From beb73a2eeacf7dbe5e292ce6e26a95a933808267 Mon Sep 17 00:00:00 2001 From: Your Name Date: Tue, 19 May 2026 04:13:11 +0530 Subject: feat(mining): integrate mining subsystem into existing modules - CMakeLists.txt: add 6 mining sources + tcp_transport dependency - config.h/c: mining_payout_mode_t enum, mining config fields, JSON parsing - tollgate_main.c: mining init in start_services(), stratum_client_tick in main loop - tollgate_api.c: GET /mining/job, POST /mining/share, GET /mining/stats endpoints - session.h/c: payment_method_t enum (CASHU/MINING/BYTES) - firewall.h/c: sandbox allowlist for mining port + mint URLs - tollgate_client.h/c: TG_CLIENT_MINING state, mining discovery tag parsing - captive_portal.c: tabbed UI with Cashu/Mine tabs, live hashrate polling --- main/firewall.c | 47 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) (limited to 'main/firewall.c') diff --git a/main/firewall.c b/main/firewall.c index 8d535b4..ae0eda7 100644 --- a/main/firewall.c +++ b/main/firewall.c @@ -7,12 +7,16 @@ #include "lwip/etharp.h" #include "lwip/netif.h" #include "lwip/prot/ip4.h" +#include "lwip/prot/tcp.h" +#include "lwip/prot/ip.h" #include #define MAX_CLIENTS 10 static const char *TAG = "firewall"; static esp_ip4_addr_t s_ap_ip; +static uint16_t s_mining_port = 3333; +static bool s_sandbox_mint_access = false; typedef struct { uint32_t ip; @@ -66,6 +70,46 @@ esp_err_t firewall_init(esp_ip4_addr_t ap_ip) return ESP_OK; } +void firewall_set_mining_port(uint16_t port) +{ + s_mining_port = port; +} + +void firewall_set_sandbox_mint_access(bool enabled) +{ + s_sandbox_mint_access = enabled; +} + +static bool is_sandbox_allowed(struct pbuf *p) +{ + if (p->len < IP_HLEN) return false; + struct ip_hdr *iphdr = (struct ip_hdr *)p->payload; + uint32_t dest_ip_h = lwip_ntohl(iphdr->dest.addr); + uint32_t ap_ip_h = lwip_ntohl(s_ap_ip.addr); + + if (dest_ip_h == ap_ip_h) { + if (iphdr->_proto == IP_PROTO_TCP) { + uint16_t dst_port = 0; + if (p->len >= IP_HLEN + TCP_HLEN) { + struct tcp_hdr *tcphdr = (struct tcp_hdr *)((uint8_t *)p->payload + IP_HLEN); + dst_port = lwip_ntohs(tcphdr->dest); + } + if (dst_port == 80 || dst_port == 2121 || dst_port == s_mining_port) { + return true; + } + } + if (iphdr->_proto == IP_PROTO_UDP) { + return true; + } + } + + if (s_sandbox_mint_access && iphdr->_proto == IP_PROTO_TCP) { + return true; + } + + return false; +} + int tollgate_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) { (void)dest_addr_hostorder; @@ -79,6 +123,9 @@ int tollgate_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) if (firewall_is_client_allowed(iphdr->src.addr)) { return 1; } + if (is_sandbox_allowed(p)) { + return 1; + } return 0; } -- cgit v1.2.3