srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/tests
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2025-11-19 21:18:00 +0200
committersrdusr <[email protected]>2025-11-19 21:18:00 +0200
commit2d010c9f851ea4eb851179db012c8977ce6e4bd5 (patch)
tree2cf84d9643df0baba62aac1b230c21f09e4872e0 /tests
parenta8f4866576fd70894ef0080c7797708db664880e (diff)
downloadpacketeer-2d010c9f851ea4eb851179db012c8977ce6e4bd5.tar.gz
packeteer-2d010c9f851ea4eb851179db012c8977ce6e4bd5.zip
Add RTP/RTCP as a labeled heuristic fallback for unmatched UDP traffic
Architecturally different from every other protocol added so far: RTP has no fixed well-known port at all - it's negotiated per call via SDP/SIP/WebRTC signaling this project doesn't parse - so L7Registry's port-keyed dispatch doesn't apply. Handled instead as a fallback tried only when a UDP packet's normal port-based lookup finds nothing, with every match labeled "?" (e.g. "RTCP? SR") to mark it as inferred from packet shape rather than certain - the same honesty Wireshark itself applies to heuristic dissection, which is off by default there for exactly this reason. The two heuristics aren't equally trusted, and the code says so: RTCP checks a narrow packet-type range (200-204) plus an exact self-declared length, both unlikely to occur by chance; RTP leans mostly on the 2-bit version field, since its other structural checks are trivially satisfied whenever those bits happen to be zero, the common case even for unrelated traffic. Shipped anyway - a labeled guess on real RTP/RTCP traffic is more useful than silence - but this is the first place in the project where a match doesn't mean certainty. Live-verified against genuine media traffic: ffmpeg streaming a real RTP video test pattern to loopback, correctly decoded with incrementing sequence numbers and a consistent SSRC across the stream, plus a real RTCP Sender Report ffmpeg sent alongside it.
Diffstat (limited to 'tests')
-rw-r--r--tests/test_rtcp.cpp69
-rw-r--r--tests/test_rtp.cpp92
-rw-r--r--tests/test_summarize.cpp30
3 files changed, 191 insertions, 0 deletions
diff --git a/tests/test_rtcp.cpp b/tests/test_rtcp.cpp
new file mode 100644
index 0000000..9dde6cc
--- /dev/null
+++ b/tests/test_rtcp.cpp
@@ -0,0 +1,69 @@
+#include <doctest/doctest.h>
+
+#include <vector>
+
+#include "packeteer/net/rtcp.hpp"
+
+using namespace packeteer::net;
+
+namespace {
+
+std::vector<unsigned char> rtcp_packet(std::uint8_t packet_type, std::uint16_t length_words,
+ std::size_t total_bytes) {
+ std::vector<unsigned char> bytes(total_bytes, 0);
+ bytes[0] = 0x80; // version 2, no padding, RC/SC = 0
+ bytes[1] = packet_type;
+ bytes[2] = static_cast<unsigned char>(length_words >> 8);
+ bytes[3] = static_cast<unsigned char>(length_words & 0xFF);
+ return bytes;
+}
+
+} // namespace
+
+TEST_CASE("parse_rtcp_heuristic decodes a Sender Report") {
+ auto bytes = rtcp_packet(kRtcpSenderReport, 5, 24); // (5+1)*4 = 24 bytes
+ auto rtcp = parse_rtcp_heuristic(bytes);
+ REQUIRE(rtcp.has_value());
+ CHECK(rtcp->version == 2);
+ CHECK(rtcp->packet_type == kRtcpSenderReport);
+ CHECK(rtcp->length_words == 5);
+}
+
+TEST_CASE("parse_rtcp_heuristic accepts the first packet of a longer compound datagram") {
+ auto bytes = rtcp_packet(kRtcpReceiverReport, 1, 8); // declares 8 bytes
+ bytes.resize(40, 0); // but the datagram continues with more RTCP packets after it
+ auto rtcp = parse_rtcp_heuristic(bytes);
+ REQUIRE(rtcp.has_value());
+ CHECK(rtcp->packet_type == kRtcpReceiverReport);
+}
+
+TEST_CASE("parse_rtcp_heuristic rejects a packet type outside 200-204") {
+ auto bytes = rtcp_packet(199, 1, 8);
+ CHECK_FALSE(parse_rtcp_heuristic(bytes).has_value());
+
+ auto bytes2 = rtcp_packet(205, 1, 8);
+ CHECK_FALSE(parse_rtcp_heuristic(bytes2).has_value());
+}
+
+TEST_CASE("parse_rtcp_heuristic rejects version other than 2") {
+ std::vector<unsigned char> bytes = {0x00, kRtcpBye, 0x00, 0x00};
+ CHECK_FALSE(parse_rtcp_heuristic(bytes).has_value());
+}
+
+TEST_CASE("parse_rtcp_heuristic rejects a buffer shorter than the declared length") {
+ auto bytes = rtcp_packet(kRtcpBye, 10, 8); // declares (10+1)*4=44 bytes, buffer is only 8
+ CHECK_FALSE(parse_rtcp_heuristic(bytes).has_value());
+}
+
+TEST_CASE("parse_rtcp_heuristic rejects a buffer shorter than the fixed header") {
+ std::vector<unsigned char> bytes = {0x80, kRtcpBye};
+ CHECK_FALSE(parse_rtcp_heuristic(bytes).has_value());
+}
+
+TEST_CASE("rtcp_packet_type_name names every known type") {
+ CHECK(rtcp_packet_type_name(kRtcpSenderReport) == "SR");
+ CHECK(rtcp_packet_type_name(kRtcpReceiverReport) == "RR");
+ CHECK(rtcp_packet_type_name(kRtcpSourceDescription) == "SDES");
+ CHECK(rtcp_packet_type_name(kRtcpBye) == "BYE");
+ CHECK(rtcp_packet_type_name(kRtcpApp) == "APP");
+}
diff --git a/tests/test_rtp.cpp b/tests/test_rtp.cpp
new file mode 100644
index 0000000..860f267
--- /dev/null
+++ b/tests/test_rtp.cpp
@@ -0,0 +1,92 @@
+#include <doctest/doctest.h>
+
+#include <vector>
+
+#include "packeteer/net/rtp.hpp"
+
+using namespace packeteer::net;
+
+namespace {
+
+std::vector<unsigned char> rtp_packet(std::uint8_t payload_type, std::uint16_t seq,
+ std::uint32_t timestamp, std::uint32_t ssrc,
+ std::size_t extra_payload = 0) {
+ std::vector<unsigned char> bytes(12 + extra_payload, 0);
+ bytes[0] = 0x80; // version 2, no padding, no extension, CC=0
+ bytes[1] = payload_type & 0x7F;
+ bytes[2] = static_cast<unsigned char>(seq >> 8);
+ bytes[3] = static_cast<unsigned char>(seq & 0xFF);
+ bytes[4] = static_cast<unsigned char>(timestamp >> 24);
+ bytes[5] = static_cast<unsigned char>(timestamp >> 16);
+ bytes[6] = static_cast<unsigned char>(timestamp >> 8);
+ bytes[7] = static_cast<unsigned char>(timestamp);
+ bytes[8] = static_cast<unsigned char>(ssrc >> 24);
+ bytes[9] = static_cast<unsigned char>(ssrc >> 16);
+ bytes[10] = static_cast<unsigned char>(ssrc >> 8);
+ bytes[11] = static_cast<unsigned char>(ssrc);
+ return bytes;
+}
+
+} // namespace
+
+TEST_CASE("parse_rtp_heuristic decodes a plain fixed-header packet") {
+ auto bytes = rtp_packet(0, 1000, 160000, 0xDEADBEEF, 160);
+ auto rtp = parse_rtp_heuristic(bytes);
+ REQUIRE(rtp.has_value());
+ CHECK(rtp->version == 2);
+ CHECK(rtp->payload_type == 0);
+ CHECK(rtp->sequence_number == 1000);
+ CHECK(rtp->timestamp == 160000);
+ CHECK(rtp->ssrc == 0xDEADBEEF);
+ CHECK_FALSE(rtp->padding);
+ CHECK_FALSE(rtp->extension);
+ CHECK(rtp->csrc_count == 0);
+}
+
+TEST_CASE("parse_rtp_heuristic rejects version other than 2") {
+ std::vector<unsigned char> bytes(12, 0);
+ bytes[0] = 0x00;
+ CHECK_FALSE(parse_rtp_heuristic(bytes).has_value());
+}
+
