2802 Commits

Author SHA1 Message Date
merge-script afff8cba00 Merge bitcoin-core/secp256k1#1894: extrakeys: check invariant that x-only pubkeys have even Y
89a54b5aaf extrakeys: check invariant that x-only pubkeys have even Y (Sebastian Falbesoner)

Pull request description:

  A violation of this invariant has been found by reviewers of the silentpayments module (kudos to w0xlt and andrewtoth, see https://github.com/bitcoin-core/secp256k1/pull/1765#discussion_r3229620362, https://github.com/bitcoin-core/secp256k1/pull/1765#discussion_r3238616034). Closes #1892.

ACKs for top commit:
  real-or-random:
    utACK 89a54b5aaf
  andrewtoth:
    ACK 89a54b5aaf

Tree-SHA512: d19381a2979c5c7777ab56d8f525073068f82c1db81b40b5c2202ad87604853ff243093e5b7aeebe7b33974eb88fb9d1d8e8d5e68f4165476849681ebddce97e
2026-07-21 09:15:45 +02:00
Sebastian Falbesoner 89a54b5aaf extrakeys: check invariant that x-only pubkeys have even Y 2026-07-20 13:37:40 +02:00
merge-script 8c3e6e6d99 Merge bitcoin-core/secp256k1#1889: field: serialize elements by word
e217ead5c4 field: serialize elements by word (Lőrinc)

Pull request description:

  **Problem:** Both field implementations serialize normalized elements with 32 separate byte assignments in `secp256k1_fe_impl_get_b32`.
  They were introduced in [#437](https://github.com/bitcoin-core/secp256k1/pull/437/changes#diff-6e0cae0111d7c054ba27f22399eb4a2ac6c9788ee97da7f9fc5948c63dcf882cL353) to unroll nested nibble loops for performance.
  At the time, the endian write helpers did not exist, so the unrolling was expressed directly.

  **Fix:** Keep both serializers unrolled by packing the 5x52 limbs into four 64-bit words and the 10x26 limbs into eight 32-bit words, then reuse the corresponding endian write helper.
  This matches the existing [4x64](https://github.com/bitcoin-core/secp256k1/blob/ebf594320dc838b9de1abb54d5ba98cef84f4297/src/scalar_4x64_impl.h#L161-L168) and [8x32](https://github.com/bitcoin-core/secp256k1/blob/ebf594320dc838b9de1abb54d5ba98cef84f4297/src/scalar_8x32_impl.h#L195-L206) scalar serializers.
  The serialized output is unchanged for normalized inputs, and benchmarks indicate no measurable performance regression.

  **Testing:** Existing [field conversion and reduced-boundary tests](https://github.com/bitcoin-core/secp256k1/blob/ebf594320dc838b9de1abb54d5ba98cef84f4297/src/tests.c#L3079-L3173) compare the serialized bytes directly.
  [Compiler Explorer](https://godbolt.org/z/nxaKecdxh) compares the exact before and after serializers with GCC 16.1 and Clang 22.1 at `-O2`, in both native and `-m32` modes.

  <details><summary>Benchmarks</summary>

  ```bash
  for cc in gcc clang; do \
    echo; $cc --version | head -1; \
    CC=$cc cmake -B build-$cc -GNinja -DCMAKE_BUILD_TYPE=Release >/dev/null 2>&1 && \
    CC=$cc cmake -B build-$cc-10x26 -GNinja -DCMAKE_BUILD_TYPE=Release -DSECP256K1_TEST_OVERRIDE_WIDE_MULTIPLY=int64 >/dev/null 2>&1 && \
    for build in build-$cc build-$cc-10x26; do \
      echo; echo $build; \
      for rev in ebf594320d e217ead5c46062ecda964ba858f7518b7e3bb5e7; do \
        git fetch origin -q $rev && git checkout -q $rev && \
        ninja -C $build bench >/dev/null 2>&1 && \
        echo $rev && \
        SECP256K1_BENCH_ITERS=10000 $build/bin/bench; \
      done; \
    done; \
  done
  ```

  ```bash
  gcc (Ubuntu 15.2.0-16ubuntu1) 15.2.0

  build-gcc
  ebf594320d
  Benchmark                     ,    Min(us)    ,    Avg(us)    ,    Max(us)

  ecdsa_verify                  ,    33.9       ,    34.0       ,    34.0
  ecdsa_sign                    ,    21.6       ,    21.6       ,    21.6
  ec_keygen                     ,    15.2       ,    15.2       ,    15.3
  ecdh                          ,    33.4       ,    33.5       ,    33.5
  schnorrsig_sign               ,    16.1       ,    16.1       ,    16.2
  schnorrsig_verify             ,    34.3       ,    34.3       ,    34.4
  ellswift_encode               ,    16.2       ,    16.2       ,    16.2
  ellswift_decode               ,     7.21      ,     7.22      ,     7.24
  ellswift_keygen               ,    31.5       ,    31.5       ,    31.5
  ellswift_ecdh                 ,    36.0       ,    36.1       ,    36.1
  e217ead5c4
  Benchmark                     ,    Min(us)    ,    Avg(us)    ,    Max(us)

  ecdsa_verify                  ,    34.0       ,    34.1       ,    34.4
  ecdsa_sign                    ,    21.6       ,    21.6       ,    21.6
  ec_keygen                     ,    15.3       ,    15.3       ,    15.3
  ecdh                          ,    33.3       ,    33.4       ,    33.6
  schnorrsig_sign               ,    16.1       ,    16.1       ,    16.2
  schnorrsig_verify             ,    34.4       ,    34.4       ,    34.5
  ellswift_encode               ,    16.3       ,    16.3       ,    16.3
  ellswift_decode               ,     7.24      ,     7.24      ,     7.25
  ellswift_keygen               ,    31.5       ,    31.6       ,    31.7
  ellswift_ecdh                 ,    36.0       ,    36.1       ,    36.1

  build-gcc-10x26
  ebf594320d
  Benchmark                     ,    Min(us)    ,    Avg(us)    ,    Max(us)

  ecdsa_verify                  ,    58.4       ,    58.5       ,    58.5
  ecdsa_sign                    ,    29.7       ,    29.8       ,    29.8
  ec_keygen                     ,    22.3       ,    22.4       ,    22.5
  ecdh                          ,    56.0       ,    56.1       ,    56.2
  schnorrsig_sign               ,    23.4       ,    23.4       ,    23.5
  schnorrsig_verify             ,    58.9       ,    59.0       ,    59.1
  ellswift_encode               ,    22.7       ,    22.7       ,    22.7
  ellswift_decode               ,    10.8       ,    10.8       ,    10.8
  ellswift_keygen               ,    45.1       ,    45.2       ,    45.3
  ellswift_ecdh                 ,    59.6       ,    59.7       ,    59.8
  e217ead5c4
  Benchmark                     ,    Min(us)    ,    Avg(us)    ,    Max(us)

  ecdsa_verify                  ,    58.5       ,    58.6       ,    58.7
  ecdsa_sign                    ,    29.8       ,    29.8       ,    29.9
  ec_keygen                     ,    22.3       ,    22.4       ,    22.4
  ecdh                          ,    56.0       ,    56.1       ,    56.4
  schnorrsig_sign               ,    23.5       ,    23.5       ,    23.5
  schnorrsig_verify             ,    58.9       ,    59.0       ,    59.1
  ellswift_encode               ,    22.9       ,    22.9       ,    22.9
  ellswift_decode               ,    10.8       ,    10.8       ,    10.8
  ellswift_keygen               ,    45.2       ,    45.3       ,    45.4
  ellswift_ecdh                 ,    59.6       ,    59.8       ,    59.9

  Ubuntu clang version 21.1.8 (6ubuntu1)

  build-clang
  ebf594320d
  Benchmark                     ,    Min(us)    ,    Avg(us)    ,    Max(us)

  ecdsa_verify                  ,    36.2       ,    36.3       ,    36.7
  ecdsa_sign                    ,    23.1       ,    23.1       ,    23.2
  ec_keygen                     ,    16.6       ,    16.7       ,    16.7
  ecdh                          ,    35.6       ,    35.7       ,    35.7
  schnorrsig_sign               ,    17.6       ,    17.6       ,    17.6
  schnorrsig_verify             ,    36.6       ,    36.7       ,    36.9
  ellswift_encode               ,    16.6       ,    16.6       ,    16.7
  ellswift_decode               ,     7.28      ,     7.29      ,     7.30
  ellswift_keygen               ,    33.2       ,    33.2       ,    33.3
  ellswift_ecdh                 ,    38.5       ,    38.5       ,    38.6
  e217ead5c4
  Benchmark                     ,    Min(us)    ,    Avg(us)    ,    Max(us)

  ecdsa_verify                  ,    35.5       ,    35.6       ,    35.8
  ecdsa_sign                    ,    23.0       ,    23.1       ,    23.2
  ec_keygen                     ,    16.6       ,    16.7       ,    16.8
  ecdh                          ,    35.7       ,    35.7       ,    35.8
  schnorrsig_sign               ,    17.6       ,    17.6       ,    17.7
  schnorrsig_verify             ,    35.9       ,    35.9       ,    36.0
  ellswift_encode               ,    16.4       ,    16.4       ,    16.4
  ellswift_decode               ,     7.22      ,     7.22      ,     7.23
  ellswift_keygen               ,    33.0       ,    33.0       ,    33.1
  ellswift_ecdh                 ,    38.5       ,    38.6       ,    38.8

  build-clang-10x26
  ebf594320d
  Benchmark                     ,    Min(us)    ,    Avg(us)    ,    Max(us)

  ecdsa_verify                  ,    64.2       ,    64.3       ,    64.7
  ecdsa_sign                    ,    33.8       ,    33.9       ,    33.9
  ec_keygen                     ,    26.3       ,    26.3       ,    26.3
  ecdh                          ,    63.4       ,    63.6       ,    63.8
  schnorrsig_sign               ,    27.2       ,    27.3       ,    27.3
  schnorrsig_verify             ,    64.5       ,    64.6       ,    64.7
  ellswift_encode               ,    22.1       ,    22.1       ,    22.1
  ellswift_decode               ,    10.6       ,    10.6       ,    10.7
  ellswift_keygen               ,    48.3       ,    48.3       ,    48.5
  ellswift_ecdh                 ,    67.0       ,    67.0       ,    67.1
  e217ead5c4
  Benchmark                     ,    Min(us)    ,    Avg(us)    ,    Max(us)

  ecdsa_verify                  ,    63.9       ,    64.0       ,    64.3
  ecdsa_sign                    ,    33.8       ,    33.9       ,    34.0
  ec_keygen                     ,    26.3       ,    26.3       ,    26.3
  ecdh                          ,    62.5       ,    62.5       ,    62.6
  schnorrsig_sign               ,    27.2       ,    27.3       ,    27.4
  schnorrsig_verify             ,    64.1       ,    64.2       ,    64.2
  ellswift_encode               ,    22.1       ,    22.2       ,    22.3
  ellswift_decode               ,    10.6       ,    10.7       ,    10.7
  ellswift_keygen               ,    48.4       ,    48.4       ,    48.6
  ellswift_ecdh                 ,    66.2       ,    66.3       ,    66.4
  ```
  </details>

ACKs for top commit:
  real-or-random:
    utACK e217ead5c4
  theStack:
    ACK e217ead5c4

Tree-SHA512: 9a92a8d8682e5fd1ac40cab097770741fb78fc6de7c54edf24bd0796bc06b1ec1c375c996099fdaf228a56788208faa6aae107a53b15d596d19f047a5f1a30e6
2026-07-18 00:46:21 +02:00
merge-script 11dad6d06c Merge bitcoin-core/secp256k1#1887: Make theStack a maintainer and a security contact
d5c64bafc7 SECURITY.md: Align the table (Tim Ruffing)
9bd50f0cef SECURITY.md: Add theStack's key (Tim Ruffing)

Pull request description:

  @sipa, @jonasnick and I [proposed in a recent Bitcoin Core dev meeting](https://achow101.com/ircmeetings/2026/bitcoin-core-dev.2026-06-25_16_00.log.html#f6c02cf2aae64685af41255b948d8eb5) to add @theStack as a maintainer of libsecp256k1. The purpose of this PR is to seek (N)ACKs for the maintainer change and for adding his public key fingerprint to SECURITY.md.

ACKs for top commit:
  fjahr:
    ACK d5c64bafc7
  stratospher:
    ACK d5c64ba. matches the one in [Stack's gist](https://gist.github.com/theStack/60ed7ccc7c0caffeef2d001b8b54148b).
  fanquake:
    ACK d5c64bafc7
  furszy:
    All good now, ACK d5c64bafc7
  jonasnick:
    ACK d5c64bafc7
  hebasto:
    ACK d5c64bafc7, I've verified @theStack's key.
  theStack:
    ACK d5c64bafc7
  sipa:
    ACK d5c64bafc7

Tree-SHA512: c4140eaf17443f06861c86c6e91563f7e4810a885615f1606fb3e0476f12be27e151f76be9372d723b4720b7145f3e5c6eb6b7967cb94a0b0885c444cdd85c73
2026-07-16 17:34:50 +02:00
Lőrinc e217ead5c4 field: serialize elements by word
The byte assignments replaced nested nibble loops before the endian write helpers existed.
Pack the 5x52 limbs into four 64-bit words and the 10x26 limbs into eight 32-bit words, then use those helpers.
This matches the scalar serializers and keeps the output unchanged.
Benchmarks indicate no measurable performance regression.
2026-07-13 00:10:38 -07:00
Tim Ruffing d5c64bafc7 SECURITY.md: Align the table 2026-07-09 22:26:11 +02:00
Tim Ruffing 9bd50f0cef SECURITY.md: Add theStack's key 2026-07-09 22:22:11 +02:00
merge-script ebf594320d Merge bitcoin-core/secp256k1#1884: SECURITY.md: remove Jonas Nick from trusted keys
21645c03a2 SECURITY.md: remove Jonas Nick from trusted keys (Jonas Nick)

Pull request description:

  As announced in `#bitcoin-core-dev` IRC, I’m stepping down as a libsecp256k1 maintainer because I’m no longer able to dedicate the time and attention that the project deserves. This PR removes me from the contact list in `SECURITY.md`.

ACKs for top commit:
  real-or-random:
    ACK 21645c03a2 🫡
  theStack:
    ACK 21645c03a2 🫡
  furszy:
    ACK 21645c03a2 🫡

Tree-SHA512: c7d5fc32476e377766e9f4c07f78a4d8389b213f319070810456879996c6b3ac25949ae65a500f79b9108c3fb52b53a735842b438438349a3f5e2d3df1ba0e1e
2026-06-30 08:35:53 +02:00
Jonas Nick 21645c03a2 SECURITY.md: remove Jonas Nick from trusted keys 2026-06-29 07:06:10 +00:00
merge-script b90075a074 Merge bitcoin-core/secp256k1#1882: scalar: correct _scalar_get_bits_{limb32,var} input condition docs
6a599a4428 scalar: correct `_scalar_get_bits_{limb32,var}` input condition docs (Sebastian Falbesoner)

Pull request description:

  This PR is a small correction of documented (off-by-one) input conditions for the `scalar_get_bits_{limb32,var}`, that came up during reviewing #1845.

ACKs for top commit:
  real-or-random:
    ACK 6a599a4428

Tree-SHA512: 2f0982b6d69d2abeebe0c9d82161e85feaae317d1e3ac2f415338044c8725a0442e14d998053e62f1b5f59f785a31796b5b3c4b36d9eb516ff53e9bb11429e78
2026-06-26 08:40:47 +02:00
merge-script 5a8a411425 Merge bitcoin-core/secp256k1#1877: field: correct fe_equal magnitude bound for b
994b35010d field: correct fe_equal's b magnitude bound (Lőrinc)

Pull request description:

  **Problem:** While reviewing this area with Fable, I noticed that `secp256k1_fe_equal(a, b)` documented `b` up to magnitude 31.
  Review pointed out that the implementation negates `a` before adding `b`, so the actual internal bound is 30.

  **Fix:** Lower the documented and checked bound to 30.
  This keeps `fe_equal` unchanged at runtime and matches current callers, which use much smaller magnitudes.

  **Test:** Add a focused test with random field elements whose magnitudes are randomized within the accepted `a <= 1` and `b <= 30` bounds.

ACKs for top commit:
  theStack:
    ACK 994b35010d
  real-or-random:
    utACK 994b35010d

Tree-SHA512: 034b90b4020c65fcb335ab361341424e08355f64deefaf153d94b05304e68760c9f771e4bc3e0fd664aee164d7e9f5f533d001f21207ef968c52f67d2c23a74a
2026-06-26 08:38:37 +02:00
Sebastian Falbesoner 6a599a4428 scalar: correct _scalar_get_bits_{limb32,var} input condition docs 2026-06-26 03:04:13 +02:00
Lőrinc 994b35010d field: correct fe_equal's b magnitude bound
`secp256k1_fe_equal` negates `a` before adding `b`.
That gives the temporary value magnitude 2, and the following field addition requires the input magnitudes to sum to at most 32.
So the largest `b` magnitude the implementation can accept is 30, not 31.

Lower the documented and checked bound for `b` to 30.
Adjust the focused test to use random field elements with randomized magnitudes within the accepted `a <= 1` and `b <= 30` bounds.

Co-authored-by: Sebastian Falbesoner <sebastian.falbesoner@gmail.com>
Co-authored-by: Tim Ruffing <me@real-or-random.org>
2026-06-25 09:23:38 -07:00
merge-script 2ce4f71dc5 Merge bitcoin-core/secp256k1#1845: Improve checks for scalar _get_bits methods
0cad3df503 Improve checks for scalar _get_bits methods (Peter.Dettman)

Pull request description:

  Improves the `VERIFY_CHECK`s in all `_scalar_get_bits_limb32` and `_scalar_get_bits_var` methods.

  The initial prompt was noticing that scalar_4x64_impl/`secp256k1_scalar_get_bits_limb32` was not restricting to 32-bit limbs correctly. Then missing range checks for `offset` were added and all such checks rewritten to avoid overflow.

  With these changes, the _low and _4x64 impls of `_get_bits_var` can no longer forward to `_get_bits_limb32`, so those calls were inlined instead.

ACKs for top commit:
  sipa:
    ACK 0cad3df503
  theStack:
    ACK 0cad3df503
  real-or-random:
    utACK 0cad3df503

Tree-SHA512: 753991d586fe5695dd33af6c261c5458ab659be94204626166503af7d403748abb76d791846857a16383cbd38a1f84af9fde74b4327d68d706f88b6531ee7546
2026-06-25 17:02:04 +02:00
merge-script 68b45fd4e2 Merge bitcoin-core/secp256k1#1881: tests: Fix GCC 17 snapshot warning
9d75769dec tests: Fix GCC 17 snapshot warning (Tim Ruffing)

Pull request description:

  Passing a non-malloc pointer to free() would be UB. In this case, the
  free() line is never actually reached (and GCC 17 fails to prove this)
  in a correct implementation of secp256k1_scratch_space_destroy(), but
  the test shouldn't rely on the correctness of the tested function.

  Alternative to #1880. I think this is cleaner
   - it doesn't recreate the scratch space in the middle of some other tests
   - it has an obvious matching (malloc, free) pair
   - it additionally checks that only `magic` is accessed

ACKs for top commit:
  hebasto:
    ACK 9d75769dec, I have reviewed the code and it looks OK.
  theStack:
    re-ACK 9d75769dec

Tree-SHA512: eb1a73c04e1996aeecabaa804e6a4fb1f5e6dfba4b9a775b6dd33d147be17185115a5aa9b7d9bf50260c20849e159d1b57f9ee41901d3d691dec25f2643b7cd2
2026-06-25 16:44:49 +02:00
Tim Ruffing 9d75769dec tests: Fix GCC 17 snapshot warning
Passing a non-malloc pointer to free() would be UB. In this case, the
free() line is never actually reached (and GCC 17 fails to prove this)
in a correct implementation of secp256k1_scratch_space_destroy(), but
the test shouldn't rely on the correctness of the tested function.
2026-06-25 14:57:56 +02:00
merge-script 9e3a165ad0 Merge bitcoin-core/secp256k1#1879: ci: add 'brew trust' invocation to macOS CI
66260b78a2 ci: add 'brew trust' invocation to macOS CI (fanquake)

Pull request description:

  This is probably needed to fix the issues in the macOS Valgrind jobs. i.e in #1877: https://github.com/bitcoin-core/secp256k1/actions/runs/28111568199/job/83240127830?pr=1877#step:4:199

  ```bash
  Cache restored from key: x86_64-macos-native-valgrind-6ebc928a1e40da9db2f283a1c4ac74cfcff9f06687481fd0396a7b4c26ecfb09
  Run brew link valgrind
  Error: Refusing to load formula louisbrunner/valgrind/valgrind from untrusted tap louisbrunner/valgrind.
  Run `brew trust --formula louisbrunner/valgrind/valgrind` or `brew trust louisbrunner/valgrind` to trust it.
  Error: Process completed with exit code 1.
  ```

ACKs for top commit:
  real-or-random:
    utACK 66260b78a2
  hebasto:
    ACK 66260b78a2.

Tree-SHA512: 447f7687d1cb2ed983f77efea509c7a5255e2436ee0260767b7f9faa71c2c81fca5bc24477761e36cf27c8afdd72acccbb7475371dc233f11cd35d1d1d78d268
2026-06-25 11:24:47 +02:00
fanquake 66260b78a2 ci: add 'brew trust' invocation to macOS CI
Should fix issues like:

> Error: Refusing to load formula louisbrunner/valgrind/valgrind from untrusted tap louisbrunner/valgrind.
> Run `brew trust --formula louisbrunner/valgrind/valgrind` or `brew trust louisbrunner/valgrind` to trust it.
> Error: Process completed with exit code 1.
2026-06-25 09:17:04 +01:00
merge-script bd0287d650 Merge bitcoin-core/secp256k1#1859: field: force-inline 5x52 mul and sqr
71fcd8410e field: force-inline 5x52 mul and sqr (Lőrinc)

Pull request description:

  **Problem:** The 5x52 field multiplication and squaring routines are hot in group arithmetic and scalar multiplication. Some compilers leave the thin wrappers and int128 inner helpers out of line, which keeps a call boundary in this hot path and limits scheduling of the 64x64->128 arithmetic.

  **Fix:** Define `SECP256K1_FORCE_INLINE` next to the existing inline helper and use it for the 5x52 multiplication and squaring wrappers and `int128` inner helpers.

  For default optimized builds, this expands to `__forceinline` on MSVC-compatible compilers and to `__attribute__((always_inline))` on GCC-compatible compilers. It falls back to the existing inline spelling when inlining is disabled, when optimization is disabled, when optimizing for size on GCC/Clang, or when `_DEBUG` is defined.

  **Benchmarks:** Values are relative changes in `Min(us)`, lower is better.

  | Source | Host / CPU | Compiler | ecdsa_verify | ecdh | schnorrsig_verify | field_sqr | field_mul |
  |---|---|---|---:|---:|---:|---:|---:|
  | local | M4-Max.local | gcc-14 14.3.0 | -9.1% | -9.0% | -9.6% | -7.0% | -4.0% |
  | local | i9-ssd | GCC 16.1.0 | -5.3% | -4.1% | -5.5% | -15.7% | -11.6% |
  | local | WIN-A2EHOAU4JET / Xeon E5-2637 v2 | MSVC 19.50.35728 | -2.6% | -9.3% | -2.4% | -7.4% | -7.4% |
  | local | i7-hdd | GCC 14.2.0 | -10.9% | -11.1% | -10.5% | -9.4% | -21.6% |
  | local | umbrel / Intel N150 | GCC 12.2.0 | -4.9% | -4.3% | -4.6% | +0.6% | -1.1% |
  | local | rpi5-16-3 | GCC 14.2.0 | -0.6% | -0.7% | -0.6% | -5.5% | -1.0% |
  | local | rpi4-2-1 | GCC 14.2.0 | -2.7% | -2.3% | -2.7% | -5.6% | -4.0% |
  | local | nodl / Cortex-A53 | GCC 11.4.0 | -3.3% | -7.6% | -5.7% | -9.9% | -1.8% |
  | andrewtoth | i9-14900HX | GCC 12.3 | -5.3% | -4.2% | -5.6% | -1.5% | -6.1% |
  | theStack | Snapdragon X Elite X1E-78-100 | GCC 14.2.0 | -11.2% | n/a | -11.1% | n/a | n/a |
  | sipa | Ryzen 5950X | GCC 15.2.0 | -11.4% | -10.4% | -8.4% | n/a | n/a |

  <img width="2534" height="1104" alt="image" src="https://github.com/user-attachments/assets/218a4075-5937-4850-ab8b-c6fc5d2fee57" />

  **Tradeoffs:** The speedups reproduce most consistently with GCC and MSVC. Clang was less consistently positive.

  Inlining also increases code size:
  | Platform | Artifact | Before | After | Delta |
  |---|---|---:|---:|---:|
  | macOS GCC | `libsecp256k1.a` | 1,254,320 | 1,311,368 | +57,048 (+4.55%) |
  | Linux GCC | `libsecp256k1.a` | 1,271,040 | 1,330,808 | +59,768 (+4.70%) |
  | Windows MSVC Release | `libsecp256k1-*.dll` | 1,239,040 | 1,414,144 | +175,104 (+14.13%) |

  ---

  <details><summary>Linux benchmarking script</summary>

  ```bash
  BEFORE=8363a2d8d1b47857c437f7cf22bd11ab06c7c50f; AFTER=33b1b9c455eb2bb07eded939b36abc49859d2ccf; CC=gcc; \
  API_ITERS=10000; INT_ITERS=200000; JOBS=1; \
  BH=$(git rev-parse --short=12 "$BEFORE") && AH=$(git rev-parse --short=12 "$AFTER") && \
  RUN=$(date +%Y%m%d%H%M%S) && \
  ROOT="$PWD/.bench-builds/gcc-$BH-$AH-$RUN" && \
  RAW="$PWD/.bench-results/secp-bench-gcc-$BH-$AH-$RUN.txt" && \
  (set -e; \
    mkdir -p "$ROOT" "$(dirname "$RAW")"; \
    printf "host: %s, compiler: %s\n" "$(hostname)" "$("$CC" --version | sed -n '1p')" | tee "$RAW" >&2; \
    old=$(git symbolic-ref --short -q HEAD || git rev-parse HEAD); \
    trap 'git switch -q "$old" 2>/dev/null || git switch -q --detach "$old"' EXIT; \
    for side in before after; do \
      ref=$([ "$side" = before ] && printf %s "$BEFORE" || printf %s "$AFTER"); \
      git cat-file -e "$ref^{commit}" 2>/dev/null || git fetch -q origin "$ref"; \
      h=$(git rev-parse --short=12 "$ref"); \
      b="$ROOT/$side-$h"; \
      echo "== $side $h ==" >&2; \
      git switch -q --detach "$ref"; \
      cmake -S . -B "$b" -DCMAKE_C_COMPILER="$CC" -DCMAKE_BUILD_TYPE=Release -DBUILD_SHARED_LIBS=OFF -DSECP256K1_BUILD_BENCHMARK=ON -DSECP256K1_BUILD_TESTS=OFF -DSECP256K1_BUILD_EXHAUSTIVE_TESTS=OFF -DSECP256K1_BUILD_CTIME_TESTS=OFF -DSECP256K1_BUILD_EXAMPLES=OFF -DSECP256K1_ENABLE_MODULE_MUSIG=OFF -DSECP256K1_VALGRIND=OFF >> "$RAW" 2>&1; \
      cmake --build "$b" -j "$JOBS" --target bench bench_internal >> "$RAW" 2>&1; \
      echo "=== $side $ref $h ===" >> "$RAW"; \
      SECP256K1_BENCH_ITERS=$API_ITERS "$b/bin/bench" ecdsa ec ecdh schnorrsig ellswift >> "$RAW"; \
      SECP256K1_BENCH_ITERS=$INT_ITERS "$b/bin/bench_internal" field group ecmult hash context >> "$RAW"; \
    done; \
    awk -F, '/^=== /{split($0,p," "); side=p[2]; next} /^[[:alnum:]_][[:alnum:]_]*[[:space:]]*,/{name=$1; val=$2+0; gsub(/^[[:space:]]+|[[:space:]]+$/,"",name); if(name!="Benchmark"){if(!(name in seen)){seen[name]=1; order[++n]=name} x[side,name]=val}} END{print "Benchmark\tBefore min(us)\tAfter min(us)\tDelta"; for(i=1;i<=n;i++){name=order[i]; b=x["before",name]; a=x["after",name]; if(b&&a) printf "%s\t%.6g\t%.6g\t%+.1f%%\n",name,b,a,100*(a-b)/b}}' "$RAW" | column -t -s $'\t'; \
    echo "raw: $RAW" >&2)
  ```
  </details>

