9e85f522f6
Explore returned partial data (no ELF/module entries, the installed package
missing) and then failed with cntr_low. Two causes, both in the
actual-response SMS-SUBMIT path the card uses for big listings:
- `_find_sms_tpdu` read TLV lengths as a single byte; the FETCH carries
`8B 81 97 ...` (BER long form) for the big pages, so it returned a
corrupted, truncated TPDU.
- `_calc_ud_offset` treated the SMS-SUBMIT relative validity period (VPF=10)
as 7 bytes instead of 1, shifting the UD offset: `_parse_sms_concat` then
read a bogus UDH and reported no concatenation, so the segments never
assembled and the PoR/data was dropped ("RAM RESPONSE-PACKET: empty").
The step was marked failed, the counter did not advance, the same counter
was retried and the card answered `cntr_low`, which also blocked P1=10
(modules) where the installed package appears.
- the captured segments now always store the assembled UD (`submit_ud_hex`);
`_sms_submit_por()` rebuilds the DELIVER-style packet (`02 71 00` + UD) for
`_decode_por`. Verified against the live capture: por_ok, remote SW 6310,
438 hex chars of listing data (the exact bytes of the P1=20 page).
- `spPorAccepted` counts `actual_response_sms_submit` (0x0B) as accepted, so
the counter advances when the data follows via SMS-SUBMIT.
Explore queries follow GP Card Spec v2.3.1 11.4.2.2: compact listings
(P2.b2=0) with the chained GET RESPONSE (`ramGetStatusApdu`, paging P2=00 ->
P2=01), the malformed P2=02 attempt is gone, and the ISD-only query (P1=80)
never pages with next-occurrence (the card shall reject it).
Tests: Python SmsSubmitCaptureTest with the live FETCH bytes (TPDU length,
UD offset, concat reassembly, 027100+UD decode); ram.test.js checks the APDU
builder and the missing P2=02 attempt; cards_counter covers 0x0B.
608 frontend / 492 Python green; version 3.6.4; sw simple-v277.
92 lines
3.6 KiB
JavaScript
92 lines
3.6 KiB
JavaScript
const { test } = require('node:test');
|
|
const assert = require('node:assert');
|
|
const fs = require('node:fs');
|
|
const path = require('node:path');
|
|
|
|
const html = fs.readFileSync(path.join(__dirname, '..', 'index.html'), 'utf8');
|
|
|
|
function extractFunc(src, name) {
|
|
const re = new RegExp('function\\s+' + name + '\\s*\\([^)]*\\)\\s*\\{');
|
|
const m = re.exec(src);
|
|
if (!m) throw new Error('function ' + name + ' not found');
|
|
let i = m.index + m[0].length - 1;
|
|
let depth = 0;
|
|
for (; i < src.length; i++) {
|
|
if (src[i] === '{') depth++;
|
|
else if (src[i] === '}') {
|
|
depth--;
|
|
if (depth === 0) break;
|
|
}
|
|
}
|
|
return src.slice(m.index, i + 1);
|
|
}
|
|
|
|
let code = '';
|
|
for (const fn of ['cardsTarValue', 'cardsApplyFields', 'cardsApply',
|
|
'spRefreshFromPreset', 'spPorAccepted', 'spNextCntr']) {
|
|
code += extractFunc(html, fn) + '\n';
|
|
}
|
|
eval(code);
|
|
|
|
// The SP form is a working copy: the preset is the source of truth, and
|
|
// every SCP80/RAM operation re-reads it before starting (v3.6.3).
|
|
function fakeEnv(selValue, selId, presetCntr) {
|
|
const els = {};
|
|
for (const id of ['sp-spi1', 'sp-spi2-hex', 'sp-kic-idx', 'sp-kic-alg',
|
|
'sp-kid-idx', 'sp-kid-alg', 'sp-tar', 'sp-cntr', 'sp-kic-key', 'sp-kid-key']) {
|
|
els[id] = { value: '' };
|
|
}
|
|
els[selId || 'sp-card-sel'] = { value: selValue };
|
|
globalThis.document = { getElementById: id => els[id] || null };
|
|
globalThis.cards = [{ name: 'C', cntr: presetCntr, spi1: '16', spi2: '01',
|
|
kic: '15', kid: '15', tar: '000000', uiccTar: 'B00000',
|
|
kicKey: 'AA', kidKey: 'BB' }];
|
|
globalThis._spTarKey = 'uiccTar';
|
|
globalThis.updateSpKic = () => {};
|
|
globalThis.updateSpKid = () => {};
|
|
globalThis.spInvalidate = () => {};
|
|
globalThis.updateSp = () => {};
|
|
let gen = 0;
|
|
globalThis.genSp = () => { gen++; };
|
|
return { els, gen: () => gen };
|
|
}
|
|
|
|
test('spRefreshFromPreset re-reads the edited preset before an operation', () => {
|
|
const env = fakeEnv('0', 'sp-card-sel', '00000000AA');
|
|
env.els['sp-cntr'].value = '0000000001'; // stale form copy
|
|
assert.strictEqual(spRefreshFromPreset('sp-card-sel'), '00000000AA');
|
|
assert.strictEqual(env.els['sp-cntr'].value, '00000000AA');
|
|
assert.ok(env.gen() > 0, 'the packet must be regenerated from the new counter');
|
|
// no preset selected: the manual form is left alone
|
|
globalThis.cards = [];
|
|
assert.strictEqual(spRefreshFromPreset('sp-card-sel'), '');
|
|
assert.strictEqual(env.els['sp-cntr'].value, '00000000AA');
|
|
});
|
|
|
|
test('spRefreshFromPreset for the RAM selector targets the ISD TAR', () => {
|
|
const env = fakeEnv('0', 'ram-card-sel', '0000000010');
|
|
assert.strictEqual(spRefreshFromPreset('ram-card-sel'), '0000000010');
|
|
assert.strictEqual(_spTarKey, 'tar');
|
|
assert.strictEqual(env.els['sp-tar'].value, '000000');
|
|
});
|
|
|
|
test('cardsApplyFields fills the form without generating a packet', () => {
|
|
const env = fakeEnv('0', 'sp-card-sel', '0000000007');
|
|
env.els['sp-cntr'].value = 'nonsense';
|
|
assert.strictEqual(cardsApplyFields(0), true);
|
|
assert.strictEqual(env.els['sp-cntr'].value, '0000000007');
|
|
assert.strictEqual(env.gen(), 0, 'a plain field refresh must not rebuild the packet');
|
|
cardsApply(0);
|
|
assert.strictEqual(env.gen(), 1);
|
|
assert.strictEqual(cardsApplyFields(3), false);
|
|
});
|
|
|
|
test('spPorAccepted treats a missing PoR and por_ok as accepted', () => {
|
|
assert.strictEqual(spPorAccepted(undefined), true);
|
|
assert.strictEqual(spPorAccepted({ response_status: 'por_ok' }), true);
|
|
// 0x0B: the real response follows as an SMS-SUBMIT - the packet was consumed
|
|
assert.strictEqual(spPorAccepted({ response_status: 'actual_response_sms_submit' }), true);
|
|
assert.strictEqual(spPorAccepted({ response_status: 'cntr_low' }), false);
|
|
assert.strictEqual(spPorAccepted({ response_status: 'rc_cc_ds_failed' }), false);
|
|
});
|