]> git.codecow.com Git - nano25519.git/commitdiff
Reverse hash and signature order to match libsodium convention for combined mode.
authorChris Duncan <chris@codecow.com>
Thu, 27 Aug 2026 14:25:14 +0000 (07:25 -0700)
committerChris Duncan <chris@codecow.com>
Thu, 27 Aug 2026 14:25:14 +0000 (07:25 -0700)
src/assembly/index.ts
src/index.ts
src/lib/verify.ts

index f3b7c2902ab1776a30a5516d51cacc1f8fb85ac1..12e0dae601234fa067162d080026f4a41597ccef 100644 (file)
@@ -171,10 +171,10 @@ export function verify (mlen: i32): void {
  * Verify a 64-byte detached signature for a 32-byte Nano block hash against a
  * 32-byte public key. Input parameters are read as bytes from separate buffers.
  *
- * The message buffer holds both the block hash and the signature buffer as a
- * 96-byte concatenated value. The 32 KiB message buffer cannot be divided
- * evenly by 96, so up to 341 block hash/signature pairs are supported with an
- * extra 32 bytes left at the end.
+ * The message buffer holds both the signature and the block hash as a 96-byte
+ * concatenated value. The 32 KiB message buffer cannot be divided evenly by 96,
+ * so up to 341 block signature/hash pairs are supported with an extra 32 bytes
+ * left at the end.
  *
  * All pairs are verified against a single public key. The results are written
  * to the output buffer in the same order they were received.
@@ -203,11 +203,11 @@ export function verify_blocks (count: i32): void {
        // Verify public key before proceeding with signature verification
        if (crypto_verify_pubkey(pub) == 0) {
 
-               // Iterate over block hash/signature pairs
+               // Iterate over block signature/hash pairs
                for (let i = 0, ptr = changetype<usize>(MESSAGE_BUFFER); i < count; i++, ptr += 96) {
-                       // Copy block hash/signature from message buffer to locals
-                       memory.copy(changetype<usize>(h), ptr, BLOCKHASH_BYTELENGTH)
-                       memory.copy(changetype<usize>(sig), ptr + BLOCKHASH_BYTELENGTH, SIGNATURE_BYTELENGTH)
+                       // Copy block signature/hash from message buffer to locals
+                       memory.copy(changetype<usize>(sig), ptr, SIGNATURE_BYTELENGTH)
+                       memory.copy(changetype<usize>(h), ptr + SIGNATURE_BYTELENGTH, BLOCKHASH_BYTELENGTH)
 
                        // Verify hash and signature, then write result to output buffer
                        OUTPUT_BUFFER[i] = u8(crypto_verify_relaxed(sig, h, pub))
index 8dbb67298575f57b789c818c9f35de46e368c950..e843a5c43ccf8e90bfd3971dc5549aed977dc3fe 100644 (file)
@@ -85,22 +85,22 @@ export function verify (sig: string | Uint8Array<ArrayBuffer>, msg: string | Uin
 /**
  * Nano block signature bulk verification using WebAssembly.
  * @param {Uint8Array<ArrayBuffer>} publicKey - 32-byte public key
- * @param {object[]} blocks - Array of up to 341 block hash/signature pairs
- * @param {Uint8Array<ArrayBuffer>} blocks.hash - 32-byte block hash
+ * @param {object[]} blocks - Array of up to 341 block signature/hash pairs
  * @param {Uint8Array<ArrayBuffer>} blocks.signature - 64-byte block signature
+ * @param {Uint8Array<ArrayBuffer>} blocks.hash - 32-byte block hash
  * @returns Array of results with, for each case, true if signature matches block hash and public key, else false
  */
 export function verify_blocks (publicKey: Uint8Array<ArrayBuffer>, blocks: { hash: Uint8Array<ArrayBuffer>, signature: Uint8Array<ArrayBuffer> }[]): boolean[]
 /**
  * Nano block signature bulk verification using WebAssembly.
  * @param {string} publicKey - 64-character hexadecimal public key
- * @param {object[]} blocks - Array of up to 341 block hash/signature pairs
- * @param {string} blocks.hash - 64-character hexadecimal block hash
+ * @param {object[]} blocks - Array of up to 341 block signature/hash pairs
  * @param {string} blocks.signature - 128-character hexadecimal block signature
+ * @param {string} blocks.hash - 64-character hexadecimal block hash
  * @returns Array of results with, for each case, true if signature matches block hash and public key, else false
  */
-export function verify_blocks (publicKey: string, blocks: { hash: string, signature: string }[]): boolean[]
-export function verify_blocks (publicKey: string | Uint8Array<ArrayBuffer>, blocks: { hash: string | Uint8Array<ArrayBuffer>, signature: string | Uint8Array<ArrayBuffer> }[]): boolean[] {
+export function verify_blocks (publicKey: string, blocks: { signature: string, hash: string }[]): boolean[]
+export function verify_blocks (publicKey: string | Uint8Array<ArrayBuffer>, blocks: { signature: string | Uint8Array<ArrayBuffer>, hash: string | Uint8Array<ArrayBuffer> }[]): boolean[] {
        return nano25519.verify_blocks(publicKey, blocks)
 }
 
index 0ef454cc4b3e6b31eab1e8cd479fa93fdfc15da8..e61efd79a759f747efdd7faee2f8273743827032 100644 (file)
@@ -48,22 +48,22 @@ export function verify_blocks (pub: unknown, data: unknown): boolean[] {
                        if (block == null || typeof block !== 'object') {
                                throw new TypeError('Invalid block', { cause: block })
                        }
-                       if (!('hash' in block)) {
-                               throw new TypeError('Block hash is required to verify', { cause: block })
-                       }
                        if (!('signature' in block)) {
                                throw new TypeError('Block signature is required to verify', { cause: block })
                        }
-                       const hash = normalize('hash', BLK_LEN, BLK_LEN, block.hash)
-                       const signature = normalize('signature', SIG_LEN, SIG_LEN, block.signature)
-                       for (let i = 0; i < BLK_LEN; i++) {
-                               buffer[p + i] = hash[i]
+                       if (!('hash' in block)) {
+                               throw new TypeError('Block hash is required to verify', { cause: block })
                        }
-                       p += BLK_LEN
+                       const signature = normalize('signature', SIG_LEN, SIG_LEN, block.signature)
+                       const hash = normalize('hash', BLK_LEN, BLK_LEN, block.hash)
                        for (let i = 0; i < SIG_LEN; i++) {
                                buffer[p + i] = signature[i]
                        }
                        p += SIG_LEN
+                       for (let i = 0; i < BLK_LEN; i++) {
+                               buffer[p + i] = hash[i]
+                       }
+                       p += BLK_LEN
                }
                exports.verify_blocks(blocks.length)
                for (let i = 0; i < count; i++) {