_code`, `txq_status` | Per-transaction apply during accept |
|
||||
| `txq.cleanup` | TxQ.cpp | `ledger_seq` | Post-close cleanup of expired queue entries |
|
||||
|
||||
### PathFinding Spans
|
||||
|
||||
| Span Name | Source File | Attributes | Description |
|
||||
| --------------------- | --------------------------------- | -------------------------------------------------- | ------------------------------------------------------- |
|
||||
| `pathfind.request` | PathFind.cpp / RipplePathFind.cpp | `pathfind_source_account`, `pathfind_dest_account` | Path-find RPC entry (accounts hashed; set when present) |
|
||||
| `pathfind.compute` | PathRequest.cpp | `pathfind_fast`, `pathfind_dest_currency` | Path computation for one request (`doUpdate`) |
|
||||
| `pathfind.discover` | PathRequest.cpp | `pathfind_search_level`, `pathfind_num_paths` | Graph exploration (one per RPC call in `findPaths`) |
|
||||
| `pathfind.update_all` | PathRequestManager.cpp | `pathfind_ledger_index`, `pathfind_num_requests` | Async recomputation of active requests on ledger close |
|
||||
|
||||
### Consensus Spans
|
||||
|
||||
| Span Name | Source File | Attributes | Description |
|
||||
| ------------------------------ | ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| `consensus.round` | RCLConsensus.cpp | `consensus_ledger_id`, `ledger_seq`, `consensus_mode`, `trace_strategy`, `consensus_round_id` | Root span for a consensus round (deterministic or random trace ID) |
|
||||
| `consensus.phase.open` | Consensus.h | -- | Open phase duration (child of round) |
|
||||
| `consensus.proposal.send` | RCLConsensus.cpp | `consensus_round`, `is_bow_out` | Consensus proposal broadcast |
|
||||
| `consensus.ledger_close` | RCLConsensus.cpp | `ledger_seq`, `consensus_mode` | Ledger close event |
|
||||
| `consensus.establish` | Consensus.h | `converge_percent`, `establish_count`, `proposers`, `disputes_count` (all overwritten each iteration); `close_time_avalanche_state` (terminal regime, set once when the span ends) | Establish phase duration (child of round) |
|
||||
| `consensus.update_positions` | Consensus.h | `converge_percent`, `proposers`, `disputes_count` | Position update and dispute resolution (see Events below) |
|
||||
| `consensus.check` | Consensus.h | `agree_count`, `disagree_count`, `converge_percent`, `have_close_time_consensus`, `threshold_percent`, `proposers_finished`, `consensus_stalled`, `establish_count`, `consensus_result` | Consensus threshold check |
|
||||
| `consensus.accept` | RCLConsensus.cpp | `proposers`, `round_time_ms`, `quorum`, `disputes_count`, `consensus_state` | Ledger accepted by consensus |
|
||||
| `consensus.accept.apply` | RCLConsensus.cpp | `ledger_seq`, `close_time_ripple_epoch_s`, `close_time_correct`, `close_resolution_ms`, `consensus_state`, `proposing`, `round_time_ms`, `parent_close_time_ripple_epoch_s`, `close_time_self_ripple_epoch_s`, `close_time_vote_bins`, `resolution_direction`, `tx_count` | Ledger application with close time details (see Events below) |
|
||||
| `consensus.validation.send` | RCLConsensus.cpp | `ledger_seq`, `proposing`, `ledger_hash`, `full_validation`, `validation_sign_time` | Validation sent after accept (follows-from link) |
|
||||
| `consensus.mode_change` | RCLConsensus.cpp | `mode_old`, `mode_new` | Consensus mode transition |
|
||||
| `consensus.proposal.receive` | PeerImp.cpp | `proposal_trusted`, `consensus_round` | Proposal received from peer (extracts parent context from TraceContext when present; falls back to standalone span for older peers) |
|
||||
| `consensus.validation.receive` | PeerImp.cpp | `validation_trusted`, `ledger_seq` | Validation received from peer (extracts parent context from TraceContext when present; falls back to standalone span for older peers) |
|
||||
|
||||
#### Consensus Span Events
|
||||
|
||||
| Parent Span | Event Name | Event Attributes | Description |
|
||||
| ---------------------------- | ----------------- | ----------------------------------------------------------- | ------------------------------------------------------------------------------------------ |
|
||||
| `consensus.update_positions` | `dispute.resolve` | `tx_id`, `dispute_our_vote`, `dispute_yays`, `dispute_nays` | Emitted per dispute when votes are tallied |
|
||||
| `consensus.accept.apply` | `tx.included` | `tx_id` | Emitted per transaction of the agreed consensus set, before the ledger is built — see note |
|
||||
|
||||
> **`tx.included` note**: the event is recorded while the canonical transaction set is being assembled, which happens before `buildLCL()` applies anything. So a transaction that fails to apply, or is left over to retry in a later ledger, still has a `tx.included` event. Treat the events as the round's **input** set, not as proof a transaction reached the accepted ledger; `tx_count` on the same span counts the same set. A transaction whose bytes cannot be parsed gets no event, and nothing in the accepted ledger is missing one, so the events are always a superset of the ledger's contents. To confirm a transaction actually applied, read `ter_result` and `applied` on its `tx.transactor` span.
|
||||
|
||||
#### Close Time Queries (Tempo TraceQL)
|
||||
|
||||
> **TraceQL syntax**: an attribute filter belongs inside the braces, as
|
||||
> `{name="x" && span.attr = value}`. The `{name="x"} | attr = value` form used
|
||||
> by several examples in this document is rejected by current Tempo with a parse
|
||||
> error, so convert an example to the braced form before running it. Numeric
|
||||
> attributes such as `consensus_round_id` and `retries_remaining` must be
|
||||
> compared unquoted.
|
||||
|
||||
```
|
||||
# Find rounds where validators disagreed on close time
|
||||
{name="consensus.accept.apply"} | close_time_correct = false
|
||||
|
||||
# Find consensus failures (moved_on)
|
||||
{name="consensus.accept.apply"} | consensus_state = "moved_on"
|
||||
|
||||
# Find slow ledger applications (>5s)
|
||||
{name="consensus.accept.apply"} | duration > 5s
|
||||
|
||||
# Find specific ledger's consensus details
|
||||
{name="consensus.accept.apply"} | ledger_seq = 92345678
|
||||
|
||||
# Find a consensus round by its id. consensus_round_id is an integer, so it
|
||||
# must not be quoted, and it is set only on consensus.round.
|
||||
{name="consensus.round" && span.consensus_round_id = 92345678}
|
||||
|
||||
# Find dispute resolutions. The event is recorded on the update_positions
|
||||
# span itself, so it is a condition on that span, not on a descendant.
|
||||
{name="consensus.update_positions" && event:name="dispute.resolve"}
|
||||
```
|
||||
|
||||
## Insights and Sample Queries
|
||||
|
||||
This section shows what questions you can now answer using the enriched span attributes, with example Tempo TraceQL queries.
|
||||
|
||||
### Transaction Workflow Analysis
|
||||
|
||||
```
|
||||
# Find all AMM transactions (AMMDeposit, AMMWithdraw, AMMCreate, etc.)
|
||||
{name="tx.process"} | tx_type =~ "AMM.*"
|
||||
|
||||
# Find Payment transactions that failed
|
||||
{name="tx.process"} | tx_type = "Payment" && ter_result != "tesSUCCESS"
|
||||
|
||||
# Compare latency of different transaction types
|
||||
{name="tx.process"} | tx_type = "OfferCreate"
|
||||
{name="tx.process"} | tx_type = "Payment"
|
||||
|
||||
# Find high-fee transactions (fee > 1 XRP = 1000000 drops)
|
||||
{name="tx.process"} | fee > 1000000
|
||||
|
||||
# Find transactions that were not applied
|
||||
{name="tx.process"} | applied = false
|
||||
|
||||
# Trace a specific transaction by type across the network
|
||||
{name=~"tx\\..*"} | tx_type = "NFTokenMint"
|
||||
```
|
||||
|
||||
### Transaction Queue Health
|
||||
|
||||
```
|
||||
# Find transactions rejected from the queue
|
||||
{name="txq.accept_tx"} | txq_status = "failed"
|
||||
|
||||
# Which transaction types get queued most often?
|
||||
{name="txq.enqueue"} | tx_type = "Payment"
|
||||
{name="txq.enqueue"} | tx_type = "OfferCreate"
|
||||
|
||||
# Find ledger closes that applied queued transactions
|
||||
{name="txq.accept"} | ledger_changed = true
|
||||
|
||||
# Find transactions dropped because they had no retries left.
|
||||
# retries_remaining is recorded before the attempt, and the "retried" branch
|
||||
# is only reached while retries are left, so exhaustion always shows up as
|
||||
# "failed" with a zero count.
|
||||
{name="txq.accept_tx" && span.txq_status = "failed" && span.retries_remaining <= 0}
|
||||
```
|
||||
|
||||
### RPC Debugging
|
||||
|
||||
```
|
||||
# Find batch RPC requests
|
||||
{name="rpc.process"} | is_batch = true
|
||||
|
||||
# Find large RPC payloads (>100KB)
|
||||
{name="rpc.http_request"} | request_payload_size > 100000
|
||||
|
||||
# Find resource-heavy RPC commands (by load_type)
|
||||
{name=~"rpc.command.*"} | load_type = "exception_rpc"
|
||||
|
||||
# Find a specific WebSocket command
|
||||
{name="rpc.ws_message"} | command = "subscribe"
|
||||
|
||||
# Find slow pathfinding with many source assets
|
||||
{name="pathfind.discover"} | pathfind_num_source_assets > 10
|
||||
```
|
||||
|
||||
### PathFinding Performance
|
||||
|
||||
```
|
||||
# Find pathfinding for specific currencies
|
||||
{name="pathfind.compute"} | pathfind_dest_currency = "USD"
|
||||
|
||||
# Find expensive pathfinding (many source assets to explore)
|
||||
{name="pathfind.discover"} | pathfind_num_source_assets > 20
|
||||
|
||||
# Find large pathfinding requests
|
||||
{name="pathfind.compute"} | duration > 1s
|
||||
```
|
||||
|
||||
### Consensus Health
|
||||
|
||||
```
|
||||
# Find rounds where consensus timed out (expired)
|
||||
{name="consensus.accept"} | consensus_state = "expired"
|
||||
|
||||
# Find rounds where we moved on without full agreement
|
||||
{name="consensus.accept"} | consensus_state = "moved_on"
|
||||
|
||||
# Find rounds with many disputes
|
||||
{name="consensus.accept"} | disputes_count > 5
|
||||
|
||||
# Find bow-out proposals (node resigned from round)
|
||||
{name="consensus.proposal.send"} | is_bow_out = true
|
||||
|
||||
# Correlate validation with its ledger
|
||||
{name="consensus.validation.send"} | ledger_hash = "<hash>"
|
||||
|
||||
# Find rounds where validators disagreed on close time
|
||||
{name="consensus.accept.apply"} | close_time_correct = false
|
||||
```
|
||||
|
||||
### Cross-Subsystem Correlation
|
||||
|
||||
```
|
||||
# Follow a transaction from receive through queue to ledger
|
||||
{name=~"tx\\..*|txq\\..*"} | tx_type = "Payment" && duration > 500ms
|
||||
|
||||
# Find all NFT-related activity
|
||||
{name=~"tx\\..*|txq\\..*"} | tx_type =~ "NFToken.*"
|
||||
|
||||
# Find consensus rounds with slow transactions
|
||||
{name="consensus.accept"} | round_time_ms > 5000
|
||||
```
|
||||
|
||||
### Where to Look (Quick Reference)
|
||||
|
||||
| Question | Span | Key Attributes |
|
||||
| ----------------------------------- | --------------------------- | ------------------------------ |
|
||||
| "Which tx type is slowest?" | `tx.process` | `tx_type` + duration |
|
||||
| "Why was my tx rejected?" | `tx.process` | `ter_result`, `applied` |
|
||||
| "Is the TxQ backing up?" | `txq.accept` | `queue_size`, `ledger_changed` |
|
||||
| "Why was my tx dropped from queue?" | `txq.accept_tx` | `txq_status`, `ter_code` |
|
||||
| "Are batch requests a problem?" | `rpc.process` | `is_batch`, `batch_size` |
|
||||
| "Which RPC is expensive?" | `rpc.command.*` | `load_type`, duration |
|
||||
| "Did consensus stall?" | `consensus.check` | `consensus_stalled` |
|
||||
| "Was consensus outcome normal?" | `consensus.accept` | `consensus_state` |
|
||||
| "Did a validator bow out?" | `consensus.proposal.send` | `is_bow_out` |
|
||||
| "Which ledger was validated?" | `consensus.validation.send` | `ledger_hash` |
|
||||
| "What tx work fed a given ledger?" | `tx.*` / `txq.*` | `current_ledger_seq` |
|
||||
|
||||
### Correlating a transaction to the ledger it was worked on
|
||||
|
||||
The `tx.process`, `tx.receive`, `txq.enqueue`, `tx.preclaim`, and `tx.transactor`
|
||||
spans carry `current_ledger_seq` — the open/in-flight ledger they acted on (not
|
||||
an established ledger). Because these spans are keyed on the transaction id (their
|
||||
own trace) while the ledger/consensus spans are keyed on the ledger, use the
|
||||
attribute to bridge the two id-spaces:
|
||||
|
||||
```
|
||||
# All transaction-side work recorded against ledger N
|
||||
{span.current_ledger_seq = N}
|
||||
|
||||
# Join to the ledger build/consensus trace for the same ledger
|
||||
{name="ledger.build" && span.ledger_seq = N}
|
||||
```
|
||||
|
||||
`txq.enqueue` and the view-bearing apply stages also carry `current_ledger_hash`
|
||||
(the current ledger's parent hash), which equals the `consensus.round`
|
||||
deterministic trace-id seed on the consensus-build path. `tx.preflight` is
|
||||
stateless and omits both attributes.
|
||||
|
||||
---
|
||||
|
||||
## Cross-Node Trace Propagation
|
||||
|
||||
xrpld propagates trace context across nodes via protobuf `TraceContext` fields
|
||||
embedded in peer-to-peer messages. When Node A sends a transaction, proposal,
|
||||
or validation, it injects its active span's trace/span IDs into the protobuf
|
||||
message. Node B extracts that context on receipt and creates a child span,
|
||||
linking the two nodes into a single distributed trace.
|
||||
|
||||
### How It Works
|
||||
|
||||
```
|
||||
Node A (sender) Node B (receiver)
|
||||
+-----------------------------+ +-------------------------------+
|
||||
| tx.process / consensus.* | | PeerImp::onMessage() |
|
||||
| | | | | |
|
||||
| v | | v |
|
||||
| SpanGuard::getTraceBytes() | | extract TraceContext from |
|
||||
| | | | protobuf message |
|
||||
| v | send | | |
|
||||
| injectSpanContext() --------|--------->| v |
|
||||
| sets TraceContext fields | proto | txReceiveSpan() |
|
||||
| (trace_id, span_id, flags) | msg | proposalReceiveSpan() |
|
||||
+-----------------------------+ | validationReceiveSpan() |
|
||||
| | |
|
||||
| v |
|
||||
| child span with parent link |
|
||||
+-------------------------------+
|
||||
```
|
||||
|
||||
### Send-Side Injection
|
||||
|
||||
| Message Type | Injection Point | Mechanism |
|
||||
| ------------- | -------------------------- | ------------------------------------------ |
|
||||
| TMTransaction | `NetworkOPs::apply()` | Injects `tx.process` span into relay msg |
|
||||
| TMProposeSet | `RCLConsensus::propose()` | Injects active context into proposal msg |
|
||||
| TMValidation | `RCLConsensus::validate()` | Injects active context into validation msg |
|
||||
|
||||
### Receive-Side Extraction
|
||||
|
||||
| Message Type | Extraction Point | Helper Function |
|
||||
| ------------- | ----------------------------------- | -------------------------------------------------- |
|
||||
| TMTransaction | `PeerImp::onMessage(TMTransaction)` | `TxTracing::txReceiveSpan()` |
|
||||
| TMProposeSet | `PeerImp::onMessage(TMProposeSet)` | `ConsensusReceiveTracing::proposalReceiveSpan()` |
|
||||
| TMValidation | `PeerImp::onMessage(TMValidation)` | `ConsensusReceiveTracing::validationReceiveSpan()` |
|
||||
|
||||
### Key Files
|
||||
|
||||
| File | Role |
|
||||
| ------------------------------------------------- | ----------------------------------------------- |
|
||||
| `src/xrpld/telemetry/PropagationHelpers.h` | `injectSpanContext()` — SpanGuard to protobuf |
|
||||
| `include/xrpl/telemetry/TraceContextPropagator.h` | OTel context <-> protobuf conversion primitives |
|
||||
| `src/xrpld/telemetry/ConsensusReceiveTracing.h` | Proposal/validation receive span factories |
|
||||
| `src/xrpld/telemetry/TxTracing.h` | Transaction receive span factory |
|
||||
|
||||
### Backwards Compatibility
|
||||
|
||||
Older peers that do not populate `TraceContext` fields in their messages will
|
||||
simply produce empty trace bytes on the receive side. The extraction helpers
|
||||
detect this and create standalone (root) spans instead of child spans. No
|
||||
errors are logged and no data is lost — the receive span is still created with
|
||||
all its normal attributes, it just lacks a cross-node parent link.
|
||||
|
||||
### Example Tempo Queries
|
||||
|
||||
```
|
||||
# Find cross-node transaction traces (tx.process -> tx.receive across nodes)
|
||||
{name="tx.receive"} && status != error
|
||||
|
||||
# Find proposals received with cross-node parent context
|
||||
{} >> {name="consensus.proposal.receive"}
|
||||
|
||||
# Trace a transaction across the network by its hash
|
||||
{name=~"tx\\..*"} | tx_hash = "<hash>"
|
||||
|
||||
# Find a cross-node consensus trace by round id, then open the returned trace
|
||||
# to see every node's spans. Under the deterministic strategy all validators of
|
||||
# a round share one trace id, so one trace holds all of them. The value is an
|
||||
# integer, so it must not be quoted, and it only matches the consensus.round
|
||||
# span that carries it.
|
||||
{name="consensus.round" && span.consensus_round_id = 92345678}
|
||||
|
||||
# Compare latency between sender and receiver for validations
|
||||
{name="consensus.validation.send" || name="consensus.validation.receive"}
|
||||
```
|
||||
|
||||
## Prometheus Metrics (Spanmetrics)
|
||||
|
||||
The OTel Collector's spanmetrics connector automatically derives RED (Rate, Errors, Duration) metrics from every span. No custom metrics code is needed in xrpld.
|
||||
|
||||
### Generated Metric Names
|
||||
|
||||
| Prometheus Metric | Type | Description |
|
||||
| -------------------------------------------------- | --------- | ---------------------------- |
|
||||
| `traces_span_metrics_calls_total` | Counter | Total span invocations |
|
||||
| `traces_span_metrics_duration_milliseconds_bucket` | Histogram | Latency distribution buckets |
|
||||
| `traces_span_metrics_duration_milliseconds_count` | Histogram | Latency observation count |
|
||||
| `traces_span_metrics_duration_milliseconds_sum` | Histogram | Cumulative latency |
|
||||
|
||||
### Metric Labels
|
||||
|
||||
Every metric carries these standard labels:
|
||||
|
||||
| Label | Source | Example |
|
||||
| -------------- | ------------------ | ---------------------------------------- |
|
||||
| `span_name` | Span name | `rpc.command.server_info` |
|
||||
| `status_code` | Span status | `STATUS_CODE_UNSET`, `STATUS_CODE_ERROR` |
|
||||
| `service_name` | Resource attribute | `xrpld` |
|
||||
| `span_kind` | Span kind | `SPAN_KIND_INTERNAL` |
|
||||
|
||||
Additionally, span attributes configured as dimensions in the collector
|
||||
become metric labels. The span attribute keys are already underscore form
|
||||
(the naming convention forbids dots), so the label name matches the attribute
|
||||
name verbatim. Prometheus' dots → underscores sanitization only fires for
|
||||
dotted attribute names (e.g. resource attributes like `service.name`), which
|
||||
does not apply to these dimensions.
|
||||
|
||||
| Span Attribute | Metric Label | Applies To |
|
||||
| ---------------- | ---------------- | ------------------------------ |
|
||||
| `command` | `command` | `rpc.command.*` spans |
|
||||
| `rpc_status` | `rpc_status` | `rpc.command.*` spans |
|
||||
| `consensus_mode` | `consensus_mode` | `consensus.ledger_close` spans |
|
||||
| `local` | `local` | `tx.process` spans |
|
||||
|
||||
### Histogram Buckets
|
||||
|
||||
Configured in `otel-collector-config.yaml`:
|
||||
|
||||
```
|
||||
1ms, 5ms, 10ms, 25ms, 50ms, 100ms, 250ms, 500ms, 1s, 5s
|
||||
```
|
||||
|
||||
## Deployment Tiers
|
||||
|
||||
Multiple xrpld instances can send telemetry to per-tier collectors that all
|
||||
forward to one Grafana stack. Four resource attributes segregate the data so
|
||||
one dashboard set serves every deployment:
|
||||
|
||||
| Dimension | Attribute | Set by | Example values |
|
||||
| ----------- | ------------------------ | ---------- | ------------------------------ |
|
||||
| Node | `service.instance.id` | xrpld cfg | `alice-laptop`, `ci-runner-7` |
|
||||
| Service | `service.name` | xrpld cfg | `xrpld`, `xrpld-validator` |
|
||||
| Network | `xrpl.network.type` | xrpld node | `mainnet`, `testnet`, `devnet` |
|
||||
| Environment | `deployment.environment` | collector | `local`, `test`, `ci`, `prod` |
|
||||
|
||||
Dashboards expose these as the template variables `$node`, `$service_name`,
|
||||
`$xrpl_network_type`, and `$deployment_environment` (each variable name
|
||||
matches its Prometheus label). Select them top-down — environment → network
|
||||
→ service → node. Selecting **All** matches every value, including series
|
||||
lacking the label, so mixed old/new data never disappears.
|
||||
|
||||
### Who owns which attribute
|
||||
|
||||
- **Node and service** come from xrpld config (`service_instance_id`,
|
||||
`service_name`). Unique per process.
|
||||
- **Network** is a property of the chain the node joined; the node derives it
|
||||
from `[network_id]` and stamps `xrpl.network.type` on all three signals.
|
||||
- **Environment** is a property of where the collector runs; each collector
|
||||
serves one environment and stamps it.
|
||||
|
||||
### The upsert vs insert rule
|
||||
|
||||
The collector's `resource/tier` processor uses two actions on purpose:
|
||||
|
||||
- `deployment.environment` → **`upsert`** (overwrite). The collector _is_ the
|
||||
environment, so it is authoritative.
|
||||
- `xrpl.network.type` → **`insert`** (fill only if absent). The node knows
|
||||
its real network, so the collector must not overwrite it — `insert` only
|
||||
supplies a value when the source did not (e.g. an older xrpld build). This
|
||||
is what lets a local node connected to mainnet report `network=mainnet`,
|
||||
not the collector's default.
|
||||
|
||||
### Configuring a collector for a tier
|
||||
|
||||
Each tier runs its own collector. Set the two values in the `resource/tier`
|
||||
processor of the collector config (`otel-collector-config.yaml` for local
|
||||
backends, `otel-collector-config.grafanacloud.yaml` for Grafana Cloud):
|
||||
|
||||
```yaml
|
||||
processors:
|
||||
resource/tier:
|
||||
attributes:
|
||||
- key: deployment.environment
|
||||
value: <tier> # local | test | ci | prod
|
||||
action: upsert
|
||||
- key: xrpl.network.type
|
||||
value: <network> # mainnet | testnet | devnet (fallback only)
|
||||
action: insert
|
||||
```
|
||||
|
||||
Suggested per-tier values:
|
||||
|
||||
| Collector | `deployment.environment` | `xrpl.network.type` (fallback) |
|
||||
| ------------------- | ------------------------ | ------------------------------ |
|
||||
| Developer laptop | `local` | `devnet` |
|
||||
| Test machines | `test` | `testnet` |
|
||||
| CI runs | `ci` | `testnet` |
|
||||
| Production observer | `prod` | `mainnet` |
|
||||
|
||||
The `xrpl.network.type` value is only a fallback: when the node stamps its
|
||||
own network (all current builds do), the node's value wins. Set it to the
|
||||
network the collector most commonly serves.
|
||||
|
||||
### How the tier labels reach metrics
|
||||
|
||||
Resource attributes do not become Prometheus labels automatically. Two
|
||||
collector settings make it work, both already enabled:
|
||||
|
||||
- `prometheus.resource_to_telemetry_conversion: enabled: true` promotes
|
||||
resource attributes to metric labels on the local scrape surface.
|
||||
- `spanmetrics.resource_metrics_key_attributes` lists the tier attributes so
|
||||
span-derived series stay grouped per node and tier.
|
||||
|
||||
Traces and logs carry resource attributes natively; Grafana Cloud ingests all
|
||||
three signals' attributes over OTLP directly.
|
||||
|
||||
## Grafana Dashboards
|
||||
|
||||
Three dashboards are pre-provisioned in `docker/telemetry/grafana/dashboards/`:
|
||||
|
||||
### RPC Performance (`rpc-performance`)
|
||||
|
||||
| Panel | Type | PromQL | Labels Used |
|
||||
| --------------------------- | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ------------------------ |
|
||||
| RPC Request Rate by Command | timeseries | `sum by (command) (rate(traces_span_metrics_calls_total{span_name=~"rpc.command.*"}[5m]))` | `command` |
|
||||
| RPC Latency p95 by Command | timeseries | `histogram_quantile(0.95, sum by (le, command) (rate(traces_span_metrics_duration_milliseconds_bucket{span_name=~"rpc.command.*"}[5m])))` | `command` |
|
||||
| RPC Error Rate | bargauge | Error spans / total spans × 100, grouped by `command` | `command`, `status_code` |
|
||||
| RPC Latency Heatmap | heatmap | `sum(increase(traces_span_metrics_duration_milliseconds_bucket{span_name=~"rpc.command.*"}[5m])) by (le)` | `le` (bucket boundaries) |
|
||||
|
||||
### Transaction Overview (`transaction-overview`)
|
||||
|
||||
| Panel | Type | PromQL | Labels Used |
|
||||
| --------------------------------- | ---------- | ------------------------------------------------------------------------------------ | ----------- |
|
||||
| Transaction Processing Rate | timeseries | `rate(traces_span_metrics_calls_total{span_name="tx.process"}[5m])` and `tx.receive` | `span_name` |
|
||||
| Transaction Processing Latency | timeseries | `histogram_quantile(0.95 / 0.50, ... {span_name="tx.process"})` | — |
|
||||
| Transaction Path Distribution | piechart | `sum by (local) (rate(traces_span_metrics_calls_total{span_name="tx.process"}[5m]))` | `local` |
|
||||
| Transaction Receive vs Suppressed | timeseries | `rate(traces_span_metrics_calls_total{span_name="tx.receive"}[5m])` | — |
|
||||
|
||||
### Consensus Health (`consensus-health`)
|
||||
|
||||
| Panel | Type | PromQL | Labels Used |
|
||||
| ----------------------------- | ---------- | ---------------------------------------------------------------------------------- | ----------- |
|
||||
| Consensus Round Duration | timeseries | `histogram_quantile(0.95 / 0.50, ... {span_name="consensus.accept"})` | — |
|
||||
| Consensus Proposals Sent Rate | timeseries | `rate(traces_span_metrics_calls_total{span_name="consensus.proposal.send"}[5m])` | — |
|
||||
| Ledger Close Duration | timeseries | `histogram_quantile(0.95, ... {span_name="consensus.ledger_close"})` | — |
|
||||
| Validation Send Rate | stat | `rate(traces_span_metrics_calls_total{span_name="consensus.validation.send"}[5m])` | — |
|
||||
| Ledger Apply Duration | timeseries | `histogram_quantile(0.95 / 0.50, ... {span_name="consensus.accept.apply"})` | — |
|
||||
| Close Time Agreement | timeseries | `rate(traces_span_metrics_calls_total{span_name="consensus.accept.apply"}[5m])` | — |
|
||||
|
||||
### Span → Metric → Dashboard Summary
|
||||
|
||||
| Span Name | Prometheus Metric Filter | Grafana Dashboard |
|
||||
| ------------------------------ | -------------------------------------------- | --------------------------------------------- |
|
||||
| `rpc.http_request` | `{span_name="rpc.http_request"}` | -- (available but not paneled) |
|
||||
| `rpc.ws_upgrade` | `{span_name="rpc.ws_upgrade"}` | -- (available but not paneled) |
|
||||
| `rpc.ws_message` | `{span_name="rpc.ws_message"}` | -- (available but not paneled) |
|
||||
| `rpc.process` | `{span_name="rpc.process"}` | -- (available but not paneled) |
|
||||
| `rpc.command.*` | `{span_name=~"rpc.command.*"}` | RPC Performance (all 4 panels) |
|
||||
| `tx.process` | `{span_name="tx.process"}` | Transaction Overview (3 panels) |
|
||||
| `tx.receive` | `{span_name="tx.receive"}` | Transaction Overview (2 panels) |
|
||||
| `txq.enqueue` | `{span_name="txq.enqueue"}` | -- (available but not paneled) |
|
||||
| `txq.apply_direct` | `{span_name="txq.apply_direct"}` | -- (available but not paneled) |
|
||||
| `txq.batch_clear` | `{span_name="txq.batch_clear"}` | -- (available but not paneled) |
|
||||
| `txq.accept` | `{span_name="txq.accept"}` | -- (available but not paneled) |
|
||||
| `txq.accept_tx` | `{span_name="txq.accept_tx"}` | -- (available but not paneled) |
|
||||
| `txq.cleanup` | `{span_name="txq.cleanup"}` | -- (available but not paneled) |
|
||||
| `consensus.round` | `{span_name="consensus.round"}` | -- (available but not paneled) |
|
||||
| `consensus.phase.open` | `{span_name="consensus.phase.open"}` | -- (available but not paneled) |
|
||||
| `consensus.establish` | `{span_name="consensus.establish"}` | -- (available but not paneled) |
|
||||
| `consensus.update_positions` | `{span_name="consensus.update_positions"}` | -- (available but not paneled) |
|
||||
| `consensus.check` | `{span_name="consensus.check"}` | -- (available but not paneled) |
|
||||
| `consensus.accept` | `{span_name="consensus.accept"}` | Consensus Health (Round Duration) |
|
||||
| `consensus.proposal.send` | `{span_name="consensus.proposal.send"}` | Consensus Health (Proposals Rate) |
|
||||
| `consensus.ledger_close` | `{span_name="consensus.ledger_close"}` | Consensus Health (Close Duration) |
|
||||
| `consensus.validation.send` | `{span_name="consensus.validation.send"}` | Consensus Health (Validation Rate) |
|
||||
| `consensus.accept.apply` | `{span_name="consensus.accept.apply"}` | Consensus Health (Apply Duration, Close Time) |
|
||||
| `consensus.mode_change` | `{span_name="consensus.mode_change"}` | -- (available but not paneled) |
|
||||
| `consensus.proposal.receive` | `{span_name="consensus.proposal.receive"}` | -- (available but not paneled) |
|
||||
| `consensus.validation.receive` | `{span_name="consensus.validation.receive"}` | -- (available but not paneled) |
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### No traces appearing in Tempo
|
||||
|
||||
1. Check xrpld logs for `Telemetry starting` message
|
||||
2. Verify `enabled=1` in the `[telemetry]` config section
|
||||
3. Test collector connectivity: `curl -v http://localhost:4318/v1/traces`
|
||||
4. Check collector logs: `docker compose -f docker/telemetry/docker-compose.yml logs otel-collector`
|
||||
5. Verify Tempo is receiving data: open Grafana → Explore → select Tempo datasource → search by `service.name = xrpld`
|
||||
6. Check Tempo logs: `docker compose -f docker/telemetry/docker-compose.yml logs tempo`
|
||||
|
||||
### High memory usage
|
||||
|
||||
- Reduce trace volume with collector-side tail sampling (xrpld head sampling is
|
||||
fixed at 1.0 and is not configurable)
|
||||
- Reduce `max_queue_size` and `batch_size`
|
||||
- Disable high-volume trace categories: `trace_peer=0`
|
||||
|
||||
### Collector connection failures
|
||||
|
||||
- Verify endpoint URL matches collector address
|
||||
- Check firewall rules for ports 4317/4318
|
||||
- If using TLS, verify certificate path with `tls_ca_cert`
|
||||
|
||||
### Node exits at startup with `Unable to start ...: [telemetry] ...`
|
||||
|
||||
- Symptom: the process exits immediately with a non-zero status (255 on POSIX)
|
||||
— a clean exit, not a crash — after printing that line on stderr. Any
|
||||
exception thrown while the `Application` object is constructed prints the same
|
||||
`Unable to start` prefix, so confirm the text after the colon begins with
|
||||
`[telemetry]` before using this entry
|
||||
- Cause: either the `[telemetry]` mTLS keys (`tls_client_cert` and
|
||||
`tls_client_key`) contradict each other, or one of the TLS certificate paths
|
||||
cannot be read. Only these three checks are gated on `enabled=1`; the rest of
|
||||
the section is still read when telemetry is off, so a malformed value in any
|
||||
key — including `enabled` itself, which is read before the gate — still fails
|
||||
startup with a different message
|
||||
- Fix: the three checks need different remedies, and the printed message says
|
||||
which one fired
|
||||
- `tls_client_cert and tls_client_key must be set together` — exactly one of
|
||||
the two paths is set. Either delete the one that is set, or add the missing
|
||||
one **and** set `use_tls=1`. Unless `use_tls=1` is already set, adding the
|
||||
missing path on its own just moves the failure to the second check
|
||||
- `tls_client_cert/tls_client_key require use_tls=1` — both paths are set but
|
||||
TLS is off. Either set `use_tls=1`, or delete **both** paths. Deleting only
|
||||
one of them trips the first check
|
||||
- `<key> cannot be read` — the named key (`tls_ca_cert`, `tls_client_cert` or
|
||||
`tls_client_key`) points at a file the node cannot open; the message also
|
||||
prints the path and the OS error. Fix the path or its permissions — the
|
||||
pairing is not what is wrong here. This check runs only when `use_tls=1`,
|
||||
and an empty `tls_ca_cert` is always accepted (it selects the system CA
|
||||
store)
|
||||
- If you did not mean to enable telemetry at all, set `enabled=0` — that
|
||||
clears all three checks whichever one fired
|
||||
|
||||
## Performance Tuning
|
||||
|
||||
| Scenario | Recommendation |
|
||||
| ------------------------ | --------------------------------------------------------- |
|
||||
| Production mainnet | `trace_peer=0`; reduce volume via collector tail sampling |
|
||||
| Testnet/devnet | Full tracing (head sampling fixed at 1.0) |
|
||||
| Debugging specific issue | Full tracing (head sampling fixed at 1.0) |
|
||||
| High-throughput node | Increase `batch_size=1024`, `max_queue_size=4096` |
|
||||
|
||||
## Disabling Telemetry
|
||||
|
||||
Set `enabled=0` in config (runtime disable), or compile telemetry out:
|
||||
|
||||
```bash
|
||||
conan install .. --output-folder . --build missing -o telemetry=False --settings build_type=Release
|
||||
cmake -DCMAKE_TOOLCHAIN_FILE:FILEPATH=build/generators/conan_toolchain.cmake -DCMAKE_BUILD_TYPE=Release -Dtelemetry=OFF ..
|
||||
```
|
||||
|
||||
Both flags are needed, and both must be stated. The default is `ON`, so omitting a flag leaves telemetry compiled in.
|
||||
|
||||
When telemetry is compiled out, all trace macros expand to no-ops with zero overhead.
|
||||
@@ -543,21 +543,8 @@ public:
|
||||
setround(RoundingMode inMode);
|
||||
|
||||
/**
|
||||
* Convert an integer to a RoundingMode, validating that it is in range.
|
||||
* Returns which mantissa scale is currently in use for normalization.
|
||||
*
|
||||
* Returns std::nullopt if the value does not correspond to a valid
|
||||
* RoundingMode.
|
||||
*/
|
||||
static std::optional<RoundingMode>
|
||||
checkedRoundingMode(int mode) noexcept
|
||||
{
|
||||
if (mode < static_cast<int>(RoundingMode::ToNearest) ||
|
||||
mode > static_cast<int>(RoundingMode::Upward))
|
||||
return std::nullopt;
|
||||
return static_cast<RoundingMode>(mode);
|
||||
}
|
||||
|
||||
/**
|
||||
* If you think you need to call this outside of unit tests, no you don't.
|
||||
*/
|
||||
static MantissaRange::MantissaScale
|
||||
|
||||
@@ -82,10 +82,4 @@ base64Encode(std::string_view s)
|
||||
std::string
|
||||
base64Decode(std::string_view data);
|
||||
|
||||
/** Decode a base64url-encoded string (RFC 4648 S5).
|
||||
Converts '-' to '+' and '_' to '/', adds padding, then decodes.
|
||||
*/
|
||||
std::string
|
||||
base64urlDecode(std::string_view data);
|
||||
|
||||
} // namespace xrpl
|
||||
|
||||
@@ -11,7 +11,6 @@ struct Sections
|
||||
static constexpr auto kCompression = "compression";
|
||||
static constexpr auto kCrawl = "crawl";
|
||||
static constexpr auto kDatabasePath = "database_path";
|
||||
static constexpr auto kDatagramMonitor = "datagram_monitor";
|
||||
static constexpr auto kDebugLogfile = "debug_logfile";
|
||||
static constexpr auto kElbSupport = "elb_support";
|
||||
static constexpr auto kFeatures = "features";
|
||||
@@ -68,7 +67,6 @@ struct Sections
|
||||
static constexpr auto kValidationSeed = "validation_seed";
|
||||
static constexpr auto kValidatorKeys = "validator_keys";
|
||||
static constexpr auto kValidatorKeyRevocation = "validator_key_revocation";
|
||||
static constexpr auto kValidatorKeyType = "validator_key_type";
|
||||
static constexpr auto kValidatorListKeys = "validator_list_keys";
|
||||
static constexpr auto kValidatorListSites = "validator_list_sites";
|
||||
static constexpr auto kValidatorListThreshold = "validator_list_threshold";
|
||||
@@ -96,7 +94,6 @@ struct Keys
|
||||
static constexpr auto kBbtOptions = "bbt_options";
|
||||
static constexpr auto kBgThreads = "bg_threads";
|
||||
static constexpr auto kBlockSize = "block_size";
|
||||
static constexpr auto kBytecodeSizeLimit = "bytecode_size_limit";
|
||||
static constexpr auto kCacheAge = "cache_age";
|
||||
static constexpr auto kCacheMb = "cache_mb";
|
||||
static constexpr auto kCacheSize = "cache_size";
|
||||
@@ -111,8 +108,6 @@ struct Keys
|
||||
static constexpr auto kFileSizeMult = "file_size_mult";
|
||||
static constexpr auto kFilterBits = "filter_bits";
|
||||
static constexpr auto kFilterFull = "filter_full";
|
||||
static constexpr auto kGasLimit = "gas_limit";
|
||||
static constexpr auto kGasPrice = "gas_price";
|
||||
static constexpr auto kHardSet = "hard_set";
|
||||
static constexpr auto kHighThreads = "high_threads";
|
||||
static constexpr auto kHoldTime = "hold_time";
|
||||
|
||||
@@ -8,10 +8,13 @@
|
||||
#include <xrpl/beast/utility/instrumentation.h>
|
||||
#include <xrpl/consensus/ConsensusParms.h>
|
||||
#include <xrpl/consensus/ConsensusProposal.h>
|
||||
#include <xrpl/consensus/ConsensusSpanLabels.h>
|
||||
#include <xrpl/consensus/ConsensusSpanNames.h>
|
||||
#include <xrpl/consensus/ConsensusTypes.h>
|
||||
#include <xrpl/json/json_value.h>
|
||||
#include <xrpl/json/json_writer.h>
|
||||
#include <xrpl/ledger/LedgerTiming.h>
|
||||
#include <xrpl/telemetry/SpanGuard.h>
|
||||
|
||||
#include <algorithm>
|
||||
#include <chrono>
|
||||
@@ -24,16 +27,42 @@
|
||||
#include <ranges>
|
||||
#include <sstream>
|
||||
#include <string>
|
||||
#include <string_view>
|
||||
#include <utility>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
/**
|
||||
* Determines why the current ledger should close at this time.
|
||||
*
|
||||
* Holds the close decision. shouldCloseLedger() delegates here and adds only
|
||||
* a comparison, so the logging happens once either way; call whichever suits.
|
||||
* Parameters match shouldCloseLedger().
|
||||
*
|
||||
* @return The deciding branch, or KeepOpen if no close condition is met.
|
||||
*/
|
||||
LedgerCloseReason
|
||||
whyCloseLedger(
|
||||
bool anyTransactions,
|
||||
std::size_t prevProposers,
|
||||
std::size_t proposersClosed,
|
||||
std::size_t proposersValidated,
|
||||
std::chrono::milliseconds prevRoundTime,
|
||||
std::chrono::milliseconds timeSincePrevClose,
|
||||
std::chrono::milliseconds openTime,
|
||||
std::chrono::milliseconds idleInterval,
|
||||
ConsensusParms const& parms,
|
||||
beast::Journal j,
|
||||
std::unique_ptr<std::stringstream> const& clog = {});
|
||||
|
||||
/**
|
||||
* Determines whether the current ledger should close at this time.
|
||||
*
|
||||
* This function should be called when a ledger is open and there is no close
|
||||
* in progress, or when a transaction is received and no close is in progress.
|
||||
*
|
||||
* Equivalent to `whyCloseLedger(...) != LedgerCloseReason::KeepOpen`.
|
||||
*
|
||||
* @param anyTransactions indicates whether any transactions have been received
|
||||
* @param prevProposers proposers in the last closing
|
||||
* @param proposersClosed proposers who have currently closed this ledger
|
||||
@@ -447,13 +476,29 @@ public:
|
||||
getJson(bool full) const;
|
||||
|
||||
private:
|
||||
/**
|
||||
* Why startRoundInternal is being entered.
|
||||
*
|
||||
* Distinguishes the normal Initial entry (from public startRound)
|
||||
* from a Recovered re-entry (from handleWrongLedger after the
|
||||
* correct prior ledger was acquired mid-round). The Recovered path
|
||||
* resets phase to Open within the SAME round, which is a state
|
||||
* transition that would otherwise be invisible in traces — the
|
||||
* recovery flag drives a `phase.recovery` event on the round span.
|
||||
*/
|
||||
enum class StartRoundReason : std::uint8_t {
|
||||
Initial,
|
||||
Recovered,
|
||||
};
|
||||
|
||||
void
|
||||
startRoundInternal(
|
||||
NetClock::time_point const& now,
|
||||
Ledger_t::ID const& prevLedgerID,
|
||||
Ledger_t const& prevLedger,
|
||||
ConsensusMode mode,
|
||||
std::unique_ptr<std::stringstream> const& clog);
|
||||
std::unique_ptr<std::stringstream> const& clog,
|
||||
StartRoundReason reason = StartRoundReason::Initial);
|
||||
|
||||
// Change our view of the previous ledger
|
||||
void
|
||||
@@ -627,6 +672,67 @@ private:
|
||||
// nodes that have bowed out of this consensus process
|
||||
hash_set<NodeID_t> deadNodes_;
|
||||
|
||||
/**
|
||||
* Span for the establish phase of consensus.
|
||||
* Created when the ledger closes and we enter phaseEstablish;
|
||||
* cleared (ended) when consensus is reached. A thread-free SpanGuard,
|
||||
* emplaced and reset() on different job workers.
|
||||
*/
|
||||
std::optional<xrpl::telemetry::SpanGuard> establishSpan_;
|
||||
|
||||
/**
|
||||
* Captured context of establishSpan_ (its own span context). Children
|
||||
* (update_positions, check) build from this explicit context.
|
||||
*/
|
||||
xrpl::telemetry::SpanContext establishSpanContext_;
|
||||
|
||||
/**
|
||||
* Span for the open phase of consensus.
|
||||
* Created in startRoundInternal(); cleared (ended) in closeLedger().
|
||||
* A thread-free SpanGuard, emplaced and reset() on different job workers.
|
||||
*/
|
||||
std::optional<xrpl::telemetry::SpanGuard> openSpan_;
|
||||
|
||||
/**
|
||||
* Record how the open-phase span began.
|
||||
*
|
||||
* @param reason Which startRoundInternal() entry path created it.
|
||||
* @param prevLedger The prior ledger, read before previousLedger_ is set.
|
||||
*/
|
||||
void
|
||||
annotateOpenStart(StartRoundReason reason, Ledger_t const& prevLedger);
|
||||
|
||||
/**
|
||||
* Record what ended the open phase.
|
||||
*
|
||||
* @param closeReason The deciding whyCloseLedger() branch.
|
||||
* @param proposersValidated Trusted peers already past the prior ledger.
|
||||
*/
|
||||
void
|
||||
annotateOpenClose(LedgerCloseReason closeReason, std::size_t proposersValidated);
|
||||
|
||||
/**
|
||||
* Create the establish-phase span if not yet active.
|
||||
* Called on each phaseEstablish() invocation; no-op while span is live.
|
||||
*/
|
||||
void
|
||||
startEstablishTracing();
|
||||
|
||||
/**
|
||||
* Overwrite convergence metrics on the establish span each iteration.
|
||||
* Final span attributes always reflect the last state before consensus.
|
||||
*/
|
||||
void
|
||||
updateEstablishTracing();
|
||||
|
||||
/**
|
||||
* End the establish span, recording its terminal regime.
|
||||
* Also called from startRoundInternal() on a wrongLedger recovery, so a
|
||||
* round that never reaches Accepted still reports the regime it reached.
|
||||
*/
|
||||
void
|
||||
endEstablishTracing();
|
||||
|
||||
// Journal for debugging
|
||||
beast::Journal const j_;
|
||||
};
|
||||
@@ -690,13 +796,52 @@ Consensus<Adaptor>::startRoundInternal(
|
||||
Ledger_t::ID const& prevLedgerID,
|
||||
Ledger_t const& prevLedger,
|
||||
ConsensusMode mode,
|
||||
std::unique_ptr<std::stringstream> const& clog)
|
||||
std::unique_ptr<std::stringstream> const& clog,
|
||||
StartRoundReason const reason)
|
||||
{
|
||||
// Recovery path: handleWrongLedger acquired the correct prior ledger
|
||||
// and re-entered startRoundInternal mid-round. The roundSpan_ owned by
|
||||
// the adaptor is still the SAME span as before — startRoundTracing is
|
||||
// not called on the recovery path, so we record the recovery as an
|
||||
// event on the surviving round span. Pass empty phaseLabel to leave
|
||||
// consensus_phase unchanged (the actual phase reset to open is marked
|
||||
// separately by the new openSpan_ being emplaced below).
|
||||
if (reason == StartRoundReason::Recovered)
|
||||
{
|
||||
adaptor_.onPhaseEvent(telemetry::consensus::span::event::phaseRecovery, "");
|
||||
}
|
||||
|
||||
phase_ = ConsensusPhase::Open;
|
||||
JLOG(j_.debug()) << "transitioned to ConsensusPhase::Open ";
|
||||
CLOG(clog) << "startRoundInternal transitioned to ConsensusPhase::Open, "
|
||||
"previous ledgerID: "
|
||||
<< prevLedgerID << ", seq: " << prevLedger.seq() << ". ";
|
||||
// End establishSpan_ so a wrongLedger recovery mid-establish doesn't leak
|
||||
// the prior round's span into the new one (startEstablishTracing
|
||||
// early-returns when establishSpan_ is populated). Via
|
||||
// endEstablishTracing() so the recovered round still records its terminal
|
||||
// regime; closeTimeAvalancheState_ is not reset until further down.
|
||||
endEstablishTracing();
|
||||
// Child of the round span via its captured context: parent phase.open
|
||||
// explicitly under roundSpanContext_. An invalid round context (round span
|
||||
// not yet created) yields a null guard. openSpan_ is a thread-free
|
||||
// SpanGuard emplaced here on one job worker and reset() on another; no
|
||||
// scope to strip.
|
||||
openSpan_.emplace(
|
||||
telemetry::SpanGuard::childSpan(
|
||||
telemetry::consensus::span::phaseOpen, adaptor_.roundSpanContext()));
|
||||
annotateOpenStart(reason, prevLedger);
|
||||
// On the Recovered path, fire phase.open here because startRoundTracing
|
||||
// (which fires it for the Initial path) is not called on re-entry. On
|
||||
// the Initial path this is a no-op because the round span hasn't been
|
||||
// created yet — the phase.open event is fired later by startRoundTracing
|
||||
// after the new round span is in place.
|
||||
if (reason == StartRoundReason::Recovered)
|
||||
{
|
||||
adaptor_.onPhaseEvent(
|
||||
telemetry::consensus::span::event::phaseOpen,
|
||||
telemetry::consensus::span::val::phaseOpen);
|
||||
}
|
||||
mode_.set(mode, adaptor_);
|
||||
now_ = now;
|
||||
prevLedgerID_ = prevLedgerID;
|
||||
@@ -720,10 +865,21 @@ Consensus<Adaptor>::startRoundInternal(
|
||||
playbackProposals();
|
||||
CLOG(clog) << "number of peer proposals,previous proposers: " << currPeerPositions_.size()
|
||||
<< ',' << prevProposers_ << ". ";
|
||||
if (currPeerPositions_.size() > (prevProposers_ / 2))
|
||||
// We may be falling behind, don't wait for the timer
|
||||
// consider closing the ledger immediately
|
||||
bool const closeImmediately = currPeerPositions_.size() > (prevProposers_ / 2);
|
||||
// Annotate before the timerEntry() below, which can end this span.
|
||||
if (openSpan_ && *openSpan_)
|
||||
{
|
||||
namespace cs = telemetry::consensus::span;
|
||||
// Head start after playbackProposals() replayed the buffered
|
||||
// positions. Pairs with peer_positions_at_close.
|
||||
openSpan_->setAttribute(
|
||||
cs::attr::peerPositionsAtOpen, static_cast<int64_t>(currPeerPositions_.size()));
|
||||
openSpan_->setAttribute(cs::attr::earlyCloseTriggered, closeImmediately);
|
||||
}
|
||||
if (closeImmediately)
|
||||
{
|
||||
// We may be falling behind, don't wait for the timer
|
||||
// consider closing the ledger immediately
|
||||
CLOG(clog) << "consider closing the ledger immediately. ";
|
||||
timerEntry(now_, clog);
|
||||
}
|
||||
@@ -947,6 +1103,9 @@ Consensus<Adaptor>::simulate(
|
||||
result_->proposers = prevProposers_ = currPeerPositions_.size();
|
||||
prevRoundTime_ = result_->roundTime.read();
|
||||
phase_ = ConsensusPhase::Accepted;
|
||||
adaptor_.onPhaseEvent(
|
||||
telemetry::consensus::span::event::phaseAccepted,
|
||||
telemetry::consensus::span::val::phaseAccepted);
|
||||
adaptor_.onForceAccept(
|
||||
*result_, previousLedger_, closeResolution_, rawCloseTimes_, mode_.get(), getJson(true));
|
||||
// NOLINTEND(bugprone-unchecked-optional-access)
|
||||
@@ -1095,7 +1254,13 @@ Consensus<Adaptor>::handleWrongLedger(
|
||||
{
|
||||
JLOG(j_.info()) << "Have the consensus ledger " << prevLedgerID_;
|
||||
CLOG(clog) << "Have the consensus ledger " << prevLedgerID_ << ". ";
|
||||
startRoundInternal(now_, lgrId, *newLedger, ConsensusMode::SwitchedLedger, clog);
|
||||
startRoundInternal(
|
||||
now_,
|
||||
lgrId,
|
||||
*newLedger,
|
||||
ConsensusMode::SwitchedLedger,
|
||||
clog,
|
||||
StartRoundReason::Recovered);
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -1203,20 +1368,23 @@ Consensus<Adaptor>::phaseOpen(std::unique_ptr<std::stringstream> const& clog)
|
||||
<< ", previous ledger close time resolution: "
|
||||
<< previousLedger_.closeTimeResolution().count() << "ms. ";
|
||||
|
||||
// Decide if we should close the ledger
|
||||
if (shouldCloseLedger(
|
||||
anyTransactions,
|
||||
prevProposers_,
|
||||
proposersClosed,
|
||||
proposersValidated,
|
||||
prevRoundTime_,
|
||||
sinceClose,
|
||||
openTime_.read(),
|
||||
idleInterval,
|
||||
adaptor_.parms(),
|
||||
j_,
|
||||
clog))
|
||||
// Decide if we should close the ledger. whyCloseLedger() so the deciding
|
||||
// branch can be recorded; it logs the same, so only one is called.
|
||||
LedgerCloseReason const closeReason = whyCloseLedger(
|
||||
anyTransactions,
|
||||
prevProposers_,
|
||||
proposersClosed,
|
||||
proposersValidated,
|
||||
prevRoundTime_,
|
||||
sinceClose,
|
||||
openTime_.read(),
|
||||
idleInterval,
|
||||
adaptor_.parms(),
|
||||
j_,
|
||||
clog);
|
||||
if (closeReason != LedgerCloseReason::KeepOpen)
|
||||
{
|
||||
annotateOpenClose(closeReason, proposersValidated);
|
||||
CLOG(clog) << "closing ledger. ";
|
||||
closeLedger(clog);
|
||||
}
|
||||
@@ -1356,6 +1524,8 @@ Consensus<Adaptor>::phaseEstablish(std::unique_ptr<std::stringstream> const& clo
|
||||
XRPL_ASSERT(result_, "xrpl::Consensus::phaseEstablish : result is set");
|
||||
// NOLINTBEGIN(bugprone-unchecked-optional-access) assert above
|
||||
|
||||
startEstablishTracing();
|
||||
|
||||
++peerUnchangedCounter_;
|
||||
++establishCounter_;
|
||||
|
||||
@@ -1383,6 +1553,8 @@ Consensus<Adaptor>::phaseEstablish(std::unique_ptr<std::stringstream> const& clo
|
||||
|
||||
updateOurPositions(clog);
|
||||
|
||||
updateEstablishTracing();
|
||||
|
||||
// Nothing to do if too many laggards or we don't have consensus.
|
||||
if (shouldPause(clog) || !haveConsensus(clog))
|
||||
return;
|
||||
@@ -1400,7 +1572,26 @@ Consensus<Adaptor>::phaseEstablish(std::unique_ptr<std::stringstream> const& clo
|
||||
adaptor_.updateOperatingMode(currPeerPositions_.size());
|
||||
prevProposers_ = currPeerPositions_.size();
|
||||
prevRoundTime_ = result_->roundTime.read();
|
||||
endEstablishTracing();
|
||||
{
|
||||
namespace cs = telemetry::consensus::span;
|
||||
if (result_->state == ConsensusState::Yes)
|
||||
{
|
||||
adaptor_.onOutcomeEvent(cs::event::outcomeYes);
|
||||
}
|
||||
else if (result_->state == ConsensusState::MovedOn)
|
||||
{
|
||||
adaptor_.onOutcomeEvent(cs::event::outcomeMovedOn);
|
||||
}
|
||||
else if (result_->state == ConsensusState::Expired)
|
||||
{
|
||||
adaptor_.onOutcomeEvent(cs::event::outcomeExpired);
|
||||
}
|
||||
}
|
||||
phase_ = ConsensusPhase::Accepted;
|
||||
adaptor_.onPhaseEvent(
|
||||
telemetry::consensus::span::event::phaseAccepted,
|
||||
telemetry::consensus::span::val::phaseAccepted);
|
||||
JLOG(j_.debug()) << "transitioned to ConsensusPhase::Accepted";
|
||||
adaptor_.onAccept(
|
||||
*result_,
|
||||
@@ -1420,7 +1611,26 @@ Consensus<Adaptor>::closeLedger(std::unique_ptr<std::stringstream> const& clog)
|
||||
// We should not be closing if we already have a position
|
||||
XRPL_ASSERT(!result_, "xrpl::Consensus::closeLedger : result is not set");
|
||||
|
||||
// Annotate the open-phase span with end-of-phase metadata before
|
||||
// ending it, so a Tempo/Jaeger query for consensus.phase.open shows
|
||||
// how long the phase ran and how many peer positions arrived during it.
|
||||
openTime_.tick(clock_.now());
|
||||
if (openSpan_ && *openSpan_)
|
||||
{
|
||||
namespace cs = telemetry::consensus::span;
|
||||
openSpan_->setAttribute(
|
||||
cs::attr::openDurationMs, static_cast<int64_t>(openTime_.read().count()));
|
||||
openSpan_->setAttribute(
|
||||
cs::attr::peerPositionsAtClose, static_cast<int64_t>(currPeerPositions_.size()));
|
||||
// Read before our own position is added below, so this counts only
|
||||
// what peers shared.
|
||||
openSpan_->setAttribute(cs::attr::txSetsAcquired, static_cast<int64_t>(acquired_.size()));
|
||||
}
|
||||
openSpan_.reset();
|
||||
phase_ = ConsensusPhase::Establish;
|
||||
adaptor_.onPhaseEvent(
|
||||
telemetry::consensus::span::event::phaseEstablish,
|
||||
telemetry::consensus::span::val::phaseEstablish);
|
||||
JLOG(j_.debug()) << "transitioned to ConsensusPhase::Establish";
|
||||
rawCloseTimes_.self = now_;
|
||||
peerUnchangedCounter_ = 0;
|
||||
@@ -1477,6 +1687,18 @@ Consensus<Adaptor>::updateOurPositions(std::unique_ptr<std::stringstream> const&
|
||||
// We must have a position if we are updating it
|
||||
XRPL_ASSERT(result_, "xrpl::Consensus::updateOurPositions : result is set");
|
||||
// NOLINTBEGIN(bugprone-unchecked-optional-access) assert above
|
||||
using namespace telemetry;
|
||||
// Child of the establish span via its captured context (establishSpan_ is
|
||||
// a thread-free SpanGuard, so parent explicitly via its context). A null
|
||||
// context — the establish phase has not started — yields a null guard, so
|
||||
// the setAttribute calls below are no-ops.
|
||||
auto span = SpanGuard::childSpan(consensus::span::updatePositions, establishSpanContext_);
|
||||
span.setAttribute(
|
||||
consensus::span::attr::convergePercent, static_cast<int64_t>(convergePercent_));
|
||||
span.setAttribute(
|
||||
consensus::span::attr::proposers, static_cast<int64_t>(currPeerPositions_.size()));
|
||||
span.setAttribute(
|
||||
consensus::span::attr::disputesCount, static_cast<int64_t>(result_->disputes.size()));
|
||||
ConsensusParms const& parms = adaptor_.parms();
|
||||
|
||||
// Compute a cutoff time
|
||||
@@ -1536,6 +1758,24 @@ Consensus<Adaptor>::updateOurPositions(std::unique_ptr<std::stringstream> const&
|
||||
// now a no
|
||||
mutableSet->erase(txId);
|
||||
}
|
||||
|
||||
// The event exists only for the span, so it is guarded on the
|
||||
// span being active. Unguarded, every dispute that flips
|
||||
// position builds a 64-character tx hash plus two number
|
||||
// strings, on every establish tick.
|
||||
if (span)
|
||||
{
|
||||
auto const yaysStr = std::to_string(dispute.getYays());
|
||||
auto const naysStr = std::to_string(dispute.getNays());
|
||||
span.addEvent(
|
||||
consensus::span::event::disputeResolve,
|
||||
{{consensus::span::attr::txId, to_string(txId)},
|
||||
{consensus::span::attr::disputeOurVote,
|
||||
dispute.getOurVote() ? std::string_view{consensus::span::val::yes}
|
||||
: std::string_view{consensus::span::val::no}},
|
||||
{consensus::span::attr::disputeYays, yaysStr},
|
||||
{consensus::span::attr::disputeNays, naysStr}});
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1560,6 +1800,8 @@ Consensus<Adaptor>::updateOurPositions(std::unique_ptr<std::stringstream> const&
|
||||
if (newState)
|
||||
closeTimeAvalancheState_ = *newState;
|
||||
CLOG(clog) << "neededWeight " << neededWeight << ". ";
|
||||
span.setAttribute(
|
||||
consensus::span::attr::avalancheThreshold, static_cast<int64_t>(neededWeight));
|
||||
|
||||
int participants = currPeerPositions_.size();
|
||||
if (mode_.get() == ConsensusMode::Proposing)
|
||||
@@ -1614,6 +1856,10 @@ Consensus<Adaptor>::updateOurPositions(std::unique_ptr<std::stringstream> const&
|
||||
}
|
||||
}
|
||||
|
||||
span.setAttribute(consensus::span::attr::haveCloseTimeConsensus, haveCloseTimeConsensus_);
|
||||
span.setAttribute(
|
||||
consensus::span::attr::closeTimeThreshold, static_cast<int64_t>(parms.avCtConsensusPct));
|
||||
|
||||
if (!ourNewSet &&
|
||||
((consensusCloseTime != asCloseTime(result_->position.closeTime())) ||
|
||||
result_->position.isStale(ourCutoff)))
|
||||
@@ -1665,6 +1911,10 @@ Consensus<Adaptor>::haveConsensus(std::unique_ptr<std::stringstream> const& clog
|
||||
// Must have a stance if we are checking for consensus
|
||||
XRPL_ASSERT(result_, "xrpl::Consensus::haveConsensus : has result");
|
||||
// NOLINTBEGIN(bugprone-unchecked-optional-access) assert above
|
||||
using namespace telemetry;
|
||||
// Child of the establish span via its captured context (establishSpan_ is
|
||||
// a thread-free SpanGuard, so parent explicitly via its context).
|
||||
auto span = SpanGuard::childSpan(consensus::span::check, establishSpanContext_);
|
||||
|
||||
// CHECKME: should possibly count unacquired TX sets as disagreeing
|
||||
int agree = 0, disagree = 0;
|
||||
@@ -1723,6 +1973,38 @@ Consensus<Adaptor>::haveConsensus(std::unique_ptr<std::stringstream> const& clog
|
||||
j_,
|
||||
clog);
|
||||
|
||||
// Set span attributes before the early-return branches below so the
|
||||
// consensus.check span carries diagnostic data even when consensus is
|
||||
// not reached (the No / Expired paths return early).
|
||||
span.setAttribute(consensus::span::attr::agreeCount, static_cast<int64_t>(agree));
|
||||
span.setAttribute(consensus::span::attr::disagreeCount, static_cast<int64_t>(disagree));
|
||||
span.setAttribute(
|
||||
consensus::span::attr::convergePercent, static_cast<int64_t>(convergePercent_));
|
||||
span.setAttribute(consensus::span::attr::haveCloseTimeConsensus, haveCloseTimeConsensus_);
|
||||
span.setAttribute(
|
||||
consensus::span::attr::thresholdPercent,
|
||||
static_cast<int64_t>(adaptor_.parms().avCtConsensusPct));
|
||||
span.setAttribute(
|
||||
consensus::span::attr::proposersFinished, static_cast<int64_t>(currentFinished));
|
||||
span.setAttribute(consensus::span::attr::consensusStalled, stalled);
|
||||
span.setAttribute(
|
||||
consensus::span::attr::establishCount, static_cast<int64_t>(establishCounter_));
|
||||
|
||||
std::string_view stateStr = consensus::span::val::no;
|
||||
if (result_->state == ConsensusState::Yes)
|
||||
{
|
||||
stateStr = consensus::span::val::yes;
|
||||
}
|
||||
else if (result_->state == ConsensusState::MovedOn)
|
||||
{
|
||||
stateStr = consensus::span::val::movedOn;
|
||||
}
|
||||
else if (result_->state == ConsensusState::Expired)
|
||||
{
|
||||
stateStr = consensus::span::val::expired;
|
||||
}
|
||||
span.setAttribute(consensus::span::attr::consensusResult, stateStr);
|
||||
|
||||
if (result_->state == ConsensusState::No)
|
||||
{
|
||||
CLOG(clog) << "No consensus. ";
|
||||
@@ -1885,4 +2167,89 @@ Consensus<Adaptor>::asCloseTime(NetClock::time_point raw) const
|
||||
return roundCloseTime(raw, closeResolution_);
|
||||
}
|
||||
|
||||
template <class Adaptor>
|
||||
void
|
||||
Consensus<Adaptor>::annotateOpenStart(StartRoundReason const reason, Ledger_t const& prevLedger)
|
||||
{
|
||||
if (!openSpan_ || !*openSpan_)
|
||||
return;
|
||||
namespace cs = telemetry::consensus::span;
|
||||
openSpan_->setAttribute(
|
||||
cs::attr::startReason,
|
||||
reason == StartRoundReason::Recovered ? std::string_view{cs::val::startRecovered}
|
||||
: std::string_view{cs::val::startInitial});
|
||||
// From the parameter: previousLedger_ is not assigned until later.
|
||||
openSpan_->setAttribute(cs::attr::previousCloseAgree, prevLedger.closeAgree());
|
||||
}
|
||||
|
||||
template <class Adaptor>
|
||||
void
|
||||
Consensus<Adaptor>::annotateOpenClose(
|
||||
LedgerCloseReason const closeReason,
|
||||
std::size_t const proposersValidated)
|
||||
{
|
||||
// Called before closeLedger() ends the span, and only on the closing tick,
|
||||
// so each attribute is written once per round.
|
||||
if (!openSpan_ || !*openSpan_)
|
||||
return;
|
||||
namespace cs = telemetry::consensus::span;
|
||||
openSpan_->setAttribute(cs::attr::closeReason, cs::closeReasonLabel(closeReason));
|
||||
openSpan_->setAttribute(cs::attr::proposersValidated, static_cast<int64_t>(proposersValidated));
|
||||
}
|
||||
|
||||
template <class Adaptor>
|
||||
void
|
||||
Consensus<Adaptor>::startEstablishTracing()
|
||||
{
|
||||
if (establishSpan_)
|
||||
return;
|
||||
// Child of the round span via its captured context: parent establish
|
||||
// explicitly under roundSpanContext_. An invalid round context (round span
|
||||
// not yet created) yields a null guard.
|
||||
establishSpan_.emplace(
|
||||
telemetry::SpanGuard::childSpan(
|
||||
telemetry::consensus::span::establish, adaptor_.roundSpanContext()));
|
||||
// Capture the establish context; children (update_positions, check) parent
|
||||
// to it explicitly via establishSpanContext_. establishSpan_ is a
|
||||
// thread-free SpanGuard reset() on a different worker than it is emplaced
|
||||
// on -- no scope work.
|
||||
if (*establishSpan_)
|
||||
{
|
||||
establishSpanContext_ = establishSpan_->spanContext();
|
||||
}
|
||||
}
|
||||
|
||||
template <class Adaptor>
|
||||
void
|
||||
Consensus<Adaptor>::updateEstablishTracing()
|
||||
{
|
||||
if (!establishSpan_)
|
||||
return;
|
||||
namespace cs = telemetry::consensus::span;
|
||||
establishSpan_->setAttribute(cs::attr::convergePercent, static_cast<int64_t>(convergePercent_));
|
||||
establishSpan_->setAttribute(cs::attr::establishCount, static_cast<int64_t>(establishCounter_));
|
||||
establishSpan_->setAttribute(
|
||||
cs::attr::proposers, static_cast<int64_t>(currPeerPositions_.size()));
|
||||
if (result_)
|
||||
{
|
||||
establishSpan_->setAttribute(
|
||||
cs::attr::disputesCount, static_cast<int64_t>(result_->disputes.size()));
|
||||
}
|
||||
}
|
||||
|
||||
template <class Adaptor>
|
||||
void
|
||||
Consensus<Adaptor>::endEstablishTracing()
|
||||
{
|
||||
// Terminal convergence regime, recorded once before the span ends.
|
||||
if (establishSpan_ && *establishSpan_)
|
||||
{
|
||||
namespace cs = telemetry::consensus::span;
|
||||
establishSpan_->setAttribute(
|
||||
cs::attr::closeTimeAvalancheState, cs::avalancheStateLabel(closeTimeAvalancheState_));
|
||||
}
|
||||
establishSpan_.reset();
|
||||
establishSpanContext_ = telemetry::SpanContext{};
|
||||
}
|
||||
|
||||
} // namespace xrpl
|
||||
|
||||
86
include/xrpl/consensus/ConsensusSpanLabels.h
Normal file
86
include/xrpl/consensus/ConsensusSpanLabels.h
Normal file
@@ -0,0 +1,86 @@
|
||||
#pragma once
|
||||
|
||||
/**
|
||||
* Enum-to-label mappings for consensus span attribute values.
|
||||
*
|
||||
* These mappings live in their own header so ConsensusSpanNames.h stays
|
||||
* dependency-free like its siblings: the span-name and attribute-key
|
||||
* constants are included by overlay and app translation units that have no
|
||||
* use for the consensus enums, while these mappings are needed only by
|
||||
* Consensus.h.
|
||||
*
|
||||
* ConsensusSpanNames.h (constants only, no domain deps)
|
||||
* ^
|
||||
* | includes
|
||||
* ConsensusSpanLabels.h --includes--> ConsensusParms.h, ConsensusTypes.h
|
||||
* ^
|
||||
* | includes
|
||||
* Consensus.h
|
||||
*/
|
||||
|
||||
#include <xrpl/consensus/ConsensusParms.h>
|
||||
#include <xrpl/consensus/ConsensusSpanNames.h>
|
||||
#include <xrpl/consensus/ConsensusTypes.h>
|
||||
|
||||
#include <string_view>
|
||||
|
||||
namespace xrpl::telemetry::consensus::span {
|
||||
|
||||
/**
|
||||
* Map a close-time avalanche state to its `avalanche_state` label.
|
||||
*
|
||||
* The regime escalates Init -> Mid -> Late -> Stuck, raising the close-time
|
||||
* agreement threshold at each step.
|
||||
*
|
||||
* @param state The state held by Consensus::closeTimeAvalancheState_.
|
||||
* @return The wire label; one of val::avalanche*.
|
||||
*
|
||||
* @note No default arm, so a new enumerator is a -Wswitch warning; the
|
||||
* fall-through returns "unknown" rather than a plausible-looking regime.
|
||||
*/
|
||||
[[nodiscard]] constexpr std::string_view
|
||||
avalancheStateLabel(ConsensusParms::AvalancheState const state)
|
||||
{
|
||||
switch (state)
|
||||
{
|
||||
case ConsensusParms::AvalancheState::Init:
|
||||
return val::avalancheInit;
|
||||
case ConsensusParms::AvalancheState::Mid:
|
||||
return val::avalancheMid;
|
||||
case ConsensusParms::AvalancheState::Late:
|
||||
return val::avalancheLate;
|
||||
case ConsensusParms::AvalancheState::Stuck:
|
||||
return val::avalancheStuck;
|
||||
}
|
||||
return val::unknown;
|
||||
}
|
||||
|
||||
/**
|
||||
* Map a ledger-close decision to its `close_reason` label.
|
||||
*
|
||||
* @param reason The value returned by whyCloseLedger().
|
||||
* @return The wire label; one of val::close*.
|
||||
*
|
||||
* @note No default arm, so a new enumerator is a -Wswitch warning; the
|
||||
* fall-through returns "unknown". `keep_open` is mapped but never emitted.
|
||||
*/
|
||||
[[nodiscard]] constexpr std::string_view
|
||||
closeReasonLabel(LedgerCloseReason const reason)
|
||||
{
|
||||
switch (reason)
|
||||
{
|
||||
case LedgerCloseReason::KeepOpen:
|
||||
return val::closeKeepOpen;
|
||||
case LedgerCloseReason::Anomaly:
|
||||
return val::closeAnomaly;
|
||||
case LedgerCloseReason::OthersClosed:
|
||||
return val::closeOthersClosed;
|
||||
case LedgerCloseReason::Idle:
|
||||
return val::closeIdle;
|
||||
case LedgerCloseReason::Normal:
|
||||
return val::closeNormal;
|
||||
}
|
||||
return val::unknown;
|
||||
}
|
||||
|
||||
} // namespace xrpl::telemetry::consensus::span
|
||||
383
include/xrpl/consensus/ConsensusSpanNames.h
Normal file
383
include/xrpl/consensus/ConsensusSpanNames.h
Normal file
@@ -0,0 +1,383 @@
|
||||
#pragma once
|
||||
|
||||
/**
|
||||
* Compile-time span name constants for consensus tracing.
|
||||
*
|
||||
* Used by RCLConsensus (app), Consensus.h (template), and PeerImp
|
||||
* (overlay) for consensus lifecycle spans.
|
||||
* Built on StaticStr/join() from SpanNames.h.
|
||||
*
|
||||
* ## Span Hierarchy
|
||||
*
|
||||
* Root span created in Adaptor::startRoundTracing(). In "deterministic"
|
||||
* strategy the trace-id is derived from the previous ledger hash so all
|
||||
* nodes tracing the same round share a trace.
|
||||
*
|
||||
* consensus.round [main thread, root]
|
||||
* | Created: Adaptor::startRoundTracing()
|
||||
* | Attrs: consensus_ledger_id, ledger_seq, trace_strategy,
|
||||
* | consensus_round_id; consensus_mode from
|
||||
* | Adaptor::onModeChange()
|
||||
* |
|
||||
* +-- consensus.phase.open [main thread, child]
|
||||
* | Created: Consensus::startRoundInternal()
|
||||
* | Ended: Consensus::closeLedger()
|
||||
* | Attrs: start_reason, previous_close_agree, peer_positions_at_open,
|
||||
* | early_close_triggered (at start); open_duration_ms,
|
||||
* | peer_positions_at_close, tx_sets_acquired, close_reason,
|
||||
* | proposers_validated (at close; absent if the round is
|
||||
* | recovered or simulated, neither of which reaches
|
||||
* | closeLedger())
|
||||
* |
|
||||
* +-- consensus.proposal.send [main thread]
|
||||
* | Created: Adaptor::propose()
|
||||
* | Attrs: consensus_round (proposeSeq)
|
||||
* |
|
||||
* +-- consensus.ledger_close [main thread]
|
||||
* | Created: Adaptor::onClose()
|
||||
* | Attrs: ledger_seq, consensus_mode
|
||||
* |
|
||||
* +-- consensus.establish [main thread, child]
|
||||
* | Created: Consensus::startEstablishTracing()
|
||||
* | Ended: Consensus::phaseEstablish() on accept
|
||||
* | Attrs: converge_percent, establish_count, proposers,
|
||||
* | disputes_count (overwritten each iteration);
|
||||
* | close_time_avalanche_state (terminal, at end)
|
||||
* |
|
||||
* +-- consensus.update_positions [main thread]
|
||||
* | Created: Consensus::updateOurPositions()
|
||||
* | Attrs: converge_percent, proposers, disputes_count
|
||||
* | Events: per-dispute vote details (tx_id, our_vote, yays, nays)
|
||||
* |
|
||||
* +-- consensus.check [main thread]
|
||||
* | Created: Consensus::haveConsensus()
|
||||
* | Attrs: agree/disagree counts, threshold_percent, result
|
||||
* |
|
||||
* +-- consensus.accept [main thread, child of round]
|
||||
* | Created: Adaptor::makeAcceptSpan(), shared_ptr kept alive
|
||||
* | until doAccept() completes on jtACCEPT thread
|
||||
* | Attrs: proposers, round_time_ms, quorum
|
||||
* | |
|
||||
* | +-- consensus.accept.apply [jtACCEPT thread, child of accept]
|
||||
* | Created: Adaptor::doAccept()
|
||||
* | Attrs: ledger_seq, close_time_ripple_epoch_s, close_time_correct,
|
||||
* | close_resolution_ms, consensus_state, proposing, round_time_ms,
|
||||
* | parent_close_time_ripple_epoch_s, close_time_self_ripple_epoch_s,
|
||||
* | close_time_vote_bins, resolution_direction, tx_count
|
||||
* | Events: tx.included (per tx, attrs: tx_id)
|
||||
* |
|
||||
* +~~~ consensus.validation.send [jtACCEPT thread, linked]
|
||||
* | Created: Adaptor::createValidationSpan() (follows-from link)
|
||||
* | Attrs: ledger_seq, proposing
|
||||
* |
|
||||
* +-- consensus.mode_change [main thread]
|
||||
* Created: Adaptor::onModeChange()
|
||||
* Attrs: mode_old, mode_new
|
||||
*
|
||||
* Standalone spans (no parent, created per-message in overlay):
|
||||
*
|
||||
* consensus.proposal.receive [PeerImp I/O thread]
|
||||
* Created: PeerImp::onMessage(TMProposeSet)
|
||||
*
|
||||
* consensus.validation.receive [PeerImp I/O thread]
|
||||
* Created: PeerImp::onMessage(TMValidation)
|
||||
*
|
||||
* Legend:
|
||||
* +-- child-of relationship (same trace)
|
||||
* +~~~ follows-from link (separate sub-tree, causal link)
|
||||
*/
|
||||
|
||||
#include <xrpl/telemetry/SpanNames.h>
|
||||
|
||||
namespace xrpl::telemetry::consensus::span {
|
||||
|
||||
// ===== Span name segments ====================================================
|
||||
|
||||
namespace part {
|
||||
inline constexpr auto proposal = makeStr("proposal");
|
||||
inline constexpr auto validation = makeStr("validation");
|
||||
inline constexpr auto accept = makeStr("accept");
|
||||
inline constexpr auto phase = makeStr("phase");
|
||||
} // namespace part
|
||||
|
||||
namespace op {
|
||||
inline constexpr auto round = makeStr("round");
|
||||
inline constexpr auto proposalSend = join(part::proposal, makeStr("send"));
|
||||
inline constexpr auto ledgerClose = makeStr("ledger_close");
|
||||
inline constexpr auto establish = makeStr("establish");
|
||||
inline constexpr auto updatePositions = makeStr("update_positions");
|
||||
inline constexpr auto check = makeStr("check");
|
||||
inline constexpr auto accept = makeStr("accept");
|
||||
inline constexpr auto acceptApply = join(part::accept, makeStr("apply"));
|
||||
inline constexpr auto validationSend = join(part::validation, makeStr("send"));
|
||||
inline constexpr auto modeChange = makeStr("mode_change");
|
||||
inline constexpr auto proposalReceive = join(part::proposal, makeStr("receive"));
|
||||
inline constexpr auto validationReceive = join(part::validation, makeStr("receive"));
|
||||
inline constexpr auto phaseOpen = join(part::phase, makeStr("open"));
|
||||
} // namespace op
|
||||
|
||||
// ===== Full span names (prefix.op) ===========================================
|
||||
|
||||
inline constexpr auto round = join(seg::consensus, op::round);
|
||||
inline constexpr auto proposalSend = join(seg::consensus, op::proposalSend);
|
||||
inline constexpr auto ledgerClose = join(seg::consensus, op::ledgerClose);
|
||||
inline constexpr auto establish = join(seg::consensus, op::establish);
|
||||
inline constexpr auto updatePositions = join(seg::consensus, op::updatePositions);
|
||||
inline constexpr auto check = join(seg::consensus, op::check);
|
||||
inline constexpr auto accept = join(seg::consensus, op::accept);
|
||||
inline constexpr auto acceptApply = join(seg::consensus, op::acceptApply);
|
||||
inline constexpr auto validationSend = join(seg::consensus, op::validationSend);
|
||||
inline constexpr auto modeChange = join(seg::consensus, op::modeChange);
|
||||
inline constexpr auto proposalReceive = join(seg::consensus, op::proposalReceive);
|
||||
inline constexpr auto validationReceive = join(seg::consensus, op::validationReceive);
|
||||
inline constexpr auto phaseOpen = join(seg::consensus, op::phaseOpen);
|
||||
|
||||
// ===== Attribute keys ========================================================
|
||||
|
||||
namespace attr {
|
||||
/**
|
||||
* Canonical shared constants (defined in SpanNames.h). `ledgerHash` and
|
||||
* `fullValidation` are shared with the peer.validation.receive span — same
|
||||
* concept, same key, distinguished by span name (not an emitter prefix).
|
||||
*/
|
||||
using ::xrpl::telemetry::attr::closeResolutionMs;
|
||||
using ::xrpl::telemetry::attr::closeTimeCorrect;
|
||||
using ::xrpl::telemetry::attr::closeTimeRippleEpochS;
|
||||
using ::xrpl::telemetry::attr::fullValidation;
|
||||
using ::xrpl::telemetry::attr::ledgerHash;
|
||||
using ::xrpl::telemetry::attr::ledgerSeq;
|
||||
|
||||
/**
|
||||
* Domain-qualified attrs (rule 5 — bare name ambiguous across domains).
|
||||
* Use `<domain>_<field>` underscore form for TraceQL ergonomics.
|
||||
*/
|
||||
inline constexpr auto ledgerId = makeStr("consensus_ledger_id");
|
||||
/**
|
||||
* Consensus mode. On consensus.round it is written by onModeChange, the point
|
||||
* at which the engine applies the mode; on consensus.ledger_close the engine
|
||||
* passes the mode in.
|
||||
*/
|
||||
inline constexpr auto mode = makeStr("consensus_mode");
|
||||
inline constexpr auto round = makeStr("consensus_round");
|
||||
inline constexpr auto roundId = makeStr("consensus_round_id");
|
||||
/**
|
||||
* Current phase name attached to consensus.round; updated on each
|
||||
* phase transition event (open/establish/accepted).
|
||||
*/
|
||||
inline constexpr auto consensusPhase = makeStr("consensus_phase");
|
||||
/**
|
||||
* Boolean flag set on consensus.check when checkConsensus reports stalled.
|
||||
*/
|
||||
inline constexpr auto consensusStalled = makeStr("consensus_stalled");
|
||||
|
||||
/**
|
||||
* Domain-owned bare attrs.
|
||||
*/
|
||||
inline constexpr auto proposers = makeStr("proposers");
|
||||
inline constexpr auto roundTimeMs = makeStr("round_time_ms");
|
||||
inline constexpr auto proposing = makeStr("proposing");
|
||||
/**
|
||||
* Round continuity / context attrs (set on consensus.round at round start).
|
||||
*/
|
||||
inline constexpr auto previousProposers = makeStr("previous_proposers");
|
||||
inline constexpr auto previousRoundTimeMs = makeStr("previous_round_time_ms");
|
||||
inline constexpr auto previousLedgerSeq = makeStr("previous_ledger_seq");
|
||||
inline constexpr auto closeTimeResolutionMs = makeStr("close_time_resolution_ms");
|
||||
/**
|
||||
* Open-phase start metadata (set on consensus.phase.open at creation).
|
||||
*
|
||||
* A handleWrongLedger recovery emits a SECOND phase.open span under the same
|
||||
* round, so `start_reason` is what tells the two apart.
|
||||
*/
|
||||
inline constexpr auto startReason = makeStr("start_reason");
|
||||
inline constexpr auto previousCloseAgree = makeStr("previous_close_agree");
|
||||
inline constexpr auto peerPositionsAtOpen = makeStr("peer_positions_at_open");
|
||||
inline constexpr auto earlyCloseTriggered = makeStr("early_close_triggered");
|
||||
/**
|
||||
* Open-phase end metadata (set on consensus.phase.open before reset).
|
||||
*
|
||||
* `proposers_validated` counts validators of the previous ledger, unlike
|
||||
* `proposers_finished` below, which counts those already past it.
|
||||
*/
|
||||
inline constexpr auto openDurationMs = makeStr("open_duration_ms");
|
||||
inline constexpr auto peerPositionsAtClose = makeStr("peer_positions_at_close");
|
||||
inline constexpr auto txSetsAcquired = makeStr("tx_sets_acquired");
|
||||
inline constexpr auto closeReason = makeStr("close_reason");
|
||||
inline constexpr auto proposersValidated = makeStr("proposers_validated");
|
||||
/**
|
||||
* Ledger-close inputs.
|
||||
*/
|
||||
inline constexpr auto txCountOpen = makeStr("tx_count_open");
|
||||
/**
|
||||
* Establish/check additional state.
|
||||
*/
|
||||
inline constexpr auto proposersFinished = makeStr("proposers_finished");
|
||||
/**
|
||||
* Establish-phase end metadata.
|
||||
*
|
||||
* The terminal close-time regime, set once. Qualified because DisputedTx
|
||||
* tracks a SECOND, per-transaction avalanche; this is not that one. The
|
||||
* derived `avalanche_threshold` cannot be inverted back to it.
|
||||
*/
|
||||
inline constexpr auto closeTimeAvalancheState = makeStr("close_time_avalanche_state");
|
||||
/**
|
||||
* Accept/apply enrichment.
|
||||
*/
|
||||
inline constexpr auto disputesResolvedCount = makeStr("disputes_resolved_count");
|
||||
/**
|
||||
* Validation send/receive enrichment. (`full_validation` is shared — see the
|
||||
* `using` re-export above.)
|
||||
*/
|
||||
inline constexpr auto validationSignTime = makeStr("validation_sign_time");
|
||||
/**
|
||||
* Receive-side hash prefixes for cross-peer correlation.
|
||||
*/
|
||||
inline constexpr auto prevLedgerPrefix = makeStr("prev_ledger_prefix");
|
||||
inline constexpr auto positionHashPrefix = makeStr("position_hash_prefix");
|
||||
/**
|
||||
* "consensus_state" — domain-qualified (collides with other domains' state).
|
||||
*/
|
||||
inline constexpr auto consensusState = makeStr("consensus_state");
|
||||
/**
|
||||
* Close-time instants, both NetClock readings in whole seconds since the XRP
|
||||
* Ledger epoch (2000-01-01T00:00:00Z) — see `closeTimeRippleEpochS` in
|
||||
* SpanNames.h for why the epoch is spelled into the key.
|
||||
*
|
||||
* `parentCloseTimeRippleEpochS` is the previous ledger's close time;
|
||||
* `closeTimeSelfRippleEpochS` is this node's own close-time vote for the round,
|
||||
* so the pair shows how far the node's position sat from the ledger it built on.
|
||||
*
|
||||
* `closeTimeVoteBins` is not a time: it holds the number of distinct close-time
|
||||
* positions seen from peers this round.
|
||||
*/
|
||||
inline constexpr auto parentCloseTimeRippleEpochS = makeStr("parent_close_time_ripple_epoch_s");
|
||||
inline constexpr auto closeTimeSelfRippleEpochS = makeStr("close_time_self_ripple_epoch_s");
|
||||
inline constexpr auto closeTimeVoteBins = makeStr("close_time_vote_bins");
|
||||
inline constexpr auto resolutionDirection = makeStr("resolution_direction");
|
||||
inline constexpr auto convergePercent = makeStr("converge_percent");
|
||||
inline constexpr auto establishCount = makeStr("establish_count");
|
||||
inline constexpr auto avalancheThreshold = makeStr("avalanche_threshold");
|
||||
inline constexpr auto closeTimeThreshold = makeStr("close_time_threshold");
|
||||
inline constexpr auto haveCloseTimeConsensus = makeStr("have_close_time_consensus");
|
||||
inline constexpr auto agreeCount = makeStr("agree_count");
|
||||
inline constexpr auto disagreeCount = makeStr("disagree_count");
|
||||
inline constexpr auto thresholdPercent = makeStr("threshold_percent");
|
||||
/**
|
||||
* "consensus_result" — domain-qualified (collides with generic result).
|
||||
*/
|
||||
inline constexpr auto consensusResult = makeStr("consensus_result");
|
||||
inline constexpr auto quorum = makeStr("quorum");
|
||||
inline constexpr auto traceStrategy = makeStr("trace_strategy");
|
||||
inline constexpr auto modeOld = makeStr("mode_old");
|
||||
inline constexpr auto modeNew = makeStr("mode_new");
|
||||
|
||||
/**
|
||||
* "is_bow_out" — whether this proposal is a bow-out (resigning from round).
|
||||
*/
|
||||
inline constexpr auto isBowOut = makeStr("is_bow_out");
|
||||
|
||||
/**
|
||||
* Transaction/dispute attrs used in consensus accept spans.
|
||||
*/
|
||||
inline constexpr auto txId = makeStr("tx_id");
|
||||
inline constexpr auto disputeOurVote = makeStr("dispute_our_vote");
|
||||
inline constexpr auto disputeYays = makeStr("dispute_yays");
|
||||
inline constexpr auto disputeNays = makeStr("dispute_nays");
|
||||
inline constexpr auto txCount = makeStr("tx_count");
|
||||
inline constexpr auto disputesCount = makeStr("disputes_count");
|
||||
/**
|
||||
* Trust flag (is the message origin a trusted UNL validator). Qualified by
|
||||
* message type, shared with the peer.{proposal,validation}.receive spans:
|
||||
* consensus.proposal.receive uses `proposal_trusted`, consensus.validation.
|
||||
* receive uses `validation_trusted`. Same concept on both emitters → same key.
|
||||
*/
|
||||
inline constexpr auto proposalTrusted = makeStr("proposal_trusted");
|
||||
inline constexpr auto validationTrusted = makeStr("validation_trusted");
|
||||
|
||||
/**
|
||||
* "validation_receive_status" — which exit the inbound validation took on
|
||||
* consensus.validation.receive. Set once per exit, so a dropped validation
|
||||
* (microseconds) is separable from a queued one (job wait plus
|
||||
* checkValidation); without it the span reports two unrelated latency
|
||||
* distributions and every quantile over it is meaningless.
|
||||
*
|
||||
* Deliberately NOT `validation_status`: that key belongs to
|
||||
* consensus.validation.accept and carries what the validation store did
|
||||
* (`ValStatus`). One key with two value domains would make any aggregation
|
||||
* that does not also filter on span name meaningless.
|
||||
*/
|
||||
inline constexpr auto validationReceiveStatus = makeStr("validation_receive_status");
|
||||
} // namespace attr
|
||||
|
||||
// ===== Event names ===========================================================
|
||||
|
||||
namespace event {
|
||||
/**
|
||||
* "dispute.resolve"
|
||||
*/
|
||||
inline constexpr auto disputeResolve = join(makeStr("dispute"), makeStr("resolve"));
|
||||
/**
|
||||
* "tx.included" — one per transaction of the agreed consensus set, recorded
|
||||
* before the ledger is built. A transaction that then fails to apply still
|
||||
* has an event, so this is a superset of the accepted ledger's contents.
|
||||
*/
|
||||
inline constexpr auto txIncluded = join(makeStr("tx"), makeStr("included"));
|
||||
|
||||
/**
|
||||
* Phase transition events — fired on consensus.round at each transition
|
||||
* so the round-level span carries a complete timeline of phase changes,
|
||||
* including the handleWrongLedger recovery edge that re-enters Open.
|
||||
*/
|
||||
inline constexpr auto phaseOpen = join(makeStr("phase"), makeStr("open"));
|
||||
inline constexpr auto phaseEstablish = join(makeStr("phase"), makeStr("establish"));
|
||||
inline constexpr auto phaseAccepted = join(makeStr("phase"), makeStr("accepted"));
|
||||
inline constexpr auto phaseRecovery = join(makeStr("phase"), makeStr("recovery"));
|
||||
|
||||
/**
|
||||
* Outcome events — fired on consensus.round at the establish→accepted
|
||||
* transition so the path that drove acceptance is queryable.
|
||||
*/
|
||||
inline constexpr auto outcomeYes = join(makeStr("outcome"), makeStr("yes"));
|
||||
inline constexpr auto outcomeMovedOn = join(makeStr("outcome"), makeStr("moved_on"));
|
||||
inline constexpr auto outcomeExpired = join(makeStr("outcome"), makeStr("expired"));
|
||||
} // namespace event
|
||||
|
||||
// ===== Attribute values ======================================================
|
||||
|
||||
namespace val {
|
||||
inline constexpr auto finished = makeStr("finished");
|
||||
inline constexpr auto movedOn = makeStr("moved_on");
|
||||
inline constexpr auto yes = makeStr("yes");
|
||||
inline constexpr auto no = makeStr("no");
|
||||
inline constexpr auto expired = makeStr("expired");
|
||||
inline constexpr auto increased = makeStr("increased");
|
||||
inline constexpr auto decreased = makeStr("decreased");
|
||||
inline constexpr auto unchanged = makeStr("unchanged");
|
||||
// consensus_phase attribute values (the phase the round is entering).
|
||||
inline constexpr auto phaseOpen = makeStr("open");
|
||||
inline constexpr auto phaseEstablish = makeStr("establish");
|
||||
inline constexpr auto phaseAccepted = makeStr("accepted");
|
||||
// start_reason values (how startRoundInternal was entered).
|
||||
inline constexpr auto startInitial = makeStr("initial");
|
||||
inline constexpr auto startRecovered = makeStr("recovered");
|
||||
// close_time_avalanche_state values, one per AvalancheState enumerator.
|
||||
inline constexpr auto avalancheInit = makeStr("init");
|
||||
inline constexpr auto avalancheMid = makeStr("mid");
|
||||
inline constexpr auto avalancheLate = makeStr("late");
|
||||
inline constexpr auto avalancheStuck = makeStr("stuck");
|
||||
// Sentinel for an unmapped enumerator, matching to_string(ConsensusPhase).
|
||||
inline constexpr auto unknown = makeStr("unknown");
|
||||
// close_reason values, one per LedgerCloseReason enumerator. keep_open is
|
||||
// never emitted: the attribute is only set on the path that closes.
|
||||
inline constexpr auto closeKeepOpen = makeStr("keep_open");
|
||||
inline constexpr auto closeAnomaly = makeStr("anomaly");
|
||||
inline constexpr auto closeOthersClosed = makeStr("others_closed");
|
||||
inline constexpr auto closeIdle = makeStr("idle");
|
||||
inline constexpr auto closeNormal = makeStr("normal");
|
||||
// validation_receive_status values, one per exit of the receive path.
|
||||
inline constexpr auto validationQueued = makeStr("queued");
|
||||
inline constexpr auto validationDroppedDiverged = makeStr("dropped_diverged");
|
||||
inline constexpr auto validationDroppedLoad = makeStr("dropped_load");
|
||||
} // namespace val
|
||||
|
||||
} // namespace xrpl::telemetry::consensus::span
|
||||
@@ -80,10 +80,32 @@ to_string(ConsensusMode m)
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Title Case display name for telemetry attributes and dashboards.
|
||||
* Separate from to_string() which is used in logs and must remain stable.
|
||||
*/
|
||||
inline std::string
|
||||
toDisplayString(ConsensusMode m)
|
||||
{
|
||||
switch (m)
|
||||
{
|
||||
case ConsensusMode::Proposing:
|
||||
return "Proposing";
|
||||
case ConsensusMode::Observing:
|
||||
return "Observing";
|
||||
case ConsensusMode::WrongLedger:
|
||||
return "Wrong Ledger";
|
||||
case ConsensusMode::SwitchedLedger:
|
||||
return "Switched Ledger";
|
||||
default:
|
||||
return "Unknown";
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Phases of consensus for a single ledger round.
|
||||
*
|
||||
* @code
|
||||
* @code
|
||||
* "close" "accept"
|
||||
* open ------- > establish ---------> accepted
|
||||
* ^ | |
|
||||
@@ -132,6 +154,41 @@ to_string(ConsensusPhase p)
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Why the open ledger should, or should not, close right now.
|
||||
*
|
||||
* Returned by whyCloseLedger(); shouldCloseLedger() reduces it to a bool.
|
||||
*
|
||||
* @note KeepOpen is not a close reason. Compare against it rather than
|
||||
* treating the enum as a flag.
|
||||
*/
|
||||
enum class LedgerCloseReason : std::uint8_t {
|
||||
/**
|
||||
* No close condition is met yet.
|
||||
*/
|
||||
KeepOpen,
|
||||
|
||||
/**
|
||||
* Timings out of range; close defensively.
|
||||
*/
|
||||
Anomaly,
|
||||
|
||||
/**
|
||||
* More than half the network has closed or validated.
|
||||
*/
|
||||
OthersClosed,
|
||||
|
||||
/**
|
||||
* Nothing waiting and the idle interval elapsed.
|
||||
*/
|
||||
Idle,
|
||||
|
||||
/**
|
||||
* Transactions waiting and both minimum-open floors met.
|
||||
*/
|
||||
Normal,
|
||||
};
|
||||
|
||||
/**
|
||||
* Measures the duration of phases of consensus
|
||||
*/
|
||||
|
||||
@@ -197,6 +197,24 @@ public:
|
||||
[[nodiscard]] json::Value
|
||||
getJson() const;
|
||||
|
||||
/**
|
||||
* Number of peers voting yes.
|
||||
*/
|
||||
[[nodiscard]] int
|
||||
getYays() const
|
||||
{
|
||||
return yays_;
|
||||
}
|
||||
|
||||
/**
|
||||
* Number of peers voting no.
|
||||
*/
|
||||
[[nodiscard]] int
|
||||
getNays() const
|
||||
{
|
||||
return nays_;
|
||||
}
|
||||
|
||||
private:
|
||||
int yays_{0}; //< Number of yes votes
|
||||
int nays_{0}; //< Number of no votes
|
||||
|
||||
@@ -6,7 +6,6 @@
|
||||
#include <xrpl/basics/TaggedCache.h>
|
||||
#include <xrpl/basics/base_uint.h>
|
||||
#include <xrpl/beast/utility/Journal.h>
|
||||
#include <xrpl/protocol/Fees.h>
|
||||
|
||||
#include <boost/asio.hpp>
|
||||
|
||||
@@ -25,6 +24,9 @@ class Manager;
|
||||
namespace perf {
|
||||
class PerfLog;
|
||||
} // namespace perf
|
||||
namespace telemetry {
|
||||
class Telemetry;
|
||||
} // namespace telemetry
|
||||
|
||||
// This is temporary until we migrate all code to use ServiceRegistry.
|
||||
class Application;
|
||||
@@ -225,6 +227,9 @@ public:
|
||||
virtual perf::PerfLog&
|
||||
getPerfLog() = 0;
|
||||
|
||||
virtual telemetry::Telemetry&
|
||||
getTelemetry() = 0;
|
||||
|
||||
// Configuration and state
|
||||
[[nodiscard]] virtual bool
|
||||
isStopping() const = 0;
|
||||
@@ -247,9 +252,6 @@ public:
|
||||
virtual DatabaseCon&
|
||||
getWalletDB() = 0;
|
||||
|
||||
[[nodiscard]] virtual Fees
|
||||
getFees() const = 0;
|
||||
|
||||
// Temporary: Get the underlying Application for functions that haven't
|
||||
// been migrated yet. This should be removed once all code is migrated.
|
||||
virtual Application&
|
||||
|
||||
@@ -528,7 +528,6 @@ public:
|
||||
using iterator_category = std::bidirectional_iterator_tag;
|
||||
using size_t = unsigned int;
|
||||
using difference_type = int;
|
||||
using value_type = Value;
|
||||
using SelfType = ValueIteratorBase;
|
||||
|
||||
ValueIteratorBase();
|
||||
|
||||
@@ -13,7 +13,6 @@
|
||||
#include <xrpl/protocol/TxMeta.h>
|
||||
|
||||
#include <cstddef>
|
||||
#include <cstdint>
|
||||
#include <functional>
|
||||
#include <optional>
|
||||
|
||||
@@ -69,18 +68,6 @@ public:
|
||||
deliver_ = amount;
|
||||
}
|
||||
|
||||
void
|
||||
setGasUsed(std::optional<std::uint32_t> const gasUsed)
|
||||
{
|
||||
gasUsed_ = gasUsed;
|
||||
}
|
||||
|
||||
void
|
||||
setVMReturnCode(std::int32_t const vmReturnCode)
|
||||
{
|
||||
vmReturnCode_ = vmReturnCode;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get the number of modified entries
|
||||
*/
|
||||
@@ -101,8 +88,6 @@ public:
|
||||
|
||||
private:
|
||||
std::optional<STAmount> deliver_;
|
||||
std::optional<std::uint32_t> gasUsed_;
|
||||
std::optional<std::int32_t> vmReturnCode_;
|
||||
};
|
||||
|
||||
} // namespace xrpl
|
||||
|
||||
@@ -78,12 +78,6 @@ public:
|
||||
return base_.succ(key, last);
|
||||
}
|
||||
|
||||
std::optional<key_type>
|
||||
pred(key_type const& key, std::optional<key_type> const& first = std::nullopt) const override
|
||||
{
|
||||
return base_.pred(key, first);
|
||||
}
|
||||
|
||||
std::unique_ptr<SlesType::iter_base>
|
||||
slesBegin() const override
|
||||
{
|
||||
|
||||
@@ -186,9 +186,6 @@ public:
|
||||
std::optional<uint256>
|
||||
succ(uint256 const& key, std::optional<uint256> const& last = std::nullopt) const override;
|
||||
|
||||
std::optional<uint256>
|
||||
pred(uint256 const& key, std::optional<uint256> const& first = std::nullopt) const override;
|
||||
|
||||
SLE::const_pointer
|
||||
read(Keylet const& k) const override;
|
||||
|
||||
|
||||
@@ -221,9 +221,6 @@ public:
|
||||
std::optional<key_type>
|
||||
succ(key_type const& key, std::optional<key_type> const& last = std::nullopt) const override;
|
||||
|
||||
std::optional<key_type>
|
||||
pred(key_type const& key, std::optional<key_type> const& first = std::nullopt) const override;
|
||||
|
||||
SLE::const_pointer
|
||||
read(Keylet const& k) const override;
|
||||
|
||||
|
||||
@@ -1,82 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/ledger/OpenView.h>
|
||||
|
||||
#include <memory>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
class OpenViewSandbox
|
||||
{
|
||||
private:
|
||||
OpenView& parent_;
|
||||
std::unique_ptr<OpenView> sandbox_;
|
||||
|
||||
public:
|
||||
using key_type = ReadView::key_type;
|
||||
|
||||
OpenViewSandbox(OpenView& parent)
|
||||
: parent_(parent), sandbox_(std::make_unique<OpenView>(kBatchView, parent))
|
||||
{
|
||||
}
|
||||
|
||||
void
|
||||
rawErase(std::shared_ptr<SLE> const& sle)
|
||||
{
|
||||
sandbox_->rawErase(sle);
|
||||
}
|
||||
|
||||
void
|
||||
rawInsert(std::shared_ptr<SLE> const& sle)
|
||||
{
|
||||
sandbox_->rawInsert(sle);
|
||||
}
|
||||
|
||||
void
|
||||
rawReplace(std::shared_ptr<SLE> const& sle)
|
||||
{
|
||||
sandbox_->rawReplace(sle);
|
||||
}
|
||||
|
||||
void
|
||||
rawDestroyXRP(XRPAmount const& fee)
|
||||
{
|
||||
sandbox_->rawDestroyXRP(fee);
|
||||
}
|
||||
|
||||
void
|
||||
rawTxInsert(
|
||||
key_type const& key,
|
||||
std::shared_ptr<Serializer const> const& txn,
|
||||
std::shared_ptr<Serializer const> const& metaData)
|
||||
{
|
||||
sandbox_->rawTxInsert(key, txn, metaData);
|
||||
}
|
||||
|
||||
void
|
||||
commit()
|
||||
{
|
||||
sandbox_->apply(parent_);
|
||||
sandbox_ = std::make_unique<OpenView>(kBatchView, parent_);
|
||||
}
|
||||
|
||||
void
|
||||
discard()
|
||||
{
|
||||
sandbox_ = std::make_unique<OpenView>(kBatchView, parent_);
|
||||
}
|
||||
|
||||
OpenView const&
|
||||
view() const
|
||||
{
|
||||
return *sandbox_;
|
||||
}
|
||||
|
||||
OpenView&
|
||||
view()
|
||||
{
|
||||
return *sandbox_;
|
||||
}
|
||||
};
|
||||
|
||||
} // namespace xrpl
|
||||
@@ -154,19 +154,6 @@ public:
|
||||
[[nodiscard]] virtual std::optional<key_type>
|
||||
succ(key_type const& key, std::optional<key_type> const& last = std::nullopt) const = 0;
|
||||
|
||||
/** Return the key of the previous state item.
|
||||
|
||||
This returns the key of the first state item
|
||||
whose key is less than the specified key. If
|
||||
no such key is present, std::nullopt is returned.
|
||||
|
||||
If `first` is engaged, returns std::nullopt when
|
||||
the key returned would be outside the open
|
||||
interval (first, key).
|
||||
*/
|
||||
[[nodiscard]] virtual std::optional<key_type>
|
||||
pred(key_type const& key, std::optional<key_type> const& first = std::nullopt) const = 0;
|
||||
|
||||
/**
|
||||
* Return the state item associated with a key.
|
||||
*
|
||||
|
||||
@@ -5,10 +5,6 @@
|
||||
#include <xrpl/beast/utility/Journal.h>
|
||||
#include <xrpl/ledger/ApplyView.h>
|
||||
#include <xrpl/ledger/ReadView.h>
|
||||
#include <xrpl/ledger/helpers/MPTokenHelpers.h>
|
||||
#include <xrpl/ledger/helpers/OfferHelpers.h>
|
||||
#include <xrpl/ledger/helpers/RippleStateHelpers.h>
|
||||
#include <xrpl/ledger/helpers/TokenHelpers.h>
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/Asset.h>
|
||||
#include <xrpl/protocol/Keylet.h>
|
||||
@@ -279,27 +275,6 @@ doWithdraw(
|
||||
STAmount const& amount,
|
||||
beast::Journal j);
|
||||
|
||||
enum class SendIssuerHandling { ihSENDER_NOT_ALLOWED, ihRECEIVER_NOT_ALLOWED, ihIGNORE };
|
||||
enum class SendEscrowHandling { ehIGNORE, ehCHECK };
|
||||
enum class SendAuthHandling { ahCHECK_SENDER, ahCHECK_RECEIVER, ahBOTH, ahNEITHER };
|
||||
enum class SendFreezeHandling { fhCHECK_SENDER, fhCHECK_RECEIVER, fhBOTH, fhNEITHER };
|
||||
enum class SendTransferHandling { thIGNORE, thCHECK };
|
||||
enum class SendBalanceHandling { bhIGNORE, bhCHECK };
|
||||
|
||||
TER
|
||||
canTransferFT(
|
||||
ReadView const& view,
|
||||
AccountID const& sender,
|
||||
AccountID const& receiver,
|
||||
STAmount const& amount,
|
||||
beast::Journal j,
|
||||
SendIssuerHandling issuerHandling,
|
||||
SendEscrowHandling escrowHandling,
|
||||
SendAuthHandling authHandling,
|
||||
SendFreezeHandling freezeHandling,
|
||||
SendTransferHandling transferHandling,
|
||||
SendBalanceHandling balanceHandling);
|
||||
|
||||
/**
|
||||
* Deleter function prototype. Returns the status of the entry deletion
|
||||
* (if should not be skipped) and if the entry should be skipped. The status
|
||||
|
||||
@@ -16,7 +16,6 @@
|
||||
#include <xrpl/protocol/XRPAmount.h>
|
||||
|
||||
#include <cstddef>
|
||||
#include <cstdint>
|
||||
#include <functional>
|
||||
#include <map>
|
||||
#include <optional>
|
||||
@@ -63,8 +62,6 @@ public:
|
||||
TER ter,
|
||||
std::optional<STAmount> const& deliver,
|
||||
std::optional<uint256 const> const& parentBatchId,
|
||||
std::optional<std::uint32_t> const& gasUsed,
|
||||
std::optional<std::int32_t> const& vmReturnCode,
|
||||
bool isDryRun,
|
||||
beast::Journal j);
|
||||
|
||||
@@ -74,9 +71,6 @@ public:
|
||||
[[nodiscard]] std::optional<key_type>
|
||||
succ(ReadView const& base, key_type const& key, std::optional<key_type> const& last) const;
|
||||
|
||||
[[nodiscard]] std::optional<key_type>
|
||||
pred(ReadView const& base, key_type const& key, std::optional<key_type> const& first) const;
|
||||
|
||||
[[nodiscard]] SLE::const_pointer
|
||||
read(ReadView const& base, Keylet const& k) const;
|
||||
|
||||
|
||||
@@ -50,9 +50,6 @@ public:
|
||||
[[nodiscard]] std::optional<key_type>
|
||||
succ(key_type const& key, std::optional<key_type> const& last = std::nullopt) const override;
|
||||
|
||||
[[nodiscard]] std::optional<key_type>
|
||||
pred(key_type const& key, std::optional<key_type> const& first = std::nullopt) const override;
|
||||
|
||||
[[nodiscard]] SLE::const_pointer
|
||||
read(Keylet const& k) const override;
|
||||
|
||||
|
||||
@@ -56,9 +56,6 @@ public:
|
||||
[[nodiscard]] std::optional<key_type>
|
||||
succ(ReadView const& base, key_type const& key, std::optional<key_type> const& last) const;
|
||||
|
||||
[[nodiscard]] std::optional<key_type>
|
||||
pred(ReadView const& base, key_type const& key, std::optional<key_type> const& first) const;
|
||||
|
||||
void
|
||||
erase(SLE::ref sle);
|
||||
|
||||
|
||||
@@ -1,249 +0,0 @@
|
||||
// Pluggable AMM curve architecture.
|
||||
// Concentrated liquidity (CurveType 1) based on XRPL-Standards Discussion #427
|
||||
// by Roman Thpt (@RomThpt), which adapted Uniswap v3 tick math, fee tier
|
||||
// structure, and fee accounting to the XRPL. This implementation extends that
|
||||
// work with a pluggable curve interface, StableSwap, and Smart AMM.
|
||||
// See: https://github.com/XRPLF/XRPL-Standards/discussions/427
|
||||
|
||||
#pragma once
|
||||
|
||||
#include <expected>
|
||||
#include <xrpl/basics/Number.h>
|
||||
#include <xrpl/ledger/helpers/AMMHelpers.h>
|
||||
#include <xrpl/protocol/AMMCore.h>
|
||||
#include <xrpl/protocol/AmountConversions.h>
|
||||
#include <xrpl/protocol/Indexes.h>
|
||||
#include <xrpl/protocol/Quality.h>
|
||||
#include <xrpl/protocol/Rules.h>
|
||||
#include <xrpl/protocol/SField.h>
|
||||
#include <xrpl/protocol/STAmount.h>
|
||||
#include <xrpl/protocol/STLedgerEntry.h>
|
||||
#include <xrpl/protocol/STObject.h>
|
||||
#include <xrpl/protocol/TER.h>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
class ReadView;
|
||||
class ApplyView;
|
||||
|
||||
struct CurveContext
|
||||
{
|
||||
ReadView const* view = nullptr;
|
||||
uint256 const* ammID = nullptr;
|
||||
// Optional out: set to true if a CL swap-walk terminated because it hit
|
||||
// maxTickCrossings. Callers pass a pointer when they want to detect
|
||||
// the cap (e.g. to emit tecAMM_TICK_CAP_HIT); pass nullptr to ignore.
|
||||
bool* tickCapHit = nullptr;
|
||||
};
|
||||
|
||||
class CurveInterface
|
||||
{
|
||||
public:
|
||||
virtual ~CurveInterface() = default;
|
||||
|
||||
virtual std::expected<STAmount, TER>
|
||||
swapIn(
|
||||
STAmount const& poolIn,
|
||||
STAmount const& poolOut,
|
||||
STAmount const& assetIn,
|
||||
std::uint16_t tfee,
|
||||
STObject const* ammSle,
|
||||
CurveContext const& ctx = {}) const = 0;
|
||||
|
||||
virtual std::expected<STAmount, TER>
|
||||
swapOut(
|
||||
STAmount const& poolIn,
|
||||
STAmount const& poolOut,
|
||||
STAmount const& assetOut,
|
||||
std::uint16_t tfee,
|
||||
STObject const* ammSle,
|
||||
CurveContext const& ctx = {}) const = 0;
|
||||
|
||||
virtual std::expected<Number, TER>
|
||||
spotPrice(
|
||||
STAmount const& poolIn,
|
||||
STAmount const& poolOut,
|
||||
std::uint16_t tfee,
|
||||
STObject const* ammSle,
|
||||
CurveContext const& ctx = {}) const = 0;
|
||||
|
||||
[[nodiscard]] virtual TER
|
||||
validateParams(STObject const& tx) const = 0;
|
||||
|
||||
virtual std::expected<STAmount, TER>
|
||||
initialLPTokens(
|
||||
STAmount const& asset1,
|
||||
STAmount const& asset2,
|
||||
Issue const& lptIssue,
|
||||
STObject const* txParams) const = 0;
|
||||
|
||||
virtual bool
|
||||
checkInvariant(
|
||||
STAmount const& oldIn,
|
||||
STAmount const& oldOut,
|
||||
STAmount const& newIn,
|
||||
STAmount const& newOut,
|
||||
STObject const* ammSle) const = 0;
|
||||
|
||||
// Apply a realized swap to the AMM SLE. Trustline balances are updated
|
||||
// by the caller (BookStep). For CP and StableSwap the pool state is fully
|
||||
// implicit in trustline balances, so the default is a no-op. CL must
|
||||
// mutate currentTick/activeLiquidity/feeGrowthGlobal and flip
|
||||
// feeGrowthOutside on crossed ticks, because none of that state is
|
||||
// derivable from the trustlines alone.
|
||||
virtual TER
|
||||
applySwap(
|
||||
ApplyView& /*view*/,
|
||||
uint256 const& /*ammID*/,
|
||||
STAmount const& /*assetIn*/,
|
||||
STAmount const& /*assetOut*/,
|
||||
std::uint16_t /*tfee*/,
|
||||
STObject const* /*curveParams*/) const
|
||||
{
|
||||
return tesSUCCESS;
|
||||
}
|
||||
};
|
||||
|
||||
CurveInterface const*
|
||||
getCurve(std::uint8_t curveType, Rules const& rules);
|
||||
|
||||
// Max output the pool can deliver before crossing the next initialised
|
||||
// tick boundary in the swap direction. Audit #19: caller (AMMLiquidity's
|
||||
// offer generation) uses this to cap an advertised AMM offer at the
|
||||
// current tick range, so the offer's quality reflects only the marginal
|
||||
// range — not a blended average across multiple tick crossings.
|
||||
//
|
||||
// Returns std::nullopt if there is no further tick in the swap direction
|
||||
// (no cap; offer is bounded only by reserves) or if the pool has no
|
||||
// active liquidity. Returns 0 if the swap is already at the boundary.
|
||||
// Caller should treat nullopt as "no cap".
|
||||
std::optional<Number>
|
||||
maxClOutputWithinCurrentRange(
|
||||
ReadView const& view,
|
||||
uint256 const& ammID,
|
||||
STObject const& ammSle,
|
||||
bool zeroForOne);
|
||||
|
||||
// Equivalent for CtBinned: cap the advertised AMMOffer output at the
|
||||
// active bin's reserve. Without this cap, AMMLiquidity quotes against
|
||||
// the pool's aggregate balance — which spans multiple bins at different
|
||||
// prices — and BookStep mispricesthe offer's quality vs CLOB. Capping
|
||||
// per active bin lets BookStep iterate naturally, getting each bin's
|
||||
// marginal price one offer at a time.
|
||||
//
|
||||
// Returns std::nullopt if no active bin exists (empty pool) or the
|
||||
// active bin lacks the output asset.
|
||||
std::optional<Number>
|
||||
maxBinnedOutputAtActiveBin(
|
||||
ReadView const& view,
|
||||
uint256 const& ammID,
|
||||
STObject const& ammSle,
|
||||
bool inIsAsset0);
|
||||
|
||||
// ─── CL tick bitmap ─────────────────────────────────────────────────────
|
||||
//
|
||||
// Sparse 256-tick-per-word presence bitmap. See spec §3.6.
|
||||
|
||||
// Convert a tick to its (wordIndex, bitInWord) position. Offset-binary so
|
||||
// arithmetic stays in unsigned domain. Uses kTickBitmapOffset (= -minTick)
|
||||
// from AMMCore.h — single source of truth, do NOT duplicate inline.
|
||||
inline std::pair<std::uint16_t, std::uint8_t>
|
||||
tickToBitmapPos(std::int32_t tick) noexcept
|
||||
{
|
||||
auto const offsetT = static_cast<std::uint32_t>(
|
||||
tick + static_cast<std::int32_t>(kTickBitmapOffset));
|
||||
return {static_cast<std::uint16_t>(offsetT >> 8),
|
||||
static_cast<std::uint8_t>(offsetT & 0xFFu)};
|
||||
}
|
||||
|
||||
inline std::int32_t
|
||||
bitmapPosToTick(std::uint16_t wordIndex, std::uint8_t bitInWord) noexcept
|
||||
{
|
||||
auto const offsetT =
|
||||
(static_cast<std::uint32_t>(wordIndex) << 8) | bitInWord;
|
||||
return static_cast<std::int32_t>(offsetT) -
|
||||
static_cast<std::int32_t>(kTickBitmapOffset);
|
||||
}
|
||||
|
||||
// Bit-test for the bitmap word storage. `bits` is the raw `sfBitmapBits`
|
||||
// value read off the SLE. Convention: bit i = LSB of byte (i/8), little-
|
||||
// endian within bytes. The convention is internal — callers that write
|
||||
// bits must use the same scheme (and do, via the maintenance helpers).
|
||||
inline bool
|
||||
bitmapBitIsSet(uint256 const& bits, std::uint8_t pos) noexcept
|
||||
{
|
||||
return ((bits.data()[pos / 8]) >> (pos % 8)) & 1u;
|
||||
}
|
||||
|
||||
// AMMDeposit and AMMWithdraw call these when a tick crosses the
|
||||
// "initialised / uninitialised" boundary (sfLiquidityGross transitioning
|
||||
// 0↔>0). Each pool has a sparse set of `ltAMM_TICK_BITMAP` SLEs covering
|
||||
// 256 ticks each; setting / clearing creates and deletes those SLEs on
|
||||
// demand. Idempotent — calling set on an already-set bit is a no-op.
|
||||
//
|
||||
// Returns tesSUCCESS on the happy path. The current implementation has
|
||||
// no failure path beyond the AMM SLE being missing; reserved as TER for
|
||||
// forward compatibility.
|
||||
TER
|
||||
setTickBitmap(ApplyView& view, uint256 const& ammID, std::int32_t tick, beast::Journal j);
|
||||
|
||||
TER
|
||||
clearTickBitmap(ApplyView& view, uint256 const& ammID, std::int32_t tick, beast::Journal j);
|
||||
|
||||
inline std::uint8_t
|
||||
getCurveType(SLE const& ammSle)
|
||||
{
|
||||
if (ammSle.isFieldPresent(sfCurveType))
|
||||
return ammSle.getFieldU8(sfCurveType);
|
||||
return CtConstantProduct;
|
||||
}
|
||||
|
||||
template <typename TIn, typename TOut>
|
||||
TOut
|
||||
curveSwapIn(
|
||||
TAmounts<TIn, TOut> const& pool,
|
||||
TIn const& assetIn,
|
||||
std::uint16_t tfee,
|
||||
std::uint8_t curveType,
|
||||
STObject const* ammSle,
|
||||
CurveContext const& cctx = {})
|
||||
{
|
||||
if (curveType == CtConstantProduct)
|
||||
return swapAssetIn(pool, assetIn, tfee);
|
||||
|
||||
if (auto const* curve = getCurve(curveType, *getCurrentTransactionRules()))
|
||||
{
|
||||
auto const stPoolIn = toSTAmount(pool.in);
|
||||
auto const stPoolOut = toSTAmount(pool.out);
|
||||
auto const stAssetIn = toSTAmount(assetIn);
|
||||
if (auto const result = curve->swapIn(stPoolIn, stPoolOut, stAssetIn, tfee, ammSle, cctx))
|
||||
return get<TOut>(*result);
|
||||
}
|
||||
return toAmount<TOut>(getAsset(pool.out), 0);
|
||||
}
|
||||
|
||||
template <typename TIn, typename TOut>
|
||||
TIn
|
||||
curveSwapOut(
|
||||
TAmounts<TIn, TOut> const& pool,
|
||||
TOut const& assetOut,
|
||||
std::uint16_t tfee,
|
||||
std::uint8_t curveType,
|
||||
STObject const* ammSle,
|
||||
CurveContext const& cctx = {})
|
||||
{
|
||||
if (curveType == CtConstantProduct)
|
||||
return swapAssetOut(pool, assetOut, tfee);
|
||||
|
||||
if (auto const* curve = getCurve(curveType, *getCurrentTransactionRules()))
|
||||
{
|
||||
auto const stPoolIn = toSTAmount(pool.in);
|
||||
auto const stPoolOut = toSTAmount(pool.out);
|
||||
auto const stAssetOut = toSTAmount(assetOut);
|
||||
if (auto const result = curve->swapOut(stPoolIn, stPoolOut, stAssetOut, tfee, ammSle, cctx))
|
||||
return get<TIn>(*result);
|
||||
}
|
||||
return toMaxAmount<TIn>(getAsset(pool.in));
|
||||
}
|
||||
|
||||
} // namespace xrpl
|
||||
@@ -837,8 +837,7 @@ ammLPHolds(
|
||||
Asset const& asset2,
|
||||
AccountID const& ammAccount,
|
||||
AccountID const& lpAccount,
|
||||
beast::Journal const j,
|
||||
std::uint8_t curveType = CtConstantProduct);
|
||||
beast::Journal const j);
|
||||
|
||||
STAmount
|
||||
ammLPHolds(
|
||||
@@ -866,12 +865,7 @@ ammAccountHolds(ReadView const& view, AccountID const& ammAccountID, Asset const
|
||||
* AMM object and account are deleted. Otherwise tecINCOMPLETE is returned.
|
||||
*/
|
||||
TER
|
||||
deleteAMMAccount(
|
||||
Sandbox& view,
|
||||
Asset const& asset,
|
||||
Asset const& asset2,
|
||||
beast::Journal j,
|
||||
std::uint8_t curveType = 0);
|
||||
deleteAMMAccount(Sandbox& view, Asset const& asset, Asset const& asset2, beast::Journal j);
|
||||
|
||||
/**
|
||||
* Initialize Auction and Voting slots and set the trading/discounted fee.
|
||||
|
||||
@@ -1,19 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/basics/Number.h>
|
||||
#include <xrpl/protocol/AMMCore.h>
|
||||
|
||||
#include <cstdint>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
Number
|
||||
tickToSqrtPrice(std::int32_t tick);
|
||||
|
||||
std::int32_t
|
||||
sqrtPriceToTick(Number const& sqrtPrice);
|
||||
|
||||
bool
|
||||
isValidTick(std::int32_t tick, std::int32_t tickSpacing);
|
||||
|
||||
} // namespace xrpl
|
||||
@@ -338,17 +338,6 @@ adjustLoanBrokerOwnerCount(
|
||||
[[nodiscard]] Rate
|
||||
transferRate(ReadView const& view, AccountID const& issuer);
|
||||
|
||||
/**
|
||||
* Returns the transfer fee charged for a specific currency of the issuer.
|
||||
* A per-currency TransferFee on the currency's TokenIssuance overrides the
|
||||
* account-wide TransferRate.
|
||||
*/
|
||||
[[nodiscard]] Rate
|
||||
transferRate(ReadView const& view, AccountID const& issuer, Currency const& currency);
|
||||
|
||||
[[nodiscard]] Rate
|
||||
transferRate(ReadView const& view, Issue const& issue);
|
||||
|
||||
/**
|
||||
* Generate a pseudo-account address from a pseudo owner key.
|
||||
* @param pseudoOwnerKey The key to generate the address from
|
||||
|
||||
@@ -1,102 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/basics/Log.h>
|
||||
#include <xrpl/basics/base_uint.h>
|
||||
#include <xrpl/beast/utility/Journal.h>
|
||||
#include <xrpl/core/ServiceRegistry.h>
|
||||
#include <xrpl/ledger/ApplyView.h>
|
||||
#include <xrpl/ledger/ReadView.h>
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/STData.h>
|
||||
#include <xrpl/protocol/STJson.h>
|
||||
#include <xrpl/protocol/STTx.h>
|
||||
#include <xrpl/protocol/TER.h>
|
||||
#include <xrpl/protocol/TxFlags.h>
|
||||
|
||||
#include <map>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
class ContractDataMap : public std::map<xrpl::AccountID, std::pair<bool, STJson>>
|
||||
{
|
||||
public:
|
||||
uint32_t modifiedCount = 0;
|
||||
};
|
||||
|
||||
class ContractEventMap : public std::map<std::string, STJson>
|
||||
{
|
||||
};
|
||||
|
||||
namespace contract {
|
||||
|
||||
/** The maximum number of data modifications in a single function. */
|
||||
int64_t constexpr maxDataModifications = 1000;
|
||||
|
||||
/** The maximum number of bytes the data can occupy. */
|
||||
int64_t constexpr maxContractDataSize = 1024;
|
||||
|
||||
/** The multiplier for contract data size calculations. */
|
||||
int64_t constexpr dataByteMultiplier = 512;
|
||||
|
||||
/** The cost multiplier of creating a contract in bytes. */
|
||||
int64_t constexpr createByteMultiplier = 500ULL;
|
||||
|
||||
/** The value to return when the fee calculation failed. */
|
||||
int64_t constexpr feeCalculationFailed = 0x7FFFFFFFFFFFFFFFLL;
|
||||
|
||||
/** The maximum number of contract parameters that can be in a transaction. */
|
||||
std::size_t constexpr maxContractParams = 8;
|
||||
|
||||
/** The maximum number of contract functions that can be in a transaction. */
|
||||
std::size_t constexpr maxContractFunctions = 32;
|
||||
|
||||
int64_t
|
||||
contractCreateFee(uint64_t byteCount);
|
||||
|
||||
NotTEC
|
||||
preflightFunctions(STTx const& tx, beast::Journal j);
|
||||
|
||||
NotTEC
|
||||
preflightInstanceParameters(STTx const& tx, beast::Journal j);
|
||||
|
||||
bool
|
||||
validateParameterMapping(STArray const& params, STArray const& values, beast::Journal j);
|
||||
|
||||
NotTEC
|
||||
preflightInstanceParameterValues(STTx const& tx, beast::Journal j);
|
||||
|
||||
NotTEC
|
||||
preflightFlagParameters(STArray const& parameters, beast::Journal j);
|
||||
|
||||
bool
|
||||
isValidParameterFlag(std::uint32_t flags);
|
||||
|
||||
TER
|
||||
preclaimFlagParameters(
|
||||
ReadView const& view,
|
||||
AccountID const& sourceAccount,
|
||||
AccountID const& contractAccount,
|
||||
STArray const& parameters,
|
||||
beast::Journal j);
|
||||
|
||||
TER
|
||||
doApplyFlagParameters(
|
||||
ApplyView& view,
|
||||
STTx const& tx,
|
||||
AccountID const& sourceAccount,
|
||||
AccountID const& contractAccount,
|
||||
STArray const& parameters,
|
||||
XRPAmount const& priorBalance,
|
||||
beast::Journal j);
|
||||
|
||||
TER
|
||||
finalizeContractData(
|
||||
ServiceRegistry& registry,
|
||||
ApplyView& view,
|
||||
AccountID const& contractAccount,
|
||||
ContractDataMap const& dataMap,
|
||||
ContractEventMap const& eventMap,
|
||||
uint256 const& txnID);
|
||||
|
||||
} // namespace contract
|
||||
} // namespace xrpl
|
||||
@@ -1,49 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/beast/utility/Journal.h>
|
||||
#include <xrpl/ledger/ApplyView.h>
|
||||
#include <xrpl/ledger/ReadView.h>
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/STAmount.h>
|
||||
#include <xrpl/protocol/STLedgerEntry.h>
|
||||
#include <xrpl/protocol/TER.h>
|
||||
|
||||
#include <cstdint>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
/**
|
||||
* Settle a holder's accrued coupons on their MPToken.
|
||||
*
|
||||
* Adds units * (AccruedPerUnit - CouponIndex) to CouponAccrued, rounded
|
||||
* once downward to the coupon asset, then advances CouponIndex to
|
||||
* AccruedPerUnit. Units are MPTAmount + LockedAmount. Increments the
|
||||
* schedule's ClaimantCount when CouponAccrued becomes non-zero on a
|
||||
* holder that had none. The caller must view.update() both entries on
|
||||
* tesSUCCESS.
|
||||
*/
|
||||
[[nodiscard]] TER
|
||||
couponSettleMPToken(SLE::ref schedule, SLE::ref mptoken, beast::Journal j);
|
||||
|
||||
/**
|
||||
* Settle a holder against the schedule of the issuance their MPToken
|
||||
* belongs to, if that issuance carries lsfMPTCouponSchedule. Does
|
||||
* nothing when the flag is clear, which is the case for every issuance
|
||||
* without a coupon schedule.
|
||||
*
|
||||
* This is the entry point called from the MPT unit-change helpers.
|
||||
*/
|
||||
[[nodiscard]] TER
|
||||
couponSettleIfScheduled(
|
||||
ApplyView& view,
|
||||
SLE::const_ref issuance,
|
||||
SLE::ref mptoken,
|
||||
beast::Journal j);
|
||||
|
||||
/**
|
||||
* The units a holder is credited for: MPTAmount + LockedAmount.
|
||||
*/
|
||||
[[nodiscard]] std::uint64_t
|
||||
couponHolderUnits(SLE::const_ref mptoken);
|
||||
|
||||
} // namespace xrpl
|
||||
@@ -2,10 +2,8 @@
|
||||
|
||||
#include <xrpl/basics/Log.h>
|
||||
#include <xrpl/beast/utility/Journal.h>
|
||||
#include <xrpl/beast/utility/Zero.h>
|
||||
#include <xrpl/beast/utility/instrumentation.h>
|
||||
#include <xrpl/ledger/ApplyView.h>
|
||||
#include <xrpl/ledger/ReadView.h>
|
||||
#include <xrpl/ledger/helpers/AccountRootHelpers.h>
|
||||
#include <xrpl/ledger/helpers/MPTokenHelpers.h>
|
||||
#include <xrpl/ledger/helpers/RippleStateHelpers.h>
|
||||
@@ -27,295 +25,8 @@
|
||||
#include <xrpl/protocol/TER.h>
|
||||
#include <xrpl/protocol/UintTypes.h>
|
||||
|
||||
#include <cstdint>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
/**
|
||||
* Validate that @p account may lock @p amount of a token for later delivery
|
||||
* to @p dest.
|
||||
*
|
||||
* The lock-side counterpart of escrowUnlockPreclaimHelper: every issuer
|
||||
* control (locking opt-in, authorization, freeze/lock, transferability,
|
||||
* spendable balance) that gates locking token value lives here, so any
|
||||
* transactor that locks funds applies the same rules. The signature is
|
||||
* view-based rather than PreclaimContext-based so it can also run from
|
||||
* doApply.
|
||||
*/
|
||||
template <ValidIssueType T>
|
||||
TER
|
||||
escrowLockPreclaimHelper(
|
||||
ReadView const& view,
|
||||
AccountID const& account,
|
||||
AccountID const& dest,
|
||||
STAmount const& amount,
|
||||
beast::Journal j);
|
||||
|
||||
template <>
|
||||
inline TER
|
||||
escrowLockPreclaimHelper<Issue>(
|
||||
ReadView const& view,
|
||||
AccountID const& account,
|
||||
AccountID const& dest,
|
||||
STAmount const& amount,
|
||||
beast::Journal j)
|
||||
{
|
||||
auto const& issue = amount.get<Issue>();
|
||||
auto const& issuer = amount.getIssuer();
|
||||
// If the issuer is the same as the account, return tecNO_PERMISSION
|
||||
if (issuer == account)
|
||||
return tecNO_PERMISSION;
|
||||
|
||||
// If the lsfAllowTrustLineLocking is not enabled, return tecNO_PERMISSION
|
||||
auto const sleIssuer = view.read(keylet::account(issuer));
|
||||
if (!sleIssuer)
|
||||
return tecNO_ISSUER;
|
||||
if (!sleIssuer->isFlag(lsfAllowTrustLineLocking))
|
||||
return tecNO_PERMISSION;
|
||||
|
||||
// If the account does not have a trustline to the issuer, return tecNO_LINE
|
||||
auto const sleRippleState = view.read(keylet::trustLine(account, issuer, issue.currency));
|
||||
if (!sleRippleState)
|
||||
return tecNO_LINE;
|
||||
|
||||
STAmount const balance = (*sleRippleState)[sfBalance];
|
||||
|
||||
// If balance is positive, issuer must have higher address than account
|
||||
if (balance > beast::kZero && issuer < account)
|
||||
return tecNO_PERMISSION; // LCOV_EXCL_LINE
|
||||
|
||||
// If balance is negative, issuer must have lower address than account
|
||||
if (balance < beast::kZero && issuer > account)
|
||||
return tecNO_PERMISSION; // LCOV_EXCL_LINE
|
||||
|
||||
// If the issuer has requireAuth set, check if the account is authorized
|
||||
if (auto const ter = requireAuth(view, issue, account); !isTesSuccess(ter))
|
||||
return ter;
|
||||
|
||||
// If the issuer has requireAuth set, check if the destination is authorized
|
||||
if (auto const ter = requireAuth(view, issue, dest); !isTesSuccess(ter))
|
||||
return ter;
|
||||
|
||||
// If the issuer has frozen the account, return tecFROZEN
|
||||
if (isFrozen(view, account, issue))
|
||||
return tecFROZEN;
|
||||
|
||||
// If the issuer has frozen the destination, return tecFROZEN
|
||||
if (isFrozen(view, dest, issue))
|
||||
return tecFROZEN;
|
||||
|
||||
STAmount const spendableAmount =
|
||||
accountHolds(view, account, issue.currency, issuer, FreezeHandling::IgnoreFreeze, j);
|
||||
|
||||
// If the balance is less than or equal to 0, return tecINSUFFICIENT_FUNDS
|
||||
if (spendableAmount <= beast::kZero)
|
||||
return tecINSUFFICIENT_FUNDS;
|
||||
|
||||
// If the spendable amount is less than the amount, return
|
||||
// tecINSUFFICIENT_FUNDS
|
||||
if (spendableAmount < amount)
|
||||
return tecINSUFFICIENT_FUNDS;
|
||||
|
||||
// If the amount is not addable to the balance, return tecPRECISION_LOSS
|
||||
if (!canAdd(spendableAmount, amount))
|
||||
return tecPRECISION_LOSS;
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
template <>
|
||||
inline TER
|
||||
escrowLockPreclaimHelper<MPTIssue>(
|
||||
ReadView const& view,
|
||||
AccountID const& account,
|
||||
AccountID const& dest,
|
||||
STAmount const& amount,
|
||||
beast::Journal j)
|
||||
{
|
||||
AccountID const issuer = amount.getIssuer();
|
||||
// If the issuer is the same as the account, return tecNO_PERMISSION
|
||||
if (issuer == account)
|
||||
return tecNO_PERMISSION;
|
||||
|
||||
// If the mpt does not exist, return tecOBJECT_NOT_FOUND
|
||||
auto const issuanceKey = keylet::mptokenIssuance(amount.get<MPTIssue>().getMptID());
|
||||
auto const sleIssuance = view.read(issuanceKey);
|
||||
if (!sleIssuance)
|
||||
return tecOBJECT_NOT_FOUND;
|
||||
|
||||
// If the lsfMPTCanEscrow is not enabled, return tecNO_PERMISSION
|
||||
if (!sleIssuance->isFlag(lsfMPTCanEscrow))
|
||||
return tecNO_PERMISSION;
|
||||
|
||||
// If the issuer is not the same as the issuer of the mpt, return
|
||||
// tecNO_PERMISSION
|
||||
if (sleIssuance->getAccountID(sfIssuer) != issuer)
|
||||
return tecNO_PERMISSION; // LCOV_EXCL_LINE
|
||||
|
||||
// If the account does not have the mpt, return tecOBJECT_NOT_FOUND
|
||||
if (!view.exists(keylet::mptoken(issuanceKey.key, account)))
|
||||
return tecOBJECT_NOT_FOUND;
|
||||
|
||||
// If the issuer has requireAuth set, check if the account is
|
||||
// authorized
|
||||
auto const& mptIssue = amount.get<MPTIssue>();
|
||||
if (auto const ter = requireAuth(view, mptIssue, account, AuthType::WeakAuth);
|
||||
!isTesSuccess(ter))
|
||||
return ter;
|
||||
|
||||
// If the issuer has requireAuth set, check if the destination is
|
||||
// authorized
|
||||
if (auto const ter = requireAuth(view, mptIssue, dest, AuthType::WeakAuth); !isTesSuccess(ter))
|
||||
return ter;
|
||||
|
||||
// If the issuer has frozen the account, return tecLOCKED
|
||||
if (isFrozen(view, account, *sleIssuance))
|
||||
return tecLOCKED;
|
||||
|
||||
// If the issuer has frozen the destination, return tecLOCKED
|
||||
if (isFrozen(view, dest, *sleIssuance))
|
||||
return tecLOCKED;
|
||||
|
||||
// If the mpt cannot be transferred, return tecNO_AUTH
|
||||
if (auto const ter = canTransfer(view, mptIssue, account, dest); !isTesSuccess(ter))
|
||||
return ter;
|
||||
|
||||
STAmount const spendableAmount = accountHolds(
|
||||
view,
|
||||
account,
|
||||
amount.get<MPTIssue>(),
|
||||
FreezeHandling::IgnoreFreeze,
|
||||
AuthHandling::IgnoreAuth,
|
||||
j);
|
||||
|
||||
// If the balance is less than or equal to 0, return tecINSUFFICIENT_FUNDS
|
||||
if (spendableAmount <= beast::kZero)
|
||||
return tecINSUFFICIENT_FUNDS;
|
||||
|
||||
// If the spendable amount is less than the amount, return
|
||||
// tecINSUFFICIENT_FUNDS
|
||||
if (spendableAmount < amount)
|
||||
return tecINSUFFICIENT_FUNDS;
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
template <ValidIssueType T>
|
||||
TER
|
||||
escrowLockApplyHelper(
|
||||
ApplyView& view,
|
||||
AccountID const& issuer,
|
||||
AccountID const& sender,
|
||||
STAmount const& amount,
|
||||
beast::Journal journal);
|
||||
|
||||
template <>
|
||||
inline TER
|
||||
escrowLockApplyHelper<Issue>(
|
||||
ApplyView& view,
|
||||
AccountID const& issuer,
|
||||
AccountID const& sender,
|
||||
STAmount const& amount,
|
||||
beast::Journal journal)
|
||||
{
|
||||
// Defensive: Issuer cannot create an escrow
|
||||
if (issuer == sender)
|
||||
return tecINTERNAL; // LCOV_EXCL_LINE
|
||||
|
||||
auto const ter =
|
||||
directSendNoFee(view, sender, issuer, amount, !amount.holds<MPTIssue>(), journal);
|
||||
if (!isTesSuccess(ter))
|
||||
return ter; // LCOV_EXCL_LINE
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
template <>
|
||||
inline TER
|
||||
escrowLockApplyHelper<MPTIssue>(
|
||||
ApplyView& view,
|
||||
AccountID const& issuer,
|
||||
AccountID const& sender,
|
||||
STAmount const& amount,
|
||||
beast::Journal journal)
|
||||
{
|
||||
// Defensive: Issuer cannot create an escrow
|
||||
if (issuer == sender)
|
||||
return tecINTERNAL; // LCOV_EXCL_LINE
|
||||
|
||||
auto const ter = lockEscrowMPT(view, sender, amount, journal);
|
||||
if (!isTesSuccess(ter))
|
||||
return ter; // LCOV_EXCL_LINE
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
template <ValidIssueType T>
|
||||
TER
|
||||
escrowUnlockPreclaimHelper(
|
||||
ReadView const& view,
|
||||
AccountID const& account,
|
||||
STAmount const& amount,
|
||||
bool checkFreeze = true);
|
||||
|
||||
template <>
|
||||
inline TER
|
||||
escrowUnlockPreclaimHelper<Issue>(
|
||||
ReadView const& view,
|
||||
AccountID const& account,
|
||||
STAmount const& amount,
|
||||
bool checkFreeze)
|
||||
{
|
||||
AccountID const& issuer = amount.getIssuer();
|
||||
// If the issuer is the same as the account, return tesSUCCESS
|
||||
if (issuer == account)
|
||||
return tesSUCCESS;
|
||||
|
||||
// If the issuer has requireAuth set, check if the destination is authorized
|
||||
if (auto const ter = requireAuth(view, amount.get<Issue>(), account); !isTesSuccess(ter))
|
||||
return ter;
|
||||
|
||||
// If the issuer has deep frozen the destination, return tecFROZEN
|
||||
if (checkFreeze &&
|
||||
isDeepFrozen(view, account, amount.get<Issue>().currency, amount.getIssuer()))
|
||||
return tecFROZEN;
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
template <>
|
||||
inline TER
|
||||
escrowUnlockPreclaimHelper<MPTIssue>(
|
||||
ReadView const& view,
|
||||
AccountID const& account,
|
||||
STAmount const& amount,
|
||||
bool checkFreeze)
|
||||
{
|
||||
AccountID const& issuer = amount.getIssuer();
|
||||
// If the issuer is the same as the account, return tesSUCCESS
|
||||
if (issuer == account)
|
||||
return tesSUCCESS;
|
||||
|
||||
// If the mpt does not exist, return tecOBJECT_NOT_FOUND
|
||||
auto const issuanceKey = keylet::mptokenIssuance(amount.get<MPTIssue>().getMptID());
|
||||
auto const sleIssuance = view.read(issuanceKey);
|
||||
if (!sleIssuance)
|
||||
return tecOBJECT_NOT_FOUND;
|
||||
|
||||
// If the issuer has requireAuth set, check if the account is
|
||||
// authorized
|
||||
auto const& mptIssue = amount.get<MPTIssue>();
|
||||
if (auto const ter = requireAuth(view, mptIssue, account, AuthType::WeakAuth);
|
||||
!isTesSuccess(ter))
|
||||
return ter;
|
||||
|
||||
// If the issuer has frozen the account, return tecLOCKED
|
||||
if (checkFreeze && isFrozen(view, account, *sleIssuance))
|
||||
return tecLOCKED;
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
//------------------------------------------------------------------------------
|
||||
|
||||
template <ValidIssueType T>
|
||||
TER
|
||||
escrowUnlockApplyHelper(
|
||||
@@ -344,6 +55,9 @@ escrowUnlockApplyHelper<Issue>(
|
||||
bool createAsset,
|
||||
beast::Journal journal)
|
||||
{
|
||||
auto const& issue = amount.get<Issue>();
|
||||
Keylet const trustLineKey = keylet::trustLine(receiver, issue);
|
||||
bool const recvLow = issuer > receiver;
|
||||
bool const senderIssuer = issuer == sender;
|
||||
bool const receiverIssuer = issuer == receiver;
|
||||
|
||||
@@ -353,10 +67,6 @@ escrowUnlockApplyHelper<Issue>(
|
||||
if (receiverIssuer)
|
||||
return tesSUCCESS;
|
||||
|
||||
auto const& issue = amount.get<Issue>();
|
||||
Keylet const trustLineKey = keylet::trustLine(receiver, issue);
|
||||
bool const recvLow = issuer > receiver;
|
||||
|
||||
if (!ctx.view.exists(trustLineKey) && createAsset)
|
||||
{
|
||||
// Can the account cover the trust line's reserve?
|
||||
@@ -562,18 +272,4 @@ escrowUnlockApplyHelper<MPTIssue>(
|
||||
journal);
|
||||
}
|
||||
|
||||
// calculateAdditionalReserve computes the owner count impact of an Escrow.
|
||||
// An escrow without a FinishFunction costs 1 reserve. With a FinishFunction,
|
||||
// each additional 500 bytes beyond the first 500 adds another reserve slot.
|
||||
template <class T>
|
||||
static int32_t
|
||||
calculateAdditionalReserve(T const& finishFunction)
|
||||
{
|
||||
if (!finishFunction)
|
||||
return 1;
|
||||
// First 500 bytes included in the normal reserve
|
||||
// Each additional 500 bytes requires an additional reserve
|
||||
return 1 + (finishFunction->size() / 500);
|
||||
}
|
||||
|
||||
} // namespace xrpl
|
||||
|
||||
@@ -101,24 +101,6 @@ static constexpr std::uint32_t kSecondsInYear = 365 * 24 * 60 * 60;
|
||||
Number
|
||||
loanPeriodicRate(TenthBips32 interestRate, std::uint32_t paymentInterval);
|
||||
|
||||
/**
|
||||
* Assets a loan earns per second at this principal outstanding.
|
||||
*
|
||||
* Equation (27) of XLS-66 is linear in elapsed time, and sfPaymentInterval
|
||||
* cancels out of it, so a loan's accrual rate depends only on its principal
|
||||
* and interest rate. Principal is flat between payments, which makes the rate
|
||||
* piecewise-constant with breakpoints exactly at the events that update it —
|
||||
* summing it across a vault's loans is therefore exact, not an approximation.
|
||||
*/
|
||||
inline Number
|
||||
loanAccrualRate(Number const& principalOutstanding, TenthBips32 interestRate)
|
||||
{
|
||||
if (interestRate == TenthBips32{0} || principalOutstanding <= Number{})
|
||||
return Number{};
|
||||
|
||||
return tenthBipsOfValue(principalOutstanding, interestRate) / Number{kSecondsInYear};
|
||||
}
|
||||
|
||||
/**
|
||||
* Ensure the periodic payment is always rounded consistently
|
||||
*/
|
||||
|
||||
@@ -132,29 +132,6 @@ authorizeMPToken(
|
||||
std::uint32_t flags = 0,
|
||||
std::optional<AccountID> holderID = std::nullopt);
|
||||
|
||||
// Authorize an AMM-issued MPT and apply the reserve-exemption rule in
|
||||
// one shot: standard authorize (which increments owner count) followed
|
||||
// by an immediate adjustOwnerCount(-1) so the LP doesn't pay reserve
|
||||
// for the AMM-issued holding. Returns the same TER as authorizeMPToken.
|
||||
//
|
||||
// Callers must ensure the MPT's issuance is owned by an AMM pseudo-
|
||||
// account; mis-using this helper for non-AMM-issued MPTs would let an
|
||||
// LP hold an arbitrary issuer's MPT for free.
|
||||
[[nodiscard]] TER
|
||||
authorizeAMMIssuedMPT(
|
||||
ApplyViewContext ctx,
|
||||
XRPAmount const& priorBalance,
|
||||
MPTID const& mptIssuanceID,
|
||||
AccountID const& account,
|
||||
beast::Journal journal);
|
||||
|
||||
// Symmetric for snapshot-style SLEs the AMM owns on behalf of an LP
|
||||
// (e.g. ltAMM_BIN_HOLDING). The SLE is inserted into the LP's owner
|
||||
// directory by the caller; this helper compensates the owner-count
|
||||
// increment so the LP doesn't pay reserve.
|
||||
void
|
||||
exemptAMMOwnedSLE(ApplyView& view, AccountID const& account, beast::Journal journal);
|
||||
|
||||
/**
|
||||
* Check if the account lacks required authorization for MPT.
|
||||
*
|
||||
|
||||
@@ -16,7 +16,6 @@
|
||||
#include <xrpl/protocol/TER.h>
|
||||
#include <xrpl/protocol/TxFlags.h>
|
||||
#include <xrpl/protocol/XRPAmount.h>
|
||||
#include <xrpl/protocol/nft.h>
|
||||
|
||||
#include <cstddef>
|
||||
#include <cstdint>
|
||||
@@ -162,12 +161,4 @@ checkTrustlineDeepFrozen(
|
||||
beast::Journal const j,
|
||||
Issue const& issue);
|
||||
|
||||
TER
|
||||
transferNFToken(
|
||||
ApplyView& view,
|
||||
AccountID const& buyer,
|
||||
AccountID const& seller,
|
||||
uint256 const& nftokenID,
|
||||
beast::Journal j);
|
||||
|
||||
} // namespace xrpl::nft
|
||||
|
||||
@@ -2,85 +2,28 @@
|
||||
|
||||
#include <xrpl/basics/base_uint.h>
|
||||
#include <xrpl/beast/utility/Journal.h>
|
||||
#include <xrpl/beast/utility/Zero.h>
|
||||
#include <xrpl/ledger/ApplyView.h>
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/Concepts.h>
|
||||
#include <xrpl/protocol/Feature.h>
|
||||
#include <xrpl/protocol/Issue.h>
|
||||
#include <xrpl/protocol/MPTAmount.h>
|
||||
#include <xrpl/protocol/MPTIssue.h>
|
||||
#include <xrpl/protocol/Protocol.h>
|
||||
#include <xrpl/protocol/Rules.h>
|
||||
#include <xrpl/protocol/STAmount.h>
|
||||
#include <xrpl/protocol/STLedgerEntry.h>
|
||||
#include <xrpl/protocol/TER.h>
|
||||
#include <xrpl/protocol/UintTypes.h>
|
||||
|
||||
#include <cstdint>
|
||||
#include <optional>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
/**
|
||||
* Validate the token amount of a PaymentChannelCreate or PaymentChannelFund
|
||||
* transaction during preflight.
|
||||
*
|
||||
* @param rules The current ledger rules used to check amendment status.
|
||||
* @param amount The channel or funding amount from the transaction.
|
||||
* @return tesSUCCESS if the amount is valid; temBAD_AMOUNT, temBAD_CURRENCY,
|
||||
* or temDISABLED otherwise.
|
||||
*/
|
||||
template <ValidIssueType T>
|
||||
NotTEC
|
||||
payChanAmountPreflightHelper(Rules const& rules, STAmount const& amount);
|
||||
|
||||
template <>
|
||||
inline NotTEC
|
||||
payChanAmountPreflightHelper<Issue>(Rules const&, STAmount const& amount)
|
||||
{
|
||||
if (amount.native() || amount <= beast::kZero)
|
||||
return temBAD_AMOUNT;
|
||||
|
||||
if (badCurrency() == amount.get<Issue>().currency)
|
||||
return temBAD_CURRENCY;
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
template <>
|
||||
inline NotTEC
|
||||
payChanAmountPreflightHelper<MPTIssue>(Rules const& rules, STAmount const& amount)
|
||||
{
|
||||
if (!rules.enabled(fixCleanup3_2_0) && !rules.enabled(featureMPTokensV1))
|
||||
return temDISABLED;
|
||||
|
||||
if (amount.native() || amount.mpt() > MPTAmount{kMaxMpTokenAmount} || amount <= beast::kZero)
|
||||
return temBAD_AMOUNT;
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
/**
|
||||
* Close a payment channel and return its remaining funds to the channel owner.
|
||||
*
|
||||
* @param slep The SLE for the PayChannel object to close.
|
||||
* @param ctx The apply view context (view and transaction) in which ledger
|
||||
* state modifications are made.
|
||||
* @param key The ledger key identifying the PayChannel entry.
|
||||
* @param txAccount The account submitting the transaction that closes the
|
||||
* channel.
|
||||
* @param j Journal used for fatal-level diagnostic messages.
|
||||
* @return tesSUCCESS on success; tefBAD_LEDGER if a directory removal
|
||||
* fails; tefINTERNAL if the source account SLE cannot be found.
|
||||
* @param slep The SLE for the PayChannel object to close.
|
||||
* @param view The apply view in which ledger state modifications are made.
|
||||
* @param key The ledger key identifying the PayChannel entry.
|
||||
* @param j Journal used for fatal-level diagnostic messages.
|
||||
* @return tesSUCCESS on success; tefBAD_LEDGER if a directory removal
|
||||
* fails; tefINTERNAL if the source account SLE cannot be found.
|
||||
*/
|
||||
TER
|
||||
closeChannel(
|
||||
SLE::ref slep,
|
||||
ApplyViewContext ctx,
|
||||
uint256 const& key,
|
||||
AccountID const& txAccount,
|
||||
beast::Journal j);
|
||||
closeChannel(SLE::ref slep, ApplyView& view, uint256 const& key, beast::Journal j);
|
||||
|
||||
/**
|
||||
* Add two uint32_t values with saturation at UINT32_MAX.
|
||||
|
||||
@@ -1,85 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/beast/utility/Journal.h>
|
||||
#include <xrpl/ledger/ApplyView.h>
|
||||
#include <xrpl/ledger/ReadView.h>
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/Asset.h>
|
||||
#include <xrpl/protocol/STAmount.h>
|
||||
#include <xrpl/protocol/STLedgerEntry.h>
|
||||
#include <xrpl/protocol/TER.h>
|
||||
|
||||
#include <cstdint>
|
||||
|
||||
namespace xrpl {
|
||||
namespace repo {
|
||||
|
||||
/**
|
||||
* Seconds in a year, the denominator of the annualized interest rate.
|
||||
*/
|
||||
|
||||
/**
|
||||
* A repo is active once the buyer has accepted it, which is recorded by
|
||||
* sfStartDate. Before that it is a pending offer.
|
||||
*/
|
||||
[[nodiscard]] inline bool
|
||||
isActive(SLE::const_ref sleRepo)
|
||||
{
|
||||
return sleRepo->isFieldPresent(sfStartDate);
|
||||
}
|
||||
|
||||
/**
|
||||
* The amount the seller owes to repurchase the collateral.
|
||||
*
|
||||
* PurchasePrice * (1 + InterestRate * elapsed / kSecondsInYear), where elapsed
|
||||
* runs from StartDate to the close time, capped at MaturityDate so the seller
|
||||
* never pays for time past maturity. Computed in Number and rounded up, so
|
||||
* rounding never favours the seller.
|
||||
*/
|
||||
[[nodiscard]] STAmount
|
||||
repurchaseAmount(SLE::const_ref sleRepo, std::uint32_t closeTime);
|
||||
|
||||
/**
|
||||
* Lock the collateral out of the seller's spendable balance.
|
||||
*
|
||||
* XRP is deducted from the account balance by the caller; this handles the
|
||||
* issued-asset cases the same way an escrow does.
|
||||
*/
|
||||
[[nodiscard]] TER
|
||||
lockCollateral(
|
||||
ApplyView& view,
|
||||
AccountID const& issuer,
|
||||
AccountID const& seller,
|
||||
STAmount const& amount,
|
||||
beast::Journal journal);
|
||||
|
||||
/**
|
||||
* The XLS-85 checks that decide whether collateral may be locked at all.
|
||||
*
|
||||
* Both parties are checked, not just the seller: the buyer receives the
|
||||
* collateral if the repo defaults, so an unauthorized or frozen buyer would
|
||||
* leave the collateral unable to move at exactly the moment it must.
|
||||
*/
|
||||
[[nodiscard]] TER
|
||||
checkCollateral(
|
||||
ReadView const& view,
|
||||
AccountID const& seller,
|
||||
AccountID const& buyer,
|
||||
STAmount const& collateral,
|
||||
beast::Journal journal);
|
||||
|
||||
/**
|
||||
* Return the locked collateral to an account and remove the entry.
|
||||
*
|
||||
* Used by cancel, close and default; they differ only in who receives the
|
||||
* collateral and whether any cash moved first.
|
||||
*/
|
||||
[[nodiscard]] TER
|
||||
releaseAndDelete(
|
||||
ApplyViewContext ctx,
|
||||
SLE::ref sleRepo,
|
||||
AccountID const& receiver,
|
||||
beast::Journal journal);
|
||||
|
||||
} // namespace repo
|
||||
} // namespace xrpl
|
||||
@@ -1,429 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/basics/Log.h>
|
||||
#include <xrpl/beast/utility/Journal.h>
|
||||
#include <xrpl/beast/utility/Zero.h>
|
||||
#include <xrpl/ledger/ApplyView.h>
|
||||
#include <xrpl/ledger/ReadView.h>
|
||||
#include <xrpl/ledger/helpers/AccountRootHelpers.h>
|
||||
#include <xrpl/ledger/helpers/MPTokenHelpers.h>
|
||||
#include <xrpl/ledger/helpers/RippleStateHelpers.h>
|
||||
#include <xrpl/ledger/helpers/TokenHelpers.h>
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/Concepts.h>
|
||||
#include <xrpl/protocol/Indexes.h>
|
||||
#include <xrpl/protocol/Issue.h>
|
||||
#include <xrpl/protocol/Keylet.h>
|
||||
#include <xrpl/protocol/LedgerFormats.h>
|
||||
#include <xrpl/protocol/MPTIssue.h>
|
||||
#include <xrpl/protocol/SField.h>
|
||||
#include <xrpl/protocol/STAmount.h>
|
||||
#include <xrpl/protocol/STLedgerEntry.h>
|
||||
#include <xrpl/protocol/TER.h>
|
||||
#include <xrpl/protocol/UintTypes.h>
|
||||
|
||||
#include <cstdint>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
template <ValidIssueType T>
|
||||
TER
|
||||
canTransferTokenHelper(
|
||||
ReadView const& view,
|
||||
AccountID const& account,
|
||||
AccountID const& dest,
|
||||
STAmount const& amount,
|
||||
beast::Journal const& j);
|
||||
|
||||
template <>
|
||||
inline TER
|
||||
canTransferTokenHelper<Issue>(
|
||||
ReadView const& view,
|
||||
AccountID const& account,
|
||||
AccountID const& dest,
|
||||
STAmount const& amount,
|
||||
beast::Journal const& j)
|
||||
{
|
||||
AccountID issuer = amount.getIssuer();
|
||||
if (issuer == account)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Issuer is the same as the account.";
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
// If the issuer does not exist, return tecNO_ISSUER
|
||||
auto const sleIssuer = view.read(keylet::account(issuer));
|
||||
if (!sleIssuer)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Issuer does not exist.";
|
||||
return tecNO_ISSUER;
|
||||
}
|
||||
|
||||
// If the account does not have a trustline to the issuer, return tecNO_LINE
|
||||
auto const sleRippleState =
|
||||
view.read(keylet::trustLine(account, issuer, amount.get<Issue>().currency));
|
||||
if (!sleRippleState)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Trust line does not exist.";
|
||||
return tecNO_LINE;
|
||||
}
|
||||
|
||||
STAmount const balance = (*sleRippleState)[sfBalance];
|
||||
|
||||
// If balance is positive, issuer must have higher address than account
|
||||
if (balance > beast::kZero && issuer < account)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Invalid trust line state.";
|
||||
return tecNO_PERMISSION;
|
||||
}
|
||||
|
||||
// If balance is negative, issuer must have lower address than account
|
||||
if (balance < beast::kZero && issuer > account)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Invalid trust line state.";
|
||||
return tecNO_PERMISSION;
|
||||
}
|
||||
|
||||
// If the issuer has requireAuth set, check if the account is authorized
|
||||
if (auto const ter = requireAuth(view, amount.get<Issue>(), account); ter != tesSUCCESS)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Account is not authorized";
|
||||
return ter;
|
||||
}
|
||||
|
||||
// If the issuer has requireAuth set, check if the destination is authorized
|
||||
if (auto const ter = requireAuth(view, amount.get<Issue>(), dest); ter != tesSUCCESS)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Destination is not authorized.";
|
||||
return ter;
|
||||
}
|
||||
|
||||
// If the issuer has frozen the account, return tecFROZEN
|
||||
if (isFrozen(view, account, amount.get<Issue>()) ||
|
||||
isDeepFrozen(view, account, amount.get<Issue>().currency, amount.get<Issue>().account))
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Account is frozen.";
|
||||
return tecFROZEN;
|
||||
}
|
||||
|
||||
// If the issuer has frozen the destination, return tecFROZEN
|
||||
if (isFrozen(view, dest, amount.get<Issue>()) ||
|
||||
isDeepFrozen(view, dest, amount.get<Issue>().currency, amount.get<Issue>().account))
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Destination is frozen.";
|
||||
return tecFROZEN;
|
||||
}
|
||||
|
||||
STAmount const spendableAmount = accountHolds(
|
||||
view, account, amount.get<Issue>().currency, issuer, FreezeHandling::IgnoreFreeze, j);
|
||||
|
||||
// If the balance is less than or equal to 0, return
|
||||
// tecINSUFFICIENT_FUNDS
|
||||
if (spendableAmount <= beast::kZero)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Spendable amount is less "
|
||||
"than or equal to 0.";
|
||||
return tecINSUFFICIENT_FUNDS;
|
||||
}
|
||||
|
||||
// If the spendable amount is less than the amount, return
|
||||
// tecINSUFFICIENT_FUNDS
|
||||
if (spendableAmount < amount)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Spendable amount is less "
|
||||
"than the amount.";
|
||||
return tecINSUFFICIENT_FUNDS;
|
||||
}
|
||||
|
||||
// If the amount is not addable to the balance, return tecPRECISION_LOSS
|
||||
if (!canAdd(spendableAmount, amount))
|
||||
return tecPRECISION_LOSS;
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
template <>
|
||||
inline TER
|
||||
canTransferTokenHelper<MPTIssue>(
|
||||
ReadView const& view,
|
||||
AccountID const& account,
|
||||
AccountID const& dest,
|
||||
STAmount const& amount,
|
||||
beast::Journal const& j)
|
||||
{
|
||||
AccountID issuer = amount.getIssuer();
|
||||
if (issuer == account)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Issuer is the same as the account.";
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
// If the mpt does not exist, return tecOBJECT_NOT_FOUND
|
||||
auto const issuanceKey = keylet::mptokenIssuance(amount.get<MPTIssue>().getMptID());
|
||||
auto const sleIssuance = view.read(issuanceKey);
|
||||
if (!sleIssuance)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: MPT issuance does not exist.";
|
||||
return tecOBJECT_NOT_FOUND;
|
||||
}
|
||||
|
||||
// If the issuer is not the same as the issuer of the mpt, return
|
||||
// tecNO_PERMISSION
|
||||
if (sleIssuance->getAccountID(sfIssuer) != issuer)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Issuer is not the same as "
|
||||
"the issuer of the MPT.";
|
||||
return tecNO_PERMISSION;
|
||||
}
|
||||
|
||||
// If the account does not have the mpt, return tecOBJECT_NOT_FOUND
|
||||
if (!view.exists(keylet::mptoken(issuanceKey.key, account)))
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Account does not have the MPT.";
|
||||
return tecOBJECT_NOT_FOUND;
|
||||
}
|
||||
|
||||
// If the issuer has requireAuth set, check if the account is
|
||||
// authorized
|
||||
auto const& mptIssue = amount.get<MPTIssue>();
|
||||
if (auto const ter = requireAuth(view, mptIssue, account, AuthType::WeakAuth);
|
||||
ter != tesSUCCESS)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Account is not authorized.";
|
||||
return ter;
|
||||
}
|
||||
|
||||
// If the issuer has requireAuth set, check if the destination is
|
||||
// authorized
|
||||
if (auto const ter = requireAuth(view, mptIssue, dest, AuthType::WeakAuth); ter != tesSUCCESS)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Destination is not authorized.";
|
||||
return ter;
|
||||
}
|
||||
|
||||
// If the issuer has locked the account, return tecLOCKED
|
||||
if (isFrozen(view, account, mptIssue))
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Account is locked.";
|
||||
return tecLOCKED;
|
||||
}
|
||||
|
||||
// If the issuer has locked the destination, return tecLOCKED
|
||||
if (isFrozen(view, dest, mptIssue))
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Destination is locked.";
|
||||
return tecLOCKED;
|
||||
}
|
||||
|
||||
// If the mpt cannot be transferred, return tecNO_AUTH
|
||||
if (auto const ter = canTransfer(view, mptIssue, account, dest); ter != tesSUCCESS)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: MPT cannot be transferred.";
|
||||
return ter;
|
||||
}
|
||||
|
||||
STAmount const spendableAmount = accountHolds(
|
||||
view,
|
||||
account,
|
||||
amount.get<MPTIssue>(),
|
||||
FreezeHandling::IgnoreFreeze,
|
||||
AuthHandling::IgnoreAuth,
|
||||
j);
|
||||
|
||||
// If the balance is less than or equal to 0, return
|
||||
// tecINSUFFICIENT_FUNDS
|
||||
if (spendableAmount <= beast::kZero)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Spendable amount is less "
|
||||
"than or equal to 0.";
|
||||
return tecINSUFFICIENT_FUNDS;
|
||||
}
|
||||
|
||||
// If the spendable amount is less than the amount, return
|
||||
// tecINSUFFICIENT_FUNDS
|
||||
if (spendableAmount < amount)
|
||||
{
|
||||
JLOG(j.trace()) << "canTransferTokenHelper: Spendable amount is less "
|
||||
"than the amount.";
|
||||
return tecINSUFFICIENT_FUNDS;
|
||||
}
|
||||
|
||||
// If the amount is not addable to the balance, return tecPRECISION_LOSS
|
||||
if (!canAdd(spendableAmount, amount))
|
||||
return tecPRECISION_LOSS;
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
template <ValidIssueType T>
|
||||
TER
|
||||
doTransferTokenHelper(
|
||||
ApplyView& view,
|
||||
SLE::ref sleDest,
|
||||
STAmount const& xrpBalance,
|
||||
STAmount const& amount,
|
||||
AccountID const& issuer,
|
||||
AccountID const& sender,
|
||||
AccountID const& receiver,
|
||||
bool createAsset,
|
||||
beast::Journal journal);
|
||||
|
||||
template <>
|
||||
inline TER
|
||||
doTransferTokenHelper<Issue>(
|
||||
ApplyView& view,
|
||||
SLE::ref sleDest,
|
||||
STAmount const& xrpBalance,
|
||||
STAmount const& amount,
|
||||
AccountID const& issuer,
|
||||
AccountID const& sender,
|
||||
AccountID const& receiver,
|
||||
bool createAsset,
|
||||
beast::Journal journal)
|
||||
{
|
||||
Keylet const trustLineKey = keylet::trustLine(receiver, amount.get<Issue>());
|
||||
bool const recvLow = issuer > receiver;
|
||||
|
||||
// Review Note: We could remove this and just say to use batch to auth the
|
||||
// token first
|
||||
if (!view.exists(trustLineKey) && createAsset && issuer != receiver)
|
||||
{
|
||||
// Can the account cover the trust line's reserve?
|
||||
if (xrpBalance < accountReserve(view, sleDest, journal, {.ownerCountDelta = 1}))
|
||||
{
|
||||
JLOG(journal.trace()) << "doTransferTokenHelper: Trust line does not exist. "
|
||||
"Insufficent reserve to create line.";
|
||||
|
||||
return tecNO_LINE_INSUF_RESERVE;
|
||||
}
|
||||
|
||||
Currency const currency = amount.get<Issue>().currency;
|
||||
STAmount initialBalance(amount.get<Issue>());
|
||||
initialBalance.get<Issue>().account = noAccount();
|
||||
|
||||
// clang-format off
|
||||
if (TER const ter = trustCreate(
|
||||
view, // payment sandbox
|
||||
recvLow, // is dest low?
|
||||
issuer, // source
|
||||
receiver, // destination
|
||||
trustLineKey.key, // ledger index
|
||||
sleDest, // Account to add to
|
||||
false, // authorize account
|
||||
(sleDest->getFlags() & lsfDefaultRipple) == 0,
|
||||
false, // freeze trust line
|
||||
false, // deep freeze trust line
|
||||
initialBalance, // zero initial balance
|
||||
Issue(currency, receiver), // limit of zero
|
||||
0, // quality in
|
||||
0, // quality out
|
||||
SLE::pointer(), // sponsor
|
||||
journal); // journal
|
||||
!isTesSuccess(ter))
|
||||
{
|
||||
JLOG(journal.trace()) << "doTransferTokenHelper: Failed to create trust line: " << transToken(ter);
|
||||
return ter;
|
||||
}
|
||||
// clang-format on
|
||||
|
||||
view.update(sleDest);
|
||||
}
|
||||
|
||||
if (!view.exists(trustLineKey) && issuer != receiver)
|
||||
return tecNO_LINE;
|
||||
|
||||
auto const ter =
|
||||
accountSend(view, sender, receiver, amount, journal, SLE::pointer(), WaiveTransferFee::No);
|
||||
if (ter != tesSUCCESS)
|
||||
{
|
||||
JLOG(journal.trace()) << "doTransferTokenHelper: Failed to send token: " << transToken(ter);
|
||||
return ter; // LCOV_EXCL_LINE
|
||||
}
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
template <>
|
||||
inline TER
|
||||
doTransferTokenHelper<MPTIssue>(
|
||||
ApplyView& view,
|
||||
SLE::ref sleDest,
|
||||
STAmount const& xrpBalance,
|
||||
STAmount const& amount,
|
||||
AccountID const& issuer,
|
||||
AccountID const& sender,
|
||||
AccountID const& receiver,
|
||||
bool createAsset,
|
||||
beast::Journal journal)
|
||||
{
|
||||
auto const mptID = amount.get<MPTIssue>().getMptID();
|
||||
auto const issuanceKey = keylet::mptokenIssuance(mptID);
|
||||
if (!view.exists(keylet::mptoken(issuanceKey.key, receiver)) && createAsset &&
|
||||
issuer != receiver)
|
||||
{
|
||||
if (xrpBalance < accountReserve(view, sleDest, journal, {.ownerCountDelta = 1}))
|
||||
{
|
||||
JLOG(journal.trace()) << "doTransferTokenHelper: MPT does not exist. "
|
||||
"Insufficent reserve to create MPT.";
|
||||
return tecINSUFFICIENT_RESERVE;
|
||||
}
|
||||
|
||||
if (auto const ter = createMPToken(view, mptID, receiver, SLE::pointer(), 0);
|
||||
!isTesSuccess(ter))
|
||||
{
|
||||
JLOG(journal.trace()) << "doTransferTokenHelper: Failed to create MPT: "
|
||||
<< transToken(ter);
|
||||
return ter;
|
||||
}
|
||||
|
||||
// Update owner count.
|
||||
increaseOwnerCount(view, sleDest, SLE::pointer(), 1, journal);
|
||||
}
|
||||
|
||||
if (issuer != receiver && !view.exists(keylet::mptoken(issuanceKey.key, receiver)))
|
||||
{
|
||||
JLOG(journal.trace()) << "doTransferTokenHelper: MPT does not exist.";
|
||||
return tecNO_PERMISSION;
|
||||
}
|
||||
|
||||
auto const ter =
|
||||
accountSend(view, sender, receiver, amount, journal, SLE::pointer(), WaiveTransferFee::No);
|
||||
if (ter != tesSUCCESS)
|
||||
{
|
||||
JLOG(journal.trace()) << "doTransferTokenHelper: Failed to send MPT: " << transToken(ter);
|
||||
return ter; // LCOV_EXCL_LINE
|
||||
}
|
||||
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
// Remove a subscription from both owner directories, release the owner's
|
||||
// reserve, and erase the object. Shared by SubscriptionCancel and the
|
||||
// single-use claim path so the two never diverge.
|
||||
inline TER
|
||||
deleteSubscription(ApplyView& view, SLE::ref sleSub, beast::Journal journal)
|
||||
{
|
||||
AccountID const account{sleSub->getAccountID(sfAccount)};
|
||||
AccountID const dstAcct{sleSub->getAccountID(sfDestination)};
|
||||
|
||||
std::uint64_t const ownerPage{(*sleSub)[sfOwnerNode]};
|
||||
if (!view.dirRemove(keylet::ownerDir(account), ownerPage, sleSub->key(), true))
|
||||
{
|
||||
JLOG(journal.fatal()) << "deleteSubscription: Unable to delete from source.";
|
||||
return tefBAD_LEDGER;
|
||||
}
|
||||
|
||||
std::uint64_t const destPage{(*sleSub)[sfDestinationNode]};
|
||||
if (!view.dirRemove(keylet::ownerDir(dstAcct), destPage, sleSub->key(), true))
|
||||
{
|
||||
JLOG(journal.fatal()) << "deleteSubscription: Unable to delete from destination.";
|
||||
return tefBAD_LEDGER;
|
||||
}
|
||||
|
||||
auto const sleSrc = view.peek(keylet::account(account));
|
||||
decreaseOwnerCount(view, sleSrc, SLE::pointer(), 1, journal);
|
||||
view.erase(sleSub);
|
||||
return tesSUCCESS;
|
||||
}
|
||||
|
||||
} // namespace xrpl
|
||||
@@ -4,7 +4,6 @@
|
||||
#include <xrpl/beast/utility/Journal.h>
|
||||
#include <xrpl/ledger/ApplyView.h>
|
||||
#include <xrpl/ledger/ReadView.h>
|
||||
#include <xrpl/ledger/helpers/TokenIssuanceHelpers.h>
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/Asset.h>
|
||||
#include <xrpl/protocol/Issue.h>
|
||||
@@ -392,8 +391,7 @@ directSendNoFee(
|
||||
AccountID const& uReceiverID,
|
||||
STAmount const& saAmount,
|
||||
bool bCheckIssuer,
|
||||
beast::Journal j,
|
||||
EnforceSupplyCap enforceSupplyCap = EnforceSupplyCap::Yes);
|
||||
beast::Journal j);
|
||||
|
||||
/**
|
||||
* Calls static accountSendIOU if saAmount represents Issue.
|
||||
|
||||
@@ -1,109 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/basics/Number.h>
|
||||
#include <xrpl/beast/utility/Journal.h>
|
||||
#include <xrpl/ledger/ApplyView.h>
|
||||
#include <xrpl/ledger/ReadView.h>
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/Issue.h>
|
||||
#include <xrpl/protocol/STAmount.h>
|
||||
#include <xrpl/protocol/STLedgerEntry.h>
|
||||
#include <xrpl/protocol/TER.h>
|
||||
#include <xrpl/protocol/UintTypes.h>
|
||||
|
||||
#include <cstdint>
|
||||
#include <optional>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
/**
|
||||
* ceil(value * 10^scale), exact.
|
||||
*
|
||||
* The shift is a pure exponent adjustment; the +1 for a fractional
|
||||
* positive value is exact because a fractional Number is < 10^16.
|
||||
* Truncation toward zero already is the ceiling for negative values.
|
||||
*/
|
||||
[[nodiscard]] Number
|
||||
tokenScaledCeil(Number const& value, std::uint8_t scale);
|
||||
|
||||
/**
|
||||
* floor(value * 10^scale) as integer base units; nullopt if it does not
|
||||
* fit in a non-negative int64.
|
||||
*/
|
||||
[[nodiscard]] std::optional<std::int64_t>
|
||||
tokenBaseUnits(Number const& value, std::uint8_t scale);
|
||||
|
||||
/**
|
||||
* True if the issuance violates
|
||||
* ceil(IssuedAmount * 10^TokenScale) + MPT OutstandingAmount > MaximumAmount.
|
||||
* Always false for an uncapped issuance.
|
||||
*/
|
||||
[[nodiscard]] bool
|
||||
tokenSupplyExceeded(ReadView const& view, SLE::const_ref sleIssuance);
|
||||
|
||||
/**
|
||||
* Controls whether an IOU credit hard-fails when a capped TokenIssuance
|
||||
* would exceed its MaximumAmount. Flow-engine steps pass No: their send
|
||||
* results are advisory (return values ignored, reverse-pass execution can
|
||||
* legitimately overshoot transiently) and the supply-cap invariant checker
|
||||
* gates the final state instead.
|
||||
*/
|
||||
enum class EnforceSupplyCap : bool { No = false, Yes = true };
|
||||
|
||||
/**
|
||||
* Maintain IssuedAmount on the issuer's TokenIssuance for a trust-line
|
||||
* balance move of `amount` from `sender` to `receiver`. Only the amount's
|
||||
* issuer is adjusted: balance moving away from the issuer increases its
|
||||
* net issuance, balance returning decreases it.
|
||||
*
|
||||
* No-op when the amendment is disabled, neither party is the issuer, or no
|
||||
* TokenIssuance exists. Returns tecSUPPLY_EXCEEDED when the cap is enforced
|
||||
* and a capped issuer would exceed MaximumAmount.
|
||||
*/
|
||||
[[nodiscard]] TER
|
||||
adjustTokenIssuance(
|
||||
ApplyView& view,
|
||||
AccountID const& sender,
|
||||
AccountID const& receiver,
|
||||
STAmount const& amount,
|
||||
EnforceSupplyCap enforceCap,
|
||||
beast::Journal j);
|
||||
|
||||
/**
|
||||
* Remaining IOU the issuer can issue under the supply cap, floored to the
|
||||
* representable amount; nullopt when there is no TokenIssuance or no cap.
|
||||
*/
|
||||
[[nodiscard]] std::optional<STAmount>
|
||||
tokenIssuanceHeadroom(ReadView const& view, Issue const& issue);
|
||||
|
||||
/**
|
||||
* True when the issue's TokenIssuance carries the per-currency lock
|
||||
* (lsfTokenLocked). The per-currency analog of lsfGlobalFreeze.
|
||||
*/
|
||||
[[nodiscard]] bool
|
||||
isTokenLocked(ReadView const& view, Issue const& issue);
|
||||
|
||||
/**
|
||||
* For an MPT issuance bound to a capped TokenIssuance: the additional MPT
|
||||
* base units that can be minted under the shared cap
|
||||
* (MaximumAmount - OutstandingAmount - ceil(IssuedAmount * 10^TokenScale)).
|
||||
* nullopt when unbound or uncapped.
|
||||
*/
|
||||
[[nodiscard]] std::optional<std::int64_t>
|
||||
mptBoundHeadroom(ReadView const& view, SLE::const_ref sleMptIssuance);
|
||||
|
||||
/**
|
||||
* Validate binding an MPTokenIssuance to a TokenIssuance: the MPT issuance
|
||||
* exists, is issued by `account`, is not already bound, and its
|
||||
* MaximumAmount/AssetScale equal the TokenIssuance's MaximumAmount/
|
||||
* TokenScale.
|
||||
*/
|
||||
[[nodiscard]] TER
|
||||
validateTokenBinding(
|
||||
ReadView const& view,
|
||||
MPTID const& mptId,
|
||||
AccountID const& account,
|
||||
std::optional<std::uint64_t> const& maximumAmount,
|
||||
std::uint8_t tokenScale);
|
||||
|
||||
} // namespace xrpl
|
||||
@@ -1,7 +1,6 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/basics/Number.h>
|
||||
#include <xrpl/ledger/ApplyView.h>
|
||||
#include <xrpl/ledger/ReadView.h>
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/Asset.h>
|
||||
@@ -17,111 +16,20 @@
|
||||
namespace xrpl {
|
||||
|
||||
class STTx;
|
||||
/**
|
||||
* Interest the vault's loans have earned since sfLastAccrualTime, capped by
|
||||
* the sfUnearnedInterest budget still left to recognize.
|
||||
*
|
||||
* sfAssetsTotal is only credited when a loan event settles the vault, so
|
||||
* between those events it lags by this amount. Adding it back at read time
|
||||
* recognizes interest continuously as it is earned, without writing to
|
||||
* sfAssetsTotal outside the loan transactions.
|
||||
*
|
||||
* Returns zero when nothing is accruing — no rate, no budget left, or a vault
|
||||
* created before featureLendingProtocolV1_1.
|
||||
*/
|
||||
[[nodiscard]] Number
|
||||
vaultAccruedInterest(ReadView const& view, SLE::const_ref vault);
|
||||
|
||||
/**
|
||||
* Whether a rolling vault is inside a dealing window at this close time.
|
||||
*
|
||||
* A rolling vault deals in [SubscriptionDate + k * DealingInterval,
|
||||
* SubscriptionDate + k * DealingInterval + DealingWindow) for integer k >= 0.
|
||||
* Returns true for any vault that is not rolling, which has no windows to be
|
||||
* outside of, and false before the first window opens.
|
||||
*/
|
||||
[[nodiscard]] bool
|
||||
inDealingWindow(ReadView const& view, SLE::const_ref vault);
|
||||
|
||||
/**
|
||||
* End of the dealing window containing this close time.
|
||||
*
|
||||
* Only meaningful when inDealingWindow is true for a rolling vault; it is the
|
||||
* sfStruckUntil written when a window's price is struck.
|
||||
*/
|
||||
[[nodiscard]] std::uint32_t
|
||||
dealingWindowEnd(ReadView const& view, SLE::const_ref vault);
|
||||
|
||||
/**
|
||||
* The price every deal in the current window converts at, in vault asset per
|
||||
* share, or nullopt when no struck price governs this ledger.
|
||||
*
|
||||
* Returns a price only for a rolling vault inside a window whose sfStruckUntil
|
||||
* matches that window's end. Accrual continues underneath it: the dealing price
|
||||
* is frozen for the window, the accounting is not.
|
||||
*/
|
||||
/**
|
||||
* The interest recognition method of a vault.
|
||||
*
|
||||
* Returns sfAccountingMethod where it is present. A vault created before
|
||||
* featureVaultContinuousAccrual carries no such field, so the method is derived
|
||||
* from its schema version instead: CashBasis recognizes interest as it is
|
||||
* collected, and anything older is Legacy, which recognizes a loan's whole-life
|
||||
* interest at origination. Every vault that exists today therefore resolves
|
||||
* without being touched.
|
||||
*/
|
||||
[[nodiscard]] std::uint8_t
|
||||
getAccountingMethod(SLE::const_ref vault);
|
||||
|
||||
[[nodiscard]] std::optional<Number>
|
||||
struckPriceInForce(ReadView const& view, SLE::const_ref vault);
|
||||
|
||||
/**
|
||||
* Strike the price for the current window if it has not been struck yet.
|
||||
*
|
||||
* Called by the first deposit or withdrawal of a window. Does nothing for a
|
||||
* vault that is not rolling, outside a window, or where this window's price is
|
||||
* already struck, so it is safe to call unconditionally.
|
||||
*/
|
||||
void
|
||||
strikeWindowPrice(ApplyView& view, SLE::ref vault, SLE::const_ref issuance);
|
||||
|
||||
/**
|
||||
* Credit interest earned since the last settlement into sfAssetsTotal, draw
|
||||
* it out of the sfUnearnedInterest budget, and stamp the current close time.
|
||||
*
|
||||
* Must be called before adjusting sfAccrualRate, so the elapsed period is
|
||||
* charged at the rate that was in effect over it. Only the ttLOAN_*
|
||||
* transactions may call this: ValidVault requires sfAssetsTotal to move with
|
||||
* the vault balance on deposit and withdraw, which settling would violate.
|
||||
* Pricing does not need it — the conversion helpers add elapsed interest
|
||||
* themselves.
|
||||
*/
|
||||
void
|
||||
accrueVault(ApplyView& view, SLE::ref vault);
|
||||
|
||||
/**
|
||||
* From the perspective of a vault, return the number of shares to give
|
||||
* depositor when they offer a fixed amount of assets. Note, since shares are
|
||||
* MPT, this number is integral and always truncated in this calculation.
|
||||
*
|
||||
* /**
|
||||
* * From the perspective of a vault, return the number of shares to give
|
||||
* * depositor when they offer a fixed amount of assets. Note, since shares are
|
||||
* * MPT, this number is integral and always truncated in this calculation.
|
||||
* *
|
||||
* * @param vault The vault SLE.
|
||||
* * @param issuance The MPTokenIssuance SLE for the vault's shares.
|
||||
* * @param assets The amount of assets to convert.
|
||||
* *
|
||||
* * @return The number of shares, or nullopt on error.
|
||||
* @param vault The vault SLE.
|
||||
* @param issuance The MPTokenIssuance SLE for the vault's shares.
|
||||
* @param assets The amount of assets to convert.
|
||||
*
|
||||
* @return The number of shares, or nullopt on error.
|
||||
*/
|
||||
[[nodiscard]] std::optional<STAmount>
|
||||
assetsToSharesDeposit(
|
||||
ReadView const& view,
|
||||
SLE::const_ref vault,
|
||||
SLE::const_ref issuance,
|
||||
STAmount const& assets);
|
||||
assetsToSharesDeposit(SLE::const_ref vault, SLE::const_ref issuance, STAmount const& assets);
|
||||
|
||||
/**
|
||||
* From the perspective of a vault, return the number of assets to take from
|
||||
@@ -135,11 +43,7 @@ assetsToSharesDeposit(
|
||||
* @return The number of assets, or nullopt on error.
|
||||
*/
|
||||
[[nodiscard]] std::optional<STAmount>
|
||||
sharesToAssetsDeposit(
|
||||
ReadView const& view,
|
||||
SLE::const_ref vault,
|
||||
SLE::const_ref issuance,
|
||||
STAmount const& shares);
|
||||
sharesToAssetsDeposit(SLE::const_ref vault, SLE::const_ref issuance, STAmount const& shares);
|
||||
|
||||
/**
|
||||
* Adjusts a requested asset change (`delta`) to match the decimal scale of the
|
||||
@@ -187,12 +91,11 @@ enum class WaiveUnrealizedLoss : bool { No = false, Yes = true };
|
||||
* unrealized loss is waived. Used by assetsToSharesWithdraw and
|
||||
* sharesToAssetsWithdraw as the numerator of the share/asset exchange rate.
|
||||
*
|
||||
* @param view The ledger view, for interest accrued since the last settlement.
|
||||
* @param vault The vault SLE.
|
||||
* @param waive Whether to skip subtracting the unrealized loss.
|
||||
*/
|
||||
[[nodiscard]] Number
|
||||
assetsTotalForWithdrawal(ReadView const& view, SLE::const_ref vault, WaiveUnrealizedLoss waive);
|
||||
assetsTotalForWithdrawal(SLE::const_ref vault, WaiveUnrealizedLoss waive);
|
||||
|
||||
/**
|
||||
* Returns true if debiting `amount` from `total` (the current value of a
|
||||
@@ -228,7 +131,6 @@ debitIsNonZeroDust(Asset const& asset, Number const& total, Number const& amount
|
||||
*/
|
||||
[[nodiscard]] std::optional<STAmount>
|
||||
assetsToSharesWithdraw(
|
||||
ReadView const& view,
|
||||
SLE::const_ref vault,
|
||||
SLE::const_ref issuance,
|
||||
STAmount const& assets,
|
||||
@@ -250,7 +152,6 @@ assetsToSharesWithdraw(
|
||||
*/
|
||||
[[nodiscard]] std::optional<STAmount>
|
||||
sharesToAssetsWithdraw(
|
||||
ReadView const& view,
|
||||
SLE::const_ref vault,
|
||||
SLE::const_ref issuance,
|
||||
STAmount const& shares,
|
||||
|
||||
@@ -26,7 +26,8 @@ struct Config
|
||||
/**
|
||||
* The largest number of public peer slots to allow.
|
||||
* This includes both inbound and outbound, but does not include
|
||||
* fixed peers.
|
||||
* fixed peers. A configuration built by `makeConfig` always holds
|
||||
* `maxPeers == inPeers + outPeers`.
|
||||
*/
|
||||
std::size_t maxPeers{tuning::kDefaultMaxPeers};
|
||||
|
||||
|
||||
@@ -84,6 +84,25 @@ message TMPublicKey {
|
||||
// If you want to send an amount that is greater than any single address of yours
|
||||
// you must first combine coins from one address to another.
|
||||
|
||||
// Trace context for OpenTelemetry distributed tracing across nodes.
|
||||
// Uses W3C Trace Context format internally.
|
||||
//
|
||||
// Field numbering note: this message is embedded as field 1001 on
|
||||
// TMTransaction, TMProposeSet, and TMValidation. Field numbers >= 1000
|
||||
// are reserved for optional, observability-only additions that must not
|
||||
// collide with protocol-semantic fields (which historically use 1-99).
|
||||
// Older peers that do not understand field 1001 will simply ignore it
|
||||
// per protobuf wire-format rules, preserving backwards compatibility.
|
||||
//
|
||||
// trace_state is reserved for future use. It is currently neither
|
||||
// populated on inject nor read on extract; consumers must not rely on it.
|
||||
message TraceContext {
|
||||
optional bytes trace_id = 1; // 16-byte trace identifier
|
||||
optional bytes span_id = 2; // 8-byte parent span identifier
|
||||
optional uint32 trace_flags = 3; // bit 0 = sampled
|
||||
optional string trace_state = 4; // RESERVED — see TraceContext header note
|
||||
}
|
||||
|
||||
enum TransactionStatus {
|
||||
tsNEW = 1; // origin node did/could not validate
|
||||
tsCURRENT = 2; // scheduled to go in this ledger
|
||||
@@ -100,6 +119,9 @@ message TMTransaction {
|
||||
required TransactionStatus status = 2;
|
||||
optional uint64 receiveTimestamp = 3;
|
||||
optional bool deferred = 4; // not applied to open ledger
|
||||
|
||||
// Optional trace context for OpenTelemetry distributed tracing
|
||||
optional TraceContext trace_context = 1001;
|
||||
}
|
||||
|
||||
message TMTransactions {
|
||||
@@ -148,6 +170,9 @@ message TMProposeSet {
|
||||
|
||||
// Number of hops traveled
|
||||
optional uint32 hops = 12 [deprecated = true];
|
||||
|
||||
// Optional trace context for OpenTelemetry distributed tracing
|
||||
optional TraceContext trace_context = 1001;
|
||||
}
|
||||
|
||||
enum TxSetStatus {
|
||||
@@ -185,6 +210,9 @@ message TMValidation {
|
||||
|
||||
// Number of hops traveled
|
||||
optional uint32 hops = 3 [deprecated = true];
|
||||
|
||||
// Optional trace context for OpenTelemetry distributed tracing
|
||||
optional TraceContext trace_context = 1001;
|
||||
}
|
||||
|
||||
// An array of Endpoint messages
|
||||
|
||||
@@ -29,78 +29,6 @@ constexpr std::uint32_t kAuctionSlotIntervalDuration =
|
||||
constexpr std::uint16_t kVoteMaxSlots = 8;
|
||||
constexpr std::uint32_t kVoteWeightScaleFactor = 100000;
|
||||
|
||||
// Curve type identifiers
|
||||
enum CurveType : std::uint8_t {
|
||||
CtConstantProduct = 0,
|
||||
CtConcentratedLiquidity = 1,
|
||||
CtStableSwap = 2,
|
||||
CtBinned = 3,
|
||||
};
|
||||
|
||||
inline constexpr CurveType protocolCurveTypes[] = {
|
||||
CtConstantProduct,
|
||||
CtConcentratedLiquidity,
|
||||
CtStableSwap,
|
||||
CtBinned,
|
||||
};
|
||||
|
||||
// Fee tier definitions for concentrated liquidity
|
||||
enum FeeTier : std::uint8_t {
|
||||
FtStable = 0, // 1 bp, tick spacing 1
|
||||
FtLow = 1, // 5 bp, tick spacing 10
|
||||
FtMedium = 2, // 30 bp, tick spacing 60
|
||||
FtHigh = 3, // 100 bp, tick spacing 200
|
||||
};
|
||||
|
||||
inline constexpr std::uint16_t feeTierToFee[] = {1, 5, 30, 100};
|
||||
inline constexpr std::int32_t feeTierToTickSpacing[] = {1, 10, 60, 200};
|
||||
inline constexpr std::uint8_t feeTierCount = 4;
|
||||
|
||||
// Tick bounds
|
||||
inline constexpr std::int32_t minTick = -887272;
|
||||
inline constexpr std::int32_t maxTick = 887272;
|
||||
|
||||
// Offset-binary scaling applied wherever a tick is hashed or bit-packed
|
||||
// to keep arithmetic in unsigned domain (avoids signed-division surprises
|
||||
// near zero). Used by:
|
||||
// - keylet::ammTick (offset-encoded into the low 64 keylet bits)
|
||||
// - keylet::ammTickBitmapWord (wordIndex = (tick + offset) >> 8)
|
||||
// - Validthe AMM bitmap-consistency invariant
|
||||
// One constant, one source of fragility — DO NOT duplicate inline.
|
||||
inline constexpr std::uint32_t kTickBitmapOffset =
|
||||
static_cast<std::uint32_t>(-static_cast<std::int64_t>(minTick));
|
||||
|
||||
// StableSwap limits
|
||||
inline constexpr std::uint32_t minAmplification = 1;
|
||||
inline constexpr std::uint32_t maxAmplification = 5000;
|
||||
inline constexpr std::uint32_t maxAmpChangePct = 10;
|
||||
inline constexpr std::uint32_t ampRampDuration = 86400;
|
||||
|
||||
// Binned-curve limits. Bin step in basis points; bin price grows as
|
||||
// (1 + binStep/10000)^binID. Range bound keeps state size finite and
|
||||
// price range close to v3's effective range at default tick spacing.
|
||||
inline constexpr std::int32_t minBinID = -221818;
|
||||
inline constexpr std::int32_t maxBinID = 221818;
|
||||
inline constexpr std::uint16_t validBinSteps[] = {1, 5, 10, 25, 100};
|
||||
inline constexpr std::uint8_t binStepCount = 5;
|
||||
|
||||
// Newton's method convergence
|
||||
inline constexpr int newtonMaxIterations = 256;
|
||||
|
||||
// Concentrated-liquidity per-swap tick-crossing cap. Bounds the
|
||||
// per-swap work done by the curve's iterative tick traversal (each
|
||||
// crossing does one SHAMap lookup for the next initialised tick + one
|
||||
// SLE read). With FtStable's tickSpacing=1, 1000 crossings = ~10%
|
||||
// price range; with FtMedium's tickSpacing=60, 1000 crossings spans
|
||||
// the equivalent of a ~4x price move — both comfortably larger than
|
||||
// any reasonable swap requires. Hitting the cap produces a silent
|
||||
// partial fill: the curve returns the output realized over the first
|
||||
// `maxTickCrossings` boundaries, and the caller infers the cap from
|
||||
// the (smaller-than-requested) result. Uniswap v3 has no protocol
|
||||
// cap (only block gas); we cap here because XRPL has no metered
|
||||
// execution and the cap is the only fairness bound on per-swap work.
|
||||
inline constexpr int maxTickCrossings = 1000;
|
||||
|
||||
class STObject;
|
||||
class STAmount;
|
||||
class Rules;
|
||||
@@ -109,20 +37,13 @@ class Rules;
|
||||
* Calculate Liquidity Provider Token (LPT) Currency.
|
||||
*/
|
||||
Currency
|
||||
ammLPTCurrency(
|
||||
Asset const& asset1,
|
||||
Asset const& asset2,
|
||||
std::uint8_t curveType = CtConstantProduct);
|
||||
ammLPTCurrency(Asset const& asset1, Asset const& asset2);
|
||||
|
||||
/**
|
||||
* Calculate LPT Issue from AMM asset pair.
|
||||
*/
|
||||
Issue
|
||||
ammLPTIssue(
|
||||
Asset const& asset1,
|
||||
Asset const& asset2,
|
||||
AccountID const& ammAccountID,
|
||||
std::uint8_t curveType = CtConstantProduct);
|
||||
ammLPTIssue(Asset const& asset1, Asset const& asset2, AccountID const& ammAccountID);
|
||||
|
||||
/**
|
||||
* Validate the amount.
|
||||
|
||||
@@ -6,6 +6,7 @@
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/SField.h>
|
||||
#include <xrpl/protocol/STInteger.h> // IWYU pragma: keep
|
||||
#include <xrpl/protocol/STLedgerEntry.h>
|
||||
#include <xrpl/protocol/STObject.h>
|
||||
#include <xrpl/protocol/TER.h>
|
||||
#include <xrpl/protocol/UintTypes.h>
|
||||
@@ -16,7 +17,6 @@
|
||||
#include <cstdint>
|
||||
#include <limits>
|
||||
#include <optional>
|
||||
#include <vector>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
@@ -302,6 +302,63 @@ verifySchnorrProof(Slice const& pubKeySlice, Slice const& proofSlice, uint256 co
|
||||
NotTEC
|
||||
checkEncryptedAmountFormat(STObject const& object);
|
||||
|
||||
/**
|
||||
* @brief Checks whether a holder's issuer mirror is encrypted under the
|
||||
* issuance's currently registered issuer key.
|
||||
*
|
||||
* Verifies that the holder's issuer mirror epoch matches the active issuer key
|
||||
* epoch on the issuance. An absent mirror epoch defaults to epoch 0. A holder without an issuer
|
||||
* mirror is considered stale, as there is no key anchor for future re-encryptions.
|
||||
*
|
||||
* @param issuance The MPTokenIssuance ledger object.
|
||||
* @param mptoken The holder's MPToken ledger object.
|
||||
* @return true if the MPToken's issuer mirror is current. false if stale.
|
||||
*/
|
||||
[[nodiscard]] bool
|
||||
isIssuerMirrorCurrent(SLE const& issuance, SLE const& mptoken);
|
||||
|
||||
/**
|
||||
* @brief Checks whether a holder's auditor mirror is encrypted under the
|
||||
* issuance's currently registered auditor key.
|
||||
*
|
||||
* Verifies that the holder's auditor mirror epoch matches the active auditor key
|
||||
* epoch on the issuance. An absent mirror epoch defaults to epoch 0. An issuance
|
||||
* without an auditor key requires no auditor mirror and is considered current.
|
||||
*
|
||||
* @param issuance The MPTokenIssuance ledger object.
|
||||
* @param mptoken The holder's MPToken ledger object.
|
||||
* @return true if the auditor mirror is current or not required.
|
||||
*/
|
||||
[[nodiscard]] bool
|
||||
isAuditorMirrorCurrent(SLE const& issuance, SLE const& mptoken);
|
||||
|
||||
/**
|
||||
* @brief Checks whether each mirror a holder is required to have is encrypted
|
||||
* under the issuance's currently registered ElGamal keys.
|
||||
*
|
||||
* Verifies that both the issuer mirror and the auditor mirror (if required)
|
||||
* are current. This serves as a combined check, ensuring all necessary
|
||||
* holder mirror epochs match the active key epochs on the issuance.
|
||||
*
|
||||
* @param issuance The MPTokenIssuance ledger object.
|
||||
* @param mptoken The holder's MPToken ledger object.
|
||||
* @return true if the required mirrors are current.
|
||||
*/
|
||||
[[nodiscard]] bool
|
||||
areMirrorsCurrent(SLE const& issuance, SLE const& mptoken);
|
||||
|
||||
/**
|
||||
* @brief Set the holder's MPToken mirror epochs to match the issuance's current key epochs.
|
||||
*
|
||||
* Call this after writing mirror ciphertexts under the issuance's currently
|
||||
* registered keys, so that the mirrors read as current afterwards.
|
||||
*
|
||||
* @param issuance The MPTokenIssuance ledger object.
|
||||
* @param mptoken The holder's MPToken ledger entry to update.
|
||||
*/
|
||||
void
|
||||
setMirrorEpochs(SLE const& issuance, SLE& mptoken);
|
||||
|
||||
/**
|
||||
* @brief Verifies revealed amount encryptions for all recipients.
|
||||
*
|
||||
@@ -434,88 +491,4 @@ verifyConvertBackProof(
|
||||
uint64_t amount,
|
||||
uint256 const& contextHash);
|
||||
|
||||
/**
|
||||
* @brief Generates the context hash for a BallotCastVote transaction.
|
||||
*
|
||||
* Binds the cast's range proof to this specific transaction, preventing
|
||||
* proof reuse across ballots or accounts.
|
||||
*
|
||||
* @param account The voter's account ID.
|
||||
* @param ballotID The target ballot's ledger index.
|
||||
* @param sequence The transaction sequence number or ticket number.
|
||||
* @return A 256-bit context hash unique to this cast.
|
||||
*/
|
||||
uint256
|
||||
getBallotCastContextHash(AccountID const& account, uint256 const& ballotID, std::uint32_t sequence);
|
||||
|
||||
/**
|
||||
* @brief Generates the context hash for a BallotFinalize transaction.
|
||||
*
|
||||
* Binds each per-option decryption-correctness proof to this specific
|
||||
* finalize transaction.
|
||||
*
|
||||
* @param account The tally authority's account ID.
|
||||
* @param ballotID The target ballot's ledger index.
|
||||
* @param sequence The transaction sequence number or ticket number.
|
||||
* @return A 256-bit context hash unique to this finalize.
|
||||
*/
|
||||
uint256
|
||||
getBallotFinalizeContextHash(
|
||||
AccountID const& account,
|
||||
uint256 const& ballotID,
|
||||
std::uint32_t sequence);
|
||||
|
||||
/**
|
||||
* @brief Verifies an aggregated Bulletproof range proof over ballot option
|
||||
* commitments.
|
||||
*
|
||||
* Proves that every one of the N per-option values committed in
|
||||
* @p commitments lies in the non-negative range, so a vote cannot subtract
|
||||
* weight from a disliked option. Thin wrapper over
|
||||
* mpt_verify_aggregated_bulletproof.
|
||||
*
|
||||
* @param proof The serialized aggregated Bulletproof.
|
||||
* @param commitments One 33-byte Pedersen commitment per option.
|
||||
* @param contextHash The 256-bit context hash binding the proof.
|
||||
* @return tesSUCCESS if the proof is valid, or an error code otherwise.
|
||||
*/
|
||||
TER
|
||||
verifyBallotRangeProof(
|
||||
Slice const& proof,
|
||||
std::vector<Slice> const& commitments,
|
||||
uint256 const& contextHash);
|
||||
|
||||
/**
|
||||
* @brief Verifies the ciphertext-commitment linkage for one ballot option.
|
||||
*
|
||||
* Proves that the option's ElGamal ciphertext(s) encrypt the same value that
|
||||
* its Pedersen commitment commits to, and that every mirror ciphertext (tally,
|
||||
* optional auditor, optional voter) encrypts that same value under shared
|
||||
* randomness. Combined with the aggregated range proof over the commitment,
|
||||
* this pins the tally update to a non-negative value the voter cannot forge —
|
||||
* the verifiable-encryption guarantee a vote needs because it encrypts under
|
||||
* the tally key, which the voter does not own.
|
||||
*
|
||||
* Wraps secp256k1_compact_standard_verify. The balance-linkage terms of that
|
||||
* relation are neutralized with a canonical witness (sk_A = 1, rho_b = 1), so
|
||||
* pk_A = G, PC_b = H and B1 = B2 = G are reconstructed identically here and by
|
||||
* the prover, and only the 192-byte proof is carried on the wire.
|
||||
*
|
||||
* @param pubKeys The n mirror public keys, tally key first (33 bytes each).
|
||||
* @param c1 The shared ElGamal C1 component (33 bytes).
|
||||
* @param c2PerKey The n ElGamal C2 components, one per mirror key (33 bytes).
|
||||
* @param commitment The option's Pedersen commitment PC_m (33 bytes).
|
||||
* @param proof The 192-byte compact sigma linkage proof.
|
||||
* @param contextHash The 256-bit context hash binding the proof.
|
||||
* @return tesSUCCESS if the linkage holds, or an error code otherwise.
|
||||
*/
|
||||
TER
|
||||
verifyBallotVoteLinkage(
|
||||
std::vector<Slice> const& pubKeys,
|
||||
Slice const& c1,
|
||||
std::vector<Slice> const& c2PerKey,
|
||||
Slice const& commitment,
|
||||
Slice const& proof,
|
||||
uint256 const& contextHash);
|
||||
|
||||
} // namespace xrpl
|
||||
|
||||
@@ -1,77 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/protocol/Rules.h>
|
||||
#include <xrpl/protocol/TER.h>
|
||||
#include <xrpl/protocol/TxFormats.h>
|
||||
#include <xrpl/protocol/TxSettings.h>
|
||||
|
||||
#include <optional>
|
||||
#include <string>
|
||||
#include <unordered_map>
|
||||
|
||||
namespace xrpl {
|
||||
/**
|
||||
* We have both transaction type emitables and granular type emitables.
|
||||
* Since we will reuse the TransactionFormats to parse the Transaction
|
||||
* Emitables, only the GranularEmitableType is defined here. To prevent
|
||||
* conflicts with TxType, the GranularEmitableType is always set to a value
|
||||
* greater than the maximum value of uint16.
|
||||
*/
|
||||
enum GranularEmitableType : std::uint32_t {
|
||||
#pragma push_macro("EMITABLE")
|
||||
#undef EMITABLE
|
||||
|
||||
#define EMITABLE(type, txType, value) type = value,
|
||||
|
||||
#include <xrpl/protocol/detail/emitable.macro>
|
||||
|
||||
#undef EMITABLE
|
||||
#pragma pop_macro("EMITABLE")
|
||||
};
|
||||
|
||||
class Emitable
|
||||
{
|
||||
private:
|
||||
Emitable();
|
||||
|
||||
std::unordered_map<std::uint16_t, Emittance> emitableTx_;
|
||||
|
||||
std::unordered_map<std::string, GranularEmitableType> granularEmitableMap_;
|
||||
|
||||
std::unordered_map<GranularEmitableType, std::string> granularNameMap_;
|
||||
|
||||
std::unordered_map<GranularEmitableType, TxType> granularTxTypeMap_;
|
||||
|
||||
public:
|
||||
static Emitable const&
|
||||
getInstance();
|
||||
|
||||
Emitable(Emitable const&) = delete;
|
||||
Emitable&
|
||||
operator=(Emitable const&) = delete;
|
||||
|
||||
std::optional<std::string>
|
||||
getEmitableName(std::uint32_t const value) const;
|
||||
|
||||
std::optional<std::uint32_t>
|
||||
getGranularValue(std::string const& name) const;
|
||||
|
||||
std::optional<std::string>
|
||||
getGranularName(GranularEmitableType const& value) const;
|
||||
|
||||
std::optional<TxType>
|
||||
getGranularTxType(GranularEmitableType const& gpType) const;
|
||||
|
||||
bool
|
||||
isEmitable(std::uint32_t const& emitableValue) const;
|
||||
|
||||
// for tx level emitable, emitable value is equal to tx type plus one
|
||||
uint32_t
|
||||
txToEmitableType(TxType const& type) const;
|
||||
|
||||
// tx type value is emitable value minus one
|
||||
TxType
|
||||
emitableToTxType(uint32_t const& value) const;
|
||||
};
|
||||
|
||||
} // namespace xrpl
|
||||
@@ -10,15 +10,6 @@ namespace xrpl {
|
||||
// This was the reference fee units used in the old fee calculation.
|
||||
inline constexpr std::uint32_t kFeeUnitsDeprecated = 10;
|
||||
|
||||
// Number of micro-drops in one drop.
|
||||
constexpr std::uint32_t microDropsPerDrop{1'000'000};
|
||||
|
||||
/**
|
||||
* Maximum Feature Extension fee settings.
|
||||
*/
|
||||
inline constexpr std::uint32_t kMaxGasLimit{2'000'000};
|
||||
inline constexpr std::uint32_t kMaxBytecodeSizeLimit{200'000};
|
||||
|
||||
/**
|
||||
* Reflects the fee settings for a particular ledger.
|
||||
*
|
||||
@@ -42,21 +33,6 @@ struct Fees
|
||||
*/
|
||||
XRPAmount increment{0};
|
||||
|
||||
/**
|
||||
* @brief Gas limit for Feature Extensions (instructions).
|
||||
*/
|
||||
std::uint32_t gasLimit{0};
|
||||
|
||||
/**
|
||||
* @brief Bytecode size limit for Feature Extensions (bytes).
|
||||
*/
|
||||
std::uint32_t bytecodeSizeLimit{0};
|
||||
|
||||
/**
|
||||
* @brief Price of WASM gas (micro-drops).
|
||||
*/
|
||||
std::uint32_t gasPrice{0};
|
||||
|
||||
explicit Fees() = default;
|
||||
Fees(Fees const&) = default;
|
||||
Fees&
|
||||
|
||||
@@ -1,17 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/protocol/TxFormats.h>
|
||||
#include <xrpl/protocol/TxSettings.h>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
/**
|
||||
* How an account's firewall treats a transaction of the given type.
|
||||
*
|
||||
* The classification is declared per transaction in transactions.macro. A type
|
||||
* the switch does not name, which means a deprecated one, is allowed.
|
||||
*/
|
||||
[[nodiscard]] FirewallAction
|
||||
firewallAction(TxType txType) noexcept;
|
||||
|
||||
} // namespace xrpl
|
||||
@@ -15,43 +15,13 @@
|
||||
#include <xrpl/protocol/SeqProxy.h>
|
||||
#include <xrpl/protocol/UintTypes.h>
|
||||
|
||||
#include <boost/endian/conversion.hpp>
|
||||
|
||||
#include <array>
|
||||
#include <cstdint>
|
||||
#include <cstring>
|
||||
#include <functional>
|
||||
#include <set>
|
||||
#include <utility>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
class SeqProxy;
|
||||
|
||||
// Structured-key helpers: read/write the low 64 bits of a uint256 keylet
|
||||
// in big-endian byte order. Used by every AMM keylet scheme that
|
||||
// embeds an ordered subkey (tick index, bitmap-word index, bin ID) into
|
||||
// the low 64 bits so SHAMap range walks visit entries in subkey order.
|
||||
//
|
||||
// We type-pun via std::memcpy rather than a reinterpret_cast through
|
||||
// uint64_t* — the latter violates strict aliasing and has no alignment
|
||||
// guarantee on base_uint's underlying byte storage. memcpy of an
|
||||
// 8-byte value compiles to a single load/store on x86_64 / ARM64 under
|
||||
// any optimization level, so the safer idiom is free at runtime.
|
||||
inline void
|
||||
setLow64BE(uint256& key, std::uint64_t value) noexcept
|
||||
{
|
||||
auto const be = boost::endian::native_to_big(value);
|
||||
std::memcpy(key.end() - sizeof(std::uint64_t), &be, sizeof(std::uint64_t));
|
||||
}
|
||||
|
||||
[[nodiscard]] inline std::uint64_t
|
||||
getLow64BE(uint256 const& key) noexcept
|
||||
{
|
||||
std::uint64_t be;
|
||||
std::memcpy(&be, key.end() - sizeof(std::uint64_t), sizeof(std::uint64_t));
|
||||
return boost::endian::big_to_native(be);
|
||||
}
|
||||
/**
|
||||
* Keylet computation functions.
|
||||
*
|
||||
@@ -136,9 +106,7 @@ book(Book const& b);
|
||||
* BTC, and Bob trusts Alice for BTC, here is only a single BTC trust line
|
||||
* between them.
|
||||
*/
|
||||
/**
|
||||
* @{.
|
||||
*/
|
||||
/** @{ */
|
||||
Keylet
|
||||
trustLine(AccountID const& id0, AccountID const& id1, Currency const& currency) noexcept;
|
||||
|
||||
@@ -147,16 +115,12 @@ trustLine(AccountID const& id, Issue const& issue) noexcept
|
||||
{
|
||||
return trustLine(id, issue.account, issue.currency);
|
||||
}
|
||||
/**
|
||||
* @}.
|
||||
*/
|
||||
/** @} */
|
||||
|
||||
/**
|
||||
* An offer from an account
|
||||
*/
|
||||
/**
|
||||
* @{.
|
||||
*/
|
||||
/** @{ */
|
||||
Keylet
|
||||
offer(AccountID const& id, SeqProxy const& seq) noexcept;
|
||||
|
||||
@@ -165,9 +129,7 @@ offer(uint256 const& key) noexcept
|
||||
{
|
||||
return {ltOFFER, key};
|
||||
}
|
||||
/**
|
||||
* @}.
|
||||
*/
|
||||
/** @} */
|
||||
|
||||
/**
|
||||
* The initial directory page for a specific quality
|
||||
@@ -184,9 +146,7 @@ next(Keylet const& k);
|
||||
/**
|
||||
* A ticket belonging to an account
|
||||
*/
|
||||
/**
|
||||
* @{.
|
||||
*/
|
||||
/** @{ */
|
||||
Keylet
|
||||
ticket(AccountID const& id, SeqProxy const& ticketSeq);
|
||||
|
||||
@@ -195,9 +155,7 @@ ticket(uint256 const& key)
|
||||
{
|
||||
return {ltTICKET, key};
|
||||
}
|
||||
/**
|
||||
* @}.
|
||||
*/
|
||||
/** @} */
|
||||
|
||||
/**
|
||||
* A SignerList
|
||||
@@ -211,18 +169,10 @@ signerList(AccountID const& account) noexcept;
|
||||
Keylet
|
||||
sponsorship(AccountID const& sponsor, AccountID const& sponsee) noexcept;
|
||||
|
||||
/**
|
||||
* An account's beneficiary designation. One per account.
|
||||
*/
|
||||
Keylet
|
||||
beneficiary(AccountID const& account) noexcept;
|
||||
|
||||
/**
|
||||
* A Check
|
||||
*/
|
||||
/**
|
||||
* @{.
|
||||
*/
|
||||
/** @{ */
|
||||
Keylet
|
||||
check(AccountID const& id, SeqProxy const& seq) noexcept;
|
||||
|
||||
@@ -231,16 +181,12 @@ check(uint256 const& key) noexcept
|
||||
{
|
||||
return {ltCHECK, key};
|
||||
}
|
||||
/**
|
||||
* @}.
|
||||
*/
|
||||
/** @} */
|
||||
|
||||
/**
|
||||
* A DepositPreauth
|
||||
*/
|
||||
/**
|
||||
* @{.
|
||||
*/
|
||||
/** @{ */
|
||||
Keylet
|
||||
depositPreauth(AccountID const& owner, AccountID const& preauthorized) noexcept;
|
||||
|
||||
@@ -254,9 +200,7 @@ depositPreauth(uint256 const& key) noexcept
|
||||
{
|
||||
return {ltDEPOSIT_PREAUTH, key};
|
||||
}
|
||||
/**
|
||||
* @}.
|
||||
*/
|
||||
/** @} */
|
||||
|
||||
//------------------------------------------------------------------------------
|
||||
|
||||
@@ -275,9 +219,7 @@ ownerDir(AccountID const& id) noexcept;
|
||||
/**
|
||||
* A page in a directory
|
||||
*/
|
||||
/**
|
||||
* @{.
|
||||
*/
|
||||
/** @{ */
|
||||
Keylet
|
||||
page(uint256 const& root, std::uint64_t const index = 0) noexcept;
|
||||
|
||||
@@ -287,9 +229,7 @@ page(Keylet const& root, std::uint64_t const index = 0) noexcept
|
||||
XRPL_ASSERT(root.type == ltDIR_NODE, "xrpl::keylet::page : valid root type");
|
||||
return page(root.key, index);
|
||||
}
|
||||
/**
|
||||
* @}.
|
||||
*/
|
||||
/** @} */
|
||||
|
||||
/**
|
||||
* An escrow entry
|
||||
@@ -297,12 +237,6 @@ page(Keylet const& root, std::uint64_t const index = 0) noexcept
|
||||
Keylet
|
||||
escrow(AccountID const& src, SeqProxy const& seq) noexcept;
|
||||
|
||||
inline Keylet
|
||||
escrow(uint256 const& key) noexcept
|
||||
{
|
||||
return {ltESCROW, key};
|
||||
}
|
||||
|
||||
/**
|
||||
* A PaymentChannel
|
||||
*/
|
||||
@@ -317,9 +251,7 @@ payChannel(AccountID const& src, AccountID const& dst, SeqProxy const& seq) noex
|
||||
* 160-bit AccountID, followed by a 96-bit value that determines which NFT
|
||||
* tokens are candidates for that page.
|
||||
*/
|
||||
/**
|
||||
* @{.
|
||||
*/
|
||||
/** @{ */
|
||||
/**
|
||||
* A keylet for the owner's first possible NFT page.
|
||||
*/
|
||||
@@ -334,9 +266,7 @@ nftokenPageMax(AccountID const& owner);
|
||||
|
||||
Keylet
|
||||
nftokenPage(Keylet const& k, uint256 const& token);
|
||||
/**
|
||||
* @}.
|
||||
*/
|
||||
/** @} */
|
||||
|
||||
/**
|
||||
* An offer from an account to buy or sell an NFT
|
||||
@@ -366,7 +296,7 @@ nftSells(uint256 const& id) noexcept;
|
||||
* AMM entry
|
||||
*/
|
||||
Keylet
|
||||
amm(Asset const& issue1, Asset const& issue2, std::uint8_t curveType = 0) noexcept;
|
||||
amm(Asset const& issue1, Asset const& issue2) noexcept;
|
||||
|
||||
Keylet
|
||||
amm(uint256 const& amm) noexcept;
|
||||
@@ -412,15 +342,6 @@ mptokenIssuance(uint256 const& issuanceKey)
|
||||
return {ltMPTOKEN_ISSUANCE, issuanceKey};
|
||||
}
|
||||
|
||||
Keylet
|
||||
tokenIssuance(AccountID const& issuer, Currency const& currency) noexcept;
|
||||
|
||||
inline Keylet
|
||||
tokenIssuance(uint256 const& key)
|
||||
{
|
||||
return {ltTOKEN_ISSUANCE, key};
|
||||
}
|
||||
|
||||
Keylet
|
||||
mptoken(MPTID const& issuanceID, AccountID const& holder) noexcept;
|
||||
|
||||
@@ -445,45 +366,6 @@ vault(uint256 const& vaultKey)
|
||||
Keylet
|
||||
loanBroker(AccountID const& owner, SeqProxy const& seq) noexcept;
|
||||
|
||||
/**
|
||||
* A repurchase agreement, keyed by the seller and the creating sequence.
|
||||
*/
|
||||
Keylet
|
||||
repo(AccountID const& seller, SeqProxy const& seq) noexcept;
|
||||
|
||||
inline Keylet
|
||||
repo(uint256 const& repoID)
|
||||
{
|
||||
return {ltREPO, repoID};
|
||||
}
|
||||
|
||||
/**
|
||||
* A firewall, keyed by the account it protects.
|
||||
*/
|
||||
Keylet
|
||||
firewall(AccountID const& account) noexcept;
|
||||
|
||||
inline Keylet
|
||||
firewall(uint256 const& firewallID)
|
||||
{
|
||||
return {ltFIREWALL, firewallID};
|
||||
}
|
||||
|
||||
/**
|
||||
* A withdraw preauthorization, keyed by owner, authorized account and tag.
|
||||
*/
|
||||
Keylet
|
||||
withdrawPreauth(
|
||||
AccountID const& owner,
|
||||
AccountID const& preauthorized,
|
||||
std::uint32_t dtag) noexcept;
|
||||
|
||||
inline Keylet
|
||||
withdrawPreauth(uint256 const& key)
|
||||
{
|
||||
return {ltWITHDRAW_PREAUTH, key};
|
||||
}
|
||||
|
||||
inline Keylet
|
||||
loanBroker(uint256 const& key)
|
||||
{
|
||||
@@ -499,174 +381,11 @@ loan(uint256 const& key)
|
||||
return {ltLOAN, key};
|
||||
}
|
||||
|
||||
Keylet
|
||||
couponSchedule(uint192 const& mptIssuanceID) noexcept;
|
||||
|
||||
inline Keylet
|
||||
couponSchedule(uint256 const& scheduleKey)
|
||||
{
|
||||
return {ltCOUPON_SCHEDULE, scheduleKey};
|
||||
}
|
||||
|
||||
Keylet
|
||||
permissionedDomain(AccountID const& account, SeqProxy const& seq) noexcept;
|
||||
|
||||
Keylet
|
||||
permissionedDomain(uint256 const& domainID) noexcept;
|
||||
|
||||
Keylet
|
||||
contractSource(uint256 const& contractHash) noexcept;
|
||||
|
||||
Keylet
|
||||
contract(uint256 const& contractHash, AccountID const& owner, std::uint32_t seq) noexcept;
|
||||
|
||||
inline Keylet
|
||||
contract(uint256 const& contractID)
|
||||
{
|
||||
return {ltCONTRACT, contractID};
|
||||
}
|
||||
|
||||
Keylet
|
||||
contractData(AccountID const& owner, AccountID const& contractAccount) noexcept;
|
||||
|
||||
Keylet
|
||||
passkeyList(AccountID const& account) noexcept;
|
||||
|
||||
/**
|
||||
* A ballot owned by `owner`, keyed by the creating transaction sequence.
|
||||
*/
|
||||
Keylet
|
||||
ballot(AccountID const& owner, std::uint32_t seq) noexcept;
|
||||
|
||||
inline Keylet
|
||||
ballot(uint256 const& ballotID)
|
||||
{
|
||||
return {ltBALLOT, ballotID};
|
||||
}
|
||||
|
||||
/**
|
||||
* A voter's cast on the ballot identified by `ballotID`.
|
||||
*/
|
||||
Keylet
|
||||
ballotVote(uint256 const& ballotID, AccountID const& voter) noexcept;
|
||||
|
||||
inline Keylet
|
||||
ballotVote(uint256 const& key)
|
||||
{
|
||||
return {ltBALLOT_VOTE, key};
|
||||
}
|
||||
/**
|
||||
* A concentrated liquidity AMM position.
|
||||
*/
|
||||
Keylet
|
||||
ammPosition(uint256 const& ammID, AccountID const& owner, std::uint32_t seq) noexcept;
|
||||
|
||||
inline Keylet
|
||||
ammPosition(uint256 const& key)
|
||||
{
|
||||
return {ltAMM_POSITION, key};
|
||||
}
|
||||
|
||||
/**
|
||||
* A concentrated liquidity AMM tick.
|
||||
* Uses structured (non-hashed) keys for ordered SHAMap traversal.
|
||||
* High 192 bits: pool scope (from ammID hash).
|
||||
* Low 64 bits: encoded tick index (offset binary, big-endian).
|
||||
*/
|
||||
Keylet
|
||||
ammTick(uint256 const& ammID, std::int32_t tickIndex) noexcept;
|
||||
|
||||
inline Keylet
|
||||
ammTick(uint256 const& key)
|
||||
{
|
||||
return {ltAMM_TICK, key};
|
||||
}
|
||||
|
||||
/**
|
||||
* Base key for a CL pool's tick range (low 64 bits zeroed).
|
||||
*/
|
||||
Keylet
|
||||
ammTickBase(uint256 const& ammID) noexcept;
|
||||
|
||||
/**
|
||||
* End key for a CL pool's tick range (low 64 bits all 1s).
|
||||
*/
|
||||
Keylet
|
||||
ammTickEnd(uint256 const& ammID) noexcept;
|
||||
|
||||
/**
|
||||
* A 256-tick presence bitmap window for a CL pool.
|
||||
* Keylet structure mirrors `ammTick`: high 192 bits derive from a pool-scoped
|
||||
* hash, low 64 bits encode the word index (big-endian) so range walks via
|
||||
* SHAMap succ/pred yield the next-higher / next-lower word.
|
||||
*/
|
||||
Keylet
|
||||
ammTickBitmapWord(uint256 const& ammID, std::uint16_t wordIndex) noexcept;
|
||||
|
||||
inline Keylet
|
||||
ammTickBitmapWord(uint256 const& key)
|
||||
{
|
||||
return {ltAMM_TICK_BITMAP, key};
|
||||
}
|
||||
|
||||
/**
|
||||
* Base key for a CL pool's tick-bitmap range (low 64 bits zeroed).
|
||||
*/
|
||||
Keylet
|
||||
ammTickBitmapBase(uint256 const& ammID) noexcept;
|
||||
|
||||
/**
|
||||
* End key for a CL pool's tick-bitmap range (low 64 bits all 1s).
|
||||
*/
|
||||
Keylet
|
||||
ammTickBitmapEnd(uint256 const& ammID) noexcept;
|
||||
|
||||
/**
|
||||
* A single bin within a CtBinned AMM pool. Bins are keyed by signed
|
||||
* bin ID, offset-encoded into the low 64 bits of the keylet so SHAMap
|
||||
* range walks yield consecutive bins in price order.
|
||||
*/
|
||||
Keylet
|
||||
ammBin(uint256 const& ammID, std::int32_t binID) noexcept;
|
||||
|
||||
/**
|
||||
* Lookup a bin SLE by its raw key (used by transactors that have a
|
||||
* stored issuance / bin reference).
|
||||
*/
|
||||
Keylet
|
||||
ammBin(uint256 const& key) noexcept;
|
||||
|
||||
/**
|
||||
* Base / end keys for a binned AMM's bin-SLE range. Bins for the
|
||||
* same AMM are contiguous in SHAMap order (high 192 bits are an
|
||||
* ammID-scoped hash; low 64 bits offset-encode the bin ID), so
|
||||
* `view.succ(bin_at(binID).key, ammBinEnd(ammID).key)` jumps to the
|
||||
* next populated bin in O(log n) regardless of gap size.
|
||||
*/
|
||||
Keylet
|
||||
ammBinBase(uint256 const& ammID) noexcept;
|
||||
|
||||
Keylet
|
||||
ammBinEnd(uint256 const& ammID) noexcept;
|
||||
|
||||
/**
|
||||
* A single LP's holding record in a single bin. Phase 5 will replace
|
||||
* this with a fungible MPT issuance per bin.
|
||||
*/
|
||||
Keylet
|
||||
ammBinHolding(uint256 const& ammID, AccountID const& owner, std::int32_t binID) noexcept;
|
||||
|
||||
Keylet
|
||||
ammBinHolding(uint256 const& key) noexcept;
|
||||
|
||||
Keylet
|
||||
subscription(AccountID const& account, AccountID const& dest, std::uint32_t seq) noexcept;
|
||||
|
||||
inline Keylet
|
||||
subscription(uint256 const& key) noexcept
|
||||
{
|
||||
return {ltSUBSCRIPTION, key};
|
||||
}
|
||||
} // namespace keylet
|
||||
|
||||
// Everything below is deprecated and should be removed in favor of keylets:
|
||||
|
||||
@@ -8,8 +8,6 @@ namespace xrpl {
|
||||
enum class KeyType {
|
||||
Secp256k1 = 0,
|
||||
Ed25519 = 1,
|
||||
Dilithium = 2,
|
||||
P256 = 3,
|
||||
};
|
||||
|
||||
inline std::optional<KeyType>
|
||||
@@ -21,12 +19,6 @@ keyTypeFromString(std::string const& s)
|
||||
if (s == "ed25519")
|
||||
return KeyType::Ed25519;
|
||||
|
||||
if (s == "dilithium")
|
||||
return KeyType::Dilithium;
|
||||
|
||||
if (s == "p256")
|
||||
return KeyType::P256;
|
||||
|
||||
return {};
|
||||
}
|
||||
|
||||
@@ -39,12 +31,6 @@ to_string(KeyType type)
|
||||
if (type == KeyType::Ed25519)
|
||||
return "ed25519";
|
||||
|
||||
if (type == KeyType::Dilithium)
|
||||
return "dilithium";
|
||||
|
||||
if (type == KeyType::P256)
|
||||
return "p256";
|
||||
|
||||
return "INVALID";
|
||||
}
|
||||
|
||||
|
||||
@@ -85,6 +85,15 @@ enum LedgerEntryType : std::uint16_t {
|
||||
*/
|
||||
ltNICKNAME [[deprecated("This object type is not supported and should not be used.")]] = 0x006e,
|
||||
|
||||
/**
|
||||
* A legacy, deprecated type.
|
||||
*
|
||||
* @deprecated **This object type is not supported and should not be used.**
|
||||
* Support for this type of object was never implemented.
|
||||
* No objects of this type were ever created.
|
||||
*/
|
||||
ltCONTRACT [[deprecated("This object type is not supported and should not be used.")]] = 0x0063,
|
||||
|
||||
/**
|
||||
* A legacy, deprecated type.
|
||||
*
|
||||
@@ -145,8 +154,7 @@ enum LedgerEntryType : std::uint16_t {
|
||||
LEDGER_OBJECT(Offer, \
|
||||
LSF_FLAG(lsfPassive, 0x00010000) \
|
||||
LSF_FLAG(lsfSell, 0x00020000) /* True, offer was placed as a sell. */ \
|
||||
LSF_FLAG(lsfHybrid, 0x00040000) /* True, offer is hybrid. */ \
|
||||
LSF_FLAG(lsfAllOrNone, 0x00080000)) /* True, offer is all-or-none. */ \
|
||||
LSF_FLAG(lsfHybrid, 0x00040000)) /* True, offer is hybrid. */ \
|
||||
\
|
||||
LEDGER_OBJECT(RippleState, \
|
||||
LSF_FLAG(lsfLowReserve, 0x00010000) /* True, if entry counts toward reserve. */ \
|
||||
@@ -180,8 +188,7 @@ enum LedgerEntryType : std::uint16_t {
|
||||
LSF_FLAG(lsfMPTCanTrade, 0x00000010) \
|
||||
LSF_FLAG(lsfMPTCanTransfer, 0x00000020) \
|
||||
LSF_FLAG(lsfMPTCanClawback, 0x00000040) \
|
||||
LSF_FLAG(lsfMPTCanHoldConfidentialBalance, 0x00000080) \
|
||||
LSF_FLAG(lsfMPTCouponSchedule, 0x00000100)) \
|
||||
LSF_FLAG(lsfMPTCanHoldConfidentialBalance, 0x00000080)) \
|
||||
\
|
||||
LEDGER_OBJECT(MPToken, \
|
||||
LSF_FLAG2(lsfMPTLocked, 0x00000001) \
|
||||
@@ -201,20 +208,7 @@ enum LedgerEntryType : std::uint16_t {
|
||||
\
|
||||
LEDGER_OBJECT(Sponsorship, \
|
||||
LSF_FLAG(lsfSponsorshipRequireSignForFee, 0x00010000) \
|
||||
LSF_FLAG(lsfSponsorshipRequireSignForReserve, 0x00020000)) \
|
||||
\
|
||||
LEDGER_OBJECT(TokenIssuance, \
|
||||
LSF_FLAG(lsfTokenLocked, 0x00000001) /* True, per-currency global freeze */ \
|
||||
LSF_FLAG(lsfTokenCannotLock, 0x00000002) /* True, issuer renounced the per-currency lock */ \
|
||||
LSF_FLAG(lsfTokenWrapped, 0x00000004) /* True, owned by a pseudo-account (blackholed issuer) */ \
|
||||
LSF_FLAG(lsfTokenVerifiedSupply, 0x00000008)) /* True, IssuedAmount reflects verified legacy supply */ \
|
||||
\
|
||||
LEDGER_OBJECT(Ballot, \
|
||||
LSF_FLAG(lsfBallotFinalized, 0x00000001) /* True, results have been published */ \
|
||||
LSF_FLAG(lsfVoterRecoverable, 0x00000002)) /* True, casts carry a voter self-recovery vector */ \
|
||||
\
|
||||
LEDGER_OBJECT(Subscription, \
|
||||
LSF_FLAG(lsfSingleUse, 0x00010000)) /* True, delete on first successful claim */
|
||||
LSF_FLAG(lsfSponsorshipRequireSignForReserve, 0x00020000))
|
||||
|
||||
// clang-format on
|
||||
|
||||
|
||||
@@ -1,20 +1,10 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/basics/base_uint.h>
|
||||
#include <xrpl/beast/utility/Zero.h>
|
||||
#include <xrpl/protocol/AccountID.h>
|
||||
#include <xrpl/protocol/HashPrefix.h>
|
||||
#include <xrpl/protocol/IOUAmount.h>
|
||||
#include <xrpl/protocol/Issue.h>
|
||||
#include <xrpl/protocol/MPTAmount.h>
|
||||
#include <xrpl/protocol/MPTIssue.h>
|
||||
#include <xrpl/protocol/STAmount.h>
|
||||
#include <xrpl/protocol/Serializer.h>
|
||||
#include <xrpl/protocol/UintTypes.h>
|
||||
#include <xrpl/protocol/XRPAmount.h>
|
||||
|
||||
#include <cstdint>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
inline void
|
||||
@@ -25,70 +15,4 @@ serializePayChanAuthorization(Serializer& msg, uint256 const& key, XRPAmount con
|
||||
msg.add64(amt.drops());
|
||||
}
|
||||
|
||||
inline void
|
||||
serializePayChanAuthorization(
|
||||
Serializer& msg,
|
||||
uint256 const& key,
|
||||
IOUAmount const& amt,
|
||||
Currency const& cur,
|
||||
AccountID const& iss)
|
||||
{
|
||||
msg.add32(HashPrefix::PaymentChannelClaim);
|
||||
msg.addBitString(key);
|
||||
if (amt == beast::kZero)
|
||||
{
|
||||
msg.add64(STAmount::kIssuedCurrency);
|
||||
}
|
||||
else if (amt.signum() == -1)
|
||||
{ // 512 = not native; the sign is encoded by omitting the 256 flag, so
|
||||
// the mantissa must be serialized as its absolute value
|
||||
msg.add64(
|
||||
static_cast<std::uint64_t>(-amt.mantissa()) |
|
||||
(static_cast<std::uint64_t>(amt.exponent() + 512 + 97) << (64 - 10)));
|
||||
}
|
||||
else
|
||||
{ // 256 = positive
|
||||
msg.add64(
|
||||
amt.mantissa() |
|
||||
(static_cast<std::uint64_t>(amt.exponent() + 512 + 256 + 97) << (64 - 10)));
|
||||
}
|
||||
msg.addBitString(cur);
|
||||
msg.addBitString(iss);
|
||||
}
|
||||
|
||||
inline void
|
||||
serializePayChanAuthorization(
|
||||
Serializer& msg,
|
||||
uint256 const& key,
|
||||
MPTAmount const& amt,
|
||||
MPTID const& mptID,
|
||||
AccountID const& iss)
|
||||
{
|
||||
msg.add32(HashPrefix::PaymentChannelClaim);
|
||||
msg.addBitString(key);
|
||||
msg.add64(amt.value());
|
||||
msg.addBitString(mptID);
|
||||
msg.addBitString(iss);
|
||||
}
|
||||
|
||||
inline void
|
||||
serializePayChanAuthorization(Serializer& msg, uint256 const& key, STAmount const& amt)
|
||||
{
|
||||
if (amt.native())
|
||||
{
|
||||
serializePayChanAuthorization(msg, key, amt.xrp());
|
||||
}
|
||||
else if (amt.holds<Issue>())
|
||||
{
|
||||
serializePayChanAuthorization(
|
||||
msg, key, amt.iou(), amt.get<Issue>().currency, amt.get<Issue>().account);
|
||||
}
|
||||
else if (amt.holds<MPTIssue>())
|
||||
{
|
||||
auto const& mpt = amt.get<MPTIssue>();
|
||||
auto const& mptID = mpt.getMptID();
|
||||
serializePayChanAuthorization(msg, key, amt.mpt(), mptID, amt.getIssuer());
|
||||
}
|
||||
}
|
||||
|
||||
} // namespace xrpl
|
||||
|
||||
@@ -141,13 +141,6 @@ tenthBipsOfValue(T value, TenthBips<TBips> bips)
|
||||
return value * bips.value() / kTenthBipsPerUnity.value();
|
||||
}
|
||||
|
||||
/**
|
||||
* The longest inactivity period a beneficiary designation may require, ten
|
||||
* years in seconds. Long enough for the intended use and short enough that the
|
||||
* value still means something.
|
||||
*/
|
||||
constexpr std::uint32_t kMaxBeneficiaryTimeLock = 10 * 365 * 24 * 60 * 60;
|
||||
|
||||
namespace lending {
|
||||
/**
|
||||
* The maximum management fee rate allowed by a loan broker in 1/10 bips.
|
||||
@@ -309,29 +302,11 @@ static_assert(Number::kMaxRep >= kMaxMpTokenAmount);
|
||||
*/
|
||||
constexpr std::size_t kMaxDataPayloadLength = 256;
|
||||
|
||||
/**
|
||||
* The maximum length of a structured-data Schema
|
||||
*/
|
||||
constexpr std::size_t kMaxSchemaLength = 256;
|
||||
|
||||
/**
|
||||
* Vault withdrawal policies
|
||||
*/
|
||||
constexpr std::uint8_t kVaultStrategyFirstComeFirstServe = 1;
|
||||
|
||||
/**
|
||||
* Vault interest recognition methods.
|
||||
*
|
||||
* Legacy recognizes a loan's whole-life interest at origination and is the
|
||||
* implicit method for vaults created before featureLendingProtocolV1_1. Cash
|
||||
* recognizes interest as it is collected; accrual recognizes it continuously
|
||||
* as it is earned. Fixed at VaultCreate — changing it would reprice every
|
||||
* outstanding share in a single step.
|
||||
*/
|
||||
constexpr std::uint8_t kVaultAccountingLegacy = 0;
|
||||
constexpr std::uint8_t kVaultAccountingCash = 1;
|
||||
constexpr std::uint8_t kVaultAccountingAccrual = 2;
|
||||
|
||||
/**
|
||||
* Default IOU scale factor for a Vault
|
||||
*/
|
||||
@@ -341,13 +316,7 @@ constexpr std::uint8_t kVaultDefaultIouScale = 6;
|
||||
* 1 IOU can be always converted to shares.
|
||||
* 10^19 > maxMPTokenAmount (2^64-1) > 10^18
|
||||
*/
|
||||
constexpr std::uint8_t kVaultMaximumIouScale =
|
||||
18; /** Largest deposit or redemption fee a vault may charge, in 1/10 bips.
|
||||
|
||||
Matches kMaxTransferFee: half of what is moved is the most any fee may
|
||||
retain.
|
||||
*/
|
||||
constexpr std::uint32_t kMaxVaultFee = 50'000;
|
||||
constexpr std::uint8_t kVaultMaximumIouScale = 18;
|
||||
|
||||
/**
|
||||
* Vault ledger-entry schema versions. Assigned to newly created
|
||||
@@ -361,16 +330,12 @@ enum class VaultVersion : uint8_t {
|
||||
};
|
||||
|
||||
/**
|
||||
* Vault kind. Distinguishes closed-ended and rolling vaults from the default
|
||||
* open-ended kind. Persisted as sfVaultKind (UINT8); absent means OpenEnded.
|
||||
*
|
||||
* A rolling vault deals in a window that reopens every sfDealingInterval
|
||||
* seconds and stays open for sfDealingWindow of them.
|
||||
* Vault kind. Distinguishes closed-ended vaults from the default open-ended
|
||||
* kind. Persisted as sfVaultKind (UINT8); absent means OpenEnded.
|
||||
*/
|
||||
enum class VaultKind : std::uint8_t {
|
||||
OpenEnded = 0,
|
||||
ClosedEnded = 1,
|
||||
Rolling = 2,
|
||||
};
|
||||
|
||||
/**
|
||||
@@ -411,30 +376,6 @@ constexpr std::uint32_t kMaxInvestmentPeriod = std::chrono::seconds{std::chrono:
|
||||
*/
|
||||
constexpr std::uint8_t kMaxAssetCheckDepth = 5;
|
||||
|
||||
/**
|
||||
* Maximum length of a Data field in Escrow object that can be updated by WASM code.
|
||||
*/
|
||||
constexpr std::size_t kMaxWasmDataLength = 1 * 1024; // 1KB
|
||||
|
||||
/**
|
||||
* Maximum amount of data transfer across hostfunction<->wasm border.
|
||||
*/
|
||||
constexpr std::size_t kWasmTransferLimit = 1 << 20; // 1MB
|
||||
|
||||
/**
|
||||
* Maximum MaximumAmount of a TokenIssuance, in base units (10^15). Bounded
|
||||
* to what Number/STAmount arithmetic represents exactly, so the supply-cap
|
||||
* comparison can never be affected by mantissa rounding.
|
||||
*/
|
||||
constexpr std::uint64_t kMaxTokenIssuanceAmount = 1'000'000'000'000'000ull;
|
||||
static_assert(kMaxTokenIssuanceAmount <= kMaxMpTokenAmount);
|
||||
|
||||
/**
|
||||
* Maximum TokenScale of a TokenIssuance: 10^scale must stay in exact int64
|
||||
* range. 10^19 > 2^63-1 > 10^18
|
||||
*/
|
||||
constexpr std::uint8_t kMaxTokenIssuanceScale = 18;
|
||||
|
||||
/**
|
||||
* A ledger index.
|
||||
*/
|
||||
|
||||
@@ -36,12 +36,10 @@ namespace xrpl {
|
||||
* information needed to determine the cryptosystem
|
||||
* parameters used is stored inside the key.
|
||||
*
|
||||
* As of this writing three systems are supported:
|
||||
* As of this writing two systems are supported:
|
||||
*
|
||||
* secp256k1
|
||||
* ed25519
|
||||
* dilithium
|
||||
* p256
|
||||
*
|
||||
* secp256k1 public keys consist of a 33 byte
|
||||
* compressed public key, with the lead byte equal
|
||||
@@ -50,19 +48,14 @@ namespace xrpl {
|
||||
* The ed25519 public keys consist of a 1 byte
|
||||
* prefix constant 0xED, followed by 32 bytes of
|
||||
* public key data.
|
||||
*
|
||||
* The dilithium public keys will have their own specific format.
|
||||
*/
|
||||
class PublicKey
|
||||
{
|
||||
protected:
|
||||
// Minimum / standard public key size (secp256k1, ed25519).
|
||||
// All the constructed public keys are valid, non-empty and contain 33
|
||||
// bytes of data.
|
||||
static constexpr std::size_t kSize = 33;
|
||||
// Buffer sized for the largest supported key (dilithium = 1312 bytes;
|
||||
// uncompressed p256 = 65 bytes). Actual length is tracked in size_.
|
||||
static constexpr std::size_t kMaxSize = 1312;
|
||||
std::uint8_t buf_[kMaxSize]{};
|
||||
std::size_t size_ = 0;
|
||||
std::uint8_t buf_[kSize]{}; // should be large enough
|
||||
|
||||
public:
|
||||
using const_iterator = std::uint8_t const*;
|
||||
@@ -88,10 +81,10 @@ public:
|
||||
return buf_;
|
||||
}
|
||||
|
||||
[[nodiscard]] std::size_t
|
||||
size() const noexcept
|
||||
static std::size_t
|
||||
size() noexcept
|
||||
{
|
||||
return size_;
|
||||
return kSize;
|
||||
}
|
||||
|
||||
[[nodiscard]] const_iterator
|
||||
@@ -109,19 +102,19 @@ public:
|
||||
[[nodiscard]] const_iterator
|
||||
end() const noexcept
|
||||
{
|
||||
return buf_ + size_;
|
||||
return buf_ + kSize;
|
||||
}
|
||||
|
||||
[[nodiscard]] const_iterator
|
||||
cend() const noexcept
|
||||
{
|
||||
return buf_ + size_;
|
||||
return buf_ + kSize;
|
||||
}
|
||||
|
||||
[[nodiscard]] Slice
|
||||
slice() const noexcept
|
||||
{
|
||||
return {buf_, size_};
|
||||
return {buf_, kSize};
|
||||
}
|
||||
|
||||
operator Slice() const noexcept
|
||||
@@ -139,7 +132,7 @@ operator<<(std::ostream& os, PublicKey const& pk);
|
||||
inline bool
|
||||
operator==(PublicKey const& lhs, PublicKey const& rhs)
|
||||
{
|
||||
return lhs.size() == rhs.size() && std::memcmp(lhs.data(), rhs.data(), rhs.size()) == 0;
|
||||
return std::memcmp(lhs.data(), rhs.data(), rhs.size()) == 0;
|
||||
}
|
||||
|
||||
inline bool
|
||||
|
||||
@@ -34,9 +34,6 @@ class STNumber;
|
||||
class STXChainBridge;
|
||||
class STVector256;
|
||||
class STCurrency;
|
||||
class STData;
|
||||
class STDataType;
|
||||
class STJson;
|
||||
|
||||
// NOLINTBEGIN(readability-identifier-naming)
|
||||
#pragma push_macro("XMACRO")
|
||||
@@ -76,9 +73,6 @@ class STJson;
|
||||
STYPE(STI_ISSUE, 24) \
|
||||
STYPE(STI_XCHAIN_BRIDGE, 25) \
|
||||
STYPE(STI_CURRENCY, 26) \
|
||||
STYPE(STI_DATA, 27) \
|
||||
STYPE(STI_DATATYPE, 28) \
|
||||
STYPE(STI_JSON, 29) \
|
||||
\
|
||||
/* high-level types */ \
|
||||
/* cannot be serialized inside other types */ \
|
||||
@@ -365,9 +359,6 @@ using SF_NUMBER = TypedField<STNumber>;
|
||||
using SF_VL = TypedField<STBlob>;
|
||||
using SF_VECTOR256 = TypedField<STVector256>;
|
||||
using SF_XCHAIN_BRIDGE = TypedField<STXChainBridge>;
|
||||
using SF_DATA = TypedField<STData>;
|
||||
using SF_DATATYPE = TypedField<STDataType>;
|
||||
using SF_JSON = TypedField<STJson>;
|
||||
|
||||
//------------------------------------------------------------------------------
|
||||
|
||||
|
||||
@@ -1,289 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/basics/Buffer.h>
|
||||
#include <xrpl/protocol/SField.h>
|
||||
#include <xrpl/protocol/STAccount.h>
|
||||
#include <xrpl/protocol/STAmount.h>
|
||||
#include <xrpl/protocol/STBase.h>
|
||||
#include <xrpl/protocol/STBitString.h>
|
||||
#include <xrpl/protocol/STInteger.h>
|
||||
#include <xrpl/protocol/detail/STVar.h>
|
||||
|
||||
#include <cstdint>
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
class STData final : public STBase
|
||||
{
|
||||
private:
|
||||
using data_type = detail::STVar;
|
||||
std::uint16_t inner_type_;
|
||||
data_type data_;
|
||||
bool default_{true};
|
||||
|
||||
public:
|
||||
using value_type = STData; // Although not directly holding a single value
|
||||
|
||||
STData(SField const& n);
|
||||
STData(SField const& n, unsigned char);
|
||||
STData(SField const& n, std::uint16_t);
|
||||
STData(SField const& n, std::uint32_t);
|
||||
STData(SField const& n, std::uint64_t);
|
||||
STData(SField const& n, uint128 const&);
|
||||
STData(SField const& n, uint160 const&);
|
||||
STData(SField const& n, uint192 const&);
|
||||
STData(SField const& n, uint256 const&);
|
||||
STData(SField const& n, Blob const&);
|
||||
STData(SField const& n, Slice const&);
|
||||
STData(SField const& n, AccountID const&);
|
||||
STData(SField const& n, STAmount const&);
|
||||
STData(SField const& n, STIssue const&);
|
||||
STData(SField const& n, STCurrency const&);
|
||||
STData(SField const& n, STNumber const&);
|
||||
|
||||
STData(SerialIter& sit, SField const& name);
|
||||
|
||||
std::size_t
|
||||
size() const;
|
||||
|
||||
SerializedTypeID
|
||||
getSType() const override;
|
||||
|
||||
std::string
|
||||
getInnerTypeString() const;
|
||||
|
||||
std::string
|
||||
getText() const override;
|
||||
|
||||
json::Value getJson(JsonOptions) const override;
|
||||
|
||||
void
|
||||
add(Serializer& s) const override;
|
||||
|
||||
bool
|
||||
isEquivalent(STBase const& t) const override;
|
||||
|
||||
bool
|
||||
isDefault() const override;
|
||||
|
||||
SerializedTypeID
|
||||
getInnerSType() const noexcept;
|
||||
|
||||
STBase*
|
||||
makeFieldPresent();
|
||||
|
||||
void
|
||||
setFieldU8(unsigned char);
|
||||
void
|
||||
setFieldU16(std::uint16_t);
|
||||
void
|
||||
setFieldU32(std::uint32_t);
|
||||
void
|
||||
setFieldU64(std::uint64_t);
|
||||
void
|
||||
setFieldH128(uint128 const&);
|
||||
void
|
||||
setFieldH160(uint160 const&);
|
||||
void
|
||||
setFieldH192(uint192 const&);
|
||||
void
|
||||
setFieldH256(uint256 const&);
|
||||
void
|
||||
setFieldVL(Blob const&);
|
||||
void
|
||||
setFieldVL(Slice const&);
|
||||
void
|
||||
setAccountID(AccountID const&);
|
||||
void
|
||||
setFieldAmount(STAmount const&);
|
||||
void
|
||||
setIssue(STIssue const&);
|
||||
void
|
||||
setCurrency(STCurrency const&);
|
||||
void
|
||||
setFieldNumber(STNumber const&);
|
||||
|
||||
unsigned char
|
||||
getFieldU8() const;
|
||||
std::uint16_t
|
||||
getFieldU16() const;
|
||||
std::uint32_t
|
||||
getFieldU32() const;
|
||||
std::uint64_t
|
||||
getFieldU64() const;
|
||||
uint128
|
||||
getFieldH128() const;
|
||||
uint160
|
||||
getFieldH160() const;
|
||||
uint192
|
||||
getFieldH192() const;
|
||||
uint256
|
||||
getFieldH256() const;
|
||||
Blob
|
||||
getFieldVL() const;
|
||||
AccountID
|
||||
getAccountID() const;
|
||||
STAmount const&
|
||||
getFieldAmount() const;
|
||||
STIssue
|
||||
getFieldIssue() const;
|
||||
STCurrency
|
||||
getFieldCurrency() const;
|
||||
STNumber
|
||||
getFieldNumber() const;
|
||||
|
||||
private:
|
||||
STBase*
|
||||
copy(std::size_t n, void* buf) const override;
|
||||
STBase*
|
||||
move(std::size_t n, void* buf) override;
|
||||
|
||||
friend class detail::STVar;
|
||||
|
||||
// Implementation for getting (most) fields that return by value.
|
||||
//
|
||||
// The remove_cv and remove_reference are necessitated by the STBitString
|
||||
// types. Their value() returns by const ref. We return those types
|
||||
// by value.
|
||||
template <
|
||||
typename T,
|
||||
typename V = typename std::remove_cv<
|
||||
typename std::remove_reference<decltype(std::declval<T>().value())>::type>::type>
|
||||
V
|
||||
getFieldByValue() const;
|
||||
|
||||
// Implementations for getting (most) fields that return by const reference.
|
||||
//
|
||||
// If an absent optional field is deserialized we don't have anything
|
||||
// obvious to return. So we insist on having the call provide an
|
||||
// 'empty' value we return in that circumstance.
|
||||
template <typename T, typename V>
|
||||
V const&
|
||||
getFieldByConstRef(V const& empty) const;
|
||||
|
||||
// Implementation for setting most fields with a setValue() method.
|
||||
template <typename T, typename V>
|
||||
void
|
||||
setFieldUsingSetValue(V value);
|
||||
|
||||
// Implementation for setting fields using assignment
|
||||
template <typename T>
|
||||
void
|
||||
setFieldUsingAssignment(T const& value);
|
||||
};
|
||||
|
||||
//------------------------------------------------------------------------------
|
||||
// Implementation
|
||||
//------------------------------------------------------------------------------
|
||||
|
||||
inline SerializedTypeID
|
||||
STData::getInnerSType() const noexcept
|
||||
{
|
||||
return static_cast<SerializedTypeID>(inner_type_);
|
||||
}
|
||||
|
||||
template <typename T, typename V>
|
||||
V
|
||||
STData::getFieldByValue() const
|
||||
{
|
||||
STBase const* rf = &data_.get();
|
||||
|
||||
// if (!rf)
|
||||
// throwFieldNotFound(getFName());
|
||||
|
||||
SerializedTypeID const id = rf->getSType();
|
||||
|
||||
if (id == STI_NOTPRESENT)
|
||||
Throw<std::runtime_error>("Field not present");
|
||||
|
||||
T const* cf = dynamic_cast<T const*>(rf);
|
||||
|
||||
if (!cf)
|
||||
Throw<std::runtime_error>("Wrong field type");
|
||||
|
||||
return cf->value();
|
||||
}
|
||||
|
||||
// Implementations for getting (most) fields that return by const reference.
|
||||
//
|
||||
// If an absent optional field is deserialized we don't have anything
|
||||
// obvious to return. So we insist on having the call provide an
|
||||
// 'empty' value we return in that circumstance.
|
||||
template <typename T, typename V>
|
||||
V const&
|
||||
STData::getFieldByConstRef(V const& empty) const
|
||||
{
|
||||
STBase const* rf = &data_.get();
|
||||
|
||||
// if (!rf)
|
||||
// throwFieldNotFound(field);
|
||||
|
||||
SerializedTypeID const id = rf->getSType();
|
||||
|
||||
if (id == STI_NOTPRESENT)
|
||||
return empty; // optional field not present
|
||||
|
||||
T const* cf = dynamic_cast<T const*>(rf);
|
||||
|
||||
if (!cf)
|
||||
Throw<std::runtime_error>("Wrong field type");
|
||||
|
||||
return *cf;
|
||||
}
|
||||
|
||||
// Implementation for setting most fields with a setValue() method.
|
||||
template <typename T, typename V>
|
||||
void
|
||||
STData::setFieldUsingSetValue(V value)
|
||||
{
|
||||
static_assert(!std::is_lvalue_reference<V>::value, "");
|
||||
|
||||
STBase* rf = &data_.get();
|
||||
|
||||
// if (!rf)
|
||||
// throwFieldNotFound(field);
|
||||
|
||||
if (rf->getSType() == STI_NOTPRESENT)
|
||||
rf = makeFieldPresent();
|
||||
|
||||
T* cf = dynamic_cast<T*>(rf);
|
||||
|
||||
if (!cf)
|
||||
Throw<std::runtime_error>("Wrong field type");
|
||||
|
||||
cf->setValue(std::move(value));
|
||||
}
|
||||
|
||||
// Implementation for setting fields using assignment
|
||||
template <typename T>
|
||||
void
|
||||
STData::setFieldUsingAssignment(T const& value)
|
||||
{
|
||||
STBase* rf = &data_.get();
|
||||
|
||||
// if (!rf)
|
||||
// throwFieldNotFound(field);
|
||||
|
||||
// if (rf->getSType() == STI_NOTPRESENT)
|
||||
// rf = makeFieldPresent(field);
|
||||
|
||||
T* cf = dynamic_cast<T*>(rf);
|
||||
|
||||
if (!cf)
|
||||
Throw<std::runtime_error>("Wrong field type");
|
||||
|
||||
(*cf) = value;
|
||||
}
|
||||
|
||||
//------------------------------------------------------------------------------
|
||||
//
|
||||
// Creation
|
||||
//
|
||||
//------------------------------------------------------------------------------
|
||||
|
||||
STData
|
||||
dataFromJson(SField const& field, json::Value const& value);
|
||||
|
||||
} // namespace xrpl
|
||||
@@ -1,87 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/basics/Buffer.h>
|
||||
#include <xrpl/protocol/SField.h>
|
||||
#include <xrpl/protocol/STAccount.h>
|
||||
#include <xrpl/protocol/STAmount.h>
|
||||
#include <xrpl/protocol/STBase.h>
|
||||
#include <xrpl/protocol/STBitString.h>
|
||||
#include <xrpl/protocol/STInteger.h>
|
||||
#include <xrpl/protocol/detail/STVar.h>
|
||||
|
||||
#include <cstdint>
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
class STDataType final : public STBase
|
||||
{
|
||||
private:
|
||||
std::uint16_t inner_type_;
|
||||
bool default_{true};
|
||||
|
||||
public:
|
||||
using value_type = STDataType; // Although not directly holding a single value
|
||||
|
||||
STDataType(SField const& n);
|
||||
STDataType(SField const& n, SerializedTypeID);
|
||||
|
||||
STDataType(SerialIter& sit, SField const& name);
|
||||
|
||||
SerializedTypeID
|
||||
getSType() const override;
|
||||
|
||||
std::string
|
||||
getInnerTypeString() const;
|
||||
|
||||
std::string
|
||||
getText() const override;
|
||||
|
||||
json::Value getJson(JsonOptions) const override;
|
||||
|
||||
void
|
||||
add(Serializer& s) const override;
|
||||
|
||||
bool
|
||||
isEquivalent(STBase const& t) const override;
|
||||
|
||||
bool
|
||||
isDefault() const override;
|
||||
|
||||
void setInnerSType(SerializedTypeID);
|
||||
|
||||
SerializedTypeID
|
||||
getInnerSType() const noexcept;
|
||||
|
||||
STBase*
|
||||
makeFieldPresent();
|
||||
|
||||
STBase*
|
||||
copy(std::size_t n, void* buf) const override;
|
||||
STBase*
|
||||
move(std::size_t n, void* buf) override;
|
||||
|
||||
friend class detail::STVar;
|
||||
};
|
||||
|
||||
//------------------------------------------------------------------------------
|
||||
// Implementation
|
||||
//------------------------------------------------------------------------------
|
||||
|
||||
inline SerializedTypeID
|
||||
STDataType::getInnerSType() const noexcept
|
||||
{
|
||||
return static_cast<SerializedTypeID>(inner_type_);
|
||||
}
|
||||
|
||||
//------------------------------------------------------------------------------
|
||||
//
|
||||
// Creation
|
||||
//
|
||||
//------------------------------------------------------------------------------
|
||||
|
||||
STDataType
|
||||
dataTypeFromJson(SField const& field, json::Value const& value);
|
||||
|
||||
} // namespace xrpl
|
||||
@@ -1,193 +0,0 @@
|
||||
#pragma once
|
||||
|
||||
#include <xrpl/json/json_value.h>
|
||||
#include <xrpl/protocol/STBase.h>
|
||||
#include <xrpl/protocol/Serializer.h>
|
||||
|
||||
#include <map>
|
||||
#include <memory>
|
||||
#include <string>
|
||||
#include <variant>
|
||||
#include <vector>
|
||||
|
||||
namespace xrpl {
|
||||
|
||||
/**
|
||||
* STJson: Serialized Type for JSON-like structures (objects or arrays).
|
||||
*
|
||||
* Supports two modes:
|
||||
* - Object: Key-value pairs where keys are VL-encoded strings
|
||||
* - Array: Ordered list of values
|
||||
*
|
||||
* Values are [SType marker][VL-encoded SType serialization].
|
||||
* Values can be any SType, including nested STJson.
|
||||
*
|
||||
* Serialization format: [type_byte][VL_length][data...]
|
||||
* - type_byte: 0x00 = Object, 0x01 = Array
|
||||
*/
|
||||
class STJson : public STBase
|
||||
{
|
||||
public:
|
||||
enum class JsonType : uint8_t { Object = 0x00, Array = 0x01 };
|
||||
|
||||
using value_type = STJson;
|
||||
value_type
|
||||
value() const
|
||||
{
|
||||
return *this;
|
||||
}
|
||||
|
||||
using Key = std::string;
|
||||
using Value = std::shared_ptr<STBase>;
|
||||
using Map = std::map<Key, Value>;
|
||||
using Array = std::vector<Value>;
|
||||
|
||||
STJson() = default;
|
||||
|
||||
explicit STJson(Map&& map);
|
||||
explicit STJson(Array&& array);
|
||||
explicit STJson(SField const& name);
|
||||
explicit STJson(SerialIter& sit, SField const& name);
|
||||
|
||||
SerializedTypeID
|
||||
getSType() const override;
|
||||
|
||||
// Type checking
|
||||
bool
|
||||
isArray() const;
|
||||
|
||||
bool
|
||||
isObject() const;
|
||||
|
||||
JsonType
|
||||
getType() const;
|
||||
|
||||
// Depth checking (0 = no nesting, 1 = one level of nesting)
|
||||
int
|
||||
getDepth() const;
|
||||
|
||||
// Parse from binary blob
|
||||
static std::shared_ptr<STJson>
|
||||
fromBlob(void const* data, std::size_t size);
|
||||
|
||||
// Parse from SerialIter
|
||||
static std::shared_ptr<STJson>
|
||||
fromSerialIter(SerialIter& sit);
|
||||
|
||||
// Serialize to binary
|
||||
void
|
||||
add(Serializer& s) const override;
|
||||
|
||||
// JSON representation
|
||||
json::Value
|
||||
getJson(JsonOptions options) const override;
|
||||
|
||||
bool
|
||||
isEquivalent(STBase const& t) const override;
|
||||
|
||||
bool
|
||||
isDefault() const override;
|
||||
|
||||
// Blob representation
|
||||
Blob
|
||||
toBlob() const;
|
||||
|
||||
// STJson size
|
||||
std::size_t
|
||||
size() const;
|
||||
|
||||
// Object accessors (only valid when isObject() == true)
|
||||
Map const&
|
||||
getMap() const;
|
||||
|
||||
void
|
||||
setObjectField(Key const& key, Value const& value);
|
||||
|
||||
std::optional<STJson::Value>
|
||||
getObjectField(Key const& key) const;
|
||||
|
||||
void
|
||||
setNestedObjectField(Key const& key, Key const& nestedKey, Value const& value);
|
||||
|
||||
std::optional<Value>
|
||||
getNestedObjectField(Key const& key, Key const& nestedKey) const;
|
||||
|
||||
// Array accessors (only valid when isArray() == true)
|
||||
Array const&
|
||||
getArray() const;
|
||||
|
||||
void
|
||||
pushArrayElement(Value const& value);
|
||||
|
||||
std::optional<Value>
|
||||
getArrayElement(size_t index) const;
|
||||
|
||||
void
|
||||
setArrayElement(size_t index, Value const& value);
|
||||
|
||||
void
|
||||
setArrayElementField(size_t index, Key const& key, Value const& value);
|
||||
|
||||
std::optional<Value>
|
||||
getArrayElementField(size_t index, Key const& key) const;
|
||||
|
||||
size_t
|
||||
arraySize() const;
|
||||
|
||||
// Nested array accessors (for arrays stored in object fields)
|
||||
void
|
||||
setNestedArrayElement(Key const& key, size_t index, Value const& value);
|
||||
|
||||
void
|
||||
setNestedArrayElementField(
|
||||
Key const& key,
|
||||
size_t index,
|
||||
Key const& nestedKey,
|
||||
Value const& value);
|
||||
|
||||
std::optional<Value>
|
||||
getNestedArrayElement(Key const& key, size_t index) const;
|
||||
|
||||
std::optional<Value>
|
||||
getNestedArrayElementField(Key const& key, size_t index, Key const& nestedKey) const;
|
||||
|
||||
// Factory for SType value from blob (with SType marker)
|
||||
static Value
|
||||
makeValueFromVLWithType(SerialIter& sit);
|
||||
|
||||
void
|
||||
setValue(STJson const& v);
|
||||
|
||||
private:
|
||||
std::variant<Map, Array> data_{Map{}};
|
||||
bool default_{false};
|
||||
|
||||
// Helper: validate nesting depth (max 1 level)
|
||||
void
|
||||
validateDepth(Value const& value, int currentDepth) const;
|
||||
|
||||
// Helper: parse a single key-value pair from SerialIter
|
||||
static std::pair<Key, Value>
|
||||
parsePair(SerialIter& sit);
|
||||
|
||||
// Helper: parse array elements from SerialIter
|
||||
static Array
|
||||
parseArray(SerialIter& sit, int length);
|
||||
|
||||
// Helper: encode a key as VL
|
||||
static void
|
||||
addVLKey(Serializer& s, std::string const& str);
|
||||
|
||||
// Helper: encode a value as [SType marker][VL]
|
||||
static void
|
||||
addVLValue(Serializer& s, std::shared_ptr<STBase> const& value);
|
||||
|
||||
STBase*
|
||||
copy(std::size_t n, void* buf) const override;
|
||||
STBase*
|
||||
move(std::size_t n, void* buf) override;
|
||||
|
||||
friend class detail::STVar;
|
||||
};
|
||||
|
||||
} // namespace xrpl
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user