]> git.codecow.com Git - nano25519.git/commitdiff
Move buffers and adjust naming convention.
authorChris Duncan <chris@zoso.dev>
Fri, 2 Oct 2026 08:47:34 +0000 (01:47 -0700)
committerChris Duncan <chris@zoso.dev>
Fri, 2 Oct 2026 08:47:34 +0000 (01:47 -0700)
src/assembly/ed25519/fe.ts
src/assembly/ed25519/ge.ts

index 5d072cd428c54149163e1656261db5afd097069c..75c22457e2c8d2e72e8fa2a0586d98ae6aa4be31 100644 (file)
@@ -244,8 +244,6 @@ export function fe_isnegative (f: FieldElement, t: FieldElement): u8 {
        return u8(t[0] & 1)
 }
 
-const fe_iszero_s = new StaticArray<u8>(32)
-const fe_iszero_t: FieldElement = fe()
 /**
  * return 1 if f == 0
  * return 0 if f != 0
@@ -253,9 +251,7 @@ const fe_iszero_t: FieldElement = fe()
  * Preconditions:
  * |f| bounded by 1.1x2²⁶,1.1x2²⁵,1.1x2²⁶,1.1x2²⁵,etc.
  */
-export function fe_iszero (f: FieldElement): u8 {
-       const s = fe_iszero_s
-       const t = fe_iszero_t
+export function fe_iszero (s: StaticArray<u8>, f: FieldElement, t: FieldElement): u8 {
        fe_tobytes(s, f, t)
        return sodium_is_zero(s, 32)
 }
index 6bb99287a83663fcb1861921b4404e0c6bf77f14..66b8fc1eddc6979f2d86e39be875fa7539c46b6c 100644 (file)
@@ -85,7 +85,8 @@ function ge_cmov8_base (t: ge_precomp, bp: usize, b: i8): void {
        v128.store_lane<u64>(td, v128.bitselect(v128.neg<i32>(d2), d2, n), 0, 32)
 }
 
-const t: FieldElement = fe()
+const ge_frombytes_negate_vartime_u8x32_scratch = new StaticArray<u8>(32)
+const ge_frombytes_negate_vartime_fe_scratch: FieldElement = fe()
 const u: FieldElement = fe()
 const v: FieldElement = fe()
 const v3: FieldElement = fe()
@@ -100,6 +101,8 @@ const p_root_check: FieldElement = fe()
  * @returns {i32} 0 if `s` decodes to a valid point, else -1
  */
 export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray<u8>): i32 {
+       const u8x32_scratch = ge_frombytes_negate_vartime_u8x32_scratch
+       const fe_scratch = ge_frombytes_negate_vartime_fe_scratch
        fe_frombytes(h.Y, s)
        fe_1(h.Z)
 
@@ -132,16 +135,16 @@ export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray<u8>): i32
 
        // m = vx²-u
        fe_sub(m_root_check, vxx, u)
-       if (fe_iszero(m_root_check) == 0) {
+       if (fe_iszero(u8x32_scratch, m_root_check, fe_scratch) == 0) {
                // p = vx²+u
                fe_add(p_root_check, vxx, u)
-               if (fe_iszero(p_root_check) == 0) {
+               if (fe_iszero(u8x32_scratch, p_root_check, fe_scratch) == 0) {
                        return -1
                }
                fe_mul(h.X, h.X, fe_sqrtm1)
        }
 
-       if (fe_isnegative(h.X, t) == (s[31] >> 7)) {
+       if (fe_isnegative(h.X, fe_scratch) == (s[31] >> 7)) {
                fe_neg(h.X, h.X)
        }
        fe_mul(h.T, h.X, h.Y)
@@ -149,7 +152,8 @@ export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray<u8>): i32
        return 0
 }
 
-const ge_frombytes_t: FieldElement = fe()
+const ge_frombytes_u8x32_scratch = new StaticArray<u8>(32)
+const ge_frombytes_fe_scratch: FieldElement = fe()
 const ge_frombytes_u: FieldElement = fe()
 const ge_frombytes_v: FieldElement = fe()
 const ge_frombytes_vxx: FieldElement = fe()
@@ -163,7 +167,8 @@ const x_sqrtm1: FieldElement = fe()
  * @returns {i32} 0 if `s` decodes to a valid point, else -1
  */
 export function ge_frombytes (h: ge_p3, s: StaticArray<u8>): i32 {
-       const t = ge_frombytes_t
+       const u8x32_scratch = ge_frombytes_u8x32_scratch
+       const fe_scratch = ge_frombytes_fe_scratch
        const u = ge_frombytes_u
        const v = ge_frombytes_v
        const vxx = ge_frombytes_vxx
@@ -194,37 +199,41 @@ export function ge_frombytes (h: ge_p3, s: StaticArray<u8>): i32 {
 
        // m = vx²-u
        fe_sub(m_root_check, vxx, u)
-       has_m_root = fe_iszero(m_root_check)
+       has_m_root = fe_iszero(u8x32_scratch, m_root_check, fe_scratch)
 
        // p = vx²+u
        fe_add(p_root_check, vxx, u)
-       has_p_root = fe_iszero(p_root_check)
+       has_p_root = fe_iszero(u8x32_scratch, p_root_check, fe_scratch)
 
        // x√-1
        fe_mul(x_sqrtm1, h.X, fe_sqrtm1)
        fe_cmov(h.X, x_sqrtm1, 1 - has_m_root)
 
        fe_neg(negx, h.X)
-       fe_cmov(h.X, negx, fe_isnegative(h.X, t) ^ (s[31] >> 7))
+       fe_cmov(h.X, negx, fe_isnegative(h.X, fe_scratch) ^ (s[31] >> 7))
        fe_mul(h.T, h.X, h.Y)
 
        return i32(has_m_root | has_p_root) - 1
 }
 
+const ge_has_small_order_u8x32_scratch = new StaticArray<u8>(32)
+const ge_has_small_order_fe_scratch: FieldElement = fe()
 const y_sqrtm1: FieldElement = fe()
 const c: FieldElement = fe()
 /** return 1 if p has small order else return 0 */
 export function ge_has_small_order (p: ge_p3): i32 {
+       const u8x32_scratch = ge_has_small_order_u8x32_scratch
+       const fe_scratch = ge_has_small_order_fe_scratch
        let ret: i32 = 0
 
-       ret |= fe_iszero(p.X)
-       ret |= fe_iszero(p.Y)
-       ret |= fe_iszero(p.Z)
+       ret |= fe_iszero(u8x32_scratch, p.X, fe_scratch)
+       ret |= fe_iszero(u8x32_scratch, p.Y, fe_scratch)
+       ret |= fe_iszero(u8x32_scratch, p.Z, fe_scratch)
        fe_mul(y_sqrtm1, p.Y, fe_sqrtm1)
        fe_sub(c, y_sqrtm1, p.X)
-       ret |= fe_iszero(c)
+       ret |= fe_iszero(u8x32_scratch, c, fe_scratch)
        fe_add(c, y_sqrtm1, p.X)
-       ret |= fe_iszero(c)
+       ret |= fe_iszero(u8x32_scratch, c, fe_scratch)
 
        return ret
 }