ptp¶
PTP (IEEE 1588-2008/2019) flows from packet captures.
Messages are read over UDP (event port 319, general port 320; IPv4 and IPv6) and over Ethernet (EtherType 0x88F7, with VLAN tags). For each master and slave port the capture yields a time series, measured from the capture host's clock as the NTP analysis is:
t1is the master's Sync origin (the Sync itself for one-step clocks, the Follow_Up for two-step clocks),c2the capture time of the Sync;c3is the capture time of the slave's Delay_Req,t4the master's receive timestamp from the Delay_Resp;-
correction fields are applied as IEEE 1588 prescribes (Sync + Follow_Up on the master-to-slave side, Delay_Resp on the slave-to-master side)::
ms = c2 - t1 - cf_sync (one-way, includes the offset) sm = t4 - c3 - cf_delay_resp mean_path_delay = (ms + sm) / 2 (from the Sync preceding each Delay_Req) offset (reference - local) = mean_path_delay - ms (for every Sync)
With the peer-delay mechanism (Pdelay_Req/Resp/Resp_Follow_Up, one- or
two-step) the mean link delay replaces the mean path delay. With no delay
messages the series is the one-way -ms (offset plus delay), which
still serves packet-delay-variation analysis (G.8260 FPP).
When the capture is taken at the slave, "local" is the slave's clock as the
capture timestamps it; with hardware timestamps (tcpdump -j
adapter_unsynced, nanosecond pcapng) this is the PHC. PTP timestamps are
on the PTP timescale (TAI): the UTC offset comes from Announce messages
(currentUtcOffset) or, without Announce, is inferred when the one-way
times are 30-45 s. Messages carrying an AUTHENTICATION TLV (IEEE 1588-2019
annex P, used by NTS4PTP) are flagged; they are not verified.
decode(payload, ts, transport, src)
¶
Decode a PTPv2 common header (34 octets) plus the raw message.
messages(data)
¶
All PTP messages in a capture, in capture order.
parse_ptp(data, name='capture')
¶
One :class:TimeSeries per PTP master/slave flow in a capture (possibly none).
summary(data)
¶
Message counts per type, domains, versions and transports of a capture.