mirror of
https://github.com/XRPLF/rippled.git
synced 2026-09-26 23:19:07 +00:00
The OTLP/HTTP exporter selects TLS from the endpoint URL scheme alone (HttpSslOptions in the pinned SDK matches "https:" exactly), so a client certificate handed to it alongside an http:// traces_endpoint is loaded and never presented. The parser checked the cert/key pairing, use_tls and file readability, but never the scheme, and the default traces_endpoint is plain HTTP. makeTelemetrySetup() now requires traces_endpoint to start with "https://" whenever tls_client_cert is set, including when the key is left at its default. Nothing asserted the client options reaching the exporter, so a swapped certificate and key would have passed every test. Move the options mapping into makeTraceExporterOptions() and assert it at that boundary with distinct certificate and key paths, plus a one-way-TLS control and a use_tls=0 control. One case runs the whole path from a [telemetry] section. Runbook and example-config fixes: - tx.included is emitted per transaction of the agreed consensus set, before buildLCL() applies anything, so it is a superset of the accepted ledger rather than proof of inclusion. - the dispute.resolve query used the descendant operator, but the event is on the consensus.update_positions span itself, so it matched nothing. - the exhausted-retries query asked for txq_status="retried" with retries_remaining=0, which cannot occur: the attribute is stamped before the attempt and the retried branch only runs while retries are left. Exhaustion is txq_status="failed" with a zero count. - consensus_round_id is an int64, so the two queries comparing it to a quoted string matched nothing. - note that consensus_trace_strategy=random is experimental and not used. - note that a trailing "| attr = value" is rejected by current Tempo; attribute filters belong inside the braces.