Commit Graph
652 Commits
Author SHA1 Message Date
Frank Denis 3117ccf358 Use memcpy() instead of ugly casts. No changes to compiled code. 2015-04-24 13:52:56 +02:00
Frank Denis 957a29c469 salsa20_random_buf(): mix the output size with the key 2015-04-23 00:09:17 +02:00
Frank Denis 70487753ee JS target: window.crypto is not defined in webworkers; use self.crypto instead. 2015-04-20 14:26:27 +02:00
Frank Denis 575ce93058 + crypto_box_seal() 2015-04-17 01:01:32 +02:00
Frank Denis f740cb5968 Better separation between crypto_auth[_verify] and the NIST-like API. 2015-04-05 20:14:21 +02:00
Frank Denis dbcca2a501 Don't divide by zero if sodium_allocarray() is called with count=0 2015-03-23 21:43:27 +01:00
Frank Denis 9d5c067ad2 Use getrandom(2) on Linux, if available. 2015-03-09 17:22:34 +01:00
Frank Denis ceb72f25d8 Indentation 2015-03-09 15:09:27 +01:00
Frank Denis ef4290b71c Indentation 2015-02-21 16:15:35 +01:00
Frank Denis ef7d825f1f __declspec() / __attribute__(()) shouldn't come before "typedef" 2015-02-17 17:38:54 +01:00
Frank Denis a2a72d3472 Compare size_t values with ULL 2015-02-16 09:01:36 +01:00
Frank Denis 90447b0283 scrypt: keep r as a size_t value 2015-02-15 22:37:59 +01:00
Frank Denis 663fe8229e scrypt: corrected pointer alias issues causing scrypt to fail on MIPS64
by jfoug <jfoug at cox.net> via JtR issue #1032
2015-02-15 22:31:04 +01:00
Frank Denis 788d8d0178 Make bin2hex() code consistent with hex2bin() 2015-02-10 19:34:11 +01:00
Frank Denis f8af1790dd Constant-time hex2bin. 2015-02-10 17:01:51 +01:00
Frank Denis 2fb83ade4c crypto_sign_detached(): no need to store a copy of the public key on the stack 2015-02-10 13:40:12 +01:00
Frank Denis a1b3da7dd9 Add crypto_stream_xsalsa20_ic() 2015-02-02 21:27:19 +01:00
Frank Denis f61e179d8e (p1 - p2 == 0) => (p1 == p2)
No binary changes on supported platforms except on gcc/armv7l where
the control flow remains identical but permutative statements get switched.
2015-01-31 12:18:51 +01:00
Frank Denis 5db61c617b Add statebytes for crypto_hmac_* 2015-01-23 23:08:49 +01:00
Frank Denis d0e9b8f69c Suggest crypto_generichash_statebytes() instead of sizeof() 2015-01-23 22:54:27 +01:00
Frank Denis b5deb4d070 + crypto_hash_sha(256|512)_statebytes 2015-01-23 11:17:40 +01:00
Frank Denis 9e538624f4 + crypto_generichash_statebytes() 2015-01-23 11:00:57 +01:00
Frank Denis c9ba75a48f Add crypto_generichash_statebytes()
sizeof() is not always an option when accessing the library from
other languages.
2015-01-23 10:56:01 +01:00
Frank Denis e2a24e69ec Invert #if[n]def __EMSCRIPTEN__ logic, put more common case first 2015-01-18 10:20:12 +01:00
Frank Denis feaba594db || -> | spotted by Ahmad 2015-01-18 10:17:53 +01:00
Frank Denis 5b3d8a4bf9 Mention what is optional and what is required for a randombytes implementation 2015-01-18 10:12:27 +01:00
Frank Denis 0b4fb379d4 Factorize randombytes_uniform()
Don't require randombytes implementations to reimplement this.
NULL can be passed instead of a function pointer to use the default
implementation.
Allow NULL for randombytes_stir() and randombytes_close() as well.
2015-01-18 10:08:36 +01:00
Frank Denis add0fcede4 randombytes_random() is 32 bits, even in JS. 2015-01-18 09:50:17 +01:00
Frank Denis c64baf38c6 Do not require /dev/urandom emulation in Javascript any more. 2015-01-17 23:01:20 +01:00
Frank Denis 2a562f8986 Proper overlapping check; memmove() was called when it was superfluous. 2015-01-15 00:44:28 +01:00
Frank Denis f0b76de13e chacha20: counting the remaining bytes in a block doesn't require ULL 2015-01-13 20:43:27 +01:00
Frank Denis f580fcfa92 Sync reduced rounds versions of salsa20 with supercop 2015-01-13 19:36:50 +01:00
Frank Denis 0fef202b37 Wipe the last salsa20 block in the reduced rounds versions 2015-01-13 19:18:50 +01:00
Frank Denis ab4171e37f Error checking 2015-01-13 16:26:58 +01:00
Frank Denis 8ba7fbd062 Mention that sodium_alloc() can be used with sodium data structures
And explain how to deal with crypto_generichash_state
2015-01-13 11:04:39 +01:00
Frank Denis 2d380c97f3 Move prototypes of functions requiring padding together 2015-01-06 18:28:07 +01:00
Frank Denis aaf5fbf2e5 + precomputed interface for crypto_box() 2015-01-06 17:52:42 +01:00
Frank Denis fab8a0b55f Indentation 2015-01-06 17:22:12 +01:00
Frank Denis 49f87845b7 Missing #include for sodium_memzero() 2015-01-04 20:02:03 +01:00
Frank Denis 16f32cf1a5 Wipe the shared key in crypto_box() and crypto_secretbox()
The _easy and _detached interfaces already did this.
2015-01-04 18:29:17 +01:00
Frank Denis 26f87e266e Let sodium_malloc() and friends work on systems without protected memory.
On these systems, they become simple aliases for malloc() and friends.

Canaries could be added, but adding too much bloat for these rare systems
is probably not worth it, and malloc debuggers are better tools to use.
2014-12-29 23:23:33 +01:00
Frank Denis cae09d458a Let crypto_sign_open() accept NULL for the message length pointer
Ditto for edwards25519sha512batch for consistency
Add a _p suffix to lengths that are actually pointers for clarity
2014-12-28 21:34:59 +01:00
Frank Denis 4cd1d03a28 Use relative paths in sodium.h
This make it easier to use sodium when bundled with another project.
2014-12-27 09:15:02 +01:00
Frank Denis d5ad99fed6 Retry if open(2) is interrupted; set the CLOEXEC flag as well.
Also retry if read(2) returns EAGAIN. This shouldn't happen in blocking mode,
but it can't hurt either.
2014-12-25 12:30:14 +01:00
Frank Denis e7a84c9e84 We always need to allocate aligned memory 2014-12-12 08:52:05 -08:00
Frank Denis 9b27460618 We always need a page size 2014-12-12 08:51:47 -08:00
Frank Denis b1cac74b00 We can still directly call _mprotect_readwrite() instead of the high-level function. 2014-12-07 14:59:32 -08:00
Frank Denis 5e364632e0 Make sodium_free() callable even if protection is PROT_NONE.
Reported by @stouset, thanks!
2014-12-07 14:52:44 -08:00
Frank Denis e5024c368f Remove obsolete, undocumented compatibility layer with Sodium 0.5 2014-11-30 19:57:41 -08:00
Frank Denis da2c9952db Check if mmap(2) works, not just the presence of MAP_ANON
In particular, mmap(2) doesn't return an aligner pointer on Emscripten.
2014-11-24 10:22:50 -08:00