{
  "schemaVersion": "0.11.0",
  "canonical": "https://www.pystone.net/notes/adb-working-principles/",
  "atlas": "https://www.pystone.net/?node=adb-working-principles#knowledge-atlas",
  "markdown": "https://www.pystone.net/notes/adb-working-principles.md",
  "context": "https://www.pystone.net/notes/adb-working-principles.context.json",
  "knowledgeVersion": "224c990773de.5fa8af6e39fa",
  "build": {
    "siteCommit": "224c990773de166d23a886306577dd90379529ce",
    "notesCommit": "5fa8af6e39fa3891d1b9b4832bfa6c4e0ecaaf0a",
    "builtAt": "1970-01-01T00:00:00.000Z",
    "version": "224c990773de.5fa8af6e39fa"
  },
  "id": "note:adb-working-principles",
  "slug": "adb-working-principles",
  "title": "ADB工作原理",
  "type": "note",
  "visibility": "public",
  "idStability": "rename-stable",
  "author": {
    "name": "Perrin Yong",
    "profile": "https://www.pystone.net/profile/"
  },
  "publisher": {
    "name": "Perrin Yong",
    "profile": "https://www.pystone.net/profile/"
  },
  "aliases": [],
  "summary": "ADB工作原理 adb原理",
  "contentRole": "unspecified",
  "isMoc": false,
  "mocRecognition": "none",
  "generated": false,
  "attribution": "unspecified",
  "domain": "10-计算机、信息技术与工程",
  "tags": [],
  "mocs": [],
  "updatedAt": "2021-05-20T13:41:46.000003Z",
  "contentHash": "d43e9c74babc8a1a819ec454b48cb39381662054de99fd8c20fd5df51f597913",
  "assets": [
    {
      "reference": "assets/0021 - 【自动化测试】ADB原理__1621006571443.png",
      "url": "/media/b8cd112701af284343e4.png",
      "mediaType": "image/png",
      "contentHash": "b8cd112701af284343e4181ccd0b3782cc21e5a9211c97ba95cbd78f954c9af7",
      "byteLength": 42313,
      "width": 1073,
      "height": 604
    },
    {
      "reference": "assets/0021 - 【自动化测试】ADB原理__1620997882024.png",
      "url": "/media/0524f567931ca6432d9f.png",
      "mediaType": "image/png",
      "contentHash": "0524f567931ca6432d9f4d1e7d59c9d7968122d85f6b9ca6af43af46f1982ab0",
      "byteLength": 177105,
      "width": 739,
      "height": 652
    },
    {
      "reference": "assets/0021 - 【自动化测试】ADB原理__1621006667165.png",
      "url": "/media/4fe8d91d51316c90d25c.png",
      "mediaType": "image/png",
      "contentHash": "4fe8d91d51316c90d25c60f82ceee9d3366af2e7b695efcd330f2445aa2da2bc",
      "byteLength": 658633,
      "width": 1734,
      "height": 1276
    },
    {
      "reference": "assets/0021 - 【自动化测试】ADB原理__1621006991650.png",
      "url": "/media/433c64e8c67d40eb5219.png",
      "mediaType": "image/png",
      "contentHash": "433c64e8c67d40eb52190c0703e2a75ebb44045043582788eb10a230e7a80fed",
      "byteLength": 25717,
      "width": 568,
      "height": 375
    },
    {
      "reference": "assets/0021 - 【自动化测试】ADB原理__1621007056515.png",
      "url": "/media/2b9fdd0eb942de0e40bb.png",
      "mediaType": "image/png",
      "contentHash": "2b9fdd0eb942de0e40bb0e7dda00d91be5ed6224d9fbd3926e7a15c8131d6b84",
