Compare commits

..

1 commit

Author SHA1 Message Date
dependabot[bot]
e57e51ba68
Merge a7b121eccc into d275613c37 2026-07-04 21:01:19 +00:00

View file

@ -121,6 +121,7 @@ use {
use rand_core::{CryptoRng, RngCore};
use subtle::Choice;
use subtle::ConditionallyNegatable;
use subtle::ConditionallySelectable;
use subtle::ConstantTimeEq;
@ -245,13 +246,7 @@ mod decompress {
// FieldElement::sqrt_ratio_i always returns the nonnegative square root,
// so we negate according to the supplied sign bit.
let compressed_sign_bit = Choice::from(repr.as_bytes()[31] >> 7);
// AENEAS-COMPAT: negate-then-conditional-assign instead of
// `X.conditional_negate(...)` — semantically identical and still
// constant-time, but avoids subtle's `ConditionallyNegatable`
// blanket impl which breaks the verification toolchain (the same
// documented rewrite as in `FieldElement::sqrt_ratio_i`).
let X_neg = -&X;
X.conditional_assign(&X_neg, compressed_sign_bit);
X.conditional_negate(compressed_sign_bit);
EdwardsPoint {
X,