# bellisys **Repository Path**: GeekKernel/bellisys ## Basic Information - **Project Name**: bellisys - **Description**: No description available - **Primary Language**: Unknown - **License**: Not specified - **Default Branch**: master - **Homepage**: None - **GVP Project**: No ## Statistics - **Stars**: 0 - **Forks**: 0 - **Created**: 2026-07-29 - **Last Updated**: 2026-09-15 ## Categories & Tags **Categories**: Uncategorized **Tags**: None ## README # Bellisys 抓包工具栏的 `Clear`(或 `File -> Clear all packets`)可清空所有设备的当前包数据及关联分析、 Marker、调试轨迹和时间线测量,保留 J-Link 连接和采集状态,无需重启软件即可继续抓取。 HCI/DLI、BT/BLE 表格的 `Length` 列及通用 `length` 查询采用包含协议头的协议包长度, 排除抓取封装、伪头和解析附加信息;不使用上层重组数据的长度。 空口表格新增 SLE `Packet Type` 和 `Empty` 列,解析详情显示字段含义。 `Empty` 列只显示 `empty` / `data`,数值 0/1 保留在详情中。 `Empty` 读取底层 SLAR `packet_flags` 的 bit0(0=数据包,1=空包), 不会将载荷长度为 0、Muted 或 Invalid 标志当作空包指示;缺失时显示未知。 SLE 时间线颜色使用相同指示:空包蓝色、数据包绿色、未知灰色,校验错误颜色优先。 SLE 表格 `Length` 显示物理层控制信息中声明的长度(L2),表头悬浮可查看口径;未上报时显示“—”。 SLE 的 `length` 查询仍表示 L1,查询 L2 使用 `controller_air.on_air_payload_length`。 SLE 详情区明确区分三层长度:L1 为协议 PDU 总长(归一化控制头 + 头后数据), L2 为 PHY 控制头声明的数据长度,L3 为控制包中 Opcode 后的一字节参数长度。 例如一个 A2 纯控制包:L3=18 B,控制 PDU 为 2+1+18=21 B,L2=21 B,L1=4+21=25 B。 实际捕获数据及采集描述符/PHY 附加信息单独标注;缺失的 L2 声明在导出后仍保持未知。 ## J-Link 实时采集 底部 `Capture quality` 页提供按设备的包速率、上报序号缺口、控制器丢弃数、CRC 错误、 解析错误及队列状态,也可从 `File -> Capture quality and automatic save…` 打开。 实时协议解码与事务匹配在后台按批次处理,默认显示最近 10,000 个包,包与解析结果的 估算缓存上限为 128 MiB。默认自动保存所有已接收进入队列的包、调试文本和活动区间, 按 64 MiB 或 5 分钟切分 pcapng 文件;可以在该页面选择保存目录、调整限制并打开文件。 普通导出使用当前显示缓存和过滤条件,完整历史请查看自动保存目录。 参数在 `Clear` 或下一次新采集时生效,已保存文件不会被自动删除。 主窗口顶部的齿轮、播放和停止按钮分别用于配置、启动和停止 J-Link 实时采集;也可从 `File` 菜单操作。Bellisys 可同时打开最多 3 个 J-Link,直接从每个目标的 `SysView` RTT 通道读取 custom event 186/187/188,并实时显示 AIR、HCI/DLI 包和调试文本轨道。 配置窗口可扫描 USB J-Link 并自动填入序列号,target device 默认为 `Cortex-M33`。 同一 J-Link 的三类流由同一个 RTT 读取器分流并使用同一 controller 时间域;此路径 不依赖逻辑分析仪。每个 J-Link 按用户别名显示设备 Tab,其下分别提供 HCI/DLI 和 空口两个子 Tab,并可将当前设备的两类流单独保存为一个 pcapng。配置、固件约定和 C++ 接口见 [`docs/jlink-live-capture.md`](docs/jlink-live-capture.md)。 `File -> Open multi J-Link RTT Logger...` 可同时显示 3 个探针的 Terminal/Logger RTT 文本通道。Logger 与实时抓包共享每个槽位唯一的 J-Link 会话和通道读取者,支持 按来源暂停、清空、搜索、关键字高亮与文本导出。 SystemView 控制命令在 RTT Down Buffer 忙时会有界重试,并对快速启停产生的旧命令 进行合并/淘汰;SystemView 与 Logger 通道独立降级和自动重发现,单项读写错误不会再 连带断开另一项采集,只有连续的 J-Link/目标健康检查失败才关闭整个槽位。 RTT/SystemView 尚未就绪时会按槽位持续重试并周期性刷新 RTT 搜索;重复点击连接按钮 不会断开配置未改变且采集正常的 J-Link,只会重试失败的槽位。 每个槽位的 J-Link DLL/RTT 会话运行在独立工作进程中;多台同时连接时会自动调整探针 打开顺序,以兼容短序列号旧探针对后续 RTT 会话的影响。 Bellisys 每次启动都会在用户本地应用数据目录的 `logs` 子目录创建独立 UTF-8 诊断日志。J-Link 配置/连接/启动/停止等 UI 操作、连接状态变化、DLL 加载结果及 底层 J-Link API 返回值都会自动记录;通过 `File -> Open diagnostic log folder...` 可直接打开本次运行日志所在目录。 Qt 6 Bluetooth/SLE capture analyzer. The native capture format is pcapng. Current scope: - pcapng import for `LINKTYPE_BLUETOOTH_HCI_H4` (187) and `LINKTYPE_BLUETOOTH_HCI_H4_WITH_PHDR` (201) - btsnoop v1 import for HCI (1001), UART/H4 (1002) and BlueZ Monitor (2001) datalinks - BlueZ/Linux Monitor HCI packet normalization (link type 254) - stateful HCI Command/Event correlation, connection tracking and ACL reassembly - structured BR/EDR Link Control/Policy, Controller/Baseband, security, Information/Status command and return decoding; classic inquiry, synchronous link, SSP/OOB, link-quality, AMP and connectionless-broadcast events are decoded with BlueZ 5.87-compatible length validation - BlueZ monitor-derived parameter decoding for common LE commands and events, including extended advertising parameters/data/enable, advertising-data structures, PHY/data-length events and completed-packet accounting - BlueZ-style HCI opcode registry carrying command/response length rules and decoder callbacks; BLE 5.x coverage includes resolving/privacy lists, periodic advertising and transfer, extended scanning, CIS/BIG events, ISO data headers and ISO data-path setup; Bluetooth power control, connection subrating and PAwR fields are decoded through their command/response/events - Channel Sounding command coverage includes capabilities, FAE, security, configuration, procedure control and test opcodes; CS result steps expose mode/channel data plus quality, NADM, RSSI, ToA/ToD, PCT I/Q and tone quality - BLE air LL Control coverage extends through power control, connection subrating, channel reporting, extended feature pages, CIS establishment and the Channel Sounding security/capability/configuration/procedure PDUs - BlueZ 5.87 monitor-derived L2CAP dispatch/validation, ATT, SMP, SDP, RFCOMM and AVDTP signaling decoding - capture-wide classic Bluetooth SDP database reconstruction, grouped by controller, ACL connection and local/remote SDP server, with service record, class, name and protocol/profile attribute trees - L2CAP configuration options and LE CoC/ECRED signaling fields; recursive SDP data elements, continuation reassembly and named service attributes - RFCOMM SABM/UA/DISC/UIH and MCC parameter decoding (PN/RPN/MSC/RLS/NSC) uses an Ellisys-style Information/Header/Message/FCS tree, printable SPP payloads, credit/DLC state, GSM 07.10 FCS validation and transaction grouping - stateful SMP pairing/Secure Connections phases and negotiated key distribution; AVDTP signaling reassembly, endpoint/configuration/stream state, SBC/MPEG/AAC/ATRAC/vendor codecs and RTP media headers - BlueZ-compatible A2DP capability/configuration detail for SBC, MPEG-1/2, AAC, aptX, aptX HD/Low Latency, FastStream, LDAC and Google Opus; AVDTP accept/reject correlation, error codes, security control and delay reports - SMP EDIV/Rand, identity address, split P-256 public-key coordinates and keypress fields; learned IRK/identity pairs resolve subsequent LE RPAs using the Bluetooth `ah` function - AVCTP fragmentation, AVRCP vendor-dependent metadata/browsing/pass-through, plus BNEP control, protocol/multicast filters and extension headers - stateful LE CoC channel credits and cross-PDU SDU reassembly, with completed SDUs dispatched back into ATT or the negotiated dynamic-PSM decoder - pcapng `LINKTYPE_BLUETOOTH_LE_LL_WITH_PHDR` air-interface decoding for RF metadata, access addresses, legacy/extended advertising and AD structures, data-channel headers, LL Control PDUs, stateful ACL/L2CAP reassembly and HCI-shared ATT/GATT decoding; the detailed BR/EDR and BLE data path is in [`docs/air-interface-decoding.md`](docs/air-interface-decoding.md) - controller-manufacturer learning from Read Local Version Information and Intel/Broadcom/Microsoft vendor-event selection with common Intel exception, boot, scan and trace fields plus Broadcom LM Diagnostic metadata - standalone HCI opcode registry infrastructure for command/response metadata and decoder callbacks - passive GATT database reconstruction from ATT discovery traffic, including standard service/characteristic names, characteristic capabilities and permission requirements observed through ATT errors - standard GATT value interpretation for common strings, Battery Level, Client Characteristic Configuration, Service Changed, Heart Rate, GAP connection preferences, robust-caching features, Database Hash, HID report metadata/protocol mode and Device Information PnP/System ID values - dedicated Air Interface overview with channel, RSSI, access-address and CRC/MIC columns plus an independent BT/BLE/NearLink layer ribbon for Link Layer, L2CAP, SMP, ATT and service-database navigation; protocol layers use the same collapsed transaction/packet hierarchy, node styling, selection synchronization and expand/collapse context menu as HCI/DLI, while AIR packets open chronologically with the oldest packet at the top. The AIR L2CAP layer remains layer-pure: each SDU expands through B-Frame and LE-U/ Link-Layer nodes, while ATT/SMP request-response pairing stays in its own higher-layer view - compiled field queries shared by filtering and previous/next search, including decoded-field paths, numeric/hex comparisons, text/regular-expression matching and Boolean expressions - a single Query can run in Filter display mode (hide non-matches) or Highlight matches mode (keep every packet in the current layer and color matching rows); the highlight color is customizable and persisted with workspace/analysis - Global text mode filters the active HCI/DLI or Air packet tab with a case-insensitive literal search across table values, raw/display hex, decoded names, field values, descriptions and capture metadata; hex text can be entered in compact or separated form - grouped HCI and ATT/SDP/AVDTP transactions plus reassembly groups with request/response status, timing and expandable protocol/transport source paths; SDP, RFCOMM and related profile traffic expands through its semantic PDU, L2CAP/DTAP SDU and frame, down to the originating HCI/DLI packet - stateful NearLink DLI -> DTAP -> SSAP decoding aligned with the SSAP specification: DLI/DTAP/SSAP fragmentation, DTAP basic/reliable/ aggregate/ACK frames, all standard SSAP message codes, v1.2 transaction control, request/response aggregation and a reconstructed SSAP service database with standard service/property names and observed requirements - NearLink packed-field detail for DLI schema bitmaps and feature sets, pairing authentication/algorithm fields, DTAP P/F/S/SAR/sequence bits, SSAP access-control and descriptor configuration bits, plus LWCLTP v1 version/option-length, port, option-bitmap and payload-length decoding; NearLink HID report maps and 8-byte report-index values are interpreted too - NearLink business-layer HID and Audio views built from the reconstructed SSAP handle/UUID/service relationships. HID parses captured USB HID Report Descriptors (with compatible NearLink mouse/keyboard fallbacks) and expands input/output/feature reports into buttons, signed axes, modifiers and key usages. BLE HOGP uses the same decoder: captured Report Map and Report Reference values are associated with each `0x2A4D` characteristic, and the decoded controls appear inline below the original ATT Attribute Value. Audio reconstructs ASC/MCP/VCP/CCP/CDSM profiles, pairs SSAP requests with responses and nearby state notifications, names the user-visible action and explains its purpose and result. Service discovery is promoted to the discovered audio profile instead of remaining a generic packet. This is control/status analysis; synchronous elementary audio-stream payload decoding remains separate from SSAP/DLI - SSAP packet summaries put the terminal operation first, for example `[SSAP Read Request: 0X0013 (Remaining Battery Percentage)]`, before the underlying DLI/DTAP transport description - capture-wide `Service Database` overview combines link-based classic SDP, HCI-side BLE GATT, NearLink SSAP and GATT discovery reconstructed directly from ATT air traffic. HCI/DLI and AIR databases live under separate source roots, each with Classic Bluetooth, BLE and NearLink service-family children. Advertising UUIDs remain packet-detail information and are not promoted into the Service Database; database state is preserved for asynchronous pcapng/btsnoop file loading as well as built-in captures - compact standalone HCI/DLI protocol-layer ribbon inside the HCI/DLI tab: BT/BLE packet, command/event, transaction and profile icons are grouped separately from SLE DLI/DTAP/SSAP icons on one row; the Air Interface has a parallel ribbon split into BT/BLE AIR and NearLink AIR groups. Captions and availability move to hover, available layers are colored, unavailable layers are gray, and clicking an icon switches to its packet, transaction or database view. In NearLink DLI, `DLI` means the A1 command/A2 event stream while `CTL` is restricted to Set Controller Control Data (`0x1812`) and Controller Control Data (`0x0014`). NearLink AIR `CTL` matches packet-type indication 3 only. BLE `LL` excludes the advertising access address; classic BT `LL` requires CAC/connection identity metadata so inquiry/page traffic is not silently treated as an established link - configurable protocol-verification registry with field-level decoder errors, capture truncation, air CRC/MIC/access-address checks, ATT errors and unmatched transaction detection - field tree, linked hexadecimal view and a dynamic multi-track timeline for HCI OUT/IN, BLE advertising, LL control and air data TX/RX - bottom Timing/Audio tabs: the Audio page groups A2DP RTP media by connection, direction and SSRC, validates SBC frames, and shows simultaneous per-device tracks with peer/handle/codec information; playback position is mapped from cumulative audio samples into the green capture-time segments so gaps remain gaps. Play, pause, stop and seek use the Qt multimedia backend for SBC, while unsupported codecs retain a clearly labelled timeline-only simulation - decoded field trees start fully collapsed and provide context-menu commands to expand every branch by one or two levels, expand/collapse the complete tree, or expand/collapse only the selected branch; verification severity no longer changes the expansion state automatically; the