xref: /freebsd/sys/crypto/skein/skein.h (revision 71625ec9ad2a9bc8c09784fbd23b759830e0ee5f)
1*b468a9ffSAllan Jude #ifndef _SKEIN_H_
2*b468a9ffSAllan Jude #define _SKEIN_H_     1
3*b468a9ffSAllan Jude /**************************************************************************
4*b468a9ffSAllan Jude **
5*b468a9ffSAllan Jude ** Interface declarations and internal definitions for Skein hashing.
6*b468a9ffSAllan Jude **
7*b468a9ffSAllan Jude ** Source code author: Doug Whiting, 2008.
8*b468a9ffSAllan Jude **
9*b468a9ffSAllan Jude ** This algorithm and source code is released to the public domain.
10*b468a9ffSAllan Jude **
11*b468a9ffSAllan Jude ***************************************************************************
12*b468a9ffSAllan Jude **
13*b468a9ffSAllan Jude ** The following compile-time switches may be defined to control some
14*b468a9ffSAllan Jude ** tradeoffs between speed, code size, error checking, and security.
15*b468a9ffSAllan Jude **
16*b468a9ffSAllan Jude ** The "default" note explains what happens when the switch is not defined.
17*b468a9ffSAllan Jude **
18*b468a9ffSAllan Jude **  SKEIN_DEBUG            -- make callouts from inside Skein code
19*b468a9ffSAllan Jude **                            to examine/display intermediate values.
20*b468a9ffSAllan Jude **                            [default: no callouts (no overhead)]
21*b468a9ffSAllan Jude **
22*b468a9ffSAllan Jude **  SKEIN_ERR_CHECK        -- how error checking is handled inside Skein
23*b468a9ffSAllan Jude **                            code. If not defined, most error checking
24*b468a9ffSAllan Jude **                            is disabled (for performance). Otherwise,
25*b468a9ffSAllan Jude **                            the switch value is interpreted as:
26*b468a9ffSAllan Jude **                                0: use assert()      to flag errors
27*b468a9ffSAllan Jude **                                1: return SKEIN_FAIL to flag errors
28*b468a9ffSAllan Jude **
29*b468a9ffSAllan Jude ***************************************************************************/
30*b468a9ffSAllan Jude #ifdef __cplusplus
31*b468a9ffSAllan Jude extern "C"
32*b468a9ffSAllan Jude {
33*b468a9ffSAllan Jude #endif
34*b468a9ffSAllan Jude 
35*b468a9ffSAllan Jude #ifndef _KERNEL
36*b468a9ffSAllan Jude #include <stddef.h>                          /* get size_t definition */
37*b468a9ffSAllan Jude #endif
38*b468a9ffSAllan Jude #include "skein_port.h"                      /* get platform-specific definitions */
39*b468a9ffSAllan Jude 
40*b468a9ffSAllan Jude enum
41*b468a9ffSAllan Jude     {
42*b468a9ffSAllan Jude     SKEIN_SUCCESS         =      0,          /* return codes from Skein calls */
43*b468a9ffSAllan Jude     SKEIN_FAIL            =      1,
44*b468a9ffSAllan Jude     SKEIN_BAD_HASHLEN     =      2
45*b468a9ffSAllan Jude     };
46*b468a9ffSAllan Jude 
47*b468a9ffSAllan Jude #define  SKEIN_MODIFIER_WORDS  ( 2)          /* number of modifier (tweak) words */
48*b468a9ffSAllan Jude 
49*b468a9ffSAllan Jude #define  SKEIN_256_STATE_WORDS ( 4)
50*b468a9ffSAllan Jude #define  SKEIN_512_STATE_WORDS ( 8)
51*b468a9ffSAllan Jude #define  SKEIN1024_STATE_WORDS (16)
52*b468a9ffSAllan Jude #define  SKEIN_MAX_STATE_WORDS (16)
53*b468a9ffSAllan Jude 
54*b468a9ffSAllan Jude #define  SKEIN_256_STATE_BYTES ( 8*SKEIN_256_STATE_WORDS)
55*b468a9ffSAllan Jude #define  SKEIN_512_STATE_BYTES ( 8*SKEIN_512_STATE_WORDS)
56*b468a9ffSAllan Jude #define  SKEIN1024_STATE_BYTES ( 8*SKEIN1024_STATE_WORDS)
57*b468a9ffSAllan Jude 
58*b468a9ffSAllan Jude #define  SKEIN_256_STATE_BITS  (64*SKEIN_256_STATE_WORDS)
