pub enum Error {
Show 13 variants
InvalidLength {
what: &'static str,
expected: usize,
got: usize,
},
InvalidPoint,
InvalidIdentityPoint,
InvalidScalar,
InvalidSecretKey,
InvalidHex,
InvalidPrefix {
expected: &'static str,
got: String,
},
InvalidChecksum,
SignerNotInRing,
RingTooSmall,
DuplicateRingMember,
EmptyVote,
EmptyElectionId,
}Expand description
Anything that can go wrong when parsing or processing inputs.
Note that a signature being mathematically invalid is not an error —
it is a false return from crate::verify_vote. An Error is only
produced when the caller hands us malformed bytes (wrong length, not
on the curve, etc.) or asks for an operation that does not make sense
(e.g. signing with a key that is not in the authorised ring).
Variants§
InvalidLength
A byte slice did not have the size required for the type it was supposed to decode into.
Fields
InvalidPoint
32 bytes that do not represent a valid Ristretto255 point.
InvalidIdentityPoint
A Ristretto255 point decoded correctly but is the identity point, which is not a valid public protocol value.
InvalidScalar
32 bytes that do not represent a canonical scalar (mod ℓ).
InvalidSecretKey
A scalar decoded correctly but is not usable as a secret key.
InvalidHex
The hex string handed to a *_from_hex constructor could not be
decoded.
InvalidPrefix
A prefixed string (e.g. pk_…) handed to a *_from_prefixed
constructor was not in the expected three-part shape, or carried
the wrong tag for the type being decoded (e.g. a ki_ value where
a pk_ one was required).
Fields
InvalidChecksum
A prefixed string decoded structurally but its trailing checksum did not match the body — the value was almost certainly mistyped, truncated or corrupted in transit.
SignerNotInRing
sign_vote was called with a secret key whose public key is not
in the supplied authorised ring. Signing would still mathematically
produce something, but it would not verify, so we refuse it early.
RingTooSmall
sign_vote or verify_vote was called with an authorised ring
containing fewer than two members. A ring of one trivially
de-anonymises the signer, so we reject it.
DuplicateRingMember
sign_vote was given a ring containing the same public key twice.
The protocol’s anonymity guarantees assume distinct members, and
we refuse to silently de-duplicate.
EmptyVote
sign_vote was called with a zero-byte ballot. The library has
no opinion on the payload format, but an empty payload is almost
always a caller bug (forgot to serialise the form, fed in the
wrong variable, …) so we surface it instead of silently signing
nothing.
EmptyElectionId
sign_vote was called with a zero-byte election identifier.
Allowing it would defeat the whole point of binding signatures
to an election context, so we refuse early.
Trait Implementations§
impl Eq for Error
Source§impl Error for Error
impl Error for Error
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()