Laan Tungir
0b1c3ea382
v0.1.24 - Migrate Teensy 4.1 signer to role+path authorization model (deprecate nostr_index)
2026-08-08 13:55:02 -04:00
Laan Tungir
fd895db0c9
v0.1.23 - Make role-as-password the default authorization model; remove interactive approval prompts from wizard; add Makefile guard to direct agents to build_static.sh; optimize build_static.sh with content-hash skip and fix .dockerignore to exclude 1.3GB of unnecessary files from Docker context
2026-08-08 08:09:56 -04:00
Laan Tungir
9afbb8fcbd
Refactor n_signer_client to use nostr_core_lib high-level wrappers
...
The CLI was hand-building cJSON params and calling the low-level
nsigner_client_call for all 16 verbs. Now it uses the high-level
nostr_signer_t typed wrappers from nostr_core_lib for 14 of 16 verbs:
get_info, get_public_key (alg + nostr), sign_event, mine_event,
nip04/44 encrypt+decrypt, sign, verify, derive, encapsulate,
decapsulate, derive_shared_secret, otp encrypt/decrypt.
The 'call' verb (raw passthrough) and 'derive --algorithm' still use
the low-level nsigner_client_call on the shared connection (created via
nostr_signer_nsigner_from_client). The 'list' verb uses
nsigner_transport_list_unix directly.
The client shrank from 945 to ~840 lines, with the per-verb cJSON
building logic now in the library. Error messages use
nostr_signer_last_error() to surface the raw n_signer RPC error text
(path_not_allowed, unknown_role, etc.).
Also adds two plan docs:
- plans/client_breaking_change_audit.md: audit of n_signer breaking
changes vs all ~/lt/ client repos
- plans/nostr_core_lib_full_verb_coverage.md: analysis of the library
verb coverage gap that motivated this refactor
Tests: 45/45 pass, 0 fail, 2 skip (test_n_signer_client.sh).
2026-08-06 10:17:47 -04:00
Laan Tungir
e65ed5c5d6
v0.1.15 - Rename binaries to nsigner/nsigner_client, integrate client into release pipeline, update role+path authorization model with wizard presets and wildcard path support
2026-08-05 18:59:47 -04:00
Laan Tungir
7cbefe13ec
v0.1.13 - Change default index to 0 in wizard (when 0 is in range/set)
2026-08-04 21:29:58 -04:00
Laan Tungir
f0e90e0ea6
v0.1.11 - Fix named path-role display and allow fixed paths without range/set
2026-08-04 20:53:12 -04:00
Laan Tungir
86a97aee01
v0.1.10 - Add unified hardware-signer broker plan for Qubes OS sharing across qubes
2026-08-04 09:31:52 -04:00
Laan Tungir
ac2e6347a2
v0.1.6 - Teensy 4.1 SD-card OTP pad: real implementation working on hardware
...
- otppad_embedded: bit-compatible port of libotppad (2386/2386 host tests pass)
- otp_pad_sd: SdFat-direct SD card pad reader (FAT-only, ASCII armor + binary .otp)
- pad_gen.ino: TRNG-sourced 1 MB pad generator using i.MX RT1062 TRNG registers
- Linker script: moved .rodata from DTCM to FLASH (EXCLUDE_FILE ed25519),
reclaiming 124 KB DTCM, free stack 5.9 KB -> 130.9 KB
- check_stack.sh: build-time FlexRAM stack gauge, wired into build_signer.sh
- test_otp_sd.py: 8/9 hardware tests pass (ASCII + binary round-trips,
offset advance, tamper detection; 10 KB plaintext times out on perf)
- test_classical.py: 16/16 pass with new memory layout (ed25519 OK)
- Memory evaluation document: plans/teensy41_memory_evaluation.md
2026-07-30 17:10:50 -04:00
Laan Tungir
d7369646fb
Added remaining-todo document for Teensy 4.1 signer: captures v0.1.1-v0.1.5 fixes, current 20/24 suite score, and next steps for ml-dsa-65 sign hang (NTT correctness in matvec/scalar wrappers) and OTP decrypt mismatch
2026-07-27 19:14:22 -04:00
Laan Tungir
2ba81c4bc8
v0.1.1 - Fixed Teensy 4.1 NIP-04 crash and NIP-44 dispatch bug: reduced secp256k1 ECMULT_CONST_GROUP_SIZE 5->4 to halve ECDH stack usage (~3.5KB->~1.7KB) preventing DTCM stack overflow in secp256k1_ecmult_const during nip04/nip44 ECDH; fixed is_nip44 selector in dispatch.cpp (method[7] was always 'i', digit is at method[9]) so nostr_nip44_* verbs now reach the nip44 implementation instead of silently calling nip04; verified nip04+nip44 round-trip on hardware
2026-07-27 07:16:53 -04:00
Laan Tungir
64fbd5c874
v0.1.0 - CYD firmware v0.0.2: algorithm-based API upgrade (all verbs, all algorithms), vendored Keccak/SHAKE + PSA ed25519/x25519 for IDF v5.4, Web Serial test page, CYD docs, Teensy 4.1 port plan (1TB SDXC OTP pad), brainstorming READMEs for BLE/IR/NFC/FPGA signer concepts
2026-07-21 13:16:04 -04:00
Laan Tungir
ca18e1e42d
v0.0.58 - Added derive verb: HMAC-SHA256(privkey, data) for secp256k1, enabling opaque d-tag derivation via nsigner remote backend without exposing the privkey
2026-07-20 19:56:51 -04:00
Laan Tungir
b3421c3e40
v0.0.57 - Migrated to unified nostr_ prefixed verb names; removed legacy verb aliases (sign_data, ssh_sign, verify_signature, kem_encapsulate, kem_decapsulate, otp_encrypt, otp_decrypt); split get_public_key into algorithm-based get_public_key and role-based nostr_get_public_key; OTP now selected via algorithm:otp instead of curve:otp; consolidated API docs from api.md into README.md
2026-07-20 17:29:45 -04:00
Laan Tungir
a0a5987ffa
v0.0.54 - TUI: show full derivation path in Roles table, move connection instructions to on-demand 'd' hotkey display with spaced transport blocks
2026-07-20 09:49:20 -04:00
Laan Tungir
0355744103
v0.0.52 - Added api.md with unified verb scheme, fixed TUI status display in README, added TCP/HTTP port auto-increment on EADDRINUSE (up to 5 tries)
2026-07-20 09:07:21 -04:00
Laan Tungir
05c055503d
v0.0.48 - Added OTP one-time pad encryption (otp_encrypt/otp_decrypt verbs), HTTP listener mode (--listen http:HOST:PORT), interactive OTP pad auto-scan on USB drives, raised SERVER_MAX_MSG_SIZE to 16MB, updated README with curl examples and current API documentation
2026-07-19 11:07:07 -04:00
Laan Tungir
a7c6de2dcd
v0.0.47 - Clean up main menu layout and hotkeys
2026-07-16 17:59:58 -04:00
Laan Tungir
c5f1a70658
v0.0.47 - Added post-quantum cryptography (ML-DSA-65, SLH-DSA-128s, ML-KEM-768) and standard ECC (ed25519, x25519) support with algorithm-based API
2026-07-16 15:14:57 -04:00
Laan Tungir
6fd7b8ce1f
v0.0.45 - Display qrexec service name (qubes.NsignerRpc) in signer connection info; use human-readable timestamps in activity log; fix static release build by adding miner.c to Dockerfile.alpine-musl
2026-07-11 19:12:34 -04:00
Laan Tungir
9a8657f663
v0.0.42 - Add C qrexec client example using high-level nostr_signer API with nostr_index selector; sync nostr_core_lib with qrexec transport and index support
2026-07-11 14:28:09 -04:00
Laan Tungir
2e8ce777d8
v0.0.37 - Add interactive multi-transport selection menu at startup — users can select one or more transports (unix, qrexec bridge, TCP) from a menu instead of memorizing CLI flags
2026-07-11 11:31:21 -04:00
Laan Tungir
d15eebb80f
v0.0.34 - Add qrexec bridge subcommand and --bridge-source-trusted flag for persistent-signer qrexec transport
2026-07-11 09:37:51 -04:00
Laan Tungir
69c46ab2a7
v0.0.32 - Fix KB2040 Python WebUSB handshake and robust frame reassembly for get-public-key
2026-06-08 20:24:02 -04:00
Laan Tungir
430e391347
v0.0.30 - CYD: add post-approval event log screen and document CH340 EN-GND capacitor reset mitigation
2026-05-27 06:56:40 -04:00
Laan Tungir
bd23b674d6
v0.0.29 - Feather firmware: auto-approve sign_event and always return explicit JSON-RPC errors for unhandled/oversized requests
2026-05-11 13:43:14 -04:00
Laan Tungir
e4fa743654
v0.0.28 - Finalize Feather TinyUSB migration and remove cardputer artifacts
2026-05-09 16:22:50 -04:00
Laan Tungir
5c214f3614
v0.0.26 - Add mnemonic-stdin and mnemonic-fd startup input modes with tests/docs
2026-05-06 17:38:50 -04:00
Laan Tungir
f4413b7969
v0.0.25 - Add --allow-all flag and short aliases for CLI options
2026-05-06 12:09:08 -04:00
Laan Tungir
cc797a16df
v0.0.20 - Implement TCP auth envelope verification with signed caller pubkey identity, replay protection, tests, and deferred NIP-46 bunker plan
2026-05-05 11:22:58 -04:00
Laan Tungir
7ffba2b678
v0.0.16 - Implement deny-by-default approval model with on-demand nostr_index derivation and --preapprove CLI flag
2026-05-04 18:44:40 -04:00
Laan Tungir
f9d7b94962
v0.0.7 - Allow TCP non-loopback IPv4/IPv6 binds for FIPS reachability
2026-05-03 11:41:42 -04:00
Laan Tungir
b089bf36e3
v0.0.6 - Tier-1 TCP listener + FIPS deployment documentation
2026-05-02 18:14:20 -04:00
Laan Tungir
3e86e539e0
v0.0.5 - Add CLIENT_IMPLEMENTATION.md agent integration spec
2026-05-02 16:19:05 -04:00
Laan Tungir
21f1258844
v0.0.2 - Add random mnemonic startup flow and multi-instance random socket naming
2026-05-02 13:46:01 -04:00
Laan Tungir
268b33b6d3
first
2026-05-02 12:31:26 -04:00