Files
fips/docs/design
Johnathan Corgan 6b6d2a8df9 feat(fipsctl): rework the probe report layout and fix the path row text
The stage block and the sections below it now share one left margin, the
stage rows carry shorter text, and a blank line separates the stages by
the question each answers: where is the target, how do we get there, can
we reach it.

The path row no longer appears when it computed a route. It restated the
heading of the path section printed below it, and that section said the
same thing in full. The row is kept when the stage failed or was skipped,
where it carries a finding that appears nowhere else in the block.

That exposed a defect the row had all along: its text ignored the stage's
reason, so a disjoint_trees or no_next_hop failure printed the success
wording. It now keys on the reason like every other stage.

Also in the report: the npub moves onto its own line so the three
identifiers align, the depth column no longer shifts with the length of
the coordinate list, the route line sits directly under the two
coordinate lists it derives from and is set off by a blank line on each
side, the next-hop class loses its underscore, and the round-trip row
names the exchange count only when it is not one. The path section
heading, which said the route was computed rather than observed, is gone;
the JSON keeps computed_locally and observed.

Off a terminal the block is rebuilt from the settled prefix rather than
appended row by row, because a group separator belongs to the row below
it and a single-row render cannot know whether that row exists yet.

A stage-pipeline diagram lands alongside the report, drawing the five
stages left to right at 16:9 with each stage's failure reasons below it,
and the bypass that skips both lookup stages when the coordinates are
cached or the target is a direct peer. Its branches come from the probe
state machine rather than from the report, so the path stage is drawn as
the one failure that does not stop the probe.
2026-08-29 06:38:22 +00:00
..
2026-06-07 23:30:35 +00:00
2026-08-15 07:56:54 +00:00

FIPS Design

Architectural and protocol-level explanations for FIPS — the why and the how behind the wire and the system. For wire formats and configuration keys, see reference/. For task recipes, see how-to/. For end-to-end lessons, see tutorials/.

Reading Order

Start with fips-concepts.md for the novice-friendly framing of what FIPS is and why, then move to fips-architecture.md for the protocol stack, identity model, and two-layer encryption walkthrough. From there, follow the protocol stack from bottom to top. After the stack, fips-mesh-operation.md explains how the pieces work together at runtime. Cross-cutting and supporting documents cover specific subsystems in detail.

Foundations

Document Description
fips-concepts.md What FIPS is, why it exists, mental model
fips-architecture.md Protocol stack, identity, two-layer encryption
fips-prior-work.md Designs and protocols FIPS builds on

Protocol Stack

Document Description
fips-transport-layer.md Transport layer: datagram delivery over arbitrary media
fips-mesh-layer.md FIPS Mesh Protocol (FMP): peer authentication, link encryption, forwarding
fips-session-layer.md FIPS Session Protocol (FSP): end-to-end encryption, sessions
fips-ipv6-adapter.md IPv6 adaptation: TUN interface, DNS, MTU enforcement
fips-native-api.md Native datagram API: pubkey-addressed flows over FSP, and what it is instead of the TUN path

Cross-Cutting

Document Description
fips-mmp.md Metrics Measurement Protocol (link + session)
fips-mtu.md Path MTU model, encapsulation overhead, PMTUD
fips-security.md fips0 interface threat model and default-deny baseline

Mesh Behavior

Document Description
fips-mesh-operation.md How the mesh operates: routing, discovery, error recovery
fips-nostr-discovery.md Optional Nostr-mediated peer discovery and UDP NAT hole-punch
port-advertisement-and-nat-traversal.md Nostr-signaled port advertisement and UDP NAT-traversal protocol; generic, with FIPS as an example implementation

Deeper Dives

Document Description
fips-spanning-tree.md Spanning tree algorithms: root discovery, parent selection, coordinates
fips-bloom-filters.md Bloom filter properties: FPR analysis, size classes, split-horizon
spanning-tree-dynamics.md Spanning tree walkthroughs: convergence scenarios, worked examples

Adjacent Components

Document Description
fips-gateway.md fips-gateway service: outbound (LAN-to-mesh) DNS-proxy + virtual-IP NAT and inbound (mesh-to-LAN) port-forwarding, sharing one nftables table