| Age | Commit message (Collapse) | Author |
|
Root cause: mbedtls SSL buffers (16KB) couldn't allocate from fragmented
internal RAM (largest block 8KB). Fix by lowering SPIRAM_MALLOC_ALWAYSINTERNAL
from 16KB to 4KB, allowing SSL buffers to go to PSRAM.
Additional fixes:
- DNS server binds to AP IP only (prevents self-hijacking)
- start_services() moved from esp_timer (2KB stack) to dedicated FreeRTOS
task (16KB stack) — was causing stack overflow with dynamic buffers
- Mint health probe now logs errors and exposes last_err in API
- Debug endpoint shows internal/PSRAM heap breakdown and DNS resolve test
- Enabled CONFIG_MBEDTLS_DYNAMIC_BUFFER for better memory management
- Board C config: mint_url → testnut-nutshell.mints.orangesync.tech
|
|
- Add DoT reject server on port 853 (TCP RST forces DNS-over-TLS fallback)
- DNS hijack returns NXDOMAIN for all non-A query types (no forwarding for unauthed)
- Shorter TTL on hijack responses (10s) for faster captive detection
- Explicit 302 redirect handlers for /generate_204, /hotspot-detect.html, etc.
- HTTP and DNS request logging for debugging captive detection
- Per-MAC tracking in firewall (find_by_mac, get_mac_for_ip with ARP fallback)
- Session MAC tracking (session_find_by_mac)
- Phase 2 test 18: add route through TollGate before ping test
- All 17 Phase 2 tests pass (15-21 + whoami + portal form)
|
|
- Fix WiFi init order: netif creation before esp_wifi_init, set mode before set_config
- Replace broken netif input filter with NAPT on/off per authentication state
- NAPT disabled by default, enabled when client granted, disabled on revoke
- Fix test helpers: use -I wlp59s0 for ping, handle nslookup exit code 1
- All 20 API tests pass, all 6 smoke tests pass
|
|
|