The previous implementation used libsecp256k1's hashed ECDH, a non-standard
HKDF info string, ChaCha20-Poly1305 with a 12-byte nonce, no padding, and no
version byte. It could not decrypt real NIP-44 v2 payloads, causing the remote
signer to reject nostr_nip44_decrypt with invalid_params (-32602).
Rewrote to match the NIP-44 v2 spec and added known-answer tests using the
official test vectors (calc_padded_len, get_conversation_key, get_message_keys,
encrypt_decrypt).