upleb.uk

Public git repos — served from a NIP-34 GRASP relay at git.upleb.uk

summaryrefslogtreecommitdiff
path: root/tollgate_core/src/tollgate_firewall.c
diff options
context:
space:
mode:
Diffstat (limited to 'tollgate_core/src/tollgate_firewall.c')
-rw-r--r--tollgate_core/src/tollgate_firewall.c166
1 files changed, 0 insertions, 166 deletions
diff --git a/tollgate_core/src/tollgate_firewall.c b/tollgate_core/src/tollgate_firewall.c
deleted file mode 100644
index 8111be8..0000000
--- a/tollgate_core/src/tollgate_firewall.c
+++ /dev/null
@@ -1,166 +0,0 @@
1#include "tollgate_firewall.h"
2#include "tollgate_core.h"
3#include "tollgate_platform.h"
4#include <string.h>
5#include <stdio.h>
6
7#define FW_MAX_CLIENTS 10
8
9static const char *TAG = "tg_fw";
10static uint32_t s_ap_ip;
11static uint16_t s_mining_port;
12static bool s_sandbox_mint;
13
14typedef struct {
15 uint32_t ip;
16 char mac[TG_FW_MAX_MAC_LEN];
17} fw_client_t;
18
19static fw_client_t s_clients[FW_MAX_CLIENTS];
20static int s_client_count = 0;
21
22static void log_fw(const char *verb, uint32_t client_ip, const char *mac)
23{
24 const tollgate_platform_t *p = tollgate_core_get_platform();
25 if (p && p->log_info) {
26 char ip_str[16];
27 snprintf(ip_str, sizeof(ip_str), "%d.%d.%d.%d",
28 (int)((client_ip >> 0) & 0xFF), (int)((client_ip >> 8) & 0xFF),
29 (int)((client_ip >> 16) & 0xFF), (int)((client_ip >> 24) & 0xFF));
30 p->log_info(TAG, "%s %s mac=%s", verb, ip_str, mac ? mac : "unknown");
31 }
32}
33
34int tg_firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, int mac_out_size)
35{
36 const tollgate_platform_t *p = tollgate_core_get_platform();
37 if (!p) return -1;
38
39 if (p->mac_for_ip) {
40 if (p->mac_for_ip(client_ip, mac_out, mac_out_size)) {
41 return 0;
42 }
43 }
44 return -1;
45}
46
47int tg_firewall_init(uint32_t ap_ip)
48{
49 s_ap_ip = ap_ip;
50 memset(s_clients, 0, sizeof(s_clients));
51 s_client_count = 0;
52 s_mining_port = 0;
53 s_sandbox_mint = false;
54
55 const tollgate_platform_t *p = tollgate_core_get_platform();
56 if (p && p->napt_enable) p->napt_enable(ap_ip, true);
57
58 if (p && p->log_info) {
59 char ip_str[16];
60 snprintf(ip_str, sizeof(ip_str), "%d.%d.%d.%d",
61 (int)((ap_ip >> 0) & 0xFF), (int)((ap_ip >> 8) & 0xFF),
62 (int)((ap_ip >> 16) & 0xFF), (int)((ap_ip >> 24) & 0xFF));
63 p->log_info(TAG, "Firewall initialized AP=%s NAT on, per-client filter", ip_str);
64 }
65 return 0;
66}
67
68static fw_client_t *find_client_by_ip(uint32_t client_ip)
69{
70 for (int i = 0; i < s_client_count; i++) {
71 if (s_clients[i].ip == client_ip) return &s_clients[i];
72 }
73 return NULL;
74}
75
76static fw_client_t *find_client_by_mac(const char *mac)
77{
78 for (int i = 0; i < s_client_count; i++) {
79 if (s_clients[i].mac[0] != '\0' && strcmp(s_clients[i].mac, mac) == 0) {
80 return &s_clients[i];
81 }
82 }
83 return NULL;
84}
85
86void tg_firewall_grant(uint32_t client_ip)
87{
88 fw_client_t *existing = find_client_by_ip(client_ip);
89 if (existing) return;
90
91 if (s_client_count >= FW_MAX_CLIENTS) {
92 const tollgate_platform_t *p = tollgate_core_get_platform();
93 if (p && p->log_warn) p->log_warn(TAG, "Max clients, cannot grant");
94 return;
95 }
96
97 fw_client_t *c = &s_clients[s_client_count];
98 c->ip = client_ip;
99 c->mac[0] = '\0';
100 tg_firewall_get_mac_for_ip(client_ip, c->mac, sizeof(c->mac));
101 s_client_count++;
102
103 log_fw("granted", client_ip, c->mac[0] ? c->mac : "unknown");
104}
105
106void tg_firewall_revoke(uint32_t client_ip)
107{
108 for (int i = 0; i < s_client_count; i++) {
109 if (s_clients[i].ip == client_ip) {
110 log_fw("revoked", client_ip, s_clients[i].mac[0] ? s_clients[i].mac : "unknown");
111 s_clients[i] = s_clients[s_client_count - 1];
112 s_client_count--;
113 return;
114 }
115 }
116}
117
118int tg_firewall_revoke_all(void)
119{
120 s_client_count = 0;
121 memset(s_clients, 0, sizeof(s_clients));
122 const tollgate_platform_t *p = tollgate_core_get_platform();
123 if (p && p->log_info) p->log_info(TAG, "All clients revoked");
124 return 0;
125}
126
127bool tg_firewall_is_allowed(uint32_t client_ip)
128{
129 return find_client_by_ip(client_ip) != NULL;
130}
131
132bool tg_firewall_is_mac_allowed(const char *mac)
133{
134 return find_client_by_mac(mac) != NULL;
135}
136
137int tg_firewall_client_count(void)
138{
139 return s_client_count;
140}
141
142void tg_firewall_set_mining_port(uint16_t port)
143{
144 s_mining_port = port;
145}
146
147void tg_firewall_set_sandbox_mint_access(bool enable)
148{
149 s_sandbox_mint = enable;
150}
151
152int tg_firewall_filter_packet(const uint8_t *payload, int payload_len)
153{
154 if (payload_len < 20) return -1;
155
156 uint32_t src_ip = (uint32_t)payload[12] | ((uint32_t)payload[13] << 8) |
157 ((uint32_t)payload[14] << 16) | ((uint32_t)payload[15] << 24);
158
159 uint32_t ap_subnet = s_ap_ip & 0x00FFFFFF;
160 uint32_t src_subnet = src_ip & 0x00FFFFFF;
161 if (src_subnet != ap_subnet) return 1;
162
163 if (tg_firewall_is_allowed(src_ip)) return 1;
164
165 return 0;
166}