bad_usb_script.c 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757
  1. #include <furi.h>
  2. #include <furi_hal.h>
  3. #include <gui/gui.h>
  4. #include <input/input.h>
  5. #include <lib/toolbox/args.h>
  6. #include <furi_hal_usb_hid.h>
  7. #include <storage/storage.h>
  8. #include "bad_usb_script.h"
  9. #include <dolphin/dolphin.h>
  10. #define TAG "BadUSB"
  11. #define WORKER_TAG TAG "Worker"
  12. #define FILE_BUFFER_LEN 16
  13. #define SCRIPT_STATE_ERROR (-1)
  14. #define SCRIPT_STATE_END (-2)
  15. #define SCRIPT_STATE_NEXT_LINE (-3)
  16. #define BADUSB_ASCII_TO_KEY(script, x) \
  17. (((uint8_t)x < 128) ? (script->layout[(uint8_t)x]) : HID_KEYBOARD_NONE)
  18. typedef enum {
  19. WorkerEvtToggle = (1 << 0),
  20. WorkerEvtEnd = (1 << 1),
  21. WorkerEvtConnect = (1 << 2),
  22. WorkerEvtDisconnect = (1 << 3),
  23. } WorkerEvtFlags;
  24. struct BadUsbScript {
  25. FuriHalUsbHidConfig hid_cfg;
  26. BadUsbState st;
  27. FuriString* file_path;
  28. uint32_t defdelay;
  29. uint16_t layout[128];
  30. uint32_t stringdelay;
  31. FuriThread* thread;
  32. uint8_t file_buf[FILE_BUFFER_LEN + 1];
  33. uint8_t buf_start;
  34. uint8_t buf_len;
  35. bool file_end;
  36. FuriString* line;
  37. FuriString* line_prev;
  38. uint32_t repeat_cnt;
  39. };
  40. typedef struct {
  41. char* name;
  42. uint16_t keycode;
  43. } DuckyKey;
  44. static const DuckyKey ducky_keys[] = {
  45. {"CTRL-ALT", KEY_MOD_LEFT_CTRL | KEY_MOD_LEFT_ALT},
  46. {"CTRL-SHIFT", KEY_MOD_LEFT_CTRL | KEY_MOD_LEFT_SHIFT},
  47. {"ALT-SHIFT", KEY_MOD_LEFT_ALT | KEY_MOD_LEFT_SHIFT},
  48. {"ALT-GUI", KEY_MOD_LEFT_ALT | KEY_MOD_LEFT_GUI},
  49. {"GUI-SHIFT", KEY_MOD_LEFT_GUI | KEY_MOD_LEFT_SHIFT},
  50. {"GUI-CTRL", KEY_MOD_LEFT_GUI | KEY_MOD_LEFT_CTRL},
  51. {"CTRL", KEY_MOD_LEFT_CTRL},
  52. {"CONTROL", KEY_MOD_LEFT_CTRL},
  53. {"SHIFT", KEY_MOD_LEFT_SHIFT},
  54. {"ALT", KEY_MOD_LEFT_ALT},
  55. {"GUI", KEY_MOD_LEFT_GUI},
  56. {"WINDOWS", KEY_MOD_LEFT_GUI},
  57. {"DOWNARROW", HID_KEYBOARD_DOWN_ARROW},
  58. {"DOWN", HID_KEYBOARD_DOWN_ARROW},
  59. {"LEFTARROW", HID_KEYBOARD_LEFT_ARROW},
  60. {"LEFT", HID_KEYBOARD_LEFT_ARROW},
  61. {"RIGHTARROW", HID_KEYBOARD_RIGHT_ARROW},
  62. {"RIGHT", HID_KEYBOARD_RIGHT_ARROW},
  63. {"UPARROW", HID_KEYBOARD_UP_ARROW},
  64. {"UP", HID_KEYBOARD_UP_ARROW},
  65. {"ENTER", HID_KEYBOARD_RETURN},
  66. {"BREAK", HID_KEYBOARD_PAUSE},
  67. {"PAUSE", HID_KEYBOARD_PAUSE},
  68. {"CAPSLOCK", HID_KEYBOARD_CAPS_LOCK},
  69. {"DELETE", HID_KEYBOARD_DELETE_FORWARD},
  70. {"BACKSPACE", HID_KEYBOARD_DELETE},
  71. {"END", HID_KEYBOARD_END},
  72. {"ESC", HID_KEYBOARD_ESCAPE},
  73. {"ESCAPE", HID_KEYBOARD_ESCAPE},
  74. {"HOME", HID_KEYBOARD_HOME},
  75. {"INSERT", HID_KEYBOARD_INSERT},
  76. {"NUMLOCK", HID_KEYPAD_NUMLOCK},
  77. {"PAGEUP", HID_KEYBOARD_PAGE_UP},
  78. {"PAGEDOWN", HID_KEYBOARD_PAGE_DOWN},
  79. {"PRINTSCREEN", HID_KEYBOARD_PRINT_SCREEN},
  80. {"SCROLLLOCK", HID_KEYBOARD_SCROLL_LOCK},
  81. {"SPACE", HID_KEYBOARD_SPACEBAR},
  82. {"TAB", HID_KEYBOARD_TAB},
  83. {"MENU", HID_KEYBOARD_APPLICATION},
  84. {"APP", HID_KEYBOARD_APPLICATION},
  85. {"F1", HID_KEYBOARD_F1},
  86. {"F2", HID_KEYBOARD_F2},
  87. {"F3", HID_KEYBOARD_F3},
  88. {"F4", HID_KEYBOARD_F4},
  89. {"F5", HID_KEYBOARD_F5},
  90. {"F6", HID_KEYBOARD_F6},
