Skip to main content

KeyPair

Struct KeyPair 

Source
pub struct KeyPair { /* private fields */ }
Expand description

An Ed25519 keypair. The public half is the macula NodeId.

Implementations§

Source§

impl KeyPair

Source

pub fn generate() -> Self

Generate a fresh keypair. Does not grind a puzzle — the resulting identity will be silently rejected by any station that enforces puzzle admission (which is every station in practice). Prefer generate_with_puzzle unless you specifically need an unhardened identity (e.g. a unit test that never dials a real station).

Seeded directly from the OS RNG (rand::rngs::SysRng), unwrapped via rand::rand_core::UnwrapErr to make it panic rather than return a Result on the rare case the OS entropy syscall itself fails — the exact same fail-fast behavior rand 0.8’s OsRng had implicitly, since rand 0.9 split SysRng into a fallible-only type that no longer satisfies SigningKey::generate’s infallible CryptoRng bound on its own. This is the pattern ed25519-dalek 3.0’s own docs use for this exact call (ed25519_dalek::SigningKey::generate’s doc example), not rand::rng()/ThreadRng — a userspace CSPRNG that, since rand 0.9, is explicitly documented as not reseeding on fork(), which would be a real (if narrow) identity-collision risk for a long-lived process that forks after generating a key. Direct OS randomness has no such state to reuse across a fork.

Source

pub fn generate_with_puzzle(difficulty: u32) -> Self

Generate a keypair, grinding fresh candidates until puzzle_valid(pubkey, difficulty) holds. This is the one-time cost described in the module doc — not something to redo per connection.

Source

pub fn generate_with_default_puzzle() -> Self

Source

pub fn from_seed_bytes(seed: [u8; 32]) -> Self

Reconstruct a keypair from its 32-byte seed. Deterministic — the same seed always yields the same public key and, for a given message, the same signature (Ed25519 per RFC 8032 has no signing randomness).

Source

pub fn public_bytes(&self) -> [u8; 32]

The public key — also this identity’s macula NodeId.

Source

pub fn private_bytes(&self) -> [u8; 32]

The 32-byte seed. Matches macula_identity:private/1.

Source

pub fn node_id(&self) -> [u8; 32]

Alias for public_bytes — NodeId == public key, matching macula_identity:node_id/1’s own doc (“Phase 1: NodeId == public key”).

Source

pub fn sign(&self, msg: &[u8]) -> [u8; 64]

Sign msg with this identity. Callers add their own domain separation by prefixing msg (see the frame-signing domains in plans/PLAN_WIRE_PROTOCOL.md §4) — this function itself is raw Ed25519, matching macula_identity:sign/2 exactly.

Source

pub fn puzzle_evidence(&self) -> [u8; 32]

This identity’s puzzle evidence — see puzzle_evidence.

Source

pub fn save(&self, path: impl AsRef<Path>) -> Result<()>

Save this keypair to path, atomically (write to a .tmp sibling, then rename) with 0600 permissions on Unix — matching macula_identity:save/2’s own file format and discipline exactly: a 14-byte magic header ("macula-v2-key\0"), then the 32-byte public key, then the 32-byte private seed.

This raw-file format is a testing/parity convenience, matching the Erlang reference. A real mobile binding should use platform secure storage (Keychain on iOS, Keystore on Android) instead of this file format directly — see plans/PLAN_WIRE_PROTOCOL.md’s puzzle_evidence lifecycle note.

Source

pub fn load(path: impl AsRef<Path>) -> Result<Self, LoadKeyError>

Load a keypair previously written by save. Returns LoadKeyError::PubkeyMismatch if the file’s stored public key doesn’t match the one derived from its stored private key — a corrupted or hand-edited key file would otherwise silently produce a keypair that can never complete a real handshake, which is a much harder failure to diagnose than a load-time error.

Source

pub fn save_to_keystore( &self, store: &dyn KeyStore, ) -> Result<(), KeyStoreError>

Persist this keypair’s seed to store — see crate::keystore’s module doc for why this, not save, is what a real mobile (or otherwise security-sensitive) binding should use.

Source

pub fn load_from_keystore(store: &dyn KeyStore) -> Result<Self, KeyStoreError>

Reconstruct a keypair from a seed previously written by save_to_keystore. Unlike load, there is no separately-stored public key to cross-check — a keystore-backed secret is either exactly the seed this method wrote or KeyStoreError::InvalidSeedLength, and the public key a seed derives is always internally consistent by construction (see from_seed_bytes).

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more