# rawcli — catalog & memory-hinting roadmap The MVP is a list of **named transponders**, each surfaced through the **same UX**: a command catalog + a datasheet memory map, both offered as **autocomplete suggestions in the completion dropdown** — never on the bottom bar, never in command output. ## The UX contract (applies to every transponder) - Completion dropdown offers: command names (by letter → `READ(`), opcodes (by hex/binary value → raw byte inserted, command as the label), and page/block landmarks with datasheet roles. - **Must work in both hex AND binary entry modes**, rendering in the active base. - Function-call args are base-10 (`READ(4)`); raw bytes are hex, `0b` to intermix binary. ## FIXED — raw byte-line autocomplete now fires in hex AND binary Root cause: `entry._digit` applied each keystroke as `buf.document = Document(...)`, which resets prompt_toolkit's `complete_state` and never re-fires completion — so the live menu never appeared during raw byte entry. This hit **both** hex and binary (the earlier "hex works, binary doesn't" was inaccurate; only command-name completion worked, because that path already used `insert_text`). Fixed by appending the per-keystroke delta via `buf.insert_text` instead — `type_digit` only ever appends (optionally after an auto-space) or drops, so the change is always a pure suffix, and `insert_text` triggers completion exactly like an ordinary keystroke. Verified by driving the real key handler: the menu now populates on every digit in both modes. Regression: `TestKeyBindings::test_digit_binding_fires_completion_trigger_for_raw_bytes`. Still worth a quick live-REPL eyeball with a tag on the antenna, and confirming the Ctrl-t / Ctrl-_ toggle flips the breadcrumb to `0b` (separate from the completion trigger, not yet re-verified). ## Priority 1 — MIFARE Classic (do this first) - **Identify**: distinguish 1K (SAK 0x08) / 4K (0x18) / Mini (0x09); today only named, no map. - **Memory map** (block → role), mirroring the NTAG page map: - Block 0 = manufacturer block: UID + BCC + SAK + ATQA + manufacturer data. - Sector trailer (block 3,7,…,63 on 1K; last block of each sector on 4K): **Key A (0-5), access bits (6-8) + GPB (9), Key B (10-15)** — the access bits are the bit-level detail. - Other blocks = data block (with sector number). - 4K: sectors 0-31 are 4 blocks; sectors 32-39 are 16 blocks each. - **Catalog**: READ/WRITE/HALT exist; note that reads/writes need prior AUTH (Key A/B) — the authenticate step is the reader's job before these. - Autocomplete must work in hex + binary (see the bug above). ## After MFC — 15693 vicinity chips: ICODE SLIX, ICODE SLIX2, NTAG5 1. **15693 header builder** (shared foundation). Replace the ad-hoc `bytes([0x02, cmd, …])` with a real request-header builder: flags (data rate, addressed-vs-nonaddressed + 8-byte UID, option, protocol-extension) + command + NXP **manufacturer code 0x04** for ICODE/NTAG5 custom commands. 2. **Per-chip identify.** Today identify stamps `"ISO15693"` generically; resolve the actual IC (UID mfg byte `E0 04…` + GET_SYSTEM_INFO / IC-reference) so catalog + map key off SLIX2 / NTAG5. 3. **Catalogs + memory maps** per chip (blocks, config, counters, EAS/AFI, password/AES) — sourced from the models in `transponders/hf/iso15693/nxp/` (`icode_slix`, `icode_slix2`, `ntag5_*`). 4. Same autocomplete UX (hex + binary). ## Also queued - **T5577 config block (block 0)** bitfield decode (modulation, bit-rate, block count, PWD/AOR) — currently just "config block". - NTAG I2C plus (model exists, identify names it) — catalog + map. See [[project_rawcli_mvp]] in memory for the named-transponder scope.