fail rather than loop indefinitely on an unsuccessful card wait or repeated secure channel resets

This commit is contained in:
Craig Raw
2026-08-21 13:03:57 +02:00
parent e49b6a4a63
commit 3e53f19353
3 changed files with 13 additions and 3 deletions
+1 -1
Submodule lark updated: f2b6b66247...450758a05e
@@ -83,9 +83,11 @@ public class CkCardApi extends CardApi {
delayProperty.set(delay);
messageProperty.set("Auth delay, waiting " + delay + "s...");
CardWait cardWait = cardProtocol.authWait();
if(cardWait.success) {
delay = cardWait.auth_delay == null ? 0 : cardWait.auth_delay.intValue();
if(!cardWait.success) {
throw new CardException("Card did not accept the request to wait out the authentication delay.");
}
delay = cardWait.auth_delay == null ? 0 : cardWait.auth_delay.intValue();
}
}
}
@@ -27,6 +27,8 @@ public class SatochipCommandSet {
private static final Logger log = LoggerFactory.getLogger(SatochipCommandSet.class);
private static final int MAX_SECURE_CHANNEL_RESETS = 3;
private final SatoCardTransport cardTransport;
private final SecureChannelSession secureChannel;
private SatoCardStatus status;
@@ -66,6 +68,7 @@ public class SatochipCommandSet {
public APDUResponse cardTransmit(APDUCommand plainApdu) {
// we try to transmit the APDU until we receive the answer or we receive an unrecoverable error
boolean isApduTransmitted = false;
int secureChannelResets = 0;
do {
try {
byte[] apduBytes = plainApdu.serialize();
@@ -114,6 +117,11 @@ public class SatochipCommandSet {
// SecureChannel is not initialized
else if(sw12 == 0x9C21) {
log.error("Error, Satochip secure channel required");
if(++secureChannelResets > MAX_SECURE_CHANNEL_RESETS) {
// the card keeps asking for a secure channel it will not accept, so stop rather than retry indefinitely
log.error("Error, Satochip secure channel could not be established");
return new APDUResponse(new byte[0], (byte)0x00, (byte)0x00);
}
secureChannel.resetSecureChannel();
} else {
// cannot resolve issue at this point