2019-01-12 04:58:27 +00:00
|
|
|
// Copyright 2012 The Go Authors. All rights reserved.
|
|
|
|
// Use of this source code is governed by a BSD-style
|
|
|
|
// license that can be found in the LICENSE file.
|
|
|
|
|
2020-09-09 22:08:21 +00:00
|
|
|
// +build amd64,!gccgo,!appengine
|
2019-01-12 04:58:27 +00:00
|
|
|
|
|
|
|
package poly1305
|
|
|
|
|
|
|
|
//go:noescape
|
2020-09-09 22:08:21 +00:00
|
|
|
func initialize(state *[7]uint64, key *[32]byte)
|
2019-09-05 18:55:53 +00:00
|
|
|
|
2020-09-09 22:08:21 +00:00
|
|
|
//go:noescape
|
|
|
|
func update(state *[7]uint64, msg []byte)
|
|
|
|
|
|
|
|
//go:noescape
|
|
|
|
func finalize(tag *[TagSize]byte, state *[7]uint64)
|
|
|
|
|
|
|
|
// Sum generates an authenticator for m using a one-time key and puts the
|
|
|
|
// 16-byte result into out. Authenticating two different messages with the same
|
|
|
|
// key allows an attacker to forge messages at will.
|
|
|
|
func Sum(out *[16]byte, m []byte, key *[32]byte) {
|
|
|
|
h := newMAC(key)
|
|
|
|
h.Write(m)
|
|
|
|
h.Sum(out)
|
|
|
|
}
|
|
|
|
|
|
|
|
func newMAC(key *[32]byte) (h mac) {
|
|
|
|
initialize(&h.state, key)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
type mac struct {
|
|
|
|
state [7]uint64 // := uint64{ h0, h1, h2, r0, r1, pad0, pad1 }
|
|
|
|
|
|
|
|
buffer [TagSize]byte
|
|
|
|
offset int
|
|
|
|
}
|
2019-09-05 18:55:53 +00:00
|
|
|
|
2020-09-09 22:08:21 +00:00
|
|
|
func (h *mac) Write(p []byte) (n int, err error) {
|
|
|
|
n = len(p)
|
2019-09-05 18:55:53 +00:00
|
|
|
if h.offset > 0 {
|
2020-09-09 22:08:21 +00:00
|
|
|
remaining := TagSize - h.offset
|
|
|
|
if n < remaining {
|
|
|
|
h.offset += copy(h.buffer[h.offset:], p)
|
|
|
|
return n, nil
|
2019-09-05 18:55:53 +00:00
|
|
|
}
|
2020-09-09 22:08:21 +00:00
|
|
|
copy(h.buffer[h.offset:], p[:remaining])
|
|
|
|
p = p[remaining:]
|
2019-09-05 18:55:53 +00:00
|
|
|
h.offset = 0
|
2020-09-09 22:08:21 +00:00
|
|
|
update(&h.state, h.buffer[:])
|
2019-09-05 18:55:53 +00:00
|
|
|
}
|
2020-09-09 22:08:21 +00:00
|
|
|
if nn := len(p) - (len(p) % TagSize); nn > 0 {
|
|
|
|
update(&h.state, p[:nn])
|
|
|
|
p = p[nn:]
|
2019-09-05 18:55:53 +00:00
|
|
|
}
|
|
|
|
if len(p) > 0 {
|
|
|
|
h.offset += copy(h.buffer[h.offset:], p)
|
|
|
|
}
|
2020-09-09 22:08:21 +00:00
|
|
|
return n, nil
|
2019-09-05 18:55:53 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func (h *mac) Sum(out *[16]byte) {
|
2020-09-09 22:08:21 +00:00
|
|
|
state := h.state
|
2019-09-05 18:55:53 +00:00
|
|
|
if h.offset > 0 {
|
|
|
|
update(&state, h.buffer[:h.offset])
|
2019-01-12 04:58:27 +00:00
|
|
|
}
|
2020-09-09 22:08:21 +00:00
|
|
|
finalize(out, &state)
|
2019-01-12 04:58:27 +00:00
|
|
|
}
|