bt-trace was reading kernel-prepended 0xFD as the low byte of bt_31 counter (and shifting all subsequent fields by 1), producing nonsensical rates like 200000/s and frame lengths of 20224 bytes. Slicing buf[1:] before decoding gives the firmware-supplied payload bytes aligned to the documented 0xFD layout. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>