btmon(1) btmon(1) (NAME) btmon - HCI (SYNOPSIS) btmon [OPTIONS ...] (DESCRIPTION) btmon(1) (traces) HCI . (OPTIONS) -r FILE, --read FILE (traces) btsnoop FILE. -w FILE, --write FILE btsnoop FILE. -a FILE, --analyze FILE btsnoop FILE. FILE . gnuplot . -s SOCKET, --server SOCKET . -p PRIORITY, --priority PRIORITY . +-------------------+-----------------------------------+ | | (NAME) | |(PRIORITY) | | +-------------------+-----------------------------------+ |3 | (Error) | +-------------------+-----------------------------------+ |4 | (Warning) | +-------------------+-----------------------------------+ |6 | | | | () | +-------------------+-----------------------------------+ |7 | | | | (Debug). | | | debug | | | . | +-------------------+-----------------------------------+ -i NUM, --index NUM . hciNUM . . -d TTY, --tty TTY TTY. -B SPEED, --rate SPEED TTY. SPEED 115300 . -V COMPID, --vendor COMPID . COMPID Bluetooth SIG Bluetooth SIG . (Intel) 2 (Realtek) 93 . -M, --mgmt (mgmt). -K, --kernel kmsg (kernel). -t, --time ( ). -T, --date . -N, --no-time . -S, --sco (Dump) SCO . -A, --a2dp A2DP . -I, --iso (ISO) . LE Audio . -E IP, --ellisys IP HCI (Ellisys HCI Injection). -P, --no-pager ( less) . -J OPTIONS, --jlink OPTIONS RTT. (,) . +-------------------------+----------------------------+ | | | |(OPTIONS) | (Description) | +-------------------------+----------------------------+ |DEVICE | . | | | | | | | | | . | +-------------------------+----------------------------+ |SERIALNO | () | | | | | | | | | USB. | | | 0 | | | . | +-------------------------+----------------------------+ |INTERFACE | () | | | . | | | swd | | | . | +-------------------------+----------------------------+ |SPEED | () | | | | | | | | | | | | | | | (kHz). | | | 1000 | | | . | +-------------------------+----------------------------+ -R OPTIONS, --rtt OPTIONS RTT. (,) . +-------------------------+----------------------------+ | | | |(OPTIONS) | (Description) | +-------------------------+----------------------------+ |ADDRESS | () | | | | | | RTT. | | | 0x00 . | +-------------------------+----------------------------+ |AREA | () | | | | | | | | | | | | | | | RTT. | | | 0 | | | . | +-------------------------+----------------------------+ |NAME | () | | | . | | | | | | btmonitor . | +-------------------------+----------------------------+ -C WIDTH, --columns WIDTH . -c MODE, --color MODE . MODE : auto|always|never. auto . -v, --version -h, --help (READING THE OUTPUT) btmon . . (Line Prefixes) : +-------------------+-----------------------------------+------------------------------------+ | | (Meaning) | | |(Prefix) | | (Description) | +-------------------+-----------------------------------+------------------------------------+ |< | / | | | | HCI (HCI Command / | | | | Data TX) | | | | | (). | | | | HCI | | | | | | | | ACL/SCO/ISO | | | | | | | | . | +-------------------+-----------------------------------+------------------------------------+ |> | | | | | / | | | | HCI (HCI Event / Data RX) | | | | | | | | | (). | | | | HCI | | | | | | | | ACL/SCO/ISO | | | | | | | | | | | | . | +-------------------+-----------------------------------+------------------------------------+ |@ | | | | | (Management | | | | traffic) | | | | | (MGMT) bluetoothd | | | | | | | | (kernel). | +-------------------+-----------------------------------+------------------------------------+ |= | | | | | (System notes) | | | | | : | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | D-Bus. | +-------------------+-----------------------------------+------------------------------------+ HCI (HCI Traffic) (< >) HCI . HCI: < HCI Command: Reset (0x03|0x0003) plen 0 #5 [hci0] 12:35:01.843185 | | | | | | | | | | | | | | | Timestamp | | | | | | Controller | | | | | Frame number | | | | Parameter length (bytes) | | | Full opcode (16-bit) | | OGF|OCF (Opcode Group / Command Field) | Command name (human-readable) Direction: < = Host to Controller (outgoing) HCI: > HCI Event: Command Complete (0x0e) plen 4 #6 [hci0] 12:35:01.864922 | | | | | | | | | | | Timestamp | | | | Controller | | | Frame number | | Parameter length | Event code | Direction: > = Controller to Host (incoming) < ( ). > ( ). : < > . HCI : < HCI Command: LE Set Extende.. (0x08|0x0039) plen 2 #1 [hci0] 12:35:01.738352 Extended advertising: Disabled (0x00) Number of sets: Disable all sets (0x00) HCI : > HCI Event: Command Complete (0x0e) plen 4 #6 [hci0] 12:35:01.864922 Reset (0x03|0x0003) ncmd 2 Status: Success (0x00) ncmd 2 ( HCI flow control). . LE (LE Meta Events) (subevent) : > HCI Event: LE Meta Event (0x3e) plen 31 #487 [hci0] 12:36:18.974201 LE Enhanced Connection Complete (0x0a) Status: Success (0x00) Handle: 2048 Role: Peripheral (0x01) Peer address type: Public (0x00) Peer address: AA:BB:CC:DD:EE:FF (OUI Company) Connection interval: 60.00 msec (0x0030) Connection latency: 0 (0x0000) Supervision timeout: 9600 msec (0x03c0) ACL (data plane) (handle) : < LE-ACL: Handle 2048 [66:B0:26:F1:D3:BC] [1/6] flags 0x00 dlen 16 #493 [hci0] 12:36:18.977915 | | | | | | | | | | | | | | | | | | | Timestamp | | | | | | | | Controller | | | | | | | Frame number | | | | | | Data length | | | | | flags | | | | Buffer tracking (optional) | | | Peer address (optional) | | Handle number | Connection-type-aware label (e.g. BR-ACL, LE-ACL, BR-SCO, LE-ISO) Direction marker: '<' = host->controller (TX), '>' = controller->host (RX) ACL : < LE-ACL: Handle 2048 [2/6] flags 0x00 dlen 7 #494 [hci0] 12:36:18.978488 ATT: Exchange MTU Request (0x02) len 2 Client RX MTU: 517 > LE-ACL: Handle 2048 flags 0x02 dlen 11 #497 [hci0] 12:36:19.000048 SMP: Pairing Request (0x01) len 6 IO capability: NoInputNoOutput (0x03) OOB data: Authentication data not present (0x00) Authentication requirement: Bonding, MITM, SC, No Keypresses, CT2 (0x2d) Max encryption key size: 16 (Management Traffic) (@) @ -- / bluetoothd ( doc/mgmt-protocol.rst). : @ MGMT Command: Set Powered (0x0005) plen 1 {0x0001} [hci0] 12:35:04.033564 | | | | | | | | | | | Timestamp | | | | Controller | | | MGMT socket ID | | Parameter length | MGMT opcode @ = Management channel {0x0001} -- ( bluetoothd btmgmt) . MGMT Open/Close : @ MGMT Open: bluetoothd (privileged) version 1.23 {0x0001} 12:34:49.881936 @ MGMT Close: bluetoothd {0x0001} 12:35:01.866256 () . MGMT : @ MGMT Command: Set Powered (0x0005) plen 1 {0x0001} [hci0] 12:35:04.033564 Powered: Enabled (0x01) MGMT ( ): @ MGMT Event: Command Complete (0x0001) plen 7 {0x0001} [hci0] 12:35:04.114789 Set Powered (0x0005) plen 4 Status: Success (0x00) Current settings: 0x004e0ac1 Powered Secure Simple Pairing MGMT ( ): @ MGMT Command: Read Management Ver.. (0x0001) plen 0 {0x0001} 12:35:04.027771 @ MGMT Event: Command Complete (0x0001) plen 6 {0x0001} 12:35:04.027776 [hci0] -- . (System Notes) (=) = . HCI MGMT . (Kernel information) ( ): = Note: Linux version 6.16.0-rc6-0903 (x86_64) 12:34:49.881926 = Note: Bluetooth subsystem version 2.22 12:34:49.881930 (Index lifecycle) (// / ): = New Index: 00:11:22:33:44:55 (Primary,USB,hci0) [hci0] 12:34:49.881932 = Open Index: 00:11:22:33:44:55 [hci0] 12:34:49.881933 = Index Info: 00:11:22:33:44:55 (OUI Company) [hci0] 12:34:49.881934 = Close Index: 00:11:22:33:44:55 [hci0] 12:35:01.865125 o New Index -- o Open Index -- o Index Info -- o Close Index -- (Process log messages) ( bluetoothd ): = bluetoothd: src/adapter.c:connected_callback() hci0 devic.. 12:36:18.975307 | | | | | Timestamp | Source file, function, and message (may be truncated) Process name bluetoothd (-d) . -- HCI . D-Bus (D-Bus activity) ( ): = bluetoothd: [:1.21220:method_call] > org.freedesktop.DBus.. 12:34:53.912508 = bluetoothd: [:1.21220:method_return] < [#5] 12:34:53.912546 = bluetoothd: [signal] org.freedesktop.DBus.ObjectManager.I.. 12:36:18.975691 [bus_name:message_type] > () < () . > < D-Bus D-Bus HCI. (Right-Side Metadata) . : Main content (left-aligned, variable width) | Frame # Controller Timestamp | | | | | | | < HCI Command: Reset (0x03|0x0003) plen 0 #5 [hci0] 12:35:01.843185 > HCI Event: Command Complete (0x0e) plen 4 #6 [hci0] 12:35:01.864922 @ MGMT Command: Set Powered (0x0005) plen 1 {0x0001} [hci0] 12:35:04.033564 = Note: Linux version 6.16.0-rc6-0903 (x86_64) 12:34:49.881926 = Open Index: 00:11:22:33:44:55 [hci0] 12:34:49.881933 (Frame number) (#N): HCI. . HCI (< >) -- MGMT (@) (=) . (Controller) ([hciN]): . ( MGMT ) . MGMT (MGMT socket ID) ({0xNNNN}): @ . () . (Timestamp): . : +------------------------+---------------------+-----------------+ | | | | |(Option) | (Format) | (Example) | +------------------------+---------------------+-----------------+ |() | | 0.881932 | | | | | | | | | | | | | +------------------------+---------------------+-----------------+ |-t | | 12:35:01.843185 | | | | | | | (HH:MM:SS.usec) | | +------------------------+---------------------+-----------------+ |-T | | 2026-01-13 | | | | 12:34:49.881926 | | | | | +------------------------+---------------------+-----------------+ (Indented Detail Lines) (payload) . : o ( ): HCI/MGMT o ( ): o (+ ): ( L2CAP ACL ATT L2CAP) ACL: > ACL: Handle 2048 flags 0x02 dlen 11 #497 [hci0] 12:36:19.000048 SMP: Pairing Request (0x01) len 6 <- L2CAP/SMP layer IO capability: NoInputNoOutput (0x03) <- SMP fields OOB data: Authentication data not present (0x00) Authentication requirement: Bonding, MITM, SC (0x2d) Max encryption key size: 16 (Timestamp Notes) btsnoop -t -T (wall-clock time) btsnoop . : o (Live capture) ( btmon): . o btsnoop: btsnoop (epoch) . ( 14:38:46.589000) . . (Frame Numbers vs Line Numbers) btmon (#N) HCI . . btmon grep sed . : o ( + ). o HCI (< >) . MGMT (@) (=) . o (#487) . (Practical Reading Guide) -: < HCI Command: Read BD ADDR (0x04|0x0009) plen 0 #13 [hci0] 12:35:04.057866 > HCI Event: Command Complete (0x0e) plen 10 #14 [hci0] 12:35:04.058750 Read BD ADDR (0x04|0x0009) ncmd 1 Status: Success (0x00) Address: 00:11:22:33:44:55 (OUI Company) : #13 . #14 00:11:22:33:44:55 . 0.9 . MGMT HCI : @ MGMT Command: Set Powered (0x0005) plen 1 {0x0001} [hci0] 12:35:04.033564 Powered: Enabled (0x01) < HCI Command: Reset (0x03|0x0003) plen 0 #7 [hci0] 12:35:04.033907 > HCI Event: Command Complete (0x0e) plen 4 #8 [hci0] 12:35:04.055753 Reset (0x03|0x0003) ncmd 2 Status: Success (0x00) ... (more HCI commands to configure the controller) ... @ MGMT Event: Command Complete (0x0001) plen 7 {0x0001} [hci0] 12:35:04.114789 Set Powered (0x0005) plen 4 Status: Success (0x00) : bluetoothd Set Powered MGMT . HCI ( Reset ) . HCI MGMT Command Complete bluetoothd . : > HCI Event: LE Meta Event (0x3e) plen 31 #487 [hci0] 12:36:18.974201 LE Enhanced Connection Complete (0x0a) Status: Success (0x00) Handle: 2048 Role: Peripheral (0x01) Peer address: AA:BB:CC:DD:EE:FF (OUI Company) @ MGMT Event: Device Connec.. (0x000b) plen 13 {0x0001} [hci0] 12:36:18.974319 = bluetoothd: src/adapter.c:connected_callback() hci0 devic.. 12:36:18.975307 < ACL: Handle 2048 [1.. flags 0x00 dlen 16 #493 [hci0] 12:36:18.977915 LE L2CAP: Connection Parameter Update Request (0x12) ident 1 len 8 < ACL: Handle 2048 [2/6] flags 0x00 dlen 7 #494 [hci0] 12:36:18.978488 ATT: Exchange MTU Request (0x02) len 2 Client RX MTU: 517 : LE ( HCI). MGMT Device Connected . bluetoothd connected_callback() . -- L2CAP ATT MTU ACL. (ANALYZE MODE) -a (--analyze) btsnoop . (Usage) $ btmon -a hcidump.log (Output Contents) : o (Packet counts): HCI ( ACL SCO ISO ). o (Per-connection statistics): : o (BR-ACL, LE-ACL, BR-SCO, BR-ESCO, LE-ISO) o o TX RX o ( ) o ( ) () o (Throughput) (Kb/s) o (Per-channel statistics): L2CAP / /. o (Latency plots): gnuplot (ASCII-art) . (PROTOCOL ERROR CODES) btmon . ATT SMP L2CAP . ATT (ATT Error Codes) ATT PDU Error Response (0x01) . GATT ( Attribute Not Found ) : +----------+---------------------+---------------------------------------+ | | | | +----------+---------------------+---------------------------------------+ |0x01 | Invalid Handle | | | | | (handle) | | | | | | | | | +----------+---------------------+---------------------------------------+ |0x02 | Read Not Permitted | (Characteristic) | | | | | | | | | +----------+---------------------+---------------------------------------+ |0x03 | Write Not Permitted | | | | | | | | | | +----------+---------------------+---------------------------------------+ |0x05 | Authentication | | | | Insufficient | | | | | (bond) | | | | | | | | | | | | ( | | | | MITM) | | | | . | | | | | | | | | | | | SMP | | | | . | +----------+---------------------+---------------------------------------+ |0x06 | Request Not | | | | Supported | ATT | | | | | | | | | +----------+---------------------+---------------------------------------+ |0x07 | Invalid Offset | | | | | / | | | | | | | | (blob) | | | | (attribute) | | | | | +----------+---------------------+---------------------------------------+ |0x08 | Authorization | | | | Insufficient | | | | | (authorization) | | | | | +----------+---------------------+---------------------------------------+ |0x09 | Prepare Queue Full | | | | | | | | | | | | | | | | | | | | | | +----------+---------------------+---------------------------------------+ |0x0a | Attribute Not Found | | | | | | | | | | | | | . | | | | | | | | GATT. | +----------+---------------------+---------------------------------------+ |0x0b | Attribute Not Long | | | | | Read Blob | | | | | +----------+---------------------+---------------------------------------+ |0x0c | Insufficient | | | | Encryption Key Size | | | | | | +----------+---------------------+---------------------------------------+ |0x0d | Invalid Attribute | | | | Value Length | | | | | | | | | | +----------+---------------------+---------------------------------------+ |0x0e | Unlikely Error | | | | | (Generic unlikely | | | | error) | +----------+---------------------+---------------------------------------+ |0x0f | Insufficient | | | | Encryption | | | | | . | | | | | | | | | | | | . | +----------+---------------------+---------------------------------------+ |0x10 | Unsupported Group | | | | Type | | | | | | +----------+---------------------+---------------------------------------+ |0x11 | Insufficient | | | | Resources | | | | | | +----------+---------------------+---------------------------------------+ |0x12 | Value Not Allowed | | | | | | | | | | +----------+---------------------+---------------------------------------+ |0x80-0x9f | Application Error | | | | | | | | | | | | | | | | | / | | | | . | | | | ASCS | | | | | | | | | | | | ASE | | | | . | +----------+---------------------+---------------------------------------+ |0xfc | Write Request | | | | Rejected | (CSIP, ASCS) | +----------+---------------------+---------------------------------------+ |0xfd | CCC Descriptor | CCC | | | Improperly | | | | Configured | | | | | | +----------+---------------------+---------------------------------------+ |0xfe | Procedure Already | | | | in Progress | | | | | | +----------+---------------------+---------------------------------------+ |0xff | Out of Range | | | | | | | | | | +----------+---------------------+---------------------------------------+ L2CAP (L2CAP Connection Response Results) L2CAP LE : +-------+---------------------+--------------------------------+ | | | | | | | | +-------+---------------------+--------------------------------+ |0x0000 | Connection | | | | successful | | | | | | | | | | +-------+---------------------+--------------------------------+ |0x0001 | Connection pending | | | | | | | | | ( BR/EDR) | +-------+---------------------+--------------------------------+ |0x0002 | Connection refused | | | | - PSM not supported | | | | | | | | | | | | | | +-------+---------------------+--------------------------------+ |0x0003 | Connection refused | | | | - security block | | | | | | | | | | +-------+---------------------+--------------------------------+ |0x0004 | Connection refused | | | | - no resources | | | | | | | | | | | | | | | | | | +-------+---------------------+--------------------------------+ |0x0005 | Connection refused | CID | | | - invalid Source | | | | CID | | | | | | | | | | | | | | | | | | +-------+---------------------+--------------------------------+ |0x0006 | Connection refused | CID | | | - Source CID | ( | | | already allocated | | | | | ) | +-------+---------------------+--------------------------------+ |0x0007 | Connection refused | | | | - unacceptable | LE: | | | parameters | | | | | MTU MPS | | | | | | | | | | | | | +-------+---------------------+--------------------------------+ |0x0008 | Connection refused | | | | - invalid | | | | parameters | | | | | | +-------+---------------------+--------------------------------+ |0x0009 | Connection refused | | | | - insufficient | | | | authentication | | +-------+---------------------+--------------------------------+ |0x000a | Connection refused | | | | - insufficient | | | | authorization | | | | | | +-------+---------------------+--------------------------------+ |0x000b | Connection refused | | | | - insufficient | | | | encryption key size | | | | | | +-------+---------------------+--------------------------------+ |0x000c | Connection refused | | | | - insufficient | | | | encryption | | +-------+---------------------+--------------------------------+ (Automating Error Detection) ATT ( ): grep -n "Error Response" output.txt Attribute Not Found (0x0a) () (). /: grep -n "Authentication Insufficient\|Insufficient Encryption\|Insufficient Security\|security block" output.txt . SMP . L2CAP: grep -n "Connection refused" output.txt (Cross-layer error correlation): . : 1. ATT Insufficient Encryption (0x0f) -> HCI LE Start Encryption -> Encryption Change -> ATT 2. ATT Authentication Insufficient (0x05) -> SMP Pairing Request -> -> ATT 3. SMP Pairing Failed -> Disconnect Complete Authentication Failure (0x05) 4. L2CAP Connection refused - security block -> SMP (PROTOCOL FLOWS) HCI (HCI INITIALIZATION SEQUENCE) btsnoop HCI . net/bluetooth/hci_sync.c . . (Overview) HCI . HCI . : hci_power_on_sync hci_dev_open_sync hci_dev_init_sync hci_dev_setup_sync (driver setup + quirks) hci_init_sync Stage 1: Reset + identity Stage 2: Capabilities + buffer sizes Stage 3: Event masks + policy Stage 4: Final configuration (hci_powered_update_sync) SSP (advertising) (scan) . ( BD ) . : ( ) (Stage 0: Reset and Basic Identity (Unconfigured Only)) (setup) . : +-----------------------------------+---------------------------------------------------------+ | HCI | | +-----------------------------------+---------------------------------------------------------+ |HCI_Reset | | | | ( | | | | | | RESET_ON_CLOSE | | | ) | +-----------------------------------+---------------------------------------------------------+ |HCI_Read_Local_Version_Information | | | | / | +-----------------------------------+---------------------------------------------------------+ |HCI_Read_BD_ADDR | | | | | +-----------------------------------+---------------------------------------------------------+ : (Stage 1: Reset and Read Local Features) . : +-----------------------------------+-----------------------------------+ | HCI | | +-----------------------------------+-----------------------------------+ |HCI_Reset | | | | | +-----------------------------------+-----------------------------------+ |HCI_Read_Local_Supported_Features | | | | | | | LMP | | | ( BR/EDR LE SSP | | | ) | +-----------------------------------+-----------------------------------+ |HCI_Read_Local_Version_Information | | | | HCI LMP | | | | +-----------------------------------+-----------------------------------+ |HCI_Read_BD_ADDR | | | | | | | | +-----------------------------------+-----------------------------------+ : (Stage 2: Read Capabilities and Setup) . : BR/EDR LE. (Common Commands) +-----------------------------------------------+--------------------------------------+ | HCI | | +-----------------------------------------------+--------------------------------------+ |HCI_Read_Local_Supported_Commands | | | | | | | | | | | | | (HCI 1.2 ) | +-----------------------------------------------+--------------------------------------+ |HCI_Write_Simple_Pairing_Mode (enable) | SSP | | | | | | | | | | +-----------------------------------------------+--------------------------------------+ |HCI_Write_Extended_Inquiry_Response (clear) | | | | EIR | | | | | | SSP | +-----------------------------------------------+--------------------------------------+ |HCI_Write_Inquiry_Mode | | | | (RSSI | | | Extended | | | ) | +-----------------------------------------------+--------------------------------------+ |HCI_Read_Inquiry_Response_Transmit_Power_Level | | | | | | | (TX) | | | | | | | +-----------------------------------------------+--------------------------------------+ |HCI_Read_Local_Extended_Features (page 1) | | | | | | | | | | ( SSP | | | LE | | | ) | +-----------------------------------------------+--------------------------------------+ |HCI_Write_Authentication_Enable | | | | | | | | | | LINK_SECURITY | +-----------------------------------------------+--------------------------------------+ BR/EDR ( BR/EDR) (BR/EDR Commands) +------------------------------------------+--------------------------------------+ | HCI | | +------------------------------------------+--------------------------------------+ |HCI_Read_Buffer_Size | | | | | | | | | | ACL/SCO | +------------------------------------------+--------------------------------------+ |HCI_Read_Class_of_Device | | | | | +------------------------------------------+--------------------------------------+ |HCI_Read_Local_Name | | | | | | | | +------------------------------------------+--------------------------------------+ |HCI_Read_Voice_Setting | | | | | | | SCO ( | | | ) | +------------------------------------------+--------------------------------------+ |HCI_Read_Number_of_Supported_IAC | | | | | | | (IAC) | | | | +------------------------------------------+--------------------------------------+ |HCI_Read_Current_IAC_LAP | | | | IAC | | | LAP | +------------------------------------------+--------------------------------------+ |HCI_Set_Event_Filter (clear all) | | | | | | | | | | | +------------------------------------------+--------------------------------------+ |HCI_Write_Connection_Accept_Timeout | | | | | | | ( | | | ) | +------------------------------------------+--------------------------------------+ |HCI_Write_Synchronous_Flow_Control_Enable | | | | SCO | | | | | | | +------------------------------------------+--------------------------------------+ LE ( LE) (LE Commands) +-------------------------------------+-----------------------------------+ | HCI | | +-------------------------------------+-----------------------------------+ |LE_Read_Local_Supported_Features | | | | | | | LE | +-------------------------------------+-----------------------------------+ |LE_Read_All_Local_Supported_Features | | | | | | | | | | LE ( | | | ) | +-------------------------------------+-----------------------------------+ |LE_Read_Buffer_Size [v2] or [v1] | | | | | | | LE ACL ( ISO) | | | v2 | | | | | | | | | ISO | | | | +-------------------------------------+-----------------------------------+ |LE_Read_Supported_States | | | | | | | LE | +-------------------------------------+-----------------------------------+ : (Stage 3: Event Masks, Link Policy, and Features) . . (Event Masks and Link Policy) +------------------------------------------+-----------------------------------+ | HCI | | +------------------------------------------+-----------------------------------+ |HCI_Set_Event_Mask | | | | | | | | | | | | | | +------------------------------------------+-----------------------------------+ |HCI_Read_Stored_Link_Key | | | | | | | | | | | +------------------------------------------+-----------------------------------+ |HCI_Write_Default_Link_Policy_Settings | | | | | | | hold | | | sniff park | | | | | | LMP | +------------------------------------------+-----------------------------------+ |HCI_Read_Page_Scan_Activity | | | | | | | | | | | +------------------------------------------+-----------------------------------+ |HCI_Read_Default_Erroneous_Data_Reporting | | | | | | | | | | ( | | | | | | ) | +------------------------------------------+-----------------------------------+ |HCI_Read_Page_Scan_Type | | | | | | | ( | | | | | | ) | +------------------------------------------+-----------------------------------+ |HCI_Read_Local_Extended_Features (pages | | |2..N) | | | | | | | | | | | | | | +------------------------------------------+-----------------------------------+ : (RSSI ) SSP ( IO ) sniff subrating - LE . LE . LE (LE Event Mask and Capabilities) +---------------------------------------------+---------------------------------------+ | HCI | | +---------------------------------------------+---------------------------------------+ |LE_Set_Event_Mask | | | | - | | | LE | | | | +---------------------------------------------+---------------------------------------+ |LE_Read_Advertising_Channel_Tx_Power | | | | | | | ( | | | ) | +---------------------------------------------+---------------------------------------+ |LE_Read_Transmit_Power | | | | / | | | | +---------------------------------------------+---------------------------------------+ |LE_Read_Accept_List_Size | | | | | | | | +---------------------------------------------+---------------------------------------+ |LE_Clear_Accept_List | | | | | +---------------------------------------------+---------------------------------------+ |LE_Read_Resolving_List_Size | | | | | | | (LL Privacy) | +---------------------------------------------+---------------------------------------+ |LE_Clear_Resolving_List | | | | | +---------------------------------------------+---------------------------------------+ |LE_Set_Resolvable_Private_Address_Timeout | | | | RPA | +---------------------------------------------+---------------------------------------+ |LE_Read_Maximum_Data_Length | | | | TX/RX | | | ( | | | ) | +---------------------------------------------+---------------------------------------+ |LE_Read_Suggested_Default_Data_Length | | | | | | | | +---------------------------------------------+---------------------------------------+ |LE_Read_Number_of_Supported_Advertising_Sets | | | | | | | | | | | +---------------------------------------------+---------------------------------------+ |HCI_Write_LE_Host_Supported | | | | | | | LE | | | | | | ( | | | ) | +---------------------------------------------+---------------------------------------+ |LE_Set_Host_Feature | CIS | | | Central ( ) / | | | Channel Sounding ( ) | +---------------------------------------------+---------------------------------------+ LE: - LE : ( ) ( ) PHY / CIS ( CIS) // BIG ( BIS) ( CS). : (Stage 4: Final Configuration) : (Secure Connections) PHY LE . (Keys, Codecs, and Secure Connections) +-------------------------------------------+------------------------------------------------------------------+ | HCI | | +-------------------------------------------+------------------------------------------------------------------+ |HCI_Delete_Stored_Link_Key (all) | | | | | | | | +-------------------------------------------+------------------------------------------------------------------+ |HCI_Set_Event_Mask_Page_2 | | | | ( | | | | | | ) | +-------------------------------------------+------------------------------------------------------------------+ |HCI_Read_Local_Supported_Codecs [v2] or | | |[v1] | v2 | | | | | | | +-------------------------------------------+------------------------------------------------------------------+ |HCI_Read_Local_Pairing_Options | | | | | | | ( | | | ) | +-------------------------------------------+------------------------------------------------------------------+ |HCI_Get_MWS_Transport_Layer_Configuration | | | | MWS | | | | +-------------------------------------------+------------------------------------------------------------------+ |HCI_Read_Synchronization_Train_Parameters | | | | (Connectionless Peripheral | | | Broadcast) | +-------------------------------------------+------------------------------------------------------------------+ |HCI_Write_Secure_Connections_Support | | |(enable) | (Secure Connections) | | | SSP | +-------------------------------------------+------------------------------------------------------------------+ |HCI_Write_Default_Erroneous_Data_Reporting | / | | | | | | | +-------------------------------------------+------------------------------------------------------------------+ LE PHY (LE Data Length and PHY Defaults) +---------------------------------------+------------------------------------+ | HCI | | +---------------------------------------+------------------------------------+ |LE_Write_Suggested_Default_Data_Length | | | | / | | | TX | | | | | | | +---------------------------------------+------------------------------------+ |LE_Set_Default_PHY | | | | (PHY) | | | | | | ( 1M 2M | | | Coded | | | ) | +---------------------------------------+------------------------------------+ (Post-Initialization) hci_powered_update_sync : +----------------------------------------------+--------------------------------+ | | | +----------------------------------------------+--------------------------------+ |HCI_Write_Simple_Pairing_Mode | | | | SSP + Secure | | | Connections | | | | | | | +----------------------------------------------+--------------------------------+ |HCI_Write_LE_Host_Supported | | | | | | | | | | LE | +----------------------------------------------+--------------------------------+ | LE | | | | | | | | | | | +----------------------------------------------+--------------------------------+ |HCI_Write_Authentication_Enable | | | | | | | | | | | +----------------------------------------------+--------------------------------+ | | | |///EIR | | | | | | | | | | | | | EIR | +----------------------------------------------+--------------------------------+ |LE_Set_Random_Address | | | | | | | | | | | | | | | | | +----------------------------------------------+--------------------------------+ (Reading the Init Sequence in a Trace) btsnoop . : < HCI Command: Reset > HCI Event: Command Complete (Reset) < HCI Command: Read Local Supported Features > HCI Event: Command Complete (Read Local Supported Features) < HCI Command: Read Local Version Information > HCI Event: Command Complete (Read Local Version Information) < HCI Command: Read BD ADDR > HCI Event: Command Complete (Read BD ADDR) ... [Stage 2-4 commands follow] : o (Missing commands): . LE_Read_Buffer_Size BR/EDR . o (Command failures): Status 0x00 Command Complete . . o (Buffer sizes): Read_Buffer_Size LE_Read_Buffer_Size (in-flight) . (throughput) . o (Feature bits): Read_Local_Supported_Features ( LE SSP eSCO ). -- . o (Event mask): Set_Event_Mask . . o LE (LE-only controllers): BR/EDR ( Read_Buffer_Size Read_Local_Name ) . . o (Vendor commands): (Intel Broadcom Qualcomm Realtek MediaTek) HCI . 0x3F () . (CONNECTION TRACKING) HCI (connection handles) ( ) . . (Handle Types) (controller-specific) . : +-----------------+---------------------+------------------------+ | (Type) | | | | | | (Description) | | | (Creation Event) | | +-----------------+---------------------+------------------------+ |BR/EDR ACL | Connection Complete | | | | | | | | | | | | | | +-----------------+---------------------+------------------------+ |LE ACL | LE (Enhanced) | | | | Connection Complete | | | | | | | | | | | | | (LE) | +-----------------+---------------------+------------------------+ |CIS | LE CIS Established | | | | | | | | | (LE | | | | Audio) | +-----------------+---------------------+------------------------+ |BIS | LE BIG Complete | | | | | | | | | (LE | | | | Audio) | +-----------------+---------------------+------------------------+ |SCO/eSCO | Synchronous | | | | Connection Complete | | | | | / | | | | () | +-----------------+---------------------+------------------------+ . LE Audio LE ACL CIS . LE CIS Established ACL CIS . (Controller Buffer Tracking) : < ACL: Handle 2048 [1/6] flags 0x00 dlen 16 [1/6] ACL . HCI : . Number of Completed Packets . HCI (HCI ERROR AND DISCONNECT REASON CODES) HCI . Status: Reason: . btmon . (Common Disconnect Reasons) +--------------+---------------------+------------------------------------------------------------+ | (Code) | (Name) | (Diagnostic Meaning) | +--------------+---------------------+------------------------------------------------------------+ |0x05 | Authentication | | | | Failure | | | | | . | | | | | | | | | | | | | | | | | | | | . | +--------------+---------------------+------------------------------------------------------------+ |0x08 | Connection Timeout | (supervision timer) | | | | . | | | | | | | | . | | | | | | | | (RF) . | +--------------+---------------------+------------------------------------------------------------+ |0x13 | Remote User | | | | Terminated | . | | | Connection | | | | | (graceful) . | +--------------+---------------------+------------------------------------------------------------+ |0x14 | Remote Device | | | | Terminated due to | ( | | | Low Resources | ) . | +--------------+---------------------+------------------------------------------------------------+ |0x15 | Remote Device | | | | Terminated due to | . | | | Power Off | | +--------------+---------------------+------------------------------------------------------------+ |0x16 | Connection | BlueZ | | | Terminated By Local | . | | | Host | bluetoothd | | | | | | | | . | +--------------+---------------------+------------------------------------------------------------+ |0x1f | Unspecified Error | . | | | | | | | | / | | | | (firmware) . | +--------------+---------------------+------------------------------------------------------------+ |0x22 | LMP/LL Response | | | | Timeout | (Link Layer) | | | | . | | | | PDU | | | | LL . | +--------------+---------------------+------------------------------------------------------------+ |0x28 | Instant Passed | | | | | . | | | | | | | | | | | | | | | | . | +--------------+---------------------+------------------------------------------------------------+ |0x2f | Insufficient | | | | Security | ( MITM) | | | | . | +--------------+---------------------+------------------------------------------------------------+ |0x3b | Unacceptable | | | | Connection | | | | Parameters | | | | | . | +--------------+---------------------+------------------------------------------------------------+ |0x3d | Connection | | | | Terminated due to | (MIC) | | | MIC Failure | . | | | | . | +--------------+---------------------+------------------------------------------------------------+ |0x3e | Connection Failed | | | | to be Established | | | | | ( | | | | | | | | | | | | ). | +--------------+---------------------+------------------------------------------------------------+ |0x3f | MAC Connection | MAC. | | | Failed | | +--------------+---------------------+------------------------------------------------------------+ |0x44 | Operation Cancelled | | | | by Host | . | +--------------+---------------------+------------------------------------------------------------+ (Full Error Code Table) HCI ( 0x00 0x45) (Bluetooth Core Specification) F . btmon Status: Reason: . monitor/packet.c (error2str_table) . GATT SNOOP (RECONSTRUCTING A GATT DATABASE FROM SNOOP TRACES) btsnoop ATT GATT . GATT -- -- . GATT ATT btmon . GATT (Overview of GATT Discovery) GATT ATT / (attribute) . : 1. (Primary Service Discovery) -- . 