|  | 
|  | 1 | +use crate::Blake2Parameters; | 
|  | 2 | +use crate::Blake2bVarCore; | 
|  | 3 | +use digest::{ | 
|  | 4 | +    ExtendableOutput, Update, XofReader, | 
|  | 5 | +    block_buffer::{LazyBuffer, ReadBuffer}, | 
|  | 6 | +    consts::U64, | 
|  | 7 | +    core_api::{Buffer, BufferKindUser, UpdateCore, VariableOutputCore}, | 
|  | 8 | +}; | 
|  | 9 | + | 
|  | 10 | +use super::{Blake2b512, BlockSizeUser, InvalidLength, Unsigned}; | 
|  | 11 | + | 
|  | 12 | +/// Blake2Xb root hasher | 
|  | 13 | +pub struct Blake2Xb { | 
|  | 14 | +    root_hasher: Blake2bVarCore, | 
|  | 15 | +    buffer: LazyBuffer<<Blake2b512 as BlockSizeUser>::BlockSize>, | 
|  | 16 | +    max_length: Option<u32>, | 
|  | 17 | +} | 
|  | 18 | + | 
|  | 19 | +impl Blake2Xb { | 
|  | 20 | +    /// Create new instance using provided key. | 
|  | 21 | +    /// | 
|  | 22 | +    /// Setting key to `None` indicates unkeyed usage. | 
|  | 23 | +    /// | 
|  | 24 | +    /// # Errors | 
|  | 25 | +    /// | 
|  | 26 | +    /// If key is `Some`, then its length should not be zero or bigger | 
|  | 27 | +    /// than the block size. If this conditions is false the method will | 
|  | 28 | +    /// return an error. | 
|  | 29 | +    #[inline] | 
|  | 30 | +    pub fn new(key: Option<&[u8]>, max_length: Option<u32>) -> Result<Self, InvalidLength> { | 
|  | 31 | +        let kl = key.map_or(0, |k| k.len()); | 
|  | 32 | +        let bs = <Blake2b512 as BlockSizeUser>::BlockSize::USIZE; | 
|  | 33 | +        if key.is_some() && kl == 0 || kl > bs { | 
|  | 34 | +            return Err(InvalidLength); | 
|  | 35 | +        } | 
|  | 36 | + | 
|  | 37 | +        let params = Blake2Parameters { | 
|  | 38 | +            digest_length: 64, | 
|  | 39 | +            key_size: kl.try_into().unwrap(), | 
|  | 40 | +            fanout: 1, | 
|  | 41 | +            depth: 1, | 
|  | 42 | +            xof_digest_length: Some(max_length.unwrap_or(u32::MAX)), | 
|  | 43 | +            ..<_>::default() | 
|  | 44 | +        }; | 
|  | 45 | +        let root_hasher = Blake2bVarCore::from_params(params); | 
|  | 46 | + | 
|  | 47 | +        let mut hasher = Self { | 
|  | 48 | +            root_hasher, | 
|  | 49 | +            buffer: <_>::default(), | 
|  | 50 | +            max_length, | 
|  | 51 | +        }; | 
|  | 52 | + | 
|  | 53 | +        if let Some(k) = key { | 
|  | 54 | +            // Update state with key | 
|  | 55 | +            hasher.update(k); | 
|  | 56 | +            // Pad key with zeros | 
|  | 57 | +            let pad_len = 128 - kl; | 
|  | 58 | +            let padding = [0; 128]; | 
|  | 59 | +            hasher.update(&padding[..pad_len]); | 
|  | 60 | +        } | 
|  | 61 | + | 
|  | 62 | +        Ok(hasher) | 
|  | 63 | +    } | 
|  | 64 | +} | 
|  | 65 | + | 
|  | 66 | +pub struct Blake2bXReader { | 
|  | 67 | +    h0: [u8; 64], | 
|  | 68 | +    buffer: ReadBuffer<<Self as BlockSizeUser>::BlockSize>, | 
|  | 69 | +    node_offset: u32, | 
|  | 70 | +    total_length: u32, | 
|  | 71 | +} | 
|  | 72 | + | 
|  | 73 | +impl BlockSizeUser for Blake2bXReader { | 
|  | 74 | +    type BlockSize = U64; | 
|  | 75 | +} | 
|  | 76 | + | 
|  | 77 | +impl BufferKindUser for Blake2bXReader { | 
|  | 78 | +    type BufferKind = <Blake2bVarCore as BufferKindUser>::BufferKind; | 
|  | 79 | +} | 
|  | 80 | + | 
|  | 81 | +impl XofReader for Blake2bXReader { | 
|  | 82 | +    fn read(&mut self, buffer: &mut [u8]) { | 
|  | 83 | +        let Self { buffer: buf, .. } = self; | 
|  | 84 | +        buf.read(buffer, |block| { | 
|  | 85 | +            let digest_length = 64.min(self.total_length - self.node_offset * 64) as u8; | 
|  | 86 | + | 
|  | 87 | +            let mut hasher = Blake2bVarCore::from_params(Blake2Parameters { | 
|  | 88 | +                digest_length, | 
|  | 89 | +                leaf_length: 64, | 
|  | 90 | +                node_offset: self.node_offset as u64, | 
|  | 91 | +                xof_digest_length: Some(self.total_length), | 
|  | 92 | +                inner_length: 64, | 
|  | 93 | +                ..<_>::default() | 
|  | 94 | +            }); | 
|  | 95 | + | 
|  | 96 | +            self.node_offset += 1; | 
|  | 97 | + | 
|  | 98 | +            hasher.finalize_variable_core(&mut Buffer::<Blake2bVarCore>::new(&self.h0), block); | 
|  | 99 | +        }); | 
|  | 100 | +    } | 
|  | 101 | +} | 
|  | 102 | + | 
|  | 103 | +#[cfg(feature = "std")] | 
|  | 104 | +impl std::io::Read for Blake2bXReader { | 
|  | 105 | +    #[inline] | 
|  | 106 | +    fn read(&mut self, buf: &mut [u8]) -> std::io::Result<usize> { | 
|  | 107 | +        XofReader::read(self, buf); | 
|  | 108 | +        Ok(buf.len()) | 
|  | 109 | +    } | 
|  | 110 | +} | 
|  | 111 | + | 
|  | 112 | +impl BlockSizeUser for Blake2Xb { | 
|  | 113 | +    type BlockSize = <Blake2bVarCore as BlockSizeUser>::BlockSize; | 
|  | 114 | +} | 
|  | 115 | + | 
|  | 116 | +impl BufferKindUser for Blake2Xb { | 
|  | 117 | +    type BufferKind = <Blake2bVarCore as BufferKindUser>::BufferKind; | 
|  | 118 | +} | 
|  | 119 | + | 
|  | 120 | +impl Update for Blake2Xb { | 
|  | 121 | +    fn update(&mut self, data: &[u8]) { | 
|  | 122 | +        let Self { | 
|  | 123 | +            root_hasher, | 
|  | 124 | +            buffer, | 
|  | 125 | +            .. | 
|  | 126 | +        } = self; | 
|  | 127 | +        buffer.digest_blocks(data, |blocks| root_hasher.update_blocks(blocks)); | 
|  | 128 | +    } | 
|  | 129 | +} | 
|  | 130 | + | 
|  | 131 | +impl ExtendableOutput for Blake2Xb { | 
|  | 132 | +    type Reader = Blake2bXReader; | 
|  | 133 | + | 
|  | 134 | +    fn finalize_xof(self) -> Self::Reader { | 
