}
const ge_frombytes_negate_vartime_u8x32_scratch = new StaticArray<u8>(32)
-const ge_frombytes_negate_vartime_fe_scratch: FieldElement = fe()
+const ge_frombytes_negate_vartime_fe_scratch_0: FieldElement = fe()
+const ge_frombytes_negate_vartime_fe_scratch_1: FieldElement = fe()
+const ge_frombytes_negate_vartime_fe_scratch_2: FieldElement = fe()
const u: FieldElement = fe()
const v: FieldElement = fe()
const v3: FieldElement = fe()
*/
export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray<u8>): i32 {
const u8x32_scratch = ge_frombytes_negate_vartime_u8x32_scratch
- const fe_scratch = ge_frombytes_negate_vartime_fe_scratch
+ const fe_scratch_0 = ge_frombytes_negate_vartime_fe_scratch_0
+ const fe_scratch_1 = ge_frombytes_negate_vartime_fe_scratch_1
+ const fe_scratch_2 = ge_frombytes_negate_vartime_fe_scratch_2
fe_frombytes(h.Y, s)
fe_1(h.Z)
fe_mul(h.X, h.X, u)
// x = (uv⁷)^((q-5)/8)
- fe_pow22523(h.X, h.X)
+ fe_pow22523(h.X, h.X, fe_scratch_0, fe_scratch_1, fe_scratch_2)
// x = uv³((uv⁷)^((q-5)/8))
fe_mul(h.X, h.X, v3)
// m = vx²-u
fe_sub(m_root_check, vxx, u)
- if (fe_iszero(m_root_check, u8x32_scratch, fe_scratch) == 0) {
+ if (fe_iszero(m_root_check, u8x32_scratch, fe_scratch_0) == 0) {
// p = vx²+u
fe_add(p_root_check, vxx, u)
- if (fe_iszero(p_root_check, u8x32_scratch, fe_scratch) == 0) {
+ if (fe_iszero(p_root_check, u8x32_scratch, fe_scratch_0) == 0) {
return -1
}
fe_mul(h.X, h.X, fe_sqrtm1)
}
- if (fe_isnegative(h.X, fe_scratch) == (s[31] >> 7)) {
+ if (fe_isnegative(h.X, fe_scratch_0) == (s[31] >> 7)) {
fe_neg(h.X, h.X)
}
fe_mul(h.T, h.X, h.Y)
}
const ge_frombytes_u8x32_scratch = new StaticArray<u8>(32)
-const ge_frombytes_fe_scratch: FieldElement = fe()
+const ge_frombytes_fe_scratch_0: FieldElement = fe()
+const ge_frombytes_fe_scratch_1: FieldElement = fe()
+const ge_frombytes_fe_scratch_2: FieldElement = fe()
const ge_frombytes_u: FieldElement = fe()
const ge_frombytes_v: FieldElement = fe()
const ge_frombytes_vxx: FieldElement = fe()
*/
export function ge_frombytes (h: ge_p3, s: StaticArray<u8>): i32 {
const u8x32_scratch = ge_frombytes_u8x32_scratch
- const fe_scratch = ge_frombytes_fe_scratch
+ const fe_scratch_0 = ge_frombytes_fe_scratch_0
+ const fe_scratch_1 = ge_frombytes_fe_scratch_1
+ const fe_scratch_2 = ge_frombytes_fe_scratch_2
const u = ge_frombytes_u
const v = ge_frombytes_v
const vxx = ge_frombytes_vxx
/* x = u((uv)^((q-5)/8)) */
fe_mul(h.X, u, v)
- fe_pow22523(h.X, h.X)
+ fe_pow22523(h.X, h.X, fe_scratch_0, fe_scratch_1, fe_scratch_2)
fe_mul(h.X, u, h.X)
// vxx = vx²
// m = vx²-u
fe_sub(m_root_check, vxx, u)
- has_m_root = fe_iszero(m_root_check, u8x32_scratch, fe_scratch)
+ has_m_root = fe_iszero(m_root_check, u8x32_scratch, fe_scratch_0)
// p = vx²+u
fe_add(p_root_check, vxx, u)
- has_p_root = fe_iszero(p_root_check, u8x32_scratch, fe_scratch)
+ has_p_root = fe_iszero(p_root_check, u8x32_scratch, fe_scratch_0)
// x√-1
fe_mul(x_sqrtm1, h.X, fe_sqrtm1)
fe_cmov(h.X, x_sqrtm1, 1 - has_m_root)
fe_neg(negx, h.X)
- fe_cmov(h.X, negx, fe_isnegative(h.X, fe_scratch) ^ (s[31] >> 7))
+ fe_cmov(h.X, negx, fe_isnegative(h.X, fe_scratch_0) ^ (s[31] >> 7))
fe_mul(h.T, h.X, h.Y)
return i32(has_m_root | has_p_root) - 1