doc(purgatory): explain why TOCTOU on placeholder upgrade is not a real concern

The test add_prs_pr_placeholder_does_not_overwrite_existing_scoped_placeholder
openly documents that a raw insert would overwrite an existing scoped placeholder
if the caller's gate were bypassed. A reviewer flagged this as a TOCTOU between
two concurrent /prs/ pushes from different submitters for the same event_id.

Add a comment explaining why this race cannot occur in practice: an event_id is
a hash of the event content, which includes the signer's pubkey. Two different
signers therefore cannot share an event_id, so only one submitter can ever
legitimately push a given refs/nostr/<event-id>. The existing check-then-insert
guard is sufficient; no atomic upgrade primitive is needed.
This commit is contained in:
DanConwayDev
2026-05-16 09:38:36 +00:00
parent 3d4dda38ce
commit 661bf584d7
+8
View File
@@ -3247,6 +3247,14 @@ fn add_prs_pr_placeholder_does_not_overwrite_existing_scoped_placeholder() {
// calling, so this test documents what happens if the gate is bypassed.
// Direct `insert` via add_prs_pr_placeholder would overwrite; the guard in
// post_push_validate prevents that from happening in practice.
//
// NOTE on the apparent TOCTOU: the two-step check-then-insert looks like a
// race between two concurrent /prs/ pushes from *different* submitters for
// the same event_id. In practice this cannot happen: an event_id is a hash
// of the event content, which includes the signer's pubkey. Two different
// signers therefore cannot share an event_id, so only one submitter can ever
// legitimately push a given refs/nostr/<event-id>. No atomic upgrade is
// needed; the guard is sufficient.
let purgatory = Purgatory::new(PathBuf::new());
let submitter_a = Keys::generate();
let submitter_b = Keys::generate();