97 lines
3.5 KiB
C
97 lines
3.5 KiB
C
/* dispatch.h — verb dispatch for the Teensy 4.1 n_signer firmware.
|
|
*
|
|
* Phase 6 of plans/teensy41_signer_implementation.md.
|
|
*
|
|
* Ported from firmware/cyd_esp32_2432s028/main/main.c handle_request() (line
|
|
* 1297+). This is the bulk of the signer logic: parse a JSON-RPC request,
|
|
* optionally verify the auth envelope, dispatch by verb, call ui_approve() for
|
|
* signing verbs, build the structured JSON result, and return the response.
|
|
*
|
|
* The verb set and wire protocol are defined in api.md and
|
|
* plans/algorithm_based_api.md, and match the CYD and host n_signer so the
|
|
* same clients work against all three.
|
|
*
|
|
* Signer state (seed, privkey, pubkey, npub) is owned by signer.ino (Phase 7)
|
|
* and declared here as `extern` so dispatch.cpp can read them. signer.ino
|
|
* defines and populates them after the startup menu.
|
|
*/
|
|
#ifndef FIRMWARE_TEENSY41_SIGNER_DISPATCH_H
|
|
#define FIRMWARE_TEENSY41_SIGNER_DISPATCH_H
|
|
|
|
#include <stddef.h>
|
|
#include <stdint.h>
|
|
|
|
#ifdef __cplusplus
|
|
extern "C" {
|
|
#endif
|
|
|
|
/* ---- Firmware identity (signer.ino may override via -D) ---- */
|
|
#ifndef FIRMWARE_VERSION
|
|
#define FIRMWARE_VERSION "0.1.0"
|
|
#endif
|
|
#ifndef GIT_HASH
|
|
#define GIT_HASH "dev"
|
|
#endif
|
|
#define DISPATCH_IMPLEMENTATION "teensy41"
|
|
|
|
/* ---- Auth envelope policy ----
|
|
* If non-zero, every request must carry a valid kind-27235 auth envelope
|
|
* signed by an authorized caller. If zero, the caller is treated as "anon".
|
|
* Configurable at build time via -DAUTH_REQUIRED=0/1. */
|
|
#ifndef AUTH_REQUIRED
|
|
#define AUTH_REQUIRED 0
|
|
#endif
|
|
|
|
/* ---- Signer state (defined by signer.ino in Phase 7) ----
|
|
* These are populated after the startup menu applies the mnemonic:
|
|
* s_seed : 64-byte BIP-39 seed (mnemonic_to_seed output)
|
|
* s_privkey : 32-byte secp256k1 NIP-06 privkey at index 0
|
|
* s_pubkey : 32-byte secp256k1 x-only pubkey (Nostr pubkey)
|
|
* s_npub : NUL-terminated bech32 npub string ("npub1...")
|
|
* s_pubkey_hex : NUL-terminated 64-hex of s_pubkey
|
|
*
|
|
* s_seed_len is the number of valid bytes in s_seed (64 for BIP-39). */
|
|
extern uint8_t g_seed[64];
|
|
extern size_t g_seed_len;
|
|
extern uint8_t g_privkey[32];
|
|
extern uint8_t g_pubkey[32];
|
|
extern char g_npub[128];
|
|
extern char g_pubkey_hex[65];
|
|
|
|
/* Whether the signer has a loaded mnemonic / derived keys (set by signer.ino
|
|
* after apply_mnemonic). When 0, every verb except get_info returns an error. */
|
|
extern int g_signer_ready;
|
|
|
|
/* The role table (populated by signer.ino after the role wizard). Used by the
|
|
* nostr_* verbs to resolve role + role_path selectors. Defined in dispatch.cpp
|
|
* as a DMAMEM global. */
|
|
struct role_table_t;
|
|
extern struct role_table_t g_roles;
|
|
|
|
/* ---- Entry point ----
|
|
* Process one parsed JSON-RPC request and write the JSON-RPC response into
|
|
* `out_buf`.
|
|
*
|
|
* request_json : NUL-terminated raw JSON-RPC request string.
|
|
* out_buf : caller-provided response buffer.
|
|
* out_buf_len : size of out_buf in bytes.
|
|
*
|
|
* Returns the number of bytes written to out_buf (excluding the NUL), or -1
|
|
* if the response did not fit (caller should treat as an internal error).
|
|
*
|
|
* This function performs auth-envelope verification (if AUTH_REQUIRED),
|
|
* dispatches the verb, calls ui_approve() for signing verbs, and formats the
|
|
* structured JSON result. It does NOT do transport I/O — the caller frames
|
|
* the response. */
|
|
int dispatch_handle_request(const char *request_json,
|
|
char *out_buf, size_t out_buf_len);
|
|
|
|
/* Initialize dispatch state (nonce cache, etc). Call once at boot. */
|
|
void dispatch_init(void);
|
|
|
|
#ifdef __cplusplus
|
|
}
|
|
#endif
|
|
|
|
#endif /* FIRMWARE_TEENSY41_SIGNER_DISPATCH_H */
|