[Summary]
StormByte Crypto is the cryptography module of the StormByte C++ suite.
It depends on StormByte Base ≥ 2.0.0, StormByte Buffer ≥ 2.0.0 and StormByte System ≥ 2.0.0. This repository is not Base, Buffer, Config, Database, Logger, Multimedia, Network or System.
Public headers under StormByte/crypto/ cover Hasher, Compressor, Crypter (symmetric and asymmetric), Signer, Secret, KeyPair, Password and Vault. Crypto++ never leaves the private tree.
If you landed here from a release link and have not read the tree:
- What this module is, how to build it, and short examples: README.md
- License: GNU Lesser General Public License version 3 or later, LICENSE
Changed
- Exception message constructors now accept
std::string_view; exception copy/move special members are defined out of line in their owning Crypto DLLs. - Port public text to Base's
StormByte::Safe::Stringand polymorphic ownership toStormByte::Safe::Clonable/Safe::Shared; Password accepts mutablestd::string&for wipeable caller-owned input. - Updated repository links to the StormByte-Suite organization and removed documentation for the retired standalone dependency.
- Shared vs static follows CMake
BUILD_SHARED_LIBS(declared in the project root, default ON). There is noSTORMBYTE_CRYPTO_SHAREDCMake option. When the library is shared, the compile definitionSTORMBYTE_CRYPTO_SHAREDis still set sovisibility.hcan distinguishdllexport/dllimport/ static. CI passes-DBUILD_SHARED_LIBS=ON. Vendored Crypto++ and BZip2 stay static BM components; their archives are closed onto consumers by the static sidecar. - Breaking: Port to StormByte Base 2.0.0, Buffer 2.0.0 and System 2.0.0. Public types follow Base 2.0:
Clonable+MakePointer/Sharedinstead ofstd::shared_ptr,StormByte::BinaryDatainstead of BufferDataType/ raw vectors at the public edge,StormByte::Sizefor abstract counts andStormByte::ByteSizefor octet lengths (Password::Size()isByteSize).std::sizeis gone from the public API. - Breaking: Exceptions no longer use
StormByte::Component.Crypto::ExceptionforwardsPath{"Crypto"}toStormByte::Exception. Per-office exceptions (Compressor::Exception,Crypter::Exception,Hasher::Exception,KeyPair::Exception,Secret::Exception,Signer::Exception) live in their own namespace and add only their own segment; Crypto concatenates before forwarding.what()isStormByte.CryptoorStormByte.Crypto.<Child>: message. - Breaking: Buffer 2.0 streaming contract. Block I/O is
std::span<const std::byte>intoBuffer::WriteOnly. Pipelines takeBuffer::Consumerand return a consumer;FIFO::Data()isBinaryData. - Breaking: Factories and keypair / signer / crypter / secret constructors take
KeyPair::Generic::PointerType(Safe::Shared), notstd::shared_ptr. Generate / Load return that pointer type.Safe::Clonable::MakePointeris used for public-only views. - Breaking: Public leaf classes are
final. Destructors of public types are declared in the header and defined out of line in the.cxx(= default) so the vtable and typeinfo stay on this side of the DLL. - Breaking: Non-secret public text is ingested as
std::string_viewand copied inside the library. That includes KeyPair leaf constructors,Secret::Share, Vault names (Store/Get/Contains/Remove),KeyPair::Generic::SavebaseName, andSigner::Verify/DoVerifysignatures.StormByte::Safe::Stringandstd::stringconvert tostring_view. Owned public text (PublicKey()) isconst StormByte::Safe::String&. Conversion tostd::stringis explicit (std::string{std::string_view{...}}). - Breaking:
Passwordno longer takesstd::stringby value. Ingest is a non-conststd::string&; the bytes are copied into wiped storage and the caller's object is overwritten and cleared. Literals useexplicit Password(const char*)and are not wiped. Raw bytes (const void*+ByteSize) are copied and not wiped.string_viewis rejected so a live password buffer cannot remain in the caller after construction, and so astd::stringis not moved across the DLL heap. - Breaking:
PasswordandVaultmove toStormByte::Crypto::Secure(StormByte/crypto/secure/{password,vault,exception}.{hxx,cxx}).Crypto::VaultExceptionis nowCrypto::Secure::VaultException(what()isStormByte.Crypto.Secure.Vault: message).Secure::ExceptionisStormByte.Crypto.Secure.ExpectedPasswordlives next to Vault. HeadersStormByte/crypto/password.hxxandStormByte/crypto/vault.hxxare gone. - Breaking: Private backend namespace
ImplementationisEngine(StormByte::Crypto::Engine). Public headers do not mention it. - Dual license on sources and
LICENSE: LGPL-3.0-or-later or commercial. Neither covers Crypto++, bundled libbzip2, or vendored StormByte trees underthirdparty/. - Tests rewritten to the suite format (section headers, snake_case functions, accumulating
main). Coverage of hasher, compressor, crypter, signer, secret, password, vault and keypair (save/load and OpenSSL fixtures) updated to the new pins. - Hybrid encrypt/decrypt tests compare plaintext with
std::string::operator==(ASSERT_TRUE), notASSERT_EQUAL. The harness C-string path false-failed prefix+4096 payloads on Ubuntu clang while the bytes already matched. - Doxygen (
ENABLE_DOC) resolves Buffer, Logger, System and Base headers viaINCLUDE_PATHand skipsthirdparty. CONTRIBUTING.mdandCODING_STYLE.mdaligned with Logger.
Notes
- Installed headers still do not include Crypto++. Crypto++ stays under
lib/privateandthirdparty. - Needs a C++26 compiler, StormByte Base ≥ 2.0.0, StormByte Buffer ≥ 2.0.0, StormByte System ≥ 2.0.0, and Crypto++ at build time.