Files
fips/docs/how-to
Johnathan Corgan 8b396b662d Keep the daemon's copy of a native API descriptor until the client holds it
A native API flow's descriptor reaches the client inside a message: an
arrival for a flow a listener accepts, or a connect or listen reply. The
daemon closed its own copy once the message was written, so until the client
read it, the message was the only reference to the socket. xnu's descriptor
collector flushes a socket in that state, and the client then receives a
flow that reads as end of file with the datagrams the daemon held for it
gone. That is the intermittent macOS failure of the two listener tests.

A listener now keeps the daemon's copy of each flow it hands over until the
client's first write on the flow, the listener's close, or the flow's end, on
every platform the listener builds on. The flow is recorded before its reader
starts, so a write already queued cannot race the record. The connection's
serving loop, now a method on the connection so a test can run it over a real
socket, keeps the copy sent in a connect or listen reply until the client's
next command on that connection or the connection's end of file. A client
sends its next command only after reading the reply, so either event means
the descriptor has left the message. The shipped client closes the connection
as soon as it has the reply, so it sees no change.

The cost is accepted and documented: a flow a client accepts and closes
without ever writing stays open, holding its port and a flow slot, until the
listener closes, so a server that refuses flows by dropping them pays for each
one until then; a client speaking the protocol directly that leaves its setup
connection open sees a flow or listener it closes stay open until its next
command or the connection's close. The reference and how-to pages, the client
rustdoc on FipsStream, FipsListener and accept, and the design note say so,
and the security reference records that a remote peer opening flows from many
source ports to such a server can exhaust the node-wide max_flows ceiling.

Tests cover an arrival surviving a provoked collection (deterministic on
macOS), a held flow outliving its dropped descriptor until the listener
closes, a client's write releasing it, a flow its client still holds working
after the listener has closed and let its copy go, and a reply's copy kept
until the next command and let go when the connection ends. The native API
harness asserts the new lifetime of a refused flow. On macOS and FreeBSD the
daemon notices a client's close only when a reader retries its read, up to a
quarter second later, so the test helpers that wait for a close (forgotten,
rebind, settle_closed) retry for up to five seconds by the clock rather than
for a count of yields, and still_open waits two retry intervals there before
asserting a flow is still open.
2026-10-01 22:40:40 +00:00
..

How-To Guides

Task-oriented, step-by-step recipes for operators with a specific goal in mind. Each guide assumes the reader already knows what FIPS is and wants to get a particular thing done — enable a feature, deploy a component, troubleshoot a class of problem.

How-to guides do not teach concepts (that is the role of design/) and do not enumerate options (that is the role of reference/). They take the reader along the shortest correct path from "I want to do X" to "X is done".

Available Guides

Guide Goal
enable-mesh-firewall.md Activate the default-deny nftables baseline on fips0
enable-nostr-discovery.md Turn on Nostr-mediated discovery (3 capabilities — resolve, advertise, open — across 5 scenarios)
deploy-tor-onion.md Run a Tor onion service for inbound FIPS connections
tune-udp-buffers.md Set host sysctls so FIPS UDP sockets don't get clamped
tune-file-descriptors.md Raise RLIMIT_NOFILE so a busy node doesn't exhaust file descriptors (EMFILE) as peer count grows
run-as-unprivileged-user.md Run the daemon under a dedicated unprivileged service account (drops the default-root posture)
deploy-gateway.md Manually deploy fips-gateway on a non-OpenWrt Linux host (LAN-to-mesh outbound + mesh-to-LAN inbound port-forwards). For the OpenWrt path, see the gateway tutorial.
troubleshoot-gateway.md Diagnostic recipes for the gateway, organised by half (outbound, inbound, common)
persistent-identity.md Provision a stable Nostr keypair so the node keeps the same npub across restarts
host-aliases.md Use shortnames (test-us01.fips, my-laptop.fips) instead of full npubs by editing /etc/fips/hosts or setting peer aliases
set-up-bluetooth-peer.md Configure a Bluetooth Low Energy peer link
set-up-80211s-mesh-backhaul.md Link OpenWrt FIPS routers over an open 802.11s radio backhaul (FIPS provides encryption, authentication, and routing)
set-up-open-access-ssid.md Broadcast the open !FIPS access SSID so phones and laptops roam onto the mesh (one ESS: save once, roam every FIPS router)
diagnose-mtu-issues.md Triage MTU-shaped failures and rule out their imposters (bufferbloat, transport saturation)
use-the-native-datagram-api.md Enable the experimental native datagram API and write a program that sends and receives datagrams by pubkey and port (no IPv6 emulation, no TUN). Read the fips group warning first
write-a-native-api-client.md Speak the native datagram API's line protocol directly from C, Python or Go, where there is no client library
serve-many-peers-on-one-thread.md Handle every native API flow from one poll loop instead of a thread per peer