mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 23:18:24 +00:00
Production traffic containing unparseable client messages tore down the entire WebSocket connection. A single bad message - most visibly requests carrying invalid event IDs, failing deserialization with `Invalid input length 64` - propagated out of the relay's read loop and closed the session, so every affected client had to reconnect and re-subscribe. One malformed frame cost a client all of its live subscriptions, and clients that retried the same payload produced sustained connection churn. The defect was upstream in rust-nostr's local relay, not in ngit-grasp, and was reported as nostr:nevent1qqsqmmfv6fxk995yr5858eev7z6zmchchgmk90d4rffuuwe6ewcvx0cpz3mhxue69uhhyetvv9ujumn8d96zuer9wckedd82 and fixed by nostr:nevent1qqs24l0rv6qw3mdqdaj8nj4wlds2gy8a9wrqs3gj5kcmz27c8gm7kagpz3mhxue69uhhyetvv9ujumn8d96zuer9wc7gp6cp Deserialization failures are now contained inside the WebSocket loop and answered with a `NOTICE`, leaving the session and its subscriptions intact. Upgrade the NostrDevKit crates from 0.45.0-alpha.3 to 0.45.0-alpha.8, the first published release containing the fix. Inclusion was verified three ways rather than by release notes: upstream commit 7c0f3aa2cf2fbeb9f0067cb2349579754919eabd is an ancestor of the `Bump to v0.45.0-alpha.8` commit on upstream master; the alpha.8 crate downloaded from crates.io contains the repaired match arm in `src/local_relay/local/inner.rs`; and it also ships the upstream regression test `test_malformed_client_message_does_not_close_connection`, which drives a real WebSocket with a short-author REQ and asserts a subsequent valid REQ still reaches EOSE on the same socket. That upstream test covers the behaviour directly, so no equivalent test is duplicated here. All four rust-nostr crates move together to keep the tree off a mixture of alpha versions. `nostr-relay-builder` is gone: upstream merged it into `nostr-sdk` at alpha.4, so its imports become `nostr_sdk::local_relay` and `nostr_sdk::prelude`, and `nostr-sdk` now enables the `local-relay` feature. Three further alpha-to-alpha API removals are absorbed: `nostr::hashes` is no longer re-exported, so the `Sec-WebSocket-Accept` derivation depends on `bitcoin_hashes` directly - the same crate `nostr` still uses internally, so no second hash implementation enters the tree; `BoxedFuture` became crate-private, so `WritePolicy::admit_event` spells out its `Pin<Box<dyn Future<...>>>` return type; and `EventBuilder::text_note` was removed in favour of `EventBuilder::new(Kind::TextNote, ..)`, which affects test code only. These requirements are pinned exactly as `=0.45.0-alpha.n` rather than left as caret requirements. Cargo reads `"0.45.0-alpha.3"` as `^0.45.0-alpha.3`, which admits *any* later prerelease of 0.45.0 even though prereleases promise no compatibility - exactly the surprise reported against ngit in nostr:nevent1qqs0yvj4z302cjsnqx9jpp78jrfujhse0w47adjncwkxr922rjltk8spz3mhxue69uhhyetvv9ujumn8d96zuer9wcr42j8n where a declared alpha.2 resolved to alpha.7. This upgrade is direct evidence that the risk is real: alpha.4 deleted a whole crate this project depended on, which a caret requirement would have accepted silently. Pinning is safe because it only narrows resolution, and the committed `Cargo.lock` already selects these versions; what it adds is protection for builds that do not honour the lockfile - `cargo install`, and downstream consumers of the `ngit_grasp` library. The pins should be relaxed to caret requirements once 0.45.0 is released. Validated in the project Nix development shell with `CARGO_BUILD_JOBS=2`: `cargo fmt --all --check` clean, `cargo clippy --workspace --all-targets -D warnings` clean, and `cargo test --workspace --no-fail-fast` at 1937 passed / 32 failed. The 32 failures were confirmed pre-existing by running the identical suite on unmodified master in this environment: the same 1937/32 split and a byte-identical set of failing test names, so this upgrade introduces no regressions. All dependencies remain crates.io sources, so no `flake.nix` or `nix/module.nix` hashes required updating.
161 lines
4.0 KiB
TOML
161 lines
4.0 KiB
TOML
[package]
|
|
name = "ngit-grasp"
|
|
version = "2.0.0"
|
|
edition = "2021"
|
|
authors = ["ngit-grasp contributors"]
|
|
license = "MIT"
|
|
description = "A GRASP (Git Relays Authorized via Signed-Nostr Proofs) implementation in Rust"
|
|
repository = "https://gitworkshop.dev/danconwaydev.com/ngit-grasp"
|
|
|
|
[dependencies]
|
|
# Async runtime
|
|
tokio = { version = "1.35", features = ["full"] }
|
|
|
|
# HTTP server (hyper for relay integration)
|
|
hyper = { version = "1.4", features = ["full"] }
|
|
hyper-util = { version = "0.1", features = ["tokio", "server", "http1", "http2"] }
|
|
http-body-util = "0.1"
|
|
|
|
# Nostr
|
|
#
|
|
# These are prerelease (alpha) requirements and are pinned exactly with `=`.
|
|
# Cargo treats `"0.45.0-alpha.8"` as `^0.45.0-alpha.8`, which accepts *any*
|
|
# later prerelease of 0.45.0 even though alphas carry no compatibility
|
|
# guarantee (alpha.4 deleted the `nostr-relay-builder` crate outright). Exact
|
|
# pins keep lockfile-less builds - `cargo install`, downstream consumers of the
|
|
# `ngit_grasp` library - on the version this tree is tested against.
|
|
# Relax to caret requirements once 0.45.0 is released.
|
|
nostr = "=0.45.0-alpha.8"
|
|
# `local-relay` carries the embedded relay implementation, previously the
|
|
# separate `nostr-relay-builder` crate.
|
|
nostr-sdk = { version = "=0.45.0-alpha.8", features = ["local-relay"] }
|
|
nostr-lmdb = "=0.45.0-alpha.8"
|
|
nostr-memory = "=0.45.0-alpha.8"
|
|
|
|
# Utilities
|
|
# SHA-1 for the `Sec-WebSocket-Accept` handshake. `nostr` uses this same crate
|
|
# internally but stopped re-exporting it as `nostr::hashes` in 0.45.0-alpha.8,
|
|
# so depend on it directly rather than pulling in a second hash implementation.
|
|
bitcoin_hashes = "0.14"
|
|
futures-util = "0.3"
|
|
base64 = "0.22"
|
|
flate2 = "1.0"
|
|
tar = "0.4"
|
|
fs2 = "0.4"
|
|
|
|
# Metrics
|
|
prometheus = "0.14"
|
|
dashmap = "6"
|
|
lazy_static = "1.4"
|
|
|
|
# Data structures
|
|
indexmap = "2"
|
|
|
|
# Random (for startup jitter)
|
|
rand = "0.10"
|
|
|
|
# Serialization
|
|
serde = { version = "1.0", features = ["derive"] }
|
|
serde_json = "1.0"
|
|
|
|
# Logging
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
|
|
|
# Configuration
|
|
dotenvy = "0.15"
|
|
clap = { version = "4.5", features = ["derive", "env"] }
|
|
|
|
# Error handling
|
|
anyhow = "1.0"
|
|
|
|
# Async traits
|
|
async-trait = "0.1"
|
|
|
|
# Temporary directories (used for GRASP-06 empty-repo synthesis)
|
|
tempfile = "3"
|
|
|
|
# Git (for future use)
|
|
# git-http-backend = "0.3"
|
|
|
|
[dev-dependencies]
|
|
# Testing
|
|
grasp-audit = { path = "grasp-audit", version = "0.2.0" }
|
|
tempfile = "3"
|
|
reqwest = { version = "0.13", default-features = false, features = ["native-tls"] }
|
|
|
|
[lib]
|
|
name = "ngit_grasp"
|
|
path = "src/lib.rs"
|
|
|
|
[[bin]]
|
|
name = "ngit-grasp"
|
|
path = "src/main.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_announcement_cascade"
|
|
path = "tests/lifecycle/nip09_announcement_cascade.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_blacklist_ops"
|
|
path = "tests/lifecycle/nip09_blacklist_ops.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_cascade_event_types"
|
|
path = "tests/lifecycle/nip09_cascade_event_types.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_disrespector"
|
|
path = "tests/lifecycle/nip09_disrespector.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_git_archive_cleanup"
|
|
path = "tests/lifecycle/nip09_git_archive_cleanup.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_holding_cleanup"
|
|
path = "tests/lifecycle/nip09_holding_cleanup.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_holding_db"
|
|
path = "tests/lifecycle/nip09_holding_db.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_multi_maintainer"
|
|
path = "tests/lifecycle/nip09_multi_maintainer.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_recovery"
|
|
path = "tests/lifecycle/nip09_recovery.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_state_cascade"
|
|
path = "tests/lifecycle/nip09_state_cascade.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_state_multi_maintainer"
|
|
path = "tests/lifecycle/nip09_state_multi_maintainer.rs"
|
|
|
|
[[test]]
|
|
name = "nip09_validation"
|
|
path = "tests/lifecycle/nip09_validation.rs"
|
|
|
|
[[test]]
|
|
name = "deletion_request_retention"
|
|
path = "tests/lifecycle/deletion_request_retention.rs"
|
|
|
|
[[test]]
|
|
name = "nip62_lifecycle"
|
|
path = "tests/lifecycle/nip62_lifecycle.rs"
|
|
|
|
[[test]]
|
|
name = "nip62_validation"
|
|
path = "tests/lifecycle/nip62_validation.rs"
|
|
|
|
[[test]]
|
|
name = "replaceable_history"
|
|
path = "tests/lifecycle/replaceable_history.rs"
|
|
|
|
[workspace]
|
|
members = [".", "grasp-audit"]
|