mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 11:38:24 +00:00
Carries show_peers stale reporting, derived from how long a peer has been silent. Carries the removal of the stored peer connectivity, which on this line also drops the always-true health conjunct from the msg3 cross-connection and rekey-responder gates and from the rekey scan, and drops the send filter from next-hop candidate selection. Carries per-connection ids and draining closes on TCP, Tor and Nym, so a crossed TCP handshake's msg3 is written before the losing connection closes. Carries the reuse flags on an adopted traversal socket, whose node test now drives this line's three-message handshake directly instead of one receive-loop pass per node. Carries the netmon test and the probe's measured syscall cost. The rekey msg2 rollback from maint is not carried here: its read rollback, handler arm, node test and changelog entry are written for IK, so this merge keeps this line's XX rekey msg2 path as it was, and the XX change follows in its own commit. Two tests reached the msg2 resend arm through a health lever production never sets. The node test now reaches it through a rekey declaration naming keys the responder no longer holds, after replacing the responder's keys the way a cross-connection swap does, and the core test declares a mismatched rekey on the peer's own link. A new core test covers a matching declaration with no session, so the rekey-responder gate's session check keeps a test that can fail. The establish characterisation test file and the IK duplicate-msg1 decision test stay out, as before. The conflicts were next's XX establish classification and its rewritten establish tests against master's edits to the IK versions; every region resolves to next's text with only the health and send-state reads removed and their doc comments reworded.
Reference
Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.
Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.
Available Reference
| Document | Scope |
|---|---|
| wire-formats.md | All FMP and FSP message byte layouts, encapsulation walkthrough |
| configuration.md | Full YAML configuration reference for the daemon and gateway |
| security.md | nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix |
| nostr-events.md | Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays |
| transports.md | Per-transport statistics counter inventory |
| control-socket.md | Line-delimited JSON control protocol for the daemon and gateway |
| native-api.md | Native datagram API: the Rust surface, addressing and ports, errno table, ceilings, line protocol, command reference |
| cli-fips.md | fips daemon CLI: options, exit codes, environment, files |
| cli-fipsctl.md | fipsctl control-client: subcommands, options, exit codes |
| cli-fipstop.md | fipstop live-status TUI: tabs, keybindings |
| cli-fips-gateway.md | fips-gateway service CLI: options, exit codes, files |