mirror of
https://github.com/jmcorgan/fips.git
synced 2026-08-09 16:24:45 +00:00
Wire format diagrams: - Add 24 SVG diagrams covering every FMP and FSP wire format: common prefix, established frame headers, Noise IK handshake messages, handshake flow, TreeAnnounce, AncestryEntry, FilterAnnounce, LookupRequest/Response, SessionDatagram, Disconnect, SenderReport, ReceiverReport, FSP complete message, SessionSetup/Ack/Msg3, PathMtuNotification, CoordsRequired, PathBroken, and MtuExceeded - Replace ASCII art in fips-wire-formats.md with SVG references - Apply text edits to fips-mesh-layer.md, fips-mesh-operation.md, fips-transport-layer.md, and fips-ipv6-adapter.md Spanning tree dynamics: - Add 12 topology SVG diagrams: node join (overview + 3-panel steps), three-node convergence (4-panel), link addition with depth labels, link removal, partition formation, and 6 real-world example diagrams (office, mixed-link, two-site WAN topologies) - Rewrite all code blocks to narrative prose with diagram references - Add inline prior art attributions distinguishing Yggdrasil-derived concepts from FIPS-novel contributions - Add 3 new references (De Couto ETX, IEEE 802.1D, RFC 2328 OSPF) and Prior Art summary - Remove outdated sections: indirect partition note, integration test gaps, DHT-based lookup reference - Change "must elect a new root" to "must rediscover its new root" Spanning tree design review (fips-spanning-tree.md): - Rename "Root Election" to "Root Discovery" across docs - Add "What Is a Spanning Tree?" introductory section - Add parent selection intro explaining self-organization role - Fix tree distance example: 4 hops, not 2 - Clarify timestamp field as advisory only - Remove unimplemented ROOT_TIMEOUT and TREE_ENTRY_TTL from timing parameters and implementation status tables Bloom filter design review (fips-bloom-filters.md): - Add "What Is a Bloom Filter?" intro section - Rewrite Purpose section to frame filters as routing path identification - Correct FPR analysis (old values were 3-50x overstated) - Add Filter Occupancy Model based on network size and tree position - Fix filter expiration to describe actual MMP-based cleanup - Combine Scale Considerations with Size Classes after Wire Format - Fix stale FPR values in src/bloom/mod.rs comments Session layer review (fips-session-layer.md): - Add inline prior art attributions: Noise Protocol Framework, WireGuard, DTLS (RFC 6347), IKEv2 (RFC 7296), RFC 1191 PMTUD, Yggdrasil, NIP-44 - Replace warmup state machine ASCII art with SVG diagram - Convert CoordsWarmup wire format code block to prose - Add External References section with full citations Level 5 implementation doc cleanup: - Delete fips-software-architecture.md (redundant with protocol layer docs) - Delete fips-state-machines.md (Rust tutorial, not protocol design) - Add fipsctl command reference to README.md - Update cross-references in fips-intro.md, docs/design/README.md, fips-transport-layer.md, fips-configuration.md Fixes: - Correct fd::/8 to fd00::/8 in fips-session-layer.md, fips-identity-derivation.svg, and fips-node-architecture.svg - Fix config example MTU: 1197 → 1472 in fips-configuration.md File organization: - Move all SVG diagrams into docs/design/diagrams/ subdirectory - Update all diagram references to use new paths
50 lines
2.8 KiB
XML
50 lines
2.8 KiB
XML
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 895 620" font-family="monospace" font-size="15">
|
|
<style>
|
|
rect.layer { rx: 5; }
|
|
rect.app { fill: #1a3a2a; stroke: #40a060; stroke-width: 2; }
|
|
rect.fsp { fill: #2a2040; stroke: #8060c0; stroke-width: 2; }
|
|
rect.fmp { fill: #2e3a5e; stroke: #5080c0; stroke-width: 2; }
|
|
rect.xport { fill: #2a1a1a; stroke: #c06040; stroke-width: 2; }
|
|
text { fill: #e0e0e0; }
|
|
text.name { font-size: 23px; font-weight: bold; }
|
|
text.desc { font-size: 18px; fill: #a0a0b0; }
|
|
text.scope { font-size: 17px; fill: #707080; font-style: italic; }
|
|
text.caption { font-size: 18px; fill: #808090; font-style: italic; }
|
|
</style>
|
|
|
|
<!-- Background -->
|
|
<rect width="875" height="560" fill="#0d1117" rx="10"/>
|
|
|
|
<!-- Applications layer -->
|
|
<rect x="50" y="25" width="775" height="100" class="layer app"/>
|
|
<text x="75" y="58" class="name">Application Layer Interface</text>
|
|
<text x="75" y="78" class="desc">Native FIPS API — for FIPS-aware applications</text>
|
|
<text x="75" y="98" class="desc">IPv6 Shim — for traditional IP application backward compatibility</text>
|
|
|
|
<!-- FSP layer -->
|
|
<rect x="50" y="150" width="775" height="120" class="layer fsp"/>
|
|
<text x="75" y="183" class="name">FIPS Session Protocol (FSP)</text>
|
|
<text x="75" y="205" class="desc">End-to-end authenticated encryption between endpoints</text>
|
|
<text x="75" y="225" class="desc">Session lifecycle, path discovery, in-band metrics</text>
|
|
<text x="75" y="245" class="desc">Replay protection, forward secrecy, identity privacy</text>
|
|
<text x="800" y="183" class="scope" text-anchor="end">end-to-end</text>
|
|
|
|
<!-- FMP layer -->
|
|
<rect x="50" y="295" width="775" height="120" class="layer fmp"/>
|
|
<text x="75" y="328" class="name">FIPS Mesh Protocol (FMP)</text>
|
|
<text x="75" y="350" class="desc">Hop-by-hop peer authentication, link encryption, liveness detection</text>
|
|
<text x="75" y="370" class="desc">Spanning tree, bloom filters, routing, forwarding, repair</text>
|
|
<text x="75" y="390" class="desc">Link quality monitoring, maintenance, optional discovery</text>
|
|
<text x="800" y="328" class="scope" text-anchor="end">hop-by-hop</text>
|
|
|
|
<!-- Transport layer -->
|
|
<rect x="50" y="440" width="775" height="95" class="layer xport"/>
|
|
<text x="75" y="473" class="name">Transport Layer</text>
|
|
<text x="800" y="473" class="scope" text-anchor="end">(overlay, shared medium, point-to-point)</text>
|
|
<text x="75" y="495" class="desc">Datagram delivery over arbitrary media</text>
|
|
<text x="75" y="515" class="desc">UDP, Ethernet, WiFi, Bluetooth, Tor, serial, ...</text>
|
|
|
|
<!-- Caption -->
|
|
<text x="438" y="585" text-anchor="middle" class="caption">FIPS protocol layer stack — three layers with clean service boundaries</text>
|
|
</svg>
|