ReactOS 0.4.17-dev-1005-g171e1de
sha512.c
Go to the documentation of this file.
1//
2// Sha512.c
3//
4// Copyright (c) Microsoft Corporation. Licensed under the MIT license.
5//
6
7//
8// This module contains the routines to implement SHA2-512 from FIPS 180-2
9//
10
11
12#include "precomp.h"
13
14//
15// SHA-512 uses 80 magic constants of 64 bits each. These are
16// referred to as K^{512}_i for i=0...79 by FIPS 180-2.
17// We use a static array as that does not pollute the linker name space
18// For performance we align to the cache line size of 64 bytes
19// We have one extra value at the end to allow an XMM read from each element
20// of the array.
21//
22SYMCRYPT_ALIGN_AT( 64 ) const UINT64 SymCryptSha512K[81] = {
23 0x428a2f98d728ae22UL, 0x7137449123ef65cdUL,
24 0xb5c0fbcfec4d3b2fUL, 0xe9b5dba58189dbbcUL,
25 0x3956c25bf348b538UL, 0x59f111f1b605d019UL,
26 0x923f82a4af194f9bUL, 0xab1c5ed5da6d8118UL,
27 0xd807aa98a3030242UL, 0x12835b0145706fbeUL,
28 0x243185be4ee4b28cUL, 0x550c7dc3d5ffb4e2UL,
29 0x72be5d74f27b896fUL, 0x80deb1fe3b1696b1UL,
30 0x9bdc06a725c71235UL, 0xc19bf174cf692694UL,
31 0xe49b69c19ef14ad2UL, 0xefbe4786384f25e3UL,
32 0x0fc19dc68b8cd5b5UL, 0x240ca1cc77ac9c65UL,
33 0x2de92c6f592b0275UL, 0x4a7484aa6ea6e483UL,
34 0x5cb0a9dcbd41fbd4UL, 0x76f988da831153b5UL,
35 0x983e5152ee66dfabUL, 0xa831c66d2db43210UL,
36 0xb00327c898fb213fUL, 0xbf597fc7beef0ee4UL,
37 0xc6e00bf33da88fc2UL, 0xd5a79147930aa725UL,
38 0x06ca6351e003826fUL, 0x142929670a0e6e70UL,
39 0x27b70a8546d22ffcUL, 0x2e1b21385c26c926UL,
40 0x4d2c6dfc5ac42aedUL, 0x53380d139d95b3dfUL,
41 0x650a73548baf63deUL, 0x766a0abb3c77b2a8UL,
42 0x81c2c92e47edaee6UL, 0x92722c851482353bUL,
43 0xa2bfe8a14cf10364UL, 0xa81a664bbc423001UL,
44 0xc24b8b70d0f89791UL, 0xc76c51a30654be30UL,
45 0xd192e819d6ef5218UL, 0xd69906245565a910UL,
46 0xf40e35855771202aUL, 0x106aa07032bbd1b8UL,
47 0x19a4c116b8d2d0c8UL, 0x1e376c085141ab53UL,
48 0x2748774cdf8eeb99UL, 0x34b0bcb5e19b48a8UL,
49 0x391c0cb3c5c95a63UL, 0x4ed8aa4ae3418acbUL,
50 0x5b9cca4f7763e373UL, 0x682e6ff3d6b2b8a3UL,
51 0x748f82ee5defb2fcUL, 0x78a5636f43172f60UL,
52 0x84c87814a1f0ab72UL, 0x8cc702081a6439ecUL,
53 0x90befffa23631e28UL, 0xa4506cebde82bde9UL,
54 0xbef9a3f7b2c67915UL, 0xc67178f2e372532bUL,
55 0xca273eceea26619cUL, 0xd186b8c721c0c207UL,
56 0xeada7dd6cde0eb1eUL, 0xf57d4f7fee6ed178UL,
57 0x06f067aa72176fbaUL, 0x0a637dc5a2c898a6UL,
58 0x113f9804bef90daeUL, 0x1b710b35131c471bUL,
59 0x28db77f523047d84UL, 0x32caab7b40c72493UL,
60 0x3c9ebe0a15c9bebcUL, 0x431d67c49c100d4cUL,
61 0x4cc5d4becb3e42b6UL, 0x597f299cfc657e2aUL,
62 0x5fcb6fab3ad6faecUL, 0x6c44198c4a475817UL,
63};
64
65//
66// Initial states
67//
69 0x6a09e667f3bcc908UL,
70 0xbb67ae8584caa73bUL,
71 0x3c6ef372fe94f82bUL,
72 0xa54ff53a5f1d36f1UL,
73 0x510e527fade682d1UL,
74 0x9b05688c2b3e6c1fUL,
75 0x1f83d9abfb41bd6bUL,
76 0x5be0cd19137e2179UL,
77};
78
80 0xcbbb9d5dc1059ed8UL,
81 0x629a292a367cd507UL,
82 0x9159015a3070dd17UL,
83 0x152fecd8f70e5939UL,
84 0x67332667ffc00b31UL,
85 0x8eb44a8768581511UL,
86 0xdb0c2e0d64f98fa7UL,
87 0x47b5481dbefa4fa4UL,
88};
89
91 0x8c3d37c819544da2UL,
92 0x73e1996689dcd4d6UL,
93 0x1dfab7ae32ff9c82UL,
94 0x679dd514582f9fcfUL,
95 0x0f6d2b697bd44da8UL,
96 0x77e36f7304c48942UL,
97 0x3f9d85a86a1d36c8UL,
98 0x1112e6ad91d692a1UL,
99};
100
102 0x22312194fc2bf72cUL,
103 0x9f555fa3c84c64c2UL,
104 0x2393b86b6f53b151UL,
105 0x963877195940eabdUL,
106 0x96283ee2a88effe3UL,
107 0xbe5e1e2553863992UL,
108 0x2b0199fc2c85b8aaUL,
109 0x0eb72ddc81c52ca2UL,
110};
111
112
113//
114// Todo: this structure pulls in the SHA284 code anytime someone uses
115// SHA-512; should be split into a separate file.
116//
123 sizeof( SYMCRYPT_SHA384_STATE ),
128};
129
136 sizeof( SYMCRYPT_SHA512_STATE ),
141};
142
154};
155
167};
168
173
174//
175// SymCryptSha384
176//
177#define ALG SHA384
178#define Alg Sha384
179#include "hash_pattern.c"
180#undef ALG
181#undef Alg
182
183//
184// SymCryptSha512
185//
186#define ALG SHA512
187#define Alg Sha512
188#include "hash_pattern.c"
189#undef ALG
190#undef Alg
191
192//
193// SymCryptSha512/224
194//
195#define ALG SHA512_224
196#define Alg Sha512_224
197#include "hash_pattern.c"
198#undef ALG
199#undef Alg
200
201//
202// SymCryptSha512/256
203//
204#define ALG SHA512_256
205#define Alg Sha512_256
206#include "hash_pattern.c"
207#undef ALG
208#undef Alg
209
210
211SYMCRYPT_NOINLINE
212VOID
215{
217
218 pState->dataLengthH = 0;
219 pState->dataLengthL = 0;
220 pState->bytesInBuffer = 0;
221
223
224 //
225 // There is no need to initialize the buffer part of the state as that will be
226 // filled before it is used.
227 //
228}
229
230
231SYMCRYPT_NOINLINE
232VOID
235{
237
238 pState->dataLengthH = 0;
239 pState->dataLengthL = 0;
240 pState->bytesInBuffer = 0;
241
243
244 //
245 // There is no need to initialize the buffer part of the state as that will be
246 // filled before it is used.
247 //
248}
249
250
251SYMCRYPT_NOINLINE
252VOID
255{
257
258 pState->dataLengthH = 0;
259 pState->dataLengthL = 0;
260 pState->bytesInBuffer = 0;
261
263
264 //
265 // There is no need to initialize the buffer part of the state as that will be
266 // filled before it is used.
267 //
268}
269
270
271SYMCRYPT_NOINLINE
272VOID
275{
277
278 pState->dataLengthH = 0;
279 pState->dataLengthL = 0;
280 pState->bytesInBuffer = 0;
281
283
284 //
285 // There is no need to initialize the buffer part of the state as that will be
286 // filled before it is used.
287 //
288}
289
290
291SYMCRYPT_NOINLINE
292VOID
297 SIZE_T cbData )
298{
300 UINT32 freeInBuffer;
301 SIZE_T tmp;
302
304
305 pState->dataLengthL += cbData;
306 if( pState->dataLengthL < cbData ) {
307 pState->dataLengthH++;
308 }
309
310 bytesInBuffer = pState->bytesInBuffer;
311
312 //
313 // If previous data in buffer, buffer new input and transform if possible.
314 //
315 if( bytesInBuffer > 0 )
316 {
318
320 if( cbData < freeInBuffer )
321 {
322 //
323 // All the data will fit in the buffer.
324 // We don't do anything here.
325 // As cbData < inputBlockSize the bulk data processing is skipped,
326 // and the data will be copied to the buffer at the end
327 // of this code.
328 } else {
329 //
330 // Enough data to fill the whole buffer & process it
331 //
332 memcpy(&pState->buffer[bytesInBuffer], pbData, freeInBuffer);
333 pbData += freeInBuffer;
334 cbData -= freeInBuffer;
336
337 bytesInBuffer = 0;
338 }
339 }
340
341 //
342 // Internal buffer is empty; process all remaining whole blocks in the input
343 //
345 {
348 pbData += cbData - tmp;
349 cbData = tmp;
350 }
351
353
354 //
355 // buffer remaining input if necessary.
356 //
357 if( cbData > 0 )
358 {
359 memcpy( &pState->buffer[bytesInBuffer], pbData, cbData );
361 }
362
363 pState->bytesInBuffer = bytesInBuffer;
364
365}
366
367SYMCRYPT_NOINLINE
368VOID
373 SIZE_T cbData )
374{
375
377
378}
379
380SYMCRYPT_NOINLINE
381VOID
386 SIZE_T cbData )
387{
389}
390
391SYMCRYPT_NOINLINE
392VOID
397 SIZE_T cbData )
398{
400}
401
402
403SYMCRYPT_NOINLINE
404VOID
409{
411 SIZE_T tmp;
412
414
415 bytesInBuffer = pState->bytesInBuffer;
416
417 //
418 // The buffer is never completely full, so we can always put the first
419 // padding byte in.
420 //
421 pState->buffer[bytesInBuffer++] = 0x80;
422
423 if( bytesInBuffer > 128-16 ) {
424 //
425 // No room for the rest of the padding. Pad with zeroes & process block
426 // bytesInBuffer is at most 128, so we do not have an integer underflow
427 //
429 SymCryptSha512AppendBlocks( &pState->chain, pState->buffer, 128, &tmp );
430 bytesInBuffer = 0;
431 }
432
433 //
434 // Set rest of padding
435 // We wipe to the end of the buffer as it is 16-aligned,
436 // and it is faster to wipe to an aligned point
437 //
439 SYMCRYPT_STORE_MSBFIRST64( &pState->buffer[128-16], (pState->dataLengthH << 3) + (pState->dataLengthL >> 61) );
440 SYMCRYPT_STORE_MSBFIRST64( &pState->buffer[128- 8], (pState->dataLengthL << 3) );
441
442 SymCryptSha512AppendBlocks( &pState->chain, pState->buffer, 128, &tmp );
443
444 SymCryptUint64ToMsbFirst( &pState->chain.H[0], pbResult, 8 );
445
446 //
447 // We have to wipe the whole state because the Init call
448 // might be optimized away by a smart compiler.
449 //
450 SymCryptWipeKnownSize( pState, sizeof( *pState ) );
451
453
455 }
456
457SYMCRYPT_NOINLINE
458VOID
463{
464 //
465 // For simplicity we re-use SymCryptSha512Result. This is slightly slower,
466 // but SHA-384 isn't used that much.
467 //
468 SYMCRYPT_ALIGN BYTE sha512Result[SYMCRYPT_SHA512_RESULT_SIZE]; // Buffer for SHA-512 output
469
470 //
471 // The SHA-384 result is the first 48 bytes of the SHA-512 result of our state
472 //
475
476 //
477 // The buffer was already wiped by the SymCryptSha512Result function, we
478 // just have to re-initialize for SHA-384
479 //
481
482 SymCryptWipeKnownSize( sha512Result, sizeof( sha512Result ) );
483}
484
485
486SYMCRYPT_NOINLINE
487VOID
492{
493 SYMCRYPT_ALIGN BYTE sha512Result[SYMCRYPT_SHA512_RESULT_SIZE]; // Buffer for SHA-512 output
494
495 //
496 // The SHA-512/224 result is the first 28 bytes of the SHA-512 result of our state
497 //
500
501 //
502 // The buffer was already wiped by the SymCryptSha512Result function, we
503 // just have to re-initialize for SHA-512/224
504 //
506
507 SymCryptWipeKnownSize( sha512Result, sizeof( sha512Result ) );
508}
509
510
511SYMCRYPT_NOINLINE
512VOID
517{
518 SYMCRYPT_ALIGN BYTE sha512Result[SYMCRYPT_SHA512_RESULT_SIZE]; // Buffer for SHA-512 output
519
520 //
521 // The SHA-512/256 result is the first 32 bytes of the SHA-512 result of our state
522 //
525
526 //
527 // The buffer was already wiped by the SymCryptSha512Result function, we
528 // just have to re-initialize for SHA-512/256
529 //
531
532 SymCryptWipeKnownSize( sha512Result, sizeof( sha512Result ) );
533}
534
535
536VOID
542{
543 SYMCRYPT_ALIGN SYMCRYPT_SHA512_STATE_EXPORT_BLOB blob; // local copy to have proper alignment.
545
547
548 SymCryptWipeKnownSize( &blob, sizeof( blob ) ); // wipe to avoid any data leakage
549
550 blob.header.magic = SYMCRYPT_BLOB_MAGIC;
552 blob.header.type = type;
553
554 //
555 // Copy the relevant data. Buffer will be 0-padded.
556 //
557
558 SymCryptUint64ToMsbFirst( &pState->chain.H[0], &blob.chain[0], 8 );
559 blob.dataLengthL = pState->dataLengthL;
560 blob.dataLengthH = pState->dataLengthH;
561 memcpy( &blob.buffer[0], &pState->buffer[0], blob.dataLengthL & 0x7f );
562
563 SYMCRYPT_ASSERT( (PCBYTE) &blob + sizeof( blob ) - sizeof( SYMCRYPT_BLOB_TRAILER ) == (PCBYTE) &blob.trailer );
564 SymCryptMarvin32( SymCryptMarvin32DefaultSeed, (PCBYTE) &blob, sizeof( blob ) - sizeof( SYMCRYPT_BLOB_TRAILER ), &blob.trailer.checksum[0] );
565
566 memcpy( pbBlob, &blob, sizeof( blob ) );
567
568//cleanup:
569 SymCryptWipeKnownSize( &blob, sizeof( blob ) );
570 return;
571}
572
573VOID
578{
580}
581
582VOID
587{
589}
590
591VOID
596{
598}
599
600VOID
605{
607}
608
609
616{
617 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
618 SYMCRYPT_ALIGN SYMCRYPT_SHA512_STATE_EXPORT_BLOB blob; // local copy to have proper alignment.
619 BYTE checksum[8];
620
622 memcpy( &blob, pbBlob, sizeof( blob ) );
623
624 if( blob.header.magic != SYMCRYPT_BLOB_MAGIC ||
626 blob.header.type != type )
627 {
628 scError = SYMCRYPT_INVALID_BLOB;
629 goto cleanup;
630 }
631
633 if( memcmp( checksum, &blob.trailer.checksum[0], 8 ) != 0 )
634 {
635 scError = SYMCRYPT_INVALID_BLOB;
636 goto cleanup;
637 }
638
639 SymCryptMsbFirstToUint64( &blob.chain[0], &pState->chain.H[0], 8 );
640 pState->dataLengthL = blob.dataLengthL;
641 pState->dataLengthH = blob.dataLengthH;
642 pState->bytesInBuffer = blob.dataLengthL & 0x7f;
643 memcpy( &pState->buffer[0], &blob.buffer[0], pState->bytesInBuffer );
644
646
647cleanup:
648 SymCryptWipeKnownSize( &blob, sizeof(blob) );
649 return scError;
650}
651
657{
659}
660
666{
668}
669
675{
677}
678
684{
686}
687
688
689//
690// A simple test case intended for module testing for
691// FIPS compliance.
692// This is the one-block example message from FIPS 180-2 appendix C
693//
694
696{
697 0xdd, 0xaf, 0x35, 0xa1, 0x93, 0x61, 0x7a, 0xba,
698 0xcc, 0x41, 0x73, 0x49, 0xae, 0x20, 0x41, 0x31,
699 0x12, 0xe6, 0xfa, 0x4e, 0x89, 0xa9, 0x7e, 0xa2,
700 0x0a, 0x9e, 0xee, 0xe6, 0x4b, 0x55, 0xd3, 0x9a,
701 0x21, 0x92, 0x99, 0x2a, 0x27, 0x4f, 0xc1, 0xa8,
702 0x36, 0xba, 0x3c, 0x23, 0xa3, 0xfe, 0xeb, 0xbd,
703 0x45, 0x4d, 0x44, 0x23, 0x64, 0x3c, 0xe8, 0x0e,
704 0x2a, 0x9a, 0xc9, 0x4f, 0xa5, 0x4c, 0xa4, 0x9f,
705};
706
707VOID
710{
712
714
715 SymCryptInjectError( result, sizeof( result ) );
716
717 if( memcmp( result, SymCryptSha512KATAnswer, sizeof( result ) ) != 0 ) {
718 SymCryptFatal( 'SH51' );
719 }
720}
721
722//
723// A simple test case intended for module testing for
724// FIPS compliance.
725// This is the one-block example message from FIPS 180-2 appendix D
726//
727
729{
730 0xcb, 0x00, 0x75, 0x3f, 0x45, 0xa3, 0x5e, 0x8b,
731 0xb5, 0xa0, 0x3d, 0x69, 0x9a, 0xc6, 0x50, 0x07,
732 0x27, 0x2c, 0x32, 0xab, 0x0e, 0xde, 0xd1, 0x63,
733 0x1a, 0x8b, 0x60, 0x5a, 0x43, 0xff, 0x5b, 0xed,
734 0x80, 0x86, 0x07, 0x2b, 0xa1, 0xe7, 0xcc, 0x23,
735 0x58, 0xba, 0xec, 0xa1, 0x34, 0xc8, 0x25, 0xa7,
736};
737
738VOID
741{
743
745
746 SymCryptInjectError( result, sizeof( result ) );
747
748 if( memcmp( result, SymCryptSha384KATAnswer, sizeof( result ) ) != 0 ) {
749 SymCryptFatal( 'SH38' );
750 }
751}
752
753//
754// Simple test vector for FIPS module testing
755//
756
758{
759 0x46, 0x34, 0x27, 0x0f, 0x70, 0x7b, 0x6a, 0x54,
760 0xda, 0xae, 0x75, 0x30, 0x46, 0x08, 0x42, 0xe2,
761 0x0e, 0x37, 0xed, 0x26, 0x5c, 0xee, 0xe9, 0xa4,
762 0x3e, 0x89, 0x24, 0xaa,
763};
764
765VOID
768{
770
772
773 SymCryptInjectError( result, sizeof( result ) );
774
775 if( memcmp( result, SymCryptSha512_224KATAnswer, sizeof( result ) ) != 0 ) {
776 SymCryptFatal( 'SH51' );
777 }
778}
779
780//
781// Simple test vector for FIPS module testing
782//
783
785{
786 0x53, 0x04, 0x8e, 0x26, 0x81, 0x94, 0x1e, 0xf9,
787 0x9b, 0x2e, 0x29, 0xb7, 0x6b, 0x4c, 0x7d, 0xab,
788 0xe4, 0xc2, 0xd0, 0xc6, 0x34, 0xfc, 0x6d, 0x46,
789 0xe0, 0xe2, 0xf1, 0x31, 0x07, 0xe7, 0xaf, 0x23,
790};
791
792VOID
795{
797
799
800 SymCryptInjectError( result, sizeof( result ) );
801
802 if( memcmp( result, SymCryptSha512_256KATAnswer, sizeof( result ) ) != 0 ) {
803 SymCryptFatal( 'SH51' );
804 }
805}
806
807//
808// We keep multiple implementations in this file.
809// This allows us to switch different platforms to different implementations, whichever
810// is faster. Even if we don't use a particular implementation in one release,
811// we keep it around in case it becomes the preferred one for a new CPU release.
812// (Performance can change a lot with changes in micro-architecture.)
813//
814
815//===================================================================================
816// Implementation of compression function using UINT64s
817//
818
819//
820// For documentation on these function see FIPS 180-2
821//
822// MAJ and CH are the functions Maj and Ch from the standard.
823// CSIGMA0 and CSIGMA1 are the capital sigma functions.
824// LSIGMA0 and LSIGMA1 are the lowercase sigma functions.
825//
826// The canonical definitions of the MAJ and CH functions are:
827//#define MAJ( x, y, z ) (((x) & (y)) ^ ((x) & (z)) ^ ((y) & (z)))
828//#define CH( x, y, z ) (((x) & (y)) ^ ((~(x)) & (z)))
829// We use optimized versions defined below
830//
831#define MAJ( x, y, z ) ((((z) | (y)) & (x) ) | ((z) & (y)))
832#define CH( x, y, z ) ((((z) ^ (y)) & (x)) ^ (z))
833
834//
835// The four Sigma functions
836//
837
838//#define CSIGMA0( x ) (ROR64((x), 28) ^ ROR64((x), 34) ^ ROR64((x), 39))
839//#define CSIGMA1( x ) (ROR64((x), 14) ^ ROR64((x), 18) ^ ROR64((x), 41))
840//#define LSIGMA0( x ) (ROR64((x), 1) ^ ROR64((x), 8) ^ ((x)>> 7))
841//#define LSIGMA1( x ) (ROR64((x), 19) ^ ROR64((x), 61) ^ ((x)>> 6))
842
843#define CSIGMA0( x ) (ROR64((ROR64((x), 6) ^ ROR64((x), 11) ^ (x)), 28))
844#define CSIGMA1( x ) (ROR64((ROR64((x), 4) ^ ROR64((x), 27) ^ (x)), 14))
845#define LSIGMA0( x ) (ROR64((x) ^ ROR64((x), 7), 1) ^ ((x)>> 7))
846#define LSIGMA1( x ) (ROR64((x) ^ ROR64((x), 42), 19) ^ ((x)>> 6))
847
848
849
850//
851// The values a-h were stored in an array called ah.
852// We have unrolled the loop 16 times. This makes both the indices into
853// the ah array constant, and it makes the message addressing constant.
854// This provides a significant speed improvement, at the cost of making
855// the main loop about 4 kB in code.
856//
857// Initial round; r16 is the round number mod 16
858// ah[ r16 &7] = h
859// ah[(r16+1)&7] = g;
860// ah[(r16+2)&7] = f;
861// ah[(r16+3)&7] = e;
862// ah[(r16+4)&7] = d;
863// ah[(r16+5)&7] = c;
864// ah[(r16+6)&7] = b;
865// ah[(r16+7)&7] = a;
866//
867// Unfortunately, the compiler seems to choke on this, allocating an extra variable for
868// each of the array indices, with duplicate stores to both locations.
869//
870
871//
872// The core round, after the message word has been computed for this round and put in Wt.
873// r16 is the round number modulo 16. (Static after loop unrolling)
874// r is the round number
875#define CROUND( a, b, c, d, e, f, g, h, r, r16 ) {;\
876 W[r16] = Wt; \
877 h += CSIGMA1(e) + CH(e, f, g) + SymCryptSha512K[r] + Wt;\
878 d += h;\
879 h += CSIGMA0(a) + MAJ(a, b, c);\
880}
881
882//
883// Initial round that reads the message.
884// r is the round number 0..15
885//
886#define IROUND( a, b, c, d, e, f, g, h, r ) {\
887 Wt = SYMCRYPT_LOAD_MSBFIRST64( &pbData[ 8*r ] );\
888 CROUND( a, b, c, d, e, f, g, h, r, r);\
889 }
890//
891// Subsequent rounds.
892// r is the round number, r16 is the round number mod 16.
893// These are separate as typically r is run-time and r16 is compile time constant.
894//
895#define FROUND( a, b, c, d, e, f, g, h, r, r16 ) { \
896 Wt = LSIGMA1( W[(r16-2) & 15] ) + W[(r16-7) & 15] + \
897 LSIGMA0( W[(r16-15) & 15]) + W[r16 & 15]; \
898 CROUND( a, b, c, d, e, f, g, h, r, r16 ); \
899 }
900
901//
902// This is the core routine that does the actual hard work
903// This is based on the older one in RSA32LIB by Scott Field from 2001
904//
905VOID
911 _Out_ SIZE_T * pcbRemaining )
912{
914 UINT64 A, B, C, D, E, F, G, H;
915 int round;
916 UINT64 Wt;
917
918
919 while( cbData >= 128 )
920 {
921 A = pChain->H[0];
922 B = pChain->H[1];
923 C = pChain->H[2];
924 D = pChain->H[3];
925 E = pChain->H[4];
926 F = pChain->H[5];
927 G = pChain->H[6];
928 H = pChain->H[7];
929
930 //
931 // initial rounds 1 to 16
932 //
933
934 IROUND( A, B, C, D, E, F, G, H, 0 );
935 IROUND( H, A, B, C, D, E, F, G, 1 );
936 IROUND( G, H, A, B, C, D, E, F, 2 );
937 IROUND( F, G, H, A, B, C, D, E, 3 );
938 IROUND( E, F, G, H, A, B, C, D, 4 );
939 IROUND( D, E, F, G, H, A, B, C, 5 );
940 IROUND( C, D, E, F, G, H, A, B, 6 );
941 IROUND( B, C, D, E, F, G, H, A, 7 );
942 IROUND( A, B, C, D, E, F, G, H, 8 );
943 IROUND( H, A, B, C, D, E, F, G, 9 );
944 IROUND( G, H, A, B, C, D, E, F, 10 );
945 IROUND( F, G, H, A, B, C, D, E, 11 );
946 IROUND( E, F, G, H, A, B, C, D, 12 );
947 IROUND( D, E, F, G, H, A, B, C, 13 );
948 IROUND( C, D, E, F, G, H, A, B, 14 );
949 IROUND( B, C, D, E, F, G, H, A, 15 );
950
951 for( round=16; round<80; round += 16 )
952 {
953 FROUND( A, B, C, D, E, F, G, H, round + 0, 0 );
954 FROUND( H, A, B, C, D, E, F, G, round + 1, 1 );
955 FROUND( G, H, A, B, C, D, E, F, round + 2, 2 );
956 FROUND( F, G, H, A, B, C, D, E, round + 3, 3 );
957 FROUND( E, F, G, H, A, B, C, D, round + 4, 4 );
958 FROUND( D, E, F, G, H, A, B, C, round + 5, 5 );
959 FROUND( C, D, E, F, G, H, A, B, round + 6, 6 );
960 FROUND( B, C, D, E, F, G, H, A, round + 7, 7 );
961 FROUND( A, B, C, D, E, F, G, H, round + 8, 8 );
962 FROUND( H, A, B, C, D, E, F, G, round + 9, 9 );
963 FROUND( G, H, A, B, C, D, E, F, round + 10, 10 );
964 FROUND( F, G, H, A, B, C, D, E, round + 11, 11 );
965 FROUND( E, F, G, H, A, B, C, D, round + 12, 12 );
966 FROUND( D, E, F, G, H, A, B, C, round + 13, 13 );
967 FROUND( C, D, E, F, G, H, A, B, round + 14, 14 );
968 FROUND( B, C, D, E, F, G, H, A, round + 15, 15 );
969 }
970
971 pChain->H[0] = A + pChain->H[0];
972 pChain->H[1] = B + pChain->H[1];
973 pChain->H[2] = C + pChain->H[2];
974 pChain->H[3] = D + pChain->H[3];
975 pChain->H[4] = E + pChain->H[4];
976 pChain->H[5] = F + pChain->H[5];
977 pChain->H[6] = G + pChain->H[6];
978 pChain->H[7] = H + pChain->H[7];
979
980 pbData += 128;
981 cbData -= 128;
982 }
983
984 *pcbRemaining = cbData;
985
986 //
987 // Wipe the variables;
988 //
989 SymCryptWipeKnownSize( W, sizeof( W ) );
994 SYMCRYPT_FORCE_WRITE64( &E, 0 );
998 SYMCRYPT_FORCE_WRITE64( &Wt, 0 );
999}
1000
1001//
1002// UINT64 based implementation that
1003// first computes the expanded message, and then the
1004// actual hash computation.
