falcon: satisfy test_boolean

This commit is contained in:
John M. Schanck 2020-09-15 13:32:02 -04:00 committed by Kris Kwiatkowski
parent a8c4ac414b
commit 82ae2d3e34
8 changed files with 74 additions and 32 deletions

View File

@ -443,7 +443,8 @@ PQCLEAN_FALCON1024_CLEAN_comp_decode(
return 0; return 0;
} }
} }
x[u] = (int16_t)(s ? -(int)m : (int)m); x[u] = (int16_t) m;
if (s) x[u] = -x[u];
} }
return v; return v;
} }

View File

@ -436,8 +436,8 @@ fpr_lt(fpr x, fpr y) {
*/ */
int cc0, cc1; int cc0, cc1;
cc0 = *(int64_t *)&x < *(int64_t *)&y; cc0 = ((*(int64_t *)&x - *(int64_t *)&y) >> 63) & 1;
cc1 = *(int64_t *)&x > *(int64_t *)&y; cc1 = ((*(int64_t *)&y - *(int64_t *)&x) >> 63) & 1;
return cc0 ^ ((cc0 ^ cc1) & (int)((x & y) >> 63)); return cc0 ^ ((cc0 ^ cc1) & (int)((x & y) >> 63));
} }

View File

@ -1902,7 +1902,11 @@ zint_add_scaled_mul_small(uint32_t *x, size_t xlen,
* Get the next word of y (scaled). * Get the next word of y (scaled).
*/ */
v = u - sch; v = u - sch;
wy = v < ylen ? y[v] : ysign; if (v < ylen) {
wy = y[v];
} else {
wy = ysign;
}
wys = ((wy << scl) & 0x7FFFFFFF) | tw; wys = ((wy << scl) & 0x7FFFFFFF) | tw;
tw = wy >> (31 - scl); tw = wy >> (31 - scl);
@ -1960,7 +1964,11 @@ zint_sub_scaled(uint32_t *x, size_t xlen,
* Get the next word of y (scaled). * Get the next word of y (scaled).
*/ */
v = u - sch; v = u - sch;
wy = v < ylen ? y[v] : ysign; if (v < ylen) {
wy = y[v];
} else {
wy = ysign;
}
wys = ((wy << scl) & 0x7FFFFFFF) | tw; wys = ((wy << scl) & 0x7FFFFFFF) | tw;
tw = wy >> (31 - scl); tw = wy >> (31 - scl);
@ -2648,10 +2656,16 @@ make_fg(uint32_t *data, const int8_t *f, const int8_t *g,
return; return;
} }
for (d = 0; d < depth; d ++) { if (depth == 0) return;
make_fg_step(data, logn - d, d, if (depth == 1) {
d != 0, (d + 1) < depth || out_ntt); make_fg_step(data, logn, 0, 0, out_ntt);
return;
} }
make_fg_step(data, logn, 0, 0, 1);
for (d = 1; d+1 < depth; d ++) {
make_fg_step(data, logn - d, d, 1, 1);
}
make_fg_step(data, logn-depth+1, depth-1, 1, out_ntt);
} }
/* /*
@ -3028,7 +3042,8 @@ solve_NTRU_intermediate(unsigned logn_top,
* computed so that average maximum length will fall in the * computed so that average maximum length will fall in the
* middle or the upper half of these top 10 words. * middle or the upper half of these top 10 words.
*/ */
rlen = (slen > 10) ? 10 : slen; rlen = slen;
if (rlen > 10) rlen = 10;
poly_big_to_fp(rt3, ft + slen - rlen, rlen, slen, logn); poly_big_to_fp(rt3, ft + slen - rlen, rlen, slen, logn);
poly_big_to_fp(rt4, gt + slen - rlen, rlen, slen, logn); poly_big_to_fp(rt4, gt + slen - rlen, rlen, slen, logn);
@ -3102,7 +3117,8 @@ solve_NTRU_intermediate(unsigned logn_top,
* Convert current F and G into floating-point. We apply * Convert current F and G into floating-point. We apply
* scaling if the current length is more than 10 words. * scaling if the current length is more than 10 words.
*/ */
rlen = (FGlen > 10) ? 10 : FGlen; rlen = FGlen;
if (rlen > 10) rlen = 10;
scale_FG = 31 * (int)(FGlen - rlen); scale_FG = 31 * (int)(FGlen - rlen);
poly_big_to_fp(rt1, Ft + FGlen - rlen, rlen, llen, logn); poly_big_to_fp(rt1, Ft + FGlen - rlen, rlen, llen, logn);
poly_big_to_fp(rt2, Gt + FGlen - rlen, rlen, llen, logn); poly_big_to_fp(rt2, Gt + FGlen - rlen, rlen, llen, logn);

View File

@ -1189,9 +1189,11 @@ PQCLEAN_FALCON1024_CLEAN_sign_tree(int16_t *sig, inner_shake256_context *rng,
* Normal sampling. We use a fast PRNG seeded from our * Normal sampling. We use a fast PRNG seeded from our
* SHAKE context ('rng'). * SHAKE context ('rng').
*/ */
spc.sigma_min = (logn == 10) if (logn == 10) {
? fpr_sigma_min_10 spc.sigma_min = fpr_sigma_min_10;
: fpr_sigma_min_9; } else {
spc.sigma_min = fpr_sigma_min_9;
}
PQCLEAN_FALCON1024_CLEAN_prng_init(&spc.p, rng); PQCLEAN_FALCON1024_CLEAN_prng_init(&spc.p, rng);
samp = PQCLEAN_FALCON1024_CLEAN_sampler; samp = PQCLEAN_FALCON1024_CLEAN_sampler;
samp_ctx = &spc; samp_ctx = &spc;
@ -1234,9 +1236,11 @@ PQCLEAN_FALCON1024_CLEAN_sign_dyn(int16_t *sig, inner_shake256_context *rng,
* Normal sampling. We use a fast PRNG seeded from our * Normal sampling. We use a fast PRNG seeded from our
* SHAKE context ('rng'). * SHAKE context ('rng').
*/ */
spc.sigma_min = (logn == 10) if (logn == 10) {
? fpr_sigma_min_10 spc.sigma_min = fpr_sigma_min_10;
: fpr_sigma_min_9; } else {
spc.sigma_min = fpr_sigma_min_9;
}
PQCLEAN_FALCON1024_CLEAN_prng_init(&spc.p, rng); PQCLEAN_FALCON1024_CLEAN_prng_init(&spc.p, rng);
samp = PQCLEAN_FALCON1024_CLEAN_sampler; samp = PQCLEAN_FALCON1024_CLEAN_sampler;
samp_ctx = &spc; samp_ctx = &spc;

View File

@ -443,7 +443,8 @@ PQCLEAN_FALCON512_CLEAN_comp_decode(
return 0; return 0;
} }
} }
x[u] = (int16_t)(s ? -(int)m : (int)m); x[u] = (int16_t) m;
if (s) x[u] = -x[u];
} }
return v; return v;
} }

View File

@ -436,8 +436,8 @@ fpr_lt(fpr x, fpr y) {
*/ */
int cc0, cc1; int cc0, cc1;
cc0 = *(int64_t *)&x < *(int64_t *)&y; cc0 = ((*(int64_t *)&x - *(int64_t *)&y) >> 63) & 1;
cc1 = *(int64_t *)&x > *(int64_t *)&y; cc1 = ((*(int64_t *)&y - *(int64_t *)&x) >> 63) & 1;
return cc0 ^ ((cc0 ^ cc1) & (int)((x & y) >> 63)); return cc0 ^ ((cc0 ^ cc1) & (int)((x & y) >> 63));
} }

View File

@ -1902,7 +1902,11 @@ zint_add_scaled_mul_small(uint32_t *x, size_t xlen,
* Get the next word of y (scaled). * Get the next word of y (scaled).
*/ */
v = u - sch; v = u - sch;
wy = v < ylen ? y[v] : ysign; if (v < ylen) {
wy = y[v];
} else {
wy = ysign;
}
wys = ((wy << scl) & 0x7FFFFFFF) | tw; wys = ((wy << scl) & 0x7FFFFFFF) | tw;
tw = wy >> (31 - scl); tw = wy >> (31 - scl);
@ -1960,7 +1964,11 @@ zint_sub_scaled(uint32_t *x, size_t xlen,
* Get the next word of y (scaled). * Get the next word of y (scaled).
*/ */
v = u - sch; v = u - sch;
wy = v < ylen ? y[v] : ysign; if (v < ylen) {
wy = y[v];
} else {
wy = ysign;
}
wys = ((wy << scl) & 0x7FFFFFFF) | tw; wys = ((wy << scl) & 0x7FFFFFFF) | tw;
tw = wy >> (31 - scl); tw = wy >> (31 - scl);
@ -2648,10 +2656,16 @@ make_fg(uint32_t *data, const int8_t *f, const int8_t *g,
return; return;
} }
for (d = 0; d < depth; d ++) { if (depth == 0) return;
make_fg_step(data, logn - d, d, if (depth == 1) {
d != 0, (d + 1) < depth || out_ntt); make_fg_step(data, logn, 0, 0, out_ntt);
return;
} }
make_fg_step(data, logn, 0, 0, 1);
for (d = 1; d+1 < depth; d ++) {
make_fg_step(data, logn - d, d, 1, 1);
}
make_fg_step(data, logn-depth+1, depth-1, 1, out_ntt);
} }
/* /*
@ -3028,7 +3042,8 @@ solve_NTRU_intermediate(unsigned logn_top,
* computed so that average maximum length will fall in the * computed so that average maximum length will fall in the
* middle or the upper half of these top 10 words. * middle or the upper half of these top 10 words.
*/ */
rlen = (slen > 10) ? 10 : slen; rlen = slen;
if (rlen > 10) rlen = 10;
poly_big_to_fp(rt3, ft + slen - rlen, rlen, slen, logn); poly_big_to_fp(rt3, ft + slen - rlen, rlen, slen, logn);
poly_big_to_fp(rt4, gt + slen - rlen, rlen, slen, logn); poly_big_to_fp(rt4, gt + slen - rlen, rlen, slen, logn);
@ -3102,7 +3117,8 @@ solve_NTRU_intermediate(unsigned logn_top,
* Convert current F and G into floating-point. We apply * Convert current F and G into floating-point. We apply
* scaling if the current length is more than 10 words. * scaling if the current length is more than 10 words.
*/ */
rlen = (FGlen > 10) ? 10 : FGlen; rlen = FGlen;
if (rlen > 10) rlen = 10;
scale_FG = 31 * (int)(FGlen - rlen); scale_FG = 31 * (int)(FGlen - rlen);
poly_big_to_fp(rt1, Ft + FGlen - rlen, rlen, llen, logn); poly_big_to_fp(rt1, Ft + FGlen - rlen, rlen, llen, logn);
poly_big_to_fp(rt2, Gt + FGlen - rlen, rlen, llen, logn); poly_big_to_fp(rt2, Gt + FGlen - rlen, rlen, llen, logn);

View File

@ -1189,9 +1189,11 @@ PQCLEAN_FALCON512_CLEAN_sign_tree(int16_t *sig, inner_shake256_context *rng,
* Normal sampling. We use a fast PRNG seeded from our * Normal sampling. We use a fast PRNG seeded from our
* SHAKE context ('rng'). * SHAKE context ('rng').
*/ */
spc.sigma_min = (logn == 10) if (logn == 10) {
? fpr_sigma_min_10 spc.sigma_min = fpr_sigma_min_10;
: fpr_sigma_min_9; } else {
spc.sigma_min = fpr_sigma_min_9;
}
PQCLEAN_FALCON512_CLEAN_prng_init(&spc.p, rng); PQCLEAN_FALCON512_CLEAN_prng_init(&spc.p, rng);
samp = PQCLEAN_FALCON512_CLEAN_sampler; samp = PQCLEAN_FALCON512_CLEAN_sampler;
samp_ctx = &spc; samp_ctx = &spc;
@ -1234,9 +1236,11 @@ PQCLEAN_FALCON512_CLEAN_sign_dyn(int16_t *sig, inner_shake256_context *rng,
* Normal sampling. We use a fast PRNG seeded from our * Normal sampling. We use a fast PRNG seeded from our
* SHAKE context ('rng'). * SHAKE context ('rng').
*/ */
spc.sigma_min = (logn == 10) if (logn == 10) {
? fpr_sigma_min_10 spc.sigma_min = fpr_sigma_min_10;
: fpr_sigma_min_9; } else {
spc.sigma_min = fpr_sigma_min_9;
}
PQCLEAN_FALCON512_CLEAN_prng_init(&spc.p, rng); PQCLEAN_FALCON512_CLEAN_prng_init(&spc.p, rng);
samp = PQCLEAN_FALCON512_CLEAN_sampler; samp = PQCLEAN_FALCON512_CLEAN_sampler;
samp_ctx = &spc; samp_ctx = &spc;