bip-0327: derive extra_in from secrets in the reference self-test #2278

pull fametrano wants to merge 1 commits into bitcoin:master from fametrano:bip327-portable-monotonic-clock changing 1 files +3 −4
  1. fametrano commented at 6:50 PM on September 7, 2026: contributor

    bip-0327/reference.py's self-test read time.clock_gettime_ns(time.CLOCK_MONOTONIC) for extra_in. Both symbols are documented "Availability: Unix" in CPython, so python3 reference.py raises AttributeError on Windows.

    Following real-or-random's suggestion, extra_in now comes from secrets, with a random length in 0..41, so the self-test also exercises variable-length extra_in. time has no other use in the file, so its import is dropped.

    Not tested on Windows; verified against CPython's platform-availability docs.

  2. murchandamus commented at 6:14 PM on September 9, 2026: member

    I’m a bit on the fence regarding maintenance updates to the reference implementations, as this repository is not intended to maintain living code, but allows attaching reference implementations to illustrate how features could be implemented. From the linked report, it sounds like this is fixes a crash, though.

    Since Python 3.7 has been out since 2018, this seems low-risk and benign, so SGTM. Will wait for a few days to see if the owners have an opinion. cc: @jonasnick, @real-or-random, @robot-dreams

  3. murchandamus added the label Fixups on Sep 9, 2026
  4. in bip-0327/reference.py:843 in fc9a1bce34
     838 | @@ -839,7 +839,7 @@ def test_sign_and_verify_random(iters: int) -> None:
     839 |          # otherwise use deterministic signing algorithm
     840 |          if i % 2 == 0:
     841 |              # Use a clock for extra_in
     842 | -            t = time.clock_gettime_ns(time.CLOCK_MONOTONIC)
     843 | +            t = time.monotonic_ns()
     844 |              secnonce_2, pubnonce_2 = nonce_gen(sk_2, pk_2, aggpk, msg, t.to_bytes(8, 'big'))
    


    real-or-random commented at 6:55 AM on September 10, 2026:
                extra_in = secrets.token_bytes(secrets.randbelow(42))
                secnonce_2, pubnonce_2 = nonce_gen(sk_2, pk_2, aggpk, msg, extra_in)
    

    fametrano commented at 2:08 PM on September 10, 2026:

    Applied as suggested (4f9567f): extra_in now comes from secrets with a random length, so the test also covers variable-length extra_in. That line was the only use of time in the file, so I dropped the import; if you would rather keep it, say so and I will put it back. Title and commit message updated accordingly.

  5. real-or-random commented at 6:57 AM on September 10, 2026: contributor

    Yeah, this is an improvement, but let's just not remove import time entirely..

  6. bip-0327: derive extra_in from secrets in the reference self-test
    The self-test reads time.clock_gettime_ns(time.CLOCK_MONOTONIC) for
    extra_in on even iterations. CPython documents both symbols
    "Availability: Unix", so the attribute lookup raises AttributeError on
    Windows and python3 reference.py does not run there.
    
    Take extra_in from secrets instead, at a random length, so the self-test
    also exercises extra_in of varying length. time has no other use in the
    file, so its import goes too.
    4f9567fd60
  7. fametrano force-pushed on Sep 10, 2026
  8. fametrano renamed this:
    bip-0327: use a portable monotonic clock in the reference self-test
    bip-0327: derive extra_in from secrets in the reference self-test
    on Sep 10, 2026
  9. real-or-random approved
  10. real-or-random commented at 2:35 PM on September 10, 2026: contributor

    utACK 4f9567fd60021cb7dea032250ab241cd68d9ff91

  11. murchandamus commented at 3:24 PM on September 10, 2026: member
  12. murchandamus merged this on Sep 10, 2026
  13. murchandamus closed this on Sep 10, 2026


github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bips. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-09-29 05:10 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me