1
mirror of https://github.com/jedisct1/libsodium.git synced 2024-12-24 04:25:10 -07:00
This commit is contained in:
Frank Denis 2017-02-23 09:05:47 +01:00
parent 05349aa14d
commit c06418a382

View File

@ -1,72 +1,82 @@
#include "crypto_shorthash_siphash24.h"
#include "private/common.h"
typedef uint64_t u64;
typedef uint32_t u32;
typedef uint8_t u8;
#define SIPROUND \
do { \
v0 += v1; \
v1 = ROTL64(v1, 13); \
v1 ^= v0; \
v0 = ROTL64(v0, 32); \
v2 += v3; \
v3 = ROTL64(v3, 16); \
v3 ^= v2; \
v0 += v3; \
v3 = ROTL64(v3, 21); \
v3 ^= v0; \
v2 += v1; \
v1 = ROTL64(v1, 17); \
v1 ^= v2; \
v2 = ROTL64(v2, 32); \
} while (0)
#define ROTL(x, b) ROTL64(x, b)
#define SIPROUND \
do { \
v0 += v1; v1=ROTL(v1,13); v1 ^= v0; v0=ROTL(v0,32); \
v2 += v3; v3=ROTL(v3,16); v3 ^= v2; \
v0 += v3; v3=ROTL(v3,21); v3 ^= v0; \
v2 += v1; v1=ROTL(v1,17); v1 ^= v2; v2=ROTL(v2,32); \
} while(0)
int crypto_shorthash_siphash24(unsigned char *out, const unsigned char *in,
unsigned long long inlen, const unsigned char *k)
int
crypto_shorthash_siphash24(unsigned char *out, const unsigned char *in,
unsigned long long inlen, const unsigned char *k)
{
/* "somepseudorandomlygeneratedbytes" */
u64 v0 = 0x736f6d6570736575ULL;
u64 v1 = 0x646f72616e646f6dULL;
u64 v2 = 0x6c7967656e657261ULL;
u64 v3 = 0x7465646279746573ULL;
u64 b;
u64 k0 = LOAD64_LE( k );
u64 k1 = LOAD64_LE( k + 8 );
u64 m;
const u8 *end = in + inlen - ( inlen % sizeof( u64 ) );
const int left = inlen & 7;
b = ( ( u64 )inlen ) << 56;
v3 ^= k1;
v2 ^= k0;
v1 ^= k1;
v0 ^= k0;
/* "somepseudorandomlygeneratedbytes" */
uint64_t v0 = 0x736f6d6570736575ULL;
uint64_t v1 = 0x646f72616e646f6dULL;
uint64_t v2 = 0x6c7967656e657261ULL;
uint64_t v3 = 0x7465646279746573ULL;
uint64_t b;
uint64_t k0 = LOAD64_LE(k);
uint64_t k1 = LOAD64_LE(k + 8);
uint64_t m;
const uint8_t *end = in + inlen - (inlen % sizeof(uint64_t));
const int left = inlen & 7;
b = ((uint64_t) inlen) << 56;
v3 ^= k1;
v2 ^= k0;
v1 ^= k1;
v0 ^= k0;
for ( ; in != end; in += 8 )
{
m = LOAD64_LE( in );
v3 ^= m;
for (; in != end; in += 8) {
m = LOAD64_LE(in);
v3 ^= m;
SIPROUND;
SIPROUND;
v0 ^= m;
}
switch (left) {
case 7:
b |= ((uint64_t) in[6]) << 48;
case 6:
b |= ((uint64_t) in[5]) << 40;
case 5:
b |= ((uint64_t) in[4]) << 32;
case 4:
b |= ((uint64_t) in[3]) << 24;
case 3:
b |= ((uint64_t) in[2]) << 16;
case 2:
b |= ((uint64_t) in[1]) << 8;
case 1:
b |= ((uint64_t) in[0]);
break;
case 0:
break;
}
v3 ^= b;
SIPROUND;
SIPROUND;
v0 ^= m;
}
v0 ^= b;
v2 ^= 0xff;
SIPROUND;
SIPROUND;
SIPROUND;
SIPROUND;
b = v0 ^ v1 ^ v2 ^ v3;
STORE64_LE(out, b);
switch( left )
{
case 7: b |= ( ( u64 )in[ 6] ) << 48;
case 6: b |= ( ( u64 )in[ 5] ) << 40;
case 5: b |= ( ( u64 )in[ 4] ) << 32;
case 4: b |= ( ( u64 )in[ 3] ) << 24;
case 3: b |= ( ( u64 )in[ 2] ) << 16;
case 2: b |= ( ( u64 )in[ 1] ) << 8;
case 1: b |= ( ( u64 )in[ 0] ); break;
case 0: break;
}
v3 ^= b;
SIPROUND;
SIPROUND;
v0 ^= b;
v2 ^= 0xff;
SIPROUND;
SIPROUND;
SIPROUND;
SIPROUND;
b = v0 ^ v1 ^ v2 ^ v3;
STORE64_LE( out, b );
return 0;
return 0;
}