ReactOS 0.4.17-dev-1005-g171e1de
sha512.c File Reference
#include "precomp.h"
#include "hash_pattern.c"
Include dependency graph for sha512.c:

Go to the source code of this file.

Macros

#define ALG   SHA384
 
#define Alg   Sha384
 
#define ALG   SHA512
 
#define Alg   Sha512
 
#define ALG   SHA512_224
 
#define Alg   Sha512_224
 
#define ALG   SHA512_256
 
#define Alg   Sha512_256
 
#define MAJ(x, y, z)   ((((z) | (y)) & (x) ) | ((z) & (y)))
 
#define CH(x, y, z)   ((((z) ^ (y)) & (x)) ^ (z))
 
#define CSIGMA0(x)   (ROR64((ROR64((x), 6) ^ ROR64((x), 11) ^ (x)), 28))
 
#define CSIGMA1(x)   (ROR64((ROR64((x), 4) ^ ROR64((x), 27) ^ (x)), 14))
 
#define LSIGMA0(x)   (ROR64((x) ^ ROR64((x), 7), 1) ^ ((x)>> 7))
 
#define LSIGMA1(x)   (ROR64((x) ^ ROR64((x), 42), 19) ^ ((x)>> 6))
 
#define CROUND(a, b, c, d, e, f, g, h, r, r16)
 
#define IROUND(a, b, c, d, e, f, g, h, r)
 
#define FROUND(a, b, c, d, e, f, g, h, r, r16)
 
#define EXPAND(a, b, c, d, r)
 
#define DO_ROUND(a, b, c, d, t, r)
 
#define EXPAND(a, b, c, d, r)
 
#define DO_ROUND(a, b, c, d, e, f, g, h, r)
 

Functions

 SYMCRYPT_ALIGN_AT (64) const
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Init (_Out_ PSYMCRYPT_SHA512_STATE pState)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Init (_Out_ PSYMCRYPT_SHA384_STATE pState)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Init (_Out_ PSYMCRYPT_SHA512_224_STATE pState)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Init (_Out_ PSYMCRYPT_SHA512_256_STATE pState)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Append (_Inout_ PSYMCRYPT_SHA512_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Append (_Inout_ PSYMCRYPT_SHA384_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Append (_Inout_ PSYMCRYPT_SHA512_224_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Append (_Inout_ PSYMCRYPT_SHA512_256_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Result (_Inout_ PSYMCRYPT_SHA512_STATE pState, _Out_writes_(SYMCRYPT_SHA512_RESULT_SIZE) PBYTE pbResult)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Result (_Inout_ PSYMCRYPT_SHA384_STATE pState, _Out_writes_(SYMCRYPT_SHA384_RESULT_SIZE) PBYTE pbResult)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Result (_Inout_ PSYMCRYPT_SHA512_224_STATE pState, _Out_writes_(SYMCRYPT_SHA512_224_RESULT_SIZE) PBYTE pbResult)
 
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Result (_Inout_ PSYMCRYPT_SHA512_256_STATE pState, _Out_writes_(SYMCRYPT_SHA512_256_RESULT_SIZE) PBYTE pbResult)
 
VOID SYMCRYPT_CALL SymCryptSha512StateExportCore (_In_ PCSYMCRYPT_SHA512_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PBYTE pbBlob, _In_ UINT32 type)
 
VOID SYMCRYPT_CALL SymCryptSha512StateExport (_In_ PCSYMCRYPT_SHA512_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PBYTE pbBlob)
 
VOID SYMCRYPT_CALL SymCryptSha384StateExport (_In_ PCSYMCRYPT_SHA384_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA384_STATE_EXPORT_SIZE) PBYTE pbBlob)
 
VOID SYMCRYPT_CALL SymCryptSha512_224StateExport (_In_ PCSYMCRYPT_SHA512_224_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA512_224_STATE_EXPORT_SIZE) PBYTE pbBlob)
 
VOID SYMCRYPT_CALL SymCryptSha512_256StateExport (_In_ PCSYMCRYPT_SHA512_256_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA512_256_STATE_EXPORT_SIZE) PBYTE pbBlob)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha512StateImportCore (_Out_ PSYMCRYPT_SHA512_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PCBYTE pbBlob, _In_ UINT32 type)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha512StateImport (_Out_ PSYMCRYPT_SHA512_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PCBYTE pbBlob)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha384StateImport (_Out_ PSYMCRYPT_SHA384_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA384_STATE_EXPORT_SIZE) PCBYTE pbBlob)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha512_224StateImport (_Out_ PSYMCRYPT_SHA512_224_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA512_224_STATE_EXPORT_SIZE) PCBYTE pbBlob)
 
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha512_256StateImport (_Out_ PSYMCRYPT_SHA512_256_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA512_256_STATE_EXPORT_SIZE) PCBYTE pbBlob)
 
VOID SYMCRYPT_CALL SymCryptSha512Selftest (void)
 
VOID SYMCRYPT_CALL SymCryptSha384Selftest (void)
 
VOID SYMCRYPT_CALL SymCryptSha512_224Selftest (void)
 
VOID SYMCRYPT_CALL SymCryptSha512_256Selftest (void)
 
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_ull (_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
 
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_ull2 (_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
 
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_ull3 (_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
 
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks (_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
 

Variables

const UINT64 SymCryptSha512InitialState [8]
 
const UINT64 SymCryptSha384InitialState [8]
 
const UINT64 SymCryptSha512_224InitialState [8]
 
const UINT64 SymCryptSha512_256InitialState [8]
 
const SYMCRYPT_HASH SymCryptSha384Algorithm_default
 
const SYMCRYPT_HASH SymCryptSha512Algorithm_default
 
const SYMCRYPT_HASH SymCryptSha512_224Algorithm_default
 
const SYMCRYPT_HASH SymCryptSha512_256Algorithm_default
 
const PCSYMCRYPT_HASH SymCryptSha384Algorithm = &SymCryptSha384Algorithm_default
 
const PCSYMCRYPT_HASH SymCryptSha512Algorithm = &SymCryptSha512Algorithm_default
 
const PCSYMCRYPT_HASH SymCryptSha512_224Algorithm = &SymCryptSha512_224Algorithm_default
 
const PCSYMCRYPT_HASH SymCryptSha512_256Algorithm = &SymCryptSha512_256Algorithm_default
 
const BYTE SymCryptSha512KATAnswer [64]
 
const BYTE SymCryptSha384KATAnswer [48]
 
const BYTE SymCryptSha512_224KATAnswer [28]
 
const BYTE SymCryptSha512_256KATAnswer [32]
 

Macro Definition Documentation

◆ ALG [1/4]

#define ALG   SHA384

Definition at line 204 of file sha512.c.

◆ Alg [1/4]

#define Alg   Sha384

Definition at line 205 of file sha512.c.

◆ ALG [2/4]

#define ALG   SHA512

Definition at line 204 of file sha512.c.

◆ Alg [2/4]

#define Alg   Sha512

Definition at line 205 of file sha512.c.

◆ ALG [3/4]

#define ALG   SHA512_224

Definition at line 204 of file sha512.c.

◆ Alg [3/4]

#define Alg   Sha512_224

Definition at line 205 of file sha512.c.

◆ ALG [4/4]

#define ALG   SHA512_256

Definition at line 204 of file sha512.c.

◆ Alg [4/4]

#define Alg   Sha512_256

Definition at line 205 of file sha512.c.

◆ CH

#define CH (   x,
  y,
  z 
)    ((((z) ^ (y)) & (x)) ^ (z))

Definition at line 832 of file sha512.c.

◆ CROUND

#define CROUND (   a,
  b,
  c,
  d,
  e,
  f,
  g,
  h,
  r,
  r16 
)
Value:
{;\
W[r16] = Wt; \
h += CSIGMA1(e) + CH(e, f, g) + SymCryptSha512K[r] + Wt;\
d += h;\
h += CSIGMA0(a) + MAJ(a, b, c);\
}
GLdouble GLdouble GLdouble r
Definition: gl.h:2055
const GLubyte * c
Definition: glext.h:8905
GLfloat f
Definition: glext.h:7540
GLboolean GLboolean GLboolean b
Definition: glext.h:6204
GLboolean GLboolean g
Definition: glext.h:6204
GLboolean GLboolean GLboolean GLboolean a
Definition: glext.h:6204
GLfloat GLfloat GLfloat GLfloat h
Definition: glext.h:7723
#define d
Definition: ke_i.h:81
#define e
Definition: ke_i.h:82
#define CH(x, y, z)
Definition: sha512.c:832
#define CSIGMA0(x)
Definition: sha512.c:843
#define MAJ(x, y, z)
Definition: sha512.c:831
#define CSIGMA1(x)
Definition: sha512.c:844
Definition: polytest.cpp:36

Definition at line 875 of file sha512.c.

◆ CSIGMA0

#define CSIGMA0 (   x)    (ROR64((ROR64((x), 6) ^ ROR64((x), 11) ^ (x)), 28))

Definition at line 843 of file sha512.c.

◆ CSIGMA1

#define CSIGMA1 (   x)    (ROR64((ROR64((x), 4) ^ ROR64((x), 27) ^ (x)), 14))

Definition at line 844 of file sha512.c.

◆ DO_ROUND [1/2]

#define DO_ROUND (   a,
  b,
  c,
  d,
  e,
  f,
  g,
  h,
  r 
)
Value:
h += W[r] + CSIGMA1( e ) + CH( e, f, g ) + SymCryptSha512K[r]; \
d += h; \
h += CSIGMA0( a ) + MAJ( c, b, a );

◆ DO_ROUND [2/2]

#define DO_ROUND (   a,
  b,
  c,
  d,
  t,
  r 
)
Value:
t = W[r] + CSIGMA1( W[r-5] ) + W[r-8] + CH( W[r-5], W[r-6], W[r-7] ) + SymCryptSha512K[r]; \
W[r-4] = t + d; \
d = t + CSIGMA0( a ) + MAJ( c, b, a );
GLdouble GLdouble t
Definition: gl.h:2047

◆ EXPAND [1/2]

#define EXPAND (   a,
  b,
  c,
  d,
  r 
)
Value:
c = W[r-15]; \
b = d + LSIGMA1( b ) + W[r-7] + LSIGMA0( c ); \
W[r] = b; \
#define b
Definition: ke_i.h:79
#define LSIGMA1(x)
Definition: sha512.c:846
#define LSIGMA0(x)
Definition: sha512.c:845

◆ EXPAND [2/2]

#define EXPAND (   a,
  b,
  c,
  d,
  r 
)
Value:
c = W[r-15]; \
b = d + LSIGMA1( b ) + W[r-7] + LSIGMA0( c ); \
W[r] = b; \

◆ FROUND

#define FROUND (   a,
  b,
  c,
  d,
  e,
  f,
  g,
  h,
  r,
  r16 
)
Value:
{ \
Wt = LSIGMA1( W[(r16-2) & 15] ) + W[(r16-7) & 15] + \
LSIGMA0( W[(r16-15) & 15]) + W[r16 & 15]; \
CROUND( a, b, c, d, e, f, g, h, r, r16 ); \
}

Definition at line 895 of file sha512.c.

◆ IROUND

#define IROUND (   a,
  b,
  c,
  d,
  e,
  f,
  g,
  h,
  r 
)
Value:
{\
CROUND( a, b, c, d, e, f, g, h, r, r);\
}
#define SYMCRYPT_LOAD_MSBFIRST64(p)
Definition: symcrypt.h:304
PCBYTE pbData

Definition at line 886 of file sha512.c.

◆ LSIGMA0

#define LSIGMA0 (   x)    (ROR64((x) ^ ROR64((x), 7), 1) ^ ((x)>> 7))

Definition at line 845 of file sha512.c.

◆ LSIGMA1

#define LSIGMA1 (   x)    (ROR64((x) ^ ROR64((x), 42), 19) ^ ((x)>> 6))

Definition at line 846 of file sha512.c.

◆ MAJ

#define MAJ (   x,
  y,
  z 
)    ((((z) | (y)) & (x) ) | ((z) & (y)))

Definition at line 831 of file sha512.c.

Function Documentation

◆ SYMCRYPT_ALIGN_AT()

SYMCRYPT_ALIGN_AT ( 64  ) const

Definition at line 22 of file sha512.c.

22 {
23 0x428a2f98d728ae22UL, 0x7137449123ef65cdUL,
24 0xb5c0fbcfec4d3b2fUL, 0xe9b5dba58189dbbcUL,
25 0x3956c25bf348b538UL, 0x59f111f1b605d019UL,
26 0x923f82a4af194f9bUL, 0xab1c5ed5da6d8118UL,
27 0xd807aa98a3030242UL, 0x12835b0145706fbeUL,
28 0x243185be4ee4b28cUL, 0x550c7dc3d5ffb4e2UL,
29 0x72be5d74f27b896fUL, 0x80deb1fe3b1696b1UL,
30 0x9bdc06a725c71235UL, 0xc19bf174cf692694UL,
31 0xe49b69c19ef14ad2UL, 0xefbe4786384f25e3UL,
32 0x0fc19dc68b8cd5b5UL, 0x240ca1cc77ac9c65UL,
33 0x2de92c6f592b0275UL, 0x4a7484aa6ea6e483UL,
34 0x5cb0a9dcbd41fbd4UL, 0x76f988da831153b5UL,
35 0x983e5152ee66dfabUL, 0xa831c66d2db43210UL,
36 0xb00327c898fb213fUL, 0xbf597fc7beef0ee4UL,
37 0xc6e00bf33da88fc2UL, 0xd5a79147930aa725UL,
38 0x06ca6351e003826fUL, 0x142929670a0e6e70UL,
39 0x27b70a8546d22ffcUL, 0x2e1b21385c26c926UL,
40 0x4d2c6dfc5ac42aedUL, 0x53380d139d95b3dfUL,
41 0x650a73548baf63deUL, 0x766a0abb3c77b2a8UL,
42 0x81c2c92e47edaee6UL, 0x92722c851482353bUL,
43 0xa2bfe8a14cf10364UL, 0xa81a664bbc423001UL,
44 0xc24b8b70d0f89791UL, 0xc76c51a30654be30UL,
45 0xd192e819d6ef5218UL, 0xd69906245565a910UL,
46 0xf40e35855771202aUL, 0x106aa07032bbd1b8UL,
47 0x19a4c116b8d2d0c8UL, 0x1e376c085141ab53UL,
48 0x2748774cdf8eeb99UL, 0x34b0bcb5e19b48a8UL,
49 0x391c0cb3c5c95a63UL, 0x4ed8aa4ae3418acbUL,
50 0x5b9cca4f7763e373UL, 0x682e6ff3d6b2b8a3UL,
51 0x748f82ee5defb2fcUL, 0x78a5636f43172f60UL,
52 0x84c87814a1f0ab72UL, 0x8cc702081a6439ecUL,
53 0x90befffa23631e28UL, 0xa4506cebde82bde9UL,
54 0xbef9a3f7b2c67915UL, 0xc67178f2e372532bUL,
55 0xca273eceea26619cUL, 0xd186b8c721c0c207UL,
56 0xeada7dd6cde0eb1eUL, 0xf57d4f7fee6ed178UL,
57 0x06f067aa72176fbaUL, 0x0a637dc5a2c898a6UL,
58 0x113f9804bef90daeUL, 0x1b710b35131c471bUL,
59 0x28db77f523047d84UL, 0x32caab7b40c72493UL,
60 0x3c9ebe0a15c9bebcUL, 0x431d67c49c100d4cUL,
61 0x4cc5d4becb3e42b6UL, 0x597f299cfc657e2aUL,
62 0x5fcb6fab3ad6faecUL, 0x6c44198c4a475817UL,
63};

◆ SymCryptSha384Append()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Append ( _Inout_ PSYMCRYPT_SHA384_STATE  pState,
_In_reads_(cbData) PCBYTE  pbData,
SIZE_T  cbData 
)

Definition at line 370 of file sha512.c.

374{
375
377
378}
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Append(_Inout_ PSYMCRYPT_SHA512_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: sha512.c:294
PCBYTE PBYTE SIZE_T cbData
* PSYMCRYPT_SHA512_STATE
PSYMCRYPT_COMMON_HASH_STATE pState

◆ SymCryptSha384Init()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Init ( _Out_ PSYMCRYPT_SHA384_STATE  pState)

Definition at line 234 of file sha512.c.

235{
237
238 pState->dataLengthH = 0;
239 pState->dataLengthL = 0;
240 pState->bytesInBuffer = 0;
241
243
244 //
245 // There is no need to initialize the buffer part of the state as that will be
246 // filled before it is used.
247 //
248}
#define memcpy(s1, s2, n)
Definition: mkisofs.h:878
const UINT64 SymCryptSha384InitialState[8]
Definition: sha512.c:79
#define SYMCRYPT_SET_MAGIC(p)

Referenced by SymCryptSha384Result().

◆ SymCryptSha384Result()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Result ( _Inout_ PSYMCRYPT_SHA384_STATE  pState,
_Out_writes_(SYMCRYPT_SHA384_RESULT_SIZE) PBYTE  pbResult 
)

Definition at line 460 of file sha512.c.

463{
464 //
465 // For simplicity we re-use SymCryptSha512Result. This is slightly slower,
466 // but SHA-384 isn't used that much.
467 //
468 SYMCRYPT_ALIGN BYTE sha512Result[SYMCRYPT_SHA512_RESULT_SIZE]; // Buffer for SHA-512 output
469
470 //
471 // The SHA-384 result is the first 48 bytes of the SHA-512 result of our state
472 //
475
476 //
477 // The buffer was already wiped by the SymCryptSha512Result function, we
478 // just have to re-initialize for SHA-384
479 //
481
482 SymCryptWipeKnownSize( sha512Result, sizeof( sha512Result ) );
483}
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Init(_Out_ PSYMCRYPT_SHA384_STATE pState)
Definition: sha512.c:234
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Result(_Inout_ PSYMCRYPT_SHA512_STATE pState, _Out_writes_(SYMCRYPT_SHA512_RESULT_SIZE) PBYTE pbResult)
Definition: sha512.c:406
static const BYTE pbResult[]
FORCEINLINE VOID SYMCRYPT_CALL SymCryptWipeKnownSize(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)
#define SYMCRYPT_SHA384_RESULT_SIZE
Definition: symcrypt.h:1287
#define SYMCRYPT_SHA512_RESULT_SIZE
Definition: symcrypt.h:1352
#define SYMCRYPT_ALIGN
unsigned char BYTE
Definition: xxhash.c:193

◆ SymCryptSha384Selftest()

VOID SYMCRYPT_CALL SymCryptSha384Selftest ( void  )

Definition at line 740 of file sha512.c.

741{
743
745
746 SymCryptInjectError( result, sizeof( result ) );
747
748 if( memcmp( result, SymCryptSha384KATAnswer, sizeof( result ) ) != 0 ) {
749 SymCryptFatal( 'SH38' );
750 }
751}
_ACRTIMP int __cdecl memcmp(const void *, const void *, size_t)
Definition: string.c:2807
GLuint64EXT * result
Definition: glext.h:11304
VOID SYMCRYPT_CALL SymCryptInjectError(PBYTE pbData, SIZE_T cbData)
const BYTE SymCryptTestMsg3[3]
Definition: selftest.c:8
const BYTE SymCryptSha384KATAnswer[48]
Definition: sha512.c:728
_Analysis_noreturn_ VOID SYMCRYPT_CALL SymCryptFatal(UINT32 fatalCode)
VOID SYMCRYPT_CALL SymCryptSha384(_In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_SHA384_RESULT_SIZE) PBYTE pbResult)

◆ SymCryptSha384StateExport()

Definition at line 584 of file sha512.c.

587{
589}
@ SymCryptBlobTypeSha384State
Definition: sc_lib.h:1066
VOID SYMCRYPT_CALL SymCryptSha512StateExportCore(_In_ PCSYMCRYPT_SHA512_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PBYTE pbBlob, _In_ UINT32 type)
Definition: sha512.c:538
const SYMCRYPT_SHA512_STATE * PCSYMCRYPT_SHA512_STATE

◆ SymCryptSha384StateImport()

Definition at line 663 of file sha512.c.

666{
668}
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha512StateImportCore(_Out_ PSYMCRYPT_SHA512_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PCBYTE pbBlob, _In_ UINT32 type)
Definition: sha512.c:612

◆ SymCryptSha512_224Append()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Append ( _Inout_ PSYMCRYPT_SHA512_224_STATE  pState,
_In_reads_(cbData) PCBYTE  pbData,
SIZE_T  cbData 
)

Definition at line 383 of file sha512.c.

◆ SymCryptSha512_224Init()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Init ( _Out_ PSYMCRYPT_SHA512_224_STATE  pState)

Definition at line 254 of file sha512.c.

255{
257
258 pState->dataLengthH = 0;
259 pState->dataLengthL = 0;
260 pState->bytesInBuffer = 0;
261
263
264 //
265 // There is no need to initialize the buffer part of the state as that will be
266 // filled before it is used.
267 //
268}
const UINT64 SymCryptSha512_224InitialState[8]
Definition: sha512.c:90

Referenced by SymCryptSha512_224Result().

◆ SymCryptSha512_224Result()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Result ( _Inout_ PSYMCRYPT_SHA512_224_STATE  pState,
_Out_writes_(SYMCRYPT_SHA512_224_RESULT_SIZE) PBYTE  pbResult 
)

Definition at line 489 of file sha512.c.

492{
493 SYMCRYPT_ALIGN BYTE sha512Result[SYMCRYPT_SHA512_RESULT_SIZE]; // Buffer for SHA-512 output
494
495 //
496 // The SHA-512/224 result is the first 28 bytes of the SHA-512 result of our state
497 //
500
501 //
502 // The buffer was already wiped by the SymCryptSha512Result function, we
503 // just have to re-initialize for SHA-512/224
504 //
506
507 SymCryptWipeKnownSize( sha512Result, sizeof( sha512Result ) );
508}
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Init(_Out_ PSYMCRYPT_SHA512_224_STATE pState)
Definition: sha512.c:254
#define SYMCRYPT_SHA512_224_RESULT_SIZE
Definition: symcrypt.h:1420

◆ SymCryptSha512_224Selftest()

VOID SYMCRYPT_CALL SymCryptSha512_224Selftest ( void  )

Definition at line 767 of file sha512.c.

768{
770
772
773 SymCryptInjectError( result, sizeof( result ) );
774
775 if( memcmp( result, SymCryptSha512_224KATAnswer, sizeof( result ) ) != 0 ) {
776 SymCryptFatal( 'SH51' );
777 }
778}
const BYTE SymCryptSha512_224KATAnswer[28]
Definition: sha512.c:757
VOID SYMCRYPT_CALL SymCryptSha512_224(_In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_SHA512_224_RESULT_SIZE) PBYTE pbResult)

◆ SymCryptSha512_224StateExport()

Definition at line 593 of file sha512.c.

◆ SymCryptSha512_224StateImport()

◆ SymCryptSha512_256Append()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Append ( _Inout_ PSYMCRYPT_SHA512_256_STATE  pState,
_In_reads_(cbData) PCBYTE  pbData,
SIZE_T  cbData 
)

Definition at line 394 of file sha512.c.

◆ SymCryptSha512_256Init()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Init ( _Out_ PSYMCRYPT_SHA512_256_STATE  pState)

Definition at line 274 of file sha512.c.

275{
277
278 pState->dataLengthH = 0;
279 pState->dataLengthL = 0;
280 pState->bytesInBuffer = 0;
281
283
284 //
285 // There is no need to initialize the buffer part of the state as that will be
286 // filled before it is used.
287 //
288}
const UINT64 SymCryptSha512_256InitialState[8]
Definition: sha512.c:101

Referenced by SymCryptSha512_256Result().

◆ SymCryptSha512_256Result()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Result ( _Inout_ PSYMCRYPT_SHA512_256_STATE  pState,
_Out_writes_(SYMCRYPT_SHA512_256_RESULT_SIZE) PBYTE  pbResult 
)

Definition at line 514 of file sha512.c.

