3f7a9429ad ecdsa_adaptor: batch affine conversion in dleq_pair and dleq_prove (mllwchrry)
d380549e38 ecdsa_adaptor: optimize encrypt with batch affine conversion (mllwchrry)
Pull request description:
Replace pairs of `secp256k1_ge_set_gej` calls with single `secp256k1_ge_set_all_gej[_var]` calls, saving one expensive field inversion per operation.
`secp256k1_ecdsa_adaptor_encrypt`:
- Batch convert nonce points `R'` and `R` using `secp256k1_ge_set_all_gej`.
- Add early `enckey` validation: `secp256k1_ge_set_all_gej` requires non-infinity inputs, but invalid `enckey` could cause `secp256k1_ecmult_const` to produce infinity.
- Add early return when `secp256k1_dleq_prove` fails.
`secp256k1_dleq_pair`:
- Batch convert points `p[0]` and `p[1]` using `secp256k1_ge_set_all_gej`.
`secp256k1_dleq_prove`:
- Add early return with `secp256k1_declassify` when nonce generation fails, ensuring the nonce `k` passed to `secp256k1_dleq_pair` is always non-zero (required by `secp256k1_ge_set_all_gej`).
`secp256k1_dleq_verify`:
- Batch convert using variable-time `secp256k1_ge_set_all_gej_var` (already uses variable-time operations, processes public data).
ACKs for top commit:
real-or-random:
ACK 3f7a9429ad
Tree-SHA512: 706ab9df439f0803d1ec0181caf94a6f480f8e2c9337eae966c6b7a94b5c3ad14e71fc1a223a7d0f2b8d6db0c46a059b83712adff1d74e2d63ac3fc915234698
7111d365fb modules, tests: Port bitcoin-core/secp256k1#1734 to zkp-specific code (DarkWindman)
7699fe9aa6 modules: Port bitcoin-core/secp256k1#1735 to zkp-specific code (DarkWindman)
c09519f0e3 ci: Drop workaround for Valgrind older than 3.20.0 (Hennadii Stepanov)
8bc50b72ff ci: Switch to macOS 15 Sequoia Intel-based image (Hennadii Stepanov)
2f4546ce56 test: add --log option to display tests execution (furszy)
95b9953ea4 test: Add option to display all available tests (furszy)
953f7b0088 test: support running specific tests/modules targets (furszy)
0302c1a3d7 test: add --help for command-line options (furszy)
9ec3bfe22d test: adapt modules to the new test infrastructure (furszy)
48789dafc2 test: introduce (mini) unit test framework (furszy)
9cce703863 refactor: move 'gettime_i64()' to tests_common.h (furszy)
15d014804e ci: Drop default for `inputs.command` in `run-in-docker-action` (Hennadii Stepanov)
1decc49a1f ci: Use YAML anchor and aliases for repeated "CI script" steps (Hennadii Stepanov)
dff1bc107d ci, refactor: Generalize use of `matrix.configuration.env_vars` (Hennadii Stepanov)
4b644da199 ci: Use YAML anchor and aliases for repeated "Print logs" steps (Hennadii Stepanov)
a889cd93df ci: Bump `actions/checkout` version (Hennadii Stepanov)
574c2f3080 ci: Use YAML anchor and aliases for repeated "Checkout" steps (Hennadii Stepanov)
53585f93b7 ci: Use clang-snapshot in "MSan" job (Hennadii Stepanov)
6894c964f3 Fix Clang 21+ `-Wuninitialized-const-pointer` warning when using MSan (Hennadii Stepanov)
f163c35897 ci: Set `DEBIAN_FRONTEND=noninteractive` (Hennadii Stepanov)
70ae177ca0 ci: Bump `docker/build-push-action` version (Hennadii Stepanov)
b2a95a420f ci: Drop `tags` input for `docker/build-push-action` (Hennadii Stepanov)
122014edb3 ci: Add `scope` parameter to `cache-{to,from}` options (Hennadii Stepanov)
4d90585fea docs: Improve API docs of _context_set_illegal_callback (Tim Ruffing)
895f53d1cf docs: Clarify that callback can be called more than once (Tim Ruffing)
dfe284ed2d bench: improve context creation in ECDH benchmark (Sebastian Falbesoner)
ab560078aa build: Fix warnings in x86_64 assembly check (Hennadii Stepanov)
7321bdf27b doc: clarify API doc of `secp256k1_ecdsa_recover` return value (Jonas Nick)
0c91c56041 test: introduce group order byte-array constant for deduplication (Sebastian Falbesoner)
399b582a5f Split memclear into two versions (John Moffett)
Pull request description:
Merge bitcoin-core/secp256k1#1735: musig: Invalidate secnonce in secp256k1_musig_partial_sign
Merge bitcoin-core/secp256k1#1745: test: introduce group order byte-array constant for deduplication
Merge bitcoin-core/secp256k1#1741: doc: clarify API doc of `secp256k1_ecdsa_recover` return value
Merge bitcoin-core/secp256k1#1749: build: Fix warnings in x86_64 assembly check
Merge bitcoin-core/secp256k1#1748: bench: improve context creation in ECDH benchmark
Merge bitcoin-core/secp256k1#1727: docs: Clarify that callback can be called more than once
Merge bitcoin-core/secp256k1#1756: ci: Fix image caching and apply other improvements
Merge bitcoin-core/secp256k1#1750: ci: Use clang-snapshot in "MSan" job
Merge bitcoin-core/secp256k1#1719: ci: DRY workflow using anchors
Merge bitcoin-core/secp256k1#1734: Introduce (mini) unit test framework
Merge bitcoin-core/secp256k1#1759: ci: Switch to macOS 15 Sequoia Intel-based image
Merge bitcoin-core/secp256k1#1758: ci: Drop workaround for Valgrind older than 3.20.0
This PR can be recreated with `./contrib/sync-upstream.sh -b master range 7a2fff8`.
Tips:
* Use `git show --remerge-diff <pr-branch>` to show the conflict resolution in the merge commit.
* Use `git read-tree --reset -u <pr-branch>` to replay these resolutions during the conflict resolution stage when recreating the PR branch locally.
Be aware that this may discard your index as well as the uncommitted changes and untracked files in your worktree.
ACKs for top commit:
real-or-random:
ACK 7111d365fb
Tree-SHA512: 9f8fd21eee9ad3b7ea8d688f79783a43baffdeafb6b313372761ce368a24219a83c430c49070413f9972813ae03adde9a8660abfe4b0893b3700e241a81e5b13
01b1b916eb modules: Port bitcoin-core/secp256k1#1725 to zkp-specific code (DarkWindman)
7ebaa134a7 check-abi: remove support for obsolete CMake library output location (src/libsecp256k1.so) (Sebastian Falbesoner)
806de38bfc doc: mention ctx requirement for `_ellswift_create` (not secp256k1_context_static) (Sebastian Falbesoner)
737912430d ci: Add more tests for clang-cl (Hennadii Stepanov)
7379a5bed3 doc: Recommend clang-cl when building on Windows (Hennadii Stepanov)
325d65a8cf Rename and clear var containing k or -k (John Moffett)
960ba5f9c6 Use size_t instead of int for RFC6979 outlen copy (John Moffett)
5153cf1c91 tests: refactor tagged hash tests (josibake)
489a43d1bf docs: fix broken link to eprint cache.pdf paper (VolodymyrBg)
0458def51e doc: Add `--gcov-ignore-parse-errors=all` option to `gcovr` invocations (Hennadii Stepanov)
1aecce5936 doc: Add `--merge-mode-functions=separate` option to `gcovr` invocations (Hennadii Stepanov)
106a7cbf41 doc: Exclude modules' `bench_impl.h` headers from coverage report (Hennadii Stepanov)
a9e955d3ea autotools, docs: Adjust help string for `--enable-coverage` option (Hennadii Stepanov)
24ba8ff168 chore(ci): Fix typo in Dockerfile comment (Maximilian Hubert)
c25c3c8a88 test: update wycheproof test vectors (josibake)
7b07b22957 cmake: Avoid contaminating parent project's cache with BUILD_SHARED_LIBS (Hennadii Stepanov)
5433648ca0 Fix typos and spellings (Adrien Ufferte)
9ea54c69b7 tests: update Wycheproof files (fanquake)
Pull request description:
Merge bitcoin-core/secp256k1#1711: tests: update Wycheproof
Merge bitcoin-core/secp256k1#1688: cmake: Avoid contaminating parent project's cache with `BUILD_SHARED_LIBS`
Merge bitcoin-core/secp256k1#1717: test: update wycheproof test vectors
Merge bitcoin-core/secp256k1#1720: chore(ci): Fix typo in Dockerfile comment
Merge bitcoin-core/secp256k1#1722: docs: Exclude modules' `bench_impl.h` headers from coverage report
Merge bitcoin-core/secp256k1#1726: docs: fix broken link to Tromer's cache.pdf paper
Merge bitcoin-core/secp256k1#1725: tests: refactor tagged hash verification
Merge bitcoin-core/secp256k1#1729: hash: Use size_t instead of int for RFC6979 outlen copy
Merge bitcoin-core/secp256k1#1731: schnorrsig: Securely clear buf containing k or its negation
Merge bitcoin-core/secp256k1#1681: doc: Recommend clang-cl when building on Windows
Merge bitcoin-core/secp256k1#1737: doc: mention ctx requirement for `_ellswift_create` (not secp256k1_context_static)
Merge bitcoin-core/secp256k1#1738: check-abi: remove support for obsolete CMake library output location (src/libsecp256k1.so)
This PR can be recreated with `./contrib/sync-upstream.sh -b master range 36e7695`.
