modules: Port bitcoin-core/secp256k1#1725 to zkp-specific code

This commit is contained in:
DarkWindman
2026-02-25 13:11:18 +02:00
parent 38284aa008
commit 01b1b916eb
2 changed files with 8 additions and 25 deletions

View File

@@ -718,24 +718,12 @@ static void nonce_function_ecdsa_adaptor_bitflip(unsigned char **args, size_t n_
CHECK(secp256k1_memcmp_var(nonces[0], nonces[1], 32) != 0);
}
/* Tests for the equality of two sha256 structs. This function only produces a
* correct result if an integer multiple of 64 many bytes have been written
* into the hash functions. */
static void ecdsa_adaptor_test_sha256_eq(const secp256k1_sha256 *sha1, const secp256k1_sha256 *sha2) {
/* Is buffer fully consumed? */
CHECK((sha1->bytes & 0x3F) == 0);
CHECK(sha1->bytes == sha2->bytes);
CHECK(secp256k1_memcmp_var(sha1->s, sha2->s, sizeof(sha1->s)) == 0);
}
static void run_nonce_function_ecdsa_adaptor_tests(void) {
unsigned char tag[] = {'E', 'C', 'D', 'S', 'A', 'a', 'd', 'a', 'p', 't', 'o', 'r', '/', 'n', 'o', 'n'};
unsigned char aux_tag[] = {'E', 'C', 'D', 'S', 'A', 'a', 'd', 'a', 'p', 't', 'o', 'r', '/', 'a', 'u', 'x'};
static const unsigned char tag[] = {'E', 'C', 'D', 'S', 'A', 'a', 'd', 'a', 'p', 't', 'o', 'r', '/', 'n', 'o', 'n'};
static const unsigned char aux_tag[] = {'E', 'C', 'D', 'S', 'A', 'a', 'd', 'a', 'p', 't', 'o', 'r', '/', 'a', 'u', 'x'};
unsigned char algo[] = {'E', 'C', 'D', 'S', 'A', 'a', 'd', 'a', 'p', 't', 'o', 'r', '/', 'n', 'o', 'n'};
size_t algolen = sizeof(algo);
unsigned char dleq_tag[] = {'D', 'L', 'E', 'Q'};
secp256k1_sha256 sha;
static const unsigned char dleq_tag[] = {'D', 'L', 'E', 'Q'};
secp256k1_sha256 sha_optimized;
unsigned char nonce[32];
unsigned char msg[32];
@@ -748,23 +736,20 @@ static void run_nonce_function_ecdsa_adaptor_tests(void) {
/* Check that hash initialized by
* secp256k1_nonce_function_ecdsa_adaptor_sha256_tagged has the expected
* state. */
secp256k1_sha256_initialize_tagged(&sha, tag, sizeof(tag));
secp256k1_nonce_function_ecdsa_adaptor_sha256_tagged(&sha_optimized);
ecdsa_adaptor_test_sha256_eq(&sha, &sha_optimized);
test_sha256_tag_midstate(&sha_optimized, tag, sizeof(tag));
/* Check that hash initialized by
* secp256k1_nonce_function_ecdsa_adaptor_sha256_tagged_aux has the expected
* state. */
secp256k1_sha256_initialize_tagged(&sha, aux_tag, sizeof(aux_tag));
secp256k1_nonce_function_ecdsa_adaptor_sha256_tagged_aux(&sha_optimized);
ecdsa_adaptor_test_sha256_eq(&sha, &sha_optimized);
test_sha256_tag_midstate(&sha_optimized, aux_tag, sizeof(aux_tag));
/* Check that hash initialized by
* secp256k1_nonce_function_dleq_sha256_tagged_aux has the expected
* state. */
secp256k1_sha256_initialize_tagged(&sha, dleq_tag, sizeof(dleq_tag));
secp256k1_nonce_function_dleq_sha256_tagged(&sha_optimized);
ecdsa_adaptor_test_sha256_eq(&sha, &sha_optimized);
test_sha256_tag_midstate(&sha_optimized, dleq_tag, sizeof(dleq_tag));
testrand_bytes_test(msg, sizeof(msg));
testrand_bytes_test(key, sizeof(key));

View File

@@ -8,13 +8,11 @@
/* We test that the hash initialized by secp256k1_schnorrsig_sha256_tagged_aggregate
* has the expected state. */
void test_schnorrsig_sha256_tagged_aggregate(void) {
unsigned char tag[] = {'H', 'a', 'l', 'f', 'A', 'g', 'g', '/', 'r', 'a', 'n', 'd', 'o', 'm', 'i', 'z', 'e', 'r'};
secp256k1_sha256 sha;
static const unsigned char tag[] = {'H', 'a', 'l', 'f', 'A', 'g', 'g', '/', 'r', 'a', 'n', 'd', 'o', 'm', 'i', 'z', 'e', 'r'};
secp256k1_sha256 sha_optimized;
secp256k1_sha256_initialize_tagged(&sha, (unsigned char *) tag, sizeof(tag));
secp256k1_schnorrsig_sha256_tagged_aggregation(&sha_optimized);
test_sha256_eq(&sha, &sha_optimized);
test_sha256_tag_midstate(&sha_optimized, tag, sizeof(tag));
}
/* Create n many x-only pubkeys and sigs for random messages */