<feed xmlns='http://www.w3.org/2005/Atom'>
<title>npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/main, branch master</title>
<subtitle>[no description]</subtitle>
<id>https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/atom?h=master</id>
<link rel='self' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/'/>
<updated>2026-05-21T22:18:46+00:00</updated>
<entry>
<title>feat(cvm): fix CVM MCP roundtrip - task creation, subscription, relay selection</title>
<updated>2026-05-21T22:18:46+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-21T22:18:46+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=ed06f7eeab28c1fa6242c4ea6c3b9c933661fc06'/>
<id>urn:sha1:ed06f7eeab28c1fa6242c4ea6c3b9c933661fc06</id>
<content type='text'>
- Move CVM server start before mint_health_start (avoids RAM fragmentation)
- Fix NIP-01 subscription: #p tag must be array not string
- Fix read loop: tolerate TLS timeouts, don't disconnect
- Reduce TLS timeout from 15s to 5s for faster event delivery
- Add WS frame logging for debugging
- Sign test events with board's nsec (--sec flag) for owner auth
- Change default CVM relay to nos.lol (forwards ephemeral kind 25910)
- MCP get_config and get_balance roundtrips confirmed working
- Unit tests pass (16/16)
</content>
</entry>
<entry>
<title>Wallet receive via health task queue (no separate TLS worker)</title>
<updated>2026-05-21T11:16:51+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-21T11:16:51+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=19e175b1c1dea54efb61e8040ffdfa973fbac5d5'/>
<id>urn:sha1:19e175b1c1dea54efb61e8040ffdfa973fbac5d5</id>
<content type='text'>
- Removed standalone TLS worker task (couldn't allocate 16KB internal stack)
- Added wallet receive queue to mint_health task (already has 16KB stack + working TLS)
- health_task processes wallet tokens between probe intervals (1s poll)
- tls_worker_set_queue() registers queue from mint_health_start()
- Fallback to synchronous receive if queue not available
- Added freertos/queue.h and tollgate_api.h stubs for unit tests
- Added BaseType_t/UBaseType_t/TickType_t/pdFALSE to FreeRTOS stub
- Full payment round-trip confirmed: 2 payments → 41 sat balance
</content>
</entry>
<entry>
<title>feat(wallet): lazy keyset loading with exponential backoff + jitter</title>
<updated>2026-05-21T10:14:46+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-21T10:14:46+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=243e4808246555f86d464d1c476681a902e644ff'/>
<id>urn:sha1:243e4808246555f86d464d1c476681a902e644ff</id>
<content type='text'>
- Remove eager load_keysets() from init_wallet(), load on first use
- Add ensure_keysets() with binary exponential backoff + random jitter
- Guard all wallet operations (receive, send, melt, swap_all) with ensure_keysets()
- Skip checkstate on TLS failure, let wallet swap verify proofs instead
- Pin HTTP server to core 0 (fixes TLS cert verification in checkstate)
- Rewrite nucula http.c to use manual open/write/read (same as working health probe)
- Disable hardware MPI (CONFIG_MBEDTLS_HARDWARE_MPI=n)
- Add http.h stub for unit tests

Known issue: progressive TLS failure after 2-3 connections (PK verify 0x4290),
wallet receive swap fails. Needs deeper mbedTLS/PSRAM investigation.
</content>
</entry>
<entry>
<title>fix: restore AP gateway for DHCP client routing</title>
<updated>2026-05-21T08:20:50+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-21T08:20:50+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=a000d033ae9555e434ad3c6c7b44ed9b445ba99b'/>
<id>urn:sha1:a000d033ae9555e434ad3c6c7b44ed9b445ba99b</id>
<content type='text'>
AP gateway was set to 0.0.0.0 to prevent routing issues, but this
broke DHCP — clients didn't get a default route through the board.
Now set ap_gw = ap_ip so DHCP advertises the board as gateway,
while the STA default route handles outbound internet traffic.
</content>
</entry>
<entry>
<title>cleanup: remove debug code, align mint URL to testnut-nutshell</title>
<updated>2026-05-21T07:49:51+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-21T07:49:51+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=5592e194029aafe96d76a0948750b8b43ae74413'/>
<id>urn:sha1:5592e194029aafe96d76a0948750b8b43ae74413</id>
<content type='text'>
- Remove DNS resolve test and unused includes from debug endpoint
- Reduce mint_health probe logging to DEBUG level
- Update default mint URL from testnut.cashu.space to
  testnut-nutshell.mints.orangesync.tech in config.c,
  tollgate_platform.c, .env, AGENTS.md
</content>
</entry>
<entry>
<title>fix: TLS allocation, stack overflow, DNS bind — mint now reachable</title>
<updated>2026-05-21T00:50:45+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-21T00:50:45+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=716daafce3eaa5ebfd246c1ef9915a2972b4c6fd'/>
<id>urn:sha1:716daafce3eaa5ebfd246c1ef9915a2972b4c6fd</id>
<content type='text'>
Root cause: mbedtls SSL buffers (16KB) couldn't allocate from fragmented
internal RAM (largest block 8KB). Fix by lowering SPIRAM_MALLOC_ALWAYSINTERNAL
from 16KB to 4KB, allowing SSL buffers to go to PSRAM.

