Files
fips/docs
Johnathan Corgan fe9e51316f Merge branch 'master' into next
Five conflicts, all from the pre-v0.5.0 batch landing in handshake and
rekey code that next's peer/control-machine refactor has already
rewritten. How each was resolved, since none of it is mechanical:

src/node/handlers/rekey.rs keeps next's comment. Both sides describe the
same removal and differ only in which sibling arms they name, and next's
names next's own.

src/node/handlers/handshake.rs takes master's comment. next already had
the `let _slot` binding and the test-build assertion below it; what it
lacked was the paragraph saying why the binding name is load-bearing,
which is the thing a later tidy-up would delete.

src/node/tests/acl.rs keeps next's file whole. next already covers the
outbound ACL reject arm with a test written against its own structure;
master's variant is written against master's API and its helper does not
exist here. An earlier attempt spliced the two and produced a duplicate
definition and four unresolved names.

src/node/tests/unit.rs keeps next's side plus one test from master's,
`msg1_handler_holds_its_pending_slot_while_the_handler_runs`. The rest of
master's side already exists on next and would have duplicated it. The
test is placed at module level: the conflict boundary fell inside another
function's signature, so taking the hunk verbatim nested it and clippy
caught it as an inner test item.

src/node/tests/establish_chartests.rs is removed. next has no such
module; master modified it in the same commit.

Gated here rather than assumed: rustfmt clean, clippy clean at
-D warnings, 2381 tests passed and 0 failed, all six repo guards exit 0,
and the carried-over test confirmed present in the run output.
2026-08-25 21:27:37 +01:00
..
2026-08-21 05:55:35 +00:00
2026-08-21 05:55:35 +00:00
2026-08-25 21:27:37 +01:00
2026-08-22 11:04:58 +01:00

FIPS Documentation

FIPS (Free Internetworking Peering System) is a self-organizing encrypted mesh network built on Nostr identities, capable of operating over arbitrary transports — local networks, the public internet, Tor, Bluetooth, or point-to-point links — without central infrastructure.

With FIPS, your machine becomes a node in the mesh with a self-generated cryptographic identity. There are two ways to deploy it.

As an overlay on top of existing IP networks, FIPS lets your node reach any other FIPS node wherever it sits — behind a NAT, on a different ISP, on a phone over cellular, on a laptop with only Bluetooth in range, or behind a Tor onion. The mesh forwards IPv6 traffic transparently and end-to-end encrypted, with no central VPN concentrator or coordinating server.

From the ground up over raw Ethernet, WiFi, or Bluetooth, FIPS provides a complete permissionless network without any pre-existing IP infrastructure, ISP, or DNS. Any node that joins the link gets routable IPv6 addresses, peer discovery, and a path to every other node automatically.

Either way, existing networking software runs over it unchanged: SSH, HTTP servers, file transfer, anything IPv6-native works the same way it would on a local network.

New to FIPS? Start with the Getting Started guide.

Documentation Sections

Tutorials

If you are starting from scratch and want a guided path to a working mesh, go here.

How-To Guides

If you have a specific task in mind — enabling a feature, deploying a component, diagnosing a problem — go here.

Reference

If you need to look up wire formats, configuration keys, command flags, or counter inventories, go here.

Design

If you want to understand how the mesh self-organizes, why FIPS makes the choices it does, or how the pieces fit together, go here.