upleb.uk

Public git repos — served from a NIP-34 GRASP relay at git.upleb.uk

summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorYour Name <you@example.com>2026-05-23 04:50:26 +0530
committerYour Name <you@example.com>2026-05-23 04:50:26 +0530
commit9330b01c28aebc865a3c0a51df8730196cb4152e (patch)
tree60c3ae35b2550c737c228e81fd342c8d07af11af
parent851801f50f1282ab1db5f8a241dbd245f59e447e (diff)
Phase 6a-6d: Consolidate and clean up
6a: Delete dead standalone tollgate_core/ (12 files, never compiled) 6b: Rewrite dns_server.c as thin shim to component's tollgate_core_dns - Fix component DNS to bind to AP IP instead of INADDR_ANY 6c: Rewrite stratum_proxy.c as thin shim with struct cast to component types 6d: Move sandbox logic into component's tollgate_core_firewall - Add tollgate_core_fw_set_sandbox_ports/set_sandbox_mint_access - Add is_sandbox_allowed() to component's ip4_canforward_filter - Clean main/firewall.c to delegate filter to component - Remove redundant DNS auth double-calls from main firewall Add ROADMAP.md with full extraction plan and checklists All 21 unit tests pass. ESP-IDF build passes.
-rw-r--r--ROADMAP.md262
-rw-r--r--components/tollgate_core/src/tollgate_core_dns.c2
-rw-r--r--components/tollgate_core/src/tollgate_core_firewall.c47
-rw-r--r--components/tollgate_core/src/tollgate_core_firewall.h2
-rw-r--r--main/dns_server.c304
-rw-r--r--main/firewall.c72
-rw-r--r--main/stratum_proxy.c145
-rwxr-xr-xtests/unit/test_firewall_sandboxbin30568 -> 111016 bytes
-rwxr-xr-xtests/unit/test_mining_paymentbin28664 -> 111000 bytes
-rwxr-xr-xtests/unit/test_session_payment_methodbin54680 -> 117880 bytes
-rwxr-xr-xtests/unit/test_stratum_proxybin40784 -> 113304 bytes
-rw-r--r--tollgate_core/CMakeLists.txt28
-rw-r--r--tollgate_core/include/tollgate_core.h90
-rw-r--r--tollgate_core/include/tollgate_platform.h68
-rw-r--r--tollgate_core/src/tollgate_cashu.c253
-rw-r--r--tollgate_core/src/tollgate_cashu.h40
-rw-r--r--tollgate_core/src/tollgate_core.c466
-rw-r--r--tollgate_core/src/tollgate_firewall.c166
-rw-r--r--tollgate_core/src/tollgate_firewall.h21
-rw-r--r--tollgate_core/src/tollgate_mining.c171
-rw-r--r--tollgate_core/src/tollgate_mining.h34
-rw-r--r--tollgate_core/src/tollgate_session.c220
-rw-r--r--tollgate_core/src/tollgate_session.h42
23 files changed, 329 insertions, 2104 deletions
diff --git a/ROADMAP.md b/ROADMAP.md
new file mode 100644
index 0000000..b4fe16b
--- /dev/null
+++ b/ROADMAP.md
@@ -0,0 +1,262 @@
1# TollGate Core Extraction Roadmap
2
3**Branch:** `feature/tollgate-core-v2`
4**Start commit:** `851801f` (Phase 5 complete, hardware-verified)
5**Goal:** Extract all portable TollGate business logic into `components/tollgate_core/` for reuse in NerdQAxePlus and other ESP32 firmware.
6
7## Testing Protocol
8
9After **every** step:
10
111. `make test-unit` -- all 21+ unit tests must pass
122. `idf.py build` -- ESP-IDF build must succeed
133. After multi-step phases: flash Board A + `pytest tests/test_smoke.py --board=a`
14
15---
16
17## Phase 6: Consolidate & Clean Up
18
19### 6a. Delete standalone `tollgate_core/`
20
21Dead code -- nothing in the build references it. The component version is what's compiled.
22
23- [ ] `git rm -r tollgate_core/`
24- [ ] Verify nothing references it: `grep -r "tollgate_core/" main/ components/ tests/`
25- [ ] Test: `make test-unit` + `idf.py build`
26
27### 6b. Eliminate `dns_server.c` duplication
28
29`main/dns_server.c` (316 lines) duplicates `components/tollgate_core/src/tollgate_core_dns.c`.
30
31- [ ] Rewrite `main/dns_server.c` as thin shim: `dns_server_*()` calls `tollgate_core_dns_*()`
32- [ ] Update `main/dns_server.h` to keep original function signatures
33- [ ] Move `dns_server_set_client_authenticated()` notification to component's internal DNS
34- [ ] Add unit test for DNS shim if not covered by existing `test_firewall_sandbox`
35- [ ] Test: `make test-unit` + `idf.py build` + flash + pytest smoke
36
37### 6c. Eliminate `stratum_proxy.c` duplication
38
39`main/stratum_proxy.c` (160 lines) duplicates `components/tollgate_core/src/tollgate_core_stratum_proxy.c`.
40
41- [ ] Rewrite `main/stratum_proxy.c` as thin shim: `stratum_proxy_*()` -> `tollgate_core_stratum_proxy_*()`
42- [ ] Update `main/stratum_proxy.h` to keep original type names for backward compat
43- [ ] Test: `make test-unit` + `idf.py build`
44
45### 6d. Move sandbox logic into component firewall
46
47`main/firewall.c` has `is_sandbox_allowed()` (allows TCP to ports 80/2121/mining_port for unauth clients) -- missing from component.
48
49- [ ] Add `tollgate_core_fw_set_sandbox_ports()` to component's firewall API
50- [ ] Add `tollgate_core_fw_is_sandbox_allowed()` to component's internal firewall
51- [ ] Update component's `tollgate_core_ip4_canforward_filter` to check sandbox rules
52- [ ] Update `main/firewall.c` shim to call `tollgate_core_fw_set_sandbox_ports()` in init
53- [ ] Add unit test for sandbox logic with known port combinations
54- [ ] Test: `make test-unit` + `idf.py build` + flash + `pytest tests/test_dns_firewall.py --board=a`
55
56### 6e. Break `mint_health` <-> `tollgate_api` circular dependency
57
58`mint_health.c` includes `tollgate_api.h` for `tls_worker_set_queue()`. `tollgate_api.c` includes `mint_health.h` for `mint_health_get_all()`.
59
60- [ ] Extract `QueueHandle_t tls_worker_queue` into a shared module (e.g., `tls_worker.h/c`)
61- [ ] `mint_health.c` includes `tls_worker.h` instead of `tollgate_api.h`
62- [ ] `tollgate_api.c` includes `tls_worker.h` to get the queue
63- [ ] Test: `make test-unit` + `idf.py build`
64
65### 6f. Break `config.h` -> `lightning_payout.h` reverse dependency
66
67`config.h` includes `lightning_payout.h` for `payout_config_t` type.
68
69- [ ] Move `payout_config_t` typedef to `config.h` (or a shared `tollgate_types.h`)
70- [ ] Remove `#include "lightning_payout.h"` from `config.h`
71- [ ] Add `#include "config.h"` to `lightning_payout.c` if needed
72- [ ] Test: `make test-unit` + `idf.py build` + **commit + push**
73
74---
75
76## Phase 7: Eliminate Shim Files
77
78Remove thin wrappers. Consumers use component headers directly.
79
80### 7a. Remove `session.c` / `session.h` shim
81
82- [ ] Update `tollgate_api.c`: `#include "tollgate_core_session.h"` instead of `#include "session.h"`
83- [ ] Update `captive_portal.c`: same
84- [ ] Update any other consumers of `session.h`
85- [ ] Delete `main/session.c` and `main/session.h`
86- [ ] Remove from `main/CMakeLists.txt` SRCS
87- [ ] Update unit test Makefile if needed
88- [ ] Test: `make test-unit` + `idf.py build`
89
90### 7b. Remove `cashu.c` / `cashu.h` shim
91
92- [ ] Update `tollgate_api.c`: `#include "tollgate_core_cashu.h"` instead of `#include "cashu.h"`
93- [ ] Move multi-mint logic (iterating `accepted_mints[]`) into component's `tollgate_core_cashu_is_mint_accepted()`
94- [ ] Delete `main/cashu.c` and `main/cashu.h`
95- [ ] Remove from `main/CMakeLists.txt` SRCS
96- [ ] Test: `make test-unit` + `idf.py build`
97
98### 7c. Remove `mining_payment.c` / `mining_payment.h` shim
99
100- [ ] Update all consumers: `#include "tollgate_core_mining.h"` instead of `#include "mining_payment.h"`
101- [ ] Delete `main/mining_payment.c` and `main/mining_payment.h`
102- [ ] Remove from `main/CMakeLists.txt` SRCS
103- [ ] Test: `make test-unit` + `idf.py build`
104
105### 7d. Remove `firewall.c` / `firewall.h` shim
106
107After 6d, firewall shim only has lwIP hook registration + DNS notification.
108
109- [ ] Move lwIP hook registration into `tollgate_main.c` or a new `main/esp_hooks.c`
110- [ ] Update consumers to use `tollgate_core_fw_*()` directly
111- [ ] Delete `main/firewall.c` and `main/firewall.h`
112- [ ] Remove from `main/CMakeLists.txt` SRCS
113- [ ] Test: `make test-unit` + `idf.py build` + flash + pytest smoke + DNS/firewall tests
114- [ ] **Commit + push**
115
116---
117
118## Phase 8: Extract Layer 1 into Component
119
120### 8a. Extract `beacon_price.c` -> `tollgate_core_beacon.c`
121
122Dependencies: `config`, `identity`, `esp_wifi`, `mbedtls/sha256`
123
124- [ ] Create `components/tollgate_core/src/tollgate_core_beacon.c/h`
125- [ ] Abstract WiFi vendor IE API via `tollgate_platform_t` callbacks: `set_vendor_ie()`, `scan_start()`
126- [ ] Move mint URL + npub hashing, geohash embedding, IE construction to component
127- [ ] Rewrite `main/beacon_price.c` as thin ESP-specific glue calling component
128- [ ] Add unit test with known IE vectors
129- [ ] Test: `make test-unit` + `idf.py build`
130
131### 8b. Extract `market.c` -> `tollgate_core_market.c`
132
133Dependencies: `beacon_price`, `config`, `identity`, `esp_wifi`
134
135- [ ] Create `components/tollgate_core/src/tollgate_core_market.c/h`
136- [ ] Abstract WiFi scan results via platform callback: `on_scan_result()`
137- [ ] Move market entry table, price comparison, cheapest selection to component
138- [ ] Rewrite `main/market.c` as thin glue
139- [ ] Add unit test for market table operations
140- [ ] Test: `make test-unit` + `idf.py build`
141
142### 8c. Extract `captive_portal.c` -> `tollgate_core_portal.c`
143
144Dependencies: `firewall`, `session`, `config`, `mining_payment`, `stratum_proxy`, `esp_http_server`
145
146- [ ] Create `components/tollgate_core/src/tollgate_core_portal.c/h`
147- [ ] Extract template rendering logic (HTML generation, `__AP_IP__`/`__PRICE__` substitution)
148- [ ] Extract captive detection URI handling (generate_204, hotspot-detect, success.txt, etc.)
149- [ ] Extract payment processing flow (POST token -> decode -> validate -> grant)
150- [ ] Abstract HTTP server via platform callbacks: `httpd_start()`, `register_handler()`, `send_response()`
151- [ ] Keep ESP `httpd` glue in `main/captive_portal.c` (thin handler registration)
152- [ ] Add unit test for template substitution + captive URI detection
153- [ ] Test: `make test-unit` + `idf.py build` + flash + pytest portal tests
154
155### 8d. Extract `stratum_client.c` -> `tollgate_core_stratum_client.c`
156
157Dependencies: `stratum_proxy`, `mining_payment`, `config`, `esp_transport`
158
159- [ ] Create `components/tollgate_core/src/tollgate_core_stratum_client.c/h`
160- [ ] Abstract TCP transport via platform callbacks
161- [ ] Move Stratum V1 protocol logic (subscribe, authorize, handle mining.notify, submit share)
162- [ ] Rewrite `main/stratum_client.c` as thin glue
163- [ ] Add unit test for Stratum message parsing
164- [ ] Test: `make test-unit` + `idf.py build`
165
166### 8e. Extract `mint_health.c` -> `tollgate_core_mint_health.c`
167
168Dependencies: `tls_worker` (after 6e), `nucula_wallet`, `esp_http_client`
169
170- [ ] Create `components/tollgate_core/src/tollgate_core_mint_health.c/h`
171- [ ] Abstract HTTP client via platform callback: `http_get()`, `tls_worker_queue`
172- [ ] Move mint probing logic, health state tracking, reachable/unreachable marking
173- [ ] Rewrite `main/mint_health.c` as thin glue
174- [ ] Add unit test for health state machine
175- [ ] Test: `make test-unit` + `idf.py build`
176
177### 8f. Extract `tollgate_client.c` -> `tollgate_core_client.c`
178
179Dependencies: `config`, `market`, `nucula_wallet`, `esp_http_client`
180
181- [ ] Create `components/tollgate_core/src/tollgate_core_client.c/h`
182- [ ] Abstract HTTP + wallet via platform callbacks
183- [ ] Move upstream TollGate discovery, auto-pay, usage tracking, auto-renew logic
184- [ ] Rewrite `main/tollgate_client.c` as thin glue
185- [ ] Add unit test for client state machine (already exists: `test_tollgate_client.c`)
186- [ ] Test: `make test-unit` + `idf.py build` + flash + full pytest suite
187- [ ] **Commit + push**
188
189---
190
191## Phase 9: NerdQAxePlus Integration
192
193### 9a. Restore miner-integration worktree
194
195- [ ] `git worktree add /home/c03rad0r/esp32-miner-integration feature/miner-integration`
196- [ ] Or create fresh from `remotes/orangesync/feature/miner-integration`
197- [ ] Verify NerdQAxePlus fork at `/home/c03rad0r/esp-miner-nerdqaxeplus/` is intact
198
199### 9b. Copy finalized `tollgate_core` component
200
201- [ ] Sync `components/tollgate_core/` from esp32-tollgate -> NerdQAxePlus `components/tollgate_core/`
202- [ ] Update NerdQAxePlus `CMakeLists.txt` to depend on `tollgate_core`
203- [ ] Verify `BOARD=NERDAXE TOLLGATE=1 idf.py build` succeeds
204
205### 9c. Implement `tollgate_platform_t` for BitAxe/BM1397
206
207- [ ] Create `components/tollgate_baxe/` with BitAxe-specific platform implementation
208- [ ] Implement callbacks: `get_price_sats()`, `get_mint_url()`, `spend_proofs()`, stratum config
209- [ ] Wire BM1397 ASIC -> stratum proxy -> tollgate_core mining pipeline
210- [ ] Wire eCash payment -> session -> internet access on BitAxe AP
211
212### 9d. Integrate into NerdQAxePlus UI
213
214- [ ] Add payment status to OLED/LCD display
215- [ ] Add WiFi AP setup with SSID derived from identity
216- [ ] Add Cashu token input via web portal
217- [ ] Test: Flash NerdAxe Ultra + mining test + payment test + internet verification
218- [ ] **Commit + push**
219
220---
221
222## Phase 10: Publish
223
224### 10a. Component metadata
225
226- [ ] Update `idf_component.yml` with proper version, description, dependencies
227- [ ] Add `README.md` to `components/tollgate_core/` with API docs
228- [ ] Add `CHANGELOG.md` to component
229
230### 10b. CI pipeline
231
232- [ ] GitHub Actions or self-hosted CI: build on push, run unit tests
233- [ ] Hardware-in-the-loop testing on push to develop (Board A)
234- [ ] Integration test matrix: Board A + Board B + Board C
235
236### 10c. Publish to IDF Component Registry
237
238- [ ] `compote component upload` to ESP-IDF Component Registry
239- [ ] Verify `idf.py add-dependency` works from a clean project
240- [ ] Document usage in top-level README
241
242---
243
244## Dependency Graph (Extraction Order)
245
246```
247Layer 0: dns_server, lnurl_pay, asic_miner (no main/ deps)
248Layer 1: config, identity, session, cashu, mining (foundation)
249Layer 2: firewall, beacon_price, lightning_payout (depends on Layer 1)
250Layer 3: market, stratum_proxy, stratum_client (depends on Layer 2)
251Layer 4: captive_portal, tollgate_client, mint_health (depends on Layer 3)
252Layer 5: tollgate_api (depends on everything)
253```
254
255## Current Test Coverage
256
257| Type | Count | Command |
258|------|-------|---------|
259| Host unit tests | 21 | `make test-unit` |
260| Integration tests | 17 | `TOLLGATE_IP=x make test-integration` |
261| E2E tests | 3 suites | `make test-e2e` |
262| Pytest (hardware) | 12 files | `pytest tests/ --board=a` |
diff --git a/components/tollgate_core/src/tollgate_core_dns.c b/components/tollgate_core/src/tollgate_core_dns.c
index 84322e6..c44dd31 100644
--- a/components/tollgate_core/src/tollgate_core_dns.c
+++ b/components/tollgate_core/src/tollgate_core_dns.c
@@ -160,7 +160,7 @@ static void dns_server_task(void *arg)
160 struct sockaddr_in bind_addr = { 160 struct sockaddr_in bind_addr = {
161 .sin_family = AF_INET, 161 .sin_family = AF_INET,
162 .sin_port = htons(DNS_PORT), 162 .sin_port = htons(DNS_PORT),
163 .sin_addr.s_addr = INADDR_ANY, 163 .sin_addr.s_addr = s_ap_ip.addr,
164 }; 164 };
165 if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { 165 if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) {
166 ESP_LOGE(TAG, "Failed to bind DNS socket"); 166 ESP_LOGE(TAG, "Failed to bind DNS socket");
diff --git a/components/tollgate_core/src/tollgate_core_firewall.c b/components/tollgate_core/src/tollgate_core_firewall.c
index ad0697e..4f12923 100644
--- a/components/tollgate_core/src/tollgate_core_firewall.c
+++ b/components/tollgate_core/src/tollgate_core_firewall.c
@@ -9,12 +9,16 @@
9#include "lwip/etharp.h" 9#include "lwip/etharp.h"
10#include "lwip/netif.h" 10#include "lwip/netif.h"
11#include "lwip/prot/ip4.h" 11#include "lwip/prot/ip4.h"
12#include "lwip/prot/tcp.h"
13#include "lwip/prot/ip.h"
12#include <string.h> 14#include <string.h>
13 15
14#define MAX_CLIENTS 10 16#define MAX_CLIENTS 10
15 17
16static const char *TAG = "tg_core_fw"; 18static const char *TAG = "tg_core_fw";
17static esp_ip4_addr_t s_ap_ip; 19static esp_ip4_addr_t s_ap_ip;
20static uint16_t s_mining_port = 3333;
21static bool s_sandbox_mint_access = false;
18 22
19typedef struct { 23typedef struct {
20 uint32_t ip; 24 uint32_t ip;
@@ -70,6 +74,46 @@ esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip)
70 return ESP_OK; 74 return ESP_OK;
71} 75}
72 76
77void tollgate_core_fw_set_sandbox_ports(uint16_t mining_port)
78{
79 s_mining_port = mining_port;
80}
81
82void tollgate_core_fw_set_sandbox_mint_access(bool enabled)
83{
84 s_sandbox_mint_access = enabled;
85}
86
87static bool is_sandbox_allowed(struct pbuf *p)
88{
89 if (p->len < IP_HLEN) return false;
90 struct ip_hdr *iphdr = (struct ip_hdr *)p->payload;
91 uint32_t dest_ip_h = lwip_ntohl(iphdr->dest.addr);
92 uint32_t ap_ip_h = lwip_ntohl(s_ap_ip.addr);
93
94 if (dest_ip_h == ap_ip_h) {
95 if (iphdr->_proto == IP_PROTO_TCP) {
96 uint16_t dst_port = 0;
97 if (p->len >= IP_HLEN + TCP_HLEN) {
98 struct tcp_hdr *tcphdr = (struct tcp_hdr *)((uint8_t *)p->payload + IP_HLEN);
99 dst_port = lwip_ntohs(tcphdr->dest);
100 }
101 if (dst_port == 80 || dst_port == 2121 || dst_port == s_mining_port) {
102 return true;
103 }
104 }
105 if (iphdr->_proto == IP_PROTO_UDP) {
106 return true;
107 }
108 }
109
110 if (s_sandbox_mint_access && iphdr->_proto == IP_PROTO_TCP) {
111 return true;
112 }
113
114 return false;
115}
116
73int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) 117int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder)
74{ 118{
75 (void)dest_addr_hostorder; 119 (void)dest_addr_hostorder;
@@ -83,6 +127,9 @@ int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorde
83 if (tollgate_core_fw_is_allowed(iphdr->src.addr)) { 127 if (tollgate_core_fw_is_allowed(iphdr->src.addr)) {
84 return 1; 128 return 1;
85 } 129 }
130 if (is_sandbox_allowed(p)) {
131 return 1;
132 }
86 return 0; 133 return 0;
87} 134}
88 135
diff --git a/components/tollgate_core/src/tollgate_core_firewall.h b/components/tollgate_core/src/tollgate_core_firewall.h
index f06c801..7f24372 100644
--- a/components/tollgate_core/src/tollgate_core_firewall.h
+++ b/components/tollgate_core/src/tollgate_core_firewall.h
@@ -11,6 +11,8 @@ struct pbuf;
11#define TG_FW_MAX_MAC_LEN 18 11#define TG_FW_MAX_MAC_LEN 18
12 12
13esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip); 13esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip);
14void tollgate_core_fw_set_sandbox_ports(uint16_t mining_port);
15void tollgate_core_fw_set_sandbox_mint_access(bool enabled);
14void tollgate_core_fw_grant(uint32_t client_ip); 16void tollgate_core_fw_grant(uint32_t client_ip);
15void tollgate_core_fw_revoke(uint32_t client_ip); 17void tollgate_core_fw_revoke(uint32_t client_ip);
16void tollgate_core_fw_revoke_all(void); 18void tollgate_core_fw_revoke_all(void);
diff --git a/main/dns_server.c b/main/dns_server.c
index b84a4cf..5b1bdc3 100644
--- a/main/dns_server.c
+++ b/main/dns_server.c
@@ -1,316 +1,22 @@
1#include "dns_server.h" 1#include "dns_server.h"
2#include "esp_log.h" 2#include "tollgate_core_dns.h"
3#include "freertos/FreeRTOS.h"
4#include "freertos/task.h"
5#include "lwip/sockets.h"
6#include "lwip/netdb.h"
7#include <string.h>
8#include <sys/param.h>
9
10#define MAX_AUTH_IPS 10
11#define MAX_PENDING 50
12#define DNS_BUF_SIZE 512
13#define DNS_PORT 53
14#define DOT_PORT 853
15#define DNS_TASK_STACK 4096
16#define DOT_TASK_STACK 3072
17#define DNS_TASK_PRIO 5
18#define DOT_TASK_PRIO 5
19#define DNS_FORWARD_TIMEOUT_MS 2000
20#define NXDOMAIN_TTL 30
21#define HIJACK_TTL 10
22
23static const char *TAG = "dns_server";
24
25#pragma pack(push, 1)
26typedef struct {
27 uint16_t id;
28 uint16_t flags;
29 uint16_t qdcount;
30 uint16_t ancount;
31 uint16_t nscount;
32 uint16_t arcount;
33} dns_header_t;
34#pragma pack(pop)
35
36#pragma pack(push, 1)
37typedef struct {
38 uint16_t name;
39 uint16_t type;
40 uint16_t class;
41 uint32_t ttl;
42 uint16_t len;
43 uint32_t addr;
44} dns_answer_t;
45#pragma pack(pop)
46
47typedef struct {
48 uint32_t ip;
49} auth_entry_t;
50
51static auth_entry_t s_auth_list[MAX_AUTH_IPS];
52static int s_auth_count = 0;
53static TaskHandle_t s_dns_task = NULL;
54static TaskHandle_t s_dot_task = NULL;
55static volatile bool s_dns_running = false;
56static esp_ip4_addr_t s_ap_ip;
57static esp_ip4_addr_t s_upstream_dns;
58
59static bool is_authenticated(uint32_t ip)
60{
61 for (int i = 0; i < s_auth_count; i++) {
62 if (s_auth_list[i].ip == ip) return true;
63 }
64 return false;
65}
66
67static void parse_dns_name(const uint8_t *buf, int buf_len, int offset, char *out, int out_len)
68{
69 int pos = offset;
70 int out_pos = 0;
71 int jumped = 0;
72 int jump_pos = 0;
73 while (pos < buf_len && out_pos < out_len - 1) {
74 uint8_t len = buf[pos];
75 if (len == 0) break;
76 if ((len & 0xC0) == 0xC0) {
77 if (!jumped) jump_pos = pos + 2;
78 pos = ((len & 0x3F) << 8) | buf[pos + 1];
79 jumped = 1;
80 continue;
81 }
82 if (out_pos > 0 && out_pos < out_len - 1) out[out_pos++] = '.';
83 pos++;
84 for (int i = 0; i < len && pos < buf_len && out_pos < out_len - 1; i++) {
85 out[out_pos++] = buf[pos++];
86 }
87 }
88 out[out_pos] = '\0';
89}
90
91static int build_nxdomain(uint8_t *response, int req_len)
92{
93 dns_header_t *hdr = (dns_header_t *)response;
94 hdr->flags = htons(0x8403);
95 hdr->ancount = 0;
96 hdr->nscount = 0;
97 hdr->arcount = 0;
98 return req_len;
99}
100
101static int build_redirect_response(uint8_t *response, int req_len)
102{
103 memmove(response, response, req_len);
104 dns_header_t *hdr = (dns_header_t *)response;
105 hdr->flags = htons(0x8180);
106 hdr->ancount = htons(1);
107 hdr->nscount = 0;
108 hdr->arcount = 0;
109 int resp_len = req_len;
110 dns_answer_t ans;
111 ans.name = htons(0xC00C);
112 ans.type = htons(1);
113 ans.class = htons(1);
114 ans.ttl = htonl(HIJACK_TTL);
115 ans.len = htons(4);
116 ans.addr = s_ap_ip.addr;
117 memcpy(response + resp_len, &ans, sizeof(ans));
118 resp_len += sizeof(ans);
119 return resp_len;
120}
121
122static int forward_dns(const uint8_t *req, int req_len, uint8_t *resp, int resp_buf_len,
123 const struct sockaddr_in *client_addr, uint16_t txn_id)
124{
125 int upstream_sock = socket(AF_INET, SOCK_DGRAM, 0);
126 if (upstream_sock < 0) return -1;
127
128 struct timeval tv = { .tv_sec = DNS_FORWARD_TIMEOUT_MS / 1000, .tv_usec = (DNS_FORWARD_TIMEOUT_MS % 1000) * 1000 };
129 setsockopt(upstream_sock, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv));
130
131 struct sockaddr_in upstream_addr = {
132 .sin_family = AF_INET,
133 .sin_port = htons(DNS_PORT),
134 .sin_addr.s_addr = s_upstream_dns.addr,
135 };
136
137 sendto(upstream_sock, req, req_len, 0, (struct sockaddr *)&upstream_addr, sizeof(upstream_addr));
138
139 int n = recvfrom(upstream_sock, resp, resp_buf_len, 0, NULL, NULL);
140 close(upstream_sock);
141
142 if (n > 0) {
143 if (n >= sizeof(dns_header_t)) {
144 dns_header_t *hdr = (dns_header_t *)resp;
145 hdr->id = htons(txn_id);
146 }
147 }
148 return n;
149}
150
151static void dns_server_task(void *arg)
152{
153 int sock = socket(AF_INET, SOCK_DGRAM, 0);
154 if (sock < 0) {
155 ESP_LOGE(TAG, "Failed to create DNS socket");
156 s_dns_running = false;
157 vTaskDelete(NULL);
158 return;
159 }
160
161 struct sockaddr_in bind_addr = {
162 .sin_family = AF_INET,
163 .sin_port = htons(DNS_PORT),
164 .sin_addr.s_addr = s_ap_ip.addr,
165 };
166 if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) {
167 ESP_LOGE(TAG, "Failed to bind DNS socket");
168 close(sock);
169 s_dns_running = false;
170 vTaskDelete(NULL);
171 return;
172 }
173
174 ESP_LOGI(TAG, "DNS server started on port %d, AP IP=" IPSTR ", upstream DNS=" IPSTR,
175 DNS_PORT, IP2STR(&s_ap_ip), IP2STR(&s_upstream_dns));
176
177 uint8_t rx_buf[DNS_BUF_SIZE];
178 uint8_t tx_buf[DNS_BUF_SIZE + sizeof(dns_answer_t)];
179
180 while (s_dns_running) {
181 struct sockaddr_in client_addr;
182 socklen_t client_len = sizeof(client_addr);
183 int n = recvfrom(sock, rx_buf, sizeof(rx_buf), 0,
184 (struct sockaddr *)&client_addr, &client_len);
185 if (n < (int)sizeof(dns_header_t)) continue;
186
187 uint32_t client_ip = client_addr.sin_addr.s_addr;
188 dns_header_t *hdr = (dns_header_t *)rx_buf;
189 uint16_t txn_id = ntohs(hdr->id);
190 bool is_query = (ntohs(hdr->flags) & 0x8000) == 0;
191 uint16_t qdcount = ntohs(hdr->qdcount);
192
193 if (!is_query || qdcount == 0) continue;
194
195 int q_offset = sizeof(dns_header_t);
196 while (q_offset < n && rx_buf[q_offset] != 0) {
197 q_offset += rx_buf[q_offset] + 1;
198 }
199 if (q_offset + 5 > n) continue;
200 uint16_t qtype = (rx_buf[q_offset + 1] << 8) | rx_buf[q_offset + 2];
201 int req_len = q_offset + 5;
202
203 if (is_authenticated(client_ip)) {
204 int resp_len = forward_dns(rx_buf, req_len, tx_buf, sizeof(tx_buf), &client_addr, txn_id);
205 if (resp_len > 0) {
206 sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len);
207 }
208 } else {
209 char qname[256] = {0};
210 parse_dns_name(rx_buf, n, sizeof(dns_header_t), qname, sizeof(qname));
211 ESP_LOGI(TAG, "Hijack DNS from " IPSTR ": %s (type=%d)", IP2STR(&(esp_ip4_addr_t){.addr=client_ip}), qname, qtype);
212 if (qtype == 1) {
213 int resp_len = build_redirect_response(rx_buf, req_len);
214 memcpy(tx_buf, rx_buf, resp_len);
215 dns_header_t *resp_hdr = (dns_header_t *)tx_buf;
216 resp_hdr->id = htons(txn_id);
217 sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len);
218 } else {
219 int resp_len = build_nxdomain(rx_buf, req_len);
220 memcpy(tx_buf, rx_buf, resp_len);
221 dns_header_t *resp_hdr = (dns_header_t *)tx_buf;
222 resp_hdr->id = htons(txn_id);
223 sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len);
224 }
225 }
226 }
227
228 close(sock);
229 ESP_LOGI(TAG, "DNS server stopped");
230 vTaskDelete(NULL);
231}
232
233static void dot_reject_task(void *arg)
234{
235 int sock = socket(AF_INET, SOCK_STREAM, 0);
236 if (sock < 0) {
237 ESP_LOGE(TAG, "Failed to create DoT reject socket");
238 vTaskDelete(NULL);
239 return;
240 }
241
242 int opt = 1;
243 setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &opt, sizeof(opt));
244
245 struct sockaddr_in bind_addr = {
246 .sin_family = AF_INET,
247 .sin_port = htons(DOT_PORT),
248 .sin_addr.s_addr = INADDR_ANY,
249 };
250 if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) {
251 ESP_LOGE(TAG, "Failed to bind DoT reject socket on port %d", DOT_PORT);
252 close(sock);
253 vTaskDelete(NULL);
254 return;
255 }
256
257 listen(sock, 1);
258 ESP_LOGI(TAG, "DoT reject server on port %d (forces DNS fallback to port 53)", DOT_PORT);
259
260 while (s_dns_running) {
261 struct sockaddr_in client_addr;
262 socklen_t client_len = sizeof(client_addr);
263 int client_sock = accept(sock, (struct sockaddr *)&client_addr, &client_len);
264 if (client_sock >= 0) {
265 struct linger ling = { .l_onoff = 1, .l_linger = 0 };
266 setsockopt(client_sock, SOL_SOCKET, SO_LINGER, &ling, sizeof(ling));
267 close(client_sock);
268 }
269 }
270
271 close(sock);
272 ESP_LOGI(TAG, "DoT reject server stopped");
273 vTaskDelete(NULL);
274}
275 3
276esp_err_t dns_server_start(esp_ip4_addr_t ap_ip, esp_ip4_addr_t upstream_dns) 4esp_err_t dns_server_start(esp_ip4_addr_t ap_ip, esp_ip4_addr_t upstream_dns)
277{ 5{
278 if (s_dns_running) return ESP_OK; 6 return tollgate_core_dns_start_internal(ap_ip, upstream_dns);
279 s_ap_ip = ap_ip;
280 s_upstream_dns = upstream_dns;
281 s_dns_running = true;
282 xTaskCreate(dns_server_task, "dns_server", DNS_TASK_STACK, NULL, DNS_TASK_PRIO, &s_dns_task);
283 xTaskCreate(dot_reject_task, "dot_reject", DOT_TASK_STACK, NULL, DOT_TASK_PRIO, &s_dot_task);
284 return ESP_OK;
285} 7}
286 8
287void dns_server_stop(void) 9void dns_server_stop(void)
288{ 10{
289 s_dns_running = false; 11 tollgate_core_dns_stop();
290 vTaskDelay(pdMS_TO_TICKS(200));
291 s_dns_task = NULL;
292} 12}
293 13
294void dns_server_set_client_authenticated(uint32_t client_ip, bool authenticated) 14void dns_server_set_client_authenticated(uint32_t client_ip, bool authenticated)
295{ 15{
296 if (authenticated) { 16 tollgate_core_dns_set_authenticated(client_ip, authenticated);
297 if (is_authenticated(client_ip)) return;
298 if (s_auth_count < MAX_AUTH_IPS) {
299 s_auth_list[s_auth_count].ip = client_ip;
300 s_auth_count++;
301 }
302 } else {
303 for (int i = 0; i < s_auth_count; i++) {
304 if (s_auth_list[i].ip == client_ip) {
305 s_auth_list[i] = s_auth_list[s_auth_count - 1];
306 s_auth_count--;
307 return;
308 }
309 }
310 }
311} 17}
312 18
313bool dns_server_is_running(void) 19bool dns_server_is_running(void)
314{ 20{
315 return s_dns_running; 21 return tollgate_core_dns_is_running();
316} 22}
diff --git a/main/firewall.c b/main/firewall.c
index 077d16c..5ffdee0 100644
--- a/main/firewall.c
+++ b/main/firewall.c
@@ -1,36 +1,28 @@
1#include "firewall.h" 1#include "firewall.h"
2#include "dns_server.h"
3#include "tollgate_core.h" 2#include "tollgate_core.h"
4#include "tollgate_core_firewall.h" 3#include "tollgate_core_firewall.h"
5#include "esp_log.h" 4#include "esp_log.h"
6#include "lwip/netif.h"
7#include "lwip/lwip_napt.h"
8#include "lwip/prot/ip4.h" 5#include "lwip/prot/ip4.h"
9#include "lwip/prot/tcp.h"
10#include "lwip/prot/ip.h"
11#include <string.h> 6#include <string.h>
12 7
13static const char *TAG = "firewall"; 8static const char *TAG = "firewall";
14static esp_ip4_addr_t s_ap_ip; 9static esp_ip4_addr_t s_ap_ip;
15static uint16_t s_mining_port = 3333;
16static bool s_sandbox_mint_access = false;
17 10
18esp_err_t firewall_init(esp_ip4_addr_t ap_ip) 11esp_err_t firewall_init(esp_ip4_addr_t ap_ip)
19{ 12{
20 s_ap_ip = ap_ip; 13 s_ap_ip = ap_ip;
21 ip_napt_enable(s_ap_ip.addr, 1); 14 ESP_LOGI(TAG, "Firewall initialized with AP IP=" IPSTR, IP2STR(&s_ap_ip));
22 ESP_LOGI(TAG, "Firewall initialized with AP IP=" IPSTR " (NAT always on, per-client filter)", IP2STR(&s_ap_ip));
23 return ESP_OK; 15 return ESP_OK;
24} 16}
25 17
26void firewall_set_mining_port(uint16_t port) 18void firewall_set_mining_port(uint16_t port)
27{ 19{
28 s_mining_port = port; 20 tollgate_core_fw_set_sandbox_ports(port);
29} 21}
30 22
31void firewall_set_sandbox_mint_access(bool enabled) 23void firewall_set_sandbox_mint_access(bool enabled)
32{ 24{
33 s_sandbox_mint_access = enabled; 25 tollgate_core_fw_set_sandbox_mint_access(enabled);
34} 26}
35 27
36esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_out_size) 28esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_out_size)
@@ -38,80 +30,24 @@ esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_
38 return tollgate_core_fw_get_mac_for_ip(client_ip, mac_out, mac_out_size); 30 return tollgate_core_fw_get_mac_for_ip(client_ip, mac_out, mac_out_size);
39} 31}
40 32
41static bool is_sandbox_allowed(struct pbuf *p)
42{
43 if (p->len < IP_HLEN) return false;
44 struct ip_hdr *iphdr = (struct ip_hdr *)p->payload;
45 uint32_t dest_ip_h = lwip_ntohl(iphdr->dest.addr);
46 uint32_t ap_ip_h = lwip_ntohl(s_ap_ip.addr);
47
48 if (dest_ip_h == ap_ip_h) {
49 if (iphdr->_proto == IP_PROTO_TCP) {
50 uint16_t dst_port = 0;
51 if (p->len >= IP_HLEN + TCP_HLEN) {
52 struct tcp_hdr *tcphdr = (struct tcp_hdr *)((uint8_t *)p->payload + IP_HLEN);
53 dst_port = lwip_ntohs(tcphdr->dest);
54 }
55 if (dst_port == 80 || dst_port == 2121 || dst_port == s_mining_port) {
56 return true;
57 }
58 }
59 if (iphdr->_proto == IP_PROTO_UDP) {
60 return true;
61 }
62 }
63
64 if (s_sandbox_mint_access && iphdr->_proto == IP_PROTO_TCP) {
65 return true;
66 }
67
68 return false;
69}
70
71int tollgate_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) 33int tollgate_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder)
72{ 34{
73 (void)dest_addr_hostorder; 35 return tollgate_core_ip4_canforward_filter(p, dest_addr_hostorder);
74 if (p->len < IP_HLEN) return -1;
75 struct ip_hdr *iphdr = (struct ip_hdr *)p->payload;
76 uint32_t src_ip_h = lwip_ntohl(iphdr->src.addr);
77 uint32_t ap_subnet = lwip_ntohl(s_ap_ip.addr) & 0xFFFFFF00;
78 if ((src_ip_h & 0xFFFFFF00) != ap_subnet) {
79 return 1;
80 }
81 if (firewall_is_client_allowed(iphdr->src.addr)) {
82 return 1;
83 }
84 if (is_sandbox_allowed(p)) {
85 return 1;
86 }
87 return 0;
88} 36}
89 37
90void firewall_grant_access(uint32_t client_ip) 38void firewall_grant_access(uint32_t client_ip)
91{ 39{
92 tollgate_core_fw_grant(client_ip); 40 tollgate_core_fw_grant(client_ip);
93 dns_server_set_client_authenticated(client_ip, true);
94
95 char mac[18] = {0};
96 tollgate_core_fw_get_mac_for_ip(client_ip, mac, sizeof(mac));
97 esp_ip4_addr_t ip_addr = { .addr = client_ip };
98 ESP_LOGI(TAG, "Access granted to " IPSTR " mac=%s", IP2STR(&ip_addr),
99 mac[0] ? mac : "unknown");
100} 41}
101 42
102void firewall_revoke_access(uint32_t client_ip) 43void firewall_revoke_access(uint32_t client_ip)
103{ 44{
104 tollgate_core_fw_revoke(client_ip); 45 tollgate_core_fw_revoke(client_ip);
105 dns_server_set_client_authenticated(client_ip, false);
106
107 esp_ip4_addr_t ip_addr = { .addr = client_ip };
108 ESP_LOGI(TAG, "Access revoked for " IPSTR, IP2STR(&ip_addr));
109} 46}
110 47
111void firewall_revoke_all(void) 48void firewall_revoke_all(void)
112{ 49{
113 tollgate_core_fw_revoke_all(); 50 tollgate_core_fw_revoke_all();
114 ESP_LOGI(TAG, "All client access revoked");
115} 51}
116 52
117bool firewall_is_client_allowed(uint32_t client_ip) 53bool firewall_is_client_allowed(uint32_t client_ip)
diff --git a/main/stratum_proxy.c b/main/stratum_proxy.c
index 288c633..53909f0 100644
--- a/main/stratum_proxy.c
+++ b/main/stratum_proxy.c
@@ -1,160 +1,31 @@
1#include "stratum_proxy.h" 1#include "stratum_proxy.h"
2#include "mining_payment.h" 2#include "tollgate_core_stratum_proxy.h"
3#include "esp_log.h"
4#include "lwip/sockets.h"
5#include "freertos/FreeRTOS.h"
6#include "freertos/task.h"
7#include <string.h> 3#include <string.h>
8 4
9static const char *TAG = "stratum_proxy"; 5_Static_assert(sizeof(stratum_job_t) == sizeof(tollgate_stratum_job_t), "job struct size mismatch");
10static uint16_t s_port = 3333; 6_Static_assert(sizeof(stratum_proxy_stats_t) == sizeof(tollgate_stratum_proxy_stats_t), "stats struct size mismatch");
11static bool s_running = false;
12static TaskHandle_t s_task_handle = NULL;
13static int s_server_fd = -1;
14
15static stratum_job_t s_current_job = {0};
16static stratum_proxy_stats_t s_stats = {0};
17
18static void proxy_client_handler(void *arg)
19{
20 int client_fd = (int)(intptr_t)arg;
21 struct sockaddr_in client_addr;
22 socklen_t addr_len = sizeof(client_addr);
23 getpeername(client_fd, (struct sockaddr *)&client_addr, &addr_len);
24 uint32_t client_ip = client_addr.sin_addr.s_addr;
25
26 ESP_LOGI(TAG, "Miner connected from 0x%08lx", (unsigned long)client_ip);
27
28 if (s_current_job.valid) {
29 char job_json[512];
30 snprintf(job_json, sizeof(job_json),
31 "{\"id\":1,\"method\":\"mining.notify\",\"params\":[\"%lu\",\"%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx\",\"\",\"\",\"\",\"%08lx\",\"%08lx\",\"%08lx\",true]}\n",
32 (unsigned long)s_current_job.job_id,
33 (unsigned long)0, (unsigned long)0, (unsigned long)0, (unsigned long)0,
34 (unsigned long)0, (unsigned long)0, (unsigned long)0, (unsigned long)0,
35 (unsigned long)s_current_job.nbits, (unsigned long)s_current_job.ntime,
36 (unsigned long)s_current_job.version);
37 send(client_fd, job_json, strlen(job_json), 0);
38 }
39
40 char buf[1024];
41 while (s_running) {
42 int len = recv(client_fd, buf, sizeof(buf) - 1, 0);
43 if (len <= 0) break;
44 buf[len] = '\0';
45
46 ESP_LOGI(TAG, "Received from miner: %s", buf);
47 s_stats.total_shares++;
48 s_stats.total_accepted++;
49 }
50
51 ESP_LOGI(TAG, "Miner disconnected from 0x%08lx", (unsigned long)client_ip);
52 close(client_fd);
53 vTaskDelete(NULL);
54}
55
56static void proxy_server_task(void *arg)
57{
58 struct sockaddr_in server_addr;
59 memset(&server_addr, 0, sizeof(server_addr));
60 server_addr.sin_family = AF_INET;
61 server_addr.sin_addr.s_addr = INADDR_ANY;
62 server_addr.sin_port = htons(s_port);
63
64 s_server_fd = socket(AF_INET, SOCK_STREAM, 0);
65 if (s_server_fd < 0) {
66 ESP_LOGE(TAG, "Failed to create socket");
67 vTaskDelete(NULL);
68 return;
69 }
70
71 int opt = 1;
72 setsockopt(s_server_fd, SOL_SOCKET, SO_REUSEADDR, &opt, sizeof(opt));
73
74 if (bind(s_server_fd, (struct sockaddr *)&server_addr, sizeof(server_addr)) != 0) {
75 ESP_LOGE(TAG, "Failed to bind to port %u", (unsigned)s_port);
76 close(s_server_fd);
77 s_server_fd = -1;
78 vTaskDelete(NULL);
79 return;
80 }
81
82 if (listen(s_server_fd, 5) != 0) {
83 ESP_LOGE(TAG, "Failed to listen");
84 close(s_server_fd);
85 s_server_fd = -1;
86 vTaskDelete(NULL);
87 return;
88 }
89
90 ESP_LOGI(TAG, "Stratum proxy listening on port %u", (unsigned)s_port);
91
92 while (s_running) {
93 struct sockaddr_in client_addr;
94 socklen_t client_len = sizeof(client_addr);
95 int client_fd = accept(s_server_fd, (struct sockaddr *)&client_addr, &client_len);
96 if (client_fd < 0) continue;
97
98 s_stats.active_miners++;
99 char task_name[20];
100 snprintf(task_name, sizeof(task_name), "miner_%d", client_fd);
101 xTaskCreate(proxy_client_handler, task_name, 4096, (void *)(intptr_t)client_fd, 3, NULL);
102 }
103
104 close(s_server_fd);
105 s_server_fd = -1;
106 vTaskDelete(NULL);
107}
108 7
109esp_err_t stratum_proxy_init(uint16_t port) 8esp_err_t stratum_proxy_init(uint16_t port)
110{ 9{
111 s_port = port; 10 return tollgate_core_stratum_proxy_init(port);
112 memset(&s_current_job, 0, sizeof(s_current_job));
113 memset(&s_stats, 0, sizeof(s_stats));
114 s_running = true;
115
116 BaseType_t ret = xTaskCreate(proxy_server_task, "stratum_proxy", 4096, NULL, 4, &s_task_handle);
117 if (ret != pdPASS) {
118 ESP_LOGE(TAG, "Failed to create proxy task");
119 s_running = false;
120 return ESP_FAIL;
121 }
122
123 ESP_LOGI(TAG, "Stratum proxy initialized on port %u", (unsigned)port);
124 return ESP_OK;
125} 11}
126 12
127void stratum_proxy_set_job(const stratum_job_t *job) 13void stratum_proxy_set_job(const stratum_job_t *job)
128{ 14{
129 if (job) { 15 tollgate_core_stratum_proxy_set_job((const tollgate_stratum_job_t *)job);
130 memcpy(&s_current_job, job, sizeof(stratum_job_t));
131 s_stats.nbits = job->nbits;
132 s_stats.current_hashprice = mining_get_current_hashprice();
133 }
134} 16}
135 17
136const stratum_job_t *stratum_proxy_get_current_job(void) 18const stratum_job_t *stratum_proxy_get_current_job(void)
137{ 19{
138 return &s_current_job; 20 return (const stratum_job_t *)tollgate_core_stratum_proxy_get_current_job();
139} 21}
140 22
141void stratum_proxy_get_stats(stratum_proxy_stats_t *stats) 23void stratum_proxy_get_stats(stratum_proxy_stats_t *stats)
142{ 24{
143 if (stats) { 25 tollgate_core_stratum_proxy_get_stats((tollgate_stratum_proxy_stats_t *)stats);
144 *stats = s_stats;
145 stats->current_hashprice = mining_get_current_hashprice();
146 }
147} 26}
148 27
149void stratum_proxy_stop(void) 28void stratum_proxy_stop(void)
150{ 29{
151 s_running = false; 30 tollgate_core_stratum_proxy_stop();
152 if (s_server_fd >= 0) {
153 close(s_server_fd);
154 s_server_fd = -1;
155 }
156 if (s_task_handle) {
157 vTaskDelay(pdMS_TO_TICKS(500));
158 s_task_handle = NULL;
159 }
160} 31}
diff --git a/tests/unit/test_firewall_sandbox b/tests/unit/test_firewall_sandbox
index 3e2895b..7e5aa6d 100755
--- a/tests/unit/test_firewall_sandbox
+++ b/tests/unit/test_firewall_sandbox
Binary files differ
diff --git a/tests/unit/test_mining_payment b/tests/unit/test_mining_payment
index d38bf9d..dd4e781 100755
--- a/tests/unit/test_mining_payment
+++ b/tests/unit/test_mining_payment
Binary files differ
diff --git a/tests/unit/test_session_payment_method b/tests/unit/test_session_payment_method
index 950a72f..44cafd3 100755
--- a/tests/unit/test_session_payment_method
+++ b/tests/unit/test_session_payment_method
Binary files differ
diff --git a/tests/unit/test_stratum_proxy b/tests/unit/test_stratum_proxy
index 963df67..542d82f 100755
--- a/tests/unit/test_stratum_proxy
+++ b/tests/unit/test_stratum_proxy
Binary files differ
diff --git a/tollgate_core/CMakeLists.txt b/tollgate_core/CMakeLists.txt
deleted file mode 100644
index 988167f..0000000
--- a/tollgate_core/CMakeLists.txt
+++ /dev/null
@@ -1,28 +0,0 @@
1cmake_minimum_required(VERSION 3.16)
2project(tollgate_core C)
3
4set(TG_CORE_SOURCES
5 src/tollgate_core.c
6 src/tollgate_cashu.c
7 src/tollgate_session.c
8 src/tollgate_mining.c
9)
10
11add_library(tollgate_core STATIC ${TG_CORE_SOURCES})
12
13target_include_directories(tollgate_core PUBLIC
14 ${CMAKE_CURRENT_SOURCE_DIR}/include
15 ${CMAKE_CURRENT_SOURCE_DIR}/src
16)
17
18find_package(PkgConfig REQUIRED)
19pkg_check_modules(CJSON REQUIRED libcjson)
20
21target_include_directories(tollgate_core PRIVATE
22 ${CJSON_INCLUDE_DIRS}
23 /usr/include
24)
25
26target_link_libraries(tollgate_core PUBLIC mbedcrypto cjson m)
27
28target_compile_options(tollgate_core PRIVATE -Wall -Wextra -Wno-unused-parameter)
diff --git a/tollgate_core/include/tollgate_core.h b/tollgate_core/include/tollgate_core.h
deleted file mode 100644
index bbae7cf..0000000
--- a/tollgate_core/include/tollgate_core.h
+++ /dev/null
@@ -1,90 +0,0 @@
1#ifndef TOLLGATE_CORE_H
2#define TOLLGATE_CORE_H
3
4#include "tollgate_platform.h"
5#include <stdbool.h>
6#include <stdint.h>
7
8int tollgate_core_init(const tollgate_platform_t *platform, uint32_t ap_ip);
9void tollgate_core_tick(void);
10
11int tollgate_core_dns_start(uint32_t upstream_dns);
12void tollgate_core_dns_stop(void);
13
14int tollgate_core_process_payment(uint32_t client_ip, const char *token_str);
15int tollgate_core_process_share(uint32_t client_ip, const char *job_id,
16 const char *nonce, const char *ntime, const char *version);
17
18void tollgate_core_client_connected(const uint8_t *mac, uint32_t client_ip);
19void tollgate_core_client_disconnected(const uint8_t *mac);
20
21bool tollgate_core_is_client_allowed(uint32_t client_ip);
22bool tollgate_core_is_dns_running(void);
23
24char *tollgate_core_get_status_json(void);
25char *tollgate_core_get_config_json(void);
26
27int tollgate_core_active_session_count(void);
28int tollgate_core_allowed_client_count(void);
29int tollgate_core_firewall_revoke_all(void);
30void tollgate_core_firewall_set_mining_port(uint16_t port);
31void tollgate_core_firewall_set_sandbox_mint_access(bool enable);
32
33bool tollgate_core_is_owner(uint32_t client_ip);
34bool tollgate_core_is_owner_connected(void);
35
36double tollgate_core_get_hashprice(void);
37void tollgate_core_set_nbits(uint32_t nbits);
38const void *tollgate_core_get_current_job(void);
39void tollgate_core_set_job(const void *job);
40
41int tollgate_core_stratum_client_start(void);
42void tollgate_core_stratum_client_stop(void);
43
44int tollgate_core_stratum_proxy_init(uint16_t port);
45void tollgate_core_stratum_proxy_get_stats(void *out);
46
47void tollgate_core_mining_init(void);
48
49void tollgate_core_beacon_start(void);
50
51void tollgate_core_market_init(void);
52void tollgate_core_market_on_scan_result(const void *ie_data, int ie_len,
53 const uint8_t *bssid, int rssi);
54
55const void *tollgate_core_get_sessions_array(void);
56int tollgate_core_get_sessions_array_size(void);
57void *tollgate_core_find_session_by_ip(uint32_t ip);
58void *tollgate_core_find_session_by_mac(const char *mac);
59void *tollgate_core_session_create(uint32_t client_ip, uint64_t allotment_ms);
60void *tollgate_core_session_create_bytes(uint32_t client_ip, uint64_t allotment_bytes);
61void tollgate_core_session_extend(void *session, uint64_t additional_ms);
62void tollgate_core_session_revoke(void *session);
63int tollgate_core_session_add_bytes(uint32_t client_ip, uint64_t bytes);
64bool tollgate_core_session_is_expired(const void *session);
65
66void tollgate_core_firewall_grant(uint32_t client_ip);
67void tollgate_core_firewall_revoke(uint32_t client_ip);
68int tollgate_core_firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, int mac_out_size);
69
70int tollgate_core_cashu_decode(const char *token_str, void *out);
71int tollgate_core_cashu_check_states(const char *mint_url, const void *token,
72 void *states, int *state_count);
73uint64_t tollgate_core_cashu_allotment(uint64_t amount, uint64_t price, uint64_t step_size);
74bool tollgate_core_cashu_is_mint_accepted(const char *mint_url);
75const char *tollgate_core_cashu_token_mint(const void *token);
76uint64_t tollgate_core_cashu_token_amount(const void *token);
77
78void tollgate_core_mining_update_hashrate(uint32_t client_ip, bool accepted);
79const void *tollgate_core_mining_get_client_stats(uint32_t client_ip);
80double tollgate_core_mining_get_hashprice(void);
81uint64_t tollgate_core_mining_shares_to_allotment_ms(double hashrate, double hashprice,
82 int price, int step_ms);
83uint64_t tollgate_core_mining_shares_to_allotment_bytes(double hashrate, double hashprice,
84 int price, int step_bytes);
85void tollgate_core_mining_set_nbits(uint32_t nbits);
86
87const tollgate_platform_t *tollgate_core_get_platform(void);
88uint32_t tollgate_core_get_ap_ip(void);
89
90#endif
diff --git a/tollgate_core/include/tollgate_platform.h b/tollgate_core/include/tollgate_platform.h
deleted file mode 100644
index b553a83..0000000
--- a/tollgate_core/include/tollgate_platform.h
+++ /dev/null
@@ -1,68 +0,0 @@
1#ifndef TOLLGATE_PLATFORM_H
2#define TOLLGATE_PLATFORM_H
3
4#include <stdint.h>
5#include <stdbool.h>
6#include <stddef.h>
7
8typedef struct {
9 uint16_t (*get_price_sats)(void);
10 int32_t (*get_step_ms)(void);
11 int64_t (*get_step_bytes)(void);
12 const char* (*get_mint_url)(void);
13 const char* (*get_metric)(void);
14
15 int64_t (*get_time_ms)(void);
16
17 void (*log_info)(const char *tag, const char *fmt, ...);
18 void (*log_warn)(const char *tag, const char *fmt, ...);
19 void (*log_error)(const char *tag, const char *fmt, ...);
20
21 bool (*wallet_receive)(const char *token);
22 bool (*wallet_send)(uint64_t amount, char *buf, size_t buf_len);
23 uint64_t (*wallet_balance)(void);
24
25 int (*http_post)(const char *url, const char *headers,
26 const char *body, int body_len,
27 char *resp, int resp_len);
28
29 bool (*create_task)(void (*fn)(void*), void *arg,
30 const char *name, int stack_bytes, int priority);
31
32 int (*socket_udp)(void);
33 int (*socket_tcp)(void);
34 int (*socket_bind)(int fd, uint32_t ip, uint16_t port);
35 int (*socket_listen)(int fd, int backlog);
36 int (*socket_accept)(int fd, uint32_t *client_ip, uint16_t *client_port);
37 int (*socket_recvfrom)(int fd, void *buf, int len,
38 uint32_t *src_ip, uint16_t *src_port);
39 int (*socket_sendto)(int fd, const void *buf, int len,
40 uint32_t dest_ip, uint16_t dest_port);
41 int (*socket_read)(int fd, void *buf, int len);
42 int (*socket_write)(int fd, const void *buf, int len);
43 void (*socket_close)(int fd);
44 void (*socket_set_recv_timeout)(int fd, int ms);
45
46 bool (*get_sta_mac_ip_list)(void *list_out, int max, int *count_out);
47 bool (*set_vendor_ie)(bool enable, const void *ie_data, int ie_len);
48 int (*arp_get_mac)(uint32_t ip, uint8_t *mac_out);
49 void (*napt_enable)(uint32_t ip, bool enable);
50
51 bool (*mining_enabled)(void);
52 const char* (*get_stratum_host)(void);
53 uint16_t (*get_stratum_port)(void);
54 const char* (*get_stratum_user)(void);
55 const char* (*get_stratum_pass)(void);
56 uint16_t (*get_mining_port)(void);
57 uint64_t (*get_hashprice_override)(void);
58
59 void (*fill_random)(void *buf, int len);
60
61 int (*get_accepted_mint_count)(void);
62 const char* (*get_accepted_mint)(int index);
63 bool (*is_mint_reachable)(const char *mint_url);
64 bool (*mac_for_ip)(uint32_t ip, char *mac_out, int mac_out_size);
65
66} tollgate_platform_t;
67
68#endif
diff --git a/tollgate_core/src/tollgate_cashu.c b/tollgate_core/src/tollgate_cashu.c
deleted file mode 100644
index 55f4953..0000000
--- a/tollgate_core/src/tollgate_cashu.c
+++ /dev/null
@@ -1,253 +0,0 @@
1#include "tollgate_cashu.h"
2#include "tollgate_core.h"
3#include "tollgate_platform.h"
4#include <stdlib.h>
5#include <string.h>
6#include <stdio.h>
7#include <cJSON.h>
8#include <mbedtls/base64.h>
9#include <mbedtls/sha256.h>
10
11static const char *TAG = "tg_cashu";
12
13static const char V3_PREFIX[] = "cashuA";
14static const size_t V3_PREFIX_LEN = 6;
15
16static int b64url_decode(const char *input, size_t input_len, char *out, size_t out_size, size_t *out_len)
17{
18 char *b64 = malloc(input_len + 4);
19 if (!b64) return -1;
20 size_t b64_len = input_len;
21 memcpy(b64, input, b64_len);
22 b64[b64_len] = '\0';
23
24 for (size_t i = 0; i < b64_len; i++) {
25 if (b64[i] == '-') b64[i] = '+';
26 else if (b64[i] == '_') b64[i] = '/';
27 }
28 while (b64_len % 4 != 0) {
29 b64[b64_len++] = '=';
30 }
31 b64[b64_len] = '\0';
32
33 size_t olen = 0;
34 int ret = mbedtls_base64_decode((unsigned char *)out, out_size, &olen,
35 (const unsigned char *)b64, b64_len);
36 free(b64);
37 if (ret != 0) return -1;
38 *out_len = olen;
39 return 0;
40}
41
42static int parse_proofs_array(cJSON *arr, tg_cashu_token_t *out)
43{
44 if (!cJSON_IsArray(arr)) return -1;
45 int count = cJSON_GetArraySize(arr);
46 if (count > TG_CASHU_MAX_PROOFS) return -1;
47
48 out->proof_count = 0;
49 out->total_amount = 0;
50 for (int i = 0; i < count; i++) {
51 cJSON *proof = cJSON_GetArrayItem(arr, i);
52 cJSON *amt = cJSON_GetObjectItemCaseSensitive(proof, "amount");
53 cJSON *id = cJSON_GetObjectItemCaseSensitive(proof, "id");
54 cJSON *secret = cJSON_GetObjectItemCaseSensitive(proof, "secret");
55 cJSON *c = cJSON_GetObjectItemCaseSensitive(proof, "C");
56
57 if (!amt || !cJSON_IsNumber(amt)) return -1;
58
59 out->proofs[i].amount = (uint64_t)amt->valuedouble;
60 out->total_amount += out->proofs[i].amount;
61
62 if (id && cJSON_IsString(id)) {
63 strncpy(out->proofs[i].id, id->valuestring, sizeof(out->proofs[i].id) - 1);
64 }
65 if (secret && cJSON_IsString(secret)) {
66 strncpy(out->proofs[i].secret, secret->valuestring, sizeof(out->proofs[i].secret) - 1);
67 }
68 if (c && cJSON_IsString(c)) {
69 strncpy(out->proofs[i].c, c->valuestring, sizeof(out->proofs[i].c) - 1);
70 }
71 out->proof_count++;
72 }
73 return 0;
74}
75
76int tg_cashu_decode_token(const char *token_str, tg_cashu_token_t *out)
77{
78 const tollgate_platform_t *p = tollgate_core_get_platform();
79 if (!token_str || !out) return -1;
80 memset(out, 0, sizeof(*out));
81
82 size_t len = strlen(token_str);
83 char *nl = strchr(token_str, '\n');
84 if (nl) len = nl - token_str;
85 char *cr = strchr(token_str, '\r');
86 if (cr && (cr - token_str) < (int)len) len = cr - token_str;
87 if (len <= V3_PREFIX_LEN) {
88 if (p && p->log_error) p->log_error(TAG, "Token too short");
89 return -1;
90 }
91 if (strncmp(token_str, V3_PREFIX, V3_PREFIX_LEN) != 0) {
92 if (p && p->log_error) p->log_error(TAG, "Token missing cashuA prefix");
93 return -1;
94 }
95
96 size_t b64_len = len - V3_PREFIX_LEN;
97 size_t decoded_size = (b64_len * 3) / 4 + 4;
98 char *json_buf = malloc(decoded_size);
99 if (!json_buf) return -1;
100 size_t json_len = 0;
101 if (b64url_decode(token_str + V3_PREFIX_LEN, b64_len,
102 json_buf, decoded_size - 1, &json_len) != 0) {
103 if (p && p->log_error) p->log_error(TAG, "Base64url decode failed");
104 free(json_buf);
105 return -1;
106 }
107 json_buf[json_len] = '\0';
108
109 cJSON *root = cJSON_Parse(json_buf);
110 free(json_buf);
111 if (!root) {
112 if (p && p->log_error) p->log_error(TAG, "JSON parse failed");
113 return -1;
114 }
115
116 cJSON *token_arr = cJSON_GetObjectItemCaseSensitive(root, "token");
117 if (token_arr && cJSON_IsArray(token_arr)) {
118 cJSON *first = cJSON_GetArrayItem(token_arr, 0);
119 if (!first) { cJSON_Delete(root); return -1; }
120
121 cJSON *mint = cJSON_GetObjectItemCaseSensitive(first, "mint");
122 if (mint && cJSON_IsString(mint)) {
123 strncpy(out->mint_url, mint->valuestring, sizeof(out->mint_url) - 1);
124 }
125
126 cJSON *proofs = cJSON_GetObjectItemCaseSensitive(first, "proofs");
127 if (proofs) {
128 if (parse_proofs_array(proofs, out) != 0) { cJSON_Delete(root); return -1; }
129 }
130 } else {
131 cJSON *mint = cJSON_GetObjectItemCaseSensitive(root, "mint");
132 if (mint && cJSON_IsString(mint)) {
133 strncpy(out->mint_url, mint->valuestring, sizeof(out->mint_url) - 1);
134 }
135
136 cJSON *proofs = cJSON_GetObjectItemCaseSensitive(root, "proofs");
137 if (proofs) {
138 if (parse_proofs_array(proofs, out) != 0) { cJSON_Delete(root); return -1; }
139 }
140 }
141
142 cJSON_Delete(root);
143
144 if (out->proof_count == 0) {
145 if (p && p->log_error) p->log_error(TAG, "No proofs in token");
146 return -1;
147 }
148
149 if (p && p->log_info) p->log_info(TAG, "Decoded token: %d proofs, total=%llu, mint=%s",
150 out->proof_count, (unsigned long long)out->total_amount, out->mint_url);
151 return 0;
152}
153
154static void sha256_hex(const char *data, size_t data_len, char *hex_out)
155{
156 unsigned char hash[32];
157 mbedtls_sha256((const unsigned char *)data, data_len, hash, 0);
158 for (int i = 0; i < 32; i++) {
159 sprintf(hex_out + i * 2, "%02x", hash[i]);
160 }
161 hex_out[64] = '\0';
162}
163
164int tg_cashu_check_proof_states(const char *mint_url, const tg_cashu_token_t *token,
165 tg_cashu_proof_state_t *states, int *state_count)
166{
167 const tollgate_platform_t *p = tollgate_core_get_platform();
168
169 cJSON *ys_arr = cJSON_CreateArray();
170 for (int i = 0; i < token->proof_count; i++) {
171 char y_hex[65];
172 sha256_hex(token->proofs[i].secret, strlen(token->proofs[i].secret), y_hex);
173 cJSON_AddItemToArray(ys_arr, cJSON_CreateString(y_hex));
174 strncpy(states[i].y_hex, y_hex, sizeof(states[i].y_hex) - 1);
175 states[i].spent = false;
176 }
177 *state_count = token->proof_count;
178
179 char *ys_json = cJSON_PrintUnformatted(ys_arr);
180 cJSON_Delete(ys_arr);
181
182 char *post_body = malloc(4096);
183 if (!post_body) { cJSON_free(ys_json); return -1; }
184 snprintf(post_body, 4096, "{\"Ys\":%s}", ys_json);
185 cJSON_free(ys_json);
186
187 char url[512];
188 snprintf(url, sizeof(url), "%s/v1/checkstate", mint_url);
189
190 if (!p || !p->http_post) {
191 free(post_body);
192 return -1;
193 }
194
195 char *resp_buf = malloc(8192);
196 if (!resp_buf) { free(post_body); return -1; }
197
198 int resp_len = p->http_post(url, "Content-Type: application/json",
199 post_body, (int)strlen(post_body),
200 resp_buf, 8191);
201 free(post_body);
202
203 if (resp_len <= 0) {
204 if (p && p->log_error) p->log_error(TAG, "checkstate HTTP failed: resp_len=%d", resp_len);
205 free(resp_buf);
206 return -1;
207 }
208 resp_buf[resp_len] = '\0';
209
210 cJSON *root = cJSON_Parse(resp_buf);
211 free(resp_buf);
212 if (!root) return -1;
213
214 cJSON *states_arr = cJSON_GetObjectItemCaseSensitive(root, "states");
215 if (!states_arr || !cJSON_IsArray(states_arr)) {
216 cJSON_Delete(root);
217 return -1;
218 }
219
220 int n = cJSON_GetArraySize(states_arr);
221 for (int i = 0; i < n && i < token->proof_count; i++) {
222 cJSON *s = cJSON_GetArrayItem(states_arr, i);
223 cJSON *state = cJSON_GetObjectItemCaseSensitive(s, "state");
224 if (state && cJSON_IsString(state)) {
225 states[i].spent = (strcmp(state->valuestring, "SPENT") == 0);
226 }
227 }
228
229 cJSON_Delete(root);
230 return 0;
231}
232
233uint64_t tg_cashu_calculate_allotment_ms(uint64_t token_amount, uint64_t price_per_step,
234 uint64_t step_size_ms)
235{
236 if (price_per_step == 0) return 0;
237 return (token_amount / price_per_step) * step_size_ms;
238}
239
240uint64_t tg_cashu_calculate_allotment(uint64_t token_amount, uint64_t price_per_step,
241 uint64_t step_size)
242{
243 if (price_per_step == 0) return 0;
244 return (token_amount / price_per_step) * step_size;
245}
246
247bool tg_cashu_is_mint_accepted(const char *mint_url, const char *accepted_mint_url)
248{
249 if (!mint_url || mint_url[0] == '\0') return false;
250 if (!accepted_mint_url || accepted_mint_url[0] == '\0') return false;
251 return (strstr(mint_url, accepted_mint_url) != NULL ||
252 strcmp(mint_url, accepted_mint_url) == 0);
253}
diff --git a/tollgate_core/src/tollgate_cashu.h b/tollgate_core/src/tollgate_cashu.h
deleted file mode 100644
index 9785e98..0000000
--- a/tollgate_core/src/tollgate_cashu.h
+++ /dev/null
@@ -1,40 +0,0 @@
1#ifndef TOLLGATE_CORE_CASHU_H
2#define TOLLGATE_CORE_CASHU_H
3
4#include <stdint.h>
5#include <stdbool.h>
6
7#define TG_CASHU_MAX_PROOFS 10
8#define TG_CASHU_MAX_SECRET_LEN 128
9#define TG_CASHU_MAX_ID_LEN 68
10#define TG_CASHU_MAX_C_LEN 128
11
12typedef struct {
13 uint64_t amount;
14 char id[TG_CASHU_MAX_ID_LEN];
15 char secret[TG_CASHU_MAX_SECRET_LEN];
16 char c[TG_CASHU_MAX_C_LEN];
17} tg_cashu_proof_t;
18
19typedef struct {
20 tg_cashu_proof_t proofs[TG_CASHU_MAX_PROOFS];
21 int proof_count;
22 char mint_url[256];
23 uint64_t total_amount;
24} tg_cashu_token_t;
25
26typedef struct {
27 char y_hex[65];
28 bool spent;
29} tg_cashu_proof_state_t;
30
31int tg_cashu_decode_token(const char *token_str, tg_cashu_token_t *out);
32int tg_cashu_check_proof_states(const char *mint_url, const tg_cashu_token_t *token,
33 tg_cashu_proof_state_t *states, int *state_count);
34uint64_t tg_cashu_calculate_allotment_ms(uint64_t token_amount, uint64_t price_per_step,
35 uint64_t step_size_ms);
36uint64_t tg_cashu_calculate_allotment(uint64_t token_amount, uint64_t price_per_step,
37 uint64_t step_size);
38bool tg_cashu_is_mint_accepted(const char *mint_url, const char *accepted_mint_url);
39
40#endif
diff --git a/tollgate_core/src/tollgate_core.c b/tollgate_core/src/tollgate_core.c
deleted file mode 100644
index c7c2902..0000000
--- a/tollgate_core/src/tollgate_core.c
+++ /dev/null
@@ -1,466 +0,0 @@
1#include "tollgate_core.h"
2#include "tollgate_platform.h"
3#include "tollgate_cashu.h"
