Skip to content

Commit 29391e4

Browse files
authored
ctutils: make Choice::{to_bool, to_u8} into const fn; MSRV 1.86 (#1547)
We have a stable release for MSRV 1.85 users of that version can rely on, and 1.86 was released nearly a year and half ago. We've also received reports of codegen problems in `const fn`s that can only be addressed this way.
1 parent f09945d commit 29391e4

5 files changed

Lines changed: 17 additions & 21 deletions

File tree

‎.github/workflows/ctutils.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ jobs:
3333
strategy:
3434
matrix:
3535
rust:
36-
- 1.85.0 # MSRV
36+
- 1.86.0 # MSRV
3737
- stable
3838
target:
3939
- thumbv7em-none-eabi
@@ -58,7 +58,7 @@ jobs:
5858
strategy:
5959
matrix:
6060
rust:
61-
- 1.85.0 # MSRV
61+
- 1.86.0 # MSRV
6262
- stable
6363
steps:
6464
- uses: actions/checkout@v7

‎ctutils/Cargo.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ categories = ["cryptography", "no-std"]
1414
keywords = ["constant-time", "crypto", "intrinsics"]
1515
readme = "README.md"
1616
edition = "2024"
17-
rust-version = "1.85"
17+
rust-version = "1.86"
1818

1919
[dependencies]
2020
cmov = "0.5.3"

‎ctutils/README.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -79,7 +79,7 @@ dual licensed as above, without any additional terms or conditions.
7979
[docs-image]: https://docs.rs/ctutils/badge.svg
8080
[docs-link]: https://docs.rs/ctutils/
8181
[license-image]: https://img.shields.io/badge/license-Apache2.0/MIT-blue.svg
82-
[msrv-image]: https://img.shields.io/badge/rustc-1.85+-blue.svg
82+
[msrv-image]: https://img.shields.io/badge/rustc-1.86+-blue.svg
8383
[build-image]: https://github.com/RustCrypto/utils/actions/workflows/ctutils.yml/badge.svg
8484
[build-link]: https://github.com/RustCrypto/utils/actions/workflows/ctutils.yml
8585
[chat-image]: https://img.shields.io/badge/zulip-join_chat-blue.svg

‎ctutils/src/choice.rs‎

Lines changed: 10 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -386,44 +386,42 @@ impl Choice {
386386
/// the small amount of timing variability it introduces can potentially be exploited. Whenever
387387
/// possible, prefer fully constant-time approaches instead.
388388
/// </div>
389-
// TODO(tarcieri): `const fn` when MSRV 1.86
390389
#[must_use]
391-
pub fn to_bool(self) -> bool {
390+
pub const fn to_bool(self) -> bool {
392391
self.to_u8() != 0
393392
}
394393

395394
/// Convert [`Choice`] to a `u8`, attempting to apply a "best effort" optimization barrier.
396-
// TODO(tarcieri): `const fn` when MSRV 1.86
397395
#[must_use]
398-
pub fn to_u8(self) -> u8 {
396+
pub const fn to_u8(self) -> u8 {
399397
// `black_box` is documented as working on a "best effort" basis. That's fine, this type is
400398
// likewise documented as only working on a "best effort" basis itself. The only way we
401399
// rely on `black_box` for correctness is it behaving as the identity function.
402400
core::hint::black_box(self.0)
403401
}
404402

405-
/// HACK: workaround to allow `const fn` boolean support on Rust 1.85.
403+
/// DEPRECATED: previously a workaround to allow `const fn` boolean support on Rust 1.85.
406404
///
407-
/// This does not apply `black_box` to the output.
405+
/// Use [`Choice::to_bool`] instead.
408406
///
409407
/// <div class = "warning">
410408
/// <b>Security Warning</b>
411409
///
412410
/// See the security warnings for [`Choice::to_bool`].
413411
/// </div>
414-
// TODO(tarcieri): deprecate/remove this in favor of `to_bool` when MSRV is Rust 1.86
412+
#[deprecated(since = "0.4.3", note = "use `Choice::to_bool` instead")]
415413
#[must_use]
416414
pub const fn to_bool_vartime(self) -> bool {
417-
self.0 != 0
415+
self.to_bool()
418416
}
419417

420-
/// HACK: workaround to allow `const fn` boolean support on Rust 1.85.
418+
/// DEPRECATED: previously a workaround to allow `const fn` boolean support on Rust 1.85.
421419
///
422-
/// This does not apply `black_box` to the output.
423-
// TODO(tarcieri): deprecate/remove this in favor of `to_u8` when MSRV is Rust 1.86
420+
/// Use [`Choice::to_u8`] instead.
421+
#[deprecated(since = "0.4.3", note = "use `Choice::to_u8` instead")]
424422
#[must_use]
425423
pub const fn to_u8_vartime(self) -> u8 {
426-
self.0
424+
self.to_u8()
427425
}
428426

429427
/// Create a `u8` bitmask.

‎ctutils/src/ct_option.rs‎

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -158,8 +158,7 @@ impl<T> CtOption<T> {
158158
#[must_use]
159159
#[track_caller]
160160
pub const fn expect_ref(&self, msg: &str) -> &T {
161-
// TODO(tarcieri): use `self.is_some().to_bool()` when MSRV is 1.86
162-
assert!(self.is_some.to_bool_vartime(), "{}", msg);
161+
assert!(self.is_some.to_bool(), "{}", msg);
163162
self.as_inner_unchecked()
164163
}
165164

@@ -222,8 +221,7 @@ impl<T> CtOption<T> {
222221
where
223222
T: Copy,
224223
{
225-
// TODO(tarcieri): use `self.is_some().to_bool()` when MSRV is 1.86
226-
if self.is_some.to_bool_vartime() {
224+
if self.is_some.to_bool() {
227225
Some(self.value)
228226
} else {
229227
None
@@ -693,7 +691,7 @@ mod tests {
693691
// Don't actually use this! It's just a test function implemented in variable-time
694692
#[allow(clippy::trivially_copy_pass_by_ref)]
695693
const fn select_vartime(a: &u8, b: &u8, choice: Choice) -> u8 {
696-
if choice.to_bool_vartime() { *b } else { *a }
694+
if choice.to_bool() { *b } else { *a }
697695
}
698696

699697
assert_eq!(

0 commit comments

Comments
 (0)