Skip to content

Guard decoder lengths and nullable input fields - #12

Merged
piotr-roslaniec merged 3 commits into
devfrom
codex/input-guards
Sep 29, 2026
Merged

piotr-roslaniec merged 3 commits into
devfrom
codex/input-guards

Conversation

@mswilkison

Copy link
Copy Markdown

Validate decoder lengths and nullable helper inputs before indexed reads, coordinate allocation, or dereferencing. Require a commitment payload and propagate nil signing point results through existing error paths. Valid encodings, optional proof serialization, nil-key parameter skips, and existing API signatures are preserved.

Source-level backports of the public upstream input-validation changes; the individual upstream commits are recorded in the commit message.

Validation: bounded input and roundtrip tests plus the complete tss, crypto, crypto/commitments, crypto/mta, and ecdsa/signing package suites passed with GOMAXPROCS=2 and go test -p 1. Formatting, diff checks, and independent patch review passed.

Validate helper inputs before indexed reads and coordinate-buffer allocation,
require a commitment payload, and propagate nil signing point results through
the existing error paths. Preserve base proof arities, optional-mode proof
serialization, nil-key parameter skips, and valid routing and point encodings.

Adapted from upstream commits:
f1588ae (WC decoder arity)
8deab46 (sender metadata guards)
1a8e277 (embedded PartyID guards)
8069c6c (SortedPartyIDs.Keys guard)
6e0bcd4 (shared nullable-input guards)
58a131c (commitment minimum parts)
cbb8fe4 (commitment boundary coverage)
e65fb36 (Gob coordinate allocation bounds)
8acae9a (signing nil-result guards)
1693884 (PartyID.String content guard)
Merge origin/dev (contains #18/#20/#21) into the input-guards branch.
Auto-merged cleanly (no textual conflicts); key choices:
- go.mod/go.sum: adopt origin/dev toolchain and dependencies
  (go 1.25.7, toolchain go1.26.8, x/crypto v0.52.0, x/sys v0.45.0,
  protobuf v1.33.0, btcd v0.24.2, btcec/v2 v2.2.0, btcutil v1.1.5,
  bigmod v0.1.0) per the integration contract.
- crypto/mta/proofs.go: keep #12 decoder guards (ProofBobWC 12-part
  arity, Bytes nil-receiver panics) plus dev's CT/sampling changes;
  changes were in disjoint regions and both survived.
Second integration pass: origin/dev advanced to 0efe90c (merged
#17 ct-defaults-and-bounds and #23 ct-hardening-schnorr-signing-coverage
after the first merge at 39e7d87).

Auto-merged cleanly; key choices:
- crypto/mta/proofs.go: disjoint regions survived both sides —
  #12 decoder guards (ProofBobWC 12-part arity, Bytes nil-receiver
  panics) plus #17/#23 CT changes on the same file.
- ecdsa/signing/round_5.go: #12 R == nil guard retained below the
  #23 CT-context hunks; no conflict.
- go.mod/go.sum: origin/dev dependency set retained.
@piotr-roslaniec
piotr-roslaniec merged commit 0d33a84 into dev Sep 29, 2026
2 checks passed
@piotr-roslaniec

Copy link
Copy Markdown

Merged into dev after two integration merges: current dependency/toolchain changes, then #17/#23 CT changes. Shared hunks in crypto/mta/proofs.go and signing round 5 retain both sides.

Verification:

  • CI Test and Go fmt green.
  • Local tidy, build, vet, format, and targeted tss/crypto/commitments/MtA/signing tests green.
  • Six native fuzz targets, 5 minutes each: 10.5M+ executions total on the PR head, zero crashes. Negative control on dev found two concrete panics fixed here: a 4 GiB ECPoint allocation from an 8-byte length input, and a 10-part ProofBobWC index panic.
  • Honest deterministic serialization is byte-identical before/after.

Follow-up findings from variant analysis, not regressions introduced here: direct keygen proof-decoder arity/nil guards, RangeProofAlice.Bytes symmetry, and the upstream ModProof 65,536-bit allocation ceiling remain to be handled in a separate hardening/test PR. The ModProof gap is not wire-reachable in shipped keygen (wire moduli are pinned to 2048 bits) but is reachable through the exported API.

Full report: agent-docs/pr-integration/12.md (local).

piotr-roslaniec added a commit that referenced this pull request Sep 29, 2026
Absorb PR #12 (codex/input-guards) on top of #17/#23. Preserve this
branch's safe-prime cancellation and save-data ownership changes; dev
wins on Go toolchain and dependency versions.
piotr-roslaniec added a commit that referenced this pull request Sep 29, 2026
Absorb #12 input guards on top of #17/#23. Preserve this branch's
nil/sampling guards in crypto/paillier/paillier.go and crypto/mta;
dev wins on Go toolchain and dependency versions.
piotr-roslaniec added a commit that referenced this pull request Sep 29, 2026
Merge current origin/dev (includes #12/#13/#15) into PR #14.

Conflict choices:
- No textual conflicts; clean automatic merge.
- Go toolchain/deps, CT hardening, input guards and sampling-bounds
  changes kept from origin/dev.
- Preserved PR #14 changes on top of dev: BaseParty fatal-error latch
  (abort/abortedWith), keygen unmarshalVSSCommitment part-count guard,
  and all earlier integration changes.
piotr-roslaniec added a commit that referenced this pull request Sep 29, 2026
Bring PR #9 current with dev after #17/#23/#12/#13/#15/#14/#26 landed.

Conflicts resolved:
- CHANGELOG.md: retain dev's PR #17/#23 composing-PR entry alongside PR #9;
  keep the rollout-only historical Bob compatibility (8ae2cf8) risk text.
- crypto/mta/proofs.go: preserve #9 legacy vs security-v2 tau/gamma sampling
  branches; keep dev's #15 nil sampling guard on beta. P1 8ae2cf8 opt-in
  historical Bob compatibility (default tight maxT1, opt-in (q+1)*N bound)
  unchanged.
- crypto/schnorr/schnorr_proof.go: combine #9 legacy/v2 challenge API split
  with dev's #23 constant-time MulCT branch for t = a + c*x.
- ecdsa/keygen/round_3.go: keep #14 unmarshalVSSCommitment part-count guard
  and re-apply #9 mode-conditional round.proofContext(j) for FactorVerify.
- ecdsa/signing/round_ct_wiring_test.go: select ProtocolModeSecurityV2 +
  nonce for the CT wiring test that constructs local signing parties.

Auto-merged and preserved: dev toolchain (Go 1.25.7 / 1.26.8) and deps in
go.mod/go.sum, #17 CT default-on behavior and fixed public-width ExpCTWithBitLen
calls, #12 arity/input guards, #15 nil/bounds guards, #14 keygen changes, and
dev workflows/tests. No transcript mode or CT path was dropped.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants