Files
fips/docs/reference
Johnathan Corgan 6305287491 Bring the changelog current and correct four documentation defects
The Unreleased block is rebuilt from a walk of all 117 commits since
v0.4.1 rather than from what the block already held, which is how six
gaps surfaced. Two of them were whole missing effects. The identity
write path discarded six results, so a node configured for a persistent
identity could fall through to an ephemeral one in silence and change
its npub, routing address and mesh address on every start. And the
OpenWrt zig download verification was described only in part.

Chronological fix sequences are collapsed to their net state, and fixes
for bugs introduced and closed inside this cycle are folded away rather
than described, since no user ever saw them. Sixty-one CI and harness
commits are summarized rather than left out, because they change what a
contributor running the local pipeline sees. The flat lists are
reorganized into subsections by area. Everything from 0.4.1 down is
untouched.

Two entries carry effects no commit message mentioned. Clearing every
copy of private key material added Drop to four public types, so their
fields can no longer be moved out, which is source-breaking for anyone
using the crate as a library and is reachable through node.identity on
the public config. And the responder-side rekey narrowing covers five
call sites, not the four the original entry claimed; the ack initiator
arm is the one that deliberately still abandons the whole rekey.

The four test-harness fixes landed since then get entries under the CI
and test-harness heading, written as what a contributor sees: a failing
harness that names the condition instead of exiting bare, dns-resolver
scenarios that stop burning the full boot timeout on a container that
booted correctly, and a chaos harness that checks its teardown and node
stops actually happened rather than assuming it.

Four documentation defects are fixed alongside. Two sent macOS readers
to paths that do not exist there: the configuration reference stated the
highest-priority system config path as /etc/fips/fips.yaml
unconditionally, where the macOS package installs under
/usr/local/etc/fips/, and the persistent-identity tutorial had the same
problem throughout with nothing saying its paths were Linux ones. It now
opens with the substitution table, notes that the daemon derives the key
directory from whichever config it loaded, and points at the migration
recipe for a host already carrying keys at the old path.

The other two described test coverage that does not exist. The testing
readme claimed twenty chaos scenarios where ten exist, and the chaos
readme documented three that are in neither runner nor tree. Both
scenario tables are rewritten from the files, and bloom-storm is
described honestly as retired from both runners with no replacement,
which is a coverage gap rather than a migration to other tests.

The readme's Rust badge asserted 1.85+ while rust-toolchain.toml pins
something else, so the badge no longer carries a version and the
toolchain file is the only place that states one.
2026-08-22 09:34:38 +01:00
..

Reference

Information-oriented technical descriptions for lookup on demand. Reference content describes what is: wire formats, configuration keys, command-line flags, control-socket commands, default values, file paths, exit codes. It is consulted, not read end-to-end.

Reference is austere by design: minimal narrative, no opinions, no guidance on when to use a feature. The "why" lives in design/; the "how do I accomplish X" lives in how-to/.

Available Reference

Document Scope
wire-formats.md All FMP and FSP message byte layouts, encapsulation walkthrough
configuration.md Full YAML configuration reference for the daemon and gateway
security.md nftables baseline, peer ACL, cryptographic primitives, rekey defaults, threat-resistance matrix
nostr-events.md Kind 37195 advert, Kind 21059 traversal signaling, Kind 10050 inbox relays
transports.md Per-transport statistics counter inventory
control-socket.md Line-delimited JSON control protocol for the daemon and gateway
cli-fips.md fips daemon CLI: options, exit codes, environment, files
cli-fipsctl.md fipsctl control-client: subcommands, options, exit codes
cli-fipstop.md fipstop live-status TUI: tabs, keybindings
cli-fips-gateway.md fips-gateway service CLI: options, exit codes, files