Documentation
July 18, 2026 · View on GitHub
This directory contains user and contributor documentation for the Rust
crafter crate and its validation workflow. It is organized into role-based
areas:
guide/— per-protocol wire coverage for everyday packet work, each with the explicit list of RFCs/standards the library implements.reference/— the API surface, the wire I/O layer, and how to run the bundled examples.operations/— live, provider-backed, and manual testing workflows (validation, probes, lab sessions, endpoints).
Guides
Per-protocol wire coverage for building and decoding packets.
- IPv4 wire coverage — IPv4 construction, DSCP/ECN, protocol-number labels, checksum status, typed options, fragment fields without reassembly, decode policy, and validation coverage.
- IGMP wire coverage — IPv4 packet-layer IGMP construction, decode, Router Alert envelope guidance, v1/v2/v3 membership packets, generic extensions, multicast router discovery packet shapes, and the dry-run/live boundary. IGMP is not a multicast router implementation or scanner.
- IPv6 wire coverage — IPv6 base and extension headers, source-backed manifests, offline fixtures, and oracle coverage.
- TCP wire coverage — TCP segment construction, typed options, checksums, decode, inspection, and sizing helpers.
- UDP wire coverage — UDP datagram construction, length and checksum auto-fill, decode dispatch, and the implemented RFCs.
- SCTP wire coverage — native IPv4/IPv6 SCTP, RFC 6951 UDP encapsulation, CRC32c status, chunk/parameter/cause preservation, pcap fixtures, and the dry-run/live boundary. SCTP support is not an association stack or socket API.
- DHCPv4 wire coverage — BOOTP/DHCPv4 packet construction, named message constructors, typed options, option overload, RFC 3396 long options, relay agent information (option 82), client identifiers, authentication, leasequery packet fields, decode, inspection, dry-run planning, and the provider-backed live boundary.
- DHCPv6 wire coverage — DHCPv6 client/server and relay packet construction, typed options, prefix delegation, decode, inspection, offline fixtures, dry-run send/receive planning, and the provider-backed live boundary.
- ARP wire coverage — ARP request/reply construction over Ethernet, IPv4 address resolution, decode, and the implemented RFCs.
- ICMPv6 wire coverage — ICMPv6 error/informational messages, Neighbor Discovery, checksum handling, decode, and the implemented RFCs.
- DNS wire coverage — supported DNS wire-message primitives, planned typed records, and known deferrals.
- BGP wire coverage — BGP message construction, UPDATE path attributes, MP-BGP, TCP/179 decode dispatch, and the offline/live surfaces.
- MQTT wire coverage — MQTT 3.1.1 and 5.0 control packet construction, properties, TCP/1883 decode dispatch, stacked payload decode, inspection, and the offline/live surfaces.
- CoAP wire coverage — CoAP datagrams and reliable frames, typed options and extensions, OSCORE transforms, conservative Raw fallback, pcap persistence, and the guarded provider-backed validation boundary.
- SNMP wire coverage — SNMP BER values, VarBinds, v1/v2c PDUs, v3 wire framing, UDP/161 and UDP/162 decode dispatch, unknown preservation, pcap fixtures, and the dry-run/live-lab boundary. SNMP support is not a scanner, manager, agent daemon, MIB engine, credential store, or VACM evaluator.
- NTP wire coverage — NTP fixed-header construction, UDP/123 decode dispatch, extension fields, NTS packet extension wrappers, legacy MAC tails, Kiss-o'-Death labels, raw fallback, and the provider-backed live boundary.
- RIP wire coverage — RIPv1/RIPv2 and RIPng message construction, route entries, authentication, UDP/520 and UDP/521 decode dispatch, and the offline/live surfaces.
- Dot11 wire coverage — bare IEEE 802.11, radiotap, LLC/SNAP, EAPOL, RSN foundations, pcap link types, and the dry-run/manual live boundary.
- BLE advertising wire coverage — BLE radio pseudo-header, advertising Link Layer PDUs, GAP Advertising Data structures, pcap link type, and the dry-run/live dongle boundary.
- IPsec wire coverage — AH/ESP construction, transforms, and the supported offline and live surfaces.
Reference
The public API and wire I/O surface, plus example instructions.
- API guide — the public crate, explicit IPv4/IPv6 packet APIs, packet composition style, packet I/O, and helper APIs.
- Wire packet I/O —
crafter::wire,PacketWire,PacketRecordmetadata,Sniffer,Transmitter, and transform chains. - Examples — how to build and run the Rust examples.
Operations
Live, provider-backed, and manual testing workflows.
- Tools overview — the endpoint/lab/oracle/probe stack, when to reach for each tool, and safe dry-run examples.
- Appliance operations — the standard Docker appliance, profiles, modules, substrates, persistent assets, leases, checks, artifacts, dry-run defaults, and live gates.
- Oracle validation — corpus, offline, pcap, and provider-backed reference validation.
- Probe validation — kernel and service behavior probes.
- Lab sessions — provider-backed multi-endpoint sessions used by oracle and probe.
- Endpoint provider guide — shared disposable endpoint provider setup, credentials, artifacts, and cleanup for one endpoint.
- NTP live validation — guarded dry-run, oracle, probe, endpoint, artifact, and teardown notes for NTP live validation.
- Dot11 live manual — manual procedure for the IEEE 802.11 live testing boundary.
- BLE WHAD live manual — manual procedure for the feature-gated WHAD dongle live testing boundary.
Agent operating guidance belongs under
.agents/docs/cookbook.md, not here.