mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-25 05:45:18 +00:00
Verify Nostr inbound signatures once, off the main actor
Every inbound relay event was Schnorr-verified TWICE, both times on the main actor: once in NostrRelayManager.handleParsedMessage and again in each NostrInboundPipeline / GeoPresenceTracker handler. Each verification re-serializes the event JSON, hashes it, and runs a secp256k1 Schnorr verify, so busy geohashes paid double crypto on the UI thread. Geohash gift-wrap NIP-17 decryption (two ECDH+ChaCha layers) also ran on the main actor. Changes: - NostrRelayManager now owns a serial off-main inbound pipeline (AsyncStream + single consumer task): frames are parsed and verified in arrival order off the main actor, preserving per-subscription delivery order. This is the single verification point for the whole inbound path; downstream handlers only ever see verified events. - Dedup stays two-phase and unpoisonable: a cheap main-actor duplicate LOOKUP runs before verification (duplicate fan-in from several relays never pays for crypto — previously every duplicate was verified), and events are RECORDED as seen only after the signature verifies, so a forged-signature copy can never suppress the genuine event. - NostrInboundPipeline and GeoPresenceTracker drop their redundant re-verification; geohash gift-wrap decryption moves off the main actor following the existing account-mailbox Task.detached pattern (atomic main-actor check-and-record, then decrypt off-main, then hop back for state updates). - Tests: relay-level coverage for tampered gift wraps and for in-order delivery of back-to-back frames; pipeline-level tampered-signature tests move to the relay boundary where the invariant now lives; the mock relay connection queues frames emitted before receive re-arms. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -352,31 +352,11 @@ struct ChatViewModelNostrExtensionTests {
|
||||
#expect(!viewModel.messages.contains { $0.content == "Blocked" })
|
||||
}
|
||||
|
||||
@Test @MainActor
|
||||
func handleNostrEvent_rejectsInvalidSignature() async throws {
|
||||
let (viewModel, _) = makeTestableViewModel()
|
||||
let geohash = "u4pruydq"
|
||||
let identity = try NostrIdentity.generate()
|
||||
|
||||
viewModel.switchLocationChannel(to: .location(GeohashChannel(level: .city, geohash: geohash)))
|
||||
|
||||
let event = NostrEvent(
|
||||
pubkey: identity.publicKeyHex,
|
||||
createdAt: Date(),
|
||||
kind: .ephemeralEvent,
|
||||
tags: [["g", geohash]],
|
||||
content: "Valid"
|
||||
)
|
||||
var signed = try event.sign(with: identity.schnorrSigningKey())
|
||||
signed.id = "deadbeef"
|
||||
|
||||
viewModel.handleNostrEvent(signed)
|
||||
|
||||
try? await Task.sleep(nanoseconds: 100_000_000)
|
||||
viewModel.publicMessagePipeline.flushIfNeeded()
|
||||
|
||||
#expect(!viewModel.messages.contains { $0.content == "Tampered" })
|
||||
}
|
||||
// NOTE: Tampered-signature rejection is enforced once, off the main
|
||||
// actor, at the relay boundary (events only reach the inbound pipeline
|
||||
// after verification) — see NostrRelayManagerTests
|
||||
// `test_receiveEvent_invalidSignatureDoesNotPoisonDuplicateCache` and
|
||||
// `test_receiveGiftWrap_tamperedSignatureIsDroppedAndDoesNotPoisonDedup`.
|
||||
|
||||
@Test @MainActor
|
||||
func subscribeGiftWrap_rejectsOversizedEmbeddedPacket() async throws {
|
||||
@@ -565,9 +545,14 @@ struct ChatViewModelNostrExtensionTests {
|
||||
|
||||
viewModel.handleGiftWrap(giftWrap, id: recipient)
|
||||
|
||||
try? await Task.sleep(nanoseconds: 50_000_000)
|
||||
// Gift-wrap decryption runs off the main actor; wait for the ack
|
||||
// (sent even for blocked senders) to know processing finished.
|
||||
let didAck = await TestHelpers.waitUntil(
|
||||
{ viewModel.sentGeoDeliveryAcks.contains(messageID) },
|
||||
timeout: 5.0
|
||||
)
|
||||
#expect(didAck)
|
||||
#expect(viewModel.privateChats[convKey] == nil)
|
||||
#expect(viewModel.sentGeoDeliveryAcks.contains(messageID))
|
||||
}
|
||||
|
||||
@Test @MainActor
|
||||
|
||||
Reference in New Issue
Block a user