diff --git a/blake2/CHANGELOG.md b/blake2/CHANGELOG.md index 675474d98..4ca17eec4 100644 --- a/blake2/CHANGELOG.md +++ b/blake2/CHANGELOG.md @@ -5,6 +5,10 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## Unreleased +### Fixed +- Implement `ZeroizeOnDrop` for `Blake2b`/`Blake2s` wrappers ([#912]) + ## 0.11.0 (2026-08-26) ### Added - `zeroize` support ([#545]) diff --git a/blake2/src/lib.rs b/blake2/src/lib.rs index d2ce5524f..76974e095 100644 --- a/blake2/src/lib.rs +++ b/blake2/src/lib.rs @@ -73,6 +73,13 @@ where } } +// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does) +#[cfg(feature = "zeroize")] +impl ZeroizeOnDrop for Blake2b where + OutSize: ArraySize + IsLessOrEqual +{ +} + /// BLAKE2b-128 hasher state. pub type Blake2b128 = Blake2b; /// BLAKE2b-256 hasher state. @@ -121,6 +128,13 @@ where } } +// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does) +#[cfg(feature = "zeroize")] +impl ZeroizeOnDrop for Blake2s where + OutSize: ArraySize + IsLessOrEqual +{ +} + /// BLAKE2s-128 hasher state. pub type Blake2s128 = Blake2s; /// BLAKE2s-256 hasher state. @@ -130,3 +144,21 @@ blake2_mac_impl!(Blake2sMac, Blake2sVarCore, U32, "Blake2s MAC function"); /// BLAKE2s-256 MAC state. pub type Blake2sMac256 = Blake2sMac; + +#[cfg(all(test, feature = "zeroize"))] +mod zeroize_on_drop { + use super::*; + + fn assert_zeroize_on_drop() {} + + #[test] + fn wrappers_impl_zeroize_on_drop() { + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + } +} diff --git a/groestl/CHANGELOG.md b/groestl/CHANGELOG.md index 5986cd5a6..50b220f39 100644 --- a/groestl/CHANGELOG.md +++ b/groestl/CHANGELOG.md @@ -5,6 +5,10 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## Unreleased +### Fixed +- Implement `ZeroizeOnDrop` for `GroestlShort`/`GroestlLong` wrappers + ## 0.11.0 (2026-03-27) ### Added - `alloc` crate feature ([#678]) diff --git a/groestl/src/lib.rs b/groestl/src/lib.rs index 95f5a6160..2e38d85b8 100644 --- a/groestl/src/lib.rs +++ b/groestl/src/lib.rs @@ -18,6 +18,12 @@ mod compress_short; mod table; use digest::consts::{U28, U32, U48, U64}; +#[cfg(feature = "zeroize")] +use digest::{ + array::ArraySize, + typenum::{IsLessOrEqual, True}, + zeroize::ZeroizeOnDrop, +}; digest::buffer_ct_variable!( /// Short Groestl variant generic over output size. @@ -30,6 +36,20 @@ digest::buffer_ct_variable!( max_size: U64; ); +// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does) +#[cfg(feature = "zeroize")] +impl ZeroizeOnDrop for GroestlShort where + OutSize: ArraySize + IsLessOrEqual +{ +} + +// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does) +#[cfg(feature = "zeroize")] +impl ZeroizeOnDrop for GroestlLong where + OutSize: ArraySize + IsLessOrEqual +{ +} + /// Groestl-224 hasher. pub type Groestl224 = GroestlShort; /// Groestl-256 hasher. @@ -39,3 +59,18 @@ pub type Groestl256 = GroestlShort; pub type Groestl384 = GroestlLong; /// Groestl-512 hasher. pub type Groestl512 = GroestlLong; + +#[cfg(all(test, feature = "zeroize"))] +mod zeroize_on_drop { + use super::*; + + fn assert_zeroize_on_drop() {} + + #[test] + fn wrappers_impl_zeroize_on_drop() { + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + } +} diff --git a/kupyna/CHANGELOG.md b/kupyna/CHANGELOG.md index 38b723b87..4aed98a54 100644 --- a/kupyna/CHANGELOG.md +++ b/kupyna/CHANGELOG.md @@ -4,6 +4,10 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## Unreleased +### Fixed +- Implement `ZeroizeOnDrop` for `KupynaShort`/`KupynaLong` wrappers + ## 0.1.0 (2026-03-27) - Initial release ([#621]) diff --git a/kupyna/src/lib.rs b/kupyna/src/lib.rs index 7265846a8..1a8d6e600 100644 --- a/kupyna/src/lib.rs +++ b/kupyna/src/lib.rs @@ -19,6 +19,12 @@ mod table; pub(crate) mod utils; use digest::consts::{U28, U32, U48, U64}; +#[cfg(feature = "zeroize")] +use digest::{ + array::ArraySize, + typenum::{IsLessOrEqual, True}, + zeroize::ZeroizeOnDrop, +}; digest::buffer_ct_variable!( /// Short Kupyna variant generic over output size. @@ -31,6 +37,20 @@ digest::buffer_ct_variable!( max_size: U64; ); +// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does) +#[cfg(feature = "zeroize")] +impl ZeroizeOnDrop for KupynaShort where + OutSize: ArraySize + IsLessOrEqual +{ +} + +// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does) +#[cfg(feature = "zeroize")] +impl ZeroizeOnDrop for KupynaLong where + OutSize: ArraySize + IsLessOrEqual +{ +} + /// Kupyna-224 hasher. pub type Kupyna224 = KupynaShort; /// Kupyna-256 hasher. @@ -39,3 +59,18 @@ pub type Kupyna256 = KupynaShort; pub type Kupyna384 = KupynaLong; /// Kupyna-512 hasher. pub type Kupyna512 = KupynaLong; + +#[cfg(all(test, feature = "zeroize"))] +mod zeroize_on_drop { + use super::*; + + fn assert_zeroize_on_drop() {} + + #[test] + fn wrappers_impl_zeroize_on_drop() { + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + assert_zeroize_on_drop::(); + } +}