ReactOS 0.4.17-dev-1005-g171e1de
sha3.c
Go to the documentation of this file.
1//
2// Sha3.c
3//
4// Copyright (c) Microsoft Corporation. Licensed under the MIT license.
5//
6
7#include "precomp.h"
8
9//
10// See the symcrypt.h file for documentation on what the various functions do.
11//
12
13
14//
15// Keccak state
16//
17// Keccak-f[1600] state consists of 25 64-bit words. We represent this state as a single
18// dimensional array of 25 elements (Wi being the i^th element of the array for i=0..24)
19// with the following mapping to two dimensional coordinates. Note that in FIPS 202 Figure 2,
20// the element W0 at (x,y)=(0,0) is depicted in the middle of the 5x5 array. We set W0
21// to be the first element so that the rate part of the permutation maps to the beginning
22// of the state.
23//
24// x=0 x=1 x=2 x=3 x=4
25// -----------------------
26// y=0 W0 W1 W2 W3 W4
27// y=1 W5 W6 W7 W8 W9
28// y=2 W10 W11 W12 W13 W14
29// y=3 W15 W16 W17 W18 W19
30// y=4 W20 W21 W22 W23 W24
31
32
33
34// Rotation constants for Keccak Rho transformation
35static const UINT8 KeccakRhoK[25] = {
36 0, 1, 62, 28, 27, // y = 0
37 36, 44, 6, 55, 20, // y = 1
38 3, 10, 43, 25, 39, // y = 2
39 41, 45, 15, 21, 8, // y = 3
40 18, 2, 61, 56, 14, // y = 4
41};
42
43// Keccak round constants
44static UINT64 KeccakIotaK[24] = {
45 0x0000000000000001ULL, 0x0000000000008082ULL, 0x800000000000808aULL, 0x8000000080008000ULL,
46 0x000000000000808bULL, 0x0000000080000001ULL, 0x8000000080008081ULL, 0x8000000000008009ULL,
47 0x000000000000008aULL, 0x0000000000000088ULL, 0x0000000080008009ULL, 0x000000008000000aULL,
48 0x000000008000808bULL, 0x800000000000008bULL, 0x8000000000008089ULL, 0x8000000000008003ULL,
49 0x8000000000008002ULL, 0x8000000000000080ULL, 0x000000000000800aULL, 0x800000008000000aULL,
50 0x8000000080008081ULL, 0x8000000000008080ULL, 0x0000000080000001ULL, 0x8000000080008008ULL
51};
52
53// XOR sum of column c of the state
54#define KECCAK_COLUMN_SUM(state, c) \
55 (state[0 + (c)] ^ state[5 + (c)] ^ state[10 + (c)] ^ state[15 + (c)] ^ state[20 + (c)])
56
57// XOR w to all the lanes in column c of the state
58//
59// Note: The expression to be XORed is copied to a temporary variable to avoid reevaluation
60#define KECCAK_COLUMN_UPDATE(state, c, w) { \
61 UINT64 t = (w); \
62 state[ 0 + (c)] ^= t; \
63 state[ 5 + (c)] ^= t; \
64 state[10 + (c)] ^= t; \
65 state[15 + (c)] ^= t; \
66 state[20 + (c)] ^= t; \
67}
68
69// Apply Theta transformation to the state
70#define KECCAK_THETA(state) { \
71 UINT64 colSum[5]; \
72 colSum[0] = KECCAK_COLUMN_SUM(state, 0); \
73 colSum[1] = KECCAK_COLUMN_SUM(state, 1); \
74 colSum[2] = KECCAK_COLUMN_SUM(state, 2); \
75 colSum[3] = KECCAK_COLUMN_SUM(state, 3); \
76 colSum[4] = KECCAK_COLUMN_SUM(state, 4); \
77 KECCAK_COLUMN_UPDATE(state, 0, colSum[4] ^ ROL64(colSum[1], 1)); \
78 KECCAK_COLUMN_UPDATE(state, 1, colSum[0] ^ ROL64(colSum[2], 1)); \
79 KECCAK_COLUMN_UPDATE(state, 2, colSum[1] ^ ROL64(colSum[3], 1)); \
80 KECCAK_COLUMN_UPDATE(state, 3, colSum[2] ^ ROL64(colSum[4], 1)); \
81 KECCAK_COLUMN_UPDATE(state, 4, colSum[3] ^ ROL64(colSum[0], 1)); \
82}
83
84// Apply Rho transformation to row r of the state
85#define KECCAK_RHO_ROW(state, r) { \
86 state[5 * (r) + 0] = ROL64(state[5 * (r) + 0], KeccakRhoK[5 * (r) + 0]); \
87 state[5 * (r) + 1] = ROL64(state[5 * (r) + 1], KeccakRhoK[5 * (r) + 1]); \
88 state[5 * (r) + 2] = ROL64(state[5 * (r) + 2], KeccakRhoK[5 * (r) + 2]); \
89 state[5 * (r) + 3] = ROL64(state[5 * (r) + 3], KeccakRhoK[5 * (r) + 3]); \
90 state[5 * (r) + 4] = ROL64(state[5 * (r) + 4], KeccakRhoK[5 * (r) + 4]); \
91}
92
93// Apply Rho transformation to row 0 of the state
94//
95// The first row contains a rotation by 0 on the first lane that uses a shift
96// by 64 which we want to avoid. Rho operation below omits the rotation on the first lane.
97#define KECCAK_RHO_ROW0(state) { \
98 state[1] = ROL64(state[1], KeccakRhoK[1]); \
99 state[2] = ROL64(state[2], KeccakRhoK[2]); \
100 state[3] = ROL64(state[3], KeccakRhoK[3]); \
101 state[4] = ROL64(state[4], KeccakRhoK[4]); \
102}
103
104// Apply Rho transformation to the state
105#define KECCAK_RHO(state) { \
106 KECCAK_RHO_ROW0(state); \
107 KECCAK_RHO_ROW(state, 1); \
108 KECCAK_RHO_ROW(state, 2); \
109 KECCAK_RHO_ROW(state, 3); \
110 KECCAK_RHO_ROW(state, 4); \
111}
112
113// Apply Pi transformation to the state
114#define KECCAK_PI(state) { \
115 UINT64 t = state[ 1]; state[ 1] = state[ 6]; state[ 6] = state[ 9]; state[ 9] = state[22]; state[22] = state[14]; \
116 state[14] = state[20]; state[20] = state[ 2]; state[ 2] = state[12]; state[12] = state[13]; state[13] = state[19]; \
117 state[19] = state[23]; state[23] = state[15]; state[15] = state[ 4]; state[ 4] = state[24]; state[24] = state[21]; \
118 state[21] = state[ 8]; state[ 8] = state[16]; state[16] = state[ 5]; state[ 5] = state[ 3]; state[ 3] = state[18]; \
119 state[18] = state[17]; state[17] = state[11]; state[11] = state[ 7]; state[ 7] = state[10]; state[10] = t; \
120}
121
122// Apply Chi transformation on row r of state
123#define KECCAK_CHI_ROW(state, r) { \
124 UINT64 t1 = state[5 * (r) + 0] ^ (~state[5 * (r) + 1] & state[5 * (r) + 2]); \
125 UINT64 t2 = state[5 * (r) + 1] ^ (~state[5 * (r) + 2] & state[5 * (r) + 3]); \
126 state[5 * (r) + 2] = state[5 * (r) + 2] ^ (~state[5 * (r) + 3] & state[5 * (r) + 4]); \
127 state[5 * (r) + 3] = state[5 * (r) + 3] ^ (~state[5 * (r) + 4] & state[5 * (r) + 0]); \
128 state[5 * (r) + 4] = state[5 * (r) + 4] ^ (~state[5 * (r) + 0] & state[5 * (r) + 1]); \
129 state[5 * (r) + 0] = t1; \
130 state[5 * (r) + 1] = t2; \
131}
132
133// Apply Chi transformation to state
134#define KECCAK_CHI(state) { \
135 KECCAK_CHI_ROW(state, 0); \
136 KECCAK_CHI_ROW(state, 1); \
137 KECCAK_CHI_ROW(state, 2); \
138 KECCAK_CHI_ROW(state, 3); \
139 KECCAK_CHI_ROW(state, 4); \
140}
141
142// Add round constant to state
143#define KECCAK_IOTA(state, rnd) state[0] ^= KeccakIotaK[rnd]
144
145// Perform one round of Keccak permutation on state
146#define KECCAK_PERM_ROUND(state, rnd) { \
147 KECCAK_THETA(state); \
148 KECCAK_RHO(state); \
149 KECCAK_PI(state); \
150 KECCAK_CHI(state); \
151 KECCAK_IOTA(state, rnd); \
152}
153
154
155//
156// SymCryptKeccakPermute
157//
158VOID
161{
162 for (int r = 0; r < 24; r++)
163 {
165 }
166}
167
168
169//
170// SymCryptKeccakInit
171//
172VOID
175{
176 pState->inputBlockSize = inputBlockSize;
177 pState->paddingValue = paddingValue;
178
179 // Initialize the Keccak permutation state and set mutable state variables
180 // to their default values.
182}
183
184VOID
187{
188 //
189 // Wipe & re-initialize
190 //
191 // Wipe the Keccak permutation state and set the mutable state variables to their
192 // default values. Non-mutable state variables retain their values. State becomes
193 // re-initialized after this call.
194 SymCryptWipeKnownSize(pState->state, sizeof(pState->state));
195 pState->stateIndex = 0;
196 pState->squeezeMode = FALSE;
197}
198
199//
200// SymCryptKeccakAppendByte
201//
203VOID
206{
207 SYMCRYPT_ASSERT(!pState->squeezeMode);
208 SYMCRYPT_ASSERT(pState->stateIndex < pState->inputBlockSize);
209
210 pState->state[pState->stateIndex / sizeof(UINT64)] ^= ((UINT64)val << (8 * (pState->stateIndex % 8)));
211 pState->stateIndex++;
212}
213
214//
215// SymCryptKeccakAppendBytes
216//
218VOID
221{
222 SYMCRYPT_ASSERT(!pState->squeezeMode);
223 SYMCRYPT_ASSERT((pState->stateIndex + cbBuffer) <= pState->inputBlockSize);
224
225 for (SIZE_T i = 0; i < cbBuffer; i++)
226 {
227 pState->state[(pState->stateIndex + i) / sizeof(UINT64)] ^= ((UINT64)pbBuffer[i] << (8 * ((pState->stateIndex + i) % 8)));
228 }
229
230 pState->stateIndex += (UINT32)cbBuffer;
231}
232
233
234//
235// SymCryptKeccakAppendLanes
236//
237VOID
241 _In_reads_(uLaneCount * sizeof(UINT64)) PCBYTE pbData,
242 SIZE_T uLaneCount)
243{
244 SYMCRYPT_ASSERT(!pState->squeezeMode);
245 SYMCRYPT_ASSERT((pState->inputBlockSize & 0x7) == 0);
246 SYMCRYPT_ASSERT((pState->stateIndex & 0x7) == 0);
247 SYMCRYPT_ASSERT(pState->stateIndex != pState->inputBlockSize);
248
249 // Locate the lane in the state for next append.
250 // Currently, pState->stateIndex/sizeof(UINT64) of the lanes are used.
251 UINT32 uLaneIndex = pState->stateIndex / sizeof(UINT64);
252
253 for (SIZE_T i = 0; i < uLaneCount; i++)
254 {
255 pState->state[uLaneIndex] ^= SYMCRYPT_LOAD_LSBFIRST64(pbData + i * sizeof(UINT64));
256 pState->stateIndex += sizeof(UINT64);
257 uLaneIndex++;
258
259 if (pState->stateIndex == pState->inputBlockSize)
260 {
262 pState->stateIndex = 0;
263 uLaneIndex = 0;
264 }
265 }
266}
267
268//
269// SymCryptKeccakZeroAppendBlock
270//
271VOID
274{
275 SYMCRYPT_ASSERT(!pState->squeezeMode);
277 pState->stateIndex = 0;
278}
279
280//
281// SymCryptKeccakAppend
282//
283VOID
289{
290 SYMCRYPT_ASSERT(pState->inputBlockSize % 8 == 0);
291
292 // If we were in squeeze mode (Append is called after an Extract without wiping),
293 // switch to absorb mode to start a new hash computation.