  91. {"F7", HID_KEYBOARD_F7},
  92. {"F8", HID_KEYBOARD_F8},
  93. {"F9", HID_KEYBOARD_F9},
  94. {"F10", HID_KEYBOARD_F10},
  95. {"F11", HID_KEYBOARD_F11},
  96. {"F12", HID_KEYBOARD_F12},
  97. };
  98. static const char ducky_cmd_comment[] = {"REM"};
  99. static const char ducky_cmd_id[] = {"ID"};
  100. static const char ducky_cmd_delay[] = {"DELAY "};
  101. static const char ducky_cmd_string[] = {"STRING "};
  102. static const char ducky_cmd_defdelay_1[] = {"DEFAULT_DELAY "};
  103. static const char ducky_cmd_defdelay_2[] = {"DEFAULTDELAY "};
  104. static const char ducky_cmd_stringdelay_1[] = {"STRINGDELAY "};
  105. static const char ducky_cmd_stringdelay_2[] = {"STRING_DELAY "};
  106. static const char ducky_cmd_repeat[] = {"REPEAT "};
  107. static const char ducky_cmd_sysrq[] = {"SYSRQ "};
  108. static const char ducky_cmd_altchar[] = {"ALTCHAR "};
  109. static const char ducky_cmd_altstr_1[] = {"ALTSTRING "};
  110. static const char ducky_cmd_altstr_2[] = {"ALTCODE "};
  111. static const uint8_t numpad_keys[10] = {
  112. HID_KEYPAD_0,
  113. HID_KEYPAD_1,
  114. HID_KEYPAD_2,
  115. HID_KEYPAD_3,
  116. HID_KEYPAD_4,
  117. HID_KEYPAD_5,
  118. HID_KEYPAD_6,
  119. HID_KEYPAD_7,
  120. HID_KEYPAD_8,
  121. HID_KEYPAD_9,
  122. };
  123. static bool ducky_get_number(const char* param, uint32_t* val) {
  124. uint32_t value = 0;
  125. if(sscanf(param, "%lu", &value) == 1) {
  126. *val = value;
  127. return true;
  128. }
  129. return false;
  130. }
  131. static uint32_t ducky_get_command_len(const char* line) {
  132. uint32_t len = strlen(line);
  133. for(uint32_t i = 0; i < len; i++) {
  134. if(line[i] == ' ') return i;
  135. }
  136. return 0;
  137. }
  138. static bool ducky_is_line_end(const char chr) {
  139. return ((chr == ' ') || (chr == '\0') || (chr == '\r') || (chr == '\n'));
  140. }
  141. static void ducky_numlock_on() {
  142. if((furi_hal_hid_get_led_state() & HID_KB_LED_NUM) == 0) {
  143. furi_hal_hid_kb_press(HID_KEYBOARD_LOCK_NUM_LOCK);
  144. furi_hal_hid_kb_release(HID_KEYBOARD_LOCK_NUM_LOCK);
  145. }
  146. }
  147. static bool ducky_numpad_press(const char num) {
  148. if((num < '0') || (num > '9')) return false;
  149. uint16_t key = numpad_keys[num - '0'];
  150. furi_hal_hid_kb_press(key);
  151. furi_hal_hid_kb_release(key);
  152. return true;
  153. }
  154. static bool ducky_altchar(const char* charcode) {
  155. uint8_t i = 0;
  156. bool state = false;
  157. FURI_LOG_I(WORKER_TAG, "char %s", charcode);
  158. furi_hal_hid_kb_press(KEY_MOD_LEFT_ALT);
  159. while(!ducky_is_line_end(charcode[i])) {
  160. state = ducky_numpad_press(charcode[i]);
  161. if(state == false) break;
  162. i++;
  163. }
  164. furi_hal_hid_kb_release(KEY_MOD_LEFT_ALT);
  165. return state;
  166. }
  167. static bool ducky_altstring(const char* param) {
  168. uint32_t i = 0;
  169. bool state = false;
  170. while(param[i] != '\0') {
  171. if((param[i] < ' ') || (param[i] > '~')) {
  172. i++;
  173. continue; // Skip non-printable chars
  174. }
  175. char temp_str[4];
  176. snprintf(temp_str, 4, "%u", param[i]);
  177. state = ducky_altchar(temp_str);
  178. if(state == false) break;
  179. i++;
  180. }
  181. return state;
  182. }
  183. static bool ducky_string(BadUsbScript* bad_usb, const char* param) {
  184. uint32_t i = 0;
  185. while(param[i] != '\0') {
  186. uint16_t keycode = BADUSB_ASCII_TO_KEY(bad_usb, param[i]);
  187. if(keycode != HID_KEYBOARD_NONE) {
  188. furi_hal_hid_kb_press(keycode);
  189. furi_hal_hid_kb_release(keycode);
  190. if(bad_usb->stringdelay > 0) {
  191. furi_delay_ms(bad_usb->stringdelay);
  192. }
  193. }
  194. i++;
  195. }
  196. bad_usb->stringdelay = 0;
  197. return true;
  198. }
  199. static uint16_t ducky_get_keycode(BadUsbScript* bad_usb, const char* param, bool accept_chars) {
  200. for(size_t i = 0; i < (sizeof(ducky_keys) / sizeof(ducky_keys[0])); i++) {
  201. size_t key_cmd_len = strlen(ducky_keys[i].name);
  202. if((strncmp(param, ducky_keys[i].name, key_cmd_len) == 0) &&
  203. (ducky_is_line_end(param[key_cmd_len]))) {
  204. return ducky_keys[i].keycode;
  205. }
  206. }
  207. if((accept_chars) && (strlen(param) > 0)) {
  208. return (BADUSB_ASCII_TO_KEY(bad_usb, param[0]) & 0xFF);
  209. }
  210. return 0;
  211. }
  212. static int32_t
  213. ducky_parse_line(BadUsbScript* bad_usb, FuriString* line, char* error, size_t error_len) {
  214. uint32_t line_len = furi_string_size(line);
  215. const char* line_tmp = furi_string_get_cstr(line);
  216. bool state = false;
  217. if(line_len == 0) {
  218. return SCRIPT_STATE_NEXT_LINE; // Skip empty lines
  219. }
  220. FURI_LOG_D(WORKER_TAG, "line:%s", line_tmp);
  221. // General commands
  222. if(strncmp(line_tmp, ducky_cmd_comment, strlen(ducky_cmd_comment)) == 0) {
  223. // REM - comment line
  224. return (0);
  225. } else if(strncmp(line_tmp, ducky_cmd_id, strlen(ducky_cmd_id)) == 0) {
  226. // ID - executed in ducky_script_preload
  227. return (0);
  228. } else if(strncmp(line_tmp, ducky_cmd_delay, strlen(ducky_cmd_delay)) == 0) {
  229. // DELAY
  230. line_tmp = &line_tmp[ducky_get_command_len(line_tmp) + 1];
  231. uint32_t delay_val = 0;
  232. state = ducky_get_number(line_tmp, &delay_val);
  233. if((state) && (delay_val > 0)) {
  234. return (int32_t)delay_val;
  235. }
  236. if(error != NULL) {
  237. snprintf(error, error_len, "Invalid number %s", line_tmp);
  238. }
  239. return SCRIPT_STATE_ERROR;
  240. } else if(
  241. (strncmp(line_tmp, ducky_cmd_defdelay_1, strlen(ducky_cmd_defdelay_1)) == 0) ||
  242. (strncmp(line_tmp, ducky_cmd_defdelay_2, strlen(ducky_cmd_defdelay_2)) == 0)) {
  243. // DEFAULT_DELAY
  244. line_tmp = &line_tmp[ducky_get_command_len(line_tmp) + 1];
  245. state = ducky_get_number(line_tmp, &bad_usb->defdelay);
  246. if(!state && error != NULL) {
  247. snprintf(error, error_len, "Invalid number %s", line_tmp);
  248. }
  249. return (state) ? (0) : SCRIPT_STATE_ERROR;
  250. } else if(
  251. (strncmp(line_tmp, ducky_cmd_stringdelay_1, strlen(ducky_cmd_stringdelay_1)) == 0) ||
  252. (strncmp(line_tmp, ducky_cmd_stringdelay_2, strlen(ducky_cmd_stringdelay_2)) == 0)) {
  253. //STRINGDELAY, finally it's here
  254. line_tmp = &line_tmp[ducky_get_command_len(line_tmp) + 1];
  255. state = ducky_get_number(line_tmp, &bad_usb->stringdelay);
  256. if((state) && (bad_usb->stringdelay > 0)) {
  257. return state;
  258. }
  259. if(error != NULL) {
  260. snprintf(error, error_len, "Invalid number %s", line_tmp);
  261. }
  262. return SCRIPT_STATE_ERROR;
  263. } else if(strncmp(line_tmp, ducky_cmd_string, strlen(ducky_cmd_string)) == 0) {
  264. // STRING
