pallet_evm_precompile_blake2/
eip_152.rs

1// This file is part of Frontier.
2
3// Copyright (C) Parity Technologies (UK) Ltd.
4// SPDX-License-Identifier: Apache-2.0
5
6// Licensed under the Apache License, Version 2.0 (the "License");
7// you may not use this file except in compliance with the License.
8// You may obtain a copy of the License at
9//
10// 	http://www.apache.org/licenses/LICENSE-2.0
11//
12// Unless required by applicable law or agreed to in writing, software
13// distributed under the License is distributed on an "AS IS" BASIS,
14// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15// See the License for the specific language governing permissions and
16// limitations under the License.
17
18/// The precomputed values for BLAKE2b [from the spec](https://tools.ietf.org/html/rfc7693#section-2.7)
19/// There are 10 16-byte arrays - one for each round
20/// the entries are calculated from the sigma constants.
21const SIGMA: [[usize; 16]; 10] = [
22	[0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15],
23	[14, 10, 4, 8, 9, 15, 13, 6, 1, 12, 0, 2, 11, 7, 5, 3],
24	[11, 8, 12, 0, 5, 2, 15, 13, 10, 14, 3, 6, 7, 1, 9, 4],
25	[7, 9, 3, 1, 13, 12, 11, 14, 2, 6, 5, 10, 4, 0, 15, 8],
26	[9, 0, 5, 7, 2, 4, 10, 15, 14, 1, 11, 12, 6, 8, 3, 13],
27	[2, 12, 6, 10, 0, 11, 8, 3, 4, 13, 7, 5, 15, 14, 1, 9],
28	[12, 5, 1, 15, 14, 13, 4, 10, 0, 7, 6, 3, 9, 2, 8, 11],
29	[13, 11, 7, 14, 12, 1, 3, 9, 5, 0, 15, 4, 8, 6, 2, 10],
30	[6, 15, 14, 9, 11, 3, 0, 8, 12, 2, 13, 7, 1, 4, 10, 5],
31	[10, 2, 8, 4, 7, 6, 1, 5, 15, 11, 9, 14, 3, 12, 13, 0],
32];
33
34/// IV is the initialization vector for BLAKE2b. See https://tools.ietf.org/html/rfc7693#section-2.6
35/// for details.
36const IV: [u64; 8] = [
37	0x6a09e667f3bcc908,
38	0xbb67ae8584caa73b,
39	0x3c6ef372fe94f82b,
40	0xa54ff53a5f1d36f1,
41	0x510e527fade682d1,
42	0x9b05688c2b3e6c1f,
43	0x1f83d9abfb41bd6b,
44	0x5be0cd19137e2179,
45];
46
47#[inline(always)]
48/// The G mixing function. See https://tools.ietf.org/html/rfc7693#section-3.1
49fn g(v: &mut [u64], a: usize, b: usize, c: usize, d: usize, x: u64, y: u64) {
50	v[a] = v[a].wrapping_add(v[b]).wrapping_add(x);
51	v[d] = (v[d] ^ v[a]).rotate_right(32);
52	v[c] = v[c].wrapping_add(v[d]);
53	v[b] = (v[b] ^ v[c]).rotate_right(24);
54	v[a] = v[a].wrapping_add(v[b]).wrapping_add(y);
55	v[d] = (v[d] ^ v[a]).rotate_right(16);
56	v[c] = v[c].wrapping_add(v[d]);
57	v[b] = (v[b] ^ v[c]).rotate_right(63);
58}
59
60/// The Blake2 compression function F. See https://tools.ietf.org/html/rfc7693#section-3.2
61/// Takes as an argument the state vector `h`, message block vector `m`, offset counter `t`, final
62/// block indicator flag `f`, and number of rounds `rounds`. The state vector provided as the first
63/// parameter is modified by the function.
64pub fn compress(h: &mut [u64; 8], m: [u64; 16], t: [u64; 2], f: bool, rounds: usize) {
65	let mut v = [0u64; 16];
66	v[..h.len()].copy_from_slice(h); // First half from state.
67	v[h.len()..].copy_from_slice(&IV); // Second half from IV.
68
69	v[12] ^= t[0];
70	v[13] ^= t[1];
71
72	if f {
73		v[14] = !v[14] // Invert all bits if the last-block-flag is set.
74	}
75	for i in 0..rounds {
76		// Message word selection permutation for this round.
77		let s = &SIGMA[i % 10];
78		g(&mut v, 0, 4, 8, 12, m[s[0]], m[s[1]]);
79		g(&mut v, 1, 5, 9, 13, m[s[2]], m[s[3]]);
80		g(&mut v, 2, 6, 10, 14, m[s[4]], m[s[5]]);
81		g(&mut v, 3, 7, 11, 15, m[s[6]], m[s[7]]);
82
83		g(&mut v, 0, 5, 10, 15, m[s[8]], m[s[9]]);
84		g(&mut v, 1, 6, 11, 12, m[s[10]], m[s[11]]);
85		g(&mut v, 2, 7, 8, 13, m[s[12]], m[s[13]]);
86		g(&mut v, 3, 4, 9, 14, m[s[14]], m[s[15]]);
87	}
88
89	for i in 0..8 {
90		h[i] ^= v[i] ^ v[i + 8];
91	}
92}