update blake2b test vectors

This commit is contained in:
koe 2024-02-21 19:42:51 -06:00
parent fa47c7b7d6
commit e151ff711f
3 changed files with 388 additions and 389 deletions

View file

@ -5,14 +5,14 @@ All rights reserved.
Redistribution and use in source and binary forms, with or without Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are met: modification, are permitted provided that the following conditions are met:
* Redistributions of source code must retain the above copyright * Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer. notice, this list of conditions and the following disclaimer.
* Redistributions in binary form must reproduce the above copyright * Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution. documentation and/or other materials provided with the distribution.
* Neither the name of the copyright holder nor the * Neither the name of the copyright holder nor the
names of its contributors may be used to endorse or promote products names of its contributors may be used to endorse or promote products
derived from this software without specific prior written permission. derived from this software without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
@ -40,7 +40,6 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
#include <string.h> #include <string.h>
#include <stdio.h> #include <stdio.h>
/// BEGIN: endian.h /// BEGIN: endian.h
#if defined(_MSC_VER) #if defined(_MSC_VER)
@ -53,9 +52,9 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
/* Argon2 Team - Begin Code */ /* Argon2 Team - Begin Code */
/* /*
Not an exhaustive list, but should cover the majority of modern platforms Not an exhaustive list, but should cover the majority of modern platforms
Additionally, the code will always be correct---this is only a performance Additionally, the code will always be correct---this is only a performance
tweak. tweak.
*/ */
#if (defined(__BYTE_ORDER__) && \ #if (defined(__BYTE_ORDER__) && \
(__BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__)) || \ (__BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__)) || \
@ -69,81 +68,81 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
static FORCE_INLINE uint32_t load32(const void *src) { static FORCE_INLINE uint32_t load32(const void *src) {
#if defined(NATIVE_LITTLE_ENDIAN) #if defined(NATIVE_LITTLE_ENDIAN)
uint32_t w; uint32_t w;
memcpy(&w, src, sizeof w); memcpy(&w, src, sizeof w);
return w; return w;
#else #else
const uint8_t *p = (const uint8_t *)src; const uint8_t *p = (const uint8_t *)src;
uint32_t w = *p++; uint32_t w = *p++;
w |= (uint32_t)(*p++) << 8; w |= (uint32_t)(*p++) << 8;
w |= (uint32_t)(*p++) << 16; w |= (uint32_t)(*p++) << 16;
w |= (uint32_t)(*p++) << 24; w |= (uint32_t)(*p++) << 24;
return w; return w;
#endif #endif
} }
static FORCE_INLINE uint64_t load64_native(const void *src) { static FORCE_INLINE uint64_t load64_native(const void *src) {
uint64_t w; uint64_t w;
memcpy(&w, src, sizeof w); memcpy(&w, src, sizeof w);
return w; return w;
} }
static FORCE_INLINE uint64_t load64(const void *src) { static FORCE_INLINE uint64_t load64(const void *src) {
#if defined(NATIVE_LITTLE_ENDIAN) #if defined(NATIVE_LITTLE_ENDIAN)
return load64_native(src); return load64_native(src);
#else #else
const uint8_t *p = (const uint8_t *)src; const uint8_t *p = (const uint8_t *)src;
uint64_t w = *p++; uint64_t w = *p++;
w |= (uint64_t)(*p++) << 8; w |= (uint64_t)(*p++) << 8;
w |= (uint64_t)(*p++) << 16; w |= (uint64_t)(*p++) << 16;
w |= (uint64_t)(*p++) << 24; w |= (uint64_t)(*p++) << 24;
w |= (uint64_t)(*p++) << 32; w |= (uint64_t)(*p++) << 32;
w |= (uint64_t)(*p++) << 40; w |= (uint64_t)(*p++) << 40;
w |= (uint64_t)(*p++) << 48; w |= (uint64_t)(*p++) << 48;
w |= (uint64_t)(*p++) << 56; w |= (uint64_t)(*p++) << 56;
return w; return w;
#endif #endif
} }
static FORCE_INLINE void store32(void *dst, uint32_t w) { static FORCE_INLINE void store32(void *dst, uint32_t w) {
#if defined(NATIVE_LITTLE_ENDIAN) #if defined(NATIVE_LITTLE_ENDIAN)
memcpy(dst, &w, sizeof w); memcpy(dst, &w, sizeof w);
#else #else
uint8_t *p = (uint8_t *)dst; uint8_t *p = (uint8_t *)dst;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
#endif #endif
} }
static FORCE_INLINE void store64_native(void *dst, uint64_t w) { static FORCE_INLINE void store64_native(void *dst, uint64_t w) {
memcpy(dst, &w, sizeof w); memcpy(dst, &w, sizeof w);
} }
static FORCE_INLINE void store64(void *dst, uint64_t w) { static FORCE_INLINE void store64(void *dst, uint64_t w) {
#if defined(NATIVE_LITTLE_ENDIAN) #if defined(NATIVE_LITTLE_ENDIAN)
store64_native(dst, w); store64_native(dst, w);
#else #else
uint8_t *p = (uint8_t *)dst; uint8_t *p = (uint8_t *)dst;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
#endif #endif
} }
@ -152,37 +151,37 @@ static FORCE_INLINE void store64(void *dst, uint64_t w) {
/// BEGIN: blake2-impl.h /// BEGIN: blake2-impl.h
static FORCE_INLINE uint64_t load48(const void *src) { static FORCE_INLINE uint64_t load48(const void *src) {
const uint8_t *p = (const uint8_t *)src; const uint8_t *p = (const uint8_t *)src;
uint64_t w = *p++; uint64_t w = *p++;
w |= (uint64_t)(*p++) << 8; w |= (uint64_t)(*p++) << 8;
w |= (uint64_t)(*p++) << 16; w |= (uint64_t)(*p++) << 16;
w |= (uint64_t)(*p++) << 24; w |= (uint64_t)(*p++) << 24;
w |= (uint64_t)(*p++) << 32; w |= (uint64_t)(*p++) << 32;
w |= (uint64_t)(*p++) << 40; w |= (uint64_t)(*p++) << 40;
return w; return w;
} }
static FORCE_INLINE void store48(void *dst, uint64_t w) { static FORCE_INLINE void store48(void *dst, uint64_t w) {
uint8_t *p = (uint8_t *)dst; uint8_t *p = (uint8_t *)dst;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
w >>= 8; w >>= 8;
*p++ = (uint8_t)w; *p++ = (uint8_t)w;
} }
static FORCE_INLINE uint32_t rotr32(const uint32_t w, const unsigned c) { static FORCE_INLINE uint32_t rotr32(const uint32_t w, const unsigned c) {
return (w >> c) | (w << (32 - c)); return (w >> c) | (w << (32 - c));
} }
static FORCE_INLINE uint64_t rotr64(const uint64_t w, const unsigned c) { static FORCE_INLINE uint64_t rotr64(const uint64_t w, const unsigned c) {
return (w >> c) | (w << (64 - c)); return (w >> c) | (w << (64 - c));
} }
/// END: blake2-impl.h /// END: blake2-impl.h
@ -194,166 +193,166 @@ void clear_internal_memory(void *mem, const size_t length) {
/// BEGIN: blake2b.c /// BEGIN: blake2b.c
static const uint64_t blake2b_IV[8] = { static const uint64_t blake2b_IV[8] = {
UINT64_C(0x6a09e667f3bcc908), UINT64_C(0xbb67ae8584caa73b), UINT64_C(0x6a09e667f3bcc908), UINT64_C(0xbb67ae8584caa73b),
UINT64_C(0x3c6ef372fe94f82b), UINT64_C(0xa54ff53a5f1d36f1), UINT64_C(0x3c6ef372fe94f82b), UINT64_C(0xa54ff53a5f1d36f1),
UINT64_C(0x510e527fade682d1), UINT64_C(0x9b05688c2b3e6c1f), UINT64_C(0x510e527fade682d1), UINT64_C(0x9b05688c2b3e6c1f),
