test_check.c 380 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139414041414142414341444145414641474148414941504151415241534154415541564157415841594160416141624163416441654166416741684169417041714172417341744175417641774178417941804181418241834184418541864187418841894190419141924193419441954196419741984199420042014202420342044205420642074208420942104211421242134214421542164217421842194220422142224223422442254226422742284229423042314232423342344235423642374238423942404241424242434244424542464247424842494250425142524253425442554256425742584259426042614262426342644265426642674268426942704271427242734274427542764277427842794280428142824283428442854286428742884289429042914292429342944295429642974298429943004301430243034304430543064307430843094310431143124313431443154316431743184319432043214322432343244325432643274328432943304331433243334334433543364337433843394340434143424343434443454346434743484349435043514352435343544355435643574358435943604361436243634364436543664367436843694370437143724373437443754376437743784379438043814382438343844385438643874388438943904391439243934394439543964397439843994400440144024403440444054406440744084409441044114412441344144415441644174418441944204421442244234424442544264427442844294430443144324433443444354436443744384439444044414442444344444445444644474448444944504451445244534454445544564457445844594460446144624463446444654466446744684469447044714472447344744475447644774478447944804481448244834484448544864487448844894490449144924493449444954496449744984499450045014502450345044505450645074508450945104511451245134514451545164517451845194520452145224523452445254526452745284529453045314532453345344535453645374538453945404541454245434544454545464547454845494550455145524553455445554556455745584559456045614562456345644565456645674568456945704571457245734574457545764577457845794580458145824583458445854586458745884589459045914592459345944595459645974598459946004601460246034604460546064607460846094610461146124613461446154616461746184619462046214622462346244625462646274628462946304631463246334634463546364637463846394640464146424643464446454646464746484649465046514652465346544655465646574658465946604661466246634664466546664667466846694670467146724673467446754676467746784679468046814682468346844685468646874688468946904691469246934694469546964697469846994700470147024703470447054706470747084709471047114712471347144715471647174718471947204721472247234724472547264727472847294730473147324733473447354736473747384739474047414742474347444745474647474748474947504751475247534754475547564757475847594760476147624763476447654766476747684769477047714772477347744775477647774778477947804781478247834784478547864787478847894790479147924793479447954796479747984799480048014802480348044805480648074808480948104811481248134814481548164817481848194820482148224823482448254826482748284829483048314832483348344835483648374838483948404841484248434844484548464847484848494850485148524853485448554856485748584859486048614862486348644865486648674868486948704871487248734874487548764877487848794880488148824883488448854886488748884889489048914892489348944895489648974898489949004901490249034904490549064907490849094910491149124913491449154916491749184919492049214922492349244925492649274928492949304931493249334934493549364937493849394940494149424943494449454946494749484949495049514952495349544955495649574958495949604961496249634964496549664967496849694970497149724973497449754976497749784979498049814982498349844985498649874988498949904991499249934994499549964997499849995000500150025003500450055006500750085009501050115012501350145015501650175018501950205021502250235024502550265027502850295030503150325033503450355036503750385039504050415042504350445045504650475048504950505051505250535054505550565057505850595060506150625063506450655066506750685069507050715072507350745075507650775078507950805081508250835084508550865087508850895090509150925093509450955096509750985099510051015102510351045105510651075108510951105111511251135114511551165117511851195120512151225123512451255126512751285129513051315132513351345135513651375138513951405141514251435144514551465147514851495150515151525153515451555156515751585159516051615162516351645165516651675168516951705171517251735174517551765177517851795180518151825183518451855186518751885189519051915192519351945195519651975198519952005201520252035204520552065207520852095210521152125213521452155216521752185219522052215222522352245225522652275228522952305231523252335234523552365237523852395240524152425243524452455246524752485249525052515252525352545255525652575258525952605261526252635264526552665267526852695270527152725273527452755276527752785279528052815282528352845285528652875288528952905291529252935294529552965297529852995300530153025303530453055306530753085309531053115312531353145315531653175318531953205321532253235324532553265327532853295330533153325333533453355336533753385339534053415342534353445345534653475348534953505351535253535354535553565357535853595360536153625363536453655366536753685369537053715372537353745375537653775378537953805381538253835384538553865387538853895390539153925393539453955396539753985399540054015402540354045405540654075408540954105411541254135414541554165417541854195420542154225423542454255426542754285429543054315432543354345435543654375438543954405441544254435444544554465447544854495450545154525453545454555456545754585459546054615462546354645465546654675468546954705471547254735474547554765477547854795480548154825483548454855486548754885489549054915492549354945495549654975498549955005501550255035504550555065507550855095510551155125513551455155516551755185519552055215522552355245525552655275528552955305531553255335534553555365537553855395540554155425543554455455546554755485549555055515552555355545555555655575558555955605561556255635564556555665567556855695570557155725573557455755576557755785579558055815582558355845585558655875588558955905591559255935594559555965597559855995600560156025603560456055606560756085609561056115612561356145615561656175618561956205621562256235624562556265627562856295630563156325633563456355636563756385639564056415642564356445645564656475648564956505651565256535654565556565657565856595660566156625663566456655666566756685669567056715672567356745675567656775678567956805681568256835684568556865687568856895690569156925693569456955696569756985699570057015702570357045705570657075708570957105711571257135714571557165717571857195720572157225723572457255726572757285729573057315732573357345735573657375738573957405741574257435744574557465747574857495750575157525753575457555756575757585759576057615762576357645765576657675768576957705771577257735774577557765777577857795780578157825783578457855786578757885789579057915792579357945795579657975798579958005801580258035804580558065807580858095810581158125813581458155816581758185819582058215822582358245825582658275828582958305831583258335834583558365837583858395840584158425843584458455846584758485849585058515852585358545855585658575858585958605861586258635864586558665867586858695870587158725873587458755876587758785879588058815882588358845885588658875888588958905891589258935894589558965897589858995900590159025903590459055906590759085909591059115912591359145915591659175918591959205921592259235924592559265927592859295930593159325933593459355936593759385939594059415942594359445945594659475948594959505951595259535954595559565957595859595960596159625963596459655966596759685969597059715972597359745975597659775978597959805981598259835984598559865987598859895990599159925993599459955996599759985999600060016002600360046005600660076008600960106011601260136014601560166017601860196020602160226023602460256026602760286029603060316032603360346035603660376038603960406041604260436044604560466047604860496050605160526053605460556056605760586059606060616062606360646065606660676068606960706071607260736074607560766077607860796080608160826083608460856086608760886089609060916092609360946095609660976098609961006101610261036104610561066107610861096110611161126113611461156116611761186119612061216122612361246125612661276128612961306131613261336134613561366137613861396140614161426143614461456146614761486149615061516152615361546155615661576158615961606161616261636164616561666167616861696170617161726173617461756176617761786179618061816182618361846185618661876188618961906191619261936194619561966197619861996200620162026203620462056206620762086209621062116212621362146215621662176218621962206221622262236224622562266227622862296230623162326233623462356236623762386239624062416242624362446245624662476248624962506251625262536254625562566257625862596260626162626263626462656266626762686269627062716272627362746275627662776278627962806281628262836284628562866287628862896290629162926293629462956296629762986299630063016302630363046305630663076308630963106311631263136314631563166317631863196320632163226323632463256326632763286329633063316332633363346335633663376338633963406341634263436344634563466347634863496350635163526353635463556356635763586359636063616362636363646365636663676368636963706371637263736374637563766377637863796380638163826383638463856386638763886389639063916392639363946395639663976398639964006401640264036404640564066407640864096410641164126413641464156416641764186419642064216422642364246425642664276428642964306431643264336434643564366437643864396440644164426443644464456446644764486449645064516452645364546455645664576458645964606461646264636464646564666467646864696470647164726473647464756476647764786479648064816482648364846485648664876488648964906491649264936494649564966497649864996500650165026503650465056506650765086509651065116512651365146515651665176518651965206521652265236524652565266527652865296530653165326533653465356536653765386539654065416542654365446545654665476548654965506551655265536554655565566557655865596560656165626563656465656566656765686569657065716572657365746575657665776578657965806581658265836584658565866587658865896590659165926593659465956596659765986599660066016602660366046605660666076608660966106611661266136614661566166617661866196620662166226623662466256626662766286629663066316632663366346635663666376638663966406641664266436644664566466647664866496650665166526653665466556656665766586659666066616662666366646665666666676668666966706671667266736674667566766677667866796680668166826683668466856686668766886689669066916692669366946695669666976698669967006701670267036704670567066707670867096710671167126713671467156716671767186719672067216722672367246725672667276728672967306731673267336734673567366737673867396740674167426743674467456746674767486749675067516752675367546755675667576758675967606761676267636764676567666767676867696770677167726773677467756776677767786779678067816782678367846785678667876788678967906791679267936794679567966797679867996800680168026803680468056806680768086809681068116812681368146815681668176818681968206821682268236824682568266827682868296830683168326833683468356836683768386839684068416842684368446845684668476848684968506851685268536854685568566857685868596860686168626863686468656866686768686869687068716872687368746875687668776878687968806881688268836884688568866887688868896890689168926893689468956896689768986899690069016902690369046905690669076908690969106911691269136914691569166917691869196920692169226923692469256926692769286929693069316932693369346935693669376938693969406941694269436944694569466947694869496950695169526953695469556956695769586959696069616962696369646965696669676968696969706971697269736974697569766977697869796980698169826983698469856986698769886989699069916992699369946995699669976998699970007001700270037004700570067007700870097010701170127013701470157016701770187019702070217022702370247025702670277028702970307031703270337034703570367037703870397040704170427043704470457046704770487049705070517052705370547055705670577058705970607061706270637064706570667067706870697070707170727073707470757076707770787079708070817082708370847085708670877088708970907091709270937094709570967097709870997100710171027103710471057106710771087109711071117112711371147115711671177118711971207121712271237124712571267127712871297130713171327133713471357136713771387139714071417142714371447145714671477148714971507151715271537154715571567157715871597160716171627163716471657166716771687169717071717172717371747175717671777178717971807181718271837184718571867187718871897190719171927193719471957196719771987199720072017202720372047205720672077208720972107211721272137214721572167217721872197220722172227223722472257226722772287229723072317232723372347235723672377238723972407241724272437244724572467247724872497250725172527253725472557256725772587259726072617262726372647265726672677268726972707271727272737274727572767277727872797280728172827283728472857286728772887289729072917292729372947295729672977298729973007301730273037304730573067307730873097310731173127313731473157316731773187319732073217322732373247325732673277328732973307331733273337334733573367337733873397340734173427343734473457346734773487349735073517352735373547355735673577358735973607361736273637364736573667367736873697370737173727373737473757376737773787379738073817382738373847385738673877388738973907391739273937394739573967397739873997400740174027403740474057406740774087409741074117412741374147415741674177418741974207421742274237424742574267427742874297430743174327433743474357436743774387439744074417442744374447445744674477448744974507451745274537454745574567457745874597460746174627463746474657466746774687469747074717472747374747475747674777478747974807481748274837484748574867487748874897490749174927493749474957496749774987499750075017502750375047505750675077508750975107511751275137514751575167517751875197520752175227523752475257526752775287529753075317532753375347535753675377538753975407541754275437544754575467547754875497550755175527553755475557556755775587559756075617562756375647565756675677568756975707571757275737574757575767577757875797580758175827583758475857586758775887589759075917592759375947595759675977598759976007601760276037604760576067607760876097610761176127613761476157616761776187619762076217622762376247625762676277628762976307631763276337634763576367637763876397640764176427643764476457646764776487649765076517652765376547655765676577658765976607661766276637664766576667667766876697670767176727673767476757676767776787679768076817682768376847685768676877688768976907691769276937694769576967697769876997700770177027703770477057706770777087709771077117712771377147715771677177718771977207721772277237724772577267727772877297730773177327733773477357736773777387739774077417742774377447745774677477748774977507751775277537754775577567757775877597760776177627763776477657766776777687769777077717772777377747775777677777778777977807781778277837784778577867787778877897790779177927793779477957796779777987799780078017802780378047805780678077808780978107811781278137814781578167817781878197820782178227823782478257826782778287829783078317832783378347835783678377838783978407841784278437844784578467847784878497850785178527853785478557856785778587859786078617862786378647865786678677868786978707871787278737874787578767877787878797880788178827883788478857886788778887889789078917892789378947895789678977898789979007901790279037904790579067907790879097910791179127913791479157916791779187919792079217922792379247925792679277928792979307931793279337934793579367937793879397940794179427943794479457946794779487949795079517952795379547955795679577958795979607961796279637964796579667967796879697970797179727973797479757976797779787979798079817982798379847985798679877988798979907991799279937994799579967997799879998000800180028003800480058006800780088009801080118012801380148015801680178018801980208021802280238024802580268027802880298030803180328033803480358036803780388039804080418042804380448045804680478048804980508051805280538054805580568057805880598060806180628063806480658066806780688069807080718072807380748075807680778078807980808081808280838084808580868087808880898090809180928093809480958096809780988099810081018102810381048105810681078108810981108111811281138114811581168117811881198120812181228123812481258126812781288129813081318132813381348135813681378138813981408141814281438144814581468147814881498150815181528153815481558156815781588159816081618162816381648165816681678168816981708171817281738174817581768177817881798180818181828183818481858186818781888189819081918192819381948195819681978198819982008201820282038204820582068207820882098210821182128213821482158216821782188219822082218222822382248225822682278228822982308231823282338234823582368237823882398240824182428243824482458246824782488249825082518252825382548255825682578258825982608261826282638264826582668267826882698270827182728273827482758276827782788279828082818282828382848285828682878288828982908291829282938294829582968297829882998300830183028303830483058306830783088309831083118312831383148315831683178318831983208321832283238324832583268327832883298330833183328333833483358336833783388339834083418342834383448345834683478348834983508351835283538354835583568357835883598360836183628363836483658366836783688369837083718372837383748375837683778378837983808381838283838384838583868387838883898390839183928393839483958396839783988399840084018402840384048405840684078408840984108411841284138414841584168417841884198420842184228423842484258426842784288429843084318432843384348435843684378438843984408441844284438444844584468447844884498450845184528453845484558456845784588459846084618462846384648465846684678468846984708471847284738474847584768477847884798480848184828483848484858486848784888489849084918492849384948495849684978498849985008501850285038504850585068507850885098510851185128513851485158516851785188519852085218522852385248525852685278528852985308531853285338534853585368537853885398540854185428543854485458546854785488549855085518552855385548555855685578558855985608561856285638564856585668567856885698570857185728573857485758576857785788579858085818582858385848585858685878588858985908591859285938594859585968597859885998600860186028603860486058606860786088609861086118612861386148615861686178618861986208621862286238624862586268627862886298630863186328633863486358636863786388639864086418642864386448645864686478648864986508651865286538654865586568657865886598660866186628663866486658666866786688669867086718672867386748675867686778678867986808681868286838684868586868687868886898690869186928693869486958696869786988699870087018702870387048705870687078708870987108711871287138714871587168717871887198720872187228723872487258726872787288729873087318732873387348735873687378738873987408741874287438744874587468747874887498750875187528753875487558756875787588759876087618762876387648765876687678768876987708771877287738774877587768777877887798780878187828783878487858786878787888789879087918792879387948795879687978798879988008801880288038804880588068807880888098810881188128813881488158816881788188819882088218822882388248825882688278828882988308831883288338834883588368837883888398840884188428843884488458846884788488849885088518852885388548855885688578858885988608861886288638864886588668867886888698870887188728873887488758876887788788879888088818882888388848885888688878888888988908891889288938894889588968897889888998900890189028903890489058906890789088909891089118912891389148915891689178918891989208921892289238924892589268927892889298930893189328933893489358936893789388939894089418942894389448945894689478948894989508951895289538954895589568957895889598960896189628963896489658966896789688969897089718972897389748975897689778978897989808981898289838984898589868987898889898990899189928993899489958996899789988999900090019002900390049005900690079008900990109011901290139014901590169017901890199020902190229023902490259026902790289029903090319032903390349035903690379038903990409041904290439044904590469047904890499050905190529053905490559056905790589059906090619062906390649065906690679068906990709071907290739074907590769077907890799080908190829083908490859086908790889089909090919092909390949095909690979098909991009101910291039104910591069107910891099110911191129113911491159116911791189119912091219122912391249125912691279128912991309131913291339134913591369137913891399140914191429143914491459146914791489149915091519152915391549155915691579158915991609161916291639164916591669167916891699170917191729173917491759176917791789179918091819182918391849185918691879188918991909191919291939194919591969197919891999200920192029203920492059206920792089209921092119212921392149215921692179218921992209221922292239224922592269227922892299230923192329233923492359236923792389239924092419242924392449245924692479248924992509251925292539254925592569257925892599260926192629263926492659266926792689269927092719272927392749275927692779278927992809281928292839284928592869287928892899290929192929293929492959296929792989299930093019302930393049305930693079308930993109311931293139314931593169317931893199320932193229323932493259326932793289329933093319332933393349335933693379338933993409341934293439344934593469347934893499350935193529353935493559356935793589359936093619362936393649365936693679368936993709371937293739374937593769377937893799380938193829383938493859386938793889389939093919392939393949395939693979398939994009401940294039404940594069407940894099410941194129413941494159416941794189419942094219422942394249425942694279428942994309431943294339434943594369437943894399440944194429443944494459446944794489449945094519452945394549455945694579458945994609461946294639464946594669467946894699470947194729473947494759476947794789479948094819482948394849485948694879488948994909491949294939494949594969497949894999500950195029503950495059506950795089509951095119512951395149515951695179518951995209521952295239524952595269527952895299530953195329533953495359536953795389539954095419542954395449545954695479548954995509551955295539554955595569557955895599560956195629563956495659566956795689569957095719572957395749575957695779578957995809581958295839584958595869587958895899590959195929593959495959596959795989599960096019602960396049605960696079608960996109611961296139614961596169617961896199620962196229623962496259626962796289629963096319632963396349635963696379638963996409641964296439644964596469647964896499650965196529653965496559656965796589659966096619662966396649665966696679668966996709671967296739674967596769677967896799680968196829683968496859686968796889689969096919692969396949695969696979698969997009701970297039704970597069707970897099710971197129713971497159716971797189719972097219722972397249725972697279728972997309731973297339734973597369737973897399740974197429743974497459746974797489749975097519752975397549755975697579758975997609761976297639764976597669767976897699770977197729773977497759776977797789779978097819782978397849785978697879788978997909791979297939794979597969797979897999800980198029803980498059806980798089809981098119812981398149815
  1. /**
  2. * Copyright (c) 2013-2014 Tomas Dzetkulic
  3. * Copyright (c) 2013-2014 Pavol Rusnak
  4. *
  5. * Permission is hereby granted, free of charge, to any person obtaining
  6. * a copy of this software and associated documentation files (the "Software"),
  7. * to deal in the Software without restriction, including without limitation
  8. * the rights to use, copy, modify, merge, publish, distribute, sublicense,
  9. * and/or sell copies of the Software, and to permit persons to whom the
  10. * Software is furnished to do so, subject to the following conditions:
  11. *
  12. * The above copyright notice and this permission notice shall be included
  13. * in all copies or substantial portions of the Software.
  14. *
  15. * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
  16. * OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
  17. * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
  18. * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES
  19. * OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
  20. * ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR
  21. * OTHER DEALINGS IN THE SOFTWARE.
  22. */
  23. #include <assert.h>
  24. #include <check.h>
  25. #include <inttypes.h>
  26. #include <stdint.h>
  27. #include <stdio.h>
  28. #include <stdlib.h>
  29. #include <string.h>
  30. #include <time.h>
  31. #include "check_mem.h"
  32. #ifdef VALGRIND
  33. #include <valgrind/memcheck.h>
  34. #include <valgrind/valgrind.h>
  35. #endif
  36. #include "options.h"
  37. #include "address.h"
  38. #include "aes/aes.h"
  39. #include "base32.h"
  40. #include "base58.h"
  41. #include "bignum.h"
  42. #include "bip32.h"
  43. #include "bip39.h"
  44. #include "blake256.h"
  45. #include "blake2b.h"
  46. #include "blake2s.h"
  47. #include "cardano.h"
  48. #include "chacha_drbg.h"
  49. #include "curves.h"
  50. #include "ecdsa.h"
  51. #include "ed25519-donna/ed25519-donna.h"
  52. #include "ed25519-donna/ed25519-keccak.h"
  53. #include "ed25519-donna/ed25519.h"
  54. #include "hmac_drbg.h"
  55. #include "memzero.h"
  56. #include "monero/monero.h"
  57. #include "nem.h"
  58. #include "nist256p1.h"
  59. #include "pbkdf2.h"
  60. #include "rand.h"
  61. #include "rc4.h"
  62. #include "rfc6979.h"
  63. #include "script.h"
  64. #include "secp256k1.h"
  65. #include "sha2.h"
  66. #include "sha3.h"
  67. #include "shamir.h"
  68. #include "slip39.h"
  69. #include "slip39_wordlist.h"
  70. #include "zkp_bip340.h"
  71. #include "zkp_context.h"
  72. #include "zkp_ecdsa.h"
  73. #ifdef VALGRIND
  74. /*
  75. * This is a clever trick to make Valgrind's Memcheck verify code
  76. * is constant-time with respect to secret data.
  77. */
  78. /* Call after secret data is written, before first use */
  79. #define MARK_SECRET_DATA(addr, len) VALGRIND_MAKE_MEM_UNDEFINED(addr, len)
  80. /* Call before secret data is freed or to mark non-secret data (public keys or
  81. * signatures) */
  82. #define UNMARK_SECRET_DATA(addr, len) VALGRIND_MAKE_MEM_DEFINED(addr, len)
  83. #else
  84. #define MARK_SECRET_DATA(addr, len)
  85. #define UNMARK_SECRET_DATA(addr, len)
  86. #endif
  87. #define FROMHEX_MAXLEN 512
  88. #define VERSION_PUBLIC 0x0488b21e
  89. #define VERSION_PRIVATE 0x0488ade4
  90. #define DECRED_VERSION_PUBLIC 0x02fda926
  91. #define DECRED_VERSION_PRIVATE 0x02fda4e8
  92. const uint8_t *fromhex(const char *str) {
  93. static uint8_t buf[FROMHEX_MAXLEN];
  94. size_t len = strlen(str) / 2;
  95. if (len > FROMHEX_MAXLEN) len = FROMHEX_MAXLEN;
  96. for (size_t i = 0; i < len; i++) {
  97. uint8_t c = 0;
  98. if (str[i * 2] >= '0' && str[i * 2] <= '9') c += (str[i * 2] - '0') << 4;
  99. if ((str[i * 2] & ~0x20) >= 'A' && (str[i * 2] & ~0x20) <= 'F')
  100. c += (10 + (str[i * 2] & ~0x20) - 'A') << 4;
  101. if (str[i * 2 + 1] >= '0' && str[i * 2 + 1] <= '9')
  102. c += (str[i * 2 + 1] - '0');
  103. if ((str[i * 2 + 1] & ~0x20) >= 'A' && (str[i * 2 + 1] & ~0x20) <= 'F')
  104. c += (10 + (str[i * 2 + 1] & ~0x20) - 'A');
  105. buf[i] = c;
  106. }
  107. return buf;
  108. }
  109. void nem_private_key(const char *reversed_hex, ed25519_secret_key private_key) {
  110. const uint8_t *reversed_key = fromhex(reversed_hex);
  111. for (size_t j = 0; j < sizeof(ed25519_secret_key); j++) {
  112. private_key[j] = reversed_key[sizeof(ed25519_secret_key) - j - 1];
  113. }
  114. }
  115. START_TEST(test_bignum_read_be) {
  116. bignum256 a;
  117. uint8_t input[32];
  118. memcpy(
  119. input,
  120. fromhex(
  121. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd5"),
  122. 32);
  123. bn_read_be(input, &a);
  124. bignum256 b = {{0x086d8bd5, 0x1018f82f, 0x11a8bb07, 0x0bc3f7af, 0x0437cd3b,
  125. 0x14087f0a, 0x15498fe5, 0x10b161bb, 0xc55ece}};
  126. for (int i = 0; i < 9; i++) {
  127. ck_assert_uint_eq(a.val[i], b.val[i]);
  128. }
  129. }
  130. END_TEST
  131. START_TEST(test_bignum_write_be) {
  132. bignum256 a = {{0x086d8bd5, 0x1018f82f, 0x11a8bb07, 0x0bc3f7af, 0x0437cd3b,
  133. 0x14087f0a, 0x15498fe5, 0x10b161bb, 0xc55ece}};
  134. uint8_t tmp[32];
  135. bn_write_be(&a, tmp);
  136. ck_assert_mem_eq(
  137. tmp,
  138. fromhex(
  139. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd5"),
  140. 32);
  141. }
  142. END_TEST
  143. START_TEST(test_bignum_is_equal) {
  144. bignum256 a = {{0x086d8bd5, 0x1018f82f, 0x11a8bb07, 0x0bc3f7af, 0x0437cd3b,
  145. 0x14087f0a, 0x15498fe5, 0x10b161bb, 0xc55ece}};
  146. bignum256 b = {{0x086d8bd5, 0x1018f82f, 0x11a8bb07, 0x0bc3f7af, 0x0437cd3b,
  147. 0x14087f0a, 0x15498fe5, 0x10b161bb, 0xc55ece}};
  148. bignum256 c = {{
  149. 0,
  150. }};
  151. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  152. ck_assert_int_eq(bn_is_equal(&c, &c), 1);
  153. ck_assert_int_eq(bn_is_equal(&a, &c), 0);
  154. }
  155. END_TEST
  156. START_TEST(test_bignum_zero) {
  157. bignum256 a;
  158. bignum256 b;
  159. bn_read_be(
  160. fromhex(
  161. "0000000000000000000000000000000000000000000000000000000000000000"),
  162. &a);
  163. bn_zero(&b);
  164. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  165. }
  166. END_TEST
  167. START_TEST(test_bignum_is_zero) {
  168. bignum256 a;
  169. bn_read_be(
  170. fromhex(
  171. "0000000000000000000000000000000000000000000000000000000000000000"),
  172. &a);
  173. ck_assert_int_eq(bn_is_zero(&a), 1);
  174. bn_read_be(
  175. fromhex(
  176. "0000000000000000000000000000000000000000000000000000000000000001"),
  177. &a);
  178. ck_assert_int_eq(bn_is_zero(&a), 0);
  179. bn_read_be(
  180. fromhex(
  181. "1000000000000000000000000000000000000000000000000000000000000000"),
  182. &a);
  183. ck_assert_int_eq(bn_is_zero(&a), 0);
  184. bn_read_be(
  185. fromhex(
  186. "f000000000000000000000000000000000000000000000000000000000000000"),
  187. &a);
  188. ck_assert_int_eq(bn_is_zero(&a), 0);
  189. }
  190. END_TEST
  191. START_TEST(test_bignum_one) {
  192. bignum256 a;
  193. bignum256 b;
  194. bn_read_be(
  195. fromhex(
  196. "0000000000000000000000000000000000000000000000000000000000000001"),
  197. &a);
  198. bn_one(&b);
  199. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  200. }
  201. END_TEST
  202. START_TEST(test_bignum_read_le) {
  203. bignum256 a;
  204. bignum256 b;
  205. bn_read_be(
  206. fromhex(
  207. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd5"),
  208. &a);
  209. bn_read_le(
  210. fromhex(
  211. "d58b6de8051f031eeca2c6d7fbe1b5d37c4314fe1068f96352dd0d8b85ce5ec5"),
  212. &b);
  213. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  214. }
  215. END_TEST
  216. START_TEST(test_bignum_write_le) {
  217. bignum256 a;
  218. bignum256 b;
  219. uint8_t tmp[32];
  220. bn_read_be(
  221. fromhex(
  222. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd5"),
  223. &a);
  224. bn_write_le(&a, tmp);
  225. bn_read_le(tmp, &b);
  226. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  227. bn_read_be(
  228. fromhex(
  229. "d58b6de8051f031eeca2c6d7fbe1b5d37c4314fe1068f96352dd0d8b85ce5ec5"),
  230. &a);
  231. bn_read_be(tmp, &b);
  232. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  233. }
  234. END_TEST
  235. START_TEST(test_bignum_read_uint32) {
  236. bignum256 a;
  237. bignum256 b;
  238. // lowest 30 bits set
  239. bn_read_be(
  240. fromhex(
  241. "000000000000000000000000000000000000000000000000000000003fffffff"),
  242. &a);
  243. bn_read_uint32(0x3fffffff, &b);
  244. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  245. // bit 31 set
  246. bn_read_be(
  247. fromhex(
  248. "0000000000000000000000000000000000000000000000000000000040000000"),
  249. &a);
  250. bn_read_uint32(0x40000000, &b);
  251. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  252. }
  253. END_TEST
  254. START_TEST(test_bignum_read_uint64) {
  255. bignum256 a;
  256. bignum256 b;
  257. // lowest 30 bits set
  258. bn_read_be(
  259. fromhex(
  260. "000000000000000000000000000000000000000000000000000000003fffffff"),
  261. &a);
  262. bn_read_uint64(0x3fffffff, &b);
  263. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  264. // bit 31 set
  265. bn_read_be(
  266. fromhex(
  267. "0000000000000000000000000000000000000000000000000000000040000000"),
  268. &a);
  269. bn_read_uint64(0x40000000, &b);
  270. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  271. // bit 33 set
  272. bn_read_be(
  273. fromhex(
  274. "0000000000000000000000000000000000000000000000000000000100000000"),
  275. &a);
  276. bn_read_uint64(0x100000000LL, &b);
  277. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  278. // bit 61 set
  279. bn_read_be(
  280. fromhex(
  281. "0000000000000000000000000000000000000000000000002000000000000000"),
  282. &a);
  283. bn_read_uint64(0x2000000000000000LL, &b);
  284. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  285. // all 64 bits set
  286. bn_read_be(
  287. fromhex(
  288. "000000000000000000000000000000000000000000000000ffffffffffffffff"),
  289. &a);
  290. bn_read_uint64(0xffffffffffffffffLL, &b);
  291. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  292. }
  293. END_TEST
  294. START_TEST(test_bignum_write_uint32) {
  295. bignum256 a;
  296. // lowest 29 bits set
  297. bn_read_be(
  298. fromhex(
  299. "000000000000000000000000000000000000000000000000000000001fffffff"),
  300. &a);
  301. ck_assert_uint_eq(bn_write_uint32(&a), 0x1fffffff);
  302. // lowest 30 bits set
  303. bn_read_be(
  304. fromhex(
  305. "000000000000000000000000000000000000000000000000000000003fffffff"),
  306. &a);
  307. ck_assert_uint_eq(bn_write_uint32(&a), 0x3fffffff);
  308. // bit 31 set
  309. bn_read_be(
  310. fromhex(
  311. "0000000000000000000000000000000000000000000000000000000040000000"),
  312. &a);
  313. ck_assert_uint_eq(bn_write_uint32(&a), 0x40000000);
  314. }
  315. END_TEST
  316. START_TEST(test_bignum_write_uint64) {
  317. bignum256 a;
  318. // lowest 30 bits set
  319. bn_read_be(
  320. fromhex(
  321. "000000000000000000000000000000000000000000000000000000003fffffff"),
  322. &a);
  323. ck_assert_uint_eq(bn_write_uint64(&a), 0x3fffffff);
  324. // bit 31 set
  325. bn_read_be(
  326. fromhex(
  327. "0000000000000000000000000000000000000000000000000000000040000000"),
  328. &a);
  329. ck_assert_uint_eq(bn_write_uint64(&a), 0x40000000);
  330. // bit 33 set
  331. bn_read_be(
  332. fromhex(
  333. "0000000000000000000000000000000000000000000000000000000100000000"),
  334. &a);
  335. ck_assert_uint_eq(bn_write_uint64(&a), 0x100000000LL);
  336. // bit 61 set
  337. bn_read_be(
  338. fromhex(
  339. "0000000000000000000000000000000000000000000000002000000000000000"),
  340. &a);
  341. ck_assert_uint_eq(bn_write_uint64(&a), 0x2000000000000000LL);
  342. // all 64 bits set
  343. bn_read_be(
  344. fromhex(
  345. "000000000000000000000000000000000000000000000000ffffffffffffffff"),
  346. &a);
  347. ck_assert_uint_eq(bn_write_uint64(&a), 0xffffffffffffffffLL);
  348. }
  349. END_TEST
  350. START_TEST(test_bignum_copy) {
  351. bignum256 a;
  352. bignum256 b;
  353. bn_read_be(
  354. fromhex(
  355. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd5"),
  356. &a);
  357. bn_copy(&a, &b);
  358. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  359. }
  360. END_TEST
  361. START_TEST(test_bignum_is_even) {
  362. bignum256 a;
  363. bn_read_be(
  364. fromhex(
  365. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd5"),
  366. &a);
  367. ck_assert_int_eq(bn_is_even(&a), 0);
  368. bn_read_be(
  369. fromhex(
  370. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd2"),
  371. &a);
  372. ck_assert_int_eq(bn_is_even(&a), 1);
  373. bn_read_be(
  374. fromhex(
  375. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd0"),
  376. &a);
  377. ck_assert_int_eq(bn_is_even(&a), 1);
  378. }
  379. END_TEST
  380. START_TEST(test_bignum_is_odd) {
  381. bignum256 a;
  382. bn_read_be(
  383. fromhex(
  384. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd5"),
  385. &a);
  386. ck_assert_int_eq(bn_is_odd(&a), 1);
  387. bn_read_be(
  388. fromhex(
  389. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd2"),
  390. &a);
  391. ck_assert_int_eq(bn_is_odd(&a), 0);
  392. bn_read_be(
  393. fromhex(
  394. "c55ece858b0ddd5263f96810fe14437cd3b5e1fbd7c6a2ec1e031f05e86d8bd0"),
  395. &a);
  396. ck_assert_int_eq(bn_is_odd(&a), 0);
  397. }
  398. END_TEST
  399. START_TEST(test_bignum_is_less) {
  400. bignum256 a;
  401. bignum256 b;
  402. bn_read_uint32(0x1234, &a);
  403. bn_read_uint32(0x8765, &b);
  404. ck_assert_int_eq(bn_is_less(&a, &b), 1);
  405. ck_assert_int_eq(bn_is_less(&b, &a), 0);
  406. bn_zero(&a);
  407. bn_read_be(
  408. fromhex(
  409. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  410. &b);
  411. ck_assert_int_eq(bn_is_less(&a, &b), 1);
  412. ck_assert_int_eq(bn_is_less(&b, &a), 0);
  413. }
  414. END_TEST
  415. START_TEST(test_bignum_bitcount) {
  416. bignum256 a, b;
  417. bn_zero(&a);
  418. ck_assert_int_eq(bn_bitcount(&a), 0);
  419. bn_one(&a);
  420. ck_assert_int_eq(bn_bitcount(&a), 1);
  421. // test for 10000 and 11111 when i=5
  422. for (int i = 2; i <= 256; i++) {
  423. bn_one(&a);
  424. bn_one(&b);
  425. for (int j = 2; j <= i; j++) {
  426. bn_lshift(&a);
  427. bn_lshift(&b);
  428. bn_addi(&b, 1);
  429. }
  430. ck_assert_int_eq(bn_bitcount(&a), i);
  431. ck_assert_int_eq(bn_bitcount(&b), i);
  432. }
  433. bn_read_uint32(0x3fffffff, &a);
  434. ck_assert_int_eq(bn_bitcount(&a), 30);
  435. bn_read_uint32(0xffffffff, &a);
  436. ck_assert_int_eq(bn_bitcount(&a), 32);
  437. bn_read_be(
  438. fromhex(
  439. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  440. &a);
  441. ck_assert_int_eq(bn_bitcount(&a), 256);
  442. }
  443. END_TEST
  444. START_TEST(test_bignum_digitcount) {
  445. bignum256 a;
  446. bn_zero(&a);
  447. ck_assert_int_eq(bn_digitcount(&a), 1);
  448. // test for (10^i) and (10^i) - 1
  449. uint64_t m = 1;
  450. for (int i = 0; i <= 19; i++, m *= 10) {
  451. bn_read_uint64(m, &a);
  452. ck_assert_int_eq(bn_digitcount(&a), i + 1);
  453. uint64_t n = m - 1;
  454. bn_read_uint64(n, &a);
  455. ck_assert_int_eq(bn_digitcount(&a), n == 0 ? 1 : i);
  456. }
  457. bn_read_uint32(0x3fffffff, &a);
  458. ck_assert_int_eq(bn_digitcount(&a), 10);
  459. bn_read_uint32(0xffffffff, &a);
  460. ck_assert_int_eq(bn_digitcount(&a), 10);
  461. bn_read_be(
  462. fromhex(
  463. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  464. &a);
  465. ck_assert_int_eq(bn_digitcount(&a), 78);
  466. }
  467. END_TEST
  468. START_TEST(test_bignum_format_uint64) {
  469. char buf[128], str[128];
  470. size_t r;
  471. // test for (10^i) and (10^i) - 1
  472. uint64_t m = 1;
  473. for (int i = 0; i <= 19; i++, m *= 10) {
  474. sprintf(str, "%" PRIu64, m);
  475. r = bn_format_uint64(m, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  476. ck_assert_uint_eq(r, strlen(str));
  477. ck_assert_str_eq(buf, str);
  478. uint64_t n = m - 1;
  479. sprintf(str, "%" PRIu64, n);
  480. r = bn_format_uint64(n, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  481. ck_assert_uint_eq(r, strlen(str));
  482. ck_assert_str_eq(buf, str);
  483. }
  484. }
  485. END_TEST
  486. START_TEST(test_bignum_format) {
  487. bignum256 a;
  488. char buf[128];
  489. size_t r;
  490. bn_read_be(
  491. fromhex(
  492. "0000000000000000000000000000000000000000000000000000000000000000"),
  493. &a);
  494. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  495. ck_assert_uint_eq(r, 1);
  496. ck_assert_str_eq(buf, "0");
  497. bn_read_be(
  498. fromhex(
  499. "0000000000000000000000000000000000000000000000000000000000000000"),
  500. &a);
  501. r = bn_format(&a, NULL, NULL, 20, 0, true, 0, buf, sizeof(buf));
  502. ck_assert_uint_eq(r, 22);
  503. ck_assert_str_eq(buf, "0.00000000000000000000");
  504. bn_read_be(
  505. fromhex(
  506. "0000000000000000000000000000000000000000000000000000000000000000"),
  507. &a);
  508. r = bn_format(&a, NULL, NULL, 0, 5, false, 0, buf, sizeof(buf));
  509. ck_assert_uint_eq(r, 1);
  510. ck_assert_str_eq(buf, "0");
  511. bn_read_be(
  512. fromhex(
  513. "0000000000000000000000000000000000000000000000000000000000000000"),
  514. &a);
  515. r = bn_format(&a, NULL, NULL, 0, -5, false, 0, buf, sizeof(buf));
  516. ck_assert_uint_eq(r, 1);
  517. ck_assert_str_eq(buf, "0");
  518. bn_read_be(
  519. fromhex(
  520. "0000000000000000000000000000000000000000000000000000000000000000"),
  521. &a);
  522. r = bn_format(&a, "", "", 0, 0, false, 0, buf, sizeof(buf));
  523. ck_assert_uint_eq(r, 1);
  524. ck_assert_str_eq(buf, "0");
  525. bn_read_be(
  526. fromhex(
  527. "0000000000000000000000000000000000000000000000000000000000000000"),
  528. &a);
  529. r = bn_format(&a, NULL, "SFFX", 0, 0, false, 0, buf, sizeof(buf));
  530. ck_assert_uint_eq(r, 1 + 4);
  531. ck_assert_str_eq(buf, "0SFFX");
  532. bn_read_be(
  533. fromhex(
  534. "0000000000000000000000000000000000000000000000000000000000000000"),
  535. &a);
  536. r = bn_format(&a, "PRFX", NULL, 0, 0, false, 0, buf, sizeof(buf));
  537. ck_assert_uint_eq(r, 4 + 1);
  538. ck_assert_str_eq(buf, "PRFX0");
  539. bn_read_be(
  540. fromhex(
  541. "0000000000000000000000000000000000000000000000000000000000000000"),
  542. &a);
  543. r = bn_format(&a, "PRFX", "SFFX", 0, 0, false, 0, buf, sizeof(buf));
  544. ck_assert_uint_eq(r, 4 + 1 + 4);
  545. ck_assert_str_eq(buf, "PRFX0SFFX");
  546. bn_read_be(
  547. fromhex(
  548. "0000000000000000000000000000000000000000000000000000000000000000"),
  549. &a);
  550. r = bn_format(&a, NULL, NULL, 18, 0, false, 0, buf, sizeof(buf));
  551. ck_assert_uint_eq(r, 1);
  552. ck_assert_str_eq(buf, "0");
  553. bn_read_be(
  554. fromhex(
  555. "0000000000000000000000000000000000000000000000000000000000000001"),
  556. &a);
  557. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  558. ck_assert_uint_eq(r, 1);
  559. ck_assert_str_eq(buf, "1");
  560. bn_read_be(
  561. fromhex(
  562. "0000000000000000000000000000000000000000000000000000000000000001"),
  563. &a);
