Files
fips/docs
Johnathan Corgan 056f577ad3 Merge branch 'master' into next
Carries the BLE platform work up to the feature line: the reframing that
recovers packet boundaries from the FMP length prefix, the L2CAP PSM seam and
its BlueZ implementation, the io.rs / io_linux.rs / io_android.rs split, the
Android backend, the probe backoff and connect-outcome counters, the
stop_scanning seam, and the pool-refusal fix.

Nine conflicts, all in src/transport/ble/mod.rs, and all one collision rather
than nine: `next` removed the pre-handshake pubkey exchange and the cross-probe
tie-breaker in 8162d3c, because XX replaces IK and identity is learned from the
handshake rather than from the transport. Most of what master added since sits
on top of that exchange.

Resolved by taking master's module and re-applying next's removal over it.
`next`'s own BLE delta is purely subtractive, so the two are reconcilable
without inventing anything: what survives is every change that does not need
the exchange, and what goes is everything that does.

Dropped deliberately, not lost:

- The node-identity pool keying, which keyed the pool on the NodeAddr the
  exchange learned. There is no identity source for it here, so `next` keeps
  address-keyed dedup. The RPA-rotation defect it fixes on master therefore
  stands on next, and closing it needs a decision about where BLE peer identity
  comes from once the XX handshake owns it. That decision is not made here.
- The inbound handshake concurrency bound, which exists to run the pubkey
  exchange off the accept loop. With no exchange there is nothing to run off
  it, and ISSUE-2026-0171 already records next as NOT AFFECTED.
- The exchange itself, its tie-breaker, and the announced-address
  canonicalisation built on them.

Five BLE counters went with them rather than being left to read zero forever:
pubkey_exchange_failures, tiebreaker_yields, tiebreaker_drops,
duplicate_node_declines and handshakes_aborted. Each counts a mechanism this
branch no longer has, and a metric that can only ever report zero is worse than
no metric.

The two scan tests take next's shape rather than master's: master's relied on
the no-local-pubkey shortcut to reach the neighbour buffer without dialling,
and that shortcut is gone, so they set a connect handler and let the probe
succeed.

Quartet green: rustfmt and clippy clean at -D warnings, 2478 tests passed,
0 failed. Six repo guards exit 0.
2026-08-26 08:55:12 +01:00
..
2026-08-21 05:55:35 +00:00
2026-08-21 05:55:35 +00:00
2026-08-26 08:55:12 +01:00
2026-08-22 11:04:58 +01:00

FIPS Documentation

FIPS (Free Internetworking Peering System) is a self-organizing encrypted mesh network built on Nostr identities, capable of operating over arbitrary transports — local networks, the public internet, Tor, Bluetooth, or point-to-point links — without central infrastructure.

With FIPS, your machine becomes a node in the mesh with a self-generated cryptographic identity. There are two ways to deploy it.

As an overlay on top of existing IP networks, FIPS lets your node reach any other FIPS node wherever it sits — behind a NAT, on a different ISP, on a phone over cellular, on a laptop with only Bluetooth in range, or behind a Tor onion. The mesh forwards IPv6 traffic transparently and end-to-end encrypted, with no central VPN concentrator or coordinating server.

From the ground up over raw Ethernet, WiFi, or Bluetooth, FIPS provides a complete permissionless network without any pre-existing IP infrastructure, ISP, or DNS. Any node that joins the link gets routable IPv6 addresses, peer discovery, and a path to every other node automatically.

Either way, existing networking software runs over it unchanged: SSH, HTTP servers, file transfer, anything IPv6-native works the same way it would on a local network.

New to FIPS? Start with the Getting Started guide.

Documentation Sections

Tutorials

If you are starting from scratch and want a guided path to a working mesh, go here.

How-To Guides

If you have a specific task in mind — enabling a feature, deploying a component, diagnosing a problem — go here.

Reference

If you need to look up wire formats, configuration keys, command flags, or counter inventories, go here.

Design

If you want to understand how the mesh self-organizes, why FIPS makes the choices it does, or how the pieces fit together, go here.