refactor: take nostrPublicKey() from the library, and pin it against NIP-06

The app has carried its own `LocalKeyManager.nostrPublicKey()` in
WalletManagerExtension.kt since before the library's returned anything usable:
the library's gave back `publicKey().toHex()`, the 33-byte compressed encoding,
so the app went through quartz -- `KeyPair(privKey).pubKey.toHexKey()` -- to
get the x-only key that relays, events and npubs actually carry. As of
lightning-kmp-app 84cc44c the library's returns the x-only key too, and the
app's copy is a second implementation of the one value that is every profile's
identity. This deletes it and switches its three callers -- RelaysSocketManager,
NavigationViewModel, CreateProfileViewModel -- to
`fr.acinq.phoenix.managers.nostrPublicKey`.

**The two were proved equal before anything was deleted, not read to be.** They
go through different stacks (quartz's `KeyPair` against bitcoin-kmp's
`xOnly()`), and a difference between them would not fail a build or a test: it
would publish every existing profile under a new key on the next launch, with
nothing on screen to say so. So the first form of the test in this commit built
one `LocalKeyManager` from NIP-06's mnemonic exactly as CreateProfileViewModel
does -- `NodeParamsManager.chain`, `NodeParamsManager.remoteSwapInXpub` -- and
called both functions on it, the library's imported under an alias because the
names collide. Equal on mainnet, which is what the app ships on, and equal on
Testnet3, where the library derives from account 1' instead of 0'. Only then
did the app's go.

**What remains is a pin from the consuming side, anchored to NIP-06 rather than
to a captured output.** A value copied out of a passing run pins the code to
itself; NIP-06 publishes two test vectors -- a twelve-word and a twenty-four-word
mnemonic, empty passphrase, path m/44'/1237'/0'/0/0 -- and that path is the
library's mainnet path exactly, so on the chain the app ships on the answer is
not ours to choose. Both vectors are asserted, and the test also asserts that
`NodeParamsManager.chain` is Mainnet, so a chain change surfaces here as the
moment the published answers stop applying rather than as two mysteriously
failing assertions.

**Quartz stays in the test, as an oracle rather than as an implementation.** The
app signs events with quartz from `nostrPrivateKey()`, and the key it publishes
has to be the one quartz derives for the secret it signs with; that agreement
was the property the deleted copy embodied by construction. It is now stated
once, on mainnet and on Testnet3 -- alongside the shape check, sixty-four
lowercase hex characters, which is the line a revert to the compressed form
(sixty-six) would trip. Off mainnet there is no published vector for account
1', so shape and quartz-agreement are all that is asserted there.

**The test lives in `managers`, not `extensions`.** Its first form sat beside
the function it was checking, in `press.mantra.compose.extensions`. With that
function gone, a test in that package would be about an extension the app no
longer has; `press.mantra.compose.managers` mirrors `fr.acinq.phoenix.managers`,
the library package it pins, and is where the app's other key-material tests
sit. The import in each caller is placed inside the file's sorted
`fr.acinq.phoenix` block rather than where the old `press.mantra` line stood.

:composeApp:compileDebugKotlinAndroid is clean; :composeApp:jvmTest is 736
tests, 0 failures -- the 733 before this change plus the three here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Kgothatso Ngako
2026-09-12 23:06:50 +02:00
parent f4434ab15d
commit 39fb64b6c0
5 changed files with 75 additions and 15 deletions

View File

@@ -1,12 +0,0 @@
package press.mantra.compose.extensions
import com.vitorpamplona.quartz.nip01Core.core.toHexKey
import com.vitorpamplona.quartz.nip01Core.crypto.KeyPair
import fr.acinq.lightning.crypto.LocalKeyManager
import fr.acinq.phoenix.managers.nostrPrivateKey
fun LocalKeyManager.nostrPublicKey(): String {
return KeyPair(
privKey = nostrPrivateKey().value.toByteArray()
).pubKey.toHexKey()
}

View File

@@ -9,6 +9,7 @@ import com.vitorpamplona.quartz.nip77Negentropy.NegCloseCmd
import com.vitorpamplona.quartz.nip77Negentropy.NegMsgCmd
import com.vitorpamplona.quartz.nip77Negentropy.NegOpenCmd
import fr.acinq.phoenix.data.ActiveWallet
import fr.acinq.phoenix.managers.nostrPublicKey
import kotlinx.coroutines.CancellationException
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
@@ -20,7 +21,6 @@ import kotlinx.coroutines.flow.collectLatest
import kotlinx.coroutines.launch
import kotlinx.coroutines.sync.Mutex
import kotlinx.coroutines.sync.withLock
import press.mantra.compose.extensions.nostrPublicKey
/**

View File

@@ -17,6 +17,7 @@ import fr.acinq.bitcoin.byteVector
import fr.acinq.lightning.Lightning
import fr.acinq.lightning.crypto.LocalKeyManager
import fr.acinq.phoenix.managers.NodeParamsManager
import fr.acinq.phoenix.managers.nostrPublicKey
import fr.acinq.phoenix.managers.nsecPassword
import fr.acinq.phoenix.utils.MnemonicLanguage
import kotlinx.coroutines.CoroutineExceptionHandler
@@ -24,7 +25,6 @@ import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.IO
import kotlinx.coroutines.delay
import kotlinx.coroutines.launch
import press.mantra.compose.extensions.nostrPublicKey
import kotlin.time.Duration.Companion.seconds
class CreateProfileViewModel(

View File

@@ -9,6 +9,7 @@ import press.mantra.compose.ui.composable.navigation.routes.SovereignWalletStart
import press.mantra.compose.ui.view.state.NavigationUIState
import co.touchlab.kermit.Logger
import fr.acinq.phoenix.data.ActiveWallet
import fr.acinq.phoenix.managers.nostrPublicKey
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.IO
@@ -21,7 +22,6 @@ import kotlinx.coroutines.flow.distinctUntilChanged
import kotlinx.coroutines.flow.firstOrNull
import kotlinx.coroutines.flow.getAndUpdate
import kotlinx.coroutines.launch
import press.mantra.compose.extensions.nostrPublicKey
import kotlin.time.Duration.Companion.milliseconds
class NavigationViewModel(

View File

@@ -0,0 +1,72 @@
package press.mantra.compose.managers
import com.vitorpamplona.quartz.nip01Core.core.toHexKey
import com.vitorpamplona.quartz.nip01Core.crypto.KeyPair
import fr.acinq.bitcoin.Chain
import fr.acinq.bitcoin.MnemonicCode
import fr.acinq.bitcoin.byteVector
import fr.acinq.lightning.crypto.LocalKeyManager
import fr.acinq.phoenix.managers.NodeParamsManager
import fr.acinq.phoenix.managers.nostrPrivateKey
import fr.acinq.phoenix.managers.nostrPublicKey
import kotlin.test.Test
import kotlin.test.assertEquals
import kotlin.test.assertTrue
/**
* `LocalKeyManager.nostrPublicKey()` is what the app publishes as a profile's
* identity, and since lightning-kmp-app `84cc44c` it comes from the library rather
* than from a copy of its own. This pins the contract from the consuming side:
* x-only, sixty-four lowercase hex characters, NIP-06's published answer for
* NIP-06's own mnemonics, and the same key quartz -- the stack the app signs with
* -- derives from that secret. A library change back to the 33-byte compressed
* form, or off the NIP-06 path, fails here before it renames every profile.
*/
class NostrPublicKeyJvmTest {
private fun keyManager(
mnemonics: String,
chain: Chain = NodeParamsManager.chain,
swapInXpub: String = NodeParamsManager.remoteSwapInXpub,
) = LocalKeyManager(MnemonicCode.toSeed(mnemonics, "").byteVector(), chain, swapInXpub)
// NIP-06's two test vectors: empty passphrase, path m/44'/1237'/0'/0/0 -- which is
// the mainnet path, and the app ships on mainnet.
@Test
fun `is NIP-06's answer for its twelve-word vector`() {
assertEquals(Chain.Mainnet, NodeParamsManager.chain)
assertEquals(
"17162c921dc4d2518f9a101db33695df1afb56ab82f5ff3e5da6eec3ca5cd917",
keyManager("leader monkey parrot ring guide accident before fence cannon height naive bean")
.nostrPublicKey()
)
}
@Test
fun `is NIP-06's answer for its twenty-four-word vector`() {
assertEquals(
"d41b22899549e1f3d335a31002cfd382174006e166d3e658e3a5eecdb6463573",
keyManager(
"what bleak badge arrange retreat wolf trade produce cricket blur garlic valid " +
"proud rude strong choose busy staff weather area salt hollow arm fade"
).nostrPublicKey()
)
}
// Off mainnet the library derives from account 1', so there is no published answer;
// the shape and the agreement with quartz still have to hold there.
@Test
fun `is the x-only key quartz derives from the same secret, on every chain`() {
val mnemonics = "leader monkey parrot ring guide accident before fence cannon height naive bean"
val testnetSwapInXpub = "tpubDDt5vQap1awkyDXx1z1cP7QFKSZHDCCpbU8nSq9jy7X2grTjUVZDePexf6gc6AHtRRzkgfPW87K6EKUVV6t3Hu2hg7YkHkmMeLSfrP85x41"
for (km in listOf(keyManager(mnemonics), keyManager(mnemonics, Chain.Testnet3, testnetSwapInXpub))) {
val key = km.nostrPublicKey()
assertTrue(key.matches(Regex("[0-9a-f]{64}")), "${km.chain}: not 32 bytes of lowercase hex: $key")
assertEquals(
KeyPair(privKey = km.nostrPrivateKey().value.toByteArray()).pubKey.toHexKey(),
key,
"${km.chain}: quartz derives a different key from the same secret"
)
}
}
}