Skip to content

ed448-goldilocks: fix Decaf448 field bytes endianness - #1939

Open
0xShadowX wants to merge 1 commit into
RustCrypto:masterfrom
0xShadowX:decaf448-field-endianness
Open

0xShadowX wants to merge 1 commit into
RustCrypto:masterfrom
0xShadowX:decaf448-field-endianness

Conversation

@0xShadowX

Copy link
Copy Markdown

#1831 replaced the little endian FieldBytesEncoding impls with the new FIELD_ENDIANNESS const, but only Ed448 got ByteOrder::LittleEndian. Decaf448 now uses the default big endian order while DecafScalar::to_repr is little endian, so anything going through bytes_to_uint, e.g. SecretKey::<Decaf448>::from_bytes(&scalar.to_repr()), gets the byte reversed scalar.

Added the missing const and a test for the SecretKey round trip, which fails on master:

left:  Scalar(Uint(0x0807060504030201000000...))
right: Scalar(Uint(0x...0000000102030405060708))

Tested with:

cargo test -p ed448-goldilocks --all-features
cargo test -p x448 --all-features

The LE FieldBytesEncoding impls were replaced by the FIELD_ENDIANNESS const in RustCrypto#1831, but only Ed448 got it, so Decaf448 fell back to big endian.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant