uhf_module.c 9.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280
  1. #include "uhf_module.h"
  2. #include "uhf_module_cmd.h"
  3. #define DELAY_MS 50
  4. void rx_callback(UartIrqEvent event, uint8_t data, void* ctx) {
  5. UNUSED(event);
  6. Buffer* buf = ctx;
  7. buffer_append_single(buf, data);
  8. if(data == FRAME_END) buffer_close(buf);
  9. }
  10. M100ModuleInfo* m100_module_info_alloc() {
  11. M100ModuleInfo* module_info = (M100ModuleInfo*)malloc(sizeof(M100ModuleInfo));
  12. module_info->hw_version = NULL;
  13. module_info->sw_version = NULL;
  14. module_info->manufacturer = NULL;
  15. return module_info;
  16. }
  17. void m100_module_info_free(M100ModuleInfo* module_info) {
  18. free(module_info->hw_version);
  19. free(module_info->sw_version);
  20. free(module_info->manufacturer);
  21. free(module_info);
  22. }
  23. M100Module* m100_module_alloc() {
  24. M100Module* module = (M100Module*)malloc(sizeof(M100Module));
  25. module->info = m100_module_info_alloc();
  26. module->buf = buffer_alloc(128);
  27. furi_hal_uart_set_br(FuriHalUartIdUSART1, DEFAULT_BAUDRATE);
  28. module->baudrate = (uint16_t)(DEFAULT_BAUDRATE);
  29. return module;
  30. }
  31. void m100_module_free(M100Module* module) {
  32. m100_module_info_free(module->info);
  33. buffer_free(module->buf);
  34. free(module);
  35. }
  36. uint8_t checksum(const uint8_t* data, size_t length) {
  37. // CheckSum8 Modulo 256
  38. // Sum of Bytes % 256
  39. uint64_t sum_val = 0x00;
  40. for(size_t i = 0; i < length; i++) {
  41. sum_val += data[i];
  42. }
  43. return (uint8_t)(sum_val % 0x100);
  44. }
  45. uint16_t crc16_genibus(const uint8_t* data, size_t length) {
  46. uint16_t crc = 0xFFFF; // Initial value
  47. uint16_t polynomial = 0x1021; // CRC-16/GENIBUS polynomial
  48. for(size_t i = 0; i < length; i++) {
  49. crc ^= (data[i] << 8); // Move byte into MSB of 16bit CRC
  50. for(int j = 0; j < 8; j++) {
  51. if(crc & 0x8000) {
  52. crc = (crc << 1) ^ polynomial;
  53. } else {
  54. crc <<= 1;
  55. }
  56. }
  57. }
  58. return crc ^ 0xFFFF; // Post-inversion
  59. }
  60. char* m100_get_hardware_version(M100Module* module) {
  61. if(module->info->hw_version != NULL) return module->info->hw_version;
  62. buffer_reset(module->buf);
  63. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  64. furi_hal_uart_tx(FuriHalUartIdUSART1, (uint8_t*)&CMD_HW_VERSION.cmd[0], CMD_HW_VERSION.length);
  65. furi_delay_ms(DELAY_MS);
  66. if(!buffer_get_size(module->buf)) return NULL;
  67. uint8_t* data = buffer_get_data(module->buf);
  68. uint16_t payload_len = data[3];
  69. payload_len = (payload_len << 8) + data[4];
  70. FuriString* temp_str = furi_string_alloc();
  71. for(int i = 0; i < payload_len; i++) {
  72. furi_string_cat_printf(temp_str, "%c", data[6 + i]);
  73. }
  74. char* hw_version = (char*)malloc(sizeof(char) * payload_len);
  75. memcpy(hw_version, furi_string_get_cstr(temp_str), payload_len);
  76. module->info->hw_version = hw_version;
  77. furi_string_free(temp_str);
  78. return module->info->hw_version;
  79. }
  80. char* m100_get_software_version(M100Module* module) {
  81. if(module->info->sw_version != NULL) return module->info->sw_version;
  82. buffer_reset(module->buf);
  83. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  84. furi_hal_uart_tx(FuriHalUartIdUSART1, (uint8_t*)&CMD_SW_VERSION.cmd[0], CMD_SW_VERSION.length);
  85. furi_delay_ms(DELAY_MS);
  86. if(!buffer_get_size(module->buf)) return NULL;
  87. uint8_t* data = buffer_get_data(module->buf);
  88. uint16_t payload_len = data[3];
  89. payload_len = (payload_len << 8) + data[4];
  90. FuriString* temp_str = furi_string_alloc();
  91. for(int i = 0; i < payload_len; i++) {
  92. furi_string_cat_printf(temp_str, "%c", data[6 + i]);
  93. }
  94. char* sw_version = (char*)malloc(sizeof(char) * payload_len);
  95. memcpy(sw_version, furi_string_get_cstr(temp_str), payload_len);
  96. module->info->sw_version = sw_version;
  97. furi_string_free(temp_str);
  98. return module->info->sw_version;
  99. }
  100. char* m100_get_manufacturers(M100Module* module) {
  101. if(module->info->manufacturer != NULL) return module->info->manufacturer;
  102. buffer_reset(module->buf);
  103. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  104. furi_hal_uart_tx(
  105. FuriHalUartIdUSART1, (uint8_t*)&CMD_MANUFACTURERS.cmd[0], CMD_MANUFACTURERS.length);
  106. furi_delay_ms(DELAY_MS);
  107. if(!buffer_get_size(module->buf)) return NULL;
  108. uint8_t* data = buffer_get_data(module->buf);
  109. uint16_t payload_len = data[3];
  110. payload_len = (payload_len << 8) + data[4];
  111. FuriString* temp_str = furi_string_alloc();
  112. for(int i = 0; i < payload_len; i++) {
  113. furi_string_cat_printf(temp_str, "%c", data[6 + i]);
  114. }
  115. char* manufacturer = (char*)malloc(sizeof(char) * payload_len);
  116. memcpy(manufacturer, furi_string_get_cstr(temp_str), payload_len);
  117. module->info->manufacturer = manufacturer;
  118. furi_string_free(temp_str);
  119. return module->info->manufacturer;
  120. }
  121. UHFTag* m100_send_single_poll(M100Module* module) {
  122. buffer_reset(module->buf);
  123. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  124. furi_hal_uart_tx(
  125. FuriHalUartIdUSART1, (uint8_t*)&CMD_SINGLE_POLLING.cmd[0], CMD_SINGLE_POLLING.length);
  126. furi_delay_ms(DELAY_MS);
  127. uint8_t* data = buffer_get_data(module->buf);
  128. size_t length = buffer_get_size(module->buf);
  129. if(length <= 8 && data[2] == 0xFF) return NULL;
  130. uint16_t pc = data[6];
  131. uint16_t crc = 0;
  132. // mask out epc length from protocol control
  133. size_t epc_len = pc;
  134. epc_len >>= 3;
  135. epc_len *= 2;
  136. // get protocol control
  137. pc <<= 8;
  138. pc += data[7];
  139. // get cyclic redundency check
  140. crc = data[8 + epc_len];
  141. crc <<= 8;
  142. crc += data[8 + epc_len + 1];
  143. // validate checksum
  144. uint8_t cs = checksum(data + 1, length - 3);
  145. for(size_t i = 0; i < length; i++){
  146. FURI_LOG_E("m100", "data[%d]=%02X", i, data[i]);
  147. }
  148. if(cs != data[length - 2]) return NULL;
  149. FURI_LOG_E("m100", "checksum pass");
  150. // validate crc
  151. uint16_t ccrc = crc16_genibus(data + 6, epc_len + 2);
  152. FURI_LOG_E("m100", "crc found = %04X, calculated crc = %04X", crc, ccrc);
  153. if(ccrc != crc) return NULL;
  154. FURI_LOG_E("m100", "crc pass");
  155. UHFTag* uhf_tag = uhf_tag_alloc();
  156. uhf_tag_set_epc_pc(uhf_tag, pc);
  157. uhf_tag_set_epc_crc(uhf_tag, crc);
  158. uhf_tag_set_epc(uhf_tag, data + 8, epc_len);
  159. FURI_LOG_E("m100", "returning tag");
  160. return uhf_tag;
  161. }
  162. bool m100_set_select(M100Module* module, UHFTag* uhf_tag) {
  163. buffer_reset(module->buf);
  164. // Set select
  165. uint8_t cmd[MAX_BUFFER_SIZE];
  166. size_t cmd_length = CMD_SET_SELECT_PARAMETER.length;
  167. size_t mask_length_bytes = uhf_tag->epc->size;
  168. size_t mask_length_bits = mask_length_bytes * 8;
  169. // payload len = sel param len + ptr len + mask len + epc len
  170. size_t payload_len = 7 + mask_length_bytes;
  171. memcpy(cmd, CMD_SET_SELECT_PARAMETER.cmd, cmd_length);
