Commit Graph
209 Commits
Author SHA1 Message Date
Philippe Teuwen 2b7a436ada Warn if sending bitstream to FPGA fails 2026-09-01 00:17:28 +02:00
iceman1001 81aa2d437a Real SPI completion wait 2026-08-31 19:47:17 +02:00
iceman1001 ca5913a2db text 2026-08-30 16:54:20 +02:00
iceman1001 35c098d489 make style 2026-08-29 17:42:29 +02:00
iceman1001 9b61ef867c fix SpinDelayUsPrecision() clock, no more wrapping 43ms> issues. Still capped at 1390ms. This affects a bunch of tearoff attacks 14b especially win 100ms actually being 16ms wrapped. Should be handled according to new HAL layer. Next things is rate renegotiated at reconnect for sim module. Makes things a more stable if something fails. Thanks Claude! 2026-08-29 06:42:17 +02:00
iceman1001andClaude Opus 5 cb48c928a5 hf felica: make reading actually work
FeliCa reading was broken on every card tested: 'hf felica reader' returned PM3_ETIMEOUT while the tag was answering correctly. The cause was in the FPGA demodulator, not the ARM.

fpga/hi_flite.v
---------------
Adaptive hysteresis thresholds. The envelope tracker clamped curmin to <= 70 and curmax to >= 180, so curminthres/curmaxthres were pinned near 91/160 no
matter where the signal actually sat. Measured on a RDV4 with the field on, the peak detector idles near 112 and a tag swings it by about +/-35, ie entirely
inside that window - so nothing ever crossed a threshold and every frame demodulated as a constant. The band is now derived from the tracked envelope,
3/16 of its span, floored at +/- 8 to stay clear of the 4..6 counts of carrier ripple.

Matched-filter bit detector. The slicer counted comparator trips (+1 above curmaxthres, -1 below curminthres, repeat the last crossing direction inside
the dead band), so every bit depended on where the band happened to sit. A mispositioned band railed the output to a constant and, since only the stable
branch can recompute thresholds or desync, it stayed that way for the rest of the session. It also discarded amplitude, gaining nothing from 32x
oversampling. Each half-bit is now integrated in the ADC domain and the larger half wins. Thresholds still drive bit phase and the desync, they no longer
decide bit values, so a clipped or mispositioned envelope can no longer rail the output.

Polarity lock guard. try_sync arms part way through a half-bit, so the first decision after arming is meaningless and could latch 'zero' inverted, decoding
the whole frame with the wrong polarity and losing the sync word. Skip the first two decisions; the preamble is 48 bits.

curbit re-timing. The bit decision was made in the bit-phase domain, which is aligned to the tag's edges, but sampled by the SSC in the carrier domain. The
ARM could latch a bit mid-transition at a phase that varied per frame. Both run at 64 carrier periods per bit, so re-timing curbit half an SSP bit away from the
sampling edge is a re-time, not a resample.

Envelope watchdog. FPGA registers persist across PM3 commands - only a bitstream reload clears them - so the tracker could enter a state it never left and the
first command after the client started would work while every one after it failed. Force a re-centre when the demodulator has not reached a known-good idle
for 19.3 ms, held off at the start of each frame so it cannot fire mid-reply.

state is marked (* fsm_extract = 'no' *). The project synthesises with -fsm_style bram; once XST recognised this register as a state machine it placed
the state ROM in a block RAM, and the xc2s30's six were already spoken for. MAP then failed to fit with nothing but a generic 'design is too large' error, no
BITGEN, and no new bitstream.

armsrc/felica.c
---------------
- felica_select_card() returning 4 (response too short for IDm+PMm) fell through to PM3_SUCCESS, so 'hf felica reader' reported an all-zero IDm as a good read.
- After a poll timeout the code still read FelicaFrame; with a stale POLLING_RES and len == 0, check_crc() was handed (len - 2) as a size_t, ie 65534.
- WaitForFelicaReply() could only time out from STATE_UNSYNCD/TRYING_SYNC and would spin forever if a frame never completed.
- felica_sniff() decremented and broke before LogTrace, so '-s 10' logged nine frames and '-s 0' logged none. CRC-failed noise no longer pollutes the trace.
- felica_sendraw() sent no reply at all for some flag combinations, leaving the client blocked until its own timeout.
- Polling used time slot 0 only, so several cards in the field collided forever. Retries now widen the TSN window.
- BuildFliteRdblk() warned about a bad block count and built the frame anyway.

Signal probe
------------
'hf felica raw -p' streams the per-window envelope min and max instead of demodulated bits, so reading distance and coupling can be measured rather than
guessed. This is what told 'tag out of range' apart from 'demodulator not locking', which are otherwise identical from the ARM's point of view.

Measured on a RDV4, both cards previously unreadable:
  FeliCa Standard RC-S830 (CJRC 0003): reader 4/4, info 4/4, 39 nodes discovered, dump complete in 2.0 s, 37/40 single polls.
  FeliCa Standard RC-S962 (Octopus 8008): reader 10/10, 23 nodes discovered, dump complete in 1.5 s, 40/60 single polls. This one drives the envelope onto the bottom ADC rail; the matched filter reads it anyway.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-28 22:35:08 +02:00
Niel Nielsen d35ddce206 Update low-battery options in Makefile.hal
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-28 14:14:29 +02:00
Niel Nielsen 98abc5d5f7 Clarify low-battery options in Makefile.hal
Updated comments for clarity on low-battery options.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-28 14:14:29 +02:00
Philippe Teuwen 18bc735822 ARM: err on more warnings 2026-08-26 17:19:13 +02:00
Niel Nielsen e71f37ef32 Remove WITH_BWM_FORWARD from PLATFORM_DEFS
Removed the conditional definition for WITH_BWM_FORWARD in PLATFORM_DEFS.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-26 16:07:37 +02:00
Niel Nielsen 7f9619eb7d Add files via upload
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-26 16:07:37 +02:00
Iceman 1c9ade5a95 Merge pull request #3526 from xianglin1998/fpgac-cfg-check-size
Check the file size when configuring the fpga.
2026-08-26 13:42:40 +07:00
dxl 1c9c84c6d7 Check the file size when configuring the fpga. 2026-08-26 13:17:22 +08:00
dxl 16f622d907 Update comment for StopTicks() 2026-08-26 11:45:05 +08:00
Niel Nielsen ee0c841556 Add WITH_PM5_AUTOOFF to PLATFORM_DEFS
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-25 12:43:53 +02:00
Niel Nielsen 4d529bc4d7 CHANGE: Battery temp to Temp (gauge), ADD: Dim green LED when on battery only 2026-08-24 21:05:00 +02:00
dxl 03b7ca16e2 Translate source related to fpga_gw_jtag. 2026-08-24 09:55:27 +02:00
dxl 659d400bc3 Using GPIO defs in fpga_gw_jtag.h 2026-08-24 09:55:27 +02:00
dxl d9292e59fb rename delay_ms to delay_ms_gowin in fpga_gw_jtag module 2026-08-24 09:55:27 +02:00
dxl 347cbf153a Move gpio defs to config_gpio_proxmark5.h 2026-08-24 09:55:27 +02:00
dxl 216ed863a7 Deleted code for debug 2026-08-24 09:55:27 +02:00
dxl 5b8d65810e Refactor the clock generation in gowin jtag to try to fix the bug that caused the erase to fail. 2026-08-24 09:55:27 +02:00
dxl 010107a058 Add the gpio_pull type to gpio_fpga_download_setup() 2026-08-24 09:55:27 +02:00
Niel Nielsen 1f09027bec Update PLATFORM_DEFS in Makefile.hal
Removed BWM_LOWBATT_BEEP definition from PLATFORM_DEFS.

Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-23 20:41:56 +02:00
Niel Nielsen 190ed8a990 ADD: BWM status includes AW32001ECSR registerd, Charging set to 256mAh and keeps BWM safety guards for temperature 2026-08-23 20:31:01 +02:00
Niel Nielsen 165e44b1ba Add WITH_BWM_STATUS to PLATFORM_DEFS
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
2026-08-23 11:29:30 +02:00
dxl 2a11c73bbe To expand crm_ertc_clock_select() in at32_bpr_write_dt1() for reduce code size. 2026-08-22 03:04:27 +08:00
Iceman a7c696b9a0 Merge branch 'master' into fix/pm5-flash-mode-bpr-hick
Signed-off-by: Iceman <iceman@iuse.se>
2026-08-20 21:52:08 +07:00
Nemanja Nedeljkovic f71bc53d0c fix(pm5): power on the FPGA in hw fpga config
`hw fpga config` drives the FPGA over JTAG, but on PM5 the FPGA has to be
clocked/powered first - previously that only happened as a side effect of a
reader command (e.g. `hf 14a read`), so `hw fpga config` failed if run on its
own. Bring the FPGA up in the HAL at the start of FpgaStartConfig()
(FpgaSetup24MHzClk) so the command works standalone; no doc workaround needed.
2026-08-20 15:36:17 +02:00
Nemanja Nedeljkovic 6507b8f36b feat(pm5): hf tune --rgb / lf tune --rgb - antenna RGB as a tuning meter
Adds an opt-in `--rgb` flag to the continuous `hf tune` / `lf tune` commands that
mirrors the antenna tuning level on the PM5 antenna RGB LED: blue = low, green =
mid, red = high, tracking the on-screen bar so you can find coupling (e.g. an
implant) by feel without watching the screen.

The colour is computed client-side from the same per-iteration voltage / running
peak the bar uses (so it matches the bar and auto-scales), and pushed to the
device via a new dumb CMD_PM5_RGB_SET {r,g,b}. That command is handled (#ifdef
PM5) by a dedicated AT32 RGB HAL module, common_arm/rgb/{rgb_apis.h,
rgb_hw_at32.c} (RgbLedSet(), I2C controller @ 0x48), wired into the armsrc
Makefile/CMake as SRC_RGB for PM5 only - so no other platform is affected and no
hardware code lands in shared files.
2026-08-20 11:55:55 +02:00
Nemanja Nedeljkovic b81966c419 fix(pm5): select an ERTC clock before the BPR write
The AT32 battery-domain helper at32_bpr_write_dt1() enabled the ERTC (ertcen)
but never selected an ERTC clock source (ertcsel stayed NOCLK). Writing the
ERTC write-protection register (ERTC->wp) requires the ERTC to be clocked, so
with no source the write stalled the APB once the CPU ran at the full PLL clock
(288MHz, 144MHz APB); it only survived on the slow HICK clock.

The bootrom reaches this via check_goto_flash_mode() -> system_bpr_chk_clear()
while reading/clearing the "enter flash mode" magic the OS sets on a software
reset. That runs after ConfigSystemClocks() (the button branch needs
SpinDelayUs()/the timer clock, so the clock must be up first), i.e. at 288MHz,
so the bootrom hung and the device never re-enumerated into the bootloader
until a physical USB replug.

Fix: select the ERTC clock (HEXT/20, as the tick HAL does) before touching the
ERTC registers. HEXT is running by the time this executes, so the wp write no
longer stalls. The fix is contained in the AT32 HAL (sys_hw_at32.c, which only
builds for AT32/PM5); the shared bootrom flow and its ConfigSystemClocks()-first
ordering (needed by AT91/RDV4 SpinDelayUs) are unchanged.
2026-08-19 19:33:01 +02:00
dxl 86dfdfff89 Fixed a bug in reading hitagU and hitagS on RDV4. 2026-08-19 18:53:35 +02:00
Philippe Teuwen 4e684cb4d3 PM5: Detect incompatible PLATFORM_EXTRAS 2026-08-19 17:52:15 +02:00
Philippe Teuwen 827fce4839 Use ARRAYLEN when possible 2026-08-19 15:51:54 +02:00
Philippe Teuwen 5518e6af77 Fix Flash_UniqueID 2026-08-19 15:51:54 +02:00
dxl a286002d27 Refactor ISO14443A DMA RX to use cross-platform buffer helpers
Replace the hard-coded AT91 PDC register access in SniffIso14443a() with
cross-platform helpers for the RX double-buffer status/refresh, so the
sniffer no longer depends on AT91-specific registers.

- Add FPGA_SSC_DMA_RX_{Primary,Secondary}_Done and
  FPGA_SSC_DMA_RX_Refresh_{Both,Secondary} to fpga_apis.h.
- AT91: primary maps to PDC RPR/RCR, secondary ("next") to RNPR/RNCR.
- AT32: no double buffer, so the primary path is a no-op and all re-arming
  is done through the secondary (single-shot DMA re-arm).
2026-08-19 15:51:53 +02:00
dxl d286946d0f Update the Makefile support for ARM 2026-08-19 15:51:53 +02:00
DXL 0191fb78ec CMake has been implemented to manage ARM projects.
Add the mkversion bat and ps1 implementation to the Windows platform compilation.
Make armlib a static library so that bootrom and armsrc can be reused.
2026-08-19 15:51:50 +02:00
dxl 36f1c7e44c Make common_arm to hardware abstraction layer. 2026-08-19 15:32:39 +02:00
Philippe Teuwen 6efff9a6ae ARM: tidy compilation flags 2026-04-28 13:00:42 +02:00
Philippe Teuwen 961e59b5d1 Revert "Release v4.21611 - BREAKMEIFYOUCAN!"
This reverts commit aaacc75e9f.
2026-04-14 10:19:30 +02:00
Philippe Teuwen aaacc75e9f Release v4.21611 - BREAKMEIFYOUCAN! 2026-04-14 10:19:30 +02:00
iceman1001 c33f10f56b style 2026-04-03 11:46:58 +07:00
iceman1001 6da8aa2e98 style 2026-04-03 11:27:38 +07:00
kormax 6c4b995e21 Introduce 'GetTickCountLabel' for detecting RTCC reconfigurations 2026-03-31 20:42:15 +03:00
Sujit Konapur 0577f6f321 fix: use strip() when comparing PLATFORM_DEFS to avoid spurious rebuilds
PLATFORM_DEFS is built with += on an initially empty variable, which
produces a leading space in GNU make. The cached value written to
.Makefile.options.cache has no leading space, so the ifneq comparison
always evaluates to true, causing PLATFORM_CHANGED=true on every
invocation and triggering a clean of bootrom/armsrc/recovery after
every build.
2026-03-09 23:26:45 -07:00
Philippe Teuwen 64247b33b1 Init PLATFORM_DEFS 2026-03-01 21:00:05 +01:00
iceman1001 338ab9c81a Revert "Release v4.21128 - Permafrost"
This reverts commit b10235b03b.
2026-02-25 16:15:01 +01:00
iceman1001 b10235b03b Release v4.21128 - Permafrost 2026-02-25 16:15:01 +01:00
Aaron Tulino (Aaronjamt) c0e82539f2 [hf seos] Simulate support 2025-12-21 04:26:44 -07:00