]>
Commit | Line | Data |
---|---|---|
e30c654b | 1 | //----------------------------------------------------------------------------- |
e30c654b | 2 | // Jonathan Westhues, Mar 2006 |
3 | // Edits by Gerhard de Koning Gans, Sep 2007 | |
bd20f8f4 | 4 | // |
5 | // This code is licensed to you under the terms of the GNU GPL, version 2 or, | |
6 | // at your option, any later version. See the LICENSE.txt file for the text of | |
7 | // the license. | |
8 | //----------------------------------------------------------------------------- | |
9 | // Definitions for all the types of commands that may be sent over USB; our | |
10 | // own protocol. | |
e30c654b | 11 | //----------------------------------------------------------------------------- |
12 | ||
72622d64 | 13 | #ifndef USB_CMD_H__ |
14 | #define USB_CMD_H__ | |
15 | ||
e30c654b | 16 | #ifdef _MSC_VER |
17 | typedef DWORD uint32_t; | |
18 | typedef BYTE uint8_t; | |
19 | #define PACKED | |
e30c654b | 20 | #else |
21 | #include <stdint.h> | |
22 | #include <stdbool.h> | |
23 | #define PACKED __attribute__((packed)) | |
24 | #endif | |
25 | ||
902cb3c0 | 26 | #define USB_CMD_DATA_SIZE 512 |
27 | ||
b8ed9975 | 28 | // the packets sent from client to PM3 |
902cb3c0 | 29 | typedef struct { |
72622d64 | 30 | uint64_t cmd; |
31 | uint64_t arg[3]; | |
32 | union { | |
33 | uint8_t asBytes[USB_CMD_DATA_SIZE]; | |
34 | uint32_t asDwords[USB_CMD_DATA_SIZE/4]; | |
35 | } d; | |
e30c654b | 36 | } PACKED UsbCommand; |
a9104f7e | 37 | |
b8ed9975 | 38 | // the packets sent from PM3 to client (a smaller version of UsbCommand) |
39 | typedef struct { | |
40 | uint16_t cmd; | |
41 | uint16_t datalen; | |
42 | uint32_t arg[3]; | |
43 | union { | |
44 | uint8_t asBytes[USB_CMD_DATA_SIZE]; | |
45 | uint32_t asDwords[USB_CMD_DATA_SIZE/4]; | |
46 | } d; | |
47 | } PACKED UsbResponse; | |
72622d64 | 48 | |
31abe49f | 49 | // A struct used to send sample-configs over USB |
72622d64 | 50 | typedef struct { |
31abe49f MHS |
51 | uint8_t decimation; |
52 | uint8_t bits_per_sample; | |
53 | bool averaging; | |
54 | int divisor; | |
55 | int trigger_threshold; | |
2de26056 | 56 | int samples_to_skip; |
31abe49f | 57 | } sample_config; |
e30c654b | 58 | |
72622d64 | 59 | |
e30c654b | 60 | // For the bootloader |
3ebf4b3d | 61 | #define CMD_DEVICE_INFO 0x0000 |
62 | #define CMD_SETUP_WRITE 0x0001 | |
63 | #define CMD_FINISH_WRITE 0x0003 | |
64 | #define CMD_HARDWARE_RESET 0x0004 | |
65 | #define CMD_START_FLASH 0x0005 | |
66 | #define CMD_NACK 0x00fe | |
67 | #define CMD_ACK 0x00ff | |
e30c654b | 68 | |
69 | // For general mucking around | |
