X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~mdw/git/catacomb-python/blobdiff_plain/204d480b9f065082728d39d981f505d3bff58bb2..183e9cd31b1ac2f14b86c5de6ac2643b8a4364a2:/algorithms.c diff --git a/algorithms.c b/algorithms.c index 4561b9a..7eab3ae 100644 --- a/algorithms.c +++ b/algorithms.c @@ -35,21 +35,31 @@ PyTypeObject *keysz_pytype; PyTypeObject *keyszany_pytype, *keyszrange_pytype, *keyszset_pytype; PyObject *sha_pyobj, *has160_pyobj; +#ifndef KSZ_OPMASK +# define KSZ_OPMASK 0x1f +#endif + +#ifndef KSZ_16BIT +# define KSZ_16BIT 0x20 +#endif + PyObject *keysz_pywrap(const octet *k) { - switch (k[0]) { + unsigned op = *k++; +#define ARG(i) (op&KSZ_16BIT ? LOAD16(k + 2*(i)) : k[i]) + switch (op&KSZ_OPMASK) { case KSZ_ANY: { keysz_pyobj *o = PyObject_New(keysz_pyobj, keyszany_pytype); - o->dfl = k[1]; + o->dfl = ARG(0); return ((PyObject *)o); } break; case KSZ_RANGE: { keyszrange_pyobj *o = PyObject_New(keyszrange_pyobj, keyszrange_pytype); - o->dfl = k[1]; - o->min = k[2]; - o->max = k[3]; - o->mod = k[4]; + o->dfl = ARG(0); + o->min = ARG(1); + o->max = ARG(2); + o->mod = ARG(3); if (!o->mod) o->mod = 1; return ((PyObject *)o); } break; @@ -57,16 +67,17 @@ PyObject *keysz_pywrap(const octet *k) keyszset_pyobj *o = PyObject_New(keyszset_pyobj, keyszset_pytype); int i, n; - o->dfl = k[1]; - for (i = 0; k[i + 1]; i++) ; + o->dfl = ARG(0); + for (i = 0; ARG(i); i++) ; n = i; o->set = PyTuple_New(n); for (i = 0; i < n; i++) - PyTuple_SET_ITEM(o->set, i, PyInt_FromLong(k[i + 1])); + PyTuple_SET_ITEM(o->set, i, PyInt_FromLong(ARG(i))); return ((PyObject *)o); } break; default: abort(); } +#undef ARG } static PyObject *keyszany_pynew(PyTypeObject *ty, @@ -96,11 +107,9 @@ static PyObject *keyszrange_pynew(PyTypeObject *ty, if (!PyArg_ParseTupleAndKeywords(arg, kw, "i|iii:new", kwlist, &dfl, &min, &max, &mod)) goto end; - if (dfl < 0 || min < 0 || max < 0) - VALERR("key size cannot be negative"); - if (min > dfl || (max && dfl > max)) - VALERR("bad key size bounds"); - if (mod <= 0 || dfl % mod || min % mod || max % mod) + if (dfl < 0 || min < 0) VALERR("key size cannot be negative"); + if (min > dfl || (max && dfl > max)) VALERR("bad key size bounds"); + if (mod <= 0 || dfl%mod || min%mod || max%mod) VALERR("bad key size modulus"); o = (keyszrange_pyobj *)ty->tp_alloc(ty, 0); o->dfl = dfl; @@ -121,8 +130,7 @@ static PyObject *keyszset_pynew(PyTypeObject *ty, PyObject *x = 0, *l = 0; keyszset_pyobj *o = 0; - if (!PyArg_ParseTupleAndKeywords(arg, kw, "i|O:new", kwlist, - &dfl, &set)) + if (!PyArg_ParseTupleAndKeywords(arg, kw, "i|O:new", kwlist, &dfl, &set)) goto end; if (!set) set = PyTuple_New(0); else Py_INCREF(set); @@ -253,7 +261,7 @@ static PyTypeObject keysz_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Key size constraints.", +"Key size constraints. Abstract.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -301,7 +309,8 @@ static PyTypeObject keyszany_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Key size constraints. This object imposes no constraints on size.", +"KeySZAny(DEFAULT)\n\ + Key size constraints. This object imposes no constraints on size.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -349,8 +358,9 @@ static PyTypeObject keyszrange_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Key size constraints. This object asserts minimum and maximum (if\n\ -sizes, and requires the key length to be a multiple of some value.", +"KeySZRange(DEFAULT, [min = 0], [max = 0], [mod = 1])\n\ + Key size constraints. Key size must be between MIN and MAX inclusive,\n\ + and be a multiple of MOD.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -398,8 +408,8 @@ static PyTypeObject keyszset_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Key size constraints. This object requires the key to be one of a\n\ -few listed sizes.", +"KeySZSet(DEFAULT, SEQ)\n\ + Key size constraints. Key size must be DEFAULT or one in SEQ.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -462,7 +472,7 @@ static PyObject *gcipher_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) { char *kwlist[] = { "k", 0 }; char *k; - int sz; + Py_ssize_t sz; if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#:new", kwlist, &k, &sz)) goto end; @@ -511,7 +521,7 @@ static PyObject *gccget_blksz(PyObject *me, void *hunoz) static PyObject *gcmeth_encrypt(PyObject *me, PyObject *arg) { char *p; - int sz; + Py_ssize_t sz; PyObject *rc = 0; if (!PyArg_ParseTuple(arg, "s#:encrypt", &p, &sz)) return (0); @@ -537,7 +547,7 @@ static PyObject *gcmeth_enczero(PyObject *me, PyObject *arg) static PyObject *gcmeth_decrypt(PyObject *me, PyObject *arg) { char *p; - int sz; + Py_ssize_t sz; PyObject *rc = 0; if (!PyArg_ParseTuple(arg, "s#:decrypt", &p, &sz)) return (0); @@ -563,9 +573,10 @@ static PyObject *gcmeth_deczero(PyObject *me, PyObject *arg) static PyObject *gcmeth_setiv(PyObject *me, PyObject *arg) { char *p; - int sz; + Py_ssize_t sz; if (!PyArg_ParseTuple(arg, "s#:setiv", &p, &sz)) goto end; + if (!GCIPHER_C(me)->ops->setiv) VALERR("`setiv' not supported"); if (!GC_CLASS(GCIPHER_C(me))->blksz) VALERR("not a block cipher mode"); if (sz != GC_CLASS(GCIPHER_C(me))->blksz) VALERR("bad IV length"); GC_SETIV(GCIPHER_C(me), p); @@ -577,6 +588,7 @@ end: static PyObject *gcmeth_bdry(PyObject *me, PyObject *arg) { if (!PyArg_ParseTuple(arg, ":bdry")) goto end; + if (!GCIPHER_C(me)->ops->bdry) VALERR("`bdry' not supported"); if (!GC_CLASS(GCIPHER_C(me))->blksz) VALERR("not a block cipher mode"); GC_BDRY(GCIPHER_C(me)); RETURN_ME; @@ -766,7 +778,7 @@ static PyObject *gchget_bufsz(PyObject *me, void *hunoz) static PyObject *ghmeth_hash(PyObject *me, PyObject *arg) { char *p; - int sz; + Py_ssize_t sz; if (!PyArg_ParseTuple(arg, "s#:hash", &p, &sz)) return (0); GH_HASH(GHASH_H(me), p, sz); RETURN_ME; @@ -788,7 +800,7 @@ DOUINTCONV(GHMETH_HASHU_) static PyObject *ghmeth_hashbuf##w(PyObject *me, PyObject *arg) \ { \ char *p; \ - int sz; \ + Py_ssize_t sz; \ if (!PyArg_ParseTuple(arg, "s#:hashbuf" #w, &p, &sz)) goto end; \ if (sz > MASK##n) TYERR("string too long"); \ GH_HASHBUF##W(GHASH_H(me), p, sz); \ @@ -950,7 +962,7 @@ static PyObject *gmac_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) { char *kwlist[] = { "k", 0 }; char *k; - int sz; + Py_ssize_t sz; if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#:new", kwlist, &k, &sz)) goto end; @@ -1212,7 +1224,7 @@ static PyObject *poly1305hash_pynew(PyTypeObject *ty, poly1305key_pyobj *pk = (poly1305key_pyobj *)ty; poly1305hash_pyobj *ph; char *m = 0; - int sz; + Py_ssize_t sz; if (!PyArg_ParseTupleAndKeywords(arg, kw, "|s#:new", kwlist, &m, &sz)) return (0); @@ -1233,7 +1245,7 @@ static PyObject *poly1305key_pynew(PyTypeObject *ty, char *kwlist[] = { "k", 0 }; poly1305key_pyobj *pk; char *k; - int sz; + Py_ssize_t sz; if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#:new", kwlist, &k, &sz)) goto end; @@ -1285,7 +1297,7 @@ static PyObject *polymeth_copy(PyObject *me, PyObject *arg) static PyObject *polymeth_hash(PyObject *me, PyObject *arg) { char *p; - int sz; + Py_ssize_t sz; if (!PyArg_ParseTuple(arg, "s#:hash", &p, &sz)) return (0); poly1305_hash(P1305_CTX(me), p, sz); RETURN_ME; @@ -1297,7 +1309,7 @@ static PyObject *polymeth_hash(PyObject *me, PyObject *arg) uint##n x; \ octet b[SZ_##W]; \ if (!PyArg_ParseTuple(arg, "O&:hashu" #w, convu##n, &x)) goto end; \ - STORE##W(b, n); poly1305_hash(P1305_CTX(me), b, sizeof(b)); \ + STORE##W(b, x); poly1305_hash(P1305_CTX(me), b, sizeof(b)); \ RETURN_ME; \ end: \ return (0); \ @@ -1308,11 +1320,11 @@ DOUINTCONV(POLYMETH_HASHU_) static PyObject *polymeth_hashbuf##w(PyObject *me, PyObject *arg) \ { \ char *p; \ - int sz; \ + Py_ssize_t sz; \ octet b[SZ_##W]; \ if (!PyArg_ParseTuple(arg, "s#:hashbuf" #w, &p, &sz)) goto end; \ if (sz > MASK##n) TYERR("string too long"); \ - STORE##W(b, n); poly1305_hash(P1305_CTX(me), b, sizeof(b)); \ + STORE##W(b, sz); poly1305_hash(P1305_CTX(me), b, sizeof(b)); \ poly1305_hash(P1305_CTX(me), p, sz); \ RETURN_ME; \ end: \ @@ -1335,6 +1347,13 @@ static PyObject *polymeth_flush(PyObject *me, PyObject *arg) RETURN_ME; } +static PyObject *polymeth_flushzero(PyObject *me, PyObject *arg) +{ + if (!PyArg_ParseTuple(arg, ":flushzero")) return (0); + poly1305_flushzero(P1305_CTX(me)); + RETURN_ME; +} + static PyObject *polymeth_concat(PyObject *me, PyObject *arg) { PyObject *pre, *suff; @@ -1385,6 +1404,7 @@ static PyMethodDef poly1305hash_pymethods[] = { #undef METHBUF_ METH (hashstrz, "P.hashstrz(STRING)") METH (flush, "P.flush()") + METH (flushzero, "P.flushzero()") METH (concat, "P.concat(PREFIX, SUFFIX)") METH (done, "P.done() -> TAG") #undef METHNAME @@ -1464,7 +1484,7 @@ static PyTypeObject poly1305key_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Poly1305 key.", +"poly1305(K): Poly1305 key.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -1535,6 +1555,539 @@ static PyTypeObject poly1305hash_pytype_skel = { 0 /* @tp_is_gc@ */ }; +/*----- Special snowflake for HSalsa and HChaCha --------------------------*/ + +#define DEF_HDANCE(DANCE, HDANCE, dance, hdance) \ + static PyObject *meth_##hdance##_prf(PyObject *me, PyObject *arg) \ + { \ + dance##_ctx dance; \ + char *k, *n; \ + Py_ssize_t ksz, nsz; \ + PyObject *rc; \ + if (!PyArg_ParseTuple(arg, "s#s#:" #hdance "_prf", \ + &k, &ksz, &n, &nsz)) \ + goto end; \ + if (ksz != DANCE##_KEYSZ) VALERR("bad key length"); \ + if (nsz != HDANCE##_INSZ) VALERR("bad input length"); \ + rc = bytestring_pywrap(0, HSALSA20_OUTSZ); \ + dance##_init(&dance, k, ksz, 0); \ + hdance##_prf(&dance, n, PyString_AS_STRING(rc)); \ + return (rc); \ + end: \ + return (0); \ + } + +DEF_HDANCE(SALSA20, HSALSA20, salsa20, hsalsa20) +DEF_HDANCE(SALSA20, HSALSA20, salsa20, hsalsa2012) +DEF_HDANCE(SALSA20, HSALSA20, salsa20, hsalsa208) + +DEF_HDANCE(CHACHA, HCHACHA, chacha, hchacha20) +DEF_HDANCE(CHACHA, HCHACHA, chacha, hchacha12) +DEF_HDANCE(CHACHA, HCHACHA, chacha, hchacha8) + +/*----- Keccak-p[1600, n] -------------------------------------------------*/ + +static PyTypeObject *kxvik_pytype; + +typedef struct kxvik_pyobj { + PyObject_HEAD + keccak1600_state s; + unsigned n; +} kxvik_pyobj; + +static PyObject *kxvik_pynew(PyTypeObject *ty, + PyObject *arg, PyObject *kw) +{ + unsigned n = 24; + kxvik_pyobj *rc = 0; + char *kwlist[] = { "nround", 0 }; + if (!PyArg_ParseTupleAndKeywords(arg, kw, "|O&:new", kwlist, + convuint, &n)) + goto end; + rc = (kxvik_pyobj *)ty->tp_alloc(ty, 0); + rc->n = n; + keccak1600_init(&rc->s); +end: + return ((PyObject *)rc); +} + +static PyObject *kxvikmeth_mix(PyObject *me, PyObject *arg) +{ + kxvik_pyobj *k = (kxvik_pyobj *)me; + kludge64 t[25]; + const octet *q; + octet buf[8]; + unsigned i; + char *p; Py_ssize_t n; + + if (!PyArg_ParseTuple(arg, "s#:mix", &p, &n)) goto end; + if (n > 200) VALERR("out of range"); + q = (const octet *)p; + i = 0; + while (n > 8) { LOAD64_L_(t[i], q); i++; q += 8; n -= 8; } + if (n) { + memcpy(buf, q, n); memset(buf + n, 0, 8 - n); + LOAD64_L_(t[i], buf); i++; + } + keccak1600_mix(&k->s, t, i); + RETURN_ME; +end: + return (0); +} + +static PyObject *kxvikmeth_extract(PyObject *me, PyObject *arg) +{ + kxvik_pyobj *k = (kxvik_pyobj *)me; + PyObject *rc = 0; + kludge64 t[25]; + octet *q, buf[8]; + unsigned i; + unsigned n; + + if (!PyArg_ParseTuple(arg, "O&:mix", convuint, &n)) goto end; + if (n > 200) VALERR("out of range"); + rc = bytestring_pywrap(0, n); + q = (octet *)PyString_AS_STRING(rc); + keccak1600_extract(&k->s, t, (n + 7)/8); + i = 0; + while (n > 8) { STORE64_L_(q, t[i]); i++; q += 8; n -= 8; } + if (n) { STORE64_L_(buf, t[i]); memcpy(q, buf, n); } +end: + return (rc); +} + +static PyObject *kxvikmeth_step(PyObject *me, PyObject *arg) +{ + kxvik_pyobj *k = (kxvik_pyobj *)me; + if (!PyArg_ParseTuple(arg, ":step")) return (0); + keccak1600_p(&k->s, &k->s, k->n); + RETURN_ME; +} + +static PyObject *kxvikget_nround(PyObject *me, void *hunoz) +{ + kxvik_pyobj *k = (kxvik_pyobj *)me; + return (PyInt_FromLong(k->n)); +} + +static int kxvikset_nround(PyObject *me, PyObject *val, void *hunoz) +{ + kxvik_pyobj *k = (kxvik_pyobj *)me; + unsigned n; + + if (!convuint(val, &n)) return (-1); + k->n = n; + return (0); +} + +static PyGetSetDef kxvik_pygetset[] = { +#define GETSETNAME(op, name) kxvik##op##_##name + GETSET(nround, "KECCAK.nround -> number of rounds") +#undef GETSETNAME + { 0 } +}; + +static PyMethodDef kxvik_pymethods[] = { +#define METHNAME(func) kxvikmeth_##func + METH (mix, "KECCAK.mix(DATA)") + METH (extract, "KECCAK.extract(NOCTETS)") + METH (step, "KECCAK.step()") +#undef METHNAME + { 0 } +}; + +static PyTypeObject kxvik_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "Keccak1600", /* @tp_name@ */ + sizeof(kxvik_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Keccak1600([nround = 24]): Keccak-p[1600, n] state.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + kxvik_pymethods, /* @tp_methods@ */ + 0, /* @tp_members@ */ + kxvik_pygetset, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + kxvik_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject *shake_pytype, *shake128_pytype, *shake256_pytype; + +typedef struct shake_pyobj { + PyObject_HEAD + int st; + shake_ctx h; +} shake_pyobj; + +#define SHAKE_H(o) (&((shake_pyobj *)(o))->h) +#define SHAKE_ST(o) (((shake_pyobj *)(o))->st) + +static PyObject *shake_dopynew(void (*initfn)(shake_ctx *, + const void *, size_t, + const void *, size_t), + PyTypeObject *ty, + PyObject *arg, PyObject *kw) +{ + shake_pyobj *rc = 0; + char *p = 0, *f = 0; + Py_ssize_t psz = 0, fsz = 0; + char *kwlist[] = { "perso", "func", 0 }; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "|s#s#:new", kwlist, + &p, &psz, &f, &fsz)) + goto end; + rc = (shake_pyobj *)ty->tp_alloc(ty, 0); + initfn(&rc->h, f, fsz, p, psz); + rc->st = 0; +end: + return ((PyObject *)rc); +} + +static PyObject *shake128_pynew(PyTypeObject *ty, + PyObject *arg, PyObject *kw) + { return (shake_dopynew(cshake128_init, ty, arg, kw)); } + +static PyObject *shake256_pynew(PyTypeObject *ty, + PyObject *arg, PyObject *kw) + { return (shake_dopynew(cshake256_init, ty, arg, kw)); } + +static int shake_check(PyObject *me, int st) +{ + if (SHAKE_ST(me) != st) VALERR("wrong state"); + return (0); +end: + return (-1); +} + +static PyObject *shakemeth_hash(PyObject *me, PyObject *arg) +{ + char *p; + Py_ssize_t sz; + if (!PyArg_ParseTuple(arg, "s#:hash", &p, &sz)) return (0); + if (shake_check(me, 0)) return (0); + shake_hash(SHAKE_H(me), p, sz); + RETURN_ME; +} + +#define SHAKEMETH_HASHU_(n, W, w) \ + static PyObject *shakemeth_hashu##w(PyObject *me, PyObject *arg) \ + { \ + uint##n x; \ + octet b[SZ_##W]; \ + if (!PyArg_ParseTuple(arg, "O&:hashu" #w, convu##n, &x)) goto end; \ + if (shake_check(me, 0)) goto end; \ + STORE##W(b, x); shake_hash(SHAKE_H(me), b, sizeof(b)); \ + RETURN_ME; \ + end: \ + return (0); \ + } +DOUINTCONV(SHAKEMETH_HASHU_) + +#define SHAKEMETH_HASHBUF_(n, W, w) \ + static PyObject *shakemeth_hashbuf##w(PyObject *me, PyObject *arg) \ + { \ + char *p; \ + Py_ssize_t sz; \ + octet b[SZ_##W]; \ + if (!PyArg_ParseTuple(arg, "s#:hashbuf" #w, &p, &sz)) goto end; \ + if (sz > MASK##n) TYERR("string too long"); \ + if (shake_check(me, 0)) goto end; \ + STORE##W(b, sz); shake_hash(SHAKE_H(me), b, sizeof(b)); \ + shake_hash(SHAKE_H(me), p, sz); \ + RETURN_ME; \ + end: \ + return (0); \ + } +DOUINTCONV(SHAKEMETH_HASHBUF_) + +static PyObject *shakemeth_hashstrz(PyObject *me, PyObject *arg) +{ + char *p; + if (!PyArg_ParseTuple(arg, "s:hashstrz", &p)) return (0); + if (shake_check(me, 0)) return (0); + shake_hash(SHAKE_H(me), p, strlen(p) + 1); + RETURN_ME; +} + +static PyObject *shakemeth_xof(PyObject *me, PyObject *arg) +{ + if (!PyArg_ParseTuple(arg, ":xof")) goto end; + if (shake_check(me, 0)) goto end; + shake_xof(SHAKE_H(me)); + SHAKE_ST(me) = 1; + RETURN_ME; +end: + return (0); +} + +static PyObject *shakemeth_done(PyObject *me, PyObject *arg) +{ + PyObject *rc = 0; + size_t n; + if (!PyArg_ParseTuple(arg, "O&:done", convszt, &n)) goto end; + if (shake_check(me, 0)) goto end; + rc = bytestring_pywrap(0, n); + shake_done(SHAKE_H(me), PyString_AS_STRING(rc), n); + SHAKE_ST(me) = -1; +end: + return (rc); +} + +static PyObject *shakemeth_copy(PyObject *me, PyObject *arg) +{ + shake_pyobj *rc = 0; + + if (!PyArg_ParseTuple(arg, ":copy")) goto end; + rc = PyObject_NEW(shake_pyobj, me->ob_type); + rc->h = *SHAKE_H(me); + rc->st = SHAKE_ST(me); +end: + return ((PyObject *)me); +} + +static PyObject *shakemeth_get(PyObject *me, PyObject *arg) +{ + PyObject *rc = 0; + size_t sz; + + if (!PyArg_ParseTuple(arg, "O&:get", convszt, &sz)) goto end; + if (shake_check(me, 1)) goto end; + rc = bytestring_pywrap(0, sz); + shake_get(SHAKE_H(me), PyString_AS_STRING(rc), sz); +end: + return (rc); +} + +static PyObject *shakemeth_mask(PyObject *me, PyObject *arg) +{ + PyObject *rc = 0; + char *p; Py_ssize_t sz; + + if (!PyArg_ParseTuple(arg, "s#:mask", &p, &sz)) goto end; + if (shake_check(me, 1)) goto end; + rc = bytestring_pywrap(0, sz); + shake_mask(SHAKE_H(me), p, PyString_AS_STRING(rc), sz); +end: + return (rc); +} + +static PyObject *shakeget_rate(PyObject *me, void *hunoz) + { return (PyInt_FromLong(SHAKE_H(me)->h.r)); } + +static PyObject *shakeget_buffered(PyObject *me, void *hunoz) + { return (PyInt_FromLong(SHAKE_H(me)->h.n)); } + +static PyObject *shakeget_state(PyObject *me, void *hunoz) +{ + int st = SHAKE_ST(me); + return (PyString_FromString(st == 0 ? "absorb" : + st == 1 ? "squeeze" : "dead")); +} + +static PyGetSetDef shake_pygetset[] = { +#define GETSETNAME(op, name) shake##op##_##name + GET (rate, "S.rate -> rate, in bytes") + GET (buffered, "S.buffered -> amount currently buffered") + GET (state, "S.state -> `absorb', `squeeze', `dead'") +#undef GETSETNAME + { 0 } +}; + +static PyMethodDef shake_pymethods[] = { +#define METHNAME(func) shakemeth_##func + METH (copy, "S.copy() -> SS") + METH (hash, "S.hash(M)") +#define METHU_(n, W, w) METH(hashu##w, "S.hashu" #w "(WORD)") + DOUINTCONV(METHU_) +#undef METHU_ +#define METHBUF_(n, W, w) METH(hashbuf##w, "S.hashbuf" #w "(BYTES)") + DOUINTCONV(METHBUF_) +#undef METHBUF_ + METH (hashstrz, "S.hashstrz(STRING)") + METH (xof, "S.xof()") + METH (done, "S.done(LEN) ->H") + METH (get, "S.get(LEN) -> H") + METH (mask, "S.mask(M) -> C") +#undef METHNAME + { 0 } +}; + +static PyTypeObject shake_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "Shake", /* @tp_name@ */ + sizeof(shake_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"SHAKE/cSHAKE base class.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + shake_pymethods, /* @tp_methods@ */ + 0, /* @tp_members@ */ + shake_pygetset, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject shake128_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "Shake128", /* @tp_name@ */ + 0, /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Shake128([perso = STR], [func = STR]): SHAKE128/cSHAKE128 XOF.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + shake128_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject shake256_pytype_skel = { + PyObject_HEAD_INIT(0) 0, /* Header */ + "Shake256", /* @tp_name@ */ + 0, /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ +"Shake256([perso = STR], [func = STR]): SHAKE256/cSHAKE256 XOF.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + shake256_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; /*----- Pseudorandom permutations -----------------------------------------*/ @@ -1597,7 +2150,7 @@ static PyObject *gprp_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) { char *kwlist[] = { "key", 0 }; char *k; - int sz; + Py_ssize_t sz; const prpinfo *prp = GCPRP_PRP(ty); PyObject *me; @@ -1643,7 +2196,7 @@ static PyObject *gcpget_blksz(PyObject *me, void *hunoz) static PyObject *gpmeth_encrypt(PyObject *me, PyObject *arg) { char *p; - int n; + Py_ssize_t n; PyObject *rc = 0; if (!PyArg_ParseTuple(arg, "s#:encrypt", &p, &n)) goto end; @@ -1657,7 +2210,7 @@ end: static PyObject *gpmeth_decrypt(PyObject *me, PyObject *arg) { char *p; - int n; + Py_ssize_t n; PyObject *rc = 0; if (!PyArg_ParseTuple(arg, "s#:decrypt", &p, &n)) goto end; @@ -1801,6 +2354,17 @@ toschnorr(N) -> M: convert work factor to Schnorr group order") toif(N) -> M: convert work factor to integer factorization problem size") METH (_KeySZ_toec, "\ toec(N) -> M: convert work factor to elliptic curve group order") + METH (_KeySZ_toec, "\ +toec(N) -> M: convert work factor to elliptic curve group order") +#define METH_HDANCE(hdance, HDance) METH(hdance##_prf, "\ +" #hdance "_prf(K, N) -> H: calculate " HDance " hash of N with K") + METH_HDANCE(hsalsa20, "HSalsa20") + METH_HDANCE(hsalsa2012, "HSalsa20/12") + METH_HDANCE(hsalsa208, "HSalsa20/8") + METH_HDANCE(hchacha20, "HChaCha20") + METH_HDANCE(hchacha12, "HChaCha12") + METH_HDANCE(hchacha8, "HChaCha8") +#undef METH_DANCE #undef METHNAME { 0 } }; @@ -1821,6 +2385,10 @@ void algorithms_pyinit(void) INITTYPE(poly1305cls, type); INITTYPE_META(poly1305key, type, poly1305cls); INITTYPE(poly1305hash, root); + INITTYPE(kxvik, root); + INITTYPE(shake, root); + INITTYPE(shake128, shake); + INITTYPE(shake256, shake); INITTYPE(gcprp, type); INITTYPE(gprp, root); addmethods(methods); @@ -1854,6 +2422,10 @@ void algorithms_pyinsert(PyObject *mod) INSERT("Poly1305Class", poly1305cls_pytype); INSERT("poly1305", poly1305key_pytype); INSERT("Poly1305Hash", poly1305hash_pytype); + INSERT("Keccak1600", kxvik_pytype); + INSERT("Shake", shake_pytype); + INSERT("Shake128", shake128_pytype); + INSERT("Shake256", shake256_pytype); INSERT("GCPRP", gcprp_pytype); INSERT("GPRP", gprp_pytype); INSERT("gcprps", gcprps());