- pmul_ct: double-and-add-always over the Renes–Costello–Batina complete projective addition formula (Alg. 4, a=-3) — one exception-free formula for add and double, identity (0:1:0), so there is NO point-at-infinity branch. Closes the documented residual: the Jacobian jadd/jdouble ladder's fp_zero checks leaked k's leading-zero count (a bit-length hint) during ECDSA sign - wo_ecdsa_p256_sha256_sign uses it; affine x = X * Z^-1 (projective), the inversion via the constant-time modexp. Dead Jacobian jmul_ct/jpt_cmov removed - RFC 6979 A.2.5 vectors still byte-exact (test_crypto 130/0); server loopback (signs with this ladder) still green (test_tls 123/0); ASan/UBSan clean - docs: rv2 9 review_pending — close_notify + complete-formula ladder moved from deferred to landed; lang-41 decision 4 fixture marked landed Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> (cherry picked from commit fba30352b965e0f3b749168421a920a832df541b) |
||
|---|---|---|
| .. | ||
| 00-story.md | ||
| 01-streaming-subprocess.md | ||
| 02-pty.md | ||
| 03-signals-as-events.md | ||
| 04-termios.md | ||
| 05-fd-passing.md | ||
| 06-term-size-width.md | ||
| 07-observability.md | ||
| 08-symmetric-cipher.md | ||
| 09-in-process-tls.md | ||