
Bluetooth 5 and 4.x LE sniffer for TI CC1352/CC26x2 hardware with support for extended advertising, all PHY modes, MAC/RSSI filtering, and PCAP export compatible with Wireshark.
Sniffle is a sniffer for Bluetooth 5 and 4.x (LE) using TI CC1352/CC26x2 hardware.
Sniffle has a number of useful features, including:
If you don't want to go through the effort of setting up a build environment for the firmware, you can just flash prebuilt firmware binaries using UniFlash/DSLite. Prebuilt firmware binaries are attached to releases on the GitHub releases tab of this project. When using prebuilt firmware, be sure to use the Python code corresponding to the release tag rather than master to avoid compatibility issues with firmware that is behind the master branch.
The arm-none-eabi-gcc provided through various Linux distributions' package
manager often lacks some header files or requires some changes to linker
configuration. For minimal hassle, I suggest using the ARM GCC linked above.
You can just download and extract the prebuilt executables.
The TI SDK is provided as an executable binary that extracts a bunch of source
code once you accept the license agreement. On Linux and Mac, the default
installation directory is inside~/ti/. This works fine and my makefiles
expect this path, so I suggest just going with the default here. The same
applies for the TI SysConfig tool.
Once the SDK has been extracted, you will need to edit one makefile to match
your build environment. Within ~/ti/simplelink_cc13xx_cc26xx_sdk_8_30_01_01
(or wherever the SDK was installed) there is a makefile named imports.mak.
The only paths that need to be set here to build Sniffle are for GCC, XDC,
cmake and SysConfig. We don't need the CCS compiler. See the diff below as
an example, and adapt for wherever you installed things.
diff --git a/imports.mak b/imports.mak
index b2cf5bf59..389d1a7c3 100644
--- a/imports.mak
+++ b/imports.mak
@@ -18,14 +18,14 @@
# will build using each non-empty *_ARMCOMPILER cgtool.
#
-XDC_INSTALL_DIR ?= /home/username/ti/xdctools_3_62_01_15_core
-SYSCONFIG_TOOL ?= /home/username/ti/ccs1270/ccs/utils/sysconfig_1.21.1/sysconfig_cli.sh
+XDC_INSTALL_DIR ?= $(HOME)/ti/xdctools_3_62_01_15_core
+SYSCONFIG_TOOL ?= $(HOME)/ti/sysconfig_1.21.1/sysconfig_cli.sh
-CMAKE ?= /home/username/cmake-3.21.3/bin/cmake
+CMAKE ?= cmake
PYTHON ?= python3
TICLANG_ARMCOMPILER ?= /home/username/ti/ccs1270/ccs/tools/compiler/ti-cgt-armllvm_3.2.2.LTS-0
-GCC_ARMCOMPILER ?= /home/username/arm-none-eabi-gcc/12.3.Rel1-0
+GCC_ARMCOMPILER ?= $(HOME)/arm_tools/arm-gnu-toolchain-14.3.rel1-x86_64-arm-none-eabi
IAR_ARMCOMPILER ?= /home/username/iar9.50.2
# Uncomment this to enable the TFM build
As of SDK version 8.30.01.01, to compile with recent versions of GCC (and binutils), a small modification to the SDK is needed to avoid linking errors "Unknown destination type (ARM/Thumb)" and "dangerous relocation: unsupported relocation".
diff --git a/kernel/tirtos7/packages/ti/sysbios/family/arm/m3/Hwi_asm_gcc.s b/kernel/tirtos7/packages/ti/sysbios/family/arm/m3/Hwi_asm_gcc.s
index 187cfd744..4cbf0d384 100644
--- a/kernel/tirtos7/packages/ti/sysbios/family/arm/m3/Hwi_asm_gcc.s
+++ b/kernel/tirtos7/packages/ti/sysbios/family/arm/m3/Hwi_asm_gcc.s
@@ -236,6 +236,7 @@ lab$1:
@ user code has set the PRIMASK and not cleared it, or when single
@ stepping with interrupts disabled.
+.type ti_sysbios_family_arm_m3_Hwi_interruptsAreDisabledButShouldNotBe, %function
ti_sysbios_family_arm_m3_Hwi_interruptsAreDisabledButShouldNotBe:
b ti_sysbios_family_arm_m3_Hwi_interruptsAreDisabledButShouldNotBe
diff --git a/kernel/tirtos7/packages/ti/sysbios/family/arm/v8m/Hwi_asm_gcc.s b/kernel/tirtos7/packages/ti/sysbios/family/arm/v8m/Hwi_asm_gcc.s
index 717f49c9a..1c83ed725 100644
--- a/kernel/tirtos7/packages/ti/sysbios/family/arm/v8m/Hwi_asm_gcc.s
+++ b/kernel/tirtos7/packages/ti/sysbios/family/arm/v8m/Hwi_asm_gcc.s
@@ -226,6 +226,7 @@ lab$1:
@ user code has set the PRIMASK and not cleared it, or when single
@ stepping with interrupts disabled.
+.type ti_sysbios_family_arm_v8m_Hwi_interruptsAreDisabledButShouldNotBe, %function
ti_sysbios_family_arm_v8m_Hwi_interruptsAreDisabledButShouldNotBe:
b ti_sysbios_family_arm_v8m_Hwi_interruptsAreDisabledButShouldNotBe
After making this modification, you will need to recompile the SDK.
cd ~/ti/simplelink_cc13xx_cc26xx_sdk_8_30_01_01
make build-gcc -j5
DSLite is TI's command line programming and debug server tool for XDS110
debuggers. The CC26xx and CC13xx Launchpad boards both include XDS110 debuggers.
Unfortunately, TI does not provide a standalone command line DSLite download.
The easiest way to obtain DSLite is to install UniFlash
from TI. It's available for Linux, Mac, and Windows. The DSLite executable will
be located at deskdb/content/TICloudAgent/linux/ccs_base/DebugServer/bin/DSLite
relative to the UniFlash installation directory. On Linux, the default UniFlash
installation directory is inside ~/ti/.
You should place the DSLite executable directory within your $PATH.
Once the GCC, DSLite, and the SDK is installed and operational, building
Sniffle should be straight forward. Just navigate to the fw directory and
run make. If you didn't install the SDK to the default directory, you may
need to edit SIMPLELINK_SDK_INSTALL_DIR in the makefile.
If building for or installing on a some variant of Launchpad other than CC26x2R,
you must specify PLATFORM=xxx, either as an argument to make, or by defining
it as an environment variable prior to invoking make. Supported values for PLATFORM
can be found in the firmware makefile. Be sure to perform a make clean before
building for a different platform.