A Rust sender and reflector for the Simple Two-Way Active Measurement Protocol (STAMP). Measures round-trip time, packet loss, one-way delay, and residual bit errors in delivered test packets.
Run a reflector on a trusted network:
stamp-suite --is-reflectorSend 100 probes, 100 ms apart:
stamp-suite --remote-addr 192.0.2.20 --count 100 --send-delay 100 -RThe reflector listens on UDP/862 by default. Senders use randomized dynamic source ports. Both endpoints send with TTL/Hop Limit 255.
Open mode accepts unsigned traffic. For untrusted networks, restrict access and configure authenticated mode.
- RTT and probe loss, with cumulative statistics and bounded-memory quantiles.
- Signed forward/reverse one-way delay. This requires synchronized clocks on compatible timescales; NTP and truncated PTP wire encodings can differ between endpoints. See clock settings.
- RFC 8762 base packets and HMAC authentication; RFC 8972 optional TLVs.
- RFC 9503 return-path controls, including optional Linux SRv6 forwarding.
- RFC 9534 numeric Micro-session IDs. Physical LAG member selection is unsupported.
- Draft extensions for asymmetric replies, header reflection, CoS/ECN response, and residual BER. Experimental codepoints require peer agreement.
- Text, JSON lines, and CSV output; optional Prometheus, AgentX, and control API.
See the conformance matrices for supported profiles and gaps, and measurement semantics for burst-copy, directional-loss, and clock-quality limits.
DEB and RPM packages for x86_64 and aarch64 are published with
GitHub releases.
They install /usr/bin/stamp-suite, the man page, a systemd service, and the
stamp service account.
sudo apt install ./stamp-suite_*_amd64.deb # Debian/Ubuntu
sudo dnf install ./stamp-suite-*.x86_64.rpm # Fedora/RHEL
sudo systemctl enable --now stamp-suiteThe packaged service starts in open mode. Configure authentication before exposing it to an untrusted network.
cargo build --release
# Or install into Cargo's binary directory:
cargo install --path .Rust 1.85 or newer is required. Build optional features with, for example,
cargo build --release --features metrics,control,hwtstamp.
nix build
nix run . -- --is-reflector
nix developThe Gentoo overlay includes service-account packages, systemd/OpenRC integration, and Cargo feature mappings.
| Platform | Default receiver | Requirements |
|---|---|---|
| Linux | nix UDP socket | No raw-socket privilege; low ports may need bind permission |
| macOS | nix UDP socket | No raw-socket privilege |
| Windows | pnet capture | Npcap; capture tests require a driver-backed environment |
Both backends capture received TTL/Hop Limit. See backend limits.
| Cargo feature | Purpose |
|---|---|
ttl-nix |
Select the nix receiver |
ttl-pnet |
Select raw packet capture; Linux requires CAP_NET_RAW |
metrics |
Prometheus HTTP endpoint |
control |
Reflector session/key/limit API with optional HTTPS |
snmp |
Read-only AgentX sub-agent, Unix only |
hwtstamp |
Kernel timestamps and optional Linux NIC hardware timestamps |
Use --config PATH for TOML settings. Explicit CLI values override file values.
STAMP_HMAC_KEY supplies the CLI key field; it conflicts with a configured key
file or directory. Plaintext hmac_key is not a TOML field.
is_reflector = true
local_addr = "192.0.2.20"
auth_mode = "A"
hmac_key_file = "/etc/stamp/hmac.key"
verify_tlv_hmac = true
stateful_reflector = true
session_timeout = 300Protect key files with owner-only permissions. See key setup and the configuration reference.
Sessions are separated by both UDP endpoints, SSID, and optional sender
Micro-session ID. The default permissive policy learns sessions from traffic.
For RFC 8972 provisioned admission:
stamp-suite -i --local-addr 192.0.2.20 --session-admission provisioned \
--reflector-session '42,192.0.2.10:4862,192.0.2.20:862'See session provisioning and IPv6 interface zones.
Request CoS and reflector metadata:
stamp-suite --remote-addr 192.0.2.20 --cos --dscp 46 \
--direct-measurement --location --timestamp-infoRecord measurements separately from diagnostics:
stamp-suite --remote-addr 192.0.2.20 --output-format json \
> measurements.jsonl 2> diagnostics.logMeasure residual BER with one-second windows:
stamp-suite --remote-addr 192.0.2.20 --ber --ber-pattern ff00 \
--ber-padding-size 128 --send-delay 100 --ber-interval 10BER measures delivered padding, not raw link errors. Use --ber-omit-burst if
Type 242 means Heartbeat to the peer. See BER limits.
With the control feature, --control enables a reflector API at
127.0.0.1:9091. It manages keys, sessions, limits, drain, and shutdown. Set a
bearer token on shared hosts; use HTTPS or a secure tunnel for remote access.
See the API reference.
- Usage: configuration, options, and migration notes.
- Architecture: packet processing, backends, and TLVs.
- Measurements and statistics: definitions and retention.
- Security and vulnerability reporting.
- Benchmarks: reproducible throughput and CPU measurements.
- Release verification: platform and integration gates.
- Conformance: protocol sources, evidence, and exclusions.
The 1.x compatibility contract covers CLI behavior, TOML schema, and default wire behavior. The internal Rust library API is unsupported and may change in any release. Experimental codepoint renumbering and MSRV increases may occur in minor releases and are recorded in CHANGELOG.md.
Open an issue before a major change. Before submitting, run:
cargo fmt --all
cargo clippy --all-targets --all-features -- -D warnings
cargo test --all-featuresIndependent wire fixtures run separately from Cargo and are required by conformance CI.
Maintained by Piotr Olszewski, with contributors. Licensed under MIT.