Commit graph

252 commits

Author SHA1 Message Date
François Garillot
756a921bee
bump fiat-crypto version 2021-01-11 09:30:30 -08:00
François Garillot
3422872346
bump fiat-crypto version 2021-01-11 09:30:30 -08:00
François Garillot
4ce680d3aa
Update the fiat backend to use the fiat-crypto package
https://crates.io/crates/fiat-crypto
2021-01-11 09:30:30 -08:00
François Garillot
d684e13f09
Add a fiat_u64_backend option to curve25519-dalek
This uses https://github.com/calibra/rust-curve25519-fiat/ to implement a new 64bit serial backend for dalek.

Co-authored-by: Zoe Parakevopoulou <zoopar@fb.com>
2021-01-11 09:30:07 -08:00
Paul Grandperrin
d0dacb2699 Update rand to 0.8 2021-01-10 15:13:58 -03:00
Paul Grandperrin
86cdb11cf2 Update rand_core to 0.6
https://github.com/rust-random/rand/blob/master/rand_core/CHANGELOG.md
This new version makes using rand_core on wasm seamless (thanks to the update of getrandom to v0.2)
The crate compiles well with this PR, but since some `rand_core` traits are publicly exposed in this crate's API, this is strictly speaking a breaking change.
2021-01-10 15:13:58 -03:00
Isis Lovecruft
55e0db7cf6
Bump curve25519-dalek version to 3.0.2. 2021-01-08 03:32:42 +00:00
Isis Lovecruft
e47a180991
Bump curve25519-dalek to 3.0.1. 2021-01-07 21:29:17 +00:00
François Garillot
8aa1458941
Implements an Elligator2 map for Curve25519
This implementation:
- is agnostic on the hash used to pick a field element, even though SHA512 is commonly used,
- follows https://tools.ietf.org/id/draft-irtf-cfrg-hash-to-curve-10.html closely
- tests the outputs of the function using libsignal's implementation.
2020-10-21 17:38:22 -04:00
Henry de Valence
45f3f53351
Add link to Cargo.toml with explanation of packed_simd renaming 2020-09-30 12:01:43 -07:00
Markus Zoppelt
f27923bf8c
adjusted dependency entry like to pick up latest pick up the latest packed_simd crate under an alternative name.
see also: https://github.com/rust-lang/packed_simd/issues/303#issuecomment-701361161
2020-09-30 15:17:18 +02:00
Markus Zoppelt
c2e394dd04
bumped packed_simd to 0.3.4. resolves #333 2020-09-30 12:59:10 +02:00
Henry de Valence
6d96eb7796 Bump version to 3.0.0. 2020-08-17 18:20:26 -07:00
François Garillot
6afd8ff212
Update sha2, digest to 0.9 2020-06-15 07:16:04 -04:00
Henry de Valence
3fc47ef867 Bump version to 2.1.0 2020-05-29 12:39:39 -07:00
François Garillot
7b1363a964
Bump criterion version 2020-02-24 14:24:49 -05:00
Isis Lovecruft
eb827d5779
Pin zeroize dependency to =1.3.0 to maintain MSRV 1.41. 2020-02-07 11:31:41 +00:00
Henry de Valence
d889ac8a15 Finalize 2.0.0
This collapses the CHANGELOG entries for the intermediate alpha releases (to be
yanked) into a list of changes from 1.x to 2.0.0.
2019-11-22 13:14:14 -08:00
Henry de Valence
69d72f92d6 Bump version to 2.0.0-alpha.2 and update changelog. 2019-11-15 15:00:15 -08:00
Henry de Valence
2b51978553 Remove nightly recommendation now that subtle has stable opt barriers.
This bumps the required `subtle` version to `2.2.1`, which contains those changes.
2019-11-15 14:29:14 -08:00
Isis Lovecruft
409ebd94c0
Remove dev-dependency on deprecated rand_os crate.
The functionality we were using is now contained in the `rand_core` crate, which
we already depend upon.  As far as testing code goes, only benchmarks still
depend upon `rand`, as they use `thread_rng`.
2019-10-28 18:06:29 +00:00
Henry de Valence
6b71cd863a Update CHANGELOG and bump version 2019-10-25 16:07:19 -07:00
Henry de Valence
6739399ec2 Upgrade to current rand_core, rand, rand_os.
Of these only `rand_core` is included in the public API; regardless of `rand`
semver tricks, this is a breaking API change, but the major version is already
bumped to include the Serde serialization fixes.
2019-10-24 12:29:01 -07:00
Henry de Valence
018fccfe8c Avoid over-specific version specifiers.
By default, Cargo treats version specifiers as semver-compatible ranges, so the
version specifiers we include should only have the components that are actually
meaningful, e.g., "1" instead of "1.0.0" (which actually means "1").
2019-10-24 12:25:50 -07:00
Henry de Valence
a79459a1c8
Merge pull request #289 from tarcieri/zeroize
Switch from `clear_on_drop` to `zeroize` (fixes #281)
2019-10-23 20:17:14 -07:00
Tony Arcieri
9480844b8d Switch from clear_on_drop to zeroize (fixes #281)
`zeroize` is WASM-friendly as it has no dependencies on C compilers.

Instead uses Rust's own volatile write semantics and compiler fences to
ensure zeroization is not elided by the compiler.
2019-10-23 16:39:21 -07:00
Henry de Valence
70e46c9826 Fill in missing Serde impl for MontgomeryPoint. 2019-10-23 15:55:03 -07:00
Henry de Valence
0fc534d989 Use "tuples" instead of "bytes" in the Serde datamodel.
This is a breaking change to the serialization format.  It fixes it so that the
Serde encoding can match the conventional encoding of each type of object, and
so that Serde can be used with no overhead -- when using serde-bincode, the
Serde encoding now matches the manual encoding.
2019-10-23 15:40:50 -07:00
Henry de Valence
574217694e Remove build.rs.
This was more useful at the time when we were determining, e.g., optimal lookup
table sizes and could regenerate them more easily, but it came at a massive
complexity cost.  It also meant that we were unable to implement backend
autoselection.  This commit removes the `build.rs` entirely.  In the future, a
different `build.rs` could be added that auto-selects a backend, but it seems
like the current default-u64 setup has been working fine.
2019-10-23 14:20:38 -07:00
Henry de Valence
4dc8073330 Update CHANGELOG and bump version 2019-08-07 13:24:36 -07:00
Henry de Valence
e6d580b0cf Bump version to 1.2.2 2019-07-31 15:25:22 -07:00
Henry de Valence
78d9804bf9 'crypto' means 'cryptography' 2019-07-30 12:43:56 -07:00
Henry de Valence
45b316d26b Update version to 1.2.1 2019-06-06 15:39:59 -07:00
Henry de Valence
62fbd6ab63 Update version to 1.2.0 2019-06-04 15:27:12 -07:00
isis agora lovecruft
33f21a9f34
Merge pull request #255 from xoloki/no-std-optional-serde
Turn off default serde features but keep it as an optional dependency
2019-06-04 19:39:30 +00:00
Joey Yandle
fd69503a40 turn off default serde features but keep it optional 2019-06-03 15:29:08 -07:00
Henry de Valence
ea9d7411d5 Bump version to 1.1.4 2019-05-06 19:09:04 -07:00
Henry de Valence
bd96f25baa Bump patch version 2019-02-15 13:47:16 -08:00
Henry de Valence
96796e620e Bump patch version 2019-02-15 11:32:54 -08:00
Henry de Valence
64c542ec84 Bump patch version 2019-02-15 11:20:25 -08:00
Henry de Valence
b8c62ec4b4 Attempt to fix cfg(rustdoc) on docs.rs
Building the docs currently doesn't work, because rustdoc enables parts of the
code (to document them) which then don't check (because there are missing
exports or dependencies).  This **should** fix the issue, but there's no way to
test without publishing a new version.
2019-02-15 11:18:25 -08:00
Henry de Valence
ad838ecd73 Remove -pre.0; reword CHANGELOG entries. 2019-02-15 10:11:18 -08:00
Henry de Valence
a35adbef84 Bump version number to 1.1.0-pre.0 2019-02-14 14:49:36 -08:00
Henry de Valence
