Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -365,8 +365,9 @@ The former C 3DES helper and C PIV protocol parsers have been removed.
- `src/backend/`: PC/SC lifetime, the bounded synchronous libcanokey executor,
typed result conversion and public cache/profile coordination.
- `src/internal/`: host hashing/padding/crypto, templates, logging and mutexes.
- `rust/`: private static linkage to the exact pinned libcanokey C ABI. Rust owns
PIV APDUs, formats, credentials, management crypto and firmware compatibility.
- `rust/`: private static linkage to the published crates.io canokey-c C ABI.
Rust owns PIV APDUs, formats, credentials, management crypto and firmware
compatibility.

PIV object IDs map to slots as:

Expand Down
33 changes: 22 additions & 11 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ path = "rust/lib.rs"
crate-type = ["staticlib"]

[dependencies]
canokey-c = { git = "https://github.com/canokeys/libcanokey", rev = "b709b3dfe30402e4c6224949b20185bc809ec7e8", default-features = false, features = ["piv"] }
canokey-c = { version = "0.1.0", default-features = false, features = ["piv"] }

[profile.release]
lto = "thin"
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,8 +21,8 @@ GCC should be supported, but is not tested.

This experimental branch also requires CMake 3.20+ and the latest stable Rust
via rustup. Cargo builds the private protocol adapter as a static library;
`Cargo.toml` pins libcanokey by Git revision and `Cargo.lock` pins its transitive
dependencies. There is no libcanokey submodule or Rust DLL. Existing C crypto
`Cargo.toml` selects the published `canokey-c` crate from crates.io and
`Cargo.lock` pins its transitive dependencies. There is no libcanokey submodule or Rust DLL. Existing C crypto
and synchronization submodules are still needed. See
[the migration status and acceptance plan](docs/libcanokey-piv-migration-plan.md) for the remaining PIV work.

Expand Down
2 changes: 1 addition & 1 deletion cmake/libcanokey.cmake
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Cargo owns the pinned Git dependency; no source checkout/submodule is needed.
# Cargo owns the crates.io canokey-c dependency; no source checkout/submodule is needed.
find_program(CNK_CARGO cargo HINTS "$ENV{USERPROFILE}/.cargo/bin" "$ENV{HOME}/.cargo/bin" REQUIRED)
find_program(CNK_RUSTC rustc HINTS "$ENV{USERPROFILE}/.cargo/bin" "$ENV{HOME}/.cargo/bin" REQUIRED)

Expand Down
4 changes: 2 additions & 2 deletions docs/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -151,7 +151,7 @@ Both credential mutations revoke host credentials/private contexts on attempted

## Build and diagnostics

Cargo.toml pins libcanokey; Cargo.lock pins its dependency closure. The private Rust
Cargo.toml selects the published crates.io canokey-c crate; Cargo.lock pins its dependency closure. The private Rust
static library is linked into the existing DLL, with no Rust DLL or submodule.
ThinLTO and function/data section collection remove unused code. PIV-only C ABI
features exclude unrelated applets; host crypto, curves and Rust runtime still
Expand Down Expand Up @@ -204,7 +204,7 @@ prehash case (RustCrypto's half-field minimum is 33 bytes). These experiments we
not retained: Rust hash/ECDSA APIs need explicit compatibility adaptation and a
measured benefit before replacing the existing host backend. RSA and PQC stay put.

The dependency follows merged libcanokey main (b709b3d). PIV-only C ABI features
The dependency is the published crates.io canokey-c release (currently 0.1.0). PIV-only C ABI features
remain selected; NDEF/CTAP facade modules do not opt this consumer into ClientPIN
or expose additional PKCS11 operations. The error POD retains its size and uses
its formerly reserved byte for optional applet status; diagnostics preserve that
Expand Down
Loading