From 2d010c9f851ea4eb851179db012c8977ce6e4bd5 Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Wed, 19 Nov 2025 21:18:00 +0200 Subject: Add RTP/RTCP as a labeled heuristic fallback for unmatched UDP traffic Architecturally different from every other protocol added so far: RTP has no fixed well-known port at all - it's negotiated per call via SDP/SIP/WebRTC signaling this project doesn't parse - so L7Registry's port-keyed dispatch doesn't apply. Handled instead as a fallback tried only when a UDP packet's normal port-based lookup finds nothing, with every match labeled "?" (e.g. "RTCP? SR") to mark it as inferred from packet shape rather than certain - the same honesty Wireshark itself applies to heuristic dissection, which is off by default there for exactly this reason. The two heuristics aren't equally trusted, and the code says so: RTCP checks a narrow packet-type range (200-204) plus an exact self-declared length, both unlikely to occur by chance; RTP leans mostly on the 2-bit version field, since its other structural checks are trivially satisfied whenever those bits happen to be zero, the common case even for unrelated traffic. Shipped anyway - a labeled guess on real RTP/RTCP traffic is more useful than silence - but this is the first place in the project where a match doesn't mean certainty. Live-verified against genuine media traffic: ffmpeg streaming a real RTP video test pattern to loopback, correctly decoded with incrementing sequence numbers and a consistent SSRC across the stream, plus a real RTCP Sender Report ffmpeg sent alongside it. --- tests/test_rtcp.cpp | 69 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 69 insertions(+) create mode 100644 tests/test_rtcp.cpp (limited to 'tests/test_rtcp.cpp') diff --git a/tests/test_rtcp.cpp b/tests/test_rtcp.cpp new file mode 100644 index 0000000..9dde6cc --- /dev/null +++ b/tests/test_rtcp.cpp @@ -0,0 +1,69 @@ +#include + +#include + +#include "packeteer/net/rtcp.hpp" + +using namespace packeteer::net; + +namespace { + +std::vector rtcp_packet(std::uint8_t packet_type, std::uint16_t length_words, + std::size_t total_bytes) { + std::vector bytes(total_bytes, 0); + bytes[0] = 0x80; // version 2, no padding, RC/SC = 0 + bytes[1] = packet_type; + bytes[2] = static_cast(length_words >> 8); + bytes[3] = static_cast(length_words & 0xFF); + return bytes; +} + +} // namespace + +TEST_CASE("parse_rtcp_heuristic decodes a Sender Report") { + auto bytes = rtcp_packet(kRtcpSenderReport, 5, 24); // (5+1)*4 = 24 bytes + auto rtcp = parse_rtcp_heuristic(bytes); + REQUIRE(rtcp.has_value()); + CHECK(rtcp->version == 2); + CHECK(rtcp->packet_type == kRtcpSenderReport); + CHECK(rtcp->length_words == 5); +} + +TEST_CASE("parse_rtcp_heuristic accepts the first packet of a longer compound datagram") { + auto bytes = rtcp_packet(kRtcpReceiverReport, 1, 8); // declares 8 bytes + bytes.resize(40, 0); // but the datagram continues with more RTCP packets after it + auto rtcp = parse_rtcp_heuristic(bytes); + REQUIRE(rtcp.has_value()); + CHECK(rtcp->packet_type == kRtcpReceiverReport); +} + +TEST_CASE("parse_rtcp_heuristic rejects a packet type outside 200-204") { + auto bytes = rtcp_packet(199, 1, 8); + CHECK_FALSE(parse_rtcp_heuristic(bytes).has_value()); + + auto bytes2 = rtcp_packet(205, 1, 8); + CHECK_FALSE(parse_rtcp_heuristic(bytes2).has_value()); +} + +TEST_CASE("parse_rtcp_heuristic rejects version other than 2") { + std::vector bytes = {0x00, kRtcpBye, 0x00, 0x00}; + CHECK_FALSE(parse_rtcp_heuristic(bytes).has_value()); +} + +TEST_CASE("parse_rtcp_heuristic rejects a buffer shorter than the declared length") { + auto bytes = rtcp_packet(kRtcpBye, 10, 8); // declares (10+1)*4=44 bytes, buffer is only 8 + CHECK_FALSE(parse_rtcp_heuristic(bytes).has_value()); +} + +TEST_CASE("parse_rtcp_heuristic rejects a buffer shorter than the fixed header") { + std::vector bytes = {0x80, kRtcpBye}; + CHECK_FALSE(parse_rtcp_heuristic(bytes).has_value()); +} + +TEST_CASE("rtcp_packet_type_name names every known type") { + CHECK(rtcp_packet_type_name(kRtcpSenderReport) == "SR"); + CHECK(rtcp_packet_type_name(kRtcpReceiverReport) == "RR"); + CHECK(rtcp_packet_type_name(kRtcpSourceDescription) == "SDES"); + CHECK(rtcp_packet_type_name(kRtcpBye) == "BYE"); + CHECK(rtcp_packet_type_name(kRtcpApp) == "APP"); +} -- cgit v1.2.3