mirror of
https://github.com/bitcoin/bitcoin.git
synced 2025-02-10 10:52:31 -05:00
afb7a6fe06
8746600eec Merge bitcoin-core/secp256k1#1093: hash: Make code agnostic of endianness 37d36927df tests: Add tests for _read_be32 and _write_be32 912b7ccc44 Merge bitcoin-core/secp256k1#1094: doc: Clarify configure flags for optional modules 55512d30b7 doc: clean up module help text in configure.ac d9d94a9969 doc: mention optional modules in README 616b43dd3b util: Remove endianness detection 8d89b9e6e5 hash: Make code agnostic of endianness d0ad5814a5 Merge bitcoin-core/secp256k1#995: build: stop treating schnorrsig, extrakeys modules as experimental 1ac7e31c5b Merge bitcoin-core/secp256k1#1089: Schnorrsig API improvements 587239dbe3 Merge bitcoin-core/secp256k1#731: Change SHA256 byte counter from size_t to uint64_t f8d9174357 Add SHA256 bit counter tests 7f09d0f311 README: mention that ARM assembly is experimental b8f8b99f0f docs: Fix return value for functions that don't have invalid inputs f813bb0df3 schnorrsig: Adapt example to new API 99e6568fc6 schnorrsig: Rename schnorrsig_sign to schnorsig_sign32 and deprecate fc94a2da44 Use SECP256K1_DEPRECATED for existing deprecated API functions 3db0560606 Add SECP256K1_DEPRECATED attribute for marking API parts as deprecated 80cf4eea5f build: stop treating schnorrsig, extrakeys modules as experimental e0508ee9db Merge bitcoin-core/secp256k1#1090: configure: Remove redundant pkg-config code 21b2ebaf74 configure: Remove redundant pkg-config code 0e5cbd01b3 Merge bitcoin-core/secp256k1#1088: configure: Use modern way to set AR 0d253d52e8 configure: Use modern way to set AR 9b514ce1d2 Add test vector for very long SHA256 messages 8e3dde1137 Simplify struct initializer for SHA256 padding eb28464a8b Change SHA256 byte counter from size_t to uint64_t ac83be33d0 Merge bitcoin-core/secp256k1#1079: configure: Add hidden --enable-dev-mode to enable all the stuff e0838d663d configure: Add hidden --enable-dev-mode to enable all the stuff fabd579dfa configure: Remove redundant code that sets _enable variables 0d4226c051 configure: Use canonical variable prefix _enable consistently 64b34979ed Merge bitcoin-core/secp256k1#748: Add usage examples 7c9502cece Add a copy of the CC0 license to the examples 42e03432e6 Add usage examples to the readme 517644eab1 Optionally compile the examples in autotools, compile+run in travis 422a7cc86a Add a ecdh shared secret example b0cfbcc143 Add a Schnorr signing and verifying example fee7d4bf9e Add an ECDSA signing and verifying example 1253a27756 Merge bitcoin-core/secp256k1#1033: Add _fe_half and use in _gej_add_ge and _gej_double 3ef94aa5ba Merge bitcoin-core/secp256k1#1026: ecdh: Add test computing shared_secret=basepoint with random inputs 3531a43b5b ecdh: Make generator_basepoint test depend on global iteration count c881dd49bd ecdh: Add test computing shared_secret=basepoint with random inputs 077528317d Merge bitcoin-core/secp256k1#1074: ci: Retry brew update a few times to avoid random failures e51ad3b737 ci: Retry `brew update` a few times to avoid random failures b1cb969e8a ci: Revert "Attempt to make macOS builds more reliable" 5dcc6f8dbd Merge bitcoin-core/secp256k1#1069: build: Replace use of deprecated autoconf macro AC_PROG_CC_C89 59547943d6 Merge bitcoin-core/secp256k1#1072: ci: Attempt to make macOS builds more reliable 85b00a1c65 Merge bitcoin-core/secp256k1#1068: sage: Fix incompatibility with sage 9.4 ebb1beea78 sage: Ensure that constraints are always fastfracs d8d54859ed ci: Run sage prover on CI 77cfa98dbc sage: Normalize sign of polynomial factors in prover eae75869cf sage: Exit with non-zero status in case of failures d9396a56da ci: Attempt to make macOS builds more reliable e0db3f8a25 build: Replace use of deprecated autoconf macro AC_PROG_CC_C89 e848c3799c Update sage files for new formulae d64bb5d4f3 Add fe_half tests for worst-case inputs b54d843eac sage: Fix printing of errors 4eb8b932ff Further improve doubling formula using fe_half 557b31fac3 Doubling formula using fe_half 2cbb4b1a42 Run more iterations of run_field_misc 9cc5c257ed Add test for secp256k1_fe_half 925f78d55e Add _fe_half and use in _gej_add_ge e108d0039c sage: Fix incompatibility with sage 9.4 d8a2463246 Merge bitcoin-core/secp256k1#899: Reduce stratch space needed by ecmult_strauss_wnaf. 0a40a4861a Merge bitcoin-core/secp256k1#1049: Faster fixed-input ecmult tests 070e772211 Faster fixed-input ecmult tests c8aa516b57 Merge bitcoin-core/secp256k1#1064: Modulo-reduce msg32 inside RFC6979 nonce fn to match spec. Fixes #1063 b797a500ec Create a SECP256K1_ECMULT_TABLE_VERIFY macro. a731200cc3 Replace ECMULT_TABLE_GET_GE_STORAGE macro with a function. fe34d9f341 Eliminate input_pos state field from ecmult_strauss_wnaf. 0397d00ba0 Eliminate na_1 and na_lam state fields from ecmult_strauss_wnaf. 7ba3ffcca0 Remove the unused pre_a_lam allocations. b3b57ad6ee Eliminate the pre_a_lam array from ecmult_strauss_wnaf. ae7ba0f922 Remove the unused prej allocations. e5c18892db Eliminate the prej array from ecmult_strauss_wnaf. c9da1baad1 Move secp256k1_fe_one to field.h 45f37b6506 Modulo-reduce msg32 inside RFC6979 nonce fn to match spec. Fixes #1063. a1102b1219 Merge bitcoin-core/secp256k1#1029: Simpler and faster ecdh skew fixup e82144edfb Fixup skew before global Z fixup 40b624c90b Add tests for _gej_cmov 8c13a9bfe1 ECDH skews by 0 or 1 1515099433 Simpler and faster ecdh skew fixup 39a36db94a Merge bitcoin-core/secp256k1#1054: tests: Fix test whose result is implementation-defined a310e79ee5 Merge bitcoin-core/secp256k1#1052: Use xoshiro256++ instead of RFC6979 for tests 423b6d19d3 Merge bitcoin-core/secp256k1#964: Add release-process.md 9281c9f4e1 Merge bitcoin-core/secp256k1#1053: ecmult: move `_ecmult_odd_multiples_table_globalz_windowa` 77a19750b4 Use xoshiro256++ PRNG instead of RFC6979 in tests 5f2efe684e secp256k1_testrand_int(2**N) -> secp256k1_testrand_bits(N) 05e049b73c ecmult: move `_ecmult_odd_multiples_table_globalz_windowa` 3d7cbafb5f tests: Fix test whose result is implementation-defined 3ed0d02bf7 doc: add CHANGELOG template 6f42dc16c8 doc: add release_process.md 0bd3e4243c build: set library version to 0.0.0 explicitly b4b02fd8c4 build: change libsecp version from 0.1 to 0.1.0-pre 09971a3ffd Merge bitcoin-core/secp256k1#1047: ci: Various improvements 0b83b203e1 Merge bitcoin-core/secp256k1#1030: doc: Fix upper bounds + cleanup in field_5x52_impl.h comment 1287786c7a doc: Add comment to top of field_10x26_impl.h 58da5bd589 doc: Fix upper bounds + cleanup in field_5x52_impl.h comment b39d431aed Merge bitcoin-core/secp256k1#1044: Add another ecmult_multi test b4ac1a1d5f ci: Run valgrind/memcheck tasks with 2 CPUs e70acab601 ci: Use Cirrus "greedy" flag to use idle CPU time when available d07e30176e ci: Update brew on macOS 22382f0ea0 ci: Test different ecmult window sizes a69df3ad24 Merge bitcoin-core/secp256k1#816: Improve checks at top of _fe_negate methods 22d25c8e0a Add another ecmult_multi test 515e7953ca Improve checks at top of _fe_negate methods 26a022a3a0 ci: Remove STATICPRECOMPUTATION 10461d8bd3 precompute_ecmult: Always compute all tables up to default WINDOW_G be6944ade9 Merge bitcoin-core/secp256k1#1042: Follow-ups to making all tables fully static e05da9e480 Fix c++ build c45386d994 Cleanup preprocessor indentation in precompute{,d}_ecmult{,_gen} 19d96e15f9 Split off .c file from precomputed_ecmult.h 1a6691adae Split off .c file from precomputed_ecmult_gen.h bb36331412 Simplify precompute_ecmult_print_* 38cd84a0cb Compute ecmult tables at runtime for tests_exhaustive e458ec26d6 Move ecmult table computation code to separate file fc1bf9f15f Split ecmult table computation and printing 31feab053b Rename function secp256k1_ecmult_gen_{create_prec -> compute}_table 725370c3f2 Rename ecmult_gen_prec -> ecmult_gen_compute_table 075252c1b7 Rename ecmult_static_pre_g -> precomputed_ecmult 7cf47f72bc Rename ecmult_gen_static_prec_table -> precomputed_ecmult_gen f95b8106d0 Rename gen_ecmult_static_pre_g -> precompute_ecmult bae77685eb Rename gen_ecmult_gen_static_prec_table -> precompute_ecmult_gen git-subtree-dir: src/secp256k1 git-subtree-split: 8746600eec5e7fcd35dabd480839a3a4bdfee87b
302 lines
8.8 KiB
Python
302 lines
8.8 KiB
Python
# Test libsecp256k1' group operation implementations using prover.sage
|
|
|
|
import sys
|
|
|
|
load("group_prover.sage")
|
|
load("weierstrass_prover.sage")
|
|
|
|
def formula_secp256k1_gej_double_var(a):
|
|
"""libsecp256k1's secp256k1_gej_double_var, used by various addition functions"""
|
|
rz = a.Z * a.Y
|
|
s = a.Y^2
|
|
l = a.X^2
|
|
l = l * 3
|
|
l = l / 2
|
|
t = -s
|
|
t = t * a.X
|
|
rx = l^2
|
|
rx = rx + t
|
|
rx = rx + t
|
|
s = s^2
|
|
t = t + rx
|
|
ry = t * l
|
|
ry = ry + s
|
|
ry = -ry
|
|
return jacobianpoint(rx, ry, rz)
|
|
|
|
def formula_secp256k1_gej_add_var(branch, a, b):
|
|
"""libsecp256k1's secp256k1_gej_add_var"""
|
|
if branch == 0:
|
|
return (constraints(), constraints(nonzero={a.Infinity : 'a_infinite'}), b)
|
|
if branch == 1:
|
|
return (constraints(), constraints(zero={a.Infinity : 'a_finite'}, nonzero={b.Infinity : 'b_infinite'}), a)
|
|
z22 = b.Z^2
|
|
z12 = a.Z^2
|
|
u1 = a.X * z22
|
|
u2 = b.X * z12
|
|
s1 = a.Y * z22
|
|
s1 = s1 * b.Z
|
|
s2 = b.Y * z12
|
|
s2 = s2 * a.Z
|
|
h = -u1
|
|
h = h + u2
|
|
i = -s1
|
|
i = i + s2
|
|
if branch == 2:
|
|
r = formula_secp256k1_gej_double_var(a)
|
|
return (constraints(), constraints(zero={h : 'h=0', i : 'i=0', a.Infinity : 'a_finite', b.Infinity : 'b_finite'}), r)
|
|
if branch == 3:
|
|
return (constraints(), constraints(zero={h : 'h=0', a.Infinity : 'a_finite', b.Infinity : 'b_finite'}, nonzero={i : 'i!=0'}), point_at_infinity())
|
|
i2 = i^2
|
|
h2 = h^2
|
|
h3 = h2 * h
|
|
h = h * b.Z
|
|
rz = a.Z * h
|
|
t = u1 * h2
|
|
rx = t
|
|
rx = rx * 2
|
|
rx = rx + h3
|
|
rx = -rx
|
|
rx = rx + i2
|
|
ry = -rx
|
|
ry = ry + t
|
|
ry = ry * i
|
|
h3 = h3 * s1
|
|
h3 = -h3
|
|
ry = ry + h3
|
|
return (constraints(), constraints(zero={a.Infinity : 'a_finite', b.Infinity : 'b_finite'}, nonzero={h : 'h!=0'}), jacobianpoint(rx, ry, rz))
|
|
|
|
def formula_secp256k1_gej_add_ge_var(branch, a, b):
|
|
"""libsecp256k1's secp256k1_gej_add_ge_var, which assume bz==1"""
|
|
if branch == 0:
|
|
return (constraints(zero={b.Z - 1 : 'b.z=1'}), constraints(nonzero={a.Infinity : 'a_infinite'}), b)
|
|
if branch == 1:
|
|
return (constraints(zero={b.Z - 1 : 'b.z=1'}), constraints(zero={a.Infinity : 'a_finite'}, nonzero={b.Infinity : 'b_infinite'}), a)
|
|
z12 = a.Z^2
|
|
u1 = a.X
|
|
u2 = b.X * z12
|
|
s1 = a.Y
|
|
s2 = b.Y * z12
|
|
s2 = s2 * a.Z
|
|
h = -u1
|
|
h = h + u2
|
|
i = -s1
|
|
i = i + s2
|
|
if (branch == 2):
|
|
r = formula_secp256k1_gej_double_var(a)
|
|
return (constraints(zero={b.Z - 1 : 'b.z=1'}), constraints(zero={a.Infinity : 'a_finite', b.Infinity : 'b_finite', h : 'h=0', i : 'i=0'}), r)
|
|
if (branch == 3):
|
|
return (constraints(zero={b.Z - 1 : 'b.z=1'}), constraints(zero={a.Infinity : 'a_finite', b.Infinity : 'b_finite', h : 'h=0'}, nonzero={i : 'i!=0'}), point_at_infinity())
|
|
i2 = i^2
|
|
h2 = h^2
|
|
h3 = h * h2
|
|
rz = a.Z * h
|
|
t = u1 * h2
|
|
rx = t
|
|
rx = rx * 2
|
|
rx = rx + h3
|
|
rx = -rx
|
|
rx = rx + i2
|
|
ry = -rx
|
|
ry = ry + t
|
|
ry = ry * i
|
|
h3 = h3 * s1
|
|
h3 = -h3
|
|
ry = ry + h3
|
|
return (constraints(zero={b.Z - 1 : 'b.z=1'}), constraints(zero={a.Infinity : 'a_finite', b.Infinity : 'b_finite'}, nonzero={h : 'h!=0'}), jacobianpoint(rx, ry, rz))
|
|
|
|
def formula_secp256k1_gej_add_zinv_var(branch, a, b):
|
|
"""libsecp256k1's secp256k1_gej_add_zinv_var"""
|
|
bzinv = b.Z^(-1)
|
|
if branch == 0:
|
|
return (constraints(), constraints(nonzero={b.Infinity : 'b_infinite'}), a)
|
|
if branch == 1:
|
|
bzinv2 = bzinv^2
|
|
bzinv3 = bzinv2 * bzinv
|
|
rx = b.X * bzinv2
|
|
ry = b.Y * bzinv3
|
|
rz = 1
|
|
return (constraints(), constraints(zero={b.Infinity : 'b_finite'}, nonzero={a.Infinity : 'a_infinite'}), jacobianpoint(rx, ry, rz))
|
|
azz = a.Z * bzinv
|
|
z12 = azz^2
|
|
u1 = a.X
|
|
u2 = b.X * z12
|
|
s1 = a.Y
|
|
s2 = b.Y * z12
|
|
s2 = s2 * azz
|
|
h = -u1
|
|
h = h + u2
|
|
i = -s1
|
|
i = i + s2
|
|
if branch == 2:
|
|
r = formula_secp256k1_gej_double_var(a)
|
|
return (constraints(), constraints(zero={a.Infinity : 'a_finite', b.Infinity : 'b_finite', h : 'h=0', i : 'i=0'}), r)
|
|
if branch == 3:
|
|
return (constraints(), constraints(zero={a.Infinity : 'a_finite', b.Infinity : 'b_finite', h : 'h=0'}, nonzero={i : 'i!=0'}), point_at_infinity())
|
|
i2 = i^2
|
|
h2 = h^2
|
|
h3 = h * h2
|
|
rz = a.Z
|
|
rz = rz * h
|
|
t = u1 * h2
|
|
rx = t
|
|
rx = rx * 2
|
|
rx = rx + h3
|
|
rx = -rx
|
|
rx = rx + i2
|
|
ry = -rx
|
|
ry = ry + t
|
|
ry = ry * i
|
|
h3 = h3 * s1
|
|
h3 = -h3
|
|
ry = ry + h3
|
|
return (constraints(), constraints(zero={a.Infinity : 'a_finite', b.Infinity : 'b_finite'}, nonzero={h : 'h!=0'}), jacobianpoint(rx, ry, rz))
|
|
|
|
def formula_secp256k1_gej_add_ge(branch, a, b):
|
|
"""libsecp256k1's secp256k1_gej_add_ge"""
|
|
zeroes = {}
|
|
nonzeroes = {}
|
|
a_infinity = False
|
|
if (branch & 4) != 0:
|
|
nonzeroes.update({a.Infinity : 'a_infinite'})
|
|
a_infinity = True
|
|
else:
|
|
zeroes.update({a.Infinity : 'a_finite'})
|
|
zz = a.Z^2
|
|
u1 = a.X
|
|
u2 = b.X * zz
|
|
s1 = a.Y
|
|
s2 = b.Y * zz
|
|
s2 = s2 * a.Z
|
|
t = u1
|
|
t = t + u2
|
|
m = s1
|
|
m = m + s2
|
|
rr = t^2
|
|
m_alt = -u2
|
|
tt = u1 * m_alt
|
|
rr = rr + tt
|
|
degenerate = (branch & 3) == 3
|
|
if (branch & 1) != 0:
|
|
zeroes.update({m : 'm_zero'})
|
|
else:
|
|
nonzeroes.update({m : 'm_nonzero'})
|
|
if (branch & 2) != 0:
|
|
zeroes.update({rr : 'rr_zero'})
|
|
else:
|
|
nonzeroes.update({rr : 'rr_nonzero'})
|
|
rr_alt = s1
|
|
rr_alt = rr_alt * 2
|
|
m_alt = m_alt + u1
|
|
if not degenerate:
|
|
rr_alt = rr
|
|
m_alt = m
|
|
n = m_alt^2
|
|
q = -t
|
|
q = q * n
|
|
n = n^2
|
|
if degenerate:
|
|
n = m
|
|
t = rr_alt^2
|
|
rz = a.Z * m_alt
|
|
infinity = False
|
|
if (branch & 8) != 0:
|
|
if not a_infinity:
|
|
infinity = True
|
|
zeroes.update({rz : 'r.z=0'})
|
|
else:
|
|
nonzeroes.update({rz : 'r.z!=0'})
|
|
t = t + q
|
|
rx = t
|
|
t = t * 2
|
|
t = t + q
|
|
t = t * rr_alt
|
|
t = t + n
|
|
ry = -t
|
|
ry = ry / 2
|
|
if a_infinity:
|
|
rx = b.X
|
|
ry = b.Y
|
|
rz = 1
|
|
if infinity:
|
|
return (constraints(zero={b.Z - 1 : 'b.z=1', b.Infinity : 'b_finite'}), constraints(zero=zeroes, nonzero=nonzeroes), point_at_infinity())
|
|
return (constraints(zero={b.Z - 1 : 'b.z=1', b.Infinity : 'b_finite'}), constraints(zero=zeroes, nonzero=nonzeroes), jacobianpoint(rx, ry, rz))
|
|
|
|
def formula_secp256k1_gej_add_ge_old(branch, a, b):
|
|
"""libsecp256k1's old secp256k1_gej_add_ge, which fails when ay+by=0 but ax!=bx"""
|
|
a_infinity = (branch & 1) != 0
|
|
zero = {}
|
|
nonzero = {}
|
|
if a_infinity:
|
|
nonzero.update({a.Infinity : 'a_infinite'})
|
|
else:
|
|
zero.update({a.Infinity : 'a_finite'})
|
|
zz = a.Z^2
|
|
u1 = a.X
|
|
u2 = b.X * zz
|
|
s1 = a.Y
|
|
s2 = b.Y * zz
|
|
s2 = s2 * a.Z
|
|
z = a.Z
|
|
t = u1
|
|
t = t + u2
|
|
m = s1
|
|
m = m + s2
|
|
n = m^2
|
|
q = n * t
|
|
n = n^2
|
|
rr = t^2
|
|
t = u1 * u2
|
|
t = -t
|
|
rr = rr + t
|
|
t = rr^2
|
|
rz = m * z
|
|
infinity = False
|
|
if (branch & 2) != 0:
|
|
if not a_infinity:
|
|
infinity = True
|
|
else:
|
|
return (constraints(zero={b.Z - 1 : 'b.z=1', b.Infinity : 'b_finite'}), constraints(nonzero={z : 'conflict_a'}, zero={z : 'conflict_b'}), point_at_infinity())
|
|
zero.update({rz : 'r.z=0'})
|
|
else:
|
|
nonzero.update({rz : 'r.z!=0'})
|
|
rz = rz * (0 if a_infinity else 2)
|
|
rx = t
|
|
q = -q
|
|
rx = rx + q
|
|
q = q * 3
|
|
t = t * 2
|
|
t = t + q
|
|
t = t * rr
|
|
t = t + n
|
|
ry = -t
|
|
rx = rx * (0 if a_infinity else 4)
|
|
ry = ry * (0 if a_infinity else 4)
|
|
t = b.X
|
|
t = t * (1 if a_infinity else 0)
|
|
rx = rx + t
|
|
t = b.Y
|
|
t = t * (1 if a_infinity else 0)
|
|
ry = ry + t
|
|
t = (1 if a_infinity else 0)
|
|
rz = rz + t
|
|
if infinity:
|
|
return (constraints(zero={b.Z - 1 : 'b.z=1', b.Infinity : 'b_finite'}), constraints(zero=zero, nonzero=nonzero), point_at_infinity())
|
|
return (constraints(zero={b.Z - 1 : 'b.z=1', b.Infinity : 'b_finite'}), constraints(zero=zero, nonzero=nonzero), jacobianpoint(rx, ry, rz))
|
|
|
|
if __name__ == "__main__":
|
|
success = True
|
|
success = success & check_symbolic_jacobian_weierstrass("secp256k1_gej_add_var", 0, 7, 5, formula_secp256k1_gej_add_var)
|
|
success = success & check_symbolic_jacobian_weierstrass("secp256k1_gej_add_ge_var", 0, 7, 5, formula_secp256k1_gej_add_ge_var)
|
|
success = success & check_symbolic_jacobian_weierstrass("secp256k1_gej_add_zinv_var", 0, 7, 5, formula_secp256k1_gej_add_zinv_var)
|
|
success = success & check_symbolic_jacobian_weierstrass("secp256k1_gej_add_ge", 0, 7, 16, formula_secp256k1_gej_add_ge)
|
|
success = success & (not check_symbolic_jacobian_weierstrass("secp256k1_gej_add_ge_old [should fail]", 0, 7, 4, formula_secp256k1_gej_add_ge_old))
|
|
|
|
if len(sys.argv) >= 2 and sys.argv[1] == "--exhaustive":
|
|
success = success & check_exhaustive_jacobian_weierstrass("secp256k1_gej_add_var", 0, 7, 5, formula_secp256k1_gej_add_var, 43)
|
|
success = success & check_exhaustive_jacobian_weierstrass("secp256k1_gej_add_ge_var", 0, 7, 5, formula_secp256k1_gej_add_ge_var, 43)
|
|
success = success & check_exhaustive_jacobian_weierstrass("secp256k1_gej_add_zinv_var", 0, 7, 5, formula_secp256k1_gej_add_zinv_var, 43)
|
|
success = success & check_exhaustive_jacobian_weierstrass("secp256k1_gej_add_ge", 0, 7, 16, formula_secp256k1_gej_add_ge, 43)
|
|
success = success & (not check_exhaustive_jacobian_weierstrass("secp256k1_gej_add_ge_old [should fail]", 0, 7, 4, formula_secp256k1_gej_add_ge_old, 43))
|
|
|
|
sys.exit(int(not success))
|