mirror of
https://github.com/vitorpamplona/amethyst.git
synced 2026-08-10 08:27:04 +00:00
Findings from an audit of the signer, all verified against the code: - Data race: NostrConnectSignerService deduped request ids inside onEvent, which the relay pool invokes CONCURRENTLY from each relay's socket thread (PoolRequests dispatches listeners outside its lock). Two relays delivering the same subscription could mutate the LinkedHashSet at once → race / CME. Move dedup into the single consumer coroutine; onEvent now only does the thread-safe channel send. - Swallowed cancellation: broad `catch (Exception)` around suspend calls in the processor, the service's decrypt + publish, and connectViaNostrConnect caught CancellationException too, breaking structured cancellation when the service restarts. Rethrow it first (matching the AccountCacheState convention). - Write amplification: the ledger wrote last-used to that client's DataStore file on EVERY authorized request (unthrottled, unlike the relay-auth store). Coalesce to at most one write per client per 60s in the authorizer. - Redundant resubscribe: the enable/relays collector lacked distinctUntilChanged, so a duplicate inbox-relay emission tore the subscription down and re-opened it on every relay for nothing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015FHr2mu5SiHwYNR7evYUuF