24#include "freertos/FreeRTOS.h"
25#include "freertos/task.h"
26#include "freertos/queue.h"
27#include "driver/spi_master.h"
28#include "driver/gpio.h"
30#include "esp_heap_caps.h"
32#include "esp_system.h"
36#include "CryptnoxWallet.h"
38#include "Pn532NfcTransport.h"
39#include "ESP32Logger.h"
40#include "ESP32Platform.h"
41#include "esp32_crypto_provider.h"
69static const char *
const TAG =
"cryptnox_pos";
183 const char *pin,
size_t pin_chars,
inflight_t *fl,
184 char *err_out,
size_t err_max);
190void evm_fees_wei(
bool polygon, uint64_t *max_fee, uint64_t *prio_fee);
194 const char *pin,
size_t pin_chars,
inflight_t *fl,
195 char *err_out,
size_t err_max);
203 const char *pin,
size_t pin_chars,
inflight_t *fl,
204 char *err_out,
size_t err_max);
225const char *
pin_fail_text(Pn532NfcTransport &transport,
const char *wrong);
226bool card_connect(CryptnoxWallet &wallet, Pn532NfcTransport &transport,
227 CW_SecureSession &session,
bool setup =
false);
228bool card_sign(CryptnoxWallet &wallet, CW_SecureSession &session,
229 const uint8_t *hash, uint8_t hash_len,
230 const uint8_t *path, uint8_t path_len,
231 const char *pin,
size_t pin_chars,
232 uint8_t rs_out[64],
char *err_out,
size_t err_max);
234 CW_CryptoProvider &crypto,
const char *pin,
size_t pin_chars,
235 char *eth_out,
size_t eth_n,
char *tron_out,
size_t tron_n,
236 char *err,
size_t err_n);
267bool run_wizard(CryptnoxWallet &wallet, Pn532NfcTransport &transport,
268 CW_CryptoProvider &crypto,
bool wifi_only);
What each selectable asset IS — one row per pos_chain_t.
static bool pos_chain_is_native_evm(pos_chain_t c)
true for ETH and POL: no contract, the amount goes in value, 21000 gas, 18 decimals....
static bool pos_chain_is_tron(pos_chain_t c)
true for the Tron selections; every other one is EVM.
static bool pos_chain_is_polygon(pos_chain_t c)
true for the Polygon selections. EVM like Ethereum, but its own endpoint, chain id and contracts.
const char *const NOTE_NO_TIME
const char *const NOTE_JOIN_FAILED
const char * s_card_fault
What a tapped card is missing, read from its SELECT response.
config.h, plus a default for every key added after the first config.h files shipped — so an older con...
Hex Ethereum-address parsing — a pure, dependency-free unit so it can be unit-tested and fuzzed on th...
#define ETH_ADDR_LEN
Length of a raw (binary) Ethereum address, in bytes.
Minimal RLP encoder for EIP-1559 (type 2) Ethereum transactions.
static const char *const TAG
Ethereum JSON-RPC client over HTTPS (nonce / ecrecover parity / raw-tx broadcast / receipt polling)....
eth_rpc_receipt_result_t
Outcome of one eth_getTransactionReceipt poll.
The recovery bit of a secp256k1 signature, computed on the device.
Decision-integrity primitives (see docs/HARDENING.md §3, §4).
Original Keccak-256 digest as used by Ethereum.
std::atomic< bool > s_user_cancelled
The sale's arithmetic: keypad cents, base units, wei, fees, calldata.
Network bring-up: Wi-Fi station (init/scan/connect/RSSI) and SNTP time sync. No application-protocol ...
Firmware slot handling: receive an image into the idle slot, verify it, and install it only once some...
Dotted version comparison, for deciding whether an update goes forwards or backwards.
const token_cfg_t TOKEN_CFG[]
char s_payout_tron[SETTINGS_PAYOUT_MAX]
const size_t TOKEN_CFG_COUNT
const uint8_t ETH_DERIVE_PATH[20]
char s_payout_eth[SETTINGS_PAYOUT_MAX]
token_t s_token[POS_CHAIN__COUNT]
bool run_wizard(CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_CryptoProvider &crypto, bool wifi_only)
Run the browser wizard until the operator presses Finish.
bool card_sign(CryptnoxWallet &wallet, CW_SecureSession &session, const uint8_t *hash, uint8_t hash_len, const uint8_t *path, uint8_t path_len, const char *pin, size_t pin_chars, uint8_t rs_out[64], char *err_out, size_t err_max)
Have the card sign hash, then close the session.
static bool chain_is_tron(void)
true when the operator has switched the terminal to Tron.
void eth_rpc_select_for(bool polygon)
Point eth_rpc at the endpoint for the selected EVM network.
eth_rpc_receipt_result_t tron_receipt_as_eth(tron_receipt_t r)
Map a Tron receipt onto the Ethereum verdicts the UI flow uses.
void token_load(const token_cfg_t *cfg, CW_CryptoProvider &crypto)
Load one token at boot: the operator's contract if one is set and parses, config.h otherwise.
bool evm_balance_ok(const pos_amount_t *amount, char *err, size_t err_max)
Refuse an EVM sale the tapped card cannot fund, before it signs.
void eth_rpc_select(void)
uint64_t wall_ms(void)
Unix time in ms, 0 while the clock is unset.
bool card_read_payouts(CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_CryptoProvider &crypto, const char *pin, size_t pin_chars, char *eth_out, size_t eth_n, char *tron_out, size_t tron_n, char *err, size_t err_n)
Read the card's payout addresses and put them through the panel.
bcast_t sign_and_broadcast_tron(CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_CryptoProvider &crypto, const pos_amount_t *amount, const pos_addr_t *to, const token_t *token, const char *pin, size_t pin_chars, inflight_t *fl, char *err_out, size_t err_max)
Sign a Tron transfer on the card and broadcast it — TRX or TRC-20.
pos_hw_t pos_boot(void)
Everything before the main loop. Returns the card stack, which lives for the life of the program.
bool token_decimals_ok(pos_chain_t chain, char *err, size_t err_max)
Before the first sale in an operator-set token, read its decimals() and refuse anything but 6.
token_t * active_token(pos_chain_t chain=settings_get_chain())
The selection's token, or NULL for a native coin.
bcast_t sign_and_broadcast(CryptnoxWallet &wallet, Pn532NfcTransport &transport, const pos_amount_t *amount, const pos_addr_t *to, const char *pin, size_t pin_chars, inflight_t *fl, char *err_out, size_t err_max)
Sign an EVM token or coin transfer on the card and broadcast it.
bcast_t pay_sign_and_broadcast(CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_CryptoProvider &crypto, const pos_amount_t *amount, const char *pin, size_t pin_chars, inflight_t *fl, char *err_out, size_t err_max)
Sign and broadcast the reconciled sale on whichever family is selected. The family is read once,...
void evm_fees_wei(bool polygon, uint64_t *max_fee, uint64_t *prio_fee)
The EIP-1559 fees one EVM sale will offer, in wei per gas.
bool card_connect(CryptnoxWallet &wallet, Pn532NfcTransport &transport, CW_SecureSession &session, bool setup=false)
Wait for a card and open a secure channel, cancellable from the UI.
void sale_fee_text(char *out, size_t n)
The most network fee the customer's card can be charged on top of the sale, for the confirm screen....
void wifi_keep_or_drop(bool keep)
Persist or discard the pending picker credentials, then scrub them.
void boot_fault(ui_boot_err_t kind, const char *detail)
Show a startup fault, then restart. Does not return.
void settle_inflight(void)
Poll the in-flight sale for up to 120 s and show what the chain says.
void inflight_persist(const inflight_t *fl)
Write the sale to NVS just before it leaves the terminal.
const pos_addr_t * active_dest(void)
The reconciled recipient for the chain currently selected.
static bool chain_is_polygon(void)
true when the terminal is charging on Polygon rather than Ethereum.
void tron_addr_to_hex(const uint8_t *addr21, char *out, size_t n)
Format a raw 21-byte Tron address as the "41..." hex the API wants.
static bool chain_is_native_evm(void)
true when charging in the network's own coin (ETH / POL), not a token.
void wait_for_ui_event(ui_event_t want)
Block until the UI reports want, discarding anything else.
bool sync_time(void)
Block on an SNTP sync so TLS certificate validity-period checks run against real time instead of the ...
bool wifi_picker(const char *note)
Run the panel network picker (scan → list → keyboard → connect) until connected.
const char * pin_fail_text(Pn532NfcTransport &transport, const char *wrong)
Why verifyPin said no: the PIN, or the card leaving the field.
void ui_event_dispatch(ui_event_t event, uint64_t payload)
UI-task callback: forward a touch event to the main task queue.
bool wifi_try_saved(void)
Try the saved credentials, staying on the splash while it happens.
The config portal: one web app for setting a terminal up and for administering it afterwards,...
Turn a node's JSON-RPC refusal into a line an operator can act on.
pos_chain_t settings_get_chain(void)
Selected chain, or POS_CHAIN_ETH_USDC if never set.
Persistent device settings stored in NVS (backlight, Wi-Fi creds).
pos_chain_t
Which chain (and therefore which asset) the terminal charges in.
#define SETTINGS_PAYOUT_MAX
Longest payout address plus NUL — "0x" + 40 hex, or 34 base58 Tron.
WipeGuard & operator=(const WipeGuard &)=delete
WipeGuard(uint8_t *b, size_t n)
WipeGuard(const WipeGuard &)=delete
uint8_t payee[ETH_ADDR_LEN]
The card stack pos_boot() brought up; lives for the program.
CW_CryptoProvider & crypto
Pn532NfcTransport & transport
A token's contract, dual-stored.
char str[SETTINGS_PAYOUT_MAX]
Tron HTTP API client (Nile testnet): build a TRX transfer, broadcast it signed, poll its receipt.
tron_receipt_t
Outcome of one gettransactioninfobyid poll.
Tron transaction hex helpers — protobuf varints, the TransferContract integrity check and the signed-...
Touchscreen UI API: screens, events and transaction states for the CYD (ILI9341 + XPT2046) payment fl...
ui_event_t
Events emitted by the UI task towards the main task.
ui_boot_err_t
Startup faults shown on UI_SCREEN_BOOT_ERROR.
Task-watchdog feed that is safe to call from any task.