diff options
Diffstat (limited to 'main/firewall.c')
| -rw-r--r-- | main/firewall.c | 124 |
1 files changed, 21 insertions, 103 deletions
diff --git a/main/firewall.c b/main/firewall.c index ae0eda7..077d16c 100644 --- a/main/firewall.c +++ b/main/firewall.c | |||
| @@ -1,70 +1,23 @@ | |||
| 1 | #include "firewall.h" | 1 | #include "firewall.h" |
| 2 | #include "dns_server.h" | 2 | #include "dns_server.h" |
| 3 | #include "tollgate_core.h" | ||
| 4 | #include "tollgate_core_firewall.h" | ||
| 3 | #include "esp_log.h" | 5 | #include "esp_log.h" |
| 4 | #include "esp_wifi.h" | ||
| 5 | #include "esp_wifi_ap_get_sta_list.h" | ||
| 6 | #include "lwip/lwip_napt.h" | ||
| 7 | #include "lwip/etharp.h" | ||
| 8 | #include "lwip/netif.h" | 6 | #include "lwip/netif.h" |
| 7 | #include "lwip/lwip_napt.h" | ||
| 9 | #include "lwip/prot/ip4.h" | 8 | #include "lwip/prot/ip4.h" |
| 10 | #include "lwip/prot/tcp.h" | 9 | #include "lwip/prot/tcp.h" |
| 11 | #include "lwip/prot/ip.h" | 10 | #include "lwip/prot/ip.h" |
| 12 | #include <string.h> | 11 | #include <string.h> |
| 13 | 12 | ||
| 14 | #define MAX_CLIENTS 10 | ||
| 15 | |||
| 16 | static const char *TAG = "firewall"; | 13 | static const char *TAG = "firewall"; |
| 17 | static esp_ip4_addr_t s_ap_ip; | 14 | static esp_ip4_addr_t s_ap_ip; |
| 18 | static uint16_t s_mining_port = 3333; | 15 | static uint16_t s_mining_port = 3333; |
| 19 | static bool s_sandbox_mint_access = false; | 16 | static bool s_sandbox_mint_access = false; |
| 20 | 17 | ||
| 21 | typedef struct { | ||
| 22 | uint32_t ip; | ||
| 23 | char mac[FW_MAX_MAC_LEN]; | ||
| 24 | } fw_client_t; | ||
| 25 | |||
| 26 | static fw_client_t s_clients[MAX_CLIENTS]; | ||
| 27 | static int s_client_count = 0; | ||
| 28 | |||
| 29 | esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_out_size) | ||
| 30 | { | ||
| 31 | wifi_sta_list_t sta_list; | ||
| 32 | if (esp_wifi_ap_get_sta_list(&sta_list) == ESP_OK) { | ||
| 33 | wifi_sta_mac_ip_list_t ip_mac_list; | ||
| 34 | if (esp_wifi_ap_get_sta_list_with_ip(&sta_list, &ip_mac_list) == ESP_OK) { | ||
| 35 | for (int i = 0; i < ip_mac_list.num; i++) { | ||
| 36 | if (ip_mac_list.sta[i].ip.addr == client_ip) { | ||
| 37 | snprintf(mac_out, mac_out_size, "%02x:%02x:%02x:%02x:%02x:%02x", | ||
| 38 | ip_mac_list.sta[i].mac[0], ip_mac_list.sta[i].mac[1], | ||
| 39 | ip_mac_list.sta[i].mac[2], ip_mac_list.sta[i].mac[3], | ||
| 40 | ip_mac_list.sta[i].mac[4], ip_mac_list.sta[i].mac[5]); | ||
| 41 | return ESP_OK; | ||
| 42 | } | ||
| 43 | } | ||
| 44 | } | ||
| 45 | } | ||
| 46 | |||
| 47 | ip4_addr_t *entry_ip = NULL; | ||
| 48 | struct netif *entry_netif = NULL; | ||
| 49 | struct eth_addr *entry_eth = NULL; | ||
| 50 | ssize_t i = 0; | ||
| 51 | while (etharp_get_entry(i, &entry_ip, &entry_netif, &entry_eth) == ERR_OK) { | ||
| 52 | if (entry_ip && entry_ip->addr == client_ip && entry_eth) { | ||
| 53 | snprintf(mac_out, mac_out_size, "%02x:%02x:%02x:%02x:%02x:%02x", | ||
| 54 | entry_eth->addr[0], entry_eth->addr[1], entry_eth->addr[2], | ||
| 55 | entry_eth->addr[3], entry_eth->addr[4], entry_eth->addr[5]); | ||
| 56 | return ESP_OK; | ||
| 57 | } | ||
| 58 | i++; | ||
| 59 | } | ||
| 60 | return ESP_FAIL; | ||
| 61 | } | ||
| 62 | |||
| 63 | esp_err_t firewall_init(esp_ip4_addr_t ap_ip) | 18 | esp_err_t firewall_init(esp_ip4_addr_t ap_ip) |
| 64 | { | 19 | { |
| 65 | s_ap_ip = ap_ip; | 20 | s_ap_ip = ap_ip; |
| 66 | memset(s_clients, 0, sizeof(s_clients)); | ||
| 67 | s_client_count = 0; | ||
| 68 | ip_napt_enable(s_ap_ip.addr, 1); | 21 | ip_napt_enable(s_ap_ip.addr, 1); |
| 69 | ESP_LOGI(TAG, "Firewall initialized with AP IP=" IPSTR " (NAT always on, per-client filter)", IP2STR(&s_ap_ip)); | 22 | ESP_LOGI(TAG, "Firewall initialized with AP IP=" IPSTR " (NAT always on, per-client filter)", IP2STR(&s_ap_ip)); |
| 70 | return ESP_OK; | 23 | return ESP_OK; |
| @@ -80,6 +33,11 @@ void firewall_set_sandbox_mint_access(bool enabled) | |||
| 80 | s_sandbox_mint_access = enabled; | 33 | s_sandbox_mint_access = enabled; |
| 81 | } | 34 | } |
| 82 | 35 | ||
| 36 | esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_out_size) | ||
| 37 | { | ||
| 38 | return tollgate_core_fw_get_mac_for_ip(client_ip, mac_out, mac_out_size); | ||
| 39 | } | ||
| 40 | |||
| 83 | static bool is_sandbox_allowed(struct pbuf *p) | 41 | static bool is_sandbox_allowed(struct pbuf *p) |
| 84 | { | 42 | { |
| 85 | if (p->len < IP_HLEN) return false; | 43 | if (p->len < IP_HLEN) return false; |
| @@ -129,84 +87,44 @@ int tollgate_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) | |||
| 129 | return 0; | 87 | return 0; |
| 130 | } | 88 | } |
| 131 | 89 | ||
| 132 | static fw_client_t *find_client_by_ip(uint32_t client_ip) | ||
| 133 | { | ||
| 134 | for (int i = 0; i < s_client_count; i++) { | ||
| 135 | if (s_clients[i].ip == client_ip) return &s_clients[i]; | ||
| 136 | } | ||
| 137 | return NULL; | ||
| 138 | } | ||
| 139 | |||
| 140 | static fw_client_t *find_client_by_mac(const char *mac) | ||
| 141 | { | ||
| 142 | for (int i = 0; i < s_client_count; i++) { | ||
| 143 | if (s_clients[i].mac[0] != '\0' && strcmp(s_clients[i].mac, mac) == 0) { | ||
| 144 | return &s_clients[i]; | ||
| 145 | } | ||
| 146 | } | ||
| 147 | return NULL; | ||
| 148 | } | ||
| 149 | |||
| 150 | void firewall_grant_access(uint32_t client_ip) | 90 | void firewall_grant_access(uint32_t client_ip) |
| 151 | { | 91 | { |
| 152 | fw_client_t *existing = find_client_by_ip(client_ip); | 92 | tollgate_core_fw_grant(client_ip); |
| 153 | if (existing) { | ||
| 154 | existing->ip = client_ip; | ||
| 155 | return; | ||
| 156 | } | ||
| 157 | if (s_client_count >= MAX_CLIENTS) { | ||
| 158 | ESP_LOGW(TAG, "Max clients reached, cannot grant access"); | ||
| 159 | return; | ||
| 160 | } | ||
| 161 | |||
| 162 | fw_client_t *client = &s_clients[s_client_count]; | ||
| 163 | client->ip = client_ip; | ||
| 164 | client->mac[0] = '\0'; | ||
