From 14b03e381f02653a2bd2e3df4c9c9dbd76a91d50 Mon Sep 17 00:00:00 2001 From: Chris Duncan Date: Fri, 2 Oct 2026 02:27:59 -0700 Subject: [PATCH] Adjust how scratch args are sorted. --- src/assembly/ed25519/fe.ts | 25 +++++++++++++++---------- src/assembly/ed25519/ge.ts | 18 +++++++++--------- src/assembly/ed25519/p.ts | 8 ++++---- 3 files changed, 28 insertions(+), 23 deletions(-) diff --git a/src/assembly/ed25519/fe.ts b/src/assembly/ed25519/fe.ts index 75c2245..714e9d2 100644 --- a/src/assembly/ed25519/fe.ts +++ b/src/assembly/ed25519/fe.ts @@ -14,7 +14,7 @@ * * `n = 2⁰a[0] + 2²⁶a[1] + 2⁷⁷a[2] ... + 2²³⁰a[9]` */ -import { load_3, load_4, sodium_is_zero } from './utils' +import { load_3, load_4 } from './utils' /** * 10x 25- and 26-bit array of values representing a large integer `n mod p`. In @@ -239,9 +239,9 @@ export function fe_invert (out: FieldElement, z: FieldElement): void { * Preconditions: * |f| bounded by 1.1x2²⁶,1.1x2²⁵,1.1x2²⁶,1.1x2²⁵,etc. */ -export function fe_isnegative (f: FieldElement, t: FieldElement): u8 { - fe_reduce(t, f) - return u8(t[0] & 1) +export function fe_isnegative (f: FieldElement, fe_scratch: FieldElement): u8 { + fe_reduce(fe_scratch, f) + return u8(fe_scratch[0] & 1) } /** @@ -251,9 +251,14 @@ export function fe_isnegative (f: FieldElement, t: FieldElement): u8 { * Preconditions: * |f| bounded by 1.1x2²⁶,1.1x2²⁵,1.1x2²⁶,1.1x2²⁵,etc. */ -export function fe_iszero (s: StaticArray, f: FieldElement, t: FieldElement): u8 { - fe_tobytes(s, f, t) - return sodium_is_zero(s, 32) +export function fe_iszero (f: FieldElement, u8x32_scratch: StaticArray, fe_scratch: FieldElement): u8 { + fe_tobytes(u8x32_scratch, f, fe_scratch) + let d: i32 = 0 + for (let i: i32 = 0; i < 32; i++) { + d |= u8x32_scratch[i] + } + d &= 255 + return u8(((d - 1) >> 8) & 1) } /** @@ -1068,9 +1073,9 @@ export function fe_sub (h: FieldElement, f: FieldElement, g: FieldElement): void * * Goal: Output h0+...+2²³⁰ h9. */ -export function fe_tobytes (s: StaticArray, h: FieldElement, t: FieldElement): void { - fe_reduce(t, h) - const t_ptr: usize = changetype(t) +export function fe_tobytes (s: StaticArray, h: FieldElement, fe_scratch: FieldElement): void { + fe_reduce(fe_scratch, h) + const t_ptr: usize = changetype(fe_scratch) const t0 = load(t_ptr, 0) const t1 = load(t_ptr, 4) const t2 = load(t_ptr, 8) diff --git a/src/assembly/ed25519/ge.ts b/src/assembly/ed25519/ge.ts index 66b8fc1..e979d05 100644 --- a/src/assembly/ed25519/ge.ts +++ b/src/assembly/ed25519/ge.ts @@ -135,10 +135,10 @@ export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray): i32 // m = vx²-u fe_sub(m_root_check, vxx, u) - if (fe_iszero(u8x32_scratch, m_root_check, fe_scratch) == 0) { + if (fe_iszero(m_root_check, u8x32_scratch, fe_scratch) == 0) { // p = vx²+u fe_add(p_root_check, vxx, u) - if (fe_iszero(u8x32_scratch, p_root_check, fe_scratch) == 0) { + if (fe_iszero(p_root_check, u8x32_scratch, fe_scratch) == 0) { return -1 } fe_mul(h.X, h.X, fe_sqrtm1) @@ -199,11 +199,11 @@ export function ge_frombytes (h: ge_p3, s: StaticArray): i32 { // m = vx²-u fe_sub(m_root_check, vxx, u) - has_m_root = fe_iszero(u8x32_scratch, m_root_check, fe_scratch) + has_m_root = fe_iszero(m_root_check, u8x32_scratch, fe_scratch) // p = vx²+u fe_add(p_root_check, vxx, u) - has_p_root = fe_iszero(u8x32_scratch, p_root_check, fe_scratch) + has_p_root = fe_iszero(p_root_check, u8x32_scratch, fe_scratch) // x√-1 fe_mul(x_sqrtm1, h.X, fe_sqrtm1) @@ -226,14 +226,14 @@ export function ge_has_small_order (p: ge_p3): i32 { const fe_scratch = ge_has_small_order_fe_scratch let ret: i32 = 0 - ret |= fe_iszero(u8x32_scratch, p.X, fe_scratch) - ret |= fe_iszero(u8x32_scratch, p.Y, fe_scratch) - ret |= fe_iszero(u8x32_scratch, p.Z, fe_scratch) + ret |= fe_iszero(p.X, u8x32_scratch, fe_scratch) + ret |= fe_iszero(p.Y, u8x32_scratch, fe_scratch) + ret |= fe_iszero(p.Z, u8x32_scratch, fe_scratch) fe_mul(y_sqrtm1, p.Y, fe_sqrtm1) fe_sub(c, y_sqrtm1, p.X) - ret |= fe_iszero(u8x32_scratch, c, fe_scratch) + ret |= fe_iszero(c, u8x32_scratch, fe_scratch) fe_add(c, y_sqrtm1, p.X) - ret |= fe_iszero(u8x32_scratch, c, fe_scratch) + ret |= fe_iszero(c, u8x32_scratch, fe_scratch) return ret } diff --git a/src/assembly/ed25519/p.ts b/src/assembly/ed25519/p.ts index 401cd0f..6874727 100644 --- a/src/assembly/ed25519/p.ts +++ b/src/assembly/ed25519/p.ts @@ -105,20 +105,20 @@ export function ge_p3_to_cached (r: ge_cached, p: ge_p3): void { fe_mul(r.T2d, p.T, ed25519_d2) } -const ge_p3_tobytes_t: FieldElement = fe() +const ge_p3_tobytes_fe_scratch: FieldElement = fe() const ge_p3_tobytes_recip: FieldElement = fe() const ge_p3_tobytes_x: FieldElement = fe() const ge_p3_tobytes_y: FieldElement = fe() export function ge_p3_tobytes (s: StaticArray, h: ge_p3): void { - const t = ge_p3_tobytes_t + const fe_scratch = ge_p3_tobytes_fe_scratch const recip = ge_p3_tobytes_recip const x = ge_p3_tobytes_x const y = ge_p3_tobytes_y fe_invert(recip, h.Z) fe_mul(x, h.X, recip) fe_mul(y, h.Y, recip) - fe_tobytes(s, y, t) - s[31] ^= fe_isnegative(x, t) << 7 + fe_tobytes(s, y, fe_scratch) + s[31] ^= fe_isnegative(x, fe_scratch) << 7 } const ge_p2_dbl_t: FieldElement = fe() -- 2.52.0