2021-02-25 13:31:15 -08:00
|
|
|
#!/usr/bin/env python3
|
|
|
|
import sys; assert sys.version_info[0] >= 3, "Python 3 required."
|
|
|
|
|
|
|
|
import math
|
|
|
|
|
|
|
|
import orchard_iso_pallas
|
|
|
|
|
2021-04-26 17:28:43 -07:00
|
|
|
from orchard_pallas import Fp, Point
|
2021-05-06 07:53:12 -07:00
|
|
|
from utils import cldiv, lebs2ip, i2leosp
|
2021-04-26 17:28:43 -07:00
|
|
|
from orchard_group_hash import group_hash
|
2021-04-26 20:41:19 -07:00
|
|
|
from tv_output import render_args, render_tv
|
2021-04-28 17:59:16 -07:00
|
|
|
from tv_rand import Rand
|
2021-02-25 13:31:15 -08:00
|
|
|
|
|
|
|
SINSEMILLA_K = 10
|
|
|
|
|
2021-04-26 20:12:20 -07:00
|
|
|
# Interprets a string or a list as a sequence of bits.
|
|
|
|
def str_to_bits(s):
|
|
|
|
for c in s:
|
|
|
|
assert c in ['0', '1', 0, 1, False, True]
|
|
|
|
# Regular Python truthiness is fine here except for bool('0') == True.
|
|
|
|
return [c != '0' and bool(c) for c in s]
|
2021-02-25 13:31:15 -08:00
|
|
|
|
2021-04-26 20:12:20 -07:00
|
|
|
def pad(n, m):
|
|
|
|
padding_needed = n * SINSEMILLA_K - len(m)
|
|
|
|
zeros = [0] * padding_needed
|
|
|
|
m = list(m) + zeros
|
2021-02-25 13:31:15 -08:00
|
|
|
|
2021-04-26 20:12:20 -07:00
|
|
|
return [lebs2ip(str_to_bits(m[i*SINSEMILLA_K : (i+1)*SINSEMILLA_K])) for i in range(n)]
|
2021-02-25 13:31:15 -08:00
|
|
|
|
|
|
|
def sinsemilla_hash_to_point(d, m):
|
2021-04-26 20:12:20 -07:00
|
|
|
n = cldiv(len(m), SINSEMILLA_K)
|
2021-02-25 13:31:15 -08:00
|
|
|
m = pad(n, m)
|
|
|
|
acc = group_hash(b"z.cash:SinsemillaQ", d)
|
|
|
|
|
|
|
|
for m_i in m:
|
2021-04-26 17:21:01 -07:00
|
|
|
acc = acc.checked_incomplete_add(
|
|
|
|
group_hash(b"z.cash:SinsemillaS", i2leosp(32, m_i))
|
|
|
|
).checked_incomplete_add(acc)
|
2021-04-02 09:57:29 -07:00
|
|
|
|
2021-02-25 13:31:15 -08:00
|
|
|
return acc
|
|
|
|
|
|
|
|
def sinsemilla_hash(d, m):
|
|
|
|
return sinsemilla_hash_to_point(d, m).extract()
|
|
|
|
|
2021-04-02 09:57:29 -07:00
|
|
|
|
2021-04-26 20:41:19 -07:00
|
|
|
def main():
|
|
|
|
test_vectors = [
|
|
|
|
# 40 bits, so no padding
|
|
|
|
(b"z.cash:test-Sinsemilla", [0,0,0,1,0,1,1,0,1,0,1,0,0,1,1,0,0,0,1,1,0,1,1,0,0,0,1,1,0,1,1,0,1,1,1,1,0,1,1,0]),
|
|
|
|
]
|
|
|
|
|
|
|
|
sh = sinsemilla_hash_to_point(test_vectors[0][0], test_vectors[0][1])
|
2021-04-02 09:57:29 -07:00
|
|
|
assert sh == Point(Fp(19681977528872088480295086998934490146368213853811658798708435106473481753752),
|
|
|
|
Fp(14670850419772526047574141291705097968771694788047376346841674072293161339903))
|
2021-04-26 20:41:19 -07:00
|
|
|
|
2021-04-28 17:59:16 -07:00
|
|
|
from random import Random
|
|
|
|
rng = Random(0xabad533d)
|
|
|
|
def randbytes(l):
|
|
|
|
ret = []
|
|
|
|
while len(ret) < l:
|
|
|
|
ret.append(rng.randrange(0, 256))
|
|
|
|
return bytes(ret)
|
|
|
|
rand = Rand(randbytes)
|
|
|
|
|
|
|
|
# Generate test vectors with the following properties:
|
|
|
|
# - One of two domains.
|
|
|
|
# - Random message lengths between 0 and 255 bytes.
|
|
|
|
# - Random message bits.
|
|
|
|
for _ in range(10):
|
|
|
|
domain = b"z.cash:test-Sinsemilla-longer" if rand.bool() else b"z.cash:test-Sinsemilla"
|
|
|
|
msg_len = rand.u8()
|
|
|
|
msg = bytes([rand.bool() for _ in range(msg_len)])
|
|
|
|
test_vectors.append((domain, msg))
|
|
|
|
|
2021-04-26 20:41:19 -07:00
|
|
|
test_vectors = [{
|
|
|
|
'domain': domain,
|
|
|
|
'msg': msg,
|
|
|
|
'point': bytes(sinsemilla_hash_to_point(domain, msg)),
|
|
|
|
'hash': bytes(sinsemilla_hash(domain, msg)),
|
|
|
|
} for (domain, msg) in test_vectors]
|
|
|
|
|
|
|
|
render_tv(
|
|
|
|
render_args(),
|
|
|
|
'orchard_sinsemilla',
|
|
|
|
(
|
|
|
|
('domain', 'Vec<u8>'),
|
|
|
|
('msg', {
|
|
|
|
'rust_type': 'Vec<bool>',
|
|
|
|
'rust_fmt': lambda x: str_to_bits(x),
|
|
|
|
}),
|
|
|
|
('point', '[u8; 32]'),
|
|
|
|
('hash', '[u8; 32]'),
|
|
|
|
),
|
|
|
|
test_vectors,
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
|
if __name__ == "__main__":
|
|
|
|
main()
|