Skip to content

Replace the OSConfig 1DS SDK uploader with a focused C implementation using direct IPC and system OpenSSL - #1315

Draft
Marius Niculescu (MariusNi) wants to merge 63 commits into
mainfrom
MariusNi/OsConfig_1dsDistillation_Sep30_2026
Draft

Marius Niculescu (MariusNi) wants to merge 63 commits into
mainfrom
MariusNi/OsConfig_1dsDistillation_Sep30_2026

Conversation

@MariusNi

@MariusNi Marius Niculescu (MariusNi) commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Description

Replace the general-purpose 1DS SDK-based telemetry uploader with a focused C implementation of the functionality OSConfig uses. This reduces the production dependency footprint while preserving existing event schemas, package integration and the OSConfigTelemetry executable contract.

Summary

  • Implement event validation, Common Schema encoding and HTTPS delivery in C, removing telemetry-only build dependencies on the 1DS C++ SDK, curl, bundled OpenSSL, SQLite, zlib and nlohmann JSON.
  • Keep DNS, TLS and network operations in the telemetry worker, with bounded communication, deadlines and explicit failure handling.
  • Use system OpenSSL in preference order 3, 1.1, then 1.0.2.
  • Preserve certificate-chain, validity and hostname/IP verification, system trust selection and provider configuration. Failures after provider selection never trigger a retry through an older provider.
  • Diagnose provider availability and connection failures without logging payloads, certificate contents or key material.

Removal of file-based event handoff between the client library and the SDK executable

  • The change in this PR teplaces the local event-handoff file with direct, in-memory IPC between the telemetry client linked into OSConfig binaries/SOs and the separate  OSConfigTelemetry  worker. Events are sent over a private, unnamed Unix-domain socket pair, not temporary files or a filesystem socket.
  • The client sends framed event requests with sequence numbers and deadlines. The worker encodes and uploads them over HTTPS using system OpenSSL, then returns delivery status and collector suppression state over the same connection.
  • This preserves process isolation and worker reuse while eliminating event-file creation, disk I/O, and cleanup from the handoff path. There is no disk-backed event queue and no replay of failed events. The worker remains a separately installed executable.

TLS compatibility

  • OpenSSL 1.0.2 support extends compatibility to older distributions and custom derivatives without maintaining a private cryptographic implementation. Cryptographic operations and certificate verification remain in the installed system OpenSSL library.
  • Telemetry requires a usable supported OpenSSL shared-library runtime and a provisioned CA trust store. OpenSSL 1.0.1-only systems, including stock Ubuntu 14.04, and images without a supported runtime require an additional installation to send telemetry. Missing or incompatible runtimes fail explicitly; there is no bundled or plaintext fallback.
  • Runtime compatibility does not establish security-update status or FIPS validation; those depend on the installed provider and its configuration.

Checklist

  • I have read the contribution guidelines.
  • I added unit-tests to validate my changes. All unit tests are passing.
  • I have merged the latest main branch prior to this PR submission.
  • I ran pre-commit on my changes prior to this PR submission.
  • I submitted this PR against the main branch.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Test Results

  1 files   -    20   22 suites   - 146   1m 24s ⏱️ - 26m 33s
368 tests +  175  368 ✅ +  176  0 💤 ±0  0 ❌  - 1 
368 runs   - 3 685  368 ✅  - 3 683  0 💤 ±0  0 ❌  - 2 

Results for commit 01c898c. ± Comparison against base commit 131a590.

This pull request removes 31 and adds 206 tests. Note that renamed tests count towards both.
TelemetryBinTest ‑ CombinedOptionsWork
TelemetryBinTest ‑ FileAndPositionalArgumentCannotBothBeUsed
TelemetryBinTest ‑ FileOptionAcceptsFilePath
TelemetryBinTest ‑ InvalidOptionReturnsFalse
TelemetryBinTest ‑ InvalidTeardownValueFails
TelemetryBinTest ‑ LongFormFileOptionWorks
TelemetryBinTest ‑ LongFormTeardownWithValue
TelemetryBinTest ‑ LongFormVerboseWorks
TelemetryBinTest ‑ MixedLongAndShortOptionsWork
TelemetryBinTest ‑ NegativeTeardownValueFails
…
TelemetryEncoderTest ‑ AcceptsNameLimitsAndRejectsOversizedNames
TelemetryEncoderTest ‑ BorrowsPropertiesOnlyForTheDurationOfTheCall
TelemetryEncoderTest ‑ EncodesBooleanKindEvenWhenFalse
TelemetryEncoderTest ‑ EncodesDoubleAsLittleEndianAndOmitsZeroSlot
TelemetryEncoderTest ‑ EncodesFlagsAndDeviceAndSdkExtensions
TelemetryEncoderTest ‑ EncodesOneCommonSchemaRecordWithoutAnOuterEnvelope
TelemetryEncoderTest ‑ EncodesSignedValuesWithoutLosingIntegerPrecision
TelemetryEncoderTest ‑ EncodesStringLengthVarintBoundary
TelemetryEncoderTest ‑ EncodesStringPropertyAndItsDefaultKind
TelemetryEncoderTest ‑ EnforcesPropertyArrayAndCountLimits
…

♻️ This comment has been updated with latest results.

@MariusNi Marius Niculescu (MariusNi) changed the title Distill OSConfig telemetry into a focused C implementation with an in-tree TLS fallback Replace the OSConfig 1DS SDK uploader with a focused C implementation using direct IPC and system OpenSSL Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant