Repository navigation
[tls_mgm] Add TLS handshake outcome and latency observability - #15
Draft
darwvin-dev wants to merge 1 commit into
Draft
darwvin-dev wants to merge 1 commit into
darwvin-dev wants to merge 1 commit into
Conversation
darwvin-dev
force-pushed
the
feature/tls-handshake-observability
branch
from
October 7, 2026 13:27
08d54fe to
1be2bf4
Compare
Export backend independent (OpenSSL and wolfSSL) handshake statistics: attempts, successes, failures, aborted, client vs server attempts, peer verified vs unverified, handshakes in progress and the cumulative handshake duration in microseconds. Each handshake is tracked once per TCP connection in a shared memory table sharded into 64 locked buckets by connection id, so a handshake spanning several non-blocking calls is counted exactly once and unrelated handshakes do not contend on a single lock. Latency uses the monotonic clock, and the tracker is only touched while a handshake is pending, so I/O on established connections has no extra cost. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
darwvin-dev
force-pushed
the
feature/tls-mgm-statistics
branch
from
October 7, 2026 13:50
d839b8a to
db03ff8
Compare
darwvin-dev
force-pushed
the
feature/tls-handshake-observability
branch
from
October 7, 2026 13:50
1be2bf4 to
76abbb6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to OpenSIPS#4283.
Add backend-independent TLS handshake observability in
tls_mgmwhile leaving the already mergeable active-connection statistics PR unchanged.Statistics
tls_mgm:handshake_attemptstls_mgm:handshake_successestls_mgm:handshake_failurestls_mgm:handshake_abortedtls_mgm:client_handshake_attemptstls_mgm:server_handshake_attemptstls_mgm:peer_verified_handshakestls_mgm:peer_unverified_handshakestls_mgm:handshakes_in_progresstls_mgm:handshake_duration_us_totalImplementation
TLS handshakes can span several non-blocking callbacks and can resume in another worker. A small shared-memory tracker keyed by the globally unique TCP connection id records one start timestamp per connection. The common
tls_mgmwrappers observe completion for both OpenSSL and wolfSSL, so the backend code does not need duplicated instrumentation.A zero return is intentionally not reported as a timeout because the backend API also uses zero for WANT_READ/WANT_WRITE / still-pending handshakes. Connections which disappear before completion are reported as
handshake_aborted, a subset of failures.This PR is intentionally based on
feature/tls-mgm-statistics. After OpenSIPS#4283 lands it can be rebased onto master.Draft pending compile/runtime validation.