NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #4227 most downloaded on crates.io
Procedural macro library used to build custom prime field implementations
Last release 4 months ago
30 May 2026
Release timing varies
gaps range from 8 days to 2.3 years
Some releases are documented
notes for 9 of 16 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
18 releases · first in 2017
ff::Field::try_random (rng: &mut R) -> Result , a new trait method that must be implemented by downstreams. It samples a field element using a fallibl
ff::Field::try_random<R: TryRng + ?Sized>(rng: &mut R) -> Result<Self, R::Error>,
a new trait method that must be implemented by downstreams. It samples a field
element using a fallible RNG and propagates the RNG's error.rand_core 0.10.ff::Field::random(rng: impl RngCore) -> Self has been changed back to
Field::random<R: Rng + ?Sized>(rng: &mut R) -> Self, to enable passing a
trait object as the RNG. It now has a default implementation in terms of
Field::try_random.derive_bits feature flag (use bits instead).Nothing published for this version
One column per quarter.
Nothing published for this version
ff_derive now works with all odd primes, not just primes that are either 3 (mod 4) or 1 (mod 16).
ff_derive now works with all odd primes, not just primes that are either
3 (mod 4) or 1 (mod 16).ff_derive and hybrid-array are in the same
dependency tree has been fixed.ff::Field::{sqrt_ratio, sqrt_alt}
ff::Field::{ZERO, ONE}ff::Field::powff::Field::{sqrt_ratio, sqrt_alt}core::iter::{Sum, Product} bounds on ff::Fieldff::PrimeField::from_u128ff::PrimeField::{MODULUS, TWO_INV}ff::PrimeField::MULTIPLICATIVE_GENERATORff::PrimeField::{ROOT_OF_UNITY, ROOT_OF_UNITY_INV}ff::PrimeField::DELTAff::WithSmallOrderMulGroupff::FromUniformBytesff::helpers:
sqrt_tonelli_shankssqrt_ratio_genericff::Field::sqrt is now a provided method that uses the Field::sqrt_ratio
method. Implementors of the Field trait can choose to implement
Field::sqrt_ratio and use the provided ff::Field::sqrt method, especially
if it is more efficient in practice, or they can keep their own implementation
of Field::sqrt and implement Field::sqrt_ratio in terms of that
implementation using the ff::helpers::sqrt_ratio_generic helper function.ff::PrimeField is now documented as representing a non-binary field (i.e.
its prime is not 2). This was always the intention, but is now a concrete
requirement in order for PrimeField::TWO_INV to exist.ff::Field::{zero, one} (use ff::Field::{ZERO, ONE} instead).ff::PrimeField::{multiplicative_generator, root_of_unity} (use
ff::PrimeField::{MULTIPLICATIVE_GENERATOR, ROOT_OF_UNITY} instead).ff_derive previously generated a Field::random implementation that would overflow for fields that needed a full 64-bit spare limb.
ff_derive previously generated a Field::random implementation that would
overflow for fields that needed a full 64-bit spare limb.### Changed - MSRV is now 1.56.0. - Bumped bitvec to 1.0.
bitvec to 1.0.ff_derive procedural macro can now be invoked within regular macros.
ff_derive procedural macro can now be invoked within regular macros.ff_derive's procedural macro would generate implementations of
PrimeFieldBits even when the bits crate feature was disabled. ff_derive
can now be used without a dependency on bitvec by disabling feature
features. The new crate feature derive_bits can be used to force the
generation of PrimeFieldBits implementations. This new crate feature will be
removed once our MSRV is at least 1.60 and we have access to weak dependency
features.subtle::ConstantTimeEq bound on ff::Field
subtle::ConstantTimeEq bound on ff::FieldCopy + Send + Sync + 'static bounds on ff::PrimeField::Reprff::derive module behind the derive feature flag, containing dependencies for the
PrimeField derive macro:
adc, mac, sbb constant-time const helper functions.ff::Field::is_zero_vartimeff::PrimeField::from_repr_vartimeff::Field::is_zero now returns subtle::Choice.ff::PrimeField::{is_odd, is_even} now return subtle::Choice.ff::PrimeField::from_repr now return subtle::CtOption<Self>.ff::PrimeField::from_str has been renamed to PrimeField::from_str_vartime.ff::{adc, mac_with_carry, sbb} (replaced by ff::derive::{adc, mac, sbb}).ff::PrimeFieldBits: PrimeField trait, behind a bits feature flag.
ff::PrimeFieldBits: PrimeField trait, behind a bits feature flag.bitvec to 0.22 to enable fixing a performance regression in ff 0.9.
The bitvec::view::BitView re-export has been replaced by
bitvec::view::BitViewSized.bitvec dependency and its re-exports have been gated behind the bits
feature flag.ff::PrimeField::{ReprBits, char_le_bits, to_le_bits} (replaced by
ff::PrimeFieldBits trait).#[derive(PrimeField)] now works on small moduli (that fit in a single u64
limb).ff::PrimeField::{ReprBits, char_le_bits, to_le_bits}, and a public dependency on bitvec 0.18.
ff::PrimeField::{ReprBits, char_le_bits, to_le_bits}, and a public
dependency on bitvec 0.18.ff::Field::cube method with provided implementation.Send + Sync bounds on ff::PrimeField::ReprBitsff::Field::random<R: RngCore + ?Sized>(rng: &mut R) -> Self has been changed
to Field::random(rng: impl RngCore) -> Self, to align with
group::Group::random.fmt::Display bound on ff::Field.ff::PrimeField::char (replaced by ff::PrimeField::char_le_bits).ff::{BitIterator, Endianness, PrimeField::ReprEndianness (replaced by
ff::PrimeField::to_le_bits).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →