Skip to content

chore: bump nmilat to v0.4.0 and gitignore go.work - #58

Merged
naliyi merged 2 commits into
mainfrom
worktree-bump-nmilat-v0.4.0
Sep 23, 2026
Merged

naliyi merged 2 commits into
mainfrom
worktree-bump-nmilat-v0.4.0

Conversation

@naliyi

@naliyi naliyi commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

Moves ncli onto the latest published nmilat and makes the pinned remote version the one that actually builds.

The bump: v0.3.1 → v0.4.0

The reason to take it is the v0.3.2 relay fix, which ncli on v0.3.1 was exposed to:

The relay could freeze until restarted. A REQ kept its database read open while sending events to the client, so when a write needed to grow the database file, every other REQ and EVENT on the relay hung — even with healthy clients, and while health checks stayed green.

Anyone running ncli relay could hit that. v0.3.2 also dropped debug logging from busy relay paths.

v0.4.0 is breaking upstream — but not for ncli

It renames NIP-CASH's "bearer" mode to cash mode across the wire and the Go API. Those renames are confined to the BearerTarget / BearerSecret / RekeyBearerSlice family. ncli only uses nipcash.Decode, nipcash.Encode and nipcash.Token, none of which changed — the single Bearer hit elsewhere in the tree is an HTTP Authorization header in the meilisearch client, unrelated.

Verified rather than assumed: go build ./... and go vet ./... clean, and go test -short -race ./... passes — including client/decode_test.go and cli/ncli/decode_test.go, which round-trip an actual cash token through encode/decode.

One thing to be aware of operationally, from upstream's own note: v0.4.0 only speaks to a Hub running lokihub 0.5.0-rc.6 or later. Existing tokens and <token>#<secret> strings are unaffected.

Use the remote version, not a local workspace

go.work and go.work.sum are now gitignored. A local go.work silently overrides the nmilat version pinned in go.mod, so a developer's build and CI stop agreeing about what's actually being compiled — which is exactly why verifying a bump requires GOWORK=off. Keeping the workspace files out of the repo means the pinned remote version is what builds.

(There was no replace directive in go.mod; the shadowing came from the workspace file.)

Verification

gofmt, go build, go vet, go test -short -race ./..., golangci-lint v2.13.2 (0 issues), and CI's own tidy check — go mod tidy against the committed state produces no diff.

Picks up the v0.3.2 relay fix: a REQ held its database read open while
sending events, so a write that grew the database file hung every other
REQ and EVENT until the relay was restarted -- health checks included.
ncli was on v0.3.1 and exposed to it.

v0.4.0 itself is breaking upstream, renaming NIP-CASH's bearer mode to
cash mode across the Go API, but the renames are confined to the
BearerTarget/BearerSecret/RekeyBearerSlice family. ncli only uses
nipcash.Decode/Encode/Token, which are untouched, so nothing here
changes.
A local go.work silently overrides the nmilat version pinned in go.mod,
so a developer's build and CI stop agreeing about which version is in
use -- which is why verifying a bump needs GOWORK=off. Keeping the
workspace files out of the repo means the pinned remote version is
always what actually builds.
@naliyi
naliyi merged commit 5863587 into main Sep 23, 2026
7 of 8 checks passed
@naliyi
naliyi deleted the worktree-bump-nmilat-v0.4.0 branch September 23, 2026 15:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant