Files
ww/lib/hash/siphash/siphash.ww
Hojun-Cho aadc6618f0 lib: banner purge + WHY-only comment sweep (rule 8)
Every // ---- section banner dies (132 -> 0): names carry the WHAT.
Narration deleted (filename restatements, run-with lines, what-the-
next-line-does); every ref/hare cite, task cite, divergence, ABI/
layout contract, and ownership qualifier kept (borrowed-view lines
restored where the sweep over-cut). Comment-only proven: all 442
walk-workdir .s and 32 import-probe .s byte-identical before/after;
libbyteid 56-roster all-ID.
2026-08-08 21:10:18 +09:00

97 lines
2.5 KiB
Plaintext

// Mirrors Hare's hash::siphash for the one-shot path: take a 16-byte
// key and a buffer, return the 64-bit hash. Hare ships a streaming
// io::stream-backed type; ww's subset doesn't, matching the rest of
// lib/hash/*. The (c, d) parameter pair is exposed as `sum`; `sum24`
// fixes c=2, d=4 (the recommendation in the SipHash paper).
//
// Constants and round structure follow Aumasson & Bernstein, "SipHash:
// a fast short-input PRF" (CHES 2012).
package siphash;
import endian;
fn rotl64(x: u64, n: u64) u64 = {
return (x << n) | (x >> (64u64 - n));
};
fn round(v: *[4]u64) void = {
let v0: u64 = v[0];
let v1: u64 = v[1];
let v2: u64 = v[2];
let v3: u64 = v[3];
v0 = v0 + v1;
v1 = rotl64(v1, 13u64);
v1 = v1 ^ v0;
v0 = rotl64(v0, 32u64);
v2 = v2 + v3;
v3 = rotl64(v3, 16u64);
v3 = v3 ^ v2;
v0 = v0 + v3;
v3 = rotl64(v3, 21u64);
v3 = v3 ^ v0;
v2 = v2 + v1;
v1 = rotl64(v1, 17u64);
v1 = v1 ^ v2;
v2 = rotl64(v2, 32u64);
v[0] = v0;
v[1] = v1;
v[2] = v2;
v[3] = v3;
};
// sum — compute SipHash-c-d of `buf` under `key`. `key` must be a
// 16-byte slice. (c, d) are the compression and finalization round
// counts. Mirrors Hare's siphash::sum (one-shot form).
export fn sum(key: []u8, buf: []u8, c: i32, d: i32) u64 = {
let k0: u64 = endian.legetu64(key[0:8]);
let k1: u64 = endian.legetu64(key[8:16]);
let v: [4]u64;
v[0] = 0x736F6D6570736575u64 ^ k0;
v[1] = 0x646F72616E646F6Du64 ^ k1;
v[2] = 0x6C7967656E657261u64 ^ k0;
v[3] = 0x7465646279746573u64 ^ k1;
let i: i32 = 0;
let n: i32 = buf.len;
let last: i32 = n - (n & 7); // last whole-block boundary
for (i < last) {
let m: u64 = endian.legetu64(buf[i:i + 8]);
v[3] = v[3] ^ m;
let r: i32 = 0;
for (r < c) { round(&v); r += 1; };
v[0] = v[0] ^ m;
i += 8;
};
// Pack the trailing 0..7 bytes plus length-byte into the final
// 8-byte word.
let tail: u64 = 0u64;
let shift: u64 = 0u64;
let k: i32 = i;
for (k < n) {
let b: u64 = (buf[k]: u64) & 0xFFu64;
tail = tail | (b << shift);
shift = shift + 8u64;
k += 1;
};
let lenbyte: u64 = (n: u64) & 0xFFu64;
tail = tail | (lenbyte << 56u64);
v[3] = v[3] ^ tail;
let r2: i32 = 0;
for (r2 < c) { round(&v); r2 += 1; };
v[0] = v[0] ^ tail;
v[2] = v[2] ^ 0xFFu64;
let r3: i32 = 0;
for (r3 < d) { round(&v); r3 += 1; };
return v[0] ^ v[1] ^ v[2] ^ v[3];
};
// sum24 — SipHash-2-4 of `buf` under `key`. The standard recommended
// variant. Equivalent to sum(key, buf, 2, 4).
export fn sum24(key: []u8, buf: []u8) u64 = {
return sum(key, buf, 2, 4);
};