Files
fips/docs/reference
Arjen ddb9a8336a feat(udp): bind a UDP instance to one interface
`transports.udp.<name>.interface` binds the instance's listen socket,
and the per-peer connected sockets under it, to the named interface:
Linux `SO_BINDTODEVICE` in both directions, macOS `IP_BOUND_IF` /
`IPV6_BOUND_IF` for egress only (inbound on a wildcard bind still
arrives from any interface there). Elsewhere naming an interface is an
error at start rather than a silent no-op. One fd-based helper in
`io/bind_device.rs` serves both sockets, so the two cannot drift.

Without the connected-socket half, an interface-bound instance's data
routed by the kernel's table and could leave by another NIC, which
made the binding a lie; with it, two instances bound to two interfaces
are two distinct paths to a peer reachable over both. The interface
must exist when the daemon starts: unlike an Ethernet transport, an
interface-bound UDP instance is not retried when its interface appears
later, and it gets no presence or carrier signal while running. That
is documented rather than fixed here.
2026-09-23 11:48:33 -03:00
..
2026-08-30 10:42:59 +00:00

Reference

Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.

Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.

Available Reference

Document Scope
wire-formats.md All FMP and FSP message byte layouts, encapsulation walkthrough
configuration.md Full YAML configuration reference for the daemon and gateway
security.md nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix
nostr-events.md Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays
transports.md Per-transport statistics counter inventory
control-socket.md Line-delimited JSON control protocol for the daemon and gateway
native-api.md Native datagram API: the Rust surface, addressing and ports, errno table, ceilings, line protocol, command reference
cli-fips.md fips daemon CLI: options, exit codes, environment, files
cli-fipsctl.md fipsctl control-client: subcommands, options, exit codes
cli-fipstop.md fipstop live-status TUI: tabs, keybindings
cli-fips-gateway.md fips-gateway service CLI: options, exit codes, files