From: Chris Duncan Date: Thu, 27 Aug 2026 14:25:14 +0000 (-0700) Subject: Reverse hash and signature order to match libsodium convention for combined mode. X-Git-Url: https://git.codecow.com/?a=commitdiff_plain;h=f5f81fee61ccf5d255c74c180996d7f1dac876fb;p=nano25519.git Reverse hash and signature order to match libsodium convention for combined mode. --- diff --git a/src/assembly/index.ts b/src/assembly/index.ts index f3b7c29..12e0dae 100644 --- a/src/assembly/index.ts +++ b/src/assembly/index.ts @@ -171,10 +171,10 @@ export function verify (mlen: i32): void { * Verify a 64-byte detached signature for a 32-byte Nano block hash against a * 32-byte public key. Input parameters are read as bytes from separate buffers. * - * The message buffer holds both the block hash and the signature buffer as a - * 96-byte concatenated value. The 32 KiB message buffer cannot be divided - * evenly by 96, so up to 341 block hash/signature pairs are supported with an - * extra 32 bytes left at the end. + * The message buffer holds both the signature and the block hash as a 96-byte + * concatenated value. The 32 KiB message buffer cannot be divided evenly by 96, + * so up to 341 block signature/hash pairs are supported with an extra 32 bytes + * left at the end. * * All pairs are verified against a single public key. The results are written * to the output buffer in the same order they were received. @@ -203,11 +203,11 @@ export function verify_blocks (count: i32): void { // Verify public key before proceeding with signature verification if (crypto_verify_pubkey(pub) == 0) { - // Iterate over block hash/signature pairs + // Iterate over block signature/hash pairs for (let i = 0, ptr = changetype(MESSAGE_BUFFER); i < count; i++, ptr += 96) { - // Copy block hash/signature from message buffer to locals - memory.copy(changetype(h), ptr, BLOCKHASH_BYTELENGTH) - memory.copy(changetype(sig), ptr + BLOCKHASH_BYTELENGTH, SIGNATURE_BYTELENGTH) + // Copy block signature/hash from message buffer to locals + memory.copy(changetype(sig), ptr, SIGNATURE_BYTELENGTH) + memory.copy(changetype(h), ptr + SIGNATURE_BYTELENGTH, BLOCKHASH_BYTELENGTH) // Verify hash and signature, then write result to output buffer OUTPUT_BUFFER[i] = u8(crypto_verify_relaxed(sig, h, pub)) diff --git a/src/index.ts b/src/index.ts index 8dbb672..e843a5c 100644 --- a/src/index.ts +++ b/src/index.ts @@ -85,22 +85,22 @@ export function verify (sig: string | Uint8Array, msg: string | Uin /** * Nano block signature bulk verification using WebAssembly. * @param {Uint8Array} publicKey - 32-byte public key - * @param {object[]} blocks - Array of up to 341 block hash/signature pairs - * @param {Uint8Array} blocks.hash - 32-byte block hash + * @param {object[]} blocks - Array of up to 341 block signature/hash pairs * @param {Uint8Array} blocks.signature - 64-byte block signature + * @param {Uint8Array} blocks.hash - 32-byte block hash * @returns Array of results with, for each case, true if signature matches block hash and public key, else false */ export function verify_blocks (publicKey: Uint8Array, blocks: { hash: Uint8Array, signature: Uint8Array }[]): boolean[] /** * Nano block signature bulk verification using WebAssembly. * @param {string} publicKey - 64-character hexadecimal public key - * @param {object[]} blocks - Array of up to 341 block hash/signature pairs - * @param {string} blocks.hash - 64-character hexadecimal block hash + * @param {object[]} blocks - Array of up to 341 block signature/hash pairs * @param {string} blocks.signature - 128-character hexadecimal block signature + * @param {string} blocks.hash - 64-character hexadecimal block hash * @returns Array of results with, for each case, true if signature matches block hash and public key, else false */ -export function verify_blocks (publicKey: string, blocks: { hash: string, signature: string }[]): boolean[] -export function verify_blocks (publicKey: string | Uint8Array, blocks: { hash: string | Uint8Array, signature: string | Uint8Array }[]): boolean[] { +export function verify_blocks (publicKey: string, blocks: { signature: string, hash: string }[]): boolean[] +export function verify_blocks (publicKey: string | Uint8Array, blocks: { signature: string | Uint8Array, hash: string | Uint8Array }[]): boolean[] { return nano25519.verify_blocks(publicKey, blocks) } diff --git a/src/lib/verify.ts b/src/lib/verify.ts index 0ef454c..e61efd7 100644 --- a/src/lib/verify.ts +++ b/src/lib/verify.ts @@ -48,22 +48,22 @@ export function verify_blocks (pub: unknown, data: unknown): boolean[] { if (block == null || typeof block !== 'object') { throw new TypeError('Invalid block', { cause: block }) } - if (!('hash' in block)) { - throw new TypeError('Block hash is required to verify', { cause: block }) - } if (!('signature' in block)) { throw new TypeError('Block signature is required to verify', { cause: block }) } - const hash = normalize('hash', BLK_LEN, BLK_LEN, block.hash) - const signature = normalize('signature', SIG_LEN, SIG_LEN, block.signature) - for (let i = 0; i < BLK_LEN; i++) { - buffer[p + i] = hash[i] + if (!('hash' in block)) { + throw new TypeError('Block hash is required to verify', { cause: block }) } - p += BLK_LEN + const signature = normalize('signature', SIG_LEN, SIG_LEN, block.signature) + const hash = normalize('hash', BLK_LEN, BLK_LEN, block.hash) for (let i = 0; i < SIG_LEN; i++) { buffer[p + i] = signature[i] } p += SIG_LEN + for (let i = 0; i < BLK_LEN; i++) { + buffer[p + i] = hash[i] + } + p += BLK_LEN } exports.verify_blocks(blocks.length) for (let i = 0; i < count; i++) {