crypt

package
v0.4.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: MIT Imports: 5 Imported by: 0

Documentation

Overview

Package crypt implements the files byte-layer cipher: whole-file AES-256-CFB with a zero IV and a random per-file key — the exact format anytype-heart writes (cfb.New(key, [aes.BlockSize]byte{})), so ciphertext and the derived UnixFS cids stay byte-compatible.

A zero IV is safe here because a file key is generated fresh per file and never reused; integrity comes from the merkle cids over the ciphertext, not from the cipher (CFB carries no tags). Readers must therefore only feed cid-verified bytes into a decryptor.

Index

Constants

View Source
const KeySize = 32

KeySize is the AES-256 key length in bytes.

Variables

View Source
var ErrBadKey = errors.New("crypt: key must be 32 bytes")

ErrBadKey is returned for a key of the wrong length.

Functions

func NewEncryptReader

func NewEncryptReader(key []byte, r io.Reader) (io.Reader, error)

NewEncryptReader wraps r so reads return the AES-256-CFB ciphertext of its bytes (zero IV). Single forward pass; the stream state makes it single-use.

Types

type Reader

type Reader struct {
	// contains filtered or unexported fields
}

Reader decrypts an AES-256-CFB ciphertext stream with random access. Seek re-keys the stream from the ciphertext block boundary before the target offset: the 16 ciphertext bytes preceding the aligned position are the IV, so decryption never restarts from zero (ports anytype-heart's cfb.CFBDecryptor).

The underlying ciphertext reader must serve only cid-verified bytes; Reader adds no integrity of its own.

func NewReader

func NewReader(key []byte, ct io.ReadSeeker) (*Reader, error)

NewReader positions a Reader at plaintext offset 0.

func (*Reader) Read

func (r *Reader) Read(p []byte) (int, error)

func (*Reader) Seek

func (r *Reader) Seek(offset int64, whence int) (int64, error)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL