src/crypto/blake/blake3/compress.bend source
src/crypto/blake/blake3/compress.bend on the hub · documented module
import Baseimport ./types.bend as T# Generated by tools/generators/blake3/gen.py; do not edit by hand.def rot16(+x: U32) -> U32: U32.or(U32.shrn(x,16n),U32.shln(x,16n))def rot12(+x: U32) -> U32: U32.or(U32.shrn(x,12n),U32.shln(x,20n))def rot8(+x: U32) -> U32: U32.or(U32.shrn(x,8n),U32.shln(x,24n))def rot7(+x: U32) -> U32: U32.or(U32.shrn(x,7n),U32.shln(x,25n))# G on the four columns, message words m0..m7.def column(s: T.St, +m0: U32, +m1: U32, +m2: U32, +m3: U32, +m4: U32, +m5: U32, +m6: U32, +m7: U32) -> T.St: match s: case T.St{+v0,+v1,+v2,+v3,+v4,+v5,+v6,+v7,+v8,+v9,+v10,+v11,+v12,+v13,+v14,+v15}: +t0 = U32.add(U32.add(v0,v4),m0) +t1 = rot16(U32.xor(v12,t0)) +t2 = U32.add(v8,t1) +t3 = rot12(U32.xor(v4,t2)) +t4 = U32.add(U32.add(t0,t3),m1) +t5 = rot8(U32.xor(t1,t4)) +t6 = U32.add(t2,t5) +t7 = rot7(U32.xor(t3,t6)) +t8 = U32.add(U32.add(v1,v5),m2) +t9 = rot16(U32.xor(v13,t8)) +t10 = U32.add(v9,t9) +t11 = rot12(U32.xor(v5,t10)) +t12 = U32.add(U32.add(t8,t11),m3) +t13 = rot8(U32.xor(t9,t12)) +t14 = U32.add(t10,t13) +t15 = rot7(U32.xor(t11,t14)) +t16 = U32.add(U32.add(v2,v6),m4) +t17 = rot16(U32.xor(v14,t16)) +t18 = U32.add(v10,t17) +t19 = rot12(U32.xor(v6,t18)) +t20 = U32.add(U32.add(t16,t19),m5) +t21 = rot8(U32.xor(t17,t20)) +t22 = U32.add(t18,t21) +t23 = rot7(U32.xor(t19,t22)) +t24 = U32.add(U32.add(v3,v7),m6) +t25 = rot16(U32.xor(v15,t24)) +t26 = U32.add(v11,t25) +t27 = rot12(U32.xor(v7,t26)) +t28 = U32.add(U32.add(t24,t27),m7) +t29 = rot8(U32.xor(t25,t28)) +t30 = U32.add(t26,t29) +t31 = rot7(U32.xor(t27,t30)) T.St{t4,t12,t20,t28,t7,t15,t23,t31,t6,t14,t22,t30,t5,t13,t21,t29}# G on the four diagonals, message words m8..m15.def diagonal(s: T.St, +m8: U32, +m9: U32, +m10: U32, +m11: U32, +m12: U32, +m13: U32, +m14: U32, +m15: U32) -> T.St: match s: case T.St{+v0,+v1,+v2,+v3,+v4,+v5,+v6,+v7,+v8,+v9,+v10,+v11,+v12,+v13,+v14,+v15}: +t0 = U32.add(U32.add(v0,v5),m8) +t1 = rot16(U32.xor(v15,t0)) +t2 = U32.add(v10,t1) +t3 = rot12(U32.xor(v5,t2)) +t4 = U32.add(U32.add(t0,t3),m9) +t5 = rot8(U32.xor(t1,t4)) +t6 = U32.add(t2,t5) +t7 = rot7(U32.xor(t3,t6)) +t8 = U32.add(U32.add(v1,v6),m10) +t9 = rot16(U32.xor(v12,t8)) +t10 = U32.add(v11,t9) +t11 = rot12(U32.xor(v6,t10)) +t12 = U32.add(U32.add(t8,t11),m11) +t13 = rot8(U32.xor(t9,t12)) +t14 = U32.add(t10,t13) +t15 = rot7(U32.xor(t11,t14)) +t16 = U32.add(U32.add(v2,v7),m12) +t17 = rot16(U32.xor(v13,t16)) +t18 = U32.add(v8,t17) +t19 = rot12(U32.xor(v7,t18)) +t20 = U32.add(U32.add(t16,t19),m13) +t21 = rot8(U32.xor(t17,t20)) +t22 = U32.add(t18,t21) +t23 = rot7(U32.xor(t19,t22)) +t24 = U32.add(U32.add(v3,v4),m14) +t25 = rot16(U32.xor(v14,t24)) +t26 = U32.add(v9,t25) +t27 = rot12(U32.xor(v4,t26)) +t28 = U32.add(U32.add(t24,t27),m15) +t29 = rot8(U32.xor(t25,t28)) +t30 = U32.add(t26,t29) +t31 = rot7(U32.xor(t27,t30)) T.St{t4,t12,t20,t28,t31,t7,t15,t23,t22,t30,t6,t14,t13,t21,t29,t5}# One round: the column step then the diagonal step.def round(s: T.St, +m0: U32, +m1: U32, +m2: U32, +m3: U32, +m4: U32, +m5: U32, +m6: U32, +m7: U32, +m8: U32, +m9: U32, +m10: U32, +m11: U32, +m12: U32, +m13: U32, +m14: U32, +m15: U32) -> T.St: diagonal(column(s,m0,m1,m2,m3,m4,m5,m6,m7),m8,m9,m10,m11,m12,m13,m14,m15)def fold(s: T.St) -> T.CV: match s: case T.St{v0,v1,v2,v3,v4,v5,v6,v7,v8,v9,v10,v11,v12,v13,v14,v15}: T.CV{U32.xor(v0,v8),U32.xor(v1,v9),U32.xor(v2,v10),U32.xor(v3,v11),U32.xor(v4,v12),U32.xor(v5,v13),U32.xor(v6,v14),U32.xor(v7,v15)}# The initial state: the chaining value, IV[0..3], the counter (low word,# then the high word, 0: an input has fewer than 2^32 chunks), the block# length and the flags.def init(cv: T.CV, +t: U32, +len: U32, +flags: U32) -> T.St: match cv: case T.CV{h0,h1,h2,h3,h4,h5,h6,h7}: T.St{h0,h1,h2,h3,h4,h5,h6,h7,1779033703,3144134277,1013904242,2773480762,t,0,len,flags}# Seven rounds; round r takes the message words in the order of the# permutation applied r times (the fixed BLAKE3 schedule).def rounds7(s: T.St, b: T.Block) -> T.St: match b: case T.B{+m0,+m1,+m2,+m3,+m4,+m5,+m6,+m7,+m8,+m9,+m10,+m11,+m12,+m13,+m14,+m15}: round(round(round(round(round(round(round(s,m0,m1,m2,m3,m4,m5,m6,m7,m8,m9,m10,m11,m12,m13,m14,m15),m2,m6,m3,m10,m7,m0,m4,m13,m1,m11,m12,m5,m9,m14,m15,m8),m3,m4,m10,m12,m13,m2,m7,m14,m6,m5,m9,m0,m11,m15,m8,m1),m10,m7,m12,m9,m14,m3,m13,m15,m4,m0,m11,m2,m5,m8,m1,m6),m12,m13,m9,m11,m15,m10,m14,m8,m7,m2,m5,m3,m0,m1,m6,m4),m9,m14,m11,m5,m8,m12,m15,m1,m13,m3,m0,m10,m2,m6,m4,m7),m11,m15,m5,m0,m1,m9,m8,m6,m14,m10,m2,m12,m3,m4,m7,m13)# The compression function (hash mode, 32-byte output): the new chaining# value is the low half of the final state xor its high half.def compress(cv: T.CV, b: T.Block, +t: U32, +len: U32, +flags: U32) -> T.CV: fold(rounds7(init(cv,t,len,flags),b))