From 4be3d2557dea13fd9abdc38ed42a85688c31e84d Mon Sep 17 00:00:00 2001 From: Pierre Le Fevre Date: Sat, 7 Mar 2026 16:40:19 +0100 Subject: [PATCH] Fix Poly1305 final reduction: include h4 in conditional select The constant-time conditional select between h and g in the Poly1305 final reduction was missing h4/g4. When h >= p (2^130-5), the code selected g for h0-h3 but left h4 unchanged, producing incorrect tags for inputs where the accumulator exceeds the prime. Co-Authored-By: Claude Opus 4.6 --- crates/crypto/src/chacha20_poly1305.rs | 2 ++ 1 file changed, 2 insertions(+) diff --git a/crates/crypto/src/chacha20_poly1305.rs b/crates/crypto/src/chacha20_poly1305.rs index 28ed6af..acef060 100644 --- a/crates/crypto/src/chacha20_poly1305.rs +++ b/crates/crypto/src/chacha20_poly1305.rs @@ -264,11 +264,13 @@ fn poly1305_mac(key: &[u8; 32], data: &[u8]) -> [u8; 16] { g1 &= mask; g2 &= mask; g3 &= mask; + let g4 = g4 & mask; let nmask = !mask; h0 = (h0 & nmask) | g0; h1 = (h1 & nmask) | g1; h2 = (h2 & nmask) | g2; h3 = (h3 & nmask) | g3; + h4 = (h4 & nmask) | g4; // Reassemble h as a 128-bit number (mod 2^128) and add s let h_val: u128 = (h0 as u128) -- 2.51.2