Compare commits

..
13 Commits
Author SHA1 Message Date
Mathias Buus d546f63e11 0.3.0 2017-06-12 10:19:02 +02:00
Mathias Buus 78f7c7111c add wasm info 2017-06-12 10:15:52 +02:00
Mathias Buus 51875f2288 remove unused assert 2017-06-12 10:10:01 +02:00
Mathias Buus 95732bdd4f add crypto_shorthash (#4) 2017-06-12 10:05:49 +02:00
Emil Bay 1967024766 Update to new blake2b 2017-06-11 20:23:06 +02:00
Emil Bay 776ffea91c Fix keygen overflow bug 2017-06-11 10:44:02 +02:00
Emil Bay 56913733b9 0.2.0 2017-06-07 22:39:24 +02:00
Emil Bay 94e3891f67 Added crypto_kdf 2017-06-07 22:38:40 +02:00
Emil Bay afa3b5fc04 0.1.0 2017-06-06 21:05:48 +02:00
Emil Bay 226ecd8778 Add memzero 2017-06-06 21:04:50 +02:00
Emil Bay 5397910bbb Add blake2b for generichash 2017-06-06 21:04:36 +02:00
Emil Bay f639c1ce6f Fix sodium-test require 2017-04-13 17:59:36 +02:00
Emil Bay 92bea299c6 Add sodium-test script 2017-04-11 22:19:34 +02:00
8 changed files with 622 additions and 27 deletions
+35
View File
@@ -0,0 +1,35 @@
var blake2b = require('blake2b')
module.exports.crypto_generichash_PRIMITIVE = 'blake2b'
module.exports.crypto_generichash_BYTES_MIN = blake2b.BYTES_MIN
module.exports.crypto_generichash_BYTES_MAX = blake2b.BYTES_MAX
module.exports.crypto_generichash_BYTES = blake2b.BYTES
module.exports.crypto_generichash_KEYBYTES_MIN = blake2b.KEYBYTES_MIN
module.exports.crypto_generichash_KEYBYTES_MAX = blake2b.KEYBYTES_MAX
module.exports.crypto_generichash_KEYBYTES = blake2b.KEYBYTES
module.exports.crypto_generichash_WASM_SUPPORTED = blake2b.WASM_SUPPORTED
module.exports.crypto_generichash_WASM_LOADED = false
module.exports.crypto_generichash = function (output, input, key) {
blake2b(output.length, key).update(input).final(output)
}
module.exports.crypto_generichash_ready = blake2b.ready
module.exports.crypto_generichash_batch = function (output, inputArray, key) {
var ctx = blake2b(output.length, key)
for (var i = 0; i < inputArray.length; i++) {
ctx.update(inputArray[i])
}
ctx.final(output)
}
module.exports.crypto_generichash_instance = function (key, outlen) {
if (outlen == null) outlen = module.exports.crypto_generichash_BYTES
return blake2b(outlen, key)
}
blake2b.ready(function (err) {
if (blake2b.WASM_SUPPORTED) module.exports.crypto_generichash_WASM_LOADED = !err
})
+39
View File
@@ -0,0 +1,39 @@
var assert = require('nanoassert')
var randombytes_buf = require('.').randombytes_buf
var blake2b = require('blake2b')
module.exports.crypto_kdf_PRIMITIVE = 'blake2b'
module.exports.crypto_kdf_BYTES_MIN = 16
module.exports.crypto_kdf_BYTES_MAX = 64
module.exports.crypto_kdf_CONTEXTBYTES = 8
module.exports.crypto_kdf_KEYBYTES = 64
function STORE64_LE(dest, int) {
var mul = 1
var i = 0
dest[0] = int & 0xFF
while (++i < 8 && (mul *= 0x100)) {
dest[i] = (int / mul) & 0xFF
}
}
module.exports.crypto_kdf_derive_from_key = function crypto_kdf_derive_from_key (subkey, subkey_id, ctx, key) {
assert(subkey.length >= module.exports.crypto_kdf_BYTES_MIN, 'subkey must be at least crypto_kdf_BYTES_MIN')
assert(subkey_id >= 0 && subkey_id <= 0x1fffffffffffff, 'subkey_id must be safe integer')
assert(ctx.length >= module.exports.crypto_kdf_CONTEXTBYTES, 'context must be at least crypto_kdf_CONTEXTBYTES')
var ctx_padded = new Uint8Array(blake2b.PERSONALBYTES)
var salt = new Uint8Array(blake2b.SALTBYTES)
ctx_padded.set(ctx, 0, module.exports.crypto_kdf_CONTEXTBYTES)
STORE64_LE(salt, subkey_id)
var outlen = Math.min(subkey.length, module.exports.crypto_kdf_BYTES_MAX)
blake2b(outlen, key, salt, ctx_padded, true)
.final(subkey)
}
module.exports.crypto_kdf_keygen = function crypto_kdf_keygen (out) {
assert(out.length >= module.exports.crypto_kdf_KEYBYTES, 'out.length must be crypto_kdf_KEYBYTES')
randombytes_buf(out.subarray(0, module.exports.crypto_kdf_KEYBYTES))
}
+169
View File
@@ -0,0 +1,169 @@
var fs = require('fs')
var toUint8Array = require('base64-to-uint8array')
var assert = require('nanoassert')
var WASM = toUint8Array(fs.readFileSync(__dirname + '/wasm/siphash.wasm', 'base64'))
var mod
var mem
var rdy
var BYTES = exports.crypto_shorthash_BYTES = 8
var KEYBYTES = exports.crypto_shorthash_KEYBYTES = 16
exports.crypto_shorthash_PRIMITIVE = 'siphash24'
exports.crypto_shorthash_WASM_SUPPORTED = typeof WebAssembly !== 'undefined'
exports.crypto_shorthash_WASM_LOADED = false
exports.crypto_shorthash_ready = ready
exports.crypto_shorthash = shorthash
ready(function (err) {
if (!err) exports.crypto_shorthash_WASM_LOADED = true
})
function ready (cb) {
if (!cb) cb = noop
if (!exports.crypto_shorthash_WASM_SUPPORTED) return cb(new Error('WebAssembly not supported'))
if (!rdy) rdy = WebAssembly.instantiate(WASM).then(setup)
return rdy.then(cb).catch(cb)
}
function shorthash (out, data, key, noAssert) {
if (noAssert !== true) {
assert(out.length >= BYTES, 'output must be at least crypto_shorthash_BYTES')
assert(key.length >= KEYBYTES, 'output must be at least crypto_shorthash_KEYBYTES')
}
if (mod) {
mem.set(key, 8)
mem.set(data, 24)
mod.siphash(24, data.length)
out.set(mem.subarray(0, 8))
} else {
fallback(out, data, key)
}
}
function noop () {}
function setup (w) {
mod = w.instance.exports
mem = new Uint8Array(w.instance.exports.siphash_memory.buffer)
}
function _add(a, b) {
var rl = a.l + b.l
var a2 = {
h: a.h + b.h + (rl / 2 >>> 31) >>> 0,
l: rl >>> 0
}
a.h = a2.h
a.l = a2.l
}
function _xor(a, b) {
a.h ^= b.h
a.h >>>= 0
a.l ^= b.l
a.l >>>= 0
}
function _rotl(a, n) {
var a2 = {
h: a.h << n | a.l >>> (32 - n),
l: a.l << n | a.h >>> (32 - n)
}
a.h = a2.h
a.l = a2.l
}
function _rotl32(a) {
var al = a.l
a.l = a.h
a.h = al
}
function _compress(v0, v1, v2, v3) {
_add(v0, v1)
_add(v2, v3)
_rotl(v1, 13)
_rotl(v3, 16)
_xor(v1, v0)
_xor(v3, v2)
_rotl32(v0)
_add(v2, v1)
_add(v0, v3)
_rotl(v1, 17)
_rotl(v3, 21)
_xor(v1, v2)
_xor(v3, v0)
_rotl32(v2)
}
function _get_int(a, offset) {
return (a[offset + 3] << 24) | (a[offset + 2] << 16) | (a[offset + 1] << 8) | a[offset]
}
function fallback (out, m, key) { // modified from https://github.com/jedisct1/siphash-js to use uint8arrays
var k0 = {h: _get_int(key, 4), l: _get_int(key, 0)}
var k1 = {h: _get_int(key, 12), l: _get_int(key, 8)}
var v0 = {h: k0.h, l: k0.l}
var v2 = k0
var v1 = {h: k1.h, l: k1.l}
var v3 = k1
var mi
var mp = 0
var ml = m.length
var ml7 = ml - 7
var buf = new Uint8Array(new ArrayBuffer(8))
_xor(v0, {h: 0x736f6d65, l: 0x70736575})
_xor(v1, {h: 0x646f7261, l: 0x6e646f6d})
_xor(v2, {h: 0x6c796765, l: 0x6e657261})
_xor(v3, {h: 0x74656462, l: 0x79746573})
while (mp < ml7) {
mi = {h: _get_int(m, mp + 4), l: _get_int(m, mp)}
_xor(v3, mi)
_compress(v0, v1, v2, v3)
_compress(v0, v1, v2, v3)
_xor(v0, mi)
mp += 8
}
buf[7] = ml
var ic = 0
while (mp < ml) {
buf[ic++] = m[mp++]
}
while (ic < 7) {
buf[ic++] = 0
}
mi = {
h: buf[7] << 24 | buf[6] << 16 | buf[5] << 8 | buf[4],
l: buf[3] << 24 | buf[2] << 16 | buf[1] << 8 | buf[0]
}
_xor(v3, mi)
_compress(v0, v1, v2, v3)
_compress(v0, v1, v2, v3)
_xor(v0, mi)
_xor(v2, { h: 0, l: 0xff })
_compress(v0, v1, v2, v3)
_compress(v0, v1, v2, v3)
_compress(v0, v1, v2, v3)
_compress(v0, v1, v2, v3)
var h = v0
_xor(h, v1)
_xor(h, v2)
_xor(h, v3)
out[0] = h.l & 0xff
out[1] = (h.l >> 8) & 0xff
out[2] = (h.l >> 16) & 0xff
out[3] = (h.l >> 24) & 0xff
out[4] = h.h & 0xff
out[5] = (h.h >> 8) & 0xff
out[6] = (h.h >> 16) & 0xff
out[7] = (h.h >> 24) & 0xff
}
+14 -24
View File
@@ -2162,21 +2162,6 @@ function crypto_secretbox_open_easy(msg, box, n, k) {
return true
}
var blake2b = require('blakejs/blake2b')
function crypto_generichash (out, data, key) {
var tmp = blake2b.blake2b(data, key, out.length)
for (var i = 0; i < tmp.length; i++) out[i] = tmp[i]
}
function crypto_generichash_batch (out, batch, key) {
var i = 0
var ctx = blake2b.blake2bInit(out.length, key)
for (i = 0; i < batch.length; i++) blake2b.blake2bUpdate(ctx, batch[i])
var tmp = blake2b.blake2bFinal(ctx)
for (var i = 0; i < tmp.length; i++) out[i] = tmp[i]
}
var crypto_secretbox_KEYBYTES = 32,
crypto_secretbox_NONCEBYTES = 24,
crypto_secretbox_ZEROBYTES = 32,
@@ -2195,6 +2180,10 @@ var crypto_secretbox_KEYBYTES = 32,
crypto_sign_SEEDBYTES = 32,
crypto_hash_BYTES = 64;
sodium.memzero = function (len, offset) {
for (var i = offset; i < len; i++) arr[i] = 0;
}
sodium.randombytes_buf = randombytes_buf
sodium.crypto_sign_BYTES = crypto_sign_BYTES
@@ -2208,6 +2197,10 @@ sodium.crypto_sign_open = crypto_sign_open
sodium.crypto_sign_detached = crypto_sign_detached
sodium.crypto_sign_verify_detached = crypto_sign_verify_detached
forward(require('./crypto_generichash'))
forward(require('./crypto_kdf'))
forward(require('./crypto_shorthash'))
sodium.crypto_stream_KEYBYTES = 32
sodium.crypto_stream_NONCEBYTES = 24
sodium.crypto_stream = crypto_stream_wrap
@@ -2224,15 +2217,6 @@ sodium.crypto_secretbox_MACBYTES = 16
sodium.crypto_secretbox_easy = crypto_secretbox_easy
sodium.crypto_secretbox_open_easy = crypto_secretbox_open_easy
sodium.crypto_generichash_BYTES_MIN = 16
sodium.crypto_generichash_BYTES_MAX = 64
sodium.crypto_generichash_BYTES = 32
sodium.crypto_generichash_KEYBYTES_MIN = 16
sodium.crypto_generichash_KEYBYTES_MAX = 64
sodium.crypto_generichash_KEYBYTES = 32
sodium.crypto_generichash = crypto_generichash
sodium.crypto_generichash_batch = crypto_generichash_batch
function cleanup(arr) {
for (var i = 0; i < arr.length; i++) arr[i] = 0;
}
@@ -2241,6 +2225,12 @@ function check (buf, len) {
if (!buf || (len && buf.length < len)) throw new Error('Argument must be a buffer' + (len ? ' of length ' + len : ''))
}
function forward (submodule) {
Object.keys(submodule).forEach(function (prop) {
module.exports[prop] = submodule[prop]
})
}
(function() {
// Initialize PRNG if environment provides CSPRNG.
// If not, methods calling randombytes will throw.
+16 -3
View File
@@ -1,12 +1,25 @@
{
"name": "sodium-javascript",
"version": "0.0.1",
"version": "0.3.0",
"description": "WIP - a pure javascript version of sodium-native",
"main": "index.js",
"dependencies": {
"blakejs": "^1.0.1"
"base64-to-uint8array": "^1.0.0",
"blake2b": "^2.1.1",
"brfs": "^1.4.3",
"nanoassert": "^1.0.0"
},
"devDependencies": {
"sodium-test": "^0.4.0"
},
"scripts": {
"test": " node test.js"
},
"browserify": {
"transform": [
"brfs"
]
},
"devDependencies": {},
"repository": {
"type": "git",
"url": "https://github.com/mafintosh/sodium-javascript.git"
+1
View File
@@ -0,0 +1 @@
require('sodium-test')(require('.'))
BIN
View File
Binary file not shown.
+348
View File
@@ -0,0 +1,348 @@
(module
(memory (export "siphash_memory") 10 10)
(func (export "siphash") (param $ptr i32) (param $ptr_len i32)
(local $v0 i64)
(local $v1 i64)
(local $v2 i64)
(local $v3 i64)
(local $b i64)
(local $k0 i64)
(local $k1 i64)
(local $m i64)
(local $end i32)
(local $left i32)
(set_local $v0 (i64.const 0x736f6d6570736575))
(set_local $v1 (i64.const 0x646f72616e646f6d))
(set_local $v2 (i64.const 0x6c7967656e657261))
(set_local $v3 (i64.const 0x7465646279746573))
(set_local $k0 (i64.load (i32.const 8)))
(set_local $k1 (i64.load (i32.const 16)))
;; b = ((uint64_t) inlen) << 56;
(set_local $b (i64.shl (i64.extend_u/i32 (get_local $ptr_len)) (i64.const 56)))
;; left = inlen & 7;
(set_local $left (i32.and (get_local $ptr_len) (i32.const 7)))
;; end = in + inlen - left;
(set_local $end (i32.sub (i32.add (get_local $ptr) (get_local $ptr_len)) (get_local $left)))
;; v3 ^= k1;
(set_local $v3 (i64.xor (get_local $v3) (get_local $k1)))
;; v2 ^= k0;
(set_local $v2 (i64.xor (get_local $v2) (get_local $k0)))
;; v1 ^= k1;
(set_local $v1 (i64.xor (get_local $v1) (get_local $k1)))
;; v0 ^= k0;
(set_local $v0 (i64.xor (get_local $v0) (get_local $k0)))
(block $end_loop
(loop $start_loop
(br_if $end_loop (i32.eq (get_local $ptr) (get_local $end)))
;; m = LOAD64_LE(in);
(set_local $m (i64.load (get_local $ptr)))
;; v3 ^= m
(set_local $v3 (i64.xor (get_local $v3) (get_local $m)))
;; SIPROUND
;; v0 += v1;
(set_local $v0 (i64.add (get_local $v0) (get_local $v1)))
;; v1 = ROTL64(v1, 13);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 13)))
;; v1 ^= v0;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v0)))
;; v0 = ROTL64(v0, 32)
(set_local $v0 (i64.rotl (get_local $v0) (i64.const 32)))
;; v2 += v3;
(set_local $v2 (i64.add (get_local $v2) (get_local $v3)))
;; v3 = ROTL64(v3, 16);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 16)))
;; v3 ^= v2;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v2)))
;; v0 += v3;
(set_local $v0 (i64.add (get_local $v0) (get_local $v3)))
;; v3 = ROTL64(v3, 21);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 21)))
;; v3 ^= v0;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v0)))
;; v2 += v1;
(set_local $v2 (i64.add (get_local $v2) (get_local $v1)))
;; v1 = ROTL64(v1, 17);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 17)))
;; v1 ^= v2;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v2)))
;; v2 = ROTL64(v2, 32);
(set_local $v2 (i64.rotl (get_local $v2) (i64.const 32)))
;; SIPROUND
;; v0 += v1;
(set_local $v0 (i64.add (get_local $v0) (get_local $v1)))
;; v1 = ROTL64(v1, 13);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 13)))
;; v1 ^= v0;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v0)))
;; v0 = ROTL64(v0, 32)
(set_local $v0 (i64.rotl (get_local $v0) (i64.const 32)))
;; v2 += v3;
(set_local $v2 (i64.add (get_local $v2) (get_local $v3)))
;; v3 = ROTL64(v3, 16);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 16)))
;; v3 ^= v2;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v2)))
;; v0 += v3;
(set_local $v0 (i64.add (get_local $v0) (get_local $v3)))
;; v3 = ROTL64(v3, 21);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 21)))
;; v3 ^= v0;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v0)))
;; v2 += v1;
(set_local $v2 (i64.add (get_local $v2) (get_local $v1)))
;; v1 = ROTL64(v1, 17);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 17)))
;; v1 ^= v2;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v2)))
;; v2 = ROTL64(v2, 32);
(set_local $v2 (i64.rotl (get_local $v2) (i64.const 32)))
;; v0 ^= m;
(set_local $v0 (i64.xor (get_local $v0) (get_local $m)))
;; ptr += 8
(set_local $ptr (i32.add (get_local $ptr) (i32.const 8)))
(br $start_loop)
)
)
(block $0
(block $1
(block $2
(block $3
(block $4
(block $5
(block $6
(block $7
(br_table $0 $1 $2 $3 $4 $5 $6 $7 (get_local $left))
)
;; b |= ((uint64_t) in[6]) << 48;
(set_local $b (i64.or (get_local $b) (i64.shl (i64.load8_u (i32.add (get_local $ptr) (i32.const 6))) (i64.const 48))))
)
;; b |= ((uint64_t) in[5]) << 40;
(set_local $b (i64.or (get_local $b) (i64.shl (i64.load8_u (i32.add (get_local $ptr) (i32.const 5))) (i64.const 40))))
)
;; b |= ((uint64_t) in[4]) << 32;
(set_local $b (i64.or (get_local $b) (i64.shl (i64.load8_u (i32.add (get_local $ptr) (i32.const 4))) (i64.const 32))))
)
;; b |= ((uint64_t) in[3]) << 24;
(set_local $b (i64.or (get_local $b) (i64.shl (i64.load8_u (i32.add (get_local $ptr) (i32.const 3))) (i64.const 24))))
)
;; b |= ((uint64_t) in[2]) << 16;
(set_local $b (i64.or (get_local $b) (i64.shl (i64.load8_u (i32.add (get_local $ptr) (i32.const 2))) (i64.const 16))))
)
;; b |= ((uint64_t) in[1]) << 8;
(set_local $b (i64.or (get_local $b) (i64.shl (i64.load8_u (i32.add (get_local $ptr) (i32.const 1))) (i64.const 8))))
)
;; b |= ((uint64_t) in[0]);
(set_local $b (i64.or (get_local $b) (i64.load8_u (get_local $ptr))))
)
;; v3 ^= b;
(set_local $v3 (i64.xor (get_local $v3) (get_local $b)))
;; SIPROUND
;; v0 += v1;
(set_local $v0 (i64.add (get_local $v0) (get_local $v1)))
;; v1 = ROTL64(v1, 13);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 13)))
;; v1 ^= v0;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v0)))
;; v0 = ROTL64(v0, 32)
(set_local $v0 (i64.rotl (get_local $v0) (i64.const 32)))
;; v2 += v3;
(set_local $v2 (i64.add (get_local $v2) (get_local $v3)))
;; v3 = ROTL64(v3, 16);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 16)))
;; v3 ^= v2;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v2)))
;; v0 += v3;
(set_local $v0 (i64.add (get_local $v0) (get_local $v3)))
;; v3 = ROTL64(v3, 21);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 21)))
;; v3 ^= v0;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v0)))
;; v2 += v1;
(set_local $v2 (i64.add (get_local $v2) (get_local $v1)))
;; v1 = ROTL64(v1, 17);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 17)))
;; v1 ^= v2;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v2)))
;; v2 = ROTL64(v2, 32);
(set_local $v2 (i64.rotl (get_local $v2) (i64.const 32)))
;; SIPROUND
;; v0 += v1;
(set_local $v0 (i64.add (get_local $v0) (get_local $v1)))
;; v1 = ROTL64(v1, 13);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 13)))
;; v1 ^= v0;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v0)))
;; v0 = ROTL64(v0, 32)
(set_local $v0 (i64.rotl (get_local $v0) (i64.const 32)))
;; v2 += v3;
(set_local $v2 (i64.add (get_local $v2) (get_local $v3)))
;; v3 = ROTL64(v3, 16);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 16)))
;; v3 ^= v2;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v2)))
;; v0 += v3;
(set_local $v0 (i64.add (get_local $v0) (get_local $v3)))
;; v3 = ROTL64(v3, 21);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 21)))
;; v3 ^= v0;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v0)))
;; v2 += v1;
(set_local $v2 (i64.add (get_local $v2) (get_local $v1)))
;; v1 = ROTL64(v1, 17);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 17)))
;; v1 ^= v2;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v2)))
;; v2 = ROTL64(v2, 32);
(set_local $v2 (i64.rotl (get_local $v2) (i64.const 32)))
;; v0 ^= b;
(set_local $v0 (i64.xor (get_local $v0) (get_local $b)))
;; v2 ^= 0xff;
(set_local $v2 (i64.xor (get_local $v2) (i64.const 0xff)))
;; SIPROUND
;; v0 += v1;
(set_local $v0 (i64.add (get_local $v0) (get_local $v1)))
;; v1 = ROTL64(v1, 13);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 13)))
;; v1 ^= v0;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v0)))
;; v0 = ROTL64(v0, 32)
(set_local $v0 (i64.rotl (get_local $v0) (i64.const 32)))
;; v2 += v3;
(set_local $v2 (i64.add (get_local $v2) (get_local $v3)))
;; v3 = ROTL64(v3, 16);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 16)))
;; v3 ^= v2;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v2)))
;; v0 += v3;
(set_local $v0 (i64.add (get_local $v0) (get_local $v3)))
;; v3 = ROTL64(v3, 21);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 21)))
;; v3 ^= v0;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v0)))
;; v2 += v1;
(set_local $v2 (i64.add (get_local $v2) (get_local $v1)))
;; v1 = ROTL64(v1, 17);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 17)))
;; v1 ^= v2;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v2)))
;; v2 = ROTL64(v2, 32);
(set_local $v2 (i64.rotl (get_local $v2) (i64.const 32)))
;; SIPROUND
;; v0 += v1;
(set_local $v0 (i64.add (get_local $v0) (get_local $v1)))
;; v1 = ROTL64(v1, 13);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 13)))
;; v1 ^= v0;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v0)))
;; v0 = ROTL64(v0, 32)
(set_local $v0 (i64.rotl (get_local $v0) (i64.const 32)))
;; v2 += v3;
(set_local $v2 (i64.add (get_local $v2) (get_local $v3)))
;; v3 = ROTL64(v3, 16);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 16)))
;; v3 ^= v2;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v2)))
;; v0 += v3;
(set_local $v0 (i64.add (get_local $v0) (get_local $v3)))
;; v3 = ROTL64(v3, 21);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 21)))
;; v3 ^= v0;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v0)))
;; v2 += v1;
(set_local $v2 (i64.add (get_local $v2) (get_local $v1)))
;; v1 = ROTL64(v1, 17);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 17)))
;; v1 ^= v2;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v2)))
;; v2 = ROTL64(v2, 32);
(set_local $v2 (i64.rotl (get_local $v2) (i64.const 32)))
;; SIPROUND
;; v0 += v1;
(set_local $v0 (i64.add (get_local $v0) (get_local $v1)))
;; v1 = ROTL64(v1, 13);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 13)))
;; v1 ^= v0;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v0)))
;; v0 = ROTL64(v0, 32)
(set_local $v0 (i64.rotl (get_local $v0) (i64.const 32)))
;; v2 += v3;
(set_local $v2 (i64.add (get_local $v2) (get_local $v3)))
;; v3 = ROTL64(v3, 16);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 16)))
;; v3 ^= v2;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v2)))
;; v0 += v3;
(set_local $v0 (i64.add (get_local $v0) (get_local $v3)))
;; v3 = ROTL64(v3, 21);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 21)))
;; v3 ^= v0;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v0)))
;; v2 += v1;
(set_local $v2 (i64.add (get_local $v2) (get_local $v1)))
;; v1 = ROTL64(v1, 17);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 17)))
;; v1 ^= v2;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v2)))
;; v2 = ROTL64(v2, 32);
(set_local $v2 (i64.rotl (get_local $v2) (i64.const 32)))
;; SIPROUND
;; v0 += v1;
(set_local $v0 (i64.add (get_local $v0) (get_local $v1)))
;; v1 = ROTL64(v1, 13);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 13)))
;; v1 ^= v0;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v0)))
;; v0 = ROTL64(v0, 32)
(set_local $v0 (i64.rotl (get_local $v0) (i64.const 32)))
;; v2 += v3;
(set_local $v2 (i64.add (get_local $v2) (get_local $v3)))
;; v3 = ROTL64(v3, 16);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 16)))
;; v3 ^= v2;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v2)))
;; v0 += v3;
(set_local $v0 (i64.add (get_local $v0) (get_local $v3)))
;; v3 = ROTL64(v3, 21);
(set_local $v3 (i64.rotl (get_local $v3) (i64.const 21)))
;; v3 ^= v0;
(set_local $v3 (i64.xor (get_local $v3) (get_local $v0)))
;; v2 += v1;
(set_local $v2 (i64.add (get_local $v2) (get_local $v1)))
;; v1 = ROTL64(v1, 17);
(set_local $v1 (i64.rotl (get_local $v1) (i64.const 17)))
;; v1 ^= v2;
(set_local $v1 (i64.xor (get_local $v1) (get_local $v2)))
;; v2 = ROTL64(v2, 32);
(set_local $v2 (i64.rotl (get_local $v2) (i64.const 32)))
;; b = v0 ^ v1 ^ v2 ^ v3;
(i64.store (i32.const 0) (i64.xor (get_local $v0) (i64.xor (get_local $v1) (i64.xor (get_local $v2) (get_local $v3)))))
)
)