Files
fips/docs/reference
Johnathan Corgan 5a79d3fc5e Merge master into next
Brings up the two release lines' work: the maint harness and guard
fixes, the documentation corrections, master's probe, onion and epoch
fixes, and both rebuilt changelog blocks.

Three conflicts.

The readme conflicted on the badge pair. Resolved by taking the Rust
badge that no longer asserts a version, since rust-toolchain.toml is the
only place that states one, and keeping this line's own v0.6.0-dev
status badge.

The peer machine conflicted, and the resolution is an adaptation rather
than a pick. Master deleted PeerMachine.remote_epoch on the grounds that
nothing read it, and that reasoning had to be re-derived here because
this line's machine is the XX rewrite and shares almost no text with it.
It holds. The shadow's only production write is inbound_msg3, which is
where XX crystallizes identity, so it is inbound-only exactly as the msg1
write was on the other lines; conn carries the same value written from
both legs, complete_handshake on the outbound one and
complete_handshake_msg3 on the inbound; the only read is the cutover
action payload, whose executor arm binds nothing; and the live consumer
reads conn_remote_epoch. So an initiator cutover, which runs on an
outbound machine, carried a zeroed epoch here too.

One thing differs and needed handling. This line has an `established`
constructor the others do not, and it writes the shadow and conn from the
same argument, which would have made the field direction-correct. Its
only caller is in the test module and its own doc comment calls the
machine inert, so it is a seam that is not wired yet rather than a
production path, and it does not rescue the field. Its assignment goes
with the rest; the parameter stays, because conn still needs the value.

The adaptation is folded into this merge rather than left to a follow-on,
because master's half of the same change reached peer_actions.rs through
a clean auto-merge. Keeping this line's field while accepting that
auto-merge would have left the machine emitting a payload field the
executor no longer has, which is a break that only the test build shows.

The changelog conflicted because both lines had rebuilt their unreleased
block. The Breaking section stays at the top untouched; Unreleased now
holds the ten entries that are this line's own; and the other two lines'
work sits below under 0.5.0 and 0.4.2 headings, neither dated, matching
how master already carries 0.4.2. Four entries existed on both sides in
branch-adapted form and were merged rather than picked, so each keeps the
rework's wording and this line's accuracy: the OpenWrt entry drops its IK
reference, the msg1 classifier keeps the promotion-state paragraph, the
SessionAck entry keeps the two XX-only exits, and the msg3 epoch entry
counts six sites here against master's five.
2026-08-22 11:04:58 +01:00
..
2026-05-08 13:45:04 +00:00
2026-08-09 13:41:09 +00:00
2026-08-22 11:04:58 +01:00
2026-08-21 05:55:35 +00:00

Reference

Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.

Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.

Available Reference

Document Scope
wire-formats.md All FMP and FSP message byte layouts, encapsulation walkthrough
configuration.md Full YAML configuration reference for the daemon and gateway
security.md nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix
nostr-events.md Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays
transports.md Per-transport statistics counter inventory
control-socket.md Line-delimited JSON control protocol for the daemon and gateway
native-api.md Native datagram API: the Rust surface, addressing and ports, errno table, ceilings, line protocol, command reference
cli-fips.md fips daemon CLI: options, exit codes, environment, files
cli-fipsctl.md fipsctl control-client: subcommands, options, exit codes
cli-fipstop.md fipstop live-status TUI: tabs, keybindings
cli-fips-gateway.md fips-gateway service CLI: options, exit codes, files