From b88f04fc6963b0e5bd05e1c40ec6185c53b49a4c Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?=D0=90=D0=BD=D1=82=D0=BE=D0=BD=20=D0=A2=D1=80=D0=BE=D1=88?=
=?UTF-8?q?=D0=B8=D0=BD?=
Date: Sat, 26 Sep 2026 00:33:38 +0300
Subject: [PATCH] feat: name standard package AIDs in the Explore / SCP81 /
R-APDU views (v3.5.7)
The RAM Explore view, the SCP81 GET STATUS script results and the R-APDU
parser tree showed package AIDs as bare hex. A shared resolver now
annotates the known standard JavaCard / ETSI / 3GPP / GlobalPlatform
package AIDs with their library name (workspace export-file study
`docs/JAVACARD.md`, 2026-09-26, plus the GP default ISD AID from GP Card
Spec v2.3.1 H.1.3); a RID table gives a weak owner hint for otherwise
unknown AIDs, and vendor/applet AIDs stay bare.
- JC_AID_NAMES / JC_AID_RIDS + jcAidName / jcAidSuffix / jcAidHtml.
- Wired into ramRenderExploreHtml (ISD, applications, ELFs, module and SD
AIDs), scp81ResultLines GET STATUS listings and decodeTlvValue
(4F/84/C4/CC - the R-APDU parser tree).
- aid_names.test.js (families, normalisation, RID hints, malformed input,
table sanity) plus render assertions in ram.test.js and scp81.test.js.
- Help EN/RU note the annotation; table is hand-maintained from the note.
561 frontend / 421 Python green; version 3.5.7; sw cache simple-v260.
---
frontend/help-ru.html | 4 +-
frontend/help.html | 4 +-
frontend/index.html | 130 +++++++++++++++++++++++++++----
frontend/sw.js | 2 +-
frontend/tests/aid_names.test.js | 93 ++++++++++++++++++++++
frontend/tests/ram.test.js | 21 ++++-
frontend/tests/scp81.test.js | 13 ++++
pyproject.toml | 2 +-
pysim_simple_server/server.py | 2 +-
9 files changed, 248 insertions(+), 23 deletions(-)
create mode 100644 frontend/tests/aid_names.test.js
diff --git a/frontend/help-ru.html b/frontend/help-ru.html
index 91ad414..d01b595 100644
--- a/frontend/help-ru.html
+++ b/frontend/help-ru.html
@@ -271,6 +271,7 @@
4F, 84, C4, CC) дополняются именем стандартного библиотечного пакета, когда AID — известный пакет JavaCard / ETSI / 3GPP / GlobalPlatform (или подсказкой по RID).DELETE по AID).0x80).
Стандартные пакетные AID дополняются именем библиотеки (пакеты JavaCard / ETSI / 3GPP / GlobalPlatform, а также AID ISD по умолчанию); неизвестные и вендорские AID остаются без имени.
Удаление подтверждается через диалог браузера перед отправкой команды GP DELETE через SCP80. Обзор автоматически обновляется после успешного удаления.
Блок Настройки (по умолчанию свёрнут; при отличии от эталонных значений показывается метка изменены; применяются при Start, сохраняются в браузере) открывает HTTP-фрейминг — Chunked body / размер чанка (0 = весь ответ в одной TLS-записи), заголовок Connection, компактные заголовки (без необязательного пробела после :, допустимо по RFC 7230 §3.2) и Next-URI (флажок + шаблон; выкл - команда без ответа: карта выполнит команду, не вернёт строку ответа и закроет сессию) — и фрейминг скрипта (неопределённая длина AE 80 … / определённая AA в Command Scripting template, теги comprehension-required и необязательный X-Admin-Targeted-Application со своим флажком). Показывать события канала (ENVELOPE Channel status, TS 102 223 §7.5.11) действует во всех режимах. Соединение удерживается между POST-запросами и аккуратно закрывается на 204. У TLS нет настроек: слушатель предлагает TLS 1.0–1.2 и все PSK-наборы, а карта выбирает; строка состояния и TLS-журнал показывают фактически использованные версию и набор, а сбой рукопожатия по причине TLS/набора пишется как tls-handshake-failed.
Сценарий выбирает список команд, отдаваемый в сессии — Нет (оставить настроенный на сервере скрипт) или один из скриптов подвкладки «Скрипты»; выбранный список передаётся серверу при старте слушателя.
-Строка состояния показывает слушатель, согласованный идентификатор и активные каналы (байты in/out). Панель Script results (R-APDUs) перечисляет каждый отданный C-APDU с его R-APDU/SW и прогрессом done/total; журнал HTTP OTA log фиксирует OPEN/CLOSE CHANNEL, SEND/RECEIVE DATA и каждый шаг TLS/HTTP/скрипта (tls-handshake, tls-request, script-send, script-rapdu, script-page, script-done, data-available, peer-close), кнопка Clear очищает его.
Строка состояния показывает слушатель, согласованный идентификатор и активные каналы (байты in/out). Панель Script results (R-APDUs) перечисляет каждый отданный C-APDU с его R-APDU/SW и прогрессом done/total (списки GET STATUS дополняют известные стандартные пакетные AID именем библиотеки); журнал HTTP OTA log фиксирует OPEN/CLOSE CHANNEL, SEND/RECEIVE DATA и каждый шаг TLS/HTTP/скрипта (tls-handshake, tls-request, script-send, script-rapdu, script-page, script-done, data-available, peer-close), кнопка Clear очищает его.
Именованные списки APDU хранятся локально (simple_scripts) и передаются серверу при старте слушателя. Каждый список — последовательность hex C-APDU (по одной в строке; допускаются комментарии #/;). Кнопка Новый создаёт список из шаблона:
4F, 84, C4, CC) are annotated with the standard library package name when the AID is a known JavaCard / ETSI / 3GPP / GlobalPlatform package (or a RID owner hint).DELETE by AID).0x80) buttons.Standard package AIDs are annotated with their library name (JavaCard / ETSI / 3GPP / GlobalPlatform packages, plus the default GlobalPlatform ISD AID); unknown and vendor AIDs stay bare.
Delete confirms via a browser prompt before sending the GP DELETE command via SCP80. The explorer auto-refreshes after a successful deletion.
The Options block (collapsed by default; a custom marker appears when anything differs from the reference defaults; applied at Start, remembered in the browser) exposes the HTTP framing — Chunked body / chunk size (0 = the whole response in one TLS record), the Connection header, compact headers (omitting the optional space after :, legal per RFC 7230 §3.2) and the Next-URI (checkbox + template; unchecked = one-shot: the card executes the command, returns no response string and closes the session) — and the script framing (indefinite AE 80 … / definite AA Command Scripting template, comprehension-required tags, and the optional X-Admin-Targeted-Application with its own checkbox). Show link events (Channel status ENVELOPEs, TS 102 223 §7.5.11) applies to every mode. The connection is kept open between POSTs and closed cleanly at the 204. TLS itself has no settings: the listener offers TLS 1.0–1.2 and all PSK suites and lets the card negotiate; the state line and the TLS log show the version/cipher actually used, and a handshake that fails for a TLS/cipher reason is logged as tls-handshake-failed.
Script selects the command list served over the session — None (leave the server's configured script) or one of the scripts from the Scripts pill; the chosen list is sent to the server when the listener starts.
-The state line shows the listener, the negotiated identity and live channels (bytes in/out). Script results (R-APDUs) lists each served C-APDU with its R-APDU/SW and a done/total progress; the HTTP OTA log records OPEN/CLOSE CHANNEL, SEND/RECEIVE DATA and every TLS/HTTP/script step (tls-handshake, tls-request, script-send, script-rapdu, script-page, script-done, data-available, peer-close), with Clear.
The state line shows the listener, the negotiated identity and live channels (bytes in/out). Script results (R-APDUs) lists each served C-APDU with its R-APDU/SW and a done/total progress (GET STATUS listings annotate known standard package AIDs with their library name); the HTTP OTA log records OPEN/CLOSE CHANNEL, SEND/RECEIVE DATA and every TLS/HTTP/script step (tls-handshake, tls-request, script-send, script-rapdu, script-page, script-done, data-available, peer-close), with Clear.
Named APDU lists stored locally (simple_scripts) and sent to the server when a listener starts. Each list is a sequence of hex C-APDUs (one per line; #/; comments allowed). New creates one from a template: