Commit graph

102 commits

Author SHA1 Message Date
Isis Lovecruft
f43f4f9770
Update year in copyright notices to 2018. 2018-07-05 00:30:27 +00:00
Sean Bowe
61d6d89cd8
Fix comment describing Montgomery adjustment factor's value. 2018-07-02 10:41:45 -06:00
Henry de Valence
16f39c82e5 Remove yolocrypto from avx2_backend 2018-06-18 13:32:04 -07:00
Henry de Valence
d791047aac Rewrite notes and documentation. 2018-06-18 13:22:03 -07:00
Henry de Valence
15f97221ba Suppress extraneous warnings 2018-06-15 13:44:31 -07:00
Henry de Valence
7198719419 Document bounds on FieldElement32x4 functions 2018-06-15 13:36:38 -07:00
Henry de Valence
9f5bd8c4c0 Rename reduce32 to reduce and have it return its result.
This means that all FieldElement32x4 operations return values, vs mutating interior state.
2018-06-14 15:54:36 -07:00
Henry de Valence
bab1ebbeb8 Replace scale_by_curve_constants by a Mul<(u32,u32,u32,u32)> impl 2018-06-14 15:42:20 -07:00
Henry de Valence
6ef9e9dcfb Make publicity a little more consistent 2018-06-14 15:22:16 -07:00
Henry de Valence
97292fef91 Move packing functions to top of the module 2018-06-14 15:21:51 -07:00
Henry de Valence
4dc219910a Move blend_lanes into the blend function 2018-06-14 15:13:53 -07:00
Henry de Valence
64b1b481ba Rewrite diff_sum in terms of shuffle, blend, negate 2018-06-14 14:59:11 -07:00
Henry de Valence
fe51adad31 Don't expose u32x8 unpacking functions 2018-06-14 14:32:13 -07:00
Henry de Valence
c46ec9638c Add documentation 2018-06-14 14:23:24 -07:00
Henry de Valence
eea3eadf5b Replace special-case swap_{AB,CD} methods with general shuffles 2018-06-14 14:23:24 -07:00
Henry de Valence
02296fafb5 Delete unused constant 2018-06-14 14:23:24 -07:00
Henry de Valence
25d9f3f6ca Eliminate vector constants from edwards module 2018-06-14 14:23:24 -07:00
Henry de Valence
cc8728b2a6 Add comment about rustc-constant-info to blend function 2018-06-14 14:23:24 -07:00
Henry de Valence
28f10bc183 Change Lanes::ALL to Lanes::ABCD for consistency 2018-06-14 14:23:24 -07:00
Henry de Valence
794ed5c8e3 Rewrite the doubling horrorshow 2018-06-14 14:23:24 -07:00
Henry de Valence
30a2b01c05 Add more selectors to the Lanes enum 2018-06-14 14:19:46 -07:00
Henry de Valence
64cb999866 Make platform-vector lanes constants private 2018-06-14 14:19:26 -07:00
Henry de Valence
00d8b6ea4f Change negate_D, negate_D_lazy to impl Neg, negate_lazy 2018-06-14 14:17:36 -07:00
Henry de Valence
14ce6d3da6 Add a shuffling abstraction for FieldElement32x4 2018-06-14 14:10:37 -07:00
Henry de Valence
c8dc2a6418 Implement addition for FieldElement32x4 2018-06-14 14:10:32 -07:00
Henry de Valence
bd1e3c5f3e some rustfmt changes 2018-06-14 14:05:52 -07:00
Henry de Valence
149c5004e8 Use multiscalar traits for the backend implementations. 2018-05-15 11:33:38 -07:00
Henry de Valence
34c43c20a9 Rework backend selection code.
Each backend can now be selected by an individual feature:

- `u32_backend` for `backend::u32`;
- `u64_backend` for `backend::u64`;
- `avx2_backend` for `backend::avx2`;

The `u64_backend` is selected by default, since most people use X64 and we have
no way to select based on target (see discussion in #126).  However, these
changes mean that it is possible to select the backend explicitly, and if we
had the ability to select target-default features, we could do so easily.
2018-05-14 17:43:54 -07:00
Henry de Valence
9b6c932635 Rename 'precomputed_tables' to the more accurate 'stage2_build' 2018-05-14 15:41:45 -07:00
Henry de Valence
185bbd3da8 Fix build on recent nightlies (was broken due to type inference failure) 2018-05-02 17:30:10 -07:00
Henry de Valence
285e57f2ff
Merge pull request #128 from hdevalence/feature/avx2-docs
Update docs for AVX2 backend
2018-04-08 17:16:05 -07:00
Henry de Valence
67ba201835 Update AVX2 documentation 2018-04-08 16:59:57 -07:00
Henry de Valence
9fc5602ce7 Split AVX2 docs into markdown file 2018-04-08 15:15:23 -07:00
Henry de Valence
6b768c2a1a Change AVX2 backend to use width-8 tables 2018-04-05 16:20:47 -07:00
Henry & Isis
753a0292de
Rename OddLookupTable to NafLookupTable5.
An OddLookupTable corresponds to a non-adjacent form of width 5.
2018-04-05 04:48:28 +00:00
Henry de Valence
7e0ddf6b98 Rewrite NAF code to work with more window sizes
Change Scalar::non_adjacent_form() to take a width parameter.

This rewrite also makes it faster, although it's probably a ways off
from optimal. I don't know how much it matters.

TODO: write up description of why this computes the same thing.

Thanks to @oleganza for pointing out an error reading bits across words
in an earlier version of this code.
2018-04-04 21:13:09 -07:00
Henry de Valence
5f136fbd0c Remove some warnings.
Not all of the warnings are removed, since although this code works, it still
needs a significant amount of cleanup, editing, and polish.
2018-04-04 10:25:42 -07:00
Henry de Valence
b0bda0278c Drop the stdsimd crate in favor of core::{simd, arch}.
This change required some work, because the to-be-stabilized SIMD functions
don't allow non-constant `imm8`s.  Previously, the `stdsimd` functions had a
constifying macro that ensured that the immediates were known.  The dalek code
used this to build helper functions which would be inlined into different
places where the immediates were known.  Unfortunately, since constexprs aren't
fully supported in Rust yet, this is done by a hidden compiler attribute, and
there's no way to propagate "constness".

To deal with this, some of the functions are specialized (e.g.,
`square_and_negate_D` instead of taking a mask), and others use an enum.
2018-04-03 17:58:23 -07:00
Henry de Valence
4a648df713 Feature-gate multiscalar impls on alloc 2018-03-26 17:58:31 -07:00
Henry de Valence
7ef6a1e6fa Reorganize AVX2 point code 2018-03-26 17:41:05 -07:00
Henry de Valence
e8b053b281 Remove AVX2 addition formulas
Only the readdition formulas are actually used by scalar multiplication, so
there's no reason to implement vectorized addition.
2018-03-26 17:41:05 -07:00
Henry de Valence
c73a0fd0d6 Remove AVX2 fixed-base code.
This was faster than the non-AVX2 code, but the serial code is already so fast that there's no reason not to use it.
2018-03-26 17:41:05 -07:00
Henry de Valence
0c4e7188a0 Pull out vartime double-base scalar mul code 2018-03-26 17:41:05 -07:00
Henry de Valence
2d99892eab Pull out variable-time straus implementation 2018-03-26 17:41:05 -07:00
Henry de Valence
2864a422bc Pull out constant-time straus implementation 2018-03-26 16:04:17 -07:00
Henry de Valence
ac739a3edd Split out constant-time variable-base scalar mul.
The serial (`u32`/`u64`) implementations use a multiple curve models, passing
between extended and projective coordinates when performing addition and
doubling (respectively). But the AVX2 backend doesn't, so in order to write a
single scalar mult implementation, we have to either abstract over the curve
models or have two implementations.

A generic solution is possible but extremely unreadable: the scalar mul
implementation would be parameterized over the point types used by the serial
implementations, with many where clauses describing how the types relate. The
AVX2 types could then be substituted in the appropriate places.

Instead we just duplicate the code into the `avx2` backend.
2018-03-26 16:01:51 -07:00
Henry de Valence
76a8d43a04 Create a new scalar_mul module hierarchy.
This should contain generic implementations of scalar multiplication algorithms
that can be used with multiple backends.  The goal is to move the existing
scalar multiplication code into this submodule, then call it from the
user-facing API.  This can also contain code for things we can't do now, like
multiscalar multiplication with precomputation.
2018-03-26 14:34:28 -07:00
Henry de Valence
d6b8389428 Use criterion.rs instead of libtest for benchmarks.
Since Criterion can only benchmark public API, these changes just drop
all internal benchmarks (e.g., benchmarks for field operations). But
those are usually microbenchmarks whose meaning is kind of questionable
anyways, so I don't think this is a big loss.

The `bench` feature disappears, since Criterion works on stable Rust.
2018-03-25 17:14:37 -07:00
Henry de Valence
c9239f54e9 Merge branch 'fix/warnings' into develop 2018-03-22 12:34:31 -07:00
Henry de Valence
f2e44898ee Suppress warnings about square() on UnpackedScalars 2018-03-22 12:17:23 -07:00