v128.store_lane<u64>(td, v128.bitselect(v128.neg<i32>(d2), d2, n), 0, 32)
}
-const t: FieldElement = fe()
+const ge_frombytes_negate_vartime_u8x32_scratch = new StaticArray<u8>(32)
+const ge_frombytes_negate_vartime_fe_scratch: FieldElement = fe()
const u: FieldElement = fe()
const v: FieldElement = fe()
const v3: FieldElement = fe()
* @returns {i32} 0 if `s` decodes to a valid point, else -1
*/
export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray<u8>): i32 {
+ const u8x32_scratch = ge_frombytes_negate_vartime_u8x32_scratch
+ const fe_scratch = ge_frombytes_negate_vartime_fe_scratch
fe_frombytes(h.Y, s)
fe_1(h.Z)
// m = vx²-u
fe_sub(m_root_check, vxx, u)
- if (fe_iszero(m_root_check) == 0) {
+ if (fe_iszero(u8x32_scratch, m_root_check, fe_scratch) == 0) {
// p = vx²+u
fe_add(p_root_check, vxx, u)
- if (fe_iszero(p_root_check) == 0) {
+ if (fe_iszero(u8x32_scratch, p_root_check, fe_scratch) == 0) {
return -1
}
fe_mul(h.X, h.X, fe_sqrtm1)
}
- if (fe_isnegative(h.X, t) == (s[31] >> 7)) {
+ if (fe_isnegative(h.X, fe_scratch) == (s[31] >> 7)) {
fe_neg(h.X, h.X)
}
fe_mul(h.T, h.X, h.Y)
return 0
}
-const ge_frombytes_t: FieldElement = fe()
+const ge_frombytes_u8x32_scratch = new StaticArray<u8>(32)
+const ge_frombytes_fe_scratch: FieldElement = fe()
const ge_frombytes_u: FieldElement = fe()
const ge_frombytes_v: FieldElement = fe()
const ge_frombytes_vxx: FieldElement = fe()
* @returns {i32} 0 if `s` decodes to a valid point, else -1
*/
export function ge_frombytes (h: ge_p3, s: StaticArray<u8>): i32 {
- const t = ge_frombytes_t
+ const u8x32_scratch = ge_frombytes_u8x32_scratch
+ const fe_scratch = ge_frombytes_fe_scratch
const u = ge_frombytes_u
const v = ge_frombytes_v
const vxx = ge_frombytes_vxx
// m = vx²-u
fe_sub(m_root_check, vxx, u)
- has_m_root = fe_iszero(m_root_check)
+ has_m_root = fe_iszero(u8x32_scratch, m_root_check, fe_scratch)
// p = vx²+u
fe_add(p_root_check, vxx, u)
- has_p_root = fe_iszero(p_root_check)
+ has_p_root = fe_iszero(u8x32_scratch, p_root_check, fe_scratch)
// x√-1
fe_mul(x_sqrtm1, h.X, fe_sqrtm1)
fe_cmov(h.X, x_sqrtm1, 1 - has_m_root)
fe_neg(negx, h.X)
- fe_cmov(h.X, negx, fe_isnegative(h.X, t) ^ (s[31] >> 7))
+ fe_cmov(h.X, negx, fe_isnegative(h.X, fe_scratch) ^ (s[31] >> 7))
fe_mul(h.T, h.X, h.Y)
return i32(has_m_root | has_p_root) - 1
}
+const ge_has_small_order_u8x32_scratch = new StaticArray<u8>(32)
+const ge_has_small_order_fe_scratch: FieldElement = fe()
const y_sqrtm1: FieldElement = fe()
const c: FieldElement = fe()
/** return 1 if p has small order else return 0 */
export function ge_has_small_order (p: ge_p3): i32 {
+ const u8x32_scratch = ge_has_small_order_u8x32_scratch
+ const fe_scratch = ge_has_small_order_fe_scratch
let ret: i32 = 0
- ret |= fe_iszero(p.X)
- ret |= fe_iszero(p.Y)
- ret |= fe_iszero(p.Z)
+ ret |= fe_iszero(u8x32_scratch, p.X, fe_scratch)
+ ret |= fe_iszero(u8x32_scratch, p.Y, fe_scratch)
+ ret |= fe_iszero(u8x32_scratch, p.Z, fe_scratch)
fe_mul(y_sqrtm1, p.Y, fe_sqrtm1)
fe_sub(c, y_sqrtm1, p.X)
- ret |= fe_iszero(c)
+ ret |= fe_iszero(u8x32_scratch, c, fe_scratch)
fe_add(c, y_sqrtm1, p.X)
- ret |= fe_iszero(c)
+ ret |= fe_iszero(u8x32_scratch, c, fe_scratch)
return ret
}