Skip to content
Prev Previous commit
Next Next commit
crypto_primitives, hardwarekey: fix mypy-invalid type annotations
PKCS1v15 and SHA256 are constant instances, not classes, so using them
as type annotations (crypto_primitives.PKCS1v15, etc.) is invalid and
fails mypy's check-stubs target. Use object instead, matching the
existing precedent in OAEP.__init__'s algorithm parameter. The
:param TypeName name: docstring prose is left as-is since it still
documents the expected values for humans and Sphinx.

Also fix a broken bare cross-reference in the crypto_primitives module
docstring (`.decrypt()` -> `hardwarekey.HardwareKey.decrypt()`), found
by running the full sphinx-build -W pipeline locally.
  • Loading branch information
mmabey committed Sep 19, 2026
commit 91ab25b2dd9ac97a47306067b179669ce31268f7
3 changes: 2 additions & 1 deletion shared-bindings/crypto_primitives/__init__.c
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,8 @@
//|
//| ``crypto_primitives`` holds padding and hash-algorithm markers used to
//| parameterize an operation elsewhere, for example
//| `hardwarekey.HardwareKey.sign()` / `.decrypt()`. It does no cryptography itself
//| `hardwarekey.HardwareKey.sign()` / `hardwarekey.HardwareKey.decrypt()`. It does
//| no cryptography itself
//| and holds no key material; it exists only so those operations can take explicit
//| ``padding``/``algorithm`` arguments instead of baking one fixed combination into
//| a method name. Named and organized after
Expand Down
6 changes: 3 additions & 3 deletions shared-bindings/hardwarekey/HardwareKey.c
Original file line number Diff line number Diff line change
Expand Up @@ -140,8 +140,8 @@ static MP_DEFINE_CONST_FUN_OBJ_2(hardwarekey_hardwarekey_load_ds_params_obj, har
//| def sign(
//| self,
//| data: ReadableBuffer,
//| padding: crypto_primitives.PKCS1v15,
//| algorithm: crypto_primitives.SHA256,
//| padding: object,
//| algorithm: object,
//| ) -> bytes:
//| """Sign ``data`` with this Digital Signature key and return the
//| signature (``rsa_key_bits // 8`` bytes). The private key is never
Expand Down Expand Up @@ -204,7 +204,7 @@ static MP_DEFINE_CONST_FUN_OBJ_KW(hardwarekey_hardwarekey_sign_obj, 1, hardwarek
//| def decrypt(
//| self,
//| ciphertext: ReadableBuffer,
//| padding: crypto_primitives.PKCS1v15 | crypto_primitives.OAEP,
//| padding: object,
//| ) -> bytes:
//| """Decrypt ``ciphertext`` (``rsa_key_bits // 8`` bytes) with this Digital
//| Signature key and return the recovered plaintext. The private key is
Expand Down
Loading