Repository navigation
Derive the GET SERIAL response from the device UUID - #47
Open
FlorianFranzen wants to merge 1 commit into
Open
FlorianFranzen wants to merge 1 commit into
FlorianFranzen wants to merge 1 commit into
Conversation
FlorianFranzen
force-pushed
the
feat/uuid-serial
branch
from
October 8, 2026 18:46
73ed4b2 to
bb11de1
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every device answered the Yubico GET SERIAL extension with the same made-up constant
00 52 F7 43. That breaks clients that select a card by serial or handle several cards at once: yubikey.rs keys its card handle on the serial, and ykman lists devices by it.Use the first four bytes of the per-device UUID that the runner already passes in through
Optionsfor the CHUID. A simple truncation rather than a hash: the serial only needs to be stable and distinct between devices, the UUID's leading bytes already are, and the mapping stays recognizable when debugging. Platforms that do not provide a UUID keep the previous constant, so existing setups (and theaa_serialtest configuration) see no change.Tested in
command_response.ronfor both the UUID-derived serial and the constant fallback.