]>
Commit | Line | Data |
---|---|---|
1 | //----------------------------------------------------------------------------- | |
2 | // Jonathan Westhues, Mar 2006 | |
3 | // Edits by Gerhard de Koning Gans, Sep 2007 | |
4 | // | |
5 | // This code is licensed to you under the terms of the GNU GPL, version 2 or, | |
6 | // at your option, any later version. See the LICENSE.txt file for the text of | |
7 | // the license. | |
8 | //----------------------------------------------------------------------------- | |
9 | // Definitions for all the types of commands that may be sent over USB; our | |
10 | // own protocol. | |
11 | //----------------------------------------------------------------------------- | |
12 | ||
13 | #ifndef __USB_CMD_H | |
14 | #define __USB_CMD_H | |
15 | #ifdef _MSC_VER | |
16 | typedef DWORD uint32_t; | |
17 | typedef BYTE uint8_t; | |
18 | #define PACKED | |
19 | // stuff | |
20 | #else | |
21 | #include <stdint.h> | |
22 | #include <stdbool.h> | |
23 | #define PACKED __attribute__((packed)) | |
24 | #endif | |
25 | ||
26 | #define USB_CMD_DATA_SIZE 512 | |
27 | ||
28 | typedef struct { | |
29 | uint64_t cmd; | |
30 | uint64_t arg[3]; | |
31 | union { | |
32 | uint8_t asBytes[USB_CMD_DATA_SIZE]; | |
33 | uint32_t asDwords[USB_CMD_DATA_SIZE/4]; | |
34 | } d; | |
35 | } PACKED UsbCommand; | |
36 | // A struct used to send sample-configs over USB | |
37 | typedef struct{ | |
38 | uint8_t decimation; | |
39 | uint8_t bits_per_sample; | |
40 | bool averaging; | |
41 | int divisor; | |
42 | int trigger_threshold; | |
43 | } sample_config; | |
44 | ||
45 | // For the bootloader | |
46 | #define CMD_DEVICE_INFO 0x0000 | |
47 | #define CMD_SETUP_WRITE 0x0001 | |
48 | #define CMD_FINISH_WRITE 0x0003 | |
49 | #define CMD_HARDWARE_RESET 0x0004 | |
50 | #define CMD_START_FLASH 0x0005 | |
51 | #define CMD_NACK 0x00fe | |
52 | #define CMD_ACK 0x00ff | |
53 | ||
54 | // For general mucking around | |
55 | #define CMD_DEBUG_PRINT_STRING 0x0100 | |
56 | #define CMD_DEBUG_PRINT_INTEGERS 0x0101 | |
57 | #define CMD_DEBUG_PRINT_BYTES 0x0102 | |
58 | #define CMD_LCD_RESET 0x0103 | |
59 | #define CMD_LCD 0x0104 | |
60 | #define CMD_BUFF_CLEAR 0x0105 | |
61 | #define CMD_READ_MEM 0x0106 | |
62 | #define CMD_VERSION 0x0107 | |
63 | #define CMD_STATUS 0x0108 | |
64 | #define CMD_PING 0x0109 | |
65 | ||
66 | #define CMD_DOWNLOAD_EML_BIGBUF 0x0110 | |
67 | #define CMD_DOWNLOADED_EML_BIGBUF 0x0111 | |
68 | ||
69 | // For low-frequency tags | |
70 | #define CMD_READ_TI_TYPE 0x0202 | |
71 | #define CMD_WRITE_TI_TYPE 0x0203 | |
72 | #define CMD_DOWNLOADED_RAW_BITS_TI_TYPE 0x0204 | |
73 | #define CMD_ACQUIRE_RAW_ADC_SAMPLES_125K 0x0205 | |
74 | #define CMD_MOD_THEN_ACQUIRE_RAW_ADC_SAMPLES_125K 0x0206 | |
75 | #define CMD_DOWNLOAD_RAW_ADC_SAMPLES_125K 0x0207 | |
76 | #define CMD_DOWNLOADED_RAW_ADC_SAMPLES_125K 0x0208 | |
77 | #define CMD_DOWNLOADED_SIM_SAMPLES_125K 0x0209 | |
78 | #define CMD_SIMULATE_TAG_125K 0x020A | |
79 | #define CMD_HID_DEMOD_FSK 0x020B | |
80 | #define CMD_HID_SIM_TAG 0x020C | |
81 | #define CMD_SET_LF_DIVISOR 0x020D | |
82 | #define CMD_LF_SIMULATE_BIDIR 0x020E | |
83 | #define CMD_SET_ADC_MUX 0x020F | |
84 | #define CMD_HID_CLONE_TAG 0x0210 | |
85 | #define CMD_EM410X_WRITE_TAG 0x0211 | |
86 | #define CMD_INDALA_CLONE_TAG 0x0212 | |
87 | // for 224 bits UID | |
88 | #define CMD_INDALA_CLONE_TAG_L 0x0213 | |
89 | #define CMD_T55XX_READ_BLOCK 0x0214 | |
90 | #define CMD_T55XX_WRITE_BLOCK 0x0215 | |
91 | #define CMD_T55XX_RESET_READ 0x0216 | |
92 | #define CMD_PCF7931_READ 0x0217 | |
93 | #define CMD_PCF7931_WRITE 0x0223 | |
94 | #define CMD_EM4X_READ_WORD 0x0218 | |
95 | #define CMD_EM4X_WRITE_WORD 0x0219 | |
96 | #define CMD_IO_DEMOD_FSK 0x021A | |
97 | #define CMD_IO_CLONE_TAG 0x021B | |
98 | #define CMD_EM410X_DEMOD 0x021c | |
99 | // Sampling configuration for LF reader/snooper | |
100 | #define CMD_SET_LF_SAMPLING_CONFIG 0x021d | |
101 | #define CMD_FSK_SIM_TAG 0x021E | |
102 | #define CMD_ASK_SIM_TAG 0x021F | |
103 | #define CMD_PSK_SIM_TAG 0x0220 | |
104 | #define CMD_AWID_DEMOD_FSK 0x0221 | |
105 | #define CMD_VIKING_CLONE_TAG 0x0222 | |
106 | #define CMD_T55XX_WAKEUP 0x0224 | |
107 | ||
108 | /* CMD_SET_ADC_MUX: ext1 is 0 for lopkd, 1 for loraw, 2 for hipkd, 3 for hiraw */ | |
109 | ||
110 | // For the 13.56 MHz tags | |
111 | #define CMD_ACQUIRE_RAW_ADC_SAMPLES_ISO_15693 0x0300 | |
112 | #define CMD_READ_SRI_TAG 0x0303 | |
113 | #define CMD_ISO_14443B_COMMAND 0x0305 | |
114 | #define CMD_READER_ISO_15693 0x0310 | |
115 | #define CMD_SIMTAG_ISO_15693 0x0311 | |
116 | #define CMD_RECORD_RAW_ADC_SAMPLES_ISO_15693 0x0312 | |
117 | #define CMD_ISO_15693_COMMAND 0x0313 | |
118 | #define CMD_ISO_15693_COMMAND_DONE 0x0314 | |
119 | #define CMD_ISO_15693_FIND_AFI 0x0315 | |
120 | #define CMD_ISO_15693_DEBUG 0x0316 | |
121 | #define CMD_LF_SNOOP_RAW_ADC_SAMPLES 0x0317 | |
122 | ||
123 | // For Hitag2 transponders | |
124 | #define CMD_SNOOP_HITAG 0x0370 | |
125 | #define CMD_SIMULATE_HITAG 0x0371 | |
126 | #define CMD_READER_HITAG 0x0372 | |
127 | ||
128 | // For HitagS | |
129 | #define CMD_TEST_HITAGS_TRACES 0x0367 | |
130 | #define CMD_SIMULATE_HITAG_S 0x0368 | |
131 | #define CMD_READ_HITAG_S 0x0373 | |
132 | #define CMD_WR_HITAG_S 0x0375 | |
133 | #define CMD_EMU_HITAG_S 0x0376 | |
134 | ||
135 | ||
136 | #define CMD_SIMULATE_TAG_ISO_14443B 0x0381 | |
137 | #define CMD_SNOOP_ISO_14443B 0x0382 | |
138 | #define CMD_SNOOP_ISO_14443a 0x0383 | |
139 | #define CMD_SIMULATE_TAG_ISO_14443a 0x0384 | |
140 | #define CMD_READER_ISO_14443a 0x0385 | |
141 | #define CMD_RAW_WRITER_LEGIC_RF 0x0386 | |
142 | #define CMD_SIMULATE_TAG_LEGIC_RF 0x0387 | |
143 | #define CMD_READER_LEGIC_RF 0x0388 | |
144 | #define CMD_WRITER_LEGIC_RF 0x0389 | |
145 | ||
146 | #define CMD_EPA_PACE_COLLECT_NONCE 0x038A | |
147 | #define CMD_EPA_PACE_REPLAY 0x038B | |
148 | ||
149 | #define CMD_LEGIC_INFO 0x03BC | |
150 | #define CMD_LEGIC_ESET 0x03BD | |
151 | #define CMD_LEGIC_EGET 0x03BE | |
152 | ||
153 | #define CMD_ICLASS_READCHECK 0x038F | |
154 | #define CMD_ICLASS_CLONE 0x0390 | |
155 | #define CMD_ICLASS_DUMP 0x0391 | |
156 | #define CMD_SNOOP_ICLASS 0x0392 | |
157 | #define CMD_SIMULATE_TAG_ICLASS 0x0393 | |
158 | #define CMD_READER_ICLASS 0x0394 | |
159 | #define CMD_READER_ICLASS_REPLAY 0x0395 | |
160 | #define CMD_ICLASS_READBLOCK 0x0396 | |
161 | #define CMD_ICLASS_WRITEBLOCK 0x0397 | |
162 | #define CMD_ICLASS_EML_MEMSET 0x0398 | |
163 | #define CMD_ICLASS_AUTHENTICATION 0x0399 | |
164 | ||
165 | // For measurements of the antenna tuning | |
166 | #define CMD_MEASURE_ANTENNA_TUNING 0x0400 | |
167 | #define CMD_MEASURE_ANTENNA_TUNING_HF 0x0401 | |
168 | #define CMD_MEASURED_ANTENNA_TUNING 0x0410 | |
169 | #define CMD_LISTEN_READER_FIELD 0x0420 | |
170 | ||
171 | // For direct FPGA control | |
172 | #define CMD_FPGA_MAJOR_MODE_OFF 0x0500 | |
173 | ||
174 | // For mifare commands | |
175 | #define CMD_MIFARE_SET_DBGMODE 0x0600 | |
176 | #define CMD_MIFARE_EML_MEMCLR 0x0601 | |
177 | #define CMD_MIFARE_EML_MEMSET 0x0602 | |
178 | #define CMD_MIFARE_EML_MEMGET 0x0603 | |
179 | #define CMD_MIFARE_EML_CARDLOAD 0x0604 | |
180 | ||
181 | // magic chinese card commands | |
182 | #define CMD_MIFARE_CSETBLOCK 0x0605 | |
183 | #define CMD_MIFARE_CGETBLOCK 0x0606 | |
184 | #define CMD_MIFARE_CIDENT 0x0607 | |
185 | ||
186 | #define CMD_SIMULATE_MIFARE_CARD 0x0610 | |
187 | ||
188 | #define CMD_READER_MIFARE 0x0611 | |
189 | #define CMD_MIFARE_NESTED 0x0612 | |
190 | #define CMD_MIFARE_ACQUIRE_ENCRYPTED_NONCES 0x0613 | |
191 | ||
192 | #define CMD_MIFARE_READBL 0x0620 | |
193 | #define CMD_MIFAREU_READBL 0x0720 | |
194 | #define CMD_MIFARE_READSC 0x0621 | |
195 | #define CMD_MIFAREU_READCARD 0x0721 | |
196 | #define CMD_MIFARE_WRITEBL 0x0622 | |
197 | #define CMD_MIFAREU_WRITEBL 0x0722 | |
198 | #define CMD_MIFAREU_WRITEBL_COMPAT 0x0723 | |
199 | ||
200 | #define CMD_MIFARE_CHKKEYS 0x0623 | |
201 | ||
202 | #define CMD_MIFARE_SNIFFER 0x0630 | |
203 | //ultralightC | |
204 | #define CMD_MIFAREUC_AUTH 0x0724 | |
205 | //0x0725 and 0x0726 no longer used | |
206 | #define CMD_MIFAREUC_SETPWD 0x0727 | |
207 | ||
208 | ||
209 | // mifare desfire | |
210 | #define CMD_MIFARE_DESFIRE_READBL 0x0728 | |
211 | #define CMD_MIFARE_DESFIRE_WRITEBL 0x0729 | |
212 | #define CMD_MIFARE_DESFIRE_AUTH1 0x072a | |
213 | #define CMD_MIFARE_DESFIRE_AUTH2 0x072b | |
214 | #define CMD_MIFARE_DES_READER 0x072c | |
215 | #define CMD_MIFARE_DESFIRE_INFO 0x072d | |
216 | #define CMD_MIFARE_DESFIRE 0x072e | |
217 | ||
218 | #define CMD_MIFARE_COLLECT_NONCES 0x072f | |
219 | ||
220 | #define CMD_HF_SNIFFER 0x0800 | |
221 | ||
222 | ||
223 | // For EMV Commands | |
224 | #define CMD_EMV_READ_RECORD 0x0700 | |
225 | #define CMD_EMV_TRANSACTION 0x0701 | |
226 | #define CMD_EMV_CLONE 0x0702 | |
227 | #define CMD_EMV_SIM 0x0703 | |
228 | #define CMD_EMV_TEST 0x0704 | |
229 | #define CMD_EMV_FUZZ_RATS 0x0705 | |
230 | #define CMD_EMV_GET_RANDOM_NUM 0x0706 | |
231 | #define CMD_EMV_LOAD_VALUE 0x0707 | |
232 | #define CMD_EMV_DUMP_CARD 0x0708 | |
233 | ||
234 | #define CMD_UNKNOWN 0xFFFF | |
235 | ||
236 | ||
237 | //Mifare simulation flags | |
238 | #define FLAG_INTERACTIVE 0x01 | |
239 | #define FLAG_4B_UID_IN_DATA 0x02 | |
240 | #define FLAG_7B_UID_IN_DATA 0x04 | |
241 | #define FLAG_10B_UID_IN_DATA 0x08 | |
242 | #define FLAG_UID_IN_EMUL 0x10 | |
243 | #define FLAG_NR_AR_ATTACK 0x20 | |
244 | ||
245 | ||
246 | //Iclass reader flags | |
247 | #define FLAG_ICLASS_READER_ONLY_ONCE 0x01 | |
248 | #define FLAG_ICLASS_READER_CC 0x02 | |
249 | #define FLAG_ICLASS_READER_CSN 0x04 | |
250 | #define FLAG_ICLASS_READER_CONF 0x08 | |
251 | #define FLAG_ICLASS_READER_AA 0x10 | |
252 | #define FLAG_ICLASS_READER_ONE_TRY 0x20 | |
253 | #define FLAG_ICLASS_READER_CEDITKEY 0x40 | |
254 | ||
255 | ||
256 | ||
257 | // CMD_DEVICE_INFO response packet has flags in arg[0], flag definitions: | |
258 | /* Whether a bootloader that understands the common_area is present */ | |
259 | #define DEVICE_INFO_FLAG_BOOTROM_PRESENT (1<<0) | |
260 | ||
261 | /* Whether a osimage that understands the common_area is present */ | |
262 | #define DEVICE_INFO_FLAG_OSIMAGE_PRESENT (1<<1) | |
263 | ||
264 | /* Set if the bootloader is currently executing */ | |
265 | #define DEVICE_INFO_FLAG_CURRENT_MODE_BOOTROM (1<<2) | |
266 | ||
267 | /* Set if the OS is currently executing */ | |
268 | #define DEVICE_INFO_FLAG_CURRENT_MODE_OS (1<<3) | |
269 | ||
270 | /* Set if this device understands the extend start flash command */ | |
271 | #define DEVICE_INFO_FLAG_UNDERSTANDS_START_FLASH (1<<4) | |
272 | ||
273 | /* CMD_START_FLASH may have three arguments: start of area to flash, | |
274 | end of area to flash, optional magic. | |
275 | The bootrom will not allow to overwrite itself unless this magic | |
276 | is given as third parameter */ | |
277 | ||
278 | #define START_FLASH_MAGIC 0x54494f44 // 'DOIT' | |
279 | ||
280 | #endif |