uhf_module.c 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382
  1. #include "uhf_module.h"
  2. #include "uhf_module_cmd.h"
  3. #define DELAY_MS 100
  4. void rx_callback(UartIrqEvent event, uint8_t data, void* ctx) {
  5. UNUSED(event);
  6. Buffer* buf = ctx;
  7. buffer_append_single(buf, data);
  8. if(data == FRAME_END) buffer_close(buf);
  9. }
  10. M100ModuleInfo* m100_module_info_alloc() {
  11. M100ModuleInfo* module_info = (M100ModuleInfo*)malloc(sizeof(M100ModuleInfo));
  12. module_info->hw_version = NULL;
  13. module_info->sw_version = NULL;
  14. module_info->manufacturer = NULL;
  15. return module_info;
  16. }
  17. void m100_module_info_free(M100ModuleInfo* module_info) {
  18. free(module_info->hw_version);
  19. free(module_info->sw_version);
  20. free(module_info->manufacturer);
  21. free(module_info);
  22. }
  23. M100Module* m100_module_alloc() {
  24. M100Module* module = (M100Module*)malloc(sizeof(M100Module));
  25. module->info = m100_module_info_alloc();
  26. module->buf = buffer_alloc(128);
  27. furi_hal_uart_set_br(FuriHalUartIdUSART1, DEFAULT_BAUDRATE);
  28. module->baudrate = (uint16_t)(DEFAULT_BAUDRATE);
  29. return module;
  30. }
  31. void m100_module_free(M100Module* module) {
  32. m100_module_info_free(module->info);
  33. buffer_free(module->buf);
  34. free(module);
  35. }
  36. uint8_t checksum(const uint8_t* data, size_t length) {
  37. // CheckSum8 Modulo 256
  38. // Sum of Bytes % 256
  39. uint64_t sum_val = 0x00;
  40. for(size_t i = 0; i < length; i++) {
  41. sum_val += data[i];
  42. }
  43. return (uint8_t)(sum_val % 0x100);
  44. }
  45. uint16_t crc16_genibus(const uint8_t* data, size_t length) {
  46. uint16_t crc = 0xFFFF; // Initial value
  47. uint16_t polynomial = 0x1021; // CRC-16/GENIBUS polynomial
  48. for(size_t i = 0; i < length; i++) {
  49. crc ^= (data[i] << 8); // Move byte into MSB of 16bit CRC
  50. for(int j = 0; j < 8; j++) {
  51. if(crc & 0x8000) {
  52. crc = (crc << 1) ^ polynomial;
  53. } else {
  54. crc <<= 1;
  55. }
  56. }
  57. }
  58. return crc ^ 0xFFFF; // Post-inversion
  59. }
  60. char* m100_get_hardware_version(M100Module* module) {
  61. if(module->info->hw_version != NULL) {
  62. free(module->info->hw_version);
  63. module->info->hw_version = NULL;
  64. }
  65. buffer_reset(module->buf);
  66. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  67. furi_hal_uart_tx(FuriHalUartIdUSART1, (uint8_t*)&CMD_HW_VERSION.cmd[0], CMD_HW_VERSION.length);
  68. furi_delay_ms(DELAY_MS);
  69. if(!buffer_get_size(module->buf)) return NULL;
  70. uint8_t* data = buffer_get_data(module->buf);
  71. uint16_t payload_len = data[3];
  72. payload_len = (payload_len << 8) + data[4];
  73. FuriString* temp_str = furi_string_alloc();
  74. for(int i = 0; i < payload_len; i++) {
  75. furi_string_cat_printf(temp_str, "%c", data[6 + i]);
  76. }
  77. char* hw_version = (char*)malloc(sizeof(char) * payload_len);
  78. memcpy(hw_version, furi_string_get_cstr(temp_str), payload_len);
  79. module->info->hw_version = hw_version;
  80. furi_string_free(temp_str);
  81. return module->info->hw_version;
  82. }
  83. char* m100_get_software_version(M100Module* module) {
  84. if(module->info->sw_version != NULL) {
  85. free(module->info->sw_version);
  86. module->info->sw_version = NULL;
  87. }
  88. buffer_reset(module->buf);
  89. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  90. furi_hal_uart_tx(FuriHalUartIdUSART1, (uint8_t*)&CMD_SW_VERSION.cmd[0], CMD_SW_VERSION.length);
  91. furi_delay_ms(DELAY_MS);
  92. if(!buffer_get_size(module->buf)) return NULL;
  93. uint8_t* data = buffer_get_data(module->buf);
  94. uint16_t payload_len = data[3];
  95. payload_len = (payload_len << 8) + data[4];
  96. FuriString* temp_str = furi_string_alloc();
  97. for(int i = 0; i < payload_len; i++) {
  98. furi_string_cat_printf(temp_str, "%c", data[6 + i]);
  99. }
  100. char* sw_version = (char*)malloc(sizeof(char) * payload_len);
  101. memcpy(sw_version, furi_string_get_cstr(temp_str), payload_len);
  102. module->info->sw_version = sw_version;
  103. furi_string_free(temp_str);
  104. return module->info->sw_version;
  105. }
  106. char* m100_get_manufacturers(M100Module* module) {
  107. if(module->info->manufacturer != NULL) {
  108. free(module->info->manufacturer);
  109. module->info->manufacturer = NULL;
  110. }
  111. buffer_reset(module->buf);
  112. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  113. furi_hal_uart_tx(
  114. FuriHalUartIdUSART1, (uint8_t*)&CMD_MANUFACTURERS.cmd[0], CMD_MANUFACTURERS.length);
  115. furi_delay_ms(DELAY_MS);
  116. if(!buffer_get_size(module->buf)) return NULL;
  117. uint8_t* data = buffer_get_data(module->buf);
  118. uint16_t payload_len = data[3];
  119. payload_len = (payload_len << 8) + data[4];
  120. FuriString* temp_str = furi_string_alloc();
  121. for(int i = 0; i < payload_len; i++) {
  122. furi_string_cat_printf(temp_str, "%c", data[6 + i]);
  123. }
  124. char* manufacturer = (char*)malloc(sizeof(char) * payload_len);
  125. memcpy(manufacturer, furi_string_get_cstr(temp_str), payload_len);
  126. module->info->manufacturer = manufacturer;
  127. furi_string_free(temp_str);
  128. return module->info->manufacturer;
  129. }
  130. M100ResponseType m100_send_single_poll(M100Module* module, UHFTag* uhf_tag) {
  131. buffer_reset(module->buf);
  132. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  133. furi_hal_uart_tx(
  134. FuriHalUartIdUSART1, (uint8_t*)&CMD_SINGLE_POLLING.cmd[0], CMD_SINGLE_POLLING.length);
  135. furi_delay_ms(DELAY_MS);
  136. uint8_t* data = buffer_get_data(module->buf);
  137. size_t length = buffer_get_size(module->buf);
  138. if(length <= 8 && data[2] == 0xFF) return M100NoTagResponse;
  139. uint16_t pc = data[6];
  140. uint16_t crc = 0;
  141. // mask out epc length from protocol control
  142. size_t epc_len = pc;
  143. epc_len >>= 3;
  144. epc_len *= 2;
  145. // get protocol control
  146. pc <<= 8;
  147. pc += data[7];
  148. // get cyclic redundency check
  149. crc = data[8 + epc_len];
  150. crc <<= 8;
  151. crc += data[8 + epc_len + 1];
  152. // validate checksum
  153. if(checksum(data + 1, length - 3) != data[length - 2]) return M100ValidationFail;
  154. // validate crc
  155. if(crc16_genibus(data + 6, epc_len + 2) != crc) return M100ValidationFail;
  156. uhf_tag_set_epc_pc(uhf_tag, pc);
  157. uhf_tag_set_epc_crc(uhf_tag, crc);
  158. uhf_tag_set_epc(uhf_tag, data + 8, epc_len);
  159. return M100Success;
  160. }
  161. M100ResponseType m100_set_select(M100Module* module, UHFTag* uhf_tag) {
  162. buffer_reset(module->buf);
  163. // Set select
  164. uint8_t cmd[MAX_BUFFER_SIZE];
  165. size_t cmd_length = CMD_SET_SELECT_PARAMETER.length;
  166. size_t mask_length_bytes = uhf_tag->epc->size;
  167. size_t mask_length_bits = mask_length_bytes * 8;
  168. // payload len = sel param len + ptr len + mask len + epc len
  169. size_t payload_len = 7 + mask_length_bytes;
  170. memcpy(cmd, CMD_SET_SELECT_PARAMETER.cmd, cmd_length);
  171. // set payload length
  172. cmd[3] = (payload_len >> 8) & 0xFF;
  173. cmd[4] = payload_len & 0xFF;
  174. // set select param
  175. cmd[5] = 0x01; // 0x00=rfu, 0x01=epc, 0x10=tid, 0x11=user
  176. // set ptr
  177. cmd[9] = 0x20; // epc data begins after 0x20
  178. // set mask length
  179. cmd[10] = mask_length_bits;
  180. // truncate
  181. cmd[11] = false;
  182. // set mask
  183. memcpy((void*)&cmd[12], uhf_tag->epc->data, mask_length_bytes);
  184. // set checksum
  185. cmd[12 + mask_length_bytes + 1] = checksum(cmd + 1, 11 + mask_length_bytes);
  186. // end frame
  187. cmd[12 + mask_length_bytes + 2] = FRAME_END;
  188. furi_hal_uart_set_irq_cb(FuriHalUartIdLPUART1, rx_callback, module->buf);
  189. furi_hal_uart_tx(FuriHalUartIdUSART1, cmd, 12 + mask_length_bytes + 3);
  190. furi_delay_ms(DELAY_MS);
  191. uint8_t* data = buffer_get_data(module->buf);
  192. if(checksum(data + 1, 5) != data[6]) return M100ValidationFail; // error in rx
  193. if(data[5] != 0x00) return M100ValidationFail; // error if not 0
  194. return M100Success;
  195. }
  196. UHFTag* m100_get_select_param(M100Module module) {
  197. UNUSED(module);
  198. return NULL;
  199. }
  200. M100ResponseType m100_read_label_data_storage(
  201. M100Module* module,
  202. UHFTag* uhf_tag,
  203. BankType bank,
  204. uint32_t access_pwd,
  205. uint16_t word_count) {
  206. /*
  207. Will probably remove UHFTag as param and get it from get selected tag
  208. */
  209. if(bank == EPCBank) return M100Success;
  210. buffer_reset(module->buf);
  211. uint8_t cmd[MAX_BUFFER_SIZE];
  212. size_t cmd_length = CMD_READ_LABEL_DATA_STORAGE_AREA.length;
  213. memcpy(cmd, CMD_READ_LABEL_DATA_STORAGE_AREA.cmd, cmd_length);
  214. // set access password
  215. cmd[5] = (access_pwd >> 24) & 0xFF;
  216. cmd[6] = (access_pwd >> 16) & 0xFF;
  217. cmd[7] = (access_pwd >> 8) & 0xFF;
  218. cmd[8] = access_pwd & 0xFF;
  219. // set mem bank
  220. cmd[9] = (uint8_t)bank;
  221. // set word counter
  222. cmd[12] = (word_count >> 8) & 0xFF;
  223. cmd[13] = word_count & 0xFF;
  224. // calc checksum
  225. cmd[cmd_length - 2] = checksum(cmd + 1, cmd_length - 3);
  226. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  227. furi_hal_uart_tx(FuriHalUartIdUSART1, cmd, cmd_length);
  228. furi_delay_ms(DELAY_MS);
  229. uint8_t* data = buffer_get_data(module->buf);
  230. uint16_t payload_len = data[3];
  231. payload_len = (payload_len << 8) + data[4];
  232. size_t ptr_offset = 5 /*<-ptr offset*/ + uhf_tag->epc->size + 3 /*<-pc + ul*/;
  233. size_t bank_data_length = payload_len - (ptr_offset - 5 /*dont include the offset*/);
  234. if(data[2] == 0xFF) {
  235. if(payload_len == 0x0001) return M100NoTagResponse;
  236. return M100MemoryOverrun;
  237. }
  238. switch(bank) {
  239. case TIDBank:
  240. uhf_tag_set_tid(uhf_tag, data + ptr_offset, bank_data_length);
  241. break;
  242. case UserBank:
  243. uhf_tag_set_user(uhf_tag, data + ptr_offset, bank_data_length);
  244. break;
  245. default:
  246. return M100Success;
  247. }
  248. return M100Success;
  249. }
  250. M100ResponseType m100_write_label_data_storage(
  251. M100Module* module,
  252. UHFTag* uhf_tag,
  253. BankType bank,
  254. uint16_t source_address,
  255. uint32_t access_pwd) {
  256. buffer_reset(module->buf);
  257. uint8_t cmd[MAX_BUFFER_SIZE];
  258. size_t cmd_length = CMD_WRITE_LABEL_DATA_STORE.length;
  259. memcpy(cmd, CMD_WRITE_LABEL_DATA_STORE.cmd, cmd_length);
  260. uint16_t payload_len = 9;
  261. uint16_t data_length;
  262. switch(bank) {
  263. case ReservedBank:
  264. // access pwd len + kill pwd len
  265. payload_len += 4;
  266. data_length = 4;
  267. break;
  268. case EPCBank:
  269. // epc len + pc len
  270. payload_len += 4 + uhf_tag_get_epc_size(uhf_tag);
  271. data_length = 4 + uhf_tag_get_epc_size(uhf_tag);
  272. // set data
  273. uint8_t tmp_arr[4];
  274. tmp_arr[0] = (uint8_t)((uhf_tag_get_epc_crc(uhf_tag) >> 8) & 0xFF);
  275. tmp_arr[1] = (uint8_t)(uhf_tag_get_epc_crc(uhf_tag) & 0xFF);
  276. tmp_arr[2] = (uint8_t)((uhf_tag_get_epc_pc(uhf_tag) >> 8) & 0xFF);
  277. tmp_arr[3] = (uint8_t)(uhf_tag_get_epc_pc(uhf_tag) & 0xFF);
  278. FURI_LOG_E("wkr", "%04X", uhf_tag_get_epc_pc(uhf_tag));
  279. memcpy(cmd + 14, tmp_arr, 4);
  280. memcpy(cmd + 18, uhf_tag_get_epc(uhf_tag), uhf_tag_get_epc_size(uhf_tag));
  281. break;
  282. case UserBank:
  283. payload_len += uhf_tag_get_user_size(uhf_tag);
  284. data_length = uhf_tag_get_user_size(uhf_tag);
  285. // set data
  286. memcpy(cmd + 14, uhf_tag_get_user(uhf_tag), uhf_tag_get_user_size(uhf_tag));
  287. break;
  288. default:
  289. return M100MemoryOverrun;
  290. }
  291. // set payload length
  292. cmd[3] = (payload_len >> 8) & 0xFF;
  293. cmd[4] = payload_len & 0xFF;
  294. // set access password
  295. cmd[5] = (access_pwd >> 24) & 0xFF;
  296. cmd[6] = (access_pwd >> 16) & 0xFF;
  297. cmd[7] = (access_pwd >> 8) & 0xFF;
  298. cmd[8] = access_pwd & 0xFF;
  299. // set membank
  300. cmd[9] = (uint8_t)bank;
  301. // set source address
  302. cmd[10] = (source_address >> 8) & 0xFF;
  303. cmd[11] = source_address & 0xFF;
  304. // set data length
  305. size_t data_length_words = data_length / 2;
  306. cmd[12] = (data_length_words >> 8) & 0xFF;
  307. cmd[13] = data_length_words & 0xFF;
  308. // update cmd len
  309. cmd_length = 5 + payload_len;
  310. // calculate checksum
  311. cmd[cmd_length - 2] = checksum(cmd + 1, cmd_length - 3);
  312. cmd[cmd_length - 1] = FRAME_END;
  313. // send cmd
  314. for(size_t i = 0; i < cmd_length; i++) {
  315. FURI_LOG_E("m100", "cmd[%d]=%02X", i, cmd[i]);
  316. }
  317. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  318. furi_hal_uart_tx(FuriHalUartIdUSART1, cmd, cmd_length);
  319. furi_delay_ms(DELAY_MS);
  320. uint8_t* buff_data = buffer_get_data(module->buf);
  321. size_t buff_length = buffer_get_size(module->buf);
  322. if(buff_data[2] == 0xFF && buff_length == 8)
  323. return M100NoTagResponse;
  324. else if(buff_data[2] == 0xFF)
  325. return M100ValidationFail;
  326. return M100Success;
  327. }
  328. void m100_set_baudrate(M100Module* module, uint16_t baudrate) {
  329. size_t length = CMD_SET_COMMUNICATION_BAUD_RATE.length;
  330. uint8_t cmd[length];
  331. memcpy(cmd, CMD_SET_COMMUNICATION_BAUD_RATE.cmd, length);
  332. uint16_t br_mod = baudrate / 100; // module format
  333. cmd[6] = 0xFF & br_mod; // pow LSB
  334. cmd[5] = 0xFF & (br_mod >> 4); // pow MSB
  335. furi_hal_uart_tx(FuriHalUartIdUSART1, cmd, length);
  336. furi_hal_uart_set_br(FuriHalUartIdUSART1, baudrate);
  337. module->baudrate = baudrate;
  338. }
  339. bool m100_set_working_area(M100Module* module, WorkingArea area) {
  340. size_t length = CMD_SET_WORK_AREA.length;
  341. uint8_t cmd[length];
  342. memcpy(cmd, CMD_SET_WORK_AREA.cmd, length);
  343. cmd[5] = area;
  344. Buffer* buf = buffer_alloc(12);
  345. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, buf);
  346. furi_hal_uart_tx(FuriHalUartIdUSART1, cmd, length);
  347. buffer_free(buf);
  348. module->area = area;
  349. return true;
  350. }
  351. bool m100_set_working_channel(M100Module* module, WorkingChannel channel) {
  352. UNUSED(module);
  353. UNUSED(channel);
  354. return true;
  355. }
  356. bool m100_set_transmitting_power(M100Module* module, uint16_t power) {
  357. UNUSED(module);
  358. UNUSED(power);
  359. return true;
  360. }
  361. bool m100_set_freq_hopping(M100Module* module, bool hopping) {
  362. UNUSED(module);
  363. UNUSED(hopping);
  364. return true;
  365. }