|  | 135 | +        let mut m = <_>::default(); | 
|  | 136 | +        let Self { | 
|  | 137 | +            mut root_hasher, | 
|  | 138 | +            mut buffer, | 
|  | 139 | +            max_length, | 
|  | 140 | +        } = self; | 
|  | 141 | +        root_hasher.finalize_variable_core(&mut buffer, &mut m); | 
|  | 142 | + | 
|  | 143 | +        let mut h0 = [0; 64]; | 
|  | 144 | +        h0.copy_from_slice(&m); | 
|  | 145 | + | 
|  | 146 | +        Blake2bXReader { | 
|  | 147 | +            h0, | 
|  | 148 | +            buffer: <_>::default(), | 
|  | 149 | +            node_offset: 0, | 
|  | 150 | +            total_length: max_length.unwrap_or(u32::MAX), | 
|  | 151 | +        } | 
|  | 152 | +    } | 
|  | 153 | +} | 
|  | 154 | + | 
|  | 155 | +#[test] | 
|  | 156 | +fn test() { | 
|  | 157 | +    let seed = [ | 
|  | 158 | +        0x72, 0x01, 0xa8, 0x01, 0xc4, 0xf9, 0x95, 0x7c, 0x76, 0x65, 0xc2, 0xfd, 0x42, 0x76, 0x1f, | 
|  | 159 | +        0x5d, 0xa6, 0xc0, 0x55, 0x51, 0xf1, 0x5c, 0x21, 0x53, 0x78, 0x8b, 0xa7, 0x0d, 0x95, 0x60, | 
|  | 160 | +        0xd7, 0xee, | 
|  | 161 | +    ]; | 
|  | 162 | +    let mut b = crate::blake2xb(&seed[..]); | 
|  | 163 | + | 
|  | 164 | +    let expected = [ | 
|  | 165 | +        0x4b, 0xd4, 0x10, 0x91, 0x1b, 0xf5, 0xdc, 0xb1, 0x99, 0x2e, 0xb7, 0x23, 0x83, 0x54, 0x98, | 
|  | 166 | +        0xda, 0xbf, 0x58, 0xce, 0x34, 0x82, 0x39, 0x3c, 0x2b, 0xd2, 0xaa, 0x3b, 0x79, 0xc4, 0xe2, | 
|  | 167 | +        0x2c, 0xb8, 0x06, 0xe6, 0x31, 0x65, 0x2e, 0x2a, 0xff, 0x3c, 0x33, 0x98, 0x64, 0x51, 0x2e, | 
|  | 168 | +        0xdd, 0xc1, 0xe0, 0x27, 0x17, 0xb2, 0xeb, 0xd4, 0x99, 0xa6, 0xe9, 0xe1, 0xb8, 0x96, 0x7d, | 
|  | 169 | +        0x23, 0x00, 0x54, 0xa4, 0x16, 0x58, 0xa3, 0xf4, 0xfe, 0x04, 0xb0, 0x62, 0x9f, 0xc8, 0xe6, | 
|  | 170 | +        0x9f, 0x6b, 0xf5, 0x1d, 0xe7, 0x59, 0x09, 0x0c, 0xe5, 0x4d, 0x82, 0xc0, 0xda, 0xda, 0xc9, | 
|  | 171 | +        0x21, 0xa3, 0x3f, 0x18, 0xb1, 0xb6, 0xbe, 0x8e, 0x9b, 0x12, 0x4d, 0x46, 0xf2, 0x6b, 0x9c, | 
|  | 172 | +        0xb0, 0xdb, 0xec, 0xae, 0x21, 0xf5, 0x04, 0x88, 0x6b, 0xc0, 0x75, 0x3e, 0x9e, 0x62, 0xd4, | 
|  | 173 | +        0x98, 0xdf, 0xb0, 0x18, 0xb3, 0x4a, 0x14, 0xd5, 0xfc, 0xee, 0xf4, 0xc0, 0xd9, 0x78, 0xe1, | 
|  | 174 | +        0xda, 0x27, 0xa0, 0x71, 0x56, 0x4d, 0x7e, 0xbd, 0x56, 0xfd, 0x09, 0x27, 0x65, 0x19, 0x9e, | 
|  | 175 | +        0x17, 0x91, 0xdd, 0xad, 0x7b, 0x60, 0x1d, 0x26, 0xce, 0x39, 0x26, 0x39, 0xad, 0x17, 0xc2, | 
|  | 176 | +        0xeb, 0x60, 0x7f, 0x9e, 0x82, 0x78, 0x2e, 0x5f, 0x72, 0x5d, 0x19, 0x69, 0xb6, 0xb4, 0xf0, | 
|  | 177 | +        0x8b, 0x91, 0x9f, 0xf4, 0xc7, 0xf4, 0x1c, 0x04, 0xa9, 0xb8, 0xee, 0x08, | 
|  | 178 | +    ]; | 
|  | 179 | +    let mut buf = [0; 64 * 3]; | 
|  | 180 | +    b.read(&mut buf); | 
|  | 181 | +    assert_eq!(expected, buf); | 
|  | 182 | +} | 
0 commit comments