Files
fips/docs/design
Johnathan Corgan 1c93fde672 Give each sender its own traversal offer allowance, and enforce the freshness bound at load
The incoming-offer semaphore was global with no per-sender accounting and
the permit was taken before any identity check, so one sender could hold
every slot and deny rendezvous to everyone else. Each sender now has its
own allowance with the global count kept as the outer bound. Note what
this does and does not do: it raises the cost from one keypair to a small
number of them, so a sender willing to spend throwaway identities can
still saturate the pool at unchanged total offer rate.

The signal freshness bound is only sound while the acceptance window
stays strictly inside the replay window, or an offer evicted from the
replay cache is still fresh enough to be accepted twice. The relation was
stated in a comment and enforced nowhere. Config validation now rejects
the bad combination at load, derived from the skew constant rather than a
literal, and checked regardless of whether the feature is enabled so that
turning it on later cannot surface an error at a surprising moment. The
NAT lab config generator produced a combination the new rule rejects and
is corrected in the same change.

The punch-target filter shipped with no test that would fail if it were
reverted. Loopback, link-local and multicast candidates and an oversized
list are now covered, and the cap assertion is tightened from a bound to
an equality. The private-range inclusion that LAN traversal depends on is
pinned as a healthy path so a blanket ban cannot pass.

Green: fmt, build, clippy and test --lib, 1533 passed.
2026-08-15 07:21:45 +00:00
..
2026-06-07 23:30:35 +00:00

FIPS Design

Architectural and protocol-level explanations for FIPS — the why and the how behind the wire and the system. For wire formats and configuration keys, see reference/. For task recipes, see how-to/. For end-to-end lessons, see tutorials/.

Reading Order

Start with fips-concepts.md for the novice-friendly framing of what FIPS is and why, then move to fips-architecture.md for the protocol stack, identity model, and two-layer encryption walkthrough. From there, follow the protocol stack from bottom to top. After the stack, fips-mesh-operation.md explains how the pieces work together at runtime. Cross-cutting and supporting documents cover specific subsystems in detail.

Foundations

Document Description
fips-concepts.md What FIPS is, why it exists, mental model
fips-architecture.md Protocol stack, identity, two-layer encryption
fips-prior-work.md Designs and protocols FIPS builds on

Protocol Stack

Document Description
fips-transport-layer.md Transport layer: datagram delivery over arbitrary media
fips-mesh-layer.md FIPS Mesh Protocol (FMP): peer authentication, link encryption, forwarding
fips-session-layer.md FIPS Session Protocol (FSP): end-to-end encryption, sessions
fips-ipv6-adapter.md IPv6 adaptation: TUN interface, DNS, MTU enforcement

Cross-Cutting

Document Description
fips-mmp.md Metrics Measurement Protocol (link + session)
fips-mtu.md Path MTU model, encapsulation overhead, PMTUD
fips-security.md fips0 interface threat model and default-deny baseline

Mesh Behavior

Document Description
fips-mesh-operation.md How the mesh operates: routing, discovery, error recovery
fips-nostr-discovery.md Optional Nostr-mediated peer discovery and UDP NAT hole-punch
port-advertisement-and-nat-traversal.md Nostr-signaled port advertisement and UDP NAT-traversal protocol; generic, with FIPS as an example implementation

Deeper Dives

Document Description
fips-spanning-tree.md Spanning tree algorithms: root discovery, parent selection, coordinates
fips-bloom-filters.md Bloom filter properties: FPR analysis, size classes, split-horizon
spanning-tree-dynamics.md Spanning tree walkthroughs: convergence scenarios, worked examples

Adjacent Components

Document Description
fips-gateway.md fips-gateway service: outbound (LAN-to-mesh) DNS-proxy + virtual-IP NAT and inbound (mesh-to-LAN) port-forwarding, sharing one nftables table