precompiles: withdraw the uncitable 'audited' adjective from the patch and the published sources (O-006, D-376)

This commit is contained in:
Aere Network 2026-09-11 21:33:52 +03:00
parent ba7f09d46d
commit 50bf1a07ca
3 changed files with 21 additions and 6 deletions

View File

@ -47,6 +47,15 @@ Regenerated 2026-09-10 from the production tree over the same file set, so that
the public recipe carries the same Apache-2.0 section 4(b) modification notices the public recipe carries the same Apache-2.0 section 4(b) modification notices
that the production sources carry; measured the same day: a build from this that the production sources carry; measured the same day: a build from this
recipe reproduces the fleet's consensus jars class for class. recipe reproduces the fleet's consensus jars class for class.
Corrected 2026-09-11, comments only. This patch still called Bouncy Castle
"audited" in three places after that adjective had already been removed from the
production sources and from the copies published beside it, because nothing
compared the patch with the sources it is generated from. We cannot cite an audit
of bcprov-jdk18on: it is not a FIPS validated module and we know of no published
third-party review of it. What is citable is byte-for-byte agreement with the NIST
KAT and ACVP vectors in both directions, and that is what the comments now say.
No code changed; the wording did.
--- ---
diff --git a/datatypes/src/main/java/org/hyperledger/besu/datatypes/Address.java b/datatypes/src/main/java/org/hyperledger/besu/datatypes/Address.java diff --git a/datatypes/src/main/java/org/hyperledger/besu/datatypes/Address.java b/datatypes/src/main/java/org/hyperledger/besu/datatypes/Address.java
index 950cd59e3..3a63362d7 100644 index 950cd59e3..3a63362d7 100644
@ -182,7 +191,7 @@ index 000000000..1dbb2b85c
+ * Shared logic for the AERE Falcon-512 / Falcon-1024 verification precompiles. + * Shared logic for the AERE Falcon-512 / Falcon-1024 verification precompiles.
+ * + *
+ * <p>Transcodes the NIST round-3 reference "signed message" (sm) blob into the encoding Bouncy + * <p>Transcodes the NIST round-3 reference "signed message" (sm) blob into the encoding Bouncy
+ * Castle's {@link FalconSigner#verifySignature(byte[], byte[])} expects and drives the audited + * Castle's {@link FalconSigner#verifySignature(byte[], byte[])} expects and drives that
+ * verifier. No cryptography is reimplemented here. + * verifier. No cryptography is reimplemented here.
+ * + *
+ * <p>NIST sm layout: {@code sigLen(2, big-endian) || nonce(40) || message || esig} where + * <p>NIST sm layout: {@code sigLen(2, big-endian) || nonce(40) || message || esig} where
@ -544,7 +553,7 @@ index 28d84abf1..554a1e111 100644
+ // Activated on a running chain via genesis config "futureEipsTime"; no re-genesis needed. + // Activated on a running chain via genesis config "futureEipsTime"; no re-genesis needed.
+ populateForOsaka(registry, gasCalculator); + populateForOsaka(registry, gasCalculator);
+ +
+ // Native post-quantum precompiles (audited Bouncy Castle BCPQC verifiers). + // Native post-quantum precompiles (Bouncy Castle BCPQC verifiers).
+ registry.put(Address.AERE_FALCON512, new Falcon512PrecompiledContract(gasCalculator)); + registry.put(Address.AERE_FALCON512, new Falcon512PrecompiledContract(gasCalculator));
+ registry.put(Address.AERE_FALCON1024, new Falcon1024PrecompiledContract(gasCalculator)); + registry.put(Address.AERE_FALCON1024, new Falcon1024PrecompiledContract(gasCalculator));
+ registry.put(Address.AERE_MLDSA44, new MLDSA44PrecompiledContract(gasCalculator)); + registry.put(Address.AERE_MLDSA44, new MLDSA44PrecompiledContract(gasCalculator));
@ -557,7 +566,7 @@ new file mode 100644
index 000000000..0c20e6a66 index 000000000..0c20e6a66
--- /dev/null --- /dev/null
+++ b/evm/src/main/java/org/hyperledger/besu/evm/precompile/SHAKE256PrecompiledContract.java +++ b/evm/src/main/java/org/hyperledger/besu/evm/precompile/SHAKE256PrecompiledContract.java
@@ -0,0 +1,93 @@ @@ -0,0 +1,96 @@
+/* +/*
+ * Copyright contributors to the AERE Network. + * Copyright contributors to the AERE Network.
+ * + *
@ -588,7 +597,10 @@ index 000000000..0c20e6a66
+ * Output: exactly {@code outLen} bytes of SHAKE256(data). + * Output: exactly {@code outLen} bytes of SHAKE256(data).
+ * + *
+ * <p>SHAKE256 is the hashing bottleneck inside Falcon, ML-DSA and SLH-DSA; exposing it natively lets + * <p>SHAKE256 is the hashing bottleneck inside Falcon, ML-DSA and SLH-DSA; exposing it natively lets
+ * on-chain PQC flows offload the hot path to audited Bouncy Castle rather than hand-rolled Solidity. + * on-chain PQC flows offload the hot path to Bouncy Castle rather than hand-rolled Solidity. The
+ * provider we ship, bcprov-jdk18on, is not a FIPS validated module and we know of no published
+ * third-party audit of it; what is citable is byte-for-byte agreement with the NIST KAT and ACVP
+ * vectors, in both directions. See AERE-NIST-VALIDATION-STATUS.md section 3.4.
+ */ + */
+public class SHAKE256PrecompiledContract extends AbstractPrecompiledContract { +public class SHAKE256PrecompiledContract extends AbstractPrecompiledContract {
+ +

View File

@ -26,7 +26,7 @@ import org.bouncycastle.pqc.crypto.falcon.FalconSigner;
* Shared logic for the AERE Falcon-512 / Falcon-1024 verification precompiles. * Shared logic for the AERE Falcon-512 / Falcon-1024 verification precompiles.
* *
* <p>Transcodes the NIST round-3 reference "signed message" (sm) blob into the encoding Bouncy * <p>Transcodes the NIST round-3 reference "signed message" (sm) blob into the encoding Bouncy
* Castle's {@link FalconSigner#verifySignature(byte[], byte[])} expects and drives the audited * Castle's {@link FalconSigner#verifySignature(byte[], byte[])} expects and drives that
* verifier. No cryptography is reimplemented here. * verifier. No cryptography is reimplemented here.
* *
* <p>NIST sm layout: {@code sigLen(2, big-endian) || nonce(40) || message || esig} where * <p>NIST sm layout: {@code sigLen(2, big-endian) || nonce(40) || message || esig} where

View File

@ -28,7 +28,10 @@ import org.bouncycastle.crypto.digests.SHAKEDigest;
* Output: exactly {@code outLen} bytes of SHAKE256(data). * Output: exactly {@code outLen} bytes of SHAKE256(data).
* *
* <p>SHAKE256 is the hashing bottleneck inside Falcon, ML-DSA and SLH-DSA; exposing it natively lets * <p>SHAKE256 is the hashing bottleneck inside Falcon, ML-DSA and SLH-DSA; exposing it natively lets
* on-chain PQC flows offload the hot path to Bouncy Castle (well-exercised, but not FIPS-validated and with no published third-party audit known) rather than hand-rolled Solidity. * on-chain PQC flows offload the hot path to Bouncy Castle rather than hand-rolled Solidity. The
* provider we ship, bcprov-jdk18on, is not a FIPS validated module and we know of no published
* third-party audit of it; what is citable is byte-for-byte agreement with the NIST KAT and ACVP
* vectors, in both directions. See AERE-NIST-VALIDATION-STATUS.md section 3.4.
*/ */
public class SHAKE256PrecompiledContract extends AbstractPrecompiledContract { public class SHAKE256PrecompiledContract extends AbstractPrecompiledContract {