cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
Loading...
Searching...
No Matches
card_io.cpp File Reference

The card on the reader: is it usable, open a channel, sign, read the payout addresses off it. More...

#include "pos_app.h"
Include dependency graph for card_io.cpp:

Go to the source code of this file.

Functions

static const char * card_fault (Pn532NfcTransport &transport)
 Whether the card now on the reader is set up at all.
const char * pin_fail_text (Pn532NfcTransport &transport, const char *wrong)
 Why verifyPin said no: the PIN, or the card leaving the field.
bool card_connect (CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_SecureSession &session, bool setup)
 Wait for a card and open a secure channel, cancellable from the UI.
bool card_sign (CryptnoxWallet &wallet, CW_SecureSession &session, const uint8_t *hash, uint8_t hash_len, const uint8_t *path, uint8_t path_len, const char *pin, size_t pin_chars, uint8_t rs_out[64], char *err_out, size_t err_max)
 Have the card sign hash, then close the session.
bool card_read_payouts (CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_CryptoProvider &crypto, const char *pin, size_t pin_chars, char *eth_out, size_t eth_n, char *tron_out, size_t tron_n, char *err, size_t err_n)
 Read the card's payout addresses and put them through the panel.

Variables

const char * s_card_fault = NULL

Detailed Description

The card on the reader: is it usable, open a channel, sign, read the payout addresses off it.

Definition in file card_io.cpp.

Function Documentation

◆ card_connect()

bool card_connect ( CryptnoxWallet & wallet,
Pn532NfcTransport & transport,
CW_SecureSession & session,
bool setup )

Wait for a card and open a secure channel, cancellable from the UI.

Manual connect loop with cancel checks between PN532 polls, so a Cancel aborts within one PN532 timeout. Drives the "Tap your card" / "Processing" screens.

Parameters
[in]walletInitialised wallet instance.
[in]transportPN532 transport, polled directly.
[out]sessionOpen secure session on success.
[in]setuptrue when reading payout addresses rather than paying; shows the card-wait screen instead of the transaction one.
Returns
true with session open; false on user cancel, after 60 s, or on a card that is not set up — the three are told apart by s_user_cancelled and s_card_fault.

Definition at line 79 of file card_io.cpp.

References card_fault(), s_card_fault, s_user_cancelled, ui_show_card_wait(), ui_show_tx_status(), UI_TX_STATE_PLACE_CARD, UI_TX_STATE_PROCESSING, and wdt_feed().

Referenced by card_read_payouts(), sign_and_broadcast(), and sign_and_broadcast_tron().

◆ card_fault()

const char * card_fault ( Pn532NfcTransport & transport)
static

Whether the card now on the reader is set up at all.

Runs before the secure channel because the SELECT response says so in the clear; later, an uninitialised card reads as "Wrong card PIN" and a seedless one as a sign error. A second SELECT (establishSecureChannel) is harmless.

Returns
NULL if the card is usable, or if this cannot tell; else the line to show. See card_status.h.

Definition at line 30 of file card_io.cpp.

References CARD_READY, CARD_SELECT_APDU, card_state(), card_state_text(), and TAG.

Referenced by card_connect().

◆ card_read_payouts()

bool card_read_payouts ( CryptnoxWallet & wallet,
Pn532NfcTransport & transport,
CW_CryptoProvider & crypto,
const char * pin,
size_t pin_chars,
char * eth_out,
size_t eth_n,
char * tron_out,
size_t tron_n,
char * err,
size_t err_n )

Read the card's payout addresses and put them through the panel.

The card will not export a public key without a verified PIN, so this needs the card PIN exactly as signing does — the caller collects it on the keypad first.

One tap yields both addresses (Ethereum m/44'/60'/0'/0/0, Tron m/44'/195'/0'/0/0), so a terminal is not left half configured, offering one network's payments to the compiled-in address.

Neither address is stored here. Both are proposed, through the same accept-on-the-panel handshake a browser submission goes through, because "the card said so" is not the same claim as "the operator checked it" — a card presented by a customer would otherwise redirect the takings.

Parameters
[out]eth_outEIP-55 "0x..." address, or "" if it could not be read.
[in]eth_nCapacity of eth_out.
[out]tron_outbase58 "T..." address, or "".
[in]tron_nCapacity of tron_out.
[out]errShort reason for the panel when nothing could be read.
[in]err_nCapacity of err.
Returns
true if at least one address was read.

Definition at line 233 of file card_io.cpp.

References card_connect(), eth_addr_format(), ETH_DERIVE_PATH, keccak256(), pin_fail_text(), s_card_fault, s_user_cancelled, and TAG.

Referenced by app_main(), and run_wizard().

◆ card_sign()

bool card_sign ( CryptnoxWallet & wallet,
CW_SecureSession & session,
const uint8_t * hash,
uint8_t hash_len,
const uint8_t * path,
uint8_t path_len,
const char * pin,
size_t pin_chars,
uint8_t rs_out[64],
char * err_out,
size_t err_max )

Have the card sign hash, then close the session.

Shared tail of both payment paths: build the request, copy the PIN in as late as possible, sign, scrub the PIN, close the session, map the status byte to an operator-readable message. One copy of the PIN handling and wipe.

The caller reconciles its amount and addresses immediately before calling this, which makes that check the last thing before an irreversible signature. It stays with the caller because the anomaly label and values differ per path.

The session is disconnected on every exit — including the failures — so no caller can leave a card held open.

Parameters
[in]walletInitialised wallet instance.
[in]sessionOpen secure session; disconnected before returning.
[in]hashDigest to sign (the keccak of the RLP, or a Tron txID).
[in]hash_lenLength of hash.
[in]pathBIP-32 derivation path blob.
[in]path_lenLength of path.
[in]pinOperator-entered card PIN; the caller still owns and scrubs its own copy.
[in]pin_charsNumber of PIN characters in pin.
[out]rs_out64 bytes: r || s. Wiped by the caller (WipeGuard).
[out]err_outShort UI-facing error message on failure.
[in]err_maxCapacity of err_out.
Returns
true when rs_out holds a signature.

Definition at line 160 of file card_io.cpp.

Referenced by sign_and_broadcast(), and sign_and_broadcast_tron().

◆ pin_fail_text()

const char * pin_fail_text ( Pn532NfcTransport & transport,
const char * wrong )

Why verifyPin said no: the PIN, or the card leaving the field.

verifyPin returns a bare bool, and a card pulled away mid-APDU fails exactly like a mistyped PIN. Asked before the session is dropped: if the card does not answer a SELECT, it was not the PIN.

Definition at line 52 of file card_io.cpp.

References CARD_SELECT_APDU, and TAG.

Referenced by card_read_payouts(), sign_and_broadcast(), and sign_and_broadcast_tron().

Variable Documentation

◆ s_card_fault

const char* s_card_fault = NULL