Repository navigation
Conversation
This change removes variable-time padding behavior by writing into fixed-width buffers instead of slicing based on secret leading-zero counts. It also enforces the RFC 8017 ciphertext-length check before PKCS#1 v1.5 decryption and avoids variable-time Montgomery reduction on private-key paths. The patch adds regression tests covering padding edge cases, PKCS#1 v1.5 length rejection, and Montgomery reduction correctness.
|
Overall I like the direction of this PR, thanks |
| let (hi, lo) = bytes.split_at(bytes.len() - padded_len); | ||
| let overflow = hi.iter().fold(0u8, |acc, b| acc | b); | ||
| out.copy_from_slice(lo); | ||
| if core::hint::black_box(overflow) != 0 { |
There was a problem hiding this comment.
This seems value-dependent? I'm also not sure what black_box is buying you here.
There was a problem hiding this comment.
Yup agreed on both black_box was really just an optimizer hint anyway I'm gonna push soon to address this
There was a problem hiding this comment.
Perhaps the function could be infallible and this could just be a debug_assert!? Then you can just add a precondition comment.
There was a problem hiding this comment.
I've worked a bit on it and chose to use Choice with a debug_assert! idk if it would be more convenient
|
Note: I created #711 as a tracking issue for constant-time problems and noted this PR addresses several of them, or at least attempts to partially address them |
This change removes variable-time padding behavior by writing into fixed-width buffers instead of slicing based on secret leading-zero counts. It also enforces the RFC 8017 ciphertext-length check before PKCS#1 v1.5 decryption and avoids variable-time Montgomery reduction on private-key paths. The patch adds regression tests covering padding edge cases, PKCS#1 v1.5 length rejection, and Montgomery reduction correctness.