cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
Loading...
Searching...
No Matches
hardening.h
Go to the documentation of this file.
1/*
2 * SPDX-License-Identifier: LGPL-3.0-or-later
3 * Copyright (c) 2026 Cryptnox SA
4 */
5
20
21#ifndef HARDENING_H
22#define HARDENING_H
23
24#include <stdint.h>
25#include <string.h>
26
27#include "eth_addr.h" /* ETH_ADDR_LEN — the recipient is an ETH address */
28
29#ifdef __cplusplus
30#include "CW_Utils.h" /* SDK hardened primitives: constant-time secure_compare */
31#endif
32
33#ifdef __cplusplus
34extern "C" {
35#endif
36
37/* ── §3.1 Anti-symmetric boolean ──────────────────────────────────── */
38typedef uint32_t bool32;
39/* Bitwise complements, Hamming distance 32: no small burst of flips can turn
40 * FALSE32 into TRUE32. Only TRUE32 reads as true; ANY other pattern is false. */
41#define TRUE32 ((bool32)0x5AA55AA5u)
42#define FALSE32 ((bool32)0xA55AA55Au)
43#define IS_TRUE32(x) ((x) == TRUE32)
44
45/* ── §4 payment verdict token (anti-symmetric, never 0/1) ─────────── */
46typedef uint32_t pos_verdict_t;
47#define POS_VERDICT_APPROVED ((pos_verdict_t)0x33CC33CCu)
48#define POS_VERDICT_DECLINED ((pos_verdict_t)0xCC33CC33u)
49
50#ifdef __cplusplus
51static_assert(TRUE32 == (bool32)~FALSE32,
52 "bool32 sentinels must be bitwise complements");
54 "verdict sentinels must be bitwise complements");
55#endif
56
57/* ── §3.2 dual-stored business data ───────────────────────────────── */
58typedef struct {
59 uint64_t amount_minor;
63
64typedef struct {
65 uint8_t addr[ETH_ADDR_LEN];
68
70static inline void pos_amount_set(pos_amount_t *a, uint64_t v)
71{
72 a->amount_minor = v;
73 a->amount_minor_inv = ~v; /* distinct pattern: the two stores can't be
74 proven redundant, so neither is elided */
75}
76
85void pos_handle_anomaly(const char *where);
86
88uint32_t pos_anomaly_count(void);
89
90/* ── Pure comparators — no side effects, so the caller decides how to react
91 * (and the host self-test needs no NVS/log stubs). ────────────────── */
92
93static inline bool32 amount_consistent(const pos_amount_t *a)
94{
95 return (a->amount_minor == (uint64_t)~a->amount_minor_inv) ? TRUE32 : FALSE32;
96}
97
98static inline bool32 address_consistent(const pos_addr_t *a)
99{
100 /* ponytail: C++-only; every consumer is a .cpp. Restore a memcmp #else
101 * branch if a C translation unit ever needs this header. */
102 return CW_Utils::secure_compare(a->addr, a->addr_echo, ETH_ADDR_LEN) ? TRUE32
103 : FALSE32;
104}
105
118static inline bool32 run_payment_decision(const pos_amount_t *amount,
119 const pos_addr_t *to,
120 pos_verdict_t verdict)
121{
122 bool32 ok = FALSE32;
123
124 if (IS_TRUE32(amount_consistent(amount)) &&
126 (verdict == POS_VERDICT_APPROVED)) {
127 ok = TRUE32;
128 }
129
130 return ok;
131}
132
133#ifdef __cplusplus
134}
135#endif
136
137#endif /* HARDENING_H */
Hex Ethereum-address parsing — a pure, dependency-free unit so it can be unit-tested and fuzzed on th...
#define ETH_ADDR_LEN
Length of a raw (binary) Ethereum address, in bytes.
Definition eth_addr.h:25
#define IS_TRUE32(x)
Definition hardening.h:43
#define TRUE32
Definition hardening.h:41
static bool32 amount_consistent(const pos_amount_t *a)
Definition hardening.h:93
static bool32 run_payment_decision(const pos_amount_t *amount, const pos_addr_t *to, pos_verdict_t verdict)
§4 decision gate: return TRUE32 only if amount and recipient are self-consistent AND the verdict is t...
Definition hardening.h:118
uint32_t pos_verdict_t
Definition hardening.h:46
#define POS_VERDICT_APPROVED
Definition hardening.h:47
static bool32 address_consistent(const pos_addr_t *a)
Definition hardening.h:98
static void pos_amount_set(pos_amount_t *a, uint64_t v)
Write both amount stores from one value (two independent writes).
Definition hardening.h:70
uint32_t bool32
Definition hardening.h:38
#define POS_VERDICT_DECLINED
Definition hardening.h:48
#define FALSE32
Definition hardening.h:42
uint32_t pos_anomaly_count(void)
Persisted total anomaly count (for the optional maintenance view).
void pos_handle_anomaly(const char *where)
Report an anomaly: bump a self-checked persisted counter, log it, and keep a local ring buffer for on...
Definition hardening.cpp:99
static esp_err_t ok(httpd_req_t *req, const char *msg)
200 with a plain-text message.
uint8_t addr_echo[ETH_ADDR_LEN]
Definition hardening.h:66
uint8_t addr[ETH_ADDR_LEN]
Definition hardening.h:65
uint64_t amount_minor_inv
Definition hardening.h:60
uint64_t amount_minor
Definition hardening.h:59