docs: refresh README, CONTRIBUTING, and examples for v0.3.0

Four short prose corrections folded together to align operator-facing
docs with current v0.3.0 reality:

- README Rust prerequisite reconciled with the toolchain pin (1.94.1,
  was 1.85+).
- CONTRIBUTING.md bumps the Rust prerequisite and adds the squash-merge
  policy note.
- examples/sidecar-nostr-relay/Dockerfile drops stale --features tui
  and the paired --no-default-features; the tui/ble/gateway cargo
  features were replaced by platform cfg gates in cbc7809.
- README Features list adds two v0.3.0-visible items: the mesh-
  interface security baseline (fips.nft conffile, fips.d/ drop-in,
  opt-in fips-firewall.service across all packaging formats) and the
  fipsctl stats time-series queries plus fipstop inline sparkline
  dashboards.

Status badge bump (v0.3.0--dev to v0.3.0) is deferred to tag time per
the release-prep checklist.
This commit is contained in:
Johnathan Corgan
2026-05-10 21:53:40 +00:00
parent eaba693b18
commit 42b88c9bb8
3 changed files with 15 additions and 6 deletions
+12 -4
View File
@@ -66,9 +66,17 @@ same way it would on a local network.
Protocol.
- **ECN congestion signaling.** Hop-by-hop CE-flag relay with RFC
3168 IPv6 marking and transport kernel-drop detection.
- **Operator visibility.** `fipsctl` CLI for control and inspection,
`fipstop` TUI for live status, and a JSON-line control socket on
each binary for direct programmatic access.
- **Mesh-interface security baseline.** Optional default-deny
nftables policy for `fips0` shipped as a packaged conffile
(`/etc/fips/fips.nft`) with an operator drop-in directory
(`/etc/fips/fips.d/`) and a disabled-by-default
`fips-firewall.service`. The baseline polices only the mesh
interface, leaving Docker, Tor, and the host firewall untouched.
- **Operator visibility.** `fipsctl` CLI for control and inspection
with time-series stats history queryable for any metric,
`fipstop` TUI for live status with inline sparkline dashboards,
and a JSON-line control socket on each binary for direct
programmatic access.
- **Reproducible builds** with toolchain pinning and
`SOURCE_DATE_EPOCH`.
@@ -103,7 +111,7 @@ tutorial progression starting at
cargo build --release
```
Requires Rust 1.85+ (edition 2024). Linux, macOS, and Windows are
Requires Rust 1.94.1+ (edition 2024). Linux, macOS, and Windows are
supported; transport availability varies by platform.
| Transport | Linux | macOS | Windows | OpenWrt |