diff --git a/Cargo.toml b/Cargo.toml index 739d4585..07bb3848 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -21,7 +21,7 @@ rust-argon2 = { version = "3.0", default-features = false } name = "devolutions-crypto" version.workspace = true authors = ["Mathieu Morrissette ", "Sebastien Duquette "] -edition = "2021" +edition = "2024" readme = "README_RUST.md" license = "MIT OR Apache-2.0" homepage = "https://github.com/Devolutions/devolutions-crypto" diff --git a/cli/Cargo.toml b/cli/Cargo.toml index 0f105c5c..d375cfc0 100644 --- a/cli/Cargo.toml +++ b/cli/Cargo.toml @@ -2,7 +2,7 @@ name = "devolutions-crypto-cli" version.workspace = true authors = ["Devolutions "] -edition = "2018" +edition = "2024" # See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html diff --git a/cli/src/main.rs b/cli/src/main.rs index 4d8c9d6b..b21470a1 100644 --- a/cli/src/main.rs +++ b/cli/src/main.rs @@ -1,6 +1,6 @@ use clap::{Parser, Subcommand}; -use devolutions_crypto::utils::{base64_decode, base64_encode}; use devolutions_crypto::DEFAULT_PBKDF2_ITERATIONS; +use devolutions_crypto::utils::{base64_decode, base64_encode}; use std::{borrow::Borrow, convert::TryFrom}; /// Gives a CLI interface to Devolutions Crypto Library @@ -236,7 +236,7 @@ fn main() { } fn generate_key() { - use devolutions_crypto::key::{generate_secret_key, KeyVersion}; + use devolutions_crypto::key::{KeyVersion, generate_secret_key}; let key: Vec = generate_secret_key(KeyVersion::Latest).into(); println!("{}", base64_encode(&key)); diff --git a/ffi/Cargo.toml b/ffi/Cargo.toml index fdd1abb4..3bd61fa8 100644 --- a/ffi/Cargo.toml +++ b/ffi/Cargo.toml @@ -1,7 +1,7 @@ [package] name = "devolutions-crypto-ffi" version.workspace = true -edition = "2021" +edition = "2024" [lib] name = "devolutions_crypto_ffi" diff --git a/ffi/src/lib.rs b/ffi/src/lib.rs index 8f88765d..d74048b9 100644 --- a/ffi/src/lib.rs +++ b/ffi/src/lib.rs @@ -8,32 +8,32 @@ //! The Size functions must be called to get the required length of the returned array before //! calling it. +use devolutions_crypto::Argon2Parameters; +use devolutions_crypto::DataType; +use devolutions_crypto::Error; use devolutions_crypto::online_ciphertext::OnlineCiphertextDecryptor; use devolutions_crypto::online_ciphertext::OnlineCiphertextEncryptor; use devolutions_crypto::online_ciphertext::OnlineCiphertextHeader; use devolutions_crypto::utils; -use devolutions_crypto::Argon2Parameters; -use devolutions_crypto::DataType; -use devolutions_crypto::Error; -use base64::{engine::general_purpose, Engine as _}; +use base64::{Engine as _, engine::general_purpose}; +use devolutions_crypto::KeyDerivationVersion; +use devolutions_crypto::OnlineCiphertextVersion; use devolutions_crypto::ciphertext::{ - encrypt_asymmetric_with_aad, encrypt_with_aad, Ciphertext, CiphertextVersion, + Ciphertext, CiphertextVersion, encrypt_asymmetric_with_aad, encrypt_with_aad, }; -use devolutions_crypto::derive_encrypt::{encrypt_with_password_and_aad, KdfEncryptedData}; +use devolutions_crypto::derive_encrypt::{KdfEncryptedData, encrypt_with_password_and_aad}; use devolutions_crypto::key::{ - generate_keypair, generate_secret_key, mix_key_exchange, KeyVersion, PrivateKey, PublicKey, + KeyVersion, PrivateKey, PublicKey, generate_keypair, generate_secret_key, mix_key_exchange, }; use devolutions_crypto::key_derivation::{Argon2, DerivationParameters, Pbkdf2}; use devolutions_crypto::password_hash::{ - hash_password, hash_password_with_parameters, PasswordHash, PasswordHashVersion, + PasswordHash, PasswordHashVersion, hash_password, hash_password_with_parameters, }; use devolutions_crypto::secret_sharing::{ - generate_shared_key, join_shares, SecretSharingVersion, Share, + SecretSharingVersion, Share, generate_shared_key, join_shares, }; -use devolutions_crypto::KeyDerivationVersion; -use devolutions_crypto::OnlineCiphertextVersion; use devolutions_crypto::{ signature, signature::{Signature, SignatureVersion}, @@ -77,7 +77,7 @@ pub const PASSWORD_HASH_V2: u16 = 2; /// appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn Encrypt( data: *const u8, data_length: usize, @@ -89,37 +89,39 @@ pub unsafe extern "C" fn Encrypt( result_length: usize, version: u16, ) -> i64 { - if data.is_null() || key.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if data.is_null() || key.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + }; - if result_length != EncryptSize(data_length, version) as usize { - return Error::InvalidOutputLength.error_code(); - } + if result_length != EncryptSize(data_length, version) as usize { + return Error::InvalidOutputLength.error_code(); + } - let aad = if aad.is_null() { - &[] - } else { - slice::from_raw_parts(aad, aad_length) - }; + let aad = if aad.is_null() { + &[] + } else { + slice::from_raw_parts(aad, aad_length) + }; - let data = slice::from_raw_parts(data, data_length); - let key = slice::from_raw_parts(key, key_length); - let result = slice::from_raw_parts_mut(result, result_length); + let data = slice::from_raw_parts(data, data_length); + let key = slice::from_raw_parts(key, key_length); + let result = slice::from_raw_parts_mut(result, result_length); - let version = match CiphertextVersion::try_from(version) { - Ok(v) => v, - Err(_) => return Error::UnknownVersion.error_code(), - }; + let version = match CiphertextVersion::try_from(version) { + Ok(v) => v, + Err(_) => return Error::UnknownVersion.error_code(), + }; - match encrypt_with_aad(data, key, aad, version) { - Ok(res) => { - let res: Zeroizing> = Zeroizing::new(res.into()); - let length = res.len(); - result[0..length].copy_from_slice(&res); - length as i64 + match encrypt_with_aad(data, key, aad, version) { + Ok(res) => { + let res: Zeroizing> = Zeroizing::new(res.into()); + let length = res.len(); + result[0..length].copy_from_slice(&res); + length as i64 + } + Err(e) => e.error_code(), } - Err(e) => e.error_code(), } } @@ -141,7 +143,7 @@ pub unsafe extern "C" fn Encrypt( /// appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn EncryptAsymmetric( data: *const u8, data_length: usize, @@ -153,44 +155,46 @@ pub unsafe extern "C" fn EncryptAsymmetric( result_length: usize, version: u16, ) -> i64 { - if data.is_null() || public_key.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if data.is_null() || public_key.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + }; - if result_length != EncryptAsymmetricSize(data_length, version) as usize { - return Error::InvalidOutputLength.error_code(); - } + if result_length != EncryptAsymmetricSize(data_length, version) as usize { + return Error::InvalidOutputLength.error_code(); + } - let aad = if aad.is_null() { - &[] - } else { - slice::from_raw_parts(aad, aad_length) - }; + let aad = if aad.is_null() { + &[] + } else { + slice::from_raw_parts(aad, aad_length) + }; - let data = slice::from_raw_parts(data, data_length); - let public_key = PublicKey::try_from(slice::from_raw_parts(public_key, public_key_length)); + let data = slice::from_raw_parts(data, data_length); + let public_key = PublicKey::try_from(slice::from_raw_parts(public_key, public_key_length)); - match public_key { - Ok(public_key) => { - let result = slice::from_raw_parts_mut(result, result_length); + match public_key { + Ok(public_key) => { + let result = slice::from_raw_parts_mut(result, result_length); - let version = match CiphertextVersion::try_from(version) { - Ok(v) => v, - Err(_) => return Error::UnknownVersion.error_code(), - }; + let version = match CiphertextVersion::try_from(version) { + Ok(v) => v, + Err(_) => return Error::UnknownVersion.error_code(), + }; - match encrypt_asymmetric_with_aad(data, &public_key, aad, version) { - Ok(res) => { - let res: Zeroizing> = Zeroizing::new(res.into()); - let length = res.len(); + match encrypt_asymmetric_with_aad(data, &public_key, aad, version) { + Ok(res) => { + let res: Zeroizing> = Zeroizing::new(res.into()); + let length = res.len(); - result[0..length].copy_from_slice(&res); - length as i64 + result[0..length].copy_from_slice(&res); + length as i64 + } + Err(e) => e.error_code(), } - Err(e) => e.error_code(), } + Err(e) => e.error_code(), } - Err(e) => e.error_code(), } } @@ -199,7 +203,7 @@ pub unsafe extern "C" fn EncryptAsymmetric( /// * data_length - Length of the plaintext. /// # Returns /// Returns the length of the ciphertext to input as `result_length` in `Encrypt()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn EncryptSize(data_length: usize, version: u16) -> i64 { match version { 1 => { @@ -217,7 +221,7 @@ pub extern "C" fn EncryptSize(data_length: usize, version: u16) -> i64 { /// * data_length - Length of the plaintext. /// # Returns /// Returns the length of the asymmetric ciphertext to input as `result_length` in `EncryptAsymmetric()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn EncryptAsymmetricSize(data_length: usize, version: u16) -> i64 { match version { 0 | 2 => { @@ -234,7 +238,7 @@ pub extern "C" fn EncryptAsymmetricSize(data_length: usize, version: u16) -> i64 /// * ciphertext_version - Version for ciphertext (0 latest, 1 V1, 2 V2). /// # Returns /// Returns the exact output length expected by `DeriveEncryptData()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn DeriveEncryptSize( data_length: usize, key_derivation_version: u16, @@ -281,7 +285,7 @@ pub extern "C" fn DeriveEncryptSize( /// The number of bytes written on success, or a negative DevoCryptoError code on failure. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn DeriveEncryptData( data: *const u8, data_length: usize, @@ -294,57 +298,59 @@ pub unsafe extern "C" fn DeriveEncryptData( key_derivation_version: u16, ciphertext_version: u16, ) -> i64 { - if data.is_null() || password.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - } + unsafe { + if data.is_null() || password.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + } - if result_length - != DeriveEncryptSize(data_length, key_derivation_version, ciphertext_version) as usize - { - return Error::InvalidOutputLength.error_code(); - } + if result_length + != DeriveEncryptSize(data_length, key_derivation_version, ciphertext_version) as usize + { + return Error::InvalidOutputLength.error_code(); + } - let key_derivation_version = match KeyDerivationVersion::try_from(key_derivation_version) { - Ok(v) => v, - Err(_) => return Error::UnknownVersion.error_code(), - }; + let key_derivation_version = match KeyDerivationVersion::try_from(key_derivation_version) { + Ok(v) => v, + Err(_) => return Error::UnknownVersion.error_code(), + }; - let ciphertext_version = match CiphertextVersion::try_from(ciphertext_version) { - Ok(v) => v, - Err(_) => return Error::UnknownVersion.error_code(), - }; + let ciphertext_version = match CiphertextVersion::try_from(ciphertext_version) { + Ok(v) => v, + Err(_) => return Error::UnknownVersion.error_code(), + }; - let aad = if aad.is_null() { - &[] - } else { - slice::from_raw_parts(aad, aad_length) - }; + let aad = if aad.is_null() { + &[] + } else { + slice::from_raw_parts(aad, aad_length) + }; - let data = slice::from_raw_parts(data, data_length); - let password = Zeroizing::new(slice::from_raw_parts(password, password_length).to_vec()); - let result = slice::from_raw_parts_mut(result, result_length); + let data = slice::from_raw_parts(data, data_length); + let password = Zeroizing::new(slice::from_raw_parts(password, password_length).to_vec()); + let result = slice::from_raw_parts_mut(result, result_length); - let derivation_parameters = match key_derivation_version { - KeyDerivationVersion::Latest | KeyDerivationVersion::V2 => Argon2::new().parameters(), - KeyDerivationVersion::V1 => Pbkdf2::new() - .parameters() - .expect("default PKBDF2 parameters shouldn't fail"), - }; + let derivation_parameters = match key_derivation_version { + KeyDerivationVersion::Latest | KeyDerivationVersion::V2 => Argon2::new().parameters(), + KeyDerivationVersion::V1 => Pbkdf2::new() + .parameters() + .expect("default PKBDF2 parameters shouldn't fail"), + }; - match encrypt_with_password_and_aad( - data, - &password, - aad, - derivation_parameters, - ciphertext_version, - ) { - Ok(res) => { - let res: Vec = res.into(); - let length = res.len(); - result[0..length].copy_from_slice(&res); - length as i64 + match encrypt_with_password_and_aad( + data, + &password, + aad, + derivation_parameters, + ciphertext_version, + ) { + Ok(res) => { + let res: Vec = res.into(); + let length = res.len(); + result[0..length].copy_from_slice(&res); + length as i64 + } + Err(e) => e.error_code(), } - Err(e) => e.error_code(), } } @@ -365,7 +371,7 @@ pub unsafe extern "C" fn DeriveEncryptData( /// The number of bytes written on success, or a negative DevoCryptoError code on failure. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn DeriveEncryptDataWithParams( data: *const u8, data_length: usize, @@ -379,51 +385,54 @@ pub unsafe extern "C" fn DeriveEncryptDataWithParams( result_length: usize, ciphertext_version: u16, ) -> i64 { - if data.is_null() || password.is_null() || params.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - } + unsafe { + if data.is_null() || password.is_null() || params.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + } - if result_length - != DeriveEncryptDataWithParamsSize(data_length, params_length, ciphertext_version) as usize - { - return Error::InvalidOutputLength.error_code(); - } + if result_length + != DeriveEncryptDataWithParamsSize(data_length, params_length, ciphertext_version) + as usize + { + return Error::InvalidOutputLength.error_code(); + } - let ciphertext_version = match CiphertextVersion::try_from(ciphertext_version) { - Ok(v) => v, - Err(_) => return Error::UnknownVersion.error_code(), - }; + let ciphertext_version = match CiphertextVersion::try_from(ciphertext_version) { + Ok(v) => v, + Err(_) => return Error::UnknownVersion.error_code(), + }; - let aad = if aad.is_null() { - &[] - } else { - slice::from_raw_parts(aad, aad_length) - }; + let aad = if aad.is_null() { + &[] + } else { + slice::from_raw_parts(aad, aad_length) + }; - let data = slice::from_raw_parts(data, data_length); - let password = Zeroizing::new(slice::from_raw_parts(password, password_length).to_vec()); - let params_raw = slice::from_raw_parts(params, params_length); - let result = slice::from_raw_parts_mut(result, result_length); + let data = slice::from_raw_parts(data, data_length); + let password = Zeroizing::new(slice::from_raw_parts(password, password_length).to_vec()); + let params_raw = slice::from_raw_parts(params, params_length); + let result = slice::from_raw_parts_mut(result, result_length); - let derivation_parameters = match DerivationParameters::try_from(params_raw) { - Ok(p) => p, - Err(e) => return e.error_code(), - }; + let derivation_parameters = match DerivationParameters::try_from(params_raw) { + Ok(p) => p, + Err(e) => return e.error_code(), + }; - match encrypt_with_password_and_aad( - data, - &password, - aad, - derivation_parameters, - ciphertext_version, - ) { - Ok(res) => { - let res: Vec = res.into(); - let length = res.len(); - result[0..length].copy_from_slice(&res); - length as i64 + match encrypt_with_password_and_aad( + data, + &password, + aad, + derivation_parameters, + ciphertext_version, + ) { + Ok(res) => { + let res: Vec = res.into(); + let length = res.len(); + result[0..length].copy_from_slice(&res); + length as i64 + } + Err(e) => e.error_code(), } - Err(e) => e.error_code(), } } @@ -434,7 +443,7 @@ pub unsafe extern "C" fn DeriveEncryptDataWithParams( /// * `ciphertext_version` - Version for ciphertext (0 latest, 1 AES-CBC, 2 XChaCha20). /// # Returns /// Returns the exact output length expected by `DeriveEncryptDataWithParams()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn DeriveEncryptDataWithParamsSize( data_length: usize, params_length: usize, @@ -466,7 +475,7 @@ pub extern "C" fn DeriveEncryptDataWithParamsSize( /// The number of plaintext bytes written on success, or a negative DevoCryptoError code on failure. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn DeriveDecryptData( data: *const u8, data_length: usize, @@ -477,34 +486,36 @@ pub unsafe extern "C" fn DeriveDecryptData( result: *mut u8, result_length: usize, ) -> i64 { - if data.is_null() || password.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - } + unsafe { + if data.is_null() || password.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + } - let aad = if aad.is_null() { - &[] - } else { - slice::from_raw_parts(aad, aad_length) - }; + let aad = if aad.is_null() { + &[] + } else { + slice::from_raw_parts(aad, aad_length) + }; - let data = slice::from_raw_parts(data, data_length); - let password = Zeroizing::new(slice::from_raw_parts(password, password_length).to_vec()); - let result = slice::from_raw_parts_mut(result, result_length); - - match KdfEncryptedData::try_from(data) { - Ok(res) => match res.decrypt_with_password_and_aad(&password, aad) { - Ok(plaintext) => { - if result.len() >= plaintext.len() { - let length = plaintext.len(); - result[0..length].copy_from_slice(&plaintext); - length as i64 - } else { - Error::InvalidOutputLength.error_code() + let data = slice::from_raw_parts(data, data_length); + let password = Zeroizing::new(slice::from_raw_parts(password, password_length).to_vec()); + let result = slice::from_raw_parts_mut(result, result_length); + + match KdfEncryptedData::try_from(data) { + Ok(res) => match res.decrypt_with_password_and_aad(&password, aad) { + Ok(plaintext) => { + if result.len() >= plaintext.len() { + let length = plaintext.len(); + result[0..length].copy_from_slice(&plaintext); + length as i64 + } else { + Error::InvalidOutputLength.error_code() + } } - } + Err(e) => e.error_code(), + }, Err(e) => e.error_code(), - }, - Err(e) => e.error_code(), + } } } @@ -525,7 +536,7 @@ pub unsafe extern "C" fn DeriveDecryptData( /// appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn Decrypt( data: *const u8, data_length: usize, @@ -536,36 +547,38 @@ pub unsafe extern "C" fn Decrypt( result: *mut u8, result_length: usize, ) -> i64 { - if data.is_null() || key.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - }; - - let aad = if aad.is_null() { - &[] - } else { - slice::from_raw_parts(aad, aad_length) - }; + unsafe { + if data.is_null() || key.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + }; - let data = slice::from_raw_parts(data, data_length); - let key = slice::from_raw_parts(key, key_length); - let result = slice::from_raw_parts_mut(result, result_length); + let aad = if aad.is_null() { + &[] + } else { + slice::from_raw_parts(aad, aad_length) + }; - match Ciphertext::try_from(data) { - Ok(res) => match res.decrypt_with_aad(key, aad) { - Ok(res) => { - let res = Zeroizing::new(res); + let data = slice::from_raw_parts(data, data_length); + let key = slice::from_raw_parts(key, key_length); + let result = slice::from_raw_parts_mut(result, result_length); - if result.len() >= res.len() { - let length = res.len(); - result[0..length].copy_from_slice(&res); - length as i64 - } else { - Error::InvalidOutputLength.error_code() + match Ciphertext::try_from(data) { + Ok(res) => match res.decrypt_with_aad(key, aad) { + Ok(res) => { + let res = Zeroizing::new(res); + + if result.len() >= res.len() { + let length = res.len(); + result[0..length].copy_from_slice(&res); + length as i64 + } else { + Error::InvalidOutputLength.error_code() + } } - } + Err(e) => e.error_code(), + }, Err(e) => e.error_code(), - }, - Err(e) => e.error_code(), + } } } @@ -586,7 +599,7 @@ pub unsafe extern "C" fn Decrypt( /// appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn DecryptAsymmetric( data: *const u8, data_length: usize, @@ -597,41 +610,44 @@ pub unsafe extern "C" fn DecryptAsymmetric( result: *mut u8, result_length: usize, ) -> i64 { - if data.is_null() || private_key.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - }; - - let aad = if aad.is_null() { - &[] - } else { - slice::from_raw_parts(aad, aad_length) - }; - - let data = slice::from_raw_parts(data, data_length); - let private_key = PrivateKey::try_from(slice::from_raw_parts(private_key, private_key_length)); + unsafe { + if data.is_null() || private_key.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + }; - match private_key { - Ok(private_key) => { - let result = slice::from_raw_parts_mut(result, result_length); + let aad = if aad.is_null() { + &[] + } else { + slice::from_raw_parts(aad, aad_length) + }; - match Ciphertext::try_from(data) { - Ok(res) => match res.decrypt_asymmetric_with_aad(&private_key, aad) { - Ok(res) => { - let res = Zeroizing::new(res); - if result.len() >= res.len() { - let length = res.len(); - result[0..length].copy_from_slice(&res); - length as i64 - } else { - Error::InvalidOutputLength.error_code() + let data = slice::from_raw_parts(data, data_length); + let private_key = + PrivateKey::try_from(slice::from_raw_parts(private_key, private_key_length)); + + match private_key { + Ok(private_key) => { + let result = slice::from_raw_parts_mut(result, result_length); + + match Ciphertext::try_from(data) { + Ok(res) => match res.decrypt_asymmetric_with_aad(&private_key, aad) { + Ok(res) => { + let res = Zeroizing::new(res); + if result.len() >= res.len() { + let length = res.len(); + result[0..length].copy_from_slice(&res); + length as i64 + } else { + Error::InvalidOutputLength.error_code() + } } - } + Err(e) => e.error_code(), + }, Err(e) => e.error_code(), - }, - Err(e) => e.error_code(), + } } + Err(e) => e.error_code(), } - Err(e) => e.error_code(), } } @@ -649,7 +665,7 @@ pub unsafe extern "C" fn DecryptAsymmetric( /// appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn Sign( data: *const u8, data_length: usize, @@ -659,32 +675,34 @@ pub unsafe extern "C" fn Sign( result_length: usize, version: u16, ) -> i64 { - if data.is_null() || keypair.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if data.is_null() || keypair.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + }; - if result_length != SignSize(version) as usize { - return Error::InvalidOutputLength.error_code(); - }; + if result_length != SignSize(version) as usize { + return Error::InvalidOutputLength.error_code(); + }; - let data = slice::from_raw_parts(data, data_length); - let keypair = slice::from_raw_parts(keypair, keypair_length); - let result = slice::from_raw_parts_mut(result, result_length); + let data = slice::from_raw_parts(data, data_length); + let keypair = slice::from_raw_parts(keypair, keypair_length); + let result = slice::from_raw_parts_mut(result, result_length); - match SigningKeyPair::try_from(keypair) { - Ok(keypair) => { - let version = match SignatureVersion::try_from(version) { - Ok(v) => v, - Err(_) => return Error::UnknownVersion.error_code(), - }; + match SigningKeyPair::try_from(keypair) { + Ok(keypair) => { + let version = match SignatureVersion::try_from(version) { + Ok(v) => v, + Err(_) => return Error::UnknownVersion.error_code(), + }; - let signature: Vec = signature::sign(data, &keypair, version).into(); + let signature: Vec = signature::sign(data, &keypair, version).into(); - result[0..signature.len()].copy_from_slice(&signature); + result[0..signature.len()].copy_from_slice(&signature); - 0 + 0 + } + Err(e) => e.error_code(), } - Err(e) => e.error_code(), } } @@ -701,7 +719,7 @@ pub unsafe extern "C" fn Sign( /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn VerifySignature( data: *const u8, data_length: usize, @@ -710,33 +728,35 @@ pub unsafe extern "C" fn VerifySignature( signature: *const u8, signature_length: usize, ) -> i64 { - if data.is_null() || public_key.is_null() || signature.is_null() { - return Error::NullPointer.error_code(); - }; - - let data = slice::from_raw_parts(data, data_length); - let public_key = slice::from_raw_parts(public_key, public_key_length); - let signature = slice::from_raw_parts(signature, signature_length); + unsafe { + if data.is_null() || public_key.is_null() || signature.is_null() { + return Error::NullPointer.error_code(); + }; - match SigningPublicKey::try_from(public_key) { - Ok(public_key) => match Signature::try_from(signature) { - Ok(signature) => { - if signature.verify(data, &public_key) { - 1 - } else { - 0 + let data = slice::from_raw_parts(data, data_length); + let public_key = slice::from_raw_parts(public_key, public_key_length); + let signature = slice::from_raw_parts(signature, signature_length); + + match SigningPublicKey::try_from(public_key) { + Ok(public_key) => match Signature::try_from(signature) { + Ok(signature) => { + if signature.verify(data, &public_key) { + 1 + } else { + 0 + } } - } + Err(e) => e.error_code(), + }, Err(e) => e.error_code(), - }, - Err(e) => e.error_code(), + } } } /// Get the size of the resulting signature. /// # Returns /// Returns the length of the signature to input as `result_length` in `Sign()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn SignSize(_version: u16) -> i64 { 8 + 64 // header + signature } @@ -754,7 +774,7 @@ pub extern "C" fn SignSize(_version: u16) -> i64 { /// appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn HashPassword( password: *const u8, password_length: usize, @@ -762,30 +782,32 @@ pub unsafe extern "C" fn HashPassword( result_length: usize, version: u16, ) -> i64 { - if password.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if password.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + }; - let version = match PasswordHashVersion::try_from(version) { - Ok(v) => v, - Err(_) => return Error::UnknownVersion.error_code(), - }; + let version = match PasswordHashVersion::try_from(version) { + Ok(v) => v, + Err(_) => return Error::UnknownVersion.error_code(), + }; - if result_length != HashPasswordLength(version as u16) as usize { - return Error::InvalidOutputLength.error_code(); - }; + if result_length != HashPasswordLength(version as u16) as usize { + return Error::InvalidOutputLength.error_code(); + }; - let password = slice::from_raw_parts(password, password_length); - let result = slice::from_raw_parts_mut(result, result_length); + let password = slice::from_raw_parts(password, password_length); + let result = slice::from_raw_parts_mut(result, result_length); - let res: Zeroizing> = match hash_password(password, version) { - Ok(x) => Zeroizing::new(x.into()), - Err(e) => return e.error_code(), - }; + let res: Zeroizing> = match hash_password(password, version) { + Ok(x) => Zeroizing::new(x.into()), + Err(e) => return e.error_code(), + }; - let length = res.len(); - result[0..length].copy_from_slice(&res); - length as i64 + let length = res.len(); + result[0..length].copy_from_slice(&res); + length as i64 + } } /// Returns the length of the hash to input as `result_length` in `HashPassword()`. @@ -793,7 +815,7 @@ pub unsafe extern "C" fn HashPassword( /// * `version` - Version to use. Use 0 for the latest one. /// # Returns /// Returns the length of the hash, or a negative error code for an unknown version. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn HashPasswordLength(version: u16) -> i64 { match version { // V1: PBKDF2 — fixed layout: 4 (iterations) + 32 (salt) + 32 (hash) = 68, plus 8-byte header @@ -821,7 +843,7 @@ pub extern "C" fn HashPasswordLength(version: u16) -> i64 { /// Returns the number of bytes written, or a negative error code. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn HashPasswordWithParams( password: *const u8, password_length: usize, @@ -830,32 +852,34 @@ pub unsafe extern "C" fn HashPasswordWithParams( result: *mut u8, result_length: usize, ) -> i64 { - if password.is_null() || params.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if password.is_null() || params.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + }; - let password = slice::from_raw_parts(password, password_length); - let params_slice = slice::from_raw_parts(params, params_length); - let result = slice::from_raw_parts_mut(result, result_length); + let password = slice::from_raw_parts(password, password_length); + let params_slice = slice::from_raw_parts(params, params_length); + let result = slice::from_raw_parts_mut(result, result_length); - let dp = match DerivationParameters::try_from(params_slice) { - Ok(p) => p, - Err(e) => return e.error_code(), - }; + let dp = match DerivationParameters::try_from(params_slice) { + Ok(p) => p, + Err(e) => return e.error_code(), + }; - let expected_len = HashPasswordWithParamsLength(params, params_length) as usize; - if result_length != expected_len { - return Error::InvalidOutputLength.error_code(); - }; + let expected_len = HashPasswordWithParamsLength(params, params_length) as usize; + if result_length != expected_len { + return Error::InvalidOutputLength.error_code(); + }; - let res: Zeroizing> = match hash_password_with_parameters(password, dp) { - Ok(x) => Zeroizing::new(x.into()), - Err(e) => return e.error_code(), - }; + let res: Zeroizing> = match hash_password_with_parameters(password, dp) { + Ok(x) => Zeroizing::new(x.into()), + Err(e) => return e.error_code(), + }; - let length = res.len(); - result[0..length].copy_from_slice(&res); - length as i64 + let length = res.len(); + result[0..length].copy_from_slice(&res); + length as i64 + } } /// Returns the output buffer size required for `HashPasswordWithParams()`. @@ -866,21 +890,23 @@ pub unsafe extern "C" fn HashPasswordWithParams( /// Returns the required output length, or a negative error code. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn HashPasswordWithParamsLength( params: *const u8, params_length: usize, ) -> i64 { - if params.is_null() { - return Error::NullPointer.error_code(); - }; - let params_slice = slice::from_raw_parts(params, params_length); - let dp = match DerivationParameters::try_from(params_slice) { - Ok(p) => p, - Err(e) => return e.error_code(), - }; - // 8 (PasswordHash header) + 4 (u32 params_len) + params_length + hash_length - (8 + 4 + params_length + dp.output_length()) as i64 + unsafe { + if params.is_null() { + return Error::NullPointer.error_code(); + }; + let params_slice = slice::from_raw_parts(params, params_length); + let dp = match DerivationParameters::try_from(params_slice) { + Ok(p) => p, + Err(e) => return e.error_code(), + }; + // 8 (PasswordHash header) + 4 (u32 params_len) + params_length + hash_length + (8 + 4 + params_length + dp.output_length()) as i64 + } } /// Verify a password against a hash with constant-time equality. @@ -894,29 +920,31 @@ pub unsafe extern "C" fn HashPasswordWithParamsLength( /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn VerifyPassword( password: *const u8, password_length: usize, hash: *const u8, hash_length: usize, ) -> i64 { - if password.is_null() || hash.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if password.is_null() || hash.is_null() { + return Error::NullPointer.error_code(); + }; - let password = slice::from_raw_parts(password, password_length); - let hash = slice::from_raw_parts(hash, hash_length); + let password = slice::from_raw_parts(password, password_length); + let hash = slice::from_raw_parts(hash, hash_length); - match PasswordHash::try_from(hash) { - Ok(res) => { - if res.verify_password(password) { - 1 - } else { - 0 + match PasswordHash::try_from(hash) { + Ok(res) => { + if res.verify_password(password) { + 1 + } else { + 0 + } } + Err(e) => e.error_code(), } - Err(e) => e.error_code(), } } @@ -933,34 +961,36 @@ pub unsafe extern "C" fn VerifyPassword( /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn GenerateKeyPair( private: *mut u8, private_length: usize, public: *mut u8, public_length: usize, ) -> i64 { - if private.is_null() || public.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if private.is_null() || public.is_null() { + return Error::NullPointer.error_code(); + }; - if private_length != GenerateKeyPairSize() as usize - || public_length != GenerateKeyPairSize() as usize - { - return Error::InvalidOutputLength.error_code(); - } + if private_length != GenerateKeyPairSize() as usize + || public_length != GenerateKeyPairSize() as usize + { + return Error::InvalidOutputLength.error_code(); + } - let private = slice::from_raw_parts_mut(private, private_length); - let public = slice::from_raw_parts_mut(public, public_length); + let private = slice::from_raw_parts_mut(private, private_length); + let public = slice::from_raw_parts_mut(public, public_length); - let keypair = generate_keypair(KeyVersion::Latest); + let keypair = generate_keypair(KeyVersion::Latest); - let priv_res: Zeroizing> = Zeroizing::new(keypair.private_key.into()); - let pub_res: Zeroizing> = Zeroizing::new(keypair.public_key.into()); + let priv_res: Zeroizing> = Zeroizing::new(keypair.private_key.into()); + let pub_res: Zeroizing> = Zeroizing::new(keypair.public_key.into()); - public[0..pub_res.len()].copy_from_slice(&pub_res); - private[0..priv_res.len()].copy_from_slice(&priv_res); - 0 + public[0..pub_res.len()].copy_from_slice(&pub_res); + private[0..priv_res.len()].copy_from_slice(&priv_res); + 0 + } } /// Generate a key pair to sign and verify data with. @@ -974,34 +1004,36 @@ pub unsafe extern "C" fn GenerateKeyPair( /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn GenerateSigningKeyPair( keypair: *mut u8, keypair_length: usize, version: u16, ) -> i64 { - if keypair.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if keypair.is_null() { + return Error::NullPointer.error_code(); + }; - if keypair_length != GenerateSigningKeyPairSize(version) as usize { - return Error::InvalidOutputLength.error_code(); - } + if keypair_length != GenerateSigningKeyPairSize(version) as usize { + return Error::InvalidOutputLength.error_code(); + } - let keypair = slice::from_raw_parts_mut(keypair, keypair_length); + let keypair = slice::from_raw_parts_mut(keypair, keypair_length); - let version = match SigningKeyVersion::try_from(version) { - Ok(v) => v, - Err(_) => return Error::UnknownVersion.error_code(), - }; + let version = match SigningKeyVersion::try_from(version) { + Ok(v) => v, + Err(_) => return Error::UnknownVersion.error_code(), + }; - let generated_keypair = signing_key::generate_signing_keypair(version); + let generated_keypair = signing_key::generate_signing_keypair(version); - let keypair_bytes: Zeroizing> = Zeroizing::new(generated_keypair.into()); + let keypair_bytes: Zeroizing> = Zeroizing::new(generated_keypair.into()); - keypair[0..keypair_bytes.len()].copy_from_slice(&keypair_bytes); + keypair[0..keypair_bytes.len()].copy_from_slice(&keypair_bytes); - 0 + 0 + } } /// Get the public part of a keypair used to sign data. @@ -1013,33 +1045,35 @@ pub unsafe extern "C" fn GenerateSigningKeyPair( /// You can get the value by calling `GetSigningPublicKeySize()` beforehand. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn GetSigningPublicKey( keypair: *const u8, keypair_length: usize, public: *mut u8, public_length: usize, ) -> i64 { - if keypair.is_null() || public.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if keypair.is_null() || public.is_null() { + return Error::NullPointer.error_code(); + }; - if public_length != GetSigningPublicKeySize(keypair, keypair_length) as usize { - return Error::InvalidOutputLength.error_code(); - }; + if public_length != GetSigningPublicKeySize(keypair, keypair_length) as usize { + return Error::InvalidOutputLength.error_code(); + }; - let keypair = slice::from_raw_parts(keypair, keypair_length); - let public = slice::from_raw_parts_mut(public, public_length); + let keypair = slice::from_raw_parts(keypair, keypair_length); + let public = slice::from_raw_parts_mut(public, public_length); - let keypair = SigningKeyPair::try_from(keypair); - match keypair { - Ok(keypair) => { - let public_key: Vec = keypair.get_public_key().into(); - public[..public_key.len()].copy_from_slice(&public_key); + let keypair = SigningKeyPair::try_from(keypair); + match keypair { + Ok(keypair) => { + let public_key: Vec = keypair.get_public_key().into(); + public[..public_key.len()].copy_from_slice(&public_key); - 0 + 0 + } + Err(e) => e.error_code(), } - Err(e) => e.error_code(), } } @@ -1047,7 +1081,7 @@ pub unsafe extern "C" fn GetSigningPublicKey( /// # Returns /// Returns the length of the keys to input as `private_length` /// and `public_length` in `GenerateKeyPair()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn GenerateKeyPairSize() -> i64 { 8 + 32 // header + key length } @@ -1062,29 +1096,31 @@ pub extern "C" fn GenerateKeyPairSize() -> i64 { /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn GenerateSecretKey(result: *mut u8, result_length: usize) -> i64 { - if result.is_null() { - return Error::NullPointer.error_code(); - } + unsafe { + if result.is_null() { + return Error::NullPointer.error_code(); + } - if result_length != GenerateSecretKeySize() as usize { - return Error::InvalidOutputLength.error_code(); - } + if result_length != GenerateSecretKeySize() as usize { + return Error::InvalidOutputLength.error_code(); + } - let result = slice::from_raw_parts_mut(result, result_length); + let result = slice::from_raw_parts_mut(result, result_length); - let key = generate_secret_key(KeyVersion::Latest); - let key_bytes: Zeroizing> = Zeroizing::new(key.into()); + let key = generate_secret_key(KeyVersion::Latest); + let key_bytes: Zeroizing> = Zeroizing::new(key.into()); - result[0..key_bytes.len()].copy_from_slice(&key_bytes); - 0 + result[0..key_bytes.len()].copy_from_slice(&key_bytes); + 0 + } } /// Get the size of a serialized secret key. /// # Returns /// Returns the length of the buffer to pass as `result_length` in `GenerateSecretKey()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn GenerateSecretKeySize() -> i64 { 8 + 32 // header + key length } @@ -1093,7 +1129,7 @@ pub extern "C" fn GenerateSecretKeySize() -> i64 { /// # Returns /// Returns the length of the keypair to input as `keypair_length` /// in `GenerateSigningKeyPair()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn GenerateSigningKeyPairSize(_version: u16) -> i64 { 8 + 64 // header + keypair length } @@ -1102,7 +1138,7 @@ pub extern "C" fn GenerateSigningKeyPairSize(_version: u16) -> i64 { /// # Returns /// Returns the length of the public key to input as `public_length` /// in `GetSigningPublicKey()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn GetSigningPublicKeySize(_keypair: *const u8, _keypair_length: usize) -> i64 { 8 + 32 // header + public key length } @@ -1120,7 +1156,7 @@ pub extern "C" fn GetSigningPublicKeySize(_keypair: *const u8, _keypair_length: /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn MixKeyExchange( private: *const u8, private_size: usize, @@ -1129,37 +1165,39 @@ pub unsafe extern "C" fn MixKeyExchange( shared: *mut u8, shared_size: usize, ) -> i64 { - if private.is_null() || public.is_null() || shared.