fix: install-form grant hygiene + correct 82 access coding (v3.6.12)
Live findings (2026-09-28): a browser-restored Receipt Generation privilege bit (third byte, ISD-only per GP Table 6-2) was silently sent and produced 6985, and the '82' access entries were missing the mandatory "Length of Access Domain DAP" byte, so the card rejected the ADF.USIM entry with 6A80. - ramResetGrants() clears the privilege / toolkit-enable / file-access checkboxes and refreshes the aggregates on load; ramInstallCap re-derives the privileges from the checkboxes at send time - no stale or browser-restored grant can be sent. - the privileges aggregate emits 1 or 3 bytes, never the invalid 2-byte form (GP Table 11-43), in both updateRcPriv and the chain's computePriv. - '82' entries carry the DAP-length byte: '00 01 00 00' (shared FS) and '<len> <ADF AID> 01 00 00' (ADF); the ADF AID is editable (rc-tk-adfaid, default A0000000871002 = ADF.USIM, 5..16 bytes enforced). - tests: ram_grants.test.js (aggregate forms, the send-time derivation, the load-time reset) and the updated access-parameter shapes in stk_params.test.js. 638 frontend / 496 Python green; version 3.6.12; sw simple-v285.
This commit is contained in:
@@ -31,7 +31,7 @@ from osmocom.tlv import BER_TLV_IE
|
||||
from osmocom.utils import rpad
|
||||
|
||||
|
||||
VERSION = '3.6.11'
|
||||
VERSION = '3.6.12'
|
||||
|
||||
MAX_ENVELOPE_SEGMENTS = 5 # max SMS segments for outgoing C-APDU in ENVELOPE
|
||||
|
||||
|
||||
Reference in New Issue
Block a user