musig: test nonce_gen_counter with random counters #1947

pull ViniciusCestarii wants to merge 1 commits into bitcoin-core:master from ViniciusCestarii:musig-test-nonce-gen-counter changing 1 files +24 −0
  1. ViniciusCestarii commented at 1:45 PM on September 28, 2026: none

    The only output check of nonce_gen_counter uses nonrepeating_cnt = 0, so the following mutant replacing secp256k1_write_be64 with secp256k1_write_be32 (which could enable nonce reuse) survived because zero serializes the same either way.

    diff --git a/src/modules/musig/session_impl.h b/src/modules/musig/session_impl.h
    index d8a3cca..710c4c5 100644
    --- a/src/modules/musig/session_impl.h
    +++ b/src/modules/musig/session_impl.h
    @@ -447,7 +447,7 @@ int secp256k1_musig_nonce_gen_counter(const secp256k1_context* ctx, secp256k1_mu
         memset(secnonce, 0, sizeof(*secnonce));
         ARG_CHECK(keypair != NULL);
     
    -    secp256k1_write_be64(buf, nonrepeating_cnt);
    +    secp256k1_write_be32(buf, nonrepeating_cnt);
         /* keypair_sec and keypair_pub do not fail if the arguments are not NULL */
         ret = secp256k1_keypair_sec(ctx, seckey, keypair);
         VERIFY_CHECK(ret);
    

    This add a new test, which checks that for random 64-bit counters, nonce_gen_counter gives the same nonce as nonce_gen.

  2. musig: test nonce_gen_counter with random counters b819a790f0
  3. real-or-random requested review from Copilot on Sep 29, 2026
  4. real-or-random added the label assurance on Sep 29, 2026
  5. real-or-random added the label tweak/refactor on Sep 29, 2026
  6. real-or-random approved
  7. real-or-random commented at 7:40 AM on September 29, 2026: contributor

    utACK b819a790f06122d5a53c0320e79c0dc486349fbd

  8. ?
    copilot_work_started real-or-random
  9. Copilot commented at 7:41 AM on September 29, 2026: none

    <!-- ccr-overview-v2 -->

    Copilot review overview

    🟢 Approval recommended

    The focused test correctly detects incorrect counter serialization with no unresolved issues.

    Review effort: Balanced
    Findings: None

    <details> <summary><strong>What changed in this PR</strong></summary>

    Adds regression coverage ensuring MuSig counter-based nonce generation uses the complete 64-bit counter representation.

    Changes:

    • Compares nonce_gen_counter against equivalent nonce_gen calls using random counters.
    • Registers the new test.
    File Description
    src/​modules/​musig/​tests_impl.h Adds and registers counter serialization regression coverage.

    </details>


    💡 <a href="/bitcoin-core/secp256k1/new/master?filename=.github/skills/code-review/SKILL.md" class="Link--inTextBlock" target="_blank" rel="noopener noreferrer">Add a code-review agent skill</a> or configure MCP servers for context-aware, tailored reviews. <a href="https://docs.github.com/copilot/how-tos/use-copilot-agents/request-a-code-review/use-code-review?tool=webui#mcp-servers-and-agent-skills" class="Link--inTextBlock" target="_blank" rel="noopener noreferrer">Learn more in the docs.</a>

  10. real-or-random merged this on Sep 29, 2026
  11. real-or-random closed this on Sep 29, 2026


github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin-core/secp256k1. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-10-03 03:15 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me