Ask Your Question

Error parsing BT HCI trace created with

asked 2021-01-09 23:47:02 +0000

dandreye gravatar image

updated 2021-01-10 00:13:28 +0000

Hi All,

I've just used these instructions and python script from there to extract BT HCI log (trace) from the bug report zip produced by my Samsung SM-A320FL smartphone running Android 8 Oreo:

Unfortunately Wireshark only displays the first 5 packets and returns the following error: "The capture file appears to be damaged or corrupt. (btsnoop: File has 117440512-byte packet, bigger than maximum of 262144)". I understand that this trace is of some type (extension) ".cfa" but others can still open theirs with Wireshark and I can open theirs too. Assuming extension as such doesn't matter I gave mine extension .pcap as .cfa doesn't seem to be associated with anything.

Although I should probably be asking Android Engineering that instead, just wondering if I'm doing something obvious wrong by chance? Here's the trace in question:

Wireshark build is current stable 3.4.2 (v3.4.2-0-ga889cf1b1bf9).

Many thanks in anticipation!

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2021-01-10 23:14:56 +0000

dandreye gravatar image

Apparently that python script is implied for use with Linux: just verified it on Ubuntu with python v2.7 and it produces correct pcap files parsed by Wireshark w/o any such errors.

edit flag offensive delete link more


I doubt the platform is relevant, maybe the Python versions used? Anyway, the script would need some work either way.

Jaap gravatar imageJaap ( 2021-01-11 12:15:15 +0000 )edit

Thanks for your comment. Further research revealed that when used on Windows it writes 0D0A instead of every 0A, causing those Wireshark parsing errors. Replacing those 0D0A "back" with 0A in a hex editor fixed those errors in my case. As for the python version, I've just tried checking it on my W10x64 using "python --version" and it can't even find such app, so no idea how the script managed to run..

dandreye gravatar imagedandreye ( 2021-01-11 12:20:49 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2021-01-09 23:47:02 +0000

Seen: 916 times

Last updated: Jan 10 '21