- pmul_ct: double-and-add-always over the Renes–Costello–Batina complete projective addition formula (Alg. 4, a=-3) — one exception-free formula for add and double, identity (0:1:0), so there is NO point-at-infinity branch. Closes the documented residual: the Jacobian jadd/jdouble ladder's fp_zero checks leaked k's leading-zero count (a bit-length hint) during ECDSA sign - wo_ecdsa_p256_sha256_sign uses it; affine x = X * Z^-1 (projective), the inversion via the constant-time modexp. Dead Jacobian jmul_ct/jpt_cmov removed - RFC 6979 A.2.5 vectors still byte-exact (test_crypto 130/0); server loopback (signs with this ladder) still green (test_tls 123/0); ASan/UBSan clean - docs: rv2 9 review_pending — close_notify + complete-formula ladder moved from deferred to landed; lang-41 decision 4 fixture marked landed Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> (cherry picked from commit fba30352b965e0f3b749168421a920a832df541b) |
||
|---|---|---|
| .. | ||
| databasev2 | ||
| jarvis | ||
| language-runtime-database | ||
| porch | ||
| runtime-v2 | ||
| wmux | ||
| 00-status.md | ||
| board-views.md | ||