mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 23:18:24 +00:00
A public mirror gains nothing from dialing a GRASP-08 private service: the service will never admit it, and even attempting the connection performs an AUTH exchange with a relay that only wants members. Worse, retry machinery would hammer it indefinitely. Approach: public instances fetch the NIP-11 document before the WebSocket dial (`preflight_limit_hints`). When it advertises GRASP-08, the worker returns a new `ConnectAttemptOutcome::PrivateService` without dialing. The actor parks the relay in `private_service_relays` (warn once, stable message tests grep for), retires all sync state without the re-registration path, and both `register_relay` and `schedule_connect_relay` refuse parked targets thereafter. Private instances treat GRASP-08 peers as ordinary sync targets and skip the probe. Session limit hints deliberately keep coming from the existing post-connect fetch: reusing the pre-dial probe for hints would remove the post-connect setup window whose stale-success handling (disconnect during NIP-11 setup) is separately guaranteed and tested. Correctness assumptions: the pre-dial NIP-11 probe is an outbound TCP connection, so `preflight_limit_hints` re-runs the resolved outbound target policy for event-directed URLs and skips the HTTP request entirely on rejection - `connect()` then fails with the same policy rejection through its own gate (tests/outbound_policy.rs stays green). The park set is in-memory by design: a service that stops being private becomes reachable again after a process restart at the latest. Deliberately excluded: private-instance behavior toward GRASP-08 peers (NIP-98 credentials on git fetches) lands separately. Test infrastructure: `wait_for_log_line` moved from outbound_policy.rs into the shared sync helpers; TestRelay gained a sync constructor with identity publication disabled so log assertions about the bootstrap connection are not confounded by user-index traffic. SetupDropRelay now answers pre-dial NIP-11 probes directly and only runs its drop-during-setup choreography for a fetch that arrives during a live WebSocket session; the naughty-list scheduling test accounts for the probe as a second accepted connection on the first attempt. Validation: new tests/sync/outbound_auth.rs proves the park warning appears exactly once and that, across a 2s observation window, the private bootstrap relay is never connected to and no NIP-42 authentication occurs. cargo test --test sync -- sync::outbound_auth sync::stale_connect_result sync::naughty_list_scheduling and --test outbound_policy pass.
71 lines
2.7 KiB
Rust
71 lines
2.7 KiB
Rust
//! Outbound Authentication and GRASP-08 Private-Service Sync Policy
|
|
//!
|
|
//! These tests cover how a syncing instance treats relays that demand
|
|
//! authentication or advertise the GRASP-08 private-service extension:
|
|
//!
|
|
//! - A PUBLIC instance recognizes a GRASP-08 private service from its NIP-11
|
|
//! document before dialing, and parks it without any WebSocket connection
|
|
//! or AUTH exchange.
|
|
|
|
use std::time::Duration;
|
|
|
|
use crate::common::{wait_for_log_line, TestRelay};
|
|
use nostr_sdk::prelude::*;
|
|
|
|
/// The stable park warning emitted when a public instance excludes a
|
|
/// GRASP-08 private service from sync.
|
|
const PARK_LOG: &str = "Relay advertises GRASP-08 private service; excluding it from public sync";
|
|
|
|
/// A public instance must never dial a relay whose NIP-11 advertises
|
|
/// GRASP-08: the private service would only refuse it, and dialing would
|
|
/// leak an AUTH exchange to a service that never admits this mirror.
|
|
#[tokio::test]
|
|
async fn public_instance_parks_grasp08_relay_without_dialing() {
|
|
let member = Keys::generate();
|
|
let private_service = TestRelay::start_private(&member.public_key()).await;
|
|
let syncing =
|
|
TestRelay::start_with_sync_without_user_index(Some(private_service.url().to_string()))
|
|
.await;
|
|
|
|
let parked = wait_for_log_line(&syncing.log_path(), Duration::from_secs(30), |line| {
|
|
line.contains(PARK_LOG) && line.contains(private_service.url())
|
|
})
|
|
.await;
|
|
assert!(
|
|
parked,
|
|
"public instance must park its GRASP-08 bootstrap relay"
|
|
);
|
|
|
|
// Absence over time (see relay_identity.rs for the sanctioned pattern):
|
|
// across a 2s observation window the parked relay is never connected to,
|
|
// no NIP-42 authentication happens, and the park warning is not repeated.
|
|
let window_end = tokio::time::Instant::now() + Duration::from_secs(2);
|
|
loop {
|
|
let log = tokio::fs::read_to_string(syncing.log_path())
|
|
.await
|
|
.unwrap_or_default();
|
|
assert!(
|
|
!log.lines()
|
|
.any(|line| line.contains("Connected") && line.contains(private_service.url())),
|
|
"parked GRASP-08 relay must never be dialed"
|
|
);
|
|
assert!(
|
|
!log.lines()
|
|
.any(|line| line.contains("Authenticated to relay")),
|
|
"no NIP-42 exchange may happen with a parked relay"
|
|
);
|
|
assert_eq!(
|
|
log.lines().filter(|line| line.contains(PARK_LOG)).count(),
|
|
1,
|
|
"park warning must be logged exactly once"
|
|
);
|
|
if tokio::time::Instant::now() >= window_end {
|
|
break;
|
|
}
|
|
tokio::time::sleep(Duration::from_millis(100)).await;
|
|
}
|
|
|
|
syncing.stop().await;
|
|
private_service.stop().await;
|
|
}
|