199 Commits
Author SHA1 Message Date
GameTec-liveandGitHub f06efdf815 Merge pull request #413 from nieldk/t55write
T55write
2026-05-08 17:26:51 +02:00
GameTec-liveandGitHub 1a769a0c4a Merge pull request #417 from azuwis/fix-hf-mf-eview
fix: hf mf eview param error due to chunk exceeding 32-block limit
2026-05-07 21:20:58 +02:00
Niel NielsenandGitHub 394781a45f Add files via upload 2026-05-07 20:08:23 +02:00
Niel NielsenandGitHub 36daf7038c Add files via upload 2026-05-07 20:07:23 +02:00
Niel Nielsen f8b0ae6085 FEAT: hf 14a auth-trace 2026-05-07 17:46:53 +02:00
Niel NielsenandGitHub 5c4cf13124 Merge branch 'RfidResearchGroup:main' into t55write 2026-05-07 13:54:35 +02:00
GameTec-liveandGitHub cce9d5b48d Merge pull request #419 from azuwis/fix-hf14a-raw
fix: hf14a_raw should return data bytes, not Response object
2026-05-07 11:24:48 +02:00
Zhong Jianxin d2c1f43a0e fix: hf14a_raw should return data bytes, not Response object
Callers treat the return value as bytes (len(), slicing), but hf14a_raw
was returning the Response object itself, causing TypeError.
2026-05-06 21:05:44 +08:00
Zhong Jianxin 874bb49485 fix: hf mf eview param error due to chunk exceeding 32-block limit
The firmware limits mf1_read_emu_block_data to at most 32 blocks per
request, but eview's chunk_count only honored data_max_length (256).
Added the same 32-block cap already used by esave.
2026-05-06 18:21:47 +08:00
Niel NielsenandGitHub bba432c579 Add files via upload 2026-05-01 20:14:24 +02:00
Niel NielsenandGitHub f7feda5dc9 Add files via upload 2026-05-01 18:45:52 +02:00
Niel NielsenandGitHub 8555f86c22 Merge branch 'RfidResearchGroup:main' into t55write 2026-05-01 17:52:45 +02:00
Niel NielsenandGitHub c63cc16bb5 Add files via upload 2026-05-01 17:50:32 +02:00
GameTec-liveandGitHub e4a6e74b45 Merge pull request #387 from naaraxi/main
Support for changing the wake time in the client
2026-05-01 16:30:25 +02:00
naaraxi 0460d9b95e Support for changing the wake time in the client 2026-05-01 14:36:52 +03:00
GameTec-liveandGitHub d7b8e63966 Merge pull request #406 from nieldk/t55write
hf 14a sniff improvements for nonce collection and crack, fence to catch missing or blocked mfkey binaries
2026-04-30 17:56:42 +02:00
Niel Nielsen 285d81b31e fix: restore executable permission to chameleon_cli_main.py 2026-04-28 20:36:26 +00:00
Niel NielsenandGitHub fc35ce41ba Merge branch 'RfidResearchGroup:main' into t55write 2026-04-28 22:08:46 +02:00
GameTec-liveandGitHub dc4c6fdbb0 Merge pull request #403 from DGinefra/main
Add iOS client "MCT Mifare Chameleon Tool" to compatible applications
2026-04-25 10:38:17 +02:00
GameTec-liveandGitHub 763ea77cbd Merge pull request #379 from andrassmuk/fix/issue-378-mingw-pthread
fix: use native winpthreads for MinGW/MSYS2 Windows builds
2026-04-25 08:02:57 +02:00
Niel NielsenandGitHub de1d9f6c28 T55xx PAC clone
Add lf clone PAC command
2026-04-24 13:21:48 +02:00
Niel NielsenandGitHub ae345c6a59 Fix ADC buffer dimensions in ble_main.c 2026-04-24 11:41:59 +02:00
Niel Nielsen c3fd94ca8c hf 14a sniff, even more descriptive answers 2026-04-23 09:08:23 +02:00
Niel Nielsen 20d6136ee0 hf 14a sniff, more descriptive answers 2026-04-23 08:45:34 +02:00
Niel Nielsen 1e8c36f38c hf 14a sniff improvements for nonce collection and crack, fence to catch missing or blocked mfkey binaries 2026-04-23 07:58:57 +02:00
GameTec-liveandGitHub 75eb389fe9 Merge pull request #401 from nieldk/t55write
T55xx clone
2026-04-19 15:18:46 +02:00
Niel Nielsen 4406788aef BUG: reverted bug that was reintroduced 2026-04-15 14:45:41 +02:00
Niel Nielsen 378c2b302f Various bug fixes 2026-04-15 06:29:10 +02:00
Niel Nielsen 76c961ed59 Added Ultra/Lite guard 2026-04-14 09:45:02 +02:00
Niel Nielsen d70a0dd63f fix hf14a sniff 2026-04-14 09:32:35 +02:00
GameTec-liveandGitHub fb6480f355 doc: Update text in brackets to clarify debug / beta state and iOS only nature 2026-04-13 13:18:17 +02:00
Niel NielsenandGitHub 0ce680b5c7 Refactor LF clone command and update usage examples 2026-04-13 06:39:03 +02:00
Niel NielsenandGitHub 63a465ce9b Fix argument parsing for 'fc' in ioprox 2026-04-12 20:10:36 +02:00
DGinefraandGitHub af8b8f3c5c Add iOS app "Mifare Chameleon Tool" to compatible applications
Hi,

I would like to add my iOS application "Mifare Chameleon Tool" to the list of compatible applications.

App Store link:
https://apps.apple.com/it/app/mifare-chameleon-tool/id6761231484

The app supports BLE communication with Chameleon Ultra.

Thanks!
2026-04-12 17:32:34 +02:00
DGinefraandGitHub c45286d8d1 Add Mifare Chameleon Tool (iOS) to compatible apps 2026-04-12 17:31:32 +02:00
Niel NielsenandGitHub 1a09fbaf0e Merge branch 'RfidResearchGroup:main' into t55write 2026-04-08 13:11:02 +02:00
Niel Nielsen 12284d5f71 Fix: emv scan truncation 2026-04-08 12:36:12 +02:00
GameTec-liveandGitHub 6d30d33aef Merge pull request #357 from fmuk/pr/nfcimport-v2
feat: add Flipper Zero .nfc file importer for MFU/NTAG slots
2026-04-07 20:47:18 +02:00
Niel Nielsen e4dca3fcc4 align with RRG 2026-04-07 10:57:08 +02:00
Niel Nielsen 350a774d7c align with RRG 2026-04-07 10:47:41 +02:00
Niel NielsenandNiel Nielsen 67c1c36212 Clarify exit method behavior with comments
Added comments to clarify behavior of exit method.
2026-04-07 10:36:15 +02:00
Niel NielsenandNiel Nielsen bbfda3070d Fix: T55 write commands help 2026-04-07 10:36:15 +02:00
Niel NielsenandNiel Nielsen e16505e6a7 FEAT! Add T55 write commands 2026-04-07 10:36:06 +02:00
Niel NielsenandNiel Nielsen a3d3c1fc34 Remove conditional compilation for PROJECT_CHAMELEON_ULTRA 2026-04-07 10:29:12 +02:00
Niel NielsenandNiel Nielsen fcf0c31ca5 Fix syntax error in app_cmd.c 2026-04-07 10:29:12 +02:00
Niel NielsenandNiel Nielsen 9183ac40e4 Add PROJECT_CHAMELEON_ULTRA specific commands 2026-04-07 10:28:51 +02:00
Niel NielsenandNiel Nielsen c7e038cc61 Remove duplicate rc522.h include
Removed duplicate rc522.h include and adjusted spacing.
2026-04-07 10:25:13 +02:00
Niel NielsenandNiel Nielsen efa2ea2c7b protocol ISO 14443-4 and emv scan, loading json file from PM3rdv4 2026-04-07 10:23:58 +02:00
Fauzan Mirza dc950c4f60 fix: correct nfcimport class placement after merge 2026-04-07 00:52:07 +02:00
Fauzan Mirza 7931150412 Merge remote-tracking branch 'origin/main' into pr/nfcimport-v2 2026-04-07 00:49:42 +02:00
GameTec-liveandGitHub 93c1e150ab Merge pull request #361 from azuwis/esave
Fix `param error` of `hf mf esave`
2026-04-06 18:30:30 +02:00
GameTec-liveandGitHub 92505b0364 Merge pull request #362 from kevihiiin/pac-emulation
Add LF PAC/Stanley (125kHz) Support
2026-04-06 18:29:46 +02:00
Kevin YuanandGitHub eddbb31c05 Merge branch 'main' into pac-emulation 2026-04-06 16:43:41 +01:00
GameTec-liveandGitHub b77af1e779 Merge pull request #389 from Crazycurly/main
feat(cli): integrate HardNested attack into autopwn
2026-04-04 20:12:31 +02:00
GameTec-liveandGitHub a4b11e441a Merge pull request #388 from taichunmin/usb-serial-number
Fix firmware application USB serial number
2026-04-04 20:09:59 +02:00
Kevin YuanandGitHub 3924ad134b Merge branch 'main' into pac-emulation 2026-04-02 14:17:42 +01:00
GameTec-liveandGitHub 91f2e46bcb Merge pull request #397 from nieldk/feat/lf-data-analysis
feat(data): add LF capture analysis commands
2026-04-02 12:40:10 +02:00
GameTec-liveandGitHub 78e78eb883 Merge pull request #396 from nieldk/feat/hf14a-sniff
feat(hf): add ISO14443A reader frame capture (hf 14a sniff)
2026-04-02 12:32:26 +02:00
Niel NielsenandGitHub 890f316ca0 Merge branch 'main' into feat/lf-data-analysis 2026-04-02 12:09:01 +02:00
GameTec-liveandGitHub 652f341ff9 Merge pull request #399 from nieldk/feat/lf-raw-sniff-v2
feat(lf): add raw LF field ADC capture (lf sniff)
2026-04-02 11:47:06 +02:00
Niel Nielsen d0a8ade9e4 feat(lf): add raw LF field ADC capture (lf sniff) 2026-04-02 11:16:32 +02:00
GameTec-liveandGitHub 0ac25caedc Merge pull request #398 from RfidResearchGroup/revert-395-feat/lf-raw-sniff
Revert "feat(lf): add raw LF field ADC capture (lf sniff)"
2026-04-02 11:09:15 +02:00
GameTec-liveandGitHub 74e2dac27e Revert "feat(lf): add raw LF field ADC capture (lf sniff)" 2026-04-02 11:07:16 +02:00
Niel NielsenandGitHub 27697f9344 Merge branch 'main' into feat/lf-data-analysis 2026-04-02 10:58:20 +02:00
Benjamin MøllerandGitHub dd27081cdf Merge branch 'main' into feat/hf14a-sniff 2026-04-02 10:50:53 +02:00
GameTec-liveandGitHub 4f9cc9ec7c Merge pull request #395 from nieldk/feat/lf-raw-sniff
feat(lf): add raw LF field ADC capture (lf sniff)
2026-04-02 10:44:33 +02:00
Benjamin MøllerandGitHub 3f68690399 Merge branch 'main' into feat/lf-raw-sniff 2026-04-02 10:40:44 +02:00
GameTec-liveandGitHub 88f7fda526 Merge pull request #394 from nieldk/feat/lf-em4x05-reader
feat(lf): add EM4x05/EM4x69 reader (RTF gap protocol)
2026-04-02 09:00:33 +02:00
Niel Nielsen 29c407464b fix: make each PR self-contained with all required source files 2026-04-02 08:14:18 +02:00
Niel Nielsen f65acdd26d fix: make each PR self-contained with all required source files 2026-04-02 08:14:17 +02:00
Niel Nielsen 5daad00953 fix: make each PR self-contained with all required source files 2026-04-02 08:14:16 +02:00
Niel Nielsen 0b6bb28fc1 fix(data): guard Ultra-only includes and processors for Lite build 2026-04-02 08:07:15 +02:00
Niel Nielsen cff829e81c fix(hf): guard Ultra-only includes and processors for Lite build 2026-04-02 08:06:26 +02:00
Niel Nielsen dcad76bf38 fix(lf): guard Ultra-only includes and processors for Lite build 2026-04-02 08:05:33 +02:00
Niel Nielsen 4b88bf57b9 fix(lf): guard Ultra-only includes and processors for Lite build 2026-04-02 08:04:41 +02:00
Niel Nielsen ce932d2e8a feat(data): add LF capture analysis commands 2026-04-02 07:43:16 +02:00
Niel Nielsen 164d450f87 feat(hf): add ISO14443A reader frame capture (hf 14a sniff) 2026-04-02 07:42:26 +02:00
Niel Nielsen 264c2799a7 feat(lf): add raw LF field ADC capture (lf sniff) 2026-04-02 07:41:24 +02:00
Niel Nielsen e02918b867 feat(lf): add EM4x05/EM4x69 reader (RTF gap protocol) 2026-04-02 07:34:16 +02:00
Daniel Wagner a421e99648 request hfxo 2026-03-30 15:37:29 +01:00
Sam 6f4722a964 feat(cli): integrate hardnested attack into autopwn for HardNested vulnerable cards
When autopwn detects a HardNested vulnerable card (nt_level=2) with some known keys,
it now automatically attempts to recover remaining keys using the hardnested attack,
instead of only printing an advisory message. The implementation:

- Iterates over each missing key slot, picking a known key before each attempt
  (allows newly recovered keys to be reused for subsequent targets)
- Invokes hardnested.recover_key() with standard parameters (200 max runs, 3 max attempts)
- After each found key, checks if it is reusable for other sectors
- Falls back to senested attack if hardnested does not recover all keys

This matches the existing behavior for nested and static-encrypted-nested attacks.
2026-03-25 16:30:48 +08:00
Kevin Yuan 9e58461f9a Potential fix: Compare glitch in PWM module 2026-03-24 17:04:18 +00:00
Kevin Yuan ac859f7531 Add PAC/Stanley LF entry 2026-03-24 15:44:12 +00:00
Kevin Yuan f5d721bbfd PAC/Stanley CLI: replace --id with --cn/--raw (PM3 parity)
Split the single --id argument into --cn (8 ASCII chars) and --raw
(32 hex char T55XX bitstream, directly compatible with PM3 raw output).
Add Python-side PAC bitstream encoder/decoder for raw format support.
Output now shows CN and Raw labels matching PM3's format.

Add NRF_LOG module registration to pac.c for debug logging,
consistent with other protocol implementations.

Reassign PAC command IDs (3014/3015) to avoid collision with ioProx
(3010/3011) after rebase onto upstream/main.
2026-03-24 15:04:41 +00:00
Kevin Yuan 69327ded7d Clean up PAC/Stanley CLI: remove debug command, accept ASCII IDs, handle unknown tag types gracefully
- Remove lf pac debug command (development-only)
- Accept both 16-hex and 8-ASCII card ID formats with 7-bit validation
- Add T55xx write command under lf pac write
- Handle unknown TagSpecificType values in slot list without crashing
- Auto-initialize slot data when setting tag type
- Simplify pac_write_to_t55xx by removing unused key parameters
2026-03-24 14:41:22 +00:00
Kevin Yuan ccf4510c1c Improve PAC/Stanley NRZ reader reliability
Three fixes that together bring rapid-fire read reliability from ~20%
to 100%:

- Add MIN_SPIKE_CAP floor (8000) to prevent spike_cap from clipping
  NRZ high when prescan correctly captures NRZ low. Without this,
  spike_cap = raw_min*3 ≈ 2820 collapses the signal range.

- Reorder carrier-before-SAADC in pac_read(): start the 125kHz field
  and wait 10ms before enabling ADC sampling, so prescan calibration
  sees real NRZ signal levels rather than T55XX power-on-reset noise.

- Add auto-recalibration: if no valid frame is found after 20480
  Phase 3 samples (~164ms, ~5 frame periods), reset the decoder to
  Phase 1 and re-calibrate from fresh samples. This gives ~3
  calibration attempts per 500ms scan window instead of just one.

Tested with Proxmark3 sim (15 consecutive rapid-fire reads, 100%) and
T55XX tag (write-read roundtrip + 15x rapid-fire, 100%).
2026-03-24 14:38:46 +00:00
Kevin Yuan 8442bea4c1 Add PAC/Stanley T55XX write support
Add pac_t55xx_writer() for encoding PAC card data into T55XX blocks,
along with the T5577_PAC_CONFIG (NRZ/Direct, RF/32, password-protected,
4 data blocks). Wire DATA_CMD_PAC_WRITE_TO_T55XX (3011) through the
command processor, dispatch table, and Python client.
2026-03-24 14:38:46 +00:00
Kevin Yuan 17ff2abf60 Replace moving average with PM3-style per-sample thresholding and fix integer overflows
Replace the 32-sample moving average + hysteresis demodulation with
Proxmark3-inspired per-sample thresholding and dead zone. This
eliminates ~16 samples of group delay per edge, reducing timing
jitter from ~11 samples to ~2-3 samples.

The new approach:
- Prescan: track raw_min, compute spike_cap (unchanged)
- Warmup: track min/max of clipped samples directly (not averaged)
- Detection: per-sample dead zone classification — sample >= high
  threshold → 1, sample <= low threshold → 0, between → keep
  previous state. Thresholds set at 75% fuzz of signal range.

Removes the avg_buf[32] circular buffer, avg_sum, avg_idx, and
sum-unit threshold/hysteresis state. Struct is 72 bytes smaller.

Widen integer types to prevent overflow UB:
- sample_count: uint16_t -> uint32_t (overflows at 524ms)
- interval, nbits: uint16_t -> uint32_t (matching sample_count width)
2026-03-24 14:38:46 +00:00
Kevin Yuan 2fd1a260cf Add PAC/Stanley LF tag emulation support
Implements NRZ/Direct modulation at RF/32 for PAC/Stanley tag emulation.
The modulator encodes 8-byte ASCII card IDs into 128-bit NRZ frames
(0xFF sync + 12 UART frames) and generates PWM waveforms using constant
output levels (compare=counter_top for HIGH, compare=0 for LOW).

Firmware: modulator in pac.c, load/save/factory callbacks in lf_tag_em,
tag_emulation registration, SET/GET_EMU_ID commands (5006/5007).
CLI: pac_set/get_emu_id methods, 'lf pac econfig' command, hw slot list
display for PAC tags.
2026-03-24 14:38:46 +00:00
Kevin Yuan c494a2cc81 Add PAC/Stanley LF tag reading support
Implements NRZ/Direct modulation decoder for PAC/Stanley 125kHz cards
using SAADC ADC sampling with spike-aware threshold calibration.
The LC antenna produces brief high-amplitude transients at NRZ transitions
which are clipped before the moving-average filter to isolate the actual
data levels.
2026-03-24 14:37:25 +00:00
taichunmin c51051b30e Fix firmware application USB serial number 2026-03-24 00:44:36 +08:00
Fauzan MirzaandClaude Opus 4.6 acb8959117 docs: add nfcimport entry to CHANGELOG
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-21 23:52:35 +01:00
Fauzan MirzaandClaude Opus 4.6 193f66acdd feat: add --amiibo flag to hf mfu nfcimport for PWD/PACK derivation
Real NTAG 215 chips never reveal the stored password over NFC, so
Flipper .nfc dumps always have zeros for pages 133-134 (PWD/PACK).
This causes readers to reject the emulated tag when they attempt
PWD_AUTH as part of their amiibo validation flow.

The --amiibo flag derives the correct PWD from the UID using the
well-known XOR algorithm and sets PACK to the standard 0x8080,
enabling proper authentication with Nintendo devices.

Usage: hf mfu nfcimport -f Kirby.nfc -s 6 --amiibo

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-21 23:52:13 +01:00
Fauzan MirzaandClaude Opus 4.6 a5847c75ef feat: add Flipper Zero .nfc file importer for MFU/NTAG slots
Add `hf mfu nfcimport` command to import Flipper Zero .nfc files
directly into ChameleonUltra emulator slots. Supports NTAG 210/212/
213/215/216, Mifare Ultralight, Ultralight C, and Ultralight EV1.

The importer parses the Flipper .nfc format and configures the slot
with the correct tag type, anti-collision data (UID/ATQA/SAK),
GET_VERSION response, READ_SIG signature, counter values, and full
page data.

Handles NTAG counter index mapping (Flipper's NFC counter index 2
maps to firmware internal index 0) and gracefully skips unsupported
counters with a warning.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-21 23:52:13 +01:00
GameTec-liveandGitHub e5d615d512 Merge pull request #367 from bernadic/feat/ioprox
feat(lf): add ioProx support (read, emulate, clone)
2026-03-20 18:46:07 +01:00
andrassmuk 8e28d1a40e fix: use native winpthreads for MinGW/MSYS2 builds on Windows
The pthreads4w dependency uses MSVC-specific architecture detection
(_M_X64, _M_IX86 macros) which fails under MinGW/MSYS2/ProxSpace
with "unknown not supported in version.rc".

MinGW-w64 ships with winpthreads, so only MSVC builds need pthreads4w.

Fixes #378
2026-03-19 15:06:33 +01:00
Jozef Bernadic e4d70d1417 fix(cmd): resolve ioProx command ID conflict with #362 2026-03-19 08:25:59 +01:00
Jozef Bernadic 76bb091247 docs(changelog): add ioProx entry 2026-03-03 16:58:34 +01:00
Jozef Bernadic 1b6701661d feat(cli): add ioProx commands 2026-03-03 16:24:26 +01:00
Jozef Bernadic 202c6a677e feat(lf): integrate ioProx into LF reader, emulation and T55xx writer pipeline 2026-03-03 16:24:26 +01:00
Jozef Bernadic 36645932de feat(lf): add ioProx support (reader, emulation and T55xx writer) 2026-03-03 16:24:08 +01:00
Jozef Bernadic e1a2f698f4 chore: ignore local IDE files and build artifacts 2026-03-03 15:16:27 +01:00
GameTec-liveandGitHub 7846bca44b Merge pull request #364 from luu176/main
Add `hf mf autopwn` command with key saving and card dump
2026-02-24 18:35:19 +01:00
GameTec-liveandGitHub 7f71201e16 Merge pull request #363 from WillyJL/feat/rgb-marquee-improvements-upstream
New Symmetrical LED Animation Mode and Improved Minimal Mode
2026-02-19 11:57:05 +01:00
Luu dbc8ce0526 autopwn command added 2026-02-18 22:40:38 +01:00
WillyJL 24259f78b9 Update CHANGELOG.md 2026-02-18 20:58:33 +01:00
WillyJL 4bafe186b3 Symmetric animation mode for boot, shutdown, usb 2026-02-18 20:47:56 +01:00
WillyJL 402665cd75 Minimal shutdown and post-flash boot animations 2026-02-18 20:47:55 +01:00
WillyJL 9f25debe4d Fix rgb_marquee_sweep_from_to() to the left 2026-02-18 20:47:55 +01:00
WillyJL f2225767a2 Give useful names to ledblink*() functions 2026-02-18 20:47:54 +01:00
Zhong Jianxin 9d483cdc5e Fix param error of hf mf esave
Step to reproduce:

```
[USB] chameleon --> hf mf esave -f test.bin
API request fail, param error
```

Commit d95112f821 change
NETDATA_MAX_DATA_LENGTH from 512 to 4096, this increase max block count
to 256, while [cmd_processor_mf1_read_emu_block_data][1] hardcode max
block count to 32

[1]: https://github.com/RfidResearchGroup/ChameleonUltra/blob/b108c84af9b473c840ddcae6f769502adb6c5aa5/firmware/application/src/app_cmd.c#L1088
2026-02-17 09:52:59 +08:00
GameTec-liveandGitHub b108c84af9 Merge pull request #355 from LupusE/main
Fix broken CLI after multiple merges
2026-02-07 23:19:22 +01:00
Benjamin Moeller c7aebdf168 Fix Part2, because of multiple PR used the same ID. 2026-02-07 23:16:08 +01:00
Benjamin MøllerandGitHub 643dd03ff6 Update chameleon_enum.py
ReFix, because of link to firmware/application/src/data_cmd.h
2026-02-07 23:12:22 +01:00
Benjamin Moeller fa35c8ae3f fix double value in unique enumeration 2026-02-07 22:59:43 +01:00
Benjamin Moeller 5ee9254012 Delete invalid escape charater in message 2026-02-07 22:58:44 +01:00
GameTec-liveandGitHub dfa2680d51 Merge pull request #201 from rickNmorty2/enh-clone
Add CLI commands to dump and clone tag
2026-02-07 20:47:38 +01:00
GameTec-liveandGitHub d7ae363099 Merge pull request #343 from LupusE/main
Fix compiler error  `a label can only be part of a statement and a de…
2026-02-07 20:44:36 +01:00
GameTec-liveandGitHub 4d3479943f Merge branch 'main' into enh-clone 2026-02-07 20:43:59 +01:00
GameTec-liveandGitHub 38e3567add Merge pull request #306 from merlokk/lf_read_adc
Adds generic ADC read functionality
2026-02-07 20:42:25 +01:00
GameTec-liveandGitHub 2c7c3eeb4d Merge pull request #352 from suut/fix_bad_missing_tools_warning
Fix bad missing tools warning
2026-02-06 23:58:07 +01:00
Benjamin MøllerandGitHub 7a69e68b3f Update nfc_mf0_ntag.c (braces instead of simicolon)
Changed formatting of the fix for a more union layout, as suggested in the comments.
2026-02-06 22:36:02 +01:00
suut 688bb452aa Fix bad missing tools warning 2026-02-06 21:39:19 +01:00
GameTec-liveandGitHub 9ae0755d80 Merge pull request #332 from RickConsole/fix-hidprox-cli-args
fix hidprox UnboundLocalError cli arg error + hidprox slot set warning
2026-02-06 11:19:48 +01:00
GameTec-liveandGitHub 3755bc24ce Merge pull request #307 from azuwis/hf-14a-config
Add `hf 14a config` to deal with badly configured cards
2026-02-06 11:19:23 +01:00
Benjamin MøllerandGitHub 5d2946ffaa Merge branch 'RfidResearchGroup:main' into main 2026-02-04 13:10:05 +01:00
GameTec-liveandGitHub 41937c52a3 Merge pull request #338 from naaraxi/main
Add Electra intercom tag support with slot auto switch
2026-02-03 22:45:19 +01:00
DXLandGitHub db3e53dd08 Merge pull request #346 from YuyangisCoding/main
fix cli arg parser for FIELD_OFF_DO_RESET
2026-02-03 19:16:59 +08:00
Alexandru MazâluandGitHub 35192d9fc1 Merge branch 'RfidResearchGroup:main' into main 2026-02-03 12:49:45 +02:00
GameTec-liveandGitHub c3a35ffd9b Merge pull request #345 from suut/fix_windows_build
Fix Windows build
2026-02-03 05:54:03 +01:00
yuyangzhang eaa366b453 fix cli arg parser for FIELD_OFF_DO_RESET 2026-02-03 12:16:51 +10:00
suut 23181d84f1 Run GitHub actions 2026-02-03 00:34:05 +01:00
Rick ConsoleandGitHub 997f6bcaab Merge branch 'main' into fix-hidprox-cli-args 2026-02-02 15:58:42 -05:00
suut 6e4a564417 Fix typo in CMakeLists.txt 2026-02-02 21:25:14 +01:00
suut f6ac86cc19 Fix missing bswap64 on Windows 2026-02-02 21:22:01 +01:00
suut f1ae0e0bb0 Disable the "deprecated declaration" warning for MSVC build 2026-02-02 20:35:59 +01:00
Benjamin Moeller 54b302356a Fix compiler error a label can only be part of a statement and a declaration is not a statement 2026-02-02 17:00:21 +01:00
DXLandGitHub eeaca1604f Merge pull request #342 from tommiv/cli-field-off-reset
Added FIELD_OFF_DO_RESET support to cli hf mf econfig
2026-02-02 21:29:05 +08:00
Zhong Jianxin b967bdcd98 Add hf 14a config to deal with badly configured cards 2026-02-02 20:48:03 +08:00
Konstantin Ilchenko 613987b4f4 Shortened set_field_off_do_reset to field_off_do_reset CLI flags 2026-02-02 12:21:39 +02:00
Konstantin Ilchenko c1b9df0e5d Added FIELD_OFF_DO_RESET support to cli hf mf econfig 2026-02-02 12:18:26 +02:00
GameTec-liveandGitHub 6686acf714 Merge pull request #314 from dogty/main
Fixed FAST_READ command and handling of dynamic and static locks for …
2026-02-01 15:06:40 +01:00
GameTec-liveandGitHub d303ddb9c7 Merge pull request #316 from brewt/hidprox-hw-slot-list-formatting
Fix HIDProx formatting with `hw slot list`
2026-02-01 15:05:53 +01:00
GameTec-liveandGitHub ef76f794d0 Merge pull request #341 from MusicLeecher/main
Fix typo in hid prox econfig and add ACTProx HID card type
2026-02-01 15:04:37 +01:00
Alexandru MazâluandGitHub d1ad03a567 Merge branch 'RfidResearchGroup:main' into main 2026-01-30 23:57:30 +02:00
GameTec-liveandGitHub 13d0060ed7 Merge pull request #337 from suut/cli_android_support
TCP transport in the CLI to support Android (Termux)
2026-01-30 21:52:20 +01:00
GameTec-liveandGitHub 055ae2322e Merge branch 'main' into cli_android_support 2026-01-30 21:51:46 +01:00
Gabriel Cardoso 2f86756948 fix tipo in previous commint 2026-01-26 19:10:39 +00:00
Gabriel Cardoso 8ed2677ba2 - added ACT Prox HID format 2026-01-26 19:06:34 +00:00
Gabriel Cardoso 71e45a3194 - fix typo in hidprox econfig set/get function 2026-01-26 18:34:06 +00:00
Alexandru Mazalu c1c2b66882 Add Electra intercom tag support with slot auto switch 2026-01-24 14:45:15 +02:00
DXLandGitHub f2bea7d4ea Merge pull request #299 from xianglin1998/main
Fix some bugs & Performance improvement
2026-01-24 19:44:04 +08:00
dxl ca743273af Added cmd for set mf1 config 'field_off_do_reset' 2026-01-24 19:39:49 +08:00
dxl c0e7cb18f7 Export some functions related to mf1 emulation configuration. 2026-01-24 19:38:36 +08:00
dxl a25b4a8b64 Added MF1 configuration to enable/disable resetting NFC peripherals after leaving RF field. 2026-01-24 19:19:35 +08:00
DXLandGitHub 1543bac108 Merge branch 'RfidResearchGroup:main' into main 2026-01-24 17:54:15 +08:00
suut 8f0a9240ba Fix linter errors 2026-01-24 02:09:48 +01:00
suut b10f4ccb25 Fix build on Darwin 2026-01-24 01:59:03 +01:00
suut 0bc8287f14 Better Android detection 2026-01-24 01:48:03 +01:00
suut ec1bd33b5f Add TCP and Android (Termux) support 2026-01-24 01:30:19 +01:00
GameTec-liveandGitHub 53fe83d81a Merge pull request #331 from suut/issue-322__led_bug_after_battery_check
Fix LEDs being stuck on after battery check
2026-01-23 20:36:10 +01:00
GameTec-liveandGitHub 00de9663f3 Merge pull request #315 from brewt/color-string-em-read-fix
Fix error in `lf em 410x read` from color_string()
2026-01-21 22:56:47 +01:00
noprotoandPhilippe Teuwen 1ee7da63b1 Add initial ULCG/USCUID-UL support 2026-01-19 23:29:05 +01:00
Rick Console b272682546 fix hidprox UnboundLocalError cli arg error 2026-01-19 00:09:33 -05:00
suut 6a43ce6e05 Add information to changelog about the battery check 2026-01-18 17:53:29 +01:00
suut 9e7aa3635f Fix LEDs being stuck on after battery check
Signed-off-by: suut <suut@users.noreply.github.com>
2026-01-18 17:51:23 +01:00
dogty 11bafac176 fix(ntag): Check if the dynamic lock page can be written or not (for NTAG215, NTAG213 and NTAG216) 2025-11-03 14:46:37 +01:00
dogty 64f22dfc53 docs: updated changelog 2025-11-01 18:17:10 +01:00
dogty f6cde1629a fix(ntag): CFGLCK bit is checked before to see if CFG0 and CFG1 are writable even if a password is set (only for NTAG215, NTAG216 and NTAG213) 2025-11-01 18:17:09 +01:00
dogty 335ffee69d fix(ntag): The page lock check doesn't take into account the blocking lock bits (only for NTAG213, NTAG215 and NTA216) 2025-11-01 18:17:09 +01:00
dogty 494d397e7b fix(nfc 14a): The fast read command now handles the last block 2025-11-01 18:14:59 +01:00
dogty afacb2a565 fix: handle REQA and WUP commands for NFC tag 14a 2025-11-01 18:14:35 +01:00
Adrian YeeandGitHub efbf79e497 Fix HIDProx formatting with hw slot list
Fix HIDProx formatting to match the formatting of all other card types.
2025-10-30 16:53:33 -07:00
Adrian YeeandGitHub 7efde79235 Fix error in lf em 410x read from color_string()
Fix bug in color_string() usage introduced by 35d2f40 (bug #295).
2025-10-30 16:41:12 -07:00
GameTec-liveandGitHub 97dfe5b9a4 Merge pull request #295 from mischif/color-string
Use a function for colored strings
2025-10-13 21:44:00 +02:00
Oleg Moiseenko f5bed3c5b1 Adjusts LF ADC raw data processing
Adjusts the bit shift for ADC raw data conversion to refine the value range.
2025-10-09 09:42:43 +03:00
Oleg Moiseenko e2c6bfc9e1 Adds generic ADC read functionality
This introduces a new command to sample the ADC values from the LF antenna and returns them to the user.
2025-10-09 00:32:07 +03:00
Jeremy Brown e1b4218bb3 Fixed unnecessary formatting 2025-10-05 15:42:11 -04:00
dxl dabf1a415f Use a more thorough NFC peripheral reset strategy. 2025-09-23 11:08:27 +08:00
dxl 67357feba0 Parameter error should return STATUS_PAR_ERR 2025-09-23 00:56:55 +08:00
dxl 0858e325e5 Fix the bug where HEX printing of large data packets caused it to freeze. 2025-09-23 00:43:17 +08:00
dxl 1e8758bc1f Fixed bug that caused NFC peripheral devices to always respond with incorrect data due to special condition. 2025-09-23 00:38:01 +08:00
dxl 0448a369a3 Fixed a bug where the parameters were abnormal but the subsequent logic was still executed. 2025-09-23 00:33:05 +08:00
dxl d065a2f18e Improve the efficiency of USB packet reception. 2025-09-23 00:32:17 +08:00
Jeremy Brown d440d98d12 Cleaned up follow-up issues 2025-09-19 01:11:46 -04:00
dxl 50f72653db Fix the bug that cannot be compiled on the MSYS2 platform. 2025-09-19 12:45:32 +08:00
GameTec-liveandGitHub 8998621a47 Merge pull request #294 from RocketGod-git/feature/local-changes
Add option for NFC Field Generator
2025-09-12 19:12:27 +02:00
Jeremy Brown 35d2f40ff5 Switched to function for color stings 2025-09-11 11:52:05 -04:00
RocketGod b3b1fa9c71 Update app_main.c 2025-09-06 21:49:46 -07:00
RocketGod 0aacfcde24 Add option for NFC Field Generator
I've integrated the option for the NFC Field Generator into Python CLI and application files. TODO: GUI integration.
2025-09-06 21:46:22 -07:00
you fcbf474e19 Update CHANGELOG.md 2024-04-24 00:50:17 +02:00
you 0686d0816d Fix default ACL (suggested by @taichunmin) 2024-04-24 00:42:33 +02:00
you 4568e8fd57 Fix dump and clone commands accordingly to PR#199 2024-04-24 00:41:13 +02:00
you 6ddda661d8 tosqash 2024-04-23 23:45:13 +02:00
you 7912bde311 Merge branch 'main' of https://github.com/RfidResearchGroup/ChameleonUltra into enh-clone 2024-04-23 23:34:17 +02:00
you 8a02d6f4f8 Add CLI command to clone a MF tag from file (bin/hex) 2024-01-28 17:55:01 +01:00
you a1a49ed953 Add CLI command to dump a MF tag to file (bin/hex) 2024-01-28 17:54:20 +01:00
you 3e6a2b505b Add fchk argument to export found keys to file 2024-01-28 17:48:18 +01:00
taichunmin e470958373 Added command to check keys of multiple sectors at once 2024-01-20 17:25:05 +08:00
66 changed files with 12695 additions and 1416 deletions
+5
View File
@@ -708,3 +708,8 @@ FodyWeavers.xsd
# End of https://www.toptal.com/developers/gitignore/api/visualstudio,c++,c,python,visualstudiocode,macos,windows
software/script/tests/nonces.bin
software/script/nonces.bin
.vscode/settings.json
.vscode/tasks.json
firmware/compile_commands.json
firmware/application/compile_commands.json
software/src/target_arch_detect.c
+18
View File
@@ -3,7 +3,25 @@ All notable changes to this project will be documented in this file.
This project uses the changelog in accordance with [keepchangelog](http://keepachangelog.com/). Please use this to write notable changes, which is not the same as git commit log...
## [unreleased][unreleased]
- Added PAC/Stanley LF protocol support: read, emulate and T55xx clone (@kevihiiin, @danieltwagner)
- Fix firmware application USB serial number (@taichunmin)
- Added ioProx LF protocol support (read, emulate and T55xx clone)
- Added `hf mfu nfcimport` to import Flipper Zero `.nfc` files into MFU/NTAG emulator slots, with `--amiibo` flag for automatic PWD/PACK derivation (@fmuk)
- Added commands to dump and clone Mifare tags
- Fix bad missing tools warning (@suut)
- Fix for FAST_READ command for nfc - mf0 tags
- Rewrite of the dynamic and static locks logic for NTAG213, NTAG215 and NTAG216; we shouldn't take into account the block lock bits
- Fixed an issue where we wouldn't be able to change CFG0 and CFG1 for NTAG213, NTAG215 and NTG216 once a password was added even if the cfg bit was reset.
- Fix for static nested key recovery (@jekkos)
- Fix LEDs being stuck on after battery check (@suut)
- Add TCP support for the CLI (@suut)
- Fix build on Android in Termux (@suut)
- Fix the issue where some reader cause CU to enter a strange state (@xianglin1998)
- The transmission performance of USB has been improved (@xianglin1998)
- Added cmd for set mf1 config 'field_off_do_reset' (@xianglin1998)
- Fix Windows build (@suut)
- Added `hf 14a config` to deal with badly configured cards (@azuwis)
- New Symmetrical LED Animation Mode and Improved Minimal Mode (@WillyJL)
## [v2.1.0][2025-09-02]
- Added UV, formatter and linter. Contribution guidelines. (@GameTec-live)
+2 -1
View File
@@ -26,6 +26,7 @@ Read the [available documentation](https://github.com/RfidResearchGroup/Chameleo
* [ChameleonUltraGUI](https://github.com/GameTec-live/ChameleonUltraGUI)
* [MTools BLE](https://github.com/RfidResearchGroup/ChameleonUltra/wiki/mtoolsble)
* [Mifare Chameleon Tool (iOS only, Beta)](https://apps.apple.com/it/app/mifare-chameleon-tool/id6761231484)
# Videos
@@ -45,4 +46,4 @@ Where do you find the community?
* Devices/chameleon-ultra for usage discussions
* [GameTec_live discord server](https://discord.gg/DJ2A4wxncK)
###### Searching for the docs repo? Find it [here](https://github.com/RfidResearchGroup/ChameleonUltraDocs)
###### Searching for the docs repo? Find it [here](https://github.com/RfidResearchGroup/ChameleonUltraDocs)
+8
View File
@@ -28,6 +28,7 @@ SRC_FILES += \
$(PROJ_DIR)/rfid/nfctag/tag_persistence.c \
$(PROJ_DIR)/rfid/nfctag/hf/crypto1_helper.c \
$(PROJ_DIR)/rfid/nfctag/hf/nfc_14a.c \
$(PROJ_DIR)/rfid/nfctag/hf/nfc_14a_4.c \
$(PROJ_DIR)/rfid/nfctag/hf/nfc_mf1.c \
$(PROJ_DIR)/rfid/nfctag/hf/nfc_mf0_ntag.c \
$(PROJ_DIR)/rfid/nfctag/lf/lf_tag_em.c \
@@ -36,6 +37,8 @@ SRC_FILES += \
$(PROJ_DIR)/rfid/nfctag/lf/utils/manchester.c \
$(PROJ_DIR)/rfid/nfctag/lf/protocols/em410x.c \
$(PROJ_DIR)/rfid/nfctag/lf/protocols/hidprox.c \
$(PROJ_DIR)/rfid/nfctag/lf/protocols/pac.c \
$(PROJ_DIR)/rfid/nfctag/lf/protocols/ioprox.c \
$(PROJ_DIR)/rfid/nfctag/lf/protocols/viking.c \
$(PROJ_DIR)/rfid/nfctag/lf/protocols/wiegand.c \
$(PROJ_DIR)/utils/dataframe.c \
@@ -340,10 +343,15 @@ ifeq (${CURRENT_DEVICE_TYPE}, ${CHAMELEON_ULTRA})
$(PROJ_DIR)/rfid/reader/hf/rc522.c \
$(PROJ_DIR)/rfid/reader/lf/lf_125khz_radio.c \
$(PROJ_DIR)/rfid/reader/lf/lf_em410x_data.c \
$(PROJ_DIR)/rfid/reader/lf/lf_em4x05_data.c \
$(PROJ_DIR)/rfid/reader/lf/lf_gap.c \
$(PROJ_DIR)/rfid/reader/lf/lf_reader_generic.c \
$(PROJ_DIR)/rfid/reader/lf/lf_reader_data.c \
$(PROJ_DIR)/rfid/reader/lf/lf_reader_main.c \
$(PROJ_DIR)/rfid/reader/lf/lf_t55xx_data.c \
$(PROJ_DIR)/rfid/reader/lf/lf_hidprox_data.c \
$(PROJ_DIR)/rfid/reader/lf/lf_pac_data.c \
$(PROJ_DIR)/rfid/reader/lf/lf_ioprox_data.c \
$(PROJ_DIR)/rfid/reader/lf/lf_viking_data.c \
INC_FOLDERS +=\
File diff suppressed because it is too large Load Diff
+189 -38
View File
@@ -41,6 +41,10 @@ NRF_LOG_MODULE_REGISTER();
#include "tag_persistence.h"
#include "settings.h"
#if defined(PROJECT_CHAMELEON_ULTRA)
#include "rc522.h"
#endif
// Defining soft timers
APP_TIMER_DEF(m_button_check_timer); // Timer for button debounce
@@ -56,6 +60,9 @@ static bool m_is_a_btn_release = false;
static bool m_system_off_processing = false;
// NFC field generator state
volatile bool m_is_field_on = false;
// cpu reset reason
static uint32_t m_reset_source;
static uint32_t m_gpregret_val;
@@ -139,12 +146,41 @@ static void gpio_te_init(void) {
APP_ERROR_CHECK(err_code);
}
#if defined(PROJECT_CHAMELEON_ULTRA)
static void field_generator_rainbow_loop(void) {
static uint8_t color_index = 0;
static uint32_t last_update = 0;
if (!m_is_field_on) return;
uint32_t now = app_timer_cnt_get();
if (app_timer_cnt_diff_compute(now, last_update) < APP_TIMER_TICKS(100)) {
return;
}
last_update = now;
// Rainbow colors
const uint8_t colors[] = {RGB_RED, RGB_YELLOW, RGB_GREEN, RGB_CYAN, RGB_BLUE, RGB_MAGENTA};
set_slot_light_color(colors[color_index]);
uint32_t *led_pins = hw_get_led_array();
// Light up all LEDs with current color
for (int i = 0; i < RGB_LIST_NUM; i++) {
nrf_gpio_pin_set(led_pins[i]);
}
color_index = (color_index + 1) % 6;
}
#endif
/**@brief Button Matrix Events
*/
static void button_pin_handler(nrf_drv_gpiote_pin_t pin, nrf_gpiote_polarity_t action) {
device_mode_t mode = get_device_mode();
// Temporarily allow only the analog card mode to respond to button operations
if (mode == DEVICE_MODE_TAG) {
// Allow button operations in both tag and reader mode
if (mode == DEVICE_MODE_TAG || mode == DEVICE_MODE_READER) {
static nrf_drv_gpiote_pin_t pin_static; // Use static internal variables to store the GPIO where the current event occurred
pin_static = pin; // Cache the button that currently triggers the event into an internal variable
app_timer_start(m_button_check_timer, APP_TIMER_TICKS(50), &pin_static); // Start timer anti-shake
@@ -162,7 +198,9 @@ static void timer_button_event_handle(void *arg) {
NRF_LOG_INFO("BUTTON press during shutdown");
return;
}
nrf_drv_gpiote_pin_t pin = *(nrf_drv_gpiote_pin_t *)arg;
// Check here if the current GPIO is at the pressed level
if (nrf_gpio_pin_read(pin) == 1) {
if (pin == BUTTON_1) {
@@ -263,24 +301,28 @@ static void system_off_enter(void) {
for (uint8_t i = 0; i < RGB_LIST_NUM; i++) {
nrf_gpio_pin_clear(p_led_array[i]);
}
// Power off animation
uint8_t animation_config = settings_get_animation_config();
if (animation_config == SettingsAnimationModeFull) {
uint8_t slot = tag_emulation_get_slot();
// Power off animation
uint8_t dir = slot > 3 ? 1 : 0;
uint8_t color = get_color_by_slot(slot);
if (m_reset_source & (NRF_POWER_RESETREAS_NFC_MASK | NRF_POWER_RESETREAS_LPCOMP_MASK)) {
if (m_reset_source & NRF_POWER_RESETREAS_NFC_MASK) {
color = 1;
} else {
color = 2;
}
uint8_t slot = tag_emulation_get_slot();
uint8_t dir = slot > 3 ? 1 : 0;
uint8_t color = get_color_by_slot(slot);
if (m_reset_source & (NRF_POWER_RESETREAS_NFC_MASK | NRF_POWER_RESETREAS_LPCOMP_MASK)) {
if (m_reset_source & NRF_POWER_RESETREAS_NFC_MASK) {
color = 1;
} else {
color = 2;
}
if (m_system_off_processing) ledblink5(color, slot, dir ? 7 : 0);
if (m_system_off_processing) ledblink4(color, dir, 7, 99, 75);
if (m_system_off_processing) ledblink4(color, !dir, 7, 75, 50);
if (m_system_off_processing) ledblink4(color, dir, 7, 50, 25);
if (m_system_off_processing) ledblink4(color, !dir, 7, 25, 0);
}
if (animation_config == SettingsAnimationModeFull) {
if (m_system_off_processing) rgb_marquee_sweep_from_to(color, slot, dir ? 7 : 0);
if (m_system_off_processing) rgb_marquee_sweep_fade(color, dir, 7, 99, 75);
if (m_system_off_processing) rgb_marquee_sweep_fade(color, !dir, 7, 75, 50);
if (m_system_off_processing) rgb_marquee_sweep_fade(color, dir, 7, 50, 25);
if (m_system_off_processing) rgb_marquee_sweep_fade(color, !dir, 7, 25, 0);
} else if (animation_config == SettingsAnimationModeMinimal) {
if (m_system_off_processing) rgb_marquee_sweep_from_to(color, slot, !dir ? 7 : 0);
} else if (animation_config == SettingsAnimationModeSymmetric) {
if (m_system_off_processing) rgb_marquee_symmetric_in(color, slot);
}
rgb_marquee_stop();
if (!m_system_off_processing) {
@@ -422,11 +464,13 @@ static void check_wakeup_src(void) {
// Button wake-up boot animation
uint8_t animation_config = settings_get_animation_config();
if (animation_config == SettingsAnimationModeFull) {
ledblink2(color, !dir, 11);
ledblink2(color, dir, 11);
ledblink2(color, !dir, dir ? slot : 7 - slot);
rgb_marquee_sweep_to(color, !dir, 11);
rgb_marquee_sweep_to(color, dir, 11);
rgb_marquee_sweep_to(color, !dir, dir ? slot : 7 - slot);
} else if (animation_config == SettingsAnimationModeMinimal) {
ledblink2(color, !dir, dir ? slot : 7 - slot);
rgb_marquee_sweep_to(color, !dir, dir ? slot : 7 - slot);
} else if (animation_config == SettingsAnimationModeSymmetric) {
rgb_marquee_symmetric_out(color, slot);
} else {
set_slot_light_color(color);
}
@@ -435,7 +479,7 @@ static void check_wakeup_src(void) {
light_up_by_slot();
// If no operation follows, wait for the timeout and then deep hibernate
sleep_timer_start(SLEEP_DELAY_MS_BUTTON_WAKEUP);
sleep_timer_start(settings_get_sleep_timeout());
} else if ((m_reset_source & (NRF_POWER_RESETREAS_NFC_MASK | NRF_POWER_RESETREAS_LPCOMP_MASK)) ||
(m_gpregret_val & RESET_ON_LF_FIELD_EXISTS_Msk)) {
NRF_LOG_INFO("WakeUp from rfid field");
@@ -459,9 +503,12 @@ static void check_wakeup_src(void) {
uint8_t animation_config = settings_get_animation_config();
if (animation_config == SettingsAnimationModeFull) {
// In the case of field wake-up, only one round of RGB is swept as the power-on animation
ledblink2(color, !dir, dir ? slot : 7 - slot);
rgb_marquee_sweep_to(color, !dir, dir ? slot : 7 - slot);
} else if (animation_config == SettingsAnimationModeSymmetric) {
rgb_marquee_symmetric_out(color, slot);
} else {
set_slot_light_color(color);
}
set_slot_light_color(color);
light_up_by_slot();
// We can only run tag emulation at field wakeup source.
@@ -488,9 +535,20 @@ static void check_wakeup_src(void) {
tag_emulation_factory_init();
// RGB
ledblink2(0, !dir, 11);
ledblink2(1, dir, 11);
ledblink2(2, !dir, 11);
uint8_t animation_config = settings_get_animation_config();
if (animation_config == SettingsAnimationModeFull) {
rgb_marquee_sweep_to(0, !dir, 11);
rgb_marquee_sweep_to(1, dir, 11);
rgb_marquee_sweep_to(2, !dir, 11);
} else if (animation_config == SettingsAnimationModeMinimal) {
rgb_marquee_sweep_from_to(0, 0, 2);
rgb_marquee_sweep_from_to(1, 2, 5);
rgb_marquee_sweep_from_to(2, 5, 7);
} else if (animation_config == SettingsAnimationModeSymmetric) {
rgb_marquee_symmetric_out(0, ~0);
rgb_marquee_symmetric_in(1, ~0);
rgb_marquee_symmetric_out(2, ~0);
}
// Show RGB for slot.
set_slot_light_color(color);
@@ -521,6 +579,12 @@ static void cycle_slot(bool dec) {
}
// Update status only if the new card slot switch is valid
tag_emulation_change_slot(slot_new, true); // Tell the analog card module that we need to switch card slots
// Turn off the LEDs in case we were showing the battery status
rgb_marquee_stop();
uint32_t *led_pins = hw_get_led_array();
for (int i = 0; i < RGB_LIST_NUM; i++) {
nrf_gpio_pin_clear(led_pins[i]);
}
// Go back to the color corresponding to the field enablement type
apply_slot_change(slot_now, slot_new);
}
@@ -603,11 +667,28 @@ static void btn_fn_copy_lf(uint8_t slot, tag_specific_type_t type) {
size = LF_HIDPROX_TAG_ID_SIZE;
data = id_buffer;
break;
case TAG_TYPE_IOPROX:
status = scan_ioprox(id_buffer, 0);
size = LF_IOPROX_TAG_ID_SIZE;
data = id_buffer;
break;
case TAG_TYPE_EM410X:
case TAG_TYPE_EM410X_ELECTRA: {
status = scan_em410x(id_buffer);
size = LF_EM410X_TAG_ID_SIZE;
data = id_buffer + 2; // skip tag type
tag_specific_type_t detected_type = (id_buffer[0] << 8) | id_buffer[1];
tag_specific_type_t new_type =
detected_type == TAG_TYPE_EM410X_ELECTRA ? TAG_TYPE_EM410X_ELECTRA : TAG_TYPE_EM410X;
// If we read Electra but the slot was classic (or vice versa), switch slot type automatically.
if (new_type != type) {
tag_emulation_change_type(slot, new_type);
type = new_type;
}
size = (new_type == TAG_TYPE_EM410X_ELECTRA) ? LF_EM410X_ELECTRA_TAG_ID_SIZE : LF_EM410X_TAG_ID_SIZE;
data = id_buffer + 2; // skip tag type
break;
}
case TAG_TYPE_VIKING:
status = scan_viking(id_buffer);
size = LF_VIKING_TAG_ID_SIZE;
@@ -757,13 +838,67 @@ static void run_button_function_by_settings(settings_button_function_t sbf) {
case SettingsButtonCloneIcUid:
btn_fn_copy_ic_uid();
break;
case SettingsButtonNfcFieldGenerator:
if (!m_is_field_on) {
// Initialize reader hardware if not already in reader mode
device_mode_t current_mode = get_device_mode();
if (current_mode != DEVICE_MODE_READER) {
// Temporarily init reader hardware just for the field
nrf_gpio_cfg_output(READER_POWER);
nrf_gpio_pin_set(READER_POWER); // reader power enable
nrf_gpio_cfg_output(HF_ANT_SEL);
nrf_gpio_pin_clear(HF_ANT_SEL); // hf ant switch to reader mode
pcd_14a_reader_init();
bsp_delay_ms(10);
}
pcd_14a_reader_reset();
pcd_14a_reader_antenna_on();
m_is_field_on = true;
NRF_LOG_INFO("NFC field ON");
// Set initial rainbow state
set_slot_light_color(RGB_RED);
uint32_t *led_pins = hw_get_led_array();
for (int i = 0; i < RGB_LIST_NUM; i++) {
nrf_gpio_pin_set(led_pins[i]);
}
// Stop sleep timer while field is active
NRF_LOG_INFO("Stopping sleep timer for field generator");
sleep_timer_stop();
NRF_LOG_INFO("Sleep timer stopped");
} else {
pcd_14a_reader_antenna_off();
m_is_field_on = false;
NRF_LOG_INFO("NFC field OFF");
// If we're not in reader mode, clean up the hardware
device_mode_t current_mode = get_device_mode();
if (current_mode != DEVICE_MODE_READER) {
pcd_14a_reader_uninit();
nrf_gpio_pin_clear(READER_POWER); // reader power disable
nrf_gpio_pin_set(HF_ANT_SEL); // hf ant switch back to tag mode
}
// Restore normal LED
light_up_by_slot();
// Restart sleep timer
NRF_LOG_INFO("Field off, restarting sleep timer");
sleep_timer_start(SLEEP_DELAY_MS_BUTTON_CLICK);
NRF_LOG_INFO("Sleep timer restarted");
}
break;
#endif
case SettingsButtonShowBattery:
show_battery();
break;
default:
NRF_LOG_ERROR("Unsupported button function")
NRF_LOG_ERROR("Unsupported button function");
break;
}
}
@@ -792,8 +927,10 @@ static void button_press_process(void) {
}
// Disable led marquee for usb at button pressed.
g_usb_led_marquee_enable = false;
// Re-delay into hibernation
sleep_timer_start(SLEEP_DELAY_MS_BUTTON_CLICK);
// Re-delay into hibernation (unless field is on)
if (!m_is_field_on) {
sleep_timer_start(SLEEP_DELAY_MS_BUTTON_CLICK);
}
}
}
@@ -812,12 +949,17 @@ static void blink_usb_led_status(void) {
}
} else {
// The light effect is enabled and can be displayed
if (is_rgb_marquee_enable()) {
if (rgb_marquee_is_enabled()) {
is_working = true;
if (g_usb_port_opened) {
ledblink1(color, dir);
uint8_t animation_config = settings_get_animation_config();
if (animation_config == SettingsAnimationModeSymmetric) {
rgb_marquee_usb_open_symmetric(color);
} else {
rgb_marquee_usb_open_sweep(color, dir);
}
} else {
ledblink6();
rgb_marquee_usb_idle();
}
} else {
if (is_working) {
@@ -887,8 +1029,17 @@ int main(void) {
lesc_event_process();
// Button event process
button_press_process();
// Led blink at usb status
blink_usb_led_status();
#if defined(PROJECT_CHAMELEON_ULTRA)
// Field generator rainbow animation
field_generator_rainbow_loop();
#endif
// Led blink at usb status (only if field generator is off)
if (!m_is_field_on) {
blink_usb_led_status();
}
// Data pack process
data_frame_process();
// Log print process
+5
View File
@@ -19,6 +19,7 @@
/////////////////////////////////////////////////////////////////////
#define STATUS_LF_TAG_OK (0x40) // Some of the low -frequency cards are successful!
#define STATUS_LF_TAG_NO_FOUND (0x41) // Can't search for valid LF tags
#define STATUS_LF_TAG_LOGIN_REQUIRED (0x42) // Tag requires LOGIN before read
/////////////////////////////////////////////////////////////////////
// other status
@@ -31,5 +32,9 @@
#define STATUS_FLASH_WRITE_FAIL (0x70) // Flash writing failed
#define STATUS_FLASH_READ_FAIL (0x71) // Flash read failed
#define STATUS_INVALID_SLOT_TYPE (0x72) // Invalid slot type
#define STATUS_MEM_ERR (0x73) // Can't allocate memory or work with memory error
#define STATUS_CREATE_RESPONSE_ERR (0x74) // Can't create response for command
#define STATUS_CMD_ERR (0x75) // Execution of command failed
#endif
+2 -2
View File
@@ -90,7 +90,7 @@ BLE_ADVERTISING_DEF(m_advertising);
uint16_t batt_lvl_in_milli_volts = 0;
uint8_t percentage_batt_lvl = 0;
static nrf_saadc_value_t adc_buf[ADC_BUF_SIZE][ADC_BUF_COUNT];
static nrf_saadc_value_t adc_buf[ADC_BUF_COUNT][ADC_BUF_SIZE];
static uint16_t m_conn_handle = BLE_CONN_HANDLE_INVALID; /**< Handle of the current connection. */
static uint16_t m_ble_nus_max_data_len = BLE_GATT_ATT_MTU_DEFAULT - 3; /**< Maximum length of data (in bytes) that can be transmitted to the peer by the Nordic UART service module. */
lf_adc_callback_t m_lf_adc_callback = NULL;
@@ -806,4 +806,4 @@ void unregister_lf_adc_callback(void) {
nrfx_saadc_uninit();
adc_configure();
m_lf_adc_callback = NULL;
}
}
+40
View File
@@ -46,6 +46,8 @@
#define DATA_CMD_GET_BLE_PAIRING_ENABLE (1036)
#define DATA_CMD_SET_BLE_PAIRING_ENABLE (1037)
#define DATA_CMD_GET_ALL_SLOT_NICKS (1038)
#define DATA_CMD_GET_SLEEP_TIMEOUT (1039)
#define DATA_CMD_SET_SLEEP_TIMEOUT (1040)
//
// ******************************************************************
@@ -67,12 +69,21 @@
#define DATA_CMD_MF1_READ_ONE_BLOCK (2008)
#define DATA_CMD_MF1_WRITE_ONE_BLOCK (2009)
#define DATA_CMD_HF14A_RAW (2010)
#define DATA_CMD_HF14A_SCAN_KEEP (2016) /* scan+RATS, keep field alive for APDU exchange */
#define DATA_CMD_HF14A_AUTH_TRACE (2017) /* full anticoll + Crypto1 auth, every frame returned for inspection */
#define DATA_CMD_MF1_MANIPULATE_VALUE_BLOCK (2011)
#define DATA_CMD_MF1_CHECK_KEYS_OF_SECTORS (2012)
#define DATA_CMD_MF1_HARDNESTED_ACQUIRE (2013)
#define DATA_CMD_MF1_ENC_NESTED_ACQUIRE (2014)
#define DATA_CMD_MF1_CHECK_KEYS_ON_BLOCK (2015)
#define DATA_CMD_HF14A_SET_FIELD_ON (2100)
#define DATA_CMD_HF14A_SET_FIELD_OFF (2101)
#define DATA_CMD_HF14A_GET_CONFIG (2200)
#define DATA_CMD_HF14A_SET_CONFIG (2201)
#define DATA_CMD_HF14A_SNIFF (2020)
//
// ******************************************************************
@@ -84,10 +95,21 @@
//
#define DATA_CMD_EM410X_SCAN (3000)
#define DATA_CMD_EM410X_WRITE_TO_T55XX (3001)
#define DATA_CMD_EM410X_ELECTRA_WRITE_TO_T55XX (3006)
#define DATA_CMD_HIDPROX_SCAN (3002)
#define DATA_CMD_HIDPROX_WRITE_TO_T55XX (3003)
#define DATA_CMD_PAC_SCAN (3014)
#define DATA_CMD_PAC_WRITE_TO_T55XX (3015)
#define DATA_CMD_VIKING_SCAN (3004)
#define DATA_CMD_VIKING_WRITE_TO_T55XX (3005)
#define DATA_CMD_ADC_GENERIC_READ (3009)
#define DATA_CMD_GENERIC_READ (3007)
#define DATA_CMD_CORR_GENERIC_READ (3008)
#define DATA_CMD_IOPROX_SCAN (3010)
#define DATA_CMD_IOPROX_WRITE_TO_T55XX (3011)
#define DATA_CMD_IOPROX_DECODE_RAW (3012)
#define DATA_CMD_IOPROX_COMPOSE_ID (3013)
#define DATA_CMD_LF_T55XX_WRITE (3016)
//
// ******************************************************************
@@ -136,6 +158,8 @@
#define DATA_CMD_MF0_NTAG_GET_DETECTION_LOG (4035)
#define DATA_CMD_MF0_NTAG_GET_DETECTION_ENABLE (4036)
#define DATA_CMD_MF0_NTAG_GET_EMULATOR_CONFIG (4037)
#define DATA_CMD_MF1_SET_FIELD_OFF_DO_RESET (4038)
#define DATA_CMD_MF1_GET_FIELD_OFF_DO_RESET (4039)
//
// ******************************************************************
@@ -148,11 +172,27 @@
//
// ******************************************************************
/* ISO14443-4 T=CL emulation commands */
#define DATA_CMD_HF14A_4_APDU_RECV (6000) /* non-blocking poll: firmware->host APDU */
#define DATA_CMD_HF14A_4_APDU_SEND (6001) /* host->firmware APDU response */
#define DATA_CMD_HF14A_4_SET_ANTI_COLL (6002) /* set UID/ATQA/SAK/ATS */
#define DATA_CMD_HF14A_4_STATIC_RESP (6003) /* add/clear static APDU response pair */
#define DATA_CMD_HF14A_4_READER_APDU (6004) /* select+RATS+send APDU, keep field */
#define DATA_CMD_HF14A_4_EMV_SCAN (6005) /* full EMV scan in one call */
#define DATA_CMD_EM410X_SET_EMU_ID (5000)
#define DATA_CMD_EM410X_GET_EMU_ID (5001)
#define DATA_CMD_HIDPROX_SET_EMU_ID (5002)
#define DATA_CMD_HIDPROX_GET_EMU_ID (5003)
#define DATA_CMD_VIKING_SET_EMU_ID (5004)
#define DATA_CMD_VIKING_GET_EMU_ID (5005)
#define DATA_CMD_PAC_SET_EMU_ID (5006)
#define DATA_CMD_PAC_GET_EMU_ID (5007)
#define DATA_CMD_IOPROX_SET_EMU_ID (5008)
#define DATA_CMD_IOPROX_GET_EMU_ID (5009)
#define DATA_CMD_EM4X05_SCAN (3030)
#define DATA_CMD_EM4X05_READSNIFF (3032)
#define DATA_CMD_LF_SNIFF (3031)
#endif
@@ -59,9 +59,42 @@ const uint16_t ats_fsdi_table[] = {
static volatile bool m_is_responded = false;
// Receiving buffer
static uint8_t m_nfc_rx_buffer[MAX_NFC_RX_BUFFER_SIZE] = { 0x00 };
/* Optional sniff callback — fires for every received frame */
static nfc_tag_14a_sniff_cb_t m_sniff_cb = NULL;
void nfc_tag_14a_set_sniff_cb(nfc_tag_14a_sniff_cb_t cb) {
m_sniff_cb = cb;
}
void nfc_tag_14a_clear_sniff_cb(void) {
m_sniff_cb = NULL;
}
/* TX sniff: captures card→reader frames at TX_FRAMESTART */
static nfc_tag_14a_tx_sniff_cb_t m_tx_sniff_cb = NULL;
void nfc_tag_14a_set_tx_sniff_cb(nfc_tag_14a_tx_sniff_cb_t cb) {
m_tx_sniff_cb = cb;
}
void nfc_tag_14a_clear_tx_sniff_cb(void) {
m_tx_sniff_cb = NULL;
}
/* Passive sniff mode: suppress all tag TX responses so the CU does not
* participate in anticollision and avoids colliding with the real card. */
static bool m_sniff_passive = false;
void nfc_tag_14a_set_sniff_passive(bool passive) {
m_sniff_passive = passive;
}
static uint8_t m_nfc_tx_buffer[MAX_NFC_TX_BUFFER_SIZE] = { 0x00 };
// The N -secondary connection needs to use SAK, when the "third 'bit' in SAK is 1 is 1, the logo UID is incomplete
static uint8_t m_uid_incomplete_sak[] = { 0x04, 0xda, 0x17 };
static uint8_t m_uid_incomplete_sak[] = { 0x04, 0xda, 0x17 };
// Reset nfc peripheral after field lost?
static bool reset_if_field_lost = false; // default is 'false', Unless there is a genuine need for a reset.
/**
* @brief Calculate BCC
@@ -323,6 +356,11 @@ void nfc_tag_14a_data_process(uint8_t *p_data) {
// Because of this error receiving event caused by this possible interference
return;
}
/* Sniff hook — fire before any tag response logic */
if (m_sniff_cb != NULL) {
m_sniff_cb(p_data, szDataBits);
}
// Manually draw frame, separate data and strange school inspection
#if !NFC_TAG_14A_RX_PARITY_AUTO_DEL_ENABLE
if (szDataBits >= 9) {
@@ -347,9 +385,11 @@ void nfc_tag_14a_data_process(uint8_t *p_data) {
if (auto_coll_res != NULL) {
// The status machine is set to the preparation state, and the next operation is to enter the card selection link
m_tag_state_14a = NFC_TAG_STATE_14A_READY;
// After receiving the WUPA or REQA instruction, we need to reply to ATQA
nfc_tag_14a_tx_bytes(auto_coll_res->atqa, 2, false);
// NRF_LOG_INFO("ATQA reply.");
if (!m_sniff_passive) {
// After receiving the WUPA or REQA instruction, we need to reply to ATQA
nfc_tag_14a_tx_bytes(auto_coll_res->atqa, 2, false);
// NRF_LOG_INFO("ATQA reply: %02x%02x", auto_coll_res->atqa[0], auto_coll_res->atqa[1]);
}
} else {
m_tag_state_14a = NFC_TAG_STATE_14A_IDLE;
NRF_LOG_INFO("Auto anti-collision resource no exists.");
@@ -397,6 +437,15 @@ void nfc_tag_14a_data_process(uint8_t *p_data) {
m_tag_state_14a = NFC_TAG_STATE_14A_IDLE;
}
return;
case NFC_TAG_14A_CMD_REQA:
case NFC_TAG_14A_CMD_WUPA:
// Reader is re-sending REQA/WUPA while in READY state
// This can happen if reader retries or if frame was received incorrectly
// Respond with ATQA again and stay in READY state
if (auto_coll_res != NULL) {
nfc_tag_14a_tx_bytes(auto_coll_res->atqa, 2, false);
}
return;
default: {
// After receiving the wrong level instruction, directly reset the status machine
NRF_LOG_INFO("[MFEMUL_SELECT] Incorrect cascade level received: %02x", p_data[0]);
@@ -456,7 +505,9 @@ void nfc_tag_14a_data_process(uint8_t *p_data) {
}
// Incoming SELECT ALL for any cascade level
if (szDataBits == 16 && p_data[1] == 0x20) {
nfc_tag_14a_tx_bytes(uid, 5, false);
if (!m_sniff_passive) {
nfc_tag_14a_tx_bytes(uid, 5, false);
}
// NRF_LOG_INFO("[MFEMUL_SELECT] SEL Reply.");
break;
}
@@ -470,10 +521,14 @@ void nfc_tag_14a_data_process(uint8_t *p_data) {
if (cl_finished) {
// NRF_LOG_INFO("[MFEMUL_SELECT] m_tag_state_14a = MFEMUL_WORK");
m_tag_state_14a = NFC_TAG_STATE_14A_ACTIVE;
nfc_tag_14a_tx_bytes(auto_coll_res->sak, 1, true);
if (!m_sniff_passive) {
nfc_tag_14a_tx_bytes(auto_coll_res->sak, 1, true);
}
} else {
// It is necessary to continue the level, so we need to respond to a data that marks the incomplete UID in SAK
nfc_tag_14a_tx_bytes(m_uid_incomplete_sak, 3, false);
if (!m_sniff_passive) {
nfc_tag_14a_tx_bytes(m_uid_incomplete_sak, 3, false);
}
}
} else {
// IDLE, not our UID
@@ -499,6 +554,10 @@ void nfc_tag_14a_data_process(uint8_t *p_data) {
}
// RATS instruction
if (p_data[0] == NFC_TAG_14A_CMD_RATS && nfc_tag_14a_checks_crc(p_data, 4)) {
// Reset T=CL layer state for the new session
if (m_tag_handler.cb_reset != NULL) {
m_tag_handler.cb_reset();
}
// Make sure the sub -packaging opens the support of ATS
if (auto_coll_res->ats->length > 0) {
// Take out FSD and return according to the maximum FSD
@@ -523,6 +582,42 @@ void nfc_tag_14a_data_process(uint8_t *p_data) {
}
}
// Copy from nrf_nfct.c and modified for nrf52840 adapted(no verify on nrf52832)
static inline void nrf_nfct_reset(void) {
uint32_t fdm;
uint32_t int_enabled;
// Save parameter settings before the reset of the NFCT peripheral.
fdm = nrf_nfct_frame_delay_max_get();
int_enabled = nrf_nfct_int_enable_get();
// Reset the NFCT peripheral.
*(volatile uint32_t *)0x40005FFC = 0;
*(volatile uint32_t *)0x40005FFC;
*(volatile uint32_t *)0x40005FFC = 1;
// Restore parameter settings after the reset of the NFCT peripheral.
nrf_nfct_frame_delay_max_set(fdm);
// Use Window Grid frame delay mode.
nrf_nfct_frame_delay_mode_set(NRF_NFCT_FRAME_DELAY_MODE_WINDOWGRID);
/* Use SDD00001 per ISO14443-3 standard.
* Note: SDD00100 was previously used for Windows Phone compatibility
* but breaks standard readers (including Proxmark3). SDD00001 is correct. */
nrf_nfct_sensres_bit_frame_sdd_set(NRF_NFCT_SENSRES_BIT_FRAME_SDD_00001);
// Restore interrupts.
nrf_nfct_int_enable(int_enabled);
// Disable interrupts associated with data exchange.
nrf_nfct_int_disable(NRF_NFCT_INT_RXFRAMESTART_MASK |
NRF_NFCT_INT_RXFRAMEEND_MASK |
NRF_NFCT_INT_RXERROR_MASK |
NRF_NFCT_INT_TXFRAMESTART_MASK |
NRF_NFCT_INT_TXFRAMEEND_MASK);
}
static inline void nfc_fdt_reset(void) {
// STOP TX
*(volatile uint32_t *)0x40005010 = 0x01;
@@ -571,12 +666,31 @@ void nfc_tag_14a_event_callback(nrfx_nfct_evt_t const *p_event) {
TAG_FIELD_LED_OFF()
m_tag_state_14a = NFC_TAG_STATE_14A_IDLE;
if (reset_if_field_lost) {
// Fix a bug where certain special conditions prevent triggering TX start events and actually transmit incorrect data to the card reader.
// After more more more testing, I found that simply going into sleep mode and restarting can restore work.
// Therefore, I suspect that there may be some issues with the NFC peripheral that require a reset to resolve.
nrf_nfct_reset();
}
NRF_LOG_INFO("HF FIELD LOST");
break;
}
case NRFX_NFCT_EVT_TX_FRAMESTART: {
// NRF_LOG_INFO("TX start.\n");
// NRF_LOG_INFO("TX config is %d.\n", nrf_nfct_tx_frame_config_get(NRF_NFCT));
if (m_tx_sniff_cb != NULL) {
uint32_t amt = NRF_NFCT->TXD.AMOUNT;
uint16_t tx_bytes = (amt >> NFCT_TXD_AMOUNT_TXDATABYTES_Pos)
& (NFCT_TXD_AMOUNT_TXDATABYTES_Msk >> NFCT_TXD_AMOUNT_TXDATABYTES_Pos);
uint16_t tx_bits_rem = (amt >> NFCT_TXD_AMOUNT_TXDATABITS_Pos)
& (NFCT_TXD_AMOUNT_TXDATABITS_Msk >> NFCT_TXD_AMOUNT_TXDATABITS_Pos);
uint16_t tx_bits = (tx_bits_rem > 0)
? ((tx_bytes - 1) * 8 + tx_bits_rem)
: (tx_bytes * 8);
if (tx_bits > 0 && tx_bytes <= MAX_NFC_TX_BUFFER_SIZE) {
m_tx_sniff_cb(m_nfc_tx_buffer, tx_bits);
}
}
break;
}
case NRFX_NFCT_EVT_TX_FRAMEEND: {
@@ -688,3 +802,11 @@ bool is_valid_uid_size(uint8_t uid_length) {
uid_length == NFC_TAG_14A_UID_DOUBLE_SIZE ||
uid_length == NFC_TAG_14A_UID_TRIPLE_SIZE;
}
void nfc_tag_14a_set_reset_enable(bool enable) {
reset_if_field_lost = enable;
}
bool nfc_tag_14a_is_reset_enable() {
return reset_if_field_lost;
}
@@ -4,7 +4,7 @@
#include "tag_emulation.h"
#define MAX_NFC_RX_BUFFER_SIZE 257
#define MAX_NFC_TX_BUFFER_SIZE 64
#define MAX_NFC_TX_BUFFER_SIZE 512 /* must hold PCB + max APDU response */
#define NFC_TAG_14A_CRC_LENGTH 2
@@ -82,6 +82,27 @@ typedef struct {
// Communication reception function that needs to be implemented
typedef void (*nfc_tag_14a_reset_handler_t)(void);
/* Sniff callback — called for every received frame before the tag handler.
* data : raw frame bytes (after parity strip)
* szBits : number of bits received */
typedef void (*nfc_tag_14a_sniff_cb_t)(const uint8_t *data, uint16_t szBits);
void nfc_tag_14a_set_sniff_cb(nfc_tag_14a_sniff_cb_t cb);
void nfc_tag_14a_clear_sniff_cb(void);
/* TX sniff callback — fires at TX_FRAMESTART with the frame the tag is about
* to send (cardreader direction). Same signature as the RX sniff callback.
* Install alongside nfc_tag_14a_set_sniff_cb() to capture both directions. */
typedef void (*nfc_tag_14a_tx_sniff_cb_t)(const uint8_t *data, uint16_t szBits);
void nfc_tag_14a_set_tx_sniff_cb(nfc_tag_14a_tx_sniff_cb_t cb);
void nfc_tag_14a_clear_tx_sniff_cb(void);
/* Passive sniff mode: when true, suppresses all CU anticollision responses
* (ATQA, UID, SAK) so the CU does not collide with real cards in the field.
* Enable before starting a sniff session, disable on completion. */
void nfc_tag_14a_set_sniff_passive(bool passive);
typedef void (*nfc_tag_14a_state_handler_t)(uint8_t *data, uint16_t szBits);
typedef nfc_tag_14a_coll_res_reference_t *(*nfc_tag_14a_coll_handler_t)(void);
@@ -115,4 +136,8 @@ void nfc_tag_14a_tx_nbit(uint8_t data, uint32_t bits);
// Determine whether it is an effective UID length
bool is_valid_uid_size(uint8_t uid_length);
// Reset nfc peripheral after field lost
void nfc_tag_14a_set_reset_enable(bool enable);
bool nfc_tag_14a_is_reset_enable();
#endif
@@ -0,0 +1,446 @@
/**
* @file nfc_14a_4.c
* @brief ISO14443-4 T=CL emulation for ChameleonUltra
*
* Implements a full ISO14443-4 tag emulator with a static APDU response
* table. The table is populated by the host before field activation, so
* the firmware can respond to an EMV reader autonomously without any USB
* communication while the RF field is active.
*
* SPDX-License-Identifier: GPL-2.0-or-later
*/
#include <string.h>
#include "nfc_14a_4.h"
#include "nfc_14a.h"
#include "tag_emulation.h"
#include "tag_persistence.h"
#include "fds_util.h"
#include "nrf_log.h"
/* ------------------------------------------------------------------ */
/* PCB byte constants (ISO14443-4 §7) */
/* ------------------------------------------------------------------ */
#define PCB_IBLOCK_MASK 0xC0
#define PCB_IBLOCK_VAL 0x00
#define PCB_RBLOCK_MASK 0xE0
#define PCB_RBLOCK_VAL 0x80 /* R(ACK) = 0xA2/0xA3, R(NAK) = 0xB2/0xB3 */
#define PCB_SBLOCK_MASK 0xC0
#define PCB_SBLOCK_VAL 0xC0
#define PCB_BLOCK_NUM 0x01
#define PCB_CID_FOLLOWING 0x10 /* bit4: CID follows */
#define PCB_NAD_FOLLOWING 0x08 /* bit3: NAD follows */
#define PCB_CHAIN 0x20 /* bit5: chaining flag per ISO14443-4 Table 3 */
#define PCB_SBLOCK_WTX 0x30
#define PCB_SBLOCK_DESELECT 0xC2
#define WTX_VALUE 0x3B /* WTXM=59 (~3s extra wait) */
static inline bool is_iblock(uint8_t pcb) {
return (pcb & PCB_IBLOCK_MASK) == PCB_IBLOCK_VAL;
}
static inline bool is_rblock(uint8_t pcb) {
/* R-block: bit7=1, bit6=0, bit2=1, bit1=0 (mask 0xC6, value 0x82) */
return (pcb & 0xC6) == 0x82;
}
static inline bool is_sblock(uint8_t pcb) {
return (pcb & PCB_SBLOCK_MASK) == PCB_SBLOCK_VAL;
}
/* ------------------------------------------------------------------ */
/* Module state */
/* ------------------------------------------------------------------ */
static nfc_tag_14a_4_information_t *m_tag_information = NULL;
/* Shadow coll-res references into m_tag_information */