UINT64_C(0x1f83d9abfb41bd6b), UINT64_C(0x5be0cd19137e2179) }; UINT64_C(0x1f83d9abfb41bd6b), UINT64_C(0x5be0cd19137e2179) };
static const unsigned int blake2b_sigma[12][16] = { static const unsigned int blake2b_sigma[12][16] = {
{0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15}, {0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15},
{14, 10, 4, 8, 9, 15, 13, 6, 1, 12, 0, 2, 11, 7, 5, 3}, {14, 10, 4, 8, 9, 15, 13, 6, 1, 12, 0, 2, 11, 7, 5, 3},
{11, 8, 12, 0, 5, 2, 15, 13, 10, 14, 3, 6, 7, 1, 9, 4}, {11, 8, 12, 0, 5, 2, 15, 13, 10, 14, 3, 6, 7, 1, 9, 4},
{7, 9, 3, 1, 13, 12, 11, 14, 2, 6, 5, 10, 4, 0, 15, 8}, {7, 9, 3, 1, 13, 12, 11, 14, 2, 6, 5, 10, 4, 0, 15, 8},
{9, 0, 5, 7, 2, 4, 10, 15, 14, 1, 11, 12, 6, 8, 3, 13}, {9, 0, 5, 7, 2, 4, 10, 15, 14, 1, 11, 12, 6, 8, 3, 13},
{2, 12, 6, 10, 0, 11, 8, 3, 4, 13, 7, 5, 15, 14, 1, 9}, {2, 12, 6, 10, 0, 11, 8, 3, 4, 13, 7, 5, 15, 14, 1, 9},
{12, 5, 1, 15, 14, 13, 4, 10, 0, 7, 6, 3, 9, 2, 8, 11}, {12, 5, 1, 15, 14, 13, 4, 10, 0, 7, 6, 3, 9, 2, 8, 11},
{13, 11, 7, 14, 12, 1, 3, 9, 5, 0, 15, 4, 8, 6, 2, 10}, {13, 11, 7, 14, 12, 1, 3, 9, 5, 0, 15, 4, 8, 6, 2, 10},
{6, 15, 14, 9, 11, 3, 0, 8, 12, 2, 13, 7, 1, 4, 10, 5}, {6, 15, 14, 9, 11, 3, 0, 8, 12, 2, 13, 7, 1, 4, 10, 5},
{10, 2, 8, 4, 7, 6, 1, 5, 15, 11, 9, 14, 3, 12, 13, 0}, {10, 2, 8, 4, 7, 6, 1, 5, 15, 11, 9, 14, 3, 12, 13, 0},
{0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15}, {0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15},
{14, 10, 4, 8, 9, 15, 13, 6, 1, 12, 0, 2, 11, 7, 5, 3}, {14, 10, 4, 8, 9, 15, 13, 6, 1, 12, 0, 2, 11, 7, 5, 3},
}; };
static FORCE_INLINE void blake2b_set_lastnode(blake2b_state *S) { static FORCE_INLINE void blake2b_set_lastnode(blake2b_state *S) {
S->f[1] = (uint64_t)-1; S->f[1] = (uint64_t)-1;
} }
static FORCE_INLINE void blake2b_set_lastblock(blake2b_state *S) { static FORCE_INLINE void blake2b_set_lastblock(blake2b_state *S) {
if (S->last_node) { if (S->last_node) {
blake2b_set_lastnode(S); blake2b_set_lastnode(S);
} }
S->f[0] = (uint64_t)-1; S->f[0] = (uint64_t)-1;
} }
static FORCE_INLINE void blake2b_increment_counter(blake2b_state *S, static FORCE_INLINE void blake2b_increment_counter(blake2b_state *S,
uint64_t inc) { uint64_t inc) {
S->t[0] += inc; S->t[0] += inc;
S->t[1] += (S->t[0] < inc); S->t[1] += (S->t[0] < inc);
} }
static FORCE_INLINE void blake2b_invalidate_state(blake2b_state *S) { static FORCE_INLINE void blake2b_invalidate_state(blake2b_state *S) {
clear_internal_memory(S, sizeof(*S)); /* wipe */ clear_internal_memory(S, sizeof(*S)); /* wipe */
blake2b_set_lastblock(S); /* invalidate for further use */ blake2b_set_lastblock(S); /* invalidate for further use */
} }
static FORCE_INLINE void blake2b_init0(blake2b_state *S) { static FORCE_INLINE void blake2b_init0(blake2b_state *S) {
memset(S, 0, sizeof(*S)); memset(S, 0, sizeof(*S));
memcpy(S->h, blake2b_IV, sizeof(S->h)); memcpy(S->h, blake2b_IV, sizeof(S->h));
} }
int blake2b_init_param(blake2b_state *S, const blake2b_param *P) { int blake2b_init_param(blake2b_state *S, const blake2b_param *P) {
const unsigned char *p = (const unsigned char *)P; const unsigned char *p = (const unsigned char *)P;
unsigned int i; unsigned int i;
if (NULL == P || NULL == S) { if (NULL == P || NULL == S) {
return -1; return -1;
} }
blake2b_init0(S); blake2b_init0(S);
/* IV XOR Parameter Block */ /* IV XOR Parameter Block */
for (i = 0; i < 8; ++i) { for (i = 0; i < 8; ++i) {
S->h[i] ^= load64(&p[i * sizeof(S->h[i])]); S->h[i] ^= load64(&p[i * sizeof(S->h[i])]);
} }
S->outlen = P->digest_length; S->outlen = P->digest_length;
return 0; return 0;
} }
/* Sequential blake2b initialization */ /* Sequential blake2b initialization */
int blake2b_init(blake2b_state *S, size_t outlen) { int blake2b_init(blake2b_state *S, size_t outlen) {
blake2b_param P; blake2b_param P;
if (S == NULL) { if (S == NULL) {
return -1; return -1;
} }
if ((outlen == 0) || (outlen > BLAKE2B_OUTBYTES)) { if ((outlen == 0) || (outlen > BLAKE2B_OUTBYTES)) {
blake2b_invalidate_state(S); blake2b_invalidate_state(S);
return -1; return -1;
} }
/* Setup Parameter Block for unkeyed BLAKE2 */ /* Setup Parameter Block for unkeyed BLAKE2 */
P.digest_length = (uint8_t)outlen; P.digest_length = (uint8_t)outlen;
P.key_length = 0; P.key_length = 0;
P.fanout = 1; P.fanout = 1;
P.depth = 1; P.depth = 1;
P.leaf_length = 0; P.leaf_length = 0;
P.node_offset = 0; P.node_offset = 0;
P.node_depth = 0; P.node_depth = 0;
P.inner_length = 0; P.inner_length = 0;
memset(P.reserved, 0, sizeof(P.reserved)); memset(P.reserved, 0, sizeof(P.reserved));
memset(P.salt, 0, sizeof(P.salt)); memset(P.salt, 0, sizeof(P.salt));
memset(P.personal, 0, sizeof(P.personal)); memset(P.personal, 0, sizeof(P.personal));
return blake2b_init_param(S, &P); return blake2b_init_param(S, &P);
} }
int blake2b_init_key(blake2b_state *S, size_t outlen, const void *key, size_t keylen) { int blake2b_init_key(blake2b_state *S, size_t outlen, const void *key, size_t keylen) {
blake2b_param P; blake2b_param P;
if (S == NULL) { if (S == NULL) {
return -1; return -1;
} }
if ((outlen == 0) || (outlen > BLAKE2B_OUTBYTES)) { if ((outlen == 0) || (outlen > BLAKE2B_OUTBYTES)) {
blake2b_invalidate_state(S); blake2b_invalidate_state(S);
return -1; return -1;
} }
if ((key == 0) || (keylen == 0) || (keylen > BLAKE2B_KEYBYTES)) { if ((key == 0) || (keylen == 0) || (keylen > BLAKE2B_KEYBYTES)) {
blake2b_invalidate_state(S); blake2b_invalidate_state(S);
return -1; return -1;
} }
/* Setup Parameter Block for keyed BLAKE2 */ /* Setup Parameter Block for keyed BLAKE2 */
P.digest_length = (uint8_t)outlen; P.digest_length = (uint8_t)outlen;
P.key_length = (uint8_t)keylen; P.key_length = (uint8_t)keylen;
P.fanout = 1; P.fanout = 1;
P.depth = 1; P.depth = 1;
P.leaf_length = 0; P.leaf_length = 0;
P.node_offset = 0; P.node_offset = 0;
P.node_depth = 0; P.node_depth = 0;
P.inner_length = 0; P.inner_length = 0;
memset(P.reserved, 0, sizeof(P.reserved)); memset(P.reserved, 0, sizeof(P.reserved));
memset(P.salt, 0, sizeof(P.salt)); memset(P.salt, 0, sizeof(P.salt));
memset(P.personal, 0, sizeof(P.personal)); memset(P.personal, 0, sizeof(P.personal));
if (blake2b_init_param(S, &P) < 0) { if (blake2b_init_param(S, &P) < 0) {
blake2b_invalidate_state(S); blake2b_invalidate_state(S);
return -1; return -1;
} }
{ {
uint8_t block[BLAKE2B_BLOCKBYTES]; uint8_t block[BLAKE2B_BLOCKBYTES];
memset(block, 0, BLAKE2B_BLOCKBYTES); memset(block, 0, BLAKE2B_BLOCKBYTES);
memcpy(block, key, keylen); memcpy(block, key, keylen);
blake2b_update(S, block, BLAKE2B_BLOCKBYTES); blake2b_update(S, block, BLAKE2B_BLOCKBYTES);
/* Burn the key from stack */ /* Burn the key from stack */
clear_internal_memory(block, BLAKE2B_BLOCKBYTES); clear_internal_memory(block, BLAKE2B_BLOCKBYTES);
} }
return 0; return 0;
} }
static void blake2b_compress(blake2b_state *S, const uint8_t *block) { static void blake2b_compress(blake2b_state *S, const uint8_t *block) {
uint64_t m[16]; uint64_t m[16];
uint64_t v[16]; uint64_t v[16];
unsigned int i, r; unsigned int i, r;
for (i = 0; i < 16; ++i) { for (i = 0; i < 16; ++i) {
m[i] = load64(block + i * sizeof(m[i])); m[i] = load64(block + i * sizeof(m[i]));
} }
for (i = 0; i < 8; ++i) { for (i = 0; i < 8; ++i) {
v[i] = S->h[i]; v[i] = S->h[i];
} }
v[8] = blake2b_IV[0]; v[8] = blake2b_IV[0];
v[9] = blake2b_IV[1]; v[9] = blake2b_IV[1];
v[10] = blake2b_IV[2]; v[10] = blake2b_IV[2];
v[11] = blake2b_IV[3]; v[11] = blake2b_IV[3];
v[12] = blake2b_IV[4] ^ S->t[0]; v[12] = blake2b_IV[4] ^ S->t[0];
v[13] = blake2b_IV[5] ^ S->t[1]; v[13] = blake2b_IV[5] ^ S->t[1];
v[14] = blake2b_IV[6] ^ S->f[0]; v[14] = blake2b_IV[6] ^ S->f[0];
v[15] = blake2b_IV[7] ^ S->f[1]; v[15] = blake2b_IV[7] ^ S->f[1];
#define G(r, i, a, b, c, d) \ #define G(r, i, a, b, c, d) \
do { \ do { \
@ -379,140 +378,140 @@ static void blake2b_compress(blake2b_state *S, const uint8_t *block) {
G(r, 7, v[3], v[4], v[9], v[14]); \ G(r, 7, v[3], v[4], v[9], v[14]); \
} while ((void)0, 0) } while ((void)0, 0)
for (r = 0; r < 12; ++r) { for (r = 0; r < 12; ++r) {
ROUND(r); ROUND(r);
} }
for (i = 0; i < 8; ++i) { for (i = 0; i < 8; ++i) {
S->h[i] = S->h[i] ^ v[i] ^ v[i + 8]; S->h[i] = S->h[i] ^ v[i] ^ v[i + 8];
} }
#undef G #undef G
#undef ROUND #undef ROUND
} }
int blake2b_update(blake2b_state *S, const void *in, size_t inlen) { int blake2b_update(blake2b_state *S, const void *in, size_t inlen) {
const uint8_t *pin = (const uint8_t *)in; const uint8_t *pin = (const uint8_t *)in;
if (inlen == 0) { if (inlen == 0) {
return 0; return 0;
} }
/* Sanity check */ /* Sanity check */
if (S == NULL || in == NULL) { if (S == NULL || in == NULL) {
return -1; return -1;
} }
/* Is this a reused state? */ /* Is this a reused state? */
if (S->f[0] != 0) { if (S->f[0] != 0) {
return -1; return -1;
} }
if (S->buflen + inlen > BLAKE2B_BLOCKBYTES) { if (S->buflen + inlen > BLAKE2B_BLOCKBYTES) {
/* Complete current block */ /* Complete current block */
size_t left = S->buflen; size_t left = S->buflen;
size_t fill = BLAKE2B_BLOCKBYTES - left; size_t fill = BLAKE2B_BLOCKBYTES - left;
memcpy(&S->buf[left], pin, fill); memcpy(&S->buf[left], pin, fill);
blake2b_increment_counter(S, BLAKE2B_BLOCKBYTES); blake2b_increment_counter(S, BLAKE2B_BLOCKBYTES);
blake2b_compress(S, S->buf); blake2b_compress(S, S->buf);
S->buflen = 0; S->buflen = 0;
inlen -= fill; inlen -= fill;
pin += fill; pin += fill;
/* Avoid buffer copies when possible */ /* Avoid buffer copies when possible */
while (inlen > BLAKE2B_BLOCKBYTES) { while (inlen > BLAKE2B_BLOCKBYTES) {
blake2b_increment_counter(S, BLAKE2B_BLOCKBYTES); blake2b_increment_counter(S, BLAKE2B_BLOCKBYTES);
blake2b_compress(S, pin); blake2b_compress(S, pin);
inlen -= BLAKE2B_BLOCKBYTES; inlen -= BLAKE2B_BLOCKBYTES;
pin += BLAKE2B_BLOCKBYTES; pin += BLAKE2B_BLOCKBYTES;
} }
} }
memcpy(&S->buf[S->buflen], pin, inlen); memcpy(&S->buf[S->buflen], pin, inlen);
S->buflen += (unsigned int)inlen; S->buflen += (unsigned int)inlen;
return 0; return 0;
} }
int blake2b_final(blake2b_state *S, void *out, size_t outlen) { int blake2b_final(blake2b_state *S, void *out, size_t outlen) {
uint8_t buffer[BLAKE2B_OUTBYTES] = { 0 }; uint8_t buffer[BLAKE2B_OUTBYTES] = { 0 };
unsigned int i; unsigned int i;
/* Sanity checks */ /* Sanity checks */
if (S == NULL || out == NULL || outlen < S->outlen) { if (S == NULL || out == NULL || outlen < S->outlen) {
return -1; return -1;
} }
/* Is this a reused state? */ /* Is this a reused state? */
if (S->f[0] != 0) { if (S->f[0] != 0) {
return -1; return -1;
} }
blake2b_increment_counter(S, S->buflen); blake2b_increment_counter(S, S->buflen);
blake2b_set_lastblock(S); blake2b_set_lastblock(S);
memset(&S->buf[S->buflen], 0, BLAKE2B_BLOCKBYTES - S->buflen); /* Padding */ memset(&S->buf[S->buflen], 0, BLAKE2B_BLOCKBYTES - S->buflen); /* Padding */
blake2b_compress(S, S->buf); blake2b_compress(S, S->buf);
for (i = 0; i < 8; ++i) { /* Output full hash to temp buffer */ for (i = 0; i < 8; ++i) { /* Output full hash to temp buffer */
store64(buffer + sizeof(S->h[i]) * i, S->h[i]); store64(buffer + sizeof(S->h[i]) * i, S->h[i]);
} }
memcpy(out, buffer, S->outlen); memcpy(out, buffer, S->outlen);
clear_internal_memory(buffer, sizeof(buffer)); clear_internal_memory(buffer, sizeof(buffer));
clear_internal_memory(S->buf, sizeof(S->buf)); clear_internal_memory(S->buf, sizeof(S->buf));
clear_internal_memory(S->h, sizeof(S->h)); clear_internal_memory(S->h, sizeof(S->h));
return 0; return 0;
} }
int blake2b(void *out, size_t outlen, const void *in, size_t inlen, int blake2b(void *out, size_t outlen, const void *in, size_t inlen,
const void *key, size_t keylen) { const void *key, size_t keylen) {
blake2b_state S; blake2b_state S;
int ret = -1; int ret = -1;
/* Verify parameters */ /* Verify parameters */
if (NULL == in && inlen > 0) { if (NULL == in && inlen > 0) {
goto fail; goto fail;
} }
if (NULL == out || outlen == 0 || outlen > BLAKE2B_OUTBYTES) { if (NULL == out || outlen == 0 || outlen > BLAKE2B_OUTBYTES) {
goto fail; goto fail;
} }
if ((NULL == key && keylen > 0) || keylen > BLAKE2B_KEYBYTES) { if ((NULL == key && keylen > 0) || keylen > BLAKE2B_KEYBYTES) {
goto fail; goto fail;
} }
if (keylen > 0) { if (keylen > 0) {
if (blake2b_init_key(&S, outlen, key, keylen) < 0) { if (blake2b_init_key(&S, outlen, key, keylen) < 0) {
goto fail; goto fail;
} }
} }
else { else {
if (blake2b_init(&S, outlen) < 0) { if (blake2b_init(&S, outlen) < 0) {
goto fail; goto fail;
} }
} }
if (blake2b_update(&S, in, inlen) < 0) { if (blake2b_update(&S, in, inlen) < 0) {
goto fail; goto fail;
} }
ret = blake2b_final(&S, out, outlen); ret = blake2b_final(&S, out, outlen);
fail: fail:
clear_internal_memory(&S, sizeof(S)); clear_internal_memory(&S, sizeof(S));
return ret; return ret;
} }
/* Argon2 Team - Begin Code */ /* Argon2 Team - Begin Code */
int blake2b_long(void *pout, size_t outlen, const void *in, size_t inlen) { int blake2b_long(void *pout, size_t outlen, const void *in, size_t inlen) {
uint8_t *out = (uint8_t *)pout; uint8_t *out = (uint8_t *)pout;
blake2b_state blake_state; blake2b_state blake_state;
uint8_t outlen_bytes[sizeof(uint32_t)] = { 0 }; uint8_t outlen_bytes[sizeof(uint32_t)] = { 0 };
int ret = -1; int ret = -1;
if (outlen > UINT32_MAX) { if (outlen > UINT32_MAX) {
goto fail; goto fail;
} }
/* Ensure little-endian byte order! */ /* Ensure little-endian byte order! */
store32(outlen_bytes, (uint32_t)outlen); store32(outlen_bytes, (uint32_t)outlen);
