Skip to content

Take the multiply's constant-time answer for each session, from the caller #186

Description

@c4milo

WIDEMUL=native is fixed when an object is built. CH_NATIVE_WIDEMUL is the builder's statement that the part multiplies in constant time, in the mode it runs in (ct.h). colibri cannot make that statement for the CPUs its callers run on, so it builds the decomposition today.

Decided (Camilo, 2026-09-29, in colibri's session)

What colibri asks for

One object that holds both multiplies and takes the caller's answer for each session:

  • The answer says either that the multiply runs in constant time on this CPU, in the mode it runs in, or that nothing says so. An unset answer is refused, as an unset aes_instructions is.
  • With the first answer, Poly1305 and the other code built on ct.h's widening multiply take the native product. With the second, they take the decomposition, as today.

What the answer rests on

ct.h's note on CH_NATIVE_MUL128 states both halves:

  • arm64: Arm lists MADD and UMULH as independent of their data only while PSTATE.DIT is 1, on a core with FEAT_DIT. Code at EL0 can set the bit, and nothing in chapulin does. Who sets it, chapulin around its own calls or the caller on its thread, is chapulin's to rule.
  • x86-64: Intel's DOIT list holds on Ice Lake and later parts only while the operating system has set DOITM, which user code cannot read. There the caller's answer is its policy, not a probe's.

Open, to rule on when the work starts

  • The build value's name, and the field's name and values.
  • How the choice reaches the multiply without a branch for each product: a path chosen for each call or each session.
  • What the codegen and timing lints check in each path.

Check

The unit, ML-KEM and Wycheproof vectors under both answers, and each path's codegen lint.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions