mirror of
https://github.com/RfidResearchGroup/proxmark3.git
synced 2026-10-07 03:17:59 +00:00
cep_attach_poll() (and cep_init()) call I2C_BufferReadRaw()/I2C_init(true), which spin on the shared ticks timer via WaitUS()/WaitMS(). That timer is routinely stopped with StopTicks() by LF/HF protocol code once it's done with precision timing (em4x50.c, legicrf.c, hitag_common.c, lfsampling.c, etc). cep_attach_poll() runs unconditionally every 50ms in the main loop with no idea whether the timer is currently running - if its poll lands in a window where something just called StopTicks(), WaitTicks()'s `while (GetTicks() < target)` spins forever on a frozen counter, hanging the entire main loop irrecoverably. `hf search` cycles through many such probes, giving this poll many chances to land in that window, matching the reported "hf search hangs the PM5, needs a battery pull" regression - and since the poll runs regardless of Flipper attachment, merely compiling in WITH_CEP was enough to trigger it. bwm_lowbatt_poll() (armsrc/bwm_charger.c) is the same shape of periodic main-loop I2C poller and already guards against exactly this by calling StartTicks(); I2C_init(true); itself immediately before every I2C access. Mirror that convention in cep_attach_poll() and cep_init(). Re-enables WITH_CEP as the PM5 default (reverts f88880fc6's temporary disable) now that the underlying bug is fixed. SKIP_CEP=1 remains available for anyone who wants to opt out at build time regardless. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>