X-Git-Url: https://git.distorted.org.uk/~mdw/catacomb-python/blobdiff_plain/0040152918b6695e73807fd479024db8a27a83fb..a444923a0b12546f16e042926904a94cbec456b3:/algorithms.c diff --git a/algorithms.c b/algorithms.c index 16d426d..4e22a54 100644 --- a/algorithms.c +++ b/algorithms.c @@ -27,29 +27,59 @@ /*----- Header files ------------------------------------------------------*/ #include "catacomb-python.h" +PUBLIC_SYMBOLS; #include "algorithms.h" +PRIVATE_SYMBOLS; /*----- Key sizes ---------------------------------------------------------*/ -PyTypeObject *keysz_pytype; -PyTypeObject *keyszany_pytype, *keyszrange_pytype, *keyszset_pytype; -PyObject *sha_pyobj, *has160_pyobj; +static PyTypeObject *keysz_pytype; +static PyTypeObject *keyszany_pytype, *keyszrange_pytype, *keyszset_pytype; + +typedef struct keysz_pyobj { + PyObject_HEAD + int dfl; +} keysz_pyobj; + +typedef struct keyszrange_pyobj { + PyObject_HEAD + int dfl; + int min, max, mod; +} keyszrange_pyobj; + +typedef struct keyszset_pyobj { + PyObject_HEAD + int dfl; + PyObject *set; +} keyszset_pyobj; + +#define KEYSZ_PYCHECK(o) PyObject_TypeCheck((o), keysz_pytype) + +#ifndef KSZ_OPMASK +# define KSZ_OPMASK 0x1f +#endif + +#ifndef KSZ_16BIT +# define KSZ_16BIT 0x20 +#endif PyObject *keysz_pywrap(const octet *k) { - switch (k[0]) { + unsigned op = *k++; +#define ARG(i) (op&KSZ_16BIT ? LOAD16(k + 2*(i)) : k[i]) + switch (op&KSZ_OPMASK) { case KSZ_ANY: { keysz_pyobj *o = PyObject_New(keysz_pyobj, keyszany_pytype); - o->dfl = k[1]; + o->dfl = ARG(0); return ((PyObject *)o); } break; case KSZ_RANGE: { keyszrange_pyobj *o = PyObject_New(keyszrange_pyobj, keyszrange_pytype); - o->dfl = k[1]; - o->min = k[2]; - o->max = k[3]; - o->mod = k[4]; + o->dfl = ARG(0); + o->min = ARG(1); + o->max = ARG(2); + o->mod = ARG(3); if (!o->mod) o->mod = 1; return ((PyObject *)o); } break; @@ -57,26 +87,27 @@ PyObject *keysz_pywrap(const octet *k) keyszset_pyobj *o = PyObject_New(keyszset_pyobj, keyszset_pytype); int i, n; - o->dfl = k[1]; - for (i = 0; k[i + 1]; i++) ; + o->dfl = ARG(0); + for (i = 0; ARG(i); i++) ; n = i; o->set = PyTuple_New(n); for (i = 0; i < n; i++) - PyTuple_SET_ITEM(o->set, i, PyInt_FromLong(k[i + 1])); + PyTuple_SET_ITEM(o->set, i, PyInt_FromLong(ARG(i))); return ((PyObject *)o); } break; default: abort(); } +#undef ARG } static PyObject *keyszany_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) { - char *kwlist[] = { "default", 0 }; + static const char *const kwlist[] = { "default", 0 }; int dfl; keysz_pyobj *o; - if (!PyArg_ParseTupleAndKeywords(arg, kw, "i:new", kwlist, &dfl)) + if (!PyArg_ParseTupleAndKeywords(arg, kw, "i:new", KWLIST, &dfl)) goto end; if (dfl < 0) VALERR("key size cannot be negative"); o = (keysz_pyobj *)ty->tp_alloc(ty, 0); @@ -89,18 +120,16 @@ end: static PyObject *keyszrange_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) { - char *kwlist[] = { "default", "min", "max", "mod", 0 }; + static const char *const kwlist[] = { "default", "min", "max", "mod", 0 }; int dfl, min = 0, max = 0, mod = 1; keyszrange_pyobj *o; - if (!PyArg_ParseTupleAndKeywords(arg, kw, "i|iii:new", kwlist, + if (!PyArg_ParseTupleAndKeywords(arg, kw, "i|iii:new", KWLIST, &dfl, &min, &max, &mod)) goto end; - if (dfl < 0 || min < 0 || max < 0) - VALERR("key size cannot be negative"); - if (min > dfl || (max && dfl > max)) - VALERR("bad key size bounds"); - if (mod <= 0 || dfl % mod || min % mod || max % mod) + if (dfl < 0 || min < 0) VALERR("key size cannot be negative"); + if (min > dfl || (max && dfl > max)) VALERR("bad key size bounds"); + if (mod <= 0 || dfl%mod || min%mod || max%mod) VALERR("bad key size modulus"); o = (keyszrange_pyobj *)ty->tp_alloc(ty, 0); o->dfl = dfl; @@ -115,21 +144,19 @@ end: static PyObject *keyszset_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) { - char *kwlist[] = { "default", "set", 0 }; + static const char *const kwlist[] = { "default", "set", 0 }; int dfl, i, n, xx; PyObject *set = 0; PyObject *x = 0, *l = 0; keyszset_pyobj *o = 0; - if (!PyArg_ParseTupleAndKeywords(arg, kw, "i|O:new", kwlist, - &dfl, &set)) + if (!PyArg_ParseTupleAndKeywords(arg, kw, "i|O:new", KWLIST, &dfl, &set)) goto end; if (!set) set = PyTuple_New(0); else Py_INCREF(set); if (!PySequence_Check(set)) TYERR("want a sequence"); - n = PySequence_Size(set); - l = PyList_New(0); - if (PyErr_Occurred()) goto end; + n = PySequence_Size(set); if (n < 0) goto end; + l = PyList_New(0); if (!l) goto end; if (dfl < 0) VALERR("key size cannot be negative"); x = PyInt_FromLong(dfl); PyList_Append(l, x); @@ -166,9 +193,9 @@ static PyObject *ksget_min(PyObject *me, void *hunoz) { PyObject *set = ((keyszset_pyobj *)me)->set; int i, n, y, x = -1; - n = PyTuple_Size(set); + n = PyTuple_GET_SIZE(set); for (i = 0; i < n; i++) { - y = PyInt_AsLong(PyTuple_GetItem(set, i)); + y = PyInt_AS_LONG(PyTuple_GET_ITEM(set, i)); if (x == -1 || y < x) x = y; } return (PyInt_FromLong(x)); @@ -178,59 +205,99 @@ static PyObject *ksget_max(PyObject *me, void *hunoz) { PyObject *set = ((keyszset_pyobj *)me)->set; int i, n, y, x = -1; - n = PyTuple_Size(set); + n = PyTuple_GET_SIZE(set); for (i = 0; i < n; i++) { - y = PyInt_AsLong(PyTuple_GetItem(set, i)); + y = PyInt_AS_LONG(PyTuple_GET_ITEM(set, i)); if (y > x) x = y; } return (PyInt_FromLong(x)); } -static PyMemberDef keysz_pymembers[] = { +static const PyMemberDef keysz_pymembers[] = { #define MEMBERSTRUCT keysz_pyobj -#define default dfl /* ugh! */ - MEMBER(default, T_INT, READONLY, "KSZ.default -> default key size") -#undef default + MEMRNM(default, T_INT, dfl, READONLY, "KSZ.default -> default key size") #undef MEMBERSTRUCT { 0 } }; -static PyGetSetDef keyszany_pygetset[] = { +#define KSZCONVOP(op) \ + static PyObject *kszmeth_##op(PyObject *me, PyObject *arg) \ + { \ + double x, y; \ + if (!PyArg_ParseTuple(arg, "d:" #op, &x)) return (0); \ + y = keysz_##op(x); \ + return (PyFloat_FromDouble(y)); \ + } +KSZCONVOP(fromdl) +KSZCONVOP(fromschnorr) +KSZCONVOP(fromif) +KSZCONVOP(fromec) +KSZCONVOP(todl) +KSZCONVOP(toschnorr) +KSZCONVOP(toif) +KSZCONVOP(toec) +#undef KSZCONVOP + +static const PyMethodDef keysz_pymethods[] = { +#define METHNAME(name) kszmeth_##name + SMTH (fromdl, "fromdl(N) -> M: " + "convert integer discrete log field size to work factor") + SMTH (fromschnorr, "fromschnorr(N) -> M: " + "convert Schnorr group order to work factor") + SMTH (fromif, "fromif(N) -> M: " + "convert integer factorization problem size to work factor") + SMTH (fromec, "fromec(N) -> M: " + "convert elliptic curve group order to work factor") + SMTH (todl, "todl(N) -> M: " + "convert work factor to integer discrete log field size") + SMTH (toschnorr, "toschnorr(N) -> M: " + "convert work factor to Schnorr group order") + SMTH (toif, "toif(N) -> M: " + "convert work factor to integer factorization problem size") + SMTH (toec, "toec(N) -> M: " + "convert work factor to elliptic curve group order") + SMTH (toec, "toec(N) -> M: " + "convert work factor to elliptic curve group order") +#undef METHNAME + { 0 } +}; + +static const PyGetSetDef keyszany_pygetset[] = { #define GETSETNAME(op, name) ka##op##_##name - GET (min, "KSZ.min -> smallest allowed key size") - GET (max, "KSZ.min -> largest allowed key size") + GET (min, "KSZ.min -> smallest allowed key size") + GET (max, "KSZ.max -> largest allowed key size") #undef GETSETNAME { 0 } }; -static PyMemberDef keyszrange_pymembers[] = { +static const PyMemberDef keyszrange_pymembers[] = { #define MEMBERSTRUCT keyszrange_pyobj - MEMBER(min, T_INT, READONLY, "KSZ.min -> smallest allowed key size") - MEMBER(max, T_INT, READONLY, "KSZ.min -> largest allowed key size") - MEMBER(mod, T_INT, READONLY, - "KSZ.mod -> key size must be a multiple of this") + MEMBER(min, T_INT, READONLY, "KSZ.min -> smallest allowed key size") + MEMBER(max, T_INT, READONLY, "KSZ.max -> largest allowed key size") + MEMBER(mod, T_INT, READONLY, + "KSZ.mod -> key size must be a multiple of this") #undef MEMBERSTRUCT { 0 } }; -static PyGetSetDef keyszset_pygetset[] = { +static const PyGetSetDef keyszset_pygetset[] = { #define GETSETNAME(op, name) ks##op##_##name - GET (min, "KSZ.min -> smallest allowed key size") - GET (max, "KSZ.min -> largest allowed key size") + GET (min, "KSZ.min -> smallest allowed key size") + GET (max, "KSZ.max -> largest allowed key size") #undef GETSETNAME { 0 } }; -static PyMemberDef keyszset_pymembers[] = { +static const PyMemberDef keyszset_pymembers[] = { #define MEMBERSTRUCT keyszset_pyobj - MEMBER(set, T_OBJECT, READONLY, "KSZ.set -> allowed key sizes") + MEMBER(set, T_OBJECT, READONLY, "KSZ.set -> allowed key sizes") #undef MEMBERSTRUCT { 0 } }; -static PyTypeObject keysz_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.KeySZ", /* @tp_name@ */ +static const PyTypeObject keysz_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "KeySZ", /* @tp_name@ */ sizeof(keysz_pyobj), /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ @@ -253,7 +320,7 @@ static PyTypeObject keysz_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Key size constraints.", + "Key size constraints. Abstract.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -261,8 +328,8 @@ static PyTypeObject keysz_pytype_skel = { 0, /* @tp_weaklistoffset@ */ 0, /* @tp_iter@ */ 0, /* @tp_iternext@ */ - 0, /* @tp_methods@ */ - keysz_pymembers, /* @tp_members@ */ + PYMETHODS(keysz), /* @tp_methods@ */ + PYMEMBERS(keysz), /* @tp_members@ */ 0, /* @tp_getset@ */ 0, /* @tp_base@ */ 0, /* @tp_dict@ */ @@ -276,9 +343,9 @@ static PyTypeObject keysz_pytype_skel = { 0 /* @tp_is_gc@ */ }; -static PyTypeObject keyszany_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.KeySZAny", /* @tp_name@ */ +static const PyTypeObject keyszany_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "KeySZAny", /* @tp_name@ */ sizeof(keysz_pyobj), /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ @@ -301,7 +368,8 @@ static PyTypeObject keyszany_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Key size constraints. This object imposes no constraints on size.", + "KeySZAny(DEFAULT)\n" + " Key size constraints. This object imposes no constraints on size.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -311,7 +379,7 @@ static PyTypeObject keyszany_pytype_skel = { 0, /* @tp_iternext@ */ 0, /* @tp_methods@ */ 0, /* @tp_members@ */ - keyszany_pygetset, /* @tp_getset@ */ + PYGETSET(keyszany), /* @tp_getset@ */ 0, /* @tp_base@ */ 0, /* @tp_dict@ */ 0, /* @tp_descr_get@ */ @@ -324,9 +392,9 @@ static PyTypeObject keyszany_pytype_skel = { 0 /* @tp_is_gc@ */ }; -static PyTypeObject keyszrange_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.KeySZRange", /* @tp_name@ */ +static const PyTypeObject keyszrange_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "KeySZRange", /* @tp_name@ */ sizeof(keyszrange_pyobj), /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ @@ -349,8 +417,9 @@ static PyTypeObject keyszrange_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Key size constraints. This object asserts minimum and maximum (if\n\ -sizes, and requires the key length to be a multiple of some value.", + "KeySZRange(DEFAULT, [min = 0], [max = 0], [mod = 1])\n" + " Key size constraints: size must be between MIN and MAX inclusive, and\n" + " be a multiple of MOD.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -359,7 +428,7 @@ sizes, and requires the key length to be a multiple of some value.", 0, /* @tp_iter@ */ 0, /* @tp_iternext@ */ 0, /* @tp_methods@ */ - keyszrange_pymembers, /* @tp_members@ */ + PYMEMBERS(keyszrange), /* @tp_members@ */ 0, /* @tp_getset@ */ 0, /* @tp_base@ */ 0, /* @tp_dict@ */ @@ -373,9 +442,9 @@ sizes, and requires the key length to be a multiple of some value.", 0 /* @tp_is_gc@ */ }; -static PyTypeObject keyszset_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.KeySZSet", /* @tp_name@ */ +static const PyTypeObject keyszset_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "KeySZSet", /* @tp_name@ */ sizeof(keyszset_pyobj), /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ @@ -398,8 +467,8 @@ static PyTypeObject keyszset_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Key size constraints. This object requires the key to be one of a\n\ -few listed sizes.", + "KeySZSet(DEFAULT, SEQ)\n" + " Key size constraints: size must be DEFAULT or an element of SEQ.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -408,8 +477,8 @@ few listed sizes.", 0, /* @tp_iter@ */ 0, /* @tp_iternext@ */ 0, /* @tp_methods@ */ - keyszset_pymembers, /* @tp_members@ */ - keyszset_pygetset, /* @tp_getset@ */ + PYMEMBERS(keyszset), /* @tp_members@ */ + PYGETSET(keyszset), /* @tp_getset@ */ 0, /* @tp_base@ */ 0, /* @tp_dict@ */ 0, /* @tp_descr_get@ */ @@ -424,34 +493,46 @@ few listed sizes.", /*----- Symmetric encryption ----------------------------------------------*/ -PyTypeObject *gccipher_pytype, *gcipher_pytype; +static PyTypeObject *gccipher_pytype, *gcipher_pytype; + +typedef struct gccipher_pyobj { + PyHeapTypeObject ty; + gccipher *cc; +} gccipher_pyobj; + +#define GCCIPHER_PYCHECK(o) PyObject_TypeCheck((o), gccipher_pytype) +#define GCCIPHER_CC(o) (((gccipher_pyobj *)(o))->cc) + +typedef struct gcipher_pyobj { + PyObject_HEAD + gcipher *c; +} gcipher_pyobj; + +#define GCIPHER_PYCHECK(o) PyObject_TypeCheck((o), gcipher_pytype) +#define GCIPHER_C(o) (((gcipher_pyobj *)(o))->c) CONVFUNC(gccipher, gccipher *, GCCIPHER_CC) -CONVFUNC(gcipher, gcipher *, GCIPHER_C) -PyObject *gcipher_pywrap(PyObject *cobj, gcipher *c, unsigned f) +static PyObject *gcipher_pywrap(PyObject *cobj, gcipher *c) { gcipher_pyobj *g; if (!cobj) cobj = gccipher_pywrap((/*unconst*/ gccipher *)GC_CLASS(c)); else Py_INCREF(cobj); g = PyObject_NEW(gcipher_pyobj, (PyTypeObject *)cobj); g->c = c; - g->f = f; return ((PyObject *)g); } static PyObject *gcipher_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) { - char *kwlist[] = { "k", 0 }; - char *k; - int sz; + static const char *const kwlist[] = { "k", 0 }; + struct bin k; - if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#:new", kwlist, &k, &sz)) + if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&:new", KWLIST, convbin, &k)) goto end; - if (keysz(sz, GCCIPHER_CC(ty)->keysz) != sz) VALERR("bad key length"); + if (keysz(k.sz, GCCIPHER_CC(ty)->keysz) != k.sz) VALERR("bad key length"); return (gcipher_pywrap((PyObject *)ty, - GC_INIT(GCCIPHER_CC(ty), k, sz), - f_freeme)); + GC_INIT(GCCIPHER_CC(ty), k.p, k.sz))); end: return (0); } @@ -469,20 +550,19 @@ PyObject *gccipher_pywrap(gccipher *cc) g->ty.ht_type.tp_alloc = PyType_GenericAlloc; g->ty.ht_type.tp_free = 0; g->ty.ht_type.tp_new = gcipher_pynew; - PyType_Ready(&g->ty.ht_type); + typeready(&g->ty.ht_type); return ((PyObject *)g); } static void gcipher_pydealloc(PyObject *me) { - if (GCIPHER_F(me) & f_freeme) - GC_DESTROY(GCIPHER_C(me)); - Py_DECREF(me->ob_type); + GC_DESTROY(GCIPHER_C(me)); + Py_DECREF(Py_TYPE(me)); FREEOBJ(me); } static PyObject *gccget_name(PyObject *me, void *hunoz) - { return (PyString_FromString(GCCIPHER_CC(me)->name)); } + { return (TEXT_FROMSTR(GCCIPHER_CC(me)->name)); } static PyObject *gccget_keysz(PyObject *me, void *hunoz) { return (keysz_pywrap(GCCIPHER_CC(me)->keysz)); } @@ -492,13 +572,12 @@ static PyObject *gccget_blksz(PyObject *me, void *hunoz) static PyObject *gcmeth_encrypt(PyObject *me, PyObject *arg) { - char *p; - int sz; + struct bin m; PyObject *rc = 0; - if (!PyArg_ParseTuple(arg, "s#:encrypt", &p, &sz)) return (0); - rc = bytestring_pywrap(0, sz); - GC_ENCRYPT(GCIPHER_C(me), p, PyString_AS_STRING(rc), sz); + if (!PyArg_ParseTuple(arg, "O&:encrypt", convbin, &m)) return (0); + rc = bytestring_pywrap(0, m.sz); + GC_ENCRYPT(GCIPHER_C(me), m.p, BIN_PTR(rc), m.sz); return (rc); } @@ -510,7 +589,7 @@ static PyObject *gcmeth_enczero(PyObject *me, PyObject *arg) if (!PyArg_ParseTuple(arg, "i:enczero", &sz)) return (0); rc = bytestring_pywrap(0, sz); - p = PyString_AS_STRING(rc); + p = BIN_PTR(rc); memset(p, 0, sz); GC_ENCRYPT(GCIPHER_C(me), p, p, sz); return (rc); @@ -518,13 +597,12 @@ static PyObject *gcmeth_enczero(PyObject *me, PyObject *arg) static PyObject *gcmeth_decrypt(PyObject *me, PyObject *arg) { - char *p; - int sz; + struct bin c; PyObject *rc = 0; - if (!PyArg_ParseTuple(arg, "s#:decrypt", &p, &sz)) return (0); - rc = bytestring_pywrap(0, sz); - GC_DECRYPT(GCIPHER_C(me), p, PyString_AS_STRING(rc), sz); + if (!PyArg_ParseTuple(arg, "O&:decrypt", convbin, &c)) return (0); + rc = bytestring_pywrap(0, c.sz); + GC_DECRYPT(GCIPHER_C(me), c.p, BIN_PTR(rc), c.sz); return (rc); } @@ -536,7 +614,7 @@ static PyObject *gcmeth_deczero(PyObject *me, PyObject *arg) if (!PyArg_ParseTuple(arg, "i:deczero", &sz)) return (0); rc = bytestring_pywrap(0, sz); - p = PyString_AS_STRING(rc); + p = BIN_PTR(rc); memset(p, 0, sz); GC_DECRYPT(GCIPHER_C(me), p, p, sz); return (rc); @@ -544,21 +622,21 @@ static PyObject *gcmeth_deczero(PyObject *me, PyObject *arg) static PyObject *gcmeth_setiv(PyObject *me, PyObject *arg) { - char *p; - int sz; + struct bin iv; - if (!PyArg_ParseTuple(arg, "s#:setiv", &p, &sz)) goto end; + if (!PyArg_ParseTuple(arg, "O&:setiv", convbin, &iv)) goto end; + if (!GCIPHER_C(me)->ops->setiv) VALERR("`setiv' not supported"); if (!GC_CLASS(GCIPHER_C(me))->blksz) VALERR("not a block cipher mode"); - if (sz != GC_CLASS(GCIPHER_C(me))->blksz) VALERR("bad IV length"); - GC_SETIV(GCIPHER_C(me), p); + if (iv.sz != GC_CLASS(GCIPHER_C(me))->blksz) VALERR("bad IV length"); + GC_SETIV(GCIPHER_C(me), iv.p); RETURN_ME; end: return (0); } -static PyObject *gcmeth_bdry(PyObject *me, PyObject *arg) +static PyObject *gcmeth_bdry(PyObject *me) { - if (!PyArg_ParseTuple(arg, ":bdry")) goto end; + if (!GCIPHER_C(me)->ops->bdry) VALERR("`bdry' not supported"); if (!GC_CLASS(GCIPHER_C(me))->blksz) VALERR("not a block cipher mode"); GC_BDRY(GCIPHER_C(me)); RETURN_ME; @@ -566,30 +644,30 @@ end: return (0); } -static PyGetSetDef gccipher_pygetset[] = { +static const PyGetSetDef gccipher_pygetset[] = { #define GETSETNAME(op, name) gcc##op##_##name - GET (keysz, "CC.keysz -> acceptable key sizes") - GET (blksz, "CC.blksz -> block size, or zero") - GET (name, "CC.name -> name of this kind of cipher") + GET (keysz, "CC.keysz -> acceptable key sizes") + GET (blksz, "CC.blksz -> block size, or zero") + GET (name, "CC.name -> name of this kind of cipher") #undef GETSETNAME { 0 } }; -static PyMethodDef gcipher_pymethods[] = { +static const PyMethodDef gcipher_pymethods[] = { #define METHNAME(name) gcmeth_##name - METH (encrypt, "C.encrypt(PT) -> CT") - METH (enczero, "C.enczero(N) -> CT") - METH (decrypt, "C.decrypt(CT) -> PT") - METH (deczero, "C.deczero(N) -> PT") - METH (setiv, "C.setiv(IV)") - METH (bdry, "C.bdry()") + METH (encrypt, "C.encrypt(PT) -> CT") + METH (enczero, "C.enczero(N) -> CT") + METH (decrypt, "C.decrypt(CT) -> PT") + METH (deczero, "C.deczero(N) -> PT") + METH (setiv, "C.setiv(IV)") + NAMETH(bdry, "C.bdry()") #undef METHNAME { 0 } }; -static PyTypeObject gccipher_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.GCCipher", /* @tp_name@ */ +static const PyTypeObject gccipher_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GCCipher", /* @tp_name@ */ sizeof(gccipher_pyobj), /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ @@ -612,7 +690,7 @@ static PyTypeObject gccipher_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Symmetric cipher metaclass.", + "Symmetric cipher metaclass.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -622,7 +700,7 @@ static PyTypeObject gccipher_pytype_skel = { 0, /* @tp_iternext@ */ 0, /* @tp_methods@ */ 0, /* @tp_members@ */ - gccipher_pygetset, /* @tp_getset@ */ + PYGETSET(gccipher), /* @tp_getset@ */ 0, /* @tp_base@ */ 0, /* @tp_dict@ */ 0, /* @tp_descr_get@ */ @@ -635,9 +713,9 @@ static PyTypeObject gccipher_pytype_skel = { 0 /* @tp_is_gc@ */ }; -static PyTypeObject gcipher_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.GCipher", /* @tp_name@ */ +static const PyTypeObject gcipher_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GCipher", /* @tp_name@ */ sizeof(gcipher_pyobj), /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ @@ -660,7 +738,7 @@ static PyTypeObject gcipher_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Symmetric cipher, abstract base class.", + "Symmetric cipher, abstract base class.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -668,7 +746,7 @@ static PyTypeObject gcipher_pytype_skel = { 0, /* @tp_weaklistoffset@ */ 0, /* @tp_iter@ */ 0, /* @tp_iternext@ */ - gcipher_pymethods, /* @tp_methods@ */ + PYMETHODS(gcipher), /* @tp_methods@ */ 0, /* @tp_members@ */ 0, /* @tp_getset@ */ 0, /* @tp_base@ */ @@ -683,227 +761,2009 @@ static PyTypeObject gcipher_pytype_skel = { 0 /* @tp_is_gc@ */ }; -/*----- Hash functions ----------------------------------------------------*/ +/*----- Authenticated encryption ------------------------------------------*/ -PyTypeObject *gchash_pytype, *ghash_pytype; +static PyTypeObject *gcaead_pytype, *gaeadkey_pytype; +static PyTypeObject *gcaeadaad_pytype, *gaeadaad_pytype; +static PyTypeObject *gcaeadenc_pytype, *gaeadenc_pytype; +static PyTypeObject *gcaeaddec_pytype, *gaeaddec_pytype; -CONVFUNC(gchash, gchash *, GCHASH_CH) -CONVFUNC(ghash, ghash *, GHASH_H) +typedef struct gcaead_pyobj { + PyHeapTypeObject ty; + gcaead *aec; + struct gcaeadaad_pyobj *aad; + struct gcaeadenc_pyobj *enc; + struct gcaeaddec_pyobj *dec; +} gcaead_pyobj; + +#define GCAEAD_PYCHECK(o) PyObject_TypeCheck((o), gcaead_pytype) +#define GCAEAD_AEC(o) (((gcaead_pyobj *)(o))->aec) +#define GCAEAD_AAD(o) (((gcaead_pyobj *)(o))->aad) +#define GCAEAD_ENC(o) (((gcaead_pyobj *)(o))->enc) +#define GCAEAD_DEC(o) (((gcaead_pyobj *)(o))->dec) +static PyObject *gcaead_pywrap(gcaead *); + +typedef struct gaeadkey_pyobj { + PyObject_HEAD + gaead_key *k; +} gaeadkey_pyobj; -static PyObject *ghash_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) +#define GAEADKEY_PYCHECK(o) PyObject_TypeCheck((o), gaeadkey_pytype) +#define GAEADKEY_K(o) (((gaeadkey_pyobj *)(o))->k) + +typedef struct gcaeadaad_pyobj { + PyHeapTypeObject ty; + gcaead_pyobj *key; +} gcaeadaad_pyobj; + +#define GCAEADAAD_KEY(o) (((gcaeadaad_pyobj *)(o))->key) +static PyObject *gaeadaad_pywrap(PyObject *, gaead_aad *, unsigned, size_t); + +typedef struct gaeadaad_pyobj { + PyObject_HEAD + gaead_aad *a; + unsigned f; +#define AEADF_DEAD 32768u + size_t hsz, hlen; +} gaeadaad_pyobj; + +#define GAEADAAD_PYCHECK(o) PyObject_TypeCheck((o), gaeadaad_pytype) +#define GAEADAAD_A(o) (((gaeadaad_pyobj *)(o))->a) +#define GAEADAAD_F(o) (((gaeadaad_pyobj *)(o))->f) +#define GAEADAAD_HSZ(o) (((gaeadaad_pyobj *)(o))->hsz) +#define GAEADAAD_HLEN(o) (((gaeadaad_pyobj *)(o))->hlen) + +typedef struct gcaeadenc_pyobj { + PyHeapTypeObject ty; + gcaead_pyobj *key; +} gcaeadenc_pyobj; + +#define GCAEADENC_KEY(o) (((gcaeadenc_pyobj *)(o))->key) +static PyObject *gaeadenc_pywrap(PyObject *, gaead_enc *, unsigned, + size_t, size_t, size_t); + +typedef struct gaeadenc_pyobj { + PyObject_HEAD + gaead_enc *e; + gaeadaad_pyobj *aad; + unsigned f; + size_t hsz, msz, tsz; + size_t mlen; +} gaeadenc_pyobj; + +#define GAEADENC_PYCHECK(o) PyObject_TypeCheck((o), gaeadenc_pytype) +#define GAEADENC_AAD(o) (((gaeadenc_pyobj *)(o))->aad) +#define GAEADENC_E(o) (((gaeadenc_pyobj *)(o))->e) +#define GAEADENC_F(o) (((gaeadenc_pyobj *)(o))->f) +#define GAEADENC_HSZ(o) (((gaeadenc_pyobj *)(o))->hsz) +#define GAEADENC_MSZ(o) (((gaeadenc_pyobj *)(o))->msz) +#define GAEADENC_TSZ(o) (((gaeadenc_pyobj *)(o))->tsz) +#define GAEADENC_MLEN(o) (((gaeadenc_pyobj *)(o))->mlen) + +typedef struct gcaeaddec_pyobj { + PyHeapTypeObject ty; + gcaead_pyobj *key; +} gcaeaddec_pyobj; + +#define GCAEADDEC_KEY(o) (((gcaeaddec_pyobj *)(o))->key) +static PyObject *gaeaddec_pywrap(PyObject *, gaead_dec *, unsigned, + size_t, size_t, size_t); + +typedef struct gaeaddec_pyobj { + PyObject_HEAD + gaead_dec *d; + gaeadaad_pyobj *aad; + unsigned f; + size_t hsz, csz, tsz; + size_t clen; +} gaeaddec_pyobj; + +#define GAEADDEC_PYCHECK(o) PyObject_TypeCheck((o), gaeaddec_pytype) +#define GAEADDEC_AAD(o) (((gaeaddec_pyobj *)(o))->aad) +#define GAEADDEC_D(o) (((gaeaddec_pyobj *)(o))->d) +#define GAEADDEC_F(o) (((gaeaddec_pyobj *)(o))->f) +#define GAEADDEC_HSZ(o) (((gaeaddec_pyobj *)(o))->hsz) +#define GAEADDEC_CSZ(o) (((gaeaddec_pyobj *)(o))->csz) +#define GAEADDEC_TSZ(o) (((gaeaddec_pyobj *)(o))->tsz) +#define GAEADDEC_CLEN(o) (((gaeaddec_pyobj *)(o))->clen) + +static PyObject *gaeadkey_pywrap(PyObject *cobj, gaead_key *k) +{ + gaeadkey_pyobj *gk; + + if (!cobj) cobj = gcaead_pywrap((/*unconst*/ gcaead *)GAEAD_CLASS(k)); + else Py_INCREF(cobj); + gk = PyObject_NEW(gaeadkey_pyobj, (PyTypeObject *)cobj); + gk->k = k; + return ((PyObject *)gk); +} + +static PyObject *gaeadkey_pynew(PyTypeObject *ty, + PyObject *arg, PyObject *kw) { - char *kwlist[] = { 0 }; - if (!PyArg_ParseTupleAndKeywords(arg, kw, ":new", kwlist)) + static const char *const kwlist[] = { "k", 0 }; + struct bin k; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&:new", KWLIST, convbin, &k)) goto end; - return (ghash_pywrap((PyObject *)ty, GH_INIT(GCHASH_CH(ty)), f_freeme)); + if (keysz(k.sz, GCAEAD_AEC(ty)->keysz) != k.sz) VALERR("bad key length"); + return (gaeadkey_pywrap((PyObject *)ty, + GAEAD_KEY(GCAEAD_AEC(ty), k.p, k.sz))); end: return (0); } -PyObject *gchash_pywrap(gchash *ch) +static PyObject *gcaead_pywrap(gcaead *aec) { - gchash_pyobj *g = newtype(gchash_pytype, 0, ch->name); - g->ch = ch; - g->ty.ht_type.tp_basicsize = sizeof(ghash_pyobj); - g->ty.ht_type.tp_base = ghash_pytype; - Py_INCREF(ghash_pytype); - g->ty.ht_type.tp_flags = (Py_TPFLAGS_DEFAULT | - Py_TPFLAGS_BASETYPE | - Py_TPFLAGS_HEAPTYPE); - g->ty.ht_type.tp_alloc = PyType_GenericAlloc; - g->ty.ht_type.tp_free = 0; - g->ty.ht_type.tp_new = ghash_pynew; - PyType_Ready(&g->ty.ht_type); - return ((PyObject *)g); + gcaead_pyobj *gck; + gcaeadaad_pyobj *gca; + gcaeadenc_pyobj *gce; + gcaeaddec_pyobj *gcd; + +#define MKTYPE(obj, thing, newfn, namefmt) do { \ + (obj) = newtype(gcaead_pytype, 0, 0); \ + (obj)->ty.ht_name = TEXT_FORMAT(namefmt, aec->name); \ + (obj)->ty.ht_type.tp_name = TEXT_PTR((obj)->ty.ht_name); \ + (obj)->ty.ht_type.tp_basicsize = sizeof(gaead##thing##_pyobj); \ + (obj)->ty.ht_type.tp_base = gaead##thing##_pytype; \ + Py_INCREF(gaead##thing##_pytype); \ + (obj)->ty.ht_type.tp_flags = \ + (Py_TPFLAGS_DEFAULT | Py_TPFLAGS_BASETYPE | Py_TPFLAGS_HEAPTYPE); \ + (obj)->ty.ht_type.tp_alloc = PyType_GenericAlloc; \ + (obj)->ty.ht_type.tp_free = 0; \ + (obj)->ty.ht_type.tp_new = newfn; \ + typeready(&(obj)->ty.ht_type); \ +} while (0) + + MKTYPE(gck, key, gaeadkey_pynew, "%s(key)"); + MKTYPE(gca, aad, abstract_pynew, "%s(aad-hash)"); + MKTYPE(gce, enc, abstract_pynew, "%s(encrypt)"); + MKTYPE(gcd, dec, abstract_pynew, "%s(decrypt)"); + +#undef MKTYPE + + gck->aec = aec; gck->aad = gca; gck->enc = gce; gck->dec = gcd; + gca->key = gce->key = gcd->key = gck; + return ((PyObject *)gck); } -PyObject *ghash_pywrap(PyObject *cobj, ghash *h, unsigned f) +static void gaeadkey_pydealloc(PyObject *me) + { GAEAD_DESTROY(GAEADKEY_K(me)); Py_DECREF(Py_TYPE(me)); FREEOBJ(me); } + +static PyObject *gcaeget_name(PyObject *me, void *hunoz) + { return (TEXT_FROMSTR(GCAEAD_AEC(me)->name)); } + +static PyObject *gcaeget_keysz(PyObject *me, void *hunoz) + { return (keysz_pywrap(GCAEAD_AEC(me)->keysz)); } + +static PyObject *gcaeget_noncesz(PyObject *me, void *hunoz) + { return (keysz_pywrap(GCAEAD_AEC(me)->noncesz)); } + +static PyObject *gcaeget_tagsz(PyObject *me, void *hunoz) + { return (keysz_pywrap(GCAEAD_AEC(me)->tagsz)); } + +static PyObject *gcaeget_blksz(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCAEAD_AEC(me)->blksz)); } + +static PyObject *gcaeget_bufsz(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCAEAD_AEC(me)->bufsz)); } + +static PyObject *gcaeget_ohd(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCAEAD_AEC(me)->ohd)); } + +static PyObject *gcaeget_flags(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCAEAD_AEC(me)->f)); } + +static const PyGetSetDef gcaead_pygetset[] = { +#define GETSETNAME(op, name) gcae##op##_##name + GET (keysz, "AEC.keysz -> acceptable key sizes") + GET (noncesz, "AEC.noncesz -> acceptable nonce sizes") + GET (tagsz, "AEC.tagsz -> acceptable tag sizes") + GET (blksz, "AEC.blksz -> block size, or zero") + GET (bufsz, "AEC.bufsz -> amount of data buffered internally") + GET (ohd, "AEC.ohd -> maximum encryption overhead") + GET (name, "AEC.name -> name of this kind of AEAD scheme") + GET (flags, "AEC.flags -> mask of `AEADF_...' flags") +#undef GETSETNAME + { 0 } +}; + +static PyObject *gaekmeth_aad(PyObject *me) { - ghash_pyobj *g; - if (!cobj) cobj = gchash_pywrap((/*unconst*/ gchash *)GH_CLASS(h)); - else Py_INCREF(cobj); - g = PyObject_NEW(ghash_pyobj, (PyTypeObject *)cobj); - g->h = h; - g->f = f; - return ((PyObject *)g); + const gaead_key *k = GAEADKEY_K(me); + PyObject *rc = 0; + + if (k->ops->c->f&AEADF_AADNDEP) + VALERR("aad must be associated with enc/dec op"); + rc = gaeadaad_pywrap((PyObject *)GCAEAD_AAD(Py_TYPE(me)), + GAEAD_AAD(k), 0, 0); +end: + return (rc); } -static void ghash_pydealloc(PyObject *me) +static int check_aead_encdec(const gcaead *aec, unsigned *f_out, size_t nsz, + PyObject *hszobj, size_t *hsz_out, + PyObject *mszobj, size_t *msz_out, + PyObject *tszobj, size_t *tsz_out) { - if (GHASH_F(me) & f_freeme) - GH_DESTROY(GHASH_H(me)); - Py_DECREF(me->ob_type); - FREEOBJ(me); + unsigned f = 0, miss; + int rc = -1; + + if (hszobj != Py_None) + { f |= AEADF_PCHSZ; if (!convszt(hszobj, hsz_out)) goto end; } + if (mszobj != Py_None) + { f |= AEADF_PCMSZ; if (!convszt(mszobj, msz_out)) goto end; } + if (tszobj != Py_None) + { f |= AEADF_PCTSZ; if (!convszt(tszobj, tsz_out)) goto end; } + miss = aec->f&~f; + if (miss&AEADF_PCHSZ) VALERR("header length precommitment required"); + if (miss&AEADF_PCMSZ) VALERR("message length precommitment required"); + if (miss&AEADF_PCTSZ) VALERR("tag length precommitment required"); + if (keysz(nsz, aec->noncesz) != nsz) VALERR("bad nonce length"); + if (tszobj != Py_None && keysz(*tsz_out, aec->tagsz) != *tsz_out) + VALERR("bad tag length"); + *f_out = f | aec->f; rc = 0; +end: + return (rc); } -static PyObject *gchget_name(PyObject *me, void *hunoz) - { return (PyString_FromString(GCHASH_CH(me)->name)); } +static PyObject *gaekmeth_enc(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "nonce", "hsz", "msz", "tsz", 0 }; + const gaead_key *k = GAEADKEY_K(me); + gaead_enc *e; + PyObject *rc = 0; + struct bin n; + PyObject *hszobj = Py_None, *mszobj = Py_None, *tszobj = Py_None; + size_t hsz = 0, msz = 0, tsz = 0; + unsigned f; -static PyObject *gchget_hashsz(PyObject *me, void *hunoz) - { return (PyInt_FromLong(GCHASH_CH(me)->hashsz)); } + if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&|OOO:enc", KWLIST, + convbin, &n, &hszobj, &mszobj, &tszobj)) + goto end; + if (check_aead_encdec(k->ops->c, &f, n.sz, + hszobj, &hsz, mszobj, &msz, tszobj, &tsz)) + goto end; + e = GAEAD_ENC(GAEADKEY_K(me), n.p, n.sz, hsz, msz, tsz); + if (!e) VALERR("bad aead parameter combination"); + rc = gaeadenc_pywrap((PyObject *)GCAEAD_ENC(Py_TYPE(me)), + e, f, hsz, msz, tsz); +end: + return (rc); +} -static PyObject *gchget_bufsz(PyObject *me, void *hunoz) - { return (PyInt_FromLong(GCHASH_CH(me)->bufsz)); } +static PyObject *gaekmeth_dec(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "nonce", "hsz", "csz", "tsz", 0 }; + const gaead_key *k = GAEADKEY_K(me); + gaead_dec *d; + PyObject *rc = 0; + struct bin n; + PyObject *hszobj = Py_None, *cszobj = Py_None, *tszobj = Py_None; + size_t hsz = 0, csz = 0, tsz = 0; + unsigned f; -static PyObject *ghmeth_hash(PyObject *me, PyObject *arg) + if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&|OOO:dec", KWLIST, + convbin, &n, &hszobj, &cszobj, &tszobj)) + goto end; + if (check_aead_encdec(k->ops->c, &f, n.sz, + hszobj, &hsz, cszobj, &csz, tszobj, &tsz)) + goto end; + d = GAEAD_DEC(GAEADKEY_K(me), n.p, n.sz, hsz, csz, tsz); + if (!d) VALERR("bad aead parameter combination"); + rc = gaeaddec_pywrap((PyObject *)GCAEAD_DEC(Py_TYPE(me)), + d, f, hsz, csz, tsz); +end: + return (rc); +} + +static const PyMethodDef gaeadkey_pymethods[] = { +#define METHNAME(name) gaekmeth_##name + NAMETH(aad, "KEY.aad() -> AAD") + KWMETH(enc, "KEY.enc(NONCE, [hsz], [msz], [tsz]) -> ENC") + KWMETH(dec, "KEY.dec(NONCE, [hsz], [csz], [tsz]) -> DEC") +#undef METHNAME + { 0 } +}; + +static PyObject *gaeadaad_pywrap(PyObject *cobj, gaead_aad *a, + unsigned f, size_t hsz) { - char *p; - int sz; - if (!PyArg_ParseTuple(arg, "s#:hash", &p, &sz)) return (0); - GH_HASH(GHASH_H(me), p, sz); - RETURN_ME; + gaeadaad_pyobj *ga; + + assert(cobj); Py_INCREF(cobj); + ga = PyObject_NEW(gaeadaad_pyobj, (PyTypeObject *)cobj); + ga->a = a; ga->f = f; ga->hsz = hsz; ga->hlen = 0; + return ((PyObject *)ga); } -static PyObject *ghmeth_done(PyObject *me, PyObject *arg) +static void gaeadaad_pydealloc(PyObject *me) { - ghash *g; - PyObject *rc; - if (!PyArg_ParseTuple(arg, ":done")) return (0); - g = GH_COPY(GHASH_H(me)); - rc = bytestring_pywrap(0, g->ops->c->hashsz); - GH_DONE(g, PyString_AS_STRING(rc)); - GH_DESTROY(g); + gaeadaad_pyobj *ga = (gaeadaad_pyobj *)me; + + if (ga->a) GAEAD_DESTROY(ga->a); + Py_DECREF(Py_TYPE(me)); FREEOBJ(me); +} + +static int gaea_check(PyObject *me) +{ + gaeadaad_pyobj *ga = (gaeadaad_pyobj *)me; + int rc = -1; + + if ((ga->f&AEADF_DEAD) || !ga->a) VALERR("aad object no longer active"); + rc = 0; +end: return (rc); } -static PyGetSetDef gchash_pygetset[] = { -#define GETSETNAME(op, name) gch##op##_##name - GET (bufsz, "CH.bufsz -> hash buffer size, or zero") - GET (hashsz, "CH.blksz -> hash output size") - GET (name, "CH.name -> name of this kind of hash") +static void gaea_invalidate(gaeadaad_pyobj *ga) + { if (ga) ga->f |= AEADF_DEAD; } + +static void gaea_sever(gaeadaad_pyobj **ga_inout) +{ + gaeadaad_pyobj *ga = *ga_inout; + if (ga) { ga->f |= AEADF_DEAD; ga->a = 0; Py_DECREF(ga); *ga_inout = 0; } +} + +static PyObject *gaeaget_hsz(PyObject *me, void *hunoz) +{ + if (gaea_check(me)) return (0); + else if (GAEADAAD_F(me)&AEADF_PCHSZ) return getulong(GAEADAAD_HSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaeaget_hlen(PyObject *me, void *hunoz) + { return (gaea_check(me) ? 0 : getulong(GAEADAAD_HLEN(me))); } + +static const PyGetSetDef gaeadaad_pygetset[] = { +#define GETSETNAME(op, name) gaea##op##_##name + GET (hsz, "AAD.hsz -> precommitted header length or `None'") + GET (hlen, "AAD.hlen -> header length so far") #undef GETSETNAME { 0 } }; -#define GHMETH_HASHU_(n, W, w) \ - static PyObject *ghmeth_hashu##w(PyObject *me, PyObject *arg) \ +static PyObject *gaeameth_copy(PyObject *me) +{ + PyObject *rc = 0; + + if (gaea_check(me)) goto end; + if (GAEADAAD_F(me)&AEADF_AADNDEP) + VALERR("can't duplicate nonce-dependent aad"); + rc = gaeadaad_pywrap((PyObject *)Py_TYPE(me), + GAEAD_DUP(GAEADAAD_A(me)), 0, 0); + GAEADAAD_HLEN(rc) = GAEADAAD_HLEN(me); +end: + return (rc); +} + +static int gaeadaad_hash(PyObject *me, const void *h, size_t hsz) +{ + gaeadaad_pyobj *ga = (gaeadaad_pyobj *)me; + int rc = -1; + + if (gaea_check(me)) goto end; + if ((ga->f&AEADF_NOAAD) && hsz) + VALERR("header data not permitted"); + if ((ga->f&AEADF_PCHSZ) && hsz > ga->hsz - ga->hlen) + VALERR("too large for precommitted header length"); + GAEAD_HASH(ga->a, h, hsz); ga->hlen += hsz; + rc = 0; +end: + return (rc); +} + +static PyObject *gaeameth_hash(PyObject *me, PyObject *arg) +{ + struct bin h; + + if (!PyArg_ParseTuple(arg, "O&:hash", convbin, &h)) return (0); + if (gaeadaad_hash(me, h.p, h.sz)) return (0); + RETURN_ME; +} + +#define GAEAMETH_HASHU_(n, W, w) \ + static PyObject *gaeameth_hashu##w(PyObject *me, PyObject *arg) \ { \ - uint##n x; \ - if (!PyArg_ParseTuple(arg, "O&:hashu" #w, convu##n, &x)) goto end; \ - GH_HASHU##W(GHASH_H(me), x); \ + uint##n x; octet b[SZ_##W]; \ + if (!PyArg_ParseTuple(arg, "O&:hashu" #w, convu##n, &x)) return (0); \ + STORE##W(b, x); if (gaeadaad_hash(me, b, sizeof(b))) return (0); \ RETURN_ME; \ - end: \ - return (0); \ } -DOUINTCONV(GHMETH_HASHU_) +DOUINTCONV(GAEAMETH_HASHU_) -#define GHMETH_HASHBUF_(n, W, w) \ - static PyObject *ghmeth_hashbuf##w(PyObject *me, PyObject *arg) \ +#define GAEAMETH_HASHBUF_(n, W, w) \ + static PyObject *gaeameth_hashbuf##w(PyObject *me, PyObject *arg) \ { \ - char *p; \ - int sz; \ - if (!PyArg_ParseTuple(arg, "s#:hashbuf" #w, &p, &sz)) goto end; \ - if (sz > MASK##n) TYERR("string too long"); \ - GH_HASHBUF##W(GHASH_H(me), p, sz); \ + struct bin in; octet b[SZ_##W]; \ + if (!PyArg_ParseTuple(arg, "O&:hashbuf" #w, convbin, &in)) goto end; \ + if (in.sz > MASK##n) TYERR("string too long"); \ + STORE##W(b, in.sz); if (gaeadaad_hash(me, b, sizeof(b))) goto end; \ + if (gaeadaad_hash(me, in.p, in.sz)) goto end; \ RETURN_ME; \ end: \ return (0); \ } -DOUINTCONV(GHMETH_HASHBUF_) +DOUINTCONV(GAEAMETH_HASHBUF_) -static PyObject *ghmeth_hashstrz(PyObject *me, PyObject *arg) +static PyObject *gaeameth_hashstrz(PyObject *me, PyObject *arg) { char *p; if (!PyArg_ParseTuple(arg, "s:hashstrz", &p)) return (0); - GH_HASHSTRZ(GHASH_H(me), p); + if (gaeadaad_hash(me, p, strlen(p) + 1)) return (0); RETURN_ME; } -static PyMethodDef ghash_pymethods[] = { -#define METHNAME(name) ghmeth_##name - METH (hash, "H.hash(M)") -#define METHU_(n, W, w) METH(hashu##w, "H.hashu" #w "(WORD)") +static const PyMethodDef gaeadaad_pymethods[] = { +#define METHNAME(name) gaeameth_##name + NAMETH(copy, "AAD.copy() -> AAD'") + METH (hash, "AAD.hash(H)") +#define METHU_(n, W, w) METH(hashu##w, "AAD.hashu" #w "(WORD)") DOUINTCONV(METHU_) -#define METHBUF_(n, W, w) METH(hashbuf##w, "H.hashbuf" #w "(BYTES)") +#undef METHU_ +#define METHBUF_(n, W, w) METH(hashbuf##w, "AAD.hashbuf" #w "(BYTES)") DOUINTCONV(METHBUF_) - METH (hashstrz, "H.hashstrz(STRING)") - METH (done, "H.done() -> HASH") +#undef METHBUF_ + METH (hashstrz, "AAD.hashstrz(STRING)") #undef METHNAME { 0 } }; -static PyTypeObject gchash_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.GCHash", /* @tp_name@ */ - sizeof(gchash_pyobj), /* @tp_basicsize@ */ - 0, /* @tp_itemsize@ */ +static PyObject *gaeadenc_pywrap(PyObject *cobj, gaead_enc *e, unsigned f, + size_t hsz, size_t msz, size_t tsz) +{ + gaeadenc_pyobj *ge; - 0, /* @tp_dealloc@ */ - 0, /* @tp_print@ */ - 0, /* @tp_getattr@ */ - 0, /* @tp_setattr@ */ - 0, /* @tp_compare@ */ - 0, /* @tp_repr@ */ - 0, /* @tp_as_number@ */ - 0, /* @tp_as_sequence@ */ - 0, /* @tp_as_mapping@ */ - 0, /* @tp_hash@ */ - 0, /* @tp_call@ */ - 0, /* @tp_str@ */ - 0, /* @tp_getattro@ */ - 0, /* @tp_setattro@ */ - 0, /* @tp_as_buffer@ */ - Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ - Py_TPFLAGS_BASETYPE, + assert(cobj); Py_INCREF(cobj); + ge = PyObject_NEW(gaeadenc_pyobj, (PyTypeObject *)cobj); + ge->e = e; ge->f = f; ge->hsz = hsz; ge->msz = msz; ge->tsz = tsz; + ge->aad = 0; ge->mlen = 0; + return ((PyObject *)ge); +} - /* @tp_doc@ */ -"Hash function metaclass.", +static void gaeadenc_pydealloc(PyObject *me) +{ + gaeadenc_pyobj *ge = (gaeadenc_pyobj *)me; - 0, /* @tp_traverse@ */ - 0, /* @tp_clear@ */ - 0, /* @tp_richcompare@ */ - 0, /* @tp_weaklistoffset@ */ - 0, /* @tp_iter@ */ - 0, /* @tp_iternext@ */ - 0, /* @tp_methods@ */ - 0, /* @tp_members@ */ - gchash_pygetset, /* @tp_getset@ */ - 0, /* @tp_base@ */ - 0, /* @tp_dict@ */ - 0, /* @tp_descr_get@ */ - 0, /* @tp_descr_set@ */ - 0, /* @tp_dictoffset@ */ - 0, /* @tp_init@ */ - PyType_GenericAlloc, /* @tp_alloc@ */ - abstract_pynew, /* @tp_new@ */ - 0, /* @tp_free@ */ - 0 /* @tp_is_gc@ */ -}; + gaea_sever(&ge->aad); GAEAD_DESTROY(ge->e); + Py_DECREF(Py_TYPE(me)); FREEOBJ(me); +} -static PyTypeObject ghash_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.GHash", /* @tp_name@ */ - sizeof(ghash_pyobj), /* @tp_basicsize@ */ - 0, /* @tp_itemsize@ */ +static PyObject *gaeeget_hsz(PyObject *me, void *hunoz) +{ + if (GAEADENC_F(me)&AEADF_PCHSZ) return getulong(GAEADENC_HSZ(me)); + else RETURN_NONE; +} - ghash_pydealloc, /* @tp_dealloc@ */ - 0, /* @tp_print@ */ - 0, /* @tp_getattr@ */ - 0, /* @tp_setattr@ */ - 0, /* @tp_compare@ */ - 0, /* @tp_repr@ */ - 0, /* @tp_as_number@ */ - 0, /* @tp_as_sequence@ */ - 0, /* @tp_as_mapping@ */ - 0, /* @tp_hash@ */ - 0, /* @tp_call@ */ - 0, /* @tp_str@ */ - 0, /* @tp_getattro@ */ - 0, /* @tp_setattro@ */ - 0, /* @tp_as_buffer@ */ - Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ - Py_TPFLAGS_BASETYPE, +static PyObject *gaeeget_msz(PyObject *me, void *hunoz) +{ + if (GAEADENC_F(me)&AEADF_PCMSZ) return getulong(GAEADENC_MSZ(me)); + else RETURN_NONE; +} - /* @tp_doc@ */ -"Hash function, abstract base class.", +static PyObject *gaeeget_tsz(PyObject *me, void *hunoz) +{ + if (GAEADENC_F(me)&AEADF_PCTSZ) return getulong(GAEADENC_TSZ(me)); + else RETURN_NONE; +} - 0, /* @tp_traverse@ */ - 0, /* @tp_clear@ */ - 0, /* @tp_richcompare@ */ - 0, /* @tp_weaklistoffset@ */ - 0, /* @tp_iter@ */ - 0, /* @tp_iternext@ */ - ghash_pymethods, /* @tp_methods@ */ +static PyObject *gaeeget_mlen(PyObject *me, void *hunoz) + { return getulong(GAEADENC_MLEN(me)); } + +static const PyGetSetDef gaeadenc_pygetset[] = { +#define GETSETNAME(op, name) gaee##op##_##name + GET (hsz, "ENC.hsz -> precommitted header length or `None'") + GET (msz, "ENC.msz -> precommitted message length or `None'") + GET (tsz, "ENC.tsz -> precommitted tag length or `None'") + GET (mlen, "ENC.mlen -> message length so far") +#undef GETSETNAME + { 0 } +}; + +static PyObject *gaeemeth_aad(PyObject *me) +{ + gaeadenc_pyobj *ge = (gaeadenc_pyobj *)me; + PyObject *rc = 0; + + if (!(ge->f&AEADF_AADNDEP)) + rc = gaeadaad_pywrap((PyObject *)GCAEADENC_KEY(Py_TYPE(ge))->aad, + GAEAD_AAD(ge->e), 0, 0); + else { + if ((ge->f&AEADF_AADFIRST) && ge->mlen) + VALERR("too late for aad"); + if (!ge->aad) + ge->aad = (gaeadaad_pyobj *) + gaeadaad_pywrap((PyObject *)GCAEADENC_KEY(Py_TYPE(ge))->aad, + GAEAD_AAD(ge->e), ge->f&(AEADF_PCHSZ | AEADF_NOAAD), + ge->hsz); + Py_INCREF(ge->aad); + rc = (PyObject *)ge->aad; + } +end: + return (rc); +} + +static PyObject *gaeemeth_reinit(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "nonce", "hsz", "msz", "tsz", 0 }; + gaeadenc_pyobj *ge = (gaeadenc_pyobj *)me; + struct bin n; + PyObject *hszobj = Py_None, *mszobj = Py_None, *tszobj = Py_None; + size_t hsz = 0, msz = 0, tsz = 0; + unsigned f; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&|OOO:enc", KWLIST, + convbin, &n, &hszobj, &mszobj, &tszobj)) + goto end; + if (check_aead_encdec(ge->e->ops->c, &f, n.sz, + hszobj, &hsz, mszobj, &msz, tszobj, &tsz)) + goto end; + if (GAEAD_REINIT(ge->e, n.p, n.sz, hsz, msz, tsz)) + VALERR("bad aead parameter combination"); + gaea_sever(&ge->aad); + ge->f = f; ge->hsz = hsz; ge->msz = msz; ge->tsz = tsz; +end: + return (0); +} + +static PyObject *gaeemeth_encrypt(PyObject *me, PyObject *arg) +{ + gaeadenc_pyobj *ge = (gaeadenc_pyobj *)me; + struct bin m; + char *c = 0; size_t csz; buf b; + int err; + PyObject *rc = 0; + + if (!PyArg_ParseTuple(arg, "O&:encrypt", convbin, &m)) goto end; + if (ge->f&AEADF_AADFIRST) { + if ((ge->f&AEADF_PCHSZ) && (ge->aad ? ge->aad->hlen : 0) != ge->hsz) + VALERR("header doesn't match precommitted length"); + gaea_invalidate(ge->aad); + } + if ((ge->f&AEADF_PCMSZ) && m.sz > ge->msz - ge->mlen) + VALERR("too large for precommitted message length"); + csz = m.sz + ge->e->ops->c->bufsz; c = xmalloc(csz); buf_init(&b, c, csz); + err = GAEAD_ENCRYPT(ge->e, m.p, m.sz, &b); assert(!err); (void)err; + buf_flip(&b); rc = bytestring_pywrapbuf(&b); ge->mlen += m.sz; +end: + xfree(c); + return (rc); +} + +static PyObject *gaeemeth_done(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "tsz", "aad", 0 }; + gaeadenc_pyobj *ge = (gaeadenc_pyobj *)me; + PyObject *aad = Py_None; + char *c = 0; size_t csz; buf b; + PyObject *tszobj = Py_None; PyObject *tag; size_t tsz; + int err; + PyObject *rc = 0; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "|OO:done", KWLIST, + &tszobj, &aad)) + goto end; + if (tszobj != Py_None && !convszt(tszobj, &tsz)) goto end; + if (aad != Py_None && + !PyObject_TypeCheck(aad, + (PyTypeObject *)GCAEADENC_KEY(Py_TYPE(me))->aad)) + TYERR("wanted aad"); + if ((ge->f&AEADF_AADNDEP) && aad != Py_None && aad != (PyObject *)ge->aad) + VALERR("mismatched aad"); + if ((ge->f&AEADF_PCHSZ) && + (aad == Py_None ? 0 : GAEADAAD_HLEN(aad)) != ge->hsz) + VALERR("header doesn't match precommitted length"); + if ((ge->f&AEADF_PCMSZ) && ge->mlen != ge->msz) + VALERR("message doesn't match precommitted length"); + if (tszobj == Py_None) { + if (ge->f&AEADF_PCTSZ) tsz = ge->tsz; + else tsz = keysz(0, ge->e->ops->c->tagsz); + } else { + if ((ge->f&AEADF_PCTSZ) && tsz != ge->tsz) + VALERR("tag length doesn't match precommitted value"); + if (keysz(tsz, ge->e->ops->c->tagsz) != tsz) VALERR("bad tag length"); + } + csz = ge->e->ops->c->bufsz; c = xmalloc(csz); buf_init(&b, c, csz); + tag = bytestring_pywrap(0, tsz); + err = GAEAD_DONE(ge->e, aad == Py_None ? 0 : GAEADAAD_A(aad), &b, + BIN_PTR(tag), tsz); + assert(!err); (void)err; + buf_flip(&b); rc = Py_BuildValue("NN", bytestring_pywrapbuf(&b), tag); +end: + xfree(c); + return (rc); +} + +static const PyMethodDef gaeadenc_pymethods[] = { +#define METHNAME(name) gaeemeth_##name + NAMETH(aad, "ENC.aad() -> AAD") + KWMETH(reinit, "ENC.reinit(NONCE, [hsz], [msz], [tsz])") + METH (encrypt, "ENC.encrypt(MSG) -> CT") + KWMETH(done, "ENC.done([tsz], [aad]) -> CT, TAG") +#undef METHNAME + { 0 } +}; + +static PyObject *gaeaddec_pywrap(PyObject *cobj, gaead_dec *d, unsigned f, + size_t hsz, size_t csz, size_t tsz) +{ + gaeaddec_pyobj *gd; + assert(cobj); Py_INCREF(cobj); + gd = PyObject_NEW(gaeaddec_pyobj, (PyTypeObject *)cobj); + gd->d = d; gd->f = f; gd->hsz = hsz; gd->csz = csz; gd->tsz = tsz; + gd->aad = 0; gd->clen = 0; + return ((PyObject *)gd); +} + +static void gaeaddec_pydealloc(PyObject *me) +{ + gaeaddec_pyobj *gd = (gaeaddec_pyobj *)me; + + gaea_sever(&gd->aad); GAEAD_DESTROY(GAEADDEC_D(me)); + Py_DECREF(Py_TYPE(me)); FREEOBJ(me); +} + +static PyObject *gaedget_hsz(PyObject *me, void *hunoz) +{ + if (GAEADDEC_F(me)&AEADF_PCHSZ) return getulong(GAEADDEC_HSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaedget_csz(PyObject *me, void *hunoz) +{ + if (GAEADDEC_F(me)&AEADF_PCMSZ) return getulong(GAEADDEC_CSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaedget_tsz(PyObject *me, void *hunoz) +{ + if (GAEADDEC_F(me)&AEADF_PCTSZ) return getulong(GAEADDEC_TSZ(me)); + else RETURN_NONE; +} + +static PyObject *gaedget_clen(PyObject *me, void *hunoz) + { return getulong(GAEADDEC_CLEN(me)); } + +static const PyGetSetDef gaeaddec_pygetset[] = { +#define GETSETNAME(op, name) gaed##op##_##name + GET (hsz, "DEC.hsz -> precommitted header length or `None'") + GET (csz, "DEC.csz -> precommitted ciphertext length or `None'") + GET (tsz, "DEC.tsz -> precommitted tag length or `None'") + GET (clen, "DEC.clen -> ciphertext length so far") +#undef GETSETNAME + { 0 } +}; + +static PyObject *gaedmeth_aad(PyObject *me) +{ + gaeaddec_pyobj *gd = (gaeaddec_pyobj *)me; + + if (!(gd->f&AEADF_AADNDEP)) + return (gaeadaad_pywrap((PyObject *)GCAEADDEC_KEY(Py_TYPE(gd))->aad, + GAEAD_AAD(gd->d), 0, 0)); + else { + if (!gd->aad) + gd->aad = (gaeadaad_pyobj *) + gaeadaad_pywrap((PyObject *)GCAEADENC_KEY(Py_TYPE(gd))->aad, + GAEAD_AAD(gd->d), gd->f&(AEADF_PCHSZ | AEADF_NOAAD), + gd->hsz); + Py_INCREF(gd->aad); + return ((PyObject *)gd->aad); + } +} + +static PyObject *gaedmeth_reinit(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "nonce", "hsz", "csz", "tsz", 0 }; + gaeaddec_pyobj *gd = (gaeaddec_pyobj *)me; + struct bin n; + PyObject *hszobj = Py_None, *cszobj = Py_None, *tszobj = Py_None; + size_t hsz = 0, csz = 0, tsz = 0; + unsigned f; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&|OOO:enc", KWLIST, + convbin, &n, &hszobj, &cszobj, &tszobj)) + goto end; + if (check_aead_encdec(gd->d->ops->c, &f, n.sz, + hszobj, &hsz, cszobj, &csz, tszobj, &tsz)) + goto end; + if (GAEAD_REINIT(gd->d, n.p, n.sz, hsz, csz, tsz)) + VALERR("bad aead parameter combination"); + gaea_sever(&gd->aad); + gd->f = f; gd->hsz = hsz; gd->csz = csz; gd->tsz = tsz; +end: + return (0); +} + +static PyObject *gaedmeth_decrypt(PyObject *me, PyObject *arg) +{ + gaeaddec_pyobj *gd = (gaeaddec_pyobj *)me; + struct bin c; + char *m = 0; size_t msz; buf b; + int err; + PyObject *rc = 0; + + if (!PyArg_ParseTuple(arg, "O&:decrypt", convbin, &c)) goto end; + if (gd->f&AEADF_AADFIRST) { + if ((gd->f&AEADF_PCHSZ) && (gd->aad ? gd->aad->hlen : 0) != gd->hsz) + VALERR("header doesn't match precommitted length"); + gaea_invalidate(gd->aad); + } + if ((gd->f&AEADF_PCMSZ) && c.sz > gd->csz - gd->clen) + VALERR("too large for precommitted message length"); + msz = c.sz + gd->d->ops->c->bufsz; m = xmalloc(msz); buf_init(&b, m, msz); + err = GAEAD_DECRYPT(gd->d, c.p, c.sz, &b); assert(!err); (void)err; + buf_flip(&b); rc = bytestring_pywrapbuf(&b); gd->clen += c.sz; +end: + xfree(m); + return (rc); +} + +static PyObject *gaedmeth_done(PyObject *me, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "tag", "aad", 0 }; + gaeaddec_pyobj *gd = (gaeaddec_pyobj *)me; + PyObject *aad = Py_None; + struct bin t; + char *m = 0; size_t msz; buf b; + int err; + PyObject *rc = 0; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&|O:done", KWLIST, + convbin, &t, &aad)) + goto end; + if (aad != Py_None && + !PyObject_TypeCheck(aad, + (PyTypeObject *)GCAEADENC_KEY(Py_TYPE(me))->aad)) + TYERR("wanted aad"); + if ((gd->f&AEADF_AADNDEP) && aad != Py_None && aad != (PyObject *)gd->aad) + VALERR("mismatched aad"); + if ((gd->f&AEADF_PCHSZ) && + (aad == Py_None ? 0 : GAEADAAD_HLEN(aad)) != gd->hsz) + VALERR("header doesn't match precommitted length"); + if ((gd->f&AEADF_PCMSZ) && gd->clen != gd->csz) + VALERR("message doesn't match precommitted length"); + if ((gd->f&AEADF_PCTSZ) && t.sz != gd->tsz) + VALERR("tag length doesn't match precommitted value"); + if (keysz(t.sz, gd->d->ops->c->tagsz) != t.sz) VALERR("bad tag length"); + msz = gd->d->ops->c->bufsz; m = xmalloc(msz); buf_init(&b, m, msz); + err = GAEAD_DONE(gd->d, aad == Py_None ? 0 : GAEADAAD_A(aad), + &b, t.p, t.sz); + assert(err >= 0); + if (!err) VALERR("decryption failed"); + buf_flip(&b); rc = bytestring_pywrapbuf(&b); +end: + xfree(m); + return (rc); +} + +static const PyMethodDef gaeaddec_pymethods[] = { +#define METHNAME(name) gaedmeth_##name + NAMETH(aad, "DEC.aad() -> AAD") + KWMETH(reinit, "DEC.reinit(NONCE, [hsz], [csz], [tsz])") + METH (decrypt, "DEC.decrypt(CT) -> MSG") + KWMETH(done, "DEC.done(TAG, [aad]) -> MSG | None") +#undef METHNAME + { 0 } +}; + +static const PyTypeObject gcaead_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GCAEAD", /* @tp_name@ */ + sizeof(gcaead_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Authenticated encryption (key) metaclass.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + PYGETSET(gcaead), /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject gaeadkey_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GAEKey", /* @tp_name@ */ + sizeof(gaeadkey_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + gaeadkey_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Authenticated encryption key.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + PYMETHODS(gaeadkey), /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject gcaeadaad_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GAEAADClass", /* @tp_name@ */ + sizeof(gcaeadaad_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Authenticated encryption additional-data hash metaclass.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject gaeadaad_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GAEAAD", /* @tp_name@ */ + sizeof(gaeadaad_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + gaeadaad_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Authenticated encryption AAD hash.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + PYMETHODS(gaeadaad), /* @tp_methods@ */ + 0, /* @tp_members@ */ + PYGETSET(gaeadaad), /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject gcaeadenc_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GAEEncClass", /* @tp_name@ */ + sizeof(gcaeadenc_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Authenticated encryption operation metaclass.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject gaeadenc_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GAEEnc", /* @tp_name@ */ + sizeof(gaeadenc_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + gaeadenc_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Authenticated encryption operation.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + PYMETHODS(gaeadenc), /* @tp_methods@ */ + 0, /* @tp_members@ */ + PYGETSET(gaeadenc), /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject gcaeaddec_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GAEDecClass", /* @tp_name@ */ + sizeof(gcaeaddec_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Authenticated decryption operation metaclass.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject gaeaddec_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GAEDec", /* @tp_name@ */ + sizeof(gaeaddec_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + gaeaddec_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Authenticated decryption operation.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + PYMETHODS(gaeaddec), /* @tp_methods@ */ + 0, /* @tp_members@ */ + PYGETSET(gaeaddec), /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +/*----- Hash functions ----------------------------------------------------*/ + +PyTypeObject *gchash_pytype; +static PyTypeObject *ghash_pytype; +PyObject *sha_pyobj, *has160_pyobj; + +typedef struct ghash_pyobj { + PyObject_HEAD + ghash *h; +} ghash_pyobj; + +#define GHASH_PYCHECK(o) PyObject_TypeCheck((o), ghash_pytype) +#define GHASH_H(o) (((ghash_pyobj *)(o))->h) + +CONVFUNC(gchash, gchash *, GCHASH_CH) +CONVFUNC(ghash, ghash *, GHASH_H) + +static PyObject *ghash_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { 0 }; + if (!PyArg_ParseTupleAndKeywords(arg, kw, ":new", KWLIST)) + goto end; + return (ghash_pywrap((PyObject *)ty, GH_INIT(GCHASH_CH(ty)))); +end: + return (0); +} + +static PyObject *gchash_pywrap(gchash *ch) +{ + gchash_pyobj *g = newtype(gchash_pytype, 0, ch->name); + g->ch = ch; + g->ty.ht_type.tp_basicsize = sizeof(ghash_pyobj); + g->ty.ht_type.tp_base = ghash_pytype; + Py_INCREF(ghash_pytype); + g->ty.ht_type.tp_flags = (Py_TPFLAGS_DEFAULT | + Py_TPFLAGS_BASETYPE | + Py_TPFLAGS_HEAPTYPE); + g->ty.ht_type.tp_alloc = PyType_GenericAlloc; + g->ty.ht_type.tp_free = 0; + g->ty.ht_type.tp_new = ghash_pynew; + typeready(&g->ty.ht_type); + return ((PyObject *)g); +} + +PyObject *ghash_pywrap(PyObject *cobj, ghash *h) +{ + ghash_pyobj *g; + if (!cobj) cobj = gchash_pywrap((/*unconst*/ gchash *)GH_CLASS(h)); + else Py_INCREF(cobj); + g = PyObject_NEW(ghash_pyobj, (PyTypeObject *)cobj); + g->h = h; + return ((PyObject *)g); +} + +static void ghash_pydealloc(PyObject *me) +{ + GH_DESTROY(GHASH_H(me)); + Py_DECREF(Py_TYPE(me)); + FREEOBJ(me); +} + +static PyObject *gchget_name(PyObject *me, void *hunoz) + { return (TEXT_FROMSTR(GCHASH_CH(me)->name)); } + +static PyObject *gchget_hashsz(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCHASH_CH(me)->hashsz)); } + +static PyObject *gchget_bufsz(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCHASH_CH(me)->bufsz)); } + +static PyObject *ghmeth_copy(PyObject *me) + { return (ghash_pywrap((PyObject *)Py_TYPE(me), GH_COPY(GHASH_H(me)))); } + +static PyObject *ghmeth_hash(PyObject *me, PyObject *arg) +{ + struct bin m; + if (!PyArg_ParseTuple(arg, "O&:hash", convbin, &m)) return (0); + GH_HASH(GHASH_H(me), m.p, m.sz); + RETURN_ME; +} + +#define GHMETH_HASHU_(n, W, w) \ + static PyObject *ghmeth_hashu##w(PyObject *me, PyObject *arg) \ + { \ + uint##n x; \ + if (!PyArg_ParseTuple(arg, "O&:hashu" #w, convu##n, &x)) return (0); \ + GH_HASHU##W(GHASH_H(me), x); \ + RETURN_ME; \ + } +DOUINTCONV(GHMETH_HASHU_) + +#define GHMETH_HASHBUF_(n, W, w) \ + static PyObject *ghmeth_hashbuf##w(PyObject *me, PyObject *arg) \ + { \ + struct bin in; \ + if (!PyArg_ParseTuple(arg, "O&:hashbuf" #w, convbin, &in)) goto end; \ + if (in.sz > MASK##n) TYERR("string too long"); \ + GH_HASHBUF##W(GHASH_H(me), in.p, in.sz); \ + RETURN_ME; \ + end: \ + return (0); \ + } +DOUINTCONV(GHMETH_HASHBUF_) + +static PyObject *ghmeth_hashstrz(PyObject *me, PyObject *arg) +{ + char *p; + if (!PyArg_ParseTuple(arg, "s:hashstrz", &p)) return (0); + GH_HASHSTRZ(GHASH_H(me), p); + RETURN_ME; +} + +static PyObject *ghmeth_done(PyObject *me) +{ + ghash *g; + PyObject *rc; + g = GH_COPY(GHASH_H(me)); + rc = bytestring_pywrap(0, g->ops->c->hashsz); + GH_DONE(g, BIN_PTR(rc)); + GH_DESTROY(g); + return (rc); +} + +static const PyGetSetDef gchash_pygetset[] = { +#define GETSETNAME(op, name) gch##op##_##name + GET (bufsz, "CH.bufsz -> hash buffer size, or zero") + GET (hashsz, "CH.hashsz -> hash output size") + GET (name, "CH.name -> name of this kind of hash") +#undef GETSETNAME + { 0 } +}; + +static const PyMethodDef ghash_pymethods[] = { +#define METHNAME(name) ghmeth_##name + NAMETH(copy, "H.copy() -> HH") + METH (hash, "H.hash(M)") +#define METHU_(n, W, w) METH(hashu##w, "H.hashu" #w "(WORD)") + DOUINTCONV(METHU_) +#undef METHU_ +#define METHBUF_(n, W, w) METH(hashbuf##w, "H.hashbuf" #w "(BYTES)") + DOUINTCONV(METHBUF_) +#undef METHBUF_ + METH (hashstrz, "H.hashstrz(STRING)") + NAMETH(done, "H.done() -> HASH") +#undef METHNAME + { 0 } +}; + +static const PyTypeObject gchash_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GCHash", /* @tp_name@ */ + sizeof(gchash_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Hash function metaclass.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + PYGETSET(gchash), /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject ghash_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GHash", /* @tp_name@ */ + sizeof(ghash_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + ghash_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Hash function, abstract base class.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + PYMETHODS(ghash), /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +/*----- Message authentication --------------------------------------------*/ + +static PyTypeObject *gcmac_pytype, *gmac_pytype, *gmhash_pytype; + +typedef struct gcmac_pyobj { + PyHeapTypeObject ty; + gcmac *cm; +} gcmac_pyobj; + +#define GCMAC_PYCHECK(o) PyObject_TypeCheck((o), gcmac_pytype) +#define GCMAC_CM(o) (((gcmac_pyobj *)(o))->cm) +#define GCMAC_F(o) (((gcmac_pyobj *)(o))->f) +CONVFUNC(gcmac, gcmac *, GCMAC_CM) +static PyObject *gmac_pywrap(PyObject *, gmac *); + +typedef struct gmac_pyobj { + PyHeapTypeObject ty; + gmac *m; +} gmac_pyobj; + +extern PyTypeObject *gmac_pytype; +#define GMAC_PYCHECK(o) PyObject_TypeCheck((o), gmac_pytype) +#define GMAC_M(o) (((gmac_pyobj *)(o))->m) +#define GMAC_F(o) (((gmac_pyobj *)(o))->f) +extern PyObject *gmac_pywrap(PyObject *, gmac *); +extern int convgmac(PyObject *, void *); + +static PyObject *gmac_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "k", 0 }; + struct bin k; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&:new", KWLIST, convbin, &k)) + goto end; + if (keysz(k.sz, GCMAC_CM(ty)->keysz) != k.sz) VALERR("bad key length"); + return (gmac_pywrap((PyObject *)ty, + GM_KEY(GCMAC_CM(ty), k.p, k.sz))); +end: + return (0); +} + +static PyObject *gmhash_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { 0 }; + ghash_pyobj *g; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, ":new", KWLIST)) return (0); + g = PyObject_NEW(ghash_pyobj, ty); + g->h = GM_INIT(GMAC_M(ty)); + Py_INCREF(ty); + return ((PyObject *)g); +} + +static PyObject *gcmac_pywrap(gcmac *cm) +{ + gcmac_pyobj *g = newtype(gcmac_pytype, 0, cm->name); + g->cm = cm; + g->ty.ht_type.tp_basicsize = sizeof(gmac_pyobj); + g->ty.ht_type.tp_base = gmac_pytype; + Py_INCREF(gmac_pytype); + g->ty.ht_type.tp_flags = (Py_TPFLAGS_DEFAULT | + Py_TPFLAGS_BASETYPE | + Py_TPFLAGS_HEAPTYPE); + g->ty.ht_type.tp_alloc = PyType_GenericAlloc; + g->ty.ht_type.tp_free = 0; + g->ty.ht_type.tp_new = gmac_pynew; + typeready(&g->ty.ht_type); + return ((PyObject *)g); +} + +static PyObject *gmac_pywrap(PyObject *cobj, gmac *m) +{ + gmac_pyobj *g; + if (!cobj) cobj = gcmac_pywrap((/*unconst*/ gcmac *)GM_CLASS(m)); + else Py_INCREF(cobj); + g = newtype((PyTypeObject *)cobj, 0, 0); + g->ty.ht_type.tp_basicsize = sizeof(ghash_pyobj); + g->ty.ht_name = TEXT_FORMAT("%s(keyed)", m->ops->c->name); + g->ty.ht_type.tp_name = TEXT_PTR(g->ty.ht_name); + g->ty.ht_type.tp_base = gmhash_pytype; + Py_INCREF(gmac_pytype); + g->ty.ht_type.tp_flags = (Py_TPFLAGS_DEFAULT | + Py_TPFLAGS_BASETYPE | + Py_TPFLAGS_HEAPTYPE); + g->ty.ht_type.tp_alloc = PyType_GenericAlloc; + g->ty.ht_type.tp_free = 0; + g->ty.ht_type.tp_new = gmhash_pynew; + typeready(&g->ty.ht_type); + g->m = m; + return ((PyObject *)g); +} + +static void gmac_pydealloc(PyObject *me) +{ + GM_DESTROY(GMAC_M(me)); + Py_DECREF(Py_TYPE(me)); + PyType_Type.tp_dealloc(me); +} + +static PyObject *gcmget_name(PyObject *me, void *hunoz) + { return (TEXT_FROMSTR(GCMAC_CM(me)->name)); } + +static PyObject *gcmget_keysz(PyObject *me, void *hunoz) + { return (keysz_pywrap(GCMAC_CM(me)->keysz)); } + +static PyObject *gcmget_tagsz(PyObject *me, void *hunoz) + { return (PyInt_FromLong(GCMAC_CM(me)->hashsz)); } + +static const PyGetSetDef gcmac_pygetset[] = { +#define GETSETNAME(op, name) gcm##op##_##name + GET (keysz, "CM.keysz -> acceptable key sizes") + GET (tagsz, "CM.tagsz -> MAC output size") + GET (name, "CM.name -> name of this kind of MAC") +#undef GETSETNAME + { 0 } +}; + +static const PyTypeObject gcmac_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GCMAC", /* @tp_name@ */ + sizeof(gchash_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Message authentication code metametaclass.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + PYGETSET(gcmac), /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject gmac_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GMAC", /* @tp_name@ */ + sizeof(gmac_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + gmac_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Message authentication code metaclass, abstract base class.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject gmhash_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GMACHash", /* @tp_name@ */ + sizeof(ghash_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + ghash_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Message authentication code, abstract base class.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +/*----- Special snowflake for Poly1305 ------------------------------------*/ + +PyTypeObject *poly1305cls_pytype, *poly1305key_pytype, *poly1305hash_pytype; + +typedef struct poly1305key_pyobj { + PyHeapTypeObject ty; + poly1305_key k; +} poly1305key_pyobj; + +typedef struct poly1305hash_pyobj { + PyObject_HEAD + unsigned f; +#define f_mask 1u + poly1305_ctx ctx; +} poly1305hash_pyobj; + +#define P1305_F(o) (((poly1305hash_pyobj *)(o))->f) +#define P1305_CTX(o) (&((poly1305hash_pyobj *)(o))->ctx) +CONVFUNC(poly1305hash, poly1305_ctx *, P1305_CTX) + +static PyObject *poly1305hash_pynew(PyTypeObject *ty, + PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "mask", 0 }; + poly1305key_pyobj *pk = (poly1305key_pyobj *)ty; + poly1305hash_pyobj *ph; + struct bin m = { 0, 0 }; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "|O&:new", KWLIST, convbin, &m)) + return (0); + if (m.p && m.sz != POLY1305_MASKSZ) VALERR("bad mask length"); + ph = PyObject_NEW(poly1305hash_pyobj, ty); + ph->f = 0; + if (m.p) ph->f |= f_mask; + poly1305_macinit(&ph->ctx, &pk->k, m.p); + Py_INCREF(ty); + return ((PyObject *)ph); +end: + return (0); +} + +static PyObject *poly1305key_pynew(PyTypeObject *ty, + PyObject *arg, PyObject *kw) +{ + static const char *const kwlist[] = { "k", 0 }; + poly1305key_pyobj *pk; + struct bin k; + + if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&:new", KWLIST, convbin, &k)) + goto end; + if (keysz(k.sz, poly1305_keysz) != k.sz) VALERR("bad key length"); + + pk = newtype(ty, 0, 0); + pk->ty.ht_name = TEXT_FROMSTR("poly1305(keyed)"); + pk->ty.ht_type.tp_basicsize = sizeof(poly1305hash_pyobj); + pk->ty.ht_type.tp_name = TEXT_PTR(pk->ty.ht_name); + pk->ty.ht_type.tp_base = poly1305hash_pytype; + Py_INCREF(poly1305key_pytype); + pk->ty.ht_type.tp_flags = (Py_TPFLAGS_DEFAULT | + Py_TPFLAGS_BASETYPE | + Py_TPFLAGS_HEAPTYPE); + pk->ty.ht_type.tp_alloc = PyType_GenericAlloc; + pk->ty.ht_type.tp_free = 0; + pk->ty.ht_type.tp_new = poly1305hash_pynew; + typeready(&pk->ty.ht_type); + + poly1305_keyinit(&pk->k, k.p, k.sz); + return ((PyObject *)pk); + +end: + return (0); +} + +static PyObject *poly1305clsget_name(PyObject *me, void *hunoz) + { return (TEXT_FROMSTR("poly1305")); } + +static PyObject *poly1305clsget_keysz(PyObject *me, void *hunoz) + { return (keysz_pywrap(poly1305_keysz)); } + +static PyObject *poly1305clsget_masksz(PyObject *me, void *hunoz) + { return (PyInt_FromLong(POLY1305_MASKSZ)); } + +static PyObject *poly1305clsget_tagsz(PyObject *me, void *hunoz) + { return (PyInt_FromLong(POLY1305_TAGSZ)); } + +static PyObject *polymeth_copy(PyObject *me) +{ + poly1305hash_pyobj *ph; + ph = PyObject_NEW(poly1305hash_pyobj, Py_TYPE(me)); + poly1305_copy(&ph->ctx, P1305_CTX(me)); + Py_INCREF(Py_TYPE(me)); + return ((PyObject *)ph); +} + +static PyObject *polymeth_hash(PyObject *me, PyObject *arg) +{ + struct bin m; + if (!PyArg_ParseTuple(arg, "O&:hash", convbin, &m)) return (0); + poly1305_hash(P1305_CTX(me), m.p, m.sz); + RETURN_ME; +} + +#define POLYMETH_HASHU_(n, W, w) \ + static PyObject *polymeth_hashu##w(PyObject *me, PyObject *arg) \ + { \ + uint##n x; \ + octet b[SZ_##W]; \ + if (!PyArg_ParseTuple(arg, "O&:hashu" #w, convu##n, &x)) return (0); \ + STORE##W(b, x); poly1305_hash(P1305_CTX(me), b, sizeof(b)); \ + RETURN_ME; \ + } +DOUINTCONV(POLYMETH_HASHU_) + +#define POLYMETH_HASHBUF_(n, W, w) \ + static PyObject *polymeth_hashbuf##w(PyObject *me, PyObject *arg) \ + { \ + struct bin in; \ + octet b[SZ_##W]; \ + if (!PyArg_ParseTuple(arg, "O&:hashbuf" #w, convbin, &in)) goto end; \ + if (in.sz > MASK##n) TYERR("string too long"); \ + STORE##W(b, in.sz); poly1305_hash(P1305_CTX(me), b, sizeof(b)); \ + poly1305_hash(P1305_CTX(me), in.p, in.sz); \ + RETURN_ME; \ + end: \ + return (0); \ + } +DOUINTCONV(POLYMETH_HASHBUF_) + +static PyObject *polymeth_hashstrz(PyObject *me, PyObject *arg) +{ + char *p; + if (!PyArg_ParseTuple(arg, "s:hashstrz", &p)) return (0); + poly1305_hash(P1305_CTX(me), p, strlen(p) + 1); + RETURN_ME; +} + +static PyObject *polymeth_flush(PyObject *me) + { poly1305_flush(P1305_CTX(me)); RETURN_ME; } + +static PyObject *polymeth_flushzero(PyObject *me) + { poly1305_flushzero(P1305_CTX(me)); RETURN_ME; } + +static PyObject *polymeth_concat(PyObject *me, PyObject *arg) +{ + PyObject *pre, *suff; + if (!PyArg_ParseTuple(arg, "OO:concat", &pre, &suff)) return (0); + if (!PyObject_TypeCheck(pre, poly1305hash_pytype) || + !PyObject_TypeCheck(suff, poly1305hash_pytype)) + TYERR("wanted a poly1305hash"); + if (Py_TYPE(me) != Py_TYPE(pre) || Py_TYPE(me) != Py_TYPE(suff)) + TYERR("key mismatch"); + if (P1305_CTX(pre)->nbuf) VALERR("prefix is not block-aligned"); + poly1305_concat(P1305_CTX(me), P1305_CTX(pre), P1305_CTX(suff)); + RETURN_ME; +end: + return (0); +} + +static PyObject *polymeth_done(PyObject *me) +{ + PyObject *rc; + if (!(P1305_F(me) & f_mask)) VALERR("no mask"); + rc = bytestring_pywrap(0, POLY1305_TAGSZ); + poly1305_done(P1305_CTX(me), BIN_PTR(rc)); + return (rc); +end: + return (0); +} + +static const PyGetSetDef poly1305cls_pygetset[] = { +#define GETSETNAME(op, name) poly1305cls##op##_##name + GET (keysz, "PC.keysz -> acceptable key sizes") + GET (masksz, "PC.masksz -> mask size") + GET (tagsz, "PC.tagsz -> MAC output size") + GET (name, "PC.name -> name of this kind of MAC") +#undef GETSETNAME + { 0 } +}; + +static const PyMethodDef poly1305hash_pymethods[] = { +#define METHNAME(name) polymeth_##name + NAMETH(copy, "P.copy() -> PP") + METH (hash, "P.hash(M)") +#define METHU_(n, W, w) METH(hashu##w, "P.hashu" #w "(WORD)") + DOUINTCONV(METHU_) +#undef METHU_ +#define METHBUF_(n, W, w) METH(hashbuf##w, "P.hashbuf" #w "(BYTES)") + DOUINTCONV(METHBUF_) +#undef METHBUF_ + METH (hashstrz, "P.hashstrz(STRING)") + NAMETH(flush, "P.flush()") + NAMETH(flushzero, "P.flushzero()") + METH (concat, "P.concat(PREFIX, SUFFIX)") + NAMETH(done, "P.done() -> TAG") +#undef METHNAME + { 0 } +}; + +static const PyTypeObject poly1305cls_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "Poly1305Class", /* @tp_name@ */ + sizeof(PyHeapTypeObject), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Poly1305 metametaclass. Best not to ask.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + PYGETSET(poly1305cls), /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + abstract_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject poly1305key_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "poly1305", /* @tp_name@ */ + sizeof(poly1305key_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "poly1305(K): Poly1305 key.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + 0, /* @tp_methods@ */ + 0, /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + poly1305key_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static const PyTypeObject poly1305hash_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "Poly1305Hash", /* @tp_name@ */ + sizeof(poly1305hash_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Poly1305 MAC context base class.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + PYMETHODS(poly1305hash), /* @tp_methods@ */ 0, /* @tp_members@ */ 0, /* @tp_getset@ */ 0, /* @tp_base@ */ @@ -918,112 +2778,384 @@ static PyTypeObject ghash_pytype_skel = { 0 /* @tp_is_gc@ */ }; -/*----- Message authentication --------------------------------------------*/ +/*----- Special snowflake for HSalsa and HChaCha --------------------------*/ + +#define DEF_HDANCE(DANCE, HDANCE, dance, hdance) \ + static PyObject *meth_##hdance##_prf(PyObject *me, PyObject *arg) \ + { \ + dance##_ctx dance; \ + struct bin k, n; \ + PyObject *rc; \ + if (!PyArg_ParseTuple(arg, "O&O&:" #hdance "_prf", \ + convbin, &k, convbin, &n)) \ + goto end; \ + if (k.sz != keysz(k.sz, dance##_keysz)) VALERR("bad key length"); \ + if (n.sz != HDANCE##_INSZ) VALERR("bad input length"); \ + rc = bytestring_pywrap(0, HSALSA20_OUTSZ); \ + dance##_init(&dance, k.p, k.sz, 0); \ + hdance##_prf(&dance, n.p, BIN_PTR(rc)); \ + return (rc); \ + end: \ + return (0); \ + } -PyTypeObject *gcmac_pytype, *gmac_pytype, *gmhash_pytype; +DEF_HDANCE(SALSA20, HSALSA20, salsa20, hsalsa20) +DEF_HDANCE(SALSA20, HSALSA20, salsa20, hsalsa2012) +DEF_HDANCE(SALSA20, HSALSA20, salsa20, hsalsa208) -CONVFUNC(gcmac, gcmac *, GCMAC_CM) -CONVFUNC(gmac, gmac *, GMAC_M) -CONVFUNC(gmhash, ghash *, GHASH_H) +DEF_HDANCE(CHACHA, HCHACHA, chacha, hchacha20) +DEF_HDANCE(CHACHA, HCHACHA, chacha, hchacha12) +DEF_HDANCE(CHACHA, HCHACHA, chacha, hchacha8) -static PyObject *gmac_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) +/*----- Keccak-p[1600, n] -------------------------------------------------*/ + +static PyTypeObject *kxvik_pytype; + +typedef struct kxvik_pyobj { + PyObject_HEAD + keccak1600_state s; + unsigned n; +} kxvik_pyobj; + +static PyObject *kxvik_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) { - char *kwlist[] = { "k", 0 }; - char *k; - int sz; + unsigned n = 24; + kxvik_pyobj *rc = 0; + static const char *const kwlist[] = { "nround", 0 }; + if (!PyArg_ParseTupleAndKeywords(arg, kw, "|O&:new", KWLIST, + convuint, &n)) + goto end; + rc = (kxvik_pyobj *)ty->tp_alloc(ty, 0); + rc->n = n; + keccak1600_init(&rc->s); +end: + return ((PyObject *)rc); +} + +static PyObject *kxvikmeth_copy(PyObject *me) +{ + kxvik_pyobj *k = (kxvik_pyobj *)me, *rc = 0; + rc = (kxvik_pyobj *)Py_TYPE(k)->tp_alloc(Py_TYPE(k), 0); + rc->s = k->s; rc->n = k->n; + return ((PyObject *)rc); +} + +static PyObject *kxvikmeth_mix(PyObject *me, PyObject *arg) +{ + kxvik_pyobj *k = (kxvik_pyobj *)me; + kludge64 t[25]; + const octet *q; + octet buf[8]; + unsigned i; + struct bin in; + size_t n; + + if (!PyArg_ParseTuple(arg, "O&:mix", convbin, &in)) goto end; + if (in.sz > 200) VALERR("out of range"); + q = in.p; n = in.sz; + i = 0; + while (n > 8) { LOAD64_L_(t[i], q); i++; q += 8; n -= 8; } + if (n) { + memcpy(buf, q, n); memset(buf + n, 0, 8 - n); + LOAD64_L_(t[i], buf); i++; + } + keccak1600_mix(&k->s, t, i); + RETURN_ME; +end: + return (0); +} + +static PyObject *kxvikmeth_extract(PyObject *me, PyObject *arg) +{ + kxvik_pyobj *k = (kxvik_pyobj *)me; + PyObject *rc = 0; + kludge64 t[25]; + octet *q, buf[8]; + unsigned i; + unsigned n; + + if (!PyArg_ParseTuple(arg, "O&:extract", convuint, &n)) goto end; + if (n > 200) VALERR("out of range"); + rc = bytestring_pywrap(0, n); + q = (octet *)BIN_PTR(rc); + keccak1600_extract(&k->s, t, (n + 7)/8); + i = 0; + while (n > 8) { STORE64_L_(q, t[i]); i++; q += 8; n -= 8; } + if (n) { STORE64_L_(buf, t[i]); memcpy(q, buf, n); } +end: + return (rc); +} + +static PyObject *kxvikmeth_step(PyObject *me) +{ + kxvik_pyobj *k = (kxvik_pyobj *)me; + keccak1600_p(&k->s, &k->s, k->n); + RETURN_ME; +} + +static const PyMemberDef kxvik_pymembers[] = { +#define MEMBERSTRUCT kxvik_pyobj + MEMRNM(nround, T_UINT, n, 0, "KECCAC.nround -> number of rounds") +#undef MEMBERSTRUCT + { 0 } +}; + +static const PyMethodDef kxvik_pymethods[] = { +#define METHNAME(func) kxvikmeth_##func + NAMETH(copy, "KECCAK.copy() -> KECCAK'") + METH (mix, "KECCAK.mix(DATA)") + METH (extract, "KECCAK.extract(NOCTETS)") + NAMETH(step, "KECCAK.step()") +#undef METHNAME + { 0 } +}; + +static const PyTypeObject kxvik_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "Keccak1600", /* @tp_name@ */ + sizeof(kxvik_pyobj), /* @tp_basicsize@ */ + 0, /* @tp_itemsize@ */ + + 0, /* @tp_dealloc@ */ + 0, /* @tp_print@ */ + 0, /* @tp_getattr@ */ + 0, /* @tp_setattr@ */ + 0, /* @tp_compare@ */ + 0, /* @tp_repr@ */ + 0, /* @tp_as_number@ */ + 0, /* @tp_as_sequence@ */ + 0, /* @tp_as_mapping@ */ + 0, /* @tp_hash@ */ + 0, /* @tp_call@ */ + 0, /* @tp_str@ */ + 0, /* @tp_getattro@ */ + 0, /* @tp_setattro@ */ + 0, /* @tp_as_buffer@ */ + Py_TPFLAGS_DEFAULT | /* @tp_flags@ */ + Py_TPFLAGS_BASETYPE, + + /* @tp_doc@ */ + "Keccak1600([nround = 24]): Keccak-p[1600, n] state.", + + 0, /* @tp_traverse@ */ + 0, /* @tp_clear@ */ + 0, /* @tp_richcompare@ */ + 0, /* @tp_weaklistoffset@ */ + 0, /* @tp_iter@ */ + 0, /* @tp_iternext@ */ + PYMETHODS(kxvik), /* @tp_methods@ */ + PYMEMBERS(kxvik), /* @tp_members@ */ + 0, /* @tp_getset@ */ + 0, /* @tp_base@ */ + 0, /* @tp_dict@ */ + 0, /* @tp_descr_get@ */ + 0, /* @tp_descr_set@ */ + 0, /* @tp_dictoffset@ */ + 0, /* @tp_init@ */ + PyType_GenericAlloc, /* @tp_alloc@ */ + kxvik_pynew, /* @tp_new@ */ + 0, /* @tp_free@ */ + 0 /* @tp_is_gc@ */ +}; + +static PyTypeObject *shake_pytype, *shake128_pytype, *shake256_pytype; + +typedef struct shake_pyobj { + PyObject_HEAD + int st; + shake_ctx h; +} shake_pyobj; + +#define SHAKE_H(o) (&((shake_pyobj *)(o))->h) +#define SHAKE_ST(o) (((shake_pyobj *)(o))->st) + +static PyObject *shake_dopynew(void (*initfn)(shake_ctx *, + const void *, size_t, + const void *, size_t), + PyTypeObject *ty, + PyObject *arg, PyObject *kw) +{ + shake_pyobj *rc = 0; + struct bin p = { 0, 0 }, f = { 0, 0 }; + static const char *const kwlist[] = { "perso", "func", 0 }; - if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#:new", kwlist, &k, &sz)) + if (!PyArg_ParseTupleAndKeywords(arg, kw, "|O&O&:new", KWLIST, + convbin, &p, convbin, &f)) goto end; - if (keysz(sz, GCMAC_CM(ty)->keysz) != sz) VALERR("bad key length"); - return (gmac_pywrap((PyObject *)ty, - GM_KEY(GCMAC_CM(ty), k, sz), - f_freeme)); + rc = (shake_pyobj *)ty->tp_alloc(ty, 0); + initfn(&rc->h, f.p, f.sz, p.p, p.sz); + rc->st = 0; end: + return ((PyObject *)rc); +} + +static PyObject *shake128_pynew(PyTypeObject *ty, + PyObject *arg, PyObject *kw) + { return (shake_dopynew(cshake128_init, ty, arg, kw)); } + +static PyObject *shake256_pynew(PyTypeObject *ty, + PyObject *arg, PyObject *kw) + { return (shake_dopynew(cshake256_init, ty, arg, kw)); } + +static int shake_check(PyObject *me, int st) +{ + if (SHAKE_ST(me) != st) VALERR("wrong state"); return (0); +end: + return (-1); } -static PyObject *gmhash_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) +static PyObject *shakemeth_hash(PyObject *me, PyObject *arg) { - char *kwlist[] = { 0 }; - ghash_pyobj *g; + struct bin m; + if (!PyArg_ParseTuple(arg, "O&:hash", convbin, &m)) return (0); + if (shake_check(me, 0)) return (0); + shake_hash(SHAKE_H(me), m.p, m.sz); + RETURN_ME; +} - if (!PyArg_ParseTupleAndKeywords(arg, kw, ":new", kwlist)) return (0); - g = PyObject_NEW(ghash_pyobj, ty); - g->h = GM_INIT(GMAC_M(ty)); - g->f = f_freeme; - Py_INCREF(ty); - return ((PyObject *)g); +#define SHAKEMETH_HASHU_(n, W, w) \ + static PyObject *shakemeth_hashu##w(PyObject *me, PyObject *arg) \ + { \ + uint##n x; \ + octet b[SZ_##W]; \ + if (!PyArg_ParseTuple(arg, "O&:hashu" #w, convu##n, &x)) return (0); \ + if (shake_check(me, 0)) return (0); \ + STORE##W(b, x); shake_hash(SHAKE_H(me), b, sizeof(b)); \ + RETURN_ME; \ + } +DOUINTCONV(SHAKEMETH_HASHU_) + +#define SHAKEMETH_HASHBUF_(n, W, w) \ + static PyObject *shakemeth_hashbuf##w(PyObject *me, PyObject *arg) \ + { \ + struct bin in; \ + octet b[SZ_##W]; \ + if (!PyArg_ParseTuple(arg, "O&:hashbuf" #w, convbin, &in)) goto end; \ + if (in.sz > MASK##n) TYERR("string too long"); \ + if (shake_check(me, 0)) goto end; \ + STORE##W(b, in.sz); shake_hash(SHAKE_H(me), b, sizeof(b)); \ + shake_hash(SHAKE_H(me), in.p, in.sz); \ + RETURN_ME; \ + end: \ + return (0); \ + } +DOUINTCONV(SHAKEMETH_HASHBUF_) + +static PyObject *shakemeth_hashstrz(PyObject *me, PyObject *arg) +{ + char *p; + if (!PyArg_ParseTuple(arg, "s:hashstrz", &p)) return (0); + if (shake_check(me, 0)) return (0); + shake_hash(SHAKE_H(me), p, strlen(p) + 1); + RETURN_ME; } -PyObject *gcmac_pywrap(gcmac *cm) +static PyObject *shakemeth_xof(PyObject *me) { - gcmac_pyobj *g = newtype(gcmac_pytype, 0, cm->name); - g->cm = cm; - g->ty.ht_type.tp_basicsize = sizeof(gmac_pyobj); - g->ty.ht_type.tp_base = gmac_pytype; - Py_INCREF(gmac_pytype); - g->ty.ht_type.tp_flags = (Py_TPFLAGS_DEFAULT | - Py_TPFLAGS_BASETYPE | - Py_TPFLAGS_HEAPTYPE); - g->ty.ht_type.tp_alloc = PyType_GenericAlloc; - g->ty.ht_type.tp_free = 0; - g->ty.ht_type.tp_new = gmac_pynew; - PyType_Ready(&g->ty.ht_type); - return ((PyObject *)g); + if (shake_check(me, 0)) goto end; + shake_xof(SHAKE_H(me)); + SHAKE_ST(me) = 1; + RETURN_ME; +end: + return (0); } -PyObject *gmac_pywrap(PyObject *cobj, gmac *m, unsigned f) +static PyObject *shakemeth_done(PyObject *me, PyObject *arg) { - gmac_pyobj *g; - if (!cobj) cobj = gcmac_pywrap((/*unconst*/ gcmac *)GM_CLASS(m)); - else Py_INCREF(cobj); - g = newtype((PyTypeObject *)cobj, 0, 0); - g->ty.ht_name = PyString_FromFormat("%s(keyed)", m->ops->c->name); - g->ty.ht_type.tp_name = PyString_AS_STRING(g->ty.ht_name); - g->ty.ht_type.tp_base = gmhash_pytype; - Py_INCREF(gmac_pytype); - g->ty.ht_type.tp_flags = (Py_TPFLAGS_DEFAULT | - Py_TPFLAGS_BASETYPE | - Py_TPFLAGS_HEAPTYPE); - g->ty.ht_type.tp_alloc = PyType_GenericAlloc; - g->ty.ht_type.tp_free = 0; - g->ty.ht_type.tp_new = gmhash_pynew; - PyType_Ready(&g->ty.ht_type); - g->m = m; - g->f = f; - return ((PyObject *)g); + PyObject *rc = 0; + size_t n; + if (!PyArg_ParseTuple(arg, "O&:done", convszt, &n)) goto end; + if (shake_check(me, 0)) goto end; + rc = bytestring_pywrap(0, n); + shake_done(SHAKE_H(me), BIN_PTR(rc), n); + SHAKE_ST(me) = -1; +end: + return (rc); } -static void gmac_pydealloc(PyObject *me) +static PyObject *shakemeth_copy(PyObject *me) { - if (GMAC_F(me) & f_freeme) - GM_DESTROY(GMAC_M(me)); - Py_DECREF(me->ob_type); - PyType_Type.tp_dealloc(me); + shake_pyobj *rc = 0; + + rc = PyObject_NEW(shake_pyobj, Py_TYPE(me)); + rc->h = *SHAKE_H(me); + rc->st = SHAKE_ST(me); + return ((PyObject *)rc); } -static PyObject *gcmget_name(PyObject *me, void *hunoz) - { return (PyString_FromString(GCMAC_CM(me)->name)); } +static PyObject *shakemeth_get(PyObject *me, PyObject *arg) +{ + PyObject *rc = 0; + size_t sz; -static PyObject *gcmget_keysz(PyObject *me, void *hunoz) - { return (keysz_pywrap(GCMAC_CM(me)->keysz)); } + if (!PyArg_ParseTuple(arg, "O&:get", convszt, &sz)) goto end; + if (shake_check(me, 1)) goto end; + rc = bytestring_pywrap(0, sz); + shake_get(SHAKE_H(me), BIN_PTR(rc), sz); +end: + return (rc); +} -static PyObject *gcmget_tagsz(PyObject *me, void *hunoz) - { return (PyInt_FromLong(GCMAC_CM(me)->hashsz)); } +static PyObject *shakemeth_mask(PyObject *me, PyObject *arg) +{ + PyObject *rc = 0; + struct bin in; -static PyGetSetDef gcmac_pygetset[] = { -#define GETSETNAME(op, name) gcm##op##_##name - GET (keysz, "CM.keysz -> acceptable key sizes") - GET (tagsz, "CM.tagsz -> MAC output size") - GET (name, "CM.name -> name of this kind of MAC") + if (!PyArg_ParseTuple(arg, "O&:mask", convbin, &in)) goto end; + if (shake_check(me, 1)) goto end; + rc = bytestring_pywrap(0, in.sz); + shake_mask(SHAKE_H(me), in.p, BIN_PTR(rc), in.sz); +end: + return (rc); +} + +static PyObject *shakeget_state(PyObject *me, void *hunoz) +{ + int st = SHAKE_ST(me); + return (TEXT_FROMSTR(st == 0 ? "absorb" : + st == 1 ? "squeeze" : "dead")); +} + +static const PyMemberDef shake_pymembers[] = { +#define MEMBERSTRUCT shake_pyobj + MEMRNM(rate, T_UINT, h.h.r, READONLY, "S.rate -> rate, in bytes") + MEMRNM(buffered, T_UINT, h.h.n, READONLY, + "S.buffered -> amount currently buffered") +#undef MEMBERSTRUCT + { 0 } +}; + +static const PyGetSetDef shake_pygetset[] = { +#define GETSETNAME(op, name) shake##op##_##name + GET (state, "S.state -> `absorb', `squeeze', `dead'") #undef GETSETNAME { 0 } }; -static PyTypeObject gcmac_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.GCMAC", /* @tp_name@ */ - sizeof(gchash_pyobj), /* @tp_basicsize@ */ +static const PyMethodDef shake_pymethods[] = { +#define METHNAME(func) shakemeth_##func + NAMETH(copy, "S.copy() -> SS") + METH (hash, "S.hash(M)") +#define METHU_(n, W, w) METH(hashu##w, "S.hashu" #w "(WORD)") + DOUINTCONV(METHU_) +#undef METHU_ +#define METHBUF_(n, W, w) METH(hashbuf##w, "S.hashbuf" #w "(BYTES)") + DOUINTCONV(METHBUF_) +#undef METHBUF_ + METH (hashstrz, "S.hashstrz(STRING)") + NAMETH(xof, "S.xof()") + METH (done, "S.done(LEN) -> H") + METH (get, "S.get(LEN) -> H") + METH (mask, "S.mask(M) -> C") +#undef METHNAME + { 0 } +}; + +static const PyTypeObject shake_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "Shake", /* @tp_name@ */ + sizeof(shake_pyobj), /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ 0, /* @tp_dealloc@ */ @@ -1045,7 +3177,7 @@ static PyTypeObject gcmac_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Message authentication code metametaclass.", + "SHAKE/cSHAKE/KMAC base class.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -1053,9 +3185,9 @@ static PyTypeObject gcmac_pytype_skel = { 0, /* @tp_weaklistoffset@ */ 0, /* @tp_iter@ */ 0, /* @tp_iternext@ */ - 0, /* @tp_methods@ */ - 0, /* @tp_members@ */ - gcmac_pygetset, /* @tp_getset@ */ + PYMETHODS(shake), /* @tp_methods@ */ + PYMEMBERS(shake), /* @tp_members@ */ + PYGETSET(shake), /* @tp_getset@ */ 0, /* @tp_base@ */ 0, /* @tp_dict@ */ 0, /* @tp_descr_get@ */ @@ -1068,13 +3200,13 @@ static PyTypeObject gcmac_pytype_skel = { 0 /* @tp_is_gc@ */ }; -static PyTypeObject gmac_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.GMAC", /* @tp_name@ */ - sizeof(gmac_pyobj), /* @tp_basicsize@ */ +static const PyTypeObject shake128_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "Shake128", /* @tp_name@ */ + 0, /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ - gmac_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_dealloc@ */ 0, /* @tp_print@ */ 0, /* @tp_getattr@ */ 0, /* @tp_setattr@ */ @@ -1093,7 +3225,7 @@ static PyTypeObject gmac_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Message authentication code metaclass, abstract base class.", + "Shake128([perso = STR], [func = STR]): SHAKE128/cSHAKE128 XOF.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -1111,18 +3243,18 @@ static PyTypeObject gmac_pytype_skel = { 0, /* @tp_dictoffset@ */ 0, /* @tp_init@ */ PyType_GenericAlloc, /* @tp_alloc@ */ - abstract_pynew, /* @tp_new@ */ + shake128_pynew, /* @tp_new@ */ 0, /* @tp_free@ */ 0 /* @tp_is_gc@ */ }; -static PyTypeObject gmhash_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.GMACHash", /* @tp_name@ */ - sizeof(ghash_pyobj), /* @tp_basicsize@ */ +static const PyTypeObject shake256_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "Shake256", /* @tp_name@ */ + 0, /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ - ghash_pydealloc, /* @tp_dealloc@ */ + 0, /* @tp_dealloc@ */ 0, /* @tp_print@ */ 0, /* @tp_getattr@ */ 0, /* @tp_setattr@ */ @@ -1141,7 +3273,7 @@ static PyTypeObject gmhash_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Message authentication code, abstract base class.", + "Shake256([perso = STR], [func = STR]): SHAKE256/cSHAKE256 XOF.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -1159,7 +3291,7 @@ static PyTypeObject gmhash_pytype_skel = { 0, /* @tp_dictoffset@ */ 0, /* @tp_init@ */ PyType_GenericAlloc, /* @tp_alloc@ */ - abstract_pynew, /* @tp_new@ */ + shake256_pynew, /* @tp_new@ */ 0, /* @tp_free@ */ 0 /* @tp_is_gc@ */ }; @@ -1223,18 +3355,17 @@ typedef struct prp { static PyObject *gprp_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw) { - char *kwlist[] = { "key", 0 }; - char *k; - int sz; + static const char *const kwlist[] = { "key", 0 }; + struct bin k; const prpinfo *prp = GCPRP_PRP(ty); PyObject *me; - if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#:new", kwlist, &k, &sz)) + if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&:new", KWLIST, convbin, &k)) goto end; - if (keysz(sz, prp->keysz) != sz) VALERR("bad key length"); + if (keysz(k.sz, prp->keysz) != k.sz) VALERR("bad key length"); me = (PyObject *)ty->tp_alloc(ty, 0); GPRP_PRP(me) = prp; - prp->init(GPRP_CTX(me), k, sz); + prp->init(GPRP_CTX(me), k.p, k.sz); Py_INCREF(me); return (me); end: @@ -1242,7 +3373,7 @@ end: } static void gprp_pydealloc(PyObject *me) - { Py_DECREF(me->ob_type); FREEOBJ(me); } + { Py_DECREF(Py_TYPE(me)); FREEOBJ(me); } static PyObject *gcprp_pywrap(const prpinfo *prp) { @@ -1257,12 +3388,12 @@ static PyObject *gcprp_pywrap(const prpinfo *prp) g->ty.ht_type.tp_alloc = PyType_GenericAlloc; g->ty.ht_type.tp_free = 0; g->ty.ht_type.tp_new = gprp_pynew; - PyType_Ready(&g->ty.ht_type); + typeready(&g->ty.ht_type); return ((PyObject *)g); } static PyObject *gcpget_name(PyObject *me, void *hunoz) - { return (PyString_FromString(GCPRP_PRP(me)->name)); } + { return (TEXT_FROMSTR(GCPRP_PRP(me)->name)); } static PyObject *gcpget_keysz(PyObject *me, void *hunoz) { return (keysz_pywrap(GCPRP_PRP(me)->keysz)); } static PyObject *gcpget_blksz(PyObject *me, void *hunoz) @@ -1270,52 +3401,50 @@ static PyObject *gcpget_blksz(PyObject *me, void *hunoz) static PyObject *gpmeth_encrypt(PyObject *me, PyObject *arg) { - char *p; - int n; + struct bin m; PyObject *rc = 0; - if (!PyArg_ParseTuple(arg, "s#:encrypt", &p, &n)) goto end; - if (n != GPRP_PRP(me)->blksz) VALERR("incorrect block length"); - rc = bytestring_pywrap(0, n); - GPRP_PRP(me)->eblk(GPRP_CTX(me), p, PyString_AS_STRING(rc)); + if (!PyArg_ParseTuple(arg, "O&:encrypt", convbin, &m)) goto end; + if (m.sz != GPRP_PRP(me)->blksz) VALERR("incorrect block length"); + rc = bytestring_pywrap(0, m.sz); + GPRP_PRP(me)->eblk(GPRP_CTX(me), m.p, BIN_PTR(rc)); end: return (rc); } static PyObject *gpmeth_decrypt(PyObject *me, PyObject *arg) { - char *p; - int n; + struct bin c; PyObject *rc = 0; - if (!PyArg_ParseTuple(arg, "s#:decrypt", &p, &n)) goto end; - if (n != GPRP_PRP(me)->blksz) VALERR("incorrect block length"); - rc = bytestring_pywrap(0, n); - GPRP_PRP(me)->dblk(GPRP_CTX(me), p, PyString_AS_STRING(rc)); + if (!PyArg_ParseTuple(arg, "O&:decrypt", convbin, &c)) goto end; + if (c.sz != GPRP_PRP(me)->blksz) VALERR("incorrect block length"); + rc = bytestring_pywrap(0, c.sz); + GPRP_PRP(me)->dblk(GPRP_CTX(me), c.p, BIN_PTR(rc)); end: return (rc); } -static PyGetSetDef gcprp_pygetset[] = { +static const PyGetSetDef gcprp_pygetset[] = { #define GETSETNAME(op, name) gcp##op##_##name - GET (keysz, "CP.keysz -> acceptable key sizes") - GET (blksz, "CP.blksz -> block size") - GET (name, "CP.name -> name of this kind of PRP") + GET (keysz, "CP.keysz -> acceptable key sizes") + GET (blksz, "CP.blksz -> block size") + GET (name, "CP.name -> name of this kind of PRP") #undef GETSETNAME { 0 } }; -static PyMethodDef gprp_pymethods[] = { +static const PyMethodDef gprp_pymethods[] = { #define METHNAME(name) gpmeth_##name - METH (encrypt, "P.encrypt(PT) -> CT") - METH (decrypt, "P.decrypt(CT) -> PT") + METH (encrypt, "P.encrypt(PT) -> CT") + METH (decrypt, "P.decrypt(CT) -> PT") #undef METHNAME { 0 } }; -static PyTypeObject gcprp_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.GCPRP", /* @tp_name@ */ +static const PyTypeObject gcprp_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GCPRP", /* @tp_name@ */ sizeof(gcprp_pyobj), /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ @@ -1338,7 +3467,7 @@ static PyTypeObject gcprp_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Pseudorandom permutation metaclass.", + "Pseudorandom permutation metaclass.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -1348,7 +3477,7 @@ static PyTypeObject gcprp_pytype_skel = { 0, /* @tp_iternext@ */ 0, /* @tp_methods@ */ 0, /* @tp_members@ */ - gcprp_pygetset, /* @tp_getset@ */ + PYGETSET(gcprp), /* @tp_getset@ */ 0, /* @tp_base@ */ 0, /* @tp_dict@ */ 0, /* @tp_descr_get@ */ @@ -1361,9 +3490,9 @@ static PyTypeObject gcprp_pytype_skel = { 0 /* @tp_is_gc@ */ }; -static PyTypeObject gprp_pytype_skel = { - PyObject_HEAD_INIT(0) 0, /* Header */ - "catacomb.GPRP", /* @tp_name@ */ +static const PyTypeObject gprp_pytype_skel = { + PyVarObject_HEAD_INIT(0, 0) /* Header */ + "GPRP", /* @tp_name@ */ sizeof(gprp_pyobj), /* @tp_basicsize@ */ 0, /* @tp_itemsize@ */ @@ -1386,7 +3515,7 @@ static PyTypeObject gprp_pytype_skel = { Py_TPFLAGS_BASETYPE, /* @tp_doc@ */ -"Pseudorandom permutation, abstract base class.", + "Pseudorandom permutation, abstract base class.", 0, /* @tp_traverse@ */ 0, /* @tp_clear@ */ @@ -1394,7 +3523,7 @@ static PyTypeObject gprp_pytype_skel = { 0, /* @tp_weaklistoffset@ */ 0, /* @tp_iter@ */ 0, /* @tp_iternext@ */ - gprp_pymethods, /* @tp_methods@ */ + PYMETHODS(gprp), /* @tp_methods@ */ 0, /* @tp_members@ */ 0, /* @tp_getset@ */ 0, /* @tp_base@ */ @@ -1411,6 +3540,27 @@ static PyTypeObject gprp_pytype_skel = { /*----- Main code ---------------------------------------------------------*/ +static const struct nameval consts[] = { + CONST(AEADF_PCHSZ), CONST(AEADF_PCMSZ), CONST(AEADF_PCTSZ), + CONST(AEADF_AADNDEP), CONST(AEADF_AADFIRST), CONST(AEADF_NOAAD), + { 0 } +}; + +static const PyMethodDef methods[] = { +#define METHNAME(func) meth_##func +#define METH_HDANCE(hdance, HDance) METH(hdance##_prf, \ + "" #hdance "_prf(K, N) -> H: calculate " HDance " hash of N with K") + METH_HDANCE(hsalsa20, "HSalsa20") + METH_HDANCE(hsalsa2012, "HSalsa20/12") + METH_HDANCE(hsalsa208, "HSalsa20/8") + METH_HDANCE(hchacha20, "HChaCha20") + METH_HDANCE(hchacha12, "HChaCha12") + METH_HDANCE(hchacha8, "HChaCha8") +#undef METH_DANCE +#undef METHNAME + { 0 } +}; + void algorithms_pyinit(void) { INITTYPE(keysz, root); @@ -1419,20 +3569,39 @@ void algorithms_pyinit(void) INITTYPE(keyszset, keysz); INITTYPE(gccipher, type); INITTYPE(gcipher, root); + INITTYPE(gcaead, type); + INITTYPE(gaeadkey, root); + INITTYPE(gcaeadaad, type); + INITTYPE(gaeadaad, root); + INITTYPE(gcaeadenc, type); + INITTYPE(gaeadenc, root); + INITTYPE(gcaeaddec, type); + INITTYPE(gaeaddec, root); INITTYPE(gchash, type); INITTYPE(ghash, root); INITTYPE(gcmac, type); INITTYPE(gmac, type); INITTYPE(gmhash, ghash); + INITTYPE(poly1305cls, type); + INITTYPE_META(poly1305key, type, poly1305cls); + INITTYPE(poly1305hash, root); + INITTYPE(kxvik, root); + INITTYPE(shake, root); + INITTYPE(shake128, shake); + INITTYPE(shake256, shake); INITTYPE(gcprp, type); INITTYPE(gprp, root); + addmethods(methods); } -GEN(gcciphers, cipher) -GEN(gchashes, hash) -GEN(gcmacs, mac) #define gcprp prpinfo -GEN(gcprps, prp) +#define CLASS_TABLES(_) _(cipher) _(aead) _(hash) _(mac) _(prp) +#define TABLE_FNS(pre) \ + static const char *pre##_namefn(const void *p) \ + { const gc##pre *const *cls = p; return (*cls ? (*cls)->name : 0); } \ + static PyObject *pre##_valfn(const void *p) \ + { gc##pre *const*cls = p; return (gc##pre##_pywrap(*cls)); } +CLASS_TABLES(TABLE_FNS) void algorithms_pyinsert(PyObject *mod) { @@ -1443,19 +3612,41 @@ void algorithms_pyinsert(PyObject *mod) INSERT("KeySZSet", keyszset_pytype); INSERT("GCCipher", gccipher_pytype); INSERT("GCipher", gcipher_pytype); - INSERT("gcciphers", gcciphers()); + INSERT("gcciphers", make_algtab(gciphertab, sizeof(gccipher *), + cipher_namefn, cipher_valfn)); + INSERT("GCAEAD", gcaead_pytype); + INSERT("GAEKey", gaeadkey_pytype); + INSERT("GAEAADClass", gcaeadaad_pytype); + INSERT("GAEAAD", gaeadaad_pytype); + INSERT("GAEEncClass", gcaeadenc_pytype); + INSERT("GAEEnc", gaeadenc_pytype); + INSERT("GAEDecClass", gcaeaddec_pytype); + INSERT("GAEDec", gaeaddec_pytype); + INSERT("gcaeads", make_algtab(gaeadtab, sizeof(gcaead *), + aead_namefn, aead_valfn)); INSERT("GCHash", gchash_pytype); INSERT("GHash", ghash_pytype); - INSERT("gchashes", d = gchashes()); - sha_pyobj = PyDict_GetItemString(d, "sha"); Py_INCREF(sha_pyobj); - has160_pyobj = PyDict_GetItemString(d, "has160"); Py_INCREF(has160_pyobj); + d = make_algtab(ghashtab, sizeof(gchash *), hash_namefn, hash_valfn); + INSERT("gchashes", d); + sha_pyobj = PyMapping_GetItemString(d, "sha"); Py_INCREF(sha_pyobj); + has160_pyobj = PyMapping_GetItemString(d, "has160"); Py_INCREF(has160_pyobj); INSERT("GCMAC", gcmac_pytype); INSERT("GMAC", gmac_pytype); INSERT("GMACHash", gmhash_pytype); - INSERT("gcmacs", gcmacs()); + INSERT("gcmacs", make_algtab(gmactab, sizeof(gcmac *), + mac_namefn, mac_valfn)); + INSERT("Poly1305Class", poly1305cls_pytype); + INSERT("poly1305", poly1305key_pytype); + INSERT("Poly1305Hash", poly1305hash_pytype); + INSERT("Keccak1600", kxvik_pytype); + INSERT("Shake", shake_pytype); + INSERT("Shake128", shake128_pytype); + INSERT("Shake256", shake256_pytype); INSERT("GCPRP", gcprp_pytype); INSERT("GPRP", gprp_pytype); - INSERT("gcprps", gcprps()); + INSERT("gcprps", make_algtab(gprptab, sizeof(gcprp *), + prp_namefn, prp_valfn)); + setconstants(mod, consts); } /*----- That's all, folks -------------------------------------------------*/