2018-08-21 13:56:50 +00:00
|
|
|
// Copyright 2018 The Go Authors. All rights reserved.
|
|
|
|
// Use of this source code is governed by a BSD-style
|
|
|
|
// license that can be found src the LICENSE file.
|
|
|
|
|
|
|
|
package chacha20
|
|
|
|
|
2019-11-20 05:30:46 +00:00
|
|
|
import "runtime"
|
2018-08-21 13:56:50 +00:00
|
|
|
|
|
|
|
// Platforms that have fast unaligned 32-bit little endian accesses.
|
|
|
|
const unaligned = runtime.GOARCH == "386" ||
|
|
|
|
runtime.GOARCH == "amd64" ||
|
|
|
|
runtime.GOARCH == "arm64" ||
|
|
|
|
runtime.GOARCH == "ppc64le" ||
|
|
|
|
runtime.GOARCH == "s390x"
|
|
|
|
|
2020-05-10 17:42:52 +00:00
|
|
|
// addXor reads a little endian uint32 from src, XORs it with (a + b) and
|
2018-08-21 13:56:50 +00:00
|
|
|
// places the result in little endian byte order in dst.
|
2020-05-10 17:42:52 +00:00
|
|
|
func addXor(dst, src []byte, a, b uint32) {
|
|
|
|
_, _ = src[3], dst[3] // bounds check elimination hint
|
2018-08-21 13:56:50 +00:00
|
|
|
if unaligned {
|
|
|
|
// The compiler should optimize this code into
|
|
|
|
// 32-bit unaligned little endian loads and stores.
|
|
|
|
// TODO: delete once the compiler does a reliably
|
|
|
|
// good job with the generic code below.
|
|
|
|
// See issue #25111 for more details.
|
|
|
|
v := uint32(src[0])
|
|
|
|
v |= uint32(src[1]) << 8
|
|
|
|
v |= uint32(src[2]) << 16
|
|
|
|
v |= uint32(src[3]) << 24
|
2020-05-10 17:42:52 +00:00
|
|
|
v ^= a + b
|
2018-08-21 13:56:50 +00:00
|
|
|
dst[0] = byte(v)
|
|
|
|
dst[1] = byte(v >> 8)
|
|
|
|
dst[2] = byte(v >> 16)
|
|
|
|
dst[3] = byte(v >> 24)
|
|
|
|
} else {
|
2020-05-10 17:42:52 +00:00
|
|
|
a += b
|
|
|
|
dst[0] = src[0] ^ byte(a)
|
|
|
|
dst[1] = src[1] ^ byte(a>>8)
|
|
|
|
dst[2] = src[2] ^ byte(a>>16)
|
|
|
|
dst[3] = src[3] ^ byte(a>>24)
|
2018-08-21 13:56:50 +00:00
|
|
|
}
|
|
|
|
}
|