upleb.uk

Public git repos — served from a NIP-34 GRASP relay at git.upleb.uk

summaryrefslogtreecommitdiff
path: root/main/firewall.c
diff options
context:
space:
mode:
authorYour Name <you@example.com>2026-05-23 04:10:28 +0530
committerYour Name <you@example.com>2026-05-23 04:10:28 +0530
commit851801f50f1282ab1db5f8a241dbd245f59e447e (patch)
tree3285d0714da89879acd21b8c3fb9afeff586ed1e /main/firewall.c
parent39aa27a9522aeb8f731f4d3de48939e75775900e (diff)
Phase 5: Wire main/ shims to components/tollgate_core
- session.c/h: thin shim casting session_t* <-> tg_session_t*, delegates to tollgate_core_session_* - firewall.c/h: keeps ESP-specific lwIP hooks, delegates allowlist to tollgate_core_fw_* - cashu.c/h: shim delegates to tollgate_core_cashu_*, multi-mint via config directly - mining_payment.c: shim delegates to tollgate_core_mining_* - tollgate_main.c: calls tollgate_core_init(tollgate_esp_get_platform(), ap_ip) in start_services() - tollgate_esp: removed target_sources for standalone sources, depends on tollgate_core component - tollgate_core component: added tollgate_core_get_platform(), tg_payment_method_t enum - Unit tests: updated Makefile for component source compilation, all 22 tests pass - Hardware verified: Board A boots, AP visible, 5/6 smoke tests pass (internet test needs upstream WiFi)
Diffstat (limited to 'main/firewall.c')
-rw-r--r--main/firewall.c124
1 files changed, 21 insertions, 103 deletions
diff --git a/main/firewall.c b/main/firewall.c
index ae0eda7..077d16c 100644
--- a/main/firewall.c
+++ b/main/firewall.c
@@ -1,70 +1,23 @@
1#include "firewall.h" 1#include "firewall.h"
2#include "dns_server.h" 2#include "dns_server.h"
3#include "tollgate_core.h"
4#include "tollgate_core_firewall.h"
3#include "esp_log.h" 5#include "esp_log.h"
4#include "esp_wifi.h"
5#include "esp_wifi_ap_get_sta_list.h"
6#include "lwip/lwip_napt.h"
7#include "lwip/etharp.h"
8#include "lwip/netif.h" 6#include "lwip/netif.h"
7#include "lwip/lwip_napt.h"
9#include "lwip/prot/ip4.h" 8#include "lwip/prot/ip4.h"
10#include "lwip/prot/tcp.h" 9#include "lwip/prot/tcp.h"
11#include "lwip/prot/ip.h" 10#include "lwip/prot/ip.h"
12#include <string.h> 11#include <string.h>
13 12
14#define MAX_CLIENTS 10
15
16static const char *TAG = "firewall"; 13static const char *TAG = "firewall";
17static esp_ip4_addr_t s_ap_ip; 14static esp_ip4_addr_t s_ap_ip;
18static uint16_t s_mining_port = 3333; 15static uint16_t s_mining_port = 3333;
19static bool s_sandbox_mint_access = false; 16static bool s_sandbox_mint_access = false;
20 17
21typedef struct {
22 uint32_t ip;
23 char mac[FW_MAX_MAC_LEN];
24} fw_client_t;
25
26static fw_client_t s_clients[MAX_CLIENTS];
27static int s_client_count = 0;
28
29esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_out_size)
30{
31 wifi_sta_list_t sta_list;
32 if (esp_wifi_ap_get_sta_list(&sta_list) == ESP_OK) {
33 wifi_sta_mac_ip_list_t ip_mac_list;
34 if (esp_wifi_ap_get_sta_list_with_ip(&sta_list, &ip_mac_list) == ESP_OK) {
35 for (int i = 0; i < ip_mac_list.num; i++) {
36 if (ip_mac_list.sta[i].ip.addr == client_ip) {
37 snprintf(mac_out, mac_out_size, "%02x:%02x:%02x:%02x:%02x:%02x",
38 ip_mac_list.sta[i].mac[0], ip_mac_list.sta[i].mac[1],
39 ip_mac_list.sta[i].mac[2], ip_mac_list.sta[i].mac[3],
40 ip_mac_list.sta[i].mac[4], ip_mac_list.sta[i].mac[5]);
41 return ESP_OK;
42 }
43 }
44 }
45 }
46
47 ip4_addr_t *entry_ip = NULL;
48 struct netif *entry_netif = NULL;
49 struct eth_addr *entry_eth = NULL;
50 ssize_t i = 0;
51 while (etharp_get_entry(i, &entry_ip, &entry_netif, &entry_eth) == ERR_OK) {
52 if (entry_ip && entry_ip->addr == client_ip && entry_eth) {
53 snprintf(mac_out, mac_out_size, "%02x:%02x:%02x:%02x:%02x:%02x",
54 entry_eth->addr[0], entry_eth->addr[1], entry_eth->addr[2],
55 entry_eth->addr[3], entry_eth->addr[4], entry_eth->addr[5]);
56 return ESP_OK;
57 }
58 i++;
59 }
60 return ESP_FAIL;
61}
62
63esp_err_t firewall_init(esp_ip4_addr_t ap_ip) 18esp_err_t firewall_init(esp_ip4_addr_t ap_ip)
64{ 19{
65 s_ap_ip = ap_ip; 20 s_ap_ip = ap_ip;
66 memset(s_clients, 0, sizeof(s_clients));
67 s_client_count = 0;
68 ip_napt_enable(s_ap_ip.addr, 1); 21 ip_napt_enable(s_ap_ip.addr, 1);
69 ESP_LOGI(TAG, "Firewall initialized with AP IP=" IPSTR " (NAT always on, per-client filter)", IP2STR(&s_ap_ip)); 22 ESP_LOGI(TAG, "Firewall initialized with AP IP=" IPSTR " (NAT always on, per-client filter)", IP2STR(&s_ap_ip));
70 return ESP_OK; 23 return ESP_OK;
@@ -80,6 +33,11 @@ void firewall_set_sandbox_mint_access(bool enabled)
80 s_sandbox_mint_access = enabled; 33 s_sandbox_mint_access = enabled;
81} 34}
82 35
36esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_out_size)
37{
38 return tollgate_core_fw_get_mac_for_ip(client_ip, mac_out, mac_out_size);
39}
40
83static bool is_sandbox_allowed(struct pbuf *p) 41static bool is_sandbox_allowed(struct pbuf *p)
84{ 42{
85 if (p->len < IP_HLEN) return false; 43 if (p->len < IP_HLEN) return false;
@@ -129,84 +87,44 @@ int tollgate_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder)
129 return 0; 87 return 0;
130} 88}
131 89
132static fw_client_t *find_client_by_ip(uint32_t client_ip)
133{
134 for (int i = 0; i < s_client_count; i++) {
135 if (s_clients[i].ip == client_ip) return &s_clients[i];
136 }
137 return NULL;
138}
139
140static fw_client_t *find_client_by_mac(const char *mac)
141{
142 for (int i = 0; i < s_client_count; i++) {
143 if (s_clients[i].mac[0] != '\0' && strcmp(s_clients[i].mac, mac) == 0) {
144 return &s_clients[i];
145 }
146 }
147 return NULL;
148}
149
150void firewall_grant_access(uint32_t client_ip) 90void firewall_grant_access(uint32_t client_ip)
151{ 91{
152 fw_client_t *existing = find_client_by_ip(client_ip); 92 tollgate_core_fw_grant(client_ip);
153 if (existing) {
154 existing->ip = client_ip;
155 return;
156 }
157 if (s_client_count >= MAX_CLIENTS) {
158 ESP_LOGW(TAG, "Max clients reached, cannot grant access");
159 return;
160 }
161
162 fw_client_t *client = &s_clients[s_client_count];
163 client->ip = client_ip;
164 client->mac[0] = '\0';
165 firewall_get_mac_for_ip(client_ip, client->mac, sizeof(client->mac));
166 s_client_count++;
167
168 dns_server_set_client_authenticated(client_ip, true); 93 dns_server_set_client_authenticated(client_ip, true);
169 94
95 char mac[18] = {0};
96 tollgate_core_fw_get_mac_for_ip(client_ip, mac, sizeof(mac));
170 esp_ip4_addr_t ip_addr = { .addr = client_ip }; 97 esp_ip4_addr_t ip_addr = { .addr = client_ip };
171 ESP_LOGI(TAG, "Access granted to " IPSTR " mac=%s", IP2STR(&ip_addr), 98 ESP_LOGI(TAG, "Access granted to " IPSTR " mac=%s", IP2STR(&ip_addr),
172 client->mac[0] ? client->mac : "unknown"); 99 mac[0] ? mac : "unknown");
173} 100}
174 101
175void firewall_revoke_access(uint32_t client_ip) 102void firewall_revoke_access(uint32_t client_ip)
176{ 103{
177 for (int i = 0; i < s_client_count; i++) { 104 tollgate_core_fw_revoke(client_ip);
178 if (s_clients[i].ip == client_ip) { 105 dns_server_set_client_authenticated(client_ip, false);
179 esp_ip4_addr_t ip_addr = { .addr = client_ip }; 106
180 ESP_LOGI(TAG, "Access revoked for " IPSTR " mac=%s", IP2STR(&ip_addr), 107 esp_ip4_addr_t ip_addr = { .addr = client_ip };
181 s_clients[i].mac[0] ? s_clients[i].mac : "unknown"); 108 ESP_LOGI(TAG, "Access revoked for " IPSTR, IP2STR(&ip_addr));
182 s_clients[i] = s_clients[s_client_count - 1];
183 s_client_count--;
184 dns_server_set_client_authenticated(client_ip, false);
185 return;
186 }
187 }
188} 109}
189 110
190void firewall_revoke_all(void) 111void firewall_revoke_all(void)
191{ 112{
192 for (int i = 0; i < s_client_count; i++) { 113 tollgate_core_fw_revoke_all();
193 dns_server_set_client_authenticated(s_clients[i].ip, false);
194 }
195 s_client_count = 0;
196 ESP_LOGI(TAG, "All client access revoked"); 114 ESP_LOGI(TAG, "All client access revoked");
197} 115}
198 116
199bool firewall_is_client_allowed(uint32_t client_ip) 117bool firewall_is_client_allowed(uint32_t client_ip)
200{ 118{
201 return find_client_by_ip(client_ip) != NULL; 119 return tollgate_core_is_client_allowed(client_ip);
202} 120}
203 121
204bool firewall_is_mac_allowed(const char *mac) 122bool firewall_is_mac_allowed(const char *mac)
205{ 123{
206 return find_client_by_mac(mac) != NULL; 124 return tollgate_core_fw_is_mac_allowed(mac);
207} 125}
208 126
209int firewall_client_count(void) 127int firewall_client_count(void)
210{ 128{
211 return s_client_count; 129 return tollgate_core_allowed_client_count();
212} 130}