1005// It tries to use fewer registers; this is probably a good approach for CPUs with only 8
1006// 64-bit registers; which is what you would use on x86 XMM, but we have XMM code below.
1007// This uses more memory, but might allow better register re-use and thereby
1008// reduce the number of load/stores.
1009//
1010
1011VOID
1016 SIZE_T cbData,
1017 _Out_ SIZE_T * pcbRemaining )
1018{
1019 SYMCRYPT_ALIGN UINT64 buf[4 + 8 + 80]; // 4 words original chaining state, chaining state, and expanded input block
1020 UINT64 * W = &buf[4 + 8];
1021 UINT64 * ha = &buf[4]; // initial state words, in order h, g, ..., b, a
1022 UINT64 A, B, C, D, T;
1023 int r;
1024
1025 ha[7] = pChain->H[0]; buf[3] = ha[7];
1026 ha[6] = pChain->H[1]; buf[2] = ha[6];
1027 ha[5] = pChain->H[2]; buf[1] = ha[5];
1028 ha[4] = pChain->H[3]; buf[0] = ha[4];
1029 ha[3] = pChain->H[4];
1030 ha[2] = pChain->H[5];
1031 ha[1] = pChain->H[6];
1032 ha[0] = pChain->H[7];
1033
1034 while( cbData >= 128 )
1035 {
1036
1037 //
1038 // Capture the input into W[0..15]
1039 //
1040 for( r=0; r<16; r+= 2 )
1041 {
1042 W[r ] = SYMCRYPT_LOAD_MSBFIRST64( &pbData[ 8* r ] );
1043 W[r+1] = SYMCRYPT_LOAD_MSBFIRST64( &pbData[ 8*(r+1) ] );
1044 }
1045
1046 //
1047 // Expand the message
1048 //
1049 A = W[15];
1050 B = W[14];
1051 D = W[0];
1052 for( r=16; r<80; r+= 2 )
1053 {
1054 // Loop invariant: A=W[r-1], B = W[r-2], D = W[r-16]
1055
1056 //
1057 // Macro for one word of message expansion.
1058 // Invariant:
1059 // on entry: a = W[r-1], b = W[r-2], d = W[r-16]
1060 // on exit: W[r] computed, a = W[r-1], b = W[r], c = W[r-15]
1061 //
1062 #define EXPAND( a, b, c, d, r ) \
1063 c = W[r-15]; \
1064 b = d + LSIGMA1( b ) + W[r-7] + LSIGMA0( c ); \
1065 W[r] = b; \
1066
1067 EXPAND( A, B, C, D, r );
1068 EXPAND( B, A, D, C, (r+1));
1069
1070 #undef EXPAND
1071 }
1072
1073 A = ha[7];
1074 B = ha[6];
1075 C = ha[5];
1076 D = ha[4];
1077
1078 for( r=0; r<80; r += 4 )
1079 {
1080 //
1081 // Loop invariant:
1082 // A, B, C, and D are the a,b,c,d values of the current state.
1083 // W[r] is the next expanded message word to be processed.
1084 // W[r-8 .. r-5] contain the current state words h, g, f, e.
1085 //
1086
1087 //
1088 // Macro to compute one round
1089 //
1090 #define DO_ROUND( a, b, c, d, t, r ) \
1091 t = W[r] + CSIGMA1( W[r-5] ) + W[r-8] + CH( W[r-5], W[r-6], W[r-7] ) + SymCryptSha512K[r]; \
1092 W[r-4] = t + d; \
1093 d = t + CSIGMA0( a ) + MAJ( c, b, a );
1094
1095 DO_ROUND( A, B, C, D, T, r );
1096 DO_ROUND( D, A, B, C, T, (r+1) );
1097 DO_ROUND( C, D, A, B, T, (r+2) );
1098 DO_ROUND( B, C, D, A, T, (r+3) );
1099 #undef DO_ROUND
1100 }
1101
1102 buf[3] = ha[7] = buf[3] + A;
1103 buf[2] = ha[6] = buf[2] + B;
1104 buf[1] = ha[5] = buf[1] + C;
1105 buf[0] = ha[4] = buf[0] + D;
1106 ha[3] += W[r-5];
1107 ha[2] += W[r-6];
1108 ha[1] += W[r-7];
1109 ha[0] += W[r-8];
1110
1111 pbData += 128;
1112 cbData -= 128;
1113 }
1114
1115 pChain->H[0] = ha[7];
1116 pChain->H[1] = ha[6];
1117 pChain->H[2] = ha[5];
1118 pChain->H[3] = ha[4];
1119 pChain->H[4] = ha[3];
1120 pChain->H[5] = ha[2];
1121 pChain->H[6] = ha[1];
1122 pChain->H[7] = ha[0];
1123
1124 *pcbRemaining = cbData;
1125
1126 //
1127 // Wipe the variables;
1128 //
1129 SymCryptWipeKnownSize( buf, sizeof( buf ) );
1135
1136}
1137
1138//
1139// UINT64 based implementation that
1140// first computes the expanded message, and then the
1141// actual hash computation.
1142// This one uses more registers than the previous one.
1143//
1144
1145VOID
1150 SIZE_T cbData,
1151 _Out_ SIZE_T * pcbRemaining )
1152{
1154 SYMCRYPT_ALIGN UINT64 ha[8];
1155 UINT64 A, B, C, D, E, F, G, H;
1156 int r;
1157
1158 ha[7] = pChain->H[0];
1159 ha[6] = pChain->H[1];
1160 ha[5] = pChain->H[2];
1161 ha[4] = pChain->H[3];
1162 ha[3] = pChain->H[4];
1163 ha[2] = pChain->H[5];
1164 ha[1] = pChain->H[6];
1165 ha[0] = pChain->H[7];
1166
1167 while( cbData >= 128 )
1168 {
1169
1170 //
1171 // Capture the input into W[0..15]
1172 //
1173 for( r=0; r<16; r+= 2 )
1174 {
1175 W[r ] = SYMCRYPT_LOAD_MSBFIRST64( &pbData[ 8* r ] );
1176 W[r+1] = SYMCRYPT_LOAD_MSBFIRST64( &pbData[ 8*(r+1) ] );
1177 }
1178
1179 //
1180 // Expand the message
1181 //
1182 A = W[15];
1183 B = W[14];
1184 D = W[0];
1185 for( r=16; r<80; r+= 2 )
1186 {
1187 // Loop invariant: A=W[r-1], B = W[r-2], D = W[r-16]
1188
1189 //
1190 // Macro for one word of message expansion.
1191 // Invariant:
1192 // on entry: a = W[r-1], b = W[r-2], d = W[r-16]
1193 // on exit: W[r] computed, a = W[r-1], b = W[r], c = W[r-15]
1194 //
1195 #define EXPAND( a, b, c, d, r ) \
1196 c = W[r-15]; \
1197 b = d + LSIGMA1( b ) + W[r-7] + LSIGMA0( c ); \
1198 W[r] = b; \
1199
1200 EXPAND( A, B, C, D, r );
1201 EXPAND( B, A, D, C, (r+1));
1202
1203 #undef EXPAND
1204 }
1205
1206 A = ha[7];
1207 B = ha[6];
1208 C = ha[5];
1209 D = ha[4];
1210 E = ha[3];
1211 F = ha[2];
1212 G = ha[1];
1213 H = ha[0];
1214
1215 for( r=0; r<80; r += 8 )
1216 {
1217 //
1218 // Loop invariant:
1219 // A, B, C, and D, E, F, G, H, are the values of the current state.
1220 // W[r] is the next expanded message word to be processed.
