cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
Loading...
Searching...
No Matches
boot.cpp File Reference

Bring-up: NVS, panel, reader, wallet, addresses, setup wizard, Wi-Fi and clock — everything before the main loop. More...

#include "pos_app.h"
Include dependency graph for boot.cpp:

Go to the source code of this file.

Classes

class  NullLogger

Macros

#define PN532_I2C_PORT   0
#define PN532_SDA   27
#define PN532_SCL   22
#define PN532_IRQ   (-1)
#define PN532_RST   (-1)
#define PN532_I2C_HZ   100000U
#define LED_R   GPIO_NUM_4
#define LED_G   GPIO_NUM_16
#define LED_B   GPIO_NUM_17
#define WIFI_SAVED_ATTEMPTS   3U
#define TIME_SYNC_ATTEMPTS   3U
#define BOOT_FAULT_RESTART_S   30U

Functions

void wifi_keep_or_drop (bool keep)
 Persist or discard the pending picker credentials, then scrub them.
void wait_for_ui_event (ui_event_t want)
 Block until the UI reports want, discarding anything else.
bool wifi_try_saved (void)
 Try the saved credentials, staying on the splash while it happens.
bool wifi_picker (const char *note)
 Run the panel network picker (scan → list → keyboard → connect) until connected.
static bool resolve_evm_payout (bool *rejected)
 Resolve the EVM payout address into its dual store, at boot.
void boot_fault (ui_boot_err_t kind, const char *detail)
 Show a startup fault, then restart. Does not return.
bool run_wizard (CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_CryptoProvider &crypto, bool wifi_only)
 Run the browser wizard until the operator presses Finish.
bool sync_time (void)
 Block on an SNTP sync so TLS certificate validity-period checks run against real time instead of the 1970 epoch.
pos_hw_t pos_boot (void)
 Everything before the main loop. Returns the card stack, which lives for the life of the program.

Variables

const char *const NOTE_JOIN_FAILED
const char *const NOTE_NO_TIME
static char s_join_ssid [33] = { 0 }
static char s_join_pass [65] = { 0 }

Detailed Description

Bring-up: NVS, panel, reader, wallet, addresses, setup wizard, Wi-Fi and clock — everything before the main loop.

Definition in file boot.cpp.

Macro Definition Documentation

◆ BOOT_FAULT_RESTART_S

#define BOOT_FAULT_RESTART_S   30U

Definition at line 212 of file boot.cpp.

Referenced by boot_fault().

◆ LED_B

#define LED_B   GPIO_NUM_17

Definition at line 49 of file boot.cpp.

Referenced by pos_boot().

◆ LED_G

#define LED_G   GPIO_NUM_16

Definition at line 48 of file boot.cpp.

Referenced by pos_boot().

◆ LED_R

#define LED_R   GPIO_NUM_4

Definition at line 47 of file boot.cpp.

Referenced by pos_boot().

◆ PN532_I2C_HZ

#define PN532_I2C_HZ   100000U

Definition at line 43 of file boot.cpp.

Referenced by pos_boot().

◆ PN532_I2C_PORT

#define PN532_I2C_PORT   0

Definition at line 38 of file boot.cpp.

Referenced by pos_boot().

◆ PN532_IRQ

#define PN532_IRQ   (-1)

Definition at line 41 of file boot.cpp.

Referenced by pos_boot().

◆ PN532_RST

#define PN532_RST   (-1)

Definition at line 42 of file boot.cpp.

Referenced by pos_boot().

◆ PN532_SCL

#define PN532_SCL   22

Definition at line 40 of file boot.cpp.

Referenced by pos_boot().

◆ PN532_SDA

#define PN532_SDA   27

Definition at line 39 of file boot.cpp.

Referenced by pos_boot().

◆ TIME_SYNC_ATTEMPTS

#define TIME_SYNC_ATTEMPTS   3U

Definition at line 55 of file boot.cpp.

Referenced by sync_time().

◆ WIFI_SAVED_ATTEMPTS

#define WIFI_SAVED_ATTEMPTS   3U

Definition at line 54 of file boot.cpp.

Referenced by wifi_try_saved().

Function Documentation

◆ boot_fault()

void boot_fault ( ui_boot_err_t kind,
const char * detail )

Show a startup fault, then restart. Does not return.

Most boot faults (a reader that missed its first I2C wake-up, a card stack that did not come up) clear on the next boot, and an unattended terminal must not stay stopped. On an unconfirmed update (ota_mark_valid runs after the wallet) the restart rolls back to the image that worked. A persistent fault keeps showing, 30 s at a time.

Definition at line 223 of file boot.cpp.

References BOOT_FAULT_RESTART_S, TAG, and ui_show_boot_error().

Referenced by pos_boot(), and resolve_evm_payout().

◆ pos_boot()

◆ resolve_evm_payout()

bool resolve_evm_payout ( bool * rejected)
static

Resolve the EVM payout address into its dual store, at boot.

Take the operator's value if there is one, probe-parse it, fall back to config.h if that fails, then parse twice into the dual store (§7.1), which also runs the EIP-55 checksum, so a mistyped address is caught at boot.

A stored value that will not parse does not stop the boot (the setup page can only check an address structurally), but it is reported through rejected, and that payout must refuse every sale: falling back to the config.h recipient would quietly pay an address the operator never chose (a development address, even on mainnet). A bad config.h value IS fatal: it is the integrator's own doing and there is nothing left to fall back to.

Parameters
[out]rejectedSet true when a stored value was refused.
Returns
false when even ADDR_TO will not parse (does not actually return: see boot_fault).

Definition at line 232 of file boot.cpp.

References boot_fault(), eth_addr_parse(), s_dest, s_payout_eth, settings_get_payout(), TAG, and UI_BOOT_ERR_CONFIG.

Referenced by pos_boot().

◆ run_wizard()

bool run_wizard ( CryptnoxWallet & wallet,
Pn532NfcTransport & transport,
CW_CryptoProvider & crypto,
bool wifi_only )

Run the browser wizard until the operator presses Finish.

  1. admin code on the panel — done by the caller; its value is that it never crosses a network.
  2. QR code on the panel — a camera joins the SoftAP and the captive portal opens the page.
  3. authorise both — the browser asks; the panel takes the code.
  4. addresses in the browser
  5. Wi-Fi in the browser
  6. Finish on the panel — restarts, which applies everything.
Parameters
[in]wifi_onlySteps 5 and 6 only, for a configured terminal that lost its network. No admin code: the form can only propose what the panel must accept, and the AP passphrase on that panel is the perimeter (see prov_set_wifi_only).
Returns
false if the portal could not be raised; the caller falls back to the panel.

Definition at line 269 of file boot.cpp.

References card_read_payouts(), ui_msg_t::event, net_time_sync(), net_wifi_connect(), net_wifi_disconnect(), net_wifi_scan(), NOTE_JOIN_FAILED, NOTE_NO_TIME, PROV_ASK_PAYOUT_ETH, PROV_ASK_PAYOUT_TRON, prov_authed(), prov_mode(), PROV_MODE_OFF, PROV_MODE_WIZARD, prov_propose(), prov_set_note(), prov_set_scan(), prov_set_step(), prov_set_wifi_only(), prov_start(), prov_step(), PROV_STEP_ADDR, PROV_STEP_AUTH, PROV_STEP_DONE, PROV_STEP_WIFI, prov_stop(), s_ui_queue, s_user_cancelled, settings_has_payout(), settings_has_wifi(), SETTINGS_PAYOUT_MAX, settings_set_wifi(), TAG, UI_EVENT_CARD_PIN, ui_event_dispatch(), UI_EVENT_PROV_AUTH, UI_EVENT_PROV_CARD, UI_EVENT_PROV_FINISH, UI_EVENT_PROV_NEXT, UI_EVENT_PROV_SCAN, UI_EVENT_PROV_STOP, UI_EVENT_PROV_VALUE, UI_EVENT_PROV_VALUE_NO, UI_EVENT_PROV_VALUE_SET, UI_EVENT_WIFI_TRY, ui_set_boot_status(), ui_set_prov_note(), ui_show_card_pin(), ui_show_prov(), ui_show_prov_auth(), ui_show_prov_confirm(), ui_show_wifi_connecting(), ui_take_pin(), and ui_take_wifi_creds().

Referenced by pos_boot().

◆ sync_time()

bool sync_time ( void )

Block on an SNTP sync so TLS certificate validity-period checks run against real time instead of the 1970 epoch.

Returns
true once the clock is set, false after TIME_SYNC_ATTEMPTS rounds — flaky uplinks often need a second try.

Definition at line 483 of file boot.cpp.

References net_time_sync(), TAG, and TIME_SYNC_ATTEMPTS.

Referenced by pos_boot().

◆ wait_for_ui_event()

void wait_for_ui_event ( ui_event_t want)

Block until the UI reports want, discarding anything else.

For the modal first-run steps. The queue is flushed on the way out so a repeated tap is not read by the next stage (wifi_picker() would rescan and throw away a half-typed password).

Definition at line 94 of file boot.cpp.

References ui_msg_t::event, and s_ui_queue.

Referenced by pos_boot().

◆ wifi_keep_or_drop()

void wifi_keep_or_drop ( bool keep)

Persist or discard the pending picker credentials, then scrub them.

Parameters
[in]keeptrue once the clock is set — the only proof the network is actually usable; false to drop them unpersisted.

Definition at line 77 of file boot.cpp.

References s_join_pass, s_join_ssid, settings_set_wifi(), and TAG.

Referenced by pos_boot().

◆ wifi_picker()

bool wifi_picker ( const char * note)

Run the panel network picker (scan → list → keyboard → connect) until connected.

Blocks until a connection succeeds. The fallback to the browser setup (run_wizard): reached from the settings menu, or when the SoftAP could not come up.

A network joined here is not persisted: the credentials are staged for wifi_keep_or_drop, which the caller invokes once the clock proves the uplink usable.

Parameters
[in]noteOne-line reason shown above the picker, or NULL.
Returns
true always: the picker took the screen, so restore the splash.

Definition at line 151 of file boot.cpp.

References ui_msg_t::event, net_wifi_connect(), net_wifi_scan(), NOTE_JOIN_FAILED, ok(), s_join_pass, s_join_ssid, s_ui_queue, UI_EVENT_WIFI_SCAN, UI_EVENT_WIFI_TRY, ui_show_wifi_connecting(), ui_show_wifi_list(), and ui_take_wifi_creds().

Referenced by pos_boot().

◆ wifi_try_saved()

bool wifi_try_saved ( void )

Try the saved credentials, staying on the splash while it happens.

Unattended, so it reports through ui_set_boot_status. config.h Wi-Fi credentials are intentionally not used (NVS only).

Returns
true if a saved network was joined.

Definition at line 113 of file boot.cpp.

References net_wifi_connect(), ok(), settings_get_wifi(), TAG, ui_set_boot_status(), and WIFI_SAVED_ATTEMPTS.

Referenced by pos_boot().

Variable Documentation

◆ NOTE_JOIN_FAILED

const char* const NOTE_JOIN_FAILED
Initial value:
=
"Could not join that network - check the password"

Definition at line 58 of file boot.cpp.

Referenced by app_main(), run_wizard(), and wifi_picker().

◆ NOTE_NO_TIME

const char* const NOTE_NO_TIME
Initial value:
=
"No network time - this Wi-Fi has no usable internet"

Definition at line 60 of file boot.cpp.

Referenced by app_main(), pos_boot(), and run_wizard().

◆ s_join_pass

char s_join_pass[65] = { 0 }
static

Definition at line 69 of file boot.cpp.

Referenced by wifi_keep_or_drop(), and wifi_picker().

◆ s_join_ssid

char s_join_ssid[33] = { 0 }
static

Definition at line 68 of file boot.cpp.

Referenced by wifi_keep_or_drop(), and wifi_picker().