From fadcb92f01503edb815d35f8636528c1d8b5416d Mon Sep 17 00:00:00 2001 From: Sachymetsu Date: Mon, 13 Apr 2026 11:32:09 +0200 Subject: [PATCH] Don't bother ct checking op flags for operate/operate_no_mutate --- src/strobe.rs | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/src/strobe.rs b/src/strobe.rs index 20aa4a7..5c3a81b 100644 --- a/src/strobe.rs +++ b/src/strobe.rs @@ -239,6 +239,12 @@ impl StrobeState { /// `Strobe::squeeze`. It's like `squeeze` in that we assume we've been given all zeros as /// input, and like `overwrite` in that we do not mutate (or take) any input. fn zero_state(&mut self, mut bytes_to_zero: usize) { + // Put in a limit to allow for constant time checking + debug_assert!( + bytes_to_zero <= (u32::MAX as usize), + "Don't bother zeroing more than u32::MAX bytes" + ); + // Do the zero-writing in chunks while bytes_to_zero.ct_ne(&0).into() { let min_slice = (self.rate - self.position) as u32; @@ -331,15 +337,13 @@ impl StrobeState { // RATCHET is special cased to never call operate/operate_no_mutate directly debug_assert!(flags == ops::KEY || !bool::from(flags.contains(OpFlags::CIPHER))); - // There are no non-mutating variants of things with flags & (C | T | I) == C | T - if flags.contains(OpFlags::CIPHER).into() { + match flags { // This is equivalent to a non-mutating form of the `duplex` operation in the Python // implementation, with `cbefore = True` - self.overwrite(data); - } else { + ops::KEY => self.overwrite(data), // This is equivalent to the `duplex` operation in the Python implementation, with // `cbefore = cafter = False` - self.absorb(data); + _ => self.absorb(data), } } -- 2.51.2