2016-08-01 05:25:37 +00:00
|
|
|
/*
|
2017-02-02 10:06:28 +00:00
|
|
|
This file is part of solidity.
|
2016-08-01 05:25:37 +00:00
|
|
|
|
2017-02-02 10:06:28 +00:00
|
|
|
solidity is free software: you can redistribute it and/or modify
|
2016-08-01 05:25:37 +00:00
|
|
|
it under the terms of the GNU General Public License as published by
|
|
|
|
the Free Software Foundation, either version 3 of the License, or
|
|
|
|
(at your option) any later version.
|
|
|
|
|
2017-02-02 10:06:28 +00:00
|
|
|
solidity is distributed in the hope that it will be useful,
|
2016-08-01 05:25:37 +00:00
|
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
GNU General Public License for more details.
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License
|
2017-02-02 10:06:28 +00:00
|
|
|
along with solidity. If not, see <http://www.gnu.org/licenses/>.
|
2016-08-01 05:25:37 +00:00
|
|
|
*/
|
2020-07-17 14:54:12 +00:00
|
|
|
// SPDX-License-Identifier: GPL-3.0
|
2016-08-01 05:25:37 +00:00
|
|
|
/** @file SHA3.cpp
|
|
|
|
* @author Gav Wood <i@gavwood.com>
|
|
|
|
* @date 2014
|
|
|
|
*/
|
|
|
|
|
2020-01-06 10:52:23 +00:00
|
|
|
#include <libsolutil/Keccak256.h>
|
2018-10-18 11:35:20 +00:00
|
|
|
|
2016-08-01 05:25:37 +00:00
|
|
|
#include <cstdint>
|
|
|
|
#include <cstring>
|
2016-10-15 15:12:14 +00:00
|
|
|
|
2019-12-11 16:31:36 +00:00
|
|
|
namespace solidity::util
|
2016-08-01 05:25:37 +00:00
|
|
|
{
|
|
|
|
|
2018-10-17 22:48:28 +00:00
|
|
|
namespace
|
2016-08-01 05:25:37 +00:00
|
|
|
{
|
|
|
|
|
|
|
|
/** libkeccak-tiny
|
|
|
|
*
|
|
|
|
* A single-file implementation of SHA-3 and SHAKE.
|
|
|
|
*
|
|
|
|
* Implementor: David Leon Gil
|
|
|
|
* License: CC0, attribution kindly requested. Blame taken too,
|
|
|
|
* but not liability.
|
|
|
|
*/
|
|
|
|
|
|
|
|
/******** The Keccak-f[1600] permutation ********/
|
|
|
|
|
|
|
|
/*** Constants. ***/
|
2019-02-14 10:53:00 +00:00
|
|
|
static uint8_t const rho[24] = \
|
2018-09-20 09:41:59 +00:00
|
|
|
{ 1, 3, 6, 10, 15, 21,
|
2016-08-01 05:25:37 +00:00
|
|
|
28, 36, 45, 55, 2, 14,
|
|
|
|
27, 41, 56, 8, 25, 43,
|
|
|
|
62, 18, 39, 61, 20, 44};
|
2019-02-14 10:53:00 +00:00
|
|
|
static uint8_t const pi[24] = \
|
2018-09-20 09:41:59 +00:00
|
|
|
{10, 7, 11, 17, 18, 3,
|
2016-08-01 05:25:37 +00:00
|
|
|
5, 16, 8, 21, 24, 4,
|
2018-09-20 09:41:59 +00:00
|
|
|
15, 23, 19, 13, 12, 2,
|
|
|
|
20, 14, 22, 9, 6, 1};
|
2019-02-14 10:53:00 +00:00
|
|
|
static uint64_t const RC[24] = \
|
2018-09-20 09:41:59 +00:00
|
|
|
{1ULL, 0x8082ULL, 0x800000000000808aULL, 0x8000000080008000ULL,
|
|
|
|
0x808bULL, 0x80000001ULL, 0x8000000080008081ULL, 0x8000000000008009ULL,
|
|
|
|
0x8aULL, 0x88ULL, 0x80008009ULL, 0x8000000aULL,
|
|
|
|
0x8000808bULL, 0x800000000000008bULL, 0x8000000000008089ULL, 0x8000000000008003ULL,
|
|
|
|
0x8000000000008002ULL, 0x8000000000000080ULL, 0x800aULL, 0x800000008000000aULL,
|
|
|
|
0x8000000080008081ULL, 0x8000000000008080ULL, 0x80000001ULL, 0x8000000080008008ULL};
|
2016-08-01 05:25:37 +00:00
|
|
|
|
|
|
|
/*** Helper macros to unroll the permutation. ***/
|
|
|
|
#define rol(x, s) (((x) << s) | ((x) >> (64 - s)))
|
|
|
|
#define REPEAT6(e) e e e e e e
|
|
|
|
#define REPEAT24(e) REPEAT6(e e e e)
|
|
|
|
#define REPEAT5(e) e e e e e
|
2020-06-05 12:13:35 +00:00
|
|
|
#define FOR5(type, v, s, e) \
|
2019-02-13 15:56:46 +00:00
|
|
|
v = 0; \
|
2020-06-05 12:13:35 +00:00
|
|
|
REPEAT5(e; v = static_cast<type>(v + s);)
|
2016-08-01 05:25:37 +00:00
|
|
|
|
|
|
|
/*** Keccak-f[1600] ***/
|
|
|
|
static inline void keccakf(void* state) {
|
2020-06-05 12:13:35 +00:00
|
|
|
auto* a = static_cast<uint64_t*>(state);
|
2018-09-20 09:41:59 +00:00
|
|
|
uint64_t b[5] = {0};
|
|
|
|
|
|
|
|
for (int i = 0; i < 24; i++)
|
|
|
|
{
|
|
|
|
uint8_t x, y;
|
|
|
|
// Theta
|
2020-06-05 12:13:35 +00:00
|
|
|
FOR5(uint8_t, x, 1,
|
2019-02-13 15:56:46 +00:00
|
|
|
b[x] = 0;
|
2020-06-05 12:13:35 +00:00
|
|
|
FOR5(uint8_t, y, 5,
|
2019-02-13 15:56:46 +00:00
|
|
|
b[x] ^= a[x + y]; ))
|
2020-06-05 12:13:35 +00:00
|
|
|
FOR5(uint8_t, x, 1,
|
|
|
|
FOR5(uint8_t, y, 5,
|
2019-02-13 15:56:46 +00:00
|
|
|
a[y + x] ^= b[(x + 4) % 5] ^ rol(b[(x + 1) % 5], 1); ))
|
2018-09-20 09:41:59 +00:00
|
|
|
// Rho and pi
|
|
|
|
uint64_t t = a[1];
|
|
|
|
x = 0;
|
|
|
|
REPEAT24(b[0] = a[pi[x]];
|
2019-02-13 15:56:46 +00:00
|
|
|
a[pi[x]] = rol(t, rho[x]);
|
|
|
|
t = b[0];
|
|
|
|
x++; )
|
2018-09-20 09:41:59 +00:00
|
|
|
// Chi
|
2020-06-05 12:13:35 +00:00
|
|
|
FOR5(uint8_t,
|
|
|
|
y,
|
2019-02-13 15:56:46 +00:00
|
|
|
5,
|
2020-06-05 12:13:35 +00:00
|
|
|
FOR5(uint8_t, x, 1,
|
2018-09-20 09:41:59 +00:00
|
|
|
b[x] = a[y + x];)
|
2020-06-05 12:13:35 +00:00
|
|
|
FOR5(uint8_t, x, 1,
|
2018-09-20 09:41:59 +00:00
|
|
|
a[y + x] = b[x] ^ ((~b[(x + 1) % 5]) & b[(x + 2) % 5]); ))
|
|
|
|
// Iota
|
|
|
|
a[0] ^= RC[i];
|
|
|
|
}
|
2016-08-01 05:25:37 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/******** The FIPS202-defined functions. ********/
|
|
|
|
|
|
|
|
/*** Some helper macros. ***/
|
|
|
|
|
|
|
|
#define _(S) do { S } while (0)
|
|
|
|
#define FOR(i, ST, L, S) \
|
2019-02-13 15:56:46 +00:00
|
|
|
_(for (size_t i = 0; i < L; i += ST) { S; })
|
2016-08-01 05:25:37 +00:00
|
|
|
#define mkapply_ds(NAME, S) \
|
2019-02-13 15:56:46 +00:00
|
|
|
static inline void NAME(uint8_t* dst, \
|
2019-02-14 10:53:00 +00:00
|
|
|
uint8_t const* src, \
|
2019-02-13 15:56:46 +00:00
|
|
|
size_t len) { \
|
|
|
|
FOR(i, 1, len, S); \
|
|
|
|
}
|
2016-08-01 05:25:37 +00:00
|
|
|
#define mkapply_sd(NAME, S) \
|
2019-02-13 15:56:46 +00:00
|
|
|
static inline void NAME(uint8_t const* src, \
|
|
|
|
uint8_t* dst, \
|
|
|
|
size_t len) { \
|
|
|
|
FOR(i, 1, len, S); \
|
|
|
|
}
|
2016-08-01 05:25:37 +00:00
|
|
|
|
|
|
|
mkapply_ds(xorin, dst[i] ^= src[i]) // xorin
|
|
|
|
mkapply_sd(setout, dst[i] = src[i]) // setout
|
|
|
|
|
|
|
|
#define P keccakf
|
|
|
|
#define Plen 200
|
|
|
|
|
|
|
|
// Fold P*F over the full blocks of an input.
|
|
|
|
#define foldP(I, L, F) \
|
2019-02-13 15:56:46 +00:00
|
|
|
while (L >= rate) { \
|
|
|
|
F(a, I, rate); \
|
|
|
|
P(a); \
|
|
|
|
I += rate; \
|
|
|
|
L -= rate; \
|
|
|
|
}
|
2016-08-01 05:25:37 +00:00
|
|
|
|
|
|
|
/** The sponge-based hash construction. **/
|
2018-10-17 22:48:28 +00:00
|
|
|
inline void hash(
|
|
|
|
uint8_t* out,
|
|
|
|
size_t outlen,
|
2019-02-14 10:53:00 +00:00
|
|
|
uint8_t const* in,
|
2018-10-17 22:48:28 +00:00
|
|
|
size_t inlen,
|
|
|
|
size_t rate,
|
|
|
|
uint8_t delim
|
|
|
|
)
|
|
|
|
{
|
2018-09-20 09:41:59 +00:00
|
|
|
uint8_t a[Plen] = {0};
|
|
|
|
// Absorb input.
|
|
|
|
foldP(in, inlen, xorin);
|
|
|
|
// Xor in the DS and pad frame.
|
|
|
|
a[inlen] ^= delim;
|
|
|
|
a[rate - 1] ^= 0x80;
|
|
|
|
// Xor in the last block.
|
|
|
|
xorin(a, in, inlen);
|
|
|
|
// Apply P
|
|
|
|
P(a);
|
|
|
|
// Squeeze output.
|
|
|
|
foldP(out, outlen, setout);
|
|
|
|
setout(a, out, outlen);
|
|
|
|
memset(a, 0, 200);
|
2016-08-01 05:25:37 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
}
|
|
|
|
|
2018-10-17 22:48:28 +00:00
|
|
|
h256 keccak256(bytesConstRef _input)
|
2016-08-01 05:25:37 +00:00
|
|
|
{
|
2018-10-17 22:48:28 +00:00
|
|
|
h256 output;
|
|
|
|
// Parameters used:
|
|
|
|
// The 0x01 is the specific padding for keccak (sha3 uses 0x06) and
|
|
|
|
// the way the round size (or window or whatever it was) is calculated.
|
|
|
|
// 200 - (256 / 4) is the "rate"
|
|
|
|
hash(output.data(), output.size, _input.data(), _input.size(), 200 - (256 / 4), 0x01);
|
|
|
|
return output;
|
2016-08-01 05:25:37 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
}
|