cryptnox-pos
1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
Toggle main menu visibility
Loading...
Searching...
No Matches
hardening.h
Go to the documentation of this file.
1
/*
2
* SPDX-License-Identifier: LGPL-3.0-or-later
3
* Copyright (c) 2026 Cryptnox SA
4
*/
5
20
21
#ifndef HARDENING_H
22
#define HARDENING_H
23
24
#include <stdint.h>
25
#include <string.h>
26
27
#include "
eth_addr.h
"
/* ETH_ADDR_LEN — the recipient is an ETH address */
28
29
#ifdef __cplusplus
30
#include "CW_Utils.h"
/* SDK hardened primitives: constant-time secure_compare */
31
#endif
32
33
#ifdef __cplusplus
34
extern
"C"
{
35
#endif
36
37
/* ── §3.1 Anti-symmetric boolean ──────────────────────────────────── */
38
typedef
uint32_t
bool32
;
39
/* Bitwise complements, Hamming distance 32: no small burst of flips can turn
40
* FALSE32 into TRUE32. Only TRUE32 reads as true; ANY other pattern is false. */
41
#define TRUE32 ((bool32)0x5AA55AA5u)
42
#define FALSE32 ((bool32)0xA55AA55Au)
43
#define IS_TRUE32(x) ((x) == TRUE32)
44
45
/* ── §4 payment verdict token (anti-symmetric, never 0/1) ─────────── */
46
typedef
uint32_t
pos_verdict_t
;
47
#define POS_VERDICT_APPROVED ((pos_verdict_t)0x33CC33CCu)
48
#define POS_VERDICT_DECLINED ((pos_verdict_t)0xCC33CC33u)
49
50
#ifdef __cplusplus
51
static_assert
(
TRUE32
== (
bool32
)
~FALSE32
,
52
"bool32 sentinels must be bitwise complements"
);
53
static_assert
(
POS_VERDICT_APPROVED
== (
pos_verdict_t
)
~POS_VERDICT_DECLINED
,
54
"verdict sentinels must be bitwise complements"
);
55
#endif
56
57
/* ── §3.2 dual-stored business data ───────────────────────────────── */
58
typedef
struct
{
59
uint64_t
amount_minor
;
60
uint64_t
amount_minor_inv
;
62
}
pos_amount_t
;
63
64
typedef
struct
{
65
uint8_t
addr
[
ETH_ADDR_LEN
];
66
uint8_t
addr_echo
[
ETH_ADDR_LEN
];
67
}
pos_addr_t
;
68
70
static
inline
void
pos_amount_set
(
pos_amount_t
*a, uint64_t v)
71
{
72
a->
amount_minor
= v;
73
a->
amount_minor_inv
= ~v;
/* distinct pattern: the two stores can't be
74
proven redundant, so neither is elided */
75
}
76
85
void
pos_handle_anomaly
(
const
char
*where);
86
88
uint32_t
pos_anomaly_count
(
void
);
89
90
/* ── Pure comparators — no side effects, so the caller decides how to react
91
* (and the host self-test needs no NVS/log stubs). ────────────────── */
92
93
static
inline
bool32
amount_consistent
(
const
pos_amount_t
*a)
94
{
95
return
(a->
amount_minor
== (uint64_t)~a->
amount_minor_inv
) ?
TRUE32
:
FALSE32
;
96
}
97
98
static
inline
bool32
address_consistent
(
const
pos_addr_t
*a)
99
{
100
/* ponytail: C++-only; every consumer is a .cpp. Restore a memcmp #else
101
* branch if a C translation unit ever needs this header. */
102
return
CW_Utils::secure_compare(a->
addr
, a->
addr_echo
,
ETH_ADDR_LEN
) ?
TRUE32
103
:
FALSE32
;
104
}
105
118
static
inline
bool32
run_payment_decision
(
const
pos_amount_t
*amount,
119
const
pos_addr_t
*to,
120
pos_verdict_t
verdict)
121
{
122
bool32
ok
=
FALSE32
;
123
124
if
(
IS_TRUE32
(
amount_consistent
(amount)) &&
125
IS_TRUE32
(
address_consistent
(to)) &&
126
(verdict ==
POS_VERDICT_APPROVED
)) {
127
ok
=
TRUE32
;
128
}
129
130
return
ok
;
131
}
132
133
#ifdef __cplusplus
134
}
135
#endif
136
137
#endif
/* HARDENING_H */
eth_addr.h
Hex Ethereum-address parsing — a pure, dependency-free unit so it can be unit-tested and fuzzed on th...
ETH_ADDR_LEN
#define ETH_ADDR_LEN
Length of a raw (binary) Ethereum address, in bytes.
Definition
eth_addr.h:25
IS_TRUE32
#define IS_TRUE32(x)
Definition
hardening.h:43
TRUE32
#define TRUE32
Definition
hardening.h:41
amount_consistent
static bool32 amount_consistent(const pos_amount_t *a)
Definition
hardening.h:93
run_payment_decision
static bool32 run_payment_decision(const pos_amount_t *amount, const pos_addr_t *to, pos_verdict_t verdict)
§4 decision gate: return TRUE32 only if amount and recipient are self-consistent AND the verdict is t...
Definition
hardening.h:118
pos_verdict_t
uint32_t pos_verdict_t
Definition
hardening.h:46
POS_VERDICT_APPROVED
#define POS_VERDICT_APPROVED
Definition
hardening.h:47
address_consistent
static bool32 address_consistent(const pos_addr_t *a)
Definition
hardening.h:98
pos_amount_set
static void pos_amount_set(pos_amount_t *a, uint64_t v)
Write both amount stores from one value (two independent writes).
Definition
hardening.h:70
bool32
uint32_t bool32
Definition
hardening.h:38
POS_VERDICT_DECLINED
#define POS_VERDICT_DECLINED
Definition
hardening.h:48
FALSE32
#define FALSE32
Definition
hardening.h:42
pos_anomaly_count
uint32_t pos_anomaly_count(void)
Persisted total anomaly count (for the optional maintenance view).
Definition
hardening.cpp:125
pos_handle_anomaly
void pos_handle_anomaly(const char *where)
Report an anomaly: bump a self-checked persisted counter, log it, and keep a local ring buffer for on...
Definition
hardening.cpp:99
ok
static esp_err_t ok(httpd_req_t *req, const char *msg)
200 with a plain-text message.
Definition
provision.cpp:414
pos_addr_t
Definition
hardening.h:64
pos_addr_t::addr_echo
uint8_t addr_echo[ETH_ADDR_LEN]
Definition
hardening.h:66
pos_addr_t::addr
uint8_t addr[ETH_ADDR_LEN]
Definition
hardening.h:65
pos_amount_t
Definition
hardening.h:58
pos_amount_t::amount_minor_inv
uint64_t amount_minor_inv
Definition
hardening.h:60
pos_amount_t::amount_minor
uint64_t amount_minor
Definition
hardening.h:59
main
hardening.h
Generated by
1.17.0