mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-24 23:45:18 +00:00
The Tor egress self-check probe had no outer bound: the proxied session sets waitsForConnectivity = true, which can defer the per-request timer indefinitely, leaving a canary request bounded only by URLSession's default 7-day resource timeout. Because verify() joins concurrent callers on the in-flight task and invalidate() neither cancelled nor cleared it, one hung probe wedged every subsequent verify() caller -- even across a Tor restart -- parking awaitingTorForConnections in NostrRelayManager until process restart. Fixes (liveness only; the fail-closed policy is unchanged): - Race every probe against an independent async watchdog (probeTimeout, default 20s = the live probe's request timeout, via TorEgressVerifier.defaultProbeTimeout). On timeout the probe task is cancelled (cooperatively cancelling the underlying URLSessionTask), the verdict is the fail-closed .unreachable, and the in-flight slot is cleared so the next verify() starts fresh. - invalidate() now cancels the in-flight probe and clears it (plus the throttle timestamp it already cleared), so Tor restart/dormant/ shutdown genuinely resets the verifier. - A probe generation counter keeps actor reentrancy safe: a cancelled/ superseded probe cannot re-seed the throttle/cache that invalidate() just cleared or clobber a fresh probe's in-flight slot; its awaiting callers resolve promptly as false. Concurrent-caller join semantics are preserved (one shared probe), and the race resolves exactly once behind an NSLock never held across an await. Tests cover the hung-probe timeout bound, invalidate-cancels- in-flight, post-restart recovery, and the shared-probe invariant, all with the injected probe/clock harness (no real network). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>