4#include "tollgate_session.h"
5#include "tollgate_firewall.h"
6#include "tollgate_mining.h"
7#include <string.h>
8#include <stdlib.h>
9#include <stdio.h>
10
11static const char *TAG = "tg_core";
12static const tollgate_platform_t *s_platform;
13static uint32_t s_ap_ip;
14
15static uint32_t s_owner_ip;
16static uint8_t s_owner_mac[6];
17static bool s_owner_connected;
18
19const tollgate_platform_t *tollgate_core_get_platform(void)
20{
21 return s_platform;
22}
23
24uint32_t tollgate_core_get_ap_ip(void)
25{
26 return s_ap_ip;
27}
28
29int tollgate_core_init(const tollgate_platform_t *platform, uint32_t ap_ip)
30{
31 if (!platform) return -1;
32
33 s_platform = platform;
34 s_ap_ip = ap_ip;
35 s_owner_connected = false;
36 memset(s_owner_mac, 0, sizeof(s_owner_mac));
37
38 tg_session_init();
39 tg_firewall_init(ap_ip);
40 tg_mining_init();
41
42 if (platform->log_info) {
43 char ip_str[16];
44 snprintf(ip_str, sizeof(ip_str), "%d.%d.%d.%d",
45 (int)((ap_ip >> 0) & 0xFF), (int)((ap_ip >> 8) & 0xFF),
46 (int)((ap_ip >> 16) & 0xFF), (int)((ap_ip >> 24) & 0xFF));
47 platform->log_info(TAG, "TollGate core initialized, AP IP=%s", ip_str);
48 }
49 return 0;
50}
51
52void tollgate_core_tick(void)
53{
54 tg_session_tick();
55}
56
57int tollgate_core_process_payment(uint32_t client_ip, const char *token_str)
58{
59 if (!s_platform || !token_str) return -1;
60
61 const char *accepted_mint = s_platform->get_mint_url ? s_platform->get_mint_url() : NULL;
62 if (!accepted_mint || accepted_mint[0] == '\0') {
63 if (s_platform->log_error) s_platform->log_error(TAG, "No mint URL configured");
64 return -1;
65 }
66
67 tg_cashu_token_t token;
68 if (tg_cashu_decode_token(token_str, &token) != 0) {
69 if (s_platform->log_error) s_platform->log_error(TAG, "Token decode failed");
70 return -1;
71 }
72
73 bool mint_ok = false;
74 if (s_platform->get_accepted_mint_count && s_platform->get_accepted_mint) {
75 int count = s_platform->get_accepted_mint_count();
76 for (int i = 0; i < count; i++) {
77 if (tg_cashu_is_mint_accepted(token.mint_url, s_platform->get_accepted_mint(i))) {
78 mint_ok = true;
79 break;
80 }
81 }
82 } else {
83 mint_ok = tg_cashu_is_mint_accepted(token.mint_url, accepted_mint);
84 }
85 if (!mint_ok) {
86 if (s_platform->log_error) s_platform->log_error(TAG, "Token mint not accepted");
87 return -1;
88 }
89
90 tg_cashu_proof_state_t states[TG_CASHU_MAX_PROOFS];
91 int state_count = 0;
92 if (tg_cashu_check_proof_states(token.mint_url, &token, states, &state_count) != 0) {
93 if (s_platform->log_error) s_platform->log_error(TAG, "Proof state check failed (continuing)");
94 } else {
95 for (int i = 0; i < state_count; i++) {
96 if (states[i].spent) {
97 if (s_platform->log_error) s_platform->log_error(TAG, "Proof %d is SPENT", i);
98 return -1;
99 }
100 }
101 }
102
103 if (s_platform->wallet_receive) {
104 if (!s_platform->wallet_receive(token_str)) {
105 if (s_platform->log_error) s_platform->log_error(TAG, "wallet_receive rejected token");
106 return -1;
107 }
108 }
109
110 const char *metric = (s_platform->get_metric) ? s_platform->get_metric() : "milliseconds";
111 uint64_t price = (s_platform->get_price_sats) ? s_platform->get_price_sats() : 21;
112 uint64_t step_size;
113
114 if (strcmp(metric, "bytes") == 0) {
115 step_size = (s_platform->get_step_bytes) ? (uint64_t)s_platform->get_step_bytes() : 22020096;
116 } else {
117 step_size = (s_platform->get_step_ms) ? (uint64_t)s_platform->get_step_ms() : 60000;
118 }
119
120 uint64_t allotment = tg_cashu_calculate_allotment(token.total_amount, price, step_size);
121 if (allotment == 0) {
122 if (s_platform->log_error) s_platform->log_error(TAG, "Token amount too small");
123 return -1;
124 }
125
126 if (strcmp(metric, "bytes") == 0) {
127 if (!tg_session_create_bytes(client_ip, allotment)) return -1;
128 } else {
129 if (!tg_session_create(client_ip, allotment)) return -1;
130 }
131
132 if (s_platform->log_info) s_platform->log_info(TAG, "Payment: %llu sats -> %llu %s",
133 (unsigned long long)token.total_amount, (unsigned long long)allotment, metric);
134 return 0;
135}
136
137int tollgate_core_process_share(uint32_t client_ip, const char *job_id,
138 const char *nonce, const char *ntime, const char *version)
139{
140 (void)job_id; (void)nonce; (void)ntime; (void)version;
141 if (!s_platform) return -1;
142
143 tg_mining_update_hashrate(client_ip, true);
144 const tg_mining_client_stats_t *stats = tg_mining_get_client_stats(client_ip);
145 if (!stats) return -1;
146
147 double hashprice = tg_mining_get_current_hashprice();
148 uint64_t override = (s_platform->get_hashprice_override) ? s_platform->get_hashprice_override() : 0;
149 if (override > 0) hashprice = tg_mining_calculate_hashprice_override(override);
150
151 const char *metric = (s_platform->get_metric) ? s_platform->get_metric() : "milliseconds";
152 int price = (s_platform->get_price_sats) ? s_platform->get_price_sats() : 21;
153
154 tg_session_t *existing = tg_session_find_by_ip(client_ip);
155 if (existing && existing->payment_method == TG_PAYMENT_MINING) {
156 uint64_t allotment;
157 if (strcmp(metric, "bytes") == 0) {
158 int step_bytes = (s_platform->get_step_bytes) ? (int)s_platform->get_step_bytes() : 22020096;
159 allotment = tg_mining_shares_to_allotment_bytes(stats->hashrate_ghs, hashprice, price, step_bytes);
160 existing->allotment_bytes += allotment;
161 } else {
162 int step_ms = (s_platform->get_step_ms) ? s_platform->get_step_ms() : 60000;
163 allotment = tg_mining_shares_to_allotment_ms(stats->hashrate_ghs, hashprice, price, step_ms);
164 tg_session_extend(existing, allotment);
165 }
166 return 0;
167 }
168
169 uint64_t allotment;
170 if (strcmp(metric, "bytes") == 0) {
171 int step_bytes = (s_platform->get_step_bytes) ? (int)s_platform->get_step_bytes() : 22020096;
172 allotment = tg_mining_shares_to_allotment_bytes(stats->hashrate_ghs, hashprice, price, step_bytes);
173 tg_session_t *s = tg_session_create_bytes(client_ip, allotment);
174 if (s) s->payment_method = TG_PAYMENT_MINING;
175 } else {
176 int step_ms = (s_platform->get_step_ms) ? s_platform->get_step_ms() : 60000;
177 allotment = tg_mining_shares_to_allotment_ms(stats->hashrate_ghs, hashprice, price, step_ms);
178 tg_session_t *s = tg_session_create(client_ip, allotment);
179 if (s) s->payment_method = TG_PAYMENT_MINING;
180 }
181
182 return 0;
183}
184
185void tollgate_core_client_connected(const uint8_t *mac, uint32_t client_ip)
186{
187 if (!s_owner_connected) {
188 s_owner_connected = true;
189 s_owner_ip = client_ip;
190 if (mac) memcpy(s_owner_mac, mac, 6);
191 if (s_platform && s_platform->log_info) {
192 char ip_str[16];
193 snprintf(ip_str, sizeof(ip_str), "%d.%d.%d.%d",
194 (int)((client_ip >> 0) & 0xFF), (int)((client_ip >> 8) & 0xFF),
195 (int)((client_ip >> 16) & 0xFF), (int)((client_ip >> 24) & 0xFF));
196 s_platform->log_info(TAG, "First client = owner: %s", ip_str);
197 }
198 return;
199 }
200 if (s_platform && s_platform->log_info) s_platform->log_info(TAG, "Client connected (non-owner)");
201}
202
203void tollgate_core_client_disconnected(const uint8_t *mac)
204{
205 if (!s_owner_connected) return;
206 if (mac && memcmp(s_owner_mac, mac, 6) == 0) {
207 s_owner_connected = false;
208 memset(s_owner_mac, 0, sizeof(s_owner_mac));
209 if (s_platform && s_platform->log_info) s_platform->log_info(TAG, "Owner disconnected");
210 }
211}
212
213bool tollgate_core_is_client_allowed(uint32_t client_ip)
214{
215 return tg_firewall_is_allowed(client_ip);
216}
217
218bool tollgate_core_is_dns_running(void)
219{
220 return false;
221}
222
223char *tollgate_core_get_status_json(void)
224{
225 const int BUFSIZE = 512;
226 char *json = malloc(BUFSIZE);
227 if (!json) return NULL;
228 snprintf(json, BUFSIZE,
229 "{\"ownerConnected\":%s,\"activeSessions\":%d,\"allowedClients\":%d,\"dnsRunning\":%s}",
230 s_owner_connected ? "true" : "false",
231 tg_session_active_count(),
232 tg_firewall_client_count(),
233 tollgate_core_is_dns_running() ? "true" : "false");
234 return json;
235}
236
237char *tollgate_core_get_config_json(void)
238{
239 const int BUFSIZE = 512;
240 char *json = malloc(BUFSIZE);
241 if (!json) return NULL;
242 int pos = 0;
243 pos += snprintf(json + pos, BUFSIZE - pos, "{");
244 if (s_platform) {
245 if (s_platform->get_price_sats)
246 pos += snprintf(json + pos, BUFSIZE - pos, "\"priceSats\":%d,", (int)s_platform->get_price_sats());
247 if (s_platform->get_step_ms)
248 pos += snprintf(json + pos, BUFSIZE - pos, "\"stepMs\":%d,", (int)s_platform->get_step_ms());
249 if (s_platform->get_mint_url)
250 pos += snprintf(json + pos, BUFSIZE - pos, "\"mintUrl\":\"%s\",", s_platform->get_mint_url());
251 if (s_platform->get_metric)
252 pos += snprintf(json + pos, BUFSIZE - pos, "\"metric\":\"%s\"", s_platform->get_metric());
253 }
254 pos += snprintf(json + pos, BUFSIZE - pos, "}");
255 return json;
256}
257
258int tollgate_core_active_session_count(void)
259{
260 return tg_session_active_count();
261}
262
263int tollgate_core_allowed_client_count(void)
264{
265 return tg_firewall_client_count();
266}
267
268int tollgate_core_firewall_revoke_all(void)
269{
270 tg_session_revoke_all();
271 return tg_firewall_revoke_all();
272}
273
274void tollgate_core_firewall_set_mining_port(uint16_t port)
275{
276 tg_firewall_set_mining_port(port);
277}
278
279void tollgate_core_firewall_set_sandbox_mint_access(bool enable)
280{
281 tg_firewall_set_sandbox_mint_access(enable);
282}
283
284bool tollgate_core_is_owner(uint32_t client_ip)
285{
286 return s_owner_connected && s_owner_ip == client_ip;
287}
288
289bool tollgate_core_is_owner_connected(void)
290{
291 return s_owner_connected;
292}
293
294double tollgate_core_get_hashprice(void)
295{
296 return tg_mining_get_current_hashprice();
297}
298
299void tollgate_core_set_nbits(uint32_t nbits)
300{
301 tg_mining_set_current_nbits(nbits);
302}
303
304const void *tollgate_core_get_current_job(void) { return NULL; }
305void tollgate_core_set_job(const void *job) { (void)job; }
306int tollgate_core_stratum_client_start(void) { return -1; }
307void tollgate_core_stratum_client_stop(void) { }
308int tollgate_core_stratum_proxy_init(uint16_t port) { (void)port; return -1; }
309void tollgate_core_stratum_proxy_get_stats(void *out) { (void)out; }
310void tollgate_core_beacon_start(void) { }
311void tollgate_core_market_init(void) { }
312void tollgate_core_market_on_scan_result(const void *ie_data, int ie_len, const uint8_t *bssid, int rssi)
313{
314 (void)ie_data; (void)ie_len; (void)bssid; (void)rssi;
315}
316
317const void *tollgate_core_get_sessions_array(void)
318{
319 return tg_session_get_array();
320}
321
322int tollgate_core_get_sessions_array_size(void)
323{
324 return tg_session_get_array_size();
325}
326
327void *tollgate_core_find_session_by_ip(uint32_t ip)
328{
329 return tg_session_find_by_ip(ip);
330}
331
332void *tollgate_core_find_session_by_mac(const char *mac)
333{
334 return tg_session_find_by_mac(mac);
335}
336
337void tollgate_core_session_extend(void *session, uint64_t additional_ms)
338{
339 tg_session_extend((tg_session_t *)session, additional_ms);
340}
341
342int tollgate_core_session_add_bytes(uint32_t client_ip, uint64_t bytes)
343{
344 tg_session_add_bytes(client_ip, bytes);
345 return 0;
346}
347
348void *tollgate_core_session_create(uint32_t client_ip, uint64_t allotment_ms)
349{
350 return tg_session_create(client_ip, allotment_ms);
351}
352
353void *tollgate_core_session_create_bytes(uint32_t client_ip, uint64_t allotment_bytes)
354{
355 return tg_session_create_bytes(client_ip, allotment_bytes);
356}
357
358void tollgate_core_session_revoke(void *session)
359{
360 tg_session_revoke((tg_session_t *)session);
361}
362
363bool tollgate_core_session_is_expired(const void *session)
364{
365 return tg_session_is_expired((const tg_session_t *)session);
366}
367
368void tollgate_core_firewall_grant(uint32_t client_ip)
369{
370 tg_firewall_grant(client_ip);
371}
372
373void tollgate_core_firewall_revoke(uint32_t client_ip)
374{
375 tg_firewall_revoke(client_ip);
376}
377
378int tollgate_core_firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, int mac_out_size)
379{
380 return tg_firewall_get_mac_for_ip(client_ip, mac_out, mac_out_size);
381}
382
383int tollgate_core_cashu_decode(const char *token_str, void *out)
384{
385 return tg_cashu_decode_token(token_str, (tg_cashu_token_t *)out);
386}
387
388int tollgate_core_cashu_check_states(const char *mint_url, const void *token,
389 void *states, int *state_count)
390{
391 return tg_cashu_check_proof_states(mint_url, (const tg_cashu_token_t *)token,
392 (tg_cashu_proof_state_t *)states, state_count);
393}
394
395uint64_t tollgate_core_cashu_allotment(uint64_t amount, uint64_t price, uint64_t step_size)
396{
397 return tg_cashu_calculate_allotment(amount, price, step_size);
398}
399
400bool tollgate_core_cashu_is_mint_accepted(const char *mint_url)
401{
402 if (!s_platform) return false;
403 const char *accepted = s_platform->get_mint_url ? s_platform->get_mint_url() : NULL;
404 if (!accepted) return false;
405 if (s_platform->get_accepted_mint_count && s_platform->get_accepted_mint) {
406 int count = s_platform->get_accepted_mint_count();
407 for (int i = 0; i < count; i++) {
408 if (tg_cashu_is_mint_accepted(mint_url, s_platform->get_accepted_mint(i)))
409 return true;
410 }
411 return false;
412 }
413 return tg_cashu_is_mint_accepted(mint_url, accepted);
414}
415
416const char *tollgate_core_cashu_token_mint(const void *token)
417{
418 const tg_cashu_token_t *t = (const tg_cashu_token_t *)token;
419 return t->mint_url;
420}
421
422uint64_t tollgate_core_cashu_token_amount(const void *token)
423{
424 const tg_cashu_token_t *t = (const tg_cashu_token_t *)token;
425 return t->total_amount;
426}
427
428void tollgate_core_mining_update_hashrate(uint32_t client_ip, bool accepted)
429{
430 tg_mining_update_hashrate(client_ip, accepted);
431}
432
433const void *tollgate_core_mining_get_client_stats(uint32_t client_ip)
434{
435 return tg_mining_get_client_stats(client_ip);
436}
437
438double tollgate_core_mining_get_hashprice(void)
439{
440 return tg_mining_get_current_hashprice();
441}
442
443uint64_t tollgate_core_mining_shares_to_allotment_ms(double hashrate, double hashprice,
444 int price, int step_ms)
445{
446 return tg_mining_shares_to_allotment_ms(hashrate, hashprice, price, step_ms);
447}
448
449uint64_t tollgate_core_mining_shares_to_allotment_bytes(double hashrate, double hashprice,
450 int price, int step_bytes)
451{
452 return tg_mining_shares_to_allotment_bytes(hashrate, hashprice, price, step_bytes);
453}
454
455void tollgate_core_mining_set_nbits(uint32_t nbits)
456{
457 tg_mining_set_current_nbits(nbits);
458}
459
460int tollgate_core_dns_start(uint32_t upstream_dns)
461{
462 (void)upstream_dns;
463 return -1;
464}
465
466void tollgate_core_dns_stop(void) { }
diff --git a/tollgate_core/src/tollgate_firewall.c b/tollgate_core/src/tollgate_firewall.c
deleted file mode 100644
index 8111be8..0000000
--- a/tollgate_core/src/tollgate_firewall.c
+++ /dev/null
@@ -1,166 +0,0 @@
1#include "tollgate_firewall.h"
2#include "tollgate_core.h"
3#include "tollgate_platform.h"
4#include <string.h>
5#include <stdio.h>
6
7#define FW_MAX_CLIENTS 10
8
9static const char *TAG = "tg_fw";
10static uint32_t s_ap_ip;
11static uint16_t s_mining_port;
12static bool s_sandbox_mint;
13
14typedef struct {
15 uint32_t ip;
16 char mac[TG_FW_MAX_MAC_LEN];
17} fw_client_t;
18
19static fw_client_t s_clients[FW_MAX_CLIENTS];
20static int s_client_count = 0;
21
22static void log_fw(const char *verb, uint32_t client_ip, const char *mac)
23{
24 const tollgate_platform_t *p = tollgate_core_get_platform();
25 if (p && p->log_info) {
26 char ip_str[16];
27 snprintf(ip_str, sizeof(ip_str), "%d.%d.%d.%d",
28 (int)((client_ip >> 0) & 0xFF), (int)((client_ip >> 8) & 0xFF),
29 (int)((client_ip >> 16) & 0xFF), (int)((client_ip >> 24) & 0xFF));
30 p->log_info(TAG, "%s %s mac=%s", verb, ip_str, mac ? mac : "unknown");
31 }
32}
33
34int tg_firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, int mac_out_size)
35{
36 const tollgate_platform_t *p = tollgate_core_get_platform();
37 if (!p) return -1;
38
39 if (p->mac_for_ip) {
40 if (p->mac_for_ip(client_ip, mac_out, mac_out_size)) {
41 return 0;
42 }
43 }
44 return -1;
45}
46
47int tg_firewall_init(uint32_t ap_ip)
48{
49 s_ap_ip = ap_ip;
50 memset(s_clients, 0, sizeof(s_clients));
51 s_client_count = 0;
52 s_mining_port = 0;
53 s_sandbox_mint = false;
54
55 const tollgate_platform_t *p = tollgate_core_get_platform();
56 if (p && p->napt_enable) p->napt_enable(ap_ip, true);
57
58 if (p && p->log_info) {
59 char ip_str[16];
60 snprintf(ip_str, sizeof(ip_str), "%d.%d.%d.%d",
61 (int)((ap_ip >> 0) & 0xFF), (int)((ap_ip >> 8) & 0xFF),
62 (int)((ap_ip >> 16) & 0xFF), (int)((ap_ip >> 24) & 0xFF));
63 p->log_info(TAG, "Firewall initialized AP=%s NAT on, per-client filter", ip_str);
64 }
65 return 0;
66}
67
68static fw_client_t *find_client_by_ip(uint32_t client_ip)
69{
70 for (int i = 0; i < s_client_count; i++) {
71 if (s_clients[i].ip == client_ip) return &s_clients[i];
72 }
73 return NULL;
74}
75
76static fw_client_t *find_client_by_mac(const char *mac)
77{
78 for (int i = 0; i < s_client_count; i++) {
79 if (s_clients[i].mac[0] != '\0' && strcmp(s_clients[i].mac, mac) == 0) {
80 return &s_clients[i];
81 }
82 }
83 return NULL;
84}
85
86void tg_firewall_grant(uint32_t client_ip)
87{
88 fw_client_t *existing = find_client_by_ip(client_ip);
89 if (existing) return;
90
91 if (s_client_count >= FW_MAX_CLIENTS) {
92 const tollgate_platform_t *p = tollgate_core_get_platform();
93 if (p && p->log_warn) p->log_warn(TAG, "Max clients, cannot grant");
94 return;
95 }
96
97 fw_client_t *c = &s_clients[s_client_count];
98 c->ip = client_ip;
99 c->mac[0] = '\0';
100 tg_firewall_get_mac_for_ip(client_ip, c->mac, sizeof(c->mac));
101 s_client_count++;
102
103 log_fw("granted", client_ip, c->mac[0] ? c->mac : "unknown");
104}
105
106void tg_firewall_revoke(uint32_t client_ip)
107{
108 for (int i = 0; i < s_client_count; i++) {
109 if (s_clients[i].ip == client_ip) {
110 log_fw("revoked", client_ip, s_clients[i].mac[0] ? s_clients[i].mac : "unknown");
111 s_clients[i] = s_clients[s_client_count - 1];
112 s_client_count--;
113 return;
114 }
115 }
116}
117
118int tg_firewall_revoke_all(void)
119{
120 s_client_count = 0;
121 memset(s_clients, 0, sizeof(s_clients));
122 const tollgate_platform_t *p = tollgate_core_get_platform();
123 if (p && p->log_info) p->log_info(TAG, "All clients revoked");
124 return 0;
125}
126
127bool tg_firewall_is_allowed(uint32_t client_ip)
128{
129 return find_client_by_ip(client_ip) != NULL;
130}
131
132bool tg_firewall_is_mac_allowed(const char *mac)
133{
134 return find_client_by_mac(mac) != NULL;
135}
136
137int tg_firewall_client_count(void)
138{
139 return s_client_count;
140}
141
142void tg_firewall_set_mining_port(uint16_t port)
143{
144 s_mining_port = port;
145}
146
147void tg_firewall_set_sandbox_mint_access(bool enable)
148{
149 s_sandbox_mint = enable;
150}
151
152int tg_firewall_filter_packet(const uint8_t *payload, int payload_len)
153{
154 if (payload_len < 20) return -1;
155
156 uint32_t src_ip = (uint32_t)payload[12] | ((uint32_t)payload[13] << 8) |
157 ((uint32_t)payload[14] << 16) | ((uint32_t)payload[15] << 24);
158
159 uint32_t ap_subnet = s_ap_ip & 0x00FFFFFF;
160 uint32_t src_subnet = src_ip & 0x00FFFFFF;
161 if (src_subnet != ap_subnet) return 1;
162
163 if (tg_firewall_is_allowed(src_ip)) return 1;
164
165 return 0;
166}
diff --git a/tollgate_core/src/tollgate_firewall.h b/tollgate_core/src/tollgate_firewall.h
deleted file mode 100644
index 7df8a45..0000000
--- a/tollgate_core/src/tollgate_firewall.h
+++ /dev/null
@@ -1,21 +0,0 @@
1#ifndef TOLLGATE_CORE_FIREWALL_H
2#define TOLLGATE_CORE_FIREWALL_H
3
4#include <stdint.h>
5#include <stdbool.h>
6
7#define TG_FW_MAX_MAC_LEN 18
8
9int tg_firewall_init(uint32_t ap_ip);
10void tg_firewall_grant(uint32_t client_ip);
11void tg_firewall_revoke(uint32_t client_ip);
12int tg_firewall_revoke_all(void);
13bool tg_firewall_is_allowed(uint32_t client_ip);
14bool tg_firewall_is_mac_allowed(const char *mac);
15int tg_firewall_client_count(void);
16int tg_firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, int mac_out_size);
17void tg_firewall_set_mining_port(uint16_t port);
18void tg_firewall_set_sandbox_mint_access(bool enable);
19int tg_firewall_filter_packet(const uint8_t *payload, int payload_len);
20
21#endif
diff --git a/tollgate_core/src/tollgate_mining.c b/tollgate_core/src/tollgate_mining.c
deleted file mode 100644
index 8a4a778..0000000
--- a/tollgate_core/src/tollgate_mining.c
+++ /dev/null
@@ -1,171 +0,0 @@
1#include "tollgate_mining.h"
2#include "tollgate_core.h"
3#include "tollgate_platform.h"
4#include <string.h>
5#include <math.h>
6
7static const char *TAG = "tg_mining";
8
9static tg_mining_client_stats_t s_clients[TG_MINING_MAX_CLIENTS];
10static int s_client_count = 0;
11static double s_current_hashprice = 0.0;
12static uint32_t s_current_nbits = 0;
13static uint64_t s_current_difficulty = 1;
14
15static int64_t get_time_ms(void)
16{
17 const tollgate_platform_t *p = tollgate_core_get_platform();
18 if (p && p->get_time_ms) return p->get_time_ms();
19 return 0;
20}
21
22uint64_t tg_mining_nbits_to_difficulty(uint32_t nbits)
23{
24 if (nbits == 0) return (uint64_t)-1;
25
26 uint32_t exponent = (nbits >> 24) & 0xFF;
27 uint32_t mantissa = nbits & 0x007FFFFF;
28
29 if (exponent <= 3) {
30 mantissa >>= (8 * (3 - exponent));
31 if (mantissa == 0) return (uint64_t)-1;
32 return 0x00000000FFFF0000ULL / mantissa;
33 }
34
35 uint64_t target = (uint64_t)mantissa << (8 * (exponent - 3));
36 if (target == 0) return (uint64_t)-1;
37
38 uint64_t pdiff = 0x00000000FFFF0000ULL;
39 uint64_t diff = pdiff / target;
40 if (diff == 0) diff = 1;
41 return diff;
42}
43
44double tg_mining_calculate_hashprice(uint32_t nbits)
45{
46 uint64_t diff = tg_mining_nbits_to_difficulty(nbits);
47 if (diff == 0 || diff == (uint64_t)-1) return 0.0;
48
49 double network_hashrate_th = (double)diff * 4294967296.0 / 1e12;
50 double daily_sats = (double)TG_MINING_BLOCK_SUBSIDY_SATS * (double)TG_MINING_BLOCKS_PER_DAY;
51 double sats_per_th_day = daily_sats / network_hashrate_th;
52 return sats_per_th_day / 1000.0;
53}
54
55double tg_mining_calculate_hashprice_override(uint64_t sats_per_ghs_day)
56{
57 return (double)sats_per_ghs_day;
58}
59
60int tg_mining_validate_share(const uint8_t *header80, uint32_t nonce, const uint8_t *target, int target_len)
61{
62 (void)header80;
63 (void)nonce;
64 (void)target;
65 (void)target_len;
66 return 0;
67}
68
69uint64_t tg_mining_shares_to_allotment_ms(double hashrate_ghs, double hashprice_sats_per_ghs_s,
70 int price_per_step, int step_size_ms)
71{
72 if (hashrate_ghs <= 0.0 || hashprice_sats_per_ghs_s <= 0.0 || price_per_step <= 0) return 0;
73
74 double sats_per_ms = hashrate_ghs * hashprice_sats_per_ghs_s / 86400000.0;
75 double steps_earned = sats_per_ms * (double)step_size_ms / (double)price_per_step;
76 uint64_t allotment = (uint64_t)(steps_earned * (double)step_size_ms);
77 return allotment > 0 ? allotment : 1;
78}
79
80uint64_t tg_mining_shares_to_allotment_bytes(double hashrate_ghs, double hashprice_sats_per_ghs_s,
81 int price_per_step, int step_size_bytes)
82{
83 if (hashrate_ghs <= 0.0 || hashprice_sats_per_ghs_s <= 0.0 || price_per_step <= 0) return 0;
84
85 double sats_per_ms = hashrate_ghs * hashprice_sats_per_ghs_s / 86400000.0;
86 double steps_earned = sats_per_ms * 1000.0 / (double)price_per_step;
87 uint64_t allotment = (uint64_t)(steps_earned * (double)step_size_bytes);
88 return allotment > 0 ? allotment : 1;
89}
90
91tg_mining_client_stats_t *tg_mining_get_or_create_client(uint32_t client_ip)
92{
93 for (int i = 0; i < s_client_count; i++) {
94 if (s_clients[i].ip == client_ip) return &s_clients[i];
95 }
96
97 if (s_client_count >= TG_MINING_MAX_CLIENTS) {
98 for (int i = 0; i < TG_MINING_MAX_CLIENTS; i++) {
99 int64_t age = get_time_ms() - s_clients[i].last_share_time_ms;
100 if (age > TG_MINING_SHARE_WINDOW_S * 2000) {
101 memset(&s_clients[i], 0, sizeof(tg_mining_client_stats_t));
102 s_clients[i].ip = client_ip;
103 s_clients[i].first_share_time_ms = get_time_ms();
104 return &s_clients[i];
105 }
106 }
107 return NULL;
108 }
109
110 tg_mining_client_stats_t *c = &s_clients[s_client_count];
111 memset(c, 0, sizeof(tg_mining_client_stats_t));
112 c->ip = client_ip;
113 c->first_share_time_ms = get_time_ms();
114 s_client_count++;
115 return c;
116}
117
118void tg_mining_update_hashrate(uint32_t client_ip, bool accepted)
119{
120 tg_mining_client_stats_t *stats = tg_mining_get_or_create_client(client_ip);
121 if (!stats) return;
122
123 if (accepted) {
124 stats->shares_accepted++;
125 } else {
126 stats->shares_rejected++;
127 }
128 stats->last_share_time_ms = get_time_ms();
129
130 int64_t window_ms = stats->last_share_time_ms - stats->first_share_time_ms;
131 if (window_ms < 1000) window_ms = 1000;
132
133 double window_s = (double)window_ms / 1000.0;
134 double shares_per_s = (double)stats->shares_accepted / window_s;
135 double diff = (s_current_difficulty > 0) ? (double)s_current_difficulty : 1.0;
136 stats->hashrate_ghs = shares_per_s * diff * 4294967296.0 / 1e9;
137}
138
139const tg_mining_client_stats_t *tg_mining_get_client_stats(uint32_t client_ip)
140{
141 for (int i = 0; i < s_client_count; i++) {
142 if (s_clients[i].ip == client_ip) return &s_clients[i];
143 }
144 return NULL;
145}
146
147double tg_mining_get_current_hashprice(void)
148{
149 return s_current_hashprice;
150}
151
152void tg_mining_set_current_nbits(uint32_t nbits)
153{
154 s_current_nbits = nbits;
155 s_current_difficulty = tg_mining_nbits_to_difficulty(nbits);
156 s_current_hashprice = tg_mining_calculate_hashprice(nbits);
157 const tollgate_platform_t *p = tollgate_core_get_platform();
158 if (p && p->log_info) p->log_info(TAG, "nbits: 0x%08lx, diff=%llu, hashprice=%.6f sat/GH/s/day",
159 (unsigned long)nbits, (unsigned long long)s_current_difficulty, s_current_hashprice);
160}
161
162void tg_mining_init(void)
163{
164 memset(s_clients, 0, sizeof(s_clients));
165 s_client_count = 0;
166 s_current_hashprice = 0.0;
167 s_current_nbits = 0;
168 s_current_difficulty = 1;
169 const tollgate_platform_t *p = tollgate_core_get_platform();
170 if (p && p->log_info) p->log_info(TAG, "Mining payment initialized");
171}
diff --git a/tollgate_core/src/tollgate_mining.h b/tollgate_core/src/tollgate_mining.h
deleted file mode 100644
index 39681a5..0000000
--- a/tollgate_core/src/tollgate_mining.h
+++ /dev/null
@@ -1,34 +0,0 @@
1#ifndef TOLLGATE_CORE_MINING_H
2#define TOLLGATE_CORE_MINING_H
3
4#include <stdint.h>
5#include <stdbool.h>
6
7#define TG_MINING_SHARE_WINDOW_S 30
8#define TG_MINING_BLOCK_SUBSIDY_SATS 312500000ULL
9#define TG_MINING_BLOCKS_PER_DAY 144ULL
10#define TG_MINING_MAX_CLIENTS 10
11
12typedef struct {
13 uint32_t ip;
14 uint64_t shares_accepted;
15 uint64_t shares_rejected;
16 int64_t first_share_time_ms;
17 int64_t last_share_time_ms;
18 double hashrate_ghs;
19} tg_mining_client_stats_t;
20
21uint64_t tg_mining_nbits_to_difficulty(uint32_t nbits);
22double tg_mining_calculate_hashprice(uint32_t nbits);
23double tg_mining_calculate_hashprice_override(uint64_t sats_per_ghs_day);
24int tg_mining_validate_share(const uint8_t *header80, uint32_t nonce, const uint8_t *target, int target_len);
25uint64_t tg_mining_shares_to_allotment_ms(double hashrate_ghs, double hashprice, int price, int step_ms);
26uint64_t tg_mining_shares_to_allotment_bytes(double hashrate_ghs, double hashprice, int price, int step_bytes);
27tg_mining_client_stats_t *tg_mining_get_or_create_client(uint32_t client_ip);
28void tg_mining_update_hashrate(uint32_t client_ip, bool accepted);
29const tg_mining_client_stats_t *tg_mining_get_client_stats(uint32_t client_ip);
30double tg_mining_get_current_hashprice(void);
31void tg_mining_set_current_nbits(uint32_t nbits);
32void tg_mining_init(void);
33
34#endif
diff --git a/tollgate_core/src/tollgate_session.c b/tollgate_core/src/tollgate_session.c
deleted file mode 100644
index 667dbd0..0000000
--- a/tollgate_core/src/tollgate_session.c
+++ /dev/null
@@ -1,220 +0,0 @@
1#include "tollgate_session.h"
2#include "tollgate_core.h"
3#include "tollgate_platform.h"
4#include "tollgate_firewall.h"
5#include <string.h>
6#include <stdio.h>
7
8static const char *TAG = "tg_session";
9static tg_session_t s_sessions[TG_SESSION_MAX_CLIENTS];
10static int s_session_count = 0;
11
12static void format_ip(uint32_t ip, char *buf, int buf_len)
13{
14 snprintf(buf, buf_len, "%d.%d.%d.%d",
15 (int)((ip >> 0) & 0xFF), (int)((ip >> 8) & 0xFF),
16 (int)((ip >> 16) & 0xFF), (int)((ip >> 24) & 0xFF));
17}
18
19static int64_t get_time_ms(void)
20{
21 const tollgate_platform_t *p = tollgate_core_get_platform();
22 if (p && p->get_time_ms) return p->get_time_ms();
23 return 0;
24}
25
26static void log_session(const char *verb, uint32_t client_ip, const char *mac, const char *detail)
27{
28 const tollgate_platform_t *p = tollgate_core_get_platform();
29 if (p && p->log_info) {
30 char ip_str[16];
31 format_ip(client_ip, ip_str, sizeof(ip_str));
32 p->log_info(TAG, "%s: %s mac=%s %s", verb, ip_str, mac ? mac : "unknown", detail ? detail : "");
33 }
34}
35
36int tg_session_init(void)
37{
38 memset(s_sessions, 0, sizeof(s_sessions));
39 s_session_count = 0;
40 const tollgate_platform_t *p = tollgate_core_get_platform();
41 if (p && p->log_info) p->log_info(TAG, "Session manager initialized");
42 return 0;
43}
44
45static void populate_mac(tg_session_t *session, uint32_t client_ip)
46{
47 const tollgate_platform_t *p = tollgate_core_get_platform();
48 if (p && p->mac_for_ip) {
49 if (!p->mac_for_ip(client_ip, session->mac, sizeof(session->mac))) {
50 session->mac[0] = '\0';
51 }
52 } else {
53 session->mac[0] = '\0';
54 }
55}
56
57tg_session_t *tg_session_create(uint32_t client_ip, uint64_t allotment_ms)
58{
59 tg_session_t *existing = tg_session_find_by_ip(client_ip);
60 if (existing) {
61 tg_session_extend(existing, allotment_ms);
62 return existing;
63 }
64
65 if (s_session_count >= TG_SESSION_MAX_CLIENTS) {
66 for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) {
67 if (!s_sessions[i].active || tg_session_is_expired(&s_sessions[i])) {
68 tg_session_revoke(&s_sessions[i]);
69 break;
70 }
71 }
72 }
73
74 for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) {
75 if (!s_sessions[i].active) {
76 s_sessions[i].client_ip = client_ip;
77 s_sessions[i].allotment_ms = allotment_ms;
78 s_sessions[i].start_time_ms = get_time_ms();
79 s_sessions[i].active = true;
80 s_sessions[i].payment_method = TG_PAYMENT_CASHU;
81 populate_mac(&s_sessions[i], client_ip);
82
83 s_session_count++;
84 tg_firewall_grant(client_ip);
85
86 char detail[64];
87 snprintf(detail, sizeof(detail), "allotment=%llums", (unsigned long long)allotment_ms);
88 log_session("created", client_ip,
89 s_sessions[i].mac[0] ? s_sessions[i].mac : "unknown", detail);
90 return &s_sessions[i];
91 }
92 }
93
94 const tollgate_platform_t *p = tollgate_core_get_platform();
95 if (p && p->log_warn) p->log_warn(TAG, "No free session slots");
96 return NULL;
97}
98
99tg_session_t *tg_session_create_bytes(uint32_t client_ip, uint64_t allotment_bytes)
100{
101 tg_session_t *s = tg_session_create(client_ip, 0);
102 if (s) {
103 s->allotment_bytes = allotment_bytes;
104 s->bytes_consumed = 0;
105 s->allotment_ms = (uint64_t)-1;
106 s->payment_method = TG_PAYMENT_BYTES;
107 char detail[64];
108 snprintf(detail, sizeof(detail), "allotment=%llu bytes", (unsigned long long)allotment_bytes);
109 log_session("bytes session", client_ip, s->mac[0] ? s->mac : "unknown", detail);
110 }
111 return s;
112}
113
114void tg_session_add_bytes(uint32_t client_ip, uint64_t bytes)
115{
116 tg_session_t *s = tg_session_find_by_ip(client_ip);
117 if (s && s->active) {
118 s->bytes_consumed += bytes;
119 }
120}
121
122tg_session_t *tg_session_find_by_ip(uint32_t client_ip)
123{
124 for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) {
125 if (s_sessions[i].active && s_sessions[i].client_ip == client_ip) {
126 return &s_sessions[i];
127 }
128 }
129 return NULL;
130}
131
132tg_session_t *tg_session_find_by_mac(const char *mac)
133{
134 for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) {
135 if (s_sessions[i].active && s_sessions[i].mac[0] != '\0' &&
136 strcmp(s_sessions[i].mac, mac) == 0) {
137 return &s_sessions[i];
138 }
139 }
140 return NULL;
141}
142
143void tg_session_extend(tg_session_t *session, uint64_t additional_ms)
144{
145 if (!session || !session->active) return;
146 session->allotment_ms += additional_ms;
147 char detail[64];
148 snprintf(detail, sizeof(detail), "+%llums (total=%llu)",
149 (unsigned long long)additional_ms, (unsigned long long)session->allotment_ms);
150 log_session("extended", session->client_ip,
151 session->mac[0] ? session->mac : "unknown", detail);
152}
153
154bool tg_session_is_expired(const tg_session_t *session)
155{
156 if (!session || !session->active) return true;
157
158 const tollgate_platform_t *p = tollgate_core_get_platform();
159 if (p && p->get_metric) {
160 const char *metric = p->get_metric();
161 if (metric && strcmp(metric, "bytes") == 0) {
162 return session->bytes_consumed >= session->allotment_bytes;
163 }
164 }
165
166 int64_t elapsed = get_time_ms() - session->start_time_ms;
167 return elapsed >= (int64_t)session->allotment_ms;
168}
169
170static void check_expiry(void)
171{
172 for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) {
173 if (s_sessions[i].active && tg_session_is_expired(&s_sessions[i])) {
174 log_session("expired", s_sessions[i].client_ip,
175 s_sessions[i].mac[0] ? s_sessions[i].mac : "unknown", NULL);
176 tg_session_revoke(&s_sessions[i]);
177 }
178 }
179}
180
181void tg_session_revoke(tg_session_t *session)
182{
183 if (!session || !session->active) return;
184 tg_firewall_revoke(session->client_ip);
185 session->active = false;
186 s_session_count--;
187}
188
189void tg_session_revoke_all(void)
190{
191 for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) {
192 if (s_sessions[i].active) {
193 tg_session_revoke(&s_sessions[i]);
194 }
195 }
196}
197
198int tg_session_active_count(void)
199{
200 int count = 0;
201 for (int i = 0; i < TG_SESSION_MAX_CLIENTS; i++) {
202 if (s_sessions[i].active) count++;
203 }
204 return count;
205}
206
207void tg_session_tick(void)
208{
209 check_expiry();
210}
211
212tg_session_t *tg_session_get_array(void)
213{
214 return s_sessions;
215}
216
217int tg_session_get_array_size(void)
218{
219 return TG_SESSION_MAX_CLIENTS;
220}
diff --git a/tollgate_core/src/tollgate_session.h b/tollgate_core/src/tollgate_session.h
deleted file mode 100644
index 4008b24..0000000
--- a/tollgate_core/src/tollgate_session.h
+++ /dev/null
@@ -1,42 +0,0 @@
1#ifndef TOLLGATE_CORE_SESSION_H
2#define TOLLGATE_CORE_SESSION_H
3
4#include <stdint.h>
5#include <stdbool.h>
6
7#define TG_SESSION_MAX_CLIENTS 10
8#define TG_SESSION_MAX_MAC_LEN 18
9
10typedef enum {
11 TG_PAYMENT_CASHU,
12 TG_PAYMENT_MINING,
13 TG_PAYMENT_BYTES
14} tg_payment_method_t;
15
16typedef struct {
17 uint32_t client_ip;
18 char mac[TG_SESSION_MAX_MAC_LEN];
19 uint64_t allotment_ms;
20 int64_t start_time_ms;
21 uint64_t allotment_bytes;
22 uint64_t bytes_consumed;
23 tg_payment_method_t payment_method;
24 bool active;
25} tg_session_t;
26
27int tg_session_init(void);
28tg_session_t *tg_session_create(uint32_t client_ip, uint64_t allotment_ms);
29tg_session_t *tg_session_create_bytes(uint32_t client_ip, uint64_t allotment_bytes);
30void tg_session_add_bytes(uint32_t client_ip, uint64_t bytes);
31tg_session_t *tg_session_find_by_ip(uint32_t client_ip);
32tg_session_t *tg_session_find_by_mac(const char *mac);
33void tg_session_extend(tg_session_t *session, uint64_t additional_ms);
34bool tg_session_is_expired(const tg_session_t *session);
35void tg_session_revoke(tg_session_t *session);
36void tg_session_revoke_all(void);
37int tg_session_active_count(void);
38void tg_session_tick(void);
39tg_session_t *tg_session_get_array(void);
40int tg_session_get_array_size(void);
41
42#endif