1d059297112922cabb0c674840589be8db821fd9aAdam Langley/* $OpenBSD: hash.c,v 1.3 2013/12/09 11:03:45 markus Exp $ */ 2d059297112922cabb0c674840589be8db821fd9aAdam Langley 3d059297112922cabb0c674840589be8db821fd9aAdam Langley/* Copied from nacl-20110221/crypto_hash/sha512/ref/hash.c */ 4d059297112922cabb0c674840589be8db821fd9aAdam Langley 5d059297112922cabb0c674840589be8db821fd9aAdam Langley/* 6d059297112922cabb0c674840589be8db821fd9aAdam Langley20080913 7d059297112922cabb0c674840589be8db821fd9aAdam LangleyD. J. Bernstein 8d059297112922cabb0c674840589be8db821fd9aAdam LangleyPublic domain. 9d059297112922cabb0c674840589be8db821fd9aAdam Langley*/ 10d059297112922cabb0c674840589be8db821fd9aAdam Langley 11d059297112922cabb0c674840589be8db821fd9aAdam Langley#include "includes.h" 12d059297112922cabb0c674840589be8db821fd9aAdam Langley 13d059297112922cabb0c674840589be8db821fd9aAdam Langley#include "crypto_api.h" 14d059297112922cabb0c674840589be8db821fd9aAdam Langley 15d059297112922cabb0c674840589be8db821fd9aAdam Langley#define blocks crypto_hashblocks_sha512 16d059297112922cabb0c674840589be8db821fd9aAdam Langley 17d059297112922cabb0c674840589be8db821fd9aAdam Langleystatic const unsigned char iv[64] = { 18d059297112922cabb0c674840589be8db821fd9aAdam Langley 0x6a,0x09,0xe6,0x67,0xf3,0xbc,0xc9,0x08, 19d059297112922cabb0c674840589be8db821fd9aAdam Langley 0xbb,0x67,0xae,0x85,0x84,0xca,0xa7,0x3b, 20d059297112922cabb0c674840589be8db821fd9aAdam Langley 0x3c,0x6e,0xf3,0x72,0xfe,0x94,0xf8,0x2b, 21d059297112922cabb0c674840589be8db821fd9aAdam Langley 0xa5,0x4f,0xf5,0x3a,0x5f,0x1d,0x36,0xf1, 22d059297112922cabb0c674840589be8db821fd9aAdam Langley 0x51,0x0e,0x52,0x7f,0xad,0xe6,0x82,0xd1, 23d059297112922cabb0c674840589be8db821fd9aAdam Langley 0x9b,0x05,0x68,0x8c,0x2b,0x3e,0x6c,0x1f, 24d059297112922cabb0c674840589be8db821fd9aAdam Langley 0x1f,0x83,0xd9,0xab,0xfb,0x41,0xbd,0x6b, 25d059297112922cabb0c674840589be8db821fd9aAdam Langley 0x5b,0xe0,0xcd,0x19,0x13,0x7e,0x21,0x79 26d059297112922cabb0c674840589be8db821fd9aAdam Langley} ; 27d059297112922cabb0c674840589be8db821fd9aAdam Langley 28d059297112922cabb0c674840589be8db821fd9aAdam Langleytypedef unsigned long long uint64; 29d059297112922cabb0c674840589be8db821fd9aAdam Langley 30d059297112922cabb0c674840589be8db821fd9aAdam Langleyint crypto_hash_sha512(unsigned char *out,const unsigned char *in,unsigned long long inlen) 31d059297112922cabb0c674840589be8db821fd9aAdam Langley{ 32d059297112922cabb0c674840589be8db821fd9aAdam Langley unsigned char h[64]; 33d059297112922cabb0c674840589be8db821fd9aAdam Langley unsigned char padded[256]; 34d059297112922cabb0c674840589be8db821fd9aAdam Langley unsigned int i; 35d059297112922cabb0c674840589be8db821fd9aAdam Langley unsigned long long bytes = inlen; 36d059297112922cabb0c674840589be8db821fd9aAdam Langley 37d059297112922cabb0c674840589be8db821fd9aAdam Langley for (i = 0;i < 64;++i) h[i] = iv[i]; 38d059297112922cabb0c674840589be8db821fd9aAdam Langley 39d059297112922cabb0c674840589be8db821fd9aAdam Langley blocks(h,in,inlen); 40d059297112922cabb0c674840589be8db821fd9aAdam Langley in += inlen; 41d059297112922cabb0c674840589be8db821fd9aAdam Langley inlen &= 127; 42d059297112922cabb0c674840589be8db821fd9aAdam Langley in -= inlen; 43d059297112922cabb0c674840589be8db821fd9aAdam Langley 44d059297112922cabb0c674840589be8db821fd9aAdam Langley for (i = 0;i < inlen;++i) padded[i] = in[i]; 45d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[inlen] = 0x80; 46d059297112922cabb0c674840589be8db821fd9aAdam Langley 47d059297112922cabb0c674840589be8db821fd9aAdam Langley if (inlen < 112) { 48d059297112922cabb0c674840589be8db821fd9aAdam Langley for (i = inlen + 1;i < 119;++i) padded[i] = 0; 49d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[119] = bytes >> 61; 50d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[120] = bytes >> 53; 51d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[121] = bytes >> 45; 52d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[122] = bytes >> 37; 53d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[123] = bytes >> 29; 54d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[124] = bytes >> 21; 55d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[125] = bytes >> 13; 56d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[126] = bytes >> 5; 57d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[127] = bytes << 3; 58d059297112922cabb0c674840589be8db821fd9aAdam Langley blocks(h,padded,128); 59d059297112922cabb0c674840589be8db821fd9aAdam Langley } else { 60d059297112922cabb0c674840589be8db821fd9aAdam Langley for (i = inlen + 1;i < 247;++i) padded[i] = 0; 61d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[247] = bytes >> 61; 62d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[248] = bytes >> 53; 63d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[249] = bytes >> 45; 64d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[250] = bytes >> 37; 65d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[251] = bytes >> 29; 66d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[252] = bytes >> 21; 67d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[253] = bytes >> 13; 68d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[254] = bytes >> 5; 69d059297112922cabb0c674840589be8db821fd9aAdam Langley padded[255] = bytes << 3; 70d059297112922cabb0c674840589be8db821fd9aAdam Langley blocks(h,padded,256); 71d059297112922cabb0c674840589be8db821fd9aAdam Langley } 72d059297112922cabb0c674840589be8db821fd9aAdam Langley 73d059297112922cabb0c674840589be8db821fd9aAdam Langley for (i = 0;i < 64;++i) out[i] = h[i]; 74d059297112922cabb0c674840589be8db821fd9aAdam Langley 75d059297112922cabb0c674840589be8db821fd9aAdam Langley return 0; 76d059297112922cabb0c674840589be8db821fd9aAdam Langley} 77