diff --git a/frontend/help-ru.html b/frontend/help-ru.html index 2ce7251..08fbc4a 100644 --- a/frontend/help-ru.html +++ b/frontend/help-ru.html @@ -35,10 +35,18 @@
  • 3GPP TS 23.038 — алфавит GSM 7-bit и DCS
  • 3GPP TS 24.008 / 24.301 / 24.501 — коды причин NAS
  • GlobalPlatform Card Specification v2.3.1
  • +
  • GlobalPlatform GPC v2.2 Amendment B v1.1 — Remote Application Management over HTTP
  • ISO/IEC 7816-4 — команды обмена
  • ISO/IEC 9797-1 — алгоритмы MAC
  • +

    1.1 Интерфейс

    + +

    2. Вкладка C-APDU

    @@ -106,14 +114,13 @@ C-APDU22APDU Immediate Action81Проактивная команда или action indicator Error Action82Условное восстановление при ошибках с action indicator или проактивной командой - Script Chaining83Многопакетное выполнение скрипта с флагами First/Intermediary/Last - Response Type-Индикатор типа ответа: expanded/compact/none + Script Chaining83Многопакетное выполнение скрипта с флагами First/Intermediary/Last

    Сборщик Immediate Action предлагает action indicator (81/82), структурированный сборщик проактивных команд (REFRESH, DISPLAY TEXT, PLAY TONE с авто-генерацией COMPREHENSION-TLV), или ручной hex-ввод.

    Error Action TLV (Tag 82)

    -

    Восстановление при ошибках по TS 102 226 §5.2.1.3 — одна из трёх форм:

    +

    Восстановление при ошибках по TS 102 226 §5.2.1.3 — одна из четырёх форм:

    -

    Expanded Remote Response (TS 102 226 §5.2.2)

    -

    Результаты по каждой команде с деталями ошибок и контекстом цепочки:

    - +

    Декодирование ответов (TS 102 226 §5.2.2)

    +

    Входящие ответы Proof of Receipt декодируются сервером — формат expanded Remote Application response data (TS 102 226 §5.2.2) или компактный формат. Представление Secured Packet показывает результат после Send to Card (см. §3.1): статус PoR (TAR, счётчик, сырой PoR), а статусное слово и данные ответа последней команды подставляются на вкладку Response parser.

    2.4 RAM/GP

    CLA = 80 (GlobalPlatform Card Specification v2.3.1). Команды удалённого управления приложениями. Строятся тем же сборщиком цепочки, что и SIM/USIM.

    @@ -259,7 +260,7 @@
  • AES требует счётчик с защитой от повтора: биты SPI1 b5 b4 должны быть 10 (счётчик больше) или 11 (счётчик +1) согласно TS 102 225 §5.1.2/§5.1.3.1
  • Байт паддинга настраивается (00 по умолчанию или FF)
  • -

    Кнопка «Verify vs pySim» сверяет собранный пакет с эталонной реализацией OtaDialectSms.encode_cmd. Кнопка «Send to Card» доставляет пакет через ENVELOPE SMS-PP-DOWNLOAD (при подключении к серверу).

    +

    Кнопка «Verify vs pySim» сверяет собранный пакет с эталонной реализацией OtaDialectSms.encode_cmd. Кнопка «Send to Card» доставляет пакет через ENVELOPE SMS-PP-DOWNLOAD (при подключении к серверу). Полученный Proof of Receipt декодируется и показывается строкой статуса PoR (статус, TAR, счётчик, сырой PoR); статусное слово и данные ответа последней команды подставляются на вкладку Response parser, а успешный PoR увеличивает счётчик повторов и очищает пакет.

    3.2 Cards

    Хранит предустановки карт локально в браузере (localStorage), чтобы представление Secured Packet могло автоматически подставлять ключи и параметры.

    @@ -275,7 +276,7 @@ KIc key / KID key16/24/32 hex-символа (ключи 8/16/24 байта 3DES) или 32/48/64 hex-символа (ключи 16/24/32 байта AES) -

    Export as JSON / Import JSON from clipboard для обмена предустановками. Выбранная предустановка автоматически заполняет форму Secured Packet.

    +

    Обмен предустановками: Export as JSON и Export to file для выгрузки, Import from file, Paste & import или Import JSON from clipboard для загрузки. Выбранная предустановка автоматически заполняет форму Secured Packet.

    3.3 RAM

    Выполняет операции удалённого управления приложениями (Remote Application Management) как защищённые пакеты SCP80 через SMS-PP-DOWNLOAD ENVELOPE. Карта должна поддерживать SCP03 (AES или 3DES). Предустановка карты из подвкладки Cards обеспечивает SPI, ключи, TAR и счётчик.

    @@ -301,7 +302,7 @@

    4. Вкладка Response parser

    -

    Декодирует raw-ответ команды: выберите отправленную команду, введите SW (например, 9000) и hex данных ответа, затем нажмите Decode.

    +

    Декодирует raw-ответ команды: выберите отправленную команду, введите SW (например, 9000) и hex данных ответа, затем нажмите Decode. Поля также автоматически заполняются статусным словом и данными ответа последней команды после успешного «Send to Card» (см. §3.1).

    Правила файловой системы

    -

    Правила выполняются последовательно. Правило файловой системы задаётся:

    +

    Правила выполняются последовательно. Редактор показывает символьное имя файла pySim (если известно) рядом с путём правила; Add rule добавляет правило, Save сохраняет изменения. Правило файловой системы задаётся:

    -

    Check выполняет каждое правило на подключённой карте и показывает строку прогресса и отчёт прохождения. Рядом с путём файла указывается, что именно проверялось (например, тип файла и размер, содержимое или точный FCI); если часть проверок прошла, а часть нет — каждый аспект помечается (тип файла ✓, размер ✗, содержимое ✓), а расхождения расписываются ниже. Для record-файлов при расхождении содержимого добавляется пометка совпадающие записи: 1-5, 7-10 со списком записей, которые совпали.

    +

    Check выполняет каждое правило на подключённой карте и показывает строку прогресса и отчёт прохождения. Рядом с путём файла указывается, что именно проверялось (например, тип файла и размер, содержимое или точный FCI); если часть проверок прошла, а часть нет — каждый аспект помечается (тип файла ✓, размер ✗, содержимое ✓), а расхождения расписываются ниже. Несовпавшие сырые данные (FCI, содержимое, данные записей) показываются как поля только для чтения с моноширинным шрифтом — ожидаемое над фактическим, в одной и той же колонке — для удобного сравнения. Для record-файлов при расхождении содержимого добавляется пометка совпадающие записи: 1-5, 7-10 со списком записей, которые совпали.

    Опции сканирования «Profile from card»

    Диалог сканирования запрашивает имя профиля и предлагает селектор «FCP/FCI check» (те же три режима, по умолчанию Filetype + size), применяемый ко всем создаваемым правилам, а также список «Ignore contents of» (все отмечены по умолчанию) часто перезаписываемых файлов, содержимое которых пропускается: EF.LOCI, EF.PSLOCI, EF.EPSLOCI, EF.5GS3GPPLOCI, EF.Keys, EF.KeysPS, EF.SMS, EF.Kc, EF.KcGPRS, EF.LOCIGPRS, EF.CBMID, EF.SMSS. Ещё две отмеченные по умолчанию опции «Match first 4 bytes for» EF.IMSI и EF.ICCID захватывают содержимое этих файлов как маску только первых 4 байт (снимите для точного сравнения). Строка прогресса показывает N / всего файлов с текущим путём файла во время сканирования; при сканировании опции скрываются, а кнопки блокируются. Правила создаются только для файлов, которые реально существуют на карте (возвращён FCP-шаблон); отсутствующие файлы пропускаются. Пользовательские файлы из подвкладки Custom files включаются с той же проверкой существования.

    @@ -454,13 +456,14 @@ start.bat # запускает сервер (PWA + API) -

    6.5 Автоопределение ридера (start.sh)

    +

    6.5 Автоопределение ридера

    -

    Если ридер не обнаружен, сервер запускается без аргументов и показывает «Reader: none». Карту можно инициализировать позже кнопкой Equip на вкладке Card reader.

    +

    Если карта отсутствует, вкладка Card reader показывает «No card detected». Вставьте карту и нажмите Equip card для инициализации.

    6.6 Ручная установка

    # Создать и активировать venv
    diff --git a/frontend/help.html b/frontend/help.html
    index 886dd3b..440e822 100644
    --- a/frontend/help.html
    +++ b/frontend/help.html
    @@ -35,10 +35,18 @@
     		
  • 3GPP TS 23.038 — GSM 7-bit alphabet and DCS
  • 3GPP TS 24.008 / 24.301 / 24.501 — NAS cause codes
  • GlobalPlatform Card Specification v2.3.1
  • +
  • GlobalPlatform GPC v2.2 Amendment B v1.1 — Remote Application Management over HTTP
  • ISO/IEC 7816-4 — commands for interchange
  • ISO/IEC 9797-1 — MAC algorithms
  • +

    1.1 Interface

    +
      +
    • Header — the app version, an INSTALL PWA button (shown when the browser offers installation, enabling offline use), links to the project on GitHub and to this help, an EN/RU language toggle, and a dark/light theme toggle.
    • +
    • Language and theme choices are stored in localStorage and persist across reloads.
    • +
    • The help link opens this documentation at the section matching the current view (e.g. the Profiler sub-tab opens §5.6).
    • +
    +

    2. C-APDU tab

    @@ -106,14 +114,13 @@ C-APDU22Raw APDU hex Immediate Action81Proactive command or action indicator Error Action82Conditional error recovery with action indicator or proactive command - Script Chaining83Multi-packet script execution with First/Intermediary/Last flags - Response Type-Expanded/Compact/None response parsing indicator + Script Chaining83Multi-packet script execution with First/Intermediary/Last flags

    The Immediate Action builder offers an action indicator (81/82), a structured proactive command builder (REFRESH, DISPLAY TEXT, PLAY TONE with auto-generated COMPREHENSION-TLV objects), or a freeform hex input.

    Error Action TLV (Tag 82)

    -

    Error recovery per TS 102 226 §5.2.1.3 — one of three forms:

    +

    Error recovery per TS 102 226 §5.2.1.3 — one of four forms:

    • Proactive command: COMPREHENSION-TLV set with DISPLAY TEXT or PLAY TONE (only these two are allowed in an Error Action, TS 102 226 Table 5.9)
    • No action: 82 00
    • @@ -130,14 +137,8 @@
    • Context Preservation: UICC keeps security/transaction state open across chained scripts
    -

    Expanded Remote Response (TS 102 226 §5.2.2)

    -

    Per-command results with error details and chaining context:

    -
      -
    • Command number, status word, response data for each command
    • -
    • Error code and error info for failed commands (highlighted in red)
    • -
    • Script ID and position for chained script correlation (ID, FIRST, LAST)
    • -
    • Response type indicator: 'expanded' vs 'compact' vs 'none'
    • -
    +

    Response decoding (TS 102 226 §5.2.2)

    +

    Incoming Proof-of-Receipt responses are decoded by the server — expanded Remote Application response data (TS 102 226 §5.2.2) or the compact format. The Secured Packet view shows the outcome after Send to Card (see §3.1): the PoR status (TAR, counter, raw PoR), with the last command’s status word and response data filled into the Response parser tab.

    2.4 RAM/GP

    CLA = 80 (GlobalPlatform Card Specification v2.3.1). Remote Application Management commands for card content management. Built with the same chain builder as SIM/USIM: add rows, fill fields, and the chain preview updates automatically.

    @@ -259,7 +260,7 @@
  • AES requires a replay-protected counter: SPI1 bits b5 b4 must be 10 (counter higher) or 11 (counter +1) per TS 102 225 §5.1.2/§5.1.3.1
  • Padding byte configurable (00 default, or FF)
  • -

    A “Verify vs pySim” button cross-checks the assembled packet against pySim’s reference OtaDialectSms.encode_cmd. A “Send to Card” button delivers it via SMS-PP-DOWNLOAD ENVELOPE (when connected to the server).

    +

    A “Verify vs pySim” button cross-checks the assembled packet against pySim’s reference OtaDialectSms.encode_cmd. A “Send to Card” button delivers it via SMS-PP-DOWNLOAD ENVELOPE (when connected to the server). The returned Proof of Receipt is decoded and shown as a PoR status line (status, TAR, counter, raw PoR); the last command’s status word and response data are filled into the Response parser tab, and a successful PoR advances the replay counter and clears the packet.

    3.2 Cards

    Stores card presets locally in the browser (localStorage) so the Secured Packet view can auto-fill keys and parameters.

    @@ -275,7 +276,7 @@ KIc key / KID key16/24/32 hex chars (8/16/24-byte 3DES) or 32/48/64 hex chars (16/24/32-byte AES) keys -

    Export as JSON / Import JSON from clipboard share presets. The selected card preset auto-fills the Secured Packet form.

    +

    Presets can be shared with Export as JSON and Export to file, and restored with Import from file, Paste & import, or Import JSON from clipboard. The selected card preset auto-fills the Secured Packet form.

    3.3 RAM

    Delivers Remote Application Management operations as SCP80 secured packets via SMS-PP-DOWNLOAD ENVELOPE. The card must support SCP03 (AES or 3DES). A saved card preset from the Cards sub-tab provides the SPI, keys, TAR, and counter.

    @@ -301,7 +302,7 @@

    4. Response parser tab

    -

    Decodes a raw command response: pick the command that was sent, enter the SW (e.g. 9000) and the response data hex, then press Decode.

    +

    Decodes a raw command response: pick the command that was sent, enter the SW (e.g. 9000) and the response data hex, then press Decode. The fields are also auto-filled with the last command’s status word and response data after a successful “Send to Card” (see §3.1).

    • Command — SIM/USIM group (SELECT, STATUS, READ/UPDATE, PIN ops, CAT commands like TERMINAL PROFILE/ENVELOPE/FETCH/TERMINAL RESPONSE, MANAGE CHANNEL, …) or RAM/GP group (INSTALL, LOAD, DELETE, GET/STORE DATA, auth, SCP commands).
    • SW decode — status words resolved against generic, UICC (TS 102 221), and GlobalPlatform maps, with context auto-detected.
    • @@ -312,17 +313,18 @@

      5. Card reader (pySim) tab

      -

      Connects to a local pysim-otaman-server for live card operations. Sub-tabs: File manager, Custom files, Profiler, pySim command line, Raw APDU, and Proactive UICC.

      +

      Connects to a local pysim-otaman-server for live card operations: enter the server URL (default http://127.0.0.1:8080) and press Connect. The status area shows the reader/card state, and Equip card (re)initializes the card after insertion. Sub-tabs: File manager, Custom files, Profiler, pySim command line, Raw APDU, and Proactive UICC.

      5.1 File manager

      +

      The file system tree is displayed on the left; selecting a file opens its detail pane on the right.

      • Read — reads the selected file (auto-detects transparent vs record files)
      • -
      • Edit — modify hex data, Save to write back
      • +
      • Edit — modify hex data, Save to write back (or Cancel)
      • Raw / Decoded — toggle between hex dump and pySim-decoded JSON

      5.2 Custom files

      -

      Add files that pySim’s model does not cover. Persists in localStorage; JSON export/import.

      +

      Add files that pySim’s model does not cover: enter the full path (e.g. 3F00/7F20/6F46) and an alias (e.g. EF.SPN), then press Add; added files appear in the File manager tree. The list persists in localStorage and can be shared with Export as JSON / Export to file and restored with Import from file / Paste & import / Import JSON from clipboard.

      5.3 pySim command line

      Execute any pySim-shell command with usage hints (300 ms) and autocomplete.

      @@ -372,14 +374,14 @@
    • Each profile row shows its name and creation time, with Edit, Check, Export (download JSON), and Delete actions.

    Filesystem rules

    -

    Rules run sequentially. A filesystem rule is defined by:

    +

    Rules run sequentially. The editor shows the symbolic pySim name (when known) next to each rule’s path; use Add rule to append one and Save to keep the changes. A filesystem rule is defined by:

    • Path — starts with MF (e.g. MF/7F10/6F3A) or an ADF AID (e.g. A0000000871002/6F07).
    • FCP/FCI check — how much of the file control information to verify: Filetype only (FCP) (existence + file type), Filetype + size (FCP) (adds file size, or record length/count for record files), or Exact FCI (adds a byte-for-byte comparison of the raw SELECT response — the FCP template '62' — catching FID/AID, life-cycle status, security-attribute and proprietary-parameter changes).
    • File attributes — file type, size, record length and record count, taken from the FCP template (any may be left unset).
    • -
    • Contents (optional) — Exact hex equality, or Mask where ? is a per-nibble wildcard (a mask with no ? is a prefix match, e.g. 0891 for the IMSI MCC/MNC). Record files store a per-record list.
    • +
    • Check contents (optional) — Exact hex equality, or Mask where ? is a per-nibble wildcard (a mask with no ? is a prefix match, e.g. 0891 for the IMSI MCC/MNC). Record files store a per-record list.
    -

    Check runs every rule against the equipped card and shows a live progress line plus a pass/fail report. Each row states exactly what was verified next to the file path (e.g. filetype and size, contents or exact FCI); when some checks pass and others fail, each aspect is marked (filetype ✓, size ✗, contents ✓) with the mismatches detailed below. For record files with a contents mismatch, a matching records: 1-5, 7-10 note lists the records that did match.

    +

    Check runs every rule against the equipped card and shows a live progress line plus a pass/fail report. Each row states exactly what was verified next to the file path (e.g. filetype and size, contents or exact FCI); when some checks pass and others fail, each aspect is marked (filetype ✓, size ✗, contents ✓) with the mismatches detailed below. Mismatched raw data (FCI, contents, record data) is shown as read-only monospace fields — expected above actual, aligned in the same column — for easy comparison. For record files with a contents mismatch, a matching records: 1-5, 7-10 note lists the records that did match.

    “Profile from card” scan options

    The scan dialog asks for a profile name and offers a “FCP/FCI check” selector (the same three modes above, default Filetype + size) applied to every generated rule, plus an “Ignore contents of” checklist (all checked by default) of frequently-overwritten files whose contents are skipped: EF.LOCI, EF.PSLOCI, EF.EPSLOCI, EF.5GS3GPPLOCI, EF.Keys, EF.KeysPS, EF.SMS, EF.Kc, EF.KcGPRS, EF.LOCIGPRS, EF.CBMID, EF.SMSS. Two further checked-by-default options “Match first 4 bytes for” EF.IMSI and EF.ICCID capture those files’ contents as a mask of only the first 4 bytes (uncheck for exact matching). A progress line shows N / total files with the current file path while scanning; during the scan the options are hidden and the buttons are locked. Rules are created only for files that actually exist on the card (a FCP template is returned); missing files are skipped. Custom files from the Custom files sub-tab are included under the same existence check.

    @@ -454,13 +456,14 @@ start.bat # starts the server (serves PWA + API)
    -

    6.5 Reader auto-detection (start.sh)

    +

    6.5 Reader auto-detection

    -

    If no reader is detected, the server starts without reader arguments and shows “Reader: none”. The card can be initialized later via the Equip button in the Card reader tab.

    +

    If no card is present, the Card reader tab shows “No card detected”. Insert the card and click Equip card to initialize it.

    6.6 Manual installation

    # Create and activate a venv
    diff --git a/frontend/index.html b/frontend/index.html
    index c8d43e4..18946f8 100644
    --- a/frontend/index.html
    +++ b/frontend/index.html
    @@ -1002,7 +1002,7 @@ function cApduSwitchSubtab(name) {
     		const el = document.getElementById('c-apdu-sub-' + s);
     		if (el) el.classList.toggle('hidden', s !== name);
     	});
    -	setHelpAnchor({sim:'sim-rfm', usim:'usim-rfm', ber:'ber-tlv', ram:'ram-gp', parse:'c-apdu', httpota:'http-ota'}[name] || 'c-apdu');
    +	setHelpAnchor({sim:'sim-rfm', usim:'usim-rfm', ber:'ber-tlv', ram:'ram-gp', parse:'c-apdu-parser', httpota:'http-ota'}[name] || 'c-apdu');
     }
     
     // ===== HTTP OTA constructor =====
    @@ -5520,7 +5520,7 @@ function pysimSwitchSubtab(name) {
     	if (name === 'custom') pysimCustomRender();
     	if (name === 'proactive') { stkCheckMenu(); pysimEventsRender(); pysimProactiveLogRender(); pysimPliRender(); pysimPollStatusInit(); }
     	if (name === 'profiler') profilerSetView('list');
    -	pysimHelpAnchor = {cmd:'pysim-cmdline', apdu:'raw-apdu', files:'file-manager', custom:'custom-files', proactive:'proactive-uicc', profiler:'card-reader'}[name] || 'card-reader';
    +	pysimHelpAnchor = {cmd:'pysim-cmdline', apdu:'raw-apdu', files:'file-manager', custom:'custom-files', proactive:'proactive-uicc', profiler:'profiler'}[name] || 'card-reader';
     	setHelpAnchor(pysimHelpAnchor);
     }
     
    diff --git a/frontend/sw.js b/frontend/sw.js
    index 05d804f..5339652 100644
    --- a/frontend/sw.js
    +++ b/frontend/sw.js
    @@ -1,4 +1,4 @@
    -const CACHE = 'otaman-v60';
    +const CACHE = 'otaman-v61';
     const URLS = [
       'index.html',
       'help.html',