59*b468a9ffSAllan Jude #define  SKEIN_512_STATE_BITS  (64*SKEIN_512_STATE_WORDS)
60*b468a9ffSAllan Jude #define  SKEIN1024_STATE_BITS  (64*SKEIN1024_STATE_WORDS)
61*b468a9ffSAllan Jude 
62*b468a9ffSAllan Jude #define  SKEIN_256_BLOCK_BYTES ( 8*SKEIN_256_STATE_WORDS)
63*b468a9ffSAllan Jude #define  SKEIN_512_BLOCK_BYTES ( 8*SKEIN_512_STATE_WORDS)
64*b468a9ffSAllan Jude #define  SKEIN1024_BLOCK_BYTES ( 8*SKEIN1024_STATE_WORDS)
65*b468a9ffSAllan Jude 
66*b468a9ffSAllan Jude typedef struct
67*b468a9ffSAllan Jude     {
68*b468a9ffSAllan Jude     size_t  hashBitLen;                      /* size of hash result, in bits */
69*b468a9ffSAllan Jude     size_t  bCnt;                            /* current byte count in buffer b[] */
70*b468a9ffSAllan Jude     u64b_t  T[SKEIN_MODIFIER_WORDS];         /* tweak words: T[0]=byte cnt, T[1]=flags */
71*b468a9ffSAllan Jude     } Skein_Ctxt_Hdr_t;
72*b468a9ffSAllan Jude 
73*b468a9ffSAllan Jude typedef struct                               /*  256-bit Skein hash context structure */
74*b468a9ffSAllan Jude     {
75*b468a9ffSAllan Jude     Skein_Ctxt_Hdr_t h;                      /* common header context variables */
76*b468a9ffSAllan Jude     u64b_t  X[SKEIN_256_STATE_WORDS];        /* chaining variables */
77*b468a9ffSAllan Jude     u08b_t  b[SKEIN_256_BLOCK_BYTES];        /* partial block buffer (8-byte aligned) */
78*b468a9ffSAllan Jude     } Skein_256_Ctxt_t;
79*b468a9ffSAllan Jude 
80*b468a9ffSAllan Jude typedef struct                               /*  512-bit Skein hash context structure */
81*b468a9ffSAllan Jude     {
82*b468a9ffSAllan Jude     Skein_Ctxt_Hdr_t h;                      /* common header context variables */
83*b468a9ffSAllan Jude     u64b_t  X[SKEIN_512_STATE_WORDS];        /* chaining variables */
84*b468a9ffSAllan Jude     u08b_t  b[SKEIN_512_BLOCK_BYTES];        /* partial block buffer (8-byte aligned) */
85*b468a9ffSAllan Jude     } Skein_512_Ctxt_t;
86*b468a9ffSAllan Jude 
87*b468a9ffSAllan Jude typedef struct                               /* 1024-bit Skein hash context structure */
88*b468a9ffSAllan Jude     {
89*b468a9ffSAllan Jude     Skein_Ctxt_Hdr_t h;                      /* common header context variables */
90*b468a9ffSAllan Jude     u64b_t  X[SKEIN1024_STATE_WORDS];        /* chaining variables */
91*b468a9ffSAllan Jude     u08b_t  b[SKEIN1024_BLOCK_BYTES];        /* partial block buffer (8-byte aligned) */
92*b468a9ffSAllan Jude     } Skein1024_Ctxt_t;
93*b468a9ffSAllan Jude 
94*b468a9ffSAllan Jude /*   Skein APIs for (incremental) "straight hashing" */
95*b468a9ffSAllan Jude int  Skein_256_Init  (Skein_256_Ctxt_t *ctx, size_t hashBitLen);
96*b468a9ffSAllan Jude int  Skein_512_Init  (Skein_512_Ctxt_t *ctx, size_t hashBitLen);
97*b468a9ffSAllan Jude int  Skein1024_Init  (Skein1024_Ctxt_t *ctx, size_t hashBitLen);
98*b468a9ffSAllan Jude 
99*b468a9ffSAllan Jude int  Skein_256_Update(Skein_256_Ctxt_t *ctx, const u08b_t *msg, size_t msgByteCnt);
100*b468a9ffSAllan Jude int  Skein_512_Update(Skein_512_Ctxt_t *ctx, const u08b_t *msg, size_t msgByteCnt);
101*b468a9ffSAllan Jude int  Skein1024_Update(Skein1024_Ctxt_t *ctx, const u08b_t *msg, size_t msgByteCnt);
102*b468a9ffSAllan Jude 
103*b468a9ffSAllan Jude int  Skein_256_Final (Skein_256_Ctxt_t *ctx, u08b_t * hashVal);
104*b468a9ffSAllan Jude int  Skein_512_Final (Skein_512_Ctxt_t *ctx, u08b_t * hashVal);
105*b468a9ffSAllan Jude int  Skein1024_Final (Skein1024_Ctxt_t *ctx, u08b_t * hashVal);
106*b468a9ffSAllan Jude 
107*b468a9ffSAllan Jude /*
108*b468a9ffSAllan Jude **   Skein APIs for "extended" initialization: MAC keys, tree hashing.
109*b468a9ffSAllan Jude **   After an InitExt() call, just use Update/Final calls as with Init().
110*b468a9ffSAllan Jude **
111*b468a9ffSAllan Jude **   Notes: Same parameters as _Init() calls, plus treeInfo/key/keyBytes.
112*b468a9ffSAllan Jude **          When keyBytes == 0 and treeInfo == SKEIN_SEQUENTIAL,
113*b468a9ffSAllan Jude **              the results of InitExt() are identical to calling Init().
114*b468a9ffSAllan Jude **          The function Init() may be called once to "precompute" the IV for
115*b468a9ffSAllan Jude **              a given hashBitLen value, then by saving a copy of the context
116*b468a9ffSAllan Jude **              the IV computation may be avoided in later calls.
117*b468a9ffSAllan Jude **          Similarly, the function InitExt() may be called once per MAC key
118*b468a9ffSAllan Jude **              to precompute the MAC IV, then a copy of the context saved and
119*b468a9ffSAllan Jude **              reused for each new MAC computation.
120*b468a9ffSAllan Jude **/
121*b468a9ffSAllan Jude int  Skein_256_InitExt(Skein_256_Ctxt_t *ctx, size_t hashBitLen, u64b_t treeInfo, const u08b_t *key, size_t keyBytes);
122*b468a9ffSAllan Jude int  Skein_512_InitExt(Skein_512_Ctxt_t *ctx, size_t hashBitLen, u64b_t treeInfo, const u08b_t *key, size_t keyBytes);
123*b468a9ffSAllan Jude int  Skein1024_InitExt(Skein1024_Ctxt_t *ctx, size_t hashBitLen, u64b_t treeInfo, const u08b_t *key, size_t keyBytes);
124*b468a9ffSAllan Jude 
125*b468a9ffSAllan Jude /*
126*b468a9ffSAllan Jude **   Skein APIs for MAC and tree hash:
127*b468a9ffSAllan Jude **      Final_Pad:  pad, do final block, but no OUTPUT type
128*b468a9ffSAllan Jude **      Output:     do just the output stage
129*b468a9ffSAllan Jude */
130*b468a9ffSAllan Jude int  Skein_256_Final_Pad(Skein_256_Ctxt_t *ctx, u08b_t * hashVal);
131*b468a9ffSAllan Jude int  Skein_512_Final_Pad(Skein_512_Ctxt_t *ctx, u08b_t * hashVal);
132*b468a9ffSAllan Jude int  Skein1024_Final_Pad(Skein1024_Ctxt_t *ctx, u08b_t * hashVal);
133*b468a9ffSAllan Jude 
134*b468a9ffSAllan Jude #ifndef SKEIN_TREE_HASH
135*b468a9ffSAllan Jude #define SKEIN_TREE_HASH (1)
136*b468a9ffSAllan Jude #endif
137*b468a9ffSAllan Jude #if  SKEIN_TREE_HASH
138*b468a9ffSAllan Jude int  Skein_256_Output   (Skein_256_Ctxt_t *ctx, u08b_t * hashVal);
139*b468a9ffSAllan Jude int  Skein_512_Output   (Skein_512_Ctxt_t *ctx, u08b_t * hashVal);
140*b468a9ffSAllan Jude int  Skein1024_Output   (Skein1024_Ctxt_t *ctx, u08b_t * hashVal);
141*b468a9ffSAllan Jude #endif
142*b468a9ffSAllan Jude 
143*b468a9ffSAllan Jude /*****************************************************************
144*b468a9ffSAllan Jude ** "Internal" Skein definitions
145*b468a9ffSAllan Jude **    -- not needed for sequential hashing API, but will be
146*b468a9ffSAllan Jude **           helpful for other uses of Skein (e.g., tree hash mode).
147*b468a9ffSAllan Jude **    -- included here so that they can be shared between
148*b468a9ffSAllan Jude **           reference and optimized code.
149*b468a9ffSAllan Jude ******************************************************************/
150*b468a9ffSAllan Jude 
151*b468a9ffSAllan Jude /* tweak word T[1]: bit field starting positions */
152*b468a9ffSAllan Jude #define SKEIN_T1_BIT(BIT)       ((BIT) - 64)            /* offset 64 because it's the second word  */
153*b468a9ffSAllan Jude 
154*b468a9ffSAllan Jude #define SKEIN_T1_POS_TREE_LVL   SKEIN_T1_BIT(112)       /* bits 112..118: level in hash tree       */
155*b468a9ffSAllan Jude #define SKEIN_T1_POS_BIT_PAD    SKEIN_T1_BIT(119)       /* bit  119     : partial final input byte */
156*b468a9ffSAllan Jude #define SKEIN_T1_POS_BLK_TYPE   SKEIN_T1_BIT(120)       /* bits 120..125: type field               */
157*b468a9ffSAllan Jude #define SKEIN_T1_POS_FIRST      SKEIN_T1_BIT(126)       /* bits 126     : first block flag         */
158*b468a9ffSAllan Jude #define SKEIN_T1_POS_FINAL      SKEIN_T1_BIT(127)       /* bit  127     : final block flag         */
159*b468a9ffSAllan Jude 
160*b468a9ffSAllan Jude /* tweak word T[1]: flag bit definition(s) */
161*b468a9ffSAllan Jude #define SKEIN_T1_FLAG_FIRST     (((u64b_t)  1 ) << SKEIN_T1_POS_FIRST)
162*b468a9ffSAllan Jude #define SKEIN_T1_FLAG_FINAL     (((u64b_t)  1 ) << SKEIN_T1_POS_FINAL)
163*b468a9ffSAllan Jude #define SKEIN_T1_FLAG_BIT_PAD   (((u64b_t)  1 ) << SKEIN_T1_POS_BIT_PAD)
164*b468a9ffSAllan Jude 
165*b468a9ffSAllan Jude /* tweak word T[1]: tree level bit field mask */
166*b468a9ffSAllan Jude #define SKEIN_T1_TREE_LVL_MASK  (((u64b_t)0x7F) << SKEIN_T1_POS_TREE_LVL)
167*b468a9ffSAllan Jude #define SKEIN_T1_TREE_LEVEL(n)  (((u64b_t) (n)) << SKEIN_T1_POS_TREE_LVL)
168*b468a9ffSAllan Jude 
169*b468a9ffSAllan Jude /* tweak word T[1]: block type field */
170*b468a9ffSAllan Jude #define SKEIN_BLK_TYPE_KEY      ( 0)                    /* key, for MAC and KDF */
171*b468a9ffSAllan Jude #define SKEIN_BLK_TYPE_CFG      ( 4)                    /* configuration block */
172*b468a9ffSAllan Jude #define SKEIN_BLK_TYPE_PERS     ( 8)                    /* personalization string */
173*b468a9ffSAllan Jude #define SKEIN_BLK_TYPE_PK       (12)                    /* public key (for digital signature hashing) */
174*b468a9ffSAllan Jude #define SKEIN_BLK_TYPE_KDF      (16)                    /* key identifier for KDF */
175*b468a9ffSAllan Jude #define SKEIN_BLK_TYPE_NONCE    (20)                    /* nonce for PRNG */
176*b468a9ffSAllan Jude #define SKEIN_BLK_TYPE_MSG      (48)                    /* message processing */
177*b468a9ffSAllan Jude #define SKEIN_BLK_TYPE_OUT      (63)                    /* output stage */
178*b468a9ffSAllan Jude #define SKEIN_BLK_TYPE_MASK     (63)                    /* bit field mask */
179*b468a9ffSAllan Jude 
180*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE(T)   (((u64b_t) (SKEIN_BLK_TYPE_##T)) << SKEIN_T1_POS_BLK_TYPE)
181*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_KEY   SKEIN_T1_BLK_TYPE(KEY)  /* key, for MAC and KDF */
182*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_CFG   SKEIN_T1_BLK_TYPE(CFG)  /* configuration block */
