log.pdus on a whole
worker, which writes every session’s decoded PDUs into a shared log the cleanup timer keeps for a
fortnight.
A capture does the same for one session, on demand, and takes the result away with it.
smsg.ops.admin.token.
What it contains, and why that is the admin token
Everything, decoded: message bodies, destination numbers, TLVs. That is the point — a capture that left content out could not answer the question people start one for. It is also why these need the admin token rather than the read token, and why the.txt
says so in its own header.
What it costs
Nothing measurable, which is the rule the feature is built to. The tap is one volatile field read per PDU on sessions that are not being captured. On the captured session it does one boundedoffer onto a hand-off queue and returns; a separate thread does
all formatting and encoding, so nothing expensive runs on the Netty I/O thread.
Measured on a loopback listener at ~32 000 TPS — roughly thirty times a busy real session — a capture
under load stayed inside the run-to-run noise of the uncaptured baseline, with dropped at zero.
Bounds, and nothing touching disk
Whichever cap is reached first stops the capture and says which —
stopped_because carries a
sentence like reached the 8388608 byte limit. A truncated file with no explanation is a wrong fact
about the customer.
Captures live in memory only. The service runs under ProtectSystem=strict, so a file would have
to sit in the data directory as plaintext customer content; a bounded buffer that expires makes the
retention story “fifteen minutes, enforced” rather than “until somebody remembers”. A fourth
concurrent capture is refused with 409.
The pcap framing is synthetic
The.pcap opens in Wireshark and its SMPP dissector reads it — but the IPv4 and TCP headers around
each PDU are fabricated.
What is captured is decoded PDUs, re-encoded, not the bytes that were on the wire. Addresses and ports
are the session’s real ones; sequence numbers, windows and flags are constructed to make the stream
reassemble.
On a non-standard port, tell Wireshark it is SMPP
Wireshark registers the SMPP dissector on TCP 2775. A session on any other port — a vendor on 2779, a second listener on 27778 — is dissected as plain TCP, and the SMPP filter then matches nothing. That looks exactly like a corrupt file, so rule it out first:tcpdump -r capture.pcap -n | head -1 tells you which number to use.
Vendor sessions
Captures work the same on a vendor connection, which is why every session reports asession_id on
both kinds.
That id does not mean a vendor bind can be dropped — disconnect still answers 409 for a vendor
worker, because the guard is the worker kind, not the presence of an id.
Related
Tokens and access
Why this needs the admin token and health does not.
Worker control
Disable, suspend and hold.