mirror of
https://github.com/jmcorgan/fips.git
synced 2026-08-09 00:04:54 +00:00
Comprehensive documentation review across 12 files to reflect: - Noise XK at FSP (was IK), 3-message handshake, SessionMsg3 wire format - Epoch exchange in Noise handshakes for peer restart detection - Per-link MTU, min_mtu/path_mtu in lookup packets - MtuExceeded (0x22) error signal wire format and behavior - LookupResponse proof now covers target_coords - Discovery reverse-path routing as primary (not greedy) - Control socket architecture and fipsctl binary - FSP handshake state machine (Initiating/AwaitingMsg3/Established) - Root timeout framing updated for heartbeat cascading
95 lines
3.0 KiB
Markdown
95 lines
3.0 KiB
Markdown
# FIPS: Free Internetworking Peering System
|
|
|
|
A distributed, decentralized network routing protocol for mesh nodes
|
|
connecting over arbitrary transports.
|
|
|
|
> **Status: Experimental / Pre-release**
|
|
>
|
|
> FIPS is under active development. The protocol and APIs are not stable.
|
|
> Expect breaking changes.
|
|
|
|
## Overview
|
|
|
|
FIPS is a self-organizing mesh network that operates natively over a variety
|
|
of physical and logical media — local area networks, Bluetooth, serial links,
|
|
radio, or the existing internet as an overlay. Nodes generate their own
|
|
identities, discover each other, and route traffic without any central
|
|
authority or global topology knowledge.
|
|
|
|
FIPS uses Nostr keypairs (secp256k1/schnorr) as native node identities,
|
|
making every Nostr user a potential network participant. Nodes address each
|
|
other by npub, and the same cryptographic identity used in the Nostr ecosystem
|
|
serves as both the routing address and the basis for end-to-end encrypted
|
|
sessions across the mesh.
|
|
|
|
## Features
|
|
|
|
- **Self-organizing mesh routing** — spanning tree coordinates and bloom
|
|
filter candidate selection, no global routing tables
|
|
- **Multi-transport** — UDP/IP overlay today; designed for Ethernet,
|
|
Bluetooth, serial, radio, and Tor
|
|
- **Noise encryption** — hop-by-hop link encryption plus independent
|
|
end-to-end session encryption
|
|
- **Nostr-native identity** — secp256k1 keypairs as node addresses, no
|
|
registration or central authority
|
|
- **IPv6 adaptation** — TUN interface maps npubs to fd00::/8 addresses for
|
|
unmodified IP applications
|
|
- **Metrics Measurement Protocol** — per-link RTT, loss, jitter, and goodput
|
|
measurement
|
|
- **Operator visibility** — `fipsctl` control socket interface for runtime
|
|
inspection of peers, links, sessions, tree state, and metrics
|
|
- **Zero configuration** — sensible defaults; a node can run with no config
|
|
file
|
|
|
|
## Quick Start
|
|
|
|
### Requirements
|
|
|
|
- Rust 1.85+ (edition 2024)
|
|
- Linux (TUN interface requires `CAP_NET_ADMIN` or root)
|
|
|
|
### Build
|
|
|
|
```
|
|
git clone https://github.com/jmcorgan/fips.git
|
|
cd fips
|
|
cargo build --release
|
|
```
|
|
|
|
### Run
|
|
|
|
```
|
|
# With default configuration (ephemeral identity, default ports):
|
|
sudo ./target/release/fips
|
|
|
|
# With a configuration file:
|
|
sudo ./target/release/fips -c fips.yaml
|
|
```
|
|
|
|
See [docs/design/fips-configuration.md](docs/design/fips-configuration.md) for
|
|
the full configuration reference.
|
|
|
|
### Multi-node Testing
|
|
|
|
See [testing/](testing/) for Docker-based integration test harnesses including
|
|
static topology tests and stochastic chaos simulation.
|
|
|
|
## Documentation
|
|
|
|
Protocol design documentation is in [docs/design/](docs/design/), organized as
|
|
a layered protocol specification. Start with
|
|
[fips-intro.md](docs/design/fips-intro.md) for the full protocol overview.
|
|
|
|
## Project Structure
|
|
|
|
```
|
|
src/ Rust source (library + fips/fipsctl binaries)
|
|
docs/design/ Protocol design specifications
|
|
testing/ Docker-based integration test harnesses
|
|
benches/ Criterion benchmarks
|
|
```
|
|
|
|
## License
|
|
|
|
MIT — see [LICENSE](LICENSE).
|