Files
fips/docs/design
Johnathan Corgan a37c62898c Test and document where the own-request loop guard stops recognising an id
The guard that drops a returning copy of this node's own lookup request
recognises an id only while that lookup is outstanding and the id is
among the last eight its ladder issued. Nothing pinned either limit: the
existing test covers only an id inside the window of a live lookup. Two
new tests do. A copy arriving after the lookup timed out is recorded and
forwarded as transit, and its next copy is a duplicate. A copy of an
attempt older than the recorded window is likewise recorded and
forwarded, while a recent id on the same lookup is still dropped as our
own.

The mesh operation design said a node tests its own outstanding lookups
before consulting recent_requests, and that a returning copy of the
originator's request never enters the transit cache. The first is the
response path's order; the request path runs the dedup test first and
the own-request check second, where the order is immaterial because an
id the originator check recognises is never in the dedup cache. The
second holds only while the check recognises the id. The design now
says both, and how far the check reaches, and its heading no longer
says the originator check runs first.

When a node's own looped-back lookup request got its own counter, the
comments justified the split by saying req_duplicate means a peer resent
a request, and that the own-loop counter says nothing about the peer.
Neither holds. The duplicate test is on the request id alone, so one
flood arriving through two neighbours is counted there too, and no
discovery counter is per peer. Justify the split by cause instead: the
node's own fan-out returning, versus a request id the node has already
recorded arriving again. Say that neither counter identifies the
delivering peer, that own-request loopbacks come back through bloom
false positives and so rise with the filter's fill ratio, and that an
own copy outside the loop check's reach is recorded and forwarded as
transit, with a later copy counted as a duplicate.
2026-10-01 22:40:40 +00:00
..
2026-08-30 10:42:59 +00:00
2026-08-30 10:42:59 +00:00

FIPS Design

Architectural and protocol-level explanations for FIPS — the why and the how behind the wire and the system. For wire formats and configuration keys, see reference/. For task recipes, see how-to/. For end-to-end lessons, see tutorials/.

Reading Order

Start with fips-concepts.md for the novice-friendly framing of what FIPS is and why, then move to fips-architecture.md for the protocol stack, identity model, and two-layer encryption walkthrough. From there, follow the protocol stack from bottom to top. After the stack, fips-mesh-operation.md explains how the pieces work together at runtime. Cross-cutting and supporting documents cover specific subsystems in detail.

Foundations

Document Description
fips-concepts.md What FIPS is, why it exists, mental model
fips-architecture.md Protocol stack, identity, two-layer encryption
fips-prior-work.md Designs and protocols FIPS builds on

Protocol Stack

Document Description
fips-transport-layer.md Transport layer: datagram delivery over arbitrary media
fips-mesh-layer.md FIPS Mesh Protocol (FMP): peer authentication, link encryption, forwarding
fips-session-layer.md FIPS Session Protocol (FSP): end-to-end encryption, sessions
fips-ipv6-adapter.md IPv6 adaptation: TUN interface, DNS, MTU enforcement
fips-native-api.md Native datagram API: pubkey-addressed flows over FSP, and what it is instead of the TUN path

Cross-Cutting

Document Description
fips-mmp.md Metrics Measurement Protocol (link + session)
fips-mtu.md Path MTU model, encapsulation overhead, PMTUD
fips-security.md fips0 interface threat model and default-deny baseline

Mesh Behavior

Document Description
fips-mesh-operation.md How the mesh operates: routing, discovery, error recovery
fips-nostr-discovery.md Optional Nostr-mediated peer discovery and UDP NAT hole-punch
port-advertisement-and-nat-traversal.md Nostr-signaled port advertisement and UDP NAT-traversal protocol; generic, with FIPS as an example implementation

Deeper Dives

Document Description
fips-spanning-tree.md Spanning tree algorithms: root discovery, parent selection, coordinates
fips-bloom-filters.md Bloom filter properties: FPR analysis, size classes, split-horizon
spanning-tree-dynamics.md Spanning tree walkthroughs: convergence scenarios, worked examples

Adjacent Components

Document Description
fips-gateway.md fips-gateway service: outbound (LAN-to-mesh) DNS-proxy + virtual-IP NAT and inbound (mesh-to-LAN) port-forwarding, sharing one nftables table