-
Notifications
You must be signed in to change notification settings - Fork 2
Binary Format
awishformore edited this page May 5, 2015
·
2 revisions
The binary format for a record is a fixed length direct binary dump of all the record information. There are thus no separators, neither spaces nor new lines, and variable number of sub-records are indicated by an integer at a fixed position.
Timestamp are given in UNIX format or in UNIX nano-second precision format, and are followed by TCP addresses for both remote and local peer. IP addresses all have IPv6 length; the IPv6 representation is used for IPv4 addresses to keep length identical.
Sub-records follow main records directly and in variable number. As length is always the same for them as well, you can use offsets to quickly scan through them.
| Bytes | Type | Description | Comments |
|---|---|---|---|
| 8 | int64 | Timestamp | Timestamp in nanoseconds since UNIX epoch. |
| 16 | [16]byte | Remote IP | IP address of the remote peer. |
| 2 | uint16 | Remote Port | Port number of the remote peer. |
| 16 | [16]byte | Local IP | IP address of the local peer. |
| 2 | uint16 | Remote Port | Port number of the local peer. |
| 1 | uint8 | Command Code | Custom byte encoding of the command string for this message type. |
Total size: 45 bytes
| Bytes | Type | Description | Comments |
|---|---|---|---|
| 45 | (misc) | Header | Header with the 0 command code. See header description for details. |
| 2 | uint16 | Number of Addresses | The number of addresses sent with this address message. |
| 16 | [16]byte | IP Address 1 | The first IP address of the message. |
| 2 | uint16 | IP Port 1 | The first IP Port of the message. |
| ... | ... | ... | ... |
| 16 | [16]byte | IP Address N | The last IP address of the message. |
| 2 | uint16 | IP Port N | The last IP port of the message. |
Total size: 47 + N*18 bytes