|
| 1 | +#include "mag_helpers.h" |
| 2 | + |
| 3 | +#define GPIO_PIN_A &gpio_ext_pa6 |
| 4 | +#define GPIO_PIN_B &gpio_ext_pa7 |
| 5 | +#define RFID_PIN &gpio_rfid_carrier_out |
| 6 | + |
| 7 | +#define ZERO_PREFIX 25 // n zeros prefix |
| 8 | +#define ZERO_BETWEEN 53 // n zeros between tracks |
| 9 | +#define ZERO_SUFFIX 25 // n zeros suffix |
| 10 | +#define US_CLOCK 240 |
| 11 | +#define US_INTERPACKET 10 |
| 12 | + |
| 13 | +// bits per char on a given track |
| 14 | +const uint8_t bitlen[] = {7, 5, 5}; |
| 15 | +// char offset by track |
| 16 | +const int sublen[] = {32, 48, 48}; |
| 17 | +uint8_t bit_dir = 0; |
| 18 | + |
| 19 | +void play_bit_rfid(uint8_t send_bit) { |
| 20 | + // internal TX over RFID coil |
| 21 | + bit_dir ^= 1; |
| 22 | + furi_hal_gpio_write(RFID_PIN, bit_dir); |
| 23 | + furi_delay_us(US_CLOCK); |
| 24 | + |
| 25 | + if(send_bit) { |
| 26 | + bit_dir ^= 1; |
| 27 | + furi_hal_gpio_write(RFID_PIN, bit_dir); |
| 28 | + } |
| 29 | + furi_delay_us(US_CLOCK); |
| 30 | + |
| 31 | + furi_delay_us(US_INTERPACKET); |
| 32 | +} |
| 33 | + |
| 34 | +/*static void play_bit_gpio(uint8_t send_bit) { |
| 35 | + // external TX over motor driver wired to PIN_A and PIN_B |
| 36 | + bit_dir ^= 1; |
| 37 | + furi_hal_gpio_write(GPIO_PIN_A, bit_dir); |
| 38 | + furi_hal_gpio_write(GPIO_PIN_B, !bit_dir); |
| 39 | + furi_delay_us(US_CLOCK); |
| 40 | +
|
| 41 | + if(send_bit) { |
| 42 | + bit_dir ^= 1; |
| 43 | + furi_hal_gpio_write(GPIO_PIN_A, bit_dir); |
| 44 | + furi_hal_gpio_write(GPIO_PIN_B, !bit_dir); |
| 45 | + } |
| 46 | + furi_delay_us(US_CLOCK); |
| 47 | +
|
| 48 | + furi_delay_us(US_INTERPACKET); |
| 49 | +}*/ |
| 50 | + |
| 51 | +void rfid_tx_init() { |
| 52 | + // initialize RFID system for TX |
| 53 | + furi_hal_power_enable_otg(); |
| 54 | + |
| 55 | + furi_hal_ibutton_start_drive(); |
| 56 | + furi_hal_ibutton_pin_low(); |
| 57 | + |
| 58 | + // Initializing at GpioSpeedLow seems sufficient for our needs; no improvements seen by increasing speed setting |
| 59 | + |
| 60 | + // this doesn't seem to make a difference, leaving it in |
| 61 | + furi_hal_gpio_init(&gpio_rfid_data_in, GpioModeOutputPushPull, GpioPullNo, GpioSpeedLow); |
| 62 | + furi_hal_gpio_write(&gpio_rfid_data_in, false); |
| 63 | + |
| 64 | + // false->ground RFID antenna; true->don't ground |
| 65 | + // skotopes (RFID dev) say normally you'd want RFID_PULL in high for signal forming, while modulating RFID_OUT |
| 66 | + // dunaevai135 had it low in their old code. Leaving low, as it doesn't seem to make a difference on my janky antenna |
| 67 | + furi_hal_gpio_init(&gpio_nfc_irq_rfid_pull, GpioModeOutputPushPull, GpioPullNo, GpioSpeedLow); |
| 68 | + furi_hal_gpio_write(&gpio_nfc_irq_rfid_pull, false); |
| 69 | + |
| 70 | + furi_hal_gpio_init(RFID_PIN, GpioModeOutputPushPull, GpioPullNo, GpioSpeedLow); |
| 71 | + |
| 72 | + // confirm this delay is needed / sufficient? legacy from hackathon... |
| 73 | + furi_delay_ms(300); |
| 74 | +} |
| 75 | + |
| 76 | +void rfid_tx_reset() { |
| 77 | + // reset RFID system |
| 78 | + furi_hal_gpio_write(RFID_PIN, 0); |
| 79 | + |
| 80 | + furi_hal_rfid_pins_reset(); |
| 81 | + furi_hal_power_disable_otg(); |
| 82 | +} |
| 83 | + |
| 84 | +/* |
| 85 | +static void gpio_tx_init() { |
| 86 | + furi_hal_power_enable_otg(); |
| 87 | + gpio_item_configure_all_pins(GpioModeOutputPushPull); |
| 88 | +} |
| 89 | +
|
| 90 | +static void gpio_tx_reset() { |
| 91 | + gpio_item_set_pin(PIN_A, 0); |
| 92 | + gpio_item_set_pin(PIN_B, 0); |
| 93 | + gpio_item_set_pin(ENABLE_PIN, 0); |
| 94 | +
|
| 95 | + gpio_item_configure_all_pins(GpioModeAnalog); |
| 96 | + furi_hal_power_disable_otg(); |
| 97 | +} |
| 98 | +*/ |
| 99 | + |
| 100 | +void track_to_bits(uint8_t* bit_array, const char* track_data, uint8_t track_index) { |
| 101 | + // convert individual track to bits |
| 102 | + |
| 103 | + int tmp, crc, lrc = 0; |
| 104 | + int i = 0; |
| 105 | + |
| 106 | + // convert track data to bits |
| 107 | + for(uint8_t j = 0; track_data[i] != '\0'; j++) { |
| 108 | + crc = 1; |
| 109 | + tmp = track_data[j] - sublen[track_index]; |
| 110 | + |
| 111 | + for(uint8_t k = 0; k < bitlen[track_index] - 1; k++) { |
| 112 | + crc ^= tmp & 1; |
| 113 | + lrc ^= (tmp & 1) << k; |
| 114 | + bit_array[i] = tmp & 1; |
| 115 | + i++; |
| 116 | + tmp >>= 1; |
| 117 | + } |
| 118 | + bit_array[i] = crc; |
| 119 | + i++; |
| 120 | + } |
| 121 | + |
| 122 | + // finish calculating final "byte" (LRC) |
| 123 | + tmp = lrc; |
| 124 | + crc = 1; |
| 125 | + for(uint8_t j = 0; j < bitlen[track_index] - 1; j++) { |
| 126 | + crc ^= tmp & 1; |
| 127 | + bit_array[i] = tmp & 1; |
| 128 | + i++; |
| 129 | + tmp >>= 1; |
| 130 | + } |
| 131 | + bit_array[i] = crc; |
| 132 | + i++; |
| 133 | + |
| 134 | + // My makeshift end sentinel. All other values 0/1 |
| 135 | + bit_array[i] = 2; |
| 136 | + i++; |
| 137 | + |
| 138 | + //bool is_correct_length = (i == (strlen(track_data) * bitlen[track_index])); |
| 139 | + //furi_assert(is_correct_length); |
| 140 | +} |
| 141 | + |
| 142 | +void mag_spoof_single_track_rfid(FuriString* track_str, uint8_t track_index) { |
| 143 | + // Quick testing... |
| 144 | + |
| 145 | + rfid_tx_init(); |
| 146 | + |
| 147 | + size_t from; |
| 148 | + size_t to; |
| 149 | + |
| 150 | + // TODO ';' in first track case |
| 151 | + if(track_index == 0) { |
| 152 | + from = furi_string_search_char(track_str, '%'); |
| 153 | + to = furi_string_search_char(track_str, '?', from); |
| 154 | + } else if(track_index == 1) { |
| 155 | + from = furi_string_search_char(track_str, ';'); |
| 156 | + to = furi_string_search_char(track_str, '?', from); |
| 157 | + } else { |
| 158 | + from = 0; |
| 159 | + to = furi_string_size(track_str); |
| 160 | + } |
| 161 | + if(from >= to) { |
| 162 | + return; |
| 163 | + } |
| 164 | + furi_string_mid(track_str, from, to - from + 1); |
| 165 | + |
| 166 | + const char* data = furi_string_get_cstr(track_str); |
| 167 | + uint8_t bit_array[(strlen(data) * bitlen[track_index]) + 1]; |
| 168 | + track_to_bits(bit_array, data, track_index); |
| 169 | + |
| 170 | + FURI_CRITICAL_ENTER(); |
| 171 | + for(uint8_t i = 0; i < ZERO_PREFIX; i++) play_bit_rfid(0); |
| 172 | + for(uint8_t i = 0; bit_array[i] != 2; i++) play_bit_rfid(bit_array[i] & 1); |
| 173 | + for(uint8_t i = 0; i < ZERO_SUFFIX; i++) play_bit_rfid(0); |
| 174 | + FURI_CRITICAL_EXIT(); |
| 175 | + |
| 176 | + rfid_tx_reset(); |
| 177 | +} |
| 178 | + |
| 179 | +void mag_spoof_two_track_rfid(FuriString* track1, FuriString* track2) { |
| 180 | + // Quick testing... |
| 181 | + |
| 182 | + rfid_tx_init(); |
| 183 | + |
| 184 | + const char* data1 = furi_string_get_cstr(track1); |
| 185 | + uint8_t bit_array1[(strlen(data1) * bitlen[0]) + 1]; |
| 186 | + const char* data2 = furi_string_get_cstr(track2); |
| 187 | + uint8_t bit_array2[(strlen(data2) * bitlen[1]) + 1]; |
| 188 | + |
| 189 | + track_to_bits(bit_array1, data1, 0); |
| 190 | + track_to_bits(bit_array2, data2, 1); |
| 191 | + |
| 192 | + FURI_CRITICAL_ENTER(); |
| 193 | + for(uint8_t i = 0; i < ZERO_PREFIX; i++) play_bit_rfid(0); |
| 194 | + for(uint8_t i = 0; bit_array1[i] != 2; i++) play_bit_rfid(bit_array1[i] & 1); |
| 195 | + for(uint8_t i = 0; i < ZERO_BETWEEN; i++) play_bit_rfid(0); |
| 196 | + for(uint8_t i = 0; bit_array2[i] != 2; i++) play_bit_rfid(bit_array2[i] & 1); |
| 197 | + for(uint8_t i = 0; i < ZERO_SUFFIX; i++) play_bit_rfid(0); |
| 198 | + FURI_CRITICAL_EXIT(); |
| 199 | + |
| 200 | + rfid_tx_reset(); |
| 201 | +} |
| 202 | + |
| 203 | +//// @antirez's code from protoview for bitmapping. May want to refactor to use this... |
| 204 | + |
| 205 | +/* Set the 'bitpos' bit to value 'val', in the specified bitmap |
| 206 | + * 'b' of len 'blen'. |
| 207 | + * Out of range bits will silently be discarded. */ |
| 208 | +void set_bit(uint8_t* b, uint32_t blen, uint32_t bitpos, bool val) { |
| 209 | + uint32_t byte = bitpos / 8; |
| 210 | + uint32_t bit = bitpos & 7; |
| 211 | + if(byte >= blen) return; |
| 212 | + if(val) |
| 213 | + b[byte] |= 1 << bit; |
| 214 | + else |
| 215 | + b[byte] &= ~(1 << bit); |
| 216 | +} |
| 217 | + |
| 218 | +/* Get the bit 'bitpos' of the bitmap 'b' of 'blen' bytes. |
| 219 | + * Out of range bits return false (not bit set). */ |
| 220 | +bool get_bit(uint8_t* b, uint32_t blen, uint32_t bitpos) { |
| 221 | + uint32_t byte = bitpos / 8; |
| 222 | + uint32_t bit = bitpos & 7; |
| 223 | + if(byte >= blen) return 0; |
| 224 | + return (b[byte] & (1 << bit)) != 0; |
| 225 | +} |
| 226 | + |
| 227 | +/*uint32_t convert_signal_to_bits(uint8_t *b, uint32_t blen, RawSamplesBuffer *s, uint32_t idx, uint32_t count, uint32_t rate) { |
| 228 | + if (rate == 0) return 0; // We can't perform the conversion. |
| 229 | + uint32_t bitpos = 0; |
| 230 | + for (uint32_t j = 0; j < count; j++) { |
| 231 | + uint32_t dur; |
| 232 | + bool level; |
| 233 | + raw_samples_get(s, j+idx, &level, &dur); |
| 234 | +
|
| 235 | + uint32_t numbits = dur / rate; // full bits that surely fit. |
| 236 | + uint32_t rest = dur % rate; // How much we are left with. |
| 237 | + if (rest > rate/2) numbits++; // There is another one. |
| 238 | + while(numbits--) set_bit(b,blen,bitpos++,s[j].level); |
| 239 | + } |
| 240 | + return bitpos; |
| 241 | +}*/ |
0 commit comments