mirror of
https://github.com/jmcorgan/fips.git
synced 2026-08-09 00:04:54 +00:00
Noise IK parity fix: - Pre-message hash normalizes responder static key to even parity (0x02) so initiator and responder hash chains match regardless of actual parity - ECDH uses shared_secret_point() + SHA-256(x-only) instead of SharedSecret::new() which includes a parity-dependent version byte - Fixes handshake failure for ~50% of keys when initiator has only npub Graceful disconnect protocol (link message 0x50): - DisconnectReason enum with 8 reason codes - Disconnect struct with encode/decode - send_encrypted_link_message() reusable helper - handle_disconnect() with immediate peer removal - send_disconnect_to_all_peers() called during Node::stop() Cross-connection fix in handle_msg1(): - addr_to_link check now distinguishes inbound duplicates (reject) from outbound links (cross-connection, allow and resolve via tie-breaker) - remove_link() only clears addr_to_link if entry maps to same link_id - Link cleanup and addr_to_link restoration in cross-connection branches Handshake timeout cleanup: - RX loop uses tokio::select! with 1-second interval tick - check_timeouts() scans for stale (>30s) and failed connections - cleanup_stale_connection() removes all associated state Tests: 279 passing (4 new: cross-connection, stale cleanup, failed cleanup, odd-parity handshake)
FIPS Design Documents
Protocol design specifications and analysis for the Federated Interoperable Peering System.
Suggested Reading Order
Start with the high-level architecture, then work through session flow, routing concepts, and finally the wire-level protocol details.
1. Introduction and Overview
| Document | Description |
|---|---|
| fips-intro.md | Protocol introduction: goals, concepts, architecture |
2. Protocol Flow (How Traffic Works)
| Document | Description |
|---|---|
| fips-session-protocol.md | End-to-end session flow, Noise IK encryption, terminology |
3. Routing (How Packets Find Their Way)
| Document | Description |
|---|---|
| fips-routing.md | Routing concepts: bloom filters, discovery, greedy routing |
| spanning-tree-dynamics.md | Tree protocol behavior: convergence, partitions, recovery |
| fips-gossip-protocol.md | Wire formats: TreeAnnounce, FilterAnnounce, Lookup messages |
4. Link Layer (How Peer Connections Work)
| Document | Description |
|---|---|
| fips-wire-protocol.md | Transport layer: Noise IK, session indices, roaming, security |
| fips-transports.md | Transport-specific: UDP, Ethernet, Tor, radio characteristics |
Implementation
| Document | Description |
|---|---|
| fips-architecture.md | Software architecture: entities, state machines, configuration |
| fips-tun-driver.md | TUN interface driver: reader/writer threads, ICMPv6, packet flow |
| fips-state-machines.md | Phase-based state machine pattern: peer lifecycle, transitions |
Document Cross-References
fips-intro.md
│
┌────────────┴────────────┐
▼ ▼
fips-session-protocol.md fips-architecture.md
│ │
┌─────────┴─────────┐ ▼
▼ ▼ fips-transports.md
fips-routing.md fips-wire-protocol.md
│ │
▼ ▼
spanning-tree-dynamics.md ←→ fips-gossip-protocol.md