pub struct WalEncryptionKey { /* private fields */ }Expand description
AES-256-GCM key with a random per-lifetime epoch for nonce disambiguation.
The epoch is generated randomly at construction time. Each WAL lifetime (process start, snapshot restore, segment creation) gets a fresh epoch, ensuring that nonces are never reused even if LSNs restart from 1.
Implementations§
Source§impl WalEncryptionKey
impl WalEncryptionKey
Sourcepub fn from_bytes(key: &[u8; 32]) -> Result<Self>
pub fn from_bytes(key: &[u8; 32]) -> Result<Self>
Create from a 32-byte key with a fresh random epoch.
Returns an error if the OS RNG (getrandom) is unavailable. Without
a fresh epoch we cannot guarantee nonce uniqueness across WAL
lifetimes, so panicking would silently risk nonce reuse on RNG
failure — better to surface it.
The key material is moved into a SecureKey, which mlocks it against
swap and zeroizes it on drop.
Sourcepub fn with_epoch(key: &[u8; 32], epoch: [u8; 4]) -> Self
pub fn with_epoch(key: &[u8; 32], epoch: [u8; 4]) -> Self
Create from a 32-byte key with a caller-supplied epoch.
Use this when reopening a WAL segment whose epoch was read from the on-disk preamble, so that the nonce is reconstructed identically to the nonce used at encryption time.
Sourcepub fn with_fresh_epoch(&self) -> Result<Self>
pub fn with_fresh_epoch(&self) -> Result<Self>
Produce a new key instance with the same key material but a fresh random epoch. Used when rolling to a new WAL segment — each segment gets its own epoch so the per-segment nonce space is independent.
The mlocked key allocation is shared with self via Arc; only the
epoch differs, so no additional secret copy is made.
Sourcepub fn from_file(path: &Path) -> Result<Self>
pub fn from_file(path: &Path) -> Result<Self>
Load key from a file (must contain exactly 32 bytes).
Before reading, the file is checked for:
- No symlinks (TOCTOU / path-traversal risk).
- Regular file (not a device, FIFO, or directory).
- Unix: no group or world access bits (
mode & 0o077 == 0). - Unix: file owner matches the current process UID.
Sourcepub fn encrypt(
&self,
lsn: u64,
header_bytes: &[u8; 54],
plaintext: &[u8],
) -> Result<Vec<u8>>
pub fn encrypt( &self, lsn: u64, header_bytes: &[u8; 54], plaintext: &[u8], ) -> Result<Vec<u8>>
Encrypt a payload. Returns ciphertext + auth_tag (16 bytes appended).
lsn: used to derive a deterministic nonceheader_bytes: used as AAD (additional authenticated data)plaintext: the payload to encrypt
Sourcepub fn encrypt_aad(
&self,
lsn: u64,
aad: &[u8],
plaintext: &[u8],
) -> Result<Vec<u8>>
pub fn encrypt_aad( &self, lsn: u64, aad: &[u8], plaintext: &[u8], ) -> Result<Vec<u8>>
Encrypt with a caller-provided AAD slice (may be longer than HEADER_SIZE, e.g. preamble bytes prepended to the header).
Sourcepub fn decrypt(
&self,
epoch: &[u8; 4],
lsn: u64,
header_bytes: &[u8; 54],
ciphertext: &[u8],
) -> Result<Vec<u8>>
pub fn decrypt( &self, epoch: &[u8; 4], lsn: u64, header_bytes: &[u8; 54], ciphertext: &[u8], ) -> Result<Vec<u8>>
Decrypt a payload. Input is ciphertext + auth_tag (16 bytes at end).
epoch: must be the epoch that was used during encryption, read from the on-disk segment preamble — notself.epoch, which reflects the current in-memory lifetime and may differ after a restart.lsn: must match the LSN used during encryptionheader_bytes: must match the header used during encryption (AAD)ciphertext: the encrypted payload (includes 16-byte auth tag)
Trait Implementations§
Source§impl Clone for WalEncryptionKey
impl Clone for WalEncryptionKey
Source§fn clone(&self) -> WalEncryptionKey
fn clone(&self) -> WalEncryptionKey
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreAuto Trait Implementations§
impl Freeze for WalEncryptionKey
impl RefUnwindSafe for WalEncryptionKey
impl Send for WalEncryptionKey
impl Sync for WalEncryptionKey
impl Unpin for WalEncryptionKey
impl UnsafeUnpin for WalEncryptionKey
impl UnwindSafe for WalEncryptionKey
Blanket Implementations§
Source§impl<T> ArchivePointee for T
impl<T> ArchivePointee for T
Source§type ArchivedMetadata = ()
type ArchivedMetadata = ()
Source§fn pointer_metadata(
_: &<T as ArchivePointee>::ArchivedMetadata,
) -> <T as Pointee>::Metadata
fn pointer_metadata( _: &<T as ArchivePointee>::ArchivedMetadata, ) -> <T as Pointee>::Metadata
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> LayoutRaw for T
impl<T> LayoutRaw for T
Source§fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>
fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>
Source§impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
Source§unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool
unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool
Source§fn resolve_niched(out: Place<NichedOption<T, N1>>)
fn resolve_niched(out: Place<NichedOption<T, N1>>)
out indicating that a T is niched.impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<SS, SP> SupersetOf<SS> for SPwhere
SS: SubsetOf<SP>,
impl<SS, SP> SupersetOf<SS> for SPwhere
SS: SubsetOf<SP>,
Source§fn to_subset(&self) -> Option<SS>
fn to_subset(&self) -> Option<SS>
self from the equivalent element of its
superset. Read moreSource§fn is_in_subset(&self) -> bool
fn is_in_subset(&self) -> bool
self is actually part of its subset T (and can be converted to it).Source§fn to_subset_unchecked(&self) -> SS
fn to_subset_unchecked(&self) -> SS
self.to_subset but without any property checks. Always succeeds.Source§fn from_subset(element: &SS) -> SP
fn from_subset(element: &SS) -> SP
self to the equivalent element of its superset.