Coverage Report

Created: 2026-10-06 06:17

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/nss/lib/freebl/sha_fast.c
Line
Count
Source
1
/* This Source Code Form is subject to the terms of the Mozilla Public
2
 * License, v. 2.0. If a copy of the MPL was not distributed with this
3
 * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
4
5
#ifdef FREEBL_NO_DEPEND
6
#include "stubs.h"
7
#endif
8
9
#include <memory.h>
10
#include "blapi.h"
11
#include "sha_fast.h"
12
#include "prerror.h"
13
#include "secerr.h"
14
15
#ifdef TRACING_SSL
16
#include "ssl.h"
17
#include "ssltrace.h"
18
#endif
19
20
static void shaCompress(volatile SHA_HW_t *X, const PRUint32 *datain);
21
22
19.2M
#define W u.w
23
20.7M
#define B u.b
24
25
290M
#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
26
290M
#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
27
290M
#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
28
290M
#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
29
30
928M
#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
31
32
void SHA1_Compress_Native(SHA1Context *ctx);
33
void SHA1_Update_Native(SHA1Context *ctx, const unsigned char *dataIn, unsigned int len);
34
35
static void SHA1_Compress_Generic(SHA1Context *ctx);
36
static void SHA1_Update_Generic(SHA1Context *ctx, const unsigned char *dataIn, unsigned int len);
37
38
#ifndef USE_HW_SHA1
39
void
40
SHA1_Compress_Native(SHA1Context *ctx)
41
0
{
42
0
    PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
43
0
    PORT_Assert(0);
44
0
}
45
46
void
47
SHA1_Update_Native(SHA1Context *ctx, const unsigned char *dataIn, unsigned int len)
48
0
{
49
0
    PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
50
0
    PORT_Assert(0);
51
0
}
52
#endif
53
54
/*
55
 *  SHA: initialize context
56
 */
57
void
58
SHA1_Begin(SHA1Context *ctx)
59
9.53M
{
60
9.53M
    ctx->size = 0;
61
    /*
62
     *  Initialize H with constants from FIPS180-1.
63
     */
64
9.53M
    ctx->H[0] = 0x67452301L;
65
9.53M
    ctx->H[1] = 0xefcdab89L;
66
9.53M
    ctx->H[2] = 0x98badcfeL;
67
9.53M
    ctx->H[3] = 0x10325476L;
68
9.53M
    ctx->H[4] = 0xc3d2e1f0L;
69
70
#if defined(USE_HW_SHA1) && defined(IS_LITTLE_ENDIAN)
71
    /* arm's implementation is tested on little endian only */
72
    if (arm_sha1_support()) {
73
        ctx->compress = SHA1_Compress_Native;
74
        ctx->update = SHA1_Update_Native;
75
    } else
76
#endif
77
9.53M
    {
78
9.53M
        ctx->compress = SHA1_Compress_Generic;
79
9.53M
        ctx->update = SHA1_Update_Generic;
80
9.53M
    }
81
9.53M
}
82
83
/* Explanation of H array and index values:
84
 * The context's H array is actually the concatenation of two arrays
85
 * defined by SHA1, the H array of state variables (5 elements),
86
 * and the W array of intermediate values, of which there are 16 elements.
87
 * The W array starts at H[5], that is W[0] is H[5].
88
 * Although these values are defined as 32-bit values, we use 64-bit
89
 * variables to hold them because the AMD64 stores 64 bit values in
90
 * memory MUCH faster than it stores any smaller values.
91
 *
92
 * Rather than passing the context structure to shaCompress, we pass
93
 * this combined array of H and W values.  We do not pass the address
94
 * of the first element of this array, but rather pass the address of an
95
 * element in the middle of the array, element X.  Presently X[0] is H[11].
96
 * So we pass the address of H[11] as the address of array X to shaCompress.
97
 * Then shaCompress accesses the members of the array using positive AND
98
 * negative indexes.
99
 *
100
 * Pictorially: (each element is 8 bytes)
101
 * H | H0 H1 H2 H3 H4 W0 W1 W2 W3 W4 W5 W6 W7 W8 W9 Wa Wb Wc Wd We Wf |
102
 * X |-11-10 -9 -8 -7 -6 -5 -4 -3 -2 -1 X0 X1 X2 X3 X4 X5 X6 X7 X8 X9 |
103
 *
104
 * The byte offset from X[0] to any member of H and W is always
105
 * representable in a signed 8-bit value, which will be encoded
106
 * as a single byte offset in the X86-64 instruction set.
107
 * If we didn't pass the address of H[11], and instead passed the
108
 * address of H[0], the offsets to elements H[16] and above would be
109
 * greater than 127, not representable in a signed 8-bit value, and the
110
 * x86-64 instruction set would encode every such offset as a 32-bit
111
 * signed number in each instruction that accessed element H[16] or
112
 * higher.  This results in much bigger and slower code.
113
 */
114
#if !defined(SHA_PUT_W_IN_STACK)
115
159M
#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
116
6.03G
#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
117
#else
118
#define H2X 0
119
#endif
120
121
/*
122
 *  SHA: Add data to context.
123
 */
124
void
125
SHA1_Update(SHA1Context *ctx, const unsigned char *dataIn, unsigned int len)
126
22.7M
{
127
22.7M
    ctx->update(ctx, dataIn, len);
128
22.7M
}
129
130
static void
131
SHA1_Update_Generic(SHA1Context *ctx, const unsigned char *dataIn, unsigned int len)
132
22.7M
{
133
22.7M
    register unsigned int lenB;
134
22.7M
    register unsigned int togo;
135
136
22.7M
    if (!len)
137
69.9k
        return;
138
139
    /* accumulate the byte count. */
140
22.6M
    lenB = (unsigned int)(ctx->size) & 63U;
141
142
22.6M
    ctx->size += len;
143
144
    /*
145
     *  Read the data into W and process blocks as they get full
146
     */
147
22.6M
    if (lenB > 0) {
148
10.7M
        togo = 64U - lenB;
149
10.7M
        if (len < togo)
150
10.0M
            togo = len;
151
10.7M
        memcpy(ctx->B + lenB, dataIn, togo);
152
10.7M
        len -= togo;
153
10.7M
        dataIn += togo;
154
10.7M
        lenB = (lenB + togo) & 63U;
155
10.7M
        if (!lenB) {
156
662k
            shaCompress(&ctx->H[H2X], ctx->W);
157
662k
        }
158
10.7M
    }
159
#if !defined(HAVE_UNALIGNED_ACCESS)
160
    if ((ptrdiff_t)dataIn % sizeof(PRUint32)) {
161
        while (len >= 64U) {
162
            memcpy(ctx->B, dataIn, 64);
163
            len -= 64U;
164
            shaCompress(&ctx->H[H2X], ctx->W);
165
            dataIn += 64U;
166
        }
167
    } else
168
#endif
169
22.6M
    {
170
27.1M
        while (len >= 64U) {
171
4.53M
            len -= 64U;
172
4.53M
            shaCompress(&ctx->H[H2X], (PRUint32 *)dataIn);
173
4.53M
            dataIn += 64U;
174
4.53M
        }
175
22.6M
    }
176
22.6M
    if (len) {
177
9.94M
        memcpy(ctx->B, dataIn, len);
178
9.94M
    }
179
22.6M
}
180
181
/*
182
 *  SHA: Generate hash value from context
183
 */
184
void NO_SANITIZE_ALIGNMENT
185
SHA1_End(SHA1Context *ctx, unsigned char *hashout,
186
         unsigned int *pDigestLen, unsigned int maxDigestLen)
187
9.31M
{
188
9.31M
    register PRUint64 size;
189
9.31M
    register PRUint32 lenB;
190
191
9.31M
    static const unsigned char bulk_pad[64] = { 0x80, 0, 0, 0, 0, 0, 0, 0, 0, 0,
192
9.31M
                                                0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
193
9.31M
                                                0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 };
194
9.31M
#define tmp lenB
195
196
9.31M
    PORT_Assert(maxDigestLen >= SHA1_LENGTH);
197
198
    /*
199
     *  Pad with a binary 1 (e.g. 0x80), then zeroes, then length in bits
200
     */
201
9.31M
    size = ctx->size;
202
203
9.31M
    lenB = (PRUint32)size & 63;
204
9.31M
    SHA1_Update(ctx, bulk_pad, (((55 + 64) - lenB) & 63) + 1);
205
9.31M
    PORT_Assert(((PRUint32)ctx->size & 63) == 56);
206
    /* Convert size from bytes to bits. */
207
9.31M
    size <<= 3;
208
9.31M
    ctx->W[14] = SHA_HTONL((PRUint32)(size >> 32));
209
9.31M
    ctx->W[15] = SHA_HTONL((PRUint32)size);
210
9.31M
    ctx->compress(ctx);
211
212
    /*
213
     *  Output hash
214
     */
215
9.31M
    SHA_STORE_RESULT;
216
9.31M
    if (pDigestLen) {
217
9.29M
        *pDigestLen = SHA1_LENGTH;
218
9.29M
    }
219
9.31M
#undef tmp
220
9.31M
}
221
222
void
223
SHA1_EndRaw(SHA1Context *ctx, unsigned char *hashout,
224
            unsigned int *pDigestLen, unsigned int maxDigestLen)
225
122k
{
226
#if defined(SHA_NEED_TMP_VARIABLE)
227
    register PRUint32 tmp;
228
#endif
229
122k
    PORT_Assert(maxDigestLen >= SHA1_LENGTH);
230
231
122k
    SHA_STORE_RESULT;
232
122k
    if (pDigestLen)
233
0
        *pDigestLen = SHA1_LENGTH;
234
122k
}
235
236
#undef B
237
/*
238
 *  SHA: Compression function, unrolled.
239
 *
240
 * Some operations in shaCompress are done as 5 groups of 16 operations.
241
 * Others are done as 4 groups of 20 operations.
242
 * The code below shows that structure.
243
 *
244
 * The functions that compute the new values of the 5 state variables
245
 * A-E are done in 4 groups of 20 operations (or you may also think
246
 * of them as being done in 16 groups of 5 operations).  They are
247
 * done by the SHA_RNDx macros below, in the right column.
248
 *
249
 * The functions that set the 16 values of the W array are done in
250
 * 5 groups of 16 operations.  The first group is done by the
251
 * LOAD macros below, the latter 4 groups are done by SHA_MIX below,
252
 * in the left column.
253
 *
254
 * gcc's optimizer observes that each member of the W array is assigned
255
 * a value 5 times in this code.  It reduces the number of store
256
 * operations done to the W array in the context (that is, in the X array)
257
 * by creating a W array on the stack, and storing the W values there for
258
 * the first 4 groups of operations on W, and storing the values in the
259
 * context's W array only in the fifth group.  This is undesirable.
260
 * It is MUCH bigger code than simply using the context's W array, because
261
 * all the offsets to the W array in the stack are 32-bit signed offsets,
262
 * and it is no faster than storing the values in the context's W array.
263
 *
264
 * The original code for sha_fast.c prevented this creation of a separate
265
 * W array in the stack by creating a W array of 80 members, each of
266
 * whose elements is assigned only once. It also separated the computations
267
 * of the W array values and the computations of the values for the 5
268
 * state variables into two separate passes, W's, then A-E's so that the
269
 * second pass could be done all in registers (except for accessing the W
270
 * array) on machines with fewer registers.  The method is suboptimal
271
 * for machines with enough registers to do it all in one pass, and it
272
 * necessitates using many instructions with 32-bit offsets.
273
 *
274
 * This code eliminates the separate W array on the stack by a completely
275
 * different means: by declaring the X array volatile.  This prevents
276
 * the optimizer from trying to reduce the use of the X array by the
277
 * creation of a MORE expensive W array on the stack. The result is
278
 * that all instructions use signed 8-bit offsets and not 32-bit offsets.
279
 *
280
 * The combination of this code and the -O3 optimizer flag on GCC 3.4.3
281
 * results in code that is 3 times faster than the previous NSS sha_fast
282
 * code on AMD64.
283
 */
284
static void NO_SANITIZE_ALIGNMENT
285
shaCompress(volatile SHA_HW_t *X, const PRUint32 *inbuf)
286
14.5M
{
287
14.5M
    register SHA_HW_t A, B, C, D, E;
288
289
#if defined(SHA_NEED_TMP_VARIABLE)
290
    register PRUint32 tmp;
291
#endif
292
293
14.5M
#if !defined(SHA_PUT_W_IN_STACK)
294
145M
#define XH(n) X[n - H2X]
295
6.03G
#define XW(n) X[n - W2X]
296
#else
297
    SHA_HW_t w_0, w_1, w_2, w_3, w_4, w_5, w_6, w_7,
298
        w_8, w_9, w_10, w_11, w_12, w_13, w_14, w_15;
299
#define XW(n) w_##n
300
#define XH(n) X[n]
301
#endif
302
303
290M
#define K0 0x5a827999L
304
290M
#define K1 0x6ed9eba1L
305
290M
#define K2 0x8f1bbcdcL
306
290M
#define K3 0xca62c1d6L
307
308
14.5M
#define SHA_RND1(a, b, c, d, e, n)                         \
309
290M
    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
310
290M
    c = SHA_ROTL(c, 30)
311
14.5M
#define SHA_RND2(a, b, c, d, e, n)                         \
312
290M
    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
313
290M
    c = SHA_ROTL(c, 30)
314
14.5M
#define SHA_RND3(a, b, c, d, e, n)                         \
315
290M
    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
316
290M
    c = SHA_ROTL(c, 30)
317
14.5M
#define SHA_RND4(a, b, c, d, e, n)                         \
318
290M
    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
319
290M
    c = SHA_ROTL(c, 30)
320
321
232M
#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
322
323
14.5M
    A = XH(0);
324
14.5M
    B = XH(1);
325
14.5M
    C = XH(2);
326
14.5M
    D = XH(3);
327
14.5M
    E = XH(4);
328
329
14.5M
    LOAD(0);
330
14.5M
    SHA_RND1(E, A, B, C, D, 0);
331
14.5M
    LOAD(1);
332
14.5M
    SHA_RND1(D, E, A, B, C, 1);
333
14.5M
    LOAD(2);
334
14.5M
    SHA_RND1(C, D, E, A, B, 2);
335
14.5M
    LOAD(3);
336
14.5M
    SHA_RND1(B, C, D, E, A, 3);
337
14.5M
    LOAD(4);
338
14.5M
    SHA_RND1(A, B, C, D, E, 4);
339
14.5M
    LOAD(5);
340
14.5M
    SHA_RND1(E, A, B, C, D, 5);
341
14.5M
    LOAD(6);
342
14.5M
    SHA_RND1(D, E, A, B, C, 6);
343
14.5M
    LOAD(7);
344
14.5M
    SHA_RND1(C, D, E, A, B, 7);
345
14.5M
    LOAD(8);
346
14.5M
    SHA_RND1(B, C, D, E, A, 8);
347
14.5M
    LOAD(9);
348
14.5M
    SHA_RND1(A, B, C, D, E, 9);
349
14.5M
    LOAD(10);
350
14.5M
    SHA_RND1(E, A, B, C, D, 10);
351
14.5M
    LOAD(11);
352
14.5M
    SHA_RND1(D, E, A, B, C, 11);
353
14.5M
    LOAD(12);
354
14.5M
    SHA_RND1(C, D, E, A, B, 12);
355
14.5M
    LOAD(13);
356
14.5M
    SHA_RND1(B, C, D, E, A, 13);
357
14.5M
    LOAD(14);
358
14.5M
    SHA_RND1(A, B, C, D, E, 14);
359
14.5M
    LOAD(15);
360
14.5M
    SHA_RND1(E, A, B, C, D, 15);
361
362
14.5M
    SHA_MIX(0, 13, 8, 2);
363
14.5M
    SHA_RND1(D, E, A, B, C, 0);
364
14.5M
    SHA_MIX(1, 14, 9, 3);
365
14.5M
    SHA_RND1(C, D, E, A, B, 1);
366
14.5M
    SHA_MIX(2, 15, 10, 4);
367
14.5M
    SHA_RND1(B, C, D, E, A, 2);
368
14.5M
    SHA_MIX(3, 0, 11, 5);
369
14.5M
    SHA_RND1(A, B, C, D, E, 3);
370
371
14.5M
    SHA_MIX(4, 1, 12, 6);
372
14.5M
    SHA_RND2(E, A, B, C, D, 4);
373
14.5M
    SHA_MIX(5, 2, 13, 7);
374
14.5M
    SHA_RND2(D, E, A, B, C, 5);
375
14.5M
    SHA_MIX(6, 3, 14, 8);
376
14.5M
    SHA_RND2(C, D, E, A, B, 6);
377
14.5M
    SHA_MIX(7, 4, 15, 9);
378
14.5M
    SHA_RND2(B, C, D, E, A, 7);
379
14.5M
    SHA_MIX(8, 5, 0, 10);
380
14.5M
    SHA_RND2(A, B, C, D, E, 8);
381
14.5M
    SHA_MIX(9, 6, 1, 11);
382
14.5M
    SHA_RND2(E, A, B, C, D, 9);
383
14.5M
    SHA_MIX(10, 7, 2, 12);
384
14.5M
    SHA_RND2(D, E, A, B, C, 10);
385
14.5M
    SHA_MIX(11, 8, 3, 13);
386
14.5M
    SHA_RND2(C, D, E, A, B, 11);
387
14.5M
    SHA_MIX(12, 9, 4, 14);
388
14.5M
    SHA_RND2(B, C, D, E, A, 12);
389
14.5M
    SHA_MIX(13, 10, 5, 15);
390
14.5M
    SHA_RND2(A, B, C, D, E, 13);
391
14.5M
    SHA_MIX(14, 11, 6, 0);
392
14.5M
    SHA_RND2(E, A, B, C, D, 14);
393
14.5M
    SHA_MIX(15, 12, 7, 1);
394
14.5M
    SHA_RND2(D, E, A, B, C, 15);
395
396
14.5M
    SHA_MIX(0, 13, 8, 2);
397
14.5M
    SHA_RND2(C, D, E, A, B, 0);
398
14.5M
    SHA_MIX(1, 14, 9, 3);
399
14.5M
    SHA_RND2(B, C, D, E, A, 1);
400
14.5M
    SHA_MIX(2, 15, 10, 4);
401
14.5M
    SHA_RND2(A, B, C, D, E, 2);
402
14.5M
    SHA_MIX(3, 0, 11, 5);
403
14.5M
    SHA_RND2(E, A, B, C, D, 3);
404
14.5M
    SHA_MIX(4, 1, 12, 6);
405
14.5M
    SHA_RND2(D, E, A, B, C, 4);
406
14.5M
    SHA_MIX(5, 2, 13, 7);
407
14.5M
    SHA_RND2(C, D, E, A, B, 5);
408
14.5M
    SHA_MIX(6, 3, 14, 8);
409
14.5M
    SHA_RND2(B, C, D, E, A, 6);
410
14.5M
    SHA_MIX(7, 4, 15, 9);
411
14.5M
    SHA_RND2(A, B, C, D, E, 7);
412
413
14.5M
    SHA_MIX(8, 5, 0, 10);
414
14.5M
    SHA_RND3(E, A, B, C, D, 8);
415
14.5M
    SHA_MIX(9, 6, 1, 11);
416
14.5M
    SHA_RND3(D, E, A, B, C, 9);
417
14.5M
    SHA_MIX(10, 7, 2, 12);
418
14.5M
    SHA_RND3(C, D, E, A, B, 10);
419
14.5M
    SHA_MIX(11, 8, 3, 13);
420
14.5M
    SHA_RND3(B, C, D, E, A, 11);
421
14.5M
    SHA_MIX(12, 9, 4, 14);
422
14.5M
    SHA_RND3(A, B, C, D, E, 12);
423
14.5M
    SHA_MIX(13, 10, 5, 15);
424
14.5M
    SHA_RND3(E, A, B, C, D, 13);
425
14.5M
    SHA_MIX(14, 11, 6, 0);
426
14.5M
    SHA_RND3(D, E, A, B, C, 14);
427
14.5M
    SHA_MIX(15, 12, 7, 1);
428
14.5M
    SHA_RND3(C, D, E, A, B, 15);
429
430
14.5M
    SHA_MIX(0, 13, 8, 2);
431
14.5M
    SHA_RND3(B, C, D, E, A, 0);
432
14.5M
    SHA_MIX(1, 14, 9, 3);
433
14.5M
    SHA_RND3(A, B, C, D, E, 1);
434
14.5M
    SHA_MIX(2, 15, 10, 4);
435
14.5M
    SHA_RND3(E, A, B, C, D, 2);
436
14.5M
    SHA_MIX(3, 0, 11, 5);
437
14.5M
    SHA_RND3(D, E, A, B, C, 3);
438
14.5M
    SHA_MIX(4, 1, 12, 6);
439
14.5M
    SHA_RND3(C, D, E, A, B, 4);
440
14.5M
    SHA_MIX(5, 2, 13, 7);
441
14.5M
    SHA_RND3(B, C, D, E, A, 5);
442
14.5M
    SHA_MIX(6, 3, 14, 8);
443
14.5M
    SHA_RND3(A, B, C, D, E, 6);
444
14.5M
    SHA_MIX(7, 4, 15, 9);
445
14.5M
    SHA_RND3(E, A, B, C, D, 7);
446
14.5M
    SHA_MIX(8, 5, 0, 10);
447
14.5M
    SHA_RND3(D, E, A, B, C, 8);
448
14.5M
    SHA_MIX(9, 6, 1, 11);
449
14.5M
    SHA_RND3(C, D, E, A, B, 9);
450
14.5M
    SHA_MIX(10, 7, 2, 12);
451
14.5M
    SHA_RND3(B, C, D, E, A, 10);
452
14.5M
    SHA_MIX(11, 8, 3, 13);
453
14.5M
    SHA_RND3(A, B, C, D, E, 11);
454
455
14.5M
    SHA_MIX(12, 9, 4, 14);
456
14.5M
    SHA_RND4(E, A, B, C, D, 12);
457
14.5M
    SHA_MIX(13, 10, 5, 15);
458
14.5M
    SHA_RND4(D, E, A, B, C, 13);
459
14.5M
    SHA_MIX(14, 11, 6, 0);
460
14.5M
    SHA_RND4(C, D, E, A, B, 14);
461
14.5M
    SHA_MIX(15, 12, 7, 1);
462
14.5M
    SHA_RND4(B, C, D, E, A, 15);
463
464
14.5M
    SHA_MIX(0, 13, 8, 2);
465
14.5M
    SHA_RND4(A, B, C, D, E, 0);
466
14.5M
    SHA_MIX(1, 14, 9, 3);
467
14.5M
    SHA_RND4(E, A, B, C, D, 1);
468
14.5M
    SHA_MIX(2, 15, 10, 4);
469
14.5M
    SHA_RND4(D, E, A, B, C, 2);
470
14.5M
    SHA_MIX(3, 0, 11, 5);
471
14.5M
    SHA_RND4(C, D, E, A, B, 3);
472
14.5M
    SHA_MIX(4, 1, 12, 6);
473
14.5M
    SHA_RND4(B, C, D, E, A, 4);
474
14.5M
    SHA_MIX(5, 2, 13, 7);
475
14.5M
    SHA_RND4(A, B, C, D, E, 5);
476
14.5M
    SHA_MIX(6, 3, 14, 8);
477
14.5M
    SHA_RND4(E, A, B, C, D, 6);
478
14.5M
    SHA_MIX(7, 4, 15, 9);
479
14.5M
    SHA_RND4(D, E, A, B, C, 7);
480
14.5M
    SHA_MIX(8, 5, 0, 10);
481
14.5M
    SHA_RND4(C, D, E, A, B, 8);
482
14.5M
    SHA_MIX(9, 6, 1, 11);
483
14.5M
    SHA_RND4(B, C, D, E, A, 9);
484
14.5M
    SHA_MIX(10, 7, 2, 12);
485
14.5M
    SHA_RND4(A, B, C, D, E, 10);
486
14.5M
    SHA_MIX(11, 8, 3, 13);
487
14.5M
    SHA_RND4(E, A, B, C, D, 11);
488
14.5M
    SHA_MIX(12, 9, 4, 14);
489
14.5M
    SHA_RND4(D, E, A, B, C, 12);
490
14.5M
    SHA_MIX(13, 10, 5, 15);
491
14.5M
    SHA_RND4(C, D, E, A, B, 13);
492
14.5M
    SHA_MIX(14, 11, 6, 0);
493
14.5M
    SHA_RND4(B, C, D, E, A, 14);
494
14.5M
    SHA_MIX(15, 12, 7, 1);
495
14.5M
    SHA_RND4(A, B, C, D, E, 15);
496
497
14.5M
    XH(0) += A;
498
14.5M
    XH(1) += B;
499
14.5M
    XH(2) += C;
500
14.5M
    XH(3) += D;
501
14.5M
    XH(4) += E;
502
14.5M
}
503
504
static void
505
SHA1_Compress_Generic(SHA1Context *ctx)
506
9.31M
{
507
9.31M
    shaCompress(&ctx->H[H2X], ctx->u.w);
508
9.31M
}
509
510
/*************************************************************************
511
** Code below this line added to make SHA code support BLAPI interface
512
*/
513
514
SHA1Context *
515
SHA1_NewContext(void)
516
1.07M
{
517
1.07M
    SHA1Context *cx;
518
519
    /* no need to ZNew, SHA1_Begin will init the context */
520
1.07M
    cx = PORT_New(SHA1Context);
521
1.07M
    return cx;
522
1.07M
}
523
524
/* Zero and free the context */
525
void
526
SHA1_DestroyContext(SHA1Context *cx, PRBool freeit)
527
1.07M
{
528
1.07M
    memset(cx, 0, sizeof *cx);
529
1.07M
    if (freeit) {
530
1.07M
        PORT_Free(cx);
531
1.07M
    }
532
1.07M
}
533
534
SECStatus
535
SHA1_HashBuf(unsigned char *dest, const unsigned char *src, PRUint32 src_length)
536
2
{
537
2
    SHA1Context ctx;
538
2
    unsigned int outLen;
539
540
2
    SHA1_Begin(&ctx);
541
2
    ctx.update(&ctx, src, src_length);
542
2
    SHA1_End(&ctx, dest, &outLen, SHA1_LENGTH);
543
2
    memset(&ctx, 0, sizeof ctx);
544
2
    return SECSuccess;
545
2
}
546
547
/* Hash a null-terminated character string. */
548
SECStatus
549
SHA1_Hash(unsigned char *dest, const char *src)
550
0
{
551
0
    return SHA1_HashBuf(dest, (const unsigned char *)src, PORT_Strlen(src));
552
0
}
553
554
/*
555
 * need to support save/restore state in pkcs11. Stores all the info necessary
556
 * for a structure into just a stream of bytes.
557
 */
558
unsigned int
559
SHA1_FlattenSize(SHA1Context *cx)
560
553k
{
561
553k
    return sizeof(SHA1Context);
562
553k
}
563
564
SECStatus
565
SHA1_Flatten(SHA1Context *cx, unsigned char *space)
566
0
{
567
0
    PORT_Memcpy(space, cx, sizeof(SHA1Context));
568
0
    return SECSuccess;
569
0
}
570
571
SHA1Context *
572
SHA1_Resurrect(unsigned char *space, void *arg)
573
0
{
574
0
    SHA1Context *cx = SHA1_NewContext();
575
0
    if (cx == NULL)
576
0
        return NULL;
577
578
0
    PORT_Memcpy(cx, space, sizeof(SHA1Context));
579
0
    return cx;
580
0
}
581
582
void
583
SHA1_Clone(SHA1Context *dest, SHA1Context *src)
584
0
{
585
0
    memcpy(dest, src, sizeof *dest);
586
0
}
587
588
void
589
SHA1_TraceState(SHA1Context *ctx)
590
0
{
591
0
    PORT_SetError(PR_NOT_IMPLEMENTED_ERROR);
592
0
}