build: advance lightning-kmp-app onto the nostr credentials file
Moves the pin from 01489b8 to 84cc44c, three commits on the submodule's master:
two features and the merge between them. The submodule's own messages call this
the library half of the app's nsec/npub sign-in plan; the app half is not in
this commit, which changes no composeApp source.
The first feature gives a nostr key with no seed above it somewhere to live. A
key pasted in as an nsec cannot go in seed.dat, whose reader runs
MnemonicCode.toSeed over every entry and whose format is inherited from
upstream, so it gets a sibling file, nostr-keys.dat, under the same
KEY_NO_AUTH: one version byte, a 16-byte iv, and the ciphertext of a JSON map
from x-only public key to private key. Every secret is re-derived on read and
must land on its own key, so a corrupt file is refused rather than handed out
under the wrong identity. The temp-file / read-back / atomicMove discipline
SeedManager always had is lifted into AtomicFileWrite so the new file gets it
by calling rather than by copying; SeedManager.writeSeedToDir now goes through
it with its original check and its original exception type, and the three
public entry points the app uses -- loadAndDecrypt, loadAndDecryptOrNull,
writeSeedToDisk -- are unchanged.
The second replaces that file's shape with a typed one before anything has
written it in anger. nostr-credentials.dat holds one entry per x-only public
key, each either {"type":"secret","privateKey":hex} or {"type":"public"}, so a
profile signed in read-only and the same profile with its nsec pasted later are
one entry in one file, and the second is a single write over the first. It is a
new file rather than version 2 of the old one because an older build's identity
listing returns on an unreadable version before it publishes anything, and
would list no wallets at all, seed wallets included; a file it does not look
for cannot do that to it. NostrCredentialManager.migrateFromNostrKeys reads the
old file once, writes the new one and deletes the old, and runs only while the
new file is absent. NostrKeyManager becomes LegacyNostrKeysFile, read-only, for
that one caller.
Also in WalletManager.kt: PrivateKey.nostrPublicKeyHex(), the x-only form, and
LocalKeyManager.nostrPublicKey() now returns it. That function used to return
publicKey().toHex(), the 33-byte compressed encoding, which is not a nostr
public key at all -- nothing in the library called it, and the app has been
carrying an extension of its own with the same name instead. Retiring that copy
is the next commit, not this one.
The nested experimental/lightning-kmp gitlink does not move: it stays at
5103b79, so the lightning-kmp -> bitcoin-kmp -> secp256k1-kmp chain under the
composite is exactly what it was, and nothing native is rebuilt.
Verified in the composite: :composeApp:compileDebugKotlinAndroid is clean,
:composeApp:jvmTest is 733 tests, 0 failures, and
:lightning-kmp-app:library:jvmTest is 159 tests, 0 failures, 3 skipped -- up
from 128 by exactly the 31 tests in the four new classes
(EncryptedNostrKeysTest, EncryptedNostrCredentialsTest,
LegacyNostrKeysFileJvmTest, NostrCredentialManagerJvmTest), the skips still
being the @Ignore'd ElectrumServersTest.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in: