- bn_modexp_ct: constant-time modexp for the SECRET exponent — squares and
multiplies every bit, selects the product with a mask (bn_cmov), so the
op sequence is independent of d (the existing bn_modexp branches on the
bit, fine only for the public e)
- wo_rsa_pss_sha256_sign: EMSA-PSS-ENCODE (RFC 8017 §9.1.1) + modexp with d;
caller supplies the salt (fresh in production; fixed makes the KAT
deterministic). Private key (n,d)
- KAT: deterministic sign vs a python from-spec oracle byte-for-byte
(fixed salt), our sign round-trips through our verify, tamper rejected.
test_crypto 108, ASan/UBSan clean
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit cf8fdfcc47b2b076b63b9c63bf56411615b0d6f9)