From f4434ab15dc1b4175e39389c9432ba2c18933a12 Mon Sep 17 00:00:00 2001 From: Kgothatso Ngako Date: Sat, 12 Sep 2026 23:06:23 +0200 Subject: [PATCH] build: advance lightning-kmp-app onto the nostr credentials file Moves the pin from 01489b8 to 84cc44c, three commits on the submodule's master: two features and the merge between them. The submodule's own messages call this the library half of the app's nsec/npub sign-in plan; the app half is not in this commit, which changes no composeApp source. The first feature gives a nostr key with no seed above it somewhere to live. A key pasted in as an nsec cannot go in seed.dat, whose reader runs MnemonicCode.toSeed over every entry and whose format is inherited from upstream, so it gets a sibling file, nostr-keys.dat, under the same KEY_NO_AUTH: one version byte, a 16-byte iv, and the ciphertext of a JSON map from x-only public key to private key. Every secret is re-derived on read and must land on its own key, so a corrupt file is refused rather than handed out under the wrong identity. The temp-file / read-back / atomicMove discipline SeedManager always had is lifted into AtomicFileWrite so the new file gets it by calling rather than by copying; SeedManager.writeSeedToDir now goes through it with its original check and its original exception type, and the three public entry points the app uses -- loadAndDecrypt, loadAndDecryptOrNull, writeSeedToDisk -- are unchanged. The second replaces that file's shape with a typed one before anything has written it in anger. nostr-credentials.dat holds one entry per x-only public key, each either {"type":"secret","privateKey":hex} or {"type":"public"}, so a profile signed in read-only and the same profile with its nsec pasted later are one entry in one file, and the second is a single write over the first. It is a new file rather than version 2 of the old one because an older build's identity listing returns on an unreadable version before it publishes anything, and would list no wallets at all, seed wallets included; a file it does not look for cannot do that to it. NostrCredentialManager.migrateFromNostrKeys reads the old file once, writes the new one and deletes the old, and runs only while the new file is absent. NostrKeyManager becomes LegacyNostrKeysFile, read-only, for that one caller. Also in WalletManager.kt: PrivateKey.nostrPublicKeyHex(), the x-only form, and LocalKeyManager.nostrPublicKey() now returns it. That function used to return publicKey().toHex(), the 33-byte compressed encoding, which is not a nostr public key at all -- nothing in the library called it, and the app has been carrying an extension of its own with the same name instead. Retiring that copy is the next commit, not this one. The nested experimental/lightning-kmp gitlink does not move: it stays at 5103b79, so the lightning-kmp -> bitcoin-kmp -> secp256k1-kmp chain under the composite is exactly what it was, and nothing native is rebuilt. Verified in the composite: :composeApp:compileDebugKotlinAndroid is clean, :composeApp:jvmTest is 733 tests, 0 failures, and :lightning-kmp-app:library:jvmTest is 159 tests, 0 failures, 3 skipped -- up from 128 by exactly the 31 tests in the four new classes (EncryptedNostrKeysTest, EncryptedNostrCredentialsTest, LegacyNostrKeysFileJvmTest, NostrCredentialManagerJvmTest), the skips still being the @Ignore'd ElectrumServersTest. Co-Authored-By: Claude Opus 5 --- lightning-kmp-app | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lightning-kmp-app b/lightning-kmp-app index 01489b81..84cc44c8 160000 --- a/lightning-kmp-app +++ b/lightning-kmp-app @@ -1 +1 @@ -Subproject commit 01489b81fe8fa2e47ca813fe231b9e5cd3b34ee2 +Subproject commit 84cc44c855e3d173e26016b807c449153a3af597