[3.9] bpo-40791: Make compare_digest more constant-time. (GH-20444) by miss-islington · Pull Request #23436 · python/cpython

@ssbr @miss-islington

* bpo-40791: Make compare_digest more constant-time.

The existing volatile `left`/`right` pointers guarantee that the reads will all occur, but does not guarantee that they will be _used_. So a compiler can still short-circuit the loop, saving e.g. the overhead of doing the xors and especially the overhead of the data dependency between `result` and the reads. That would change performance depending on where the first unequal byte occurs. This change removes that optimization.

(This is change GH-1 from https://bugs.python.org/issue40791 .)
(cherry picked from commit 3172936)

Co-authored-by: Devin Jeanpierre <jeanpierreda@google.com>

@ssbr ssbr mannequin mentioned this pull request

Aug 24, 2023