From fdf662f8f1a1a3b38fe4d251982fffab8e9bf664 Mon Sep 17 00:00:00 2001 From: Your Name Date: Sun, 17 May 2026 05:27:06 +0530 Subject: Phase 7: MCP handler (25 tests), NIP-04 encrypt/decrypt (15 tests), CVM server skeleton - mcp_handler.c/h: 4 tools (get_config, set_config, get_balance, wallet_send) - nip04.c/h: AES-256-CBC + ECDH with 0x02 compressed pubkey prefix - Fixed IV copy bug: mbedTLS AES-CBC modifies IV in-place - Base64 encode/decode for ciphertext transport - PKCS7 padding - cvm_server.c/h: Nostr DM listener with FreeRTOS task - config: cvm_enabled, cvm_relays fields - 156 total tests passing across 10 test binaries --- tests/unit/Makefile | 9 ++- tests/unit/stubs/esp_log.h | 1 + tests/unit/stubs/esp_system.h | 10 +++ tests/unit/test_mcp_handler.c | 148 ++++++++++++++++++++++++++++++++++++++++++ tests/unit/test_nip04.c | 107 ++++++++++++++++++++++++++++++ 5 files changed, 274 insertions(+), 1 deletion(-) create mode 100644 tests/unit/test_mcp_handler.c create mode 100644 tests/unit/test_nip04.c (limited to 'tests/unit') diff --git a/tests/unit/Makefile b/tests/unit/Makefile index 53bcc2c..5dee0d7 100644 --- a/tests/unit/Makefile +++ b/tests/unit/Makefile @@ -10,6 +10,7 @@ CFLAGS := -Wall -Wextra -Wno-unused-parameter -Wno-unused-function -Wno-sign-com -std=gnu17 -g -O0 \ -DTEST_HOST \ -DENABLE_MODULE_SCHNORRSIG=1 -DENABLE_MODULE_EXTRAKEYS=1 \ + -DENABLE_MODULE_ECDH=1 \ -DECMULT_WINDOW_SIZE=8 -DECMULT_GEN_PREC_BITS=4 \ -include stubs/esp_err.h \ -I stubs \ @@ -21,7 +22,7 @@ LDFLAGS := -lmbedcrypto -lcjson -lm SECP256K1_OBJ := secp256k1.o precomputed_ecmult.o precomputed_ecmult_gen.o -TESTS := test_geohash test_identity test_nostr_event test_cashu test_session test_tollgate_client test_lnurl_pay test_lightning_payout +TESTS := test_geohash test_identity test_nostr_event test_cashu test_session test_tollgate_client test_lnurl_pay test_lightning_payout test_mcp_handler test_nip04 .PHONY: all test clean $(TESTS) @@ -71,5 +72,11 @@ test_lnurl_pay: test_lnurl_pay.c test_lightning_payout: test_lightning_payout.c $(CC) $(CFLAGS) $< -o $@ $(LDFLAGS) +test_mcp_handler: test_mcp_handler.c $(REPO_ROOT)/main/mcp_handler.c + $(CC) $(CFLAGS) -I $(REPO_ROOT)/main $< $(REPO_ROOT)/main/mcp_handler.c -o $@ $(LDFLAGS) + +test_nip04: test_nip04.c $(REPO_ROOT)/main/nip04.c $(SECP256K1_OBJ) + $(CC) $(CFLAGS) -I $(SECP256K1_PRIV_INC) $< $(REPO_ROOT)/main/nip04.c $(SECP256K1_OBJ) -o $@ $(LDFLAGS) + clean: rm -f $(TESTS) $(SECP256K1_OBJ) diff --git a/tests/unit/stubs/esp_log.h b/tests/unit/stubs/esp_log.h index f353fe9..b9d44b3 100644 --- a/tests/unit/stubs/esp_log.h +++ b/tests/unit/stubs/esp_log.h @@ -6,5 +6,6 @@ #define ESP_LOGI(tag, fmt, ...) do { printf("I %s: " fmt "\n", tag, ##__VA_ARGS__); } while(0) #define ESP_LOGW(tag, fmt, ...) do { printf("W %s: " fmt "\n", tag, ##__VA_ARGS__); } while(0) #define ESP_LOGE(tag, fmt, ...) do { fprintf(stderr, "E %s: " fmt "\n", tag, ##__VA_ARGS__); } while(0) +#define ESP_LOGD(tag, fmt, ...) do { } while(0) #endif diff --git a/tests/unit/stubs/esp_system.h b/tests/unit/stubs/esp_system.h index 8e63c80..cd54743 100644 --- a/tests/unit/stubs/esp_system.h +++ b/tests/unit/stubs/esp_system.h @@ -1,4 +1,14 @@ #ifndef STUBS_ESP_SYSTEM_H #define STUBS_ESP_SYSTEM_H +#include +#include + +static inline void esp_fill_random(uint8_t *buf, size_t len) +{ + for (size_t i = 0; i < len; i++) { + buf[i] = (uint8_t)(rand() & 0xFF); + } +} + #endif diff --git a/tests/unit/test_mcp_handler.c b/tests/unit/test_mcp_handler.c new file mode 100644 index 0000000..aaa199d --- /dev/null +++ b/tests/unit/test_mcp_handler.c @@ -0,0 +1,148 @@ +#include "test_framework.h" +#include "mcp_handler.h" +#include "config.h" +#include "nucula_wallet.h" +#include "cJSON.h" +#include +#include + +static tollgate_config_t g_test_config; +static uint64_t g_wallet_balance = 0; +static int g_wallet_proof_count = 0; +static int g_wallet_send_rc = 0; +static char g_wallet_send_token[256] = "cashuA_test_token"; + +const tollgate_config_t *tollgate_config_get(void) { + return &g_test_config; +} + +uint64_t nucula_wallet_balance(void) { + return g_wallet_balance; +} + +int nucula_wallet_proof_count(void) { + return g_wallet_proof_count; +} + +int nucula_wallet_send(uint64_t amount, char *token_out, size_t token_max) { + (void)amount; + (void)token_max; + if (g_wallet_send_rc == 0) { + strncpy(token_out, g_wallet_send_token, token_max - 1); + } + return g_wallet_send_rc; +} + +static void test_mcp_parse_tool(void) +{ + printf("\n=== MCP tool parsing ===\n"); + ASSERT_EQ_INT(MCP_TOOL_GET_CONFIG, mcp_parse_tool("get_config"), "get_config"); + ASSERT_EQ_INT(MCP_TOOL_SET_CONFIG, mcp_parse_tool("set_config"), "set_config"); + ASSERT_EQ_INT(MCP_TOOL_GET_BALANCE, mcp_parse_tool("get_balance"), "get_balance"); + ASSERT_EQ_INT(MCP_TOOL_WALLET_SEND, mcp_parse_tool("wallet_send"), "wallet_send"); + ASSERT_EQ_INT(MCP_TOOL_UNKNOWN, mcp_parse_tool("foo"), "unknown tool"); + ASSERT_EQ_INT(MCP_TOOL_UNKNOWN, mcp_parse_tool(NULL), "NULL tool"); +} + +static void test_mcp_get_config(void) +{ + printf("\n=== MCP get_config ===\n"); + memset(&g_test_config, 0, sizeof(g_test_config)); + strncpy(g_test_config.ap_ssid, "TollGate-TEST", sizeof(g_test_config.ap_ssid) - 1); + strncpy(g_test_config.metric, "bytes", sizeof(g_test_config.metric) - 1); + g_test_config.price_per_step = 21; + g_test_config.step_size_ms = 60000; + g_test_config.step_size_bytes = 22020096; + strncpy(g_test_config.mint_url, "https://testnut.cashu.space", sizeof(g_test_config.mint_url) - 1); + + mcp_response_t resp = mcp_handle_get_config(); + ASSERT(resp.success, "get_config succeeds"); + + cJSON *result = cJSON_Parse(resp.result_json); + ASSERT(result != NULL, "result is valid JSON"); + ASSERT_EQ_STR("bytes", cJSON_GetObjectItem(result, "metric")->valuestring, "metric=bytes"); + ASSERT_EQ_INT(21, cJSON_GetObjectItem(result, "price_per_step")->valueint, "price=21"); + cJSON_Delete(result); +} + +static void test_mcp_set_config(void) +{ + printf("\n=== MCP set_config ===\n"); + memset(&g_test_config, 0, sizeof(g_test_config)); + g_test_config.price_per_step = 21; + + const char *params = "{\"price_per_step\":42,\"metric\":\"milliseconds\"}"; + mcp_response_t resp = mcp_handle_set_config(params); + ASSERT(resp.success, "set_config succeeds"); + ASSERT_EQ_INT(42, g_test_config.price_per_step, "price updated to 42"); + ASSERT_EQ_STR("milliseconds", g_test_config.metric, "metric updated"); + + resp = mcp_handle_set_config("not json"); + ASSERT(!resp.success, "invalid JSON fails"); +} + +static void test_mcp_get_balance(void) +{ + printf("\n=== MCP get_balance ===\n"); + g_wallet_balance = 500; + g_wallet_proof_count = 8; + + mcp_response_t resp = mcp_handle_get_balance(); + ASSERT(resp.success, "get_balance succeeds"); + + cJSON *result = cJSON_Parse(resp.result_json); + ASSERT(result != NULL, "result is valid JSON"); + ASSERT_EQ_INT(500, (int)cJSON_GetObjectItem(result, "balance_sats")->valuedouble, "balance=500"); + ASSERT_EQ_INT(8, cJSON_GetObjectItem(result, "proof_count")->valueint, "proofs=8"); + cJSON_Delete(result); +} + +static void test_mcp_wallet_send(void) +{ + printf("\n=== MCP wallet_send ===\n"); + g_wallet_send_rc = 0; + strncpy(g_wallet_send_token, "cashuA_send_test", sizeof(g_wallet_send_token) - 1); + + const char *params = "{\"amount\":21}"; + mcp_response_t resp = mcp_handle_wallet_send(params); + ASSERT(resp.success, "wallet_send succeeds"); + + cJSON *result = cJSON_Parse(resp.result_json); + ASSERT(result != NULL, "result is valid JSON"); + ASSERT_EQ_STR("cashuA_send_test", cJSON_GetObjectItem(result, "token")->valuestring, "token matches"); + cJSON_Delete(result); + + printf("\n--- wallet_send missing amount ---\n"); + resp = mcp_handle_wallet_send("{}"); + ASSERT(!resp.success, "missing amount fails"); + + printf("\n--- wallet_send send fails ---\n"); + g_wallet_send_rc = -1; + resp = mcp_handle_wallet_send("{\"amount\":100}"); + ASSERT(!resp.success, "send failure reported"); +} + +static void test_mcp_dispatch(void) +{ + printf("\n=== MCP dispatch ===\n"); + mcp_request_t req = {0}; + req.tool = MCP_TOOL_UNKNOWN; + strncpy(req.method, "bogus", sizeof(req.method) - 1); + mcp_response_t resp = mcp_dispatch(&req); + ASSERT(!resp.success, "unknown tool dispatch fails"); + + resp = mcp_dispatch(NULL); + ASSERT(!resp.success, "NULL request dispatch fails"); +} + +int main(void) +{ + printf("=== test_mcp_handler ===\n"); + test_mcp_parse_tool(); + test_mcp_get_config(); + test_mcp_set_config(); + test_mcp_get_balance(); + test_mcp_wallet_send(); + test_mcp_dispatch(); + TEST_SUMMARY(); +} diff --git a/tests/unit/test_nip04.c b/tests/unit/test_nip04.c new file mode 100644 index 0000000..27eb13c --- /dev/null +++ b/tests/unit/test_nip04.c @@ -0,0 +1,107 @@ +#include "test_framework.h" +#include "../../main/nip04.h" +#include +#include +#include +#include +#include +#include +#include + +static void test_nip04_roundtrip(void) +{ + printf("\n=== NIP-04 encrypt/decrypt roundtrip ===\n"); + + secp256k1_context *ctx = secp256k1_context_create(SECP256K1_CONTEXT_SIGN | SECP256K1_CONTEXT_VERIFY); + + uint8_t alice_sec[32], bob_sec[32]; + memset(alice_sec, 0x01, 32); + memset(bob_sec, 0x02, 32); + + secp256k1_pubkey alice_pk, bob_pk; + secp256k1_ec_pubkey_create(ctx, &alice_pk, alice_sec); + secp256k1_ec_pubkey_create(ctx, &bob_pk, bob_sec); + + uint8_t alice_xonly[32], bob_xonly[32]; + secp256k1_xonly_pubkey alice_xpk, bob_xpk; + secp256k1_xonly_pubkey_from_pubkey(ctx, &alice_xpk, NULL, &alice_pk); + secp256k1_xonly_pubkey_from_pubkey(ctx, &bob_xpk, NULL, &bob_pk); + secp256k1_xonly_pubkey_serialize(ctx, alice_xonly, &alice_xpk); + secp256k1_xonly_pubkey_serialize(ctx, bob_xonly, &bob_xpk); + + const char *message = "Hello, ContextVM! This is a test message."; + + uint8_t ciphertext[4096]; + size_t ct_len = 0; + nip04_encrypt(alice_sec, bob_xonly, message, ciphertext, &ct_len); + ASSERT(ct_len > 0, "encryption produced output"); + ASSERT(ct_len > strlen(message), "ciphertext longer than plaintext"); + + char plaintext[2048]; + int pt_len = nip04_decrypt(bob_sec, alice_xonly, (const char *)ciphertext, plaintext, sizeof(plaintext)); + ASSERT(pt_len > 0, "decryption succeeded"); + ASSERT_EQ_STR(message, plaintext, "decrypted message matches original"); + + printf("\n--- Different key produces garbage ---\n"); + uint8_t eve_sec[32]; + memset(eve_sec, 0x03, 32); + pt_len = nip04_decrypt(eve_sec, alice_xonly, (const char *)ciphertext, plaintext, sizeof(plaintext)); + if (pt_len > 0) { + ASSERT(strcmp(message, plaintext) != 0, "wrong key produces different output"); + } else { + ASSERT(true, "wrong key fails to decrypt"); + } + + printf("\n--- Second roundtrip (different message) ---\n"); + const char *msg2 = "Short"; + nip04_encrypt(alice_sec, bob_xonly, msg2, ciphertext, &ct_len); + pt_len = nip04_decrypt(bob_sec, alice_xonly, (const char *)ciphertext, plaintext, sizeof(plaintext)); + ASSERT(pt_len > 0, "short message decrypts"); + ASSERT_EQ_STR(msg2, plaintext, "short message matches"); + + printf("\n--- Long message roundtrip ---\n"); + char long_msg[512]; + memset(long_msg, 'X', 511); + long_msg[511] = '\0'; + nip04_encrypt(alice_sec, bob_xonly, long_msg, ciphertext, &ct_len); + pt_len = nip04_decrypt(bob_sec, alice_xonly, (const char *)ciphertext, plaintext, sizeof(plaintext)); + ASSERT(pt_len > 0, "long message decrypts"); + ASSERT_EQ_INT(511, pt_len, "long message length matches"); + + printf("\n--- Bob encrypts, Alice decrypts ---\n"); + nip04_encrypt(bob_sec, alice_xonly, message, ciphertext, &ct_len); + pt_len = nip04_decrypt(alice_sec, bob_xonly, (const char *)ciphertext, plaintext, sizeof(plaintext)); + ASSERT(pt_len > 0, "reverse direction decrypts"); + ASSERT_EQ_STR(message, plaintext, "reverse direction matches"); + + secp256k1_context_destroy(ctx); +} + +static void test_nip04_invalid_input(void) +{ + printf("\n=== NIP-04 invalid inputs ===\n"); + char plaintext[256]; + int rc = nip04_decrypt(NULL, NULL, "AAAA", plaintext, sizeof(plaintext)); + ASSERT(rc < 0, "NULL keys fails"); + + uint8_t dummy_sec[32]; + memset(dummy_sec, 0xAA, 32); + rc = nip04_decrypt(dummy_sec, NULL, "AAAA", plaintext, sizeof(plaintext)); + ASSERT(rc < 0, "NULL pubkey fails"); + + uint8_t dummy_pub[32]; + memset(dummy_pub, 0xBB, 32); + rc = nip04_decrypt(dummy_sec, dummy_pub, "", plaintext, sizeof(plaintext)); + ASSERT(rc < 0, "empty ciphertext fails"); + + rc = nip04_decrypt(dummy_sec, dummy_pub, "AAAA", plaintext, sizeof(plaintext)); + ASSERT(rc < 0, "garbage ciphertext fails"); +} + +int main(void) +{ + printf("=== test_nip04 ===\n"); + test_nip04_roundtrip(); + test_nip04_invalid_input(); + TEST_SUMMARY(); +} -- cgit v1.2.3