| 165 | firewall_get_mac_for_ip(client_ip, client->mac, sizeof(client->mac)); | ||
| 166 | s_client_count++; | ||
| 167 | |||
| 168 | dns_server_set_client_authenticated(client_ip, true); | 93 | dns_server_set_client_authenticated(client_ip, true); |
| 169 | 94 | ||
| 95 | char mac[18] = {0}; | ||
| 96 | tollgate_core_fw_get_mac_for_ip(client_ip, mac, sizeof(mac)); | ||
| 170 | esp_ip4_addr_t ip_addr = { .addr = client_ip }; | 97 | esp_ip4_addr_t ip_addr = { .addr = client_ip }; |
| 171 | ESP_LOGI(TAG, "Access granted to " IPSTR " mac=%s", IP2STR(&ip_addr), | 98 | ESP_LOGI(TAG, "Access granted to " IPSTR " mac=%s", IP2STR(&ip_addr), |
| 172 | client->mac[0] ? client->mac : "unknown"); | 99 | mac[0] ? mac : "unknown"); |
| 173 | } | 100 | } |
| 174 | 101 | ||
| 175 | void firewall_revoke_access(uint32_t client_ip) | 102 | void firewall_revoke_access(uint32_t client_ip) |
| 176 | { | 103 | { |
| 177 | for (int i = 0; i < s_client_count; i++) { | 104 | tollgate_core_fw_revoke(client_ip); |
| 178 | if (s_clients[i].ip == client_ip) { | 105 | dns_server_set_client_authenticated(client_ip, false); |
| 179 | esp_ip4_addr_t ip_addr = { .addr = client_ip }; | 106 | |
| 180 | ESP_LOGI(TAG, "Access revoked for " IPSTR " mac=%s", IP2STR(&ip_addr), | 107 | esp_ip4_addr_t ip_addr = { .addr = client_ip }; |
| 181 | s_clients[i].mac[0] ? s_clients[i].mac : "unknown"); | 108 | ESP_LOGI(TAG, "Access revoked for " IPSTR, IP2STR(&ip_addr)); |
| 182 | s_clients[i] = s_clients[s_client_count - 1]; | ||
| 183 | s_client_count--; | ||
| 184 | dns_server_set_client_authenticated(client_ip, false); | ||
| 185 | return; | ||
| 186 | } | ||
| 187 | } | ||
| 188 | } | 109 | } |
| 189 | 110 | ||
| 190 | void firewall_revoke_all(void) | 111 | void firewall_revoke_all(void) |
| 191 | { | 112 | { |
| 192 | for (int i = 0; i < s_client_count; i++) { | 113 | tollgate_core_fw_revoke_all(); |
| 193 | dns_server_set_client_authenticated(s_clients[i].ip, false); | ||
| 194 | } | ||
| 195 | s_client_count = 0; | ||
| 196 | ESP_LOGI(TAG, "All client access revoked"); | 114 | ESP_LOGI(TAG, "All client access revoked"); |
| 197 | } | 115 | } |
| 198 | 116 | ||
| 199 | bool firewall_is_client_allowed(uint32_t client_ip) | 117 | bool firewall_is_client_allowed(uint32_t client_ip) |
| 200 | { | 118 | { |
| 201 | return find_client_by_ip(client_ip) != NULL; | 119 | return tollgate_core_is_client_allowed(client_ip); |
| 202 | } | 120 | } |
| 203 | 121 | ||
| 204 | bool firewall_is_mac_allowed(const char *mac) | 122 | bool firewall_is_mac_allowed(const char *mac) |
| 205 | { | 123 | { |
| 206 | return find_client_by_mac(mac) != NULL; | 124 | return tollgate_core_fw_is_mac_allowed(mac); |
| 207 | } | 125 | } |
| 208 | 126 | ||
| 209 | int firewall_client_count(void) | 127 | int firewall_client_count(void) |
| 210 | { | 128 | { |
| 211 | return s_client_count; | 129 | return tollgate_core_allowed_client_count(); |
| 212 | } | 130 | } |