PenguinConverters.CandyStore
3.3.5
dotnet add package PenguinConverters.CandyStore --version 3.3.5
NuGet\Install-Package PenguinConverters.CandyStore -Version 3.3.5
<PackageReference Include="PenguinConverters.CandyStore" Version="3.3.5" />
<PackageVersion Include="PenguinConverters.CandyStore" Version="3.3.5" />
<PackageReference Include="PenguinConverters.CandyStore" />
paket add PenguinConverters.CandyStore --version 3.3.5
#r "nuget: PenguinConverters.CandyStore, 3.3.5"
#:package PenguinConverters.CandyStore@3.3.5
#addin nuget:?package=PenguinConverters.CandyStore&version=3.3.5
#tool nuget:?package=PenguinConverters.CandyStore&version=3.3.5
PenguinConverters.CandyStore
The native-interop boundary between managed .NET and the Rust engine. CandyStore is the
single managed assembly that P/Invokes keyra_ffi (the Rust cdylib); it binds to the crypto
implemented in Rust, it does not implement crypto itself.
Overview
┌──────────────────────────────────────────────────────────────┐
│ CandyStore (net8.0) │
│ platform-agnostic │
├──────────────────────────────────────────────────────────────┤
│ │
│ FFI binding + engine facade BCL helpers │
│ ┌────────────────────────────┐ ┌──────────────────────┐ │
│ │ KeyraFfiNative (P/Invoke) │ │ Crypto │ │
│ │ KeyraNativeCrypto │ │ (X509 self-signed │ │
│ │ KeyraEngine (load/ABI gate)│ │ cert creation) │ │
│ │ KeyraVaultSession (handle) │ │ KeystrokeEntropy- │ │
│ │ KeyraSecretCipher │ │ Collector │ │
│ │ AesGcmCrypto (facade) │ └──────────────────────┘ │
│ └─────────────┬──────────────┘ │
└────────────────┼─────────────────────────────────────────────┘
│ P/Invoke (single boundary)
▼
┌────────────────────────┐
│ keyra_ffi (Rust cdylib)│ AES-GCM, Argon2id, HMAC,
│ │ SHA-256, HKDF, KDF recipes,
│ │ keystore, secretstore,
│ │ git, hosting, engine
└────────────────────────┘
Package Information
| Property | Value |
|---|---|
| Package ID | PenguinConverters.CandyStore |
| Target Framework | net8.0 |
| Platform | Platform-agnostic (binds to the Rust cdylib) |
| Project references | None (graph leaf — P/Invokes keyra_ffi only) |
No Windows-native crypto here. DPAPI-NG / CNG / BCrypt / NCrypt interop lives in the
KeyStorageProvider.DpapiNgprovider (net8.0-windows), not in CandyStore. CandyStore was previously described as hosting that interop; it no longer does — those files moved to the DpapiNg provider, and CandyStore staysnet8.0/agnostic.
Components
FFI binding & engine facade
| Class | Purpose |
|---|---|
KeyraFfiNative (Native/) |
The one P/Invoke surface to keyra_ffi. Loads via an explicit, ACL-protected path (NativeLibrary.SetDllImportResolver), not ambient PATH/CWD. |
KeyraEngine |
Engine gate: loads the cdylib and enforces the ABI-version handshake (refuses to proceed on mismatch). Hosts the EngineMode (Dotnet/Shadow/Rust) switch. |
KeyraNativeCrypto |
Thin managed wrappers over the FFI: AES-GCM, keystore .key load/frame/unframe, secret/folder IO, the KDF recipe executor (RecipeExecute — the single derivation entry point), git, hosting. Byte-in/byte-out; the Rust side owns and zeroizes its intermediates. |
KeyraVaultSession |
IDisposable wrapper over the opaque Rust vault-session handle. The master key never crosses to the managed heap. |
KeyraSecretCipher |
AES-GCM cipher over an already-recovered master key (e.g. a DPAPI-NG key unwrapped in .NET). |
AesGcmCrypto |
Thin AES-GCM encrypt/decrypt facade — delegates to the Rust engine. |
Cross-platform BCL helpers
| Class | Purpose |
|---|---|
Crypto |
X509 self-signed certificate creation (RSA.Create + CertificateRequest — cross-platform BCL). |
KeystrokeEntropyCollector |
Collects keystroke-timing entropy (facade over the engine entropy pool). |
Security notes
- One boundary. CandyStore is the only managed assembly with P/Invoke into the engine;
keyra-ffiis the only crate exposingextern "C". Nothing else crosses. Seedocs/interop.md. - ABI handshake.
KeyraEnginecallskeyra_ffi_abi_version()right after load and refuses to proceed on mismatch with its compiled-in expectation. - Secret ownership. Secret buffers are owned and zeroized on the Rust side; the managed side receives opaque handles or writes into fixed-size output buffers it owns — never a raw pointer to live key material on the managed heap.
- Load-time integrity. The cdylib is native (cannot be strong-named); trust comes from code signing plus a constrained load from the install directory.
License
Proprietary — PenguinConverters
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- No dependencies.
NuGet packages (4)
Showing the top 4 NuGet packages that depend on PenguinConverters.CandyStore:
| Package | Downloads |
|---|---|
|
PenguinConverters.Keyra.Core
Keyra domain layer: vault, folder, secret, and key contracts, provider and authentication abstractions, key derivation, and the export/import package model. Referenced by the Keyra SDK and every provider. |
|
|
PenguinConverters.Keyra
Keyra developer SDK: load a vault key from a .keyra package, an armored share (KEYRA: ... :ARYEK), a key.json, or a vault directory, then encrypt and decrypt application secrets and configuration entries (Settings.Secret). Add a KeyStorageProvider package (DpapiNg or AesGcm) for provider-backed keys. |
|
|
PenguinConverters.Keyra.KeyStorageProvider.DpapiNg
Keyra key storage provider for Windows DPAPI-NG (NCrypt): protects vault master keys with the Windows identity (domain or local SID). Windows-only by design; install alongside the Keyra SDK to open Windows / Active Directory vaults. |
|
|
PenguinConverters.Keyra.KeyStorageProvider.AesGcm
Keyra key storage provider for password-derived AES-256-GCM keys (Argon2id KEK via the Rust engine). Cross-platform, no OS binding; install alongside the Keyra SDK for provider-backed portable keys. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 3.3.5 | 63 | 10/5/2026 |
| 3.3.3 | 115 | 10/4/2026 |
| 3.3.1 | 129 | 10/1/2026 |
| 3.3.0 | 145 | 9/28/2026 |
| 3.2.0 | 139 | 9/28/2026 |
| 3.1.2 | 142 | 9/23/2026 |
| 3.1.1.9 | 141 | 9/23/2026 |
| 3.1.1.8 | 137 | 9/22/2026 |
| 3.1.1 | 135 | 9/21/2026 |
| 3.0.0 | 149 | 9/11/2026 |
| 2.23.7 | 162 | 9/7/2026 |
| 2.23.5 | 156 | 9/7/2026 |
| 2.23.3 | 165 | 9/7/2026 |
| 2.22.0 | 177 | 9/1/2026 |
| 2.21.0 | 150 | 8/31/2026 |
| 2.20.0 | 143 | 8/31/2026 |
| 2.19.2 | 219 | 8/28/2026 |
| 2.19.0 | 278 | 8/19/2026 |
| 2.18.0 | 162 | 8/18/2026 |
| 2.17.0 | 168 | 8/17/2026 |