About this project

Mohawk Nexus is the root integration workspace for the Mohawk network stack. It aggregates several components into one repository so they can be built, validated and tested together. Workspace layout - SMIP-MWP: Go control plane covering AF_XDP host integration, routing, crypto bindings and bridge request ingestion. - SMIP-MWP-Rust: Rust datapath with a forwarding pipeline, high-performance data plane and CLI tools. - Sovereign-Mohawk-Proto: protocol definitions, schema evolution and formal verification assets. - bridge: canonical bridge schema, manifest and request examples used by root validation. - scripts: workspace-level generation, validation and test helpers. - go.work ties the Go modules together. Requirements and setup Go (1.26.1 pinned for reproducible builds; 1.22+ expected to work for most local workflows), Python 3.8+, Docker for containerized performance/stress runs, and a Rust toolchain only when running the Rust datapath tests locally. A devcontainer configuration pins Go for Codespaces/Dev Containers, and instructions are provided for a sudo-free local Go install. Device compatibility A matrix describes supported profiles: Linux x86_64 servers with AF_XDP-capable NICs (accelerated), Linux arm64 servers/edge nodes, Raspberry Pi/ARM SBCs, macOS and Windows developer machines, and managed Kubernetes without privileged pods (portable). The accelerated AF_XDP datapath is Linux-only; portable workflows cover control, FL and SWIP services plus bridge validation. Runtime profiles are portable, accelerated and experimental. Usage Common Make targets include bootstrap, status, verify, generate-bridge, validate-bridge, verify-go, bridge-smoke and verify-rust. A local FL quickstart builds and runs a coordinator with two clients via docker-compose. Performance and stress harnesses run through scripts/bench.sh and a stress Dockerfile, writing benchmark output and pprof artifacts under SMIP-MWP/benchmarks/. Capabilities - High-performance datapath: Rust forwarder plus AF_XDP integration for low-latency packet processing. - Pluggable crypto: symmetric and asymmetric primitives with in-place encryption/decryption to reduce allocations. - Bridge contract validation: canonical schema and manifest with root-owned validators and reproducible SHA256 checks for example payloads. - Integrated test harnesses producing repeatable artifacts and pprof profiles. - CI-friendly verification: make verify runs root-level validation without depending on unpublished subrepo SHAs. - Containerized performance runs via Dockerfiles and scripts. The README also reports internal micro-benchmark figures (forwarding, multi-path spraying, crypto, session/routing, AF_XDP) on AMD EPYC hardware, with the caveat that results depend on CPU, kernel, NIC and kernel-bypass configuration. It notes that the project prioritizes safety, formal methods, multi-path spraying and sovereign features over raw maximum packet rates. Bridge contract tooling includes scripts to regenerate canonical artifacts, regenerate SDK bridge constants for Go/Rust/Python/TypeScript, and validate the manifest and hashes; bridge/bridge_contract.version.json tracks schema and manifest versions. CI runs make verify from the repository root. The workspace is multi-license because it aggregates components with different upstream licenses, documented in LICENSE and LICENSES.md.