{
  "path": "tools/hostapd_pqc/cbmc_glue_harness.c",
  "find": "    for (size_t i = 0; i < n; i++) d |= (uint8_t)(a[i] ^ b[i]);",
  "replace": "    for (size_t i = 0; i < 1; i++) d |= (uint8_t)(a[i] ^ b[i]);",
  "why": "The constant-time compare under proof now checks only the first byte, so it accepts tokens that differ after byte one. CBMC finds the counterexample to ct_eq == spec_eq, harness_ct_eq (and harness_token, which calls it) fail verification, and the gate fails. Measured by the lab at S03 (dataroom/witness_quality.json cbmc index 0)."
}
