1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
//! Error types for the library.
use thiserror::Error as ThisError;
/// Number of one-time-signature leaves in an XMSS key.
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
pub struct LeavesCount(pub u64);
impl core::fmt::Display for LeavesCount {
fn fmt(&self, f: &mut core::fmt::Formatter<'_>) -> core::fmt::Result {
self.0.fmt(f)
}
}
/// Error type for the library.
#[derive(ThisError, Debug)]
pub enum Error {
/// Classic McEliece error.
#[error("Classic McEliece error: {0}")]
McElieceError(String),
/// ML-DSA error.
#[error("ML-DSA error: {0}")]
MlDsaError(String),
/// ML-KEM error.
#[error("ML-KEM error: {0}")]
MlKemError(String),
/// MAYO error.
#[error("MAYO error: {0}")]
MayoError(String),
/// SLH-DSA error.
#[error("SLH-DSA error: {0}")]
SlhDsaError(String),
/// HQC error.
#[error("HQC error: {0}")]
HqcError(String),
/// FrodoKEM error.
#[error("FrodoKEM error: {0}")]
FrodoError(String),
/// Streamlined NTRU Prime error.
#[error("Streamlined NTRU Prime error: {0}")]
SntrupError(String),
/// XMSS error.
#[error("XMSS error: {0}")]
XmssError(String),
/// The XMSS one-time-signature leaves for this key are exhausted; no further
/// signatures may be produced without revealing the secret key.
#[error("XMSS key exhausted: all {0} one-time-signature leaves have been consumed")]
XmssKeyExhausted(LeavesCount),
/// Bird-of-Prey hybrid signature error.
#[error("Bird-of-Prey error: {0}")]
BirdOfPreyError(String),
/// Deterministic RNG error.
#[error("deterministic RNG error: {0}")]
DetRngError(String),
/// A key or signature belonging to one scheme was passed to a different scheme.
///
/// Byte length is never a reliable discriminator between parameter sets — MAYO-1
/// and MAYO-2 share a 24-byte compact secret key, and FrodoKEM's AES and SHAKE
/// variants have identical lengths in every dimension — so every dispatch method binds
/// to the stored scheme and reports this error on mismatch.
#[error("scheme mismatch: expected '{expected}', got '{actual}'")]
SchemeMismatch {
/// The scheme the operation was invoked on.
expected: String,
/// The scheme the supplied key or signature actually carries.
actual: String,
},
/// Invalid numeric scheme identifier.
#[error("Invalid scheme: {0}")]
InvalidScheme(u8),
/// Invalid string scheme identifier.
#[error("Invalid scheme: {0}")]
InvalidSchemeStr(String),
/// A deprecated scheme, removed for being too weak, was requested (for example, when
/// deserializing data produced by an older version of the library).
#[error(
"scheme '{scheme}' is deprecated and no longer supported (too weak); use '{replacement}' or a stronger parameter set"
)]
DeprecatedScheme {
/// The deprecated scheme identifier that was requested.
scheme: &'static str,
/// The recommended replacement scheme.
replacement: &'static str,
},
/// A scheme reached a dispatcher that does not handle its family.
///
/// The KEM families are dispatched by separate arms, so this indicates the scheme
/// enum and the dispatch tables have drifted apart — a library invariant violation
/// rather than bad caller input. It is an error rather than a panic so that a
/// mis-wiring in a rarely-exercised feature combination degrades to a failed call
/// instead of taking the process down.
#[error("internal dispatch error: {0}")]
SchemeDispatch(&'static str),
/// Seed-derived key generation is not offered for this scheme.
///
/// Seed-derived (and therefore HD-wallet) key generation is only offered where the
/// scheme's deterministic seed is 32 bytes or fewer, so that a single SLIP-0010
/// child key can supply it without expansion. Schemes needing a larger seed —
/// FrodoKEM among them — refuse rather than invent the extra material.
#[error("deterministic key generation is not supported: {0}")]
DeterministicKeygenUnsupported(&'static str),
/// Invalid seed length.
#[error("Invalid seed length: got {0}")]
InvalidSeedLength(usize),
/// Invalid length.
#[error("Invalid length: {0}")]
InvalidLength(usize),
/// ETHFALCON signature error.
#[error("An error occurred with eth-falcon: {0}")]
FnDsaError(String),
/// SLIP-0010 derivation errors.
#[cfg(feature = "hhd")]
#[error("SLIP-0010 error: {0}")]
Slip10Error(#[from] crate::hhd::Slip10Error),
/// Signature scheme error.
#[cfg(feature = "hhd")]
#[error("Signature scheme error: {0}")]
SignatureSchemeError(#[from] crate::hhd::SignatureSchemeError),
/// Key error.
#[cfg(feature = "hhd")]
#[error("Key error: {0}")]
KeyError(#[from] crate::hhd::KeyError),
/// Mnemonic error.
#[cfg(feature = "hhd")]
#[error("Mnemonic error: {0}")]
MnemonicError(#[from] crate::hhd::MnemonicError),
/// BIP-85 error.
#[cfg(feature = "hhd")]
#[error("BIP-85 error: {0}")]
Bip85Error(#[from] crate::hhd::Bip85Error),
/// HD wallet error.
#[cfg(feature = "hhd")]
#[error("HD wallet error: {0}")]
WalletError(#[from] crate::hhd::WalletError),
}
/// Result type for the library.
pub type Result<T> = std::result::Result<T, Error>;