Repository navigation
Propagate EC key-generation failures (N-156) - #170
Merged
Merged
Conversation
netxduo bb340972 -> 12d4f5f2: _nx_crypto_ecdh_setup() and _nx_crypto_ecdsa_sign() return a failed key-pair generation's status before extracting, reducing or writing anything from it, and ECDH setup clears the private key buffer on that path. tests/x509/test_ec_keygen_status compiles the two vendor files against stubs of the EC and huge-number layer: the key-pair generation returns an injected status, every later call is counted, and the caller's output buffers carry canaries. Success controls for both. bb340972: 31 checks, 18 failures. Here: 0. Host census 548 -> 549. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Narrow defensive contract repair: ECDH setup and ECDSA signing now return key-generation errors before using an unset point or writing outputs. ECDH also clears its half-made private-key buffer. Pins independently reviewed NetX master 12d4f5f2007b7cad1bdcbca7934e98e287e2150a. Adds a maintained benign counting/canary fixture with success controls and two injected failure statuses; no failed-point extraction is executed. Primary and independent exact-tip source review found no blocker. Inspected owner logs: strict 32-bit and LP64 ASan/UBSan 31 checks/0 failures, old source 18 contract failures, focused m68k Werror compiles pass, registered CMake host 549/549 pass. These are inspected owner results, not a primary rerun or replacement for required CI. Current Amiga random callback always returns success, so this is latent error-path hardening, not a reproduced beta7 runtime failure. ECJPAKE is disabled and out of scope. Merge remains gated on all normal required checks; cleanup follows actual merge.