Files
amethyst/tools/unicode-nfkc
Claude 0a48ddab5d fix(quartz): real NFKC on Linux, private zaps and deriveKey over NIP-46
Linux native's UnicodeNormalizer returned its input unchanged, so NIP-49
keys encrypted under a non-ASCII password (normalized by every other
client) could not be decrypted there. Add a pure-Kotlin UAX #15 NFKC
normalizer with tables generated from the Unicode 17.0 UCD by
tools/unicode-nfkc/generate.py, and use it on Linux. It passes all 20,034
lines of Unicode's NormalizationTest.txt and matches java.text.Normalizer
for every code point the JDK defines (NfkcNormalizerJdkParityTest).

NostrSignerRemote.decryptZapEvent and deriveKey were TODO(), whose
NotImplementedError is an Error that escapes DecryptCache's handlers.
A private zap's anon payload is AES-CBC under the NIP-04 shared secret,
so the recipient now decrypts it through the bunker's nip04_decrypt.
The sender's copy and deriveKey need the raw private key, which a bunker
never exposes, so they now throw CouldNotPerformException and
UnsupportedMethodException. An end-to-end test runs the remote signer
against Quartz's own bunker over an in-process relay.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QytMdt3MPxvmmWrAX3bJYS
2026-09-28 17:35:15 +00:00
..

unicode-nfkc

Generates NfkcData.kt, the tables behind Quartz's pure-Kotlin NFKC normalizer (quartz/.../utils/unicode/NfkcNormalizer.kt). Linux native uses it because it has no platform normalizer. JVM/Android use java.text.Normalizer and Apple uses NSString. NIP-49 NFKC-normalizes passwords before scrypt, so a wrong normalizer silently breaks key decryption.

V=17.0.0
mkdir -p /tmp/ucd && for f in UnicodeData.txt DerivedNormalizationProps.txt; do
  curl -sSfo /tmp/ucd/$f https://www.unicode.org/Public/$V/ucd/$f
done
tools/unicode-nfkc/generate.py /tmp/ucd \
  quartz/src/commonMain/kotlin/com/vitorpamplona/quartz/utils/unicode/NfkcData.kt

Commit the regenerated file. NfkcNormalizerJdkParityTest (jvmTest) checks the result against the JDK for every code point the JDK knows. To check a new Unicode version fully, run the normalizer over that version's NormalizationTest.txt (column 4 is the NFKC of columns 1-5).

The data is derived from the Unicode Character Database, distributed under the permissive Unicode License v3.