123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341(*****************************************************************************)(* *)(* Copyright (c) 2020-2021 Danny Willems <be.danny.willems@gmail.com> *)(* *)(* Permission is hereby granted, free of charge, to any person obtaining a *)(* copy of this software and associated documentation files (the "Software"),*)(* to deal in the Software without restriction, including without limitation *)(* the rights to use, copy, modify, merge, publish, distribute, sublicense, *)(* and/or sell copies of the Software, and to permit persons to whom the *)(* Software is furnished to do so, subject to the following conditions: *)(* *)(* The above copyright notice and this permission notice shall be included *)(* in all copies or substantial portions of the Software. *)(* *)(* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR*)(* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, *)(* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL *)(* THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER*)(* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING *)(* FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER *)(* DEALINGS IN THE SOFTWARE. *)(* *)(*****************************************************************************)moduleStubs=structtypeaffinetypejacobianexternalallocate_g2:unit->jacobian="allocate_p2_stubs"externalallocate_g2_affine:unit->affine="allocate_p2_affine_stubs"externalfrom_affine:jacobian->affine->unit="caml_blst_p2_from_affine_stubs"externalto_affine:affine->jacobian->unit="caml_blst_p2_to_affine_stubs"externaldouble:jacobian->jacobian->unit="caml_blst_p2_double_stubs"externaldadd:jacobian->jacobian->jacobian->unit="caml_blst_p2_add_or_double_stubs"externalis_zero:jacobian->bool="caml_blst_p2_is_inf_stubs"externalin_g2:jacobian->bool="caml_blst_p2_in_g2_stubs"externalequal:jacobian->jacobian->bool="caml_blst_p2_equal_stubs"externalcneg:jacobian->bool->unit="caml_blst_p2_cneg_stubs"externalmult:jacobian->jacobian->Bytes.t->Unsigned.Size_t.t->unit="caml_blst_p2_mult_stubs"externaldeserialize:affine->Bytes.t->int="caml_blst_p2_deserialize_stubs"externalserialize:Bytes.t->jacobian->unit="caml_blst_p2_serialize_stubs"externalcompress:Bytes.t->jacobian->unit="caml_blst_p2_compress_stubs"externaluncompress:affine->Bytes.t->int="caml_blst_p2_uncompress_stubs"externalhash_to_curve:jacobian->Bytes.t->Unsigned.Size_t.t->Bytes.t->Unsigned.Size_t.t->Bytes.t->Unsigned.Size_t.t->unit="caml_blst_p2_hash_to_curve_stubs_bytecode""caml_blst_p2_hash_to_curve_stubs"externalmemcpy:jacobian->jacobian->unit="caml_blst_p2_memcpy_stubs"externalset_affine_coordinates:affine->Fq2.t->Fq2.t->unit="caml_blst_p2_set_coordinates_stubs"externalfft_inplace:jacobianarray->Fr.Stubs.frarray->int->unit="caml_fft_g2_inplace_stubs"externalpippenger:jacobian->jacobianarray->Unsigned.Size_t.t->Fr.tarray->unit="caml_blst_g2_pippenger"externalmul_map_inplace:jacobianarray->Fr.Stubs.fr->int->unit="caml_mul_map_g2_inplace_stubs"endmoduleG2=structtypet=Stubs.jacobianexceptionNot_on_curveofBytes.tletsize_in_bytes=192letmemcpydstsrc=Stubs.memcpydstsrcletcopysrc=letdst=Stubs.allocate_g2()inmemcpydstsrc;dstletglobal_buffer=Stubs.allocate_g2()moduleScalar=Frletempty()=Stubs.allocate_g2()letcheck_bytesbs=letbuffer=Stubs.allocate_g2_affine()inStubs.deserializebufferbs=0letof_bytes_optbs=letbuffer_affine=Stubs.allocate_g2_affine()inifBytes.lengthbs<>size_in_bytesthenNoneelseletres=Stubs.deserializebuffer_affinebsinifres=0then(letbuffer=Stubs.allocate_g2()inStubs.from_affinebufferbuffer_affine;letis_in_prime_subgroup=Stubs.in_g2bufferinifis_in_prime_subgroupthenSomebufferelseNone)elseNoneletof_bytes_exnbs=matchof_bytes_optbswithNone->raise(Not_on_curvebs)|Somep->pletof_compressed_bytes_optbs=letbuffer_affine=Stubs.allocate_g2_affine()inletres=Stubs.uncompressbuffer_affinebsinifres=0then(letbuffer=Stubs.allocate_g2()inStubs.from_affinebufferbuffer_affine;letis_in_prime_subgroup=Stubs.in_g2bufferinifis_in_prime_subgroupthenSomebufferelseNone)elseNoneletof_compressed_bytes_exnbs=matchof_compressed_bytes_optbswith|None->raise(Not_on_curvebs)|Somep->pletzero=letbytes=Bytes.of_string"\192\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000"inof_compressed_bytes_exnbytesletone=letbytes=Bytes.of_string"\147\224+`Rq\159`}\172\211\160\136'OeYk\208\208\153 \
\182\026\181\218a\187\220\127PI3L\241\018\019\148]W\229\172}\005]\004+~\002J\162\178\240\143\n\
\145&\b\005'-\197\016Q\198\228z\212\250@;\
\002\180Q\011dz\227\209w\011\172\003&\168\005\187\239\212\128V\200\193!\189\184"inof_compressed_bytes_exnbytesletto_bytesp=letbuffer=Bytes.makesize_in_bytes'\000'inStubs.serializebufferp;bufferletto_compressed_bytesp=letbuffer=Bytes.make(size_in_bytes/2)'\000'inStubs.compressbufferp;bufferletaddxy=(* dadd must be used to be complete. add does not work when it is the same
point
*)letbuffer=Stubs.allocate_g2()inStubs.daddbufferxy;bufferletadd_inplacexy=Stubs.daddglobal_bufferxy;memcpyxglobal_bufferletadd_bulkxs=letbuffer=Stubs.allocate_g2()inList.iter(funx->Stubs.daddbufferbufferx)xs;bufferletdoublex=letbuffer=Stubs.allocate_g2()inStubs.doublebufferx;bufferletmul_bitsgbytes=letbuffer=Stubs.allocate_g2()inStubs.multbuffergbytes(Unsigned.Size_t.of_int(Bytes.lengthbytes*8));bufferletmulgn=letbytes=Fr.to_bytesninmul_bitsgbytesletmul_inplacegn=letbytes=Fr.to_bytesninStubs.multglobal_buffergbytes(Unsigned.Size_t.of_int(Bytes.lengthbytes*8));memcpygglobal_bufferletb=letbuffer=Fq2.Stubs.allocate_fp2()inletfq_four=Fq.(one+one+one+one)inletbytes=Fq.to_bytesfq_fourinFq2.Stubs.of_bytes_componentsbufferbytesbytes;bufferletclear_cofactorp=letbytes=Z.of_string_base16"5d543a95414e7f1091d50792876a202cd91de4547085abaa68a205b2e5a7ddfa628f1cb4d9e82ef21537e293a6691ae1616ec6e786f0c70cf1c38e31c7238e5"inletbytes=Bytes.of_string(Z.to_bitsbytes)inletres=mul_bitspbytesinresletrecrandom?state()=(matchstatewithNone->()|Somestate->Random.set_statestate);letx=Fq2.random()inletxx=Fq2.(x*x)inletxxx=Fq2.(x*xx)inletxxx_plus_b=Fq2.(xxx+b)inlety_opt=Fq2.sqrt_optxxx_plus_binmatchy_optwith|None->random()|Somey->lety=ifRandom.bool()thenyelseFq2.negateyin(* Printf.printf *)(* "x = %s\ny = %s\n" *)(* Hex.(show (Hex.of_bytes (Fq2.to_bytes x))) *)(* Hex.(show (Hex.of_bytes (Fq2.to_bytes y))) ; *)letp_affine=Stubs.allocate_g2_affine()inStubs.set_affine_coordinatesp_affinexy;letp=Stubs.allocate_g2()inStubs.from_affinepp_affine;(* Printf.printf "Serialized: %s\n" (Hex.show (Hex.of_bytes (to_bytes p))) ; *)letp=clear_cofactorpinpleteqg1g2=Stubs.equalg1g2letis_zerox=eqxzeroletorder_minus_one=Scalar.(negateone)letnegateg=letbuffer=copyginStubs.cnegbuffertrue;bufferletof_z_opt~x~y=let(x1,x2)=xinlet(y1,y2)=yinletx1_bytes=Bytes.of_string(Z.to_bitsx1)inletx2_bytes=Bytes.of_string(Z.to_bitsx2)inlety1_bytes=Bytes.of_string(Z.to_bitsy1)inlety2_bytes=Bytes.of_string(Z.to_bitsy2)inletx=Fq2.Stubs.allocate_fp2()inlety=Fq2.Stubs.allocate_fp2()inFq2.Stubs.of_bytes_componentsxx1_bytesx2_bytes;Fq2.Stubs.of_bytes_componentsyy1_bytesy2_bytes;letp_affine=Stubs.allocate_g2_affine()inStubs.set_affine_coordinatesp_affinexy;letp=Stubs.allocate_g2()inStubs.from_affinepp_affine;letis_ok=Stubs.in_g2pinifis_okthenSomepelseNonemoduleM=structtypegroup=ttypescalar=Scalar.tletzero=zeroletinverse_exn_scalar=Scalar.inverse_exnletscalar_of_z=Scalar.of_zletfft_inplace=Stubs.fft_inplaceletmul_map_inplace=Stubs.mul_map_inplaceletcopy=copyendletfft~domain~points=Fft.fft(moduleM)~domain~pointsletifft~domain~points=Fft.ifft(moduleM)~domain~pointsletfft_inplace~domain~points=letlogn=Z.log2(Z.of_int(Array.lengthpoints))inStubs.fft_inplacepointsdomainlognletifft_inplace~domain~points=letn=Array.lengthpointsinletlogn=Z.log2(Z.of_intn)inletn_inv=Fr.inverse_exn(Fr.of_z(Z.of_intn))inStubs.fft_inplacepointsdomainlogn;Stubs.mul_map_inplacepointsn_invnlethash_to_curvemessagedst=letmessage_length=Bytes.lengthmessageinletdst_length=Bytes.lengthdstinletbuffer=Stubs.allocate_g2()inStubs.hash_to_curvebuffermessage(Unsigned.Size_t.of_intmessage_length)dst(Unsigned.Size_t.of_intdst_length)Bytes.emptyUnsigned.Size_t.zero;bufferletpippengerpsss=letn=Array.lengthpsinifn=1thenmulps.(0)ss.(0)elseletbuffer=Stubs.allocate_g2()inStubs.pippengerbufferps(Unsigned.Size_t.of_intn)ss;bufferendincludeG2