Internals
Identity::public_key() returns an Ed25519 verifying-key object; use public_key_bytes() for its 32-byte representation.
Packet and session boundaries
Identity::public_key() returns an Ed25519 verifying-key object; use public_key_bytes() for its 32-byte representation. PendingSession owns an ephemeral X25519 handshake key and completes it against the remote ephemeral public key.
HelloMessage::new takes the ephemeral X25519 public-key bytes, not the long-term Ed25519 identity key. The packet constructor is:
pub fn new(
packet_type: PacketType,
sender: &Identity,
sequence: u64,
payload: Vec<u8>,
) -> Packet;Packet::new signs the header and payload and returns the packet directly. verify() returns a result; encode() and decode() use the package's binary representation. Decoding and signature verification are distinct operations. Session encryption uses the derived session key; the local router example still requires handshake processing before encrypted application data.
Source: filament-minimal/src/crypto.rs, packet.rs, and interface.rs.