cf7a1a4a0f Merge branch 'rand_core' of git://github.com/newpavlov/curve25519-dalek into newpavlov-rand_core 2019-02-14 14:29:58 -08:00
Henry de Valence
ff0dc4a3db Merge branch 'master' into develop 2019-01-27 23:19:44 -08:00
Henry de Valence
9cd4551b40 Bump patch version 2019-01-27 23:17:27 -08:00
Henry de Valence
47a164da4d Replace avx2_backend with simd_backend (autoselects AVX2/IFMA) 2019-01-18 01:52:17 -08:00
Henry de Valence
9ed2128a10 Add stub code for IFMA intrinsics in Rust. 2019-01-18 01:52:17 -08:00
Henry de Valence
0328fb1342 Bump patch version 2019-01-17 19:25:34 -08:00
Артём Павлов [Artyom Pavlov]
4e4730303d enable rand_core/std 2019-01-05 14:32:36 +03:00
Артём Павлов [Artyom Pavlov]
d6ca36fa0b replace rand with rand_core+rand_os 2019-01-05 14:27:24 +03:00
Henry de Valence
5d4b5cb2a4 Bump version to 1.0.1 2018-12-13 15:43:26 -08:00
Henry de Valence
fca2cd5f95 Use the released version of subtle (oops) 2018-12-13 15:42:31 -08:00
Henry de Valence
9b4361db8b Finalize 1.0.0 2018-12-13 15:35:32 -08:00
Henry de Valence
7f63eaec60 Bump version to 1.0.0-pre.1 2018-11-18 10:44:30 -08:00
Colt Frederickson
b5d6e94a64 Build for 0.6.0 2018-11-14 14:39:47 -07:00
Henry de Valence
18a7fb360a Bump version to 1.0.0-pre.0 2018-11-05 16:15:07 -08:00
Henry de Valence
92a3b9db49 Change to subtle 2.0.0-pre.0 2018-11-05 15:09:50 -08:00
Henry de Valence
a116fd9679 test subtle 2.0 2018-11-05 12:06:23 -08:00
Henry de Valence
77edbeb7a0 Remove generic-array build dep 2018-11-02 11:41:36 -07:00
Tony Arcieri
31e8626133 Update to digest 0.8 and sha2 0.8
Vicariously updates to `generic-array` 0.12, however this change also
removes `generic-array` as a direct dependency, as it can be sourced
from the `digest` crate.
2018-10-19 10:44:42 -07:00
Henry de Valence
451636b99d Bump version 2018-09-26 16:17:44 -07:00
Henry de Valence
18391bfc5f Add Serde support for compressed points; use bincode for tests. 2018-09-26 15:46:37 -07:00
Henry de Valence
b0658b05f8 Bump version 2018-09-25 17:21:10 -07:00
Henry de Valence
09048920de
Merge pull request #197 from dalek-cryptography/update-subtle
Update subtle
2018-09-25 17:19:26 -07:00
Henry de Valence
27a9b9940d Update subtle to stable 1.0 2018-09-25 17:02:46 -07:00
Henry de Valence
9dab3641a5 Merge branch 'master' into develop 2018-09-17 12:36:56 -07:00
Henry de Valence
f95806e00d Bump version to 0.19.1
This fixes the AVX2 build on nightly.
2018-09-17 12:33:30 -07:00
Henry de Valence
10d8436f0d Update packed_simd version 2018-09-17 12:29:58 -07:00
Henry de Valence
7d29b86217 Update packed_simd version 2018-09-13 23:36:44 -07:00
Isis Lovecruft
bed5aa00c5
Bump subtle dependency version to 0.9.0. 2018-09-05 03:19:58 +00:00
Henry de Valence
acceea04f6 Bump byteorder version to avoid breaking on stable
As pointed out by @ruuda:

> This is more of a problem with `#[feature]` in Rust; once a feature becomes
> stable, having `#[feature]` becomes an error, so it is not easy to depend on a
> feature on nightly, and then have the same code work on stable once the feature
> is stabilized.

The earliest `byteorder` version without a `#[feature]` is `1.2.3`, so we
require any higher version than that one.

Closes #184.
Closes #186.
2018-08-27 11:48:53 -07:00
Henry de Valence
8a488d3032 Bump version number to 0.19.0
Add an interim version prior to 1.0.0-pre.0 in order to fix the AVX2
build.
2018-07-26 20:34:00 -07:00
Henry de Valence
288625418d Migrate to packed_simd from core::simd 2018-07-26 12:40:34 -07:00
Tony Arcieri
10e8abf926 Unify alloc and std cargo features
This change provides a common convention for using allocator-dependent
features with:

    #![cfg(feature = "alloc")]

When available, `Vec` is imported consistently as `prelude::Vec`, which
means modules that need access to `Vec` can simply do:

    use prelude::*;

and if an allocator is available, `Vec` will be in the crate prelude.

This allows all `alloc` vs `std` gating to be handled in `lib.rs`,
`build.rs`, and `prelude.rs` so the rest of the codebase doesn't have to
do any gating whatsoever.
2018-07-23 10:50:21 -07:00
Henry de Valence
1e74cb3e56 Replace Scalar::from_u64 with From impls
Unfortunately, Rust selects `i32` as the type for an integer literal
when the literal has no other type constraints.  This means that someone
cannot write `Scalar::from(1)`, as Rust will choose `i32` as the type for
`1`, and we don't `impl From<i32> for Scalar`.

We could implement `From` conversions for signed integers, but since
`Scalar` operations should be constant-time by default, this would
require us to extract the sign bit of the integer and use it to
conditionally select between the positive and negative of Scalar
constructed from the value bits.  This is more expensive than the
unsigned operation, and I don't think it's what anyone really wants.

Making API consumers specify that their literals are unsigned is
slightly annoying, but better than the above alternative.

It would also be nice to change `Scalar::from_hash` to be
`impl<D: Digest<OutputSize = U64>> From<D> for Scalar`,
but this isn't currently allowed by Rust (since that `impl` "could"
conflict with the `impl From<u8>` if someone decided that `u8` should
`impl Digest`).
2018-07-19 08:39:09 -07:00
Henry de Valence
f6f20f4598
Merge pull request #152 from isislovecruft/feature/update-rand-0.5.3
Update rand dependency to 0.5.3.
2018-07-05 11:52:46 -07:00
Isis Lovecruft
3dbfad2f7a
Update rand dependency to 0.5. 2018-07-04 20:16:31 +00:00
Isis Lovecruft
b214e6e796
Bump subtle dependency to 0.7.0. 2018-07-04 19:56:16 +00:00
Henry de Valence
28b7ed5709 Change version to 0.18.0 (since feature flags changed) 2018-06-22 12:24:20 -07:00
Tony Arcieri
42430f1a1f Upgrade rand to (non-pre)release version 0.5
It was previously using pre-release version 0.5.0-pre.2
2018-06-02 11:17:10 -07:00
Isis Lovecruft
337de2a204
Bump curve25519-dalek version to 0.17.0. 2018-05-15 20:39:01 +00:00
Henry de Valence
bbb64312f7 Use rand 0.5
Requires `0.5.0-pre.2`, which adds `impl CryptoRng for OsRng`.
2018-05-15 12:30:28 -07:00
Henry de Valence
34c43c20a9 Rework backend selection code.
Each backend can now be selected by an individual feature:

- `u32_backend` for `backend::u32`;
- `u64_backend` for `backend::u64`;
- `avx2_backend` for `backend::avx2`;

The `u64_backend` is selected by default, since most people use X64 and we have
no way to select based on target (see discussion in #126).  However, these
changes mean that it is possible to select the backend explicitly, and if we
had the ability to select target-default features, we could do so easily.
2018-05-14 17:43:54 -07:00
Henry de Valence
9b6c932635 Rename 'precomputed_tables' to the more accurate 'stage2_build' 2018-05-14 15:41:45 -07:00
Henry de Valence
7b802c7bf5 Bump version to 0.16.4 2018-05-10 17:46:37 -07:00
Oleg Andreev
2a1e122300 disable default features in byteorder dependency to be no_std-compatible 2018-05-10 15:13:50 -07:00
Henry de Valence
e492ac63d0 Bump version to 0.16.3 2018-04-09 09:50:03 -07:00
Henry de Valence
6bb2c02a1f
Merge pull request #127 from hdevalence/feature/generalize-naf
Generalize NAF code to wider window sizes.
2018-04-08 16:39:45 -07:00
Henry de Valence
dc563c7415 Bump version to 0.16.2
Only change is better Ristretto docs
2018-04-06 15:11:08 -07:00
Henry de Valence
7e0ddf6b98 Rewrite NAF code to work with more window sizes
Change Scalar::non_adjacent_form() to take a width parameter.

This rewrite also makes it faster, although it's probably a ways off
from optimal. I don't know how much it matters.

TODO: write up description of why this computes the same thing.

Thanks to @oleganza for pointing out an error reading bits across words
in an earlier version of this code.
2018-04-04 21:13:09 -07:00
Henry de Valence
207fbb640e Bump version to 0.16.1 2018-04-04 15:30:12 -07:00
Henry de Valence
b0bda0278c Drop the stdsimd crate in favor of core::{simd, arch}.
This change required some work, because the to-be-stabilized SIMD functions
don't allow non-constant `imm8`s.  Previously, the `stdsimd` functions had a
constifying macro that ensured that the immediates were known.  The dalek code
used this to build helper functions which would be inlined into different
places where the immediates were known.  Unfortunately, since constexprs aren't
fully supported in Rust yet, this is done by a hidden compiler attribute, and
there's no way to propagate "constness".

To deal with this, some of the functions are specialized (e.g.,
`square_and_negate_D` instead of taking a mask), and others use an enum.
2018-04-03 17:58:23 -07:00
Henry de Valence
d6b8389428 Use criterion.rs instead of libtest for benchmarks.
Since Criterion can only benchmark public API, these changes just drop
all internal benchmarks (e.g., benchmarks for field operations). But
those are usually microbenchmarks whose meaning is kind of questionable
anyways, so I don't think this is a big loss.

The `bench` feature disappears, since Criterion works on stable Rust.
2018-03-25 17:14:37 -07:00
Henry de Valence
ce439458a1 Bump version to 0.16.0 2018-03-22 12:35:41 -07:00
Henry de Valence
792ac0775e Change to the updated subtle API. 2018-03-22 11:13:26 -07:00
Henry de Valence
151911bc47 Try to tell docs.rs to build using the "nightly" feature
We need this to put the README.md into the docs, or else the crate description is bare.
2018-02-06 11:19:50 -08:00
Henry de Valence
3fb0ccc68f Bump version to 0.15 2018-02-06 10:56:39 -08:00
Henry de Valence
31dbb9e434 Fix no_std build failure 2018-01-26 16:36:42 -08:00
Henry de Valence
04506bbca2 Consolidate Cargo.toml and document the weird build hack 2018-01-26 16:29:23 -08:00