import { KEY_BYTELENGTH } from '.'
import { Blake2b } from './blake2b'
import { crypto_derive } from './crypto_derive'
-import { errors } from './errors'
import { ge_scalarmult_base_tobytes } from './ge'
import { sc_muladd, sc_reduce } from './sc'
import { clamp } from './utils'
* In this implementation, both the private key and the public key are required.
* This ensures the user has a full correct keypair for data integrity. It also
* offers a small performance improvement in the case of an invalid public key
- * by throwing early and avoiding expensive point multiplication; RFC 8032
+ * by returning early and avoiding expensive point multiplication; RFC 8032
* indicates the public key should be recomputed from the private key when
* signing anyway, so there is no penalty for checking key validity first.
*
* @param {StaticArray<u8>} pub 32-byte public key from input buffer
*/
export function crypto_sign (RS: StaticArray<u8>, M: StaticArray<u8>, mlen: i32, prv: StaticArray<u8>, pub: StaticArray<u8>): i32 {
- // Derive `A` from private key and throw if it does not match public key
+ // Derive `A` from private key
crypto_derive(A, prv)
let c = 0
for (let i = 0; i < KEY_BYTELENGTH; i++) {
c |= A[i] ^ pub[i]
}
+ // Return early if `A` does not match public key
if (c != 0) return 1
// Hash private key to `h`
R.fill(0)
memory.copy(changetype<usize>(RS) + 32, changetype<usize>(S), 32)
S.fill(0)
-
+
return 0
}