cryptnox-pos 1.0.0
Standalone USDC payment terminal firmware (ESP32 + Cryptnox smart card)
Loading...
Searching...
No Matches
settings_rules.h File Reference

What a setting may be, apart from where it is stored. More...

#include <stdbool.h>
#include <stddef.h>
#include <stdint.h>
#include <stdio.h>
#include <string.h>
#include "CW_Utils.h"
#include "civil_time.h"
#include "keccak256.h"
#include "settings.h"
Include dependency graph for settings_rules.h:
This graph shows which files directly or indirectly include this file:

Go to the source code of this file.

Macros

#define TZ_OFFSET_BIAS   720
#define FEE_GWEI_MIN   1UL
#define FEE_GWEI_MAX   500UL
#define ADMIN_SALT_LEN   16U
#define ADMIN_HASH_LEN   32U
#define ADMIN_CODE_HASH_MAX   32U

Enumerations

enum  fee_pair_t { FEE_PAIR_OK = 0 , FEE_PAIR_OUT_OF_RANGE , FEE_PAIR_TIP_ABOVE_MAX }
 Verdict on a (max fee, tip) pair from the config page. More...

Functions

static bool tz_offset_valid (long minutes)
 true for an offset the clock accepts (TZ_OFFSET_MIN .. _MAX).
static uint32_t tz_offset_encode (int16_t minutes)
 A valid offset in its stored, biased form.
static int16_t tz_offset_decode (uint32_t raw)
 The stored form back to minutes; nonsense in NVS is UTC, not a wild clock.
static bool tz_dst_valid (long rule)
 true for a DST rule the clock knows.
static uint8_t tz_dst_decode (uint8_t r)
 A stored DST rule, or no DST if it is not one the clock knows.
static fee_pair_t fee_pair_check (unsigned long max_gwei, unsigned long prio_gwei)
 Check a (max fee, tip) pair in Gwei; the range is checked first.
static void admin_derive (const char *code, const uint8_t *salt, uint8_t out[ADMIN_HASH_LEN])
 Derive the stored digest: a single keccak256 over salt || code.
static bool settings_addr_normalise (bool tron, const char *addr, char norm[SETTINGS_PAYOUT_MAX])
 The form a payout address or contract is stored in: Tron as given, Ethereum "0x"-prefixed whichever way it arrived.

Detailed Description

What a setting may be, apart from where it is stored.

Header-only and free of ESP-IDF dependencies on purpose, like form_parse.h: settings.cpp and provision.cpp wrap these in NVS and HTTP, and the rules themselves — the time-zone range and its storage bias, the gas-fee bounds, the admin-code digest, the address normalisation the echo copy relies on — are what tests/units/test_settings_rules.cpp checks.

Definition in file settings_rules.h.

Macro Definition Documentation

◆ ADMIN_CODE_HASH_MAX

#define ADMIN_CODE_HASH_MAX   32U

Definition at line 109 of file settings_rules.h.

Referenced by admin_derive().

◆ ADMIN_HASH_LEN

#define ADMIN_HASH_LEN   32U

◆ ADMIN_SALT_LEN

#define ADMIN_SALT_LEN   16U

◆ FEE_GWEI_MAX

#define FEE_GWEI_MAX   500UL

Definition at line 80 of file settings_rules.h.

Referenced by fee_get(), and fee_pair_check().

◆ FEE_GWEI_MIN

#define FEE_GWEI_MIN   1UL

Definition at line 79 of file settings_rules.h.

Referenced by fee_get(), and fee_pair_check().

◆ TZ_OFFSET_BIAS

#define TZ_OFFSET_BIAS   720

Definition at line 38 of file settings_rules.h.

Referenced by settings_get_tz_offset_min(), tz_offset_decode(), and tz_offset_encode().

Enumeration Type Documentation

◆ fee_pair_t

enum fee_pair_t

Verdict on a (max fee, tip) pair from the config page.

Enumerator
FEE_PAIR_OK 
FEE_PAIR_OUT_OF_RANGE 

either one outside FEE_GWEI_MIN..MAX

FEE_PAIR_TIP_ABOVE_MAX 

the tip is higher than the cap

Definition at line 83 of file settings_rules.h.

Function Documentation

◆ admin_derive()

void admin_derive ( const char * code,
const uint8_t * salt,
uint8_t out[ADMIN_HASH_LEN] )
inlinestatic

Derive the stored digest: a single keccak256 over salt || code.

Not stretched, on purpose. The digest lives in the flash-encrypted NVS, so reading it already means the encryption is defeated — and past that point no KDF cost saves a 4-digit code anyway. The salt is still there so the same code yields a different digest on every unit. Guessing at the panel is what the escalating lockout in ui.cpp is for.

Definition at line 120 of file settings_rules.h.

References ADMIN_CODE_HASH_MAX, ADMIN_HASH_LEN, ADMIN_SALT_LEN, and keccak256().

Referenced by settings_check_admin_code(), and settings_set_admin_code().

◆ fee_pair_check()

fee_pair_t fee_pair_check ( unsigned long max_gwei,
unsigned long prio_gwei )
inlinestatic

Check a (max fee, tip) pair in Gwei; the range is checked first.

Definition at line 90 of file settings_rules.h.

References FEE_GWEI_MAX, FEE_GWEI_MIN, FEE_PAIR_OK, FEE_PAIR_OUT_OF_RANGE, and FEE_PAIR_TIP_ABOVE_MAX.

Referenced by fees_post(), and settings_set_fees_gwei().

◆ settings_addr_normalise()

bool settings_addr_normalise ( bool tron,
const char * addr,
char norm[SETTINGS_PAYOUT_MAX] )
inlinestatic

The form a payout address or contract is stored in: Tron as given, Ethereum "0x"-prefixed whichever way it arrived.

Normalised to the form the getter hands back, so the echo comparison compares like with like on the next boot.

Parameters
[in]trontrue for a Tron address.
[in]addrAs submitted.
[out]normSETTINGS_PAYOUT_MAX bytes.
Returns
false for a NULL, empty or over-long addr (norm untouched).

Definition at line 148 of file settings_rules.h.

References SETTINGS_PAYOUT_MAX.

Referenced by dual_set().

◆ tz_dst_decode()

uint8_t tz_dst_decode ( uint8_t r)
inlinestatic

A stored DST rule, or no DST if it is not one the clock knows.

Definition at line 68 of file settings_rules.h.

References CIVIL_DST__COUNT, and CIVIL_DST_NONE.

Referenced by settings_get_tz_dst().

◆ tz_dst_valid()

bool tz_dst_valid ( long rule)
inlinestatic

true for a DST rule the clock knows.

Definition at line 62 of file settings_rules.h.

References CIVIL_DST__COUNT.

Referenced by clock_post(), and settings_set_tz_dst().

◆ tz_offset_decode()

int16_t tz_offset_decode ( uint32_t raw)
inlinestatic

The stored form back to minutes; nonsense in NVS is UTC, not a wild clock.

Definition at line 53 of file settings_rules.h.

References TZ_OFFSET_BIAS, and TZ_OFFSET_MAX.

Referenced by settings_get_tz_offset_min().

◆ tz_offset_encode()

uint32_t tz_offset_encode ( int16_t minutes)
inlinestatic

A valid offset in its stored, biased form.

Definition at line 47 of file settings_rules.h.

References TZ_OFFSET_BIAS.

Referenced by settings_set_tz_offset_min().

◆ tz_offset_valid()

bool tz_offset_valid ( long minutes)
inlinestatic

true for an offset the clock accepts (TZ_OFFSET_MIN .. _MAX).

Definition at line 41 of file settings_rules.h.

References TZ_OFFSET_MAX, and TZ_OFFSET_MIN.

Referenced by clock_post(), and settings_set_tz_offset_min().