From ddaddf3056a3099db1d6a09dc47806ed68b08b73 Mon Sep 17 00:00:00 2001 From: naliyi <154817482+naliyi@users.noreply.github.com> Date: Wed, 23 Sep 2026 15:33:09 +0000 Subject: [PATCH 1/2] chore: bump github.com/ohstr/nmilat to v0.4.0 Picks up the v0.3.2 relay fix: a REQ held its database read open while sending events, so a write that grew the database file hung every other REQ and EVENT until the relay was restarted -- health checks included. ncli was on v0.3.1 and exposed to it. v0.4.0 itself is breaking upstream, renaming NIP-CASH's bearer mode to cash mode across the Go API, but the renames are confined to the BearerTarget/BearerSecret/RekeyBearerSlice family. ncli only uses nipcash.Decode/Encode/Token, which are untouched, so nothing here changes. --- CHANGELOG.md | 5 +++++ go.mod | 2 +- go.sum | 4 ++-- 3 files changed, 8 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 0369418..2278af5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -21,6 +21,7 @@ **stderr** -- help used to land on stdout -- and exit codes are unchanged, so a bare group command still exits 2, never 0. `--json` is untouched: one structured line, never help. (#55) +- Updated `nmilat` to v0.4.0. ### Fixed @@ -28,6 +29,10 @@ own line) and exited 1 instead of 2. (#55) - `ncli bunker sessions revoke-grant` with no `--method` exited 1 as `internal` instead of 2 as `usage`. (#55) +- `ncli relay` could freeze until restarted: a `REQ` held its database + read open while sending events, so a write that grew the database file + hung every other `REQ` and `EVENT`, health checks included. Fixed + upstream in `nmilat` v0.3.2. ## [0.5.0] diff --git a/go.mod b/go.mod index 2fc261a..58bbbe4 100644 --- a/go.mod +++ b/go.mod @@ -68,7 +68,7 @@ require ( github.com/charmbracelet/bubbles v1.0.0 github.com/charmbracelet/bubbletea v1.3.10 github.com/charmbracelet/lipgloss v1.1.0 - github.com/ohstr/nmilat v0.3.1 + github.com/ohstr/nmilat v0.4.0 github.com/spf13/pflag v1.0.10 golang.org/x/sync v0.20.0 golang.org/x/sys v0.45.0 diff --git a/go.sum b/go.sum index 8656f6a..5986e26 100644 --- a/go.sum +++ b/go.sum @@ -89,8 +89,8 @@ github.com/muesli/cancelreader v0.2.2 h1:3I4Kt4BQjOR54NavqnDogx/MIoWBFa0StPA8ELU github.com/muesli/cancelreader v0.2.2/go.mod h1:3XuTXfFS2VjM+HTLZY9Ak0l6eUKfijIfMUZ4EgX0QYo= github.com/muesli/termenv v0.16.0 h1:S5AlUN9dENB57rsbnkPyfdGuWIlkmzJjbFf0Tf5FWUc= github.com/muesli/termenv v0.16.0/go.mod h1:ZRfOIKPFDYQoDFF4Olj7/QJbW60Ol/kL1pU3VfY/Cnk= -github.com/ohstr/nmilat v0.3.1 h1:XCxcXyrmC9wlAehhwBzhwqGwDXmt6vV7/B5CstdoRfw= -github.com/ohstr/nmilat v0.3.1/go.mod h1:+6B0CT40RAJmnZESl1sBukc07RkdyPn5/EQ8ROVof0Y= +github.com/ohstr/nmilat v0.4.0 h1:/5jP47QwNMwafxGSUX5rdgxDqNzrZ01K8scEY/BMX/0= +github.com/ohstr/nmilat v0.4.0/go.mod h1:+6B0CT40RAJmnZESl1sBukc07RkdyPn5/EQ8ROVof0Y= github.com/pelletier/go-toml/v2 v2.2.3 h1:YmeHyLY8mFWbdkNWwpr+qIL2bEqT0o95WSdkNHvL12M= github.com/pelletier/go-toml/v2 v2.2.3/go.mod h1:MfCQTFTvCcUyyvvwm1+G6H/jORL20Xlb6rzQu9GuUkc= github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0= From 7cb34d2cb05096432714c56bca70b74c59833fde Mon Sep 17 00:00:00 2001 From: naliyi <154817482+naliyi@users.noreply.github.com> Date: Wed, 23 Sep 2026 15:33:20 +0000 Subject: [PATCH 2/2] chore: gitignore go.work and go.work.sum A local go.work silently overrides the nmilat version pinned in go.mod, so a developer's build and CI stop agreeing about which version is in use -- which is why verifying a bump needs GOWORK=off. Keeping the workspace files out of the repo means the pinned remote version is always what actually builds. --- .gitignore | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.gitignore b/.gitignore index 40dca45..9aaccec 100644 --- a/.gitignore +++ b/.gitignore @@ -56,5 +56,11 @@ vendor/ # Local scratch drafts, not meant to be tracked /.drafts/ +# Go workspace files. A local go.work silently overrides the nmilat version +# pinned in go.mod, so builds and CI stop agreeing; keep it out of the repo +# and use GOWORK=off when verifying a dependency bump. +/go.work +/go.work.sum + # Local-only planning/audit docs, not meant to be tracked /docs/private/