Commit graph

7 commits

Author SHA1 Message Date
5df4ce7e73 docs: record the Omnikey 5022 field test
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 22:15:32 +02:00
b655392893 fix: name SCARD_W_SECURITY_VIOLATION and point at the polkit rule
Seen on the first Arch field test: pcscd up, but polkit denied the
user, and the CLI only printed the raw 0x8010006A.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 22:05:01 +02:00
af736e09a9 feat: launcher script for running from a checkout without uv
Only click and cryptography are needed, both packaged by Arch, so a
plain ./boltcard-writer works when uv cannot be installed (Omarchy's
pinned mirror 404'd on the uv package during the first field test).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 21:58:54 +02:00
959b6ea17d feat: nix flake with package, NixOS module and dev shell
nix run / nix build produce a wrapped CLI that pins libpcsclite by store
path, the package build runs the test suite (so nix flake check is CI),
programs.boltcard-writer.enable installs it and turns on pcscd, and
nix develop / nix-shell give the uv workflow used on Arch.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 21:53:07 +02:00
6d4dbc31cd docs: README with Arch/Omarchy setup and troubleshooting
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 21:41:24 +02:00
f37026793b test: AN12196 vectors and a software NTAG 424 simulator
The vector tests replay the application note's worked examples
(auth key 0/3, IV, ChangeKey 0/2, WriteData) byte-for-byte. The
simulator implements the card side of secure messaging so the
provision and wipe flows run end to end without hardware.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 21:41:24 +02:00
7d35d3e2c7 feat: Bolt Card writer CLI for PC/SC NFC readers
Provision, inspect and wipe NTAG 424 DNA Bolt Cards from a Linux PC
using an LNbits /boltcards/api/v1/auth link, replacing the phone app
for desks with a USB reader (ACR1252U).

- pcsc.py: ctypes client for libpcsclite (no compiled deps)
- ntag424.py: EV2 secure messaging (AuthenticateEV2First, ChangeKey,
  ChangeFileSettings, GetCardUID, WriteData) per NT4H2421Gx / AN12196
- boltcard.py: the same write/wipe sequence as bolt-card-programmer
  (NDEF URL, SDM 40 00E0 C1 FF12, keys 1-4 then 0, key version 1)
  plus local p/c verification identical to the extension's nxp424.py
- cli.py: readers / read / write / wipe, keys backed up before any
  card mutation, uid cross-check on wipe

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 21:41:24 +02:00