Skip to main content

NoncePolicy

Enum NoncePolicy 

Source
pub enum NoncePolicy {
    RandomStored,
    DerivedFromContext {
        context: Vec<u8>,
    },
}
Expand description

Where a sealed payload’s base nonce comes from — the choice every caller that seals or opens one states outright.

§Invariant: a derived base must be unique per plaintext

XChaCha20-Poly1305 offers no margin for nonce reuse. Two different plaintexts sealed under one key and one nonce leak their XOR and forfeit authentication, and that failure is silent — everything still encrypts, decrypts, and round-trips. Self::DerivedFromContext is therefore only safe while its context differs whenever the plaintext does, which is why the context is part of the policy rather than something a caller can forget to pass, and why the choice is a named variant rather than a flag or a default.

Variants§

§

RandomStored

A base nonce drawn at random and written into the header, ahead of the chunks. Safe however the payload is addressed, at the cost of 24 stored bytes and a base only the stored header carries.

§

DerivedFromContext

A base nonce derived by HKDF from the sealing key and context, stored nowhere, so the same payload always seals to the same bytes and a reader that knows the context can open any chunk without reading a base first.

context must differ whenever the plaintext does. It holds for a blob because the context is minted from the blob’s semantic key, which for an opaque blob is {namespace}/opaque/{locator_hash}, and the locator hash covers the plaintext hash — so two different plaintexts cannot share a context without a SHA-256 collision. Re-sealing identical bytes under an identical context reproduces an identical base, which is fine: it reproduces identical ciphertext, not a second message under one nonce.

Any change to how a payload is addressed must preserve that. A locator that stopped folding in the plaintext hash, or a context minted from something that outlives the payload’s content (a bare row id, a stable path), would let one key seal two different plaintexts under one nonce.

Fields

§context: Vec<u8>

Trait Implementations§

Source§

impl Clone for NoncePolicy

Source§

fn clone(&self) -> NoncePolicy

Returns a duplicate of the value. Read more
1.0.0 · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for NoncePolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl PartialEq for NoncePolicy

Source§

fn eq(&self, other: &NoncePolicy) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl Eq for NoncePolicy

Source§

impl StructuralPartialEq for NoncePolicy

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,