A ~1s background watcher on DeviceRepo samples a cheap FIDO HID presence
fingerprint (vid:pid:serial, by enumeration only — it never opens the
device, so it can't contend with an in-flight read or write) and triggers
a refresh whenever the key is plugged, unplugged or swapped. Every screen
then reflects the current device without the manual Refresh button. The
watcher skips a tick while a refresh/write is in flight and stops cleanly
when the repo is dropped.
Several Configuration-screen fields were blank, wrong, or silently
overwrote a working device on save when talking to RS-Key firmware:
- CONFIG_READ over CTAPHID 0x41 answers with a CBOR `{1: blob}` map, but
the client fed the raw CBOR bytes downstream. The PHY read only worked
by accident for records under 24 bytes and broke once a product name
pushed it over; the LED read never worked. Decode the map and return
the inner record.
- Parse the LED status block at the correct stride ((len-1)/4) in one
shared helper, fixing the CCID path that read a 17-byte block as a
legacy 9-byte one (colour shown as the effect id).
- Read hardware LED (GPIO/brightness/driver) and touch-timeout as
optionals: an absent phy tag now means "firmware default" (blank
field) and is not written back, so a virgin phy is no longer clobbered
with GPIO=0 / driver=Pico / brightness=0 on the next Apply. A value is
written only when the user sets one.
- Hide the "Supported Curves" card for RS-Key: its firmware ignores the
phy ENABLED_CURVES tag (curve support is compile-time), so the toggles
were a no-op that also wrote a meaningless tag on save.
- Preserve each status' LED effect/speed on a colour write (read-modify-
write), reject over-long product names, read the enabled USB apps over
the 0xC2 vendor command, and fall back to the USB product string when
the phy record carries no product override.
macOS holds FIDO-usage-page (0xF1D0) HID devices exclusively, so hidapi's
default open fails with 0xE00002C5 ("exclusive access and device already
open") and the entire FIDO transport is unreachable. GetInfo, the VID/PID
seed and hardware-config-over-FIDO then silently fall back to rescue-only,
leaving the Configuration screen blank on an otherwise healthy key.
Enable hidapi's `macos-shared-device` feature so opens go through
hid_darwin_set_open_exclusive(0). No-op on Linux/Windows; hidapi 2.6
explicitly allows several concurrent HidApi contexts.
- Switch `checks` and docs jobs from Nix to dtolnay/rust-toolchain +
Swatinem/rust-cache + apt system deps for faster setup
- Add dependency vulnerability scanning via rustsec/audit-check@v2.0.0
- Add CodeQL static analysis via github/codeql-action@v4 (manual build)
- Reversed transport priority: PCSC/Rescue preferred over FIDO
- Added `RescueCurves` bitflags re-export to `hal/types.rs`
- Replaced single secp256k1 toggle with full "Supported Curves" card
(11 curves) gated on RS-Key, with mask-building in apply_changes
- Updated FIDO/Rescue write status messages to match transport behavior
- Cleaned up device status display (green "Online" for RS-Key)
Changes: src/ui/screens/config/view.rs, view_model.rs, hal/io.rs, hal/transport/mod.rs, hal/types.rs.
- Add //! module-level headers and /// item-level docs to every source file
- Fix unresolved doc links in hal/mod.rs, ui/mod.rs, transport/pcsc.rs, transport/fido.rs
- Add #![deny(missing_docs)] at crate root to enforce doc completeness in CI
- Move HidTransport from hal/fido/hid.rs to hal/transport/fido.rs
- Add PcscTransport in hal/transport/pcsc.rs for CCID communication
- Refactor DeviceHandle::Rescue to hold PcscTransport instead of bare FirmwareType
- Split monolithic rescue/mod.rs into high-level interface and ops.rs with APDU logic
- Rename hal/fido/hid.rs → hal/fido/ops.rs (FidoOperations), depend on transport::fido
- Update FIDO config-write capability checks with more specific trait methods
- Fix all import paths in hal/io.rs and ui/models/device.rs
This commit significantly refactors the HAL layer to introduce proper support for the RS-Key firmware and abstraction across different hardware profiles
(PicoFido, RSKey, LkOne).
Key changes include:
- **Firmware Abstraction**: Added `FirmwareTrait` and `AnyFirmware` in `src/hal/firmwares/mod.rs` with specific implementations for `PicoFidoFirmware` and
`RSKeyFirmware` to decouple hardware-specific logic from the high-level `io.rs` layer.
- **RS-Key FIDO Support**: Implemented RS-Key payload logic in `src/hal/fido/mod.rs` to support reading/writing LED configuration and DEV_CONF directly over
the CTAPHID FIDO transport using TLV and custom command targets.
- **Constants Cleanup**: Stripped out and consolidated 200+ lines of raw CTAP2 constants and vendor opcodes from `src/hal/fido/constants.rs` to clean up the
module.
- **UI & PIN Dialogs**: Updated `src/ui/screens/config/view_model.rs` to route `DeviceMethod` correctly when applying configurations. Added
`StatusDialogHandle` integration to prompt the user for their FIDO PIN and instruct them to "Please touch your device if it flashes" when performing hardware
config writes over FIDO.
- **LkOne Type**: Added the `LkOne` AAGUID and firmware types to the hardware definition tree.
- **Home View Check**: Fixed a UI issue in `home/view.rs` to conditionally display the LED config card based on whether the `FirmwareType` actually supports
FIDO config modifications (like RS-Key).
This lays the architectural foundation needed to handle FIDO configurations dynamically based on the discovered firmware type.