feat: generic BIP terminal control (Simulator BIP pill) (v3.6.0)
BIP was only reachable through the SCP81 listener; cards that use TCP for
other purposes (an applet's OPEN CHANNEL, a push trigger without HTTP OTA)
now get a generic control surface, independent of SCP81.
Server:
- /api/bip/control starts a plain BIP session in three modes: sink
(default; a local TcpDumpServer that accepts the card's channels and only
logs conn/sink-rx/conn-close, never answering; port 0 = ephemeral, the
bound port is reported), passthru (dial the OPEN CHANNEL destination, TCP
client only) and redirect (fixed host:port).
- /api/bip/status returns {owner, bip, listener}; /api/bip/log and
/api/bip/log-clear share the BIP event log with /api/scp81/log.
- The session state is shared with the SCP81 listener and only one session
runs at a time: _bip_session_stop() stops whichever control started it
and the control responses report it as `replaced` (both directions,
SCP81 <-> BIP). State renamed _SCP81_MODE/_TARGET/_LISTENER/_LINK_EVENTS
-> _BIP_* plus _BIP_OWNER.
- TcpDumpServer logs conn-close and counts accepted connections; stop()
joins the accept thread so the port is really free on restart.
- The new control endpoints are blocked during test-script runs.
PWA:
- New Simulator pill BIP (after TR Config): mode select with notes,
Host/Port rules, Start/Stop with a "replaced" notice, status line (mode,
bound address, owner, channels), a Channels box and the shared BIP log
(reuses the SCP81 log renderer, now showing `peer`).
- The SCP81 status line marks a session owned by the BIP pill.
Help EN/RU 8.10, docs/api.md, AGENTS; CAT_TP/UDP recorded as not
implemented.
Tests: tests/test_bip.py (9) and frontend/tests/bip.test.js (6).
600 frontend / 482 Python green; version 3.6.0; sw simple-v273.
This commit is contained in:
+49
-1
@@ -65,9 +65,13 @@ a 3.x PWA).
|
||||
| `/api/pli-dict` | GET | Current dictionary (hex values per qualifier) |
|
||||
| `/api/pli-dict` | POST | Update dictionary entries |
|
||||
| `/api/scp81/bip` | POST | Start/stop the HTTP OTA listener (dump capture or PSK TLS server) |
|
||||
| `/api/scp81/status` | GET | BIP terminal + listener state (channels, PSK identities, handshake identity) |
|
||||
| `/api/scp81/status` | GET | BIP terminal + listener state (channels, PSK identities, handshake identity, `owner`) |
|
||||
| `/api/scp81/log` | GET | HTTP OTA event log (`?after=<seq>`) |
|
||||
| `/api/scp81/log-clear` | POST | Clear the HTTP OTA event log |
|
||||
| `/api/bip/control` | POST | Start/stop the generic BIP session (`sink` / `passthru` / `redirect`) |
|
||||
| `/api/bip/status` | GET | BIP session state + owner (same shape as `/api/scp81/status`) |
|
||||
| `/api/bip/log` | GET | BIP event log (`?after=<seq>`) |
|
||||
| `/api/bip/log-clear` | POST | Clear the BIP event log |
|
||||
| `/api/scp81/queue` | POST | Replace the SCP81 command script (optionally force-restart) |
|
||||
| `/api/scp81/script` | GET | Active command script + execution state and R-APDUs |
|
||||
| `/api/scp81/psk-map` | POST | Replace the PSK table of a running TLS listener |
|
||||
@@ -985,6 +989,47 @@ its run progress.
|
||||
|
||||
Stop either mode with `{"action": "stop"}` (also disables the BIP terminal).
|
||||
|
||||
### `POST /api/bip/control`
|
||||
|
||||
Generic BIP terminal control for the Simulator's **BIP** pill - the terminal
|
||||
side of the Bearer Independent Protocol for cards that use TCP without HTTP
|
||||
OTA. The session is shared with the SCP81 listener: only one BIP session runs
|
||||
at a time, starting either control stops the other, and the response reports
|
||||
what was stopped as `replaced: {"owner": "scp81"|"bip", "mode": ...}` (the
|
||||
PWA shows a notice).
|
||||
|
||||
```json
|
||||
{"action": "start", "mode": "sink", "host": "127.0.0.1", "port": 0}
|
||||
```
|
||||
|
||||
Modes:
|
||||
|
||||
- `sink` (default) - starts a local TCP listener that accepts the card's BIP
|
||||
channels and only logs what arrives (`conn`, `sink-rx`, `conn-close`); it
|
||||
never sends anything back. `port` may be `0`/omitted for an ephemeral port;
|
||||
the bound address is reported in the status. Use it for cards that open a
|
||||
TCP connection just to upload data.
|
||||
- `passthru` - no listener and no target: each channel dials the destination
|
||||
the card requests in OPEN CHANNEL (TCP client only, no default port; an
|
||||
incomplete or non-TCP request fails with result `3A`).
|
||||
- `redirect` - every channel connects to the required `host`/`port`; the
|
||||
address the card requests is only logged.
|
||||
|
||||
`link_events` (default `true`) controls the terminal-side Channel status
|
||||
events (TS 102 223 7.5.11). An invalid request never disturbs a running
|
||||
session. Stop with `{"action": "stop"}`; the response carries the same body
|
||||
as the status endpoints.
|
||||
|
||||
### `GET /api/bip/status`
|
||||
|
||||
Same shape as `GET /api/scp81/status`: `{"owner": "bip"|"scp81"|null,
|
||||
"bip": {...}, "listener": {...}}`. A running sink reports
|
||||
`{"mode": "sink", "host": ..., "port": ..., "connections": N}`.
|
||||
|
||||
### `GET /api/bip/log` / `POST /api/bip/log-clear`
|
||||
|
||||
The shared BIP event log (`?after=<seq>`) - identical to `/api/scp81/log`.
|
||||
|
||||
### `GET /api/scp81/status`
|
||||
|
||||
```json
|
||||
@@ -995,6 +1040,9 @@ Stop either mode with `{"action": "stop"}` (also disables the BIP terminal).
|
||||
"version_seen": "TLSv1.2", "cipher_seen": "PSK-AES128-CBC-SHA256"}}
|
||||
```
|
||||
|
||||
`owner` is `scp81` or `bip` (whichever control started the session), `null`
|
||||
when idle; it is returned by both this endpoint and `/api/bip/status`.
|
||||
|
||||
Listener modes: `tls` (local PSK TLS server), `dump` (capture-only TCP
|
||||
listener), `redirect` (no local listener; the BIP channels go straight to the
|
||||
configured `host:port`, e.g. an external HTTP OTA platform — reported as
|
||||
|
||||
Reference in New Issue
Block a user