upleb.uk

Public git repos — served from a NIP-34 GRASP relay at git.upleb.uk

summaryrefslogtreecommitdiff
path: root/components/tollgate_core/src
diff options
context:
space:
mode:
authorYour Name <you@example.com>2026-05-23 04:50:26 +0530
committerYour Name <you@example.com>2026-05-23 04:50:26 +0530
commit9330b01c28aebc865a3c0a51df8730196cb4152e (patch)
tree60c3ae35b2550c737c228e81fd342c8d07af11af /components/tollgate_core/src
parent851801f50f1282ab1db5f8a241dbd245f59e447e (diff)
Phase 6a-6d: Consolidate and clean up
6a: Delete dead standalone tollgate_core/ (12 files, never compiled) 6b: Rewrite dns_server.c as thin shim to component's tollgate_core_dns - Fix component DNS to bind to AP IP instead of INADDR_ANY 6c: Rewrite stratum_proxy.c as thin shim with struct cast to component types 6d: Move sandbox logic into component's tollgate_core_firewall - Add tollgate_core_fw_set_sandbox_ports/set_sandbox_mint_access - Add is_sandbox_allowed() to component's ip4_canforward_filter - Clean main/firewall.c to delegate filter to component - Remove redundant DNS auth double-calls from main firewall Add ROADMAP.md with full extraction plan and checklists All 21 unit tests pass. ESP-IDF build passes.
Diffstat (limited to 'components/tollgate_core/src')
-rw-r--r--components/tollgate_core/src/tollgate_core_dns.c2
-rw-r--r--components/tollgate_core/src/tollgate_core_firewall.c47
-rw-r--r--components/tollgate_core/src/tollgate_core_firewall.h2
3 files changed, 50 insertions, 1 deletions
diff --git a/components/tollgate_core/src/tollgate_core_dns.c b/components/tollgate_core/src/tollgate_core_dns.c
index 84322e6..c44dd31 100644
--- a/components/tollgate_core/src/tollgate_core_dns.c
+++ b/components/tollgate_core/src/tollgate_core_dns.c
@@ -160,7 +160,7 @@ static void dns_server_task(void *arg)
160 struct sockaddr_in bind_addr = { 160 struct sockaddr_in bind_addr = {
161 .sin_family = AF_INET, 161 .sin_family = AF_INET,
162 .sin_port = htons(DNS_PORT), 162 .sin_port = htons(DNS_PORT),
163 .sin_addr.s_addr = INADDR_ANY, 163 .sin_addr.s_addr = s_ap_ip.addr,
164 }; 164 };
165 if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { 165 if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) {
166 ESP_LOGE(TAG, "Failed to bind DNS socket"); 166 ESP_LOGE(TAG, "Failed to bind DNS socket");
diff --git a/components/tollgate_core/src/tollgate_core_firewall.c b/components/tollgate_core/src/tollgate_core_firewall.c
index ad0697e..4f12923 100644
--- a/components/tollgate_core/src/tollgate_core_firewall.c
+++ b/components/tollgate_core/src/tollgate_core_firewall.c
@@ -9,12 +9,16 @@
9#include "lwip/etharp.h" 9#include "lwip/etharp.h"
10#include "lwip/netif.h" 10#include "lwip/netif.h"
11#include "lwip/prot/ip4.h" 11#include "lwip/prot/ip4.h"
12#include "lwip/prot/tcp.h"
13#include "lwip/prot/ip.h"
12#include <string.h> 14#include <string.h>
13 15
14#define MAX_CLIENTS 10 16#define MAX_CLIENTS 10
15 17
16static const char *TAG = "tg_core_fw"; 18static const char *TAG = "tg_core_fw";
17static esp_ip4_addr_t s_ap_ip; 19static esp_ip4_addr_t s_ap_ip;
20static uint16_t s_mining_port = 3333;
21static bool s_sandbox_mint_access = false;
18 22
19typedef struct { 23typedef struct {
20 uint32_t ip; 24 uint32_t ip;
@@ -70,6 +74,46 @@ esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip)
70 return ESP_OK; 74 return ESP_OK;
71} 75}
72 76
77void tollgate_core_fw_set_sandbox_ports(uint16_t mining_port)
78{
79 s_mining_port = mining_port;
80}
81
82void tollgate_core_fw_set_sandbox_mint_access(bool enabled)
83{
84 s_sandbox_mint_access = enabled;
85}
86
87static bool is_sandbox_allowed(struct pbuf *p)
88{
89 if (p->len < IP_HLEN) return false;
90 struct ip_hdr *iphdr = (struct ip_hdr *)p->payload;
91 uint32_t dest_ip_h = lwip_ntohl(iphdr->dest.addr);
92 uint32_t ap_ip_h = lwip_ntohl(s_ap_ip.addr);
93
94 if (dest_ip_h == ap_ip_h) {
95 if (iphdr->_proto == IP_PROTO_TCP) {
96 uint16_t dst_port = 0;
97 if (p->len >= IP_HLEN + TCP_HLEN) {
98 struct tcp_hdr *tcphdr = (struct tcp_hdr *)((uint8_t *)p->payload + IP_HLEN);
99 dst_port = lwip_ntohs(tcphdr->dest);
100 }
101 if (dst_port == 80 || dst_port == 2121 || dst_port == s_mining_port) {
102 return true;
103 }
104 }
105 if (iphdr->_proto == IP_PROTO_UDP) {
106 return true;
107 }
108 }
109
110 if (s_sandbox_mint_access && iphdr->_proto == IP_PROTO_TCP) {
111 return true;
112 }
113
114 return false;
115}
116
73int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) 117int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder)
74{ 118{
75 (void)dest_addr_hostorder; 119 (void)dest_addr_hostorder;
@@ -83,6 +127,9 @@ int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorde
83 if (tollgate_core_fw_is_allowed(iphdr->src.addr)) { 127 if (tollgate_core_fw_is_allowed(iphdr->src.addr)) {
84 return 1; 128 return 1;
85 } 129 }
130 if (is_sandbox_allowed(p)) {
131 return 1;
132 }
86 return 0; 133 return 0;
87} 134}
88 135
diff --git a/components/tollgate_core/src/tollgate_core_firewall.h b/components/tollgate_core/src/tollgate_core_firewall.h
index f06c801..7f24372 100644
--- a/components/tollgate_core/src/tollgate_core_firewall.h
+++ b/components/tollgate_core/src/tollgate_core_firewall.h
@@ -11,6 +11,8 @@ struct pbuf;
11#define TG_FW_MAX_MAC_LEN 18 11#define TG_FW_MAX_MAC_LEN 18
12 12
13esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip); 13esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip);
14void tollgate_core_fw_set_sandbox_ports(uint16_t mining_port);
15void tollgate_core_fw_set_sandbox_mint_access(bool enabled);
14void tollgate_core_fw_grant(uint32_t client_ip); 16void tollgate_core_fw_grant(uint32_t client_ip);
15void tollgate_core_fw_revoke(uint32_t client_ip); 17void tollgate_core_fw_revoke(uint32_t client_ip);
16void tollgate_core_fw_revoke_all(void); 18void tollgate_core_fw_revoke_all(void);