NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #3388 most downloaded on crates.io
Implementation of the Pallas and Vesta (Pasta) curve cycle
Last release 12 days ago
25 Sep 2026
Ships unpredictably
gaps range from 2 weeks to 3.4 years
Nearly every release is documented
notes for 13 of 14 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
14 releases · first in 2021
One column per quarter.
zeroize feature flag, which enables impl zeroize::DefaultIsZeroes for Fp, Fq, Ep, EpAffine, Eq and EqAffine. Zeroizing a field element sets it to zero
zeroize feature flag, which enables impl zeroize::DefaultIsZeroes for
Fp, Fq, Ep, EpAffine, Eq and EqAffine. Zeroizing a field element
sets it to zero; zeroizing a point sets it to the identity.pasta_curves::{EpAffine, EqAffine}::from_xy_unchecked, a const
constructor that builds an affine point from coordinates without checking
that it lies on the curve. It is intended for protocol constants and
precomputed tables, which can now be written as const or static items
instead of paying for CurveAffine::from_xy on every use.pasta_curves::arithmetic:
VartimeField, an extension trait for ff::Field that exposes
variable-time operations. All trait methods have default impls that fall
back on the constant-time implementations, but can be overriden for
additional performance.VartimeBatchInvert, a variable-time equivalent of ff::BatchInvert.impl VartimeField for pasta_curves::{Fp, Fq}.ff 0.14, group 0.14, rand 0.10.pasta_curves::arithmetic:
Base and ScalarExt associated types of CurveExt and CurveAffine
now have an additional VartimeField bound, enabling downstream generic
code to use variable-time operations.CurveExt trait:
CurveExt::to_affine_vartimeCurveExt::batch_normalize_vartimepasta_curves::deferred module, behind the new deferred feature flag. This provides the DeferredField trait and a wide Product accumulator, which toget
pasta_curves::deferred module, behind the new deferred feature flag. This
provides the DeferredField trait and a wide Product accumulator, which
together allow summing many field multiplications (e.g. an inner product)
with a single Montgomery reduction at the end.pasta_curves::glv module, behind the new glv feature flag. This provides
variable-time scalar multiplication for Pallas and Vesta via their cube-root
endomorphism, for use where scalars are not secret (e.g. in verifiers); its
precomputations can be reused across multiplications that share a point or a
scalar.Fix a bug on 32-bit platforms that could cause the square root implementation to return an incorrect result.
sqrt-table feature now works without std and only requires alloc.serde feature flag, which enables Serde compatibility to the crate types. Field elements and points are serialized to their canonical byte encoding (e
serde feature flag, which enables Serde compatibility to the crate types.
Field elements and points are serialized to their canonical byte encoding
(encoded as hexadecimal if the data format is human readable).ff 0.13, group 0.13, ec-gpu 0.2.pasta_curves::arithmetic:
FieldExt bounds on associated types of CurveExt and CurveAffine have
been replaced by bounds on ff::WithSmallOrderMulGroup<3> (and Ord in the
case of CurveExt).pasta_curves::hashtocurve:
FieldExt bounds on the module functions have been replaced by equivalent
ff trait bounds.pasta_curves::arithmetic:
FieldExt (use ff::PrimeField or ff::WithSmallOrderMulGroup instead).GroupSqrtRatio (use ff::Field::{sqrt_ratio, sqrt_alt} instead).SqrtTables (from public API, as it isn't suitable for generic usage).uninline-portable feature flag, which disables inlining of some functions. This is useful for tiny microchips (such as ARM Cortex-M0), where inlining
uninline-portable feature flag, which disables inlining of some functions.
This is useful for tiny microchips (such as ARM Cortex-M0), where inlining
can hurt performance and blow up binary size.Migrated to ff 0.12, group 0.12.
ff 0.12, group 0.12.gpu feature flag, which exposes implementations of the GpuField trait from the ec-gpu crate for pasta_curves::{Fp, Fq}. This flag will eventually cont
gpu feature flag, which exposes implementations of the GpuField trait from
the ec-gpu crate for pasta_curves::{Fp, Fq}. This flag will eventually
control all GPU functionality.repr-c feature flag, which helps to facilitate usage of this crate's types
across FFI by conditionally adding repr(C) attribute to point structures.pasta_curves::arithmetic::Coordinates::from_xypasta_curves::{Fp, Fq} are now declared as repr(transparent), to enable
their use across FFI. They remain opaque structs in Rust code.Support for no-std builds, via two new (default-enabled) feature flags:
no-std builds, via two new (default-enabled) feature flags:
alloc enables the pasta_curves::arithmetic::{CurveAffine, CurveExt}
traits, as well as implementations of traits like group::WnafGroup.sqrt-table depends on alloc, and enables the large precomputed tables
(stored on the heap) that speed up square root computation.pasta_curves::arithmetic::SqrtRatio trait, extending ff::PrimeField with
square roots of ratios. This trait is likely to be moved into the ff crate
in a future release (once we're satisfied with it).pasta_curves::arithmetic:
Field re-export (pasta_curves::group::ff::Field is equivalent).FieldExt::ROOT_OF_UNITY (use ff::PrimeField::root_of_unity instead).FieldExt::{T_MINUS1_OVER2, pow_by_t_minus1_over2, get_lower_32, sqrt_alt,
sqrt_ratio} (moved to SqrtRatio trait).FieldExt::{RESCUE_ALPHA, RESCUE_INVALPHA}FieldExt::from_u64 (use From<u64> for ff::PrimeField instead).FieldExt::{from_bytes, read, to_bytes, write}
(use ff::PrimeField::{from_repr, to_repr} instead).FieldExt::rand (use ff::Field::random instead).CurveAffine::{read, write}
(use group::GroupEncoding::{from_bytes, to_bytes} instead).The crate is now licensed as MIT OR Apache-2.0.
MIT OR Apache-2.0.Migrated to ff 0.11, group 0.11.
ff 0.11, group 0.11.Implementation of group::WnafGroup for Pallas and Vesta, enabling them to be used with group::Wnaf for targeted performance improvements.
group::WnafGroup for Pallas and Vesta, enabling them to be
used with group::Wnaf for targeted performance improvements.Implementations of group::{CofactorCurve, CofactorCurveAffine} for Pallas and Vesta, enabling them to be used in cofactor-aware protocols that also wa
group::cofactor::{CofactorCurve, CofactorCurveAffine} for
Pallas and Vesta, enabling them to be used in cofactor-aware protocols that
also want to leverage the affine point representation.Initial release!
Initial release!
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →