mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-25 19:05:20 +00:00
* Add capability bits to announce TLV Announces now carry an optional capabilities TLV (0x05): a little-endian bitfield with named bits for upcoming features (prekeys, wifiBulk, gateway, groups, board, vouch, meshDiagnostics). Old clients skip the unknown TLV; peers without it decode as nil so features can distinguish "legacy peer" from "advertises nothing". PeerCapabilities lives in BitFoundation with a minimal-length encoding that preserves unknown bits for forward compatibility. Peer capabilities are stored in the BLE peer registry on verified announce and exposed via BLEService.peerCapabilities(_:). The local advertisement set is empty until each feature ships its bit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Gateway mode: opt-in mesh↔Nostr uplink for geohash channels An opt-in "internet gateway" toggle lets one connected phone bridge the local geohash channel for mesh-only peers: signed kind-20000 events ride a new nostrCarrier (0x28) packet — directed to the gateway for uplink, broadcast with TTL for downlink — with Schnorr verification at every hop, CourierStore-style quotas, and explicit loop-prevention rules. - BitFoundation: MessageType.nostrCarrier = 0x28 - NostrCarrierPacket: 2-byte-length TLV codec (direction, geohash, signed event JSON), 16 KiB cap, tolerant decoder - GatewayService: closure-injected policy layer — verify gates (sig, kind, #g tag, age, size), uplink quotas (10/min/depositor rate limit, offline queue of 20 total / 5 per depositor, drop-oldest, flush on reconnect), downlink budget (30/min, bounded drop-oldest backlog), bounded loop-prevention ID sets - BLEService: runtime capability bits (advertise .gateway only while the toggle is on, re-announce on change), signed directed uplink sends, carrier ingress with depositor signature verification - Mesh-only senders uplink automatically from sendGeohash when no relay is connected and a reachable peer advertises .gateway; once-per- channel "sent via mesh gateway" notice - UI: gateway toggle beside the Tor toggle, globe header indicator, VoiceOver labels, xcstrings entries Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Gateway: harden downlink freshness, uplink verify ordering, and drain Fixes the confirmed downlink/uplink defects from the PR #1384 review + Codex findings: - Downlink age + #g gate (Codex P2 / review #1): rebroadcastRelayEvent now drops events outside the same freshness window receivers enforce and whose #g tag mismatches the carrier geohash, BEFORE spending any budget — so a 1h/200-event channel-resubscribe backfill no longer burns the 30/min BLE budget on events every receiver drops. - Rate-limit + dedup before Schnorr (review #2): handleUplinkDeposit now runs cheap structural checks + carried-ID dedup + rate-token consume before isValidSignature(), so a replay flood is bounded by cheap work instead of unbounded main-actor verifies. - Quota-dropped deposits not rendered (review #3): enqueueUplink reports acceptance and injectInbound only fires for events actually published/queued, ending the local-timeline divergence. - Drain timer + mark-after-send (Codex P2 / review #4): a burst beyond budget now arms a timer to drain when the window frees; rebroadcast IDs are marked only after an event is actually sent, so overflow- dropped events stay retryable. - Symmetric publish path (review #5): the gateway publish closure now refuses when no geo relay is known, matching the local send path instead of publishing dead traffic to default relays. - Loop-rule doc (review #7): softened to reflect that rule 3 is a call-site convention with unit-tested backstops; added tests for the publishedEventIDs backstop, downlink freshness/mismatch, drain timer, and quota-drop non-injection. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Gateway: stop self-echo of uplinked events onto the mesh Every event a gateway uplinks to the relays comes back through its own geohash subscription. `rebroadcastRelayEvent` deduped against `meshBroadcastEventIDs`, `rebroadcastEventIDs`, and `pendingDownlinks`, but not `publishedEventIDs` — so an event this gateway just published was downlink-rebroadcast onto the same mesh it originated from, doubling BLE airtime per uplinked message and able to starve the 30/min downlink budget on a busy channel (device-confirmed, filed on #1384). Fix: also skip the downlink rebroadcast when the event id is in `publishedEventIDs`. That set is already the bounded (drop-oldest, capacity maxTrackedEventIDs) loop-rule-2 uplink cache, populated only by `publish()`, so genuine inbound-from-internet events (never published here) still rebroadcast normally. Reconciles cleanly with the existing loop-prevention sets — no new state. Adds a GatewayServiceTests case asserting an uplinked event that echoes back via the subscription is not rebroadcast, while a genuine inbound event still is. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: jack <jackjackbits@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
97 lines
4.2 KiB
Swift
97 lines
4.2 KiB
Swift
//
|
|
// NostrCarrierPacketTests.swift
|
|
// bitchat
|
|
//
|
|
// This is free and unencumbered software released into the public domain.
|
|
// For more information, see <https://unlicense.org>
|
|
//
|
|
|
|
import Foundation
|
|
import Testing
|
|
@testable import bitchat
|
|
|
|
@Suite("Nostr carrier packet TLV")
|
|
struct NostrCarrierPacketTests {
|
|
private func makeEvent(geohash: String = "u4pruy", content: String = "hello mesh") throws -> NostrEvent {
|
|
let identity = try NostrIdentity.generate()
|
|
return try NostrProtocol.createEphemeralGeohashEvent(
|
|
content: content,
|
|
geohash: geohash,
|
|
senderIdentity: identity,
|
|
nickname: "tester"
|
|
)
|
|
}
|
|
|
|
@Test("round-trips both directions with the signed event intact")
|
|
func roundTrip() throws {
|
|
let event = try makeEvent()
|
|
for direction in [NostrCarrierPacket.Direction.toGateway, .fromGateway] {
|
|
let packet = try #require(NostrCarrierPacket(direction: direction, geohash: "u4pruy", event: event))
|
|
let encoded = try #require(packet.encode())
|
|
let decoded = try #require(NostrCarrierPacket.decode(encoded))
|
|
|
|
#expect(decoded == packet)
|
|
#expect(decoded.direction == direction)
|
|
#expect(decoded.geohash == "u4pruy")
|
|
|
|
// The carried event survives byte-exact: same ID, and the
|
|
// signature still verifies after the mesh hop.
|
|
let carried = try #require(decoded.event())
|
|
#expect(carried.id == event.id)
|
|
#expect(carried.sig == event.sig)
|
|
#expect(carried.isValidSignature())
|
|
}
|
|
}
|
|
|
|
@Test("rejects an oversized event at construction and at decode")
|
|
func oversizedRejected() throws {
|
|
let oversized = Data(repeating: 0x7B, count: NostrCarrierPacket.maxEventJSONBytes + 1)
|
|
#expect(NostrCarrierPacket(direction: .toGateway, geohash: "u4pruy", eventJSON: oversized) == nil)
|
|
|
|
// Hand-build the TLV bytes to bypass the initializer's cap.
|
|
var data = Data([0x01, 0x00, 0x01, NostrCarrierPacket.Direction.toGateway.rawValue])
|
|
let geohash = Data("u4pruy".utf8)
|
|
data.append(contentsOf: [0x02, 0x00, UInt8(geohash.count)])
|
|
data.append(geohash)
|
|
data.append(contentsOf: [0x03, UInt8((oversized.count >> 8) & 0xFF), UInt8(oversized.count & 0xFF)])
|
|
data.append(oversized)
|
|
#expect(NostrCarrierPacket.decode(data) == nil)
|
|
}
|
|
|
|
@Test("rejects an over-length or empty geohash")
|
|
func geohashBoundsEnforced() throws {
|
|
let event = try makeEvent()
|
|
#expect(NostrCarrierPacket(direction: .toGateway, geohash: "", event: event) == nil)
|
|
#expect(NostrCarrierPacket(direction: .toGateway, geohash: String(repeating: "u", count: 13), event: event) == nil)
|
|
#expect(NostrCarrierPacket(direction: .toGateway, geohash: String(repeating: "u", count: 12), event: event) != nil)
|
|
}
|
|
|
|
@Test("skips unknown TLVs for forward compatibility")
|
|
func unknownTLVSkipped() throws {
|
|
let event = try makeEvent()
|
|
let packet = try #require(NostrCarrierPacket(direction: .fromGateway, geohash: "u4pruy", event: event))
|
|
var encoded = try #require(packet.encode())
|
|
// Append an unknown TLV (type 0x7F, 2-byte value).
|
|
encoded.append(contentsOf: [0x7F, 0x00, 0x02, 0xDE, 0xAD])
|
|
let decoded = try #require(NostrCarrierPacket.decode(encoded))
|
|
#expect(decoded == packet)
|
|
}
|
|
|
|
@Test("rejects truncated and missing-field payloads")
|
|
func malformedRejected() throws {
|
|
let event = try makeEvent()
|
|
let packet = try #require(NostrCarrierPacket(direction: .toGateway, geohash: "u4pruy", event: event))
|
|
let encoded = try #require(packet.encode())
|
|
|
|
// Truncation anywhere inside the last TLV fails cleanly.
|
|
#expect(NostrCarrierPacket.decode(encoded.dropLast(1)) == nil)
|
|
#expect(NostrCarrierPacket.decode(encoded.prefix(4)) == nil)
|
|
#expect(NostrCarrierPacket.decode(Data()) == nil)
|
|
|
|
// Direction TLV alone (missing geohash and event) fails.
|
|
#expect(NostrCarrierPacket.decode(Data([0x01, 0x00, 0x01, 0x01])) == nil)
|
|
// Unknown direction value fails.
|
|
#expect(NostrCarrierPacket.decode(Data([0x01, 0x00, 0x01, 0x77])) == nil)
|
|
}
|
|
}
|