Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions blake2/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## Unreleased
### Fixed
- Implement `ZeroizeOnDrop` for `Blake2b`/`Blake2s` wrappers ([#912])

## 0.11.0 (2026-08-26)
### Added
- `zeroize` support ([#545])
Expand Down
32 changes: 32 additions & 0 deletions blake2/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -73,6 +73,13 @@ where
}
}

// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does)
#[cfg(feature = "zeroize")]
impl<OutSize> ZeroizeOnDrop for Blake2b<OutSize> where
OutSize: ArraySize + IsLessOrEqual<U64, Output = True>
{
}

/// BLAKE2b-128 hasher state.
pub type Blake2b128 = Blake2b<U16>;
/// BLAKE2b-256 hasher state.
Expand Down Expand Up @@ -121,6 +128,13 @@ where
}
}

// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does)
#[cfg(feature = "zeroize")]
impl<OutSize> ZeroizeOnDrop for Blake2s<OutSize> where
OutSize: ArraySize + IsLessOrEqual<U32, Output = True>
{
}

/// BLAKE2s-128 hasher state.
pub type Blake2s128 = Blake2s<U16>;
/// BLAKE2s-256 hasher state.
Expand All @@ -130,3 +144,21 @@ blake2_mac_impl!(Blake2sMac, Blake2sVarCore, U32, "Blake2s MAC function");

/// BLAKE2s-256 MAC state.
pub type Blake2sMac256 = Blake2sMac<U32>;

#[cfg(all(test, feature = "zeroize"))]
mod zeroize_on_drop {
use super::*;

fn assert_zeroize_on_drop<T: ZeroizeOnDrop>() {}

#[test]
fn wrappers_impl_zeroize_on_drop() {
assert_zeroize_on_drop::<Blake2b128>();
assert_zeroize_on_drop::<Blake2b256>();
assert_zeroize_on_drop::<Blake2b512>();
assert_zeroize_on_drop::<Blake2s128>();
assert_zeroize_on_drop::<Blake2s256>();
assert_zeroize_on_drop::<Blake2bMac512>();
assert_zeroize_on_drop::<Blake2sMac256>();
}
}
4 changes: 4 additions & 0 deletions groestl/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## Unreleased
### Fixed
- Implement `ZeroizeOnDrop` for `GroestlShort`/`GroestlLong` wrappers

## 0.11.0 (2026-03-27)
### Added
- `alloc` crate feature ([#678])
Expand Down
35 changes: 35 additions & 0 deletions groestl/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,12 @@ mod compress_short;
mod table;

use digest::consts::{U28, U32, U48, U64};
#[cfg(feature = "zeroize")]
use digest::{
array::ArraySize,
typenum::{IsLessOrEqual, True},
zeroize::ZeroizeOnDrop,
};

digest::buffer_ct_variable!(
/// Short Groestl variant generic over output size.
Expand All @@ -30,6 +36,20 @@ digest::buffer_ct_variable!(
max_size: U64;
);

// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does)
#[cfg(feature = "zeroize")]
impl<OutSize> ZeroizeOnDrop for GroestlShort<OutSize> where
OutSize: ArraySize + IsLessOrEqual<U32, Output = True>
{
}

// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does)
#[cfg(feature = "zeroize")]
impl<OutSize> ZeroizeOnDrop for GroestlLong<OutSize> where
OutSize: ArraySize + IsLessOrEqual<U64, Output = True>
{
}

/// Groestl-224 hasher.
pub type Groestl224 = GroestlShort<U28>;
/// Groestl-256 hasher.
Expand All @@ -39,3 +59,18 @@ pub type Groestl256 = GroestlShort<U32>;
pub type Groestl384 = GroestlLong<U48>;
/// Groestl-512 hasher.
pub type Groestl512 = GroestlLong<U64>;

#[cfg(all(test, feature = "zeroize"))]
mod zeroize_on_drop {
use super::*;

fn assert_zeroize_on_drop<T: ZeroizeOnDrop>() {}

#[test]
fn wrappers_impl_zeroize_on_drop() {
assert_zeroize_on_drop::<Groestl224>();
assert_zeroize_on_drop::<Groestl256>();
assert_zeroize_on_drop::<Groestl384>();
assert_zeroize_on_drop::<Groestl512>();
}
}
4 changes: 4 additions & 0 deletions kupyna/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## Unreleased
### Fixed
- Implement `ZeroizeOnDrop` for `KupynaShort`/`KupynaLong` wrappers

## 0.1.0 (2026-03-27)
- Initial release ([#621])

Expand Down
35 changes: 35 additions & 0 deletions kupyna/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,12 @@ mod table;
pub(crate) mod utils;

use digest::consts::{U28, U32, U48, U64};
#[cfg(feature = "zeroize")]
use digest::{
array::ArraySize,
typenum::{IsLessOrEqual, True},
zeroize::ZeroizeOnDrop,
};

digest::buffer_ct_variable!(
/// Short Kupyna variant generic over output size.
Expand All @@ -31,6 +37,20 @@ digest::buffer_ct_variable!(
max_size: U64;
);

// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does)
#[cfg(feature = "zeroize")]
impl<OutSize> ZeroizeOnDrop for KupynaShort<OutSize> where
OutSize: ArraySize + IsLessOrEqual<U32, Output = True>
{
}

// TODO: impl in the `buffer_ct_variable!` macro (as `buffer_fixed!` already does)
#[cfg(feature = "zeroize")]
impl<OutSize> ZeroizeOnDrop for KupynaLong<OutSize> where
OutSize: ArraySize + IsLessOrEqual<U64, Output = True>
{
}

/// Kupyna-224 hasher.
pub type Kupyna224 = KupynaShort<U28>;
/// Kupyna-256 hasher.
Expand All @@ -39,3 +59,18 @@ pub type Kupyna256 = KupynaShort<U32>;
pub type Kupyna384 = KupynaLong<U48>;
/// Kupyna-512 hasher.
pub type Kupyna512 = KupynaLong<U64>;

#[cfg(all(test, feature = "zeroize"))]
mod zeroize_on_drop {
use super::*;

fn assert_zeroize_on_drop<T: ZeroizeOnDrop>() {}

#[test]
fn wrappers_impl_zeroize_on_drop() {
assert_zeroize_on_drop::<Kupyna224>();
assert_zeroize_on_drop::<Kupyna256>();
assert_zeroize_on_drop::<Kupyna384>();
assert_zeroize_on_drop::<Kupyna512>();
}
}
Loading