@@ -33,16 +33,20 @@ pub(crate) type HmacSha256 = Hmac<Sha256>;
3333
3434/// The message authentication code of a ciphertext.
3535#[ derive( Debug , Clone , PartialEq , Eq ) ]
36+ #[ allow( unreachable_pub) ]
3637pub struct Mac ( pub ( crate ) [ u8 ; Self :: LENGTH ] ) ;
3738
3839impl Mac {
3940 /// The expected length of the message authentication code (MAC).
41+ #[ allow( unreachable_pub) ]
4042 pub const LENGTH : usize = 32 ;
4143 /// The expected length of the message authentication code (MAC) if
4244 /// truncation is applied.
45+ #[ allow( unreachable_pub) ]
4346 pub const TRUNCATED_LEN : usize = 8 ;
4447
4548 /// Truncates and converts the [`Mac`] into a byte array.
49+ #[ allow( unreachable_pub) ]
4650 pub fn truncate ( & self ) -> [ u8 ; Self :: TRUNCATED_LEN ] {
4751 let mut truncated = [ 0u8 ; Self :: TRUNCATED_LEN ] ;
4852 truncated. copy_from_slice ( & self . 0 [ 0 ..Self :: TRUNCATED_LEN ] ) ;
@@ -51,6 +55,7 @@ impl Mac {
5155 }
5256
5357 /// Return the [`Mac`] as a byte slice.
58+ #[ allow( unreachable_pub) ]
5459 pub fn as_bytes ( & self ) -> & [ u8 ] {
5560 self . 0 . as_ref ( )
5661 }
@@ -63,7 +68,7 @@ pub(crate) enum MessageMac {
6368}
6469
6570impl MessageMac {
66- pub fn as_bytes ( & self ) -> & [ u8 ] {
71+ pub ( crate ) fn as_bytes ( & self ) -> & [ u8 ] {
6772 match self {
6873 MessageMac :: Truncated ( m) => m. as_ref ( ) ,
6974 MessageMac :: Full ( m) => m. as_bytes ( ) ,
@@ -94,6 +99,7 @@ pub enum DecryptionError {
9499}
95100
96101/// A cipher used for encrypting and decrypting messages.
102+ #[ allow( unreachable_pub) ]
97103pub struct Cipher {
98104 keys : CipherKeys ,
99105}
@@ -107,6 +113,7 @@ impl Cipher {
107113 ///
108114 /// This key derivation format is typically used for generating individual
109115 /// message keys in the Olm double ratchet.
116+ #[ allow( unreachable_pub) ]
110117 pub fn new ( key : & [ u8 ; 32 ] ) -> Self {
111118 let keys = CipherKeys :: new ( key) ;
112119
@@ -122,6 +129,7 @@ impl Cipher {
122129 ///
123130 /// This key derivation format is typically used for generating individual
124131 /// message keys in the Megolm ratchet.
132+ #[ allow( unreachable_pub) ]
125133 pub fn new_megolm ( & key: & [ u8 ; 128 ] ) -> Self {
126134 let keys = CipherKeys :: new_megolm ( & key) ;
127135
@@ -138,6 +146,7 @@ impl Cipher {
138146 ///
139147 /// This key derivation format is typically used for libolm-compatible
140148 /// encrypted pickle formats.
149+ #[ allow( unreachable_pub) ]
141150 pub fn new_pickle ( key : & [ u8 ] ) -> Self {
142151 let keys = CipherKeys :: new_pickle ( key) ;
143152
@@ -160,6 +169,7 @@ impl Cipher {
160169 /// **Warning**: This is a low-level function and does not provide
161170 /// authentication for the ciphertext. You must call [`Cipher::mac()`]
162171 /// separately to generate the message authentication code (MAC).
172+ #[ allow( unreachable_pub) ]
163173 pub fn encrypt ( & self , plaintext : & [ u8 ] ) -> Vec < u8 > {
164174 let cipher = Aes256CbcEnc :: new ( self . keys . aes_key ( ) , self . keys . iv ( ) ) ;
165175 cipher. encrypt_padded_vec :: < Pkcs7 > ( plaintext)
@@ -170,6 +180,7 @@ impl Cipher {
170180 /// **Warning**: This is a low-level function and must be called after the
171181 /// [`Cipher::encrypt`] method. The ciphertext produced by
172182 /// [`Cipher::encrypt`] must be passed as the argument to this method.
183+ #[ allow( unreachable_pub) ]
173184 pub fn mac ( & self , message : & [ u8 ] ) -> Mac {
174185 let mut hmac = self . get_hmac ( ) ;
175186 hmac. update ( message) ;
@@ -187,6 +198,7 @@ impl Cipher {
187198 /// **Warning**: This is a low-level function. Before calling this, you must
188199 /// call [`Cipher::verify_mac()`] or [`Cipher::verify_truncated_mac()`]
189200 /// to ensure the integrity of the ciphertext.
201+ #[ allow( unreachable_pub) ]
190202 pub fn decrypt ( & self , ciphertext : & [ u8 ] ) -> Result < Vec < u8 > , UnpadError > {
191203 let cipher = Aes256CbcDec :: new ( self . keys . aes_key ( ) , self . keys . iv ( ) ) ;
192204 cipher. decrypt_padded_vec :: < Pkcs7 > ( ciphertext)
@@ -198,6 +210,7 @@ impl Cipher {
198210 /// **Warning**: This is a low-level function and must be called before
199211 /// invoking the [`Cipher::decrypt()`] method.
200212 #[ cfg( all( not( fuzzing) , feature = "experimental-session-config" ) ) ]
213+ #[ allow( unreachable_pub) ]
201214 pub fn verify_mac ( & self , message : & [ u8 ] , tag : & Mac ) -> Result < ( ) , MacError > {
202215 let mut hmac = self . get_hmac ( ) ;
203216
@@ -211,6 +224,7 @@ impl Cipher {
211224 /// **Warning**: This is a low-level function and must be called before
212225 /// invoking the [`Cipher::decrypt()`] method.
213226 #[ cfg( not( fuzzing) ) ]
227+ #[ allow( unreachable_pub) ]
214228 pub fn verify_truncated_mac ( & self , message : & [ u8 ] , tag : & [ u8 ] ) -> Result < ( ) , MacError > {
215229 let mut hmac = self . get_hmac ( ) ;
216230
@@ -251,6 +265,7 @@ impl Cipher {
251265 /// message authentication tag to it.
252266 ///
253267 /// This follows the encryption method used by the libolm pickle format.
268+ #[ allow( unreachable_pub) ]
254269 pub fn encrypt_pickle ( & self , plaintext : & [ u8 ] ) -> Vec < u8 > {
255270 let mut ciphertext = self . encrypt ( plaintext) ;
256271 let mac = self . mac ( & ciphertext) ;
@@ -267,6 +282,7 @@ impl Cipher {
267282 /// MAC before decrypting the ciphertext.
268283 ///
269284 /// This follows the encryption method used by the libolm pickle format.
285+ #[ allow( unreachable_pub) ]
270286 pub fn decrypt_pickle ( & self , ciphertext : & [ u8 ] ) -> Result < Vec < u8 > , DecryptionError > {
271287 if ciphertext. len ( ) < Mac :: TRUNCATED_LEN + 1 {
272288 Err ( DecryptionError :: MacMissing )
0 commit comments