You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
review: cover derive_key with the official vectors, fix a backwards timing doc
Addresses the CodeRabbit pass on #268. Taking the findings that hold and
saying which do not, rather than applying all nine.
FIXED — correctness:
- **`derive_key` had zero vector coverage.** The parser read `input_len`,
`hash`, and `keyed_hash` and skipped past the `derive_key` field already
present in the file. It is the one public mode built as TWO passes
(DERIVE_KEY_CONTEXT over the context string, whose output keys a
DERIVE_KEY_MATERIAL pass over the material), so a swapped or collapsed
transcription would have been invisible while hash/keyed_hash stayed green.
Now asserted for all 35 cases at both the 32-byte and extended XOF lengths.
It passed on the first run — the transcription was right; it just wasn't
proven. Control-tested: swapping the two flags fails ONLY the new assertion.
- **`Hash::eq`'s documentation described the opposite of the code.** The
doc-comment said `read_volatile` (the code uses `core::hint::black_box`) and
the not-transcribed list flatly asserted "`PartialEq` here is a normal
short-circuiting byte-array compare" — stale since the constant-time fold
landed. On a MAC-comparison path a backwards timing claim is worse than no
claim: an auditor would have believed this file leaks match-prefix length
when it does not. Also now states that `black_box` is a best-effort barrier,
not a guarantee; the data-independent loop is the actual property.
FIXED — hazards:
- `run.sh` copied the bench to a fixed `examples/blake3_ab.rs` and had the EXIT
trap `rm` it unconditionally: a pre-existing file there would be clobbered
and then deleted. Now refuses to overwrite, and only removes the directory it
created.
- `shiftor_rot_u64x8` is `pub` and took arbitrary `u32` into `a >> n` — a debug
panic and a release wrapping-shift for `n >= 64`. Normalized at the PUBLIC
wrapper and deliberately NOT in the measured inner body, which would have
changed the codegen the oracle exists to observe.
- Rotate test extended past 64 (65/127/128/191) against std's `u64::rotate_*`,
pinning the mod-64 contract rather than only the width case.
- Test-local context const renamed `VECTORS_CONTEXT`; as `DERIVE_KEY_CONTEXT`
it shadowed the module-scope u32 flag of that name.
- Redundant `.into()` in `derive_key` (`clippy::useless_conversion`).
- The `pub mod blake3` incident history was an OUTER doc comment, so rustdoc
would publish it as module documentation. Now a plain `//` comment.
Three more stale doc claims, all the same class already corrected elsewhere in
this PR — an assertion outliving the change that falsified it:
- EPIPHANIES said "an error there means no cycle and the work is unblocked"
one paragraph after explaining the error is ambiguous. Read literally it
marks blocked work unblocked on the strength of a typo. Now a four-step
procedure with the error explicitly inconclusive.
- crypto-lane-status prescribed an explicit shift-or for AVX2/NEON/wasm,
contradicting the measurement directly above it (LLVM folds the two forms
byte-identically) and misdescribing what shipped.
- blake3-in-tree-measured still credited the swap with removing the C build,
already removed by `features = ["pure"]` in #264.
NOT taken, with reasons:
- Doctest examples on every public API. Worth doing, but it is a separate
change across a surface this PR is not otherwise touching, and the vectors
already smoke-test the public path harder than an example would.
- Caching the compressed block in `OutputReader`. A real inefficiency for
small repeated `fill` calls, but unmeasured, and the module is explicitly
not on a hot path pending the swap ruling.
- Deduplicating the rotate body across backends. Every other lane type in this
crate is duplicated per backend by design; collapsing one method would make
it the exception, not the rule.
- Secret-scanner allowlist for the vectors file. Correct that the hex is
published test data, not credentials, but no scanner config lives in this
repo to add it to.
Full lib suite green: 2200 passed, 0 failed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VdfbkUCBbtZhy3yjSfCDHp
0 commit comments