gitea

Development moved to Codeberg

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12
  13. 13
  14. 14
  15. 15
  16. 16
  17. 17
  18. 18
  19. 19
  20. 20
  21. 21
  22. 22
  23. 23
  24. 24
  25. 25
  26. 26
  27. 27
  28. 28
  29. 29
  30. 30
  31. 31
  32. 32
  33. 33
  34. 34
  35. 35
  36. 36
  37. 37
  38. 38
  39. 39
  40. 40
  41. 41
  42. 42
  43. 43
  44. 44
  45. 45
  46. 46
  47. 47
  48. 48
  49. 49
  50. 50
  51. 51
  52. 52
  53. 53
  54. 54
  55. 55
  56. 56
  57. 57
  58. 58
  59. 59
  60. 60
  61. 61
  62. 62
  63. 63
  64. 64
  65. 65
  66. 66
  67. 67
  68. 68
  69. 69
  70. 70
  71. 71
  72. 72
  73. 73
  74. 74
  75. 75
  76. 76
  77. 77
  78. 78
  79. 79
  80. 80
  81. 81
  82. 82
  83. 83
  84. 84
  85. 85
  86. 86
  87. 87
  88. 88
  89. 89
  90. 90
  91. 91
  92. 92
  93. 93
  94. 94
  95. 95
  96. 96
  97. 97
  98. 98
  99. 99
  100. 100
  101. 101
  102. 102
  103. 103
  104. 104
  105. 105
  106. 106
  107. 107
  108. 108
  109. 109
  110. 110
  111. 111
  112. 112
  113. 113
  114. 114
  115. 115
  116. 116
  117. 117
  118. 118
  119. 119
  120. 120
  121. 121
  122. 122
  123. 123
  124. 124
package curve25519

import (
	"crypto/elliptic"
	"math/big"
	"sync"
)

var cv25519 cv25519Curve

type cv25519Curve struct {
	*elliptic.CurveParams
}

func copyReverse(dst []byte, src []byte) {
	// Curve 25519 multiplication functions expect scalars in reverse
	// order than PGP. To keep the curve25519Curve type consistent
	// with other curves, we reverse it here.
	for i, j := 0, len(src)-1; j >= 0 && i < len(dst); i, j = i+1, j-1 {
		dst[i] = src[j]
	}
}

func copyTruncate(dst []byte, src []byte) {
	lenDst, lenSrc := len(dst), len(src)
	if lenDst == lenSrc {
		copy(dst, src)
	} else if lenDst > lenSrc {
		copy(dst[lenDst-lenSrc:lenDst], src)
	} else if lenDst < lenSrc {
		copy(dst, src[:lenDst])
	}
}

func (cv25519Curve) ScalarMult(x1, y1 *big.Int, scalar []byte) (x, y *big.Int) {
	// Assume y1 is 0 with cv25519.
	var dst [32]byte
	var x1Bytes [32]byte
	var scalarBytes [32]byte

	copyTruncate(x1Bytes[:], x1.Bytes())
	copyReverse(scalarBytes[:], scalar)

	scalarMult(&dst, &scalarBytes, &x1Bytes)

	x = new(big.Int).SetBytes(dst[:])
	y = new(big.Int)
	return x, y
}

func (cv25519Curve) ScalarBaseMult(scalar []byte) (x, y *big.Int) {
	var dst [32]byte
	var scalarBytes [32]byte
	copyReverse(scalarBytes[:], scalar[:32])
	scalarMult(&dst, &scalarBytes, &basePoint)
	x = new(big.Int).SetBytes(dst[:])
	y = new(big.Int)
	return x, y
}

func (cv25519Curve) IsOnCurve(bigX, bigY *big.Int) bool {
	return bigY.Sign() == 0 // bigY == 0 ?
}

// More information about 0x40 point format:
// https://tools.ietf.org/html/draft-koch-eddsa-for-openpgp-00#section-3
// In addition to uncompressed point format described here:
// https://tools.ietf.org/html/rfc6637#section-6

func (cv25519Curve) MarshalType40(x, y *big.Int) []byte {
	byteLen := 32

	ret := make([]byte, 1+byteLen)
	ret[0] = 0x40

	xBytes := x.Bytes()
	copyTruncate(ret[1:], xBytes)
	return ret
}

func (cv25519Curve) UnmarshalType40(data []byte) (x, y *big.Int) {
	if len(data) != 1+32 {
		return nil, nil
	}
	if data[0] != 0x40 {
		return nil, nil
	}
	x = new(big.Int).SetBytes(data[1:])
	// Any x is a valid curve point.
	return x, new(big.Int)
}

// ToCurve25519 casts given elliptic.Curve type to Curve25519 type, or
// returns nil, false if cast was unsuccessful.
func ToCurve25519(cv elliptic.Curve) (cv25519Curve, bool) {
	cv2, ok := cv.(cv25519Curve)
	return cv2, ok
}

func initCv25519() {
	cv25519.CurveParams = &elliptic.CurveParams{Name: "Curve 25519"}
	// Some code relies on these parameters being available for
	// checking Curve coordinate length. They should not be used
	// directly for any calculations.
	cv25519.P, _ = new(big.Int).SetString("7fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffed", 16)
	cv25519.N, _ = new(big.Int).SetString("1000000000000000000000000000000014def9dea2f79cd65812631a5cf5d3ed", 16)
	cv25519.Gx, _ = new(big.Int).SetString("9", 16)
	cv25519.Gy, _ = new(big.Int).SetString("20ae19a1b8a086b4e01edd2c7748d14c923d4d7e6d7c61b229e9c5a27eced3d9", 16)
	cv25519.BitSize = 256
}

var initonce sync.Once

// Cv25519 returns a Curve which (partially) implements Cv25519. Only
// ScalarMult and ScalarBaseMult are valid for this curve. Add and
// Double should not be used.
func Cv25519() elliptic.Curve {
	initonce.Do(initCv25519)
	return cv25519
}

func (curve cv25519Curve) Params() *elliptic.CurveParams {
	return curve.CurveParams
}