build: upgrade Nostr dependencies to released 0.45 patches

Our 0.45.0 lockfile predates the released LMDB fix that keeps NIP-77 scans
off async workers. Concurrent scans can otherwise delay unrelated relay
connections. Require the current compatible releases in both workspace
crates and refresh only the six Nostr packages in the shared lockfile.

Use nostr 0.45.5, nostr-sdk/nostr-lmdb 0.45.3, nostr-memory/nostr-database
0.45.2 and nostr-gossip 0.45.1. These also exclude expired reconciliation
items and separate continuation accounting from query starts. Document the
relay validation fixes in the patch-release changelog and update the
architecture dependency examples. All packages use crates.io sources;
there are no Git vendor hashes to update.

Keep the service configuration, release version and production diagnostic
pin unchanged. Retiring the now-redundant local compatibility overrides is
a separate follow-up commit. This upgrade does not claim the production
timeouts have been conclusively attributed to NIP-77 traffic.

Validation: workspace formatting, all-target workspace Clippy with warnings
denied and the full locked workspace test suite pass with the accompanying
compatibility cleanup and separate startup reconstruction race fix. The
initial suite exposed that existing race; its original integration assertion
passes unchanged after the fix. Nix package derivation evaluation succeeds.

Assisted-by: GPT-6
This commit is contained in:
DanConwayDev
2026-09-17 13:44:47 +00:00
parent f40e10dee9
commit e37319d6d3
5 changed files with 29 additions and 25 deletions
+9
View File
@@ -9,6 +9,15 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
### Fixed
- Upgrade the Nostr SDK and database dependencies to released 0.45 patch
versions. NIP-77 database scans now run off async workers, avoiding runtime
stalls that can delay unrelated relay connections. Reconciliation excludes
expired events, and NIP-77 continuation messages no longer consume the
query-start allowance.
- Pick up upstream relay validation fixes that reject reposted protected
events and verify the declared proof-of-work target as well as the event hash.
- Require EOSE before accepting background discovery history, instead of treating
a disconnected or timed-out partial response as a completed fetch.
Generated
+13 -12
View File
@@ -1359,9 +1359,9 @@ dependencies = [
[[package]]
name = "nostr"
version = "0.45.0"
version = "0.45.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7279feef28d43a04c0b3529acd4fea923ac816729bd643191b292296f1f6cc13"
checksum = "38ca5c25a6df8d4d78fdf39b42792438f6ce22b4809ccbfdb27582ed9ca45407"
dependencies = [
"base64",
"bech32",
@@ -1379,13 +1379,14 @@ dependencies = [
"unicode-normalization",
"universal-time",
"url",
"zeroize",
]
[[package]]
name = "nostr-database"
version = "0.45.0"
version = "0.45.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "81c7ffd33114d62c737dd2b8f77ffec4693c64b7a1c6090cab0d0009f9986e22"
checksum = "309950383c9854ca413d195705400e78b1376aedc48f3256754a86c609c047e8"
dependencies = [
"nostr",
"opaquerr",
@@ -1393,9 +1394,9 @@ dependencies = [
[[package]]
name = "nostr-gossip"
version = "0.45.0"
version = "0.45.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "fa07539e52a71cb91fe0d693facaa298f03fcf9edcd66a521094e18e286e2336"
checksum = "4ea822fd48ff6b84b81ddf84169e6edf1dc0bc9b312c8e41685b2278debaac3d"
dependencies = [
"nostr",
"opaquerr",
@@ -1403,9 +1404,9 @@ dependencies = [
[[package]]
name = "nostr-lmdb"
version = "0.45.0"
version = "0.45.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b7a313418ff58bfa444ba4b71200ff8fe2d3eb31f2b5d0d8fdb7f5e60a703d31"
checksum = "79727470014fb64cd1e03bf52f82bc46b69cc7ac0a9298a517498a0e84239f2a"
dependencies = [
"async-utility",
"flatbuffers",
@@ -1419,9 +1420,9 @@ dependencies = [
[[package]]
name = "nostr-memory"
version = "0.45.0"
version = "0.45.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "1a827de4b11c4f2b235eabe37f1a67460db68e453606f4755e1ac5a522347a86"
checksum = "f5a9091e50b0ebcf8d9bd8ded23665d0434aa0eeb22b8464fc882ac124dbe5bf"
dependencies = [
"btreecap",
"nostr",
@@ -1431,9 +1432,9 @@ dependencies = [
[[package]]
name = "nostr-sdk"
version = "0.45.0"
version = "0.45.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "359881fbaded2d19a5003609673744b8b68c4973817598eb0e262d049ec9c3f3"
checksum = "c53a37469ce2df8fe6471b6a4d1c4da833f86c7ba0138ac95299b6f37f69ec84"
dependencies = [
"async-utility",
"async-wsocket",
+4 -9
View File
@@ -17,15 +17,10 @@ hyper-util = { version = "0.1", features = ["tokio", "server", "http1", "http2"]
http-body-util = "0.1"
# Nostr
#
# The stable 0.45 series contains the upstream NEG-OPEN handling fix used by
# the embedded relay. Caret requirements accept compatible patch releases.
nostr = "0.45.0"
# `local-relay` carries the embedded relay implementation, previously the
# separate `nostr-relay-builder` crate.
nostr-sdk = { version = "0.45.0", features = ["local-relay"] }
nostr-lmdb = "0.45.0"
nostr-memory = "0.45.0"
nostr = "0.45.5"
nostr-sdk = { version = "0.45.3", features = ["local-relay"] }
nostr-lmdb = "0.45.3"
nostr-memory = "0.45.2"
# Utilities
# SHA-1 for the `Sec-WebSocket-Accept` handshake. `nostr` uses this same crate
+2 -3
View File
@@ -118,9 +118,8 @@ runtime:
```rust
hyper = "1"
tokio = { version = "1", features = ["full"] }
nostr-relay-builder = "0.45.0-alpha.3"
nostr-sdk = "0.45.0-alpha.3"
nostr-lmdb = "0.45.0-alpha.3"
nostr-sdk = { version = "0.45.3", features = ["local-relay"] }
nostr-lmdb = "0.45.3"
```
### 2. HTTP Module ([`src/http/mod.rs`](src/http/mod.rs))
+1 -1
View File
@@ -13,7 +13,7 @@ path = "src/bin/grasp-audit.rs"
[dependencies]
# Nostr
nostr-sdk = "0.45.0"
nostr-sdk = "0.45.3"
# Async
tokio = { version = "1", features = ["full"] }