Skip to content

fix: Remove branching on carry propagation for Montgomery reduction - #166

Merged
hubot merged 1 commit into
bcgit:feature/ecdsafrom
laruizlo:feature/ecdsa--fix/montgomery-branching
Oct 6, 2026
Merged

hubot merged 1 commit into
bcgit:feature/ecdsafrom
laruizlo:feature/ecdsa--fix/montgomery-branching

Conversation

@laruizlo

@laruizlo laruizlo commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

Make REDC carry propagation a counted loop, removing a secret-dependent branching

  • replace the while carry != 0 tail in the five hand-written scalar REDCs and the shared montgomery::redc with a for over the limbs above the addition window, so the trip count depends only on the public round index, never on the (secret-derived) operands
  • behaviour is unchanged: once the carry has propagated out, the remaining iterations add 0; CAVP SigGen, wycheproof (all curves) and RFC 6979 suites pin identical signature bytes (760 tests pass)
  • release asm for all eleven redc/finish_redc functions now contains zero data-dependent conditional jumps (previously 22), making the branch-free contracts in ec/src/lib.rs and ecdsa/src/lib.rs accurate
  • diff-scoped cargo mutants (ec plus ecdsa test packages): 34/34 caught
  • rewrite the stale "genuinely reachable branch" and "accepted equivalent mutant" comments that described the old while loops

Assisted-by: Claude:claude-fable-5

…endent branch

- replace the `while carry != 0` tail in the five hand-written scalar
  REDCs and the shared montgomery::redc with a `for` over the limbs
  above the addition window, so the trip count depends only on the
  public round index, never on the (secret-derived) operands
- behaviour is unchanged: once the carry has propagated out, the
  remaining iterations add 0; CAVP SigGen, wycheproof (all curves) and
  RFC 6979 suites pin identical signature bytes (760 tests pass)
- release asm for all eleven redc/finish_redc functions now contains
  zero data-dependent conditional jumps (previously 22), making the
  branch-free contracts in ec/src/lib.rs and ecdsa/src/lib.rs accurate
- diff-scoped cargo mutants (ec plus ecdsa test packages): 34/34 caught
- rewrite the stale "genuinely reachable branch" and "accepted
  equivalent mutant" comments that described the old while loops

Assisted-by: Claude:claude-fable-5
@hubot
hubot merged commit 4dd5d84 into bcgit:feature/ecdsa Oct 6, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants