From 9330b01c28aebc865a3c0a51df8730196cb4152e Mon Sep 17 00:00:00 2001 From: Your Name Date: Sat, 23 May 2026 04:50:26 +0530 Subject: Phase 6a-6d: Consolidate and clean up 6a: Delete dead standalone tollgate_core/ (12 files, never compiled) 6b: Rewrite dns_server.c as thin shim to component's tollgate_core_dns - Fix component DNS to bind to AP IP instead of INADDR_ANY 6c: Rewrite stratum_proxy.c as thin shim with struct cast to component types 6d: Move sandbox logic into component's tollgate_core_firewall - Add tollgate_core_fw_set_sandbox_ports/set_sandbox_mint_access - Add is_sandbox_allowed() to component's ip4_canforward_filter - Clean main/firewall.c to delegate filter to component - Remove redundant DNS auth double-calls from main firewall Add ROADMAP.md with full extraction plan and checklists All 21 unit tests pass. ESP-IDF build passes. --- components/tollgate_core/src/tollgate_core_dns.c | 2 +- .../tollgate_core/src/tollgate_core_firewall.c | 47 ++++++++++++++++++++++ .../tollgate_core/src/tollgate_core_firewall.h | 2 + 3 files changed, 50 insertions(+), 1 deletion(-) (limited to 'components/tollgate_core/src') diff --git a/components/tollgate_core/src/tollgate_core_dns.c b/components/tollgate_core/src/tollgate_core_dns.c index 84322e6..c44dd31 100644 --- a/components/tollgate_core/src/tollgate_core_dns.c +++ b/components/tollgate_core/src/tollgate_core_dns.c @@ -160,7 +160,7 @@ static void dns_server_task(void *arg) struct sockaddr_in bind_addr = { .sin_family = AF_INET, .sin_port = htons(DNS_PORT), - .sin_addr.s_addr = INADDR_ANY, + .sin_addr.s_addr = s_ap_ip.addr, }; if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { ESP_LOGE(TAG, "Failed to bind DNS socket"); diff --git a/components/tollgate_core/src/tollgate_core_firewall.c b/components/tollgate_core/src/tollgate_core_firewall.c index ad0697e..4f12923 100644 --- a/components/tollgate_core/src/tollgate_core_firewall.c +++ b/components/tollgate_core/src/tollgate_core_firewall.c @@ -9,12 +9,16 @@ #include "lwip/etharp.h" #include "lwip/netif.h" #include "lwip/prot/ip4.h" +#include "lwip/prot/tcp.h" +#include "lwip/prot/ip.h" #include #define MAX_CLIENTS 10 static const char *TAG = "tg_core_fw"; static esp_ip4_addr_t s_ap_ip; +static uint16_t s_mining_port = 3333; +static bool s_sandbox_mint_access = false; typedef struct { uint32_t ip; @@ -70,6 +74,46 @@ esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip) return ESP_OK; } +void tollgate_core_fw_set_sandbox_ports(uint16_t mining_port) +{ + s_mining_port = mining_port; +} + +void tollgate_core_fw_set_sandbox_mint_access(bool enabled) +{ + s_sandbox_mint_access = enabled; +} + +static bool is_sandbox_allowed(struct pbuf *p) +{ + if (p->len < IP_HLEN) return false; + struct ip_hdr *iphdr = (struct ip_hdr *)p->payload; + uint32_t dest_ip_h = lwip_ntohl(iphdr->dest.addr); + uint32_t ap_ip_h = lwip_ntohl(s_ap_ip.addr); + + if (dest_ip_h == ap_ip_h) { + if (iphdr->_proto == IP_PROTO_TCP) { + uint16_t dst_port = 0; + if (p->len >= IP_HLEN + TCP_HLEN) { + struct tcp_hdr *tcphdr = (struct tcp_hdr *)((uint8_t *)p->payload + IP_HLEN); + dst_port = lwip_ntohs(tcphdr->dest); + } + if (dst_port == 80 || dst_port == 2121 || dst_port == s_mining_port) { + return true; + } + } + if (iphdr->_proto == IP_PROTO_UDP) { + return true; + } + } + + if (s_sandbox_mint_access && iphdr->_proto == IP_PROTO_TCP) { + return true; + } + + return false; +} + int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) { (void)dest_addr_hostorder; @@ -83,6 +127,9 @@ int tollgate_core_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorde if (tollgate_core_fw_is_allowed(iphdr->src.addr)) { return 1; } + if (is_sandbox_allowed(p)) { + return 1; + } return 0; } diff --git a/components/tollgate_core/src/tollgate_core_firewall.h b/components/tollgate_core/src/tollgate_core_firewall.h index f06c801..7f24372 100644 --- a/components/tollgate_core/src/tollgate_core_firewall.h +++ b/components/tollgate_core/src/tollgate_core_firewall.h @@ -11,6 +11,8 @@ struct pbuf; #define TG_FW_MAX_MAC_LEN 18 esp_err_t tollgate_core_fw_init(esp_ip4_addr_t ap_ip); +void tollgate_core_fw_set_sandbox_ports(uint16_t mining_port); +void tollgate_core_fw_set_sandbox_mint_access(bool enabled); void tollgate_core_fw_grant(uint32_t client_ip); void tollgate_core_fw_revoke(uint32_t client_ip); void tollgate_core_fw_revoke_all(void); -- cgit v1.2.3