Repository navigation
perf: adopt ring-go perf/hash-cache off-chain signing optimization - #49
Merged
Merged
Conversation
Adds ring-go's hash-cache off-chain fast path to the SDK as an opt-in, named alongside the existing deterministic default (mirrors ring-go's own Sign vs SignWithContext split). Dependency: - ring-go -> perf/hash-cache (0830a5c); go-dleq now a direct dep (types.Scalar used for the cached signer scalar). - pulls go-ethereum v1.16.9 -> v1.17.4 (CVE fixes; only active with the ethereum_secp256k1 cgo backend) and x/crypto/net/etc. signer.go: - Sign: unchanged behavior — deterministic, consensus-safe (Ring.Sign). Remains the default; existing callers keep identical semantics. - SignOffChain / SignOffChainWithRing: NEW opt-in off-chain fast path (Ring.SignWithContext). Caches one secret-free SignerContext per ring (sync.Map) and reuses it across signs; SkipSelfCheck enabled (safe: off-chain, always signed with the scalar the context was built from). OFF-CHAIN ONLY — never use on consensus-critical / gas-metered paths. - ClearSignerContextCache for session rollover; private-key scalar decoded once at construction (removes the per-call DecodeToScalar TODO). signer_test.go: - Sign: round-trip verify, tampered-message reject, asserts cache untouched. - SignOffChain: round-trip verify + cache populated. - Off-chain cache reuse across signs + ClearSignerContextCache. Both paths produce signatures that verify identically; Verify is unchanged. Build, vet, golangci-lint (0 issues), and tests pass. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Maps signer-context-cache call sites to the new Sign (deterministic) vs SignOffChain/SignOffChainWithRing (opt-in off-chain) split, plus the Go 1.26 toolchain requirement. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
golangci-lint v2.6.0 is built with go1.25.3 and refuses to lint a module
targeting go 1.26.4 ("Go language version used to build golangci-lint is
lower than the targeted Go version"). v2.11.3 is built with go1.26.1.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…lover Per PATH canary feedback: signerContextCache is keyed by ring pointer and grows one entry per session with no automatic eviction, so consumers must call ClearSignerContextCache() on session rollover or memory leaks slowly. Adds a prominent warning to the migration guide (TL;DR + step 3) and strengthens the ClearSignerContextCache doc comment. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Contributor
Author
✅ Canary validation (PATH, draft PR #517)PATH adopted this branch and validated on canary (beta-4, node-matched, 82 min, rc=0, live HTTP + WebSocket + hedge traffic):
Follow-up applied
Still gated on
|
go-ring cut the hash-cache release tag. Move from the branch-commit pseudo-version to v0.2.0. API unchanged (SignWithContext takes the private key per call). Build, vet, tests, and golangci-lint all pass. This removes the "pinned to a branch commit" merge blocker for PR #49. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
oten91
marked this pull request as ready for review
July 2, 2026 16:00
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adopts ring-go's
perf/hash-cacheoff-chain signing optimization as an opt-in, named path alongside the existing deterministicSign— mirroring ring-go's ownSignvsSignWithContextsplit.Supersedes the
perf/signer-context-cacheapproach (which overloadedSignwith off-chain-only behavior).Changes
signer.goSign— unchanged behavior: deterministic, consensus-safe (Ring.Sign). Existing callers keep identical semantics.SignOffChain/SignOffChainWithRing— new opt-in off-chain fast path (Ring.SignWithContext). Caches one secret-freeSignerContextper ring (sync.Map), reused across signs;SkipSelfCheckenabled (safe — off-chain, always signed with the scalar the context was built from). Off-chain only.ClearSignerContextCachefor session rollover; private-key scalar decoded once at construction.signer_test.go— round-trip verify for both paths, tampered-message reject, cache reuse + clear, assertsSignnever touches the cache.perf/hash-cache(0830a5c);go-dleqnow direct; go-ethereum → v1.17.4 (CVEs, cgo-only); x/crypto/net bumps.docs/migration-ring-go-hash-cache.mdfor PATH.Downstream (PATH etc.)
signer-context-cache,Signwas the cached path. HereSignis deterministic again — swapSign→SignOffChain,SignWithRing→SignOffChainWithRingto keep the speedup. LeavingSignas-is stays correct, just slower. See the migration doc.Verification
Build ✅ · vet ✅ · golangci-lint 0 issues ✅ · tests pass (both paths verify) ✅
ring-go is pinned to a branch commit, not a release tag. Keep off
mainuntil go-ring promoteshash-cacheto master/tags it, and until the gateway reports off-chain before/after numbers.🤖 Generated with Claude Code