Files
amethyst/geode/src
Claude 845ae7be14 fix: NIP-FE audit — slow bodies, malformed Content-Type, body buffers, one parse, faster gzip
Bugs (reproduced on a live geode before fixing, now regression tests):
- A body trickled in forever held its admission slot forever: a client
  that declared 100 bytes and sent 5 still had its slot after 20 s, so
  a few addresses could fill the global cap. The body read is now
  bounded by [http].body_timeout_seconds (10 s): 408, Connection: close.
- A malformed Content-Type made the NIP-86 check throw, answering 500.
  It is now compared as text, and a command needs no type at all.

Performance:
- Every request allocated a cap-sized body buffer (512 KiB) for what is
  usually a 50-byte frame. The buffer is now sized to Content-Length,
  or grows from 4 KiB for a chunked body.
- The session parsed each body again after the handler had.
  RelaySession.receive(text, parsed) runs the raw-text policies on the
  text and dispatches the parsed command.
- Gzip at level 1: 42% of raw against 39% at the default 6 on
  Nostr-shaped events, for about 2.5x less CPU. Compressed bytes go to
  the socket from their own buffer instead of a copy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RbNrTdV2e7kW5S9tkMoPgh
2026-09-27 18:18:48 +00:00
..