Commit Graph
14063 Commits
Author SHA1 Message Date
iceman1001 7556dd8fc0 Resync drain after framing error 2026-08-31 19:45:23 +02:00
iceman1001 179de04301 Clear ring per send, check start ack 2026-08-31 19:43:38 +02:00
Antiklesys a47bdebc87 Extended T=1 support
Extended T=1 support with TA1=95 and T1_IFSD_WANTED 254
2026-08-31 15:28:49 +08:00
Iceman be7f55f72b Merge pull request #3555 from munzzyy/fix/xerox-view-info-block-oob
Fix heap out-of-bounds read in hf xerox view on short dump files
2026-08-31 03:50:44 +07:00
Philippe Teuwen c356ce7f14 Restore client and fw capabilities version parity 2026-08-30 22:42:52 +02:00
Cole Munz 18936b2188 Fix heap out-of-bounds read in hf xerox view on short dump files 2026-08-30 15:39:45 -05:00
Iceman ff94b8b376 Merge pull request #3554 from actuallysparky/codex/emrtd-sod-stack-overflow
fix(eMRTD): move EF_SOD parser buffers off the stack
2026-08-31 02:18:08 +07:00
iceman1001 9e2092fc66 capabilities: report device frame size so the client can adapt
PM3_CMD_DATA_SIZE went 512 -> 624 without a capabilities bump, so a new
client connects to old firmware and every oversized command dies at the
device's length check with no message.

Append max_cmd_data_size, bump to v9. The client now accepts an older
capabilities struct - it only ever grows by appending, so an older layout
is a prefix - and defaults the frame size for pre-v9 firmware.
SendCommandNG bounds by the device value instead of the compile time one.

Also zero init capabilities_t on the device, it leaked stack bytes.
2026-08-30 20:13:38 +02:00
SparkyandCodex 879a4bd273 fix(eMRTD): avoid EF_SOD parser stack overflow
Allocate EF_SOD parsing scratch buffers on the heap so macOS worker threads do not exceed their stack while reading protected travel documents.

Co-Authored-By: Codex <noreply@openai.com>
2026-08-30 10:48:29 -07:00
iceman1001 b7bd6ddadb fix return value that break 'hf search', Thanks @atk! 2026-08-30 19:11:37 +02:00
Niel Nielsen e6220a828f Add files via upload
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-30 15:24:08 +02:00
Philippe Teuwen 519e0f6de9 pm5_battery_test: misc fixes 2026-08-30 14:11:47 +02:00
Philippe Teuwen aa052ca444 pm5_battery_test: fix missing arg 2026-08-30 13:58:20 +02:00
Philippe Teuwen bf32513d1b pm5_battery_test: merge nieldk version and add test scenarios 2026-08-30 13:44:46 +02:00
iceman1001 1d87a6c192 chunk CMD_READ_MEM_DOWNLOADED by the OLD frame size reply_old clamps its payload to PM3_CMD_DATA_SIZE_OLD but the sender still
chunked by PM3_CMD_DATA_SIZE. Identical today, but if the NG size moves the
chunk would be built oversized, truncated on the wire, and still announced
at full length in oldarg[1] - the client would copy past the valid bytes and
advance by the wrong stride. Bound the client's OLD download branch by the
same constant.
2026-08-30 13:33:50 +02:00
iceman1001 ed066d84aa 'hf mfu cchk' - widen 3-pass chkkey nkeys to a full byte
nkeys was a 6 bit field but the client chunked by what fits in a frame -
123 keys in segment mode. nkeys wrapped to 59 while memcpy copied all 123
and the loop advanced by 123, so 64 of every 123 keys were never tested
and never reported. Full key mode was unaffected, it chunks 30.

Give nkeys its own byte. MIFAREU3P_CHKKEY_HEADER goes 18 -> 19, costing
one byte of payload, and segment mode chunks 123 again

Payload layout changed: client and firmware must be updated together.
Thanks Claude!
2026-08-30 13:25:50 +02:00
iceman1001 25d958e5e6 split PM3_CMD_DATA_SIZE_OLD out of PM3_CMD_DATA_SIZE
The OLD frame size was tied to the NG one, but the bootloader only speaks
OLD - growing PM3_CMD_DATA_SIZE would silently change sizeof(PacketCommandOLD)
and break flashing against every deployed bootrom in both directions.

Pin the OLD structs to their own constant and use it on every OLD path:
reply_old and the OLD receive branch on both sides, the bootrom, and the
flasher's write_block/send_finish_write_cmd, which memcpy into a
PacketCommandOLD using the NG size.

No behaviour change - both constants are 512 and armsrc .text is
byte-identical before and after.
2026-08-30 13:03:53 +02:00
Philippe Teuwen 0197fe8484 Battery test graph: elapsed time 2026-08-30 00:06:13 +02:00
Philippe Teuwen 8017246fd5 Battery test scripts 2026-08-30 00:06:13 +02:00
Iceman 1d035e8643 Merge pull request #3498 from 0x6r1an0y/20260823-ndefnlen
Correct NLEN log message and empty record example
2026-08-30 04:28:30 +07:00
歐歪 910f6ba41f Update cmdhf14a.c
Signed-off-by: 歐歪 <brian20020925@gmail.com>
2026-08-30 03:46:41 +08:00
iceman1001 a1053ad70d New individual json dump file formats for ht1, ht2, htS, htU. '.bin' / binary format for hitag has been deprecated 2026-08-29 20:58:59 +02:00
Niel Nielsen 03bbf292dc Enhance CLI with WiFi status check and timeout adjustment
Added status option to CLI for checking WiFi connection state and IP address. Updated command timeout for join and DHCP wait.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-29 20:03:12 +02:00
iceman1001 7fade30465 remove commented out code 2026-08-29 17:48:25 +02:00
iceman1001 35c098d489 make style 2026-08-29 17:42:29 +02:00
iceman1001 a0a3eb4bbf remove CMD_LF_SIMULATE_BIDIR, never implemented 2026-08-29 17:38:41 +02:00
iceman1001 026a1c7648 fixed missing waits for return OPcodes 2026-08-29 17:30:07 +02:00
iceman1001 c5ee0ea3d5 fix leftover oldarg in lua scripts 2026-08-29 17:07:33 +02:00
iceman1001 1ee41ecf95 fix leftover oldargs 2026-08-29 17:06:24 +02:00
iceman1001 87b5ee37c9 stablize download trace more 2026-08-29 17:02:15 +02:00
iceman1001 0f11c5c4d1 Phase E - dismantle MIX functionality 2026-08-29 16:50:29 +02:00
iceman1001 07a0ff70db fix string formatting CodeQL 2026-08-29 16:42:01 +02:00
iceman1001 ff56ec85f9 missed one 2026-08-29 16:35:13 +02:00
iceman1001 11f5e58136 text 2026-08-29 16:34:47 +02:00
iceman1001 177d240ee3 dangling code parts 2026-08-29 16:34:08 +02:00
iceman1001 094bed1176 remove MIX bindings in lua 2026-08-29 16:33:16 +02:00
iceman1001 bd20f7cc81 OLD/MIX convert to NG: Phase D. reworked all lua scripts to handle and behavie same way. Thanks Claude 2026-08-29 16:31:01 +02:00
iceman1001 7b7ec48bd9 OLD/MIX convert to NG: Phase C10 2026-08-29 15:50:36 +02:00
iceman1001 72ff6a5b80 OLD/MIX convert to NG: Phase C9 2026-08-29 15:18:54 +02:00
iceman1001 721641428c OLD/MIX convert to NG: Phase C8 2026-08-29 15:13:34 +02:00
iceman1001 0bbc9025ae OLD/MIX convert to NG: Phase C7 2026-08-29 15:00:03 +02:00
iceman1001 3762130c42 OLD/MIX convert to NG: Phase C6 2026-08-29 14:48:36 +02:00
iceman1001 5589cbf847 OLD/MIX convert to NG: Phase C5 2026-08-29 14:31:34 +02:00
iceman1001 d1cc742987 OLD/MIX convert to NG: Phase C4 2026-08-29 14:24:11 +02:00
iceman1001 f42564283e OLD/MIX convert to NG: Phase C3 2026-08-29 14:19:26 +02:00
iceman1001 ad629c77e8 OLD/MIX convert to NG: Phase C2 2026-08-29 14:12:22 +02:00
iceman1001 5c7e9f6c42 OLD/MIX convert to NG: Phase C1 2026-08-29 13:58:42 +02:00
iceman1001 1a3f64960a OLD/MIX convert to NG: Phase C 2026-08-29 13:50:49 +02:00
iceman1001 bbc8cc25b2 OLD/MIX convert to NG, Phase B 2026-08-29 13:30:07 +02:00
iceman1001 99c58f9dea NG: iso14a_raw_cmd_t, convert hf 14a raw, dual-mode reader handler. A multi step process, this is the first step. Thanks Claude 2026-08-29 13:06:28 +02:00