lib.rs 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564
  1. // We really want points to be capital letters and scalars to be
  2. // lowercase letters
  3. #![allow(non_snake_case)]
  4. #![doc = include_str!("../README.md")]
  5. pub use cmz_derive::*;
  6. use core::any::Any;
  7. use ff::{Field, PrimeField};
  8. use generic_static::StaticTypeMap;
  9. use group::prime::PrimeGroup;
  10. use group::{Group, GroupEncoding};
  11. #[cfg(feature = "wnaf_is_constant_time")]
  12. use group::{WnafBase, WnafScalar};
  13. use lazy_static::lazy_static;
  14. use rand::RngCore;
  15. use serde::{Deserialize, Deserializer, Serialize, Serializer};
  16. pub use serde_with::serde_as;
  17. use serde_with::{DeserializeAs, SerializeAs};
  18. use sigma_compiler::*;
  19. pub use sigma_compiler::{self};
  20. use thiserror::Error;
  21. // We need wrappers for group::Group and ff::PrimeField elements to be
  22. // handled by serde
  23. //
  24. // Pattern from https://docs.rs/serde_with/3.12.0/serde_with/guide/serde_as/index.html
  25. mod group_serde;
  26. /// A wrapper for serializing and deserializing a `Scalar`
  27. pub struct SerdeScalar;
  28. impl<F: PrimeField> SerializeAs<F> for SerdeScalar {
  29. fn serialize_as<S>(value: &F, serializer: S) -> Result<S::Ok, S::Error>
  30. where
  31. S: Serializer,
  32. {
  33. group_serde::serialize_scalar(value, serializer)
  34. }
  35. }
  36. impl<'de, F: PrimeField> DeserializeAs<'de, F> for SerdeScalar {
  37. fn deserialize_as<D>(deserializer: D) -> Result<F, D::Error>
  38. where
  39. D: Deserializer<'de>,
  40. {
  41. group_serde::deserialize_scalar(deserializer)
  42. }
  43. }
  44. /// A wrapper for serializing and deserializing a `Point` (a group
  45. /// element)
  46. pub struct SerdePoint;
  47. impl<G: Group + GroupEncoding> SerializeAs<G> for SerdePoint {
  48. fn serialize_as<S>(value: &G, serializer: S) -> Result<S::Ok, S::Error>
  49. where
  50. S: Serializer,
  51. {
  52. group_serde::serialize_point(value, serializer)
  53. }
  54. }
  55. impl<'de, G: Group + GroupEncoding> DeserializeAs<'de, G> for SerdePoint {
  56. fn deserialize_as<D>(deserializer: D) -> Result<G, D::Error>
  57. where
  58. D: Deserializer<'de>,
  59. {
  60. group_serde::deserialize_point(deserializer)
  61. }
  62. }
  63. /// The CMZMac struct represents a MAC on a CMZ credential.
  64. #[serde_as]
  65. #[derive(Copy, Clone, Debug, Default, PartialEq, Serialize, Deserialize)]
  66. pub struct CMZMac<G: PrimeGroup> {
  67. #[serde_as(as = "SerdePoint")]
  68. pub P: G,
  69. #[serde_as(as = "SerdePoint")]
  70. pub Q: G,
  71. }
  72. /// The CMZPrivkey struct represents a CMZ private key
  73. #[serde_as]
  74. #[derive(Clone, Debug, Default, PartialEq, Serialize, Deserialize)]
  75. pub struct CMZPrivkey<G: PrimeGroup> {
  76. // Is this key for µCMZ or classic CMZ14?
  77. pub muCMZ: bool,
  78. #[serde_as(as = "SerdeScalar")]
  79. pub x0: <G as Group>::Scalar,
  80. // The next field is xr for µCMZ, and serves the role of x0tilde for
  81. // CMZ14
  82. #[serde_as(as = "SerdeScalar")]
  83. pub xr: <G as Group>::Scalar,
  84. // The elements of x correspond to the attributes of the credential
  85. #[serde_as(as = "Vec<SerdeScalar>")]
  86. pub x: Vec<<G as Group>::Scalar>,
  87. }
  88. /// The CMZPubkey struct represents a CMZ public key
  89. #[serde_as]
  90. #[derive(Clone, Debug, Default, PartialEq, Serialize, Deserialize)]
  91. pub struct CMZPubkey<G: PrimeGroup> {
  92. #[serde_as(as = "Option<SerdePoint>")]
  93. pub X0: Option<G>,
  94. // Xr is only used for µCMZ, not CMZ14 (where it will be None)
  95. #[serde_as(as = "Option<SerdePoint>")]
  96. pub Xr: Option<G>,
  97. // The elements of X correspond to the attributes of the credential
  98. #[serde_as(as = "Vec<SerdePoint>")]
  99. pub X: Vec<G>,
  100. }
  101. // The size of the WNAF windows. Larger sizes take more memory, but
  102. // result in faster multiplications.
  103. #[cfg(feature = "wnaf_is_constant_time")]
  104. const WNAF_SIZE: usize = 6;
  105. /// A struct (generic over G) holding the two CMZ bases, and their Wnaf
  106. /// basepoint tables
  107. #[derive(Clone)]
  108. pub struct CMZBasepoints<G: Group> {
  109. A_: G,
  110. B_: G,
  111. #[cfg(feature = "wnaf_is_constant_time")]
  112. A_TABLE: WnafBase<G, WNAF_SIZE>,
  113. #[cfg(feature = "wnaf_is_constant_time")]
  114. B_TABLE: WnafBase<G, WNAF_SIZE>,
  115. }
  116. impl<G: Group> CMZBasepoints<G> {
  117. pub fn init(generator_A: G) -> Self {
  118. let A_ = generator_A;
  119. let B_ = G::generator();
  120. #[cfg(feature = "wnaf_is_constant_time")]
  121. let A_TABLE = WnafBase::new(A_);
  122. #[cfg(feature = "wnaf_is_constant_time")]
  123. let B_TABLE = WnafBase::new(B_);
  124. CMZBasepoints {
  125. A_,
  126. B_,
  127. #[cfg(feature = "wnaf_is_constant_time")]
  128. A_TABLE,
  129. #[cfg(feature = "wnaf_is_constant_time")]
  130. B_TABLE,
  131. }
  132. }
  133. #[cfg(feature = "wnaf_is_constant_time")]
  134. pub fn mulA(&self, s: &G::Scalar) -> G {
  135. let wnaf_s = WnafScalar::<G::Scalar, WNAF_SIZE>::new(s);
  136. &self.A_TABLE * &wnaf_s
  137. }
  138. #[cfg(feature = "wnaf_is_constant_time")]
  139. pub fn mulB(&self, s: &G::Scalar) -> G {
  140. let wnaf_s = WnafScalar::<G::Scalar, WNAF_SIZE>::new(s);
  141. &self.B_TABLE * &wnaf_s
  142. }
  143. #[cfg(not(feature = "wnaf_is_constant_time"))]
  144. pub fn mulA(&self, s: &G::Scalar) -> G {
  145. self.A_ * s
  146. }
  147. #[cfg(not(feature = "wnaf_is_constant_time"))]
  148. pub fn mulB(&self, s: &G::Scalar) -> G {
  149. self.B_ * s
  150. }
  151. pub fn keypairA(&self, rng: &mut impl RngCore) -> (G::Scalar, G) {
  152. let x = G::Scalar::random(&mut *rng);
  153. (x, self.mulA(&x))
  154. }
  155. pub fn keypairB(&self, rng: &mut impl RngCore) -> (G::Scalar, G) {
  156. let x = G::Scalar::random(&mut *rng);
  157. (x, self.mulB(&x))
  158. }
  159. pub fn A(&self) -> G {
  160. self.A_
  161. }
  162. pub fn B(&self) -> G {
  163. self.B_
  164. }
  165. }
  166. // What's going on here needs some explanation. For each group G, we
  167. // want to pre-compute the WnafBase tables in a [`CMZBasepoints`] struct,
  168. // and we want that pre-computed struct to remain globally accessible.
  169. // So ideally, we'd just have a generic static CMZBasepoints<G> struct,
  170. // and instantiate it once for each G that we use.
  171. //
  172. // The tricky bit is that we don't know what group(s) G the programmer
  173. // (the person using this cmz crate) will end up using, and Rust doesn't
  174. // support generic statics.
