mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
Nothing printed a node's fd00::/8 mesh address without a running daemon: keygen prints the nsec and npub only, and every show path goes through the control socket. That blocks fips-initramfs, whose postinst has to write the address of the identity it just generated into DROPBEAR_OPTIONS at image build time, when no daemon is running and none can be. fipsctl address prints the address and nothing else, so it can be captured in a shell substitution. It takes an npub or a hostname from the hosts file, or --key naming a key file (an nsec) or public key file (an npub); with neither it reads fips.key from the default key directory, falling back to the world-readable fips.pub beside it, since fips.key is mode 0600 and an unprivileged run cannot read it. The derivation is the library's own: PeerIdentity/Identity compute the address from the public key exactly as the daemon computes its own, so the packaging does not gain a second copy free to drift. The command returns before the socket path is resolved, alongside keygen, so no connection is attempted. (cherry picked from commit 6e8a0033dbc9a546a2d24cc295335ccef0cd0ead)
Reference
Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.
Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.
Available Reference
| Document | Scope |
|---|---|
| wire-formats.md | All FMP and FSP message byte layouts, encapsulation walkthrough |
| configuration.md | Full YAML configuration reference for the daemon and gateway |
| security.md | nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix |
| nostr-events.md | Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays |
| transports.md | Per-transport statistics counter inventory |
| control-socket.md | Line-delimited JSON control protocol for the daemon and gateway |
| native-api.md | Native datagram API: the Rust surface, addressing and ports, errno table, ceilings, line protocol, command reference |
| cli-fips.md | fips daemon CLI: options, exit codes, environment, files |
| cli-fipsctl.md | fipsctl control-client: subcommands, options, exit codes |
| cli-fipstop.md | fipstop live-status TUI: tabs, keybindings |
| cli-fips-gateway.md | fips-gateway service CLI: options, exit codes, files |