Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 29 additions & 5 deletions SilKit/source/tracing/Pcap.hpp
Original file line number Diff line number Diff line change
Expand Up @@ -5,16 +5,27 @@
#pragma once
#include <cstdint>

#include "silkit/participant/exception.hpp"

namespace SilKit {
namespace Tracing {
namespace Pcap {

const uint32_t NativeMagic = 0xa1b23c4d;
// The magic number defines the unit of PacketHeader::ts_fraction. SIL Kit writes nanosecond files.
const uint32_t NativeMagic = 0xa1b23c4d; // nanosecond resolution
const uint32_t MicrosecondMagic = 0xa1b2c3d4; // microsecond resolution, e.g., written by tcpdump / Wireshark
const size_t GlobalHeaderSize = 24;
const size_t PacketHeaderSize = 16;
const uint16_t MajorVersion = 2;
const uint16_t MinorVersion = 4;

// The unit of PacketHeader::ts_fraction
enum class TimestampMode
{
Nanoseconds,
Microseconds,
};

struct GlobalHeader
{
uint32_t magic_number = NativeMagic; /* magic number */
Expand All @@ -24,15 +35,28 @@ struct GlobalHeader
uint32_t sigfigs = 0; /* accuracy of timestamps */
uint32_t snaplen = 65535; /* max length of captured packets, in octets */
uint32_t network = 1; /* data link type */

auto GetTimestampMode() const -> TimestampMode
{
switch (magic_number)
{
case NativeMagic:
return TimestampMode::Nanoseconds;
case MicrosecondMagic:
return TimestampMode::Microseconds;
default:
throw SilKitError("PCAP global header: invalid magic number");
}
}
};
static_assert(sizeof(GlobalHeader) == GlobalHeaderSize, "GlobalHeader size must be equal to 24 bytes");

struct PacketHeader
{
uint32_t ts_sec; /* timestamp seconds */
uint32_t ts_usec; /* timestamp microseconds */
uint32_t incl_len; /* number of octets of packet saved in file */
uint32_t orig_len; /* actual length of packet */
uint32_t ts_sec; /* timestamp seconds */
uint32_t ts_fraction; /* timestamp nanoseconds or microseconds, depending on the magic number */
uint32_t incl_len; /* number of octets of packet saved in file */
uint32_t orig_len; /* actual length of packet */

@VDanielEdwards VDanielEdwards Oct 2, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could add

  • a enum struct TimestampMode with two enumerators Nanoseconds and Microseconds
  • and a method GetTimestampMode() const -> TimestampMode that compares the magic number

That makes it simpler for code using the PacketHeader structure to get that info without having to know about the magic numbers.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The magicNumber lives in GlobalHeader, I added GetTimestampMode there.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i think we should keep this code as simple as possible, and just support microseconds, and clamp the timestamps appropriately

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd say the error handling to check for the MicrosecondMagic only in the header and return an error is just as complicated as supporting both cases.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a downside to using nanoseconds? Since SIL Kit timestamps are nanoseconds that seems like the more natural choice for us.

Also since we can also read PCAP files for replay, shouldn't we support both, since we could get a file that was recorded, e.g., using tcpdump.

};
static_assert(sizeof(PacketHeader) == PacketHeaderSize, "PacketHeader size must be equal to 16 bytes");

Expand Down
12 changes: 9 additions & 3 deletions SilKit/source/tracing/PcapReader.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -137,9 +137,14 @@ void PcapReader::ReadGlobalHeader()
throw SilKitError("PCAP file cannot be opened: global header short read");
}
auto* hdr = reinterpret_cast<Pcap::GlobalHeader*>(buf.data());
if (hdr->magic_number != Pcap::NativeMagic)
switch (hdr->GetTimestampMode())
{
throw SilKitError("PCAP file cannot be opened: invalid PCAP valid magic number");
case Pcap::TimestampMode::Nanoseconds:
_nsPerTimestampFraction = 1;
break;
case Pcap::TimestampMode::Microseconds:
_nsPerTimestampFraction = 1000;
break;
}
if ((hdr->version_major != Pcap::MajorVersion) && (hdr->version_minor != Pcap::MinorVersion))
{
Expand Down Expand Up @@ -181,7 +186,8 @@ bool PcapReader::Seek(size_t messageNumber)
}
auto msg = std::make_shared<PcapMessage>();
auto* hdr = reinterpret_cast<Pcap::PacketHeader*>(buf.data());
std::chrono::nanoseconds timeStamp{((uint64_t)hdr->ts_sec * 1000000000u) + ((uint64_t)hdr->ts_usec * 1000u)};
std::chrono::nanoseconds timeStamp{((uint64_t)hdr->ts_sec * 1000000000u)
+ ((uint64_t)hdr->ts_fraction * _nsPerTimestampFraction)};

std::vector<uint8_t> msgBuf{};
msgBuf.resize(hdr->incl_len);
Expand Down
1 change: 1 addition & 0 deletions SilKit/source/tracing/PcapReader.hpp
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@ class PcapReader final : public SilKit::IReplayChannelReader
SilKit::Services::Logging::ILogger* _log{nullptr};
std::chrono::nanoseconds _startTime{0};
std::chrono::nanoseconds _endTime{0};
uint64_t _nsPerTimestampFraction{1}; //!< 1 for nanosecond files, 1000 for microsecond files
};

