pub enum NoncePolicy {
RandomStored,
DerivedFromContext {
context: Vec<u8>,
},
}Expand description
Where a sealed payload’s base nonce comes from — the choice every caller that seals or opens one states outright.
§Invariant: a derived base must be unique per plaintext
XChaCha20-Poly1305 offers no margin for nonce reuse. Two different
plaintexts sealed under one key and one nonce leak their XOR and forfeit
authentication, and that failure is silent — everything still encrypts,
decrypts, and round-trips. Self::DerivedFromContext is therefore only
safe while its context differs whenever the plaintext does, which is why
the context is part of the policy rather than something a caller can forget
to pass, and why the choice is a named variant rather than a flag or a
default.
Variants§
RandomStored
A base nonce drawn at random and written into the header, ahead of the chunks. Safe however the payload is addressed, at the cost of 24 stored bytes and a base only the stored header carries.
DerivedFromContext
A base nonce derived by HKDF from the sealing key and context, stored
nowhere, so the same payload always seals to the same bytes and a reader
that knows the context can open any chunk without reading a base first.
context must differ whenever the plaintext does. It holds for a blob
because the context is minted from the blob’s semantic key, which for an
opaque blob is {namespace}/opaque/{locator_hash}, and the locator hash
covers the plaintext hash — so two different plaintexts cannot share a
context without a SHA-256 collision. Re-sealing identical bytes under an
identical context reproduces an identical base, which is fine: it
reproduces identical ciphertext, not a second message under one nonce.
Any change to how a payload is addressed must preserve that. A locator that stopped folding in the plaintext hash, or a context minted from something that outlives the payload’s content (a bare row id, a stable path), would let one key seal two different plaintexts under one nonce.
Trait Implementations§
Source§impl Clone for NoncePolicy
impl Clone for NoncePolicy
Source§fn clone(&self) -> NoncePolicy
fn clone(&self) -> NoncePolicy
1.0.0 · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for NoncePolicy
impl Debug for NoncePolicy
Source§impl PartialEq for NoncePolicy
impl PartialEq for NoncePolicy
impl Eq for NoncePolicy
impl StructuralPartialEq for NoncePolicy
Auto Trait Implementations§
impl Freeze for NoncePolicy
impl RefUnwindSafe for NoncePolicy
impl Send for NoncePolicy
impl Sync for NoncePolicy
impl Unpin for NoncePolicy
impl UnsafeUnpin for NoncePolicy
impl UnwindSafe for NoncePolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.