Files
fips/docs/reference
Jeff GardnerandJohnathan Corgan 5e3892edb8 Secure the control socket's runtime directory, and stop chowning /tmp
On any Unix host that falls through to the last-resort
/tmp/fips-control.sock path, bind chowned the socket's parent
unconditionally, and that parent is /tmp itself. A root daemon on such a
host changed the group ownership of /tmp to fips at every start. The mode
was left alone, so nothing lost access, but the ownership was ours to
take and never ours to keep.

macOS has no /run, so the resolver's /var/run/fips arm only fired when
the directory already existed, and nothing on macOS creates it: /var/run
is cleared at boot and the shipped LaunchDaemon has no equivalent of the
FreeBSD rc.d fips_precmd. The packaged macOS daemon has therefore been
landing on /tmp/fips-control.sock every boot. A privileged macOS process
now selects /var/run/fips before its leaf exists, so that bind creates
it, and the clients follow once it is there. The two halves are the same
change: the bootstrap only works if bind may create and secure that
directory, and the /tmp chown had to go before bind could be trusted to.

Which parent bind may secure is keyed on the directory's identity rather
than on which call created it. is_managed_socket_parent matches only the
resolver's own candidates: /run/fips, /var/run/fips where the platform
policy consults it, and $XDG_RUNTIME_DIR/fips. Keying it on creation
alone was tried first and regressed Linux, because systemd removes
RuntimeDirectory=fips when the unit stops and recreates it as root:root
on the next start, while the tmpfiles fragment that sets the fips group
runs only at install and boot. The daemon's own chown was what repaired
that at every bind, so a fips-group operator lost fipsctl after the first
restart following a boot. Matching on identity restores it and still
leaves /tmp, and any operator-configured directory, alone.

The resolver is split into a pure core taking the policy, the
XDG_RUNTIME_DIR value and an is_dir predicate, so the macOS and Linux
policies are both exercised deterministically on a Linux runner with no
environment mutation. The deb-install suite gains the end-to-end half:
after a service restart it asserts /run/fips is 750 root:fips and that a
real non-root fips-group user can reach the socket, which is the property
an operator actually has.

Also corrects a configuration.md paragraph claiming the daemon and the
clients use different fallback orders, which stopped being true when the
resolver order disagreement was resolved and the prose was never updated.
2026-08-13 14:01:30 +00:00
..

Reference

Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.

Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.

Available Reference

Document Scope
wire-formats.md All FMP and FSP message byte layouts, encapsulation walkthrough
configuration.md Full YAML configuration reference for the daemon and gateway
security.md nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix
nostr-events.md Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays
transports.md Per-transport statistics counter inventory
control-socket.md Line-delimited JSON control protocol for the daemon and gateway
cli-fips.md fips daemon CLI: options, exit codes, environment, files
cli-fipsctl.md fipsctl control-client: subcommands, options, exit codes
cli-fipstop.md fipstop live-status TUI: tabs, keybindings
cli-fips-gateway.md fips-gateway service CLI: options, exit codes, files