Expand description
Entropy sources for secret generation.
The point of this module is a rule that is easy to state and easy to get wrong: hardware entropy is mixed in, never consumed raw.
A physical source can be absent, unplugged mid-read, wedged returning
constant bytes, counterfeit, or deliberately backdoored. If its output were
used directly, anyone who controlled the device would control every key
generated on that machine — strictly worse than the OS RNG the feature was
meant to improve on. Mixing means the result is at least as good as
getrandom no matter what the device does:
output = HKDF-SHA256(ikm = os_bytes ‖ device_bytes, salt = domain, info = purpose)Three consequences, all deliberate:
- The default never changes.
Source::Osis what every generator uses unless a caller asks for something else. - Absence fails closed. A selected device that cannot be read is an error, not a quiet fallback — otherwise the user believes they used the token and did not, which is the one outcome worse than not having the feature.
- Generation only. The vault salt, the Argon2 salt and backup IVs stay on the OS RNG. A salt that depends on a device turns a lost device into a lost vault, and this module exists to reduce risk, not to add a new way to lose everything.
Structs§
- Entropy
Rng - A
RngCoreview over aSource, for crates that generate keys themselves.
Enums§
- Availability
- Result of probing a source without using it.
- Source
- Where the extra entropy comes from.
Functions§
- fill
- Fill
bufwith random bytes fromsource, mixed with OS entropy. - health_
check - Run both health tests, naming which one failed.