1221 //
1222
1223 //
1224 // Macro to compute one round
1225 //
1226 #define DO_ROUND( a, b, c, d, e, f, g, h, r ) \
1227 h += W[r] + CSIGMA1( e ) + CH( e, f, g ) + SymCryptSha512K[r]; \
1228 d += h; \
1229 h += CSIGMA0( a ) + MAJ( c, b, a );
1230
1231 DO_ROUND( A, B, C, D, E, F, G, H, (r ) );
1232 DO_ROUND( H, A, B, C, D, E, F, G, (r+1) );
1233 DO_ROUND( G, H, A, B, C, D, E, F, (r+2) );
1234 DO_ROUND( F, G, H, A, B, C, D, E, (r+3) );
1235 DO_ROUND( E, F, G, H, A, B, C, D, (r+4) );
1236 DO_ROUND( D, E, F, G, H, A, B, C, (r+5) );
1237 DO_ROUND( C, D, E, F, G, H, A, B, (r+6) );
1238 DO_ROUND( B, C, D, E, F, G, H, A, (r+7) );
1239 #undef DO_ROUND
1240 }
1241
1242 ha[7] += A;
1243 ha[6] += B;
1244 ha[5] += C;
1245 ha[4] += D;
1246 ha[3] += E;
1247 ha[2] += F;
1248 ha[1] += G;
1249 ha[0] += H;
1250
1251 pbData += 128;
1252 cbData -= 128;
1253 }
1254
1255 pChain->H[0] = ha[7];
1256 pChain->H[1] = ha[6];
1257 pChain->H[2] = ha[5];
1258 pChain->H[3] = ha[4];
1259 pChain->H[4] = ha[3];
1260 pChain->H[5] = ha[2];
1261 pChain->H[6] = ha[1];
1262 pChain->H[7] = ha[0];
1263
1264 *pcbRemaining = cbData;
1265
1266 //
1267 // Wipe the variables;
1268 //
1269 SymCryptWipeKnownSize( W, sizeof( W ) );
1270 SymCryptWipeKnownSize( ha, sizeof( ha ) );
1275 SYMCRYPT_FORCE_WRITE64( &E, 0 );
1279}
1280
1281#undef MAJ
1282#undef CH
1283#undef CSIGMA0
1284#undef CSIGMA1
1285#undef LSIGMA0
1286#undef LSIGMA1
1287#undef CROUND
1288#undef IROUND
1289#undef FROUND
1290
1291//======================================================================================
1292// Implementation using Xmm registers
1293//
1294#if SYMCRYPT_CPU_X86 // only on X86; AMD64 is faster when using UINT64s
1295
1296#ifdef __clang__
1297#pragma clang attribute push (__attribute__((target("ssse3"))), apply_to=function)
1298#else
1299#pragma GCC push_options
1300#pragma GCC target("ssse3")
1301#endif
1302
1303
1304#define XMMADD( _a, _b ) _mm_add_epi64((_a), (_b))
1305#define XMMAND( _a, _b ) _mm_and_si128((_a), (_b))
1306#define XMMOR( _a, _b ) _mm_or_si128((_a), (_b))
1307#define XMMROR( _a, _n ) _mm_xor_si128( _mm_slli_epi64( (_a), 64-(_n)), _mm_srli_epi64( (_a), (_n)) )
1308#define XMMSHR( _a, _n ) _mm_srli_epi64((_a), (_n))
1309#define XMMXOR( _a, _b ) _mm_xor_si128((_a), (_b))
1310#define XMMSTORE_UINT64( _a, _addr ) _mm_storel_epi64((__m128i*)(_addr), (_a))
1311
1312#define XMMMAJ( x, y, z ) XMMOR( XMMAND( XMMOR( (z), (y)), (x)), XMMAND( (z), (y) ) )
1313#define XMMCH( x, y, z ) XMMXOR( XMMAND( XMMXOR( (z), (y) ), (x)), (z))
1314#define XMMCSIGMA0( x ) XMMXOR( XMMXOR( XMMROR((x), 28), XMMROR((x), 34)), XMMROR((x), 39))
1315#define XMMCSIGMA1( x ) XMMXOR( XMMXOR( XMMROR((x), 14), XMMROR((x), 18)), XMMROR((x), 41))
1316#define XMMLSIGMA0( x ) XMMXOR( XMMXOR( XMMROR((x), 1), XMMROR((x), 8)), XMMSHR((x), 7))
1317#define XMMLSIGMA1( x ) XMMXOR( XMMXOR( XMMROR((x), 19), XMMROR((x), 61)), XMMSHR((x), 6))
1318
1319//
1320// Core round takes two arguments: r16 = round number modulo 16, r = round number - r16.
1321// On entry, Wt must be equal to the sum of the round constant and the expanded message word for this round.
1322// Only the lower word of each Xmm register is used.
1323//
1324#define XMMCROUND( r16, r ) {;\
1325 ah[r16 & 7] = XMMADD( XMMADD( XMMADD( ah[r16 & 7], XMMCSIGMA1(ah[(r16+3)&7]) ), XMMCH(ah[(r16+3)&7], ah[(r16+2)&7], ah[(r16+1)&7]) ), Wt );\
1326 ah[(r16+4)&7] = XMMADD( ah[(r16+4)&7], ah[r16 &7] );\
1327 ah[r16 & 7] = XMMADD( XMMADD( ah[r16 & 7], XMMCSIGMA0(ah[(r16+7)&7])), XMMMAJ(ah[(r16+7)&7], ah[(r16+6)&7], ah[(r16+5)&7]) );\
1328}
1329
1330#pragma warning( disable: 4127 ) // conditional expression is constant
1331
1332//
1333// Initial round; reads data and performs a round.
1334// Data is read in 128-bit chunks every other round.
1335//
1336#define XMMIROUND( r ) {\
1337 if( (r&1) == 0 ) \
1338 { \
1339 Wt = _mm_loadu_si128( (__m128i *)&pbData[ 8*r ] ); \
1340 Wt = _mm_shuffle_epi8( Wt, BYTE_REVERSE_64 ); \
1341 W[r/2] = Wt; \
1342 Wt = XMMADD( Wt, _mm_load_si128( (__m128i *)&SymCryptSha512K[r] ) ); \
1343 Ws = _mm_srli_si128( Wt, 8 ); \
1344 } else {\
1345 Wt = Ws;\
1346 }\
1347 XMMCROUND( r, r );\
1348}
1349
1350//
1351// Working version of XMMIROUND:
1352// Wt = XMMFROM_MSBF( &pbData[ 8*r ] );\
1353// W[r] = Wt;\
1354// Wt = XMMADD( XMMFROM_UINT64(SymCryptSha512K[r]), Wt );\
1355// XMMCROUND(r,r);\
1356
1357#define XMMFROUND(r16, rb) { \
1358 if( (r16 & 1) == 0 ) \
1359 {\
1360 Wt = XMMADD( XMMADD( XMMADD( XMMLSIGMA1( W[((r16 - 2)&15)/2] ), \
1361 _mm_alignr_epi8( W[((r16 - 6)&15)/2], W[((r16 - 7)&15)/2], 8 ) ), \
1362 XMMLSIGMA0( _mm_alignr_epi8( W[((r16 - 14)&15)/2], W[((r16 - 15)&15)/2], 8 ) ) ), \
1363 W[((r16 - 16)&15)/2] ); \
1364 W[r16/2] = Wt;\
1365 Ws = _mm_load_si128( (__m128i *)&SymCryptSha512K[r16 + rb] );\
1366 Wt = XMMADD( Ws , Wt );\
1367 Ws = _mm_srli_si128( Wt, 8 );\
1368 } else {\
1369 Wt = Ws;\
1370 }\
1371 XMMCROUND( r16, r16+rb ); \
1372}
1373
1374VOID
1379 SIZE_T cbData,
1380 _Out_ SIZE_T * pcbRemaining )
1381{
1382 SYMCRYPT_ALIGN __m128i W[8]; // message expansion buffer, 8 elements each storing 2 consecutive UINT64s
1383 SYMCRYPT_ALIGN __m128i ah[8];
1384 SYMCRYPT_ALIGN __m128i feedf[8];
1385 int round;
1386 __m128i Wt, Ws;
1387 const __m128i BYTE_REVERSE_64 = _mm_set_epi8( 8, 9, 10, 11, 12, 13, 14, 15, 0, 1, 2, 3, 4, 5, 6, 7 );
1388
1389 Wt = _mm_loadu_si128( (__m128i *) &pChain->H[0] );
1390 feedf[7] = ah[7] = Wt;
1391 feedf[6] = ah[6] = _mm_srli_si128( Wt, 8 );
1392 Wt = _mm_loadu_si128( (__m128i *) &pChain->H[2] );
1393 feedf[5] = ah[5] = Wt;
1394 feedf[4] = ah[4] = _mm_srli_si128( Wt, 8 );
1395 Wt = _mm_loadu_si128( (__m128i *) &pChain->H[4] );
1396 feedf[3] = ah[3] = Wt;
1397 feedf[2] = ah[2] = _mm_srli_si128( Wt, 8 );
1398 Wt = _mm_loadu_si128( (__m128i *) &pChain->H[6] );
1399 feedf[1] = ah[1] = Wt;
1400 feedf[0] = ah[0] = _mm_srli_si128( Wt, 8 );
1401
1402 while( cbData >= 128 )
1403 {
1404 //
1405 // initial rounds 1 to 16
1406 //
1407
1408 XMMIROUND( 0 );
1409 XMMIROUND( 1 );
1410 XMMIROUND( 2 );
1411 XMMIROUND( 3 );
1412 XMMIROUND( 4 );
1413 XMMIROUND( 5 );
1414 XMMIROUND( 6 );
1415 XMMIROUND( 7 );
1416 XMMIROUND( 8 );
1417 XMMIROUND( 9 );
1418 XMMIROUND( 10 );
1419 XMMIROUND( 11 );
1420 XMMIROUND( 12 );
1421 XMMIROUND( 13 );
1422 XMMIROUND( 14 );
1423 XMMIROUND( 15 );
1424
1425 for( round=16; round<80; round += 16 )
1426 {
1427 XMMFROUND( 0, round );
1428 XMMFROUND( 1, round );
1429 XMMFROUND( 2, round );
1430 XMMFROUND( 3, round );
1431 XMMFROUND( 4, round );
1432 XMMFROUND( 5, round );
1433 XMMFROUND( 6, round );
1434 XMMFROUND( 7, round );
1435 XMMFROUND( 8, round );
1436 XMMFROUND( 9, round );
1437 XMMFROUND( 10, round );
1438 XMMFROUND( 11, round );
1439 XMMFROUND( 12, round );
1440 XMMFROUND( 13, round );
1441 XMMFROUND( 14, round );
1442 XMMFROUND( 15, round );
1443 }
1444
1445 feedf[0] = ah[0] = XMMADD( ah[0], feedf[0] );
1446 feedf[1] = ah[1] = XMMADD( ah[1], feedf[1] );
1447 feedf[2] = ah[2] = XMMADD( ah[2], feedf[2] );
1448 feedf[3] = ah[3] = XMMADD( ah[3], feedf[3] );
1449 feedf[4] = ah[4] = XMMADD( ah[4], feedf[4] );
1450 feedf[5] = ah[5] = XMMADD( ah[5], feedf[5] );
1451 feedf[6] = ah[6] = XMMADD( ah[6], feedf[6] );