#define TRY(statement) \ #define TRY(statement) \
do { \ do { \
@ -522,41 +521,41 @@ int blake2b_long(void *pout, size_t outlen, const void *in, size_t inlen) {
} \ } \
} while ((void)0, 0) } while ((void)0, 0)
if (outlen <= BLAKE2B_OUTBYTES) { if (outlen <= BLAKE2B_OUTBYTES) {
TRY(blake2b_init(&blake_state, outlen)); TRY(blake2b_init(&blake_state, outlen));
TRY(blake2b_update(&blake_state, outlen_bytes, sizeof(outlen_bytes))); TRY(blake2b_update(&blake_state, outlen_bytes, sizeof(outlen_bytes)));
TRY(blake2b_update(&blake_state, in, inlen)); TRY(blake2b_update(&blake_state, in, inlen));
TRY(blake2b_final(&blake_state, out, outlen)); TRY(blake2b_final(&blake_state, out, outlen));
} }
else { else {
uint32_t toproduce; uint32_t toproduce;
uint8_t out_buffer[BLAKE2B_OUTBYTES]; uint8_t out_buffer[BLAKE2B_OUTBYTES];
uint8_t in_buffer[BLAKE2B_OUTBYTES]; uint8_t in_buffer[BLAKE2B_OUTBYTES];
TRY(blake2b_init(&blake_state, BLAKE2B_OUTBYTES)); TRY(blake2b_init(&blake_state, BLAKE2B_OUTBYTES));
TRY(blake2b_update(&blake_state, outlen_bytes, sizeof(outlen_bytes))); TRY(blake2b_update(&blake_state, outlen_bytes, sizeof(outlen_bytes)));
TRY(blake2b_update(&blake_state, in, inlen)); TRY(blake2b_update(&blake_state, in, inlen));
TRY(blake2b_final(&blake_state, out_buffer, BLAKE2B_OUTBYTES)); TRY(blake2b_final(&blake_state, out_buffer, BLAKE2B_OUTBYTES));
memcpy(out, out_buffer, BLAKE2B_OUTBYTES / 2); memcpy(out, out_buffer, BLAKE2B_OUTBYTES / 2);
out += BLAKE2B_OUTBYTES / 2; out += BLAKE2B_OUTBYTES / 2;
toproduce = (uint32_t)outlen - BLAKE2B_OUTBYTES / 2; toproduce = (uint32_t)outlen - BLAKE2B_OUTBYTES / 2;
while (toproduce > BLAKE2B_OUTBYTES) { while (toproduce > BLAKE2B_OUTBYTES) {
memcpy(in_buffer, out_buffer, BLAKE2B_OUTBYTES); memcpy(in_buffer, out_buffer, BLAKE2B_OUTBYTES);
TRY(blake2b(out_buffer, BLAKE2B_OUTBYTES, in_buffer, TRY(blake2b(out_buffer, BLAKE2B_OUTBYTES, in_buffer,
BLAKE2B_OUTBYTES, NULL, 0)); BLAKE2B_OUTBYTES, NULL, 0));
memcpy(out, out_buffer, BLAKE2B_OUTBYTES / 2); memcpy(out, out_buffer, BLAKE2B_OUTBYTES / 2);
out += BLAKE2B_OUTBYTES / 2; out += BLAKE2B_OUTBYTES / 2;
toproduce -= BLAKE2B_OUTBYTES / 2; toproduce -= BLAKE2B_OUTBYTES / 2;
} }
memcpy(in_buffer, out_buffer, BLAKE2B_OUTBYTES); memcpy(in_buffer, out_buffer, BLAKE2B_OUTBYTES);
TRY(blake2b(out_buffer, toproduce, in_buffer, BLAKE2B_OUTBYTES, NULL, TRY(blake2b(out_buffer, toproduce, in_buffer, BLAKE2B_OUTBYTES, NULL,
0)); 0));
memcpy(out, out_buffer, toproduce); memcpy(out, out_buffer, toproduce);
} }
fail: fail:
clear_internal_memory(&blake_state, sizeof(blake_state)); clear_internal_memory(&blake_state, sizeof(blake_state));
return ret; return ret;
#undef TRY #undef TRY
} }
/* Argon2 Team - End Code */ /* Argon2 Team - End Code */

View file

@ -5,14 +5,14 @@ All rights reserved.
Redistribution and use in source and binary forms, with or without Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are met: modification, are permitted provided that the following conditions are met:
* Redistributions of source code must retain the above copyright * Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer. notice, this list of conditions and the following disclaimer.
* Redistributions in binary form must reproduce the above copyright * Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution. documentation and/or other materials provided with the distribution.
* Neither the name of the copyright holder nor the * Neither the name of the copyright holder nor the
names of its contributors may be used to endorse or promote products names of its contributors may be used to endorse or promote products
derived from this software without specific prior written permission. derived from this software without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
@ -44,49 +44,49 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
extern "C" { extern "C" {
#endif #endif
enum blake2b_constant { enum blake2b_constant {
BLAKE2B_BLOCKBYTES = 128, BLAKE2B_BLOCKBYTES = 128,
BLAKE2B_OUTBYTES = 64, BLAKE2B_OUTBYTES = 64,
BLAKE2B_KEYBYTES = 64, BLAKE2B_KEYBYTES = 64,
BLAKE2B_SALTBYTES = 16, BLAKE2B_SALTBYTES = 16,
BLAKE2B_PERSONALBYTES = 16 BLAKE2B_PERSONALBYTES = 16
}; };
#pragma pack(push, 1) #pragma pack(push, 1)
typedef struct __blake2b_param { typedef struct __blake2b_param {
uint8_t digest_length; /* 1 */ uint8_t digest_length; /* 1 */
uint8_t key_length; /* 2 */ uint8_t key_length; /* 2 */
uint8_t fanout; /* 3 */ uint8_t fanout; /* 3 */
uint8_t depth; /* 4 */ uint8_t depth; /* 4 */
uint32_t leaf_length; /* 8 */ uint32_t leaf_length; /* 8 */
uint64_t node_offset; /* 16 */ uint64_t node_offset; /* 16 */
uint8_t node_depth; /* 17 */ uint8_t node_depth; /* 17 */
uint8_t inner_length; /* 18 */ uint8_t inner_length; /* 18 */
uint8_t reserved[14]; /* 32 */ uint8_t reserved[14]; /* 32 */
uint8_t salt[BLAKE2B_SALTBYTES]; /* 48 */ uint8_t salt[BLAKE2B_SALTBYTES]; /* 48 */
uint8_t personal[BLAKE2B_PERSONALBYTES]; /* 64 */ uint8_t personal[BLAKE2B_PERSONALBYTES]; /* 64 */
} blake2b_param; } blake2b_param;
#pragma pack(pop) #pragma pack(pop)
typedef struct __blake2b_state { typedef struct __blake2b_state {
uint64_t h[8]; uint64_t h[8];
uint64_t t[2]; uint64_t t[2];
uint64_t f[2]; uint64_t f[2];
uint8_t buf[BLAKE2B_BLOCKBYTES]; uint8_t buf[BLAKE2B_BLOCKBYTES];
unsigned buflen; unsigned buflen;
unsigned outlen; unsigned outlen;
uint8_t last_node; uint8_t last_node;
} blake2b_state; } blake2b_state;
/* Ensure param structs have not been wrongly padded */ /* Ensure param structs have not been wrongly padded */
/* Poor man's static_assert */ /* Poor man's static_assert */
enum { enum {
blake2_size_check_0 = 1 / !!(CHAR_BIT == 8), blake2_size_check_0 = 1 / !!(CHAR_BIT == 8),
blake2_size_check_2 = blake2_size_check_2 =
1 / !!(sizeof(blake2b_param) == sizeof(uint64_t) * CHAR_BIT) 1 / !!(sizeof(blake2b_param) == sizeof(uint64_t) * CHAR_BIT)
}; };
// crypto namespace (fixes naming collisions with libsodium) // crypto namespace (fixes naming collisions with libsodium)
#define blake2b_init crypto_blake2b_init #define blake2b_init crypto_blake2b_init
#define blake2b_init_key crypto_blake2b_init_key #define blake2b_init_key crypto_blake2b_init_key
#define blake2b_init_param crypto_blake2b_init_param #define blake2b_init_param crypto_blake2b_init_param
@ -95,21 +95,21 @@ extern "C" {
#define blake2b crypto_blake2b #define blake2b crypto_blake2b
#define blake2b_long crypto_blake2b_long #define blake2b_long crypto_blake2b_long
/* Streaming API */ /* Streaming API */
int blake2b_init(blake2b_state *S, size_t outlen); int blake2b_init(blake2b_state *S, size_t outlen);
int blake2b_init_key(blake2b_state *S, size_t outlen, const void *key, int blake2b_init_key(blake2b_state *S, size_t outlen, const void *key,
size_t keylen); size_t keylen);
int blake2b_init_param(blake2b_state *S, const blake2b_param *P); int blake2b_init_param(blake2b_state *S, const blake2b_param *P);
int blake2b_update(blake2b_state *S, const void *in, size_t inlen); int blake2b_update(blake2b_state *S, const void *in, size_t inlen);
int blake2b_final(blake2b_state *S, void *out, size_t outlen); int blake2b_final(blake2b_state *S, void *out, size_t outlen);
/* Simple API */ /* Simple API */
int blake2b(void *out, size_t outlen, const void *in, size_t inlen, int blake2b(void *out, size_t outlen, const void *in, size_t inlen,
const void *key, size_t keylen); const void *key, size_t keylen);
/* Argon2 Team - Begin Code */ /* Argon2 Team - Begin Code */
int blake2b_long(void *out, size_t outlen, const void *in, size_t inlen); int blake2b_long(void *out, size_t outlen, const void *in, size_t inlen);
/* Argon2 Team - End Code */ /* Argon2 Team - End Code */
#if defined(__cplusplus) #if defined(__cplusplus)
} }

View file

@ -43,7 +43,7 @@
#include "warnings.h" #include "warnings.h"
#include "crypto/hash.h" #include "crypto/hash.h"
#include "crypto/variant2_int_sqrt.h" #include "crypto/variant2_int_sqrt.h"
#include "randomx/src/blake2/blake2.h" #include "crypto/blake2b.h"
#include "../io.h" #include "../io.h"
using namespace std; using namespace std;