Releases: keyuraghao/chipwhisperer-studio
Release list
ChipWhisperer Studio v0.5.2
Added
- Real-hardware test session.
tests/hardwareruns the whole flow (connect, build and flash firmware, talk to the target, capture, CPA, glitch, the logic analyser and the other interfaces, notebooks and the MCP server) against a real ChipWhisperer through the HTTP API, and against the simulator withCWSTUDIO_HW=sim.CWSTUDIO_HW_TARGETselects the SimpleSerial version, with the firmwaress_verand the codemap emulator protocol following it. Verified end to end on a Husky with a CW308 SAM4S target (full AES-128 key recovered, reliable voltage glitch); see tests/hardware/README.md, with per-stage results written totests/hardware/last_run.json.
Fixed
- Logic analyser
capturetrigger.la_capturewithtrigger="capture"now arms the ADC even when the analog trace is not kept, so the capture trigger reaches the analyser instead of waiting out its timeout with an empty FIFO. - SAD trigger threshold. The threshold is capped at the hardware maximum (
2**(counter_width-1), 64 on the Husky) and an out-of-range value is rejected up front with a clear message instead of failing deep in the SAD setter; the Pro keeps its 100000 limit and the simulator its wider range. - Note creation.
POST /api/noteswrites an optionaltextbody in one call instead of always creating an empty note. - Job progress fields. Capture and glitch jobs report a consistent
done/totalpair (alongside the existingtargetandpoint/points), matching firmware builds, so a client can show progress without special-casing the job type.
ChipWhisperer Studio v0.5.1
Studio is now on PyPI: pip install chipwhisperer-studio. No changes to the application itself.
Added
- PyPI package. Every release is now also published to PyPI by CI. The package description is the README with its screenshots, clips and links pointing at the release tag (
tools/pypi_readme.py), and the package lists keywords, classifiers for the supported systems and Python versions, and links to the documentation, issues, changelog and video tour.
Changed
- The README and the Installation wiki page install with
pip install chipwhisperer-studioand update withpip install --upgrade chipwhisperer-studio(the Installation page still pointed at the 0.4.5 wheel).
ChipWhisperer Studio v0.5.0
This release adds five large features: Studio's own application window, several notebooks at once, an Interfaces tab for everything that talks to the target, a logic analyser for every ChipWhisperer, and firmware code mapped onto the waveform. The MCP server grows from 68 to 106 tools to cover them.
Added
- Studio's own application window. Studio now opens in a window of its own instead of a browser tab, using the operating system's web engine: Microsoft Edge WebView2 on Windows and WebKit on macOS (through pywebview, now a dependency on those systems), and WebKitGTK on Linux through a small helper run by the system Python, so the bundle does not ship GTK (
sudo apt install python3-gi gir1.2-webkit2-4.1,dnf install python3-gobject webkit2gtk4.1orpacman -S python-gobject webkit2gtk-4.1if it is missing). Downloads, file pickers and links to other sites work, settings persist between runs, closing the window quits Studio and stopping Studio closes the window. If the window cannot open, Studio says why and uses the browser; over SSH it prints the address instead of starting a text browser.--browseropens the browser,--app-windowforces the window,--no-browserruns only the server;CWSTUDIO_DEFAULT_UIsets the default,CWSTUDIO_GTK_PYTHONpicks the Python for the Linux window andCWSTUDIO_DEVTOOLS=1enables its web inspector. The newcw-studio-webcommand opens the browser by default.- Two builds per OS: ChipWhisperer Studio (
ChipWhispererStudio-<os>-<arch>.zip, own window) and ChipWhisperer Studio Web (ChipWhispererStudio-Web-<os>-<arch>.zip, browser), about 72 MB each. On macOS each is a real.app(ChipWhisperer Studio.app,ChipWhisperer Studio Web.app); on Windows the window build'sChipWhispererStudio.exehas no console window andcw-studio.exenext to it is the console version for scripts and AI agents.
- Several notebooks at once. Notebooks open as tabs, and two can be shown side by side (drag a tab to the right half or press the split button; drag the divider to resize). Every notebook has its own kernel, so variables, execution counts, Stop and Restart are per notebook, while all kernels share Studio's hardware connection and run their cells one at a time on the hardware thread. A kernel is shut down shortly after its notebook is closed in every window. Notebooks open in several windows, or rewritten by the API or an agent, stay in sync: a tab without edits reloads, a tab with unsaved edits shows a conflict notice instead of being overwritten.
- API:
GET /api/kernels,POST /api/kernels/shutdown,/api/kernels/rename,/api/kernels/attach,POST /api/notebooks/rename, and akernelparameter on the kernel routes; saves takebase_mtimeand are refused with 409 or 410 when the file changed or was deleted. MCP:kernel_listandkernel_shutdown, andnotebook_pathon the kernel tools. %config InlineBackend.figure_format = 'svg'shows figures as SVG;%cdlasts until the kernel restarts.
- API:
- Interfaces tab with everything that talks to the target, gated by the connected model: the target UART (baud, parity, stop bits and pins) with a terminal (text or hex, line endings, history, timestamps), SimpleSerial 1.0, 1.1, 2.1 and v2 over the scope's USB-CDC port, an SPI master with SPI flash shortcuts, GPIO on the target pins with read-back and a reset pulse, the Husky's USERIO header, triggers (edge and level on any pin combination, the Pro's UART I/O decode trigger, the Husky's UART pattern rules, edge counter, ADC level and trigger sequencer, SAD), the Husky bit-banger and 1-Wire, and JTAG/SWD through OpenOCD: switch the scope into MPSSE mode, start an OpenOCD server for a target configuration, run commands, flash and connect GDB. OpenOCD (xPack 0.12.0) installs on demand like the compilers.
- A new capabilities module knows what every model supports, from the
chipwhispererlibrary's source: the Interfaces tab, the Target tab's programmers and the Scope tab's choices offer only that, and everything else shows the reason (for example the CW-Nano has no SPI pins). The capability matrix is on the new Protocols and Interfaces wiki page. - Simulate as: the simulator can pose as a Husky (default), Husky Plus, Pro, Lite or Nano, with exactly that model's interfaces, triggers, programmers and settings, a simulated W25Q128 SPI flash, pins, bit-banger and 1-Wire device.
- iCE40 and XC7A35T FPGA bitstreams can be programmed from the Target tab.
- API:
GET /api/capabilitiesand/api/interfaces/*. MCP: 20 tools,hardware_capabilities,interfaces_status,uart_configure,simpleserial_connect,spi_*,gpio_*,userio_set,trigger_configure,bitbang,onewireandopenocd_*.
- A new capabilities module knows what every model supports, from the
- Logic tab, a logic analyser for every ChipWhisperer. Sources: the Husky's built-in logic analyser (9 signals from the 20-pin header, the USERIO header or the glitch internals, up to 16,376 or 65,535 samples), one digital line through the analog input of any scope, external analysers through sigrok-cli, VCD, CSV (Saleae Logic 1 and 2, sigrok, generic) and sigrok
.srfiles, and simulated traffic. Decoders for UART (with automatic baud rate), SPI, I2C, 1-Wire (with overdrive), JTAG, SWD, CAN (CAN FD frames are marked, not misdecoded) and SimpleSerial, plus sigrok's decoders when sigrok-cli is installed, with a glitch filter. The viewer has zoom and pan, cursors with edge snapping, measurements (frequency, period, duty cycle, pulse widths), buses, edge, pattern and decoded-value search, a results table with CSV export, repeat capture that keeps your channel setup, the last eight captures in memory, exports to VCD, CSV and.sr, and analog rows (the ADC input, or a stored power trace on the logic time base). It stays fast at 10 million samples, and big captures decode in a worker process. API:/api/la/*. MCP: 10la_*tools. - Code on the waveform (Code tab). Studio emulates the firmware's ELF for the key and plaintext of a captured trace (Unicorn for Arm Cortex-M and RISC-V RV32, Studio's own cycle-accurate emulator for AVR and XMEGA), counts clock cycles per core, maps them to samples from the scope's clocks and aligns the result with the stored traces by correlation, with a confidence score. A code band under the waveform shows the functions (as a flame chart, inlined functions included) and source lines; Ctrl, Cmd or Alt+drag picks a region and the Code tab lists its functions and source lines with highlighted source and disassembly; clicking a function or line shades every sample where it ran. Peripherals, interrupts and UART timing are not emulated; the HAL's
getch,putchand trigger functions are hooked instead. On a Husky with an Arm target, exact mode records program counter samples over SWO and compares them with the emulation. API:/api/codemap/*. MCP: 6code_map_*tools. - The simulator evaluates the special triggers on what its target really does (its serial traffic on TIO1 and TIO2 and its trigger pin, timed like on the wire): the Husky's UART pattern rules, the Pro's UART decode trigger, the edge counter, the ADC level, SAD and the trigger sequencer start the capture where they would fire on hardware, and a trigger that never fires times out with a log message saying why. Only the Arm trace and bit-banger triggers fall back to the TIO4 edge, with a warning.
- A scope left in MPSSE mode is found and restored: after a restart (or replug), Studio recognises a ChipWhisperer still in JTAG/SWD mode by its USB configuration, shows it in the Interfaces tab and restores it with Restore normal mode (
openocd_mpsse(enable=false)). - Updating the tutorials keeps your work: Download tutorials keeps files you edited or added, and asks before replacing an edited file that also changed upstream (Update, back up mine keeps yours as
<name>.local-YYYYMMDD-HHMMSS.ipynb, Keep mine, Cancel). API and MCP:on_modifiedand the job stateconfirm. - The Help tab's MCP setup shows the right command for the installation (
cw-studio.exein the Windows window build), also asmcp_commandinGET /api/meta. - The simulator runs your firmware. Programming an ELF (or a
.hexStudio built, which keeps its.elf) into the simulator runs it in the emulator: responses and traces come from your code, CPA recovers the key from them, and a glitch skips the instructions where it lands or crashes the core. eol(none, lf, cr, crlf) forPOST /api/target/serial/writeand the MCP toolserial_write;sim_modelfor scope connections.- New wiki pages: Protocols and Interfaces, Logic Analyser and Code on the Waveform. New screenshots, video chapters and clips show the new features.
Changed
cw-studioopens Studio's window instead of the browser. Usecw-studio-web,--browseror the Web build for the old behaviour.--windowstill works as an alias of--app-window; thewindowextra is no longer needed.- The simulator poses as a ChipWhisperer-Husky by default (it used to behave like a CW-Lite), and its target drives only TIO4, like ChipWhisperer firmware: a trigger on another pin now times out as on hardware, and the special triggers are evaluated (see Added). Its ADC clock follows
clock.adc_src(CW-Lite and Pro models) orclock.adc_mul(Husky models), and the traces stretch or squeeze with it. - The Target tab's serial console is the same terminal as in the Interfaces tab: line endings, history and timestamps; UART settings live in the Interfaces tab.
- The Capture tab shows the trigger the scope is set to, wherever it was changed.
- Choices the ...
ChipWhisperer Studio v0.4.5
Added
- Application icon on every platform, drawn from Studio's logo (
tools/make_icon.py):- Windows: the executable has the Studio icon instead of PyInstaller's default, plus version information, so Explorer, the taskbar and Task Manager show "ChipWhisperer Studio" and its version.
- macOS: the bundle includes
ChipWhisperer Studio.app, which shows the icon in Finder and the Dock and opens Studio in Terminal (a plain executable cannot have an icon on macOS). - Linux:
cw-studio --install-desktop(or./ChipWhispererStudio --install-desktopin the bundle) adds Studio with its icon to the applications menu;--remove-desktoptakes it out. The bundle also includes the icon asChipWhispererStudio.png.
- The logo is shown at the top of the README and the wiki.
Changed
- The documentation was reviewed against the code for production: wrong sizes, flags, labels and links fixed, references to pages that do not exist and to replaced libraries removed, and the architecture diagram updated (
web.py,mcplite.py, the simulator). - All screenshots, the video tour and its clips were regenerated for this version from a neutral data folder. The settings-tree screenshots and the tour now show their groups expanded (the scripts used to click open groups closed).
- The programmer list names the CW-Nano under STM32F and the CW304 under AVR (it wrongly listed a "Nano ATmega").
ChipWhisperer Studio v0.4.4
Stress tests with very large trace sets, large files, long sessions, many windows and leak checks (tools/benchmark.py, results on the new Performance wiki page and in the README) found the problems below. No memory leaks were found in any workload.
Changed
- Mean, standard deviation and min/max of all traces (the waveform's mean and envelope,
/api/traces/stats, the MCPtraces_statstool) come from running sums that only take in the traces added since the last request. With 50,000 stored traces a request under load takes about 6 ms instead of 6.3 s, and with 200,000 traces the extra memory drops from 7.6 GB to about 60 MB. The values are also more accurate (float64 sums: within 4e-9 of exact, against 3e-6 before). - Exporting to .npz is about 10 times faster (54 instead of 6 MB/s on realistic ADC data; 1.9 GB now takes 35 s instead of almost 6 minutes). Files are about 13 percent larger and load exactly as before.
- Clearing traces gives the memory back to the operating system on Linux, so Studio's memory drops back to where it was (61 instead of 157 MB after 30 capture and clear cycles).
- Studio keeps only log, capture and glitch events for
/api/logs; it used to also keep the last 2000 notebook outputs (with their figures), CPA results and other events, which could hold hundreds of MB in figure-heavy sessions.
ChipWhisperer Studio v0.4.3
Added
- Video tour: a walkthrough of every feature in under three minutes (
chipwhisperer-studio-demo.mp4, attached to this release), with a chapter list on the new Video Tour wiki page.tools/demo_video.pyrecords it from the real UI with captions, so it can be regenerated after UI changes. - Screenshots in both themes: every screenshot in the README and the wiki now exists in the dark and the light theme, and GitHub shows the one matching your theme. New screenshots show the zoom buttons and the glitch sweep, and an animated GIF shows zooming.
tools/theme_images.pykeeps the docs in sync, and CI checks it.
Fixed
- With time axis on, the waveform's time labels no longer run into each other when the whole trace is shown.
- The README's pip instructions install the wheel from the release (Studio is not on PyPI yet), and the README images that referred to old screenshots use the current ones.
ChipWhisperer Studio v0.4.2
Added
- Zoom buttons in the waveform view: zoom in and zoom out (magnifier buttons next to Fit, or the + and - keys) halve or double the visible range of samples, centred on cursor A when it is in view and otherwise on the middle of the view. The zoom stops at the ends of the trace and at about 10 samples, keeps across live traces, and zooming out past the whole trace fits it.
ChipWhisperer Studio v0.4.1
A full review of 0.4.0 against 0.3.0 (every HTTP route, all 68 MCP tools on three transports, every tab in the browser, the numerics and the published packages) found the issues below. They are fixed here, together with several older bugs it uncovered.
Fixed
- macOS bundle without libusb: the 0.3.0 and 0.4.0 macOS bundles did not contain libusb, so they could only reach real hardware when Homebrew's libusb was installed. The bundle build now includes it on every OS and fails if it cannot.
- MCP arguments:
nullfor a parameter that is not optional is rejected again, as in 0.3.0. In 0.4.0capture_start(count=null)reported an error but left an endless capture running, andscope_connect(kind=null)disconnected the scope. List items are validated and converted again (bytes=["0"]), and numbers, booleans and strings convert as leniently as before. - MCP results: structured results are wrapped as
{"result": ...}with an output schema again, exactly as 0.3.0 sent them, and lists come as one text block per item. NaN and infinity are sent asnullinstead of invalid JSON. - MCP concurrency: every request runs on its own thread, so
ping,capture_stopand status calls answer at once even while many long calls wait (0.4.0 had a pool of 8). - MCP over HTTP: the streamable HTTP transport checks the Host header (DNS rebinding), Accept, Content-Type, session ids and the protocol version header again,
DELETEends a session, and request bodies are bounded. A lone surrogate character in a request no longer stops the stdio server, and on Windows child processes can no longer write into the protocol stream. - Uploads: a request without a file is rejected with 422 as in 0.3.0 (0.4.0 programmed an empty firmware file), filenames containing
;or escaped quotes are kept intact, file content that happens to contain the boundary text is no longer cut short, and multipart uploads need about half the memory. - API errors: invalid or missing parameters return FastAPI's 422 format again (
{"detail": [{"type", "loc", "msg", "input"}]}), whole numbers like3.0are accepted for integer parameters,HEADrequests are refused as before instead of running an export, and/openapi.jsonis back (a compact description of every route). Values that JSON cannot represent (infinity, NaN, numpy keys, dates, enums) no longer cause a 500 (/api/calcwith1e308*10, trace meta of a trace containing NaN). - CPA results are bit-identical to 0.3.0 again: 0.4.0 rearranged the correlation formula, which changed the last bit of some values and, with ties, the reported sample. The formula is restored inside the faster blocked computation.
- Live view: the WebSocket loop sends queued events without per-event task overhead (0.4.0 was slower than 0.3.0 when events backed up) and cleans up its pending read when a window closes.
- Header Stop button: a capture or glitch sweep started from the panel, a notebook, a script or an agent now shows in the header right away with live progress, and the header Stop button works during it. Before, the header said Idle and Stop stayed disabled until the job ended.
plt.show()in the first cell that imports pyplot now shows the figure at that point too, without a warning (Studio has its own matplotlib backend for notebooks). Figures can also be saved as SVG, PDF and PS in the bundles, and common standard modules (zoneinfo,tomllib,sqlite3and others) import there again.- ChipWhisperer project download: Download in browser for
.cwpnow gives a zip with the project and its data folder (it was a 264 byte file that could not be opened), and importing such a zip works. - Notebook import never overwrites an earlier import with the same name,
notebook_readover MCP works, relative paths for trace import resolve inside the data folder like export,python -m cwstudio mcp --no-embedexits with status 1 when Studio is not running, and reset FPGA on a scope without an FPGA says so. - Markdown: tabs in code blocks are kept, SVG images given as data URLs show again, and inline styles can no longer pin content over the whole window.
- Packaging: README images that went missing with the wiki move are back, the Python badge says 3.10 to 3.12, the sdist includes the test helpers, the package metadata uses the SPDX licence expression, and CI checks README links and the plain (MCP SDK free) install.
Performance
CPA with live progress (5000 traces of 5000 samples, progress every 50 traces) takes 13 to 15 s against 24 to 26 s in 0.3.0, about 1.8 times faster, with bit-identical results. The 0.4.0 table below listed 3.0 times from one run; independent runs of 0.4.0 measured 2.1 times.
ChipWhisperer Studio v0.4.0
This release makes Studio smaller and faster. Heavy libraries that Studio used only a small part of are replaced by compact built-in code, so a pip install pulls in about 25 fewer packages and the standalone bundles shrink by a third, while CPA, the simulator and live streaming get several times faster. The HTTP API, the MCP tools and the file formats are unchanged.
