feat: log the plaintext RAM APDUs of the install steps (v3.6.19)

`_ram_send_gp_apdu` (the shared step sender of /api/ram-install and
/api/ram-install-app) now logs every step's plaintext APDU and packed
packet, like /api/send-ota's unconditional lines:

  RAM C-APDU (INSTALL [for load]): 80E602000C07F0414C4641610100000000
  RAM SECURED-PACKET (INSTALL [for load]): 00281516212525000000...

No flag - the step name keeps the sequence readable, and --apdu-trace stays
the card-level (ENVELOPE) trace.  Tests: the logging pinned with stubbed
packet builders.

498 Python / 650 frontend green; version 3.6.19; sw simple-v292.
This commit is contained in:
2026-09-28 08:23:28 +03:00
parent face2268ca
commit 31162efc8c
5 changed files with 43 additions and 4 deletions
+5 -1
View File
@@ -31,7 +31,7 @@ from osmocom.tlv import BER_TLV_IE
from osmocom.utils import rpad
VERSION = '3.6.18'
VERSION = '3.6.19'
MAX_ENVELOPE_SEGMENTS = 5 # max SMS segments for outgoing C-APDU in ENVELOPE
@@ -1208,6 +1208,10 @@ def _ram_send_gp_apdu(server, scc, sp, state, step_name, apdu_hex):
sp_hex, _ = _build_secured_packet(spi1, spi2, sp['kic'], sp['kid'], sp['tar'],
state['cntr'], apdu_hex,
sp['kic_key'], sp['kid_key'])
# Log the plaintext APDU and the packed packet like /api/send-ota does
# (the step name keeps the sequence readable).
sys.stderr.write('RAM C-APDU (%s): %s\n' % (step_name, apdu_hex))
sys.stderr.write('RAM SECURED-PACKET (%s): %s\n' % (step_name, sp_hex))
except ValueError as e:
state['encode_error'] = str(e)
state['steps'].append({'name': step_name, 'por_status': 'encode_error',