2. (Secondary Service Discovery) -- ( ). 3. (Included Service Discovery) -- . 4. (Characteristic Discovery) -- . 5. (Descriptor Discovery) -- . 6. (Characteristic Value Reading) -- . ATT / . Attribute Not Found . : ( ) (Phase 1: Primary Service Discovery (Read By Group Type)) Read By Group Type Request UUID Primary Service ( 0x2800) . (Request): < ACL Data TX: Handle 2048 flags 0x00 dlen 11 #516 [hci0] 0.124726 ATT: Read By Group Type Request (0x10) len 6 Handle range: 0x0001-0xffff Attribute group type: Primary Service (0x2800) 0x0001 0xffff ( ) . (Response): > ACL Data RX: Handle 2048 flags 0x02 dlen 42 #523 [hci0] 0.240151 ATT: Read By Group Type Response (0x11) len 37 Attribute data length: 6 Attribute group list: 6 entries Handle range: 0x0001-0x0009 UUID: Generic Access Profile (0x1800) Handle range: 0x000a-0x0011 UUID: Generic Attribute Profile (0x1801) Handle range: 0x0012-0x0014 UUID: Device Information (0x180a) Handle range: 0x0015-0x0039 UUID: Generic Telephony Bearer (0x184c) Handle range: 0x003a-0x0059 UUID: Generic Media Control (0x1849) Handle range: 0x005a-0x005c UUID: Telephony and Media Audio (0x1855) : o (Handle range) -- . / ( ) . o UUID -- . UUID ( Generic Access Profile). (vendor-specific) UUID . : < ACL Data TX: Handle 2048 flags 0x00 dlen 11 #525 [hci0] 0.240641 ATT: Read By Group Type Request (0x10) len 6 Handle range: 0x005d-0xffff Attribute group type: Primary Service (0x2800) Attribute Not Found : > ACL Data RX: Handle 2048 flags 0x02 dlen 9 #532 [hci0] 0.360069 ATT: Error Response (0x01) len 4 Read By Group Type Request (0x10) Handle: 0x005d Error: Attribute Not Found (0x0a) 0x005d . . : Attribute data length . UUID ( + + UUID). UUID ( + + ). . : (Phase 2: Secondary Service Discovery) Read By Group Type Request UUID Secondary Service ( 0x2801) : < ACL Data TX: Handle 2048 flags 0x00 dlen 11 #534 [hci0] 0.360752 ATT: Read By Group Type Request (0x10) len 6 Handle range: 0x0001-0xffff Attribute group type: Secondary Service (0x2801) Attribute Not Found . -- (include) . : ( ) (Phase 3: Included Service Discovery (Read By Type)) Read By Type Request UUID Include ( 0x2802) : < ACL Data TX: Handle 2048 flags 0x00 dlen 11 #540 [hci0] 0.480731 ATT: Read By Type Request (0x08) len 6 Handle range: 0x0001-0x005c Attribute type: Include (0x2802) . (include declaration) . : ( ) (Phase 4: Characteristic Discovery (Read By Type)) Read By Type Request UUID Characteristic ( 0x2803) . . (Request): > ACL Data RX: Handle 2048 flags 0x02 dlen 11 #531 [hci0] 0.360063 ATT: Read By Type Request (0x08) len 6 Handle range: 0x0008-0x0011 Attribute type: Characteristic (0x2803) (Response): < ACL Data TX: Handle 2048 flags 0x00 dlen 27 #533 [hci0] 0.360714 ATT: Read By Type Response (0x09) len 22 Attribute data length: 7 Attribute data list: 3 entries Handle: 0x0009 Value[5]: 200a00052a Properties: 0x20 Indicate (0x20) Value Handle: 0x000a Value UUID: Service Changed (0x2a05) Handle: 0x000c Value[5]: 0a0d00292b Properties: 0x0a Read (0x02) Write (0x08) Value Handle: 0x000d Value UUID: Client Supported Features (0x2b29) Handle: 0x000e Value[5]: 020f002a2b Properties: 0x02 Read (0x02) Value Handle: 0x000f Value UUID: Database Hash (0x2b2a) : o Handle -- (characteristic declaration attribute). o Properties -- (bitmask) : +----------------+---------------------+-----------------------------------+ | (Bit) | | | | | (Property) | (Description) | +----------------+---------------------+-----------------------------------+ |0x01 | Broadcast | | | | | | | | | | | | | (advertising) | | | | | +----------------+---------------------+-----------------------------------+ |0x02 | Read | | | | | | +----------------+---------------------+-----------------------------------+ |0x04 | Write Without | | | | Response | | | | | | | | | | +----------------+---------------------+-----------------------------------+ |0x08 | Write | | | | | | | | | | | | | | +----------------+---------------------+-----------------------------------+ |0x10 | Notify | | | | | | | | | | | | | (notifications) | | | | | +----------------+---------------------+-----------------------------------+ |0x20 | Indicate | | | | | | | | | | | | | (indications) | | | | | +----------------+---------------------+-----------------------------------+ |0x40 | Authenticated | | | | Signed Writes | | | | | | | | | | | | | | +----------------+---------------------+-----------------------------------+ |0x80 | Extended Properties | | | | | | | | | | | | | | | | | | +----------------+---------------------+-----------------------------------+ o Value Handle -- ( + ). o Value UUID -- UUID . Attribute Not Found : > ACL Data RX: Handle 2048 flags 0x02 dlen 9 #572 [hci0] 1.200228 ATT: Error Response (0x01) len 4 Read By Type Request (0x08) Handle: 0x005c Error: Attribute Not Found (0x0a) : ( ) (Phase 5: Descriptor Discovery (Find Information)) ( ) . Find Information Request . (Request): > ACL Data RX: Handle 2048 flags 0x02 dlen 9 #556 [hci0] 0.959965 ATT: Find Information Request (0x04) len 4 Handle range: 0x000b-0x000b . (Response): < ACL Data TX: Handle 2048 flags 0x00 dlen 10 #561 [hci0] 0.961049 ATT: Find Information Response (0x05) len 5 Format: UUID-16 (0x01) Handle: 0x000b UUID: Client Characteristic Configuration (0x2902) (Descriptor UUIDs): +-------+---------------------+---------------------------------------------------+ |UUID | (Name) | / (Purpose) | +-------+---------------------+---------------------------------------------------+ |0x2900 | Characteristic | | | | Extended Properties | | +-------+---------------------+---------------------------------------------------+ |0x2901 | Characteristic User | | | | Description | | +-------+---------------------+---------------------------------------------------+ |0x2902 | Client | / | | | Characteristic | | | | Configuration (CCC) | | +-------+---------------------+---------------------------------------------------+ |0x2903 | Server | | | | Characteristic | | | | Configuration | | +-------+---------------------+---------------------------------------------------+ |0x2904 | Characteristic | | | | Presentation Format | | +-------+---------------------+---------------------------------------------------+ : (Phase 6: Reading Characteristic Values) Read Request : > ACL Data RX: Handle 2048 flags 0x02 dlen 7 #577 [hci0] 1.380203 ATT: Read Request (0x0a) len 2 Handle: 0x000f < ACL Data TX: Handle 2048 flags 0x00 dlen 21 #579 [hci0] 1.380774 ATT: Read Response (0x0b) len 16 Value[16]: a470d508da8751a2a50b79da0250bfda Handle . btmon UUID . ( ) (Find By Type Value (Targeted Service Search)) Find By Type Value Request UUID : > ACL Data RX: Handle 2048 flags 0x02 dlen 13 #513 [hci0] 0.124195 ATT: Find By Type Value Request (0x06) len 8 Handle range: 0x0001-0xffff Attribute type: Primary Service (0x2800) UUID: Generic Attribute Profile (0x1801) < ACL Data TX: Handle 2048 flags 0x00 dlen 9 #515 [hci0] 0.124684 ATT: Find By Type Value Response (0x07) len 4 Handle range: 0x0008-0x0011 . : < ACL Data TX: Handle 2048 flags 0x00 dlen 9 #524 [hci0] 0.240607 ATT: Error Response (0x01) len 4 Find By Type Value Request (0x06) Handle: 0x0012 Error: Attribute Not Found (0x0a) (Bidirectional Discovery) GATT . btsnoop : o TX (``<``) + RX (``>``) -- ( ) GATT . o RX (``>``) + TX (``<``) -- GATT . : > ACL Data RX: Handle 2048 flags 0x02 dlen 11 #584 [hci0] 1.512006 ATT: Read By Group Type Request (0x10) len 6 Handle range: 0x0001-0xffff Attribute group type: Primary Service (0x2800) < ACL Data TX: Handle 2048 flags 0x00 dlen 66 #586 [hci0] 1.518778 ATT: Read By Group Type Response (0x11) len 61 Attribute data length: 6 Attribute group list: 10 entries Handle range: 0x0001-0x0007 UUID: Generic Access Profile (0x1800) Handle range: 0x0008-0x0011 UUID: Generic Attribute Profile (0x1801) Handle range: 0x0012-0x0014 UUID: Device Information (0x180a) Handle range: 0x0015-0x001e UUID: Coordinated Set Identification (0x1846) Handle range: 0x001f-0x0020 UUID: Common Audio (0x1853) Handle range: 0x0021-0x0024 UUID: Microphone Control (0x184d) Handle range: 0x0041-0x004b UUID: Volume Control (0x1844) Handle range: 0x006b-0x0073 UUID: Broadcast Audio Scan (0x184f) Handle range: 0x0074-0x0086 UUID: Published Audio Capabilities (0x1850) Handle range: 0x0087-0x0096 UUID: Audio Stream Control (0x184e) GATT . TX RX ( ). (Building the Attribute Table) GATT . 00:11:22:33:44:55 : (Services) ( Read By Group Type Response): Handle Range UUID Service Name 0x0001-0x0009 0x1800 Generic Access Profile 0x000a-0x0011 0x1801 Generic Attribute Profile 0x0012-0x0014 0x180a Device Information 0x0015-0x0039 0x184c Generic Telephony Bearer 0x003a-0x0059 0x1849 Generic Media Control 0x005a-0x005c 0x1855 Telephony and Media Audio (Characteristics) ( Read By Type Response GAP 0x0001-0x0009): Handle Value Handle Properties UUID Name 0x0002 0x0003 Read 0x2a00 Device Name 0x0004 0x0005 Read 0x2a01 Appearance 0x0006 0x0007 Read 0x2a04 Peripheral Preferred Conn Params 0x0008 0x0009 Read 0x2aa6 Central Address Resolution (Characteristics) ( GATT 0x000a-0x0011): Handle Value Handle Properties UUID Name 0x000b 0x000c Indicate 0x2a05 Service Changed 0x000e 0x000f Read, Write 0x2b29 Client Supported Features 0x0010 0x0011 Read 0x2b2a Database Hash (Descriptors) ( Find Information Response): Handle UUID Name 0x000d 0x2902 Client Characteristic Configuration CCC 0x000d Service Changed ( 0x000c) 0x000e . SMP (SMP PAIRING FLOW) (SMP Security Manager Protocol) . SMP L2CAP (CID) 0x0006 ( LE) CID 0x0007 ( BR/EDR) . btmon SMP . (Pairing Phases) SMP . btmon . : (Phase 1: Feature Exchange) (Security Request) ( / peripheral) . (Pairing Request) (Pairing Response) : > ACL Data RX: Handle 2048 flags 0x02 dlen 11 #497 [hci0] 0.026107 SMP: Pairing Request (0x01) len 6 IO capability: NoInputNoOutput (0x03) OOB data: Authentication data not present (0x00) Authentication requirement: Bonding, MITM, SC, CT2 (0x2d) Max encryption key size: 16 Initiator key distribution: IdKey Sign (0x06) Responder key distribution: IdKey Sign (0x06) < ACL Data TX: Handle 2048 flags 0x00 dlen 11 #499 [hci0] 0.026894 SMP: Pairing Response (0x02) len 6 IO capability: KeyboardDisplay (0x04) OOB data: Authentication data not present (0x00) Authentication requirement: Bonding, SC, CT2 (0x29) Max encryption key size: 16 Initiator key distribution: IdKey (0x02) Responder key distribution: IdKey (0x02) : o Authentication requirement -- SC (Secure Connections) . (Legacy Pairing) . o IO capability -- (Just Works Passkey Entry Numeric Comparison OOB) . o Key distribution -- . IdKey = (IRK) EncKey = (LTK ) Sign = CSRK. : ( - Secure Connections) ( SC) confirm/random : > ACL Data RX: Handle 2048 flags 0x02 dlen 69 #501 [hci0] 0.098224 SMP: Pairing Public Key (0x0c) len 64 X: 1a2b3c4d... Y: 5e6f7a8b... < ACL Data TX: Handle 2048 flags 0x00 dlen 69 #503 [hci0] 0.148556 SMP: Pairing Public Key (0x0c) len 64 X: 9c8d7e6f... Y: 0a1b2c3d... < ACL Data TX: Handle 2048 flags 0x00 dlen 21 #505 [hci0] 0.149003 SMP: Pairing Confirm (0x03) len 16 Confirm value: a1b2c3d4e5f6... > ACL Data RX: Handle 2048 flags 0x02 dlen 21 #507 [hci0] 0.212884 SMP: Pairing Random (0x04) len 16 Random value: 1122334455... < ACL Data TX: Handle 2048 flags 0x00 dlen 21 #509 [hci0] 0.213100 SMP: Pairing Random (0x04) len 16 Random value: 6677889900... > ACL Data RX: Handle 2048 flags 0x02 dlen 21 #511 [hci0] 0.278003 SMP: Pairing DHKey Check (0x0d) len 16 E: aabbccddee... < ACL Data TX: Handle 2048 flags 0x00 dlen 21 #513 [hci0] 0.278450 SMP: Pairing DHKey Check (0x0d) len 16 E: ffeeddccbb... DHKey HCI : < HCI Command: LE Start Encryption (0x08|0x0019) plen 28 #515 [hci0] 0.279002 > HCI Event: Encryption Change (0x08) plen 4 #517 [hci0] 0.342556 Status: Success (0x00) Handle: 2048 Encryption: Enabled with AES-CCM (0x01) : ( - Legacy Pairing) ( SC) DHKey . Confirm Random : < ACL Data TX: Handle 2048 flags 0x00 dlen 21 #501 [hci0] 0.098224 SMP: Pairing Confirm (0x03) len 16 Confirm value: ... > ACL Data RX: Handle 2048 flags 0x02 dlen 21 #503 [hci0] 0.162556 SMP: Pairing Confirm (0x03) len 16 Confirm value: ... < ACL Data TX: Handle 2048 flags 0x00 dlen 21 #505 [hci0] 0.163003 SMP: Pairing Random (0x04) len 16 Random value: ... > ACL Data RX: Handle 2048 flags 0x02 dlen 21 #507 [hci0] 0.228884 SMP: Pairing Random (0x04) len 16 Random value: ... : (Phase 3: Key Distribution) : > ACL Data RX: Handle 2048 flags 0x02 dlen 21 #519 [hci0] 0.343002 SMP: Identity Information (0x08) len 16 Identity resolving key: 00112233445566778899aabbccddeeff > ACL Data RX: Handle 2048 flags 0x02 dlen 12 #521 [hci0] 0.343556 SMP: Identity Address Information (0x09) len 7 Address type: Public (0x00) Address: 00:11:22:33:44:55 Identity Address Information ( ). (Legacy Pairing) LTK : > ACL Data RX: Handle 2048 flags 0x02 dlen 21 #519 [hci0] 0.343002 SMP: Encryption Information (0x06) len 16 Long term key: 00112233... > ACL Data RX: Handle 2048 flags 0x02 dlen 15 #521 [hci0] 0.343556 SMP: Central Identification (0x07) len 10 EDIV: 0x1234 Rand: 0x0123456789abcdef (Pairing Failure) PDU Pairing Failed : > ACL Data RX: Handle 2048 flags 0x02 dlen 6 #505 [hci0] 0.213002 SMP: Pairing Failed (0x05) len 1 Reason: Authentication requirements (0x03) SMP: +-------+---------------------+-----------------------------------+ | | | | | | (Reason) | | +-------+---------------------+-----------------------------------+ |0x01 | Passkey Entry | | | | Failed | | | | | | | | | | | | | (passkey) | | | | | +-------+---------------------+-----------------------------------+ |0x02 | OOB Not Available | OOB | | | | | | | | | | | | | +-------+---------------------+-----------------------------------+ |0x03 | Authentication | | | | Requirements | | | | | | | | | | | | | | | | | ( | | | | | | | | MITM | | | | IO | | | | Just Works | | | | | | | | ) | +-------+---------------------+-----------------------------------+ |0x04 | Confirm Value | | | | Failed | | | | | | | | | | | | | MITM | +-------+---------------------+-----------------------------------+ |0x05 | Pairing Not | | | | Supported | | | | | | | | | | | | | | +-------+---------------------+-----------------------------------+ |0x06 | Encryption Key Size | | | | | | | | | | | | | | +-------+---------------------+-----------------------------------+ |0x07 | Command Not | | | | Supported | SMP | | | | | +-------+---------------------+-----------------------------------+ |0x08 | Unspecified Reason | | | | | | +-------+---------------------+-----------------------------------+ |0x09 | Repeated Attempts | | | | | | | | | | | | | (Rate-limited) | | | | | | | | | | | | | +-------+---------------------+-----------------------------------+ |0x0a | Invalid Parameters | | | | | | | | | SMP | +-------+---------------------+-----------------------------------+ |0x0b | DHKey Check Failed | ECDH | | | | | | | | ( SC) | +-------+---------------------+-----------------------------------+ |0x0c | Numeric Comparison | | | | Failed | | | | | (Numeric Comparison) | | | | | +-------+---------------------+-----------------------------------+ |0x0d | BR/EDR Pairing In | | | | Progress | | | | | | | | | | | | | | +-------+---------------------+-----------------------------------+ |0x0e | Cross-Transport Key | | | | Derivation Not | | | | Allowed | (CTKD) | | | | | +-------+---------------------+-----------------------------------+ (Automating Pairing Analysis) : grep -n "Pairing Request\|Pairing Response\|Pairing Failed\|Pairing Public Key\|DHKey Check" output.txt ( ): o Pairing Public Key Request/Response Confirm : (Secure Connections). o Request/Response Confirm/Random : (Legacy Pairing). o Authentication requirement SC . : grep -n "Pairing Failed" output.txt : Encryption Change Status: Success . : grep -n "Encryption Change\|Encryption:" output.txt : (bonded) Encryption Change SMP ( ) . SMP Pairing Request . : 1. Pairing Request -- handle IO 2. Pairing Response -- IO (association model) 3. Pairing Failed -- 4. Encryption Change Status: Success -- 5. Identity Address Information -- L2CAP (L2CAP CHANNEL TRACKING) L2CAP (Logical Link Control and Adaptation Protocol) ACL () . btmon L2CAP . (Fixed Channels) (CID) : +-------+--------------------+---------------------------------+ |CID | | | +-------+--------------------+---------------------------------+ |0x0001 | L2CAP Signaling | | | | (BR/EDR) | | | | | | | | | | +-------+--------------------+---------------------------------+ |0x0002 | Connectionless | | | | Reception | | | | | L2CAP | +-------+--------------------+---------------------------------+ |0x0003 | AMP Manager | AMP (Alternate | | | | MAC/PHY) | +-------+--------------------+---------------------------------+ |0x0004 | ATT | | | | | | | | | ( | | | | GATT) | +-------+--------------------+---------------------------------+ |0x0005 | L2CAP Signaling | | | | (LE) | | | | | LE | +-------+--------------------+---------------------------------+ |0x0006 | SMP (LE) | | | | | | | | | (Security | | | | Manager Protocol) | +-------+--------------------+---------------------------------+ |0x0007 | SMP (BR/EDR) | | | | | | | | | | | | | | +-------+--------------------+---------------------------------+ btmon L2CAP . ATT CID 0x0004 : < ACL Data TX: Handle 2048 flags 0x00 dlen 7 #494 [hci0] 0.004488 ATT: Exchange MTU Request (0x02) len 2 Client RX MTU: 517 (BR/EDR) (Dynamic Channels (BR/EDR)) L2CAP CID 0x0001 . PSM (Protocol/Service Multiplexer) . : > ACL Data RX: Handle 256 flags 0x02 dlen 16 #142 [hci0] 2.034556 L2CAP: Connection Request (0x02) ident 3 len 4 PSM: 25 (0x0019) Source CID: 0x0040 < ACL Data TX: Handle 256 flags 0x00 dlen 20 #144 [hci0] 2.035002 L2CAP: Connection Response (0x03) ident 3 len 8 Destination CID: 0x0041 Source CID: 0x0040 Result: Connection successful (0x0000) Status: No further information available (0x0000) : > ACL Data RX: Handle 256 flags 0x02 dlen 20 #146 [hci0] 2.035556 L2CAP: Configure Request (0x04) ident 4 len 8 Destination CID: 0x0041 Flags: 0x0000 Option: MTU (0x01) [2] MTU: 1024 < ACL Data TX: Handle 256 flags 0x00 dlen 18 #148 [hci0] 2.036003 L2CAP: Configure Response (0x05) ident 4 len 6 Source CID: 0x0040 Flags: 0x0000 Result: Success (0x0000) PSM : +-------+--------------------+-----------------------------------+ |PSM | | | +-------+--------------------+-----------------------------------+ |0x0001 | SDP | | | | | (Service | | | | Discovery Protocol) | +-------+--------------------+-----------------------------------+ |0x0003 | RFCOMM | | | | | | | | | (SPP HFP ) | +-------+--------------------+-----------------------------------+ |0x000f | BNEP | | | | | | | | | | | | | (Bluetooth Network Encapsulation | | | | Protocol) | +-------+--------------------+-----------------------------------+ |0x0017 | AVCTP | | | | | | | | | / | | | | (AVRCP) | +-------+--------------------+-----------------------------------+ |0x0019 | AVDTP | | | | | | | | | / | | | | (A2DP) | +-------+--------------------+-----------------------------------+ |0x001b | AVCTP Browsing | | | | | AVRCP | +-------+--------------------+-----------------------------------+ |0x001f | ATT (BR/EDR) | | | | | | | | | | +-------+--------------------+-----------------------------------+ |0x0027 | EATT | | | | | | | | | (Enhanced Attribute Protocol) | +-------+--------------------+-----------------------------------+ LE (LE Credit-Based Channels) LE L2CAP CID 0x0005 . LE : < ACL Data TX: Handle 2048 flags 0x00 dlen 18 #600 [hci0] 1.824003 LE L2CAP: LE Connection Request (0x14) ident 1 len 10 PSM: 39 (0x0027) Source CID: 0x0040 MTU: 517 MPS: 251 Credits: 10 > ACL Data RX: Handle 2048 flags 0x02 dlen 18 #602 [hci0] 1.886556 LE L2CAP: LE Connection Response (0x15) ident 1 len 10 Destination CID: 0x0041 MTU: 517 MPS: 251 Credits: 10 Result: Connection successful (0x0000) EATT (Enhanced ATT) PSM 0x0027 LE (bearer) ATT . (Connection Parameter Updates) LE (Peripherals) L2CAP : < ACL Data TX: Handle 2048 flags 0x00 dlen 16 #493 [hci0] 0.003915 LE L2CAP: Connection Parameter Update Request (0x12) ident 1 len 8 Min interval: 24 Max interval: 40 Peripheral latency: 0 Timeout multiplier: 256 > ACL Data RX: Handle 2048 flags 0x02 dlen 10 #495 [hci0] 0.066003 LE L2CAP: Connection Parameter Update Response (0x13) ident 1 len 2 Result: Connection Parameters accepted (0x0000) Connection Parameters rejected (0x0001) . L2CAP (Automating L2CAP Analysis) L2CAP: grep -n "Connection Request\|Connection Response\|LE Connection Request\|LE Connection Response" output.txt PSM ( ): grep -n "PSM:" output.txt : grep -n "Parameter Update Request\|Parameter Update Response\|Parameters rejected" output.txt EATT: grep -n "PSM: 39\|Enhanced Credit" output.txt L2CAP : Source CID Destination CID / (Connection Request/Response) . CID . (Throughput Estimation) --analyze (-a) btmon . L2CAP : o Speed: bytes * 8 / latency_sum_ms latency_sum_ms ( / wall-clock) . . o Min/Avg/Max latency: (inter-arrival time). : Found TX L2CAP channel with CID 64 PSM 128 (0x0080) Mode: LE Credit MTU: 672 MPS: 490 TX packets: 29120/29114 TX Latency: 1-79 msec (~29 msec) TX size: 494-494 octets (~494 octets) TX speed: ~571 Kb/s analyze: o (CID <= 7) ( ATT L2CAP Signaling (LE)). o PSM . o Mode Configure Request ( BR/EDR) LE ( Basic ERTM LE Credit Enhanced Credit ) . o MTU MPS . : 1. (wall-clock). ( (Credits)) . 2. TX . RX . TX RX . 3. (min/avg/max) btsnoop-analyzer . analyze btmon: btmon -a trace.btsnoop 2>/dev/null | grep -E "speed:|Mode:|MTU:|MPS:|PSM" LE AUDIO (LE AUDIO PROTOCOL FLOW) LE Audio btmon . ATT GATT ( PACS ASCS) CIS/BIG HCI . btmon . PAC ( ) (PAC Discovery) (Audio Streaming) (Published Audio Capabilities Service PACS) . PACS . PAC Sink ( ): < ACL Data TX: Handle 2048 flags 0x00 dlen 7 #550 [hci0] 0.824003 ATT: Read Request (0x0a) len 2 Handle: 0x0075 > ACL Data RX: Handle 2048 flags 0x02 dlen 30 #552 [hci0] 0.886556 ATT: Read Response (0x0b) len 25 Handle: 0x0075 Number of PAC(s): 1 Codec: LC3 (0x06) Codec Specific Capabilities: #0 Sampling Frequency: 8000 Hz 16000 Hz 24000 Hz 32000 Hz 48000 Hz Frame Duration: 7.5 ms 10 ms Audio Channel Counts: 1 Frame Length: 26 - 240 PAC LTV (-- / Length-Type-Value) . : o Codec -- LE Audio LC3 (0x06) o Sampling Frequency -- () o Frame Duration -- (. / ) o Audio Channel Counts -- o Frame Length -- () Audio Locations ( ): > ACL Data RX: Handle 2048 flags 0x02 dlen 9 #554 [hci0] 0.948003 ATT: Read Response (0x0b) len 4 Handle: 0x0077 Location: Front Left Available Audio Contexts ( ): > ACL Data RX: Handle 2048 flags 0x02 dlen 9 #558 [hci0] 1.012556 ATT: Read Response (0x0b) len 4 Handle: 0x007b Sink Context: Media Conversational Source Context: Unspecified ASE (ASE Discovery and State Machine) (Audio Stream Control Service ASCS) ASE ( / Audio Stream Endpoint) . ASE . ASE: Idle Codec Configured QoS Configured Enabling Streaming | Idle Releasing Disabling ASE (ASE Status notification) ( ): > ACL Data RX: Handle 2048 flags 0x02 dlen 20 #580 [hci0] 1.456003 ATT: Handle Value Notification (0x1b) len 15 Handle: 0x0088 ASE ID: 0x01 State: Codec Configured (0x01) Framing: Unframed PDUs supported (0x00) PHY: 0x02 LE 2M PHY (0x02) RTN: 2 Max Transport Latency: 10 Presentation Delay Min: 20000 us Presentation Delay Max: 40000 us Preferred Presentation Delay Min: 20000 us Preferred Presentation Delay Max: 40000 us Codec: LC3 (0x06) Sampling Frequency: 48000 Hz Frame Duration: 10 ms Audio Channel Allocation: Front Left Frame Length: 120 ASE (ASE Control Point operations) . ASE : < ACL Data TX: Handle 2048 flags 0x00 dlen 25 #582 [hci0] 1.518003 ATT: Write Request (0x12) len 20 Handle: 0x008b ASE Control Point: Config Codec (0x01) ASE ID: 0x01 Target Latency: Low Latency (0x01) PHY: LE 2M PHY Codec: LC3 (0x06) Sampling Frequency: 48000 Hz Frame Duration: 10 ms Audio Channel Allocation: Front Left Frame Length: 120 ASE (ASE Control Point): +----------------------+---------------------+--------------------------------+ | | | (Purpose) | | | (Command) | | |(Opcode) | | | +----------------------+---------------------+--------------------------------+ |0x01 | Config Codec | | | | | | | | | | | | | (Idle -> Codec Configured) | +----------------------+---------------------+--------------------------------+ |0x02 | Config QoS | | | | | | | | | CIG/CIS | | | | | | | | | | | | QoS (Codec | | | | Configured -> QoS Configured) | +----------------------+---------------------+--------------------------------+ |0x03 | Enable | | | | | ASE | | | | (QoS | | | | Configured -> Enabling) | +----------------------+---------------------+--------------------------------+ |0x04 | Receiver Start | | | | Ready | | | | | (Enabling | | | | -> Streaming | | | | ) | +----------------------+---------------------+--------------------------------+ |0x05 | Disable | | | | | (Streaming -> | | | | Disabling) | +----------------------+---------------------+--------------------------------+ |0x06 | Receiver Stop Ready | | | | | | +----------------------+---------------------+--------------------------------+ |0x07 | Update Metadata | | | | | | | | | | | | | | +----------------------+---------------------+--------------------------------+ |0x08 | Release | ASE ( | | | | -> | | | | Releasing -> Idle) | +----------------------+---------------------+--------------------------------+ BAP (BAP Unicast Audio Flow) ASE . () ASE Sink ( ) ASE Source ( ) . ASE CIG CIS (Connected Isochronous Streams CIS) . btmon: o Receiver Start Ready ASE Source (ASE ) . . o Receiver Stop Ready ASE Source . o Sink Receiver Start Ready Enabling Streaming . ( ASE CIS): Config Codec ASE ID=1 (Sink) -> Codec Configured Config Codec ASE ID=3 (Source) -> Codec Configured Config QoS ASE ID=1 -> QoS Configured (CIG=X, CIS=Y) Config QoS ASE ID=3 -> QoS Configured (CIG=X, CIS=Y) Enable ASE ID=1 -> Enabling -> Streaming (immediate) Enable ASE ID=3 -> Enabling CIS Established (Success) Setup ISO Data Path Input (Host->Controller, for Sink) Setup ISO Data Path Output (Controller->Host, for Source) Receiver Start Ready ASE ID=3 -> Streaming ASE Streaming . ASE Sink CIS ASE Source Receiver Start Ready . : . ASE Source ASE Sink () . . CIS . ASE . ASE Sink ( ) ASE Source ( ) GATT ASE . CIS (CIS Establishment) (QoS) ASE (Connected Isochronous Streams CIS) HCI . CIG ( CIS): < HCI Command: LE Set CIG Parameters (0x08|0x0062) plen 26 #590 [hci0] 1.624003 CIG ID: 0x00 Central to Peripheral SDU Interval: 10000 us Peripheral to Central SDU Interval: 10000 us SCA: 0x00 Packing: Sequential (0x00) Framing: Unframed (0x00) Central to Peripheral Max Latency: 10 ms Peripheral to Central Max Latency: 10 ms Number of CIS: 1 CIS ID: 0x00 Central to Peripheral Max SDU: 120 Peripheral to Central Max SDU: 0 Central to Peripheral PHY: LE 2M PHY Peripheral to Central PHY: LE 2M PHY Central to Peripheral RTN: 2 Peripheral to Central RTN: 2 > HCI Event: Command Complete (0x0e) plen 8 #592 [hci0] 1.624556 LE Set CIG Parameters (0x08|0x0062) ncmd 1 Status: Success (0x00) CIG ID: 0x00 Number of Handles: 1 Connection Handle: 2064 CIS: < HCI Command: LE Create CIS (0x08|0x0064) plen 9 #594 [hci0] 1.688003 Number of CIS: 1 CIS Handle: 2064 ACL Handle: 2048 > HCI Event: LE Meta Event (0x3e) plen 29 #596 [hci0] 1.756556 LE CIS Established (0x19) Status: Success (0x00) Connection Handle: 2064 CIG Sync Delay: 5000 us CIS Sync Delay: 5000 us Central to Peripheral Latency: 10000 us Peripheral to Central Latency: 10000 us Central to Peripheral PHY: LE 2M PHY Peripheral to Central PHY: LE 2M PHY NSE: 3 Central to Peripheral BN: 1 Peripheral to Central BN: 0 Central to Peripheral FT: 2 Peripheral to Central FT: 2 Max PDU C to P: 120 Max PDU P to C: 0 ISO Interval: 10.00 msec (0x0008) CIS ( 2064) ACL ( 2048) . CIS CIS . ISO (ISO Data Path Setup): < HCI Command: LE Setup ISO Data Path (0x08|0x006e) plen 13 #598 [hci0] 1.820003 Handle: 2064 Data Path Direction: Input (Host to Controller) (0x00) Data Path ID: HCI (0x00) Coding Format: LC3 (0x06) Company ID: 0x0000 Vendor Codec ID: 0x0000 Controller Delay: 0 us ISO CIS : < ISO Data TS: Handle 2064 flags 0x02 dlen 124 #600 [hci0] 1.884003 (BIS / Auracast) (Broadcast Audio (BIS / AURACAST)) (Broadcast Isochronous Streams) CIS (Broadcast Isochronous Group BIG) . BASE ( / Broadcast Audio Source Endpoint) . BASE ( ): > HCI Event: LE Meta Event (0x3e) plen 80 #200 [hci0] 0.500003 LE Periodic Advertising Report (0x0f) ... Service Data: Basic Audio Announcement (0x1851) Presentation Delay: 40000 us Number of Subgroups: 1 Number of BIS: 2 Codec: LC3 (0x06) Sampling Frequency: 48000 Hz Frame Duration: 10 ms Frame Length: 120 BIS #1 Audio Channel Allocation: Front Left BIS #2 Audio Channel Allocation: Front Right BIG ( ): < HCI Command: LE Create BIG (0x08|0x0068) plen 31 #210 [hci0] 0.600003 BIG Handle: 0x00 Advertising Handle: 0x01 Number of BIS: 2 SDU Interval: 10000 us Max SDU: 120 Max Latency: 10 ms RTN: 2 PHY: LE 2M PHY Packing: Sequential (0x00) Framing: Unframed (0x00) Encryption: Unencrypted (0x00) BIG ( ): < HCI Command: LE BIG Create Sync (0x08|0x006b) plen 15 #220 [hci0] 0.700003 BIG Handle: 0x00 Sync Handle: 0x0001 Encryption: Unencrypted (0x00) Number of BIS: 2 BIS: 0x01 BIS: 0x02 BIG (BIG Sync Receiver Flow) (Broadcast Audio) . : 1. (PA) -- . 2. PA BASE -- BASE ( ) . 3. BIG Info -- BIG ( BIS SDU ) . : BIG Info LE BIG Create Sync . 4. LE BIG Create Sync -- . 5. BIG Sync Established -- BIS . 6. ISO (Setup ISO Data Path) -- BIS. 7. ISO -- . . BIG Info ( BIG PA BIG Info ) LE BIG Create Sync . PAST ( PA) (Without PAST (Direct PA Sync)) ( / Broadcast Assistant) : -- PA (Create PA sync): < HCI Command: LE Periodic Advertising Create Sync (0x08|0x0044) plen 14 #100 [hci0] 0.100003 Options: 0x0000 SID: 0x01 Adv Address Type: Public (0x00) Adv Address: XX:XX:XX:XX:XX:XX Skip: 0x0000 Sync Timeout: 2000 msec (0x00c8) Sync CTE Type: 0x0000 -- PA ( ): > HCI Event: LE Meta Event (0x3e) plen 16 #105 [hci0] 0.150003 LE Periodic Advertising Sync Established (0x0e) Status: Success (0x00) Sync Handle: 0x0001 Advertising SID: 0x01 Advertiser Address Type: Public (0x00) Advertiser Address: XX:XX:XX:XX:XX:XX Advertiser PHY: LE 2M PHY (0x02) Periodic Advertising Interval: 10.000 msec (0x0008) Advertiser Clock Accuracy: 0x05 -- PA ( BASE): > HCI Event: LE Meta Event (0x3e) plen 80 #110 [hci0] 0.200003 LE Periodic Advertising Report (0x0f) Sync Handle: 0x0001 ... Service Data: Basic Audio Announcement (0x1851) -- BIG Info ( ): > HCI Event: LE Meta Event (0x3e) plen 24 #120 [hci0] 0.300003 LE BIG Info Advertising Report (0x22) Sync Handle: 0x0001 Number BIS: 2 NSE: 4 ISO Interval: 10.000 msec (0x0008) BN: 2 PTO: 1 IRC: 2 Maximum PDU: 120 SDU Interval: 10000 us Maximum SDU: 120 PHY: LE 2M PHY (0x02) Framing: Unframed (0x00) Encryption: 0x00 BIG Info . BIG . : o Number BIS -- BIS . o SDU Interval Maximum SDU -- . o Encryption -- (Broadcast Code) (0x01) (0x00). LE BIG Create Sync . o Sync Handle -- PA . -- BIG Create Sync ( + BIG Info): < HCI Command: LE BIG Create Sync (0x08|0x006b) plen 15 #130 [hci0] 0.400003 BIG Handle: 0x00 BIG Sync Handle: 0x0001 Encryption: Unencrypted (0x00) Broadcast Code: 00000000000000000000000000000000 Maximum Number Subevents: 0x00 Timeout: 2000 ms (0x00c8) Number of BIS: 2 BIS: 0x01 BIS: 0x02 -- BIG (BIG Sync Established): > HCI Event: LE Meta Event (0x3e) plen 20 #135 [hci0] 0.450003 LE BIG Sync Established (0x1d) Status: Success (0x00) BIG Handle: 0x00 Transport Latency: 10000 us NSE: 4 BN: 2 PTO: 1 IRC: 2 Maximum PDU: 120 ISO Interval: 10.000 msec (0x0008) Connection Handle: 0x0010 Connection Handle: 0x0011 BIS (0x0010 0x0011 ). (Status) -- : o 0x3e ( / Connection Failed to be Established) -- BIG BIG . o 0x3f ( / Limit Reached) -- . -- ISO ( BIS): < HCI Command: LE Setup ISO Data Path (0x08|0x006e) plen 13 #140 [hci0] 0.500003 Connection Handle: 0x0010 Data Path Direction: Output (Controller to Host) (0x01) Data Path ID: HCI (0x00) < HCI Command: LE Setup ISO Data Path (0x08|0x006e) plen 13 #145 [hci0] 0.550003 Connection Handle: 0x0011 Data Path Direction: Output (Controller to Host) (0x01) Data Path ID: HCI (0x00) -- ISO BIS: > ISO Data: Handle 0x0010 flags 0x02 dlen 124 #150 [hci0] 0.600003 > ISO Data: Handle 0x0011 flags 0x02 dlen 124 #151 [hci0] 0.600003 PAST ( ) (With PAST (Periodic Advertising Sync Transfer)) ( ) ( ) PA PAST ACL . PA . BASS ( / Broadcast Audio Scan Service) : 1. Add Source BASS PA Sync 0x01 ( PAST) . 2. PAST . 3. PA . 4. PAST . 5. PAST ( PA -> BIG Info -> BIG Create Sync -> ). BASS Add Source ( ATT): < ACL Data TX: Handle 64 flags 0x00 dlen 27 #300 [hci0] 1.000003 ATT: Write Command (0x52) len 22 Handle: 0x0025 Data: 04... Opcode: Add Source (0x04) Advertiser Address Type: Public (0x00) Advertiser Address: XX:XX:XX:XX:XX:XX Advertising SID: 0x01 PA Sync: Synchronize to PA - PAST (0x01) PA Interval: 0x0008 Number of Subgroups: 1 BIS Sync: 0x00000003 Metadata Length: 0 PA Sync Add Source: o 0x00 -- PA o 0x01 -- PA PAST o 0x02 -- PA PAST ( ) PAST (PAST Parameters) ( ): < HCI Command: LE Periodic Advertising Sync Transfer Parameters (0x08|0x005c) plen 8 #310 [hci0] 1.100003 Connection handle: 64 Mode: Enabled with report events enabled (0x02) Skip: 0x00 Sync timeout: 2000 msec (0x00c8) Sync CTE Type: 0x0000 PAST (PAST Transfer) ( PA ): < HCI Command: LE Periodic Advertising Sync Transfer (0x08|0x005a) plen 6 #320 [hci0] 1.200003 Connection handle: 64 Service data: 0x0001 Sync handle: 1 PAST (PAST Received) ( ): > HCI Event: LE Meta Event (0x3e) plen 19 #325 [hci0] 1.250003 LE Periodic Advertising Sync Transfer Received (0x18) Status: Success (0x00) Handle: 64 Connection handle: 64 Service data: 0x0001 Sync handle: 1 SID: 0x01 Address type: Public (0x00) Address: XX:XX:XX:XX:XX:XX PHY: LE 2M PHY (0x02) Periodic advertising Interval: 10.000 Clock Accuracy: 0x05 PA (Sync handle: 1) PA BIG Info PAST . : (Race condition): PAST Parameters PAST Transfer . BlueZ PA BASS PAST PAST HCI . BIG (BIG Sync Teardown) -- BIG : < HCI Command: LE BIG Terminate Sync (0x08|0x006c) plen 1 #500 [hci0] 5.000003 BIG Handle: 0x00 > HCI Event: Command Complete (0x0e) plen 5 #501 [hci0] 5.001003 LE BIG Terminate Sync (0x08|0x006c) ncmd 1 Status: Success (0x00) BIG Handle: 0x00 -- BIG BIG Sync Lost : > HCI Event: LE Meta Event (0x3e) plen 2 #510 [hci0] 6.000003 LE BIG Sync Lost (0x1e) BIG Handle: 0x00 Reason: Connection Terminated By Local Host (0x16) Reason : o 0x08 ( / Connection Timeout) -- BIG . o 0x13 ( / Remote User Terminated Connection) -- BIG . o 0x16 ( / Connection Terminated By Local Host) -- . o 0x3e ( / Connection Failed to be Established) -- . BIG (Source-side BIG termination) ( ): < HCI Command: LE Terminate BIG (0x08|0x006a) plen 2 #520 [hci0] 7.000003 BIG Handle: 0x00 Reason: Connection Terminated By Local Host (0x16) > HCI Event: LE Meta Event (0x3e) plen 2 #521 [hci0] 7.001003 LE BIG Terminate (0x1c) BIG Handle: 0x00 Reason: Connection Terminated By Local Host (0x16) BIG (BIG Sync Failure Diagnosis) BIG : 1. PA -- LE Periodic Advertising Sync Established Status: Success . PA . 2. PA -- LE Periodic Advertising Report . PA PA . 3. BIG Info -- LE BIG Info Advertising Report . BIG PA . BIG Info LE BIG Create Sync . 4. BIG Create Sync -- BIG Info LE BIG Create Sync BIG Info ( ). 5. BIG Sync Established -- Status . BIG . 6. ISO -- LE Setup ISO Data Path BIS BIG Sync Established . 7. ISO -- ISO Data BIS . LE Audio (Automating LE Audio Analysis) LE Audio: grep -n "ASE Control Point\|ASE ID\|State:.*Codec Configured\|State:.*QoS Configured\|State:.*Enabling\|State:.*Streaming\|State:.*Releasing" output.txt ASE ASE : grep -n "ASE ID:" output.txt State: ASE ID . : grep -n "Codec: LC3\|Sampling Frequency:\|Frame Duration:\|Frame Length:\|Audio Channel" output.txt CIS: grep -n "Set CIG Parameters\|Create CIS\|CIS Established\|Setup ISO Data Path" output.txt CIS -- Status CIS Established: grep -n "CIS Established" output.txt Status: . (): grep -n "Basic Audio Announcement\|Create BIG\|BIG Complete\|BIG Create Sync\|BIG Sync\|BIG Info\|BIG Terminate\|BIG Sync Lost" output.txt BIG -- : grep -n "Periodic Advertising Create Sync\|Periodic Advertising Sync Established\|BIG Info Advertising Report\|BIG Create Sync\|BIG Sync Established\|BIG Sync Lost\|BIG Terminate" output.txt PAST -- : grep -n "Sync Transfer Parameters\|Sync Transfer (0x08\|PAST Received\|PA Sync:.*PAST\|Add Source" output.txt BIG Info -- BIG. BIG : grep -n "BIG Info Advertising Report" output.txt LE Audio: (CIS): 1. PACS -- 2. ASE -- Config Codec -> Config QoS -> Enable 3. ASE -- 4. CIG CIS -- HCI 5. CIS Established -- Status 6. Setup ISO Data Path -- 7. ISO -- 8. ASE ( Response Code Response Reason) (BIG): 1. Periodic Advertising Create Sync PAST Received -- PA 2. Periodic Advertising Sync Established PAST Received Status: Success -- PA 3. Periodic Advertising Report Basic Audio Announcement -- BASE 4. BIG Info Advertising Report -- : BIG BIG . 5. BIG Create Sync -- BIG 6. BIG Sync Established -- Status . 7. Setup ISO Data Path BIS. 8. ISO Data BIS -- . 9. BIG Sync Lost Reason. (CHANNEL SOUNDING PROTOCOL FLOW) (Channel Sounding CS) (Bluetooth LE) . HCI (tones) . btmon CS (step-level) . (CS) : (Initiator) CS (Reflector) . CS ( LE). (Capability Discovery) (CS) CS . (Controller) (over the air) . CS: < HCI Command: LE CS Read Local Supported Capabilities (0x08|0x0089) plen 0 #100 [hci0] > HCI Event: Command Complete (0x0e) plen 42 #101 [hci0] LE CS Read Local Supported Capabilities (0x08|0x0089) ncmd 1 Status: Success (0x00) Num Config Supported: 4 Max Consecutive Procedures Supported: 255 Num Antennas Supported: 2 Max Antenna Paths Supported: 4 Roles Supported: 0x03 Initiator Reflector Modes Supported: 0x03 RTT Capability: 0x03 RTT AA Only N: 10 RTT Sounding N: 10 RTT Random Payload N: 10 CS Sync PHYs Supported: 0x02 LE 2M T_IP1 Times Supported: 0x0005 10 us 30 us T_IP2 Times Supported: 0x0005 10 us 30 us T_FCS Times Supported: 0x0009 15 us 50 us T_PM Times Supported: 0x0003 10 us 20 us : o Roles Supported -- : 0 = (Initiator) 1 = (Reflector). . o Modes Supported -- CS ( = RTT = PBR = ). o CS Sync PHYs -- CS. LE 2M . o Num Antennas / Max Antenna Paths -- (PBR) . o T_IP / T_FCS / T_PM times -- . CS ( LL): < HCI Command: LE CS Read Remote Supported Capabilities (0x08|0x008a) plen 2 #110 [hci0] Handle: 2048 > HCI Event: Command Status (0x0f) plen 4 #111 [hci0] LE CS Read Remote Supported Capabilities (0x08|0x008a) ncmd 1 Status: Success (0x00) > HCI Event: LE Meta Event (0x3e) plen 42 #115 [hci0] LE CS Read Remote Supported Capabilities Complete (0x2c) Status: Success (0x00) Handle: 2048 Num Config Supported: 4 Max Consecutive Procedures Supported: 128 Num Antennas Supported: 1 Max Antenna Paths Supported: 1 Roles Supported: 0x03 Initiator Reflector Modes Supported: 0x03 ... (asynchronous) -- (Command Status) LL . CS . (cached) LE CS Write Cached Remote Supported Capabilities . (Security Enablement) CS . CS LL (nonces) : < HCI Command: LE CS Security Enable (0x08|0x008c) plen 2 #120 [hci0] Handle: 2048 > HCI Event: Command Status (0x0f) plen 4 #121 [hci0] LE CS Security Enable (0x08|0x008c) ncmd 1 Status: Success (0x00) > HCI Event: LE Meta Event (0x3e) plen 3 #125 [hci0] LE CS Security Enable Complete (0x2e) Status: Success (0x00) Handle: 2048 (Security Enable) . CS . (Default Settings) / : < HCI Command: LE CS Set Default Settings (0x08|0x008d) plen 5 #130 [hci0] Handle: 2048 Role Enable: 0x03 Initiator Reflector CS Sync Antenna Selection: 0x01 Max TX Power: 20 > HCI Event: Command Complete (0x0e) plen 5 #131 [hci0] LE CS Set Default Settings (0x08|0x008d) ncmd 1 Status: Success (0x00) Handle: 2048 o Role Enable -- . . o CS Sync Antenna Selection -- CS. o Max TX Power -- CS ( dBm ). FAE (FAE Table Exchange) (FAE Frequency Actuation Error) . . FAE : < HCI Command: LE CS Read Remote FAE Table (0x08|0x008e) plen 2 #135 [hci0] Handle: 2048 > HCI Event: Command Status (0x0f) plen 4 #136 [hci0] LE CS Read Remote FAE Table (0x08|0x008e) ncmd 1 Status: Success (0x00) > HCI Event: LE Meta Event (0x3e) plen 75 #140 [hci0] LE CS Read Remote FAE Table Complete (0x2d) Status: Success (0x00) Handle: 2048 FAE ( ). 0.5 ppm . 0x7f . (CS Configuration) CS : . (config_id 0 3). CS: < HCI Command: LE CS Create Config (0x08|0x0090) plen 20 #150 [hci0] Handle: 2048 Config ID: 0 Create Context: 0x00 Main Mode Type: 0x01 Sub Mode Type: 0xff Min Main Mode Steps: 2 Max Main Mode Steps: 5 Main Mode Repetition: 0 Mode 0 Steps: 3 Role: Initiator (0x00) RTT Type: 0x01 CS Sync PHY: LE 2M (0x01) Channel Map: ffffffffff7f0000000000000000 Channel Map Repetition: 1 Channel Selection Type: 0x00 Ch3c Shape: 0x00 Ch3c Jump: 0x00 > HCI Event: Command Status (0x0f) plen 4 #151 [hci0] LE CS Create Config (0x08|0x0090) ncmd 1 Status: Success (0x00) > HCI Event: LE Meta Event (0x3e) plen 30 #155 [hci0] LE CS Config Complete (0x2f) Status: Success (0x00) Handle: 2048 Config ID: 0 Action: 0x00 Main Mode Type: 0x01 Sub Mode Type: 0xff Min Main Mode Steps: 2 Max Main Mode Steps: 5 Main Mode Repetition: 0 Mode 0 Steps: 3 Role: Initiator (0x00) RTT Type: 0x01 CS Sync PHY: LE 2M (0x01) Channel Map: ffffffffff7f0000000000000000 Channel Map Repetition: 1 Channel Selection Type: 0x00 Ch3c Shape: 0x00 Ch3c Jump: 0x00 T_IP1 Time: 30 us T_IP2 Time: 30 us T_FCS Time: 50 us T_PM Time: 10 us : o Main Mode Type -- CS: 0x01 = ( RTT) 0x02 = ( /PBR) 0x03 = ( RTT + PBR). o Sub Mode Type -- . 0xff = . o Mode 0 Steps -- () . . o Main/Min/Max Mode Steps -- . o Role -- 0x00 = (Initiator) 0x01 = (Reflector). . o RTT Type -- ( AA ). o Channel Map -- CS. . o T_IP1/T_IP2/T_FCS/T_PM -- . Config Complete . Config Complete . . CS: < HCI Command: LE CS Remove Config (0x08|0x0091) plen 3 #160 [hci0] Handle: 2048 Config ID: 0 > HCI Event: Command Status (0x0f) plen 4 #161 [hci0] LE CS Remove Config (0x08|0x0091) ncmd 1 Status: Success (0x00) (Procedure Parameters) : < HCI Command: LE CS Set Procedure Parameters (0x08|0x0093) plen 16 #170 [hci0] Handle: 2048 Config ID: 0 Max Procedure Len: 200 Min Procedure Interval: 10 Max Procedure Interval: 20 Max Procedure Count: 0 Min Subevent Len: 5000 us Max Subevent Len: 10000 us Tone Antenna Config Selection: 0x01 PHY: LE 2M (0x02) TX Power Delta: 0 Preferred Peer Antenna: 0x01 SNR Control Initiator: 0x00 SNR Control Reflector: 0x00 > HCI Event: Command Complete (0x0e) plen 5 #171 [hci0] LE CS Set Procedure Parameters (0x08|0x0093) ncmd 1 Status: Success (0x00) Handle: 2048 o Max Procedure Len -- CS 0.625 . o Procedure Interval -- ( ). o Max Procedure Count -- 0 . o Subevent Len -- ( ). o Tone Antenna Config Selection -- . o SNR Control -- (SNR) . (Procedure Execution) CS / . CS: < HCI Command: LE CS Procedure Enable (0x08|0x0094) plen 4 #180 [hci0] Handle: 2048 Config ID: 0 Enable: 0x01 > HCI Event: Command Status (0x0f) plen 4 #181 [hci0] LE CS Procedure Enable (0x08|0x0094) ncmd 1 Status: Success (0x00) > HCI Event: LE Meta Event (0x3e) plen 20 #185 [hci0] LE CS Procedure Enable Complete (0x30) Status: Success (0x00) Handle: 2048 Config ID: 0 State: 0x01 Tone Antenna Config Selection: 0x01 Selected TX Power: 12 Subevent Len: 5000 us Subevents Per Event: 2 Subevent Interval: 3750 Event Interval: 10 Procedure Interval: 10 Procedure Count: 100 Max Procedure Len: 200 Procedure Enable Complete . : o State -- 0x01 = 0x00 = . o Subevents Per Event -- . o Procedure Count -- ( ). CS: < HCI Command: LE CS Procedure Enable (0x08|0x0094) plen 4 #300 [hci0] Handle: 2048 Config ID: 0 Enable: 0x00 > HCI Event: Command Status (0x0f) plen 4 #301 [hci0] LE CS Procedure Enable (0x08|0x0094) ncmd 1 Status: Success (0x00) > HCI Event: LE Meta Event (0x3e) plen 20 #305 [hci0] LE CS Procedure Enable Complete (0x30) Status: Success (0x00) Handle: 2048 Config ID: 0 State: 0x00 ... (Channel Classification) CS : < HCI Command: LE CS Set Channel Classification (0x08|0x0092) plen 10 #145 [hci0] Channel Map: ffffffffff7f0000000000 > HCI Event: Command Complete (0x0e) plen 1 #146 [hci0] LE CS Set Channel Classification (0x08|0x0092) ncmd 1 Status: Success (0x00) ( ) . N = 1 N CS . . (Schedulability and Subevents) CS (subevent result events) . . (Subevent Result): > HCI Event: LE Meta Event (0x3e) plen 50 #200 [hci0] LE CS Subevent Result (0x31) Handle: 2048 Config ID: 0 Start ACL Conn Event Counter: 1200 Procedure Counter: 0 Frequency Compensation: 0x0000 Reference Power Level: -20 Procedure Done Status: Partial results (0x01) Subevent Done Status: All results complete (0x00) Abort Reason: 0x00 Num Antenna Paths: 1 Num Steps Reported: 8 Step Data: Mode: 0 Channel: 10 Length: 5 Packet Quality: 0x00 Packet RSSI: -45 Packet Antenna: 0 Measured Freq Offset: 150 Mode: 1 Channel: 20 Length: 6 Packet Quality: 0x00 Packet NADM: Attack is extremely unlikely (0x00) Packet RSSI: -42 ToA/ToD: 1234 Packet Antenna: 0 Mode: 2 Channel: 30 Length: 5 Antenna Permutation Index: 0 PCT[0]: I=1024, Q=-512 Tone Quality: High (0x00) ... : (Subevent Result Continue) ( ): > HCI Event: LE Meta Event (0x3e) plen 40 #202 [hci0] LE CS Subevent Result Continue (0x32) Handle: 2048 Config ID: 0 Procedure Done Status: Partial results (0x01) Subevent Done Status: All results complete (0x00) Abort Reason: 0x00 Num Antenna Paths: 1 Num Steps Reported: 4 Step Data: ... (CS Step Modes) CS . : -- ( CS) . CS . : o Packet Quality -- 0x00 = CS 0x01 = 0x02 = . o Packet RSSI -- ( dBm). o Packet Antenna -- . o Measured Freq Offset -- 0.01 ppm ( ). . -- (RTT) (ToA) (ToD) . : o Packet Quality -- . o Packet NADM -- (Normalized Attack Detector Metric) RTT : o 0x00 = o 0x01 = o 0x02 = o 0x03 = o 0x04 = o 0x05 = o 0x06 = o 0xff = o ToA/ToD -- ( ). 0x8000 = . o PCT1/PCT2 -- (I/Q ). RTT . -- (PBR / ) . . : o Antenna Permutation Index -- . o PCT ( ) -- I ( 0 11) Q ( 12 23). o Tone Quality Indicator -- : o 0x00 = o 0x01 = o 0x02 = o 0x03 = ( ): o 0x00 = o 0x01 = o 0x02 = -- RTT + (PBR) . ( NADM RSSI ToA/ToD ) . (Subevent Result Data Format) . (Procedure Done Status): o 0x00 -- CS o 0x01 -- o 0x0f -- (Subevent Done Status): o 0x00 -- o 0x01 -- o 0x0f -- (Abort Reason) ( ): ( ): o 0x00 -- o 0x01 -- o 0x02 -- o 0x03 -- o 0x0f -- ( ): o 0x00 -- o 0x01 -- o 0x02 -- CS_SYNC ( ) o 0x03 -- o 0x0f -- (CS State Machine) CS . -- HCI : | IDLE | | LE CS Read Local/Remote Supported Capabilities | LE CS Security Enable Complete | LE CS Set Default Settings | CAPABILITIES | Both devices' CS parameters are known. | EXCHANGED | Security is established. | LE CS Create Config | LE CS Config Complete (status=0x00) | CONFIGURED | Config ID N exists with negotiated params. | (config_id=N) | Can create up to 4 configs simultaneously. | LE CS Set Procedure Parameters | PARAMETERS SET | Scheduling and antenna params are locked. | (config_id=N) | | LE CS Procedure Enable (enable=1) | LE CS Procedure Enable Complete (state=1) | PROCEDURE | Controller is actively measuring. | RUNNING | Subevent Result events stream in. | (config_id=N) | | LE CS Procedure Enable (enable=0) | LE CS Procedure Enable Complete (state=0) | CONFIGURED | Config still exists, can re-enable. | (config_id=N) | | LE CS Remove Config | IDLE | . . (Typical CS Setup Sequence) CS HCI . Host Controller : Host Controller State LE CS Read Local Supported Capabilities IDLE Command Complete (capabilities) | LE CS Read Remote Supported Capabilities | Command Status | LE CS Read Remote Supp. Cap. Complete | | LE CS Security Enable | Command Status | LE CS Security Enable Complete | | LE CS Set Default Settings | Command Complete CAPABILITIES EXCHANGED LE CS Read Remote FAE Table (optional) | LE CS Read Remote FAE Complete | | LE CS Set Channel Classification (optional) | Command Complete | | LE CS Create Config (config_id=0) | Command Status | LE CS Config Complete CONFIGURED (id=0) LE CS Set Procedure Parameters (config_id=0) | Command Complete PARAMETERS SET (id=0) LE CS Procedure Enable (id=0, enable=1) | Command Status | LE CS Procedure Enable Complete (state=1) PROCEDURE RUNNING (id=0) LE CS Subevent Result | LE CS Subevent Result Cont. |(repeated) | LE CS Subevent Result | | LE CS Procedure Enable (id=0, enable=0) | Command Status | LE CS Procedure Enable Complete (state=0) CONFIGURED (id=0) LE CS Remove Config (id=0) (optional) | Command Status IDLE LE CS Create Config . / / / . (CS Test Mode) CS CS : < HCI Command: LE CS Test (0x08|0x0095) plen 34 #400 [hci0] Main Mode Type: 0x01 Sub Mode Type: 0xff Main Mode Repetition: 0 Mode 0 Steps: 3 Role: Initiator (0x00) RTT Type: 0x01 CS Sync PHY: LE 2M (0x01) CS Sync Antenna Selection: 0x01 Subevent Len: 5000 us Subevent Interval: 0 Max Num Subevents: 1 Transmit Power Level: 10 T_IP1 Time: 30 us T_IP2 Time: 30 us T_FCS Time: 50 us T_PM Time: 10 us T_SW Time: 0 us Tone Antenna Config Selection: 0x01 SNR Control Initiator: 0x00 SNR Control Reflector: 0x00 DRBG Nonce: 0x0000 Channel Map Repetition: 1 Override Config: 0x0000 > HCI Event: Command Complete (0x0e) plen 5 #401 [hci0] LE CS Test (0x08|0x0095) ncmd 1 Status: Success (0x00) LE CS Subevent Result . : < HCI Command: LE CS Test End (0x08|0x0096) plen 0 #450 [hci0] > HCI Event: LE Meta Event (0x3e) plen 1 #451 [hci0] LE CS Test End Complete (0x33) Status: Success (0x00) (Channel Sounding Error Handling) (Security Enable fails) CS Security Enable . SMP LE Encrypt . CS LE . Config Complete (Config Complete with error) . PHY . (Channel map too small) (CS) . 0x02 ( ) . (No Mode 0 sync received) 0x02 ( ) ( ). RF . (Procedure aborted by host) 0x01 Procedure Enable enable=0 . ToA/ToD ( 0x8000) . CS ( = 0x02) . (RAS) / (RAP) (RANGING SERVICE (RAS) / RANGING PROFILE (RAP)) (RAS) GATT CS . CS HCI ATT . (RAP) RAS . btmon ATT (UUID) RAS RAS . (UUID) RAS: 0x185B RAS (RAS Characteristics) +-----------------+-----------------+--------------------------+--------------------------------------+ | | | | (Description) | |(Characteristic) | | (Properties) | | | | (UUID) | | | +-----------------+-----------------+--------------------------+--------------------------------------+ |RAS Features | 0x2C14 | Read | | | | | | | | | | | | | | | | RAS | +-----------------+-----------------+--------------------------+--------------------------------------+ |RAS Real-time | 0x2C15 | Notify, Indicate | | |Ranging Data | | | | | | | | | | | | | | | | | | | +-----------------+-----------------+--------------------------+--------------------------------------+ |RAS On-demand | 0x2C16 | Notify, Indicate | | |Ranging Data | | | | | | | | | | | | | | +-----------------+-----------------+--------------------------+--------------------------------------+ |RAS Control | 0x2C17 | Write Without Response, | | |Point | | Indicate | | | | | | | | | | | | +-----------------+-----------------+--------------------------+--------------------------------------+ |RAS Ranging Data | 0x2C18 | Read, Notify, Indicate | | |Ready | | | | | | | | | | | | | | | | | | | | | | | | +-----------------+-----------------+--------------------------+--------------------------------------+ |RAS Ranging Data | 0x2C19 | Read, Notify, Indicate | | |Overwritten | | | | | | | | | | | | | | | | | | | +-----------------+-----------------+--------------------------+--------------------------------------+ RAS Features (CCC) (Notifications) (Indications) . GATT . RAS (RAS Feature and Capabilities) RAS Features : > ACL Data RX: Handle 2048 flags 0x02 dlen 11 #200 [hci0] ATT: Read Response (0x0b) len 4 Handle: 0x0003 Features: 0x0000000f Real-time Ranging Data (0x00000001) Retrieve Lost Ranging Data Segments (0x00000002) Abort Operation (0x00000004) Filter Ranging Data (0x00000008) : o -- (Real-time Ranging Data): CS Real-time Ranging Data . o -- (Retrieve Lost Ranging Data Segments): . o -- (Abort Operation): . o -- (Filter Ranging Data): . RAS (RAS Ranging Data Ready) CS : > ACL Data RX: Handle 2048 flags 0x02 dlen 9 #250 [hci0] ATT: Handle Value Notification (0x1b) len 2 Handle: 0x000e Counter: 42 (Counter) . (Control Point) (ACK) . RAS (RAS Ranging Data Overwritten) : > ACL Data RX: Handle 2048 flags 0x02 dlen 9 #260 [hci0] ATT: Handle Value Notification (0x1b) len 2 Handle: 0x0011 Overwritten Count: 38 ( ) . RAS (RAS Control Point) RAS (RAS Control Point) . (Indications) . (Opcodes): +-------------------+------------------+-----------------------------------+ | | | | | | (Command) | (Description) | |(Opcode) | | | +-------------------+------------------+-----------------------------------+ |0x00 | Get Ranging Data | | | | | | | | | | | | | | | | | | | | | | +-------------------+------------------+-----------------------------------+ |0x01 | ACK Ranging Data | | | | | | | | | | +-------------------+------------------+-----------------------------------+ |0x02 | Retrieve Lost | | | | Ranging Data | | | | Segments | | | | | | +-------------------+------------------+-----------------------------------+ |0x03 | Abort Operation | | | | | | | | | | +-------------------+------------------+-----------------------------------+ |0x04 | Set Filter | | | | | | | | | | | | | | +-------------------+------------------+-----------------------------------+ Get Ranging Data -- : < ACL Data TX: Handle 2048 flags 0x00 dlen 10 #270 [hci0] ATT: Write Command (0x52) len 3 Handle: 0x000b Opcode: Get Ranging Data (0x00) Ranging Counter: 0x002a (RAS On-demand Ranging Data 0x2C16) . ACK Ranging Data -- : < ACL Data TX: Handle 2048 flags 0x00 dlen 10 #290 [hci0] ATT: Write Command (0x52) len 3 Handle: 0x000b Opcode: ACK Ranging Data (0x01) Ranging Counter: 0x002a Retrieve Lost Ranging Data Segments -- : < ACL Data TX: Handle 2048 flags 0x00 dlen 12 #295 [hci0] ATT: Write Command (0x52) len 5 Handle: 0x000b Opcode: Retrieve Lost Ranging Data Segments (0x02) Ranging Counter: 0x002a First Segment Index: 3 Last Segment Index: 5 0xFF << >> . Abort Operation -- : < ACL Data TX: Handle 2048 flags 0x00 dlen 8 #298 [hci0] ATT: Write Command (0x52) len 1 Handle: 0x000b Opcode: Abort Operation (0x03) Set Filter -- : < ACL Data TX: Handle 2048 flags 0x00 dlen 10 #265 [hci0] ATT: Write Command (0x52) len 3 Handle: 0x000b Opcode: Set Filter (0x04) Filter Configuration: 0x0001 Mode: 1 Filter Bit Mask: 0x0000 : [1:0] [15:2] . (Ranging Data Format) (0x2C15) (0x2C16) . ATT . (Segmentation Header) ( ): > ACL Data RX: Handle 2048 flags 0x02 dlen 30 #275 [hci0] ATT: Handle Value Notification (0x1b) len 25 Handle: 0x0005 Segmentation Header: 0x01 First Segment: True Last Segment: False Segment Index: 0 Ranging Data Body: Ranging Counter: 0x02a Configuration ID: 0 Selected TX Power: 12 dBm Antenna Paths Mask: 0x03 Antenna Path 1 (0x01) Antenna Path 2 (0x02) Subevent #0: Start ACL Connection Event: 1200 Frequency Compensation: 150 (0.01 ppm) Ranging Done Status: Partial results (0x1) Subevent Done Status: All results complete (0x0) Ranging Abort Reason: No abort (0x0) Subevent Abort Reason: No abort (0x0) Reference Power Level: -20 dBm Number of Steps Reported: 8 Remaining Ranging Data Segment: ... : o First Segment ( ) -- True . Ranging Header . o Last Segment ( ) -- True . . o Segment Index ( [7:2]) -- . Ranging Header ( ): o Ranging Counter ( [11:0]) -- Data Ready CS . o Configuration ID ( [15:12]) -- CS ( ) . o Selected TX Power ( ) -- dBm. o Antenna Paths Mask ( ) -- : = = . Subevent Header ( ): o Start ACL Connection Event -- ACL CS . o Frequency Compensation -- 0.01 ppm ( ). o Ranging Done Status -- HCI: 0x0 = 0x1 = 0xF = . o Subevent Done Status -- 0x0 = 0xF = . o Ranging/Subevent Abort Reason -- HCI: 0x0 = 0x1 = / 0x2 = / 0x3 = 0xF = . o Reference Power Level -- RSSI dBm (). o Number of Steps Reported -- CS . HCI CS ( ) CS . (Continuation segments) . RAS (RAS Data Transfer State Machine) RAS : | IDLE | No active data transfer. | Server: CS procedure completes (HCI level) | Server: notifies Ranging Data Ready (counter=N) | DATA READY | Dataset N is buffered on server. | (counter=N) | Client has been notified. | Client writes: Get Ranging Data (counter=N) | OR (real-time mode: automatic push) | TRANSFERRING | Server sends segmented notifications. | (counter=N) | Segment Index increments: 0, 1, 2, ... | | Segment lost? Client writes: | | Retrieve Lost Segments (counter=N, first, last) | | Server re-sends missing segments. | | (loops back to TRANSFERRING) | | | | Client writes: Abort Operation | | Last Segment received | | COMPLETE | | ABORTED | | (counter=N) | | | Client writes: | | ACK Ranging Data | | (counter=N) | | IDLE | Server may free buffer for counter=N. Ranging Data Overwritten DATA READY ( ) . RAS (Typical RAS Data Flow) RAS : 1. Client discovers RAS (UUID 0x185B) via GATT primary service discovery 2. Client reads RAS Features (0x2C14) to learn capabilities 3. Client enables CCC notifications on: - RAS Ranging Data Ready (0x2C18) - RAS Ranging Data Overwritten (0x2C19) - RAS On-demand Ranging Data (0x2C16) or RAS Real-time Ranging Data (0x2C15) 4. CS procedure runs (HCI level) 5. Server notifies Ranging Data Ready with counter=N 6. Client writes Control Point: Get Ranging Data (counter=N) 7. Server sends On-demand Ranging Data notifications (segmented) 8. Client writes Control Point: ACK Ranging Data (counter=N) -- CS (Real-time Ranging Data 0x2C15) (Push) . ( ATT MTU ) Retrieve Lost Ranging Data Segments . HCI + GATT (Combined HCI + GATT Flow) HCI CS GATT RAS btmon . HCI (< HCI / > HCI) GATT ATT (< ACL / > ACL) : HCI (CS) GATT (RAS) State --- One-time connection setup --- < LE CS Read Local Supp. Cap. IDLE > Command Complete | < LE CS Read Remote Supp. Cap. | > Command Status | > LE CS Read Remote Supp. | Cap. Complete | < LE CS Security Enable | > Command Status | > LE CS Security Enable | Complete | < LE CS Set Default Settings | > Command Complete CAPS EXCHANGED < ATT: Find By Type Value | (RAS UUID 0x185B) | > ATT: Find By Type Value | Response | < ATT: Read Request | (RAS Features 0x2C14) | > ATT: Read Response | Features: 0x0000000f | < ATT: Write Request | (CCC: Ready 0x2C18) | > ATT: Write Response | < ATT: Write Request | (CCC: On-demand 0x2C16) | > ATT: Write Response RAS READY --- Per-measurement cycle (repeatable) --- < LE CS Create Config (id=0) | > Command Status | > LE CS Config Complete CONFIGURED (id=0) < LE CS Set Proc. Params (id=0) | > Command Complete PARAMS SET (id=0) < LE CS Proc. Enable | (id=0, enable=1) | > Command Status | > LE CS Proc. Enable | Complete (state=1) PROCEDURE RUNNING > LE CS Subevent Result | > LE CS Subevent Result | (measurement data | Continue | streams from | > LE CS Subevent Result | controller) | > LE CS Subevent Result | | > LE CS Subevent Result | (Procedure Done=0x00) PROCEDURE COMPLETE > ATT: Notification | (Data Ready 0x2C18) | Counter: N DATA READY (N) < ATT: Write Command | (Control Point 0x2C17) | Get Ranging Data | Counter: N TRANSFERRING (N) > ATT: Notification | (On-demand 0x2C16) | Seg[0]: First=T Last=F | Ranging Header + data | > ATT: Notification | (On-demand 0x2C16) | Seg[1]: First=F Last=F | > ATT: Notification | (On-demand 0x2C16) | Seg[2]: First=F Last=T TRANSFER COMPLETE (N) < ATT: Write Command | (Control Point 0x2C17) | ACK Ranging Data | Counter: N IDLE (buffer freed) --- Cleanup (optional) --- < LE CS Remove Config (id=0) > Command Status IDLE (Real-time Streaming Flow) ( ) CS Get Ranging Data : HCI (CS) GATT (RAS) State < LE CS Proc. Enable PARAMS SET (id=0, enable=1) > LE CS Proc. Enable Complete PROCEDURE RUNNING > LE CS Subevent Result | > ATT: Notification | (Real-time 0x2C15) | Seg[0]: First=T Last=T | Ranging Header + | subevent data > LE CS Subevent Result | > ATT: Notification | (Real-time 0x2C15) | Seg[0]: First=T Last=F | > ATT: Notification | (Real-time 0x2C15) | Seg[1]: First=F Last=T > LE CS Subevent Result > ATT: Notification (Real-time 0x2C15) ... > LE CS Subevent Result | (Procedure Done=0x00) PROCEDURE COMPLETE < ATT: Write Command ACK Ranging Data Counter: N IDLE HCI GATT . (Ranging Counter) . Retrieve Lost Segments ( ). (Lost Segment Recovery Flow) : GATT (RAS) State > ATT: Notification (On-demand 0x2C16) TRANSFERRING Seg[0]: First=T Last=F received > ATT: Notification (On-demand 0x2C16) Seg[1]: First=F Last=F received | Seg[2] LOST (not received) | | > ATT: Notification (On-demand 0x2C16) | Seg[3]: First=F Last=T received | | (Client detects gap: Seg[2] missing) INCOMPLETE < ATT: Write Command (Control Point 0x2C17) Retrieve Lost Ranging Data Segments Counter: N First Segment Index: 2 Last Segment Index: 2 RECOVERING > ATT: Notification (On-demand 0x2C16) Seg[2]: First=F Last=F re-sent TRANSFER COMPLETE < ATT: Write Command (Control Point 0x2C17) ACK Ranging Data Counter: N IDLE RAS (RAS Common Issues) 0x00000000 (Features read returns 0x00000000) RAS . (Control Point) . (Ranging Data Ready not received) CCC 0x2C18 . CS -- Data Ready . (Segmentation reassembly errors) (Segment Index) First Segment . ( ) Retrieve Lost Segments . (Data Overwritten before retrieval) . (ACK) . Data Overwritten . (Control Point write rejected) . RAS (WRITE_ENCRYPT) . SMP . (CLASSIC AUDIO PROTOCOL FLOW) : A2DP HFP . ACL BR/EDR -- A2DP AVDTP L2CAP HFP SCO/eSCO . A2DP: (A2DP: Advanced Audio Distribution) A2DP AVDTP ( /) L2CAP (Codec) . btmon AVDTP AVRCP . AVDTP (AVDTP Signaling Channel) A2DP L2CAP PSM 25 (0x0019) . L2CAP PSM AVDTP PSM : < ACL Data TX: Handle 1 flags 0x00 dlen 12 L2CAP: Connection Request (0x02) ident 1 len 4 PSM: 25 (0x0019) Source CID: 64 > ACL Data RX: Handle 1 flags 0x02 dlen 16 L2CAP: Connection Response (0x03) ident 1 len 8 Destination CID: 64 Source CID: 64 Result: Connection successful (0x0000) Status: No further information available (0x0000) L2CAP AVDTP . (Stream Endpoint Discovery) (initiator) (SEP) : < ACL Data TX: Handle 1 flags 0x00 dlen 6 Channel: 64 len 2 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Discover (0x01) Command (0x00) type 0x00 label 0 nosp 0 > ACL Data RX: Handle 1 flags 0x02 dlen 10 Channel: 64 len 6 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Discover (0x01) Response Accept (0x02) type 0x00 label 0 nosp 0 ACP SEID: 1 Media Type: Audio (0x00) SEP Type: SNK (0x01) In use: No (SEP) SEID ( ) (Source Sink) . In use: Yes . (Codec Capability Discovery) SEID : < ACL Data TX: Handle 1 flags 0x00 dlen 7 Channel: 64 len 3 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Get All Capabilities (0x0c) Command (0x00) type 0x00 label 1 nosp 0 ACP SEID: 1 > ACL Data RX: Handle 1 flags 0x02 dlen 30 Channel: 64 len 26 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Get All Capabilities (0x0c) Response Accept (0x02) type 0x00 label 1 nosp 0 Service Category: Media Transport (0x01) Service Category: Media Codec (0x07) Media Type: Audio (0x00) Media Codec: SBC (0x00) Frequency: 0xf0 16000 32000 44100 48000 Channel Mode: 0x0f Mono Dual Channel Stereo Joint Stereo Block Length: 0xf0 4 8 12 16 Subbands: 0x0c 4 8 Allocation Method: 0x03 SNR Loudness Minimum Bitpool: 2 Maximum Bitpool: 53 Service Category: Content Protection (0x04) Content Protection Type: SCMS-T (0x0002) Service Category: Delay Reporting (0x08) (bitmask) . : o Media Transport (0x01) -- o Media Codec (0x07) -- (Codec) o Content Protection (0x04) -- (SCMS-T DTCP) o Delay Reporting (0x08) -- (Supported Codecs) btmon (Codec) A2DP . . SBC ( A2DP): Media Codec: SBC (0x00) Frequency: 44100 (0x20) Channel Mode: Joint Stereo (0x01) Block Length: 16 (0x10) Subbands: 8 (0x04) Allocation Method: Loudness (0x01) Minimum Bitpool: 2 Maximum Bitpool: 53 AAC (MPEG-2,4): Media Codec: MPEG-2,4 AAC (0x02) Object Type: MPEG-4 AAC LC (0x40) Frequency: 44100 (0x0100) Channels: 2 (0x04) Bitrate: 256000bps VBR: No aptX ( Qualcomm ): Media Codec: Non-A2DP (0xff) Vendor ID: Qualcomm Technologies International, Ltd. (APT) (0x0000004f) Vendor Specific Codec ID: aptX (0x0001) Frequency: 44100 (0x20) Channel Mode: Stereo (0x02) aptX HD ( Qualcomm ): Media Codec: Non-A2DP (0xff) Vendor ID: Qualcomm Technologies, Inc. (0x000000d7) Vendor Specific Codec ID: aptX HD (0x0024) Frequency: 44100 (0x20) Channel Mode: Stereo (0x02) LDAC ( Sony ): Media Codec: Non-A2DP (0xff) Vendor ID: Sony Corporation (0x0000012d) Vendor Specific Codec ID: LDAC (0x00aa) Non-A2DP (0xff) Vendor ID Codec ID . . (Stream Configuration) Set Configuration : < ACL Data TX: Handle 1 flags 0x00 dlen 20 Channel: 64 len 16 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Set Configuration (0x03) Command (0x00) type 0x00 label 2 nosp 0 ACP SEID: 1 INT SEID: 1 Service Category: Media Transport (0x01) Service Category: Media Codec (0x07) Media Type: Audio (0x00) Media Codec: SBC (0x00) Frequency: 44100 (0x20) Channel Mode: Joint Stereo (0x01) Block Length: 16 (0x10) Subbands: 8 (0x04) Allocation Method: Loudness (0x01) Minimum Bitpool: 2 Maximum Bitpool: 53 > ACL Data RX: Handle 1 flags 0x02 dlen 6 Channel: 64 len 2 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Set Configuration (0x03) Response Accept (0x02) type 0x00 label 2 nosp 0 . ACP SEID INT SEID . : > ACL Data RX: Handle 1 flags 0x02 dlen 8 Channel: 64 len 4 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Set Configuration (0x03) Response Reject (0x03) type 0x00 label 2 nosp 0 Service Category: Media Codec (0x07) Error code: Unsupported Configuration (0x29) AVDTP: +-------+-------------------+--------------------------------+ | | | | +-------+-------------------+--------------------------------+ |0x01 | Bad Header Format | AVDTP | | | | | +-------+-------------------+--------------------------------+ |0x11 | Bad ACP SEID | | | | | | | | | | | | | | +-------+-------------------+--------------------------------+ |0x12 | SEP In Use | | | | | | | | | | | | | | | | | | +-------+-------------------+--------------------------------+ |0x13 | SEP Not In Use | | | | | | | | | | | | | | +-------+-------------------+--------------------------------+ |0x29 | Unsupported | | | | Configuration | | | | | | | | | | +-------+-------------------+--------------------------------+ |0x31 | Bad State | | | | | | | | | | +-------+-------------------+--------------------------------+ (Open and Start) : < ACL Data TX: Handle 1 flags 0x00 dlen 7 Channel: 64 len 3 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Open (0x06) Command (0x00) type 0x00 label 3 nosp 0 ACP SEID: 1 > ACL Data RX: Handle 1 flags 0x02 dlen 6 Channel: 64 len 2 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Open (0x06) Response Accept (0x02) type 0x00 label 3 nosp 0 Open L2CAP PSM 25 . Start : < ACL Data TX: Handle 1 flags 0x00 dlen 7 Channel: 64 len 3 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Start (0x07) Command (0x00) type 0x00 label 4 nosp 0 ACP SEID: 1 > ACL Data RX: Handle 1 flags 0x02 dlen 6 Channel: 64 len 2 [PSM 25 mode Basic (0x00)] {chan 0} AVDTP: Start (0x07) Response Accept (0x02) type 0x00 label 4 nosp 0 (Media Data) Start ( L2CAP PSM 25) . btmon -- . --show-a2dp-stream L2CAP (payload) . AVDTP : +----------------+-----------------------------+-----------------------------+ | | | | | | | | +----------------+-----------------------------+-----------------------------+ |Idle | / | | | | Abort | | | | | | | | | | +----------------+-----------------------------+-----------------------------+ |Configured | Set | | | | Configuration | | | | | | | | | | +----------------+-----------------------------+-----------------------------+ |Open | Open / | | | | Suspend | | | | | | | | | | | | | | | | | | | | | | +----------------+-----------------------------+-----------------------------+ |Streaming | Start | | | | | | | | | | | | | | +----------------+-----------------------------+-----------------------------+ |Closing | | | | | Close | | | | | | +----------------+-----------------------------+-----------------------------+ |Aborting | | | | | Abort | | +----------------+-----------------------------+-----------------------------+ (Suspend, Close, and Abort) Suspend () : AVDTP: Suspend (0x09) Command (0x00) type 0x00 label 5 nosp 0 ACP SEID: 1 AVDTP: Suspend (0x09) Response Accept (0x02) type 0x00 label 5 nosp 0 Close ( Idle): AVDTP: Close (0x08) Command (0x00) type 0x00 label 6 nosp 0 ACP SEID: 1 AVDTP: Close (0x08) Response Accept (0x02) type 0x00 label 6 nosp 0 Abort : AVDTP: Abort (0x0a) Command (0x00) type 0x00 label 7 nosp 0 ACP SEID: 1 AVDTP: Abort (0x0a) Response Accept (0x02) type 0x00 label 7 nosp 0 (Delay Reporting) (sink) (Delay Report) (source) : AVDTP: Delay Report (0x0d) Command (0x00) type 0x00 label 8 nosp 0 ACP SEID: 1 Delay: 15.0ms AVDTP: Delay Report (0x0d) Response Accept (0x02) type 0x00 label 8 nosp 0 AVRCP (AVRCP Remote Control) AVRCP ( /) L2CAP PSM 23 () PSM 27 () . btmon AVCTP PDU AVRCP . : < ACL Data TX: Handle 1 flags 0x00 dlen 17 Channel: 66 len 13 [PSM 23 mode Basic (0x00)] {chan 2} AVCTP Control: Response: type 0x00 label 0 PID 0x110e AV/C: Accepted: address 0x48 opcode 0x00 Subunit: Panel Opcode: Vendor Dependent Company ID: 0x001958 AVRCP: SetAbsoluteVolume pt Single len 0x0001 Volume: 50.39% (64/127) : AVRCP: GetPlayStatus pt Single len 0x0009 SongLength: 0x00038270 (230000 milliseconds) SongPosition: 0x00000000 (0 milliseconds) PlayStatus: 0x01 (PLAYING) ( GetElementAttributes): AVRCP: GetElementAttributes pt Single len 0x0050 AttributeCount: 0x02 Attribute: 0x00000001 (Title) CharsetID: 0x006a (UTF-8) AttributeValueLength: 0x000c AttributeValue: My Song Name Attribute: 0x00000002 (Artist) CharsetID: 0x006a (UTF-8) AttributeValueLength: 0x000b AttributeValue: The Artist Passthrough ( ): AVCTP Control: Command: type 0x00 label 1 PID 0x110e AV/C: Control: address 0x48 opcode 0x7c Subunit: Panel Opcode: Passthrough Operation: 0x44 (PLAY Pressed) Length: 0x00 ( ): AVRCP: RegisterNotification pt Single len 0x0005 EventID: 0x0d (EVENT_VOLUME_CHANGED) Volume: 50.39% (64/127) A2DP (Automating A2DP Analysis) A2DP: grep -n "AVDTP:\|Media Codec:" output.txt AVDTP: grep -n "AVDTP:.*Command\|AVDTP:.*Response" output.txt ( ): grep -n "Set Configuration\|Media Codec:" output.txt -- Start : grep -n "AVDTP: Start\|PSM 25.*chan 1" output.txt -- Set Configuration: grep -n "Response Reject\|Error code:" output.txt AVRCP: grep -n "SetAbsoluteVolume\|Volume:\|GetPlayStatus\|PlayStatus:" output.txt A2DP: 1. Connection Request L2CAP PSM 25 -- AVDTP 2. Discover -- 3. Get All Capabilities -- 4. Set Configuration -- 5. Open Start -- 6. L2CAP PSM 25 -- 7. Response Reject 8. Suspend Close ACL HFP: (HFP: Hands-Free Profile) HFP SCO/eSCO RFCOMM . btmon RFCOMM SCO/eSCO (Decode) . AT ( HFP) RFCOMM -- btmon (Syntax) AT . SDP (SDP Discovery) HFP SDP (Hands-Free) (Audio Gateway) RFCOMM : < ACL Data TX: Handle 1 flags 0x00 dlen 25 Channel: 64 len 21 [PSM 1 mode Basic (0x00)] {chan 0} SDP: Service Search Attribute Request (0x06) tid 1 len 16 Search pattern: [len 5] Sequence (6) with 3 byte(s) [8 extra bits] len 5 UUID (3) with 2 byte(s) [0 extra bits] len 3 Handsfree Audio Gateway (0x111f) Max record count: 65535 Attribute list: [len 5] Sequence (6) with 3 byte(s) [8 extra bits] len 5 Unsigned Integer (1) with 4 byte(s) [0 extra bits] len 5 0x0000ffff Continuation state: 0 RFCOMM : > ACL Data RX: Handle 1 flags 0x02 dlen 89 Channel: 64 len 85 [PSM 1 mode Basic (0x00)] {chan 0} SDP: Service Search Attribute Response (0x07) tid 1 len 80 Attribute bytes: 77 Attribute list: [len 75] {position 0} Attribute: Service Class ID List (0x0001) [len 2] Handsfree Audio Gateway (0x111f) Attribute: Protocol Descriptor List (0x0004) [len 2] L2CAP (0x0100) RFCOMM (0x0003) Channel: 1 Attribute: Bluetooth Profile Descriptor List (0x0009) [len 2] Handsfree (0x111e) Version: 0x0108 Continuation state: 0 : o (Service Class) -- Handsfree (0x111e) HF Handsfree Audio Gateway (0x111f) AG o RFCOMM -- RFCOMM (0x0003) ( ) o (Profile Version) -- ( 0x0108 = HFP 1.8 0x0109 = HFP 1.9) RFCOMM (RFCOMM Connection Setup) RFCOMM L2CAP PSM 3 . : (Multiplexer) DLCI 0 DLCI . L2CAP RFCOMM: < ACL Data TX: Handle 1 flags 0x00 dlen 12 L2CAP: Connection Request (0x02) ident 2 len 4 PSM: 3 (0x0003) Source CID: 65 > ACL Data RX: Handle 1 flags 0x02 dlen 16 L2CAP: Connection Response (0x03) ident 2 len 8 Destination CID: 65 Source CID: 65 Result: Connection successful (0x0000) Status: No further information available (0x0000) SABM/UA DLCI 0 ( ): < ACL Data TX: Handle 1 flags 0x00 dlen 12 Channel: 65 len 4 [PSM 3 mode Basic (0x00)] {chan 1} RFCOMM: Set Async Balance Mode (SABM) (0x2f) Address: 0x03 cr 1 dlci 0x00 Control: 0x3f poll/final 1 Length: 0 FCS: 0x1c > ACL Data RX: Handle 1 flags 0x02 dlen 12 Channel: 65 len 4 [PSM 3 mode Basic (0x00)] {chan 1} RFCOMM: Unnumbered Ack (UA) (0x63) Address: 0x03 cr 1 dlci 0x00 Control: 0x73 poll/final 1 Length: 0 FCS: 0xd7 (Parameter Negotiation) ( MCC DLCI 0): Channel: 65 len 14 [PSM 3 mode Basic (0x00)] {chan 1} RFCOMM: Unnumbered Info with Header Check (UIH) (0xef) Address: 0x03 cr 1 dlci 0x00 Control: 0xef poll/final 0 Length: 10 FCS: 0x70 MCC Message type: DLC Parameter Negotiation CMD (0x20) Length: 8 dlci 2 frame_type 0 credit_flow 15 pri 7 ack_timer 0 frame_size 127 max_retrans 0 credits 7 DLCI PN . RFCOMM N DLCI N * 2 ( N * 2 + 1). SABM/UA DLCI ( ): Channel: 65 len 4 [PSM 3 mode Basic (0x00)] {chan 1} RFCOMM: Set Async Balance Mode (SABM) (0x2f) Address: 0x0b cr 1 dlci 0x02 Control: 0x3f poll/final 1 Length: 0 FCS: 0x59 Channel: 65 len 4 [PSM 3 mode Basic (0x00)] {chan 1} RFCOMM: Unnumbered Ack (UA) (0x63) Address: 0x0b cr 1 dlci 0x02 Control: 0x73 poll/final 1 Length: 0 FCS: 0x92 (Modem Status Command) ( ): Channel: 65 len 8 [PSM 3 mode Basic (0x00)] {chan 1} RFCOMM: Unnumbered Info with Header Check (UIH) (0xef) Address: 0x03 cr 1 dlci 0x00 Control: 0xef poll/final 0 Length: 4 FCS: 0x70 MCC Message type: Modem Status Command CMD (0x38) Length: 2 dlci 2 fc 0 rtc 1 rtr 1 ic 0 dv 1 AT ( SLC) (AT Command Exchange (SLC Setup)) HFP AT RFCOMM . btmon RFCOMM UIH AT . AT RFCOMM UIH: Channel: 65 len 21 [PSM 3 mode Basic (0x00)] {chan 1} RFCOMM: Unnumbered Info with Header Check (UIH) (0xef) Address: 0x09 cr 0 dlci 0x02 Control: 0xff poll/final 1 Length: 14 FCS: 0x86 Credits: 1 41 54 2b 42 52 53 46 3d 32 30 35 35 0d AT+BRSF=2055. AT ASCII ( ) . (SLC) : 1. AT+BRSF= / +BRSF: -- 2. AT+BAC=1,2 -- ( ). : 1 = CVSD 2 = mSBC 3 = LC3-SWB 3. AT+CIND=? / +CIND:(...) -- 4. AT+CIND? / +CIND:values -- 5. AT+CMER=3,0,0,1 -- 6. AT+CHLD=? / +CHLD:(0,1,2,3,4) -- HFP ( AT+BRSF): +----------+-----------------------------------+-----------------------------------+ | | HF | AG | +----------+-----------------------------------+-----------------------------------+ |0 | EC/NR | | | | | | +----------+-----------------------------------+-----------------------------------+ |1 | | EC/NR | | | | | +----------+-----------------------------------+-----------------------------------+ |2 | | | | | | | | | (CLI) | | +----------+-----------------------------------+-----------------------------------+ |3 | | | | | | | +----------+-----------------------------------+-----------------------------------+ |4 | | | | | | | +----------+-----------------------------------+-----------------------------------+ |5 | | | | | | | +----------+-----------------------------------+-----------------------------------+ |6 | | | | | | | +----------+-----------------------------------+-----------------------------------+ |7 | | | | | | | +----------+-----------------------------------+-----------------------------------+ |8 | HF | | | | | | +----------+-----------------------------------+-----------------------------------+ |9 | eSCO S4 (T2) | | +----------+-----------------------------------+-----------------------------------+ |11 | | eSCO S4 (T2) | +----------+-----------------------------------+-----------------------------------+ (Codec Connection Setup) ( HF AG) AG . AT RFCOMM UIH : AG -> HF: +BCS:2 (select mSBC) HF -> AG: AT+BCS=2 (confirm mSBC) AG -> HF: OK HFP ( AT+BAC AT+BCS): +----------------+-----------+------------------------------+ | | | | +----------------+-----------+------------------------------+ |1 | CVSD | | | | | ( | | | | ) | | | | | +----------------+-----------+------------------------------+ |2 | mSBC | | | | | | | | | ( | | | | ) | +----------------+-----------+------------------------------+ |3 | LC3-SWB | | | | | ( | | | | ) | | | | HFP 1.9+ | +----------------+-----------+------------------------------+ HFP HCI . (Voice Setting) SCO/eSCO . CVSD CVSD mSBC LC3-SWB (Transparent Data) : < HCI Command: Write Voice Setting (0x0c|0x0026) plen 2 Setting: 0x0063 Input Coding: Linear Input Data Format: 2's complement Input Sample Size: 16-bit # of bits padding at MSB: 0 Air Coding Format: Transparent Data CVSD: < HCI Command: Write Voice Setting (0x0c|0x0026) plen 2 Setting: 0x0060 Input Coding: Linear Input Data Format: 2's complement Input Sample Size: 16-bit # of bits padding at MSB: 0 Air Coding Format: CVSD SCO/eSCO (SCO/eSCO Connection Setup) . (Setup Synchronous Connection) (): < HCI Command: Setup Synchronous Connection (0x01|0x0028) plen 17 Handle: 1 Transmit bandwidth: 8000 Receive bandwidth: 8000 Max latency: 13 Setting: 0x0063 Input Coding: Linear Input Data Format: 2's complement Input Sample Size: 16-bit # of bits padding at MSB: 0 Air Coding Format: Transparent Data Retransmission effort: Optimize for link quality (0x02) Packet type: 0x0008 EV3 may be used (Enhanced Setup Synchronous Connection) ( ): < HCI Command: Enhanced Setup Synchronous Connection (0x01|0x003d) plen 59 Handle: 1 Transmit bandwidth: 8000 Receive bandwidth: 8000 Transmit Coding Format: Codec: mSBC (0x05) Receive Coding Format: Codec: mSBC (0x05) Transmit Codec Frame Size: 60 Receive Codec Frame Size: 60 Input Coding Format: Codec: mSBC (0x05) Output Coding Format: Codec: mSBC (0x05) Input Coded Data Size: 16 Output Coded Data Size: 16 Input PCM Data Format: 2's complement Output PCM Data Format: 2's complement Input PCM Sample Payload MSB Position: 0 Output PCM Sample Payload MSB Position: 0 Input Data Path: HCI Output Data Path: HCI Input Transport Unit Size: 60 Output Transport Unit Size: 60 Max latency: 13 Packet type: 0x0008 EV3 may be used Retransmission effort: Optimize for link quality (0x02) HCI btmon : +----------------+------------------+---------------------------------+ | | | | | | btmon | | +----------------+------------------+---------------------------------+ |0x02 | CVSD | | | | | | +----------------+------------------+---------------------------------+ |0x03 | Transparent | | | | | | | | | (Transparent) | +----------------+------------------+---------------------------------+ |0x04 | Linear PCM | / | | | | | | | | PCM | +----------------+------------------+---------------------------------+ |0x05 | mSBC | | | | | | | | | (WBS) | +----------------+------------------+---------------------------------+ |0x06 | LC3 | | | | | (LC3-SWB) | +----------------+------------------+---------------------------------+ (Synchronous Connection Complete) (): > HCI Event: Synchronous Connection Complete (0x2c) plen 17 Status: Success (0x00) Handle: 257 Address: 11:22:33:44:55:66 (OUI 11-22-33) Link type: eSCO (0x02) Transmission interval: 0x0c Retransmission window: 0x06 RX packet length: 60 TX packet length: 60 Air mode: Transparent (0x03) : o (Link type) -- SCO (0x00) eSCO (0x02) ( mSBC LC3-SWB) o (Air mode) -- CVSD (0x02) Transparent (0x03) mSBC LC3-SWB o RX/TX -- mSBC T2 SCO (SCO Data Packets) SCO/eSCO : > BR-ESCO: Handle 257 flags 0x00 dlen 60 < BR-ESCO: Handle 257 flags 0x00 dlen 60 btmon Synchronous Connection Complete : o BR-SCO -- SCO o BR-ESCO -- SCO ( mSBC LC3-SWB eSCO CVSD) (Payload) SCO . --show-sco-data . (Codec-Specific Connection Summary) CVSD ( ): o HFP: o HCI: CVSD (0x02) o : 0x0060 ( : CVSD) o : CVSD (0x02) o : SCO eSCO o : (HV3) (EV3) mSBC ( ): o HFP: o HCI: mSBC (0x05) o : 0x0063 ( : / Transparent Data) o : Transparent (0x03) o : eSCO o : (EV3 T2) LC3-SWB ( ): o HFP: o HCI: LC3 (0x06) o : 0x0063 ( : / Transparent Data) o : Transparent (0x03) o : eSCO o : btmon LC3 LC3-SWB HFP (Automating HFP Analysis) HFP -- RFCOMM PSM 3: grep -n "PSM: 3\|RFCOMM:" output.txt AT -- AT ASCII : grep -n "AT+B\|AT+C\|+BRSF\|+CIND\|+CHLD\|+BCS" output.txt -- BCS ( ): grep -n "+BCS\|AT+BAC\|AT+BCS" output.txt SCO/eSCO: grep -n "Setup Synchronous\|Enhanced Setup Synchronous\|Synchronous Connection Complete\|Write Voice Setting" output.txt -- : grep -n "Air mode:\|Air Coding Format:\|Codec:" output.txt SCO -- Synchronous Connection Complete: grep -n "Synchronous Connection Complete" output.txt Status: . : o Connection Rejected due to Limited Resources (0x0d) -- o SCO Offset Rejected (0x2b) -- o SCO Interval Rejected (0x2c) -- -- CIEV: grep -n "+CIEV\|AT+CHUP\|ATD\|ATA\|AT+CLCC\|RING" output.txt HFP: 1. SDP UUID 0x111e/0x111f -- HFP 2. L2CAP Connection Request PSM 3 -- RFCOMM 3. RFCOMM SABM/UA DLCI 0 DLCI -- 4. AT+BRSF -- 5. AT+BAC -- 6. +BCS/AT+BCS -- 7. Write Voice Setting -- 8. Setup Synchronous Connection Enhanced -- SCO 9. Synchronous Connection Complete -- Status Link type Air mode 10. BR-SCO BR-ESCO -- (ADVERTISING AND SCANNING) btmon (advertising data) . (scan response) HCI LE . (Advertising Reports) : > HCI Event: LE Meta Event (0x3e) plen 43 #120 [hci0] 0.500003 LE Extended Advertising Report (0x0d) Event type: 0x0013 Props: 0x0013 Connectable Scannable Complete Address type: Random (0x01) Address: 00:11:22:33:44:55 Primary PHY: LE 1M Secondary PHY: LE 2M SID: 0x01 TX power: 0 dBm RSSI: -55 dBm (0xc9) Data length: 18 (AD) : AD btmon : +-------------+---------------------+--------------------------------------+ | AD | | | | | | btmon | +-------------+---------------------+--------------------------------------+ |0x01 | Flags | Flags: 0x06 | | | | | | | | | | | | (LE General Discoverable BR/EDR | | | | Not Supported) | +-------------+---------------------+--------------------------------------+ |0x02/0x03 | Incomplete/Complete | 16-bit Service UUIDs (complete): 2 | | | 16-bit UUIDs | entries | | | | UUID | +-------------+---------------------+--------------------------------------+ |0x06/0x07 | Incomplete/Complete | 128-bit Service UUIDs (complete): 1 | | | 128-bit UUIDs | entry | +-------------+---------------------+--------------------------------------+ |0x08/0x09 | Shortened/Complete | Name (complete): MyDevice | | | Local Name | | +-------------+---------------------+--------------------------------------+ |0x0a | TX Power Level | TX power: 4 dBm | +-------------+---------------------+--------------------------------------+ |0x16 | Service Data | Service Data (UUID 0x184e): ... | | | (16-bit UUID) | | | | | | +-------------+---------------------+--------------------------------------+ |0xff | Manufacturer | Company: Apple, Inc. (76) | | | Specific Data | | | | | | | | | | +-------------+---------------------+--------------------------------------+ : > HCI Event: LE Meta Event (0x3e) plen 38 #120 [hci0] 0.500003 LE Extended Advertising Report (0x0d) Address: 00:11:22:33:44:55 RSSI: -62 dBm (0xc2) Flags: 0x06 LE General Discoverable Mode BR/EDR Not Supported Name (complete): LE-Audio-Left 16-bit Service UUIDs (complete): 3 entries Published Audio Capabilities (0x1850) Audio Stream Control (0x184e) Common Audio (0x1853) Service Data (UUID 0x1852): 01a2b3 Appearance: Earbud (0x0941) (Extended Advertising) . btmon: < HCI Command: LE Set Extended Adv Parameters (0x08|0x0036) plen 25 #50 [hci0] 0.100003 Handle: 0x01 Properties: 0x0000 Min advertising interval: 160.000 msec (0x0100) Max advertising interval: 160.000 msec (0x0100) Channel map: 37, 38, 39 (0x07) Own address type: Random (0x01) Peer address type: Public (0x00) PHY: LE 1M, LE 2M SID: 0x01 TX power: 7 dBm < HCI Command: LE Set Extended Adv Data (0x08|0x0037) plen 35 #52 [hci0] 0.101003 Handle: 0x01 Operation: Complete extended advertising data (0x01) Fragment preference: No fragmentation (0x01) ( LE) (Periodic Advertising (LE Audio)) LE BASE (codec) : > HCI Event: LE Meta Event (0x3e) plen 80 #200 [hci0] 0.500003 LE Periodic Advertising Report (0x0f) Sync handle: 0x0001 TX power: 0 dBm RSSI: -45 dBm CTE Type: No CTE (0xff) Data status: Complete (0x00) Data length: 60 Service Data: Basic Audio Announcement (0x1851) Presentation Delay: 40000 us Number of Subgroups: 1 Codec: LC3 (0x06) Sampling Frequency: 48000 Hz Frame Duration: 10 ms Frame Length: 120 (Automating Advertising Analysis) ( ): grep -n "Advertising Report\|Address:.*RSSI:" output.txt : grep -n "Name (complete):\|Name (short):" output.txt LE Audio ( UUID ): grep -n "Audio Stream Control\|Published Audio Capabilities\|Common Audio\|Basic Audio Announcement\|Broadcast Audio" output.txt ( ): grep -n "Set Extended Adv\|Set Advertising\|Set Scan Response\|Adv Enable" output.txt ( ): grep -n "Periodic Advertising\|PA Sync\|PA Report\|Basic Audio Announcement\|Broadcast.