Skip to main content

XChaCha20Poly1305Cipher

Struct XChaCha20Poly1305Cipher 

Source
pub struct XChaCha20Poly1305Cipher { /* private fields */ }
Expand description

A vault-keyed XChaCha20-Poly1305 PayloadCipher with a one-key rotation window.

The cipher holds a current key used for all seals, plus an optional previous key that open can still select during a rotation window. The on-disk layout key_id(1) || nonce(24) || ciphertext || tag(16) lets open pick the right key by its leading byte; an unrecognized key-id fails closed with CipherError::UnknownKeyId.

Key rotation is otherwise drain-based: see book vault documentation for the operational policy. See zeph_durable::PayloadCipher for the full contract.

Implementations§

Source§

impl XChaCha20Poly1305Cipher

Source

pub fn new(key_id: u8, key: [u8; 32]) -> Self

Construct a cipher with a single current key identified by key_id.

The key array is zeroized once copied into the AEAD state.

Source

pub fn from_vault_bytes(key_id: u8, key: &[u8]) -> Result<Self, CipherKeyError>

Construct a cipher from vault-resolved key bytes, validating the length.

§Errors

Returns CipherKeyError::InvalidKeyLength when key is not exactly 32 bytes.

§Examples
use zeph_core::durable::XChaCha20Poly1305Cipher;

assert!(XChaCha20Poly1305Cipher::from_vault_bytes(0, &[0u8; 32]).is_ok());
assert!(XChaCha20Poly1305Cipher::from_vault_bytes(0, b"too short").is_err());
Source

pub fn from_vault_b64(b64_key: &str) -> Result<Self, CipherKeyError>

Construct the current cipher from the base64-encoded ZEPH_DURABLE_KEY vault value.

This is the single decode path shared by the agent-loop engine and the zeph durable --reveal CLI; both use DURABLE_KEY_ID so a sealed blob round-trips. The key is generated in this same encoding by generate_durable_key_b64.

§Errors

Returns CipherKeyError::MalformedEncoding when b64_key is not valid base64, or CipherKeyError::InvalidKeyLength when the decoded key is not exactly 32 bytes.

§Examples
use zeph_core::durable::{XChaCha20Poly1305Cipher, generate_durable_key_b64};

let key = generate_durable_key_b64();
assert!(XChaCha20Poly1305Cipher::from_vault_b64(&key).is_ok());
assert!(XChaCha20Poly1305Cipher::from_vault_b64("not base64!").is_err());
Source

pub fn from_vault_b64_with_id( key_id: u8, b64_key: &str, ) -> Result<Self, CipherKeyError>

Construct the current cipher from a base64-encoded vault value with an explicit key_id.

Like from_vault_b64 but for an operator-controlled key_id ([durable].key_id, zeph durable rotate-key, #6447) rather than the hardcoded DURABLE_KEY_ID default — the current cipher’s decode path used by load_durable_cipher once a rotation has bumped the config’s key_id.

§Errors

Returns CipherKeyError::MalformedEncoding when b64_key is not valid base64, or CipherKeyError::InvalidKeyLength when the decoded key is not exactly 32 bytes.

§Examples
use zeph_core::durable::{XChaCha20Poly1305Cipher, generate_durable_key_b64};

let key = generate_durable_key_b64();
assert!(XChaCha20Poly1305Cipher::from_vault_b64_with_id(1, &key).is_ok());
Source

pub fn with_previous(self, key_id: u8, key: [u8; 32]) -> Self

Register a previous key for the rotation window.

open will select this key for blobs whose leading key-id byte matches key_id; seal always uses the current key. Use this so in-flight executions sealed under the old key can still be replayed after a rotation.

Trait Implementations§

Source§

impl PayloadCipher for XChaCha20Poly1305Cipher

Source§

fn seal( &self, plaintext: &[u8], aad: &PayloadAad, ) -> Result<Vec<u8>, CipherError>

Seal plaintext under aad, returning the stored blob (key_id || nonce || ciphertext || tag). Read more
Source§

fn open(&self, sealed: &[u8], aad: &PayloadAad) -> Result<Vec<u8>, CipherError>

Open a blob previously produced by seal, verifying aad. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more