Update McEliece suppression files for generic config #1677
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR updates the suppression files for the "clean" (pure C) implementation of Classic McEliece. I've run the tests both in a container built from the CI image and locally on my machine.
For now, I've labelled all of these as "issues", as I'm not knowledgeable enough about McEliece to confidently classify them as false positives or true instances of secret-dependent behaviour. I believe that this is in line with what we had done previously for the AVX2 constant-time failures.
To test:
Partially addresses #1666.
I suspect that this may also address #1540. @bhess @praveksharma is it plausible that the "env-specific" constant-time errors were simply caused by building without AVX2 optimization? There were previously no suppressions for the "clean" implementation.