static nfc_tag_14a_coll_res_reference_t m_shadow_coll_res;
/* T=CL session state */
static uint8_t m_block_num = 0;
static bool m_cid_supported = false;
static uint8_t m_cid = 0;
static uint8_t m_apdu_buf[NFC_14A_4_MAX_APDU];
static uint16_t m_apdu_len = 0;
static bool m_apdu_pending = false;
static uint8_t m_resp_buf[NFC_14A_4_MAX_APDU];
static uint16_t m_resp_len = 0;
static bool m_response_ready = false;
/* TX scratch buffer */
static uint8_t m_tx_buf[NFC_14A_4_MAX_APDU + 4];
/* Debug counters — readable via hf 14a debug */
static uint8_t m_dbg_iblocks_rx = 0; /* I-blocks received */
static uint8_t m_dbg_iblocks_tx = 0; /* I-blocks sent */
static uint8_t m_dbg_last_rx_pcb = 0; /* PCB of last received I-block */
static uint8_t m_dbg_last_match = 0; /* last find_static_response result */
/* Static APDU response table (RAM copy, populated from m_tag_information) */
static nfc_tag_14a_4_static_response_t m_static_resp[NFC_14A_4_MAX_STATIC_RESPONSES];
static uint8_t m_static_resp_count = 0;
/* Large response overflow (RAM only, > NFC_14A_4_MAX_STATIC_RESP_LEN bytes).
* NOT persisted to flash. Must reload via emv load after power cycle. */
typedef struct {
uint8_t cmd[NFC_14A_4_MAX_STATIC_CMD_LEN];
uint8_t cmd_len;
uint8_t resp[NFC_14A_4_MAX_LARGE_RESP_LEN];
uint16_t resp_len;
} nfc_tag_14a_4_large_response_t;
static nfc_tag_14a_4_large_response_t m_large_resp[NFC_14A_4_MAX_LARGE_RESPONSES];
static uint8_t m_large_resp_count = 0;
/* ------------------------------------------------------------------ */
/* Static response table */
/* ------------------------------------------------------------------ */
void nfc_tag_14a_4_add_static_response(const uint8_t *cmd, uint8_t cmd_len,
const uint8_t *resp, uint16_t resp_len) {
if (cmd_len > NFC_14A_4_MAX_STATIC_CMD_LEN) cmd_len = NFC_14A_4_MAX_STATIC_CMD_LEN;
if (resp_len > NFC_14A_4_MAX_STATIC_RESP_LEN) {
/* Large response: RAM-only overflow table */
if (m_large_resp_count >= NFC_14A_4_MAX_LARGE_RESPONSES) return;
if (resp_len > NFC_14A_4_MAX_LARGE_RESP_LEN) resp_len = NFC_14A_4_MAX_LARGE_RESP_LEN;
nfc_tag_14a_4_large_response_t *le = &m_large_resp[m_large_resp_count++];
le->cmd_len = cmd_len;
le->resp_len = resp_len;
memcpy(le->cmd, cmd, cmd_len);
memcpy(le->resp, resp, resp_len);
return;
}
/* Normal response: flash-backed table */
if (m_static_resp_count >= NFC_14A_4_MAX_STATIC_RESPONSES) return;
nfc_tag_14a_4_static_response_t *e = &m_static_resp[m_static_resp_count++];
e->cmd_len = cmd_len;
e->resp_len = (uint8_t)resp_len;
memcpy(e->cmd, cmd, cmd_len);
memcpy(e->resp, resp, resp_len);
if (m_tag_information &&
m_tag_information->static_resp_count < NFC_14A_4_MAX_STATIC_RESPONSES) {
memcpy(&m_tag_information->static_resp[m_tag_information->static_resp_count++],
e, sizeof(*e));
}
}
void nfc_tag_14a_4_clear_static_responses(void) {
m_static_resp_count = 0;
m_large_resp_count = 0;
if (m_tag_information) {
m_tag_information->static_resp_count = 0;
}
}
static bool find_static_response(const uint8_t *apdu, uint16_t apdu_len,
uint8_t **resp_out, uint16_t *resp_len_out) {
/* Flash-backed table */
for (uint8_t i = 0; i < m_static_resp_count; i++) {
nfc_tag_14a_4_static_response_t *e = &m_static_resp[i];
if (apdu_len >= e->cmd_len &&
memcmp(apdu, e->cmd, e->cmd_len) == 0) {
*resp_out = e->resp;
*resp_len_out = e->resp_len;
return true;
}
}
/* RAM-only large response table */
for (uint8_t i = 0; i < m_large_resp_count; i++) {
nfc_tag_14a_4_large_response_t *e = &m_large_resp[i];
if (apdu_len >= e->cmd_len &&
memcmp(apdu, e->cmd, e->cmd_len) == 0) {
*resp_out = e->resp;
*resp_len_out = e->resp_len;
return true;
}
}
return false;
}
/* ------------------------------------------------------------------ */
/* TX helpers */
/* ------------------------------------------------------------------ */
static void send_iblock(const uint8_t *data, uint16_t len) {
uint8_t pcb = 0x02 | (m_block_num & 0x01);
if (m_cid_supported) pcb |= PCB_CID_FOLLOWING;
uint8_t off = 0;
m_tx_buf[off++] = pcb;
if (m_cid_supported) m_tx_buf[off++] = m_cid & 0x0F;
if (len > NFC_14A_4_MAX_APDU) len = NFC_14A_4_MAX_APDU;
memcpy(&m_tx_buf[off], data, len);
nfc_tag_14a_tx_bytes(m_tx_buf, off + len, true);
m_block_num ^= 1;
}
static void send_rack(void) {
uint8_t pcb = 0xA2 | (m_block_num & 0x01);
if (m_cid_supported) {
pcb |= PCB_CID_FOLLOWING;
uint8_t buf[2] = { pcb, m_cid & 0x0F };
nfc_tag_14a_tx_bytes(buf, 2, true);
} else {
nfc_tag_14a_tx_bytes(&pcb, 1, true);
}
}
static void send_wtx(void) {
uint8_t buf[3];
uint8_t off = 0;
buf[off++] = PCB_SBLOCK_WTX | (m_cid_supported ? PCB_CID_FOLLOWING : 0);
if (m_cid_supported) buf[off++] = m_cid & 0x0F;
buf[off++] = WTX_VALUE;
nfc_tag_14a_tx_bytes(buf, off, true);
}
/* ------------------------------------------------------------------ */
/* State handler (called from NFCT ISR on each received frame) */
/* ------------------------------------------------------------------ */
static void nfc_tag_14a_4_state_handler(uint8_t *data, uint16_t szBytes) {
if (szBytes == 0) return;
uint8_t pcb = data[0];
/* ---- S-block ---- */
if (is_sblock(pcb)) {
if ((pcb & 0xF7) == PCB_SBLOCK_DESELECT) {
/* Echo DESELECT */
nfc_tag_14a_tx_bytes(data, szBytes, true);
nfc_tag_14a_4_reset_handler();
return;
}
if ((pcb & 0x3F) == (PCB_SBLOCK_WTX & 0x3F)) {
/* Reader sending WTX — echo back with our WTXM */
uint8_t wtxm = (szBytes > 1) ? data[szBytes - 1] & 0x3F : WTX_VALUE;
uint8_t resp[3];
uint8_t off = 0;
resp[off++] = PCB_SBLOCK_WTX | (m_cid_supported ? PCB_CID_FOLLOWING : 0);
if (m_cid_supported) resp[off++] = m_cid & 0x0F;
resp[off++] = wtxm;
nfc_tag_14a_tx_bytes(resp, off, true);
/* If we now have a response ready, send it next I-block */
if (m_response_ready) {
m_response_ready = false;
send_iblock(m_resp_buf, m_resp_len);
}
return;
}
return;
}
/* ---- R-block ---- */
if (is_rblock(pcb)) {
send_rack();
return;
}
/* ---- I-block ---- */
if (is_iblock(pcb)) {
uint8_t reader_blknum = pcb & PCB_BLOCK_NUM;
bool has_cid = (pcb & PCB_CID_FOLLOWING) != 0;
bool has_nad = (pcb & PCB_NAD_FOLLOWING) != 0;
bool more_chain = (pcb & PCB_CHAIN) != 0;
uint8_t offset = 1;
if (has_cid) {
/* CID acknowledged but not used in responses (keeps protocol simpler) */
m_cid_supported = false;
offset++; /* skip CID byte */
}
if (has_nad) offset++;
if (offset >= szBytes) {
send_rack();
return;
}
uint16_t apdu_len = szBytes - offset;
if (apdu_len > NFC_14A_4_MAX_APDU) apdu_len = NFC_14A_4_MAX_APDU;
m_dbg_iblocks_rx++;
m_dbg_last_rx_pcb = pcb;
NRF_LOG_INFO("14A4 I-block #%d: reader_blk=%d m_block_num=%d apdu_len=%d",
m_dbg_iblocks_rx, reader_blknum, m_block_num, apdu_len);
/* Block number check per ISO14443-4 §7.5.3.3:
* If block number matches expected, process new APDU.
* If block number does NOT match, it is a retransmit
* resend the last response without re-processing. */
if (reader_blknum != (m_block_num & 0x01)) {
/* Retransmit: resend last response */
if (m_resp_len > 0) {
/* Restore block num to what we sent last time and resend */
m_block_num ^= 1; /* undo the increment from last send */
send_iblock(m_resp_buf, m_resp_len);
} else {
send_rack();
}
return;
}
memcpy(m_apdu_buf, &data[offset], apdu_len);
m_apdu_len = apdu_len;
m_apdu_pending = true;
m_response_ready = false;
if (more_chain) {
send_rack();
return;
}
/* APDU complete — check static table first, then WTX */
{
uint8_t *static_resp = NULL;
uint16_t static_len = 0;
bool _found = find_static_response(m_apdu_buf, apdu_len,
&static_resp, &static_len);
m_dbg_last_match = _found ? 1 : 0;
NRF_LOG_INFO("14A4 find_static: found=%d static_len=%d resp_count=%d",
_found, static_len, m_static_resp_count);
if (_found) {
m_dbg_iblocks_tx++;
memcpy(m_resp_buf, static_resp, static_len);
m_resp_len = static_len;
send_iblock(m_resp_buf, m_resp_len);
} else if (m_response_ready) {
m_response_ready = false;
send_iblock(m_resp_buf, m_resp_len);
} else {
/* No response ready — keep reader alive with WTX */
send_wtx();
}
}
return;
}
NRF_LOG_INFO("14A-4: unknown PCB 0x%02x", pcb);
}
/* ------------------------------------------------------------------ */
/* APDU relay API (for host-driven responses) */
/* ------------------------------------------------------------------ */
bool nfc_tag_14a_4_get_pending_apdu(uint8_t *buf, uint16_t *length) {
if (!m_apdu_pending) return false;
m_apdu_pending = false;
*length = m_apdu_len;
memcpy(buf, m_apdu_buf, m_apdu_len);
return true;
}
void nfc_tag_14a_4_set_response(const uint8_t *data, uint16_t length) {
if (length > NFC_14A_4_MAX_APDU) length = NFC_14A_4_MAX_APDU;
memcpy(m_resp_buf, data, length);
m_resp_len = length;
m_response_ready = true;
}
/* ------------------------------------------------------------------ */
/* Reset handler */
/* ------------------------------------------------------------------ */
void nfc_tag_14a_4_reset_handler(void) {
m_block_num = 0;
m_cid_supported = false;
m_cid = 0;
m_apdu_pending = false;
m_response_ready = false;
m_apdu_len = 0;
m_resp_len = 0;
}
void nfc_tag_14a_4_get_debug_counters(uint8_t *rx, uint8_t *tx,
uint8_t *last_pcb, uint8_t *last_match) {
*rx = m_dbg_iblocks_rx;
*tx = m_dbg_iblocks_tx;
*last_pcb = m_dbg_last_rx_pcb;
*last_match = m_dbg_last_match;
}
/* ------------------------------------------------------------------ */
/* Anti-collision resource */
/* ------------------------------------------------------------------ */
nfc_tag_14a_coll_res_reference_t *nfc_tag_14a_4_get_coll_res(void) {
if (m_tag_information == NULL) return NULL;
m_shadow_coll_res.sak = m_tag_information->res_coll.sak;
m_shadow_coll_res.atqa = m_tag_information->res_coll.atqa;
m_shadow_coll_res.uid = m_tag_information->res_coll.uid;
m_shadow_coll_res.size = &m_tag_information->res_coll.size;
m_shadow_coll_res.ats = &m_tag_information->res_coll.ats;
return &m_shadow_coll_res;
}
/* ------------------------------------------------------------------ */
/* Data load / save / factory callbacks */
/* ------------------------------------------------------------------ */
int nfc_tag_14a_4_data_loadcb(tag_specific_type_t type, tag_data_buffer_t *buffer) {
int info_size = sizeof(nfc_tag_14a_4_information_t);
if (buffer->length < info_size) {
NRF_LOG_ERROR("14A-4 loadcb: buffer too small (%d < %d)",
buffer->length, info_size);
return info_size;
}
m_tag_information = (nfc_tag_14a_4_information_t *)buffer->buffer;
/* Populate RAM static table from persisted slot data */
m_static_resp_count = m_tag_information->static_resp_count;
if (m_static_resp_count > NFC_14A_4_MAX_STATIC_RESPONSES)
m_static_resp_count = NFC_14A_4_MAX_STATIC_RESPONSES;
memcpy(m_static_resp, m_tag_information->static_resp,
m_static_resp_count * sizeof(nfc_tag_14a_4_static_response_t));
nfc_tag_14a_handler_t handler = {
.get_coll_res = nfc_tag_14a_4_get_coll_res,
.cb_state = nfc_tag_14a_4_state_handler,
.cb_reset = nfc_tag_14a_4_reset_handler,
};
nfc_tag_14a_set_handler(&handler);
NRF_LOG_INFO("14A-4 loadcb OK: SAK=%02x uid_sz=%d static_resp=%d",
m_tag_information->res_coll.sak[0],
m_tag_information->res_coll.size,
m_static_resp_count);
return info_size;
}
int nfc_tag_14a_4_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buffer) {
return sizeof(nfc_tag_14a_4_information_t);
}
bool nfc_tag_14a_4_data_factory(uint8_t slot, tag_specific_type_t tag_type) {
if (tag_type != TAG_TYPE_HF14A_4) return false;
/* Build factory defaults on stack and write directly to FDS
* (same pattern as nfc_tag_mf1_data_factory). */
nfc_tag_14a_4_information_t info;
memset(&info, 0, sizeof(info));
/* Placeholder 7-byte NXP-style UID */
info.res_coll.size = NFC_TAG_14A_UID_DOUBLE_SIZE;
info.res_coll.atqa[0] = 0x04;
info.res_coll.atqa[1] = 0x00;
info.res_coll.sak[0] = 0x20; /* ISO14443-4 */
info.res_coll.uid[0] = 0x04;
info.res_coll.uid[1] = 0x01;
info.res_coll.uid[2] = 0x02;
info.res_coll.uid[3] = 0x03;
info.res_coll.uid[4] = 0x04;
info.res_coll.uid[5] = 0x05;
info.res_coll.uid[6] = 0x06;
static const uint8_t default_ats[] = {
0x10, 0x78, 0x80, 0x70, 0x02, 0x00,
0x31, 0xC1, 0x64, 0x09, 0x97, 0x61,
0x26, 0x00, 0x90, 0x00
};
info.res_coll.ats.length = sizeof(default_ats);
memcpy(info.res_coll.ats.data, default_ats, sizeof(default_ats));
info.static_resp_count = 0;
fds_slot_record_map_t map_info;
get_fds_map_by_slot_sense_type_for_dump(slot, TAG_SENSE_HF, &map_info);
bool ret = fds_write_sync(map_info.id, map_info.key, sizeof(info), &info);
NRF_LOG_INFO("14A-4 factory slot %d: %s", slot, ret ? "OK" : "FAIL");
return ret;
}
@@ -0,0 +1,71 @@
/**
* @file nfc_14a_4.h
* @brief ISO14443-4 T=CL emulation for ChameleonUltra
*
* Implements a full ISO14443-4 tag emulator:
* - I-blocks (information, chaining, CID)
* - R-blocks (ACK/NAK retransmit)
* - S-blocks (WTX to keep reader alive, DESELECT)
* - Static APDU response table (pre-loaded before field, no USB needed
* during field exchange)
*
* SPDX-License-Identifier: GPL-2.0-or-later
*/
#ifndef NFC_14A_4_H
#define NFC_14A_4_H
#include "nfc_14a.h"
#include "tag_emulation.h"
/* Maximum APDU size (FSCI=8 → FSC=256, minus PCB+CRC = 253) */
#define NFC_14A_4_MAX_APDU 260 /* max APDU in RAM; flash entries capped at 253 */
/* Static APDU response table — up to 12 pre-configured command/response pairs.
* Loaded before field activation; firmware responds autonomously without USB. */
#define NFC_14A_4_MAX_STATIC_RESPONSES 12
#define NFC_14A_4_MAX_LARGE_RESPONSES 4 /* RAM-only, for resp > 253 bytes */
#define NFC_14A_4_MAX_LARGE_RESP_LEN 260 /* max large response size */
#define NFC_14A_4_MAX_STATIC_CMD_LEN 16
#define NFC_14A_4_MAX_STATIC_RESP_LEN 253 /* max bytes in flash-backed slot */
typedef struct __attribute__((packed)) {
uint8_t cmd_len;
uint8_t cmd[NFC_14A_4_MAX_STATIC_CMD_LEN];
uint8_t resp_len;
uint8_t resp[NFC_14A_4_MAX_STATIC_RESP_LEN];
} nfc_tag_14a_4_static_response_t;
/**
* Per-slot persistent data layout stored in FDS flash.
* Anti-collision response (UID/ATQA/SAK/ATS) plus the static response table.
*/
typedef struct __attribute__((packed)) {
nfc_tag_14a_coll_res_entity_t res_coll;
uint8_t static_resp_count;
nfc_tag_14a_4_static_response_t static_resp[NFC_14A_4_MAX_STATIC_RESPONSES];
} nfc_tag_14a_4_information_t;
/* Anti-collision resource — used by get_coll_res_data in app_cmd.c */
nfc_tag_14a_coll_res_reference_t *nfc_tag_14a_4_get_coll_res(void);
/* tag_base_map callbacks */
int nfc_tag_14a_4_data_loadcb(tag_specific_type_t type, tag_data_buffer_t *buffer);
int nfc_tag_14a_4_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buffer);
bool nfc_tag_14a_4_data_factory(uint8_t slot, tag_specific_type_t tag_type);
/* Static response table management (called before hw mode -e) */
void nfc_tag_14a_4_add_static_response(const uint8_t *cmd, uint8_t cmd_len,
const uint8_t *resp, uint16_t resp_len);
void nfc_tag_14a_4_clear_static_responses(void);
/* APDU relay — host-driven responses */
bool nfc_tag_14a_4_get_pending_apdu(uint8_t *buf, uint16_t *length);
void nfc_tag_14a_4_set_response(const uint8_t *data, uint16_t length);
/* Reset handler */
void nfc_tag_14a_4_reset_handler(void);
#endif /* NFC_14A_4_H */
void nfc_tag_14a_4_get_debug_counters(uint8_t *rx, uint8_t *tx, uint8_t *last_pcb, uint8_t *last_match);
@@ -675,29 +675,50 @@ static void handle_fast_read_command(uint8_t block_num, uint8_t end_block_num) {
int block_max = get_block_max_by_tag_type(m_tag_type, true);
if (block_num >= end_block_num || end_block_num >= block_max) {
if (block_num > end_block_num || end_block_num >= block_max) {
nfc_tag_14a_tx_nbit(NAK_INVALID_OPERATION_TBV, 4);
return;
}
NRF_LOG_INFO("HANDLING FAST READ %02x %02x", block_num, end_block_num);
handle_any_read(block_num, end_block_num - block_num, block_max);
// FAST_READ is inclusive: read from block_num to end_block_num (both included)
handle_any_read(block_num, end_block_num - block_num + 1, block_max);
}
static bool check_ro_lock_on_page(int block_num) {
if (block_num < 3) return true;
else if (block_num == 3) return (m_tag_information->memory[2][2] & 9) != 0; // bits 0 and 3
else if (block_num <= MF0ICU1_PAGES) {
else if (block_num == 3) {
switch (m_tag_type) {
case TAG_TYPE_NTAG_213:
case TAG_TYPE_NTAG_215:
case TAG_TYPE_NTAG_216:
//page 3 can be locked or not independant of BL CC bit
//the BL bit only freezes the lock bytes !
return (m_tag_information->memory[2][2] & 8) != 0;
default:
return (m_tag_information->memory[2][2] & 9) != 0;
}
// bits 0 and 3
} else if (block_num <= MF0ICU1_PAGES) {
bool locked = false;
switch (m_tag_type) {
case TAG_TYPE_NTAG_213:
case TAG_TYPE_NTAG_215:
case TAG_TYPE_NTAG_216: {
// pages can be locked or not independant of BL bits
//the BL bits only freezes the lock bytes !
uint16_t lock_bits = *(uint16_t *)&m_tag_information->memory[2][2];
return ((lock_bits >> block_num) & 0x01) == 1;
}
default:
// check block locking bits
if (block_num <= 9) locked |= (m_tag_information->memory[2][2] & 2) == 2;
else locked |= (m_tag_information->memory[2][2] & 4) == 4;
// check block locking bits
if (block_num <= 9) locked |= (m_tag_information->memory[2][2] & 2) == 2;
else locked |= (m_tag_information->memory[2][2] & 4) == 4;
locked |= (((*(uint16_t *)&m_tag_information->memory[2][2]) >> block_num) & 1) == 1;
locked |= (((*(uint16_t *)&m_tag_information->memory[2][2]) >> block_num) & 1) == 1;
return locked;
return locked;
}
} else {
uint8_t *p_lock_bytes = NULL;
int user_memory_end = 0;
@@ -776,9 +797,42 @@ static bool check_ro_lock_on_page(int block_num) {
bool locked_small_range = ((lock_word >> (index / dyn_lock_bit_page_cnt)) & 1) != 0;
bool locked_large_range = ((p_lock_bytes[2] >> (index / dyn_lock_bit_page_cnt / 2)) & 1) != 0;
return locked_small_range | locked_large_range;
switch (m_tag_type) {
case TAG_TYPE_NTAG_213:
case TAG_TYPE_NTAG_215:
case TAG_TYPE_NTAG_216:
// For NTAG213/215/216: byte 2 contains block-locking bits (BL) which only freeze
// the lock configuration. We only check the actual lock bits (L0-L15) in bytes 0-1.
return locked_small_range;
default:
return locked_small_range | locked_large_range;
}
} else {
//Check the block locking bits to see if we can touch the dynamic locks bytes for NTAG tags
if(block_num == user_memory_end)
{
switch (m_tag_type) {
case TAG_TYPE_NTAG_213:
case TAG_TYPE_NTAG_215:
case TAG_TYPE_NTAG_216: {
uint8_t block_bytes = m_tag_information->memory[user_memory_end][2];
uint16_t block_world = 0;
// Each bit in block_bytes maps to 2 bits in block_world
for (int i = 0; i < 8; i++) {
if (block_bytes & (0x01 << i)) {
block_world |= (0x0003 << (i * 2));
}
}
p_lock_bytes = m_tag_information->memory[user_memory_end];
uint16_t lock_word = (((uint16_t)p_lock_bytes[1]) << 8) | (uint16_t)p_lock_bytes[0];
return (lock_word & block_world) != 0;
}
default:
break;
}
}
// check CFGLCK bit
int first_cfg_page = get_first_cfg_page_by_tag_type(m_tag_type);
uint8_t access = m_tag_information->memory[first_cfg_page + CONF_ACCESS_PAGE_OFFSET][CONF_ACCESS_BYTE];
@@ -793,7 +847,26 @@ static bool check_ro_lock_on_page(int block_num) {
static int handle_write_command(uint8_t block_num, uint8_t *p_data) {
int block_max = get_block_max_by_tag_type(m_tag_type, false);
if (block_num >= block_max) {
bool out_of_bounds = false;
switch (m_tag_type) {
case TAG_TYPE_NTAG_213:
case TAG_TYPE_NTAG_215:
case TAG_TYPE_NTAG_216: {
int first_cfg_page = get_first_cfg_page_by_tag_type(m_tag_type);
uint8_t cfglck = m_tag_information->memory[first_cfg_page][0] & 0x40;
// For NTAG cards we need to check CFGLCK bit for config pages
bool is_config_page = (block_num >= first_cfg_page) && (block_num <= first_cfg_page + 1);
bool config_locked = (cfglck != 0) && (!m_tag_information->config.mode_uid_magic);
bool is_beyond_user_memory = (block_num >= block_max);
out_of_bounds = (is_beyond_user_memory && !is_config_page) || (config_locked && is_config_page);
break;
}
default:
out_of_bounds = block_num >= block_max;
break;
}
// Reject out-of-bounds writes (except config pages)
if (out_of_bounds) {
NRF_LOG_ERROR("Write failed: block_num %08x >= block_max %08x", block_num, block_max);
return NAK_INVALID_OPERATION_TBV;
}
@@ -1111,6 +1111,8 @@ int nfc_tag_mf1_data_loadcb(tag_specific_type_t type, tag_data_buffer_t *buffer)
.cb_reset = nfc_tag_mf1_reset_handler,
};
nfc_tag_14a_set_handler(&handler_for_14a);
NRF_LOG_INFO("HF mf1 config 'field_off_do_reset' = %d", m_tag_information->config.field_off_do_reset);
nfc_tag_14a_set_reset_enable(m_tag_information->config.field_off_do_reset);
NRF_LOG_INFO("HF mf1 data load finish.");
} else {
NRF_LOG_ERROR("nfc_tag_mf1_information_t too big.");
@@ -1157,6 +1159,12 @@ bool nfc_tag_mf1_data_factory(uint8_t slot, tag_specific_type_t tag_type) {
p_mf1_information->config.use_mf1_coll_res = false;
p_mf1_information->config.mode_block_write = NFC_TAG_MF1_WRITE_NORMAL;
p_mf1_information->config.detection_enable = false;
p_mf1_information->config.field_off_do_reset = false;
// zero for reserved byte
p_mf1_information->config.reserved1 = 0x00;
p_mf1_information->config.reserved2 = 0x00;
p_mf1_information->config.reserved3 = 0x00;
// save data to flash
tag_sense_type_t sense_type = get_sense_type_from_tag_type(tag_type);
@@ -1236,3 +1244,10 @@ nfc_tag_mf1_write_mode_t nfc_tag_mf1_get_write_mode(void) {
return m_tag_information->config.mode_block_write;
}
void nfc_tag_mf1_set_field_off_do_reset(bool enable) {
m_tag_information->config.field_off_do_reset = enable;
}
bool nfc_tag_mf1_is_field_off_do_reset(void) {
return m_tag_information->config.field_off_do_reset;
}
@@ -71,8 +71,15 @@ typedef struct {
uint8_t detection_enable: 1;
// Allow to write block 0 (CUID/gen2 mode)
uint8_t mode_gen2_magic: 1;
// reserve
uint8_t reserved1: 4;
/**
* Should the NFC peripheral be reset after losing the RF field?
* This configuration can fix the issue where some card readers cause the CU to enter a strange state of no response/incorrect response.
* Once in this state, the device must be restarted to resolve the issue.
* Alternatively, enabling this configuration for resetting the NFC after leaving the rf field can also solve the aforementioned problem.
*/
uint8_t field_off_do_reset: 1;
// reserved
uint8_t reserved1: 3;
uint8_t reserved2;
uint8_t reserved3;
} nfc_tag_mf1_configure_t;
@@ -157,6 +164,7 @@ void nfc_tag_mf1_set_use_mf1_coll_res(bool enable);
bool nfc_tag_mf1_is_use_mf1_coll_res(void);
void nfc_tag_mf1_set_write_mode(nfc_tag_mf1_write_mode_t write_mode);
nfc_tag_mf1_write_mode_t nfc_tag_mf1_get_write_mode(void);
void nfc_tag_mf1_set_field_off_do_reset(bool enable);
bool nfc_tag_mf1_is_field_off_do_reset(void);
#endif
@@ -5,10 +5,13 @@
#include "bsp_delay.h"
#include "fds_util.h"
#include "nrf_gpio.h"
#include "nrf_soc.h"
#include "nrfx_lpcomp.h"
#include "nrfx_pwm.h"
#include "protocols/em410x.h"
#include "protocols/hidprox.h"
#include "protocols/ioprox.h"
#include "protocols/pac.h"
#include "protocols/viking.h"
#include "syssleep.h"
#include "tag_emulation.h"
@@ -21,7 +24,6 @@
NRF_LOG_MODULE_REGISTER();
#define ANT_NO_MOD() nrf_gpio_pin_clear(LF_MOD)
#define LF_125KHZ_BROADCAST_MAX (10)
// Whether the USB light effect is allowed to enable
extern bool g_usb_led_marquee_enable;
@@ -40,7 +42,8 @@ static void lf_field_lost(void) {
g_is_tag_emulating = false; // Reset the flag in the emulation
m_is_lf_emulating = false;
TAG_FIELD_LED_OFF() // Make sure the indicator light of the LF field status
NRF_LPCOMP->INTENSET = LPCOMP_INTENCLR_CROSS_Msk | LPCOMP_INTENCLR_UP_Msk | LPCOMP_INTENCLR_DOWN_Msk | LPCOMP_INTENCLR_READY_Msk;
// Re-arm LPCOMP so the next field appearance triggers lpcomp_event_handler.
NRF_LPCOMP->INTENSET = LPCOMP_INTENSET_UP_Msk;
// call sleep_timer_start *after* unsetting g_is_tag_emulating
sleep_timer_start(SLEEP_DELAY_MS_FIELD_125KHZ_LOST); // Start the timer to enter the sleep
NRF_LOG_INFO("LF FIELD LOST");
@@ -65,12 +68,15 @@ bool is_lf_field_exists(void) {
* priority is set to APP_IRQ_PRIORITY_HIGH).
*/
static void lpcomp_event_handler(nrf_lpcomp_event_t event) {
// Only when the lf -frequency emulation is not launched, and the analog card is started
// Only when the lf-frequency emulation is not launched, and the analog card is started
if (m_is_lf_emulating || event != NRF_LPCOMP_EVENT_UP) {
return;
}
sleep_timer_stop(); // turn off dormant delay
// Disable LPCOMP during emulation — LF_RSSI fluctuates during load
// modulation and would trigger spurious DOWN events with DETECT_CROSS.
// Field-loss is checked periodically via EVT_END_SEQ0 in pwm_handler.
nrfx_lpcomp_disable();
// set the emulation status logo bit
@@ -83,8 +89,9 @@ static void lpcomp_event_handler(nrf_lpcomp_event_t event) {
set_slot_light_color(RGB_BLUE);
TAG_FIELD_LED_ON()
// use precise hardware timer to broadcast card id
nrfx_pwm_simple_playback(&m_broadcast, m_pwm_seq, LF_125KHZ_BROADCAST_MAX, NRFX_PWM_FLAG_STOP);
// Loop continuously — no stop/restart gaps between sequence plays.
// Field-loss is detected in pwm_handler via EVT_END_SEQ0.
nrfx_pwm_simple_playback(&m_broadcast, m_pwm_seq, 1, NRFX_PWM_FLAG_LOOP);
NRF_LOG_INFO("LF FIELD DETECTED");
}
@@ -101,21 +108,23 @@ static void lpcomp_init(void) {
}
static void pwm_handler(nrfx_pwm_evt_type_t event_type) {
if (event_type == NRFX_PWM_EVT_END_SEQ0) {
// Fired at end of each loop iteration — check field without stopping PWM.
// Mask UP interrupt while sampling to prevent re-entrancy.
NRF_LPCOMP->INTENCLR = LPCOMP_INTENCLR_UP_Msk;
if (!is_lf_field_exists()) {
// Field gone — stop the loop; pwm_handler will get EVT_STOPPED next.
nrfx_pwm_stop(&m_broadcast, false);
}
// Re-enable will happen either in lf_field_lost (via INTENSET) or stays
// suppressed while PWM keeps looping (we only need it after field_lost).
return;
}
if (event_type != NRFX_PWM_EVT_STOPPED) {
return;
}
// after last broadcast, force NO_MOD on antenna to measure field.
ANT_NO_MOD();
bsp_delay_ms(1);
// We don't need any events, but only need to detect the state of the field
NRF_LPCOMP->INTENCLR = LPCOMP_INTENCLR_CROSS_Msk | LPCOMP_INTENCLR_UP_Msk | LPCOMP_INTENCLR_DOWN_Msk | LPCOMP_INTENCLR_READY_Msk;
if (is_lf_field_exists()) {
nrfx_lpcomp_disable();
nrfx_pwm_simple_playback(&m_broadcast, m_pwm_seq, LF_125KHZ_BROADCAST_MAX, NRFX_PWM_FLAG_STOP);
} else {
lf_field_lost();
}
lf_field_lost();
}
static void pwm_init(void) {
@@ -135,6 +144,23 @@ static void pwm_init(void) {
}
static void lf_sense_enable(void) {
// PWM bit timing divides HFCLK by a fixed ratio. On HFINT (64 MHz RC,
// ±1.5% at 25°C after factory trim, wider over temperature) this gives a
// chip-to-chip spread that NRZ readers — which see cumulative error across
// runs of same-polarity bits with no intra-run resync — reject even when
// Manchester/FSK readers don't. Holding HFXO brings the PWM clock to
// ±40 ppm. We can't lock to the reader's carrier (tag-mode antenna taps
// on this board are envelope-only), so this is as good as it gets.
//
// Paired release in lf_sense_disable(). SD reference-counts HFXO requests,
// so this coexists with BLE. Both functions run from thread context
// (tag_mode_enter/tag_emulation_sense_end) where SVCs are safe.
sd_clock_hfclk_request();
uint32_t hfclk_running = 0;
while (!hfclk_running) {
sd_clock_hfclk_is_running(&hfclk_running);
}
lpcomp_init();
pwm_init(); // use precise hardware pwm to broadcast card id
if (is_lf_field_exists()) {
@@ -147,6 +173,7 @@ static void lf_sense_disable(void) {
nrfx_lpcomp_uninit();
m_pwm_seq = NULL;
m_is_lf_emulating = false;
sd_clock_hfclk_release();
}
static enum {
@@ -155,6 +182,10 @@ static enum {
LF_SENSE_STATE_ENABLE,
} m_lf_sense_state = LF_SENSE_STATE_NONE;
static uint16_t lf_em410x_id_size(tag_specific_type_t type) {
return type == TAG_TYPE_EM410X_ELECTRA ? LF_EM410X_ELECTRA_TAG_ID_SIZE : LF_EM410X_TAG_ID_SIZE;
}
/**
* @brief switchLfFieldInductionToEnableTheState
*/
@@ -182,13 +213,14 @@ void lf_tag_125khz_sense_switch(bool enable) {
int lf_tag_data_loadcb(tag_specific_type_t type, tag_data_buffer_t *buffer) {
// ensure buffer size is large enough for specific tag type,
// so that tag data (e.g., card numbers) can be converted to corresponding pwm sequence here.
if (type == TAG_TYPE_EM410X && buffer->length >= LF_EM410X_TAG_ID_SIZE) {
if ((type == TAG_TYPE_EM410X || type == TAG_TYPE_EM410X_ELECTRA) && buffer->length >= lf_em410x_id_size(type)) {
const protocol *p = type == TAG_TYPE_EM410X_ELECTRA ? &em410x_electra : &em410x_64;
m_tag_type = type;
void *codec = em410x_64.alloc();
m_pwm_seq = em410x_64.modulator(codec, buffer->buffer);
em410x_64.free(codec);
NRF_LOG_INFO("load lf em410x data finish.");
return LF_EM410X_TAG_ID_SIZE;
void *codec = p->alloc();
m_pwm_seq = p->modulator(codec, buffer->buffer);
p->free(codec);
NRF_LOG_INFO("load lf em410x%s data finish.", type == TAG_TYPE_EM410X_ELECTRA ? " electra" : "");
return lf_em410x_id_size(type);
}
if (type == TAG_TYPE_HID_PROX && buffer->length >= LF_HIDPROX_TAG_ID_SIZE) {
@@ -200,6 +232,15 @@ int lf_tag_data_loadcb(tag_specific_type_t type, tag_data_buffer_t *buffer) {
return LF_HIDPROX_TAG_ID_SIZE;
}
if (type == TAG_TYPE_IOPROX && buffer->length >= LF_IOPROX_TAG_ID_SIZE) {
m_tag_type = type;
void *codec = ioprox.alloc();
m_pwm_seq = ioprox.modulator(codec, buffer->buffer);
ioprox.free(codec);
NRF_LOG_INFO("load lf ioprox data finish.");
return LF_IOPROX_TAG_ID_SIZE;
}
if (type == TAG_TYPE_VIKING && buffer->length >= LF_VIKING_TAG_ID_SIZE) {
m_tag_type = type;
void *codec = viking.alloc();
@@ -209,6 +250,15 @@ int lf_tag_data_loadcb(tag_specific_type_t type, tag_data_buffer_t *buffer) {
return LF_VIKING_TAG_ID_SIZE;
}
if (type == TAG_TYPE_PAC && buffer->length >= LF_PAC_TAG_ID_SIZE) {
m_tag_type = type;
void *codec = pac.alloc();
m_pwm_seq = pac.modulator(codec, buffer->buffer);
pac.free(codec);
NRF_LOG_INFO("load lf pac data finish.");
return LF_PAC_TAG_ID_SIZE;
}
NRF_LOG_ERROR("no valid data exists in buffer for tag type: %d.", type);
return 0;
}
@@ -221,7 +271,13 @@ int lf_tag_data_loadcb(tag_specific_type_t type, tag_data_buffer_t *buffer) {
int lf_tag_em410x_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buffer) {
// Make sure to load this tag before allowing saving
// Just save the original card package directly
return m_tag_type == TAG_TYPE_EM410X ? LF_EM410X_TAG_ID_SIZE : 0;
if (m_tag_type == TAG_TYPE_EM410X) {
return LF_EM410X_TAG_ID_SIZE;
}
if (m_tag_type == TAG_TYPE_EM410X_ELECTRA) {
return LF_EM410X_ELECTRA_TAG_ID_SIZE;
}
return 0;
}
/** @brief Id card deposit card number before callback
@@ -235,6 +291,17 @@ int lf_tag_hidprox_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buff
return m_tag_type == TAG_TYPE_HID_PROX ? LF_HIDPROX_TAG_ID_SIZE : 0;
}
/** @brief Id card deposit card number before callback
* @param type Refined tag type
* @param buffer Data buffer
* @return The length of the data that needs to be saved is that it does not save when 0
*/
int lf_tag_ioprox_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buffer) {
// Make sure to load this tag before allowing saving
// Just save the original card package directly
return m_tag_type == TAG_TYPE_IOPROX ? LF_IOPROX_TAG_ID_SIZE : 0;
}
/** @brief Id card deposit card number before callback
* @param type Refined tag type
* @param buffer Data buffer
@@ -252,7 +319,7 @@ bool lf_tag_data_factory(uint8_t slot, tag_specific_type_t tag_type, uint8_t *ta
fds_slot_record_map_t map_info; // Get the special card slot FDS record information
get_fds_map_by_slot_sense_type_for_dump(slot, sense_type, &map_info);
// Call the blocked FDS to write the function, and write the data of the specified field type of the card slot into the Flash
bool ret = fds_write_sync(map_info.id, map_info.key, sizeof(tag_id), (uint8_t *)tag_id);
bool ret = fds_write_sync(map_info.id, map_info.key, length, (uint8_t *)tag_id);
if (ret) {
NRF_LOG_INFO("Factory slot data success.");
} else {
@@ -267,9 +334,18 @@ bool lf_tag_data_factory(uint8_t slot, tag_specific_type_t tag_type, uint8_t *ta
* @return Whether the format is successful, if the formatting is successful, it will return to True, otherwise False will be returned
*/
bool lf_tag_em410x_data_factory(uint8_t slot, tag_specific_type_t tag_type) {
// default id, must to align(4), more word...
uint8_t tag_id[5] = {0xDE, 0xAD, 0xBE, 0xEF, 0x88};
return lf_tag_data_factory(slot, tag_type, tag_id, sizeof(tag_id));
static const uint8_t tag_id_base[LF_EM410X_TAG_ID_SIZE] = {0xDE, 0xAD, 0xBE, 0xEF, 0x88};
static const uint8_t tag_id_electra[LF_EM410X_ELECTRA_TAG_ID_SIZE] = {0xDE, 0xAD, 0xBE, 0xEF, 0x88,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00};
switch (tag_type) {
case TAG_TYPE_EM410X_ELECTRA:
return lf_tag_data_factory(slot, tag_type, (uint8_t *)tag_id_electra, sizeof(tag_id_electra));
case TAG_TYPE_EM410X:
return lf_tag_data_factory(slot, tag_type, (uint8_t *)tag_id_base, sizeof(tag_id_base));
default:
return false;
}
}
/** @brief Id card deposit card number before callback
@@ -283,6 +359,18 @@ bool lf_tag_hidprox_data_factory(uint8_t slot, tag_specific_type_t tag_type) {
return lf_tag_data_factory(slot, tag_type, tag_id, sizeof(tag_id));
}
/** @brief Id card deposit card number before callback
* @param slot Card slot number
* @param tag_type Refined tag type
* @return Whether the format is successful, if the formatting is successful, it will return to True, otherwise False will be returned
*/
bool lf_tag_ioprox_data_factory(uint8_t slot, tag_specific_type_t tag_type) {
uint8_t tag_id[16] = {
0x01,0xAA,0x30,0x39,0x00,0x78,0x6A,0xA0,0x33,0x09,0xCF,0xEF,0x00,0x00,0x00,0x00
};
return lf_tag_data_factory(slot, tag_type, tag_id, sizeof(tag_id));
}
/** @brief Id card deposit card number before callback
* @param slot Card slot number
* @param tag_type Refined tag type
@@ -293,3 +381,13 @@ bool lf_tag_viking_data_factory(uint8_t slot, tag_specific_type_t tag_type) {
uint8_t tag_id[4] = {0xDE, 0xAD, 0xBE, 0xEF};
return lf_tag_data_factory(slot, tag_type, tag_id, sizeof(tag_id));
}
int lf_tag_pac_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buffer) {
return m_tag_type == TAG_TYPE_PAC ? LF_PAC_TAG_ID_SIZE : 0;
}
bool lf_tag_pac_data_factory(uint8_t slot, tag_specific_type_t tag_type) {
// default id: 8 ASCII bytes
uint8_t tag_id[8] = {'C', 'A', 'R', 'D', '0', '0', '0', '1'};
return lf_tag_data_factory(slot, tag_type, tag_id, sizeof(tag_id));
}
@@ -6,8 +6,11 @@
#include "tag_emulation.h"
#define LF_EM410X_TAG_ID_SIZE 5
#define LF_EM410X_ELECTRA_TAG_ID_SIZE 13
#define LF_IOPROX_TAG_ID_SIZE 16
#define LF_HIDPROX_TAG_ID_SIZE 13
#define LF_VIKING_TAG_ID_SIZE 4
#define LF_PAC_TAG_ID_SIZE 8
void lf_tag_125khz_sense_switch(bool enable);
int lf_tag_data_loadcb(tag_specific_type_t type, tag_data_buffer_t *buffer);
@@ -15,6 +18,10 @@ int lf_tag_em410x_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buffe
bool lf_tag_em410x_data_factory(uint8_t slot, tag_specific_type_t tag_type);
int lf_tag_hidprox_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buffer);
bool lf_tag_hidprox_data_factory(uint8_t slot, tag_specific_type_t tag_type);
int lf_tag_ioprox_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buffer);
bool lf_tag_ioprox_data_factory(uint8_t slot, tag_specific_type_t tag_type);
int lf_tag_viking_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buffer);
bool lf_tag_viking_data_factory(uint8_t slot, tag_specific_type_t tag_type);
int lf_tag_pac_data_savecb(tag_specific_type_t type, tag_data_buffer_t *buffer);
bool lf_tag_pac_data_factory(uint8_t slot, tag_specific_type_t tag_type);
bool is_lf_field_exists(void);
@@ -15,11 +15,17 @@
#define EM_BITS_PER_ROW_COUNT (EM_COLUMN_COUNT + 1)
#define EM_RAW_SIZE (64)
#define EM_DATA_SIZE (5)
#define EM_DATA_SIZE_BASE (5)
#define EM_ELECTRA_EPILOGUE_SIZE (8)
#define EM_DATA_SIZE_ELECTRA (EM_DATA_SIZE_BASE + EM_ELECTRA_EPILOGUE_SIZE)
#define EM_DATA_SIZE_MAX (EM_DATA_SIZE_ELECTRA)
#define EM_T55XX_ELECTRA_BLOCK_COUNT (5)
#define EM_ROW_COUNT (10)
#define EM_COLUMN_COUNT (4)
#define EM_HEADER (0x1ff) // 9 bits of 1
#define EM_ENCODED_DATA_HEADER (0xFF80000000000000ULL)
#define EM_T55XX_BLOCK_COUNT (3)
#define EM_READ_TIME1_BASE (0x40)
@@ -33,16 +39,25 @@
#include "nrf_log_default_backends.h"
NRF_LOG_MODULE_REGISTER();
static nrf_pwm_values_wave_form_t m_em410x_pwm_seq_vals[EM_RAW_SIZE] = {};
static nrf_pwm_values_wave_form_t m_em410x_pwm_seq_vals_base[EM_RAW_SIZE] = {};
static nrf_pwm_values_wave_form_t m_em410x_pwm_seq_vals_electra[EM_RAW_SIZE * 2] = {};
nrf_pwm_sequence_t const m_em410x_pwm_seq = {
.values.p_wave_form = m_em410x_pwm_seq_vals,
.length = NRF_PWM_VALUES_LENGTH(m_em410x_pwm_seq_vals),
nrf_pwm_sequence_t const m_em410x_pwm_seq_base = {
.values.p_wave_form = m_em410x_pwm_seq_vals_base,
.length = NRF_PWM_VALUES_LENGTH(m_em410x_pwm_seq_vals_base),
.repeats = 0,
.end_delay = 0,
};
nrf_pwm_sequence_t const m_em410x_pwm_seq_electra = {
.values.p_wave_form = m_em410x_pwm_seq_vals_electra,
.length = NRF_PWM_VALUES_LENGTH(m_em410x_pwm_seq_vals_electra),
.repeats = 0,
.end_delay = 0,
};
const protocol *em410x_protocols[] = {
&em410x_electra,
&em410x_64,
&em410x_32,
&em410x_16,
@@ -51,9 +66,11 @@ const protocol *em410x_protocols[] = {
size_t em410x_protocols_size = ARRAY_SIZE(em410x_protocols);
typedef struct {
uint8_t data[EM_DATA_SIZE];
uint8_t data[EM_DATA_SIZE_MAX];
uint64_t raw;
uint64_t epilogue;
uint8_t raw_length;
uint8_t total_length;
manchester *modem;
} em410x_codec;
@@ -80,6 +97,17 @@ uint64_t em410x_raw_data(uint8_t *uid) {
return raw;
}
uint64_t em410x_raw_epilogue(uint8_t *uid) {
uint64_t raw = 0;
for (int i = 0; i < EM_ELECTRA_EPILOGUE_SIZE; i++) {
raw <<= 8;
raw |= uid[EM_DATA_SIZE_BASE + i];
}
return raw;
}
bool em410x_get_time(uint16_t divisor, uint8_t interval, uint8_t base) {
return interval >= (base - EM_READ_JITTER_TIME_BASE) / divisor &&
interval <= (base + EM_READ_JITTER_TIME_BASE) / divisor;
@@ -142,9 +170,11 @@ void em410x_free(em410x_codec *d) {
uint8_t *em410x_get_data(em410x_codec *d) { return d->data; };
void em410x_decoder_start(em410x_codec *d, uint8_t format) {
memset(d->data, 0, EM_DATA_SIZE);
memset(d->data, 0, EM_DATA_SIZE_MAX);
d->raw = 0;
d->raw_length = 0;
d->total_length = 0;
d->epilogue = 0;
manchester_reset(d->modem);
};
@@ -202,6 +232,8 @@ bool em410x_decoder_feed(em410x_codec *d, uint16_t interval) {
if (bitlen == -1) {
d->raw = 0;
d->raw_length = 0;
d->total_length = 0;
d->epilogue = 0;
return false;
}
for (int i = 0; i < bitlen; i++) {
@@ -212,6 +244,79 @@ bool em410x_decoder_feed(em410x_codec *d, uint16_t interval) {
return false;
};
void em410x_electra_decoder_start(em410x_codec *d, uint8_t format) {
em410x_decoder_start(d, format);
}
static bool em410x_electra_decode_feed(em410x_codec *d, bool bit) {
bool carry_bit = (d->epilogue >> 63) & 0x01;
if (d->total_length < EM_RAW_SIZE + EM_RAW_SIZE) {
d->total_length++;
}
d->raw = (d->raw << 1) | carry_bit;
d->epilogue = (d->epilogue << 1) | (bit ? 1 : 0);
if (d->total_length < EM_RAW_SIZE + EM_RAW_SIZE) {
return false;
}
if ((d->raw & EM_ENCODED_DATA_HEADER) != EM_ENCODED_DATA_HEADER) {
return false;
}
if (d->raw & 0x01) {
return false;
}
uint8_t pc = 0;
for (int i = 0; i < EM_ROW_COUNT + 1; i++) {
uint8_t row = d->raw >> (EM_RAW_SIZE - 9 - (i + 1) * EM_BITS_PER_ROW_COUNT) & 0x1f;
uint8_t data = (row >> 1) & 0x0f;
pc ^= data;
if (i == 10) {
break;
}
if (!oddparity8(row)) { // row parity
return false;
}
if (i % 2) {
d->data[i >> 1] |= data;
} else {
d->data[i >> 1] = data << 4;
}
}
// if we only saw the same frame twice, treat as standard EM410X
if (d->raw == d->epilogue) {
return false;
}
for (int i = 0; i < EM_ELECTRA_EPILOGUE_SIZE; i++) {
d->data[EM_DATA_SIZE_BASE + i] = (d->epilogue >> ((EM_ELECTRA_EPILOGUE_SIZE - 1 - i) * 8)) & 0xFF;
}
return pc == 0x00;
}
bool em410x_electra_decoder_feed(em410x_codec *d, uint16_t interval) {
bool bits[2] = {0};
int8_t bitlen = 0;
manchester_feed(d->modem, (uint8_t)interval, bits, &bitlen);
if (bitlen == -1) {
em410x_decoder_start(d, 0);
return false;
}
for (int i = 0; i < bitlen; i++) {
if (em410x_electra_decode_feed(d, bits[i])) {
return true;
}
}
return false;
};
const nrf_pwm_sequence_t *em410x_modulator(em410x_codec *d, uint8_t *buf) {
uint64_t lo = em410x_raw_data(buf);
for (int i = 0; i < EM_RAW_SIZE; i++) {
@@ -219,16 +324,50 @@ const nrf_pwm_sequence_t *em410x_modulator(em410x_codec *d, uint8_t *buf) {
if (IS_SET(lo, EM_RAW_SIZE - i - 1)) {
msb = (1 << 15);
}
m_em410x_pwm_seq_vals[i].channel_0 = msb | 32;
m_em410x_pwm_seq_vals[i].counter_top = 64;
m_em410x_pwm_seq_vals_base[i].channel_0 = msb | 32;
m_em410x_pwm_seq_vals_base[i].counter_top = 64;
}
return &m_em410x_pwm_seq;
return &m_em410x_pwm_seq_base;
};
const nrf_pwm_sequence_t *em410x_electra_modulator(em410x_codec *d, uint8_t *buf) {
uint64_t data[] = {em410x_raw_data(buf), em410x_raw_epilogue(buf)};
uint16_t output_index = 0;
for (int frame = 0; frame < 2; frame++) {
for (int i = 0; i < EM_RAW_SIZE; i++) {
uint16_t msb = 0x00;
if (IS_SET(data[frame], EM_RAW_SIZE - i - 1)) {
msb = (1 << 15);
}
m_em410x_pwm_seq_vals_electra[output_index].channel_0 = msb | 32;
m_em410x_pwm_seq_vals_electra[output_index].counter_top = 64;
output_index++;
}
}
return &m_em410x_pwm_seq_electra;
};
// EM-Micro, EM410x/64 (std)
const protocol em410x_electra = {
.tag_type = TAG_TYPE_EM410X_ELECTRA,
.data_size = EM_DATA_SIZE_ELECTRA,
.alloc = (codec_alloc)em410x_64_alloc,
.free = (codec_free)em410x_free,
.get_data = (codec_get_data)em410x_get_data,
.modulator = (modulator)em410x_electra_modulator,
.decoder =
{
.start = (decoder_start)em410x_electra_decoder_start,
.feed = (decoder_feed)em410x_electra_decoder_feed,
},
};
// EM-Micro, EM410x/64 (std)
const protocol em410x_64 = {
.tag_type = TAG_TYPE_EM410X_64,
.data_size = EM_DATA_SIZE,
.data_size = EM_DATA_SIZE_BASE,
.alloc = (codec_alloc)em410x_64_alloc,
.free = (codec_free)em410x_free,
.get_data = (codec_get_data)em410x_get_data,
@@ -243,7 +382,7 @@ const protocol em410x_64 = {
// EM-Micro, EM410x/32
const protocol em410x_32 = {
.tag_type = TAG_TYPE_EM410X_32,
.data_size = EM_DATA_SIZE,
.data_size = EM_DATA_SIZE_BASE,
.alloc = (codec_alloc)em410x_32_alloc,
.free = (codec_free)em410x_free,
.get_data = (codec_get_data)em410x_get_data,
@@ -258,7 +397,7 @@ const protocol em410x_32 = {
// EM-Micro, EM410x/16
const protocol em410x_16 = {
.tag_type = TAG_TYPE_EM410X_16,
.data_size = EM_DATA_SIZE,
.data_size = EM_DATA_SIZE_BASE,
.alloc = (codec_alloc)em410x_16_alloc,
.free = (codec_free)em410x_free,
.get_data = (codec_get_data)em410x_get_data,
@@ -277,4 +416,17 @@ uint8_t em410x_t55xx_writer(uint8_t *uid, uint32_t *blks) {
blks[1] = raw >> 32;
blks[2] = raw & 0xffffffff;
return EM_T55XX_BLOCK_COUNT;
}
}
uint8_t em410x_electra_t55xx_writer(uint8_t *uid, uint32_t *blks) {
uint64_t raw_data = em410x_raw_data(uid);
uint64_t raw_epilogue = em410x_raw_epilogue(uid);
blks[0] = T5577_EM410X_ELECTRA_CONFIG;
blks[1] = raw_data >> 32;
blks[2] = raw_data & 0xffffffff;
blks[3] = raw_epilogue >> 32;
blks[4] = raw_epilogue & 0xffffffff;
return EM_T55XX_ELECTRA_BLOCK_COUNT;
}
@@ -5,8 +5,10 @@
extern const protocol em410x_64;
extern const protocol em410x_32;
extern const protocol em410x_16;
extern const protocol em410x_electra;
extern const protocol* em410x_protocols[];
extern size_t em410x_protocols_size;
uint8_t em410x_t55xx_writer(uint8_t* uid, uint32_t* blks);
uint8_t em410x_t55xx_writer(uint8_t* uid, uint32_t* blks);
uint8_t em410x_electra_t55xx_writer(uint8_t* uid, uint32_t* blks);

Some files were not shown because too many files have changed in this diff Show More