feat: generic BIP terminal control (Simulator BIP pill) (v3.6.0)

BIP was only reachable through the SCP81 listener; cards that use TCP for
other purposes (an applet's OPEN CHANNEL, a push trigger without HTTP OTA)
now get a generic control surface, independent of SCP81.

Server:
- /api/bip/control starts a plain BIP session in three modes: sink
  (default; a local TcpDumpServer that accepts the card's channels and only
  logs conn/sink-rx/conn-close, never answering; port 0 = ephemeral, the
  bound port is reported), passthru (dial the OPEN CHANNEL destination, TCP
  client only) and redirect (fixed host:port).
- /api/bip/status returns {owner, bip, listener}; /api/bip/log and
  /api/bip/log-clear share the BIP event log with /api/scp81/log.
- The session state is shared with the SCP81 listener and only one session
  runs at a time: _bip_session_stop() stops whichever control started it
  and the control responses report it as `replaced` (both directions,
  SCP81 <-> BIP).  State renamed _SCP81_MODE/_TARGET/_LISTENER/_LINK_EVENTS
  -> _BIP_* plus _BIP_OWNER.
- TcpDumpServer logs conn-close and counts accepted connections; stop()
  joins the accept thread so the port is really free on restart.
- The new control endpoints are blocked during test-script runs.

PWA:
- New Simulator pill BIP (after TR Config): mode select with notes,
  Host/Port rules, Start/Stop with a "replaced" notice, status line (mode,
  bound address, owner, channels), a Channels box and the shared BIP log
  (reuses the SCP81 log renderer, now showing `peer`).
- The SCP81 status line marks a session owned by the BIP pill.

Help EN/RU 8.10, docs/api.md, AGENTS; CAT_TP/UDP recorded as not
implemented.

Tests: tests/test_bip.py (9) and frontend/tests/bip.test.js (6).
600 frontend / 482 Python green; version 3.6.0; sw simple-v273.
This commit is contained in:
2026-09-27 15:28:23 +03:00
parent 73ef3a67ca
commit 18a36a8f27
14 changed files with 924 additions and 97 deletions
+49 -1
View File
@@ -65,9 +65,13 @@ a 3.x PWA).
| `/api/pli-dict` | GET | Current dictionary (hex values per qualifier) |
| `/api/pli-dict` | POST | Update dictionary entries |
| `/api/scp81/bip` | POST | Start/stop the HTTP OTA listener (dump capture or PSK TLS server) |
| `/api/scp81/status` | GET | BIP terminal + listener state (channels, PSK identities, handshake identity) |
| `/api/scp81/status` | GET | BIP terminal + listener state (channels, PSK identities, handshake identity, `owner`) |
| `/api/scp81/log` | GET | HTTP OTA event log (`?after=<seq>`) |
| `/api/scp81/log-clear` | POST | Clear the HTTP OTA event log |
| `/api/bip/control` | POST | Start/stop the generic BIP session (`sink` / `passthru` / `redirect`) |
| `/api/bip/status` | GET | BIP session state + owner (same shape as `/api/scp81/status`) |
| `/api/bip/log` | GET | BIP event log (`?after=<seq>`) |
| `/api/bip/log-clear` | POST | Clear the BIP event log |
| `/api/scp81/queue` | POST | Replace the SCP81 command script (optionally force-restart) |
| `/api/scp81/script` | GET | Active command script + execution state and R-APDUs |
| `/api/scp81/psk-map` | POST | Replace the PSK table of a running TLS listener |
@@ -985,6 +989,47 @@ its run progress.
Stop either mode with `{"action": "stop"}` (also disables the BIP terminal).
### `POST /api/bip/control`
Generic BIP terminal control for the Simulator's **BIP** pill - the terminal
side of the Bearer Independent Protocol for cards that use TCP without HTTP
OTA. The session is shared with the SCP81 listener: only one BIP session runs
at a time, starting either control stops the other, and the response reports
what was stopped as `replaced: {"owner": "scp81"|"bip", "mode": ...}` (the
PWA shows a notice).
```json
{"action": "start", "mode": "sink", "host": "127.0.0.1", "port": 0}
```
Modes:
- `sink` (default) - starts a local TCP listener that accepts the card's BIP
channels and only logs what arrives (`conn`, `sink-rx`, `conn-close`); it
never sends anything back. `port` may be `0`/omitted for an ephemeral port;
the bound address is reported in the status. Use it for cards that open a
TCP connection just to upload data.
- `passthru` - no listener and no target: each channel dials the destination
the card requests in OPEN CHANNEL (TCP client only, no default port; an
incomplete or non-TCP request fails with result `3A`).
- `redirect` - every channel connects to the required `host`/`port`; the
address the card requests is only logged.
`link_events` (default `true`) controls the terminal-side Channel status
events (TS 102 223 7.5.11). An invalid request never disturbs a running
session. Stop with `{"action": "stop"}`; the response carries the same body
as the status endpoints.
### `GET /api/bip/status`
Same shape as `GET /api/scp81/status`: `{"owner": "bip"|"scp81"|null,
"bip": {...}, "listener": {...}}`. A running sink reports
`{"mode": "sink", "host": ..., "port": ..., "connections": N}`.
### `GET /api/bip/log` / `POST /api/bip/log-clear`
The shared BIP event log (`?after=<seq>`) - identical to `/api/scp81/log`.
### `GET /api/scp81/status`
```json
@@ -995,6 +1040,9 @@ Stop either mode with `{"action": "stop"}` (also disables the BIP terminal).
"version_seen": "TLSv1.2", "cipher_seen": "PSK-AES128-CBC-SHA256"}}
```
`owner` is `scp81` or `bip` (whichever control started the session), `null`
when idle; it is returned by both this endpoint and `/api/bip/status`.
Listener modes: `tls` (local PSK TLS server), `dump` (capture-only TCP
listener), `redirect` (no local listener; the BIP channels go straight to the
configured `host:port`, e.g. an external HTTP OTA platform — reported as