      "byteLength": 71649,
      "width": 1045,
      "height": 403
    },
    {
      "reference": "assets/0021%20-%20【自动化测试】ADB原理__1621006571443.png",
      "url": "/media/b8cd112701af284343e4.png",
      "mediaType": "image/png",
      "contentHash": "b8cd112701af284343e4181ccd0b3782cc21e5a9211c97ba95cbd78f954c9af7",
      "byteLength": 42313,
      "width": 1073,
      "height": 604
    },
    {
      "reference": "assets/0021%20-%20【自动化测试】ADB原理__1620997882024.png",
      "url": "/media/0524f567931ca6432d9f.png",
      "mediaType": "image/png",
      "contentHash": "0524f567931ca6432d9f4d1e7d59c9d7968122d85f6b9ca6af43af46f1982ab0",
      "byteLength": 177105,
      "width": 739,
      "height": 652
    },
    {
      "reference": "assets/0021%20-%20【自动化测试】ADB原理__1621006667165.png",
      "url": "/media/4fe8d91d51316c90d25c.png",
      "mediaType": "image/png",
      "contentHash": "4fe8d91d51316c90d25c60f82ceee9d3366af2e7b695efcd330f2445aa2da2bc",
      "byteLength": 658633,
      "width": 1734,
      "height": 1276
    },
    {
      "reference": "assets/0021%20-%20【自动化测试】ADB原理__1621006991650.png",
      "url": "/media/433c64e8c67d40eb5219.png",
      "mediaType": "image/png",
      "contentHash": "433c64e8c67d40eb52190c0703e2a75ebb44045043582788eb10a230e7a80fed",
      "byteLength": 25717,
      "width": 568,
      "height": 375
    },
    {
      "reference": "assets/0021%20-%20【自动化测试】ADB原理__1621007056515.png",
      "url": "/media/2b9fdd0eb942de0e40bb.png",
      "mediaType": "image/png",
      "contentHash": "2b9fdd0eb942de0e40bb0e7dda00d91be5ed6224d9fbd3926e7a15c8131d6b84",
      "byteLength": 71649,
      "width": 1045,
      "height": 403
    }
  ],
  "headings": [
    {
      "depth": 1,
      "text": "ADB工作原理",
      "anchor": "adb工作原理",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#adb%E5%B7%A5%E4%BD%9C%E5%8E%9F%E7%90%86"
    },
    {
      "depth": 2,
      "text": "adb原理",
      "anchor": "adb原理",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#adb%E5%8E%9F%E7%90%86"
    },
    {
      "depth": 3,
      "text": "架构",
      "anchor": "架构",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#%E6%9E%B6%E6%9E%84"
    },
    {
      "depth": 3,
      "text": "通信机制与workflow",
      "anchor": "通信机制与workflow",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#%E9%80%9A%E4%BF%A1%E6%9C%BA%E5%88%B6%E4%B8%8Eworkflow"
    },
    {
      "depth": 3,
      "text": "ADB Protocol 通信协议",
      "anchor": "adb-protocol-通信协议",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#adb-protocol-%E9%80%9A%E4%BF%A1%E5%8D%8F%E8%AE%AE"
    },
    {
      "depth": 4,
      "text": "Client 和 Server 间的通信",
      "anchor": "client-和-server-间的通信",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#client-%E5%92%8C-server-%E9%97%B4%E7%9A%84%E9%80%9A%E4%BF%A1"
    },
    {
      "depth": 4,
      "text": "ADB Daemon 和 ADB Server 间的通信 — transport协议",
      "anchor": "adb-daemon-和-adb-server-间的通信-transport协议",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#adb-daemon-%E5%92%8C-adb-server-%E9%97%B4%E7%9A%84%E9%80%9A%E4%BF%A1-transport%E5%8D%8F%E8%AE%AE"
    },
    {
      "depth": 3,
      "text": "USB Vendor ID",
      "anchor": "usb-vendor-id",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#usb-vendor-id"
    },
    {
      "depth": 3,
      "text": "adb forward",
      "anchor": "adb-forward",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#adb-forward"
    },
    {
      "depth": 2,
      "text": "实践用法",
      "anchor": "实践用法",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#%E5%AE%9E%E8%B7%B5%E7%94%A8%E6%B3%95"
    },
    {
      "depth": 3,
      "text": "Profiler: Editor-to-Android connection",
      "anchor": "profiler-editor-to-android-connection",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#profiler-editor-to-android-connection"
    },
    {
      "depth": 3,
      "text": "log抓取",
      "anchor": "log抓取",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#log%E6%8A%93%E5%8F%96"
    },
    {
      "depth": 3,
      "text": "其他常用命令",
      "anchor": "其他常用命令",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#%E5%85%B6%E4%BB%96%E5%B8%B8%E7%94%A8%E5%91%BD%E4%BB%A4"
    },
    {
      "depth": 2,
      "text": "Ref",
      "anchor": "ref",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#ref"
    },
    {
      "depth": 2,
      "text": "【自动化测试】ADB原理",
      "anchor": "自动化测试adb原理",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#%E8%87%AA%E5%8A%A8%E5%8C%96%E6%B5%8B%E8%AF%95adb%E5%8E%9F%E7%90%86"
    },
    {
      "depth": 2,
      "text": "adb原理",
      "anchor": "adb原理-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#adb%E5%8E%9F%E7%90%86-1"
    },
    {
      "depth": 3,
      "text": "架构",
      "anchor": "架构-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#%E6%9E%B6%E6%9E%84-1"
    },
    {
      "depth": 3,
      "text": "通信机制与workflow",
      "anchor": "通信机制与workflow-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#%E9%80%9A%E4%BF%A1%E6%9C%BA%E5%88%B6%E4%B8%8Eworkflow-1"
    },
    {
      "depth": 3,
      "text": "ADB Protocol 通信协议",
      "anchor": "adb-protocol-通信协议-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#adb-protocol-%E9%80%9A%E4%BF%A1%E5%8D%8F%E8%AE%AE-1"
    },
    {
      "depth": 4,
      "text": "Client 和 Server 间的通信",
      "anchor": "client-和-server-间的通信-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#client-%E5%92%8C-server-%E9%97%B4%E7%9A%84%E9%80%9A%E4%BF%A1-1"
    },
    {
      "depth": 4,
      "text": "ADB Daemon 和 ADB Server 间的通信 — transport协议",
      "anchor": "adb-daemon-和-adb-server-间的通信-transport协议-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#adb-daemon-%E5%92%8C-adb-server-%E9%97%B4%E7%9A%84%E9%80%9A%E4%BF%A1-transport%E5%8D%8F%E8%AE%AE-1"
    },
    {
      "depth": 3,
      "text": "USB Vendor ID",
      "anchor": "usb-vendor-id-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#usb-vendor-id-1"
    },
    {
      "depth": 3,
      "text": "adb forward",
      "anchor": "adb-forward-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#adb-forward-1"
    },
    {
      "depth": 2,
      "text": "实践用法",
      "anchor": "实践用法-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#%E5%AE%9E%E8%B7%B5%E7%94%A8%E6%B3%95-1"
    },
    {
      "depth": 3,
      "text": "Profiler: Editor-to-Android connection",
      "anchor": "profiler-editor-to-android-connection-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#profiler-editor-to-android-connection-1"
    },
    {
      "depth": 3,
      "text": "log抓取",
      "anchor": "log抓取-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#log%E6%8A%93%E5%8F%96-1"
    },
    {
      "depth": 3,
      "text": "其他常用命令",
      "anchor": "其他常用命令-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#%E5%85%B6%E4%BB%96%E5%B8%B8%E7%94%A8%E5%91%BD%E4%BB%A4-1"
    },
    {
      "depth": 2,
      "text": "Ref",
      "anchor": "ref-1",
      "citation": "https://www.pystone.net/notes/adb-working-principles/#ref-1"
    }
  ],
  "claims": [],
  "outgoing": [],
  "incoming": [
    {
      "id": "note:application-and-cloud-engineering",
      "title": "应用开发与云端工程",
      "url": "https://www.pystone.net/notes/application-and-cloud-engineering/",
      "atlas": "https://www.pystone.net/?node=application-and-cloud-engineering#knowledge-atlas",
      "label": "应用开发与云端工程",
      "origin": "explicit",
      "humanReviewed": true,
      "context": "Android开发中的“ADB工作原理”导航项",
      "citation": "https://www.pystone.net/notes/application-and-cloud-engineering/#android%E5%BC%80%E5%8F%91"
    }
  ],
  "contentMarkdown": "# ADB工作原理\n## adb原理\n\nADB - Android Debug Bridge\n\nADB源码：\n\n<http://androidxref.com/8.1.0_r33/xref/system/core/adb/adb.cpp>\n\n\n<https://android.googlesource.com/platform/system/adb>\n\n\n<https://github.com/aosp-mirror/platform_system_core.git>\n\n\n### 架构\n\n![](assets/0021 - 【自动化测试】ADB原理__1621006571443.png)\n\n\n**ADB Client** : 运行在PC HOST端，用来发送adb命令。**本质上就是Shell**，用来发送命令给Server。发送命令时，首先检测PC上有没有启动Server，如果没有Server，则自动启动一个Server，然后将命令发送到Server，并不关心命令发送过去以后会怎样。\n\n\n**ADB Server** :\n\n运行在PC HOST端，用来管理Client端和手机的Deamon之间的通信。\n\n检测USB接口何时连接或者移除设备。ADB Server维护着一个“已连接的设备的链表”，并且为每一个设备标记了一个状态：offline，bootloader，recovery或者online。Server一直在做一些循环和等待，以协调client和Server还有daemon之间的通信。\n\n\n> offline说明Server发现了一个设备，但是不能成功连接到Daemon。\n\n\n**Daemon（adbd守护进程）**:\n\n运行在调试设备中（手机或者模拟器），连接到adb server（通过usb或tcp-ip）,接受并执行adb命令, 为client提供一些服务。\n\n\n![](assets/0021 - 【自动化测试】ADB原理__1620997882024.png)\n\n\n### 通信机制与workflow\n\n1. 在PC HOST端，adb会fork出一个守护进程（不是adbd），即ADB Server，而父进程（ADB Client）继续处理Client请求，所有的Client通过TCP端口号5037进行与Server通信，而Server创建 local socket 与 remote socket，前者用于和Client通信，后者用与远端进行通信，emulator通过TCP，real device则通过usb。\n2. 在emulator/device端，adbd也创建 local socket 和 remote socket，前者与通过 jdwp 与Java虚拟机进程通信，后者通过 TCP/USB 与 PC HOST通信。\n - Client和Server虽然是同一个执行程序，但在命令行输入一条adb命令后，实际上完成了一次通信。adb server启动后，会在**5037**端口侦听从client发起的TCP连接\n - Server与模拟器或者手机设备的端口5555~5585建立TCP连接，PC上与之相连的端口号随机。\n\n![](assets/0021 - 【自动化测试】ADB原理__1621006667165.png)\n\n\n通过以下命令，可以看到server的启动日志：\n\n\n```\n$ adb\nkill\n-\nserver\n && adb devices\n\n* daemon\nnot\n running.\nstarting\n it\nnow\n\non\n port\n5037\n *\n\n* daemon started successfully *\n```\n\n\n通过以下命令，可以看到TCP的5037端口，在侦听连接：\n\n\n```\n$ netstat -l | grep\n5037\n\n\nProto Recv-Q Send-Q Local Address Foreign Address State\n\ntcp\n0\n\n0\n\n127.0\n.0\n.1\n:\n5037\n\n0.0\n.0\n.0\n:* LISTEN\n```\n\n\n1. Client 调用某个 adb 命令\n2. adb 进程 fork 出一个子进程作为 Server\n3. Server 查找当前连接的 emulator/device\n4. Server 接收到来自 Client 请求\n5. Server 处理请求，将本地处理不了的请求发给\n6. emulator/device\n7. 位于 emulator/device 的 adbd拿到请求后交给对应的java虚拟机进程。\n8. adbd 将结果发回给 Server\n9. Server 将结果发回给 Client\n\n\n### ADB Protocol 通信协议\n\n#### Client 和 Server 间的通信\n\nClient发送的指令分为三种\n\n\n- 不需要经过Server处理就能成功的，如adb version,adb help。\n- 需要和Server通讯，但不需要和Demon通讯的指令，如adb devices.\n- 需要Daemon进行处理的命令。\n\nClient 和 Server 间传输的命令定义: <http://androidxref.com/8.1.0_r33/xref/system/core/adb/SERVICES.TXT>\n\n\nClient每个命令都包含两个部分:\n\n\n1. 命令的长度(Length)，由四位的十六进制表示\n2. 实际的命令(Payload)，通过ASCII编码\n\n\n```\n000\nChost:\nversion\n```\n\n\n000C：表示”host:version”这条命令的长度为12个字节；\n\nhost前缀：是为了区分其他类型的命令(后面还会看到shell前缀的命令)；\n\n\nServer收到Client的请求后，返回的数据遵循如下格式：\n\n\n- 如果成功，则返回四个字节的字符串”OKAY“\n- 如果失败，则返回四个字节的字符串”FAIL“和出错原因\n- 如果异常，则返回错误码\n\n\n#### ADB Daemon 和 ADB Server 间的通信 — transport协议\n\n这个数据通道对client而言，完全是透明的，client不关注这个通道怎么建立以及怎么进行数据传输。\n\n\n关于 transport 协议的定义在 system/core/adb/protocol.txt 文件中\n\n\n```\nThe transport layer deals in\n\"messages\"\n, which consist of a\n24\n\nbyte\n\n\nheader\nfollowed\n\n(optionally)\n by a payload. The header consists of 6\n\n\n32 bit words which are sent across the wire in little endian format.\n\n\nstruct\n message\n{\n\n\nunsigned\n command;\n/* command identifier constant (A_CNXN, ...) */\n\n\nunsigned\n arg0;\n/* first argument */\n\n\nunsigned\n arg1;\n/* second argument */\n\n\nunsigned\n data_length;\n/* length of payload (0 is allowed) */\n\n\nunsigned\n data_crc32;\n/* crc32 of data payload */\n\n\nunsigned\n magic;\n/* command ^ 0xffffffff */\n\n\n};\n```\n\n\nclient与adbd的数据传输是需要用到两个通道的，当与server建立第一个通道的连接后，需要向server发送transport命令，表示接下来，要与adbd进行数据传输。当server返回“OKAY”后，client后续发送的数据，就直接传输到adbd了。\n\n\n![](assets/0021 - 【自动化测试】ADB原理__1621006991650.png)\n\n\n### USB Vendor ID\n\n![](assets/0021 - 【自动化测试】ADB原理__1621007056515.png)\n\n\n### adb forward\n\n设置任意端口转发，将特定主机端口上的请求转发到设备上的其他端口。PC 作为Client客户端 可以任意访问 Phone 上的 Server 服务器\n\n\n```\nadb\nforward\n tcp:\n6100\n tcp:\n7100\n\n\nadb\nforward\n --list\n\nadb\nforward\n --\nremove\n-all\n\nadb\nforward\n tcp:\n8888\n tcp:\n8888\n```\n\n\n该转发可以用于自己写的程序。