From 6e1342dbbf5d542f0f0f2845c385b16f12e36968 Mon Sep 17 00:00:00 2001 From: Chris Duncan Date: Fri, 2 Oct 2026 02:40:18 -0700 Subject: [PATCH] More scratch buffers. --- src/assembly/ed25519/fe.ts | 8 ++++---- src/assembly/ed25519/ge.ts | 32 ++++++++++++++++++++------------ 2 files changed, 24 insertions(+), 16 deletions(-) diff --git a/src/assembly/ed25519/fe.ts b/src/assembly/ed25519/fe.ts index 714e9d2..632ef5c 100644 --- a/src/assembly/ed25519/fe.ts +++ b/src/assembly/ed25519/fe.ts @@ -512,10 +512,10 @@ const fe_pow22523_t2: FieldElement = fe() * returns z^((p-5)/8) = z^(2²⁵²-3) * used to compute square roots since we have p=5 (mod 8); see Cohen and Frey. */ -export function fe_pow22523 (out: FieldElement, z: FieldElement): void { - const t0 = fe_pow22523_t0 - const t1 = fe_pow22523_t1 - const t2 = fe_pow22523_t2 +export function fe_pow22523 (out: FieldElement, z: FieldElement, fe_scratch_0: FieldElement, fe_scratch_1: FieldElement, fe_scratch_2: FieldElement): void { + const t0 = fe_scratch_0 + const t1 = fe_scratch_1 + const t2 = fe_scratch_2 fe_sq(t0, z) fe_sq(t1, t0) diff --git a/src/assembly/ed25519/ge.ts b/src/assembly/ed25519/ge.ts index e979d05..59bc428 100644 --- a/src/assembly/ed25519/ge.ts +++ b/src/assembly/ed25519/ge.ts @@ -86,7 +86,9 @@ function ge_cmov8_base (t: ge_precomp, bp: usize, b: i8): void { } const ge_frombytes_negate_vartime_u8x32_scratch = new StaticArray(32) -const ge_frombytes_negate_vartime_fe_scratch: FieldElement = fe() +const ge_frombytes_negate_vartime_fe_scratch_0: FieldElement = fe() +const ge_frombytes_negate_vartime_fe_scratch_1: FieldElement = fe() +const ge_frombytes_negate_vartime_fe_scratch_2: FieldElement = fe() const u: FieldElement = fe() const v: FieldElement = fe() const v3: FieldElement = fe() @@ -102,7 +104,9 @@ const p_root_check: FieldElement = fe() */ export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray): i32 { const u8x32_scratch = ge_frombytes_negate_vartime_u8x32_scratch - const fe_scratch = ge_frombytes_negate_vartime_fe_scratch + const fe_scratch_0 = ge_frombytes_negate_vartime_fe_scratch_0 + const fe_scratch_1 = ge_frombytes_negate_vartime_fe_scratch_1 + const fe_scratch_2 = ge_frombytes_negate_vartime_fe_scratch_2 fe_frombytes(h.Y, s) fe_1(h.Z) @@ -123,7 +127,7 @@ export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray): i32 fe_mul(h.X, h.X, u) // x = (uv⁷)^((q-5)/8) - fe_pow22523(h.X, h.X) + fe_pow22523(h.X, h.X, fe_scratch_0, fe_scratch_1, fe_scratch_2) // x = uv³((uv⁷)^((q-5)/8)) fe_mul(h.X, h.X, v3) @@ -135,16 +139,16 @@ export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray): i32 // m = vx²-u fe_sub(m_root_check, vxx, u) - if (fe_iszero(m_root_check, u8x32_scratch, fe_scratch) == 0) { + if (fe_iszero(m_root_check, u8x32_scratch, fe_scratch_0) == 0) { // p = vx²+u fe_add(p_root_check, vxx, u) - if (fe_iszero(p_root_check, u8x32_scratch, fe_scratch) == 0) { + if (fe_iszero(p_root_check, u8x32_scratch, fe_scratch_0) == 0) { return -1 } fe_mul(h.X, h.X, fe_sqrtm1) } - if (fe_isnegative(h.X, fe_scratch) == (s[31] >> 7)) { + if (fe_isnegative(h.X, fe_scratch_0) == (s[31] >> 7)) { fe_neg(h.X, h.X) } fe_mul(h.T, h.X, h.Y) @@ -153,7 +157,9 @@ export function ge_frombytes_negate_vartime (h: ge_p3, s: StaticArray): i32 } const ge_frombytes_u8x32_scratch = new StaticArray(32) -const ge_frombytes_fe_scratch: FieldElement = fe() +const ge_frombytes_fe_scratch_0: FieldElement = fe() +const ge_frombytes_fe_scratch_1: FieldElement = fe() +const ge_frombytes_fe_scratch_2: FieldElement = fe() const ge_frombytes_u: FieldElement = fe() const ge_frombytes_v: FieldElement = fe() const ge_frombytes_vxx: FieldElement = fe() @@ -168,7 +174,9 @@ const x_sqrtm1: FieldElement = fe() */ export function ge_frombytes (h: ge_p3, s: StaticArray): i32 { const u8x32_scratch = ge_frombytes_u8x32_scratch - const fe_scratch = ge_frombytes_fe_scratch + const fe_scratch_0 = ge_frombytes_fe_scratch_0 + const fe_scratch_1 = ge_frombytes_fe_scratch_1 + const fe_scratch_2 = ge_frombytes_fe_scratch_2 const u = ge_frombytes_u const v = ge_frombytes_v const vxx = ge_frombytes_vxx @@ -190,7 +198,7 @@ export function ge_frombytes (h: ge_p3, s: StaticArray): i32 { /* x = u((uv)^((q-5)/8)) */ fe_mul(h.X, u, v) - fe_pow22523(h.X, h.X) + fe_pow22523(h.X, h.X, fe_scratch_0, fe_scratch_1, fe_scratch_2) fe_mul(h.X, u, h.X) // vxx = vx² @@ -199,18 +207,18 @@ export function ge_frombytes (h: ge_p3, s: StaticArray): i32 { // m = vx²-u fe_sub(m_root_check, vxx, u) - has_m_root = fe_iszero(m_root_check, u8x32_scratch, fe_scratch) + has_m_root = fe_iszero(m_root_check, u8x32_scratch, fe_scratch_0) // p = vx²+u fe_add(p_root_check, vxx, u) - has_p_root = fe_iszero(p_root_check, u8x32_scratch, fe_scratch) + has_p_root = fe_iszero(p_root_check, u8x32_scratch, fe_scratch_0) // x√-1 fe_mul(x_sqrtm1, h.X, fe_sqrtm1) fe_cmov(h.X, x_sqrtm1, 1 - has_m_root) fe_neg(negx, h.X) - fe_cmov(h.X, negx, fe_isnegative(h.X, fe_scratch) ^ (s[31] >> 7)) + fe_cmov(h.X, negx, fe_isnegative(h.X, fe_scratch_0) ^ (s[31] >> 7)) fe_mul(h.T, h.X, h.Y) return i32(has_m_root | has_p_root) - 1 -- 2.52.0