libp2p / libp2p/rust-libp2p

identity: fuzz `Keypair::sign` to check whether our configuration can ever fail on RSA

Open
#4,650 10 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
5.6k
Forks
1.3k
Avg merge
8h 47m
Merged PRs (30d)
19

Description

Description

Currently, KeyPair::sign can return an error if the keypair is RSA. This is annoying and leads to many "this should never happen" errors. We should fuzz the interface to check whether that can actually happen and making it infallible if we can't detect any cases.

Motivation

Infallible code is easier to reason about.

Current Implementation

The function can technically fail.

Are you planning to do it yourself in a pull request ?

Yes

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the KeyPair::sign interface and inspect its RSA error path. Add fuzz coverage for RSA signing to determine whether the configured interface can fail; done means the fuzzing results establish the behavior and the infallibility decision is reflected in the interface.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cryptography, networking
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.