update master-with-bazel from master branch

This commit is contained in:
BoringSSL Robot
2024-05-22 13:10:16 +00:00
10 changed files with 1256 additions and 8 deletions
+2
View File
@@ -285,6 +285,8 @@ crypto_test_data = [
"src/crypto/cipher_extra/test/xchacha20_poly1305_tests.txt",
"src/crypto/curve25519/ed25519_tests.txt",
"src/crypto/dilithium/dilithium_tests.txt",
"src/crypto/dilithium/edge_cases_draft_dilithium3_sign.txt",
"src/crypto/dilithium/edge_cases_draft_dilithium3_verify.txt",
"src/crypto/ecdh_extra/ecdh_tests.txt",
"src/crypto/evp/evp_tests.txt",
"src/crypto/evp/scrypt_tests.txt",
+2
View File
@@ -664,6 +664,8 @@
"src/crypto/cipher_extra/test/xchacha20_poly1305_tests.txt",
"src/crypto/curve25519/ed25519_tests.txt",
"src/crypto/dilithium/dilithium_tests.txt",
"src/crypto/dilithium/edge_cases_draft_dilithium3_sign.txt",
"src/crypto/dilithium/edge_cases_draft_dilithium3_verify.txt",
"src/crypto/ecdh_extra/ecdh_tests.txt",
"src/crypto/evp/evp_tests.txt",
"src/crypto/evp/scrypt_tests.txt",
+2
View File
@@ -861,6 +861,8 @@
"crypto/cipher_extra/test/nist_cavp/*.txt",
"crypto/curve25519/ed25519_tests.txt",
"crypto/dilithium/dilithium_tests.txt",
"crypto/dilithium/edge_cases_draft_dilithium3_sign.txt",
"crypto/dilithium/edge_cases_draft_dilithium3_verify.txt",
"crypto/ecdh_extra/ecdh_tests.txt",
"crypto/evp/evp_tests.txt",
"crypto/evp/scrypt_tests.txt",
+8 -8
View File
@@ -721,8 +721,8 @@ static void scalar_from_keccak_vartime(
}
// FIPS 204, Algorithm 25 (`RejBoundedPoly`).
static void scalar_uniform_eta_4(
scalar *out, const uint8_t derived_seed[SIGMA_BYTES + 2]) {
static void scalar_uniform_eta_4(scalar *out,
const uint8_t derived_seed[SIGMA_BYTES + 2]) {
static_assert(ETA == 4, "This implementation is specialized for ETA == 4");
struct BORINGSSL_keccak_st keccak_ctx;
@@ -827,7 +827,7 @@ static void matrix_expand(matrix *out, const uint8_t rho[RHO_BYTES]) {
// FIPS 204, Algorithm 27 (`ExpandS`).
static void vector_expand_short(vectorl *s1, vectork *s2,
const uint8_t sigma[SIGMA_BYTES]) {
const uint8_t sigma[SIGMA_BYTES]) {
static_assert(K <= 0x100, "K must fit in 8 bits");
static_assert(L <= 0x100, "L must fit in 8 bits");
static_assert(K + L <= 0x100, "K+L must fit in 8 bits");
@@ -1273,15 +1273,15 @@ static int dilithium_sign_with_randomizer(
matrix_expand(&values->a_ntt, priv->rho);
for (size_t kappa = 0;; kappa += L) {
//TODO(bbe): y only lives long enough to compute y_ntt.
//consider using another vectorl to save memory.
// TODO(bbe): y only lives long enough to compute y_ntt.
// consider using another vectorl to save memory.
vectorl_expand_mask(&values->y, rho_prime, kappa);
OPENSSL_memcpy(&values->y_ntt, &values->y, sizeof(values->y_ntt));
vectorl_ntt(&values->y_ntt);
//TODO(bbe): w only lives long enough to compute y_ntt.
//consider using another vectork to save memory.
// TODO(bbe): w only lives long enough to compute y_ntt.
// consider using another vectork to save memory.
matrix_mult(&values->w, &values->a_ntt, &values->y_ntt);
vectork_inverse_ntt(&values->w);
@@ -1334,7 +1334,7 @@ static int dilithium_sign_with_randomizer(
uint32_t ct0_max = vectork_max(&values->ct0);
size_t h_ones = vectork_count_ones(&values->sign.h);
if (constant_time_declassify_w(constant_time_ge_w(ct0_max, kGamma2) |
constant_time_ge_w(h_ones, OMEGA))) {
constant_time_lt_w(OMEGA, h_ones))) {
continue;
}
+84
View File
@@ -256,10 +256,94 @@ static void DilithiumFileTest(FileTest *t) {
Bytes(encoded_private_key.get(), DILITHIUM_PRIVATE_KEY_BYTES));
}
static void DilithiumSignFileTest(FileTest *t) {
std::string description, valid;
std::vector<uint8_t> message, private_key, signed_message_expected;
ASSERT_TRUE(t->GetAttribute(&description, "description"));
t->IgnoreAttribute("mlen");
ASSERT_TRUE(t->GetBytes(&message, "msg"));
ASSERT_TRUE(t->GetBytes(&private_key, "sk"));
ASSERT_TRUE(t->GetAttribute(&valid, "valid"));
t->IgnoreAttribute("smlen");
ASSERT_TRUE(t->GetBytes(&signed_message_expected, "sm"));
bool is_valid = valid == "true";
// Parse private key.
DILITHIUM_private_key priv;
CBS cbs;
CBS_init(&cbs, private_key.data(), private_key.size());
if (!DILITHIUM_parse_private_key(&priv, &cbs)) {
EXPECT_FALSE(is_valid) << "Unexpected signing result for edge case: "
<< description;
return;
}
// Reproduce signature.
uint8_t encoded_signature[DILITHIUM_SIGNATURE_BYTES];
DILITHIUM_sign_deterministic(encoded_signature, &priv, message.data(),
message.size());
ASSERT_GE(signed_message_expected.size(), (size_t)DILITHIUM_SIGNATURE_BYTES);
EXPECT_EQ(Bytes(encoded_signature),
Bytes(signed_message_expected.data(), DILITHIUM_SIGNATURE_BYTES))
<< "Unexpected signing result for edge case: " << description;
EXPECT_EQ(Bytes(message),
Bytes(&signed_message_expected[DILITHIUM_SIGNATURE_BYTES],
signed_message_expected.size() - DILITHIUM_SIGNATURE_BYTES))
<< "Unexpected signing result for edge case: " << description;
EXPECT_TRUE(is_valid) << "Unexpected signing result for edge case: "
<< description;
}
static void DilithiumVerifyFileTest(FileTest *t) {
std::string description, valid;
std::vector<uint8_t> message, public_key, signed_message;
ASSERT_TRUE(t->GetAttribute(&description, "description"));
t->IgnoreAttribute("mlen");
ASSERT_TRUE(t->GetBytes(&message, "msg"));
ASSERT_TRUE(t->GetBytes(&public_key, "pk"));
ASSERT_TRUE(t->GetAttribute(&valid, "valid"));
t->IgnoreAttribute("smlen");
ASSERT_TRUE(t->GetBytes(&signed_message, "sm"));
bool is_valid = valid == "true";
// Parse public key.
DILITHIUM_public_key pub;
CBS cbs;
CBS_init(&cbs, public_key.data(), public_key.size());
if (!DILITHIUM_parse_public_key(&pub, &cbs)) {
EXPECT_FALSE(is_valid) << "Unexpected verification result for edge case: "
<< description;
return;
}
// Verify signature.
ASSERT_GE(signed_message.size(), (size_t)DILITHIUM_SIGNATURE_BYTES);
EXPECT_EQ(DILITHIUM_verify(&pub, signed_message.data(),
&signed_message[DILITHIUM_SIGNATURE_BYTES],
signed_message.size() - DILITHIUM_SIGNATURE_BYTES),
is_valid)
<< "Unexpected verification result for edge case: " << description;
}
TEST(DilithiumTest, TestVectors) {
FileTestGTest("crypto/dilithium/dilithium_tests.txt", DilithiumFileTest);
}
TEST(DilithiumTest, EdgeCaseSigningTests) {
FileTestGTest("crypto/dilithium/edge_cases_draft_dilithium3_sign.txt",
DilithiumSignFileTest);
}
TEST(DilithiumTest, EdgeCaseVerifyTests) {
FileTestGTest("crypto/dilithium/edge_cases_draft_dilithium3_verify.txt",
DilithiumVerifyFileTest);
}
TEST(DilithiumTest, KeyGenerationHardCodedNIST) {
// Published on
// https://csrc.nist.gov/Projects/post-quantum-cryptography/post-quantum-cryptography-standardization/example-files
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+2
View File
@@ -785,6 +785,8 @@ crypto_test_data = [
"crypto/cipher_extra/test/xchacha20_poly1305_tests.txt",
"crypto/curve25519/ed25519_tests.txt",
"crypto/dilithium/dilithium_tests.txt",
"crypto/dilithium/edge_cases_draft_dilithium3_sign.txt",
"crypto/dilithium/edge_cases_draft_dilithium3_verify.txt",
"crypto/ecdh_extra/ecdh_tests.txt",
"crypto/evp/evp_tests.txt",
"crypto/evp/scrypt_tests.txt",
+2
View File
@@ -811,6 +811,8 @@ set(
crypto/cipher_extra/test/xchacha20_poly1305_tests.txt
crypto/curve25519/ed25519_tests.txt
crypto/dilithium/dilithium_tests.txt
crypto/dilithium/edge_cases_draft_dilithium3_sign.txt
crypto/dilithium/edge_cases_draft_dilithium3_verify.txt
crypto/ecdh_extra/ecdh_tests.txt
crypto/evp/evp_tests.txt
crypto/evp/scrypt_tests.txt
+2
View File
@@ -765,6 +765,8 @@
"crypto/cipher_extra/test/xchacha20_poly1305_tests.txt",
"crypto/curve25519/ed25519_tests.txt",
"crypto/dilithium/dilithium_tests.txt",
"crypto/dilithium/edge_cases_draft_dilithium3_sign.txt",
"crypto/dilithium/edge_cases_draft_dilithium3_verify.txt",
"crypto/ecdh_extra/ecdh_tests.txt",
"crypto/evp/evp_tests.txt",
"crypto/evp/scrypt_tests.txt",