[nexus] add test 5.3.2 Realm-Local Addressing (#12405)

Adds a new Nexus test case for 'Realm-Local Addressing' (5.3.2) as
specified in the test specification.

Summary of changes:
- Implemented Nexus test 5.3.2:
    - Added test_5_3_2.cpp: Sets up a topology with a Leader,
      Router 1, Router 2 (DUT), and SED 1. Verifies that the DUT
      correctly handles and responds to ICMPv6 Echo Requests sent to
      its ML-EID and various Realm-Local multicast addresses
      (FF03::1, FF03::2, and Realm-Local All Thread Nodes).
    - Added verify_5_3_2.py: PCAP verification script for test 5.3.2.
      Ensures that the DUT MUST NOT forward multicast Echo Requests
      (FF03::1, FF03::2) to the SED, and that it MUST use IEEE
      802.15.4 indirect transmissions to forward the Realm-Local All
      Thread Nodes multicast packet to the SED.
- Updated build and execution scripts:
    - Modified CMakeLists.txt to build the new 5.3.2 test executable.
    - Updated run_nexus_tests.sh to include 5.3.2 in the default
      test list.
This commit is contained in:
Jonathan Hui
2026-02-11 17:21:03 -06:00
committed by GitHub
parent f7061af035
commit 9137223384
4 changed files with 468 additions and 0 deletions
+1
View File
@@ -136,6 +136,7 @@ ot_nexus_test(5_2_5 "cert;nexus")
ot_nexus_test(5_2_6 "cert;nexus")
ot_nexus_test(5_2_7 "cert;nexus")
ot_nexus_test(5_3_1 "cert;nexus")
ot_nexus_test(5_3_2 "cert;nexus")
# Misc tests
ot_nexus_test(border_admitter "core;nexus")
+1
View File
@@ -68,6 +68,7 @@ DEFAULT_TESTS=(
"5_2_6"
"5_2_7"
"5_3_1"
"5_3_2"
)
# Use provided arguments or the default test list
+239
View File
@@ -0,0 +1,239 @@
/*
* Copyright (c) 2026, The OpenThread Authors.
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
* 3. Neither the name of the copyright holder nor the
* names of its contributors may be used to endorse or promote products
* derived from this software without specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
* AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
* ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
* INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
* CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
* POSSIBILITY OF SUCH DAMAGE.
*/
#include <stdio.h>
#include "common/as_core_type.hpp"
#include "common/encoding.hpp"
#include "mac/data_poll_sender.hpp"
#include "platform/nexus_core.hpp"
#include "platform/nexus_node.hpp"
namespace ot {
namespace Nexus {
/** Time to advance for a node to form a network and become leader, in milliseconds. */
static constexpr uint32_t kFormNetworkTime = 13 * 1000;
/** Time to advance for a node to join as a child and upgrade to a router, in milliseconds. */
static constexpr uint32_t kAttachToRouterTime = 200 * 1000;
/** Time to advance for a node to join as a child. */
static constexpr uint32_t kAttachToChildTime = 10 * 1000;
/** Time to advance for the network to stabilize after routers have attached. */
static constexpr uint32_t kStabilizationTime = 10 * 1000;
/** Large payload size to ensure fragmentation. */
static constexpr uint16_t kLargePayloadSize = 200;
/** Poll period for SED in milliseconds. */
static constexpr uint32_t kSedPollPeriod = 200;
void Test5_3_2(void)
{
/**
* 5.3.2 Realm-Local Addressing
*
* 5.3.2.1 Topology
* - Leader
* - Router 1
* - Router 2 (DUT)
* - SED 1
*
* 5.3.2.2 Purpose & Description
* The purpose of this test case is to validate the Realm-Local addresses that the DUT configures.
*
* Spec Reference | V1.1 Section | V1.3.0 Section
* -----------------|--------------|---------------
* Realm-Local Scope| 5.2.3.2 | 5.2.1.2
*/
Core nexus;
Node &leader = nexus.CreateNode();
Node &router1 = nexus.CreateNode();
Node &dut = nexus.CreateNode();
Node &sed1 = nexus.CreateNode();
leader.SetName("LEADER");
router1.SetName("ROUTER_1");
dut.SetName("DUT");
sed1.SetName("SED_1");
Instance::SetLogLevel(kLogLevelNote);
/**
* Step 1: All
* - Description: Build the topology as described and begin the wireless sniffer.
* - Pass Criteria: N/A
*/
Log("Step 1: All");
leader.AllowList(router1);
router1.AllowList(leader);
router1.AllowList(dut);
dut.AllowList(router1);
dut.AllowList(sed1);
sed1.AllowList(dut);
leader.Form();
nexus.AdvanceTime(kFormNetworkTime);
router1.Join(leader);
nexus.AdvanceTime(kAttachToRouterTime);
dut.Join(router1);
nexus.AdvanceTime(kAttachToRouterTime);
sed1.Join(dut, Node::kAsSed);
SuccessOrQuit(sed1.Get<DataPollSender>().SetExternalPollPeriod(kSedPollPeriod));
nexus.AdvanceTime(kAttachToChildTime);
VerifyOrQuit(leader.Get<Mle::Mle>().IsLeader());
VerifyOrQuit(router1.Get<Mle::Mle>().IsRouter());
VerifyOrQuit(dut.Get<Mle::Mle>().IsRouter());
VerifyOrQuit(sed1.Get<Mle::Mle>().IsChild());
nexus.AdvanceTime(kStabilizationTime);
/**
* Step 2: Leader
* - Description: Harness instructs the device to send an ICMPv6 Echo Request to the DUT ML-EID.
* - Pass Criteria: The DUT MUST respond with an ICMPv6 Echo Reply.
*/
Log("Step 2: Leader");
nexus.SendAndVerifyEchoRequest(leader, dut.Get<Mle::Mle>().GetMeshLocalEid());
/**
* Step 3: Leader
* - Description: Harness instructs the device to send a fragmented ICMPv6 Echo Request to the DUT ML-EID.
* - Pass Criteria: The DUT MUST respond with an ICMPv6 Echo Reply.
*/
Log("Step 3: Leader");
nexus.SendAndVerifyEchoRequest(leader, dut.Get<Mle::Mle>().GetMeshLocalEid(), kLargePayloadSize);
/**
* Step 4: Leader
* - Description: Harness instructs the device to send an ICMPv6 Echo Request to the Realm-Local All-Nodes
* multicast address (FF03::1).
* - Pass Criteria:
* - The DUT MUST respond with an ICMPv6 Echo Reply.
* - The DUT MUST NOT forward the ICMPv6 Echo Request to SED_1.
*/
Log("Step 4: Leader");
{
Ip6::Address multicastAddr;
multicastAddr.SetToRealmLocalAllNodesMulticast();
nexus.SendAndVerifyEchoRequest(leader, multicastAddr);
}
/**
* Step 5: Leader
* - Description: Harness instructs the device to send a fragmented ICMPv6 Echo Request to the Realm-Local
* All-Nodes multicast address (FF03::1).
* - Pass Criteria:
* - The DUT MUST respond with an ICMPv6 Echo Reply.
* - The DUT MUST NOT forward the ICMPv6 Echo Request to SED_1.
*/
Log("Step 5: Leader");
{
Ip6::Address multicastAddr;
multicastAddr.SetToRealmLocalAllNodesMulticast();
nexus.SendAndVerifyEchoRequest(leader, multicastAddr, kLargePayloadSize);
}
/**
* Step 6: Leader
* - Description: Harness instructs the device to send an ICMPv6 Echo Request to the Realm-Local All-Routers
* multicast address (FF03::2).
* - Pass Criteria:
* - The DUT MUST respond with an ICMPv6 Echo Reply.
* - The DUT MUST NOT forward the ICMPv6 Echo Request to SED_1.
*/
Log("Step 6: Leader");
{
Ip6::Address multicastAddr;
multicastAddr.SetToRealmLocalAllRoutersMulticast();
nexus.SendAndVerifyEchoRequest(leader, multicastAddr);
}
/**
* Step 7: Leader
* - Description: Harness instructs the device to send a fragmented ICMPv6 Echo Request to the Realm-Local
* All-Routers multicast address (FF03::2).
* - Pass Criteria:
* - The DUT MUST respond with an ICMPv6 Echo Reply.
* - The DUT MUST NOT forward the ICMPv6 Echo Request to SED_1.
*/
Log("Step 7: Leader");
{
Ip6::Address multicastAddr;
multicastAddr.SetToRealmLocalAllRoutersMulticast();
nexus.SendAndVerifyEchoRequest(leader, multicastAddr, kLargePayloadSize);
}
/**
* Step 8: Leader
* - Description: Harness instructs the device to send a Fragmented ICMPv6 Echo Request to the Realm-Local All
* Thread Nodes multicast address.
* - Pass Criteria:
* - The Realm-Local All Thread Nodes multicast address MUST be a realm-local Unicast Prefix-Based Multicast
* Address [RFC 3306], with:
* - flgs set to 3 (P = 1 and T = 1)
* - scop set to 3
* - plen set to the Mesh Local Prefix length
* - network prefix set to the Mesh Local Prefix
* - group ID set to 1
* - The DUT MUST use IEEE 802.15.4 indirect transmissions to forward packet to SED_1.
*/
Log("Step 8: Leader");
{
Ip6::Address multicastAddr;
multicastAddr.Clear();
multicastAddr.mFields.m8[0] = 0xff;
multicastAddr.mFields.m8[1] = 0x33;
multicastAddr.SetMulticastNetworkPrefix(dut.Get<Mle::Mle>().GetMeshLocalPrefix());
multicastAddr.mFields.m32[3] = BigEndian::HostSwap32(1);
nexus.SendAndVerifyEchoRequest(leader, multicastAddr, kLargePayloadSize);
}
nexus.SaveTestInfo("test_5_3_2.json");
}
} // namespace Nexus
} // namespace ot
int main(void)
{
ot::Nexus::Test5_3_2();
printf("All tests passed\n");
return 0;
}
+227
View File
@@ -0,0 +1,227 @@
#!/usr/bin/env python3
#
# Copyright (c) 2026, The OpenThread Authors.
# All rights reserved.
#
# Redistribution and use in source and binary forms, with or without
# modification, are permitted provided that the following conditions are met:
# 1. Redistributions of source code must retain the above copyright
# notice, this list of conditions and the following disclaimer.
# 2. Redistributions in binary form must reproduce the above copyright
# notice, this list of conditions and the following disclaimer in the
# documentation and/or other materials provided with the distribution.
# 3. Neither the name of the copyright holder nor the
# names of its contributors may be used to endorse or promote products
# derived from this software without specific prior written permission.
#
# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
# AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
# ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
# LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
# POSSIBILITY OF SUCH DAMAGE.
#
import sys
import os
# Add the current directory to sys.path to find verify_utils
CUR_DIR = os.path.dirname(os.path.abspath(__file__))
sys.path.append(CUR_DIR)
import verify_utils
from pktverify import consts
from pktverify.addrs import Ipv6Addr
def verify(pv):
# 5.3.2 Realm-Local Addressing
#
# 5.3.2.1 Topology
# - Leader
# - Router 1
# - Router 2 (DUT)
# - SED 1
#
# 5.3.2.2 Purpose & Description
# The purpose of this test case is to validate the Realm-Local addresses that the DUT configures.
#
# Spec Reference | V1.1 Section | V1.3.0 Section
# -----------------|--------------|---------------
# Realm-Local Scope| 5.2.3.2 | 5.2.1.2
pkts = pv.pkts
pv.summary.show()
LEADER = pv.vars['LEADER']
DUT = pv.vars['DUT']
SED_1 = pv.vars['SED_1']
DUT_MLEID = pv.vars['DUT_MLEID']
LEADER_MLEID = pv.vars['LEADER_MLEID']
DUT_RLOC16 = pv.vars['DUT_RLOC16']
SED_1_RLOC16 = pv.vars['SED_1_RLOC16']
mesh_local_prefix_str = pv.vars['mesh_local_prefix']
prefix = mesh_local_prefix_str.split('/')[0]
# ff33:00:40:prefix:00000001
realm_local_all_thread_nodes = Ipv6Addr(
bytearray([0xff, 0x33, 0x00, 64]) + Ipv6Addr(prefix)[:8] + bytearray([0, 0, 0, 1]))
