ccid.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397
  1. #include "seader_i.h"
  2. #define TAG "SeaderCCID"
  3. bool hasSAM = false;
  4. const uint8_t SAM_ATR[] =
  5. {0x3b, 0x95, 0x96, 0x80, 0xb1, 0xfe, 0x55, 0x1f, 0xc7, 0x47, 0x72, 0x61, 0x63, 0x65, 0x13};
  6. const uint8_t SAM_ATR2[] = {0x3b, 0x90, 0x96, 0x91, 0x81, 0xb1, 0xfe, 0x55, 0x1f, 0xc7, 0xd4};
  7. bool powered[2] = {false, false};
  8. uint8_t sam_slot = 0;
  9. uint8_t sequence[2] = {0, 0};
  10. uint8_t retries = 3;
  11. uint8_t getSequence(uint8_t slot) {
  12. if(sequence[slot] > 254) {
  13. sequence[slot] = 0;
  14. }
  15. return sequence[slot]++;
  16. }
  17. void seader_ccid_IccPowerOn(SeaderUartBridge* seader_uart, uint8_t slot) {
  18. if(powered[slot]) {
  19. return;
  20. }
  21. powered[slot] = true;
  22. FURI_LOG_D(TAG, "Sending Power On (%d)", slot);
  23. memset(seader_uart->tx_buf, 0, SEADER_UART_RX_BUF_SIZE);
  24. seader_uart->tx_buf[0] = SYNC;
  25. seader_uart->tx_buf[1] = CTRL;
  26. seader_uart->tx_buf[2 + 0] = CCID_MESSAGE_TYPE_PC_to_RDR_IccPowerOn;
  27. seader_uart->tx_buf[2 + 5] = slot;
  28. seader_uart->tx_buf[2 + 6] = getSequence(slot);
  29. seader_uart->tx_buf[2 + 7] = 2; //power
  30. seader_uart->tx_len = seader_add_lrc(seader_uart->tx_buf, 2 + 10);
  31. furi_thread_flags_set(furi_thread_get_id(seader_uart->tx_thread), WorkerEvtSamRx);
  32. }
  33. void seader_ccid_check_for_sam(SeaderUartBridge* seader_uart) {
  34. hasSAM = false; // If someone is calling this, reset sam state
  35. powered[0] = false;
  36. powered[1] = false;
  37. retries = 3;
  38. seader_ccid_GetSlotStatus(seader_uart, 0);
  39. }
  40. void seader_ccid_GetSlotStatus(SeaderUartBridge* seader_uart, uint8_t slot) {
  41. FURI_LOG_D(TAG, "seader_ccid_GetSlotStatus(%d)", slot);
  42. memset(seader_uart->tx_buf, 0, SEADER_UART_RX_BUF_SIZE);
  43. seader_uart->tx_buf[0] = SYNC;
  44. seader_uart->tx_buf[1] = CTRL;
  45. seader_uart->tx_buf[2 + 0] = CCID_MESSAGE_TYPE_PC_to_RDR_GetSlotStatus;
  46. seader_uart->tx_buf[2 + 5] = slot;
  47. seader_uart->tx_buf[2 + 6] = getSequence(slot);
  48. seader_uart->tx_len = seader_add_lrc(seader_uart->tx_buf, 2 + 10);
  49. furi_thread_flags_set(furi_thread_get_id(seader_uart->tx_thread), WorkerEvtSamRx);
  50. }
  51. void seader_ccid_SetParameters(Seader* seader, uint8_t slot, uint8_t* atr, size_t atr_len) {
  52. SeaderWorker* seader_worker = seader->worker;
  53. SeaderUartBridge* seader_uart = seader_worker->uart;
  54. UNUSED(atr_len);
  55. FURI_LOG_D(TAG, "seader_ccid_SetParameters(%d)", slot);
  56. uint8_t payloadLen = 0;
  57. if(seader_uart->T == 0) {
  58. payloadLen = 5;
  59. } else if(atr[4] == 0xB1 && seader_uart->T == 1) {
  60. payloadLen = 7;
  61. }
  62. memset(seader_uart->tx_buf, 0, SEADER_UART_RX_BUF_SIZE);
  63. seader_uart->tx_buf[0] = SYNC;
  64. seader_uart->tx_buf[1] = CTRL;
  65. seader_uart->tx_buf[2 + 0] = CCID_MESSAGE_TYPE_PC_to_RDR_SetParameters;
  66. seader_uart->tx_buf[2 + 1] = payloadLen;
  67. seader_uart->tx_buf[2 + 5] = slot;
  68. seader_uart->tx_buf[2 + 6] = getSequence(slot);
  69. seader_uart->tx_buf[2 + 7] = seader_uart->T;
  70. seader_uart->tx_buf[2 + 8] = 0;
  71. seader_uart->tx_buf[2 + 9] = 0;
  72. if(seader_uart->T == 0) {
  73. // I'm leaving this here for completeness, but it was actually causing ICC_MUTE on the first apdu.
  74. seader_uart->tx_buf[2 + 10] = 0x96; //atr[2]; //bmFindexDindex
  75. seader_uart->tx_buf[2 + 11] = 0x00; //bmTCCKST1
  76. seader_uart->tx_buf[2 + 12] = 0x00; //bGuardTimeT0
  77. seader_uart->tx_buf[2 + 13] = 0x0a; //bWaitingIntegerT0
  78. seader_uart->tx_buf[2 + 14] = 0x00; //bClockStop
  79. } else if(seader_uart->T == 1) {
  80. seader_uart->tx_buf[2 + 10] = atr[2]; //bmFindexDindex
  81. seader_uart->tx_buf[2 + 11] = 0x10; //bmTCCKST1
  82. seader_uart->tx_buf[2 + 12] = 0xfe; //bGuardTimeT1
  83. seader_uart->tx_buf[2 + 13] = atr[6]; //bWaitingIntegerT1
  84. seader_uart->tx_buf[2 + 14] = atr[8]; //bClockStop
  85. seader_uart->tx_buf[2 + 15] = atr[5]; //bIFSC
  86. seader_uart->tx_buf[2 + 16] = 0x00; //bNadValue
  87. }
  88. seader_uart->tx_len = seader_add_lrc(seader_uart->tx_buf, 2 + 10 + payloadLen);
  89. furi_thread_flags_set(furi_thread_get_id(seader_uart->tx_thread), WorkerEvtSamRx);
  90. }
  91. void seader_ccid_GetParameters(SeaderUartBridge* seader_uart) {
  92. memset(seader_uart->tx_buf, 0, SEADER_UART_RX_BUF_SIZE);
  93. seader_uart->tx_buf[0] = SYNC;
  94. seader_uart->tx_buf[1] = CTRL;
  95. seader_uart->tx_buf[2 + 0] = CCID_MESSAGE_TYPE_PC_to_RDR_GetParameters;
  96. seader_uart->tx_buf[2 + 1] = 0;
  97. seader_uart->tx_buf[2 + 5] = sam_slot;
  98. seader_uart->tx_buf[2 + 6] = getSequence(sam_slot);
  99. seader_uart->tx_buf[2 + 7] = 0;
  100. seader_uart->tx_buf[2 + 8] = 0;
  101. seader_uart->tx_buf[2 + 9] = 0;
  102. seader_uart->tx_len = seader_add_lrc(seader_uart->tx_buf, 2 + 10);
  103. furi_thread_flags_set(furi_thread_get_id(seader_uart->tx_thread), WorkerEvtSamRx);
  104. }
  105. void seader_ccid_XfrBlock(SeaderUartBridge* seader_uart, uint8_t* data, size_t len) {
  106. seader_ccid_XfrBlockToSlot(seader_uart, sam_slot, data, len);
  107. }
  108. void seader_ccid_XfrBlockToSlot(
  109. SeaderUartBridge* seader_uart,
  110. uint8_t slot,
  111. uint8_t* data,
  112. size_t len) {
  113. memset(seader_uart->tx_buf, 0, SEADER_UART_RX_BUF_SIZE);
  114. seader_uart->tx_buf[0] = SYNC;
  115. seader_uart->tx_buf[1] = CTRL;
  116. seader_uart->tx_buf[2 + 0] = CCID_MESSAGE_TYPE_PC_to_RDR_XfrBlock;
  117. seader_uart->tx_buf[2 + 1] = (len >> 0) & 0xff;
  118. seader_uart->tx_buf[2 + 2] = (len >> 8) & 0xff;
  119. seader_uart->tx_buf[2 + 5] = slot;
  120. seader_uart->tx_buf[2 + 6] = getSequence(slot);
  121. seader_uart->tx_buf[2 + 7] = 5;
  122. seader_uart->tx_buf[2 + 8] = 0;
  123. seader_uart->tx_buf[2 + 9] = 0;
  124. uint8_t header_len = 2 + 10;
  125. memcpy(seader_uart->tx_buf + header_len, data, len);
  126. seader_uart->tx_len = header_len + len;
  127. seader_uart->tx_len = seader_add_lrc(seader_uart->tx_buf, seader_uart->tx_len);
  128. char display[SEADER_UART_RX_BUF_SIZE * 2 + 1] = {0};
  129. for(uint8_t i = 0; i < seader_uart->tx_len; i++) {
  130. snprintf(display + (i * 2), sizeof(display), "%02x", seader_uart->tx_buf[i]);
  131. }
  132. FURI_LOG_D(TAG, "seader_ccid_XfrBlockToSlot(%d) %d: %s", slot, seader_uart->tx_len, display);
  133. furi_thread_flags_set(furi_thread_get_id(seader_uart->tx_thread), WorkerEvtSamRx);
  134. }
  135. size_t seader_ccid_process(Seader* seader, uint8_t* cmd, size_t cmd_len) {
  136. SeaderWorker* seader_worker = seader->worker;
  137. SeaderUartBridge* seader_uart = seader_worker->uart;
  138. CCID_Message message;
  139. message.consumed = 0;
  140. char display[SEADER_UART_RX_BUF_SIZE * 2 + 1] = {0};
  141. for(uint8_t i = 0; i < cmd_len; i++) {
  142. snprintf(display + (i * 2), sizeof(display), "%02x", cmd[i]);
  143. }
  144. FURI_LOG_D(TAG, "seader_ccid_process %d: %s", cmd_len, display);
  145. if(cmd_len == 2) {
  146. if(cmd[0] == CCID_MESSAGE_TYPE_RDR_to_PC_NotifySlotChange) {
  147. switch(cmd[1] & SLOT_0_MASK) {
  148. case 0:
  149. case 1:
  150. // No change, no-op
  151. break;
  152. case CARD_IN_1:
  153. FURI_LOG_D(TAG, "Card Inserted (0)");
  154. if(hasSAM && sam_slot == 0) {
  155. break;
  156. }
  157. sequence[0] = 0;
  158. seader_ccid_IccPowerOn(seader_uart, 0);
  159. break;
  160. case CARD_OUT_1:
  161. FURI_LOG_D(TAG, "Card Removed (0)");
  162. if(hasSAM && sam_slot == 0) {
  163. powered[0] = false;
  164. hasSAM = false;
  165. retries = 3;
  166. if(seader_worker->callback) {
  167. seader_worker->callback(
  168. SeaderWorkerEventSamMissing, seader_worker->context);
  169. }
  170. }
  171. break;
  172. };
  173. switch(cmd[1] & SLOT_1_MASK) {
  174. case 0:
  175. case 1:
  176. // No change, no-op
  177. break;
  178. case CARD_IN_2:
  179. FURI_LOG_D(TAG, "Card Inserted (1)");
  180. if(hasSAM && sam_slot == 1) {
  181. break;
  182. }
  183. sequence[1] = 0;
  184. seader_ccid_IccPowerOn(seader_uart, 1);
  185. break;
  186. case CARD_OUT_2:
  187. FURI_LOG_D(TAG, "Card Removed (1)");
  188. if(hasSAM && sam_slot == 1) {
  189. powered[1] = false;
  190. hasSAM = false;
  191. retries = 3;
  192. if(seader_worker->callback) {
  193. seader_worker->callback(
  194. SeaderWorkerEventSamMissing, seader_worker->context);
  195. }
  196. }
  197. break;
  198. };
  199. return 2;
  200. }
  201. }
  202. while(cmd_len >= 3 && cmd[0] == SYNC && cmd[1] == NAK) {
  203. // 031516
  204. FURI_LOG_W(TAG, "NAK");
  205. cmd += 3;
  206. cmd_len -= 3;
  207. message.consumed += 3;
  208. }
  209. while(cmd_len > 2 && (cmd[0] != SYNC || cmd[1] != CTRL)) {
  210. FURI_LOG_W(TAG, "invalid start: %02x", cmd[0]);
  211. cmd += 1;
  212. cmd_len -= 1;
  213. message.consumed += 1;
  214. }
  215. if(cmd_len > 12 && cmd[0] == SYNC && cmd[1] == CTRL) {
  216. uint8_t* ccid = cmd + 2;
  217. message.bMessageType = ccid[0];
  218. message.dwLength = *((uint32_t*)(ccid + 1));
  219. message.bSlot = ccid[5];
  220. message.bSeq = ccid[6];
  221. message.bStatus = ccid[7];
  222. message.bError = ccid[8];
  223. message.payload = ccid + 10;
  224. memset(display, 0, sizeof(display));
  225. for(uint8_t i = 0; i < message.dwLength; i++) {
  226. snprintf(display + (i * 2), sizeof(display), "%02x", message.payload[i]);
  227. }
  228. if(cmd_len < 2 + 10 + message.dwLength + 1) {
  229. // Incomplete
  230. return message.consumed;
  231. }
  232. message.consumed += 2 + 10 + message.dwLength + 1;
  233. if(seader_validate_lrc(cmd, 2 + 10 + message.dwLength + 1) == false) {
  234. FURI_LOG_W(
  235. TAG,
  236. "Invalid LRC. Recv: %02x vs Calc: %02x",
  237. cmd[2 + 10 + message.dwLength + 1],
  238. seader_calc_lrc(cmd, 2 + 10 + message.dwLength));
  239. // TODO: Should I respond with an error?
  240. return message.consumed;
  241. }
  242. /*
  243. if(message.dwLength == 0) {
  244. FURI_LOG_D(
  245. TAG,
  246. "CCID [%d|%d] type: %02x, status: %02x, error: %02x",
  247. message.bSlot,
  248. message.bSeq,
  249. message.bMessageType,
  250. message.bStatus,
  251. message.bError);
  252. } else {
  253. FURI_LOG_D(
  254. TAG,
  255. "CCID [%d|%d] %ld: %s",
  256. message.bSlot,
  257. message.bSeq,
  258. message.dwLength,
  259. display);
  260. }
  261. */
  262. //0306 81 00000000 0000 0200 01 87
  263. //0306 81 00000000 0000 0100 01 84
  264. if(message.bMessageType == CCID_MESSAGE_TYPE_RDR_to_PC_SlotStatus) {
  265. uint8_t status = (message.bStatus & BMICCSTATUS_MASK);
  266. if(status == 0 || status == 1) {
  267. seader_ccid_IccPowerOn(seader_uart, message.bSlot);
  268. return message.consumed;
  269. } else if(status == 2) {
  270. FURI_LOG_W(TAG, "No ICC is present [retries %d]", retries);
  271. if(retries-- > 1 && hasSAM == false) {
  272. furi_delay_ms(100);
  273. seader_ccid_GetSlotStatus(seader_uart, retries % 2);
  274. } else {
  275. if(seader_worker->callback) {
  276. seader_worker->callback(
  277. SeaderWorkerEventSamMissing, seader_worker->context);
  278. }
  279. }
  280. return message.consumed;
  281. }
  282. }
  283. //0306 80 00000000 0001 42fe 00 38
  284. if(message.bStatus == 0x41 && message.bError == 0xfe) {
  285. FURI_LOG_W(TAG, "card probably upside down");
  286. hasSAM = false;
  287. if(seader_worker->callback) {
  288. seader_worker->callback(SeaderWorkerEventSamMissing, seader_worker->context);
  289. }
  290. return message.consumed;
  291. }
  292. if(message.bStatus == 0x42 && message.bError == 0xfe) {
  293. FURI_LOG_W(TAG, "No card");
  294. if(seader_worker->callback) {
  295. seader_worker->callback(SeaderWorkerEventSamMissing, seader_worker->context);
  296. }
  297. return message.consumed;
  298. }
  299. if(message.bError != 0) {
  300. FURI_LOG_W(TAG, "CCID error %02x", message.bError);
  301. message.consumed = cmd_len;
  302. if(seader_worker->callback) {
  303. seader_worker->callback(SeaderWorkerEventSamMissing, seader_worker->context);
  304. }
  305. return message.consumed;
  306. }
  307. if(message.bMessageType == CCID_MESSAGE_TYPE_RDR_to_PC_Parameters) {
  308. FURI_LOG_D(TAG, "Got Parameters");
  309. if(seader_uart->T == 1) {
  310. seader_t_1_set_IFSD(seader);
  311. } else {
  312. seader_worker_send_version(seader);
  313. if(seader_worker->callback) {
  314. seader_worker->callback(SeaderWorkerEventSamPresent, seader_worker->context);
  315. }
  316. }
  317. } else if(message.bMessageType == CCID_MESSAGE_TYPE_RDR_to_PC_DataBlock) {
  318. if(hasSAM) {
  319. if(message.bSlot == sam_slot) {
  320. if(seader_uart->T == 0) {
  321. seader_worker_process_sam_message(
  322. seader, message.payload, message.dwLength);
  323. } else if(seader_uart->T == 1) {
  324. seader_recv_t1(seader, &message);
  325. }
  326. } else {
  327. FURI_LOG_D(TAG, "Discarding message on non-sam slot");
  328. }
  329. } else {
  330. if(memcmp(SAM_ATR, message.payload, sizeof(SAM_ATR)) == 0) {
  331. FURI_LOG_I(TAG, "SAM ATR!");
  332. hasSAM = true;
  333. sam_slot = message.bSlot;
  334. if(seader_uart->T == 0) {
  335. seader_ccid_GetParameters(seader_uart);
  336. } else if(seader_uart->T == 1) {
  337. seader_ccid_SetParameters(
  338. seader, sam_slot, message.payload, message.dwLength);
  339. }
  340. } else if(memcmp(SAM_ATR2, message.payload, sizeof(SAM_ATR2)) == 0) {
  341. FURI_LOG_I(TAG, "SAM ATR2!");
  342. hasSAM = true;
  343. sam_slot = message.bSlot;
  344. // I don't have an ATR2 to test with
  345. seader_ccid_GetParameters(seader_uart);
  346. } else {
  347. FURI_LOG_W(TAG, "Unknown ATR");
  348. if(seader_worker->callback) {
  349. seader_worker->callback(SeaderWorkerEventSamWrong, seader_worker->context);
  350. }
  351. }
  352. }
  353. } else {
  354. FURI_LOG_W(TAG, "Unhandled CCID message type %02x", message.bMessageType);
  355. }
  356. }
  357. return message.consumed;
  358. }