  265. line_tmp = &line_tmp[ducky_get_command_len(line_tmp) + 1];
  266. state = ducky_string(bad_usb, line_tmp);
  267. if(!state && error != NULL) {
  268. snprintf(error, error_len, "Invalid string %s", line_tmp);
  269. }
  270. return (state) ? (0) : SCRIPT_STATE_ERROR;
  271. } else if(strncmp(line_tmp, ducky_cmd_altchar, strlen(ducky_cmd_altchar)) == 0) {
  272. // ALTCHAR
  273. line_tmp = &line_tmp[ducky_get_command_len(line_tmp) + 1];
  274. ducky_numlock_on();
  275. state = ducky_altchar(line_tmp);
  276. if(!state && error != NULL) {
  277. snprintf(error, error_len, "Invalid altchar %s", line_tmp);
  278. }
  279. return (state) ? (0) : SCRIPT_STATE_ERROR;
  280. } else if(
  281. (strncmp(line_tmp, ducky_cmd_altstr_1, strlen(ducky_cmd_altstr_1)) == 0) ||
  282. (strncmp(line_tmp, ducky_cmd_altstr_2, strlen(ducky_cmd_altstr_2)) == 0)) {
  283. // ALTSTRING
  284. line_tmp = &line_tmp[ducky_get_command_len(line_tmp) + 1];
  285. ducky_numlock_on();
  286. state = ducky_altstring(line_tmp);
  287. if(!state && error != NULL) {
  288. snprintf(error, error_len, "Invalid altstring %s", line_tmp);
  289. }
  290. return (state) ? (0) : SCRIPT_STATE_ERROR;
  291. } else if(strncmp(line_tmp, ducky_cmd_repeat, strlen(ducky_cmd_repeat)) == 0) {
  292. // REPEAT
  293. line_tmp = &line_tmp[ducky_get_command_len(line_tmp) + 1];
  294. state = ducky_get_number(line_tmp, &bad_usb->repeat_cnt);
  295. if(!state && error != NULL) {
  296. snprintf(error, error_len, "Invalid number %s", line_tmp);
  297. }
  298. return (state) ? (0) : SCRIPT_STATE_ERROR;
  299. } else if(strncmp(line_tmp, ducky_cmd_sysrq, strlen(ducky_cmd_sysrq)) == 0) {
  300. // SYSRQ
  301. line_tmp = &line_tmp[ducky_get_command_len(line_tmp) + 1];
  302. uint16_t key = ducky_get_keycode(bad_usb, line_tmp, true);
  303. furi_hal_hid_kb_press(KEY_MOD_LEFT_ALT | HID_KEYBOARD_PRINT_SCREEN);
  304. furi_hal_hid_kb_press(key);
  305. furi_hal_hid_kb_release_all();
  306. return (0);
  307. } else {
  308. // Special keys + modifiers
  309. uint16_t key = ducky_get_keycode(bad_usb, line_tmp, false);
  310. if(key == HID_KEYBOARD_NONE) {
  311. if(error != NULL) {
  312. snprintf(error, error_len, "No keycode defined for %s", line_tmp);
  313. }
  314. return SCRIPT_STATE_ERROR;
  315. }
  316. if((key & 0xFF00) != 0) {
  317. // It's a modifier key
  318. line_tmp = &line_tmp[ducky_get_command_len(line_tmp) + 1];
  319. key |= ducky_get_keycode(bad_usb, line_tmp, true);
  320. }
  321. furi_hal_hid_kb_press(key);
  322. furi_hal_hid_kb_release(key);
  323. return (0);
  324. }
  325. }
  326. static bool ducky_set_usb_id(BadUsbScript* bad_usb, const char* line) {
  327. if(sscanf(line, "%lX:%lX", &bad_usb->hid_cfg.vid, &bad_usb->hid_cfg.pid) == 2) {
  328. bad_usb->hid_cfg.manuf[0] = '\0';
  329. bad_usb->hid_cfg.product[0] = '\0';
  330. uint8_t id_len = ducky_get_command_len(line);
  331. if(!ducky_is_line_end(line[id_len + 1])) {
  332. sscanf(
  333. &line[id_len + 1],
  334. "%31[^\r\n:]:%31[^\r\n]",
  335. bad_usb->hid_cfg.manuf,
  336. bad_usb->hid_cfg.product);
  337. }
  338. FURI_LOG_D(
  339. WORKER_TAG,
  340. "set id: %04lX:%04lX mfr:%s product:%s",
  341. bad_usb->hid_cfg.vid,
  342. bad_usb->hid_cfg.pid,
  343. bad_usb->hid_cfg.manuf,
  344. bad_usb->hid_cfg.product);
  345. return true;
  346. }
  347. return false;
  348. }
  349. static bool ducky_script_preload(BadUsbScript* bad_usb, File* script_file) {
  350. uint8_t ret = 0;
  351. uint32_t line_len = 0;
  352. furi_string_reset(bad_usb->line);
  353. do {
  354. ret = storage_file_read(script_file, bad_usb->file_buf, FILE_BUFFER_LEN);
  355. for(uint16_t i = 0; i < ret; i++) {
  356. if(bad_usb->file_buf[i] == '\n' && line_len > 0) {
  357. bad_usb->st.line_nb++;
  358. line_len = 0;
  359. } else {
  360. if(bad_usb->st.line_nb == 0) { // Save first line
  361. furi_string_push_back(bad_usb->line, bad_usb->file_buf[i]);
  362. }
  363. line_len++;
  364. }
  365. }
  366. if(storage_file_eof(script_file)) {
  367. if(line_len > 0) {
  368. bad_usb->st.line_nb++;
  369. break;
  370. }
  371. }
  372. } while(ret > 0);
  373. const char* line_tmp = furi_string_get_cstr(bad_usb->line);
  374. bool id_set = false; // Looking for ID command at first line
  375. if(strncmp(line_tmp, ducky_cmd_id, strlen(ducky_cmd_id)) == 0) {
  376. id_set = ducky_set_usb_id(bad_usb, &line_tmp[strlen(ducky_cmd_id) + 1]);
  377. }
  378. if(id_set) {
  379. furi_check(furi_hal_usb_set_config(&usb_hid, &bad_usb->hid_cfg));
  380. } else {
  381. furi_check(furi_hal_usb_set_config(&usb_hid, NULL));
  382. }
  383. storage_file_seek(script_file, 0, true);
  384. furi_string_reset(bad_usb->line);
  385. return true;
  386. }
  387. static int32_t ducky_script_execute_next(BadUsbScript* bad_usb, File* script_file) {
  388. int32_t delay_val = 0;
  389. if(bad_usb->repeat_cnt > 0) {
  390. bad_usb->repeat_cnt--;
  391. delay_val = ducky_parse_line(
  392. bad_usb, bad_usb->line_prev, bad_usb->st.error, sizeof(bad_usb->st.error));
  393. if(delay_val == SCRIPT_STATE_NEXT_LINE) { // Empty line
  394. return 0;
  395. } else if(delay_val < 0) { // Script error
  396. bad_usb->st.error_line = bad_usb->st.line_cur - 1;
  397. FURI_LOG_E(WORKER_TAG, "Unknown command at line %u", bad_usb->st.line_cur - 1U);
  398. return SCRIPT_STATE_ERROR;
  399. } else {
  400. return (delay_val + bad_usb->defdelay);
  401. }
  402. }
  403. furi_string_set(bad_usb->line_prev, bad_usb->line);
  404. furi_string_reset(bad_usb->line);
  405. while(1) {
  406. if(bad_usb->buf_len == 0) {
  407. bad_usb->buf_len = storage_file_read(script_file, bad_usb->file_buf, FILE_BUFFER_LEN);
  408. if(storage_file_eof(script_file)) {
  409. if((bad_usb->buf_len < FILE_BUFFER_LEN) && (bad_usb->file_end == false)) {
  410. bad_usb->file_buf[bad_usb->buf_len] = '\n';
  411. bad_usb->buf_len++;
  412. bad_usb->file_end = true;
  413. }
  414. }
  415. bad_usb->buf_start = 0;
  416. if(bad_usb->buf_len == 0) return SCRIPT_STATE_END;
  417. }
  418. for(uint8_t i = bad_usb->buf_start; i < (bad_usb->buf_start + bad_usb->buf_len); i++) {
  419. if(bad_usb->file_buf[i] == '\n' && furi_string_size(bad_usb->line) > 0) {
  420. bad_usb->st.line_cur++;
  421. bad_usb->buf_len = bad_usb->buf_len + bad_usb->buf_start - (i + 1);
  422. bad_usb->buf_start = i + 1;
  423. furi_string_trim(bad_usb->line);
  424. delay_val = ducky_parse_line(
  425. bad_usb, bad_usb->line, bad_usb->st.error, sizeof(bad_usb->st.error));
  426. if(delay_val == SCRIPT_STATE_NEXT_LINE) { // Empty line
  427. return 0;
  428. } else if(delay_val < 0) {
  429. bad_usb->st.error_line = bad_usb->st.line_cur;
  430. FURI_LOG_E(WORKER_TAG, "Unknown command at line %u", bad_usb->st.line_cur);
  431. return SCRIPT_STATE_ERROR;
  432. } else {
  433. return (delay_val + bad_usb->defdelay);
  434. }
  435. } else {
  436. furi_string_push_back(bad_usb->line, bad_usb->file_buf[i]);
  437. }
  438. }
  439. bad_usb->buf_len = 0;
  440. if(bad_usb->file_end) return SCRIPT_STATE_END;
  441. }
  442. return 0;
  443. }
  444. static void bad_usb_hid_state_callback(bool state, void* context) {
  445. furi_assert(context);
  446. BadUsbScript* bad_usb = context;
  447. if(state == true)
  448. furi_thread_flags_set(furi_thread_get_id(bad_usb->thread), WorkerEvtConnect);
  449. else
  450. furi_thread_flags_set(furi_thread_get_id(bad_usb->thread), WorkerEvtDisconnect);
  451. }
  452. static uint32_t bad_usb_flags_get(uint32_t flags_mask, uint32_t timeout) {
  453. uint32_t flags = furi_thread_flags_get();
  454. furi_check((flags & FuriFlagError) == 0);
  455. if(flags == 0) {
  456. flags = furi_thread_flags_wait(flags_mask, FuriFlagWaitAny, timeout);
  457. furi_check(((flags & FuriFlagError) == 0) || (flags == (unsigned)FuriFlagErrorTimeout));
  458. } else {
  459. uint32_t state = furi_thread_flags_clear(flags);
  460. furi_check((state & FuriFlagError) == 0);
  461. }
  462. return flags;
  463. }
  464. static int32_t bad_usb_worker(void* context) {
  465. BadUsbScript* bad_usb = context;
  466. BadUsbWorkerState worker_state = BadUsbStateInit;
  467. int32_t delay_val = 0;
  468. FURI_LOG_I(WORKER_TAG, "Init");
  469. File* script_file = storage_file_alloc(furi_record_open(RECORD_STORAGE));
  470. bad_usb->line = furi_string_alloc();
  471. bad_usb->line_prev = furi_string_alloc();
  472. furi_hal_hid_set_state_callback(bad_usb_hid_state_callback, bad_usb);
  473. while(1) {
  474. if(worker_state == BadUsbStateInit) { // State: initialization
  475. if(storage_file_open(
  476. script_file,
  477. furi_string_get_cstr(bad_usb->file_path),
  478. FSAM_READ,
  479. FSOM_OPEN_EXISTING)) {
  480. if((ducky_script_preload(bad_usb, script_file)) && (bad_usb->st.line_nb > 0)) {
  481. if(furi_hal_hid_is_connected()) {
  482. worker_state = BadUsbStateIdle; // Ready to run
  483. } else {
  484. worker_state = BadUsbStateNotConnected; // USB not connected
  485. }
  486. } else {
  487. worker_state = BadUsbStateScriptError; // Script preload error
  488. }
  489. } else {
  490. FURI_LOG_E(WORKER_TAG, "File open error");
  491. worker_state = BadUsbStateFileError; // File open error
  492. }
  493. bad_usb->st.state = worker_state;
  494. } else if(worker_state == BadUsbStateNotConnected) { // State: USB not connected
  495. uint32_t flags = bad_usb_flags_get(
  496. WorkerEvtEnd | WorkerEvtConnect | WorkerEvtToggle, FuriWaitForever);
  497. if(flags & WorkerEvtEnd) {
  498. break;
  499. } else if(flags & WorkerEvtConnect) {
  500. worker_state = BadUsbStateIdle; // Ready to run
  501. } else if(flags & WorkerEvtToggle) {
  502. worker_state = BadUsbStateWillRun; // Will run when USB is connected
  503. }
  504. bad_usb->st.state = worker_state;
  505. } else if(worker_state == BadUsbStateIdle) { // State: ready to start
  506. uint32_t flags = bad_usb_flags_get(
  507. WorkerEvtEnd | WorkerEvtToggle | WorkerEvtDisconnect, FuriWaitForever);
  508. if(flags & WorkerEvtEnd) {
  509. break;
  510. } else if(flags & WorkerEvtToggle) { // Start executing script
  511. DOLPHIN_DEED(DolphinDeedBadUsbPlayScript);
  512. delay_val = 0;
  513. bad_usb->buf_len = 0;
  514. bad_usb->st.line_cur = 0;
  515. bad_usb->defdelay = 0;
  516. bad_usb->stringdelay = 0;
  517. bad_usb->repeat_cnt = 0;
  518. bad_usb->file_end = false;
  519. storage_file_seek(script_file, 0, true);
  520. worker_state = BadUsbStateRunning;
  521. } else if(flags & WorkerEvtDisconnect) {
  522. worker_state = BadUsbStateNotConnected; // USB disconnected
  523. }
  524. bad_usb->st.state = worker_state;
  525. } else if(worker_state == BadUsbStateWillRun) { // State: start on connection
  526. uint32_t flags = bad_usb_flags_get(
  527. WorkerEvtEnd | WorkerEvtConnect | WorkerEvtToggle, FuriWaitForever);
  528. if(flags & WorkerEvtEnd) {
  529. break;
  530. } else if(flags & WorkerEvtConnect) { // Start executing script
  531. DOLPHIN_DEED(DolphinDeedBadUsbPlayScript);
  532. delay_val = 0;
  533. bad_usb->buf_len = 0;
  534. bad_usb->st.line_cur = 0;
  535. bad_usb->defdelay = 0;
  536. bad_usb->stringdelay = 0;
  537. bad_usb->repeat_cnt = 0;
  538. bad_usb->file_end = false;
  539. storage_file_seek(script_file, 0, true);
  540. // extra time for PC to recognize Flipper as keyboard
  541. flags = furi_thread_flags_wait(
  542. WorkerEvtEnd | WorkerEvtDisconnect | WorkerEvtToggle,
  543. FuriFlagWaitAny | FuriFlagNoClear,
  544. 1500);
  545. if(flags == (unsigned)FuriFlagErrorTimeout) {
  546. // If nothing happened - start script execution
  547. worker_state = BadUsbStateRunning;
  548. } else if(flags & WorkerEvtToggle) {
  549. worker_state = BadUsbStateIdle;
  550. furi_thread_flags_clear(WorkerEvtToggle);
  551. }
  552. } else if(flags & WorkerEvtToggle) { // Cancel scheduled execution
  553. worker_state = BadUsbStateNotConnected;
  554. }
  555. bad_usb->st.state = worker_state;
  556. } else if(worker_state == BadUsbStateRunning) { // State: running
  557. uint16_t delay_cur = (delay_val > 1000) ? (1000) : (delay_val);
  558. uint32_t flags = furi_thread_flags_wait(
  559. WorkerEvtEnd | WorkerEvtToggle | WorkerEvtDisconnect, FuriFlagWaitAny, delay_cur);
  560. delay_val -= delay_cur;
  561. if(!(flags & FuriFlagError)) {
  562. if(flags & WorkerEvtEnd) {
  563. break;
  564. } else if(flags & WorkerEvtToggle) {
  565. worker_state = BadUsbStateIdle; // Stop executing script
  566. furi_hal_hid_kb_release_all();
  567. } else if(flags & WorkerEvtDisconnect) {
  568. worker_state = BadUsbStateNotConnected; // USB disconnected
  569. furi_hal_hid_kb_release_all();
  570. }
  571. bad_usb->st.state = worker_state;
  572. continue;
  573. } else if(
  574. (flags == (unsigned)FuriFlagErrorTimeout) ||
  575. (flags == (unsigned)FuriFlagErrorResource)) {
  576. if(delay_val > 0) {
  577. bad_usb->st.delay_remain--;
  578. continue;
  579. }
  580. bad_usb->st.state = BadUsbStateRunning;
  581. delay_val = ducky_script_execute_next(bad_usb, script_file);
  582. if(delay_val == SCRIPT_STATE_ERROR) { // Script error
  583. delay_val = 0;
  584. worker_state = BadUsbStateScriptError;
  585. bad_usb->st.state = worker_state;
  586. } else if(delay_val == SCRIPT_STATE_END) { // End of script
  587. delay_val = 0;
  588. worker_state = BadUsbStateIdle;
  589. bad_usb->st.state = BadUsbStateDone;
  590. furi_hal_hid_kb_release_all();
  591. continue;
  592. } else if(delay_val > 1000) {
  593. bad_usb->st.state = BadUsbStateDelay; // Show long delays
  594. bad_usb->st.delay_remain = delay_val / 1000;
  595. }
  596. } else {
  597. furi_check((flags & FuriFlagError) == 0);
  598. }
  599. } else if(
  600. (worker_state == BadUsbStateFileError) ||
  601. (worker_state == BadUsbStateScriptError)) { // State: error
  602. uint32_t flags =
  603. bad_usb_flags_get(WorkerEvtEnd, FuriWaitForever); // Waiting for exit command
  604. if(flags & WorkerEvtEnd) {
  605. break;
  606. }
  607. }
  608. }
  609. furi_hal_hid_set_state_callback(NULL, NULL);
  610. storage_file_close(script_file);
  611. storage_file_free(script_file);
  612. furi_string_free(bad_usb->line);
  613. furi_string_free(bad_usb->line_prev);
  614. FURI_LOG_I(WORKER_TAG, "End");
  615. return 0;
  616. }
  617. static void bad_usb_script_set_default_keyboard_layout(BadUsbScript* bad_usb) {
  618. furi_assert(bad_usb);
  619. memset(bad_usb->layout, HID_KEYBOARD_NONE, sizeof(bad_usb->layout));
  620. memcpy(bad_usb->layout, hid_asciimap, MIN(sizeof(hid_asciimap), sizeof(bad_usb->layout)));
  621. }
  622. BadUsbScript* bad_usb_script_open(FuriString* file_path) {
  623. furi_assert(file_path);
  624. BadUsbScript* bad_usb = malloc(sizeof(BadUsbScript));
  625. bad_usb->file_path = furi_string_alloc();
  626. furi_string_set(bad_usb->file_path, file_path);
  627. bad_usb_script_set_default_keyboard_layout(bad_usb);
  628. bad_usb->st.state = BadUsbStateInit;
  629. bad_usb->st.error[0] = '\0';
  630. bad_usb->thread = furi_thread_alloc_ex("BadUsbWorker", 2048, bad_usb_worker, bad_usb);
  631. furi_thread_start(bad_usb->thread);
  632. return bad_usb;
  633. } //-V773
  634. void bad_usb_script_close(BadUsbScript* bad_usb) {
  635. furi_assert(bad_usb);
  636. furi_thread_flags_set(furi_thread_get_id(bad_usb->thread), WorkerEvtEnd);
  637. furi_thread_join(bad_usb->thread);
  638. furi_thread_free(bad_usb->thread);
  639. furi_string_free(bad_usb->file_path);
  640. free(bad_usb);
  641. }
  642. void bad_usb_script_set_keyboard_layout(BadUsbScript* bad_usb, FuriString* layout_path) {
  643. furi_assert(bad_usb);
  644. if((bad_usb->st.state == BadUsbStateRunning) || (bad_usb->st.state == BadUsbStateDelay)) {
  645. // do not update keyboard layout while a script is running
  646. return;
  647. }
  648. File* layout_file = storage_file_alloc(furi_record_open(RECORD_STORAGE));
  649. if(!furi_string_empty(layout_path)) { //-V1051
  650. if(storage_file_open(
  651. layout_file, furi_string_get_cstr(layout_path), FSAM_READ, FSOM_OPEN_EXISTING)) {
  652. uint16_t layout[128];
  653. if(storage_file_read(layout_file, layout, sizeof(layout)) == sizeof(layout)) {
  654. memcpy(bad_usb->layout, layout, sizeof(layout));
  655. }
  656. }
  657. storage_file_close(layout_file);
  658. } else {
  659. bad_usb_script_set_default_keyboard_layout(bad_usb);
  660. }
  661. storage_file_free(layout_file);
  662. }
  663. void bad_usb_script_toggle(BadUsbScript* bad_usb) {
  664. furi_assert(bad_usb);
  665. furi_thread_flags_set(furi_thread_get_id(bad_usb->thread), WorkerEvtToggle);
  666. }
  667. BadUsbState* bad_usb_script_get_state(BadUsbScript* bad_usb) {
  668. furi_assert(bad_usb);
  669. return &(bad_usb->st);
  670. }