kyn_vdf/error.rs
1//! Error types for VDF verification and Class Group arithmetic.
2//!
3//! All public functions in `kyn-vdf` return [`KynVdfError`] on failure rather than
4//! panicking, ensuring the library is safe for use in WASM, `no_std`, and adversarial
5//! input environments.
6
7use thiserror::Error;
8
9/// Domain-specific errors returned during Class Group operations and Wesolowski VDF verification.
10///
11/// Every variant carries a human-readable message describing the exact failure point.
12/// Callers should treat [`KynVdfError::VerificationFailed`] as a clean "proof rejected"
13/// signal, and all other variants as malformed or invalid inputs.
14#[derive(Debug, Error, Clone, PartialEq, Eq)]
15pub enum KynVdfError {
16 /// The proof byte slice is shorter than the required minimum.
17 ///
18 /// Chia-format proofs must be exactly 200 bytes (`y || π`, each 100 bytes).
19 #[error("Invalid proof length: expected {expected} bytes, got {actual}")]
20 InvalidProofLength { expected: usize, actual: usize },
21
22 /// The challenge seed passed to [`crate::create_discriminant`] was empty or invalid.
23 ///
24 /// Seeds must be non-empty byte slices. Longer seeds (≥32 bytes) are recommended
25 /// for security.
26 #[error("Invalid seed: {0}")]
27 InvalidSeed(String),
28
29 /// The discriminant bit-size is zero, not a multiple of 8, or otherwise unsupported.
30 ///
31 /// Valid values are multiples of 8 (e.g. `512`, `1024`, `2048`).
32 #[error("Invalid discriminant size: {0} bits (must be a non-zero multiple of 8)")]
33 InvalidDiscriminantSize(usize),
34
35 /// Discriminant generation or prime hashing failed unexpectedly.
36 #[error("Failed to generate discriminant: {0}")]
37 DiscriminantError(String),
38
39 /// A quadratic form could not be serialized or deserialized from the Chia BQFC format.
40 ///
41 /// This typically means the proof bytes are corrupted, truncated, or were produced
42 /// by an incompatible implementation.
43 #[error("Quadratic form (de)serialization failed: {0}")]
44 FormDeserializationError(String),
45
46 /// The deserialized or constructed quadratic form does not satisfy the fundamental
47 /// discriminant identity $b^2 - 4ac = D$.
48 ///
49 /// Indicates a corrupted proof or an incorrect discriminant was used for verification.
50 #[error("Invalid quadratic form: discriminant identity b² - 4ac = D does not hold")]
51 InvalidDiscriminantIdentity,
52
53 /// An extended GCD, modular inverse, or other class group arithmetic step failed.
54 #[error("Class group arithmetic error: {0}")]
55 ArithmeticError(String),
56
57 /// The iteration count passed to verify is zero.
58 ///
59 /// A VDF with zero iterations is undefined — the minimum meaningful value is 1.
60 #[error("Invalid iteration count: {0} (must be ≥ 1)")]
61 InvalidIterations(u64),
62
63 /// Verification completed without error but the proof equation does not hold:
64 /// `π^B · x^r ≠ y`.
65 ///
66 /// This is the expected error when a valid but incorrect proof is presented.
67 #[error("VDF proof rejected: π^B · x^r ≠ y (proof does not verify)")]
68 VerificationFailed,
69}