chore: bump nmilat to v0.4.0 and gitignore go.work - #58
Merged
Merged
Conversation
Picks up the v0.3.2 relay fix: a REQ held its database read open while sending events, so a write that grew the database file hung every other REQ and EVENT until the relay was restarted -- health checks included. ncli was on v0.3.1 and exposed to it. v0.4.0 itself is breaking upstream, renaming NIP-CASH's bearer mode to cash mode across the Go API, but the renames are confined to the BearerTarget/BearerSecret/RekeyBearerSlice family. ncli only uses nipcash.Decode/Encode/Token, which are untouched, so nothing here changes.
A local go.work silently overrides the nmilat version pinned in go.mod, so a developer's build and CI stop agreeing about which version is in use -- which is why verifying a bump needs GOWORK=off. Keeping the workspace files out of the repo means the pinned remote version is always what actually builds.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moves ncli onto the latest published
nmilatand makes the pinned remote version the one that actually builds.The bump: v0.3.1 → v0.4.0
The reason to take it is the v0.3.2 relay fix, which ncli on v0.3.1 was exposed to:
Anyone running
ncli relaycould hit that. v0.3.2 also dropped debug logging from busy relay paths.v0.4.0 is breaking upstream — but not for ncli
It renames NIP-CASH's "bearer" mode to cash mode across the wire and the Go API. Those renames are confined to the
BearerTarget/BearerSecret/RekeyBearerSlicefamily. ncli only usesnipcash.Decode,nipcash.Encodeandnipcash.Token, none of which changed — the singleBearerhit elsewhere in the tree is an HTTPAuthorizationheader in the meilisearch client, unrelated.Verified rather than assumed:
go build ./...andgo vet ./...clean, andgo test -short -race ./...passes — includingclient/decode_test.goandcli/ncli/decode_test.go, which round-trip an actual cash token through encode/decode.One thing to be aware of operationally, from upstream's own note: v0.4.0 only speaks to a Hub running lokihub 0.5.0-rc.6 or later. Existing tokens and
<token>#<secret>strings are unaffected.Use the remote version, not a local workspace
go.workandgo.work.sumare now gitignored. A localgo.worksilently overrides thenmilatversion pinned ingo.mod, so a developer's build and CI stop agreeing about what's actually being compiled — which is exactly why verifying a bump requiresGOWORK=off. Keeping the workspace files out of the repo means the pinned remote version is what builds.(There was no
replacedirective ingo.mod; the shadowing came from the workspace file.)Verification
gofmt,go build,go vet,go test -short -race ./..., golangci-lint v2.13.2 (0 issues), and CI's own tidy check —go mod tidyagainst the committed state produces no diff.