Files
fips/docs/reference
Johnathan Corgan 19d8537e97 Stop unauthenticated messages destroying a live key epoch, and meter the setup path
Three changes to FSP session handling.

Five sites discarded a completed key epoch when only a handshake had
failed. Four are the failure paths in the rekey msg3 responder arm; the
fifth is the dual-initiation yield arm in the setup handler, which is
gated on a rekey being in progress rather than on us having initiated it,
so a peer-armed entry holding a completed epoch reaches it. All five now
abandon only the handshake. Reachable in two unauthenticated messages
once a completed epoch has waited out a full idle timeout. The four
remaining sites in the ack initiator arm are left alone, and the reason
is recorded at the site: an entry with the initiator flag set holds no
pending session, so the two calls are the same action there.

A forged ack of valid length destroyed an in-flight initiation, because
the handler removed the entry before it knew the message was genuine.
The entry is now put back. Reinserting alone is not enough: reading msg2
mixes the sender ephemeral into the symmetric state before authenticating
it, so the kept handshake could never read the genuine msg2 afterwards
and re-initiation was blocked until timeout. A wrapper restores the exact
state the read writes when it fails. That mirror is maintained by hand
and says so.

The setup path passed no rate limiter, so forged msg1 naming distinct
addresses inserted half-open entries without bound. It is now metered on
the authenticated link peer the datagram arrived over, not the sender
chosen address, which varying the address would defeat. Setups naming an
already-established peer get their own budget, so a flood behind one link
cannot silently suppress rekey for everything else behind it. A refused
setup sends nothing, which also bounds the ack amplification.

Green: fmt, build, clippy and test --lib, 1535 passed.
2026-08-15 07:23:20 +00:00
..

Reference

Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.

Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.

Available Reference

Document Scope
wire-formats.md All FMP and FSP message byte layouts, encapsulation walkthrough
configuration.md Full YAML configuration reference for the daemon and gateway
security.md nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix
nostr-events.md Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays
transports.md Per-transport statistics counter inventory
control-socket.md Line-delimited JSON control protocol for the daemon and gateway
cli-fips.md fips daemon CLI: options, exit codes, environment, files
cli-fipsctl.md fipsctl control-client: subcommands, options, exit codes
cli-fipstop.md fipstop live-status TUI: tabs, keybindings
cli-fips-gateway.md fips-gateway service CLI: options, exit codes, files