517{
518 SYMCRYPT_ALIGN BYTE sha512Result[SYMCRYPT_SHA512_RESULT_SIZE]; // Buffer for SHA-512 output
519
520 //
521 // The SHA-512/256 result is the first 32 bytes of the SHA-512 result of our state
522 //
525
526 //
527 // The buffer was already wiped by the SymCryptSha512Result function, we
528 // just have to re-initialize for SHA-512/256
529 //
531
532 SymCryptWipeKnownSize( sha512Result, sizeof( sha512Result ) );
533}
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Init(_Out_ PSYMCRYPT_SHA512_256_STATE pState)
Definition: sha512.c:274
#define SYMCRYPT_SHA512_256_RESULT_SIZE
Definition: symcrypt.h:1488

◆ SymCryptSha512_256Selftest()

VOID SYMCRYPT_CALL SymCryptSha512_256Selftest ( void  )

Definition at line 794 of file sha512.c.

795{
797
799
800 SymCryptInjectError( result, sizeof( result ) );
801
802 if( memcmp( result, SymCryptSha512_256KATAnswer, sizeof( result ) ) != 0 ) {
803 SymCryptFatal( 'SH51' );
804 }
805}
const BYTE SymCryptSha512_256KATAnswer[32]
Definition: sha512.c:784
VOID SYMCRYPT_CALL SymCryptSha512_256(_In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_SHA512_256_RESULT_SIZE) PBYTE pbResult)

◆ SymCryptSha512_256StateExport()

Definition at line 602 of file sha512.c.

◆ SymCryptSha512_256StateImport()

◆ SymCryptSha512Append()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Append ( _Inout_ PSYMCRYPT_SHA512_STATE  pState,
_In_reads_(cbData) PCBYTE  pbData,
SIZE_T  cbData 
)

Definition at line 294 of file sha512.c.

298{
300 UINT32 freeInBuffer;
301 SIZE_T tmp;
302
304
305 pState->dataLengthL += cbData;
306 if( pState->dataLengthL < cbData ) {
307 pState->dataLengthH++;
308 }
309
310 bytesInBuffer = pState->bytesInBuffer;
311
312 //
313 // If previous data in buffer, buffer new input and transform if possible.
314 //
315 if( bytesInBuffer > 0 )
316 {
318
320 if( cbData < freeInBuffer )
321 {
322 //
323 // All the data will fit in the buffer.
324 // We don't do anything here.
325 // As cbData < inputBlockSize the bulk data processing is skipped,
326 // and the data will be copied to the buffer at the end
327 // of this code.
328 } else {
329 //
330 // Enough data to fill the whole buffer & process it
331 //
332 memcpy(&pState->buffer[bytesInBuffer], pbData, freeInBuffer);
333 pbData += freeInBuffer;
334 cbData -= freeInBuffer;
336
337 bytesInBuffer = 0;
338 }
339 }
340
341 //
342 // Internal buffer is empty; process all remaining whole blocks in the input
343 //
345 {
348 pbData += cbData - tmp;
349 cbData = tmp;
350 }
351
353
354 //
355 // buffer remaining input if necessary.
356 //
357 if( cbData > 0 )
358 {
359 memcpy( &pState->buffer[bytesInBuffer], pbData, cbData );
361 }
362
363 pState->bytesInBuffer = bytesInBuffer;
364
365}
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks(_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
Definition: sha512.c:1643
#define SYMCRYPT_ASSERT(_x)
Definition: symcrypt.h:10807
#define SYMCRYPT_SHA512_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1353
SIZE_T bytesInBuffer
#define SYMCRYPT_CHECK_MAGIC(p)
ULONG_PTR SIZE_T
Definition: typedefs.h:80
uint32_t UINT32
Definition: typedefs.h:59

Referenced by SymCryptSha384Append(), SymCryptSha512_224Append(), and SymCryptSha512_256Append().

◆ SymCryptSha512AppendBlocks()

VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks ( _Inout_ SYMCRYPT_SHA512_CHAINING_STATE *  pChain,
_In_reads_(cbData) PCBYTE  pbData,
SIZE_T  cbData,
_Out_ SIZE_T *  pcbRemaining 
)

Definition at line 1643 of file sha512.c.

1648{
1649#if SYMCRYPT_CPU_AMD64
1650
1651 // Temporarily disabling use of Ymm in SHA2
1652 // SYMCRYPT_EXTENDED_SAVE_DATA SaveData;
1653
1654 // if (SYMCRYPT_CPU_FEATURES_PRESENT(SYMCRYPT_CPU_FEATURE_AVX512 | SYMCRYPT_CPU_FEATURE_BMI2) &&
1655 // SymCryptSaveYmm(&SaveData) == SYMCRYPT_NO_ERROR)
1656 // {
1657 // SymCryptSha512AppendBlocks_ymm_avx512vl_asm(pChain, pbData, cbData, pcbRemaining);
1658
1659 // SymCryptRestoreYmm(&SaveData);
1660 // }
1661 // else if (SYMCRYPT_CPU_FEATURES_PRESENT(SYMCRYPT_CPU_FEATURE_AVX2 | SYMCRYPT_CPU_FEATURE_BMI2) &&
1662 // SymCryptSaveYmm(&SaveData) == SYMCRYPT_NO_ERROR)
1663 // {
1664 // //SymCryptSha512AppendBlocks_ymm_1block(pChain, pbData, cbData, pcbRemaining);
1665 // //SymCryptSha512AppendBlocks_ymm_2blocks(pChain, pbData, cbData, pcbRemaining);
1666 // //SymCryptSha512AppendBlocks_ymm_4blocks(pChain, pbData, cbData, pcbRemaining);
1667 // SymCryptSha512AppendBlocks_ymm_avx2_asm(pChain, pbData, cbData, pcbRemaining);
1668
1669 // SymCryptRestoreYmm(&SaveData);
1670 // }
1671 // else
1672 {
1673 SymCryptSha512AppendBlocks_ull( pChain, pbData, cbData, pcbRemaining );
1674 //SymCryptSha512AppendBlocks_ull2( pChain, pbData, cbData, pcbRemaining );
1675 //SymCryptSha512AppendBlocks_ull3( pChain, pbData, cbData, pcbRemaining );
1676 }
1677
1678
1679#elif SYMCRYPT_CPU_ARM
1680
1681 if( SYMCRYPT_CPU_FEATURES_PRESENT( SYMCRYPT_CPU_FEATURE_NEON ) )
1682 {
1683 SymCryptSha512AppendBlocks_neon( pChain, pbData, cbData, pcbRemaining ); // Tegra T3: 48 c/B
1684 } else {
1685 SymCryptSha512AppendBlocks_ull( pChain, pbData, cbData, pcbRemaining ); // Tegra T3: 65.34 c/B
1686 //SymCryptSha512AppendBlocks_ull2( pChain, pbData, cbData, pcbRemaining ); // Tegra T3: 77.4 c/B
1687 //SymCryptSha512AppendBlocks_ull3( pChain, pbData, cbData, pcbRemaining ); // Tegra T3: 71.6 c/B
1688 }
1689
1690#elif SYMCRYPT_CPU_X86
1691
1692 SYMCRYPT_EXTENDED_SAVE_DATA SaveData;
1693
1694 if( SYMCRYPT_CPU_FEATURES_PRESENT( SYMCRYPT_CPU_FEATURE_SSSE3 ) && SymCryptSaveXmm( &SaveData ) == SYMCRYPT_NO_ERROR )
1695 {
1696 SymCryptSha512AppendBlocks_xmm( pChain, pbData, cbData, pcbRemaining );
1697 SymCryptRestoreXmm( &SaveData );
1698 } else {
1699 SymCryptSha512AppendBlocks_ull( pChain, pbData, cbData, pcbRemaining ); // core2: 36.40 c/B
1700 //SymCryptSha512AppendBlocks_ull2( pChain, pbData, cbData, pcbRemaining ); // core2: 49.09 c/B
1701 //SymCryptSha512AppendBlocks_ull3( pChain, pbData, cbData, pcbRemaining ); // core2: 38.29 c/B
1702 }
1703
1704#else
1705
1706 SymCryptSha512AppendBlocks_ull( pChain, pbData, cbData, pcbRemaining ); // need tuning...
1707
1708#endif
1709}
VOID SaveData(HWND hwndDlg)
Definition: volume.c:368
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_xmm(_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_ull(_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
Definition: sha512.c:907
#define SYMCRYPT_CPU_FEATURES_PRESENT(x)

Referenced by SymCryptSha512Append(), and SymCryptSha512Result().

◆ SymCryptSha512AppendBlocks_ull()

VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_ull ( _Inout_ SYMCRYPT_SHA512_CHAINING_STATE *  pChain,
_In_reads_(cbData) PCBYTE  pbData,
SIZE_T  cbData,
_Out_ SIZE_T *  pcbRemaining 
)

Definition at line 907 of file sha512.c.

912{
914 UINT64 A, B, C, D, E, F, G, H;
915 int round;
916 UINT64 Wt;
917
918
919 while( cbData >= 128 )
920 {
921 A = pChain->H[0];
922 B = pChain->H[1];
923 C = pChain->H[2];
924 D = pChain->H[3];
925 E = pChain->H[4];
926 F = pChain->H[5];
927 G = pChain->H[6];
928 H = pChain->H[7];
929
930 //
931 // initial rounds 1 to 16
932 //
933
934 IROUND( A, B, C, D, E, F, G, H, 0 );
935 IROUND( H, A, B, C, D, E, F, G, 1 );
936 IROUND( G, H, A, B, C, D, E, F, 2 );
937 IROUND( F, G, H, A, B, C, D, E, 3 );
938 IROUND( E, F, G, H, A, B, C, D, 4 );
939 IROUND( D, E, F, G, H, A, B, C, 5 );
940 IROUND( C, D, E, F, G, H, A, B, 6 );
941 IROUND( B, C, D, E, F, G, H, A, 7 );
942 IROUND( A, B, C, D, E, F, G, H, 8 );
943 IROUND( H, A, B, C, D, E, F, G, 9 );
944 IROUND( G, H, A, B, C, D, E, F, 10 );
945 IROUND( F, G, H, A, B, C, D, E, 11 );
946 IROUND( E, F, G, H, A, B, C, D, 12 );
947 IROUND( D, E, F, G, H, A, B, C, 13 );
948 IROUND( C, D, E, F, G, H, A, B, 14 );
949 IROUND( B, C, D, E, F, G, H, A, 15 );
950
951 for( round=16; round<80; round += 16 )
952 {
953 FROUND( A, B, C, D, E, F, G, H, round + 0, 0 );
954 FROUND( H, A, B, C, D, E, F, G, round + 1, 1 );
955 FROUND( G, H, A, B, C, D, E, F, round + 2, 2 );
956 FROUND( F, G, H, A, B, C, D, E, round + 3, 3 );
957 FROUND( E, F, G, H, A, B, C, D, round + 4, 4 );
958 FROUND( D, E, F, G, H, A, B, C, round + 5, 5 );
959 FROUND( C, D, E, F, G, H, A, B, round + 6, 6 );
960 FROUND( B, C, D, E, F, G, H, A, round + 7, 7 );
961 FROUND( A, B, C, D, E, F, G, H, round + 8, 8 );
962 FROUND( H, A, B, C, D, E, F, G, round + 9, 9 );
963 FROUND( G, H, A, B, C, D, E, F, round + 10, 10 );
964 FROUND( F, G, H, A, B, C, D, E, round + 11, 11 );
965 FROUND( E, F, G, H, A, B, C, D, round + 12, 12 );
966 FROUND( D, E, F, G, H, A, B, C, round + 13, 13 );
967 FROUND( C, D, E, F, G, H, A, B, round + 14, 14 );
968 FROUND( B, C, D, E, F, G, H, A, round + 15, 15 );
969 }
970
971 pChain->H[0] = A + pChain->H[0];
972 pChain->H[1] = B + pChain->H[1];
973 pChain->H[2] = C + pChain->H[2];
974 pChain->H[3] = D + pChain->H[3];
975 pChain->H[4] = E + pChain->H[4];
976 pChain->H[5] = F + pChain->H[5];
977 pChain->H[6] = G + pChain->H[6];
978 pChain->H[7] = H + pChain->H[7];
979
980 pbData += 128;
981 cbData -= 128;
982 }
983
984 *pcbRemaining = cbData;
985
986 //
987 // Wipe the variables;
988 //
989 SymCryptWipeKnownSize( W, sizeof( W ) );
994 SYMCRYPT_FORCE_WRITE64( &E, 0 );
998 SYMCRYPT_FORCE_WRITE64( &Wt, 0 );
999}
COMPILER_DEPENDENT_UINT64 UINT64
Definition: actypes.h:131
#define G(r, i, a, b, c, d)
Definition: blake2b-ref.c:117
#define D(d)
Definition: builtin.c:4557
#define C(c)
Definition: builtin.c:4556
Definition: ehthrow.cxx:93
Definition: ehthrow.cxx:54
Definition: terminate.cpp:24
#define A(row, col)
#define B(row, col)
#define H
#define F(x, y, z)
Definition: md5.c:51
#define IROUND(a, b, c, d, e, f, g, h, r)
Definition: sha512.c:886
#define FROUND(a, b, c, d, e, f, g, h, r, r16)
Definition: sha512.c:895
#define SYMCRYPT_FORCE_WRITE64(_p, _v)
Definition: symcrypt.h:424
#define round(x)
Definition: opentype.c:51

Referenced by SymCryptSha512AppendBlocks().

◆ SymCryptSha512AppendBlocks_ull2()

VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_ull2 ( _Inout_ SYMCRYPT_SHA512_CHAINING_STATE *  pChain,
_In_reads_(cbData) PCBYTE  pbData,
SIZE_T  cbData,
_Out_ SIZE_T *  pcbRemaining 
)

Definition at line 1013 of file sha512.c.

1018{
1019 SYMCRYPT_ALIGN UINT64 buf[4 + 8 + 80]; // 4 words original chaining state, chaining state, and expanded input block
1020 UINT64 * W = &buf[4 + 8];
1021 UINT64 * ha = &buf[4]; // initial state words, in order h, g, ..., b, a
1022 UINT64 A, B, C, D, T;
1023 int r;
1024
1025 ha[7] = pChain->H[0]; buf[3] = ha[7];
1026 ha[6] = pChain->H[1]; buf[2] = ha[6];
1027 ha[5] = pChain->H[2]; buf[1] = ha[5];
1028 ha[4] = pChain->H[3]; buf[0] = ha[4];
1029 ha[3] = pChain->H[4];
1030 ha[2] = pChain->H[5];
1031 ha[1] = pChain->H[6];
1032 ha[0] = pChain->H[7];
1033
1034 while( cbData >= 128 )
1035 {
1036
1037 //
1038 // Capture the input into W[0..15]
1039 //
1040 for( r=0; r<16; r+= 2 )
1041 {
1042 W[r ] = SYMCRYPT_LOAD_MSBFIRST64( &pbData[ 8* r ] );
1043 W[r+1] = SYMCRYPT_LOAD_MSBFIRST64( &pbData[ 8*(r+1) ] );
1044 }
1045
1046 //
1047 // Expand the message
1048 //
1049 A = W[15];
1050 B = W[14];
1051 D = W[0];
1052 for( r=16; r<80; r+= 2 )
1053 {
1054 // Loop invariant: A=W[r-1], B = W[r-2], D = W[r-16]
1055
1056 //
1057 // Macro for one word of message expansion.
1058 // Invariant:
1059 // on entry: a = W[r-1], b = W[r-2], d = W[r-16]
1060 // on exit: W[r] computed, a = W[r-1], b = W[r], c = W[r-15]
1061 //
1062 #define EXPAND( a, b, c, d, r ) \
1063 c = W[r-15]; \
1064 b = d + LSIGMA1( b ) + W[r-7] + LSIGMA0( c ); \
1065 W[r] = b; \
1066
1067 EXPAND( A, B, C, D, r );
1068 EXPAND( B, A, D, C, (r+1));
1069
1070 #undef EXPAND
1071 }
1072
1073 A = ha[7];
1074 B = ha[6];
1075 C = ha[5];
1076 D = ha[4];
1077
1078 for( r=0; r<80; r += 4 )
1079 {
1080 //
1081 // Loop invariant:
1082 // A, B, C, and D are the a,b,c,d values of the current state.
1083 // W[r] is the next expanded message word to be processed.
1084 // W[r-8 .. r-5] contain the current state words h, g, f, e.
1085 //
1086
1087 //
1088 // Macro to compute one round
1089 //
1090 #define DO_ROUND( a, b, c, d, t, r ) \
1091 t = W[r] + CSIGMA1( W[r-5] ) + W[r-8] + CH( W[r-5], W[r-6], W[r-7] ) + SymCryptSha512K[r]; \
1092 W[r-4] = t + d; \
1093 d = t + CSIGMA0( a ) + MAJ( c, b, a );
1094
1095 DO_ROUND( A, B, C, D, T, r );
1096 DO_ROUND( D, A, B, C, T, (r+1) );
1097 DO_ROUND( C, D, A, B, T, (r+2) );
1098 DO_ROUND( B, C, D, A, T, (r+3) );
1099 #undef DO_ROUND
1100 }
1101
1102 buf[3] = ha[7] = buf[3] + A;
1103 buf[2] = ha[6] = buf[2] + B;
1104 buf[1] = ha[5] = buf[1] + C;
1105 buf[0] = ha[4] = buf[0] + D;
1106 ha[3] += W[r-5];
1107 ha[2] += W[r-6];
1108 ha[1] += W[r-7];
1109 ha[0] += W[r-8];
1110
1111 pbData += 128;
1112 cbData -= 128;
1113 }
1114
1115 pChain->H[0] = ha[7];
1116 pChain->H[1] = ha[6];
1117 pChain->H[2] = ha[5];
1118 pChain->H[3] = ha[4];
1119 pChain->H[4] = ha[3];
1120 pChain->H[5] = ha[2];
1121 pChain->H[6] = ha[1];
1122 pChain->H[7] = ha[0];
1123
1124 *pcbRemaining = cbData;
1125
1126 //
1127 // Wipe the variables;
1128 //
1129 SymCryptWipeKnownSize( buf, sizeof( buf ) );
1135
1136}
GLenum GLuint GLenum GLsizei const GLchar * buf
Definition: glext.h:7751
#define T(num)
Definition: thunks.c:311
#define DO_ROUND(a, b, c, d, t, r)
#define EXPAND(a, b, c, d, r)

◆ SymCryptSha512AppendBlocks_ull3()

VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_ull3 ( _Inout_ SYMCRYPT_SHA512_CHAINING_STATE *  pChain,
_In_reads_(cbData) PCBYTE  pbData,
SIZE_T  cbData,
_Out_ SIZE_T *  pcbRemaining 
)

Definition at line 1147 of file sha512.c.

1152{
1154 SYMCRYPT_ALIGN UINT64 ha[8];
1155 UINT64 A, B, C, D, E, F, G, H;
1156 int r;
1157
1158 ha[7] = pChain->H[0];
1159 ha[6] = pChain->H[1];
1160 ha[5] = pChain->H[2];
1161 ha[4] = pChain->H[3];
1162 ha[3] = pChain->H[4];
1163 ha[2] = pChain->H[5];
1164 ha[1] = pChain->H[6];
1165 ha[0] = pChain->H[7];
1166
1167 while( cbData >= 128 )
1168 {
1169
1170 //
1171 // Capture the input into W[0..15]
1172 //
1173 for( r=0; r<16; r+= 2 )
1174 {
1175 W[r ] = SYMCRYPT_LOAD_MSBFIRST64( &pbData[ 8* r ] );
1176 W[r+1] = SYMCRYPT_LOAD_MSBFIRST64( &pbData[ 8*(r+1) ] );
1177 }
1178
1179 //
1180 // Expand the message
1181 //
1182 A = W[15];
1183 B = W[14];
1184 D = W[0];
1185 for( r=16; r<80; r+= 2 )
1186 {
1187 // Loop invariant: A=W[r-1], B = W[r-2], D = W[r-16]
1188
1189 //
1190 // Macro for one word of message expansion.
1191 // Invariant:
1192 // on entry: a = W[r-1], b = W[r-2], d = W[r-16]
1193 // on exit: W[r] computed, a = W[r-1], b = W[r], c = W[r-15]
1194 //
1195 #define EXPAND( a, b, c, d, r ) \
1196 c = W[r-15]; \
1197 b = d + LSIGMA1( b ) + W[r-7] + LSIGMA0( c ); \
1198 W[r] = b; \
1199
1200 EXPAND( A, B, C, D, r );
1201 EXPAND( B, A, D, C, (r+1));
1202
1203 #undef EXPAND
1204 }
1205
1206 A = ha[7];
1207 B = ha[6];
1208 C = ha[5];
1209 D = ha[4];
1210 E = ha[3];
1211 F = ha[2];
1212 G = ha[1];
1213 H = ha[0];
1214
1215 for( r=0; r<80; r += 8 )
1216 {
1217 //
1218 // Loop invariant:
1219 // A, B, C, and D, E, F, G, H, are the values of the current state.
1220 // W[r] is the next expanded message word to be processed.
1221 //
1222
1223 //
1224 // Macro to compute one round
1225 //
1226 #define DO_ROUND( a, b, c, d, e, f, g, h, r ) \
1227 h += W[r] + CSIGMA1( e ) + CH( e, f, g ) + SymCryptSha512K[r]; \
1228 d += h; \
1229 h += CSIGMA0( a ) + MAJ( c, b, a );
1230
1231 DO_ROUND( A, B, C, D, E, F, G, H, (r ) );
1232 DO_ROUND( H, A, B, C, D, E, F, G, (r+1) );
1233 DO_ROUND( G, H, A, B, C, D, E, F, (r+2) );
1234 DO_ROUND( F, G, H, A, B, C, D, E, (r+3) );
1235 DO_ROUND( E, F, G, H, A, B, C, D, (r+4) );
1236 DO_ROUND( D, E, F, G, H, A, B, C, (r+5) );
1237 DO_ROUND( C, D, E, F, G, H, A, B, (r+6) );
1238 DO_ROUND( B, C, D, E, F, G, H, A, (r+7) );
1239 #undef DO_ROUND
1240 }
1241
1242 ha[7] += A;
1243 ha[6] += B;
1244 ha[5] += C;
1245 ha[4] += D;
1246 ha[3] += E;
1247 ha[2] += F;
1248 ha[1] += G;
1249 ha[0] += H;
1250
1251 pbData += 128;
1252 cbData -= 128;
1253 }
1254
1255 pChain->H[0] = ha[7];
1256 pChain->H[1] = ha[6];
1257 pChain->H[2] = ha[5];
1258 pChain->H[3] = ha[4];
1259 pChain->H[4] = ha[3];
1260 pChain->H[5] = ha[2];
1261 pChain->H[6] = ha[1];
1262 pChain->H[7] = ha[0];
1263
1264 *pcbRemaining = cbData;
1265
1266 //
1267 // Wipe the variables;
1268 //
1269 SymCryptWipeKnownSize( W, sizeof( W ) );
1270 SymCryptWipeKnownSize( ha, sizeof( ha ) );
1275 SYMCRYPT_FORCE_WRITE64( &E, 0 );
1279}

◆ SymCryptSha512Init()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Init ( _Out_ PSYMCRYPT_SHA512_STATE  pState)

Definition at line 214 of file sha512.c.

215{
217
218 pState->dataLengthH = 0;
219 pState->dataLengthL = 0;
220 pState->bytesInBuffer = 0;
221
223
224 //
225 // There is no need to initialize the buffer part of the state as that will be
226 // filled before it is used.
227 //
228}
const UINT64 SymCryptSha512InitialState[8]
Definition: sha512.c:68

◆ SymCryptSha512Result()

SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Result ( _Inout_ PSYMCRYPT_SHA512_STATE  pState,
_Out_writes_(SYMCRYPT_SHA512_RESULT_SIZE) PBYTE  pbResult 
)

Definition at line 406 of file sha512.c.

409{
411 SIZE_T tmp;
412
414
415 bytesInBuffer = pState->bytesInBuffer;
416
417 //
418 // The buffer is never completely full, so we can always put the first
419 // padding byte in.
420 //
421 pState->buffer[bytesInBuffer++] = 0x80;
422
423 if( bytesInBuffer > 128-16 ) {
424 //
425 // No room for the rest of the padding. Pad with zeroes & process block
426 // bytesInBuffer is at most 128, so we do not have an integer underflow
427 //
429 SymCryptSha512AppendBlocks( &pState->chain, pState->buffer, 128, &tmp );
430 bytesInBuffer = 0;
431 }
432
433 //
434 // Set rest of padding
435 // We wipe to the end of the buffer as it is 16-aligned,
436 // and it is faster to wipe to an aligned point
437 //
439 SYMCRYPT_STORE_MSBFIRST64( &pState->buffer[128-16], (pState->dataLengthH << 3) + (pState->dataLengthL >> 61) );
440 SYMCRYPT_STORE_MSBFIRST64( &pState->buffer[128- 8], (pState->dataLengthL << 3) );
441
442 SymCryptSha512AppendBlocks( &pState->chain, pState->buffer, 128, &tmp );
443
444 SymCryptUint64ToMsbFirst( &pState->chain.H[0], pbResult, 8 );
445
446 //
447 // We have to wipe the whole state because the Init call
448 // might be optimized away by a smart compiler.
449 //
450 SymCryptWipeKnownSize( pState, sizeof( *pState ) );
451
453
455 }
FORCEINLINE VOID SYMCRYPT_CALL SymCryptUint64ToMsbFirst(_In_reads_(cuData) PCUINT64 puData, _Out_writes_(8 *cuData) PBYTE pbResult, SIZE_T cuData)
Definition: sc_lib.h:576
VOID SYMCRYPT_CALL SymCryptWipe(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)
Definition: libmain.c:137
#define SYMCRYPT_STORE_MSBFIRST64(p, v)
Definition: symcrypt.h:312

Referenced by SymCryptSha384Result(), SymCryptSha512_224Result(), and SymCryptSha512_256Result().

◆ SymCryptSha512Selftest()

VOID SYMCRYPT_CALL SymCryptSha512Selftest ( void  )

Definition at line 709 of file sha512.c.

710{
712
714
715 SymCryptInjectError( result, sizeof( result ) );
716
717 if( memcmp( result, SymCryptSha512KATAnswer, sizeof( result ) ) != 0 ) {
718 SymCryptFatal( 'SH51' );
719 }
720}
const BYTE SymCryptSha512KATAnswer[64]
Definition: sha512.c:695
VOID SYMCRYPT_CALL SymCryptSha512(_In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_SHA512_RESULT_SIZE) PBYTE pbResult)

◆ SymCryptSha512StateExport()

Definition at line 575 of file sha512.c.

578{
580}
@ SymCryptBlobTypeSha512State
Definition: sc_lib.h:1067

◆ SymCryptSha512StateExportCore()

VOID SYMCRYPT_CALL SymCryptSha512StateExportCore ( _In_ PCSYMCRYPT_SHA512_STATE  pState,
_Out_writes_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PBYTE  pbBlob,
_In_ UINT32  type 
)

Definition at line 538 of file sha512.c.

542{
543 SYMCRYPT_ALIGN SYMCRYPT_SHA512_STATE_EXPORT_BLOB blob; // local copy to have proper alignment.
545
547
548 SymCryptWipeKnownSize( &blob, sizeof( blob ) ); // wipe to avoid any data leakage
549
550 blob.header.magic = SYMCRYPT_BLOB_MAGIC;
552 blob.header.type = type;
553
554 //
555 // Copy the relevant data. Buffer will be 0-padded.
556 //
557
558 SymCryptUint64ToMsbFirst( &pState->chain.H[0], &blob.chain[0], 8 );
559 blob.dataLengthL = pState->dataLengthL;
560 blob.dataLengthH = pState->dataLengthH;
561 memcpy( &blob.buffer[0], &pState->buffer[0], blob.dataLengthL & 0x7f );
562
563 SYMCRYPT_ASSERT( (PCBYTE) &blob + sizeof( blob ) - sizeof( SYMCRYPT_BLOB_TRAILER ) == (PCBYTE) &blob.trailer );
564 SymCryptMarvin32( SymCryptMarvin32DefaultSeed, (PCBYTE) &blob, sizeof( blob ) - sizeof( SYMCRYPT_BLOB_TRAILER ), &blob.trailer.checksum[0] );
565
566 memcpy( pbBlob, &blob, sizeof( blob ) );
567
568//cleanup:
569 SymCryptWipeKnownSize( &blob, sizeof( blob ) );
570 return;
571}
GLuint GLuint GLsizei GLenum type
Definition: gl.h:1545
#define C_ASSERT(e)
Definition: intsafe.h:73
#define SYMCRYPT_BLOB_MAGIC
Definition: sc_lib.h:1077
Definition: image.c:229
VOID SYMCRYPT_CALL SymCryptMarvin32(_In_ PCSYMCRYPT_MARVIN32_EXPANDED_SEED pExpandedSeed, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_MARVIN32_RESULT_SIZE) PBYTE pbResult)
Definition: marvin32.c:239
PCSYMCRYPT_MARVIN32_EXPANDED_SEED const SymCryptMarvin32DefaultSeed
Definition: marvin32.c:29
const BYTE * PCBYTE
#define SYMCRYPT_SHA512_STATE_EXPORT_SIZE

Referenced by SymCryptSha384StateExport(), SymCryptSha512_224StateExport(), SymCryptSha512_256StateExport(), and SymCryptSha512StateExport().

◆ SymCryptSha512StateImport()

Definition at line 654 of file sha512.c.

◆ SymCryptSha512StateImportCore()

Definition at line 612 of file sha512.c.

616{
617 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
618 SYMCRYPT_ALIGN SYMCRYPT_SHA512_STATE_EXPORT_BLOB blob; // local copy to have proper alignment.
619 BYTE checksum[8];
620
622 memcpy( &blob, pbBlob, sizeof( blob ) );
623
624 if( blob.header.magic != SYMCRYPT_BLOB_MAGIC ||
626 blob.header.type != type )
627 {
628 scError = SYMCRYPT_INVALID_BLOB;
629 goto cleanup;
630 }
631
633 if( memcmp( checksum, &blob.trailer.checksum[0], 8 ) != 0 )
634 {
635 scError = SYMCRYPT_INVALID_BLOB;
636 goto cleanup;
637 }
638
639 SymCryptMsbFirstToUint64( &blob.chain[0], &pState->chain.H[0], 8 );
640 pState->dataLengthL = blob.dataLengthL;
641 pState->dataLengthH = blob.dataLengthH;
642 pState->bytesInBuffer = blob.dataLengthL & 0x7f;
643 memcpy( &pState->buffer[0], &blob.buffer[0], pState->bytesInBuffer );
644
646
647cleanup:
648 SymCryptWipeKnownSize( &blob, sizeof(blob) );
649 return scError;
650}
static cab_ULONG checksum(const cab_UBYTE *data, cab_UWORD bytes, cab_ULONG csum)
Definition: fdi.c:353
static void cleanup(void)
Definition: main.c:1335
FORCEINLINE VOID SYMCRYPT_CALL SymCryptMsbFirstToUint64(_In_reads_(8 *cuResult) PCBYTE pbData, _Out_writes_(cuResult) PUINT64 puResult, SIZE_T cuResult)
Definition: sc_lib.h:592
SYMCRYPT_ERROR
Definition: symcrypt.h:227

Referenced by SymCryptSha384StateImport(), SymCryptSha512_224StateImport(), SymCryptSha512_256StateImport(), and SymCryptSha512StateImport().

Variable Documentation

◆ SymCryptSha384Algorithm

Definition at line 169 of file sha512.c.

Referenced by init_hash_impl().

◆ SymCryptSha384Algorithm_default

const SYMCRYPT_HASH SymCryptSha384Algorithm_default
Initial value:
= {
}
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Result(_Inout_ PSYMCRYPT_SHA384_STATE pState, _Out_writes_(SYMCRYPT_SHA384_RESULT_SIZE) PBYTE pbResult)
Definition: sha512.c:460
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Append(_Inout_ PSYMCRYPT_SHA384_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: sha512.c:370
#define SYMCRYPT_SHA384_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1288
VOID SYMCRYPT_CALL SymCryptSha384StateCopy(_In_ PCSYMCRYPT_SHA384_STATE pSrc, _Out_ PSYMCRYPT_SHA384_STATE pDst)
#define SYMCRYPT_FIELD_SIZE(type, field)
#define SYMCRYPT_FIELD_OFFSET(type, field)
SYMCRYPT_SHA384_STATE
struct sock * chain
Definition: tcpcore.h:1

Definition at line 117 of file sha512.c.

