loom-encrypt · codec
Source declarations, signatures and documentation for codec.
Source: sigil/weave/tools/loom-encrypt/src/codec.rs. SHA-256: 608fa0d851755d4358ae6a24c30a7b9f540088ac9cf74678cef88263120b70c9.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
codec::FORMAT_VERSION
Format version byte at offset 0.
pub const FORMAT_VERSION: u8;Source line: 26.
codec::EncryptError
Errors raised during [seal].
#[derive(Debug, Error)]
pub enum EncryptError {
/// AEAD failed (should not happen with well-formed inputs).
#[error("AEAD seal failed: {0}")]
Aead(String),
}Source line: 37.
codec::DecryptError
Errors raised during [open].
#[derive(Debug, Error)]
pub enum DecryptError {
/// Ciphertext shorter than the minimum header + tag.
#[error("ciphertext too short: {len} bytes (need at least {needed})")]
TooShort {
/// Actual length.
len: usize,
/// Required minimum.
needed: usize,
},
/// Format version byte was not [`FORMAT_VERSION`].
#[error("unknown format version 0x{0:02x}")]
UnknownVersion(u8),
/// In-band nonce did not match the expected derivation. Indicates
/// the ciphertext was forged or copy-paste'd from another (mek,
/// blob_hash) pair — refuse to decrypt either way.
#[error("nonce mismatch (ciphertext was sealed under a different key/blob_hash)")]
NonceMismatch,
/// AEAD authentication failed (tampered ciphertext or wrong key).
#[error("authentication tag invalid (wrong key, wrong blob_hash, or tampering)")]
Auth,
}Source line: 45.
codec::seal
Encrypt plaintext for storage. The associated data committed to by
the AEAD is the BLAKE3 blob_hash itself, so a ciphertext relocated
to a different /blobs/<other_hash> slot fails to decrypt — that
makes the storage path tamper-evident in addition to the AEAD tag.
pub fn seal(mek: &MasterKey, blob_hash: &str, plaintext: &[u8]) -> Result<Vec<u8>, EncryptError>;Source line: 71.
codec::open
Decrypt a ciphertext previously produced by [seal]. Verifies the
in-band nonce against the expected derivation (catches accidental
blob-hash mix-ups) and the AEAD tag (catches tampering).
pub fn open(mek: &MasterKey, blob_hash: &str, ciphertext: &[u8]) -> Result<Vec<u8>, DecryptError>;Source line: 98.