mirror of
https://github.com/saymrwulf/anza-cryptography-source.git
synced 2026-09-10 21:21:04 +00:00
Compare commits
2 commits
e57e51ba68
...
ca701d2e7b
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ca701d2e7b | ||
| 5f8e70e636 |
1 changed files with 7 additions and 2 deletions
|
|
@ -121,7 +121,6 @@ use {
|
||||||
use rand_core::{CryptoRng, RngCore};
|
use rand_core::{CryptoRng, RngCore};
|
||||||
|
|
||||||
use subtle::Choice;
|
use subtle::Choice;
|
||||||
use subtle::ConditionallyNegatable;
|
|
||||||
use subtle::ConditionallySelectable;
|
use subtle::ConditionallySelectable;
|
||||||
use subtle::ConstantTimeEq;
|
use subtle::ConstantTimeEq;
|
||||||
|
|
||||||
|
|
@ -246,7 +245,13 @@ mod decompress {
|
||||||
// FieldElement::sqrt_ratio_i always returns the nonnegative square root,
|
// FieldElement::sqrt_ratio_i always returns the nonnegative square root,
|
||||||
// so we negate according to the supplied sign bit.
|
// so we negate according to the supplied sign bit.
|
||||||
let compressed_sign_bit = Choice::from(repr.as_bytes()[31] >> 7);
|
let compressed_sign_bit = Choice::from(repr.as_bytes()[31] >> 7);
|
||||||
X.conditional_negate(compressed_sign_bit);
|
// AENEAS-COMPAT: negate-then-conditional-assign instead of
|
||||||
|
// `X.conditional_negate(...)` — semantically identical and still
|
||||||
|
// constant-time, but avoids subtle's `ConditionallyNegatable`
|
||||||
|
// blanket impl which breaks the verification toolchain (the same
|
||||||
|
// documented rewrite as in `FieldElement::sqrt_ratio_i`).
|
||||||
|
let X_neg = -&X;
|
||||||
|
X.conditional_assign(&X_neg, compressed_sign_bit);
|
||||||
|
|
||||||
EdwardsPoint {
|
EdwardsPoint {
|
||||||
X,
|
X,
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue