From 0c2c67b463d6a90aaa0bb69bf3c91dba1d9ec3ec Mon Sep 17 00:00:00 2001 From: Your Name Date: Sun, 17 May 2026 16:39:31 +0530 Subject: feat: per-client NAT filtering via LWIP_HOOK_IP4_CANFORWARD - Add lwip_tollgate_hooks.h defining LWIP_HOOK_IP4_CANFORWARD macro - Inject hook into lwIP build via CMakeLists.txt ESP_IDF_LWIP_HOOK_FILENAME - Filter forwarded packets by source IP against firewall allowed list - Only filter packets from AP subnet (10.192.45.0/24), allow all others - Fix byte order bug: use network byte order for firewall_is_client_allowed - NAT always enabled, removed global NAT toggle functions - Remove spent-secret tracking from session.c (mint is authority) - Remove unused get_ap_netif() function - Reduce API server stack from 32KB to 16KB (fixes ESP_ERR_HTTPD_TASK) - Add esp_random.h stub for unit tests - All 186 unit tests passing - Verified on hardware: block->pay->allow->revoke->block E2E works --- main/lwip_tollgate_hooks.h | 10 ++++++++++ 1 file changed, 10 insertions(+) create mode 100644 main/lwip_tollgate_hooks.h (limited to 'main/lwip_tollgate_hooks.h') diff --git a/main/lwip_tollgate_hooks.h b/main/lwip_tollgate_hooks.h new file mode 100644 index 0000000..76017be --- /dev/null +++ b/main/lwip_tollgate_hooks.h @@ -0,0 +1,10 @@ +#ifndef LWIP_TOLLGATE_HOOKS_H +#define LWIP_TOLLGATE_HOOKS_H + +#include "lwip/pbuf.h" + +int tollgate_ip4_canforward_filter(struct pbuf *p, u32_t dest_addr_hostorder); + +#define LWIP_HOOK_IP4_CANFORWARD(p, addr) tollgate_ip4_canforward_filter(p, addr) + +#endif -- cgit v1.2.3