Files
ruvnet--RuView/firmware/privshield/openwrt/openwrt.mk
T
Claude b827dc40b1 feat(privshield): E2E hardware program — validated C core + multi-provider firmware scaffolds
Take VEIL from the synthetic Rust reference model toward real WiFi silicon
across multiple hardware providers, around one shared, host-validated core.
Answers the questions "can OpenWRT / open WiFi software implement this?" and
"can ESP32 help scramble signals?" with an honest per-platform feasibility map.

Portable C shield core (firmware/privshield/core/) — VALIDATED (host test):
- veil_shield.{h,c}: keyed Givens-rotation obfuscation of the identity-bearing
  "fine" subspace, C99, no malloc / no libc I/O, only <math.h>. SplitMix64 key
  schedule byte-identical to the Rust crate, so on-air behavior is consistent
  everywhere and every adapter links the same math.
- make test passes: energy conservation (orthogonal => "not jamming"),
  reversibility (recover inverts apply), wrong-key-fails, and PRNG stream parity
  with the Rust crate. This is build/host evidence, NOT silicon.

Per-provider adapters (all SYNTHETIC / L0, build-only, TODO(hw) markers):
- openwifi/  grade B (ceiling A, effort D): only open PHY/MAC (FPGA) that can
  host the full keyed rotation + inverse; needs new HDL + 2nd TX chain. Carries
  the P5 measurement protocol (MEASUREMENT.md) for the first MEASURED result.
- openwrt/   grade C: per-packet keyed unitary is blob-blocked on commodity APs;
  coarse compliant knobs (TX antenna map, sounding-cadence jitter) reachable
  from userspace/hostapd; ath9k is the one credible driver-patch route.
- nexmon/    grade C: reading the compressed-BF angles is solved (nexmon_csi /
  Wi-BFI); shaping the transmitted report is research-grade (D11 ucode-adjacent).
- esp32/     grade F (self) / B (supporting): cannot shape its own BF feedback
  (closed esp-phy-lib blob); legitimate as a sensing detector and external-RIS
  controller — the honest way ESP32 "helps scramble", via an external surface.

Docs:
- firmware/privshield/README.md: architecture, layout, and the feasibility matrix.
- ADR-290: the E2E hardware program, PROOF discipline, and per-provider decision;
  added to docs/adr/README.md index.

Compliant waveform controls only, never jamming. No adapter has run on silicon;
no MEASURED claim is made (that is roadmap P5, gated on a captured log).

Co-Authored-By: claude-flow <ruv@ruv.net>
Claude-Session: https://claude.ai/code/session_01WEXNqzs7UsfNFBcP5yW21p
2026-08-09 16:34:11 +00:00

61 lines
2.2 KiB
Makefile

# SPDX-License-Identifier: MIT OR Apache-2.0
#
# OpenWRT package Makefile STUB for veil_shieldd.
# STATUS: SYNTHETIC / L0 — package skeleton, UNTESTED ON HARDWARE / not in any feed.
#
# Drop this (renamed to `Makefile`) into a package dir such as
# `package/utils/veil-shieldd/` in an OpenWRT buildroot, alongside the copied
# core (veil_shield.{c,h}) and veil_shieldd.c under ./src/. It builds against
# libnl-tiny (the OpenWRT netlink lib) — the same nl80211 API surface, smaller.
#
# This stub does NOT prove the daemon works on a device; it only wires the
# build. No hardware validation is implied.
include $(TOPDIR)/rules.mk
PKG_NAME:=veil-shieldd
PKG_VERSION:=0.0.0-l0
PKG_RELEASE:=1
PKG_LICENSE:=MIT OR Apache-2.0
include $(INCLUDE_DIR)/package.mk
define Package/veil-shieldd
SECTION:=utils
CATEGORY:=Utilities
TITLE:=VEIL compliant-waveform privacy shield (mac80211 adapter, L0)
# libnl-tiny provides nl80211/genl; hostapd for the ctrl_iface cadence path.
DEPENDS:=+libnl-tiny +hostapd-common
URL:=https://github.com/ruvnet/RuView
endef
define Package/veil-shieldd/description
BUILD-ONLY / UNTESTED-ON-HARDWARE userspace adapter that drives the
standards-compliant subset of VEIL controls reachable from OpenWRT
(TX antenna map, hostapd-mediated sounding cadence) and links the portable
keyed-rotation core. The full per-packet keyed rotation is blob-blocked on
commodity Qualcomm/MediaTek parts and requires a driver/firmware patch.
This is NOT a jammer and emits no denial energy.
endef
# Build flags: point at libnl-tiny headers and the copied core.
TARGET_CFLAGS += -I$(STAGING_DIR)/usr/include/libnl-tiny -I$(PKG_BUILD_DIR)/src
TARGET_LDFLAGS += -lnl-tiny -lm
define Build/Compile
$(TARGET_CC) $(TARGET_CFLAGS) -std=c99 -Wall -Wextra \
-o $(PKG_BUILD_DIR)/veil_shieldd \
$(PKG_BUILD_DIR)/src/veil_shieldd.c \
$(PKG_BUILD_DIR)/src/veil_shield.c \
$(TARGET_LDFLAGS)
endef
define Package/veil-shieldd/install
$(INSTALL_DIR) $(1)/usr/sbin
$(INSTALL_BIN) $(PKG_BUILD_DIR)/veil_shieldd $(1)/usr/sbin/veil_shieldd
# TODO(hw): ship a procd init script that reads the session key from a
# secure store (never a world-readable config) and passes -i <ifindex>.
endef
$(eval $(call BuildPackage,veil-shieldd))