mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The OpenWrt upgrade fixture was the fips.yaml from the commit before the gateway's DNS port moved, not one any release shipped. Replace it with the v0.5.1 bytes and say which releases it stands for, since v0.3.0 to v0.4.2 shipped an older file with the same legacy listen line. busybox:1.37 moves with every 1.37.x rebuild, so the pin did not keep the shell under test fixed as its comment said. Pin the multi-arch index digest instead, as the tree does for its other third-party images. The comment describing run_ci_parity had drifted above run_openwrt_scripts; move it back to its function. The deb-install header named `apt install` where the script runs `apt-get install -y --no-install-recommends`, and its usage line omitted the --deb option the script accepts. Nothing in the tree read the package's Recommends: the Depends check compares Depends only, and the install test installs with --no-install-recommends. check-deb-depends.sh now compares each package's Recommends with the recommends Cargo.toml declares, in any order, and refuses to pass when that declaration cannot be read.
197 lines
7.1 KiB
YAML
197 lines
7.1 KiB
YAML
# FIPS Node Configuration
|
|
|
|
node:
|
|
identity:
|
|
# By default, a new ephemeral keypair is generated on each start.
|
|
# Uncomment persistent to keep the same identity across restarts;
|
|
# on first start a keypair is saved to fips.key/fips.pub next to
|
|
# this config file (mode 0600/0644).
|
|
# persistent: true
|
|
#
|
|
# Or set an explicit key (overrides persistent):
|
|
# nsec: "nsec1..."
|
|
# Mesh-lookup protocol (node.lookup.*): the overlay coordinate-lookup engine
|
|
# (mesh address -> coordinates). Defaults shown; uncomment to override.
|
|
# lookup:
|
|
# ttl: 64
|
|
# attempt_timeouts_secs: [1, 2, 4, 8]
|
|
# recent_expiry_secs: 10
|
|
# backoff_base_secs: 0
|
|
# backoff_max_secs: 0
|
|
# forward_min_interval_secs: 2
|
|
rendezvous:
|
|
# Optional Nostr-mediated overlay endpoint rendezvous.
|
|
# nostr:
|
|
# enabled: true
|
|
# policy: configured_only # disabled | configured_only | open
|
|
# open_discovery_max_pending: 64 # caps queued open-rendezvous retries
|
|
# app: "fips-overlay-v1"
|
|
# advertise: true
|
|
# advert_relays:
|
|
# - "wss://relay.damus.io"
|
|
# - "wss://nos.lol"
|
|
# - "wss://offchain.pub"
|
|
# dm_relays:
|
|
# - "wss://relay.damus.io"
|
|
# - "wss://nos.lol"
|
|
# - "wss://offchain.pub"
|
|
# # Optional override. If omitted, FIPS uses the built-in STUN list.
|
|
# # Built-in relay/STUN defaults are best-effort and should be
|
|
# # overridden by operators for production use.
|
|
# stun_servers:
|
|
# - "stun:stun.l.google.com:19302"
|
|
# - "stun:stun.cloudflare.com:3478"
|
|
# - "stun:global.stun.twilio.com:3478"
|
|
|
|
# mDNS/DNS-SD peer rendezvous on the local link. Ships commented (the
|
|
# daemon default is off); 'fips-ap-setup' uncomments it when creating
|
|
# the access SSID — phone FIPS apps cannot see raw-Ethernet beacons,
|
|
# so mDNS is how they find this router's daemon. Daemon-wide switch,
|
|
# left enabled on 'fips-ap-setup remove'.
|
|
# lan:
|
|
# enabled: true
|
|
|
|
tun:
|
|
enabled: true
|
|
name: fips0
|
|
mtu: 1280
|
|
|
|
dns:
|
|
enabled: true
|
|
# bind_addr defaults to "::1" (IPv6 loopback). The shipped
|
|
# fips-dns-setup script configures systemd-resolved with a global
|
|
# /etc/systemd/resolved.conf.d/fips.conf drop-in pointing at
|
|
# [::1]:5354.
|
|
#
|
|
# Set "::" to expose the responder to mesh peers as well (e.g. for
|
|
# gateway hosts that resolve .fips on behalf of LAN clients). The
|
|
# mesh-interface filter in src/upper/dns.rs will still defend
|
|
# /etc/fips/hosts aliases from cross-mesh enumeration.
|
|
# bind_addr: "::1"
|
|
port: 5354
|
|
|
|
transports:
|
|
udp:
|
|
# Dual-stack wildcard, not "0.0.0.0": access-SSID clients (phones) learn
|
|
# this node's addresses from the mDNS advert and prefer the IPv6
|
|
# link-local — a v4-only bind silently drops their Noise msg1.
|
|
# OpenWrt is Linux (bindv6only=0), so "[::]" accepts v4 too.
|
|
bind_addr: "[::]:2121"
