Merge bitcoin-core/secp256k1#1783: Add VERIFY_CHECKs and documentation that flags must be 0 or 1
ae00c552dfAdd VERIFY_CHECKs that flags are 0 or 1 (John Moffett) Pull request description: Flags for constant-time masking rely on the values being exactly `0` or `1` rather than `0` or true (any nonzero). One function, `secp256k1_fe_cmov` [documents](e7f7083b53/src/field.h (L315)) and [`VERIFY_CHECK`s](e7f7083b53/src/field_impl.h (L365)) this, but most don't. This updates the documentation and adds `VERIFY_CHECK`s enforcing `flag == 0 || flag == 1` for: `secp256k1_fe_storage_cmov` `secp256k1_gej_cmov` `secp256k1_ge_storage_cmov` `secp256k1_scalar_cadd_bit` `secp256k1_scalar_cond_negate` `secp256k1_scalar_cmov` `secp256k1_int_cmov` ACKs for top commit: furszy: ACKae00c55hebasto: re-ACKae00c552df. Tree-SHA512: c9d358929d39d93b0aea602d318429f7e82af96bf601f048a1cdeb0621b8adc6d1204648d352aa2060cb0f63db6dcf0da863854375ed313cea44dfad61c19a18
This commit is contained in:
@@ -69,7 +69,8 @@ static int secp256k1_musig_secnonce_load(const secp256k1_context* ctx, secp256k1
|
||||
return 1;
|
||||
}
|
||||
|
||||
/* If flag is true, invalidate the secnonce; otherwise leave it. Constant-time. */
|
||||
/* If flag is 1, invalidate the secnonce; if flag is 0, leave it.
|
||||
* Constant-time. Flag must be 0 or 1. */
|
||||
static void secp256k1_musig_secnonce_invalidate(const secp256k1_context* ctx, secp256k1_musig_secnonce *secnonce, int flag) {
|
||||
secp256k1_memczero(secnonce->data, sizeof(secnonce->data), flag);
|
||||
/* The flag argument is usually classified. So, the line above makes the
|
||||
|
||||
Reference in New Issue
Block a user