ic_core/lib.rs
1//! # ic-core — foundational types for IronCrypto
2//!
3//! Zero-dependency, `no_std`-first building blocks shared by every other crate in
4//! the workspace:
5//!
6//! * [`Error`] / [`Result`] — a single, exhaustive, non-panicking error domain.
7//! * [`ct`] — constant-time comparison and selection primitives.
8//! * [`Zeroizing`] — scope-bound secret erasure with a compiler-fence barrier.
9//! * [`traits`] — the object-safe algorithm contracts (`Digest`, `Mac`, `Aead`, …).
10//! * [`codec`] — hex / base64 encoding used by the agent-facing surfaces.
11//! * [`cpu`] — CPU feature detection, shared by the backends and the ontology.
12//! * [`entropy`] — OS entropy acquisition (SP 800-90B conditioned input).
13//!
14//! Every public function in this crate is total: it returns `Result` rather than
15//! panicking, so an autonomous agent can drive the library without tripping an
16//! abort in a sandbox.
17#![cfg_attr(not(feature = "std"), no_std)]
18// Unsafe is confined to the two modules that cannot avoid it, each of which
19// carries an explicit allowance and says why. Anywhere else in this crate it is
20// a compile error rather than a review comment.
21#![deny(unsafe_code)]
22#![forbid(unsafe_op_in_unsafe_fn)]
23#![deny(missing_docs)]
24#![warn(clippy::all)]
25
26pub mod codec;
27pub mod cpu;
28pub mod ct;
29// The operating system's entropy source is a syscall; there is no safe way to
30// ask for it.
31#[allow(unsafe_code)]
32pub mod entropy;
33pub mod sig;
34pub mod traits;
35
36mod error;
37// Zeroing must survive the optimiser, which means volatile writes, which are
38// unsafe by construction. A safe loop here would be deleted as dead stores and
39// the secret would stay in memory -- the exact failure this module exists to
40// prevent.
41#[allow(unsafe_code)]
42mod zeroize;
43
44pub use error::{Error, ErrorKind, Result};
45pub use zeroize::{Zeroize, Zeroizing};
46
47/// The semantic version of the IronCrypto core contract.
48pub const CORE_VERSION: &str = env!("CARGO_PKG_VERSION");