\n\n\n## 实践用法\n\n用法大全: <https://github.com/mzlogin/awesome-adb>\n\n\n### Profiler: Editor-to-Android connection\n\nadb forward tcp:34999 localabstract:Unity-{insert bundle identifier here}\n\n\n### log抓取\n\nadb logcat -s Unity\n\nadb -s %DeviceName% logcat -s Unity\n\nadb logcat -s Unity ActivityManager PackageManager dalvikvm DEBUG #获取log，-s指定过滤器\n\nadb -s deviceName logcat -s Unity -f c:\\unity_log.txt #-f 输出log到指定文件\n\n\n### 其他常用命令\n\n<https://www.huaweicloud.com/articles/39c8580fd6d8eacb6b0b89082f9d15b4.html>\n\n\n## Ref\n\n<https://www.zhihu.com/zvideo/1261234074455998464>\n\n\n<https://www.jianshu.com/p/6769bfc3e2da>\n\n\n<https://itimetraveler.github.io/2019/06/07/Android ADB原理探究/>\n\n\n<https://learning.oreilly.com/library/view/unboxing-android-usb/9781430262084/9781430262084_Ch07.xhtml>\n\n## 【自动化测试】ADB原理\n@(10. DevOps)\n\n[TOC]\n\n\n## adb原理\nADB - Android Debug Bridge\nADB源码：\nhttp://androidxref.com/8.1.0_r33/xref/system/core/adb/adb.cpp\n\nhttps://android.googlesource.com/platform/system/adb\n\nhttps://github.com/aosp-mirror/platform_system_core.git\n\n### 架构\n\n![ADB 工作原理示意图](assets/0021%20-%20【自动化测试】ADB原理__1621006571443.png)\n\n\n**ADB Client** : 运行在PC HOST端，用来发送adb命令。**本质上就是Shell**，用来发送命令给Server。发送命令时，首先检测PC上有没有启动Server，如果没有Server，则自动启动一个Server，然后将命令发送到Server，并不关心命令发送过去以后会怎样。\n\n\n**ADB Server** :\n运行在PC HOST端，用来管理Client端和手机的Deamon之间的通信。\n检测USB接口何时连接或者移除设备。ADB Server维护着一个“已连接的设备的链表”，并且为每一个设备标记了一个状态：offline，bootloader，recovery或者online。Server一直在做一些循环和等待，以协调client和Server还有daemon之间的通信。\n> offline说明Server发现了一个设备，但是不能成功连接到Daemon。\n\n\n**Daemon（adbd守护进程）**:\n运行在调试设备中（手机或者模拟器），连接到adb server（通过usb或tcp-ip）,接受并执行adb命令, 为client提供一些服务。\n\n![ADB 工作原理示意图](assets/0021%20-%20【自动化测试】ADB原理__1620997882024.png)\n\n### 通信机制与workflow\n1. 在PC HOST端，adb会fork出一个守护进程（不是adbd），即ADB Server，而父进程（ADB Client）继续处理Client请求，所有的Client通过TCP端口号5037进行与Server通信，而Server创建 local socket 与 remote socket，前者用于和Client通信，后者用与远端进行通信，emulator通过TCP，real device则通过usb。\n\n2. 在emulator/device端，adbd也创建 local socket 和 remote socket，前者与通过 jdwp 与Java虚拟机进程通信，后者通过 TCP/USB 与 PC HOST通信。\n\n* Client和Server虽然是同一个执行程序，但在命令行输入一条adb命令后，实际上完成了一次通信。adb server启动后，会在**5037**端口侦听从client发起的TCP连接\n* Server与模拟器或者手机设备的端口5555~5585建立TCP连接，PC上与之相连的端口号随机。\n\n![ADB 工作原理示意图](assets/0021%20-%20【自动化测试】ADB原理__1621006667165.png)\n\n\n通过以下命令，可以看到server的启动日志：\n```\n$ adb kill-server && adb devices\n* daemon not running. starting it now on port 5037 *\n* daemon started successfully *\n```\n通过以下命令，可以看到TCP的5037端口，在侦听连接：\n```\n$ netstat -l | grep 5037\nProto Recv-Q Send-Q    Local Address   Foreign Address     State\ntcp        0      0    127.0.0.1:5037  0.0.0.0:*           LISTEN\n```\n1. Client 调用某个 adb 命令\n2. adb 进程 fork 出一个子进程作为 Server\n3. Server 查找当前连接的 emulator/device\n4. Server 接收到来自 Client 请求\n5. Server 处理请求，将本地处理不了的请求发给\n6. emulator/device\n7. 位于 emulator/device 的 adbd拿到请求后交给对应的java虚拟机进程。\n8. adbd 将结果发回给 Server\n9. Server 将结果发回给 Client\n\n\n### ADB Protocol 通信协议\n#### Client 和 Server 间的通信\nClient发送的指令分为三种\n* 不需要经过Server处理就能成功的，如adb version,adb help。\n* 需要和Server通讯，但不需要和Demon通讯的指令，如adb devices.\n* 需要Daemon进行处理的命令。\n\nClient 和 Server 间传输的命令定义: http://androidxref.com/8.1.0_r33/xref/system/core/adb/SERVICES.TXT\n\nClient每个命令都包含两个部分:\n1. 命令的长度(Length)，由四位的十六进制表示\n2. 实际的命令(Payload)，通过ASCII编码\n\n```\n000Chost:version\n```\n000C：表示”host:version”这条命令的长度为12个字节；\nhost前缀：是为了区分其他类型的命令(后面还会看到shell前缀的命令)；\n\nServer收到Client的请求后，返回的数据遵循如下格式：\n* 如果成功，则返回四个字节的字符串”OKAY“\n* 如果失败，则返回四个字节的字符串”FAIL“和出错原因\n* 如果异常，则返回错误码\n\n\n\n\n\n#### ADB Daemon 和 ADB Server 间的通信 — transport协议\n这个数据通道对client而言，完全是透明的，client不关注这个通道怎么建立以及怎么进行数据传输。\n\n\n关于 transport 协议的定义在 system/core/adb/protocol.txt 文件中\n```cpp\nThe transport layer deals in \"messages\", which consist of a 24 byte\nheader followed (optionally) by a payload.  The header consists of 6\n32 bit words which are sent across the wire in little endian format.\n\nstruct message {\n    unsigned command;       /* command identifier constant (A_CNXN, ...) */\n    unsigned arg0;          /* first argument                            */\n    unsigned arg1;          /* second argument                           */\n    unsigned data_length;   /* length of payload (0 is allowed)          */\n    unsigned data_crc32;    /* crc32 of data payload                     */\n    unsigned magic;         /* command ^ 0xffffffff                      */\n};\n```\n\nclient与adbd的数据传输是需要用到两个通道的，当与server建立第一个通道的连接后，需要向server发送transport命令，表示接下来，要与adbd进行数据传输。当server返回“OKAY”后，client后续发送的数据，就直接传输到adbd了。\n![ADB 工作原理示意图](assets/0021%20-%20【自动化测试】ADB原理__1621006991650.png)\n\n### USB Vendor ID\n![ADB 工作原理示意图](assets/0021%20-%20【自动化测试】ADB原理__1621007056515.png)\n\n### adb forward\n设置任意端口转发，将特定主机端口上的请求转发到设备上的其他端口。PC 作为Client客户端 可以任意访问 Phone 上的 Server 服务器\n\n```\nadb forward tcp:6100 tcp:7100\nadb forward --list\nadb forward --remove-all\nadb forward tcp:8888 tcp:8888\n\n```\n该转发可以用于自己写的程序。\n\n\n## 实践用法\n用法大全: https://github.com/mzlogin/awesome-adb\n\n### Profiler: Editor-to-Android connection\nadb forward tcp:34999 localabstract:Unity-{insert bundle identifier here}\n\n### log抓取\nadb logcat -s Unity\nadb -s %DeviceName% logcat -s Unity\nadb logcat -s Unity ActivityManager PackageManager dalvikvm DEBUG #获取log，-s指定过滤器\nadb -s deviceName logcat -s Unity  -f c:\\unity_log.txt #-f 输出log到指定文件\n\n### 其他常用命令\nhttps://www.huaweicloud.com/articles/39c8580fd6d8eacb6b0b89082f9d15b4.html\n## Ref\nhttps://www.zhihu.com/zvideo/1261234074455998464\n\nhttps://www.jianshu.com/p/6769bfc3e2da\n\nhttps://itimetraveler.github.io/2019/06/07/Android ADB原理探究/\n\nhttps://learning.oreilly.com/library/view/unboxing-android-usb/9781430262084/9781430262084_Ch07.xhtml\n"
}
