Grant Application - Constant-Time Hardening and Explicit Timing Semantics for Zcash Rust Cryptography

Hi @zcg! Great news!

We wanted to share where we’ve landed after the last round of feedback, and make sure we’re aligned on next steps before moving forward.

As I said in my last message, during the arborist call we were suggested to include extra repositories in our analysis. We spoke with Daira-Emma and confirmed that the new scope would include 6 new repositories (zcash_note_encryption, sapling-crypto, orchard, zip32, pasta_curves, and zcash_spec). Such project’s scope extension requires a re-budgeting. By including analysis over all the requested repos, the new timeline would be 8-10 weeks of work (including reviewing time) and the updated total budget $25k. How should we channel this change in scope? We could always start working on the original approved scope and budget ( librustzcash only, 10k ) and tackle the extra requested repos on an independently submitted grant. We just want assurance we are all on the same page regarding scope & budget. Looking forward to your advice. Thanks!