Source tree reorganization: - Move StarForth v3 engine to v3/ (src/, include/, Makefile) - Move kernel to kernel/ (src/, include/, linker/, Makefile) - Create v4/ skeleton for F18-ISA golden model (DECOMPOSITION.md, JUSTIFICATION.md) - Move FABRIC-0..4.md to docs/fabric/ - Move ONTOLOGY.md and ROADMAP.md to docs/ Board infrastructure: - Add boards/ser5/, boards/raspi/, boards/milkv/, boards/zynq7020/ - Each board has board.mk (ISA, CPU flags, boot recipe) and README.md - Root Makefile becomes thin dispatcher: boot_image, all, clean, docs take TARGET - make boot_image TARGET=SER5|RASPI|MILKV builds one GPT/MBR image per board - ZYNQ7020 target exists but stops with clear error (ARMv7 port not built yet) - scripts/mkdiskimage.sh builds disk images for all boards Docs pipeline: - docs/book/ with LaTeX master (main.tex) and Makefile - pandoc converts Markdown to LaTeX at build time - Two Lua filters: table-widths.lua (wide tables wrap), code-breaks.lua (inline code breaks) - make docs builds single PDF (754 pages, 0 missing characters) - make docs TARGET=<board> adds board appendix - build/docs/<book|board>/meta.tex stamps git commit into PDF Bug fixes: - 42 include paths that only worked by accident now use correct relative paths - clang-18 hardcode replaced with configurable CC variable (fixed aarch64 build) - Pi 5: kernel_2712.img linked at 0x80000, .bss zeroed, memory reserved - Doxyfile, .clang-tidy, README.md, Kconfig paths updated Verified: - Hosted v3 build passes 1012 tests, 0 failures - SER5 image boots in QEMU (OVMF), POST passes, K exact (65536 = Q48_ONE) - Milk-V image boots in QEMU (OpenSBI + U-Boot + bootefi), POST passes - make clean TARGET=<board> removes only that board and its ISA objects - make all builds all boards, hosted v3, and docs in one run Co-authored-by: Junie <junie@jetbrains.com>
38 lines
1.7 KiB
C
38 lines
1.7 KiB
C
/* scalar25519.h -- arithmetic mod L (the Ed25519 base point's order),
|
|
* for reducing SHA-512 output to a valid scalar and checking a
|
|
* signature's S component for the RFC 8032 malleability requirement
|
|
* (S < L, not just S < 2^256).
|
|
*
|
|
* Deliberately NOT the intricate hand-tuned "sc_reduce" reduction most
|
|
* reference implementations use (a bespoke Barrett-style reduction with
|
|
* constants specific to L, notoriously easy to transcribe wrong) --
|
|
* this is a plain binary long-division reduction, one bit at a time.
|
|
* O(512) steps per reduction; this is a verify-only, non-hot-path
|
|
* library (one reduction per signature check), so the simpler,
|
|
* more obviously-correct approach is the right tradeoff here.
|
|
*/
|
|
#ifndef SCALAR25519_H
|
|
#define SCALAR25519_H
|
|
|
|
#include <stdint.h>
|
|
|
|
/* 32-byte little-endian scalars, reduced mod L where noted. */
|
|
|
|
/* Reduce a 64-byte little-endian value (e.g. raw SHA-512 output) mod L,
|
|
* producing a 32-byte little-endian result < L. */
|
|
void scalar_reduce512(uint8_t out[32], const uint8_t in[64]);
|
|
|
|
/* 1 if the 32-byte little-endian scalar is < L (a well-formed,
|
|
* non-malleable signature component per RFC 8032), else 0. */
|
|
int scalar_lt_L(const uint8_t s[32]);
|
|
|
|
/* out = (a*b + c) mod L, all 32-byte little-endian scalars (a, b, c need
|
|
* not already be reduced mod L, though every caller in this codebase
|
|
* passes already-reduced inputs). Needed for EdDSA signing's
|
|
* S = (k*a + r) mod L step -- verify never needed scalar multiplication,
|
|
* only reduction, so this didn't exist until signing did. */
|
|
void scalar_muladd(uint8_t out[32], const uint8_t a[32], const uint8_t b[32],
|
|
const uint8_t c[32]);
|
|
|
|
#endif /* SCALAR25519_H */
|