Adds packaging/openwrt/ with everything needed to produce and distribute
FIPS .ipk packages for OpenWrt routers:
- Makefile: OpenWrt feed package definition using rust/host toolchain,
maps OpenWrt ARCH to Rust musl target triples
- build-ipk.sh: local build script using cargo-zigbuild + direct tar
assembly — no OpenWrt SDK or Docker required. Handles macOS BSD tar
(ustar format, resource fork suppression) and portable ar header
generation for cross-platform .ipk creation. Accepts PKG_VERSION
env var override for CI use.
- files/: procd init script, default fips.yaml (persistent identity,
br-lan and wwan interface examples), firewall helper, dnsmasq .fips
forwarding, br_netfilter sysctl, hotplug for fips0, UCI defaults for
first-boot setup, sysupgrade keeplist
- .github/workflows/package-openwrt.yml: CI workflow (ubuntu-latest +
cargo-zigbuild) building aarch64 and x86_64 .ipk packages using
build-ipk.sh; llvm-strip for cross-compiled binaries; triggers on
every push; publishes to GitHub Releases on version tags. MIPS
targets disabled pending portable-atomic crate (32-bit MIPS lacks
native AtomicU64), with nightly/rust-src toolchain steps prepared
for re-enablement.
- .gitignore: add reference/, dist/, *.ipk
- Ethernet ioctl: cfg-gate the ioctl request parameter type — c_int on
musl, c_ulong on gnu — so the same code compiles on both
x86_64-unknown-linux-gnu and x86_64-unknown-linux-musl targets
- Chaos harness macOS support: replace direct host 'ip link' invocations
with a privileged Docker container helper (--net=host --pid=host) that
shares the Docker VM's namespaces, making veth pair setup work on both
Linux and macOS (where host 'ip' is unavailable and container PIDs
live inside the Docker Desktop VM)
- Python 3.9 compat: add 'from __future__ import annotations' to
docker_exec.py for X|Y union syntax support
- Add deploy/ to .gitignore
Co-authored-by: origami74 <origami74@gmail.com>
Implements FIPS Identity System (Section 1 of design doc):
- NodeId: 32-byte SHA-256 hash of npub, with Ord for root election
- FipsAddress: 128-bit IPv6-compatible address (0xfd prefix)
- Identity: keypair holder with sign/verify methods
- AuthChallenge/AuthResponse: challenge-response authentication
All 11 tests passing.