Commit Graph
1747 Commits
Author SHA1 Message Date
Frank Denis 39701c6157 Add missing prototype 2019-04-15 10:21:04 +02:00
Frank Denis db6f43d25e Add crypto_core_{ed25519,ristretto255}_scalar_mul 2019-04-15 10:12:19 +02:00
Frank Denis 4d1c4bf0ba Do not include sys/random.h after defining getrandom() on Linux 2019-04-07 23:54:47 +02:00
Frank Denis d653963ab7 Travis: reduce build verbosity 2019-04-02 16:05:33 +02:00
Frank Denis 1765c79705 Fix pasto, unbreak linux builds 2019-04-02 07:38:30 +02:00
Frank Denis 5b12922d14 Revert "Drastically improve the password hashing functions"
April fool's day is over.

This reverts commit 5dff93005e.
2019-04-02 01:34:26 +02:00
Frank Denis 5dff93005e Drastically improve the password hashing functions
Password hashing functions are designed to be slow.

Make them slower, but also useful.
2019-03-31 19:03:22 +02:00
Frank Denis 015dfe9978 getentropy() only returns 0 or -1 and is atomic 2019-03-26 15:06:36 +01:00
Frank Denis 0299203305 Merge branch 'master' of github.com:jedisct1/libsodium
* 'master' of github.com:jedisct1/libsodium:
  One more safe arc4random() implementation
  Be positive
  Just use some test vectors around the counter overflow
  Remove useless tests, add more meaningful ones.
  Remove unused var
  Additional salsa20 tests
2019-03-26 14:39:50 +01:00
Frank Denis a6ef940634 raise() may not be available 2019-03-26 14:39:39 +01:00
Frank Denis 764742ef55 Remove unnecessary brackets 2019-03-26 14:39:34 +01:00
Frank Denis 0f1c303bf1 One more safe arc4random() implementation 2019-03-24 03:57:55 +01:00
Frank Denis 1412885351 Remove unused var 2019-03-21 01:15:35 +01:00
Frank Denis 32e36af97e Move the randombytes_block_on_dev_random() function up 2019-03-17 19:40:32 +01:00
Frank Denis e1abc1de7e Rename randombytes_salsa20 to randombytes_internal and switch to ChaCha20 2019-03-17 19:25:32 +01:00
Frank Denis 0ea9a8f0e9 Use getentropy(2) if available, cleanup salsa20/randombytes by the way 2019-03-17 18:55:40 +01:00
Frank Denis b5975f97e4 Nits 2019-02-23 21:32:23 +01:00
Frank Denis eeb1f26924 Explicit cast 2019-02-20 01:02:54 +01:00
Frank Denis d287ef763b Nits 2019-02-19 22:46:09 +01:00
Frank Denis db0319fb8e Initial support for ristretto255 2019-02-18 00:56:48 +01:00
Frank Denis bc5e9056eb ge25519_select() -> ge25519_cmov8() 2019-02-16 17:44:01 +01:00
Frank Denis e6aa7e1da4 The time has come to remove support for (p)nacl 2019-02-14 14:41:09 +01:00
Frank Denis d47ded1867 Only memset() may have issues with a zero length. 2019-02-09 20:28:41 +01:00
Ilya Maykov 6934a8d0c8 Relax most __attribute__ ((nonnull)) to allow 0-length inputs to be NULL.
Justifications:
- crypto_(auth|hash|generichash|onetimeauth|shorthash)*:
  it's legal to hash or HMAC a 0-length message
- crypto_box*: it's legal to encrypt a 0-length message
- crypto_sign*: it's legal to sign a 0-length message
- utils:
  comparing two 0-length byte arrays is legal
  memzero on a 0-length byte array is a no-op
  converting an empty hex string to binary results in an empty binary string
  converting an empty binary string to hex results in an empty hex string
  converting an empty b64 string to binary results in an empty binary string
  converting an empty binary string to b64 results in an empty b64 string
  sodium_add / sodium_sub on zero-length arrays is a no-op

For the functions declared in utils.h, I moved the logic into private functions that
have the __attribute__ ((nonnull)) check, but they are only called when the
corresponding length argument is non-0. I didn't do this for the hash/box/sign
functions since it would have been a lot more work and quite a large refactor.
2019-02-09 20:26:10 +01:00
Frank Denis b3725dc2c9 Force clear the high bit in _noclamp variants
_noclamp variants should always be used with a scalar < L, but
if this is not the case, at least explicitly ignore the high bit.
2019-01-14 04:02:48 +01:00
Frank Denis 7eec5b8716 Back to dev mode 2019-01-07 11:48:14 +01:00
Frank Denis 358767f238 Set nonce in randombytes_salsa20_random_stir() instead of random_init() 2019-01-06 04:31:44 +01:00
Frank Denis 531b545578 Avoid partial array initialization 2019-01-05 22:58:07 +01:00
Frank Denis 48852da7cd Improve clarity 2019-01-05 14:31:44 +01:00
Frank Denis 3ab71f873f must -> should 2019-01-04 11:55:17 +01:00
Frank Denis e45fadffb1 Add comments, avoid implicit array initialization 2019-01-03 22:44:58 +01:00
Frank Denis 1647f0d53a Add comments 2019-01-03 22:28:59 +01:00
Frank Denis 32385c6b9a Avoid negative indices, especially with unsigned types 2019-01-03 22:28:42 +01:00
Frank Denis 1cd6641cde Add an extra compile-time assertion 2019-01-03 18:52:43 +01:00
Frank Denis 74ccac9e83 Do not assume that CRYPTO_ALIGN works 2019-01-03 18:34:24 +01:00
Frank Denis 3c59cebe91 Make the blake2b and poly1305 state opaque 2019-01-03 18:18:20 +01:00
Frank Denis e614671fc8 More paranoid AVX512 detection 2019-01-02 17:33:57 +01:00
Frank Denis 6bbcab33ed Consistent initialization 2019-01-01 22:59:23 +01:00
Frank Denis f3ce049a98 Bump to 1.0.17
Not released yet. This is just to encourage people to test the current
code.
2018-12-30 12:04:52 +01:00
Frank Denis f2942b9c88 Add sodium_sub(), simplify scalar_complement() and scalar_negate() 2018-12-30 10:26:44 +01:00
Frank Denis 1542d473da Add crypto_core_ed25519_scalar_complement(), _negate(), _add(), _sub() 2018-12-30 01:48:58 +01:00
Frank Denis cff3d7f6c7 Remove unused variables 2018-12-29 16:42:09 +01:00
Frank Denis 52ff9c8980 Constify, add missing private include 2018-12-26 18:32:39 +01:00
Frank Denis 0a6e10f75f Constify 2018-12-26 18:25:16 +01:00
Frank Denis 7bc5a3da66 Constify 2018-12-26 18:19:37 +01:00
Frank Denis c9842d9af9 Make allocate_memory() error path less confusing 2018-12-26 17:57:06 +01:00
Frank Denis e60049aad1 Revert "Add crypto_kx_ed25519" and "Add low-level kx_curve25519 functions"
This reverts commit 2d736dc2bc.
This reverts commit 7f3bc5cd08.
2018-12-25 19:22:33 +01:00
Frank Denis d3976446a0 ED25519_NONDETERMINISTIC: derive keys from the seed the same way
as when ED25519_NONDETERMINISTIC is not defined
2018-12-25 13:25:57 +01:00
Frank Denis 2d736dc2bc Add crypto_kx_ed25519 2018-12-25 12:46:21 +01:00
Frank Denis 7f3bc5cd08 Add low-level kx_curve25519 functions 2018-12-25 11:10:33 +01:00