AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 12 Bitcoin

Merge bitcoin-core/secp256k1#1947: musig: test nonce_gen_counter with random counters

Public commit record

What the developer wrote

Authored by merge-script

100/100 · Strong
Merge bitcoin-core/secp256k1#1947: musig: test nonce_gen_counter with random counters

b819a790f06122d5a53c0320e79c0dc486349fbd musig: test nonce_gen_counter with random counters (ViniciusCestarii)

Pull request description:

The only output check of `nonce_gen_counter` uses `nonrepeating_cnt = 0`, so the following mutant replacing `secp256k1_write_be64` with `secp256k1_write_be32` (which could enable nonce reuse) survived because zero serializes the same either way.

```diff
diff --git a/src/modules/musig/session_impl.h b/src/modules/musig/session_impl.h
index d8a3cca..710c4c5 100644
--- a/src/modules/musig/session_impl.h
+++ b/src/modules/musig/session_impl.h
@@ -447,7 +447,7 @@ int secp256k1_musig_nonce_gen_counter(const secp256k1_context* ctx, secp256k1_mu
memset(secnonce, 0, sizeof(*secnonce));
ARG_CHECK(keypair != NULL);

- secp256k1_write_be64(buf, nonrepeating_cnt);
+ secp256k1_write_be32(buf, nonrepeating_cnt);
/* keypair_sec and keypair_pub do not fail if the arguments are not NULL */
ret = secp256k1_keypair_sec(ctx, seckey, keypair);
VERIFY_CHECK(ret);
```

This add a new test, which checks that for random 64-bit counters, `nonce_gen_counter` gives the same nonce as `nonce_gen`.

ACKs for top commit:
real-or-random:
utACK b819a790f06122d5a53c0320e79c0dc486349fbd

Tree-SHA512: 1f16375880808eacea1f4db9931f345f2f1b44a2724d61710beb5e39e956d4f28bd6707c90b8300f033282bee207fd2f44c039cb01ef0675858d415ad6ea2978
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit only adds a new test to the MuSig cryptographic module. It does not change any production code. The new test verifies that two different nonce-generation functions produce matching results when given equivalent random 64-bit counters. The pull request description mentions a hypothetical mutation (replacing a 64-bit write with a 32-bit write) that could survive testing if only zero-valued counters were used, but that mutation is not present in the code and is only described as motivation for stronger testing.

Recommended action

No security action required. This is a test-hardening change. Reviewers may optionally verify that the new test correctly exercises the 64-bit counter serialization path and that the existing `secp256k1_write_be64` call in `session_impl.h` remains intact.

Security signals we found

01

MuSig nonce generation is security-critical; nonce reuse can leak private keys.

02

The PR description discusses a mutation that could enable nonce reuse, but the mutation is not in the committed code.

03

The change is test-only; no production cryptographic logic is altered.

Risk score

Why this scored 12/100

Our methodology →
Potential impact 0/30
Exploitability 0/25
Stealth signal 0/15
Affected reach 0/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.