2019-03-27 19:15:23 +08:00
|
|
|
// Copyright 2018 The Go Authors. All rights reserved.
|
|
|
|
// Use of this source code is governed by a BSD-style
|
|
|
|
// license that can be found in the LICENSE file.
|
|
|
|
|
2020-05-10 19:42:52 +02:00
|
|
|
// +build !gccgo,!purego
|
2019-03-27 19:15:23 +08:00
|
|
|
|
|
|
|
package poly1305
|
|
|
|
|
2019-05-13 08:38:53 -07:00
|
|
|
import (
|
|
|
|
"golang.org/x/sys/cpu"
|
|
|
|
)
|
2019-03-27 19:15:23 +08:00
|
|
|
|
2020-05-10 19:42:52 +02:00
|
|
|
// updateVX is an assembly implementation of Poly1305 that uses vector
|
2019-03-27 19:15:23 +08:00
|
|
|
// instructions. It must only be called if the vector facility (vx) is
|
|
|
|
// available.
|
|
|
|
//go:noescape
|
2020-05-10 19:42:52 +02:00
|
|
|
func updateVX(state *macState, msg []byte)
|
2019-03-27 19:15:23 +08:00
|
|
|
|
2020-05-10 19:42:52 +02:00
|
|
|
// mac is a replacement for macGeneric that uses a larger buffer and redirects
|
|
|
|
// calls that would have gone to updateGeneric to updateVX if the vector
|
|
|
|
// facility is installed.
|
|
|
|
//
|
|
|
|
// A larger buffer is required for good performance because the vector
|
|
|
|
// implementation has a higher fixed cost per call than the generic
|
|
|
|
// implementation.
|
|
|
|
type mac struct {
|
|
|
|
macState
|
|
|
|
|
|
|
|
buffer [16 * TagSize]byte // size must be a multiple of block size (16)
|
|
|
|
offset int
|
|
|
|
}
|
2019-03-27 19:15:23 +08:00
|
|
|
|
2020-05-10 19:42:52 +02:00
|
|
|
func (h *mac) Write(p []byte) (int, error) {
|
|
|
|
nn := len(p)
|
|
|
|
if h.offset > 0 {
|
|
|
|
n := copy(h.buffer[h.offset:], p)
|
|
|
|
if h.offset+n < len(h.buffer) {
|
|
|
|
h.offset += n
|
|
|
|
return nn, nil
|
2019-03-27 19:15:23 +08:00
|
|
|
}
|
2020-05-10 19:42:52 +02:00
|
|
|
p = p[n:]
|
|
|
|
h.offset = 0
|
|
|
|
if cpu.S390X.HasVX {
|
|
|
|
updateVX(&h.macState, h.buffer[:])
|
2019-03-27 19:15:23 +08:00
|
|
|
} else {
|
2020-05-10 19:42:52 +02:00
|
|
|
updateGeneric(&h.macState, h.buffer[:])
|
2019-03-27 19:15:23 +08:00
|
|
|
}
|
|
|
|
}
|
2020-05-10 19:42:52 +02:00
|
|
|
|
|
|
|
tail := len(p) % len(h.buffer) // number of bytes to copy into buffer
|
|
|
|
body := len(p) - tail // number of bytes to process now
|
|
|
|
if body > 0 {
|
|
|
|
if cpu.S390X.HasVX {
|
|
|
|
updateVX(&h.macState, p[:body])
|
|
|
|
} else {
|
|
|
|
updateGeneric(&h.macState, p[:body])
|
|
|
|
}
|
|
|
|
}
|
|
|
|
h.offset = copy(h.buffer[:], p[body:]) // copy tail bytes - can be 0
|
|
|
|
return nn, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (h *mac) Sum(out *[TagSize]byte) {
|
|
|
|
state := h.macState
|
|
|
|
remainder := h.buffer[:h.offset]
|
|
|
|
|
|
|
|
// Use the generic implementation if we have 2 or fewer blocks left
|
|
|
|
// to sum. The vector implementation has a higher startup time.
|
|
|
|
if cpu.S390X.HasVX && len(remainder) > 2*TagSize {
|
|
|
|
updateVX(&state, remainder)
|
|
|
|
} else if len(remainder) > 0 {
|
|
|
|
updateGeneric(&state, remainder)
|
|
|
|
}
|
|
|
|
finalize(out, &state.h, &state.s)
|
2019-03-27 19:15:23 +08:00
|
|
|
}
|