Repository navigation
Guard decoder lengths and nullable input fields - #12
Merged
Merged
Conversation
Validate helper inputs before indexed reads and coordinate-buffer allocation, require a commitment payload, and propagate nil signing point results through the existing error paths. Preserve base proof arities, optional-mode proof serialization, nil-key parameter skips, and valid routing and point encodings. Adapted from upstream commits: f1588ae (WC decoder arity) 8deab46 (sender metadata guards) 1a8e277 (embedded PartyID guards) 8069c6c (SortedPartyIDs.Keys guard) 6e0bcd4 (shared nullable-input guards) 58a131c (commitment minimum parts) cbb8fe4 (commitment boundary coverage) e65fb36 (Gob coordinate allocation bounds) 8acae9a (signing nil-result guards) 1693884 (PartyID.String content guard)
Merge origin/dev (contains #18/#20/#21) into the input-guards branch. Auto-merged cleanly (no textual conflicts); key choices: - go.mod/go.sum: adopt origin/dev toolchain and dependencies (go 1.25.7, toolchain go1.26.8, x/crypto v0.52.0, x/sys v0.45.0, protobuf v1.33.0, btcd v0.24.2, btcec/v2 v2.2.0, btcutil v1.1.5, bigmod v0.1.0) per the integration contract. - crypto/mta/proofs.go: keep #12 decoder guards (ProofBobWC 12-part arity, Bytes nil-receiver panics) plus dev's CT/sampling changes; changes were in disjoint regions and both survived.
Second integration pass: origin/dev advanced to 0efe90c (merged #17 ct-defaults-and-bounds and #23 ct-hardening-schnorr-signing-coverage after the first merge at 39e7d87). Auto-merged cleanly; key choices: - crypto/mta/proofs.go: disjoint regions survived both sides — #12 decoder guards (ProofBobWC 12-part arity, Bytes nil-receiver panics) plus #17/#23 CT changes on the same file. - ecdsa/signing/round_5.go: #12 R == nil guard retained below the #23 CT-context hunks; no conflict. - go.mod/go.sum: origin/dev dependency set retained.
|
Merged into Verification:
Follow-up findings from variant analysis, not regressions introduced here: direct keygen proof-decoder arity/nil guards, RangeProofAlice.Bytes symmetry, and the upstream ModProof 65,536-bit allocation ceiling remain to be handled in a separate hardening/test PR. The ModProof gap is not wire-reachable in shipped keygen (wire moduli are pinned to 2048 bits) but is reachable through the exported API. Full report: agent-docs/pr-integration/12.md (local). |
piotr-roslaniec
added a commit
that referenced
this pull request
Sep 29, 2026
Merge current origin/dev (includes #12/#13/#15) into PR #14. Conflict choices: - No textual conflicts; clean automatic merge. - Go toolchain/deps, CT hardening, input guards and sampling-bounds changes kept from origin/dev. - Preserved PR #14 changes on top of dev: BaseParty fatal-error latch (abort/abortedWith), keygen unmarshalVSSCommitment part-count guard, and all earlier integration changes.
piotr-roslaniec
added a commit
that referenced
this pull request
Sep 29, 2026
Bring PR #9 current with dev after #17/#23/#12/#13/#15/#14/#26 landed. Conflicts resolved: - CHANGELOG.md: retain dev's PR #17/#23 composing-PR entry alongside PR #9; keep the rollout-only historical Bob compatibility (8ae2cf8) risk text. - crypto/mta/proofs.go: preserve #9 legacy vs security-v2 tau/gamma sampling branches; keep dev's #15 nil sampling guard on beta. P1 8ae2cf8 opt-in historical Bob compatibility (default tight maxT1, opt-in (q+1)*N bound) unchanged. - crypto/schnorr/schnorr_proof.go: combine #9 legacy/v2 challenge API split with dev's #23 constant-time MulCT branch for t = a + c*x. - ecdsa/keygen/round_3.go: keep #14 unmarshalVSSCommitment part-count guard and re-apply #9 mode-conditional round.proofContext(j) for FactorVerify. - ecdsa/signing/round_ct_wiring_test.go: select ProtocolModeSecurityV2 + nonce for the CT wiring test that constructs local signing parties. Auto-merged and preserved: dev toolchain (Go 1.25.7 / 1.26.8) and deps in go.mod/go.sum, #17 CT default-on behavior and fixed public-width ExpCTWithBitLen calls, #12 arity/input guards, #15 nil/bounds guards, #14 keygen changes, and dev workflows/tests. No transcript mode or CT path was dropped.
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Validate decoder lengths and nullable helper inputs before indexed reads, coordinate allocation, or dereferencing. Require a commitment payload and propagate nil signing point results through existing error paths. Valid encodings, optional proof serialization, nil-key parameter skips, and existing API signatures are preserved.
Source-level backports of the public upstream input-validation changes; the individual upstream commits are recorded in the commit message.
Validation: bounded input and roundtrip tests plus the complete
tss,crypto,crypto/commitments,crypto/mta, andecdsa/signingpackage suites passed withGOMAXPROCS=2andgo test -p 1. Formatting, diff checks, and independent patch review passed.