Hardware-validated. Two real bugs in the T55xx config decode, both fixed by requiring a
bit-rotation of the recovered repeating word to match a known preset:
- Rotation ambiguity: a block read recovers the 32-bit config at an arbitrary bit offset.
A real capture came back 0x000A4020 = the EM4100 word 0x00148040 rotated by one; the old
"looks sane" scorer accepted the rotation verbatim and mislabeled it FSK1/RF-6. Now every
rotation is tried and only a preset match (EM4100/HID/Indala/FDX-B/Viking/default) is
accepted -> resolves to 0x00148040 = EM4100.
- False positives: garbage config captures (all-0, all-1, a rotation of the tag's own
emission) no longer pass -> decode returns None and the reliable emitted-stream decode
carries the result.
identify_lf label now names the chip + the actual decoded credential:
"T5577 (EM4100 00FFFFFFFF)" instead of the config's guess. On real hardware this is now
stable 4/4: config 00148040, emitted EM4100 00FFFFFFFF.
Tests: rotation recovery (0x000A4020 -> EM4100), no-false-positive on all-1s/random,
updated label expectation.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>