WIDEMUL=native is fixed when an object is built. CH_NATIVE_WIDEMUL is the builder's statement that the part multiplies in constant time, in the mode it runs in (ct.h). colibri cannot make that statement for the CPUs its callers run on, so it builds the decomposition today.
Decided (Camilo, 2026-09-29, in colibri's session)
What colibri asks for
One object that holds both multiplies and takes the caller's answer for each session:
- The answer says either that the multiply runs in constant time on this CPU, in the mode it runs in, or that nothing says so. An unset answer is refused, as an unset
aes_instructions is.
- With the first answer, Poly1305 and the other code built on
ct.h's widening multiply take the native product. With the second, they take the decomposition, as today.
What the answer rests on
ct.h's note on CH_NATIVE_MUL128 states both halves:
- arm64: Arm lists MADD and UMULH as independent of their data only while PSTATE.DIT is 1, on a core with FEAT_DIT. Code at EL0 can set the bit, and nothing in chapulin does. Who sets it, chapulin around its own calls or the caller on its thread, is chapulin's to rule.
- x86-64: Intel's DOIT list holds on Ice Lake and later parts only while the operating system has set DOITM, which user code cannot read. There the caller's answer is its policy, not a probe's.
Open, to rule on when the work starts
- The build value's name, and the field's name and values.
- How the choice reaches the multiply without a branch for each product: a path chosen for each call or each session.
- What the codegen and timing lints check in each path.
Check
The unit, ML-KEM and Wycheproof vectors under both answers, and each path's codegen lint.
WIDEMUL=nativeis fixed when an object is built.CH_NATIVE_WIDEMULis the builder's statement that the part multiplies in constant time, in the mode it runs in (ct.h). colibri cannot make that statement for the CPUs its callers run on, so it builds the decomposition today.Decided (Camilo, 2026-09-29, in colibri's session)
aes_instructionsto anAES=runtimeobject (entry 81, Run AES on the instructions or fall back in one object, from the caller's CPU probe #183).platformmodule, which a program calls once at start, beside the answer for the AES instructions: platform: probe the CPU once at program start, exempt from the syscall rule stdx#15.What colibri asks for
One object that holds both multiplies and takes the caller's answer for each session:
aes_instructionsis.ct.h's widening multiply take the native product. With the second, they take the decomposition, as today.What the answer rests on
ct.h's note onCH_NATIVE_MUL128states both halves:Open, to rule on when the work starts
Check
The unit, ML-KEM and Wycheproof vectors under both answers, and each path's codegen lint.