Revision 1990ae634d0602ff022afc946ef66933e4e4a2dc authored by Santiago Zanella-Beguelin on 09 December 2019, 17:48:55 UTC, committed by Santiago Zanella-Beguelin on 09 December 2019, 17:50:10 UTC
1 parent ae8e182
Raw File
EverCrypt_Poly1305.c
/* MIT License
 *
 * Copyright (c) 2016-2020 INRIA, CMU and Microsoft Corporation
 *
 * Permission is hereby granted, free of charge, to any person obtaining a copy
 * of this software and associated documentation files (the "Software"), to deal
 * in the Software without restriction, including without limitation the rights
 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
 * copies of the Software, and to permit persons to whom the Software is
 * furnished to do so, subject to the following conditions:
 *
 * The above copyright notice and this permission notice shall be included in all
 * copies or substantial portions of the Software.
 *
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
 * SOFTWARE.
 */


#include "EverCrypt_Poly1305.h"

static void
EverCrypt_Poly1305_poly1305_vale(uint8_t *dst, uint8_t *src, uint32_t len, uint8_t *key)
{
  uint8_t ctx[192U] = { 0U };
  uint32_t n_blocks;
  uint32_t n_extra;
  memcpy(ctx + (uint32_t)24U, key, (uint32_t)32U * sizeof key[0U]);
  n_blocks = len / (uint32_t)16U;
  n_extra = len % (uint32_t)16U;
  {
    uint8_t tmp[16U];
    if (n_extra == (uint32_t)0U)
    {
      uint64_t scrut = x64_poly1305(ctx, src, (uint64_t)len, (uint64_t)1U);
    }
    else
    {
      uint8_t init = (uint8_t)0U;
      {
        uint32_t i;
        for (i = (uint32_t)0U; i < (uint32_t)16U; i = i + (uint32_t)1U)
        {
          tmp[i] = init;
        }
      }
      {
        uint32_t len16 = n_blocks * (uint32_t)16U;
        uint8_t *src16 = src;
        memcpy(tmp, src + len16, n_extra * sizeof src[0U]);
        {
          uint64_t scrut = x64_poly1305(ctx, src16, (uint64_t)len16, (uint64_t)0U);
          memcpy(ctx + (uint32_t)24U, key, (uint32_t)32U * sizeof key[0U]);
          {
            uint64_t scrut0 = x64_poly1305(ctx, tmp, (uint64_t)n_extra, (uint64_t)1U);
          }
        }
      }
    }
    memcpy(dst, ctx, (uint32_t)16U * sizeof ctx[0U]);
  }
}

void EverCrypt_Poly1305_poly1305(uint8_t *dst, uint8_t *src, uint32_t len, uint8_t *key)
{
  bool avx2 = EverCrypt_AutoConfig2_has_avx2();
  bool avx = EverCrypt_AutoConfig2_has_avx();
  bool vale = EverCrypt_AutoConfig2_wants_vale();
  #if EVERCRYPT_TARGETCONFIG_X64
  if (avx2)
  {
    Hacl_Poly1305_256_poly1305_mac(dst, len, src, key);
    return;
  }
  #endif
  #if EVERCRYPT_TARGETCONFIG_X64
  if (avx)
  {
    Hacl_Poly1305_128_poly1305_mac(dst, len, src, key);
    return;
  }
  #endif
  #if EVERCRYPT_TARGETCONFIG_X64
  if (vale)
  {
    EverCrypt_Poly1305_poly1305_vale(dst, src, len, key);
    return;
  }
  #endif
  Hacl_Poly1305_32_poly1305_mac(dst, len, src, key);
}

back to top