mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The incoming-offer semaphore was global with no per-sender accounting and the permit was taken before any identity check, so one sender could hold every slot and deny rendezvous to everyone else. Each sender now has its own allowance with the global count kept as the outer bound. Note what this does and does not do: it raises the cost from one keypair to a small number of them, so a sender willing to spend throwaway identities can still saturate the pool at unchanged total offer rate. The signal freshness bound is only sound while the acceptance window stays strictly inside the replay window, or an offer evicted from the replay cache is still fresh enough to be accepted twice. The relation was stated in a comment and enforced nowhere. Config validation now rejects the bad combination at load, derived from the skew constant rather than a literal, and checked regardless of whether the feature is enabled so that turning it on later cannot surface an error at a surprising moment. The NAT lab config generator produced a combination the new rule rejects and is corrected in the same change. The punch-target filter shipped with no test that would fail if it were reverted. Loopback, link-local and multicast candidates and an oversized list are now covered, and the cap assertion is tightened from a bound to an equality. The private-range inclusion that LAN traversal depends on is pinned as a healthy path so a blanket ban cannot pass. Green: fmt, build, clippy and test --lib, 1533 passed.
Reference
Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.
Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.
Available Reference
| Document | Scope |
|---|---|
| wire-formats.md | All FMP and FSP message byte layouts, encapsulation walkthrough |
| configuration.md | Full YAML configuration reference for the daemon and gateway |
| security.md | nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix |
| nostr-events.md | Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays |
| transports.md | Per-transport statistics counter inventory |
| control-socket.md | Line-delimited JSON control protocol for the daemon and gateway |
| cli-fips.md | fips daemon CLI: options, exit codes, environment, files |
| cli-fipsctl.md | fipsctl control-client: subcommands, options, exit codes |
| cli-fipstop.md | fipstop live-status TUI: tabs, keybindings |
| cli-fips-gateway.md | fips-gateway service CLI: options, exit codes, files |