|
cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
|
Persistent device settings stored in NVS (backlight, Wi-Fi creds). More...
#include <stdint.h>#include <stdbool.h>#include <stddef.h>Go to the source code of this file.
Macros | |
| #define | POS_AMOUNT_UNITS_MAX_NATIVE 18446744ULL |
| Ceiling on a native-coin sale, in the keypad's 6-decimal base units. | |
| #define | TZ_OFFSET_MIN (-720) |
| Widest real-world UTC offsets, in minutes: UTC-12:00 to UTC+14:00. | |
| #define | TZ_OFFSET_MAX (840) |
| #define | SETTINGS_PAYOUT_MAX 64U |
| Longest payout address plus NUL — "0x" + 40 hex, or 34 base58 Tron. | |
Enumerations | |
| enum | pos_chain_t { POS_CHAIN_ETH_USDC = 0 , POS_CHAIN_TRON_TRX = 1 , POS_CHAIN_TRON_USDT = 2 , POS_CHAIN_ETH_USDT = 3 , POS_CHAIN_POLY_USDC = 4 , POS_CHAIN_POLY_USDT = 5 , POS_CHAIN_TRON_USDC = 6 , POS_CHAIN_ETH_NATIVE = 7 , POS_CHAIN_POLY_NATIVE = 8 , POS_CHAIN__COUNT } |
| Which chain (and therefore which asset) the terminal charges in. More... | |
Functions | |
| pos_chain_t | settings_get_chain (void) |
| Selected chain, or POS_CHAIN_ETH_USDC if never set. | |
| void | settings_set_chain (pos_chain_t chain) |
| Persist the selected chain. | |
| bool | settings_get_mainnet (void) |
| true when the terminal is on the production networks. | |
| void | settings_set_mainnet (bool mainnet) |
| Persist the production/test network choice. | |
| const char * | settings_net_str (const char *testnet, const char *mainnet) |
| Pick the string belonging to the network the terminal is on. | |
| int16_t | settings_get_tz_offset_min (void) |
| The panel clock's standard (winter) offset from UTC, in minutes east. | |
| bool | settings_set_tz_offset_min (int16_t minutes) |
| Store the panel clock's UTC offset. | |
| uint8_t | settings_get_tz_dst (void) |
| The clock's DST rule, a civil_dst_t; CIVIL_DST_NONE when unset. | |
| bool | settings_set_tz_dst (uint8_t rule) |
| Store the DST rule. | |
| uint8_t | settings_get_brightness (void) |
| Backlight level in percent, or 80 if never set. | |
| void | settings_set_brightness (uint8_t pct) |
| Persist the backlight level (0..100). | |
| void | settings_get_touch_cal (uint16_t *x_min, uint16_t *x_max, uint16_t *y_min, uint16_t *y_max) |
| Raw XPT2046 range that maps to the panel's four edges. | |
| void | settings_set_touch_cal (uint16_t x_min, uint16_t x_max, uint16_t y_min, uint16_t y_max) |
| Persist a calibration. Rejected (and ignored) if an axis is inverted or collapsed — a bad store here makes the panel untappable, including the screen that would fix it. | |
| bool | settings_has_wifi (void) |
| true if a Wi-Fi SSID has been stored. | |
| bool | settings_get_wifi (char *ssid, size_t ssid_n, char *pass, size_t pass_n) |
| Read the stored Wi-Fi credentials. | |
| void | settings_set_wifi (const char *ssid, const char *pass) |
| Persist Wi-Fi credentials (plaintext — see README threat model). | |
| bool | settings_has_admin_code (void) |
| true once an admin code exists. | |
| bool | settings_set_admin_code (const char *code) |
| Store a new admin code, with a fresh random salt. | |
| bool | settings_check_admin_code (const char *code) |
| Check a candidate code, maintaining the failure counter. | |
| uint8_t | settings_admin_fail_count (void) |
| Consecutive failed unlock attempts, persisted. | |
| uint32_t | settings_get_max_fee_gwei (void) |
| EIP-1559 max fee per gas, in Gwei. | |
| uint32_t | settings_get_priority_fee_gwei (void) |
| EIP-1559 max priority fee (tip) per gas, in Gwei. | |
| bool | settings_set_fees_gwei (uint32_t max_gwei, uint32_t prio_gwei) |
| Persist the max fee and the tip per gas (Gwei), as a pair. | |
| bool | settings_get_payout (bool tron, char *out, size_t n) |
| Read the payout address for a network. | |
| bool | settings_has_payout (bool tron) |
| Whether an operator has actually set the payout address for a network. | |
| bool | settings_set_payout (bool tron, const char *addr) |
| Persist a payout address, writing both the value and its echo copy. | |
| bool | settings_get_contract (pos_chain_t chain, char *out, size_t n) |
| Read the token-contract address for a network. | |
| bool | settings_set_contract (pos_chain_t chain, const char *addr) |
| Persist a token-contract address, value and echo copy. | |
| void | settings_factory_reset (void) |
| Erase all stored settings (brightness, auto, Wi-Fi creds, fees). | |
| bool | settings_inflight_save (const void *rec, size_t n) |
| Persist the sale between broadcast and verdict (opaque record). | |
| bool | settings_inflight_load (void *rec, size_t n) |
Read the persisted sale back. false if none, or not n bytes. | |
| void | settings_inflight_clear (void) |
| Drop the persisted sale. Writes nothing when there is none. | |
| bool | settings_wipe_if_new_build (void) |
| Erase NVS unless this exact build is the one that wrote it. | |
Persistent device settings stored in NVS (backlight, Wi-Fi creds).
All getters return sensible defaults when nothing has been written. Requires nvs_flash_init() to have run first.
Definition in file settings.h.
| #define POS_AMOUNT_UNITS_MAX_NATIVE 18446744ULL |
Ceiling on a native-coin sale, in the keypad's 6-decimal base units.
ETH and POL are 18-decimal, so wei = units * 10^12, and eth_tx_t::eth_value is a uint64 — 2^64-1 wei is 18.446744073709551615 of the coin. Past that the multiply wraps and the card would sign a value nobody entered, so the keypad stops at 18.44 and the payment path re-checks it.
ponytail: uint64 wei, 18.44 ETH/POL a sale. Widening means carrying eth_value as a 32-byte big-endian buffer through eth_rlp and its two encoders — worth it only if somebody actually needs to charge more.
Definition at line 60 of file settings.h.
Referenced by evm_units_to_wei().
| #define SETTINGS_PAYOUT_MAX 64U |
Longest payout address plus NUL — "0x" + 40 hex, or 34 base58 Tron.
Definition at line 214 of file settings.h.
Referenced by app_main(), build_prov_confirm(), dual_get(), dual_set(), run_wizard(), settings_addr_normalise(), settings_has_payout(), sign_and_broadcast(), state_get(), and value_post().
| #define TZ_OFFSET_MAX (840) |
Definition at line 92 of file settings.h.
Referenced by tz_offset_decode(), and tz_offset_valid().
| #define TZ_OFFSET_MIN (-720) |
Widest real-world UTC offsets, in minutes: UTC-12:00 to UTC+14:00.
Definition at line 91 of file settings.h.
Referenced by tz_offset_valid().
| enum pos_chain_t |
Which chain (and therefore which asset) the terminal charges in.
The numbers are persisted in NVS, so existing ones never move; new assets are appended. settings.cpp rejects anything at or past POS_CHAIN__COUNT, so a downgrade falls back to the default rather than guessing what a number meant.
Definition at line 33 of file settings.h.
| uint8_t settings_admin_fail_count | ( | void | ) |
Consecutive failed unlock attempts, persisted.
Kept in NVS so power-cycling does not clear the penalty the UI derives from it.
Definition at line 448 of file settings.cpp.
References K_ADMIN_FAILS, and nvs_u8_get().
Referenced by admin_submit(), open_admin_entry(), settings_check_admin_code(), and ui_show_prov_auth().
| bool settings_check_admin_code | ( | const char * | code | ) |
Check a candidate code, maintaining the failure counter.
| [in] | code | NUL-terminated candidate. |
Definition at line 414 of file settings.cpp.
References admin_derive(), ADMIN_HASH_LEN, ADMIN_SALT_LEN, admin_set_fails(), K_ADMIN_HASH, K_ADMIN_SALT, NS_SETTINGS, ok(), settings_admin_fail_count(), and TAG.
Referenced by admin_submit().
| void settings_factory_reset | ( | void | ) |
Erase all stored settings (brightness, auto, Wi-Fi creds, fees).
Definition at line 619 of file settings.cpp.
References cache_invalidate(), K_BUILD_ID, NS_SETTINGS, and TAG.
Referenced by btn_event_cb().
| uint8_t settings_get_brightness | ( | void | ) |
Backlight level in percent, or 80 if never set.
Definition at line 215 of file settings.cpp.
References DEFAULT_BRIGHTNESS, K_BRIGHTNESS, and nvs_u8_get().
Referenced by ui_task().
| pos_chain_t settings_get_chain | ( | void | ) |
Selected chain, or POS_CHAIN_ETH_USDC if never set.
Definition at line 165 of file settings.cpp.
References K_CHAIN, nvs_u8_get(), POS_CHAIN__COUNT, POS_CHAIN_ETH_USDC, and s_chain_cache.
Referenced by admin_submit(), amount_cents_max(), app_main(), chain_is_native_evm(), chain_is_polygon(), chain_is_tron(), evm_balance_ok(), make_asset_button(), open_admin_entry(), pay_sign_and_broadcast(), tron_balance_ok(), tx_amount_row(), and ui_refresh_addresses().
| bool settings_get_contract | ( | pos_chain_t | chain, |
| char * | out, | ||
| size_t | n ) |
Read the token-contract address for a network.
Same dual store and config.h fallback as settings_get_payout: the contract decides which asset moves, so a half-written NVS string must not redirect it. Only USDC on Ethereum and USDT on Tron are settable; any other chain returns false with out empty.
Stored separately per network (settings_get_mainnet): the same token is a different deployment on each, and one slot would leave a mainnet terminal calling a testnet contract that holds nothing.
| [in] | chain | The token's selection. |
| [out] | out | Buffer, >= SETTINGS_PAYOUT_MAX. Ethereum contracts are returned "0x"-prefixed. |
| [in] | n | Capacity of out. |
chain, nothing) was. Definition at line 549 of file settings.cpp.
References ADDR_USDC_MAIN, dual_get(), K_CT_ETH, K_CT_ETH2, K_CT_ETH_M, K_CT_ETH_M2, K_CT_TRX, K_CT_TRX2, K_CT_TRX_M, K_CT_TRX_M2, POS_CHAIN_ETH_USDC, POS_CHAIN_TRON_USDT, settings_get_mainnet(), TRON_ADDR_USDT, and TRON_ADDR_USDT_MAIN.
Referenced by state_get(), and token_load().
| bool settings_get_mainnet | ( | void | ) |
true when the terminal is on the production networks.
Picks the deployment (Ethereum/Sepolia, Polygon/Amoy, Tron/Nile), not the asset. Defaults to true: a unit coming up on a testnet would report every sale as paid and settle nothing. Endpoints, chain ids and contracts are read once at boot into the dual stores, so settings_set_mainnet takes effect only on a restart, which the caller performs.
Definition at line 189 of file settings.cpp.
References K_MAINNET, nvs_u8_get(), and s_mainnet_cache.
Referenced by add_test_chip(), network_post(), pos_boot(), settings_get_contract(), settings_net_str(), settings_set_contract(), sign_and_broadcast(), and state_get().
| uint32_t settings_get_max_fee_gwei | ( | void | ) |
EIP-1559 max fee per gas, in Gwei.
Definition at line 347 of file settings.cpp.
References DEFAULT_MAX_FEE_GWEI, fee_get(), and K_MAX_FEE.
Referenced by build_settings(), evm_fees_wei(), state_get(), and ui_task().
| bool settings_get_payout | ( | bool | tron, |
| char * | out, | ||
| size_t | n ) |
Read the payout address for a network.
Falls back to the config.h recipient when nothing is stored, so callers always get a parseable address. That fallback is for display and boot-time reasoning only: the payment path checks settings_has_payout first and refuses the sale, because an address nobody chose is somebody else's.
Dual-stored: the NVS value carries an echo copy compared here (the config.h value lives in the signed image and needs none). A mismatch falls back to config.h rather than paying out to a half-written string.
| [in] | tron | true for the Tron payout address, false for Ethereum. |
| [out] | out | Buffer, >= SETTINGS_PAYOUT_MAX. Ethereum addresses are returned "0x"-prefixed, ready to parse. |
| [in] | n | Capacity of out. |
out is valid. Definition at line 525 of file settings.cpp.
References dual_get(), K_PAY_ETH, K_PAY_ETH2, K_PAY_TRX, and K_PAY_TRX2.
Referenced by pos_boot(), resolve_evm_payout(), settings_has_payout(), and state_get().
| uint32_t settings_get_priority_fee_gwei | ( | void | ) |
EIP-1559 max priority fee (tip) per gas, in Gwei.
Definition at line 352 of file settings.cpp.
References DEFAULT_PRIORITY_FEE_GWEI, fee_get(), and K_PRIO_FEE.
Referenced by build_settings(), evm_fees_wei(), state_get(), and ui_task().
| void settings_get_touch_cal | ( | uint16_t * | x_min, |
| uint16_t * | x_max, | ||
| uint16_t * | y_min, | ||
| uint16_t * | y_max ) |
Raw XPT2046 range that maps to the panel's four edges.
Resistive overlays vary unit to unit, so this is stored per device. Defaults to 200..3800, close enough to reach the calibration screen uncalibrated.
Definition at line 260 of file settings.cpp.
References K_TOUCH_X, K_TOUCH_Y, nvs_u32_get(), TOUCH_CAL_DEF_MAX, and TOUCH_CAL_DEF_MIN.
Referenced by touch_cal_load().
| uint8_t settings_get_tz_dst | ( | void | ) |
The clock's DST rule, a civil_dst_t; CIVIL_DST_NONE when unset.
Definition at line 243 of file settings.cpp.
References CIVIL_DST_NONE, K_TZ_DST, nvs_u8_get(), and tz_dst_decode().
Referenced by clock_refresh(), pos_boot(), and state_get().
| int16_t settings_get_tz_offset_min | ( | void | ) |
The panel clock's standard (winter) offset from UTC, in minutes east.
Minutes because half- and quarter-hour zones exist. DST is added on top from settings_get_tz_dst() by civil_time.cpp (newlib's tzset costs 64 KB of flash).
Definition at line 226 of file settings.cpp.
References K_TZ_OFFSET, nvs_u32_get(), TZ_OFFSET_BIAS, and tz_offset_decode().
Referenced by clock_refresh(), pos_boot(), and state_get().
| bool settings_get_wifi | ( | char * | ssid, |
| size_t | ssid_n, | ||
| char * | pass, | ||
| size_t | pass_n ) |
Read the stored Wi-Fi credentials.
| [out] | ssid | Buffer for the SSID (>= 33 bytes recommended). |
| [in] | ssid_n | Capacity of ssid. |
| [out] | pass | Buffer for the password (>= 65 bytes recommended). |
| [in] | pass_n | Capacity of pass. |
Definition at line 298 of file settings.cpp.
References K_WIFI_PASS, K_WIFI_SSID, NS_SETTINGS, and ok().
Referenced by app_main(), build_settings(), state_get(), and wifi_try_saved().
| bool settings_has_admin_code | ( | void | ) |
true once an admin code exists.
Not "configured": an interrupted setup leaves a code and no payout address. Use settings_has_payout for "can this unit take money". Cleared by settings_factory_reset.
Definition at line 372 of file settings.cpp.
References ADMIN_HASH_LEN, K_ADMIN_HASH, and NS_SETTINGS.
Referenced by auth_post(), open_admin_entry(), and pos_boot().
| bool settings_has_payout | ( | bool | tron | ) |
Whether an operator has actually set the payout address for a network.
Decides whether an asset is offered at all: a unit set up for Ethereum only must not offer Tron payments to the compile-time recipient, which is somebody else's address.
Definition at line 534 of file settings.cpp.
References settings_get_payout(), and SETTINGS_PAYOUT_MAX.
Referenced by app_main(), build_settings(), open_network_picker(), pos_boot(), and run_wizard().
| bool settings_has_wifi | ( | void | ) |
true if a Wi-Fi SSID has been stored.
Definition at line 284 of file settings.cpp.
References K_WIFI_SSID, and NS_SETTINGS.
Referenced by pos_boot(), and run_wizard().
| void settings_inflight_clear | ( | void | ) |
Drop the persisted sale. Writes nothing when there is none.
Definition at line 673 of file settings.cpp.
References K_INFLIGHT, and NS_SETTINGS.
Referenced by app_main(), and settle_inflight().
| bool settings_inflight_load | ( | void * | rec, |
| size_t | n ) |
Read the persisted sale back. false if none, or not n bytes.
Definition at line 660 of file settings.cpp.
References K_INFLIGHT, and NS_SETTINGS.
Referenced by app_main().
| bool settings_inflight_save | ( | const void * | rec, |
| size_t | n ) |
Persist the sale between broadcast and verdict (opaque record).
Written just before the transaction leaves the terminal and cleared on the final verdict, so a brownout or panic while polling does not lose whether the customer paid: the next boot resumes polling the same hash. Layout is main.cpp's. Survives a power cut, not a firmware update (see settings_wipe_if_new_build) or a factory reset.
Definition at line 645 of file settings.cpp.
References K_INFLIGHT, NS_SETTINGS, ok(), and TAG.
Referenced by inflight_persist().
| const char * settings_net_str | ( | const char * | testnet, |
| const char * | mainnet ) |
Pick the string belonging to the network the terminal is on.
One place for every config.h testnet/mainnet pair (RPC URLs, contracts, names), so no call site can leave a mainnet sale pointed at a testnet contract.
Definition at line 210 of file settings.cpp.
References settings_get_mainnet().
Referenced by asset_network(), eth_rpc_select_for(), open_network_picker(), pos_boot(), and token_load().
| bool settings_set_admin_code | ( | const char * | code | ) |
Store a new admin code, with a fresh random salt.
Only a salted keccak256 digest is persisted, deliberately not stretched (see settings.cpp). Resets the failure counter.
| [in] | code | NUL-terminated code; the caller wipes its own copy. |
Definition at line 385 of file settings.cpp.
References admin_derive(), ADMIN_HASH_LEN, ADMIN_SALT_LEN, K_ADMIN_FAILS, K_ADMIN_HASH, K_ADMIN_SALT, NS_SETTINGS, ok(), and TAG.
Referenced by admin_submit().
| void settings_set_brightness | ( | uint8_t | pct | ) |
Persist the backlight level (0..100).
Definition at line 220 of file settings.cpp.
References K_BRIGHTNESS, and nvs_u8_set().
Referenced by settings_persist().
| void settings_set_chain | ( | pos_chain_t | chain | ) |
Persist the selected chain.
Definition at line 181 of file settings.cpp.
References K_CHAIN, nvs_u8_set(), and s_chain_cache.
Referenced by btn_event_cb(), and pos_boot().
| bool settings_set_contract | ( | pos_chain_t | chain, |
| const char * | addr ) |
Persist a token-contract address, value and echo copy.
Does not validate — same contract as settings_set_payout: the caller checks the address and has it accepted on the device screen first.
Definition at line 566 of file settings.cpp.
References dual_set(), K_CT_ETH, K_CT_ETH2, K_CT_ETH_M, K_CT_ETH_M2, K_CT_TRX, K_CT_TRX2, K_CT_TRX_M, K_CT_TRX_M2, POS_CHAIN_ETH_USDC, POS_CHAIN_TRON_USDT, and settings_get_mainnet().
Referenced by prov_pending_commit().
| bool settings_set_fees_gwei | ( | uint32_t | max_gwei, |
| uint32_t | prio_gwei ) |
Persist the max fee and the tip per gas (Gwei), as a pair.
fee_pair_check (settings_rules.h) refuses it. Definition at line 357 of file settings.cpp.
References fee_pair_check(), FEE_PAIR_OK, K_MAX_FEE, K_PRIO_FEE, and nvs_u32_set().
Referenced by fees_post().
| void settings_set_mainnet | ( | bool | mainnet | ) |
Persist the production/test network choice.
Definition at line 201 of file settings.cpp.
References K_MAINNET, nvs_u8_set(), and TAG.
Referenced by network_post().
| bool settings_set_payout | ( | bool | tron, |
| const char * | addr ) |
Persist a payout address, writing both the value and its echo copy.
Does not validate: the caller checks the EIP-55 / base58 checksum first and shows the address on the device screen for the operator to accept.
| [in] | tron | true for the Tron address, false for Ethereum. |
| [in] | addr | NUL-terminated address; Ethereum with or without "0x". |
Definition at line 542 of file settings.cpp.
References dual_set(), K_PAY_ETH, K_PAY_ETH2, K_PAY_TRX, and K_PAY_TRX2.
Referenced by prov_pending_commit().
| void settings_set_touch_cal | ( | uint16_t | x_min, |
| uint16_t | x_max, | ||
| uint16_t | y_min, | ||
| uint16_t | y_max ) |
Persist a calibration. Rejected (and ignored) if an axis is inverted or collapsed — a bad store here makes the panel untappable, including the screen that would fix it.
Definition at line 270 of file settings.cpp.
References K_TOUCH_X, K_TOUCH_Y, nvs_u32_set(), and TAG.
Referenced by btn_event_cb().
| bool settings_set_tz_dst | ( | uint8_t | rule | ) |
Store the DST rule.
Definition at line 248 of file settings.cpp.
References K_TZ_DST, nvs_u8_set(), and tz_dst_valid().
Referenced by clock_post().
| bool settings_set_tz_offset_min | ( | int16_t | minutes | ) |
Store the panel clock's UTC offset.
| [in] | minutes | Minutes east of UTC, TZ_OFFSET_MIN to TZ_OFFSET_MAX. |
Definition at line 234 of file settings.cpp.
References K_TZ_OFFSET, nvs_u32_set(), tz_offset_encode(), and tz_offset_valid().
Referenced by clock_post().
| void settings_set_wifi | ( | const char * | ssid, |
| const char * | pass ) |
Persist Wi-Fi credentials (plaintext — see README threat model).
Definition at line 324 of file settings.cpp.
References K_WIFI_PASS, K_WIFI_SSID, NS_SETTINGS, and TAG.
Referenced by app_main(), run_wizard(), and wifi_keep_or_drop().
| bool settings_wipe_if_new_build | ( | void | ) |
Erase NVS unless this exact build is the one that wrote it.
Call once at the top of app_main, right after nvs_flash_init() and before anything else opens NVS (nvs_flash_erase() cannot run with handles outstanding). Handles its own re-init and stamps BUILD_ID.
A security control: the firmware is open source, so any other image could have written anything into NVS, a payout address above all. The test is equality — newer, older and absent stamps all erase. A rollback therefore erases again; settings are cheaper to re-enter than a payout address to lose.
The stamp does not authenticate itself: a hostile image that runs can forge it. Secure Boot (and Flash Encryption in RELEASE) stops foreign images; this covers state left by non-hostile ones (old releases, engineering builds).
Erases the whole partition, Wi-Fi and provision.cpp namespaces included, so the unit comes up in first-run setup and stays unowned until an operator re-enters Wi-Fi and re-accepts the payout address.
Definition at line 578 of file settings.cpp.
References cache_invalidate(), K_BUILD_ID, NS_SETTINGS, and TAG.
Referenced by pos_boot().