1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
//! # ic-core — foundational types for IronCrypto
//!
//! Zero-dependency, `no_std`-first building blocks shared by every other crate in
//! the workspace:
//!
//! * [`Error`] / [`Result`] — a single, exhaustive, non-panicking error domain.
//! * [`ct`] — constant-time comparison and selection primitives.
//! * [`Zeroizing`] — scope-bound secret erasure with a compiler-fence barrier.
//! * [`traits`] — the object-safe algorithm contracts (`Digest`, `Mac`, `Aead`, …).
//! * [`codec`] — hex / base64 encoding used by the agent-facing surfaces.
//! * [`cpu`] — CPU feature detection, shared by the backends and the ontology.
//! * [`entropy`] — OS entropy acquisition (SP 800-90B conditioned input).
//!
//! Every public function in this crate is total: it returns `Result` rather than
//! panicking, so an autonomous agent can drive the library without tripping an
//! abort in a sandbox.
// Unsafe is confined to the two modules that cannot avoid it, each of which
// carries an explicit allowance and says why. Anywhere else in this crate it is
// a compile error rather than a review comment.
// The operating system's entropy source is a syscall; there is no safe way to
// ask for it.
// Zeroing must survive the optimiser, which means volatile writes, which are
// unsafe by construction. A safe loop here would be deleted as dead stores and
// the secret would stay in memory -- the exact failure this module exists to
// prevent.
pub use ;
pub use ;
/// The semantic version of the IronCrypto core contract.
pub const CORE_VERSION: &str = env!;