cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
Loading...
Searching...
No Matches
pay_tron.cpp File Reference

Tron: pre-flight balance, sign and broadcast a TRX or TRC-20 transfer. More...

#include "pos_app.h"
Include dependency graph for pay_tron.cpp:

Go to the source code of this file.

Functions

void tron_addr_to_hex (const uint8_t *addr21, char *out, size_t n)
 Format a raw 21-byte Tron address as the "41..." hex the API wants.
static bool tron_balance_ok (const char *owner_hex, const char *token_hex, uint64_t amount, char *err, size_t err_max)
 Refuse a Tron sale the tapped card cannot fund, before it signs.
bcast_t sign_and_broadcast_tron (CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_CryptoProvider &crypto, const pos_amount_t *amount, const pos_addr_t *to, const token_t *token, const char *pin, size_t pin_chars, inflight_t *fl, char *err_out, size_t err_max)
 Sign a Tron transfer on the card and broadcast it — TRX or TRC-20.
eth_rpc_receipt_result_t tron_receipt_as_eth (tron_receipt_t r)
 Map a Tron receipt onto the Ethereum verdicts the UI flow uses.

Detailed Description

Tron: pre-flight balance, sign and broadcast a TRX or TRC-20 transfer.

The sender is not configured: the card's m/44'/195'/0'/0/0 public key is read over the secure channel at sign time and turned into an address by CW_Tron, so the terminal follows whichever card is presented.

Definition in file pay_tron.cpp.

Function Documentation

◆ sign_and_broadcast_tron()

bcast_t sign_and_broadcast_tron ( CryptnoxWallet & wallet,
Pn532NfcTransport & transport,
CW_CryptoProvider & crypto,
const pos_amount_t * amount,
const pos_addr_t * to,
const token_t * token,
const char * pin,
size_t pin_chars,
inflight_t * fl,
char * err_out,
size_t err_max )

Sign a Tron transfer on the card and broadcast it — TRX or TRC-20.

Same shape as sign_and_broadcast, but Tron has no RLP and no local nonce: the full node serialises the transaction and we sign its txID. What the node returns is therefore verified before the card ever sees the hash (see tron_rpc.h), and the recipient handed to the node is derived from the dual-stored to right after the reconcile, never from a config literal.

TRX and TRC-20 differ only in which transaction the node builds, so they share one function and the security checks cannot drift apart.

Parameters
[in]walletInitialised wallet instance.
[in]transportPN532 transport (cancellable connect loop).
[in]amountDual-stored amount, 6 decimals — sun for TRX, token base units for TRC-20.
[in]toDual-stored recipient (20-byte key hash).
[in]tokenToken to charge in, or NULL for native TRX.
[in]pinOperator-entered card PIN (scrubbed after signing).
[in]pin_charsNumber of PIN characters in pin.
[out]flFilled once built: the txID and its expiration.
[out]err_outShort UI-facing error message on failure.
[in]err_maxCapacity of err_out.
Returns
BCAST_SENT, BCAST_UNKNOWN (broadcast not confirmed — poll fl until it expires), or BCAST_FAILED on refusal or user cancel.

Definition at line 125 of file pay_tron.cpp.

References pos_addr_t::addr, token_t::addr, address_consistent(), amount_consistent(), pos_amount_t::amount_minor, BCAST_FAILED, BCAST_SENT, BCAST_UNKNOWN, card_connect(), card_sign(), ETH_ADDR_LEN, inflight_t::expiration_ms, tron_tx_ctx_t::expiration_ms, inflight_t::hash, inflight_persist(), IS_TRUE32, token_t::ok, pin_fail_text(), pos_handle_anomaly(), s_card_fault, s_user_cancelled, TAG, inflight_t::tron, TRON_ADDR_HEX_LEN, tron_addr_to_hex(), tron_balance_ok(), tron_rpc_broadcast(), tron_rpc_create_transfer(), tron_rpc_create_trc20_transfer(), TRON_TRC20_FEE_LIMIT_SUN, tron_tx_ctx_t::txid, tron_tx_ctx_t::txid_hex, ui_show_tx_status(), UI_TX_STATE_SENDING, and UI_TX_STATE_SIGNING.

Referenced by pay_sign_and_broadcast().

◆ tron_addr_to_hex()

void tron_addr_to_hex ( const uint8_t * addr21,
char * out,
size_t n )

Format a raw 21-byte Tron address as the "41..." hex the API wants.

Parameters
[in]addr2121-byte address (0x41 prefix included).
[out]outTRON_ADDR_HEX_LEN chars + NUL.
[in]nCapacity of out.

Definition at line 25 of file pay_tron.cpp.

References TRON_ADDR_HEX_LEN.

Referenced by sign_and_broadcast_tron(), and token_decimals_ok().

◆ tron_balance_ok()

bool tron_balance_ok ( const char * owner_hex,
const char * token_hex,
uint64_t amount,
char * err,
size_t err_max )
static

Refuse a Tron sale the tapped card cannot fund, before it signs.

The Tron half of evm_balance_ok, run once the card is read and its PIN verified, before signing. Matters mostly for TRC-20: the node builds a TriggerSmartContract regardless of balance, so an underfunded one would be signed, broadcast, reverted and charged for.

A read that fails is not a refusal, as on the EVM side.

Parameters
[in]owner_hexThe tapped card's address, "41"-prefixed hex.
[in]token_hexToken contract, same form; NULL/empty for native TRX.
[in]amountSale amount — sun for TRX, base units for a token.
[out]errPanel-facing reason on refusal; untouched otherwise.
[in]err_maxCapacity of err.
Returns
true to let the sale proceed (funded, or unknowable).

Definition at line 51 of file pay_tron.cpp.

References pos_asset_of(), settings_get_chain(), TAG, tron_rpc_get_balance(), tron_rpc_get_energy(), and tron_rpc_get_trc20_balance().

Referenced by sign_and_broadcast_tron().

◆ tron_receipt_as_eth()

eth_rpc_receipt_result_t tron_receipt_as_eth ( tron_receipt_t r)

Map a Tron receipt onto the Ethereum verdicts the UI flow uses.

Definition at line 309 of file pay_tron.cpp.

References ETH_RPC_RECEIPT_PENDING, ETH_RPC_RECEIPT_REVERTED, ETH_RPC_RECEIPT_RPC_ERROR, ETH_RPC_RECEIPT_SUCCESS, TRON_RECEIPT_FAILED, TRON_RECEIPT_PENDING, and TRON_RECEIPT_SUCCESS.

Referenced by settle_inflight().