  172. // set payload length
  173. cmd[3] = (payload_len >> 8) & 0xFF;
  174. cmd[4] = payload_len & 0xFF;
  175. // set select param
  176. cmd[5] = 0x01; // 0x00=rfu, 0x01=epc, 0x10=tid, 0x11=user
  177. // set ptr
  178. cmd[9] = 0x20; // epc data begins after 0x20
  179. // set mask length
  180. cmd[10] = mask_length_bits;
  181. // truncate
  182. cmd[11] = false;
  183. // set mask
  184. memcpy((void*)&cmd[12], uhf_tag->epc->data, mask_length_bytes);
  185. // set checksum
  186. cmd[12 + mask_length_bytes + 1] = checksum(cmd + 1, 11 + mask_length_bytes);
  187. // end frame
  188. cmd[12 + mask_length_bytes + 2] = FRAME_END;
  189. furi_hal_uart_set_irq_cb(FuriHalUartIdLPUART1, rx_callback, module->buf);
  190. furi_hal_uart_tx(FuriHalUartIdUSART1, cmd, 12 + mask_length_bytes + 3);
  191. furi_delay_ms(DELAY_MS);
  192. uint8_t* data = buffer_get_data(module->buf);
  193. if(checksum(data + 1, 5) != data[6]) return false; // error in rx
  194. if(data[5] != 0x00) return false; // error if not 0
  195. return true;
  196. }
  197. UHFTag* m100_get_select_param(M100Module module) {
  198. UNUSED(module);
  199. return NULL;
  200. }
  201. bool m100_read_label_data_storage(
  202. M100Module* module,
  203. UHFTag* uhf_tag,
  204. BankType bank,
  205. uint32_t access_pwd) {
  206. UNUSED(uhf_tag);
  207. buffer_reset(module->buf);
  208. uint8_t cmd[MAX_BUFFER_SIZE];
  209. size_t length = CMD_READ_LABEL_DATA_STORAGE_AREA.length;
  210. memcpy(cmd, CMD_READ_LABEL_DATA_STORAGE_AREA.cmd, length);
  211. // set access password
  212. cmd[5] = (access_pwd >> 24) & 0xFF;
  213. cmd[6] = (access_pwd >> 16) & 0xFF;
  214. cmd[7] = (access_pwd >> 8) & 0xFF;
  215. cmd[8] = access_pwd & 0xFF;
  216. // set mem bank
  217. cmd[9] = (uint8_t)bank;
  218. // recalc checksum
  219. cmd[length - 2] = checksum(cmd + 1, length - 3);
  220. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, module->buf);
  221. furi_hal_uart_tx(FuriHalUartIdUSART1, cmd, length);
  222. furi_delay_ms(DELAY_MS);
  223. return true;
  224. }
  225. void m100_set_baudrate(M100Module* module, uint16_t baudrate) {
  226. size_t length = CMD_SET_COMMUNICATION_BAUD_RATE.length;
  227. uint8_t cmd[length];
  228. memcpy(cmd, CMD_SET_COMMUNICATION_BAUD_RATE.cmd, length);
  229. uint16_t br_mod = baudrate / 100; // module format
  230. cmd[6] = 0xFF & br_mod; // pow LSB
  231. cmd[5] = 0xFF & (br_mod >> 4); // pow MSB
  232. // furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, NULL, NULL);
  233. furi_hal_uart_tx(FuriHalUartIdUSART1, cmd, length);
  234. furi_hal_uart_set_br(FuriHalUartIdUSART1, baudrate);
  235. module->baudrate = baudrate;
  236. }
  237. bool m100_set_working_area(M100Module* module, WorkingArea area) {
  238. size_t length = CMD_SET_WORK_AREA.length;
  239. uint8_t cmd[length];
  240. memcpy(cmd, CMD_SET_WORK_AREA.cmd, length);
  241. cmd[5] = area;
  242. Buffer* buf = buffer_alloc(12);
  243. furi_hal_uart_set_irq_cb(FuriHalUartIdUSART1, rx_callback, buf);
  244. furi_hal_uart_tx(FuriHalUartIdUSART1, cmd, length);
  245. buffer_free(buf);
  246. module->area = area;
  247. return true;
  248. }
  249. bool m100_set_working_channel(M100Module* module, WorkingChannel channel) {
  250. UNUSED(module);
  251. UNUSED(channel);
  252. return true;
  253. }
  254. bool m100_set_transmitting_power(M100Module* module, uint16_t power) {
  255. UNUSED(module);
  256. UNUSED(power);
  257. return true;
  258. }
  259. bool m100_set_freq_hopping(M100Module* module, bool hopping) {
  260. UNUSED(module);
  261. UNUSED(hopping);
  262. return true;
  263. }