| 1 | module edwards25519 |
| 2 | |
| 3 | import encoding.hex |
| 4 | |
| 5 | const zero_point = Point{fe_zero, fe_zero, fe_zero, fe_zero} |
| 6 | |
| 7 | fn test_invalid_encodings() { |
| 8 | // An invalid point, that also happens to have y > p. |
| 9 | invalid := 'efffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f' |
| 10 | inv_bytes := hex.decode(invalid) or { []u8{} } |
| 11 | mut p := new_generator_point() |
| 12 | |
| 13 | out := p.set_bytes(inv_bytes) or { zero_point } |
| 14 | assert out == zero_point |
| 15 | // assert p.equal(bgp) == 1 //not makes sense when error |
| 16 | |
| 17 | assert check_on_curve(p) == true |
| 18 | } |
| 19 | |
| 20 | fn test_add_sub_neg_on_basepoint() { |
| 21 | bgp := new_generator_point() |
| 22 | mut idp := new_identity_point() |
| 23 | mut checklhs := Point{} |
| 24 | mut checkrhs := Point{} |
| 25 | |
| 26 | checklhs.add(bgp, bgp) |
| 27 | |
| 28 | mut proj_p1 := ProjectiveP1{} |
| 29 | mut proj_p2 := ProjectiveP2{} |
| 30 | |
| 31 | tmp_p2 := proj_p2.from_p3(bgp) |
| 32 | tmp_p1 := proj_p1.double(tmp_p2) |
| 33 | checkrhs.from_p1(tmp_p1) |
| 34 | |
| 35 | assert checklhs.equal(checkrhs) == 1 |
| 36 | assert check_on_curve(checklhs, checkrhs) == true |
| 37 | |
| 38 | checklhs.subtract(bgp, bgp) |
| 39 | mut p0 := Point{} |
| 40 | bneg := p0.negate(bgp) |
| 41 | checkrhs.add(bgp, bneg) |
| 42 | |
| 43 | assert checklhs.equal(checkrhs) == 1 |
| 44 | assert idp.equal(checklhs) == 1 |
| 45 | assert idp.equal(checkrhs) == 1 |
| 46 | assert check_on_curve(checklhs, checkrhs, bneg) == true |
| 47 | } |
| 48 | |
| 49 | struct NonCanonicalTest { |
| 50 | name string |
| 51 | encoding string |
| 52 | canonical string |
| 53 | } |
| 54 | |
| 55 | fn test_non_canonical_points() { |
| 56 | tests := [ |
| 57 | // Points with x = 0 and the sign bit set. With x = 0 the curve equation |
| 58 | // gives y² = 1, so y = ±1. 1 has two valid encodings. |
| 59 | NonCanonicalTest{'y=1,sign-', '0100000000000000000000000000000000000000000000000000000000000080', '0100000000000000000000000000000000000000000000000000000000000000'}, |
| 60 | NonCanonicalTest{'y=p+1,sign-', 'eeffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '0100000000000000000000000000000000000000000000000000000000000000'}, |
| 61 | NonCanonicalTest{'y=p-1,sign-', 'ecffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', 'ecffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f'}, |
| 62 | // Non-canonical y encodings with values 2²⁵⁵-19 (p) to 2²⁵⁵-1 (p+18). |
| 63 | NonCanonicalTest{'y=p,sign+', 'edffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '0000000000000000000000000000000000000000000000000000000000000000'}, |
| 64 | NonCanonicalTest{'y=p,sign-', 'edffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '0000000000000000000000000000000000000000000000000000000000000080'}, |
| 65 | NonCanonicalTest{'y=p+1,sign+', 'eeffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '0100000000000000000000000000000000000000000000000000000000000000'}, |
| 66 | // "y=p+1,sign-" is already tested above. |
| 67 | // p+2 is not a valid y-coordinate. |
| 68 | NonCanonicalTest{'y=p+3,sign+', 'f0ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '0300000000000000000000000000000000000000000000000000000000000000'}, |
| 69 | NonCanonicalTest{'y=p+3,sign-', 'f0ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '0300000000000000000000000000000000000000000000000000000000000080'}, |
| 70 | NonCanonicalTest{'y=p+4,sign+', 'f1ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '0400000000000000000000000000000000000000000000000000000000000000'}, |
| 71 | NonCanonicalTest{'y=p+4,sign-', 'f1ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '0400000000000000000000000000000000000000000000000000000000000080'}, |
| 72 | NonCanonicalTest{'y=p+5,sign+', 'f2ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '0500000000000000000000000000000000000000000000000000000000000000'}, |
