Update SPHINCS+ "clean" suppression files #1683
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Update the Sphincs+ suppression files so that constant-time tests are green. For now I've classified all of the failures as "issues"; someone with more knowledge about SPHINCS+ might want to take a look and see whether or not they're false positives.
The "SHA2-f" variants of SPHINCS+ are pretty fast, so I've added them to the weekly constant-time runs. Hopefully this keep us honest with regards to keeping suppression files up to date. It seems likely that this change will catch most constant-time errors in the "SHAKE" and "SHA2-s" variants as well.
Resolves #1666, pending merge of #1677.