RPL trace analysis from Cooja logs
Reconstruct DODAG parent choices and count DIO and DAO messages from a saved Cooja trace.

Packet Pete: inspect the input, calculation and observed output before choosing a route.
Predict the reading, then compare it with the measurement.
Python 3 in your browser (JupyterLite)
Python · no installReconstruct DODAG parent choices and count DIO and DAO messages from a saved Cooja trace.
Open the notebook in your browser and run each Python cell; no install or account is needed.
Three ways to run: use JupyterLite here with no install; run main.py locally from the downloadable lab folder; or open the same notebook in Google Colab.
Steps
Step 1
- Do
- In the JupyterLite notebook, run step 1 to verify the saved Cooja log hash and parse timestamped rows.
- You will see
- REAL saved Contiki-NG Cooja headless serial/test log; source=practice/cooja-rpl-parent-switch/expected-output.txt; sha256=a04f5ac80bbd7000942935d334a16369b8134cede785167bd7204ccf9ee46f05
- Why it matters
- The hash ties the analysis to the saved real simulator run.

Step 1 · Python 3 in your browser (JupyterLite); numbered callout added to a real capture. Enlarge screenshot (new tab) Step 2
- Do
- In the JupyterLite notebook, run step 2 to rebuild the parent table over time.
- You will see
- DODAG parent table reconstructed from parent-switch lines; time_s node->parent (- means no selected parent); 85.065 1->- 2->1 3->1 4->2 5->3 6->3
- Why it matters
- Explicit switch events provide a reproducible parent timeline.

Step 2 · Python 3 in your browser (JupyterLite); numbered callout added to a real capture. Enlarge screenshot (new tab) Step 3
- Do
- In the JupyterLite notebook, run step 3 to locate target 5’s parent switch after relay removal.
- You will see
- Target 5 parent transition around relay removal; fault scheduled=90.065000 s; relay 3 moved away; switch=100.760728 s: node 5 parent 3 -> 2
- Why it matters
- The timestamp difference measures observed parent-change delay.

Step 3 · Python 3 in your browser (JupyterLite); numbered callout added to a real capture. Enlarge screenshot (new tab) Step 4
- Do
- In the JupyterLite notebook, run step 4 to inspect other parent changes.
- You will see
- Other observed parent events after removal, before 140.065 s; time_s node old->new; 100.760728 5 3->2
- Why it matters
- The rest of the DODAG may behave differently from target 5.

Step 4 · Python 3 in your browser (JupyterLite); numbered callout added to a real capture. Enlarge screenshot (new tab) Step 5
- Do
- In the JupyterLite notebook, run step 5 to count outgoing DIO and DAO lines.
- You will see
- Outgoing RPL control messages in serial log; phase DIO DAO (DAO-ACK excluded); before fault 47 5
- Why it matters
- Logged sends are countable without assuming delivery.

Step 5 · Python 3 in your browser (JupyterLite); numbered callout added to a real capture. Enlarge screenshot (new tab) Step 6
- Do
- In the JupyterLite notebook, run step 6 to record the result and its evidence limit.
- You will see
- RESULT CARD: real saved Cooja run, seed 1; target 5 parent 3->2 at 100.760728 s; first post-fault parent change delay=10.695728 s
- Why it matters
- A target recovery result does not prove global repair.

Step 6 · Python 3 in your browser (JupyterLite); numbered callout added to a real capture. Enlarge screenshot (new tab)
Chapter checks
These questions refer to the chapter’s examples. Use the return links to review their answers.
A node has selected a preferred parent after hearing compatible DIO messages. Which extra RPL evidence matters when gateway-to-node commands are part of the claim?
Return to the chapter’s knowledge checkA trace shows one DAO from a node, then a parent repair occurs. Later, root-to-node commands fail. What is the strongest RPL review response?
Return to the chapter’s knowledge check