3.3 KiB
3.3 KiB
Changelog
All notable changes to this project are documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
[Unreleased]
[0.0.2] - 2026-08-17
[0.0.1] - 2026-08-17
Added
- NIP-06: Full BIP-32 HD path derivation (
m/44'/1237'/0'/0/0) withbip32_master_key,bip32_derive_child(hardened + non-hardened),bip32_derive_path,parse_bip44_path. Restores C/Rust key compatibility. - NIP-06: SLIP-0010 ed25519/x25519 derivation (
slip10_master_key,slip10_derive_child,slip10_derive_path,keypair_from_seed_ed25519). - NIP-06: 13 test vectors including official BIP-32 vectors and a pinned mnemonic vector cross-verified against a Python reference.
- NIP-03: Real OpenTimestamps verification — OTS binary file parser,
Merkle proof execution (append/prepend/SHA-256/RIPEMD-160/SHA-1/double
SHA-256), Bitcoin block header attestation comparison. Replaces the
Ok(true)placeholder stub. - NIP-03: 10 tests including tampered-root and malformed-file cases.
- Validator: Enforce all 8
AuthRuleTypevariants —HashBlacklist,MimeWhitelist(OR-combined),MimeBlacklist,SizeLimit,RateLimit(stateful per-IP windowed counter),Custom. The_ => {}fallthrough that silently allowed denied requests is removed. - Validator: 12 new tests covering every rule type.
- Nsigner: Three new transports —
SerialTransport(CDC-ACM viaserialport),FdTransport(Unix FD-pair viaFromRawFd),QrexecTransport(Qubes qrexec viaqrexec-client-vm). - Nsigner: Algorithm-based verbs — ed25519 sign/get_public_key, x25519 get_public_key/ecdh, ML-DSA-65 sign/verify, ML-KEM-768 encapsulate/decapsulate, OTP encrypt/decrypt.
- Nsigner:
derive_hmacnow uses a configurable algorithm (defaultsecp256k1);role_pathis now sent in all RPC calls when set. - Nsigner:
MockTransporttest helper and 16 new tests. - Cashu: Five new mint operations —
request_melt_quote,check_melt_quote,mint_tokens,swap_tokens,check_spent,restore_keysets.get_mint_keysnow returns typedCashuKeysResponse. - Cashu: Typed structs
CashuKeysetKeys,BlindedMessage,BlindSignature,MintResponse,Proof,CheckStateResponse,RestoreResponse. 11 tests. - Blossom:
head_blob(HEAD request with header metadata extraction),upload_file(from file path),download_to_file(to file path). - Blossom:
BlossomSignertrait for remote-signer support withcreate_auth_header_with_signer,upload_with_signer,delete_with_signer. 5 tests. - Versioning:
VERSIONfile,CHANGELOG.md,increment_and_push.shscript for semantic version bumps with git tagging and pushing.
Fixed
- NIP-06 (CRITICAL):
keypair_from_seedno longer skips BIP-32 path derivation. The same mnemonic + path now produces identical keypairs in C and Rust, restoring identity portability. - NIP-03 (HIGH):
verify_otsno longer returnsOk(true)for any non-empty input. It now performs real Merkle proof verification. - Validator (HIGH): 6 of 8 auth rule types are no longer silently
allowed via a
_ => {}fallthrough. Configured deny rules are now enforced.