Live findings (2026-09-28): a browser-restored Receipt Generation privilege
bit (third byte, ISD-only per GP Table 6-2) was silently sent and produced
6985, and the '82' access entries were missing the mandatory "Length of
Access Domain DAP" byte, so the card rejected the ADF.USIM entry with 6A80.
- ramResetGrants() clears the privilege / toolkit-enable / file-access
checkboxes and refreshes the aggregates on load; ramInstallCap re-derives
the privileges from the checkboxes at send time - no stale or
browser-restored grant can be sent.
- the privileges aggregate emits 1 or 3 bytes, never the invalid 2-byte
form (GP Table 11-43), in both updateRcPriv and the chain's computePriv.
- '82' entries carry the DAP-length byte: '00 01 00 00' (shared FS) and
'<len> <ADF AID> 01 00 00' (ADF); the ADF AID is editable
(rc-tk-adfaid, default A0000000871002 = ADF.USIM, 5..16 bytes enforced).
- tests: ram_grants.test.js (aggregate forms, the send-time derivation, the
load-time reset) and the updated access-parameter shapes in
stk_params.test.js.
638 frontend / 496 Python green; version 3.6.12; sw simple-v285.