Tips:
* Use `git show --remerge-diff <pr-branch>` to show the conflict resolution in the merge commit.
* Use `git read-tree --reset -u <pr-branch>` to replay these resolutions during the conflict resolution stage when recreating the PR branch locally.
Be aware that this may discard your index as well as the uncommitted changes and untracked files in your worktree.
ACKs for top commit:
real-or-random:
ACK 01b1b916eb
Tree-SHA512: 3d945e55313eb0afde66bd2064edd169854294f9e1e185e6199beec2a079f872cd3172d00e9c4da6cda25ccf296ddd3f205280076f94d009941eab4e319bcd0a
7ab8b0cc01 release cleanup: bump version after 0.7.0 (Jonas Nick)
a3e742d947 release: Prepare for 0.7.0 (Tim Ruffing)
f67b0ac1a0 ci: Don't hardcode ABI version (Tim Ruffing)
cde4130898 musig/tests: initialize keypair (Jonas Nick)
40b4a06520 changelog: update (Jonas Nick)
8d967a602b musig/test: Remove dead code (Tim Ruffing)
983711cd6d musig/tests: Refactor vectors_signverify (Tim Ruffing)
c82d84bb86 build: add CMake option for disabling symbol visibility attributes (Cory Fields)
ce7923874f build: Add SECP256K1_NO_API_VISIBILITY_ATTRIBUTES (Tim Ruffing)
e5297f6d79 build: Refactor visibility logic (Tim Ruffing)
bf082221ff cmake: Make `secp256k1_objs` inherit interface defines from `secp256k1` (Hennadii Stepanov)
3352f9d667 ci: enable musig module for native macOS arm64 job (Sebastian Falbesoner)
44b205e9ee Revert "cmake: configure libsecp256k1.pc during install" (Daniel Pfeifer)
004f57fcd8 ci: Move Valgrind build for `arm64` from Cirrus to GHA (Hennadii Stepanov)
5fafdfc30f ci: Move `gcc-snapshot` build for `arm64` from Cirrus to GHA (Hennadii Stepanov)
e814b79a8b ci: Switch `arm64_debian` from QEMU to native `arm64` Docker image (Hennadii Stepanov)
bcf77346b9 ci: Add `arm64` architecture to `docker_cache` job (Hennadii Stepanov)
b77aae9226 ci: Rename Docker image tag to reflect architecture (Hennadii Stepanov)
0dfe387dbe cmake: support the use of launchers in ctest -S scripts (Daniel Pfeifer)
7106dce6fd cmake: configure libsecp256k1.pc during install (Daniel Pfeifer)
37dd422b5c cmake: Emulate Libtool's behavior on FreeBSD (Hennadii Stepanov)
Pull request description:
Merge bitcoin-core/secp256k1#1685: cmake: Emulate Libtool's behavior on FreeBSD
Merge bitcoin-core/secp256k1#1692: cmake: configure libsecp256k1.pc during install
Merge bitcoin-core/secp256k1#1687: cmake: support the use of launchers in ctest -S scripts
Merge bitcoin-core/secp256k1#1689: ci: Convert `arm64` Cirrus tasks to GHA jobs
Merge bitcoin-core/secp256k1#1694: Revert "cmake: configure libsecp256k1.pc during install"
Merge bitcoin-core/secp256k1#1699: ci: enable musig module for native macOS arm64 job
Merge bitcoin-core/secp256k1#1704: cmake: Make `secp256k1_objs` inherit interface defines from `secp256k1`
Merge bitcoin-core/secp256k1#1696: build: Refactor visibility logic and add override
Merge bitcoin-core/secp256k1#1705: musig/test: Remove dead code
Merge bitcoin-core/secp256k1#1702: changelog: update
Merge bitcoin-core/secp256k1#1706: musig/tests: initialize keypair
Merge bitcoin-core/secp256k1#1707: release: Prepare for 0.7.0
Merge bitcoin-core/secp256k1#1708: release cleanup: bump version after 0.7.0
This PR can be recreated with `./contrib/sync-upstream.sh -b master range b9313c6e`.
Tips:
* Use `git show --remerge-diff <pr-branch>` to show the conflict resolution in the merge commit.
* Use `git read-tree --reset -u <pr-branch>` to replay these resolutions during the conflict resolution stage when recreating the PR branch locally.
Be aware that this may discard your index as well as the uncommitted changes and untracked files in your worktree.
ACKs for top commit:
real-or-random:
ACK 9dcd857d54
Tree-SHA512: 4f5844185006fc4d3551febc6803096a36bcf49b0b9042e8d6ed0d7f6856de6bba44a69063406bb421b644708a91981a378133683f850ee1cf23275eab13b0c8
4dda31229e ci: Use Python virtual environment in x86_64-macos-native job (mllwchrry)
795f19af1f ci: Switch to macOS 15 Sequoia Intel-based image (Hennadii Stepanov)
2f057a145f ci: Don't hardcode ABI version (Tim Ruffing)
17ad196018 schnorrsig_halfagg: Fix symbol visibility for internal function (mllwchrry)
ec343f0b2f Port bitcoin-core/secp256k1#1642 to zkp-specific code (mllwchrry)
20b05c9d3f configure: Show exhaustive tests in summary (Tim Ruffing)
1b6e081538 include: remove WARN_UNUSED_RESULT for functions always returning 1 (Jonas Nick)
d87c3bc58f ci: Fix exiting from ci.sh on error (Tim Ruffing)
51907fa918 tests: remove unused uncounting_illegal_callback_fn (Jonas Nick)
d1478763a5 build: Drop no longer needed `-fvisibility=hidden` compiler option (Hennadii Stepanov)
8ed1d83d92 ci: Run `tools/symbol-check.py` (Hennadii Stepanov)
41d32ab2de test: Add `tools/symbol-check.py` (Hennadii Stepanov)
88548058b3 Introduce `SECP256K1_LOCAL_VAR` macro (Hennadii Stepanov)
37d2c60bec Remove deprecated _ec_privkey_{negate,tweak_add,tweak_mul} aliases (Sebastian Falbesoner)
59860bcc24 gha: Print all *.log files, in a separate action (Tim Ruffing)
4c50d73dd9 ci: Add new "Windows (clang-cl)" job (Hennadii Stepanov)
84c0bd1f72 cmake: Adjust diagnostic flags for clang-cl (Hennadii Stepanov)
961ec25a83 musig: Fix clearing of pubnonces (Tim Ruffing)
64228a648f musig: Use _ge_set_all_gej for own public nonces (Tim Ruffing)
300aab1c05 tests: Improve _ge_set_all_gej(_var) tests (Tim Ruffing)
365f274ce3 group: Simplify secp256k1_ge_set_all_gej (Tim Ruffing)
d3082ddead group: Add constant-time secp256k1_ge_set_all_gej (Tim Ruffing)
432ac57705 Make static context const (Daniel Pfeifer)
1823594761 Verify `compressed` argument in `secp256k1_eckey_pubkey_serialize` (Sebastian Falbesoner)
Pull request description:
Merge bitcoin-core/secp256k1#1642: Verify `compressed` argument in `secp256k1_eckey_pubkey_serialize`
Merge bitcoin-core/secp256k1#1639: Make static context const
Merge bitcoin-core/secp256k1#1614: Add _ge_set_all_gej and use it in musig for own public nonces
Merge bitcoin-core/secp256k1#1656: musig: Fix clearing of pubnonces
Merge bitcoin-core/secp256k1#1647: cmake: Adjust diagnostic flags for `clang-cl`
Merge bitcoin-core/secp256k1#1655: gha: Print all *.log files, in a separate action
Merge bitcoin-core/secp256k1#1593: Remove deprecated `_ec_privkey_{negate,tweak_add,tweak_mul}` aliases from API
Merge bitcoin-core/secp256k1#1359: Fix symbol visibility issues, add test for it
Merge bitcoin-core/secp256k1#1657: tests: remove unused uncounting_illegal_callback_fn
Merge bitcoin-core/secp256k1#1660: ci: Fix exiting from ci.sh on error
Merge bitcoin-core/secp256k1#1659: include: remove WARN_UNUSED_RESULT for functions always returning 1
Merge bitcoin-core/secp256k1#1661: configure: Show exhaustive tests in summary
This PR can be recreated with `./contrib/sync-upstream.sh -b master range d84bb83e`.
Tips:
* Use `git show --remerge-diff <pr-branch>` to show the conflict resolution in the merge commit.
* Use `git read-tree --reset -u <pr-branch>` to replay these resolutions during the conflict resolution stage when recreating the PR branch locally.
Be aware that this may discard your index as well as the uncommitted changes and untracked files in your worktree.
Additional fixes:
* schnorrsig_halfagg: Added `static` to internal helper function to pass `symbol-check.py` introduced in bitcoin-core/secp256k1#1359.
* ci: Cherry-picked bitcoin-core/secp256k1@f67b0ac1 to fix hardcoded DLL version in symbol-check (zkp produces `libsecp256k1-0.dll`, not `-5.dll`)
ACKs for top commit:
real-or-random:
ACK 4dda31229e
Tree-SHA512: 56c6a7dc977fec9cd57330db2a4513b82ee2284e905b70f83d50e9b84f4606b83f695be8eece653ffd88b9852f0a7903662f8ab215434c56c7d3bf3062a3ed16
e3bddfa750 modules: Port bitcoin-core/secp256k1#1579 to zkp-specific code (DarkWindman)
13d389629a CONTRIBUTING: mention that `EXIT_` codes should be used (Sebastian Falbesoner)
c855581728 test, bench, precompute_ecmult: use `EXIT_...` constants for `main` return values (Sebastian Falbesoner)
965393fcea examples: use `EXIT_...` constants for `main` return values (Sebastian Falbesoner)
b682dbcf84 README: add instructions for verifying GPG signatures (James O'Beirne)
a82287fb85 schnorrsig: clear out masked secret key in BIP-340 nonce function (Sebastian Falbesoner)
2ac9f558c4 doc: Improve cmake instructions in README (Fabian Jahr)
39705450eb Fix some misspellings (Nicolas Iooss)
c97059f594 release cleanup: bump version after 0.6.0 (Jonas Nick)
39d5dfd542 release: prepare for 0.6.0 (Jonas Nick)
df2eceb279 build: add ellswift.md and musig.md to release tarball (Jonas Nick)
a306bb7e90 tools: fix check-abi.sh after cmake out locations were changed (Jonas Nick)
145868a84d Do not export `secp256k1_musig_nonce_gen_internal` (Hennadii Stepanov)
765ef53335 Clear _gej instances after point multiplication to avoid potential leaks (Sebastian Falbesoner)
349e6ab916 Introduce separate _clear functions for hash module (Tim Ruffing)
99cc9fd6d0 Don't rely on memset to set signed integers to 0 (Tim Ruffing)
97c57f42ba Implement various _clear() functions with secp256k1_memclear() (Tim Ruffing)
9bb368d146 Use secp256k1_memclear() to clear stack memory instead of memset() (Tim Ruffing)
e3497bbf00 Separate between clearing memory and setting to zero in tests (Tim Ruffing)
d79a6ccd43 Separate secp256k1_fe_set_int( . , 0 ) from secp256k1_fe_clear() (Tim Ruffing)
1c08126222 Add secp256k1_memclear() for clearing secret data (Tim Ruffing)
e7d384488e Don't clear secrets in pippenger implementation (Tim Ruffing)
Pull request description:
Merge bitcoin-core/secp256k1#1579: Clear sensitive memory without getting optimized out (revival of #636)
Merge bitcoin-core/secp256k1#1631: release: prepare for 0.6.0
Merge bitcoin-core/secp256k1#1633: release cleanup: bump version after 0.6.0
Merge bitcoin-core/secp256k1#1634: Fix some misspellings
Merge bitcoin-core/secp256k1#1641: doc: Improve cmake instructions in README
Merge bitcoin-core/secp256k1#1650: schnorrsig: clear out masked secret key in BIP-340 nonce function
Merge bitcoin-core/secp256k1#1646: README: add instructions for verifying GPG signatures
Merge bitcoin-core/secp256k1#1654: use `EXIT_` constants over magic numbers for indicating program execution status
This PR can be recreated with `./contrib/sync-upstream.sh -b master range c0d9480`.
Tips:
* Use `git show --remerge-diff <pr-branch>` to show the conflict resolution in the merge commit.
* Use `git read-tree --reset -u <pr-branch>` to replay these resolutions during the conflict resolution stage when recreating the PR branch locally.
Be aware that this may discard your index as well as the uncommitted changes and untracked files in your worktree.
### zkp fixes for Valgrind compatibility
PR #1579 introduced `secp256k1_memclear` that marks cleared memory as undefined. Updated rangeproof to use `memset`/`secp256k1_scalar_set_int` for initialization, keeping `memclear` only for cleanup.
ACKs for top commit:
real-or-random:
ACK e3bddfa750
Tree-SHA512: 7a089d1c6cb34dd0706d53a9a92c0aecc6183a60c77de147ba97db9133bb96031aa2178e0cc07017c76fb30048697c1d976eb7b6c206fa50984d28487cf023f6
a8e6a3cc34 Port bitcoin-core/secp256k1#1628 to zkp public API (mllwchrry)
694342fdb7 Name public API structs (Ava Chow)
0f73caf7c6 test, ci: Lower default iteration count to 16 (Hennadii Stepanov)
87384f5c0f cmake, test: Add `secp256k1_` prefix to test names (Hennadii Stepanov)
980c08df80 util: Remove unused (u)int64_t formatting macros (Tim Ruffing)
096e3e23f6 ci: Update macOS image (Hennadii Stepanov)
57eda3ba30 musig: ctimetests: fix _declassify range for generated nonce points (Sebastian Falbesoner)
447334cb06 include: Avoid visibility("default") on Windows (Tim Ruffing)
8be3839fb2 Remove unused scratch space from API (Jonas Nick)
c232486d84 Revert "cmake: Set `ENVIRONMENT` property for examples on Windows" (Hennadii Stepanov)
26e4a7c214 cmake: Set top-level target output locations (Hennadii Stepanov)
5bab8f6d3c examples: make key generation doc consistent (Jonas Nick)
e8908221a4 examples: do not retry generating seckey randomness in musig (Jonas Nick)
70b6be1834 extrakeys: improve doc of keypair_create (don't suggest retry) (Jonas Nick)
cd4f84f3ba Improve examples/documentation: remove key generation loops (cheapshot003)
ef7ff03407 f can never equal -m (Russell O'Connor)
Pull request description:
Merge bitcoin-core/secp256k1#1603: f can never equal -m
Merge bitcoin-core/secp256k1#1599: #1570 improve examples: remove key generation loop
Merge bitcoin-core/secp256k1#1616: examples: do not retry generating seckey randomness in musig
Merge bitcoin-core/secp256k1#1553: cmake: Set top-level target output locations
Merge bitcoin-core/secp256k1#1620: Remove unused scratch space from API
Merge bitcoin-core/secp256k1#1595: build: 45839th attempt to fix symbol visibility on Windows
Merge bitcoin-core/secp256k1#1619: musig: ctimetests: fix _declassify range for generated nonce points
Merge bitcoin-core/secp256k1#1624: ci: Update macOS image
Merge bitcoin-core/secp256k1#1625: util: Remove unused (u)int64_t formatting macros
Merge bitcoin-core/secp256k1#1582: cmake, test: Add `secp256k1_` prefix to test names
Merge bitcoin-core/secp256k1#1581: test, ci: Lower default iteration count to 16
Merge bitcoin-core/secp256k1#1628: Name public API structs
This PR can be recreated with `./contrib/sync-upstream.sh -b master range a38d879a`.
Tips:
* Use `git show --remerge-diff <pr-branch>` to show the conflict resolution in the merge commit.
* Use `git read-tree --reset -u <pr-branch>` to replay these resolutions during the conflict resolution stage when recreating the PR branch locally.
Be aware that this may discard your index as well as the uncommitted changes and untracked files in your worktree.
ACKs for top commit:
real-or-random:
ACK a8e6a3cc34
Tree-SHA512: 662518c9f569066402d4b5890abe33d7dc9662bcc2006b42ad83cc08f0a2be6ff923a792681a797b191ed7dd7882155c1eadbc8387011e9c5a10d06183cefb56
7c987ec89e cmake: Call `enable_testing()` unconditionally (Hennadii Stepanov)
6aa576515e cmake: Delete `CTest` module (Hennadii Stepanov)
292310fbb2 doc: fix typos in `secp256k1_ecdsa_{recoverable_,}signature` API description (Sebastian Falbesoner)
421ed1b46f cmake: Introduce `SECP256K1_APPEND_LDFLAGS` variable (Hennadii Stepanov)
9b0f37bff1 fix: remove duplicate 'the' from header file comment (Epic Curious)
fa67b6752d refactor: Use array initialization for unterminated strings (MarcoFalke)
e34b476730 ci: Bump GCC_SNAPSHOT_MAJOR to 15 (maflcko)
7057d3c9af ci: Silent Homebrew's noisy reinstall warnings (Hennadii Stepanov)
c3e40d75db release cleanup: bump version after 0.5.1 (Jonas Nick)
40d87b8e45 release: prepare for 0.5.1 (Jonas Nick)
5770226176 changelog: clarify CMake option (Jonas Nick)
759bd4bbc8 doc: mention `needs-changelog` github label in release process (Jonas Nick)
763d938cf0 ci: only enable extrakeys module when schnorrsig is enabled (Jonas Nick)
af551ab9db tests: do not use functions from extrakeys module (Jonas Nick)
Pull request description:
Merge bitcoin-core/secp256k1#1574: Fix compilation when extrakeys module isn't enabled
Merge bitcoin-core/secp256k1#1576: doc: mention `needs-changelog` github label in release process
Merge bitcoin-core/secp256k1#1575: release: prepare for 0.5.1
Merge bitcoin-core/secp256k1#1577: release cleanup: bump version after 0.5.1
Merge bitcoin-core/secp256k1#1578: ci: Silent Homebrew's noisy reinstall warnings
Merge bitcoin-core/secp256k1#1583: ci: Bump GCC_SNAPSHOT_MAJOR to 15
Merge bitcoin-core/secp256k1#1586: fix: remove duplicate 'the' from header file comment
Merge bitcoin-core/secp256k1#1600: cmake: Introduce `SECP256K1_APPEND_LDFLAGS` variable
Merge bitcoin-core/secp256k1#1604: doc: fix typos in `secp256k1_ecdsa_{recoverable_,}signature` API description
Merge bitcoin-core/secp256k1#1554: cmake: Clean up testing code
This PR can be recreated with `./contrib/sync-upstream.sh -b master range 4c57c7a`.
Tips:
* Use `git show --remerge-diff <pr-branch>` to show the conflict resolution in the merge commit.
* Use `git read-tree --reset -u <pr-branch>` to replay these resolutions during the conflict resolution stage when recreating the PR branch locally.
Be aware that this may discard your index as well as the uncommitted changes and untracked files in your worktree.
ACKs for top commit:
real-or-random:
ACK 551b5dd415
Tree-SHA512: f05d1f21fbd373929666174e0396c46212f28a0ae819e244b7c6b620d0e9aee9ae11bad1d1616cafc34dd375c3635c7637ce25123c66ce92f247ae0fb063be9a
31f84595c4 Add ellswift usage example (Sebastian Falbesoner)
fe4fbaa7f3 examples: fix case typos in secret clearing paragraphs (s/, Or/, or/) (Sebastian Falbesoner)
16685649d2 doc: Add convention for defaults (Tim Ruffing)
e2af491263 ci: Switch to the new default value of the precomputed table for signing (Hennadii Stepanov)
d94a9273f8 build: Adjust the default size of the precomputed table for signing (Hennadii Stepanov)
9420eece24 cmake: Bump CMake minimum required version up to 3.16 (Hennadii Stepanov)
b8fe33332b cmake: Fixed O3 replacement (Eduardo Menges Mattje)
4d9645bee0 cmake: Remove "AUTO" value of `SECP256K1_ECMULT_GEN_KB` option (Hennadii Stepanov)
a06805ee74 cmake: Remove "AUTO" value of `SECP256K1_ECMULT_WINDOW_SIZE` option (Hennadii Stepanov)
26b94ee92a autotools: Remove "auto" value of `--with-ecmult-gen-kb` option (Hennadii Stepanov)
122dbaeb37 autotools: Remove "auto" value of `--with-ecmult-window` option (Hennadii Stepanov)
158f9e5eae cmake: Do not modify build types when integrating by downstream project (Hennadii Stepanov)
4706be2cd0 cmake: Reimplement `SECP256K1_APPEND_CFLAGS` using Bitcoin Core approach (Hennadii Stepanov)
c2764dbb99 cmake: Rename `SECP256K1_LATE_CFLAGS` to `SECP256K1_APPEND_CFLAGS` (Hennadii Stepanov)
0e2fadb20c fix: typos in secp256k1.c (Elliot Lee)
f87a3589f4 cmake: Do not set `CTEST_TEST_TARGET_ALIAS` (Hennadii Stepanov)
7454a53736 README: mention ellswift module (Sebastian Falbesoner)
ec4c002faa cmake: Simplify `PROJECT_IS_TOP_LEVEL` emulation (Hennadii Stepanov)
cae9a7ad14 cmake: Do not set emulated PROJECT_IS_TOP_LEVEL as cache variable (Hennadii Stepanov)
Pull request description:
Merge bitcoin-core/secp256k1#1529: cmake: Fix cache issue when integrating by downstream project
Merge bitcoin-core/secp256k1#1548: README: mention ellswift module
Merge bitcoin-core/secp256k1#1545: cmake: Do not set `CTEST_TEST_TARGET_ALIAS`
Merge bitcoin-core/secp256k1#1550: fix: typos in secp256k1.c
Merge bitcoin-core/secp256k1#1546: cmake: Rename `SECP256K1_LATE_CFLAGS` and switch to Bitcoin Core's approach
Merge bitcoin-core/secp256k1#1543: cmake: Do not modify build types when integrating by downstream project
Merge bitcoin-core/secp256k1#1535: build: Replace hardcoded "auto" value with default one
Merge bitcoin-core/secp256k1#1555: Fixed O3 replacement
Merge bitcoin-core/secp256k1#1565: cmake: Bump CMake minimum required version up to 3.16
Merge bitcoin-core/secp256k1#1564: build, ci: Adjust the default size of the precomputed table for signing
Merge bitcoin-core/secp256k1#1563: doc: Add convention for defaults
Merge bitcoin-core/secp256k1#1551: Add ellswift usage example
This PR can be recreated with `./contrib/sync-upstream.sh -b master range 0055b86`.
Tips:
* Use `git show --remerge-diff <pr-branch>` to show the conflict resolution in the merge commit.
* Use `git read-tree --reset -u <pr-branch>` to replay these resolutions during the conflict resolution stage when recreating the PR branch locally.
Be aware that this may discard your index as well as the uncommitted changes and untracked files in your worktree.
ACKs for top commit:
real-or-random:
ACK d0dde4aa2a
Tree-SHA512: 8551626c0f183c495cbbc12d9c292e1995ce4b5558f950e1a2ca84188724884180117f9bcc10c0d2f3e73da054c5b4647efaa8282be74936f4d156038b1c10da
The LLVM apt repository uses legacy SHA1 signatures which are now
rejected by the stricter Sequoia PGP policy.
This change extends the 'sha1.second_preimage_resistance' cutoff date to
9999-01-01 in the default Sequoia config. This effectively whitelists
the legacy signature algorithm, preventing "OpenPGP signature
verification failed" errors during `apt-get update`.
See https://github.com/llvm/llvm-project/issues/153385.
2cb2e312e9 extrakeys: Migrate to bitcoin-core/secp256k1#1518 secp256k1_ec_pubkey_sort (DarkWindman)
7d2591ce12 Add secp256k1_pubkey_sort (Jonas Nick)
Pull request description:
Merge bitcoin-core/secp256k1#1518: Add secp256k1_pubkey_sort
This PR can be recreated with `./contrib/sync-upstream.sh -b master range bb528cf`.
Tip: Use `git show --remerge-diff` to show the changes manually added to the merge commit.
ACKs for top commit:
real-or-random:
ACK 2cb2e312e9
Tree-SHA512: dbdb6c5df2195d2ece9574367e0f684a651ea199806a80232c85b0ffd0ba6b930b108bd97385d9fab656754a85fa6de223a93b945046b043aab20ad7bb3d1bff
96a415b1c0 scalar: Port bitcoin-core/secp256k1#1393 to zkp-specific code (mllwchrry)
Pull request description:
Add the `SECP256K1_SCALAR_VERIFY` macro to the zkp-specific `secp256k1_scalar_set_u64` function.
This was missed when upstream PRs bitcoin-core/secp256k1#1373 and bitcoin-core/secp256k1#1393 were merged.
ACKs for top commit:
real-or-random:
ACK 96a415b1c0
Tree-SHA512: 4c3c6209e4c27bec7afc07398c9fc50aef7d44850fbbf5969ff4b57991279960c9645c8daeee5d78bee54dac7fe85bc3d9a01ba4b9deb761d574ae6221ef41c1