fix: recover from a card swap without a server restart (v3.5.2)

Equip was broken after a card swap: auto-equip (and manual Equip) failed with
"Failed to transmit with protocol T0. Card was removed. (0x80100069)" until
the server was restarted.

Chain (v3.1.2 regression):
- _handle_card_disconnect() cleared server.card/scc but not pySim's
  app.card/app.rs/app.lchan, so the removed card - and with it the old PC/SC
  link and its exclusive card handle - stayed referenced; handlers using
  app.rs (e.g. the PWA's /api/tree poll) kept transmitting over the dead card.
- those errors carry hresult=0x80100069 (SCARD_W_REMOVED_CARD), but
  _is_pcsc_error() treated any PC/SC error as a dead service and set
  _TRANSPORT_STALE; the next auto-equip then called _ensure_transport(),
  which built a second PcscSimLink while the old one was still connected -
  the new link inherited the removed card's handle and failed on its first
  APDU.  No retry existed, so every later equip repeated the failure.

Fixes:
- _is_transport_fatal(): only service/context hresults rebuild the transport
  (E_NO_SERVICE, E_SERVICE_STOPPED, E_NO_READERS_AVAILABLE, E_INVALID_HANDLE,
  ...); card-level states (W_REMOVED_CARD, E_NO_SMARTCARD, W_RESET_CARD,
  W_UNRESPONSIVE_CARD, W_UNPOWERED_CARD) reconnect on the existing link.
  All 8 disconnect call sites pass the new verdict.
- _clear_app_card_state(): unequip through pySim's own equip(None, None)
  before clearing app.card/app.rs/app.lchan.  Nulling them alone would make
  the next equip abort with "CommandSet ... is already installed"
  (PysimApp.equip() unregisters the previous profile's command sets from
  self.rs), which left /api/tree broken after a swap.  A failed auto-equip
  attempt unequips the half-initialized shell as well.  Handlers now answer
  "no card" instead of transmitting over the dead card, and the old link
  becomes collectable.
- _ensure_transport(): disconnects the old link before building the new one
  (restoring it if the factory fails) - the rebuild path is now safe for the
  real pcscd-restart case.
- auto-equip: _auto_equip_attempt()/_auto_equip_attempts() retry up to 3
  times, 1 s apart (fatal failures mark the transport so the retry rebuilds);
  the watchdog re-arms it (_auto_equip_rearm) every 5 s while a card is
  present and the session is down, with exponential backoff to 60 s for a
  card that cannot be initialized at all.
- fastinit.init_card_fast(): also retries once after a PC/SC link error
  (CardConnectionException/NoCardException), not only after SW mismatches.

Tests: transport-fatal classification, app-state clearing, shell unequip,
old-link release, auto-equip retry/backoff/re-arm, fastinit link retry.
547 frontend / 410 Python green; version 3.5.2; sw cache simple-v254.
This commit is contained in:
2026-09-24 08:57:06 +03:00
parent 73ff6a60bd
commit 0f8c6dea50
9 changed files with 434 additions and 52 deletions
+2 -1
View File
@@ -752,7 +752,8 @@ pysim-simple-server --http-port 8080
- **"Failed to establish context: Access denied"** — `pcscd` isn't running or the user lacks permission: `sudo systemctl enable --now pcscd && sudo usermod -a -G pcscd $USER`.
- **"device file /dev/ttyUSB0 does not exist"** — no serial reader; connect a USB reader or pass `-d` explicitly. The server still starts without a reader.
- **"Service not available" (0x8010001D) / reader gone after a `pcscd` restart** — the server recovers by itself: a watchdog revives pyscard's presence monitor and the next equip (automatic after re-insertion, or the **Equip** button) recreates the PC/SC transport. No server restart needed.
- **"Service not available" (0x8010001D) / reader gone after a `pcscd` restart** — the server recovers by itself: a watchdog revives pyscard's presence monitor and the next equip (automatic after re-insertion, or the **Equip** button) recreates the PC/SC transport (releasing the old link first). No server restart needed.
- **"Card was removed" errors / auto-equip fails after a card swap** — a normal card swap reconnects on the existing transport (card-level PC/SC errors no longer force a transport rebuild), a failed auto-equip is retried up to 3 times, and the watchdog re-arms it every 5 s while a card is present. A removed card also clears the card state completely, so handlers answer "no card" instead of transmitting over the dead card.
### API reference