Expand description
Constant-time primitives.
These routines avoid branches and table lookups on secret data (lengths are
considered public). Input and output barriers using core::hint::black_box
prevent known optimizer transformations back into branches. Compiled-code
regression probes check fixed-size cases; this is not a guarantee for every
compiler, optimization profile or caller.
Structs§
- Choice
- A branch-free boolean whose value is never observable through control flow.
Functions§
- cmov
- Copy
srcoverdstonly whencis true, in constant time. - cswap
- Conditionally swap two equal-length buffers in constant time.
- eq
- Constant-time equality over two byte slices.
- is_zero
- Constant-time check that every byte of
xis zero. - lt_be
- Constant-time
a < bover big-endian byte strings of equal length. - select_
u8 - Branch-free select: returns
awhencis true, otherwiseb. - select_
u32 - Branch-free select over
u32. - select_
u64 - Branch-free select over
u64. - verify
- Constant-time byte-slice comparison returning a plain
bool.