Skip to content

Make helper cancellation and save-data ownership explicit - #13

Merged
piotr-roslaniec merged 5 commits into
devfrom
codex/helper-lifecycle
Sep 29, 2026
Merged

piotr-roslaniec merged 5 commits into
devfrom
codex/helper-lifecycle

Conversation

@mswilkison

Copy link
Copy Markdown

Allow safe-prime workers to observe cancellation during result delivery. Give ECDSA save-data subsets independent copies of Xi and ShareID, preserving nil, and report nil saved keys or missing roster content with named diagnostics. Other pre-parameter and per-party object sharing remains documented.

Adapted from public upstream commits 24bb7d379f262294cb1422532d26b77f20939ac8, 04bb840ad562822962fc87371b82e608784fbb71, and the roster guard in 16938849b0f49bf925ea3902f5fab21b9ea9904b. The nil saved-key diagnostic and focused tests are local additions.

Validation: full common, focused cancellation/ownership tests, and ecdsa/keygen excluding TestE2EConcurrentAndSaveFixtures passed. The full keygen attempt reached Go's default ten-minute timeout in that existing 20-party E2E test during proof verification. Tests used GOMAXPROCS=2 and -p 1; formatting, diff checks, and independent patch review passed.

Adapt the result handoff in common/safe_prime.go from public upstream
commit 24bb7d3.

Add bounded worker lifecycle tests for cancellation with no receiver and
a full result buffer, plus ordinary result delivery. Test cleanup drains
pending results and joins workers.
Adapt Xi and ShareID copying from public upstream commit
04bb840 and the roster-content guard
from 1693884, limited to
ecdsa/keygen/save_data.go.

Preserve nil local secrets and existing pre-parameter and per-party
pointer sharing. The nil saved-key diagnostic and focused ownership,
subset-selection, and input-guard unit tests are additions for this branch.
Absorb PR #17 (ct-defaults-and-bounds) and #23 (ct-hardening-schnorr-signing-coverage). Preserve this branch's safe-prime cancellation (b547dd9) and save-data ownership changes (0f88232); dev wins on Go toolchain and dependency versions.
Absorb PR #12 (codex/input-guards) on top of #17/#23. Preserve this
branch's safe-prime cancellation and save-data ownership changes; dev
wins on Go toolchain and dependency versions.
@piotr-roslaniec
piotr-roslaniec merged commit e572b13 into dev Sep 29, 2026
2 checks passed
@piotr-roslaniec

Copy link
Copy Markdown

Merged into dev after integrating dependencies, CT hardening, and #12. The integrations were conflict-free.

Verification:

  • CI Test and Go fmt green on the final head.
  • Local tidy, build, vet, format, and focused cancellation/ownership tests green; focused tests are race-clean at -count=3 (review also ran cancellation tests at -count=20).
  • Negative control confirmed the original safe-prime result-delivery deadlock: a worker blocked sending after cancellation and the caller's deferred WaitGroup wait could never finish. The new cancellation-aware send terminates.
  • Negative control confirmed save-data aliasing: mutating a subset's Xi/ShareID previously changed the master save data; the new independent copies prevent it.
  • Remaining shared pre-params/public fields are read-only in every current path.

Full report: agent-docs/pr-integration/13.md (local).

piotr-roslaniec added a commit that referenced this pull request Sep 29, 2026
Merge current origin/dev (includes #12/#13/#15) into PR #14.

Conflict choices:
- No textual conflicts; clean automatic merge.
- Go toolchain/deps, CT hardening, input guards and sampling-bounds
  changes kept from origin/dev.
- Preserved PR #14 changes on top of dev: BaseParty fatal-error latch
  (abort/abortedWith), keygen unmarshalVSSCommitment part-count guard,
  and all earlier integration changes.
piotr-roslaniec added a commit that referenced this pull request Sep 29, 2026
Bring PR #9 current with dev after #17/#23/#12/#13/#15/#14/#26 landed.

Conflicts resolved:
- CHANGELOG.md: retain dev's PR #17/#23 composing-PR entry alongside PR #9;
  keep the rollout-only historical Bob compatibility (8ae2cf8) risk text.
- crypto/mta/proofs.go: preserve #9 legacy vs security-v2 tau/gamma sampling
  branches; keep dev's #15 nil sampling guard on beta. P1 8ae2cf8 opt-in
  historical Bob compatibility (default tight maxT1, opt-in (q+1)*N bound)
  unchanged.
- crypto/schnorr/schnorr_proof.go: combine #9 legacy/v2 challenge API split
  with dev's #23 constant-time MulCT branch for t = a + c*x.
- ecdsa/keygen/round_3.go: keep #14 unmarshalVSSCommitment part-count guard
  and re-apply #9 mode-conditional round.proofContext(j) for FactorVerify.
- ecdsa/signing/round_ct_wiring_test.go: select ProtocolModeSecurityV2 +
  nonce for the CT wiring test that constructs local signing parties.

Auto-merged and preserved: dev toolchain (Go 1.25.7 / 1.26.8) and deps in
go.mod/go.sum, #17 CT default-on behavior and fixed public-width ExpCTWithBitLen
calls, #12 arity/input guards, #15 nil/bounds guards, #14 keygen changes, and
dev workflows/tests. No transcript mode or CT path was dropped.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants