mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
Everything the release needs except the version number, which stays at 0.5.0-dev until the tag. The changelog entry covers only the work that is new on this line. The point release's forty-six entries arrived under their own heading with the forward merge and are left alone; the twenty that remained are regrouped by topic and eight more added for changes no entry covered. Three of those eight matter to someone upgrading. Five root modules and four re-exports left the public library surface and Node::connections narrowed, none of it recorded anywhere; the entry names what to use instead and distinguishes the removed connection-phase enum from the Noise type of the same name, which is a different type that still exists. Tracing targets moved, so an existing RUST_LOG filter stops matching rather than erroring. And the handshake resend interval key no longer governs the first resend, which is now a constant, though it still governs later ones. Seven more entries cover the work that landed after the first content pass was written: the experimental native datagram API, the fipsctl probe diagnostic, per-instance transport addressing, the app-owned UDP socket seam, and the connect, disconnect and path-MTU fixes. The four bug fixes among them all reach the deployed line, so the release notes no longer claim this release carries exactly one fix for a shipped bug; it carries four. There is no security section, because after the split every security entry belongs to the point release. The release notes say so plainly rather than leaving a reader upgrading across both releases to conclude this one carries no security work. The notes are organized by audience, since the release spans OpenWrt routers, embedders, FreeBSD, and the existing platforms, and a single list serves none of them. The native datagram API is given a section of its own rather than folded into the embedding seam: it is a client-facing API rather than a way to host a node, and its one rule with no Berkeley-socket counterpart, that the v1 wire carries no half-close, needs to be somewhere a client author will read it. FreeBSD is advertised as supported on x86_64 only, stated wherever the platform appears. Android is advertised as an embedding seam and not as a supported platform: a compile-gated library surface with no artifact and no host application guide. The configuration table rename is carried through every shipped file that taught the old spelling: nine documentation files, the OpenWrt sample config and a test generator, twenty-two sites in all. Guides written this same cycle were among them, which is how the omission was found. The documentation that arrived with the native API was checked for the same omission and was already clean. The compatibility tests keep the old spelling deliberately, since they exist to test the fold. The changelog section is the fold of master's [Unreleased], not a snapshot of it. An earlier version of this commit took a copy that then drifted, so each section ended up holding a bullet the other did not and re-folding them would have picked a winner silently. Both causes were fixed on master instead — the NixOS module had never been recorded there, and the pre-release batch of fixes was new — so [Unreleased] is a strict superset and this is a copy rather than a merge. [0.5.0] carries all forty-six bullets byte for byte, [Unreleased] is empty, and [0.4.2] is untouched, checked by hashing it against master's copy. The BLE work landed after the content pass and gets one summary entry in the changelog and one section in the release notes rather than nine bullets: the ble_available gate replacing target_os = "linux", packet-boundary recovery for stream-oriented backends, peer recognition by node identity instead of a rotating link address, the L2CAP PSM moving into the backend seam and onto the advertisement, the embedder-supplied Android radio, bounded probe retry, and inbound handshakes moved off the accept loop. The two release-notes copies no longer share their link paths. Relative links resolve from one directory only, so the seven written for docs/releases/ all 404ed from the root copy. The root copy now uses paths from the repository root and the versioned copy keeps the ../ form; both sets were resolved against the tree. The same two links are broken the same way in the v0.4.0 through v0.4.2 notes, left as shipped history. The contributor tallies are re-derived against maint..HEAD rather than adjusted: twenty commits from outside the project and 171 from me, with Arjen at fifteen and fr34aky at two. An earlier count of twelve and 138 was carried from a measurement taken three days before this content was written, and the BLE branch widened the gap after it. Arjen's NixOS flake module, the UDP sin6_scope_id fix and most of the BLE rework were uncredited, as was fr34aky's L2CAP PSM seam. They want one last re-derive at tag time if anything lands before the tag. A sweep of all 99 tracked markdown files against the tree corrected fifty-three of them. Four told the reader to run a build.sh that does not exist; the only harness builder is testing/scripts/build.sh. The BLE build prerequisites were described as optional on the strength of a probe that build.rs does not perform, and bluez was named a build prerequisite when libdbus-sys asks only for libdbus-1-dev and pkg-config and bluez is the runtime daemon. Link cost is the primary sort key in next-hop ranking, not reserved for future use; Ethernet runs on macOS as well as Linux; the BLE MTU is the L2CAP CoC MTU rather than a negotiated ATT_MTU; effective Ethernet MTU is 1497; the LAN discovery subsystem is src/mdns and eight citations still named a src/discovery that never existed here. The connectivity states in three tutorials were invented, and their jq filters matched nothing including healthy peers. One command filtered on a literal fd97: address prefix, which only the first byte of fixes, so it returned empty for all but one reader in 256 and every later step using the variable failed silently. transports.tor.advertise_on_nostr was undocumented despite being validated against node.rendezvous.nostr.enabled. The transport design document gains the BLE section it never had, written from the source: the backend cascade and its compile_error tripwire, the platform gate, the PSM advertisement wire layout and the byte budget that forces a 16-bit service-data key, and the probe and admission bounds. Three source files carried the same class of staleness and are corrected with the documentation: the OpenWrt ipk usage line and Makefile error text both named a packaging/openwrt that does not exist, and chaos.sh parsed --subnet without listing it. Folded in with the content commit, having been prepared alongside it: The three GitHub Action pins that had gone stale. Every third-party action is pinned to a commit SHA, nothing reports that a pin has aged, and re-resolving all ten against their tags found dorny/test-reporter@v2, taiki-e/install-action@v2 and vmactions/freebsd-vm@v1 had moved. The three install-action@nextest references stay unpinned, since that action reads the tool to install from the ref name. check-action-pins.sh passes at 75 references and all nine workflow files parse. The lockfile refresh, which is the mutating half of the dependency sweep. Thirty-six packages move to their latest semver-compatible versions and every one is transitive; nothing declared in Cargo.toml changes version. No advisory forces any of them. It was taken before the validation battery, because a gate run against a lockfile that later moves proves nothing about what ships. The sha2 0.10 to 0.11, hkdf 0.12 to 0.13 and bech32 0.11 to 0.12 majors, three of the four deferred at v0.4.0 for change surface rather than security. All three land with no source change. sha2 and hkdf must move together, since both depend on digest 0.11, and neither changes an algorithm. That matters because the chaining-key KDF in the Noise handshake is built on Hkdf::<Sha256>, where an output change would be a wire break rather than a compile error; no known-answer vectors exist for that path, so the wire-compatibility gate is what covers it. secp256k1 0.31 is deliberately absent, since nostr's own requirement would leave two copies of the ECC library in the tree. The README support matrix, rebuilt as one feature table broken out by Linux variety. A single Linux column hid that Debian, Ubuntu, Arch and NixOS are one glibc build differing in packaging, that OpenWrt is musl and drops BLE, and that Android is not a daemon platform. Transport rows sort by how many platforms carry them. A Native API row reads its platform set from the cfg gates. The installer row becomes a package format row naming the artifact, and only the .deb is exercised per release. Four changelog and release-note gaps the BLE re-walk found: a Bluetooth LE bullet stranded inside the released 0.4.2 section, a missing Fixed entry for the scan and probe loop counting a pool-refused connection as an established link, the unnamed embedder call that installs an application-owned radio, and the fact that stopping the transport now stops scanning as well as advertising. Three release-document gaps found walking the unsurveyed commits: the UDP reuse-flag fix stated in the direction opposite to the one it was made, with the silent second-daemon bind it prevents left unsaid; the corrected native-API socket paragraph carried into both release-note copies, which still named SOCK_SEQPACKET on FreeBSD and two kernels where three are handled; and the coordinate-cache hardening, which shipped with no text anywhere despite adding four operator-visible status fields. That last entry states plainly that the checks are mitigations and not a closure, since the coordinate is still not authenticated. Also folded in, the documentation pass that followed the content commit: A stage-pipeline diagram for the probe, embedded in the fipsctl reference under the five-stage list. It draws the five stages left to right with each stage's failure reasons below it, and the bypass that skips both lookup stages when the coordinates are cached or the target is a direct peer. Its branches come from the probe state machine rather than from the report, so the path stage is drawn as the one failure that does not stop the probe. A rewrite of the README's "What FIPS does" section. It now opens with what a machine running FIPS gets, rather than with the two deployment modes, and gives the self-organizing and permissionless property its own paragraph since it holds for both modes. A regrouping of the README's feature list into the mesh, getting traffic onto it, and running a node, with a bullet added for the native datagram API, which had none despite sitting in the support matrix. The Quick start now leads with the released packages rather than a source build. It also fixes a real defect: the package enables fips.service and fips-dns.service and starts neither on a fresh install, so .fips name resolution was silently dead until the next reboot and neither page said to start the service. A rewrite of the release notes. They opened with seven subsections of upgrade caveats and reached the first feature two hundred lines in; they now open with a summary of the release and elaborate below it in the same order. Android is stated as supported through an embedded crate rather than as a standalone daemon, consistently across all three documents. The OpenWrt pair is corrected: it is 802.11s between routers with FIPS supplying encryption, authentication and routing, plus a convention of an open !FIPS SSID a client joins over WiFi, not meshing over a router's own radios. The probe's path output is described as the least-common-ancestor walk, which is the worst-case fallback route rather than the route a packet takes. Detail that did not change what a reader does was cut from the notes and kept in the changelog.
341 lines
17 KiB
Markdown
341 lines
17 KiB
Markdown
# `fipsctl`
|
|
|
|
Command-line client for the FIPS daemon's control socket.
|
|
|
|
## Synopsis
|
|
|
|
```text
|
|
fipsctl [-s SOCKET] <subcommand> [args...]
|
|
```
|
|
|
|
## Description
|
|
|
|
`fipsctl` connects to a running daemon over its control socket
|
|
(Unix domain socket on Linux/macOS, TCP loopback on Windows), sends
|
|
one JSON request, and pretty-prints the response. Exits with a
|
|
non-zero status if the socket cannot be reached, the daemon returns an
|
|
error, or the request times out.
|
|
|
|
`fipsctl keygen` and `fipsctl address` are special cases: they do not
|
|
contact the daemon and operate purely on local files.
|
|
|
|
For the line-delimited JSON wire protocol, see
|
|
[control-socket.md](control-socket.md). For the YAML configuration
|
|
that defines the socket location, see
|
|
[configuration.md](configuration.md).
|
|
|
|
## Global Options
|
|
|
|
| Flag | Argument | Description |
|
|
| ---- | -------- | ----------- |
|
|
| `-s`, `--socket` | `PATH` | Override the control-socket path (Linux/macOS) or TCP port (Windows). |
|
|
| `-V` | — | Print the short version, `<version> (rev <git-hash>)`. |
|
|
| `--version` | — | Print the long version: short version plus build target triple. |
|
|
| `-h`, `--help` | — | Print usage and exit. Per-subcommand help via `fipsctl <subcommand> --help`. |
|
|
|
|
## Subcommands
|
|
|
|
### `show <what>`
|
|
|
|
Read-only queries against the daemon. Each subcommand maps 1:1 to a
|
|
control-socket query (see [control-socket.md](control-socket.md)) and
|
|
prints the response's `data` object as pretty JSON.
|
|
|
|
| Subcommand | Control-socket command | Returns |
|
|
| ---------- | ---------------------- | ------- |
|
|
| `show status` | `show_status` | Node-level status: identity, version, peer/link/session counts, TUN state, recent sparklines. |
|
|
| `show peers` | `show_peers` | Authenticated peer list with link IDs, transport addresses, MMP metrics, Noise/rekey state. |
|
|
| `show links` | `show_links` | Active links (one per FMP-authenticated peer): direction, state, byte counters. |
|
|
| `show tree` | `show_tree` | Spanning-tree state: root, my coordinates, parent, peer declarations. |
|
|
| `show sessions` | `show_sessions` | End-to-end FSP sessions: state, traffic counters, session-MMP metrics, path MTU. |
|
|
| `show bloom` | `show_bloom` | Bloom-filter state: own filter sequence, leaf dependents, per-peer filter summaries. |
|
|
| `show mmp` | `show_mmp` | MMP metrics summary: per-peer link-layer metrics and per-session session-layer metrics. |
|
|
| `show cache` | `show_cache` | Coordinate cache: TTL, fill ratio, per-destination coords and path MTU. |
|
|
| `show connections` | `show_connections` | Pending handshake connections: state, idle time, resend count. |
|
|
| `show transports` | `show_transports` | Transport instances: type, state, MTU, local address, per-transport stats. |
|
|
| `show routing` | `show_routing` | Routing summary: pending lookups, retry state, forwarding/discovery/error/congestion counters. |
|
|
| `show identity-cache` | `show_identity_cache` | Cached `(node_addr → npub)` entries with last-seen timestamps. |
|
|
| `show native-flows` | `show_native_flows` | Native datagram API: open and pending flows with their ports, queue depth and age, bound listeners with their backlog, and the `native` counters. |
|
|
|
|
### `acl <what>`
|
|
|
|
| Subcommand | Control-socket command | Returns |
|
|
| ---------- | ---------------------- | ------- |
|
|
| `acl show` | `show_acl` | Loaded peer-ACL state: allow/deny files, effective mode, default decision, entry counts. |
|
|
|
|
### `stats <what>`
|
|
|
|
Time-series metrics from the in-process history rings.
|
|
|
|
| Subcommand | Control-socket command | Description |
|
|
| ---------- | ---------------------- | ----------- |
|
|
| `stats list` | `show_stats_list` | Enumerate available metrics, their units, and the per-ring retention windows. |
|
|
| `stats metrics` | `show_metrics` | Dump current counter values for every protocol metric family (`forwarding`, `discovery`, `tree`, `bloom`, `congestion`, `errors`, `native`). |
|
|
| `stats peers` | `show_stats_peers` | List peers tracked in stats history (active or recently active). |
|
|
| `stats history <metric> [options]` | `show_stats_history` | Fetch a time-series window for one metric. |
|
|
|
|
`stats history` options:
|
|
|
|
| Flag | Argument | Default | Description |
|
|
| ---- | -------- | ------- | ----------- |
|
|
| `--peer` | `npub` or hostname | *(none)* | Required for per-peer metrics; resolves through `/etc/fips/hosts` if not an npub. |
|
|
| `--window` | `<N>s` / `<N>m` / `<N>h` | `10m` | Window duration. |
|
|
| `--granularity` | `1s` or `1m` | `1s` | Ring resolution. `1s` uses the fast ring; `1m` uses the slow ring. |
|
|
| `--plot` | — | off | Render a Unicode-block sparkline to stdout instead of JSON. |
|
|
|
|
### `keygen [options]`
|
|
|
|
Generate a new FIPS identity keypair locally. Does not contact the
|
|
daemon.
|
|
|
|
| Flag | Argument | Default | Description |
|
|
| ---- | -------- | ------- | ----------- |
|
|
| `-d`, `--dir` | `DIR` | `/usr/local/etc/fips` (macOS, FreeBSD), `/etc/fips` (other Unix), `%APPDATA%\fips` (Windows) | Output directory for `fips.key` and `fips.pub`. Matches the directory the platform's packaging installs config into, which is where the daemon derives the key paths from. |
|
|
| `-f`, `--force` | — | off | Overwrite an existing `fips.key`. |
|
|
| `-s`, `--stdout` | — | off | Print `nsec` then `npub` to stdout instead of writing files. |
|
|
|
|
`fips.key` is written with mode `0600` and `fips.pub` with mode `0644`
|
|
on Unix. After running `keygen`, set `node.identity.persistent: true`
|
|
in `fips.yaml` or the daemon will overwrite the keys on next start.
|
|
|
|
### `address [identity] [options]`
|
|
|
|
Print a node's mesh address (`fd00::/8`) and nothing else, so it can be
|
|
captured in a shell substitution. Does not contact the daemon, which
|
|
makes it usable from an installer or image build where no node is
|
|
running.
|
|
|
|
| Argument | Description |
|
|
| -------- | ----------- |
|
|
| `identity` | npub (bech32) or hostname from `/etc/fips/hosts`. Omit to use this node's own identity. |
|
|
|
|
| Flag | Argument | Default | Description |
|
|
| ---- | -------- | ------- | ----------- |
|
|
| `-k`, `--key` | `PATH` | *(none)* | Derive from this key file (an `nsec`) or public key file (an `npub`). Conflicts with `identity`. |
|
|
|
|
With neither an `identity` nor `--key`, the address comes from
|
|
`fips.key` in the default key directory (the same directory `keygen`
|
|
writes to), falling back to `fips.pub` beside it, since `fips.key` is
|
|
mode `0600` and an unprivileged run cannot read it.
