1  | 
     | 
     | 
    /* $OpenBSD: chacha.c,v 1.7 2015/12/09 14:07:55 bcook Exp $ */  | 
    
    
    2  | 
     | 
     | 
    /*  | 
    
    
    3  | 
     | 
     | 
     * Copyright (c) 2014 Joel Sing <jsing@openbsd.org>  | 
    
    
    4  | 
     | 
     | 
     *  | 
    
    
    5  | 
     | 
     | 
     * Permission to use, copy, modify, and distribute this software for any  | 
    
    
    6  | 
     | 
     | 
     * purpose with or without fee is hereby granted, provided that the above  | 
    
    
    7  | 
     | 
     | 
     * copyright notice and this permission notice appear in all copies.  | 
    
    
    8  | 
     | 
     | 
     *  | 
    
    
    9  | 
     | 
     | 
     * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES  | 
    
    
    10  | 
     | 
     | 
     * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF  | 
    
    
    11  | 
     | 
     | 
     * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR  | 
    
    
    12  | 
     | 
     | 
     * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES  | 
    
    
    13  | 
     | 
     | 
     * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN  | 
    
    
    14  | 
     | 
     | 
     * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF  | 
    
    
    15  | 
     | 
     | 
     * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.  | 
    
    
    16  | 
     | 
     | 
     */  | 
    
    
    17  | 
     | 
     | 
     | 
    
    
    18  | 
     | 
     | 
    #include <stdint.h>  | 
    
    
    19  | 
     | 
     | 
     | 
    
    
    20  | 
     | 
     | 
    #include <openssl/chacha.h>  | 
    
    
    21  | 
     | 
     | 
     | 
    
    
    22  | 
     | 
     | 
    #include "chacha-merged.c"  | 
    
    
    23  | 
     | 
     | 
     | 
    
    
    24  | 
     | 
     | 
    void  | 
    
    
    25  | 
     | 
     | 
    ChaCha_set_key(ChaCha_ctx *ctx, const unsigned char *key, uint32_t keybits)  | 
    
    
    26  | 
     | 
     | 
    { | 
    
    
    27  | 
     | 
    200  | 
    	chacha_keysetup((chacha_ctx *)ctx, key, keybits);  | 
    
    
    28  | 
     | 
    100  | 
    	ctx->unused = 0;  | 
    
    
    29  | 
     | 
    100  | 
    }  | 
    
    
    30  | 
     | 
     | 
     | 
    
    
    31  | 
     | 
     | 
    void  | 
    
    
    32  | 
     | 
     | 
    ChaCha_set_iv(ChaCha_ctx *ctx, const unsigned char *iv,  | 
    
    
    33  | 
     | 
     | 
        const unsigned char *counter)  | 
    
    
    34  | 
     | 
     | 
    { | 
    
    
    35  | 
     | 
    200  | 
    	chacha_ivsetup((chacha_ctx *)ctx, iv, counter);  | 
    
    
    36  | 
     | 
    100  | 
    	ctx->unused = 0;  | 
    
    
    37  | 
     | 
    100  | 
    }  | 
    
    
    38  | 
     | 
     | 
     | 
    
    
    39  | 
     | 
     | 
    void  | 
    
    
    40  | 
     | 
     | 
    ChaCha(ChaCha_ctx *ctx, unsigned char *out, const unsigned char *in, size_t len)  | 
    
    
    41  | 
     | 
     | 
    { | 
    
    
    42  | 
     | 
     | 
    	unsigned char *k;  | 
    
    
    43  | 
     | 
     | 
    	int i, l;  | 
    
    
    44  | 
     | 
     | 
     | 
    
    
    45  | 
     | 
     | 
    	/* Consume remaining keystream, if any exists. */  | 
    
    
    46  | 
    ✓✓ | 
    3512  | 
    	if (ctx->unused > 0) { | 
    
    
    47  | 
     | 
    1656  | 
    		k = ctx->ks + 64 - ctx->unused;  | 
    
    
    48  | 
    ✗✓ | 
    4968  | 
    		l = (len > ctx->unused) ? ctx->unused : len;  | 
    
    
    49  | 
    ✓✓ | 
    7920  | 
    		for (i = 0; i < l; i++)  | 
    
    
    50  | 
     | 
    2304  | 
    			*(out++) = *(in++) ^ *(k++);  | 
    
    
    51  | 
     | 
    1656  | 
    		ctx->unused -= l;  | 
    
    
    52  | 
     | 
    1656  | 
    		len -= l;  | 
    
    
    53  | 
     | 
    1656  | 
    	}  | 
    
    
    54  | 
     | 
     | 
     | 
    
    
    55  | 
     | 
    1756  | 
    	chacha_encrypt_bytes((chacha_ctx *)ctx, in, out, (uint32_t)len);  | 
    
    
    56  | 
     | 
    1756  | 
    }  | 
    
    
    57  | 
     | 
     | 
     | 
    
    
    58  | 
     | 
     | 
    void  | 
    
    
    59  | 
     | 
     | 
    CRYPTO_chacha_20(unsigned char *out, const unsigned char *in, size_t len,  | 
    
    
    60  | 
     | 
     | 
        const unsigned char key[32], const unsigned char iv[8], uint64_t counter)  | 
    
    
    61  | 
     | 
     | 
    { | 
    
    
    62  | 
     | 
    408  | 
    	struct chacha_ctx ctx;  | 
    
    
    63  | 
     | 
     | 
     | 
    
    
    64  | 
     | 
     | 
    	/*  | 
    
    
    65  | 
     | 
     | 
    	 * chacha_ivsetup expects the counter to be in u8. Rather than  | 
    
    
    66  | 
     | 
     | 
    	 * converting size_t to u8 and then back again, pass a counter of  | 
    
    
    67  | 
     | 
     | 
    	 * NULL and manually assign it afterwards.  | 
    
    
    68  | 
     | 
     | 
    	 */  | 
    
    
    69  | 
     | 
    204  | 
    	chacha_keysetup(&ctx, key, 256);  | 
    
    
    70  | 
     | 
    204  | 
    	chacha_ivsetup(&ctx, iv, NULL);  | 
    
    
    71  | 
    ✓✓ | 
    204  | 
    	if (counter != 0) { | 
    
    
    72  | 
     | 
    171  | 
    		ctx.input[12] = (uint32_t)counter;  | 
    
    
    73  | 
     | 
    171  | 
    		ctx.input[13] = (uint32_t)(counter >> 32);  | 
    
    
    74  | 
     | 
    171  | 
    	}  | 
    
    
    75  | 
     | 
     | 
     | 
    
    
    76  | 
     | 
    204  | 
    	chacha_encrypt_bytes(&ctx, in, out, (uint32_t)len);  | 
    
    
    77  | 
     | 
    204  | 
    }  |