294 if (pState->squeezeMode)
295 {
297 }
298
299 SYMCRYPT_ASSERT(pState->stateIndex < pState->inputBlockSize);
300
301 // Make pState->stateIndex a multiple of 8.
302 // Message block boundary will not be crossed, check
303 // if permutation is needed after this part.
304 while (cbData > 0 && (pState->stateIndex & 0x7))
305 {
307 pbData++;
308 cbData--;
309 }
310
311 // Permute if input message block is filled
312 if (pState->stateIndex == pState->inputBlockSize)
313 {
315 pState->stateIndex = 0;
316 }
317
318 // Append full lanes
319 SIZE_T uFullLanes = cbData / sizeof(UINT64);
320 if (uFullLanes > 0)
321 {
323 pbData += uFullLanes * sizeof(UINT64);
324 cbData -= uFullLanes * sizeof(UINT64);
325 }
326
327 SYMCRYPT_ASSERT(cbData < sizeof(UINT64));
329
330 SYMCRYPT_ASSERT(pState->stateIndex != pState->inputBlockSize);
331}
332
333//
334// SymCryptKeccakApplyPadding
335//
336VOID
339{
340 SYMCRYPT_ASSERT(!pState->squeezeMode);
341
342 // Locate the lane and byte position for the padding byte
343 UINT32 uLanePos = pState->stateIndex / sizeof(UINT64);
344 UINT32 uBytePos = pState->stateIndex % sizeof(UINT64);
345 pState->state[uLanePos] ^= ((UINT64)pState->paddingValue << (8 * uBytePos));
346
347 // Pad the final 1 bit to the msb of the last lane in the rate portion of the state
348 pState->state[pState->inputBlockSize / sizeof(UINT64) - 1] ^= (1ULL << 63);
349
350 // Process the padded block and switch to squeeze mode
352 pState->stateIndex = 0;
353 pState->squeezeMode = TRUE;
354}
355
356//
357// SymCryptKeccakExtractByte
358//
360BYTE
363{
364 SYMCRYPT_ASSERT(pState->squeezeMode);
365 SYMCRYPT_ASSERT(pState->stateIndex < pState->inputBlockSize);
366
367 BYTE ret = (BYTE)((pState->state[pState->stateIndex / sizeof(UINT64)] >> (8 * (pState->stateIndex % 8))) & 0xff);
368 pState->stateIndex++;
369 return ret;
370}
371
372//
373// SymCryptKeccakExtractLanes
374//
375VOID
379 _Out_writes_(uLaneCount * sizeof(UINT64)) PBYTE pbResult,
380 SIZE_T uLaneCount)
381{
382 SYMCRYPT_ASSERT(pState->squeezeMode);
383 SYMCRYPT_ASSERT((pState->inputBlockSize & 0x7) == 0);
384 SYMCRYPT_ASSERT((pState->stateIndex & 0x7) == 0);
385
386 // Locate the lane in the state for next extraction
387 UINT32 uLaneIndex = pState->stateIndex / sizeof(UINT64);
388
389 for (SIZE_T i = 0; i < uLaneCount; i++)
390 {
391 SYMCRYPT_ASSERT(pState->stateIndex <= pState->inputBlockSize);
392
393 if (pState->stateIndex == pState->inputBlockSize)
394 {
396 pState->stateIndex = 0;
397 uLaneIndex = 0;
398 }
399
400 SYMCRYPT_STORE_LSBFIRST64(pbResult + i * sizeof(UINT64), pState->state[uLaneIndex]);
401 pState->stateIndex += sizeof(UINT64);
402 uLaneIndex++;
403 }
404}
405
406//
407// SymCryptKeccakExtract
408//
409VOID
413 _Out_writes_(cbResult) PBYTE pbResult,
414 SIZE_T cbResult,
415 BOOLEAN bWipe)
416{
417 // Apply padding and switch to squeeze mode if this is the first call to Extract
418 if (!pState->squeezeMode)
419 {
421 }
422
423 // Do the permutation if there are no bytes available in the state
424 if ( (cbResult > 0) && (pState->stateIndex == pState->inputBlockSize) )
425 {
427 pState->stateIndex= 0;
428 }
429
430 // Make stateIndex a multiple of 8 so that the extraction can be performed in lanes.
431 // We don't call the permutation as soon as the stateIndex reaches inputBlockSize,
432 // cbResult must also be non-zero for that. This condition is checked
433 // in ExtractLanes or in the 'remaining bytes' block that follows it.
434 while (cbResult > 0 && (pState->stateIndex & 0x7))
435 {
437 pbResult++;
438 cbResult--;
439 }
440
441 SYMCRYPT_ASSERT((cbResult == 0) || ((pState->stateIndex & 0x7) == 0));
442
443 // Extract full lanes
444 SIZE_T uFullLanes = cbResult / sizeof(UINT64);
445 if (uFullLanes > 0)
446 {
448 pbResult += uFullLanes * sizeof(UINT64);
449 cbResult -= uFullLanes * sizeof(UINT64);
450 }
451
452 // Extract the remaining bytes
453 SYMCRYPT_ASSERT(cbResult < sizeof(UINT64));
454 while (cbResult > 0)
455 {
456 if (pState->stateIndex == pState->inputBlockSize)
457 {
459 pState->stateIndex = 0;
460 }
461
463 pbResult++;
464 cbResult--;
465 }
466
467 if (bWipe)
468 {
469 // Wipe the Keccak state and make it ready for a new hash computation
471 }
472}
473
474//
475// SymCryptKeccakStateExport
476//
477VOID
483{
484
485 SYMCRYPT_ALIGN SYMCRYPT_KECCAK_STATE_EXPORT_BLOB blob; // local copy to have proper alignment.
487
488 SymCryptWipeKnownSize(&blob, sizeof(blob)); // wipe to avoid any data leakage
489
490 blob.header.magic = SYMCRYPT_BLOB_MAGIC;
492 blob.header.type = type;
493
494 //
495 // Copy the relevant data. Buffer will be 0-padded.
496 //
497
498 SymCryptUint64ToLsbFirst(&pState->state[0], &blob.state[0], 25);
499 blob.stateIndex = pState->stateIndex;
500 blob.paddingValue = pState->paddingValue;
501 blob.squeezeMode = pState->squeezeMode;
502
503 SYMCRYPT_ASSERT((PCBYTE)&blob + sizeof(blob) - sizeof(SYMCRYPT_BLOB_TRAILER) == (PCBYTE)&blob.trailer);
504 SymCryptMarvin32(SymCryptMarvin32DefaultSeed, (PCBYTE)&blob, sizeof(blob) - sizeof(SYMCRYPT_BLOB_TRAILER), &blob.trailer.checksum[0]);
505
506 memcpy(pbBlob, &blob, sizeof(blob));
507
509 return;
510}
511
512
513//
514// SymCryptKeccakStateImport
515//
522{
523 SYMCRYPT_ERROR scError = SYMCRYPT_NO_ERROR;
524
525 SYMCRYPT_ALIGN SYMCRYPT_KECCAK_STATE_EXPORT_BLOB blob; // local copy to have proper alignment.
526 BYTE checksum[8];
527
529 memcpy(&blob, pbBlob, sizeof(blob));
530
531 if (blob.header.magic != SYMCRYPT_BLOB_MAGIC ||
533 blob.header.type != (UINT32)type)
534 {
535 scError = SYMCRYPT_INVALID_BLOB;
536 goto cleanup;
537 }
538
540 if (memcmp(checksum, &blob.trailer.checksum[0], 8) != 0)
541 {
542 scError = SYMCRYPT_INVALID_BLOB;
543 goto cleanup;
544 }
545
546 SymCryptLsbFirstToUint64(&blob.state[0], &pState->state[0], 25);
547 pState->stateIndex = blob.stateIndex;
548 pState->paddingValue = blob.paddingValue;
549 pState->squeezeMode = blob.squeezeMode;
550
551 //
552 // Set state fields based on the blob type and do validation
553 //
554
555 // default values indicate error
556 pState->inputBlockSize = 0;
557 pState->paddingValue = 0;
558
559 switch (blob.header.type)
560 {
563 if (blob.paddingValue == SYMCRYPT_SHA3_PADDING_VALUE)
564 {
565 pState->paddingValue = blob.paddingValue;
566 }
567 break;
570 if (blob.paddingValue == SYMCRYPT_SHA3_PADDING_VALUE)
571 {
572 pState->paddingValue = blob.paddingValue;
573 }
574 break;
575
578 if (blob.paddingValue == SYMCRYPT_SHA3_PADDING_VALUE)
579 {
580 pState->paddingValue = blob.paddingValue;
581 }
582 break;
583
586 if (blob.paddingValue == SYMCRYPT_SHA3_PADDING_VALUE)
587 {
588 pState->paddingValue = blob.paddingValue;
589 }
590 break;
591 default:
592 scError = SYMCRYPT_INVALID_BLOB;
593 goto cleanup;
594 }
595
596 if (pState->inputBlockSize == 0 || pState->paddingValue == 0)
597 {
598 scError = SYMCRYPT_INVALID_BLOB;
599 goto cleanup;
600 }
601
602 if (pState->stateIndex > pState->inputBlockSize)
603 {
604 scError = SYMCRYPT_INVALID_BLOB;
605 goto cleanup;
606 }
607
608 // Allow stateIndex = inputBlockSize only in squeeze mode
609 if ((pState->stateIndex == pState->inputBlockSize) && !pState->squeezeMode)
610 {
611 scError = SYMCRYPT_INVALID_BLOB;
612 goto cleanup;
613 }
614
615cleanup:
617
618 return scError;
619}
unsigned char BOOLEAN
Definition: actypes.h:127
unsigned char UINT8
Definition: actypes.h:128
COMPILER_DEPENDENT_UINT64 UINT64
Definition: actypes.h:131
#define TRUE
Definition: types.h:120
#define FALSE
Definition: types.h:117
static cab_ULONG checksum(const cab_UBYTE *data, cab_UWORD bytes, cab_ULONG csum)
Definition: fdi.c:353
static void cleanup(void)
Definition: main.c:1335
_ACRTIMP int __cdecl memcmp(const void *, const void *, size_t)
Definition: string.c:2807
return ret
Definition: mutex.c:147
GLuint GLuint GLsizei GLenum type
Definition: gl.h:1545
GLdouble GLdouble GLdouble r
Definition: gl.h:2055
GLuint GLfloat * val
Definition: glext.h:7180
