Skip to content

[tls_mgm] Add TLS handshake outcome and latency observability - #15

Draft
darwvin-dev wants to merge 1 commit into
feature/tls-mgm-statisticsfrom
feature/tls-handshake-observability
Draft

darwvin-dev wants to merge 1 commit into
feature/tls-mgm-statisticsfrom
feature/tls-handshake-observability

Conversation

@darwvin-dev

Copy link
Copy Markdown
Owner

Summary

Follow-up to OpenSIPS#4283.

Add backend-independent TLS handshake observability in tls_mgm while leaving the already mergeable active-connection statistics PR unchanged.

Statistics

  • tls_mgm:handshake_attempts
  • tls_mgm:handshake_successes
  • tls_mgm:handshake_failures
  • tls_mgm:handshake_aborted
  • tls_mgm:client_handshake_attempts
  • tls_mgm:server_handshake_attempts
  • tls_mgm:peer_verified_handshakes
  • tls_mgm:peer_unverified_handshakes
  • tls_mgm:handshakes_in_progress
  • tls_mgm:handshake_duration_us_total

Implementation

TLS handshakes can span several non-blocking callbacks and can resume in another worker. A small shared-memory tracker keyed by the globally unique TCP connection id records one start timestamp per connection. The common tls_mgm wrappers observe completion for both OpenSSL and wolfSSL, so the backend code does not need duplicated instrumentation.

A zero return is intentionally not reported as a timeout because the backend API also uses zero for WANT_READ/WANT_WRITE / still-pending handshakes. Connections which disappear before completion are reported as handshake_aborted, a subset of failures.

This PR is intentionally based on feature/tls-mgm-statistics. After OpenSIPS#4283 lands it can be rebased onto master.

Draft pending compile/runtime validation.

@darwvin-dev
darwvin-dev force-pushed the feature/tls-handshake-observability branch from 08d54fe to 1be2bf4 Compare October 7, 2026 13:27
Export backend independent (OpenSSL and wolfSSL) handshake statistics:
attempts, successes, failures, aborted, client vs server attempts,
peer verified vs unverified, handshakes in progress and the cumulative
handshake duration in microseconds.

Each handshake is tracked once per TCP connection in a shared memory
table sharded into 64 locked buckets by connection id, so a handshake
spanning several non-blocking calls is counted exactly once and
unrelated handshakes do not contend on a single lock. Latency uses the
monotonic clock, and the tracker is only touched while a handshake is
pending, so I/O on established connections has no extra cost.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@darwvin-dev
darwvin-dev force-pushed the feature/tls-mgm-statistics branch from d839b8a to db03ff8 Compare October 7, 2026 13:50
@darwvin-dev
darwvin-dev force-pushed the feature/tls-handshake-observability branch from 1be2bf4 to 76abbb6 Compare October 7, 2026 13:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant