cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
Loading...
Searching...
No Matches
pay_evm.cpp File Reference

Ethereum and Polygon: endpoint, fees, pre-flight balance, sign and broadcast an EIP-1559 transfer. More...

#include "pos_app.h"
Include dependency graph for pay_evm.cpp:

Go to the source code of this file.

Macros

#define TX_BUF_SIZE   300U

Functions

void eth_rpc_select_for (bool polygon)
 Point eth_rpc at the endpoint for the selected EVM network.
void eth_rpc_select (void)
void evm_fees_wei (bool polygon, uint64_t *max_fee, uint64_t *prio_fee)
 The EIP-1559 fees one EVM sale will offer, in wei per gas.
bool evm_balance_ok (const pos_amount_t *amount, char *err, size_t err_max)
 Refuse an EVM sale the tapped card cannot fund, before it signs.
bcast_t sign_and_broadcast (CryptnoxWallet &wallet, Pn532NfcTransport &transport, const pos_amount_t *amount, const pos_addr_t *to, const char *pin, size_t pin_chars, inflight_t *fl, char *err_out, size_t err_max)
 Sign an EVM token or coin transfer on the card and broadcast it.

Detailed Description

Ethereum and Polygon: endpoint, fees, pre-flight balance, sign and broadcast an EIP-1559 transfer.

Definition in file pay_evm.cpp.

Macro Definition Documentation

◆ TX_BUF_SIZE

#define TX_BUF_SIZE   300U

Definition at line 16 of file pay_evm.cpp.

Referenced by sign_and_broadcast().

Function Documentation

◆ eth_rpc_select()

void eth_rpc_select ( void )

Definition at line 51 of file pay_evm.cpp.

References chain_is_polygon(), and eth_rpc_select_for().

Referenced by pos_boot(), sign_and_broadcast(), and token_decimals_ok().

◆ eth_rpc_select_for()

void eth_rpc_select_for ( bool polygon)

Point eth_rpc at the endpoint for the selected EVM network.

Called at boot and at the top of every payment, since the network can change between sales. URL, credentials and pinned cert are separate statics in eth_rpc, so all three are re-applied each time (a stale cert or auth from the other network shows up as an unexplained TLS failure).

Definition at line 26 of file pay_evm.cpp.

References eth_rpc_init(), eth_rpc_set_auth(), eth_rpc_set_ca_cert(), POLY_RPC_URL, POLY_RPC_URL_MAIN, RPC_URL_MAIN, and settings_net_str().

Referenced by eth_rpc_select(), settle_inflight(), and token_decimals_ok().

◆ evm_balance_ok()

bool evm_balance_ok ( const pos_amount_t * amount,
char * err,
size_t err_max )

Refuse an EVM sale the tapped card cannot fund, before it signs.

Otherwise an underfunded token transfer is broadcast, mined, reverted and charged gas, and a short coin balance is refused only after signing.

The caller must have selected the endpoint and set the payer first. This does not call eth_rpc_select: that resets the from-address to config.h and would check the integrator's account instead of the tapped card.

A failed read is NOT a refusal: this improves a message, it does not gate payments.

Parameters
[in]amountThe reconciled sale amount, in keypad base units.
[out]errPanel-facing reason on refusal; untouched otherwise.
[in]err_maxCapacity of err.
Returns
true to let the sale proceed (funded, or unknowable).

Definition at line 91 of file pay_evm.cpp.

References active_token(), pos_amount_t::amount_minor, chain_is_native_evm(), chain_is_polygon(), eth_rpc_get_balance(), eth_rpc_get_token_balance(), evm_funds_check(), EVM_FUNDS_SHORT_GAS, EVM_FUNDS_SHORT_VALUE, GAS_LIMIT_NATIVE, pos_asset_of(), s_sale_fee, settings_get_chain(), token_t::str, and TAG.

Referenced by sign_and_broadcast().

◆ evm_fees_wei()

void evm_fees_wei ( bool polygon,
uint64_t * max_fee,
uint64_t * prio_fee )

The EIP-1559 fees one EVM sale will offer, in wei per gas.

One function so the signed transaction and the pre-flight check agree: a check against a cheaper fee than the tx carries would pass the very sale it exists to catch.

Parameters
[in]polygontrue on Polygon, which has a tip floor of its own.
[out]max_feeFee cap, wei per gas.
[out]prio_feeTip, wei per gas; never above max_fee.

Definition at line 64 of file pay_evm.cpp.

References evm_fees_from_gwei(), POLY_MIN_PRIORITY_FEE_GWEI, settings_get_max_fee_gwei(), and settings_get_priority_fee_gwei().

Referenced by app_main().

◆ sign_and_broadcast()

bcast_t sign_and_broadcast ( CryptnoxWallet & wallet,
Pn532NfcTransport & transport,
const pos_amount_t * amount,
const pos_addr_t * to,
const char * pin,
size_t pin_chars,
inflight_t * fl,
char * err_out,
size_t err_max )

Sign an EVM token or coin transfer on the card and broadcast it.

Pipeline: reconcile → calldata → card connect + PIN → payer address → balance → nonce → RLP + keccak256 → reconcile → sign (cancellable) → local parity check → broadcast. The PIN is scrubbed with CW_Utils::secure_wipe right after signing; hash, signature and encoded txs via WipeGuard.

Parameters
[in]walletInitialised wallet instance.
[in]transportPN532 transport, used for the cancellable connect loop.
[in]amountReconciled amount, keypad base units (6 decimals).
[in]toReconciled recipient.
[in]pinOperator-entered card PIN (scrubbed after signing).
[in]pin_charsNumber of PIN characters in pin.
[out]flFilled once signed: the locally computed hash and what its receipt must show.
[out]err_outShort UI-facing error message on failure.
[in]err_maxCapacity of err_out.
Returns
BCAST_SENT, BCAST_UNKNOWN (no answer — poll fl), or BCAST_FAILED on refusal or user cancel (err_out is only meaningful when s_user_cancelled is clear).

Definition at line 165 of file pay_evm.cpp.

References active_token(), pos_addr_t::addr, token_t::addr, address_consistent(), inflight_t::amount, amount_consistent(), pos_amount_t::amount_minor, BCAST_FAILED, BCAST_SENT, BCAST_UNKNOWN, build_usdc_calldata(), eth_tx_t::calldata, eth_tx_t::calldata_len, card_connect(), card_sign(), eth_tx_t::chain_id, CHAIN_ID_AMOY, CHAIN_ID_MAINNET, CHAIN_ID_POLYGON, chain_is_native_evm(), chain_is_polygon(), eth_addr_format(), ETH_ADDR_LEN, ETH_DERIVE_PATH, eth_rlp_encode_signed(), eth_rlp_encode_unsigned(), eth_rpc_err_already_known(), eth_rpc_get_nonce(), eth_rpc_select(), eth_rpc_send_raw_tx(), eth_rpc_set_from(), eth_sig_parity(), eth_tx_t::eth_value, evm_balance_ok(), evm_units_to_wei(), eth_tx_t::gas_limit, GAS_LIMIT_NATIVE, inflight_t::hash, inflight_persist(), IS_TRUE32, keccak256(), eth_tx_t::max_fee, eth_tx_t::max_priority_fee, eth_tx_t::nonce, token_t::ok, inflight_t::payee, pin_fail_text(), inflight_t::polygon, pos_handle_anomaly(), rpc_error_text(), s_card_fault, s_sale_fee, s_user_cancelled, settings_get_mainnet(), SETTINGS_PAYOUT_MAX, TAG, eth_tx_t::to, inflight_t::to, inflight_t::token, inflight_t::tron, TX_BUF_SIZE, ui_set_tx_info(), ui_show_tx_status(), UI_TX_STATE_SENDING, UI_TX_STATE_SIGNING, and USDC_CALLDATA_LEN.

Referenced by pay_sign_and_broadcast().