GLsizei GLenum const GLvoid GLsizei GLenum GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLint GLint GLint GLshort GLshort GLshort GLubyte GLubyte GLubyte GLuint GLuint GLuint GLushort GLushort GLushort GLbyte GLbyte GLbyte GLbyte GLdouble GLdouble GLdouble GLdouble GLfloat GLfloat GLfloat GLfloat GLint GLint GLint GLint GLshort GLshort GLshort GLshort GLubyte GLubyte GLubyte GLubyte GLuint GLuint GLuint GLuint GLushort GLushort GLushort GLushort GLboolean const GLdouble const GLfloat const GLint const GLshort const GLbyte const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLdouble const GLfloat const GLfloat const GLint const GLint const GLshort const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort const GLdouble const GLfloat const GLint const GLshort GLenum GLenum GLenum GLfloat GLenum GLint GLenum GLenum GLenum GLfloat GLenum GLenum GLint GLenum GLfloat GLenum GLint GLint GLushort GLenum GLenum GLfloat GLenum GLenum GLint GLfloat const GLubyte GLenum GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLint GLint GLsizei GLsizei GLint GLenum GLenum const GLvoid GLenum GLenum const GLfloat GLenum GLenum const GLint GLenum GLenum const GLdouble GLenum GLenum const GLfloat GLenum GLenum const GLint GLsizei GLuint GLfloat GLuint GLbitfield GLfloat GLint GLuint GLboolean GLenum GLfloat GLenum GLbitfield GLenum GLfloat GLfloat GLint GLint const GLfloat GLenum GLfloat GLfloat GLint GLint GLfloat GLfloat GLint GLint const GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat GLint GLfloat GLfloat const GLdouble const GLfloat const GLdouble const GLfloat GLint i
Definition: glfuncs.h:248
#define C_ASSERT(e)
Definition: intsafe.h:73
VOID SYMCRYPT_CALL SymCryptKeccakZeroAppendBlock(_Inout_ PSYMCRYPT_KECCAK_STATE pState)
Definition: sha3.c:273
static const UINT8 KeccakRhoK[25]
Definition: sha3.c:35
VOID SYMCRYPT_CALL SymCryptKeccakReset(_Out_ PSYMCRYPT_KECCAK_STATE pState)
Definition: sha3.c:186
VOID SYMCRYPT_CALL SymCryptKeccakAppend(_Inout_ PSYMCRYPT_KECCAK_STATE pState, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData)
Definition: sha3.c:285
static UINT64 KeccakIotaK[24]
Definition: sha3.c:44
SYMCRYPT_ERROR SYMCRYPT_CALL SymCryptKeccakStateImport(SYMCRYPT_BLOB_TYPE type, _Out_ PSYMCRYPT_KECCAK_STATE pState, _In_reads_bytes_(SYMCRYPT_KECCAK_STATE_EXPORT_SIZE) PCBYTE pbBlob)
Definition: sha3.c:518
#define KECCAK_PERM_ROUND(state, rnd)
Definition: sha3.c:146
VOID SYMCRYPT_CALL SymCryptKeccakInit(_Out_ PSYMCRYPT_KECCAK_STATE pState, UINT32 inputBlockSize, UINT8 paddingValue)
Definition: sha3.c:174
FORCEINLINE BYTE SYMCRYPT_CALL SymCryptKeccakExtractByte(_Inout_ PSYMCRYPT_KECCAK_STATE pState)
Definition: sha3.c:362
VOID SYMCRYPT_CALL SymCryptKeccakExtractLanes(_Inout_ PSYMCRYPT_KECCAK_STATE pState, _Out_writes_(uLaneCount *sizeof(UINT64)) PBYTE pbResult, SIZE_T uLaneCount)
Definition: sha3.c:377
VOID SYMCRYPT_CALL SymCryptKeccakStateExport(SYMCRYPT_BLOB_TYPE type, _In_ PCSYMCRYPT_KECCAK_STATE pState, _Out_writes_bytes_(SYMCRYPT_KECCAK_STATE_EXPORT_SIZE) PBYTE pbBlob)
Definition: sha3.c:479
VOID SYMCRYPT_CALL SymCryptKeccakApplyPadding(_Inout_ PSYMCRYPT_KECCAK_STATE pState)
Definition: sha3.c:338
VOID SYMCRYPT_CALL SymCryptKeccakExtract(_Inout_ PSYMCRYPT_KECCAK_STATE pState, _Out_writes_(cbResult) PBYTE pbResult, SIZE_T cbResult, BOOLEAN bWipe)
Definition: sha3.c:411
FORCEINLINE VOID SYMCRYPT_CALL SymCryptKeccakAppendByte(_Inout_ PSYMCRYPT_KECCAK_STATE pState, BYTE val)
Definition: sha3.c:205
FORCEINLINE VOID SYMCRYPT_CALL SymCryptKeccakAppendBytes(_Inout_ PSYMCRYPT_KECCAK_STATE pState, PCBYTE pbBuffer, SIZE_T cbBuffer)
Definition: sha3.c:220
VOID SYMCRYPT_CALL SymCryptKeccakPermute(_Inout_updates_(25) UINT64 *pState)
Definition: sha3.c:160
VOID SYMCRYPT_CALL SymCryptKeccakAppendLanes(_Inout_ PSYMCRYPT_KECCAK_STATE pState, _In_reads_(uLaneCount *sizeof(UINT64)) PCBYTE pbData, SIZE_T uLaneCount)
Definition: sha3.c:239
#define memcpy(s1, s2, n)
Definition: mkisofs.h:878
#define _In_reads_bytes_(s)
Definition: no_sal2.h:170
#define _In_reads_(s)
Definition: no_sal2.h:168
#define _Inout_updates_(s)
Definition: no_sal2.h:182
#define _Inout_
Definition: no_sal2.h:162
#define _Out_writes_(s)
Definition: no_sal2.h:176
#define _Out_
Definition: no_sal2.h:160
#define _In_
Definition: no_sal2.h:158
#define _Out_writes_bytes_(s)
Definition: no_sal2.h:178
BYTE * PBYTE
Definition: pedump.c:66
#define SYMCRYPT_BLOB_MAGIC
Definition: sc_lib.h:1077
FORCEINLINE VOID SYMCRYPT_CALL SymCryptUint64ToLsbFirst(_In_reads_(cuData) PCUINT64 puData, _Out_writes_(8 *cuData) PBYTE pbResult, SIZE_T cuData)
Definition: sc_lib.h:538
FORCEINLINE VOID SYMCRYPT_CALL SymCryptLsbFirstToUint64(_In_reads_(8 *cuResult) PCBYTE pbData, _Out_writes_(cuResult) PUINT64 puResult, SIZE_T cuResult)
Definition: sc_lib.h:554
@ SymCryptBlobTypeSha3_256State
Definition: sc_lib.h:1068
@ SymCryptBlobTypeSha3_224State
Definition: sc_lib.h:1074
@ SymCryptBlobTypeSha3_384State
Definition: sc_lib.h:1069
@ SymCryptBlobTypeSha3_512State
Definition: sc_lib.h:1070
#define SYMCRYPT_SHA3_PADDING_VALUE
Definition: sc_lib.h:1808
enum _SYMCRYPT_BLOB_TYPE SYMCRYPT_BLOB_TYPE
SIZE_T cbBuffer
Definition: sc_lib_mldsa.h:405
static const BYTE pbResult[]
Definition: image.c:229
#define SYMCRYPT_ASSERT(_x)
Definition: symcrypt.h:10807
#define SYMCRYPT_SHA3_256_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1615
VOID SYMCRYPT_CALL SymCryptMarvin32(_In_ PCSYMCRYPT_MARVIN32_EXPANDED_SEED pExpandedSeed, _In_reads_(cbData) PCBYTE pbData, SIZE_T cbData, _Out_writes_(SYMCRYPT_MARVIN32_RESULT_SIZE) PBYTE pbResult)
Definition: marvin32.c:239
FORCEINLINE VOID SYMCRYPT_CALL SymCryptWipeKnownSize(_Out_writes_bytes_(cbData) PVOID pbData, SIZE_T cbData)
#define SYMCRYPT_LOAD_LSBFIRST64(p)
Definition: symcrypt.h:300
#define SYMCRYPT_SHA3_224_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1561
PCSYMCRYPT_MARVIN32_EXPANDED_SEED const SymCryptMarvin32DefaultSeed
Definition: marvin32.c:29
#define SYMCRYPT_STORE_LSBFIRST64(p, v)
Definition: symcrypt.h:308
#define SYMCRYPT_SHA3_512_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1723
#define SYMCRYPT_SHA3_384_INPUT_BLOCK_SIZE
Definition: symcrypt.h:1669
SYMCRYPT_ERROR
Definition: symcrypt.h:227
const SYMCRYPT_KECCAK_STATE * PCSYMCRYPT_KECCAK_STATE
#define SYMCRYPT_ALIGN
#define SYMCRYPT_CALL
* PSYMCRYPT_KECCAK_STATE
#define SYMCRYPT_KECCAK_STATE_EXPORT_SIZE
UINT8 paddingValue
PCBYTE PBYTE SIZE_T cbData
UINT32 inputBlockSize
PSYMCRYPT_COMMON_HASH_STATE pState
const BYTE * PCBYTE
PCBYTE pbData
ULONG_PTR SIZE_T
Definition: typedefs.h:80
uint32_t UINT32
Definition: typedefs.h:59
#define FORCEINLINE
Definition: wdftypes.h:67
unsigned char BYTE
Definition: xxhash.c:193