mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
5353 is the mDNS port, which the daemon's LAN rendezvous, Avahi and systemd-resolved can hold. On an OpenWrt access point with the gateway enabled, the gateway lost the port to the daemon's mDNS responder and dnsmasq sent .fips queries to a responder that does not answer them. 5365 is unassigned by IANA and not used by any common resolver. The OpenWrt init script now points dnsmasq at the port gateway.dns.listen actually sets, falling back to the new default, and when it swaps the .fips forwarding it clears every loopback .fips entry rather than four fixed ones, so a stale entry for an old or custom port does not linger. Forwards to other hosts and other domains are kept. The shipped OpenWrt config and the example config leave the listen line at the default. fips.yaml is a conffile on OpenWrt, and fips-ap-setup edits it, so routers that set up an access point would keep the old explicit listen: "[::1]:5353" across an upgrade and stay broken after the default moved. The first-boot setup script, which every install and upgrade path runs before the services start, now rewrites that exact shipped line to the line a fresh install ships and logs that it did; any other value is left as configured. The script is sourced rather than executed on the SDK-feed and sysupgrade paths, so the migration runs last, cannot end the script early and cannot change its exit status. The script also removes stale loopback .fips forwarding entries for port 5353. The gateway warns at startup when it is configured on 5353, whether or not the bind succeeds, since an mDNS responder can take the port later. The OpenWrt scenario harness checks the port the init script reads, that its default matches the gateway's, and the swap's cleanup against a uci stub. It also runs the real setup script executed by both package managers' upgrade scripts and sourced in a subshell, and checks the negative, missing-file, repeat-run and stale-entry cases. The dns-resolver and deb-install harnesses check that the gateway binds the new default.
191 lines
7.0 KiB
YAML
191 lines
7.0 KiB
YAML
# FIPS Node Configuration
|
|
|
|
node:
|
|
identity:
|
|
# By default, a new ephemeral keypair is generated on each start.
|
|
# Uncomment persistent to keep the same identity across restarts;
|
|
# on first start a keypair is saved to fips.key/fips.pub next to
|
|
# this config file (mode 0600/0644).
|
|
# persistent: true
|
|
#
|
|
# Or set an explicit key (overrides persistent):
|
|
# nsec: "nsec1..."
|
|
# Mesh-lookup protocol (node.lookup.*): the overlay coordinate-lookup engine
|
|
# (mesh address -> coordinates). Defaults shown; uncomment to override.
|
|
# lookup:
|
|
# ttl: 64
|
|
# attempt_timeouts_secs: [1, 2, 4, 8]
|
|
# recent_expiry_secs: 10
|
|
# backoff_base_secs: 0
|
|
# backoff_max_secs: 0
|
|
# forward_min_interval_secs: 2
|
|
rendezvous:
|
|
# Optional Nostr-mediated overlay endpoint rendezvous.
|
|
# nostr:
|
|
# enabled: true
|
|
# policy: configured_only # disabled | configured_only | open
|
|
# open_discovery_max_pending: 64 # caps queued open-rendezvous retries
|
|
# app: "fips-overlay-v1"
|
|
# advertise: true
|
|
# advert_relays:
|
|
# - "wss://relay.damus.io"
|
|
# - "wss://nos.lol"
|
|
# - "wss://offchain.pub"
|
|
# dm_relays:
|
|
# - "wss://relay.damus.io"
|
|
# - "wss://nos.lol"
|
|
# - "wss://offchain.pub"
|
|
# # Optional override. If omitted, FIPS uses the built-in STUN list.
|
|
# # Built-in relay/STUN defaults are best-effort and should be
|
|
# # overridden by operators for production use.
|
|
# stun_servers:
|
|
# - "stun:stun.l.google.com:19302"
|
|
# - "stun:stun.cloudflare.com:3478"
|
|
# - "stun:global.stun.twilio.com:3478"
|
|
|
|
# mDNS/DNS-SD peer rendezvous on the local link. Ships commented (the
|
|
# daemon default is off); 'fips-ap-setup' uncomments it when creating
|
|
# the access SSID — phone FIPS apps cannot see raw-Ethernet beacons,
|
|
# so mDNS is how they find this router's daemon. Daemon-wide switch,
|
|
# left enabled on 'fips-ap-setup remove'.
|
|
# lan:
|
|
# enabled: true
|
|
|
|
tun:
|
|
enabled: true
|
|
name: fips0
|
|
mtu: 1280
|
|
|
|
dns:
|
|
enabled: true
|
|
# bind_addr defaults to "::1" (IPv6 loopback). The shipped
|
|
# fips-dns-setup script configures systemd-resolved with a global
|
|
# /etc/systemd/resolved.conf.d/fips.conf drop-in pointing at
|
|
# [::1]:5354.
|
|
#
|
|
# Set "::" to expose the responder to mesh peers as well (e.g. for
|
|
# gateway hosts that resolve .fips on behalf of LAN clients). The
|
|
# mesh-interface filter in src/upper/dns.rs will still defend
|
|
# /etc/fips/hosts aliases from cross-mesh enumeration.
|
|
# bind_addr: "::1"
|
|
port: 5354
|
|
|
|
transports:
|
|
udp:
|
|
# Dual-stack wildcard, not "0.0.0.0": access-SSID clients (phones) learn
|
|
# this node's addresses from the mDNS advert and prefer the IPv6
|
|
# link-local — a v4-only bind silently drops their Noise msg1.
|
|
# OpenWrt is Linux (bindv6only=0), so "[::]" accepts v4 too.
|
|
bind_addr: "[::]:2121"
|
|
# advertise_on_nostr: true
|
|
# public: false # false => advertise udp:nat; true => advertise bound host:port
|
|
# accept_connections: true # default; refuse inbound msg1 when false
|
|
# outbound_only: false # true => bind ephemeral, no listener on a
|
|
# # known port. Forces advertise_on_nostr=false
|
|
# # and accept_connections=false. Pure-client
|
|
# # posture; bind_addr is ignored.
|
|
|
|
tcp:
|
|
# Accepts inbound connections. No static outbound peers.
|
|
bind_addr: "0.0.0.0:8443"
|
|
# advertise_on_nostr: true
|
|
|
|
# Ethernet transport — physical port names, NOT bridge names.
|
|
# Run 'ip link show' on the router to identify port names.
|
|
ethernet:
|
|
wan:
|
|
interface: "eth0"
|
|
listen: true
|
|
announce: true
|
|
auto_connect: true
|
|
accept_connections: true
|
|
wwan:
|
|
interface: "phy0-sta0"
|
|
listen: true
|
|
announce: true
|
|
auto_connect: true
|
|
accept_connections: true
|
|
lan:
|
|
interface: "br-lan"
|
|
listen: true
|
|
announce: true
|
|
auto_connect: true
|
|
accept_connections: true
|
|
|
|
# 802.11s mesh backhaul between FIPS routers. These entries ship
|
|
# commented out so a stock install that never creates fips-mesh*
|
|
# logs no per-boot "interface missing" bind warning. Running
|
|
# 'fips-mesh-setup <radio>' creates the interface AND uncomments the
|
|
# matching block here (once per radio; radio0 -> fips-mesh0, radio1 ->
|
|
# fips-mesh1); 'fips-mesh-setup remove' re-comments it. Restart fips
|
|
# after — a transport whose interface is missing at startup is skipped,
|
|
# not retried. Dual-band routers can mesh on both bands at once —
|
|
# failover, not multipath: FIPS keeps one active link per peer, the
|
|
# other band stands by. The mesh runs OPEN (no SAE) with 802.11s
|
|
# forwarding off: FIPS's Noise handshake is the encryption and
|
|
# authentication, and FIPS is the routing layer. See
|
|
# docs/how-to/set-up-80211s-mesh-backhaul.md.
|
|
# mesh0:
|
|
# interface: "fips-mesh0"
|
|
# listen: true
|
|
# announce: true
|
|
# auto_connect: true
|
|
# accept_connections: true
|
|
# mesh1:
|
|
# interface: "fips-mesh1"
|
|
# listen: true
|
|
# announce: true
|
|
# auto_connect: true
|
|
# accept_connections: true
|
|
|
|
# Open "!FIPS" access SSID for phones and laptops running FIPS. These
|
|
# entries ship commented out so a stock install that never creates
|
|
# fips-ap* logs no per-boot "interface missing" bind warning. Running
|
|
# 'fips-ap-setup <radio>' creates the interface AND uncomments the
|
|
# matching block here (once per radio; radio0 -> fips-ap0, radio1 ->
|
|
# fips-ap1); 'fips-ap-setup remove' re-comments it. Restart fips after
|
|
# — a transport whose interface is missing at startup is skipped, not
|
|
# retried. The SSID is OPEN and isolated on purpose: FIPS's Noise
|
|
# handshake is the only security layer, and associated clients reach
|
|
# nothing but the FIPS handshake surface. See
|
|
# docs/how-to/set-up-open-access-ssid.md.
|
|
# ap0:
|
|
# interface: "fips-ap0"
|
|
# listen: true
|
|
# announce: true
|
|
# auto_connect: true
|
|
# accept_connections: true
|
|
# ap1:
|
|
# interface: "fips-ap1"
|
|
# listen: true
|
|
# announce: true
|
|
# auto_connect: true
|
|
# accept_connections: true
|
|
|
|
# No BLE transport: OpenWrt builds target musl, which has no BlueZ backend.
|
|
|
|
# Outbound LAN gateway. dnsmasq forwards .fips queries to listen=[::1]:5353
|
|
# while it runs (configured by the fips-gateway init script). Requires IPv6
|
|
# forwarding enabled.
|
|
gateway:
|
|
enabled: true
|
|
pool: "fd01::/112"
|
|
lan_interface: "br-lan"
|
|
dns:
|
|
listen: "[::1]:5353"
|
|
upstream: "[::1]:5354"
|
|
ttl: 60
|
|
pool_grace_period: 60
|
|
|
|
peers: []
|
|
# Static peers for bootstrapping (UDP or TCP):
|
|
# - npub: "npub1qmc3cvfz0yu2hx96nq3gp55zdan2qclealn7xshgr448d3nh6lks7zel98"
|
|
# alias: "gateway"
|
|
# via_nostr: true
|
|
# addresses:
|
|
# - transport: udp
|
|
# addr: "test-us01.fips.network:2121" # IP or hostname (e.g., "peer.example.com:2121")
|
|
# - transport: udp
|
|
# addr: "nat" # Use node.rendezvous.nostr for Nostr/STUN hole punching
|
|
# connect_policy: auto_connect
|