You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).
3
+
All notable changes to this project will be documented in this file.
4
4
5
-
## [Unreleased]
5
+
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
6
+
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
7
+
8
+
## [0.3.2] - 2023-05-13
9
+
We strongly recommend updating to 0.3.2 if you use or plan to use GCC >=13 to compile libsecp256k1. When in doubt, check the GCC version using `gcc -v`.
10
+
11
+
#### Security
12
+
- Module `ecdh`: Fix "constant-timeness" issue with GCC 13.1 (and potentially future versions of GCC) that could leave applications using libsecp256k1's ECDH module vulnerable to a timing side-channel attack. The fix avoids secret-dependent control flow during ECDH computations when libsecp256k1 is compiled with GCC 13.1.
13
+
14
+
#### Fixed
15
+
- Fixed an old bug that permitted compilers to potentially output bad assembly code on x86_64. In theory, it could lead to a crash or a read of unrelated memory, but this has never been observed on any compilers so far.
16
+
17
+
#### Changed
18
+
- Various improvements and changes to CMake builds. CMake builds remain experimental.
19
+
- Made API versioning consistent with GNU Autotools builds.
20
+
- Switched to `BUILD_SHARED_LIBS` variable for controlling whether to build a static or a shared library.
21
+
- Added `SECP256K1_INSTALL` variable for the controlling whether to install the build artefacts.
22
+
- Renamed asm build option `arm` to `arm32`. Use `--with-asm=arm32` instead of `--with-asm=arm` (GNU Autotools), and `-DSECP256K1_ASM=arm32` instead of `-DSECP256K1_ASM=arm` (CMake).
23
+
24
+
#### ABI Compatibility
25
+
The ABI is compatible with versions 0.3.0 and 0.3.1.
26
+
27
+
## [0.3.1] - 2023-04-10
28
+
We strongly recommend updating to 0.3.1 if you use or plan to use Clang >=14 to compile libsecp256k1, e.g., Xcode >=14 on macOS has Clang >=14. When in doubt, check the Clang version using `clang -v`.
29
+
30
+
#### Security
31
+
- Fix "constant-timeness" issue with Clang >=14 that could leave applications using libsecp256k1 vulnerable to a timing side-channel attack. The fix avoids secret-dependent control flow and secret-dependent memory accesses in conditional moves of memory objects when libsecp256k1 is compiled with Clang >=14.
32
+
33
+
#### Added
34
+
- Added tests against [Project Wycheproof's](https://github.com/google/wycheproof/) set of ECDSA test vectors (Bitcoin "low-S" variant), a fixed set of test cases designed to trigger various edge cases.
35
+
36
+
#### Changed
37
+
- Increased minimum required CMake version to 3.13. CMake builds remain experimental.
38
+
39
+
#### ABI Compatibility
40
+
The ABI is compatible with version 0.3.0.
41
+
42
+
## [0.3.0] - 2023-03-08
43
+
44
+
#### Added
45
+
- Added experimental support for CMake builds. Traditional GNU Autotools builds (`./configure` and `make`) remain fully supported.
46
+
- Usage examples: Added a recommended method for securely clearing sensitive data, e.g., secret keys, from memory.
47
+
- Tests: Added a new test binary `noverify_tests`. This binary runs the tests without some additional checks present in the ordinary `tests` binary and is thereby closer to production binaries. The `noverify_tests` binary is automatically run as part of the `make check` target.
48
+
49
+
#### Fixed
50
+
- Fixed declarations of API variables for MSVC (`__declspec(dllimport)`). This fixes MSVC builds of programs which link against a libsecp256k1 DLL dynamically and use API variables (and not only API functions). Unfortunately, the MSVC linker now will emit warning `LNK4217` when trying to link against libsecp256k1 statically. Pass `/ignore:4217` to the linker to suppress this warning.
51
+
52
+
#### Changed
53
+
- Forbade cloning or destroying `secp256k1_context_static`. Create a new context instead of cloning the static context. (If this change breaks your code, your code is probably wrong.)
54
+
- Forbade randomizing (copies of) `secp256k1_context_static`. Randomizing a copy of `secp256k1_context_static` did not have any effect and did not provide defense-in-depth protection against side-channel attacks. Create a new context if you want to benefit from randomization.
55
+
56
+
#### Removed
57
+
- Removed the configuration header `src/libsecp256k1-config.h`. We recommend passing flags to `./configure` or `cmake` to set configuration options (see `./configure --help` or `cmake -LH`). If you cannot or do not want to use one of the supported build systems, pass configuration flags such as `-DSECP256K1_ENABLE_MODULE_SCHNORRSIG` manually to the compiler (see the file `configure.ac` for supported flags).
58
+
59
+
#### ABI Compatibility
60
+
Due to changes in the API regarding `secp256k1_context_static` described above, the ABI is *not* compatible with previous versions.
6
61
7
62
## [0.2.0] - 2022-12-12
8
63
9
-
### Added
64
+
#### Added
65
+
- Added usage examples for common use cases in a new `examples/` directory.
10
66
- Added `secp256k1_selftest`, to be used in conjunction with `secp256k1_context_static`.
67
+
- Added support for 128-bit wide multiplication on MSVC for x86_64 and arm64, giving roughly a 20% speedup on those platforms.
11
68
12
-
### Changed
13
-
- Enabled modules schnorrsig, extrakeys and ECDH by default in `./configure`.
69
+
#### Changed
70
+
- Enabled modules `schnorrsig`, `extrakeys` and `ecdh` by default in `./configure`.
71
+
- The `secp256k1_nonce_function_rfc6979` nonce function, used by default by `secp256k1_ecdsa_sign`, now reduces the message hash modulo the group order to match the specification. This only affects improper use of ECDSA signing API.
14
72
15
-
### Deprecated
73
+
####Deprecated
16
74
- Deprecated context flags `SECP256K1_CONTEXT_VERIFY` and `SECP256K1_CONTEXT_SIGN`. Use `SECP256K1_CONTEXT_NONE` instead.
17
75
- Renamed `secp256k1_context_no_precomp` to `secp256k1_context_static`.
76
+
- Module `schnorrsig`: renamed `secp256k1_schnorrsig_sign` to `secp256k1_schnorrsig_sign32`.
18
77
19
-
### ABI Compatibility
20
-
78
+
#### ABI Compatibility
21
79
Since this is the first release, we do not compare application binary interfaces.
22
-
However, there are unreleased versions of libsecp256k1 that are *not* ABI compatible with this version.
80
+
However, there are earlier unreleased versions of libsecp256k1 that are *not* ABI compatible with this version.
23
81
24
82
## [0.1.0] - 2013-03-05 to 2021-12-25
25
83
26
84
This version was in fact never released.
27
85
The number was given by the build system since the introduction of autotools in Jan 2014 (ea0fe5a5bf0c04f9cc955b2966b614f5f378c6f6).
28
86
Therefore, this version number does not uniquely identify a set of source files.
0 commit comments