Files
KAT/docs
KaraZajac 754af4134a
Deploy to Pages / build (push) Waiting to run
Deploy to Pages / deploy (push) Blocked by required conditions
v1.3.0: Add 14 keyfob protocols (8 ProtoPirate + 6 Flipper-ARF), fix KeeLoq overflow
Brings KAT to 32 protocol decoders. Ported from the ProtoPirate reference and the
D4C1-Labs/Flipper-ARF firmware:

  ProtoPirate (8): Kia V7, Ford V1, Ford V2, Ford V3, Chrysler V0, Honda Static,
  Honda V1, Land Rover V0.
  Flipper-ARF (6): Toyota, Land Rover RKE, Mazda Siemens, BMW CAS4,
  Porsche Cayenne, PSA2.

Each decoder is gated (CRC / checksum / fixed markers / frame structure) so it
cannot false-match existing protocols; every previously-decoding IMPORTS capture
decodes unchanged. Real-capture decodes added for Ford V3 (LDV T80), Honda Static
(Honda), Toyota (Camry NRZ variant), and PSA2 (Groupe PSA, serial 0x99EB25); the
rest are validated by encode/decode round-trip and synthetic-frame tests.

Also fixes a debug-only underflow panic in keeloq_common::keeloq_decrypt
(15 - r underflowed; now wrapping_sub to match the reference's unsigned wrap;
release behavior unchanged).

Adds per-protocol docs, updates the README protocol table, capture metadata
(encoding / RF / encryption), make-suggestion mapping, and CHANGELOG.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JEfaKqzB3T4qsrybwfEi73
2026-06-23 20:08:54 -04:00
..

KAT Protocol Documentation

This folder describes how each keyfob protocol supported by KAT works. Each document corresponds to a decoder/encoder in src/protocols/.

Capture/encode model: Decoded signals expose optional extra (e.g. VAG: vag_type + key_idx). When present, the app stores it in Capture.data_extra so retransmit can encode from the capture without decoder instance state. See vag.md for the VAG encode-from-capture flow.

Protocol Rust module Doc
Kia V0 kia_v0.rs kia_v0.md
Kia V1 kia_v1.rs kia_v1.md
Kia V2 kia_v2.rs kia_v2.md
Kia V3/V4 kia_v3_v4.rs kia_v3_v4.md
Kia V5 kia_v5.rs kia_v5.md
Kia V6 kia_v6.rs kia_v6.md
Kia V7 kia_v7.rs kia_v7.md
Ford V0 ford_v0.rs ford_v0.md
Ford V1 ford_v1.rs ford_v1.md
Ford V2 ford_v2.rs ford_v2.md
Ford V3 ford_v3.rs ford_v3.md
Honda Static honda_static.rs honda_static.md
Honda V1 honda_v1.rs honda_v1.md
Chrysler V0 chrysler_v0.rs chrysler_v0.md
Subaru subaru.rs subaru.md
Toyota toyota.rs toyota.md
VAG vag.rs vag.md
Fiat V0 fiat_v0.rs fiat_v0.md
Fiat V1 fiat_v1.rs fiat_v1.md
Mazda V0 mazda_v0.rs mazda_v0.md
Mazda Siemens mazda_siemens.rs mazda_siemens.md
Mitsubishi V0 mitsubishi_v0.rs mitsubishi_v0.md
Land Rover V0 land_rover_v0.rs land_rover_v0.md
Land Rover RKE land_rover_rke.rs land_rover_rke.md
BMW CAS4 bmw_cas4.rs bmw_cas4.md
Porsche Touareg porsche_touareg.rs porsche_touareg.md
Porsche Cayenne porsche_cayenne.rs porsche_cayenne.md
Suzuki suzuki.rs suzuki.md
Scher-Khan scher_khan.rs scher_khan.md
Star Line star_line.rs star_line.md
PSA psa.rs psa.md
PSA2 (PSA OLD) psa2.rs psa2.md
KeeLoq generic (fallback) keeloq_generic.rs keeloq_generic.md

KeeLoq generic is not a registered decoder; it runs when no protocol matches and tries KeeLoq with every keystore manufacturer key (using keeloq_common). Successful decodes appear as Keeloq (keystore name).

Implementations are aligned with the ProtoPirate reference in REFERENCES/ProtoPirate/protocols/.