From 5cb0e31b627949cb33c29f40edef7be14ee6edc3 Mon Sep 17 00:00:00 2001 From: Chris Duncan Date: Fri, 2 Oct 2026 01:47:34 -0700 Subject: [PATCH] Move buffers and adjust naming convention. --- src/assembly/ed25519/fe.ts | 6 +----- src/assembly/ed25519/ge.ts | 37 +++++++++++++++++++++++-------------- 2 files changed, 24 insertions(+), 19 deletions(-) diff --git a/src/assembly/ed25519/fe.ts b/src/assembly/ed25519/fe.ts index 5d072cd..75c2245 100644 --- a/src/assembly/ed25519/fe.ts +++ b/src/assembly/ed25519/fe.ts @@ -244,8 +244,6 @@ export function fe_isnegative (f: FieldElement, t: FieldElement): u8 { return u8(t[0] & 1) } -const fe_iszero_s = new StaticArray(32) -const fe_iszero_t: FieldElement = fe() /** * return 1 if f == 0 * return 0 if f != 0 @@ -253,9 +251,7 @@ const fe_iszero_t: FieldElement = fe() * Preconditions: * |f| bounded by 1.1x2²⁶,1.1x2²⁵,1.1x2²⁶,1.1x2²⁵,etc. */ -export function fe_iszero (f: FieldElement): u8 { - const s = fe_iszero_s - const t = fe_iszero_t +export function fe_iszero (s: StaticArray, f: FieldElement, t: FieldElement): u8 { fe_tobytes(s, f, t) return sodium_is_zero(s, 32) } diff --git a/src/assembly/ed25519/ge.ts b/src/assembly/ed25519/ge.ts index 6bb9928..66b8fc1 100644 --- a/src/assembly/ed25519/ge.ts +++ b/src/assembly/ed25519/ge.ts @@ -85,7 +85,8 @@ function ge_cmov8_base (t: ge_precomp, bp: usize, b: i8): void { v128.store_lane(td, v128.bitselect(v128.neg(d2), d2, n), 0, 32) } -const t: FieldElement = fe() +const ge_frombytes_negate_vartime_u8x32_scratch = new StaticArray(32) +const ge_frombytes_negate_vartime_fe_scratch: FieldElement = fe() const u: FieldElement = fe() const v: FieldElement = fe() const v3: FieldElement = fe() @@ -100,6 +101,8 @@ const p_root_check: FieldElement = fe() * @returns {i32} 0 if `s` decodes to a valid point, else -1 */ export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray): i32 { + const u8x32_scratch = ge_frombytes_negate_vartime_u8x32_scratch + const fe_scratch = ge_frombytes_negate_vartime_fe_scratch fe_frombytes(h.Y, s) fe_1(h.Z) @@ -132,16 +135,16 @@ export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray): i32 // m = vx²-u fe_sub(m_root_check, vxx, u) - if (fe_iszero(m_root_check) == 0) { + if (fe_iszero(u8x32_scratch, m_root_check, fe_scratch) == 0) { // p = vx²+u fe_add(p_root_check, vxx, u) - if (fe_iszero(p_root_check) == 0) { + if (fe_iszero(u8x32_scratch, p_root_check, fe_scratch) == 0) { return -1 } fe_mul(h.X, h.X, fe_sqrtm1) } - if (fe_isnegative(h.X, t) == (s[31] >> 7)) { + if (fe_isnegative(h.X, fe_scratch) == (s[31] >> 7)) { fe_neg(h.X, h.X) } fe_mul(h.T, h.X, h.Y) @@ -149,7 +152,8 @@ export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray): i32 return 0 } -const ge_frombytes_t: FieldElement = fe() +const ge_frombytes_u8x32_scratch = new StaticArray(32) +const ge_frombytes_fe_scratch: FieldElement = fe() const ge_frombytes_u: FieldElement = fe() const ge_frombytes_v: FieldElement = fe() const ge_frombytes_vxx: FieldElement = fe() @@ -163,7 +167,8 @@ const x_sqrtm1: FieldElement = fe() * @returns {i32} 0 if `s` decodes to a valid point, else -1 */ export function ge_frombytes (h: ge_p3, s: StaticArray): i32 { - const t = ge_frombytes_t + const u8x32_scratch = ge_frombytes_u8x32_scratch + const fe_scratch = ge_frombytes_fe_scratch const u = ge_frombytes_u const v = ge_frombytes_v const vxx = ge_frombytes_vxx @@ -194,37 +199,41 @@ export function ge_frombytes (h: ge_p3, s: StaticArray): i32 { // m = vx²-u fe_sub(m_root_check, vxx, u) - has_m_root = fe_iszero(m_root_check) + has_m_root = fe_iszero(u8x32_scratch, m_root_check, fe_scratch) // p = vx²+u fe_add(p_root_check, vxx, u) - has_p_root = fe_iszero(p_root_check) + has_p_root = fe_iszero(u8x32_scratch, p_root_check, fe_scratch) // x√-1 fe_mul(x_sqrtm1, h.X, fe_sqrtm1) fe_cmov(h.X, x_sqrtm1, 1 - has_m_root) fe_neg(negx, h.X) - fe_cmov(h.X, negx, fe_isnegative(h.X, t) ^ (s[31] >> 7)) + fe_cmov(h.X, negx, fe_isnegative(h.X, fe_scratch) ^ (s[31] >> 7)) fe_mul(h.T, h.X, h.Y) return i32(has_m_root | has_p_root) - 1 } +const ge_has_small_order_u8x32_scratch = new StaticArray(32) +const ge_has_small_order_fe_scratch: FieldElement = fe() const y_sqrtm1: FieldElement = fe() const c: FieldElement = fe() /** return 1 if p has small order else return 0 */ export function ge_has_small_order (p: ge_p3): i32 { + const u8x32_scratch = ge_has_small_order_u8x32_scratch + const fe_scratch = ge_has_small_order_fe_scratch let ret: i32 = 0 - ret |= fe_iszero(p.X) - ret |= fe_iszero(p.Y) - ret |= fe_iszero(p.Z) + ret |= fe_iszero(u8x32_scratch, p.X, fe_scratch) + ret |= fe_iszero(u8x32_scratch, p.Y, fe_scratch) + ret |= fe_iszero(u8x32_scratch, p.Z, fe_scratch) fe_mul(y_sqrtm1, p.Y, fe_sqrtm1) fe_sub(c, y_sqrtm1, p.X) - ret |= fe_iszero(c) + ret |= fe_iszero(u8x32_scratch, c, fe_scratch) fe_add(c, y_sqrtm1, p.X) - ret |= fe_iszero(c) + ret |= fe_iszero(u8x32_scratch, c, fe_scratch) return ret } -- 2.52.0