Frank Denis
95983d4471
Don't downcast size_t to int
2015-05-02 10:56:03 +02:00
Frank Denis
3117ccf358
Use memcpy() instead of ugly casts. No changes to compiled code.
2015-04-24 13:52:56 +02:00
Frank Denis
957a29c469
salsa20_random_buf(): mix the output size with the key
2015-04-23 00:09:17 +02:00
Frank Denis
70487753ee
JS target: window.crypto is not defined in webworkers; use self.crypto instead.
2015-04-20 14:26:27 +02:00
Frank Denis
575ce93058
+ crypto_box_seal()
2015-04-17 01:01:32 +02:00
Frank Denis
f740cb5968
Better separation between crypto_auth[_verify] and the NIST-like API.
2015-04-05 20:14:21 +02:00
Frank Denis
dbcca2a501
Don't divide by zero if sodium_allocarray() is called with count=0
2015-03-23 21:43:27 +01:00
Frank Denis
9d5c067ad2
Use getrandom(2) on Linux, if available.
2015-03-09 17:22:34 +01:00
Frank Denis
ceb72f25d8
Indentation
2015-03-09 15:09:27 +01:00
Frank Denis
ef4290b71c
Indentation
2015-02-21 16:15:35 +01:00
Frank Denis
ef7d825f1f
__declspec() / __attribute__(()) shouldn't come before "typedef"
2015-02-17 17:38:54 +01:00
Frank Denis
a2a72d3472
Compare size_t values with ULL
2015-02-16 09:01:36 +01:00
Frank Denis
90447b0283
scrypt: keep r as a size_t value
2015-02-15 22:37:59 +01:00
Frank Denis
663fe8229e
scrypt: corrected pointer alias issues causing scrypt to fail on MIPS64
...
by jfoug <jfoug at cox.net> via JtR issue #1032
2015-02-15 22:31:04 +01:00
Frank Denis
788d8d0178
Make bin2hex() code consistent with hex2bin()
2015-02-10 19:34:11 +01:00
Frank Denis
f8af1790dd
Constant-time hex2bin.
2015-02-10 17:01:51 +01:00
Frank Denis
2fb83ade4c
crypto_sign_detached(): no need to store a copy of the public key on the stack
2015-02-10 13:40:12 +01:00
Frank Denis
a1b3da7dd9
Add crypto_stream_xsalsa20_ic()
2015-02-02 21:27:19 +01:00
Frank Denis
f61e179d8e
(p1 - p2 == 0) => (p1 == p2)
...
No binary changes on supported platforms except on gcc/armv7l where
the control flow remains identical but permutative statements get switched.
2015-01-31 12:18:51 +01:00
Frank Denis
5db61c617b
Add statebytes for crypto_hmac_*
2015-01-23 23:08:49 +01:00
Frank Denis
d0e9b8f69c
Suggest crypto_generichash_statebytes() instead of sizeof()
2015-01-23 22:54:27 +01:00
Frank Denis
b5deb4d070
+ crypto_hash_sha(256|512)_statebytes
2015-01-23 11:17:40 +01:00
Frank Denis
9e538624f4
+ crypto_generichash_statebytes()
2015-01-23 11:00:57 +01:00
Frank Denis
c9ba75a48f
Add crypto_generichash_statebytes()
...
sizeof() is not always an option when accessing the library from
other languages.
2015-01-23 10:56:01 +01:00
Frank Denis
e2a24e69ec
Invert #if[n]def __EMSCRIPTEN__ logic, put more common case first
2015-01-18 10:20:12 +01:00
Frank Denis
feaba594db
|| -> | spotted by Ahmad
2015-01-18 10:17:53 +01:00
Frank Denis
5b3d8a4bf9
Mention what is optional and what is required for a randombytes implementation
2015-01-18 10:12:27 +01:00
Frank Denis
0b4fb379d4
Factorize randombytes_uniform()
...
Don't require randombytes implementations to reimplement this.
NULL can be passed instead of a function pointer to use the default
implementation.
Allow NULL for randombytes_stir() and randombytes_close() as well.
2015-01-18 10:08:36 +01:00
Frank Denis
add0fcede4
randombytes_random() is 32 bits, even in JS.
2015-01-18 09:50:17 +01:00
Frank Denis
c64baf38c6
Do not require /dev/urandom emulation in Javascript any more.
2015-01-17 23:01:20 +01:00
Frank Denis
2a562f8986
Proper overlapping check; memmove() was called when it was superfluous.
2015-01-15 00:44:28 +01:00
Frank Denis
f0b76de13e
chacha20: counting the remaining bytes in a block doesn't require ULL
2015-01-13 20:43:27 +01:00
Frank Denis
f580fcfa92
Sync reduced rounds versions of salsa20 with supercop
2015-01-13 19:36:50 +01:00
Frank Denis
0fef202b37
Wipe the last salsa20 block in the reduced rounds versions
2015-01-13 19:18:50 +01:00
Frank Denis
ab4171e37f
Error checking
2015-01-13 16:26:58 +01:00
Frank Denis
8ba7fbd062
Mention that sodium_alloc() can be used with sodium data structures
...
And explain how to deal with crypto_generichash_state
2015-01-13 11:04:39 +01:00
Frank Denis
2d380c97f3
Move prototypes of functions requiring padding together
2015-01-06 18:28:07 +01:00
Frank Denis
aaf5fbf2e5
+ precomputed interface for crypto_box()
2015-01-06 17:52:42 +01:00
Frank Denis
fab8a0b55f
Indentation
2015-01-06 17:22:12 +01:00
Frank Denis
49f87845b7
Missing #include for sodium_memzero()
2015-01-04 20:02:03 +01:00
Frank Denis
16f32cf1a5
Wipe the shared key in crypto_box() and crypto_secretbox()
...
The _easy and _detached interfaces already did this.
2015-01-04 18:29:17 +01:00
Frank Denis
26f87e266e
Let sodium_malloc() and friends work on systems without protected memory.
...
On these systems, they become simple aliases for malloc() and friends.
Canaries could be added, but adding too much bloat for these rare systems
is probably not worth it, and malloc debuggers are better tools to use.
2014-12-29 23:23:33 +01:00
Frank Denis
cae09d458a
Let crypto_sign_open() accept NULL for the message length pointer
...
Ditto for edwards25519sha512batch for consistency
Add a _p suffix to lengths that are actually pointers for clarity
2014-12-28 21:34:59 +01:00
Frank Denis
4cd1d03a28
Use relative paths in sodium.h
...
This make it easier to use sodium when bundled with another project.
2014-12-27 09:15:02 +01:00
Frank Denis
d5ad99fed6
Retry if open(2) is interrupted; set the CLOEXEC flag as well.
...
Also retry if read(2) returns EAGAIN. This shouldn't happen in blocking mode,
but it can't hurt either.
2014-12-25 12:30:14 +01:00
Frank Denis
e7a84c9e84
We always need to allocate aligned memory
2014-12-12 08:52:05 -08:00
Frank Denis
9b27460618
We always need a page size
2014-12-12 08:51:47 -08:00
Frank Denis
b1cac74b00
We can still directly call _mprotect_readwrite() instead of the high-level function.
2014-12-07 14:59:32 -08:00
Frank Denis
5e364632e0
Make sodium_free() callable even if protection is PROT_NONE.
...
Reported by @stouset, thanks!
2014-12-07 14:52:44 -08:00
Frank Denis
e5024c368f
Remove obsolete, undocumented compatibility layer with Sodium 0.5
2014-11-30 19:57:41 -08:00