Harden cryptographic primitive contracts - #209
Draft
wangxiao1254 wants to merge 6 commits into
Draft
wangxiao1254 wants to merge 6 commits into
wangxiao1254 wants to merge 6 commits into
Conversation
Use unsigned counters throughout AES-CTR expansion, reject negative and overflowing dimensions, and define empty compile-time shapes without dereferencing their buffers. Reset PRG buffered-word state on reseed and cover aligned and unaligned output across counter wrap, canary preservation, zero lengths, and byte-bool state parity. Add compile-fail probes for invalid AES shapes.
Reject negative vector lengths and invalid compile-time hash dimensions before pointer arithmetic or template instantiation. Define empty CCRH vector operations and preserve byte-bool selector support. Add compile-fail probes for invalid shapes plus focused zero-length, tail, and reference-equivalence tests.
Prevent loop-invariant motion in runtime AES measurements, report the active SIMD tier, and include small-vector and alignment boundaries. Correct F2K byte and cycle accounting, half-gate gate counts, and PRG alignment. Retain benchmark outputs against dead-code elimination and compare MITCCRH in-place, out-of-place, and unaligned-gid call shapes.
Use nonzero private scalar generation, bounded and padded scalar encodings, const-safe BIGNUM access, and deterministic test-mode rejection sampling. Validate random-oracle output sizes and domain-separation tags, clear stale OpenSSL errors before retryable map-to-curve operations, and reject unsupported curves and malformed encodings with focused tests.
Initialize MITCCRH state deterministically and require callers to install one shared public hash seed that is independent of the free-XOR delta. Pin the shared gid schedule and seed-independence contract across garbling and evaluation. Cover in-place and out-of-place hashing, reuse buckets, batch-size invariance, exhaustive gate truth tables, and secret-delta changes under a fixed public seed.
Mark derive() nodiscard so accidentally discarded child identifiers are diagnosed while value() remains the non-advancing accessor. Document copy and counter semantics and add direct tests for default, seeded, sequential, copied, and independently advanced derivation streams.
wangxiao1254
force-pushed
the
audit/crypto-foundations
branch
from
August 22, 2026 13:47
ad590de to
b3c2173
Compare
wangxiao1254
force-pushed
the
audit/core-contracts
branch
from
August 22, 2026 13:47
05e630f to
f32f40c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Harden the contracts of the runtime cryptographic primitives and correct their benchmark coverage and accounting.
Changes
AES and PRG
operator()words onPRG::reseed();CCRH, F2K, and MITCCRH
EC and random oracle
Half gates and SessionID
SessionID::derive()[[nodiscard]]and document copy/counter behavior.Benchmarks
The benchmark changes make the existing measurements faithful.
Compatibility
The stricter size/shape contracts fail before pointer arithmetic.
Scalar::n()becomes const-safe, and half-gate callers must provide the same public hash seed to garbler and evaluator independently of the delta.Tests
EMP_TOOL_NATIVE_ARCH=OFF): focused suite 10/10 and compile-failure contracts 16/16 passed.Coverage includes AES and crypto compile-fail probes, AES/PRG/CCRH/F2K/MITCCRH boundary and reference tests, EC/RO malformed-input tests, exhaustive half-gate truth tables, seed/gid invariants, and SessionID derivation streams.
Stack
This is PR 4 of 6 and targets
audit/core-contracts.