<feed xmlns='http://www.w3.org/2005/Atom'>
<title>npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/main, branch feature/tollgate-core-v2</title>
<subtitle>[no description]</subtitle>
<id>https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/atom?h=feature%2Ftollgate-core-v2</id>
<link rel='self' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/atom?h=feature%2Ftollgate-core-v2'/>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/'/>
<updated>2026-05-28T18:58:27+00:00</updated>
<entry>
<title>fix(firewall): remove blanket TCP allow for unpaid clients</title>
<updated>2026-05-28T18:58:27+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-28T18:58:27+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=57bcd53b14e1f795aa94b079c463d41ba8c02e94'/>
<id>urn:sha1:57bcd53b14e1f795aa94b079c463d41ba8c02e94</id>
<content type='text'>
The sandbox_mint_access=true default allowed ALL TCP forwarding from
unpaid clients, completely bypassing the firewall. Fix:
- Remove the blanket TCP allow when sandbox_mint_access is set
- Only allow traffic to AP IP on specific ports (80, 2121, 4869, mining)
- Allow ICMP to AP IP for diagnostics
- Default sandbox_mint_access to false
- Add port 4869 (local relay) to allowed sandbox ports

Verified on Board B: unpaid clients blocked from internet, local
services (portal, API, relay) still accessible.
</content>
</entry>
<entry>
<title>Phase 8c-8f: Extract portal, stratum_client, mint_health, client into tollgate_core</title>
<updated>2026-05-23T09:56:52+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-23T09:56:52+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=be4d490e96de3d20cc6c9921f09534cde0ca0765'/>
<id>urn:sha1:be4d490e96de3d20cc6c9921f09534cde0ca0765</id>
<content type='text'>
New component modules:
- tollgate_core_portal.c/h: template rendering, usage calc, captive URI detection
- tollgate_core_stratum_client.c/h: Stratum V1 JSON protocol parsing, message building
- tollgate_core_mint_health.c/h: mint health state tracking, recovery threshold logic
- tollgate_core_client.c/h: discovery/session/usage JSON parsing, renewal check, price calc

Main shims updated to delegate pure logic to component:
- captive_portal.c: uses tollgate_core_portal_render(), format_usage(), is_captive_uri()
- stratum_client.c: uses tollgate_core_stratum_parse_notify/build_*()
- mint_health.c: uses tollgate_core_mint_health_update/is_reachable/mark_unreachable()
- tollgate_client.c: uses tollgate_core_client_parse_*/should_renew/calc_price_per_min()

4 new unit tests (test_portal, test_stratum_client, test_mint_health_core, test_client_core)
All 25 unit tests pass. ESP-IDF build passes (68% partition free).
</content>
</entry>
<entry>
<title>Phase 8a-8b: extract beacon_price and market into component</title>
<updated>2026-05-23T00:54:33+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-23T00:54:33+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=0642900ae44d84cfe24abe6911dbed4cd31ab8ad'/>
<id>urn:sha1:0642900ae44d84cfe24abe6911dbed4cd31ab8ad</id>
<content type='text'>
- tollgate_core_beacon.c/h: pure logic (hash_mint, hash_npub, build_ie)
  with platform-agnostic tollgate_beacon_config_t input struct
- tollgate_core_market.c/h: market table logic (parse_ie, find_cheapest,
  update_ssid) with platform callbacks for time
- main/beacon_price.c: thin shim delegates to component, WiFi IE start/stop
- main/market.h: typedef aliases to component types
- All 21 unit tests pass, ESP-IDF build passes
- Hardware smoke test: 5/6 pass (AP, portal, grant/revoke, firewall)
- Market scanner discovers other TollGates via vendor IEs on hardware
</content>
</entry>
<entry>
<title>Phase 7: eliminate shims - consumer files use component headers directly</title>
<updated>2026-05-23T00:02:22+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-23T00:02:22+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=5140a30be35aaf3574efce9193549f18524ce46e'/>
<id>urn:sha1:5140a30be35aaf3574efce9193549f18524ce46e</id>
<content type='text'>
- Deleted standalone shims: session.c/h, cashu.c/h, mining_payment.c/h, firewall.c/h
- Updated captive_portal.c, tollgate_api.c, tollgate_main.c, mcp_handler.c,
  cvm_server.c, sw_miner.c, stratum_client.c to include component headers
- Moved tollgate_ip4_canforward_filter() lwIP hook into tollgate_main.c
- Fixed all unit tests to use component API (test_cashu, test_session,
  test_mining_payment, test_stratum_proxy, test_session_payment_method,
  test_firewall_sandbox, test_mcp_handler)
- Removed deleted source files from Makefile targets
- All 21 unit tests pass, ESP-IDF build passes
</content>
</entry>
<entry>
<title>Phase 6e-6f: Break circular dependencies</title>
<updated>2026-05-22T23:25:11+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-22T23:25:11+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=fb8558cbf964fae5a840f8f948b89a0d42045802'/>
<id>urn:sha1:fb8558cbf964fae5a840f8f948b89a0d42045802</id>
<content type='text'>
6e: Extract tls_worker queue from tollgate_api.c into shared tls_worker.c/h
    - mint_health.c no longer includes tollgate_api.h
    - tollgate_api.c no longer defines tls_worker functions
    - Clean circular dependency broken

6f: Move payout_config_t from lightning_payout.h to config.h
    - config.h no longer includes lightning_payout.h
    - lightning_payout.h includes config.h for types
    - Reverse dependency broken

