Files
fips/packaging
Johnathan Corgan 23c6609a6e Ship fips0 nftables security baseline (Linux)
Add a default-deny nftables ruleset for the fips0 mesh interface as
a packaged operator asset, with a companion fips-firewall.service
oneshot unit for systemd hosts. Both are shipped disabled — the
baseline is an operator conffile and the unit is intentionally not
enabled in postinst. Activation is an explicit one-liner:

  sudo systemctl enable --now fips-firewall.service

This is deliberate: silently mutating host firewall state on package
install is hostile across the axes that matter (collisions with
existing operator nftables / Docker / OPNsense rulesets, surprise
behaviour for hosts that already filter elsewhere, conversion of an
explicit security decision into an invisible one). The opt-in
posture preserves operator agency.

The baseline closes a real default-exposure gap: any service on a
mesh host bound to a wildcard address (0.0.0.0 or [::]) is
reachable from every authenticated peer in the mesh by default.
Identity on the mesh is the peer's npub but identity is not
authorization, and the mesh is closer to a shared LAN than to the
public internet. With this filter loaded, the surface is closed
unless a drop-in opens it explicitly.

Baseline shape:
- Early-return for non-fips0 traffic (every other firewall left
  undisturbed)
- conntrack established/related accept (replies to outbound flows)
- ICMPv6 echo-request accept (ping6 reachability)
- include "/etc/fips/fips.d/*.nft" — operator-supplied allowances
- counter drop default

The accompanying docs/fips-security.md lays out the threat model
(npub-authenticated mesh is closer to a shared LAN than to the
public internet — identity is not authorization), the activation
workflow, drop-in extension recipes (allow inbound SSH from a
specific peer fd97:.../128, allow HTTP from one /64, etc), drop
visibility / debugging via the journal log rule and the drop
counter, coexistence with the runtime-managed `inet fips_gateway`
table, what the baseline does NOT cover (outbound, application
auth, mesh handshake ACL = PR #50 / IDEA-0047 territory), and
future cross-OS work (macOS PF baseline, OpenWrt fw4, gateway
abstraction).

Packaging:
- packaging/common/fips.nft       → /etc/fips/fips.nft (conffile)
- packaging/debian/fips-firewall.service → /lib/systemd/system/
- docs/fips-security.md           → /usr/share/doc/fips/
- postinst creates /etc/fips/fips.d/ (mode 0755) on configure
- prerm stops/disables fips-firewall.service on remove/purge

OpenWrt fw4 path and macOS PF baseline are deferred — separate
asymmetries, separate work.
2026-04-30 03:10:56 +00:00
..
2026-04-11 18:31:48 +01:00
2026-04-11 18:31:48 +01:00

FIPS Packaging

This directory contains packaging for all supported target platforms. All build outputs go to deploy/ at the project root.

Quick Start

make deb        # Debian/Ubuntu .deb
make tarball    # systemd install tarball
make ipk        # OpenWrt .ipk
make aur        # Arch Linux AUR package (fips-git, local build + namcap)
make pkg        # macOS .pkg installer
make zip        # Windows .zip package
make all        # deb + tarball (default)

Directory Structure

packaging/
  aur/            Arch Linux AUR packaging (PKGBUILD, supporting files)
  common/         Shared assets (default config, hosts file)
  debian/         Debian/Ubuntu .deb packaging via cargo-deb
  macos/          macOS .pkg installer via pkgbuild
  systemd/        Generic Linux systemd tarball packaging
  openwrt/        OpenWrt .ipk packaging via cargo-zigbuild
  windows/        Windows .zip package with service scripts

Formats

Debian/Ubuntu (.deb)

Built with cargo-deb. Installs fips, fipsctl, and fipstop to /usr/bin/, places config at /etc/fips/fips.yaml (preserved on upgrade), and enables the systemd service.

# Build
make deb

# Install
sudo dpkg -i deploy/fips_<version>_<arch>.deb

# Remove (preserves config and keys)
sudo dpkg -r fips

# Purge (removes config and identity keys)
sudo dpkg -P fips

systemd Tarball

A self-contained tarball with binaries and an install.sh script for any systemd-based Linux distribution.

# Build
make tarball

# Install (on target host)
tar -xzf deploy/fips-<version>-linux-<arch>.tar.gz
sudo ./fips-<version>-linux-<arch>/install.sh

See systemd/README.install.md for full installation and configuration instructions.

OpenWrt (.ipk)

Cross-compiled with cargo-zigbuild and assembled as a standard .ipk archive. Supports aarch64, mipsel, mips, arm, and x86_64 targets.

# Build (default: aarch64)
make ipk

# Build for a specific architecture
bash packaging/openwrt/build-ipk.sh --arch mipsel

See openwrt/README.md for router-specific installation instructions.

macOS (.pkg)

Built with pkgbuild (included with Xcode command-line tools). Installs binaries to /usr/local/bin/, config to /usr/local/etc/fips/, sets up the /etc/resolver/fips DNS resolver for .fips domains, and loads a launchd daemon. The TUN device is named utun<N> (kernel-assigned) rather than fips0.

# Build
make pkg

# Install
sudo installer -pkg deploy/fips-<version>-macos-<arch>.pkg -target /

# Remove
sudo packaging/macos/uninstall.sh

Windows (.zip)

A ZIP archive containing binaries, default config, and PowerShell service helper scripts. Requires the wintun driver for TUN support.

# Build
make zip

# Or directly
powershell -File packaging/windows/build-zip.ps1

# Extract and install as service (requires Administrator)
Expand-Archive deploy\fips-<version>-windows-x86_64.zip -DestinationPath fips
cd fips
powershell -File install-service.ps1

# Uninstall (preserves config)
powershell -File uninstall-service.ps1

# Uninstall and remove config
powershell -File uninstall-service.ps1 -RemoveAll

Arch Linux (AUR)

Two AUR packages are maintained: fips (release, builds from tagged tarball) and fips-git (development, builds from latest git master).

# Build and validate locally (git variant)
make aur

# Install from AUR
yay -S fips-git    # development build from master
yay -S fips        # release build from latest tag

See aur/README.md for AUR publication instructions and maintainer guide.

Shared Assets

common/ contains assets used across packaging formats:

  • fips.yaml — default configuration (ephemeral identity, UDP/TCP/TUN/DNS)
  • hosts — static hostname-to-npub mappings for .fips DNS resolution