Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-13 Thread Sultan Khan via tcpdump-workers
--- Begin Message --- I think so, based on what Chris said previously about those BT related spec pages hosted on his site. The link type list page should probably be updated to point to the tcpdump.org version of the LINKTYPE_BLUETOOTH_BREDR_BB spec. Sultan >> On Jul 13, 2020, at 3:20 PM, Guy

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-13 Thread Guy Harris via tcpdump-workers
--- Begin Message --- On Jul 13, 2020, at 8:09 AM, Sultan Khan wrote: > Hmm. Chris Kilgour (whiterocker) originally created the spec, and the version > on tcpdump.org was just a backup copy. Now, Chris has said that he is no > longer active in the Bluetooth LE sniffing space, and he doesn’t wan

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-13 Thread Sultan Khan via tcpdump-workers
ultan Khan > To: Guy Harris > Cc: Chris Kilgour , tcpdump-workers < > tcpdump-workers@lists.tcpdump.org>, Joakim Andersson < > joakim.anders...@nordicsemi.no>, virtual...@gmail.com > Bcc: > Date: Mon, 13 Jul 2020 13:51:48 -0400 > Subject: Re: [tcpdump-workers] Propos

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-13 Thread Sultan Khan via tcpdump-workers
--- Begin Message --- Correct, it's a superset of the old version. OK, I'll omit the link then. On Mon, Jul 13, 2020 at 1:11 PM Guy Harris wrote: > On Jul 13, 2020, at 9:02 AM, Sultan Khan wrote: > > > Thanks Chris. I’ll make a pull request to tcpdump-htdocs later today, > and I’ll include a li

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-13 Thread Guy Harris via tcpdump-workers
--- Begin Message --- On Jul 13, 2020, at 9:02 AM, Sultan Khan wrote: > Thanks Chris. I’ll make a pull request to tcpdump-htdocs later today, and > I’ll include a link to the previous version of the spec as an archive.org > link to the old one on whiterocker.com. The new version is a superset

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-13 Thread Sultan Khan via tcpdump-workers
--- Begin Message --- Thanks Chris. I’ll make a pull request to tcpdump-htdocs later today, and I’ll include a link to the previous version of the spec as an archive.org link to the old one on whiterocker.com. Cheers, Sultan >>> On Jul 13, 2020, at 11:54 AM, Chris Kilgour wrote: >> On 2020-07

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-13 Thread Sultan Khan via tcpdump-workers
--- Begin Message --- Hmm. Chris Kilgour (whiterocker) originally created the spec, and the version on tcpdump.org was just a backup copy. Now, Chris has said that he is no longer active in the Bluetooth LE sniffing space, and he doesn’t want to be in charge of the spec any more. Perhaps the sp

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-13 Thread Guy Harris via tcpdump-workers
--- Begin Message --- On Jul 10, 2020, at 2:57 PM, Sultan Khan wrote: > Link to the updated version of the spec with the latest changes: > https://gistcdn.githack.com/sultanqasim/8b6561309f5934f084a0d938ae733b7a/raw/199fb1867642c927f768fe7d67dae2a639acb48e/LINKTYPE_BLUETOOTH_LE_LL_WITH_PHDR.html

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-10 Thread Sultan Khan via tcpdump-workers
--- Begin Message --- The reason the extra auxiliary PDU type field is needed is that the four-bit auxiliary PDU type is ambiguous and context-dependent for auxiliary PDUs. See Volume 6, Part B, Section 2.3, Table 2.3. The four least significant bits of the advertising PDU header will be 0b0111 for

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-10 Thread Guy Harris via tcpdump-workers
--- Begin Message --- For an advertising physical channel PDU, it appears that the PDU type is in the least-significant 4 bits of the PDU header. Is that not present in an auxiliary advertising packet?--- End Message --- ___ tcpdump-workers mailing list

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-10 Thread Sultan Khan via tcpdump-workers
--- Begin Message --- Thanks for the feedback, your suggestions do make the specification clearer. I edited the specification based on your suggestions, and I also clarified the usage of integer bit fields within the Flags field. Link to the updated version of the spec with the latest changes: htt

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-10 Thread Guy Harris via tcpdump-workers
--- Begin Message --- A couple more editorial comments: In the description of the bits in the Flags field, I'd describe the 0x3000 bits as "PDU type dependent", and, after they're listed indicate that: For PDU types other than type 1 (auxiliary advertising), the PDU type dependent field

[tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-10 Thread Sultan Khan via tcpdump-workers
--- Begin Message --- Hello all, DLT_BLUETOOTH_LE_LL_WITH_PHDR was created close to a decade ago mainly to support Bluetooth LE sniffers. It includes parameters describing sniffer RF capture settings in addition to the BLE link layer packet. It was created in the days of Bluetooth 4.0, when BLE wa

Re: [tcpdump-workers] Proposed update to DLT_BLUETOOTH_LE_LL_WITH_PHDR

2020-07-09 Thread Guy Harris via tcpdump-workers
--- Begin Message --- On Jul 9, 2020, at 1:46 PM, Sultan Khan wrote: > Through discussions with Joakim Anderson (of Nordic) and Mike Ryan (Ubertooth > developer), and going through several iterations of proposed protocol > updates, I/we came up with this: > https://gistcdn.githack.com/sultanqa