3ebf4b3d | 70 | #define CMD_DEBUG_PRINT_STRING 0x0100 |
71 | #define CMD_DEBUG_PRINT_INTEGERS 0x0101 | |
72 | #define CMD_DEBUG_PRINT_BYTES 0x0102 | |
73 | #define CMD_LCD_RESET 0x0103 | |
74 | #define CMD_LCD 0x0104 | |
75 | #define CMD_BUFF_CLEAR 0x0105 | |
76 | #define CMD_READ_MEM 0x0106 | |
77 | #define CMD_VERSION 0x0107 | |
43591e64 | 78 | #define CMD_STATUS 0x0108 |
79 | #define CMD_PING 0x0109 | |
80 | ||
a9104f7e | 81 | // controlling the ADC input multiplexer |
82 | #define CMD_SET_ADC_MUX 0x020F | |
83 | ||
43591e64 | 84 | // RDV40, Smart card operations |
85 | #define CMD_SMART_RAW 0x0140 | |
86 | #define CMD_SMART_UPGRADE 0x0141 | |
87 | #define CMD_SMART_UPLOAD 0x0142 | |
88 | #define CMD_SMART_ATR 0x0143 | |
89 | // CMD_SMART_SETBAUD is unused for now | |
90 | #define CMD_SMART_SETBAUD 0x0144 | |
91 | #define CMD_SMART_SETCLOCK 0x0145 | |
e30c654b | 92 | |
93 | // For low-frequency tags | |
3ebf4b3d | 94 | #define CMD_READ_TI_TYPE 0x0202 |
95 | #define CMD_WRITE_TI_TYPE 0x0203 | |
96 | #define CMD_DOWNLOADED_RAW_BITS_TI_TYPE 0x0204 | |
97 | #define CMD_ACQUIRE_RAW_ADC_SAMPLES_125K 0x0205 | |
98 | #define CMD_MOD_THEN_ACQUIRE_RAW_ADC_SAMPLES_125K 0x0206 | |
99 | #define CMD_DOWNLOAD_RAW_ADC_SAMPLES_125K 0x0207 | |
100 | #define CMD_DOWNLOADED_RAW_ADC_SAMPLES_125K 0x0208 | |
101 | #define CMD_DOWNLOADED_SIM_SAMPLES_125K 0x0209 | |
102 | #define CMD_SIMULATE_TAG_125K 0x020A | |
103 | #define CMD_HID_DEMOD_FSK 0x020B | |
104 | #define CMD_HID_SIM_TAG 0x020C | |
105 | #define CMD_SET_LF_DIVISOR 0x020D | |
106 | #define CMD_LF_SIMULATE_BIDIR 0x020E | |
3ebf4b3d | 107 | #define CMD_HID_CLONE_TAG 0x0210 |
108 | #define CMD_EM410X_WRITE_TAG 0x0211 | |
109 | #define CMD_INDALA_CLONE_TAG 0x0212 | |
110 | // for 224 bits UID | |
111 | #define CMD_INDALA_CLONE_TAG_L 0x0213 | |
54a942b0 | 112 | #define CMD_T55XX_READ_BLOCK 0x0214 |
113 | #define CMD_T55XX_WRITE_BLOCK 0x0215 | |
66837a03 | 114 | #define CMD_T55XX_RESET_READ 0x0216 |
54a942b0 | 115 | #define CMD_PCF7931_READ 0x0217 |
dc4300ba | 116 | #define CMD_PCF7931_WRITE 0x0222 |
786ad91c | 117 | #define CMD_PCF7931_BRUTEFORCE 0x0227 |
54a942b0 | 118 | #define CMD_EM4X_READ_WORD 0x0218 |
119 | #define CMD_EM4X_WRITE_WORD 0x0219 | |
a1f3bb12 | 120 | #define CMD_IO_DEMOD_FSK 0x021A |
121 | #define CMD_IO_CLONE_TAG 0x021B | |
abd6112f | 122 | #define CMD_EM410X_DEMOD 0x021c |
31abe49f MHS |
123 | // Sampling configuration for LF reader/snooper |
124 | #define CMD_SET_LF_SAMPLING_CONFIG 0x021d | |
abd6112f | 125 | #define CMD_FSK_SIM_TAG 0x021E |
126 | #define CMD_ASK_SIM_TAG 0x021F | |
872e3d4d | 127 | #define CMD_PSK_SIM_TAG 0x0220 |
dbf6e824 | 128 | #define CMD_AWID_DEMOD_FSK 0x0221 |
709665b5 | 129 | #define CMD_VIKING_CLONE_TAG 0x0223 |
be2d41b7 | 130 | #define CMD_T55XX_WAKEUP 0x0224 |
e04475c4 | 131 | #define CMD_COTAG 0x0225 |
5f84531b | 132 | #define CMD_PARADOX_CLONE_TAG 0x0226 |
2de26056 | 133 | #define CMD_EM4X_PROTECT 0x0228 |
66707a3b | 134 | |
e30c654b | 135 | // For the 13.56 MHz tags |
3ebf4b3d | 136 | #define CMD_ACQUIRE_RAW_ADC_SAMPLES_ISO_15693 0x0300 |
3ebf4b3d | 137 | #define CMD_READ_SRI512_TAG 0x0303 |
138 | #define CMD_READ_SRIX4K_TAG 0x0304 | |
7cf3ef20 | 139 | #define CMD_ISO_14443B_COMMAND 0x0305 |
3ebf4b3d | 140 | #define CMD_READER_ISO_15693 0x0310 |
141 | #define CMD_SIMTAG_ISO_15693 0x0311 | |
d9de20fa | 142 | #define CMD_SNOOP_ISO_15693 0x0312 |
3ebf4b3d | 143 | #define CMD_ISO_15693_COMMAND 0x0313 |
144 | #define CMD_ISO_15693_COMMAND_DONE 0x0314 | |
145 | #define CMD_ISO_15693_FIND_AFI 0x0315 | |
146 | #define CMD_ISO_15693_DEBUG 0x0316 | |
b014c96d | 147 | #define CMD_LF_SNOOP_RAW_ADC_SAMPLES 0x0317 |
096dee17 | 148 | #define CMD_CSETUID_ISO_15693 0x0318 |
d19929cb | 149 | |
150 | // For Hitag2 transponders | |
151 | #define CMD_SNOOP_HITAG 0x0370 | |
152 | #define CMD_SIMULATE_HITAG 0x0371 | |
153 | #define CMD_READER_HITAG 0x0372 | |
4e12287d | 154 | #define CMD_SIMULATE_HITAG_S 0x0368 |
43591e64 | 155 | #define CMD_TEST_HITAGS_TRACES 0x0367 |
156 | #define CMD_READ_HITAG_S 0x0373 | |
7b6e3205 | 157 | #define CMD_READ_HITAG_S_BLK 0x0374 |
43591e64 | 158 | #define CMD_WR_HITAG_S 0x0375 |
159 | #define CMD_EMU_HITAG_S 0x0376 | |
4e12287d | 160 | |
132a0217 | 161 | #define CMD_SIMULATE_TAG_ISO_14443B 0x0381 |
162 | #define CMD_SNOOP_ISO_14443B 0x0382 | |
3ebf4b3d | 163 | #define CMD_SNOOP_ISO_14443a 0x0383 |
164 | #define CMD_SIMULATE_TAG_ISO_14443a 0x0384 | |
165 | #define CMD_READER_ISO_14443a 0x0385 | |
166 | #define CMD_SIMULATE_TAG_LEGIC_RF 0x0387 | |
167 | #define CMD_READER_LEGIC_RF 0x0388 | |
168 | #define CMD_WRITER_LEGIC_RF 0x0389 | |
5acd09bd | 169 | #define CMD_EPA_PACE_COLLECT_NONCE 0x038A |
3bb07d96 | 170 | #define CMD_EPA_PACE_REPLAY 0x038B |
3ebf4b3d | 171 | |
aa53efc3 | 172 | #define CMD_ICLASS_CLONE 0x0390 |
173 | #define CMD_ICLASS_DUMP 0x0391 | |
3ebf4b3d | 174 | #define CMD_SNOOP_ICLASS 0x0392 |
175 | #define CMD_SIMULATE_TAG_ICLASS 0x0393 | |
176 | #define CMD_READER_ICLASS 0x0394 | |
aa53efc3 | 177 | #define CMD_ICLASS_READBLOCK 0x0396 |
178 | #define CMD_ICLASS_WRITEBLOCK 0x0397 | |
7781a656 | 179 | #define CMD_ICLASS_EML_MEMSET 0x0398 |
ece38ef3 | 180 | #define CMD_ICLASS_CHECK 0x0399 |
72622d64 | 181 | #define CMD_ICLASS_READCHECK 0x039A |
e30c654b | 182 | |
183 | // For measurements of the antenna tuning | |
3ebf4b3d | 184 | #define CMD_MEASURE_ANTENNA_TUNING 0x0400 |
185 | #define CMD_MEASURE_ANTENNA_TUNING_HF 0x0401 | |
186 | #define CMD_MEASURED_ANTENNA_TUNING 0x0410 | |
187 | #define CMD_LISTEN_READER_FIELD 0x0420 | |
e30c654b | 188 | |
189 | // For direct FPGA control | |
3ebf4b3d | 190 | #define CMD_FPGA_MAJOR_MODE_OFF 0x0500 |
9ca155ba M |
191 | |
192 | // For mifare commands | |
3ebf4b3d | 193 | #define CMD_MIFARE_SET_DBGMODE 0x0600 |
194 | #define CMD_MIFARE_EML_MEMCLR 0x0601 | |
195 | #define CMD_MIFARE_EML_MEMSET 0x0602 | |
196 | #define CMD_MIFARE_EML_MEMGET 0x0603 | |
197 | #define CMD_MIFARE_EML_CARDLOAD 0x0604 | |
3fe4ff4f | 198 | |
199 | // magic chinese card commands | |
200 | #define CMD_MIFARE_CSETBLOCK 0x0605 | |
201 | #define CMD_MIFARE_CGETBLOCK 0x0606 | |
202 | #define CMD_MIFARE_CIDENT 0x0607 | |
3a05a1e7 | 203 | #define CMD_MIFARE_CWIPE 0x0608 |
9ca155ba | 204 | |
3ebf4b3d | 205 | #define CMD_SIMULATE_MIFARE_CARD 0x0610 |
9ca155ba | 206 | |
3ebf4b3d | 207 | #define CMD_READER_MIFARE 0x0611 |
208 | #define CMD_MIFARE_NESTED 0x0612 | |
c48c4d78 | 209 | #define CMD_MIFARE_ACQUIRE_ENCRYPTED_NONCES 0x0613 |
9ca155ba | 210 | |
3ebf4b3d | 211 | #define CMD_MIFARE_READBL 0x0620 |
212 | #define CMD_MIFARE_READSC 0x0621 | |
213 | #define CMD_MIFARE_WRITEBL 0x0622 | |
214 | #define CMD_MIFARE_CHKKEYS 0x0623 | |
0b4efbde | 215 | #define CMD_MIFARE_PERSONALIZE_UID 0x0624 |
3ebf4b3d | 216 | #define CMD_MIFARE_SNIFFER 0x0630 |
0b4efbde | 217 | |
3fe4ff4f | 218 | //ultralightC |
0b4efbde | 219 | #define CMD_MIFAREU_READBL 0x0720 |
220 | #define CMD_MIFAREU_READCARD 0x0721 | |
221 | #define CMD_MIFAREU_WRITEBL 0x0722 | |
222 | #define CMD_MIFAREU_WRITEBL_COMPAT 0x0723 | |
9d87eb66 | 223 | #define CMD_MIFAREUC_AUTH 0x0724 |
72622d64 | 224 | //0x0725 and 0x0726 no longer used |
f168b263 | 225 | #define CMD_MIFAREUC_SETPWD 0x0727 |
226 | ||
3fe4ff4f | 227 | |
228 | // mifare desfire | |
229 | #define CMD_MIFARE_DESFIRE_READBL 0x0728 | |
230 | #define CMD_MIFARE_DESFIRE_WRITEBL 0x0729 | |
231 | #define CMD_MIFARE_DESFIRE_AUTH1 0x072a | |
232 | #define CMD_MIFARE_DESFIRE_AUTH2 0x072b | |
233 | #define CMD_MIFARE_DES_READER 0x072c | |
234 | #define CMD_MIFARE_DESFIRE_INFO 0x072d | |
235 | #define CMD_MIFARE_DESFIRE 0x072e | |
b62a5a84 | 236 | |
0472d76d | 237 | #define CMD_HF_SNIFFER 0x0800 |
fc52fbd4 | 238 | #define CMD_HF_PLOT 0x0801 |
0472d76d | 239 | |
b8ed9975 | 240 | #define CMD_VARIABLE_SIZE_FLAG 0x8000 |
3ebf4b3d | 241 | #define CMD_UNKNOWN 0xFFFF |
3851172d | 242 | |
d2f487af | 243 | |
0ab9002f | 244 | // Mifare simulation flags |
72622d64 | 245 | #define FLAG_INTERACTIVE (1<<0) |
246 | #define FLAG_4B_UID_IN_DATA (1<<1) | |
247 | #define FLAG_7B_UID_IN_DATA (1<<2) | |
248 | #define FLAG_NR_AR_ATTACK (1<<4) | |
249 | #define FLAG_RANDOM_NONCE (1<<5) | |
d2f487af | 250 | |
251 | ||
0ab9002f | 252 | // iCLASS reader flags |
496bb4be | 253 | #define FLAG_ICLASS_READER_INIT (1<<0) |
254 | #define FLAG_ICLASS_READER_CC (1<<1) | |
255 | #define FLAG_ICLASS_READER_CSN (1<<2) | |
256 | #define FLAG_ICLASS_READER_CONF (1<<3) | |
257 | #define FLAG_ICLASS_READER_AA (1<<4) | |
258 | #define FLAG_ICLASS_READER_CREDITKEY (1<<5) | |
259 | #define FLAG_ICLASS_READER_CLEARTRACE (1<<6) | |
260 | ||
caaf9618 | 261 | |
0ab9002f | 262 | // iCLASS simulation modes |
263 | #define ICLASS_SIM_MODE_CSN 0 | |
264 | #define ICLASS_SIM_MODE_CSN_DEFAULT 1 | |
265 | #define ICLASS_SIM_MODE_READER_ATTACK 2 | |
266 | #define ICLASS_SIM_MODE_FULL 3 | |
267 | #define ICLASS_SIM_MODE_READER_ATTACK_KEYROLL 4 | |
268 | #define ICLASS_SIM_MODE_EXIT_AFTER_MAC 5 // note: device internal only | |
d2f487af | 269 | |
0ab9002f | 270 | |
271 | // hw tune args | |
fdcfbdcc RAB |
272 | #define FLAG_TUNE_LF 1 |
273 | #define FLAG_TUNE_HF 2 | |
274 | #define FLAG_TUNE_ALL 3 | |
275 | ||
a9104f7e | 276 | // Hardware capabilities |
277 | #define HAS_EXTRA_FLASH_MEM (1 << 0) | |
278 | #define HAS_SMARTCARD_SLOT (1 << 1) | |
279 | ||
31abe49f | 280 | |
e30c654b | 281 | // CMD_DEVICE_INFO response packet has flags in arg[0], flag definitions: |
282 | /* Whether a bootloader that understands the common_area is present */ | |
72622d64 | 283 | #define DEVICE_INFO_FLAG_BOOTROM_PRESENT (1<<0) |
e30c654b | 284 | |
285 | /* Whether a osimage that understands the common_area is present */ | |
72622d64 | 286 | #define DEVICE_INFO_FLAG_OSIMAGE_PRESENT (1<<1) |
e30c654b | 287 | |
288 | /* Set if the bootloader is currently executing */ | |
72622d64 | 289 | #define DEVICE_INFO_FLAG_CURRENT_MODE_BOOTROM (1<<2) |
e30c654b | 290 | |
291 | /* Set if the OS is currently executing */ | |
72622d64 | 292 | #define DEVICE_INFO_FLAG_CURRENT_MODE_OS (1<<3) |
e30c654b | 293 | |
294 | /* Set if this device understands the extend start flash command */ | |
72622d64 | 295 | #define DEVICE_INFO_FLAG_UNDERSTANDS_START_FLASH (1<<4) |
e30c654b | 296 | |
297 | /* CMD_START_FLASH may have three arguments: start of area to flash, | |
298 | end of area to flash, optional magic. | |
299 | The bootrom will not allow to overwrite itself unless this magic | |
300 | is given as third parameter */ | |
301 | ||
302 | #define START_FLASH_MAGIC 0x54494f44 // 'DOIT' | |
303 | ||
304 | #endif |