ccid.c 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373
  1. #include "seader_i.h"
  2. #define TAG "SeaderCCID"
  3. bool hasSAM = false;
  4. const uint8_t SAM_ATR[] =
  5. {0x3b, 0x95, 0x96, 0x80, 0xb1, 0xfe, 0x55, 0x1f, 0xc7, 0x47, 0x72, 0x61, 0x63, 0x65, 0x13};
  6. const uint8_t SAM_ATR2[] = {0x3b, 0x90, 0x96, 0x91, 0x81, 0xb1, 0xfe, 0x55, 0x1f, 0xc7, 0xd4};
  7. bool powered[2] = {false, false};
  8. uint8_t sam_slot = 0;
  9. uint8_t sequence[2] = {0, 0};
  10. uint8_t retries = 3;
  11. uint8_t getSequence(uint8_t slot) {
  12. if(sequence[slot] > 254) {
  13. sequence[slot] = 0;
  14. }
  15. return sequence[slot]++;
  16. }
  17. void seader_ccid_IccPowerOn(SeaderUartBridge* seader_uart, uint8_t slot) {
  18. if(powered[slot]) {
  19. return;
  20. }
  21. powered[slot] = true;
  22. FURI_LOG_D(TAG, "Sending Power On (%d)", slot);
  23. memset(seader_uart->tx_buf, 0, SEADER_UART_RX_BUF_SIZE);
  24. seader_uart->tx_buf[0] = SYNC;
  25. seader_uart->tx_buf[1] = CTRL;
  26. seader_uart->tx_buf[2 + 0] = CCID_MESSAGE_TYPE_PC_to_RDR_IccPowerOn;
  27. seader_uart->tx_buf[2 + 5] = slot;
  28. seader_uart->tx_buf[2 + 6] = getSequence(slot);
  29. seader_uart->tx_buf[2 + 7] = 2; //power
  30. seader_uart->tx_len = seader_add_lrc(seader_uart->tx_buf, 2 + 10);
  31. furi_thread_flags_set(furi_thread_get_id(seader_uart->tx_thread), WorkerEvtSamRx);
  32. }
  33. void seader_ccid_check_for_sam(SeaderUartBridge* seader_uart) {
  34. hasSAM = false; // If someone is calling this, reset sam state
  35. powered[0] = false;
  36. powered[1] = false;
  37. retries = 3;
  38. seader_ccid_GetSlotStatus(seader_uart, 0);
  39. }
  40. void seader_ccid_GetSlotStatus(SeaderUartBridge* seader_uart, uint8_t slot) {
  41. FURI_LOG_D(TAG, "seader_ccid_GetSlotStatus(%d)", slot);
  42. memset(seader_uart->tx_buf, 0, SEADER_UART_RX_BUF_SIZE);
  43. seader_uart->tx_buf[0] = SYNC;
  44. seader_uart->tx_buf[1] = CTRL;
  45. seader_uart->tx_buf[2 + 0] = CCID_MESSAGE_TYPE_PC_to_RDR_GetSlotStatus;
  46. seader_uart->tx_buf[2 + 5] = slot;
  47. seader_uart->tx_buf[2 + 6] = getSequence(slot);
  48. seader_uart->tx_len = seader_add_lrc(seader_uart->tx_buf, 2 + 10);
  49. furi_thread_flags_set(furi_thread_get_id(seader_uart->tx_thread), WorkerEvtSamRx);
  50. }
  51. void seader_ccid_SetParameters(Seader* seader, uint8_t slot, uint8_t* atr, size_t atr_len) {
  52. SeaderWorker* seader_worker = seader->worker;
  53. SeaderUartBridge* seader_uart = seader_worker->uart;
  54. UNUSED(atr_len);
  55. FURI_LOG_D(TAG, "seader_ccid_SetParameters(%d)", slot);
  56. uint8_t payloadLen = 0;
  57. if(seader_uart->T == 0) {
  58. payloadLen = 5;
  59. } else if(atr[4] == 0xB1 && seader_uart->T == 1) {
  60. payloadLen = 7;
  61. }
  62. memset(seader_uart->tx_buf, 0, SEADER_UART_RX_BUF_SIZE);
  63. seader_uart->tx_buf[0] = SYNC;
  64. seader_uart->tx_buf[1] = CTRL;
  65. seader_uart->tx_buf[2 + 0] = CCID_MESSAGE_TYPE_PC_to_RDR_SetParameters;
  66. seader_uart->tx_buf[2 + 1] = payloadLen;
  67. seader_uart->tx_buf[2 + 5] = slot;
  68. seader_uart->tx_buf[2 + 6] = getSequence(slot);
  69. seader_uart->tx_buf[2 + 7] = seader_uart->T;
  70. seader_uart->tx_buf[2 + 8] = 0;
  71. seader_uart->tx_buf[2 + 9] = 0;
  72. if(seader_uart->T == 0) {
  73. // I'm leaving this here for completeness, but it was actually causing ICC_MUTE on the first apdu.
  74. seader_uart->tx_buf[2 + 10] = 0x96; //atr[2]; //bmFindexDindex
  75. seader_uart->tx_buf[2 + 11] = 0x00; //bmTCCKST1
  76. seader_uart->tx_buf[2 + 12] = 0x00; //bGuardTimeT0
  77. seader_uart->tx_buf[2 + 13] = 0x0a; //bWaitingIntegerT0
  78. seader_uart->tx_buf[2 + 14] = 0x00; //bClockStop
  79. } else if(seader_uart->T == 1) {
  80. seader_uart->tx_buf[2 + 10] = atr[2]; //bmFindexDindex
  81. seader_uart->tx_buf[2 + 11] = 0x10; //bmTCCKST1
  82. seader_uart->tx_buf[2 + 12] = 0xfe; //bGuardTimeT1
  83. seader_uart->tx_buf[2 + 13] = atr[6]; //bWaitingIntegerT1
  84. seader_uart->tx_buf[2 + 14] = atr[8]; //bClockStop
  85. seader_uart->tx_buf[2 + 15] = atr[5]; //bIFSC
  86. seader_uart->tx_buf[2 + 16] = 0x00; //bNadValue
  87. }
  88. seader_uart->tx_len = seader_add_lrc(seader_uart->tx_buf, 2 + 10 + payloadLen);
  89. furi_thread_flags_set(furi_thread_get_id(seader_uart->tx_thread), WorkerEvtSamRx);
  90. }
  91. void seader_ccid_GetParameters(SeaderUartBridge* seader_uart) {
  92. memset(seader_uart->tx_buf, 0, SEADER_UART_RX_BUF_SIZE);
  93. seader_uart->tx_buf[0] = SYNC;
  94. seader_uart->tx_buf[1] = CTRL;
  95. seader_uart->tx_buf[2 + 0] = CCID_MESSAGE_TYPE_PC_to_RDR_GetParameters;
  96. seader_uart->tx_buf[2 + 1] = 0;
  97. seader_uart->tx_buf[2 + 5] = sam_slot;
  98. seader_uart->tx_buf[2 + 6] = getSequence(sam_slot);
  99. seader_uart->tx_buf[2 + 7] = 0;
  100. seader_uart->tx_buf[2 + 8] = 0;
  101. seader_uart->tx_buf[2 + 9] = 0;
  102. seader_uart->tx_len = seader_add_lrc(seader_uart->tx_buf, 2 + 10);
  103. furi_thread_flags_set(furi_thread_get_id(seader_uart->tx_thread), WorkerEvtSamRx);
  104. }
  105. void seader_ccid_XfrBlock(SeaderUartBridge* seader_uart, uint8_t* data, size_t len) {
  106. seader_ccid_XfrBlockToSlot(seader_uart, sam_slot, data, len);
  107. }
  108. void seader_ccid_XfrBlockToSlot(
  109. SeaderUartBridge* seader_uart,
  110. uint8_t slot,
  111. uint8_t* data,
  112. size_t len) {
  113. memset(seader_uart->tx_buf, 0, SEADER_UART_RX_BUF_SIZE);
  114. seader_uart->tx_buf[0] = SYNC;
  115. seader_uart->tx_buf[1] = CTRL;
  116. seader_uart->tx_buf[2 + 0] = CCID_MESSAGE_TYPE_PC_to_RDR_XfrBlock;
  117. seader_uart->tx_buf[2 + 1] = (len >> 0) & 0xff;
  118. seader_uart->tx_buf[2 + 2] = (len >> 8) & 0xff;
  119. seader_uart->tx_buf[2 + 5] = slot;
  120. seader_uart->tx_buf[2 + 6] = getSequence(slot);
  121. seader_uart->tx_buf[2 + 7] = 5;
  122. seader_uart->tx_buf[2 + 8] = 0;
  123. seader_uart->tx_buf[2 + 9] = 0;
  124. uint8_t header_len = 2 + 10;
  125. memcpy(seader_uart->tx_buf + header_len, data, len);
  126. seader_uart->tx_len = header_len + len;
  127. seader_uart->tx_len = seader_add_lrc(seader_uart->tx_buf, seader_uart->tx_len);
  128. char* display = malloc(seader_uart->tx_len * 2 + 1);
  129. for(uint8_t i = 0; i < seader_uart->tx_len; i++) {
  130. snprintf(display + (i * 2), sizeof(display), "%02x", seader_uart->tx_buf[i]);
  131. }
  132. FURI_LOG_D(TAG, "seader_ccid_XfrBlockToSlot(%d) %d: %s", slot, seader_uart->tx_len, display);
  133. free(display);
  134. furi_thread_flags_set(furi_thread_get_id(seader_uart->tx_thread), WorkerEvtSamRx);
  135. }
  136. size_t seader_ccid_process(Seader* seader, uint8_t* cmd, size_t cmd_len) {
  137. SeaderWorker* seader_worker = seader->worker;
  138. SeaderUartBridge* seader_uart = seader_worker->uart;
  139. CCID_Message message;
  140. message.consumed = 0;
  141. char* display = malloc(cmd_len * 2 + 1);
  142. for(uint8_t i = 0; i < cmd_len; i++) {
  143. snprintf(display + (i * 2), sizeof(display), "%02x", cmd[i]);
  144. }
  145. FURI_LOG_D(TAG, "seader_ccid_process %d: %s", cmd_len, display);
  146. free(display);
  147. if(cmd_len == 2) {
  148. if(cmd[0] == CCID_MESSAGE_TYPE_RDR_to_PC_NotifySlotChange) {
  149. switch(cmd[1] & SLOT_0_MASK) {
  150. case 0:
  151. case 1:
  152. // No change, no-op
  153. break;
  154. case CARD_IN_1:
  155. FURI_LOG_D(TAG, "Card Inserted (0)");
  156. if(hasSAM && sam_slot == 0) {
  157. break;
  158. }
  159. sequence[0] = 0;
  160. seader_ccid_IccPowerOn(seader_uart, 0);
  161. break;
  162. case CARD_OUT_1:
  163. FURI_LOG_D(TAG, "Card Removed (0)");
  164. if(hasSAM && sam_slot == 0) {
  165. powered[0] = false;
  166. hasSAM = false;
  167. retries = 3;
  168. if(seader_worker->callback) {
  169. seader_worker->callback(
  170. SeaderWorkerEventSamMissing, seader_worker->context);
  171. }
  172. }
  173. break;
  174. };
  175. switch(cmd[1] & SLOT_1_MASK) {
  176. case 0:
  177. case 1:
  178. // No change, no-op
  179. break;
  180. case CARD_IN_2:
  181. FURI_LOG_D(TAG, "Card Inserted (1)");
  182. if(hasSAM && sam_slot == 1) {
  183. break;
  184. }
  185. sequence[1] = 0;
  186. seader_ccid_IccPowerOn(seader_uart, 1);
  187. break;
  188. case CARD_OUT_2:
  189. FURI_LOG_D(TAG, "Card Removed (1)");
  190. if(hasSAM && sam_slot == 1) {
  191. powered[1] = false;
  192. hasSAM = false;
  193. retries = 3;
  194. if(seader_worker->callback) {
  195. seader_worker->callback(
  196. SeaderWorkerEventSamMissing, seader_worker->context);
  197. }
  198. }
  199. break;
  200. };
  201. return 2;
  202. }
  203. }
  204. while(cmd_len >= 3 && cmd[0] == SYNC && cmd[1] == NAK) {
  205. // 031516
  206. FURI_LOG_W(TAG, "NAK");
  207. cmd += 3;
  208. cmd_len -= 3;
  209. message.consumed += 3;
  210. }
  211. while(cmd_len > 2 && (cmd[0] != SYNC || cmd[1] != CTRL)) {
  212. FURI_LOG_W(TAG, "invalid start: %02x", cmd[0]);
  213. cmd += 1;
  214. cmd_len -= 1;
  215. message.consumed += 1;
  216. }
  217. if(cmd_len > 12 && cmd[0] == SYNC && cmd[1] == CTRL) {
  218. uint8_t* ccid = cmd + 2;
  219. message.bMessageType = ccid[0];
  220. message.dwLength = *((uint32_t*)(ccid + 1));
  221. message.bSlot = ccid[5];
  222. message.bSeq = ccid[6];
  223. message.bStatus = ccid[7];
  224. message.bError = ccid[8];
  225. message.payload = ccid + 10;
  226. if(cmd_len < 2 + 10 + message.dwLength + 1) {
  227. // Incomplete
  228. return message.consumed;
  229. }
  230. message.consumed += 2 + 10 + message.dwLength + 1;
  231. if(seader_validate_lrc(cmd, 2 + 10 + message.dwLength + 1) == false) {
  232. FURI_LOG_W(
  233. TAG,
  234. "Invalid LRC. Recv: %02x vs Calc: %02x",
  235. cmd[2 + 10 + message.dwLength + 1],
  236. seader_calc_lrc(cmd, 2 + 10 + message.dwLength));
  237. // TODO: Should I respond with an error?
  238. return message.consumed;
  239. }
  240. //0306 81 00000000 0000 0200 01 87
  241. //0306 81 00000000 0000 0100 01 84
  242. if(message.bMessageType == CCID_MESSAGE_TYPE_RDR_to_PC_SlotStatus) {
  243. uint8_t status = (message.bStatus & BMICCSTATUS_MASK);
  244. if(status == 0 || status == 1) {
  245. seader_ccid_IccPowerOn(seader_uart, message.bSlot);
  246. return message.consumed;
  247. } else if(status == 2) {
  248. FURI_LOG_W(TAG, "No ICC is present [retries %d]", retries);
  249. if(retries-- > 1 && hasSAM == false) {
  250. furi_delay_ms(100);
  251. seader_ccid_GetSlotStatus(seader_uart, retries % 2);
  252. } else {
  253. if(seader_worker->callback) {
  254. seader_worker->callback(
  255. SeaderWorkerEventSamMissing, seader_worker->context);
  256. }
  257. }
  258. return message.consumed;
  259. }
  260. }
  261. //0306 80 00000000 0001 42fe 00 38
  262. if(message.bStatus == 0x41 && message.bError == 0xfe) {
  263. FURI_LOG_W(TAG, "card probably upside down");
  264. hasSAM = false;
  265. if(seader_worker->callback) {
  266. seader_worker->callback(SeaderWorkerEventSamMissing, seader_worker->context);
  267. }
  268. return message.consumed;
  269. }
  270. if(message.bStatus == 0x42 && message.bError == 0xfe) {
  271. FURI_LOG_W(TAG, "No card");
  272. if(seader_worker->callback) {
  273. seader_worker->callback(SeaderWorkerEventSamMissing, seader_worker->context);
  274. }
  275. return message.consumed;
  276. }
  277. if(message.bError != 0) {
  278. FURI_LOG_W(TAG, "CCID error %02x", message.bError);
  279. message.consumed = cmd_len;
  280. if(seader_worker->callback) {
  281. seader_worker->callback(SeaderWorkerEventSamMissing, seader_worker->context);
  282. }
  283. return message.consumed;
  284. }
  285. if(message.bMessageType == CCID_MESSAGE_TYPE_RDR_to_PC_Parameters) {
  286. FURI_LOG_D(TAG, "Got Parameters");
  287. if(seader_uart->T == 1) {
  288. seader_t_1_set_IFSD(seader);
  289. } else {
  290. seader_worker_send_version(seader);
  291. if(seader_worker->callback) {
  292. seader_worker->callback(SeaderWorkerEventSamPresent, seader_worker->context);
  293. }
  294. }
  295. } else if(message.bMessageType == CCID_MESSAGE_TYPE_RDR_to_PC_DataBlock) {
  296. if(hasSAM) {
  297. if(message.bSlot == sam_slot) {
  298. if(seader_uart->T == 0) {
  299. seader_worker_process_sam_message(
  300. seader, message.payload, message.dwLength);
  301. } else if(seader_uart->T == 1) {
  302. seader_recv_t1(seader, &message);
  303. }
  304. } else {
  305. FURI_LOG_D(TAG, "Discarding message on non-sam slot");
  306. }
  307. } else {
  308. if(memcmp(SAM_ATR, message.payload, sizeof(SAM_ATR)) == 0) {
  309. FURI_LOG_I(TAG, "SAM ATR!");
  310. hasSAM = true;
  311. sam_slot = message.bSlot;
  312. if(seader_uart->T == 0) {
  313. seader_ccid_GetParameters(seader_uart);
  314. } else if(seader_uart->T == 1) {
  315. seader_ccid_SetParameters(
  316. seader, sam_slot, message.payload, message.dwLength);
  317. }
  318. } else if(memcmp(SAM_ATR2, message.payload, sizeof(SAM_ATR2)) == 0) {
  319. FURI_LOG_I(TAG, "SAM ATR2!");
  320. hasSAM = true;
  321. sam_slot = message.bSlot;
  322. // I don't have an ATR2 to test with
  323. seader_ccid_GetParameters(seader_uart);
  324. } else {
  325. FURI_LOG_W(TAG, "Unknown ATR");
  326. if(seader_worker->callback) {
  327. seader_worker->callback(SeaderWorkerEventSamWrong, seader_worker->context);
  328. }
  329. }
  330. }
  331. } else {
  332. FURI_LOG_W(TAG, "Unhandled CCID message type %02x", message.bMessageType);
  333. }
  334. }
  335. return message.consumed;
  336. }