]> git.codecow.com Git - nano25519.git/commitdiff
Import constant instead of hardcoding. Improve spread vector. Fix pairwise checks.
authorChris Duncan <chris@codecow.com>
Fri, 4 Sep 2026 19:05:59 +0000 (12:05 -0700)
committerChris Duncan <chris@codecow.com>
Fri, 4 Sep 2026 19:05:59 +0000 (12:05 -0700)
src/assembly/tests.ts

index 635a32425e089f51c4d7abb76ed339c57e103432..34691bc9eca5f0326ef270d46cbe0400603fd563 100644 (file)
@@ -1,6 +1,7 @@
 //! SPDX-FileCopyrightText: 2026 Chris Duncan <chris@codecow.com>
 //! SPDX-License-Identifier: GPL-3.0-or-later
 
+import { KEY_BYTELENGTH } from './constants'
 import { equalbytes } from './utils'
 
 /**
@@ -11,13 +12,13 @@ function err (fname: string, vector: string, expected: string, actual: string):
 }
 
 function xpass_equalbytes (vector: string, expected: StaticArray<u8>, actual: StaticArray<u8>): void {
-       if (!equalbytes(expected, actual, 32)) {
+       if (!equalbytes(expected, actual, KEY_BYTELENGTH)) {
                err('equalbytes', vector, `pass [${expected}]`, `fail [${actual}]`)
        }
 }
 
 function xfail_equalbytes (vector: string, expected: StaticArray<u8>, actual: StaticArray<u8>): void {
-       if (equalbytes(expected, actual, 32)) {
+       if (equalbytes(expected, actual, KEY_BYTELENGTH)) {
                err('equalbytes', vector, `fail [${expected}]`, `pass [${actual}]`)
        }
 }
@@ -28,45 +29,42 @@ function xfail_equalbytes (vector: string, expected: StaticArray<u8>, actual: St
  * - `ones`: upper boundary with every bit set
  * - `spread`: all bytes distinct from each other and setting each bit to 0 or 1
  */
-const zeros = new StaticArray<u8>(32).fill(0)
-const ones = new StaticArray<u8>(32).fill(255)
-const spread = new StaticArray<u8>(32)
-// 37 is large enough prime to cover all bit positions as either 0 or 1
-for (let i = 0; i < 32; i++) {
-       spread[i] = u8(i * 37)
+const zeros = new StaticArray<u8>(KEY_BYTELENGTH).fill(0)
+const ones = new StaticArray<u8>(KEY_BYTELENGTH).fill(255)
+const spread = new StaticArray<u8>(KEY_BYTELENGTH)
+// 37 + 11 balances all bit positions as either 0 or 1
+for (let i = 0; i < KEY_BYTELENGTH; i++) {
+       spread[i] = u8(i * 37 + 11)
 }
 
 const vectors = ['zeros', 'ones', 'spread',]
 const expecteds = [zeros, ones, spread,]
 
-const actual = new StaticArray<u8>(32)
+const actual = new StaticArray<u8>(KEY_BYTELENGTH)
 
 for (let v = 0; v < vectors.length; v++) {
        const vector = vectors[v]
        const expected = expecteds[v]
-       memory.copy(changetype<usize>(actual), changetype<usize>(expected), 32)
-       xpass_equalbytes('equal bytes', expected, actual)
+       memory.copy(changetype<usize>(actual), changetype<usize>(expected), KEY_BYTELENGTH)
+       xpass_equalbytes(vector, expected, actual)
 
-       for (let i = 0; i < 32; i++) {
-               for (let j = 1; j < 256; j++) {
-                       const p = u8(j)
-                       const q = u8(256 - j)
+       for (let i = 0; i < KEY_BYTELENGTH; i++) {
 
-                       // check that any individual bit difference fails
-                       actual[i] ^= p
+               // verify any individual bit difference fails
+               for (let j = 1; j < 256; j++) {
+                       actual[i] ^= u8(j)
                        xfail_equalbytes(vector, expected, actual)
+                       actual[i] = expected[i]
+               }
 
-                       // check that |= was not replaced by ^= or += due to a typo
-                       // only necessary to check once per vector, for all bit positions
-                       if (i === 0) {
-                               actual[i + 1] ^= p
-                               xfail_equalbytes(vector, expected, actual)
-                               actual[i + 1] ^= p ^ q
-                               xfail_equalbytes(vector, expected, actual)
-                               actual[i + 1] = expected[i + 1]
-                       }
-
+               // verify |= was not replaced by ^= or += due to a typo
+               // invisible to single byte checks, caught only by comparing byte pairs
+               for (let j = i + 1; j < KEY_BYTELENGTH; j++) {
+                       actual[i] ^= 128
+                       actual[j] ^= 128
+                       xfail_equalbytes(vector, expected, actual)
                        actual[i] = expected[i]
+                       actual[j] = expected[j]
                }
        }
 }