ic_core/lib.rs
1//! # ic-core — foundational types for IronCrypto
2//!
3//! Zero-dependency, `no_std`-first building blocks shared by every other crate in
4//! the workspace:
5//!
6//! * [`Error`] / [`Result`] — a single, exhaustive, non-panicking error domain.
7//! * [`ct`] — constant-time comparison and selection primitives.
8//! * [`Zeroizing`] — scope-bound secret erasure with a compiler-fence barrier.
9//! * [`traits`] — the object-safe algorithm contracts (`Digest`, `Mac`, `Aead`, …).
10//! * [`codec`] — hex / base64 encoding used by the agent-facing surfaces.
11//! * [`cpu`] — CPU feature detection, shared by the backends and the ontology.
12//! * [`entropy`] — OS entropy acquisition (SP 800-90B conditioned input).
13//!
14//! Every public function in this crate is total: it returns `Result` rather than
15//! panicking, so an autonomous agent can drive the library without tripping an
16//! abort in a sandbox.
17#![cfg_attr(not(feature = "std"), no_std)]
18// Unsafe is confined to the two modules that cannot avoid it, each of which
19// carries an explicit allowance and says why. Anywhere else in this crate it is
20// a compile error rather than a review comment.
21#![deny(unsafe_code)]
22#![forbid(unsafe_op_in_unsafe_fn)]
23#![deny(missing_docs)]
24#![warn(clippy::all)]
25
26pub mod codec;
27pub mod cpu;
28pub mod ct;
29// The operating system's entropy source is a syscall; there is no safe way to
30// ask for it.
31#[allow(unsafe_code)]
32pub mod entropy;
33pub mod traits;
34
35mod error;
36// Zeroing must survive the optimiser, which means volatile writes, which are
37// unsafe by construction. A safe loop here would be deleted as dead stores and
38// the secret would stay in memory -- the exact failure this module exists to
39// prevent.
40#[allow(unsafe_code)]
41mod zeroize;
42
43pub use error::{Error, ErrorKind, Result};
44pub use zeroize::{Zeroize, Zeroizing};
45
46/// The semantic version of the IronCrypto core contract.
47pub const CORE_VERSION: &str = env!("CARGO_PKG_VERSION");