*Announcement" output.txt (Appearance): grep -n "Appearance:" output.txt (MGMT PROTOCOL FLOWS) (MGMT) / ( bluetoothd) (kernel) . btmon MGMT @ HCI . MGMT btmon . MGMT ( Open/Close ) << (Management Traffic)>> (READING THE OUTPUT) . (Initialization and Version Handshake) bluetoothd . (handshake) : @ MGMT Open: bluetoothd (privileged) version 1.23 {0x0001} 12:34:49.881936 @ MGMT Command: Read Management Ver.. (0x0001) plen 0 {0x0001} 12:34:49.882003 @ MGMT Event: Command Complete (0x0001) plen 6 {0x0001} 12:34:49.882010 Read Management Version Information (0x0001) plen 3 Status: Success (0x00) Version: 1.23 @ MGMT Command: Read Management Sup.. (0x0002) plen 0 {0x0001} 12:34:49.882050 @ MGMT Event: Command Complete (0x0001) plen 58 {0x0001} 12:34:49.882055 Read Supported Commands (0x0002) plen 55 Status: Success (0x00) Num of commands: 120 Num of events: 38 bluetoothd : @ MGMT Command: Read Controller Index List (0x0003) plen 0 {0x0001} 12:34:49.882100 @ MGMT Event: Command Complete (0x0001) plen 7 {0x0001} 12:34:49.882105 Read Controller Index List (0x0003) plen 4 Status: Success (0x00) Num controllers: 1 Controller: hci0 @ MGMT Command: Read Controller Inf.. (0x0004) plen 0 {0x0001} [hci0] 12:34:49.882200 @ MGMT Event: Command Complete (0x0001) plen 283 {0x0001} [hci0] 12:34:49.882210 Read Controller Information (0x0004) plen 280 Status: Success (0x00) Address: 00:11:22:33:44:55 Bluetooth version: 5.4 Manufacturer: Intel (2) Supported settings: 0x003effff Current settings: 0x00000080 : o MGMT Open -- bluetoothd . MGMT . o (Version mismatch) -- bluetoothd MGMT . o Num controllers: 0 -- . dmesg . o Current settings -- (Powered LE BR/EDR SSP ). (Adapter Configuration) bluetoothd MGMT . main.conf . : @ MGMT Command: Load Link Keys (0x0012) plen 3 {0x0001} [hci0] 12:34:50.001200 Debug keys: Disabled (0x00) Key count: 0 @ MGMT Event: Command Complete (0x0001) plen 4 {0x0001} [hci0] 12:34:50.001220 Load Link Keys (0x0012) plen 1 Status: Success (0x00) @ MGMT Command: Load Long Term Keys (0x0013) plen 2 {0x0001} [hci0] 12:34:50.001300 Key count: 0 @ MGMT Event: Command Complete (0x0001) plen 4 {0x0001} [hci0] 12:34:50.001315 Load Long Term Keys (0x0013) plen 1 Status: Success (0x00) @ MGMT Command: Load Identity Resolving Keys (0x0030) plen 2 {0x0001} [hci0] 12:34:50.001400 Key count: 0 @ MGMT Event: Command Complete (0x0001) plen 4 {0x0001} [hci0] 12:34:50.001415 Load Identity Resolving Keys (0x0030) plen 1 Status: Success (0x00) (bonded) Key count btmon . . : @ MGMT Command: Set Secure Connections (0x002d) plen 1 {0x0001} [hci0] 12:34:50.002100 Secure connections: Enabled (0x01) @ MGMT Event: Command Complete (0x0001) plen 7 {0x0001} [hci0] 12:34:50.002120 Set Secure Connections (0x002d) plen 4 Status: Success (0x00) Current settings: 0x004e0a81 @ MGMT Command: Set Bondable (0x0009) plen 1 {0x0001} [hci0] 12:34:50.002200 Bondable: Enabled (0x01) @ MGMT Event: Command Complete (0x0001) plen 7 {0x0001} [hci0] 12:34:50.002220 Set Bondable (0x0009) plen 4 Status: Success (0x00) Current settings: 0x004e0a91 (Powering on): @ MGMT Command: Set Powered (0x0005) plen 1 {0x0001} [hci0] 12:35:04.033564 Powered: Enabled (0x01) @ MGMT Event: Command Complete (0x0001) plen 7 {0x0001} [hci0] 12:35:04.114789 Set Powered (0x0005) plen 4 Status: Success (0x00) Current settings: 0x004e0ac1 Set Powered btmon HCI ( << HCI>> ). (Discovery) HCI MGMT . bluetoothd ( btmgmt) Start Discovery (transport) . : @ MGMT Command: Start Discovery (0x0023) plen 1 {0x0001} [hci0] 12:36:00.100200 Address type: 0x07 BR/EDR LE Public LE Random @ MGMT Event: Command Complete (0x0001) plen 5 {0x0001} [hci0] 12:36:00.100500 Start Discovery (0x0023) plen 2 Status: Success (0x00) Address type: 0x07 btmon HCI (LE Set Scan Parameters LE Set Scan Enable / Inquiry BR/EDR). MGMT : @ MGMT Event: Device Found (0x0012) plen 38 {0x0001} [hci0] 12:36:00.250003 LE Address: AA:BB:CC:DD:EE:FF (Random) RSSI: -62 Flags: 0x0000 EIR Data: Name (complete): My Device TX power: 0 : @ MGMT Command: Start Service Discovery (0x003a) plen 19 {0x0001} [hci0] 12:36:10.100200 Address type: 0x06 LE Public LE Random RSSI threshold: -127 UUIDs: 1 UUID: Heart Rate (0x180d) @ MGMT Event: Command Complete (0x0001) plen 5 {0x0001} [hci0] 12:36:10.100500 Start Service Discovery (0x003a) plen 2 Status: Success (0x00) : @ MGMT Command: Stop Discovery (0x0024) plen 1 {0x0001} [hci0] 12:36:15.200100 Address type: 0x07 @ MGMT Event: Command Complete (0x0001) plen 5 {0x0001} [hci0] 12:36:15.200400 Stop Discovery (0x0024) plen 2 Status: Success (0x00) @ MGMT Event: Discovering (0x0013) plen 2 {0x0001} [hci0] 12:36:15.200500 Address type: 0x07 Discovery: Disabled (0x00) : o Status: Busy (0x0a) Start Discovery -- . o Status: Not Powered (0x0f) -- . o Status: RFKilled (0x12) -- rfkill . o Device Found -- . MGMT (Pairing and Bonding via MGMT) MGMT . Pair Device SMP SSP . : @ MGMT Command: Pair Device (0x0019) plen 8 {0x0001} [hci0] 12:37:00.500200 LE Address: AA:BB:CC:DD:EE:FF (Random) Capability: KeyboardDisplay (0x04) btmon SMP SSP ( << SMP>> << HCI>> ). : @ MGMT Event: User Confirmation Request (0x000f) plen 12 {0x0001} [hci0] 12:37:01.200100 LE Address: AA:BB:CC:DD:EE:FF (Random) Value: 123456 @ MGMT Command: User Confirmation Reply (0x001e) plen 6 {0x0001} [hci0] 12:37:03.800200 LE Address: AA:BB:CC:DD:EE:FF (Random) @ MGMT Event: Command Complete (0x0001) plen 10 {0x0001} [hci0] 12:37:03.800350 User Confirmation Reply (0x001e) plen 7 Status: Success (0x00) (passkey): @ MGMT Event: User Passkey Request (0x0010) plen 6 {0x0001} [hci0] 12:37:01.200100 LE Address: AA:BB:CC:DD:EE:FF (Random) @ MGMT Command: User Passkey Reply (0x0020) plen 10 {0x0001} [hci0] 12:37:05.100200 LE Address: AA:BB:CC:DD:EE:FF (Random) Passkey: 123456 : @ MGMT Event: New Long Term Key (0x000a) plen 37 {0x0001} [hci0] 12:37:06.100200 Store hint: Yes (0x01) LE Address: AA:BB:CC:DD:EE:FF (Random) Key type: Authenticated P-256 (0x03) Central: 0x00 Encryption size: 16 @ MGMT Event: New Identity Resolving Key (0x0018) plen 30 {0x0001} [hci0] 12:37:06.100300 Store hint: Yes (0x01) Random address: AA:BB:CC:DD:EE:FF LE Address: 11:22:33:44:55:66 (Public) Key: 00112233445566778899aabbccddeeff @ MGMT Event: Command Complete (0x0001) plen 10 {0x0001} [hci0] 12:37:06.100500 Pair Device (0x0019) plen 7 Status: Success (0x00) LE Address: AA:BB:CC:DD:EE:FF (Random) : o New Long Term Key Store hint: Yes -- . o New Identity Resolving Key -- (RPA) . . o Key type -- Authenticated P-256 (Secure Connections) MITM . Unauthenticated P-256 Just Works SC . Authenticated ( P-256) (Legacy) MITM . : @ MGMT Event: Command Complete (0x0001) plen 10 {0x0001} [hci0] 12:37:06.100500 Pair Device (0x0019) plen 7 Status: Authentication Failed (0x05) LE Address: AA:BB:CC:DD:EE:FF (Random) MGMT: +-------+--------------------+-----------------------------+ | | | | | | | | +-------+--------------------+-----------------------------+ |0x03 | Failed | | | | | | | | | SMP | | | | HCI | | | | | | | | | | | | | +-------+--------------------+-----------------------------+ |0x04 | Connect Failed | | | | | | | | | | | | | | | | | | +-------+--------------------+-----------------------------+ |0x05 | Authentication | | | | Failed | SMP SSP | | | | | | | | | | | | SMP Pairing Failed | | | | HCI | | | | Authentication Failure | | | | | | | | | +-------+--------------------+-----------------------------+ |0x08 | Timeout | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | +-------+--------------------+-----------------------------+ |0x0b | Rejected | | | | | | | | | | | | | | | | | | +-------+--------------------+-----------------------------+ |0x0d | Invalid Parameters | | | | | | | | | | | | | (capability) | | | | | | | | Pair | | | | Device | +-------+--------------------+-----------------------------+ (Device Connection and Disconnection) MGMT HCI . : @ MGMT Event: Device Connected (0x000b) plen 13 {0x0001} [hci0] 12:36:18.974319 LE Address: AA:BB:CC:DD:EE:FF (Random) Flags: 0x0000 EIR Data Length: 0 HCI LE (Enhanced) Connection Complete . . : @ MGMT Event: Device Disconnected (0x000c) plen 8 {0x0001} [hci0] 12:38:20.500200 LE Address: AA:BB:CC:DD:EE:FF (Random) Reason: Connection timeout (0x01) MGMT: +-------+---------------------+-----------------------+ | | | | | | | | +-------+---------------------+-----------------------+ |0x00 | Unspecified | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | +-------+---------------------+-----------------------+ |0x01 | Connection timeout | | | | | | | | | | | | | (link | | | | supervision timeout) | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | +-------+---------------------+-----------------------+ |0x02 | Connection | | | | terminated by local | | | | host | | | | | | | | | | | | | | | | | | +-------+---------------------+-----------------------+ |0x03 | Connection | | | | terminated by | | | | remote host | | | | | | | | | | | | | | | | | | +-------+---------------------+-----------------------+ Unpair Device : @ MGMT Command: Unpair Device (0x001a) plen 7 {0x0001} [hci0] 12:39:00.100200 LE Address: AA:BB:CC:DD:EE:FF (Random) Disconnect: Enabled (0x01) @ MGMT Event: Command Complete (0x0001) plen 10 {0x0001} [hci0] 12:39:00.100500 Unpair Device (0x001a) plen 7 Status: Success (0x00) MGMT (Advertising via MGMT) BlueZ HCI LE MGMT . (multi-client) . : @ MGMT Command: Add Advertising (0x003e) plen 22 {0x0001} [hci0] 12:40:00.100200 Instance: 1 Flags: 0x0006 The connectable flag will be managed The limited discoverable flag will be managed Duration: 0 Timeout: 0 Advertising data length: 6 Scan response length: 0 @ MGMT Event: Command Complete (0x0001) plen 5 {0x0001} [hci0] 12:40:00.100500 Add Advertising (0x003e) plen 2 Status: Success (0x00) Instance: 1 : @ MGMT Command: Remove Advertising (0x003f) plen 1 {0x0001} [hci0] 12:41:00.100200 Instance: 1 @ MGMT Event: Command Complete (0x0001) plen 5 {0x0001} [hci0] 12:41:00.100500 Remove Advertising (0x003f) plen 2 Status: Success (0x00) Instance: 1 HCI MGMT << (ADVERTISING AND SCANNING)>> . (Error Diagnosis) MGMT Command Status Command Complete HCI . . MGMT error in Command Complete: @ MGMT Event: Command Complete (0x0001) plen 4 {0x0001} [hci0] 12:42:00.100200 Set Powered (0x0005) plen 1 Status: RFKilled (0x12) MGMT Command Status ( / asynchronous): @ MGMT Event: Command Status (0x0002) plen 3 {0x0001} [hci0] 12:42:01.100200 Start Discovery (0x0023) plen 0 Status: Busy (0x0a) MGMT: +-------+--------------------+--------------------------------+ | | | | | | | | +-------+--------------------+--------------------------------+ |0x00 | Success | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x01 | Unknown Command | | | | | | | | | | | | | | | | | MGMT | | | | | +-------+--------------------+--------------------------------+ |0x02 | Not Connected | | | | | | | | | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x03 | Failed | | | | | | | | | | | | | HCI | | | | | | | | | +-------+--------------------+--------------------------------+ |0x04 | Connect Failed | | | | | | | | | HCI | | | | | +-------+--------------------+--------------------------------+ |0x05 | Authentication | | | | Failed | | | | | | | | | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x06 | Not Paired | | | | | | | | | (bond) | | | | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x07 | No Resources | | | | | | | | | | | | | ( | | | | | | | | ) | +-------+--------------------+--------------------------------+ |0x08 | Timeout | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x09 | Already Connected | | | | | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x0a | Busy | | | | | | | | | | | | | ( | | | | | | | | ) | +-------+--------------------+--------------------------------+ |0x0b | Rejected | | | | | | | | | | | | | | | | | | | | | (policy) | +-------+--------------------+--------------------------------+ |0x0c | Not Supported | | | | | | | | | | | | | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x0d | Invalid Parameters | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x0e | Disconnected | | | | | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x0f | Not Powered | | | | | | | | | Set Powered | | | | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x10 | Cancelled | | | | | | | | | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x11 | Invalid Index | | | | | | | | | | +-------+--------------------+--------------------------------+ |0x12 | RFKilled | | | | | rfkill | | | | | | | | rfkill unblock bluetooth | | | | | | | | | +-------+--------------------+--------------------------------+ |0x13 | Already Paired | | | | | | | | | | | | | | | | | | | | | | | | | | | | | unpair | | | | | +-------+--------------------+--------------------------------+ |0x14 | Permission Denied | | | | | | | | | | | | | | | | | (CAP_NET_ADMIN) | +-------+--------------------+--------------------------------+ MGMT HCI: MGMT Failed (0x03) Authentication Failed (0x05) HCI MGMT . HCI ( Authentication Failure (0x05) Connection Timeout (0x08)) . MGMT (Automating MGMT Analysis) MGMT: grep -n "@ MGMT" output.txt MGMT ( ): grep -n "@ MGMT" output.txt | grep -v "Status: Success" : grep -n "Set Powered\|RFKilled\|Not Powered" output.txt : grep -n "Start Discovery\|Stop Discovery\|Device Found\|Discovering" output.txt MGMT: grep -n "Pair Device\|User Confirmation\|User Passkey\|New Long Term Key\|New Identity Resolving Key\|Authentication Failed" output.txt : grep -n "Device Connected\|Device Disconnected\|Unpair Device" output.txt MGMT: grep -n "@ MGMT Open\|@ MGMT Close" output.txt MGMT: 1. MGMT Open -- bluetoothd 2. Read Controller Information -- 3. Set Powered -- 4. Success -- 5. Pair Device Command Complete 6. Device Connected/Device Disconnected (EXAMPLES) hci0 hcidump.log (Capture the traces from hci0 to hcidump.log file) $ btmon -i hci0 -w hcidump.log (Open the trace file) $ btmon -r hcidump.log (Open the trace file with wall-clock timestamps) $ btmon -t -r hcidump.log (Open the trace file with full date and time) $ btmon -T -r hcidump.log (AUTOMATED TRACE ANALYSIS) btmon . . (Recommended Workflow) 1. : btmon -a . 2. : btmon -t -r > output.txt . 3. : : grep -n "Connection Complete\|Enhanced Connection Complete\|CIS Established" output.txt 4. : : grep -n "Disconnect Complete" output.txt Reason: . << HCI>> (HCI ERROR AND DISCONNECT REASON CODES) . 5. /: SMP ( << SMP>> (SMP PAIRING FLOW) ): grep -n "Pairing Request\|Pairing Response\|Pairing Failed\|Encryption Change" output.txt 6. LE Audio: ASCS CIS ( << LE AUDIO>> (LE AUDIO PROTOCOL FLOW) ): grep -n "ASE Control Point\|CIG Parameters\|Create Connected Isochronous\|CIS Established\|Setup ISO Data Path" output.txt 7. : ( << >> (PROTOCOL ERROR CODES) ): # HCI-level errors grep -n "Status:" output.txt | grep -v "Success" # ATT-level errors grep -n "Error Response" output.txt # SMP failures grep -n "Pairing Failed" output.txt # L2CAP rejections grep -n "Connection refused" output.txt 8. GATT: / GATT ( << GATT SNOOP>> (RECONSTRUCTING A GATT DATABASE FROM SNOOP TRACES) ): # Find all service discovery responses grep -n "Read By Group Type Response\|Attribute group list\|Handle range.*UUID" output.txt # Find all characteristic discovery responses grep -n "Read By Type Response\|Properties:\|Value Handle:\|Value UUID:" output.txt # Find all descriptor discovery responses grep -n "Find Information Response\|Format:\|Handle:.*UUID:" output.txt # Find targeted service searches grep -n "Find By Type Value" output.txt 9. L2CAP: ( << L2CAP>> (L2CAP CHANNEL TRACKING) ): grep -n "PSM:\|Connection Request\|Connection Response\|Parameter Update" output.txt 10. (Advertising): ( << >> (ADVERTISING AND SCANNING) ): grep -n "Advertising Report\|Name (complete):\|Appearance:" output.txt (Key Patterns for Connection Lifecycle) LE ACL : 1. LE Enhanced Connection Complete -- Handle Peer . 2. LE Connection Update Complete -- ( ). 3. Encryption Change -- ( ). SMP << SMP>> (SMP PAIRING FLOW) . 4. ACL ATT/SMP/L2CAP -- . GATT << GATT SNOOP>> (RECONSTRUCTING A GATT DATABASE FROM SNOOP TRACES) << L2CAP>> (L2CAP CHANNEL TRACKING) << >> (PROTOCOL ERROR CODES) . 5. Disconnect Complete -- Reason . << HCI>> (HCI ERROR AND DISCONNECT REASON CODES) . LE Audio ( << LE AUDIO>> (LE AUDIO PROTOCOL FLOW) ): o ATT PACS/ASCS ( ) o LE Set CIG Parameters o LE Create CIS o LE CIS Established ( CIS ) o LE Setup ISO Data Path o ISO Data TX/RX ( ) o Disconnect Complete CIS ( ) o LE Remove CIG ( ) (Common Debugging Scenarios) : 1. Pairing Request -- IO . 2. Pairing Response -- . 3. Pairing Failed ( << SMP>> (SMP PAIRING FLOW) ). 4. Encryption Change Status: Success . 5. SMP Encryption Change (bond) . ( << LE AUDIO>> (LE AUDIO PROTOCOL FLOW) ): 1. PACS -- 2. ASE Control Point Config Codec -- 3. ASE -- ASE Streaming 4. CIS Established -- Status Success 5. Setup ISO Data Path -- 6. ISO Data -- GATT ( << >> (PROTOCOL ERROR CODES) ): 1. Error Response -- . 2. Insufficient Encryption (0x0f) -> LE Start Encryption . 3. Authentication Insufficient (0x05) -> SMP . 4. ATT . : 1. Connection Parameter Update Request ( L2CAP). 2. (Response) -- rejected . 3. LE Connection Update Complete ( HCI). 4. (Status) -- . (Vendor-Specific Events) HCI ( 0xFF) . btmon (Intel Broadcom ) Unknown . . Intel ( 0x8780) (firmware) . monitor/intel.c . (RESOURCES) (REPORTING BUGS) (SEE ALSO) btsnoop(7) (AUTHORS) Marcel Holtmann , Tedd Ho-Jeong An (COPYRIGHT) (LGPL) . BlueZ April 2021 btmon(1)