From 822bc804cf2a838200b9b77d43d0c606bf18f1f2 Mon Sep 17 00:00:00 2001 From: Chris Duncan Date: Thu, 27 Aug 2026 07:15:28 -0700 Subject: [PATCH] Adjust names and sort order. --- src/assembly/crypto_verify.ts | 17 ++++++++++------- src/assembly/index.ts | 10 +++++----- 2 files changed, 15 insertions(+), 12 deletions(-) diff --git a/src/assembly/crypto_verify.ts b/src/assembly/crypto_verify.ts index 9a6a3ae..402b9af 100644 --- a/src/assembly/crypto_verify.ts +++ b/src/assembly/crypto_verify.ts @@ -1,6 +1,7 @@ //! SPDX-FileCopyrightText: 2026 Chris Duncan //! SPDX-License-Identifier: GPL-3.0-or-later +import { BLOCKHASH_BYTELENGTH, KEY_BYTELENGTH } from '.' import { Blake2b } from './blake2b' import { ge_double_scalarmult_vartime_to_p3, ge_frombytes, ge_frombytes_negate_vartime, ge_has_small_order, ge_is_canonical } from './ge' import { ge_p3, ge_sub_p3 } from './p' @@ -10,12 +11,12 @@ import { sc_is_canonical, sc_reduce } from './sc' const blake2b = new Blake2b() // algorithm variables -const h = new StaticArray(64) -const check = new ge_p3() -const expected_r = new ge_p3() const A = new ge_p3() -const sb_ah = new ge_p3() const S = new StaticArray(32) +const expected_r = new ge_p3() +const h = new StaticArray(64) +const sb_ah = new ge_p3() +const check = new ge_p3() /** * Verify public key `pub` is canonical, non-malleable, and correct. @@ -33,13 +34,14 @@ export function crypto_verify_pubkey (pub: StaticArray): i32 { } /** - * Verify signature `s` was made by signing message `M` using public key `pub`. + * Verify signature `s` was made by signing block hash `M` using public key + * `pub`. * * IMPORTANT: Callers MUST call `crypto_verify_pubkey` first in order to set `A` * for the scalar multiplication step before checking `sB = R + hA`. * @returns -1 if signature fails to verify, else return 0 if signature is good */ -export function crypto_verify_relaxed (s: StaticArray, M: StaticArray, mlen: i32, pub: StaticArray): i32 { +export function crypto_verify_relaxed (s: StaticArray, M: StaticArray, pub: StaticArray): i32 { // fail if private scalar `S` is non-canonical (`L ≤ S`) memory.copy(changetype(S), changetype(s) + 32, 32) @@ -52,7 +54,7 @@ export function crypto_verify_relaxed (s: StaticArray, M: StaticArray, m // data to hash is nonce point R, public key A, and message M // from parameter arguments: R = s[0,32], A = pk, M = m // R, S, A, and M are all 32-byte values in this implementation - blake2b.init().update(s, 32).update(pub, 32).update(M, mlen).digest(h) + blake2b.init().update(s, 32).update(pub, KEY_BYTELENGTH).update(M, BLOCKHASH_BYTELENGTH).digest(h) sc_reduce(h) ge_double_scalarmult_vartime_to_p3(sb_ah, h, A, S) @@ -70,6 +72,7 @@ export function crypto_verify_relaxed (s: StaticArray, M: StaticArray, m * @returns -1 if signature fails to verify, else return 0 if signature is good */ export function crypto_verify_strict (s: StaticArray, M: StaticArray, mlen: i32, pub: StaticArray): i32 { + // Check public key is valid if (crypto_verify_pubkey(pub) != 0) return -1 // fail if private scalar `S` is non-canonical (`L ≤ S`) diff --git a/src/assembly/index.ts b/src/assembly/index.ts index b1d7f25..f3b7c29 100644 --- a/src/assembly/index.ts +++ b/src/assembly/index.ts @@ -204,13 +204,13 @@ export function verify_blocks (count: i32): void { if (crypto_verify_pubkey(pub) == 0) { // Iterate over block hash/signature pairs - for (let i = 0, j = changetype(MESSAGE_BUFFER); i < count; i++, j += 96) { - // Copy message buffer to local block hash/signature buffers - memory.copy(changetype(h), j, BLOCKHASH_BYTELENGTH) - memory.copy(changetype(sig), j + BLOCKHASH_BYTELENGTH, SIGNATURE_BYTELENGTH) + for (let i = 0, ptr = changetype(MESSAGE_BUFFER); i < count; i++, ptr += 96) { + // Copy block hash/signature from message buffer to locals + memory.copy(changetype(h), ptr, BLOCKHASH_BYTELENGTH) + memory.copy(changetype(sig), ptr + BLOCKHASH_BYTELENGTH, SIGNATURE_BYTELENGTH) // Verify hash and signature, then write result to output buffer - OUTPUT_BUFFER[i] = u8(crypto_verify_relaxed(sig, h, BLOCKHASH_BYTELENGTH, pub)) + OUTPUT_BUFFER[i] = u8(crypto_verify_relaxed(sig, h, pub)) } } -- 2.52.0