A SATA disk hides behind a USB bridge and lsblk shows nothing useful, so sg_sat_identify asks the drive directly for its ATA identity data. It works through a SCSI-to-ATA Translation (SAT) layer, and reads ATA PACKET DEVICE data instead when the target is an ATAPI device. Allow about fifteen minutes.
sg3-utils, and the exact device path. Reading is normally an ordinary user operation if your account can already access the node, but that node may be restricted.sg3-utils package version 1.46-3ubuntu4; the installed binary reports utility version 1.17 20180515, so record both when comparing systems.Do not guess a device path: replace every placeholder below only after checking it.
Start with read-only discovery. These commands do not need elevated privileges:
$ command -v sg_sat_identify
/usr/bin/sg_sat_identify
$ sg_sat_identify --version
version: 1.17 20180515
$ dpkg-query -W -f='${Package} ${Version}\n' sg3-utils
sg3-utils 1.46-3ubuntu4
The version line is the program's own report, while the package query describes the distribution package. Keep the output with any support report, because a wrapper, backport or vendor build can expose different options.
Checkpoint: confirm the command accepts the expected interface.
$ sg_sat_identify --help
Usage: sg_sat_identify [--ck_cond] [--extend] [--help] [--hex] [--ident]
[--len=CLEN] [--packet] [--raw] [--readonly]
[--verbose] [--version] DEVICE
sg_sat_identify needs a SCSI-visible device whose path reaches a SAT layer. A SATA disk behind a USB bridge or host bus adapter may qualify; a plain SCSI disk does not turn into an ATA device just because it has a /dev/sdX name. Use your normal inventory tools to identify the path, then inspect it without changing anything:
$ ls -l /dev/sdX
$ lsblk -o NAME,TYPE,MODEL,SERIAL,TRAN /dev/sdX
/dev/sdX is deliberately a placeholder: do not paste it unchanged. Check that the resolved path is the intended disk, especially on a host with removable media or several USB devices. The identify command itself only requests identity information even against a mounted system disk, but an incorrect path can make later maintenance commands dangerous.
The default request is ATA IDENTIFY DEVICE. The local manual says the default SCSI ATA PASS-THROUGH command uses a 16-byte CDB, and the default output is hexadecimal grouped into 16-bit words. Add --readonly explicitly so the open operation uses read-only access:
$ DEVICE=/dev/sdX
$ sg_sat_identify --readonly "$DEVICE"
Response for IDENTIFY DEVICE ATA command:
00 0c5a 3fff c837 0010 0000 0000 003f 0000 .Z ?. .7 .. .. .. .? ..
...
Your response will be much longer and the words will differ. Three things are worth checking: the response heading, a complete-looking hexadecimal payload, and a zero exit status.
$ printf 'exit status: %s\n' "$?"
exit status: 0
Checkpoint: run that immediately after sg_sat_identify. Any command inserted between them changes which status is printed.
If the device cannot be opened, first check the path and permissions. Use sudo only when the host's device permissions require it, and keep the read-only option:
$ sudo sg_sat_identify --readonly "$DEVICE"
Elevated privileges do not add SAT support. An unsupported pass-through operation error usually means the bridge or enclosure does not implement the required SAT translation, not that you lack permission.
Raw identify words are useful for archival evidence but awkward to read. If sg_inq is installed, ask sg_sat_identify for unadorned byte output and pipe it to the ATA decoder:
$ sg_sat_identify --readonly --hex --hex --hex --hex "$DEVICE" \
| sg_inq --ata -I -
ATA device: model, serial number and firmware revision:
ST9500420AS 5VJCE6R7 0002SDM1
Four --hex options produce space-separated bytes, 16 per line; the short spelling is -HHHH. The model, serial number and firmware above are examples from the manpage, not predictions about your disk. Treat serial numbers as sensitive asset data when storing command output.
For a fuller decode, three --hex options produce unadorned little-endian 16-bit words suitable for hdparm --Istdin:
$ sg_sat_identify --readonly -HHH "$DEVICE" | hdparm --Istdin
ATA device, with non-removable media
Model Number: ST9500420AS
Serial Number: 5VJCE6R7
Firmware Revision: 0002SDM1
Transport: Serial
H gives ASCII hex bytes.hdparm form.A decoder failure does not necessarily mean the identify request failed; check the first command's exit status and capture each stage separately if diagnosing a pipeline.
The --ident option prints the device World Wide Name as a hexadecimal value prefixed with 0x:
$ sg_sat_identify --readonly --ident "$DEVICE"
0x5000c50012345678
The value above is illustrative. A device with no WWN prints 0x0000000000000000, an unavailable value, not a useful identifier. For comparison, an equivalent SCSI disk logical unit name can be queried with sg_vpd -ii, but that is a separate command and can report a different identifier.
--packet is only for an ATAPI device that needs ATA IDENTIFY PACKET DEVICE. It is not a more detailed disk query; it selects a different command entirely. The manual calls the ATAPI PACKET interface obsolete, so leave this out for an ordinary ATA disk.--extend sets the ATA PASS-THROUGH EXTEND bit for 48-bit LBA addressing, and has no effect with --len=12. The 16-byte CDB is the default. Choose --len=12 or --len=32 only when the SAT implementation and the device require that CDB size; the 32-byte form carries additional ATA registers and needs SAT-4 revision 5 or later according to the installed help text.--ck_cond requests an ATA Result descriptor in the sense buffer even when the command succeeds. It is mainly a diagnostic aid. Use --verbose to increase diagnostics, not as a repair action.--raw writes the response as binary to standard output and errors to standard error. It is suitable for a file or another program, not for a terminal:
$ output=/tmp/ata-identify.bin
$ test ! -e "$output" || { printf 'refusing to overwrite %s\n' "$output" >&2; exit 1; }
$ sg_sat_identify --readonly --raw "$DEVICE" > "$output"
$ test -s "$output" && file "$output"
/tmp/ata-identify.bin: data
Warning: the destination is under /tmp for this example and may contain serial numbers or other hardware details. Remove it after review if it is no longer needed, and never redirect to a path that already contains evidence unless you have made a deliberate backup: shell redirection truncates the destination before the command starts.
--readonly.sg_inq or hdparm.