Commit Graph
2082 Commits
Author SHA1 Message Date
Frank Denis 5357d3c6cf nsec isn't used 2025-12-08 15:59:11 +01:00
Frank Denis 468646cef2 MSVC compat 2025-12-08 15:35:40 +01:00
Frank Denis d1f92fc5b7 dynamic -> static 2025-12-08 15:33:35 +01:00
Frank Denis 70e453b870 MSVC compat 2025-12-08 15:25:15 +01:00
Frank Denis 22f9b38d39 Import ipcrypt 2025-12-08 23:15:08 +01:00
Frank Denis be8e2275ca Add ipcrypt support 2025-12-08 23:08:08 +01:00
Frank Denis 0f60c6e0f4 Expand softaes 2025-12-08 23:00:08 +01:00
Frank Denis 6a892675bc SHAKE: if the rate is exactly full, process that block before padding 2025-11-26 23:00:42 +01:00
Frank Denis 37e4f5860b SHAKE: align default separator and test vectors with Zig
And remove redundant macros
2025-11-18 12:10:59 +01:00
Frank Denis ca3acebf8f XOF: don't absorb/squeeze bytes one by one 2025-11-18 11:46:34 +01:00
Frank Denis 7c70a2807e XOF: use size_t internally, unsigned long long externally 2025-11-18 12:07:59 +01:00
Frank Denis d11e907107 Remove crypto_xof_*_final 2025-11-18 12:00:59 +01:00
Frank Denis 0a9450c679 Add SHAKE and TurboSHAKE 2025-10-18 11:31:29 +02:00
Frank Denis 09e995c0c8 Relax ((nonnull)) attributes where applicable
Reported by @stef -- Thanks!

Fixes #1477
2025-09-12 23:07:20 +02:00
Frank Denis e6d6321ab5 More optblockers.
- ristretto255_is_canonical
- fe25519_reduce64
- ge25519_from_uniform
2025-08-27 20:33:07 +02:00
Frank Denis 59b8ba3573 Include <threads.h> if it exists 2025-07-30 23:04:45 +02:00
Frank Denis 4f21b2f4af Remove duplicate include 2025-07-30 23:03:45 +02:00
Frank Denis d537f3010a Improve AES256-GCM performance on ARM 2025-05-21 23:11:26 +02:00
Frank Denis 8466abb280 Reorder arguments to vaeseq_u8 to improve AArch64 performance
The register arguments to the AESE instruction are commutative, however
the first input register is constrained in that it also names the output
register. The constraint on register allocation causes recent LLVM
versions to emit a lot of MOV instructions, significantly impacting
performance.

Swapping the register operands allows the compiler to emit significantly
fewer MOV instructions. This change improves performance on Arm
infrastructure micro-architectures by 14-36% depending on the
micro-architecture

Found and reported by George Steed from ARM. Thanks!
2025-05-21 23:04:26 +02:00
Frank Denis d67b1e8f8d Nits 2025-04-30 01:41:32 +02:00
Frank Denis 72fdf1b86c MSC_VER -> _MSC_VER 2025-04-22 11:33:28 +02:00
Frank Denis 59a98bc7f9 <stdio.h> shouldn't be required 2025-01-26 23:02:41 +01:00
Frank Denis b6bfaf5ab9 Check that __cpuid() is not a macro 2025-01-19 13:37:01 +01:00
Frank Denis 584f61dcd4 Use uint64_t sizes in aegis*_mac()
No-op in libsodium for now, but useful if we introduce a streaming
API later.
2024-12-04 17:22:07 +01:00
Frank Denis 985ad65bfb Remove a non-constant modulo operation in argon2
Adapted from a change originally written by @Sc00bz
2024-11-09 13:24:26 +01:00
Frank Denis cd92e5cfc8 Sync softaes with libaegis 2024-10-23 22:10:27 +02:00
Frank Denis 0c1a25e9d1 Use an optblocker in crypto_verify_n() 2024-10-23 19:58:33 +02:00
Frank Denis 51d2455cd8 Decrement and shift in separate steps 2024-10-23 19:51:10 +02:00
Frank Denis d0eb23e532 Add assembly versions of equal() and negative() 2024-10-23 19:24:13 +02:00
Frank Denis d6dd9c3ce0 More optblocker usage 2024-10-23 19:08:20 +02:00
Frank Denis b1f9c53875 Add another optblocker 2024-10-23 18:42:48 +02:00
Frank Denis 7154fb9041 randombytes_internal_random.c: move clang target attribute down
Specifically, move it after the system includes.

This appears to address an issue with clang 18 when cross-compiling
to windows.

Fixes #1413
2024-09-26 21:59:59 +02:00
Frank Denis beec06eb46 Revert "RFC9381 ECVRF implementation (#1188)"
This reverts commit 7978205916.
2024-09-25 21:37:31 +02:00
mschwarzlandFrank Denis 1012bbc380 Support for Cloudflare Workers for javascript_stir (#1401)
* Support for Cloudflare Workers for javascript_stir

* Ramove debugging comment

---------

Co-authored-by: Frank Denis <124872+jedisct1@users.noreply.github.com>
2024-08-13 21:40:10 +02:00
Frank Denis 6edcd85169 Add another optblocker 2024-08-01 14:32:16 +02:00
Frank Denis 92611e300d Start introducing optblockers to prevent unwanted conditional jumps 2024-08-01 14:25:32 +02:00
Frank Denis 633f922791 Indent 2024-08-01 13:56:57 +02:00
SeungHwan Hur e1861bb935 help MSVC optimize ROL/ROR functions (#1392) 2024-08-01 13:55:04 +02:00
Frank Denis 4a15ab7cd0 fe25519_{abs,cneg} require a single argument
They were always used with the same input and output pointers,
so their definition can be simplified.

Fixes #1376
2024-05-30 16:06:56 +02:00
Frank Denis 704e97fdf5 Proper zeroization in hkdf
Fixes #1375
2024-05-30 15:56:54 +02:00
Iñigo Querejeta AzurmendiandFrank Denis 7978205916 RFC9381 ECVRF implementation (#1188)
* Version 12 of ECVRF

* Incorrect ordering of function inputs

* Identation and notation

* single multiscalar multiplication function

Also changed the style of tests, where the expected output is in vrf.exp rather than in test data (following the style of the hashing).

* declarations inside the if code block

* identation of test_data

* Rename to RFC9381

* Move declarations to top of block

* Check small order over deserialised PK

* Include from_string functions in ed25519_ref10

* Update quirks.h

---------

Co-authored-by: Frank Denis <124872+jedisct1@users.noreply.github.com>
2024-05-25 18:55:14 +02:00
Frank Denis a67325c42c AEGIS: improve performance of AD absorption on x86_64
No apparent regression on other platforms.

Adapted from libaegis.
2024-05-25 00:41:08 +02:00
Frank Denis 4ad956470f Explicitly enabling evex512 is now required with LLVM 18 2024-05-09 22:27:45 +02:00
Frank Denis da0ce565d2 Use clang pragmas to enable features rather than depend on compiler settings 2024-04-27 23:05:38 +02:00
Frank Denis edb94a99a6 Remove redundant definition 2024-04-26 13:50:40 +02:00
Andrzej Fiedukowicz b564794edd Move includes in crypto_onetimeauth_poly1305.h outside of extern C (#1345)
Includes being outside of `extern "C"` are de-facto standard in all other include files of libsodium.

At the same time, having inside the `extern "C"` is causing problem with C++ vs. C toolchain being confused about which libraries should be linked. This was especially painful while working on `swift-sodium` integration with windows.
2024-01-17 15:06:11 +01:00
Frank Denis 4c56848dcc When using MSVC on aarch64, __ARM_ARCH is not defined
Reported by RADDI.net -- Thanks!
2024-01-07 16:14:21 +01:00
Frank Denis 44b99c5a23 Add forgotten crypto_kdf_hkdf_sha512_statebytes() 2023-11-29 22:02:37 +01:00
Frank Denis 39184b5b96 Include argon2id in crypto_pwhash_primitive()
Fixes #1331
2023-11-10 12:12:02 +01:00
Frank Denis b5eaa810c8 Revert "Include argon2id in crypto_pwhash_primitive()"
This reverts commit a2b12dfcc0.
2023-11-10 12:10:10 +01:00