Files
fips/docs/reference
Johnathan Corgan 01de81a4d6 Merge master into next, carrying the twenty-one security fixes
Nine files conflicted over fifteen hunks. Most were adjacent additions and
resolved as keep-both, but two of the fixes could not be replayed because
next has restructured the code they were written into, so they were
re-derived instead.

0164 could not be replayed because next changed the Ethernet beacon wire
format. parse_beacon returns bool there against Option<XOnlyPublicKey> on
the other two lines, and next's beacon is five bytes carrying no key, so
the bound, its drop counter and its four tests are rewritten against the
pubkey-free signature. next's own BEACON_SIZE == 5 pin is kept; taking
master's side of that hunk would have deleted it.

0161 could not be replayed because next has none of EstablishView,
Msg1Waiver or the inline msg1 arm the dampener was written into, having
moved the establish classification into Fmp::establish_inbound. The gate
therefore lands in the sans-IO core rather than in the driver: the
snapshot gains peering_idle_ms and epoch_restart_dampened, the core
returns a new InboundReject::EpochRestartDampened, and the shell supplies
the two observations and stamps the dampener on acceptance only. Same
fix, re-derived rather than replayed.

That one is why the merge is not a text merge. Keeping master's side of
the src/node/mod.rs hunks alone gave a tree that compiled and passed with
the dampener field and constant present and nothing reading them; the
dead-code warnings were the only thing that said so, and clippy -D
warnings is what would have caught it.

Three of master's new tests referenced APIs next has changed and were
adapted: LookupRequest carries no coordinates on next, and ReceiverReport
has no max_burst_loss, where burst_loss_count already asserts the same
property.

All twenty-one fixes were then checked present on next by construct
rather than inferred from the merge succeeding.
2026-08-23 17:34:44 +01:00
..
2026-05-08 13:45:04 +00:00
2026-08-09 13:41:09 +00:00
2026-08-22 11:04:58 +01:00
2026-08-21 05:55:35 +00:00

Reference

Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.

Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.

Available Reference

Document Scope
wire-formats.md All FMP and FSP message byte layouts, encapsulation walkthrough
configuration.md Full YAML configuration reference for the daemon and gateway
security.md nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix
nostr-events.md Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays
transports.md Per-transport statistics counter inventory
control-socket.md Line-delimited JSON control protocol for the daemon and gateway
native-api.md Native datagram API: the Rust surface, addressing and ports, errno table, ceilings, line protocol, command reference
cli-fips.md fips daemon CLI: options, exit codes, environment, files
cli-fipsctl.md fipsctl control-client: subcommands, options, exit codes
cli-fipstop.md fipstop live-status TUI: tabs, keybindings
cli-fips-gateway.md fips-gateway service CLI: options, exit codes, files