◆ SymCryptSha384InitialState

const UINT64 SymCryptSha384InitialState[8]
Initial value:
= {
0xcbbb9d5dc1059ed8UL,
0x629a292a367cd507UL,
0x9159015a3070dd17UL,
0x152fecd8f70e5939UL,
0x67332667ffc00b31UL,
0x8eb44a8768581511UL,
0xdb0c2e0d64f98fa7UL,
0x47b5481dbefa4fa4UL,
}

Definition at line 79 of file sha512.c.

Referenced by SymCryptSha384Init().

◆ SymCryptSha384KATAnswer

const BYTE SymCryptSha384KATAnswer[48]
Initial value:
=
{
0xcb, 0x00, 0x75, 0x3f, 0x45, 0xa3, 0x5e, 0x8b,
0xb5, 0xa0, 0x3d, 0x69, 0x9a, 0xc6, 0x50, 0x07,
0x27, 0x2c, 0x32, 0xab, 0x0e, 0xde, 0xd1, 0x63,
0x1a, 0x8b, 0x60, 0x5a, 0x43, 0xff, 0x5b, 0xed,
0x80, 0x86, 0x07, 0x2b, 0xa1, 0xe7, 0xcc, 0x23,
0x58, 0xba, 0xec, 0xa1, 0x34, 0xc8, 0x25, 0xa7,
}

Definition at line 728 of file sha512.c.

Referenced by SymCryptSha384Selftest().

◆ SymCryptSha512_224Algorithm

Definition at line 171 of file sha512.c.

◆ SymCryptSha512_224Algorithm_default

const SYMCRYPT_HASH SymCryptSha512_224Algorithm_default
Initial value:
= {
}
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Result(_Inout_ PSYMCRYPT_SHA512_224_STATE pState, _Out_writes_(SYMCRYPT_SHA512_224_RESULT_SIZE) PBYTE pbResult)
Definition: sha512.c:489
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Append(_Inout_ PSYMCRYPT_SHA512_224_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: sha512.c:383
VOID SYMCRYPT_CALL SymCryptSha512_224StateCopy(_In_ PCSYMCRYPT_SHA512_224_STATE pSrc, _Out_ PSYMCRYPT_SHA512_224_STATE pDst)
#define SYMCRYPT_SHA512_224_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1421
SYMCRYPT_SHA512_224_STATE

Definition at line 143 of file sha512.c.

◆ SymCryptSha512_224InitialState

const UINT64 SymCryptSha512_224InitialState[8]
Initial value:
= {
0x8c3d37c819544da2UL,
0x73e1996689dcd4d6UL,
0x1dfab7ae32ff9c82UL,
0x679dd514582f9fcfUL,
0x0f6d2b697bd44da8UL,
0x77e36f7304c48942UL,
0x3f9d85a86a1d36c8UL,
0x1112e6ad91d692a1UL,
}

Definition at line 90 of file sha512.c.

Referenced by SymCryptSha512_224Init().

◆ SymCryptSha512_224KATAnswer

const BYTE SymCryptSha512_224KATAnswer[28]
Initial value:
=
{
0x46, 0x34, 0x27, 0x0f, 0x70, 0x7b, 0x6a, 0x54,
0xda, 0xae, 0x75, 0x30, 0x46, 0x08, 0x42, 0xe2,
0x0e, 0x37, 0xed, 0x26, 0x5c, 0xee, 0xe9, 0xa4,
0x3e, 0x89, 0x24, 0xaa,
}

Definition at line 757 of file sha512.c.

Referenced by SymCryptSha512_224Selftest().

◆ SymCryptSha512_256Algorithm

Definition at line 172 of file sha512.c.

◆ SymCryptSha512_256Algorithm_default

const SYMCRYPT_HASH SymCryptSha512_256Algorithm_default
Initial value:
= {
}
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Result(_Inout_ PSYMCRYPT_SHA512_256_STATE pState, _Out_writes_(SYMCRYPT_SHA512_256_RESULT_SIZE) PBYTE pbResult)
Definition: sha512.c:514
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Append(_Inout_ PSYMCRYPT_SHA512_256_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: sha512.c:394
VOID SYMCRYPT_CALL SymCryptSha512_256StateCopy(_In_ PCSYMCRYPT_SHA512_256_STATE pSrc, _Out_ PSYMCRYPT_SHA512_256_STATE pDst)
#define SYMCRYPT_SHA512_256_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1489
SYMCRYPT_SHA512_256_STATE

Definition at line 156 of file sha512.c.

◆ SymCryptSha512_256InitialState

const UINT64 SymCryptSha512_256InitialState[8]
Initial value:
= {
0x22312194fc2bf72cUL,
0x9f555fa3c84c64c2UL,
0x2393b86b6f53b151UL,
0x963877195940eabdUL,
0x96283ee2a88effe3UL,
0xbe5e1e2553863992UL,
0x2b0199fc2c85b8aaUL,
0x0eb72ddc81c52ca2UL,
}

Definition at line 101 of file sha512.c.

Referenced by SymCryptSha512_256Init().

◆ SymCryptSha512_256KATAnswer

const BYTE SymCryptSha512_256KATAnswer[32]
Initial value:
=
{
0x53, 0x04, 0x8e, 0x26, 0x81, 0x94, 0x1e, 0xf9,
0x9b, 0x2e, 0x29, 0xb7, 0x6b, 0x4c, 0x7d, 0xab,
0xe4, 0xc2, 0xd0, 0xc6, 0x34, 0xfc, 0x6d, 0x46,
0xe0, 0xe2, 0xf1, 0x31, 0x07, 0xe7, 0xaf, 0x23,
}

Definition at line 784 of file sha512.c.

Referenced by SymCryptSha512_256Selftest().

◆ SymCryptSha512Algorithm

Definition at line 170 of file sha512.c.

Referenced by init_hash_impl(), and SymCryptSshKdfSha512SelfTest().

◆ SymCryptSha512Algorithm_default

const SYMCRYPT_HASH SymCryptSha512Algorithm_default
Initial value:
= {
}
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Init(_Out_ PSYMCRYPT_SHA512_STATE pState)
Definition: sha512.c:214
VOID SYMCRYPT_CALL SymCryptSha512StateCopy(_In_ PCSYMCRYPT_SHA512_STATE pSrc, _Out_ PSYMCRYPT_SHA512_STATE pDst)
SYMCRYPT_SHA512_STATE

Definition at line 130 of file sha512.c.

◆ SymCryptSha512InitialState

const UINT64 SymCryptSha512InitialState[8]
Initial value:
= {
0x6a09e667f3bcc908UL,
0xbb67ae8584caa73bUL,
0x3c6ef372fe94f82bUL,
0xa54ff53a5f1d36f1UL,
0x510e527fade682d1UL,
0x9b05688c2b3e6c1fUL,
0x1f83d9abfb41bd6bUL,
0x5be0cd19137e2179UL,
}

Definition at line 68 of file sha512.c.

Referenced by SymCryptSha512Init(), and SymCryptSha512Result().

◆ SymCryptSha512KATAnswer

const BYTE SymCryptSha512KATAnswer[64]
Initial value:
=
{
0xdd, 0xaf, 0x35, 0xa1, 0x93, 0x61, 0x7a, 0xba,
0xcc, 0x41, 0x73, 0x49, 0xae, 0x20, 0x41, 0x31,
0x12, 0xe6, 0xfa, 0x4e, 0x89, 0xa9, 0x7e, 0xa2,
0x0a, 0x9e, 0xee, 0xe6, 0x4b, 0x55, 0xd3, 0x9a,
0x21, 0x92, 0x99, 0x2a, 0x27, 0x4f, 0xc1, 0xa8,
0x36, 0xba, 0x3c, 0x23, 0xa3, 0xfe, 0xeb, 0xbd,
0x45, 0x4d, 0x44, 0x23, 0x64, 0x3c, 0xe8, 0x0e,
0x2a, 0x9a, 0xc9, 0x4f, 0xa5, 0x4c, 0xa4, 0x9f,
}

Definition at line 695 of file sha512.c.

Referenced by SymCryptSha512Selftest().