From e37319d6d38a684420813422e1952b9a607e5f5b Mon Sep 17 00:00:00 2001 From: DanConwayDev Date: Thu, 17 Sep 2026 13:44:34 +0000 Subject: [PATCH] build: upgrade Nostr dependencies to released 0.45 patches Our 0.45.0 lockfile predates the released LMDB fix that keeps NIP-77 scans off async workers. Concurrent scans can otherwise delay unrelated relay connections. Require the current compatible releases in both workspace crates and refresh only the six Nostr packages in the shared lockfile. Use nostr 0.45.5, nostr-sdk/nostr-lmdb 0.45.3, nostr-memory/nostr-database 0.45.2 and nostr-gossip 0.45.1. These also exclude expired reconciliation items and separate continuation accounting from query starts. Document the relay validation fixes in the patch-release changelog and update the architecture dependency examples. All packages use crates.io sources; there are no Git vendor hashes to update. Keep the service configuration, release version and production diagnostic pin unchanged. Retiring the now-redundant local compatibility overrides is a separate follow-up commit. This upgrade does not claim the production timeouts have been conclusively attributed to NIP-77 traffic. Validation: workspace formatting, all-target workspace Clippy with warnings denied and the full locked workspace test suite pass with the accompanying compatibility cleanup and separate startup reconstruction race fix. The initial suite exposed that existing race; its original integration assertion passes unchanged after the fix. Nix package derivation evaluation succeeds. Assisted-by: GPT-6 --- CHANGELOG.md | 9 +++++++++ Cargo.lock | 25 +++++++++++++------------ Cargo.toml | 13 ++++--------- docs/explanation/architecture.md | 5 ++--- grasp-audit/Cargo.toml | 2 +- 5 files changed, 29 insertions(+), 25 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index ef4adda..f8496ba 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,15 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Fixed +- Upgrade the Nostr SDK and database dependencies to released 0.45 patch + versions. NIP-77 database scans now run off async workers, avoiding runtime + stalls that can delay unrelated relay connections. Reconciliation excludes + expired events, and NIP-77 continuation messages no longer consume the + query-start allowance. + +- Pick up upstream relay validation fixes that reject reposted protected + events and verify the declared proof-of-work target as well as the event hash. + - Require EOSE before accepting background discovery history, instead of treating a disconnected or timed-out partial response as a completed fetch. diff --git a/Cargo.lock b/Cargo.lock index f979768..a3e6556 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1359,9 +1359,9 @@ dependencies = [ [[package]] name = "nostr" -version = "0.45.0" +version = "0.45.5" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "7279feef28d43a04c0b3529acd4fea923ac816729bd643191b292296f1f6cc13" +checksum = "38ca5c25a6df8d4d78fdf39b42792438f6ce22b4809ccbfdb27582ed9ca45407" dependencies = [ "base64", "bech32", @@ -1379,13 +1379,14 @@ dependencies = [ "unicode-normalization", "universal-time", "url", + "zeroize", ] [[package]] name = "nostr-database" -version = "0.45.0" +version = "0.45.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "81c7ffd33114d62c737dd2b8f77ffec4693c64b7a1c6090cab0d0009f9986e22" +checksum = "309950383c9854ca413d195705400e78b1376aedc48f3256754a86c609c047e8" dependencies = [ "nostr", "opaquerr", @@ -1393,9 +1394,9 @@ dependencies = [ [[package]] name = "nostr-gossip" -version = "0.45.0" +version = "0.45.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "fa07539e52a71cb91fe0d693facaa298f03fcf9edcd66a521094e18e286e2336" +checksum = "4ea822fd48ff6b84b81ddf84169e6edf1dc0bc9b312c8e41685b2278debaac3d" dependencies = [ "nostr", "opaquerr", @@ -1403,9 +1404,9 @@ dependencies = [ [[package]] name = "nostr-lmdb" -version = "0.45.0" +version = "0.45.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b7a313418ff58bfa444ba4b71200ff8fe2d3eb31f2b5d0d8fdb7f5e60a703d31" +checksum = "79727470014fb64cd1e03bf52f82bc46b69cc7ac0a9298a517498a0e84239f2a" dependencies = [ "async-utility", "flatbuffers", @@ -1419,9 +1420,9 @@ dependencies = [ [[package]] name = "nostr-memory" -version = "0.45.0" +version = "0.45.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "1a827de4b11c4f2b235eabe37f1a67460db68e453606f4755e1ac5a522347a86" +checksum = "f5a9091e50b0ebcf8d9bd8ded23665d0434aa0eeb22b8464fc882ac124dbe5bf" dependencies = [ "btreecap", "nostr", @@ -1431,9 +1432,9 @@ dependencies = [ [[package]] name = "nostr-sdk" -version = "0.45.0" +version = "0.45.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "359881fbaded2d19a5003609673744b8b68c4973817598eb0e262d049ec9c3f3" +checksum = "c53a37469ce2df8fe6471b6a4d1c4da833f86c7ba0138ac95299b6f37f69ec84" dependencies = [ "async-utility", "async-wsocket", diff --git a/Cargo.toml b/Cargo.toml index c9aaf10..7335343 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -17,15 +17,10 @@ hyper-util = { version = "0.1", features = ["tokio", "server", "http1", "http2"] http-body-util = "0.1" # Nostr -# -# The stable 0.45 series contains the upstream NEG-OPEN handling fix used by -# the embedded relay. Caret requirements accept compatible patch releases. -nostr = "0.45.0" -# `local-relay` carries the embedded relay implementation, previously the -# separate `nostr-relay-builder` crate. -nostr-sdk = { version = "0.45.0", features = ["local-relay"] } -nostr-lmdb = "0.45.0" -nostr-memory = "0.45.0" +nostr = "0.45.5" +nostr-sdk = { version = "0.45.3", features = ["local-relay"] } +nostr-lmdb = "0.45.3" +nostr-memory = "0.45.2" # Utilities # SHA-1 for the `Sec-WebSocket-Accept` handshake. `nostr` uses this same crate diff --git a/docs/explanation/architecture.md b/docs/explanation/architecture.md index d49fd77..ff1c4ee 100644 --- a/docs/explanation/architecture.md +++ b/docs/explanation/architecture.md @@ -118,9 +118,8 @@ runtime: ```rust hyper = "1" tokio = { version = "1", features = ["full"] } -nostr-relay-builder = "0.45.0-alpha.3" -nostr-sdk = "0.45.0-alpha.3" -nostr-lmdb = "0.45.0-alpha.3" +nostr-sdk = { version = "0.45.3", features = ["local-relay"] } +nostr-lmdb = "0.45.3" ``` ### 2. HTTP Module ([`src/http/mod.rs`](src/http/mod.rs)) diff --git a/grasp-audit/Cargo.toml b/grasp-audit/Cargo.toml index 503c3c8..a89f2e9 100644 --- a/grasp-audit/Cargo.toml +++ b/grasp-audit/Cargo.toml @@ -13,7 +13,7 @@ path = "src/bin/grasp-audit.rs" [dependencies] # Nostr -nostr-sdk = "0.45.0" +nostr-sdk = "0.45.3" # Async tokio = { version = "1", features = ["full"] }