update main-with-bazel from master branch
This commit is contained in:
@@ -251,6 +251,7 @@ crypto_internal_headers = [
|
||||
"src/crypto/fipsmodule/tls/internal.h",
|
||||
"src/crypto/hrss/internal.h",
|
||||
"src/crypto/internal.h",
|
||||
"src/crypto/kyber/internal.h",
|
||||
"src/crypto/lhash/internal.h",
|
||||
"src/crypto/obj/obj_dat.h",
|
||||
"src/crypto/pkcs7/internal.h",
|
||||
@@ -377,6 +378,7 @@ crypto_sources = [
|
||||
"src/crypto/hkdf/hkdf.c",
|
||||
"src/crypto/hpke/hpke.c",
|
||||
"src/crypto/hrss/hrss.c",
|
||||
"src/crypto/kyber/keccak.c",
|
||||
"src/crypto/lhash/lhash.c",
|
||||
"src/crypto/mem.c",
|
||||
"src/crypto/obj/obj.c",
|
||||
|
||||
@@ -40,6 +40,7 @@ test_support_sources = [
|
||||
"src/crypto/fipsmodule/tls/internal.h",
|
||||
"src/crypto/hrss/internal.h",
|
||||
"src/crypto/internal.h",
|
||||
"src/crypto/kyber/internal.h",
|
||||
"src/crypto/lhash/internal.h",
|
||||
"src/crypto/obj/obj_dat.h",
|
||||
"src/crypto/pkcs7/internal.h",
|
||||
@@ -120,6 +121,7 @@ crypto_test_sources = [
|
||||
"src/crypto/hpke/hpke_test.cc",
|
||||
"src/crypto/hrss/hrss_test.cc",
|
||||
"src/crypto/impl_dispatch_test.cc",
|
||||
"src/crypto/kyber/kyber_test.cc",
|
||||
"src/crypto/lhash/lhash_test.cc",
|
||||
"src/crypto/obj/obj_test.cc",
|
||||
"src/crypto/pem/pem_test.cc",
|
||||
@@ -213,6 +215,7 @@ crypto_test_data = [
|
||||
"src/crypto/fipsmodule/rand/ctrdrbg_vectors.txt",
|
||||
"src/crypto/hmac_extra/hmac_tests.txt",
|
||||
"src/crypto/hpke/hpke_test_vectors.txt",
|
||||
"src/crypto/kyber/keccak_tests.txt",
|
||||
"src/crypto/pkcs8/test/empty_password.p12",
|
||||
"src/crypto/pkcs8/test/no_encryption.p12",
|
||||
"src/crypto/pkcs8/test/nss.p12",
|
||||
|
||||
@@ -376,6 +376,7 @@ add_library(
|
||||
src/crypto/hkdf/hkdf.c
|
||||
src/crypto/hpke/hpke.c
|
||||
src/crypto/hrss/hrss.c
|
||||
src/crypto/kyber/keccak.c
|
||||
src/crypto/lhash/lhash.c
|
||||
src/crypto/mem.c
|
||||
src/crypto/obj/obj.c
|
||||
|
||||
@@ -15,6 +15,7 @@
|
||||
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
L$zero:
|
||||
.long 0,0,0,0
|
||||
@@ -44,6 +45,7 @@ L$incz:
|
||||
L$sixteen:
|
||||
.long 16,16,16,16,16,16,16,16,16,16,16,16,16,16,16,16
|
||||
.byte 67,104,97,67,104,97,50,48,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.text
|
||||
.globl _ChaCha20_ctr32
|
||||
.private_extern _ChaCha20_ctr32
|
||||
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
#if defined(BORINGSSL_PREFIX)
|
||||
#include <boringssl_prefix_symbols_asm.h>
|
||||
#endif
|
||||
.data
|
||||
.section __DATA,__const
|
||||
|
||||
.p2align 4
|
||||
one:
|
||||
|
||||
@@ -16,6 +16,7 @@
|
||||
|
||||
chacha20_poly1305_constants:
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
L$chacha20_consts:
|
||||
.byte 'e','x','p','a','n','d',' ','3','2','-','b','y','t','e',' ','k'
|
||||
@@ -53,6 +54,7 @@ L$and_masks:
|
||||
.byte 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x00,0x00
|
||||
.byte 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x00
|
||||
.byte 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff
|
||||
.text
|
||||
|
||||
|
||||
.p2align 6
|
||||
|
||||
@@ -851,6 +851,7 @@ L$gcm_enc_abort:
|
||||
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
L$bswap_mask:
|
||||
.byte 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -864,6 +865,7 @@ L$one_lsb:
|
||||
.byte 1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
|
||||
.byte 65,69,83,45,78,73,32,71,67,77,32,109,111,100,117,108,101,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.p2align 6
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -2478,6 +2478,7 @@ L$key_expansion_256b:
|
||||
.byte 0xf3,0xc3
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
L$bswap_mask:
|
||||
.byte 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -2500,6 +2501,7 @@ L$key_rcon1b:
|
||||
|
||||
.byte 65,69,83,32,102,111,114,32,73,110,116,101,108,32,65,69,83,45,78,73,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.p2align 6
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -415,6 +415,7 @@ L$oop_row_6:
|
||||
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 4
|
||||
|
||||
|
||||
@@ -423,6 +424,7 @@ L$reverse_bytes:
|
||||
|
||||
L$low4_mask:
|
||||
.quad 0x0f0f0f0f0f0f0f0f, 0x0f0f0f0f0f0f0f0f
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -1117,6 +1117,7 @@ L$tail_no_xor_avx:
|
||||
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
L$bswap_mask:
|
||||
.byte 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -1128,6 +1129,7 @@ L$7_mask:
|
||||
|
||||
.byte 71,72,65,83,72,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.p2align 6
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -15,6 +15,7 @@
|
||||
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
L$poly:
|
||||
.quad 0xffffffffffffffff, 0x00000000ffffffff, 0x0000000000000000, 0xffffffff00000001
|
||||
@@ -33,6 +34,7 @@ L$ord:
|
||||
.quad 0xf3b9cac2fc632551, 0xbce6faada7179e84, 0xffffffffffffffff, 0xffffffff00000000
|
||||
L$ordK:
|
||||
.quad 0xccd1c8aaee00bc4f
|
||||
.text
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -1733,6 +1733,7 @@ L$oop_gather_1024:
|
||||
|
||||
L$SEH_end_rsaz_1024_gather5:
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
L$and_mask:
|
||||
.quad 0x1fffffff,0x1fffffff,0x1fffffff,0x1fffffff
|
||||
@@ -1745,6 +1746,7 @@ L$inc:
|
||||
.long 2,2,2,2, 3,3,3,3
|
||||
.long 4,4,4,4, 4,4,4,4
|
||||
.p2align 6
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -5448,6 +5448,7 @@ L$epilogue_avx2:
|
||||
.byte 0xf3,0xc3
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
K_XX_XX:
|
||||
.long 0x5a827999,0x5a827999,0x5a827999,0x5a827999
|
||||
@@ -5463,6 +5464,7 @@ K_XX_XX:
|
||||
.byte 0xf,0xe,0xd,0xc,0xb,0xa,0x9,0x8,0x7,0x6,0x5,0x4,0x3,0x2,0x1,0x0
|
||||
.byte 83,72,65,49,32,98,108,111,99,107,32,116,114,97,110,115,102,111,114,109,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.p2align 6
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -1739,6 +1739,7 @@ L$epilogue:
|
||||
.byte 0xf3,0xc3
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
|
||||
K256:
|
||||
@@ -1782,6 +1783,7 @@ K256:
|
||||
.long 0xffffffff,0xffffffff,0x03020100,0x0b0a0908
|
||||
.long 0xffffffff,0xffffffff,0x03020100,0x0b0a0908
|
||||
.byte 83,72,65,50,53,54,32,98,108,111,99,107,32,116,114,97,110,115,102,111,114,109,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.text
|
||||
|
||||
.p2align 6
|
||||
sha256_block_data_order_shaext:
|
||||
|
||||
@@ -1735,6 +1735,7 @@ L$epilogue:
|
||||
.byte 0xf3,0xc3
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
|
||||
K512:
|
||||
@@ -1822,6 +1823,7 @@ K512:
|
||||
.quad 0x0001020304050607,0x08090a0b0c0d0e0f
|
||||
.quad 0x0001020304050607,0x08090a0b0c0d0e0f
|
||||
.byte 83,72,65,53,49,50,32,98,108,111,99,107,32,116,114,97,110,115,102,111,114,109,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.text
|
||||
|
||||
.p2align 6
|
||||
sha512_block_data_order_avx:
|
||||
|
||||
@@ -1018,6 +1018,7 @@ _vpaes_preheat:
|
||||
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
_vpaes_consts:
|
||||
L$k_inv:
|
||||
@@ -1127,6 +1128,7 @@ L$ctr_add_two:
|
||||
.byte 86,101,99,116,111,114,32,80,101,114,109,117,116,97,116,105,111,110,32,65,69,83,32,102,111,114,32,120,56,54,95,54,52,47,83,83,83,69,51,44,32,77,105,107,101,32,72,97,109,98,117,114,103,32,40,83,116,97,110,102,111,114,100,32,85,110,105,118,101,114,115,105,116,121,41,0
|
||||
.p2align 6
|
||||
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -3615,11 +3615,13 @@ L$gather:
|
||||
L$SEH_end_bn_gather5:
|
||||
|
||||
|
||||
.section __DATA,__const
|
||||
.p2align 6
|
||||
L$inc:
|
||||
.long 0,0, 1,1
|
||||
.long 2,2, 2,2
|
||||
.byte 77,111,110,116,103,111,109,101,114,121,32,77,117,108,116,105,112,108,105,99,97,116,105,111,110,32,119,105,116,104,32,115,99,97,116,116,101,114,47,103,97,116,104,101,114,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
+677
-493
File diff suppressed because one or more lines are too long
@@ -16,6 +16,7 @@
|
||||
.extern OPENSSL_ia32cap_P
|
||||
.hidden OPENSSL_ia32cap_P
|
||||
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lzero:
|
||||
.long 0,0,0,0
|
||||
@@ -45,6 +46,7 @@
|
||||
.Lsixteen:
|
||||
.long 16,16,16,16,16,16,16,16,16,16,16,16,16,16,16,16
|
||||
.byte 67,104,97,67,104,97,50,48,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.text
|
||||
.globl ChaCha20_ctr32
|
||||
.hidden ChaCha20_ctr32
|
||||
.type ChaCha20_ctr32,@function
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
#if defined(BORINGSSL_PREFIX)
|
||||
#include <boringssl_prefix_symbols_asm.h>
|
||||
#endif
|
||||
.data
|
||||
.section .rodata
|
||||
|
||||
.align 16
|
||||
one:
|
||||
|
||||
@@ -17,6 +17,7 @@
|
||||
|
||||
chacha20_poly1305_constants:
|
||||
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lchacha20_consts:
|
||||
.byte 'e','x','p','a','n','d',' ','3','2','-','b','y','t','e',' ','k'
|
||||
@@ -54,6 +55,7 @@ chacha20_poly1305_constants:
|
||||
.byte 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x00,0x00
|
||||
.byte 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x00
|
||||
.byte 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff
|
||||
.text
|
||||
|
||||
.type poly_hash_ad_internal,@function
|
||||
.align 64
|
||||
|
||||
@@ -866,6 +866,7 @@ aesni_gcm_encrypt:
|
||||
|
||||
.cfi_endproc
|
||||
.size aesni_gcm_decrypt,.-aesni_gcm_decrypt
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lbswap_mask:
|
||||
.byte 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -879,6 +880,7 @@ aesni_gcm_encrypt:
|
||||
.byte 1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
|
||||
.byte 65,69,83,45,78,73,32,71,67,77,32,109,111,100,117,108,101,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.align 64
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -2480,6 +2480,7 @@ __aesni_set_encrypt_key:
|
||||
.byte 0xf3,0xc3
|
||||
.size aes_hw_set_encrypt_key,.-aes_hw_set_encrypt_key
|
||||
.size __aesni_set_encrypt_key,.-__aesni_set_encrypt_key
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lbswap_mask:
|
||||
.byte 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -2502,6 +2503,7 @@ __aesni_set_encrypt_key:
|
||||
|
||||
.byte 65,69,83,32,102,111,114,32,73,110,116,101,108,32,65,69,83,45,78,73,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.align 64
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -415,6 +415,7 @@ gcm_ghash_ssse3:
|
||||
|
||||
.size gcm_ghash_ssse3,.-gcm_ghash_ssse3
|
||||
|
||||
.section .rodata
|
||||
.align 16
|
||||
|
||||
|
||||
@@ -423,6 +424,7 @@ gcm_ghash_ssse3:
|
||||
|
||||
.Llow4_mask:
|
||||
.quad 0x0f0f0f0f0f0f0f0f, 0x0f0f0f0f0f0f0f0f
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -1118,6 +1118,7 @@ gcm_ghash_avx:
|
||||
.cfi_endproc
|
||||
|
||||
.size gcm_ghash_avx,.-gcm_ghash_avx
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lbswap_mask:
|
||||
.byte 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -1129,6 +1130,7 @@ gcm_ghash_avx:
|
||||
|
||||
.byte 71,72,65,83,72,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.align 64
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -16,6 +16,7 @@
|
||||
.hidden OPENSSL_ia32cap_P
|
||||
|
||||
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lpoly:
|
||||
.quad 0xffffffffffffffff, 0x00000000ffffffff, 0x0000000000000000, 0xffffffff00000001
|
||||
@@ -34,6 +35,7 @@
|
||||
.quad 0xf3b9cac2fc632551, 0xbce6faada7179e84, 0xffffffffffffffff, 0xffffffff00000000
|
||||
.LordK:
|
||||
.quad 0xccd1c8aaee00bc4f
|
||||
.text
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -1733,6 +1733,7 @@ rsaz_1024_gather5_avx2:
|
||||
.cfi_endproc
|
||||
.LSEH_end_rsaz_1024_gather5:
|
||||
.size rsaz_1024_gather5_avx2,.-rsaz_1024_gather5_avx2
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Land_mask:
|
||||
.quad 0x1fffffff,0x1fffffff,0x1fffffff,0x1fffffff
|
||||
@@ -1745,6 +1746,7 @@ rsaz_1024_gather5_avx2:
|
||||
.long 2,2,2,2, 3,3,3,3
|
||||
.long 4,4,4,4, 4,4,4,4
|
||||
.align 64
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -5449,6 +5449,7 @@ _avx2_shortcut:
|
||||
.byte 0xf3,0xc3
|
||||
.cfi_endproc
|
||||
.size sha1_block_data_order_avx2,.-sha1_block_data_order_avx2
|
||||
.section .rodata
|
||||
.align 64
|
||||
K_XX_XX:
|
||||
.long 0x5a827999,0x5a827999,0x5a827999,0x5a827999
|
||||
@@ -5464,6 +5465,7 @@ K_XX_XX:
|
||||
.byte 0xf,0xe,0xd,0xc,0xb,0xa,0x9,0x8,0x7,0x6,0x5,0x4,0x3,0x2,0x1,0x0
|
||||
.byte 83,72,65,49,32,98,108,111,99,107,32,116,114,97,110,115,102,111,114,109,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.align 64
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -1740,6 +1740,7 @@ sha256_block_data_order:
|
||||
.byte 0xf3,0xc3
|
||||
.cfi_endproc
|
||||
.size sha256_block_data_order,.-sha256_block_data_order
|
||||
.section .rodata
|
||||
.align 64
|
||||
.type K256,@object
|
||||
K256:
|
||||
@@ -1783,6 +1784,7 @@ K256:
|
||||
.long 0xffffffff,0xffffffff,0x03020100,0x0b0a0908
|
||||
.long 0xffffffff,0xffffffff,0x03020100,0x0b0a0908
|
||||
.byte 83,72,65,50,53,54,32,98,108,111,99,107,32,116,114,97,110,115,102,111,114,109,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.text
|
||||
.type sha256_block_data_order_shaext,@function
|
||||
.align 64
|
||||
sha256_block_data_order_shaext:
|
||||
|
||||
@@ -1736,6 +1736,7 @@ sha512_block_data_order:
|
||||
.byte 0xf3,0xc3
|
||||
.cfi_endproc
|
||||
.size sha512_block_data_order,.-sha512_block_data_order
|
||||
.section .rodata
|
||||
.align 64
|
||||
.type K512,@object
|
||||
K512:
|
||||
@@ -1823,6 +1824,7 @@ K512:
|
||||
.quad 0x0001020304050607,0x08090a0b0c0d0e0f
|
||||
.quad 0x0001020304050607,0x08090a0b0c0d0e0f
|
||||
.byte 83,72,65,53,49,50,32,98,108,111,99,107,32,116,114,97,110,115,102,111,114,109,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.text
|
||||
.type sha512_block_data_order_avx,@function
|
||||
.align 64
|
||||
sha512_block_data_order_avx:
|
||||
|
||||
@@ -1020,6 +1020,7 @@ _vpaes_preheat:
|
||||
|
||||
|
||||
.type _vpaes_consts,@object
|
||||
.section .rodata
|
||||
.align 64
|
||||
_vpaes_consts:
|
||||
.Lk_inv:
|
||||
@@ -1129,6 +1130,7 @@ _vpaes_consts:
|
||||
.byte 86,101,99,116,111,114,32,80,101,114,109,117,116,97,116,105,111,110,32,65,69,83,32,102,111,114,32,120,56,54,95,54,52,47,83,83,83,69,51,44,32,77,105,107,101,32,72,97,109,98,117,114,103,32,40,83,116,97,110,102,111,114,100,32,85,110,105,118,101,114,115,105,116,121,41,0
|
||||
.align 64
|
||||
.size _vpaes_consts,.-_vpaes_consts
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -3616,11 +3616,13 @@ bn_gather5:
|
||||
.LSEH_end_bn_gather5:
|
||||
.cfi_endproc
|
||||
.size bn_gather5,.-bn_gather5
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Linc:
|
||||
.long 0,0, 1,1
|
||||
.long 2,2, 2,2
|
||||
.byte 77,111,110,116,103,111,109,101,114,121,32,77,117,108,116,105,112,108,105,99,97,116,105,111,110,32,119,105,116,104,32,115,99,97,116,116,101,114,47,103,97,116,104,101,114,32,102,111,114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
.text
|
||||
#endif
|
||||
#if defined(__ELF__)
|
||||
// See https://www.airs.com/blog/archives/518.
|
||||
|
||||
@@ -112,6 +112,7 @@
|
||||
"src/crypto/hkdf/hkdf.c",
|
||||
"src/crypto/hpke/hpke.c",
|
||||
"src/crypto/hrss/hrss.c",
|
||||
"src/crypto/kyber/keccak.c",
|
||||
"src/crypto/lhash/lhash.c",
|
||||
"src/crypto/mem.c",
|
||||
"src/crypto/obj/obj.c",
|
||||
@@ -412,6 +413,7 @@
|
||||
"src/crypto/fipsmodule/tls/internal.h",
|
||||
"src/crypto/hrss/internal.h",
|
||||
"src/crypto/internal.h",
|
||||
"src/crypto/kyber/internal.h",
|
||||
"src/crypto/lhash/internal.h",
|
||||
"src/crypto/obj/obj_dat.h",
|
||||
"src/crypto/pkcs7/internal.h",
|
||||
@@ -542,6 +544,7 @@
|
||||
"src/crypto/hpke/hpke_test.cc",
|
||||
"src/crypto/hrss/hrss_test.cc",
|
||||
"src/crypto/impl_dispatch_test.cc",
|
||||
"src/crypto/kyber/kyber_test.cc",
|
||||
