455 Commits
Author SHA1 Message Date
GameTec-live 14c42544ad Merge branch 'main' into main 2026-10-04 21:26:32 +02:00
GameTec-live 68c1e72e81 Merge pull request #458 from naaraxi/fix/435-sleep-timeout
#435 - Setting sleep timeout was broken
2026-10-04 21:02:57 +02:00
GameTec-live 156324b1b6 Merge branch 'main' into hfsniff-fix 2026-10-04 10:41:56 +02:00
GameTec-live 39a597b5ea Merge branch 'main' into ulc 2026-10-04 10:37:12 +02:00
DidierA 6019973929 merge master 2026-09-08 12:56:48 +02:00
Alexandru Mazalu 3c5551a4fa Merge branch 'main' into fix/435-sleep-timeout 2026-08-28 19:08:51 +03:00
Curious, aren't we? 549e4457f0 Merge branch 'main' into main 2026-08-07 23:17:24 +02:00
Alexandru Mazalu 3d405b0468 Merge branch 'RfidResearchGroup:main' into fix/435-sleep-timeout 2026-07-29 18:31:58 +03:00
Aaron Tulino (Aaronjamt) 1f99ddd4db SEOS emulation support 2026-07-28 11:18:18 -07:00
GameTec-live 3d1ffe9b47 Merge pull request #451 from wereii/perf/fsk-demod-sqrt
Deploy wiki to GitHub Pages with Jekyll / build (push) Canceled after 0s
Deploy wiki to GitHub Pages with Jekyll / deploy (push) Canceled after 0s
Firmware build / Build and push fw-builder Docker image (push) Canceled after 0s
Firmware build / Build firmware (lite) (push) Canceled after 0s
Firmware build / Build firmware (ultra) (push) Canceled after 0s
Push handler / Build Firmware (push) Canceled after 0s
Client build / Build client ((cd software/dist && zip -r "$OLDPWD/client-linux.zip" .) , linux, ubuntu-latest, true ) (push) Canceled after 0s
Client build / Build client ((cd software/dist && zip -r "$OLDPWD/client-macos.zip" .) , macos, macos-latest, true ) (push) Canceled after 0s
Client build / Build client (Compress-Archive -Path software\dist\* -DestinationPath client-windows.zip , windows, windows-latest, ? . ) (push) Canceled after 0s
Push handler / Create dev pre-release with artifacts (push) Canceled after 0s
Push handler / Create tagged release with artifacts (push) Canceled after 0s
perf(lf): drop double-precision sqrt from FSK demod hot path
2026-07-28 19:40:40 +02:00
Aaron Tulino ac63dbdac8 Merge branch 'main' into patch-iso14443-4-blockvals 2026-07-28 10:32:47 -07:00
naaraxi 42d06ad383 #435 - Setting sleep timeout was broken 2026-07-10 18:34:50 +03:00
Aaron Tulino d0b2df564b Merge branch 'main' into patch-iso14443-4-blockvals 2026-07-07 02:01:17 -07:00
Aaron Tulino d562549b5d Merge branch 'main' into patch-14443-4 2026-07-07 02:01:15 -07:00
GameTec-live 2d9c8bcc9f Merge pull request #274 from unkernet/acl
Fix state machine behavior and access bits verification in MF1 emulation
2026-07-04 13:14:59 +02:00
wereiiandClaude Opus 4.8 ab59e7af00 perf(lf): drop double-precision sqrt from FSK demod hot path
The build targets the Cortex-M4F single-precision FPU (-mfpu=fpv4-sp-d16),
which has no double-precision hardware. goertzel_mag() used sqrt() (double):
the float result was promoted to double for the call and converted back, and
a software double-sqrt routine ran -- twice per decoded bit.

The bit decision only compares the two Goertzel outputs, and power is
monotonic with magnitude, so the sqrt is unnecessary. goertzel_power()
returns the squared magnitude and fsk_feed() compares that directly. This
also removes a latent sqrt(NaN): the magnitude argument can round slightly
negative near zero signal, which sqrt() turned into NaN (and NaN comparisons
make the bit decision unreliable); comparing the raw power is well-defined.

The old goertzel_mag() had no callers anywhere and was not declared in the
header, so it is removed rather than kept.

Shared by all FSK readers (HID Prox, ioProx, Pyramid): bit decisions are
identical, the soft-float double dependency is gone, and the time-sensitive
demod loop is slightly faster.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-24 14:06:18 +02:00
DidierA 2239acdd06 nfc_tag_14a_event_callback: remove wrong parity bit computation, which failed when there was more than 7 parity bits. Fixes #444 2026-06-18 20:09:12 +02:00
DidierA c3b08be5df blk_num is unused, which caused build to fail. 2026-06-18 20:06:34 +02:00
Aaron Tulino (Aaronjamt) 81ce26a15b Fix CID and add PPS 2026-06-17 01:47:31 -07:00
Aaron Tulino (Aaronjamt) 4b2c29fa0b nfc_tag_14a_4_reset_state function needs passed pointer 2026-06-16 21:48:13 -07:00
Aaron Tulino (Aaronjamt) 909a7e7eda Fix ISO14443-4 block values 2026-06-16 15:14:27 -07:00
Aaron Tulino (Aaronjamt) f7350ce11e send_* functions need passed pointers 2026-06-16 12:14:22 -07:00
Aaron Tulino (Aaronjamt) 976ee266b7 Pass by reference, not value 2026-06-13 21:51:45 -07:00
Aaron Tulino (Aaronjamt) c0477cd961 Export low-level ISO14443-4 handling 2026-06-13 16:49:12 -07:00
Foxushka d8e85d53dc feat: add change key command 2026-06-13 13:01:15 +03:00
Foxushka 2999d9dd5f feat: MIFARE Ultralight C authentication and emulation 2026-06-13 11:38:40 +03:00
unkernet 779bab265e Fix: mf1 encrypted HALT logic 2026-05-30 21:09:31 +07:00
unkernet ca6c299865 Merge branch 'main' into acl 2026-05-30 12:28:48 +07:00
Curious, aren't we? f0566dd720 Add long button press threshold as a user setting 2026-05-26 17:19:31 +02:00
Milan DavídekandClaude Opus 4.7 38689a82ba Move JABLOTRON_WRITE_TO_T55XX from 3017 to 3020
Keep SCAN(3019)/WRITE(3020) adjacent, matching the SCAN+WRITE
adjacency convention used by every other LF protocol
(EM410X 3000/3001, HIDPROX 3002/3003, VIKING 3004/3005,
IOPROX 3010/3011, PAC 3014/3015). Slot 3017 is now free for
future use.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 14:01:58 +02:00
Milan DavídekandClaude Opus 4.7 52f37bff8d Merge upstream/main into Jablotron PR #404
Resolved conflicts from upstream feature additions (IDTECK PR #407,
LF_T55XX_WRITE PR #413, ISO14443-4 T=CL emulation, HF14A scan-keep,
etc.) by keeping both sides where independent.

Command ID note for reviewer:
- Maintainer's IDTECK shift commit (1e78976) stated "Jablotron retains
  the original slots 3016 and 3017", but upstream had already taken
  3016 for DATA_CMD_LF_T55XX_WRITE. Only 3017 was actually free.
- Resolution: JABLOTRON_WRITE_TO_T55XX kept at 3017 (honors intent).
  JABLOTRON_SCAN moved 3016 -> 3019 (next free slot).
- 5xxx range: JABLOTRON_SET/GET_EMU_ID = 5010/5011 unchanged
  (IDTECK shifted to 5012/5013 as planned).

Python files parse cleanly. No duplicate command IDs in data_cmd.h
(3xxx and 5xxx ranges checked).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 13:51:54 +02:00
matteoscrugli 1e78976bd9 feat(lf): shift IDTECK command IDs to avoid collision with Jablotron PR #404
LupusE requested in the PR #407 review (2026-05-13) to move IDTECK
command IDs since PR #404 (Jablotron) also uses 3017 / 5010 / 5011.
Both PRs are open with the feature-freeze label; Jablotron retains
the original slots and IDTECK shifts up:

  DATA_CMD_IDTECK_WRITE_TO_T55XX: 3017 -> 3018
  DATA_CMD_IDTECK_SET_EMU_ID:     5010 -> 5012
  DATA_CMD_IDTECK_GET_EMU_ID:     5011 -> 5013

Files changed:
- firmware/application/src/data_cmd.h
- software/script/chameleon_enum.py

app_cmd.c references the constants by name only, no edit needed there.
2026-05-15 10:09:51 +02:00
matteoscrugli 77e967c78b feat(lf): integrate IDTECK into firmware command and T55xx write paths
Exposes IDTECK to the host command protocol:
- DATA_CMD_IDTECK_SET_EMU_ID (5010) / GET_EMU_ID (5011) / WRITE_TO_T55XX (3017)
- Matching handlers in app_cmd.c for setting the emulated frame on
  the current LF slot, reading it back, and programming a T55xx tag

Adds write_idteck_to_t55xx in lf_reader_main (modeled on the other
per-protocol T55xx writers), wrapping idteck_t55xx_writer and the
shared write_t55xx helper.