183*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_PERS  SKEIN_T1_BLK_TYPE(PERS) /* personalization string */
184*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_PK    SKEIN_T1_BLK_TYPE(PK)   /* public key (for digital signature hashing) */
185*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_KDF   SKEIN_T1_BLK_TYPE(KDF)  /* key identifier for KDF */
186*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_NONCE SKEIN_T1_BLK_TYPE(NONCE)/* nonce for PRNG */
187*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_MSG   SKEIN_T1_BLK_TYPE(MSG)  /* message processing */
188*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_OUT   SKEIN_T1_BLK_TYPE(OUT)  /* output stage */
189*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_MASK  SKEIN_T1_BLK_TYPE(MASK) /* field bit mask */
190*b468a9ffSAllan Jude 
191*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_CFG_FINAL       (SKEIN_T1_BLK_TYPE_CFG | SKEIN_T1_FLAG_FINAL)
192*b468a9ffSAllan Jude #define SKEIN_T1_BLK_TYPE_OUT_FINAL       (SKEIN_T1_BLK_TYPE_OUT | SKEIN_T1_FLAG_FINAL)
193*b468a9ffSAllan Jude 
194*b468a9ffSAllan Jude #define SKEIN_VERSION           (1)
195*b468a9ffSAllan Jude 
196*b468a9ffSAllan Jude #ifndef SKEIN_ID_STRING_LE      /* allow compile-time personalization */
197*b468a9ffSAllan Jude #define SKEIN_ID_STRING_LE      (0x33414853)            /* "SHA3" (little-endian)*/
198*b468a9ffSAllan Jude #endif
199*b468a9ffSAllan Jude 
200*b468a9ffSAllan Jude #define SKEIN_MK_64(hi32,lo32)  ((lo32) + (((u64b_t) (hi32)) << 32))
201*b468a9ffSAllan Jude #define SKEIN_SCHEMA_VER        SKEIN_MK_64(SKEIN_VERSION,SKEIN_ID_STRING_LE)
202*b468a9ffSAllan Jude #define SKEIN_KS_PARITY         SKEIN_MK_64(0x1BD11BDA,0xA9FC1A22)
203*b468a9ffSAllan Jude 
204*b468a9ffSAllan Jude #define SKEIN_CFG_STR_LEN       (4*8)
205*b468a9ffSAllan Jude 
206*b468a9ffSAllan Jude /* bit field definitions in config block treeInfo word */
207*b468a9ffSAllan Jude #define SKEIN_CFG_TREE_LEAF_SIZE_POS  ( 0)
208*b468a9ffSAllan Jude #define SKEIN_CFG_TREE_NODE_SIZE_POS  ( 8)
209*b468a9ffSAllan Jude #define SKEIN_CFG_TREE_MAX_LEVEL_POS  (16)
210*b468a9ffSAllan Jude 
211*b468a9ffSAllan Jude #define SKEIN_CFG_TREE_LEAF_SIZE_MSK  (((u64b_t) 0xFF) << SKEIN_CFG_TREE_LEAF_SIZE_POS)
212*b468a9ffSAllan Jude #define SKEIN_CFG_TREE_NODE_SIZE_MSK  (((u64b_t) 0xFF) << SKEIN_CFG_TREE_NODE_SIZE_POS)
213*b468a9ffSAllan Jude #define SKEIN_CFG_TREE_MAX_LEVEL_MSK  (((u64b_t) 0xFF) << SKEIN_CFG_TREE_MAX_LEVEL_POS)
214*b468a9ffSAllan Jude 
215*b468a9ffSAllan Jude #define SKEIN_CFG_TREE_INFO(leaf,node,maxLvl)                   \
216*b468a9ffSAllan Jude     ( (((u64b_t)(leaf  )) << SKEIN_CFG_TREE_LEAF_SIZE_POS) |    \
217*b468a9ffSAllan Jude       (((u64b_t)(node  )) << SKEIN_CFG_TREE_NODE_SIZE_POS) |    \
218*b468a9ffSAllan Jude       (((u64b_t)(maxLvl)) << SKEIN_CFG_TREE_MAX_LEVEL_POS) )
219*b468a9ffSAllan Jude 
220*b468a9ffSAllan Jude #define SKEIN_CFG_TREE_INFO_SEQUENTIAL SKEIN_CFG_TREE_INFO(0,0,0) /* use as treeInfo in InitExt() call for sequential processing */
221*b468a9ffSAllan Jude 
222*b468a9ffSAllan Jude /*
223*b468a9ffSAllan Jude **   Skein macros for getting/setting tweak words, etc.
224*b468a9ffSAllan Jude **   These are useful for partial input bytes, hash tree init/update, etc.
225*b468a9ffSAllan Jude **/
226*b468a9ffSAllan Jude #define Skein_Get_Tweak(ctxPtr,TWK_NUM)         ((ctxPtr)->h.T[TWK_NUM])
227*b468a9ffSAllan Jude #define Skein_Set_Tweak(ctxPtr,TWK_NUM,tVal)    {(ctxPtr)->h.T[TWK_NUM] = (tVal);}
228*b468a9ffSAllan Jude 
229*b468a9ffSAllan Jude #define Skein_Get_T0(ctxPtr)    Skein_Get_Tweak(ctxPtr,0)
230*b468a9ffSAllan Jude #define Skein_Get_T1(ctxPtr)    Skein_Get_Tweak(ctxPtr,1)
231*b468a9ffSAllan Jude #define Skein_Set_T0(ctxPtr,T0) Skein_Set_Tweak(ctxPtr,0,T0)
232*b468a9ffSAllan Jude #define Skein_Set_T1(ctxPtr,T1) Skein_Set_Tweak(ctxPtr,1,T1)
233*b468a9ffSAllan Jude 
234*b468a9ffSAllan Jude /* set both tweak words at once */
235*b468a9ffSAllan Jude #define Skein_Set_T0_T1(ctxPtr,T0,T1)           \
236*b468a9ffSAllan Jude     {                                           \
237*b468a9ffSAllan Jude     Skein_Set_T0(ctxPtr,(T0));                  \
238*b468a9ffSAllan Jude     Skein_Set_T1(ctxPtr,(T1));                  \
239*b468a9ffSAllan Jude     }
240*b468a9ffSAllan Jude 
241*b468a9ffSAllan Jude #define Skein_Set_Type(ctxPtr,BLK_TYPE)         \
242*b468a9ffSAllan Jude     Skein_Set_T1(ctxPtr,SKEIN_T1_BLK_TYPE_##BLK_TYPE)
243*b468a9ffSAllan Jude 
244*b468a9ffSAllan Jude /* set up for starting with a new type: h.T[0]=0; h.T[1] = NEW_TYPE; h.bCnt=0; */
245*b468a9ffSAllan Jude #define Skein_Start_New_Type(ctxPtr,BLK_TYPE)   \
246*b468a9ffSAllan Jude     { Skein_Set_T0_T1(ctxPtr,0,SKEIN_T1_FLAG_FIRST | SKEIN_T1_BLK_TYPE_##BLK_TYPE); (ctxPtr)->h.bCnt=0; }
247*b468a9ffSAllan Jude 
248*b468a9ffSAllan Jude #define Skein_Clear_First_Flag(hdr)      { (hdr).T[1] &= ~SKEIN_T1_FLAG_FIRST;       }
249*b468a9ffSAllan Jude #define Skein_Set_Bit_Pad_Flag(hdr)      { (hdr).T[1] |=  SKEIN_T1_FLAG_BIT_PAD;     }
250*b468a9ffSAllan Jude 
251*b468a9ffSAllan Jude #define Skein_Set_Tree_Level(hdr,height) { (hdr).T[1] |= SKEIN_T1_TREE_LEVEL(height);}
252*b468a9ffSAllan Jude 
253*b468a9ffSAllan Jude /*****************************************************************
254*b468a9ffSAllan Jude ** "Internal" Skein definitions for debugging and error checking
255*b468a9ffSAllan Jude ******************************************************************/
256*b468a9ffSAllan Jude #ifdef  SKEIN_DEBUG             /* examine/display intermediate values? */
257*b468a9ffSAllan Jude #include "skein_debug.h"
258*b468a9ffSAllan Jude #else                           /* default is no callouts */
259*b468a9ffSAllan Jude #define Skein_Show_Block(bits,ctx,X,blkPtr,wPtr,ksEvenPtr,ksOddPtr)
260*b468a9ffSAllan Jude #define Skein_Show_Round(bits,ctx,r,X)
261*b468a9ffSAllan Jude #define Skein_Show_R_Ptr(bits,ctx,r,X_ptr)
262*b468a9ffSAllan Jude #define Skein_Show_Final(bits,ctx,cnt,outPtr)
263*b468a9ffSAllan Jude #define Skein_Show_Key(bits,ctx,key,keyBytes)
264*b468a9ffSAllan Jude #endif
265*b468a9ffSAllan Jude 
266*b468a9ffSAllan Jude #ifndef SKEIN_ERR_CHECK        /* run-time checks (e.g., bad params, uninitialized context)? */
267*b468a9ffSAllan Jude #define Skein_Assert(x,retCode)/* default: ignore all Asserts, for performance */
268*b468a9ffSAllan Jude #define Skein_assert(x)
269*b468a9ffSAllan Jude #elif   defined(SKEIN_ASSERT)
270*b468a9ffSAllan Jude #include <assert.h>
271*b468a9ffSAllan Jude #define Skein_Assert(x,retCode) assert(x)
272*b468a9ffSAllan Jude #define Skein_assert(x)         assert(x)
273*b468a9ffSAllan Jude #else
274*b468a9ffSAllan Jude #include <assert.h>
275*b468a9ffSAllan Jude #define Skein_Assert(x,retCode) { if (!(x)) return retCode; } /*  caller  error */
276*b468a9ffSAllan Jude #define Skein_assert(x)         assert(x)                     /* internal error */
277*b468a9ffSAllan Jude #endif
278*b468a9ffSAllan Jude 
279*b468a9ffSAllan Jude /*****************************************************************
280*b468a9ffSAllan Jude ** Skein block function constants (shared across Ref and Opt code)
281*b468a9ffSAllan Jude ******************************************************************/
282*b468a9ffSAllan Jude enum
283*b468a9ffSAllan Jude     {
284*b468a9ffSAllan Jude         /* Skein_256 round rotation constants */
285*b468a9ffSAllan Jude     R_256_0_0=14, R_256_0_1=16,
286*b468a9ffSAllan Jude     R_256_1_0=52, R_256_1_1=57,
287*b468a9ffSAllan Jude     R_256_2_0=23, R_256_2_1=40,
288*b468a9ffSAllan Jude     R_256_3_0= 5, R_256_3_1=37,
289*b468a9ffSAllan Jude     R_256_4_0=25, R_256_4_1=33,
290*b468a9ffSAllan Jude     R_256_5_0=46, R_256_5_1=12,
291*b468a9ffSAllan Jude     R_256_6_0=58, R_256_6_1=22,
292*b468a9ffSAllan Jude     R_256_7_0=32, R_256_7_1=32,
293*b468a9ffSAllan Jude 
294*b468a9ffSAllan Jude         /* Skein_512 round rotation constants */
295*b468a9ffSAllan Jude     R_512_0_0=46, R_512_0_1=36, R_512_0_2=19, R_512_0_3=37,
296*b468a9ffSAllan Jude     R_512_1_0=33, R_512_1_1=27, R_512_1_2=14, R_512_1_3=42,
297*b468a9ffSAllan Jude     R_512_2_0=17, R_512_2_1=49, R_512_2_2=36, R_512_2_3=39,
298*b468a9ffSAllan Jude     R_512_3_0=44, R_512_3_1= 9, R_512_3_2=54, R_512_3_3=56,
299*b468a9ffSAllan Jude     R_512_4_0=39, R_512_4_1=30, R_512_4_2=34, R_512_4_3=24,
300*b468a9ffSAllan Jude     R_512_5_0=13, R_512_5_1=50, R_512_5_2=10, R_512_5_3=17,
301*b468a9ffSAllan Jude     R_512_6_0=25, R_512_6_1=29, R_512_6_2=39, R_512_6_3=43,
302*b468a9ffSAllan Jude     R_512_7_0= 8, R_512_7_1=35, R_512_7_2=56, R_512_7_3=22,
303*b468a9ffSAllan Jude 
304*b468a9ffSAllan Jude         /* Skein1024 round rotation constants */
305*b468a9ffSAllan Jude     R1024_0_0=24, R1024_0_1=13, R1024_0_2= 8, R1024_0_3=47, R1024_0_4= 8, R1024_0_5=17, R1024_0_6=22, R1024_0_7=37,
306*b468a9ffSAllan Jude     R1024_1_0=38, R1024_1_1=19, R1024_1_2=10, R1024_1_3=55, R1024_1_4=49, R1024_1_5=18, R1024_1_6=23, R1024_1_7=52,
307*b468a9ffSAllan Jude     R1024_2_0=33, R1024_2_1= 4, R1024_2_2=51, R1024_2_3=13, R1024_2_4=34, R1024_2_5=41, R1024_2_6=59, R1024_2_7=17,
308*b468a9ffSAllan Jude     R1024_3_0= 5, R1024_3_1=20, R1024_3_2=48, R1024_3_3=41, R1024_3_4=47, R1024_3_5=28, R1024_3_6=16, R1024_3_7=25,
309*b468a9ffSAllan Jude     R1024_4_0=41, R1024_4_1= 9, R1024_4_2=37, R1024_4_3=31, R1024_4_4=12, R1024_4_5=47, R1024_4_6=44, R1024_4_7=30,
310*b468a9ffSAllan Jude     R1024_5_0=16, R1024_5_1=34, R1024_5_2=56, R1024_5_3=51, R1024_5_4= 4, R1024_5_5=53, R1024_5_6=42, R1024_5_7=41,
311*b468a9ffSAllan Jude     R1024_6_0=31, R1024_6_1=44, R1024_6_2=47, R1024_6_3=46, R1024_6_4=19, R1024_6_5=42, R1024_6_6=44, R1024_6_7=25,
312*b468a9ffSAllan Jude     R1024_7_0= 9, R1024_7_1=48, R1024_7_2=35, R1024_7_3=52, R1024_7_4=23, R1024_7_5=31, R1024_7_6=37, R1024_7_7=20
313*b468a9ffSAllan Jude     };
314*b468a9ffSAllan Jude 
315*b468a9ffSAllan Jude #ifndef SKEIN_ROUNDS
316*b468a9ffSAllan Jude #define SKEIN_256_ROUNDS_TOTAL (72)          /* number of rounds for the different block sizes */
317*b468a9ffSAllan Jude #define SKEIN_512_ROUNDS_TOTAL (72)
318*b468a9ffSAllan Jude #define SKEIN1024_ROUNDS_TOTAL (80)
319*b468a9ffSAllan Jude #else                                        /* allow command-line define in range 8*(5..14)   */
320*b468a9ffSAllan Jude #define SKEIN_256_ROUNDS_TOTAL (8*((((SKEIN_ROUNDS/100) + 5) % 10) + 5))
321*b468a9ffSAllan Jude #define SKEIN_512_ROUNDS_TOTAL (8*((((SKEIN_ROUNDS/ 10) + 5) % 10) + 5))
322*b468a9ffSAllan Jude #define SKEIN1024_ROUNDS_TOTAL (8*((((SKEIN_ROUNDS    ) + 5) % 10) + 5))
323*b468a9ffSAllan Jude #endif
324*b468a9ffSAllan Jude 
325*b468a9ffSAllan Jude #ifdef __cplusplus
326*b468a9ffSAllan Jude }
327*b468a9ffSAllan Jude #endif
328*b468a9ffSAllan Jude 
329*b468a9ffSAllan Jude /* Pull in FreeBSD specific shims */
330*b468a9ffSAllan Jude #include "skein_freebsd.h"
331*b468a9ffSAllan Jude 
332*b468a9ffSAllan Jude #endif  /* ifndef _SKEIN_H_ */
333