mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-25 18:45:20 +00:00
Verify Nostr inbound signatures once, off the main actor
Every inbound relay event was Schnorr-verified TWICE, both times on the main actor: once in NostrRelayManager.handleParsedMessage and again in each NostrInboundPipeline / GeoPresenceTracker handler. Each verification re-serializes the event JSON, hashes it, and runs a secp256k1 Schnorr verify, so busy geohashes paid double crypto on the UI thread. Geohash gift-wrap NIP-17 decryption (two ECDH+ChaCha layers) also ran on the main actor. Changes: - NostrRelayManager now owns a serial off-main inbound pipeline (AsyncStream + single consumer task): frames are parsed and verified in arrival order off the main actor, preserving per-subscription delivery order. This is the single verification point for the whole inbound path; downstream handlers only ever see verified events. - Dedup stays two-phase and unpoisonable: a cheap main-actor duplicate LOOKUP runs before verification (duplicate fan-in from several relays never pays for crypto — previously every duplicate was verified), and events are RECORDED as seen only after the signature verifies, so a forged-signature copy can never suppress the genuine event. - NostrInboundPipeline and GeoPresenceTracker drop their redundant re-verification; geohash gift-wrap decryption moves off the main actor following the existing account-mailbox Task.detached pattern (atomic main-actor check-and-record, then decrypt off-main, then hop back for state updates). - Tests: relay-level coverage for tampered gift wraps and for in-order delivery of back-to-back frames; pipeline-level tampered-signature tests move to the relay boundary where the invariant now lives; the mock relay connection queues frames emitted before receive re-arms. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -77,8 +77,10 @@ final class PerformanceBaselineTests: XCTestCase {
|
||||
// MARK: - 1a. Nostr inbound event handling (fresh events)
|
||||
|
||||
/// `NostrInboundPipeline.handleNostrEvent` for never-seen geo events
|
||||
/// (kind 20000): signature verification, dedup record, presence/nickname
|
||||
/// bookkeeping, and public-message ingest scheduling.
|
||||
/// (kind 20000): dedup record, presence/nickname bookkeeping, and
|
||||
/// public-message ingest scheduling. Schnorr signature verification is
|
||||
/// NOT part of this path anymore — it runs exactly once, off the main
|
||||
/// actor, in `NostrRelayManager` before delivery.
|
||||
func testNostrInboundEventHandling_freshEvents() throws {
|
||||
let events = try Self.makeSignedGeohashEvents(count: 500)
|
||||
// A fresh context per measure pass so every event takes the
|
||||
@@ -106,8 +108,9 @@ final class PerformanceBaselineTests: XCTestCase {
|
||||
|
||||
/// The dedup-hit path: identical events replayed. Duplicates dominate
|
||||
/// real relay traffic (the same event arrives from several relays), so
|
||||
/// this path runs hundreds of times a minute in busy geohashes. Note it
|
||||
/// still pays full Schnorr signature verification before the dedup check.
|
||||
/// this path runs hundreds of times a minute in busy geohashes. It is a
|
||||
/// pure dedup lookup: no crypto (verification happens upstream in
|
||||
/// `NostrRelayManager`, and only for the first-seen copy).
|
||||
func testNostrInboundEventHandling_duplicateEvents() throws {
|
||||
let events = try Self.makeSignedGeohashEvents(count: 500)
|
||||
let context = PerfNostrContext()
|
||||
|
||||
Reference in New Issue
Block a user