# Changelog

All notable changes to `cc06b/mooncry`. Newest first.

This file is generated by `agent_box/_tools/_gen_changelog.py` from
`git log` plus the maintainer version log; re-run it after a release
rather than editing entries by hand. Versions before 0.17.0 predate
this clone's history and are one-line summaries.

## 0.95.0

_2026-09-20_

- document every public item, and say out loud what 1.0 waits for

## 0.94.0

_2026-09-20_

- keygens and GCM encrypts return structs -- no public (Bytes, Bytes) left

## 0.93.0

_2026-09-20_

- encapsulation results are structs, not (Bytes, Bytes)

## 0.92.1

_2026-09-20_

- two files shipped with raw control bytes instead of escapes

## 0.92.0

_2026-09-20_

- the (Bytes, Bool) channel is gone -- ten decrypters and decoders return Result

## 0.91.0

_2026-09-19_

- the Option channel is gone -- five openers now return Result

## 0.90.0

_2026-09-19_

- Result twins for the five entry points that mix abort with a failure value

## 0.89.0

_2026-09-19_

- Result twins for the ten legacy-channel entry points that can have one
- consume_check now verifies the internal package is unimportable
- robust-kem's mutated-dk assertion was wrong about ML-KEM's z
- freeze the four error channels, and print the tuple list

## 0.88.0

_2026-09-19_

- the Falcon low-level layer moves to cc06b/mooncry/internal

## 0.87.0

_2026-09-19_

- a 1 GiB size policy, argon2's variant, and the fourth probe wave

## 0.86.0

_2026-09-18_

- make the three API contracts machine-checked

## 0.85.0

_2026-09-18_

- third probe wave -- streaming lengths, block offsets, OTP digits

## 0.84.0

_2026-09-17_

- validate numeric and enum parameters; fuzz seeds now rotate in CI
- split the js job by file; it was the 19-minute critical path
- shard the js suite four ways, using a measured cost profile

## 0.83.0

_2026-09-16_

- the missing API-table rows, what `pub` owes you, and one dead function

## 0.82.0

_2026-09-16_

- direct coverage for seven public entry points, and the HPKE tuple order

## 0.81.0

_2026-09-16_

- validate key material instead of trapping or silently accepting it
- cover SLH-DSA's four untested entry points

## 0.80.0

_2026-09-16_

- no trap on a peer key, or on re-encoding one

## 0.79.1

_2026-09-14_

- LENGTH is peer-derived — say so where it aborts

## 0.79.0

_2026-09-14_

- ZUC — 4.5x on the ZUC-256 MAC, bit-granular vectors

## 0.78.0

_2026-09-13_

- ZUC-256 — keystream and 32/64/128-bit MAC

## 0.77.0

_2026-09-13_

- ZUC vectors from the official specs + a compiled-reference oracle
- bound every rejection loop fed by caller-supplied randomness
- ZUC-128 core + 128-EEA3 + 128-EIA3 (GM/T 0001, 3GPP TS 35.22x)

## 0.76.0

_2026-09-13_

- structure-aware DER fuzz + streaming state suite
- strict, bounds-checked SM2 ASN.1 parsers
- sm3_clone — deep-copy an SM3 streaming hasher

## 0.75.0

_2026-09-13_

- graceful X25519/X448 + the all-zero DH output check

## 0.74.1

_2026-09-13_

- boundary-length sweeps for every block-oriented scheme

## 0.74.0

_2026-09-13_

- deterministic hostile-input robustness suite
- add js-target job — the JS backend is a first-class MoonBit target
- reject off-curve HPKE peer keys (invalid-curve attack)
- never trap on untrusted input — length guards + graceful _or variants

## 0.73.0

_2026-09-10_

- SM2 sealed envelope (GM/T 0009 style)

## 0.72.0

_2026-09-10_

- SM2 key serialization — PKCS#8/SPKI DER + PEM, openssl-identical

## 0.71.0

_2026-09-10_

- HKDF-SM3 + PBKDF2-SM3 + SM2 signature DER — GM suite complete

## 0.70.0

_2026-09-10_

- SM2 encryption (GB/T 32918.4) + openssl DER interop

## 0.69.0

_2026-09-10_

- SM4 modes (CTR/CBC/GCM) + HMAC-SM3

## 0.68.0

_2026-09-10_

- SM2 signature (GB/T 32918) — Chinese national standard complete

## 0.67.0

_2026-09-10_

- SM3 + SM4 — Chinese national standards (GB/T 32905 / GB/T 32907)
- add native64 job — the wasm default is 32-bit Int; native Linux is 64-bit. Width-sensitive crypto masking must pass on both
- docs+test: audit follow-ups
- actually bump moon.mod to 0.67.0 + README SM3/SM4 entries

## 0.66.0

_2026-09-10_

- unrolled Keccak-f[1600] — SHAKE 9.6x faster
- run the test suite in release mode (~40min debug -> ~8min); debug full runs stay in local pre-publish discipline

## 0.65.0

_2026-09-09_

- post-campaign audit — API hygiene, dead code, docs
- moon fmt the v0.63 additions (padded/bench tests, falcon.mbt) — CI fmt --check was red on 12aaefd
- falcon keywords + post-quantum coverage in description

## 0.64.0

_2026-09-09_

- Falcon campaign wrap-up

## 0.63.0

_2026-09-09_

- Falcon padded-form API, benchmarks, README

## 0.62.0

_2026-09-09_

- Falcon-1024 — full parameter set, byte-exact KATs

## 0.61.0

_2026-09-09_

- Falcon M5 — signing byte-exact, Falcon-512 COMPLETE

## 0.60.0

_2026-09-09_

- Falcon M5a — signing randomness layer (prng + Gaussian sampler)

## 0.59.0

_2026-09-09_

- Falcon M4 — keygen byte-exact vs official C reference

## 0.58.0

_2026-09-08_

- Falcon M4b — small-prime modp layer, mod-p NTT, zint bignums

## 0.57.0

_2026-09-08_

- Falcon M4a — compute_public + Gaussian sampler layer

## 0.56.0

_2026-09-08_

- Falcon M3 — verification end-to-end, official sigs pass

## 0.55.0

_2026-09-08_

- Falcon M1+M2 — XOF/hash_to_point/codecs + f64 FFT layer

## 0.53.1

_2026-09-08_

- republish without Array::new (consumers on latest nightly + deny-warn would hit the deprecation in dependency code)
- replace Array::new() with typed empty literals — the CI nightly deprecated Array::new (deny-warn red); literals compile on both pinned toolchains

## 0.53.0

_2026-09-08_

- chore+perf(v0.53.0): Ed448 Shamir verify (12.0ms), dq_mul negative results documented, 118 NUL literals normalized
- record three measured-negative dq_mul replacement attempts (f64 reciprocal, folding with loop, branchless folding) — i64.rem by constant is already strength-reduced by the engine
- Shamir double-scalar verification ([4](S*B-k*A-R)=O form, safe for non-subgroup A since 4L kills any point) + hoisted base point — verify 15.2->12.0ms

## 0.52.0

_2026-09-08_

- word-oriented scrypt (in-place Salsa20/8 words, flat V table) ~1.4x

## 0.51.0

_2026-09-08_

- native P-256 field (8x32 limbs + derived Solinas fold) — ECDSA sign 3.6ms/verify 4.5ms, differential tests vs BigInt path included

## 0.50.1

_2026-09-08_

- republish from the CI-green state (v0.50.0 tarball predated the fmt fix)
- style: relocate orphaned doc comment in ml_kem (fix CI fmt --check)
- record the measured-negative f64 dq_mul experiment inline

## 0.50.0

_2026-09-08_

- ML-DSA/ML-KEM matrix-expansion caching — verify 2.9x

## 0.49.0

_2026-09-08_

- native Curve448-Goldilocks field — Ed448 2x, X448 1.7x

## 0.48.0

_2026-09-08_

- division-free Ed448/X448 field arithmetic

## 0.47.0

_2026-09-08_

- XMSS/XMSS^MT hash-based signatures (RFC 8391)

## 0.46.0

_2026-09-07_

- division-free EC arithmetic (Barrett + bit-chain inversion)

## 0.45.0

_2026-09-07_

- native Curve25519 field — X25519 2.4x, Ed25519 2.4-2.7x

## 0.44.0

_2026-09-07_

- T-table AES core (~4x all modes) + LMS fast chains

## 0.43.0

_2026-09-07_

- LMS/HSS hash-based signatures (RFC 8554)

## 0.42.0

_2026-09-06_

- Ed25519 83x, ECDSA verify ~2x, BLAKE3 3.2x

## 0.41.0

_2026-09-06_

- HPKE DHKEM(P-384, HKDF-SHA384) + HMAC/HKDF-SHA384

## 0.40.0

_2026-09-05_

- HPKE DHKEM(P-521) — all RFC 9180 vectored suites complete

## 0.39.0

_2026-09-05_

- AES-GCM-SIV (RFC 8452), nonce-misuse-resistant AEAD

## 0.38.0

_2026-09-05_

- HPKE DHKEM(P-256) — completes the RFC 9180 vector suites

## 0.37.0

_2026-09-05_

- HPKE hybrid public-key encryption (RFC 9180)

## 0.36.0

_2026-09-05_

- TurboSHAKE + KangarooTwelve (RFC 9861)

## 0.35.0

_2026-09-04_

- X-Wing hybrid post-quantum KEM (ML-KEM-768 + X25519)

## 0.34.0

_2026-09-04_

- SLH-DSA ~25% faster — truncated finalize + concat-free T_l

## 0.33.0

_2026-09-04_

- ML-KEM hybrid encryption + incremental Poly1305; HMAC long-key fix

## 0.32.0

_2026-09-03_

- SLH-DSA hash suite (~16% faster) + hasher clone utils
- style: moon fmt for SLH-DSA files
- style: moon fmt for v0.32.0 changes

## 0.31.0

_2026-09-03_

- SLH-DSA-44..256 (SPHINCS+, FIPS 205) all 12 parameter sets

## 0.30.0

_2026-09-03_

- ML-DSA external-mu ACVP vector coverage

## 0.29.0

_2026-09-03_

- ML-DSA HashML-DSA (pre-hash) + external-mu interfaces

## 0.28.0

_2026-09-03_

- ML-DSA-44/65/87 (FIPS 204 post-quantum signatures)

## 0.27.0

_2026-09-02_

- ML-KEM-512/768/1024 (FIPS 203 post-quantum KEM)

## 0.26.0

_2026-09-02_

- Ed448 + X448 (the 448-bit suite)

## 0.25.0

_2026-09-02_

- RSA CRT × multi-hash combinations

## 0.24.0

_2026-09-01_

- P-256 low-S sign + GMAC arbitrary-length IV

## 0.23.0

_2026-09-01_

- secp256k1 BIP-62 low-S sign + multi-hash RSA-OAEP

## 0.22.0

_2026-08-31_

- ECDSA secp256k1, multi-hash RSA signatures, incremental GMAC

## 0.21.0

_2026-08-31_

- RSA CRT private-key ops (~2.6x) + SHA-256 streaming zero-alloc
- fix outdated security note (GHASH now table-based) + modernize verification wording

## 0.20.0

_2026-08-17_

- ECDSA P-256 affine -> Jacobian projective coordinates

## 0.19.0

_2026-08-15_

- 4-bit table GHASH + Poly1305 radix-2^26 limbs

## 0.18.0

_2026-08-13_

- flatten Keccak state to 25 lanes, hoist ChaCha20 key setup

## 0.17.0

_2026-08-13_

- Ed25519ctx/ph, GMAC, keyed BLAKE2b/2s, Adler-32, PBKDF2-SHA1

## 0.16.0

- RIPEMD-160+AES-CCM+TOTP-SHA2/HKDF-SHA512 _(from the maintainer version log; predates this clone's history)_

## 0.15.0

- SHA-512/224/256+BLAKE2s+XChaCha20-Poly1305+HMAC-SHA3 _(from the maintainer version log; predates this clone's history)_

## 0.14.0

- Keccak-256/cSHAKE/KMAC/CRC-64+squeeze修复 _(from the maintainer version log; predates this clone's history)_

## 0.13.1

- property tests+benches _(from the maintainer version log; predates this clone's history)_

## 0.13.0

- AES-SIV _(from the maintainer version log; predates this clone's history)_

## 0.12.0

- Argon2 _(from the maintainer version log; predates this clone's history)_

## 0.11.0

- ECDSA P-256 _(from the maintainer version log; predates this clone's history)_

## 0.10.0

- AES-KW _(from the maintainer version log; predates this clone's history)_

## 0.9.0

- SHA-1+HOTP/TOTP _(from the maintainer version log; predates this clone's history)_

## 0.8.0

- Salsa20 _(from the maintainer version log; predates this clone's history)_

## 0.7.0

- X25519+HKDF/PBKDF2-SHA3 _(from the maintainer version log; predates this clone's history)_

## 0.6.0

- Ed25519 _(from the maintainer version log; predates this clone's history)_

## 0.5.0

- RSA _(from the maintainer version log; predates this clone's history)_

## 0.4.0

- scrypt _(from the maintainer version log; predates this clone's history)_
