Skip to main content

Module ct

Module ct 

Source
Expand description

Constant-time primitives.

These routines avoid branches and table lookups on secret data (lengths are considered public). Input and output barriers using core::hint::black_box prevent known optimizer transformations back into branches. Compiled-code regression probes check fixed-size cases; this is not a guarantee for every compiler, optimization profile or caller.

Structs§

Choice
A branch-free boolean whose value is never observable through control flow.

Functions§

cmov
Copy src over dst only when c is true, in constant time.
cswap
Conditionally swap two equal-length buffers in constant time.
eq
Constant-time equality over two byte slices.
is_zero
Constant-time check that every byte of x is zero.
lt_be
Constant-time a < b over big-endian byte strings of equal length.
select_u8
Branch-free select: returns a when c is true, otherwise b.
select_u32
Branch-free select over u32.
select_u64
Branch-free select over u64.
verify
Constant-time byte-slice comparison returning a plain bool.