loom-encrypt · key
Source declarations, signatures and documentation for key.
Source: sigil/weave/tools/loom-encrypt/src/key.rs. SHA-256: 2de8c8f35ae470c630a14bd649ad9c9aa448ede2638c88d39e301e55f6aca947.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
key::MEK_LEN
Length of the master encryption key in bytes (256-bit ChaCha20 key).
pub const MEK_LEN: usize;Source line: 8.
key::MasterKey
Master encryption key. Wrapped so it zeroes its memory on drop — hostile core dumps cannot scrape it later.
#[derive(Clone, ZeroizeOnDrop)]
pub struct MasterKey([u8; MEK_LEN]);Source line: 21.
key::MasterKey::from_bytes
Wrap raw key bytes. Caller is responsible for sourcing them (from agent identity, from a secret store, from a passphrase).
pub fn from_bytes(bytes: [u8; MEK_LEN]) -> Self;Source line: 26.
key::MasterKey::as_bytes
Borrow the raw key bytes for HKDF input. Only call inside the crypto path; never log or persist the result.
pub fn as_bytes(&self) -> &[u8; MEK_LEN];Source line: 32.
key::derive_blob_key
Derive the per-blob ChaCha20 key from (blob_hash, mek).
blob_hash is the BLAKE3 hex of the plaintext; it doubles as the
HKDF salt so two different blobs end up with completely distinct keys.
pub fn derive_blob_key(mek: &MasterKey, blob_hash: &str) -> Zeroizing<[u8; 32]>;Source line: 49.
key::derive_blob_nonce
Derive the deterministic 12-byte nonce from (blob_hash, mek).
Determinism is safe here because each plaintext has a unique
blob_hash (BLAKE3), so the (key, nonce) pair is globally unique
per content. Different blobs end up with independent keys *and
nonces — there is no nonce-reuse attack surface.
pub fn derive_blob_nonce(mek: &MasterKey, blob_hash: &str) -> [u8; 12];Source line: 63.
key::mek_from_identity_bytes
Derive a MEK from an agent's identity material plus a repo id. Useful when the user doesn't want a passphrase — they get one MEK per repo per agent automatically. Identical inputs always produce the same MEK so the agent can re-derive on every loom invocation.
The repo id is bound into the HKDF info tag so two private repos on the same agent get different MEKs even if their content overlaps.
pub fn mek_from_identity_bytes(identity_bytes: &[u8], repo_id: &str) -> MasterKey;Source line: 78.