"src/crypto/lhash/lhash_test.cc",
|
||||
"src/crypto/obj/obj_test.cc",
|
||||
"src/crypto/pem/pem_test.cc",
|
||||
@@ -626,6 +629,7 @@
|
||||
"src/crypto/fipsmodule/rand/ctrdrbg_vectors.txt",
|
||||
"src/crypto/hmac_extra/hmac_tests.txt",
|
||||
"src/crypto/hpke/hpke_test_vectors.txt",
|
||||
"src/crypto/kyber/keccak_tests.txt",
|
||||
"src/crypto/pkcs8/test/empty_password.p12",
|
||||
"src/crypto/pkcs8/test/no_encryption.p12",
|
||||
"src/crypto/pkcs8/test/nss.p12",
|
||||
|
||||
@@ -171,6 +171,7 @@ add_library(
|
||||
hkdf/hkdf.c
|
||||
hpke/hpke.c
|
||||
hrss/hrss.c
|
||||
kyber/keccak.c
|
||||
lhash/lhash.c
|
||||
mem.c
|
||||
obj/obj.c
|
||||
@@ -398,6 +399,7 @@ add_executable(
|
||||
hmac_extra/hmac_test.cc
|
||||
hrss/hrss_test.cc
|
||||
impl_dispatch_test.cc
|
||||
kyber/kyber_test.cc
|
||||
lhash/lhash_test.cc
|
||||
obj/obj_test.cc
|
||||
pem/pem_test.cc
|
||||
|
||||
@@ -78,6 +78,7 @@ $code.=<<___;
|
||||
|
||||
.extern OPENSSL_ia32cap_P
|
||||
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lzero:
|
||||
.long 0,0,0,0
|
||||
@@ -107,6 +108,7 @@ $code.=<<___;
|
||||
.Lsixteen:
|
||||
.long 16,16,16,16,16,16,16,16,16,16,16,16,16,16,16,16
|
||||
.asciz "ChaCha20 for x86_64, CRYPTOGAMS by <appro\@openssl.org>"
|
||||
.text
|
||||
___
|
||||
|
||||
sub AUTOLOAD() # thunk [simplified] 32-bit style perlasm
|
||||
|
||||
@@ -32,7 +32,7 @@ open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\"";
|
||||
*STDOUT=*OUT;
|
||||
|
||||
$code.=<<___;
|
||||
.data
|
||||
.section .rodata
|
||||
|
||||
.align 16
|
||||
one:
|
||||
|
||||
@@ -42,6 +42,7 @@ $code.=<<___;
|
||||
|
||||
chacha20_poly1305_constants:
|
||||
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lchacha20_consts:
|
||||
.byte 'e','x','p','a','n','d',' ','3','2','-','b','y','t','e',' ','k'
|
||||
@@ -79,6 +80,7 @@ chacha20_poly1305_constants:
|
||||
.byte 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x00,0x00
|
||||
.byte 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x00
|
||||
.byte 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff
|
||||
.text
|
||||
___
|
||||
|
||||
my ($oup,$inp,$inl,$adp,$keyp,$itr1,$itr2,$adl)=("%rdi","%rsi","%rbx","%rcx","%r9","%rcx","%r8","%r8");
|
||||
|
||||
@@ -3778,6 +3778,7 @@ ___
|
||||
}
|
||||
|
||||
$code.=<<___;
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lbswap_mask:
|
||||
.byte 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -3800,6 +3801,7 @@ $code.=<<___;
|
||||
|
||||
.asciz "AES for Intel AES-NI, CRYPTOGAMS by <appro\@openssl.org>"
|
||||
.align 64
|
||||
.text
|
||||
___
|
||||
|
||||
# EXCEPTION_DISPOSITION handler (EXCEPTION_RECORD *rec,ULONG64 frame,
|
||||
|
||||
@@ -1288,6 +1288,7 @@ _vpaes_preheat:
|
||||
## ##
|
||||
########################################################
|
||||
.type _vpaes_consts,\@object
|
||||
.section .rodata
|
||||
.align 64
|
||||
_vpaes_consts:
|
||||
.Lk_inv: # inv, inva
|
||||
@@ -1397,6 +1398,7 @@ _vpaes_consts:
|
||||
.asciz "Vector Permutation AES for x86_64/SSSE3, Mike Hamburg (Stanford University)"
|
||||
.align 64
|
||||
.size _vpaes_consts,.-_vpaes_consts
|
||||
.text
|
||||
___
|
||||
|
||||
if ($win64) {
|
||||
|
||||
@@ -1738,6 +1738,7 @@ ___
|
||||
}
|
||||
|
||||
$code.=<<___;
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Land_mask:
|
||||
.quad 0x1fffffff,0x1fffffff,0x1fffffff,0x1fffffff
|
||||
@@ -1750,6 +1751,7 @@ $code.=<<___;
|
||||
.long 2,2,2,2, 3,3,3,3
|
||||
.long 4,4,4,4, 4,4,4,4
|
||||
.align 64
|
||||
.text
|
||||
___
|
||||
|
||||
if ($win64) {
|
||||
|
||||
@@ -3576,11 +3576,13 @@ $code.=<<___;
|
||||
___
|
||||
}
|
||||
$code.=<<___;
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Linc:
|
||||
.long 0,0, 1,1
|
||||
.long 2,2, 2,2
|
||||
.asciz "Montgomery Multiplication with scatter/gather for x86_64, CRYPTOGAMS by <appro\@openssl.org>"
|
||||
.text
|
||||
___
|
||||
|
||||
# EXCEPTION_DISPOSITION handler (EXCEPTION_RECORD *rec,ULONG64 frame,
|
||||
|
||||
@@ -62,6 +62,7 @@ $code.=<<___;
|
||||
.extern OPENSSL_ia32cap_P
|
||||
|
||||
# The polynomial
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lpoly:
|
||||
.quad 0xffffffffffffffff, 0x00000000ffffffff, 0x0000000000000000, 0xffffffff00000001
|
||||
@@ -80,6 +81,7 @@ $code.=<<___;
|
||||
.quad 0xf3b9cac2fc632551, 0xbce6faada7179e84, 0xffffffffffffffff, 0xffffffff00000000
|
||||
.LordK:
|
||||
.quad 0xccd1c8aaee00bc4f
|
||||
.text
|
||||
___
|
||||
|
||||
{
|
||||
|
||||
@@ -1053,6 +1053,7 @@ $code.=<<___;
|
||||
___
|
||||
|
||||
$code.=<<___;
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lbswap_mask:
|
||||
.byte 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -1066,6 +1067,7 @@ $code.=<<___;
|
||||
.byte 1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
|
||||
.asciz "AES-NI GCM module for x86_64, CRYPTOGAMS by <appro\@openssl.org>"
|
||||
.align 64
|
||||
.text
|
||||
___
|
||||
}}} else {{{
|
||||
$code=<<___; # assembler is too old
|
||||
|
||||
@@ -331,6 +331,7 @@ $code .= <<____;
|
||||
.seh_endproc
|
||||
.size gcm_ghash_ssse3,.-gcm_ghash_ssse3
|
||||
|
||||
.section .rodata
|
||||
.align 16
|
||||
# .Lreverse_bytes is a permutation which, if applied with pshufb, reverses the
|
||||
# bytes in an XMM register.
|
||||
@@ -339,6 +340,7 @@ $code .= <<____;
