-
Notifications
You must be signed in to change notification settings - Fork 0
Library API
sipnab is primarily a CLI/TUI tool, but its analysis engine is a
published Rust crate. The curated public API is re-exported at the crate
root; anything under a #[doc(hidden)] module (cli, tui, privilege,
…) is binary-internal and carries no semver guarantee.
[dependencies]
sipnab = { version = "0.5", default-features = false, features = ["native"] }| Item | What it is |
|---|---|
PcapReader |
Pure-Rust pcap/pcapng reader (iterator of packets) |
decompress_capture |
Transparent, bounded gunzip for gzip-compressed captures |
sip::parser::parse_sip / parse_sip_bytes
|
Parse raw bytes → SipMessage
|
capture::parse::parse_packet |
Decode a captured Packet → ParsedPacket
|
rtp::parser::parse_rtp_header |
Parse an RTP header |
sip::sdp::parse_sdp |
Parse an SDP body |
DialogStore / StreamStore
|
Capped, indexed dialog / RTP-stream stores (both Debug) |
SipMessage, SipDialog, RtpStream
|
Core value types |
FilterExpr |
Compiled filter-DSL expression |
estimate_mos |
E-model MOS from jitter/loss/codec |
use sipnab::PcapReader;
let data = std::fs::read("capture.pcap")?;
for pkt in PcapReader::new(&data)? {
// pkt.data is the captured bytes; feed to parse_packet / parse_sip …
let _ = pkt.data.len();
}The parsing and capture entry points return typed, matchable error
enums — not anyhow::Result. All three are #[non_exhaustive]
thiserror enums (std::error::Error), so you can propagate them into
anyhow/Box<dyn Error> unchanged, or match on their variants.
| Function | Returns |
|---|---|
parse_sip, parse_sip_bytes, parse_rtp_header, parse_sdp
|
Result<_, ParseError> |
parse_packet, PcapReader::new
|
Result<_, CaptureError> |
config::Config::load, address/rule/CIDR parsing |
Result<_, Error> |
-
ParseError— protocol parsers. Variants includeEmpty { what },TooShort { what, need, got },InvalidUtf8 { what },MissingCrlf,NotSip { line },InvalidStatusCode { code },BadRtpVersion { version },SdpMissingVersion,BadSdpVersion { version }. -
CaptureError— capture-file / packet decode. Variants includeTooShort { what, need, got },UnsupportedLinkType(i32),EncapTooDeep { kind, limit },NotIp { what },NoTransport,Icmp,NetMonFormat,UnknownFormat { magic }. -
Error— config/CLI/validation surface.ConfigRead/ConfigParsechain the underlyingstd::io::Error/toml::de::Errorvia#[source].
Match on variants rather than message text:
use sipnab::ParseError;
use sipnab::rtp::parser::parse_rtp_header;
match parse_rtp_header(&[0x80, 0x00]) {
Err(ParseError::TooShort { need, got, .. }) => {
eprintln!("need {need} bytes, got {got}");
}
Ok(header) => { /* use header */ }
Err(e) => eprintln!("parse failed: {e}"),
}Because every one of these enums is #[non_exhaustive], a downstream
match must include a wildcard arm — sipnab can add a variant in a
minor release without it being a breaking change. Sixteen other public
enums (TransportProto, RtcpPacket, FraudType, CipherSuite, …) are
#[non_exhaustive] for the same reason.
The crate is heavily feature-gated (see Cargo.toml). For pure parsing
you only need native; tls/hep/api/mcp pull in their respective
subsystems. See the feature table in
install.md.
Website · Repository · Issues · Generated from docs/ — edit there, not here.
Getting started
Using the TUI
CLI & automation
Configuration
Integrations (API & MCP)
Development & internals