  175. //
  176. // So what we'd like is a non-generic static _map_ that maps a group
  177. // type G to the precomputed CMZBasepoints<G> struct. But types aren't
  178. // values that can be mapped by a normal HashMap. Luckily, there's a
  179. // generic_static crate that provides a StaticTypeMap that has the
  180. // ability to map types to objects.
  181. //
  182. // However, all of those *mapped-to* objects have to all be of the same
  183. // type, whereas we want the type G to map to a struct of type
  184. // CMZBasepoints<G>, which is different for each value of G.
  185. //
  186. // So we make a non-generic trait CMZbp that all instantiations of
  187. // CMZBasepoints<G> implement (for all group types G), and have the
  188. // StaticTypeMap map each type G to a trait object Box<dyn CMZbp>.
  189. //
  190. // Then to read the CMZBasepoints<G> back out, we look up the trait
  191. // object in the StaticTypeMap, yielding a Box<dyn CMZbp>. We now need
  192. // to downcast this trait object to the concrete type CMZBasepoints<G>,
  193. // for a _specific_ G. Rust provides downcasting, but only from &dyn Any
  194. // to the original concrete type, not from other things like &dyn CMZbp.
  195. // So first we need to upcast the trait object to &dyn Any, which we do
  196. // with an "as_any()" function in the CMZbp trait, and then downcast the
  197. // result to a CMZBasepoints<G> struct.
  198. //
  199. // The up/down casting pattern is from
  200. // https://stackoverflow.com/questions/33687447/how-to-get-a-reference-to-a-concrete-type-from-a-trait-object
  201. // Static objects have to be Sync + Send, so enforce that as part of the
  202. // CMXBP trait
  203. trait CMZbp: Sync + Send {
  204. fn as_any(&self) -> &dyn Any;
  205. }
  206. impl<G: Group> CMZbp for CMZBasepoints<G> {
  207. fn as_any(&self) -> &dyn Any {
  208. self
  209. }
  210. }
  211. // The StaticTypeMap mapping group types G to trait objects Box<dyn CMZbp>
  212. lazy_static! {
  213. static ref basepoints_map: StaticTypeMap<Box<dyn CMZbp>> = StaticTypeMap::new();
  214. }
  215. /// For a given group type `G`, if `bp` is `Some(b)`, then load the
  216. /// mapping from `G` to `b` into the `basepoints_map`. (If a mapping
  217. /// from `G` already exists, the old one will be kept and the new one
  218. /// ignored.) Whether `bp` is `Some(b)` or `None`, this function
  219. /// returns the (possibly new) target of the `basepoints_map`, as a
  220. /// `&'static CMZBasepoints<G>`.
  221. fn load_bp<G: Group>(bp: Option<CMZBasepoints<G>>) -> &'static CMZBasepoints<G> {
  222. match bp {
  223. Some(b) => basepoints_map.call_once::<G, _>(|| Box::new(b.clone())),
  224. None => basepoints_map.call_once::<G, _>(|| panic!("basepoints uninitialized")),
  225. }
  226. .as_any()
  227. .downcast_ref::<CMZBasepoints<G>>()
  228. .unwrap()
  229. }
  230. /// Initialize the required second generator for a `PrimeGroup`.
  231. ///
  232. /// CMZ credentials require two generators, `A` and `B`. `B` is the
  233. /// "standard" generator. A can be any other generator (that is, any
  234. /// other non-identity point in a prime-order group), but it is required
  235. /// that no one know the discrete log between `A` and `B`. So you can't
  236. /// generate `A` by multiplying `B` by some scalar, for example. If your
  237. /// group has a hash_from_bytes function, then you can use that to generate
  238. /// `A`. For example, if your group is a curve25519 group, you can
  239. ///
  240. /// ```
  241. /// use curve25519_dalek::constants::RISTRETTO_BASEPOINT_POINT as B;
  242. /// use curve25519_dalek::ristretto::RistrettoPoint as G;
  243. /// use sha2::Sha512;
  244. /// let A = G::hash_from_bytes::<Sha512>(b"CMZ Generator A");
  245. /// assert_ne!(A, B);
  246. /// ```
  247. ///
  248. /// Otherwise, you're possibly on your own to generate an appropriate
  249. /// generator `A`. Everyone who uses a given credential type with a
  250. /// given group will need to use the same `A`. You need to call this
  251. /// before doing any operations with a credential.
  252. pub fn cmz_group_init<G: PrimeGroup>(generator_A: G) {
  253. let bp = CMZBasepoints::<G>::init(generator_A);
  254. load_bp(Some(bp));
  255. }
  256. /// Get the loaded CMZBasepoints for the given group
  257. pub fn cmz_basepoints<G: PrimeGroup>() -> &'static CMZBasepoints<G> {
  258. load_bp(None)
  259. }
  260. /// Compute a public key from a private key
  261. pub fn cmz_privkey_to_pubkey<G: PrimeGroup>(privkey: &CMZPrivkey<G>) -> CMZPubkey<G> {
  262. let bp = load_bp::<G>(None);
  263. let X0: Option<G> = if privkey.muCMZ {
  264. Some(bp.mulB(&privkey.x0))
  265. } else {
  266. Some(bp.mulA(&privkey.xr) + bp.mulB(&privkey.x0))
  267. };
  268. let Xr: Option<G> = if privkey.muCMZ {
  269. Some(bp.mulA(&privkey.xr))
  270. } else {
  271. None
  272. };
  273. let X: Vec<G> = privkey.x.iter().map(|x| bp.mulA(x)).collect();
  274. CMZPubkey { X0, Xr, X }
  275. }
  276. /// The CMZCredential trait implemented by all CMZ credential struct types.
  277. pub trait CMZCredential
  278. where
  279. for<'a> Self: Default + Sized + serde::Serialize + serde::Deserialize<'a>,
  280. {
  281. /// The type of attributes for this credential
  282. type Scalar: PrimeField;
  283. /// The type of the coordinates of the MAC for this credential
  284. type Point: PrimeGroup;
  285. /// Produce a vector of strings containing the names of the
  286. /// attributes of this credential. (The MAC is not included.)
  287. fn attrs() -> Vec<&'static str>;
  288. /// The number of attributes in this credential
  289. fn num_attrs() -> usize;
  290. /// The attribute number for a given name as a string
  291. fn attr_num(name: &str) -> usize;
  292. /// Get a reference to one of the attributes, specified by name as a
  293. /// string.
  294. fn attr(&self, name: &str) -> &Option<Self::Scalar>;
  295. /// Get a mutable reference to one of the attributes, specified by
  296. /// name as a string.
  297. fn attr_mut(&mut self, name: &str) -> &mut Option<Self::Scalar>;
  298. /// Set the public key for this credential.
  299. fn set_pubkey(&mut self, pubkey: &CMZPubkey<Self::Point>) -> &mut Self;
  300. /// Get a copy of the public key for this credential. If the public
  301. /// key has not yet been set or computed, a pubkey with X0 == None
  302. /// will be returned.
  303. fn get_pubkey(&self) -> &CMZPubkey<Self::Point>;
  304. /// Set the private key for this credential. The public key will
  305. /// automatically be computed from the private key.
  306. fn set_privkey(&mut self, privkey: &CMZPrivkey<Self::Point>) -> &mut Self;
  307. /// Set the private and public keys for this credential.
  308. fn set_keypair(
  309. &mut self,
  310. privkey: &CMZPrivkey<Self::Point>,
  311. pubkey: &CMZPubkey<Self::Point>,
  312. ) -> &mut Self;
  313. /// Get a copy of the private key for this credential. If the
  314. /// private key has not yet been set, a privkey with an empty x
  315. /// vector will be returned.
  316. fn get_privkey(&self) -> &CMZPrivkey<Self::Point>;
  317. /// Get the element of the privkey x vector associated with the
  318. /// given field name
  319. fn privkey_x(&self, name: &str) -> Self::Scalar;
  320. /// Get the element of the pubkey X vector associated with the given
  321. /// field name
  322. fn pubkey_X(&self, name: &str) -> Self::Point;
  323. /// Generate random private and public keys for this credential
  324. /// type. muCMZ should be true if this credential will be issued
  325. /// with muCMZ protocols (and _not_ classic CMZ14 protocols).
  326. fn gen_keys(
  327. rng: &mut impl RngCore,
  328. muCMZ: bool,
  329. ) -> (CMZPrivkey<Self::Point>, CMZPubkey<Self::Point>);
  330. /// Convenience functions for the above
  331. fn cmz14_gen_keys(rng: &mut impl RngCore) -> (CMZPrivkey<Self::Point>, CMZPubkey<Self::Point>) {
  332. Self::gen_keys(rng, false)
  333. }
  334. fn mucmz_gen_keys(rng: &mut impl RngCore) -> (CMZPrivkey<Self::Point>, CMZPubkey<Self::Point>) {
  335. Self::gen_keys(rng, true)
  336. }
  337. /// Convenience function for creating a new Self, and loading the
  338. /// given private key (which will also compute the public key).
  339. fn using_privkey(privkey: &CMZPrivkey<Self::Point>) -> Self {
  340. let mut slf = Self::default();
  341. slf.set_privkey(privkey);
  342. slf
  343. }
  344. /// Convenience function for creating a new Self, and loading the
  345. /// given public key.
  346. fn using_pubkey(pubkey: &CMZPubkey<Self::Point>) -> Self {
  347. let mut slf = Self::default();
  348. slf.set_pubkey(pubkey);
  349. slf
  350. }
  351. /// Create the MAC for this credential, given the private key.
  352. fn create_MAC(
  353. &mut self,
  354. rng: &mut impl RngCore,
  355. privkey: &CMZPrivkey<Self::Point>,
  356. ) -> Result<(), ()>;
  357. /// Compute the coefficient component of the MAC (the Scalar you
  358. /// would multiply P by to get Q), given the private key.
  359. fn compute_MAC_coeff(&self, privkey: &CMZPrivkey<Self::Point>) -> Result<Self::Scalar, ()>;
  360. /// Verify the MAC in this credential, given the private key. This
  361. /// is mainly useful for debugging, since the client will not have
  362. /// the private key and the issuer will typically not have the
  363. /// complete credential.
  364. fn verify_MAC(&self, privkey: &CMZPrivkey<Self::Point>) -> Result<(), ()>;
  365. /// Create a fake MAC for this credential. This is useful, for
  366. /// example, when you're doing an OR proof, and in some arms of the
  367. /// disjunction, the credential does not have to be valid.
  368. fn fake_MAC(&mut self, rng: &mut impl RngCore);
  369. /// Serialize this credential, _including_ the private key. The
  370. /// default serializer skips the private key for safety reasons.
  371. fn serialize_with_privkey(&self) -> Vec<u8> {
  372. // Accomplish this by serializing the pair (privkey, self)
  373. postcard::to_allocvec(&(self.get_privkey(), self)).unwrap()
  374. }
  375. /// Deserialize this credential, _including_ the private key. The
  376. /// default serializer skips the private key for safety reasons.
  377. fn deserialize_with_privkey(bytes: &[u8]) -> postcard::Result<Self> {
  378. let (privkey, mut cred) = postcard::from_bytes::<(CMZPrivkey<Self::Point>, Self)>(bytes)?;
  379. cred.set_privkey(&privkey);
  380. Ok(cred)
  381. }
  382. }
  383. /// The CMZ macro for declaring CMZ credentials.
  384. ///
  385. /// Use this macro to declare a CMZ credential struct type.
  386. ///
  387. /// use cmz::*;
  388. /// use group::Group;
  389. /// use rand::{CryptoRng, RngCore};
  390. /// use curve25519_dalek::ristretto::RistrettoPoint as Grp;
  391. /// CMZ!{ Name<Grp>: attr1, attr2, attr3 }
  392. ///
  393. /// will declare a struct type called `Name`, containing one field for each
  394. /// of the listed attributes. The attribute fields will be of type
  395. /// `Option<Scalar>`. It will also automatically add a field called `MAC`
  396. /// of type [`CMZMac`], and an implementation (via the `CMZCred` derive) of
  397. /// the [`CMZCredential`] trait. The mathematical group used (the field for
  398. /// the values of the attributes and the private key elements, and the group
  399. /// elements for the commitments, MAC components, and public key elements)
  400. /// is `Grp`. If `Grp` is omitted, the macro will default to using a
  401. /// group called `G`, which you can define, for example, as:
  402. ///
  403. /// use curve25519_dalek::ristretto::RistrettoPoint as G;
  404. ///
  405. /// or:
  406. ///
  407. /// use curve25519_dalek::ristretto::RistrettoPoint;
  408. /// type G = RistrettoPoint;
  409. ///
  410. /// The group must implement the trait [`PrimeGroup`](https://docs.rs/group/latest/group/prime/trait.PrimeGroup.html).
  411. #[macro_export]
  412. macro_rules! CMZ {
  413. ( $name: ident < $G: ident > : $( $id: ident ),+ ) => {
  414. #[serde_as]
  415. #[derive(CMZCred,Clone,Debug,Default,serde::Serialize,serde::Deserialize)]
  416. #[cmzcred_group(group = $G)]
  417. pub struct $name {
  418. $(
  419. #[serde_as(as="Option<SerdeScalar>")]
  420. pub $id: Option<<$G as Group>::Scalar>,
  421. )+
  422. pub MAC: CMZMac<$G>,
  423. // Don't serialize the private key by default
  424. #[serde(skip)]
  425. privkey: CMZPrivkey<$G>,
  426. pubkey: CMZPubkey<$G>,
  427. }
  428. };
  429. ( $name: ident : $( $id: ident ),+ ) => {
  430. #[serde_as]
  431. #[derive(CMZCred,Clone,Debug,Default,serde::Serialize,serde::Deserialize)]
  432. #[cmzcred_group(group = G)]
  433. pub struct $name {
  434. $(
  435. #[serde_as(as="Option<SerdeScalar>")]
  436. pub $id: Option<<G as Group>::Scalar>,
  437. )+
  438. pub MAC: CMZMac<G>,
  439. // Don't serialize the private key by default
  440. #[serde(skip)]
  441. privkey: CMZPrivkey<G>,
  442. pubkey: CMZPubkey<G>,
  443. }
  444. };
  445. }
  446. /// The type for errors generated by the prepare, handle, and finalize
  447. /// functions generated by the CMZProtocol family of macros
  448. #[non_exhaustive]
  449. #[derive(Error, Debug)]
  450. pub enum CMZError {
  451. #[error("Hide attribute {1} of credential {0} was not passed to prepare")]
  452. HideAttrMissing(&'static str, &'static str),
  453. #[error("Reveal attribute {1} of credential {0} was not passed to prepare")]
  454. RevealAttrMissing(&'static str, &'static str),
  455. #[error("Implicit attribute {1} of credential {0} was not passed to prepare")]
  456. ImplicitAttrCliMissing(&'static str, &'static str),
  457. #[error("Implicit attribute {1} of credential {0} was not set by fill_creds")]
  458. ImplicitAttrIssMissing(&'static str, &'static str),
  459. #[error("Set attribute {1} of credential {0} was not set by fill_creds")]
  460. SetAttrMissing(&'static str, &'static str),
  461. #[error("private key for credential {0} was not set by fill_creds")]
  462. PrivkeyMissing(&'static str),
  463. #[error("public key for credential {0} was not passed to prepare")]
  464. PubkeyMissing(&'static str),
  465. #[error("credential initialized with wrong protocol")]
  466. WrongProtocol(&'static str),
  467. #[error("client proof did not verify")]
  468. CliProofFailed,
  469. #[error("issuer proof did not verify")]
  470. IssProofFailed,
  471. #[error("unknown CMZ proof error")]
  472. Unknown,
  473. }
  474. #[cfg(test)]
  475. mod tests {
  476. use super::*;
  477. #[test]
  478. fn lox_credential_test() {
  479. use curve25519_dalek::ristretto::RistrettoPoint as G;
  480. CMZ! { Lox:
  481. id,
  482. bucket,
  483. trust_level,
  484. level_since,
  485. invites_remaining,
  486. blockages
  487. }
  488. println!("{:#?}", Lox::attrs());
  489. let mut L = Lox::default();
  490. println!("{:#?}", L);
  491. L.bucket = Some(<G as Group>::Scalar::ONE);
  492. println!("{:#?}", L);
  493. println!("{:#?}", L.attr("bucket"));
  494. *L.attr_mut("id") = Some(<G as Group>::Scalar::ONE);
  495. println!("{:#?}", L);
  496. }
  497. }