diff options
| author | Your Name <you@example.com> | 2026-05-23 04:50:26 +0530 |
|---|---|---|
| committer | Your Name <you@example.com> | 2026-05-23 04:50:26 +0530 |
| commit | 9330b01c28aebc865a3c0a51df8730196cb4152e (patch) | |
| tree | 60c3ae35b2550c737c228e81fd342c8d07af11af /components | |
| parent | 851801f50f1282ab1db5f8a241dbd245f59e447e (diff) | |
Phase 6a-6d: Consolidate and clean up
6a: Delete dead standalone tollgate_core/ (12 files, never compiled)
6b: Rewrite dns_server.c as thin shim to component's tollgate_core_dns
- Fix component DNS to bind to AP IP instead of INADDR_ANY
6c: Rewrite stratum_proxy.c as thin shim with struct cast to component types
6d: Move sandbox logic into component's tollgate_core_firewall
- Add tollgate_core_fw_set_sandbox_ports/set_sandbox_mint_access
- Add is_sandbox_allowed() to component's ip4_canforward_filter
- Clean main/firewall.c to delegate filter to component
- Remove redundant DNS auth double-calls from main firewall
Add ROADMAP.md with full extraction plan and checklists
All 21 unit tests pass. ESP-IDF build passes.
Diffstat (limited to 'components')
| -rw-r--r-- | components/tollgate_core/src/tollgate_core_dns.c | 2 | ||||
| -rw-r--r-- | components/tollgate_core/src/tollgate_core_firewall.c | 47 | ||||
| -rw-r--r-- | components/tollgate_core/src/tollgate_core_firewall.h | 2 |
3 files changed, 50 insertions, 1 deletions
diff --git a/components/tollgate_core/src/tollgate_core_dns.c b/components/tollgate_core/src/tollgate_core_dns.c index 84322e6..c44dd31 100644 --- a/components/tollgate_core/src/tollgate_core_dns.c +++ b/components/tollgate_core/src/tollgate_core_dns.c | |||
| @@ -160,7 +160,7 @@ static void dns_server_task(void *arg) | |||
| 160 | struct sockaddr_in bind_addr = { | 160 | struct sockaddr_in bind_addr = { |
| 161 | .sin_family = AF_INET, | 161 | .sin_family = AF_INET, |
| 162 | .sin_port = htons(DNS_PORT), | 162 | .sin_port = htons(DNS_PORT), |
| 163 | .sin_addr.s_addr = INADDR_ANY, | 163 | .sin_addr.s_addr = s_ap_ip.addr, |
| 164 | }; | 164 | }; |
| 165 | if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { | 165 | if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { |
| 166 | ESP_LOGE(TAG, "Failed to bind DNS socket"); | 166 | ESP_LOGE(TAG, "Failed to bind DNS socket"); |
diff --git a/components/tollgate_core/src/tollgate_core_firewall.c b/components/tollgate_core/src/tollgate_core_firewall.c index ad0697e..4f12923 100644 --- a/components/tollgate_core/src/tollgate_core_firewall.c +++ b/components/tollgate_core/src/tollgate_core_firewall.c | |||
| @@ -9,12 +9,16 @@ | |||
| 9 | #include "lwip/etharp.h" | 9 | #include "lwip/etharp.h" |
| 10 | #include "lwip/netif.h" | 10 | #include "lwip/netif.h" |
| 11 | #include "lwip/prot/ip4.h" | 11 | #include "lwip/prot/ip4.h" |
| 12 | #include "lwip/prot/tcp.h" | ||
| 13 | #include "lwip/prot/ip.h" | ||
| 12 | #include <string.h> | 14 | #include <string.h> |
| 13 | 15 | ||
| 14 | #define MAX_CLIENTS 10 | 16 | #define MAX_CLIENTS 10 |
| 15 | 17 | ||
| 16 | static const char *TAG = "tg_core_fw"; | 18 | static const char *TAG = "tg_core_fw"; |
| 17 | static esp_ip4_addr_t s_ap_ip; | 19 | static esp_ip4_addr_t s_ap_ip; |
| 20 | static uint16_t s_mining_port = 3333; | ||
| 21 | static bool s_sandbox_mint_access = false; | ||
| 18 | 22 | ||
| 19 | typedef struct { | 23 | typedef struct { |
| 20 | uint32_t ip; | 24 | uint32_t ip; |
| @@ -70,6 +74,46 @@ esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip) | |||
| 70 | return ESP_OK; | 74 | return ESP_OK; |
| 71 | } | 75 | } |
| 72 | 76 | ||
| 77 | void tollgate_core_fw_set_sandbox_ports(uint16_t mining_port) | ||
| 78 | { | ||
| 79 | s_mining_port = mining_port; | ||
| 80 | } | ||
| 81 | |||
| 82 | void tollgate_core_fw_set_sandbox_mint_access(bool enabled) | ||
| 83 | { | ||
| 84 | s_sandbox_mint_access = enabled; | ||
| 85 | } | ||
| 86 | |||
| 87 | static bool is_sandbox_allowed(struct pbuf *p) | ||
| 88 | { | ||
| 89 | if (p->len < IP_HLEN) return false; | ||
| 90 | struct ip_hdr *iphdr = (struct ip_hdr *)p->payload; | ||
| 91 | uint32_t dest_ip_h = lwip_ntohl(iphdr->dest.addr); | ||
| 92 | uint32_t ap_ip_h = lwip_ntohl(s_ap_ip.addr); | ||
| 93 | |||
| 94 | if (dest_ip_h == ap_ip_h) { | ||
| 95 | if (iphdr->_proto == IP_PROTO_TCP) { | ||
| 96 | uint16_t dst_port = 0; | ||
| 97 | if (p->len >= IP_HLEN + TCP_HLEN) { | ||
| 98 | struct tcp_hdr *tcphdr = (struct tcp_hdr *)((uint8_t *)p->payload + IP_HLEN); | ||
| 99 | dst_port = lwip_ntohs(tcphdr->dest); | ||
| 100 | } | ||
| 101 | if (dst_port == 80 || dst_port == 2121 || dst_port == s_mining_port) { | ||
| 102 | return true; | ||
| 103 | } | ||
| 104 | } | ||
| 105 | if (iphdr->_proto == IP_PROTO_UDP) { | ||
| 106 | return true; | ||
| 107 | } | ||
| 108 | } | ||
| 109 | |||
| 110 | if (s_sandbox_mint_access && iphdr->_proto == IP_PROTO_TCP) { | ||
| 111 | return true; | ||
| 112 | } | ||
| 113 | |||
| 114 | return false; | ||
| 115 | } | ||
| 116 | |||
| 73 | int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) | 117 | int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) |
| 74 | { | 118 | { |
| 75 | (void)dest_addr_hostorder; | 119 | (void)dest_addr_hostorder; |
| @@ -83,6 +127,9 @@ int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorde | |||
| 83 | if (tollgate_core_fw_is_allowed(iphdr->src.addr)) { | 127 | if (tollgate_core_fw_is_allowed(iphdr->src.addr)) { |
| 84 | return 1; | 128 | return 1; |
| 85 | } | 129 | } |
| 130 | if (is_sandbox_allowed(p)) { | ||
| 131 | return 1; | ||
| 132 | } | ||
| 86 | return 0; | 133 | return 0; |
| 87 | } | 134 | } |
| 88 | 135 | ||
diff --git a/components/tollgate_core/src/tollgate_core_firewall.h b/components/tollgate_core/src/tollgate_core_firewall.h index f06c801..7f24372 100644 --- a/components/tollgate_core/src/tollgate_core_firewall.h +++ b/components/tollgate_core/src/tollgate_core_firewall.h | |||
| @@ -11,6 +11,8 @@ struct pbuf; | |||
| 11 | #define TG_FW_MAX_MAC_LEN 18 | 11 | #define TG_FW_MAX_MAC_LEN 18 |
| 12 | 12 | ||
| 13 | esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip); | 13 | esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip); |
| 14 | void tollgate_core_fw_set_sandbox_ports(uint16_t mining_port); | ||
| 15 | void tollgate_core_fw_set_sandbox_mint_access(bool enabled); | ||
| 14 | void tollgate_core_fw_grant(uint32_t client_ip); | 16 | void tollgate_core_fw_grant(uint32_t client_ip); |
| 15 | void tollgate_core_fw_revoke(uint32_t client_ip); | 17 | void tollgate_core_fw_revoke(uint32_t client_ip); |
| 16 | void tollgate_core_fw_revoke_all(void); | 18 | void tollgate_core_fw_revoke_all(void); |