docs(geode): plan reflects VerifyAuthOnlyPolicy split
Tier 3 used to say operators "must omit VerifyPolicy from their policy chain" when parallelVerify is on — that turned out to be the AUTH-verify regression caught in the audit. Updated the plan to describe the real wiring: VerifyPolicy was split into a parameterised base with two singletons, and composePolicy swaps in VerifyAuthOnlyPolicy so AUTH commands keep signature verification even when the IngestQueue takes EVENT verify.
This commit is contained in:
@@ -95,13 +95,24 @@ verifies pre-mark `Rejected` and skip the insert.
|
|||||||
Wired through `NostrServer(parallelVerify = ...)` and
|
Wired through `NostrServer(parallelVerify = ...)` and
|
||||||
`geode.Relay(parallelVerify = ...)`, controlled by
|
`geode.Relay(parallelVerify = ...)`, controlled by
|
||||||
`[options].parallel_verify` in the relay config (default `true`)
|
`[options].parallel_verify` in the relay config (default `true`)
|
||||||
and `--no-parallel-verify` on the CLI. Operators that flip it on
|
and `--no-parallel-verify` on the CLI. Internal direct callers of
|
||||||
must omit `VerifyPolicy` from their policy chain — `Main.kt` does
|
`NostrServer` (tests, library users) are opt-in: the flag defaults
|
||||||
this automatically; `composePolicy` is told to skip the
|
to `false` to keep existing `VerifyPolicy`-in-chain semantics
|
||||||
`VerifyPolicy` piece when `parallelVerify` is true. Internal
|
unchanged.
|
||||||
direct callers of `NostrServer` (tests, library users) are
|
|
||||||
opt-in: the flag defaults to `false` to keep existing
|
`VerifyPolicy` was split into a parameterised
|
||||||
`VerifyPolicy`-in-chain semantics unchanged.
|
`VerifyEventsAndAuthPolicy(verifyEvents)` with two singletons:
|
||||||
|
|
||||||
|
- `VerifyPolicy` (default): verifies both `EVENT` and `AUTH`.
|
||||||
|
- `VerifyAuthOnlyPolicy`: verifies `AUTH` only, used when the
|
||||||
|
`IngestQueue` is doing the EVENT verify.
|
||||||
|
|
||||||
|
When `parallelVerify` is on, `composePolicy` swaps `VerifyPolicy`
|
||||||
|
for `VerifyAuthOnlyPolicy` so EVENTs aren't verified twice while
|
||||||
|
AUTH commands — which bypass the queue entirely — keep their
|
||||||
|
signature check. Without this split, removing `VerifyPolicy` from
|
||||||
|
the chain would let a forged AUTH event mark a pubkey as
|
||||||
|
authenticated.
|
||||||
|
|
||||||
Expected: ≈CPU_COUNT× verify-step speed-up on burst publishes
|
Expected: ≈CPU_COUNT× verify-step speed-up on burst publishes
|
||||||
from a single connection, where verify was previously serial on
|
from a single connection, where verify was previously serial on
|
||||||
|
|||||||
Reference in New Issue
Block a user