Commit Graph
600 Commits
Author SHA1 Message Date
Frank Denis 28a07bf0c9 Add explicit size_t conversions. 2014-11-20 13:31:13 -08:00
Frank Denis a31a353f0e curve25519-donna-c64: use limb instead of uint64_t everywhere for consistency 2014-11-20 11:46:25 -08:00
Frank Denis ae13df74e1 curve25519-donna-c64: replace U8TO64/U64TO8 with load_limb/store_limb
To match the current @agl code.
2014-11-20 11:43:53 -08:00
Frank Denis d3e716aa49 curve25519-donna-c64: don't read an extra byte when expanding a 32-byte number into polynomial form
Reported by Michael Holmwood.
2014-11-20 11:22:24 -08:00
Frank Denis 63ee1abf82 Explicit int32 -> int64 conversions 2014-10-29 08:37:21 -07:00
Frank Denis caeeefbcf4 Credit CodesInChaos 2014-10-19 19:26:15 -07:00
Andre Caron a7a04d7af5 Changes DLL_EXPORT to SODIUM_DLL_EXPORT.
This macro conflicts with other projects.  This results in the inability to
build one DLL that depends on libsodium if the other DLL also uses the
DLL_EXPORT macro to control visibility of library symbols.  Since the choice of
name for this macro is arbitrary, use of a library prefix is preferred.
2014-10-13 15:18:09 -04:00
Frank Denis 9e64361e66 Make sodium_bin2hex() slightly faster 2014-10-07 21:15:46 -07:00
Frank Denis 814df1e60d Constant-time sodium_bin2hex()
Original C# code by CodesInChaos.
2014-10-07 20:50:26 -07:00
Frank Denis 5c3c132e47 Make include guards consistent, and avoid reserved identifiers. 2014-10-06 14:14:49 -07:00
Frank Denis cb07df046f Remove S<l check.
Plan is to add is_standard()/is_canonical() instead of changing the current behavior
of the verification function. Suggested by CodesInChaos.
2014-10-06 12:21:40 -07:00
Frank Denis 15889c2e64 Remove dead variable and assignment 2014-10-05 01:28:00 -07:00
Frank Denis e04f1b6854 Avoid a conditional jump 2014-10-04 23:36:53 -07:00
Frank Denis d34743241e Add a test for ed25519 malleability and restore traditional behavior.
If an application really requires non-malleability, ED25519_PREVENT_MALLEABILITY
can be defined to enable the check.

This might become the default behavior depending on what other implementations
are planning to do.
2014-10-04 23:25:01 -07:00
Frank Denis 9f6d37d9c6 Support overlapping input and output regions in crypto_secretbox_detached()
crypto_stream_salsa20() doesn't support overlapping input and output regions,
except when they are aliases.
2014-10-04 22:08:09 -07:00
Frank Denis 4099618de2 ed25519_open(): check that S < l
Not strictly required, but I don't see any downsides either.
2014-10-04 22:07:58 -07:00
Frank Denis 727f3993a1 lcov exclusion 2014-09-23 21:22:44 -07:00
Frank Denis f71c1c0e17 lcov exclusion 2014-09-23 21:19:49 -07:00
Frank Denis 41db958e83 lcov exclusion 2014-09-23 14:54:10 -07:00
Frank Denis 0cb0578ede lcov exclusion 2014-09-23 14:03:28 -07:00
Frank Denis 0c73253249 lcov exclusions 2014-09-23 13:45:11 -07:00
Frank Denis dcbc538cd9 lcov exclusions 2014-09-23 13:31:42 -07:00
Frank Denis 99734cf8b4 lcov exclusions 2014-09-23 13:22:24 -07:00
Frank Denis c775f87260 escrypt_gensalt_r() cannot fail 2014-09-23 13:20:39 -07:00
Frank Denis 116cdf32f1 pickparams() and escrypt_init_local() cannot fail 2014-09-23 13:08:25 -07:00
Frank Denis a858a1971e lcov exclusion
Testing for this case rather belongs to the sodium-validation project.
2014-09-23 12:39:15 -07:00
Frank Denis 5fc704cbf0 lcov exclusions 2014-09-23 12:18:24 -07:00
Frank Denis ad5a165f94 crypto_sign(): read the copy, not the message, to properly handle overlaps 2014-09-21 22:06:45 -07:00
Frank Denis 51dfcfc223 Handle overlapping in/out buffers in crypto_sign() 2014-09-21 11:24:49 -07:00
Frank Denis d92d531ac0 Visual Studio: use #pragma warning(push/pop) instead of warning(default: ...) 2014-09-18 23:46:57 -07:00
Frank Denis abd5df9ba1 lcov: annotate the actual "can't happen" lines. 2014-09-18 22:22:51 -07:00
Frank Denis ef86392f39 Fix funky indentation after untabification 2014-09-18 22:03:30 -07:00
Frank Denis 9eefb2e487 More test + lcov exclusions 2014-09-18 22:02:25 -07:00
Frank Denis 877bf76716 crypto_(secret)box_easy: check SIZE_MAX overflow only where needed 2014-09-16 21:09:55 -07:00
Frank Denis c54b05a1e5 lcov exclusion 2014-09-16 20:55:59 -07:00
Frank Denis 37580f4f52 More tests 2014-09-16 20:46:43 -07:00
Frank Denis 1cf170a90e Test sodium_allocarray(), and sodium_malloc() with a huge size 2014-09-16 15:35:21 -07:00
Frank Denis fe4bbdc5ca More crypto_pwhash() tests 2014-09-16 15:07:42 -07:00
Frank Denis e333e55209 Increase generichash test coverage 2014-09-16 14:44:38 -07:00
Frank Denis 671ee78ce2 lcov exclusions 2014-09-16 10:52:42 -07:00
Frank Denis 7cf7f0a31c More lcov exclusions.
poly1305 optimized implementations will come after 1.0.
2014-09-16 10:43:38 -07:00
Frank Denis cee8af9b66 Test chacha20 with length == 0 2014-09-16 10:32:04 -07:00
Frank Denis 9177ebedf2 Merge branch 'master' of github.com:jedisct1/libsodium
* 'master' of github.com:jedisct1/libsodium:
  Take blake2s off the tree until we actually use it
2014-09-15 17:45:58 -07:00
Frank Denis 136af03cc3 blake2b-ref: memcpy() -> memmove() for overlapping regions 2014-09-15 17:45:07 -07:00
Frank Denis 7d630186d9 Take blake2s off the tree until we actually use it 2014-09-15 11:33:07 -07:00
Frank Denis f812967fb8 Coverage exclusion when relevant 2014-09-14 15:44:13 -07:00
Frank Denis 7dde13e1b4 Sync Blake2s changes with Blake2b
Note: Blake2s code is not compiled yet
2014-09-13 13:14:56 -07:00
Frank Denis a7d38ef15d Check outlen in blake2b_final
Not required in Sodium since the check is already performed in
higher-level functions, but it doesn't hurt either.
2014-09-13 13:09:25 -07:00
Frank Denis 8994dc340f Blake2 load/store functions must accept unaligned pointers even on LE 2014-09-13 12:59:11 -07:00
Frank Denis 59a207e4ff __cpuidex() is not really required for now, just use __cpuid() 2014-09-13 12:22:53 -07:00