2 SipHash reference C implementation
5 Jean-Philippe Aumasson <jeanphilippe.aumasson@gmail.com>
6 Daniel J. Bernstein <djb@cr.yp.to>
8 To the extent possible under law, the author(s) have dedicated all copyright
9 and related and neighboring rights to this software to the public domain
10 worldwide. This software is distributed without any warranty.
12 You should have received a copy of the CC0 Public Domain Dedication along with
13 this software. If not, see <http://creativecommons.org/publicdomain/zero/1.0/>.
15 (Minimal changes made by Lennart Poettering, to make clean for inclusion in systemd)
21 #include "siphash24.h"
27 #define ROTL(x,b) (u64)( ((x) << (b)) | ( (x) >> (64 - (b))) )
29 #define U32TO8_LE(p, v) \
30 (p)[0] = (u8)((v) ); (p)[1] = (u8)((v) >> 8); \
31 (p)[2] = (u8)((v) >> 16); (p)[3] = (u8)((v) >> 24);
33 #define U64TO8_LE(p, v) \
34 U32TO8_LE((p), (u32)((v) )); \
35 U32TO8_LE((p) + 4, (u32)((v) >> 32));
37 #define U8TO64_LE(p) \
39 ((u64)((p)[1]) << 8) | \
40 ((u64)((p)[2]) << 16) | \
41 ((u64)((p)[3]) << 24) | \
42 ((u64)((p)[4]) << 32) | \
43 ((u64)((p)[5]) << 40) | \
44 ((u64)((p)[6]) << 48) | \
45 ((u64)((p)[7]) << 56))
47 #define SIPROUND(state) \
49 (state)->v0 += (state)->v1; (state)->v1=ROTL((state)->v1,13); (state)->v1 ^= (state)->v0; (state)->v0=ROTL((state)->v0,32); \
50 (state)->v2 += (state)->v3; (state)->v3=ROTL((state)->v3,16); (state)->v3 ^= (state)->v2; \
51 (state)->v0 += (state)->v3; (state)->v3=ROTL((state)->v3,21); (state)->v3 ^= (state)->v0; \
52 (state)->v2 += (state)->v1; (state)->v1=ROTL((state)->v1,17); (state)->v1 ^= (state)->v2; (state)->v2=ROTL((state)->v2,32); \
55 void siphash_init(struct siphash *state, const uint8_t k[16]) {
59 k1 = U8TO64_LE( k + 8 );
61 /* "somepseudorandomlygeneratedbytes" */
62 state->v0 = 0x736f6d6570736575ULL ^ k0;
63 state->v1 = 0x646f72616e646f6dULL ^ k1;
64 state->v2 = 0x6c7967656e657261ULL ^ k0;
65 state->v3 = 0x7465646279746573ULL ^ k1;
70 void siphash24_compress(const void *_in, size_t inlen, struct siphash *state) {
73 const u8 *end = in + inlen;
74 int left = state->inlen & 7;
76 /* update total length */
77 state->inlen += inlen;
79 /* if padding exists, fill it out */
81 for ( ; in < end && left < 8; in ++, left ++ )
82 state->padding |= ( ( u64 )*in ) << (left * 8);
84 if (in == end && left < 8)
85 /* we did not have enough input to fill out the padding completely */
89 printf( "(%3d) v0 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v0 >> 32 ), ( u32 )state->v0 );
90 printf( "(%3d) v1 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v1 >> 32 ), ( u32 )state->v1 );
91 printf( "(%3d) v2 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v2 >> 32 ), ( u32 )state->v2 );
92 printf( "(%3d) v3 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v3 >> 32 ), ( u32 )state->v3 );
93 printf( "(%3d) compress padding %08x %08x\n", ( int )state->inlen, ( u32 )( state->padding >> 32 ), ( u32 )state->padding );
95 state->v3 ^= state->padding;
98 state->v0 ^= state->padding;
103 end -= ( state->inlen % sizeof (u64) );
105 for ( ; in < end; in += 8 )
109 printf( "(%3d) v0 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v0 >> 32 ), ( u32 )state->v0 );
110 printf( "(%3d) v1 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v1 >> 32 ), ( u32 )state->v1 );
111 printf( "(%3d) v2 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v2 >> 32 ), ( u32 )state->v2 );
112 printf( "(%3d) v3 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v3 >> 32 ), ( u32 )state->v3 );
113 printf( "(%3d) compress %08x %08x\n", ( int )state->inlen, ( u32 )( m >> 32 ), ( u32 )m );
121 left = state->inlen & 7;
125 case 7: state->padding |= ( ( u64 )in[ 6] ) << 48;
127 case 6: state->padding |= ( ( u64 )in[ 5] ) << 40;
129 case 5: state->padding |= ( ( u64 )in[ 4] ) << 32;
131 case 4: state->padding |= ( ( u64 )in[ 3] ) << 24;
133 case 3: state->padding |= ( ( u64 )in[ 2] ) << 16;
135 case 2: state->padding |= ( ( u64 )in[ 1] ) << 8;
137 case 1: state->padding |= ( ( u64 )in[ 0] ); break;
143 uint64_t siphash24_finalize(struct siphash *state) {
146 b = state->padding | (( ( u64 )state->inlen ) << 56);
148 printf( "(%3d) v0 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v0 >> 32 ), ( u32 )state->v0 );
149 printf( "(%3d) v1 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v1 >> 32 ), ( u32 )state->v1 );
150 printf( "(%3d) v2 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v2 >> 32 ), ( u32 )state->v2 );
151 printf( "(%3d) v3 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v3 >> 32 ), ( u32 )state->v3 );
152 printf( "(%3d) padding %08x %08x\n", ( int )state->inlen, ( u32 )( state->padding >> 32 ), ( u32 )state->padding );
160 printf( "(%3d) v0 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v0 >> 32 ), ( u32 )state->v0 );
161 printf( "(%3d) v1 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v1 >> 32 ), ( u32 )state->v1 );
162 printf( "(%3d) v2 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v2 >> 32 ), ( u32 )state->v2 );
163 printf( "(%3d) v3 %08x %08x\n", ( int )state->inlen, ( u32 )( state->v3 >> 32 ), ( u32 )state->v3 );
171 return state->v0 ^ state->v1 ^ state->v2 ^ state->v3;
175 void siphash24(uint8_t out[8], const void *_in, size_t inlen, const uint8_t k[16])
177 struct siphash state;
180 siphash_init(&state, k);
182 siphash24_compress(_in, inlen, &state);
184 b = siphash24_finalize(&state);