Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
tpruvot
GitHub Repository: tpruvot/cpuminer-multi
Path: blob/linux/scryptjane/scrypt-jane-hash_blake256.h
1201 views
1
#define SCRYPT_HASH "BLAKE-256"
2
#define SCRYPT_HASH_BLOCK_SIZE 64
3
#define SCRYPT_HASH_DIGEST_SIZE 32
4
5
typedef uint8_t scrypt_hash_digest[SCRYPT_HASH_DIGEST_SIZE];
6
7
const uint8_t blake256_sigma[] = {
8
0, 1, 2, 3, 4, 5, 6, 7, 8, 9,10,11,12,13,14,15,
9
14,10, 4, 8, 9,15,13, 6, 1,12, 0, 2,11, 7, 5, 3,
10
11, 8,12, 0, 5, 2,15,13,10,14, 3, 6, 7, 1, 9, 4,
11
7, 9, 3, 1,13,12,11,14, 2, 6, 5,10, 4, 0,15, 8,
12
9, 0, 5, 7, 2, 4,10,15,14, 1,11,12, 6, 8, 3,13,
13
2,12, 6,10, 0,11, 8, 3, 4,13, 7, 5,15,14, 1, 9,
14
12, 5, 1,15,14,13, 4,10, 0, 7, 6, 3, 9, 2, 8,11,
15
13,11, 7,14,12, 1, 3, 9, 5, 0,15, 4, 8, 6, 2,10,
16
6,15,14, 9,11, 3, 0, 8,12, 2,13, 7, 1, 4,10, 5,
17
10, 2, 8, 4, 7, 6, 1, 5,15,11, 9,14, 3,12,13 ,0,
18
};
19
20
const uint32_t blake256_constants[16] = {
21
0x243f6a88, 0x85a308d3, 0x13198a2e, 0x03707344,0xa4093822, 0x299f31d0, 0x082efa98, 0xec4e6c89,
22
0x452821e6, 0x38d01377, 0xbe5466cf, 0x34e90c6c,0xc0ac29b7, 0xc97c50dd, 0x3f84d5b5, 0xb5470917
23
};
24
25
typedef struct scrypt_hash_state_t {
26
uint32_t H[8], T[2];
27
uint32_t leftover;
28
uint8_t buffer[SCRYPT_HASH_BLOCK_SIZE];
29
} scrypt_hash_state;
30
31
static void
32
blake256_blocks(scrypt_hash_state *S, const uint8_t *in, size_t blocks) {
33
const uint8_t *sigma, *sigma_end = blake256_sigma + (10 * 16);
34
uint32_t m[16], v[16], h[8], t[2];
35
uint32_t i;
36
37
for (i = 0; i < 8; i++) h[i] = S->H[i];
38
for (i = 0; i < 2; i++) t[i] = S->T[i];
39
40
while (blocks--) {
41
t[0] += 512;
42
t[1] += (t[0] < 512) ? 1 : 0;
43
44
for (i = 0; i < 8; i++) v[i ] = h[i];
45
for (i = 0; i < 4; i++) v[i + 8] = blake256_constants[i];
46
for (i = 0; i < 2; i++) v[i + 12] = blake256_constants[i+4] ^ t[0];
47
for (i = 0; i < 2; i++) v[i + 14] = blake256_constants[i+6] ^ t[1];
48
49
for (i = 0; i < 16; i++) m[i] = U8TO32_BE(&in[i * 4]);
50
in += 64;
51
52
#define G(a,b,c,d,e) \
53
v[a] += (m[sigma[e+0]] ^ blake256_constants[sigma[e+1]]) + v[b]; \
54
v[d] = ROTR32(v[d] ^ v[a],16); \
55
v[c] += v[d]; \
56
v[b] = ROTR32(v[b] ^ v[c],12); \
57
v[a] += (m[sigma[e+1]] ^ blake256_constants[sigma[e+0]]) + v[b]; \
58
v[d] = ROTR32(v[d] ^ v[a], 8); \
59
v[c] += v[d]; \
60
v[b] = ROTR32(v[b] ^ v[c], 7);
61
62
for (i = 0, sigma = blake256_sigma; i < 14; i++) {
63
G(0, 4, 8,12, 0);
64
G(1, 5, 9,13, 2);
65
G(2, 6,10,14, 4);
66
G(3, 7,11,15, 6);
67
68
G(0, 5,10,15, 8);
69
G(1, 6,11,12,10);
70
G(2, 7, 8,13,12);
71
G(3, 4, 9,14,14);
72
73
sigma += 16;
74
if (sigma == sigma_end)
75
sigma = blake256_sigma;
76
}
77
78
#undef G
79
80
for (i = 0; i < 8; i++) h[i] ^= (v[i] ^ v[i + 8]);
81
}
82
83
for (i = 0; i < 8; i++) S->H[i] = h[i];
84
for (i = 0; i < 2; i++) S->T[i] = t[i];
85
}
86
87
static void
88
scrypt_hash_init(scrypt_hash_state *S) {
89
S->H[0] = 0x6a09e667ULL;
90
S->H[1] = 0xbb67ae85ULL;
91
S->H[2] = 0x3c6ef372ULL;
92
S->H[3] = 0xa54ff53aULL;
93
S->H[4] = 0x510e527fULL;
94
S->H[5] = 0x9b05688cULL;
95
S->H[6] = 0x1f83d9abULL;
96
S->H[7] = 0x5be0cd19ULL;
97
S->T[0] = 0;
98
S->T[1] = 0;
99
S->leftover = 0;
100
}
101
102
static void
103
scrypt_hash_update(scrypt_hash_state *S, const uint8_t *in, size_t inlen) {
104
size_t blocks, want;
105
106
/* handle the previous data */
107
if (S->leftover) {
108
want = (SCRYPT_HASH_BLOCK_SIZE - S->leftover);
109
want = (want < inlen) ? want : inlen;
110
memcpy(S->buffer + S->leftover, in, want);
111
S->leftover += (uint32_t)want;
112
if (S->leftover < SCRYPT_HASH_BLOCK_SIZE)
113
return;
114
in += want;
115
inlen -= want;
116
blake256_blocks(S, S->buffer, 1);
117
}
118
119
/* handle the current data */
120
blocks = (inlen & ~(SCRYPT_HASH_BLOCK_SIZE - 1));
121
S->leftover = (uint32_t)(inlen - blocks);
122
if (blocks) {
123
blake256_blocks(S, in, blocks / SCRYPT_HASH_BLOCK_SIZE);
124
in += blocks;
125
}
126
127
/* handle leftover data */
128
if (S->leftover)
129
memcpy(S->buffer, in, S->leftover);
130
}
131
132
static void
133
scrypt_hash_finish(scrypt_hash_state *S, uint8_t *hash) {
134
uint32_t th, tl, bits;
135
136
bits = (S->leftover << 3);
137
tl = S->T[0] + bits;
138
th = S->T[1];
139
if (S->leftover == 0) {
140
S->T[0] = (uint32_t)0 - (uint32_t)512;
141
S->T[1] = (uint32_t)0 - (uint32_t)1;
142
} else if (S->T[0] == 0) {
143
S->T[0] = ((uint32_t)0 - (uint32_t)512) + bits;
144
S->T[1] = S->T[1] - 1;
145
} else {
146
S->T[0] -= (512 - bits);
147
}
148
149
S->buffer[S->leftover] = 0x80;
150
if (S->leftover <= 55) {
151
memset(S->buffer + S->leftover + 1, 0, 55 - S->leftover);
152
} else {
153
memset(S->buffer + S->leftover + 1, 0, 63 - S->leftover);
154
blake256_blocks(S, S->buffer, 1);
155
S->T[0] = (uint32_t)0 - (uint32_t)512;
156
S->T[1] = (uint32_t)0 - (uint32_t)1;
157
memset(S->buffer, 0, 56);
158
}
159
S->buffer[55] |= 1;
160
U32TO8_BE(S->buffer + 56, th);
161
U32TO8_BE(S->buffer + 60, tl);
162
blake256_blocks(S, S->buffer, 1);
163
164
U32TO8_BE(&hash[ 0], S->H[0]);
165
U32TO8_BE(&hash[ 4], S->H[1]);
166
U32TO8_BE(&hash[ 8], S->H[2]);
167
U32TO8_BE(&hash[12], S->H[3]);
168
U32TO8_BE(&hash[16], S->H[4]);
169
U32TO8_BE(&hash[20], S->H[5]);
170
U32TO8_BE(&hash[24], S->H[6]);
171
U32TO8_BE(&hash[28], S->H[7]);
172
}
173
174
static const uint8_t scrypt_test_hash_expected[SCRYPT_HASH_DIGEST_SIZE] = {
175
0xcc,0xa9,0x1e,0xa9,0x20,0x97,0x37,0x40,0x17,0xc0,0xa0,0x52,0x87,0xfc,0x08,0x20,
176
0x40,0xf5,0x81,0x86,0x62,0x75,0x78,0xb2,0x79,0xce,0xde,0x27,0x3c,0x7f,0x85,0xd8,
177
};
178
179