|
|
# advertise_on_nostr: true
|
|
# public: false # false => advertise udp:nat; true => advertise bound host:port
|
|
# accept_connections: true # default; refuse inbound msg1 when false
|
|
# outbound_only: false # true => bind ephemeral, no listener on a
|
|
# # known port. Forces advertise_on_nostr=false
|
|
# # and accept_connections=false. Pure-client
|
|
# # posture; bind_addr is ignored.
|
|
|
|
tcp:
|
|
# Accepts inbound connections. No static outbound peers.
|
|
bind_addr: "0.0.0.0:8443"
|
|
# advertise_on_nostr: true
|
|
|
|
# Ethernet transport — physical port names, NOT bridge names.
|
|
# Run 'ip link show' on the router to identify port names.
|
|
ethernet:
|
|
wan:
|
|
interface: "eth0"
|
|
listen: true
|
|
announce: true
|
|
auto_connect: true
|
|
accept_connections: true
|
|
wwan:
|
|
interface: "phy0-sta0"
|
|
listen: true
|
|
announce: true
|
|
auto_connect: true
|
|
accept_connections: true
|
|
lan:
|
|
interface: "br-lan"
|
|
listen: true
|
|
announce: true
|
|
auto_connect: true
|
|
accept_connections: true
|
|
|
|
# 802.11s mesh backhaul between FIPS routers. These entries ship
|
|
# commented out so a stock install that never creates fips-mesh*
|
|
# logs no per-boot "interface missing" bind warning. Running
|
|
# 'fips-mesh-setup <radio>' creates the interface AND uncomments the
|
|
# matching block here (once per radio; radio0 -> fips-mesh0, radio1 ->
|
|
# fips-mesh1); 'fips-mesh-setup remove' re-comments it. Restart fips
|
|
# after — a transport whose interface is missing at startup is skipped,
|
|
# not retried. Dual-band routers can mesh on both bands at once —
|
|
# failover, not multipath: FIPS keeps one active link per peer, the
|
|
# other band stands by. The mesh runs OPEN (no SAE) with 802.11s
|
|
# forwarding off: FIPS's Noise handshake is the encryption and
|
|
# authentication, and FIPS is the routing layer. See
|
|
# docs/how-to/set-up-80211s-mesh-backhaul.md.
|
|
# mesh0:
|
|
# interface: "fips-mesh0"
|
|
# listen: true
|
|
# announce: true
|
|
# auto_connect: true
|
|
# accept_connections: true
|
|
# mesh1:
|
|
# interface: "fips-mesh1"
|
|
# listen: true
|
|
# announce: true
|
|
# auto_connect: true
|
|
# accept_connections: true
|
|
|
|
# Open "!FIPS" access SSID for phones and laptops running FIPS. These
|
|
# entries ship commented out so a stock install that never creates
|
|
# fips-ap* logs no per-boot "interface missing" bind warning. Running
|
|
# 'fips-ap-setup <radio>' creates the interface AND uncomments the
|
|
# matching block here (once per radio; radio0 -> fips-ap0, radio1 ->
|
|
# fips-ap1); 'fips-ap-setup remove' re-comments it. Restart fips after
|
|
# — a transport whose interface is missing at startup is skipped, not
|
|
# retried. The SSID is OPEN and isolated on purpose: FIPS's Noise
|
|
# handshake is the only security layer, and associated clients reach
|
|
# nothing but the FIPS handshake surface. See
|
|
# docs/how-to/set-up-open-access-ssid.md.
|
|
# ap0:
|
|
# interface: "fips-ap0"
|
|
# listen: true
|
|
# announce: true
|
|
# auto_connect: true
|
|
# accept_connections: true
|
|
# ap1:
|
|
# interface: "fips-ap1"
|
|
# listen: true
|
|
# announce: true
|
|
# auto_connect: true
|
|
# accept_connections: true
|
|
|
|
# Bluetooth Low Energy transport — requires BlueZ and the 'ble' feature.
|
|
# ble:
|
|
# adapter: "hci0"
|
|
# mtu: 2048
|
|
# advertise: true
|
|
# scan: true
|
|
# auto_connect: true
|
|
# accept_connections: true
|
|
|
|
# Outbound LAN gateway. dnsmasq forwards .fips queries to listen=[::1]:5353
|
|
# (configured by the fips init script). Requires IPv6 forwarding enabled.
|
|
gateway:
|
|
enabled: true
|
|
pool: "fd01::/112"
|
|
lan_interface: "br-lan"
|
|
dns:
|
|
listen: "[::1]:5353"
|
|
upstream: "[::1]:5354"
|
|
ttl: 60
|
|
pool_grace_period: 60
|
|
|
|
peers: []
|
|
# Static peers for bootstrapping (UDP or TCP):
|
|
# - npub: "npub1qmc3cvfz0yu2hx96nq3gp55zdan2qclealn7xshgr448d3nh6lks7zel98"
|
|
# alias: "gateway"
|
|
# via_nostr: true
|
|
# addresses:
|
|
# - transport: udp
|
|
# addr: "test-us01.fips.network:2121" # IP or hostname (e.g., "peer.example.com:2121")
|
|
# - transport: udp
|
|
# addr: "nat" # Use node.rendezvous.nostr for Nostr/STUN hole punching
|
|
# connect_policy: auto_connect
|