All 21 unit tests pass. ESP-IDF build passes.
</content>
</entry>
<entry>
<title>Phase 6a-6d: Consolidate and clean up</title>
<updated>2026-05-22T23:20:26+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-22T23:20:26+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=9330b01c28aebc865a3c0a51df8730196cb4152e'/>
<id>urn:sha1:9330b01c28aebc865a3c0a51df8730196cb4152e</id>
<content type='text'>
6a: Delete dead standalone tollgate_core/ (12 files, never compiled)
6b: Rewrite dns_server.c as thin shim to component's tollgate_core_dns
    - Fix component DNS to bind to AP IP instead of INADDR_ANY
6c: Rewrite stratum_proxy.c as thin shim with struct cast to component types
6d: Move sandbox logic into component's tollgate_core_firewall
    - Add tollgate_core_fw_set_sandbox_ports/set_sandbox_mint_access
    - Add is_sandbox_allowed() to component's ip4_canforward_filter
    - Clean main/firewall.c to delegate filter to component
    - Remove redundant DNS auth double-calls from main firewall
Add ROADMAP.md with full extraction plan and checklists

All 21 unit tests pass. ESP-IDF build passes.
</content>
</entry>
<entry>
<title>Phase 5: Wire main/ shims to components/tollgate_core</title>
<updated>2026-05-22T22:40:28+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-22T22:40:28+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=851801f50f1282ab1db5f8a241dbd245f59e447e'/>
<id>urn:sha1:851801f50f1282ab1db5f8a241dbd245f59e447e</id>
<content type='text'>
- session.c/h: thin shim casting session_t* &lt;-&gt; tg_session_t*, delegates to tollgate_core_session_*
- firewall.c/h: keeps ESP-specific lwIP hooks, delegates allowlist to tollgate_core_fw_*
- cashu.c/h: shim delegates to tollgate_core_cashu_*, multi-mint via config directly
- mining_payment.c: shim delegates to tollgate_core_mining_*
- tollgate_main.c: calls tollgate_core_init(tollgate_esp_get_platform(), ap_ip) in start_services()
- tollgate_esp: removed target_sources for standalone sources, depends on tollgate_core component
- tollgate_core component: added tollgate_core_get_platform(), tg_payment_method_t enum
- Unit tests: updated Makefile for component source compilation, all 22 tests pass
- Hardware verified: Board A boots, AP visible, 5/6 smoke tests pass (internet test needs upstream WiFi)
</content>
</entry>
<entry>
<title>feat(cvm): fix CVM MCP roundtrip - task creation, subscription, relay selection</title>
<updated>2026-05-21T22:18:46+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-21T22:18:46+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=ed06f7eeab28c1fa6242c4ea6c3b9c933661fc06'/>
<id>urn:sha1:ed06f7eeab28c1fa6242c4ea6c3b9c933661fc06</id>
<content type='text'>
- Move CVM server start before mint_health_start (avoids RAM fragmentation)
- Fix NIP-01 subscription: #p tag must be array not string
- Fix read loop: tolerate TLS timeouts, don't disconnect
- Reduce TLS timeout from 15s to 5s for faster event delivery
- Add WS frame logging for debugging
- Sign test events with board's nsec (--sec flag) for owner auth
- Change default CVM relay to nos.lol (forwards ephemeral kind 25910)
- MCP get_config and get_balance roundtrips confirmed working
- Unit tests pass (16/16)
</content>
</entry>
<entry>
<title>Wallet receive via health task queue (no separate TLS worker)</title>
<updated>2026-05-21T11:16:51+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-21T11:16:51+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=19e175b1c1dea54efb61e8040ffdfa973fbac5d5'/>
<id>urn:sha1:19e175b1c1dea54efb61e8040ffdfa973fbac5d5</id>
<content type='text'>
- Removed standalone TLS worker task (couldn't allocate 16KB internal stack)
- Added wallet receive queue to mint_health task (already has 16KB stack + working TLS)
- health_task processes wallet tokens between probe intervals (1s poll)
- tls_worker_set_queue() registers queue from mint_health_start()
- Fallback to synchronous receive if queue not available
- Added freertos/queue.h and tollgate_api.h stubs for unit tests
- Added BaseType_t/UBaseType_t/TickType_t/pdFALSE to FreeRTOS stub
- Full payment round-trip confirmed: 2 payments → 41 sat balance
</content>
</entry>
<entry>
<title>feat(wallet): lazy keyset loading with exponential backoff + jitter</title>
<updated>2026-05-21T10:14:46+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-21T10:14:46+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=243e4808246555f86d464d1c476681a902e644ff'/>
<id>urn:sha1:243e4808246555f86d464d1c476681a902e644ff</id>
<content type='text'>
- Remove eager load_keysets() from init_wallet(), load on first use
- Add ensure_keysets() with binary exponential backoff + random jitter
- Guard all wallet operations (receive, send, melt, swap_all) with ensure_keysets()
- Skip checkstate on TLS failure, let wallet swap verify proofs instead
- Pin HTTP server to core 0 (fixes TLS cert verification in checkstate)
- Rewrite nucula http.c to use manual open/write/read (same as working health probe)
- Disable hardware MPI (CONFIG_MBEDTLS_HARDWARE_MPI=n)
- Add http.h stub for unit tests

Known issue: progressive TLS failure after 2-3 connections (PK verify 0x4290),
wallet receive swap fails. Needs deeper mbedTLS/PSRAM investigation.
</content>
</entry>
</feed>