|
|
|
|
The address is derived from the public key exactly as the daemon
|
|
derives its own: `fd` followed by the first 15 bytes of
|
|
SHA-256(pubkey).
|
|
|
|
### `connect <peer> <address> <transport>`
|
|
|
|
Tell the daemon to dial a peer over a specific transport.
|
|
|
|
| Argument | Description |
|
|
| -------- | ----------- |
|
|
| `peer` | npub (bech32) or hostname from `/etc/fips/hosts`. |
|
|
| `address` | Transport endpoint, e.g. `192.168.1.10:2121`, `[2001:db8::1]:2121`, or a Tor onion. FIPS-mesh ULAs (`fd00::/8`) are rejected for the IP-based transports (udp, tcp, ethernet). |
|
|
| `transport` | One of `udp`, `tcp`, `tor`, `nym`, `ethernet`. The named transport must be configured and running. |
|
|
|
|
### `disconnect <peer>`
|
|
|
|
Tell the daemon to drop a peer link.
|
|
|
|
| Argument | Description |
|
|
| -------- | ----------- |
|
|
| `peer` | npub (bech32) or hostname from `/etc/fips/hosts`. |
|
|
|
|
### `probe <target>`
|
|
|
|
Diagnose whether a mesh endpoint is reachable, in five stages, and
|
|
report a per-stage verdict so a partial failure localizes itself.
|
|
|
|
| Argument | Description |
|
|
| -------- | ----------- |
|
|
| `target` | npub (bech32) or hostname from `/etc/fips/hosts`. |
|
|
| `--json` | Emit the report as JSON instead of human-readable text. |
|
|
| `--timeout <secs>` | Client-side ceiling. Defaults to the budget the daemon computed, which scales with its tick interval. |
|
|
|
|
The stages are:
|
|
|
|
1. **bloom** — does any peer's announced filter claim the target, and
|
|
did a LookupRequest therefore go out? A miss ends the probe here and
|
|
is a statement about the mesh's own knowledge: nobody has heard of
|
|
this address. Skipped when the coordinates are already cached, and
|
|
when the target is a directly connected peer.
|
|
2. **discovery** — waiting for a LookupResponse to answer with
|
|
coordinates. Each request the node sends gets its own line under the
|
|
stage, with the timeout that attempt was given and whether it drew a
|
|
reply. Failing here is the opposite finding to a bloom miss: a peer's
|
|
filter did claim the address, and nothing answered for it.
|
|
3. **path** — the least-common-ancestor walk between the two
|
|
coordinates, plus the next hop this node would select. This is a
|
|
**local computation, not a traceroute**: no hop beyond the first is
|
|
contacted, and the tree distance is an upper bound on the real hop
|
|
count because a crosslink cut-through can deliver in fewer hops.
|
|
When no coordinates were available the walk is not computed at all:
|
|
`path.coords_known` is false and every tree field is null, rather
|
|
than a default that would read as a finding about the spanning tree.
|
|
4. **session** — a full Noise XK handshake over FSP. Completing it is
|
|
genuine end-to-end evidence: our route reached them, their route
|
|
reached us, and the remote holds the expected static key.
|
|
5. **rtt** — one MMP sender/receiver report exchange, for a real
|
|
round-trip time.
|
|
|
|

|
|
|
|
Exit status is 0 only for an overall verdict of `ok`; `partial`,
|
|
`failed` and `cancelled` all exit 1.
|
|
|
|
**The stage block fills in as the probe runs.** Each stage reports its
|
|
verdict at the moment it reaches one, rather than the whole report
|
|
arriving at the end, so a slow stage is visible as the stage that is
|
|
slow. On a terminal the block is redrawn in place, with a spinner and a
|
|
running elapsed on whichever stage is working; piped or redirected, each
|
|
row is printed once, when it settles, and the transcript ends up the
|
|
same block. A running stage reports only what the daemon has observed —
|
|
which requests have gone unanswered so far, whether the handshake is in
|
|
flight, how many receiver reports have arrived — and never previews an
|
|
outcome it does not have yet. The per-request lines under the discovery
|
|
stage carry the configured timeout of each attempt in parentheses, which
|
|
is the node's own ladder rather than a measurement.
|
|
|
|
The elapsed column comes from the daemon's clock throughout: a finished
|
|
stage carries its own tick-quantized figure, and the stage still running
|
|
carries the report's elapsed less the stages already accounted for.
|
|
Nothing in that column is measured client-side.
|
|
|
|
**Stages that were never attempted get no row.** A failure marks
|
|
everything behind it as not reached, and the report says that once, in
|
|
the failed row, rather than three more times. Two cases deliberately keep
|
|
their rows: a *skipped* stage, because a skip is a result naming why that
|
|
stage was unnecessary, and everything after a *failed path* stage,
|
|
because the path preview touches nothing and the session can still
|
|
succeed where the preview named no next hop.
|
|
|
|
Below the stage block, the `path:` line renders the whole tree walk on
|
|
one line, from this node to the target, through the least common
|
|
ancestor, which is emphasised on a terminal. It is the same computed
|
|
walk the `ours`, `theirs` and `tree walk` lines describe, read in one
|
|
piece.
|
|
|
|
`--json` is unaffected and still emits exactly one document, when the
|
|
probe ends, so a script parsing the report does not have to skip past
|
|
progress output.
|
|
|
|
**What the probe leaves behind.** It tears down a session it opened
|
|
itself and never touches one that already existed. Three residues are
|
|
deliberate and worth knowing about:
|
|
|
|
- The coordinate-cache and identity-cache entries a lookup produced are
|
|
not evicted. They are TTL-bounded shared read caches, and evicting
|
|
them could strand an unrelated flow mid-route.
|
|
- The remote's half of a probe-created session persists until its own
|
|
idle timeout (default 90s). There is no teardown wire message. In the
|
|
window between our removal and its idle purge, any session frame the
|
|
remote sends lands here as one unknown-session reject.
|
|
- To obtain a round-trip time the probe sends a `CoordsWarmup`, which
|
|
starts MMP reporting on the session. On a session the probe does not
|
|
own, that reporting continues until the idle purge — the same traffic
|
|
any single data packet would cause, and bounded, but a real change to
|
|
a session the probe did not create. The report names it under
|
|
`cleanup.warmups_sent`.
|
|
|
|
Running a probe against a production node is safe: the job carries its
|
|
own deadline daemon-side, so it cleans up whether or not the client is
|
|
still there.
|
|
|
|
### `profile tick <on|off|status>`
|
|
|
|
> **Reading the output.** Step durations are wall clock measured across `await`
|
|
> points, not CPU time: a step that waits on I/O accrues that wait, and other
|
|
> tasks may run inside the span. That is the intended measure for head-of-line
|
|
> delay, and it means a large step is not necessarily an expensive one.
|
|
> `arm_starvation` is measured directly as the entry time minus the deadline
|
|
> the interval scheduled that tick for. It is not derived from
|
|
> `tick_entry_gap`, which carries no starvation signal on its own: under a
|
|
> steady delay every gap is exactly one tick period.
|
|
|
|
Start, stop and inspect a capture of the rx-loop tick body. **Present
|
|
only when both `fipsctl` and the daemon are built with
|
|
`--features profiling`**; the feature is off by default, so a stock
|
|
package does not carry this subcommand and a stock daemon reports
|
|
`profile_tick_*` as an unknown command.
|
|
|
|
| Subcommand | Control-socket command | Description |
|
|
| ---------- | ---------------------- | ----------- |
|
|
| `profile tick on` | `profile_tick_on` | Create the capture file and start recording. Fails if a capture is already running (naming the active file) or if the directory cannot be written. |
|
|
| `profile tick off` | `profile_tick_off` | Stop the capture. The writer is woken immediately, drains once more and is joined, so the command returns promptly. Succeeds, reporting nothing active, when no capture is running. |
|
|
| `profile tick status` | `profile_tick_status` | Report `idle`, `running`, `stopped_by_cap` or `stopped_by_error`, plus the active path, bytes written, flush interval and byte cap. |
|
|
|
|
`profile tick on` options:
|
|
|
|
| Flag | Argument | Default | Description |
|
|
| ---- | -------- | ------- | ----------- |
|
|
| `--dir` | directory path | `/var/log/fips` | Where to write the capture. Created if absent. Use it to profile a non-root `cargo run`. |
|
|
|
|
Against a daemon running as root, `--dir` must name an absolute path
|
|
under `/var/log/fips`, and a path that resolves outside it through a
|
|
symlinked parent is refused. The control socket is reachable by the
|
|
`fips` group, which the security model treats as strictly weaker than
|
|
root, so a group member cannot steer a root directory creation at an
|
|
arbitrary path. A daemon that is not running as root crosses no such
|
|
boundary and takes `--dir` as given, which is what keeps a non-root
|
|
`cargo run` capture working. Confining a root daemon's captures to a
|
|
different log root is not currently supported.
|
|
|
|
One file is written per capture, named `profile-<UTC timestamp>.tsv`,
|
|
with `-1`, `-2` and so on appended if a capture in the same second
|
|
already claimed the name. The capture file is created private to its
|
|
owner and is never written over an existing file.
|
|
It opens with a `#`-prefixed header block (node npub, build version,
|
|
platform, configured tick period, flush interval, byte cap, start
|
|
time), then a tab-separated column header, then one row per measured
|
|
step per flush interval:
|
|
|
|
```text
|
|
ts_unix kind domain name count max total unit
|
|
```
|
|
|
|
`kind` is `step` for a timed span and `gauge` for a sampled scalar, so
|
|
a gauge value never lands under a duration column; `unit` names the
|
|
unit of `max` and `total` for that row. Every step present in the build
|
|
gets a row every interval, including zero-count rows. Gauges cover
|
|
ticks per interval, peer count, the wall gap between successive
|
|
tick-arm entries, and the arm-starvation delay, which is measured
|
|
against the deadline the tick was scheduled for rather than derived
|
|
from the gap.
|
|
|
|
A capture stops itself on reaching 32 MB, appending a `#` line saying
|
|
so; `profile tick status` then reports `stopped_by_cap` until the next
|
|
`on` or `off` clears it.
|
|
|
|
## Exit Codes
|
|
|
|
| Code | Meaning |
|
|
| ---- | ------- |
|
|
| `0` | Daemon returned `{"status":"ok",...}`. |
|
|
| `1` | Argument parse failure, control-socket connection failure, daemon returned `{"status":"error",...}`, or local I/O failure (keygen). The error message is printed to stderr. |
|
|
|
|
## Environment
|
|
|
|
| Variable | Description |
|
|
| -------- | ----------- |
|
|
| `XDG_RUNTIME_DIR` | Used to derive the default control-socket path when `/run/fips` is absent. |
|
|
|
|
`fipsctl` does not consume `RUST_LOG`; logging is for the daemon.
|
|
|
|
## Files
|
|
|
|
| Path | Purpose |
|
|
| ---- | ------- |
|
|
| `/etc/fips/hosts` | Maps hostnames to npubs for the `connect`, `disconnect`, and `--peer` arguments. See [configuration.md](configuration.md). |
|
|
| Control socket (default) | Same resolution as the daemon: `/run/fips/control.sock` if present; then `/var/run/fips/control.sock` on macOS/FreeBSD if present; then `$XDG_RUNTIME_DIR/fips/control.sock`; finally `/tmp/fips-control.sock` (Unix). A privileged macOS daemon bootstraps the private `/var/run/fips` directory. Windows uses TCP `localhost:21210`. |
|
|
|
|
If you get `Permission denied` connecting to the socket on Linux,
|
|
add your user to the `fips` group (`sudo usermod -aG fips $USER`)
|
|
and log out and back in.
|
|
|
|
## See also
|
|
|
|
- [`fips`](cli-fips.md) — the daemon.
|
|
- [`fipstop`](cli-fipstop.md) — live-status TUI.
|
|
- [control-socket.md](control-socket.md) — wire protocol.
|
|
- [configuration.md](configuration.md) — YAML reference.
|