]> git.codecow.com Git - nano25519.git/commitdiff
Fix terminology.
authorChris Duncan <chris@zoso.dev>
Tue, 1 Sep 2026 05:53:28 +0000 (22:53 -0700)
committerChris Duncan <chris@zoso.dev>
Tue, 1 Sep 2026 05:53:28 +0000 (22:53 -0700)
src/assembly/crypto_sign.ts
src/assembly/index.ts

index a6605ce7567dd77382adca526aaae51d9852297d..cfc952328bc62e7d3c7412966af36da6f565581d 100644 (file)
@@ -4,7 +4,6 @@
 import { KEY_BYTELENGTH } from '.'
 import { Blake2b } from './blake2b'
 import { crypto_derive } from './crypto_derive'
-import { errors } from './errors'
 import { ge_scalarmult_base_tobytes } from './ge'
 import { sc_muladd, sc_reduce } from './sc'
 import { clamp } from './utils'
@@ -28,7 +27,7 @@ const S = new StaticArray<u8>(64)
  * In this implementation, both the private key and the public key are required.
  * This ensures the user has a full correct keypair for data integrity. It also
  * offers a small performance improvement in the case of an invalid public key
- * by throwing early and avoiding expensive point multiplication; RFC 8032
+ * by returning early and avoiding expensive point multiplication; RFC 8032
  * indicates the public key should be recomputed from the private key when
  * signing anyway, so there is no penalty for checking key validity first.
  *
@@ -41,12 +40,13 @@ const S = new StaticArray<u8>(64)
  * @param {StaticArray<u8>} pub 32-byte public key from input buffer
  */
 export function crypto_sign (RS: StaticArray<u8>, M: StaticArray<u8>, mlen: i32, prv: StaticArray<u8>, pub: StaticArray<u8>): i32 {
-       // Derive `A` from private key and throw if it does not match public key
+       // Derive `A` from private key
        crypto_derive(A, prv)
        let c = 0
        for (let i = 0; i < KEY_BYTELENGTH; i++) {
                c |= A[i] ^ pub[i]
        }
+       // Return early if `A` does not match public key
        if (c != 0) return 1
 
        // Hash private key to `h`
@@ -87,6 +87,6 @@ export function crypto_sign (RS: StaticArray<u8>, M: StaticArray<u8>, mlen: i32,
        R.fill(0)
        memory.copy(changetype<usize>(RS) + 32, changetype<usize>(S), 32)
        S.fill(0)
-       
+
        return 0
 }
index 67fbdc586ae558812b5177b4c34684b273e5b842..278d5a17c77b3e498d31f4a08f64e0f6844f0a26 100644 (file)
@@ -136,8 +136,8 @@ export function sign (mlen: i32): void {
        prv.fill(0)
        pub.fill(0)
        INPUT_MSG.fill(0)
-       
-       // Clear signature output buffer if signing failed      
+
+       // Clear signature output buffer if signing failed
        if (result != 0) {
                OUTPUT_SIGN.fill(0)
                throw new Error(errors[result])