Skip to content

Derive the GET SERIAL response from the device UUID - #47

Open
FlorianFranzen wants to merge 1 commit into
trussed-dev:mainfrom
FlorianFranzen:feat/uuid-serial
Open

FlorianFranzen wants to merge 1 commit into
trussed-dev:mainfrom
FlorianFranzen:feat/uuid-serial

Conversation

@FlorianFranzen

@FlorianFranzen FlorianFranzen commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Every device answered the Yubico GET SERIAL extension with the same made-up constant 00 52 F7 43. That breaks clients that select a card by serial or handle several cards at once: yubikey.rs keys its card handle on the serial, and ykman lists devices by it.

Use the first four bytes of the per-device UUID that the runner already passes in through Options for the CHUID. A simple truncation rather than a hash: the serial only needs to be stable and distinct between devices, the UUID's leading bytes already are, and the mapping stays recognizable when debugging. Platforms that do not provide a UUID keep the previous constant, so existing setups (and the aa_serial test configuration) see no change.

Tested in command_response.ron for both the UUID-derived serial and the constant fallback.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant