2020-10-14 16:21:43 +02:00
|
|
|
module subtle
|
|
|
|
|
|
|
|
// constant_time_byte_eq returns 1 when x == y.
|
2020-10-21 11:23:03 +02:00
|
|
|
pub fn constant_time_byte_eq(x byte, y byte) int {
|
2020-10-14 16:21:43 +02:00
|
|
|
return int((u32(x ^ y) - 1) >> 31)
|
|
|
|
}
|
|
|
|
|
|
|
|
// constant_time_eq returns 1 when x == y.
|
2020-10-21 11:23:03 +02:00
|
|
|
pub fn constant_time_eq(x int, y int) int {
|
2020-10-14 16:21:43 +02:00
|
|
|
return int((u64(u32(x ^ y)) - 1) >> 63)
|
|
|
|
}
|
|
|
|
|
|
|
|
// constant_time_select returns x when v == 1, and y when v == 0.
|
|
|
|
// it is undefined when v is any other value
|
2020-10-21 11:23:03 +02:00
|
|
|
pub fn constant_time_select(v int, x int, y int) int {
|
2020-10-14 16:21:43 +02:00
|
|
|
return (~(v - 1) & x) | ((v - 1) & y)
|
|
|
|
}
|
|
|
|
|
|
|
|
// constant_time_compare returns 1 when x and y have equal contents.
|
|
|
|
// The runtime of this function is proportional of the length of x and y.
|
|
|
|
// It is *NOT* dependent on their content.
|
2022-04-15 14:35:35 +02:00
|
|
|
pub fn constant_time_compare(x []u8, y []u8) int {
|
2020-10-14 16:21:43 +02:00
|
|
|
if x.len != y.len {
|
|
|
|
return 0
|
|
|
|
}
|
2022-04-15 13:58:56 +02:00
|
|
|
mut v := u8(0)
|
2020-10-14 16:21:43 +02:00
|
|
|
for i in 0 .. x.len {
|
|
|
|
v |= x[i] ^ y[i]
|
|
|
|
}
|
|
|
|
return constant_time_byte_eq(v, 0)
|
|
|
|
}
|
|
|
|
|
|
|
|
// constant_time_copy copies the contents of y into x, when v == 1.
|
|
|
|
// When v == 0, x is left unchanged. this function is undefined, when
|
|
|
|
// v takes any other value
|
2022-04-15 14:35:35 +02:00
|
|
|
pub fn constant_time_copy(v int, mut x []u8, y []u8) {
|
2020-10-14 16:21:43 +02:00
|
|
|
if x.len != y.len {
|
|
|
|
panic('subtle: arrays have different lengths')
|
|
|
|
}
|
2022-04-15 13:58:56 +02:00
|
|
|
xmask := u8(v - 1)
|
|
|
|
ymask := u8(~(v - 1))
|
2020-10-14 16:21:43 +02:00
|
|
|
for i := 0; i < x.len; i++ {
|
|
|
|
x[i] = x[i] & xmask | y[i] & ymask
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// constant_time_less_or_eq returns 1 if x <= y, and 0 otherwise.
|
|
|
|
// it is undefined when x or y are negative, or > (2^32 - 1)
|
2020-10-21 11:23:03 +02:00
|
|
|
pub fn constant_time_less_or_eq(x int, y int) int {
|
2020-10-14 16:21:43 +02:00
|
|
|
x32 := int(x)
|
|
|
|
y32 := int(y)
|
|
|
|
return int(((x32 - y32 - 1) >> 31) & 1)
|
|
|
|
}
|