Carries the comment sweep, the key-material clearing, and the two
constant-reconciliation commits up from master. Two of the five items on
that line are deliberately excluded, and most of the resolution work was
keeping them out.
Excluded, and why:
- The frame-length validation does not come. This branch needs its own
design for msg2 and msg3 rather than an extra arm, and that work is
sequenced separately. It arrived silently in four files that merged
without a conflict, so it was removed from each: the reject variant,
the stats counter, the wire helper and its tests, and the receive-path
call site with the dispatch visibility widening its tests wanted.
Landing only the counters would have left a metric that reports zero
forever with nothing able to increment it.
- The post-handshake identity confirmation does not come, and cannot.
The older lines run a pattern that learns the initiator's static key at
message 1; this branch does not learn it until message 3, so there is
no identity to confirm at that point and no insertion point for the
check. Its type, its classifier and its confirmation block all
conflicted and were resolved to this branch's side, but two further
pieces auto-merged with no conflict and had to be removed by hand: the
module visibility widening, and the classifier call site.
- The transport framing constants are not re-sourced here. This branch
has rewritten that whole block: message 1 is a different size, message
2 and message 3 are minimums rather than exact values, and the version
gate is a different version. Taking the incoming side would have
sourced a minimum from an exact value.
Carried, with adaptation where the patterns differ:
- Key-material clearing applies to this branch's own handshake, which is
XX at both layers rather than IK and XK. The incoming code could not be
taken as written, since it carries whole method bodies for patterns
this branch does not use. The erasing guard, the parameter erase in
both constructors, and the clearing of each Diffie-Hellman output and
secret-key copy were applied to this branch's own sites instead.
- The security and session-layer documents keep this branch's pattern
names and gain the correction about the handshake AEAD, which passes
an empty associated-data field here too.
- The drain-window test needed this branch's optional-identity
constructor, since an anonymous dial is a first-class case here.
Architectural and protocol-level explanations for FIPS — the why
and the how behind the wire and the system. For wire formats and
configuration keys, see reference/. For task
recipes, see how-to/. For end-to-end lessons, see
tutorials/.
Reading Order
Start with fips-concepts.md for the
novice-friendly framing of what FIPS is and why, then move to
fips-architecture.md for the protocol stack,
identity model, and two-layer encryption walkthrough. From there,
follow the protocol stack from bottom to top. After the stack,
fips-mesh-operation.md explains how the
pieces work together at runtime. Cross-cutting and supporting
documents cover specific subsystems in detail.