From 9330b01c28aebc865a3c0a51df8730196cb4152e Mon Sep 17 00:00:00 2001 From: Your Name Date: Sat, 23 May 2026 04:50:26 +0530 Subject: Phase 6a-6d: Consolidate and clean up 6a: Delete dead standalone tollgate_core/ (12 files, never compiled) 6b: Rewrite dns_server.c as thin shim to component's tollgate_core_dns - Fix component DNS to bind to AP IP instead of INADDR_ANY 6c: Rewrite stratum_proxy.c as thin shim with struct cast to component types 6d: Move sandbox logic into component's tollgate_core_firewall - Add tollgate_core_fw_set_sandbox_ports/set_sandbox_mint_access - Add is_sandbox_allowed() to component's ip4_canforward_filter - Clean main/firewall.c to delegate filter to component - Remove redundant DNS auth double-calls from main firewall Add ROADMAP.md with full extraction plan and checklists All 21 unit tests pass. ESP-IDF build passes. --- main/dns_server.c | 304 +-------------------------------------------------- main/firewall.c | 72 +----------- main/stratum_proxy.c | 145 ++---------------------- 3 files changed, 17 insertions(+), 504 deletions(-) (limited to 'main') diff --git a/main/dns_server.c b/main/dns_server.c index b84a4cf..5b1bdc3 100644 --- a/main/dns_server.c +++ b/main/dns_server.c @@ -1,316 +1,22 @@ #include "dns_server.h" -#include "esp_log.h" -#include "freertos/FreeRTOS.h" -#include "freertos/task.h" -#include "lwip/sockets.h" -#include "lwip/netdb.h" -#include -#include - -#define MAX_AUTH_IPS 10 -#define MAX_PENDING 50 -#define DNS_BUF_SIZE 512 -#define DNS_PORT 53 -#define DOT_PORT 853 -#define DNS_TASK_STACK 4096 -#define DOT_TASK_STACK 3072 -#define DNS_TASK_PRIO 5 -#define DOT_TASK_PRIO 5 -#define DNS_FORWARD_TIMEOUT_MS 2000 -#define NXDOMAIN_TTL 30 -#define HIJACK_TTL 10 - -static const char *TAG = "dns_server"; - -#pragma pack(push, 1) -typedef struct { - uint16_t id; - uint16_t flags; - uint16_t qdcount; - uint16_t ancount; - uint16_t nscount; - uint16_t arcount; -} dns_header_t; -#pragma pack(pop) - -#pragma pack(push, 1) -typedef struct { - uint16_t name; - uint16_t type; - uint16_t class; - uint32_t ttl; - uint16_t len; - uint32_t addr; -} dns_answer_t; -#pragma pack(pop) - -typedef struct { - uint32_t ip; -} auth_entry_t; - -static auth_entry_t s_auth_list[MAX_AUTH_IPS]; -static int s_auth_count = 0; -static TaskHandle_t s_dns_task = NULL; -static TaskHandle_t s_dot_task = NULL; -static volatile bool s_dns_running = false; -static esp_ip4_addr_t s_ap_ip; -static esp_ip4_addr_t s_upstream_dns; - -static bool is_authenticated(uint32_t ip) -{ - for (int i = 0; i < s_auth_count; i++) { - if (s_auth_list[i].ip == ip) return true; - } - return false; -} - -static void parse_dns_name(const uint8_t *buf, int buf_len, int offset, char *out, int out_len) -{ - int pos = offset; - int out_pos = 0; - int jumped = 0; - int jump_pos = 0; - while (pos < buf_len && out_pos < out_len - 1) { - uint8_t len = buf[pos]; - if (len == 0) break; - if ((len & 0xC0) == 0xC0) { - if (!jumped) jump_pos = pos + 2; - pos = ((len & 0x3F) << 8) | buf[pos + 1]; - jumped = 1; - continue; - } - if (out_pos > 0 && out_pos < out_len - 1) out[out_pos++] = '.'; - pos++; - for (int i = 0; i < len && pos < buf_len && out_pos < out_len - 1; i++) { - out[out_pos++] = buf[pos++]; - } - } - out[out_pos] = '\0'; -} - -static int build_nxdomain(uint8_t *response, int req_len) -{ - dns_header_t *hdr = (dns_header_t *)response; - hdr->flags = htons(0x8403); - hdr->ancount = 0; - hdr->nscount = 0; - hdr->arcount = 0; - return req_len; -} - -static int build_redirect_response(uint8_t *response, int req_len) -{ - memmove(response, response, req_len); - dns_header_t *hdr = (dns_header_t *)response; - hdr->flags = htons(0x8180); - hdr->ancount = htons(1); - hdr->nscount = 0; - hdr->arcount = 0; - int resp_len = req_len; - dns_answer_t ans; - ans.name = htons(0xC00C); - ans.type = htons(1); - ans.class = htons(1); - ans.ttl = htonl(HIJACK_TTL); - ans.len = htons(4); - ans.addr = s_ap_ip.addr; - memcpy(response + resp_len, &ans, sizeof(ans)); - resp_len += sizeof(ans); - return resp_len; -} - -static int forward_dns(const uint8_t *req, int req_len, uint8_t *resp, int resp_buf_len, - const struct sockaddr_in *client_addr, uint16_t txn_id) -{ - int upstream_sock = socket(AF_INET, SOCK_DGRAM, 0); - if (upstream_sock < 0) return -1; - - struct timeval tv = { .tv_sec = DNS_FORWARD_TIMEOUT_MS / 1000, .tv_usec = (DNS_FORWARD_TIMEOUT_MS % 1000) * 1000 }; - setsockopt(upstream_sock, SOL_SOCKET, SO_RCVTIMEO, &tv, sizeof(tv)); - - struct sockaddr_in upstream_addr = { - .sin_family = AF_INET, - .sin_port = htons(DNS_PORT), - .sin_addr.s_addr = s_upstream_dns.addr, - }; - - sendto(upstream_sock, req, req_len, 0, (struct sockaddr *)&upstream_addr, sizeof(upstream_addr)); - - int n = recvfrom(upstream_sock, resp, resp_buf_len, 0, NULL, NULL); - close(upstream_sock); - - if (n > 0) { - if (n >= sizeof(dns_header_t)) { - dns_header_t *hdr = (dns_header_t *)resp; - hdr->id = htons(txn_id); - } - } - return n; -} - -static void dns_server_task(void *arg) -{ - int sock = socket(AF_INET, SOCK_DGRAM, 0); - if (sock < 0) { - ESP_LOGE(TAG, "Failed to create DNS socket"); - s_dns_running = false; - vTaskDelete(NULL); - return; - } - - struct sockaddr_in bind_addr = { - .sin_family = AF_INET, - .sin_port = htons(DNS_PORT), - .sin_addr.s_addr = s_ap_ip.addr, - }; - if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { - ESP_LOGE(TAG, "Failed to bind DNS socket"); - close(sock); - s_dns_running = false; - vTaskDelete(NULL); - return; - } - - ESP_LOGI(TAG, "DNS server started on port %d, AP IP=" IPSTR ", upstream DNS=" IPSTR, - DNS_PORT, IP2STR(&s_ap_ip), IP2STR(&s_upstream_dns)); - - uint8_t rx_buf[DNS_BUF_SIZE]; - uint8_t tx_buf[DNS_BUF_SIZE + sizeof(dns_answer_t)]; - - while (s_dns_running) { - struct sockaddr_in client_addr; - socklen_t client_len = sizeof(client_addr); - int n = recvfrom(sock, rx_buf, sizeof(rx_buf), 0, - (struct sockaddr *)&client_addr, &client_len); - if (n < (int)sizeof(dns_header_t)) continue; - - uint32_t client_ip = client_addr.sin_addr.s_addr; - dns_header_t *hdr = (dns_header_t *)rx_buf; - uint16_t txn_id = ntohs(hdr->id); - bool is_query = (ntohs(hdr->flags) & 0x8000) == 0; - uint16_t qdcount = ntohs(hdr->qdcount); - - if (!is_query || qdcount == 0) continue; - - int q_offset = sizeof(dns_header_t); - while (q_offset < n && rx_buf[q_offset] != 0) { - q_offset += rx_buf[q_offset] + 1; - } - if (q_offset + 5 > n) continue; - uint16_t qtype = (rx_buf[q_offset + 1] << 8) | rx_buf[q_offset + 2]; - int req_len = q_offset + 5; - - if (is_authenticated(client_ip)) { - int resp_len = forward_dns(rx_buf, req_len, tx_buf, sizeof(tx_buf), &client_addr, txn_id); - if (resp_len > 0) { - sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len); - } - } else { - char qname[256] = {0}; - parse_dns_name(rx_buf, n, sizeof(dns_header_t), qname, sizeof(qname)); - ESP_LOGI(TAG, "Hijack DNS from " IPSTR ": %s (type=%d)", IP2STR(&(esp_ip4_addr_t){.addr=client_ip}), qname, qtype); - if (qtype == 1) { - int resp_len = build_redirect_response(rx_buf, req_len); - memcpy(tx_buf, rx_buf, resp_len); - dns_header_t *resp_hdr = (dns_header_t *)tx_buf; - resp_hdr->id = htons(txn_id); - sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len); - } else { - int resp_len = build_nxdomain(rx_buf, req_len); - memcpy(tx_buf, rx_buf, resp_len); - dns_header_t *resp_hdr = (dns_header_t *)tx_buf; - resp_hdr->id = htons(txn_id); - sendto(sock, tx_buf, resp_len, 0, (struct sockaddr *)&client_addr, client_len); - } - } - } - - close(sock); - ESP_LOGI(TAG, "DNS server stopped"); - vTaskDelete(NULL); -} - -static void dot_reject_task(void *arg) -{ - int sock = socket(AF_INET, SOCK_STREAM, 0); - if (sock < 0) { - ESP_LOGE(TAG, "Failed to create DoT reject socket"); - vTaskDelete(NULL); - return; - } - - int opt = 1; - setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &opt, sizeof(opt)); - - struct sockaddr_in bind_addr = { - .sin_family = AF_INET, - .sin_port = htons(DOT_PORT), - .sin_addr.s_addr = INADDR_ANY, - }; - if (bind(sock, (struct sockaddr *)&bind_addr, sizeof(bind_addr)) < 0) { - ESP_LOGE(TAG, "Failed to bind DoT reject socket on port %d", DOT_PORT); - close(sock); - vTaskDelete(NULL); - return; - } - - listen(sock, 1); - ESP_LOGI(TAG, "DoT reject server on port %d (forces DNS fallback to port 53)", DOT_PORT); - - while (s_dns_running) { - struct sockaddr_in client_addr; - socklen_t client_len = sizeof(client_addr); - int client_sock = accept(sock, (struct sockaddr *)&client_addr, &client_len); - if (client_sock >= 0) { - struct linger ling = { .l_onoff = 1, .l_linger = 0 }; - setsockopt(client_sock, SOL_SOCKET, SO_LINGER, &ling, sizeof(ling)); - close(client_sock); - } - } - - close(sock); - ESP_LOGI(TAG, "DoT reject server stopped"); - vTaskDelete(NULL); -} +#include "tollgate_core_dns.h" esp_err_t dns_server_start(esp_ip4_addr_t ap_ip, esp_ip4_addr_t upstream_dns) { - if (s_dns_running) return ESP_OK; - s_ap_ip = ap_ip; - s_upstream_dns = upstream_dns; - s_dns_running = true; - xTaskCreate(dns_server_task, "dns_server", DNS_TASK_STACK, NULL, DNS_TASK_PRIO, &s_dns_task); - xTaskCreate(dot_reject_task, "dot_reject", DOT_TASK_STACK, NULL, DOT_TASK_PRIO, &s_dot_task); - return ESP_OK; + return tollgate_core_dns_start_internal(ap_ip, upstream_dns); } void dns_server_stop(void) { - s_dns_running = false; - vTaskDelay(pdMS_TO_TICKS(200)); - s_dns_task = NULL; + tollgate_core_dns_stop(); } void dns_server_set_client_authenticated(uint32_t client_ip, bool authenticated) { - if (authenticated) { - if (is_authenticated(client_ip)) return; - if (s_auth_count < MAX_AUTH_IPS) { - s_auth_list[s_auth_count].ip = client_ip; - s_auth_count++; - } - } else { - for (int i = 0; i < s_auth_count; i++) { - if (s_auth_list[i].ip == client_ip) { - s_auth_list[i] = s_auth_list[s_auth_count - 1]; - s_auth_count--; - return; - } - } - } + tollgate_core_dns_set_authenticated(client_ip, authenticated); } bool dns_server_is_running(void) { - return s_dns_running; + return tollgate_core_dns_is_running(); } diff --git a/main/firewall.c b/main/firewall.c index 077d16c..5ffdee0 100644 --- a/main/firewall.c +++ b/main/firewall.c @@ -1,36 +1,28 @@ #include "firewall.h" -#include "dns_server.h" #include "tollgate_core.h" #include "tollgate_core_firewall.h" #include "esp_log.h" -#include "lwip/netif.h" -#include "lwip/lwip_napt.h" #include "lwip/prot/ip4.h" -#include "lwip/prot/tcp.h" -#include "lwip/prot/ip.h" #include static const char *TAG = "firewall"; static esp_ip4_addr_t s_ap_ip; -static uint16_t s_mining_port = 3333; -static bool s_sandbox_mint_access = false; esp_err_t firewall_init(esp_ip4_addr_t ap_ip) { s_ap_ip = ap_ip; - ip_napt_enable(s_ap_ip.addr, 1); - ESP_LOGI(TAG, "Firewall initialized with AP IP=" IPSTR " (NAT always on, per-client filter)", IP2STR(&s_ap_ip)); + ESP_LOGI(TAG, "Firewall initialized with AP IP=" IPSTR, IP2STR(&s_ap_ip)); return ESP_OK; } void firewall_set_mining_port(uint16_t port) { - s_mining_port = port; + tollgate_core_fw_set_sandbox_ports(port); } void firewall_set_sandbox_mint_access(bool enabled) { - s_sandbox_mint_access = enabled; + tollgate_core_fw_set_sandbox_mint_access(enabled); } esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_out_size) @@ -38,80 +30,24 @@ esp_err_t firewall_get_mac_for_ip(uint32_t client_ip, char *mac_out, size_t mac_ return tollgate_core_fw_get_mac_for_ip(client_ip, mac_out, mac_out_size); } -static bool is_sandbox_allowed(struct pbuf *p) -{ - if (p->len < IP_HLEN) return false; - struct ip_hdr *iphdr = (struct ip_hdr *)p->payload; - uint32_t dest_ip_h = lwip_ntohl(iphdr->dest.addr); - uint32_t ap_ip_h = lwip_ntohl(s_ap_ip.addr); - - if (dest_ip_h == ap_ip_h) { - if (iphdr->_proto == IP_PROTO_TCP) { - uint16_t dst_port = 0; - if (p->len >= IP_HLEN + TCP_HLEN) { - struct tcp_hdr *tcphdr = (struct tcp_hdr *)((uint8_t *)p->payload + IP_HLEN); - dst_port = lwip_ntohs(tcphdr->dest); - } - if (dst_port == 80 || dst_port == 2121 || dst_port == s_mining_port) { - return true; - } - } - if (iphdr->_proto == IP_PROTO_UDP) { - return true; - } - } - - if (s_sandbox_mint_access && iphdr->_proto == IP_PROTO_TCP) { - return true; - } - - return false; -} - int tollgate_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder) { - (void)dest_addr_hostorder; - if (p->len < IP_HLEN) return -1; - struct ip_hdr *iphdr = (struct ip_hdr *)p->payload; - uint32_t src_ip_h = lwip_ntohl(iphdr->src.addr); - uint32_t ap_subnet = lwip_ntohl(s_ap_ip.addr) & 0xFFFFFF00; - if ((src_ip_h & 0xFFFFFF00) != ap_subnet) { - return 1; - } - if (firewall_is_client_allowed(iphdr->src.addr)) { - return 1; - } - if (is_sandbox_allowed(p)) { - return 1; - } - return 0; + return tollgate_core_ip4_canforward_filter(p, dest_addr_hostorder); } void firewall_grant_access(uint32_t client_ip) { tollgate_core_fw_grant(client_ip); - dns_server_set_client_authenticated(client_ip, true); - - char mac[18] = {0}; - tollgate_core_fw_get_mac_for_ip(client_ip, mac, sizeof(mac)); - esp_ip4_addr_t ip_addr = { .addr = client_ip }; - ESP_LOGI(TAG, "Access granted to " IPSTR " mac=%s", IP2STR(&ip_addr), - mac[0] ? mac : "unknown"); } void firewall_revoke_access(uint32_t client_ip) { tollgate_core_fw_revoke(client_ip); - dns_server_set_client_authenticated(client_ip, false); - - esp_ip4_addr_t ip_addr = { .addr = client_ip }; - ESP_LOGI(TAG, "Access revoked for " IPSTR, IP2STR(&ip_addr)); } void firewall_revoke_all(void) { tollgate_core_fw_revoke_all(); - ESP_LOGI(TAG, "All client access revoked"); } bool firewall_is_client_allowed(uint32_t client_ip) diff --git a/main/stratum_proxy.c b/main/stratum_proxy.c index 288c633..53909f0 100644 --- a/main/stratum_proxy.c +++ b/main/stratum_proxy.c @@ -1,160 +1,31 @@ #include "stratum_proxy.h" -#include "mining_payment.h" -#include "esp_log.h" -#include "lwip/sockets.h" -#include "freertos/FreeRTOS.h" -#include "freertos/task.h" +#include "tollgate_core_stratum_proxy.h" #include -static const char *TAG = "stratum_proxy"; -static uint16_t s_port = 3333; -static bool s_running = false; -static TaskHandle_t s_task_handle = NULL; -static int s_server_fd = -1; - -static stratum_job_t s_current_job = {0}; -static stratum_proxy_stats_t s_stats = {0}; - -static void proxy_client_handler(void *arg) -{ - int client_fd = (int)(intptr_t)arg; - struct sockaddr_in client_addr; - socklen_t addr_len = sizeof(client_addr); - getpeername(client_fd, (struct sockaddr *)&client_addr, &addr_len); - uint32_t client_ip = client_addr.sin_addr.s_addr; - - ESP_LOGI(TAG, "Miner connected from 0x%08lx", (unsigned long)client_ip); - - if (s_current_job.valid) { - char job_json[512]; - snprintf(job_json, sizeof(job_json), - "{\"id\":1,\"method\":\"mining.notify\",\"params\":[\"%lu\",\"%08lx%08lx%08lx%08lx%08lx%08lx%08lx%08lx\",\"\",\"\",\"\",\"%08lx\",\"%08lx\",\"%08lx\",true]}\n", - (unsigned long)s_current_job.job_id, - (unsigned long)0, (unsigned long)0, (unsigned long)0, (unsigned long)0, - (unsigned long)0, (unsigned long)0, (unsigned long)0, (unsigned long)0, - (unsigned long)s_current_job.nbits, (unsigned long)s_current_job.ntime, - (unsigned long)s_current_job.version); - send(client_fd, job_json, strlen(job_json), 0); - } - - char buf[1024]; - while (s_running) { - int len = recv(client_fd, buf, sizeof(buf) - 1, 0); - if (len <= 0) break; - buf[len] = '\0'; - - ESP_LOGI(TAG, "Received from miner: %s", buf); - s_stats.total_shares++; - s_stats.total_accepted++; - } - - ESP_LOGI(TAG, "Miner disconnected from 0x%08lx", (unsigned long)client_ip); - close(client_fd); - vTaskDelete(NULL); -} - -static void proxy_server_task(void *arg) -{ - struct sockaddr_in server_addr; - memset(&server_addr, 0, sizeof(server_addr)); - server_addr.sin_family = AF_INET; - server_addr.sin_addr.s_addr = INADDR_ANY; - server_addr.sin_port = htons(s_port); - - s_server_fd = socket(AF_INET, SOCK_STREAM, 0); - if (s_server_fd < 0) { - ESP_LOGE(TAG, "Failed to create socket"); - vTaskDelete(NULL); - return; - } - - int opt = 1; - setsockopt(s_server_fd, SOL_SOCKET, SO_REUSEADDR, &opt, sizeof(opt)); - - if (bind(s_server_fd, (struct sockaddr *)&server_addr, sizeof(server_addr)) != 0) { - ESP_LOGE(TAG, "Failed to bind to port %u", (unsigned)s_port); - close(s_server_fd); - s_server_fd = -1; - vTaskDelete(NULL); - return; - } - - if (listen(s_server_fd, 5) != 0) { - ESP_LOGE(TAG, "Failed to listen"); - close(s_server_fd); - s_server_fd = -1; - vTaskDelete(NULL); - return; - } - - ESP_LOGI(TAG, "Stratum proxy listening on port %u", (unsigned)s_port); - - while (s_running) { - struct sockaddr_in client_addr; - socklen_t client_len = sizeof(client_addr); - int client_fd = accept(s_server_fd, (struct sockaddr *)&client_addr, &client_len); - if (client_fd < 0) continue; - - s_stats.active_miners++; - char task_name[20]; - snprintf(task_name, sizeof(task_name), "miner_%d", client_fd); - xTaskCreate(proxy_client_handler, task_name, 4096, (void *)(intptr_t)client_fd, 3, NULL); - } - - close(s_server_fd); - s_server_fd = -1; - vTaskDelete(NULL); -} +_Static_assert(sizeof(stratum_job_t) == sizeof(tollgate_stratum_job_t), "job struct size mismatch"); +_Static_assert(sizeof(stratum_proxy_stats_t) == sizeof(tollgate_stratum_proxy_stats_t), "stats struct size mismatch"); esp_err_t stratum_proxy_init(uint16_t port) { - s_port = port; - memset(&s_current_job, 0, sizeof(s_current_job)); - memset(&s_stats, 0, sizeof(s_stats)); - s_running = true; - - BaseType_t ret = xTaskCreate(proxy_server_task, "stratum_proxy", 4096, NULL, 4, &s_task_handle); - if (ret != pdPASS) { - ESP_LOGE(TAG, "Failed to create proxy task"); - s_running = false; - return ESP_FAIL; - } - - ESP_LOGI(TAG, "Stratum proxy initialized on port %u", (unsigned)port); - return ESP_OK; + return tollgate_core_stratum_proxy_init(port); } void stratum_proxy_set_job(const stratum_job_t *job) { - if (job) { - memcpy(&s_current_job, job, sizeof(stratum_job_t)); - s_stats.nbits = job->nbits; - s_stats.current_hashprice = mining_get_current_hashprice(); - } + tollgate_core_stratum_proxy_set_job((const tollgate_stratum_job_t *)job); } const stratum_job_t *stratum_proxy_get_current_job(void) { - return &s_current_job; + return (const stratum_job_t *)tollgate_core_stratum_proxy_get_current_job(); } void stratum_proxy_get_stats(stratum_proxy_stats_t *stats) { - if (stats) { - *stats = s_stats; - stats->current_hashprice = mining_get_current_hashprice(); - } + tollgate_core_stratum_proxy_get_stats((tollgate_stratum_proxy_stats_t *)stats); } void stratum_proxy_stop(void) { - s_running = false; - if (s_server_fd >= 0) { - close(s_server_fd); - s_server_fd = -1; - } - if (s_task_handle) { - vTaskDelay(pdMS_TO_TICKS(500)); - s_task_handle = NULL; - } + tollgate_core_stratum_proxy_stop(); } -- cgit v1.2.3