mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
Carries the five security commits up. Five of the nine behaviours merged as text; four had to be re-implemented against this line refactored structure, and two files this line had deleted needed their content relocated. Relocated: the path-MTU source reset into the protocol MMP module, adapted because this line stores the first-increase timestamp as milliseconds rather than an instant; the lookup-carrier deadline into the renamed lookup handler, where it routes through the write action rather than touching the map directly; and the flap-dampening test into the spanning-tree limits tests, rewritten against this line injected clock so it needs no real sleep. The maint copies of both deleted files are removed. The lookup write action gains a timestamp field so both stores it feeds are stamped at the same instant, which is what the deadline reasoning depends on. The alternative was a second clock read in the shell. Config keys and the new validator error strings are expressed against this line rendezvous naming rather than the maintenance line discovery naming. Three defects survived the automatic merge and were caught by the compiler: a serde default naming the old config struct, an import of a constant from the old module path, and two tests missing an import this line requires per test. The automatic merge also duplicated a test and a relocated block that already existed here; both were dropped. Green: fmt, build, clippy and test --lib, 1861 passed.
Reference
Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.
Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.
Available Reference
| Document | Scope |
|---|---|
| wire-formats.md | All FMP and FSP message byte layouts, encapsulation walkthrough |
| configuration.md | Full YAML configuration reference for the daemon and gateway |
| security.md | nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix |
| nostr-events.md | Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays |
| transports.md | Per-transport statistics counter inventory |
| control-socket.md | Line-delimited JSON control protocol for the daemon and gateway |
| cli-fips.md | fips daemon CLI: options, exit codes, environment, files |
| cli-fipsctl.md | fipsctl control-client: subcommands, options, exit codes |
| cli-fipstop.md | fipstop live-status TUI: tabs, keybindings |
| cli-fips-gateway.md | fips-gateway service CLI: options, exit codes, files |