Files
fips/docs/how-to
Johnathan Corgan d7f079618f Document that an empty datagram sent just before a close reads as the close on Linux
The native API's receive rule cannot tell a zero-length datagram that is
the last message before a close from the close itself on SOCK_SEQPACKET,
which Linux uses: reading it drains the queue, and every observation
then matches a bare end of file. macOS and FreeBSD carry the flow on
SOCK_DGRAM, where the empty datagram is delivered and the close is
reported by the read after it.

The doc comment on Received::Datagram said an empty datagram is never a
close, which contradicted the limitation stated a few hundred lines
below it. It now says where the exception applies, and the recv_once
rationale, the FipsStream::recv rustdoc, the native API reference and
the client how-to scope the limitation to Linux. The reference page's
list of places where data disappears gains the send-side consequence:
a program that sends an empty datagram and then drops its stream may
have the daemon read it as the close, so it never reaches the peer. The
datagram how-to, which counts those places, is updated to match.

A new test pins the behaviour per socket type, branching on the
module's socket-type constant rather than on the OS, so the
documentation and the test cannot drift apart.
2026-09-27 19:35:11 +00:00
..

How-To Guides

Task-oriented, step-by-step recipes for operators with a specific goal in mind. Each guide assumes the reader already knows what FIPS is and wants to get a particular thing done — enable a feature, deploy a component, troubleshoot a class of problem.

How-to guides do not teach concepts (that is the role of design/) and do not enumerate options (that is the role of reference/). They take the reader along the shortest correct path from "I want to do X" to "X is done".

Available Guides

Guide Goal
enable-mesh-firewall.md Activate the default-deny nftables baseline on fips0
enable-nostr-discovery.md Turn on Nostr-mediated discovery (3 capabilities — resolve, advertise, open — across 5 scenarios)
deploy-tor-onion.md Run a Tor onion service for inbound FIPS connections
tune-udp-buffers.md Set host sysctls so FIPS UDP sockets don't get clamped
tune-file-descriptors.md Raise RLIMIT_NOFILE so a busy node doesn't exhaust file descriptors (EMFILE) as peer count grows
run-as-unprivileged-user.md Run the daemon under a dedicated unprivileged service account (drops the default-root posture)
deploy-gateway.md Manually deploy fips-gateway on a non-OpenWrt Linux host (LAN-to-mesh outbound + mesh-to-LAN inbound port-forwards). For the OpenWrt path, see the gateway tutorial.
troubleshoot-gateway.md Diagnostic recipes for the gateway, organised by half (outbound, inbound, common)
persistent-identity.md Provision a stable Nostr keypair so the node keeps the same npub across restarts
host-aliases.md Use shortnames (test-us01.fips, my-laptop.fips) instead of full npubs by editing /etc/fips/hosts or setting peer aliases
set-up-bluetooth-peer.md Configure a Bluetooth Low Energy peer link
set-up-80211s-mesh-backhaul.md Link OpenWrt FIPS routers over an open 802.11s radio backhaul (FIPS provides encryption, authentication, and routing)
set-up-open-access-ssid.md Broadcast the open !FIPS access SSID so phones and laptops roam onto the mesh (one ESS: save once, roam every FIPS router)
diagnose-mtu-issues.md Triage MTU-shaped failures and rule out their imposters (bufferbloat, transport saturation)
use-the-native-datagram-api.md Enable the experimental native datagram API and write a program that sends and receives datagrams by pubkey and port (no IPv6 emulation, no TUN). Read the fips group warning first
write-a-native-api-client.md Speak the native datagram API's line protocol directly from C, Python or Go, where there is no client library
serve-many-peers-on-one-thread.md Handle every native API flow from one poll loop instead of a thread per peer