Added
-
Wiki: a full user and developer guide in
docs/wiki, published to the GitHub wiki by CI, with new screenshots of every tab and a diagram of how notebook cells share the hardware. -
Built-in MCP server (
mcplite.py): Studio now speaks the Model Context Protocol itself (stdio, streamable HTTP and SSE) instead of using the MCP SDK. The 68 tools, their schemas, the prompts and the resources are identical, and agents see no difference; it was checked against the official MCP client on all three transports. -
Built-in router (
web.py): the HTTP API runs on Starlette directly with a small routing layer instead of FastAPI, so pydantic is no longer needed./api/docsnow lists every endpoint with its parameters (the wiki's HTTP API page has the details). -
Uploads also accept the file as the raw request body with
?filename=NAME, besidesmultipart/form-data.
Changed
- Fewer dependencies:
fastapi,mcp,python-multipartand theuvicorn[standard]extras are gone, and with them pydantic, pydantic-core, jsonschema, rpds, httpx2, opentelemetry, pyjwt, cryptography, uvloop, httptools, watchfiles and PyYAML. Studio now needs Starlette, uvicorn, websockets, numpy, matplotlib and a few small packages. - Smaller bundles: the Linux bundle zip shrinks from 108 MB to 64 MB (macOS 80 MB to 61 MB, Windows 67 MB to 49 MB). Besides the dependencies above, the bundles leave out Cython, setuptools, matplotlib's GUI backends and sample data, and Pillow's AVIF, WebP and colour management codecs, and strip debug symbols on Linux.
- Smaller frontend: the notebook and notes Markdown renderer and HTML sanitizer are now one 14 KB module (
markdown.js) instead of marked and DOMPurify (76 KB). It renders NewAE's tutorial notebooks like before, leaves LaTeX math untouched, and keeps notebook output safe from scripts. - Faster CPA: about 3 times faster with live progress (5000 traces of 5000 samples: 27 s to 9 s) and 1.6 times faster without, with identical results; progress reports no longer allocate hundreds of MB.
- Faster capture and simulator: the simulator synthesises traces 3 times faster and AES runs 7 times faster, so simulated captures run about 2.7 times faster. The same seed still gives the same traces.
- Faster live view: each WebSocket event is encoded once for all open windows instead of once per window, the WebSocket loop sleeps until there is an event instead of waking every second, the trace store keeps running counters for its summary, and the waveform view reuses buffers instead of allocating them for every frame.
- The Connect tab now preselects SimpleSerial v2, which current ChipWhisperer firmware uses, instead of the legacy v1 protocol.
- In notebooks,
cw.plot()returns a plot object that combines with*and+like ChipWhisperer's holoviews version (cw.plot(a) * cw.plot(b),fig = cw.plot()), andplt.show()shows figures immediately. studio.build_firmware()defaults to SimpleSerial v2.1, like the Firmware tab.
Performance
Measured before and after on the same machine (about 15% noise); results are identical. On real hardware, captures are mostly limited by USB and the target, so the gains show mainly in CPA and the live view.
| Operation | Before | After | Speedup |
|---|---|---|---|
| Live update encoding (500 events, 8 open windows) | 30.6 ms | 3.8 ms | 8.1x |
| AES encryption (5000 blocks) | 650 ms | 93 ms | 7.0x |
| CPA, 5000 traces of 5000 samples, progress every 50 traces | 26.6 s | 8.8 s | 3.0x |
| Simulator trace generation (5000 traces) | 1340 ms | 441 ms | 3.0x |
| Simulated capture loop (1000 traces) | 460 ms | 168 ms | 2.7x |
| Trace export as arrays | 33 ms | 20 ms | 1.65x |
| CPA, progress every 1000 traces | 3.1 s | 1.9 s | 1.6x |
| Trace block fetch for the waveform view | 11.4 ms | 7.8 ms | 1.5x |
| Mean, min and max statistics | 81 ms | 64 ms | 1.3x |
| Trace store summary | 3.3 ms | about 0 | effectively instant |
Fixed
cw.trace(TraceWhisperer) failed with "No module named 'pkg_resources'" in the bundles and in new Python environments, because setuptools 81 removed that module. Studio now provides the small part of it that ChipWhisperer uses, and the bundles include ChipWhisperer's trace modules again.- SVG figures in notebooks show their text, tick labels and titles again (the old sanitizer removed the
<use>elements matplotlib draws text with). - Download in browser for the NumPy
.npyset now downloads one zip with all four files instead of failing. - The serial console shows traffic from before the page was opened.
- The build log prints the
make cleancommand before its output, andcleanreceives the same SimpleSerial version as the build, so the log no longer shows a misleading "SS_VER set to SS_VER_1_1".
ChipWhisperer Studio v0.3.0
Added
- Notebook tab: Jupyter-style notebooks that run inside Studio. Write Python cell by cell (Shift+Enter to run, Run all, Stop, Restart), with text (Markdown) cells, inline matplotlib figures, rich outputs and a variables panel. Notebooks are standard
.ipynbfiles: create them in Studio, import your own, export them back to Jupyter.- Cells share Studio's hardware connection: inside a notebook
cw.scope()andcw.target()return the devices connected in the Connect tab (or connect them), and traces captured withcw.capture_trace()or a manualscope.arm()/scope.capture()/scope.get_last_trace()loop appear live in the waveform view and the Capture tab, with their plaintext, ciphertext and key. - IPython features used by ChipWhisperer's tutorials work:
%run other.ipynb,!make ...and%%bash -swith Studio's downloaded compilers onPATHand{var}/$varexpansion,%cd,%env,%time,%%writefile,display(),IPython.display,tqdm.notebookprogress bars. - ChipWhisperer tutorials: one click downloads NewAE's chipwhisperer-jupyter notebooks (SCA101, Fault101 and more) at the version matching your firmware sources, with the firmware folder linked so their build cells work. NewAE's Lab 3_3 (DPA on firmware AES) runs unmodified: setup, firmware build, programming and a 2500 trace capture into the Capture tab.
- A
studiohelper in every notebook:studio.traces,studio.add_trace(),studio.show(),studio.build_firmware(),studio.program().
- Cells share Studio's hardware connection: inside a notebook
- Notes tab: a text pad with multiple notes, Markdown preview and autosave, plus buttons to insert the latest CPA key or selection statistics.
- Calc tab: a calculator for quick maths and side-channel work (bitwise XOR, hex and binary,
hw(),hd(), AESsbox(),mean(),std(), variables) and statistics (count, sum, mean, median, min, max, peak to peak, standard deviation, variance, RMS) of the current selection: selected text anywhere in Studio, the waveform between cursors or in the zoomed range, the whole trace, one sample across all stored traces, or typed numbers. - Live selection statistics: select numbers anywhere in Studio and the log bar shows count, sum, mean, min and max instantly, like a spreadsheet status bar.
- MCP tools for the new features (68 tools in total):
notebook_run_code,notebook_run,notebook_read,notebook_write,notebook_list,kernel_variables,kernel_interrupt,kernel_restart,tutorials_fetch,note_read,note_write,notes_list,calculate,selection_stats.
Fixed
- HTTPS downloads failed with "certificate verify failed: unable to get local issuer certificate" when Python could not find CA certificates, which affected Refresh list, toolchain installs, firmware source downloads and update checks. This happens in the standalone bundles, with python.org Python on macOS and Windows, and on networks that inspect HTTPS. Studio now verifies certificates against the operating system's trust store (through
truststore, including roots your IT department installed), falls back to Mozilla's CA bundle (certifi), and honoursSSL_CERT_FILEandSSL_CERT_DIR. If verification still fails, the error explains how to fix it. - Installing a toolchain that is already installed no longer downloads it again.
- Firmware source lookups use
GITHUB_TOKENwhen it is set, avoiding GitHub's limit of 60 anonymous API requests per hour.
Changed
- matplotlib and tqdm are now dependencies, and matplotlib is included in the standalone bundles.
- Bundles
marked(MIT) andDOMPurify(Apache 2.0 or MPL 2.0) for safe Markdown rendering; HTML outputs of imported notebooks are shown in a script-free sandbox.