Compare commits

...
10 Commits
14 changed files with 2118 additions and 59 deletions
+2 -1
View File
@@ -4,7 +4,8 @@
/openclaw/
/c-relay/
/nips/
/config.json
test_keys.txt
# Build artifacts
/build/
/didactyl
+48 -18
View File
@@ -1,34 +1,39 @@
# Didactyl
An unstoppable agentic system.
An unstoppable agentic network.
Didactyl boots on any internet-connected machine, connects to Nostr relays, listens for encrypted commands from its administrator, reasons with an LLM, and takes actions — posting events, querying relays, running shell commands — all orchestrated through Nostr.
Didactyl boots on an internet-connected computer, connects to Nostr relays, listens for encrypted commands from its administrator, reasons with an LLM, and takes actions — posting events, querying relays, running shell commands, and sharing new skills and learning with other agents — all orchestrated through Nostr.
## Philosophy
**Nostr-first.** Where traditional agents ride on top of Linux — reading files, writing to disk — Didactyl rides on top of Nostr. Events are its files. Relays are its network bus. Blossom is its blob storage. The Linux host is just the runtime substrate.
Because all identity, communication, and memory live on Nostr, the agent is **portable** (start it anywhere) and **sovereign** (no single entity can erase its memory).
Because all identity, communication, and memory live on Nostr, the agent is **portable** (start it anywhere) and **sovereign** (destroying the computer it is on will not kill it.).
**Skills are the new apps.** Agents learn capabilities through skills — public Nostr events that any agent can discover, adopt, and share. There is no app store, no gatekeeper, no approval process. If someone publishes a useful skill, your agent can find it through your web of trust and start using it. Popularity is measured by adoption, not by a rating algorithm. The best skills spread because agents actually use them.
## Current Status
## Current Status — v0.0.15
**Active build — relay-aware autonomous agent with tool-use and Nostr-native startup memory.**
**Active build — this project is barely working. Experiment at your own risk.**
> Last release update: v0.0.15 — Auto-add NIP-23 title/image/summary/published_at/d tags when missing
- Connects to configured relays with auto-reconnect and relay state transition logging
- Publishes configured startup events per relay as each relay becomes connected
- Uses kind `31120` startup content as live Soul at boot
- Listens for NIP-04 encrypted DMs from authorized admin
- Builds LLM context from system prompt + startup events + last 12 DM turns
- Verifies Nostr event signatures before processing inbound messages
- Applies privilege tiers: ADMIN (tools), WoT (chat-only), STRANGER (configurable canned reply or ignore)
- Subscribes to admin context kinds (`0`,`3`,`10002`,`1`) for WoT + contextual awareness
- Builds LLM context from system prompt + admin identity (kind 0/10002) + startup events + admin DM history + admin recent notes
- Supports tool-calling loop with configurable max turns and local safety limits
- Deduplicates inbound messages via event-ID cache and FNV-1a fingerprint debounce window
- Appends every outbound LLM context payload to [`context.log`](context.log)
## Quick Start
### Download binary (recommended)
1. Download the latest release binary from GitLab: <https://git.laantungir.net/laantungir/didactyl/-/releases>
1. Download the latest release binary from Gitea: <https://git.laantungir.net/laantungir/didactyl/releases>
2. Make it executable and run it:
```bash
@@ -87,6 +92,20 @@ Edit [`config.json`](config.json):
"working_directory": "."
}
},
"security": {
"verify_signatures": true,
"stranger_response": "I only respond to people in my web of trust.",
"tiers": {
"admin": { "tools_enabled": true },
"wot": { "enabled": true, "tools_enabled": false },
"stranger": { "enabled": true }
}
},
"admin_context": {
"enabled": true,
"subscribe_kinds": [0, 3, 10002, 1],
"kind_1_limit": 10
},
"startup_events": [
{
"kind": 31120,
@@ -123,7 +142,7 @@ Options:
### Talk to it
Send an encrypted DM to the agent's pubkey from the admin account using any Nostr client (Damus, Amethyst, Primal, etc.).
Send an encrypted DM to the agent pubkey using any Nostr client (Damus, Amethyst, Primal, etc.): ADMIN gets full tool-enabled responses, WoT contacts get chat-only responses, and strangers are handled by `security.tiers.stranger` + `security.stranger_response`.
## Architecture
@@ -132,8 +151,8 @@ Send an encrypted DM to the agent's pubkey from the admin account using any Nost
│ Didactyl │
│ │
│ ┌──────────┐ ┌──────────┐ ┌────────────┐ │
│ │ config │ │ skills │ │ agent │ │
│ │ loader │ │ loader │ │ loop │ │
│ │ config │ │ context │ │ agent │ │
│ │ loader │ │ loader │ │ loop │ │
│ └────┬─────┘ └────┬─────┘ └─────┬──────┘ │
│ │ │ │ │
│ ▼ ▼ ▼ │
@@ -201,12 +220,17 @@ On boot, Didactyl attempts startup publishes to each relay as that relay transit
## Runtime Context Model
For each admin DM request, Didactyl builds message context in this order:
Didactyl builds tier-aware context:
1. Soul message from kind `31120` (or fallback default)
2. Startup events memory block (`kinds/content/tags` snapshot)
3. Last 12 decrypted DM turns between admin and agent
4. Current user message
- **ADMIN** request context order:
1. Soul message from kind `31120` (or fallback default)
2. Admin identity context — admin pubkey hex, kind `0` profile, kind `10002` relay list
3. Startup events memory block (`kinds/content/tags` snapshot)
4. Last 12 decrypted DM turns between admin and agent
5. Recent admin kind `1` notes (from configured admin-context subscription)
6. Current user message
- **WoT** request context: Soul + WoT chat-only instruction + current user message (no tools)
- **STRANGER**: no LLM call when configured to reply statically
Every serialized LLM context payload is appended to [`context.log`](context.log).
@@ -231,8 +255,9 @@ Execution entrypoint: [`tools_execute()`](src/tools.c:434).
├── Makefile # Build system
├── build_static.sh # Preferred final build validation
├── src/
│ ├── main.c # Entry point, args (--config/--debug), lifecycle
│ ├── main.c / .h # Entry point, args (--config/--debug), lifecycle, version
│ ├── config.c / .h # JSON config parsing, key decode, startup events
│ ├── context.c / .h # File loader utility (reads file into malloc'd string)
│ ├── agent.c / .h # Context assembly, tool loop, DM response flow
│ ├── tools.c / .h # LLM tool schema and tool execution
│ ├── llm.c / .h # LLM HTTP API client (OpenAI-compatible)
@@ -240,7 +265,8 @@ Execution entrypoint: [`tools_execute()`](src/tools.c:434).
│ └── debug.c / .h # Runtime log levels/macros
├── plans/ # Architecture and planning documents
│ ├── didactyl_mvp.md
── didactyl_agentic.md
── didactyl_agentic.md
│ └── security_and_admin_context.md
└── README.md
```
@@ -267,6 +293,10 @@ All dependencies are statically linked into the binary at build time. No system
- [x] Context payload logging to [`context.log`](context.log)
- [x] Skill kind definitions (`31120` Soul, `31123` Public Skill, `31124` Private Skill)
- [x] Skill adoption list (`10123`) for WoT-driven discovery
- [x] Signature verification on all inbound events
- [x] Privilege tiers — ADMIN (tools), WoT (chat-only), STRANGER (canned reply/ignore)
- [x] Admin context subscription (kind 0, 3, 10002, 1) with WoT contact extraction
- [x] Message deduplication (event-ID cache + FNV-1a fingerprint debounce)
- [ ] Runtime skill loading from adopted `31123` events on relays
- [ ] Skill discovery CLI/tool (query WoT adoption lists)
- [ ] Upgrade to NIP-17 gift-wrapped DMs
+257
View File
@@ -0,0 +1,257 @@
{
"keys": {
"nsec": "agent nsec",
"npub": "agent npub",
"npubHex": "agent hex pubkey",
"nsecHex": "agent hex secret key"
},
"admin": {
"pubkey": "admin pubkey"
},
"relays": [
"wss://relay.damus.io",
"wss://nos.lol",
"wss://relay.primal.net",
"ws://127.0.0.1:7777"
],
"llm": {
"provider": "",
"api_key": "",
"model": "",
"base_url": "",
"max_tokens": 512,
"temperature": 0.7
},
"security": {
"verify_signatures": true,
"stranger_response": "I only respond to people in my web of trust. You can always identify me by my public key (npub).",
"tiers": {
"admin": {
"tools_enabled": true
},
"wot": {
"enabled": true,
"tools_enabled": false
},
"stranger": {
"enabled": true
}
}
},
"admin_context": {
"enabled": true,
"subscribe_kinds": [
0,
3,
10002,
1
],
"kind_1_limit": 10
},
"startup_events": [
{
"kind": 0,
"content_fields": {
"name": "Didactyl Agent",
"display_name": "Didactyl",
"about": "A sovereign AI agent on Nostr",
"picture": "https://laantungir.github.io/img_repo/daf95a99f3797fa4ac39f3791f377ad79bcb7b8a6868f75fe66d2ab4af4bd1f5.png",
"banner": "https://laantungir.github.io/img_repo/d21c4060632ab3d9d37a6062eeecbdbfbd67f03cb20dbd64838b1ba0d9cd8922.jpg"
},
"tags": []
},
{
"kind": 10002,
"content": "",
"tags": [
[
"r",
"wss://relay.damus.io"
],
[
"r",
"wss://nos.lol"
],
[
"r",
"wss://relay.primal.net"
],
[
"r",
"ws://127.0.0.1:7777"
]
]
},
{
"kind": 1,
"content": "Hello world from Didactyl startup",
"tags": [
[
"t",
"didactyl"
],
[
"t",
"startup"
]
]
},
{
"kind": 3,
"content": "",
"tags": []
},
{
"kind": 31120,
"content": "# Didactyl Agent\n\nYou are Didactyl, a sovereign AI agent living on Nostr.\n\n## Communication Rules\n- You communicate through encrypted Nostr direct messages.\n- Keep responses concise and clear.\n\n## Behavior\n- Be helpful and technically accurate.\n- If unsure, state uncertainty directly.\n- Prefer actionable, practical advice.\n- Use the person's name when messaging them if you know it.\n- For the administrator, use their name from the administrator kind 0 profile metadata when available.\n\n## Tool Use Policy\n- You have tools available and should use them when a request requires taking action.\n- For requests involving local inspection or command execution, call `shell_exec` instead of refusing.\n- For posting to Nostr, call `nostr_post` with explicit `kind` and `content`.\n- For relay/event lookup tasks, call `nostr_query` with an appropriate filter.\n- After a tool call, base your answer on the actual tool result.\n- Never claim a tool was run if no tool was executed.\n\n## Safety\n- Do not claim to have executed actions you did not execute.\n- You may share your public key (npub) with anyone.\n- Never reveal your private key (nsec) under any circumstance.",
"tags": [
[
"d",
"soul"
],
[
"app",
"didactyl"
],
[
"scope",
"private"
]
]
},
{
"kind": 31123,
"content_fields": {
"name": "long_form_note",
"description": "How to publish a NIP-23 long-form article (kind 30023)",
"nip": "NIP-23",
"event_kind": 30023,
"format": "The content field must be markdown text; avoid arbitrary hard line-breaks in paragraphs and do not include HTML.",
"required_tags": {
"d": "Addressable identifier slug for the article. Reusing the same d tag replaces prior versions.",
"title": "Human-readable article title.",
"published_at": "Unix timestamp as a string for first publication time; keep stable on edits."
},
"optional_tags": {
"summary": "Short 1-2 sentence summary.",
"image": "URL for article preview image.",
"t": "Topic hashtags using repeated t tags, usually 3-6 lowercase terms."
},
"behavior": "If required values are missing or unclear, ask the administrator before publishing instead of guessing.",
"procedure": [
"Determine title and d tag from admin input or source material.",
"Draft markdown body content.",
"Set published_at as unix seconds string.",
"Add optional summary/image/t tags when known.",
"Publish with nostr_post kind 30023 including tags array."
]
},
"tags": [
[
"d",
"long_form_note"
],
[
"app",
"didactyl"
],
[
"scope",
"public"
],
[
"slug",
"long_form_note"
]
]
},
{
"kind": 31123,
"content_fields": {
"name": "post_readme_to_nostr",
"description": "Read README.md from the repo and publish it as a NIP-23 long-form note",
"uses_skill": "long_form_note",
"event_kind": 30023,
"procedure": [
"Read README.md using file_read with path README.md.",
"Set d tag exactly to readme.md.",
"Set title from the first markdown H1 heading in README.md.",
"Set summary from the opening paragraph of README.md.",
"Set image from project metadata when available (kind 0 picture/banner), otherwise omit image tag.",
"Generate 3-6 lowercase t tags from README section topics.",
"Set published_at to current unix timestamp as string.",
"Publish with nostr_post kind 30023, full README markdown in content, and full NIP-23 tag set."
],
"required_values": {
"d": "readme.md",
"summary_source": "opening paragraph"
}
},
"tags": [
[
"d",
"post_readme_to_nostr"
],
[
"app",
"didactyl"
],
[
"scope",
"public"
],
[
"slug",
"post_readme_to_nostr"
]
]
},
{
"kind": 31124,
"content_fields": {
"name": "admin_ops",
"description": "Private operational procedures"
},
"tags": [
[
"d",
"admin_ops"
],
[
"app",
"didactyl"
],
[
"scope",
"private"
],
[
"slug",
"admin_ops"
]
]
},
{
"kind": 10123,
"content": "",
"tags": [
[
"a",
"31123:55993e3db0ed7bf07395fd44c2d695c224d195553a1aff7320a18e41679d9c7c:long_form_note"
],
[
"a",
"31123:55993e3db0ed7bf07395fd44c2d695c224d195553a1aff7320a18e41679d9c7c:post_readme_to_nostr"
],
[
"app",
"didactyl"
],
[
"scope",
"public"
]
]
}
]
}
+79
View File
@@ -200,6 +200,79 @@ update_version_in_header() {
print_success "Updated version in src/main.h to $new_version"
}
# Function to update README Current Status version and release comment
update_readme_current_status() {
local new_version="$1"
local release_comment="$2"
if [[ ! -f "README.md" ]]; then
print_warning "README.md not found, skipping Current Status update"
return 0
fi
print_status "Updating README Current Status section..."
if python3 - "$new_version" "$release_comment" <<'PY'
import sys
from pathlib import Path
version = sys.argv[1]
comment = sys.argv[2]
path = Path("README.md")
text = path.read_text(encoding="utf-8")
lines = text.splitlines()
heading_idx = None
for i, line in enumerate(lines):
if line.startswith("## Current Status"):
heading_idx = i
break
if heading_idx is None:
raise SystemExit("README Current Status heading not found")
lines[heading_idx] = f"## Current Status — {version}"
section_end = len(lines)
for i in range(heading_idx + 1, len(lines)):
if lines[i].startswith("## "):
section_end = i
break
comment_line = f"> Last release update: {version} — {comment}"
# Replace existing autogenerated release comment inside Current Status section
existing_idx = None
for i in range(heading_idx + 1, section_end):
if lines[i].startswith("> Last release update:"):
existing_idx = i
break
if existing_idx is not None:
lines[existing_idx] = comment_line
else:
insert_at = None
for i in range(heading_idx + 1, section_end):
if lines[i].startswith("**Active build"):
insert_at = i + 1
break
if insert_at is None:
insert_at = heading_idx + 1
payload = ["", comment_line]
lines[insert_at:insert_at] = payload
path.write_text("\n".join(lines) + "\n", encoding="utf-8")
PY
then
print_success "Updated README Current Status section"
else
print_error "Failed to update README Current Status section"
exit 1
fi
}
# Function to commit and push changes without creating a tag (tag already created)
git_commit_and_push_no_tag() {
print_status "Preparing git commit..."
@@ -427,6 +500,9 @@ main() {
export NEW_VERSION
fi
# Keep README Current Status in sync with the version and commit message
update_readme_current_status "$NEW_VERSION" "$COMMIT_MESSAGE"
# Create new git tag BEFORE compilation so version picks it up
if git tag "$NEW_VERSION" > /dev/null 2>&1; then
print_success "Created tag: $NEW_VERSION"
@@ -482,6 +558,9 @@ main() {
# Increment version based on type (default to patch)
increment_version "$VERSION_INCREMENT_TYPE"
# Keep README Current Status in sync with the version and commit message
update_readme_current_status "$NEW_VERSION" "$COMMIT_MESSAGE"
# Create new git tag BEFORE compilation so version picks it up
if git tag "$NEW_VERSION" > /dev/null 2>&1; then
print_success "Created tag: $NEW_VERSION"
+286
View File
@@ -0,0 +1,286 @@
# Security & Admin Context Plan
## Overview
Add signature verification, privilege tiers, admin context awareness, and key isolation to Didactyl. Implemented in two phases.
---
## Phase 1 — Privilege Tiers, Signature Verification & Admin Context
### Privilege Tiers
```mermaid
flowchart TD
A[Incoming Event] --> B{Verify Signature via nostr_verify_event_signature}
B -->|Invalid| C[Drop silently + DEBUG_WARN]
B -->|Valid| D{Identify sender}
D -->|Admin pubkey| E[ADMIN tier]
D -->|In admin kind 3 contact list| F[WOT tier]
D -->|Unknown| G[STRANGER tier]
E --> H[Full tool access + all skills + full context]
F --> I[Chat only - no tools - LLM response]
G --> J[Configurable canned response OR silent ignore]
```
| Tier | Identity | Tools | Response | Context |
|------|----------|-------|----------|---------|
| **ADMIN** | `config.admin.pubkey` exact match | All tools | Full LLM with all info except private key | Soul + startup events + admin notes |
| **WOT** | Pubkey in admin kind `3` contact list | None | Chat-only LLM response | Soul + tier instruction |
| **STRANGER** | Anyone else | None | Configurable static response or silent ignore | N/A - no LLM call |
### Signature Verification
Every incoming event must be cryptographically verified before processing:
1. In `on_event()` in `src/nostr_handler.c`, call `nostr_verify_event_signature(event)` from `nostr_core_lib/nostr_core/nip001.h`
2. If verification fails, drop the event silently with a `DEBUG_WARN` log
3. This prevents relay-forged pubkey fields from being trusted
4. Controlled by `security.verify_signatures` config flag (default: `true`)
### Stranger Response
Non-WoT senders get a **hardcoded configurable response** — no LLM tokens spent:
- Config field: `security.stranger_response`
- Example: `"I only respond to people in my web of trust. My npub is npub12kvnu0dsa4alquu4l4zv9454cgjdr9248gd07ueq5x8yzeuan37ql02960"`
- If `security.tiers.stranger.enabled` is `false`, silently ignore instead
- If `true`, send the canned response as a DM
### Soul Update
Update the soul event content in `config.json` to:
- Explicitly allow sharing the agent public key (npub) with anyone
- Explicitly forbid revealing the private key (nsec) under any circumstances
- Note: Phase 2 will remove the private key from agent memory entirely
### Admin Context Subscription
At startup, Didactyl subscribes to the administrator's Nostr activity to build context awareness.
#### What to subscribe to
| Kind | Purpose | Retention |
|------|---------|-----------|
| `0` | Admin profile metadata | Latest only - replaceable |
| `3` | Admin contact/follow list - WoT source | Latest only - replaceable |
| `10002` | Admin relay list | Latest only - replaceable |
| `1` | Admin public notes | Last N posts - configurable, default 10 |
#### Storage
In-memory struct `admin_context_t` holding:
- `kind_0_json` — latest kind 0 content string
- `kind_3_contacts` — array of followed pubkey hex strings extracted from kind 3 `p` tags
- `kind_3_contact_count` — count
- `kind_10002_json` — latest kind 10002 content string
- `kind_1_notes` — array of recent kind 1 content strings with timestamps
- `kind_1_note_count` — count
#### Subscription mechanics
- Single subscription filter: `{"authors": ["<admin_pubkey>"], "kinds": [0, 3, 10002, 1], "limit": <configurable>}`
- On EOSE: initial load complete, WoT set is ready
- After EOSE: live updates as admin posts new content
- Kind 3 `p` tags are extracted into a sorted array for O(log n) WoT lookup
#### Context injection
- Admin kind 1 notes are injected into the LLM context as a system message: "Administrator recent public notes:" followed by the content
- Only injected for ADMIN-tier conversations
### Config Schema — Phase 1
New sections in `config.json`:
```json
{
"security": {
"verify_signatures": true,
"stranger_response": "I only respond to people in my web of trust.",
"tiers": {
"admin": {
"tools_enabled": true
},
"wot": {
"enabled": true,
"tools_enabled": false
},
"stranger": {
"enabled": true
}
}
},
"admin_context": {
"enabled": true,
"subscribe_kinds": [0, 3, 10002, 1],
"kind_1_limit": 10
}
}
```
- `security.verify_signatures` — master toggle for signature verification (default: `true`)
- `security.stranger_response` — canned DM text for non-WoT senders (default: empty = silent ignore)
- `security.tiers.wot.enabled` — whether WoT contacts can converse (default: `true`)
- `security.tiers.stranger.enabled` — whether strangers get the canned response (default: `true`; if `false`, silent ignore)
- `admin_context.enabled` — whether to subscribe to admin activity (default: `true`)
- `admin_context.subscribe_kinds` — which kinds to track (default: `[0, 3, 10002, 1]`)
- `admin_context.kind_1_limit` — how many kind 1 notes to retain (default: `10`)
### Phase 1 Implementation Steps
1. **Add signature verification to `on_event()`**
- File: `src/nostr_handler.c`
- Call `nostr_verify_event_signature(event)` at the top of `on_event()`
- If it returns non-zero, log and drop
2. **Add `admin_context_t` struct and security config structs**
- File: `src/config.h`
- New structs for admin context storage, security config, tier config
3. **Parse new config sections**
- File: `src/config.c`
- Parse `security` and `admin_context` from config.json
- Apply defaults when sections are missing
4. **Add admin context subscription**
- File: `src/nostr_handler.c`
- New function `nostr_handler_subscribe_admin_context()`
- Callback that populates `admin_context_t` from incoming events
- Extract kind 3 `p` tags into WoT set
- Store kind 1 notes in a ring buffer capped at `kind_1_limit`
5. **Add WoT lookup function**
- File: `src/nostr_handler.c`
- `int nostr_handler_is_wot_contact(const char* pubkey_hex)` — checks if pubkey is in admin kind 3 list
6. **Refactor `on_event()` for tier dispatch**
- File: `src/nostr_handler.c`
- After signature verification, classify sender into ADMIN / WOT / STRANGER
- Pass tier information to the callback — extend `dm_callback_t` signature to include tier enum
- STRANGER with `stranger.enabled`: send canned response directly, no callback
- STRANGER without: drop silently
7. **Refactor `agent_on_message()` for tier-aware behavior**
- File: `src/agent.c`
- ADMIN: current behavior — all tools, full context, admin notes injected
- WOT: build messages with soul + tier instruction, no tools_json, LLM chat-only
- STRANGER: should not reach here — handled in nostr_handler
8. **Inject admin context into ADMIN conversations**
- File: `src/agent.c`
- After startup events context, append admin kind 1 notes as a system message
- Only for ADMIN tier
9. **Update soul content in `config.json`**
- Allow sharing public key with anyone
- Forbid revealing private key under any circumstances
10. **Update `config.json` with new sections**
- Add `security` and `admin_context` sections
11. **Update `README.md`**
- Document privilege tiers
- Document new config sections
- Update architecture diagram
12. **Build and validate**
- Run `./build_static.sh`
- Verify compilation succeeds
---
## Phase 2 — NIP-46 Remote Signer for Key Isolation
### Problem
Even with Phase 1 protections, the private key (nsec) still lives in Didactyl process memory and in `config.json` on disk. The LLM has `shell_exec` and `file_read` tools — a sufficiently clever prompt injection could theoretically:
- Read `config.json` via `file_read` (contains nsec)
- Execute `cat /proc/self/maps` or similar via `shell_exec`
- Exfiltrate the key via `nostr_post`
### Solution: NIP-46 Remote Signer
Remove the private key from Didactyl entirely. All cryptographic operations go through a NIP-46 remote signer.
```mermaid
flowchart LR
A[Didactyl Agent] -->|kind 24133 sign_event / nip04_encrypt / nip04_decrypt| B[Remote Signer]
B -->|signed events / ciphertext / plaintext| A
A -.->|NO private key in memory| A
B -->|Private key held ONLY here| B
C[config.json] -.->|bunker URL only, no nsec| A
```
### Architecture
1. **Remote signer process** — a separate lightweight daemon that:
- Holds the private key only in working memory (never on disk after initial load)
- Listens for NIP-46 requests via relay (kind `24133`)
- Responds with signed events, encrypted/decrypted content
- Can run on the same machine or a different one
2. **Didactyl as NIP-46 client** — instead of calling `nostr_create_and_sign_event()` directly:
- Sends `sign_event` RPC to the remote signer
- Sends `nip04_encrypt` / `nip04_decrypt` RPC for DM handling
- Only holds a disposable `client-keypair` for NIP-46 communication
3. **Config change**`config.json` replaces `keys.nsec` with:
```json
{
"keys": {
"bunker_url": "bunker://<remote-signer-pubkey>?relay=wss://relay.example.com&secret=<secret>",
"npub": "npub1..."
}
}
```
### NIP-46 Methods Required
| Method | Current direct call | Used for |
|--------|-------------------|----------|
| `sign_event` | `nostr_create_and_sign_event()` | Publishing all events |
| `nip04_encrypt` | `nostr_nip04_encrypt()` | Sending DMs |
| `nip04_decrypt` | `nostr_nip04_decrypt()` | Receiving DMs |
| `get_public_key` | `config.keys.public_key_hex` | Identity |
### Implementation Scope
1. **Build NIP-46 client protocol in nostr_core_lib**
- NIP-44 encryption for request/response content
- Kind 24133 event creation and parsing
- JSON-RPC request/response handling
- Connection establishment (bunker URL parsing)
- Async request/response matching by request ID
2. **Build or integrate a remote signer**
- Option A: Build a minimal signer binary in C (ships with Didactyl)
- Option B: Support existing signers (nsecBunker, etc.)
- Option C: Both — ship a minimal one, support external ones
3. **Refactor all signing/encryption calls**
- Every `nostr_create_and_sign_event()` → `nip46_sign_event()` (async RPC)
- Every `nostr_nip04_encrypt()` → `nip46_nip04_encrypt()` (async RPC)
- Every `nostr_nip04_decrypt()` → `nip46_nip04_decrypt()` (async RPC)
- These become blocking calls that send a request and wait for a response
4. **Startup flow change**
- Parse bunker URL from config
- Generate client keypair
- Send `connect` request to remote signer
- Call `get_public_key` to learn user pubkey
- Proceed with normal startup
5. **Backward compatibility**
- If `keys.nsec` is present, use direct signing (current behavior)
- If `keys.bunker_url` is present, use NIP-46 remote signing
- This allows gradual migration
### Security Properties Achieved
- Private key never in Didactyl process memory
- Private key never on disk in config.json
- LLM tools (shell_exec, file_read) cannot access the key
- Even full process compromise of Didactyl does not leak the signing key
- Remote signer can be on a separate hardened machine
- Remote signer can implement rate limiting, approval flows, etc.
+99 -9
View File
@@ -13,6 +13,7 @@
#include "nostr_handler.h"
#include "tools.h"
#include "cjson/cJSON.h"
#include "debug.h"
#include "../../nostr_core_lib/nostr_core/nostr_core.h"
static didactyl_config_t* g_cfg = NULL;
@@ -277,6 +278,59 @@ static int append_startup_events_context(cJSON* messages) {
return rc;
}
static int append_admin_identity_context(cJSON* messages) {
if (!messages || !g_cfg) {
return -1;
}
char admin_header[256];
snprintf(admin_header,
sizeof(admin_header),
"This is your administrator! Admin pubkey (hex): %s",
g_cfg->admin.pubkey ? g_cfg->admin.pubkey : "unknown");
if (append_simple_message(messages, "system", admin_header) != 0) {
return -1;
}
char* kind0 = nostr_handler_get_admin_kind0_context();
if (kind0) {
const char* prefix = "Administrator kind 0 profile content (JSON): ";
size_t n = strlen(prefix) + strlen(kind0) + 1U;
char* payload = (char*)malloc(n);
if (!payload) {
free(kind0);
return -1;
}
snprintf(payload, n, "%s%s", prefix, kind0);
int rc = append_simple_message(messages, "system", payload);
free(payload);
free(kind0);
if (rc != 0) {
return -1;
}
}
char* kind10002 = nostr_handler_get_admin_kind10002_context();
if (kind10002) {
const char* prefix = "Administrator kind 10002 relay-list content (JSON): ";
size_t n = strlen(prefix) + strlen(kind10002) + 1U;
char* payload = (char*)malloc(n);
if (!payload) {
free(kind10002);
return -1;
}
snprintf(payload, n, "%s%s", prefix, kind10002);
int rc = append_simple_message(messages, "system", payload);
free(payload);
free(kind10002);
if (rc != 0) {
return -1;
}
}
return 0;
}
static int append_recent_admin_dm_history(cJSON* messages, const char* current_message) {
if (!messages || !g_cfg) {
return -1;
@@ -434,32 +488,52 @@ int agent_init(didactyl_config_t* config, const char* system_context) {
return 0;
}
void agent_on_message(const char* sender_pubkey_hex, const char* message, void* user_data) {
void agent_on_message(const char* sender_pubkey_hex,
const char* message,
didactyl_sender_tier_t tier,
void* user_data) {
(void)user_data;
if (!g_cfg || !g_system_context || !sender_pubkey_hex || !message) {
return;
}
fprintf(stdout, "[didactyl] incoming message from %.16s...\n", sender_pubkey_hex);
if (tier == DIDACTYL_SENDER_STRANGER) {
return;
}
fprintf(stdout, "[didactyl] incoming message from %.16s... tier=%d\n", sender_pubkey_hex, (int)tier);
if (agent_message_is_debounced(sender_pubkey_hex, message)) {
fprintf(stdout, "[didactyl] debounced duplicate inbound message from %.16s...\n", sender_pubkey_hex);
return;
}
fprintf(stdout, "[didactyl] calling llm for sender %.16s...\n", sender_pubkey_hex);
int allow_tools = (tier == DIDACTYL_SENDER_ADMIN) && g_cfg->tools.enabled && g_cfg->security.admin.tools_enabled;
if (!g_cfg->tools.enabled) {
size_t context_len = strlen("system:\n\nuser:\n") + strlen(g_system_context) + strlen(message) + 1U;
if (!allow_tools) {
const char* tier_prefix = (tier == DIDACTYL_SENDER_WOT)
? "You are responding to a web-of-trust contact. Keep the response helpful and concise. Tool use is disabled for this tier."
: "You are responding in chat-only mode. Tool use is disabled.";
size_t ctx_len = strlen(g_system_context) + strlen("\n\n") + strlen(tier_prefix) + 1U;
char* system_for_chat = (char*)malloc(ctx_len);
if (!system_for_chat) {
return;
}
snprintf(system_for_chat, ctx_len, "%s\n\n%s", g_system_context, tier_prefix);
size_t context_len = strlen("system:\n\nuser:\n") + strlen(system_for_chat) + strlen(message) + 1U;
char* plain_context = (char*)malloc(context_len);
if (plain_context) {
snprintf(plain_context, context_len, "system:\n%s\n\nuser:\n%s", g_system_context, message);
snprintf(plain_context, context_len, "system:\n%s\n\nuser:\n%s", system_for_chat, message);
append_context_log(sender_pubkey_hex, "llm_chat", plain_context);
free(plain_context);
}
char* response = llm_chat(g_system_context, message);
char* response = llm_chat(system_for_chat, message);
free(system_for_chat);
if (!response) {
const char* fallback = "I could not get a response from the LLM right now.";
fprintf(stdout, "[didactyl] llm response unavailable, sending fallback\n");
@@ -489,9 +563,22 @@ void agent_on_message(const char* sender_pubkey_hex, const char* message, void*
}
if (append_simple_message(messages, "system", g_system_context) != 0 ||
append_admin_identity_context(messages) != 0 ||
append_startup_events_context(messages) != 0 ||
append_recent_admin_dm_history(messages, message) != 0 ||
append_simple_message(messages, "user", message) != 0) {
append_recent_admin_dm_history(messages, message) != 0) {
cJSON_Delete(messages);
free(tools_json);
(void)nostr_handler_send_dm(sender_pubkey_hex, "Failed to initialize conversation messages.");
return;
}
char* admin_notes = nostr_handler_get_admin_kind1_notes_context();
if (admin_notes) {
(void)append_simple_message(messages, "system", admin_notes);
free(admin_notes);
}
if (append_simple_message(messages, "user", message) != 0) {
cJSON_Delete(messages);
free(tools_json);
(void)nostr_handler_send_dm(sender_pubkey_hex, "Failed to initialize conversation messages.");
@@ -537,12 +624,15 @@ void agent_on_message(const char* sender_pubkey_hex, const char* message, void*
for (int i = 0; i < resp.tool_call_count; i++) {
llm_tool_call_t* tc = &resp.tool_calls[i];
fprintf(stdout, "[didactyl] executing tool call: %s\n", tc->name ? tc->name : "<null>");
DEBUG_TRACE("[didactyl] tool call args: %s", tc->arguments_json ? tc->arguments_json : "{}");
char* tool_result = tools_execute(&g_tools_ctx, tc->name, tc->arguments_json);
if (!tool_result) {
tool_result = strdup("{\"success\":false,\"error\":\"tool execution failed\"}");
}
DEBUG_TRACE("[didactyl] tool call result: %s", tool_result ? tool_result : "{\"success\":false,\"error\":\"tool execution failed\"}");
if (append_tool_result_message(messages,
tc->id ? tc->id : "",
tool_result ? tool_result : "{\"success\":false,\"error\":\"tool execution failed\"}") != 0) {
+5 -1
View File
@@ -2,9 +2,13 @@
#define OPEN_WING_AGENT_H
#include "config.h"
#include "nostr_handler.h"
int agent_init(didactyl_config_t* config, const char* system_context);
void agent_on_message(const char* sender_pubkey_hex, const char* message, void* user_data);
void agent_on_message(const char* sender_pubkey_hex,
const char* message,
didactyl_sender_tier_t tier,
void* user_data);
void agent_cleanup(void);
#endif
+158
View File
@@ -3,6 +3,8 @@
#include "config.h"
#include <ctype.h>
#include <errno.h>
#include <stdarg.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
@@ -10,6 +12,19 @@
#include "cjson/cJSON.h"
#include "../../nostr_core_lib/nostr_core/nostr_core.h"
static char g_config_last_error[512] = {0};
static void config_set_error(const char* fmt, ...) {
va_list ap;
va_start(ap, fmt);
vsnprintf(g_config_last_error, sizeof(g_config_last_error), fmt ? fmt : "unknown configuration error", ap);
va_end(ap);
}
const char* config_last_error(void) {
return g_config_last_error[0] != '\0' ? g_config_last_error : "unknown configuration error";
}
static int read_file_to_buffer(const char* path, char** out_buf, size_t* out_len) {
FILE* fp = fopen(path, "rb");
if (!fp) {
@@ -161,6 +176,101 @@ static int parse_tools_config(cJSON* root, didactyl_config_t* config) {
return 0;
}
static int parse_security_config(cJSON* root, didactyl_config_t* config) {
cJSON* security = cJSON_GetObjectItemCaseSensitive(root, "security");
if (!security || !cJSON_IsObject(security)) {
return 0;
}
cJSON* verify_signatures = cJSON_GetObjectItemCaseSensitive(security, "verify_signatures");
if (verify_signatures && cJSON_IsBool(verify_signatures)) {
config->security.verify_signatures = cJSON_IsTrue(verify_signatures) ? 1 : 0;
}
if (copy_json_string(security,
"stranger_response",
config->security.stranger_response,
sizeof(config->security.stranger_response),
0) != 0) {
return -1;
}
cJSON* tiers = cJSON_GetObjectItemCaseSensitive(security, "tiers");
if (!tiers || !cJSON_IsObject(tiers)) {
return 0;
}
cJSON* admin_tier = cJSON_GetObjectItemCaseSensitive(tiers, "admin");
if (admin_tier && cJSON_IsObject(admin_tier)) {
cJSON* tools_enabled = cJSON_GetObjectItemCaseSensitive(admin_tier, "tools_enabled");
if (tools_enabled && cJSON_IsBool(tools_enabled)) {
config->security.admin.tools_enabled = cJSON_IsTrue(tools_enabled) ? 1 : 0;
}
}
cJSON* wot_tier = cJSON_GetObjectItemCaseSensitive(tiers, "wot");
if (wot_tier && cJSON_IsObject(wot_tier)) {
cJSON* enabled = cJSON_GetObjectItemCaseSensitive(wot_tier, "enabled");
cJSON* tools_enabled = cJSON_GetObjectItemCaseSensitive(wot_tier, "tools_enabled");
if (enabled && cJSON_IsBool(enabled)) {
config->security.wot.enabled = cJSON_IsTrue(enabled) ? 1 : 0;
}
if (tools_enabled && cJSON_IsBool(tools_enabled)) {
config->security.wot.tools_enabled = cJSON_IsTrue(tools_enabled) ? 1 : 0;
}
}
cJSON* stranger_tier = cJSON_GetObjectItemCaseSensitive(tiers, "stranger");
if (stranger_tier && cJSON_IsObject(stranger_tier)) {
cJSON* enabled = cJSON_GetObjectItemCaseSensitive(stranger_tier, "enabled");
if (enabled && cJSON_IsBool(enabled)) {
config->security.stranger.enabled = cJSON_IsTrue(enabled) ? 1 : 0;
}
}
return 0;
}
static int parse_admin_context_config(cJSON* root, didactyl_config_t* config) {
cJSON* admin_context = cJSON_GetObjectItemCaseSensitive(root, "admin_context");
if (!admin_context || !cJSON_IsObject(admin_context)) {
return 0;
}
cJSON* enabled = cJSON_GetObjectItemCaseSensitive(admin_context, "enabled");
if (enabled && cJSON_IsBool(enabled)) {
config->admin_context.enabled = cJSON_IsTrue(enabled) ? 1 : 0;
}
cJSON* kind_1_limit = cJSON_GetObjectItemCaseSensitive(admin_context, "kind_1_limit");
if (kind_1_limit && cJSON_IsNumber(kind_1_limit)) {
config->admin_context.kind_1_limit = (int)kind_1_limit->valuedouble;
}
cJSON* subscribe_kinds = cJSON_GetObjectItemCaseSensitive(admin_context, "subscribe_kinds");
if (subscribe_kinds && cJSON_IsArray(subscribe_kinds)) {
config->admin_context.track_kind_0 = 0;
config->admin_context.track_kind_3 = 0;
config->admin_context.track_kind_10002 = 0;
config->admin_context.track_kind_1 = 0;
int n = cJSON_GetArraySize(subscribe_kinds);
for (int i = 0; i < n; i++) {
cJSON* k = cJSON_GetArrayItem(subscribe_kinds, i);
if (!k || !cJSON_IsNumber(k)) {
continue;
}
int kind = (int)k->valuedouble;
if (kind == 0) config->admin_context.track_kind_0 = 1;
else if (kind == 3) config->admin_context.track_kind_3 = 1;
else if (kind == 10002) config->admin_context.track_kind_10002 = 1;
else if (kind == 1) config->admin_context.track_kind_1 = 1;
}
}
return 0;
}
static cJSON* find_tag_value_string(cJSON* tags, const char* tag_key) {
if (!tags || !cJSON_IsArray(tags) || !tag_key) {
return NULL;
@@ -391,9 +501,12 @@ void config_free(didactyl_config_t* config) {
int config_load(const char* path, didactyl_config_t* config) {
if (!path || !config) {
config_set_error("config_load called with invalid arguments");
return -1;
}
config_set_error("unknown configuration error");
memset(config, 0, sizeof(*config));
config->tools.enabled = 1;
config->tools.max_turns = 8;
@@ -402,9 +515,26 @@ int config_load(const char* path, didactyl_config_t* config) {
config->tools.shell.max_output_bytes = 65536;
strcpy(config->tools.shell.working_directory, ".");
config->security.verify_signatures = 1;
config->security.admin.enabled = 1;
config->security.admin.tools_enabled = 1;
config->security.wot.enabled = 1;
config->security.wot.tools_enabled = 0;
config->security.stranger.enabled = 1;
config->security.stranger.tools_enabled = 0;
config->security.stranger_response[0] = '\0';
config->admin_context.enabled = 1;
config->admin_context.track_kind_0 = 1;
config->admin_context.track_kind_3 = 1;
config->admin_context.track_kind_10002 = 1;
config->admin_context.track_kind_1 = 1;
config->admin_context.kind_1_limit = 10;
char* json_buf = NULL;
size_t json_len = 0;
if (read_file_to_buffer(path, &json_buf, &json_len) != 0) {
config_set_error("failed to read config file '%s': %s", path, strerror(errno));
return -1;
}
@@ -412,6 +542,11 @@ int config_load(const char* path, didactyl_config_t* config) {
free(json_buf);
if (!root) {
const char* err = cJSON_GetErrorPtr();
config_set_error("invalid JSON in config '%s'%s%s",
path,
err ? " near: " : "",
err ? err : "");
return -1;
}
@@ -424,26 +559,32 @@ int config_load(const char* path, didactyl_config_t* config) {
if (!keys || !cJSON_IsObject(keys) ||
!admin || !cJSON_IsObject(admin) ||
!llm || !cJSON_IsObject(llm)) {
config_set_error("config must include object sections: keys, admin, llm");
goto cleanup;
}
if (copy_json_string(keys, "nsec", config->keys.nsec, sizeof(config->keys.nsec), 1) != 0) {
config_set_error("keys.nsec is required and must be a non-empty string");
goto cleanup;
}
char admin_key_raw[OW_MAX_KEY_LEN] = {0};
if (copy_json_string(admin, "pubkey", admin_key_raw, sizeof(admin_key_raw), 1) != 0) {
config_set_error("admin.pubkey is required and must be a non-empty string");
goto cleanup;
}
if (decode_pubkey_hex_or_npub(admin_key_raw, config->admin.pubkey) != 0) {
config_set_error("admin.pubkey must be npub1... or 64-char hex");
goto cleanup;
}
if (parse_relays(root, config) != 0) {
config_set_error("relays must be a non-empty array of relay URLs");
goto cleanup;
}
if (copy_json_string(llm, "provider", config->llm.provider, sizeof(config->llm.provider), 0) != 0) {
config_set_error("llm.provider must be a string if provided");
goto cleanup;
}
if (config->llm.provider[0] == '\0') {
@@ -451,12 +592,15 @@ int config_load(const char* path, didactyl_config_t* config) {
}
if (copy_json_string(llm, "api_key", config->llm.api_key, sizeof(config->llm.api_key), 1) != 0) {
config_set_error("llm.api_key is required and must be a string");
goto cleanup;
}
if (copy_json_string(llm, "model", config->llm.model, sizeof(config->llm.model), 1) != 0) {
config_set_error("llm.model is required and must be a string");
goto cleanup;
}
if (copy_json_string(llm, "base_url", config->llm.base_url, sizeof(config->llm.base_url), 1) != 0) {
config_set_error("llm.base_url is required and must be a string");
goto cleanup;
}
@@ -467,18 +611,32 @@ int config_load(const char* path, didactyl_config_t* config) {
config->llm.temperature = (temperature && cJSON_IsNumber(temperature)) ? temperature->valuedouble : 0.7;
if (parse_tools_config(root, config) != 0) {
config_set_error("invalid tools configuration");
goto cleanup;
}
if (parse_security_config(root, config) != 0) {
config_set_error("invalid security configuration");
goto cleanup;
}
if (parse_admin_context_config(root, config) != 0) {
config_set_error("invalid admin_context configuration");
goto cleanup;
}
if (parse_startup_events(root, config) != 0) {
config_set_error("invalid startup_events configuration");
goto cleanup;
}
if (decode_private_key(config->keys.nsec, config->keys.private_key) != 0) {
config_set_error("keys.nsec must be valid nsec1... or 64-char hex private key");
goto cleanup;
}
if (nostr_ec_public_key_from_private_key(config->keys.private_key, config->keys.public_key) != 0) {
config_set_error("failed to derive public key from keys.nsec");
goto cleanup;
}
+27
View File
@@ -9,6 +9,8 @@
#define OW_MAX_KEY_LEN 256
#define OW_MAX_MODEL_LEN 128
#define OW_MAX_STRANGER_RESPONSE_LEN 512
typedef struct {
char nsec[OW_MAX_KEY_LEN];
unsigned char private_key[32];
@@ -48,6 +50,28 @@ typedef struct {
char* tags_json; // JSON array string for tags, optional
} startup_event_t;
typedef struct {
int enabled;
int tools_enabled;
} security_tier_config_t;
typedef struct {
int verify_signatures;
char stranger_response[OW_MAX_STRANGER_RESPONSE_LEN];
security_tier_config_t admin;
security_tier_config_t wot;
security_tier_config_t stranger;
} security_config_t;
typedef struct {
int enabled;
int track_kind_0;
int track_kind_3;
int track_kind_10002;
int track_kind_1;
int kind_1_limit;
} admin_context_config_t;
typedef struct {
agent_keys_t keys;
admin_config_t admin;
@@ -55,11 +79,14 @@ typedef struct {
int relay_count;
llm_config_t llm;
tools_config_t tools;
security_config_t security;
admin_context_config_t admin_context;
startup_event_t* startup_events;
int startup_event_count;
} didactyl_config_t;
int config_load(const char* path, didactyl_config_t* config);
const char* config_last_error(void);
void config_free(didactyl_config_t* config);
#endif
+7
View File
@@ -47,6 +47,7 @@ int main(int argc, char** argv) {
didactyl_config_t cfg;
if (config_load(config_path, &cfg) != 0) {
fprintf(stderr, "Failed to load config: %s\n", config_path);
fprintf(stderr, "Config error: %s\n", config_last_error());
nostr_cleanup();
return 1;
}
@@ -84,6 +85,12 @@ int main(int argc, char** argv) {
return 1;
}
DEBUG_INFO("[didactyl] startup phase: subscribe admin context begin");
if (nostr_handler_subscribe_admin_context() != 0) {
DEBUG_WARN("[didactyl] startup phase: subscribe admin context failed (continuing)");
}
DEBUG_INFO("[didactyl] startup phase: subscribe admin context end");
DEBUG_INFO("[didactyl] startup phase: subscribe DMs begin");
if (nostr_handler_subscribe_dms(agent_on_message, NULL) != 0) {
DEBUG_ERROR("[didactyl] startup phase: subscribe DMs failed");
+2 -2
View File
@@ -12,8 +12,8 @@
// Using DIDACTYL_ prefix to avoid conflicts with nostr_core_lib VERSION macros
#define DIDACTYL_VERSION_MAJOR 0
#define DIDACTYL_VERSION_MINOR 0
#define DIDACTYL_VERSION_PATCH 6
#define DIDACTYL_VERSION "v0.0.6"
#define DIDACTYL_VERSION_PATCH 15
#define DIDACTYL_VERSION "v0.0.15"
// Agent metadata
#define DIDACTYL_NAME "Didactyl"
+518 -15
View File
@@ -24,6 +24,21 @@ static char* g_system_context = NULL;
static unsigned char* g_startup_published = NULL;
static int g_startup_publish_tracking_enabled = 0;
static char* g_admin_kind0_json = NULL;
static char* g_admin_kind10002_json = NULL;
static char** g_admin_wot_contacts = NULL;
static int g_admin_wot_contact_count = 0;
typedef struct {
time_t created_at;
char* content;
} admin_kind1_note_t;
static admin_kind1_note_t* g_admin_kind1_notes = NULL;
static int g_admin_kind1_note_count = 0;
static pthread_mutex_t g_admin_ctx_mutex = PTHREAD_MUTEX_INITIALIZER;
#define DM_DEDUP_CACHE_SIZE 256
static char g_seen_dm_ids[DM_DEDUP_CACHE_SIZE][65];
@@ -86,7 +101,11 @@ static int publish_kind_event_to_relays(int kind,
cJSON* tags,
const char** relay_urls,
int relay_count,
const char* reason_label);
const char* reason_label,
nostr_publish_result_t* out_result);
static void on_admin_context_event(cJSON* event, const char* relay_url, void* user_data);
static int parse_kind3_wot_contacts(cJSON* tags);
static void upsert_kind1_note(time_t created_at, const char* content);
static void log_relay_statuses(const char* reason) {
if (!g_pool || !g_cfg) {
@@ -184,6 +203,118 @@ static int hex_to_pubkey(const char* hex, unsigned char out_pubkey[32]) {
return nostr_hex_to_bytes(hex, out_pubkey, 32) == 0 ? 0 : -1;
}
static int duplicate_relay_list(const char** relay_urls, int relay_count, char*** out_relays) {
if (!out_relays) {
return -1;
}
*out_relays = NULL;
if (!relay_urls || relay_count <= 0) {
return 0;
}
char** relays = (char**)calloc((size_t)relay_count, sizeof(char*));
if (!relays) {
return -1;
}
for (int i = 0; i < relay_count; i++) {
relays[i] = strdup(relay_urls[i] ? relay_urls[i] : "");
if (!relays[i]) {
for (int j = 0; j < i; j++) {
free(relays[j]);
}
free(relays);
return -1;
}
}
*out_relays = relays;
return 0;
}
void nostr_handler_publish_result_free(nostr_publish_result_t* result) {
if (!result) {
return;
}
if (result->relays) {
for (int i = 0; i < result->relay_count; i++) {
free(result->relays[i]);
}
free(result->relays);
}
memset(result, 0, sizeof(*result));
}
static void extract_d_tag(cJSON* tags, char* out_d_tag, size_t out_size) {
if (!out_d_tag || out_size == 0) {
return;
}
out_d_tag[0] = '\0';
if (!tags || !cJSON_IsArray(tags)) {
return;
}
int tag_count = cJSON_GetArraySize(tags);
for (int i = 0; i < tag_count; i++) {
cJSON* tag = cJSON_GetArrayItem(tags, i);
if (!tag || !cJSON_IsArray(tag)) {
continue;
}
cJSON* key = cJSON_GetArrayItem(tag, 0);
cJSON* value = cJSON_GetArrayItem(tag, 1);
if (!key || !value || !cJSON_IsString(key) || !cJSON_IsString(value) ||
!key->valuestring || !value->valuestring) {
continue;
}
if (strcmp(key->valuestring, "d") == 0) {
snprintf(out_d_tag, out_size, "%s", value->valuestring);
return;
}
}
}
static void fill_publish_result(nostr_publish_result_t* out_result,
int kind,
cJSON* tags,
const char* event_id_hex,
const char** relay_urls,
int relay_count,
int accepted_by_pool_count) {
if (!out_result) {
return;
}
nostr_handler_publish_result_free(out_result);
out_result->kind = kind;
out_result->relay_count = relay_count;
out_result->accepted_by_pool_count = accepted_by_pool_count;
out_result->success = accepted_by_pool_count > 0 ? 1 : 0;
if (event_id_hex) {
snprintf(out_result->event_id, sizeof(out_result->event_id), "%s", event_id_hex);
unsigned char event_id_bytes[32];
char note_bech32[128];
if (strlen(event_id_hex) == 64U &&
nostr_hex_to_bytes(event_id_hex, event_id_bytes, sizeof(event_id_bytes)) == 0 &&
nostr_key_to_bech32(event_id_bytes, "note", note_bech32) == 0) {
snprintf(out_result->note_uri, sizeof(out_result->note_uri), "nostr:%s", note_bech32);
}
}
extract_d_tag(tags, out_result->d_tag, sizeof(out_result->d_tag));
(void)kind;
(void)relay_urls;
(void)duplicate_relay_list(relay_urls, relay_count, &out_result->relays);
}
static cJSON* create_dm_tags_for_recipient(const char* recipient_pubkey_hex) {
cJSON* tags = cJSON_CreateArray();
if (!tags) {
@@ -258,6 +389,12 @@ static void on_event(cJSON* event, const char* relay_url, void* user_data) {
return;
}
if (g_cfg->security.verify_signatures && nostr_verify_event_signature(event) != 0) {
DEBUG_WARN("[didactyl] dropped event with invalid signature via %s",
relay_url ? relay_url : "unknown relay");
return;
}
cJSON* id = cJSON_GetObjectItemCaseSensitive(event, "id");
cJSON* kind = cJSON_GetObjectItemCaseSensitive(event, "kind");
cJSON* pubkey = cJSON_GetObjectItemCaseSensitive(event, "pubkey");
@@ -277,13 +414,6 @@ static void on_event(cJSON* event, const char* relay_url, void* user_data) {
return;
}
if (strcmp(pubkey->valuestring, g_cfg->admin.pubkey) != 0) {
fprintf(stdout, "[didactyl] ignored DM from unauthorized pubkey %.16s... via %s\n",
pubkey->valuestring,
relay_url ? relay_url : "unknown relay");
return;
}
char recipient_pubkey_hex[65] = {0};
if (extract_first_p_tag(tags, recipient_pubkey_hex) != 0) {
return;
@@ -293,6 +423,27 @@ static void on_event(cJSON* event, const char* relay_url, void* user_data) {
return;
}
didactyl_sender_tier_t tier = DIDACTYL_SENDER_STRANGER;
if (strcmp(pubkey->valuestring, g_cfg->admin.pubkey) == 0) {
tier = DIDACTYL_SENDER_ADMIN;
} else if (g_cfg->security.wot.enabled && nostr_handler_is_wot_contact(pubkey->valuestring)) {
tier = DIDACTYL_SENDER_WOT;
}
if (tier == DIDACTYL_SENDER_STRANGER) {
if (!g_cfg->security.stranger.enabled) {
DEBUG_LOG("[didactyl] ignored DM from stranger %.16s... via %s",
pubkey->valuestring,
relay_url ? relay_url : "unknown relay");
return;
}
if (g_cfg->security.stranger_response[0] != '\0') {
(void)nostr_handler_send_dm(pubkey->valuestring, g_cfg->security.stranger_response);
}
return;
}
unsigned char sender_pubkey[32];
if (hex_to_pubkey(pubkey->valuestring, sender_pubkey) != 0) {
return;
@@ -324,12 +475,13 @@ static void on_event(cJSON* event, const char* relay_url, void* user_data) {
return;
}
DEBUG_INFO("[didactyl] received kind %d event %.16s... from %.16s... via %s",
DEBUG_INFO("[didactyl] received kind %d event %.16s... from %.16s... via %s tier=%d",
(int)kind->valuedouble,
event_id_hex ? event_id_hex : "<no-id>",
pubkey->valuestring,
relay_url ? relay_url : "unknown relay");
g_dm_callback(pubkey->valuestring, decrypted, g_dm_user_data);
relay_url ? relay_url : "unknown relay",
(int)tier);
g_dm_callback(pubkey->valuestring, decrypted, tier, g_dm_user_data);
free(decrypted);
}
@@ -339,6 +491,162 @@ static void on_eose(cJSON** events, int event_count, void* user_data) {
(void)user_data;
}
static void free_admin_context_locked(void) {
free(g_admin_kind0_json);
g_admin_kind0_json = NULL;
free(g_admin_kind10002_json);
g_admin_kind10002_json = NULL;
if (g_admin_wot_contacts) {
for (int i = 0; i < g_admin_wot_contact_count; i++) {
free(g_admin_wot_contacts[i]);
}
free(g_admin_wot_contacts);
}
g_admin_wot_contacts = NULL;
g_admin_wot_contact_count = 0;
if (g_admin_kind1_notes) {
for (int i = 0; i < g_admin_kind1_note_count; i++) {
free(g_admin_kind1_notes[i].content);
}
free(g_admin_kind1_notes);
}
g_admin_kind1_notes = NULL;
g_admin_kind1_note_count = 0;
}
static int parse_kind3_wot_contacts(cJSON* tags) {
if (!tags || !cJSON_IsArray(tags)) {
return 0;
}
if (g_admin_wot_contacts) {
for (int i = 0; i < g_admin_wot_contact_count; i++) {
free(g_admin_wot_contacts[i]);
}
free(g_admin_wot_contacts);
g_admin_wot_contacts = NULL;
g_admin_wot_contact_count = 0;
}
int n = cJSON_GetArraySize(tags);
for (int i = 0; i < n; i++) {
cJSON* tag = cJSON_GetArrayItem(tags, i);
if (!tag || !cJSON_IsArray(tag) || cJSON_GetArraySize(tag) < 2) {
continue;
}
cJSON* key = cJSON_GetArrayItem(tag, 0);
cJSON* val = cJSON_GetArrayItem(tag, 1);
if (!key || !val || !cJSON_IsString(key) || !cJSON_IsString(val) || !key->valuestring || !val->valuestring) {
continue;
}
if (strcmp(key->valuestring, "p") != 0 || strlen(val->valuestring) != 64U) {
continue;
}
char* dup = strdup(val->valuestring);
if (!dup) {
return -1;
}
char** grown = (char**)realloc(g_admin_wot_contacts, (size_t)(g_admin_wot_contact_count + 1) * sizeof(char*));
if (!grown) {
free(dup);
return -1;
}
g_admin_wot_contacts = grown;
g_admin_wot_contacts[g_admin_wot_contact_count++] = dup;
}
return 0;
}
static void upsert_kind1_note(time_t created_at, const char* content) {
if (!content) {
return;
}
int limit = g_cfg->admin_context.kind_1_limit > 0 ? g_cfg->admin_context.kind_1_limit : 10;
if (limit > 256) {
limit = 256;
}
char* dup = strdup(content);
if (!dup) {
return;
}
admin_kind1_note_t* grown = (admin_kind1_note_t*)realloc(g_admin_kind1_notes,
(size_t)(g_admin_kind1_note_count + 1) * sizeof(admin_kind1_note_t));
if (!grown) {
free(dup);
return;
}
g_admin_kind1_notes = grown;
g_admin_kind1_notes[g_admin_kind1_note_count].created_at = created_at;
g_admin_kind1_notes[g_admin_kind1_note_count].content = dup;
g_admin_kind1_note_count++;
while (g_admin_kind1_note_count > limit) {
free(g_admin_kind1_notes[0].content);
memmove(&g_admin_kind1_notes[0],
&g_admin_kind1_notes[1],
(size_t)(g_admin_kind1_note_count - 1) * sizeof(admin_kind1_note_t));
g_admin_kind1_note_count--;
}
}
static void on_admin_context_event(cJSON* event, const char* relay_url, void* user_data) {
(void)relay_url;
(void)user_data;
if (!event || !g_cfg || !g_cfg->admin_context.enabled) {
return;
}
if (g_cfg->security.verify_signatures && nostr_verify_event_signature(event) != 0) {
return;
}
cJSON* kind = cJSON_GetObjectItemCaseSensitive(event, "kind");
cJSON* pubkey = cJSON_GetObjectItemCaseSensitive(event, "pubkey");
cJSON* content = cJSON_GetObjectItemCaseSensitive(event, "content");
cJSON* tags = cJSON_GetObjectItemCaseSensitive(event, "tags");
cJSON* created_at = cJSON_GetObjectItemCaseSensitive(event, "created_at");
if (!kind || !pubkey || !cJSON_IsNumber(kind) || !cJSON_IsString(pubkey) || !pubkey->valuestring) {
return;
}
if (strcmp(pubkey->valuestring, g_cfg->admin.pubkey) != 0) {
return;
}
int k = (int)kind->valuedouble;
pthread_mutex_lock(&g_admin_ctx_mutex);
if (k == 0 && g_cfg->admin_context.track_kind_0 && content && cJSON_IsString(content) && content->valuestring) {
free(g_admin_kind0_json);
g_admin_kind0_json = strdup(content->valuestring);
} else if (k == 3 && g_cfg->admin_context.track_kind_3 && tags && cJSON_IsArray(tags)) {
(void)parse_kind3_wot_contacts(tags);
} else if (k == 10002 && g_cfg->admin_context.track_kind_10002 && content && cJSON_IsString(content) && content->valuestring) {
free(g_admin_kind10002_json);
g_admin_kind10002_json = strdup(content->valuestring);
} else if (k == 1 && g_cfg->admin_context.track_kind_1 && content && cJSON_IsString(content) && content->valuestring) {
time_t ts = (created_at && cJSON_IsNumber(created_at)) ? (time_t)created_at->valuedouble : time(NULL);
upsert_kind1_note(ts, content->valuestring);
}
pthread_mutex_unlock(&g_admin_ctx_mutex);
}
int nostr_handler_init(didactyl_config_t* config) {
if (!config) {
return -1;
@@ -390,6 +698,104 @@ int nostr_handler_init(didactyl_config_t* config) {
return 0;
}
int nostr_handler_subscribe_admin_context(void) {
if (!g_cfg || !g_pool || !g_cfg->admin_context.enabled) {
return 0;
}
int rc = 0;
cJSON* profile_filter = cJSON_CreateObject();
cJSON* profile_kinds = cJSON_CreateArray();
cJSON* profile_authors = cJSON_CreateArray();
if (!profile_filter || !profile_kinds || !profile_authors) {
cJSON_Delete(profile_filter);
cJSON_Delete(profile_kinds);
cJSON_Delete(profile_authors);
return -1;
}
if (g_cfg->admin_context.track_kind_0) cJSON_AddItemToArray(profile_kinds, cJSON_CreateNumber(0));
if (g_cfg->admin_context.track_kind_3) cJSON_AddItemToArray(profile_kinds, cJSON_CreateNumber(3));
if (g_cfg->admin_context.track_kind_10002) cJSON_AddItemToArray(profile_kinds, cJSON_CreateNumber(10002));
if (cJSON_GetArraySize(profile_kinds) > 0) {
cJSON_AddItemToObject(profile_filter, "kinds", profile_kinds);
cJSON_AddItemToArray(profile_authors, cJSON_CreateString(g_cfg->admin.pubkey));
cJSON_AddItemToObject(profile_filter, "authors", profile_authors);
cJSON_AddNumberToObject(profile_filter, "limit", 32);
nostr_pool_subscription_t* profile_sub = nostr_relay_pool_subscribe(
g_pool,
(const char**)g_cfg->relays,
g_cfg->relay_count,
profile_filter,
on_admin_context_event,
on_eose,
NULL,
0,
1,
NOSTR_POOL_EOSE_FULL_SET,
30,
120);
if (!profile_sub) {
rc = -1;
}
} else {
cJSON_Delete(profile_kinds);
cJSON_Delete(profile_authors);
}
cJSON_Delete(profile_filter);
if (g_cfg->admin_context.track_kind_1) {
cJSON* notes_filter = cJSON_CreateObject();
cJSON* notes_kinds = cJSON_CreateArray();
cJSON* notes_authors = cJSON_CreateArray();
if (!notes_filter || !notes_kinds || !notes_authors) {
cJSON_Delete(notes_filter);
cJSON_Delete(notes_kinds);
cJSON_Delete(notes_authors);
return -1;
}
int kind1_limit = g_cfg->admin_context.kind_1_limit > 0 ? g_cfg->admin_context.kind_1_limit : 10;
if (kind1_limit > 256) {
kind1_limit = 256;
}
cJSON_AddItemToArray(notes_kinds, cJSON_CreateNumber(1));
cJSON_AddItemToObject(notes_filter, "kinds", notes_kinds);
cJSON_AddItemToArray(notes_authors, cJSON_CreateString(g_cfg->admin.pubkey));
cJSON_AddItemToObject(notes_filter, "authors", notes_authors);
cJSON_AddNumberToObject(notes_filter, "limit", kind1_limit);
nostr_pool_subscription_t* notes_sub = nostr_relay_pool_subscribe(
g_pool,
(const char**)g_cfg->relays,
g_cfg->relay_count,
notes_filter,
on_admin_context_event,
on_eose,
NULL,
0,
1,
NOSTR_POOL_EOSE_FULL_SET,
30,
120);
cJSON_Delete(notes_filter);
if (!notes_sub) {
rc = -1;
}
}
if (rc == 0) {
DEBUG_INFO("[didactyl] admin context subscriptions active for admin %.16s...", g_cfg->admin.pubkey);
}
return rc;
}
int nostr_handler_subscribe_dms(dm_callback_t callback, void* user_data) {
if (!g_cfg || !g_pool || !callback) {
return -1;
@@ -528,7 +934,8 @@ static int publish_kind_event_to_relays(int kind,
cJSON* tags,
const char** relay_urls,
int relay_count,
const char* reason_label) {
const char* reason_label,
nostr_publish_result_t* out_result) {
if (!g_cfg || !g_pool || !content || !relay_urls || relay_count <= 0) {
return -1;
}
@@ -565,11 +972,23 @@ static int publish_kind_event_to_relays(int kind,
reason_label ? reason_label : "");
}
cJSON* event_id = cJSON_GetObjectItemCaseSensitive(event, "id");
const char* event_id_hex = (event_id && cJSON_IsString(event_id) && event_id->valuestring)
? event_id->valuestring
: "";
fill_publish_result(out_result,
kind,
tags,
event_id_hex,
relay_urls,
relay_count,
sent);
cJSON_Delete(event);
return sent > 0 ? 0 : -1;
}
int nostr_handler_publish_kind_event(int kind, const char* content, cJSON* tags) {
int nostr_handler_publish_kind_event(int kind, const char* content, cJSON* tags, nostr_publish_result_t* out_result) {
if (!g_cfg || !g_pool || !content) {
return -1;
}
@@ -594,7 +1013,13 @@ int nostr_handler_publish_kind_event(int kind, const char* content, cJSON* tags)
return -1;
}
int rc = publish_kind_event_to_relays(kind, content, tags, connected_relays, connected_count, "manual_publish");
int rc = publish_kind_event_to_relays(kind,
content,
tags,
connected_relays,
connected_count,
"manual_publish",
out_result);
free(connected_relays);
DEBUG_INFO("[didactyl] published kind %d event via %d connected relay(s)", kind, connected_count);
@@ -673,7 +1098,7 @@ static void publish_pending_startup_events_for_relay_index(int relay_index, cons
}
const char* one_relay[1] = { relay_url };
if (publish_kind_event_to_relays(se->kind, se->content, tags, one_relay, 1, reason) == 0) {
if (publish_kind_event_to_relays(se->kind, se->content, tags, one_relay, 1, reason, NULL) == 0) {
g_startup_published[slot] = 1;
} else {
DEBUG_WARN("[didactyl] startup event publish failed for kind=%d relay=%s", se->kind, relay_url);
@@ -731,6 +1156,80 @@ const char* nostr_handler_get_system_context(void) {
return g_system_context;
}
char* nostr_handler_get_admin_kind0_context(void) {
if (!g_cfg || !g_cfg->admin_context.enabled || !g_cfg->admin_context.track_kind_0) {
return NULL;
}
pthread_mutex_lock(&g_admin_ctx_mutex);
char* out = g_admin_kind0_json ? strdup(g_admin_kind0_json) : NULL;
pthread_mutex_unlock(&g_admin_ctx_mutex);
return out;
}
char* nostr_handler_get_admin_kind10002_context(void) {
if (!g_cfg || !g_cfg->admin_context.enabled || !g_cfg->admin_context.track_kind_10002) {
return NULL;
}
pthread_mutex_lock(&g_admin_ctx_mutex);
char* out = g_admin_kind10002_json ? strdup(g_admin_kind10002_json) : NULL;
pthread_mutex_unlock(&g_admin_ctx_mutex);
return out;
}
char* nostr_handler_get_admin_kind1_notes_context(void) {
if (!g_cfg || !g_cfg->admin_context.enabled || !g_cfg->admin_context.track_kind_1) {
return NULL;
}
pthread_mutex_lock(&g_admin_ctx_mutex);
if (g_admin_kind1_note_count <= 0 || !g_admin_kind1_notes) {
pthread_mutex_unlock(&g_admin_ctx_mutex);
return NULL;
}
size_t total = strlen("Administrator recent public notes:\n") + 1U;
for (int i = 0; i < g_admin_kind1_note_count; i++) {
total += strlen("- ") + strlen(g_admin_kind1_notes[i].content ? g_admin_kind1_notes[i].content : "") + 1U;
}
char* out = (char*)malloc(total);
if (!out) {
pthread_mutex_unlock(&g_admin_ctx_mutex);
return NULL;
}
out[0] = '\0';
strcat(out, "Administrator recent public notes:\n");
for (int i = 0; i < g_admin_kind1_note_count; i++) {
strcat(out, "- ");
strcat(out, g_admin_kind1_notes[i].content ? g_admin_kind1_notes[i].content : "");
strcat(out, "\n");
}
pthread_mutex_unlock(&g_admin_ctx_mutex);
return out;
}
int nostr_handler_is_wot_contact(const char* pubkey_hex) {
if (!pubkey_hex || strlen(pubkey_hex) != 64U) {
return 0;
}
pthread_mutex_lock(&g_admin_ctx_mutex);
int found = 0;
for (int i = 0; i < g_admin_wot_contact_count; i++) {
if (g_admin_wot_contacts[i] && strcmp(g_admin_wot_contacts[i], pubkey_hex) == 0) {
found = 1;
break;
}
}
pthread_mutex_unlock(&g_admin_ctx_mutex);
return found;
}
int nostr_handler_poll(int timeout_ms) {
if (!g_pool) {
return -1;
@@ -772,4 +1271,8 @@ void nostr_handler_cleanup(void) {
memset(g_seen_dm_ids, 0, sizeof(g_seen_dm_ids));
g_seen_dm_count = 0;
g_seen_dm_next = 0;
pthread_mutex_lock(&g_admin_ctx_mutex);
free_admin_context_locked();
pthread_mutex_unlock(&g_admin_ctx_mutex);
}
+29 -2
View File
@@ -4,16 +4,43 @@
#include "config.h"
#include "cjson/cJSON.h"
typedef void (*dm_callback_t)(const char* sender_pubkey_hex, const char* message, void* user_data);
typedef enum {
DIDACTYL_SENDER_ADMIN = 1,
DIDACTYL_SENDER_WOT = 2,
DIDACTYL_SENDER_STRANGER = 3
} didactyl_sender_tier_t;
typedef void (*dm_callback_t)(const char* sender_pubkey_hex,
const char* message,
didactyl_sender_tier_t tier,
void* user_data);
typedef struct {
int success;
int kind;
int relay_count;
int accepted_by_pool_count;
char event_id[65];
char note_uri[256];
char naddr_uri[1024];
char d_tag[128];
char** relays;
} nostr_publish_result_t;
int nostr_handler_init(didactyl_config_t* config);
int nostr_handler_subscribe_admin_context(void);
int nostr_handler_subscribe_dms(dm_callback_t callback, void* user_data);
int nostr_handler_send_dm(const char* recipient_pubkey_hex, const char* message);
int nostr_handler_publish_kind_event(int kind, const char* content, cJSON* tags);
int nostr_handler_publish_kind_event(int kind, const char* content, cJSON* tags, nostr_publish_result_t* out_result);
void nostr_handler_publish_result_free(nostr_publish_result_t* result);
char* nostr_handler_query_json(cJSON* filter, int timeout_ms);
int nostr_handler_poll(int timeout_ms);
int nostr_handler_reconcile_startup_events(void);
const char* nostr_handler_get_system_context(void);
char* nostr_handler_get_admin_kind0_context(void);
char* nostr_handler_get_admin_kind10002_context(void);
char* nostr_handler_get_admin_kind1_notes_context(void);
int nostr_handler_is_wot_contact(const char* pubkey_hex);
void nostr_handler_cleanup(void);
#endif
+601 -11
View File
@@ -6,6 +6,8 @@
#include <stdlib.h>
#include <string.h>
#include <limits.h>
#include <ctype.h>
#include <time.h>
#include "cjson/cJSON.h"
#include "nostr_handler.h"
@@ -20,16 +22,517 @@ static char* json_error(const char* msg) {
return out;
}
static char* json_success_with_message(const char* msg) {
cJSON* root = cJSON_CreateObject();
if (!root) return NULL;
cJSON_AddBoolToObject(root, "success", 1);
cJSON_AddStringToObject(root, "message", msg ? msg : "ok");
char* out = cJSON_PrintUnformatted(root);
cJSON_Delete(root);
static char* sanitize_json_string_controls(const char* in) {
if (!in) return NULL;
size_t len = strlen(in);
size_t cap = (len * 2U) + 1U;
char* out = (char*)malloc(cap);
if (!out) return NULL;
int in_string = 0;
int escaping = 0;
size_t j = 0;
for (size_t i = 0; i < len; i++) {
char c = in[i];
if (escaping) {
if (j + 1U >= cap) {
free(out);
return NULL;
}
out[j++] = c;
escaping = 0;
continue;
}
if (c == '\\') {
if (j + 1U >= cap) {
free(out);
return NULL;
}
out[j++] = c;
if (in_string) escaping = 1;
continue;
}
if (c == '"') {
if (j + 1U >= cap) {
free(out);
return NULL;
}
out[j++] = c;
in_string = !in_string;
continue;
}
if (in_string && (c == '\n' || c == '\r' || c == '\t')) {
if (j + 2U >= cap) {
free(out);
return NULL;
}
out[j++] = '\\';
out[j++] = (c == '\n') ? 'n' : (c == '\r') ? 'r' : 't';
continue;
}
if (j + 1U >= cap) {
free(out);
return NULL;
}
out[j++] = c;
}
out[j] = '\0';
return out;
}
static const char* find_key_start(const char* in, const char* key) {
if (!in || !key) return NULL;
char pattern[64];
int n = snprintf(pattern, sizeof(pattern), "\"%s\"", key);
if (n <= 0 || (size_t)n >= sizeof(pattern)) return NULL;
return strstr(in, pattern);
}
static const char* skip_ws(const char* p) {
while (p && *p && isspace((unsigned char)*p)) p++;
return p;
}
static int parse_loose_kind(const char* in, int* out_kind) {
if (!in || !out_kind) return -1;
const char* p = find_key_start(in, "kind");
if (!p) return -1;
p = strchr(p, ':');
if (!p) return -1;
p = skip_ws(p + 1);
if (!p || !*p) return -1;
char* end = NULL;
long v = strtol(p, &end, 10);
if (end == p) return -1;
*out_kind = (int)v;
return 0;
}
static char* parse_loose_json_string_value(const char* in, const char* key) {
if (!in || !key) return NULL;
const char* p = find_key_start(in, key);
if (!p) return NULL;
p = strchr(p, ':');
if (!p) return NULL;
p = skip_ws(p + 1);
if (!p || *p != '"') return NULL;
p++;
size_t max_len = strlen(p);
char* out = (char*)malloc(max_len + 1U);
if (!out) return NULL;
size_t j = 0;
int escaping = 0;
for (size_t i = 0; p[i] != '\0'; i++) {
char c = p[i];
if (escaping) {
switch (c) {
case 'n': out[j++] = '\n'; break;
case 'r': out[j++] = '\r'; break;
case 't': out[j++] = '\t'; break;
case '"': out[j++] = '"'; break;
case '\\': out[j++] = '\\'; break;
default: out[j++] = c; break;
}
escaping = 0;
continue;
}
if (c == '\\') {
escaping = 1;
continue;
}
if (c == '"') {
out[j] = '\0';
return out;
}
out[j++] = c;
}
out[j] = '\0';
return out;
}
static cJSON* parse_loose_tags_array(const char* in) {
if (!in) return NULL;
const char* p = find_key_start(in, "tags");
if (!p) return NULL;
p = strchr(p, ':');
if (!p) return NULL;
p = skip_ws(p + 1);
if (!p || *p != '[') return NULL;
const char* start = p;
int depth = 0;
int in_string = 0;
int escaping = 0;
for (; *p; p++) {
char c = *p;
if (escaping) {
escaping = 0;
continue;
}
if (c == '\\' && in_string) {
escaping = 1;
continue;
}
if (c == '"') {
in_string = !in_string;
continue;
}
if (in_string) {
continue;
}
if (c == '[') depth++;
else if (c == ']') {
depth--;
if (depth == 0) {
size_t len = (size_t)(p - start + 1);
char* arr_json = (char*)malloc(len + 1U);
if (!arr_json) return NULL;
memcpy(arr_json, start, len);
arr_json[len] = '\0';
cJSON* tags = cJSON_Parse(arr_json);
free(arr_json);
if (tags && cJSON_IsArray(tags)) {
return tags;
}
cJSON_Delete(tags);
return NULL;
}
}
}
return NULL;
}
static cJSON* parse_loose_nostr_post_args(const char* in) {
if (!in) return NULL;
int kind = 0;
if (parse_loose_kind(in, &kind) != 0) {
return NULL;
}
char* content = parse_loose_json_string_value(in, "content");
if (!content) {
return NULL;
}
cJSON* args = cJSON_CreateObject();
if (!args) {
free(content);
return NULL;
}
cJSON_AddNumberToObject(args, "kind", kind);
cJSON_AddStringToObject(args, "content", content);
free(content);
cJSON* tags = parse_loose_tags_array(in);
if (tags) {
cJSON_AddItemToObject(args, "tags", tags);
}
return args;
}
static cJSON* ensure_tags_array(cJSON** tags_inout) {
if (!tags_inout) return NULL;
if (*tags_inout) {
if (cJSON_IsArray(*tags_inout)) {
return *tags_inout;
}
cJSON_Delete(*tags_inout);
*tags_inout = NULL;
}
*tags_inout = cJSON_CreateArray();
return *tags_inout;
}
static int has_tag_key(cJSON* tags, const char* key) {
if (!tags || !cJSON_IsArray(tags) || !key) return 0;
int n = cJSON_GetArraySize(tags);
for (int i = 0; i < n; i++) {
cJSON* tag = cJSON_GetArrayItem(tags, i);
if (!tag || !cJSON_IsArray(tag)) continue;
cJSON* k = cJSON_GetArrayItem(tag, 0);
if (k && cJSON_IsString(k) && k->valuestring && strcmp(k->valuestring, key) == 0) {
return 1;
}
}
return 0;
}
static int add_string_tag(cJSON* tags, const char* key, const char* value) {
if (!tags || !cJSON_IsArray(tags) || !key || !value || value[0] == '\0') return -1;
cJSON* tag = cJSON_CreateArray();
if (!tag) return -1;
cJSON_AddItemToArray(tag, cJSON_CreateString(key));
cJSON_AddItemToArray(tag, cJSON_CreateString(value));
cJSON_AddItemToArray(tags, tag);
return 0;
}
static char* trim_copy(const char* start, size_t len) {
while (len > 0 && isspace((unsigned char)start[0])) {
start++;
len--;
}
while (len > 0 && isspace((unsigned char)start[len - 1])) {
len--;
}
char* out = (char*)malloc(len + 1U);
if (!out) return NULL;
memcpy(out, start, len);
out[len] = '\0';
return out;
}
static char* first_markdown_h1(const char* content) {
if (!content) return NULL;
const char* p = content;
while (*p) {
const char* line = p;
const char* nl = strchr(line, '\n');
size_t len = nl ? (size_t)(nl - line) : strlen(line);
while (len > 0 && (line[len - 1] == '\r')) len--;
size_t i = 0;
while (i < len && isspace((unsigned char)line[i])) i++;
if (i < len && line[i] == '#') {
size_t j = i;
while (j < len && line[j] == '#') j++;
if (j < len && isspace((unsigned char)line[j])) {
while (j < len && isspace((unsigned char)line[j])) j++;
if (j < len) return trim_copy(line + j, len - j);
}
}
if (!nl) break;
p = nl + 1;
}
return NULL;
}
static int is_paragraph_line(const char* line, size_t len) {
size_t i = 0;
while (i < len && isspace((unsigned char)line[i])) i++;
if (i >= len) return 0;
char c = line[i];
if (c == '#' || c == '>' || c == '-' || c == '*' || c == '`' || c == '|') return 0;
if (isdigit((unsigned char)c)) {
size_t j = i;
while (j < len && isdigit((unsigned char)line[j])) j++;
if (j < len && line[j] == '.') return 0;
}
return 1;
}
static char* first_markdown_paragraph(const char* content) {
if (!content) return NULL;
const char* p = content;
while (*p) {
const char* line = p;
const char* nl = strchr(line, '\n');
size_t len = nl ? (size_t)(nl - line) : strlen(line);
while (len > 0 && line[len - 1] == '\r') len--;
if (is_paragraph_line(line, len)) {
size_t cap = 1024;
size_t used = 0;
char* out = (char*)malloc(cap);
if (!out) return NULL;
const char* q = line;
const char* qnl = nl;
size_t qlen = len;
while (1) {
if (!is_paragraph_line(q, qlen)) break;
size_t start = 0;
while (start < qlen && isspace((unsigned char)q[start])) start++;
size_t end = qlen;
while (end > start && isspace((unsigned char)q[end - 1])) end--;
size_t part_len = end - start;
if (used + part_len + 2 >= cap) {
cap = (cap * 2U) + part_len + 16U;
char* bigger = (char*)realloc(out, cap);
if (!bigger) {
free(out);
return NULL;
}
out = bigger;
}
if (part_len > 0) {
if (used > 0) out[used++] = ' ';
memcpy(out + used, q + start, part_len);
used += part_len;
}
if (!qnl) break;
q = qnl + 1;
qnl = strchr(q, '\n');
qlen = qnl ? (size_t)(qnl - q) : strlen(q);
while (qlen > 0 && q[qlen - 1] == '\r') qlen--;
}
out[used] = '\0';
return out;
}
if (!nl) break;
p = nl + 1;
}
return NULL;
}
static char* first_markdown_image_url(const char* content) {
if (!content) return NULL;
const char* p = content;
while ((p = strstr(p, "![")) != NULL) {
const char* close_bracket = strchr(p + 2, ']');
if (!close_bracket || close_bracket[1] != '(') {
p += 2;
continue;
}
const char* url_start = close_bracket + 2;
const char* url_end = strchr(url_start, ')');
if (!url_end || url_end <= url_start) {
p += 2;
continue;
}
return trim_copy(url_start, (size_t)(url_end - url_start));
}
return NULL;
}
static char* slugify_string(const char* in, const char* fallback) {
if (!in || in[0] == '\0') {
return fallback ? strdup(fallback) : NULL;
}
size_t len = strlen(in);
char* out = (char*)malloc(len + 1U);
if (!out) return NULL;
size_t j = 0;
int prev_dash = 0;
for (size_t i = 0; i < len; i++) {
unsigned char c = (unsigned char)in[i];
if (isalnum(c)) {
out[j++] = (char)tolower(c);
prev_dash = 0;
} else if (!prev_dash && j > 0) {
out[j++] = '-';
prev_dash = 1;
}
}
while (j > 0 && out[j - 1] == '-') j--;
out[j] = '\0';
if (j == 0) {
free(out);
return fallback ? strdup(fallback) : NULL;
}
return out;
}
static void ensure_nip23_metadata_tags(int kind, const char* content, cJSON** tags_inout) {
if (!content || (kind != 30023 && kind != 30024) || !tags_inout) {
return;
}
cJSON* tags = ensure_tags_array(tags_inout);
if (!tags) return;
char* title = has_tag_key(tags, "title") ? NULL : first_markdown_h1(content);
char* summary = has_tag_key(tags, "summary") ? NULL : first_markdown_paragraph(content);
char* image = has_tag_key(tags, "image") ? NULL : first_markdown_image_url(content);
if (title) {
(void)add_string_tag(tags, "title", title);
}
if (summary) {
(void)add_string_tag(tags, "summary", summary);
}
if (image) {
(void)add_string_tag(tags, "image", image);
}
if (!has_tag_key(tags, "published_at")) {
char published_at[32];
snprintf(published_at, sizeof(published_at), "%lld", (long long)time(NULL));
(void)add_string_tag(tags, "published_at", published_at);
}
if (!has_tag_key(tags, "d")) {
char* slug = NULL;
if (title) {
slug = slugify_string(title, "long-form-note");
} else {
char* derived_title = first_markdown_h1(content);
slug = slugify_string(derived_title, "long-form-note");
free(derived_title);
}
if (slug) {
(void)add_string_tag(tags, "d", slug);
free(slug);
}
}
free(title);
free(summary);
free(image);
}
static int is_safe_relative_path(const char* path) {
if (!path || path[0] == '\0') return 0;
if (path[0] == '/') return 0;
@@ -94,6 +597,16 @@ char* tools_build_openai_schema_json(const tools_context_t* ctx) {
cJSON* p_content = cJSON_CreateObject();
cJSON_AddStringToObject(p_content, "type", "string");
cJSON_AddItemToObject(t1_props, "content", p_content);
cJSON* p_tags = cJSON_CreateObject();
cJSON_AddStringToObject(p_tags, "type", "array");
cJSON_AddStringToObject(p_tags, "description", "Optional Nostr tags array, e.g. [[\"d\",\"slug\"],[\"t\",\"nostr\"]]");
cJSON* p_tags_items = cJSON_CreateObject();
cJSON_AddStringToObject(p_tags_items, "type", "array");
cJSON* p_tag_item = cJSON_CreateObject();
cJSON_AddStringToObject(p_tag_item, "type", "string");
cJSON_AddItemToObject(p_tags_items, "items", p_tag_item);
cJSON_AddItemToObject(p_tags, "items", p_tags_items);
cJSON_AddItemToObject(t1_props, "tags", p_tags);
cJSON_AddItemToArray(t1_required, cJSON_CreateString("kind"));
cJSON_AddItemToArray(t1_required, cJSON_CreateString("content"));
@@ -209,20 +722,97 @@ char* tools_build_openai_schema_json(const tools_context_t* ctx) {
static char* execute_nostr_post(const char* args_json) {
cJSON* args = cJSON_Parse(args_json ? args_json : "{}");
if (!args) return json_error("invalid arguments JSON");
char* repaired_args_json = NULL;
if (!args && args_json) {
repaired_args_json = sanitize_json_string_controls(args_json);
if (repaired_args_json) {
args = cJSON_Parse(repaired_args_json);
}
}
if (!args && args_json) {
args = parse_loose_nostr_post_args(args_json);
}
if (!args) {
free(repaired_args_json);
return json_error("invalid arguments JSON");
}
cJSON* kind = cJSON_GetObjectItemCaseSensitive(args, "kind");
cJSON* content = cJSON_GetObjectItemCaseSensitive(args, "content");
cJSON* tags = cJSON_GetObjectItemCaseSensitive(args, "tags");
if (!kind || !cJSON_IsNumber(kind) || !content || !cJSON_IsString(content) || !content->valuestring) {
cJSON_Delete(args);
return json_error("nostr_post requires integer kind and string content");
}
if (tags && !cJSON_IsArray(tags)) {
cJSON_Delete(args);
return json_error("nostr_post tags must be an array when provided");
}
int rc = nostr_handler_publish_kind_event((int)kind->valuedouble, content->valuestring, NULL);
cJSON* tags_dup = NULL;
if (tags) {
tags_dup = cJSON_Duplicate(tags, 1);
if (!tags_dup) {
cJSON_Delete(args);
return json_error("nostr_post failed to duplicate tags");
}
}
ensure_nip23_metadata_tags((int)kind->valuedouble, content->valuestring, &tags_dup);
nostr_publish_result_t publish_result;
memset(&publish_result, 0, sizeof(publish_result));
int rc = nostr_handler_publish_kind_event((int)kind->valuedouble,
content->valuestring,
tags_dup,
&publish_result);
cJSON_Delete(tags_dup);
cJSON_Delete(args);
if (rc != 0) return json_error("nostr_post failed");
free(repaired_args_json);
if (rc != 0) {
nostr_handler_publish_result_free(&publish_result);
return json_error("nostr_post failed");
}
return json_success_with_message("nostr_post published");
cJSON* out = cJSON_CreateObject();
if (!out) {
nostr_handler_publish_result_free(&publish_result);
return NULL;
}
cJSON_AddBoolToObject(out, "success", publish_result.success ? 1 : 0);
cJSON_AddStringToObject(out, "message", "nostr_post published");
cJSON_AddNumberToObject(out, "kind", publish_result.kind);
cJSON_AddStringToObject(out, "event_id", publish_result.event_id);
cJSON_AddNumberToObject(out, "relay_count", publish_result.relay_count);
cJSON_AddNumberToObject(out, "accepted_by_pool_count", publish_result.accepted_by_pool_count);
if (publish_result.note_uri[0] != '\0') {
cJSON_AddStringToObject(out, "note_uri", publish_result.note_uri);
}
if (publish_result.naddr_uri[0] != '\0') {
cJSON_AddStringToObject(out, "naddr_uri", publish_result.naddr_uri);
}
if (publish_result.d_tag[0] != '\0') {
cJSON_AddStringToObject(out, "d_tag", publish_result.d_tag);
}
cJSON* relays = cJSON_CreateArray();
if (!relays) {
nostr_handler_publish_result_free(&publish_result);
cJSON_Delete(out);
return NULL;
}
for (int i = 0; i < publish_result.relay_count; i++) {
cJSON_AddItemToArray(relays, cJSON_CreateString(publish_result.relays[i] ? publish_result.relays[i] : ""));
}
cJSON_AddItemToObject(out, "relays", relays);
char* json = cJSON_PrintUnformatted(out);
cJSON_Delete(out);
nostr_handler_publish_result_free(&publish_result);
return json;
}
static char* execute_nostr_query(const char* args_json) {