proxmark3/include/pm3_cmd.h

930 lines
38 KiB
C
Raw Normal View History

//-----------------------------------------------------------------------------
// Jonathan Westhues, Mar 2006
// Edits by Gerhard de Koning Gans, Sep 2007
//
// This code is licensed to you under the terms of the GNU GPL, version 2 or,
// at your option, any later version. See the LICENSE.txt file for the text of
// the license.
//-----------------------------------------------------------------------------
// Definitions for all the types of commands that may be sent over USB; our
// own protocol.
//-----------------------------------------------------------------------------
2019-05-04 17:36:35 +08:00
#ifndef __PM3_CMD_H
#define __PM3_CMD_H
2017-01-21 18:26:37 +08:00
#include "common.h"
2019-04-24 05:36:36 +08:00
// Use it e.g. when using slow links such as BT
#define USART_SLOW_LINK
#define PM3_CMD_DATA_SIZE 512
#define PM3_CMD_DATA_SIZE_MIX ( PM3_CMD_DATA_SIZE - 3 * sizeof(uint64_t) )
2012-12-05 07:39:18 +08:00
typedef struct {
2019-03-10 07:00:59 +08:00
uint64_t cmd;
uint64_t arg[3];
union {
uint8_t asBytes[PM3_CMD_DATA_SIZE];
uint32_t asDwords[PM3_CMD_DATA_SIZE / 4];
2019-03-10 07:00:59 +08:00
} d;
2019-04-18 18:43:35 +08:00
} PACKED PacketCommandOLD;
typedef struct {
uint32_t magic;
uint16_t length : 15; // length of the variable part, 0 if none.
bool ng : 1;
2019-04-18 06:12:52 +08:00
uint16_t cmd;
2019-04-18 18:43:35 +08:00
} PACKED PacketCommandNGPreamble;
2019-04-19 03:49:32 +08:00
#define COMMANDNG_PREAMBLE_MAGIC 0x61334d50 // PM3a
#define COMMANDNG_POSTAMBLE_MAGIC 0x3361 // a3
typedef struct {
2019-04-17 02:06:32 +08:00
uint16_t crc;
2019-04-18 18:43:35 +08:00
} PACKED PacketCommandNGPostamble;
2019-04-18 06:12:52 +08:00
// For internal usage
2019-04-18 03:30:01 +08:00
typedef struct {
2019-04-18 06:12:52 +08:00
uint16_t cmd;
uint16_t length;
uint32_t magic; // NG
uint16_t crc; // NG
uint64_t oldarg[3]; // OLD
union {
uint8_t asBytes[PM3_CMD_DATA_SIZE];
uint32_t asDwords[PM3_CMD_DATA_SIZE / 4];
2019-04-18 06:12:52 +08:00
} data;
bool ng; // does it store NG data or OLD data?
} PacketCommandNG;
2019-04-18 06:12:52 +08:00
// For reception and CRC check
typedef struct {
2019-04-18 18:43:35 +08:00
PacketCommandNGPreamble pre;
uint8_t data[PM3_CMD_DATA_SIZE];
2019-04-18 18:43:35 +08:00
PacketCommandNGPostamble foopost; // Probably not at that offset!
} PACKED PacketCommandNGRaw;
typedef struct {
uint64_t cmd;
uint64_t arg[3];
union {
uint8_t asBytes[PM3_CMD_DATA_SIZE];
uint32_t asDwords[PM3_CMD_DATA_SIZE / 4];
2019-04-18 18:43:35 +08:00
} d;
} PACKED PacketResponseOLD;
2019-04-18 06:12:52 +08:00
typedef struct {
uint32_t magic;
uint16_t length : 15; // length of the variable part, 0 if none.
bool ng : 1;
int16_t status;
2019-04-18 05:44:48 +08:00
uint16_t cmd;
2019-04-18 18:43:35 +08:00
} PACKED PacketResponseNGPreamble;
2019-04-19 03:49:32 +08:00
#define RESPONSENG_PREAMBLE_MAGIC 0x62334d50 // PM3b
#define RESPONSENG_POSTAMBLE_MAGIC 0x3362 // b3
typedef struct {
uint16_t crc;
2019-04-18 18:43:35 +08:00
} PACKED PacketResponseNGPostamble;
2019-04-18 05:44:48 +08:00
// For internal usage
2019-04-18 03:30:01 +08:00
typedef struct {
2019-04-18 05:44:48 +08:00
uint16_t cmd;
uint16_t length;
uint32_t magic; // NG
int16_t status; // NG
uint16_t crc; // NG
uint64_t oldarg[3]; // OLD
union {
uint8_t asBytes[PM3_CMD_DATA_SIZE];
uint32_t asDwords[PM3_CMD_DATA_SIZE / 4];
2019-04-18 05:44:48 +08:00
} data;
bool ng; // does it store NG data or OLD data?
} PacketResponseNG;
2019-04-18 05:44:48 +08:00
// For reception and CRC check
typedef struct {
2019-04-18 18:43:35 +08:00
PacketResponseNGPreamble pre;
uint8_t data[PM3_CMD_DATA_SIZE];
2019-04-18 18:43:35 +08:00
PacketResponseNGPostamble foopost; // Probably not at that offset!
} PACKED PacketResponseNGRaw;
2019-04-18 05:44:48 +08:00
// A struct used to send sample-configs over USB
2019-03-10 07:00:59 +08:00
typedef struct {
int8_t decimation;
int8_t bits_per_sample;
int8_t averaging;
int16_t divisor;
int16_t trigger_threshold;
int32_t samples_to_skip;
2019-10-12 05:14:57 +08:00
bool verbose;
2019-07-28 03:15:43 +08:00
} PACKED sample_config;
2020-05-19 08:14:43 +08:00
// A struct used to send hf14a-configs over USB
typedef struct {
2020-09-07 16:24:04 +08:00
int8_t forceanticol; // 0:auto 1:force executing anticol 2:force skipping anticol
int8_t forcebcc; // 0:expect valid BCC 1:force using computed BCC 2:force using card BCC
int8_t forcecl2; // 0:auto 1:force executing CL2 2:force skipping CL2
int8_t forcecl3; // 0:auto 1:force executing CL3 2:force skipping CL3
2020-09-07 21:09:18 +08:00
int8_t forcerats; // 0:auto 1:force executing RATS 2:force skipping RATS
} PACKED hf14a_config;
2020-07-13 18:28:30 +08:00
// Tracelog Header struct
2020-05-19 08:14:43 +08:00
typedef struct {
uint32_t timestamp;
uint16_t duration;
uint16_t data_len : 15;
bool isResponse : 1;
uint8_t frame[];
// data_len bytes of data
// ceil(data_len/8) bytes of parity
} PACKED tracelog_hdr_t;
#define TRACELOG_HDR_LEN sizeof(tracelog_hdr_t)
#define TRACELOG_PARITY_LEN(x) (((x)->data_len - 1) / 8 + 1)
2021-05-20 16:07:51 +08:00
// T55XX - Extended to support 1 of 4 timing
2019-07-23 07:50:28 +08:00
typedef struct {
2019-07-28 03:15:43 +08:00
uint16_t start_gap;
uint16_t write_gap;
uint16_t write_0;
uint16_t write_1;
uint16_t read_gap;
uint16_t write_2;
uint16_t write_3;
2019-07-23 07:50:28 +08:00
} t55xx_config_t;
2019-07-28 03:15:43 +08:00
2021-05-20 16:07:51 +08:00
// T55XX - This setup will allow for the 4 downlink modes "m" as well as other items if needed.
2019-07-23 07:50:28 +08:00
// Given the one struct we can then read/write to flash/client in one go.
typedef struct {
2019-07-24 05:43:30 +08:00
t55xx_config_t m[4]; // mode
2019-07-28 03:15:43 +08:00
} t55xx_configurations_t;
2021-05-20 16:07:51 +08:00
// Capabilities struct to keep track of what functions was compiled in the device firmware
typedef struct {
uint8_t version;
uint32_t baudrate;
uint32_t bigbuf_size;
2019-05-08 07:35:51 +08:00
bool via_fpc : 1;
bool via_usb : 1;
2019-05-01 23:19:37 +08:00
// rdv4
2019-05-08 07:35:51 +08:00
bool compiled_with_flash : 1;
bool compiled_with_smartcard : 1;
bool compiled_with_fpc_usart : 1;
bool compiled_with_fpc_usart_dev : 1;
bool compiled_with_fpc_usart_host : 1;
2019-05-01 23:19:37 +08:00
// lf
2019-05-08 07:35:51 +08:00
bool compiled_with_lf : 1;
bool compiled_with_hitag : 1;
2020-06-15 20:30:18 +08:00
bool compiled_with_em4x50 : 1;
bool compiled_with_em4x70 : 1;
2019-05-01 23:19:37 +08:00
// hf
2019-05-08 07:35:51 +08:00
bool compiled_with_hfsniff : 1;
bool compiled_with_hfplot : 1;
2019-05-08 07:35:51 +08:00
bool compiled_with_iso14443a : 1;
bool compiled_with_iso14443b : 1;
bool compiled_with_iso15693 : 1;
bool compiled_with_felica : 1;
bool compiled_with_legicrf : 1;
bool compiled_with_iclass : 1;
2019-08-04 03:17:52 +08:00
bool compiled_with_nfcbarcode : 1;
2019-05-01 23:19:37 +08:00
// misc
2019-05-08 07:35:51 +08:00
bool compiled_with_lcd : 1;
2019-05-01 23:19:37 +08:00
// rdv4
2019-05-08 07:35:51 +08:00
bool hw_available_flash : 1;
bool hw_available_smartcard : 1;
} PACKED capabilities_t;
#define CAPABILITIES_VERSION 5
extern capabilities_t g_pm3_capabilities;
// For CMD_LF_T55XX_WRITEBL
typedef struct {
uint32_t data;
uint32_t pwd;
uint8_t blockno;
uint8_t flags;
} PACKED t55xx_write_block_t;
2019-10-09 19:03:23 +08:00
typedef struct {
uint8_t data[128];
uint8_t bitlen;
uint32_t time;
} PACKED t55xx_test_block_t;
2019-09-15 07:17:47 +08:00
// For CMD_LF_HID_SIMULATE (FSK)
typedef struct {
uint32_t hi2;
uint32_t hi;
uint32_t lo;
uint8_t longFMT;
bool Q5;
bool EM;
2019-09-15 07:17:47 +08:00
} PACKED lf_hidsim_t;
// For CMD_LF_FSK_SIMULATE (FSK)
typedef struct {
uint8_t fchigh;
uint8_t fclow;
uint8_t separator;
uint8_t clock;
uint8_t data[];
} PACKED lf_fsksim_t;
// For CMD_LF_ASK_SIMULATE (ASK)
2019-05-24 19:06:08 +08:00
typedef struct {
uint8_t encoding;
uint8_t invert;
uint8_t separator;
uint8_t clock;
uint8_t data[];
} PACKED lf_asksim_t;
// For CMD_LF_PSK_SIMULATE (PSK)
2019-05-24 21:11:30 +08:00
typedef struct {
uint8_t carrier;
uint8_t invert;
uint8_t clock;
uint8_t data[];
} PACKED lf_psksim_t;
// For CMD_LF_NRZ_SIMULATE (NRZ)
typedef struct {
uint8_t invert;
uint8_t separator;
uint8_t clock;
uint8_t data[];
} PACKED lf_nrzsim_t;
typedef struct {
uint8_t type;
uint16_t len;
uint8_t *data;
} PACKED lf_hitag_t;
2019-05-29 01:20:56 +08:00
typedef struct {
2019-06-08 03:40:33 +08:00
uint8_t blockno;
uint8_t keytype;
uint8_t key[6];
2019-05-29 01:20:56 +08:00
} PACKED mf_readblock_t;
2019-08-29 03:12:18 +08:00
typedef struct {
2019-08-30 16:45:52 +08:00
uint8_t sectorcnt;
uint8_t keytype;
} PACKED mfc_eload_t;
2019-05-24 21:11:30 +08:00
typedef struct {
uint8_t status;
uint8_t CSN[8];
uint8_t CONFIG[8];
uint8_t CC[8];
uint8_t AIA[8];
} PACKED iclass_reader_t;
typedef struct {
const char *desc;
const char *value;
} PACKED ecdsa_publickey_t;
2020-07-20 02:45:47 +08:00
// iCLASS auth request data structure
// used with read block, dump, write block
2020-07-20 02:45:47 +08:00
typedef struct {
uint8_t key[8];
bool use_raw;
bool use_elite;
bool use_credit_key;
bool use_replay;
bool send_reply;
bool do_auth;
uint8_t blockno;
2020-07-20 02:45:47 +08:00
} PACKED iclass_auth_req_t;
// iCLASS read block response data structure
2020-07-20 02:45:47 +08:00
typedef struct {
bool isOK;
uint8_t div_key[8];
uint8_t mac[4];
uint8_t data[8];
} PACKED iclass_readblock_resp_t;
// iCLASS dump data structure
typedef struct {
iclass_auth_req_t req;
uint8_t start_block;
uint8_t end_block;
} PACKED iclass_dump_req_t;
// iCLASS write block request data structure
typedef struct {
iclass_auth_req_t req;
uint8_t data[8];
} PACKED iclass_writeblock_req_t;
// iCLASS dump data structure
typedef struct {
uint8_t blockno;
uint8_t data[8];
} PACKED iclass_restore_item_t;
typedef struct {
iclass_auth_req_t req;
uint8_t item_cnt;
2020-10-20 07:00:23 +08:00
iclass_restore_item_t blocks[];
} PACKED iclass_restore_req_t;
2021-05-04 02:01:12 +08:00
typedef struct iclass_premac {
uint8_t mac[4];
} PACKED iclass_premac_t;
2021-05-04 02:01:12 +08:00
typedef struct {
bool use_credit_key;
uint8_t count;
iclass_premac_t items[];
} PACKED iclass_chk_t;
// iclass / picopass chip config structures and shared routines
typedef struct {
uint8_t app_limit; //[8]
uint8_t otp[2]; //[9-10]
uint8_t block_writelock;//[11]
uint8_t chip_config; //[12]
uint8_t mem_config; //[13]
uint8_t eas; //[14]
uint8_t fuses; //[15]
} PACKED picopass_conf_block_t;
// iCLASS secure mode memory mapping
typedef struct {
uint8_t csn[8];
picopass_conf_block_t conf;
uint8_t epurse[8];
uint8_t key_d[8];
uint8_t key_c[8];
uint8_t app_issuer_area[8];
} PACKED picopass_hdr_t;
// iCLASS non-secure mode memory mapping
typedef struct {
uint8_t csn[8];
picopass_conf_block_t conf;
uint8_t app_issuer_area[8];
} PACKED picopass_ns_hdr_t;
2020-07-20 02:45:47 +08:00
2020-10-16 01:29:54 +08:00
typedef struct {
uint16_t delay_us;
bool on;
bool off;
} PACKED tearoff_params_t;
// when writing to SPIFFS
typedef struct {
bool append : 1;
uint16_t bytes_in_packet : 15;
uint8_t fnlen;
uint8_t fn[32];
uint8_t data[];
} PACKED flashmem_write_t;
2021-05-02 01:01:15 +08:00
// when CMD_FLASHMEM_WRITE old flashmem commands
typedef struct {
uint32_t startidx;
uint16_t len;
uint8_t data[PM3_CMD_DATA_SIZE - sizeof(uint32_t) - sizeof(uint16_t)];
} PACKED flashmem_old_write_t;
//-----------------------------------------------------------------------------
// ISO 7618 Smart Card
//-----------------------------------------------------------------------------
typedef struct {
uint8_t atr_len;
uint8_t atr[50];
} PACKED smart_card_atr_t;
typedef enum SMARTCARD_COMMAND {
SC_CONNECT = (1 << 0),
SC_NO_DISCONNECT = (1 << 1),
SC_RAW = (1 << 2),
SC_SELECT = (1 << 3),
SC_RAW_T0 = (1 << 4),
SC_CLEARLOG = (1 << 5),
SC_LOG = (1 << 6),
} smartcard_command_t;
typedef struct {
uint8_t flags;
uint16_t len;
uint8_t data[];
} PACKED smart_card_raw_t;
// For the bootloader
#define CMD_DEVICE_INFO 0x0000
//#define CMD_SETUP_WRITE 0x0001
#define CMD_FINISH_WRITE 0x0003
#define CMD_HARDWARE_RESET 0x0004
#define CMD_START_FLASH 0x0005
#define CMD_CHIP_INFO 0x0006
#define CMD_BL_VERSION 0x0007
#define CMD_NACK 0x00fe
#define CMD_ACK 0x00ff
// For general mucking around
#define CMD_DEBUG_PRINT_STRING 0x0100
#define CMD_DEBUG_PRINT_INTEGERS 0x0101
#define CMD_DEBUG_PRINT_BYTES 0x0102
#define CMD_LCD_RESET 0x0103
#define CMD_LCD 0x0104
#define CMD_BUFF_CLEAR 0x0105
#define CMD_READ_MEM 0x0106
#define CMD_VERSION 0x0107
2019-03-10 01:41:30 +08:00
#define CMD_STATUS 0x0108
#define CMD_PING 0x0109
#define CMD_DOWNLOAD_EML_BIGBUF 0x0110
#define CMD_DOWNLOADED_EML_BIGBUF 0x0111
#define CMD_CAPABILITIES 0x0112
#define CMD_QUIT_SESSION 0x0113
2019-06-06 17:31:47 +08:00
#define CMD_SET_DBGMODE 0x0114
#define CMD_STANDALONE 0x0115
#define CMD_WTX 0x0116
#define CMD_TIA 0x0117
#define CMD_BREAK_LOOP 0x0118
2020-10-09 07:52:42 +08:00
#define CMD_SET_TEAROFF 0x0119
2018-09-06 11:24:50 +08:00
// RDV40, Flash memory operations
2019-03-10 01:41:30 +08:00
#define CMD_FLASHMEM_WRITE 0x0121
#define CMD_FLASHMEM_WIPE 0x0122
#define CMD_FLASHMEM_DOWNLOAD 0x0123
#define CMD_FLASHMEM_DOWNLOADED 0x0124
#define CMD_FLASHMEM_INFO 0x0125
2018-09-06 11:24:50 +08:00
#define CMD_FLASHMEM_SET_SPIBAUDRATE 0x0126
2019-07-24 03:33:52 +08:00
// RDV40, High level flashmem SPIFFS Manipulation
// ALL function will have a lazy or Safe version
// that will be handled as argument of safety level [0..2] respectiveley normal / lazy / safe
// However as how design is, MOUNT and UNMOUNT only need/have lazy as safest level so a safe level will still execute a lazy version
// see spiffs.c for more about the normal/lazy/safety information)
#define CMD_SPIFFS_MOUNT 0x0130
#define CMD_SPIFFS_UNMOUNT 0x0131
#define CMD_SPIFFS_WRITE 0x0132
2020-08-08 18:33:12 +08:00
// We take +0x1000 when having a variant of similar function (todo : make it an argument!)
#define CMD_SPIFFS_APPEND 0x1132
#define CMD_SPIFFS_READ 0x0133
2020-08-08 18:33:12 +08:00
//We use no open/close instruction, as they are handled internally.
#define CMD_SPIFFS_REMOVE 0x0134
#define CMD_SPIFFS_RM CMD_SPIFFS_REMOVE
#define CMD_SPIFFS_RENAME 0x0135
#define CMD_SPIFFS_MV CMD_SPIFFS_RENAME
#define CMD_SPIFFS_COPY 0x0136
#define CMD_SPIFFS_CP CMD_SPIFFS_COPY
#define CMD_SPIFFS_STAT 0x0137
#define CMD_SPIFFS_FSTAT 0x0138
#define CMD_SPIFFS_INFO 0x0139
#define CMD_SPIFFS_FORMAT CMD_FLASHMEM_WIPE
2020-08-08 18:33:12 +08:00
#define CMD_SPIFFS_WIPE 0x013A
// This take a +0x2000 as they are high level helper and special functions
// As the others, they may have safety level argument if it makkes sense
#define CMD_SPIFFS_PRINT_TREE 0x2130
#define CMD_SPIFFS_GET_TREE 0x2131
#define CMD_SPIFFS_TEST 0x2132
#define CMD_SPIFFS_PRINT_FSINFO 0x2133
#define CMD_SPIFFS_DOWNLOAD 0x2134
#define CMD_SPIFFS_DOWNLOADED 0x2135
2019-08-13 23:51:11 +08:00
#define CMD_SPIFFS_CHECK 0x3000
// more ?
2018-06-23 12:39:23 +08:00
// RDV40, Smart card operations
2019-03-10 01:41:30 +08:00
#define CMD_SMART_RAW 0x0140
#define CMD_SMART_UPGRADE 0x0141
#define CMD_SMART_UPLOAD 0x0142
#define CMD_SMART_ATR 0x0143
#define CMD_SMART_SETBAUD 0x0144
#define CMD_SMART_SETCLOCK 0x0145
2018-06-23 12:39:23 +08:00
// RDV40, FPC USART
#define CMD_USART_RX 0x0160
#define CMD_USART_TX 0x0161
#define CMD_USART_TXRX 0x0162
2019-05-15 08:15:19 +08:00
#define CMD_USART_CONFIG 0x0163
// For low-frequency tags
#define CMD_LF_TI_READ 0x0202
#define CMD_LF_TI_WRITE 0x0203
#define CMD_LF_ACQ_RAW_ADC 0x0205
#define CMD_LF_MOD_THEN_ACQ_RAW_ADC 0x0206
#define CMD_DOWNLOAD_BIGBUF 0x0207
#define CMD_DOWNLOADED_BIGBUF 0x0208
#define CMD_LF_UPLOAD_SIM_SAMPLES 0x0209
#define CMD_LF_SIMULATE 0x020A
#define CMD_LF_HID_WATCH 0x020B
#define CMD_LF_HID_SIMULATE 0x020C
#define CMD_LF_SET_DIVISOR 0x020D
#define CMD_LF_SIMULATE_BIDIR 0x020E
#define CMD_SET_ADC_MUX 0x020F
#define CMD_LF_HID_CLONE 0x0210
#define CMD_LF_EM410X_WRITE 0x0211
#define CMD_LF_T55XX_READBL 0x0214
#define CMD_LF_T55XX_WRITEBL 0x0215
#define CMD_LF_T55XX_RESET_READ 0x0216
#define CMD_LF_PCF7931_READ 0x0217
#define CMD_LF_PCF7931_WRITE 0x0223
2020-10-19 05:46:36 +08:00
#define CMD_LF_EM4X_LOGIN 0x0229
#define CMD_LF_EM4X_READWORD 0x0218
#define CMD_LF_EM4X_WRITEWORD 0x0219
#define CMD_LF_EM4X_PROTECTWORD 0x021B
2020-10-20 19:18:43 +08:00
#define CMD_LF_EM4X_BF 0x022A
#define CMD_LF_IO_WATCH 0x021A
#define CMD_LF_EM410X_WATCH 0x021C
2020-06-15 20:30:18 +08:00
#define CMD_LF_EM4X50_INFO 0x0240
#define CMD_LF_EM4X50_WRITE 0x0241
#define CMD_LF_EM4X50_WRITEPWD 0x0242
2020-06-29 03:38:19 +08:00
#define CMD_LF_EM4X50_READ 0x0243
2020-09-27 19:42:27 +08:00
#define CMD_LF_EM4X50_BRUTE 0x0245
2020-09-28 05:22:51 +08:00
#define CMD_LF_EM4X50_LOGIN 0x0246
2020-10-27 05:10:48 +08:00
#define CMD_LF_EM4X50_SIM 0x0250
2020-11-30 06:57:04 +08:00
#define CMD_LF_EM4X50_READER 0x0251
#define CMD_LF_EM4X50_ESET 0x0252
#define CMD_LF_EM4X50_CHK 0x0253
#define CMD_LF_EM4X70_INFO 0x0260
2020-12-12 12:26:17 +08:00
#define CMD_LF_EM4X70_WRITE 0x0261
#define CMD_LF_EM4X70_UNLOCK 0x0262
2020-12-12 22:59:30 +08:00
#define CMD_LF_EM4X70_AUTH 0x0263
#define CMD_LF_EM4X70_WRITEPIN 0x0264
#define CMD_LF_EM4X70_WRITEKEY 0x0265
2019-03-12 20:15:39 +08:00
// Sampling configuration for LF reader/sniffer
#define CMD_LF_SAMPLING_SET_CONFIG 0x021D
#define CMD_LF_FSK_SIMULATE 0x021E
#define CMD_LF_ASK_SIMULATE 0x021F
#define CMD_LF_PSK_SIMULATE 0x0220
#define CMD_LF_NRZ_SIMULATE 0x0232
#define CMD_LF_AWID_WATCH 0x0221
#define CMD_LF_VIKING_CLONE 0x0222
#define CMD_LF_T55XX_WAKEUP 0x0224
#define CMD_LF_COTAG_READ 0x0225
#define CMD_LF_T55XX_SET_CONFIG 0x0226
#define CMD_LF_SAMPLING_PRINT_CONFIG 0x0227
#define CMD_LF_SAMPLING_GET_CONFIG 0x0228
#define CMD_LF_T55XX_CHK_PWDS 0x0230
2019-10-09 19:03:23 +08:00
#define CMD_LF_T55XX_DANGERRAW 0x0231
/* CMD_SET_ADC_MUX: ext1 is 0 for lopkd, 1 for loraw, 2 for hipkd, 3 for hiraw */
// For the 13.56 MHz tags
#define CMD_HF_ISO15693_ACQ_RAW_ADC 0x0300
#define CMD_HF_SRI_READ 0x0303
#define CMD_HF_ISO14443B_COMMAND 0x0305
#define CMD_HF_ISO15693_READER 0x0310
#define CMD_HF_ISO15693_SIMULATE 0x0311
2020-07-08 15:45:49 +08:00
#define CMD_HF_ISO15693_SNIFF 0x0312
#define CMD_HF_ISO15693_COMMAND 0x0313
#define CMD_HF_ISO15693_FINDAFI 0x0315
2020-08-17 14:52:24 +08:00
#define CMD_HF_ISO15693_CSETUID 0x0316
2021-05-04 02:01:12 +08:00
#define CMD_HF_ISO15693_SLIX_L_DISABLE_PRIVACY 0x0317
2020-08-17 14:52:24 +08:00
#define CMD_LF_SNIFF_RAW_ADC 0x0360
// For Hitag2 transponders
#define CMD_LF_HITAG_SNIFF 0x0370
#define CMD_LF_HITAG_SIMULATE 0x0371
#define CMD_LF_HITAG_READER 0x0372
// For HitagS
#define CMD_LF_HITAGS_TEST_TRACES 0x0367
#define CMD_LF_HITAGS_SIMULATE 0x0368
#define CMD_LF_HITAGS_READ 0x0373
#define CMD_LF_HITAGS_WRITE 0x0375
#define CMD_LF_HITAG_ELOAD 0x0376
#define CMD_HF_ISO14443A_ANTIFUZZ 0x0380
#define CMD_HF_ISO14443B_SIMULATE 0x0381
#define CMD_HF_ISO14443B_SNIFF 0x0382
#define CMD_HF_ISO14443A_SNIFF 0x0383
#define CMD_HF_ISO14443A_SIMULATE 0x0384
#define CMD_HF_ISO14443A_READER 0x0385
#define CMD_HF_LEGIC_SIMULATE 0x0387
#define CMD_HF_LEGIC_READER 0x0388
#define CMD_HF_LEGIC_WRITER 0x0389
#define CMD_HF_EPA_COLLECT_NONCE 0x038A
#define CMD_HF_EPA_REPLAY 0x038B
#define CMD_HF_LEGIC_INFO 0x03BC
#define CMD_HF_LEGIC_ESET 0x03BD
// iCLASS / Picopass
#define CMD_HF_ICLASS_READCHECK 0x038F
#define CMD_HF_ICLASS_DUMP 0x0391
#define CMD_HF_ICLASS_SNIFF 0x0392
#define CMD_HF_ICLASS_SIMULATE 0x0393
#define CMD_HF_ICLASS_READER 0x0394
#define CMD_HF_ICLASS_READBL 0x0396
#define CMD_HF_ICLASS_WRITEBL 0x0397
#define CMD_HF_ICLASS_EML_MEMSET 0x0398
#define CMD_HF_ICLASS_CHKKEYS 0x039A
#define CMD_HF_ICLASS_RESTORE 0x039B
// For ISO1092 / FeliCa
#define CMD_HF_FELICA_SIMULATE 0x03A0
#define CMD_HF_FELICA_SNIFF 0x03A1
#define CMD_HF_FELICA_COMMAND 0x03A2
2017-10-21 02:27:44 +08:00
//temp
#define CMD_HF_FELICALITE_DUMP 0x03AA
#define CMD_HF_FELICALITE_SIMULATE 0x03AB
2017-10-10 20:33:27 +08:00
// For 14a config
#define CMD_HF_ISO14443A_PRINT_CONFIG 0x03B0
#define CMD_HF_ISO14443A_GET_CONFIG 0x03B1
#define CMD_HF_ISO14443A_SET_CONFIG 0x03B2
// For measurements of the antenna tuning
#define CMD_MEASURE_ANTENNA_TUNING 0x0400
2019-05-14 14:25:26 +08:00
#define CMD_MEASURE_ANTENNA_TUNING_HF 0x0401
2019-09-24 19:06:43 +08:00
#define CMD_MEASURE_ANTENNA_TUNING_LF 0x0402
#define CMD_LISTEN_READER_FIELD 0x0420
#define CMD_HF_DROPFIELD 0x0430
// For direct FPGA control
#define CMD_FPGA_MAJOR_MODE_OFF 0x0500
// For mifare commands
#define CMD_HF_MIFARE_EML_MEMCLR 0x0601
#define CMD_HF_MIFARE_EML_MEMSET 0x0602
#define CMD_HF_MIFARE_EML_MEMGET 0x0603
#define CMD_HF_MIFARE_EML_LOAD 0x0604
// magic chinese card commands
#define CMD_HF_MIFARE_CSETBL 0x0605
#define CMD_HF_MIFARE_CGETBL 0x0606
#define CMD_HF_MIFARE_CIDENT 0x0607
#define CMD_HF_MIFARE_SIMULATE 0x0610
#define CMD_HF_MIFARE_READER 0x0611
#define CMD_HF_MIFARE_NESTED 0x0612
#define CMD_HF_MIFARE_ACQ_ENCRYPTED_NONCES 0x0613
#define CMD_HF_MIFARE_ACQ_NONCES 0x0614
#define CMD_HF_MIFARE_STATIC_NESTED 0x0615
#define CMD_HF_MIFARE_READBL 0x0620
#define CMD_HF_MIFAREU_READBL 0x0720
#define CMD_HF_MIFARE_READSC 0x0621
#define CMD_HF_MIFAREU_READCARD 0x0721
#define CMD_HF_MIFARE_WRITEBL 0x0622
#define CMD_HF_MIFAREU_WRITEBL 0x0722
#define CMD_HF_MIFAREU_WRITEBL_COMPAT 0x0723
#define CMD_HF_MIFARE_CHKKEYS 0x0623
#define CMD_HF_MIFARE_SETMOD 0x0624
#define CMD_HF_MIFARE_CHKKEYS_FAST 0x0625
#define CMD_HF_MIFARE_CHKKEYS_FILE 0x0626
#define CMD_HF_MIFARE_SNIFF 0x0630
2019-10-12 05:14:57 +08:00
#define CMD_HF_MIFARE_MFKEY 0x0631
#define CMD_HF_MIFARE_PERSONALIZE_UID 0x0632
2014-09-12 05:23:46 +08:00
//ultralightC
#define CMD_HF_MIFAREUC_AUTH 0x0724
//0x0725 and 0x0726 no longer used
#define CMD_HF_MIFAREUC_SETPWD 0x0727
2014-09-12 05:23:46 +08:00
// mifare desfire
#define CMD_HF_DESFIRE_READBL 0x0728
#define CMD_HF_DESFIRE_WRITEBL 0x0729
#define CMD_HF_DESFIRE_AUTH1 0x072a
#define CMD_HF_DESFIRE_AUTH2 0x072b
#define CMD_HF_DESFIRE_READER 0x072c
#define CMD_HF_DESFIRE_INFO 0x072d
#define CMD_HF_DESFIRE_COMMAND 0x072e
#define CMD_HF_MIFARE_NACK_DETECT 0x0730
#define CMD_HF_MIFARE_STATIC_NONCE 0x0731
// MFU OTP TearOff
#define CMD_HF_MFU_OTP_TEAROFF 0x0740
2020-10-13 01:08:29 +08:00
// MFU_Ev1 Counter TearOff
#define CMD_HF_MFU_COUNTER_TEAROFF 0x0741
#define CMD_HF_SNIFF 0x0800
#define CMD_HF_PLOT 0x0801
// Fpga plot download
#define CMD_FPGAMEM_DOWNLOAD 0x0802
#define CMD_FPGAMEM_DOWNLOADED 0x0803
// For ThinFilm Kovio
#define CMD_HF_THINFILM_READ 0x0810
#define CMD_HF_THINFILM_SIMULATE 0x0811
2020-08-16 15:28:49 +08:00
//For Atmel CryptoRF
#define CMD_HF_CRYPTORF_SIM 0x0820
2020-09-06 03:32:11 +08:00
// Gen 3 magic cards
#define CMD_HF_MIFARE_GEN3UID 0x0850
#define CMD_HF_MIFARE_GEN3BLK 0x0851
#define CMD_HF_MIFARE_GEN3FREEZ 0x0852
// Gen 3 GTU magic cards
#define CMD_HF_MIFARE_G3_RDBL 0x0860
#define CMD_UNKNOWN 0xFFFF
//Mifare simulation flags
2019-03-10 01:41:30 +08:00
#define FLAG_INTERACTIVE 0x01
#define FLAG_4B_UID_IN_DATA 0x02
#define FLAG_7B_UID_IN_DATA 0x04
#define FLAG_10B_UID_IN_DATA 0x08
#define FLAG_UID_IN_EMUL 0x10
#define FLAG_NR_AR_ATTACK 0x20
2019-03-16 04:04:25 +08:00
#define FLAG_MF_MINI 0x80
#define FLAG_MF_1K 0x100
#define FLAG_MF_2K 0x200
#define FLAG_MF_4K 0x400
#define FLAG_FORCED_ATQA 0x800
#define FLAG_FORCED_SAK 0x1000
2021-05-04 02:01:12 +08:00
#define FLAG_CVE21_0430 0x2000
2020-07-06 21:16:00 +08:00
// iCLASS reader flags
#define FLAG_ICLASS_READER_INIT 0x01
#define FLAG_ICLASS_READER_CLEARTRACE 0x02
#define FLAG_ICLASS_READER_ONLY_ONCE 0x04
#define FLAG_ICLASS_READER_CREDITKEY 0x08
2019-03-10 01:41:30 +08:00
#define FLAG_ICLASS_READER_AIA 0x10
2020-07-06 21:16:00 +08:00
// iCLASS reader status flags
#define FLAG_ICLASS_CSN 0x01
#define FLAG_ICLASS_CC 0x02
#define FLAG_ICLASS_CONF 0x04
#define FLAG_ICLASS_AIA 0x08
2020-07-04 03:33:17 +08:00
// iCLASS simulation modes
#define ICLASS_SIM_MODE_CSN 0
#define ICLASS_SIM_MODE_CSN_DEFAULT 1
#define ICLASS_SIM_MODE_READER_ATTACK 2
#define ICLASS_SIM_MODE_FULL 3
#define ICLASS_SIM_MODE_READER_ATTACK_KEYROLL 4
#define ICLASS_SIM_MODE_EXIT_AFTER_MAC 5 // note: device internal only
2020-07-15 17:34:14 +08:00
#define ICLASS_SIM_MODE_CONFIG_CARD 6
2020-07-04 03:33:17 +08:00
#define MODE_SIM_CSN 0
#define MODE_EXIT_AFTER_MAC 1
#define MODE_FULLSIM 2
// Static Nonce detection
#define NONCE_FAIL 0x01
#define NONCE_NORMAL 0x02
#define NONCE_STATIC 0x03
2018-03-10 20:13:21 +08:00
// Dbprintf flags
2019-04-26 16:36:06 +08:00
#define FLAG_RAWPRINT 0x00
#define FLAG_LOG 0x01
#define FLAG_NEWLINE 0x02
#define FLAG_INPLACE 0x04
#define FLAG_ANSI 0x08
2019-01-07 03:28:23 +08:00
2019-04-20 16:34:54 +08:00
// Error codes Usages:
// Success, transfer nonces pm3: Sending nonces back to client
#define PM3_SNONCES 1
// Success (no error)
#define PM3_SUCCESS 0
2019-04-20 16:34:54 +08:00
// Undefined error
#define PM3_EUNDEF -1
2019-04-20 16:34:54 +08:00
// Invalid argument(s) client: user input parsing
#define PM3_EINVARG -2
2019-04-20 16:34:54 +08:00
// Operation not supported by device client/pm3: probably only on pm3 once client becomes universal
#define PM3_EDEVNOTSUPP -3
2019-04-20 16:34:54 +08:00
// Operation timed out client: no response in time from pm3
#define PM3_ETIMEOUT -4
2019-04-20 16:34:54 +08:00
// Operation aborted (by user) client/pm3: kbd/button pressed
#define PM3_EOPABORTED -5
// Not (yet) implemented client/pm3: TBD place holder
#define PM3_ENOTIMPL -6
2019-04-20 16:34:54 +08:00
// Error while RF transmission client/pm3: fail between pm3 & card
#define PM3_ERFTRANS -7
2019-04-20 16:34:54 +08:00
// Input / output error pm3: error in client frame reception
#define PM3_EIO -8
2019-04-20 16:34:54 +08:00
// Buffer overflow client/pm3: specified buffer too large for the operation
#define PM3_EOVFLOW -9
2019-04-20 16:34:54 +08:00
// Software error client/pm3: e.g. error in parsing some data
#define PM3_ESOFT -10
2019-04-20 16:34:54 +08:00
// Flash error client/pm3: error in RDV4 Flash operation
2019-04-19 05:26:12 +08:00
#define PM3_EFLASH -11
2019-04-20 16:34:54 +08:00
// Memory allocation error client: error in memory allocation (maybe also for pm3 BigBuff?)
2019-04-19 05:26:12 +08:00
#define PM3_EMALLOC -12
2019-04-20 16:34:54 +08:00
// File error client: error related to file access on host
2019-04-19 05:26:12 +08:00
#define PM3_EFILE -13
2019-05-07 04:41:00 +08:00
// Generic TTY error
#define PM3_ENOTTY -14
// Initialization error pm3: error related to trying to initialize the pm3 / fpga for different operations
2019-05-27 03:00:49 +08:00
#define PM3_EINIT -15
2019-08-01 03:43:00 +08:00
// Expected a different answer error client/pm3: error when expecting one answer and got another one
2020-04-29 01:58:07 +08:00
#define PM3_EWRONGANSWER -16
// Memory out-of-bounds error client/pm3: error when a read/write is outside the expected array
#define PM3_EOUTOFBOUND -17
// exchange with card error client/pm3: error when cant get answer from card or got an incorrect answer
#define PM3_ECARDEXCHANGE -18
2020-04-08 19:27:13 +08:00
// Failed to create APDU,
#define PM3_EAPDU_ENCODEFAIL -19
// APDU responded with a failure code
#define PM3_EAPDU_FAIL -20
2020-09-02 18:38:19 +08:00
// execute pm3 cmd failed client/pm3: when one of our pm3 cmd tries and fails. opposite from PM3_SUCCESS
2020-09-02 18:38:19 +08:00
#define PM3_EFAILED -21
2020-10-09 07:52:42 +08:00
// partial success client/pm3: when trying to dump a tag and fails on some blocks. Partial dump.
#define PM3_EPARTIAL -22
2021-10-10 07:35:38 +08:00
// tearoff occurred client/pm3: when a tearoff hook was called and a tearoff actually happened
2020-10-09 07:52:42 +08:00
#define PM3_ETEAROFF -23
2020-09-02 18:38:19 +08:00
// Got bad CRC client/pm3: error in transfer of data, crc mismatch.
#define PM3_ECRC -24
// No data pm3: no data available, no host frame available (not really an error)
2019-04-20 16:34:54 +08:00
#define PM3_ENODATA -98
// Quit program client: reserved, order to quit the program
2019-04-19 06:42:25 +08:00
#define PM3_EFATAL -99
// LF
#define LF_FREQ2DIV(f) ((int)(((12000.0 + (f)/2.0)/(f))-1))
#define LF_DIVISOR_125 LF_FREQ2DIV(125)
#define LF_DIVISOR_134 LF_FREQ2DIV(134.2)
#define LF_DIV2FREQ(d) (12000.0/((d)+1))
#define LF_CMDREAD_MAX_EXTRA_SYMBOLS 4
2018-03-10 20:13:21 +08:00
// Receiving from USART need more than 30ms as we used on USB
// else we get errors about partial packet reception
2021-04-16 07:53:07 +08:00
// FTDI 9600 hw status -> we need 20ms
// FTDI 115200 hw status -> we need 50ms
// FTDI 460800 hw status -> we need 30ms
// BT 115200 hf mf fchk --1k -f file.dic -> we need 140ms
// all zero's configure: no timeout for read/write used.
// took settings from libnfc/buses/uart.c
2019-05-10 14:37:52 +08:00
// uart_windows.c & uart_posix.c
# define UART_FPC_CLIENT_RX_TIMEOUT_MS 200
# define UART_USB_CLIENT_RX_TIMEOUT_MS 20
2019-07-29 03:08:50 +08:00
# define UART_TCP_CLIENT_RX_TIMEOUT_MS 500
// CMD_DEVICE_INFO response packet has flags in arg[0], flag definitions:
2021-08-22 05:23:54 +08:00
/* Whether a bootloader that understands the g_common_area is present */
2019-03-10 01:41:30 +08:00
#define DEVICE_INFO_FLAG_BOOTROM_PRESENT (1<<0)
2021-08-22 05:23:54 +08:00
/* Whether a osimage that understands the g_common_area is present */
2019-03-10 01:41:30 +08:00
#define DEVICE_INFO_FLAG_OSIMAGE_PRESENT (1<<1)
/* Set if the bootloader is currently executing */
2019-03-10 01:41:30 +08:00
#define DEVICE_INFO_FLAG_CURRENT_MODE_BOOTROM (1<<2)
/* Set if the OS is currently executing */
2019-03-10 01:41:30 +08:00
#define DEVICE_INFO_FLAG_CURRENT_MODE_OS (1<<3)
/* Set if this device understands the extend start flash command */
2019-03-10 01:41:30 +08:00
#define DEVICE_INFO_FLAG_UNDERSTANDS_START_FLASH (1<<4)
2019-07-11 03:49:14 +08:00
/* Set if this device understands the chip info command */
#define DEVICE_INFO_FLAG_UNDERSTANDS_CHIP_INFO (1<<5)
/* Set if this device understands the version command */
#define DEVICE_INFO_FLAG_UNDERSTANDS_VERSION (1<<6)
#define BL_VERSION_MAJOR(version) ((uint32_t)(version) >> 22)
#define BL_VERSION_MINOR(version) (((uint32_t)(version) >> 12) & 0x3ff)
#define BL_VERSION_PATCH(version) ((uint32_t)(version) & 0xfff)
#define BL_MAKE_VERSION(major, minor, patch) (((major) << 22) | ((minor) << 12) | (patch))
// Some boundaries to distinguish valid versions from corrupted info
#define BL_VERSION_FIRST_MAJOR 1
#define BL_VERSION_LAST_MAJOR 99
#define BL_VERSION_INVALID 0
// Different versions here. Each version should increase the numbers
#define BL_VERSION_1_0_0 BL_MAKE_VERSION(1, 0, 0)
/* CMD_START_FLASH may have three arguments: start of area to flash,
end of area to flash, optional magic.
The bootrom will not allow to overwrite itself unless this magic
is given as third parameter */
#define START_FLASH_MAGIC 0x54494f44 // 'DOIT'
#endif