sha512.h 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132
  1. /*
  2. * Definitions likely to be helpful to multiple SHA-512 implementations.
  3. */
  4. /*
  5. * The 'extra' structure used by SHA-512 implementations is used to
  6. * include information about how to check if a given implementation is
  7. * available at run time, and whether we've already checked.
  8. */
  9. struct sha512_extra_mutable;
  10. struct sha512_extra {
  11. /* Pointer to the initial state (distinguishes SHA-384 from -512) */
  12. const uint64_t *initial_state;
  13. /* Function to check availability. Might be expensive, so we don't
  14. * want to call it more than once. */
  15. bool (*check_available)(void);
  16. /* Point to a writable substructure. */
  17. struct sha512_extra_mutable *mut;
  18. };
  19. struct sha512_extra_mutable {
  20. bool checked_availability;
  21. bool is_available;
  22. };
  23. static inline bool check_availability(const struct sha512_extra *extra)
  24. {
  25. if (!extra->mut->checked_availability) {
  26. extra->mut->is_available = extra->check_available();
  27. extra->mut->checked_availability = true;
  28. }
  29. return extra->mut->is_available;
  30. }
  31. /*
  32. * Macro to define a pair of SHA-{384,512} vtables together with their
  33. * 'extra' structure.
  34. */
  35. #define SHA512_VTABLES(impl_c, impl_display) \
  36. static struct sha512_extra_mutable sha512_ ## impl_c ## _extra_mut; \
  37. static const struct sha512_extra sha384_ ## impl_c ## _extra = { \
  38. .initial_state = sha384_initial_state, \
  39. .check_available = sha512_ ## impl_c ## _available, \
  40. .mut = &sha512_ ## impl_c ## _extra_mut, \
  41. }; \
  42. static const struct sha512_extra sha512_ ## impl_c ## _extra = { \
  43. .initial_state = sha512_initial_state, \
  44. .check_available = sha512_ ## impl_c ## _available, \
  45. .mut = &sha512_ ## impl_c ## _extra_mut, \
  46. }; \
  47. const ssh_hashalg ssh_sha384_ ## impl_c = { \
  48. .new = sha512_ ## impl_c ## _new, \
  49. .reset = sha512_ ## impl_c ## _reset, \
  50. .copyfrom = sha512_ ## impl_c ## _copyfrom, \
  51. .digest = sha384_ ## impl_c ## _digest, \
  52. .free = sha512_ ## impl_c ## _free, \
  53. .hlen = 48, \
  54. .blocklen = 128, \
  55. HASHALG_NAMES_ANNOTATED("SHA-384", impl_display), \
  56. .extra = &sha384_ ## impl_c ## _extra, \
  57. }; \
  58. const ssh_hashalg ssh_sha512_ ## impl_c = { \
  59. .new = sha512_ ## impl_c ## _new, \
  60. .reset = sha512_ ## impl_c ## _reset, \
  61. .copyfrom = sha512_ ## impl_c ## _copyfrom, \
  62. .digest = sha512_ ## impl_c ## _digest, \
  63. .free = sha512_ ## impl_c ## _free, \
  64. .hlen = 64, \
  65. .blocklen = 128, \
  66. HASHALG_NAMES_ANNOTATED("SHA-512", impl_display), \
  67. .extra = &sha512_ ## impl_c ## _extra, \
  68. }
  69. extern const uint64_t sha512_initial_state[8];
  70. extern const uint64_t sha384_initial_state[8];
  71. extern const uint64_t sha512_round_constants[80];
  72. #define SHA512_ROUNDS 80
  73. typedef struct sha512_block sha512_block;
  74. struct sha512_block {
  75. uint8_t block[128];
  76. size_t used;
  77. uint64_t lenhi, lenlo;
  78. };
  79. static inline void sha512_block_setup(sha512_block *blk)
  80. {
  81. blk->used = 0;
  82. blk->lenhi = blk->lenlo = 0;
  83. }
  84. static inline bool sha512_block_write(
  85. sha512_block *blk, const void **vdata, size_t *len)
  86. {
  87. size_t blkleft = sizeof(blk->block) - blk->used;
  88. size_t chunk = *len < blkleft ? *len : blkleft;
  89. const uint8_t *p = *vdata;
  90. memcpy(blk->block + blk->used, p, chunk);
  91. *vdata = p + chunk;
  92. *len -= chunk;
  93. blk->used += chunk;
  94. size_t chunkbits = chunk << 3;
  95. blk->lenlo += chunkbits;
  96. blk->lenhi += (blk->lenlo < chunkbits);
  97. if (blk->used == sizeof(blk->block)) {
  98. blk->used = 0;
  99. return true;
  100. }
  101. return false;
  102. }
  103. static inline void sha512_block_pad(sha512_block *blk, BinarySink *bs)
  104. {
  105. uint64_t final_lenhi = blk->lenhi;
  106. uint64_t final_lenlo = blk->lenlo;
  107. size_t pad = 127 & (111 - blk->used);
  108. put_byte(bs, 0x80);
  109. put_padding(bs, pad, 0);
  110. put_uint64(bs, final_lenhi);
  111. put_uint64(bs, final_lenlo);
  112. assert(blk->used == 0 && "Should have exactly hit a block boundary");
  113. }