From d54b196d18cb1a443907ea6af389d223af0161ff Mon Sep 17 00:00:00 2001 From: Aaron Feickert <66188213+AaronFeickert@users.noreply.github.com> Date: Mon, 7 Jul 2025 16:01:55 -0500 Subject: [PATCH] curve: Use constant-time compressed equality testing (#669) --- curve25519-dalek/src/ristretto.rs | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/curve25519-dalek/src/ristretto.rs b/curve25519-dalek/src/ristretto.rs index 9c71728..ca5fa88 100644 --- a/curve25519-dalek/src/ristretto.rs +++ b/curve25519-dalek/src/ristretto.rs @@ -218,9 +218,17 @@ use crate::traits::{MultiscalarMul, VartimeMultiscalarMul, VartimePrecomputedMul /// /// The Ristretto encoding is canonical, so two points are equal if and /// only if their encodings are equal. -#[derive(Copy, Clone, Eq, PartialEq, Hash)] +#[allow(clippy::derived_hash_with_manual_eq)] +#[derive(Copy, Clone, Hash)] pub struct CompressedRistretto(pub [u8; 32]); +impl Eq for CompressedRistretto {} +impl PartialEq for CompressedRistretto { + fn eq(&self, other: &Self) -> bool { + self.ct_eq(other).into() + } +} + impl ConstantTimeEq for CompressedRistretto { fn ct_eq(&self, other: &CompressedRistretto) -> Choice { self.as_bytes().ct_eq(other.as_bytes())