Skip to content

Commit 0f6ff0b

Browse files
committed
update vendored libsecp to v0.3.2 tag
1 parent cfb0d35 commit 0f6ff0b

File tree

99 files changed

+12767
-2487
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

99 files changed

+12767
-2487
lines changed

secp256k1-sys/build.rs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@ fn main() {
2121
.include("depend/secp256k1/src")
2222
.flag_if_supported("-Wno-unused-function") // some ecmult stuff is defined but not used upstream
2323
.define("SECP256K1_API", Some(""))
24+
.define("SECP256K1_API_VAR", Some("extern"))
2425
.define("ENABLE_MODULE_ECDH", Some("1"))
2526
.define("ENABLE_MODULE_SCHNORRSIG", Some("1"))
2627
.define("ENABLE_MODULE_EXTRAKEYS", Some("1"));
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,2 @@
11
# This file was automatically created by vendor-libsecp.sh
2-
21ffe4b22a9683cf24ae0763359e401d1284cc7a
2+
acf5c55ae6a94e5ca847e07def40427547876101

secp256k1-sys/depend/secp256k1/.cirrus.yml

Lines changed: 52 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
env:
2+
### cirrus config
3+
CIRRUS_CLONE_DEPTH: 1
24
### compiler options
35
HOST:
6+
WRAPPER_CMD:
47
# Specific warnings can be disabled with -Wno-error=foo.
58
# -pedantic-errors is not equivalent to -Werror=pedantic and thus not implied by -Werror according to the GCC manual.
69
WERROR_CFLAGS: -Werror -pedantic-errors
@@ -22,7 +25,7 @@ env:
2225
SECP256K1_TEST_ITERS:
2326
BENCH: yes
2427
SECP256K1_BENCH_ITERS: 2
25-
CTIMETEST: yes
28+
CTIMETESTS: yes
2629
# Compile and run the tests
2730
EXAMPLES: yes
2831

@@ -35,10 +38,12 @@ cat_logs_snippet: &CAT_LOGS
3538
always:
3639
cat_tests_log_script:
3740
- cat tests.log || true
41+
cat_noverify_tests_log_script:
42+
- cat noverify_tests.log || true
3843
cat_exhaustive_tests_log_script:
3944
- cat exhaustive_tests.log || true
40-
cat_valgrind_ctime_test_log_script:
41-
- cat valgrind_ctime_test.log || true
45+
cat_ctime_tests_log_script:
46+
- cat ctime_tests.log || true
4247
cat_bench_log_script:
4348
- cat bench.log || true
4449
cat_config_log_script:
@@ -51,10 +56,8 @@ cat_logs_snippet: &CAT_LOGS
5156
merge_base_script_snippet: &MERGE_BASE
5257
merge_base_script:
5358
- if [ "$CIRRUS_PR" = "" ]; then exit 0; fi
54-
- git fetch $CIRRUS_REPO_CLONE_URL $CIRRUS_BASE_BRANCH
55-
- git config --global user.email "ci@ci.ci"
56-
- git config --global user.name "ci"
57-
- git merge FETCH_HEAD # Merge base to detect silent merge conflicts
59+
- git fetch --depth=1 $CIRRUS_REPO_CLONE_URL "pull/${CIRRUS_PR}/merge"
60+
- git checkout FETCH_HEAD # Use merged changes to detect silent merge conflicts
5861

5962
linux_container_snippet: &LINUX_CONTAINER
6063
container:
@@ -78,9 +81,10 @@ task:
7881
- env: {WIDEMUL: int128, ECDH: yes, SCHNORRSIG: yes}
7982
- env: {WIDEMUL: int128, ASM: x86_64}
8083
- env: { RECOVERY: yes, SCHNORRSIG: yes}
81-
- env: {BUILD: distcheck, WITH_VALGRIND: no, CTIMETEST: no, BENCH: no}
84+
- env: {CTIMETESTS: no, RECOVERY: yes, ECDH: yes, SCHNORRSIG: yes, CPPFLAGS: -DVERIFY}
85+
- env: {BUILD: distcheck, WITH_VALGRIND: no, CTIMETESTS: no, BENCH: no}
8286
- env: {CPPFLAGS: -DDETERMINISTIC}
83-
- env: {CFLAGS: -O0, CTIMETEST: no}
87+
- env: {CFLAGS: -O0, CTIMETESTS: no}
8488
- env: { ECMULTGENPRECISION: 2, ECMULTWINDOW: 2 }
8589
- env: { ECMULTGENPRECISION: 8, ECMULTWINDOW: 4 }
8690
matrix:
@@ -125,7 +129,7 @@ task:
125129
env:
126130
ASM: no
127131
WITH_VALGRIND: no
128-
CTIMETEST: no
132+
CTIMETESTS: no
129133
matrix:
130134
- env:
131135
CC: gcc
@@ -150,7 +154,7 @@ task:
150154
ECDH: yes
151155
RECOVERY: yes
152156
SCHNORRSIG: yes
153-
CTIMETEST: no
157+
CTIMETESTS: no
154158
<< : *MERGE_BASE
155159
test_script:
156160
# https://sourceware.org/bugzilla/show_bug.cgi?id=27008
@@ -169,10 +173,10 @@ task:
169173
ECDH: yes
170174
RECOVERY: yes
171175
SCHNORRSIG: yes
172-
CTIMETEST: no
176+
CTIMETESTS: no
173177
matrix:
174178
- env: {}
175-
- env: {EXPERIMENTAL: yes, ASM: arm}
179+
- env: {EXPERIMENTAL: yes, ASM: arm32}
176180
<< : *MERGE_BASE
177181
test_script:
178182
- ./ci/cirrus.sh
@@ -189,7 +193,7 @@ task:
189193
ECDH: yes
190194
RECOVERY: yes
191195
SCHNORRSIG: yes
192-
CTIMETEST: no
196+
CTIMETESTS: no
193197
<< : *MERGE_BASE
194198
test_script:
195199
- ./ci/cirrus.sh
@@ -206,7 +210,7 @@ task:
206210
ECDH: yes
207211
RECOVERY: yes
208212
SCHNORRSIG: yes
209-
CTIMETEST: no
213+
CTIMETESTS: no
210214
<< : *MERGE_BASE
211215
test_script:
212216
- ./ci/cirrus.sh
@@ -220,7 +224,7 @@ task:
220224
ECDH: yes
221225
RECOVERY: yes
222226
SCHNORRSIG: yes
223-
CTIMETEST: no
227+
CTIMETESTS: no
224228
matrix:
225229
- name: "x86_64 (mingw32-w64): Windows (Debian stable, Wine)"
226230
env:
@@ -243,7 +247,7 @@ task:
243247
RECOVERY: yes
244248
EXPERIMENTAL: yes
245249
SCHNORRSIG: yes
246-
CTIMETEST: no
250+
CTIMETESTS: no
247251
# Use a MinGW-w64 host to tell ./configure we're building for Windows.
248252
# This will detect some MinGW-w64 tools but then make will need only
249253
# the MSVC tools CC, AR and NM as specified below.
@@ -254,7 +258,7 @@ task:
254258
# Set non-essential options that affect the CLI messages here.
255259
# (They depend on the user's taste, so we don't want to set them automatically in configure.ac.)
256260
CFLAGS: -nologo -diagnostics:caret
257-
LDFLAGS: -XCClinker -nologo -XCClinker -diagnostics:caret
261+
LDFLAGS: -Xlinker -Xlinker -Xlinker -nologo
258262
matrix:
259263
- name: "x86_64 (MSVC): Windows (Debian stable, Wine)"
260264
- name: "x86_64 (MSVC): Windows (Debian stable, Wine, int128_struct)"
@@ -282,7 +286,7 @@ task:
282286
ECDH: yes
283287
RECOVERY: yes
284288
SCHNORRSIG: yes
285-
CTIMETEST: no
289+
CTIMETESTS: no
286290
matrix:
287291
- name: "Valgrind (memcheck)"
288292
container:
@@ -327,10 +331,11 @@ task:
327331
ECDH: yes
328332
RECOVERY: yes
329333
SCHNORRSIG: yes
330-
CTIMETEST: no
334+
CTIMETESTS: yes
331335
CC: clang
332336
SECP256K1_TEST_ITERS: 32
333337
ASM: no
338+
WITH_VALGRIND: no
334339
container:
335340
memory: 2G
336341
matrix:
@@ -375,3 +380,30 @@ task:
375380
test_script:
376381
- cd sage
377382
- sage prove_group_implementations.sage
383+
384+
task:
385+
name: "x86_64: Windows (VS 2022)"
386+
windows_container:
387+
image: cirrusci/windowsservercore:visualstudio2022
388+
cpu: 4
389+
memory: 3840MB
390+
env:
391+
PATH: '%CIRRUS_WORKING_DIR%\build\src\RelWithDebInfo;%PATH%'
392+
x64_NATIVE_TOOLS: '"C:\Program Files (x86)\Microsoft Visual Studio\2022\BuildTools\VC\Auxiliary\Build\vcvars64.bat"'
393+
# Ignore MSBuild warning MSB8029.
394+
# See: https://learn.microsoft.com/en-us/visualstudio/msbuild/errors/msb8029?view=vs-2022
395+
IgnoreWarnIntDirInTempDetected: 'true'
396+
merge_script:
397+
- PowerShell -NoLogo -Command if ($env:CIRRUS_PR -ne $null) { git fetch $env:CIRRUS_REPO_CLONE_URL pull/$env:CIRRUS_PR/merge; git reset --hard FETCH_HEAD; }
398+
configure_script:
399+
- '%x64_NATIVE_TOOLS%'
400+
- cmake -E env CFLAGS="/WX" cmake -G "Visual Studio 17 2022" -A x64 -S . -B build -DSECP256K1_ENABLE_MODULE_RECOVERY=ON -DSECP256K1_BUILD_EXAMPLES=ON
401+
build_script:
402+
- '%x64_NATIVE_TOOLS%'
403+
- cmake --build build --config RelWithDebInfo -- -property:UseMultiToolTask=true;CL_MPcount=5
404+
check_script:
405+
- '%x64_NATIVE_TOOLS%'
406+
- ctest -C RelWithDebInfo --test-dir build -j 5
407+
- build\src\RelWithDebInfo\bench_ecmult.exe
408+
- build\src\RelWithDebInfo\bench_internal.exe
409+
- build\src\RelWithDebInfo\bench.exe

secp256k1-sys/depend/secp256k1/.gitignore

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,12 @@
11
bench
22
bench_ecmult
33
bench_internal
4+
noverify_tests
45
tests
56
exhaustive_tests
67
precompute_ecmult_gen
78
precompute_ecmult
8-
valgrind_ctime_test
9+
ctime_tests
910
ecdh_example
1011
ecdsa_example
1112
schnorr_example
@@ -42,8 +43,6 @@ coverage.*.html
4243
*.gcno
4344
*.gcov
4445

45-
src/libsecp256k1-config.h
46-
src/libsecp256k1-config.h.in
4746
build-aux/ar-lib
4847
build-aux/config.guess
4948
build-aux/config.sub
@@ -58,5 +57,9 @@ build-aux/m4/ltversion.m4
5857
build-aux/missing
5958
build-aux/compile
6059
build-aux/test-driver
61-
src/stamp-h1
6260
libsecp256k1.pc
61+
62+
### CMake
63+
/CMakeUserPresets.json
64+
# Default CMake build directory.
65+
/build
Lines changed: 74 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,28 +1,93 @@
11
# Changelog
22

3-
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).
3+
All notable changes to this project will be documented in this file.
44

5-
## [Unreleased]
5+
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
6+
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
7+
8+
## [0.3.2] - 2023-05-13
9+
We strongly recommend updating to 0.3.2 if you use or plan to use GCC >=13 to compile libsecp256k1. When in doubt, check the GCC version using `gcc -v`.
10+
11+
#### Security
12+
- Module `ecdh`: Fix "constant-timeness" issue with GCC 13.1 (and potentially future versions of GCC) that could leave applications using libsecp256k1's ECDH module vulnerable to a timing side-channel attack. The fix avoids secret-dependent control flow during ECDH computations when libsecp256k1 is compiled with GCC 13.1.
13+
14+
#### Fixed
15+
- Fixed an old bug that permitted compilers to potentially output bad assembly code on x86_64. In theory, it could lead to a crash or a read of unrelated memory, but this has never been observed on any compilers so far.
16+
17+
#### Changed
18+
- Various improvements and changes to CMake builds. CMake builds remain experimental.
19+
- Made API versioning consistent with GNU Autotools builds.
20+
- Switched to `BUILD_SHARED_LIBS` variable for controlling whether to build a static or a shared library.
21+
- Added `SECP256K1_INSTALL` variable for the controlling whether to install the build artefacts.
22+
- Renamed asm build option `arm` to `arm32`. Use `--with-asm=arm32` instead of `--with-asm=arm` (GNU Autotools), and `-DSECP256K1_ASM=arm32` instead of `-DSECP256K1_ASM=arm` (CMake).
23+
24+
#### ABI Compatibility
25+
The ABI is compatible with versions 0.3.0 and 0.3.1.
26+
27+
## [0.3.1] - 2023-04-10
28+
We strongly recommend updating to 0.3.1 if you use or plan to use Clang >=14 to compile libsecp256k1, e.g., Xcode >=14 on macOS has Clang >=14. When in doubt, check the Clang version using `clang -v`.
29+
30+
#### Security
31+
- Fix "constant-timeness" issue with Clang >=14 that could leave applications using libsecp256k1 vulnerable to a timing side-channel attack. The fix avoids secret-dependent control flow and secret-dependent memory accesses in conditional moves of memory objects when libsecp256k1 is compiled with Clang >=14.
32+
33+
#### Added
34+
- Added tests against [Project Wycheproof's](https://github.com/google/wycheproof/) set of ECDSA test vectors (Bitcoin "low-S" variant), a fixed set of test cases designed to trigger various edge cases.
35+
36+
#### Changed
37+
- Increased minimum required CMake version to 3.13. CMake builds remain experimental.
38+
39+
#### ABI Compatibility
40+
The ABI is compatible with version 0.3.0.
41+
42+
## [0.3.0] - 2023-03-08
43+
44+
#### Added
45+
- Added experimental support for CMake builds. Traditional GNU Autotools builds (`./configure` and `make`) remain fully supported.
46+
- Usage examples: Added a recommended method for securely clearing sensitive data, e.g., secret keys, from memory.
47+
- Tests: Added a new test binary `noverify_tests`. This binary runs the tests without some additional checks present in the ordinary `tests` binary and is thereby closer to production binaries. The `noverify_tests` binary is automatically run as part of the `make check` target.
48+
49+
#### Fixed
50+
- Fixed declarations of API variables for MSVC (`__declspec(dllimport)`). This fixes MSVC builds of programs which link against a libsecp256k1 DLL dynamically and use API variables (and not only API functions). Unfortunately, the MSVC linker now will emit warning `LNK4217` when trying to link against libsecp256k1 statically. Pass `/ignore:4217` to the linker to suppress this warning.
51+
52+
#### Changed
53+
- Forbade cloning or destroying `secp256k1_context_static`. Create a new context instead of cloning the static context. (If this change breaks your code, your code is probably wrong.)
54+
- Forbade randomizing (copies of) `secp256k1_context_static`. Randomizing a copy of `secp256k1_context_static` did not have any effect and did not provide defense-in-depth protection against side-channel attacks. Create a new context if you want to benefit from randomization.
55+
56+
#### Removed
57+
- Removed the configuration header `src/libsecp256k1-config.h`. We recommend passing flags to `./configure` or `cmake` to set configuration options (see `./configure --help` or `cmake -LH`). If you cannot or do not want to use one of the supported build systems, pass configuration flags such as `-DSECP256K1_ENABLE_MODULE_SCHNORRSIG` manually to the compiler (see the file `configure.ac` for supported flags).
58+
59+
#### ABI Compatibility
60+
Due to changes in the API regarding `secp256k1_context_static` described above, the ABI is *not* compatible with previous versions.
661

762
## [0.2.0] - 2022-12-12
863

9-
### Added
64+
#### Added
65+
- Added usage examples for common use cases in a new `examples/` directory.
1066
- Added `secp256k1_selftest`, to be used in conjunction with `secp256k1_context_static`.
67+
- Added support for 128-bit wide multiplication on MSVC for x86_64 and arm64, giving roughly a 20% speedup on those platforms.
1168

12-
### Changed
13-
- Enabled modules schnorrsig, extrakeys and ECDH by default in `./configure`.
69+
#### Changed
70+
- Enabled modules `schnorrsig`, `extrakeys` and `ecdh` by default in `./configure`.
71+
- The `secp256k1_nonce_function_rfc6979` nonce function, used by default by `secp256k1_ecdsa_sign`, now reduces the message hash modulo the group order to match the specification. This only affects improper use of ECDSA signing API.
1472

15-
### Deprecated
73+
#### Deprecated
1674
- Deprecated context flags `SECP256K1_CONTEXT_VERIFY` and `SECP256K1_CONTEXT_SIGN`. Use `SECP256K1_CONTEXT_NONE` instead.
1775
- Renamed `secp256k1_context_no_precomp` to `secp256k1_context_static`.
76+
- Module `schnorrsig`: renamed `secp256k1_schnorrsig_sign` to `secp256k1_schnorrsig_sign32`.
1877

19-
### ABI Compatibility
20-
78+
#### ABI Compatibility
2179
Since this is the first release, we do not compare application binary interfaces.
22-
However, there are unreleased versions of libsecp256k1 that are *not* ABI compatible with this version.
80+
However, there are earlier unreleased versions of libsecp256k1 that are *not* ABI compatible with this version.
2381

2482
## [0.1.0] - 2013-03-05 to 2021-12-25
2583

2684
This version was in fact never released.
2785
The number was given by the build system since the introduction of autotools in Jan 2014 (ea0fe5a5bf0c04f9cc955b2966b614f5f378c6f6).
2886
Therefore, this version number does not uniquely identify a set of source files.
87+
88+
[unreleased]: https://github.com/bitcoin-core/secp256k1/compare/v0.3.2...HEAD
89+
[0.3.2]: https://github.com/bitcoin-core/secp256k1/compare/v0.3.1...v0.3.2
90+
[0.3.1]: https://github.com/bitcoin-core/secp256k1/compare/v0.3.0...v0.3.1
91+
[0.3.0]: https://github.com/bitcoin-core/secp256k1/compare/v0.2.0...v0.3.0
92+
[0.2.0]: https://github.com/bitcoin-core/secp256k1/compare/423b6d19d373f1224fd671a982584d7e7900bc93..v0.2.0
93+
[0.1.0]: https://github.com/bitcoin-core/secp256k1/commit/423b6d19d373f1224fd671a982584d7e7900bc93
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
{
2+
"cmakeMinimumRequired": {"major": 3, "minor": 21, "patch": 0},
3+
"version": 3,
4+
"configurePresets": [
5+
{
6+
"name": "dev-mode",
7+
"displayName": "Development mode (intended only for developers of the library)",
8+
"cacheVariables": {
9+
"SECP256K1_EXPERIMENTAL": "ON",
10+
"SECP256K1_ENABLE_MODULE_RECOVERY": "ON",
11+
"SECP256K1_BUILD_EXAMPLES": "ON"
12+
},
13+
"warnings": {
14+
"dev": true,
15+
"uninitialized": true
16+
}
17+
}
18+
]
19+
}

0 commit comments

Comments
 (0)