cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
Loading...
Searching...
No Matches
pay.cpp File Reference

What a sale is paid with and to, and the sale between broadcast and verdict. More...

#include "pos_app.h"
Include dependency graph for pay.cpp:

Go to the source code of this file.

Functions

token_t * active_token (pos_chain_t chain)
 The selection's token, or NULL for a native coin.
static bool token_parse (token_t *t, bool tron, CW_CryptoProvider &crypto)
 Parse t->str into its dual store, twice and independently.
void token_load (const token_cfg_t *cfg, CW_CryptoProvider &crypto)
 Load one token at boot: the operator's contract if one is set and parses, config.h otherwise.
bool token_decimals_ok (pos_chain_t chain, char *err, size_t err_max)
 Before the first sale in an operator-set token, read its decimals() and refuse anything but 6.
void ui_refresh_addresses_for (uint8_t c)
 Point the UI's address rows at the selected chain.
void ui_refresh_addresses (void)
 Implemented by main: repoint those two rows at the selected chain.
const pos_addr_t * active_dest (void)
 The reconciled recipient for the chain currently selected.
void sale_fee_text (char *out, size_t n)
 The most network fee the customer's card can be charged on top of the sale, for the confirm screen. "" where there is no cap to state: a native TRX transfer burns bandwidth, not a fee limit.
void inflight_persist (const inflight_t *fl)
 Write the sale to NVS just before it leaves the terminal.
uint64_t wall_ms (void)
 Unix time in ms, 0 while the clock is unset.
void settle_inflight (void)
 Poll the in-flight sale for up to 120 s and show what the chain says.
bcast_t pay_sign_and_broadcast (CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_CryptoProvider &crypto, const pos_amount_t *amount, const char *pin, size_t pin_chars, inflight_t *fl, char *err_out, size_t err_max)
 Sign and broadcast the reconciled sale on whichever family is selected. The family is read once, here.

Variables

const uint8_t ETH_DERIVE_PATH [20]
char s_payout_eth [SETTINGS_PAYOUT_MAX] = ""
char s_payout_tron [SETTINGS_PAYOUT_MAX] = ""
token_t s_token [POS_CHAIN__COUNT]
const token_cfg_t TOKEN_CFG []
const size_t TOKEN_CFG_COUNT = sizeof(TOKEN_CFG) / sizeof(TOKEN_CFG[0])
pos_addr_t s_dest
bool s_payout_bad [2] = { false, false }
pos_addr_t s_tron_dest
sale_fee_t s_sale_fee
inflight_t s_inflight

Detailed Description

What a sale is paid with and to, and the sale between broadcast and verdict.

Definition in file pay.cpp.

Function Documentation

◆ active_dest()

const pos_addr_t * active_dest ( void )

The reconciled recipient for the chain currently selected.

Definition at line 188 of file pay.cpp.

References chain_is_tron(), s_dest, and s_tron_dest.

Referenced by app_main(), and settle_inflight().

◆ active_token()

token_t * active_token ( pos_chain_t chain)

The selection's token, or NULL for a native coin.

Definition at line 45 of file pay.cpp.

References pos_asset_t::native, pos_asset_of(), POS_CHAIN__COUNT, and s_token.

Referenced by app_main(), evm_balance_ok(), pay_sign_and_broadcast(), sale_fee_text(), sign_and_broadcast(), token_decimals_ok(), and ui_refresh_addresses_for().

◆ inflight_persist()

void inflight_persist ( const inflight_t * fl)

Write the sale to NVS just before it leaves the terminal.

So a brownout or panic during the receipt poll does not lose whether the customer paid. Written as "broadcast not known": a record that survives a reset is by definition one whose answer nobody saw. One write per sale.

Definition at line 228 of file pay.cpp.

References inflight_t::active, inflight_t::broadcast_known, and settings_inflight_save().

Referenced by sign_and_broadcast(), and sign_and_broadcast_tron().

◆ pay_sign_and_broadcast()

bcast_t pay_sign_and_broadcast ( CryptnoxWallet & wallet,
Pn532NfcTransport & transport,
CW_CryptoProvider & crypto,
const pos_amount_t * amount,
const char * pin,
size_t pin_chars,
inflight_t * fl,
char * err_out,
size_t err_max )

Sign and broadcast the reconciled sale on whichever family is selected. The family is read once, here.

Definition at line 347 of file pay.cpp.

References active_token(), BCAST_FAILED, chain_is_tron(), s_dest, s_tron_dest, settings_get_chain(), sign_and_broadcast(), sign_and_broadcast_tron(), and token_decimals_ok().

Referenced by app_main().

◆ sale_fee_text()

void sale_fee_text ( char * out,
size_t n )

The most network fee the customer's card can be charged on top of the sale, for the confirm screen. "" where there is no cap to state: a native TRX transfer burns bandwidth, not a fee limit.

Definition at line 201 of file pay.cpp.

References active_token(), chain_is_native_evm(), chain_is_polygon(), chain_is_tron(), fmt_coin(), GAS_LIMIT_NATIVE, s_sale_fee, and TRON_TRC20_FEE_LIMIT_SUN.

Referenced by app_main().

◆ settle_inflight()

void settle_inflight ( void )

Poll the in-flight sale for up to 120 s and show what the chain says.

Only three answers end a sale: mined and ours (Approved), mined and reverted (nothing moved), or — Tron only — expired without ever being included (nothing can ever move). Everything else, including a receipt that does not match the transfer and a broadcast whose answer was lost, is Unconfirmed: the screen keeps the hash, offers Check again, and never says Declined, because a declined sale is one the merchant charges a second time.

Definition at line 255 of file pay.cpp.

References inflight_t::active, active_dest(), inflight_t::amount, inflight_t::broadcast_known, inflight_t::decided, eth_rpc_get_tx_receipt(), ETH_RPC_RECEIPT_MISMATCH, ETH_RPC_RECEIPT_PENDING, ETH_RPC_RECEIPT_REVERTED, ETH_RPC_RECEIPT_SUCCESS, eth_rpc_select_for(), inflight_t::expiration_ms, expired(), inflight_t::hash, IS_TRUE32, inflight_t::payee, inflight_t::polygon, pos_handle_anomaly(), POS_VERDICT_APPROVED, POS_VERDICT_DECLINED, run_payment_decision(), s_inflight, settings_inflight_clear(), TAG, inflight_t::to, inflight_t::token, inflight_t::tron, tron_receipt_as_eth(), tron_rpc_get_receipt(), ui_set_tx_info(), ui_show_tx_status(), UI_TX_STATE_CONFIRMING, UI_TX_STATE_DONE, UI_TX_STATE_FAILED, UI_TX_STATE_UNCONFIRMED, wall_ms(), and wdt_feed().

Referenced by app_main().

◆ token_decimals_ok()

bool token_decimals_ok ( pos_chain_t chain,
char * err,
size_t err_max )

Before the first sale in an operator-set token, read its decimals() and refuse anything but 6.

Every amount is signed in 6-decimal base units, so an 18-decimal contract would be charged 10^-12 of the figure on the screen. Checked here rather than when the contract is proposed: the config page runs with the station down, so no node can be asked then. A read that fails refuses the sale too, and the next sale asks again. Once per boot per token.

Returns
true when the token may be charged in.

Definition at line 115 of file pay.cpp.

References active_token(), pos_addr_t::addr, token_t::addr, token_t::checked, ETH_ADDR_LEN, eth_rpc_get_token_decimals(), eth_rpc_select(), eth_rpc_select_for(), pos_chain_is_polygon(), pos_chain_is_tron(), token_t::str, TAG, TRON_ADDR_HEX_LEN, tron_addr_to_hex(), and tron_rpc_get_trc20_decimals().

Referenced by app_main(), and pay_sign_and_broadcast().

◆ token_load()

void token_load ( const token_cfg_t * cfg,
CW_CryptoProvider & crypto )

Load one token at boot: the operator's contract if one is set and parses, config.h otherwise.

Non-fatal by design: a placeholder or a typo leaves ok false and that one asset is refused when selected, rather than stopping a terminal that charges in something else from booting.

Definition at line 84 of file pay.cpp.

References token_cfg_t::chain, token_t::checked, token_cfg_t::main, token_cfg_t::name, pos_asset_t::net, pos_asset_of(), pos_chain_is_tron(), pos_net_info(), s_token, settings_get_contract(), settings_net_str(), token_t::str, TAG, token_cfg_t::test, pos_asset_t::ticker, and token_parse().

Referenced by pos_boot().

◆ token_parse()

bool token_parse ( token_t * t,
bool tron,
CW_CryptoProvider & crypto )
static

Parse t->str into its dual store, twice and independently.

EVM: eth_addr_parse, which also runs the EIP-55 checksum. Tron: base58check, decoded twice by the SDK, so a mistyped contract is refused here rather than charged against the wrong asset.

Definition at line 57 of file pay.cpp.

References pos_addr_t::addr, token_t::addr, pos_addr_t::addr_echo, ETH_ADDR_LEN, eth_addr_parse(), token_t::ok, and token_t::str.

Referenced by token_load().

◆ ui_refresh_addresses()

void ui_refresh_addresses ( void )

Implemented by main: repoint those two rows at the selected chain.

The asset picker switches the chain on the UI task and rebuilds the page immediately, so it asks for the new pair here rather than posting an event and racing its own redraw. main owns the per-chain contract and payout strings; this only reads them.

Definition at line 170 of file pay.cpp.

References settings_get_chain(), and ui_refresh_addresses_for().

Referenced by app_main(), btn_event_cb(), and pos_boot().

◆ ui_refresh_addresses_for()

void ui_refresh_addresses_for ( uint8_t chain)

Point the UI's address rows at the selected chain.

Same, for any chain (a pos_chain_t) rather than the one sales use.

Called on every entry to the confirm screen and from the asset picker, since the chain can be switched while this task is parked on its queue (see ui.h).

Point the UI's address rows at the selected chain.

The admin Tx tab browses another asset's contract and payout without switching what the terminal charges in.

Definition at line 155 of file pay.cpp.

References active_token(), pos_chain_is_polygon(), pos_chain_is_tron(), s_payout_eth, s_payout_tron, token_t::str, and ui_set_addresses().

Referenced by build_settings(), and ui_refresh_addresses().

◆ wall_ms()

uint64_t wall_ms ( void )

Unix time in ms, 0 while the clock is unset.

Definition at line 237 of file pay.cpp.

Referenced by app_main(), and settle_inflight().

Variable Documentation

◆ ETH_DERIVE_PATH

const uint8_t ETH_DERIVE_PATH[20]
Initial value:
= {
0x80U, 0x00U, 0x00U, 0x2CU,
0x80U, 0x00U, 0x00U, 0x3CU,
0x80U, 0x00U, 0x00U, 0x00U,
0x00U, 0x00U, 0x00U, 0x00U,
0x00U, 0x00U, 0x00U, 0x00U,
}

Definition at line 16 of file pay.cpp.

Referenced by card_read_payouts(), and sign_and_broadcast().

◆ s_dest

pos_addr_t s_dest

Definition at line 177 of file pay.cpp.

Referenced by active_dest(), pay_sign_and_broadcast(), and resolve_evm_payout().

◆ s_inflight

inflight_t s_inflight

Definition at line 219 of file pay.cpp.

Referenced by app_main(), and settle_inflight().

◆ s_payout_bad

bool s_payout_bad[2] = { false, false }

Definition at line 182 of file pay.cpp.

Referenced by app_main(), and pos_boot().

◆ s_payout_eth

char s_payout_eth[SETTINGS_PAYOUT_MAX] = ""

Definition at line 27 of file pay.cpp.

Referenced by app_main(), pos_boot(), resolve_evm_payout(), and ui_refresh_addresses_for().

◆ s_payout_tron

char s_payout_tron[SETTINGS_PAYOUT_MAX] = ""

Definition at line 28 of file pay.cpp.

Referenced by app_main(), pos_boot(), and ui_refresh_addresses_for().

◆ s_sale_fee

sale_fee_t s_sale_fee

Definition at line 192 of file pay.cpp.

Referenced by app_main(), evm_balance_ok(), sale_fee_text(), and sign_and_broadcast().

◆ s_token

◆ s_tron_dest

pos_addr_t s_tron_dest

Definition at line 185 of file pay.cpp.

Referenced by active_dest(), pay_sign_and_broadcast(), and pos_boot().

◆ TOKEN_CFG

const token_cfg_t TOKEN_CFG[]
Initial value:
= {
{ POS_CHAIN_ETH_USDC, ADDR_USDC, ADDR_USDC_MAIN, "ADDR_USDC" },
}
#define TRON_ADDR_USDC_MAIN
#define ADDR_USDT
#define TRON_ADDR_USDT
#define ADDR_USDT_MAIN
#define TRON_ADDR_USDC
#define POLY_ADDR_USDT
#define ADDR_USDC_MAIN
#define POLY_ADDR_USDC_MAIN
#define POLY_ADDR_USDT_MAIN
#define POLY_ADDR_USDC
#define TRON_ADDR_USDT_MAIN
@ POS_CHAIN_POLY_USDT
Definition settings.h:39
@ POS_CHAIN_POLY_USDC
Definition settings.h:38
@ POS_CHAIN_ETH_USDC
Definition settings.h:34
@ POS_CHAIN_TRON_USDT
Definition settings.h:36
@ POS_CHAIN_TRON_USDC
Definition settings.h:40
@ POS_CHAIN_ETH_USDT
Definition settings.h:37

Definition at line 32 of file pay.cpp.

Referenced by pos_boot().

◆ TOKEN_CFG_COUNT

const size_t TOKEN_CFG_COUNT = sizeof(TOKEN_CFG) / sizeof(TOKEN_CFG[0])

Definition at line 41 of file pay.cpp.

Referenced by pos_boot().