diff --git a/builds/msvc/vs2010/libsodium/libsodium.vcxproj b/builds/msvc/vs2010/libsodium/libsodium.vcxproj
index 9b30d2f9..dbe6e7a6 100644
--- a/builds/msvc/vs2010/libsodium/libsodium.vcxproj
+++ b/builds/msvc/vs2010/libsodium/libsodium.vcxproj
@@ -103,6 +103,14 @@
+
+
+
+
+
+
+
+
@@ -178,6 +186,8 @@
+
+
@@ -205,6 +215,7 @@
+
@@ -212,6 +223,7 @@
+
@@ -227,14 +239,17 @@
+
+
+
@@ -243,6 +258,7 @@
+
@@ -283,6 +299,10 @@
+
+
+
+
@@ -326,6 +346,7 @@
+
diff --git a/builds/msvc/vs2010/libsodium/libsodium.vcxproj.filters b/builds/msvc/vs2010/libsodium/libsodium.vcxproj.filters
index fd834ec7..e9efdd7c 100644
--- a/builds/msvc/vs2010/libsodium/libsodium.vcxproj.filters
+++ b/builds/msvc/vs2010/libsodium/libsodium.vcxproj.filters
@@ -129,6 +129,30 @@
crypto_pwhash\scryptsalsa208sha256\sse
+
+ crypto_xof\shake128
+
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128
+
+
+ crypto_xof\turboshake128\ref
+
crypto_verify
@@ -354,6 +378,12 @@
crypto_secretstream\xchacha20poly1305
+
+ crypto_core\keccak1600
+
+
+ crypto_core\keccak1600\ref
+
crypto_core\salsa\ref
@@ -431,6 +461,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -452,6 +485,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -497,6 +533,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -506,6 +545,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -521,6 +563,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -545,6 +590,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -665,6 +713,18 @@
crypto_pwhash\scryptsalsa208sha256
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128\ref
+
crypto_shorthash\siphash24\ref
@@ -794,6 +854,9 @@
crypto_aead\aegis256
+
+ crypto_core\keccak1600\ref
+
crypto_core\ed25519
@@ -892,6 +955,12 @@
{c6b8e28c-7c54-3af7-bee3-2948ba7b2082}
+
+ {85c1722f-2d65-30a8-aefb-ebf1cbfe185e}
+
+
+ {9462f285-fee0-3779-983b-2811dc621f7d}
+
{4e9a1d6b-ee07-3bbc-ad78-6d0ba0e6d9d3}
@@ -1066,6 +1135,33 @@
{49fb9272-ffe2-3993-b562-b19d5f2c9b40}
+
+ {9d0b6e6c-57a5-33bb-a67c-c1ce5a5e0684}
+
+
+ {3311f765-9a5b-3614-a24f-9b97a56240aa}
+
+
+ {0b3ce98f-5f0a-3836-a95f-5ebd938a0e15}
+
+
+ {d4f668ef-b456-369e-b8bf-b1b6d4e90a6d}
+
+
+ {c5174d81-c82a-3411-98f7-829a427faddc}
+
+
+ {6ccaee32-fd4e-3b58-be6b-a2866132d22d}
+
+
+ {00e8736b-cf8d-3a60-bfbe-f0c535d45696}
+
+
+ {8f7b92bd-0b08-3b14-8693-2df66b256d8b}
+
+
+ {bcea4d5e-5593-3465-ac95-2ecd34340ce3}
+
{96da72eb-3aa0-3850-83eb-32788f91e5bd}
diff --git a/builds/msvc/vs2012/libsodium/libsodium.vcxproj b/builds/msvc/vs2012/libsodium/libsodium.vcxproj
index 2c86c457..d44fe790 100644
--- a/builds/msvc/vs2012/libsodium/libsodium.vcxproj
+++ b/builds/msvc/vs2012/libsodium/libsodium.vcxproj
@@ -103,6 +103,14 @@
+
+
+
+
+
+
+
+
@@ -178,6 +186,8 @@
+
+
@@ -205,6 +215,7 @@
+
@@ -212,6 +223,7 @@
+
@@ -227,14 +239,17 @@
+
+
+
@@ -243,6 +258,7 @@
+
@@ -283,6 +299,10 @@
+
+
+
+
@@ -326,6 +346,7 @@
+
diff --git a/builds/msvc/vs2012/libsodium/libsodium.vcxproj.filters b/builds/msvc/vs2012/libsodium/libsodium.vcxproj.filters
index fd834ec7..e9efdd7c 100644
--- a/builds/msvc/vs2012/libsodium/libsodium.vcxproj.filters
+++ b/builds/msvc/vs2012/libsodium/libsodium.vcxproj.filters
@@ -129,6 +129,30 @@
crypto_pwhash\scryptsalsa208sha256\sse
+
+ crypto_xof\shake128
+
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128
+
+
+ crypto_xof\turboshake128\ref
+
crypto_verify
@@ -354,6 +378,12 @@
crypto_secretstream\xchacha20poly1305
+
+ crypto_core\keccak1600
+
+
+ crypto_core\keccak1600\ref
+
crypto_core\salsa\ref
@@ -431,6 +461,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -452,6 +485,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -497,6 +533,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -506,6 +545,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -521,6 +563,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -545,6 +590,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -665,6 +713,18 @@
crypto_pwhash\scryptsalsa208sha256
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128\ref
+
crypto_shorthash\siphash24\ref
@@ -794,6 +854,9 @@
crypto_aead\aegis256
+
+ crypto_core\keccak1600\ref
+
crypto_core\ed25519
@@ -892,6 +955,12 @@
{c6b8e28c-7c54-3af7-bee3-2948ba7b2082}
+
+ {85c1722f-2d65-30a8-aefb-ebf1cbfe185e}
+
+
+ {9462f285-fee0-3779-983b-2811dc621f7d}
+
{4e9a1d6b-ee07-3bbc-ad78-6d0ba0e6d9d3}
@@ -1066,6 +1135,33 @@
{49fb9272-ffe2-3993-b562-b19d5f2c9b40}
+
+ {9d0b6e6c-57a5-33bb-a67c-c1ce5a5e0684}
+
+
+ {3311f765-9a5b-3614-a24f-9b97a56240aa}
+
+
+ {0b3ce98f-5f0a-3836-a95f-5ebd938a0e15}
+
+
+ {d4f668ef-b456-369e-b8bf-b1b6d4e90a6d}
+
+
+ {c5174d81-c82a-3411-98f7-829a427faddc}
+
+
+ {6ccaee32-fd4e-3b58-be6b-a2866132d22d}
+
+
+ {00e8736b-cf8d-3a60-bfbe-f0c535d45696}
+
+
+ {8f7b92bd-0b08-3b14-8693-2df66b256d8b}
+
+
+ {bcea4d5e-5593-3465-ac95-2ecd34340ce3}
+
{96da72eb-3aa0-3850-83eb-32788f91e5bd}
diff --git a/builds/msvc/vs2013/libsodium/libsodium.vcxproj b/builds/msvc/vs2013/libsodium/libsodium.vcxproj
index d15d7e10..5b4ef991 100644
--- a/builds/msvc/vs2013/libsodium/libsodium.vcxproj
+++ b/builds/msvc/vs2013/libsodium/libsodium.vcxproj
@@ -103,6 +103,14 @@
+
+
+
+
+
+
+
+
@@ -178,6 +186,8 @@
+
+
@@ -205,6 +215,7 @@
+
@@ -212,6 +223,7 @@
+
@@ -227,14 +239,17 @@
+
+
+
@@ -243,6 +258,7 @@
+
@@ -283,6 +299,10 @@
+
+
+
+
@@ -326,6 +346,7 @@
+
diff --git a/builds/msvc/vs2013/libsodium/libsodium.vcxproj.filters b/builds/msvc/vs2013/libsodium/libsodium.vcxproj.filters
index fd834ec7..e9efdd7c 100644
--- a/builds/msvc/vs2013/libsodium/libsodium.vcxproj.filters
+++ b/builds/msvc/vs2013/libsodium/libsodium.vcxproj.filters
@@ -129,6 +129,30 @@
crypto_pwhash\scryptsalsa208sha256\sse
+
+ crypto_xof\shake128
+
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128
+
+
+ crypto_xof\turboshake128\ref
+
crypto_verify
@@ -354,6 +378,12 @@
crypto_secretstream\xchacha20poly1305
+
+ crypto_core\keccak1600
+
+
+ crypto_core\keccak1600\ref
+
crypto_core\salsa\ref
@@ -431,6 +461,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -452,6 +485,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -497,6 +533,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -506,6 +545,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -521,6 +563,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -545,6 +590,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -665,6 +713,18 @@
crypto_pwhash\scryptsalsa208sha256
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128\ref
+
crypto_shorthash\siphash24\ref
@@ -794,6 +854,9 @@
crypto_aead\aegis256
+
+ crypto_core\keccak1600\ref
+
crypto_core\ed25519
@@ -892,6 +955,12 @@
{c6b8e28c-7c54-3af7-bee3-2948ba7b2082}
+
+ {85c1722f-2d65-30a8-aefb-ebf1cbfe185e}
+
+
+ {9462f285-fee0-3779-983b-2811dc621f7d}
+
{4e9a1d6b-ee07-3bbc-ad78-6d0ba0e6d9d3}
@@ -1066,6 +1135,33 @@
{49fb9272-ffe2-3993-b562-b19d5f2c9b40}
+
+ {9d0b6e6c-57a5-33bb-a67c-c1ce5a5e0684}
+
+
+ {3311f765-9a5b-3614-a24f-9b97a56240aa}
+
+
+ {0b3ce98f-5f0a-3836-a95f-5ebd938a0e15}
+
+
+ {d4f668ef-b456-369e-b8bf-b1b6d4e90a6d}
+
+
+ {c5174d81-c82a-3411-98f7-829a427faddc}
+
+
+ {6ccaee32-fd4e-3b58-be6b-a2866132d22d}
+
+
+ {00e8736b-cf8d-3a60-bfbe-f0c535d45696}
+
+
+ {8f7b92bd-0b08-3b14-8693-2df66b256d8b}
+
+
+ {bcea4d5e-5593-3465-ac95-2ecd34340ce3}
+
{96da72eb-3aa0-3850-83eb-32788f91e5bd}
diff --git a/builds/msvc/vs2015/libsodium/libsodium.vcxproj b/builds/msvc/vs2015/libsodium/libsodium.vcxproj
index 4a4c5b20..632230f7 100644
--- a/builds/msvc/vs2015/libsodium/libsodium.vcxproj
+++ b/builds/msvc/vs2015/libsodium/libsodium.vcxproj
@@ -103,6 +103,14 @@
+
+
+
+
+
+
+
+
@@ -178,6 +186,8 @@
+
+
@@ -205,6 +215,7 @@
+
@@ -212,6 +223,7 @@
+
@@ -227,14 +239,17 @@
+
+
+
@@ -243,6 +258,7 @@
+
@@ -283,6 +299,10 @@
+
+
+
+
@@ -326,6 +346,7 @@
+
diff --git a/builds/msvc/vs2015/libsodium/libsodium.vcxproj.filters b/builds/msvc/vs2015/libsodium/libsodium.vcxproj.filters
index fd834ec7..e9efdd7c 100644
--- a/builds/msvc/vs2015/libsodium/libsodium.vcxproj.filters
+++ b/builds/msvc/vs2015/libsodium/libsodium.vcxproj.filters
@@ -129,6 +129,30 @@
crypto_pwhash\scryptsalsa208sha256\sse
+
+ crypto_xof\shake128
+
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128
+
+
+ crypto_xof\turboshake128\ref
+
crypto_verify
@@ -354,6 +378,12 @@
crypto_secretstream\xchacha20poly1305
+
+ crypto_core\keccak1600
+
+
+ crypto_core\keccak1600\ref
+
crypto_core\salsa\ref
@@ -431,6 +461,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -452,6 +485,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -497,6 +533,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -506,6 +545,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -521,6 +563,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -545,6 +590,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -665,6 +713,18 @@
crypto_pwhash\scryptsalsa208sha256
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128\ref
+
crypto_shorthash\siphash24\ref
@@ -794,6 +854,9 @@
crypto_aead\aegis256
+
+ crypto_core\keccak1600\ref
+
crypto_core\ed25519
@@ -892,6 +955,12 @@
{c6b8e28c-7c54-3af7-bee3-2948ba7b2082}
+
+ {85c1722f-2d65-30a8-aefb-ebf1cbfe185e}
+
+
+ {9462f285-fee0-3779-983b-2811dc621f7d}
+
{4e9a1d6b-ee07-3bbc-ad78-6d0ba0e6d9d3}
@@ -1066,6 +1135,33 @@
{49fb9272-ffe2-3993-b562-b19d5f2c9b40}
+
+ {9d0b6e6c-57a5-33bb-a67c-c1ce5a5e0684}
+
+
+ {3311f765-9a5b-3614-a24f-9b97a56240aa}
+
+
+ {0b3ce98f-5f0a-3836-a95f-5ebd938a0e15}
+
+
+ {d4f668ef-b456-369e-b8bf-b1b6d4e90a6d}
+
+
+ {c5174d81-c82a-3411-98f7-829a427faddc}
+
+
+ {6ccaee32-fd4e-3b58-be6b-a2866132d22d}
+
+
+ {00e8736b-cf8d-3a60-bfbe-f0c535d45696}
+
+
+ {8f7b92bd-0b08-3b14-8693-2df66b256d8b}
+
+
+ {bcea4d5e-5593-3465-ac95-2ecd34340ce3}
+
{96da72eb-3aa0-3850-83eb-32788f91e5bd}
diff --git a/builds/msvc/vs2017/libsodium/libsodium.vcxproj b/builds/msvc/vs2017/libsodium/libsodium.vcxproj
index cab710c3..d3f1a455 100644
--- a/builds/msvc/vs2017/libsodium/libsodium.vcxproj
+++ b/builds/msvc/vs2017/libsodium/libsodium.vcxproj
@@ -103,6 +103,14 @@
+
+
+
+
+
+
+
+
@@ -178,6 +186,8 @@
+
+
@@ -205,6 +215,7 @@
+
@@ -212,6 +223,7 @@
+
@@ -227,14 +239,17 @@
+
+
+
@@ -243,6 +258,7 @@
+
@@ -283,6 +299,10 @@
+
+
+
+
@@ -326,6 +346,7 @@
+
diff --git a/builds/msvc/vs2017/libsodium/libsodium.vcxproj.filters b/builds/msvc/vs2017/libsodium/libsodium.vcxproj.filters
index fd834ec7..e9efdd7c 100644
--- a/builds/msvc/vs2017/libsodium/libsodium.vcxproj.filters
+++ b/builds/msvc/vs2017/libsodium/libsodium.vcxproj.filters
@@ -129,6 +129,30 @@
crypto_pwhash\scryptsalsa208sha256\sse
+
+ crypto_xof\shake128
+
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128
+
+
+ crypto_xof\turboshake128\ref
+
crypto_verify
@@ -354,6 +378,12 @@
crypto_secretstream\xchacha20poly1305
+
+ crypto_core\keccak1600
+
+
+ crypto_core\keccak1600\ref
+
crypto_core\salsa\ref
@@ -431,6 +461,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -452,6 +485,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -497,6 +533,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -506,6 +545,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -521,6 +563,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -545,6 +590,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -665,6 +713,18 @@
crypto_pwhash\scryptsalsa208sha256
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128\ref
+
crypto_shorthash\siphash24\ref
@@ -794,6 +854,9 @@
crypto_aead\aegis256
+
+ crypto_core\keccak1600\ref
+
crypto_core\ed25519
@@ -892,6 +955,12 @@
{c6b8e28c-7c54-3af7-bee3-2948ba7b2082}
+
+ {85c1722f-2d65-30a8-aefb-ebf1cbfe185e}
+
+
+ {9462f285-fee0-3779-983b-2811dc621f7d}
+
{4e9a1d6b-ee07-3bbc-ad78-6d0ba0e6d9d3}
@@ -1066,6 +1135,33 @@
{49fb9272-ffe2-3993-b562-b19d5f2c9b40}
+
+ {9d0b6e6c-57a5-33bb-a67c-c1ce5a5e0684}
+
+
+ {3311f765-9a5b-3614-a24f-9b97a56240aa}
+
+
+ {0b3ce98f-5f0a-3836-a95f-5ebd938a0e15}
+
+
+ {d4f668ef-b456-369e-b8bf-b1b6d4e90a6d}
+
+
+ {c5174d81-c82a-3411-98f7-829a427faddc}
+
+
+ {6ccaee32-fd4e-3b58-be6b-a2866132d22d}
+
+
+ {00e8736b-cf8d-3a60-bfbe-f0c535d45696}
+
+
+ {8f7b92bd-0b08-3b14-8693-2df66b256d8b}
+
+
+ {bcea4d5e-5593-3465-ac95-2ecd34340ce3}
+
{96da72eb-3aa0-3850-83eb-32788f91e5bd}
diff --git a/builds/msvc/vs2019/libsodium/libsodium.vcxproj b/builds/msvc/vs2019/libsodium/libsodium.vcxproj
index e7205e50..64751c30 100644
--- a/builds/msvc/vs2019/libsodium/libsodium.vcxproj
+++ b/builds/msvc/vs2019/libsodium/libsodium.vcxproj
@@ -127,6 +127,14 @@
+
+
+
+
+
+
+
+
@@ -202,6 +210,8 @@
+
+
@@ -229,6 +239,7 @@
+
@@ -236,6 +247,7 @@
+
@@ -251,14 +263,17 @@
+
+
+
@@ -267,6 +282,7 @@
+
@@ -307,6 +323,10 @@
+
+
+
+
@@ -350,6 +370,7 @@
+
diff --git a/builds/msvc/vs2019/libsodium/libsodium.vcxproj.filters b/builds/msvc/vs2019/libsodium/libsodium.vcxproj.filters
index fd834ec7..e9efdd7c 100644
--- a/builds/msvc/vs2019/libsodium/libsodium.vcxproj.filters
+++ b/builds/msvc/vs2019/libsodium/libsodium.vcxproj.filters
@@ -129,6 +129,30 @@
crypto_pwhash\scryptsalsa208sha256\sse
+
+ crypto_xof\shake128
+
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128
+
+
+ crypto_xof\turboshake128\ref
+
crypto_verify
@@ -354,6 +378,12 @@
crypto_secretstream\xchacha20poly1305
+
+ crypto_core\keccak1600
+
+
+ crypto_core\keccak1600\ref
+
crypto_core\salsa\ref
@@ -431,6 +461,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -452,6 +485,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -497,6 +533,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -506,6 +545,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -521,6 +563,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -545,6 +590,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -665,6 +713,18 @@
crypto_pwhash\scryptsalsa208sha256
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128\ref
+
crypto_shorthash\siphash24\ref
@@ -794,6 +854,9 @@
crypto_aead\aegis256
+
+ crypto_core\keccak1600\ref
+
crypto_core\ed25519
@@ -892,6 +955,12 @@
{c6b8e28c-7c54-3af7-bee3-2948ba7b2082}
+
+ {85c1722f-2d65-30a8-aefb-ebf1cbfe185e}
+
+
+ {9462f285-fee0-3779-983b-2811dc621f7d}
+
{4e9a1d6b-ee07-3bbc-ad78-6d0ba0e6d9d3}
@@ -1066,6 +1135,33 @@
{49fb9272-ffe2-3993-b562-b19d5f2c9b40}
+
+ {9d0b6e6c-57a5-33bb-a67c-c1ce5a5e0684}
+
+
+ {3311f765-9a5b-3614-a24f-9b97a56240aa}
+
+
+ {0b3ce98f-5f0a-3836-a95f-5ebd938a0e15}
+
+
+ {d4f668ef-b456-369e-b8bf-b1b6d4e90a6d}
+
+
+ {c5174d81-c82a-3411-98f7-829a427faddc}
+
+
+ {6ccaee32-fd4e-3b58-be6b-a2866132d22d}
+
+
+ {00e8736b-cf8d-3a60-bfbe-f0c535d45696}
+
+
+ {8f7b92bd-0b08-3b14-8693-2df66b256d8b}
+
+
+ {bcea4d5e-5593-3465-ac95-2ecd34340ce3}
+
{96da72eb-3aa0-3850-83eb-32788f91e5bd}
diff --git a/builds/msvc/vs2022/libsodium/libsodium.vcxproj b/builds/msvc/vs2022/libsodium/libsodium.vcxproj
index 359a4936..730e1bca 100644
--- a/builds/msvc/vs2022/libsodium/libsodium.vcxproj
+++ b/builds/msvc/vs2022/libsodium/libsodium.vcxproj
@@ -127,6 +127,14 @@
+
+
+
+
+
+
+
+
@@ -202,6 +210,8 @@
+
+
@@ -229,6 +239,7 @@
+
@@ -236,6 +247,7 @@
+
@@ -251,14 +263,17 @@
+
+
+
@@ -267,6 +282,7 @@
+
@@ -307,6 +323,10 @@
+
+
+
+
@@ -350,6 +370,7 @@
+
diff --git a/builds/msvc/vs2022/libsodium/libsodium.vcxproj.filters b/builds/msvc/vs2022/libsodium/libsodium.vcxproj.filters
index fd834ec7..e9efdd7c 100644
--- a/builds/msvc/vs2022/libsodium/libsodium.vcxproj.filters
+++ b/builds/msvc/vs2022/libsodium/libsodium.vcxproj.filters
@@ -129,6 +129,30 @@
crypto_pwhash\scryptsalsa208sha256\sse
+
+ crypto_xof\shake128
+
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128
+
+
+ crypto_xof\turboshake128\ref
+
crypto_verify
@@ -354,6 +378,12 @@
crypto_secretstream\xchacha20poly1305
+
+ crypto_core\keccak1600
+
+
+ crypto_core\keccak1600\ref
+
crypto_core\salsa\ref
@@ -431,6 +461,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -452,6 +485,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -497,6 +533,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -506,6 +545,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -521,6 +563,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -545,6 +590,9 @@
include\sodium
+
+ include\sodium
+
include\sodium
@@ -665,6 +713,18 @@
crypto_pwhash\scryptsalsa208sha256
+
+ crypto_xof\shake128\ref
+
+
+ crypto_xof\shake256\ref
+
+
+ crypto_xof\turboshake256\ref
+
+
+ crypto_xof\turboshake128\ref
+
crypto_shorthash\siphash24\ref
@@ -794,6 +854,9 @@
crypto_aead\aegis256
+
+ crypto_core\keccak1600\ref
+
crypto_core\ed25519
@@ -892,6 +955,12 @@
{c6b8e28c-7c54-3af7-bee3-2948ba7b2082}
+
+ {85c1722f-2d65-30a8-aefb-ebf1cbfe185e}
+
+
+ {9462f285-fee0-3779-983b-2811dc621f7d}
+
{4e9a1d6b-ee07-3bbc-ad78-6d0ba0e6d9d3}
@@ -1066,6 +1135,33 @@
{49fb9272-ffe2-3993-b562-b19d5f2c9b40}
+
+ {9d0b6e6c-57a5-33bb-a67c-c1ce5a5e0684}
+
+
+ {3311f765-9a5b-3614-a24f-9b97a56240aa}
+
+
+ {0b3ce98f-5f0a-3836-a95f-5ebd938a0e15}
+
+
+ {d4f668ef-b456-369e-b8bf-b1b6d4e90a6d}
+
+
+ {c5174d81-c82a-3411-98f7-829a427faddc}
+
+
+ {6ccaee32-fd4e-3b58-be6b-a2866132d22d}
+
+
+ {00e8736b-cf8d-3a60-bfbe-f0c535d45696}
+
+
+ {8f7b92bd-0b08-3b14-8693-2df66b256d8b}
+
+
+ {bcea4d5e-5593-3465-ac95-2ecd34340ce3}
+
{96da72eb-3aa0-3850-83eb-32788f91e5bd}
diff --git a/ci/appveyor/libsodium.vcxproj b/ci/appveyor/libsodium.vcxproj
index 9a8a34be..c788fce8 100644
--- a/ci/appveyor/libsodium.vcxproj
+++ b/ci/appveyor/libsodium.vcxproj
@@ -351,6 +351,14 @@
+
+
+
+
+
+
+
+
@@ -426,6 +434,8 @@
+
+
@@ -453,6 +463,7 @@
+
@@ -460,6 +471,7 @@
+
@@ -475,14 +487,17 @@
+
+
+
@@ -491,6 +506,7 @@
+
@@ -531,6 +547,10 @@
+
+
+
+
@@ -574,6 +594,7 @@
+
diff --git a/ci/appveyor/libsodium.vcxproj.filters b/ci/appveyor/libsodium.vcxproj.filters
index 56ef3cdc..3a25fec0 100644
--- a/ci/appveyor/libsodium.vcxproj.filters
+++ b/ci/appveyor/libsodium.vcxproj.filters
@@ -120,6 +120,30 @@
Source Files
+
+ Source Files
+
+
+ Source Files
+
+
+ Source Files
+
+
+ Source Files
+
+
+ Source Files
+
+
+ Source Files
+
+
+ Source Files
+
+
+ Source Files
+
Source Files
@@ -345,6 +369,12 @@
Source Files
+
+ Source Files
+
+
+ Source Files
+
Source Files
@@ -422,6 +452,9 @@
Header Files
+
+ Header Files
+
Header Files
@@ -443,6 +476,9 @@
Header Files
+
+ Header Files
+
Header Files
@@ -488,6 +524,9 @@
Header Files
+
+ Header Files
+
Header Files
@@ -497,6 +536,9 @@
Header Files
+
+ Header Files
+
Header Files
@@ -512,6 +554,9 @@
Header Files
+
+ Header Files
+
Header Files
@@ -536,6 +581,9 @@
Header Files
+
+ Header Files
+
Header Files
@@ -656,6 +704,18 @@
Header Files
+
+ Header Files
+
+
+ Header Files
+
+
+ Header Files
+
+
+ Header Files
+
Header Files
@@ -785,6 +845,9 @@
Header Files
+
+ Header Files
+
Header Files
diff --git a/src/libsodium/Makefile.am b/src/libsodium/Makefile.am
index c1f26e41..a9712304 100644
--- a/src/libsodium/Makefile.am
+++ b/src/libsodium/Makefile.am
@@ -29,6 +29,9 @@ libsodium_la_SOURCES = \
crypto_core/hchacha20/core_hchacha20.c \
crypto_core/hsalsa20/ref2/core_hsalsa20_ref2.c \
crypto_core/hsalsa20/core_hsalsa20.c \
+ crypto_core/keccak1600/keccak1600.c \
+ crypto_core/keccak1600/ref/keccak1600_ref.c \
+ crypto_core/keccak1600/ref/keccak1600_ref.h \
crypto_core/salsa/ref/core_salsa_ref.c \
crypto_core/softaes/softaes.c \
crypto_generichash/crypto_generichash.c \
@@ -98,6 +101,18 @@ libsodium_la_SOURCES = \
crypto_stream/salsa20/stream_salsa20.h \
crypto_stream/xsalsa20/stream_xsalsa20.c \
crypto_verify/verify.c \
+ crypto_xof/shake128/xof_shake128.c \
+ crypto_xof/shake128/ref/shake128_ref.c \
+ crypto_xof/shake128/ref/shake128_ref.h \
+ crypto_xof/shake256/xof_shake256.c \
+ crypto_xof/shake256/ref/shake256_ref.c \
+ crypto_xof/shake256/ref/shake256_ref.h \
+ crypto_xof/turboshake128/xof_turboshake128.c \
+ crypto_xof/turboshake128/ref/turboshake128_ref.c \
+ crypto_xof/turboshake128/ref/turboshake128_ref.h \
+ crypto_xof/turboshake256/xof_turboshake256.c \
+ crypto_xof/turboshake256/ref/turboshake256_ref.c \
+ crypto_xof/turboshake256/ref/turboshake256_ref.h \
include/sodium/private/asm_cet.h \
include/sodium/private/chacha20_ietf_ext.h \
include/sodium/private/common.h \
diff --git a/src/libsodium/crypto_core/keccak1600/keccak1600.c b/src/libsodium/crypto_core/keccak1600/keccak1600.c
new file mode 100644
index 00000000..ff9f73f6
--- /dev/null
+++ b/src/libsodium/crypto_core/keccak1600/keccak1600.c
@@ -0,0 +1,40 @@
+#include "crypto_core_keccak1600.h"
+#include "ref/keccak1600_ref.h"
+
+size_t
+crypto_core_keccak1600_statebytes(void)
+{
+ return crypto_core_keccak1600_STATEBYTES;
+}
+
+void
+crypto_core_keccak1600_init(void *state)
+{
+ keccak1600_ref_init(state);
+}
+
+void
+crypto_core_keccak1600_xor_bytes(void *state, const unsigned char *bytes, size_t offset,
+ size_t length)
+{
+ keccak1600_ref_xor_bytes(state, bytes, offset, length);
+}
+
+void
+crypto_core_keccak1600_extract_bytes(const void *state, unsigned char *bytes, size_t offset,
+ size_t length)
+{
+ keccak1600_ref_extract_bytes(state, bytes, offset, length);
+}
+
+void
+crypto_core_keccak1600_permute_24(void *state)
+{
+ keccak1600_ref_permute_24(state);
+}
+
+void
+crypto_core_keccak1600_permute_12(void *state)
+{
+ keccak1600_ref_permute_12(state);
+}
diff --git a/src/libsodium/crypto_core/keccak1600/ref/keccak1600_ref.c b/src/libsodium/crypto_core/keccak1600/ref/keccak1600_ref.c
new file mode 100644
index 00000000..3eddfdf1
--- /dev/null
+++ b/src/libsodium/crypto_core/keccak1600/ref/keccak1600_ref.c
@@ -0,0 +1,455 @@
+#include
+#include
+
+#include "keccak1600_ref.h"
+#include "private/common.h"
+
+#define KECCAK1600_STATEBYTES 200
+
+static const uint64_t keccak_round_constants[24] = {
+ 0x0000000000000001ULL, 0x0000000000008082ULL, 0x800000000000808aULL, 0x8000000080008000ULL,
+ 0x000000000000808bULL, 0x0000000080000001ULL, 0x8000000080008081ULL, 0x8000000000008009ULL,
+ 0x000000000000008aULL, 0x0000000000000088ULL, 0x0000000080008009ULL, 0x000000008000000aULL,
+ 0x000000008000808bULL, 0x800000000000008bULL, 0x8000000000008089ULL, 0x8000000000008003ULL,
+ 0x8000000000008002ULL, 0x8000000000000080ULL, 0x000000000000800aULL, 0x800000008000000aULL,
+ 0x8000000080008081ULL, 0x8000000000008080ULL, 0x0000000080000001ULL, 0x8000000080008008ULL
+};
+
+static const unsigned int keccak_rotc[24] = { 1U, 3U, 6U, 10U, 15U, 21U, 28U, 36U,
+ 45U, 55U, 2U, 14U, 27U, 41U, 56U, 8U,
+ 25U, 43U, 62U, 18U, 39U, 61U, 20U, 44U };
+
+static const unsigned int keccak_piln[24] = { 10U, 7U, 11U, 17U, 18U, 3U, 5U, 16U,
+ 8U, 21U, 24U, 4U, 15U, 23U, 19U, 13U,
+ 12U, 2U, 20U, 14U, 22U, 9U, 6U, 1U };
+
+#define KECCAK_DECLARE_STATE \
+ uint64_t Aba, Abe, Abi, Abo, Abu; \
+ uint64_t Aga, Age, Agi, Ago, Agu; \
+ uint64_t Aka, Ake, Aki, Ako, Aku; \
+ uint64_t Ama, Ame, Ami, Amo, Amu; \
+ uint64_t Asa, Ase, Asi, Aso, Asu; \
+ uint64_t Bba, Bbe, Bbi, Bbo, Bbu; \
+ uint64_t Bga, Bge, Bgi, Bgo, Bgu; \
+ uint64_t Bka, Bke, Bki, Bko, Bku; \
+ uint64_t Bma, Bme, Bmi, Bmo, Bmu; \
+ uint64_t Bsa, Bse, Bsi, Bso, Bsu; \
+ uint64_t Ca, Ce, Ci, Co, Cu; \
+ uint64_t Da, De, Di, Do, Du; \
+ uint64_t Eba, Ebe, Ebi, Ebo, Ebu; \
+ uint64_t Ega, Ege, Egi, Ego, Egu; \
+ uint64_t Eka, Eke, Eki, Eko, Eku; \
+ uint64_t Ema, Eme, Emi, Emo, Emu; \
+ uint64_t Esa, Ese, Esi, Eso, Esu
+
+#define KECCAK_PREPARE_THETA \
+ Ca = Aba ^ Aga ^ Aka ^ Ama ^ Asa; \
+ Ce = Abe ^ Age ^ Ake ^ Ame ^ Ase; \
+ Ci = Abi ^ Agi ^ Aki ^ Ami ^ Asi; \
+ Co = Abo ^ Ago ^ Ako ^ Amo ^ Aso; \
+ Cu = Abu ^ Agu ^ Aku ^ Amu ^ Asu
+
+#define KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(round_idx, A, E) \
+ Da = Cu ^ ROTL64(Ce, 1); \
+ De = Ca ^ ROTL64(Ci, 1); \
+ Di = Ce ^ ROTL64(Co, 1); \
+ Do = Ci ^ ROTL64(Cu, 1); \
+ Du = Co ^ ROTL64(Ca, 1); \
+ \
+ A##ba ^= Da; \
+ Bba = A##ba; \
+ A##ge ^= De; \
+ Bbe = ROTL64(A##ge, 44); \
+ A##ki ^= Di; \
+ Bbi = ROTL64(A##ki, 43); \
+ A##mo ^= Do; \
+ Bbo = ROTL64(A##mo, 21); \
+ A##su ^= Du; \
+ Bbu = ROTL64(A##su, 14); \
+ E##ba = Bba ^ ((~Bbe) & Bbi); \
+ E##ba ^= keccak_round_constants[round_idx]; \
+ Ca = E##ba; \
+ E##be = Bbe ^ ((~Bbi) & Bbo); \
+ Ce = E##be; \
+ E##bi = Bbi ^ ((~Bbo) & Bbu); \
+ Ci = E##bi; \
+ E##bo = Bbo ^ ((~Bbu) & Bba); \
+ Co = E##bo; \
+ E##bu = Bbu ^ ((~Bba) & Bbe); \
+ Cu = E##bu; \
+ \
+ A##bo ^= Do; \
+ Bga = ROTL64(A##bo, 28); \
+ A##gu ^= Du; \
+ Bge = ROTL64(A##gu, 20); \
+ A##ka ^= Da; \
+ Bgi = ROTL64(A##ka, 3); \
+ A##me ^= De; \
+ Bgo = ROTL64(A##me, 45); \
+ A##si ^= Di; \
+ Bgu = ROTL64(A##si, 61); \
+ E##ga = Bga ^ ((~Bge) & Bgi); \
+ Ca ^= E##ga; \
+ E##ge = Bge ^ ((~Bgi) & Bgo); \
+ Ce ^= E##ge; \
+ E##gi = Bgi ^ ((~Bgo) & Bgu); \
+ Ci ^= E##gi; \
+ E##go = Bgo ^ ((~Bgu) & Bga); \
+ Co ^= E##go; \
+ E##gu = Bgu ^ ((~Bga) & Bge); \
+ Cu ^= E##gu; \
+ \
+ A##be ^= De; \
+ Bka = ROTL64(A##be, 1); \
+ A##gi ^= Di; \
+ Bke = ROTL64(A##gi, 6); \
+ A##ko ^= Do; \
+ Bki = ROTL64(A##ko, 25); \
+ A##mu ^= Du; \
+ Bko = ROTL64(A##mu, 8); \
+ A##sa ^= Da; \
+ Bku = ROTL64(A##sa, 18); \
+ E##ka = Bka ^ ((~Bke) & Bki); \
+ Ca ^= E##ka; \
+ E##ke = Bke ^ ((~Bki) & Bko); \
+ Ce ^= E##ke; \
+ E##ki = Bki ^ ((~Bko) & Bku); \
+ Ci ^= E##ki; \
+ E##ko = Bko ^ ((~Bku) & Bka); \
+ Co ^= E##ko; \
+ E##ku = Bku ^ ((~Bka) & Bke); \
+ Cu ^= E##ku; \
+ \
+ A##bu ^= Du; \
+ Bma = ROTL64(A##bu, 27); \
+ A##ga ^= Da; \
+ Bme = ROTL64(A##ga, 36); \
+ A##ke ^= De; \
+ Bmi = ROTL64(A##ke, 10); \
+ A##mi ^= Di; \
+ Bmo = ROTL64(A##mi, 15); \
+ A##so ^= Do; \
+ Bmu = ROTL64(A##so, 56); \
+ E##ma = Bma ^ ((~Bme) & Bmi); \
+ Ca ^= E##ma; \
+ E##me = Bme ^ ((~Bmi) & Bmo); \
+ Ce ^= E##me; \
+ E##mi = Bmi ^ ((~Bmo) & Bmu); \
+ Ci ^= E##mi; \
+ E##mo = Bmo ^ ((~Bmu) & Bma); \
+ Co ^= E##mo; \
+ E##mu = Bmu ^ ((~Bma) & Bme); \
+ Cu ^= E##mu; \
+ \
+ A##bi ^= Di; \
+ Bsa = ROTL64(A##bi, 62); \
+ A##go ^= Do; \
+ Bse = ROTL64(A##go, 55); \
+ A##ku ^= Du; \
+ Bsi = ROTL64(A##ku, 39); \
+ A##ma ^= Da; \
+ Bso = ROTL64(A##ma, 41); \
+ A##se ^= De; \
+ Bsu = ROTL64(A##se, 2); \
+ E##sa = Bsa ^ ((~Bse) & Bsi); \
+ Ca ^= E##sa; \
+ E##se = Bse ^ ((~Bsi) & Bso); \
+ Ce ^= E##se; \
+ E##si = Bsi ^ ((~Bso) & Bsu); \
+ Ci ^= E##si; \
+ E##so = Bso ^ ((~Bsu) & Bsa); \
+ Co ^= E##so; \
+ E##su = Bsu ^ ((~Bsa) & Bse); \
+ Cu ^= E##su
+
+#define KECCAK_THETA_RHO_PI_CHI_IOTA(round_idx, A, E) \
+ Da = Cu ^ ROTL64(Ce, 1); \
+ De = Ca ^ ROTL64(Ci, 1); \
+ Di = Ce ^ ROTL64(Co, 1); \
+ Do = Ci ^ ROTL64(Cu, 1); \
+ Du = Co ^ ROTL64(Ca, 1); \
+ \
+ A##ba ^= Da; \
+ Bba = A##ba; \
+ A##ge ^= De; \
+ Bbe = ROTL64(A##ge, 44); \
+ A##ki ^= Di; \
+ Bbi = ROTL64(A##ki, 43); \
+ A##mo ^= Do; \
+ Bbo = ROTL64(A##mo, 21); \
+ A##su ^= Du; \
+ Bbu = ROTL64(A##su, 14); \
+ E##ba = Bba ^ ((~Bbe) & Bbi); \
+ E##ba ^= keccak_round_constants[round_idx]; \
+ E##be = Bbe ^ ((~Bbi) & Bbo); \
+ E##bi = Bbi ^ ((~Bbo) & Bbu); \
+ E##bo = Bbo ^ ((~Bbu) & Bba); \
+ E##bu = Bbu ^ ((~Bba) & Bbe); \
+ \
+ A##bo ^= Do; \
+ Bga = ROTL64(A##bo, 28); \
+ A##gu ^= Du; \
+ Bge = ROTL64(A##gu, 20); \
+ A##ka ^= Da; \
+ Bgi = ROTL64(A##ka, 3); \
+ A##me ^= De; \
+ Bgo = ROTL64(A##me, 45); \
+ A##si ^= Di; \
+ Bgu = ROTL64(A##si, 61); \
+ E##ga = Bga ^ ((~Bge) & Bgi); \
+ E##ge = Bge ^ ((~Bgi) & Bgo); \
+ E##gi = Bgi ^ ((~Bgo) & Bgu); \
+ E##go = Bgo ^ ((~Bgu) & Bga); \
+ E##gu = Bgu ^ ((~Bga) & Bge); \
+ \
+ A##be ^= De; \
+ Bka = ROTL64(A##be, 1); \
+ A##gi ^= Di; \
+ Bke = ROTL64(A##gi, 6); \
+ A##ko ^= Do; \
+ Bki = ROTL64(A##ko, 25); \
+ A##mu ^= Du; \
+ Bko = ROTL64(A##mu, 8); \
+ A##sa ^= Da; \
+ Bku = ROTL64(A##sa, 18); \
+ E##ka = Bka ^ ((~Bke) & Bki); \
+ E##ke = Bke ^ ((~Bki) & Bko); \
+ E##ki = Bki ^ ((~Bko) & Bku); \
+ E##ko = Bko ^ ((~Bku) & Bka); \
+ E##ku = Bku ^ ((~Bka) & Bke); \
+ \
+ A##bu ^= Du; \
+ Bma = ROTL64(A##bu, 27); \
+ A##ga ^= Da; \
+ Bme = ROTL64(A##ga, 36); \
+ A##ke ^= De; \
+ Bmi = ROTL64(A##ke, 10); \
+ A##mi ^= Di; \
+ Bmo = ROTL64(A##mi, 15); \
+ A##so ^= Do; \
+ Bmu = ROTL64(A##so, 56); \
+ E##ma = Bma ^ ((~Bme) & Bmi); \
+ E##me = Bme ^ ((~Bmi) & Bmo); \
+ E##mi = Bmi ^ ((~Bmo) & Bmu); \
+ E##mo = Bmo ^ ((~Bmu) & Bma); \
+ E##mu = Bmu ^ ((~Bma) & Bme); \
+ \
+ A##bi ^= Di; \
+ Bsa = ROTL64(A##bi, 62); \
+ A##go ^= Do; \
+ Bse = ROTL64(A##go, 55); \
+ A##ku ^= Du; \
+ Bsi = ROTL64(A##ku, 39); \
+ A##ma ^= Da; \
+ Bso = ROTL64(A##ma, 41); \
+ A##se ^= De; \
+ Bsu = ROTL64(A##se, 2); \
+ E##sa = Bsa ^ ((~Bse) & Bsi); \
+ E##se = Bse ^ ((~Bsi) & Bso); \
+ E##si = Bsi ^ ((~Bso) & Bsu); \
+ E##so = Bso ^ ((~Bsu) & Bsa); \
+ E##su = Bsu ^ ((~Bsa) & Bse)
+
+#define KECCAK_COPY_FROM_STATE(prefix, src) \
+ prefix##ba = (src)[0]; \
+ prefix##be = (src)[1]; \
+ prefix##bi = (src)[2]; \
+ prefix##bo = (src)[3]; \
+ prefix##bu = (src)[4]; \
+ prefix##ga = (src)[5]; \
+ prefix##ge = (src)[6]; \
+ prefix##gi = (src)[7]; \
+ prefix##go = (src)[8]; \
+ prefix##gu = (src)[9]; \
+ prefix##ka = (src)[10]; \
+ prefix##ke = (src)[11]; \
+ prefix##ki = (src)[12]; \
+ prefix##ko = (src)[13]; \
+ prefix##ku = (src)[14]; \
+ prefix##ma = (src)[15]; \
+ prefix##me = (src)[16]; \
+ prefix##mi = (src)[17]; \
+ prefix##mo = (src)[18]; \
+ prefix##mu = (src)[19]; \
+ prefix##sa = (src)[20]; \
+ prefix##se = (src)[21]; \
+ prefix##si = (src)[22]; \
+ prefix##so = (src)[23]; \
+ prefix##su = (src)[24]
+
+#define KECCAK_COPY_TO_STATE(dst, prefix) \
+ (dst)[0] = prefix##ba; \
+ (dst)[1] = prefix##be; \
+ (dst)[2] = prefix##bi; \
+ (dst)[3] = prefix##bo; \
+ (dst)[4] = prefix##bu; \
+ (dst)[5] = prefix##ga; \
+ (dst)[6] = prefix##ge; \
+ (dst)[7] = prefix##gi; \
+ (dst)[8] = prefix##go; \
+ (dst)[9] = prefix##gu; \
+ (dst)[10] = prefix##ka; \
+ (dst)[11] = prefix##ke; \
+ (dst)[12] = prefix##ki; \
+ (dst)[13] = prefix##ko; \
+ (dst)[14] = prefix##ku; \
+ (dst)[15] = prefix##ma; \
+ (dst)[16] = prefix##me; \
+ (dst)[17] = prefix##mi; \
+ (dst)[18] = prefix##mo; \
+ (dst)[19] = prefix##mu; \
+ (dst)[20] = prefix##sa; \
+ (dst)[21] = prefix##se; \
+ (dst)[22] = prefix##si; \
+ (dst)[23] = prefix##so; \
+ (dst)[24] = prefix##su
+
+#define KECCAK_COPY_STATE(prefix_dst, prefix_src) \
+ prefix_dst##ba = prefix_src##ba; \
+ prefix_dst##be = prefix_src##be; \
+ prefix_dst##bi = prefix_src##bi; \
+ prefix_dst##bo = prefix_src##bo; \
+ prefix_dst##bu = prefix_src##bu; \
+ prefix_dst##ga = prefix_src##ga; \
+ prefix_dst##ge = prefix_src##ge; \
+ prefix_dst##gi = prefix_src##gi; \
+ prefix_dst##go = prefix_src##go; \
+ prefix_dst##gu = prefix_src##gu; \
+ prefix_dst##ka = prefix_src##ka; \
+ prefix_dst##ke = prefix_src##ke; \
+ prefix_dst##ki = prefix_src##ki; \
+ prefix_dst##ko = prefix_src##ko; \
+ prefix_dst##ku = prefix_src##ku; \
+ prefix_dst##ma = prefix_src##ma; \
+ prefix_dst##me = prefix_src##me; \
+ prefix_dst##mi = prefix_src##mi; \
+ prefix_dst##mo = prefix_src##mo; \
+ prefix_dst##mu = prefix_src##mu; \
+ prefix_dst##sa = prefix_src##sa; \
+ prefix_dst##se = prefix_src##se; \
+ prefix_dst##si = prefix_src##si; \
+ prefix_dst##so = prefix_src##so; \
+ prefix_dst##su = prefix_src##su
+
+static void
+keccakf_24_rounds(uint64_t st[25])
+{
+ uint64_t *state = st;
+
+ KECCAK_DECLARE_STATE;
+
+ KECCAK_COPY_FROM_STATE(A, state);
+ KECCAK_PREPARE_THETA;
+
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(0, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(1, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(2, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(3, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(4, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(5, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(6, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(7, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(8, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(9, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(10, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(11, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(12, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(13, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(14, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(15, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(16, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(17, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(18, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(19, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(20, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(21, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(22, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA(23, E, A);
+
+ KECCAK_COPY_TO_STATE(state, A);
+}
+
+static void
+keccakf_12_rounds(uint64_t st[25])
+{
+ uint64_t *state = st;
+
+ KECCAK_DECLARE_STATE;
+
+ KECCAK_COPY_FROM_STATE(A, state);
+ KECCAK_PREPARE_THETA;
+
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(12, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(13, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(14, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(15, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(16, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(17, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(18, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(19, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(20, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(21, E, A);
+ KECCAK_THETA_RHO_PI_CHI_IOTA_PRE(22, A, E);
+ KECCAK_THETA_RHO_PI_CHI_IOTA(23, E, A);
+
+ KECCAK_COPY_TO_STATE(state, A);
+}
+
+void
+keccak1600_ref_permute_24(void *state)
+{
+ uint64_t st[25];
+ unsigned int i;
+
+ for (i = 0U; i < 25U; i++) {
+ st[i] = LOAD64_LE((const unsigned char *) state + i * 8U);
+ }
+
+ keccakf_24_rounds(st);
+
+ for (i = 0U; i < 25U; i++) {
+ STORE64_LE((unsigned char *) state + i * 8U, st[i]);
+ }
+}
+
+void
+keccak1600_ref_permute_12(void *state)
+{
+ uint64_t st[25];
+ unsigned int i;
+
+ for (i = 0U; i < 25U; i++) {
+ st[i] = LOAD64_LE((const unsigned char *) state + i * 8U);
+ }
+
+ keccakf_12_rounds(st);
+
+ for (i = 0U; i < 25U; i++) {
+ STORE64_LE((unsigned char *) state + i * 8U, st[i]);
+ }
+}
+
+void
+keccak1600_ref_init(void *state)
+{
+ memset(state, 0, KECCAK1600_STATEBYTES);
+}
+
+void
+keccak1600_ref_xor_bytes(void *state, const unsigned char *data, size_t offset, size_t length)
+{
+ unsigned char *st = (unsigned char *) state;
+ size_t i;
+
+ for (i = 0U; i < length; i++) {
+ st[offset + i] ^= data[i];
+ }
+}
+
+void
+keccak1600_ref_extract_bytes(const void *state, unsigned char *data, size_t offset, size_t length)
+{
+ const unsigned char *st = (const unsigned char *) state;
+
+ memcpy(data, st + offset, length);
+}
diff --git a/src/libsodium/crypto_core/keccak1600/ref/keccak1600_ref.h b/src/libsodium/crypto_core/keccak1600/ref/keccak1600_ref.h
new file mode 100644
index 00000000..e91253ee
--- /dev/null
+++ b/src/libsodium/crypto_core/keccak1600/ref/keccak1600_ref.h
@@ -0,0 +1,20 @@
+#ifndef keccak1600_ref_H
+#define keccak1600_ref_H
+
+#include
+
+#include "private/quirks.h"
+
+void keccak1600_ref_init(void *state);
+
+void keccak1600_ref_xor_bytes(void *state, const unsigned char *bytes,
+ size_t offset, size_t length);
+
+void keccak1600_ref_extract_bytes(const void *state, unsigned char *bytes,
+ size_t offset, size_t length);
+
+void keccak1600_ref_permute_24(void *state);
+
+void keccak1600_ref_permute_12(void *state);
+
+#endif /* keccak1600_ref_H */
diff --git a/src/libsodium/crypto_xof/shake128/ref/shake128_ref.c b/src/libsodium/crypto_xof/shake128/ref/shake128_ref.c
new file mode 100644
index 00000000..168df33f
--- /dev/null
+++ b/src/libsodium/crypto_xof/shake128/ref/shake128_ref.c
@@ -0,0 +1,115 @@
+#include
+#include
+
+#include "crypto_core_keccak1600.h"
+#include "private/common.h"
+#include "shake128_ref.h"
+
+#define SHAKE128_DOMAIN_BYTE_STANDARD 0x1F
+
+int
+shake128_ref_init_with_domain(shake128_state_internal *state, unsigned char domain)
+{
+ crypto_core_keccak1600_init(state->state);
+ state->offset = 0;
+ state->phase = SHAKE128_PHASE_ABSORBING;
+ state->domain = domain;
+
+ return 0;
+}
+
+int
+shake128_ref_init(shake128_state_internal *state)
+{
+ return shake128_ref_init_with_domain(state, SHAKE128_DOMAIN_BYTE_STANDARD);
+}
+
+int
+shake128_ref_update(shake128_state_internal *state,
+ const unsigned char *in,
+ unsigned long long inlen)
+{
+ size_t i;
+
+ if (state->phase != SHAKE128_PHASE_ABSORBING) {
+ return -1; /* Cannot absorb after squeezing */
+ }
+
+ for (i = 0; i < inlen; i++) {
+ if (state->offset == SHAKE128_RATE) {
+ crypto_core_keccak1600_permute_24(state->state);
+ state->offset = 0;
+ }
+ crypto_core_keccak1600_xor_bytes(state->state, &in[i], state->offset, 1);
+ state->offset++;
+ }
+
+ return 0;
+}
+
+static void
+shake128_finalize(shake128_state_internal *state)
+{
+ unsigned char pad;
+
+ /* Apply padding: domain byte at current position, 0x80 at last byte */
+ if (state->offset == SHAKE128_RATE - 1) {
+ /* Special case: padding fits in one byte */
+ pad = state->domain | 0x80;
+ crypto_core_keccak1600_xor_bytes(state->state, &pad, state->offset, 1);
+ } else {
+ /* Normal case: domain and 0x80 at different positions */
+ crypto_core_keccak1600_xor_bytes(state->state, &state->domain, state->offset, 1);
+ pad = 0x80;
+ crypto_core_keccak1600_xor_bytes(state->state, &pad, SHAKE128_RATE - 1, 1);
+ }
+
+ /* Final permutation */
+ crypto_core_keccak1600_permute_24(state->state);
+
+ state->offset = 0;
+ state->phase = SHAKE128_PHASE_SQUEEZING;
+}
+
+int
+shake128_ref_final(shake128_state_internal *state, unsigned char *out, size_t outlen)
+{
+ if (state->phase == SHAKE128_PHASE_ABSORBING) {
+ shake128_finalize(state);
+ }
+
+ return shake128_ref_squeeze(state, out, outlen);
+}
+
+int
+shake128_ref_squeeze(shake128_state_internal *state, unsigned char *out, size_t outlen)
+{
+ size_t i;
+
+ if (state->phase == SHAKE128_PHASE_ABSORBING) {
+ shake128_finalize(state);
+ }
+
+ for (i = 0; i < outlen; i++) {
+ if (state->offset == SHAKE128_RATE) {
+ crypto_core_keccak1600_permute_24(state->state);
+ state->offset = 0;
+ }
+ crypto_core_keccak1600_extract_bytes(state->state, &out[i], state->offset, 1);
+ state->offset++;
+ }
+
+ return 0;
+}
+
+int
+shake128_ref(unsigned char *out, size_t outlen, const unsigned char *in, unsigned long long inlen)
+{
+ shake128_state_internal state;
+
+ shake128_ref_init(&state);
+ shake128_ref_update(&state, in, inlen);
+ shake128_ref_final(&state, out, outlen);
+
+ return 0;
+}
diff --git a/src/libsodium/crypto_xof/shake128/ref/shake128_ref.h b/src/libsodium/crypto_xof/shake128/ref/shake128_ref.h
new file mode 100644
index 00000000..a90634c3
--- /dev/null
+++ b/src/libsodium/crypto_xof/shake128/ref/shake128_ref.h
@@ -0,0 +1,33 @@
+#ifndef shake128_ref_H
+#define shake128_ref_H
+
+#include
+#include
+
+#define SHAKE128_RATE 168
+
+typedef enum { SHAKE128_PHASE_ABSORBING = 0, SHAKE128_PHASE_SQUEEZING = 1 } shake128_phase;
+
+typedef struct shake128_state_internal_ {
+ unsigned char state[200];
+ size_t offset;
+ uint8_t phase;
+ unsigned char domain; /* Domain separation byte */
+} shake128_state_internal;
+
+int shake128_ref(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen);
+
+int shake128_ref_init(shake128_state_internal *state);
+
+int shake128_ref_init_with_domain(shake128_state_internal *state, unsigned char domain);
+
+int shake128_ref_update(shake128_state_internal *state,
+ const unsigned char *in,
+ unsigned long long inlen);
+
+int shake128_ref_final(shake128_state_internal *state, unsigned char *out, size_t outlen);
+
+int shake128_ref_squeeze(shake128_state_internal *state, unsigned char *out, size_t outlen);
+
+#endif /* shake128_ref_H */
diff --git a/src/libsodium/crypto_xof/shake128/xof_shake128.c b/src/libsodium/crypto_xof/shake128/xof_shake128.c
new file mode 100644
index 00000000..5b4d28e3
--- /dev/null
+++ b/src/libsodium/crypto_xof/shake128/xof_shake128.c
@@ -0,0 +1,78 @@
+#include "crypto_xof_shake128.h"
+#include "private/common.h"
+#include "ref/shake128_ref.h"
+
+size_t
+crypto_xof_shake128_blockbytes(void)
+{
+ return crypto_xof_shake128_BLOCKBYTES;
+}
+
+size_t
+crypto_xof_shake128_statebytes(void)
+{
+ return crypto_xof_shake128_STATEBYTES;
+}
+
+unsigned char
+crypto_xof_shake128_domain_standard(void)
+{
+ return crypto_xof_shake128_DOMAIN_STANDARD;
+}
+
+int
+crypto_xof_shake128(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen)
+{
+ shake128_state_internal state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_shake128_state) >= sizeof(shake128_state_internal));
+
+ return shake128_ref(out, outlen, in, inlen);
+}
+
+int
+crypto_xof_shake128_init(crypto_xof_shake128_state *state)
+{
+ shake128_state_internal *st = (shake128_state_internal *) (void *) state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_shake128_state) >= sizeof(shake128_state_internal));
+
+ return shake128_ref_init(st);
+}
+
+int
+crypto_xof_shake128_init_with_domain(crypto_xof_shake128_state *state, unsigned char domain)
+{
+ shake128_state_internal *st = (shake128_state_internal *) (void *) state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_shake128_state) >= sizeof(shake128_state_internal));
+
+ return shake128_ref_init_with_domain(st, domain);
+}
+
+int
+crypto_xof_shake128_update(crypto_xof_shake128_state *state,
+ const unsigned char *in,
+ unsigned long long inlen)
+{
+ shake128_state_internal *st = (shake128_state_internal *) (void *) state;
+
+ return shake128_ref_update(st, in, inlen);
+}
+
+int
+crypto_xof_shake128_final(crypto_xof_shake128_state *state, unsigned char *out, size_t outlen)
+{
+ shake128_state_internal *st = (shake128_state_internal *) (void *) state;
+
+ return shake128_ref_final(st, out, outlen);
+}
+
+int
+crypto_xof_shake128_squeeze(crypto_xof_shake128_state *state, unsigned char *out, size_t outlen)
+{
+ shake128_state_internal *st = (shake128_state_internal *) (void *) state;
+
+ return shake128_ref_squeeze(st, out, outlen);
+}
diff --git a/src/libsodium/crypto_xof/shake256/ref/shake256_ref.c b/src/libsodium/crypto_xof/shake256/ref/shake256_ref.c
new file mode 100644
index 00000000..9e86422f
--- /dev/null
+++ b/src/libsodium/crypto_xof/shake256/ref/shake256_ref.c
@@ -0,0 +1,115 @@
+#include
+#include
+
+#include "crypto_core_keccak1600.h"
+#include "private/common.h"
+#include "shake256_ref.h"
+
+#define SHAKE256_DOMAIN_BYTE_STANDARD 0x1F
+
+int
+shake256_ref_init_with_domain(shake256_state_internal *state, unsigned char domain)
+{
+ crypto_core_keccak1600_init(state->state);
+ state->offset = 0;
+ state->phase = SHAKE256_PHASE_ABSORBING;
+ state->domain = domain;
+
+ return 0;
+}
+
+int
+shake256_ref_init(shake256_state_internal *state)
+{
+ return shake256_ref_init_with_domain(state, SHAKE256_DOMAIN_BYTE_STANDARD);
+}
+
+int
+shake256_ref_update(shake256_state_internal *state,
+ const unsigned char *in,
+ unsigned long long inlen)
+{
+ size_t i;
+
+ if (state->phase != SHAKE256_PHASE_ABSORBING) {
+ return -1; /* Cannot absorb after squeezing */
+ }
+
+ for (i = 0; i < inlen; i++) {
+ if (state->offset == SHAKE256_RATE) {
+ crypto_core_keccak1600_permute_24(state->state);
+ state->offset = 0;
+ }
+ crypto_core_keccak1600_xor_bytes(state->state, &in[i], state->offset, 1);
+ state->offset++;
+ }
+
+ return 0;
+}
+
+static void
+shake256_finalize(shake256_state_internal *state)
+{
+ unsigned char pad;
+
+ /* Apply padding: domain byte at current position, 0x80 at last byte */
+ if (state->offset == SHAKE256_RATE - 1) {
+ /* Special case: padding fits in one byte */
+ pad = state->domain | 0x80;
+ crypto_core_keccak1600_xor_bytes(state->state, &pad, state->offset, 1);
+ } else {
+ /* Normal case: domain and 0x80 at different positions */
+ crypto_core_keccak1600_xor_bytes(state->state, &state->domain, state->offset, 1);
+ pad = 0x80;
+ crypto_core_keccak1600_xor_bytes(state->state, &pad, SHAKE256_RATE - 1, 1);
+ }
+
+ /* Final permutation */
+ crypto_core_keccak1600_permute_24(state->state);
+
+ state->offset = 0;
+ state->phase = SHAKE256_PHASE_SQUEEZING;
+}
+
+int
+shake256_ref_final(shake256_state_internal *state, unsigned char *out, size_t outlen)
+{
+ if (state->phase == SHAKE256_PHASE_ABSORBING) {
+ shake256_finalize(state);
+ }
+
+ return shake256_ref_squeeze(state, out, outlen);
+}
+
+int
+shake256_ref_squeeze(shake256_state_internal *state, unsigned char *out, size_t outlen)
+{
+ size_t i;
+
+ if (state->phase == SHAKE256_PHASE_ABSORBING) {
+ shake256_finalize(state);
+ }
+
+ for (i = 0; i < outlen; i++) {
+ if (state->offset == SHAKE256_RATE) {
+ crypto_core_keccak1600_permute_24(state->state);
+ state->offset = 0;
+ }
+ crypto_core_keccak1600_extract_bytes(state->state, &out[i], state->offset, 1);
+ state->offset++;
+ }
+
+ return 0;
+}
+
+int
+shake256_ref(unsigned char *out, size_t outlen, const unsigned char *in, unsigned long long inlen)
+{
+ shake256_state_internal state;
+
+ shake256_ref_init(&state);
+ shake256_ref_update(&state, in, inlen);
+ shake256_ref_final(&state, out, outlen);
+
+ return 0;
+}
diff --git a/src/libsodium/crypto_xof/shake256/ref/shake256_ref.h b/src/libsodium/crypto_xof/shake256/ref/shake256_ref.h
new file mode 100644
index 00000000..c65b6681
--- /dev/null
+++ b/src/libsodium/crypto_xof/shake256/ref/shake256_ref.h
@@ -0,0 +1,33 @@
+#ifndef shake256_ref_H
+#define shake256_ref_H
+
+#include
+#include
+
+#define SHAKE256_RATE 136
+
+typedef enum { SHAKE256_PHASE_ABSORBING = 0, SHAKE256_PHASE_SQUEEZING = 1 } shake256_phase;
+
+typedef struct shake256_state_internal_ {
+ unsigned char state[200];
+ size_t offset;
+ uint8_t phase;
+ unsigned char domain; /* Domain separation byte */
+} shake256_state_internal;
+
+int shake256_ref(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen);
+
+int shake256_ref_init(shake256_state_internal *state);
+
+int shake256_ref_init_with_domain(shake256_state_internal *state, unsigned char domain);
+
+int shake256_ref_update(shake256_state_internal *state,
+ const unsigned char *in,
+ unsigned long long inlen);
+
+int shake256_ref_final(shake256_state_internal *state, unsigned char *out, size_t outlen);
+
+int shake256_ref_squeeze(shake256_state_internal *state, unsigned char *out, size_t outlen);
+
+#endif /* shake256_ref_H */
diff --git a/src/libsodium/crypto_xof/shake256/xof_shake256.c b/src/libsodium/crypto_xof/shake256/xof_shake256.c
new file mode 100644
index 00000000..37402fa0
--- /dev/null
+++ b/src/libsodium/crypto_xof/shake256/xof_shake256.c
@@ -0,0 +1,78 @@
+#include "crypto_xof_shake256.h"
+#include "private/common.h"
+#include "ref/shake256_ref.h"
+
+size_t
+crypto_xof_shake256_blockbytes(void)
+{
+ return crypto_xof_shake256_BLOCKBYTES;
+}
+
+size_t
+crypto_xof_shake256_statebytes(void)
+{
+ return crypto_xof_shake256_STATEBYTES;
+}
+
+unsigned char
+crypto_xof_shake256_domain_standard(void)
+{
+ return crypto_xof_shake256_DOMAIN_STANDARD;
+}
+
+int
+crypto_xof_shake256(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen)
+{
+ shake256_state_internal state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_shake256_state) >= sizeof(shake256_state_internal));
+
+ return shake256_ref(out, outlen, in, inlen);
+}
+
+int
+crypto_xof_shake256_init(crypto_xof_shake256_state *state)
+{
+ shake256_state_internal *st = (shake256_state_internal *) (void *) state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_shake256_state) >= sizeof(shake256_state_internal));
+
+ return shake256_ref_init(st);
+}
+
+int
+crypto_xof_shake256_init_with_domain(crypto_xof_shake256_state *state, unsigned char domain)
+{
+ shake256_state_internal *st = (shake256_state_internal *) (void *) state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_shake256_state) >= sizeof(shake256_state_internal));
+
+ return shake256_ref_init_with_domain(st, domain);
+}
+
+int
+crypto_xof_shake256_update(crypto_xof_shake256_state *state,
+ const unsigned char *in,
+ unsigned long long inlen)
+{
+ shake256_state_internal *st = (shake256_state_internal *) (void *) state;
+
+ return shake256_ref_update(st, in, inlen);
+}
+
+int
+crypto_xof_shake256_final(crypto_xof_shake256_state *state, unsigned char *out, size_t outlen)
+{
+ shake256_state_internal *st = (shake256_state_internal *) (void *) state;
+
+ return shake256_ref_final(st, out, outlen);
+}
+
+int
+crypto_xof_shake256_squeeze(crypto_xof_shake256_state *state, unsigned char *out, size_t outlen)
+{
+ shake256_state_internal *st = (shake256_state_internal *) (void *) state;
+
+ return shake256_ref_squeeze(st, out, outlen);
+}
diff --git a/src/libsodium/crypto_xof/turboshake128/ref/turboshake128_ref.c b/src/libsodium/crypto_xof/turboshake128/ref/turboshake128_ref.c
new file mode 100644
index 00000000..bd232948
--- /dev/null
+++ b/src/libsodium/crypto_xof/turboshake128/ref/turboshake128_ref.c
@@ -0,0 +1,116 @@
+#include
+#include
+
+#include "crypto_core_keccak1600.h"
+#include "private/common.h"
+#include "turboshake128_ref.h"
+
+#define TURBOSHAKE128_DOMAIN_BYTE_STANDARD 0x01
+
+int
+turboshake128_ref_init_with_domain(turboshake128_state_internal *state, unsigned char domain)
+{
+ crypto_core_keccak1600_init(state->state);
+ state->offset = 0;
+ state->phase = TURBOSHAKE128_PHASE_ABSORBING;
+ state->domain = domain;
+
+ return 0;
+}
+
+int
+turboshake128_ref_init(turboshake128_state_internal *state)
+{
+ return turboshake128_ref_init_with_domain(state, TURBOSHAKE128_DOMAIN_BYTE_STANDARD);
+}
+
+int
+turboshake128_ref_update(turboshake128_state_internal *state,
+ const unsigned char *in,
+ unsigned long long inlen)
+{
+ size_t i;
+
+ if (state->phase != TURBOSHAKE128_PHASE_ABSORBING) {
+ return -1; /* Cannot absorb after squeezing */
+ }
+
+ for (i = 0; i < inlen; i++) {
+ if (state->offset == TURBOSHAKE128_RATE) {
+ crypto_core_keccak1600_permute_12(state->state);
+ state->offset = 0;
+ }
+ crypto_core_keccak1600_xor_bytes(state->state, &in[i], state->offset, 1);
+ state->offset++;
+ }
+
+ return 0;
+}
+
+static void
+turboshake128_finalize(turboshake128_state_internal *state)
+{
+ unsigned char pad;
+
+ /* Apply padding: domain byte at current position, 0x80 at last byte */
+ if (state->offset == TURBOSHAKE128_RATE - 1) {
+ /* Special case: padding fits in one byte */
+ pad = state->domain | 0x80;
+ crypto_core_keccak1600_xor_bytes(state->state, &pad, state->offset, 1);
+ } else {
+ /* Normal case: domain and 0x80 at different positions */
+ crypto_core_keccak1600_xor_bytes(state->state, &state->domain, state->offset, 1);
+ pad = 0x80;
+ crypto_core_keccak1600_xor_bytes(state->state, &pad, TURBOSHAKE128_RATE - 1, 1);
+ }
+
+ /* Final permutation (12 rounds for TurboSHAKE) */
+ crypto_core_keccak1600_permute_12(state->state);
+
+ state->offset = 0;
+ state->phase = TURBOSHAKE128_PHASE_SQUEEZING;
+}
+
+int
+turboshake128_ref_final(turboshake128_state_internal *state, unsigned char *out, size_t outlen)
+{
+ if (state->phase == TURBOSHAKE128_PHASE_ABSORBING) {
+ turboshake128_finalize(state);
+ }
+
+ return turboshake128_ref_squeeze(state, out, outlen);
+}
+
+int
+turboshake128_ref_squeeze(turboshake128_state_internal *state, unsigned char *out, size_t outlen)
+{
+ size_t i;
+
+ if (state->phase == TURBOSHAKE128_PHASE_ABSORBING) {
+ turboshake128_finalize(state);
+ }
+
+ for (i = 0; i < outlen; i++) {
+ if (state->offset == TURBOSHAKE128_RATE) {
+ crypto_core_keccak1600_permute_12(state->state);
+ state->offset = 0;
+ }
+ crypto_core_keccak1600_extract_bytes(state->state, &out[i], state->offset, 1);
+ state->offset++;
+ }
+
+ return 0;
+}
+
+int
+turboshake128_ref(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen)
+{
+ turboshake128_state_internal state;
+
+ turboshake128_ref_init(&state);
+ turboshake128_ref_update(&state, in, inlen);
+ turboshake128_ref_final(&state, out, outlen);
+
+ return 0;
+}
diff --git a/src/libsodium/crypto_xof/turboshake128/ref/turboshake128_ref.h b/src/libsodium/crypto_xof/turboshake128/ref/turboshake128_ref.h
new file mode 100644
index 00000000..04a4a6c9
--- /dev/null
+++ b/src/libsodium/crypto_xof/turboshake128/ref/turboshake128_ref.h
@@ -0,0 +1,37 @@
+#ifndef turboshake128_ref_H
+#define turboshake128_ref_H
+
+#include
+#include
+
+#define TURBOSHAKE128_RATE 168
+
+typedef enum {
+ TURBOSHAKE128_PHASE_ABSORBING = 0,
+ TURBOSHAKE128_PHASE_SQUEEZING = 1
+} turboshake128_phase;
+
+typedef struct turboshake128_state_internal_ {
+ unsigned char state[200];
+ size_t offset;
+ uint8_t phase;
+ unsigned char domain; /* Domain separation byte */
+} turboshake128_state_internal;
+
+int turboshake128_ref(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen);
+
+int turboshake128_ref_init(turboshake128_state_internal *state);
+
+int turboshake128_ref_init_with_domain(turboshake128_state_internal *state, unsigned char domain);
+
+int turboshake128_ref_update(turboshake128_state_internal *state,
+ const unsigned char *in,
+ unsigned long long inlen);
+
+int turboshake128_ref_final(turboshake128_state_internal *state, unsigned char *out, size_t outlen);
+
+int turboshake128_ref_squeeze(turboshake128_state_internal *state, unsigned char *out,
+ size_t outlen);
+
+#endif /* turboshake128_ref_H */
diff --git a/src/libsodium/crypto_xof/turboshake128/xof_turboshake128.c b/src/libsodium/crypto_xof/turboshake128/xof_turboshake128.c
new file mode 100644
index 00000000..798988ae
--- /dev/null
+++ b/src/libsodium/crypto_xof/turboshake128/xof_turboshake128.c
@@ -0,0 +1,81 @@
+#include "crypto_xof_turboshake128.h"
+#include "private/common.h"
+#include "ref/turboshake128_ref.h"
+
+size_t
+crypto_xof_turboshake128_blockbytes(void)
+{
+ return crypto_xof_turboshake128_BLOCKBYTES;
+}
+
+size_t
+crypto_xof_turboshake128_statebytes(void)
+{
+ return crypto_xof_turboshake128_STATEBYTES;
+}
+
+unsigned char
+crypto_xof_turboshake128_domain_standard(void)
+{
+ return crypto_xof_turboshake128_DOMAIN_STANDARD;
+}
+
+int
+crypto_xof_turboshake128(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen)
+{
+ turboshake128_state_internal state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_turboshake128_state) >= sizeof(turboshake128_state_internal));
+
+ return turboshake128_ref(out, outlen, in, inlen);
+}
+
+int
+crypto_xof_turboshake128_init(crypto_xof_turboshake128_state *state)
+{
+ turboshake128_state_internal *st = (turboshake128_state_internal *) (void *) state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_turboshake128_state) >= sizeof(turboshake128_state_internal));
+
+ return turboshake128_ref_init(st);
+}
+
+int
+crypto_xof_turboshake128_init_with_domain(crypto_xof_turboshake128_state *state,
+ unsigned char domain)
+{
+ turboshake128_state_internal *st = (turboshake128_state_internal *) (void *) state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_turboshake128_state) >= sizeof(turboshake128_state_internal));
+
+ return turboshake128_ref_init_with_domain(st, domain);
+}
+
+int
+crypto_xof_turboshake128_update(crypto_xof_turboshake128_state *state,
+ const unsigned char *in,
+ unsigned long long inlen)
+{
+ turboshake128_state_internal *st = (turboshake128_state_internal *) (void *) state;
+
+ return turboshake128_ref_update(st, in, inlen);
+}
+
+int
+crypto_xof_turboshake128_final(crypto_xof_turboshake128_state *state, unsigned char *out,
+ size_t outlen)
+{
+ turboshake128_state_internal *st = (turboshake128_state_internal *) (void *) state;
+
+ return turboshake128_ref_final(st, out, outlen);
+}
+
+int
+crypto_xof_turboshake128_squeeze(crypto_xof_turboshake128_state *state, unsigned char *out,
+ size_t outlen)
+{
+ turboshake128_state_internal *st = (turboshake128_state_internal *) (void *) state;
+
+ return turboshake128_ref_squeeze(st, out, outlen);
+}
diff --git a/src/libsodium/crypto_xof/turboshake256/ref/turboshake256_ref.c b/src/libsodium/crypto_xof/turboshake256/ref/turboshake256_ref.c
new file mode 100644
index 00000000..c49f2659
--- /dev/null
+++ b/src/libsodium/crypto_xof/turboshake256/ref/turboshake256_ref.c
@@ -0,0 +1,116 @@
+#include
+#include
+
+#include "crypto_core_keccak1600.h"
+#include "private/common.h"
+#include "turboshake256_ref.h"
+
+#define TURBOSHAKE256_DOMAIN_BYTE_STANDARD 0x01
+
+int
+turboshake256_ref_init_with_domain(turboshake256_state_internal *state, unsigned char domain)
+{
+ crypto_core_keccak1600_init(state->state);
+ state->offset = 0;
+ state->phase = TURBOSHAKE256_PHASE_ABSORBING;
+ state->domain = domain;
+
+ return 0;
+}
+
+int
+turboshake256_ref_init(turboshake256_state_internal *state)
+{
+ return turboshake256_ref_init_with_domain(state, TURBOSHAKE256_DOMAIN_BYTE_STANDARD);
+}
+
+int
+turboshake256_ref_update(turboshake256_state_internal *state,
+ const unsigned char *in,
+ unsigned long long inlen)
+{
+ size_t i;
+
+ if (state->phase != TURBOSHAKE256_PHASE_ABSORBING) {
+ return -1; /* Cannot absorb after squeezing */
+ }
+
+ for (i = 0; i < inlen; i++) {
+ if (state->offset == TURBOSHAKE256_RATE) {
+ crypto_core_keccak1600_permute_12(state->state);
+ state->offset = 0;
+ }
+ crypto_core_keccak1600_xor_bytes(state->state, &in[i], state->offset, 1);
+ state->offset++;
+ }
+
+ return 0;
+}
+
+static void
+turboshake256_finalize(turboshake256_state_internal *state)
+{
+ unsigned char pad;
+
+ /* Apply padding: domain byte at current position, 0x80 at last byte */
+ if (state->offset == TURBOSHAKE256_RATE - 1) {
+ /* Special case: padding fits in one byte */
+ pad = state->domain | 0x80;
+ crypto_core_keccak1600_xor_bytes(state->state, &pad, state->offset, 1);
+ } else {
+ /* Normal case: domain and 0x80 at different positions */
+ crypto_core_keccak1600_xor_bytes(state->state, &state->domain, state->offset, 1);
+ pad = 0x80;
+ crypto_core_keccak1600_xor_bytes(state->state, &pad, TURBOSHAKE256_RATE - 1, 1);
+ }
+
+ /* Final permutation (12 rounds for TurboSHAKE) */
+ crypto_core_keccak1600_permute_12(state->state);
+
+ state->offset = 0;
+ state->phase = TURBOSHAKE256_PHASE_SQUEEZING;
+}
+
+int
+turboshake256_ref_final(turboshake256_state_internal *state, unsigned char *out, size_t outlen)
+{
+ if (state->phase == TURBOSHAKE256_PHASE_ABSORBING) {
+ turboshake256_finalize(state);
+ }
+
+ return turboshake256_ref_squeeze(state, out, outlen);
+}
+
+int
+turboshake256_ref_squeeze(turboshake256_state_internal *state, unsigned char *out, size_t outlen)
+{
+ size_t i;
+
+ if (state->phase == TURBOSHAKE256_PHASE_ABSORBING) {
+ turboshake256_finalize(state);
+ }
+
+ for (i = 0; i < outlen; i++) {
+ if (state->offset == TURBOSHAKE256_RATE) {
+ crypto_core_keccak1600_permute_12(state->state);
+ state->offset = 0;
+ }
+ crypto_core_keccak1600_extract_bytes(state->state, &out[i], state->offset, 1);
+ state->offset++;
+ }
+
+ return 0;
+}
+
+int
+turboshake256_ref(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen)
+{
+ turboshake256_state_internal state;
+
+ turboshake256_ref_init(&state);
+ turboshake256_ref_update(&state, in, inlen);
+ turboshake256_ref_final(&state, out, outlen);
+
+ return 0;
+}
diff --git a/src/libsodium/crypto_xof/turboshake256/ref/turboshake256_ref.h b/src/libsodium/crypto_xof/turboshake256/ref/turboshake256_ref.h
new file mode 100644
index 00000000..9d6c3cee
--- /dev/null
+++ b/src/libsodium/crypto_xof/turboshake256/ref/turboshake256_ref.h
@@ -0,0 +1,37 @@
+#ifndef turboshake256_ref_H
+#define turboshake256_ref_H
+
+#include
+#include
+
+#define TURBOSHAKE256_RATE 136
+
+typedef enum {
+ TURBOSHAKE256_PHASE_ABSORBING = 0,
+ TURBOSHAKE256_PHASE_SQUEEZING = 1
+} turboshake256_phase;
+
+typedef struct turboshake256_state_internal_ {
+ unsigned char state[200];
+ size_t offset;
+ uint8_t phase;
+ unsigned char domain; /* Domain separation byte */
+} turboshake256_state_internal;
+
+int turboshake256_ref(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen);
+
+int turboshake256_ref_init(turboshake256_state_internal *state);
+
+int turboshake256_ref_init_with_domain(turboshake256_state_internal *state, unsigned char domain);
+
+int turboshake256_ref_update(turboshake256_state_internal *state,
+ const unsigned char *in,
+ unsigned long long inlen);
+
+int turboshake256_ref_final(turboshake256_state_internal *state, unsigned char *out, size_t outlen);
+
+int turboshake256_ref_squeeze(turboshake256_state_internal *state, unsigned char *out,
+ size_t outlen);
+
+#endif /* turboshake256_ref_H */
diff --git a/src/libsodium/crypto_xof/turboshake256/xof_turboshake256.c b/src/libsodium/crypto_xof/turboshake256/xof_turboshake256.c
new file mode 100644
index 00000000..7e0e15b3
--- /dev/null
+++ b/src/libsodium/crypto_xof/turboshake256/xof_turboshake256.c
@@ -0,0 +1,81 @@
+#include "crypto_xof_turboshake256.h"
+#include "private/common.h"
+#include "ref/turboshake256_ref.h"
+
+size_t
+crypto_xof_turboshake256_blockbytes(void)
+{
+ return crypto_xof_turboshake256_BLOCKBYTES;
+}
+
+size_t
+crypto_xof_turboshake256_statebytes(void)
+{
+ return crypto_xof_turboshake256_STATEBYTES;
+}
+
+unsigned char
+crypto_xof_turboshake256_domain_standard(void)
+{
+ return crypto_xof_turboshake256_DOMAIN_STANDARD;
+}
+
+int
+crypto_xof_turboshake256(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen)
+{
+ turboshake256_state_internal state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_turboshake256_state) >= sizeof(turboshake256_state_internal));
+
+ return turboshake256_ref(out, outlen, in, inlen);
+}
+
+int
+crypto_xof_turboshake256_init(crypto_xof_turboshake256_state *state)
+{
+ turboshake256_state_internal *st = (turboshake256_state_internal *) (void *) state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_turboshake256_state) >= sizeof(turboshake256_state_internal));
+
+ return turboshake256_ref_init(st);
+}
+
+int
+crypto_xof_turboshake256_init_with_domain(crypto_xof_turboshake256_state *state,
+ unsigned char domain)
+{
+ turboshake256_state_internal *st = (turboshake256_state_internal *) (void *) state;
+
+ COMPILER_ASSERT(sizeof(crypto_xof_turboshake256_state) >= sizeof(turboshake256_state_internal));
+
+ return turboshake256_ref_init_with_domain(st, domain);
+}
+
+int
+crypto_xof_turboshake256_update(crypto_xof_turboshake256_state *state,
+ const unsigned char *in,
+ unsigned long long inlen)
+{
+ turboshake256_state_internal *st = (turboshake256_state_internal *) (void *) state;
+
+ return turboshake256_ref_update(st, in, inlen);
+}
+
+int
+crypto_xof_turboshake256_final(crypto_xof_turboshake256_state *state, unsigned char *out,
+ size_t outlen)
+{
+ turboshake256_state_internal *st = (turboshake256_state_internal *) (void *) state;
+
+ return turboshake256_ref_final(st, out, outlen);
+}
+
+int
+crypto_xof_turboshake256_squeeze(crypto_xof_turboshake256_state *state, unsigned char *out,
+ size_t outlen)
+{
+ turboshake256_state_internal *st = (turboshake256_state_internal *) (void *) state;
+
+ return turboshake256_ref_squeeze(st, out, outlen);
+}
diff --git a/src/libsodium/include/Makefile.am b/src/libsodium/include/Makefile.am
index d639c634..84e90d18 100644
--- a/src/libsodium/include/Makefile.am
+++ b/src/libsodium/include/Makefile.am
@@ -18,6 +18,7 @@ SODIUM_EXPORT = \
sodium/crypto_core_ristretto255.h \
sodium/crypto_core_hchacha20.h \
sodium/crypto_core_hsalsa20.h \
+ sodium/crypto_core_keccak1600.h \
sodium/crypto_core_salsa20.h \
sodium/crypto_core_salsa2012.h \
sodium/crypto_core_salsa208.h \
@@ -59,6 +60,10 @@ SODIUM_EXPORT = \
sodium/crypto_verify_16.h \
sodium/crypto_verify_32.h \
sodium/crypto_verify_64.h \
+ sodium/crypto_xof_shake128.h \
+ sodium/crypto_xof_shake256.h \
+ sodium/crypto_xof_turboshake128.h \
+ sodium/crypto_xof_turboshake256.h \
sodium/export.h \
sodium/randombytes.h \
sodium/randombytes_internal_random.h \
diff --git a/src/libsodium/include/sodium.h b/src/libsodium/include/sodium.h
index ff788e34..e4508652 100644
--- a/src/libsodium/include/sodium.h
+++ b/src/libsodium/include/sodium.h
@@ -18,6 +18,7 @@
#include "sodium/crypto_box_curve25519xsalsa20poly1305.h"
#include "sodium/crypto_core_hsalsa20.h"
#include "sodium/crypto_core_hchacha20.h"
+#include "sodium/crypto_core_keccak1600.h"
#include "sodium/crypto_core_salsa20.h"
#include "sodium/crypto_core_salsa2012.h"
#include "sodium/crypto_core_salsa208.h"
@@ -51,6 +52,10 @@
#include "sodium/crypto_verify_16.h"
#include "sodium/crypto_verify_32.h"
#include "sodium/crypto_verify_64.h"
+#include "sodium/crypto_xof_shake128.h"
+#include "sodium/crypto_xof_shake256.h"
+#include "sodium/crypto_xof_turboshake128.h"
+#include "sodium/crypto_xof_turboshake256.h"
#include "sodium/randombytes.h"
#include "sodium/randombytes_internal_random.h"
#include "sodium/randombytes_sysrandom.h"
diff --git a/src/libsodium/include/sodium/crypto_core_keccak1600.h b/src/libsodium/include/sodium/crypto_core_keccak1600.h
new file mode 100644
index 00000000..1c84c720
--- /dev/null
+++ b/src/libsodium/include/sodium/crypto_core_keccak1600.h
@@ -0,0 +1,50 @@
+#ifndef crypto_core_keccak1600_H
+#define crypto_core_keccak1600_H
+
+#include
+
+#include "export.h"
+
+#ifdef __cplusplus
+# ifdef __GNUC__
+# pragma GCC diagnostic ignored "-Wlong-long"
+# endif
+extern "C" {
+#endif
+
+#define crypto_core_keccak1600_STATEBYTES 200U
+SODIUM_EXPORT
+size_t crypto_core_keccak1600_statebytes(void);
+
+/* Initialize state to all zeros */
+SODIUM_EXPORT
+void crypto_core_keccak1600_init(void *state)
+ __attribute__ ((nonnull));
+
+/* XOR bytes into state (for absorbing) */
+SODIUM_EXPORT
+void crypto_core_keccak1600_xor_bytes(void *state, const unsigned char *bytes,
+ size_t offset, size_t length)
+ __attribute__ ((nonnull));
+
+/* Extract bytes from state (for squeezing) */
+SODIUM_EXPORT
+void crypto_core_keccak1600_extract_bytes(const void *state, unsigned char *bytes,
+ size_t offset, size_t length)
+ __attribute__ ((nonnull));
+
+/* Keccak-f[1600]: 24 rounds (for SHAKE) */
+SODIUM_EXPORT
+void crypto_core_keccak1600_permute_24(void *state)
+ __attribute__ ((nonnull));
+
+/* Keccak-p[1600,12]: 12 rounds (for TurboSHAKE) */
+SODIUM_EXPORT
+void crypto_core_keccak1600_permute_12(void *state)
+ __attribute__ ((nonnull));
+
+#ifdef __cplusplus
+}
+#endif
+
+#endif
diff --git a/src/libsodium/include/sodium/crypto_xof_shake128.h b/src/libsodium/include/sodium/crypto_xof_shake128.h
new file mode 100644
index 00000000..3ac2c0b6
--- /dev/null
+++ b/src/libsodium/include/sodium/crypto_xof_shake128.h
@@ -0,0 +1,59 @@
+#ifndef crypto_xof_shake128_H
+#define crypto_xof_shake128_H
+
+#include
+
+#include "export.h"
+
+#ifdef __cplusplus
+# ifdef __GNUC__
+# pragma GCC diagnostic ignored "-Wlong-long"
+# endif
+extern "C" {
+#endif
+
+#define crypto_xof_shake128_BLOCKBYTES 168U
+SODIUM_EXPORT
+size_t crypto_xof_shake128_blockbytes(void);
+
+#define crypto_xof_shake128_STATEBYTES 256U
+SODIUM_EXPORT
+size_t crypto_xof_shake128_statebytes(void);
+
+#define crypto_xof_shake128_DOMAIN_STANDARD 0x1FU
+SODIUM_EXPORT
+unsigned char crypto_xof_shake128_domain_standard(void);
+
+typedef struct CRYPTO_ALIGN(64) crypto_xof_shake128_state {
+ unsigned char opaque[256];
+} crypto_xof_shake128_state;
+
+SODIUM_EXPORT
+int crypto_xof_shake128(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen) __attribute__((nonnull(1)));
+
+SODIUM_EXPORT
+int crypto_xof_shake128_init(crypto_xof_shake128_state *state) __attribute__((nonnull));
+
+SODIUM_EXPORT
+int crypto_xof_shake128_init_with_domain(crypto_xof_shake128_state *state, unsigned char domain)
+ __attribute__((nonnull));
+
+SODIUM_EXPORT
+int crypto_xof_shake128_update(crypto_xof_shake128_state *state,
+ const unsigned char *in,
+ unsigned long long inlen) __attribute__((nonnull(1)));
+
+SODIUM_EXPORT
+int crypto_xof_shake128_final(crypto_xof_shake128_state *state, unsigned char *out, size_t outlen)
+ __attribute__((nonnull));
+
+SODIUM_EXPORT
+int crypto_xof_shake128_squeeze(crypto_xof_shake128_state *state, unsigned char *out, size_t outlen)
+ __attribute__((nonnull));
+
+#ifdef __cplusplus
+}
+#endif
+
+#endif
diff --git a/src/libsodium/include/sodium/crypto_xof_shake256.h b/src/libsodium/include/sodium/crypto_xof_shake256.h
new file mode 100644
index 00000000..c2f6d58f
--- /dev/null
+++ b/src/libsodium/include/sodium/crypto_xof_shake256.h
@@ -0,0 +1,58 @@
+#ifndef crypto_xof_shake256_H
+#define crypto_xof_shake256_H
+
+#include "export.h"
+#include
+
+#ifdef __cplusplus
+extern "C" {
+#endif
+
+#define crypto_xof_shake256_BLOCKBYTES 136U
+SODIUM_EXPORT
+size_t crypto_xof_shake256_blockbytes(void);
+
+#define crypto_xof_shake256_STATEBYTES 256U
+SODIUM_EXPORT
+size_t crypto_xof_shake256_statebytes(void);
+
+#define crypto_xof_shake256_DOMAIN_STANDARD 0x1FU
+SODIUM_EXPORT
+unsigned char crypto_xof_shake256_domain_standard(void);
+
+typedef struct CRYPTO_ALIGN(64) crypto_xof_shake256_state {
+ unsigned char opaque[256];
+} crypto_xof_shake256_state;
+
+/* One-shot API */
+SODIUM_EXPORT
+int crypto_xof_shake256(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen) __attribute__((nonnull(1)));
+
+/* Streaming API with standard domain */
+SODIUM_EXPORT
+int crypto_xof_shake256_init(crypto_xof_shake256_state *state) __attribute__((nonnull));
+
+/* Streaming API with custom domain */
+SODIUM_EXPORT
+int crypto_xof_shake256_init_with_domain(crypto_xof_shake256_state *state, unsigned char domain)
+ __attribute__((nonnull));
+
+SODIUM_EXPORT
+int crypto_xof_shake256_update(crypto_xof_shake256_state *state,
+ const unsigned char *in,
+ unsigned long long inlen) __attribute__((nonnull(1)));
+
+SODIUM_EXPORT
+int crypto_xof_shake256_final(crypto_xof_shake256_state *state, unsigned char *out, size_t outlen)
+ __attribute__((nonnull));
+
+SODIUM_EXPORT
+int crypto_xof_shake256_squeeze(crypto_xof_shake256_state *state, unsigned char *out, size_t outlen)
+ __attribute__((nonnull));
+
+#ifdef __cplusplus
+}
+#endif
+
+#endif
diff --git a/src/libsodium/include/sodium/crypto_xof_turboshake128.h b/src/libsodium/include/sodium/crypto_xof_turboshake128.h
new file mode 100644
index 00000000..d7513171
--- /dev/null
+++ b/src/libsodium/include/sodium/crypto_xof_turboshake128.h
@@ -0,0 +1,58 @@
+#ifndef crypto_xof_turboshake128_H
+#define crypto_xof_turboshake128_H
+
+#include "export.h"
+#include
+
+#ifdef __cplusplus
+extern "C" {
+#endif
+
+#define crypto_xof_turboshake128_BLOCKBYTES 168U
+SODIUM_EXPORT
+size_t crypto_xof_turboshake128_blockbytes(void);
+
+#define crypto_xof_turboshake128_STATEBYTES 256U
+SODIUM_EXPORT
+size_t crypto_xof_turboshake128_statebytes(void);
+
+#define crypto_xof_turboshake128_DOMAIN_STANDARD 0x01U
+SODIUM_EXPORT
+unsigned char crypto_xof_turboshake128_domain_standard(void);
+
+typedef struct CRYPTO_ALIGN(64) crypto_xof_turboshake128_state {
+ unsigned char opaque[256];
+} crypto_xof_turboshake128_state;
+
+/* One-shot API */
+SODIUM_EXPORT
+int crypto_xof_turboshake128(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen) __attribute__((nonnull(1)));
+
+/* Streaming API with standard domain */
+SODIUM_EXPORT
+int crypto_xof_turboshake128_init(crypto_xof_turboshake128_state *state) __attribute__((nonnull));
+
+/* Streaming API with custom domain */
+SODIUM_EXPORT
+int crypto_xof_turboshake128_init_with_domain(crypto_xof_turboshake128_state *state,
+ unsigned char domain) __attribute__((nonnull));
+
+SODIUM_EXPORT
+int crypto_xof_turboshake128_update(crypto_xof_turboshake128_state *state,
+ const unsigned char *in,
+ unsigned long long inlen) __attribute__((nonnull(1)));
+
+SODIUM_EXPORT
+int crypto_xof_turboshake128_final(crypto_xof_turboshake128_state *state, unsigned char *out,
+ size_t outlen) __attribute__((nonnull));
+
+SODIUM_EXPORT
+int crypto_xof_turboshake128_squeeze(crypto_xof_turboshake128_state *state, unsigned char *out,
+ size_t outlen) __attribute__((nonnull));
+
+#ifdef __cplusplus
+}
+#endif
+
+#endif
diff --git a/src/libsodium/include/sodium/crypto_xof_turboshake256.h b/src/libsodium/include/sodium/crypto_xof_turboshake256.h
new file mode 100644
index 00000000..e8ecd269
--- /dev/null
+++ b/src/libsodium/include/sodium/crypto_xof_turboshake256.h
@@ -0,0 +1,58 @@
+#ifndef crypto_xof_turboshake256_H
+#define crypto_xof_turboshake256_H
+
+#include "export.h"
+#include
+
+#ifdef __cplusplus
+extern "C" {
+#endif
+
+#define crypto_xof_turboshake256_BLOCKBYTES 136U
+SODIUM_EXPORT
+size_t crypto_xof_turboshake256_blockbytes(void);
+
+#define crypto_xof_turboshake256_STATEBYTES 256U
+SODIUM_EXPORT
+size_t crypto_xof_turboshake256_statebytes(void);
+
+#define crypto_xof_turboshake256_DOMAIN_STANDARD 0x01U
+SODIUM_EXPORT
+unsigned char crypto_xof_turboshake256_domain_standard(void);
+
+typedef struct CRYPTO_ALIGN(64) crypto_xof_turboshake256_state {
+ unsigned char opaque[256];
+} crypto_xof_turboshake256_state;
+
+/* One-shot API */
+SODIUM_EXPORT
+int crypto_xof_turboshake256(unsigned char *out, size_t outlen, const unsigned char *in,
+ unsigned long long inlen) __attribute__((nonnull(1)));
+
+/* Streaming API with standard domain */
+SODIUM_EXPORT
+int crypto_xof_turboshake256_init(crypto_xof_turboshake256_state *state) __attribute__((nonnull));
+
+/* Streaming API with custom domain */
+SODIUM_EXPORT
+int crypto_xof_turboshake256_init_with_domain(crypto_xof_turboshake256_state *state,
+ unsigned char domain) __attribute__((nonnull));
+
+SODIUM_EXPORT
+int crypto_xof_turboshake256_update(crypto_xof_turboshake256_state *state,
+ const unsigned char *in,
+ unsigned long long inlen) __attribute__((nonnull(1)));
+
+SODIUM_EXPORT
+int crypto_xof_turboshake256_final(crypto_xof_turboshake256_state *state, unsigned char *out,
+ size_t outlen) __attribute__((nonnull));
+
+SODIUM_EXPORT
+int crypto_xof_turboshake256_squeeze(crypto_xof_turboshake256_state *state, unsigned char *out,
+ size_t outlen) __attribute__((nonnull));
+
+#ifdef __cplusplus
+}
+#endif
+
+#endif
diff --git a/src/libsodium/include/sodium/private/quirks.h b/src/libsodium/include/sodium/private/quirks.h
index fa474b7c..dc0ba402 100644
--- a/src/libsodium/include/sodium/private/quirks.h
+++ b/src/libsodium/include/sodium/private/quirks.h
@@ -70,6 +70,11 @@
#define ge25519_scalarmult _sodium_ge25519_scalarmult
#define ge25519_scalarmult_base _sodium_ge25519_scalarmult_base
#define ge25519_tobytes _sodium_ge25519_tobytes
+#define keccak1600_ref_extract_bytes _sodium_keccak1600_ref_extract_bytes
+#define keccak1600_ref_init _sodium_keccak1600_ref_init
+#define keccak1600_ref_permute_12 _sodium_keccak1600_ref_permute_12
+#define keccak1600_ref_permute_24 _sodium_keccak1600_ref_permute_24
+#define keccak1600_ref_xor_bytes _sodium_keccak1600_ref_xor_bytes
#define ristretto255_from_hash _sodium_ristretto255_from_hash
#define ristretto255_frombytes _sodium_ristretto255_frombytes
#define ristretto255_p3_tobytes _sodium_ristretto255_p3_tobytes
@@ -78,7 +83,31 @@
#define sc25519_mul _sodium_sc25519_mul
#define sc25519_muladd _sodium_sc25519_muladd
#define sc25519_reduce _sodium_sc25519_reduce
+#define shake128_ref _sodium_shake128_ref
+#define shake128_ref_final _sodium_shake128_ref_final
+#define shake128_ref_init _sodium_shake128_ref_init
+#define shake128_ref_init_with_domain _sodium_shake128_ref_init_with_domain
+#define shake128_ref_squeeze _sodium_shake128_ref_squeeze
+#define shake128_ref_update _sodium_shake128_ref_update
+#define shake256_ref _sodium_shake256_ref
+#define shake256_ref_final _sodium_shake256_ref_final
+#define shake256_ref_init _sodium_shake256_ref_init
+#define shake256_ref_init_with_domain _sodium_shake256_ref_init_with_domain
+#define shake256_ref_squeeze _sodium_shake256_ref_squeeze
+#define shake256_ref_update _sodium_shake256_ref_update
#define softaes_block_encrypt _sodium_softaes_block_encrypt
+#define turboshake128_ref _sodium_turboshake128_ref
+#define turboshake128_ref_final _sodium_turboshake128_ref_final
+#define turboshake128_ref_init _sodium_turboshake128_ref_init
+#define turboshake128_ref_init_with_domain _sodium_turboshake128_ref_init_with_domain
+#define turboshake128_ref_squeeze _sodium_turboshake128_ref_squeeze
+#define turboshake128_ref_update _sodium_turboshake128_ref_update
+#define turboshake256_ref _sodium_turboshake256_ref
+#define turboshake256_ref_final _sodium_turboshake256_ref_final
+#define turboshake256_ref_init _sodium_turboshake256_ref_init
+#define turboshake256_ref_init_with_domain _sodium_turboshake256_ref_init_with_domain
+#define turboshake256_ref_squeeze _sodium_turboshake256_ref_squeeze
+#define turboshake256_ref_update _sodium_turboshake256_ref_update
#endif
#endif
diff --git a/test/constcheck.sh b/test/constcheck.sh
index e9932d8d..74320f3e 100755
--- a/test/constcheck.sh
+++ b/test/constcheck.sh
@@ -13,9 +13,9 @@ done
echo "return 0; }" >> "$CT"
CPPFLAGS="${CPPFLAGS} -Wno-deprecated-declarations"
-CPPFLAGS="${CPPFLAGS} -I/opt/homebrew/include"
-LDFLAGS="${LDFLAGS} -L/opt/homebrew/lib"
+CPPFLAGS="${CPPFLAGS} -Isrc/libsodium/include"
+LDFLAGS="${LDFLAGS} -Lsrc/libsodium/.libs"
${CC:-cc} "$CT" $CPPFLAGS $CFLAGS $LDFLAGS -lsodium || exit 1
-./a.out || exit 1
+DYLD_LIBRARY_PATH=src/libsodium/.libs:$DYLD_LIBRARY_PATH ./a.out || exit 1
rm -f a.out "$CT"
diff --git a/test/default/Makefile.am b/test/default/Makefile.am
index 4ecace11..3dbb333f 100644
--- a/test/default/Makefile.am
+++ b/test/default/Makefile.am
@@ -37,6 +37,7 @@ EXTRA_DIST = \
core4.exp \
core5.exp \
core6.exp \
+ core_keccak1600.exp \
ed25519_convert.exp \
generichash.exp \
generichash2.exp \
@@ -86,7 +87,11 @@ EXTRA_DIST = \
stream3.exp \
stream4.exp \
verify1.exp \
- xchacha20.exp
+ xchacha20.exp \
+ xof_shake128.exp \
+ xof_shake256.exp \
+ xof_turboshake128.exp \
+ xof_turboshake256.exp
DISTCLEANFILES = \
aead_aegis128l.res \
@@ -121,6 +126,7 @@ DISTCLEANFILES = \
core4.res \
core5.res \
core6.res \
+ core_keccak1600.res \
ed25519_convert.res \
generichash.res \
generichash2.res \
@@ -171,7 +177,11 @@ DISTCLEANFILES = \
stream3.res \
stream4.res \
verify1.res \
- xchacha20.res
+ xchacha20.res \
+ xof_shake128.res \
+ xof_shake256.res \
+ xof_turboshake128.res \
+ xof_turboshake256.res
AM_CPPFLAGS = \
-DTEST_SRCDIR=\"@srcdir@\" \
@@ -213,6 +223,7 @@ TESTS_TARGETS = \
core4 \
core5 \
core6 \
+ core_keccak1600 \
ed25519_convert \
generichash \
generichash2 \
@@ -253,7 +264,11 @@ TESTS_TARGETS = \
stream2 \
stream3 \
stream4 \
- verify1
+ verify1 \
+ xof_shake128 \
+ xof_shake256 \
+ xof_turboshake128 \
+ xof_turboshake256
if !EMSCRIPTEN
TESTS_TARGETS += \
@@ -364,6 +379,9 @@ core5_LDADD = $(TESTS_LDADD)
core6_SOURCE = cmptest.h core6.c
core6_LDADD = $(TESTS_LDADD)
+core_keccak1600_SOURCE = cmptest.h core_keccak1600.c
+core_keccak1600_LDADD = $(TESTS_LDADD)
+
ed25519_convert_SOURCE = cmptest.h ed25519_convert.c
ed25519_convert_LDADD = $(TESTS_LDADD)
@@ -514,6 +532,18 @@ verify1_LDADD = $(TESTS_LDADD)
xchacha20_SOURCE = cmptest.h xchacha20.c
xchacha20_LDADD = $(TESTS_LDADD)
+xof_shake128_SOURCE = cmptest.h xof_shake128.c
+xof_shake128_LDADD = $(TESTS_LDADD)
+
+xof_shake256_SOURCE = cmptest.h xof_shake256.c
+xof_shake256_LDADD = $(TESTS_LDADD)
+
+xof_turboshake128_SOURCE = cmptest.h xof_turboshake128.c
+xof_turboshake128_LDADD = $(TESTS_LDADD)
+
+xof_turboshake256_SOURCE = cmptest.h xof_turboshake256.c
+xof_turboshake256_LDADD = $(TESTS_LDADD)
+
if !MINIMAL
TESTS_TARGETS += \
core_ed25519 \
diff --git a/test/default/core_keccak1600.c b/test/default/core_keccak1600.c
new file mode 100644
index 00000000..7d0263d9
--- /dev/null
+++ b/test/default/core_keccak1600.c
@@ -0,0 +1,248 @@
+
+#define TEST_NAME "core_keccak1600"
+#include "cmptest.h"
+
+static void
+print_state(const unsigned char *state, size_t len)
+{
+ size_t i;
+ for (i = 0; i < len; i++) {
+ if (i > 0 && i % 16 == 0) {
+ printf("\n");
+ }
+ printf("%02x", state[i]);
+ }
+ printf("\n");
+}
+
+static void
+print_hex(const char *label, const unsigned char *data, size_t len)
+{
+ size_t i;
+ printf("%s", label);
+ for (i = 0; i < len; i++) {
+ printf("%02x", data[i]);
+ }
+ printf("\n");
+}
+
+static int
+compare_states(const char *label, const unsigned char *actual, const unsigned char *expected,
+ size_t len)
+{
+ size_t i;
+ for (i = 0; i < len; i++) {
+ if (actual[i] != expected[i]) {
+ printf("FAIL: %s mismatch at byte %u\n", label, (unsigned int) i);
+ printf(" Expected: ");
+ for (size_t j = 0; j < len; j++) {
+ printf("%02x", expected[j]);
+ }
+ printf("\n Got: ");
+ for (size_t j = 0; j < len; j++) {
+ printf("%02x", actual[j]);
+ }
+ printf("\n");
+ return -1;
+ }
+ }
+ printf("PASS: %s\n", label);
+ return 0;
+}
+
+int
+main(void)
+{
+ unsigned char state[crypto_core_keccak1600_STATEBYTES];
+ unsigned char extracted[64];
+ size_t i;
+ int test_failures = 0;
+
+ /* Test vectors for Keccak-f[1600] (24 rounds) */
+ /* Test vector 1: All-zero input for Keccak-f[1600] */
+ static const unsigned char keccak_f_1600_zero_input[200] = { 0 };
+ static const unsigned char keccak_f_1600_zero_expected[200] = {
+ 0xe7, 0xdd, 0xe1, 0x40, 0x79, 0x8f, 0x25, 0xf1, 0x8a, 0x47, 0xc0, 0x33, 0xf9, 0xcc, 0xd5,
+ 0x84, 0xee, 0xa9, 0x5a, 0xa6, 0x1e, 0x26, 0x98, 0xd5, 0x4d, 0x49, 0x80, 0x6f, 0x30, 0x47,
+ 0x15, 0xbd, 0x57, 0xd0, 0x53, 0x62, 0x05, 0x4e, 0x28, 0x8b, 0xd4, 0x6f, 0x8e, 0x7f, 0x2d,
+ 0xa4, 0x97, 0xff, 0xc4, 0x47, 0x46, 0xa4, 0xa0, 0xe5, 0xfe, 0x90, 0x76, 0x2e, 0x19, 0xd6,
+ 0x0c, 0xda, 0x5b, 0x8c, 0x9c, 0x05, 0x19, 0x1b, 0xf7, 0xa6, 0x30, 0xad, 0x64, 0xfc, 0x8f,
+ 0xd0, 0xb7, 0x5a, 0x93, 0x30, 0x35, 0xd6, 0x17, 0x23, 0x3f, 0xa9, 0x5a, 0xeb, 0x03, 0x21,
+ 0x71, 0x0d, 0x26, 0xe6, 0xa6, 0xa9, 0x5f, 0x55, 0xcf, 0xdb, 0x16, 0x7c, 0xa5, 0x81, 0x26,
+ 0xc8, 0x47, 0x03, 0xcd, 0x31, 0xb8, 0x43, 0x9f, 0x56, 0xa5, 0x11, 0x1a, 0x2f, 0xf2, 0x01,
+ 0x61, 0xae, 0xd9, 0x21, 0x5a, 0x63, 0xe5, 0x05, 0xf2, 0x70, 0xc9, 0x8c, 0xf2, 0xfe, 0xbe,
+ 0x64, 0x11, 0x66, 0xc4, 0x7b, 0x95, 0x70, 0x36, 0x61, 0xcb, 0x0e, 0xd0, 0x4f, 0x55, 0x5a,
+ 0x7c, 0xb8, 0xc8, 0x32, 0xcf, 0x1c, 0x8a, 0xe8, 0x3e, 0x8c, 0x14, 0x26, 0x3a, 0xae, 0x22,
+ 0x79, 0x0c, 0x94, 0xe4, 0x09, 0xc5, 0xa2, 0x24, 0xf9, 0x41, 0x18, 0xc2, 0x65, 0x04, 0xe7,
+ 0x26, 0x35, 0xf5, 0x16, 0x3b, 0xa1, 0x30, 0x7f, 0xe9, 0x44, 0xf6, 0x75, 0x49, 0xa2, 0xec,
+ 0x5c, 0x7b, 0xff, 0xf1, 0xea
+ };
+
+ /* Test vector 2: Pattern input for Keccak-f[1600] */
+ static const unsigned char keccak_f_1600_pattern_input[200] = {
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3, 0xa3,
+ 0xa3, 0xa3, 0xa3, 0xa3, 0xa3
+ };
+ static const unsigned char keccak_f_1600_pattern_expected[200] = {
+ 0xcc, 0x44, 0x83, 0xfe, 0xb5, 0x5e, 0x43, 0xf4, 0x6d, 0x88, 0x81, 0xbd, 0x35, 0x8e, 0xbf,
+ 0x75, 0x9a, 0x06, 0xe7, 0xcd, 0x81, 0xf5, 0xca, 0x48, 0xbf, 0xb7, 0x1b, 0x19, 0xc8, 0x02,
+ 0x61, 0x45, 0x00, 0x0a, 0x17, 0x39, 0xb1, 0x18, 0x89, 0xc7, 0x3d, 0x53, 0xa9, 0x78, 0x17,
+ 0xd2, 0x82, 0x4e, 0x52, 0xe6, 0x76, 0xbd, 0xe5, 0xce, 0xee, 0x9a, 0x86, 0x6e, 0x8b, 0x4c,
+ 0xca, 0x8c, 0xf2, 0x99, 0xd8, 0x18, 0x53, 0xa0, 0x06, 0x15, 0x02, 0xff, 0x1a, 0x7b, 0x11,
+ 0x82, 0x7c, 0x96, 0x7d, 0x8c, 0xf2, 0xc6, 0x21, 0xa6, 0x24, 0xda, 0x96, 0x75, 0xd2, 0xab,
+ 0xc9, 0x30, 0x89, 0x22, 0x18, 0x14, 0x7e, 0xa9, 0x07, 0xa6, 0xf0, 0x88, 0x7a, 0x86, 0x6c,
+ 0x7b, 0x79, 0x89, 0xe0, 0x6c, 0xcf, 0x82, 0x66, 0x62, 0x63, 0x79, 0x98, 0x37, 0x44, 0xce,
+ 0x1d, 0xe1, 0xb1, 0xb5, 0x12, 0xca, 0x63, 0x6f, 0x25, 0x47, 0x14, 0x1d, 0xef, 0x48, 0x47,
+ 0xac, 0x64, 0x6a, 0x76, 0xbc, 0x25, 0xbc, 0xed, 0x98, 0xb7, 0x34, 0xfd, 0xd6, 0x65, 0x15,
+ 0x4d, 0x85, 0xe8, 0x1e, 0x65, 0x08, 0x09, 0x28, 0x19, 0x39, 0x04, 0xf7, 0x6f, 0xec, 0x96,
+ 0x27, 0xa2, 0x23, 0x3b, 0x2f, 0x75, 0x02, 0x09, 0x25, 0x0d, 0x46, 0xb9, 0x77, 0x65, 0xd0,
+ 0x19, 0xa5, 0x5a, 0x97, 0xc8, 0xf9, 0x81, 0x4b, 0xfd, 0xb5, 0x38, 0xb9, 0xbc, 0x68, 0x55,
+ 0xac, 0x35, 0x1b, 0xf1, 0xe4
+ };
+
+ /* Test vectors for Keccak-p[1600,12] (12 rounds, TurboSHAKE) */
+ /* Test vector 3: All-zero input for Keccak-p[1600,12] */
+ static const unsigned char keccak_p_12_zero_expected[200] = {
+ 0x17, 0x86, 0xa7, 0xb9, 0x38, 0x54, 0x5e, 0x8e, 0x1e, 0xd0, 0x59, 0xf2, 0x50, 0x6a, 0xcd,
+ 0xd9, 0x35, 0x1f, 0xa9, 0x52, 0xc6, 0xe7, 0xb8, 0x87, 0xc5, 0xe0, 0xe4, 0xcd, 0x67, 0xe0,
+ 0x93, 0x10, 0x45, 0x5a, 0xd9, 0xf2, 0x90, 0xab, 0x33, 0xb0, 0x45, 0x1a, 0xdd, 0xa8, 0x72,
+ 0x2f, 0xa7, 0xe0, 0x9c, 0x2f, 0x67, 0x14, 0xaa, 0x80, 0x37, 0xc5, 0x1d, 0x07, 0x51, 0x00,
+ 0xf5, 0x47, 0xdd, 0x3e, 0xcc, 0x8a, 0x17, 0x0c, 0x31, 0x1d, 0xa3, 0xb3, 0xa0, 0xaa, 0x57,
+ 0x92, 0xa5, 0x86, 0xb5, 0x79, 0x9b, 0xf9, 0xb1, 0xb3, 0x3d, 0x7c, 0x4a, 0xbc, 0x93, 0x67,
+ 0x8a, 0xe6, 0x63, 0x40, 0x87, 0x68, 0x66, 0x25, 0x0e, 0x2e, 0x33, 0x03, 0x6c, 0x5c, 0xda,
+ 0x30, 0xf0, 0xb9, 0x02, 0x12, 0xaa, 0x9c, 0x9f, 0x7a, 0xcf, 0x2b, 0x78, 0x9a, 0x3b, 0x5f,
+ 0x23, 0x79, 0xae, 0x61, 0xe0, 0xc1, 0x36, 0xe5, 0xec, 0x87, 0x3c, 0xb7, 0x18, 0xb6, 0xe9,
+ 0x6d, 0xc2, 0x8a, 0x91, 0x70, 0xf1, 0xd1, 0xbe, 0x2a, 0xb7, 0x24, 0xed, 0xda, 0x53, 0xbd,
+ 0xab, 0x6a, 0x5a, 0xe1, 0x2e, 0x2c, 0x6a, 0x41, 0xc1, 0xbf, 0xaf, 0x52, 0x09, 0xb9, 0x36,
+ 0xe0, 0xcf, 0xc6, 0xd7, 0x60, 0x70, 0xdc, 0x17, 0x36, 0x50, 0x45, 0xe4, 0x7a, 0x9f, 0xc2,
+ 0xb2, 0x11, 0x56, 0x62, 0x7a, 0x64, 0x30, 0x2c, 0xdb, 0x71, 0x36, 0xd4, 0x1c, 0xa0, 0x2c,
+ 0x22, 0x76, 0x0d, 0xfd, 0xcf
+ };
+
+ printf("=== Keccak-1600 Core Function Tests ===\n\n");
+
+ /* Basic API tests */
+ printf("Test 1: API constants\n");
+ printf(" statebytes: %u\n", (unsigned int) crypto_core_keccak1600_statebytes());
+ assert(crypto_core_keccak1600_statebytes() == crypto_core_keccak1600_STATEBYTES);
+ assert(crypto_core_keccak1600_STATEBYTES == 200U);
+ printf(" PASS: statebytes = 200\n\n");
+
+ /* Test 2: Init function */
+ printf("Test 2: crypto_core_keccak1600_init\n");
+ memset(state, 0xFF, sizeof state);
+ crypto_core_keccak1600_init(state);
+ for (i = 0; i < crypto_core_keccak1600_STATEBYTES; i++) {
+ if (state[i] != 0) {
+ printf(" FAIL: State not zeroed at byte %u\n", (unsigned int) i);
+ test_failures++;
+ break;
+ }
+ }
+ if (i == crypto_core_keccak1600_STATEBYTES) {
+ printf(" PASS: State initialized to zeros\n\n");
+ }
+
+ /* Test 3: XOR and extract functions */
+ printf("Test 3: crypto_core_keccak1600_xor_bytes and extract_bytes\n");
+ crypto_core_keccak1600_init(state);
+ unsigned char test_data[64];
+ for (i = 0; i < sizeof test_data; i++) {
+ test_data[i] = (unsigned char) i;
+ }
+ crypto_core_keccak1600_xor_bytes(state, test_data, 0, sizeof test_data);
+ crypto_core_keccak1600_extract_bytes(state, extracted, 0, sizeof test_data);
+ if (memcmp(extracted, test_data, sizeof test_data) == 0) {
+ printf(" PASS: XOR and extract work correctly\n\n");
+ } else {
+ printf(" FAIL: XOR/extract mismatch\n\n");
+ test_failures++;
+ }
+
+ /* Test 4: Keccak-f[1600] with all-zero input (24 rounds) */
+ printf("Test 4: Keccak-f[1600] (24 rounds) - Zero input\n");
+ memcpy(state, keccak_f_1600_zero_input, 200);
+ crypto_core_keccak1600_permute_24(state);
+ test_failures +=
+ compare_states(" Keccak-f[1600] zero", state, keccak_f_1600_zero_expected, 200);
+ printf("\n");
+
+ /* Test 5: Keccak-f[1600] with pattern input (24 rounds) */
+ printf("Test 5: Keccak-f[1600] (24 rounds) - Pattern 0xa3 input\n");
+ memcpy(state, keccak_f_1600_pattern_input, 200);
+ crypto_core_keccak1600_permute_24(state);
+ test_failures +=
+ compare_states(" Keccak-f[1600] pattern", state, keccak_f_1600_pattern_expected, 200);
+ printf("\n");
+
+ /* Test 6: Keccak-p[1600,12] with all-zero input (12 rounds) */
+ printf("Test 6: Keccak-p[1600,12] (12 rounds) - Zero input\n");
+ crypto_core_keccak1600_init(state);
+ crypto_core_keccak1600_permute_12(state);
+ test_failures +=
+ compare_states(" Keccak-p[1600,12] zero", state, keccak_p_12_zero_expected, 200);
+ printf("\n");
+
+ /* Test 7: Verify 12 and 24 rounds produce different outputs */
+ printf("Test 7: Verify 12-round and 24-round differ\n");
+ unsigned char state_12[200], state_24[200];
+ crypto_core_keccak1600_init(state_12);
+ crypto_core_keccak1600_init(state_24);
+ crypto_core_keccak1600_permute_12(state_12);
+ crypto_core_keccak1600_permute_24(state_24);
+
+ int differs = 0;
+ for (i = 0; i < 200; i++) {
+ if (state_12[i] != state_24[i]) {
+ differs = 1;
+ break;
+ }
+ }
+ if (differs) {
+ printf(" PASS: 12-round and 24-round produce different outputs\n");
+ printf(" First difference at byte %u: 12-round=0x%02x, 24-round=0x%02x\n\n",
+ (unsigned int) i, state_12[i], state_24[i]);
+ } else {
+ printf(" FAIL: 12-round and 24-round produce identical outputs\n\n");
+ test_failures++;
+ }
+
+ /* Test 8: Multiple permutations */
+ printf("Test 8: Double permutation consistency\n");
+ crypto_core_keccak1600_init(state);
+ crypto_core_keccak1600_permute_24(state);
+ memcpy(state_24, state, 200);
+ crypto_core_keccak1600_permute_24(state);
+ printf(" After 24+24 rounds: ");
+ print_hex("", state, 32);
+
+ crypto_core_keccak1600_init(state);
+ crypto_core_keccak1600_permute_12(state);
+ memcpy(state_12, state, 200);
+ crypto_core_keccak1600_permute_12(state);
+ printf(" After 12+12 rounds: ");
+ print_hex("", state, 32);
+ printf("\n");
+
+ /* Final summary */
+ printf("=== Test Summary ===\n");
+ if (test_failures == 0) {
+ printf("All tests PASSED!\n");
+ return 0;
+ } else {
+ printf("FAILED: %d test(s) failed\n", test_failures);
+ return 1;
+ }
+}
diff --git a/test/default/core_keccak1600.exp b/test/default/core_keccak1600.exp
new file mode 100644
index 00000000..6660f0db
--- /dev/null
+++ b/test/default/core_keccak1600.exp
@@ -0,0 +1,31 @@
+=== Keccak-1600 Core Function Tests ===
+
+Test 1: API constants
+ statebytes: 200
+ PASS: statebytes = 200
+
+Test 2: crypto_core_keccak1600_init
+ PASS: State initialized to zeros
+
+Test 3: crypto_core_keccak1600_xor_bytes and extract_bytes
+ PASS: XOR and extract work correctly
+
+Test 4: Keccak-f[1600] (24 rounds) - Zero input
+PASS: Keccak-f[1600] zero
+
+Test 5: Keccak-f[1600] (24 rounds) - Pattern 0xa3 input
+PASS: Keccak-f[1600] pattern
+
+Test 6: Keccak-p[1600,12] (12 rounds) - Zero input
+PASS: Keccak-p[1600,12] zero
+
+Test 7: Verify 12-round and 24-round differ
+ PASS: 12-round and 24-round produce different outputs
+ First difference at byte 0: 12-round=0x17, 24-round=0xe7
+
+Test 8: Double permutation consistency
+ After 24+24 rounds: 3ccb6ef94d955c2d6db55770d02c336a6c6bd770128d3d0994d06955b2d9208a
+ After 12+12 rounds: 048cbb36dc66034bc96a2de69835165f46e73b55de051b436c7a6154c9469f48
+
+=== Test Summary ===
+All tests PASSED!
diff --git a/test/default/xof_shake128.c b/test/default/xof_shake128.c
new file mode 100644
index 00000000..072378fe
--- /dev/null
+++ b/test/default/xof_shake128.c
@@ -0,0 +1,134 @@
+
+#define TEST_NAME "xof_shake128"
+#include "cmptest.h"
+
+typedef struct {
+ const unsigned char *msg;
+ size_t msg_len;
+ const unsigned char *out;
+ size_t out_len;
+} testvector;
+
+int
+main(void)
+{
+ /* Test vectors from NIST and various sources */
+ static const unsigned char msg_empty[] = "";
+ static const unsigned char msg_abc[] = { 0x61, 0x62, 0x63 };
+ static const unsigned char msg_fox[] = { 0x54, 0x68, 0x65, 0x20, 0x71, 0x75, 0x69, 0x63, 0x6b,
+ 0x20, 0x62, 0x72, 0x6f, 0x77, 0x6e, 0x20, 0x66, 0x6f,
+ 0x78, 0x20, 0x6a, 0x75, 0x6d, 0x70, 0x73, 0x20, 0x6f,
+ 0x76, 0x65, 0x72, 0x20, 0x74, 0x68, 0x65, 0x20, 0x6c,
+ 0x61, 0x7a, 0x79, 0x20, 0x64, 0x6f, 0x67 };
+
+ static const unsigned char out_empty_32[] = { 0x7f, 0x9c, 0x2b, 0xa4, 0xe8, 0x8f, 0x82, 0x7d,
+ 0x61, 0x60, 0x45, 0x50, 0x76, 0x05, 0x85, 0x3e,
+ 0xd7, 0x3b, 0x80, 0x93, 0xf6, 0xef, 0xbc, 0x88,
+ 0xeb, 0x1a, 0x6e, 0xac, 0xfa, 0x66, 0xef, 0x26 };
+
+ static const unsigned char out_empty_64[] = {
+ 0x7f, 0x9c, 0x2b, 0xa4, 0xe8, 0x8f, 0x82, 0x7d, 0x61, 0x60, 0x45, 0x50, 0x76,
+ 0x05, 0x85, 0x3e, 0xd7, 0x3b, 0x80, 0x93, 0xf6, 0xef, 0xbc, 0x88, 0xeb, 0x1a,
+ 0x6e, 0xac, 0xfa, 0x66, 0xef, 0x26, 0x3c, 0xb1, 0xee, 0xa9, 0x88, 0x00, 0x4b,
+ 0x93, 0x10, 0x3c, 0xfb, 0x0a, 0xee, 0xfd, 0x2a, 0x68, 0x6e, 0x01, 0xfa, 0x4a,
+ 0x58, 0xe8, 0xa3, 0x63, 0x9c, 0xa8, 0xa1, 0xe3, 0xf9, 0xae, 0x57, 0xe2
+ };
+
+ static const unsigned char out_abc_32[] = { 0x58, 0x81, 0x09, 0x2d, 0xd8, 0x18, 0xbf, 0x5c,
+ 0xf8, 0xa3, 0xdd, 0xb7, 0x93, 0xfb, 0xcb, 0xa7,
+ 0x40, 0x97, 0xd5, 0xc5, 0x26, 0xa6, 0xd3, 0x5f,
+ 0x97, 0xb8, 0x33, 0x51, 0x94, 0x0f, 0x2c, 0xc8 };
+
+ static const unsigned char out_fox_32[] = { 0xf4, 0x20, 0x2e, 0x3c, 0x58, 0x52, 0xf9, 0x18,
+ 0x2a, 0x04, 0x30, 0xfd, 0x81, 0x44, 0xf0, 0xa7,
+ 0x4b, 0x95, 0xe7, 0x41, 0x7e, 0xca, 0xe1, 0x7d,
+ 0xb0, 0xf8, 0xcf, 0xee, 0xd0, 0xe3, 0xe6, 0x6e };
+
+ static const unsigned char out_fox_64[] = {
+ 0xf4, 0x20, 0x2e, 0x3c, 0x58, 0x52, 0xf9, 0x18, 0x2a, 0x04, 0x30, 0xfd, 0x81,
+ 0x44, 0xf0, 0xa7, 0x4b, 0x95, 0xe7, 0x41, 0x7e, 0xca, 0xe1, 0x7d, 0xb0, 0xf8,
+ 0xcf, 0xee, 0xd0, 0xe3, 0xe6, 0x6e, 0xb5, 0x58, 0x5e, 0xc6, 0xf8, 0x60, 0x21,
+ 0xca, 0xcf, 0x27, 0x2c, 0x79, 0x8b, 0xcf, 0x97, 0xd3, 0x68, 0xb8, 0x86, 0xb1,
+ 0x8f, 0xec, 0x3a, 0x57, 0x1f, 0x09, 0x60, 0x86, 0xa5, 0x23, 0x71, 0x7a
+ };
+
+ testvector vectors[] = { { msg_empty, 0, out_empty_32, 32 },
+ { msg_empty, 0, out_empty_64, 64 },
+ { msg_abc, 3, out_abc_32, 32 },
+ { msg_fox, 43, out_fox_32, 32 },
+ { msg_fox, 43, out_fox_64, 64 } };
+
+ unsigned char out[256];
+ crypto_xof_shake128_state state;
+ size_t i, j;
+
+ /* Test constants */
+ assert(crypto_xof_shake128_blockbytes() == 168);
+ assert(crypto_xof_shake128_statebytes() == 256);
+ assert(crypto_xof_shake128_domain_standard() == 0x1F);
+
+ /* Test one-shot API */
+ for (i = 0; i < sizeof(vectors) / sizeof(vectors[0]); i++) {
+ crypto_xof_shake128(out, vectors[i].out_len, vectors[i].msg, vectors[i].msg_len);
+ if (memcmp(out, vectors[i].out, vectors[i].out_len) != 0) {
+ printf("Test vector %zu failed (one-shot)\n", i);
+ return 1;
+ }
+ }
+
+ /* Test streaming API */
+ for (i = 0; i < sizeof(vectors) / sizeof(vectors[0]); i++) {
+ crypto_xof_shake128_init(&state);
+ crypto_xof_shake128_update(&state, vectors[i].msg, vectors[i].msg_len);
+ crypto_xof_shake128_final(&state, out, vectors[i].out_len);
+ if (memcmp(out, vectors[i].out, vectors[i].out_len) != 0) {
+ printf("Test vector %zu failed (streaming)\n", i);
+ return 1;
+ }
+ }
+
+ /* Test multiple squeeze calls */
+ crypto_xof_shake128_init(&state);
+ crypto_xof_shake128_update(&state, msg_abc, 3);
+ crypto_xof_shake128_final(&state, out, 16);
+ crypto_xof_shake128_squeeze(&state, out + 16, 16);
+ if (memcmp(out, out_abc_32, 32) != 0) {
+ printf("Multiple squeeze test failed\n");
+ return 1;
+ }
+
+ /* Test custom domain byte produces different output */
+ crypto_xof_shake128_init(&state);
+ crypto_xof_shake128_update(&state, msg_abc, 3);
+ crypto_xof_shake128_final(&state, out, 32);
+
+ crypto_xof_shake128_init_with_domain(&state, 0x99);
+ crypto_xof_shake128_update(&state, msg_abc, 3);
+ crypto_xof_shake128_final(&state, out + 32, 32);
+
+ if (memcmp(out, out + 32, 32) == 0) {
+ printf("Custom domain byte test failed (outputs should differ)\n");
+ return 1;
+ }
+
+ /* Test standard domain constant */
+ crypto_xof_shake128_init_with_domain(&state, crypto_xof_shake128_domain_standard());
+ crypto_xof_shake128_update(&state, msg_abc, 3);
+ crypto_xof_shake128_final(&state, out + 64, 32);
+
+ if (memcmp(out, out + 64, 32) != 0) {
+ printf("Domain constant test failed (should match standard init)\n");
+ return 1;
+ }
+
+ /* Test cannot absorb after squeezing */
+ crypto_xof_shake128_init(&state);
+ crypto_xof_shake128_final(&state, out, 32);
+ if (crypto_xof_shake128_update(&state, msg_abc, 3) == 0) {
+ printf("Should not be able to absorb after squeezing\n");
+ return 1;
+ }
+
+ printf("All SHAKE-128 tests passed\n");
+ return 0;
+}
diff --git a/test/default/xof_shake128.exp b/test/default/xof_shake128.exp
new file mode 100644
index 00000000..bce522cb
--- /dev/null
+++ b/test/default/xof_shake128.exp
@@ -0,0 +1 @@
+All SHAKE-128 tests passed
diff --git a/test/default/xof_shake256.c b/test/default/xof_shake256.c
new file mode 100644
index 00000000..fbbdec7f
--- /dev/null
+++ b/test/default/xof_shake256.c
@@ -0,0 +1,135 @@
+
+#define TEST_NAME "xof_shake256"
+#include "cmptest.h"
+
+typedef struct {
+ const unsigned char *msg;
+ size_t msg_len;
+ const unsigned char *out;
+ size_t out_len;
+} testvector;
+
+int
+main(void)
+{
+ /* Test vectors from NIST FIPS 202 and various sources */
+ static const unsigned char msg_empty[] = "";
+ static const unsigned char msg_abc[] = { 0x61, 0x62, 0x63 };
+ static const unsigned char msg_fox[] = { 0x54, 0x68, 0x65, 0x20, 0x71, 0x75, 0x69, 0x63, 0x6b,
+ 0x20, 0x62, 0x72, 0x6f, 0x77, 0x6e, 0x20, 0x66, 0x6f,
+ 0x78, 0x20, 0x6a, 0x75, 0x6d, 0x70, 0x73, 0x20, 0x6f,
+ 0x76, 0x65, 0x72, 0x20, 0x74, 0x68, 0x65, 0x20, 0x6c,
+ 0x61, 0x7a, 0x79, 0x20, 0x64, 0x6f, 0x67 };
+
+ /* SHAKE-256 test vectors */
+ static const unsigned char out_empty_32[] = { 0x46, 0xb9, 0xdd, 0x2b, 0x0b, 0xa8, 0x8d, 0x13,
+ 0x23, 0x3b, 0x3f, 0xeb, 0x74, 0x3e, 0xeb, 0x24,
+ 0x3f, 0xcd, 0x52, 0xea, 0x62, 0xb8, 0x1b, 0x82,
+ 0xb5, 0x0c, 0x27, 0x64, 0x6e, 0xd5, 0x76, 0x2f };
+
+ static const unsigned char out_empty_64[] = {
+ 0x46, 0xb9, 0xdd, 0x2b, 0x0b, 0xa8, 0x8d, 0x13, 0x23, 0x3b, 0x3f, 0xeb, 0x74,
+ 0x3e, 0xeb, 0x24, 0x3f, 0xcd, 0x52, 0xea, 0x62, 0xb8, 0x1b, 0x82, 0xb5, 0x0c,
+ 0x27, 0x64, 0x6e, 0xd5, 0x76, 0x2f, 0xd7, 0x5d, 0xc4, 0xdd, 0xd8, 0xc0, 0xf2,
+ 0x00, 0xcb, 0x05, 0x01, 0x9d, 0x67, 0xb5, 0x92, 0xf6, 0xfc, 0x82, 0x1c, 0x49,
+ 0x47, 0x9a, 0xb4, 0x86, 0x40, 0x29, 0x2e, 0xac, 0xb3, 0xb7, 0xc4, 0xbe
+ };
+
+ static const unsigned char out_abc_32[] = { 0x48, 0x33, 0x66, 0x60, 0x13, 0x60, 0xa8, 0x77,
+ 0x1c, 0x68, 0x63, 0x08, 0x0c, 0xc4, 0x11, 0x4d,
+ 0x8d, 0xb4, 0x45, 0x30, 0xf8, 0xf1, 0xe1, 0xee,
+ 0x4f, 0x94, 0xea, 0x37, 0xe7, 0x8b, 0x57, 0x39 };
+
+ static const unsigned char out_fox_32[] = { 0x2f, 0x67, 0x13, 0x43, 0xd9, 0xb2, 0xe1, 0x60,
+ 0x4d, 0xc9, 0xdc, 0xf0, 0x75, 0x3e, 0x5f, 0xe1,
+ 0x5c, 0x7c, 0x64, 0xa0, 0xd2, 0x83, 0xcb, 0xbf,
+ 0x72, 0x2d, 0x41, 0x1a, 0x0e, 0x36, 0xf6, 0xca };
+
+ static const unsigned char out_fox_64[] = {
+ 0x2f, 0x67, 0x13, 0x43, 0xd9, 0xb2, 0xe1, 0x60, 0x4d, 0xc9, 0xdc, 0xf0, 0x75,
+ 0x3e, 0x5f, 0xe1, 0x5c, 0x7c, 0x64, 0xa0, 0xd2, 0x83, 0xcb, 0xbf, 0x72, 0x2d,
+ 0x41, 0x1a, 0x0e, 0x36, 0xf6, 0xca, 0x1d, 0x01, 0xd1, 0x36, 0x9a, 0x23, 0x53,
+ 0x9c, 0xd8, 0x0f, 0x7c, 0x05, 0x4b, 0x6e, 0x5d, 0xaf, 0x9c, 0x96, 0x2c, 0xad,
+ 0x5b, 0x8e, 0xd5, 0xbd, 0x11, 0x99, 0x8b, 0x40, 0xd5, 0x73, 0x44, 0x42
+ };
+
+ testvector vectors[] = { { msg_empty, 0, out_empty_32, 32 },
+ { msg_empty, 0, out_empty_64, 64 },
+ { msg_abc, 3, out_abc_32, 32 },
+ { msg_fox, 43, out_fox_32, 32 },
+ { msg_fox, 43, out_fox_64, 64 } };
+
+ unsigned char out[256];
+ crypto_xof_shake256_state state;
+ size_t i;
+
+ /* Test constants */
+ assert(crypto_xof_shake256_blockbytes() == 136);
+ assert(crypto_xof_shake256_statebytes() == 256);
+ assert(crypto_xof_shake256_domain_standard() == 0x1F);
+
+ /* Test one-shot API */
+ for (i = 0; i < sizeof(vectors) / sizeof(vectors[0]); i++) {
+ crypto_xof_shake256(out, vectors[i].out_len, vectors[i].msg, vectors[i].msg_len);
+ if (memcmp(out, vectors[i].out, vectors[i].out_len) != 0) {
+ printf("Test vector %zu failed (one-shot)\n", i);
+ return 1;
+ }
+ }
+
+ /* Test streaming API */
+ for (i = 0; i < sizeof(vectors) / sizeof(vectors[0]); i++) {
+ crypto_xof_shake256_init(&state);
+ crypto_xof_shake256_update(&state, vectors[i].msg, vectors[i].msg_len);
+ crypto_xof_shake256_final(&state, out, vectors[i].out_len);
+ if (memcmp(out, vectors[i].out, vectors[i].out_len) != 0) {
+ printf("Test vector %zu failed (streaming)\n", i);
+ return 1;
+ }
+ }
+
+ /* Test multiple squeeze calls */
+ crypto_xof_shake256_init(&state);
+ crypto_xof_shake256_update(&state, msg_abc, 3);
+ crypto_xof_shake256_final(&state, out, 16);
+ crypto_xof_shake256_squeeze(&state, out + 16, 16);
+ if (memcmp(out, out_abc_32, 32) != 0) {
+ printf("Multiple squeeze test failed\n");
+ return 1;
+ }
+
+ /* Test custom domain byte produces different output */
+ crypto_xof_shake256_init(&state);
+ crypto_xof_shake256_update(&state, msg_abc, 3);
+ crypto_xof_shake256_final(&state, out, 32);
+
+ crypto_xof_shake256_init_with_domain(&state, 0x99);
+ crypto_xof_shake256_update(&state, msg_abc, 3);
+ crypto_xof_shake256_final(&state, out + 32, 32);
+
+ if (memcmp(out, out + 32, 32) == 0) {
+ printf("Custom domain byte test failed (outputs should differ)\n");
+ return 1;
+ }
+
+ /* Test standard domain constant */
+ crypto_xof_shake256_init_with_domain(&state, crypto_xof_shake256_domain_standard());
+ crypto_xof_shake256_update(&state, msg_abc, 3);
+ crypto_xof_shake256_final(&state, out + 64, 32);
+
+ if (memcmp(out, out + 64, 32) != 0) {
+ printf("Domain constant test failed (should match standard init)\n");
+ return 1;
+ }
+
+ /* Test cannot absorb after squeezing */
+ crypto_xof_shake256_init(&state);
+ crypto_xof_shake256_final(&state, out, 32);
+ if (crypto_xof_shake256_update(&state, msg_abc, 3) == 0) {
+ printf("Should not be able to absorb after squeezing\n");
+ return 1;
+ }
+
+ printf("All SHAKE-256 tests passed\n");
+ return 0;
+}
diff --git a/test/default/xof_shake256.exp b/test/default/xof_shake256.exp
new file mode 100644
index 00000000..f9e7f729
--- /dev/null
+++ b/test/default/xof_shake256.exp
@@ -0,0 +1 @@
+All SHAKE-256 tests passed
diff --git a/test/default/xof_turboshake128.c b/test/default/xof_turboshake128.c
new file mode 100644
index 00000000..a5040823
--- /dev/null
+++ b/test/default/xof_turboshake128.c
@@ -0,0 +1,134 @@
+
+#define TEST_NAME "xof_turboshake128"
+#include "cmptest.h"
+
+typedef struct {
+ const unsigned char *msg;
+ size_t msg_len;
+ const unsigned char *out;
+ size_t out_len;
+} testvector;
+
+int
+main(void)
+{
+ /* Test vectors from TurboSHAKE reference implementation */
+ static const unsigned char msg_empty[] = "";
+ static const unsigned char msg_abc[] = { 0x61, 0x62, 0x63 };
+ static const unsigned char msg_fox[] = { 0x54, 0x68, 0x65, 0x20, 0x71, 0x75, 0x69, 0x63, 0x6b,
+ 0x20, 0x62, 0x72, 0x6f, 0x77, 0x6e, 0x20, 0x66, 0x6f,
+ 0x78, 0x20, 0x6a, 0x75, 0x6d, 0x70, 0x73, 0x20, 0x6f,
+ 0x76, 0x65, 0x72, 0x20, 0x74, 0x68, 0x65, 0x20, 0x6c,
+ 0x61, 0x7a, 0x79, 0x20, 0x64, 0x6f, 0x67 };
+
+ static const unsigned char out_empty_32[] = { 0x86, 0x8c, 0xbd, 0x53, 0xb0, 0x78, 0x20, 0x5a,
+ 0xbb, 0x85, 0x81, 0x5d, 0x94, 0x1f, 0x7d, 0x03,
+ 0x76, 0xbf, 0xf5, 0xb8, 0x88, 0x8a, 0x6a, 0x2d,
+ 0x03, 0x48, 0x3a, 0xfb, 0xaf, 0x83, 0x96, 0x7f };
+
+ static const unsigned char out_empty_64[] = {
+ 0x86, 0x8c, 0xbd, 0x53, 0xb0, 0x78, 0x20, 0x5a, 0xbb, 0x85, 0x81, 0x5d, 0x94,
+ 0x1f, 0x7d, 0x03, 0x76, 0xbf, 0xf5, 0xb8, 0x88, 0x8a, 0x6a, 0x2d, 0x03, 0x48,
+ 0x3a, 0xfb, 0xaf, 0x83, 0x96, 0x7f, 0x22, 0x6e, 0x2c, 0xad, 0x5e, 0x7b, 0x1e,
+ 0xc4, 0xca, 0x72, 0x23, 0x6f, 0x07, 0x64, 0x62, 0x19, 0x9f, 0xea, 0x48, 0xc9,
+ 0x34, 0x38, 0xad, 0x4c, 0x49, 0xc7, 0x67, 0xf9, 0x41, 0x7b, 0xe7, 0xc5
+ };
+
+ static const unsigned char out_abc_32[] = { 0x59, 0xcc, 0xfc, 0x22, 0xa3, 0xb8, 0x47, 0x42,
+ 0x58, 0x6b, 0x41, 0xf5, 0x1f, 0x8a, 0x94, 0x73,
+ 0x8d, 0xd0, 0x2b, 0xc7, 0x45, 0x51, 0xeb, 0x0e,
+ 0xf5, 0x0f, 0xc4, 0x09, 0x4e, 0xb0, 0xfc, 0x7b };
+
+ static const unsigned char out_fox_32[] = { 0x6f, 0x16, 0x24, 0x47, 0xdd, 0xd3, 0x30, 0xc8,
+ 0xee, 0x8b, 0x21, 0x89, 0x88, 0xca, 0x1b, 0xef,
+ 0x35, 0xd9, 0x02, 0xa5, 0xfd, 0x6b, 0xaa, 0xf3,
+ 0x44, 0x20, 0x48, 0x32, 0x26, 0xa1, 0x72, 0x4a };
+
+ static const unsigned char out_fox_64[] = {
+ 0x6f, 0x16, 0x24, 0x47, 0xdd, 0xd3, 0x30, 0xc8, 0xee, 0x8b, 0x21, 0x89, 0x88,
+ 0xca, 0x1b, 0xef, 0x35, 0xd9, 0x02, 0xa5, 0xfd, 0x6b, 0xaa, 0xf3, 0x44, 0x20,
+ 0x48, 0x32, 0x26, 0xa1, 0x72, 0x4a, 0xb9, 0x02, 0xc6, 0x85, 0x7e, 0xbd, 0x0b,
+ 0xa1, 0x76, 0x00, 0xdf, 0x9e, 0xe4, 0x9a, 0x06, 0x18, 0x03, 0x36, 0x92, 0x2d,
+ 0x9b, 0x61, 0x80, 0x7e, 0x8f, 0xc8, 0x03, 0xec, 0xb0, 0x1a, 0x81, 0xf9
+ };
+
+ testvector vectors[] = { { msg_empty, 0, out_empty_32, 32 },
+ { msg_empty, 0, out_empty_64, 64 },
+ { msg_abc, 3, out_abc_32, 32 },
+ { msg_fox, 43, out_fox_32, 32 },
+ { msg_fox, 43, out_fox_64, 64 } };
+
+ unsigned char out[256];
+ crypto_xof_turboshake128_state state;
+ size_t i;
+
+ /* Test constants */
+ assert(crypto_xof_turboshake128_blockbytes() == 168);
+ assert(crypto_xof_turboshake128_statebytes() == 256);
+ assert(crypto_xof_turboshake128_domain_standard() == 0x01);
+
+ /* Test one-shot API */
+ for (i = 0; i < sizeof(vectors) / sizeof(vectors[0]); i++) {
+ crypto_xof_turboshake128(out, vectors[i].out_len, vectors[i].msg, vectors[i].msg_len);
+ if (memcmp(out, vectors[i].out, vectors[i].out_len) != 0) {
+ printf("Test vector %zu failed (one-shot)\n", i);
+ return 1;
+ }
+ }
+
+ /* Test streaming API */
+ for (i = 0; i < sizeof(vectors) / sizeof(vectors[0]); i++) {
+ crypto_xof_turboshake128_init(&state);
+ crypto_xof_turboshake128_update(&state, vectors[i].msg, vectors[i].msg_len);
+ crypto_xof_turboshake128_final(&state, out, vectors[i].out_len);
+ if (memcmp(out, vectors[i].out, vectors[i].out_len) != 0) {
+ printf("Test vector %zu failed (streaming)\n", i);
+ return 1;
+ }
+ }
+
+ /* Test multiple squeeze calls */
+ crypto_xof_turboshake128_init(&state);
+ crypto_xof_turboshake128_update(&state, msg_abc, 3);
+ crypto_xof_turboshake128_final(&state, out, 16);
+ crypto_xof_turboshake128_squeeze(&state, out + 16, 16);
+ if (memcmp(out, out_abc_32, 32) != 0) {
+ printf("Multiple squeeze test failed\n");
+ return 1;
+ }
+
+ /* Test custom domain byte produces different output */
+ crypto_xof_turboshake128_init(&state);
+ crypto_xof_turboshake128_update(&state, msg_abc, 3);
+ crypto_xof_turboshake128_final(&state, out, 32);
+
+ crypto_xof_turboshake128_init_with_domain(&state, 0x99);
+ crypto_xof_turboshake128_update(&state, msg_abc, 3);
+ crypto_xof_turboshake128_final(&state, out + 32, 32);
+
+ if (memcmp(out, out + 32, 32) == 0) {
+ printf("Custom domain byte test failed (outputs should differ)\n");
+ return 1;
+ }
+
+ /* Test standard domain constant */
+ crypto_xof_turboshake128_init_with_domain(&state, crypto_xof_turboshake128_domain_standard());
+ crypto_xof_turboshake128_update(&state, msg_abc, 3);
+ crypto_xof_turboshake128_final(&state, out + 64, 32);
+
+ if (memcmp(out, out + 64, 32) != 0) {
+ printf("Domain constant test failed (should match standard init)\n");
+ return 1;
+ }
+
+ /* Test cannot absorb after squeezing */
+ crypto_xof_turboshake128_init(&state);
+ crypto_xof_turboshake128_final(&state, out, 32);
+ if (crypto_xof_turboshake128_update(&state, msg_abc, 3) == 0) {
+ printf("Should not be able to absorb after squeezing\n");
+ return 1;
+ }
+
+ printf("All TurboSHAKE-128 tests passed\n");
+ return 0;
+}
diff --git a/test/default/xof_turboshake128.exp b/test/default/xof_turboshake128.exp
new file mode 100644
index 00000000..12233c5f
--- /dev/null
+++ b/test/default/xof_turboshake128.exp
@@ -0,0 +1 @@
+All TurboSHAKE-128 tests passed
diff --git a/test/default/xof_turboshake256.c b/test/default/xof_turboshake256.c
new file mode 100644
index 00000000..68420006
--- /dev/null
+++ b/test/default/xof_turboshake256.c
@@ -0,0 +1,134 @@
+
+#define TEST_NAME "xof_turboshake256"
+#include "cmptest.h"
+
+typedef struct {
+ const unsigned char *msg;
+ size_t msg_len;
+ const unsigned char *out;
+ size_t out_len;
+} testvector;
+
+int
+main(void)
+{
+ /* Test vectors from TurboSHAKE reference implementation */
+ static const unsigned char msg_empty[] = "";
+ static const unsigned char msg_abc[] = { 0x61, 0x62, 0x63 };
+ static const unsigned char msg_fox[] = { 0x54, 0x68, 0x65, 0x20, 0x71, 0x75, 0x69, 0x63, 0x6b,
+ 0x20, 0x62, 0x72, 0x6f, 0x77, 0x6e, 0x20, 0x66, 0x6f,
+ 0x78, 0x20, 0x6a, 0x75, 0x6d, 0x70, 0x73, 0x20, 0x6f,
+ 0x76, 0x65, 0x72, 0x20, 0x74, 0x68, 0x65, 0x20, 0x6c,
+ 0x61, 0x7a, 0x79, 0x20, 0x64, 0x6f, 0x67 };
+
+ static const unsigned char out_empty_32[] = { 0xe3, 0xdd, 0x2d, 0xf0, 0x94, 0x3b, 0xde, 0x6d,
+ 0x82, 0xe3, 0x9e, 0xc3, 0x60, 0x59, 0xf3, 0x5c,
+ 0xd7, 0x67, 0x20, 0xe2, 0xdf, 0x38, 0xcc, 0x6b,
+ 0x10, 0xb6, 0x9f, 0xdd, 0xfc, 0xaa, 0x3a, 0x4a };
+
+ static const unsigned char out_empty_64[] = {
+ 0xe3, 0xdd, 0x2d, 0xf0, 0x94, 0x3b, 0xde, 0x6d, 0x82, 0xe3, 0x9e, 0xc3, 0x60,
+ 0x59, 0xf3, 0x5c, 0xd7, 0x67, 0x20, 0xe2, 0xdf, 0x38, 0xcc, 0x6b, 0x10, 0xb6,
+ 0x9f, 0xdd, 0xfc, 0xaa, 0x3a, 0x4a, 0x72, 0xfb, 0xbb, 0xe4, 0x2c, 0x00, 0xce,
+ 0xd7, 0xaa, 0x88, 0xe2, 0x6d, 0x46, 0x75, 0xdd, 0x6e, 0x2c, 0x43, 0xc4, 0x41,
+ 0x3c, 0x4e, 0xa4, 0xd4, 0x4b, 0xb1, 0x70, 0xf0, 0x3a, 0x98, 0x1c, 0xab
+ };
+
+ static const unsigned char out_abc_32[] = { 0x88, 0xfb, 0x36, 0x9d, 0x5d, 0x85, 0x6b, 0x22,
+ 0xcc, 0xe4, 0xd6, 0xa2, 0x40, 0x56, 0x60, 0x0b,
+ 0xa7, 0x27, 0x44, 0xcd, 0xb3, 0x26, 0x37, 0x49,
+ 0x07, 0x91, 0xcc, 0xd9, 0x85, 0x3b, 0xc9, 0x14 };
+
+ static const unsigned char out_fox_32[] = { 0xe9, 0x17, 0xad, 0xfe, 0x65, 0x54, 0x6d, 0x28,
+ 0xa1, 0x64, 0x57, 0x61, 0x07, 0xe5, 0xd4, 0x77,
+ 0x4d, 0x46, 0x64, 0x42, 0xc5, 0xe8, 0x86, 0xf1,
+ 0xb8, 0xc9, 0xee, 0xab, 0x5d, 0x3f, 0xbf, 0xa8 };
+
+ static const unsigned char out_fox_64[] = {
+ 0xe9, 0x17, 0xad, 0xfe, 0x65, 0x54, 0x6d, 0x28, 0xa1, 0x64, 0x57, 0x61, 0x07,
+ 0xe5, 0xd4, 0x77, 0x4d, 0x46, 0x64, 0x42, 0xc5, 0xe8, 0x86, 0xf1, 0xb8, 0xc9,
+ 0xee, 0xab, 0x5d, 0x3f, 0xbf, 0xa8, 0x96, 0x53, 0xea, 0xd9, 0x8b, 0x2a, 0x52,
+ 0x05, 0x78, 0x38, 0x9b, 0x24, 0xeb, 0xab, 0x8f, 0xcf, 0xe9, 0x12, 0x3e, 0x71,
+ 0x42, 0x1a, 0x14, 0xfb, 0xe2, 0x4e, 0x13, 0xe6, 0x27, 0x31, 0x3a, 0xa1
+ };
+
+ testvector vectors[] = { { msg_empty, 0, out_empty_32, 32 },
+ { msg_empty, 0, out_empty_64, 64 },
+ { msg_abc, 3, out_abc_32, 32 },
+ { msg_fox, 43, out_fox_32, 32 },
+ { msg_fox, 43, out_fox_64, 64 } };
+
+ unsigned char out[256];
+ crypto_xof_turboshake256_state state;
+ size_t i;
+
+ /* Test constants */
+ assert(crypto_xof_turboshake256_blockbytes() == 136);
+ assert(crypto_xof_turboshake256_statebytes() == 256);
+ assert(crypto_xof_turboshake256_domain_standard() == 0x01);
+
+ /* Test one-shot API */
+ for (i = 0; i < sizeof(vectors) / sizeof(vectors[0]); i++) {
+ crypto_xof_turboshake256(out, vectors[i].out_len, vectors[i].msg, vectors[i].msg_len);
+ if (memcmp(out, vectors[i].out, vectors[i].out_len) != 0) {
+ printf("Test vector %zu failed (one-shot)\n", i);
+ return 1;
+ }
+ }
+
+ /* Test streaming API */
+ for (i = 0; i < sizeof(vectors) / sizeof(vectors[0]); i++) {
+ crypto_xof_turboshake256_init(&state);
+ crypto_xof_turboshake256_update(&state, vectors[i].msg, vectors[i].msg_len);
+ crypto_xof_turboshake256_final(&state, out, vectors[i].out_len);
+ if (memcmp(out, vectors[i].out, vectors[i].out_len) != 0) {
+ printf("Test vector %zu failed (streaming)\n", i);
+ return 1;
+ }
+ }
+
+ /* Test multiple squeeze calls */
+ crypto_xof_turboshake256_init(&state);
+ crypto_xof_turboshake256_update(&state, msg_abc, 3);
+ crypto_xof_turboshake256_final(&state, out, 16);
+ crypto_xof_turboshake256_squeeze(&state, out + 16, 16);
+ if (memcmp(out, out_abc_32, 32) != 0) {
+ printf("Multiple squeeze test failed\n");
+ return 1;
+ }
+
+ /* Test custom domain byte produces different output */
+ crypto_xof_turboshake256_init(&state);
+ crypto_xof_turboshake256_update(&state, msg_abc, 3);
+ crypto_xof_turboshake256_final(&state, out, 32);
+
+ crypto_xof_turboshake256_init_with_domain(&state, 0x99);
+ crypto_xof_turboshake256_update(&state, msg_abc, 3);
+ crypto_xof_turboshake256_final(&state, out + 32, 32);
+
+ if (memcmp(out, out + 32, 32) == 0) {
+ printf("Custom domain byte test failed (outputs should differ)\n");
+ return 1;
+ }
+
+ /* Test standard domain constant */
+ crypto_xof_turboshake256_init_with_domain(&state, crypto_xof_turboshake256_domain_standard());
+ crypto_xof_turboshake256_update(&state, msg_abc, 3);
+ crypto_xof_turboshake256_final(&state, out + 64, 32);
+
+ if (memcmp(out, out + 64, 32) != 0) {
+ printf("Domain constant test failed (should match standard init)\n");
+ return 1;
+ }
+
+ /* Test cannot absorb after squeezing */
+ crypto_xof_turboshake256_init(&state);
+ crypto_xof_turboshake256_final(&state, out, 32);
+ if (crypto_xof_turboshake256_update(&state, msg_abc, 3) == 0) {
+ printf("Should not be able to absorb after squeezing\n");
+ return 1;
+ }
+
+ printf("All TurboSHAKE-256 tests passed\n");
+ return 0;
+}
diff --git a/test/default/xof_turboshake256.exp b/test/default/xof_turboshake256.exp
new file mode 100644
index 00000000..1c8fc7b0
--- /dev/null
+++ b/test/default/xof_turboshake256.exp
@@ -0,0 +1 @@
+All TurboSHAKE-256 tests passed