| 73 | NonCanonicalTest{'y=p+5,sign-', 'f2ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '0500000000000000000000000000000000000000000000000000000000000080'}, |
| 74 | NonCanonicalTest{'y=p+6,sign+', 'f3ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '0600000000000000000000000000000000000000000000000000000000000000'}, |
| 75 | NonCanonicalTest{'y=p+6,sign-', 'f3ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '0600000000000000000000000000000000000000000000000000000000000080'}, |
| 76 | // p+7 is not a valid y-coordinate. |
| 77 | // p+8 is not a valid y-coordinate. |
| 78 | NonCanonicalTest{'y=p+9,sign+', 'f6ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '0900000000000000000000000000000000000000000000000000000000000000'}, |
| 79 | NonCanonicalTest{'y=p+9,sign-', 'f6ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '0900000000000000000000000000000000000000000000000000000000000080'}, |
| 80 | NonCanonicalTest{'y=p+10,sign+', 'f7ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '0a00000000000000000000000000000000000000000000000000000000000000'}, |
| 81 | NonCanonicalTest{'y=p+10,sign-', 'f7ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '0a00000000000000000000000000000000000000000000000000000000000080'}, |
| 82 | // p+11 is not a valid y-coordinate. |
| 83 | // p+12 is not a valid y-coordinate. |
| 84 | // p+13 is not a valid y-coordinate. |
| 85 | NonCanonicalTest{'y=p+14,sign+', 'fbffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '0e00000000000000000000000000000000000000000000000000000000000000'}, |
| 86 | NonCanonicalTest{'y=p+14,sign-', 'fbffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '0e00000000000000000000000000000000000000000000000000000000000080'}, |
| 87 | NonCanonicalTest{'y=p+15,sign+', 'fcffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '0f00000000000000000000000000000000000000000000000000000000000000'}, |
| 88 | NonCanonicalTest{'y=p+15,sign-', 'fcffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '0f00000000000000000000000000000000000000000000000000000000000080'}, |
| 89 | NonCanonicalTest{'y=p+16,sign+', 'fdffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '1000000000000000000000000000000000000000000000000000000000000000'}, |
| 90 | NonCanonicalTest{'y=p+16,sign-', 'fdffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '1000000000000000000000000000000000000000000000000000000000000080'}, |
| 91 | // p+17 is not a valid y-coordinate. |
| 92 | NonCanonicalTest{'y=p+18,sign+', 'ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff7f', '1200000000000000000000000000000000000000000000000000000000000000'}, |
| 93 | NonCanonicalTest{'y=p+18,sign-', 'ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff', '1200000000000000000000000000000000000000000000000000000000000080'}, |
| 94 | ] |
| 95 | for tt in tests { |
| 96 | // t.Run(tt.name, func(t *testing.T) { |
| 97 | // p1, err := new(Point).SetBytes(decodeHex(tt.encoding)) |
| 98 | mut p1 := Point{} |
| 99 | p1.set_bytes(hex.decode(tt.encoding) or { []u8{} })! |
| 100 | |
| 101 | // p2, err := new(Point).SetBytes(decodeHex(tt.canonical)) |
| 102 | mut p2 := Point{} |
| 103 | p2.set_bytes(hex.decode(tt.canonical) or { []u8{} })! |
| 104 | |
| 105 | assert p1.equal(p2) == 1 |
| 106 | assert p1.bytes() == p2.bytes() |
| 107 | assert hex.encode(p1.bytes()) == tt.canonical // NEED FIX! |
| 108 | |
| 109 | assert check_on_curve(p1, p2) == true |
| 110 | } |
| 111 | } |
| 112 | |
| 113 | fn test_generator() { |
| 114 | // These are the coordinates of B from RFC 8032, Section 5.1, converted to |
| 115 | // little endian hex. |
| 116 | x := '1ad5258f602d56c9b2a7259560c72c695cdcd6fd31e2a4c0fe536ecdd3366921' |
| 117 | y := '5866666666666666666666666666666666666666666666666666666666666666' |
| 118 | mut b := new_generator_point() |
| 119 | |
| 120 | assert hex.encode(b.x.bytes()) == x |
| 121 | assert hex.encode(b.y.bytes()) == y |
| 122 | assert b.z.equal(fe_one) == 1 |
| 123 | // Check that t is correct. |
| 124 | assert check_on_curve(b) == true |
| 125 | } |
| 126 | |