SHAKE: if the rate is exactly full, process that block before padding

This commit is contained in:
Frank Denis
2025-11-26 23:00:42 +01:00
parent 9b161dccfa
commit 6a892675bc
4 changed files with 24 additions and 0 deletions
@@ -56,6 +56,12 @@ shake128_finalize(shake128_state_internal *state)
{
unsigned char pad;
/* If the rate is exactly full, process that block before padding */
if (state->offset == SHAKE128_RATE) {
crypto_core_keccak1600_permute_24(state->state);
state->offset = 0;
}
/* Apply padding: domain byte at current position, 0x80 at last byte */
if (state->offset == SHAKE128_RATE - 1) {
/* Special case: padding fits in one byte */
@@ -56,6 +56,12 @@ shake256_finalize(shake256_state_internal *state)
{
unsigned char pad;
/* If the rate is exactly full, process that block before padding */
if (state->offset == SHAKE256_RATE) {
crypto_core_keccak1600_permute_24(state->state);
state->offset = 0;
}
/* Apply padding: domain byte at current position, 0x80 at last byte */
if (state->offset == SHAKE256_RATE - 1) {
/* Special case: padding fits in one byte */
@@ -56,6 +56,12 @@ turboshake128_finalize(turboshake128_state_internal *state)
{
unsigned char pad;
/* If the rate is exactly full, process that block before padding */
if (state->offset == TURBOSHAKE128_RATE) {
crypto_core_keccak1600_permute_12(state->state);
state->offset = 0;
}
/* Apply padding: domain byte at current position, 0x80 at last byte */
if (state->offset == TURBOSHAKE128_RATE - 1) {
/* Special case: padding fits in one byte */
@@ -56,6 +56,12 @@ turboshake256_finalize(turboshake256_state_internal *state)
{
unsigned char pad;
/* If the rate is exactly full, process that block before padding */
if (state->offset == TURBOSHAKE256_RATE) {
crypto_core_keccak1600_permute_12(state->state);
state->offset = 0;
}
/* Apply padding: domain byte at current position, 0x80 at last byte */
if (state->offset == TURBOSHAKE256_RATE - 1) {
/* Special case: padding fits in one byte */