tc_block_padding 0.1.0

PKCS#7, ISO 7816-4, ANSI X9.23, TBC, zero-byte and ISO 10126 padding for block cipher modes.
Documentation
# Changelog

All notable changes to `tc_block_padding` are documented in this file.

## 0.1.0 - 2026-09-29

Initial release.

### Added

- The `BlockCipherPadding` trait: `add_padding` fills the end of a message's
  final block and returns the number of padding bytes, and `pad_count` reports
  how many bytes to remove from a decrypted final block. The trait is usable
  as a trait object.
- `Pkcs7Padding`, `Iso7816d4Padding`, `X923Padding`, `TbcPadding` and
  `ZeroBytePadding`, each stateless with `const fn new`, and
  `Iso10126Padding`, behind the default-off `rand_core` feature, which takes
  the generator it draws its filler from at construction and returns it
  through `into_inner`.
- `PaddingError` with `PositionOutOfRange`, `BlockFull`,
  `UnsupportedBlockSize` and `CorruptPadding`. Every scheme except zero-byte
  padding returns `BlockFull` for a full block, since it must add at least one
  byte; PKCS#7, X9.23 and ISO 10126 return `UnsupportedBlockSize` for blocks of
  256 bytes or more; PKCS#7 and ISO 7816-4 verify the whole padding and X9.23
  and ISO 10126 the count byte, returning `CorruptPadding` on failure.
- Constant-time padding and checks with respect to the block contents,
  following Bouncy Castle's masked, branch-free scans. TBC goes further than
  Bouncy Castle: it derives its filler from the message's last bit without
  branching, and counts its trailing run over the whole block where Bouncy
  Castle stops early.
- `Display` for every scheme, writing `"PKCS7"`, `"ISO7816-4"`, `"X9.23"`,
  `"ISO10126-2"`, `"TBC"` or `"ZeroBytePadding"`.
- Tests of padding and removal at each message length, full blocks,
  out-of-range positions, oversized blocks and corrupt padding for every
  scheme; ISO 10126 tests with a fixed generator and a seeded `StdRng`; a test
  that every public API documents whether it is constant or variable time; and
  doctests for every scheme, including an end-to-end AES-CBC example.

### Compatibility

- Requires Rust 1.85 or later for the default build and uses Rust edition
  2024. The `rand_core` feature follows the minimum Rust version of the
  `rand_core` crate, which is 1.85 for `rand_core` 0.10.1; a later `rand_core`
  release may raise it without a `tc_block_padding` release.
- Has no dependencies by default, and depends on `rand_core` 0.10 only with
  `rand_core`.
- The result of `pad_count`, the count and whether the padding was valid, is
  revealed by design; removing padding before the ciphertext is authenticated
  exposes a padding oracle.
- Zero-byte padding cannot tell padding from a message that ends in `0x00`.
  X9.23 and ISO 10126 check only the count byte, and TBC and zero-byte padding
  cannot detect corruption at all.
- Licensed under MIT OR Apache-2.0; both license texts are included in the
  published package.