1452 feedf[7] = ah[7] = XMMADD( ah[7], feedf[7] );
1453
1454 pbData += 128;
1455 cbData -= 128;
1456
1457 }
1458
1459 XMMSTORE_UINT64( ah[7], &(pChain->H[0]) );
1460 XMMSTORE_UINT64( ah[6], &(pChain->H[1]) );
1461 XMMSTORE_UINT64( ah[5], &(pChain->H[2]) );
1462 XMMSTORE_UINT64( ah[4], &(pChain->H[3]) );
1463 XMMSTORE_UINT64( ah[3], &(pChain->H[4]) );
1464 XMMSTORE_UINT64( ah[2], &(pChain->H[5]) );
1465 XMMSTORE_UINT64( ah[1], &(pChain->H[6]) );
1466 XMMSTORE_UINT64( ah[0], &(pChain->H[7]) );
1467
1468 *pcbRemaining = cbData;
1469
1470 //
1471 // Wipe the variables;
1472 //
1473 SymCryptWipeKnownSize( ah, sizeof( ah ) );
1474 SymCryptWipeKnownSize( feedf, sizeof( feedf ) );
1475 SymCryptWipeKnownSize( W, sizeof( W ) );
1476 SymCryptWipeKnownSize( &Wt, sizeof( Wt ));
1477 SymCryptWipeKnownSize( &Ws, sizeof( Ws ));
1478}
1479
1480#ifdef __clang__
1481#pragma clang attribute pop
1482#else
1483#pragma GCC pop_options
1484#endif
1485
1486#endif
1487
1488
1489
1490//======================================================================================
1491// Implementation using NEON registers
1492//
1493#if SYMCRYPT_CPU_ARM
1494
1495
1496#define ROR( _a, _n ) vorr_u64( vshl_n_u64( _a, 64 - _n ), vshr_n_u64( _a, _n ) )
1497#define ADD( x, y ) vadd_u64( (x), (y) )
1498
1499#define MAJ( x, y, z ) vorr_u64( vand_u64( vorr_u64( (z), (y)), (x)), vand_u64( (z), (y) ) )
1500#define CH( x, y, z ) veor_u64( vand_u64( veor_u64( (z), (y) ), (x)), (z))
1501#define CSIGMA0( x ) veor_u64( veor_u64( ROR((x), 28), ROR((x), 34)), ROR((x), 39))
1502#define CSIGMA1( x ) veor_u64( veor_u64( ROR((x), 14), ROR((x), 18)), ROR((x), 41))
1503#define LSIGMA0( x ) veor_u64( veor_u64( ROR((x), 1), ROR((x), 8)), vshr_n_u64((x), 7))
1504#define LSIGMA1( x ) veor_u64( veor_u64( ROR((x), 19), ROR((x), 61)), vshr_n_u64((x), 6))
1505
1506//
1507// r = round number, r16 = r mod 16 (often a compile-time constant when r is not)
1508//
1509#define CROUND( a, b, c, d, e, f, g, h, r, r16 ) {\
1510 W[r16] = Wt; \
1511 h = ADD( h, ADD( ADD( ADD( CSIGMA1(e), CH(e, f, g)), *(__n64 *)&SymCryptSha512K[r]), Wt ));\
1512 d = ADD( d, h );\
1513 h = ADD( h, ADD( CSIGMA0(a), MAJ(a, b, c)));\
1514}
1515
1516//
1517// Initial round that reads the message.
1518// r is the round number 0..15
1519//
1520#define IROUND( a, b, c, d, e, f, g, h, r ) {\
1521 Wt = vmov_n_u64( SYMCRYPT_LOAD_MSBFIRST64( &pbData[ 8*r ] ) );\
1522 CROUND( a, b, c, d, e, f, g, h, r, r);\
1523 }
1524//
1525// Subsequent rounds.
1526// r is the round number, r16 is the round number mod 16.
1527// These are separate as typically r is run-time and r16 is compile time constant.
1528//
1529#define FROUND( a, b, c, d, e, f, g, h, r, r16 ) { \
1530 Wt = ADD( ADD( LSIGMA1( W[(r16-2) & 15] ), LSIGMA0( W[(r16-15) & 15])) , ADD( W[(r16-7) & 15], W[r16 & 15])); \
1531 CROUND( a, b, c, d, e, f, g, h, r, r16 ); \
1532 }
1533
1534//
1535// This is the core routine that does the actual hard work
1536// This is based on the older one in RSA32LIB by Scott Field from 2001
1537//
1538VOID
1540SymCryptSha512AppendBlocks_neon(
1543 SIZE_T cbData,
1544 _Out_ SIZE_T * pcbRemaining )
1545{
1546 SYMCRYPT_ALIGN __n64 W[16];
1547 __n64 A, B, C, D, E, F, G, H;
1548 int round;
1549 __n64 Wt;
1550 __n64 * pH = (__n64 *) &pChain->H[0];
1551
1552 A = pH[0];
1553 B = pH[1];
1554 C = pH[2];
1555 D = pH[3];
1556 E = pH[4];
1557 F = pH[5];
1558 G = pH[6];
1559 H = pH[7];
1560
1561 while( cbData >= 128 )
1562 {
1563 //
1564 // initial rounds 1 to 16
1565 //
1566
1567 IROUND( A, B, C, D, E, F, G, H, 0 );
1568 IROUND( H, A, B, C, D, E, F, G, 1 );
1569 IROUND( G, H, A, B, C, D, E, F, 2 );
1570 IROUND( F, G, H, A, B, C, D, E, 3 );
1571 IROUND( E, F, G, H, A, B, C, D, 4 );
1572 IROUND( D, E, F, G, H, A, B, C, 5 );
1573 IROUND( C, D, E, F, G, H, A, B, 6 );
1574 IROUND( B, C, D, E, F, G, H, A, 7 );
1575 IROUND( A, B, C, D, E, F, G, H, 8 );
1576 IROUND( H, A, B, C, D, E, F, G, 9 );
1577 IROUND( G, H, A, B, C, D, E, F, 10 );
1578 IROUND( F, G, H, A, B, C, D, E, 11 );
1579 IROUND( E, F, G, H, A, B, C, D, 12 );
1580 IROUND( D, E, F, G, H, A, B, C, 13 );
1581 IROUND( C, D, E, F, G, H, A, B, 14 );
1582 IROUND( B, C, D, E, F, G, H, A, 15 );
1583
1584 for( round=16; round<80; round += 16 )
1585 {
1586 FROUND( A, B, C, D, E, F, G, H, round + 0, 0 );
1587 FROUND( H, A, B, C, D, E, F, G, round + 1, 1 );
1588 FROUND( G, H, A, B, C, D, E, F, round + 2, 2 );
1589 FROUND( F, G, H, A, B, C, D, E, round + 3, 3 );
1590 FROUND( E, F, G, H, A, B, C, D, round + 4, 4 );
1591 FROUND( D, E, F, G, H, A, B, C, round + 5, 5 );
1592 FROUND( C, D, E, F, G, H, A, B, round + 6, 6 );
1593 FROUND( B, C, D, E, F, G, H, A, round + 7, 7 );
1594 FROUND( A, B, C, D, E, F, G, H, round + 8, 8 );
1595 FROUND( H, A, B, C, D, E, F, G, round + 9, 9 );
1596 FROUND( G, H, A, B, C, D, E, F, round + 10, 10 );
1597 FROUND( F, G, H, A, B, C, D, E, round + 11, 11 );
1598 FROUND( E, F, G, H, A, B, C, D, round + 12, 12 );
1599 FROUND( D, E, F, G, H, A, B, C, round + 13, 13 );
1600 FROUND( C, D, E, F, G, H, A, B, round + 14, 14 );
1601 FROUND( B, C, D, E, F, G, H, A, round + 15, 15 );
1602 }
1603
1604 pH[0] = A = ADD( A, pH[0] );
1605 pH[1] = B = ADD( B, pH[1] );
1606 pH[2] = C = ADD( C, pH[2] );
1607 pH[3] = D = ADD( D, pH[3] );
1608 pH[4] = E = ADD( E, pH[4] );
1609 pH[5] = F = ADD( F, pH[5] );
1610 pH[6] = G = ADD( G, pH[6] );
1611 pH[7] = H = ADD( H, pH[7] );
1612
1613 pbData += 128;
1614 cbData -= 128;
1615 }
1616
1617 *pcbRemaining = cbData;
1618
1619 //
1620 // Wipe the variables;
1621 //
1622 SymCryptWipeKnownSize( W, sizeof( W ) );
1623 SymCryptWipeKnownSize( &A, sizeof( A ) );
1624 SymCryptWipeKnownSize( &B, sizeof( B ) );
1625 SymCryptWipeKnownSize( &C, sizeof( C ) );
1626 SymCryptWipeKnownSize( &D, sizeof( D ) );
1627 SymCryptWipeKnownSize( &E, sizeof( E ) );
1628 SymCryptWipeKnownSize( &F, sizeof( F ) );
1629 SymCryptWipeKnownSize( &G, sizeof( G ) );
1630 SymCryptWipeKnownSize( &H, sizeof( H ) );
1631 SymCryptWipeKnownSize( &Wt, sizeof( Wt ) );
1632}
1633
1634#endif
1635
1636//======================================================================================
1637//
1638// Switch between different implementations of compression function
1639//
1640//FORCEINLINE
1641VOID
1646 SIZE_T cbData,
1647 _Out_ SIZE_T * pcbRemaining )
1648{
1649#if SYMCRYPT_CPU_AMD64
1650
1651 // Temporarily disabling use of Ymm in SHA2
1652 // SYMCRYPT_EXTENDED_SAVE_DATA SaveData;
1653
1654 // if (SYMCRYPT_CPU_FEATURES_PRESENT(SYMCRYPT_CPU_FEATURE_AVX512 | SYMCRYPT_CPU_FEATURE_BMI2) &&
1655 // SymCryptSaveYmm(&SaveData) == SYMCRYPT_NO_ERROR)
1656 // {
1657 // SymCryptSha512AppendBlocks_ymm_avx512vl_asm(pChain, pbData, cbData, pcbRemaining);
1658
1659 // SymCryptRestoreYmm(&SaveData);
1660 // }
1661 // else if (SYMCRYPT_CPU_FEATURES_PRESENT(SYMCRYPT_CPU_FEATURE_AVX2 | SYMCRYPT_CPU_FEATURE_BMI2) &&
1662 // SymCryptSaveYmm(&SaveData) == SYMCRYPT_NO_ERROR)
1663 // {
1664 // //SymCryptSha512AppendBlocks_ymm_1block(pChain, pbData, cbData, pcbRemaining);
1665 // //SymCryptSha512AppendBlocks_ymm_2blocks(pChain, pbData, cbData, pcbRemaining);
1666 // //SymCryptSha512AppendBlocks_ymm_4blocks(pChain, pbData, cbData, pcbRemaining);
1667 // SymCryptSha512AppendBlocks_ymm_avx2_asm(pChain, pbData, cbData, pcbRemaining);
1668
1669 // SymCryptRestoreYmm(&SaveData);
1670 // }
1671 // else
1672 {
1673 SymCryptSha512AppendBlocks_ull( pChain, pbData, cbData, pcbRemaining );
1674 //SymCryptSha512AppendBlocks_ull2( pChain, pbData, cbData, pcbRemaining );
1675 //SymCryptSha512AppendBlocks_ull3( pChain, pbData, cbData, pcbRemaining );
1676 }
1677
1678
1679#elif SYMCRYPT_CPU_ARM
1680
1681 if( SYMCRYPT_CPU_FEATURES_PRESENT( SYMCRYPT_CPU_FEATURE_NEON ) )
1682 {
1683 SymCryptSha512AppendBlocks_neon( pChain, pbData, cbData, pcbRemaining ); // Tegra T3: 48 c/B
1684 } else {
1685 SymCryptSha512AppendBlocks_ull( pChain, pbData, cbData, pcbRemaining ); // Tegra T3: 65.34 c/B
1686 //SymCryptSha512AppendBlocks_ull2( pChain, pbData, cbData, pcbRemaining ); // Tegra T3: 77.4 c/B
1687 //SymCryptSha512AppendBlocks_ull3( pChain, pbData, cbData, pcbRemaining ); // Tegra T3: 71.6 c/B
1688 }
1689
1690#elif SYMCRYPT_CPU_X86
1691
1692 SYMCRYPT_EXTENDED_SAVE_DATA SaveData;
1693
1694 if( SYMCRYPT_CPU_FEATURES_PRESENT( SYMCRYPT_CPU_FEATURE_SSSE3 ) && SymCryptSaveXmm( &SaveData ) == SYMCRYPT_NO_ERROR )
1695 {
1696 SymCryptSha512AppendBlocks_xmm( pChain, pbData, cbData, pcbRemaining );
1697 SymCryptRestoreXmm( &SaveData );
1698 } else {
1699 SymCryptSha512AppendBlocks_ull( pChain, pbData, cbData, pcbRemaining ); // core2: 36.40 c/B
1700 //SymCryptSha512AppendBlocks_ull2( pChain, pbData, cbData, pcbRemaining ); // core2: 49.09 c/B
1701 //SymCryptSha512AppendBlocks_ull3( pChain, pbData, cbData, pcbRemaining ); // core2: 38.29 c/B
1702 }
1703
1704#else
1705
1706 SymCryptSha512AppendBlocks_ull( pChain, pbData, cbData, pcbRemaining ); // need tuning...
1707
1708#endif
1709}
COMPILER_DEPENDENT_UINT64 UINT64
Definition: actypes.h:131
#define G(r, i, a, b, c, d)
Definition: blake2b-ref.c:117
#define D(d)
Definition: builtin.c:4557
#define C(c)
Definition: builtin.c:4556
Definition: ehthrow.cxx:93
Definition: ehthrow.cxx:54
Definition: terminate.cpp:24
VOID SaveData(HWND hwndDlg)
Definition: volume.c:368
#define A(row, col)
#define B(row, col)
static cab_ULONG checksum(const cab_UBYTE *data, cab_UWORD bytes, cab_ULONG csum)
Definition: fdi.c:353
static void cleanup(void)
Definition: main.c:1335
_ACRTIMP int __cdecl memcmp(const void *, const void *, size_t)
Definition: string.c:2807
__m128i _mm_set_epi8(char b15, char b14, char b13, char b12, char b11, char b10, char b9, char b8, char b7, char b6, char b5, char b4, char b3, char b2, char b1, char b0)
Definition: emmintrin.h:1610
__m128i _mm_srli_si128(__m128i a, int imm)
Definition: emmintrin.h:1414
__m128i _mm_loadu_si128(__m128i_u const *p)
Definition: emmintrin.h:1561
GLuint GLuint GLsizei GLenum type
Definition: gl.h:1545
GLdouble GLdouble GLdouble r
Definition: gl.h:2055
GLenum GLuint GLenum GLsizei const GLchar * buf
Definition: glext.h:7751
GLuint64EXT * result
Definition: glext.h:11304
#define C_ASSERT(e)
Definition: intsafe.h:73
#define memcpy(s1, s2, n)
Definition: mkisofs.h:878
#define H
#define _In_reads_bytes_(s)
Definition: no_sal2.h:170
#define _In_reads_(s)
Definition: no_sal2.h:168
#define _Inout_
Definition: no_sal2.h:162
#define _Out_writes_(s)
Definition: no_sal2.h:176
#define _Out_
Definition: no_sal2.h:160
#define _In_
Definition: no_sal2.h:158
#define _Out_writes_bytes_(s)
Definition: no_sal2.h:178
BYTE * PBYTE
Definition: pedump.c:66
#define T(num)
Definition: thunks.c:311
#define SYMCRYPT_BLOB_MAGIC
Definition: sc_lib.h:1077
FORCEINLINE VOID SYMCRYPT_CALL SymCryptMsbFirstToUint64(_In_reads_(8 *cuResult) PCBYTE pbData, _Out_writes_(cuResult) PUINT64 puResult, SIZE_T cuResult)
Definition: sc_lib.h:592
@ SymCryptBlobTypeSha512_224State
Definition: sc_lib.h:1072
@ SymCryptBlobTypeSha512_256State
Definition: sc_lib.h:1073
@ SymCryptBlobTypeSha384State
Definition: sc_lib.h:1066
@ SymCryptBlobTypeSha512State
Definition: sc_lib.h:1067
VOID SYMCRYPT_CALL SymCryptInjectError(PBYTE pbData, SIZE_T cbData)
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_xmm(_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
const BYTE SymCryptTestMsg3[3]
Definition: selftest.c:8
FORCEINLINE VOID SYMCRYPT_CALL SymCryptUint64ToMsbFirst(_In_reads_(cuData) PCUINT64 puData, _Out_writes_(8 *cuData) PBYTE pbResult, SIZE_T cuData)
Definition: sc_lib.h:576
#define F(x, y, z)
Definition: md5.c:51
const PCSYMCRYPT_HASH SymCryptSha512_256Algorithm
Definition: sha512.c:172
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks(_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
Definition: sha512.c:1643
VOID SYMCRYPT_CALL SymCryptSha512_224StateExport(_In_ PCSYMCRYPT_SHA512_224_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA512_224_STATE_EXPORT_SIZE) PBYTE pbBlob)
Definition: sha512.c:593
const BYTE SymCryptSha384KATAnswer[48]
Definition: sha512.c:728
VOID SYMCRYPT_CALL SymCryptSha384StateExport(_In_ PCSYMCRYPT_SHA384_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA384_STATE_EXPORT_SIZE) PBYTE pbBlob)
Definition: sha512.c:584
VOID SYMCRYPT_CALL SymCryptSha384Selftest(void)
Definition: sha512.c:740
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_ull2(_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
Definition: sha512.c:1013
VOID SYMCRYPT_CALL SymCryptSha512StateExportCore(_In_ PCSYMCRYPT_SHA512_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PBYTE pbBlob, _In_ UINT32 type)
Definition: sha512.c:538
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Result(_Inout_ PSYMCRYPT_SHA384_STATE pState, _Out_writes_(SYMCRYPT_SHA384_RESULT_SIZE) PBYTE pbResult)
Definition: sha512.c:460
const SYMCRYPT_HASH SymCryptSha512_256Algorithm_default
Definition: sha512.c:156
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_ull(_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
Definition: sha512.c:907
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Append(_Inout_ PSYMCRYPT_SHA384_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: sha512.c:370
const UINT64 SymCryptSha512InitialState[8]
Definition: sha512.c:68
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Init(_Out_ PSYMCRYPT_SHA512_STATE pState)
Definition: sha512.c:214
const SYMCRYPT_HASH SymCryptSha512Algorithm_default
Definition: sha512.c:130
const UINT64 SymCryptSha384InitialState[8]
Definition: sha512.c:79
const BYTE SymCryptSha512_224KATAnswer[28]
Definition: sha512.c:757
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha384StateImport(_Out_ PSYMCRYPT_SHA384_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA384_STATE_EXPORT_SIZE) PCBYTE pbBlob)
Definition: sha512.c:663
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha512_256StateImport(_Out_ PSYMCRYPT_SHA512_256_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA512_256_STATE_EXPORT_SIZE) PCBYTE pbBlob)
Definition: sha512.c:681
VOID SYMCRYPT_CALL SymCryptSha512_256StateExport(_In_ PCSYMCRYPT_SHA512_256_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA512_256_STATE_EXPORT_SIZE) PBYTE pbBlob)
Definition: sha512.c:602
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Init(_Out_ PSYMCRYPT_SHA512_256_STATE pState)
Definition: sha512.c:274
VOID SYMCRYPT_CALL SymCryptSha512StateExport(_In_ PCSYMCRYPT_SHA512_STATE pState, _Out_writes_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PBYTE pbBlob)
Definition: sha512.c:575
const UINT64 SymCryptSha512_224InitialState[8]
Definition: sha512.c:90
const BYTE SymCryptSha512KATAnswer[64]
Definition: sha512.c:695
#define DO_ROUND(a, b, c, d, t, r)
const PCSYMCRYPT_HASH SymCryptSha512_224Algorithm
Definition: sha512.c:171
VOID SYMCRYPT_CALL SymCryptSha512_256Selftest(void)
Definition: sha512.c:794
VOID SYMCRYPT_CALL SymCryptSha512_224Selftest(void)
Definition: sha512.c:767
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha512_224StateImport(_Out_ PSYMCRYPT_SHA512_224_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA512_224_STATE_EXPORT_SIZE) PCBYTE pbBlob)
Definition: sha512.c:672
#define EXPAND(a, b, c, d, r)
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha512StateImportCore(_Out_ PSYMCRYPT_SHA512_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PCBYTE pbBlob, _In_ UINT32 type)
Definition: sha512.c:612
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha384Init(_Out_ PSYMCRYPT_SHA384_STATE pState)
Definition: sha512.c:234
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Result(_Inout_ PSYMCRYPT_SHA512_224_STATE pState, _Out_writes_(SYMCRYPT_SHA512_224_RESULT_SIZE) PBYTE pbResult)
Definition: sha512.c:489
const UINT64 SymCryptSha512_256InitialState[8]
Definition: sha512.c:101
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Append(_Inout_ PSYMCRYPT_SHA512_224_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: sha512.c:383
const SYMCRYPT_HASH SymCryptSha384Algorithm_default
Definition: sha512.c:117
const PCSYMCRYPT_HASH SymCryptSha512Algorithm
Definition: sha512.c:170
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_224Init(_Out_ PSYMCRYPT_SHA512_224_STATE pState)
Definition: sha512.c:254
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Append(_Inout_ PSYMCRYPT_SHA512_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: sha512.c:294
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptSha512StateImport(_Out_ PSYMCRYPT_SHA512_STATE pState, _In_reads_bytes_(SYMCRYPT_SHA512_STATE_EXPORT_SIZE) PCBYTE pbBlob)
Definition: sha512.c:654
const PCSYMCRYPT_HASH SymCryptSha384Algorithm
Definition: sha512.c:169
VOID SYMCRYPT_CALL SymCryptSha512AppendBlocks_ull3(_Inout_ SYMCRYPT_SHA512_CHAINING_STATE *pChain, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_ SIZE_T *pcbRemaining)
Definition: sha512.c:1147
#define IROUND(a, b, c, d, e, f, g, h, r)
Definition: sha512.c:886
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Result(_Inout_ PSYMCRYPT_SHA512_256_STATE pState, _Out_writes_(SYMCRYPT_SHA512_256_RESULT_SIZE) PBYTE pbResult)
Definition: sha512.c:514
VOID SYMCRYPT_CALL SymCryptSha512Selftest(void)
Definition: sha512.c:709
const BYTE SymCryptSha512_256KATAnswer[32]
Definition: sha512.c:784
const SYMCRYPT_HASH SymCryptSha512_224Algorithm_default
Definition: sha512.c:143
#define FROUND(a, b, c, d, e, f, g, h, r, r16)
Definition: sha512.c:895
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512_256Append(_Inout_ PSYMCRYPT_SHA512_256_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: sha512.c:394
SYMCRYPT_NOINLINE VOID SYMCRYPT_CALL SymCryptSha512Result(_Inout_ PSYMCRYPT_SHA512_STATE pState, _Out_writes_(SYMCRYPT_SHA512_RESULT_SIZE) PBYTE pbResult)
Definition: sha512.c:406
static const BYTE pbResult[]
Definition: polytest.cpp:36
Definition: image.c:229
#define SYMCRYPT_ASSERT(_x)
Definition: symcrypt.h:10807
#define SYMCRYPT_SHA512_256_RESULT_SIZE
Definition: symcrypt.h:1488
VOID SYMCRYPT_CALL SymCryptMarvin32(_In_ PCSYMCRYPT_MARVIN32_EXPANDED_SEED pExpandedSeed, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_MARVIN32_RESULT_SIZE) PBYTE pbResult)
Definition: marvin32.c:239
FORCEINLINE VOID SYMCRYPT_CALL SymCryptWipeKnownSize(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)
#define SYMCRYPT_SHA512_224_RESULT_SIZE
Definition: symcrypt.h:1420
VOID SYMCRYPT_CALL SymCryptSha512_224StateCopy(_In_ PCSYMCRYPT_SHA512_224_STATE pSrc, _Out_ PSYMCRYPT_SHA512_224_STATE pDst)
VOID SYMCRYPT_CALL SymCryptWipe(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)
Definition: libmain.c:137
_Analysis_noreturn_ VOID SYMCRYPT_CALL SymCryptFatal(UINT32 fatalCode)
#define SYMCRYPT_FORCE_WRITE64(_p, _v)
Definition: symcrypt.h:424
#define SYMCRYPT_LOAD_MSBFIRST64(p)
Definition: symcrypt.h:304
VOID SYMCRYPT_CALL SymCryptSha512_256(_In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_SHA512_256_RESULT_SIZE) PBYTE pbResult)
#define SYMCRYPT_SHA512_224_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1421
#define SYMCRYPT_SHA384_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1288
VOID SYMCRYPT_CALL SymCryptSha512(_In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_SHA512_RESULT_SIZE) PBYTE pbResult)
#define SYMCRYPT_SHA512_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1353
#define SYMCRYPT_SHA384_RESULT_SIZE
Definition: symcrypt.h:1287
#define SYMCRYPT_SHA512_RESULT_SIZE
Definition: symcrypt.h:1352
PCSYMCRYPT_MARVIN32_EXPANDED_SEED const SymCryptMarvin32DefaultSeed
Definition: marvin32.c:29
VOID SYMCRYPT_CALL SymCryptSha512StateCopy(_In_ PCSYMCRYPT_SHA512_STATE pSrc, _Out_ PSYMCRYPT_SHA512_STATE pDst)
VOID SYMCRYPT_CALL SymCryptSha384(_In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_SHA384_RESULT_SIZE) PBYTE pbResult)
VOID SYMCRYPT_CALL SymCryptSha512_256StateCopy(_In_ PCSYMCRYPT_SHA512_256_STATE pSrc, _Out_ PSYMCRYPT_SHA512_256_STATE pDst)
#define SYMCRYPT_STORE_MSBFIRST64(p, v)
Definition: symcrypt.h:312
VOID SYMCRYPT_CALL SymCryptSha384StateCopy(_In_ PCSYMCRYPT_SHA384_STATE pSrc, _Out_ PSYMCRYPT_SHA384_STATE pDst)
#define SYMCRYPT_SHA512_256_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1489
SYMCRYPT_ERROR
Definition: symcrypt.h:227
VOID SYMCRYPT_CALL SymCryptSha512_224(_In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_SHA512_224_RESULT_SIZE) PBYTE pbResult)
const SYMCRYPT_SHA512_224_STATE * PCSYMCRYPT_SHA512_224_STATE
* PSYMCRYPT_SHA512_256_STATE
#define SYMCRYPT_ALIGN
#define SYMCRYPT_CALL
SYMCRYPT_SHA512_256_STATE
const SYMCRYPT_SHA512_256_STATE * PCSYMCRYPT_SHA512_256_STATE
struct _SYMCRYPT_HASH SYMCRYPT_HASH
#define SYMCRYPT_FIELD_SIZE(type, field)
const SYMCRYPT_SHA384_STATE * PCSYMCRYPT_SHA384_STATE
#define SYMCRYPT_CPU_FEATURES_PRESENT(x)
#define SYMCRYPT_ALIGN_AT(alignment)
SIZE_T bytesInBuffer
SYMCRYPT_SHA512_STATE
SYMCRYPT_SHA512_CHAINING_STATE
const SYMCRYPT_HASH * PCSYMCRYPT_HASH
PCBYTE PBYTE SIZE_T cbData
#define SYMCRYPT_SET_MAGIC(p)
* PSYMCRYPT_SHA512_STATE
#define SYMCRYPT_FIELD_OFFSET(type, field)
SYMCRYPT_SHA384_STATE
* PSYMCRYPT_SHA384_STATE
#define SYMCRYPT_SHA384_STATE_EXPORT_SIZE
SYMCRYPT_SHA512_224_STATE
#define SYMCRYPT_SHA512_224_STATE_EXPORT_SIZE
PSYMCRYPT_COMMON_HASH_STATE pState
const BYTE * PCBYTE
* PSYMCRYPT_SHA512_224_STATE
#define SYMCRYPT_SHA512_STATE_EXPORT_SIZE
PCBYTE pbData
#define SYMCRYPT_SHA512_256_STATE_EXPORT_SIZE
#define SYMCRYPT_CHECK_MAGIC(p)
const SYMCRYPT_SHA512_STATE * PCSYMCRYPT_SHA512_STATE
struct sock * chain
Definition: tcpcore.h:1
ULONG_PTR SIZE_T
Definition: typedefs.h:80
uint32_t UINT32
Definition: typedefs.h:59
#define round(x)
Definition: opentype.c:51
unsigned char BYTE
Definition: xxhash.c:193
#define const
Definition: zconf.h:233