mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
Add fips-gateway binary: a separate daemon that allows unmodified LAN hosts to reach FIPS mesh destinations via DNS-allocated virtual IPs and kernel nftables NAT. Gateway DNS resolver: forwarding proxy on [::]:53 that intercepts .fips queries, forwards to daemon resolver (localhost:5354), allocates virtual IPs from pool, returns AAAA records. Always sends AAAA upstream regardless of client query type, returns proper NODATA for non-AAAA. Virtual IP pool: fd01::/112 pool with state machine lifecycle (Allocated → Active → Draining → Free), TTL-based reclamation, conntrack integration for session tracking. NAT manager: nftables DNAT/SNAT rules via rustables netlink API, per-mapping rule lifecycle, fips0 masquerade for LAN client source address rewriting. Network setup: local pool route, proxy NDP for virtual IPs on LAN interface, IPv6 forwarding validation. Control socket at /run/fips/gateway.sock with show_gateway and show_mappings queries. fipstop Gateway tab with pool summary gauge and mappings table. Gateway config section in fips.yaml with pool CIDR, LAN interface, DNS upstream, TTL, and grace period settings. Design doc at docs/design/fips-gateway.md. Integration test (testing/static/scripts/gateway-test.sh): three containers verifying DNS resolution, end-to-end HTTP, NAT state, TTL expiration, SERVFAIL fallback, and clean shutdown.
90 lines
3.0 KiB
TOML
90 lines
3.0 KiB
TOML
[package]
|
|
name = "fips"
|
|
version = "0.3.0-dev"
|
|
edition = "2024"
|
|
description = "A distributed, decentralized network routing protocol for mesh nodes connecting over arbitrary transports"
|
|
license = "MIT"
|
|
authors = ["Johnathan Corgan <jcorgan@corganlabs.com>"]
|
|
repository = "https://github.com/jmcorgan/fips"
|
|
readme = "README.md"
|
|
|
|
[features]
|
|
default = ["tui", "ble"]
|
|
tui = ["dep:ratatui"]
|
|
ble = ["dep:bluer"]
|
|
|
|
[dependencies]
|
|
ratatui = { version = "0.30", optional = true }
|
|
secp256k1 = { version = "0.30", features = ["rand", "global-context"] }
|
|
sha2 = "0.10"
|
|
hkdf = "0.12"
|
|
chacha20poly1305 = "0.10"
|
|
rand = "0.10.0"
|
|
thiserror = "2.0"
|
|
bech32 = "0.11"
|
|
serde = { version = "1.0", features = ["derive"] }
|
|
serde_json = "1.0"
|
|
serde_yaml = "0.9"
|
|
dirs = "6.0"
|
|
hex = "0.4"
|
|
clap = { version = "4.5", features = ["derive"] }
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
|
tun = { version = "0.8.5", features = ["async"] }
|
|
libc = "0.2"
|
|
rtnetlink = "0.20.0"
|
|
tokio = { version = "1", features = ["rt", "macros", "signal", "sync", "net", "time", "process"] }
|
|
futures = "0.3"
|
|
simple-dns = "0.11.2"
|
|
socket2 = { version = "0.6.2", features = ["all"] }
|
|
tokio-socks = "0.5"
|
|
bluer = { version = "0.17", features = ["bluetoothd", "l2cap"], optional = true }
|
|
rustables = "0.8.7"
|
|
|
|
[package.metadata.deb]
|
|
maintainer = "Johnathan Corgan <jcorgan@corganlabs.com>"
|
|
copyright = "2026 Johnathan Corgan"
|
|
license-file = ["LICENSE", "0"]
|
|
section = "net"
|
|
priority = "optional"
|
|
depends = "libc6, systemd, libdbus-1-3"
|
|
recommends = "bluez"
|
|
extended-description = """\
|
|
FIPS is a distributed, decentralized network routing protocol for mesh \
|
|
nodes connecting over arbitrary transports including UDP, TCP, Ethernet, \
|
|
Tor, and Bluetooth (BLE). It provides encrypted peer-to-peer connectivity \
|
|
with automatic key management, TUN-based virtual networking, and .fips DNS \
|
|
resolution."""
|
|
maintainer-scripts = "packaging/debian/"
|
|
assets = [
|
|
["target/release/fips", "/usr/bin/", "755"],
|
|
["target/release/fipsctl", "/usr/bin/", "755"],
|
|
["target/release/fipstop", "/usr/bin/", "755"],
|
|
["packaging/common/fips.yaml", "/etc/fips/fips.yaml", "600"],
|
|
["packaging/common/hosts", "/etc/fips/hosts", "644"],
|
|
["packaging/debian/fips.service", "/lib/systemd/system/fips.service", "644"],
|
|
["packaging/debian/fips-dns.service", "/lib/systemd/system/fips-dns.service", "644"],
|
|
["packaging/debian/fips.tmpfiles", "/usr/lib/tmpfiles.d/fips.conf", "644"],
|
|
["target/release/fips-gateway", "/usr/bin/", "755"],
|
|
["packaging/debian/fips-gateway.service", "/lib/systemd/system/fips-gateway.service", "644"],
|
|
]
|
|
conf-files = ["/etc/fips/fips.yaml", "/etc/fips/hosts"]
|
|
|
|
[dev-dependencies]
|
|
tempfile = "3.15"
|
|
criterion = { version = "0.8.2", features = ["html_reports"] }
|
|
tokio = { version = "1", features = ["test-util"] }
|
|
|
|
[[bin]]
|
|
name = "fipsctl"
|
|
path = "src/bin/fipsctl.rs"
|
|
|
|
[[bin]]
|
|
name = "fips-gateway"
|
|
path = "src/bin/fips-gateway.rs"
|
|
|
|
[[bin]]
|
|
name = "fipstop"
|
|
path = "src/bin/fipstop/main.rs"
|
|
required-features = ["tui"]
|