ECHO_ID = 0x1234
# Step 1: All
# - Description: Build the topology as described and begin the wireless sniffer.
# - Pass Criteria: N/A
print("Step 1: All")
pkts.filter_wpan_src64(LEADER).filter_mle_cmd(consts.MLE_ADVERTISEMENT).must_next()
pkts.filter_wpan_src64(DUT).filter_mle_cmd(consts.MLE_ADVERTISEMENT).must_next()
# Step 2: Leader
# - Description: Harness instructs the device to send an ICMPv6 Echo Request to the DUT ML-EID.
# - Pass Criteria: The DUT MUST respond with an ICMPv6 Echo Reply.
print("Step 2: Leader")
pkts.filter_wpan_src64(LEADER) \
.filter_ipv6_dst(DUT_MLEID) \
.filter_ping_request(identifier=ECHO_ID) \
.must_next()
pkts.filter_wpan_src64(DUT) \
.filter_ipv6_dst(LEADER_MLEID) \
.filter_ping_reply(identifier=ECHO_ID) \
.must_next()
# Step 3: Leader
# - Description: Harness instructs the device to send a fragmented ICMPv6 Echo Request to the DUT ML-EID.
# - Pass Criteria: The DUT MUST respond with an ICMPv6 Echo Reply.
print("Step 3: Leader")
pkts.filter_wpan_src64(LEADER) \
.filter_ipv6_dst(DUT_MLEID) \
.filter_ping_request(identifier=ECHO_ID) \
.filter(lambda p: hasattr(p, 'lowpan') and hasattr(p.lowpan, 'fragment')) \
.must_next()
pkts.filter_wpan_src64(DUT) \
.filter_ipv6_dst(LEADER_MLEID) \
.filter_ping_reply(identifier=ECHO_ID) \
.must_next()
# Step 4: Leader
# - Description: Harness instructs the device to send an ICMPv6 Echo Request to the Realm-Local All-Nodes
# multicast address (FF03::1).
# - Pass Criteria:
# - The DUT MUST respond with an ICMPv6 Echo Reply.
# - The DUT MUST NOT forward the ICMPv6 Echo Request to SED_1.
print("Step 4: Leader")
pkts.filter_wpan_src64(LEADER) \
.filter_ipv6_dst(consts.REALM_LOCAL_ALL_NODES_ADDRESS) \
.filter_ping_request(identifier=ECHO_ID) \
.must_next()
pkts.filter_wpan_src64(DUT) \
.filter_ipv6_dst(LEADER_MLEID) \
.filter_ping_reply(identifier=ECHO_ID) \
.must_next()
pkts.copy().filter_wpan_src64(DUT) \
.filter_wpan_dst64(SED_1) \
.filter_ipv6_dst(consts.REALM_LOCAL_ALL_NODES_ADDRESS) \
.must_not_next()
# Step 5: Leader
# - Description: Harness instructs the device to send a fragmented ICMPv6 Echo Request to the Realm-Local
# All-Nodes multicast address (FF03::1).
# - Pass Criteria:
# - The DUT MUST respond with an ICMPv6 Echo Reply.
# - The DUT MUST NOT forward the ICMPv6 Echo Request to SED_1.
print("Step 5: Leader")
pkts.filter_wpan_src64(LEADER) \
.filter_ipv6_dst(consts.REALM_LOCAL_ALL_NODES_ADDRESS) \
.filter_ping_request(identifier=ECHO_ID) \
.filter(lambda p: hasattr(p, 'lowpan') and hasattr(p.lowpan, 'fragment')) \
.must_next()
pkts.filter_wpan_src64(DUT) \
.filter_ipv6_dst(LEADER_MLEID) \
.filter_ping_reply(identifier=ECHO_ID) \
.must_next()
pkts.copy().filter_wpan_src64(DUT) \
.filter_wpan_dst64(SED_1) \
.filter_ipv6_dst(consts.REALM_LOCAL_ALL_NODES_ADDRESS) \
.must_not_next()
# Step 6: Leader
# - Description: Harness instructs the device to send an ICMPv6 Echo Request to the Realm-Local All-Routers
# multicast address (FF03::2).
# - Pass Criteria:
# - The DUT MUST respond with an ICMPv6 Echo Reply.
# - The DUT MUST NOT forward the ICMPv6 Echo Request to SED_1.
print("Step 6: Leader")
pkts.filter_wpan_src64(LEADER) \
.filter_ipv6_dst(consts.REALM_LOCAL_ALL_ROUTERS_ADDRESS) \
.filter_ping_request(identifier=ECHO_ID) \
.must_next()
pkts.filter_wpan_src64(DUT) \
.filter_ipv6_dst(LEADER_MLEID) \
.filter_ping_reply(identifier=ECHO_ID) \
.must_next()
pkts.copy().filter_wpan_src64(DUT) \
.filter_wpan_dst64(SED_1) \
.filter_ipv6_dst(consts.REALM_LOCAL_ALL_ROUTERS_ADDRESS) \
.must_not_next()
# Step 7: Leader
# - Description: Harness instructs the device to send a fragmented ICMPv6 Echo Request to the Realm-Local
# All-Routers multicast address (FF03::2).
# - Pass Criteria:
# - The DUT MUST respond with an ICMPv6 Echo Reply.
# - The DUT MUST NOT forward the ICMPv6 Echo Request to SED_1.
print("Step 7: Leader")
pkts.filter_wpan_src64(LEADER) \
.filter_ipv6_dst(consts.REALM_LOCAL_ALL_ROUTERS_ADDRESS) \
.filter_ping_request(identifier=ECHO_ID) \
.filter(lambda p: hasattr(p, 'lowpan') and hasattr(p.lowpan, 'fragment')) \
.must_next()
pkts.filter_wpan_src64(DUT) \
.filter_ipv6_dst(LEADER_MLEID) \
.filter_ping_reply(identifier=ECHO_ID) \
.must_next()
pkts.copy().filter_wpan_src64(DUT) \
.filter_wpan_dst64(SED_1) \
.filter_ipv6_dst(consts.REALM_LOCAL_ALL_ROUTERS_ADDRESS) \
.must_not_next()
# Step 8: Leader
# - Description: Harness instructs the device to send a Fragmented ICMPv6 Echo Request to the Realm-Local All
# Thread Nodes multicast address.
# - Pass Criteria:
# - The Realm-Local All Thread Nodes multicast address MUST be a realm-local Unicast Prefix-Based Multicast
# Address [RFC 3306], with:
# - flgs set to 3 (P = 1 and T = 1)
# - scop set to 3
# - plen set to the Mesh Local Prefix length
# - network prefix set to the Mesh Local Prefix
# - group ID set to 1
# - The DUT MUST use IEEE 802.15.4 indirect transmissions to forward packet to SED_1.
print("Step 8: Leader")
pkts.filter_wpan_src64(LEADER) \
.filter_ipv6_dst(realm_local_all_thread_nodes) \
.filter_ping_request(identifier=ECHO_ID) \
.filter(lambda p: hasattr(p, 'lowpan') and hasattr(p.lowpan, 'fragment')) \
.must_next()
pkts.filter(lambda p: p.wpan.src16 == SED_1_RLOC16) \
.filter_wpan_cmd(consts.WPAN_DATA_REQUEST) \
.must_next()
# DUT forwards the packet to SED_1 responding to the Data Request.
# We use RLOC16 filters because decryption might fail for these packets.
pkts.filter(lambda p: p.wpan.src16 == DUT_RLOC16 and p.wpan.dst16 == SED_1_RLOC16) \
.must_next()
# SED_1 sends Echo Reply (unicast to Leader).
# Unicast packets are usually mapped and decrypted correctly if mapping was learned.
pkts.filter(lambda p: p.wpan.src16 == SED_1_RLOC16) \
.filter_ipv6_dst(LEADER_MLEID) \
.filter_ping_reply(identifier=ECHO_ID) \
.must_next()
if __name__ == '__main__':
verify_utils.run_main(verify)