advtest.c 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417
  1. // SPDX-License-Identifier: GPL-2.0-or-later
  2. /*
  3. *
  4. * BlueZ - Bluetooth protocol stack for Linux
  5. *
  6. * Copyright (C) 2011-2012 Intel Corporation
  7. * Copyright (C) 2004-2010 Marcel Holtmann <marcel@holtmann.org>
  8. *
  9. *
  10. */
  11. #ifdef HAVE_CONFIG_H
  12. #include <config.h>
  13. #endif
  14. #include <getopt.h>
  15. #include "lib/bluetooth.h"
  16. #include "lib/mgmt.h"
  17. #include "monitor/bt.h"
  18. #include "src/shared/mainloop.h"
  19. #include "src/shared/util.h"
  20. #include "src/shared/mgmt.h"
  21. #include "src/shared/hci.h"
  22. #include "src/shared/crypto.h"
  23. #define PEER_ADDR_TYPE 0x00
  24. #define PEER_ADDR "\x00\x00\x00\x00\x00\x00"
  25. #define ADV_IRK "\x69\x30\xde\xc3\x8f\x84\x74\x14" \
  26. "\xe1\x23\x99\xc1\xca\x9a\xc3\x31"
  27. #define SCAN_IRK "\xfa\x73\x09\x11\x3f\x03\x37\x0f" \
  28. "\xf4\xf9\x93\x1e\xf9\xa3\x63\xa6"
  29. static struct mgmt *mgmt;
  30. static uint16_t index1 = MGMT_INDEX_NONE;
  31. static uint16_t index2 = MGMT_INDEX_NONE;
  32. static struct bt_crypto *crypto;
  33. static struct bt_hci *adv_dev;
  34. static struct bt_hci *scan_dev;
  35. static void print_rpa(const uint8_t addr[6])
  36. {
  37. printf(" Address: %02x:%02x:%02x:%02x:%02x:%02x\n",
  38. addr[5], addr[4], addr[3],
  39. addr[2], addr[1], addr[0]);
  40. printf(" Random: %02x%02x%02x\n", addr[3], addr[4], addr[5]);
  41. printf(" Hash: %02x%02x%02x\n", addr[0], addr[1], addr[2]);
  42. }
  43. static void scan_le_adv_report(const void *data, uint8_t size,
  44. void *user_data)
  45. {
  46. const struct bt_hci_evt_le_adv_report *evt = data;
  47. if (evt->addr_type == 0x01 && (evt->addr[5] & 0xc0) == 0x40) {
  48. uint8_t hash[3], irk[16];
  49. memcpy(irk, ADV_IRK, 16);
  50. bt_crypto_ah(crypto, irk, evt->addr + 3, hash);
  51. if (!memcmp(evt->addr, hash, 3)) {
  52. printf("Received advertising report\n");
  53. print_rpa(evt->addr);
  54. memcpy(irk, ADV_IRK, 16);
  55. bt_crypto_ah(crypto, irk, evt->addr + 3, hash);
  56. printf(" -> Computed hash: %02x%02x%02x\n",
  57. hash[0], hash[1], hash[2]);
  58. mainloop_quit();
  59. }
  60. }
  61. }
  62. static void scan_le_meta_event(const void *data, uint8_t size,
  63. void *user_data)
  64. {
  65. uint8_t evt_code = ((const uint8_t *) data)[0];
  66. switch (evt_code) {
  67. case BT_HCI_EVT_LE_ADV_REPORT:
  68. scan_le_adv_report(data + 1, size - 1, user_data);
  69. break;
  70. }
  71. }
  72. static void scan_enable_callback(const void *data, uint8_t size,
  73. void *user_data)
  74. {
  75. }
  76. static void adv_enable_callback(const void *data, uint8_t size,
  77. void *user_data)
  78. {
  79. struct bt_hci_cmd_le_set_scan_parameters cmd4;
  80. struct bt_hci_cmd_le_set_scan_enable cmd5;
  81. cmd4.type = 0x00; /* Passive scanning */
  82. cmd4.interval = cpu_to_le16(0x0010);
  83. cmd4.window = cpu_to_le16(0x0010);
  84. cmd4.own_addr_type = 0x00; /* Use public address */
  85. cmd4.filter_policy = 0x00;
  86. bt_hci_send(scan_dev, BT_HCI_CMD_LE_SET_SCAN_PARAMETERS,
  87. &cmd4, sizeof(cmd4), NULL, NULL, NULL);
  88. cmd5.enable = 0x01;
  89. cmd5.filter_dup = 0x01;
  90. bt_hci_send(scan_dev, BT_HCI_CMD_LE_SET_SCAN_ENABLE,
  91. &cmd5, sizeof(cmd5),
  92. scan_enable_callback, NULL, NULL);
  93. }
  94. static void adv_le_evtmask_callback(const void *data, uint8_t size,
  95. void *user_data)
  96. {
  97. struct bt_hci_cmd_le_set_resolv_timeout cmd0;
  98. struct bt_hci_cmd_le_add_to_resolv_list cmd1;
  99. struct bt_hci_cmd_le_set_resolv_enable cmd2;
  100. struct bt_hci_cmd_le_set_random_address cmd3;
  101. struct bt_hci_cmd_le_set_adv_parameters cmd4;
  102. struct bt_hci_cmd_le_set_adv_enable cmd5;
  103. cmd0.timeout = cpu_to_le16(0x0384);
  104. bt_hci_send(adv_dev, BT_HCI_CMD_LE_SET_RESOLV_TIMEOUT,
  105. &cmd0, sizeof(cmd0), NULL, NULL, NULL);
  106. cmd1.addr_type = PEER_ADDR_TYPE;
  107. memcpy(cmd1.addr, PEER_ADDR, 6);
  108. memset(cmd1.peer_irk, 0, 16);
  109. memcpy(cmd1.local_irk, ADV_IRK, 16);
  110. bt_hci_send(adv_dev, BT_HCI_CMD_LE_ADD_TO_RESOLV_LIST,
  111. &cmd1, sizeof(cmd1), NULL, NULL, NULL);
  112. cmd2.enable = 0x01;
  113. bt_hci_send(adv_dev, BT_HCI_CMD_LE_SET_RESOLV_ENABLE,
  114. &cmd2, sizeof(cmd2), NULL, NULL, NULL);
  115. bt_crypto_random_bytes(crypto, cmd3.addr + 3, 3);
  116. cmd3.addr[5] &= 0x3f; /* Clear two most significant bits */
  117. cmd3.addr[5] |= 0x40; /* Set second most significant bit */
  118. bt_crypto_ah(crypto, cmd1.local_irk, cmd3.addr + 3, cmd3.addr);
  119. bt_hci_send(adv_dev, BT_HCI_CMD_LE_SET_RANDOM_ADDRESS,
  120. &cmd3, sizeof(cmd3), NULL, NULL, NULL);
  121. printf("Setting advertising address\n");
  122. print_rpa(cmd3.addr);
  123. cmd4.min_interval = cpu_to_le16(0x0800);
  124. cmd4.max_interval = cpu_to_le16(0x0800);
  125. cmd4.type = 0x03; /* Non-connectable advertising */
  126. cmd4.own_addr_type = 0x03; /* Local IRK, random address fallback */
  127. cmd4.direct_addr_type = PEER_ADDR_TYPE;
  128. memcpy(cmd4.direct_addr, PEER_ADDR, 6);
  129. cmd4.channel_map = 0x07;
  130. cmd4.filter_policy = 0x00;
  131. bt_hci_send(adv_dev, BT_HCI_CMD_LE_SET_ADV_PARAMETERS,
  132. &cmd4, sizeof(cmd4), NULL, NULL, NULL);
  133. cmd5.enable = 0x01;
  134. bt_hci_send(adv_dev, BT_HCI_CMD_LE_SET_ADV_ENABLE,
  135. &cmd5, sizeof(cmd5),
  136. adv_enable_callback, NULL, NULL);
  137. }
  138. static void adv_le_features_callback(const void *data, uint8_t size,
  139. void *user_data)
  140. {
  141. const struct bt_hci_rsp_le_read_local_features *rsp = data;
  142. uint8_t evtmask[] = { 0xff, 0xff, 0x0f, 0x00, 0x00, 0x00, 0x00, 0x00 };
  143. if (rsp->status) {
  144. fprintf(stderr, "Failed to read local LE features\n");
  145. mainloop_exit_failure();
  146. return;
  147. }
  148. bt_hci_send(adv_dev, BT_HCI_CMD_LE_SET_EVENT_MASK, evtmask, 8,
  149. adv_le_evtmask_callback, NULL, NULL);
  150. }
  151. static void adv_features_callback(const void *data, uint8_t size,
  152. void *user_data)
  153. {
  154. const struct bt_hci_rsp_read_local_features *rsp = data;
  155. uint8_t evtmask[] = { 0x90, 0xe8, 0x04, 0x02, 0x00, 0x80, 0x00, 0x20 };
  156. if (rsp->status) {
  157. fprintf(stderr, "Failed to read local features\n");
  158. mainloop_exit_failure();
  159. return;
  160. }
  161. if (!(rsp->features[4] & 0x40)) {
  162. fprintf(stderr, "Controller without Low Energy support\n");
  163. mainloop_exit_failure();
  164. return;
  165. }
  166. bt_hci_send(adv_dev, BT_HCI_CMD_SET_EVENT_MASK, evtmask, 8,
  167. NULL, NULL, NULL);
  168. bt_hci_send(adv_dev, BT_HCI_CMD_LE_READ_LOCAL_FEATURES, NULL, 0,
  169. adv_le_features_callback, NULL, NULL);
  170. }
  171. static void scan_le_evtmask_callback(const void *data, uint8_t size,
  172. void *user_data)
  173. {
  174. bt_hci_send(adv_dev, BT_HCI_CMD_RESET, NULL, 0, NULL, NULL, NULL);
  175. bt_hci_send(adv_dev, BT_HCI_CMD_READ_LOCAL_FEATURES, NULL, 0,
  176. adv_features_callback, NULL, NULL);
  177. }
  178. static void scan_le_features_callback(const void *data, uint8_t size,
  179. void *user_data)
  180. {
  181. const struct bt_hci_rsp_le_read_local_features *rsp = data;
  182. uint8_t evtmask[] = { 0xff, 0xff, 0x0f, 0x00, 0x00, 0x00, 0x00, 0x00 };
  183. if (rsp->status) {
  184. fprintf(stderr, "Failed to read local LE features\n");
  185. mainloop_exit_failure();
  186. return;
  187. }
  188. bt_hci_send(adv_dev, BT_HCI_CMD_LE_SET_EVENT_MASK, evtmask, 8,
  189. scan_le_evtmask_callback, NULL, NULL);
  190. }
  191. static void scan_features_callback(const void *data, uint8_t size,
  192. void *user_data)
  193. {
  194. const struct bt_hci_rsp_read_local_features *rsp = data;
  195. uint8_t evtmask[] = { 0x90, 0xe8, 0x04, 0x02, 0x00, 0x80, 0x00, 0x20 };
  196. if (rsp->status) {
  197. fprintf(stderr, "Failed to read local features\n");
  198. mainloop_exit_failure();
  199. return;
  200. }
  201. if (!(rsp->features[4] & 0x40)) {
  202. fprintf(stderr, "Controller without Low Energy support\n");
  203. mainloop_exit_failure();
  204. return;
  205. }
  206. bt_hci_send(scan_dev, BT_HCI_CMD_SET_EVENT_MASK, evtmask, 8,
  207. NULL, NULL, NULL);
  208. bt_hci_send(scan_dev, BT_HCI_CMD_LE_READ_LOCAL_FEATURES, NULL, 0,
  209. scan_le_features_callback, NULL, NULL);
  210. }
  211. static void read_index_list(uint8_t status, uint16_t len, const void *param,
  212. void *user_data)
  213. {
  214. const struct mgmt_rp_read_index_list *rp = param;
  215. uint16_t count;
  216. int i;
  217. if (status) {
  218. fprintf(stderr, "Reading index list failed: %s\n",
  219. mgmt_errstr(status));
  220. mainloop_exit_failure();
  221. return;
  222. }
  223. count = le16_to_cpu(rp->num_controllers);
  224. if (count < 2) {
  225. fprintf(stderr, "At least 2 controllers are required\n");
  226. mainloop_exit_failure();
  227. return;
  228. }
  229. for (i = 0; i < count; i++) {
  230. uint16_t index = cpu_to_le16(rp->index[i]);
  231. if (index < index1)
  232. index1 = index;
  233. }
  234. for (i = 0; i < count; i++) {
  235. uint16_t index = cpu_to_le16(rp->index[i]);
  236. if (index < index2 && index > index1)
  237. index2 = index;
  238. }
  239. printf("Selecting index %u for advertiser\n", index1);
  240. printf("Selecting index %u for scanner\n", index2);
  241. crypto = bt_crypto_new();
  242. if (!crypto) {
  243. fprintf(stderr, "Failed to open crypto interface\n");
  244. mainloop_exit_failure();
  245. return;
  246. }
  247. adv_dev = bt_hci_new_user_channel(index1);
  248. if (!adv_dev) {
  249. fprintf(stderr, "Failed to open HCI for advertiser\n");
  250. mainloop_exit_failure();
  251. return;
  252. }
  253. scan_dev = bt_hci_new_user_channel(index2);
  254. if (!scan_dev) {
  255. fprintf(stderr, "Failed to open HCI for scanner\n");
  256. mainloop_exit_failure();
  257. return;
  258. }
  259. bt_hci_register(scan_dev, BT_HCI_EVT_LE_META_EVENT,
  260. scan_le_meta_event, NULL, NULL);
  261. bt_hci_send(scan_dev, BT_HCI_CMD_RESET, NULL, 0, NULL, NULL, NULL);
  262. bt_hci_send(scan_dev, BT_HCI_CMD_READ_LOCAL_FEATURES, NULL, 0,
  263. scan_features_callback, NULL, NULL);
  264. }
  265. static void signal_callback(int signum, void *user_data)
  266. {
  267. switch (signum) {
  268. case SIGINT:
  269. case SIGTERM:
  270. mainloop_quit();
  271. break;
  272. }
  273. }
  274. static void usage(void)
  275. {
  276. printf("advtest - Advertising testing\n"
  277. "Usage:\n");
  278. printf("\tadvtest [options]\n");
  279. printf("options:\n"
  280. "\t-h, --help Show help options\n");
  281. }
  282. static const struct option main_options[] = {
  283. { "version", no_argument, NULL, 'v' },
  284. { "help", no_argument, NULL, 'h' },
  285. { }
  286. };
  287. int main(int argc ,char *argv[])
  288. {
  289. int exit_status;
  290. for (;;) {
  291. int opt;
  292. opt = getopt_long(argc, argv, "vh", main_options, NULL);
  293. if (opt < 0)
  294. break;
  295. switch (opt) {
  296. case 'v':
  297. printf("%s\n", VERSION);
  298. return EXIT_SUCCESS;
  299. case 'h':
  300. usage();
  301. return EXIT_SUCCESS;
  302. default:
  303. return EXIT_FAILURE;
  304. }
  305. }
  306. if (argc - optind > 0) {
  307. fprintf(stderr, "Invalid command line parameters\n");
  308. return EXIT_FAILURE;
  309. }
  310. mainloop_init();
  311. mgmt = mgmt_new_default();
  312. if (!mgmt) {
  313. fprintf(stderr, "Failed to open management socket\n");
  314. return EXIT_FAILURE;
  315. }
  316. if (!mgmt_send(mgmt, MGMT_OP_READ_INDEX_LIST,
  317. MGMT_INDEX_NONE, 0, NULL,
  318. read_index_list, NULL, NULL)) {
  319. fprintf(stderr, "Failed to read index list\n");
  320. exit_status = EXIT_FAILURE;
  321. goto done;
  322. }
  323. exit_status = mainloop_run_with_signal(signal_callback, NULL);
  324. bt_hci_unref(adv_dev);
  325. bt_hci_unref(scan_dev);
  326. bt_crypto_unref(crypto);
  327. done:
  328. mgmt_unref(mgmt);
  329. return exit_status;
  330. }