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if private.is_null() || public.is_null() || shared.is_null() { + return Error::NullPointer.error_code(); + }; - if shared_size != MixKeyExchangeSize() as usize { - return Error::InvalidOutputLength.error_code(); - } + if shared_size != MixKeyExchangeSize() as usize { + return Error::InvalidOutputLength.error_code(); + } - let public = slice::from_raw_parts(public, public_size); - let private = slice::from_raw_parts(private, private_size); - let shared = slice::from_raw_parts_mut(shared, shared_size); + let public = slice::from_raw_parts(public, public_size); + let private = slice::from_raw_parts(private, private_size); + let shared = slice::from_raw_parts_mut(shared, shared_size); - match (PrivateKey::try_from(private), PublicKey::try_from(public)) { - (Ok(private), Ok(public)) => match mix_key_exchange(&private, &public) { - Ok(res) => { - let res = Zeroizing::new(res); - shared[0..res.len()].copy_from_slice(&res); - 0 - } - Err(e) => e.error_code(), - }, - (Ok(_), Err(e)) => e.error_code(), - (Err(e), Ok(_)) => e.error_code(), - (Err(e), Err(_)) => e.error_code(), + match (PrivateKey::try_from(private), PublicKey::try_from(public)) { + (Ok(private), Ok(public)) => match mix_key_exchange(&private, &public) { + Ok(res) => { + let res = Zeroizing::new(res); + shared[0..res.len()].copy_from_slice(&res); + 0 + } + Err(e) => e.error_code(), + }, + (Ok(_), Err(e)) => e.error_code(), + (Err(e), Ok(_)) => e.error_code(), + (Err(e), Err(_)) => e.error_code(), + } } } /// Get the size of the keys in the key exchange key pair. /// # Returns /// Returns the length of the keys to input as `shared_length` in `MixKeyExchange()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn MixKeyExchangeSize() -> i64 { 32 } @@ -1175,34 +1213,36 @@ pub extern "C" fn MixKeyExchangeSize() -> i64 { /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn GenerateSharedKey( n_shares: u8, threshold: u8, length: usize, shares: *const *mut u8, ) -> i64 { - if shares.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if shares.is_null() { + return Error::NullPointer.error_code(); + }; - match generate_shared_key(n_shares, threshold, length, SecretSharingVersion::Latest) { - Ok(s) => { - let shares = slice::from_raw_parts(shares, n_shares as usize); + match generate_shared_key(n_shares, threshold, length, SecretSharingVersion::Latest) { + Ok(s) => { + let shares = slice::from_raw_parts(shares, n_shares as usize); - for (s, res_s) in s.into_iter().zip(shares) { - if res_s.is_null() { - return Error::NullPointer.error_code(); - }; + for (s, res_s) in s.into_iter().zip(shares) { + if res_s.is_null() { + return Error::NullPointer.error_code(); + }; - let s: Vec = s.into(); - let res_s = - slice::from_raw_parts_mut(*res_s, GenerateSharedKeySize(length) as usize); - res_s.copy_from_slice(&s); + let s: Vec = s.into(); + let res_s = + slice::from_raw_parts_mut(*res_s, GenerateSharedKeySize(length) as usize); + res_s.copy_from_slice(&s); + } + 0 } - 0 + Err(e) => e.error_code(), } - Err(e) => e.error_code(), } } @@ -1211,7 +1251,7 @@ pub unsafe extern "C" fn GenerateSharedKey( /// * secret_length - The length of the desired secret /// # Returns /// Returns the size, in bytes, of each resulting shares. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn GenerateSharedKeySize(secret_length: usize) -> i64 { (secret_length + 10) as i64 } @@ -1228,7 +1268,7 @@ pub extern "C" fn GenerateSharedKeySize(secret_length: usize) -> i64 { /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn JoinShares( n_shares: usize, share_length: usize, @@ -1236,29 +1276,31 @@ pub unsafe extern "C" fn JoinShares( secret: *mut u8, secret_length: usize, ) -> i64 { - if shares.is_null() || secret.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if shares.is_null() || secret.is_null() { + return Error::NullPointer.error_code(); + }; - if secret_length != JoinSharesSize(share_length) as usize { - return Error::InvalidOutputLength.error_code(); - } + if secret_length != JoinSharesSize(share_length) as usize { + return Error::InvalidOutputLength.error_code(); + } - let shares: Result> = slice::from_raw_parts(shares, n_shares) - .iter() - .map(|s| Share::try_from(slice::from_raw_parts(*s, share_length))) - .collect(); + let shares: Result> = slice::from_raw_parts(shares, n_shares) + .iter() + .map(|s| Share::try_from(slice::from_raw_parts(*s, share_length))) + .collect(); - match shares { - Ok(shares) => match join_shares(&shares) { - Ok(s) => { - let secret = slice::from_raw_parts_mut(secret, secret_length); - secret.copy_from_slice(&s); - 0 - } + match shares { + Ok(shares) => match join_shares(&shares) { + Ok(s) => { + let secret = slice::from_raw_parts_mut(secret, secret_length); + secret.copy_from_slice(&s); + 0 + } + Err(e) => e.error_code(), + }, Err(e) => e.error_code(), - }, - Err(e) => e.error_code(), + } } } @@ -1276,7 +1318,7 @@ pub unsafe extern "C" fn JoinShares( /// 0 on success, otherwise the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn NewOnlineEncryptor( key: *const u8, key_size: usize, @@ -1287,34 +1329,36 @@ pub unsafe extern "C" fn NewOnlineEncryptor( version: u16, output: *mut *mut c_void, ) -> i64 { - if key.is_null() || aad.is_null() { - return Error::NullPointer.error_code(); - }; - - let key = slice::from_raw_parts(key, key_size); - let aad = slice::from_raw_parts(aad, aad_size); + unsafe { + if key.is_null() || aad.is_null() { + return Error::NullPointer.error_code(); + }; - let version = match OnlineCiphertextVersion::try_from(version) { - Ok(v) => v, - Err(_) => return Error::UnknownVersion.error_code(), - }; + let key = slice::from_raw_parts(key, key_size); + let aad = slice::from_raw_parts(aad, aad_size); - let encryptor = if asymmetric { - let public_key = match PublicKey::try_from(key) { - Ok(pk) => pk, - Err(e) => return e.error_code(), + let version = match OnlineCiphertextVersion::try_from(version) { + Ok(v) => v, + Err(_) => return Error::UnknownVersion.error_code(), }; - OnlineCiphertextEncryptor::new_asymmetric(&public_key, aad, chunk_size, version) - } else { - OnlineCiphertextEncryptor::new(key, aad, chunk_size, version) - }; + let encryptor = if asymmetric { + let public_key = match PublicKey::try_from(key) { + Ok(pk) => pk, + Err(e) => return e.error_code(), + }; + + OnlineCiphertextEncryptor::new_asymmetric(&public_key, aad, chunk_size, version) + } else { + OnlineCiphertextEncryptor::new(key, aad, chunk_size, version) + }; - let encryptor = Box::new(Mutex::new(encryptor)); + let encryptor = Box::new(Mutex::new(encryptor)); - *output = Box::into_raw(encryptor) as *mut c_void; + *output = Box::into_raw(encryptor) as *mut c_void; - 0 + 0 + } } /// Creates a new online (chunked) decryptor from a serialized header and writes an opaque handle to it in `output`. @@ -1331,7 +1375,7 @@ pub unsafe extern "C" fn NewOnlineEncryptor( /// 0 on success, otherwise the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn NewOnlineDecryptor( key: *const u8, key_size: usize, @@ -1342,40 +1386,42 @@ pub unsafe extern "C" fn NewOnlineDecryptor( asymmetric: bool, output: *mut *mut c_void, ) -> i64 { - if key.is_null() | aad.is_null() | header.is_null() { - return Error::NullPointer.error_code(); - }; - - let key = slice::from_raw_parts(key, key_size); - let aad = slice::from_raw_parts(aad, aad_size); - let header = slice::from_raw_parts(header, header_size); + unsafe { + if key.is_null() | aad.is_null() | header.is_null() { + return Error::NullPointer.error_code(); + }; - let header = match OnlineCiphertextHeader::try_from(header) { - Ok(h) => h, - Err(e) => return e.error_code(), - }; + let key = slice::from_raw_parts(key, key_size); + let aad = slice::from_raw_parts(aad, aad_size); + let header = slice::from_raw_parts(header, header_size); - let decryptor = if asymmetric { - let private_key = match PrivateKey::try_from(key) { - Ok(pk) => pk, + let header = match OnlineCiphertextHeader::try_from(header) { + Ok(h) => h, Err(e) => return e.error_code(), }; - header.into_decryptor_asymmetric(&private_key, aad) - } else { - header.into_decryptor(key, aad) - }; + let decryptor = if asymmetric { + let private_key = match PrivateKey::try_from(key) { + Ok(pk) => pk, + Err(e) => return e.error_code(), + }; - let decryptor = match decryptor { - Ok(d) => d, - Err(e) => return e.error_code(), - }; + header.into_decryptor_asymmetric(&private_key, aad) + } else { + header.into_decryptor(key, aad) + }; + + let decryptor = match decryptor { + Ok(d) => d, + Err(e) => return e.error_code(), + }; - let decryptor = Box::new(Mutex::new(decryptor)); + let decryptor = Box::new(Mutex::new(decryptor)); - *output = Box::into_raw(decryptor) as *mut c_void; + *output = Box::into_raw(decryptor) as *mut c_void; - 0 + 0 + } } /// Writes the serialized header of the encryptor to the result buffer. @@ -1387,29 +1433,31 @@ pub unsafe extern "C" fn NewOnlineDecryptor( /// The length of the serialized header, or the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineEncryptorGetHeader( ptr: *const c_void, result: *mut u8, result_size: usize, ) -> i64 { - if ptr.is_null() | result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() | result.is_null() { + return Error::NullPointer.error_code(); + }; - let encryptor = &*(ptr as *const Mutex); - let header: Vec = match encryptor.lock() { - Ok(c) => c.get_header().borrow().into(), - Err(_) => return Error::PoisonedMutex.error_code(), - }; + let encryptor = &*(ptr as *const Mutex); + let header: Vec = match encryptor.lock() { + Ok(c) => c.get_header().borrow().into(), + Err(_) => return Error::PoisonedMutex.error_code(), + }; - if header.len() != result_size { - return Error::InvalidOutputLength.error_code(); - } + if header.len() != result_size { + return Error::InvalidOutputLength.error_code(); + } - result.copy_from(header.as_slice().as_ptr(), result_size); + result.copy_from(header.as_slice().as_ptr(), result_size); - result_size as i64 + result_size as i64 + } } /// Writes the serialized header of the decryptor to the result buffer. @@ -1421,29 +1469,31 @@ pub unsafe extern "C" fn OnlineEncryptorGetHeader( /// The length of the serialized header, or the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineDecryptorGetHeader( ptr: *const c_void, result: *mut u8, result_size: usize, ) -> i64 { - if ptr.is_null() | result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() | result.is_null() { + return Error::NullPointer.error_code(); + }; - let decryptor = &*(ptr as *const Mutex); - let header: Vec = match decryptor.lock() { - Ok(c) => c.get_header().borrow().into(), - Err(_) => return Error::PoisonedMutex.error_code(), - }; + let decryptor = &*(ptr as *const Mutex); + let header: Vec = match decryptor.lock() { + Ok(c) => c.get_header().borrow().into(), + Err(_) => return Error::PoisonedMutex.error_code(), + }; - if header.len() != result_size { - return Error::InvalidOutputLength.error_code(); - } + if header.len() != result_size { + return Error::InvalidOutputLength.error_code(); + } - result.copy_from(header.as_slice().as_ptr(), result_size); + result.copy_from(header.as_slice().as_ptr(), result_size); - result_size as i64 + result_size as i64 + } } /// Encrypts the next chunk of data. @@ -1459,7 +1509,7 @@ pub unsafe extern "C" fn OnlineDecryptorGetHeader( /// The length of the encrypted chunk, or the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineEncryptorNextChunk( ptr: *mut c_void, data: *const u8, @@ -1469,31 +1519,33 @@ pub unsafe extern "C" fn OnlineEncryptorNextChunk( result: *mut u8, result_size: usize, ) -> i64 { - if ptr.is_null() | aad.is_null() | data.is_null() | result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() | aad.is_null() | data.is_null() | result.is_null() { + return Error::NullPointer.error_code(); + }; - let encryptor = &*(ptr as *const Mutex); - let mut encryptor = match encryptor.lock() { - Ok(c) => c, - Err(_) => return Error::PoisonedMutex.error_code(), - }; + let encryptor = &*(ptr as *const Mutex); + let mut encryptor = match encryptor.lock() { + Ok(c) => c, + Err(_) => return Error::PoisonedMutex.error_code(), + }; - let data = slice::from_raw_parts(data, data_size); - let aad = slice::from_raw_parts(aad, aad_size); + let data = slice::from_raw_parts(data, data_size); + let aad = slice::from_raw_parts(aad, aad_size); - let encrypted = match encryptor.encrypt_next_chunk(data, aad) { - Ok(e) => e, - Err(e) => return e.error_code(), - }; + let encrypted = match encryptor.encrypt_next_chunk(data, aad) { + Ok(e) => e, + Err(e) => return e.error_code(), + }; - if encrypted.len() != result_size { - return Error::InvalidOutputLength.error_code(); - } + if encrypted.len() != result_size { + return Error::InvalidOutputLength.error_code(); + } - result.copy_from(encrypted.as_slice().as_ptr(), result_size); + result.copy_from(encrypted.as_slice().as_ptr(), result_size); - result_size as i64 + result_size as i64 + } } /// Decrypts the next chunk of data. @@ -1509,7 +1561,7 @@ pub unsafe extern "C" fn OnlineEncryptorNextChunk( /// The length of the decrypted chunk, or the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineDecryptorNextChunk( ptr: *mut c_void, data: *const u8, @@ -1519,31 +1571,33 @@ pub unsafe extern "C" fn OnlineDecryptorNextChunk( result: *mut u8, result_size: usize, ) -> i64 { - if ptr.is_null() | aad.is_null() | data.is_null() | result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() | aad.is_null() | data.is_null() | result.is_null() { + return Error::NullPointer.error_code(); + }; - let decryptor = &*(ptr as *const Mutex); - let mut decryptor = match decryptor.lock() { - Ok(c) => c, - Err(_) => return Error::PoisonedMutex.error_code(), - }; + let decryptor = &*(ptr as *const Mutex); + let mut decryptor = match decryptor.lock() { + Ok(c) => c, + Err(_) => return Error::PoisonedMutex.error_code(), + }; - let data = slice::from_raw_parts(data, data_size); - let aad = slice::from_raw_parts(aad, aad_size); + let data = slice::from_raw_parts(data, data_size); + let aad = slice::from_raw_parts(aad, aad_size); - let decrypted = match decryptor.decrypt_next_chunk(data, aad) { - Ok(e) => e, - Err(e) => return e.error_code(), - }; + let decrypted = match decryptor.decrypt_next_chunk(data, aad) { + Ok(e) => e, + Err(e) => return e.error_code(), + }; - if decrypted.len() != result_size { - return Error::InvalidOutputLength.error_code(); - } + if decrypted.len() != result_size { + return Error::InvalidOutputLength.error_code(); + } - result.copy_from(decrypted.as_slice().as_ptr(), result_size); + result.copy_from(decrypted.as_slice().as_ptr(), result_size); - result_size as i64 + result_size as i64 + } } /// Encrypts the last chunk of data and consumes the encryptor. @@ -1560,7 +1614,7 @@ pub unsafe extern "C" fn OnlineDecryptorNextChunk( /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. /// This call frees the encryptor: `ptr` must not be used again afterwards. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineEncryptorLastChunk( ptr: *mut c_void, data: *const u8, @@ -1570,32 +1624,34 @@ pub unsafe extern "C" fn OnlineEncryptorLastChunk( result: *mut u8, result_size: usize, ) -> i64 { - if ptr.is_null() | aad.is_null() | data.is_null() | result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() | aad.is_null() | data.is_null() | result.is_null() { + return Error::NullPointer.error_code(); + }; - let encryptor = Box::from_raw(ptr as *mut Mutex); + let encryptor = Box::from_raw(ptr as *mut Mutex); - let encryptor = match encryptor.into_inner() { - Ok(c) => c, - Err(_) => return Error::PoisonedMutex.error_code(), - }; + let encryptor = match encryptor.into_inner() { + Ok(c) => c, + Err(_) => return Error::PoisonedMutex.error_code(), + }; - let data = slice::from_raw_parts(data, data_size); - let aad = slice::from_raw_parts(aad, aad_size); + let data = slice::from_raw_parts(data, data_size); + let aad = slice::from_raw_parts(aad, aad_size); - let encrypted = match encryptor.encrypt_last_chunk(data, aad) { - Ok(e) => e, - Err(e) => return e.error_code(), - }; + let encrypted = match encryptor.encrypt_last_chunk(data, aad) { + Ok(e) => e, + Err(e) => return e.error_code(), + }; - if result_size < encrypted.len() { - return Error::InvalidOutputLength.error_code(); - } + if result_size < encrypted.len() { + return Error::InvalidOutputLength.error_code(); + } - result.copy_from(encrypted.as_slice().as_ptr(), encrypted.len()); + result.copy_from(encrypted.as_slice().as_ptr(), encrypted.len()); - encrypted.len() as i64 + encrypted.len() as i64 + } } /// Decrypts the last chunk of data and consumes the decryptor. @@ -1612,7 +1668,7 @@ pub unsafe extern "C" fn OnlineEncryptorLastChunk( /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. /// This call frees the decryptor: `ptr` must not be used again afterwards. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineDecryptorLastChunk( ptr: *mut c_void, data: *const u8, @@ -1622,31 +1678,33 @@ pub unsafe extern "C" fn OnlineDecryptorLastChunk( result: *mut u8, result_size: usize, ) -> i64 { - if ptr.is_null() | aad.is_null() | data.is_null() | result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() | aad.is_null() | data.is_null() | result.is_null() { + return Error::NullPointer.error_code(); + }; - let decryptor = Box::from_raw(ptr as *mut Mutex); - let decryptor = match decryptor.into_inner() { - Ok(c) => c, - Err(_) => return Error::PoisonedMutex.error_code(), - }; + let decryptor = Box::from_raw(ptr as *mut Mutex); + let decryptor = match decryptor.into_inner() { + Ok(c) => c, + Err(_) => return Error::PoisonedMutex.error_code(), + }; - let data = slice::from_raw_parts(data, data_size); - let aad = slice::from_raw_parts(aad, aad_size); + let data = slice::from_raw_parts(data, data_size); + let aad = slice::from_raw_parts(aad, aad_size); - let decrypted = match decryptor.decrypt_last_chunk(data, aad) { - Ok(e) => e, - Err(e) => return e.error_code(), - }; + let decrypted = match decryptor.decrypt_last_chunk(data, aad) { + Ok(e) => e, + Err(e) => return e.error_code(), + }; - if result_size < decrypted.len() { - return Error::InvalidOutputLength.error_code(); - } + if result_size < decrypted.len() { + return Error::InvalidOutputLength.error_code(); + } - result.copy_from(decrypted.as_slice().as_ptr(), decrypted.len()); + result.copy_from(decrypted.as_slice().as_ptr(), decrypted.len()); - decrypted.len() as i64 + decrypted.len() as i64 + } } /// The size, in bytes, of the encryptor's serialized header. @@ -1656,19 +1714,21 @@ pub unsafe extern "C" fn OnlineDecryptorLastChunk( /// The length of the serialized header, or the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineEncryptorGetHeaderSize(ptr: *const c_void) -> i64 { - if ptr.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() { + return Error::NullPointer.error_code(); + }; - let encryptor = &*(ptr as *const Mutex); - let header = match encryptor.lock() { - Ok(c) => c.get_header(), - Err(_) => return Error::PoisonedMutex.error_code(), - }; + let encryptor = &*(ptr as *const Mutex); + let header = match encryptor.lock() { + Ok(c) => c.get_header(), + Err(_) => return Error::PoisonedMutex.error_code(), + }; - header.get_serialized_size() as i64 + header.get_serialized_size() as i64 + } } /// The size, in bytes, of the decryptor's serialized header. @@ -1678,19 +1738,21 @@ pub unsafe extern "C" fn OnlineEncryptorGetHeaderSize(ptr: *const c_void) -> i64 /// The length of the serialized header, or the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineDecryptorGetHeaderSize(ptr: *const c_void) -> i64 { - if ptr.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() { + return Error::NullPointer.error_code(); + }; - let decryptor = &*(ptr as *const Mutex); - let header = match decryptor.lock() { - Ok(c) => c.get_header(), - Err(_) => return Error::PoisonedMutex.error_code(), - }; + let decryptor = &*(ptr as *const Mutex); + let header = match decryptor.lock() { + Ok(c) => c.get_header(), + Err(_) => return Error::PoisonedMutex.error_code(), + }; - header.get_serialized_size() as i64 + header.get_serialized_size() as i64 + } } /// The size, in bytes, of the chunks the encryptor works with. @@ -1700,16 +1762,18 @@ pub unsafe extern "C" fn OnlineDecryptorGetHeaderSize(ptr: *const c_void) -> i64 /// The chunk size, or the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineEncryptorGetChunkSize(ptr: *const c_void) -> i64 { - if ptr.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() { + return Error::NullPointer.error_code(); + }; - let encryptor = &*(ptr as *const Mutex); - match encryptor.lock() { - Ok(c) => c.get_chunk_size() as i64, - Err(_) => Error::PoisonedMutex.error_code(), + let encryptor = &*(ptr as *const Mutex); + match encryptor.lock() { + Ok(c) => c.get_chunk_size() as i64, + Err(_) => Error::PoisonedMutex.error_code(), + } } } @@ -1720,16 +1784,18 @@ pub unsafe extern "C" fn OnlineEncryptorGetChunkSize(ptr: *const c_void) -> i64 /// The chunk size, or the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineDecryptorGetChunkSize(ptr: *const c_void) -> i64 { - if ptr.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() { + return Error::NullPointer.error_code(); + }; - let decryptor = &*(ptr as *const Mutex); - match decryptor.lock() { - Ok(c) => c.get_chunk_size() as i64, - Err(_) => Error::PoisonedMutex.error_code(), + let decryptor = &*(ptr as *const Mutex); + match decryptor.lock() { + Ok(c) => c.get_chunk_size() as i64, + Err(_) => Error::PoisonedMutex.error_code(), + } } } @@ -1740,16 +1806,18 @@ pub unsafe extern "C" fn OnlineDecryptorGetChunkSize(ptr: *const c_void) -> i64 /// The tag size, or the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineEncryptorGetTagSize(ptr: *const c_void) -> i64 { - if ptr.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() { + return Error::NullPointer.error_code(); + }; - let encryptor = &*(ptr as *const Mutex); - match encryptor.lock() { - Ok(c) => c.get_tag_size() as i64, - Err(_) => Error::PoisonedMutex.error_code(), + let encryptor = &*(ptr as *const Mutex); + match encryptor.lock() { + Ok(c) => c.get_tag_size() as i64, + Err(_) => Error::PoisonedMutex.error_code(), + } } } @@ -1760,16 +1828,18 @@ pub unsafe extern "C" fn OnlineEncryptorGetTagSize(ptr: *const c_void) -> i64 { /// The tag size, or the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn OnlineDecryptorGetTagSize(ptr: *const c_void) -> i64 { - if ptr.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() { + return Error::NullPointer.error_code(); + }; - let decryptor = &*(ptr as *const Mutex); - match decryptor.lock() { - Ok(c) => c.get_tag_size() as i64, - Err(_) => Error::PoisonedMutex.error_code(), + let decryptor = &*(ptr as *const Mutex); + match decryptor.lock() { + Ok(c) => c.get_tag_size() as i64, + Err(_) => Error::PoisonedMutex.error_code(), + } } } @@ -1781,15 +1851,17 @@ pub unsafe extern "C" fn OnlineDecryptorGetTagSize(ptr: *const c_void) -> i64 { /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. /// `ptr` must not be used again afterwards. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn FreeOnlineEncryptor(ptr: *mut c_void) -> i64 { - if ptr.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() { + return Error::NullPointer.error_code(); + }; - drop(Box::from_raw(ptr as *mut Mutex)); + drop(Box::from_raw(ptr as *mut Mutex)); - 0 + 0 + } } /// Frees a decryptor without finalizing the decryption. @@ -1800,15 +1872,17 @@ pub unsafe extern "C" fn FreeOnlineEncryptor(ptr: *mut c_void) -> i64 { /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. /// `ptr` must not be used again afterwards. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn FreeOnlineDecryptor(ptr: *mut c_void) -> i64 { - if ptr.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if ptr.is_null() { + return Error::NullPointer.error_code(); + }; - drop(Box::from_raw(ptr as *mut Mutex)); + drop(Box::from_raw(ptr as *mut Mutex)); - 0 + 0 + } } /// The size, in bytes, of the resulting secret @@ -1816,7 +1890,7 @@ pub unsafe extern "C" fn FreeOnlineDecryptor(ptr: *mut c_void) -> i64 { /// * share_length - The length of a share /// # Returns /// Returns the size, in bytes, of each resulting secret. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn JoinSharesSize(share_length: usize) -> i64 { (share_length - 10) as i64 } @@ -1830,21 +1904,23 @@ pub extern "C" fn JoinSharesSize(share_length: usize) -> i64 { /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn GenerateKey(key: *mut u8, key_length: usize) -> i64 { - if key.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if key.is_null() { + return Error::NullPointer.error_code(); + }; - let key = slice::from_raw_parts_mut(key, key_length); + let key = slice::from_raw_parts_mut(key, key_length); - let k = match utils::generate_key(key_length) { - Ok(x) => Zeroizing::new(x), - Err(e) => return e.error_code(), - }; + let k = match utils::generate_key(key_length) { + Ok(x) => Zeroizing::new(x), + Err(e) => return e.error_code(), + }; - key.copy_from_slice(&k); - 0 + key.copy_from_slice(&k); + 0 + } } /// Derive a key with Argon2 to create a new one. Can be used with a password. @@ -1860,7 +1936,7 @@ pub unsafe extern "C" fn GenerateKey(key: *mut u8, key_length: usize) -> i64 { /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn DeriveKeyArgon2( key: *const u8, key_length: usize, @@ -1869,28 +1945,31 @@ pub unsafe extern "C" fn DeriveKeyArgon2( result: *mut u8, result_length: usize, ) -> i64 { - if key.is_null() || result.is_null() || argon2_parameters.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if key.is_null() || result.is_null() || argon2_parameters.is_null() { + return Error::NullPointer.error_code(); + }; - let key = slice::from_raw_parts(key, key_length); + let key = slice::from_raw_parts(key, key_length); - let argon2_parameters_raw = slice::from_raw_parts(argon2_parameters, argon2_parameters_length); + let argon2_parameters_raw = + slice::from_raw_parts(argon2_parameters, argon2_parameters_length); - let argon2_parameters = match Argon2Parameters::try_from(argon2_parameters_raw) { - Ok(x) => x, - Err(e) => return e.error_code(), - }; + let argon2_parameters = match Argon2Parameters::try_from(argon2_parameters_raw) { + Ok(x) => x, + Err(e) => return e.error_code(), + }; - let native_result = match utils::derive_key_argon2(key, &argon2_parameters) { - Ok(x) => Zeroizing::new(x), - Err(e) => return e.error_code(), - }; + let native_result = match utils::derive_key_argon2(key, &argon2_parameters) { + Ok(x) => Zeroizing::new(x), + Err(e) => return e.error_code(), + }; - let result = slice::from_raw_parts_mut(result, result_length); + let result = slice::from_raw_parts_mut(result, result_length); - result.copy_from_slice(&native_result); - 0 + result.copy_from_slice(&native_result); + 0 + } } /// Derive a key with PBKDF2 to create a new one. Can be used with a password. @@ -1906,7 +1985,7 @@ pub unsafe extern "C" fn DeriveKeyArgon2( /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn DeriveKeyPbkdf2( key: *const u8, key_length: usize, @@ -1916,27 +1995,29 @@ pub unsafe extern "C" fn DeriveKeyPbkdf2( result: *mut u8, result_length: usize, ) -> i64 { - if key.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if key.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + }; - let salt = if salt.is_null() || salt_length == 0 { - b"" - } else { - slice::from_raw_parts(salt, salt_length) - }; + let salt = if salt.is_null() || salt_length == 0 { + b"" + } else { + slice::from_raw_parts(salt, salt_length) + }; - let key = slice::from_raw_parts(key, key_length); - let result = slice::from_raw_parts_mut(result, result_length); + let key = slice::from_raw_parts(key, key_length); + let result = slice::from_raw_parts_mut(result, result_length); - let native_result = Zeroizing::new(utils::derive_key_pbkdf2( - key, - salt, - niterations, - result_length, - )); - result.copy_from_slice(&native_result); - 0 + let native_result = Zeroizing::new(utils::derive_key_pbkdf2( + key, + salt, + niterations, + result_length, + )); + result.copy_from_slice(&native_result); + 0 + } } /// Derive a key with PBKDF2 and return both the SecretKey and the DerivationParameters. @@ -1955,7 +2036,7 @@ pub unsafe extern "C" fn DeriveKeyPbkdf2( /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn DeriveSecretKeyPbkdf2( password: *const u8, password_length: usize, @@ -1965,39 +2046,41 @@ pub unsafe extern "C" fn DeriveSecretKeyPbkdf2( params_out: *mut u8, params_out_length: usize, ) -> i64 { - if password.is_null() || secret_key.is_null() || params_out.is_null() { - return Error::NullPointer.error_code(); - } + unsafe { + if password.is_null() || secret_key.is_null() || params_out.is_null() { + return Error::NullPointer.error_code(); + } - if secret_key_length != GenerateSecretKeySize() as usize { - return Error::InvalidOutputLength.error_code(); - } + if secret_key_length != GenerateSecretKeySize() as usize { + return Error::InvalidOutputLength.error_code(); + } - if params_out_length != DeriveSecretKeyPbkdf2Size() as usize { - return Error::InvalidOutputLength.error_code(); - } + if params_out_length != DeriveSecretKeyPbkdf2Size() as usize { + return Error::InvalidOutputLength.error_code(); + } - let password = slice::from_raw_parts(password, password_length); + let password = slice::from_raw_parts(password, password_length); - let (sk, params) = match Pbkdf2::with_params(iterations).derive(password) { - Ok(x) => x, - Err(e) => return e.error_code(), - }; + let (sk, params) = match Pbkdf2::with_params(iterations).derive(password) { + Ok(x) => x, + Err(e) => return e.error_code(), + }; - let sk_bytes: Zeroizing> = Zeroizing::new(sk.into()); - let params_bytes: Vec = params.into(); + let sk_bytes: Zeroizing> = Zeroizing::new(sk.into()); + let params_bytes: Vec = params.into(); - let secret_key = slice::from_raw_parts_mut(secret_key, secret_key_length); - let params_out = slice::from_raw_parts_mut(params_out, params_out_length); + let secret_key = slice::from_raw_parts_mut(secret_key, secret_key_length); + let params_out = slice::from_raw_parts_mut(params_out, params_out_length); - secret_key.copy_from_slice(&sk_bytes); - params_out.copy_from_slice(¶ms_bytes); - 0 + secret_key.copy_from_slice(&sk_bytes); + params_out.copy_from_slice(¶ms_bytes); + 0 + } } /// Returns the size of the DerivationParameters output buffer for `DeriveSecretKeyPbkdf2()`. /// The size is fixed: 8 (header) + 4 (iterations) + 4 (salt length) + 16 (salt) = 32 bytes. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn DeriveSecretKeyPbkdf2Size() -> i64 { 32 // 8 header + 4 iterations + 4 salt_len + 16 salt } @@ -2019,7 +2102,7 @@ pub extern "C" fn DeriveSecretKeyPbkdf2Size() -> i64 { /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn DeriveSecretKeyArgon2( password: *const u8, password_length: usize, @@ -2030,48 +2113,53 @@ pub unsafe extern "C" fn DeriveSecretKeyArgon2( params_out: *mut u8, params_out_length: usize, ) -> i64 { - if password.is_null() - || argon2_parameters.is_null() - || secret_key.is_null() - || params_out.is_null() - { - return Error::NullPointer.error_code(); - } + unsafe { + if password.is_null() + || argon2_parameters.is_null() + || secret_key.is_null() + || params_out.is_null() + { + return Error::NullPointer.error_code(); + } - if secret_key_length != GenerateSecretKeySize() as usize { - return Error::InvalidOutputLength.error_code(); - } + if secret_key_length != GenerateSecretKeySize() as usize { + return Error::InvalidOutputLength.error_code(); + } - if params_out_length != DeriveSecretKeyArgon2ParametersSize(argon2_parameters_length) as usize { - return Error::InvalidOutputLength.error_code(); - } + if params_out_length + != DeriveSecretKeyArgon2ParametersSize(argon2_parameters_length) as usize + { + return Error::InvalidOutputLength.error_code(); + } - let password = slice::from_raw_parts(password, password_length); - let argon2_parameters_raw = slice::from_raw_parts(argon2_parameters, argon2_parameters_length); + let password = slice::from_raw_parts(password, password_length); + let argon2_parameters_raw = + slice::from_raw_parts(argon2_parameters, argon2_parameters_length); - let argon2_params = match Argon2Parameters::try_from(argon2_parameters_raw) { - Ok(x) => x, - Err(e) => return e.error_code(), - }; + let argon2_params = match Argon2Parameters::try_from(argon2_parameters_raw) { + Ok(x) => x, + Err(e) => return e.error_code(), + }; - let (sk, params) = match Argon2::with_params(argon2_params).derive(password) { - Ok(x) => x, - Err(e) => return e.error_code(), - }; + let (sk, params) = match Argon2::with_params(argon2_params).derive(password) { + Ok(x) => x, + Err(e) => return e.error_code(), + }; - let sk_bytes: Zeroizing> = Zeroizing::new(sk.into()); - let params_bytes: Vec = params.into(); + let sk_bytes: Zeroizing> = Zeroizing::new(sk.into()); + let params_bytes: Vec = params.into(); - if params_bytes.len() != params_out_length { - return Error::InvalidOutputLength.error_code(); - } + if params_bytes.len() != params_out_length { + return Error::InvalidOutputLength.error_code(); + } - let secret_key = slice::from_raw_parts_mut(secret_key, secret_key_length); - let params_out = slice::from_raw_parts_mut(params_out, params_out_length); + let secret_key = slice::from_raw_parts_mut(secret_key, secret_key_length); + let params_out = slice::from_raw_parts_mut(params_out, params_out_length); - secret_key.copy_from_slice(&sk_bytes); - params_out.copy_from_slice(¶ms_bytes); - 0 + secret_key.copy_from_slice(&sk_bytes); + params_out.copy_from_slice(¶ms_bytes); + 0 + } } /// Derive a key with PBKDF2 and return both the SecretKey and the DerivationParameters. @@ -2092,7 +2180,7 @@ pub unsafe extern "C" fn DeriveSecretKeyArgon2( /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn DeriveSecretKeyPbkdf2WithSalt( password: *const u8, password_length: usize, @@ -2104,42 +2192,44 @@ pub unsafe extern "C" fn DeriveSecretKeyPbkdf2WithSalt( params_out: *mut u8, params_out_length: usize, ) -> i64 { - if password.is_null() || salt.is_null() || secret_key.is_null() || params_out.is_null() { - return Error::NullPointer.error_code(); - } + unsafe { + if password.is_null() || salt.is_null() || secret_key.is_null() || params_out.is_null() { + return Error::NullPointer.error_code(); + } - if secret_key_length != GenerateSecretKeySize() as usize { - return Error::InvalidOutputLength.error_code(); - } + if secret_key_length != GenerateSecretKeySize() as usize { + return Error::InvalidOutputLength.error_code(); + } - if params_out_length != DeriveSecretKeyPbkdf2WithSaltSize(salt_length) as usize { - return Error::InvalidOutputLength.error_code(); - } + if params_out_length != DeriveSecretKeyPbkdf2WithSaltSize(salt_length) as usize { + return Error::InvalidOutputLength.error_code(); + } - let password = slice::from_raw_parts(password, password_length); - let salt = slice::from_raw_parts(salt, salt_length); + let password = slice::from_raw_parts(password, password_length); + let salt = slice::from_raw_parts(salt, salt_length); - let (sk, params) = match Pbkdf2::with_params(iterations).derive_with_salt(password, salt) { - Ok(x) => x, - Err(e) => return e.error_code(), - }; + let (sk, params) = match Pbkdf2::with_params(iterations).derive_with_salt(password, salt) { + Ok(x) => x, + Err(e) => return e.error_code(), + }; - let sk_bytes: Zeroizing> = Zeroizing::new(sk.into()); - let params_bytes: Vec = params.into(); + let sk_bytes: Zeroizing> = Zeroizing::new(sk.into()); + let params_bytes: Vec = params.into(); - let secret_key = slice::from_raw_parts_mut(secret_key, secret_key_length); - let params_out = slice::from_raw_parts_mut(params_out, params_out_length); + let secret_key = slice::from_raw_parts_mut(secret_key, secret_key_length); + let params_out = slice::from_raw_parts_mut(params_out, params_out_length); - secret_key.copy_from_slice(&sk_bytes); - params_out.copy_from_slice(¶ms_bytes); - 0 + secret_key.copy_from_slice(&sk_bytes); + params_out.copy_from_slice(¶ms_bytes); + 0 + } } /// Returns the size of the DerivationParameters output buffer for `DeriveSecretKeyPbkdf2WithSalt()`. /// The size is: 8 (header) + 4 (iterations) + 4 (salt length field) + salt_length (salt bytes). /// # Arguments /// * salt_length - The length of the salt that will be passed to `DeriveSecretKeyPbkdf2WithSalt()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn DeriveSecretKeyPbkdf2WithSaltSize(salt_length: usize) -> i64 { (8 + 4 + 4 + salt_length) as i64 } @@ -2148,7 +2238,7 @@ pub extern "C" fn DeriveSecretKeyPbkdf2WithSaltSize(salt_length: usize) -> i64 { /// The size is: 8 (header) + argon2_parameters_length (serialized Argon2Parameters bytes). /// # Arguments /// * argon2_parameters_length - The length of the Argon2Parameters that will be passed to `DeriveSecretKeyArgon2()`. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn DeriveSecretKeyArgon2ParametersSize(argon2_parameters_length: usize) -> i64 { (8 + argon2_parameters_length) as i64 } @@ -2157,7 +2247,7 @@ pub extern "C" fn DeriveSecretKeyArgon2ParametersSize(argon2_parameters_length: /// The size is: 8 (header) + argon2_parameters_length (serialized Argon2Parameters bytes). /// # Arguments /// * argon2_parameters_length - The length of the Argon2Parameters bytes. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn GetArgon2DerivationParametersSize(argon2_parameters_length: usize) -> i64 { (8 + argon2_parameters_length) as i64 } @@ -2174,36 +2264,39 @@ pub extern "C" fn GetArgon2DerivationParametersSize(argon2_parameters_length: us /// Returns the number of bytes written, or a negative error code. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn GetArgon2DerivationParameters( argon2_parameters: *const u8, argon2_parameters_length: usize, result: *mut u8, result_length: usize, ) -> i64 { - if argon2_parameters.is_null() || result.is_null() { - return Error::NullPointer.error_code(); - } + unsafe { + if argon2_parameters.is_null() || result.is_null() { + return Error::NullPointer.error_code(); + } - if result_length != GetArgon2DerivationParametersSize(argon2_parameters_length) as usize { - return Error::InvalidOutputLength.error_code(); - } + if result_length != GetArgon2DerivationParametersSize(argon2_parameters_length) as usize { + return Error::InvalidOutputLength.error_code(); + } - let argon2_parameters_raw = slice::from_raw_parts(argon2_parameters, argon2_parameters_length); - let argon2_params = match Argon2Parameters::try_from(argon2_parameters_raw) { - Ok(x) => x, - Err(e) => return e.error_code(), - }; + let argon2_parameters_raw = + slice::from_raw_parts(argon2_parameters, argon2_parameters_length); + let argon2_params = match Argon2Parameters::try_from(argon2_parameters_raw) { + Ok(x) => x, + Err(e) => return e.error_code(), + }; - let dp_bytes: Vec = Argon2::with_params(argon2_params).parameters().into(); - let result = slice::from_raw_parts_mut(result, result_length); - result.copy_from_slice(&dp_bytes); - result_length as i64 + let dp_bytes: Vec = Argon2::with_params(argon2_params).parameters().into(); + let result = slice::from_raw_parts_mut(result, result_length); + result.copy_from_slice(&dp_bytes); + result_length as i64 + } } /// Returns the required output buffer size for `GetPbkdf2DerivationParameters()`. /// The size is always 32 bytes: 8 (header) + 4 (iterations) + 4 (salt length) + 16 (salt). -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn GetPbkdf2DerivationParametersSize() -> i64 { 32 // 8 header + 4 iterations + 4 salt_len + 16 salt } @@ -2219,29 +2312,31 @@ pub extern "C" fn GetPbkdf2DerivationParametersSize() -> i64 { /// Returns the number of bytes written, or a negative error code. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn GetPbkdf2DerivationParameters( iterations: u32, result: *mut u8, result_length: usize, ) -> i64 { - if result.is_null() { - return Error::NullPointer.error_code(); - } + unsafe { + if result.is_null() { + return Error::NullPointer.error_code(); + } - if result_length != GetPbkdf2DerivationParametersSize() as usize { - return Error::InvalidOutputLength.error_code(); - } + if result_length != GetPbkdf2DerivationParametersSize() as usize { + return Error::InvalidOutputLength.error_code(); + } - let dp = match Pbkdf2::with_params(iterations).parameters() { - Ok(x) => x, - Err(e) => return e.error_code(), - }; + let dp = match Pbkdf2::with_params(iterations).parameters() { + Ok(x) => x, + Err(e) => return e.error_code(), + }; - let dp_bytes: Vec = dp.into(); - let result = slice::from_raw_parts_mut(result, result_length); - result.copy_from_slice(&dp_bytes); - result_length as i64 + let dp_bytes: Vec = dp.into(); + let result = slice::from_raw_parts_mut(result, result_length); + result.copy_from_slice(&dp_bytes); + result_length as i64 + } } /// # Arguments @@ -2252,34 +2347,36 @@ pub unsafe extern "C" fn GetPbkdf2DerivationParameters( /// 1 if the header is valid, 0 if it's not, and a negative value if there is an error. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn ValidateHeader( data: *const u8, data_length: usize, data_type: u16, ) -> i64 { - if data.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if data.is_null() { + return Error::NullPointer.error_code(); + }; - let data = slice::from_raw_parts(data, data_length); + let data = slice::from_raw_parts(data, data_length); - match DataType::try_from(data_type) { - Ok(t) => { - if utils::validate_header(data, t) { - 1 - } else { - 0 + match DataType::try_from(data_type) { + Ok(t) => { + if utils::validate_header(data, t) { + 1 + } else { + 0 + } } + Err(_) => Error::UnknownType.error_code(), } - Err(_) => Error::UnknownType.error_code(), } } /// This is binded here for one specific use case, do not use it if you don't know what you're doing. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn ScryptSimple( password: *const u8, password_length: usize, @@ -2291,24 +2388,26 @@ pub unsafe extern "C" fn ScryptSimple( output: *mut u8, output_length: usize, ) -> i64 { - if password.is_null() && salt.is_null() && output.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if password.is_null() && salt.is_null() && output.is_null() { + return Error::NullPointer.error_code(); + }; - let password = slice::from_raw_parts(password, password_length); - let salt = slice::from_raw_parts(salt, salt_length); + let password = slice::from_raw_parts(password, password_length); + let salt = slice::from_raw_parts(salt, salt_length); - let hash = utils::scrypt_simple(password, salt, log_n, r, p); + let hash = utils::scrypt_simple(password, salt, log_n, r, p); - let output = slice::from_raw_parts_mut(output, output_length); - output[..hash.len()].copy_from_slice(hash.as_bytes()); - hash.len() as i64 + let output = slice::from_raw_parts_mut(output, output_length); + output[..hash.len()].copy_from_slice(hash.as_bytes()); + hash.len() as i64 + } } /// This is binded here for one specific use case, do not use it if you don't know what you're doing. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn ScryptSimpleSize() -> i64 { 256 } @@ -2321,22 +2420,25 @@ pub unsafe extern "C" fn ScryptSimpleSize() -> i64 { /// Returns 0 if the operation is successful. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn GetDefaultArgon2Parameters( argon2_parameters: *mut u8, argon2_parameters_length: usize, ) -> i64 { - let argon2_parameters = slice::from_raw_parts_mut(argon2_parameters, argon2_parameters_length); + unsafe { + let argon2_parameters = + slice::from_raw_parts_mut(argon2_parameters, argon2_parameters_length); - let argon2_parameters_raw: Vec = (&Argon2Parameters::default()).into(); - argon2_parameters.copy_from_slice(&argon2_parameters_raw); - 0 + let argon2_parameters_raw: Vec = (&Argon2Parameters::default()).into(); + argon2_parameters.copy_from_slice(&argon2_parameters_raw); + 0 + } } /// Size of the Argon2Parameters struct. /// # Returns /// Returns 0 if the operation is successful. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn GetDefaultArgon2ParametersSize() -> i64 { // Length is calculated this way: // 5 * u32 + 2 * u8(enums) + 2 * u32(lengths) + 2 * vec.len(); @@ -2347,7 +2449,7 @@ pub extern "C" fn GetDefaultArgon2ParametersSize() -> i64 { /// Size, in bits, of the key used for the current Encrypt() implementation. /// # Returns /// Returns the size, in bits, of the key used fot the current Encrypt() implementation. -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn KeySize() -> u32 { 256 } @@ -2362,26 +2464,28 @@ pub extern "C" fn KeySize() -> u32 { /// Returns the size of the decoded string. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn Decode( input: *const u8, input_length: usize, output: *mut u8, output_length: usize, ) -> i64 { - if input.is_null() || output.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if input.is_null() || output.is_null() { + return Error::NullPointer.error_code(); + }; - let input = std::str::from_utf8_unchecked(slice::from_raw_parts(input, input_length)); - let output = slice::from_raw_parts_mut(output, output_length); + let input = std::str::from_utf8_unchecked(slice::from_raw_parts(input, input_length)); + let output = slice::from_raw_parts_mut(output, output_length); - match devolutions_crypto::utils::base64_decode(input) { - Ok(res) => { - output.copy_from_slice(&res); - res.len() as i64 + match devolutions_crypto::utils::base64_decode(input) { + Ok(res) => { + output.copy_from_slice(&res); + res.len() as i64 + } + Err(_err) => -1, } - Err(_err) => -1, } } @@ -2395,25 +2499,27 @@ pub unsafe extern "C" fn Decode( /// Returns the size, in bytes, of the output buffer. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn Encode( input: *const u8, input_length: usize, output: *mut u8, output_length: usize, ) -> i64 { - if input.is_null() || output.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if input.is_null() || output.is_null() { + return Error::NullPointer.error_code(); + }; - let input = slice::from_raw_parts(input, input_length); - let output = slice::from_raw_parts_mut(output, output_length); + let input = slice::from_raw_parts(input, input_length); + let output = slice::from_raw_parts_mut(output, output_length); - let encode_res = devolutions_crypto::utils::base64_encode(input).into_bytes(); + let encode_res = devolutions_crypto::utils::base64_encode(input).into_bytes(); - output.copy_from_slice(&encode_res); + output.copy_from_slice(&encode_res); - encode_res.len() as i64 + encode_res.len() as i64 + } } /// Decode a base64 string to bytes using base64url. @@ -2426,23 +2532,25 @@ pub unsafe extern "C" fn Encode( /// Returns the size of the decoded string. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn DecodeUrl( input: *const u8, input_length: usize, output: *mut u8, output_length: usize, ) -> i64 { - if input.is_null() || output.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if input.is_null() || output.is_null() { + return Error::NullPointer.error_code(); + }; - let input = std::str::from_utf8_unchecked(slice::from_raw_parts(input, input_length)); - let output = slice::from_raw_parts_mut(output, output_length); + let input = std::str::from_utf8_unchecked(slice::from_raw_parts(input, input_length)); + let output = slice::from_raw_parts_mut(output, output_length); - match general_purpose::URL_SAFE_NO_PAD.decode_slice_unchecked(input, output) { - Ok(res) => res as i64, - Err(_e) => -1, + match general_purpose::URL_SAFE_NO_PAD.decode_slice_unchecked(input, output) { + Ok(res) => res as i64, + Err(_e) => -1, + } } } @@ -2456,23 +2564,25 @@ pub unsafe extern "C" fn DecodeUrl( /// Returns the size, in bytes, of the output buffer. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn EncodeUrl( input: *const u8, input_length: usize, output: *mut u8, output_length: usize, ) -> i64 { - if input.is_null() || output.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if input.is_null() || output.is_null() { + return Error::NullPointer.error_code(); + }; - let input = slice::from_raw_parts(input, input_length); - let output = slice::from_raw_parts_mut(output, output_length); + let input = slice::from_raw_parts(input, input_length); + let output = slice::from_raw_parts_mut(output, output_length); - match general_purpose::URL_SAFE_NO_PAD.encode_slice(input, output) { - Ok(res) => res as i64, - Err(_err) => -1, + match general_purpose::URL_SAFE_NO_PAD.encode_slice(input, output) { + Ok(res) => res as i64, + Err(_err) => -1, + } } } @@ -2487,31 +2597,33 @@ pub unsafe extern "C" fn EncodeUrl( /// it will return the appropriate error code defined in DevoCryptoError. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn ConstantTimeEquals( x: *const u8, x_length: usize, y: *const u8, y_length: usize, ) -> i64 { - if x.is_null() || y.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if x.is_null() || y.is_null() { + return Error::NullPointer.error_code(); + }; - let x = slice::from_raw_parts(x, x_length); - let y = slice::from_raw_parts(y, y_length); + let x = slice::from_raw_parts(x, x_length); + let y = slice::from_raw_parts(y, y_length); - if utils::constant_time_equals(x, y) { - 1 - } else { - 0 + if utils::constant_time_equals(x, y) { + 1 + } else { + 0 + } } } /// Size of the version string /// # Returns /// Returns the size of the version string -#[no_mangle] +#[unsafe(no_mangle)] pub extern "C" fn VersionSize() -> i64 { VERSION.len() as i64 } @@ -2524,16 +2636,18 @@ pub extern "C" fn VersionSize() -> i64 { /// Returns the size, in bytes, of the output buffer. /// # Safety /// This method is made to be called by C, so it is therefore unsafe. The caller should make sure it passes the right pointers and sizes. -#[no_mangle] +#[unsafe(no_mangle)] pub unsafe extern "C" fn Version(output: *mut u8, output_length: usize) -> i64 { - if output.is_null() { - return Error::NullPointer.error_code(); - }; + unsafe { + if output.is_null() { + return Error::NullPointer.error_code(); + }; - let output = slice::from_raw_parts_mut(output, output_length); - output.copy_from_slice(VERSION.as_bytes()); + let output = slice::from_raw_parts_mut(output, output_length); + output.copy_from_slice(VERSION.as_bytes()); - output.len() as i64 + output.len() as i64 + } } #[test] diff --git a/fuzz/Cargo.toml b/fuzz/Cargo.toml index 093254b6..2eb45385 100644 --- a/fuzz/Cargo.toml +++ b/fuzz/Cargo.toml @@ -4,7 +4,7 @@ name = "devolutions-crypto-fuzz" version.workspace = true authors = ["Automatically generated"] publish = false -edition = "2018" +edition = "2024" [package.metadata] cargo-fuzz = true diff --git a/fuzz/fuzz_targets/ciphertext/encrypt.rs b/fuzz/fuzz_targets/ciphertext/encrypt.rs index 5a3b6111..d5a8512d 100644 --- a/fuzz/fuzz_targets/ciphertext/encrypt.rs +++ b/fuzz/fuzz_targets/ciphertext/encrypt.rs @@ -2,7 +2,7 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::ciphertext::{encrypt, CiphertextVersion}; +use devolutions_crypto::ciphertext::{CiphertextVersion, encrypt}; #[derive(Arbitrary, Clone, Debug)] struct Input { diff --git a/fuzz/fuzz_targets/ciphertext/encrypt_asymmetric.rs b/fuzz/fuzz_targets/ciphertext/encrypt_asymmetric.rs index 0e78e8b4..42d44f4f 100644 --- a/fuzz/fuzz_targets/ciphertext/encrypt_asymmetric.rs +++ b/fuzz/fuzz_targets/ciphertext/encrypt_asymmetric.rs @@ -2,7 +2,7 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::ciphertext::{encrypt_asymmetric, CiphertextVersion}; +use devolutions_crypto::ciphertext::{CiphertextVersion, encrypt_asymmetric}; use devolutions_crypto::key::PublicKey; #[derive(Arbitrary, Clone, Debug)] diff --git a/fuzz/fuzz_targets/ciphertext/encrypt_asymmetric_with_aad.rs b/fuzz/fuzz_targets/ciphertext/encrypt_asymmetric_with_aad.rs index ab7c05e9..81ab256e 100644 --- a/fuzz/fuzz_targets/ciphertext/encrypt_asymmetric_with_aad.rs +++ b/fuzz/fuzz_targets/ciphertext/encrypt_asymmetric_with_aad.rs @@ -2,7 +2,7 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::ciphertext::{encrypt_asymmetric_with_aad, CiphertextVersion}; +use devolutions_crypto::ciphertext::{CiphertextVersion, encrypt_asymmetric_with_aad}; use devolutions_crypto::key::PublicKey; #[derive(Arbitrary, Clone, Debug)] diff --git a/fuzz/fuzz_targets/ciphertext/encrypt_with_aad.rs b/fuzz/fuzz_targets/ciphertext/encrypt_with_aad.rs index e1c4e148..520f1c3b 100644 --- a/fuzz/fuzz_targets/ciphertext/encrypt_with_aad.rs +++ b/fuzz/fuzz_targets/ciphertext/encrypt_with_aad.rs @@ -2,7 +2,7 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::ciphertext::{encrypt_with_aad, CiphertextVersion}; +use devolutions_crypto::ciphertext::{CiphertextVersion, encrypt_with_aad}; #[derive(Arbitrary, Clone, Debug)] struct Input { diff --git a/fuzz/fuzz_targets/key/generate_keypair.rs b/fuzz/fuzz_targets/key/generate_keypair.rs index 01b3f6b2..b02b3e20 100644 --- a/fuzz/fuzz_targets/key/generate_keypair.rs +++ b/fuzz/fuzz_targets/key/generate_keypair.rs @@ -2,7 +2,7 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::key::{generate_keypair, KeyVersion}; +use devolutions_crypto::key::{KeyVersion, generate_keypair}; #[derive(Arbitrary, Clone, Debug)] struct Input { diff --git a/fuzz/fuzz_targets/key/mix_key_exchange.rs b/fuzz/fuzz_targets/key/mix_key_exchange.rs index c5a7429c..aa9c146b 100644 --- a/fuzz/fuzz_targets/key/mix_key_exchange.rs +++ b/fuzz/fuzz_targets/key/mix_key_exchange.rs @@ -2,7 +2,7 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::key::{mix_key_exchange, PrivateKey, PublicKey}; +use devolutions_crypto::key::{PrivateKey, PublicKey, mix_key_exchange}; #[derive(Arbitrary, Clone, Debug)] struct Input { diff --git a/fuzz/fuzz_targets/secret_sharing/generate_shared_key.rs b/fuzz/fuzz_targets/secret_sharing/generate_shared_key.rs index 0c8da999..96409043 100644 --- a/fuzz/fuzz_targets/secret_sharing/generate_shared_key.rs +++ b/fuzz/fuzz_targets/secret_sharing/generate_shared_key.rs @@ -2,7 +2,7 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::secret_sharing::{generate_shared_key, SecretSharingVersion}; +use devolutions_crypto::secret_sharing::{SecretSharingVersion, generate_shared_key}; #[derive(Arbitrary, Clone, Debug)] struct Input { diff --git a/fuzz/fuzz_targets/secret_sharing/join_shares.rs b/fuzz/fuzz_targets/secret_sharing/join_shares.rs index 1609abe5..033c17fd 100644 --- a/fuzz/fuzz_targets/secret_sharing/join_shares.rs +++ b/fuzz/fuzz_targets/secret_sharing/join_shares.rs @@ -2,7 +2,7 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::secret_sharing::{join_shares, Share}; +use devolutions_crypto::secret_sharing::{Share, join_shares}; #[derive(Arbitrary, Clone, Debug)] struct Input { diff --git a/fuzz/fuzz_targets/signature/sign.rs b/fuzz/fuzz_targets/signature/sign.rs index cd94019b..ca7d8ba0 100644 --- a/fuzz/fuzz_targets/signature/sign.rs +++ b/fuzz/fuzz_targets/signature/sign.rs @@ -2,7 +2,7 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::signature::{sign, SignatureVersion}; +use devolutions_crypto::signature::{SignatureVersion, sign}; use devolutions_crypto::signing_key::SigningKeyPair; #[derive(Arbitrary, Clone, Debug)] diff --git a/fuzz/fuzz_targets/utils/derive_key_argon2.rs b/fuzz/fuzz_targets/utils/derive_key_argon2.rs index df6fdc54..a3511471 100644 --- a/fuzz/fuzz_targets/utils/derive_key_argon2.rs +++ b/fuzz/fuzz_targets/utils/derive_key_argon2.rs @@ -2,8 +2,8 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::utils::derive_key_argon2; use devolutions_crypto::Argon2Parameters; +use devolutions_crypto::utils::derive_key_argon2; #[derive(Arbitrary, Clone, Debug)] struct Input { diff --git a/fuzz/fuzz_targets/utils/validate_header.rs b/fuzz/fuzz_targets/utils/validate_header.rs index 3c75c829..69b1091d 100644 --- a/fuzz/fuzz_targets/utils/validate_header.rs +++ b/fuzz/fuzz_targets/utils/validate_header.rs @@ -2,8 +2,8 @@ use arbitrary::Arbitrary; use libfuzzer_sys::fuzz_target; -use devolutions_crypto::utils::validate_header; use devolutions_crypto::DataType; +use devolutions_crypto::utils::validate_header; #[derive(Arbitrary, Clone, Debug)] struct Input { diff --git a/python/Cargo.toml b/python/Cargo.toml index 317820f7..a94c026d 100644 --- a/python/Cargo.toml +++ b/python/Cargo.toml @@ -1,7 +1,7 @@ [package] name = "devolutions-crypto-python" version.workspace = true -edition = "2021" +edition = "2024" [[bin]] name = "uniffi-bindgen" diff --git a/src/ciphertext/ciphertext_v1.rs b/src/ciphertext/ciphertext_v1.rs index 94e797b5..a47346ea 100644 --- a/src/ciphertext/ciphertext_v1.rs +++ b/src/ciphertext/ciphertext_v1.rs @@ -8,7 +8,7 @@ use super::Ciphertext; use std::convert::TryFrom; use aes::Aes256; -use cbc::cipher::{block_padding::Pkcs7, BlockModeDecrypt, BlockModeEncrypt, KeyIvInit}; +use cbc::cipher::{BlockModeDecrypt, BlockModeEncrypt, KeyIvInit, block_padding::Pkcs7}; use hmac::{Hmac, KeyInit, Mac}; use pbkdf2::pbkdf2; use sha2::Sha256; diff --git a/src/ciphertext/mod.rs b/src/ciphertext/mod.rs index 4b8ad5a8..483bfc8d 100644 --- a/src/ciphertext/mod.rs +++ b/src/ciphertext/mod.rs @@ -642,7 +642,7 @@ fn encrypt_decrypt_aad_v2_test() { #[test] fn asymmetric_test() { - use super::key::{generate_keypair, KeyVersion}; + use super::key::{KeyVersion, generate_keypair}; let test_plaintext = b"this is a test data"; @@ -670,7 +670,7 @@ fn asymmetric_test() { #[test] fn asymmetric_aad_test() { - use super::key::{generate_keypair, KeyVersion}; + use super::key::{KeyVersion, generate_keypair}; let test_plaintext = b"this is a test data"; let aad = b"This is some public data that we want to authenticate"; @@ -709,7 +709,7 @@ fn asymmetric_aad_test() { #[test] fn asymmetric_test_v2() { - use super::key::{generate_keypair, KeyVersion}; + use super::key::{KeyVersion, generate_keypair}; let test_plaintext = b"this is a test data"; @@ -734,7 +734,7 @@ fn asymmetric_test_v2() { #[test] fn asymmetric_aad_test_v2() { - use super::key::{generate_keypair, KeyVersion}; + use super::key::{KeyVersion, generate_keypair}; let test_plaintext = b"this is a test data"; let aad = b"This is some public data that we want to authenticate"; @@ -773,7 +773,7 @@ fn asymmetric_aad_test_v2() { #[test] fn encrypt_decrypt_with_secret_key() { - use super::key::{generate_secret_key, KeyVersion}; + use super::key::{KeyVersion, generate_secret_key}; let data = b"somesecretdata"; let key = generate_secret_key(KeyVersion::Latest); @@ -786,7 +786,7 @@ fn encrypt_decrypt_with_secret_key() { #[test] fn encrypt_decrypt_with_secret_key_aad() { - use super::key::{generate_secret_key, KeyVersion}; + use super::key::{KeyVersion, generate_secret_key}; let data = b"somesecretdata"; let aad = b"somepublicdata"; @@ -801,15 +801,17 @@ fn encrypt_decrypt_with_secret_key_aad() { assert_eq!(decrypted, data); - assert!(encrypted - .decrypt_with_secret_key_and_aad(&key, wrong_aad) - .is_err()); + assert!( + encrypted + .decrypt_with_secret_key_and_aad(&key, wrong_aad) + .is_err() + ); assert!(encrypted.decrypt_with_secret_key(&key).is_err()); } #[test] fn encrypt_decrypt_with_secret_key_v1() { - use super::key::{generate_secret_key, KeyVersion}; + use super::key::{KeyVersion, generate_secret_key}; let data = b"somesecretdata"; let key = generate_secret_key(KeyVersion::Latest); @@ -827,7 +829,7 @@ fn encrypt_decrypt_with_secret_key_v1() { #[test] fn encrypt_decrypt_with_secret_key_v2() { - use super::key::{generate_secret_key, KeyVersion}; + use super::key::{KeyVersion, generate_secret_key}; let data = b"somesecretdata"; let key = generate_secret_key(KeyVersion::Latest); diff --git a/src/derive_encrypt/mod.rs b/src/derive_encrypt/mod.rs index 376acac2..6a25f680 100644 --- a/src/derive_encrypt/mod.rs +++ b/src/derive_encrypt/mod.rs @@ -189,9 +189,9 @@ impl TryFrom<&[u8]> for KdfEncryptedData { #[cfg(test)] mod tests { + use crate::Pbkdf2; use crate::key_derivation::Argon2; use crate::utils::validate_header; - use crate::Pbkdf2; use super::*; @@ -254,9 +254,11 @@ mod tests { ) .unwrap(); - assert!(wrapped - .decrypt_with_password_and_aad(password, b"wrong aad") - .is_err()); + assert!( + wrapped + .decrypt_with_password_and_aad(password, b"wrong aad") + .is_err() + ); } #[test] diff --git a/src/error.rs b/src/error.rs index 9b049669..573919fa 100644 --- a/src/error.rs +++ b/src/error.rs @@ -62,7 +62,9 @@ pub enum Error { #[error("The version is not the same for all the data.")] InconsistentVersion, /// The length of the data to encrypt/decrypt during online encryption is not the same as the chunk size: -43 - #[error("The length of the data to encrypt/decrypt during online encryption is not the same as the chunk size")] + #[error( + "The length of the data to encrypt/decrypt during online encryption is not the same as the chunk size" + )] InvalidChunkLength, /// The mutex is poisoned and cannot be locked: -44 #[error("The mutex is poisoned and cannot be locked")] diff --git a/src/key_derivation/key_derivation_v1.rs b/src/key_derivation/key_derivation_v1.rs index 251c54d9..c5c40031 100644 --- a/src/key_derivation/key_derivation_v1.rs +++ b/src/key_derivation/key_derivation_v1.rs @@ -7,9 +7,9 @@ use zeroize::Zeroizing; use rand::TryRng; -use crate::key::{secret_key_from_raw, SecretKey}; +use crate::key::{SecretKey, secret_key_from_raw}; use crate::utils::derive_key_pbkdf2; -use crate::{Error, Header, KeyDerivationVersion, Result, DEFAULT_PBKDF2_ITERATIONS}; +use crate::{DEFAULT_PBKDF2_ITERATIONS, Error, Header, KeyDerivationVersion, Result}; use super::{DerivationParameters, DerivationParametersPayload}; diff --git a/src/key_derivation/key_derivation_v2.rs b/src/key_derivation/key_derivation_v2.rs index ae4530d8..33e5a896 100644 --- a/src/key_derivation/key_derivation_v2.rs +++ b/src/key_derivation/key_derivation_v2.rs @@ -3,7 +3,7 @@ use std::convert::TryFrom; use zeroize::Zeroizing; -use crate::key::{secret_key_from_raw, SecretKey}; +use crate::key::{SecretKey, secret_key_from_raw}; use crate::{Argon2Parameters, Error, Header, KeyDerivationVersion, Result}; use super::{DerivationParameters, DerivationParametersPayload}; diff --git a/src/key_derivation/mod.rs b/src/key_derivation/mod.rs index ad34f027..3073e06d 100644 --- a/src/key_derivation/mod.rs +++ b/src/key_derivation/mod.rs @@ -41,7 +41,7 @@ use wasm_bindgen::prelude::*; use zeroize::Zeroizing; -use crate::key::{secret_key_from_raw, SecretKey}; +use crate::key::{SecretKey, secret_key_from_raw}; #[cfg(feature = "fuzz")] use crate::Argon2Parameters; @@ -200,8 +200,8 @@ pub fn derive_key( mod tests { use std::convert::TryFrom; - use crate::key::secret_key_from_raw; use crate::Argon2Parameters; + use crate::key::secret_key_from_raw; use super::*; @@ -327,8 +327,8 @@ mod tests { #[test] fn validate_header_rejects_wrong_type() { - use crate::utils::validate_header; use crate::DataType; + use crate::utils::validate_header; let (_, params) = Pbkdf2::with_params(10) .derive_with_salt(b"pw", b"salt_16bytes!!!") .unwrap(); diff --git a/src/lib.rs b/src/lib.rs index 5239d074..ad30436a 100644 --- a/src/lib.rs +++ b/src/lib.rs @@ -292,12 +292,12 @@ pub use enums::{ pub use argon2::Variant as Argon2Variant; pub use argon2::Version as Argon2Version; -pub use argon2parameters::defaults as argon2parameters_defaults; pub use argon2parameters::Argon2Parameters; pub use argon2parameters::Argon2ParametersBuilder; -pub use derive_encrypt::{encrypt_with_password, encrypt_with_password_and_aad, KdfEncryptedData}; +pub use argon2parameters::defaults as argon2parameters_defaults; +pub use derive_encrypt::{KdfEncryptedData, encrypt_with_password, encrypt_with_password_and_aad}; pub use error::{Error, Result}; -pub use key_derivation::{derive_key, Argon2, DerivationParameters, Pbkdf2}; +pub use key_derivation::{Argon2, DerivationParameters, Pbkdf2, derive_key}; pub const DEFAULT_KEY_SIZE: usize = 32; pub const DEFAULT_PBKDF2_ITERATIONS: u32 = 600000; diff --git a/src/utils.rs b/src/utils.rs index 170da938..3990d0b2 100644 --- a/src/utils.rs +++ b/src/utils.rs @@ -1,9 +1,8 @@ //! Module for utils that does not use any of the Devolutions custom data types. use base64::{ - alphabet, + Engine as _, alphabet, engine::{DecodePaddingMode, GeneralPurpose, GeneralPurposeConfig}, - Engine as _, }; use hmac::Hmac; use pbkdf2::pbkdf2; diff --git a/src/wasm.rs b/src/wasm.rs index 970d0147..bf4d9a68 100644 --- a/src/wasm.rs +++ b/src/wasm.rs @@ -3,12 +3,12 @@ use std::convert::{TryFrom as _, TryInto as _}; use js_sys::Array; use wasm_bindgen::prelude::*; +use super::Argon2Parameters; +use super::DEFAULT_PBKDF2_ITERATIONS; +use super::DataType; use super::derive_encrypt; use super::key_derivation::{Argon2, DerivationParameters, Pbkdf2}; use super::utils; -use super::Argon2Parameters; -use super::DataType; -use super::DEFAULT_PBKDF2_ITERATIONS; use super::{ ciphertext, ciphertext::{Ciphertext, CiphertextVersion}, diff --git a/tests/conformity.rs b/tests/conformity.rs index 1109cd50..ebc9f9e2 100644 --- a/tests/conformity.rs +++ b/tests/conformity.rs @@ -1,10 +1,10 @@ -use base64::{engine::general_purpose, Engine as _}; +use base64::{Engine as _, engine::general_purpose}; use devolutions_crypto::{ + Argon2Parameters, KdfEncryptedData, ciphertext::Ciphertext, key::{PrivateKey, SecretKey}, password_hash::PasswordHash, utils::{derive_key_argon2, derive_key_pbkdf2}, - Argon2Parameters, KdfEncryptedData, }; use std::convert::TryFrom as _; diff --git a/uniffi/devolutions-crypto-uniffi/Cargo.toml b/uniffi/devolutions-crypto-uniffi/Cargo.toml index 0d1b3ea1..513e7f0f 100644 --- a/uniffi/devolutions-crypto-uniffi/Cargo.toml +++ b/uniffi/devolutions-crypto-uniffi/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "devolutions-crypto-uniffi" -edition = "2021" +edition = "2024" version.workspace = true [lib] diff --git a/uniffi/uniffi-bindgen/Cargo.toml b/uniffi/uniffi-bindgen/Cargo.toml index 173d744e..eee81bf3 100644 --- a/uniffi/uniffi-bindgen/Cargo.toml +++ b/uniffi/uniffi-bindgen/Cargo.toml @@ -1,7 +1,7 @@ [package] name = "uniffi-bindgen" version = "0.1.0" -edition = "2021" +edition = "2024" publish = false [[bin]]