3 ms·
You really do need to look at the whole chain. Of course, if Wasm had constant-time annotations as suggested by the article author, you’d expect wasm-opt to res
by codeflo 5y ago
You really do need to look at the whole chain. Of course, if Wasm had constant-time annotations as suggested by the article author, you’d expect wasm-opt to respect those.
Then there are steps below that layer to consider as well. Maybe not so relevant when targeting Wasm, but x86 code is increasingly executed inside emulators on ARM chips. Do those respect the constant-timeness?
And what about processor microcode and fused instructions, can a future CPU include an optimization that will un-constant-time your code? (In other words: I really don’t know, are there constant-time guarantees made by the ISA?)
- woodruffw 5y ago> (In other words: I really don’t know, are there constant-time guarantees made by the ISA?) Not on AMD64, at least: neither Intel nor AMD will guarantee the timing behavior or timing complexity of an instruction between processors. REP prefixes with string/data operations exemplify this -- they historically had data-dependent timings, but have become increasingly decoupled as both Intel and AMD have shoved "fast string" modes into ucode.