Frank Denis
4c2cf071f8
Include <intrin.h> on Visual Studio for __cpuid()
2017-02-16 09:24:33 +01:00
Frank Denis
727dae49e2
Back out locks in randombytes_salsa20
...
These functions were not supposed to be thread-safe, and we can't
use crit_*() in the randombytes implementations anyway.
2017-02-10 18:01:06 +01:00
Frank Denis
d5fc01b317
Merge branch 'master' of https://github.com/jedisct1/libsodium
...
* 'master' of https://github.com/jedisct1/libsodium :
C++ compat
2017-02-04 11:41:49 +01:00
Frank Denis
5095fc9afa
Reorder
2017-02-04 11:40:20 +01:00
Frank DENIS
e59bfee281
C++ compat
2017-01-31 17:14:12 +01:00
Frank Denis
8439df646b
Favor the Windows API over pthreads on mingw
2017-01-26 20:34:46 +01:00
Frank Denis
de3c0ff85e
Indent
2017-01-18 20:03:26 +01:00
Frank Denis
f053b98b64
Use getrandom() on dietlibc -- via Felix von Leitner
2017-01-18 20:00:25 +01:00
Frank Denis
3633726d56
Indent
2017-01-13 19:28:18 +01:00
Frank Denis
1686da3d3c
Remove the non-IETF versions of crypto_aead_xchacha20poly1305
2017-01-13 19:24:48 +01:00
Frank Denis
4e8832ed57
Merge branch 'master' of https://github.com/jedisct1/libsodium
...
* 'master' of https://github.com/jedisct1/libsodium :
Indent
xchacha20poly1305: optimize and be compatible with ietf chacha20poly1305 (#461 )
2016-12-27 21:03:12 +01:00
Frank DENIS
24fd77ded3
Indent
2016-12-24 02:24:24 +01:00
Jason A. Donenfeld
6abad20323
xchacha20poly1305: optimize and be compatible with ietf chacha20poly1305 ( #461 )
...
Due to SSL, the IETF version of chacha20poly1305 is going to be the one
that's in libraries places. While the 12-byte nonce thing is a little
weird, it has other benefits, like adding padding to the auth tag, which
might help fend off certain attacks.
But more importantly, since chacha20poly1305 in the IETF construction is
lots of places, it would be useful to be able to build xchacha20poly1305
out of it. Fortunately it's very easy to make hchacha20 (either
stand-alone, or out of the normal chacha20 block function), and then
that can be composed with an existing library's chacha20poly1305. It
looks a bit like this:
xchacha20poly1305(input, key, nonce) {
new_key = hchacha20(key, nonce)
return chacha20poly1305(input, new_key, nonce + 16)
}
This is also an efficient way to do it, since it means hchacha20 must
only be computed once.
Unfortuantely, non-IETF xchacha20poly1305 means that you deprive
virtually all other libraries that only support the more common
IETF construction the ability the ability to interoperate with
libsodium, through the simple construction. Rather, it forces
everyone to reimplement the AEAD part.
So, this commit adds a xchacha20poly1305 that uses the IETF construction
with the padding.
While we're at it, we redefine xchacha20poly1305 in terms of
chacha20poly1305, which gives the same output, but computes one less
hchacha20 and is generally a lot cleaner and simpler to understand.
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com >
2016-12-24 02:17:33 +01:00
Frank Denis
c5735ef215
Merge branch 'master' of https://github.com/jedisct1/libsodium
...
* 'master' of https://github.com/jedisct1/libsodium :
Check if atomic operations are supported
Remove a whitespace following trailing backslash in a Makefile
2016-12-17 19:00:59 +01:00
Frank Denis
d54b0b8d69
Do not include xchacha20poly1305 in minimal mode
2016-12-17 18:59:17 +01:00
Frank Denis
db97a35502
Check if atomic operations are supported
2016-12-16 16:37:12 +01:00
Frank Denis
4c6f704084
Remove a whitespace following trailing backslash in a Makefile
2016-12-16 16:20:30 +01:00
Frank Denis
9d2ac5f747
Correct an assertion and prefer compile-time assertions
2016-12-11 20:28:03 +01:00
Frank Denis
9979762bbe
Indent
2016-12-11 00:01:40 +01:00
Winston Durand
9cae7b6b7c
fixed GCC2 bug seeing empty statement ( #449 )
2016-11-30 06:52:18 +01:00
Frank Denis
157c4a80c1
+ crypto_aead_xchacha20poly1305
2016-11-26 21:29:26 +01:00
Frank Denis
8b7f03ddf7
Indent
2016-11-26 21:16:42 +01:00
Frank Denis
184110ccc5
+ crypto_box_curve25519xchacha20poly1305_*
2016-11-26 21:06:23 +01:00
Frank Denis
54a1357ce3
Indent
2016-11-26 20:24:58 +01:00
Frank Denis
2ace041fd9
Add secretbox_xchacha20poly1305_easy
2016-11-26 19:45:24 +01:00
Frank Denis
d4f384e388
Make crypto_secretbox_xsalsa20poly1305_open() as __warn_unused_result__
2016-11-26 19:44:51 +01:00
Frank Denis
669ed597d0
Rename box_x*poly1305.c -> secretbox_x*poly1305.c for consistency
2016-11-26 14:12:47 +01:00
Frank Denis
2848984edf
+ secretbox_xchacha20poly1305
2016-11-26 14:04:23 +01:00
Frank Denis
a86ac590d6
Reformat to make the style more consistent
2016-11-26 13:40:34 +01:00
Frank Denis
5eed910c11
Cast the scalar instead of the coefficient
2016-10-30 01:13:22 +02:00
Frank Denis
71f0693ee7
Argon2i: fix encoding issues
...
For compatibility with hashes might have been encoded using other libraries.
2016-10-26 22:50:38 +02:00
Frank Denis
aff4aaeabf
Change the garbage value to 0xdb
...
If that garbage value becomes the LSB of a pointer, the pointer is more
likely to be unaligned, an trigger more bugs.
2016-10-15 18:54:56 +02:00
Frank Denis
49741c59e8
Allows RANDOMBYTES_DEFAULT_IMPLEMENTATION to be overriden
2016-10-13 22:57:01 +02:00
Frank Denis
583c16707c
+ crypto_stream_xchacha20
2016-09-30 22:57:56 +02:00
Frank Denis
42dc78b38b
Indent
2016-09-30 08:40:15 +02:00
Frank Denis
b20d227f37
Avoid collision with a possibly existing int128 type definition
2016-09-30 08:36:50 +02:00
Frank Denis
53ee1fe758
Remove commented out code and avoid inconsistent indentation
2016-09-30 08:30:22 +02:00
Frank Denis
f257413772
uint32 -> uint32_t
2016-09-30 08:26:24 +02:00
Robert Spychala
94ea419247
add preprocessor flag to skip blocking /dev/random during libsodium init ( #429 )
2016-09-20 21:13:07 +02:00
Frank Denis
26e8b0253f
Argon2: check that m_cost/t_cost/lanes decode to uint32
2016-09-18 09:33:35 +02:00
Frank Denis
6035c0779b
Back to dev mode
2016-08-04 02:28:21 +02:00
Frank Denis
2f4f718cd9
Remove dev flag
2016-07-31 16:34:11 +02:00
Frank Denis
19a9d18b9c
_MSC_VER > 1600 -> _MSC_VER >= 1700 for consistency
2016-07-24 19:58:00 +02:00
Jan-E
6b739fc821
Fix VS2010 (and VC9) x64 build
2016-07-24 02:13:22 +02:00
Frank Denis
89918e94f1
crit_{enter,leave} can fail
2016-07-06 12:03:08 +02:00
Frank Denis
29492143ab
Warn if the library is being compiled in a custom way
2016-07-02 10:07:38 +02:00
Frank Denis
2cc0bab0e3
Update comment
2016-06-29 15:31:23 +02:00
Frank Denis
648f46d22a
Expose sodium_crit_enter() and sodium_crit_leave() internally
2016-06-29 15:28:15 +02:00
Frank Denis
5a3ff833fd
Slightly change how the length of argon2 strings is checked
2016-06-19 23:26:08 +02:00
Frank Denis
6fad3644b5
Nits
2016-06-15 16:00:59 +02:00