Details-panel Expand button expands the complete tree - timeline A/B measurement cursors, selectable time reference, colored markers, packet hover details, marker/transaction range navigation and synchronized selection across all views; packet tables use a dedicated leading Mark column with a local color swatch, double-clicking a marker jumps to its packet, and packet details show marker colors and notes with full hover text; one editor handles the marker name, note and custom color, and the Markers tab exposes the same editing actions from its context menu - direction-based packet-row coloring: Host to Controller uses pale pink and Controller to Host uses light blue; verification severity remains visible in the text color while marker color remains confined to the Mark column - analysis-project JSON persistence for colored markers and notes, query and verification-rule selection - export of filtered HCI packets to btsnoop UART/H4 and filtered mixed HCI/air captures to interoperable pcapng - an offline Chinese operation guide is available from **Help / 中文操作说明** (F1), with a dedicated display-filter syntax and troubleshooting section ## BLE air demo Open `samples/ble_air_demo.pcapng`, or choose **File → Open built-in BLE air demo**. The capture contains HCI command correlation, advertising/scan/connect traffic, LL length negotiation, ATT MTU and Read transactions, SMP pairing, multiple RF channels/RSSI values and one intentional CRC failure. It exercises the Air Interface, per-protocol transaction flows, Service Database and multi-track Timeline views. Useful queries: ```text protocol == AIR && rf.channel == 37 protocol == AIR && rf.rssi < -70 att.opcode == 0x0a || smp.code == 0x01 severity >= warning ll.crc_valid == false summary contains "MTU" ``` ## Controller AIR reconstruction demo Choose **File → Open built-in controller AIR reconstruction demo**, or open `samples/controller_air_reconstruction_demo.pcapng`. RX packets are marked as measured, TX descriptor candidates as reconstructed, and the final SLE entry as an inferred gate-only timestamp with no invented payload or duration. The Details tree and Timeline use different evidence labels/borders so the sample also documents what the tool knows versus what it only estimates. ## NearLink DLI demo Open `samples/nearlink_dli_demo.pcapng` to exercise A1 command, A2 event, A3 asynchronous unicast, A4 synchronous unicast and A5 asynchronous multicast decoding. The A3 traffic includes SSAP Battery, HID and MCP service discovery, a v1.2 transaction-numbered battery read, a HID mouse report, MCP Play and playback-state operations, a write transaction and DLI-fragmented DTAP/SSAP reassembly. Select an SSAP item to inspect the reconstructed service database in the field view, or use the NearLink HID/Audio icons for business-level views. The DLI field catalog is synchronized at build/package time from `E:\work_repo\bt_sle_repo\sle_decode\data\dli_command_schemas.json`; the packaged copy is self-contained under `dist\data`. Supported query operators are `==`, `!=`, `<`, `<=`, `>`, `>=`, `contains`, `~=` (regular expression), `!`, `&&`, `||` and parentheses. Adjacent search terms imply AND; `*` and `?` are accepted in equality values. Right-click a decoded field to create Keep, Exclude or Search queries. A bare decoded-field path, such as `(l2cap.sdp.pdu)`, tests whether that field exists; other bare words continue to perform a full-text search. Build with the configured Qt 6.7.2 MinGW toolchain: ```powershell powershell -ExecutionPolicy Bypass -File .\build.ps1 ``` Create a tested Release deployment in `dist`: ```powershell powershell -ExecutionPolicy Bypass -File .\package.ps1 ``` The package includes `dist\samples\ble_air_demo.pcapng`, `dist\samples\nearlink_dli_demo.pcapng`, and `dist\samples\controller_air_reconstruction_demo.pcapng`. All three are also available directly from the **File** menu without reading an external file. BlueZ 5.87 `monitor` is the primary behavioral reference for Host-side HCI protocol layering. Code copied or adapted from BlueZ must retain its LGPL-2.1-or-later notices; see [THIRD_PARTY_NOTICES.md](THIRD_PARTY_NOTICES.md). The pcapng interoperability profile and the reserved DLI/SLE extension header are documented in [docs/capture-format.md](docs/capture-format.md).