Skip to content

[Breaking] Local expand_message_xmd with RFC 9380 padding - #109

Merged
davxy merged 7 commits into
mainfrom
local-xmd-hasher
Sep 26, 2026
Merged

davxy merged 7 commits into
mainfrom
local-xmd-hasher

Conversation

@davxy

@davxy davxy commented Sep 26, 2026

Copy link
Copy Markdown
Owner

Arkworks 0.6 DefaultFieldHasher pads expand_message_xmd with the field element length (48 bytes on Bandersnatch) where RFC 9380 section 5.3.1 requires the hash block size (128 bytes for SHA-512).

  • hash_to_curve_ell2_xmd runs a local XmdFieldHasher with the RFC padding, so an arkworks update cannot change the output. H needs BlockSizeUser. The SEC_PARAM const generic is gone.
  • BandersnatchSha512Ell2: new BLINDING_BASE, ACCUMULATOR_BASE, PADDING and vectors. SUITE_ID is unchanged.
  • Tests: RFC 9380 J.1.1 (P-256) vectors for the RFC padding, and a comparison with DefaultFieldHasher for the old padding. The second fails when arkworks releases the fix.

Proposed upstream fix: arkworks-rs/algebra#1140.

@davxy
davxy merged commit fdcacaa into main Sep 26, 2026
20 checks passed
@davxy
davxy deleted the local-xmd-hasher branch September 26, 2026 10:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant