Skip to content

Falcon ct hardening - #11639

Open
danielinux wants to merge 4 commits into
wolfSSL:masterfrom
danielinux:falcon-ct-hardening
Open

danielinux wants to merge 4 commits into
wolfSSL:masterfrom
danielinux:falcon-ct-hardening

Conversation

@danielinux

Copy link
Copy Markdown
Member

Falcon: three constant-time hardening improvements

ca554c4 keep fpr_mul selects branchless
f9dad23 branchless fpr shift helpers on 32-bit targets
e6abd33 keep fpr_add and fpr_floor selects branchless

Copilot AI balanced review requested due to automatic review settings October 2, 2026 19:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new 32-bit arithmetic paths lack runtime test coverage in the current CI matrix.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Hardens Falcon floating-point emulation against optimizer-introduced timing branches.

Changes:

  • Adds an optimizer-opaque value helper.
  • Implements branchless 32-bit shift paths.
  • Hardens selections in fpr_floor, fpr_add, and fpr_mul.
File Description
wolfcrypt/​src/​falcon.c Adds constant-time arithmetic hardening.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread wolfcrypt/src/falcon.c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants