Barretenberg
The ZK-SNARK library at the core of Aztec
Loading...
Searching...
No Matches
blake3s.hpp
Go to the documentation of this file.
1// === AUDIT STATUS ===
2// internal: { status: not started, auditors: [], date: YYYY-MM-DD }
3// external_1: { status: not started, auditors: [], date: YYYY-MM-DD }
4// external_2: { status: not started, auditors: [], date: YYYY-MM-DD }
5// =====================
6
7#pragma once
8/*
9 BLAKE3 reference source code package - C implementations
10
11 Intellectual property:
12
13 The Rust code is copyright Jack O'Connor, 2019-2020.
14 The C code is copyright Samuel Neves and Jack O'Connor, 2019-2020.
15 The assembly code is copyright Samuel Neves, 2019-2020.
16
17 This work is released into the public domain with CC0 1.0. Alternatively, it is licensed under the Apache
18 License 2.0.
19
20 - CC0 1.0 Universal : http://creativecommons.org/publicdomain/zero/1.0
21 - Apache 2.0 : http://www.apache.org/licenses/LICENSE-2.0
22
23 More information about the BLAKE3 hash function can be found at
24 https://github.com/BLAKE3-team/BLAKE3.
25*/
26
27#include <stddef.h>
28#include <stdint.h>
29#include <vector>
30
31namespace blake3_full {
32
33#define BLAKE3_VERSION_STRING "0.3.7"
34
35// internal flags
37 CHUNK_START = 1 << 0,
38 CHUNK_END = 1 << 1,
39 PARENT = 1 << 2,
40 ROOT = 1 << 3,
41 KEYED_HASH = 1 << 4,
44};
45
46// constants
54
55// modes
57
58static const uint32_t IV[8] = { 0x6A09E667UL, 0xBB67AE85UL, 0x3C6EF372UL, 0xA54FF53AUL,
59 0x510E527FUL, 0x9B05688CUL, 0x1F83D9ABUL, 0x5BE0CD19UL };
60
61static const uint8_t MSG_SCHEDULE[7][16] = {
62 { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15 }, { 2, 6, 3, 10, 7, 0, 4, 13, 1, 11, 12, 5, 9, 14, 15, 8 },
63 { 3, 4, 10, 12, 13, 2, 7, 14, 6, 5, 9, 0, 11, 15, 8, 1 }, { 10, 7, 12, 9, 14, 3, 13, 15, 4, 0, 11, 2, 5, 8, 1, 6 },
64 { 12, 13, 9, 11, 15, 10, 14, 8, 7, 2, 5, 3, 0, 1, 6, 4 }, { 9, 14, 11, 5, 8, 12, 15, 1, 13, 3, 0, 10, 2, 6, 4, 7 },
65 { 11, 15, 5, 0, 1, 9, 8, 6, 14, 10, 2, 12, 3, 4, 7, 13 },
66};
67
68// This struct is a private implementation detail. It has to be here because
69// it's part of blake3_hasher below.
70typedef struct blake3_chunk_state__ {
71 uint32_t cv[8];
72 uint64_t chunk_counter;
74 uint8_t buf_len;
76 uint8_t flags;
78
79typedef struct blake3_hasher__ {
80 uint32_t key[8];
82 uint8_t cv_stack_len;
83 // The stack size is MAX_DEPTH + 1 because we do lazy merging. For example,
84 // with 7 chunks, we have 3 entries in the stack. Adding an 8th chunk
85 // requires a 4th entry, rather than merging everything down to 1, because we
86 // don't know whether more input is coming. This is different from how the
87 // reference implementation does things.
90
91const char* blake3_version(void);
94
96void blake3_hasher_init_derive_key_raw(blake3_hasher* self, const void* context, size_t context_len);
97
98void blake3_hasher_update(blake3_hasher* self, const void* input, size_t input_len);
99void blake3_hasher_finalize(const blake3_hasher* self, uint8_t* out, size_t out_len);
100void blake3_hasher_finalize_seek(const blake3_hasher* self, uint64_t seek, uint8_t* out, size_t out_len);
101
102void g(uint32_t* state, size_t a, size_t b, size_t c, size_t d, uint32_t x, uint32_t y);
103void round_fn(uint32_t state[16], const uint32_t* msg, size_t round);
104
105void compress_pre(uint32_t state[16],
106 const uint32_t cv[8],
107 const uint8_t block[BLAKE3_BLOCK_LEN],
108 uint8_t block_len,
109 uint64_t counter,
110 uint8_t flags);
111
113 uint32_t cv[8], const uint8_t block[BLAKE3_BLOCK_LEN], uint8_t block_len, uint64_t counter, uint8_t flags);
114
115void blake3_compress_xof(const uint32_t cv[8],
116 const uint8_t block[BLAKE3_BLOCK_LEN],
117 uint8_t block_len,
118 uint64_t counter,
119 uint8_t flags,
120 uint8_t out[64]);
121
122void blak3s_hash_one(const uint8_t* input,
123 size_t blocks,
124 const uint32_t key[8],
125 uint64_t counter,
126 uint8_t flags,
127 uint8_t flags_start,
128 uint8_t flags_end,
129 uint8_t out[BLAKE3_OUT_LEN]);
130
131void blake3_hash_many(const uint8_t* const* inputs,
132 size_t num_inputs,
133 size_t blocks,
134 const uint32_t key[8],
135 uint64_t counter,
136 bool increment_counter,
137 uint8_t flags,
138 uint8_t flags_start,
139 uint8_t flags_end,
140 uint8_t* out);
141
142std::vector<uint8_t> blake3s(std::vector<uint8_t> const& input,
143 const mode mode_id = HASH_MODE,
144 const uint8_t key[BLAKE3_KEY_LEN] = nullptr,
145 const char* context = nullptr);
146
147} // namespace blake3_full
StrictMock< MockContext > context
FF a
FF b
void blake3_hasher_init_derive_key_raw(blake3_hasher *self, const void *context, size_t context_len)
Definition blake3s.cpp:449
@ DERIVE_KEY_MATERIAL
Definition blake3s.hpp:43
@ DERIVE_KEY_CONTEXT
Definition blake3s.hpp:42
void blake3_hasher_init_keyed(blake3_hasher *self, const uint8_t key[BLAKE3_KEY_LEN])
Definition blake3s.cpp:442
struct blake3_full::blake3_chunk_state__ blake3_chunk_state
@ DERIVE_KEY_MODE
Definition blake3s.hpp:56
@ KEYED_HASH_MODE
Definition blake3s.hpp:56
void blake3_hasher_finalize_seek(const blake3_hasher *self, uint64_t seek, uint8_t *out, size_t out_len)
Definition blake3s.cpp:641
const char * blake3_version(void)
Definition blake3s.cpp:35
void blake3_hasher_init_derive_key(blake3_hasher *self, const char *context)
Definition blake3s.cpp:461
void blake3_hasher_update(blake3_hasher *self, const void *input, size_t input_len)
Definition blake3s.cpp:529
@ BLAKE3_CHUNK_LEN
Definition blake3s.hpp:51
@ BLAKE3_MAX_DEPTH
Definition blake3s.hpp:52
@ BLAKE3_BLOCK_LEN
Definition blake3s.hpp:50
std::vector< uint8_t > blake3s(std::vector< uint8_t > const &input, const mode mode_id, const uint8_t key[BLAKE3_KEY_LEN], const char *context)
Definition blake3s.cpp:860
void round_fn(uint32_t state[16], const uint32_t *msg, size_t round)
Definition blake3s.cpp:699
void blake3_compress_xof(const uint32_t cv[8], const uint8_t block[BLAKE3_BLOCK_LEN], uint8_t block_len, uint64_t counter, uint8_t flags, uint8_t out[64])
Definition blake3s.cpp:783
struct blake3_full::blake3_hasher__ blake3_hasher
void g(uint32_t *state, size_t a, size_t b, size_t c, size_t d, uint32_t x, uint32_t y)
Definition blake3s.cpp:687
void blake3_hasher_finalize(const blake3_hasher *self, uint8_t *out, size_t out_len)
Definition blake3s.cpp:636
void blake3_hasher_init(blake3_hasher *self)
Definition blake3s.cpp:437
void blak3s_hash_one(const uint8_t *input, size_t blocks, const uint32_t key[8], uint64_t counter, uint8_t flags, uint8_t flags_start, uint8_t flags_end, uint8_t out[BLAKE3_OUT_LEN])
void blake3_hash_many(const uint8_t *const *inputs, size_t num_inputs, size_t blocks, const uint32_t key[8], uint64_t counter, bool increment_counter, uint8_t flags, uint8_t flags_start, uint8_t flags_end, uint8_t *out)
Definition blake3s.cpp:838
void blake3_compress_in_place(uint32_t cv[8], const uint8_t block[BLAKE3_BLOCK_LEN], uint8_t block_len, uint64_t counter, uint8_t flags)
Definition blake3s.cpp:768
void compress_pre(uint32_t state[16], const uint32_t cv[8], const uint8_t block[BLAKE3_BLOCK_LEN], uint8_t block_len, uint64_t counter, uint8_t flags)
Definition blake3s.cpp:717
uint8_t buf[BLAKE3_BLOCK_LEN]
Definition blake3s.hpp:73
blake3_chunk_state chunk
Definition blake3s.hpp:81
uint8_t cv_stack[(BLAKE3_MAX_DEPTH+1) *BLAKE3_OUT_LEN]
Definition blake3s.hpp:88