seader_worker.c 31 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963
  1. #include "seader_worker_i.h"
  2. #include <flipper_format/flipper_format.h>
  3. #define TAG "SeaderWorker"
  4. #define APDU_HEADER_LEN 5
  5. #define ASN1_PREFIX 6
  6. #define ASN1_DEBUG true
  7. #define RFAL_PICOPASS_TXRX_FLAGS \
  8. (FURI_HAL_NFC_LL_TXRX_FLAGS_CRC_TX_MANUAL | FURI_HAL_NFC_LL_TXRX_FLAGS_AGC_ON | \
  9. FURI_HAL_NFC_LL_TXRX_FLAGS_PAR_RX_REMV | FURI_HAL_NFC_LL_TXRX_FLAGS_CRC_RX_KEEP)
  10. // TODO: const
  11. uint8_t GET_RESPONSE[] = {0x00, 0xc0, 0x00, 0x00, 0xff};
  12. char payloadDebug[384] = {0};
  13. char display[SEADER_UART_RX_BUF_SIZE * 2 + 1] = {0};
  14. char asn1_log[SEADER_UART_RX_BUF_SIZE] = {0};
  15. bool requestPacs = true;
  16. // Forward declaration
  17. void seader_send_card_detected(SeaderUartBridge* seader_uart, CardDetails_t* cardDetails);
  18. static void seader_worker_enable_field() {
  19. furi_hal_nfc_ll_txrx_on();
  20. furi_hal_nfc_exit_sleep();
  21. furi_hal_nfc_ll_poll();
  22. }
  23. static ReturnCode seader_worker_disable_field(ReturnCode rc) {
  24. furi_hal_nfc_ll_txrx_off();
  25. furi_hal_nfc_start_sleep();
  26. return rc;
  27. }
  28. static uint16_t seader_worker_picopass_update_ccitt(uint16_t crcSeed, uint8_t dataByte) {
  29. uint16_t crc = crcSeed;
  30. uint8_t dat = dataByte;
  31. dat ^= (uint8_t)(crc & 0xFFU);
  32. dat ^= (dat << 4);
  33. crc = (crc >> 8) ^ (((uint16_t)dat) << 8) ^ (((uint16_t)dat) << 3) ^ (((uint16_t)dat) >> 4);
  34. return crc;
  35. }
  36. static uint16_t
  37. seader_worker_picopass_calculate_ccitt(uint16_t preloadValue, const uint8_t* buf, uint16_t length) {
  38. uint16_t crc = preloadValue;
  39. uint16_t index;
  40. for(index = 0; index < length; index++) {
  41. crc = seader_worker_picopass_update_ccitt(crc, buf[index]);
  42. }
  43. return crc;
  44. }
  45. /***************************** Seader Worker API *******************************/
  46. SeaderWorker* seader_worker_alloc() {
  47. SeaderWorker* seader_worker = malloc(sizeof(SeaderWorker));
  48. // Worker thread attributes
  49. seader_worker->thread =
  50. furi_thread_alloc_ex("SeaderWorker", 8192, seader_worker_task, seader_worker);
  51. seader_worker->callback = NULL;
  52. seader_worker->context = NULL;
  53. seader_worker->storage = furi_record_open(RECORD_STORAGE);
  54. memset(seader_worker->sam_version, 0, sizeof(seader_worker->sam_version));
  55. seader_worker_change_state(seader_worker, SeaderWorkerStateReady);
  56. return seader_worker;
  57. }
  58. void seader_worker_free(SeaderWorker* seader_worker) {
  59. furi_assert(seader_worker);
  60. furi_thread_free(seader_worker->thread);
  61. furi_record_close(RECORD_STORAGE);
  62. free(seader_worker);
  63. }
  64. SeaderWorkerState seader_worker_get_state(SeaderWorker* seader_worker) {
  65. return seader_worker->state;
  66. }
  67. void seader_worker_start(
  68. SeaderWorker* seader_worker,
  69. SeaderWorkerState state,
  70. SeaderUartBridge* uart,
  71. SeaderCredential* credential,
  72. SeaderWorkerCallback callback,
  73. void* context) {
  74. furi_assert(seader_worker);
  75. furi_assert(uart);
  76. furi_assert(credential);
  77. seader_worker->callback = callback;
  78. seader_worker->context = context;
  79. seader_worker->uart = uart;
  80. seader_worker->credential = credential;
  81. seader_worker_change_state(seader_worker, state);
  82. furi_thread_start(seader_worker->thread);
  83. }
  84. void seader_worker_stop(SeaderWorker* seader_worker) {
  85. furi_assert(seader_worker);
  86. if(seader_worker->state == SeaderWorkerStateBroken ||
  87. seader_worker->state == SeaderWorkerStateReady) {
  88. return;
  89. }
  90. seader_worker_disable_field(ERR_NONE);
  91. seader_worker_change_state(seader_worker, SeaderWorkerStateStop);
  92. furi_thread_join(seader_worker->thread);
  93. }
  94. void seader_worker_change_state(SeaderWorker* seader_worker, SeaderWorkerState state) {
  95. seader_worker->state = state;
  96. }
  97. /***************************** Seader Worker Thread *******************************/
  98. void* calloc(size_t count, size_t size) {
  99. return malloc(count * size);
  100. }
  101. void seader_nfc_scene_field_on_enter() {
  102. furi_hal_nfc_field_on();
  103. furi_hal_nfc_exit_sleep();
  104. }
  105. void seader_nfc_scene_field_on_exit() {
  106. furi_hal_nfc_sleep();
  107. furi_hal_nfc_field_off();
  108. }
  109. bool seader_send_apdu(
  110. SeaderUartBridge* seader_uart,
  111. uint8_t CLA,
  112. uint8_t INS,
  113. uint8_t P1,
  114. uint8_t P2,
  115. uint8_t* payload,
  116. uint8_t length) {
  117. if(APDU_HEADER_LEN + length > SEADER_UART_RX_BUF_SIZE) {
  118. FURI_LOG_E(TAG, "Cannot send message, too long: %d", APDU_HEADER_LEN + length);
  119. return false;
  120. }
  121. uint8_t* apdu = malloc(APDU_HEADER_LEN + length);
  122. apdu[0] = CLA;
  123. apdu[1] = INS;
  124. apdu[2] = P1;
  125. apdu[3] = P2;
  126. apdu[4] = length;
  127. memcpy(apdu + APDU_HEADER_LEN, payload, length);
  128. seader_ccid_XfrBlock(seader_uart, apdu, APDU_HEADER_LEN + length);
  129. free(apdu);
  130. return true;
  131. }
  132. static int seader_asn_to_string(const void* buffer, size_t size, void* app_key) {
  133. if(app_key) {
  134. char* str = (char*)app_key;
  135. size_t next = strlen(str);
  136. strncpy(str + next, buffer, size);
  137. } else {
  138. uint8_t next = strlen(asn1_log);
  139. strncpy(asn1_log + next, buffer, size);
  140. }
  141. return 0;
  142. }
  143. bool seader_mf_df_check_card_type(uint8_t ATQA0, uint8_t ATQA1, uint8_t SAK) {
  144. return ATQA0 == 0x44 && ATQA1 == 0x03 && SAK == 0x20;
  145. }
  146. bool seader_mf_classic_check_card_type(uint8_t ATQA0, uint8_t ATQA1, uint8_t SAK) {
  147. if((ATQA0 == 0x44 || ATQA0 == 0x04) && (SAK == 0x08 || SAK == 0x88 || SAK == 0x09)) {
  148. return true;
  149. } else if((ATQA0 == 0x01) && (ATQA1 == 0x0F) && (SAK == 0x01)) {
  150. //skylanders support
  151. return true;
  152. } else if((ATQA0 == 0x42 || ATQA0 == 0x02) && (SAK == 0x18)) {
  153. return true;
  154. } else {
  155. return false;
  156. }
  157. }
  158. bool seader_read_nfc(SeaderUartBridge* seader_uart) {
  159. FuriHalNfcDevData nfc_data = {};
  160. bool rtn = false;
  161. if(furi_hal_nfc_detect(&nfc_data, 300)) {
  162. // Process first found device
  163. if(nfc_data.type == FuriHalNfcTypeA) {
  164. FURI_LOG_D(TAG, "NFC-A detected");
  165. CardDetails_t* cardDetails = 0;
  166. cardDetails = calloc(1, sizeof *cardDetails);
  167. assert(cardDetails);
  168. OCTET_STRING_fromBuf(&cardDetails->csn, (const char*)nfc_data.uid, nfc_data.uid_len);
  169. uint8_t protocolBytes[] = {0x00, FrameProtocol_nfc};
  170. OCTET_STRING_fromBuf(
  171. &cardDetails->protocol, (const char*)protocolBytes, sizeof(protocolBytes));
  172. OCTET_STRING_t sak = {.buf = &(nfc_data.sak), .size = 1};
  173. cardDetails->sak = &sak;
  174. uint8_t fake_seos_ats[] = {0x78, 0x77, 0x80, 0x02};
  175. uint8_t fake_desfire_ats[] = {0x75, 0x77, 0x81, 0x02, 0x80};
  176. if(seader_mf_df_check_card_type(nfc_data.atqa[0], nfc_data.atqa[1], nfc_data.sak)) {
  177. FURI_LOG_D(TAG, "Desfire");
  178. OCTET_STRING_t atqa = {.buf = fake_desfire_ats, .size = sizeof(fake_desfire_ats)};
  179. cardDetails->atqa = &atqa;
  180. seader_send_card_detected(seader_uart, cardDetails);
  181. rtn = true;
  182. } else if(seader_mf_classic_check_card_type(
  183. nfc_data.atqa[0], nfc_data.atqa[1], nfc_data.sak)) {
  184. FURI_LOG_D(TAG, "MFC");
  185. OCTET_STRING_t atqa = {.buf = nfc_data.atqa, .size = sizeof(nfc_data.atqa)};
  186. cardDetails->atqa = &atqa;
  187. seader_send_card_detected(seader_uart, cardDetails);
  188. rtn = true;
  189. } else if(nfc_data.interface == FuriHalNfcInterfaceIsoDep) {
  190. FURI_LOG_D(TAG, "ISO-DEP");
  191. OCTET_STRING_t atqa = {.buf = fake_seos_ats, .size = sizeof(fake_seos_ats)};
  192. cardDetails->atqa = &atqa;
  193. seader_send_card_detected(seader_uart, cardDetails);
  194. rtn = true;
  195. }
  196. ASN_STRUCT_FREE(asn_DEF_CardDetails, cardDetails);
  197. }
  198. }
  199. return rtn;
  200. }
  201. bool seader_detect_nfc(SeaderWorker* seader_worker) {
  202. SeaderUartBridge* seader_uart = seader_worker->uart;
  203. while(seader_worker->state == SeaderWorkerStateRead14a) {
  204. // Card found
  205. if(seader_read_nfc(seader_uart)) {
  206. return true;
  207. }
  208. furi_delay_ms(100);
  209. }
  210. return false;
  211. }
  212. void seader_send_payload(
  213. SeaderUartBridge* seader_uart,
  214. Payload_t* payload,
  215. uint8_t to,
  216. uint8_t from,
  217. uint8_t replyTo) {
  218. uint8_t rBuffer[SEADER_UART_RX_BUF_SIZE] = {0};
  219. asn_enc_rval_t er = der_encode_to_buffer(
  220. &asn_DEF_Payload, payload, rBuffer + ASN1_PREFIX, sizeof(rBuffer) - ASN1_PREFIX);
  221. #ifdef ASN1_DEBUG
  222. if(er.encoded > -1) {
  223. memset(payloadDebug, 0, sizeof(payloadDebug));
  224. (&asn_DEF_Payload)
  225. ->op->print_struct(&asn_DEF_Payload, payload, 1, seader_asn_to_string, payloadDebug);
  226. if(strlen(payloadDebug) > 0) {
  227. FURI_LOG_D(TAG, "Sending payload: %s", payloadDebug);
  228. }
  229. }
  230. #endif
  231. //0xa0, 0xda, 0x02, 0x63, 0x00, 0x00, 0x0a,
  232. //0x44, 0x0a, 0x44, 0x00, 0x00, 0x00, 0xa0, 0x02, 0x96, 0x00
  233. rBuffer[0] = to;
  234. rBuffer[1] = from;
  235. rBuffer[2] = replyTo;
  236. seader_send_apdu(seader_uart, 0xA0, 0xDA, 0x02, 0x63, rBuffer, 6 + er.encoded);
  237. }
  238. void seader_send_response(
  239. SeaderUartBridge* seader_uart,
  240. Response_t* response,
  241. uint8_t to,
  242. uint8_t from,
  243. uint8_t replyTo) {
  244. Payload_t* payload = 0;
  245. payload = calloc(1, sizeof *payload);
  246. assert(payload);
  247. payload->present = Payload_PR_response;
  248. payload->choice.response = *response;
  249. seader_send_payload(seader_uart, payload, to, from, replyTo);
  250. ASN_STRUCT_FREE(asn_DEF_Payload, payload);
  251. }
  252. void sendRequestPacs(SeaderUartBridge* seader_uart) {
  253. RequestPacs_t* requestPacs = 0;
  254. requestPacs = calloc(1, sizeof *requestPacs);
  255. assert(requestPacs);
  256. requestPacs->contentElementTag = ContentElementTag_implicitFormatPhysicalAccessBits;
  257. SamCommand_t* samCommand = 0;
  258. samCommand = calloc(1, sizeof *samCommand);
  259. assert(samCommand);
  260. samCommand->present = SamCommand_PR_requestPacs;
  261. samCommand->choice.requestPacs = *requestPacs;
  262. Payload_t* payload = 0;
  263. payload = calloc(1, sizeof *payload);
  264. assert(payload);
  265. payload->present = Payload_PR_samCommand;
  266. payload->choice.samCommand = *samCommand;
  267. seader_send_payload(seader_uart, payload, 0x44, 0x0a, 0x44);
  268. ASN_STRUCT_FREE(asn_DEF_RequestPacs, requestPacs);
  269. ASN_STRUCT_FREE(asn_DEF_SamCommand, samCommand);
  270. ASN_STRUCT_FREE(asn_DEF_Payload, payload);
  271. }
  272. void seader_worker_send_version(SeaderWorker* seader_worker) {
  273. SeaderUartBridge* seader_uart = seader_worker->uart;
  274. SamCommand_t* samCommand = 0;
  275. samCommand = calloc(1, sizeof *samCommand);
  276. assert(samCommand);
  277. samCommand->present = SamCommand_PR_version;
  278. Payload_t* payload = 0;
  279. payload = calloc(1, sizeof *payload);
  280. assert(payload);
  281. payload->present = Payload_PR_samCommand;
  282. payload->choice.samCommand = *samCommand;
  283. seader_send_payload(seader_uart, payload, 0x44, 0x0a, 0x44);
  284. ASN_STRUCT_FREE(asn_DEF_SamCommand, samCommand);
  285. ASN_STRUCT_FREE(asn_DEF_Payload, payload);
  286. }
  287. void seader_send_card_detected(SeaderUartBridge* seader_uart, CardDetails_t* cardDetails) {
  288. CardDetected_t* cardDetected = 0;
  289. cardDetected = calloc(1, sizeof *cardDetected);
  290. assert(cardDetected);
  291. cardDetected->detectedCardDetails = *cardDetails;
  292. SamCommand_t* samCommand = 0;
  293. samCommand = calloc(1, sizeof *samCommand);
  294. assert(samCommand);
  295. samCommand->present = SamCommand_PR_cardDetected;
  296. samCommand->choice.cardDetected = *cardDetected;
  297. Payload_t* payload = 0;
  298. payload = calloc(1, sizeof *payload);
  299. assert(payload);
  300. payload->present = Payload_PR_samCommand;
  301. payload->choice.samCommand = *samCommand;
  302. seader_send_payload(seader_uart, payload, 0x44, 0x0a, 0x44);
  303. ASN_STRUCT_FREE(asn_DEF_CardDetected, cardDetected);
  304. ASN_STRUCT_FREE(asn_DEF_SamCommand, samCommand);
  305. ASN_STRUCT_FREE(asn_DEF_Payload, payload);
  306. }
  307. bool seader_unpack_pacs(
  308. SeaderWorker* seader_worker,
  309. SeaderCredential* seader_credential,
  310. uint8_t* buf,
  311. size_t size) {
  312. PAC_t* pac = 0;
  313. pac = calloc(1, sizeof *pac);
  314. assert(pac);
  315. bool rtn = false;
  316. asn_dec_rval_t rval = asn_decode(0, ATS_DER, &asn_DEF_PAC, (void**)&pac, buf, size);
  317. if(rval.code == RC_OK) {
  318. char pacDebug[384] = {0};
  319. (&asn_DEF_PAC)->op->print_struct(&asn_DEF_PAC, pac, 1, seader_asn_to_string, pacDebug);
  320. if(strlen(pacDebug) > 0) {
  321. FURI_LOG_D(TAG, "Received pac: %s", pacDebug);
  322. memset(display, 0, sizeof(display));
  323. if(seader_credential->sio[0] == 0x30) {
  324. for(uint8_t i = 0; i < sizeof(seader_credential->sio); i++) {
  325. snprintf(
  326. display + (i * 2), sizeof(display), "%02x", seader_credential->sio[i]);
  327. }
  328. FURI_LOG_D(TAG, "SIO %s", display);
  329. }
  330. }
  331. if(pac->size <= sizeof(seader_credential->credential)) {
  332. // TODO: make credential into a 12 byte array
  333. seader_credential->bit_length = pac->size * 8 - pac->bits_unused;
  334. memcpy(&seader_credential->credential, pac->buf, pac->size);
  335. seader_credential->credential = __builtin_bswap64(seader_credential->credential);
  336. seader_credential->credential = seader_credential->credential >>
  337. (64 - seader_credential->bit_length);
  338. rtn = true;
  339. } else {
  340. // PACS too big (probably bad data)
  341. if(seader_worker->callback) {
  342. seader_worker->callback(SeaderWorkerEventFail, seader_worker->context);
  343. }
  344. }
  345. }
  346. ASN_STRUCT_FREE(asn_DEF_PAC, pac);
  347. return rtn;
  348. }
  349. // 800201298106683d052026b6820101
  350. //300F800201298106683D052026B6820101
  351. bool seader_parse_version(SeaderWorker* seader_worker, uint8_t* buf, size_t size) {
  352. SamVersion_t* version = 0;
  353. version = calloc(1, sizeof *version);
  354. assert(version);
  355. bool rtn = false;
  356. if(size > 30) {
  357. // Too large to handle now
  358. FURI_LOG_W(TAG, "Version of %d is to long to parse", size);
  359. return false;
  360. }
  361. // Add sequence prefix
  362. uint8_t seq[32] = {0x30};
  363. seq[1] = (uint8_t)size;
  364. memcpy(seq + 2, buf, size);
  365. asn_dec_rval_t rval =
  366. asn_decode(0, ATS_DER, &asn_DEF_SamVersion, (void**)&version, seq, size + 2);
  367. if(rval.code == RC_OK) {
  368. char versionDebug[128] = {0};
  369. (&asn_DEF_SamVersion)
  370. ->op->print_struct(
  371. &asn_DEF_SamVersion, version, 1, seader_asn_to_string, versionDebug);
  372. if(strlen(versionDebug) > 0) {
  373. FURI_LOG_D(TAG, "Received version: %s", versionDebug);
  374. }
  375. if(version->version.size == 2) {
  376. memcpy(seader_worker->sam_version, version->version.buf, version->version.size);
  377. }
  378. rtn = true;
  379. }
  380. ASN_STRUCT_FREE(asn_DEF_SamVersion, version);
  381. return rtn;
  382. }
  383. bool seader_parse_sam_response(SeaderWorker* seader_worker, SamResponse_t* samResponse) {
  384. SeaderUartBridge* seader_uart = seader_worker->uart;
  385. SeaderCredential* credential = seader_worker->credential;
  386. if(samResponse->size == 0) {
  387. if(requestPacs) {
  388. // FURI_LOG_D(TAG, "samResponse %d => requesting PACS", samResponse->size);
  389. sendRequestPacs(seader_uart);
  390. requestPacs = false;
  391. } else {
  392. // FURI_LOG_D(TAG, "samResponse %d, no action", samResponse->size);
  393. if(seader_worker->callback) {
  394. seader_worker->callback(SeaderWorkerEventFail, seader_worker->context);
  395. }
  396. }
  397. } else if(seader_parse_version(seader_worker, samResponse->buf, samResponse->size)) {
  398. // no-op
  399. } else if(seader_unpack_pacs(seader_worker, credential, samResponse->buf, samResponse->size)) {
  400. if(seader_worker->callback) {
  401. seader_worker->callback(SeaderWorkerEventSuccess, seader_worker->context);
  402. }
  403. } else {
  404. memset(display, 0, sizeof(display));
  405. for(uint8_t i = 0; i < samResponse->size; i++) {
  406. snprintf(display + (i * 2), sizeof(display), "%02x", samResponse->buf[i]);
  407. }
  408. FURI_LOG_D(TAG, "unknown samResponse %d: %s", samResponse->size, display);
  409. }
  410. return false;
  411. }
  412. bool seader_parse_response(SeaderWorker* seader_worker, Response_t* response) {
  413. switch(response->present) {
  414. case Response_PR_samResponse:
  415. seader_parse_sam_response(seader_worker, &response->choice.samResponse);
  416. break;
  417. default:
  418. break;
  419. };
  420. return false;
  421. }
  422. void seader_send_nfc_rx(SeaderUartBridge* seader_uart, uint8_t* buffer, size_t len) {
  423. OCTET_STRING_t rxData = {.buf = buffer, .size = len};
  424. uint8_t status[] = {0x00, 0x00};
  425. RfStatus_t rfStatus = {.buf = status, .size = 2};
  426. NFCRx_t* nfcRx = 0;
  427. nfcRx = calloc(1, sizeof *nfcRx);
  428. assert(nfcRx);
  429. nfcRx->rfStatus = rfStatus;
  430. nfcRx->data = &rxData;
  431. NFCResponse_t* nfcResponse = 0;
  432. nfcResponse = calloc(1, sizeof *nfcResponse);
  433. assert(nfcResponse);
  434. nfcResponse->present = NFCResponse_PR_nfcRx;
  435. nfcResponse->choice.nfcRx = *nfcRx;
  436. Response_t* response = 0;
  437. response = calloc(1, sizeof *response);
  438. assert(response);
  439. response->present = Response_PR_nfcResponse;
  440. response->choice.nfcResponse = *nfcResponse;
  441. seader_send_response(seader_uart, response, 0x14, 0x0a, 0x0);
  442. ASN_STRUCT_FREE(asn_DEF_NFCRx, nfcRx);
  443. ASN_STRUCT_FREE(asn_DEF_NFCResponse, nfcResponse);
  444. ASN_STRUCT_FREE(asn_DEF_Response, response);
  445. }
  446. bool seader_iso14443a_transmit(SeaderWorker* seader_worker, uint8_t* buffer, size_t len) {
  447. SeaderUartBridge* seader_uart = seader_worker->uart;
  448. FuriHalNfcTxRxContext tx_rx = {.tx_rx_type = FuriHalNfcTxRxTypeDefault};
  449. memcpy(&tx_rx.tx_data, buffer, len);
  450. tx_rx.tx_bits = len * 8;
  451. if(furi_hal_nfc_tx_rx_full(&tx_rx)) {
  452. furi_delay_ms(1);
  453. size_t length = tx_rx.rx_bits / 8;
  454. memset(display, 0, sizeof(display));
  455. for(uint8_t i = 0; i < length; i++) {
  456. snprintf(display + (i * 2), sizeof(display), "%02x", tx_rx.rx_data[i]);
  457. }
  458. // FURI_LOG_D(TAG, "NFC Response %d: %s", length, display);
  459. seader_send_nfc_rx(seader_uart, tx_rx.rx_data, length);
  460. } else {
  461. FURI_LOG_W(TAG, "Bad exchange");
  462. if(seader_worker->callback) {
  463. seader_worker->callback(SeaderWorkerEventFail, seader_worker->context);
  464. }
  465. }
  466. return false;
  467. }
  468. uint8_t read4Block6[] = {0x06, 0x06, 0x45, 0x56};
  469. uint8_t read4Block9[] = {0x06, 0x09, 0xB2, 0xAE};
  470. uint8_t read4Block10[] = {0x06, 0x0A, 0x29, 0x9C};
  471. uint8_t read4Block13[] = {0x06, 0x0D, 0x96, 0xE8};
  472. uint8_t updateBlock2[] = {0x87, 0x02};
  473. void seader_capture_sio(
  474. uint8_t* buffer,
  475. size_t len,
  476. uint8_t* rxBuffer,
  477. SeaderCredential* credential) {
  478. if(memcmp(buffer, read4Block6, len) == 0 && rxBuffer[0] == 0x30) {
  479. memcpy(credential->sio, rxBuffer, 32);
  480. } else if(memcmp(buffer, read4Block10, len) == 0 && rxBuffer[0] == 0x30) {
  481. memcpy(credential->sio, rxBuffer, 32);
  482. } else if(memcmp(buffer, read4Block9, len) == 0) {
  483. memcpy(credential->sio + 32, rxBuffer + 8, 24);
  484. } else if(memcmp(buffer, read4Block13, len) == 0) {
  485. memcpy(credential->sio + 32, rxBuffer + 8, 24);
  486. }
  487. }
  488. FuriHalNfcReturn
  489. seader_worker_fake_epurse_update(uint8_t* buffer, uint8_t* rxBuffer, uint16_t* recvLen) {
  490. uint8_t fake_response[10];
  491. memset(fake_response, 0, sizeof(fake_response));
  492. memcpy(fake_response + 0, buffer + 6, 4);
  493. memcpy(fake_response + 4, buffer + 2, 4);
  494. uint16_t crc = seader_worker_picopass_calculate_ccitt(0xE012, fake_response, 8);
  495. memcpy(fake_response + 8, &crc, sizeof(uint16_t));
  496. memcpy(rxBuffer, fake_response, sizeof(fake_response));
  497. *recvLen = sizeof(fake_response);
  498. memset(display, 0, sizeof(display));
  499. for(uint8_t i = 0; i < sizeof(fake_response); i++) {
  500. snprintf(display + (i * 2), sizeof(display), "%02x", fake_response[i]);
  501. }
  502. FURI_LOG_I(TAG, "Fake update E-Purse response: %s", display);
  503. return FuriHalNfcReturnOk;
  504. }
  505. bool seader_iso15693_transmit(SeaderWorker* seader_worker, uint8_t* buffer, size_t len) {
  506. SeaderUartBridge* seader_uart = seader_worker->uart;
  507. SeaderCredential* credential = seader_worker->credential;
  508. char display[SEADER_UART_RX_BUF_SIZE * 2 + 1] = {0};
  509. FuriHalNfcReturn ret;
  510. uint16_t recvLen = 0;
  511. uint32_t flags = RFAL_PICOPASS_TXRX_FLAGS;
  512. uint32_t fwt = furi_hal_nfc_ll_ms2fc(20);
  513. uint8_t rxBuffer[64] = {0};
  514. if(memcmp(buffer, updateBlock2, sizeof(updateBlock2)) == 0) {
  515. ret = seader_worker_fake_epurse_update(buffer, rxBuffer, &recvLen);
  516. } else {
  517. ret = furi_hal_nfc_ll_txrx(buffer, len, rxBuffer, sizeof(rxBuffer), &recvLen, flags, fwt);
  518. }
  519. if(ret == FuriHalNfcReturnOk) {
  520. memset(display, 0, sizeof(display));
  521. for(uint8_t i = 0; i < recvLen; i++) {
  522. snprintf(display + (i * 2), sizeof(display), "%02x", rxBuffer[i]);
  523. }
  524. // FURI_LOG_D(TAG, "Result %d %s", recvLen, display);
  525. seader_capture_sio(buffer, len, rxBuffer, credential);
  526. seader_send_nfc_rx(seader_uart, rxBuffer, recvLen);
  527. } else if(ret == FuriHalNfcReturnCrc) {
  528. memset(display, 0, sizeof(display));
  529. for(uint8_t i = 0; i < recvLen; i++) {
  530. snprintf(display + (i * 2), sizeof(display), "%02x", rxBuffer[i]);
  531. }
  532. // FURI_LOG_D(TAG, "[CRC error] Result %d %s", recvLen, display);
  533. seader_capture_sio(buffer, len, rxBuffer, credential);
  534. seader_send_nfc_rx(seader_uart, rxBuffer, recvLen);
  535. // Act as if it was OK
  536. return true;
  537. } else {
  538. FURI_LOG_E(TAG, "furi_hal_nfc_ll_txrx Error %d", ret);
  539. if(seader_worker->callback) {
  540. seader_worker->callback(SeaderWorkerEventFail, seader_worker->context);
  541. }
  542. }
  543. return ret == FuriHalNfcReturnOk;
  544. }
  545. bool seader_parse_nfc_command_transmit(SeaderWorker* seader_worker, NFCSend_t* nfcSend) {
  546. long timeOut = nfcSend->timeOut;
  547. Protocol_t protocol = nfcSend->protocol;
  548. FrameProtocol_t frameProtocol = protocol.buf[1];
  549. #ifdef ASN1_DEBUG
  550. memset(display, 0, sizeof(display));
  551. for(uint8_t i = 0; i < nfcSend->data.size; i++) {
  552. snprintf(display + (i * 2), sizeof(display), "%02x", nfcSend->data.buf[i]);
  553. }
  554. char protocolName[8] = {0};
  555. memset(protocolName, 0, sizeof(protocolName));
  556. (&asn_DEF_FrameProtocol)
  557. ->op->print_struct(
  558. &asn_DEF_FrameProtocol, &frameProtocol, 1, seader_asn_to_string, protocolName);
  559. FURI_LOG_D(
  560. TAG,
  561. "Transmit (%ld timeout) %d bytes [%s] via %s",
  562. timeOut,
  563. nfcSend->data.size,
  564. display,
  565. protocolName);
  566. #else
  567. UNUSED(timeOut);
  568. #endif
  569. if(frameProtocol == FrameProtocol_iclass) {
  570. return seader_iso15693_transmit(seader_worker, nfcSend->data.buf, nfcSend->data.size);
  571. } else if(frameProtocol == FrameProtocol_nfc) {
  572. return seader_iso14443a_transmit(seader_worker, nfcSend->data.buf, nfcSend->data.size);
  573. }
  574. return false;
  575. }
  576. bool seader_parse_nfc_off(SeaderUartBridge* seader_uart) {
  577. FURI_LOG_D(TAG, "Set Field Off");
  578. seader_worker_disable_field(ERR_NONE);
  579. seader_nfc_scene_field_on_exit();
  580. NFCResponse_t* nfcResponse = 0;
  581. nfcResponse = calloc(1, sizeof *nfcResponse);
  582. assert(nfcResponse);
  583. nfcResponse->present = NFCResponse_PR_nfcAck;
  584. Response_t* response = 0;
  585. response = calloc(1, sizeof *response);
  586. assert(response);
  587. response->present = Response_PR_nfcResponse;
  588. response->choice.nfcResponse = *nfcResponse;
  589. seader_send_response(seader_uart, response, 0x44, 0x0a, 0);
  590. ASN_STRUCT_FREE(asn_DEF_Response, response);
  591. ASN_STRUCT_FREE(asn_DEF_NFCResponse, nfcResponse);
  592. return false;
  593. }
  594. bool seader_parse_nfc_command(SeaderWorker* seader_worker, NFCCommand_t* nfcCommand) {
  595. SeaderUartBridge* seader_uart = seader_worker->uart;
  596. switch(nfcCommand->present) {
  597. case NFCCommand_PR_nfcSend:
  598. seader_parse_nfc_command_transmit(seader_worker, &nfcCommand->choice.nfcSend);
  599. break;
  600. case NFCCommand_PR_nfcOff:
  601. seader_parse_nfc_off(seader_uart);
  602. break;
  603. default:
  604. FURI_LOG_W(TAG, "unparsed NFCCommand");
  605. break;
  606. };
  607. return false;
  608. }
  609. bool seader_worker_state_machine(SeaderWorker* seader_worker, Payload_t* payload) {
  610. switch(payload->present) {
  611. case Payload_PR_response:
  612. seader_parse_response(seader_worker, &payload->choice.response);
  613. break;
  614. case Payload_PR_nfcCommand:
  615. seader_parse_nfc_command(seader_worker, &payload->choice.nfcCommand);
  616. break;
  617. case Payload_PR_errorResponse:
  618. // TODO: screen saying this was a failure, or maybe start over?
  619. if(seader_worker->callback) {
  620. seader_worker->callback(SeaderWorkerEventFail, seader_worker->context);
  621. }
  622. break;
  623. default:
  624. FURI_LOG_W(TAG, "unhandled payload");
  625. break;
  626. };
  627. return false;
  628. }
  629. bool seader_process_success_response(SeaderWorker* seader_worker, uint8_t* apdu, size_t len) {
  630. Payload_t* payload = 0;
  631. payload = calloc(1, sizeof *payload);
  632. assert(payload);
  633. asn_dec_rval_t rval =
  634. asn_decode(0, ATS_DER, &asn_DEF_Payload, (void**)&payload, apdu + 6, len - 6);
  635. if(rval.code == RC_OK) {
  636. #ifdef ASN1_DEBUG
  637. memset(payloadDebug, 0, sizeof(payloadDebug));
  638. (&asn_DEF_Payload)
  639. ->op->print_struct(&asn_DEF_Payload, payload, 1, seader_asn_to_string, payloadDebug);
  640. if(strlen(payloadDebug) > 0) {
  641. FURI_LOG_D(TAG, "Received payload: %s", payloadDebug);
  642. }
  643. #endif
  644. seader_worker_state_machine(seader_worker, payload);
  645. }
  646. ASN_STRUCT_FREE(asn_DEF_Payload, payload);
  647. return (rval.code == RC_OK);
  648. }
  649. bool seader_process_apdu(SeaderWorker* seader_worker, uint8_t* apdu, size_t len) {
  650. SeaderUartBridge* seader_uart = seader_worker->uart;
  651. if(len < 2) {
  652. return false;
  653. }
  654. /*
  655. memset(display, 0, sizeof(display));
  656. for(uint8_t i = 0; i < len; i++) {
  657. snprintf(display + (i * 2), sizeof(display), "%02x", apdu[i]);
  658. }
  659. FURI_LOG_I(TAG, "APDU: %s", display);
  660. */
  661. uint8_t SW1 = apdu[len - 2];
  662. uint8_t SW2 = apdu[len - 1];
  663. switch(SW1) {
  664. case 0x61:
  665. // FURI_LOG_I(TAG, "Request %d bytes", SW2);
  666. GET_RESPONSE[4] = SW2;
  667. seader_ccid_XfrBlock(seader_uart, GET_RESPONSE, sizeof(GET_RESPONSE));
  668. return true;
  669. break;
  670. case 0x90:
  671. if(SW2 == 0x00) {
  672. if(len > 2) {
  673. return seader_process_success_response(seader_worker, apdu, len - 2);
  674. }
  675. }
  676. break;
  677. }
  678. return false;
  679. }
  680. ReturnCode seader_picopass_card_init(SeaderWorker* seader_worker) {
  681. SeaderUartBridge* seader_uart = seader_worker->uart;
  682. SeaderCredential* credential = seader_worker->credential;
  683. rfalPicoPassIdentifyRes idRes;
  684. rfalPicoPassSelectRes selRes;
  685. ReturnCode err;
  686. err = rfalPicoPassPollerIdentify(&idRes);
  687. if(err != ERR_NONE) {
  688. FURI_LOG_E(TAG, "rfalPicoPassPollerIdentify error %d", err);
  689. return err;
  690. }
  691. err = rfalPicoPassPollerSelect(idRes.CSN, &selRes);
  692. if(err != ERR_NONE) {
  693. FURI_LOG_E(TAG, "rfalPicoPassPollerSelect error %d", err);
  694. return err;
  695. }
  696. memset(display, 0, sizeof(display));
  697. for(uint8_t i = 0; i < RFAL_PICOPASS_MAX_BLOCK_LEN; i++) {
  698. snprintf(display + (i * 2), sizeof(display), "%02x", selRes.CSN[i]);
  699. }
  700. FURI_LOG_D(TAG, "Sending card detected info: %s", display);
  701. CardDetails_t* cardDetails = 0;
  702. cardDetails = calloc(1, sizeof *cardDetails);
  703. assert(cardDetails);
  704. uint8_t protocolBytes[] = {0x00, FrameProtocol_iclass};
  705. OCTET_STRING_fromBuf(
  706. &cardDetails->protocol, (const char*)protocolBytes, sizeof(protocolBytes));
  707. OCTET_STRING_fromBuf(&cardDetails->csn, (const char*)selRes.CSN, RFAL_PICOPASS_MAX_BLOCK_LEN);
  708. memcpy(credential->diversifier, selRes.CSN, RFAL_PICOPASS_MAX_BLOCK_LEN);
  709. seader_send_card_detected(seader_uart, cardDetails);
  710. ASN_STRUCT_FREE(asn_DEF_CardDetails, cardDetails);
  711. return ERR_NONE;
  712. }
  713. ReturnCode seader_picopass_card_detect() {
  714. ReturnCode err;
  715. err = rfalPicoPassPollerInitialize();
  716. if(err != ERR_NONE) {
  717. FURI_LOG_E(TAG, "rfalPicoPassPollerInitialize error %d", err);
  718. return err;
  719. }
  720. err = rfalFieldOnAndStartGT();
  721. if(err != ERR_NONE) {
  722. FURI_LOG_E(TAG, "rfalFieldOnAndStartGT error %d", err);
  723. return err;
  724. }
  725. err = rfalPicoPassPollerCheckPresence();
  726. if(err != ERR_RF_COLLISION) {
  727. if(err != ERR_TIMEOUT) {
  728. FURI_LOG_E(TAG, "rfalPicoPassPollerCheckPresence error %d", err);
  729. }
  730. return err;
  731. }
  732. return ERR_NONE;
  733. }
  734. ReturnCode seader_picopass_card_read(SeaderWorker* seader_worker) {
  735. ReturnCode err = ERR_TIMEOUT;
  736. while(seader_worker->state == SeaderWorkerStateReadPicopass) {
  737. // Card found
  738. if(seader_picopass_card_detect() == ERR_NONE) {
  739. err = seader_picopass_card_init(seader_worker);
  740. if(err != ERR_NONE) {
  741. FURI_LOG_E(TAG, "picopass_card_init error %d", err);
  742. }
  743. break;
  744. }
  745. furi_delay_ms(100);
  746. }
  747. return err;
  748. }
  749. void seader_worker_process_message(SeaderWorker* seader_worker, CCID_Message* message) {
  750. if(seader_process_apdu(seader_worker, message->payload, message->dwLength)) {
  751. // no-op
  752. } else {
  753. memset(display, 0, sizeof(display));
  754. for(uint8_t i = 0; i < message->dwLength; i++) {
  755. snprintf(display + (i * 2), sizeof(display), "%02x", message->payload[i]);
  756. }
  757. FURI_LOG_W(TAG, "Unknown block: [%ld] %s", message->dwLength, display);
  758. if(seader_worker->callback) {
  759. seader_worker->callback(SeaderWorkerEventFail, seader_worker->context);
  760. }
  761. }
  762. }
  763. int32_t seader_worker_task(void* context) {
  764. SeaderWorker* seader_worker = context;
  765. SeaderUartBridge* seader_uart = seader_worker->uart;
  766. if(seader_worker->state == SeaderWorkerStateCheckSam) {
  767. furi_delay_ms(1000);
  768. seader_ccid_check_for_sam(seader_uart);
  769. } else if(seader_worker->state == SeaderWorkerStateReadPicopass) {
  770. FURI_LOG_D(TAG, "Read Picopass");
  771. requestPacs = true;
  772. seader_credential_clear(seader_worker->credential);
  773. seader_worker->credential->type = SeaderCredentialTypePicopass;
  774. seader_worker_enable_field();
  775. if(seader_picopass_card_read(seader_worker) != ERR_NONE) {
  776. // Turn off if cancelled / no card found
  777. seader_worker_disable_field(ERR_NONE);
  778. }
  779. } else if(seader_worker->state == SeaderWorkerStateRead14a) {
  780. FURI_LOG_D(TAG, "Read 14a");
  781. requestPacs = true;
  782. seader_credential_clear(seader_worker->credential);
  783. seader_worker->credential->type = SeaderCredentialType14A;
  784. seader_nfc_scene_field_on_enter();
  785. if(!seader_detect_nfc(seader_worker)) {
  786. // Turn off if cancelled / no card found
  787. seader_nfc_scene_field_on_exit();
  788. }
  789. }
  790. FURI_LOG_D(TAG, "Worker Task Complete");
  791. seader_worker_change_state(seader_worker, SeaderWorkerStateReady);
  792. return 0;
  793. }