Weave documentation
Rust referenceweave-crypto

weave-crypto · crate

Source declarations, signatures and documentation for crate.

Reviewed implementation boundary: The checked hash implementation uses Blake2s256. Historical source comments referring to Blake2b or guides referring to BLAKE3 do not override the function body. Read /libraries/weave-crypto/hashing for the implemented wire/hash conventions.

Source: sigil/weave/libs/weave-crypto/src/lib.rs. SHA-256: bb5ea393327975daab903bdd30ec9f74215dd55b8d6dac889235aa04a3dbf2bb.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

::CryptoError

Errors that can occur during cryptographic operations

#[derive(Error, Debug)]
pub enum CryptoError {
    #[error("Invalid key length: expected {expected}, got {actual}")]
    InvalidKeyLength { expected: usize, actual: usize },

    #[error("Invalid signature")]
    InvalidSignature,

    #[error("Decryption failed")]
    DecryptionFailed,

    #[error("Invalid seed length")]
    InvalidSeedLength,
}

Source line: 45.

::Result

Result type for crypto operations

pub type Result<T> = std::result::Result<T, CryptoError>;

Source line: 60.

::KeyPair

A key pair for signing operations

#[derive(Clone, Debug)]
pub struct KeyPair {
pub public_key: [u8; 32],
pub secret_key: [u8; 64]
}

Source line: 64.

::EncryptionKeyPair

A key pair for encryption operations

#[derive(Clone)]
pub struct EncryptionKeyPair {
pub public_key: [u8; 32],
pub secret_key: [u8; 32]
}

Source line: 77.

::Node

Node structure for merkle tree operations

#[derive(Debug, Clone)]
pub struct Node {
pub index: u64,
pub size: u64,
pub hash: [u8; 32]
}

Source line: 90.

::key_pair

Generate a new Ed25519 key pair

Arguments

  • seed - Optional 32-byte seed for deterministic key generation

Returns

A new KeyPair for signing operations

pub fn key_pair(seed: Option<&[u8; 32]>) -> KeyPair;

Source line: 103.

::validate_key_pair

Validate that a key pair's public key matches its secret key

Arguments

  • key_pair - The key pair to validate

Returns

true if the keys match, false otherwise

pub fn validate_key_pair(key_pair: &KeyPair) -> bool;

Source line: 132.

::sign

Sign a message with a secret key

Arguments

  • message - The message to sign
  • secret_key - The 64-byte secret key (32-byte seed + 32-byte public key)

Returns

A 64-byte signature

pub fn sign(message: &[u8], secret_key: &[u8; 64]) -> [u8; 64];

Source line: 149.

::verify

Verify a signature

Arguments

  • message - The original message
  • signature - The signature to verify
  • public_key - The public key to verify against

Returns

true if the signature is valid, false otherwise

pub fn verify(message: &[u8], signature: &[u8], public_key: &[u8; 32]) -> bool;

Source line: 166.

::encryption_key_pair

Generate a key pair for sealed box encryption

Arguments

  • seed - Optional seed for deterministic generation

Returns

An EncryptionKeyPair for sealed box operations

pub fn encryption_key_pair(seed: Option<&[u8; 32]>) -> EncryptionKeyPair;

Source line: 193.

::encrypt

Encrypt a message using sealed box encryption

Arguments

  • message - The message to encrypt
  • public_key - The recipient's public key

Returns

The encrypted ciphertext

pub fn encrypt(message: &[u8], public_key: &[u8; 32]) -> Vec<u8>;

Source line: 216.

::decrypt

Decrypt a sealed box

Arguments

  • ciphertext - The encrypted message
  • key_pair - The recipient's key pair

Returns

The decrypted message, or None if decryption fails

pub fn decrypt(ciphertext: &[u8], key_pair: &EncryptionKeyPair) -> Option<Vec<u8>>;

Source line: 231.

::data

Hash data for a leaf node

Arguments

  • data - The data to hash

Returns

A 32-byte hash

pub fn data(data: &[u8]) -> [u8; 32];

Source line: 251.

::parent

Hash two nodes to create a parent node

Arguments

  • left - The left child node
  • right - The right child node

Returns

A 32-byte hash for the parent

pub fn parent(left: &Node, right: &Node) -> [u8; 32];

Source line: 267.

::tree

Hash a set of root nodes

Arguments

  • roots - The root nodes to hash

Returns

A 32-byte tree hash

pub fn tree(roots: &[Node]) -> [u8; 32];

Source line: 290.

::hash

Generic hash function using Blake2b

Arguments

  • data - Slice of byte slices to hash together

Returns

A 32-byte hash

pub fn hash(data: &[&[u8]]) -> [u8; 32];

Source line: 310.

::hash_into

Generic hash function with output buffer

Arguments

  • data - Slice of byte slices to hash together
  • out - Output buffer (must be 32 bytes)
pub fn hash_into(data: &[&[u8]], out: &mut [u8; 32]);

Source line: 323.

::hkdf_sha256

Derive key material using HKDF-SHA256 (RFC 5869)

  • ikm: input keying material
  • salt: optional salt (may be empty)
  • info: optional context and application specific information
  • len: desired length of output keying material

Returns a vector of length len with pseudorandom keying material.

#[cfg(all(feature = "hkdf", feature = "sha2"))]
pub fn hkdf_sha256(ikm: &[u8], salt: &[u8], info: &[u8], len: usize) -> Vec<u8>;

Source line: 336.

::derive_nonce

Derive a deterministic nonce using HKDF-SHA256.

Uses a domain-separated salt and the provided label as HKDF info. Returns a 24-byte nonce suitable for XChaCha20-Poly1305 or similar.

#[cfg(all(feature = "hkdf", feature = "sha2"))]
pub fn derive_nonce(label: &str, seed: &[u8; 32]) -> [u8; 24];

Source line: 348.

::random_bytes

Generate random bytes

Arguments

  • n - Number of bytes to generate

Returns

A vector of random bytes

pub fn random_bytes(n: usize) -> Vec<u8>;

Source line: 363.

::discovery_key

Generate a discovery key from a public key

Arguments

  • key - A 32-byte public key

Returns

A 32-byte discovery key

pub fn discovery_key(key: &[u8; 32]) -> [u8; 32];

Source line: 377.

::namespace

Generate namespaced keys

Arguments

  • name - The namespace name
  • count - Number of keys to generate (or specific indices)

Returns

A vector of 32-byte keys

pub fn namespace(name: &str, count: impl NamespaceCount) -> Vec<[u8; 32]>;

Source line: 392.

::free

Free secure memory (no-op in Rust as memory is automatically freed)

pub fn free(_secure_buf: &[u8]);

Source line: 419.

::NamespaceCount

Trait for namespace count parameter (can be a count or specific indices)

pub trait NamespaceCount {
    fn indices(&self) -> Vec<usize>;
}

Source line: 425.

On this page