]> git.codecow.com Git - nano25519.git/commitdiff
Return exit code from crypto_sign to allow buffer cleanup.
authorChris Duncan <chris@codecow.com>
Sat, 29 Aug 2026 21:24:56 +0000 (14:24 -0700)
committerChris Duncan <chris@codecow.com>
Sat, 29 Aug 2026 21:24:56 +0000 (14:24 -0700)
src/assembly/crypto_sign.ts
src/assembly/index.ts

index 50f6b121678a713f2f55f407b61f8c3b733971a7..55e2a8ae339c03691fb6a7404bf2fcf30ab27c26 100644 (file)
@@ -39,16 +39,14 @@ const S = new StaticArray<u8>(64)
  * @param {StaticArray<u8>} prv 32-byte private key from input buffer
  * @param {StaticArray<u8>} pub 32-byte public key from input buffer
  */
-export function crypto_sign (RS: StaticArray<u8>, M: StaticArray<u8>, mlen: i32, prv: StaticArray<u8>, pub: StaticArray<u8>): void {
+export function crypto_sign (RS: StaticArray<u8>, M: StaticArray<u8>, mlen: i32, prv: StaticArray<u8>, pub: StaticArray<u8>): i32 {
        // Derive `A` from private key and throw if it does not match public key
        crypto_derive(A, prv)
        let c = 0
        for (let i = 0; i < KEY_BYTELENGTH; i++) {
                c |= A[i] ^ pub[i]
        }
-       if (c != 0) {
-               throw new Error('Invalid public key')
-       }
+       if (c != 0) return -1
 
        // Hash private key to `h`
        blake2b.init().update(prv, KEY_BYTELENGTH).digest(h)
@@ -88,4 +86,6 @@ export function crypto_sign (RS: StaticArray<u8>, M: StaticArray<u8>, mlen: i32,
        R.fill(0)
        memory.copy(changetype<usize>(RS) + 32, changetype<usize>(S), 32)
        S.fill(0)
+       
+       return 0
 }
index 8905fad2892aa35af90970b536d8c84ceddca954..a277617315719bf60c60526ee5d77537f60638f2 100644 (file)
@@ -131,16 +131,16 @@ export function sign (mlen: i32): void {
        INPUT_PUB.fill(0)
 
        // Sign message from buffer, then clear local input
-       crypto_sign(sig, INPUT_MSG, mlen, prv, pub)
+       const result = crypto_sign(OUTPUT_SIGN, INPUT_MSG, mlen, prv, pub)
        prv.fill(0)
        pub.fill(0)
        INPUT_MSG.fill(0)
-
-       // Copy local result to output buffer
-       memory.copy(changetype<usize>(OUTPUT_SIGN), changetype<usize>(sig), SIGNATURE_BYTELENGTH)
-
-       // Clear local result
-       sig.fill(0)
+       
+       // Clear signature output buffer if signing failed      
+       if (result != 0) {
+               OUTPUT_SIGN.fill(0)
+               throw new Error('Failed to sign, check keypair and message are valid')
+       }
 }
 
 /**