Time Slave Detailed Design#
Time Slave Detailed Design
|
status: draft
security: NO
safety: ASIL_B
|
||||
Description#
Use Cases#
TimeSlave is a standalone gPTP (IEEE 802.1AS) slave endpoint process that implements the low-level time synchronization protocol for the Eclipse SCORE time system. It is deployed as a separate process from the TimeDaemon to isolate real-time network I/O from the higher-level time validation and distribution logic.
More precisely we can specify the following use cases for the TimeSlave:
Receiving gPTP Sync/FollowUp messages from a Time Master on the Ethernet network
Measuring peer delay via the IEEE 802.1AS PDelayReq/PDelayResp exchange
Optionally adjusting the PTP Hardware Clock (PHC) on the NIC
Publishing the resulting
GptpIpcDatato shared memory for consumption by the TimeDaemon
The raw architectural diagram is represented below.
Rationale Behind Decomposition into Units#
TimeSlave is decomposed into seven implementation units following SOLID principles (Single Responsibility, Open/Closed) and design patterns (Strategy, Facade):
TimeSlave Application — Orchestrates the overall process lifecycle and periodic publish loop
GptpEngine — Core gPTP protocol engine managing the RxThread and PdelayThread for network I/O
FrameCodec — Encodes and decodes raw Ethernet frames for gPTP communication
MessageParser — Parses the PTP wire format (IEEE 1588-v2) from raw payload bytes
SyncStateMachine — Correlates Sync/FollowUp messages and computes clock offset and rate ratio
PeerDelayMeasurer — Implements the IEEE 802.1AS peer delay measurement protocol
PhcAdjuster — Synchronizes the PTP Hardware Clock on the NIC
This separation enables independent testing, exchangeability of platform-specific implementations (raw sockets, PHC drivers), and clear responsibility boundaries critical for ASIL_B safety qualification.
TimeSlave publishes its GptpIpcData snapshot to shared memory using the GptpIpcPublisher
from the ts_client component; the TimeDaemon-side
consumer (ShmPTPEngine) is documented in the Time Daemon detailed design.
Static Diagrams for Unit Interactions#
Class View#
Main classes and unit relationships are presented on this diagram:
Dynamic Diagrams for Unit Interactions#
Data and Control Flow#
The data and control flow between units is presented in the following diagram:
On this view you could see several “workers” scopes:
RxThread scope — receive raw gPTP Ethernet frames, decode PTP messages, correlate Sync/FollowUp and handle Pdelay messages
PdelayThread scope — periodically transmit PDelayReq frames
Main thread scope — periodically publish aggregated snapshot to shared memory
See gptp_engine.h for detailed threading model, control flow responsibilities, and concurrency aspects.
Control Flows#
Each control flow has dedicated thread and runs independently.
RxThread scope
receive raw gPTP Ethernet frames with hardware timestamps from NIC via raw sockets
decode and parse PTP messages (Sync, FollowUp, PdelayResp, PdelayRespFollowUp, PdelayReq)
depending on message type:
correlate Sync/FollowUp pairs and compute clock offset and neighborRateRatio. Update shared snapshot under mutex protection
correlate PdelayResp/PdelayRespFollowUp pairs with sent PdelayReq using the PeerDelayMeasurer unit and compute the propagation delay as defined in the IEEE 802.1AS standard
react on incoming PdelayReq by sending PdelayResp and PdelayRespFollowUp
PdelayThread scope
delay sending the first PdelayReq by the configured pdelay_warmup timespan
periodically trigger the PeerDelayMeasurer unit to send PdelayReq frames and capture hardware transmit timestamps
Main thread (periodic publish) scope
call
GptpEngine::FinalizeSnapshot()to check timeout and commit pending snapshotcall
GptpEngine::ReadPTPSnapshot(data)to copy latestGptpIpcDatato local variablepublish snapshot via
GptpIpcPublisher::Publish(data)
Data Types or Events#
Main data exchanged between units:
PTPMessage — union-based container for decoded gPTP messages plus hardware receive timestamp; produced by
MessageParserand consumed bySyncStateMachineandPeerDelayMeasurerSyncResult — produced by
SyncStateMachine::OnFollowUp(); includes computed master timestamp, clock offset, Sync/FollowUp data, and time-jump flagsPDelayResult — produced by
PeerDelayMeasurer; includes computed path delay in nanoseconds and validity flagPtpTimeInfo — TimeDaemon-internal aggregated snapshot, not shared-memory type; produced by
ShmPTPEngine::ReadPTPSnapshot()by mapping fromGptpIpcData
Units Within Time Slave#
GptpEngine#
The GptpEngine runs RxThread and PdelayThread, and provides FinalizeSnapshot() + ReadPTPSnapshot() for periodic publish logic.
Class View#
The Class Diagram is presented below:
Threading Model#
The GptpEngine operates with two background threads. The threading model is represented below:
Concurrency Aspects#
std::mutexprotectspending_snapshot_andcurrent_snapshot_(bothGptpIpcData): RxThread writes pending; main thread finalizes and reads currentPeerDelayMeasureruses internalstd::mutexto synchronizeSendRequest()(PdelayThread) withOnResponse()/OnResponseFollowUp()(RxThread)SyncStateMachineusesstd::atomic<bool>timeout flag written by RxThread and read by main thread
Hardware Timestamping Fallback#
During Initialize(), GptpEngine calls RawSocket::EnableHwTimestamping() to request NIC-level receive timestamps (SO_TIMESTAMPING on Linux). If the NIC does not support hardware timestamping, the call returns false and a warning is logged:
GptpEngine: HW timestamping not available on <iface>, falling back to SW timestamps
The engine continues to run normally. The difference between the two modes:
Field |
HW timestamping available |
SW timestamping fallback |
|---|---|---|
|
NIC hardware timestamp (nanosecond precision, captured at wire level) |
Software timestamp (captured at socket receive, higher jitter) |
|
Derived from NIC hardware timestamp |
Derived from software timestamp |
|
Always |
Always |
Clock offset accuracy |
High (sub-microsecond typical) |
Reduced (jitter depends on OS scheduling latency) |
The fallback does not affect protocol correctness – Sync/FollowUp correlation and peer delay measurement continue to work – but the computed clock offset will be less accurate due to higher receive timestamp jitter.
PeerDelayMeasurer#
The PeerDelayMeasurer unit implements the IEEE 802.1AS two-step peer delay measurement protocol. It manages the four timestamps (t1, t2, t3c, t4) across two threads.
Timestamp Definitions#
Symbol |
Message |
Captured by |
Meaning |
|---|---|---|---|
|
PDelayReq (TX) |
Slave (PdelayThread) |
HW transmit timestamp of the PDelayReq frame leaving the slave NIC |
|
PDelayResp (RX) |
Master -> carried in PDelayResp body |
HW receive timestamp of the PDelayReq frame arriving at the master NIC |
|
PDelayRespFollowUp |
Master -> carried in PDelayRespFollowUp body |
HW transmit timestamp of the PDelayResp frame leaving the master NIC (“corrected” because it includes the master’s turnaround correction) |
|
PDelayResp (RX) |
Slave (RxThread) |
HW receive timestamp of the PDelayResp frame arriving at the slave NIC |
The peer delay formula is: path_delay = ((t2 - t1) + (t4 - t3c)) / 2
(t2 - t1)= propagation time from slave -> master(t4 - t3c)= propagation time from master -> slaveThe average of the two gives the one-way link delay
PhcAdjuster#
The PhcAdjuster unit synchronizes the PTP Hardware Clock (PHC) on the NIC. It applies step corrections for large offsets and frequency slew for smooth convergence of small offsets.
Platform Support#
TimeSlave supports two target platforms with platform-specific implementations selected at compile time via Bazel select(). The RawSocket and NetworkIdentity interfaces provide the abstraction boundary.
See gptp_engine.h and raw_socket.h for hardware timestamping mechanisms (AF_PACKET/BPF), phc_adjuster.h for PHC adjustment APIs (clock_adjtime vs QNX ioctls), and network_identity.h for MAC address retrieval methods.
Platform-specific source files are organized under score/time_slave/src/gptp/platform/linux/ and score/time_slave/src/gptp/platform/qnx/.
Instrumentation#
TimeSlave provides two runtime instrumentation mechanisms for development and debugging:
ProbeManager — singleton that traces probe events at key processing points (packet RX, Sync/FollowUp processing, peer delay completion, PHC adjustments)
Recorder — thread-safe CSV file writer that appends timestamped event rows to disk
See probe.h for ProbePoint enumeration and zero-overhead GPTP_PROBE() macro.
See recorder.h for CSV format, RecordEvent types, Recorder::Config parameters, and error-handling behavior.
Logging configuration#
TimeSlave uses the following logging contexts:
Component |
Context ID |
Comments |
|---|---|---|
TimeSlave Application |
TSAP |
TimeSlave Application lifecycle (Initialize / Run) |
gPTP Engine (RxThread / PdelayThread) |
GTPS |
GPTP SLAVE engine — low-level protocol processing |
Variability#
Configuration#
The GptpEngineOptions struct provides all configurable parameters for the gPTP engine:
Parameter |
Type |
Description |
|---|---|---|
|
string |
Network interface for gPTP frames (e.g., |
|
int |
Interval between PDelayReq transmissions (ms); default: |
|
int |
Delay before the first PDelayReq is sent (ms); default: |
|
int |
Timeout for Sync message reception before declaring timeout state (ms); default: |
|
int64_t |
Threshold above which a positive clock offset is flagged as a forward time jump (ns); default: |
|
PhcConfig |
PHC hardware clock adjustment settings (see |
The PhcConfig struct (embedded in GptpEngineOptions) contains:
Parameter |
Type |
Description |
|---|---|---|
|
bool |
Enable or disable PHC adjustment; default: |
|
string |
PHC device identifier: |
|
int64_t |
Offset threshold above which a step correction is applied instead of frequency slew (ns); default: |
Scalability#
The TimeSlave architecture supports the following extensibility points:
Platform extensibility#
New target platforms can be supported by implementing the
RawSocketandNetworkIdentityinterfaces under a newplatform/<os>/directory and selecting the implementation viaBazel select()The
PhcAdjusterplatform implementations (clock_adjtimeon Linux, EMAC ioctls on QNX) can be extended for additional hardware without changing protocol logic
Protocol extensibility#
The
GptpEngineaccepts injectedRawSocketandNetworkIdentitydependencies, making it straightforward to test or replace individual platform abstractionsThe shared memory IPC channel name is configurable (
GptpIpcPublisher::Init(name)), allowing multiple gPTP instances per ECU if needed
The GptpIpcPublisher used here, and the corresponding GptpIpcReceiver/ShmPTPEngine on the
consuming side, are documented in the ts_client and
Time Daemon detailed designs respectively.
Using in Test Environment#
Using in ITF#
Normal behavior is expected. TimeSlave runs as a standalone process, communicates over real Ethernet, and writes to /gptp_ptp_info shared memory as in production.
Using in Component Tests on Host#
Overview#
The TimeSlave and its constituent components can be tested on an x86 Linux host without PTP hardware or a real network. The key platform-dependent abstractions all have test-injectable counterparts:
Abstraction |
Production implementation |
Test replacement |
|---|---|---|
|
|
|
|
|
|
|
Platform clock (Linux / QNX) |
|
The GptpEngine provides a dedicated test constructor that accepts injected implementations:
GptpEngine engine(opts,
std::make_unique<FakeSocket>(),
std::make_unique<FakeIdentity>());
This allows complete white-box testing of the Sync/FollowUp correlation, peer-delay measurement, timeout detection, and time-jump flagging logic by pushing crafted PTP frames directly into the FakeSocket queue.
The GptpIpcPublisher and GptpIpcReceiver rely on POSIX shared memory (shm_open), which works on any Linux host, so ShmPTPEngine component tests can run end-to-end using real IPC without modification.
Inspection Checklist#
The checklist for verification of the detailed design and code can be found here: