]> git.codecow.com Git - nano25519.git/commitdiff
Skip bulk block verification entirely if public key is invalid.
authorChris Duncan <chris@codecow.com>
Thu, 27 Aug 2026 06:42:27 +0000 (23:42 -0700)
committerChris Duncan <chris@codecow.com>
Thu, 27 Aug 2026 06:42:27 +0000 (23:42 -0700)
src/assembly/index.ts

index 10af85051ca3aca61773a823affdc8a5bb545084..4d4e4f5fa99d75318aecd82d1e7b92997fb9701e 100644 (file)
@@ -191,21 +191,25 @@ export function verify_blocks (count: i32): void {
        // Clear local buffers
        verify_blocks_pub.fill(0)
 
-       // Copy input buffer to local parameters, then clear input buffer
+       // Copy public key input buffer to local parameter, then clear input buffer
        memory.copy(changetype<usize>(verify_blocks_pub), changetype<usize>(PUB_BUFFER), KEY_BYTELENGTH)
        PUB_BUFFER.fill(0)
 
-       // Verify public key, then clear local input
-       const validPubkey = crypto_verify_pubkey(verify_blocks_pub)
-
-       // Iterate over block hash/signature pairs
-       for (let i = 0; i < count; i++) {
-               // Copy message buffer to local block hash/signature buffers
-               memory.copy(changetype<usize>(verify_blocks_msg), changetype<usize>(MESSAGE_BUFFER) + (96 * i), BLOCKHASH_BYTELENGTH)
-               memory.copy(changetype<usize>(verify_blocks_sig), changetype<usize>(MESSAGE_BUFFER) + BLOCKHASH_BYTELENGTH + (96 * i), SIGNATURE_BYTELENGTH)
-
-               // Verify hash and signature, then copy local result to output buffer
-               verify_blocks_out[i] = u8(validPubkey | crypto_verify_relaxed(verify_blocks_sig, verify_blocks_msg, BLOCKHASH_BYTELENGTH, verify_blocks_pub))
+       // Set all output to false so errors fail closed
+       OUTPUT_BUFFER.fill(255)
+
+       // Verify public key before proceeding with signature verification
+       if (crypto_verify_pubkey(verify_blocks_pub) {
+       
+               // Iterate over block hash/signature pairs
+               for (let i = 0; i < count; i++) {
+                       // Copy message buffer to local block hash/signature buffers
+                       memory.copy(changetype<usize>(verify_blocks_msg), changetype<usize>(MESSAGE_BUFFER) + (96 * i), BLOCKHASH_BYTELENGTH)
+                       memory.copy(changetype<usize>(verify_blocks_sig), changetype<usize>(MESSAGE_BUFFER) + BLOCKHASH_BYTELENGTH + (96 * i), SIGNATURE_BYTELENGTH)
+
+                       // Verify hash and signature
+                       verify_blocks_out[i] = u8(crypto_verify_relaxed(verify_blocks_sig, verify_blocks_msg, BLOCKHASH_BYTELENGTH, verify_blocks_pub))
+               }       
        }
 
        // Clear local input