PM5: larger NG frames (4064) - #3560
Conversation
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Removed the definition of KEYS_IN_BLOCK from mifaredefault.h. Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
|
You are welcome to add an entry to the CHANGELOG.md as well |
|
Hmm that breaks many commands that compute how much data they can send based on the PM3_CMD_DATA_SIZE |
|
hmm, it may not be a big task, let me look thru the source |
This is what i could find. client/src/cmdhflegic.c Can create a patch and apply |
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
|
There are more places to check, everywhere PM3_CMD_DATA_SIZE is used in the client to prepare a buffer to be sent. |
Good, will check. |
100 array declarations uint8_t x[PM3_CMD_DATA_SIZE] 21 receive sites — GetFromDevice, APDU/smartcard response buffers All in a days work Signed-off-by: Niel Nielsen <nieldk@gmail.com>
|
@doegox pretty sure it’s complete now |
|
I think cmdsmartcard.c line 1338 should be fixed too, even if not directly triggable |
|
also cmdhfvas.c line 705 |
|
also cmdhfepa.c line 159 |
|
also cmdtrace.c download_trace() |
|
cmdlf.c 363 the error message max length is wrong, should use m3_max_cmd_data_size() instead of sizeof(cmd) |
|
[usb] pm3 --> lf sim |
|
usart txhex -d 504d33620a80000000010100f09f988ef09fa5b3623300000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 usart tx -d |
|
hf 14a apdu -sm 00A40400 -d 325041592E5359532E444446303100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 -el 65536 [!!] 🚨 UART:: write time-out |
|
mifarehost.c client/src/mifare/mifarehost.h Beware a second client/src/mifarehost.c got introduced in the PR... |
|
oops I almost pushed your branch to master when testing locally because your PR is on your master branch. Next time better to always create a new branch when you foresee a PR. It will also make your life easier to sync with the repo master as well after merge. |
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
pm3 ? |
Signed-off-by: Niel Nielsen <nieldk@gmail.com>
yes with Blueshark |
OK, been trhrough it all. I dont have my RDV4 (and Blueshark) with me. |
This raises PM3_CMD_DATA_SIZE to 4064 for PM5 only (guarded ON_DEVICE && !PM5).
The client sizes to the larger value and already clamps sends per-device via pm3_max_cmd_data_size(). 4064 is the ceiling that fits the ESP's 4096-byte app_com payload once NG framing (+12) is accounted for.
Also in this change:
PM5 stack raised to 64 KB in ldscript.defs.at32. The 4064-byte command buffers overflow the old stack and hardfault the device; this is where the RAM on a 512 KB part goes.
Clamp KEYS_IN_BLOCK and MFC_CHKKEYS_FAST_MAX_KEYS to 255. Their frame-derived counts now exceed 255 but land in uint8_t fields (keycnt / wire key_count), which would overflow/truncate.