Files
fips/docs
Johnathan Corgan 7adcd851b7 Merge the deployed-line comment sweep and key-material work
Carries the comment sweep, the key-material clearing, and the two
constant-reconciliation commits up from master. Two of the five items on
that line are deliberately excluded, and most of the resolution work was
keeping them out.

Excluded, and why:

- The frame-length validation does not come. This branch needs its own
  design for msg2 and msg3 rather than an extra arm, and that work is
  sequenced separately. It arrived silently in four files that merged
  without a conflict, so it was removed from each: the reject variant,
  the stats counter, the wire helper and its tests, and the receive-path
  call site with the dispatch visibility widening its tests wanted.
  Landing only the counters would have left a metric that reports zero
  forever with nothing able to increment it.
- The post-handshake identity confirmation does not come, and cannot.
  The older lines run a pattern that learns the initiator's static key at
  message 1; this branch does not learn it until message 3, so there is
  no identity to confirm at that point and no insertion point for the
  check. Its type, its classifier and its confirmation block all
  conflicted and were resolved to this branch's side, but two further
  pieces auto-merged with no conflict and had to be removed by hand: the
  module visibility widening, and the classifier call site.
- The transport framing constants are not re-sourced here. This branch
  has rewritten that whole block: message 1 is a different size, message
  2 and message 3 are minimums rather than exact values, and the version
  gate is a different version. Taking the incoming side would have
  sourced a minimum from an exact value.

Carried, with adaptation where the patterns differ:

- Key-material clearing applies to this branch's own handshake, which is
  XX at both layers rather than IK and XK. The incoming code could not be
  taken as written, since it carries whole method bodies for patterns
  this branch does not use. The erasing guard, the parameter erase in
  both constructors, and the clearing of each Diffie-Hellman output and
  secret-key copy were applied to this branch's own sites instead.
- The security and session-layer documents keep this branch's pattern
  names and gain the correction about the handshake AEAD, which passes
  an empty associated-data field here too.
- The drain-window test needed this branch's optional-identity
  constructor, since an anonymous dial is a first-class case here.
2026-08-16 18:08:57 +00:00
..
2026-08-09 13:41:09 +00:00

FIPS Documentation

FIPS (Free Internetworking Peering System) is a self-organizing encrypted mesh network built on Nostr identities, capable of operating over arbitrary transports — local networks, the public internet, Tor, Bluetooth, or point-to-point links — without central infrastructure.

With FIPS, your machine becomes a node in the mesh with a self-generated cryptographic identity. There are two ways to deploy it.

As an overlay on top of existing IP networks, FIPS lets your node reach any other FIPS node wherever it sits — behind a NAT, on a different ISP, on a phone over cellular, on a laptop with only Bluetooth in range, or behind a Tor onion. The mesh forwards IPv6 traffic transparently and end-to-end encrypted, with no central VPN concentrator or coordinating server.

From the ground up over raw Ethernet, WiFi, or Bluetooth, FIPS provides a complete permissionless network without any pre-existing IP infrastructure, ISP, or DNS. Any node that joins the link gets routable IPv6 addresses, peer discovery, and a path to every other node automatically.

Either way, existing networking software runs over it unchanged: SSH, HTTP servers, file transfer, anything IPv6-native works the same way it would on a local network.

New to FIPS? Start with the Getting Started guide.

Documentation Sections

Tutorials

If you are starting from scratch and want a guided path to a working mesh, go here.

How-To Guides

If you have a specific task in mind — enabling a feature, deploying a component, diagnosing a problem — go here.

Reference

If you need to look up wire formats, configuration keys, command flags, or counter inventories, go here.

Design

If you want to understand how the mesh self-organizes, why FIPS makes the choices it does, or how the pieces fit together, go here.