Release zcash_script 0.6.0 and libzcash_script 0.2.0 (bip32 0.6, secp256k1 0.33) - #308
Merged
Merged
Conversation
…ommit 21ffe4b22a git-subtree-dir: libzcash_script/depend/zcash/src/secp256k1 git-subtree-split: 21ffe4b22a9683cf24ae0763359e401d1284cc7a
…1ffe4b2..6e2c8bc4
6e2c8bc4 Merge bitcoin-core/secp256k1#1906: release: prepare for 0.8.0
5840c19b release: prepare for 0.8.0
3873647b Merge bitcoin-core/secp256k1#1904: sha256: cross-check caller supplied compression function
c84ea465 sha256: cross-check caller supplied compression function
f8c75f89 Merge bitcoin-core/secp256k1#1903: changelog: add entry for #1821
2076b06a changelog: add entry for #1821
7fecac74 Merge bitcoin-core/secp256k1#1709: release-process: Add signing of tarball plus minor improvements
12d9cfd8 release-process: Add attaching output of check-abi.sh to PR
b0a0ae82 release-process: Add "cleaning up"
4a73b1ae release-process: Fix nits
fae22e77 release-process: Add signing of tarball
34f00ca9 release-process: Refactor
1c2933bb Merge bitcoin-core/secp256k1#1902: changelog: add entry for #1859
51fc633e changelog: add entry for #1859
d77f44e9 Merge bitcoin-core/secp256k1#1863: ellswift: don't declassify or leave sk in sha256 buffer
0ae17e30 ellswift: don't declassify or leave sk in sha256 buffer
0a9e7889 Merge bitcoin-core/secp256k1#1900: Use SHA256 override for pointers to known aux functions
300c9bb2 Merge bitcoin-core/secp256k1#1901: changelog: Add entry for #1869
44ba8cd7 changelog: Add entry for #1869
4147f8bd header: Add note on SHA256 override and aux functions
ed091bc4 ecdsa/ecdh: Use SHA256 override if known noncefp/hashfp is passed
209ed102 Merge bitcoin-core/secp256k1#1886: Remove deprecated `secp256k1_context_no_precomp` pointer
bf435856 Remove deprecated `secp256k1_context_no_precomp` pointer
528863e6 Merge bitcoin-core/secp256k1#1869: Remove SECP256K1_GNUC_PREREQ macro
3a73d473 Merge bitcoin-core/secp256k1#1776: Remove deprecated `secp256k1_schnorrsig_sign` alias
e14756bd Remove deprecated `secp256k1_schnorrsig_sign` alias
7151e3b8 Merge bitcoin-core/secp256k1#1899: changelog: add missing entries for #1777 and #1860
f52eb393 changelog: add missing entries for #1777 and #1860
0f6baf31 Merge bitcoin-core/secp256k1#1896: silentpayments: address #1765 follow-ups, add changelog entry
d9ac2ee5 Add changelog entry for silentpayments module
0fa38f3d silentpayments: API docs and internal comment followups
d2d04864 Merge bitcoin-core/secp256k1#1765: Add "silentpayments" module implementing BIP352 (take 4, limited to full-node scanning)
9e4ec507 Merge bitcoin-core/secp256k1#1890: nonce: terminate RFC6979 loop at UINT_MAX
afff8cba Merge bitcoin-core/secp256k1#1894: extrakeys: check invariant that x-only pubkeys have even Y
b1bc6f3e nonce: terminate RFC6979 loop at UINT_MAX
89a54b5a extrakeys: check invariant that x-only pubkeys have even Y
cea6d114 silentpayments: drop "shuffle outputs" recommendation from API docs
1ae90bde silentpayments: flush labels before direct match
84a02fa9 silentpayments: extract label batch checker
8c3e6e6d Merge bitcoin-core/secp256k1#1889: field: serialize elements by word
11dad6d0 Merge bitcoin-core/secp256k1#1887: Make theStack a maintainer and a security contact
4aa16704 silentpayments: skip slow benchmarks for low iters count (<= 2)
7e4b313c docs: update README
f27a2968 ci: enable silentpayments module
4f7a578d tests: add sha256 tag test
936907b0 tests: add constant time tests
b608a9d9 tests: add BIP-352 test vectors
ca0136dc silentpayments: optimize scanning by using batch inversion
7ae555c5 silentpayments: add benchmarks for scanning
f0fdd99d silentpayments: add examples/silentpayments.c
1c1b2753 silentpayments: respect per-group recipients protocol limit (K_max=2323)
d72a7432 silentpayments: receiving
c83b6783 silentpayments: recipient label support
b30ea3eb silentpayments: sending
a93e696a build: add skeleton for new silentpayments (BIP352) module
e217ead5 field: serialize elements by word
d5c64baf SECURITY.md: Align the table
9bd50f0c SECURITY.md: Add theStack's key
ebf59432 Merge bitcoin-core/secp256k1#1884: SECURITY.md: remove Jonas Nick from trusted keys
21645c03 SECURITY.md: remove Jonas Nick from trusted keys
b90075a0 Merge bitcoin-core/secp256k1#1882: scalar: correct `_scalar_get_bits_{limb32,var}` input condition docs
5a8a4114 Merge bitcoin-core/secp256k1#1877: field: correct `fe_equal` magnitude bound for `b`
6a599a44 scalar: correct `_scalar_get_bits_{limb32,var}` input condition docs
994b3501 field: correct fe_equal's b magnitude bound
2ce4f71d Merge bitcoin-core/secp256k1#1845: Improve checks for scalar _get_bits methods
68b45fd4 Merge bitcoin-core/secp256k1#1881: tests: Fix GCC 17 snapshot warning
9d75769d tests: Fix GCC 17 snapshot warning
9e3a165a Merge bitcoin-core/secp256k1#1879: ci: add 'brew trust' invocation to macOS CI
66260b78 ci: add 'brew trust' invocation to macOS CI
ae075d7c hash: Include secp256k1.h directly
dba4d937 include: Remove SECP256K1_GNUC_PREREQ macro
09870e9c Use __GNUC__ instead of SECP256K1_GNUC_PREREQ
bd0287d6 Merge bitcoin-core/secp256k1#1859: field: force-inline 5x52 mul and sqr
fdcf2d41 Merge bitcoin-core/secp256k1#1865: test: enable -Wunused-function in test suite (Fix #1831)
b2d2bd36 Merge bitcoin-core/secp256k1#1860: cmake: Emulate Libtool's behavior on NetBSD and OpenBSD
87bec430 Merge bitcoin-core/secp256k1#1867: test: musig: fix dead "aggnonce encodes two points at infinity" check
71fcd841 field: force-inline 5x52 mul and sqr
a77dacad test: enable -Wunused-function in test suite (Fix #1831)
aea86bc3 Merge bitcoin-core/secp256k1#1864: test: refactor: simplify tests by using `_ecmult_gen_ge` helper, add test
2ee79e77 test: add unit test for `_ecmult_gen_ge`
d7125e51 test: musig: fix dead "aggnonce encodes two points at infinity" check
1eab7572 cmake: Fix shared library versioning on OpenBSD
a401c514 cmake: Fix shared library versioning on NetBSD
8a0f4002 cmake, refactor: Improve documenting in `SetLibtoolAbiVersion` module
acf2084a cmake, refactor: Introduce `SetLibtoolAbiVersion` module
0f4a7e6b Merge bitcoin-core/secp256k1#1855: bench: add internal benchmark for `secp256k1_fe_normalize_var`
ca68daf8 test: refactor: simplify tests by using `_ecmult_gen_ge` helper
13db747f Merge bitcoin-core/secp256k1#1861: refactor: introduce `_ecmult_gen_ge` helper (preventing accidental gej leaks)
9e017e50 refactor: rename `_ecmult_gen` -> `_ecmult_gen_gej` for consistency
a3296d5e refactor: introduce `_ecmult_gen_ge` helper (preventing accidental gej leaks)
c6306238 Merge bitcoin-core/secp256k1#1852: Add exhaustive test for ECDH module
240578ee bench: add internal benchmark for `secp256k1_fe_normalize_var`
5698e66c Add exhaustive test for ECDH module
a39093de Merge bitcoin-core/secp256k1#1851: doc: correct API docs for ECDSA signing out-params (s/array/signature object/)
8363a2d8 Merge bitcoin-core/secp256k1#1854: tests: compare full MuSig aggregate nonce
af1fdd12 tests: compare full MuSig aggregate nonce
40a0d874 doc: correct API docs for ECDSA signing out-params (s/array/signature object/)
b11340b3 Merge bitcoin-core/secp256k1#1849: musig: always clear out secret key in `secp256k1_musig_nonce_gen_counter`
8479eafa musig: always clear out secret key in `secp256k1_musig_nonce_gen_counter`
c1a9e4fe Merge bitcoin-core/secp256k1#1848: ci: Bump GCC snapshot major version to 17
3cca6451 ci: Bump GCC snapshot major version to 17
ea174fe0 Merge bitcoin-core/secp256k1#1846: ci: Replace `ilammy/msvc-dev-cmd` with manual MSVC setup
285cb788 ci: Replace `ilammy/msvc-dev-cmd` with manual MSVC setup
0cad3df5 Improve checks for scalar _get_bits methods
7262adb4 Merge bitcoin-core/secp256k1#1841: gha: Bump deprecated GHA workflow dependencies
c5cd9d6d gha: Bump deprecated GHA workflow dependencies
95b702de Merge bitcoin-core/secp256k1#1839: ecdsa: VERIFY_CHECK result of _fe_set_b32_limit
634215f3 Merge bitcoin-core/secp256k1#1837: tests: Fix function pointer initialization C89 error in ellswift tests
43fca0ff ecdsa: VERIFY_CHECK result of _fe_set_b32_limit
b84635ed tests: Fix C89 function pointer initialization in ellswift tests
ffc25a27 Merge bitcoin-core/secp256k1#1834: ecmult: Document and test ng=NULL in ecmult
3a403639 eckey: Call ecmult with NULL instead of zero scalar
7e68c0c8 ecmult: Document and test ng=NULL in ecmult
1aafe151 Merge bitcoin-core/secp256k1#1777: Make SHA256 compression runtime pluggable
b9cb1cbf Merge bitcoin-core/secp256k1#1824: util: introduce and use `ARRAY_SIZE` macro
4d92a083 sha256: speed up writes using multi-block compression
0753f8b9 Add API to override SHA256 compression at runtime
fdb6a91a Introduce hash context to support pluggable SHA256 compression
c0a2aba0 Merge bitcoin-core/secp256k1#1811: bench: Update help functions in bench and bench_internal
10f546a2 Merge bitcoin-core/secp256k1#1832: testrand: Remove testrand_finish
8d0eda07 testrand: Remove testrand_finish
95e68158 Merge bitcoin-core/secp256k1#1825: hash: remove redundant `secp256k1_sha256_initialize` in tagged hash midstate functions
f48b1bfa hash: add midstate initializer and use it for tagged hashes
3019186a Merge bitcoin-core/secp256k1#1829: ci: Fix leftover use of old ECMULTGENPRECISION
79e9f252 ci: Fix leftover use of old ECMULTGENPRECISION
dfe042fe Merge bitcoin-core/secp256k1#1828: Revert "ci, docker: Fix LLVM repository signature failure"
76e92cfe Revert "ci, docker: Fix LLVM repository signature failure"
ac561601 Merge bitcoin-core/secp256k1#1760: cmake: Add dynamic test discovery to improve parallelism
c7a7f732 Merge bitcoin-core/secp256k1#1821: ellswift: fix overflow flag handling in secp256k1_ellswift_xdh
921b9711 util: introduce and use `ARRAY_SIZE` macro
b99a94c3 Add tests for bad scalar inputs in ellswift XDH
307b49f1 ellswift: fix overflow flag handling in secp256k1_ellswift_xdh
322d0a43 Merge bitcoin-core/secp256k1#1823: ci: Load Docker image by ID from builder step
ed02466d ci: Load Docker image by ID from builder step
c49c9be5 bench: Update help functions in bench and bench_internal
1d146ac3 Merge bitcoin-core/secp256k1#1819: tests: Improve secp256k1_scalar_check_overflow tests (Issue #1812)
f47bbc07 test: add unit tests for secp256k1_scalar_check_overflow
d071aa56 Merge bitcoin-core/secp256k1#1815: refactor: remove unnecessary `malloc` result casts
99ab4a10 Merge bitcoin-core/secp256k1#1817: ci: Disable Docker build summary generation
c5da3bde Merge bitcoin-core/secp256k1#1818: ci: Enforce base-10 evaluation
97de5120 Merge bitcoin-core/secp256k1#1804: test: show both CMake and Autotools usage for ctime_tests
4fb7ccf5 ci: Enforce base-10 evaluation
3ae72e78 ci: Disable Docker build summary generation
97b3c478 refactor: remove unnecessary `malloc` result casts
57315a69 Merge bitcoin-core/secp256k1#1813: Remove trailing spaces and introduce `-Wtrailing-whitespace=any` compiler flag
86cae58d build: Add `-Wleading-whitespace=spaces` compiler flag
fb229e76 build: Add `-Wtrailing-whitespace=any` compiler flag
13e3bee5 refactor: Remove trailing whitespace
453949ab Merge bitcoin-core/secp256k1#1816: ci: Rotate Docker cache keys
cd49c57e Merge bitcoin-core/secp256k1#1814: release process: mention the `[Unreleased]` link clearly
2ccff6eb ci: Add weekly schedule
2f18567d ci: Rotate Docker cache keys every 4 weeks
0ffb1749 ci, docker: Fix LLVM repository signature failure
0267b655 release process: mention the `[Unreleased]` link clearly
1605b02f Merge bitcoin-core/secp256k1#1775: Add CMake build directory patterns to `.gitignore`
14e56970 Merge bitcoin-core/secp256k1#1794: ecmult: Use size_t for array indices
c7a52400 Merge bitcoin-core/secp256k1#1809: release cleanup: bump version after 0.7.1
ae7eb729 release cleanup: bump version after 0.7.1
1a53f496 Merge bitcoin-core/secp256k1#1808: Prepare for 0.7.1
20a209f1 release: prepare for 0.7.1
c4b6a81a changelog: update in preparation for the v0.7.1 release
ebb35882 Merge bitcoin-core/secp256k1#1796: bench: fail early if user inputs invalid value for SECP256K1_BENCH_ITERS
c09215f7 bench: fail early if user inputs invalid value for SECP256K1_BENCH_ITERS
1bc74a22 test: show both Autotools and CMake usage for ctime_tests
471e3a13 Merge bitcoin-core/secp256k1#1800: sage: verify Eisenstein integer connection for GLV constants
8354618e cmake: Set `LABELS` property for tests
29f26ec3 cmake: Integrate DiscoverTests and normalize test names
29ac4d84 sage: verify Eisenstein integer connection for GLV constants
f95b263f cmake: Add DiscoverTests module
4ac65114 cmake, refactor: Deduplicate test-related code
4721e077 Merge bitcoin-core/secp256k1#1793: doc/bench: added help text for SECP256K1_BENCH_ITERS env var for bench_ecmult
bd5ced1f doc/bench: added help text for SECP256K1_BENCH_ITERS env var for bench_ecmult
47eb7095 ecmult: Use size_t for array indices in _odd_multiplies_table
bb1d199d ecmult: Use size_t for array indices into tables
2d9137ce Merge bitcoin-core/secp256k1#1764: group: Avoid using infinity field directly in other modules
f9a944ff Merge bitcoin-core/secp256k1#1790: doc: include arg -DSECP256K1_USE_EXTERNAL_DEFAULT_CALLBACKS=ON for cmake
0406cfc4 doc: include arg -DUSE_EXTERNAL_DEFAULT_CALLBACKS=1 for cmake
8d445730 Merge bitcoin-core/secp256k1#1783: Add VERIFY_CHECKs and documentation that flags must be 0 or 1
aa2a39c1 Merge bitcoin-core/secp256k1#1778: doc/bench: Added cmake build options to bench error messages
540fec8a Merge bitcoin-core/secp256k1#1788: test: split monolithic ellswift test into independent cases
d822b290 test: split monolithic ellswift test into independent cases
ae00c552 Add VERIFY_CHECKs that flags are 0 or 1
5c751833 Merge bitcoin-core/secp256k1#1784: refactor: remove ret from secp256k1_ec_pubkey_serialize
be5e4f02 Merge bitcoin-core/secp256k1#1779: Add ARG_CHECKs to ensure "array of pointers" elements are non-NULL
3daab83a refactor: remove ret from secp256k1_ec_pubkey_serialize
8bcda186 test: Add non-NULL checks for "pointer of array" API functions
5a08c1bc Add ARG_CHECKs to ensure "array of pointers" elements are non-NULL
3b5b03f3 doc/bench: Added cmake build options to bench error messages
e7f7083b Merge bitcoin-core/secp256k1#1774: refactor: split up internal pubkey serialization function into compressed/uncompressed variants
748c0fdd Add CMake build directory patterns to `.gitignore`
7eb86bdb autotools: Rename `build-aux` to `autotools-aux`
b6c2a3cd Merge bitcoin-core/secp256k1#1761: ecmult_multi: reduce strauss memory usage by 30%
f5e815f4 remove secp256k1_eckey_pubkey_serialize function
0d3659c5 use new `_eckey_pubkey_serialize{33,65}` functions in modules (ellswift,musig)
adb76f82 use new `_eckey_pubkey_serialize{33,65}` functions in public API
fc7458ca introduce `secp256k1_eckey_pubkey_serialize{33,65}` functions
c8206b1c Merge bitcoin-core/secp256k1#1771: ci: Use Python virtual environment in "x86_64-macos-native" job
f252da7e ci: Use Python virtual environment in "x86_64-macos-native" job
115b135f Merge bitcoin-core/secp256k1#1763: bench: Use `ALIGNMENT` macro instead of hardcoded value
2f73e528 group: Avoid using infinity field directly in other modules
153eea20 bench: Use `ALIGNMENT` macro instead of hardcoded value
26166c4f ecmult_multi: reduce strauss memory usage by 30%
7a2fff85 Merge bitcoin-core/secp256k1#1758: ci: Drop workaround for Valgrind older than 3.20.0
43e7b115 Merge bitcoin-core/secp256k1#1759: ci: Switch to macOS 15 Sequoia Intel-based image
8bc50b72 ci: Switch to macOS 15 Sequoia Intel-based image
c09519f0 ci: Drop workaround for Valgrind older than 3.20.0
d543c0d9 Merge bitcoin-core/secp256k1#1734: Introduce (mini) unit test framework
f44c1ebd Merge bitcoin-core/secp256k1#1719: ci: DRY workflow using anchors
a44a3393 Merge bitcoin-core/secp256k1#1750: ci: Use clang-snapshot in "MSan" job
15d01480 ci: Drop default for `inputs.command` in `run-in-docker-action`
1decc49a ci: Use YAML anchor and aliases for repeated "CI script" steps
dff1bc10 ci, refactor: Generalize use of `matrix.configuration.env_vars`
4b644da1 ci: Use YAML anchor and aliases for repeated "Print logs" steps
a889cd93 ci: Bump `actions/checkout` version
574c2f30 ci: Use YAML anchor and aliases for repeated "Checkout" steps
53585f93 ci: Use clang-snapshot in "MSan" job
6894c964 Fix Clang 21+ `-Wuninitialized-const-pointer` warning when using MSan
2b7337f6 Merge bitcoin-core/secp256k1#1756: ci: Fix image caching and apply other improvements
f163c358 ci: Set `DEBIAN_FRONTEND=noninteractive`
70ae177c ci: Bump `docker/build-push-action` version
b2a95a42 ci: Drop `tags` input for `docker/build-push-action`
122014ed ci: Add `scope` parameter to `cache-{to,from}` options
2f4546ce test: add --log option to display tests execution
95b9953e test: Add option to display all available tests
953f7b00 test: support running specific tests/modules targets
0302c1a3 test: add --help for command-line options
9ec3bfe2 test: adapt modules to the new test infrastructure
48789daf test: introduce (mini) unit test framework
baa26542 Merge bitcoin-core/secp256k1#1727: docs: Clarify that callback can be called more than once
4d90585f docs: Improve API docs of _context_set_illegal_callback
895f53d1 docs: Clarify that callback can be called more than once
de6af6ae Merge bitcoin-core/secp256k1#1748: bench: improve context creation in ECDH benchmark
58178851 Merge bitcoin-core/secp256k1#1749: build: Fix warnings in x86_64 assembly check
ab560078 build: Fix warnings in x86_64 assembly check
10dab907 Merge bitcoin-core/secp256k1#1741: doc: clarify API doc of `secp256k1_ecdsa_recover` return value
dfe284ed bench: improve context creation in ECDH benchmark
7321bdf2 doc: clarify API doc of `secp256k1_ecdsa_recover` return value
b4756543 Merge bitcoin-core/secp256k1#1745: test: introduce group order byte-array constant for deduplication
9cce7038 refactor: move 'gettime_i64()' to tests_common.h
0c91c560 test: introduce group order byte-array constant for deduplication
88be4e8d Merge bitcoin-core/secp256k1#1735: musig: Invalidate secnonce in secp256k1_musig_partial_sign
36e76952 Merge bitcoin-core/secp256k1#1738: check-abi: remove support for obsolete CMake library output location (src/libsecp256k1.so)
399b582a Split memclear into two versions
4985ac0f Merge bitcoin-core/secp256k1#1737: doc: mention ctx requirement for `_ellswift_create` (not secp256k1_context_static)
7ebaa134 check-abi: remove support for obsolete CMake library output location (src/libsecp256k1.so)
806de38b doc: mention ctx requirement for `_ellswift_create` (not secp256k1_context_static)
03fb60ad Merge bitcoin-core/secp256k1#1681: doc: Recommend clang-cl when building on Windows
d93380fb Merge bitcoin-core/secp256k1#1731: schnorrsig: Securely clear buf containing k or its negation
8113671f Merge bitcoin-core/secp256k1#1729: hash: Use size_t instead of int for RFC6979 outlen copy
325d65a8 Rename and clear var containing k or -k
960ba5f9 Use size_t instead of int for RFC6979 outlen copy
73791243 ci: Add more tests for clang-cl
7379a5be doc: Recommend clang-cl when building on Windows
f36afb8b Merge bitcoin-core/secp256k1#1725: tests: refactor tagged hash verification
5153cf1c tests: refactor tagged hash tests
d2dcf520 Merge bitcoin-core/secp256k1#1726: docs: fix broken link to Tromer's cache.pdf paper
489a43d1 docs: fix broken link to eprint cache.pdf paper
d5997141 Merge bitcoin-core/secp256k1#1722: docs: Exclude modules' `bench_impl.h` headers from coverage report
0458def5 doc: Add `--gcov-ignore-parse-errors=all` option to `gcovr` invocations
1aecce59 doc: Add `--merge-mode-functions=separate` option to `gcovr` invocations
106a7cbf doc: Exclude modules' `bench_impl.h` headers from coverage report
a9e955d3 autotools, docs: Adjust help string for `--enable-coverage` option
e523e4f9 Merge bitcoin-core/secp256k1#1720: chore(ci): Fix typo in Dockerfile comment
24ba8ff1 chore(ci): Fix typo in Dockerfile comment
74b8068c Merge bitcoin-core/secp256k1#1717: test: update wycheproof test vectors
c25c3c8a test: update wycheproof test vectors
20e3b447 Merge bitcoin-core/secp256k1#1688: cmake: Avoid contaminating parent project's cache with `BUILD_SHARED_LIBS`
2c076d90 Merge bitcoin-core/secp256k1#1711: tests: update Wycheproof
7b07b229 cmake: Avoid contaminating parent project's cache with BUILD_SHARED_LIBS
5433648c Fix typos and spellings
9ea54c69 tests: update Wycheproof files
b9313c6e Merge bitcoin-core/secp256k1#1708: release cleanup: bump version after 0.7.0
a660a497 Merge bitcoin-core/secp256k1#1707: release: Prepare for 0.7.0
7ab8b0cc release cleanup: bump version after 0.7.0
a3e742d9 release: Prepare for 0.7.0
f67b0ac1 ci: Don't hardcode ABI version
020ee604 Merge bitcoin-core/secp256k1#1706: musig/tests: initialize keypair
cde41308 musig/tests: initialize keypair
6037833c Merge bitcoin-core/secp256k1#1702: changelog: update
40b4a065 changelog: update
5e74086d Merge bitcoin-core/secp256k1#1705: musig/test: Remove dead code
7c338042 Merge bitcoin-core/secp256k1#1696: build: Refactor visibility logic and add override
8d967a60 musig/test: Remove dead code
983711cd musig/tests: Refactor vectors_signverify
73a69595 Merge bitcoin-core/secp256k1#1704: cmake: Make `secp256k1_objs` inherit interface defines from `secp256k1`
bf082221 cmake: Make `secp256k1_objs` inherit interface defines from `secp256k1`
c82d84bb build: add CMake option for disabling symbol visibility attributes
ce792387 build: Add SECP256K1_NO_API_VISIBILITY_ATTRIBUTES
e5297f6d build: Refactor visibility logic
cbbbf3bd Merge bitcoin-core/secp256k1#1699: ci: enable musig module for native macOS arm64 job
943479a7 Merge bitcoin-core/secp256k1#1694: Revert "cmake: configure libsecp256k1.pc during install"
3352f9d6 ci: enable musig module for native macOS arm64 job
ad60ef7e Merge bitcoin-core/secp256k1#1689: ci: Convert `arm64` Cirrus tasks to GHA jobs
c4987790 Merge bitcoin-core/secp256k1#1687: cmake: support the use of launchers in ctest -S scripts
44b205e9 Revert "cmake: configure libsecp256k1.pc during install"
0dfe387d cmake: support the use of launchers in ctest -S scripts
89096c23 Merge bitcoin-core/secp256k1#1692: cmake: configure libsecp256k1.pc during install
7106dce6 cmake: configure libsecp256k1.pc during install
29e73f4b Merge bitcoin-core/secp256k1#1685: cmake: Emulate Libtool's behavior on FreeBSD
746e36b1 Merge bitcoin-core/secp256k1#1678: cmake: add a helper for linking into static libs
a28c2ffa Merge bitcoin-core/secp256k1#1683: README: add link to musig example
2a9d3747 Merge bitcoin-core/secp256k1#1690: ci: Bump GCC snapshot major version to 16
add146e1 ci: Bump GCC snapshot major version to 16
004f57fc ci: Move Valgrind build for `arm64` from Cirrus to GHA
5fafdfc3 ci: Move `gcc-snapshot` build for `arm64` from Cirrus to GHA
e814b79a ci: Switch `arm64_debian` from QEMU to native `arm64` Docker image
bcf77346 ci: Add `arm64` architecture to `docker_cache` job
b77aae92 ci: Rename Docker image tag to reflect architecture
145ae3e2 cmake: add a helper for linking into static libs
81921097 README: add link to musig example, generalize module enabling hint
95db29b1 Merge bitcoin-core/secp256k1#1679: cmake: Use `PUBLIC_HEADER` target property in installation logic
37dd422b cmake: Emulate Libtool's behavior on FreeBSD
f24b838b Merge bitcoin-core/secp256k1#1680: doc: Promote "Building with CMake" to standard procedure
3f31ac43 doc: Promote "Building with CMake" to standard procedure
6f67151e cmake: Use `PUBLIC_HEADER` target property
c32715b2 cmake, move-only: Move module option processing to `src/CMakeLists.txt`
201b2b8f Merge bitcoin-core/secp256k1#1675: cmake: Bump minimum required CMake version to 3.22
3af71987 cmake: Bump minimum required CMake version to 3.22
92394476 Merge bitcoin-core/secp256k1#1673: Assert field magnitude at control-flow join
3a4f448c Assert field magnitude at control-flow join
9fab4252 Merge bitcoin-core/secp256k1#1668: bench_ecmult: add benchmark for ecmult_const_xonly
05445377 bench_ecmult: add benchmark for ecmult_const_xonly
bb597b3d Merge bitcoin-core/secp256k1#1670: tests: update wycheproof files
d73ed994 tests: update wycheproof files
4187a466 Merge bitcoin-core/secp256k1#1492: tests: Add Wycheproof ECDH vectors
e266ba11 tests: Add Wycheproof ECDH vectors
13906b71 Merge bitcoin-core/secp256k1#1669: gitignore: Add Python cache files
c1bcb032 gitignore: Add Python cache files
70f149b9 Merge bitcoin-core/secp256k1#1662: bench: add ellswift to bench help output
6b3fe51f bench: add ellswift to bench help output
d84bb83e Merge bitcoin-core/secp256k1#1661: configure: Show exhaustive tests in summary
3f54ed8c Merge bitcoin-core/secp256k1#1659: include: remove WARN_UNUSED_RESULT for functions always returning 1
20b05c9d configure: Show exhaustive tests in summary
e56716a3 Merge bitcoin-core/secp256k1#1660: ci: Fix exiting from ci.sh on error
d87c3bc5 ci: Fix exiting from ci.sh on error
1b6e0815 include: remove WARN_UNUSED_RESULT for functions always returning 1
2abb35b0 Merge bitcoin-core/secp256k1#1657: tests: remove unused uncounting_illegal_callback_fn
51907fa9 tests: remove unused uncounting_illegal_callback_fn
a7a51171 Merge bitcoin-core/secp256k1#1359: Fix symbol visibility issues, add test for it
13ed6f65 Merge bitcoin-core/secp256k1#1593: Remove deprecated `_ec_privkey_{negate,tweak_add,tweak_mul}` aliases from API
d1478763 build: Drop no longer needed `-fvisibility=hidden` compiler option
8ed1d83d ci: Run `tools/symbol-check.py`
41d32ab2 test: Add `tools/symbol-check.py`
88548058 Introduce `SECP256K1_LOCAL_VAR` macro
03bbe8c6 Merge bitcoin-core/secp256k1#1655: gha: Print all *.log files, in a separate action
59860bcc gha: Print all *.log files, in a separate action
4ba1ba2a Merge bitcoin-core/secp256k1#1647: cmake: Adjust diagnostic flags for `clang-cl`
abd25054 Merge bitcoin-core/secp256k1#1656: musig: Fix clearing of pubnonces
961ec25a musig: Fix clearing of pubnonces
31860823 Merge bitcoin-core/secp256k1#1614: Add _ge_set_all_gej and use it in musig for own public nonces
6c2a39da Merge bitcoin-core/secp256k1#1639: Make static context const
37d2c60b Remove deprecated _ec_privkey_{negate,tweak_add,tweak_mul} aliases
432ac577 Make static context const
1b1fc093 Merge bitcoin-core/secp256k1#1642: Verify `compressed` argument in `secp256k1_eckey_pubkey_serialize`
c0d9480f Merge bitcoin-core/secp256k1#1654: use `EXIT_` constants over magic numbers for indicating program execution status
13d38962 CONTRIBUTING: mention that `EXIT_` codes should be used
c8555817 test, bench, precompute_ecmult: use `EXIT_...` constants for `main` return values
965393fc examples: use `EXIT_...` constants for `main` return values
2e3bf136 Merge bitcoin-core/secp256k1#1646: README: add instructions for verifying GPG signatures
b682dbcf README: add instructions for verifying GPG signatures
00774d07 Merge bitcoin-core/secp256k1#1650: schnorrsig: clear out masked secret key in BIP-340 nonce function
a82287fb schnorrsig: clear out masked secret key in BIP-340 nonce function
4c50d73d ci: Add new "Windows (clang-cl)" job
84c0bd1f cmake: Adjust diagnostic flags for clang-cl
f79f46c7 Merge bitcoin-core/secp256k1#1641: doc: Improve cmake instructions in README
2ac9f558 doc: Improve cmake instructions in README
18235947 Verify `compressed` argument in `secp256k1_eckey_pubkey_serialize`
8deef00b Merge bitcoin-core/secp256k1#1634: Fix some misspellings
39705450 Fix some misspellings
ec329c25 Merge bitcoin-core/secp256k1#1633: release cleanup: bump version after 0.6.0
c97059f5 release cleanup: bump version after 0.6.0
0cdc758a Merge bitcoin-core/secp256k1#1631: release: prepare for 0.6.0
39d5dfd5 release: prepare for 0.6.0
df2eceb2 build: add ellswift.md and musig.md to release tarball
a306bb7e tools: fix check-abi.sh after cmake out locations were changed
145868a8 Do not export `secp256k1_musig_nonce_gen_internal`
b161bffb Merge bitcoin-core/secp256k1#1579: Clear sensitive memory without getting optimized out (revival of #636)
64228a64 musig: Use _ge_set_all_gej for own public nonces
300aab1c tests: Improve _ge_set_all_gej(_var) tests
365f274c group: Simplify secp256k1_ge_set_all_gej
d3082dde group: Add constant-time secp256k1_ge_set_all_gej
a38d879a Merge bitcoin-core/secp256k1#1628: Name public API structs
7d48f5ed Merge bitcoin-core/secp256k1#1581: test, ci: Lower default iteration count to 16
694342fd Name public API structs
0f73caf7 test, ci: Lower default iteration count to 16
9a8db52f Merge bitcoin-core/secp256k1#1582: cmake, test: Add `secp256k1_` prefix to test names
765ef533 Clear _gej instances after point multiplication to avoid potential leaks
349e6ab9 Introduce separate _clear functions for hash module
99cc9fd6 Don't rely on memset to set signed integers to 0
97c57f42 Implement various _clear() functions with secp256k1_memclear()
9bb368d1 Use secp256k1_memclear() to clear stack memory instead of memset()
e3497bbf Separate between clearing memory and setting to zero in tests
d79a6ccd Separate secp256k1_fe_set_int( . , 0 ) from secp256k1_fe_clear()
1c081262 Add secp256k1_memclear() for clearing secret data
1464f15c Merge bitcoin-core/secp256k1#1625: util: Remove unused (u)int64_t formatting macros
980c08df util: Remove unused (u)int64_t formatting macros
9b7c59cb Merge bitcoin-core/secp256k1#1624: ci: Update macOS image
096e3e23 ci: Update macOS image
e7d38448 Don't clear secrets in pippenger implementation
68b55209 Merge bitcoin-core/secp256k1#1619: musig: ctimetests: fix _declassify range for generated nonce points
f0868a9b Merge bitcoin-core/secp256k1#1595: build: 45839th attempt to fix symbol visibility on Windows
1fae76f5 Merge bitcoin-core/secp256k1#1620: Remove unused scratch space from API
8be3839f Remove unused scratch space from API
57eda3ba musig: ctimetests: fix _declassify range for generated nonce points
87384f5c cmake, test: Add `secp256k1_` prefix to test names
e59158b6 Merge bitcoin-core/secp256k1#1553: cmake: Set top-level target output locations
18f9b967 Merge bitcoin-core/secp256k1#1616: examples: do not retry generating seckey randomness in musig
5bab8f6d examples: make key generation doc consistent
e8908221 examples: do not retry generating seckey randomness in musig
70b6be18 extrakeys: improve doc of keypair_create (don't suggest retry)
01b58933 Merge bitcoin-core/secp256k1#1599: #1570 improve examples: remove key generation loop
cd4f84f3 Improve examples/documentation: remove key generation loops
a88aa935 Merge bitcoin-core/secp256k1#1603: f can never equal -m
3660fe5e Merge bitcoin-core/secp256k1#1479: Add module "musig" that implements MuSig2 multi-signatures (BIP 327)
168c9201 build: allow enabling the musig module in cmake
f411841a Add module "musig" that implements MuSig2 multi-signatures (BIP 327)
0be79660 util: add constant-time is_zero_array function
c8fbdb1b group: add ge_to_bytes_ext and ge_from_bytes_ext
ef7ff034 f can never equal -m
c232486d Revert "cmake: Set `ENVIRONMENT` property for examples on Windows"
26e4a7c2 cmake: Set top-level target output locations
4c57c7a5 Merge bitcoin-core/secp256k1#1554: cmake: Clean up testing code
447334cb include: Avoid visibility("default") on Windows
472faaa8 Merge bitcoin-core/secp256k1#1604: doc: fix typos in `secp256k1_ecdsa_{recoverable_,}signature` API description
292310fb doc: fix typos in `secp256k1_ecdsa_{recoverable_,}signature` API description
2f2ccc46 Merge bitcoin-core/secp256k1#1600: cmake: Introduce `SECP256K1_APPEND_LDFLAGS` variable
421ed1b4 cmake: Introduce `SECP256K1_APPEND_LDFLAGS` variable
85e224dd group: add ge_to_bytes and ge_from_bytes
19888550 Merge bitcoin-core/secp256k1#1586: fix: remove duplicate 'the' from header file comment
b3076144 Merge bitcoin-core/secp256k1#1583: ci: Bump GCC_SNAPSHOT_MAJOR to 15
fa67b675 refactor: Use array initialization for unterminated strings
9b0f37bf fix: remove duplicate 'the' from header file comment
e34b4767 ci: Bump GCC_SNAPSHOT_MAJOR to 15
3fdf146b Merge bitcoin-core/secp256k1#1578: ci: Silent Homebrew's noisy reinstall warnings
f8c1b0e0 Merge bitcoin-core/secp256k1#1577: release cleanup: bump version after 0.5.1
7057d3c9 ci: Silent Homebrew's noisy reinstall warnings
c3e40d75 release cleanup: bump version after 0.5.1
642c885b Merge bitcoin-core/secp256k1#1575: release: prepare for 0.5.1
cdf08c1a Merge bitcoin-core/secp256k1#1576: doc: mention `needs-changelog` github label in release process
40d87b8e release: prepare for 0.5.1
57702261 changelog: clarify CMake option
759bd4bb doc: mention `needs-changelog` github label in release process
fded437c Merge bitcoin-core/secp256k1#1574: Fix compilation when extrakeys module isn't enabled
763d938c ci: only enable extrakeys module when schnorrsig is enabled
af551ab9 tests: do not use functions from extrakeys module
0055b867 Merge bitcoin-core/secp256k1#1551: Add ellswift usage example
ea2d5f0f Merge bitcoin-core/secp256k1#1563: doc: Add convention for defaults
ca06e58b Merge bitcoin-core/secp256k1#1564: build, ci: Adjust the default size of the precomputed table for signing
e2af4912 ci: Switch to the new default value of the precomputed table for signing
d94a9273 build: Adjust the default size of the precomputed table for signing
fcc5d738 Merge bitcoin-core/secp256k1#1565: cmake: Bump CMake minimum required version up to 3.16
9420eece cmake: Bump CMake minimum required version up to 3.16
16685649 doc: Add convention for defaults
a5269373 Merge bitcoin-core/secp256k1#1555: Fixed O3 replacement
b8fe3333 cmake: Fixed O3 replacement
7c987ec8 cmake: Call `enable_testing()` unconditionally
6aa57651 cmake: Delete `CTest` module
31f84595 Add ellswift usage example
fe4fbaa7 examples: fix case typos in secret clearing paragraphs (s/, Or/, or/)
4af241b3 Merge bitcoin-core/secp256k1#1535: build: Replace hardcoded "auto" value with default one
f473c959 Merge bitcoin-core/secp256k1#1543: cmake: Do not modify build types when integrating by downstream project
d403eea4 Merge bitcoin-core/secp256k1#1546: cmake: Rename `SECP256K1_LATE_CFLAGS` and switch to Bitcoin Core's approach
d7ae25ce Merge bitcoin-core/secp256k1#1550: fix: typos in secp256k1.c
0e2fadb2 fix: typos in secp256k1.c
69b2192a Merge bitcoin-core/secp256k1#1545: cmake: Do not set `CTEST_TEST_TARGET_ALIAS`
5dd637f3 Merge bitcoin-core/secp256k1#1548: README: mention ellswift module
7454a537 README: mention ellswift module
4706be2c cmake: Reimplement `SECP256K1_APPEND_CFLAGS` using Bitcoin Core approach
c2764dbb cmake: Rename `SECP256K1_LATE_CFLAGS` to `SECP256K1_APPEND_CFLAGS`
f87a3589 cmake: Do not set `CTEST_TEST_TARGET_ALIAS`
158f9e5e cmake: Do not modify build types when integrating by downstream project
35c0fdc8 Merge bitcoin-core/secp256k1#1529: cmake: Fix cache issue when integrating by downstream project
4392f0f7 Merge bitcoin-core/secp256k1#1533: tests: refactor: tidy up util functions (#1491)
bedffd53 Merge bitcoin-core/secp256k1#1488: ci: Add native macOS arm64 job
4b8d5eea Merge bitcoin-core/secp256k1#1532: cmake: Disable eager MSan in ctime_tests
f55703ba autotools: Delete unneeded compiler test
396e8858 autotools: Align MSan checking code with CMake's implementation
abde59f5 cmake: Report more compiler details in summary
7abf979a cmake: Disable `ctime_tests` if build with `-fsanitize=memory`
4d9645be cmake: Remove "AUTO" value of `SECP256K1_ECMULT_GEN_KB` option
a06805ee cmake: Remove "AUTO" value of `SECP256K1_ECMULT_WINDOW_SIZE` option
1791f6fc Merge bitcoin-core/secp256k1#1517: autotools: Disable eager MSan in ctime_tests
26b94ee9 autotools: Remove "auto" value of `--with-ecmult-gen-kb` option
122dbaeb autotools: Remove "auto" value of `--with-ecmult-window` option
e73f6f8f tests: refactor: drop `secp256k1_` prefix from testrand.h functions
0ee7453a tests: refactor: add `testutil_` prefix to testutil.h functions
0c6bc76d tests: refactor: move `random_` helpers from tests.c to testutil.h
0fef8479 tests: refactor: rename `random_field_element_magnitude` -> `random_fe_magnitude`
59db007f tests: refactor: rename `random_group_element_...` -> `random_ge_...`
ebfb82ee ci: Add job with -fsanitize-memory-param-retval
e1bef096 configure: Move "experimental" warning to bottom
55e5d975 autotools: Disable eager MSan in ctime_tests
06bff6de Merge bitcoin-core/secp256k1#1528: tests: call `secp256k1_ecmult_multi_var` with a non-`NULL` error callback
ec4c002f cmake: Simplify `PROJECT_IS_TOP_LEVEL` emulation
cae9a7ad cmake: Do not set emulated PROJECT_IS_TOP_LEVEL as cache variable
4155e62f Merge bitcoin-core/secp256k1#1526: cmake: Fix `check_arm32_assembly` when using as subproject
9554362b tests: call secp256k1_ecmult_multi_var with a non-NULL error callback
9f4c8cd7 cmake: Fix `check_arm32_assembly` when using as subproject
7712a530 Merge bitcoin-core/secp256k1#1524: check-abi: explicitly provide public headers
7d0bc087 Merge bitcoin-core/secp256k1#1525: changelog: Correct 0.5.0 release date
d45d9b74 changelog: Correct 0.5.0 release date
d7f6613d Merge bitcoin-core/secp256k1#1523: release cleanup: bump version after 0.5.0
2f05e2da release cleanup: bump version after 0.5.0
e3a885d4 Merge bitcoin-core/secp256k1#1522: release: prepare for 0.5.0
dd695563 check-abi: explicitly provide public headers
c0e4ec3f release: prepare for 0.5.0
bb528cfb Merge bitcoin-core/secp256k1#1518: Add secp256k1_pubkey_sort
7d2591ce Add secp256k1_pubkey_sort
da515074 Merge bitcoin-core/secp256k1#1058: Signed-digit multi-comb ecmult_gen algorithm
4c341f89 Add changelog entry for SDMC
a0439402 Permit COMB_BITS < 256 for exhaustive tests
39b2f2a3 Add test case for ecmult_gen recoded = {-1,0,1}
644e86de Reintroduce projective blinding
07810d9a Reduce side channels from single-bit reads
a0d32b59 Optimization: use Nx32 representation for recoded bits
e03dcc44 Make secp256k1_scalar_get_bits support 32-bit reads
5005abee Rename scalar_get_bits -> scalar_get_bits_limb32; return uint32_t
6247f485 Optimization: avoid unnecessary doublings in precomputation
15d0cca2 Optimization: first table lookup needs no point addition
7a33db35 Optimization: move (2^COMB_BITS-1)/2 term into ctx->scalar_offset
ed2a056f Provide 3 configurations accessible through ./configure
5f7be9f6 Always generate tables for current (blocks,teeth) config
fde1dfcd Signed-digit multi-comb ecmult_gen algorithm
486518b3 Make exhaustive tests's scalar_inverse(&x,&x) work
ab45c3e0 Initial gej blinding -> final ge blinding
aa00a6b8 Introduce CEIL_DIV macro and use it
d8311688 Merge bitcoin-core/secp256k1#1515: ci: Note affected clangs in comment on ASLR quirk
a85e2233 ci: Note affected clangs in comment on ASLR quirk
4b77fec6 Merge bitcoin-core/secp256k1#1512: msan: notate more variable assignments from assembly code
f7f0184b msan: notate more variable assignments from assembly code
a6133914 change inconsistent array param to pointer
05bfab69 Merge bitcoin-core/secp256k1#1507: ci: Add workaround for ASLR bug in sanitizers
a5e8ab24 ci: Add sanitizer env variables to debug output
84a93de4 ci: Add workaround for ASLR bug in sanitizers
427e86b9 Merge bitcoin-core/secp256k1#1490: tests: improve fe_sqr test (issue #1472)
2028069d doc: clarify input requirements for secp256k1_fe_mul
11420a7a tests: improve fe_sqr test
cdc9a625 Merge bitcoin-core/secp256k1#1489: tests: add missing fe comparison checks for inverse field test cases
d926510c Merge bitcoin-core/secp256k1#1496: msan: notate variable assignments from assembly code
31ba4049 msan: notate variable assignments from assembly code
e7ea32e3 msan: Add SECP256K1_CHECKMEM_MSAN_DEFINE which applies to memory sanitizer and not valgrind
e7bdddd9 refactor: rename `check_fe_equal` -> `fe_equal`
00111c9c tests: add missing fe comparison checks for inverse field test cases
218f0cc9 ci: Add native macOS arm64 job
0653a25d Merge bitcoin-core/secp256k1#1486: ci: Update cache action
94a14d52 ci: Update cache action
24836272 Merge bitcoin-core/secp256k1#1483: cmake: Recommend native CMake commands in README
5ad3aa3d Merge bitcoin-core/secp256k1#1484: tests: Drop redundant _scalar_check_overflow calls
51df2d9a tests: Drop redundant _scalar_check_overflow calls
3777e3f3 cmake: Recommend native CMake commands in README
e4af41c6 Merge bitcoin-core/secp256k1#1249: cmake: Add `SECP256K1_LATE_CFLAGS` configure option
3bf4d68f Merge bitcoin-core/secp256k1#1482: build: Clean up handling of module dependencies
e6822678 build: Error if required module explicitly off
89ec583c build: Clean up handling of module dependencies
44378867 Merge bitcoin-core/secp256k1#1468: v0.4.1 release aftermath
a9db9f2d Merge bitcoin-core/secp256k1#1480: Get rid of untested sizeof(secp256k1_ge_storage) == 64 code path
74b7c3b5 Merge bitcoin-core/secp256k1#1476: include: make docs more consistent
b37fdb28 check-abi: Minor UI improvements
ad5f589a check-abi: Default to HEAD for new version
9fb7e2f1 release process: Style and formatting nits
ba5d72d6 assumptions: Use new STATIC_ASSERT macro
e53c2d9f Require that sizeof(secp256k1_ge_storage) == 64
d0ba2abb util: Add STATIC_ASSERT macro
da7bc1b8 include: in doc, remove article in front of "pointer"
aa3dd528 include: make doc about ctx more consistent
e3f69001 include: remove obvious "cannot be NULL" doc
d373bf6d Merge bitcoin-core/secp256k1#1474: tests: restore scalar_mul test
79e09451 Merge bitcoin-core/secp256k1#1473: Fix typos
3dbfb489 tests: restore scalar_mul test
d77170a8 Fix typos
e7053d06 release process: Add email step
429d21dc release process: Run sanity checks on release PR
efe85c70 Merge bitcoin-core/secp256k1#1466: release cleanup: bump version after 0.4.1
4b2e06f4 release cleanup: bump version after 0.4.1
1ad5185c Merge bitcoin-core/secp256k1#1465: release: prepare for 0.4.1
672053d8 release: prepare for 0.4.1
1a81df82 Merge bitcoin-core/secp256k1#1380: Add ABI checking tool for release process
74a4d974 doc: Add ABI checking with `check-abi.sh` to the Release Process
e7f830e3 Add `tools/check-abi.sh`
77af1da9 Merge bitcoin-core/secp256k1#1455: doc: improve secp256k1_fe_set_b32_mod doc
3928b7c3 doc: improve secp256k1_fe_set_b32_mod doc
5e9a4d7a Merge bitcoin-core/secp256k1#990: Add comment on length checks when parsing ECDSA sigs
4197d667 Merge bitcoin-core/secp256k1#1431: Add CONTRIBUTING.md
0e5ea622 CONTRIBUTING: add some coding and style conventions
e2c9888e Merge bitcoin-core/secp256k1#1451: changelog: add entry for "field: Remove x86_64 asm"
d2e36a2b changelog: add entry for "field: Remove x86_64 asm"
1a432cb9 README: update first sentence
0922a047 docs: move coverage report instructions to CONTRIBUTING
76880e40 Add CONTRIBUTING.md including scope and guidelines for new code
d3e29db8 Merge bitcoin-core/secp256k1#1450: Add group.h ge/gej equality functions
04af0ba1 Replace ge_equals_ge[,j] calls with group.h equality calls
60525f6c Add unit tests for group.h equality functions
a47cd97d Add group.h ge/gej equality functions
10e6d29b Merge bitcoin-core/secp256k1#1446: field: Remove x86_64 asm
07687e81 Merge bitcoin-core/secp256k1#1393: Implement new policy for VERIFY_CHECK and #ifdef VERIFY (issue #1381)
bb467234 remove VERIFY_SETUP define
a3a3e11a remove unneeded VERIFY_SETUP uses in ECMULT_CONST_TABLE_GET_GE macro
a0fb68a2 introduce and use SECP256K1_SCALAR_VERIFY macro
cf25c86d introduce and use SECP256K1_{FE,GE,GEJ}_VERIFY macros
5d89bc03 remove superfluous `#ifdef VERIFY`/`#endif` preprocessor conditions
c2688f8d redefine VERIFY_CHECK to empty in production (non-VERIFY) mode
5814d848 Merge bitcoin-core/secp256k1#1438: correct assertion for secp256k1_fe_mul_inner
c1b49664 Merge bitcoin-core/secp256k1#1445: bench: add --help option to bench_internal
f07cead0 build: Don't call assembly an optimization
2f0762fa field: Remove x86_64 asm
1ddd76af bench: add --help option to bench_internal
e7210393 Merge bitcoin-core/secp256k1#1441: asm: add .note.GNU-stack section for non-exec stack
ea47c82e Merge bitcoin-core/secp256k1#1442: Return temporaries to being unsigned in secp256k1_fe_sqr_inner
dcdda31f Tighten secp256k1_fe_mul_inner's VERIFY_BITS checks
10271356 Return temporaries to being unsigned in secp256k1_fe_sqr_inner
33dc7e4d asm: add .note.GNU-stack section for non-exec stack
c891c5c2 Merge bitcoin-core/secp256k1#1437: ci: Ignore internal errors of snapshot compilers
8185e72d ci: Ignore internal errors in snapshot compilers
40f50d0f Merge bitcoin-core/secp256k1#1184: Signed-digit based ecmult_const algorithm
8e2a5fe9 correct assertion for secp256k1_fe_mul_inner
355bbdf3 Add changelog entry for signed-digit ecmult_const algorithm
21f49d9b Remove unused secp256k1_scalar_shr_int
115fdc72 Remove unused secp256k1_wnaf_const
aa9f3a3c ecmult_const: add/improve tests
4d16e901 Signed-digit based ecmult_const algorithm
ba523be0 make SECP256K1_SCALAR_CONST reduce modulo exhaustive group order
2140da9c Add secp256k1_scalar_half for halving scalars (+ tests/benchmarks).
1f1bb78b Merge bitcoin-core/secp256k1#1430: README: remove CI badge
5dab0baa README: remove CI badge
b314cf28 Merge bitcoin-core/secp256k1#1426: ci/cirrus: Add native ARM64 jobs
fa4d6c76 ci/cirrus: Add native ARM64 persistent workers
ee7aaf21 Merge bitcoin-core/secp256k1#1395: tests: simplify `random_fe_non_zero` (remove loop limit and unneeded normalize)
ba9cb6f3 Merge bitcoin-core/secp256k1#1424: ci: Bump major versions for docker actions
d9d80fd1 ci: Bump major versions for docker actions
4fd00f4b Merge bitcoin-core/secp256k1#1422: cmake: Install `libsecp256k1.pc` file
421d8485 ci: Align Autotools/CMake `CI_INSTALL` directory names
9f005c60 cmake: Install `libsecp256k1.pc` file
2262d0ea ci/cirrus: Bring back skeleton .cirrus.yml without jobs
b10ddd2b Merge bitcoin-core/secp256k1#1416: doc: Align documented scripts with CI ones
49be5be9 Merge bitcoin-core/secp256k1#1390: tests: Replace counting_illegal_callbacks with CHECK_ILLEGAL_VOID
cbf3053f Merge bitcoin-core/secp256k1#1417: release cleanup: bump version after 0.4.0
9b118bc7 release cleanup: bump version after 0.4.0
199d27ce Merge bitcoin-core/secp256k1#1415: release: Prepare for 0.4.0
70303643 tests: add CHECK_ERROR_VOID and use it in scratch tests
f8d7ea68 tests: Replace counting_illegal_callbacks with CHECK_ILLEGAL_VOID
16339804 release: Prepare for 0.4.0
d9a85065 changelog: Catch up in preparation of release
b0f7bfed doc: Do not mention soname in CHANGELOG.md "ABI Compatibility" section
bd9d98d3 doc: Align documented scripts with CI ones
0b4640ae Merge bitcoin-core/secp256k1#1413: ci: Add `release` job
8659a017 ci: Add `release` job
f9b38894 ci: Update `actions/checkout` version
a1d52e3e tests: remove unnecessary test in run_ec_pubkey_parse_test
875b0ada tests: remove unnecessary set_illegal_callback
727bec5b Merge bitcoin-core/secp256k1#1414: ci/gha: Add ARM64 QEMU jobs for clang and clang-snapshot
2635068a ci/gha: Let MSan continue checking after errors in all jobs
e78c7b68 ci/Dockerfile: Reduce size of Docker image further
2f0d3bbf ci/Dockerfile: Warn if `ulimit -n` is too high when running Docker
4b8a647a ci/gha: Add ARM64 QEMU jobs for clang and clang-snapshot
6ebe7d2b ci/Dockerfile: Always use versioned clang packages
65c79fe2 Merge bitcoin-core/secp256k1#1412: ci: Switch macOS from Ventura to Monterey and add Valgrind
c223d7e3 ci: Switch macOS from Ventura to Monterey and add Valgrind
ea26b71c Merge bitcoin-core/secp256k1#1411: ci: Make repetitive command the default one
cce04563 ci: Make repetitive command the default one
317a4c48 ci: Move `git config ...` to `run-in-docker-action`
4d7fe609 Merge bitcoin-core/secp256k1#1409: ci: Move remained task from Cirrus to GitHub Actions
676ed8f9 ci: Move "C++ (public headers)" from Cirrus to GitHub Actions
61fc3a2d ci: Move "C++ -fpermissive..." from Cirrus to GitHub Actions
d51fb0a5 ci: Move "MSan" from Cirrus to GitHub Actions
c22ac275 ci: Move sanitizers task from Cirrus to GitHub Actions
26a98992 Merge bitcoin-core/secp256k1#1410: ci: Use concurrency for pull requests only
ee1be62d ci: Use concurrency for pull requests only
6ee14550 Merge bitcoin-core/secp256k1#1406: ci, gha: Move more non-x86_64 tasks from Cirrus CI to GitHub Actions
fc3dea29 ci: Move "ppc64le: Linux..." from Cirrus to GitHub Actions
7782dc82 ci: Move "ARM64: Linux..." from Cirrus to GitHub Actions
0a16de67 ci: Move "ARM32: Linux..." from Cirrus to GitHub Actions
ea33914e ci: Move "s390x (big-endian): Linux..." from Cirrus to GitHub Actions
880be8af ci: Move "i686: Linux (Debian stable)" from Cirrus to GiHub Actions
2e6cf9ba Merge bitcoin-core/secp256k1#1396: ci, gha: Add "x86_64: Linux (Debian stable)" GitHub Actions job
5373693e Merge bitcoin-core/secp256k1#1405: ci: Drop no longer needed workaround
ef9fe959 ci: Drop no longer needed workaround
e10878f5 ci, gha: Drop `driver-opts.network` input for `setup-buildx-action`
4ad4914b ci, gha: Add `retry_builder` Docker image builder
6617a620 ci: Remove "x86_64: Linux (Debian stable)" task from Cirrus CI
03c9e650 ci, gha: Add "x86_64: Linux (Debian stable)" GitHub Actions job
ad3e65d9 ci: Remove GCC build files and sage to reduce size of Docker image
6b9507ad Merge bitcoin-core/secp256k1#1398: ci, gha: Add Windows jobs based on Linux image
87d35f30 ci: Rename `cirrus.sh` to more general `ci.sh`
d6281dd0 ci: Remove Windows tasks from Cirrus CI
2b6f9cd5 ci, gha: Add Windows jobs based on Linux image
48b1d939 Merge bitcoin-core/secp256k1#1403: ci, gha: Ensure only a single workflow processes `github.ref` at a time
0ba2b945 Merge bitcoin-core/secp256k1#1373: Add invariant checking for scalars
c45b7c4f refactor: introduce testutil.h (deduplicate `random_fe_`, `ge_equals_` helpers)
dc551414 tests: simplify `random_fe_non_zero` (remove loop limit and unneeded normalize)
060e32cb Merge bitcoin-core/secp256k1#1401: ci, gha: Run all MSVC tests on Windows natively
de657c20 Merge bitcoin-core/secp256k1#1062: Removes `_fe_equal_var`, and unwanted `_fe_normalize_weak` calls (in tests)
bcffeb14 Merge bitcoin-core/secp256k1#1404: ci: Remove "arm64: macOS Ventura" task from Cirrus CI
c2f64358 ci: Add comment about switching macOS to M1 on GHA later
4a24fae0 ci: Remove "arm64: macOS Ventura" task from Cirrus CI
b0886fd3 ci, gha: Ensure only a single workflow processes `github.ref` at a time
3d05c86d Merge bitcoin-core/secp256k1#1394: ci, gha: Run "x86_64: macOS Ventura" job on GitHub Actions
d78bec70 ci: Remove Windows MSVC tasks from Cirrus CI
3545dc2b ci, gha: Run all MSVC tests on Windows natively
5d8fa825 Merge bitcoin-core/secp256k1#1274: test: Silent noisy clang warnings about Valgrind code on macOS x86_64
8e54a346 ci, gha: Run "x86_64: macOS Ventura" job on GitHub Actions
b327abfc Merge bitcoin-core/secp256k1#1402: ci: Use Homebrew's gcc in native macOS task
d62db574 ci: Use Homebrew's gcc in native macOS task
54058d16 field: remove `secp256k1_fe_equal_var`
bb4efd64 tests: remove unwanted `secp256k1_fe_normalize_weak` call
eedd7810 Merge bitcoin-core/secp256k1#1348: tighten group magnitude limits, save normalize_weak calls in group add methods (revival of #1032)
b2f6712d Merge bitcoin-core/secp256k1#1400: ctimetests: Use new SECP256K1_CHECKMEM macros also for ellswift
9c91ea41 ci: Enable ellswift module where it's missing
db32a247 ctimetests: Use new SECP256K1_CHECKMEM macros also for ellswift
ce765a5b Merge bitcoin-core/secp256k1#1399: ci, gha: Run "SageMath prover" job on GitHub Actions
8408dfdc Revert "ci: Run sage prover on CI"
c8d9914f ci, gha: Run "SageMath prover" job on GitHub Actions
8d2960c8 Merge bitcoin-core/secp256k1#1397: ci: Remove "Windows (VS 2022)" task from Cirrus CI
f1774e5e ci, gha: Make MSVC job presentation more explicit
5ee039bb ci: Remove "Windows (VS 2022)" task from Cirrus CI
96294c00 Merge bitcoin-core/secp256k1#1389: ci: Run "Windows (VS 2022)" job on GitHub Actions
a2f7ccde ci: Run "Windows (VS 2022)" job on GitHub Actions
374e2b54 Merge bitcoin-core/secp256k1#1290: cmake: Set `ENVIRONMENT` property for examples on Windows
1b13415d Merge bitcoin-core/secp256k1#1391: refactor: take use of `secp256k1_scalar_{zero,one}` constants (part 2)
a1bd4971 refactor: take use of `secp256k1_scalar_{zero,one}` constants (part 2)
b7c685e7 Save _normalize_weak calls in group add methods
c83afa66 Tighten group magnitude limits
26392da2 Merge bitcoin-core/secp256k1#1386: ci: print $ELLSWIFT in cirrus.sh
d23da6d5 use secp256k1_scalar_verify checks
46924788 ci: print $ELLSWIFT in cirrus.sh
c7d04549 add verification for scalars
c734c642 Merge bitcoin-core/secp256k1#1384: build: enable ellswift module via SECP_CONFIG_DEFINES
ad152151 update max scalar in scalar_cmov_test and fix schnorrsig_verify exhaustive test
78ca8807 build: enable ellswift module via SECP_CONFIG_DEFINES
0e00fc7d Merge bitcoin-core/secp256k1#1383: util: remove unused checked_realloc
b097a466 util: remove unused checked_realloc
2bd5f3e6 Merge bitcoin-core/secp256k1#1382: refactor: Drop unused cast
4f8c5bd7 refactor: Drop unused cast
173e8d06 Implement current magnitude assumptions
49afd2f5 Take use of _fe_verify_magnitude in field_impl.h
4e9661fc Add _fe_verify_magnitude (no-op unless VERIFY is enabled)
690b0fc0 add missing group element invariant checks
c545fdc3 Merge bitcoin-core/secp256k1#1298: Remove randomness tests
b40e2d30 Merge bitcoin-core/secp256k1#1378: ellswift: fix probabilistic test failure when swapping sides
c424e2fb ellswift: fix probabilistic test failure when swapping sides
175db311 ci: Drop no longer needed `PATH` variable update on Windows
116d2ab3 cmake: Set `ENVIRONMENT` property for examples on Windows
cef37399 cmake, refactor: Use helper function instead of interface library
907a6721 Merge bitcoin-core/secp256k1#1313: ci: Test on development snapshots of GCC and Clang
0f7657d5 Merge bitcoin-core/secp256k1#1366: field: Use `restrict` consistently in fe_sqrt
cc557575 Merge bitcoin-core/secp256k1#1340: clean up in-comment Sage code (refer to secp256k1_params.sage, update to Python3)
600c5adc clean up in-comment Sage code (refer to secp256k1_params.sage, update to Python3)
981e5be3 ci: Fix typo in comment
e9e96482 ci: Reduce number of macOS tasks from 28 to 8
609093b3 ci: Add x86_64 Linux tasks for gcc and clang snapshots
1deecaaf ci: Install development snapshots of gcc and clang
b79ba8aa field: Use `restrict` consistently in fe_sqrt
c9ebca95 Merge bitcoin-core/secp256k1#1363: doc: minor ellswift.md updates
afd7eb4a Merge bitcoin-core/secp256k1#1371: Add exhaustive tests for ellswift (with create+decode roundtrip)
27921192 Add exhaustive test for ellswift (create+decode roundtrip)
c7d900ff doc: minor ellswift.md updates
332af315 Merge bitcoin-core/secp256k1#1344: group: save normalize_weak calls in `secp256k1_ge_is_valid_var`/`secp256k1_gej_eq_x_var`
9e6d1b0e Merge bitcoin-core/secp256k1#1367: build: Improvements to symbol visibility logic on Windows (attempt 3)
0aacf643 Merge bitcoin-core/secp256k1#1370: Corrected some typos
b6b9834e small fixes
07c0e8b8 group: remove unneeded normalize_weak in `secp256k1_gej_eq_x_var`
3fc1de5c Merge bitcoin-core/secp256k1#1364: Avoid `-Wmaybe-uninitialized` when compiling with `gcc -O1`
fb758fe8 Merge bitcoin-core/secp256k1#1323: tweak_add: fix API doc for tweak=0
c6cd2b15 ci: Add task for static library on Windows + CMake
020bf69a build: Add extensive docs on visibility issues
0196e8ad build: Introduce `SECP256k1_DLL_EXPORT` macro
9f1b1904 refactor: Replace `SECP256K1_API_VAR` with `SECP256K1_API`
ae9db95c build: Introduce `SECP256K1_STATIC` macro for Windows users
7966aee3 Merge bitcoin-core/secp256k1#1369: ci: Print commit in Windows container
a7bec342 ci: Print commit in Windows container
249c81ea Merge bitcoin-core/secp256k1#1368: ci: Drop manual checkout of merge commit
98579e29 ci: Drop manual checkout of merge commit
5b9f37f1 ci: Add `CFLAGS: -O1` to task matrix
a6ca76cd Avoid `-Wmaybe-uninitialized` when compiling with `gcc -O1`
0fa84f86 Merge bitcoin-core/secp256k1#1358: tests: introduce helper for non-zero `random_fe_test()` results
5a95a268 tests: introduce helper for non-zero `random_fe_test` results
304421d5 tests: refactor: remove duplicate function `random_field_element_test`
3aef6ab8 Merge bitcoin-core/secp256k1#1345: field: Static-assert that int args affecting magnitude are constant
4494a369 Merge bitcoin-core/secp256k1#1357: tests: refactor: take use of `secp256k1_ge_x_on_curve_var`
799f4eec Merge bitcoin-core/secp256k1#1356: ci: Adjust Docker image to Debian 12 "bookworm"
c862a9fb ci: Adjust Docker image to Debian 12 "bookworm"
a1782098 ci: Force DWARF v4 for Clang when Valgrind tests are expected
7d8d5c86 tests: refactor: take use of `secp256k1_ge_x_on_curve_var`
8a727346 Help the compiler prove that a loop is entered
fd491ea1 Merge bitcoin-core/secp256k1#1355: Fix a typo in the error message
ac43613d Merge bitcoin-core/secp256k1#1354: Add ellswift to CHANGELOG
67887ae6 Fix a typo in the error message
926dd3e9 Merge bitcoin-core/secp256k1#1295: abi: Use dllexport for mingw builds
10836832 Merge bitcoin-core/secp256k1#1336: Use `__shiftright128` intrinsic in `secp256k1_u128_rshift` on MSVC
7c7467ab Refer to ellswift.md in API docs
c32ffd8d Add ellswift to CHANGELOG
3c1a0fd3 Merge bitcoin-core/secp256k1#1347: field: Document return value of fe_sqrt()
705ce7ed Merge bitcoin-core/secp256k1#1129: ElligatorSwift + integrated x-only DH
0702ecb0 Merge bitcoin-core/secp256k1#1338: Drop no longer needed `#include "../include/secp256k1.h"`
57791374 field: Document return value of fe_sqrt()
90e360ac Add doc/ellswift.md with ElligatorSwift explanation
4f091847 Add ellswift testing to CI
1bcea8c5 Add benchmarks for ellswift module
2d1d41ac Add ctime tests for ellswift module
df633cde Add _prefix and _bip324 ellswift_xdh hash functions
9695deb3 Add tests for ellswift module
c47917bb Add ellswift module implementing ElligatorSwift
79e5b2a8 Add functions to test if X coordinate is valid
a597a5a9 Add benchmark for key generation
30574f22 Merge bitcoin-core/secp256k1#1349: Normalize ge produced from secp256k1_pubkey_load
45c5ca76 Merge bitcoin-core/secp256k1#1350: scalar: introduce and use `secp256k1_{read,write}_be64` helpers
f1652528 Normalize ge produced from secp256k1_pubkey_load
7067ee54 tests: add tests for `secp256k1_{read,write}_be64`
740528ca scalar: use newly introduced `secp256k1_{read,write}_be64` helpers (4x64 impl.)
be8ff3a0 field: Static-assert that int args affecting magnitude are constant
efa76c4b group: remove unneeded normalize_weak in `secp256k1_ge_is_valid_var`
67214f5f Merge bitcoin-core/secp256k1#1339: scalar: refactor: use `secp256k1_{read,write}_be32` helpers
cb1a5927 Merge bitcoin-core/secp256k1#1341: docs: correct `pubkey` param descriptions for `secp256k1_keypair_{xonly_,}pub`
f3644287 docs: correct `pubkey` param descriptions for `secp256k1_keypair_{xonly_,}pub`
887183e7 scalar: use `secp256k1_{read,write}_be32` helpers (4x64 impl.)
52b84238 scalar: use `secp256k1_{read,write}_be32` helpers (8x32 impl.)
e449af68 Drop no longer needed `#include "../include/secp256k1.h"`
747ada35 test: Silent noisy clang warnings about Valgrind code on macOS x86_64
5b7bf2e9 Use `__shiftright128` intrinsic in `secp256k1_u128_rshift` on MSVC
60556c9f Merge bitcoin-core/secp256k1#1337: ci: Fix error D8037 in `cl.exe` (attempt 2)
db29bf22 ci: Remove quirk that runs dummy command after wineserver
c7db4942 ci: Fix error D8037 in `cl.exe`
7dae1158 Revert "ci: Move wine prefix to /tmp to avoid error D8037 in cl.exe"
bf29f8d0 Merge bitcoin-core/secp256k1#1334: fix input range comment for `secp256k1_fe_add_int`
605e07e3 fix input range comment for `secp256k1_fe_add_int`
debf3e5c Merge bitcoin-core/secp256k1#1330: refactor: take use of `secp256k1_scalar_{zero,one}` constants
d75dc59b Merge bitcoin-core/secp256k1#1333: test: Warn if both `VERIFY` and `COVERAGE` are defined
ade5b367 tests: add checks for scalar constants `secp256k1_scalar_{zero,one}`
e83801f5 test: Warn if both `VERIFY` and `COVERAGE` are defined
654246c6 refactor: take use of `secp256k1_scalar_{zero,one}` constants
908e02d5 Merge bitcoin-core/secp256k1#1328: build: Bump MSVC warning level up to W3
1549db0c build: Level up MSVC warnings
20a5da5f Merge bitcoin-core/secp256k1#1310: Refine release process
05873bb6 tweak_add: fix API doc for tweak=0
ad846032 release process: clarify change log updates
6348bc7e release process: fix process for maintenance release
79fa50b0 release process: mention targeted release schedule
16520678 release process: add sanity checks
09df0bfb Merge bitcoin-core/secp256k1#1327: ci: Move wine prefix to /tmp to avoid error D8037 in cl.exe
27504d5c ci: Move wine prefix to /tmp to avoid error D8037 in cl.exe
d373a721 Merge bitcoin-core/secp256k1#1316: Do not invoke fe_is_zero on failed set_b32_limit
6433175f Do not invoke fe_is_zero on failed set_b32_limit
5f7903c7 Merge bitcoin-core/secp256k1#1318: build: Enable -DVERIFY for precomputation binaries
e9e4526a Merge bitcoin-core/secp256k1#1317: Make fe_cmov take max of magnitudes
5768b502 build: Enable -DVERIFY for precomputation binaries
31b4bbee Make fe_cmov take max of magnitudes
83186db3 Merge bitcoin-core/secp256k1#1314: release cleanup: bump version after 0.3.2
95448ef2 release cleanup: bump version after 0.3.2
acf5c55a Merge bitcoin-core/secp256k1#1312: release: Prepare for 0.3.2
d490ca20 release: Prepare for 0.3.2
3e3d125b Merge bitcoin-core/secp256k1#1309: changelog: Catch up
e8295d07 Merge bitcoin-core/secp256k1#1311: Revert "Remove unused scratch space from API"
697e1ccf changelog: Catch up
3ad1027a Revert "Remove unused scratch space from API"
76b43f34 changelog: Add entry for #1303
7d4f86d2 Merge bitcoin-core/secp256k1#1307: Mark more assembly outputs as early clobber
b54a0672 Merge bitcoin-core/secp256k1#1304: build: Rename arm to arm32 and check if it's really supported
c6bb29b3 build: Rename `64bit` to `x86_64`
8c9ae37a Add release note
03246457 autotools: Add `SECP_ARM32_ASM_CHECK` macro
ed4ba238 cmake: Add `check_arm32_assembly` function
350b4bd6 Mark stack variables as early clobber for technical correctness
0c729ba7 Bugfix: mark outputs as early clobber in scalar x86_64 asm
3353d3c7 Merge bitcoin-core/secp256k1#1207: Split fe_set_b32 into reducing and normalizing variants
5b326022 Split fe_set_b32 into reducing and normalizing variants
006ddc1f Merge bitcoin-core/secp256k1#1306: build: Make tests work with external default callbacks
1907f0f1 build: Make tests work with external default callbacks
fb3a8063 Merge bitcoin-core/secp256k1#1133: schnorrsig: Add test vectors for variable-length messages
cd54ac7c schnorrsig: Improve docs of schnorrsig_sign_custom
28687b03 schnorrsig: Add BIP340 varlen test vectors
97a98bed schnorrsig: Refactor test vector code to allow varlen messages
ab5a9171 Merge bitcoin-core/secp256k1#1303: ct: Use more volatile
9eb6934f Merge bitcoin-core/secp256k1#1305: Remove unused scratch space from API
073d98a0 Merge bitcoin-core/secp256k1#1292: refactor: Make 64-bit shift explicit
17fa2173 ct: Be cautious and use volatile trick in more "conditional" paths
5fb336f9 ct: Use volatile trick in scalar_cond_negate
712e7f87 Remove unused scratch space from API
54d34b6c Merge bitcoin-core/secp256k1#1300: Avoid normalize conditional on VERIFY
c63ec88e Merge bitcoin-core/secp256k1#1066: Abstract out and merge all the magnitude/normalized logic
7fc642fa Simplify secp256k1_fe_{impl_,}verify
4e176ad5 Abstract out verify logic for fe_is_square_var
4371f983 Abstract out verify logic for fe_add_int
89e324c6 Abstract out verify logic for fe_half
283cd80a Abstract out verify logic for fe_get_bounds
d5aa2f03 Abstract out verify logic for fe_inv{,_var}
31676460 Abstract out verify logic for fe_from_storage
76d31e50 Abstract out verify logic for fe_to_storage
1e6894bd Abstract out verify logic for fe_cmov
be82bd8e Improve comments/checks for fe_sqrt
6ab35082 Abstract out verify logic for fe_sqr
4c25f6ef Abstract out verify logic for fe_mul
e179e651 Abstract out verify logic for fe_add
7e7ad7ff Abstract out verify logic for fe_mul_int
65d82a34 Abstract out verify logic for fe_negate
14467089 Abstract out verify logic for fe_get_b32
f7a7666a Abstract out verify logic for fe_set_b32
ce4d2093 Abstract out verify logic for fe_cmp_var
7d7d43c6 Improve comments/check for fe_equal{,_var}
c5e788d6 Abstract out verify logic for fe_is_odd
d3f3fe86 Abstract out verify logic for fe_is_zero
c701d9a4 Abstract out verify logic for fe_clear
19a2bfee Abstract out verify logic for fe_set_int
864f9db4 Abstract out verify logic for fe_normalizes_to_zero{,_var}
6c313711 Abstract out verify logic for fe_normalize_var
e28b51f5 Abstract out verify logic for fe_normalize_weak
b6b6f9cb Abstract out verify logic for fe_normalize
7fa51955 Bugfix: correct SECP256K1_FE_CONST mag/norm fields
e5cf4bf3 build: Rename `arm` to `arm32`
b29566c5 Merge magnitude/normalized fields, move/improve comments
97c63b90 Avoid normalize conditional on VERIFY
341cc197 Merge bitcoin-core/secp256k1#1299: Infinity handling: ecmult_const(infinity) works, and group verification
6ec3731e Simplify test PRNG implementation
bbc83446 Avoid secp256k1_ge_set_gej_zinv with uninitialized z
0a2e0b2a Make secp256k1_{fe,ge,gej}_verify work as no-op if non-VERIFY
f2026672 Add invariant checking to group elements
a18821d5 Always initialize output coordinates in secp256k1_ge_set_gej
3086cb90 Expose secp256k1_fe_verify to other modules
a0e696fd Make secp256k1_ecmult_const handle infinity
24c768ae Merge bitcoin-core/secp256k1#1301: Avoid using bench_verify_data as bench_sign_data; merge them
2e65f1fd Avoid using bench_verify_data as bench_sign_data; merge them
fb5bfa4e Add static test vector for Xoshiro256++
1cf15ebd Merge bitcoin-core/secp256k1#1296: docs: complete interface description for `secp256k1_schnorrsig_sign_custom`
723e8ca8 Remove randomness tests
bc7c8db1 abi: Use dllexport for mingw builds
149c41ce docs: complete interface description for `secp256k1_schnorrsig_sign_custom`
f30c7486 Merge bitcoin-core/secp256k1#1270: cmake: Fix library ABI versioning
d1e48e54 refactor: Make 64-bit shift explicit
b2e29e43 ci: Treat all compiler warnings as er…
nuttycom
force-pushed
the
release/zcash_script-0.6.0
branch
from
September 30, 2026 23:30
69bb704 to
a802bcd
Compare
conradoplg
requested changes
Sep 30, 2026
Contributor
There was a problem hiding this comment.
This is missing some fixes that were included in the 0.4.x branch that were never incorporated in to the 0.5.x branch which ended up being abandoned. Claude findings:
Must fix before merging
- Consensus regression in sig_op_count (zcash_script/src/script/iter.rs:106)
- Cause: neither 5db94de ("make sig_op_count() match zcashd", released in 0.4.5) nor bc58d40 (HashType::raw_bits(), released in 0.4.4) is an ancestor of the PR. The PR head still has the try_fold that
stops at the first Disabled opcode. - Evidence: I ran a probe on both versions:
| Script | 0.4.5 (and zcashd) | PR head |
|---|---|---|
| OP_CODESEPARATOR OP_CHECKSIG | 1 | 0 |
| OP_CAT OP_CHECKSIG | 1 | 0 |
| OP_CODESEPARATOR + 50× OP_CHECKMULTISIG | 1000 | 0 |
The PR's test plan shows 4 zcash_script tests, not 5, because 0.4.5's regression test isn't there.
- Impact: Zebra moving from 0.4.5 to 0.6.0 would undercount sigops and accept blocks that zcashd rejects.
- Fix: forward-port both commits to master first. raw_bits() is also a public API regression for anyone on 0.4.4 or later. The published 0.5.2 has the same bug. zcash_script/README.md only describes
cherry-picking from main to the backport branch, which is how this gap opened, so it needs a forward-port step.
- The Windows (MSVC) build is broken. CI's Test Suite (windows-latest) fails with LNK2019: unresolved external symbol __imp_secp256k1_ecdsa_verify and five other _imp_secp256k1* symbols.
- Cause: v0.8.0's include/secp256k1.h declares its API __declspec(dllimport) on _WIN32 unless SECP256K1_STATIC is defined. v0.2.0 had no such default.
- Fix: add .define("SECP256K1_STATIC", None) to base_config in libzcash_script/build.rs (around line 82). MinGW is affected the same way. I couldn't test this without Windows.
- The std feature doesn't enable secp256k1/std (std = []). So ecdsa::verify uses secp256k1's no-std shared context. Each call spins on one global lock, copies the context, and then builds a new one anyway,
because upstream clone_into never sets the cached pointer (I checked the source).
- The old code also built a context on every call, so this is mostly added contention when Zebra verifies in parallel.
- std = ["secp256k1?/std"] avoids it. I didn't benchmark.
- Minor items:
- The 0.6.0 CHANGELOG doesn't list which public APIs changed type: signature::Decoded::sig(), descriptor::KeyExpression::from_xpub and descriptor::Key.
nuttycom
force-pushed
the
release/zcash_script-0.6.0
branch
from
September 30, 2026 23:54
a802bcd to
b192955
Compare
nuttycom
force-pushed
the
release/zcash_script-0.6.0
branch
from
October 1, 2026 00:02
b192955 to
69c92ee
Compare
Contributor
Author
|
@conradoplg were those changes never merged back to |
Contributor
No, we ended up never getting around doing that |
A static library resolves symbols only from libraries linked after it, and the build script emitted the bundled secp256k1 library first. The build also named it `secp256k1`, the same name `secp256k1-sys` uses for its own library; the link succeeded only because the two were merged in the link order. With `secp256k1-sys 0.14` that no longer happens, and the link fails with undefined `secp256k1_*` references. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Linux C++ linking problem that held the toolchain at 1.81 is fixed in 1.85. This also addresses the clippy lints that the 1.85 toolchain reports. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This aligns zcash_script with the Zcash Rust crates, whose dependencies now require the stable `crypto-common 0.2` that `bip32 0.6.0-pre.1` cannot use. Signature verification now uses `secp256k1::ecdsa::verify`, which replaces the deprecated `Secp256k1::verify_ecdsa`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The copy of libsecp256k1 under libzcash_script/depend/zcash/src/secp256k1 comes from zcashd, which vendors libsecp256k1 v0.2.0 (21ffe4b22a9683cf24ae0763359e401d1284cc7a) as a git subtree. That subtree metadata was lost when zcashd itself was squashed into this repository. This merge records it, without changing any files, so that `git subtree` can update the copy in place. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This is the libsecp256k1 release that secp256k1-sys 0.14 vendors. zcashd's change to `secp256k1_scalar_get_b32`, which added casts to avoid truncation warnings, conflicts with upstream's rewrite of that function in terms of `secp256k1_write_be64`, which does not truncate; upstream's version is taken. zcashd's `-std=c99` change to `configure.ac` is retained. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Build the vendored libsecp256k1 0.8.0 with the modules and precomputation parameters that `secp256k1-sys 0.14` uses, so that a build with `--cfg rust_secp_no_symbol_renaming` resolves the Rust bindings against this library and links a single copy of libsecp256k1. The configuration defines inherited from zcashd are removed. None of them changes the compiled code: - `SECP256K1_BUILD` is defined by `src/secp256k1.c` itself. - `USE_NUM_NONE`, `USE_FIELD_INV_BUILTIN`, `USE_SCALAR_INV_BUILTIN`, `USE_ENDOMORPHISM`, and `WORDS_BIGENDIAN` are not read by libsecp256k1, neither by 0.8.0 nor by the 0.2.0 it replaces. The bignum backend and the choice of inversion implementation no longer exist, the endomorphism optimization is unconditional, and byte-order conversion is written to be independent of endianness. - `USE_FIELD_5X52`/`USE_SCALAR_4X64`/`HAVE___INT128` and `USE_FIELD_10X26`/`USE_SCALAR_8X32` are likewise not read by either version. libsecp256k1 selects the field and scalar implementations itself from `__SIZEOF_INT128__`/`UINT128_MAX` (and MSVC's x64/arm64 intrinsics), so the `uint128_t` probe that chose between them is removed too. `ECMULT_GEN_PREC_BITS` was live in 0.2.0, where it sized the precomputed signing table. libsecp256k1 0.5.0 replaced it with `COMB_BLOCKS` and `COMB_TEETH`, which are set to `secp256k1-sys`'s 43 and 6 (upstream's 86 KiB default table). The signing table is only used for signing, which libzcash_script's C++ does not do, but it must match `secp256k1-sys` for the Rust bindings when they share this library. `ECMULT_WINDOW_SIZE`, which sizes the verification table, is unchanged at 15. libsecp256k1 0.8.0's headers declare its API as imported from a DLL on Windows unless the consumer defines `SECP256K1_STATIC`, so the C++ build now defines it; libsecp256k1 is always linked statically here. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
cargo before 1.90 packages each workspace member against crates.io, so a member that depends on an unpublished version of another member, such as libzcash_script on zcash_script 0.6.0, fails to package until that version is published. Packaging does not depend on the MSRV, which the test suite covers, so the package job now runs on stable and nightly. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
nuttycom
force-pushed
the
release/zcash_script-0.6.0
branch
from
October 1, 2026 00:20
69c92ee to
c2f9969
Compare
Contributor
Author
|
str4d
requested changes
Oct 1, 2026
3 tasks done
Build and test libzcash_script with `--cfg rust_secp_no_symbol_renaming`, so that the tests checking the Rust interpreter against the C++ one run with the Rust `secp256k1` bindings resolved against the libsecp256k1 that libzcash_script builds. Then check that each test binary contains that unprefixed libsecp256k1 and none of the code that `secp256k1-sys` builds under its symbol prefix. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
nuttycom
force-pushed
the
release/zcash_script-0.6.0
branch
from
October 1, 2026 01:03
c2f9969 to
534eb4b
Compare
str4d
previously approved these changes
Oct 1, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
str4d
approved these changes
Oct 1, 2026
conradoplg
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
DO NOT SQUASH-MERGE
Releases
zcash_script0.6.0 andlibzcash_script0.2.0.zcash_scriptlibzcash_scriptMotivation
The Zcash Rust crates are moving to
orchard 0.16andsapling-crypto 0.9, which requirezcash_note_encryption 0.5.1. That release depends oncipher 0.5and so on the stablecrypto-common 0.2, whichbip32 =0.6.0-pre.1(viadigest 0.11.0-pre.9) cannot build against. Every consumer that links bothzcash_scriptand the shielded crates therefore needszcash_scriptonbip32 0.6(zcash/librustzcash#3091).Changes
bip32 0.6andsecp256k1 0.33. Signature verification usessecp256k1::ecdsa::verifyin place of the deprecatedSecp256k1::verify_ecdsa.secp256k1types appear in the public API, so this is a breaking release.bip32 0.6requires it. The pinned toolchain moves from 1.81 to 1.85, where the Linux C++ linking problem noted inrust-toolchain.tomlis fixed. Includes the fixes for the clippy lints the 1.85 toolchain reports.zcash_script-v0.4.5(Merge zcash_script-0.4.5 back tomaster#309), so 0.6.0 is the first release of this line to includeHashType::raw_bits()and the zcashd-matchingsig_op_count().libzcash_scriptvendors underdepend/zcash/src/secp256k1is updated in place from 0.2.0 to 0.8.0, the releasesecp256k1-sys 0.14vendors, bygit subtree pull. The zcashd subtree metadata for that path was lost when zcashd was squashed into this repository, so a-s oursmerge first records its upstream base (v0.2.0); later updates are a plaingit subtree pull --prefix libzcash_script/depend/zcash/src/secp256k1 https://github.com/bitcoin-core/secp256k1.git <tag> --squash. The library is built with the modules and precomputation parameterssecp256k1-sysuses, so building with--cfg rust_secp_no_symbol_renaminglinks the Rustsecp256k1bindings against it and leaves a single copy of libsecp256k1 in the binary. The commit message records why each of zcashd's former configuration defines could be removed.libzcash_scriptlink fixes. The bundled library is linked afterlibzcash_scriptand under a name distinct fromsecp256k1-sys's, andSECP256K1_STATICis defined so that libsecp256k1 0.8.0's headers do not declare its API as imported from a DLL on Windows.libzcash_scriptcannot be packaged against an unpublishedzcash_script. A newTest Suite (single libsecp256k1)job runslibzcash_script's Rust/C++ comparison tests with--cfg rust_secp_no_symbol_renamingand checks that each test binary contains the unprefixed libsecp256k1 and none ofsecp256k1-sys's prefixed copy.Each first-parent commit builds on its own (
cargo check --workspace --all-targetsandcargo check -p zcash_script --all-features --all-targets).Test plan
cargo test(default members):libzcash_script14 passed,zcash_script5 passedcargo test -p zcash_script --all-featurescargo test -p libzcash_scriptwith--cfg rust_secp_no_symbol_renaming, and the single-libsecp256k1 symbol check (which fails, as intended, on a default build)cargo check -p zcash_script --no-default-features --features signature-validationcargo clippy --workspace --all-targets -- -D warningsandcargo clippy -p zcash_script --all-features --all-targets -- -D warningson 1.85cargo fmt --all -- --checkcargo +stable package(both crates)After merge: create the
zcash_script-v0.6.0andlibzcash_script-v0.2.0GitHub releases and publishzcash_scriptbeforelibzcash_script, perzcash_script/README.md.🤖 Generated with Claude Code