  <details><summary>Linux size comparison script</summary>

  ```bash
  BEFORE=8363a2d8d1b47857c437f7cf22bd11ab06c7c50f; AFTER=33b1b9c455eb2bb07eded939b36abc49859d2ccf; CC=gcc; JOBS=1; \
  BH=$(git rev-parse --short=12 "$BEFORE"); AH=$(git rev-parse --short=12 "$AFTER"); RUN=$(date +%Y%m%d%H%M%S); ROOT="$PWD/.size-builds/gcc-$BH-$AH-$RUN"; \
  (set -e; old=$(git symbolic-ref --short -q HEAD || git rev-parse HEAD); trap 'git switch -q "$old" 2>/dev/null || git switch -q --detach "$old"' EXIT; \
  printf "host: %s, compiler: %s\n" "$(hostname)" "$("$CC" --version | sed -n '1p')"; \
  for side in before after; do \
    ref=$([ "$side" = before ] && printf %s "$BEFORE" || printf %s "$AFTER"); git cat-file -e "$ref^{commit}" 2>/dev/null || git fetch -q origin "$ref"; h=$(git rev-parse --short=12 "$ref"); b="$ROOT/$side-$h"; \
    git switch -q --detach "$ref"; \
    cmake -S . -B "$b" -DCMAKE_C_COMPILER="$CC" -DCMAKE_BUILD_TYPE=Release -DBUILD_SHARED_LIBS=OFF -DSECP256K1_BUILD_BENCHMARK=OFF -DSECP256K1_BUILD_TESTS=OFF -DSECP256K1_BUILD_EXHAUSTIVE_TESTS=OFF -DSECP256K1_BUILD_CTIME_TESTS=OFF -DSECP256K1_BUILD_EXAMPLES=OFF -DSECP256K1_ENABLE_MODULE_MUSIG=OFF -DSECP256K1_VALGRIND=OFF >/dev/null; \
    cmake --build "$b" -j "$JOBS" --target secp256k1 >/dev/null; \
    lib=$(find "$b" -name 'libsecp256k1.a' -print -quit); \
    bytes=$(wc -c < "$lib" | tr -d ' '); \
    printf "%s\t%s\t%s\n" "$side" "$h" "$bytes"; \
    done | awk 'BEGIN{print "Side\tCommit\tlibsecp256k1.a bytes"} {print; size[$1]=$3} END{if(size["before"]&&size["after"]) printf "Delta\t\t%+d bytes (%+.2f%%)\n",size["after"]-size["before"],100*(size["after"]-size["before"])/size["before"]}' | column -t -s $'\t')
  ```
  </details>

  <details><summary>host: M4-Max.local, compiler: gcc-14 (Homebrew GCC 14.3.0) 14.3.0</summary>

  ```bash
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              17.5            15.9           -9.1%
  ecdsa_sign                12.3            12.1           -1.6%
  ec_keygen                 8.07            7.77           -3.7%
  ecdh                      16.6            15.1           -9.0%
  schnorrsig_sign           8.6             8.29           -3.6%
  schnorrsig_verify         17.8            16.1           -9.6%
  ellswift_encode           11.1            11.1           +0.0%
  ellswift_decode           4.68            4.69           +0.2%
  ellswift_keygen           19.4            19.1           -1.5%
  ellswift_ecdh             18.5            17.1           -7.6%
  field_half                0.00154         0.00155        +0.6%
  field_normalize           0.00665         0.00672        +1.1%
  field_normalize_weak      0.00291         0.00291        +0.0%
  field_sqr                 0.00871         0.0081         -7.0%
  field_mul                 0.00969         0.0093         -4.0%
  field_inverse             1.57            1.58           +0.6%
  field_inverse_var         0.735           0.742          +1.0%
  field_is_square_var       0.994           1              +0.6%
  field_sqrt                2.21            2.22           +0.5%
  group_double_var          0.0502          0.0447         -11.0%
  group_add_var             0.126           0.11           -12.7%
  group_add_affine          0.1             0.0922         -7.8%
  group_add_affine_var      0.0887          0.077          -13.2%
  group_add_zinv_var        0.106           0.0902         -14.9%
  group_to_affine_var       0.774           0.774          +0.0%
  ecmult_wnaf               0.334           0.334          +0.0%
  hash_sha256               0.12            0.12           +0.0%
  hash_hmac_sha256          0.464           0.463          -0.2%
  hash_rfc6979_hmac_sha256  2.55            2.55           +0.0%
  context_create            1.96            1.96           +0.0%

  Side    Commit                 libsecp256k1.a bytes
  before  8363a2d8d1           1254320
  after   33b1b9c455eb           1311368
  Delta   +57048 bytes (+4.55%)
  ```

  </details>

  <details><summary>host: WIN-A2EHOAU4JET (Intel(R) Xeon(R) CPU E5-2637 v2 @ 3.50GHz), system: Microsoft Windows NT 10.0.20348.0, compiler: Microsoft (R) C/C++ Optimizing Compiler Version 19.50.35728 for x64</summary>

  ```bash
  Benchmark                    Before min(us) After min(us)    Delta
  ecdsa_verify                           74.1          72.2    -2.6%
  ecdsa_sign                             43.3          41.4    -4.4%
  ec_keygen                              32.3            30    -7.1%
  ecdh                                     75            68    -9.3%
  schnorrsig_sign                        34.1            32    -6.2%
  schnorrsig_verify                      74.9          73.1    -2.4%
  ellswift_encode                        32.3          32.5    +0.6%
  ellswift_decode                        14.4          14.6    +1.4%
  ellswift_keygen                        64.6          62.9    -2.6%
  ellswift_ecdh                          80.2          73.7    -8.1%
  field_half                          0.00378       0.00378    +0.0%
  field_normalize                      0.0114        0.0114    +0.0%
  field_normalize_weak                0.00389       0.00389    +0.0%
  field_sqr                            0.0272        0.0252    -7.4%
  field_mul                            0.0394        0.0365    -7.4%
  field_inverse                          3.27          3.29    +0.6%
  field_inverse_var                      2.07          2.11    +1.9%
  field_is_square_var                     2.7          2.67    -1.1%
  field_sqrt                             7.47          6.98    -6.6%
  group_double_var                      0.245         0.207   -15.5%
  group_add_var                           0.6         0.525   -12.5%
  group_add_affine                      0.465         0.405   -12.9%
  group_add_affine_var                  0.418         0.358   -14.4%
  group_add_zinv_var                    0.458         0.403   -12.0%
  group_to_affine_var                    2.25          2.26    +0.4%
  ecmult_wnaf                            0.58          0.59    +1.7%
  hash_sha256                           0.332         0.333    +0.3%
  hash_hmac_sha256                       1.31          1.31    +0.0%
  hash_rfc6979_hmac_sha256               7.23           7.2    -0.4%
  context_create                         3.32          3.34    +0.6%

  Side     Commit          DLL bytes
  before   8363a2d8d1      1239040
  after    a37e34e187da      1414144
  Delta                      175104 (+14.13%)
  ```
  </details>

  <details><summary>host: i9-ssd, compiler: gcc (GCC) 16.1.0</summary>

  ```bash
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              39.6            37.5           -5.3%
  ecdsa_sign                27.1            26.4           -2.6%
  ec_keygen                 18.2            17.5           -3.8%
  ecdh                      39              37.4           -4.1%
  schnorrsig_sign           19.5            18.7           -4.1%
  schnorrsig_verify         40.3            38.1           -5.5%
  ellswift_encode           20.1            19.9           -1.0%
  ellswift_decode           8.59            8.46           -1.5%
  ellswift_keygen           38.2            37.3           -2.4%
  ellswift_ecdh             43.4            40.9           -5.8%
  field_half                0.00275         0.00275        +0.0%
  field_normalize           0.00995         0.00994        -0.1%
  field_normalize_weak      0.00378         0.00378        +0.0%
  field_sqr                 0.0178          0.015          -15.7%
  field_mul                 0.019           0.0168         -11.6%
  field_inverse             2.41            2.39           -0.8%
  field_inverse_var         1.32            1.28           -3.0%
  field_is_square_var       1.69            1.68           -0.6%
  field_sqrt                4.21            4.16           -1.2%
  group_double_var          0.121           0.115          -5.0%
  group_add_var             0.309           0.272          -12.0%
  group_add_affine          0.248           0.231          -6.9%
  group_add_affine_var      0.216           0.194          -10.2%
  group_add_zinv_var        0.245           0.213          -13.1%
  group_to_affine_var       1.41            1.36           -3.5%
  ecmult_wnaf               0.536           0.581          +8.4%
  hash_sha256               0.29            0.286          -1.4%
  hash_hmac_sha256          1.14            1.13           -0.9%
  hash_rfc6979_hmac_sha256  6.3             6.21           -1.4%
  context_create            2.68            2.68           +0.0%

  Side    Commit        libsecp256k1.a bytes
  before  8363a2d8d1  1271040
  after   33b1b9c455eb  1330808
  Delta                 +59768 bytes (+4.70%)
  ```
  </details>

  <details><summary>host: i7-hdd, compiler: gcc (Ubuntu 14.2.0-19ubuntu2) 14.2.0</summary>

  ```bash
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              43.1            38.4           -10.9%
  ecdsa_sign                28.4            27.3           -3.9%
  ec_keygen                 19.3            18             -6.7%
  ecdh                      43.2            38.4           -11.1%
  schnorrsig_sign           20.6            19.4           -5.8%
  schnorrsig_verify         43.7            39.1           -10.5%
  ellswift_encode           19.9            19.7           -1.0%
  ellswift_decode           8.48            8.41           -0.8%
  ellswift_keygen           39.2            37.8           -3.6%
  ellswift_ecdh             46.4            41.8           -9.9%
  field_half                0.00275         0.00275        +0.0%
  field_normalize           0.00998         0.00998        +0.0%
  field_normalize_weak      0.00402         0.00402        +0.0%
  field_sqr                 0.017           0.0154         -9.4%
  field_mul                 0.0218          0.0171         -21.6%
  field_inverse             2.49            2.46           -1.2%
  field_inverse_var         1.36            1.35           -0.7%
  field_is_square_var       1.66            1.67           +0.6%
  field_sqrt                4.07            4.07           +0.0%
  group_double_var          0.132           0.119          -9.8%
  group_add_var             0.346           0.28           -19.1%
  group_add_affine          0.266           0.236          -11.3%
  group_add_affine_var      0.243           0.201          -17.3%
  group_add_zinv_var        0.265           0.216          -18.5%
  group_to_affine_var       1.46            1.44           -1.4%
  ecmult_wnaf               0.554           0.604          +9.0%
  hash_sha256               0.305           0.298          -2.3%
  hash_hmac_sha256          1.18            1.17           -0.8%
  hash_rfc6979_hmac_sha256  6.47            6.43           -0.6%
  context_create            2.73            2.71           -0.7%
  ```

  </details>

  <details><summary>host: rpi5-16-3, compiler: gcc (Ubuntu 14.2.0-19ubuntu2) 14.2.0</summary>

  ```bash
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              157             156            -0.6%
  ecdsa_sign                69.5            69.3           -0.3%
  ec_keygen                 57.6            57.5           -0.2%
  ecdh                      149             148            -0.7%
  schnorrsig_sign           59.3            59             -0.5%
  schnorrsig_verify         158             157            -0.6%
  ellswift_encode           44.9            44.8           -0.2%
  ellswift_decode           24.2            24.2           +0.0%
  ellswift_keygen           103             102            -1.0%
  ellswift_ecdh             154             154            +0.0%
  field_half                0.00334         0.00334        +0.0%
  field_normalize           0.0143          0.0144         +0.7%
  field_normalize_weak      0.00543         0.00543        +0.0%
  field_sqr                 0.0654          0.0618         -5.5%
  field_mul                 0.0919          0.091          -1.0%
  field_inverse             4.8             4.78           -0.4%
  field_inverse_var         2.24            2.24           +0.0%
  field_is_square_var       2.31            2.31           +0.0%
  field_sqrt                17              17             +0.0%
  group_double_var          0.526           0.525          -0.2%
  group_add_var             1.35            1.34           -0.7%
  group_add_affine          0.988           0.984          -0.4%
  group_add_affine_var      0.926           0.915          -1.2%
  group_add_zinv_var        1.02            1.01           -1.0%
  group_to_affine_var       2.6             2.6            +0.0%
  ecmult_wnaf               0.606           0.614          +1.3%
  hash_sha256               0.316           0.315          -0.3%
  hash_hmac_sha256          1.2             1.2            +0.0%
  hash_rfc6979_hmac_sha256  6.62            6.62           +0.0%
  context_create            4.18            4.18           +0.0%
  ```
  </details>

  <details><summary>host: rpi4-2-1, compiler: gcc (Ubuntu 14.2.0-19ubuntu2) 14.2.0</summary>

  ```bash
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              222             216            -2.7%
  ecdsa_sign                111             109            -1.8%
  ec_keygen                 90.4            88.6           -2.0%
  ecdh                      216             211            -2.3%
  schnorrsig_sign           93.4            91.4           -2.1%
  schnorrsig_verify         224             218            -2.7%
  ellswift_encode           64.2            64.1           -0.2%
  ellswift_decode           33.5            33.5           +0.0%
  ellswift_keygen           156             153            -1.9%
  ellswift_ecdh             226             220            -2.7%
  field_half                0.00447         0.00447        +0.0%
  field_normalize           0.0215          0.0215         +0.0%
  field_normalize_weak      0.00783         0.00783        +0.0%
  field_sqr                 0.0871          0.0822         -5.6%
  field_mul                 0.126           0.121          -4.0%
  field_inverse             8.54            8.54           +0.0%
  field_inverse_var         3.25            3.25           +0.0%
  field_is_square_var       3.57            3.57           +0.0%
  field_sqrt                22.7            22.6           -0.4%
  group_double_var          0.72            0.71           -1.4%
  group_add_var             1.87            1.8            -3.7%
  group_add_affine          1.4             1.36           -2.9%
  group_add_affine_var      1.3             1.24           -4.6%
  group_add_zinv_var        1.42            1.37           -3.5%
  group_to_affine_var       3.76            3.75           -0.3%
  ecmult_wnaf               1.06            1.05           -0.9%
  hash_sha256               0.532           0.531          -0.2%
  hash_hmac_sha256          2.02            2.02           +0.0%
  hash_rfc6979_hmac_sha256  11.2            11.2           +0.0%
  context_create            6.8             6.8            +0.0%
  ```
  </details>

  <details><summary>host: umbrel (Intel(R) N150), compiler: gcc (Debian 12.2.0-14+deb12u1) 12.2.0</summary>

  ```bash
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              371             353            -4.9%
  ecdsa_sign                163             160            -1.8%
  ec_keygen                 129             123            -4.7%
  ecdh                      347             332            -4.3%
  schnorrsig_sign           131             126            -3.8%
  schnorrsig_verify         373             356            -4.6%
  ellswift_encode           143             142            -0.7%
  ellswift_decode           71.3            70.8           -0.7%
  ellswift_keygen           272             268            -1.5%
  ellswift_ecdh             367             352            -4.1%
  field_half                0.0124          0.0124         +0.0%
  field_normalize           0.0439          0.0439         +0.0%
  field_normalize_weak      0.0192          0.0192         +0.0%
  field_sqr                 0.168           0.169          +0.6%
  field_mul                 0.182           0.18           -1.1%
  field_inverse             11.2            11.2           +0.0%
  field_inverse_var         8.44            8.4            -0.5%
  field_is_square_var       9.56            9.55           -0.1%
  field_sqrt                45              44             -2.2%
  group_double_var          1.25            1.18           -5.6%
  group_add_var             2.92            2.68           -8.2%
  group_add_affine          2.22            2.12           -4.5%
  group_add_affine_var      2.02            1.86           -7.9%
  group_add_zinv_var        2.21            2.01           -9.0%
  group_to_affine_var       9.25            9.13           -1.3%
  ecmult_wnaf               2.51            2.45           -2.4%
  hash_sha256               1.13            1.12           -0.9%
  hash_hmac_sha256          4.44            4.44           +0.0%
  hash_rfc6979_hmac_sha256  24.4            24.4           +0.0%
  context_create            14.2            14.1           -0.7%
  ```
  </details>

  <details><summary>host: nodl (Cortex-A53), compiler: gcc (Ubuntu 11.4.0-1ubuntu1~22.04.3) 11.4.0</summary>

  ```bash
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              632             611            -3.3%
  ecdsa_sign                308             291            -5.5%
  ec_keygen                 228             212            -7.0%
  ecdh                      633             585            -7.6%
  schnorrsig_sign           231             221            -4.3%
  schnorrsig_verify         630             594            -5.7%
  ellswift_encode           156             156            +0.0%
  ellswift_decode           80              76.1           -4.9%
  ellswift_keygen           438             455            +3.9%
  ellswift_ecdh             613             599            -2.3%
  field_half                0.0106          0.00985        -7.1%
  field_normalize           0.0483          0.0499         +3.3%
  field_normalize_weak      0.0173          0.0173         +0.0%
  field_sqr                 0.202           0.182          -9.9%
  field_mul                 0.278           0.273          -1.8%
  field_inverse             21.3            21.1           -0.9%
  field_inverse_var         7.67            7.48           -2.5%
  field_is_square_var       8.73            8.91           +2.1%
  field_sqrt                65.8            61.9           -5.9%
  group_double_var          2.04            1.9            -6.9%
  group_add_var             5.35            5.09           -4.9%
  group_add_affine          3.93            3.51           -10.7%
  group_add_affine_var      3.56            3.32           -6.7%
  group_add_zinv_var        3.94            3.65           -7.4%
  group_to_affine_var       9.56            10.4           +8.8%
  ecmult_wnaf               2.37            2.48           +4.6%
  hash_sha256               1.13            1.19           +5.3%
  hash_hmac_sha256          5.08            4.76           -6.3%
  hash_rfc6979_hmac_sha256  33.3            31.2           -6.3%
  context_create            19.3            18.8           -2.6%
  ```
  </details>

  <details><summary>Reviewer measurements</summary>

  ### andrewtoth, i9-14900HX, GCC 12.3

  ```text
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              22.7            21.5           -5.3%
  ecdsa_sign                14.3            14.0           -2.1%
  ec_keygen                 9.90            9.54           -3.6%
  ecdh                      21.6            20.7           -4.2%
  schnorrsig_sign           10.6            10.2           -3.8%
  schnorrsig_verify         23.1            21.8           -5.6%
  ellswift_ecdh             23.8            22.7           -4.6%
  field_sqr                 0.00912         0.00898        -1.5%
  field_mul                 0.0114          0.0107         -6.1%
  field_inverse             1.23            1.24           +0.8%
  field_inverse_var         0.770           0.773          +0.4%
  field_is_square_var       1.06            1.05           -0.9%
  field_sqrt                2.82            2.46           -12.8%
  group_double_var          0.0701          0.0612         -12.7%
  group_add_var             0.168           0.153          -8.9%
  group_add_affine          0.132           0.123          -6.8%
  group_add_affine_var      0.120           0.103          -14.2%
  group_add_zinv_var        0.138           0.117          -15.2%
  group_to_affine_var       0.820           0.819          -0.1%
  ```

  ### theStack, Snapdragon X Elite X1E-78-100, GCC 14.2.0

  ```text
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              24.1            21.4           -11.2%
  ecdsa_sign                19.0            18.5           -2.6%
  schnorrsig_sign           13.0            12.7           -2.3%
  schnorrsig_verify         24.4            21.7           -11.1%
  ```

  Bitcoin Core subtree `bench_bitcoin -filter=VerifyScript.*`:

  ```text
  Benchmark                   Before ns/script  After ns/script  Delta
  VerifyScriptP2TR_KeyPath    23679.52          20899.66         -11.7%
  VerifyScriptP2TR_ScriptPath 43430.71          39280.19         -9.6%
  VerifyScriptP2WPKH          23526.82          20870.22         -11.3%
  ```

  ### sipa, Ryzen 5950X, GCC 15.2.0

  ```text
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              30.8            27.3           -11.4%
  ecdsa_sign                18.7            17.2           -8.0%
  ec_keygen                 13.6            12.2           -10.3%
  ecdh                      29.8            26.7           -10.4%
  ecdsa_recover             31.0            28.2           -9.0%
  schnorrsig_sign           14.4            13.0           -9.7%
  schnorrsig_verify         31.1            28.5           -8.4%
  ellswift_encode           13.2            13.4           +1.5%
  ellswift_decode           5.79            5.84           +0.9%
  ellswift_keygen           26.8            25.7           -4.1%
  ellswift_ecdh             32.1            29.6           -7.8%
  ```
  </details>

  ---

  **clang:**
  <details><summary>host: i9-ssd, compiler: Ubuntu clang version 22.1.6 (++20260508084839+c0262e742787-1~exp1~20260508204859.77)</summary>

  ```bash
  Benchmark                 Before min(us)  After min(us)  Delta
  ecdsa_verify              40.1            39.8           -0.7%
  ecdsa_sign                29.2            29.1           -0.3%
  ec_keygen                 19.5            19.6           +0.5%
  ecdh                      40.3            39.8           -1.2%
  schnorrsig_sign           21              20.9           -0.5%
  schnorrsig_verify         40.6            40.3           -0.7%
  ellswift_encode           20.1            20.1           +0.0%
  ellswift_decode           8.43            8.41           -0.2%
  ellswift_keygen           39.8            39.7           -0.3%
  ellswift_ecdh             44.1            43.5           -1.4%
  field_half                0.0028          0.0028         +0.0%
  field_normalize           0.00889         0.00891        +0.2%
  field_normalize_weak      0.0037          0.0037         +0.0%
  field_sqr                 0.0144          0.0144         +0.0%
  field_mul                 0.021           0.019          -9.5%
  field_inverse             2.6             2.64           +1.5%
  field_inverse_var         1.34            1.35           +0.7%
  field_is_square_var       1.73            1.73           +0.0%
  field_sqrt                3.95            3.96           +0.3%
  group_double_var          0.128           0.125          -2.3%
  group_add_var             0.311           0.31           -0.3%
  group_add_affine          0.243           0.242          -0.4%
  group_add_affine_var      0.207           0.207          +0.0%
  group_add_zinv_var        0.229           0.228          -0.4%
  group_to_affine_var       1.43            1.44           +0.7%
  ecmult_wnaf               0.536           0.598          +11.6%
  hash_sha256               0.3             0.299          -0.3%
  hash_hmac_sha256          1.18            1.18           +0.0%
  hash_rfc6979_hmac_sha256  6.51            6.53           +0.3%
  context_create            2.16            2.15           -0.5%
  ```
  </details>

  **reindex-chainstate:**
  <details><summary>2026-05-28 | reindex-chainstate | 950059 blocks | dbcache 5000 | i9-ssd | x86_64 | Intel(R) Core(TM) i9-9900K CPU @ 3.60GHz | 16 cores | 62Gi RAM | SSD</summary>

  ```bash
  for DBCACHE in 5000; do \
      COMMITS="67250b1d97e6159d908ef44639b6a12471e7c717 c264526415f38afb9890003003b7de39b370b745"; \
      STOP=950059; CC=gcc; CXX=g++; \
      BASE_DIR="/mnt/my_storage"; DATA_DIR="$BASE_DIR/BitcoinData"; LOG_DIR="$BASE_DIR/logs"; \
      (echo ""; for c in $COMMITS; do git fetch -q origin "$c" 2>/dev/null || true; git log -1 --pretty='%h %s' $c || exit 1; done) && \
      (echo "" && echo "$(date -I) | reindex-chainstate | ${STOP} blocks | dbcache ${DBCACHE} | $(hostname) | $(uname -m) | $(lscpu | grep 'Model name' | head -1 | cut -d: -f2 | xargs) | $(nproc) cores | $(free -h | awk '/^Mem:/{print $2}') RAM | $(l
  sblk -no ROTA $(df --output=source $BASE_DIR | tail -1) | grep -q 1 && echo HDD || echo SSD)"; echo "") && \
      hyperfine \
      --sort command \
      --runs 1 \
      --export-json "$BASE_DIR/rdx-$(sed -E 's/[^ ]+/\L&/g;s/[.]/_/g;s/ /-/g'<<<"$COMMITS")-$STOP-$DBCACHE-$CC.json" \
      --parameter-list COMMIT ${COMMITS// /,} \
      --prepare "killall -9 bitcoind 2>/dev/null; rm -f ./build/bin/bitcoind; git clean -fxd; git reset --hard {COMMIT} && \
        cmake -B build -G Ninja -DCMAKE_BUILD_TYPE=Release && ninja -C build bitcoind -j1 && \
        ./build/bin/bitcoind -datadir=$DATA_DIR -stopatheight=$STOP -dbcache=1000 -printtoconsole=0; sleep 20; rm -f $DATA_DIR/debug.log; rm -rfd $DATA_DIR/indexes;" \
      --conclude "killall bitcoind || true; sleep 5; grep -q 'height=0' $DATA_DIR/debug.log && grep -q 'Disabling script verification at block #1' $DATA_DIR/debug.log && grep -q 'height=$STOP' $DATA_DIR/debug.log && grep 'Bitcoin Core version' $DATA_
  DIR/debug.log | grep -q \"\$(git rev-parse --short=12 {COMMIT})\"; \
                  cp $DATA_DIR/debug.log $LOG_DIR/debug-{COMMIT}-$(date +%s).log" \
      "COMPILER=$CC ./build/bin/bitcoind -datadir=$DATA_DIR -stopatheight=$STOP -dbcache=$DBCACHE -reindex-chainstate -blocksonly -connect=0 -printtoconsole=0 -assumevalid=0"; \
  done

  67250b1d97 parallel input fetcher
  c264526415 Refactor: optimize scalar reduction and arithmetic functions.

  2026-05-28 | reindex-chainstate | 950059 blocks | dbcache 5000 | i9-ssd | x86_64 | Intel(R) Core(TM) i9-9900K CPU @ 3.60GHz | 16 cores | 62Gi RAM | SSD

  Benchmark 1: COMPILER=gcc ./build/bin/bitcoind -datadir=/mnt/my_storage/BitcoinData -stopatheight=950059 -dbcache=5000 -reindex-chainstate -blocksonly -connect=0 -printtoconsole=0 -assumevalid=0 (COMMIT = 67250b1d97e6159d908ef44639b6a12471e7c717)
    Time (abs ≡):        37155.108 s               [User: 375835.978 s, System: 978.929 s]

  Benchmark 2: COMPILER=gcc ./build/bin/bitcoind -datadir=/mnt/my_storage/BitcoinData -stopatheight=950059 -dbcache=5000 -reindex-chainstate -blocksonly -connect=0 -printtoconsole=0 -assumevalid=0 (COMMIT = c264526415f38afb9890003003b7de39b370b745)
    Time (abs ≡):        36261.785 s               [User: 362247.387 s, System: 1002.867 s]

  Relative speed comparison
          1.02          COMPILER=gcc ./build/bin/bitcoind -datadir=/mnt/my_storage/BitcoinData -stopatheight=950059 -dbcache=5000 -reindex-chainstate -blocksonly -connect=0 -printtoconsole=0 -assumevalid=0 (COMMIT = 67250b1d97e6159d908ef44639b6a12471e7c717)
          1.00          COMPILER=gcc ./build/bin/bitcoind -datadir=/mnt/my_storage/BitcoinData -stopatheight=950059 -dbcache=5000 -reindex-chainstate -blocksonly -connect=0 -printtoconsole=0 -assumevalid=0 (COMMIT = c264526415f38afb9890003003b7de39b370b745)
  ```
  </details>

ACKs for top commit:
  real-or-random:
    utACK 71fcd8410e
  theStack:
    ACK 71fcd8410e
  hebasto:
    ACK 71fcd8410e, tested different scenarios on Linux and Windows.

Tree-SHA512: 4686badb33da4613fb43df69355354cbcbbf7cb726130670e8f97f7992332db39ca8c45c0e0944de9e2ead61c3d4b8fdd0a62b023f1cfcd2e8d9b2abb74084cd
2026-06-17 13:35:57 +02:00
merge-script fdcf2d41e2 Merge bitcoin-core/secp256k1#1865: test: enable -Wunused-function in test suite (Fix #1831)
a77dacad9a test: enable -Wunused-function in test suite (Fix #1831) (kallal79)

Pull request description:

  This PR addresses issue #1831 by enabling the `-Wunused-function` compiler warning within the test suite.

  Currently, `-Wno-unused-function` is passed globally to disable warnings about unused functions, making it too easy to write a test case but forget to actually call it. To catch untested helper functions safely, this PR uses GCC/Clang pragmas scoped strictly to the body of the test files.

  ### Changes Made:
  - Added `#pragma GCC diagnostic warning "-Wunused-function"` directly after the `#include` statements in `src/tests.c`, `src/tests_exhaustive.c`, `src/ctime_tests.c`, and `src/unit_test.c`.
  Fixes #1831

ACKs for top commit:
  real-or-random:
    ACK a77dacad9a
  hebasto:
    ACK a77dacad9a.

Tree-SHA512: 775d633d9d2e95154b6718270ce1687a1b20c2c8cc67c909953b3395d76e6853e6be1d6a95d8aef3f15a78dec3497bea8e3864e36830977e11beb42ea9abcc31
2026-06-16 13:58:19 +02:00
merge-script b2d2bd362d Merge bitcoin-core/secp256k1#1860: cmake: Emulate Libtool's behavior on NetBSD and OpenBSD
1eab757207 cmake: Fix shared library versioning on OpenBSD (Hennadii Stepanov)
a401c5145a cmake: Fix shared library versioning on NetBSD (Hennadii Stepanov)
8a0f4002c7 cmake, refactor: Improve documenting in `SetLibtoolAbiVersion` module (Hennadii Stepanov)
acf2084aa7 cmake, refactor: Introduce `SetLibtoolAbiVersion` module (Hennadii Stepanov)

Pull request description:

  This is a continuation of https://github.com/bitcoin-core/secp256k1/pull/1685.

  Additionally, the logic has been factored out into its own module and the documentation has been also improved.

ACKs for top commit:
  real-or-random:
    utACK https://github.com/bitcoin-core/secp256k1/pull/1860/changes/1eab757207c453db5bb567f2a6e18362eb49ee4c

Tree-SHA512: 24738053d3049f0ce551b0d05d62642d7f1e6645967288fbe30ce4799f4e64594e88a8fa2dd9109efd6cfc5666d7c5fe7a3bb99f0f06766d70b2a9362721e3c9
2026-06-16 11:07:32 +02:00
merge-script 87bec430bf Merge bitcoin-core/secp256k1#1867: test: musig: fix dead "aggnonce encodes two points at infinity" check
d7125e517d test: musig: fix dead "aggnonce encodes two points at infinity" check (Sebastian Falbesoner)

Pull request description:

  Due to the missing `CHECK` around, the return values were discarded and nothing was actually checked here.

  (Fwiw I prompted two AI models (MiniMax M3 and Opus 4.8) to find more similar instances in tests with bare statements that miss a surrounding `CHECK` in tests, and both didn't find any.)

ACKs for top commit:
  real-or-random:
    utACK d7125e517d
  hebasto:
    ACK d7125e517d, I have reviewed the code and it looks OK.

Tree-SHA512: 6eab61ce51a414e0555413bde29cf582b70fbf4a24ad1aae135bf88f28e3ee25ece8c79b7ccc254288395fedf6b2547931d5e00b0090146f1b83e43acc6570d7
2026-06-16 08:27:58 +02:00
Lőrinc 71fcd8410e field: force-inline 5x52 mul and sqr
The 5x52 field multiplication and squaring routines are hot in group arithmetic and scalar multiplication.

Use the new `SECP256K1_FORCE_INLINE` for the thin wrappers and `int128` inner helpers so compilers can schedule the 64x64->128 arithmetic without a call boundary.

Across the measured GCC and MSVC Release builds, this improves ECDSA verification by 0.6% to 9.1%, ECDH by 0.7% to 9.3%, and Schnorr verification by 0.6% to 9.6%.

The direct field benchmarks generally show the intended effect on field squaring and multiplication, while Clang results are mostly flat and less consistently positive.

This is a code-size tradeoff: the tested static library builds grew by about 4.6% to 4.7%, and the tested Windows Release DLL grew by 14.1%.

Co-authored-by: Sebastian Falbesoner <sebastian.falbesoner@gmail.com>
Co-authored-by: Hennadii Stepanov <32963518+hebasto@users.noreply.github.com>
Co-authored-by: Tim Ruffing <crypto@timruffing.de>
2026-06-15 23:56:19 +02:00
kallal79 a77dacad9a test: enable -Wunused-function in test suite (Fix #1831) 2026-06-12 19:10:33 +05:30
merge-script aea86bc350 Merge bitcoin-core/secp256k1#1864: test: refactor: simplify tests by using _ecmult_gen_ge helper, add test
2ee79e77e6 test: add unit test for `_ecmult_gen_ge` (Sebastian Falbesoner)
ca68daf8e1 test: refactor: simplify tests by using `_ecmult_gen_ge` helper (Sebastian Falbesoner)

Pull request description:

  This PR is a small follow-up to #1861. If the generator point multiplication result in Jacobian coordinates is immediately converted to affine coordinates after and is not needed for anything else, we can deduplicate by using the new `secp256k1_ecmult_gen_ge` helper. The second commit adds a simple unit tests, verifying for random scalars that the result of `secp256k1_ecmult_gen_ge` matches the two expected steps (`secp256k1_ecmult_gen_gej` plus Jacobian->affine conersion via `secp256k1_ge_set_gej`).

  Note that in a very strict sense the first commit is not a refactor, as the Jacobian object is now cleared out which was not done on master, but for the logic in the tests this shouldn't matter at all.

ACKs for top commit:
  real-or-random:
    utACK 2ee79e77e6

Tree-SHA512: 452895b6f6e70c686063afb051d25dab1d086aac28081c4a3071a3dbe7dae964e806f9fe8052b88a7da4305a0cf636badc2dba817cae96aae0a35b2bc9675c03
2026-06-12 08:47:31 +02:00
Sebastian Falbesoner 2ee79e77e6 test: add unit test for _ecmult_gen_ge 2026-06-11 17:56:32 +02:00
Sebastian Falbesoner d7125e517d test: musig: fix dead "aggnonce encodes two points at infinity" check 2026-06-10 00:21:24 +02:00
Hennadii Stepanov 1eab757207 cmake: Fix shared library versioning on OpenBSD 2026-06-09 13:23:25 +01:00
Hennadii Stepanov a401c5145a cmake: Fix shared library versioning on NetBSD 2026-06-09 13:23:15 +01:00
Hennadii Stepanov 8a0f4002c7 cmake, refactor: Improve documenting in SetLibtoolAbiVersion module 2026-06-09 13:23:08 +01:00
Hennadii Stepanov acf2084aa7 cmake, refactor: Introduce SetLibtoolAbiVersion module 2026-06-09 13:22:57 +01:00
merge-script 0f4a7e6bf9 Merge bitcoin-core/secp256k1#1855: bench: add internal benchmark for secp256k1_fe_normalize_var
240578eef5 bench: add internal benchmark for `secp256k1_fe_normalize_var` (Sebastian Falbesoner)

Pull request description:

  While addressing the review suggestion https://github.com/bitcoin-core/secp256k1/pull/1765#discussion_r3238616034 ([b10c mirror link](https://mirror.b10c.me/bitcoin-core-secp256k1/1765/#discussion_r3238616034)), I noticed that we don't have an internal benchmark for the variable-time variant of `_fe_normalize` yet, so this PR adds one. IIUC it's fine to repeatedly apply the operation on the same (already normalized at latest after the first loop iteration) field element for benchmarking purposes and don't put in an effort to reach the [final reduction code path](https://github.com/bitcoin-core/secp256k1/blob/b11340b3ce2afac1b6ffda4ce5828c30621d2917/src/field_5x52_impl.h#L120-L132), considering how extremely unlikely it is to reach it in practice.

  Results on my machine:
  ```
  $ ./build/bin/bench_internal normalize
  Benchmark                     ,    Min(us)    ,    Avg(us)    ,    Max(us)

  field_normalize               ,     0.0103    ,     0.0106    ,     0.0128
  field_normalize_var           ,     0.00545   ,     0.00546   ,     0.00547
  field_normalize_weak          ,     0.00352   ,     0.00354   ,     0.00363
  ```

ACKs for top commit:
  real-or-random:
    utACK 240578eef5

Tree-SHA512: 4480e65b24c9e3c498389c5faf807cc44ae2a421d4500dd95066f9bb4f4885c67d2a6e1875e93912b96422963fd1430f724d442f30eb152faf86302ba266bd94
2026-06-09 10:05:56 +02:00
Sebastian Falbesoner ca68daf8e1 test: refactor: simplify tests by using _ecmult_gen_ge helper
If the generator point multiplication result in Jacobian coordinates is
immediately converted to affine coordinates after and is not needed for
anything else, we can deduplicate by using the helper introduced in #1861.

Note that in a very strict sense this is not a refactor, as the Jacobian
object is now cleared out which was not done on master, but for the logic
in the tests this shouldn't matter at all.
2026-06-08 18:44:58 +02:00
merge-script 13db747f2b Merge bitcoin-core/secp256k1#1861: refactor: introduce _ecmult_gen_ge helper (preventing accidental gej leaks)
9e017e5062 refactor: rename `_ecmult_gen` -> `_ecmult_gen_gej` for consistency (Sebastian Falbesoner)
a3296d5e23 refactor: introduce `_ecmult_gen_ge` helper (preventing accidental gej leaks) (Sebastian Falbesoner)

Pull request description:

  Scalar multiplication with the generator point frequently involves a conversion to affine coordinates and clearing out the temporary Jacobian group element object after to avoid leaking secret key material (see 765ef53335 / #1579 for that last part), i.e. executing the following three functions:
  * `secp256k1_ecmult_gen(ctx, &rj, ...)`
  * `secp256k1_ge_set_gej(&r, &rj)`
  * `secp256k1_gej_clear(&rj)`

  This PR introduces a corresponding helper to deduplicate code and mitigate the risk that the last step is forgotten (which can easily happen, as it would not be detected by tests). It is applied in the code paths for ECDSA signing, Schnorr signing, public key creation and ecmult_gen blinding setup. The only remaining instance where we directly call `_ecmult_gen` is for [musig nonce generation](https://github.com/bitcoin-core/secp256k1/blob/a39093de15345a330fc8acbd09515fd150853bc8/src/modules/musig/session_impl.h#L416), as we apply batch inversion there for the two points.

  The idea came up during a conversation with furszy, who caught that the gej clearing was missing in the silentpayments module (sending function) as well (see https://github.com/bitcoin-core/secp256k1/pull/1765#issuecomment-4482838033, [b10c mirror link](https://mirror.b10c.me/bitcoin-core-secp256k1/1765/#issuecomment-4482838033)).

  If this gets conceptual support, I'd be curious to hear naming suggestions, as I'm not sure if the current one is fits well to the existing terminology (maybe `ecmult_gen_ge` or `ecmult_gen_to_affine`?).

ACKs for top commit:
  real-or-random:
    utACK 9e017e5062
  furszy:
    ACK 9e017e5062

Tree-SHA512: e9dc96c4301622e5b258de5c2cff5bd9f27d07d3a5f881d937c3db526e2c0a7ba5772ea24585af37be359e0510136916a15b39316c7c351d068c09545c003b6e
2026-06-08 17:36:17 +02:00
Sebastian Falbesoner 9e017e5062 refactor: rename _ecmult_gen -> _ecmult_gen_gej for consistency
Now that we have a function `_ecmult_gen_ge`, it makes sense to rename
the existing function `_ecmult_gen` to `_ecmult_gen_gej` for
consistency, to signal that the result is a Jacobian group element.

This diff was created by applying
```
$ sed -i s/secp256k1_ecmult_gen\(/secp256k1_ecmult_gen_gej\(/g $(git ls-files)
```
2026-06-07 20:21:18 +02:00
Sebastian Falbesoner a3296d5e23 refactor: introduce _ecmult_gen_ge helper (preventing accidental gej leaks)
Scalar multiplication with the generator point frequently involves a
conversion to affine coordinates and clearing out the temporary Jacobian
group element object after to avoid leaking secret key material, i.e.
executing the following three steps:
    - secp256k1_ecmult_gen(ctx, &rj, ...)
    - secp256k1_ge_set_gej(&r, &rj)
    - secp256k1_gej_clear(&rj)

This commit introduces a corresponding helper to deduplicate code
and mitigate the risk that last step is forgotten (which can easily
happen and is not detected by tests).

The idea came up during a conversation with furszy, see
https://github.com/bitcoin-core/secp256k1/pull/1765#issuecomment-4482838033
2026-06-07 20:21:18 +02:00
merge-script c63062380f Merge bitcoin-core/secp256k1#1852: Add exhaustive test for ECDH module
5698e66c64 Add exhaustive test for ECDH module (Sebastian Falbesoner)

Pull request description:

  This PR adds an exhaustive test for the ECDH module, looping over all key combinations and verifying the commutativity property (ECDH(i\*G, j) == ECDH(j\*G, i)) and checking against a recalculated ECDH result (by manually invoking the default ECDH hash function on the precalculated group element `group[i * j]`'s coordinates). The existing test coverage is already solid (including Wycheproof test vectors), but I figured it likely wouldn't hurt to add this as well.

ACKs for top commit:
  sipa:
    ACK 5698e66c64
  real-or-random:
    utACK 5698e66c64

Tree-SHA512: e80b8508ee61e3bf5230951393a08c8937f19d2d16220ff2b02fe69b039195a1545809d3ea420dfed1f192c3711f403c63e86c3af2bb2fc4ab1254388ba50287
2026-06-07 13:38:34 +02:00
Sebastian Falbesoner 240578eef5 bench: add internal benchmark for secp256k1_fe_normalize_var 2026-06-04 19:17:03 +02:00
Sebastian Falbesoner 5698e66c64 Add exhaustive test for ECDH module 2026-06-02 14:25:34 +02:00
merge-script a39093de15 Merge bitcoin-core/secp256k1#1851: doc: correct API docs for ECDSA signing out-params (s/array/signature object/)
40a0d874a6 doc: correct API docs for ECDSA signing out-params (s/array/signature object/) (Sebastian Falbesoner)

Pull request description:

  This PR is a late follow-up to https://github.com/bitcoin-core/secp256k1/pull/282, adapting the signature out param description to the API change.

  This is currently a minimum-diff based on existing API doc descriptions in the touched header files (for e.g. `_ecdsa_signature_parse_{compact,der}`, `_ecdsa_recoverable_signature_parse_compact`). For more consistency across modules, one could adopt the wording used in the musig module, e.g. "pointer to a structure to store the created signature".

ACKs for top commit:
  real-or-random:
    utACK 40a0d874a6
  furszy:
    ACK 40a0d874a6

Tree-SHA512: 028e87bb77be6118264ab14dce2037b4f8dd680b9d7a2c273773633d342e7f0597332932cd2654f07ab0d151f1de367f716205af4f9bb15bb83076a10b49d06c
2026-06-01 11:54:06 +02:00
merge-script 8363a2d8d1 Merge bitcoin-core/secp256k1#1854: tests: compare full MuSig aggregate nonce
af1fdd1215 tests: compare full MuSig aggregate nonce (w0xlt)

Pull request description:

  This PR fixes a MuSig nonce aggregation test that only compared the first 33 bytes of the serialized 66-byte aggregate nonce.

ACKs for top commit:
  theStack:
    ACK af1fdd1215
  real-or-random:
    utACK af1fdd1215

Tree-SHA512: a580bb1b43177cb2986bda2f595ec73af8fb98381fdab71b79142032c6d64d685b81963b3a7252e7772818512f6016ee8f564ff92c39d28d8e67d8afd26c96d7
2026-05-19 08:29:23 +02:00
w0xlt af1fdd1215 tests: compare full MuSig aggregate nonce 2026-05-12 15:26:12 -07:00
Sebastian Falbesoner 40a0d874a6 doc: correct API docs for ECDSA signing out-params (s/array/signature object/) 2026-04-29 17:56:54 +02:00
merge-script b11340b3ce Merge bitcoin-core/secp256k1#1849: musig: always clear out secret key in secp256k1_musig_nonce_gen_counter
8479eafa57 musig: always clear out secret key in `secp256k1_musig_nonce_gen_counter` (Sebastian Falbesoner)

Pull request description:

  Even though `secp256k1_musig_nonce_gen_internal` can currently only fail if the surrounding API function is misused (invalid `keypair` or `keyagg_cache` parameters, making the corresponding [seckey validation](https://github.com/bitcoin-core/secp256k1/blob/c1a9e4fe6471478dba9c5ef61105b9c5213c6bf1/src/modules/musig/session_impl.h#L391) or [pubkey](https://github.com/bitcoin-core/secp256k1/blob/c1a9e4fe6471478dba9c5ef61105b9c5213c6bf1/src/modules/musig/session_impl.h#L404)/[keyaggcache](https://github.com/bitcoin-core/secp256k1/blob/c1a9e4fe6471478dba9c5ef61105b9c5213c6bf1/src/modules/musig/session_impl.h#L397) load calls fail), clearing out the stack memory holding the secret key as well in this case seems reasonable to follow best practices.

  The issue was reported off-band by l0rinc (thanks!), in the course of analyzing the secp repository with AI tooling.

ACKs for top commit:
  furszy:
    ACK 8479eafa57
  real-or-random:
    utACK 8479eafa57

Tree-SHA512: dc15ed7518c6cd0b1b86d2e0382c546374e94a1c1fa15639ba3db27e083ce53a24ddf4d3cd3328b4dc229258d8cbb0e01f4b63f025d04254845f2bf20cfa5289
2026-04-29 08:04:06 +02:00
Sebastian Falbesoner 8479eafa57 musig: always clear out secret key in secp256k1_musig_nonce_gen_counter
Even though `secp256k1_musig_nonce_gen_internal` can currently only fail
if the API is misused (invalid `keypair` or `keyagg_cache` parameters),
clear out the buffer holding secret key data as well in this case to
follow best practices.

The issue was found and reported by l0rinc using GPT 5.5 (Thanks!).
2026-04-28 23:22:29 +02:00
merge-script c1a9e4fe64 Merge bitcoin-core/secp256k1#1848: ci: Bump GCC snapshot major version to 17
3cca6451a2 ci: Bump GCC snapshot major version to 17 (Hennadii Stepanov)

Pull request description:

  See https://gcc.gnu.org/pipermail/gcc/2026-April/248048.html.

ACKs for top commit:
  real-or-random:
    utACK 3cca6451a2

Tree-SHA512: 36c975c500cb0411f20189a3b451b58268ff15be08ff444833e27ae37b53bf7581ba8a8c48b393a9b96050f8c498242ba2fb5e593caee492f1fcb1182cc948bc
2026-04-27 09:08:00 +02:00
Hennadii Stepanov 3cca6451a2 ci: Bump GCC snapshot major version to 17
See https://gcc.gnu.org/pipermail/gcc/2026-April/248048.html.
2026-04-27 06:28:45 +01:00
merge-script ea174fe045 Merge bitcoin-core/secp256k1#1846: ci: Replace ilammy/msvc-dev-cmd with manual MSVC setup
285cb788e9 ci: Replace `ilammy/msvc-dev-cmd` with manual MSVC setup (Hennadii Stepanov)

Pull request description:

  The `ilammy/msvc-dev-cmd` repository seems [abandoned](https://github.com/ilammy/msvc-dev-cmd/issues/103) and should be considered unsafe.

  This PR updates the workflow to load the MSVC environment variables directly via [`vcvars64.bat`](https://learn.microsoft.com/en-us/cpp/build/building-on-the-command-line).

  For reference, the Bitcoin Core project removed `ilammy/msvc-dev-cmd` in https://github.com/bitcoin/bitcoin/pull/32513.

  **Note for Maintainers:** Once this PR is merged and other PRs are rebased on top of it, the `ilammy/msvc-dev-cmd` action should be removed from the "Action permission" settings in this repository.

ACKs for top commit:
  real-or-random:
    utACK https://github.com/bitcoin-core/secp256k1/pull/1846/changes/285cb788e9da2a965178cc8e0769e4821ff0c799

Tree-SHA512: 3faa9a316438ae3f4e7352890a77baaf0bf0adda4086111344d8279dc869a42ea837269527268fad1a2dd2e1893fd8fc51e5c3b205f394926b07988579a10ad9
2026-04-13 15:12:28 +02:00
Hennadii Stepanov 285cb788e9 ci: Replace ilammy/msvc-dev-cmd with manual MSVC setup
The `ilammy/msvc-dev-cmd` repository seems abandoned and should be
considered unsafe. This updates the workflow to load the MSVC
environment variables directly via `vcvars64.bat`.

See https://learn.microsoft.com/en-us/cpp/build/building-on-the-command-line.
2026-04-13 11:54:22 +01:00
Peter.Dettman 0cad3df503 Improve checks for scalar _get_bits methods 2026-04-12 17:37:42 +07:00