PageRenderTime 60ms CodeModel.GetById 21ms RepoModel.GetById 0ms app.codeStats 0ms

/ext/hash/hash_haval.c

https://github.com/php/php-src
C | 533 lines | 340 code | 99 blank | 94 comment | 25 complexity | dfceefa94351cfd10593741ae30ace3f MD5 | raw file
Possible License(s): BSD-2-Clause, BSD-3-Clause, MPL-2.0-no-copyleft-exception, LGPL-2.1
  1. /*
  2. +----------------------------------------------------------------------+
  3. | Copyright (c) The PHP Group |
  4. +----------------------------------------------------------------------+
  5. | This source file is subject to version 3.01 of the PHP license, |
  6. | that is bundled with this package in the file LICENSE, and is |
  7. | available through the world-wide-web at the following url: |
  8. | https://www.php.net/license/3_01.txt |
  9. | If you did not receive a copy of the PHP license and are unable to |
  10. | obtain it through the world-wide-web, please send a note to |
  11. | license@php.net so we can mail you a copy immediately. |
  12. +----------------------------------------------------------------------+
  13. | Author: Sara Golemon <pollita@php.net> |
  14. +----------------------------------------------------------------------+
  15. */
  16. #include "php_hash.h"
  17. #include "php_hash_haval.h"
  18. static const unsigned char PADDING[128] ={
  19. 1, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  20. 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  21. 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  22. 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  23. 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  24. 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  25. 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  26. 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 };
  27. static const uint32_t D0[8] = {
  28. 0x243F6A88, 0x85A308D3, 0x13198A2E, 0x03707344, 0xA4093822, 0x299F31D0, 0x082EFA98, 0xEC4E6C89 };
  29. static const uint32_t K2[32] = {
  30. 0x452821E6, 0x38D01377, 0xBE5466CF, 0x34E90C6C, 0xC0AC29B7, 0xC97C50DD, 0x3F84D5B5, 0xB5470917,
  31. 0x9216D5D9, 0x8979FB1B, 0xD1310BA6, 0x98DFB5AC, 0x2FFD72DB, 0xD01ADFB7, 0xB8E1AFED, 0x6A267E96,
  32. 0xBA7C9045, 0xF12C7F99, 0x24A19947, 0xB3916CF7, 0x0801F2E2, 0x858EFC16, 0x636920D8, 0x71574E69,
  33. 0xA458FEA3, 0xF4933D7E, 0x0D95748F, 0x728EB658, 0x718BCD58, 0x82154AEE, 0x7B54A41D, 0xC25A59B5 };
  34. static const uint32_t K3[32] = {
  35. 0x9C30D539, 0x2AF26013, 0xC5D1B023, 0x286085F0, 0xCA417918, 0xB8DB38EF, 0x8E79DCB0, 0x603A180E,
  36. 0x6C9E0E8B, 0xB01E8A3E, 0xD71577C1, 0xBD314B27, 0x78AF2FDA, 0x55605C60, 0xE65525F3, 0xAA55AB94,
  37. 0x57489862, 0x63E81440, 0x55CA396A, 0x2AAB10B6, 0xB4CC5C34, 0x1141E8CE, 0xA15486AF, 0x7C72E993,
  38. 0xB3EE1411, 0x636FBC2A, 0x2BA9C55D, 0x741831F6, 0xCE5C3E16, 0x9B87931E, 0xAFD6BA33, 0x6C24CF5C };
  39. static const uint32_t K4[32] = {
  40. 0x7A325381, 0x28958677, 0x3B8F4898, 0x6B4BB9AF, 0xC4BFE81B, 0x66282193, 0x61D809CC, 0xFB21A991,
  41. 0x487CAC60, 0x5DEC8032, 0xEF845D5D, 0xE98575B1, 0xDC262302, 0xEB651B88, 0x23893E81, 0xD396ACC5,
  42. 0x0F6D6FF3, 0x83F44239, 0x2E0B4482, 0xA4842004, 0x69C8F04A, 0x9E1F9B5E, 0x21C66842, 0xF6E96C9A,
  43. 0x670C9C61, 0xABD388F0, 0x6A51A0D2, 0xD8542F68, 0x960FA728, 0xAB5133A3, 0x6EEF0B6C, 0x137A3BE4 };
  44. static const uint32_t K5[32] = {
  45. 0xBA3BF050, 0x7EFB2A98, 0xA1F1651D, 0x39AF0176, 0x66CA593E, 0x82430E88, 0x8CEE8619, 0x456F9FB4,
  46. 0x7D84A5C3, 0x3B8B5EBE, 0xE06F75D8, 0x85C12073, 0x401A449F, 0x56C16AA6, 0x4ED3AA62, 0x363F7706,
  47. 0x1BFEDF72, 0x429B023D, 0x37D0D724, 0xD00A1248, 0xDB0FEAD3, 0x49F1C09B, 0x075372C9, 0x80991B7B,
  48. 0x25D479D8, 0xF6E8DEF7, 0xE3FE501A, 0xB6794C3B, 0x976CE0BD, 0x04C006BA, 0xC1A94FB6, 0x409F60C4 };
  49. static const short I2[32] = { 5, 14, 26, 18, 11, 28, 7, 16, 0, 23, 20, 22, 1, 10, 4, 8,
  50. 30, 3, 21, 9, 17, 24, 29, 6, 19, 12, 15, 13, 2, 25, 31, 27 };
  51. static const short I3[32] = { 19, 9, 4, 20, 28, 17, 8, 22, 29, 14, 25, 12, 24, 30, 16, 26,
  52. 31, 15, 7, 3, 1, 0, 18, 27, 13, 6, 21, 10, 23, 11, 5, 2 };
  53. static const short I4[32] = { 24, 4, 0, 14, 2, 7, 28, 23, 26, 6, 30, 20, 18, 25, 19, 3,
  54. 22, 11, 31, 21, 8, 27, 12, 9, 1, 29, 5, 15, 17, 10, 16, 13 };
  55. static const short I5[32] = { 27, 3, 21, 26, 17, 11, 20, 29, 19, 0, 12, 7, 13, 8, 31, 10,
  56. 5, 9, 14, 30, 18, 6, 28, 24, 2, 23, 16, 22, 4, 1, 25, 15 };
  57. static const short M0[32] = { 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1,
  58. 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1 };
  59. static const short M1[32] = { 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2,
  60. 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2 };
  61. static const short M2[32] = { 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3,
  62. 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3 };
  63. static const short M3[32] = { 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4,
  64. 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4 };
  65. static const short M4[32] = { 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5,
  66. 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5 };
  67. static const short M5[32] = { 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6,
  68. 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7, 6 };
  69. static const short M6[32] = { 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7,
  70. 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0, 7 };
  71. static const short M7[32] = { 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0,
  72. 7, 6, 5, 4, 3, 2, 1, 0, 7, 6, 5, 4, 3, 2, 1, 0 };
  73. /* {{{ Encode
  74. Encodes input (uint32_t) into output (unsigned char). Assumes len is
  75. a multiple of 4.
  76. */
  77. static void Encode(unsigned char *output, uint32_t *input, unsigned int len)
  78. {
  79. unsigned int i, j;
  80. for (i = 0, j = 0; j < len; i++, j += 4) {
  81. output[j] = (unsigned char) (input[i] & 0xff);
  82. output[j + 1] = (unsigned char) ((input[i] >> 8) & 0xff);
  83. output[j + 2] = (unsigned char) ((input[i] >> 16) & 0xff);
  84. output[j + 3] = (unsigned char) ((input[i] >> 24) & 0xff);
  85. }
  86. }
  87. /* }}} */
  88. /* {{{ Decode
  89. Decodes input (unsigned char) into output (uint32_t). Assumes len is
  90. a multiple of 4.
  91. */
  92. static void Decode(uint32_t *output, const unsigned char *input, unsigned int len)
  93. {
  94. unsigned int i, j;
  95. for (i = 0, j = 0; j < len; i++, j += 4) {
  96. output[i] = ((uint32_t) input[j]) | (((uint32_t) input[j + 1]) << 8) |
  97. (((uint32_t) input[j + 2]) << 16) | (((uint32_t) input[j + 3]) << 24);
  98. }
  99. }
  100. /* }}} */
  101. #define F1(x6,x5,x4,x3,x2,x1,x0) ( ((x1) & (x4)) ^ ((x2) & (x5)) ^ ((x3) & (x6)) ^ ((x0) & (x1)) ^ (x0) )
  102. #define F2(x6,x5,x4,x3,x2,x1,x0) ( ((x1) & (x2) & (x3)) ^ ((x2) & (x4) & (x5)) ^ ((x1) & (x2)) ^ ((x1) & (x4)) ^ \
  103. ((x2) & (x6)) ^ ((x3) & (x5)) ^ ((x4) & (x5)) ^ ((x0) & (x2)) ^ (x0) )
  104. #define F3(x6,x5,x4,x3,x2,x1,x0) ( ((x1) & (x2) & (x3)) ^ ((x1) & (x4)) ^ ((x2) & (x5)) ^ ((x3) & (x6)) ^ ((x0) & (x3)) ^ (x0) )
  105. #define F4(x6,x5,x4,x3,x2,x1,x0) ( ((x1) & (x2) & (x3)) ^ ((x2) & (x4) & (x5)) ^ ((x3) & (x4) & (x6)) ^ \
  106. ((x1) & (x4)) ^ ((x2) & (x6)) ^ ((x3) & (x4)) ^ ((x3) & (x5)) ^ \
  107. ((x3) & (x6)) ^ ((x4) & (x5)) ^ ((x4) & (x6)) ^ ((x0) & (x4)) ^ (x0) )
  108. #define F5(x6,x5,x4,x3,x2,x1,x0) ( ((x1) & (x4)) ^ ((x2) & (x5)) ^ ((x3) & (x6)) ^ \
  109. ((x0) & (x1) & (x2) & (x3)) ^ ((x0) & (x5)) ^ (x0) )
  110. #define ROTR(x,n) (((x) >> (n)) | ((x) << (32 - (n))))
  111. /* {{{ PHP_3HAVALTransform */
  112. static void PHP_3HAVALTransform(uint32_t state[8], const unsigned char block[128])
  113. {
  114. uint32_t E[8];
  115. uint32_t x[32];
  116. int i;
  117. Decode(x, block, 128);
  118. for(i = 0; i < 8; i++) {
  119. E[i] = state[i];
  120. }
  121. for(i = 0; i < 32; i++) {
  122. E[7 - (i % 8)] = ROTR(F1(E[M1[i]],E[M0[i]],E[M3[i]],E[M5[i]],E[M6[i]],E[M2[i]],E[M4[i]]),7) + ROTR(E[M7[i]],11) + x[i];
  123. }
  124. for(i = 0; i < 32; i++) {
  125. E[7 - (i % 8)] = ROTR(F2(E[M4[i]],E[M2[i]],E[M1[i]],E[M0[i]],E[M5[i]],E[M3[i]],E[M6[i]]),7) + ROTR(E[M7[i]],11) + x[I2[i]] + K2[i];
  126. }
  127. for(i = 0; i < 32; i++) {
  128. E[7 - (i % 8)] = ROTR(F3(E[M6[i]],E[M1[i]],E[M2[i]],E[M3[i]],E[M4[i]],E[M5[i]],E[M0[i]]),7) + ROTR(E[M7[i]],11) + x[I3[i]] + K3[i];
  129. }
  130. /* Update digest */
  131. for(i = 0; i < 8; i++) {
  132. state[i] += E[i];
  133. }
  134. /* Zeroize sensitive information. */
  135. ZEND_SECURE_ZERO((unsigned char*) x, sizeof(x));
  136. }
  137. /* }}} */
  138. /* {{{ PHP_4HAVALTransform */
  139. static void PHP_4HAVALTransform(uint32_t state[8], const unsigned char block[128])
  140. {
  141. uint32_t E[8];
  142. uint32_t x[32];
  143. int i;
  144. Decode(x, block, 128);
  145. for(i = 0; i < 8; i++) {
  146. E[i] = state[i];
  147. }
  148. for(i = 0; i < 32; i++) {
  149. E[7 - (i % 8)] = ROTR(F1(E[M2[i]],E[M6[i]],E[M1[i]],E[M4[i]],E[M5[i]],E[M3[i]],E[M0[i]]),7) + ROTR(E[M7[i]],11) + x[i];
  150. }
  151. for(i = 0; i < 32; i++) {
  152. E[7 - (i % 8)] = ROTR(F2(E[M3[i]],E[M5[i]],E[M2[i]],E[M0[i]],E[M1[i]],E[M6[i]],E[M4[i]]),7) + ROTR(E[M7[i]],11) + x[I2[i]] + K2[i];
  153. }
  154. for(i = 0; i < 32; i++) {
  155. E[7 - (i % 8)] = ROTR(F3(E[M1[i]],E[M4[i]],E[M3[i]],E[M6[i]],E[M0[i]],E[M2[i]],E[M5[i]]),7) + ROTR(E[M7[i]],11) + x[I3[i]] + K3[i];
  156. }
  157. for(i = 0; i < 32; i++) {
  158. E[7 - (i % 8)] = ROTR(F4(E[M6[i]],E[M4[i]],E[M0[i]],E[M5[i]],E[M2[i]],E[M1[i]],E[M3[i]]),7) + ROTR(E[M7[i]],11) + x[I4[i]] + K4[i];
  159. }
  160. /* Update digest */
  161. for(i = 0; i < 8; i++) {
  162. state[i] += E[i];
  163. }
  164. /* Zeroize sensitive information. */
  165. ZEND_SECURE_ZERO((unsigned char*) x, sizeof(x));
  166. }
  167. /* }}} */
  168. /* {{{ PHP_5HAVALTransform */
  169. static void PHP_5HAVALTransform(uint32_t state[8], const unsigned char block[128])
  170. {
  171. uint32_t E[8];
  172. uint32_t x[32];
  173. int i;
  174. Decode(x, block, 128);
  175. for(i = 0; i < 8; i++) {
  176. E[i] = state[i];
  177. }
  178. for(i = 0; i < 32; i++) {
  179. E[7 - (i % 8)] = ROTR(F1(E[M3[i]],E[M4[i]],E[M1[i]],E[M0[i]],E[M5[i]],E[M2[i]],E[M6[i]]),7) + ROTR(E[M7[i]],11) + x[i];
  180. }
  181. for(i = 0; i < 32; i++) {
  182. E[7 - (i % 8)] = ROTR(F2(E[M6[i]],E[M2[i]],E[M1[i]],E[M0[i]],E[M3[i]],E[M4[i]],E[M5[i]]),7) + ROTR(E[M7[i]],11) + x[I2[i]] + K2[i];
  183. }
  184. for(i = 0; i < 32; i++) {
  185. E[7 - (i % 8)] = ROTR(F3(E[M2[i]],E[M6[i]],E[M0[i]],E[M4[i]],E[M3[i]],E[M1[i]],E[M5[i]]),7) + ROTR(E[M7[i]],11) + x[I3[i]] + K3[i];
  186. }
  187. for(i = 0; i < 32; i++) {
  188. E[7 - (i % 8)] = ROTR(F4(E[M1[i]],E[M5[i]],E[M3[i]],E[M2[i]],E[M0[i]],E[M4[i]],E[M6[i]]),7) + ROTR(E[M7[i]],11) + x[I4[i]] + K4[i];
  189. }
  190. for(i = 0; i < 32; i++) {
  191. E[7 - (i % 8)] = ROTR(F5(E[M2[i]],E[M5[i]],E[M0[i]],E[M6[i]],E[M4[i]],E[M3[i]],E[M1[i]]),7) + ROTR(E[M7[i]],11) + x[I5[i]] + K5[i];
  192. }
  193. /* Update digest */
  194. for(i = 0; i < 8; i++) {
  195. state[i] += E[i];
  196. }
  197. /* Zeroize sensitive information. */
  198. ZEND_SECURE_ZERO((unsigned char*) x, sizeof(x));
  199. }
  200. /* }}} */
  201. #define PHP_HASH_HAVAL_INIT(p,b) \
  202. const php_hash_ops php_hash_##p##haval##b##_ops = { \
  203. "haval" #b "," #p, \
  204. (php_hash_init_func_t) PHP_##p##HAVAL##b##Init, \
  205. (php_hash_update_func_t) PHP_HAVALUpdate, \
  206. (php_hash_final_func_t) PHP_HAVAL##b##Final, \
  207. php_hash_copy, \
  208. php_hash_serialize, \
  209. php_hash_unserialize, \
  210. PHP_HAVAL_SPEC, \
  211. ((b) / 8), 128, sizeof(PHP_HAVAL_CTX), 1 }; \
  212. PHP_HASH_API void PHP_##p##HAVAL##b##Init(PHP_HAVAL_CTX *context, ZEND_ATTRIBUTE_UNUSED HashTable *args) \
  213. { int i; context->count[0] = context->count[1] = 0; \
  214. for(i = 0; i < 8; i++) context->state[i] = D0[i]; \
  215. context->passes = p; context->output = b; \
  216. context->Transform = PHP_##p##HAVALTransform; }
  217. PHP_HASH_HAVAL_INIT(3,128)
  218. PHP_HASH_HAVAL_INIT(3,160)
  219. PHP_HASH_HAVAL_INIT(3,192)
  220. PHP_HASH_HAVAL_INIT(3,224)
  221. PHP_HASH_HAVAL_INIT(3,256)
  222. PHP_HASH_HAVAL_INIT(4,128)
  223. PHP_HASH_HAVAL_INIT(4,160)
  224. PHP_HASH_HAVAL_INIT(4,192)
  225. PHP_HASH_HAVAL_INIT(4,224)
  226. PHP_HASH_HAVAL_INIT(4,256)
  227. PHP_HASH_HAVAL_INIT(5,128)
  228. PHP_HASH_HAVAL_INIT(5,160)
  229. PHP_HASH_HAVAL_INIT(5,192)
  230. PHP_HASH_HAVAL_INIT(5,224)
  231. PHP_HASH_HAVAL_INIT(5,256)
  232. /* {{{ PHP_HAVALUpdate */
  233. PHP_HASH_API void PHP_HAVALUpdate(PHP_HAVAL_CTX *context, const unsigned char *input, size_t inputLen)
  234. {
  235. unsigned int i, index, partLen;
  236. /* Compute number of bytes mod 128 */
  237. index = (unsigned int) ((context->count[0] >> 3) & 0x7F);
  238. /* Update number of bits */
  239. if ((context->count[0] += ((uint32_t) inputLen << 3)) < ((uint32_t) inputLen << 3)) {
  240. context->count[1]++;
  241. }
  242. context->count[1] += ((uint32_t) inputLen >> 29);
  243. partLen = 128 - index;
  244. /* Transform as many times as possible.
  245. */
  246. if (inputLen >= partLen) {
  247. memcpy((unsigned char*) & context->buffer[index], (unsigned char*) input, partLen);
  248. context->Transform(context->state, context->buffer);
  249. for (i = partLen; i + 127 < inputLen; i += 128) {
  250. context->Transform(context->state, &input[i]);
  251. }
  252. index = 0;
  253. } else {
  254. i = 0;
  255. }
  256. /* Buffer remaining input */
  257. memcpy((unsigned char*) &context->buffer[index], (unsigned char*) &input[i], inputLen - i);
  258. }
  259. /* }}} */
  260. #define PHP_HASH_HAVAL_VERSION 0x01
  261. /* {{{ PHP_HAVAL128Final */
  262. PHP_HASH_API void PHP_HAVAL128Final(unsigned char *digest, PHP_HAVAL_CTX * context)
  263. {
  264. unsigned char bits[10];
  265. unsigned int index, padLen;
  266. /* Version, Passes, and Digest Length */
  267. bits[0] = (PHP_HASH_HAVAL_VERSION & 0x07) |
  268. ((context->passes & 0x07) << 3) |
  269. ((context->output & 0x03) << 6);
  270. bits[1] = (context->output >> 2);
  271. /* Save number of bits */
  272. Encode(bits + 2, context->count, 8);
  273. /* Pad out to 118 mod 128.
  274. */
  275. index = (unsigned int) ((context->count[0] >> 3) & 0x7f);
  276. padLen = (index < 118) ? (118 - index) : (246 - index);
  277. PHP_HAVALUpdate(context, PADDING, padLen);
  278. /* Append version, passes, digest length, and message length */
  279. PHP_HAVALUpdate(context, bits, 10);
  280. /* Store state in digest */
  281. context->state[3] += (context->state[7] & 0xFF000000) |
  282. (context->state[6] & 0x00FF0000) |
  283. (context->state[5] & 0x0000FF00) |
  284. (context->state[4] & 0x000000FF);
  285. context->state[2] += (((context->state[7] & 0x00FF0000) |
  286. (context->state[6] & 0x0000FF00) |
  287. (context->state[5] & 0x000000FF)) << 8) |
  288. ((context->state[4] & 0xFF000000) >> 24);
  289. context->state[1] += (((context->state[7] & 0x0000FF00) |
  290. (context->state[6] & 0x000000FF)) << 16) |
  291. (((context->state[5] & 0xFF000000) |
  292. (context->state[4] & 0x00FF0000)) >> 16);
  293. context->state[0] += ((context->state[7] & 0x000000FF) << 24) |
  294. (((context->state[6] & 0xFF000000) |
  295. (context->state[5] & 0x00FF0000) |
  296. (context->state[4] & 0x0000FF00)) >> 8);
  297. Encode(digest, context->state, 16);
  298. /* Zeroize sensitive information.
  299. */
  300. ZEND_SECURE_ZERO((unsigned char*) context, sizeof(*context));
  301. }
  302. /* }}} */
  303. /* {{{ PHP_HAVAL160Final */
  304. PHP_HASH_API void PHP_HAVAL160Final(unsigned char *digest, PHP_HAVAL_CTX * context)
  305. {
  306. unsigned char bits[10];
  307. unsigned int index, padLen;
  308. /* Version, Passes, and Digest Length */
  309. bits[0] = (PHP_HASH_HAVAL_VERSION & 0x07) |
  310. ((context->passes & 0x07) << 3) |
  311. ((context->output & 0x03) << 6);
  312. bits[1] = (context->output >> 2);
  313. /* Save number of bits */
  314. Encode(bits + 2, context->count, 8);
  315. /* Pad out to 118 mod 128.
  316. */
  317. index = (unsigned int) ((context->count[0] >> 3) & 0x7f);
  318. padLen = (index < 118) ? (118 - index) : (246 - index);
  319. PHP_HAVALUpdate(context, PADDING, padLen);
  320. /* Append version, passes, digest length, and message length */
  321. PHP_HAVALUpdate(context, bits, 10);
  322. /* Store state in digest */
  323. context->state[4] += ((context->state[7] & 0xFE000000) |
  324. (context->state[6] & 0x01F80000) |
  325. (context->state[5] & 0x0007F000)) >> 12;
  326. context->state[3] += ((context->state[7] & 0x01F80000) |
  327. (context->state[6] & 0x0007F000) |
  328. (context->state[5] & 0x00000FC0)) >> 6;
  329. context->state[2] += (context->state[7] & 0x0007F000) |
  330. (context->state[6] & 0x00000FC0) |
  331. (context->state[5] & 0x0000003F);
  332. context->state[1] += ROTR((context->state[7] & 0x00000FC0) |
  333. (context->state[6] & 0x0000003F) |
  334. (context->state[5] & 0xFE000000), 25);
  335. context->state[0] += ROTR((context->state[7] & 0x0000003F) |
  336. (context->state[6] & 0xFE000000) |
  337. (context->state[5] & 0x01F80000), 19);
  338. Encode(digest, context->state, 20);
  339. /* Zeroize sensitive information.
  340. */
  341. ZEND_SECURE_ZERO((unsigned char*) context, sizeof(*context));
  342. }
  343. /* }}} */
  344. /* {{{ PHP_HAVAL192Final */
  345. PHP_HASH_API void PHP_HAVAL192Final(unsigned char *digest, PHP_HAVAL_CTX * context)
  346. {
  347. unsigned char bits[10];
  348. unsigned int index, padLen;
  349. /* Version, Passes, and Digest Length */
  350. bits[0] = (PHP_HASH_HAVAL_VERSION & 0x07) |
  351. ((context->passes & 0x07) << 3) |
  352. ((context->output & 0x03) << 6);
  353. bits[1] = (context->output >> 2);
  354. /* Save number of bits */
  355. Encode(bits + 2, context->count, 8);
  356. /* Pad out to 118 mod 128.
  357. */
  358. index = (unsigned int) ((context->count[0] >> 3) & 0x7f);
  359. padLen = (index < 118) ? (118 - index) : (246 - index);
  360. PHP_HAVALUpdate(context, PADDING, padLen);
  361. /* Append version, passes, digest length, and message length */
  362. PHP_HAVALUpdate(context, bits, 10);
  363. /* Store state in digest */
  364. context->state[5] += ((context->state[7] & 0xFC000000) | (context->state[6] & 0x03E00000)) >> 21;
  365. context->state[4] += ((context->state[7] & 0x03E00000) | (context->state[6] & 0x001F0000)) >> 16;
  366. context->state[3] += ((context->state[7] & 0x001F0000) | (context->state[6] & 0x0000FC00)) >> 10;
  367. context->state[2] += ((context->state[7] & 0x0000FC00) | (context->state[6] & 0x000003E0)) >> 5;
  368. context->state[1] += (context->state[7] & 0x000003E0) | (context->state[6] & 0x0000001F);
  369. context->state[0] += ROTR((context->state[7] & 0x0000001F) | (context->state[6] & 0xFC000000), 26);
  370. Encode(digest, context->state, 24);
  371. /* Zeroize sensitive information.
  372. */
  373. ZEND_SECURE_ZERO((unsigned char*) context, sizeof(*context));
  374. }
  375. /* }}} */
  376. /* {{{ PHP_HAVAL224Final */
  377. PHP_HASH_API void PHP_HAVAL224Final(unsigned char *digest, PHP_HAVAL_CTX * context)
  378. {
  379. unsigned char bits[10];
  380. unsigned int index, padLen;
  381. /* Version, Passes, and Digest Length */
  382. bits[0] = (PHP_HASH_HAVAL_VERSION & 0x07) |
  383. ((context->passes & 0x07) << 3) |
  384. ((context->output & 0x03) << 6);
  385. bits[1] = (context->output >> 2);
  386. /* Save number of bits */
  387. Encode(bits + 2, context->count, 8);
  388. /* Pad out to 118 mod 128.
  389. */
  390. index = (unsigned int) ((context->count[0] >> 3) & 0x7f);
  391. padLen = (index < 118) ? (118 - index) : (246 - index);
  392. PHP_HAVALUpdate(context, PADDING, padLen);
  393. /* Append version, passes, digest length, and message length */
  394. PHP_HAVALUpdate(context, bits, 10);
  395. /* Store state in digest */
  396. context->state[6] += context->state[7] & 0x0000000F;
  397. context->state[5] += (context->state[7] >> 4) & 0x0000001F;
  398. context->state[4] += (context->state[7] >> 9) & 0x0000000F;
  399. context->state[3] += (context->state[7] >> 13) & 0x0000001F;
  400. context->state[2] += (context->state[7] >> 18) & 0x0000000F;
  401. context->state[1] += (context->state[7] >> 22) & 0x0000001F;
  402. context->state[0] += (context->state[7] >> 27) & 0x0000001F;
  403. Encode(digest, context->state, 28);
  404. /* Zeroize sensitive information.
  405. */
  406. ZEND_SECURE_ZERO((unsigned char*) context, sizeof(*context));
  407. }
  408. /* }}} */
  409. /* {{{ PHP_HAVAL256Final */
  410. PHP_HASH_API void PHP_HAVAL256Final(unsigned char *digest, PHP_HAVAL_CTX * context)
  411. {
  412. unsigned char bits[10];
  413. unsigned int index, padLen;
  414. /* Version, Passes, and Digest Length */
  415. bits[0] = (PHP_HASH_HAVAL_VERSION & 0x07) |
  416. ((context->passes & 0x07) << 3) |
  417. ((context->output & 0x03) << 6);
  418. bits[1] = (context->output >> 2);
  419. /* Save number of bits */
  420. Encode(bits + 2, context->count, 8);
  421. /* Pad out to 118 mod 128.
  422. */
  423. index = (unsigned int) ((context->count[0] >> 3) & 0x7f);
  424. padLen = (index < 118) ? (118 - index) : (246 - index);
  425. PHP_HAVALUpdate(context, PADDING, padLen);
  426. /* Append version, passes, digest length, and message length */
  427. PHP_HAVALUpdate(context, bits, 10);
  428. /* Store state in digest */
  429. Encode(digest, context->state, 32);
  430. /* Zeroize sensitive information.
  431. */
  432. ZEND_SECURE_ZERO((unsigned char*) context, sizeof(*context));
  433. }
  434. /* }}} */