diff options
| author | Your Name <you@example.com> | 2026-05-23 04:50:26 +0530 |
|---|---|---|
| committer | Your Name <you@example.com> | 2026-05-23 04:50:26 +0530 |
| commit | 9330b01c28aebc865a3c0a51df8730196cb4152e (patch) | |
| tree | 60c3ae35b2550c737c228e81fd342c8d07af11af | |
| parent | 851801f50f1282ab1db5f8a241dbd245f59e447e (diff) | |
Phase 6a-6d: Consolidate and clean up
6a: Delete dead standalone tollgate_core/ (12 files, never compiled)
6b: Rewrite dns_server.c as thin shim to component's tollgate_core_dns
- Fix component DNS to bind to AP IP instead of INADDR_ANY
6c: Rewrite stratum_proxy.c as thin shim with struct cast to component types
6d: Move sandbox logic into component's tollgate_core_firewall
- Add tollgate_core_fw_set_sandbox_ports/set_sandbox_mint_access
- Add is_sandbox_allowed() to component's ip4_canforward_filter
- Clean main/firewall.c to delegate filter to component
- Remove redundant DNS auth double-calls from main firewall
Add ROADMAP.md with full extraction plan and checklists
All 21 unit tests pass. ESP-IDF build passes.
23 files changed, 329 insertions, 2104 deletions
diff --git a/ROADMAP.md b/ROADMAP.md new file mode 100644 index 0000000..b4fe16b --- /dev/null +++ b/ROADMAP.md | |||
| @@ -0,0 +1,262 @@ | |||
| 1 | # TollGate Core Extraction Roadmap | ||
| 2 | |||
| 3 | **Branch:** `feature/tollgate-core-v2` | ||
| 4 | **Start commit:** `851801f` (Phase 5 complete, hardware-verified) | ||
| 5 | **Goal:** Extract all portable TollGate business logic into `components/tollgate_core/` for reuse in NerdQAxePlus and other ESP32 firmware. | ||
| 6 | |||
| 7 | ## Testing Protocol | ||
| 8 | |||
| 9 | After **every** step: | ||
| 10 | |||
| 11 | 1. `make test-unit` -- all 21+ unit tests must pass | ||
| 12 | 2. `idf.py build` -- ESP-IDF build must succeed | ||
| 13 | 3. After multi-step phases: flash Board A + `pytest tests/test_smoke.py --board=a` | ||
| 14 | |||
| 15 | --- | ||
| 16 | |||
| 17 | ## Phase 6: Consolidate & Clean Up | ||
| 18 | |||
| 19 | ### 6a. Delete standalone `tollgate_core/` | ||
| 20 | |||
| 21 | Dead code -- nothing in the build references it. The component version is what's compiled. | ||
| 22 | |||
| 23 | - [ ] `git rm -r tollgate_core/` | ||
| 24 | - [ ] Verify nothing references it: `grep -r "tollgate_core/" main/ components/ tests/` | ||
| 25 | - [ ] Test: `make test-unit` + `idf.py build` | ||
| 26 | |||
| 27 | ### 6b. Eliminate `dns_server.c` duplication | ||
| 28 | |||
| 29 | `main/dns_server.c` (316 lines) duplicates `components/tollgate_core/src/tollgate_core_dns.c`. | ||
| 30 | |||
| 31 | - [ ] Rewrite `main/dns_server.c` as thin shim: `dns_server_*()` calls `tollgate_core_dns_*()` | ||
| 32 | - [ ] Update `main/dns_server.h` to keep original function signatures | ||
| 33 | - [ ] Move `dns_server_set_client_authenticated()` notification to component's internal DNS | ||
| 34 | - [ ] Add unit test for DNS shim if not covered by existing `test_firewall_sandbox` | ||
| 35 | - [ ] Test: `make test-unit` + `idf.py build` + flash + pytest smoke | ||
| 36 | |||
| 37 | ### 6c. Eliminate `stratum_proxy.c` duplication | ||
| 38 | |||
| 39 | `main/stratum_proxy.c` (160 lines) duplicates `components/tollgate_core/src/tollgate_core_stratum_proxy.c`. | ||
| 40 | |||
| 41 | - [ ] Rewrite `main/stratum_proxy.c` as thin shim: `stratum_proxy_*()` -> `tollgate_core_stratum_proxy_*()` | ||
| 42 | - [ ] Update `main/stratum_proxy.h` to keep original type names for backward compat | ||
| 43 | - [ ] Test: `make test-unit` + `idf.py build` | ||
| 44 | |||
| 45 | ### 6d. Move sandbox logic into component firewall | ||
| 46 | |||
| 47 | `main/firewall.c` has `is_sandbox_allowed()` (allows TCP to ports 80/2121/mining_port for unauth clients) -- missing from component. | ||
| 48 | |||
| 49 | - [ ] Add `tollgate_core_fw_set_sandbox_ports()` to component's firewall API | ||
| 50 | - [ ] Add `tollgate_core_fw_is_sandbox_allowed()` to component's internal firewall | ||
| 51 | - [ ] Update component's `tollgate_core_ip4_canforward_filter` to check sandbox rules | ||
| 52 | - [ ] Update `main/firewall.c` shim to call `tollgate_core_fw_set_sandbox_ports()` in init | ||
| 53 | - [ ] Add unit test for sandbox logic with known port combinations | ||
| 54 | - [ ] Test: `make test-unit` + `idf.py build` + flash + `pytest tests/test_dns_firewall.py --board=a` | ||
| 55 | |||
| 56 | ### 6e. Break `mint_health` <-> `tollgate_api` circular dependency | ||
| 57 | |||
| 58 | `mint_health.c` includes `tollgate_api.h` for `tls_worker_set_queue()`. `tollgate_api.c` includes `mint_health.h` for `mint_health_get_all()`. | ||
| 59 | |||
| 60 | - [ ] Extract `QueueHandle_t tls_worker_queue` into a shared module (e.g., `tls_worker.h/c`) | ||
| 61 | - [ ] `mint_health.c` includes `tls_worker.h` instead of `tollgate_api.h` | ||
| 62 | - [ ] `tollgate_api.c` includes `tls_worker.h` to get the queue | ||
| 63 | - [ ] Test: `make test-unit` + `idf.py build` | ||
| 64 | |||
| 65 | ### 6f. Break `config.h` -> `lightning_payout.h` reverse dependency | ||
| 66 | |||
| 67 | `config.h` includes `lightning_payout.h` for `payout_config_t` type. | ||
| 68 | |||
| 69 | - [ ] Move `payout_config_t` typedef to `config.h` (or a shared `tollgate_types.h`) | ||
| 70 | - [ ] Remove `#include "lightning_payout.h"` from `config.h` | ||
| 71 | - [ ] Add `#include "config.h"` to `lightning_payout.c` if needed | ||
| 72 | - [ ] Test: `make test-unit` + `idf.py build` + **commit + push** | ||
| 73 | |||
| 74 | --- | ||
| 75 | |||
| 76 | ## Phase 7: Eliminate Shim Files | ||
| 77 | |||
| 78 | Remove thin wrappers. Consumers use component headers directly. | ||
| 79 | |||
| 80 | ### 7a. Remove `session.c` / `session.h` shim | ||
| 81 | |||
| 82 | - [ ] Update `tollgate_api.c`: `#include "tollgate_core_session.h"` instead of `#include "session.h"` | ||
| 83 | - [ ] Update `captive_portal.c`: same | ||
| 84 | - [ ] Update any other consumers of `session.h` | ||
| 85 | - [ ] Delete `main/session.c` and `main/session.h` | ||
| 86 | - [ ] Remove from `main/CMakeLists.txt` SRCS | ||
| 87 | - [ ] Update unit test Makefile if needed | ||
| 88 | - [ ] Test: `make test-unit` + `idf.py build` | ||
| 89 | |||
| 90 | ### 7b. Remove `cashu.c` / `cashu.h` shim | ||
| 91 | |||
| 92 | - [ ] Update `tollgate_api.c`: `#include "tollgate_core_cashu.h"` instead of `#include "cashu.h"` | ||
| 93 | - [ ] Move multi-mint logic (iterating `accepted_mints[]`) into component's `tollgate_core_cashu_is_mint_accepted()` | ||
| 94 | - [ ] Delete `main/cashu.c` and `main/cashu.h` | ||
| 95 | - [ ] Remove from `main/CMakeLists.txt` SRCS | ||
| 96 | - [ ] Test: `make test-unit` + `idf.py build` | ||
| 97 | |||
| 98 | ### 7c. Remove `mining_payment.c` / `mining_payment.h` shim | ||
| 99 | |||
| 100 | - [ ] Update all consumers: `#include "tollgate_core_mining.h"` instead of `#include "mining_payment.h"` | ||
| 101 | - [ ] Delete `main/mining_payment.c` and `main/mining_payment.h` | ||
| 102 | - [ ] Remove from `main/CMakeLists.txt` SRCS | ||
| 103 | - [ ] Test: `make test-unit` + `idf.py build` | ||
| 104 | |||
| 105 | ### 7d. Remove `firewall.c` / `firewall.h` shim | ||
| 106 | |||
| 107 | After 6d, firewall shim only has lwIP hook registration + DNS notification. | ||
| 108 | |||
| 109 | - [ ] Move lwIP hook registration into `tollgate_main.c` or a new `main/esp_hooks.c` | ||
| 110 | - [ ] Update consumers to use `tollgate_core_fw_*()` directly | ||
| 111 | - [ ] Delete `main/firewall.c` and `main/firewall.h` | ||
| 112 | - [ ] Remove from `main/CMakeLists.txt` SRCS | ||
| 113 | - [ ] Test: `make test-unit` + `idf.py build` + flash + pytest smoke + DNS/firewall tests | ||
| 114 | - [ ] **Commit + push** | ||
| 115 | |||
| 116 | --- | ||
| 117 | |||
| 118 | ## Phase 8: Extract Layer 1 into Component | ||
| 119 | |||
| 120 | ### 8a. Extract `beacon_price.c` -> `tollgate_core_beacon.c` | ||
| 121 | |||
| 122 | Dependencies: `config`, `identity`, `esp_wifi`, `mbedtls/sha256` | ||
| 123 | |||
| 124 | - [ ] Create `components/tollgate_core/src/tollgate_core_beacon.c/h` | ||
| 125 | - [ ] Abstract WiFi vendor IE API via `tollgate_platform_t` callbacks: `set_vendor_ie()`, `scan_start()` | ||
| 126 | - [ ] Move mint URL + npub hashing, geohash embedding, IE construction to component | ||
| 127 | - [ ] Rewrite `main/beacon_price.c` as thin ESP-specific glue calling component | ||
| 128 | - [ ] Add unit test with known IE vectors | ||
| 129 | - [ ] Test: `make test-unit` + `idf.py build` | ||
| 130 | |||
| 131 | ### 8b. Extract `market.c` -> `tollgate_core_market.c` | ||
| 132 | |||
| 133 | Dependencies: `beacon_price`, `config`, `identity`, `esp_wifi` | ||
| 134 | |||
| 135 | - [ ] Create `components/tollgate_core/src/tollgate_core_market.c/h` | ||
| 136 | - [ ] Abstract WiFi scan results via platform callback: `on_scan_result()` | ||
| 137 | - [ ] Move market entry table, price comparison, cheapest selection to component | ||
| 138 | - [ ] Rewrite `main/market.c` as thin glue | ||
| 139 | - [ ] Add unit test for market table operations | ||
| 140 | - [ ] Test: `make test-unit` + `idf.py build` | ||
| 141 | |||
| 142 | ### 8c. Extract `captive_portal.c` -> `tollgate_core_portal.c` | ||
| 143 | |||
| 144 | Dependencies: `firewall`, `session`, `config`, `mining_payment`, `stratum_proxy`, `esp_http_server` | ||
| 145 | |||
| 146 | - [ ] Create `components/tollgate_core/src/tollgate_core_portal.c/h` | ||
| 147 | - [ ] Extract template rendering logic (HTML generation, `__AP_IP__`/`__PRICE__` substitution) | ||
| 148 | - [ ] Extract captive detection URI handling (generate_204, hotspot-detect, success.txt, etc.) | ||
| 149 | - [ ] Extract payment processing flow (POST token -> decode -> validate -> grant) | ||
| 150 | - [ ] Abstract HTTP server via platform callbacks: `httpd_start()`, `register_handler()`, `send_response()` | ||
| 151 | - [ ] Keep ESP `httpd` glue in `main/captive_portal.c` (thin handler registration) | ||
| 152 | - [ ] Add unit test for template substitution + captive URI detection | ||
| 153 | - [ ] Test: `make test-unit` + `idf.py build` + flash + pytest portal tests | ||
| 154 | |||
| 155 | ### 8d. Extract `stratum_client.c` -> `tollgate_core_stratum_client.c` | ||
| 156 | |||
| 157 | Dependencies: `stratum_proxy`, `mining_payment`, `config`, `esp_transport` | ||
| 158 | |||
| 159 | - [ ] Create `components/tollgate_core/src/tollgate_core_stratum_client.c/h` | ||
| 160 | - [ ] Abstract TCP transport via platform callbacks | ||
| 161 | - [ ] Move Stratum V1 protocol logic (subscribe, authorize, handle mining.notify, submit share) | ||
| 162 | - [ ] Rewrite `main/stratum_client.c` as thin glue | ||
| 163 | - [ ] Add unit test for Stratum message parsing | ||
| 164 | - [ ] Test: `make test-unit` + `idf.py build` | ||
| 165 | |||
| 166 | ### 8e. Extract `mint_health.c` -> `tollgate_core_mint_health.c` | ||
| 167 | |||
| 168 | Dependencies: `tls_worker` (after 6e), `nucula_wallet`, `esp_http_client` | ||
| 169 | |||
| 170 | - [ ] Create `components/tollgate_core/src/tollgate_core_mint_health.c/h` | ||
| 171 | - [ ] Abstract HTTP client via platform callback: `http_get()`, `tls_worker_queue` | ||
| 172 | - [ ] Move mint probing logic, health state tracking, reachable/unreachable marking | ||
| 173 | - [ ] Rewrite `main/mint_health.c` as thin glue | ||
| 174 | - [ ] Add unit test for health state machine | ||
| 175 | - [ ] Test: `make test-unit` + `idf.py build` | ||
| 176 | |||
| 177 | ### 8f. Extract `tollgate_client.c` -> `tollgate_core_client.c` | ||
| 178 | |||
| 179 | Dependencies: `config`, `market`, `nucula_wallet`, `esp_http_client` | ||
| 180 | |||
| 181 | - [ ] Create `components/tollgate_core/src/tollgate_core_client.c/h` | ||
| 182 | - [ ] Abstract HTTP + wallet via platform callbacks | ||
| 183 | - [ ] Move upstream TollGate discovery, auto-pay, usage tracking, auto-renew logic | ||
| 184 | - [ ] Rewrite `main/tollgate_client.c` as thin glue | ||
| 185 | - [ ] Add unit test for client state machine (already exists: `test_tollgate_client.c`) | ||
| 186 | - [ ] Test: `make test-unit` + `idf.py build` + flash + full pytest suite | ||
| 187 | - [ ] **Commit + push** | ||
| 188 | |||
| 189 | --- | ||
| 190 | |||
| 191 | ## Phase 9: NerdQAxePlus Integration | ||
| 192 | |||
| 193 | ### 9a. Restore miner-integration worktree | ||
| 194 | |||
| 195 | - [ ] `git worktree add /home/c03rad0r/esp32-miner-integration feature/miner-integration` | ||
| 196 | - [ ] Or create fresh from `remotes/orangesync/feature/miner-integration` | ||
| 197 | - [ ] Verify NerdQAxePlus fork at `/home/c03rad0r/esp-miner-nerdqaxeplus/` is intact | ||
| 198 | |||
| 199 | ### 9b. Copy finalized `tollgate_core` component | ||
| 200 | |||
| 201 | - [ ] Sync `components/tollgate_core/` from esp32-tollgate -> NerdQAxePlus `components/tollgate_core/` | ||
| 202 | - [ ] Update NerdQAxePlus `CMakeLists.txt` to depend on `tollgate_core` | ||
| 203 | - [ ] Verify `BOARD=NERDAXE TOLLGATE=1 idf.py build` succeeds | ||
| 204 | |||
| 205 | ### 9c. Implement `tollgate_platform_t` for BitAxe/BM1397 | ||
| 206 | |||
| 207 | - [ ] Create `components/tollgate_baxe/` with BitAxe-specific platform implementation | ||
| 208 | - [ ] Implement callbacks: `get_price_sats()`, `get_mint_url()`, `spend_proofs()`, stratum config | ||
| 209 | - [ ] Wire BM1397 ASIC -> stratum proxy -> tollgate_core mining pipeline | ||
| 210 | - [ ] Wire eCash payment -> session -> internet access on BitAxe AP | ||
| 211 | |||
| 212 | ### 9d. Integrate into NerdQAxePlus UI | ||
| 213 | |||
| 214 | - [ ] Add payment status to OLED/LCD display | ||
| 215 | - [ ] Add WiFi AP setup with SSID derived from identity | ||
| 216 | - [ ] Add Cashu token input via web portal | ||
| 217 | - [ ] Test: Flash NerdAxe Ultra + mining test + payment test + internet verification | ||
| 218 | - [ ] **Commit + push** | ||
| 219 | |||
| 220 | --- | ||
| 221 | |||
| 222 | ## Phase 10: Publish | ||
| 223 | |||
| 224 | ### 10a. Component metadata | ||
| 225 | |||
| 226 | - [ ] Update `idf_component.yml` with proper version, description, dependencies | ||
| 227 | - [ ] Add `README.md` to `components/tollgate_core/` with API docs | ||
| 228 | - [ ] Add `CHANGELOG.md` to component | ||
| 229 | |||
| 230 | ### 10b. CI pipeline | ||
| 231 | |||
| 232 | - [ ] GitHub Actions or self-hosted CI: build on push, run unit tests | ||
| 233 | - [ ] Hardware-in-the-loop testing on push to develop (Board A) | ||
| 234 | - [ ] Integration test matrix: Board A + Board B + Board C | ||
| 235 | |||
| 236 | ### 10c. Publish to IDF Component Registry | ||
| 237 | |||
| 238 | - [ ] `compote component upload` to ESP-IDF Component Registry | ||
| 239 | - [ ] Verify `idf.py add-dependency` works from a clean project | ||
| 240 | - [ ] Document usage in top-level README | ||
| 241 | |||
| 242 | --- | ||
| 243 | |||
| 244 | ## Dependency Graph (Extraction Order) | ||
| 245 | |||
| 246 | ``` | ||
| 247 | Layer 0: dns_server, lnurl_pay, asic_miner (no main/ deps) | ||
| 248 | Layer 1: config, identity, session, cashu, mining (foundation) | ||
| 249 | Layer 2: firewall, beacon_price, lightning_payout (depends on Layer 1) | ||
| 250 | Layer 3: market, stratum_proxy, stratum_client (depends on Layer 2) | ||
| 251 | Layer 4: captive_portal, tollgate_client, mint_health (depends on Layer 3) | ||
| 252 | Layer 5: tollgate_api (depends on everything) | ||
| 253 | ``` | ||
| 254 | |||
| 255 | ## Current Test Coverage | ||
| 256 | |||
| 257 | | Type | Count | Command | | ||
| 258 | |------|-------|---------| | ||
| 259 | | Host unit tests | 21 | `make test-unit` | | ||
| 260 | | Integration tests | 17 | `TOLLGATE_IP=x make test-integration` | | ||
| 261 | | E2E tests | 3 suites | `make test-e2e` | | ||
| 262 | | Pytest (hardware) | 12 files | `pytest tests/ --board=a` | | ||
diff --git a/components/tollgate_core/src/tollgate_core_dns.c b/components/tollgate_core/src/tollgate_core_dns.c index 84322e6..c44dd31 100644 --- a/components/tollgate_core/src/tollgate_core_dns.c +++ b/components/tollgate_core/src/tollgate_core_dns.c | |||
| @@ -160,7 +160,7 @@ static void dns_server_task(void *arg) | |||
| 160 | struct sockaddr_in bind_addr = { | 160 | struct sockaddr_in bind_addr = { |
| 161 | .sin_family = AF_INET, | 161 | .sin_family = AF_INET, |
| 162 | .sin_port = htons(DNS_PORT), | 162 | .sin_port = htons(DNS_PORT), |
| 163 | .sin_addr.s_addr = INADDR_ANY, | 163 | .sin_addr.s_addr = s_ap_ip.addr, |
| 164 | }; | 164 | }; |
| 165 | if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { | 165 | if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { |
| 166 | ESP_LOGE(TAG, "Failed to bind DNS socket"); | 166 | ESP_LOGE(TAG, "Failed to bind DNS socket"); |
diff --git a/components/tollgate_core/src/tollgate_core_firewall.c b/components/tollgate_core/src/tollgate_core_firewall.c index ad0697e..4f12923 100644 --- a/components/tollgate_core/src/tollgate_core_firewall.c +++ b/components/tollgate_core/src/tollgate_core_firewall.c | |||
| @@ -9,12 +9,16 @@ | |||
| 9 | #include "lwip/etharp.h" | 9 | #include "lwip/etharp.h" |
| 10 | #include "lwip/netif.h" | 10 | #include "lwip/netif.h" |
| 11 | #include "lwip/prot/ip4.h" | 11 | #include "lwip/prot/ip4.h" |
| 12 | #include "lwip/prot/tcp.h" | ||
| 13 | #include "lwip/prot/ip.h" | ||
| 12 | #include <string.h> | 14 | #include <string.h> |
| 13 | 15 | ||
| 14 | #define MAX_CLIENTS 10 | 16 | #define MAX_CLIENTS 10 |
| 15 | 17 | ||
| 16 | static const char *TAG = "tg_core_fw"; | 18 | static const char *TAG = "tg_core_fw"; |
| 17 | static esp_ip4_addr_t s_ap_ip; | 19 | static esp_ip4_addr_t s_ap_ip; |
| 20 | static uint16_t s_mining_port = 3333; | ||
| 21 | static bool s_sandbox_mint_access = false; | ||
| 18 | 22 | ||
| 19 | typedef struct { | 23 | typedef struct { |
| 20 | uint32_t ip; | 24 | uint32_t ip; |
| @@ -70,6 +74,46 @@ esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip) | |||
| 70 | return ESP_OK; | 74 | return ESP_OK; |
| 71 | } | 75 | } |
| 72 | 76 | ||
| 77 | void tollgate_core_fw_set_sandbox_ports(uint16_t mining_port) | ||
| 78 | { | ||
| 79 | s_mining_port = mining_port; | ||
| 80 | } | ||
| 81 | |||
| 82 | void tollgate_core_fw_set_sandbox_mint_access(bool enabled) | ||
| 83 | { | ||
| 84 | s_sandbox_mint_access = enabled; | ||
| 85 | } | ||
| 86 | |||
| 87 | static bool is_sandbox_allowed(struct pbuf *p) | ||
| 88 | { | ||
| 89 | if (p->len < IP_HLEN) return false; | ||
| 90 | struct ip_hdr *iphdr = (struct ip_hdr *)p->payload; | ||
| 91 | uint32_t dest_ip_h = lwip_ntohl(iphdr->dest.addr); | ||
| 92 | uint32_t ap_ip_h = lwip_ntohl(s_ap_ip.addr); | ||
| 93 | |||
| 94 | if (dest_ip_h == ap_ip_h) { | ||
| 95 | if (iphdr->_proto == IP_PROTO_TCP) { | ||
| 96 | uint16_t dst_port = 0; | ||
| 97 | if (p->len >= IP_HLEN + TCP_HLEN) { | ||
| 98 | struct tcp_hdr *tcphdr = (struct tcp_hdr *)((uint8_t *)p->payload + IP_HLEN); | ||
| 99 | dst_port = lwip_ntohs(tcphdr->dest); | ||
| 100 | } | ||
| 101 | if (dst_port == 80 || dst_port == 2121 || dst_port == s_mining_port) { | ||
| 102 | return true; | ||
| 103 | } | ||
| 104 | } | ||
| 105 | if (iphdr->_proto == IP_PROTO_UDP) { | ||
| 106 | return true; | ||
| 107 | } | ||
| 108 | } | ||
| 109 | |||
| 110 | if (s_sandbox_mint_access && iphdr->_proto == IP_PROTO_TCP) { | ||
| 111 | return true; | ||
| 112 | } | ||
| 113 | |||
| 114 | return false; | ||
| 115 | } | ||
| 116 | |||
| 73 | int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) | 117 | int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) |
| 74 | { | 118 | { |
| 75 | (void)dest_addr_hostorder; | 119 | (void)dest_addr_hostorder; |
| @@ -83,6 +127,9 @@ int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorde | |||
| 83 | if (tollgate_core_fw_is_allowed(iphdr->src.addr)) { | 127 | if (tollgate_core_fw_is_allowed(iphdr->src.addr)) { |
| 84 | return 1; | 128 | return 1; |
| 85 | } | 129 | } |
| 130 | if (is_sandbox_allowed(p)) { | ||
| 131 | return 1; | ||
| 132 | } | ||
| 86 | return 0; | 133 | return 0; |
| 87 | } | 134 | } |
| 88 | 135 | ||
diff --git a/components/tollgate_core/src/tollgate_core_firewall.h b/components/tollgate_core/src/tollgate_core_firewall.h index f06c801..7f24372 100644 --- a/components/tollgate_core/src/tollgate_core_firewall.h +++ b/components/tollgate_core/src/tollgate_core_firewall.h | |||
| @@ -11,6 +11,8 @@ struct pbuf; | |||
| 11 | #define TG_FW_MAX_MAC_LEN 18 | 11 | #define TG_FW_MAX_MAC_LEN 18 |
| 12 | 12 | ||
| 13 | esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip); | 13 | esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip); |
| 14 | void tollgate_core_fw_set_sandbox_ports(uint16_t mining_port); | ||
| 15 | void tollgate_core_fw_set_sandbox_mint_access(bool enabled); | ||
| 14 | void tollgate_core_fw_grant(uint32_t client_ip); | 16 | void tollgate_core_fw_grant(uint32_t client_ip); |
| 15 | void tollgate_core_fw_revoke(uint32_t client_ip); | 17 | void tollgate_core_fw_revoke(uint32_t client_ip); |
| 16 | void tollgate_core_fw_revoke_all(void); | 18 | void tollgate_core_fw_revoke_all(void); |
diff --git a/main/dns_server.c b/main/dns_server.c index b84a4cf..5b1bdc3 100644 --- a/main/dns_server.c +++ b/main/dns_server.c | |||
| @@ -1,316 +1,22 @@ | |||
| 1 | #include "dns_server.h" | 1 | #include "dns_server.h" |
| 2 | #include "esp_log.h" | 2 | #include "tollgate_core_dns.h" |
| 3 | #include "freertos/FreeRTOS.h" | ||
| 4 | #include "freertos/task.h" | ||
| 5 | #include "lwip/sockets.h" | ||
| 6 | #include "lwip/netdb.h" | ||
| 7 | #include <string.h> | ||
| 8 | #include <sys/param.h> | ||
| 9 | |||
| 10 | #define MAX_AUTH_IPS 10 | ||
| 11 | #define MAX_PENDING 50 | ||
| 12 | #define DNS_BUF_SIZE 512 | ||
| 13 | #define DNS_PORT 53 | ||
| 14 | #define DOT_PORT 853 | ||
| 15 | #define DNS_TASK_STACK 4096 | ||
| 16 | #define DOT_TASK_STACK 3072 | ||
| 17 | #define DNS_TASK_PRIO 5 | ||
| 18 | #define DOT_TASK_PRIO 5 | ||
| 19 | #define DNS_FORWARD_TIMEOUT_MS 2000 | ||
| 20 | #define NXDOMAIN_TTL 30 | ||
| 21 | #define HIJACK_TTL 10 | ||
| 22 | |||
| 23 | static const char *TAG = "dns_server"; | ||
| 24 | |||
| 25 | #pragma pack(push, 1) | ||
| 26 | typedef struct { | ||
| 27 | uint16_t id; | ||
| 28 | uint16_t flags; | ||
| 29 | uint16_t qdcount; | ||
| 30 | uint16_t ancount; | ||
| 31 | uint16_t nscount; | ||
| 32 | uint16_t arcount; | ||
| 33 | } dns_header_t; | ||
| 34 | #pragma pack(pop) | ||
| 35 | |||
| 36 | #pragma pack(push, 1) | ||
| 37 | typedef struct { | ||
| 38 | uint16_t name; | ||
| 39 | uint16_t type; | ||
| 40 | uint16_t class; | ||
| 41 | uint32_t ttl; | ||
| 42 | uint16_t len; | ||
| 43 | uint32_t addr; | ||
| 44 | } dns_answer_t; | ||
| 45 | #pragma pack(pop) | ||
| 46 | |||
| 47 | typedef struct { | ||
| 48 | uint32_t ip; | ||
| 49 | } auth_entry_t; | ||
| 50 | |||
| 51 | static auth_entry_t s_auth_list[MAX_AUTH_IPS]; | ||
| 52 | static int s_auth_count = 0; | ||
| 53 | static TaskHandle_t s_dns_task = NULL; | ||
| 54 | static TaskHandle_t s_dot_task = NULL; | ||
| 55 | static volatile bool s_dns_running = false; | ||
| 56 | static esp_ip4_addr_t s_ap_ip; | ||
| 57 | static esp_ip4_addr_t s_upstream_dns; | ||
| 58 | |||
| 59 | static bool is_authenticated(uint32_t ip) | ||
| 60 | { | ||
| 61 | for (int i = 0; i < s_auth_count; i++) { | ||
| 62 | if (s_auth_list[i].ip == ip) return true; | ||
| 63 | } | ||
| 64 | return false; | ||
| 65 | } | ||
| 66 | |||
| 67 | static void parse_dns_name(const uint8_t *buf, int buf_len, int offset, char *out, int out_len) | ||
| 68 | { | ||
| 69 | int pos = offset; | ||
| 70 | int out_pos = 0; | ||
| 71 | int jumped = 0; | ||
| 72 | int jump_pos = 0; | ||
| 73 | while (pos < buf_len && out_pos < out_len - 1) { | ||
| 74 | uint8_t len = buf[pos]; | ||
| 75 | if (len == 0) break; | ||
| 76 | if ((len & 0xC0) == 0xC0) { | ||
| 77 | if (!jumped) jump_pos = pos + 2; | ||
| 78 | pos = ((len & 0x3F) << 8) | buf[pos + 1]; | ||
| 79 | jumped = 1; | ||
| 80 | continue; | ||
| 81 | } | ||
| 82 | if (out_pos > 0 && out_pos < out_len - 1) out[out_pos++] = '.'; | ||
| 83 | pos++; | ||
| 84 | for (int i = 0; i < len && pos < buf_len && out_pos < out_len - 1; i++) { | ||
| 85 | out[out_pos++] = buf[pos++]; | ||
| 86 | } | ||
| 87 | } | ||
| 88 | out[out_pos] = '\0'; | ||
| 89 | } | ||
| 90 | |||
| 91 | static int build_nxdomain(uint8_t *response, int req_len) | ||
| 92 | { | ||
| 93 | dns_header_t *hdr = (dns_header_t *)response; | ||
| 94 | hdr->flags = htons(0x8403); | ||
| 95 | hdr->ancount = 0; | ||
| 96 | hdr->nscount = 0; | ||
| 97 | hdr->arcount = 0; | ||
| 98 | return req_len; | ||
| 99 | } | ||
| 100 | |||
| 101 | static int build_redirect_response(uint8_t *response, int req_len) | ||
| 102 | { | ||
| 103 | memmove(response, response, req_len); | ||
| 104 | dns_header_t *hdr = (dns_header_t *)response; | ||
| 105 | hdr->flags = htons(0x8180); | ||
| 106 | hdr->ancount = htons(1); | ||
| 107 | hdr->nscount = 0; | ||
| 108 | hdr->arcount = 0; | ||
| 109 | int resp_len = req_len; | ||
| 110 | dns_answer_t ans; | ||
| 111 | ans.name = htons(0xC00C); | ||
| 112 | ans.type = htons(1); | ||
| 113 | ans.class = htons(1); | ||
| 114 | ans.ttl = htonl(HIJACK_TTL); | ||
| 115 | ans.len = htons(4); | ||
| 116 | ans.addr = s_ap_ip.addr; | ||
| 117 | memcpy(response + resp_len, &ans, sizeof(ans)); | ||
| 118 | resp_len += sizeof(ans); | ||
| 119 | return resp_len; | ||
| 120 | } | ||
| 121 | |||
| 122 | static int forward_dns(const uint8_t *req, int req_len, uint8_t *resp, int resp_buf_len, | ||
| 123 | const struct sockaddr_in *client_addr, uint16_t txn_id) | ||
| 124 | { | ||
| 125 | int upstream_sock = socket(AF_INET, SOCK_DGRAM, 0); | ||
| 126 | if (upstream_sock < 0) return -1; | ||
| 127 | |||
| 128 | struct timeval tv = { .tv_sec = DNS_FORWARD_TIMEOUT_MS / 1000, .tv_usec = (DNS_FORWARD_TIMEOUT_MS % 1000) * 1000 }; | ||
| 129 | setsockopt(upstream_sock, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv)); | ||
| 130 | |||
| 131 | struct sockaddr_in upstream_addr = { | ||
| 132 | .sin_family = AF_INET, | ||
| 133 | .sin_port = htons(DNS_PORT), | ||
| 134 | .sin_addr.s_addr = s_upstream_dns.addr, | ||
| 135 | }; | ||
| 136 | |||
| 137 | sendto(upstream_sock, req, req_len, 0, (struct sockaddr *)&upstream_addr, sizeof(upstream_addr)); | ||
| 138 | |||
| 139 | int n = recvfrom(upstream_sock, resp, resp_buf_len, 0, NULL, NULL); | ||
| 140 | close(upstream_sock); | ||
| 141 | |||
| 142 | if (n > 0) { | ||
| 143 | if (n >= sizeof(dns_header_t)) { | ||
| 144 | dns_header_t *hdr = (dns_header_t *)resp; | ||
| 145 | hdr->id = htons(txn_id); | ||
| 146 | } | ||
| 147 | } | ||
| 148 | return n; | ||
| 149 | } | ||
| 150 | |||
| 151 | static void dns_server_task(void *arg) | ||
| 152 | { | ||
| 153 | int sock = socket(AF_INET, SOCK_DGRAM, 0); | ||
| 154 | if (sock < 0) { | ||
| 155 | ESP_LOGE(TAG, "Failed to create DNS socket"); | ||
| 156 | s_dns_running = false; | ||
| 157 | vTaskDelete(NULL); | ||
| 158 | return; | ||
| 159 | } | ||
| 160 | |||
| 161 | struct sockaddr_in bind_addr = { | ||
| 162 | .sin_family = AF_INET, | ||
| 163 | .sin_port = htons(DNS_PORT), | ||
| 164 | .sin_addr.s_addr = s_ap_ip.addr, | ||
| 165 | }; | ||
| 166 | if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { | ||
| 167 | ESP_LOGE(TAG, "Failed to bind DNS socket"); | ||
| 168 | close(sock); | ||
| 169 | s_dns_running = false; | ||
| 170 | vTaskDelete(NULL); | ||
| 171 | return; | ||
| 172 | } | ||
| 173 | |||
| 174 | ESP_LOGI(TAG, "DNS server started on port %d, AP IP=" IPSTR ", upstream DNS=" IPSTR, | ||
| 175 | DNS_PORT, IP2STR(&s_ap_ip), IP2STR(&s_upstream_dns)); | ||
| 176 | |||
| 177 | uint8_t rx_buf[DNS_BUF_SIZE]; | ||
| 178 | uint8_t tx_buf[DNS_BUF_SIZE + sizeof(dns_answer_t)]; | ||
| 179 | |||
| 180 | while (s_dns_running) { | ||
| 181 | struct sockaddr_in client_addr; | ||
| 182 | socklen_t client_len = sizeof(client_addr); | ||
| 183 | int n = recvfrom(sock, rx_buf, sizeof(rx_buf), 0, | ||
| 184 | (struct sockaddr *)&client_addr, &client_len); | ||
| 185 | if (n < (int)sizeof(dns_header_t)) continue; | ||
| 186 | |||
| 187 | uint32_t client_ip = client_addr.sin_addr.s_addr; | ||
| 188 | dns_header_t *hdr = (dns_header_t *)rx_buf; | ||
| 189 | uint16_t txn_id = ntohs(hdr->id); | ||
| 190 | bool is_query = (ntohs(hdr->flags) & 0x8000) == 0; | ||
| 191 | uint16_t qdcount = ntohs(hdr->qdcount); | ||
| 192 | |||
| 193 | if (!is_query || qdcount == 0) continue; | ||
| 194 | |||
| 195 | int q_offset = sizeof(dns_header_t); | ||
| 196 | while (q_offset < n && rx_buf[q_offset] != 0) { | ||
| 197 | q_offset += rx_buf[q_offset] + 1; | ||
| 198 | } | ||
| 199 | if (q_offset + 5 > n) continue; | ||
| 200 | uint16_t qtype = (rx_buf[q_offset + 1] << 8) | rx_buf[q_offset + 2]; | ||
| 201 | int req_len = q_offset + 5; | ||
| 202 | |||
| 203 | if (is_authenticated(client_ip)) { | ||
| 204 | int resp_len = forward_dns(rx_buf, req_len, tx_buf, sizeof(tx_buf), &client_addr, txn_id); | ||
| 205 | if (resp_len > 0) { | ||
| 206 | sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len); | ||
| 207 | } | ||
| 208 | } else { | ||
| 209 | char qname[256] = {0}; | ||
| 210 | parse_dns_name(rx_buf, n, sizeof(dns_header_t), qname, sizeof(qname)); | ||
| 211 | ESP_LOGI(TAG, "Hijack DNS from " IPSTR ": %s (type=%d)", IP2STR(&(esp_ip4_addr_t){.addr=client_ip}), qname, qtype); | ||
| 212 | if (qtype == 1) { | ||
| 213 | int resp_len = build_redirect_response(rx_buf, req_len); | ||
| 214 | memcpy(tx_buf, rx_buf, resp_len); | ||
| 215 | dns_header_t *resp_hdr = (dns_header_t *)tx_buf; | ||
| 216 | resp_hdr->id = htons(txn_id); | ||
| 217 | sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len); | ||
| 218 | } else { | ||
| 219 | int resp_len = build_nxdomain(rx_buf, req_len); | ||
| 220 | memcpy(tx_buf, rx_buf, resp_len); | ||
| 221 | dns_header_t *resp_hdr = (dns_header_t *)tx_buf; | ||
| 222 | resp_hdr->id = htons(txn_id); | ||
| 223 | sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len); | ||
| 224 | } | ||
| 225 | } | ||
| 226 | } | ||
| 227 | |||
| 228 | close(sock); | ||
| 229 | ESP_LOGI(TAG, "DNS server stopped"); | ||
| 230 | vTaskDelete(NULL); | ||
| 231 | } | ||
| 232 | |||
| 233 | static void dot_reject_task(void *arg) | ||
| 234 | { | ||
| 235 | int sock = socket(AF_INET, SOCK_STREAM, 0); | ||
| 236 | if (sock < 0) { | ||
| 237 | ESP_LOGE(TAG, "Failed to create DoT reject socket"); | ||
| 238 | vTaskDelete(NULL); | ||
| 239 | return; | ||
| 240 | } | ||
| 241 | |||
| 242 | int opt = 1; | ||
| 243 | setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &opt, sizeof(opt)); | ||
| 244 | |||
| 245 | struct sockaddr_in bind_addr = { | ||
| 246 | .sin_family = AF_INET, | ||
| 247 | .sin_port = htons(DOT_PORT), | ||
| 248 | .sin_addr.s_addr = INADDR_ANY, | ||
| 249 | }; | ||
| 250 | if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { | ||
| 251 | ESP_LOGE(TAG, "Failed to bind DoT reject socket on port %d", DOT_PORT); | ||
| 252 | close(sock); | ||
| 253 | vTaskDelete(NULL); | ||
| 254 | return; | ||
| 255 | } | ||
| 256 | |||
| 257 | listen(sock, 1); | ||
| 258 | ESP_LOGI(TAG, "DoT reject server on port %d (forces DNS fallback to port 53)", DOT_PORT); | ||
| 259 | |||
| 260 | while (s_dns_running) { | ||
| 261 | struct sockaddr_in client_addr; | ||
| 262 | socklen_t client_len = sizeof(client_addr); | ||
| 263 | int client_sock = accept(sock, (struct sockaddr *)&client_addr, &client_len); | ||
| 264 | if (client_sock >= 0) { | ||
| 265 | struct linger ling = { .l_onoff = 1, .l_linger = 0 }; | ||
| 266 | setsockopt(client_sock, SOL_SOCKET, SO_LINGER, &ling, sizeof(ling)); | ||
| 267 | close(client_sock); | ||
| 268 | } | ||
| 269 | } | ||
| 270 | |||
| 271 | close(sock); | ||
| 272 | ESP_LOGI(TAG, "DoT reject server stopped"); | ||
| 273 | vTaskDelete(NULL); | ||
| 274 | } | ||
| 275 | 3 | ||
| 276 | esp_err_t dns_server_start(esp_ip4_addr_t ap_ip, esp_ip4_addr_t upstream_dns) | 4 | esp_err_t dns_server_start(esp_ip4_addr_t ap_ip, esp_ip4_addr_t upstream_dns) |
| 277 | { | 5 | { |
| 278 | if (s_dns_running) return ESP_OK; | 6 | return tollgate_core_dns_start_internal(ap_ip, upstream_dns); |
| 279 | s_ap_ip = ap_ip; | ||
| 280 | s_upstream_dns = upstream_dns; | ||
| 281 | s_dns_running = true; | ||
| 282 | xTaskCreate(dns_server_task, "dns_server", DNS_TASK_STACK, NULL, DNS_TASK_PRIO, &s_dns_task); | ||
| 283 | xTaskCreate(dot_reject_task, "dot_reject", DOT_TASK_STACK, NULL, DOT_TASK_PRIO, &s_dot_task); | ||
| 284 | return ESP_OK; | ||
| 285 | } | 7 | } |
| 286 | 8 | ||
| 287 | void dns_server_stop(void) | 9 | void dns_server_stop(void) |
| 288 | { | 10 | { |
| 289 | s_dns_running = false; | 11 | tollgate_core_dns_stop(); |
| 290 | vTaskDelay(pdMS_TO_TICKS(200)); | ||
| 291 | s_dns_task = NULL; | ||
| 292 | } | 12 | } |
| 293 | 13 | ||
| 294 | void dns_server_set_client_authenticated(uint32_t client_ip, bool authenticated) | 14 | void dns_server_set_client_authenticated(uint32_t client_ip, bool authenticated) |
| 295 | { | 15 | { |
| 296 | if (authenticated) { | 16 | tollgate_core_dns_set_authenticated(client_ip, authenticated); |
| 297 | if (is_authenticated(client_ip)) return; | ||
| 298 | if (s_auth_count < MAX_AUTH_IPS) { | ||
| 299 | s_auth_list[s_auth_count].ip = client_ip; | ||
| 300 | s_auth_count++; | ||
| 301 | } | ||
| 302 | } else { | ||
| 303 | for (int i = 0; i < s_auth_count; i++) { | ||
| 304 | if (s_auth_list[i].ip == client_ip) { | ||
| 305 | s_auth_list[i] = s_auth_list[s_auth_count - 1]; | ||
| 306 | s_auth_count--; | ||
| 307 | return; | ||
| 308 | } | ||
| 309 | } | ||
| 310 | } | ||
| 311 | } | 17 | } |
| 312 | 18 | ||
| 313 | bool dns_server_is_running(void) | 19 | bool dns_server_is_running(void) |
| 314 | { | 20 | { |
| 315 | return s_dns_running; | 21 | return tollgate_core_dns_is_running(); |
| 316 | } | 22 | } |
diff --git a/main/firewall.c b/main/firewall.c index 077d16c..5ffdee0 100644 --- a/main/firewall.c +++ b/main/firewall.c | |||
| @@ -1,36 +1,28 @@ | |||
| 1 | #include "firewall.h" | 1 | #include "firewall.h" |
| 2 | #include "dns_server.h" | ||
| 3 | #include "tollgate_core.h" | 2 | #include "tollgate_core.h" |
| 4 | #include "tollgate_core_firewall.h" | 3 | #include "tollgate_core_firewall.h" |
| 5 | #include "esp_log.h" | 4 | #include "esp_log.h" |
| 6 | #include "lwip/netif.h" | ||
| 7 | #include "lwip/lwip_napt.h" | ||
| 8 | #include "lwip/prot/ip4.h" | 5 | #include "lwip/prot/ip4.h" |
| 9 | #include "lwip/prot/tcp.h" | ||
| 10 | #include "lwip/prot/ip.h" | ||
| 11 | #include <string.h> | 6 | #include <string.h> |
| 12 | 7 | ||
| 13 | static const char *TAG = "firewall"; | 8 | static const char *TAG = "firewall"; |
| 14 | static esp_ip4_addr_t s_ap_ip; | 9 | static esp_ip4_addr_t s_ap_ip; |
| 15 | static uint16_t s_mining_port = 3333; | ||
| 16 | static bool s_sandbox_mint_access = false; | ||
| 17 | 10 | ||
| 18 | esp_err_t firewall_init(esp_ip4_addr_t ap_ip) | 11 | esp_err_t firewall_init(esp_ip4_addr_t ap_ip) |
| 19 | { | 12 | { |
| 20 | s_ap_ip = ap_ip; | 13 | s_ap_ip = ap_ip; |
| 21 | ip_napt_enable(s_ap_ip.addr, 1); | 14 | ESP_LOGI(TAG, "Firewall initialized with AP IP=" IPSTR, IP2STR(&s_ap_ip)); |
| 22 | ESP_LOGI(TAG, "Firewall initialized with AP IP=" IPSTR " (NAT always on, per-client filter)", IP2STR(&s_ap_ip)); | ||
| 23 | return ESP_OK; | 15 | return ESP_OK; |
| 24 | } | 16 | } |
| 25 | 17 | ||
| 26 | void firewall_set_mining_port(uint16_t port) | 18 | void firewall_set_mining_port(uint16_t port) |
| 27 | { | 19 | { |
| 28 | s_mining_port = port; | 20 | tollgate_core_fw_set_sandbox_ports(port); |
| 29 | } | 21 | } |
| 30 | 22 | ||
| 31 | void firewall_set_sandbox_mint_access(bool enabled) | 23 | void firewall_set_sandbox_mint_access(bool enabled) |
| 32 | { | 24 | { |
| 33 | s_sandbox_mint_access = enabled; | 25 | tollgate_core_fw_set_sandbox_mint_access(enabled); |
| 34 | } | 26 | } |
| 35 | 27 | ||
| 36 | esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_out_size) | 28 | esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_out_size) |
| @@ -38,80 +30,24 @@ esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_ | |||
| 38 | return tollgate_core_fw_get_mac_for_ip(client_ip, mac_out, mac_out_size); | 30 | return tollgate_core_fw_get_mac_for_ip(client_ip, mac_out, mac_out_size); |
| 39 | } | 31 | } |
| 40 | 32 | ||
| 41 | static bool is_sandbox_allowed(struct pbuf *p) | ||
| 42 | { | ||
| 43 | if (p->len < IP_HLEN) return false; | ||
| 44 | struct ip_hdr *iphdr = (struct ip_hdr *)p->payload; | ||
| 45 | uint32_t dest_ip_h = lwip_ntohl(iphdr->dest.addr); | ||
| 46 | uint32_t ap_ip_h = lwip_ntohl(s_ap_ip.addr); | ||
| 47 | |||
| 48 | if (dest_ip_h == ap_ip_h) { | ||
| 49 | if (iphdr->_proto == IP_PROTO_TCP) { | ||
| 50 | uint16_t dst_port = 0; | ||
| 51 | if (p->len >= IP_HLEN + TCP_HLEN) { | ||
| 52 | struct tcp_hdr *tcphdr = (struct tcp_hdr *)((uint8_t *)p->payload + IP_HLEN); | ||
| 53 | dst_port = lwip_ntohs(tcphdr->dest); | ||
| 54 | } | ||
| 55 | if (dst_port == 80 || dst_port == 2121 || dst_port == s_mining_port) { | ||
| 56 | return true; | ||
| 57 | } | ||
| 58 | } | ||
| 59 | if (iphdr->_proto == IP_PROTO_UDP) { | ||
| 60 | return true; | ||
| 61 | } | ||
| 62 | } | ||
| 63 | |||
| 64 | if (s_sandbox_mint_access && iphdr->_proto == IP_PROTO_TCP) { | ||
| 65 | return true; | ||
| 66 | } | ||
| 67 | |||
| 68 | return false; | ||
| 69 | } | ||
| 70 | |||
| 71 | int tollgate_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) | 33 | int tollgate_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) |
| 72 | { | 34 | { |
| 73 | (void)dest_addr_hostorder; | 35 | return tollgate_core_ip4_canforward_filter(p, dest_addr_hostorder); |
| 74 | if (p->len < IP_HLEN) return -1; | ||
| 75 | struct ip_hdr *iphdr = (struct ip_hdr *)p->payload; | ||
| 76 | uint32_t src_ip_h = lwip_ntohl(iphdr->src.addr); | ||
| 77 | uint32_t ap_subnet = lwip_ntohl(s_ap_ip.addr) & 0xFFFFFF00; | ||
| 78 | if ((src_ip_h & 0xFFFFFF00) != ap_subnet) { | ||
| 79 | return 1; | ||
| 80 | } | ||
| 81 | if (firewall_is_client_allowed(iphdr->src.addr)) { | ||
| 82 | return 1; | ||
| 83 | } | ||
| 84 | if (is_sandbox_allowed(p)) { | ||
| 85 | return 1; | ||
| 86 | } | ||
| 87 | return 0; | ||
| 88 | } | 36 | } |
| 89 | 37 | ||
| 90 | void firewall_grant_access(uint32_t client_ip) | 38 | void firewall_grant_access(uint32_t client_ip) |
| 91 | { | 39 | { |
| 92 | tollgate_core_fw_grant(client_ip); | 40 | tollgate_core_fw_grant(client_ip); |
| 93 | dns_server_set_client_authenticated(client_ip, true); | ||
| 94 | |||
| 95 | char mac[18] = {0}; | ||
| 96 | tollgate_core_fw_get_mac_for_ip(client_ip, mac, sizeof(mac)); | ||
| 97 | esp_ip4_addr_t ip_addr = { .addr = client_ip }; | ||
| 98 | ESP_LOGI(TAG, "Access granted to " IPSTR " mac=%s", IP2STR(&ip_addr), | ||
| 99 | mac[0] ? mac : "unknown"); | ||
| 100 | } | 41 | } |
| 101 | 42 | ||
| 102 | void firewall_revoke_access(uint32_t client_ip) | 43 | void firewall_revoke_access(uint32_t client_ip) |
| 103 | { | 44 | { |
| 104 | tollgate_core_fw_revoke(client_ip); | 45 | tollgate_core_fw_revoke(client_ip); |
| 105 | dns_server_set_client_authenticated(client_ip, false); | ||
| 106 | |||
| 107 | esp_ip4_addr_t ip_addr = { .addr = client_ip }; | ||
| 108 | ESP_LOGI(TAG, "Access revoked for " IPSTR, IP2STR(&ip_addr)); | ||
| 109 | } | 46 | } |
| 110 | 47 | ||
| 111 | void firewall_revoke_all(void) | 48 | void firewall_revoke_all(void) |
| 112 | { | 49 | { |
| 113 | tollgate_core_fw_revoke_all(); | 50 | tollgate_core_fw_revoke_all(); |
| 114 | ESP_LOGI(TAG, "All client access revoked"); | ||
| 115 | } | 51 | } |
| 116 | 52 | ||
| 117 | bool firewall_is_client_allowed(uint32_t client_ip) | 53 | bool firewall_is_client_allowed(uint32_t client_ip) |
diff --git a/main/stratum_proxy.c b/main/stratum_proxy.c index 288c633..53909f0 100644 --- a/main/stratum_proxy.c +++ b/main/stratum_proxy.c | |||
| @@ -1,160 +1,31 @@ | |||
| 1 | #include "stratum_proxy.h" | 1 | #include "stratum_proxy.h" |
| 2 | #include "mining_payment.h" | 2 | #include "tollgate_core_stratum_proxy.h" |
| 3 | #include "esp_log.h" | ||
| 4 | #include "lwip/sockets.h" | ||
| 5 | #include "freertos/FreeRTOS.h" | ||
| 6 | #include "freertos/task.h" | ||
| 7 | #include <string.h> | 3 | #include <string.h> |
| 8 | 4 | ||
| 9 | static const char *TAG = "stratum_proxy"; | 5 | _Static_assert(sizeof(stratum_job_t) == sizeof(tollgate_stratum_job_t), "job struct size mismatch"); |
| 10 | static uint16_t s_port = 3333; | 6 | _Static_assert(sizeof(stratum_proxy_stats_t) == sizeof(tollgate_stratum_proxy_stats_t), "stats struct size mismatch"); |
| 11 | static bool s_running = false; | ||
| 12 | static TaskHandle_t s_task_handle = NULL; | ||
| 13 | static int s_server_fd = -1; | ||
| 14 | |||
| 15 | static stratum_job_t s_current_job = {0}; | ||
| 16 | static stratum_proxy_stats_t s_stats = {0}; | ||
| 17 | |||
| 18 | static void proxy_client_handler(void *arg) | ||
| 19 | { | ||
| 20 | int client_fd = (int)(intptr_t)arg; | ||
| 21 | struct sockaddr_in client_addr; | ||
| 22 | socklen_t addr_len = sizeof(client_addr); | ||
| 23 | getpeername(client_fd, (struct sockaddr *)&client_addr, &addr_len); | ||
| 24 | uint32_t client_ip = client_addr.sin_addr.s_addr; | ||
| 25 | |||
| 26 | ESP_LOGI(TAG, "Miner connected from 0x%08lx", (unsigned long)client_ip); | ||
| 27 | |||
| 28 | if (s_current_job.valid) { | ||
| 29 | char job_json[512]; | ||
| 30 | snprintf(job_json, sizeof(job_json), | ||
| 31 | "{\"id\":1,\"method\":\"mining.notify\",\"params\":[\"%lu\",\"%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx\",\"\",\"\",\"\",\"%08lx\",\"%08lx\",\"%08lx\",true]}\n", | ||
| 32 | (unsigned long)s_current_job.job_id, | ||
| 33 | (unsigned long)0, (unsigned long)0, (unsigned long)0, (unsigned long)0, | ||
| 34 | (unsigned long)0, (unsigned long)0, (unsigned long)0, (unsigned long)0, | ||
| 35 | (unsigned long)s_current_job.nbits, (unsigned long)s_current_job.ntime, | ||
| 36 | (unsigned long)s_current_job.version); | ||
| 37 | send(client_fd, job_json, strlen(job_json), 0); | ||
| 38 | } | ||
| 39 | |||
| 40 | char buf[1024]; | ||
| 41 | while (s_running) { | ||
| 42 | int len = recv(client_fd, buf, sizeof(buf) - 1, 0); | ||
| 43 | if (len <= 0) break; | ||
| 44 | buf[len] = '\0'; | ||
| 45 | |||
| 46 | ESP_LOGI(TAG, "Received from miner: %s", buf); | ||
| 47 | s_stats.total_shares++; | ||
| 48 | s_stats.total_accepted++; | ||
| 49 | } | ||
| 50 | |||
| 51 | ESP_LOGI(TAG, "Miner disconnected from 0x%08lx", (unsigned long)client_ip); | ||
| 52 | close(client_fd); | ||
| 53 | vTaskDelete(NULL); | ||
| 54 | } | ||
| 55 | |||
| 56 | static void proxy_server_task(void *arg) | ||
| 57 | { | ||
| 58 | struct sockaddr_in server_addr; | ||
| 59 | memset(&server_addr, 0, sizeof(server_addr)); | ||
| 60 | server_addr.sin_family = AF_INET; | ||
| 61 | server_addr.sin_addr.s_addr = INADDR_ANY; | ||
| 62 | server_addr.sin_port = htons(s_port); | ||
| 63 | |||
| 64 | s_server_fd = socket(AF_INET, SOCK_STREAM, 0); | ||
| 65 | if (s_server_fd < 0) { | ||
| 66 | ESP_LOGE(TAG, "Failed to create socket"); | ||
| 67 | vTaskDelete(NULL); | ||
| 68 | return; | ||
| 69 | } | ||
| 70 | |||
| 71 | int opt = 1; | ||
| 72 | setsockopt(s_server_fd, SOL_SOCKET, SO_REUSEADDR, &opt, sizeof(opt)); | ||
| 73 | |||
| 74 | if (bind(s_server_fd, (struct sockaddr *)&server_addr, sizeof(server_addr)) != 0) { | ||
| 75 | ESP_LOGE(TAG, "Failed to bind to port %u", (unsigned)s_port); | ||
| 76 | close(s_server_fd); | ||
| 77 | s_server_fd = -1; | ||
| 78 | vTaskDelete(NULL); | ||
| 79 | return; | ||
| 80 | } | ||
| 81 | |||
| 82 | if (listen(s_server_fd, 5) != 0) { | ||
| 83 | ESP_LOGE(TAG, "Failed to listen"); | ||
| 84 | close(s_server_fd); | ||
| 85 | s_server_fd = -1; | ||
| 86 | vTaskDelete(NULL); | ||
| 87 | return; | ||
| 88 | } | ||
| 89 | |||
| 90 | ESP_LOGI(TAG, "Stratum proxy listening on port %u", (unsigned)s_port); | ||
| 91 | |||
| 92 | while (s_running) { | ||
| 93 | struct sockaddr_in client_addr; | ||
| 94 | socklen_t client_len = sizeof(client_addr); | ||
| 95 | int client_fd = accept(s_server_fd, (struct sockaddr *)&client_addr, &client_len); | ||
| 96 | if (client_fd < 0) continue; | ||
| 97 | |||
| 98 | s_stats.active_miners++; | ||
| 99 | char task_name[20]; | ||
| 100 | snprintf(task_name, sizeof(task_name), "miner_%d", client_fd); | ||
| 101 | xTaskCreate(proxy_client_handler, task_name, 4096, (void *)(intptr_t)client_fd, 3, NULL); | ||
| 102 | } | ||
| 103 | |||
| 104 | close(s_server_fd); | ||
| 105 | s_server_fd = -1; | ||
| 106 | vTaskDelete(NULL); | ||
| 107 | } | ||
| 108 | 7 | ||
| 109 | esp_err_t stratum_proxy_init(uint16_t port) | 8 | esp_err_t stratum_proxy_init(uint16_t port) |
| 110 | { | 9 | { |
| 111 | s_port = port; | 10 | return tollgate_core_stratum_proxy_init(port); |
| 112 | memset(&s_current_job, 0, sizeof(s_current_job)); | ||
| 113 | memset(&s_stats, 0, sizeof(s_stats)); | ||
| 114 | s_running = true; | ||
| 115 | |||
| 116 | BaseType_t ret = xTaskCreate(proxy_server_task, "stratum_proxy", 4096, NULL, 4, &s_task_handle); | ||
| 117 | if (ret != pdPASS) { | ||
| 118 | ESP_LOGE(TAG, "Failed to create proxy task"); | ||
| 119 | s_running = false; | ||
| 120 | return ESP_FAIL; | ||
| 121 | } | ||
| 122 | |||
| 123 | ESP_LOGI(TAG, "Stratum proxy initialized on port %u", (unsigned)port); | ||
| 124 | return ESP_OK; | ||
| 125 | } | 11 | } |
| 126 | 12 | ||
| 127 | void stratum_proxy_set_job(const stratum_job_t *job) | 13 | void stratum_proxy_set_job(const stratum_job_t *job) |
| 128 | { | 14 | { |
| 129 | if (job) { | 15 | tollgate_core_stratum_proxy_set_job((const tollgate_stratum_job_t *)job); |
| 130 | memcpy(&s_current_job, job, sizeof(stratum_job_t)); | ||
| 131 | s_stats.nbits = job->nbits; | ||
| 132 | s_stats.current_hashprice = mining_get_current_hashprice(); | ||
| 133 | } | ||
| 134 | } | 16 | } |
| 135 | 17 | ||
| 136 | const stratum_job_t *stratum_proxy_get_current_job(void) | 18 | const stratum_job_t *stratum_proxy_get_current_job(void) |
| 137 | { | 19 | { |
| 138 | return &s_current_job; | 20 | return (const stratum_job_t *)tollgate_core_stratum_proxy_get_current_job(); |
| 139 | } | 21 | } |
| 140 | 22 | ||
| 141 | void stratum_proxy_get_stats(stratum_proxy_stats_t *stats) | 23 | void stratum_proxy_get_stats(stratum_proxy_stats_t *stats) |
| 142 | { | 24 | { |
| 143 | if (stats) { | 25 | tollgate_core_stratum_proxy_get_stats((tollgate_stratum_proxy_stats_t *)stats); |
| 144 | *stats = s_stats; | ||
| 145 | stats->current_hashprice = mining_get_current_hashprice(); | ||
| 146 | } | ||
| 147 | } | 26 | } |
| 148 | 27 | ||
| 149 | void stratum_proxy_stop(void) | 28 | void stratum_proxy_stop(void) |
| 150 | { | 29 | { |
| 151 | s_running = false; | 30 | tollgate_core_stratum_proxy_stop(); |
| 152 | if (s_server_fd >= 0) { | ||
| 153 | close(s_server_fd); | ||
| 154 | s_server_fd = -1; | ||
| 155 | } | ||
| 156 | if (s_task_handle) { | ||
| 157 | vTaskDelay(pdMS_TO_TICKS(500)); | ||
| 158 | s_task_handle = NULL; | ||
| 159 | } | ||
| 160 | } | 31 | } |
diff --git a/tests/unit/test_firewall_sandbox b/tests/unit/test_firewall_sandbox index 3e2895b..7e5aa6d 100755 --- a/tests/unit/test_firewall_sandbox +++ b/tests/unit/test_firewall_sandbox | |||
| Binary files differ | |||
diff --git a/tests/unit/test_mining_payment b/tests/unit/test_mining_payment index d38bf9d..dd4e781 100755 --- a/tests/unit/test_mining_payment +++ b/tests/unit/test_mining_payment | |||
| Binary files differ | |||
diff --git a/tests/unit/test_session_payment_method b/tests/unit/test_session_payment_method index 950a72f..44cafd3 100755 --- a/tests/unit/test_session_payment_method +++ b/tests/unit/test_session_payment_method | |||
| Binary files differ | |||
diff --git a/tests/unit/test_stratum_proxy b/tests/unit/test_stratum_proxy index 963df67..542d82f 100755 --- a/tests/unit/test_stratum_proxy +++ b/tests/unit/test_stratum_proxy | |||
| Binary files differ | |||
diff --git a/tollgate_core/CMakeLists.txt b/tollgate_core/CMakeLists.txt deleted file mode 100644 index 988167f..0000000 --- a/tollgate_core/CMakeLists.txt +++ /dev/null | |||
| @@ -1,28 +0,0 @@ | |||
| 1 | cmake_minimum_required(VERSION 3.16) | ||
| 2 | project(tollgate_core C) | ||
| 3 | |||
| 4 | set(TG_CORE_SOURCES | ||
| 5 | src/tollgate_core.c | ||
| 6 | src/tollgate_cashu.c | ||
| 7 | src/tollgate_session.c | ||
| 8 | src/tollgate_mining.c | ||
| 9 | ) | ||
| 10 | |||
| 11 | add_library(tollgate_core STATIC ${TG_CORE_SOURCES}) | ||
| 12 | |||
| 13 | target_include_directories(tollgate_core PUBLIC | ||
| 14 | ${CMAKE_CURRENT_SOURCE_DIR}/include | ||
| 15 | ${CMAKE_CURRENT_SOURCE_DIR}/src | ||
| 16 | ) | ||
| 17 | |||
| 18 | find_package(PkgConfig REQUIRED) | ||
| 19 | pkg_check_modules(CJSON REQUIRED libcjson) | ||
| 20 | |||
| 21 | target_include_directories(tollgate_core PRIVATE | ||
| 22 | ${CJSON_INCLUDE_DIRS} | ||
| 23 | /usr/include | ||
| 24 | ) | ||
| 25 | |||
| 26 | target_link_libraries(tollgate_core PUBLIC mbedcrypto cjson m) | ||
| 27 | |||
| 28 | target_compile_options(tollgate_core PRIVATE -Wall -Wextra -Wno-unused-parameter) | ||
diff --git a/tollgate_core/include/tollgate_core.h b/tollgate_core/include/tollgate_core.h deleted file mode 100644 index bbae7cf..0000000 --- a/tollgate_core/include/tollgate_core.h +++ /dev/null | |||
| @@ -1,90 +0,0 @@ | |||
| 1 | #ifndef TOLLGATE_CORE_H | ||
| 2 | #define TOLLGATE_CORE_H | ||
| 3 | |||
| 4 | #include "tollgate_platform.h" | ||
| 5 | #include <stdbool.h> | ||
| 6 | #include <stdint.h> | ||
| 7 | |||
| 8 | int tollgate_core_init(const tollgate_platform_t *platform, uint32_t ap_ip); | ||
| 9 | void tollgate_core_tick(void); | ||
| 10 | |||
| 11 | int tollgate_core_dns_start(uint32_t upstream_dns); | ||
| 12 | void tollgate_core_dns_stop(void); | ||
| 13 | |||
| 14 | int tollgate_core_process_payment(uint32_t client_ip, const char *token_str); | ||
| 15 | int tollgate_core_process_share(uint32_t client_ip, const char *job_id, | ||
| 16 | const char *nonce, const char *ntime, const char *version); | ||
| 17 | |||
| 18 | void tollgate_core_client_connected(const uint8_t *mac, uint32_t client_ip); | ||
| 19 | void tollgate_core_client_disconnected(const uint8_t *mac); | ||
| 20 | |||
| 21 | bool tollgate_core_is_client_allowed(uint32_t client_ip); | ||
| 22 | bool tollgate_core_is_dns_running(void); | ||
| 23 | |||
| 24 | char *tollgate_core_get_status_json(void); | ||
| 25 | char *tollgate_core_get_config_json(void); | ||
| 26 | |||
| 27 | int tollgate_core_active_session_count(void); | ||
| 28 | int tollgate_core_allowed_client_count(void); | ||
| 29 | int tollgate_core_firewall_revoke_all(void); | ||
| 30 | void tollgate_core_firewall_set_mining_port(uint16_t port); | ||
| 31 | void tollgate_core_firewall_set_sandbox_mint_access(bool enable); | ||
| 32 | |||
| 33 | bool tollgate_core_is_owner(uint32_t client_ip); | ||
| 34 | bool tollgate_core_is_owner_connected(void); | ||
| 35 | |||
| 36 | double tollgate_core_get_hashprice(void); | ||
| 37 | void tollgate_core_set_nbits(uint32_t nbits); | ||
| 38 | const void *tollgate_core_get_current_job(void); | ||
| 39 | void tollgate_core_set_job(const void *job); | ||
| 40 | |||
| 41 | int tollgate_core_stratum_client_start(void); | ||
| 42 | void tollgate_core_stratum_client_stop(void); | ||
| 43 | |||
| 44 | int tollgate_core_stratum_proxy_init(uint16_t port); | ||
| 45 | void tollgate_core_stratum_proxy_get_stats(void *out); | ||
| 46 | |||
| 47 | void tollgate_core_mining_init(void); | ||
| 48 | |||
| 49 | void tollgate_core_beacon_start(void); | ||
| 50 | |||
| 51 | void tollgate_core_market_init(void); | ||
| 52 | void tollgate_core_market_on_scan_result(const void *ie_data, int ie_len, | ||
| 53 | const uint8_t *bssid, int rssi); | ||
| 54 | |||
| 55 | const void *tollgate_core_get_sessions_array(void); | ||
| 56 | int tollgate_core_get_sessions_array_size(void); | ||
| 57 | void *tollgate_core_find_session_by_ip(uint32_t ip); | ||
| 58 | void *tollgate_core_find_session_by_mac(const char *mac); | ||
| 59 | void *tollgate_core_session_create(uint32_t client_ip, uint64_t allotment_ms); | ||
| 60 | void *tollgate_core_session_create_bytes(uint32_t client_ip, uint64_t allotment_bytes); | ||
| 61 | void tollgate_core_session_extend(void *session, uint64_t additional_ms); | ||
| 62 | void tollgate_core_session_revoke(void *session); | ||
| 63 | int tollgate_core_session_add_bytes(uint32_t client_ip, uint64_t bytes); | ||
| 64 | bool tollgate_core_session_is_expired(const void *session); | ||
| 65 | |||
| 66 | void tollgate_core_firewall_grant(uint32_t client_ip); | ||
| 67 | void tollgate_core_firewall_revoke(uint32_t client_ip); | ||
| 68 | int tollgate_core_firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, int mac_out_size); | ||
| 69 | |||
| 70 | int tollgate_core_cashu_decode(const char *token_str, void *out); | ||
| 71 | int tollgate_core_cashu_check_states(const char *mint_url, const void *token, | ||
| 72 | void *states, int *state_count); | ||
| 73 | uint64_t tollgate_core_cashu_allotment(uint64_t amount, uint64_t price, uint64_t step_size); | ||
| 74 | bool tollgate_core_cashu_is_mint_accepted(const char *mint_url); | ||
| 75 | const char *tollgate_core_cashu_token_mint(const void *token); | ||
| 76 | uint64_t tollgate_core_cashu_token_amount(const void *token); | ||
| 77 | |||
| 78 | void tollgate_core_mining_update_hashrate(uint32_t client_ip, bool accepted); | ||
| 79 | const void *tollgate_core_mining_get_client_stats(uint32_t client_ip); | ||
| 80 | double tollgate_core_mining_get_hashprice(void); | ||
| 81 | uint64_t tollgate_core_mining_shares_to_allotment_ms(double hashrate, double hashprice, | ||
| 82 | int price, int step_ms); | ||
| 83 | uint64_t tollgate_core_mining_shares_to_allotment_bytes(double hashrate, double hashprice, | ||
| 84 | int price, int step_bytes); | ||
| 85 | void tollgate_core_mining_set_nbits(uint32_t nbits); | ||
| 86 | |||
| 87 | const tollgate_platform_t *tollgate_core_get_platform(void); | ||
| 88 | uint32_t tollgate_core_get_ap_ip(void); | ||
| 89 | |||
| 90 | #endif | ||
diff --git a/tollgate_core/include/tollgate_platform.h b/tollgate_core/include/tollgate_platform.h deleted file mode 100644 index b553a83..0000000 --- a/tollgate_core/include/tollgate_platform.h +++ /dev/null | |||
| @@ -1,68 +0,0 @@ | |||
| 1 | #ifndef TOLLGATE_PLATFORM_H | ||
| 2 | #define TOLLGATE_PLATFORM_H | ||
| 3 | |||
| 4 | #include <stdint.h> | ||
| 5 | #include <stdbool.h> | ||
| 6 | #include <stddef.h> | ||
| 7 | |||
| 8 | typedef struct { | ||
| 9 | uint16_t (*get_price_sats)(void); | ||
| 10 | int32_t (*get_step_ms)(void); | ||
| 11 | int64_t (*get_step_bytes)(void); | ||
| 12 | const char* (*get_mint_url)(void); | ||
| 13 | const char* (*get_metric)(void); | ||
| 14 | |||
| 15 | int64_t (*get_time_ms)(void); | ||
| 16 | |||
| 17 | void (*log_info)(const char *tag, const char *fmt, ...); | ||
| 18 | void (*log_warn)(const char *tag, const char *fmt, ...); | ||
| 19 | void (*log_error)(const char *tag, const char *fmt, ...); | ||
| 20 | |||
| 21 | bool (*wallet_receive)(const char *token); | ||
| 22 | bool (*wallet_send)(uint64_t amount, char *buf, size_t buf_len); | ||
| 23 | uint64_t (*wallet_balance)(void); | ||
| 24 | |||
| 25 | int (*http_post)(const char *url, const char *headers, | ||
| 26 | const char *body, int body_len, | ||
| 27 | char *resp, int resp_len); | ||
| 28 | |||
| 29 | bool (*create_task)(void (*fn)(void*), void *arg, | ||
| 30 | const char *name, int stack_bytes, int priority); | ||
| 31 | |||
| 32 | int (*socket_udp)(void); | ||
| 33 | int (*socket_tcp)(void); | ||
| 34 | int (*socket_bind)(int fd, uint32_t ip, uint16_t port); | ||
| 35 | int (*socket_listen)(int fd, int backlog); | ||
| 36 | int (*socket_accept)(int fd, uint32_t *client_ip, uint16_t *client_port); | ||
| 37 | int (*socket_recvfrom)(int fd, void *buf, int len, | ||
| 38 | uint32_t *src_ip, uint16_t *src_port); | ||
| 39 | int (*socket_sendto)(int fd, const void *buf, int len, | ||
| 40 | uint32_t dest_ip, uint16_t dest_port); | ||
| 41 | int (*socket_read)(int fd, void *buf, int len); | ||
| 42 | int (*socket_write)(int fd, const void *buf, int len); | ||
| 43 | void (*socket_close)(int fd); | ||
| 44 | void (*socket_set_recv_timeout)(int fd, int ms); | ||
| 45 | |||
| 46 | bool (*get_sta_mac_ip_list)(void *list_out, int max, int *count_out); | ||
| 47 | bool (*set_vendor_ie)(bool enable, const void *ie_data, int ie_len); | ||
| 48 | int (*arp_get_mac)(uint32_t ip, uint8_t *mac_out); | ||
| 49 | void (*napt_enable)(uint32_t ip, bool enable); | ||
| 50 | |||
| 51 | bool (*mining_enabled)(void); | ||
| 52 | const char* (*get_stratum_host)(void); | ||
| 53 | uint16_t (*get_stratum_port)(void); | ||
| 54 | const char* (*get_stratum_user)(void); | ||
| 55 | const char* (*get_stratum_pass)(void); | ||
| 56 | uint16_t (*get_mining_port)(void); | ||
| 57 | uint64_t (*get_hashprice_override)(void); | ||
| 58 | |||
| 59 | void (*fill_random)(void *buf, int len); | ||
| 60 | |||
| 61 | int (*get_accepted_mint_count)(void); | ||
| 62 | const char* (*get_accepted_mint)(int index); | ||
| 63 | bool (*is_mint_reachable)(const char *mint_url); | ||
| 64 | bool (*mac_for_ip)(uint32_t ip, char *mac_out, int mac_out_size); | ||
| 65 | |||
| 66 | } tollgate_platform_t; | ||
| 67 | |||
| 68 | #endif | ||
diff --git a/tollgate_core/src/tollgate_cashu.c b/tollgate_core/src/tollgate_cashu.c deleted file mode 100644 index 55f4953..0000000 --- a/tollgate_core/src/tollgate_cashu.c +++ /dev/null | |||
| @@ -1,253 +0,0 @@ | |||
| 1 | #include "tollgate_cashu.h" | ||
| 2 | #include "tollgate_core.h" | ||
| 3 | #include "tollgate_platform.h" | ||
| 4 | #include <stdlib.h> | ||
| 5 | #include <string.h> | ||
| 6 | #include <stdio.h> | ||
| 7 | #include <cJSON.h> | ||
| 8 | #include <mbedtls/base64.h> | ||
| 9 | #include <mbedtls/sha256.h> | ||
| 10 | |||
| 11 | static const char *TAG = "tg_cashu"; | ||
| 12 | |||
| 13 | static const char V3_PREFIX[] = "cashuA"; | ||
| 14 | static const size_t V3_PREFIX_LEN = 6; | ||
| 15 | |||
| 16 | static int b64url_decode(const char *input, size_t input_len, char *out, size_t out_size, size_t *out_len) | ||
| 17 | { | ||
| 18 | char *b64 = malloc(input_len + 4); | ||
| 19 | if (!b64) return -1; | ||
| 20 | size_t b64_len = input_len; | ||
| 21 | memcpy(b64, input, b64_len); | ||
| 22 | b64[b64_len] = '\0'; | ||
| 23 | |||
| 24 | for (size_t i = 0; i < b64_len; i++) { | ||
| 25 | if (b64[i] == '-') b64[i] = '+'; | ||
| 26 | else if (b64[i] == '_') b64[i] = '/'; | ||
| 27 | } | ||
| 28 | while (b64_len % 4 != 0) { | ||
| 29 | b64[b64_len++] = '='; | ||
| 30 | } | ||
| 31 | b64[b64_len] = '\0'; | ||
| 32 | |||
| 33 | size_t olen = 0; | ||
| 34 | int ret = mbedtls_base64_decode((unsigned char *)out, out_size, &olen, | ||
| 35 | (const unsigned char *)b64, b64_len); | ||
| 36 | free(b64); | ||
| 37 | if (ret != 0) return -1; | ||
| 38 | *out_len = olen; | ||
| 39 | return 0; | ||
| 40 | } | ||
| 41 | |||
| 42 | static int parse_proofs_array(cJSON *arr, tg_cashu_token_t *out) | ||
| 43 | { | ||
| 44 | if (!cJSON_IsArray(arr)) return -1; | ||
| 45 | int count = cJSON_GetArraySize(arr); | ||
| 46 | if (count > TG_CASHU_MAX_PROOFS) return -1; | ||
| 47 | |||
| 48 | out->proof_count = 0; | ||
| 49 | out->total_amount = 0; | ||
| 50 | for (int i = 0; i < count; i++) { | ||
| 51 | cJSON *proof = cJSON_GetArrayItem(arr, i); | ||
| 52 | cJSON *amt = cJSON_GetObjectItemCaseSensitive(proof, "amount"); | ||
| 53 | cJSON *id = cJSON_GetObjectItemCaseSensitive(proof, "id"); | ||
| 54 | cJSON *secret = cJSON_GetObjectItemCaseSensitive(proof, "secret"); | ||
| 55 | cJSON *c = cJSON_GetObjectItemCaseSensitive(proof, "C"); | ||
| 56 | |||
| 57 | if (!amt || !cJSON_IsNumber(amt)) return -1; | ||
| 58 | |||
| 59 | out->proofs[i].amount = (uint64_t)amt->valuedouble; | ||
| 60 | out->total_amount += out->proofs[i].amount; | ||
| 61 | |||
| 62 | if (id && cJSON_IsString(id)) { | ||
| 63 | strncpy(out->proofs[i].id, id->valuestring, sizeof(out->proofs[i].id) - 1); | ||
| 64 | } | ||
| 65 | if (secret && cJSON_IsString(secret)) { | ||
| 66 | strncpy(out->proofs[i].secret, secret->valuestring, sizeof(out->proofs[i].secret) - 1); | ||
| 67 | } | ||
| 68 | if (c && cJSON_IsString(c)) { | ||
| 69 | strncpy(out->proofs[i].c, c->valuestring, sizeof(out->proofs[i].c) - 1); | ||
| 70 | } | ||
| 71 | out->proof_count++; | ||
| 72 | } | ||
| 73 | return 0; | ||
| 74 | } | ||
| 75 | |||
| 76 | int tg_cashu_decode_token(const char *token_str, tg_cashu_token_t *out) | ||
| 77 | { | ||
| 78 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 79 | if (!token_str || !out) return -1; | ||
| 80 | memset(out, 0, sizeof(*out)); | ||
| 81 | |||
| 82 | size_t len = strlen(token_str); | ||
| 83 | char *nl = strchr(token_str, '\n'); | ||
| 84 | if (nl) len = nl - token_str; | ||
| 85 | char *cr = strchr(token_str, '\r'); | ||
| 86 | if (cr && (cr - token_str) < (int)len) len = cr - token_str; | ||
| 87 | if (len <= V3_PREFIX_LEN) { | ||
| 88 | if (p && p->log_error) p->log_error(TAG, "Token too short"); | ||
| 89 | return -1; | ||
| 90 | } | ||
| 91 | if (strncmp(token_str, V3_PREFIX, V3_PREFIX_LEN) != 0) { | ||
| 92 | if (p && p->log_error) p->log_error(TAG, "Token missing cashuA prefix"); | ||
| 93 | return -1; | ||
| 94 | } | ||
| 95 | |||
| 96 | size_t b64_len = len - V3_PREFIX_LEN; | ||
| 97 | size_t decoded_size = (b64_len * 3) / 4 + 4; | ||
| 98 | char *json_buf = malloc(decoded_size); | ||
| 99 | if (!json_buf) return -1; | ||
| 100 | size_t json_len = 0; | ||
| 101 | if (b64url_decode(token_str + V3_PREFIX_LEN, b64_len, | ||
| 102 | json_buf, decoded_size - 1, &json_len) != 0) { | ||
| 103 | if (p && p->log_error) p->log_error(TAG, "Base64url decode failed"); | ||
| 104 | free(json_buf); | ||
| 105 | return -1; | ||
| 106 | } | ||
| 107 | json_buf[json_len] = '\0'; | ||
| 108 | |||
| 109 | cJSON *root = cJSON_Parse(json_buf); | ||
| 110 | free(json_buf); | ||
| 111 | if (!root) { | ||
| 112 | if (p && p->log_error) p->log_error(TAG, "JSON parse failed"); | ||
| 113 | return -1; | ||
| 114 | } | ||
| 115 | |||
| 116 | cJSON *token_arr = cJSON_GetObjectItemCaseSensitive(root, "token"); | ||
| 117 | if (token_arr && cJSON_IsArray(token_arr)) { | ||
| 118 | cJSON *first = cJSON_GetArrayItem(token_arr, 0); | ||
| 119 | if (!first) { cJSON_Delete(root); return -1; } | ||
| 120 | |||
| 121 | cJSON *mint = cJSON_GetObjectItemCaseSensitive(first, "mint"); | ||
| 122 | if (mint && cJSON_IsString(mint)) { | ||
| 123 | strncpy(out->mint_url, mint->valuestring, sizeof(out->mint_url) - 1); | ||
| 124 | } | ||
| 125 | |||
| 126 | cJSON *proofs = cJSON_GetObjectItemCaseSensitive(first, "proofs"); | ||
| 127 | if (proofs) { | ||
| 128 | if (parse_proofs_array(proofs, out) != 0) { cJSON_Delete(root); return -1; } | ||
| 129 | } | ||
| 130 | } else { | ||
| 131 | cJSON *mint = cJSON_GetObjectItemCaseSensitive(root, "mint"); | ||
| 132 | if (mint && cJSON_IsString(mint)) { | ||
| 133 | strncpy(out->mint_url, mint->valuestring, sizeof(out->mint_url) - 1); | ||
| 134 | } | ||
| 135 | |||
| 136 | cJSON *proofs = cJSON_GetObjectItemCaseSensitive(root, "proofs"); | ||
| 137 | if (proofs) { | ||
| 138 | if (parse_proofs_array(proofs, out) != 0) { cJSON_Delete(root); return -1; } | ||
| 139 | } | ||
| 140 | } | ||
| 141 | |||
| 142 | cJSON_Delete(root); | ||
| 143 | |||
| 144 | if (out->proof_count == 0) { | ||
| 145 | if (p && p->log_error) p->log_error(TAG, "No proofs in token"); | ||
| 146 | return -1; | ||
| 147 | } | ||
| 148 | |||
| 149 | if (p && p->log_info) p->log_info(TAG, "Decoded token: %d proofs, total=%llu, mint=%s", | ||
| 150 | out->proof_count, (unsigned long long)out->total_amount, out->mint_url); | ||
| 151 | return 0; | ||
| 152 | } | ||
| 153 | |||
| 154 | static void sha256_hex(const char *data, size_t data_len, char *hex_out) | ||
| 155 | { | ||
| 156 | unsigned char hash[32]; | ||
| 157 | mbedtls_sha256((const unsigned char *)data, data_len, hash, 0); | ||
| 158 | for (int i = 0; i < 32; i++) { | ||
| 159 | sprintf(hex_out + i * 2, "%02x", hash[i]); | ||
| 160 | } | ||
| 161 | hex_out[64] = '\0'; | ||
| 162 | } | ||
| 163 | |||
| 164 | int tg_cashu_check_proof_states(const char *mint_url, const tg_cashu_token_t *token, | ||
| 165 | tg_cashu_proof_state_t *states, int *state_count) | ||
| 166 | { | ||
| 167 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 168 | |||
| 169 | cJSON *ys_arr = cJSON_CreateArray(); | ||
| 170 | for (int i = 0; i < token->proof_count; i++) { | ||
| 171 | char y_hex[65]; | ||
| 172 | sha256_hex(token->proofs[i].secret, strlen(token->proofs[i].secret), y_hex); | ||
| 173 | cJSON_AddItemToArray(ys_arr, cJSON_CreateString(y_hex)); | ||
| 174 | strncpy(states[i].y_hex, y_hex, sizeof(states[i].y_hex) - 1); | ||
| 175 | states[i].spent = false; | ||
| 176 | } | ||
| 177 | *state_count = token->proof_count; | ||
| 178 | |||
| 179 | char *ys_json = cJSON_PrintUnformatted(ys_arr); | ||
| 180 | cJSON_Delete(ys_arr); | ||
| 181 | |||
| 182 | char *post_body = malloc(4096); | ||
| 183 | if (!post_body) { cJSON_free(ys_json); return -1; } | ||
| 184 | snprintf(post_body, 4096, "{\"Ys\":%s}", ys_json); | ||
| 185 | cJSON_free(ys_json); | ||
| 186 | |||
| 187 | char url[512]; | ||
| 188 | snprintf(url, sizeof(url), "%s/v1/checkstate", mint_url); | ||
| 189 | |||
| 190 | if (!p || !p->http_post) { | ||
| 191 | free(post_body); | ||
| 192 | return -1; | ||
| 193 | } | ||
| 194 | |||
| 195 | char *resp_buf = malloc(8192); | ||
| 196 | if (!resp_buf) { free(post_body); return -1; } | ||
| 197 | |||
| 198 | int resp_len = p->http_post(url, "Content-Type: application/json", | ||
| 199 | post_body, (int)strlen(post_body), | ||
| 200 | resp_buf, 8191); | ||
| 201 | free(post_body); | ||
| 202 | |||
| 203 | if (resp_len <= 0) { | ||
| 204 | if (p && p->log_error) p->log_error(TAG, "checkstate HTTP failed: resp_len=%d", resp_len); | ||
| 205 | free(resp_buf); | ||
| 206 | return -1; | ||
| 207 | } | ||
| 208 | resp_buf[resp_len] = '\0'; | ||
| 209 | |||
| 210 | cJSON *root = cJSON_Parse(resp_buf); | ||
| 211 | free(resp_buf); | ||
| 212 | if (!root) return -1; | ||
| 213 | |||
| 214 | cJSON *states_arr = cJSON_GetObjectItemCaseSensitive(root, "states"); | ||
| 215 | if (!states_arr || !cJSON_IsArray(states_arr)) { | ||
| 216 | cJSON_Delete(root); | ||
| 217 | return -1; | ||
| 218 | } | ||
| 219 | |||
| 220 | int n = cJSON_GetArraySize(states_arr); | ||
| 221 | for (int i = 0; i < n && i < token->proof_count; i++) { | ||
| 222 | cJSON *s = cJSON_GetArrayItem(states_arr, i); | ||
| 223 | cJSON *state = cJSON_GetObjectItemCaseSensitive(s, "state"); | ||
| 224 | if (state && cJSON_IsString(state)) { | ||
| 225 | states[i].spent = (strcmp(state->valuestring, "SPENT") == 0); | ||
| 226 | } | ||
| 227 | } | ||
| 228 | |||
| 229 | cJSON_Delete(root); | ||
| 230 | return 0; | ||
| 231 | } | ||
| 232 | |||
| 233 | uint64_t tg_cashu_calculate_allotment_ms(uint64_t token_amount, uint64_t price_per_step, | ||
| 234 | uint64_t step_size_ms) | ||
| 235 | { | ||
| 236 | if (price_per_step == 0) return 0; | ||
| 237 | return (token_amount / price_per_step) * step_size_ms; | ||
| 238 | } | ||
| 239 | |||
| 240 | uint64_t tg_cashu_calculate_allotment(uint64_t token_amount, uint64_t price_per_step, | ||
| 241 | uint64_t step_size) | ||
| 242 | { | ||
| 243 | if (price_per_step == 0) return 0; | ||
| 244 | return (token_amount / price_per_step) * step_size; | ||
| 245 | } | ||
| 246 | |||
| 247 | bool tg_cashu_is_mint_accepted(const char *mint_url, const char *accepted_mint_url) | ||
| 248 | { | ||
| 249 | if (!mint_url || mint_url[0] == '\0') return false; | ||
| 250 | if (!accepted_mint_url || accepted_mint_url[0] == '\0') return false; | ||
| 251 | return (strstr(mint_url, accepted_mint_url) != NULL || | ||
| 252 | strcmp(mint_url, accepted_mint_url) == 0); | ||
| 253 | } | ||
diff --git a/tollgate_core/src/tollgate_cashu.h b/tollgate_core/src/tollgate_cashu.h deleted file mode 100644 index 9785e98..0000000 --- a/tollgate_core/src/tollgate_cashu.h +++ /dev/null | |||
| @@ -1,40 +0,0 @@ | |||
| 1 | #ifndef TOLLGATE_CORE_CASHU_H | ||
| 2 | #define TOLLGATE_CORE_CASHU_H | ||
| 3 | |||
| 4 | #include <stdint.h> | ||
| 5 | #include <stdbool.h> | ||
| 6 | |||
| 7 | #define TG_CASHU_MAX_PROOFS 10 | ||
| 8 | #define TG_CASHU_MAX_SECRET_LEN 128 | ||
| 9 | #define TG_CASHU_MAX_ID_LEN 68 | ||
| 10 | #define TG_CASHU_MAX_C_LEN 128 | ||
| 11 | |||
| 12 | typedef struct { | ||
| 13 | uint64_t amount; | ||
| 14 | char id[TG_CASHU_MAX_ID_LEN]; | ||
| 15 | char secret[TG_CASHU_MAX_SECRET_LEN]; | ||
| 16 | char c[TG_CASHU_MAX_C_LEN]; | ||
| 17 | } tg_cashu_proof_t; | ||
| 18 | |||
| 19 | typedef struct { | ||
| 20 | tg_cashu_proof_t proofs[TG_CASHU_MAX_PROOFS]; | ||
| 21 | int proof_count; | ||
| 22 | char mint_url[256]; | ||
| 23 | uint64_t total_amount; | ||
| 24 | } tg_cashu_token_t; | ||
| 25 | |||
| 26 | typedef struct { | ||
| 27 | char y_hex[65]; | ||
| 28 | bool spent; | ||
| 29 | } tg_cashu_proof_state_t; | ||
| 30 | |||
| 31 | int tg_cashu_decode_token(const char *token_str, tg_cashu_token_t *out); | ||
| 32 | int tg_cashu_check_proof_states(const char *mint_url, const tg_cashu_token_t *token, | ||
| 33 | tg_cashu_proof_state_t *states, int *state_count); | ||
| 34 | uint64_t tg_cashu_calculate_allotment_ms(uint64_t token_amount, uint64_t price_per_step, | ||
| 35 | uint64_t step_size_ms); | ||
| 36 | uint64_t tg_cashu_calculate_allotment(uint64_t token_amount, uint64_t price_per_step, | ||
| 37 | uint64_t step_size); | ||
| 38 | bool tg_cashu_is_mint_accepted(const char *mint_url, const char *accepted_mint_url); | ||
| 39 | |||
| 40 | #endif | ||
diff --git a/tollgate_core/src/tollgate_core.c b/tollgate_core/src/tollgate_core.c deleted file mode 100644 index c7c2902..0000000 --- a/tollgate_core/src/tollgate_core.c +++ /dev/null | |||
| @@ -1,466 +0,0 @@ | |||
| 1 | #include "tollgate_core.h" | ||
| 2 | #include "tollgate_platform.h" | ||
| 3 | #include "tollgate_cashu.h" | ||
| 4 | #include "tollgate_session.h" | ||
| 5 | #include "tollgate_firewall.h" | ||
| 6 | #include "tollgate_mining.h" | ||
| 7 | #include <string.h> | ||
| 8 | #include <stdlib.h> | ||
| 9 | #include <stdio.h> | ||
| 10 | |||
| 11 | static const char *TAG = "tg_core"; | ||
| 12 | static const tollgate_platform_t *s_platform; | ||
| 13 | static uint32_t s_ap_ip; | ||
| 14 | |||
| 15 | static uint32_t s_owner_ip; | ||
| 16 | static uint8_t s_owner_mac[6]; | ||
| 17 | static bool s_owner_connected; | ||
| 18 | |||
| 19 | const tollgate_platform_t *tollgate_core_get_platform(void) | ||
| 20 | { | ||
| 21 | return s_platform; | ||
| 22 | } | ||
| 23 | |||
| 24 | uint32_t tollgate_core_get_ap_ip(void) | ||
| 25 | { | ||
| 26 | return s_ap_ip; | ||
| 27 | } | ||
| 28 | |||
| 29 | int tollgate_core_init(const tollgate_platform_t *platform, uint32_t ap_ip) | ||
| 30 | { | ||
| 31 | if (!platform) return -1; | ||
| 32 | |||
| 33 | s_platform = platform; | ||
| 34 | s_ap_ip = ap_ip; | ||
| 35 | s_owner_connected = false; | ||
| 36 | memset(s_owner_mac, 0, sizeof(s_owner_mac)); | ||
| 37 | |||
| 38 | tg_session_init(); | ||
| 39 | tg_firewall_init(ap_ip); | ||
| 40 | tg_mining_init(); | ||
| 41 | |||
| 42 | if (platform->log_info) { | ||
| 43 | char ip_str[16]; | ||
| 44 | snprintf(ip_str, sizeof(ip_str), "%d.%d.%d.%d", | ||
| 45 | (int)((ap_ip >> 0) & 0xFF), (int)((ap_ip >> 8) & 0xFF), | ||
| 46 | (int)((ap_ip >> 16) & 0xFF), (int)((ap_ip >> 24) & 0xFF)); | ||
| 47 | platform->log_info(TAG, "TollGate core initialized, AP IP=%s", ip_str); | ||
| 48 | } | ||
| 49 | return 0; | ||
| 50 | } | ||
| 51 | |||
| 52 | void tollgate_core_tick(void) | ||
| 53 | { | ||
| 54 | tg_session_tick(); | ||
| 55 | } | ||
| 56 | |||
| 57 | int tollgate_core_process_payment(uint32_t client_ip, const char *token_str) | ||
| 58 | { | ||
| 59 | if (!s_platform || !token_str) return -1; | ||
| 60 | |||
| 61 | const char *accepted_mint = s_platform->get_mint_url ? s_platform->get_mint_url() : NULL; | ||
| 62 | if (!accepted_mint || accepted_mint[0] == '\0') { | ||
| 63 | if (s_platform->log_error) s_platform->log_error(TAG, "No mint URL configured"); | ||
| 64 | return -1; | ||
| 65 | } | ||
| 66 | |||
| 67 | tg_cashu_token_t token; | ||
| 68 | if (tg_cashu_decode_token(token_str, &token) != 0) { | ||
| 69 | if (s_platform->log_error) s_platform->log_error(TAG, "Token decode failed"); | ||
| 70 | return -1; | ||
| 71 | } | ||
| 72 | |||
| 73 | bool mint_ok = false; | ||
| 74 | if (s_platform->get_accepted_mint_count && s_platform->get_accepted_mint) { | ||
| 75 | int count = s_platform->get_accepted_mint_count(); | ||
| 76 | for (int i = 0; i < count; i++) { | ||
| 77 | if (tg_cashu_is_mint_accepted(token.mint_url, s_platform->get_accepted_mint(i))) { | ||
| 78 | mint_ok = true; | ||
| 79 | break; | ||
| 80 | } | ||
| 81 | } | ||
| 82 | } else { | ||
| 83 | mint_ok = tg_cashu_is_mint_accepted(token.mint_url, accepted_mint); | ||
| 84 | } | ||
| 85 | if (!mint_ok) { | ||
| 86 | if (s_platform->log_error) s_platform->log_error(TAG, "Token mint not accepted"); | ||
| 87 | return -1; | ||
| 88 | } | ||
| 89 | |||
| 90 | tg_cashu_proof_state_t states[TG_CASHU_MAX_PROOFS]; | ||
| 91 | int state_count = 0; | ||
| 92 | if (tg_cashu_check_proof_states(token.mint_url, &token, states, &state_count) != 0) { | ||
| 93 | if (s_platform->log_error) s_platform->log_error(TAG, "Proof state check failed (continuing)"); | ||
| 94 | } else { | ||
| 95 | for (int i = 0; i < state_count; i++) { | ||
| 96 | if (states[i].spent) { | ||
| 97 | if (s_platform->log_error) s_platform->log_error(TAG, "Proof %d is SPENT", i); | ||
| 98 | return -1; | ||
| 99 | } | ||
| 100 | } | ||
| 101 | } | ||
| 102 | |||
| 103 | if (s_platform->wallet_receive) { | ||
| 104 | if (!s_platform->wallet_receive(token_str)) { | ||
| 105 | if (s_platform->log_error) s_platform->log_error(TAG, "wallet_receive rejected token"); | ||
| 106 | return -1; | ||
| 107 | } | ||
| 108 | } | ||
| 109 | |||
| 110 | const char *metric = (s_platform->get_metric) ? s_platform->get_metric() : "milliseconds"; | ||
| 111 | uint64_t price = (s_platform->get_price_sats) ? s_platform->get_price_sats() : 21; | ||
| 112 | uint64_t step_size; | ||
| 113 | |||
| 114 | if (strcmp(metric, "bytes") == 0) { | ||
| 115 | step_size = (s_platform->get_step_bytes) ? (uint64_t)s_platform->get_step_bytes() : 22020096; | ||
| 116 | } else { | ||
| 117 | step_size = (s_platform->get_step_ms) ? (uint64_t)s_platform->get_step_ms() : 60000; | ||
| 118 | } | ||
| 119 | |||
| 120 | uint64_t allotment = tg_cashu_calculate_allotment(token.total_amount, price, step_size); | ||
| 121 | if (allotment == 0) { | ||
| 122 | if (s_platform->log_error) s_platform->log_error(TAG, "Token amount too small"); | ||
| 123 | return -1; | ||
| 124 | } | ||
| 125 | |||
| 126 | if (strcmp(metric, "bytes") == 0) { | ||
| 127 | if (!tg_session_create_bytes(client_ip, allotment)) return -1; | ||
| 128 | } else { | ||
| 129 | if (!tg_session_create(client_ip, allotment)) return -1; | ||
| 130 | } | ||
| 131 | |||
| 132 | if (s_platform->log_info) s_platform->log_info(TAG, "Payment: %llu sats -> %llu %s", | ||
| 133 | (unsigned long long)token.total_amount, (unsigned long long)allotment, metric); | ||
| 134 | return 0; | ||
| 135 | } | ||
| 136 | |||
| 137 | int tollgate_core_process_share(uint32_t client_ip, const char *job_id, | ||
| 138 | const char *nonce, const char *ntime, const char *version) | ||
| 139 | { | ||
| 140 | (void)job_id; (void)nonce; (void)ntime; (void)version; | ||
| 141 | if (!s_platform) return -1; | ||
| 142 | |||
| 143 | tg_mining_update_hashrate(client_ip, true); | ||
| 144 | const tg_mining_client_stats_t *stats = tg_mining_get_client_stats(client_ip); | ||
| 145 | if (!stats) return -1; | ||
| 146 | |||
| 147 | double hashprice = tg_mining_get_current_hashprice(); | ||
| 148 | uint64_t override = (s_platform->get_hashprice_override) ? s_platform->get_hashprice_override() : 0; | ||
| 149 | if (override > 0) hashprice = tg_mining_calculate_hashprice_override(override); | ||
| 150 | |||
| 151 | const char *metric = (s_platform->get_metric) ? s_platform->get_metric() : "milliseconds"; | ||
| 152 | int price = (s_platform->get_price_sats) ? s_platform->get_price_sats() : 21; | ||
| 153 | |||
| 154 | tg_session_t *existing = tg_session_find_by_ip(client_ip); | ||
| 155 | if (existing && existing->payment_method == TG_PAYMENT_MINING) { | ||
| 156 | uint64_t allotment; | ||
| 157 | if (strcmp(metric, "bytes") == 0) { | ||
| 158 | int step_bytes = (s_platform->get_step_bytes) ? (int)s_platform->get_step_bytes() : 22020096; | ||
| 159 | allotment = tg_mining_shares_to_allotment_bytes(stats->hashrate_ghs, hashprice, price, step_bytes); | ||
| 160 | existing->allotment_bytes += allotment; | ||
| 161 | } else { | ||
| 162 | int step_ms = (s_platform->get_step_ms) ? s_platform->get_step_ms() : 60000; | ||
| 163 | allotment = tg_mining_shares_to_allotment_ms(stats->hashrate_ghs, hashprice, price, step_ms); | ||
| 164 | tg_session_extend(existing, allotment); | ||
| 165 | } | ||
| 166 | return 0; | ||
| 167 | } | ||
| 168 | |||
| 169 | uint64_t allotment; | ||
| 170 | if (strcmp(metric, "bytes") == 0) { | ||
| 171 | int step_bytes = (s_platform->get_step_bytes) ? (int)s_platform->get_step_bytes() : 22020096; | ||
| 172 | allotment = tg_mining_shares_to_allotment_bytes(stats->hashrate_ghs, hashprice, price, step_bytes); | ||
| 173 | tg_session_t *s = tg_session_create_bytes(client_ip, allotment); | ||
| 174 | if (s) s->payment_method = TG_PAYMENT_MINING; | ||
| 175 | } else { | ||
| 176 | int step_ms = (s_platform->get_step_ms) ? s_platform->get_step_ms() : 60000; | ||
| 177 | allotment = tg_mining_shares_to_allotment_ms(stats->hashrate_ghs, hashprice, price, step_ms); | ||
| 178 | tg_session_t *s = tg_session_create(client_ip, allotment); | ||
| 179 | if (s) s->payment_method = TG_PAYMENT_MINING; | ||
| 180 | } | ||
| 181 | |||
| 182 | return 0; | ||
| 183 | } | ||
| 184 | |||
| 185 | void tollgate_core_client_connected(const uint8_t *mac, uint32_t client_ip) | ||
| 186 | { | ||
| 187 | if (!s_owner_connected) { | ||
| 188 | s_owner_connected = true; | ||
| 189 | s_owner_ip = client_ip; | ||
| 190 | if (mac) memcpy(s_owner_mac, mac, 6); | ||
| 191 | if (s_platform && s_platform->log_info) { | ||
| 192 | char ip_str[16]; | ||
| 193 | snprintf(ip_str, sizeof(ip_str), "%d.%d.%d.%d", | ||
| 194 | (int)((client_ip >> 0) & 0xFF), (int)((client_ip >> 8) & 0xFF), | ||
| 195 | (int)((client_ip >> 16) & 0xFF), (int)((client_ip >> 24) & 0xFF)); | ||
| 196 | s_platform->log_info(TAG, "First client = owner: %s", ip_str); | ||
| 197 | } | ||
| 198 | return; | ||
| 199 | } | ||
| 200 | if (s_platform && s_platform->log_info) s_platform->log_info(TAG, "Client connected (non-owner)"); | ||
| 201 | } | ||
| 202 | |||
| 203 | void tollgate_core_client_disconnected(const uint8_t *mac) | ||
| 204 | { | ||
| 205 | if (!s_owner_connected) return; | ||
| 206 | if (mac && memcmp(s_owner_mac, mac, 6) == 0) { | ||
| 207 | s_owner_connected = false; | ||
| 208 | memset(s_owner_mac, 0, sizeof(s_owner_mac)); | ||
| 209 | if (s_platform && s_platform->log_info) s_platform->log_info(TAG, "Owner disconnected"); | ||
| 210 | } | ||
| 211 | } | ||
| 212 | |||
| 213 | bool tollgate_core_is_client_allowed(uint32_t client_ip) | ||
| 214 | { | ||
| 215 | return tg_firewall_is_allowed(client_ip); | ||
| 216 | } | ||
| 217 | |||
| 218 | bool tollgate_core_is_dns_running(void) | ||
| 219 | { | ||
| 220 | return false; | ||
| 221 | } | ||
| 222 | |||
| 223 | char *tollgate_core_get_status_json(void) | ||
| 224 | { | ||
| 225 | const int BUFSIZE = 512; | ||
| 226 | char *json = malloc(BUFSIZE); | ||
| 227 | if (!json) return NULL; | ||
| 228 | snprintf(json, BUFSIZE, | ||
| 229 | "{\"ownerConnected\":%s,\"activeSessions\":%d,\"allowedClients\":%d,\"dnsRunning\":%s}", | ||
| 230 | s_owner_connected ? "true" : "false", | ||
| 231 | tg_session_active_count(), | ||
| 232 | tg_firewall_client_count(), | ||
| 233 | tollgate_core_is_dns_running() ? "true" : "false"); | ||
| 234 | return json; | ||
| 235 | } | ||
| 236 | |||
| 237 | char *tollgate_core_get_config_json(void) | ||
| 238 | { | ||
| 239 | const int BUFSIZE = 512; | ||
| 240 | char *json = malloc(BUFSIZE); | ||
| 241 | if (!json) return NULL; | ||
| 242 | int pos = 0; | ||
| 243 | pos += snprintf(json + pos, BUFSIZE - pos, "{"); | ||
| 244 | if (s_platform) { | ||
| 245 | if (s_platform->get_price_sats) | ||
| 246 | pos += snprintf(json + pos, BUFSIZE - pos, "\"priceSats\":%d,", (int)s_platform->get_price_sats()); | ||
| 247 | if (s_platform->get_step_ms) | ||
| 248 | pos += snprintf(json + pos, BUFSIZE - pos, "\"stepMs\":%d,", (int)s_platform->get_step_ms()); | ||
| 249 | if (s_platform->get_mint_url) | ||
| 250 | pos += snprintf(json + pos, BUFSIZE - pos, "\"mintUrl\":\"%s\",", s_platform->get_mint_url()); | ||
| 251 | if (s_platform->get_metric) | ||
| 252 | pos += snprintf(json + pos, BUFSIZE - pos, "\"metric\":\"%s\"", s_platform->get_metric()); | ||
| 253 | } | ||
| 254 | pos += snprintf(json + pos, BUFSIZE - pos, "}"); | ||
| 255 | return json; | ||
| 256 | } | ||
| 257 | |||
| 258 | int tollgate_core_active_session_count(void) | ||
| 259 | { | ||
| 260 | return tg_session_active_count(); | ||
| 261 | } | ||
| 262 | |||
| 263 | int tollgate_core_allowed_client_count(void) | ||
| 264 | { | ||
| 265 | return tg_firewall_client_count(); | ||
| 266 | } | ||
| 267 | |||
| 268 | int tollgate_core_firewall_revoke_all(void) | ||
| 269 | { | ||
| 270 | tg_session_revoke_all(); | ||
| 271 | return tg_firewall_revoke_all(); | ||
| 272 | } | ||
| 273 | |||
| 274 | void tollgate_core_firewall_set_mining_port(uint16_t port) | ||
| 275 | { | ||
| 276 | tg_firewall_set_mining_port(port); | ||
| 277 | } | ||
| 278 | |||
| 279 | void tollgate_core_firewall_set_sandbox_mint_access(bool enable) | ||
| 280 | { | ||
| 281 | tg_firewall_set_sandbox_mint_access(enable); | ||
| 282 | } | ||
| 283 | |||
| 284 | bool tollgate_core_is_owner(uint32_t client_ip) | ||
| 285 | { | ||
| 286 | return s_owner_connected && s_owner_ip == client_ip; | ||
| 287 | } | ||
| 288 | |||
| 289 | bool tollgate_core_is_owner_connected(void) | ||
| 290 | { | ||
| 291 | return s_owner_connected; | ||
| 292 | } | ||
| 293 | |||
| 294 | double tollgate_core_get_hashprice(void) | ||
| 295 | { | ||
| 296 | return tg_mining_get_current_hashprice(); | ||
| 297 | } | ||
| 298 | |||
| 299 | void tollgate_core_set_nbits(uint32_t nbits) | ||
| 300 | { | ||
| 301 | tg_mining_set_current_nbits(nbits); | ||
| 302 | } | ||
| 303 | |||
| 304 | const void *tollgate_core_get_current_job(void) { return NULL; } | ||
| 305 | void tollgate_core_set_job(const void *job) { (void)job; } | ||
| 306 | int tollgate_core_stratum_client_start(void) { return -1; } | ||
| 307 | void tollgate_core_stratum_client_stop(void) { } | ||
| 308 | int tollgate_core_stratum_proxy_init(uint16_t port) { (void)port; return -1; } | ||
| 309 | void tollgate_core_stratum_proxy_get_stats(void *out) { (void)out; } | ||
| 310 | void tollgate_core_beacon_start(void) { } | ||
| 311 | void tollgate_core_market_init(void) { } | ||
| 312 | void tollgate_core_market_on_scan_result(const void *ie_data, int ie_len, const uint8_t *bssid, int rssi) | ||
| 313 | { | ||
| 314 | (void)ie_data; (void)ie_len; (void)bssid; (void)rssi; | ||
| 315 | } | ||
| 316 | |||
| 317 | const void *tollgate_core_get_sessions_array(void) | ||
| 318 | { | ||
| 319 | return tg_session_get_array(); | ||
| 320 | } | ||
| 321 | |||
| 322 | int tollgate_core_get_sessions_array_size(void) | ||
| 323 | { | ||
| 324 | return tg_session_get_array_size(); | ||
| 325 | } | ||
| 326 | |||
| 327 | void *tollgate_core_find_session_by_ip(uint32_t ip) | ||
| 328 | { | ||
| 329 | return tg_session_find_by_ip(ip); | ||
| 330 | } | ||
| 331 | |||
| 332 | void *tollgate_core_find_session_by_mac(const char *mac) | ||
| 333 | { | ||
| 334 | return tg_session_find_by_mac(mac); | ||
| 335 | } | ||
| 336 | |||
| 337 | void tollgate_core_session_extend(void *session, uint64_t additional_ms) | ||
| 338 | { | ||
| 339 | tg_session_extend((tg_session_t *)session, additional_ms); | ||
| 340 | } | ||
| 341 | |||
| 342 | int tollgate_core_session_add_bytes(uint32_t client_ip, uint64_t bytes) | ||
| 343 | { | ||
| 344 | tg_session_add_bytes(client_ip, bytes); | ||
| 345 | return 0; | ||
| 346 | } | ||
| 347 | |||
| 348 | void *tollgate_core_session_create(uint32_t client_ip, uint64_t allotment_ms) | ||
| 349 | { | ||
| 350 | return tg_session_create(client_ip, allotment_ms); | ||
| 351 | } | ||
| 352 | |||
| 353 | void *tollgate_core_session_create_bytes(uint32_t client_ip, uint64_t allotment_bytes) | ||
| 354 | { | ||
| 355 | return tg_session_create_bytes(client_ip, allotment_bytes); | ||
| 356 | } | ||
| 357 | |||
| 358 | void tollgate_core_session_revoke(void *session) | ||
| 359 | { | ||
| 360 | tg_session_revoke((tg_session_t *)session); | ||
| 361 | } | ||
| 362 | |||
| 363 | bool tollgate_core_session_is_expired(const void *session) | ||
| 364 | { | ||
| 365 | return tg_session_is_expired((const tg_session_t *)session); | ||
| 366 | } | ||
| 367 | |||
| 368 | void tollgate_core_firewall_grant(uint32_t client_ip) | ||
| 369 | { | ||
| 370 | tg_firewall_grant(client_ip); | ||
| 371 | } | ||
| 372 | |||
| 373 | void tollgate_core_firewall_revoke(uint32_t client_ip) | ||
| 374 | { | ||
| 375 | tg_firewall_revoke(client_ip); | ||
| 376 | } | ||
| 377 | |||
| 378 | int tollgate_core_firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, int mac_out_size) | ||
| 379 | { | ||
| 380 | return tg_firewall_get_mac_for_ip(client_ip, mac_out, mac_out_size); | ||
| 381 | } | ||
| 382 | |||
| 383 | int tollgate_core_cashu_decode(const char *token_str, void *out) | ||
| 384 | { | ||
| 385 | return tg_cashu_decode_token(token_str, (tg_cashu_token_t *)out); | ||
| 386 | } | ||
| 387 | |||
| 388 | int tollgate_core_cashu_check_states(const char *mint_url, const void *token, | ||
| 389 | void *states, int *state_count) | ||
| 390 | { | ||
| 391 | return tg_cashu_check_proof_states(mint_url, (const tg_cashu_token_t *)token, | ||
| 392 | (tg_cashu_proof_state_t *)states, state_count); | ||
| 393 | } | ||
| 394 | |||
| 395 | uint64_t tollgate_core_cashu_allotment(uint64_t amount, uint64_t price, uint64_t step_size) | ||
| 396 | { | ||
| 397 | return tg_cashu_calculate_allotment(amount, price, step_size); | ||
| 398 | } | ||
| 399 | |||
| 400 | bool tollgate_core_cashu_is_mint_accepted(const char *mint_url) | ||
| 401 | { | ||
| 402 | if (!s_platform) return false; | ||
| 403 | const char *accepted = s_platform->get_mint_url ? s_platform->get_mint_url() : NULL; | ||
| 404 | if (!accepted) return false; | ||
| 405 | if (s_platform->get_accepted_mint_count && s_platform->get_accepted_mint) { | ||
| 406 | int count = s_platform->get_accepted_mint_count(); | ||
| 407 | for (int i = 0; i < count; i++) { | ||
| 408 | if (tg_cashu_is_mint_accepted(mint_url, s_platform->get_accepted_mint(i))) | ||
| 409 | return true; | ||
| 410 | } | ||
| 411 | return false; | ||
| 412 | } | ||
| 413 | return tg_cashu_is_mint_accepted(mint_url, accepted); | ||
| 414 | } | ||
| 415 | |||
| 416 | const char *tollgate_core_cashu_token_mint(const void *token) | ||
| 417 | { | ||
| 418 | const tg_cashu_token_t *t = (const tg_cashu_token_t *)token; | ||
| 419 | return t->mint_url; | ||
| 420 | } | ||
| 421 | |||
| 422 | uint64_t tollgate_core_cashu_token_amount(const void *token) | ||
| 423 | { | ||
| 424 | const tg_cashu_token_t *t = (const tg_cashu_token_t *)token; | ||
| 425 | return t->total_amount; | ||
| 426 | } | ||
| 427 | |||
| 428 | void tollgate_core_mining_update_hashrate(uint32_t client_ip, bool accepted) | ||
| 429 | { | ||
| 430 | tg_mining_update_hashrate(client_ip, accepted); | ||
| 431 | } | ||
| 432 | |||
| 433 | const void *tollgate_core_mining_get_client_stats(uint32_t client_ip) | ||
| 434 | { | ||
| 435 | return tg_mining_get_client_stats(client_ip); | ||
| 436 | } | ||
| 437 | |||
| 438 | double tollgate_core_mining_get_hashprice(void) | ||
| 439 | { | ||
| 440 | return tg_mining_get_current_hashprice(); | ||
| 441 | } | ||
| 442 | |||
| 443 | uint64_t tollgate_core_mining_shares_to_allotment_ms(double hashrate, double hashprice, | ||
| 444 | int price, int step_ms) | ||
| 445 | { | ||
| 446 | return tg_mining_shares_to_allotment_ms(hashrate, hashprice, price, step_ms); | ||
| 447 | } | ||
| 448 | |||
| 449 | uint64_t tollgate_core_mining_shares_to_allotment_bytes(double hashrate, double hashprice, | ||
| 450 | int price, int step_bytes) | ||
| 451 | { | ||
| 452 | return tg_mining_shares_to_allotment_bytes(hashrate, hashprice, price, step_bytes); | ||
| 453 | } | ||
| 454 | |||
| 455 | void tollgate_core_mining_set_nbits(uint32_t nbits) | ||
| 456 | { | ||
| 457 | tg_mining_set_current_nbits(nbits); | ||
| 458 | } | ||
| 459 | |||
| 460 | int tollgate_core_dns_start(uint32_t upstream_dns) | ||
| 461 | { | ||
| 462 | (void)upstream_dns; | ||
| 463 | return -1; | ||
| 464 | } | ||
| 465 | |||
| 466 | void tollgate_core_dns_stop(void) { } | ||
diff --git a/tollgate_core/src/tollgate_firewall.c b/tollgate_core/src/tollgate_firewall.c deleted file mode 100644 index 8111be8..0000000 --- a/tollgate_core/src/tollgate_firewall.c +++ /dev/null | |||
| @@ -1,166 +0,0 @@ | |||
| 1 | #include "tollgate_firewall.h" | ||
| 2 | #include "tollgate_core.h" | ||
| 3 | #include "tollgate_platform.h" | ||
| 4 | #include <string.h> | ||
| 5 | #include <stdio.h> | ||
| 6 | |||
| 7 | #define FW_MAX_CLIENTS 10 | ||
| 8 | |||
| 9 | static const char *TAG = "tg_fw"; | ||
| 10 | static uint32_t s_ap_ip; | ||
| 11 | static uint16_t s_mining_port; | ||
| 12 | static bool s_sandbox_mint; | ||
| 13 | |||
| 14 | typedef struct { | ||
| 15 | uint32_t ip; | ||
| 16 | char mac[TG_FW_MAX_MAC_LEN]; | ||
| 17 | } fw_client_t; | ||
| 18 | |||
| 19 | static fw_client_t s_clients[FW_MAX_CLIENTS]; | ||
| 20 | static int s_client_count = 0; | ||
| 21 | |||
| 22 | static void log_fw(const char *verb, uint32_t client_ip, const char *mac) | ||
| 23 | { | ||
| 24 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 25 | if (p && p->log_info) { | ||
| 26 | char ip_str[16]; | ||
| 27 | snprintf(ip_str, sizeof(ip_str), "%d.%d.%d.%d", | ||
| 28 | (int)((client_ip >> 0) & 0xFF), (int)((client_ip >> 8) & 0xFF), | ||
| 29 | (int)((client_ip >> 16) & 0xFF), (int)((client_ip >> 24) & 0xFF)); | ||
| 30 | p->log_info(TAG, "%s %s mac=%s", verb, ip_str, mac ? mac : "unknown"); | ||
| 31 | } | ||
| 32 | } | ||
| 33 | |||
| 34 | int tg_firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, int mac_out_size) | ||
| 35 | { | ||
| 36 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 37 | if (!p) return -1; | ||
| 38 | |||
| 39 | if (p->mac_for_ip) { | ||
| 40 | if (p->mac_for_ip(client_ip, mac_out, mac_out_size)) { | ||
| 41 | return 0; | ||
| 42 | } | ||
| 43 | } | ||
| 44 | return -1; | ||
| 45 | } | ||
| 46 | |||
| 47 | int tg_firewall_init(uint32_t ap_ip) | ||
| 48 | { | ||
| 49 | s_ap_ip = ap_ip; | ||
| 50 | memset(s_clients, 0, sizeof(s_clients)); | ||
| 51 | s_client_count = 0; | ||
| 52 | s_mining_port = 0; | ||
| 53 | s_sandbox_mint = false; | ||
| 54 | |||
| 55 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 56 | if (p && p->napt_enable) p->napt_enable(ap_ip, true); | ||
| 57 | |||
| 58 | if (p && p->log_info) { | ||
| 59 | char ip_str[16]; | ||
| 60 | snprintf(ip_str, sizeof(ip_str), "%d.%d.%d.%d", | ||
| 61 | (int)((ap_ip >> 0) & 0xFF), (int)((ap_ip >> 8) & 0xFF), | ||
| 62 | (int)((ap_ip >> 16) & 0xFF), (int)((ap_ip >> 24) & 0xFF)); | ||
| 63 | p->log_info(TAG, "Firewall initialized AP=%s NAT on, per-client filter", ip_str); | ||
| 64 | } | ||
| 65 | return 0; | ||
| 66 | } | ||
| 67 | |||
| 68 | static fw_client_t *find_client_by_ip(uint32_t client_ip) | ||
| 69 | { | ||
| 70 | for (int i = 0; i < s_client_count; i++) { | ||
| 71 | if (s_clients[i].ip == client_ip) return &s_clients[i]; | ||
| 72 | } | ||
| 73 | return NULL; | ||
| 74 | } | ||
| 75 | |||
| 76 | static fw_client_t *find_client_by_mac(const char *mac) | ||
| 77 | { | ||
| 78 | for (int i = 0; i < s_client_count; i++) { | ||
| 79 | if (s_clients[i].mac[0] != '\0' && strcmp(s_clients[i].mac, mac) == 0) { | ||
| 80 | return &s_clients[i]; | ||
| 81 | } | ||
| 82 | } | ||
| 83 | return NULL; | ||
| 84 | } | ||
| 85 | |||
| 86 | void tg_firewall_grant(uint32_t client_ip) | ||
| 87 | { | ||
| 88 | fw_client_t *existing = find_client_by_ip(client_ip); | ||
| 89 | if (existing) return; | ||
| 90 | |||
| 91 | if (s_client_count >= FW_MAX_CLIENTS) { | ||
| 92 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 93 | if (p && p->log_warn) p->log_warn(TAG, "Max clients, cannot grant"); | ||
| 94 | return; | ||
| 95 | } | ||
| 96 | |||
| 97 | fw_client_t *c = &s_clients[s_client_count]; | ||
| 98 | c->ip = client_ip; | ||
| 99 | c->mac[0] = '\0'; | ||
| 100 | tg_firewall_get_mac_for_ip(client_ip, c->mac, sizeof(c->mac)); | ||
| 101 | s_client_count++; | ||
| 102 | |||
| 103 | log_fw("granted", client_ip, c->mac[0] ? c->mac : "unknown"); | ||
| 104 | } | ||
| 105 | |||
| 106 | void tg_firewall_revoke(uint32_t client_ip) | ||
| 107 | { | ||
| 108 | for (int i = 0; i < s_client_count; i++) { | ||
| 109 | if (s_clients[i].ip == client_ip) { | ||
| 110 | log_fw("revoked", client_ip, s_clients[i].mac[0] ? s_clients[i].mac : "unknown"); | ||
| 111 | s_clients[i] = s_clients[s_client_count - 1]; | ||
| 112 | s_client_count--; | ||
| 113 | return; | ||
| 114 | } | ||
| 115 | } | ||
| 116 | } | ||
| 117 | |||
| 118 | int tg_firewall_revoke_all(void) | ||
| 119 | { | ||
| 120 | s_client_count = 0; | ||
| 121 | memset(s_clients, 0, sizeof(s_clients)); | ||
| 122 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 123 | if (p && p->log_info) p->log_info(TAG, "All clients revoked"); | ||
| 124 | return 0; | ||
| 125 | } | ||
| 126 | |||
| 127 | bool tg_firewall_is_allowed(uint32_t client_ip) | ||
| 128 | { | ||
| 129 | return find_client_by_ip(client_ip) != NULL; | ||
| 130 | } | ||
| 131 | |||
| 132 | bool tg_firewall_is_mac_allowed(const char *mac) | ||
| 133 | { | ||
| 134 | return find_client_by_mac(mac) != NULL; | ||
| 135 | } | ||
| 136 | |||
| 137 | int tg_firewall_client_count(void) | ||
| 138 | { | ||
| 139 | return s_client_count; | ||
| 140 | } | ||
| 141 | |||
| 142 | void tg_firewall_set_mining_port(uint16_t port) | ||
| 143 | { | ||
| 144 | s_mining_port = port; | ||
| 145 | } | ||
| 146 | |||
| 147 | void tg_firewall_set_sandbox_mint_access(bool enable) | ||
| 148 | { | ||
| 149 | s_sandbox_mint = enable; | ||
| 150 | } | ||
| 151 | |||
| 152 | int tg_firewall_filter_packet(const uint8_t *payload, int payload_len) | ||
| 153 | { | ||
| 154 | if (payload_len < 20) return -1; | ||
| 155 | |||
| 156 | uint32_t src_ip = (uint32_t)payload[12] | ((uint32_t)payload[13] << 8) | | ||
| 157 | ((uint32_t)payload[14] << 16) | ((uint32_t)payload[15] << 24); | ||
| 158 | |||
| 159 | uint32_t ap_subnet = s_ap_ip & 0x00FFFFFF; | ||
| 160 | uint32_t src_subnet = src_ip & 0x00FFFFFF; | ||
| 161 | if (src_subnet != ap_subnet) return 1; | ||
| 162 | |||
| 163 | if (tg_firewall_is_allowed(src_ip)) return 1; | ||
| 164 | |||
| 165 | return 0; | ||
| 166 | } | ||
diff --git a/tollgate_core/src/tollgate_firewall.h b/tollgate_core/src/tollgate_firewall.h deleted file mode 100644 index 7df8a45..0000000 --- a/tollgate_core/src/tollgate_firewall.h +++ /dev/null | |||
| @@ -1,21 +0,0 @@ | |||
| 1 | #ifndef TOLLGATE_CORE_FIREWALL_H | ||
| 2 | #define TOLLGATE_CORE_FIREWALL_H | ||
| 3 | |||
| 4 | #include <stdint.h> | ||
| 5 | #include <stdbool.h> | ||
| 6 | |||
| 7 | #define TG_FW_MAX_MAC_LEN 18 | ||
| 8 | |||
| 9 | int tg_firewall_init(uint32_t ap_ip); | ||
| 10 | void tg_firewall_grant(uint32_t client_ip); | ||
| 11 | void tg_firewall_revoke(uint32_t client_ip); | ||
| 12 | int tg_firewall_revoke_all(void); | ||
| 13 | bool tg_firewall_is_allowed(uint32_t client_ip); | ||
| 14 | bool tg_firewall_is_mac_allowed(const char *mac); | ||
| 15 | int tg_firewall_client_count(void); | ||
| 16 | int tg_firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, int mac_out_size); | ||
| 17 | void tg_firewall_set_mining_port(uint16_t port); | ||
| 18 | void tg_firewall_set_sandbox_mint_access(bool enable); | ||
| 19 | int tg_firewall_filter_packet(const uint8_t *payload, int payload_len); | ||
| 20 | |||
| 21 | #endif | ||
diff --git a/tollgate_core/src/tollgate_mining.c b/tollgate_core/src/tollgate_mining.c deleted file mode 100644 index 8a4a778..0000000 --- a/tollgate_core/src/tollgate_mining.c +++ /dev/null | |||
| @@ -1,171 +0,0 @@ | |||
| 1 | #include "tollgate_mining.h" | ||
| 2 | #include "tollgate_core.h" | ||
| 3 | #include "tollgate_platform.h" | ||
| 4 | #include <string.h> | ||
| 5 | #include <math.h> | ||
| 6 | |||
| 7 | static const char *TAG = "tg_mining"; | ||
| 8 | |||
| 9 | static tg_mining_client_stats_t s_clients[TG_MINING_MAX_CLIENTS]; | ||
| 10 | static int s_client_count = 0; | ||
| 11 | static double s_current_hashprice = 0.0; | ||
| 12 | static uint32_t s_current_nbits = 0; | ||
| 13 | static uint64_t s_current_difficulty = 1; | ||
| 14 | |||
| 15 | static int64_t get_time_ms(void) | ||
| 16 | { | ||
| 17 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 18 | if (p && p->get_time_ms) return p->get_time_ms(); | ||
| 19 | return 0; | ||
| 20 | } | ||
| 21 | |||
| 22 | uint64_t tg_mining_nbits_to_difficulty(uint32_t nbits) | ||
| 23 | { | ||
| 24 | if (nbits == 0) return (uint64_t)-1; | ||
| 25 | |||
| 26 | uint32_t exponent = (nbits >> 24) & 0xFF; | ||
| 27 | uint32_t mantissa = nbits & 0x007FFFFF; | ||
| 28 | |||
| 29 | if (exponent <= 3) { | ||
| 30 | mantissa >>= (8 * (3 - exponent)); | ||
| 31 | if (mantissa == 0) return (uint64_t)-1; | ||
| 32 | return 0x00000000FFFF0000ULL / mantissa; | ||
| 33 | } | ||
| 34 | |||
| 35 | uint64_t target = (uint64_t)mantissa << (8 * (exponent - 3)); | ||
| 36 | if (target == 0) return (uint64_t)-1; | ||
| 37 | |||
| 38 | uint64_t pdiff = 0x00000000FFFF0000ULL; | ||
| 39 | uint64_t diff = pdiff / target; | ||
| 40 | if (diff == 0) diff = 1; | ||
| 41 | return diff; | ||
| 42 | } | ||
| 43 | |||
| 44 | double tg_mining_calculate_hashprice(uint32_t nbits) | ||
| 45 | { | ||
| 46 | uint64_t diff = tg_mining_nbits_to_difficulty(nbits); | ||
| 47 | if (diff == 0 || diff == (uint64_t)-1) return 0.0; | ||
| 48 | |||
| 49 | double network_hashrate_th = (double)diff * 4294967296.0 / 1e12; | ||
| 50 | double daily_sats = (double)TG_MINING_BLOCK_SUBSIDY_SATS * (double)TG_MINING_BLOCKS_PER_DAY; | ||
| 51 | double sats_per_th_day = daily_sats / network_hashrate_th; | ||
| 52 | return sats_per_th_day / 1000.0; | ||
| 53 | } | ||
| 54 | |||
| 55 | double tg_mining_calculate_hashprice_override(uint64_t sats_per_ghs_day) | ||
| 56 | { | ||
| 57 | return (double)sats_per_ghs_day; | ||
| 58 | } | ||
| 59 | |||
| 60 | int tg_mining_validate_share(const uint8_t *header80, uint32_t nonce, const uint8_t *target, int target_len) | ||
| 61 | { | ||
| 62 | (void)header80; | ||
| 63 | (void)nonce; | ||
| 64 | (void)target; | ||
| 65 | (void)target_len; | ||
| 66 | return 0; | ||
| 67 | } | ||
| 68 | |||
| 69 | uint64_t tg_mining_shares_to_allotment_ms(double hashrate_ghs, double hashprice_sats_per_ghs_s, | ||
| 70 | int price_per_step, int step_size_ms) | ||
| 71 | { | ||
| 72 | if (hashrate_ghs <= 0.0 || hashprice_sats_per_ghs_s <= 0.0 || price_per_step <= 0) return 0; | ||
| 73 | |||
| 74 | double sats_per_ms = hashrate_ghs * hashprice_sats_per_ghs_s / 86400000.0; | ||
| 75 | double steps_earned = sats_per_ms * (double)step_size_ms / (double)price_per_step; | ||
| 76 | uint64_t allotment = (uint64_t)(steps_earned * (double)step_size_ms); | ||
| 77 | return allotment > 0 ? allotment : 1; | ||
| 78 | } | ||
| 79 | |||
| 80 | uint64_t tg_mining_shares_to_allotment_bytes(double hashrate_ghs, double hashprice_sats_per_ghs_s, | ||
| 81 | int price_per_step, int step_size_bytes) | ||
| 82 | { | ||
| 83 | if (hashrate_ghs <= 0.0 || hashprice_sats_per_ghs_s <= 0.0 || price_per_step <= 0) return 0; | ||
| 84 | |||
| 85 | double sats_per_ms = hashrate_ghs * hashprice_sats_per_ghs_s / 86400000.0; | ||
| 86 | double steps_earned = sats_per_ms * 1000.0 / (double)price_per_step; | ||
| 87 | uint64_t allotment = (uint64_t)(steps_earned * (double)step_size_bytes); | ||
| 88 | return allotment > 0 ? allotment : 1; | ||
| 89 | } | ||
| 90 | |||
| 91 | tg_mining_client_stats_t *tg_mining_get_or_create_client(uint32_t client_ip) | ||
| 92 | { | ||
| 93 | for (int i = 0; i < s_client_count; i++) { | ||
| 94 | if (s_clients[i].ip == client_ip) return &s_clients[i]; | ||
| 95 | } | ||
| 96 | |||
| 97 | if (s_client_count >= TG_MINING_MAX_CLIENTS) { | ||
| 98 | for (int i = 0; i < TG_MINING_MAX_CLIENTS; i++) { | ||
| 99 | int64_t age = get_time_ms() - s_clients[i].last_share_time_ms; | ||
| 100 | if (age > TG_MINING_SHARE_WINDOW_S * 2000) { | ||
| 101 | memset(&s_clients[i], 0, sizeof(tg_mining_client_stats_t)); | ||
| 102 | s_clients[i].ip = client_ip; | ||
| 103 | s_clients[i].first_share_time_ms = get_time_ms(); | ||
| 104 | return &s_clients[i]; | ||
| 105 | } | ||
| 106 | } | ||
| 107 | return NULL; | ||
| 108 | } | ||
| 109 | |||
| 110 | tg_mining_client_stats_t *c = &s_clients[s_client_count]; | ||
| 111 | memset(c, 0, sizeof(tg_mining_client_stats_t)); | ||
| 112 | c->ip = client_ip; | ||
| 113 | c->first_share_time_ms = get_time_ms(); | ||
| 114 | s_client_count++; | ||
| 115 | return c; | ||
| 116 | } | ||
| 117 | |||
| 118 | void tg_mining_update_hashrate(uint32_t client_ip, bool accepted) | ||
| 119 | { | ||
| 120 | tg_mining_client_stats_t *stats = tg_mining_get_or_create_client(client_ip); | ||
| 121 | if (!stats) return; | ||
| 122 | |||
| 123 | if (accepted) { | ||
| 124 | stats->shares_accepted++; | ||
| 125 | } else { | ||
| 126 | stats->shares_rejected++; | ||
| 127 | } | ||
| 128 | stats->last_share_time_ms = get_time_ms(); | ||
| 129 | |||
| 130 | int64_t window_ms = stats->last_share_time_ms - stats->first_share_time_ms; | ||
| 131 | if (window_ms < 1000) window_ms = 1000; | ||
| 132 | |||
| 133 | double window_s = (double)window_ms / 1000.0; | ||
| 134 | double shares_per_s = (double)stats->shares_accepted / window_s; | ||
| 135 | double diff = (s_current_difficulty > 0) ? (double)s_current_difficulty : 1.0; | ||
| 136 | stats->hashrate_ghs = shares_per_s * diff * 4294967296.0 / 1e9; | ||
| 137 | } | ||
| 138 | |||
| 139 | const tg_mining_client_stats_t *tg_mining_get_client_stats(uint32_t client_ip) | ||
| 140 | { | ||
| 141 | for (int i = 0; i < s_client_count; i++) { | ||
| 142 | if (s_clients[i].ip == client_ip) return &s_clients[i]; | ||
| 143 | } | ||
| 144 | return NULL; | ||
| 145 | } | ||
| 146 | |||
| 147 | double tg_mining_get_current_hashprice(void) | ||
| 148 | { | ||
| 149 | return s_current_hashprice; | ||
| 150 | } | ||
| 151 | |||
| 152 | void tg_mining_set_current_nbits(uint32_t nbits) | ||
| 153 | { | ||
| 154 | s_current_nbits = nbits; | ||
| 155 | s_current_difficulty = tg_mining_nbits_to_difficulty(nbits); | ||
| 156 | s_current_hashprice = tg_mining_calculate_hashprice(nbits); | ||
| 157 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 158 | if (p && p->log_info) p->log_info(TAG, "nbits: 0x%08lx, diff=%llu, hashprice=%.6f sat/GH/s/day", | ||
| 159 | (unsigned long)nbits, (unsigned long long)s_current_difficulty, s_current_hashprice); | ||
| 160 | } | ||
| 161 | |||
| 162 | void tg_mining_init(void) | ||
| 163 | { | ||
| 164 | memset(s_clients, 0, sizeof(s_clients)); | ||
| 165 | s_client_count = 0; | ||
| 166 | s_current_hashprice = 0.0; | ||
| 167 | s_current_nbits = 0; | ||
| 168 | s_current_difficulty = 1; | ||
| 169 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 170 | if (p && p->log_info) p->log_info(TAG, "Mining payment initialized"); | ||
| 171 | } | ||
diff --git a/tollgate_core/src/tollgate_mining.h b/tollgate_core/src/tollgate_mining.h deleted file mode 100644 index 39681a5..0000000 --- a/tollgate_core/src/tollgate_mining.h +++ /dev/null | |||
| @@ -1,34 +0,0 @@ | |||
| 1 | #ifndef TOLLGATE_CORE_MINING_H | ||
| 2 | #define TOLLGATE_CORE_MINING_H | ||
| 3 | |||
| 4 | #include <stdint.h> | ||
| 5 | #include <stdbool.h> | ||
| 6 | |||
| 7 | #define TG_MINING_SHARE_WINDOW_S 30 | ||
| 8 | #define TG_MINING_BLOCK_SUBSIDY_SATS 312500000ULL | ||
| 9 | #define TG_MINING_BLOCKS_PER_DAY 144ULL | ||
| 10 | #define TG_MINING_MAX_CLIENTS 10 | ||
| 11 | |||
| 12 | typedef struct { | ||
| 13 | uint32_t ip; | ||
| 14 | uint64_t shares_accepted; | ||
| 15 | uint64_t shares_rejected; | ||
| 16 | int64_t first_share_time_ms; | ||
| 17 | int64_t last_share_time_ms; | ||
| 18 | double hashrate_ghs; | ||
| 19 | } tg_mining_client_stats_t; | ||
| 20 | |||
| 21 | uint64_t tg_mining_nbits_to_difficulty(uint32_t nbits); | ||
| 22 | double tg_mining_calculate_hashprice(uint32_t nbits); | ||
| 23 | double tg_mining_calculate_hashprice_override(uint64_t sats_per_ghs_day); | ||
| 24 | int tg_mining_validate_share(const uint8_t *header80, uint32_t nonce, const uint8_t *target, int target_len); | ||
| 25 | uint64_t tg_mining_shares_to_allotment_ms(double hashrate_ghs, double hashprice, int price, int step_ms); | ||
| 26 | uint64_t tg_mining_shares_to_allotment_bytes(double hashrate_ghs, double hashprice, int price, int step_bytes); | ||
| 27 | tg_mining_client_stats_t *tg_mining_get_or_create_client(uint32_t client_ip); | ||
| 28 | void tg_mining_update_hashrate(uint32_t client_ip, bool accepted); | ||
| 29 | const tg_mining_client_stats_t *tg_mining_get_client_stats(uint32_t client_ip); | ||
| 30 | double tg_mining_get_current_hashprice(void); | ||
| 31 | void tg_mining_set_current_nbits(uint32_t nbits); | ||
| 32 | void tg_mining_init(void); | ||
| 33 | |||
| 34 | #endif | ||
diff --git a/tollgate_core/src/tollgate_session.c b/tollgate_core/src/tollgate_session.c deleted file mode 100644 index 667dbd0..0000000 --- a/tollgate_core/src/tollgate_session.c +++ /dev/null | |||
| @@ -1,220 +0,0 @@ | |||
| 1 | #include "tollgate_session.h" | ||
| 2 | #include "tollgate_core.h" | ||
| 3 | #include "tollgate_platform.h" | ||
| 4 | #include "tollgate_firewall.h" | ||
| 5 | #include <string.h> | ||
| 6 | #include <stdio.h> | ||
| 7 | |||
| 8 | static const char *TAG = "tg_session"; | ||
| 9 | static tg_session_t s_sessions[TG_SESSION_MAX_CLIENTS]; | ||
| 10 | static int s_session_count = 0; | ||
| 11 | |||
| 12 | static void format_ip(uint32_t ip, char *buf, int buf_len) | ||
| 13 | { | ||
| 14 | snprintf(buf, buf_len, "%d.%d.%d.%d", | ||
| 15 | (int)((ip >> 0) & 0xFF), (int)((ip >> 8) & 0xFF), | ||
| 16 | (int)((ip >> 16) & 0xFF), (int)((ip >> 24) & 0xFF)); | ||
| 17 | } | ||
| 18 | |||
| 19 | static int64_t get_time_ms(void) | ||
| 20 | { | ||
| 21 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 22 | if (p && p->get_time_ms) return p->get_time_ms(); | ||
| 23 | return 0; | ||
| 24 | } | ||
| 25 | |||
| 26 | static void log_session(const char *verb, uint32_t client_ip, const char *mac, const char *detail) | ||
| 27 | { | ||
| 28 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 29 | if (p && p->log_info) { | ||
| 30 | char ip_str[16]; | ||
| 31 | format_ip(client_ip, ip_str, sizeof(ip_str)); | ||
| 32 | p->log_info(TAG, "%s: %s mac=%s %s", verb, ip_str, mac ? mac : "unknown", detail ? detail : ""); | ||
| 33 | } | ||
| 34 | } | ||
| 35 | |||
| 36 | int tg_session_init(void) | ||
| 37 | { | ||
| 38 | memset(s_sessions, 0, sizeof(s_sessions)); | ||
| 39 | s_session_count = 0; | ||
| 40 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 41 | if (p && p->log_info) p->log_info(TAG, "Session manager initialized"); | ||
| 42 | return 0; | ||
| 43 | } | ||
| 44 | |||
| 45 | static void populate_mac(tg_session_t *session, uint32_t client_ip) | ||
| 46 | { | ||
| 47 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 48 | if (p && p->mac_for_ip) { | ||
| 49 | if (!p->mac_for_ip(client_ip, session->mac, sizeof(session->mac))) { | ||
| 50 | session->mac[0] = '\0'; | ||
| 51 | } | ||
| 52 | } else { | ||
| 53 | session->mac[0] = '\0'; | ||
| 54 | } | ||
| 55 | } | ||
| 56 | |||
| 57 | tg_session_t *tg_session_create(uint32_t client_ip, uint64_t allotment_ms) | ||
| 58 | { | ||
| 59 | tg_session_t *existing = tg_session_find_by_ip(client_ip); | ||
| 60 | if (existing) { | ||
| 61 | tg_session_extend(existing, allotment_ms); | ||
| 62 | return existing; | ||
| 63 | } | ||
| 64 | |||
| 65 | if (s_session_count >= TG_SESSION_MAX_CLIENTS) { | ||
| 66 | for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) { | ||
| 67 | if (!s_sessions[i].active || tg_session_is_expired(&s_sessions[i])) { | ||
| 68 | tg_session_revoke(&s_sessions[i]); | ||
| 69 | break; | ||
| 70 | } | ||
| 71 | } | ||
| 72 | } | ||
| 73 | |||
| 74 | for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) { | ||
| 75 | if (!s_sessions[i].active) { | ||
| 76 | s_sessions[i].client_ip = client_ip; | ||
| 77 | s_sessions[i].allotment_ms = allotment_ms; | ||
| 78 | s_sessions[i].start_time_ms = get_time_ms(); | ||
| 79 | s_sessions[i].active = true; | ||
| 80 | s_sessions[i].payment_method = TG_PAYMENT_CASHU; | ||
| 81 | populate_mac(&s_sessions[i], client_ip); | ||
| 82 | |||
| 83 | s_session_count++; | ||
| 84 | tg_firewall_grant(client_ip); | ||
| 85 | |||
| 86 | char detail[64]; | ||
| 87 | snprintf(detail, sizeof(detail), "allotment=%llums", (unsigned long long)allotment_ms); | ||
| 88 | log_session("created", client_ip, | ||
| 89 | s_sessions[i].mac[0] ? s_sessions[i].mac : "unknown", detail); | ||
| 90 | return &s_sessions[i]; | ||
| 91 | } | ||
| 92 | } | ||
| 93 | |||
| 94 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 95 | if (p && p->log_warn) p->log_warn(TAG, "No free session slots"); | ||
| 96 | return NULL; | ||
| 97 | } | ||
| 98 | |||
| 99 | tg_session_t *tg_session_create_bytes(uint32_t client_ip, uint64_t allotment_bytes) | ||
| 100 | { | ||
| 101 | tg_session_t *s = tg_session_create(client_ip, 0); | ||
| 102 | if (s) { | ||
| 103 | s->allotment_bytes = allotment_bytes; | ||
| 104 | s->bytes_consumed = 0; | ||
| 105 | s->allotment_ms = (uint64_t)-1; | ||
| 106 | s->payment_method = TG_PAYMENT_BYTES; | ||
| 107 | char detail[64]; | ||
| 108 | snprintf(detail, sizeof(detail), "allotment=%llu bytes", (unsigned long long)allotment_bytes); | ||
| 109 | log_session("bytes session", client_ip, s->mac[0] ? s->mac : "unknown", detail); | ||
| 110 | } | ||
| 111 | return s; | ||
| 112 | } | ||
| 113 | |||
| 114 | void tg_session_add_bytes(uint32_t client_ip, uint64_t bytes) | ||
| 115 | { | ||
| 116 | tg_session_t *s = tg_session_find_by_ip(client_ip); | ||
| 117 | if (s && s->active) { | ||
| 118 | s->bytes_consumed += bytes; | ||
| 119 | } | ||
| 120 | } | ||
| 121 | |||
| 122 | tg_session_t *tg_session_find_by_ip(uint32_t client_ip) | ||
| 123 | { | ||
| 124 | for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) { | ||
| 125 | if (s_sessions[i].active && s_sessions[i].client_ip == client_ip) { | ||
| 126 | return &s_sessions[i]; | ||
| 127 | } | ||
| 128 | } | ||
| 129 | return NULL; | ||
| 130 | } | ||
| 131 | |||
| 132 | tg_session_t *tg_session_find_by_mac(const char *mac) | ||
| 133 | { | ||
| 134 | for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) { | ||
| 135 | if (s_sessions[i].active && s_sessions[i].mac[0] != '\0' && | ||
| 136 | strcmp(s_sessions[i].mac, mac) == 0) { | ||
| 137 | return &s_sessions[i]; | ||
| 138 | } | ||
| 139 | } | ||
| 140 | return NULL; | ||
| 141 | } | ||
| 142 | |||
| 143 | void tg_session_extend(tg_session_t *session, uint64_t additional_ms) | ||
| 144 | { | ||
| 145 | if (!session || !session->active) return; | ||
| 146 | session->allotment_ms += additional_ms; | ||
| 147 | char detail[64]; | ||
| 148 | snprintf(detail, sizeof(detail), "+%llums (total=%llu)", | ||
| 149 | (unsigned long long)additional_ms, (unsigned long long)session->allotment_ms); | ||
| 150 | log_session("extended", session->client_ip, | ||
| 151 | session->mac[0] ? session->mac : "unknown", detail); | ||
| 152 | } | ||
| 153 | |||
| 154 | bool tg_session_is_expired(const tg_session_t *session) | ||
| 155 | { | ||
| 156 | if (!session || !session->active) return true; | ||
| 157 | |||
| 158 | const tollgate_platform_t *p = tollgate_core_get_platform(); | ||
| 159 | if (p && p->get_metric) { | ||
| 160 | const char *metric = p->get_metric(); | ||
| 161 | if (metric && strcmp(metric, "bytes") == 0) { | ||
| 162 | return session->bytes_consumed >= session->allotment_bytes; | ||
| 163 | } | ||
| 164 | } | ||
| 165 | |||
| 166 | int64_t elapsed = get_time_ms() - session->start_time_ms; | ||
| 167 | return elapsed >= (int64_t)session->allotment_ms; | ||
| 168 | } | ||
| 169 | |||
| 170 | static void check_expiry(void) | ||
| 171 | { | ||
| 172 | for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) { | ||
| 173 | if (s_sessions[i].active && tg_session_is_expired(&s_sessions[i])) { | ||
| 174 | log_session("expired", s_sessions[i].client_ip, | ||
| 175 | s_sessions[i].mac[0] ? s_sessions[i].mac : "unknown", NULL); | ||
| 176 | tg_session_revoke(&s_sessions[i]); | ||
| 177 | } | ||
| 178 | } | ||
| 179 | } | ||
| 180 | |||
| 181 | void tg_session_revoke(tg_session_t *session) | ||
| 182 | { | ||
| 183 | if (!session || !session->active) return; | ||
| 184 | tg_firewall_revoke(session->client_ip); | ||
| 185 | session->active = false; | ||
| 186 | s_session_count--; | ||
| 187 | } | ||
| 188 | |||
| 189 | void tg_session_revoke_all(void) | ||
| 190 | { | ||
| 191 | for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) { | ||
| 192 | if (s_sessions[i].active) { | ||
| 193 | tg_session_revoke(&s_sessions[i]); | ||
| 194 | } | ||
| 195 | } | ||
| 196 | } | ||
| 197 | |||
| 198 | int tg_session_active_count(void) | ||
| 199 | { | ||
| 200 | int count = 0; | ||
| 201 | for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) { | ||
| 202 | if (s_sessions[i].active) count++; | ||
| 203 | } | ||
| 204 | return count; | ||
| 205 | } | ||
| 206 | |||
| 207 | void tg_session_tick(void) | ||
| 208 | { | ||
| 209 | check_expiry(); | ||
| 210 | } | ||
| 211 | |||
| 212 | tg_session_t *tg_session_get_array(void) | ||
| 213 | { | ||
| 214 | return s_sessions; | ||
| 215 | } | ||
| 216 | |||
| 217 | int tg_session_get_array_size(void) | ||
| 218 | { | ||
| 219 | return TG_SESSION_MAX_CLIENTS; | ||
| 220 | } | ||
diff --git a/tollgate_core/src/tollgate_session.h b/tollgate_core/src/tollgate_session.h deleted file mode 100644 index 4008b24..0000000 --- a/tollgate_core/src/tollgate_session.h +++ /dev/null | |||
| @@ -1,42 +0,0 @@ | |||
| 1 | #ifndef TOLLGATE_CORE_SESSION_H | ||
| 2 | #define TOLLGATE_CORE_SESSION_H | ||
| 3 | |||
| 4 | #include <stdint.h> | ||
| 5 | #include <stdbool.h> | ||
| 6 | |||
| 7 | #define TG_SESSION_MAX_CLIENTS 10 | ||
| 8 | #define TG_SESSION_MAX_MAC_LEN 18 | ||
| 9 | |||
| 10 | typedef enum { | ||
| 11 | TG_PAYMENT_CASHU, | ||
| 12 | TG_PAYMENT_MINING, | ||
| 13 | TG_PAYMENT_BYTES | ||
| 14 | } tg_payment_method_t; | ||
| 15 | |||
| 16 | typedef struct { | ||
| 17 | uint32_t client_ip; | ||
| 18 | char mac[TG_SESSION_MAX_MAC_LEN]; | ||
| 19 | uint64_t allotment_ms; | ||
| 20 | int64_t start_time_ms; | ||
| 21 | uint64_t allotment_bytes; | ||
| 22 | uint64_t bytes_consumed; | ||
| 23 | tg_payment_method_t payment_method; | ||
| 24 | bool active; | ||
| 25 | } tg_session_t; | ||
| 26 | |||
| 27 | int tg_session_init(void); | ||
| 28 | tg_session_t *tg_session_create(uint32_t client_ip, uint64_t allotment_ms); | ||
| 29 | tg_session_t *tg_session_create_bytes(uint32_t client_ip, uint64_t allotment_bytes); | ||
| 30 | void tg_session_add_bytes(uint32_t client_ip, uint64_t bytes); | ||
| 31 | tg_session_t *tg_session_find_by_ip(uint32_t client_ip); | ||
| 32 | tg_session_t *tg_session_find_by_mac(const char *mac); | ||
| 33 | void tg_session_extend(tg_session_t *session, uint64_t additional_ms); | ||
| 34 | bool tg_session_is_expired(const tg_session_t *session); | ||
| 35 | void tg_session_revoke(tg_session_t *session); | ||
| 36 | void tg_session_revoke_all(void); | ||
| 37 | int tg_session_active_count(void); | ||
| 38 | void tg_session_tick(void); | ||
| 39 | tg_session_t *tg_session_get_array(void); | ||
| 40 | int tg_session_get_array_size(void); | ||
| 41 | |||
| 42 | #endif | ||