2015-07-06 19:54:22 -05:00
// Copyright 2014 The go-ethereum Authors
2015-07-22 11:48:40 -05:00
// This file is part of the go-ethereum library.
2015-07-06 19:54:22 -05:00
//
2015-07-23 11:35:11 -05:00
// The go-ethereum library is free software: you can redistribute it and/or modify
2015-07-06 19:54:22 -05:00
// it under the terms of the GNU Lesser General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
//
2015-07-22 11:48:40 -05:00
// The go-ethereum library is distributed in the hope that it will be useful,
2015-07-06 19:54:22 -05:00
// but WITHOUT ANY WARRANTY; without even the implied warranty of
2015-07-22 11:48:40 -05:00
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
2015-07-06 19:54:22 -05:00
// GNU Lesser General Public License for more details.
//
// You should have received a copy of the GNU Lesser General Public License
2015-07-22 11:48:40 -05:00
// along with the go-ethereum library. If not, see <http://www.gnu.org/licenses/>.
2015-07-06 19:54:22 -05:00
2014-10-18 06:31:20 -05:00
package vm
2014-10-08 05:01:36 -05:00
import (
2017-02-18 02:24:12 -06:00
"crypto/sha256"
2019-06-17 12:19:47 -05:00
"encoding/binary"
2017-02-01 15:36:51 -06:00
"errors"
2023-06-05 08:43:25 -05:00
"fmt"
2024-09-06 04:31:00 -05:00
"maps"
2024-10-21 04:45:33 -05:00
"math"
common: move big integer math to common/math (#3699)
* common: remove CurrencyToString
Move denomination values to params instead.
* common: delete dead code
* common: move big integer operations to common/math
This commit consolidates all big integer operations into common/math and
adds tests and documentation.
There should be no change in semantics for BigPow, BigMin, BigMax, S256,
U256, Exp and their behaviour is now locked in by tests.
The BigD, BytesToBig and Bytes2Big functions don't provide additional
value, all uses are replaced by new(big.Int).SetBytes().
BigToBytes is now called PaddedBigBytes, its minimum output size
parameter is now specified as the number of bytes instead of bits. The
single use of this function is in the EVM's MSTORE instruction.
Big and String2Big are replaced by ParseBig, which is slightly stricter.
It previously accepted leading zeros for hexadecimal inputs but treated
decimal inputs as octal if a leading zero digit was present.
ParseUint64 is used in places where String2Big was used to decode a
uint64.
The new functions MustParseBig and MustParseUint64 are now used in many
places where parsing errors were previously ignored.
* common: delete unused big integer variables
* accounts/abi: replace uses of BytesToBig with use of encoding/binary
* common: remove BytesToBig
* common: remove Bytes2Big
* common: remove BigTrue
* cmd/utils: add BigFlag and use it for error-checked integer flags
While here, remove environment variable processing for DirectoryFlag
because we don't use it.
* core: add missing error checks in genesis block parser
* common: remove String2Big
* cmd/evm: use utils.BigFlag
* common/math: check for 256 bit overflow in ParseBig
This is supposed to prevent silent overflow/truncation of values in the
genesis block JSON. Without this check, a genesis block that set a
balance larger than 256 bits would lead to weird behaviour in the VM.
* cmd/utils: fixup import
2017-02-26 15:21:51 -06:00
"math/big"
2017-02-18 02:24:12 -06:00
2024-04-16 03:53:43 -05:00
"github.com/consensys/gnark-crypto/ecc"
bls12381 "github.com/consensys/gnark-crypto/ecc/bls12-381"
"github.com/consensys/gnark-crypto/ecc/bls12-381/fp"
"github.com/consensys/gnark-crypto/ecc/bls12-381/fr"
2015-03-16 05:27:38 -05:00
"github.com/ethereum/go-ethereum/common"
2024-03-22 12:53:53 -05:00
"github.com/ethereum/go-ethereum/core/tracing"
2015-03-18 22:56:06 -05:00
"github.com/ethereum/go-ethereum/crypto"
2019-06-17 12:19:47 -05:00
"github.com/ethereum/go-ethereum/crypto/blake2b"
2017-08-10 06:07:11 -05:00
"github.com/ethereum/go-ethereum/crypto/bn256"
2023-06-05 08:43:25 -05:00
"github.com/ethereum/go-ethereum/crypto/kzg4844"
2015-04-01 22:17:15 -05:00
"github.com/ethereum/go-ethereum/params"
2017-02-18 02:24:12 -06:00
"golang.org/x/crypto/ripemd160"
2014-10-08 05:01:36 -05:00
)
2017-08-10 08:39:43 -05:00
// PrecompiledContract is the basic interface for native Go contracts. The implementation
2017-01-05 04:52:10 -06:00
// requires a deterministic gas count based on the input size of the Run method of the
// contract.
type PrecompiledContract interface {
2017-02-01 15:36:51 -06:00
RequiredGas ( input [ ] byte ) uint64 // RequiredPrice calculates the contract gas use
Run ( input [ ] byte ) ( [ ] byte , error ) // Run runs the precompiled contract
2014-10-08 05:01:36 -05:00
}
2024-09-06 04:31:00 -05:00
// PrecompiledContracts contains the precompiled contracts supported at the given fork.
type PrecompiledContracts map [ common . Address ] PrecompiledContract
2017-08-10 08:39:43 -05:00
// PrecompiledContractsHomestead contains the default set of pre-compiled Ethereum
// contracts used in the Frontier and Homestead releases.
2024-09-06 04:31:00 -05:00
var PrecompiledContractsHomestead = PrecompiledContracts {
2024-04-18 02:08:25 -05:00
common . BytesToAddress ( [ ] byte { 0x1 } ) : & ecrecover { } ,
common . BytesToAddress ( [ ] byte { 0x2 } ) : & sha256hash { } ,
common . BytesToAddress ( [ ] byte { 0x3 } ) : & ripemd160hash { } ,
common . BytesToAddress ( [ ] byte { 0x4 } ) : & dataCopy { } ,
2014-10-08 05:01:36 -05:00
}
2017-09-14 02:07:31 -05:00
// PrecompiledContractsByzantium contains the default set of pre-compiled Ethereum
// contracts used in the Byzantium release.
2024-09-06 04:31:00 -05:00
var PrecompiledContractsByzantium = PrecompiledContracts {
2024-04-18 02:08:25 -05:00
common . BytesToAddress ( [ ] byte { 0x1 } ) : & ecrecover { } ,
common . BytesToAddress ( [ ] byte { 0x2 } ) : & sha256hash { } ,
common . BytesToAddress ( [ ] byte { 0x3 } ) : & ripemd160hash { } ,
common . BytesToAddress ( [ ] byte { 0x4 } ) : & dataCopy { } ,
common . BytesToAddress ( [ ] byte { 0x5 } ) : & bigModExp { eip2565 : false } ,
common . BytesToAddress ( [ ] byte { 0x6 } ) : & bn256AddByzantium { } ,
common . BytesToAddress ( [ ] byte { 0x7 } ) : & bn256ScalarMulByzantium { } ,
common . BytesToAddress ( [ ] byte { 0x8 } ) : & bn256PairingByzantium { } ,
2019-08-06 09:12:54 -05:00
}
// PrecompiledContractsIstanbul contains the default set of pre-compiled Ethereum
// contracts used in the Istanbul release.
2024-09-06 04:31:00 -05:00
var PrecompiledContractsIstanbul = PrecompiledContracts {
2024-04-18 02:08:25 -05:00
common . BytesToAddress ( [ ] byte { 0x1 } ) : & ecrecover { } ,
common . BytesToAddress ( [ ] byte { 0x2 } ) : & sha256hash { } ,
common . BytesToAddress ( [ ] byte { 0x3 } ) : & ripemd160hash { } ,
common . BytesToAddress ( [ ] byte { 0x4 } ) : & dataCopy { } ,
common . BytesToAddress ( [ ] byte { 0x5 } ) : & bigModExp { eip2565 : false } ,
common . BytesToAddress ( [ ] byte { 0x6 } ) : & bn256AddIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x7 } ) : & bn256ScalarMulIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x8 } ) : & bn256PairingIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x9 } ) : & blake2F { } ,
2017-08-10 06:07:11 -05:00
}
2021-02-25 01:10:30 -06:00
// PrecompiledContractsBerlin contains the default set of pre-compiled Ethereum
// contracts used in the Berlin release.
2024-09-06 04:31:00 -05:00
var PrecompiledContractsBerlin = PrecompiledContracts {
2024-04-18 02:08:25 -05:00
common . BytesToAddress ( [ ] byte { 0x1 } ) : & ecrecover { } ,
common . BytesToAddress ( [ ] byte { 0x2 } ) : & sha256hash { } ,
common . BytesToAddress ( [ ] byte { 0x3 } ) : & ripemd160hash { } ,
common . BytesToAddress ( [ ] byte { 0x4 } ) : & dataCopy { } ,
common . BytesToAddress ( [ ] byte { 0x5 } ) : & bigModExp { eip2565 : true } ,
common . BytesToAddress ( [ ] byte { 0x6 } ) : & bn256AddIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x7 } ) : & bn256ScalarMulIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x8 } ) : & bn256PairingIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x9 } ) : & blake2F { } ,
2021-01-28 14:19:07 -06:00
}
2023-06-05 08:43:25 -05:00
// PrecompiledContractsCancun contains the default set of pre-compiled Ethereum
// contracts used in the Cancun release.
2024-09-06 04:31:00 -05:00
var PrecompiledContractsCancun = PrecompiledContracts {
2024-04-18 02:08:25 -05:00
common . BytesToAddress ( [ ] byte { 0x1 } ) : & ecrecover { } ,
common . BytesToAddress ( [ ] byte { 0x2 } ) : & sha256hash { } ,
common . BytesToAddress ( [ ] byte { 0x3 } ) : & ripemd160hash { } ,
common . BytesToAddress ( [ ] byte { 0x4 } ) : & dataCopy { } ,
common . BytesToAddress ( [ ] byte { 0x5 } ) : & bigModExp { eip2565 : true } ,
common . BytesToAddress ( [ ] byte { 0x6 } ) : & bn256AddIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x7 } ) : & bn256ScalarMulIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x8 } ) : & bn256PairingIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x9 } ) : & blake2F { } ,
common . BytesToAddress ( [ ] byte { 0xa } ) : & kzgPointEvaluation { } ,
2023-06-05 08:43:25 -05:00
}
2024-04-18 02:08:25 -05:00
// PrecompiledContractsPrague contains the set of pre-compiled Ethereum
// contracts used in the Prague release.
2024-09-06 04:31:00 -05:00
var PrecompiledContractsPrague = PrecompiledContracts {
2024-04-23 08:10:24 -05:00
common . BytesToAddress ( [ ] byte { 0x01 } ) : & ecrecover { } ,
common . BytesToAddress ( [ ] byte { 0x02 } ) : & sha256hash { } ,
common . BytesToAddress ( [ ] byte { 0x03 } ) : & ripemd160hash { } ,
common . BytesToAddress ( [ ] byte { 0x04 } ) : & dataCopy { } ,
common . BytesToAddress ( [ ] byte { 0x05 } ) : & bigModExp { eip2565 : true } ,
common . BytesToAddress ( [ ] byte { 0x06 } ) : & bn256AddIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x07 } ) : & bn256ScalarMulIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x08 } ) : & bn256PairingIstanbul { } ,
common . BytesToAddress ( [ ] byte { 0x09 } ) : & blake2F { } ,
common . BytesToAddress ( [ ] byte { 0x0a } ) : & kzgPointEvaluation { } ,
2024-04-18 02:08:25 -05:00
common . BytesToAddress ( [ ] byte { 0x0b } ) : & bls12381G1Add { } ,
common . BytesToAddress ( [ ] byte { 0x0c } ) : & bls12381G1Mul { } ,
common . BytesToAddress ( [ ] byte { 0x0d } ) : & bls12381G1MultiExp { } ,
common . BytesToAddress ( [ ] byte { 0x0e } ) : & bls12381G2Add { } ,
common . BytesToAddress ( [ ] byte { 0x0f } ) : & bls12381G2Mul { } ,
common . BytesToAddress ( [ ] byte { 0x10 } ) : & bls12381G2MultiExp { } ,
common . BytesToAddress ( [ ] byte { 0x11 } ) : & bls12381Pairing { } ,
common . BytesToAddress ( [ ] byte { 0x12 } ) : & bls12381MapG1 { } ,
common . BytesToAddress ( [ ] byte { 0x13 } ) : & bls12381MapG2 { } ,
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
2024-04-18 02:08:25 -05:00
var PrecompiledContractsBLS = PrecompiledContractsPrague
2024-05-10 13:13:11 -05:00
var PrecompiledContractsVerkle = PrecompiledContractsPrague
2020-10-23 01:26:57 -05:00
var (
2024-04-18 02:08:25 -05:00
PrecompiledAddressesPrague [ ] common . Address
2023-06-05 08:43:25 -05:00
PrecompiledAddressesCancun [ ] common . Address
2021-02-25 01:10:30 -06:00
PrecompiledAddressesBerlin [ ] common . Address
2020-10-23 01:26:57 -05:00
PrecompiledAddressesIstanbul [ ] common . Address
PrecompiledAddressesByzantium [ ] common . Address
PrecompiledAddressesHomestead [ ] common . Address
)
func init ( ) {
for k := range PrecompiledContractsHomestead {
PrecompiledAddressesHomestead = append ( PrecompiledAddressesHomestead , k )
}
for k := range PrecompiledContractsByzantium {
2021-03-30 08:38:53 -05:00
PrecompiledAddressesByzantium = append ( PrecompiledAddressesByzantium , k )
2020-10-23 01:26:57 -05:00
}
for k := range PrecompiledContractsIstanbul {
PrecompiledAddressesIstanbul = append ( PrecompiledAddressesIstanbul , k )
}
2021-02-25 01:10:30 -06:00
for k := range PrecompiledContractsBerlin {
PrecompiledAddressesBerlin = append ( PrecompiledAddressesBerlin , k )
2020-10-23 01:26:57 -05:00
}
2023-06-05 08:43:25 -05:00
for k := range PrecompiledContractsCancun {
PrecompiledAddressesCancun = append ( PrecompiledAddressesCancun , k )
}
2024-04-18 02:08:25 -05:00
for k := range PrecompiledContractsPrague {
PrecompiledAddressesPrague = append ( PrecompiledAddressesPrague , k )
}
2020-10-23 01:26:57 -05:00
}
2024-09-06 04:31:00 -05:00
func activePrecompiledContracts ( rules params . Rules ) PrecompiledContracts {
switch {
case rules . IsVerkle :
return PrecompiledContractsVerkle
case rules . IsPrague :
return PrecompiledContractsPrague
case rules . IsCancun :
return PrecompiledContractsCancun
case rules . IsBerlin :
return PrecompiledContractsBerlin
case rules . IsIstanbul :
return PrecompiledContractsIstanbul
case rules . IsByzantium :
return PrecompiledContractsByzantium
default :
return PrecompiledContractsHomestead
}
}
// ActivePrecompiledContracts returns a copy of precompiled contracts enabled with the current configuration.
func ActivePrecompiledContracts ( rules params . Rules ) PrecompiledContracts {
return maps . Clone ( activePrecompiledContracts ( rules ) )
}
// ActivePrecompiles returns the precompile addresses enabled with the current configuration.
2021-04-07 09:54:31 -05:00
func ActivePrecompiles ( rules params . Rules ) [ ] common . Address {
switch {
2024-04-18 02:08:25 -05:00
case rules . IsPrague :
return PrecompiledAddressesPrague
2023-06-05 08:43:25 -05:00
case rules . IsCancun :
return PrecompiledAddressesCancun
2021-04-07 09:54:31 -05:00
case rules . IsBerlin :
return PrecompiledAddressesBerlin
case rules . IsIstanbul :
return PrecompiledAddressesIstanbul
case rules . IsByzantium :
return PrecompiledAddressesByzantium
default :
return PrecompiledAddressesHomestead
}
}
2017-08-10 08:39:43 -05:00
// RunPrecompiledContract runs and evaluates the output of a precompiled contract.
2020-07-16 07:06:19 -05:00
// It returns
// - the returned bytes,
// - the _remaining_ gas,
// - any error that occurred
2024-03-22 12:53:53 -05:00
func RunPrecompiledContract ( p PrecompiledContract , input [ ] byte , suppliedGas uint64 , logger * tracing . Hooks ) ( ret [ ] byte , remainingGas uint64 , err error ) {
2020-07-16 07:06:19 -05:00
gasCost := p . RequiredGas ( input )
if suppliedGas < gasCost {
return nil , 0 , ErrOutOfGas
2015-01-13 03:30:52 -06:00
}
2024-03-22 12:53:53 -05:00
if logger != nil && logger . OnGasChange != nil {
logger . OnGasChange ( suppliedGas , suppliedGas - gasCost , tracing . GasChangeCallPrecompiledContract )
}
2020-07-16 07:06:19 -05:00
suppliedGas -= gasCost
output , err := p . Run ( input )
return output , suppliedGas , err
2014-10-08 05:01:36 -05:00
}
2024-03-26 15:01:28 -05:00
// ecrecover implemented as a native contract.
2017-01-05 04:52:10 -06:00
type ecrecover struct { }
2014-10-08 05:01:36 -05:00
2017-02-01 15:36:51 -06:00
func ( c * ecrecover ) RequiredGas ( input [ ] byte ) uint64 {
2017-01-05 04:52:10 -06:00
return params . EcrecoverGas
2014-10-08 05:01:36 -05:00
}
2017-08-10 08:39:43 -05:00
func ( c * ecrecover ) Run ( input [ ] byte ) ( [ ] byte , error ) {
2017-01-05 04:52:10 -06:00
const ecRecoverInputLength = 128
2014-10-08 05:01:36 -05:00
2017-08-10 08:39:43 -05:00
input = common . RightPadBytes ( input , ecRecoverInputLength )
// "input" is (hash, v, r, s), each 32 bytes
2015-06-09 08:41:15 -05:00
// but for ecrecover we want (r, s, v)
2015-03-29 08:02:49 -05:00
2017-08-10 08:39:43 -05:00
r := new ( big . Int ) . SetBytes ( input [ 64 : 96 ] )
s := new ( big . Int ) . SetBytes ( input [ 96 : 128 ] )
v := input [ 63 ] - 27
2015-06-09 08:41:15 -05:00
2017-08-10 08:39:43 -05:00
// tighter sig s values input homestead only apply to tx sigs
if ! allZero ( input [ 32 : 63 ] ) || ! crypto . ValidateSignatureValues ( v , r , s , false ) {
2017-02-01 15:36:51 -06:00
return nil , nil
2015-03-18 22:56:06 -05:00
}
2019-11-04 03:31:10 -06:00
// We must make sure not to modify the 'input', so placing the 'v' along with
// the signature needs to be done on a new allocation
sig := make ( [ ] byte , 65 )
copy ( sig , input [ 64 : 128 ] )
sig [ 64 ] = v
2017-01-05 04:35:23 -06:00
// v needs to be at the end for libsecp256k1
2019-11-04 03:31:10 -06:00
pubKey , err := crypto . Ecrecover ( input [ : 32 ] , sig )
2015-03-29 08:02:49 -05:00
// make sure the public key is a valid one
2015-04-05 12:31:18 -05:00
if err != nil {
2017-02-01 15:36:51 -06:00
return nil , nil
2015-03-18 22:56:06 -05:00
}
2015-03-29 08:02:49 -05:00
2015-03-18 22:56:06 -05:00
// the first byte of pubkey is bitcoin heritage
2017-02-01 15:36:51 -06:00
return common . LeftPadBytes ( crypto . Keccak256 ( pubKey [ 1 : ] ) [ 12 : ] , 32 ) , nil
2014-10-08 05:01:36 -05:00
}
2015-01-05 10:37:30 -06:00
2017-08-10 08:39:43 -05:00
// SHA256 implemented as a native contract.
2017-02-18 02:24:12 -06:00
type sha256hash struct { }
2017-01-05 04:52:10 -06:00
2017-01-04 13:17:24 -06:00
// RequiredGas returns the gas required to execute the pre-compiled contract.
//
// This method does not require any overflow checking as the input size gas costs
// required for anything significant is so high it's impossible to pay for.
2017-02-01 15:36:51 -06:00
func ( c * sha256hash ) RequiredGas ( input [ ] byte ) uint64 {
2017-08-10 08:39:43 -05:00
return uint64 ( len ( input ) + 31 ) / 32 * params . Sha256PerWordGas + params . Sha256BaseGas
2017-01-05 04:52:10 -06:00
}
2017-08-10 08:39:43 -05:00
func ( c * sha256hash ) Run ( input [ ] byte ) ( [ ] byte , error ) {
h := sha256 . Sum256 ( input )
2017-02-01 15:36:51 -06:00
return h [ : ] , nil
2017-01-05 04:52:10 -06:00
}
2018-07-31 05:27:51 -05:00
// RIPEMD160 implemented as a native contract.
2017-02-18 02:24:12 -06:00
type ripemd160hash struct { }
2017-01-05 04:52:10 -06:00
2017-01-04 13:17:24 -06:00
// RequiredGas returns the gas required to execute the pre-compiled contract.
//
// This method does not require any overflow checking as the input size gas costs
// required for anything significant is so high it's impossible to pay for.
2017-02-01 15:36:51 -06:00
func ( c * ripemd160hash ) RequiredGas ( input [ ] byte ) uint64 {
2017-08-10 08:39:43 -05:00
return uint64 ( len ( input ) + 31 ) / 32 * params . Ripemd160PerWordGas + params . Ripemd160BaseGas
2017-01-05 04:52:10 -06:00
}
2017-08-10 08:39:43 -05:00
func ( c * ripemd160hash ) Run ( input [ ] byte ) ( [ ] byte , error ) {
2017-02-18 02:24:12 -06:00
ripemd := ripemd160 . New ( )
2017-08-10 08:39:43 -05:00
ripemd . Write ( input )
2017-02-01 15:36:51 -06:00
return common . LeftPadBytes ( ripemd . Sum ( nil ) , 32 ) , nil
2017-01-05 04:52:10 -06:00
}
2017-08-10 08:39:43 -05:00
// data copy implemented as a native contract.
2017-01-05 04:52:10 -06:00
type dataCopy struct { }
2017-01-04 13:17:24 -06:00
// RequiredGas returns the gas required to execute the pre-compiled contract.
//
// This method does not require any overflow checking as the input size gas costs
// required for anything significant is so high it's impossible to pay for.
2017-02-01 15:36:51 -06:00
func ( c * dataCopy ) RequiredGas ( input [ ] byte ) uint64 {
2017-08-10 08:39:43 -05:00
return uint64 ( len ( input ) + 31 ) / 32 * params . IdentityPerWordGas + params . IdentityBaseGas
2017-01-05 04:52:10 -06:00
}
2017-02-01 15:36:51 -06:00
func ( c * dataCopy ) Run ( in [ ] byte ) ( [ ] byte , error ) {
2022-09-20 07:58:03 -05:00
return common . CopyBytes ( in ) , nil
2015-01-05 10:37:30 -06:00
}
2017-08-10 06:07:11 -05:00
2017-08-10 08:39:43 -05:00
// bigModExp implements a native big integer exponential modular operation.
2020-11-13 06:39:59 -06:00
type bigModExp struct {
eip2565 bool
}
2017-08-10 06:07:11 -05:00
2017-08-14 09:08:49 -05:00
var (
big1 = big . NewInt ( 1 )
2020-11-13 06:39:59 -06:00
big3 = big . NewInt ( 3 )
big7 = big . NewInt ( 7 )
big20 = big . NewInt ( 20 )
2017-08-14 09:08:49 -05:00
big32 = b ig . NewInt ( 32 )
big64 = big . NewInt ( 64 )
big96 = big . NewInt ( 96 )
big480 = big . NewInt ( 480 )
big1024 = big . NewInt ( 1024 )
big3072 = big . NewInt ( 3072 )
big199680 = big . NewInt ( 199680 )
)
2020-11-13 06:39:59 -06:00
// modexpMultComplexity implements bigModexp multComplexity formula, as defined in EIP-198
//
2022-09-10 06:25:40 -05:00
// def mult_complexity(x):
// if x <= 64: return x ** 2
// elif x <= 1024: return x ** 2 // 4 + 96 * x - 3072
// else: return x ** 2 // 16 + 480 * x - 199680
2020-11-13 06:39:59 -06:00
//
// where is x is max(length_of_MODULUS, length_of_BASE)
func modexpMultComplexity ( x * big . Int ) * big . Int {
switch {
case x . Cmp ( big64 ) <= 0 :
x . Mul ( x , x ) // x ** 2
case x . Cmp ( big1024 ) <= 0 :
// (x ** 2 // 4 ) + ( 96 * x - 3072)
x = new ( big . Int ) . Add (
2024-06-28 11:08:31 -05:00
new ( big . Int ) . Rsh ( new ( big . Int ) . Mul ( x , x ) , 2 ) ,
2020-11-13 06:39:59 -06:00
new ( big . Int ) . Sub ( new ( big . Int ) . Mul ( big96 , x ) , big3072 ) ,
)
default :
// (x ** 2 // 16) + (480 * x - 199680)
x = new ( big . Int ) . Add (
2024-06-28 11:08:31 -05:00
new ( big . Int ) . Rsh ( new ( big . Int ) . Mul ( x , x ) , 4 ) ,
2020-11-13 06:39:59 -06:00
new ( big . Int ) . Sub ( new ( big . Int ) . Mul ( big480 , x ) , big199680 ) ,
)
}
return x
}
2017-08-10 06:07:11 -05:00
// RequiredGas returns the gas required to execute the pre-compiled contract.
2017-08-10 08:39:43 -05:00
func ( c * bigModExp ) RequiredGas ( input [ ] byte ) uint64 {
2017-08-10 06:07:11 -05:00
var (
2017-08-14 09:08:49 -05:00
baseLen = new ( big . Int ) . SetBytes ( getData ( input , 0 , 32 ) )
expLen = new ( big . Int ) . SetBytes ( getData ( input , 32 , 32 ) )
modLen = new ( big . Int ) . SetBytes ( getData ( input , 64 , 32 ) )
2017-08-10 06:07:11 -05:00
)
2017-08-14 09:08:49 -05:00
if len ( input ) > 96 {
input = input [ 96 : ]
} else {
input = input [ : 0 ]
}
2017-08-10 08:39:43 -05:00
// Retrieve the head 32 bytes of exp for the adjusted exponent length
var expHead * big . Int
if big . NewInt ( int64 ( len ( input ) ) ) . Cmp ( baseLen ) <= 0 {
expHead = new ( big . Int )
} else {
2017-08-14 09:08:49 -05:00
if expLen . Cmp ( big32 ) > 0 {
expHead = new ( big . Int ) . SetBytes ( getData ( input , baseLen . Uint64 ( ) , 32 ) )
2017-08-10 08:39:43 -05:00
} else {
2017-08-14 09:08:49 -05:00
expHead = new ( big . Int ) . SetBytes ( getData ( input , baseLen . Uint64 ( ) , expLen . Uint64 ( ) ) )
2017-08-10 08:39:43 -05:00
}
2017-08-10 06:07:11 -05:00
}
2017-08-10 08:39:43 -05:00
// Calculate the adjusted exponent length
var msb int
if bitlen := expHead . BitLen ( ) ; bitlen > 0 {
msb = bitlen - 1
}
adjExpLen := new ( big . Int )
2017-08-14 09:08:49 -05:00
if expLen . Cmp ( big32 ) > 0 {
adjExpLen . Sub ( expLen , big32 )
2024-06-28 11:08:31 -05:00
adjExpLen . Lsh ( adjExpLen , 3 )
2017-08-10 08:39:43 -05:00
}
adjExpLen . Add ( adjExpLen , big . NewInt ( int64 ( msb ) ) )
// Calculate the gas cost of the operation
2024-10-21 04:45:33 -05:00
gas := new ( big . Int )
if modLen . Cmp ( baseLen ) < 0 {
gas . Set ( baseLen )
} else {
gas . Set ( modLen )
}
2020-11-13 06:39:59 -06:00
if c . eip2565 {
// EIP-2565 has three changes
// 1. Different multComplexity (inlined here)
// in EIP-2565 (https://eips.ethereum.org/EIPS/eip-2565):
//
// def mult_complexity(x):
// ceiling(x/8)^2
//
//where is x is max(length_of_MODULUS, length_of_BASE)
2024-06-28 11:08:31 -05:00
gas . Add ( gas , big7 )
gas . Rsh ( gas , 3 )
2017-08-10 08:39:43 -05:00
gas . Mul ( gas , gas )
2020-11-13 06:39:59 -06:00
2024-10-21 04:45:33 -05:00
if adjExpLen . Cmp ( big1 ) > 0 {
gas . Mul ( gas , adjExpLen )
}
2020-11-13 06:39:59 -06:00
// 2. Different divisor (`GQUADDIVISOR`) (3)
gas . Div ( gas , big3 )
if gas . BitLen ( ) > 64 {
2024-10-21 04:45:33 -05:00
return math . MaxUint64
2020-11-13 06:39:59 -06:00
}
// 3. Minimum price of 200 gas
if gas . Uint64 ( ) < 200 {
return 200
}
return gas . Uint64 ( )
2017-08-10 08:39:43 -05:00
}
2020-11-13 06:39:59 -06:00
gas = modexpMultComplexity ( gas )
2024-10-21 04:45:33 -05:00
if adjExpLen . Cmp ( big1 ) > 0 {
gas . Mul ( gas , adjExpLen )
}
2020-11-13 06:39:59 -06:00
gas . Div ( gas , big20 )
2017-08-10 08:39:43 -05:00
if gas . BitLen ( ) > 64 {
2024-10-21 04:45:33 -05:00
return math . MaxUint64
2017-08-10 08:39:43 -05:00
}
return gas . Uint64 ( )
}
func ( c * bigModExp ) Run ( input [ ] byte ) ( [ ] byte , error ) {
2017-08-10 06:07:11 -05:00
var (
2017-08-14 09:08:49 -05:00
baseLen = new ( big . Int ) . SetBytes ( getData ( input , 0 , 32 ) ) . Uint64 ( )
expLen = new ( big . Int ) . SetBytes ( getData ( input , 32 , 32 ) ) . Uint64 ( )
modLen = new ( big . Int ) . SetBytes ( getData ( input , 64 , 32 ) ) . Uint64 ( )
2017-08-10 06:07:11 -05:00
)
2017-08-14 09:08:49 -05:00
if len ( input ) > 96 {
input = input [ 96 : ]
} else {
input = input [ : 0 ]
}
// Handle a special case when both the base and mod length is zero
if baseLen == 0 && modLen == 0 {
return [ ] byte { } , nil
}
// Retrieve the operands and execute the exponentiation
2017-08-10 08:39:43 -05:00
var (
2023-03-08 12:12:53 -06:00
base = new ( big . Int ) . SetBytes ( getData ( input , 0 , baseLen ) )
exp = new ( big . Int ) . SetBytes ( getData ( input , baseLen , expLen ) )
mod = new ( big . Int ) . SetBytes ( getData ( input , baseLen + expLen , modLen ) )
2022-10-12 03:34:52 -05:00
v [ ] byte
2017-08-10 08:39:43 -05:00
)
2022-10-12 03:34:52 -05:00
switch {
case mod . BitLen ( ) == 0 :
2017-08-10 08:39:43 -05:00
// Modulo 0 is undefined, return zero
return common . LeftPadBytes ( [ ] byte { } , int ( modLen ) ) , nil
2022-10-27 03:39:01 -05:00
case base . BitLen ( ) == 1 : // a bit length of 1 means it's 1 (or -1).
2022-10-12 03:34:52 -05:00
//If base == 1, then we can just return base % mod (if mod >= 1, which it is)
v = base . Mod ( base , mod ) . Bytes ( )
default :
v = base . Exp ( base , exp , mod ) . Bytes ( )
2017-08-10 06:07:11 -05:00
}
2022-10-12 03:34:52 -05:00
return common . LeftPadBytes ( v , int ( modLen ) ) , nil
2017-08-10 06:07:11 -05:00
}
2017-08-10 08:39:43 -05:00
// newCurvePoint unmarshals a binary blob into a bn256 elliptic curve point,
// returning it, or an error if the point is invalid.
func newCurvePoint ( blob [ ] byte ) ( * bn256 . G1 , error ) {
2018-03-05 06:33:45 -06:00
p := new ( bn256 . G1 )
if _ , err := p . Unmarshal ( blob ) ; err != nil {
return nil , err
2017-08-10 06:07:11 -05:00
}
2017-08-10 08:39:43 -05:00
return p , nil
}
2017-08-10 06:07:11 -05:00
2017-08-10 08:39:43 -05:00
// newTwistPoint unmarshals a binary blob into a bn256 elliptic curve point,
// returning it, or an error if the point is invalid.
func newTwistPoint ( blob [ ] byte ) ( * bn256 . G2 , error ) {
2018-03-05 06:33:45 -06:00
p := new ( bn256 . G2 )
if _ , err := p . Unmarshal ( blob ) ; err != nil {
return nil , err
2017-08-10 06:07:11 -05:00
}
2017-08-10 08:39:43 -05:00
return p , nil
2017-08-10 06:07:11 -05:00
}
2019-08-06 09:12:54 -05:00
// runBn256Add implements the Bn256Add precompile, referenced by both
// Byzantium and Istanbul operations.
func runBn256Add ( input [ ] byte ) ( [ ] byte , error ) {
2017-08-14 09:08:49 -05:00
x , err := newCurvePoint ( getData ( input , 0 , 64 ) )
2017-08-10 08:39:43 -05:00
if err != nil {
return nil , err
2017-08-10 06:07:11 -05:00
}
2017-08-14 09:08:49 -05:00
y , err := newCurvePoint ( getData ( input , 64 , 64 ) )
2017-08-10 08:39:43 -05:00
if err != nil {
return nil , err
2017-08-10 06:07:11 -05:00
}
2017-08-17 08:46:46 -05:00
res := new ( bn256 . G1 )
res . Add ( x , y )
return res . Marshal ( ) , nil
2017-08-10 06:07:11 -05:00
}
2024-03-26 15:01:28 -05:00
// bn256AddIstanbul implements a native elliptic curve point addition conforming to
2019-08-06 09:12:54 -05:00
// Istanbul consensus rules.
type bn256AddIstanbul struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bn256AddIstanbul ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bn256AddGasIstanbul
}
func ( c * bn256AddIstanbul ) Run ( input [ ] byte ) ( [ ] byte , error ) {
return runBn256Add ( input )
}
// bn256AddByzantium implements a native elliptic curve point addition
// conforming to Byzantium consensus rules.
type bn256AddByzantium struct { }
2017-08-10 06:07:11 -05:00
// RequiredGas returns the gas required to execute the pre-compiled contract.
2019-08-06 09:12:54 -05:00
func ( c * bn256AddByzantium ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bn256AddGasByzantium
}
func ( c * bn256AddByzantium ) Run ( input [ ] byte ) ( [ ] byte , error ) {
return runBn256Add ( input )
2017-08-10 06:07:11 -05:00
}
2019-08-06 09:12:54 -05:00
// runBn256ScalarMul implements the Bn256ScalarMul precompile, referenced by
// both Byzantium and Istanbul operations.
func runBn256ScalarMul ( input [ ] byte ) ( [ ] byte , error ) {
2017-08-14 09:08:49 -05:00
p , err := newCurvePoint ( getData ( input , 0 , 64 ) )
2017-08-10 08:39:43 -05:00
if err != nil {
return nil , err
}
2017-08-17 08:46:46 -05:00
res := new ( bn256 . G1 )
res . ScalarMult ( p , new ( big . Int ) . SetBytes ( getData ( input , 64 , 32 ) ) )
return res . Marshal ( ) , nil
2017-08-10 08:39:43 -05:00
}
2017-08-10 06:07:11 -05:00
2019-08-06 09:12:54 -05:00
// bn256ScalarMulIstanbul implements a native elliptic curve scalar
// multiplication conforming to Istanbul consensus rules.
type bn256ScalarMulIstanbul struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bn256ScalarMulIstanbul ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bn256ScalarMulGasIstanbul
}
func ( c * bn256ScalarMulIstanbul ) Run ( input [ ] byte ) ( [ ] byte , error ) {
return runBn256ScalarMul ( input )
}
// bn256ScalarMulByzantium implements a native elliptic curve scalar
// multiplication conforming to Byzantium consensus rules.
type bn256ScalarMulByzantium struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bn256ScalarMulByzantium ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bn256ScalarMulGasByzantium
}
func ( c * bn256ScalarMulByzantium ) Run ( input [ ] byte ) ( [ ] byte , error ) {
return runBn256ScalarMul ( input )
}
2017-08-10 06:07:11 -05:00
var (
2017-08-10 08:39:43 -05:00
// true32Byte is returned if the bn256 pairing check succeeds.
true32Byte = [ ] byte { 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 0 , 1 }
// false32Byte is returned if the bn256 pairing check fails.
false32Byte = make ( [ ] byte , 32 )
// errBadPairingInput is returned if the bn256 pairing input is invalid.
errBadPairingInput = errors . New ( "bad elliptic curve pairing size" )
2017-08-10 06:07:11 -05:00
)
2019-08-06 09:12:54 -05:00
// runBn256Pairing implements the Bn256Pairing precompile, referenced by both
// Byzantium and Istanbul operations.
func runBn256Pairing ( input [ ] byte ) ( [ ] byte , error ) {
2017-08-10 08:39:43 -05:00
// Handle some corner cases cheaply
if len ( input ) % 192 > 0 {
return nil , errBadPairingInput
}
// Convert the input into a set of coordinates
2017-08-10 06:07:11 -05:00
var (
2017-08-10 08:39:43 -05:00
cs [ ] * bn256 . G1
ts [ ] * bn256 . G2
2017-08-10 06:07:11 -05:00
)
2017-08-10 08:39:43 -05:00
for i := 0 ; i < len ( input ) ; i += 192 {
c , err := newCurvePoint ( input [ i : i + 64 ] )
if err != nil {
return nil , err
2017-08-10 06:07:11 -05:00
}
2017-08-10 08:39:43 -05:00
t , err := newTwistPoint ( input [ i + 64 : i + 192 ] )
if err != nil {
return nil , err
2017-08-10 06:07:11 -05:00
}
2017-08-10 08:39:43 -05:00
cs = append ( cs , c )
ts = append ( ts , t )
2017-08-10 06:07:11 -05:00
}
2017-08-10 08:39:43 -05:00
// Execute the pairing checks and return the results
2017-08-17 08:46:46 -05:00
if bn256 . PairingCheck ( cs , ts ) {
2017-08-10 06:07:11 -05:00
return true32Byte , nil
}
2017-08-10 08:39:43 -05:00
return false32Byte , nil
2017-08-10 06:07:11 -05:00
}
2019-08-06 09:12:54 -05:00
// bn256PairingIstanbul implements a pairing pre-compile for the bn256 curve
// conforming to Istanbul consensus rules.
type bn256PairingIstanbul struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bn256PairingIstanbul ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bn256PairingBaseGasIstanbul + uint64 ( len ( input ) / 192 ) * params . Bn256PairingPerPointGasIstanbul
}
func ( c * bn256PairingIstanbul ) Run ( input [ ] byte ) ( [ ] byte , error ) {
return runBn256Pairing ( input )
}
// bn256PairingByzantium implements a pairing pre-compile for the bn256 curve
// conforming to Byzantium consensus rules.
type bn256PairingByzantium struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bn256PairingByzantium ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bn256PairingBaseGasByzantium + uint64 ( len ( input ) / 192 ) * params . Bn256PairingPerPointGasByzantium
}
func ( c * bn256PairingByzantium ) Run ( input [ ] byte ) ( [ ] byte , error ) {
return runBn256Pairing ( input )
}
2019-06-17 12:19:47 -05:00
type blake2F struct { }
func ( c * blake2F ) RequiredGas ( input [ ] byte ) uint64 {
2019-08-21 04:38:18 -05:00
// If the input is malformed, we can't calculate the gas, return 0 and let the
// actual call choke and fault.
2019-06-17 12:19:47 -05:00
if len ( input ) != blake2FInputLength {
return 0
}
2019-08-21 04:38:18 -05:00
return uint64 ( binary . BigEndian . Uint32 ( input [ 0 : 4 ] ) )
2019-06-17 12:19:47 -05:00
}
2019-08-21 04:38:18 -05:00
const (
blake2FInputLength = 213
blake2FFinalBlockBytes = byte ( 1 )
blake2FNonFinalBlockBytes = byte ( 0 )
2019-06-17 12:19:47 -05:00
)
2019-08-21 04:38:18 -05:00
var (
errBlake2FInvalidInputLength = errors . New ( "invalid input length" )
errBlake2FInvalidFinalFlag = errors . New ( "invalid final flag" )
2019-06-17 12:19:47 -05:00
)
func ( c * blake2F ) Run ( input [ ] byte ) ( [ ] byte , error ) {
2020-05-25 03:21:28 -05:00
// Make sure the input is valid (correct length and final flag)
2019-06-17 12:19:47 -05:00
if len ( input ) != blake2FInputLength {
2019-08-21 04:38:18 -05:00
return nil , errBlake2FInvalidInputLength
2019-06-17 12:19:47 -05:00
}
if input [ 212 ] != blake2FNonFinalBlockBytes && input [ 212 ] != blake2FFinalBlockBytes {
2019-08-21 04:38:18 -05:00
return nil , errBlake2FInvalidFinalFlag
2019-06-17 12:19:47 -05:00
}
2019-08-21 04:38:18 -05:00
// Parse the input into the Blake2b call parameters
var (
rounds = binary . BigEndian . Uint32 ( input [ 0 : 4 ] )
2022-05-11 00:03:35 -05:00
final = input [ 212 ] == blake2FFinalBlockBytes
2019-06-17 12:19:47 -05:00
2019-08-21 04:38:18 -05:00
h [ 8 ] uint64
m [ 16 ] uint64
t [ 2 ] uint64
)
2019-06-17 12:19:47 -05:00
for i := 0 ; i < 8 ; i ++ {
offset := 4 + i * 8
h [ i ] = binary . LittleEndian . Uint64 ( input [ offset : offset + 8 ] )
}
for i := 0 ; i < 16 ; i ++ {
offset := 68 + i * 8
m [ i ] = binary . LittleEndian . Uint64 ( input [ offset : offset + 8 ] )
}
t [ 0 ] = binary . LittleEndian . Uint64 ( input [ 196 : 204 ] )
t [ 1 ] = binary . LittleEndian . Uint64 ( input [ 204 : 212 ] )
2019-08-21 04:38:18 -05:00
// Execute the compression function, extract and return the result
blake2b . F ( & h , m , t , final , rounds )
2019-06-17 12:19:47 -05:00
2019-08-21 04:38:18 -05:00
output := make ( [ ] byte , 64 )
2019-06-17 12:19:47 -05:00
for i := 0 ; i < 8 ; i ++ {
offset := i * 8
binary . LittleEndian . PutUint64 ( output [ offset : offset + 8 ] , h [ i ] )
}
2019-08-21 04:38:18 -05:00
return output , nil
2019-06-17 12:19:47 -05:00
}
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
var (
errBLS12381InvalidInputLength = errors . New ( "invalid input length" )
errBLS12381InvalidFieldElementTopBytes = errors . New ( "invalid field element top bytes" )
errBLS12381G1PointSubgroup = errors . New ( "g1 point is not on correct subgroup" )
errBLS12381G2PointSubgroup = errors . New ( "g2 point is not on correct subgroup" )
)
// bls12381G1Add implements EIP-2537 G1Add precompile.
type bls12381G1Add struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bls12381G1Add ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bls12381G1AddGas
}
func ( c * bls12381G1Add ) Run ( input [ ] byte ) ( [ ] byte , error ) {
// Implements EIP-2537 G1Add precompile.
// > G1 addition call expects `256` bytes as an input that is interpreted as byte concatenation of two G1 points (`128` bytes each).
// > Output is an encoding of addition operation result - single G1 point (`128` bytes).
if len ( input ) != 256 {
return nil , errBLS12381InvalidInputLength
}
var err error
2024-04-16 03:53:43 -05:00
var p0 , p1 * bls12381 . G1Affine
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode G1 point p_0
2024-04-16 03:53:43 -05:00
if p0 , err = decodePointG1 ( input [ : 128 ] ) ; err != nil {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
return nil , err
}
// Decode G1 point p_1
2024-04-16 03:53:43 -05:00
if p1 , err = decodePointG1 ( input [ 128 : ] ) ; err != nil {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
return nil , err
}
2024-04-30 07:35:48 -05:00
// No need to check the subgroup here, as specified by EIP-2537
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Compute r = p_0 + p_1
2024-04-16 03:53:43 -05:00
p0 . Add ( p0 , p1 )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Encode the G1 point result into 128 bytes
2024-04-16 03:53:43 -05:00
return encodePointG1 ( p0 ) , nil
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// bls12381G1Mul implements EIP-2537 G1Mul precompile.
type bls12381G1Mul struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bls12381G1Mul ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bls12381G1MulGas
}
func ( c * bls12381G1Mul ) Run ( input [ ] byte ) ( [ ] byte , error ) {
// Implements EIP-2537 G1Mul precompile.
// > G1 multiplication call expects `160` bytes as an input that is interpreted as byte concatenation of encoding of G1 point (`128` bytes) and encoding of a scalar value (`32` bytes).
// > Output is an encoding of multiplication operation result - single G1 point (`128` bytes).
if len ( input ) != 160 {
return nil , errBLS12381InvalidInputLength
}
var err error
2024-04-16 03:53:43 -05:00
var p0 * bls12381 . G1Affine
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode G1 point
2024-04-16 03:53:43 -05:00
if p0 , err = decodePointG1 ( input [ : 128 ] ) ; err != nil {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
return nil , err
}
2024-04-30 07:35:48 -05:00
// 'point is on curve' check already done,
// Here we need to apply subgroup checks.
if ! p0 . IsInSubGroup ( ) {
return nil , errBLS12381G1PointSubgroup
}
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode scalar value
e := new ( big . Int ) . SetBytes ( input [ 128 : ] )
// Compute r = e * p_0
2024-04-16 03:53:43 -05:00
r := new ( bls12381 . G1Affine )
r . ScalarMultiplication ( p0 , e )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Encode the G1 point into 128 bytes
2024-04-16 03:53:43 -05:00
return encodePointG1 ( r ) , nil
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// bls12381G1MultiExp implements EIP-2537 G1MultiExp precompile.
type bls12381G1MultiExp struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bls12381G1MultiExp ) RequiredGas ( input [ ] byte ) uint64 {
// Calculate G1 point, scalar value pair length
k := len ( input ) / 160
if k == 0 {
// Return 0 gas for small input length
return 0
}
// Lookup discount value for G1 point, scalar value pair length
2020-06-24 14:58:28 -05:00
var discount uint64
if dLen := len ( params . Bls12381MultiExpDiscountTable ) ; k < dLen {
discount = params . Bls12381MultiExpDiscountTable [ k - 1 ]
} else {
discount = params . Bls12381MultiExpDiscountTable [ dLen - 1 ]
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// Calculate gas and return the result
return ( uint64 ( k ) * params . Bls12381G1MulGas * discount ) / 1000
}
func ( c * bls12381G1MultiExp ) Run ( input [ ] byte ) ( [ ] byte , error ) {
// Implements EIP-2537 G1MultiExp precompile.
// G1 multiplication call expects `160*k` bytes as an input that is interpreted as byte concatenation of `k` slices each of them being a byte concatenation of encoding of G1 point (`128` bytes) and encoding of a scalar value (`32` bytes).
// Output is an encoding of multiexponentiation operation result - single G1 point (`128` bytes).
k := len ( input ) / 160
if len ( input ) == 0 || len ( input ) % 160 != 0 {
return nil , errBLS12381InvalidInputLength
}
2024-04-16 03:53:43 -05:00
points := make ( [ ] bls12381 . G1Affine , k )
scalars := make ( [ ] fr . Element , k )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode point scalar pairs
for i := 0 ; i < k ; i ++ {
off := 160 * i
t0 , t1 , t2 := off , off + 128 , off + 160
// Decode G1 point
2024-04-16 03:53:43 -05:00
p , err := decodePointG1 ( input [ t0 : t1 ] )
if err != nil {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
return nil , err
}
2024-04-30 07:35:48 -05:00
// 'point is on curve' check already done,
// Here we need to apply subgroup checks.
if ! p . IsInSubGroup ( ) {
return nil , errBLS12381G1PointSubgroup
}
2024-04-16 03:53:43 -05:00
points [ i ] = * p
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode scalar value
2024-04-16 03:53:43 -05:00
scalars [ i ] = * new ( fr . Element ) . SetBytes ( input [ t1 : t2 ] )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// Compute r = e_0 * p_0 + e_1 * p_1 + ... + e_(k-1) * p_(k-1)
2024-04-16 03:53:43 -05:00
r := new ( bls12381 . G1Affine )
r . MultiExp ( points , scalars , ecc . MultiExpConfig { } )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Encode the G1 point to 128 bytes
2024-04-16 03:53:43 -05:00
return encodePointG1 ( r ) , nil
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// bls12381G2Add implements EIP-2537 G2Add precompile.
type bls12381G2Add struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bls12381G2Add ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bls12381G2AddGas
}
func ( c * bls12381G2Add ) Run ( input [ ] byte ) ( [ ] byte , error ) {
// Implements EIP-2537 G2Add precompile.
// > G2 addition call expects `512` bytes as an input that is interpreted as byte concatenation of two G2 points (`256` bytes each).
// > Output is an encoding of addition operation result - single G2 point (`256` bytes).
if len ( input ) != 512 {
return nil , errBLS12381InvalidInputLength
}
var err error
2024-04-16 03:53:43 -05:00
var p0 , p1 * bls12381 . G2Affine
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode G2 point p_0
2024-04-16 03:53:43 -05:00
if p0 , err = decodePointG2 ( input [ : 256 ] ) ; err != nil {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
return nil , err
}
// Decode G2 point p_1
2024-04-16 03:53:43 -05:00
if p1 , err = decodePointG2 ( input [ 256 : ] ) ; err != nil {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
return nil , err
}
2024-04-30 07:35:48 -05:00
// No need to check the subgroup here, as specified by EIP-2537
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Compute r = p_0 + p_1
2024-04-16 03:53:43 -05:00
r := new ( bls12381 . G2Affine )
r . Add ( p0 , p1 )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Encode the G2 point into 256 bytes
2024-04-16 03:53:43 -05:00
return encodePointG2 ( r ) , nil
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// bls12381G2Mul implements EIP-2537 G2Mul precompile.
type bls12381G2Mul struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bls12381G2Mul ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bls12381G2MulGas
}
func ( c * bls12381G2Mul ) Run ( input [ ] byte ) ( [ ] byte , error ) {
// Implements EIP-2537 G2MUL precompile logic.
// > G2 multiplication call expects `288` bytes as an input that is interpreted as byte concatenation of encoding of G2 point (`256` bytes) and encoding of a scalar value (`32` bytes).
// > Output is an encoding of multiplication operation result - single G2 point (`256` bytes).
if len ( input ) != 288 {
return nil , errBLS12381InvalidInputLength
}
var err error
2024-04-16 03:53:43 -05:00
var p0 * bls12381 . G2Affine
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode G2 point
2024-04-16 03:53:43 -05:00
if p0 , err = decodePointG2 ( input [ : 256 ] ) ; err != nil {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
return nil , err
}
2024-04-30 07:35:48 -05:00
// 'point is on curve' check already done,
// Here we need to apply subgroup checks.
if ! p0 . IsInSubGroup ( ) {
return nil , errBLS12381G2PointSubgroup
}
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode scalar value
e := new ( big . Int ) . SetBytes ( input [ 256 : ] )
// Compute r = e * p_0
2024-04-16 03:53:43 -05:00
r := new ( bls12381 . G2Affine )
r . ScalarMultiplication ( p0 , e )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Encode the G2 point into 256 bytes
2024-04-16 03:53:43 -05:00
return encodePointG2 ( r ) , nil
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// bls12381G2MultiExp implements EIP-2537 G2MultiExp precompile.
type bls12381G2MultiExp struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bls12381G2MultiExp ) RequiredGas ( input [ ] byte ) uint64 {
// Calculate G2 point, scalar value pair length
k := len ( input ) / 288
if k == 0 {
// Return 0 gas for small input length
return 0
}
// Lookup discount value for G2 point, scalar value pair length
2020-06-24 14:58:28 -05:00
var discount uint64
if dLen := len ( params . Bls12381MultiExpDiscountTable ) ; k < dLen {
discount = params . Bls12381MultiExpDiscountTable [ k - 1 ]
} else {
discount = params . Bls12381MultiExpDiscountTable [ dLen - 1 ]
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// Calculate gas and return the result
return ( uint64 ( k ) * params . Bls12381G2MulGas * discount ) / 1000
}
func ( c * bls12381G2MultiExp ) Run ( input [ ] byte ) ( [ ] byte , error ) {
// Implements EIP-2537 G2MultiExp precompile logic
// > G2 multiplication call expects `288*k` bytes as an input that is interpreted as byte concatenation of `k` slices each of them being a byte concatenation of encoding of G2 point (`256` bytes) and encoding of a scalar value (`32` bytes).
// > Output is an encoding of multiexponentiation operation result - single G2 point (`256` bytes).
k := len ( input ) / 288
if len ( input ) == 0 || len ( input ) % 288 != 0 {
return nil , errBLS12381InvalidInputLength
}
2024-04-16 03:53:43 -05:00
points := make ( [ ] bls12381 . G2Affine , k )
scalars := make ( [ ] fr . Element , k )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode point scalar pairs
for i := 0 ; i < k ; i ++ {
off := 288 * i
t0 , t1 , t2 := off , off + 256 , off + 288
2024-04-16 03:53:43 -05:00
// Decode G2 point
p , err := decodePointG2 ( input [ t0 : t1 ] )
if err != nil {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
return nil , err
}
2024-04-30 07:35:48 -05:00
// 'point is on curve' check already done,
// Here we need to apply subgroup checks.
if ! p . IsInSubGroup ( ) {
return nil , errBLS12381G2PointSubgroup
}
2024-04-16 03:53:43 -05:00
points [ i ] = * p
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode scalar value
2024-04-16 03:53:43 -05:00
scalars [ i ] = * new ( fr . Element ) . SetBytes ( input [ t1 : t2 ] )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// Compute r = e_0 * p_0 + e_1 * p_1 + ... + e_(k-1) * p_(k-1)
2024-04-16 03:53:43 -05:00
r := new ( bls12381 . G2Affine )
r . MultiExp ( points , scalars , ecc . MultiExpConfig { } )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Encode the G2 point to 256 bytes.
2024-04-16 03:53:43 -05:00
return encodePointG2 ( r ) , nil
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// bls12381Pairing implements EIP-2537 Pairing precompile.
type bls12381Pairing struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bls12381Pairing ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bls12381PairingBaseGas + uint64 ( len ( input ) / 384 ) * params . Bls12381PairingPerPairGas
}
func ( c * bls12381Pairing ) Run ( input [ ] byte ) ( [ ] byte , error ) {
// Implements EIP-2537 Pairing precompile logic.
// > Pairing call expects `384*k` bytes as an inputs that is interpreted as byte concatenation of `k` slices. Each slice has the following structure:
// > - `128` bytes of G1 point encoding
// > - `256` bytes of G2 point encoding
// > Output is a `32` bytes where last single byte is `0x01` if pairing result is equal to multiplicative identity in a pairing target field and `0x00` otherwise
// > (which is equivalent of Big Endian encoding of Solidity values `uint256(1)` and `uin256(0)` respectively).
k := len ( input ) / 384
if len ( input ) == 0 || len ( input ) % 384 != 0 {
return nil , errBLS12381InvalidInputLength
}
2024-04-16 03:53:43 -05:00
var (
p [ ] bls12381 . G1Affine
q [ ] bls12381 . G2Affine
)
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Decode pairs
for i := 0 ; i < k ; i ++ {
off := 384 * i
t0 , t1 , t2 := off , off + 128 , off + 384
// Decode G1 point
2024-04-16 03:53:43 -05:00
p1 , err := decodePointG1 ( input [ t0 : t1 ] )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
if err != nil {
return nil , err
}
// Decode G2 point
2024-04-16 03:53:43 -05:00
p2 , err := decodePointG2 ( input [ t1 : t2 ] )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
if err != nil {
return nil , err
}
// 'point is on curve' check already done,
// Here we need to apply subgroup checks.
2024-04-16 03:53:43 -05:00
if ! p1 . IsInSubGroup ( ) {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
return nil , errBLS12381G1PointSubgroup
}
2024-04-16 03:53:43 -05:00
if ! p2 . IsInSubGroup ( ) {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
return nil , errBLS12381G2PointSubgroup
}
2024-04-16 03:53:43 -05:00
p = append ( p , * p1 )
q = append ( q , * p2 )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// Prepare 32 byte output
out := make ( [ ] byte , 32 )
// Compute pairing and set the result
2024-04-16 03:53:43 -05:00
ok , err := bls12381 . PairingCheck ( p , q )
if err == nil && ok {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
out [ 31 ] = 1
}
return out , nil
}
2024-04-16 03:53:43 -05:00
func decodePointG1 ( in [ ] byte ) ( * bls12381 . G1Affine , error ) {
if len ( in ) != 128 {
return nil , errors . New ( "invalid g1 point length" )
}
// decode x
x , err := decodeBLS12381FieldElement ( in [ : 64 ] )
if err != nil {
return nil , err
}
// decode y
y , err := decodeBLS12381FieldElement ( in [ 64 : ] )
if err != nil {
return nil , err
}
elem := bls12381 . G1Affine { X : x , Y : y }
if ! elem . IsOnCurve ( ) {
return nil , errors . New ( "invalid point: not on curve" )
}
return & elem , nil
}
// decodePointG2 given encoded (x, y) coordinates in 256 bytes returns a valid G2 Point.
func decodePointG2 ( in [ ] byte ) ( * bls12381 . G2Affine , error ) {
if len ( in ) != 256 {
return nil , errors . New ( "invalid g2 point length" )
}
x0 , err := decodeBLS12381FieldElement ( in [ : 64 ] )
if err != nil {
return nil , err
}
x1 , err := decodeBLS12381FieldElement ( in [ 64 : 128 ] )
if err != nil {
return nil , err
}
y0 , err := decodeBLS12381FieldElement ( in [ 128 : 192 ] )
if err != nil {
return nil , err
}
y1 , err := decodeBLS12381FieldElement ( in [ 192 : ] )
if err != nil {
return nil , err
}
p := bls12381 . G2Affine { X : bls12381 . E2 { A0 : x0 , A1 : x1 } , Y : bls12381 . E2 { A0 : y0 , A1 : y1 } }
if ! p . IsOnCurve ( ) {
return nil , errors . New ( "invalid point: not on curve" )
}
return & p , err
}
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// decodeBLS12381FieldElement decodes BLS12-381 elliptic curve field element.
// Removes top 16 bytes of 64 byte input.
2024-04-16 03:53:43 -05:00
func decodeBLS12381FieldElement ( in [ ] byte ) ( fp . Element , error ) {
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
if len ( in ) != 64 {
2024-04-16 03:53:43 -05:00
return fp . Element { } , errors . New ( "invalid field element length" )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// check top bytes
for i := 0 ; i < 16 ; i ++ {
if in [ i ] != byte ( 0x00 ) {
2024-04-16 03:53:43 -05:00
return fp . Element { } , errBLS12381InvalidFieldElementTopBytes
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
}
2024-04-16 03:53:43 -05:00
var res [ 48 ] byte
copy ( res [ : ] , in [ 16 : ] )
return fp . BigEndian . Element ( & res )
}
// encodePointG1 encodes a point into 128 bytes.
func encodePointG1 ( p * bls12381 . G1Affine ) [ ] byte {
out := make ( [ ] byte , 128 )
fp . BigEndian . PutElement ( ( * [ fp . Bytes ] byte ) ( out [ 16 : ] ) , p . X )
fp . BigEndian . PutElement ( ( * [ fp . Bytes ] byte ) ( out [ 64 + 16 : ] ) , p . Y )
return out
}
// encodePointG2 encodes a point into 256 bytes.
func encodePointG2 ( p * bls12381 . G2Affine ) [ ] byte {
out := make ( [ ] byte , 256 )
// encode x
fp . BigEndian . PutElement ( ( * [ fp . Bytes ] byte ) ( out [ 16 : 16 + 48 ] ) , p . X . A0 )
fp . BigEndian . PutElement ( ( * [ fp . Bytes ] byte ) ( out [ 80 : 80 + 48 ] ) , p . X . A1 )
// encode y
fp . BigEndian . PutElement ( ( * [ fp . Bytes ] byte ) ( out [ 144 : 144 + 48 ] ) , p . Y . A0 )
fp . BigEndian . PutElement ( ( * [ fp . Bytes ] byte ) ( out [ 208 : 208 + 48 ] ) , p . Y . A1 )
return out
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// bls12381MapG1 implements EIP-2537 MapG1 precompile.
type bls12381MapG1 struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bls12381MapG1 ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bls12381MapG1Gas
}
func ( c * bls12381MapG1 ) Run ( input [ ] byte ) ( [ ] byte , error ) {
// Implements EIP-2537 Map_To_G1 precompile.
2024-04-15 01:34:31 -05:00
// > Field-to-curve call expects an `64` bytes input that is interpreted as an element of the base field.
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// > Output of this call is `128` bytes and is G1 point following respective encoding rules.
if len ( input ) != 64 {
return nil , errBLS12381InvalidInputLength
}
// Decode input field element
fe , err := decodeBLS12381FieldElement ( input )
if err != nil {
return nil , err
}
// Compute mapping
2024-04-16 03:53:43 -05:00
r := bls12381 . MapToG1 ( fe )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
2020-06-08 02:53:19 -05:00
// Encode the G1 point to 128 bytes
2024-04-16 03:53:43 -05:00
return encodePointG1 ( & r ) , nil
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
// bls12381MapG2 implements EIP-2537 MapG2 precompile.
type bls12381MapG2 struct { }
// RequiredGas returns the gas required to execute the pre-compiled contract.
func ( c * bls12381MapG2 ) RequiredGas ( input [ ] byte ) uint64 {
return params . Bls12381MapG2Gas
}
func ( c * bls12381MapG2 ) Run ( input [ ] byte ) ( [ ] byte , error ) {
// Implements EIP-2537 Map_FP2_TO_G2 precompile logic.
2024-04-15 01:34:31 -05:00
// > Field-to-curve call expects an `128` bytes input that is interpreted as an element of the quadratic extension field.
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// > Output of this call is `256` bytes and is G2 point following respective encoding rules.
if len ( input ) != 128 {
return nil , errBLS12381InvalidInputLength
}
// Decode input field element
c0 , err := decodeBLS12381FieldElement ( input [ : 64 ] )
if err != nil {
return nil , err
}
c1 , err := decodeBLS12381FieldElement ( input [ 64 : ] )
if err != nil {
return nil , err
}
// Compute mapping
2024-04-16 03:53:43 -05:00
r := bls12381 . MapToG2 ( bls12381 . E2 { A0 : c0 , A1 : c1 } )
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
// Encode the G2 point to 256 bytes
2024-04-16 03:53:43 -05:00
return encodePointG2 ( & r ) , nil
core/vm, crypto/bls12381, params: add bls12-381 elliptic curve precompiles (#21018)
* crypto: add bls12-381 elliptic curve wrapper
* params: add bls12-381 precompile gas parameters
* core/vm: add bls12-381 precompiles
* core/vm: add bls12-381 precompile tests
* go.mod, go.sum: use latest bls12381 lib
* core/vm: move point encode/decode functions to base library
* crypto/bls12381: introduce bls12-381 library init function
* crypto/bls12381: import bls12381 elliptic curve implementation
* go.mod, go.sum: remove bls12-381 library
* remove unsued frobenious coeffs
supress warning for inp that used in asm
* add mappings tests for zero inputs
fix swu g2 minus z inverse constant
* crypto/bls12381: fix typo
* crypto/bls12381: better comments for bls12381 constants
* crypto/bls12381: swu, use single conditional for e2
* crypto/bls12381: utils, delete empty line
* crypto/bls12381: utils, use FromHex for string to big
* crypto/bls12381: g1, g2, strict length check for FromBytes
* crypto/bls12381: field_element, comparision changes
* crypto/bls12381: change swu, isogeny constants with hex values
* core/vm: fix point multiplication comments
* core/vm: fix multiexp gas calculation and lookup for g1 and g2
* core/vm: simpler imput length check for multiexp and pairing precompiles
* core/vm: rm empty multiexp result declarations
* crypto/bls12381: remove modulus type definition
* crypto/bls12381: use proper init function
* crypto/bls12381: get rid of new lines at fatal desciprtions
* crypto/bls12-381: fix no-adx assembly multiplication
* crypto/bls12-381: remove old config function
* crypto/bls12381: update multiplication backend
this commit changes mul backend to 6limb eip1962 backend
mul assign operations are dropped
* core/vm/contracts_tests: externalize test vectors for precompiles
* core/vm/contracts_test: externalize failure-cases for precompiles
* core/vm: linting
* go.mod: tiny up sum file
* core/vm: fix goimports linter issues
* crypto/bls12381: build tags for plain ASM or ADX implementation
Co-authored-by: Martin Holst Swende <martin@swende.se>
Co-authored-by: Péter Szilágyi <peterke@gmail.com>
2020-06-03 01:44:32 -05:00
}
2023-06-05 08:43:25 -05:00
// kzgPointEvaluation implements the EIP-4844 point evaluation precompile.
type kzgPointEvaluation struct { }
// RequiredGas estimates the gas required for running the point evaluation precompile.
func ( b * kzgPointEvaluation ) RequiredGas ( input [ ] byte ) uint64 {
return params . BlobTxPointEvaluationPrecompileGas
}
const (
blobVerifyInputLength = 192 // Max input length for the point evaluation precompile.
blobCommitmentVersionKZG uint8 = 0x01 // Version byte for the point evaluation precompile.
blobPrecompileReturnValue = "000000000000000000000000000000000000000000000000000000000000100073eda753299d7d483339d80809a1d80553bda402fffe5bfeffffffff00000001"
)
var (
errBlobVerifyInvalidInputLength = errors . New ( "invalid input length" )
errBlobVerifyMismatchedVersion = errors . New ( "mismatched versioned hash" )
errBlobVerifyKZGProof = errors . New ( "error verifying kzg proof" )
)
// Run executes the point evaluation precompile.
func ( b * kzgPointEvaluation ) Run ( input [ ] byte ) ( [ ] byte , error ) {
if len ( input ) != blobVerifyInputLength {
return nil , errBlobVerifyInvalidInputLength
}
// versioned hash: first 32 bytes
var versionedHash common . Hash
copy ( versionedHash [ : ] , input [ : ] )
var (
point kzg4844 . Point
claim kzg4844 . Claim
)
// Evaluation point: next 32 bytes
copy ( point [ : ] , input [ 32 : ] )
// Expected output: next 32 bytes
copy ( claim [ : ] , input [ 64 : ] )
// input kzg point: next 48 bytes
var commitment kzg4844 . Commitment
copy ( commitment [ : ] , input [ 96 : ] )
if kZGToVersionedHash ( commitment ) != versionedHash {
return nil , errBlobVerifyMismatchedVersion
}
// Proof: next 48 bytes
var proof kzg4844 . Proof
copy ( proof [ : ] , input [ 144 : ] )
if err := kzg4844 . VerifyProof ( commitment , point , claim , proof ) ; err != nil {
return nil , fmt . Errorf ( "%w: %v" , errBlobVerifyKZGProof , err )
}
return common . Hex2Bytes ( blobPrecompileReturnValue ) , nil
}
// kZGToVersionedHash implements kzg_to_versioned_hash from EIP-4844
func kZGToVersionedHash ( kzg kzg4844 . Commitment ) common . Hash {
h := sha256 . Sum256 ( kzg [ : ] )
h [ 0 ] = blobCommitmentVersionKZG
return h
}