Skip to content

ptp

PTP (IEEE 1588-2008/2019) flows from packet captures.

Messages are read over UDP (event port 319, general port 320; IPv4 and IPv6) and over Ethernet (EtherType 0x88F7, with VLAN tags). For each master and slave port the capture yields a time series, measured from the capture host's clock as the NTP analysis is:

  • t1 is the master's Sync origin (the Sync itself for one-step clocks, the Follow_Up for two-step clocks), c2 the capture time of the Sync;
  • c3 is the capture time of the slave's Delay_Req, t4 the master's receive timestamp from the Delay_Resp;
  • correction fields are applied as IEEE 1588 prescribes (Sync + Follow_Up on the master-to-slave side, Delay_Resp on the slave-to-master side)::

    ms = c2 - t1 - cf_sync (one-way, includes the offset) sm = t4 - c3 - cf_delay_resp mean_path_delay = (ms + sm) / 2 (from the Sync preceding each Delay_Req) offset (reference - local) = mean_path_delay - ms (for every Sync)

With the peer-delay mechanism (Pdelay_Req/Resp/Resp_Follow_Up, one- or two-step) the mean link delay replaces the mean path delay. With no delay messages the series is the one-way -ms (offset plus delay), which still serves packet-delay-variation analysis (G.8260 FPP).

When the capture is taken at the slave, "local" is the slave's clock as the capture timestamps it; with hardware timestamps (tcpdump -j adapter_unsynced, nanosecond pcapng) this is the PHC. PTP timestamps are on the PTP timescale (TAI): the UTC offset comes from Announce messages (currentUtcOffset) or, without Announce, is inferred when the one-way times are 30-45 s. Messages carrying an AUTHENTICATION TLV (IEEE 1588-2019 annex P, used by NTS4PTP) are flagged; they are not verified.

Message dataclass

timestamp(off=34)

10-byte PTP timestamp at off as ns on the PTP timescale.

decode(payload, ts, transport, src)

Decode a PTPv2 common header (34 octets) plus the raw message.

messages(data)

All PTP messages in a capture, in capture order.

parse_ptp(data, name='capture')

One :class:TimeSeries per PTP master/slave flow in a capture (possibly none).

summary(data)

Message counts per type, domains, versions and transports of a capture.