mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The guard that drops a returning copy of this node's own lookup request recognises an id only while that lookup is outstanding and the id is among the last eight its ladder issued. Nothing pinned either limit: the existing test covers only an id inside the window of a live lookup. Two new tests do. A copy arriving after the lookup timed out is recorded and forwarded as transit, and its next copy is a duplicate. A copy of an attempt older than the recorded window is likewise recorded and forwarded, while a recent id on the same lookup is still dropped as our own. The mesh operation design said a node tests its own outstanding lookups before consulting recent_requests, and that a returning copy of the originator's request never enters the transit cache. The first is the response path's order; the request path runs the dedup test first and the own-request check second, where the order is immaterial because an id the originator check recognises is never in the dedup cache. The second holds only while the check recognises the id. The design now says both, and how far the check reaches, and its heading no longer says the originator check runs first. When a node's own looped-back lookup request got its own counter, the comments justified the split by saying req_duplicate means a peer resent a request, and that the own-loop counter says nothing about the peer. Neither holds. The duplicate test is on the request id alone, so one flood arriving through two neighbours is counted there too, and no discovery counter is per peer. Justify the split by cause instead: the node's own fan-out returning, versus a request id the node has already recorded arriving again. Say that neither counter identifies the delivering peer, that own-request loopbacks come back through bloom false positives and so rise with the filter's fill ratio, and that an own copy outside the loop check's reach is recorded and forwarded as transit, with a later copy counted as a duplicate.
FIPS Design
Architectural and protocol-level explanations for FIPS — the why and the how behind the wire and the system. For wire formats and configuration keys, see reference/. For task recipes, see how-to/. For end-to-end lessons, see tutorials/.
Reading Order
Start with fips-concepts.md for the novice-friendly framing of what FIPS is and why, then move to fips-architecture.md for the protocol stack, identity model, and two-layer encryption walkthrough. From there, follow the protocol stack from bottom to top. After the stack, fips-mesh-operation.md explains how the pieces work together at runtime. Cross-cutting and supporting documents cover specific subsystems in detail.
Foundations
| Document | Description |
|---|---|
| fips-concepts.md | What FIPS is, why it exists, mental model |
| fips-architecture.md | Protocol stack, identity, two-layer encryption |
| fips-prior-work.md | Designs and protocols FIPS builds on |
Protocol Stack
| Document | Description |
|---|---|
| fips-transport-layer.md | Transport layer: datagram delivery over arbitrary media |
| fips-mesh-layer.md | FIPS Mesh Protocol (FMP): peer authentication, link encryption, forwarding |
| fips-session-layer.md | FIPS Session Protocol (FSP): end-to-end encryption, sessions |
| fips-ipv6-adapter.md | IPv6 adaptation: TUN interface, DNS, MTU enforcement |
| fips-native-api.md | Native datagram API: pubkey-addressed flows over FSP, and what it is instead of the TUN path |
Cross-Cutting
| Document | Description |
|---|---|
| fips-mmp.md | Metrics Measurement Protocol (link + session) |
| fips-mtu.md | Path MTU model, encapsulation overhead, PMTUD |
| fips-security.md | fips0 interface threat model and default-deny baseline |
Mesh Behavior
| Document | Description |
|---|---|
| fips-mesh-operation.md | How the mesh operates: routing, discovery, error recovery |
| fips-nostr-discovery.md | Optional Nostr-mediated peer discovery and UDP NAT hole-punch |
| port-advertisement-and-nat-traversal.md | Nostr-signaled port advertisement and UDP NAT-traversal protocol; generic, with FIPS as an example implementation |
Deeper Dives
| Document | Description |
|---|---|
| fips-spanning-tree.md | Spanning tree algorithms: root discovery, parent selection, coordinates |
| fips-bloom-filters.md | Bloom filter properties: FPR analysis, size classes, split-horizon |
| spanning-tree-dynamics.md | Spanning tree walkthroughs: convergence scenarios, worked examples |
Adjacent Components
| Document | Description |
|---|---|
| fips-gateway.md | fips-gateway service: outbound (LAN-to-mesh) DNS-proxy + virtual-IP NAT and inbound (mesh-to-LAN) port-forwarding, sharing one nftables table |