+TEST_CASE("parse_rtp_heuristic rejects payload types reserved to avoid an RTCP clash") {
+ auto bytes = rtp_packet(74, 1, 1, 1);
+ CHECK_FALSE(parse_rtp_heuristic(bytes).has_value());
+}
+
+TEST_CASE("parse_rtp_heuristic accounts for CSRC count when checking buffer length") {
+ std::vector<unsigned char> bytes(12, 0);
+ bytes[0] = 0x82; // version 2, CC=2: needs 12 + 2*4 = 20 bytes minimum
+ CHECK_FALSE(parse_rtp_heuristic(bytes).has_value()); // buffer too short for claimed CSRCs
+
+ bytes.resize(20, 0);
+ bytes[0] = 0x82;
+ CHECK(parse_rtp_heuristic(bytes).has_value());
+}
+
+TEST_CASE("parse_rtp_heuristic validates the extension header fits when the X bit is set") {
+ std::vector<unsigned char> bytes(12, 0);
+ bytes[0] = 0x90; // version 2, extension bit set, CC=0
+ CHECK_FALSE(parse_rtp_heuristic(bytes).has_value()); // no room for even the 4-byte ext header
+
+ bytes.resize(16, 0);
+ bytes[0] = 0x90;
+ bytes[14] = 0x00;
+ bytes[15] = 0x00; // extension length = 0 words
+ CHECK(parse_rtp_heuristic(bytes).has_value());
+}
+
+TEST_CASE("parse_rtp_heuristic validates the padding count when the P bit is set") {
+ std::vector<unsigned char> bytes(16, 0);
+ bytes[0] = 0xA0; // version 2, padding bit set, CC=0
+ bytes[15] = 0; // a padding count of 0 is invalid (RFC 3550 5.1)
+ CHECK_FALSE(parse_rtp_heuristic(bytes).has_value());
+
+ bytes[15] = 4; // a plausible padding count
+ CHECK(parse_rtp_heuristic(bytes).has_value());
+}
+
+TEST_CASE("parse_rtp_heuristic rejects a buffer shorter than the fixed 12-byte header") {
+ std::vector<unsigned char> bytes(8, 0x80);
+ CHECK_FALSE(parse_rtp_heuristic(bytes).has_value());
+}
diff --git a/tests/test_summarize.cpp b/tests/test_summarize.cpp
index 9eef454..f180f87 100644
--- a/tests/test_summarize.cpp
+++ b/tests/test_summarize.cpp
@@ -186,6 +186,36 @@ TEST_CASE("summarize_packet decodes an ARP request end to end") {
"ARP who-has 10.0.0.2 tell 10.0.0.1 (aa:bb:cc:dd:ee:ff)");
}
+TEST_CASE("summarize_packet falls back to the RTCP heuristic on an unmatched UDP port") {
+ std::vector<unsigned char> rtcp = {0x80, 0xC9, 0x00, 0x01, 0, 0, 0, 0}; // RR, len=1 -> 8 bytes
+
+ std::vector<unsigned char> udp(8, 0);
+ udp[0] = 0x4E; udp[1] = 0x20; // src port 20000: not any registered L7 port
+ udp[2] = 0x4E; udp[3] = 0x21; // dst port 20001: likewise unregistered
+ std::uint16_t udp_len = static_cast<std::uint16_t>(8 + rtcp.size());
+ udp[4] = static_cast<unsigned char>(udp_len >> 8);
+ udp[5] = static_cast<unsigned char>(udp_len & 0xFF);
+
+ std::vector<unsigned char> ip(20, 0);
+ ip[0] = 0x45;
+ ip[8] = 64;
+ ip[9] = packeteer::net::kProtoUdp;
+ ip[12] = 10; ip[13] = 0; ip[14] = 0; ip[15] = 1;
+ ip[16] = 10; ip[17] = 0; ip[18] = 0; ip[19] = 2;
+
+ std::vector<unsigned char> eth = {
+ 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0xAA, 0xBB, 0xCC, 0xDD, 0xEE, 0xFF, 0x08, 0x00,
+ };
+
+ std::vector<unsigned char> frame = eth;
+ frame.insert(frame.end(), ip.begin(), ip.end());
+ frame.insert(frame.end(), udp.begin(), udp.end());
+ frame.insert(frame.end(), rtcp.begin(), rtcp.end());
+
+ auto line = packeteer::summarize_packet(frame, DLT_EN10MB);
+ CHECK(line.find("RTCP? RR") != std::string::npos);
+}
+
TEST_CASE("summarize_packet decodes IGMP directly on IP (not through a TCP/UDP port)") {
std::vector<unsigned char> igmp = {0x16, 0x00, 0x00, 0x00, 239, 255, 255, 250}; // v2 report