|
cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
|
The sale's arithmetic: keypad cents, base units, wei, fees, calldata. More...
#include <inttypes.h>#include <stdbool.h>#include <stddef.h>#include <stdint.h>#include <stdio.h>#include <string.h>#include "CW_Utils.h"#include "eth_addr.h"#include "settings.h"Go to the source code of this file.
Macros | |
| #define | AMOUNT_CENTS_MAX 999999ULL /* 9999.99 */ |
| #define | AMOUNT_CENTS_MAX_NATIVE (POS_AMOUNT_UNITS_MAX_NATIVE / 10000ULL) |
| #define | ABI_SELECTOR_LEN 4U /* transfer(address,uint256) selector */ |
| #define | ABI_WORD_LEN 32U /* one ABI-encoded argument word */ |
| #define | USDC_CALLDATA_LEN (ABI_SELECTOR_LEN + (2U * ABI_WORD_LEN)) /* 68 */ |
| #define | ABI_TO_OFFSET (ABI_SELECTOR_LEN + (ABI_WORD_LEN - ETH_ADDR_LEN)) |
Enumerations | |
| enum | evm_funds_t { EVM_FUNDS_OK = 0 , EVM_FUNDS_SHORT_GAS , EVM_FUNDS_SHORT_VALUE , EVM_FUNDS_UNKNOWN } |
| What the pre-flight balance check concluded. More... | |
Functions | |
| static uint64_t | amount_cents_cap (bool native) |
| Ceiling on what the keypad will accept, in cents. | |
| static uint64_t | amount_key_digit (uint64_t cents, unsigned digit, uint64_t cap) |
A digit shifted in from the right; refused whole if it passes cap. | |
| static uint64_t | amount_key_00 (uint64_t cents, uint64_t cap) |
The "00" key: two zeroes shifted in, clamped to cap. | |
| static uint64_t | amount_key_back (uint64_t cents) |
| The backspace key: the last digit dropped. | |
| static uint64_t | amount_cents_to_units (uint64_t cents) |
| Keypad cents to 6-decimal base units. | |
| static void | amount_format (uint64_t units, char *out, size_t n) |
| "12.50": 6-decimal base units to two places, truncated. | |
| static bool | evm_units_to_wei (uint64_t units, uint64_t *wei) |
| 6-decimal keypad units -> wei, for the 18-decimal coins only. | |
| static void | evm_fees_from_gwei (uint32_t max_gwei, uint32_t prio_gwei, bool polygon, uint32_t floor_gwei, uint64_t *max_fee, uint64_t *prio_fee) |
| The EIP-1559 fees one EVM sale will offer, in wei per gas, from the operator's Gwei settings. | |
| static evm_funds_t | evm_funds_check (bool native, uint64_t have_wei, uint64_t gas_cost, uint64_t units) |
Can have_wei pay for this sale? | |
| static void | fmt_coin (char *out, size_t n, uint64_t v, unsigned dec, const char *coin) |
"0.0013 ETH": v base units of a dec-decimal coin, to six places, rounded UP — it is a ceiling, and rounding down would understate it. | |
| static void | build_usdc_calldata (uint8_t out[USDC_CALLDATA_LEN], const uint8_t to[ETH_ADDR_LEN], uint64_t amount) |
Build the 68-byte ABI-encoded calldata for a USDC transfer call. | |
Variables | |
| static const uint8_t | TRANSFER_SELECTOR [4] = { 0xa9U, 0x05U, 0x9cU, 0xbbU } |
The sale's arithmetic: keypad cents, base units, wei, fees, calldata.
Header-only and free of ESP-IDF dependencies on purpose, like form_parse.h. Every number the customer is charged passes through these few lines, and a mistake in them is silent — a wrapped multiply signs a value nobody entered, a byte out of place in the calldata pays somebody else. So they live where a host test can hold them against vectors from an independent signer (tests/units/test_money.cpp, tools/gen_kat_vectors.py), rather than as statics in main.cpp and ui.cpp where nothing could reach them.
Definition in file money.h.
| #define ABI_SELECTOR_LEN 4U /* transfer(address,uint256) selector */ |
Definition at line 197 of file money.h.
Referenced by build_usdc_calldata().
| #define ABI_TO_OFFSET (ABI_SELECTOR_LEN + (ABI_WORD_LEN - ETH_ADDR_LEN)) |
Definition at line 200 of file money.h.
Referenced by build_usdc_calldata().
| #define ABI_WORD_LEN 32U /* one ABI-encoded argument word */ |
| #define AMOUNT_CENTS_MAX 999999ULL /* 9999.99 */ |
Definition at line 40 of file money.h.
Referenced by amount_cents_cap().
| #define AMOUNT_CENTS_MAX_NATIVE (POS_AMOUNT_UNITS_MAX_NATIVE / 10000ULL) |
Definition at line 42 of file money.h.
Referenced by amount_cents_cap().
| #define USDC_CALLDATA_LEN (ABI_SELECTOR_LEN + (2U * ABI_WORD_LEN)) /* 68 */ |
Definition at line 199 of file money.h.
Referenced by build_usdc_calldata(), and sign_and_broadcast().
| enum evm_funds_t |
|
inlinestatic |
Ceiling on what the keypad will accept, in cents.
ETH and POL are 18-decimal and the signed value is a uint64 of wei, so a sale stops at 18.44 of either (see POS_AMOUNT_UNITS_MAX_NATIVE).
| [in] | native | true for an EVM network's own coin (ETH, POL). |
Definition at line 52 of file money.h.
References AMOUNT_CENTS_MAX, and AMOUNT_CENTS_MAX_NATIVE.
Referenced by amount_cents_max().
|
inlinestatic |
Keypad cents to 6-decimal base units.
Definition at line 78 of file money.h.
Referenced by amount_update_display().
|
inlinestatic |
|
inlinestatic |
The "00" key: two zeroes shifted in, clamped to cap.
Definition at line 65 of file money.h.
Referenced by amount_kbd_cb().
|
inlinestatic |
The backspace key: the last digit dropped.
Definition at line 72 of file money.h.
Referenced by amount_kbd_cb().
|
inlinestatic |
A digit shifted in from the right; refused whole if it passes cap.
Definition at line 58 of file money.h.
Referenced by amount_kbd_cb().
|
inlinestatic |
Build the 68-byte ABI-encoded calldata for a USDC transfer call.
Encodes the ERC-20 transfer(address,uint256) selector followed by the ABI-encoded arguments:
| [out] | out | Output buffer of USDC_CALLDATA_LEN bytes. |
| [in] | to | Recipient address, ETH_ADDR_LEN bytes (already parsed/validated). |
| [in] | amount | Transfer amount in USDC base units (6 decimals). |
Definition at line 216 of file money.h.
References ABI_SELECTOR_LEN, ABI_TO_OFFSET, ETH_ADDR_LEN, TRANSFER_SELECTOR, and USDC_CALLDATA_LEN.
Referenced by sign_and_broadcast().
|
inlinestatic |
The EIP-1559 fees one EVM sale will offer, in wei per gas, from the operator's Gwei settings.
| [in] | max_gwei | The Max fee setting. |
| [in] | prio_gwei | The Priority fee setting. |
| [in] | polygon | true on Polygon, which has a tip floor of its own. |
| [in] | floor_gwei | That floor (POLY_MIN_PRIORITY_FEE_GWEI). |
| [out] | max_fee | Fee cap, wei per gas. |
| [out] | prio_fee | Tip, wei per gas; never above max_fee. |
Definition at line 121 of file money.h.
Referenced by evm_fees_wei().
|
inlinestatic |
Can have_wei pay for this sale?
| [in] | native | true for ETH/POL; for a token only the gas is in wei. |
| [in] | have_wei | Account balance. |
| [in] | gas_cost | Gas limit * max fee. |
| [in] | units | Sale amount in keypad base units (native only). |
Definition at line 159 of file money.h.
References EVM_FUNDS_OK, EVM_FUNDS_SHORT_GAS, EVM_FUNDS_SHORT_VALUE, EVM_FUNDS_UNKNOWN, and evm_units_to_wei().
Referenced by evm_balance_ok().
|
inlinestatic |
6-decimal keypad units -> wei, for the 18-decimal coins only.
| [in] | units | Sale amount in keypad base units. |
| [out] | wei | units * 10^12; untouched on refusal. |
Definition at line 103 of file money.h.
References POS_AMOUNT_UNITS_MAX_NATIVE.
Referenced by evm_funds_check(), and sign_and_broadcast().
|
inlinestatic |
"0.0013 ETH": v base units of a dec-decimal coin, to six places, rounded UP — it is a ceiling, and rounding down would understate it.
Definition at line 177 of file money.h.
Referenced by sale_fee_text().
|
static |
Definition at line 196 of file money.h.
Referenced by build_usdc_calldata().