Skip to content

History / Security model

Revisions

  • Security model: the key-holder gap is closed

    @w453y w453y committed Oct 2, 2026
  • Security model: a compromised neighbour that holds the key

    @w453y w453y committed Oct 2, 2026
  • Scheduling and the dead-man bound, from the bare-metal runs The unit now runs the engine SCHED_FIFO 60 (#26) and the dead-man bound defaults to 3 s (#25). Why, with the bare-metal numbers, and which sessions need the engine scheduled at all.

    @w453y w453y committed Sep 30, 2026
  • Finals within a budget, packets no faster than the peer may send RFC conformance names the Poll budget as deviation 4 and the spacing as a note; Monitoring lists too-fast and changes-lost; the security model adds the churning-timer flood; Limitations has the engine at 2% for 1024.

    @w453y w453y committed Sep 24, 2026
  • Security model: floods at 1024 sessions, and the two new budgets The eight flood arms against the 1024-session mesh, and the moved-address and echo budgets they led to; Monitoring lists the two new counters.

    @w453y w453y committed Sep 24, 2026
  • Separate the instructions from the measurements The instruction pages had this testbed in them. A sample attach showed an interface the page had not told anyone to use, the scheduling note appealed to the testbed as though a reader knew what that was, and the troubleshooting page talked about a full mesh, which is this project word for its own fabric and not something anyone else has. The measurement pages keep their numbers, which is the point of them, but now say what travels to another machine. Per-frame costs do; packets per second belong to one NIC and one CPU. Session counts are given out of 64 because that is the fabric they were taken on, and what matters is whether any session was lost rather than the denominator. Also says what native and generic attach mean, since the sample output prints one of them and nothing explained it.

    @w453y w453y committed Sep 21, 2026
  • Seed the wiki: deployment, limitations, conformance, kernels, security, testing The README was cut back to what a reader needs first. This is the rest of it: the deployment notes and the reserved-port trap, the deviations from stock bfdd and from the RFC, the kernels the object is known to load on, the threat model and the flood measurements, and what each test suite covers and needs.

    @w453y w453y committed Sep 20, 2026