} // namespace Tracing
Expand Down
9 changes: 5 additions & 4 deletions SilKit/source/tracing/PcapSink.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -109,14 +109,15 @@ void PcapSink::Trace(SilKit::Services::TransmitDirection /*unused*/,

std::unique_lock<decltype(_lock)> lock;

const auto tosec = 1000'000ull;
const auto usec = std::chrono::duration_cast<std::chrono::microseconds>(timestamp);
// The global header announces nanosecond resolution (Pcap::NativeMagic).
const auto nsPerSecond = 1'000'000'000ull;
const auto nsec = static_cast<uint64_t>(timestamp.count());

Pcap::PacketHeader pcapPacketHeader;
pcapPacketHeader.orig_len = static_cast<uint32_t>(message.raw.size());
pcapPacketHeader.incl_len = pcapPacketHeader.orig_len;
pcapPacketHeader.ts_sec = static_cast<uint32_t>(usec.count() / tosec);
pcapPacketHeader.ts_usec = static_cast<uint32_t>(usec.count() % tosec);
pcapPacketHeader.ts_sec = static_cast<uint32_t>(nsec / nsPerSecond);
pcapPacketHeader.ts_fraction = static_cast<uint32_t>(nsec % nsPerSecond);

bool ok = true;
if (_file.is_open())
Expand Down
46 changes: 44 additions & 2 deletions SilKit/source/tracing/Test_Pcap.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -21,13 +21,16 @@ using namespace SilKit::Tracing;
using namespace SilKit::Services::Ethernet;
using namespace SilKit::Core::Tests;

std::vector<uint8_t> MakePcapTestData(WireEthernetFrame& wireFrame, size_t numMessages)
// Packet i has the timestamp i seconds + i fraction units (nanoseconds or microseconds, depending on the magic).
std::vector<uint8_t> MakePcapTestData(WireEthernetFrame& wireFrame, size_t numMessages,
uint32_t magic = Pcap::NativeMagic)
{
std::vector<uint8_t> data;
std::string payloadData{"Testing Trace message Pcap, padding to a minimal size of > 64 bytes"
"... and so on 0123456789ABCDEF"};

Pcap::GlobalHeader ghdr{};
ghdr.magic_number = magic;
Pcap::PacketHeader phdr{};

EthernetMac destinationMac{1, 2, 3, 4, 5, 6};
Expand All @@ -45,7 +48,7 @@ std::vector<uint8_t> MakePcapTestData(WireEthernetFrame& wireFrame, size_t numMe
for (auto i = 0u; i < numMessages; i++)
{
phdr.ts_sec = i;
phdr.ts_usec = i;
phdr.ts_fraction = i;
phdr.incl_len = static_cast<uint32_t>(frame.size());
phdr.orig_len = phdr.incl_len;
memcpy(raw, &phdr, Pcap::PacketHeaderSize);
Expand Down Expand Up @@ -90,4 +93,43 @@ TEST(Test_Pcap, read_from_pcap)
EXPECT_EQ((int)numMessages, 10);
}

auto ReadTimestamps(uint32_t magic) -> std::vector<std::chrono::nanoseconds>
{
MockLogger log;
std::stringstream ss;
WireEthernetFrame testInput;
auto raw = MakePcapTestData(testInput, 3, magic);
ss.write(reinterpret_cast<char*>(raw.data()), raw.size());

PcapReader reader{&ss, log.AsILogger()};
std::vector<std::chrono::nanoseconds> timestamps;
do
{
auto msg = reader.Read();
if (!msg)
{
break;
}
timestamps.push_back(msg->Timestamp());
} while (reader.Seek(1));
return timestamps;
}

TEST(Test_Pcap, read_nanosecond_timestamps)
{
using namespace std::chrono_literals;
EXPECT_THAT(ReadTimestamps(Pcap::NativeMagic), testing::ElementsAre(0ns, 1s + 1ns, 2s + 2ns));
}

TEST(Test_Pcap, read_microsecond_timestamps)
{
using namespace std::chrono_literals;
EXPECT_THAT(ReadTimestamps(Pcap::MicrosecondMagic), testing::ElementsAre(0ns, 1s + 1us, 2s + 2us));
}

TEST(Test_Pcap, invalid_magic_number_throws)
{
EXPECT_THROW(ReadTimestamps(0x12345678), SilKit::SilKitError);
}

} // namespace
Loading