Skip to content

Commit 1ee1fad

Browse files
committed
docs(core): anchor open-side guard comments to exchange-result invariant
The seal-side comment still named is_low_order_montgomery and the low-order vector test doc claimed a decode-path filter that does not exist. Both now describe yields_all_zero_shared_secret.
1 parent bbab74f commit 1ee1fad

1 file changed

Lines changed: 10 additions & 9 deletions

File tree

‎crates/gitlawb-core/src/encrypt.rs‎

Lines changed: 10 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -19,8 +19,10 @@ fn x25519_public(vk: &VerifyingKey) -> Result<[u8; 32]> {
1919
// rebuilt by anyone. Resolution already refuses such a key (see
2020
// Did::to_verifying_key); this guard covers the SEAL side on its own terms
2121
// for a caller that obtained the key some other way. The open side
22-
// (open_blob's attacker-supplied `eph`) is covered by
23-
// is_low_order_montgomery.
22+
// (open_blob's attacker-supplied `eph`) skips any entry whose exchange with
23+
// this reader yields the all-zero shared secret
24+
// (`yields_all_zero_shared_secret`), regardless of whether the bytes decode
25+
// to an Edwards point.
2426
if vk.is_weak() {
2527
return Err(anyhow::anyhow!("verifying key is a small-order point"));
2628
}
@@ -336,13 +338,12 @@ mod tests {
336338
assert!(open_blob(&reframe(&header), &reader).is_err());
337339
}
338340

339-
/// A low-order ephemeral public forces the all-zero shared secret, so an
340-
/// entry built on it would unwrap for anyone. The header's `eph` is
341-
/// attacker-controlled, so the open side must skip it. u = 0 and u = 1 are
342-
/// the Montgomery u-coordinates that decompress to a small-order Edwards
343-
/// point (u = 0 is the one that produces the all-zero shared secret); the
344-
/// other small-order u values fail to decompress and are already skipped
345-
/// by the decode path.
341+
/// Every standard low-order X25519 encoding must be detected by
342+
/// `yields_all_zero_shared_secret`, including encodings that do not
343+
/// decompress to an Edwards point (notably `u = p - 1`). The open side
344+
/// rejects on the exchange result, not on decode shape, because an
345+
/// encoding-shaped check misses non-decompressing low-order inputs while
346+
/// still yielding the all-zero shared secret.
346347
#[test]
347348
fn all_zero_shared_secret_is_detected_for_every_standard_low_order_encoding() {
348349
// The seven standard X25519 low-order encodings, driven as a set rather

0 commit comments

Comments
 (0)