Files
fips/docs/reference
Johnathan Corgan 056f577ad3 Merge branch 'master' into next
Carries the BLE platform work up to the feature line: the reframing that
recovers packet boundaries from the FMP length prefix, the L2CAP PSM seam and
its BlueZ implementation, the io.rs / io_linux.rs / io_android.rs split, the
Android backend, the probe backoff and connect-outcome counters, the
stop_scanning seam, and the pool-refusal fix.

Nine conflicts, all in src/transport/ble/mod.rs, and all one collision rather
than nine: `next` removed the pre-handshake pubkey exchange and the cross-probe
tie-breaker in 8162d3c, because XX replaces IK and identity is learned from the
handshake rather than from the transport. Most of what master added since sits
on top of that exchange.

Resolved by taking master's module and re-applying next's removal over it.
`next`'s own BLE delta is purely subtractive, so the two are reconcilable
without inventing anything: what survives is every change that does not need
the exchange, and what goes is everything that does.

Dropped deliberately, not lost:

- The node-identity pool keying, which keyed the pool on the NodeAddr the
  exchange learned. There is no identity source for it here, so `next` keeps
  address-keyed dedup. The RPA-rotation defect it fixes on master therefore
  stands on next, and closing it needs a decision about where BLE peer identity
  comes from once the XX handshake owns it. That decision is not made here.
- The inbound handshake concurrency bound, which exists to run the pubkey
  exchange off the accept loop. With no exchange there is nothing to run off
  it, and ISSUE-2026-0171 already records next as NOT AFFECTED.
- The exchange itself, its tie-breaker, and the announced-address
  canonicalisation built on them.

Five BLE counters went with them rather than being left to read zero forever:
pubkey_exchange_failures, tiebreaker_yields, tiebreaker_drops,
duplicate_node_declines and handshakes_aborted. Each counts a mechanism this
branch no longer has, and a metric that can only ever report zero is worse than
no metric.

The two scan tests take next's shape rather than master's: master's relied on
the no-local-pubkey shortcut to reach the neighbour buffer without dialling,
and that shortcut is gone, so they set a connect handler and let the probe
succeed.

Quartet green: rustfmt and clippy clean at -D warnings, 2478 tests passed,
0 failed. Six repo guards exit 0.
2026-08-26 08:55:12 +01:00
..
2026-05-08 13:45:04 +00:00
2026-08-09 13:41:09 +00:00
2026-08-21 05:55:35 +00:00

Reference

Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.

Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.

Available Reference

Document Scope
wire-formats.md All FMP and FSP message byte layouts, encapsulation walkthrough
configuration.md Full YAML configuration reference for the daemon and gateway
security.md nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix
nostr-events.md Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays
transports.md Per-transport statistics counter inventory
control-socket.md Line-delimited JSON control protocol for the daemon and gateway
native-api.md Native datagram API: the Rust surface, addressing and ports, errno table, ceilings, line protocol, command reference
cli-fips.md fips daemon CLI: options, exit codes, environment, files
cli-fipsctl.md fipsctl control-client: subcommands, options, exit codes
cli-fipstop.md fipstop live-status TUI: tabs, keybindings
cli-fips-gateway.md fips-gateway service CLI: options, exit codes, files