From 2d010c9f851ea4eb851179db012c8977ce6e4bd5 Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Wed, 19 Nov 2025 21:18:00 +0200 Subject: Add RTP/RTCP as a labeled heuristic fallback for unmatched UDP traffic Architecturally different from every other protocol added so far: RTP has no fixed well-known port at all - it's negotiated per call via SDP/SIP/WebRTC signaling this project doesn't parse - so L7Registry's port-keyed dispatch doesn't apply. Handled instead as a fallback tried only when a UDP packet's normal port-based lookup finds nothing, with every match labeled "?" (e.g. "RTCP? SR") to mark it as inferred from packet shape rather than certain - the same honesty Wireshark itself applies to heuristic dissection, which is off by default there for exactly this reason. The two heuristics aren't equally trusted, and the code says so: RTCP checks a narrow packet-type range (200-204) plus an exact self-declared length, both unlikely to occur by chance; RTP leans mostly on the 2-bit version field, since its other structural checks are trivially satisfied whenever those bits happen to be zero, the common case even for unrelated traffic. Shipped anyway - a labeled guess on real RTP/RTCP traffic is more useful than silence - but this is the first place in the project where a match doesn't mean certainty. Live-verified against genuine media traffic: ffmpeg streaming a real RTP video test pattern to loopback, correctly decoded with incrementing sequence numbers and a consistent SSRC across the stream, plus a real RTCP Sender Report ffmpeg sent alongside it. --- tests/test_summarize.cpp | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) (limited to 'tests/test_summarize.cpp') diff --git a/tests/test_summarize.cpp b/tests/test_summarize.cpp index 9eef454..f180f87 100644 --- a/tests/test_summarize.cpp +++ b/tests/test_summarize.cpp @@ -186,6 +186,36 @@ TEST_CASE("summarize_packet decodes an ARP request end to end") { "ARP who-has 10.0.0.2 tell 10.0.0.1 (aa:bb:cc:dd:ee:ff)"); } +TEST_CASE("summarize_packet falls back to the RTCP heuristic on an unmatched UDP port") { + std::vector rtcp = {0x80, 0xC9, 0x00, 0x01, 0, 0, 0, 0}; // RR, len=1 -> 8 bytes + + std::vector udp(8, 0); + udp[0] = 0x4E; udp[1] = 0x20; // src port 20000: not any registered L7 port + udp[2] = 0x4E; udp[3] = 0x21; // dst port 20001: likewise unregistered + std::uint16_t udp_len = static_cast(8 + rtcp.size()); + udp[4] = static_cast(udp_len >> 8); + udp[5] = static_cast(udp_len & 0xFF); + + std::vector ip(20, 0); + ip[0] = 0x45; + ip[8] = 64; + ip[9] = packeteer::net::kProtoUdp; + ip[12] = 10; ip[13] = 0; ip[14] = 0; ip[15] = 1; + ip[16] = 10; ip[17] = 0; ip[18] = 0; ip[19] = 2; + + std::vector eth = { + 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0xAA, 0xBB, 0xCC, 0xDD, 0xEE, 0xFF, 0x08, 0x00, + }; + + std::vector frame = eth; + frame.insert(frame.end(), ip.begin(), ip.end()); + frame.insert(frame.end(), udp.begin(), udp.end()); + frame.insert(frame.end(), rtcp.begin(), rtcp.end()); + + auto line = packeteer::summarize_packet(frame, DLT_EN10MB); + CHECK(line.find("RTCP? RR") != std::string::npos); +} + TEST_CASE("summarize_packet decodes IGMP directly on IP (not through a TCP/UDP port)") { std::vector igmp = {0x16, 0x00, 0x00, 0x00, 239, 255, 255, 250}; // v2 report -- cgit v1.2.3