feat(pow): apply WoT-distance-based PoW reductions - #779
Open
Priyanshubhartistm wants to merge 2 commits into
Open
Priyanshubhartistm wants to merge 2 commits into
Priyanshubhartistm wants to merge 2 commits into
Conversation
Signed-off-by: Priyanshubhartistm <bhartipriyanshustm@gmail.com>
Signed-off-by: Priyanshubhartistm <bhartipriyanshustm@gmail.com>
🦋 Changeset detectedLatest commit: acc6622 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Collaborator
There was a problem hiding this comment.
🟡 Changes recommended
Two unresolved moderate findings affect NIP-11 PoW metadata and malformed threshold validation.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds optional WoT-distance-based reductions to adaptive event PoW.
Changes:
- Adds configurable WoT thresholds and policy calculation.
- Integrates asynchronous WoT lookups into event acceptance.
- Adds validation, defaults, documentation, tests, and release notes.
File summaries
| File | Summary | Review notes |
|---|---|---|
test/unit/utils/wot-pow-policy.spec.ts |
Tests WoT PoW policy behavior. | No final comments. |
test/unit/utils/settings-config.spec.ts |
Tests threshold configuration validation. | No final comments. |
test/unit/handlers/event-message-handler.spec.ts |
Tests handler integration and async admission. | No final comments. |
src/utils/wot-pow-policy.ts |
Applies distance-based difficulty factors. | No final comments. |
src/utils/settings-config.ts |
Validates WoT threshold settings. | Moderate (3 votes): malformed null or undefined entries can cause validation to throw instead of reporting an issue. |
src/handlers/event-message-handler.ts |
Integrates WoT-aware PoW checks. | Moderate (1 vote): NIP-11 still advertises floorBits although accepted events may use lower or zero difficulty. |
src/factories/message-handler-factory.ts |
Injects the WoT service. | No final comments. |
src/@types/settings.ts |
Defines threshold configuration types. | No final comments. |
resources/default-settings.yaml |
Adds disabled-by-default configuration. | No final comments. |
CONFIGURATION.md |
Documents the new settings. | No final comments. |
.changeset/wot-aware-pow-policy.md |
Records the release change. | No final comments. |
Review details
Suppressed comments (1)
src/handlers/event-message-handler.ts:230
- This policy can reduce
requiredBitsbelowfloorBits(including to 0), but the NIP-11 response still advertisesfloorBitsaslimitation.min_pow_difficultyfor every event inroot-request-handler.ts:115-120. That metadata no longer describes all accepted events, so clients may incorrectly treat the advertised value as mandatory; update the NIP-11 representation/contract and its tests when enabling per-pubkey reductions.
const requiredBits = applyWotPowPolicy(computedDifficulty, distance, limits.pow.wotThresholds)
- Files reviewed: 11/11 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+614
to
+627
| pow.wotThresholds.forEach((threshold, index) => { | ||
| if (!(threshold.maxDistance >= 0)) { | ||
| issues.push({ | ||
| path: `limits.event.pow.wotThresholds[${index}].maxDistance`, | ||
| message: 'maxDistance must be >= 0', | ||
| }) | ||
| } | ||
| if (!(threshold.difficultyFactor >= 0) || !(threshold.difficultyFactor <= 1)) { | ||
| issues.push({ | ||
| path: `limits.event.pow.wotThresholds[${index}].difficultyFactor`, | ||
| message: 'difficultyFactor must be between 0 and 1', | ||
| }) | ||
| } | ||
| }) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
nostream now has a Web of Trust graph exposing a distance-lookup API, and a relay-load-aware adaptive PoW pipeline that scales the required eventId difficulty with observed event rate. The two didn't talk to each other every pubkey faced the same computed difficulty regardless of how trusted it is.
This wires the WoT graph into the adaptive PoW pipeline via
limits.event.pow.wotThresholds: an ordered list of{ maxDistance, difficultyFactor }entries. The eligible threshold with the smallestmaxDistanceapplies, scaling the computed difficulty bydifficultyFactor(0 bypasses eventId PoW entirely, 1 requires the full computed difficulty, fractional values in between). A pubkey outside the trust graph, or beyond every configured threshold, always pays the fullcomputed difficulty. Disabled by default (no thresholds configured), and only ever consults the WoT graph when at least one threshold is configured, so relays not using this stay unaffected.
EventMessageHandler.canAcceptEvent()is nowasyncto support the distance lookup every other check inhandleMessage's chain was already async, so this keeps the same style rather than special-casing one synchronous check.Related Issue
Closes #778
Motivation and Context
A fixed adaptive difficulty treats a well-connected community member the same as a completely unknown pubkey under load. Reducing (or waiving) the PoW requirement for pubkeys inside the operator's trust circle means a trusted author can keep posting instantly during a spam flood, while an unknown pubkey still has to prove it isn't a bot.