|
||||
# .Llow4_mask is an XMM mask which selects the low four bits of each byte.
|
||||
.Llow4_mask:
|
||||
.quad 0x0f0f0f0f0f0f0f0f, 0x0f0f0f0f0f0f0f0f
|
||||
.text
|
||||
____
|
||||
|
||||
print $code;
|
||||
|
||||
@@ -1297,6 +1297,7 @@ ___
|
||||
}
|
||||
|
||||
$code.=<<___;
|
||||
.section .rodata
|
||||
.align 64
|
||||
.Lbswap_mask:
|
||||
.byte 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -1308,6 +1309,7 @@ $code.=<<___;
|
||||
|
||||
.asciz "GHASH for x86_64, CRYPTOGAMS by <appro\@openssl.org>"
|
||||
.align 64
|
||||
.text
|
||||
___
|
||||
|
||||
$code =~ s/\`([^\`]*)\`/eval($1)/gem;
|
||||
|
||||
@@ -1815,6 +1815,7 @@ ___
|
||||
}
|
||||
}
|
||||
$code.=<<___;
|
||||
.section .rodata
|
||||
.align 64
|
||||
K_XX_XX:
|
||||
.long 0x5a827999,0x5a827999,0x5a827999,0x5a827999 # K_00_19
|
||||
@@ -1833,6 +1834,7 @@ ___
|
||||
$code.=<<___;
|
||||
.asciz "SHA1 block transform for x86_64, CRYPTOGAMS by <appro\@openssl.org>"
|
||||
.align 64
|
||||
.text
|
||||
___
|
||||
|
||||
# EXCEPTION_DISPOSITION handler (EXCEPTION_RECORD *rec,ULONG64 frame,
|
||||
|
||||
@@ -404,6 +404,7 @@ ___
|
||||
|
||||
if ($SZ==4) {
|
||||
$code.=<<___;
|
||||
.section .rodata
|
||||
.align 64
|
||||
.type $TABLE,\@object
|
||||
$TABLE:
|
||||
@@ -447,9 +448,11 @@ $TABLE:
|
||||
.long 0xffffffff,0xffffffff,0x03020100,0x0b0a0908
|
||||
.long 0xffffffff,0xffffffff,0x03020100,0x0b0a0908
|
||||
.asciz "SHA256 block transform for x86_64, CRYPTOGAMS by <appro\@openssl.org>"
|
||||
.text
|
||||
___
|
||||
} else {
|
||||
$code.=<<___;
|
||||
.section .rodata
|
||||
.align 64
|
||||
.type $TABLE,\@object
|
||||
$TABLE:
|
||||
@@ -537,6 +540,7 @@ $TABLE:
|
||||
.quad 0x0001020304050607,0x08090a0b0c0d0e0f
|
||||
.quad 0x0001020304050607,0x08090a0b0c0d0e0f
|
||||
.asciz "SHA512 block transform for x86_64, CRYPTOGAMS by <appro\@openssl.org>"
|
||||
.text
|
||||
___
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,61 @@
|
||||
/* Copyright (c) 2023, Google Inc.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
||||
* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
||||
* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
|
||||
* SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
||||
* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
|
||||
* OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
|
||||
* CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
|
||||
|
||||
#ifndef OPENSSL_HEADER_CRYPTO_KYBER_INTERNAL_H
|
||||
#define OPENSSL_HEADER_CRYPTO_KYBER_INTERNAL_H
|
||||
|
||||
#include <openssl/base.h>
|
||||
|
||||
#if defined(__cplusplus)
|
||||
extern "C" {
|
||||
#endif
|
||||
|
||||
|
||||
struct BORINGSSL_keccak_st {
|
||||
uint64_t state[25];
|
||||
size_t rate_bytes;
|
||||
size_t offset;
|
||||
};
|
||||
|
||||
enum boringssl_keccak_config_t {
|
||||
boringssl_sha3_256,
|
||||
boringssl_sha3_512,
|
||||
boringssl_shake128,
|
||||
boringssl_shake256,
|
||||
};
|
||||
|
||||
// BORINGSSL_keccak hashes |in_len| bytes from |in| and writes |out_len| bytes
|
||||
// of output to |out|. If the |config| specifies a fixed-output function, like
|
||||
// SHA3-256, then |out_len| must be the correct length for that function.
|
||||
OPENSSL_EXPORT void BORINGSSL_keccak(uint8_t *out, size_t out_len,
|
||||
const uint8_t *in, size_t in_len,
|
||||
enum boringssl_keccak_config_t config);
|
||||
|
||||
// BORINGSSL_keccak_init absorbs |in_len| bytes from |in| and sets up |ctx| for
|
||||
// squeezing. The |config| must specify a SHAKE variant, otherwise callers
|
||||
// should use |BORINGSSL_keccak|.
|
||||
OPENSSL_EXPORT void BORINGSSL_keccak_init(
|
||||
struct BORINGSSL_keccak_st *ctx, const uint8_t *in, size_t in_len,
|
||||
enum boringssl_keccak_config_t config);
|
||||
|
||||
// BORINGSSL_keccak_squeeze writes |out_len| bytes to |out| from |ctx|.
|
||||
OPENSSL_EXPORT void BORINGSSL_keccak_squeeze(
|
||||
struct BORINGSSL_keccak_st *ctx, uint8_t *out, size_t out_len);
|
||||
|
||||
|
||||
#if defined(__cplusplus)
|
||||
}
|
||||
#endif
|
||||
|
||||
#endif // OPENSSL_HEADER_CRYPTO_KYBER_INTERNAL_H
|
||||
@@ -0,0 +1,205 @@
|
||||
/* Copyright (c) 2023, Google Inc.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
||||
* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
||||
* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
|
||||
* SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
||||
* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
|
||||
* OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
|
||||
* CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
|
||||
|
||||
#include <openssl/base.h>
|
||||
|
||||
#include <assert.h>
|
||||
#include <stdlib.h>
|
||||
|
||||
#include "../internal.h"
|
||||
#include "./internal.h"
|
||||
|
||||
|
||||
// keccak_f implements the Keccak-1600 permutation as described at
|
||||
// https://keccak.team/keccak_specs_summary.html. Each lane is represented as a
|
||||
// 64-bit value and the 5×5 lanes are stored as an array in row-major order.
|
||||
static void keccak_f(uint64_t state[25]) {
|
||||
static const int kNumRounds = 24;
|
||||
for (int round = 0; round < kNumRounds; round++) {
|
||||
// θ step
|
||||
uint64_t c[5];
|
||||
for (int x = 0; x < 5; x++) {
|
||||
c[x] = state[x] ^ state[x + 5] ^ state[x + 10] ^ state[x + 15] ^
|
||||
state[x + 20];
|
||||
}
|
||||
|
||||
for (int x = 0; x < 5; x++) {
|
||||
const uint64_t d = c[(x + 4) % 5] ^ CRYPTO_rotl_u64(c[(x + 1) % 5], 1);
|
||||
for (int y = 0; y < 5; y++) {
|
||||
state[y * 5 + x] ^= d;
|
||||
}
|
||||
}
|
||||
|
||||
// ρ and π steps.
|
||||
//
|
||||
// These steps involve a mapping of the state matrix. Each input point,
|
||||
// (x,y), is rotated and written to the point (y, 2x + 3y). In the Keccak
|
||||
// pseudo-code a separate array is used because an in-place operation would
|
||||
// overwrite some values that are subsequently needed. However, the mapping
|
||||
// forms a trail through 24 of the 25 values so we can do it in place with
|
||||
// only a single temporary variable.
|
||||
//
|
||||
// Start with (1, 0). The value here will be mapped and end up at (0, 2).
|
||||
// That value will end up at (2, 1), then (1, 2), and so on. After 24
|
||||
// steps, 24 of the 25 values have been hit (as this mapping is injective)
|
||||
// and the sequence will repeat. All that remains is to handle the element
|
||||
// at (0, 0), but the rotation for that element is zero, and it goes to (0,
|
||||
// 0), so we can ignore it.
|
||||
int pi_x = 1, pi_y = 0;
|
||||
uint64_t prev_value = state[1];
|
||||
int pi_rot = 1;
|
||||
for (int i = 1; i < 25; i++) {
|
||||
const int out_x = pi_y;
|
||||
const int out_y = (2 * pi_x + 3 * pi_y) % 5;
|
||||
const int index = out_y * 5 + out_x;
|
||||
const uint64_t t = state[index];
|
||||
state[index] = CRYPTO_rotl_u64(prev_value, pi_rot);
|
||||
pi_rot = (pi_rot + i + 1) % 64;
|
||||
prev_value = t;
|
||||
pi_x = out_x;
|
||||
pi_y = out_y;
|
||||
}
|
||||
|
||||
// χ step
|
||||
for (int y = 0; y < 5; y++) {
|
||||
const int row_index = 5 * y;
|
||||
const uint64_t orig_x0 = state[row_index];
|
||||
const uint64_t orig_x1 = state[row_index + 1];
|
||||
state[row_index] ^= ~orig_x1 & state[row_index + 2];
|
||||
state[row_index + 1] ^= ~state[row_index + 2] & state[row_index + 3];
|
||||
state[row_index + 2] ^= ~state[row_index + 3] & state[row_index + 4];
|
||||
state[row_index + 3] ^= ~state[row_index + 4] & orig_x0;
|
||||
state[row_index + 4] ^= ~orig_x0 & orig_x1;
|
||||
}
|
||||
|
||||
// ι step
|
||||
//
|
||||
// From https://keccak.team/files/Keccak-reference-3.0.pdf, section
|
||||
// 1.2, the round constants are based on the output of a LFSR. Thus, as
|
||||
// suggested in the appendix of of
|
||||
// https://keccak.team/keccak_specs_summary.html, the values are
|
||||
// simply encoded here.
|
||||
static const uint64_t kRoundConstants[24] = {
|
||||
0x0000000000000001, 0x0000000000008082, 0x800000000000808a,
|
||||
0x8000000080008000, 0x000000000000808b, 0x0000000080000001,
|
||||
0x8000000080008081, 0x8000000000008009, 0x000000000000008a,
|
||||
0x0000000000000088, 0x0000000080008009, 0x000000008000000a,
|
||||
0x000000008000808b, 0x800000000000008b, 0x8000000000008089,
|
||||
0x8000000000008003, 0x8000000000008002, 0x8000000000000080,
|
||||
0x000000000000800a, 0x800000008000000a, 0x8000000080008081,
|
||||
0x8000000000008080, 0x0000000080000001, 0x8000000080008008,
|
||||
};
|
||||
|
||||
state[0] ^= kRoundConstants[round];
|
||||
}
|
||||
}
|
||||
|
||||
static void keccak_init(struct BORINGSSL_keccak_st *ctx,
|
||||
size_t *out_required_out_len, const uint8_t *in,
|
||||
size_t in_len, enum boringssl_keccak_config_t config) {
|
||||
size_t capacity_bytes;
|
||||
uint8_t terminator;
|
||||
switch (config) {
|
||||
case boringssl_sha3_256:
|
||||
capacity_bytes = 512 / 8;
|
||||
*out_required_out_len = 32;
|
||||
terminator = 0x06;
|
||||
break;
|
||||
case boringssl_sha3_512:
|
||||
capacity_bytes = 1024 / 8;
|
||||
*out_required_out_len = 64;
|
||||
terminator = 0x06;
|
||||
break;
|
||||
case boringssl_shake128:
|
||||
capacity_bytes = 256 / 8;
|
||||
*out_required_out_len = 0;
|
||||
terminator = 0x1f;
|
||||
break;
|
||||
case boringssl_shake256:
|
||||
capacity_bytes = 512 / 8;
|
||||
*out_required_out_len = 0;
|
||||
terminator = 0x1f;
|
||||
break;
|
||||
default:
|
||||
abort();
|
||||
}
|
||||
|
||||
OPENSSL_memset(ctx, 0, sizeof(*ctx));
|
||||
ctx->rate_bytes = 200 - capacity_bytes;
|
||||
assert(ctx->rate_bytes % 8 == 0);
|
||||
const size_t rate_words = ctx->rate_bytes / 8;
|
||||
|
||||
while (in_len >= ctx->rate_bytes) {
|
||||
for (size_t i = 0; i < rate_words; i++) {
|
||||
ctx->state[i] ^= CRYPTO_load_u64_le(in + 8 * i);
|
||||
}
|
||||
keccak_f(ctx->state);
|
||||
in += ctx->rate_bytes;
|
||||
in_len -= ctx->rate_bytes;
|
||||
}
|
||||
|
||||
// XOR the final block. Accessing |ctx->state| as a |uint8_t*| is allowed by
|
||||
// strict aliasing because we require |uint8_t| to be a character type.
|
||||
uint8_t *state_bytes = (uint8_t *)ctx->state;
|
||||
assert(in_len < ctx->rate_bytes);
|
||||
for (size_t i = 0; i < in_len; i++) {
|
||||
state_bytes[i] ^= in[i];
|
||||
}
|
||||
state_bytes[in_len] ^= terminator;
|
||||
state_bytes[ctx->rate_bytes - 1] ^= 0x80;
|
||||
keccak_f(ctx->state);
|
||||
}
|
||||
|
||||
void BORINGSSL_keccak(uint8_t *out, size_t out_len, const uint8_t *in,
|
||||
size_t in_len, enum boringssl_keccak_config_t config) {
|
||||
struct BORINGSSL_keccak_st ctx;
|
||||
size_t required_out_len;
|
||||
keccak_init(&ctx, &required_out_len, in, in_len, config);
|
||||
if (required_out_len != 0 && out_len != required_out_len) {
|
||||
abort();
|
||||
}
|
||||
BORINGSSL_keccak_squeeze(&ctx, out, out_len);
|
||||
}
|
||||
|
||||
void BORINGSSL_keccak_init(struct BORINGSSL_keccak_st *ctx, const uint8_t *in,
|
||||
size_t in_len,
|
||||
enum boringssl_keccak_config_t config) {
|
||||
size_t required_out_len;
|
||||
keccak_init(ctx, &required_out_len, in, in_len, config);
|
||||
if (required_out_len != 0) {
|
||||
abort();
|
||||
}
|
||||
}
|
||||
|
||||
void BORINGSSL_keccak_squeeze(struct BORINGSSL_keccak_st *ctx, uint8_t *out,
|
||||
size_t out_len) {
|
||||
// Accessing |ctx->state| as a |uint8_t*| is allowed by strict aliasing
|
||||
// because we require |uint8_t| to be a character type.
|
||||
const uint8_t *state_bytes = (const uint8_t *)ctx->state;
|
||||
while (out_len) {
|
||||
size_t remaining = ctx->rate_bytes - ctx->offset;
|
||||
size_t todo = out_len;
|
||||
if (todo > remaining) {
|
||||
todo = remaining;
|
||||
}
|
||||
OPENSSL_memcpy(out, &state_bytes[ctx->offset], todo);
|
||||
out += todo;
|
||||
out_len -= todo;
|
||||
ctx->offset += todo;
|
||||
if (ctx->offset == ctx->rate_bytes) {
|
||||
keccak_f(ctx->state);
|
||||
ctx->offset = 0;
|
||||
}
|
||||
}
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,66 @@
|
||||
/* Copyright (c) 2023, Google Inc.
|
||||
*
|
||||
* Permission to use, copy, modify, and/or distribute this software for any
|
||||
* purpose with or without fee is hereby granted, provided that the above
|
||||
* copyright notice and this permission notice appear in all copies.
|
||||
*
|
||||
* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
||||
* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
||||
* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
|
||||
* SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
||||
* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
|
||||
* OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
|
||||
* CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
|
||||
|
||||
#include <gtest/gtest.h>
|
||||
|
||||
#include "../test/file_test.h"
|
||||
#include "../test/test_util.h"
|
||||
#include "./internal.h"
|
||||
|
||||
|
||||
static void KeccakFileTest(FileTest *t) {
|
||||
std::vector<uint8_t> input, sha3_256_expected, sha3_512_expected,
|
||||
shake128_expected, shake256_expected;
|
||||
ASSERT_TRUE(t->GetBytes(&input, "Input"));
|
||||
ASSERT_TRUE(t->GetBytes(&sha3_256_expected, "SHA3-256"));
|
||||
ASSERT_TRUE(t->GetBytes(&sha3_512_expected, "SHA3-512"));
|
||||
ASSERT_TRUE(t->GetBytes(&shake128_expected, "SHAKE-128"));
|
||||
ASSERT_TRUE(t->GetBytes(&shake256_expected, "SHAKE-256"));
|
||||
|
||||
uint8_t sha3_256_digest[32];
|
||||
BORINGSSL_keccak(sha3_256_digest, sizeof(sha3_256_digest), input.data(),
|
||||
input.size(), boringssl_sha3_256);
|
||||
uint8_t sha3_512_digest[64];
|
||||
BORINGSSL_keccak(sha3_512_digest, sizeof(sha3_512_digest), input.data(),
|
||||
input.size(), boringssl_sha3_512);
|
||||
uint8_t shake128_output[512];
|
||||
BORINGSSL_keccak(shake128_output, sizeof(shake128_output), input.data(),
|
||||
input.size(), boringssl_shake128);
|
||||
uint8_t shake256_output[512];
|
||||
BORINGSSL_keccak(shake256_output, sizeof(shake256_output), input.data(),
|
||||
input.size(), boringssl_shake256);
|
||||
|
||||
EXPECT_EQ(Bytes(sha3_256_expected), Bytes(sha3_256_digest));
|
||||
EXPECT_EQ(Bytes(sha3_512_expected), Bytes(sha3_512_digest));
|
||||
EXPECT_EQ(Bytes(shake128_expected), Bytes(shake128_output));
|
||||
EXPECT_EQ(Bytes(shake256_expected), Bytes(shake256_output));
|
||||
|
||||
struct BORINGSSL_keccak_st ctx;
|
||||
|
||||
BORINGSSL_keccak_init(&ctx, input.data(), input.size(), boringssl_shake128);
|
||||
for (size_t i = 0; i < sizeof(shake128_output); i++) {
|
||||
BORINGSSL_keccak_squeeze(&ctx, &shake128_output[i], 1);
|
||||
}
|
||||
EXPECT_EQ(Bytes(shake128_expected), Bytes(shake128_output));
|
||||
|
||||
BORINGSSL_keccak_init(&ctx, input.data(), input.size(), boringssl_shake256);
|
||||
for (size_t i = 0; i < sizeof(shake256_output); i++) {
|
||||
BORINGSSL_keccak_squeeze(&ctx, &shake256_output[i], 1);
|
||||
}
|
||||
EXPECT_EQ(Bytes(shake256_expected), Bytes(shake256_output));
|
||||
}
|
||||
|
||||
TEST(KyberTest, Keccak) {
|
||||
FileTestGTest("crypto/kyber/keccak_tests.txt", KeccakFileTest);
|
||||
}
|
||||
@@ -1107,6 +1107,9 @@ ____
|
||||
$self->{value} = ".p2align\t" . (log($$line)/log(2));
|
||||
} elsif ($dir eq ".section") {
|
||||
$current_segment=$$line;
|
||||
if (!$elf && $current_segment eq ".rodata") {
|
||||
if ($flavour eq "macosx") { $self->{value} = ".section\t__DATA,__const"; }
|
||||
}
|
||||
if (!$elf && $current_segment eq ".init") {
|
||||
if ($flavour eq "macosx") { $self->{value} = ".mod_init_func"; }
|
||||
elsif ($flavour eq "mingw64") { $self->{value} = ".section\t.ctors"; }
|
||||
@@ -1159,9 +1162,10 @@ ____
|
||||
/\.section/ && do { my $v=undef;
|
||||
$$line =~ s/([^,]*).*/$1/;
|
||||
$$line = ".CRT\$XCU" if ($$line eq ".init");
|
||||
$$line = ".rdata" if ($$line eq ".rodata");
|
||||
if ($nasm) {
|
||||
$v="section $$line";
|
||||
if ($$line=~/\.([px])data/) {
|
||||
if ($$line=~/\.([prx])data/) {
|
||||
$v.=" rdata align=";
|
||||
$v.=$1 eq "p"? 4 : 8;
|
||||
} elsif ($$line=~/\.CRT\$/i) {
|
||||
@@ -1170,7 +1174,7 @@ ____
|
||||
} else {
|
||||
$v="$current_segment\tENDS\n" if ($current_segment);
|
||||
$v.="$$line\tSEGMENT";
|
||||
if ($$line=~/\.([px])data/) {
|
||||
if ($$line=~/\.([prx])data/) {
|
||||
$v.=" READONLY";
|
||||
$v.=" ALIGN(".($1 eq "p" ? 4 : 8).")" if ($masm>=$masmref);
|
||||
} elsif ($$line=~/\.CRT\$/i) {
|
||||
|
||||
@@ -66,6 +66,7 @@ set(
|
||||
crypto/fipsmodule/rand/ctrdrbg_vectors.txt
|
||||
crypto/hmac_extra/hmac_tests.txt
|
||||
crypto/hpke/hpke_test_vectors.txt
|
||||
crypto/kyber/keccak_tests.txt
|
||||
crypto/pkcs8/test/empty_password.p12
|
||||
crypto/pkcs8/test/no_encryption.p12
|
||||
crypto/pkcs8/test/nss.p12
|
||||
|
||||
@@ -15,6 +15,7 @@ section .text code align=64
|
||||
|
||||
EXTERN OPENSSL_ia32cap_P
|
||||
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
$L$zero:
|
||||
DD 0,0,0,0
|
||||
@@ -48,6 +49,8 @@ $L$sixteen:
|
||||
DB 95,54,52,44,32,67,82,89,80,84,79,71,65,77,83,32
|
||||
DB 98,121,32,60,97,112,112,114,111,64,111,112,101,110,115,115
|
||||
DB 108,46,111,114,103,62,0
|
||||
section .text code align=64
|
||||
|
||||
global ChaCha20_ctr32
|
||||
|
||||
ALIGN 64
|
||||
|
||||
@@ -10,8 +10,7 @@ default rel
|
||||
%ifdef BORINGSSL_PREFIX
|
||||
%include "boringssl_prefix_symbols_nasm.inc"
|
||||
%endif
|
||||
section .data data align=8
|
||||
|
||||
section .rdata rdata align=8
|
||||
|
||||
ALIGN 16
|
||||
one:
|
||||
|
||||
@@ -16,6 +16,7 @@ EXTERN OPENSSL_ia32cap_P
|
||||
|
||||
chacha20_poly1305_constants:
|
||||
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
$L$chacha20_consts:
|
||||
DB 'e','x','p','a','n','d',' ','3','2','-','b','y','t','e',' ','k'
|
||||
@@ -53,6 +54,8 @@ $L$and_masks:
|
||||
DB 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x00,0x00
|
||||
DB 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x00
|
||||
DB 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff
|
||||
section .text code align=64
|
||||
|
||||
|
||||
|
||||
ALIGN 64
|
||||
|
||||
@@ -939,6 +939,7 @@ $L$gcm_enc_abort:
|
||||
$L$SEH_end_aesni_gcm_encrypt_22:
|
||||
|
||||
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
$L$bswap_mask:
|
||||
DB 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -955,6 +956,8 @@ $L$one_lsb:
|
||||
DB 89,80,84,79,71,65,77,83,32,98,121,32,60,97,112,112
|
||||
DB 114,111,64,111,112,101,110,115,115,108,46,111,114,103,62,0
|
||||
ALIGN 64
|
||||
section .text code align=64
|
||||
|
||||
section .pdata rdata align=4
|
||||
ALIGN 4
|
||||
DD $L$SEH_begin_aesni_gcm_decrypt_1 wrt ..imagebase
|
||||
|
||||
@@ -2575,6 +2575,7 @@ $L$key_expansion_256b:
|
||||
DB 0F3h,0C3h ;repret
|
||||
|
||||
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
$L$bswap_mask:
|
||||
DB 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -2600,6 +2601,8 @@ $L$key_rcon1b:
|
||||
DB 32,98,121,32,60,97,112,112,114,111,64,111,112,101,110,115
|
||||
DB 115,108,46,111,114,103,62,0
|
||||
ALIGN 64
|
||||
section .text code align=64
|
||||
|
||||
EXTERN __imp_RtlVirtualUnwind
|
||||
|
||||
ALIGN 16
|
||||
|
||||
@@ -434,6 +434,7 @@ DB 102,65,15,56,0,194
|
||||
$L$SEH_end_gcm_ghash_ssse3_6:
|
||||
|
||||
|
||||
section .rdata rdata align=8
|
||||
ALIGN 16
|
||||
|
||||
|
||||
@@ -442,6 +443,8 @@ $L$reverse_bytes:
|
||||
|
||||
$L$low4_mask:
|
||||
DQ 0x0f0f0f0f0f0f0f0f,0x0f0f0f0f0f0f0f0f
|
||||
section .text code align=64
|
||||
|
||||
section .pdata rdata align=4
|
||||
ALIGN 4
|
||||
DD $L$SEH_begin_gcm_gmult_ssse3_1 wrt ..imagebase
|
||||
|
||||
@@ -1193,6 +1193,7 @@ $L$tail_no_xor_avx:
|
||||
|
||||
$L$SEH_end_gcm_ghash_avx_13:
|
||||
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
$L$bswap_mask:
|
||||
DB 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0
|
||||
@@ -1207,6 +1208,8 @@ ALIGN 64
|
||||
DB 60,97,112,112,114,111,64,111,112,101,110,115,115,108,46,111
|
||||
DB 114,103,62,0
|
||||
ALIGN 64
|
||||
section .text code align=64
|
||||
|
||||
section .pdata rdata align=4
|
||||
ALIGN 4
|
||||
DD $L$SEH_begin_gcm_init_clmul_1 wrt ..imagebase
|
||||
|
||||
@@ -15,6 +15,7 @@ section .text code align=64
|
||||
EXTERN OPENSSL_ia32cap_P
|
||||
|
||||
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
$L$poly:
|
||||
DQ 0xffffffffffffffff,0x00000000ffffffff,0x0000000000000000,0xffffffff00000001
|
||||
@@ -33,6 +34,8 @@ $L$ord:
|
||||
DQ 0xf3b9cac2fc632551,0xbce6faada7179e84,0xffffffffffffffff,0xffffffff00000000
|
||||
$L$ordK:
|
||||
DQ 0xccd1c8aaee00bc4f
|
||||
section .text code align=64
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -1824,6 +1824,7 @@ $L$oop_gather_1024:
|
||||
|
||||
$L$SEH_end_rsaz_1024_gather5:
|
||||
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
$L$and_mask:
|
||||
DQ 0x1fffffff,0x1fffffff,0x1fffffff,0x1fffffff
|
||||
@@ -1836,6 +1837,8 @@ $L$inc:
|
||||
DD 2,2,2,2,3,3,3,3
|
||||
DD 4,4,4,4,4,4,4,4
|
||||
ALIGN 64
|
||||
section .text code align=64
|
||||
|
||||
EXTERN __imp_RtlVirtualUnwind
|
||||
|
||||
ALIGN 16
|
||||
|
||||
@@ -5554,6 +5554,7 @@ $L$epilogue_avx2:
|
||||
DB 0F3h,0C3h ;repret
|
||||
|
||||
$L$SEH_end_sha1_block_data_order_avx2:
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
K_XX_XX:
|
||||
DD 0x5a827999,0x5a827999,0x5a827999,0x5a827999
|
||||
@@ -5573,6 +5574,8 @@ K_XX_XX:
|
||||
DB 97,112,112,114,111,64,111,112,101,110,115,115,108,46,111,114
|
||||
DB 103,62,0
|
||||
ALIGN 64
|
||||
section .text code align=64
|
||||
|
||||
EXTERN __imp_RtlVirtualUnwind
|
||||
|
||||
ALIGN 16
|
||||
|
||||
@@ -1749,6 +1749,7 @@ $L$epilogue:
|
||||
DB 0F3h,0C3h ;repret
|
||||
|
||||
$L$SEH_end_sha256_block_data_order:
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
|
||||
K256:
|
||||
@@ -1796,6 +1797,8 @@ K256:
|
||||
DB 52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121
|
||||
DB 32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46
|
||||
DB 111,114,103,62,0
|
||||
section .text code align=64
|
||||
|
||||
|
||||
ALIGN 64
|
||||
sha256_block_data_order_shaext:
|
||||
|
||||
@@ -1745,6 +1745,7 @@ $L$epilogue:
|
||||
DB 0F3h,0C3h ;repret
|
||||
|
||||
$L$SEH_end_sha512_block_data_order:
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
|
||||
K512:
|
||||
@@ -1836,6 +1837,8 @@ K512:
|
||||
DB 52,44,32,67,82,89,80,84,79,71,65,77,83,32,98,121
|
||||
DB 32,60,97,112,112,114,111,64,111,112,101,110,115,115,108,46
|
||||
DB 111,114,103,62,0
|
||||
section .text code align=64
|
||||
|
||||
|
||||
ALIGN 64
|
||||
sha512_block_data_order_avx:
|
||||
|
||||
@@ -1227,6 +1227,7 @@ _vpaes_preheat:
|
||||
|
||||
|
||||
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
_vpaes_consts:
|
||||
$L$k_inv:
|
||||
@@ -1340,6 +1341,8 @@ $L$ctr_add_two:
|
||||
DB 85,110,105,118,101,114,115,105,116,121,41,0
|
||||
ALIGN 64
|
||||
|
||||
section .text code align=64
|
||||
|
||||
EXTERN __imp_RtlVirtualUnwind
|
||||
|
||||
ALIGN 16
|
||||
|
||||
@@ -3679,6 +3679,7 @@ $L$gather:
|
||||
$L$SEH_end_bn_gather5:
|
||||
|
||||
|
||||
section .rdata rdata align=8
|
||||
ALIGN 64
|
||||
$L$inc:
|
||||
DD 0,0,1,1
|
||||
@@ -3689,6 +3690,8 @@ $L$inc:
|
||||
DB 114,32,120,56,54,95,54,52,44,32,67,82,89,80,84,79
|
||||
DB 71,65,77,83,32,98,121,32,60,97,112,112,114,111,64,111
|
||||
DB 112,101,110,115,115,108,46,111,114,103,62,0
|
||||
section .text code align=64
|
||||
|
||||
EXTERN __imp_RtlVirtualUnwind
|
||||
|
||||
ALIGN 16
|
||||
|
||||
Reference in New Issue
Block a user