IronWeave.Blobs
0.2.0
See the version list below for details.
dotnet add package IronWeave.Blobs --version 0.2.0
NuGet\Install-Package IronWeave.Blobs -Version 0.2.0
<PackageReference Include="IronWeave.Blobs" Version="0.2.0" />
<PackageVersion Include="IronWeave.Blobs" Version="0.2.0" />
<PackageReference Include="IronWeave.Blobs" />
paket add IronWeave.Blobs --version 0.2.0
#r "nuget: IronWeave.Blobs, 0.2.0"
#:package IronWeave.Blobs@0.2.0
#addin nuget:?package=IronWeave.Blobs&version=0.2.0
#tool nuget:?package=IronWeave.Blobs&version=0.2.0
IronWeave.Blobs -- C# Binding
A .NET wrapper for the iwblobs native library, providing chunked AES-256-GCM streaming encryption with multi-party key sharing and protobuf envelope signing. Encryption and decryption are exposed as standard System.IO.Stream subclasses: IwBlobEncryptStream (write-only) and IwBlobDecryptStream (read-only).
Installation
dotnet add package IronWeave.Blobs
Requirements
- .NET 10
- Native
iwblobslibrary (built from the Rust crate withcargo build --release)
Project Structure
bindings/csharp/
IronWeave.Blobs.csproj Class library
IwBlobs.cs All public API methods + Stream classes
tests/
IronWeave.Blobs.Tests.csproj xUnit test project
IwBlobsTests.cs FFI wrapper round-trip tests
Adding to Your Project
Reference the class library and enable unsafe blocks:
<ProjectReference Include="path/to/bindings/csharp/IronWeave.Blobs.csproj" />
<AllowUnsafeBlocks>true</AllowUnsafeBlocks>
For development, register a resolver to point at the Cargo build output:
using System.Runtime.InteropServices;
NativeLibrary.SetDllImportResolver(
typeof(IwBlobs).Assembly,
(libraryName, assembly, searchPath) =>
{
if (libraryName == "iwblobs")
return NativeLibrary.Load("/path/to/target/release/libiwblobs.dylib");
return IntPtr.Zero;
});
Stream API
Encrypt a File
using IronWeave.Blobs;
byte[] aesKey = IwBlobs.GenerateAesKey();
await using var output = File.Create("encrypted.bin");
await using var enc = new IwBlobEncryptStream(output, aesKey);
await File.OpenRead("input.bin").CopyToAsync(enc);
Disposing IwBlobEncryptStream flushes the final chunk and finalizes encryption.
Decrypt a File
await using var input = File.OpenRead("encrypted.bin");
await using var dec = new IwBlobDecryptStream(input, aesKey);
await dec.CopyToAsync(File.Create("output.bin"));
Disposing IwBlobDecryptStream verifies the final chunk was seen (detecting truncation).
SHA-256 Hashing
For encrypted_hash in BlobEnvelope, prefer the .NET built-in APIs:
using System.Security.Cryptography;
byte[] hash = SHA256.HashData(encryptedBytes);
// Or streaming:
using var hasher = IncrementalHash.CreateHash(HashAlgorithmName.SHA256);
hasher.AppendData(chunk1);
byte[] hash = hasher.GetHashAndReset();
The FFI also exposes IwBlobs.Sha256() if you prefer the native implementation.
Envelope Validation
// Structural validation only (for authors, pre-sign)
IwBlobs.ValidateBlobEnvelope(envelopeBytes);
// Signature + structural validation (for verifiers)
IwBlobs.ValidateSignedBlobEnvelope(signedEnvelopeBytes);
Both methods throw IwBlobsException on failure.
Error Handling
All methods throw IwBlobsException (extends InvalidOperationException) on failure:
| Property | Type | Description |
|---|---|---|
Function |
string |
The FFI function that failed |
Code |
int |
Return code: 1=input, 2=panic, 3=verification, 6=signature, 7=encryption |
Detail |
string? |
Human-readable detail from iwblob_last_error() |
MAUI Deployment
iOS
Static linking. Reference the .a file and route to __Internal via a DllImportResolver:
<ItemGroup Condition="$(TargetFramework.Contains('ios'))">
<NativeReference Include="path/to/libiwblobs.a">
<Kind>Static</Kind>
<ForceLoad>true</ForceLoad>
</NativeReference>
</ItemGroup>
Android
Place .so files (built via cargo-ndk) under JNI or NuGet RID directories:
<ItemGroup Condition="$(TargetFramework.Contains('android'))">
<AndroidNativeLibrary Include="libs/arm64-v8a/libiwblobs.so" Abi="arm64-v8a" />
<AndroidNativeLibrary Include="libs/armeabi-v7a/libiwblobs.so" Abi="armeabi-v7a" />
<AndroidNativeLibrary Include="libs/x86_64/libiwblobs.so" Abi="x86_64" />
</ItemGroup>
Running Tests
cargo build --release
cd bindings/csharp/tests && dotnet test
License
Proprietary. All rights reserved.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Google.Protobuf (>= 3.34.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.