Skip to content

fix(mobile): keep push discovery working when NIP-11 grows - #8017

Open
superkim0610 wants to merge 2 commits into
block:mainfrom
superkim0610:fix/push-nip11-extensible
Open

superkim0610 wants to merge 2 commits into
block:mainfrom
superkim0610:fix/push-nip11-extensible

Conversation

@superkim0610

@superkim0610 superkim0610 commented Oct 1, 2026 •

Copy link
Copy Markdown

Summary

iOS push never activates against current relays. BuzzPushLeaseDescriptor.fromRelayInformation rejected any NIP-11 document with a top-level field outside a fixed allowlist. The relay always emits artifacts and also emits read_state_snapshot (#7572), so every push-enabled relay failed that check. Discovery treats this as "no push capability" and only logs it with debugPrint. The app never asks for notification permission, never registers with APNs, and never enrolls or publishes a lease, so turning push on in Settings does nothing. The pending lease revocation outbox calls the same function, so it was blocked as well.

NIP-11 is an extensible document. NIP-PL requires strict validation only for the push descriptor. This removes the top-level allowlist and leaves descriptor validation unchanged. Unknown fields inside push are still rejected, as covered by descriptor rejects unknown push fields.

Related issue

None found. Companion fixes for iOS push end to end:

Testing

  • The regression test descriptor ignores relay metadata outside push adds artifacts, read_state_snapshot and an invented future field. Before the fix it fails with FormatException: NIP-11 document contains unknown field artifacts, the same error a device hits. After the fix it passes.
  • flutter test --dart-define=BUZZ_PUSH_GATEWAY_URL=https://push.example test/shared/push/ passes 99 tests with 3 skipped. dart format and flutter analyze are clean.
  • Device check by a human: an iPhone on iOS 27 ran a TestFlight build with this fix against a self-hosted relay (ghcr.io/block/buzz:main, BUZZ_PUSH_ENABLED=true). The notification permission prompt appeared and the gateway enrollment started. A stock build never prompted.
  • Agent review: READY, no blockers. I applied its optional test-strengthening suggestion.

buzz-review-completed

Push discovery rejected any NIP-11 document with a top-level field outside
a fixed allowlist. The relay has since added read_state_snapshot (block#7572)
and artifacts, so every relay now looked push-incapable and iOS never asked
for notification permission or enrolled. NIP-11 is extensible; only the
push descriptor needs strict validation, which stays unchanged.

Signed-off-by: superkim0610 <superkim0610@gmail.com>
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🔐 Codex Security Review

Status: review required for the current range.

The current range is 5fdb2e53659ee29002545f1022c138fe0b8282f9...50b3d8c95d08f20524e76e19265cc38991d92d95.
A new review must complete for this exact range. When manual authorization
is required, a user with write access must comment exactly
@buzz-security-review 50b3d8c95d08f20524e76e19265cc38991d92d95 to authorize a new review.
Any previous review applies only to its recorded range.

Signed-off-by: superkim0610 <superkim0610@gmail.com>
@superkim0610
superkim0610 marked this pull request as ready for review October 1, 2026 10:50
@superkim0610
superkim0610 requested a review from a team as a code owner October 1, 2026 10:50

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant