Remove unresolvable internal references from files outside the source tree

Six comments in CI configuration, packaging and test scripts cited internal
identifiers, or named the private tracker in prose. Each now states what the
identifier stood for.

One of these ships. The DNS setup helper installs to /usr/lib/fips on every
packaging path, so its comment reached users. That edit removes the
identifier and the words naming the tracker; the two lines above it already
state the whole mechanism, so nothing is lost.

The retry-policy comment in the rekey test now says the loss rate is what the
policy is sized for, rather than what the phases run under. No runner injects
loss, so the stronger claim was not true.
This commit is contained in:
Johnathan Corgan
2026-08-16 12:19:28 +00:00
parent 005942f141
commit 8de50bd22b
6 changed files with 8 additions and 8 deletions
+3 -2
View File
@@ -466,8 +466,9 @@ jobs:
# NM+dnsmasq, dns-delegate, no-resolver) across five distros, # NM+dnsmasq, dns-delegate, no-resolver) across five distros,
# plus end-to-end scenarios that boot a real fips daemon with a # plus end-to-end scenarios that boot a real fips daemon with a
# real TUN and assert `dig @127.0.0.53 AAAA <npub>.fips` # real TUN and assert `dig @127.0.0.53 AAAA <npub>.fips`
# returns AAAA. Pins the production DNS bind path that # returns AAAA. Pins the production DNS bind path where a
# ISSUE-2026-0002 lived in. Single matrix entry runs all 13 # loopback-delivered query was once misattributed to the mesh
# interface and dropped. Single matrix entry runs all 13
# scenarios sequentially; ~7-12 min warm, ~12-15 min cold. # scenarios sequentially; ~7-12 min warm, ~12-15 min cold.
- suite: dns-resolver - suite: dns-resolver
type: dns-resolver type: dns-resolver
+1 -2
View File
@@ -117,8 +117,7 @@ EOF
# - The IPV6_PKTINFO ifindex attribution behaviour where Linux reports # - The IPV6_PKTINFO ifindex attribution behaviour where Linux reports
# a packet to fips0's own IPv6 address as arriving on fips0 (despite # a packet to fips0's own IPv6 address as arriving on fips0 (despite
# loopback delivery), which would otherwise be silently dropped by # loopback delivery), which would otherwise be silently dropped by
# the daemon's mesh-interface filter — see ISSUE-2026-0002 in the # the daemon's mesh-interface filter.
# project tracker.
# #
# This backend is the recommended path on every systemd-resolved host # This backend is the recommended path on every systemd-resolved host
# that doesn't have native dns-delegate support (systemd >= 258). # that doesn't have native dns-delegate support (systemd >= 258).
+1 -1
View File
@@ -72,7 +72,7 @@ netem:
# `interval_secs`, the policies on the two listed edges are swapped. # `interval_secs`, the policies on the two listed edges are swapped.
# This drives n04 to alternate parents between n02 and n03 each # This drives n04 to alternate parents between n02 and n03 each
# round. The 4s cadence and 5ms-vs-100ms delta come from the # round. The 4s cadence and 5ms-vs-100ms delta come from the
# original ISSUE-2026-0019 reproduction harness — they are # original reproduction harness for this flap — they are
# calibrated to produce a parent switch per round under the # calibrated to produce a parent switch per round under the
# zero-hysteresis FIPS overrides below. # zero-hysteresis FIPS overrides below.
link_swap: link_swap:
+1 -1
View File
@@ -949,7 +949,7 @@ echo ""
# versions. A mixed-version bloom/tree-encoding divergence shows up as a # versions. A mixed-version bloom/tree-encoding divergence shows up as a
# node that never produces an in-band estimate (or returns null). Strict # node that never produces an in-band estimate (or returns null). Strict
# band = [0.75N, 1.25N]; polled up to MESH_SIZE_TIMEOUT (the estimate # band = [0.75N, 1.25N]; polled up to MESH_SIZE_TIMEOUT (the estimate
# converges over minutes — see ISSUE-2026-0046 on its transient jitter). # converges over minutes and is transiently jittery).
echo "Phase 7: Mesh-size estimate convergence (strict ±25% of true N=$NUM_NODES)" echo "Phase 7: Mesh-size estimate convergence (strict ±25% of true N=$NUM_NODES)"
PASSED=0; FAILED=0 PASSED=0; FAILED=0
ms_lo="$(awk -v n="$NUM_NODES" 'BEGIN{printf "%.2f", 0.75*n}')" ms_lo="$(awk -v n="$NUM_NODES" 'BEGIN{printf "%.2f", 0.75*n}')"
+1 -1
View File
@@ -1,6 +1,6 @@
# Compose override that bumps RUST_LOG to trace level on the modules # Compose override that bumps RUST_LOG to trace level on the modules
# relevant to NAT-traversal handshake-completion flake evidence # relevant to NAT-traversal handshake-completion flake evidence
# collection (ISSUE-2026-0027): # collection:
# #
# - fips::discovery::nostr — overlay advert publish/consume # - fips::discovery::nostr — overlay advert publish/consume
# (where the cross-init race begins) # (where the cross-init race begins)
+1 -1
View File
@@ -176,7 +176,7 @@ RECONVERGE_STALL=10
TIMEOUT=5 TIMEOUT=5
CONVERGENCE_PING_TIMEOUT=1 CONVERGENCE_PING_TIMEOUT=1
# Strict-ping retry policy for the per-phase ping_all asserts. Under 1% # Strict-ping retry policy for the per-phase ping_all asserts. Under 1%
# i.i.d. packet loss (the lab condition surfaced by ISSUE-2026-0028) a # i.i.d. packet loss (the lab condition this retry policy is sized for) a
# single-shot ping fails at roughly 2% per directed pair, so a 20-pair # single-shot ping fails at roughly 2% per directed pair, so a 20-pair
# strict assert misses with probability ~1 - (0.98)^20 ≈ 33%, which is # strict assert misses with probability ~1 - (0.98)^20 ≈ 33%, which is
# below the per-pair loss-math floor but well above the routing-state # below the per-pair loss-math floor but well above the routing-state