After this commit the firmware is fully functional for IDTECK: a
host can set an emulated frame, read it back, or clone it to a T55xx.
The CLI wiring is added in the following commit.
2026-05-15 10:08:48 +02:00
matteoscrugli b8f070851c feat(lf): add IDTECK tag emulation (PSK1 RF/32)
Adds IDTECK as a new LF protocol for tag emulation. IDTECK is a PSK1
encoding at RF/32 with a 64-bit frame: a 32-bit fixed preamble
0x4944544B ("IDTK") followed by a 32-bit card payload (one-byte
checksum + 24-bit card number in byte-reversed layout, matching the
format used by the Proxmark3 client).

The modulator drives LF_MOD (load-modulation, same hardware path used
for FSK protocols like HID Prox) via the shared utils/psk1 helper,
producing a 62.5kHz subcarrier with a 180-degree phase flip at every
differential bit transition. Because PSK1 is differential the reader
decodes phase transitions between consecutive bits rather than
absolute phase, so carrier phase-lock is not required — a free-running
subcarrier from HFXO (±40ppm) stays within the tolerance of consumer
readers.

The 16us subcarrier period is below the counter_top minimum of 3 at
the legacy 125kHz PWM base clock used for ASK/FSK protocols. To avoid
rescaling every existing protocol, pwm_init now selects the base
clock based on the active tag type (predicate IS_PSK1_TYPE): 1MHz for
PSK1, 125kHz otherwise. Legacy protocols are untouched.

The comment in lf_sense_enable is updated to reflect that the absence
of carrier phase-lock (envelope-only tag-mode antenna taps) rules out
coherent demod but does not preclude differential-phase encodings
like the one introduced here.

T5577 cloning configuration uses the existing T5577_MODULATION_PSK1
symbol combined with RF/32 bitrate and 2 data blocks. Emulation read
is not added: the tag-emulation ADC path is 125kHz envelope-filtered,
so PSK demod would need a dedicated edge-timing decoder (left as a
follow-up).
2026-05-15 10:08:48 +02:00
matteoscrugli 5e2401587e feat(lf): add shared PSK1 wave-form helper for tag emulation
Factors out the PSK1 subcarrier generator into utils/psk1.{c,h}.
The helper takes a frame (MSB-first bytes), a bit count and a
destination wave-form buffer, and fills the buffer with PWM entries
expressing differential PSK1 as polarity flips at bit transitions.

No protocol uses this helper yet; it is introduced alone so that
individual PSK1 protocol files (starting with IDTECK in the next
commit) can plug into the same timing and encoding logic without
each re-implementing it.

The helper targets the 1MHz PWM base clock that will be selected by
pwm_init for PSK1 tag types; counter_top and duty constants are
defined accordingly.
2026-05-15 10:08:48 +02:00
Niel Nielsen 1bf8229d26 Add files via upload 2026-05-14 13:21:31 +02:00
Niel Nielsen 7e48d5427a Add files via upload 2026-05-13 21:22:03 +02:00
Niel Nielsen 1954faf3af Fix: Device does not go to sleep, #421
The fix in EVT_END_SEQ0:
	1.	ANT_NO_MOD() — silences LF_MOD so the local drive no longer charges the peak detector
	2.	bsp_delay_ms(2) — 2ms settle, slightly above the ~2ms time constant so the detector drains to reflect only the external field
	3.	is_lf_field_exists() — now sees the real field state
	4.	If field gone → nrfx_pwm_stop() → EVT_STOPPED → lf_field_lost() runs correctly
	5.	If field present → ANT_MOD() restores modulation for the next PWM sequence​​​​​​​​​​​​​​​​
2026-05-13 21:13:57 +02:00
Niel Nielsen cef8b42c26 make_style as that is best practise 2026-05-11 12:36:51 +02:00
Niel Nielsen 43f4d55c2b Update app_cmd.c 2026-05-11 10:25:50 +02:00
Niel Nielsen d3f9a521cb Update app_cmd.c 2026-05-11 09:50:23 +02:00
Niel Nielsen 5f8f29c8b4 Update data_cmd.h 2026-05-11 09:48:31 +02:00
Niel Nielsen 9d8c52fbdb Add sleep timeout commands for configuration 2026-05-11 09:45:32 +02:00
Niel Nielsen 68f929b23f Add files via upload 2026-05-10 20:40:39 +02:00
Niel Nielsen a64798f8a7 Add files via upload 2026-05-10 19:48:06 +02:00
Niel Nielsen 2701e64755 Add files via upload 2026-05-10 19:15:34 +02:00
Niel Nielsen c0fd09b737 Add files via upload 2026-05-10 19:13:59 +02:00
Niel Nielsen e2ce3f3a29 Add files via upload 2026-05-10 17:05:43 +02:00
Niel Nielsen 4bfc18ae6f Add files via upload 2026-05-10 17:05:06 +02:00
Niel Nielsen 394781a45f Add files via upload 2026-05-07 20:08:23 +02:00