src/crypto/ed25519/scalar.bend checks
raw source on the hub · import 0xd9a2fae439ac7ff9e21e0853948f94fe/src/crypto/ed25519/scalar.bend as Scalar
3 imports
import Base import ../curve25519/field.bend as F import ../curve25519/x25519.bend as X
Definitions
def ell source · line 20 · raw
List<&2, U32>
L, little-endian bytes
def comp_l source · line 25 · raw
List<&2, U32>
2^256 - L
def csub source · line 30 · raw
@+x:List<&2, U32> -> List<&2, U32>
x - L when x >= L, else x (x tight, x < 2 L)
def addm source · line 33 · raw
@a:List<&2, U32> -> @b:List<&2, U32> -> List<&2, U32>
def mac source · line 37 · raw
@n:Nat -> @+bs:List<&2, U32> -> @+s:List<&2, U32> -> @+acc:List<&2, U32> -> List<&2, U32>
bits t = n - 1 down to 0 of bs: acc = 2 acc + bit s (mod L)
def reduce source · line 45 · raw
@+bs:List<&2, U32> -> List<&2, U32>
def mul_add source · line 48 · raw
@+k:List<&2, U32> -> @+s:List<&2, U32> -> @r:List<&2, U32> -> List<&2, U32>
def lt_l source · line 52 · raw
@+x:List<&2, U32> -> Bool
x < L: the carry of x + 2^256 - L is 0