diff --git a/Cargo.toml b/Cargo.toml index b6c5681..84d326e 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -67,7 +67,10 @@ alloc = [] yolocrypto = ["avx2_backend"] # Radix-51 arithmetic using u128 radix_51 = [] -# Include precomputed basepoint tables. This is off by default so that build.rs can generate the tables, and then re-enabled by build.rs in the main-stage compilation. -precomputed_tables = [] # experimental avx2 support avx2_backend = ["nightly"] +# Signals that we're in the main build stage. This is off by default, +# to signal stage 1 of the build, where build.rs loads the library +# into the build script. Then, the build.rs emits the stage2_build +# feature before the main-stage compilation. +stage2_build = [] diff --git a/build.rs b/build.rs index 389e7bb..52c66bd 100644 --- a/build.rs +++ b/build.rs @@ -62,8 +62,8 @@ use curve_models::AffineNielsPoint; use scalar_mul::window::NafLookupTable8; fn main() { - // Enable the "precomputed_tables" feature in the main build stage - println!("cargo:rustc-cfg=feature=\"precomputed_tables\"\n"); + // Enable the "stage2_build" feature in the main build stage + println!("cargo:rustc-cfg=feature=\"stage2_build\"\n"); let out_dir = env::var("OUT_DIR").unwrap(); let dest_path = Path::new(&out_dir).join("basepoint_table.rs"); diff --git a/src/backend/avx2/mod.rs b/src/backend/avx2/mod.rs index 94cf55a..b13ea1d 100644 --- a/src/backend/avx2/mod.rs +++ b/src/backend/avx2/mod.rs @@ -9,7 +9,9 @@ // - Henry de Valence // See the comment above the ristretto::notes module. -#![cfg_attr(all(feature = "nightly", feature="precomputed_tables"), doc(include = "../docs/avx2-notes.md"))] +#![cfg_attr( + all(feature = "nightly", feature = "stage2_build"), doc(include = "../docs/avx2-notes.md") +)] pub(crate) mod field; diff --git a/src/backend/avx2/scalar_mul/mod.rs b/src/backend/avx2/scalar_mul/mod.rs index c4c944b..f59cba2 100644 --- a/src/backend/avx2/scalar_mul/mod.rs +++ b/src/backend/avx2/scalar_mul/mod.rs @@ -10,7 +10,7 @@ pub mod variable_base; -#[cfg(feature="precomputed_tables")] +#[cfg(feature = "stage2_build")] pub mod vartime_double_base; #[cfg(any(feature = "alloc", feature = "std"))] diff --git a/src/constants.rs b/src/constants.rs index c8cf1c1..247f094 100644 --- a/src/constants.rs +++ b/src/constants.rs @@ -85,14 +85,14 @@ pub const BASEPOINT_ORDER: Scalar = Scalar{ // Precomputed basepoint table is generated into a file by build.rs -#[cfg(feature="precomputed_tables")] +#[cfg(feature = "stage2_build")] include!(concat!(env!("OUT_DIR"), "/basepoint_table.rs")); -#[cfg(feature="precomputed_tables")] +#[cfg(feature = "stage2_build")] use ristretto::RistrettoBasepointTable; /// The Ristretto basepoint, as a `RistrettoBasepointTable` for scalar multiplication. -#[cfg(feature="precomputed_tables")] +#[cfg(feature = "stage2_build")] pub const RISTRETTO_BASEPOINT_TABLE: RistrettoBasepointTable = RistrettoBasepointTable(ED25519_BASEPOINT_TABLE); diff --git a/src/edwards.rs b/src/edwards.rs index 5ba490c..95a208e 100644 --- a/src/edwards.rs +++ b/src/edwards.rs @@ -858,7 +858,7 @@ pub mod vartime { } /// Compute \\(aA + bB\\) in variable time, where \\(B\\) is the Ed25519 basepoint. - #[cfg(feature="precomputed_tables")] + #[cfg(feature="stage2_build")] pub fn double_scalar_mul_basepoint(a: &Scalar, A: &EdwardsPoint, b: &Scalar) -> EdwardsPoint { // If we built with AVX2, use the AVX2 backend. #[cfg(all(feature="nightly", all(feature="avx2_backend", target_feature="avx2")))] @@ -879,7 +879,7 @@ pub mod vartime { // Tests // ------------------------------------------------------------------------ -#[cfg(test)] +#[cfg(all(test, feature = "stage2_build"))] mod test { use field::FieldElement; use scalar::Scalar; @@ -971,7 +971,6 @@ mod test { /// Test that computing 1*basepoint gives the correct basepoint. #[test] - #[cfg(feature="precomputed_tables")] fn basepoint_mult_one_vs_basepoint() { let bp = &constants::ED25519_BASEPOINT_TABLE * &Scalar::one(); let compressed = bp.compress(); @@ -980,7 +979,6 @@ mod test { /// Test that `EdwardsBasepointTable::basepoint()` gives the correct basepoint. #[test] - #[cfg(feature="precomputed_tables")] fn basepoint_table_basepoint_function_correct() { let bp = constants::ED25519_BASEPOINT_TABLE.basepoint(); assert_eq!(bp.compress(), constants::ED25519_BASEPOINT_COMPRESSED); @@ -1031,7 +1029,6 @@ mod test { /// Sanity check for conversion to precomputed points #[test] - #[cfg(feature="precomputed_tables")] fn to_affine_niels_clears_denominators() { // construct a point as aB so it has denominators (ie. Z != 1) let aB = &constants::ED25519_BASEPOINT_TABLE * &A_SCALAR; @@ -1043,7 +1040,6 @@ mod test { /// Test basepoint_mult versus a known scalar multiple from ed25519.py #[test] - #[cfg(feature="precomputed_tables")] fn basepoint_mult_vs_ed25519py() { let aB = &constants::ED25519_BASEPOINT_TABLE * &A_SCALAR; assert_eq!(aB.compress(), A_TIMES_BASEPOINT); @@ -1051,7 +1047,6 @@ mod test { /// Test that multiplication by the basepoint order kills the basepoint #[test] - #[cfg(feature="precomputed_tables")] fn basepoint_mult_by_basepoint_order() { let B = &constants::ED25519_BASEPOINT_TABLE; let should_be_id = B * &constants::BASEPOINT_ORDER; @@ -1060,11 +1055,9 @@ mod test { /// Test precomputed basepoint mult #[test] - #[cfg(feature="precomputed_tables")] fn test_precomputed_basepoint_mult() { - let table = EdwardsBasepointTable::create(&constants::ED25519_BASEPOINT_POINT); let aB_1 = &constants::ED25519_BASEPOINT_TABLE * &A_SCALAR; - let aB_2 = &table * &A_SCALAR; + let aB_2 = &constants::ED25519_BASEPOINT_POINT * &A_SCALAR; assert_eq!(aB_1.compress(), aB_2.compress()); } @@ -1084,7 +1077,6 @@ mod test { /// Test that computing 2*basepoint is the same as basepoint.double() #[test] - #[cfg(feature="precomputed_tables")] fn basepoint_mult_two_vs_basepoint2() { let two = Scalar::from_u64(2); let bp2 = &constants::ED25519_BASEPOINT_TABLE * &two; @@ -1210,7 +1202,6 @@ mod test { /// Test double_scalar_mul_vartime vs ed25519.py #[test] - #[cfg(feature="precomputed_tables")] fn double_scalar_mul_basepoint_vs_ed25519py() { let A = A_TIMES_BASEPOINT.decompress().unwrap(); let result = vartime::double_scalar_mul_basepoint(&A_SCALAR, &A, &B_SCALAR); diff --git a/src/montgomery.rs b/src/montgomery.rs index 0ebca9a..ad03c69 100644 --- a/src/montgomery.rs +++ b/src/montgomery.rs @@ -279,7 +279,7 @@ impl<'a, 'b> Mul<&'b MontgomeryPoint> for &'a Scalar { // Tests // ------------------------------------------------------------------------ -#[cfg(test)] +#[cfg(all(test, feature = "stage2_build"))] mod test { use constants; use super::*; @@ -338,7 +338,6 @@ mod test { } #[test] - #[cfg(feature="precomputed_tables")] fn montgomery_ladder_matches_edwards_scalarmult() { let mut csprng: OsRng = OsRng::new().unwrap(); diff --git a/src/ristretto.rs b/src/ristretto.rs index c5b86f6..b293fb8 100644 --- a/src/ristretto.rs +++ b/src/ristretto.rs @@ -161,7 +161,7 @@ // missing). // // This hack is also used in the avx2 notes. -#[cfg_attr(all(feature = "nightly", feature="precomputed_tables"), doc(include = "../docs/ristretto-notes.md"))] +#[cfg_attr(all(feature = "nightly", feature = "stage2_build"), doc(include = "../docs/ristretto-notes.md"))] mod notes { } @@ -1014,7 +1014,7 @@ pub mod vartime { // Tests // ------------------------------------------------------------------------ -#[cfg(test)] +#[cfg(all(test, feature = "stage2_build"))] mod test { use rand::OsRng; @@ -1152,7 +1152,6 @@ mod test { } #[test] - #[cfg(feature="precomputed_tables")] fn four_torsion_random() { let mut rng = OsRng::new().unwrap(); let B = &constants::RISTRETTO_BASEPOINT_TABLE; @@ -1215,7 +1214,6 @@ mod test { } #[test] - #[cfg(feature="precomputed_tables")] fn random_roundtrip() { let mut rng = OsRng::new().unwrap(); let B = &constants::RISTRETTO_BASEPOINT_TABLE; diff --git a/src/scalar_mul/mod.rs b/src/scalar_mul/mod.rs index f172788..78ba7cd 100644 --- a/src/scalar_mul/mod.rs +++ b/src/scalar_mul/mod.rs @@ -12,7 +12,7 @@ pub mod window; pub mod variable_base; -#[cfg(feature="precomputed_tables")] +#[cfg(feature = "stage2_build")] pub mod vartime_double_base; #[cfg(any(feature = "alloc", feature = "std"))]