Additional fixes:
- DNS server binds to AP IP only (prevents self-hijacking)
- start_services() moved from esp_timer (2KB stack) to dedicated FreeRTOS
  task (16KB stack) — was causing stack overflow with dynamic buffers
- Mint health probe now logs errors and exposes last_err in API
- Debug endpoint shows internal/PSRAM heap breakdown and DNS resolve test
- Enabled CONFIG_MBEDTLS_DYNAMIC_BUFFER for better memory management
- Board C config: mint_url → testnut-nutshell.mints.orangesync.tech
</content>
</entry>
<entry>
<title>fix: start captive portal on AP_START, use esp_timer for service init</title>
<updated>2026-05-20T01:20:27+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-20T01:20:27+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=09c9a6425587e8f71a8089815aaae11e51bdfef9'/>
<id>urn:sha1:09c9a6425587e8f71a8089815aaae11e51bdfef9</id>
<content type='text'>
Root cause: xTaskCreate from within IP event handler never scheduled the
services_start_task on ESP32-S3. Replaced with esp_timer one-shot callback.

Also moved captive_portal_start() into start_ap_services() so the portal
starts immediately when the AP comes up, not waiting for STA GOT IP.

Added /debug endpoint for runtime diagnostics.
Added captive_portal diagnostic getters.
</content>
</entry>
<entry>
<title>fix: resolve display-fix merge conflicts</title>
<updated>2026-05-19T20:48:36+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-19T20:48:36+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=f4f85f938405867be89cfee029d5117cb1b4ac69'/>
<id>urn:sha1:f4f85f938405867be89cfee029d5117cb1b4ac69</id>
<content type='text'>
- Update display_update() call to match new signature (7 args)
- Add tollgate_config_add_wifi() implementation for WiFi setup UI
</content>
</entry>
<entry>
<title>feat: merge display-fix — touch driver, keyboard, WiFi setup UI</title>
<updated>2026-05-19T20:44:45+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-19T20:44:45+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=899016795c389151e6b486ec470653f5688e5c5f'/>
<id>urn:sha1:899016795c389151e6b486ec470653f5688e5c5f</id>
<content type='text'>
Squash-merge of feature/display-fix (27 commits):
- AXS15231B touch driver with coordinate parsing (touch.c/h)
- On-screen keyboard with layout/hit detection (keyboard.c/h)
- WiFi setup state machine + config_add_wifi (wifi_setup.c/h)
- Web-based WiFi setup via captive portal
- Display rotation fix (stride=480), color fixes, DMA byte-swap
- WiFi QR code on BOOT and ERROR screens
- ERROR state transition after WiFi retries exhausted
- Unit tests: test_touch, test_keyboard, test_wifi_setup
- Integration test: wifi_setup.mjs
- E2E test: wifi-setup.spec.mjs
- Per-board hardware locks for flash targets

Conflicts resolved: took master for config/cvm/api/main (more current),
took display-fix for display/axs15231b (newer fixes).
</content>
</entry>
<entry>
<title>fix: revert lwip hook to use main/firewall.c function</title>
<updated>2026-05-19T20:42:13+00:00</updated>
<author>
<name>Your Name</name>
<email>you@example.com</email>
</author>
<published>2026-05-19T20:42:13+00:00</published>
<link rel='alternate' type='text/html' href='https://upleb.uk/npub12m5exm2uk3xa674cc5r0hlyvccs5xxn7qv83ezuteefv5972nquq4j4szl/esp32-tollgate/commit/?id=4f713120dbedd37a3512c2ec1af0766025a59d57'/>
<id>urn:sha1:4f713120dbedd37a3512c2ec1af0766025a59d57</id>
<content type='text'>
tollgate_core_ip4_canforward_filter is in a separate component that
lwip can't link against. Use the existing tollgate_ip4_canforward_filter
from main/firewall.c instead.
</content>
</entry>
</feed>