  564. r = bn_format(&a, NULL, NULL, 6, 6, true, 0, buf, sizeof(buf));
  565. ck_assert_uint_eq(r, 8);
  566. ck_assert_str_eq(buf, "1.000000");
  567. bn_read_be(
  568. fromhex(
  569. "0000000000000000000000000000000000000000000000000000000000000001"),
  570. &a);
  571. r = bn_format(&a, NULL, NULL, 1, 5, true, 0, buf, sizeof(buf));
  572. ck_assert_uint_eq(r, 7);
  573. ck_assert_str_eq(buf, "10000.0");
  574. bn_read_be(
  575. fromhex(
  576. "0000000000000000000000000000000000000000000000000000000000000001"),
  577. &a);
  578. r = bn_format(&a, NULL, NULL, 1, 5, true, ',', buf, sizeof(buf));
  579. ck_assert_uint_eq(r, 8);
  580. ck_assert_str_eq(buf, "10,000.0");
  581. bn_read_be(
  582. fromhex(
  583. "000000000000000000000000000000000000000000000000000000000001e240"),
  584. &a);
  585. r = bn_format(&a, NULL, NULL, 0, 0, true, ',', buf, sizeof(buf));
  586. ck_assert_uint_eq(r, 7);
  587. ck_assert_str_eq(buf, "123,456");
  588. bn_read_be(
  589. fromhex(
  590. "000000000000000000000000000000000000000000000000000000000001e240"),
  591. &a);
  592. r = bn_format(&a, NULL, NULL, 0, 1, true, ',', buf, sizeof(buf));
  593. ck_assert_uint_eq(r, 9);
  594. ck_assert_str_eq(buf, "1,234,560");
  595. bn_read_be(
  596. fromhex(
  597. "000000000000000000000000000000000000000000000000000000000001e240"),
  598. &a);
  599. r = bn_format(&a, NULL, NULL, 0, 5, true, ',', buf, sizeof(buf));
  600. ck_assert_uint_eq(r, 14);
  601. ck_assert_str_eq(buf, "12,345,600,000");
  602. bn_read_be(
  603. fromhex(
  604. "0000000000000000000000000000000000000000000000000000000000000002"),
  605. &a);
  606. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  607. ck_assert_uint_eq(r, 1);
  608. ck_assert_str_eq(buf, "2");
  609. bn_read_be(
  610. fromhex(
  611. "0000000000000000000000000000000000000000000000000000000000000005"),
  612. &a);
  613. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  614. ck_assert_uint_eq(r, 1);
  615. ck_assert_str_eq(buf, "5");
  616. bn_read_be(
  617. fromhex(
  618. "0000000000000000000000000000000000000000000000000000000000000009"),
  619. &a);
  620. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  621. ck_assert_uint_eq(r, 1);
  622. ck_assert_str_eq(buf, "9");
  623. bn_read_be(
  624. fromhex(
  625. "000000000000000000000000000000000000000000000000000000000000000a"),
  626. &a);
  627. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  628. ck_assert_uint_eq(r, 2);
  629. ck_assert_str_eq(buf, "10");
  630. bn_read_be(
  631. fromhex(
  632. "0000000000000000000000000000000000000000000000000000000000000014"),
  633. &a);
  634. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  635. ck_assert_uint_eq(r, 2);
  636. ck_assert_str_eq(buf, "20");
  637. bn_read_be(
  638. fromhex(
  639. "0000000000000000000000000000000000000000000000000000000000000032"),
  640. &a);
  641. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  642. ck_assert_uint_eq(r, 2);
  643. ck_assert_str_eq(buf, "50");
  644. bn_read_be(
  645. fromhex(
  646. "0000000000000000000000000000000000000000000000000000000000000063"),
  647. &a);
  648. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  649. ck_assert_uint_eq(r, 2);
  650. ck_assert_str_eq(buf, "99");
  651. bn_read_be(
  652. fromhex(
  653. "0000000000000000000000000000000000000000000000000000000000000064"),
  654. &a);
  655. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  656. ck_assert_uint_eq(r, 3);
  657. ck_assert_str_eq(buf, "100");
  658. bn_read_be(
  659. fromhex(
  660. "00000000000000000000000000000000000000000000000000000000000000c8"),
  661. &a);
  662. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  663. ck_assert_uint_eq(r, 3);
  664. ck_assert_str_eq(buf, "200");
  665. bn_read_be(
  666. fromhex(
  667. "00000000000000000000000000000000000000000000000000000000000001f4"),
  668. &a);
  669. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  670. ck_assert_uint_eq(r, 3);
  671. ck_assert_str_eq(buf, "500");
  672. bn_read_be(
  673. fromhex(
  674. "00000000000000000000000000000000000000000000000000000000000003e7"),
  675. &a);
  676. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  677. ck_assert_uint_eq(r, 3);
  678. ck_assert_str_eq(buf, "999");
  679. bn_read_be(
  680. fromhex(
  681. "00000000000000000000000000000000000000000000000000000000000003e8"),
  682. &a);
  683. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  684. ck_assert_uint_eq(r, 4);
  685. ck_assert_str_eq(buf, "1000");
  686. bn_read_be(
  687. fromhex(
  688. "00000000000000000000000000000000000000000000000000000000000003e8"),
  689. &a);
  690. r = bn_format(&a, NULL, NULL, 0, 0, false, ',', buf, sizeof(buf));
  691. ck_assert_uint_eq(r, 5);
  692. ck_assert_str_eq(buf, "1,000");
  693. bn_read_be(
  694. fromhex(
  695. "0000000000000000000000000000000000000000000000000000000000989680"),
  696. &a);
  697. r = bn_format(&a, NULL, NULL, 7, 0, false, 0, buf, sizeof(buf));
  698. ck_assert_uint_eq(r, 1);
  699. ck_assert_str_eq(buf, "1");
  700. bn_read_be(
  701. fromhex(
  702. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  703. &a);
  704. r = bn_format(&a, NULL, NULL, 0, 0, false, 0, buf, sizeof(buf));
  705. ck_assert_uint_eq(r, 78);
  706. ck_assert_str_eq(buf,
  707. "11579208923731619542357098500868790785326998466564056403945"
  708. "7584007913129639935");
  709. bn_read_be(
  710. fromhex(
  711. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  712. &a);
  713. r = bn_format(&a, NULL, NULL, 1, 0, false, 0, buf, sizeof(buf));
  714. ck_assert_uint_eq(r, 79);
  715. ck_assert_str_eq(buf,
  716. "11579208923731619542357098500868790785326998466564056403945"
  717. "758400791312963993.5");
  718. bn_read_be(
  719. fromhex(
  720. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  721. &a);
  722. r = bn_format(&a, NULL, NULL, 2, 0, false, 0, buf, sizeof(buf));
  723. ck_assert_uint_eq(r, 79);
  724. ck_assert_str_eq(buf,
  725. "11579208923731619542357098500868790785326998466564056403945"
  726. "75840079131296399.35");
  727. bn_read_be(
  728. fromhex(
  729. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  730. &a);
  731. r = bn_format(&a, NULL, NULL, 8, 0, false, 0, buf, sizeof(buf));
  732. ck_assert_uint_eq(r, 79);
  733. ck_assert_str_eq(buf,
  734. "11579208923731619542357098500868790785326998466564056403945"
  735. "75840079131.29639935");
  736. bn_read_be(
  737. fromhex(
  738. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  739. &a);
  740. r = bn_format(&a, NULL, NULL, 9, 0, false, ',', buf, sizeof(buf));
  741. ck_assert_uint_eq(r, 101);
  742. ck_assert_str_eq(
  743. buf,
  744. "115,792,089,237,316,195,423,570,985,008,687,907,853,269,984,"
  745. "665,640,564,039,457,584,007,913.129639935");
  746. bn_read_be(
  747. fromhex(
  748. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  749. &a);
  750. r = bn_format(&a, NULL, NULL, 9, 0, false, ' ', buf, sizeof(buf));
  751. ck_assert_uint_eq(r, 101);
  752. ck_assert_str_eq(
  753. buf,
  754. "115 792 089 237 316 195 423 570 985 008 687 907 853 269 984 "
  755. "665 640 564 039 457 584 007 913.129639935");
  756. bn_read_be(
  757. fromhex(
  758. "fffffffffffffffffffffffffffffffffffffffffffffffffffffffffe3bbb00"),
  759. &a);
  760. r = bn_format(&a, NULL, NULL, 8, 0, false, 0, buf, sizeof(buf));
  761. ck_assert_uint_eq(r, 70);
  762. ck_assert_str_eq(buf,
  763. "11579208923731619542357098500868790785326998466564056403945"
  764. "75840079131");
  765. bn_read_be(
  766. fromhex(
  767. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  768. &a);
  769. r = bn_format(&a, NULL, NULL, 18, 0, false, 0, buf, sizeof(buf));
  770. ck_assert_uint_eq(r, 79);
  771. ck_assert_str_eq(buf,
  772. "11579208923731619542357098500868790785326998466564056403945"
  773. "7.584007913129639935");
  774. bn_read_be(
  775. fromhex(
  776. "fffffffffffffffffffffffffffffffffffffffffffffffff7e52fe5afe40000"),
  777. &a);
  778. r = bn_format(&a, NULL, NULL, 18, 0, false, 0, buf, sizeof(buf));
  779. ck_assert_uint_eq(r, 60);
  780. ck_assert_str_eq(
  781. buf, "115792089237316195423570985008687907853269984665640564039457");
  782. bn_read_be(
  783. fromhex(
  784. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  785. &a);
  786. r = bn_format(&a, NULL, NULL, 78, 0, false, 0, buf, sizeof(buf));
  787. ck_assert_uint_eq(r, 80);
  788. ck_assert_str_eq(buf,
  789. "0."
  790. "11579208923731619542357098500868790785326998466564056403945"
  791. "7584007913129639935");
  792. bn_read_be(
  793. fromhex(
  794. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  795. &a);
  796. r = bn_format(&a, NULL, NULL, 0, 10, false, 0, buf, sizeof(buf));
  797. ck_assert_uint_eq(r, 88);
  798. ck_assert_str_eq(buf,
  799. "11579208923731619542357098500868790785326998466564056403945"
  800. "75840079131296399350000000000");
  801. bn_read_be(
  802. fromhex(
  803. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  804. &a);
  805. r = bn_format(&a, "quite a long prefix", "even longer suffix", 60, 0, false,
  806. 0, buf, sizeof(buf));
  807. ck_assert_uint_eq(r, 116);
  808. ck_assert_str_eq(buf,
  809. "quite a long "
  810. "prefix115792089237316195."
  811. "42357098500868790785326998466564056403945758400791312963993"
  812. "5even longer suffix");
  813. bn_read_be(
  814. fromhex(
  815. "0000000000000000000000000000000000000000000000000123456789abcdef"),
  816. &a);
  817. memset(buf, 'a', sizeof(buf));
  818. r = bn_format(&a, "prefix", "suffix", 10, 0, false, 0, buf, 31);
  819. ck_assert_str_eq(buf, "prefix8198552.9216486895suffix");
  820. ck_assert_uint_eq(r, 30);
  821. memset(buf, 'a', sizeof(buf));
  822. r = bn_format(&a, "prefix", "suffix", 10, 0, false, 0, buf, 30);
  823. ck_assert_uint_eq(r, 0);
  824. ck_assert_str_eq(buf, "");
  825. }
  826. END_TEST
  827. START_TEST(test_bignum_sqrt) {
  828. uint32_t quadratic_residua[] = {
  829. 1, 2, 4, 8, 9, 11, 15, 16, 17, 18, 19, 21, 22, 25, 29,
  830. 30, 31, 32, 34, 35, 36, 38, 39, 42, 43, 44, 47, 49, 50, 58,
  831. 59, 60, 61, 62, 64, 65, 67, 68, 69, 70, 71, 72, 76, 78, 81,
  832. 83, 84, 86, 88, 91, 94, 98, 99, 100, 103, 107, 111, 115, 116, 118,
  833. 120, 121, 122, 123, 124, 127, 128, 130, 131, 134, 135, 136, 137, 138, 139,
  834. 140, 142, 144, 149, 152, 153, 156, 159, 161, 162, 165, 166, 167, 168, 169,
  835. 171, 172, 176, 181, 182, 185, 187, 188, 189, 191, 193, 196, 197, 198, 200,
  836. 205, 206, 209, 214, 219, 222, 223, 225, 229, 230, 231, 232, 233, 236, 237,
  837. 239, 240, 242, 244, 246, 248, 254, 255, 256, 259, 260, 261, 262, 265, 267,
  838. 268, 269, 270, 272, 274, 275, 276, 277, 278, 279, 280, 281, 284, 285, 287,
  839. 288, 289, 291, 293, 298, 299, 303, 304, 306, 311, 312, 315, 318, 319, 322,
  840. 323, 324, 327, 330, 331, 332, 334, 336, 337, 338, 339, 341, 342, 344, 349,
  841. 351, 352, 353, 357, 359, 361, 362, 364, 365, 370, 371, 373, 374, 375, 376,
  842. 378, 379, 382, 383, 385, 386, 387, 389, 392, 394, 395, 396, 399, 400, 409,
  843. 410, 412, 418, 421, 423, 425, 428, 429, 431, 435, 438, 439, 441, 443, 444,
  844. 445, 446, 450, 453, 458, 460, 461, 462, 463, 464, 465, 466, 467, 471, 472,
  845. 473, 474, 475, 478, 479, 480, 481, 484, 485, 487, 488, 489, 492, 493, 496,
  846. 503, 505, 508, 510, 511, 512, 517, 518, 519, 520, 521, 522, 523, 524, 525,
  847. 527, 529, 530, 531, 533, 534, 536, 537, 538, 539, 540, 541, 544, 545, 547,
  848. 548, 549, 550, 551, 552, 553, 554, 556, 557, 558, 560, 562, 563, 565, 568,
  849. 570, 571, 574, 576, 578, 582, 585, 586, 587, 589, 595, 596, 597, 598, 599,
  850. 603, 606, 607, 608, 609, 612, 613, 619, 621, 622, 623, 624, 625, 630, 633,
  851. 636, 638, 639, 644, 645, 646, 648, 649, 651, 653, 654, 660, 662, 663, 664,
  852. 665, 668, 671, 672, 673, 674, 676, 678, 679, 681, 682, 684, 688, 689, 698,
  853. 702, 704, 705, 706, 707, 714, 715, 718, 722, 723, 724, 725, 728, 729, 730,
  854. 731, 733, 735, 737, 740, 741, 742, 746, 747, 748, 750, 751, 752, 753, 755,
  855. 756, 758, 759, 761, 763, 764, 766, 769, 770, 771, 772, 774, 775, 778, 781,
  856. 784, 785, 788, 789, 790, 791, 792, 797, 798, 799, 800, 813, 815, 817, 818,
  857. 819, 820, 823, 824, 833, 836, 841, 842, 846, 849, 850, 851, 856, 857, 858,
  858. 862, 865, 870, 875, 876, 878, 882, 885, 886, 887, 888, 890, 891, 892, 893,
  859. 895, 899, 900, 903, 906, 907, 911, 913, 915, 916, 919, 920, 921, 922, 924,
  860. 926, 927, 928, 930, 931, 932, 934, 937, 939, 942, 943, 944, 946, 948, 949,
  861. 950, 951, 953, 956, 958, 960, 961, 962, 963, 968, 970, 971, 974, 975, 976,
  862. 977, 978, 984, 986, 987, 992, 995, 999};
  863. bignum256 a, b;
  864. bn_zero(&a);
  865. b = a;
  866. bn_sqrt(&b, &secp256k1.prime);
  867. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  868. bn_one(&a);
  869. b = a;
  870. bn_sqrt(&b, &secp256k1.prime);
  871. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  872. // test some quadratic residua
  873. for (size_t i = 0; i < sizeof(quadratic_residua) / sizeof(*quadratic_residua);
  874. i++) {
  875. bn_read_uint32(quadratic_residua[i], &a);
  876. b = a;
  877. bn_sqrt(&b, &secp256k1.prime);
  878. bn_multiply(&b, &b, &secp256k1.prime);
  879. bn_mod(&b, &secp256k1.prime);
  880. ck_assert_int_eq(bn_is_equal(&a, &b), 1);
  881. }
  882. }
  883. END_TEST
  884. // https://tools.ietf.org/html/rfc4648#section-10
  885. START_TEST(test_base32_rfc4648) {
  886. static const struct {
  887. const char *decoded;
  888. const char *encoded;
  889. const char *encoded_lowercase;
  890. } tests[] = {
  891. {"", "", ""},
  892. {"f", "MY", "my"},
  893. {"fo", "MZXQ", "mzxq"},
  894. {"foo", "MZXW6", "mzxw6"},
  895. {"foob", "MZXW6YQ", "mzxw6yq"},
  896. {"fooba", "MZXW6YTB", "mzxw6ytb"},
  897. {"foobar", "MZXW6YTBOI", "mzxw6ytboi"},
  898. };
  899. char buffer[64];
  900. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  901. const char *in = tests[i].decoded;
  902. const char *out = tests[i].encoded;
  903. const char *out_lowercase = tests[i].encoded_lowercase;
  904. size_t inlen = strlen(in);
  905. size_t outlen = strlen(out);
  906. ck_assert_uint_eq(outlen, base32_encoded_length(inlen));
  907. ck_assert_uint_eq(inlen, base32_decoded_length(outlen));
  908. ck_assert(base32_encode((uint8_t *)in, inlen, buffer, sizeof(buffer),
  909. BASE32_ALPHABET_RFC4648) != NULL);
  910. ck_assert_str_eq(buffer, out);
  911. char *ret = (char *)base32_decode(out, outlen, (uint8_t *)buffer,
  912. sizeof(buffer), BASE32_ALPHABET_RFC4648);
  913. ck_assert(ret != NULL);
  914. *ret = '\0';
  915. ck_assert_str_eq(buffer, in);
  916. ret = (char *)base32_decode(out_lowercase, outlen, (uint8_t *)buffer,
  917. sizeof(buffer), BASE32_ALPHABET_RFC4648);
  918. ck_assert(ret != NULL);
  919. *ret = '\0';
  920. ck_assert_str_eq(buffer, in);
  921. }
  922. }
  923. END_TEST
  924. // from
  925. // https://github.com/bitcoin/bitcoin/blob/master/src/test/data/base58_keys_valid.json
  926. START_TEST(test_base58) {
  927. static const char *base58_vector[] = {
  928. "0065a16059864a2fdbc7c99a4723a8395bc6f188eb",
  929. "1AGNa15ZQXAZUgFiqJ2i7Z2DPU2J6hW62i",
  930. "0574f209f6ea907e2ea48f74fae05782ae8a665257",
  931. "3CMNFxN1oHBc4R1EpboAL5yzHGgE611Xou",
  932. "6f53c0307d6851aa0ce7825ba883c6bd9ad242b486",
  933. "mo9ncXisMeAoXwqcV5EWuyncbmCcQN4rVs",
  934. "c46349a418fc4578d10a372b54b45c280cc8c4382f",
  935. "2N2JD6wb56AfK4tfmM6PwdVmoYk2dCKf4Br",
  936. "80eddbdc1168f1daeadbd3e44c1e3f8f5a284c2029f78ad26af98583a499de5b19",
  937. "5Kd3NBUAdUnhyzenEwVLy9pBKxSwXvE9FMPyR4UKZvpe6E3AgLr",
  938. "8055c9bccb9ed68446d1b75273bbce89d7fe013a8acd1625514420fb2aca1a21c401",
  939. "Kz6UJmQACJmLtaQj5A3JAge4kVTNQ8gbvXuwbmCj7bsaabudb3RD",
  940. "ef36cb93b9ab1bdabf7fb9f2c04f1b9cc879933530ae7842398eef5a63a56800c2",
  941. "9213qJab2HNEpMpYNBa7wHGFKKbkDn24jpANDs2huN3yi4J11ko",
  942. "efb9f4892c9e8282028fea1d2667c4dc5213564d41fc5783896a0d843fc15089f301",
  943. "cTpB4YiyKiBcPxnefsDpbnDxFDffjqJob8wGCEDXxgQ7zQoMXJdH",
  944. "006d23156cbbdcc82a5a47eee4c2c7c583c18b6bf4",
  945. "1Ax4gZtb7gAit2TivwejZHYtNNLT18PUXJ",
  946. "05fcc5460dd6e2487c7d75b1963625da0e8f4c5975",
  947. "3QjYXhTkvuj8qPaXHTTWb5wjXhdsLAAWVy",
  948. "6ff1d470f9b02370fdec2e6b708b08ac431bf7a5f7",
  949. "n3ZddxzLvAY9o7184TB4c6FJasAybsw4HZ",
  950. "c4c579342c2c4c9220205e2cdc285617040c924a0a",
  951. "2NBFNJTktNa7GZusGbDbGKRZTxdK9VVez3n",
  952. "80a326b95ebae30164217d7a7f57d72ab2b54e3be64928a19da0210b9568d4015e",
  953. "5K494XZwps2bGyeL71pWid4noiSNA2cfCibrvRWqcHSptoFn7rc",
  954. "807d998b45c219a1e38e99e7cbd312ef67f77a455a9b50c730c27f02c6f730dfb401",
  955. "L1RrrnXkcKut5DEMwtDthjwRcTTwED36thyL1DebVrKuwvohjMNi",
  956. "efd6bca256b5abc5602ec2e1c121a08b0da2556587430bcf7e1898af2224885203",
  957. "93DVKyFYwSN6wEo3E2fCrFPUp17FtrtNi2Lf7n4G3garFb16CRj",
  958. "efa81ca4e8f90181ec4b61b6a7eb998af17b2cb04de8a03b504b9e34c4c61db7d901",
  959. "cTDVKtMGVYWTHCb1AFjmVbEbWjvKpKqKgMaR3QJxToMSQAhmCeTN",
  960. "007987ccaa53d02c8873487ef919677cd3db7a6912",
  961. "1C5bSj1iEGUgSTbziymG7Cn18ENQuT36vv",
  962. "0563bcc565f9e68ee0189dd5cc67f1b0e5f02f45cb",
  963. "3AnNxabYGoTxYiTEZwFEnerUoeFXK2Zoks",
  964. "6fef66444b5b17f14e8fae6e7e19b045a78c54fd79",
  965. "n3LnJXCqbPjghuVs8ph9CYsAe4Sh4j97wk",
  966. "c4c3e55fceceaa4391ed2a9677f4a4d34eacd021a0",
  967. "2NB72XtkjpnATMggui83aEtPawyyKvnbX2o",
  968. "80e75d936d56377f432f404aabb406601f892fd49da90eb6ac558a733c93b47252",
  969. "5KaBW9vNtWNhc3ZEDyNCiXLPdVPHCikRxSBWwV9NrpLLa4LsXi9",
  970. "808248bd0375f2f75d7e274ae544fb920f51784480866b102384190b1addfbaa5c01",
  971. "L1axzbSyynNYA8mCAhzxkipKkfHtAXYF4YQnhSKcLV8YXA874fgT",
  972. "ef44c4f6a096eac5238291a94cc24c01e3b19b8d8cef72874a079e00a242237a52",
  973. "927CnUkUbasYtDwYwVn2j8GdTuACNnKkjZ1rpZd2yBB1CLcnXpo",
  974. "efd1de707020a9059d6d3abaf85e17967c6555151143db13dbb06db78df0f15c6901",
  975. "cUcfCMRjiQf85YMzzQEk9d1s5A4K7xL5SmBCLrezqXFuTVefyhY7",
  976. "00adc1cc2081a27206fae25792f28bbc55b831549d",
  977. "1Gqk4Tv79P91Cc1STQtU3s1W6277M2CVWu",
  978. "05188f91a931947eddd7432d6e614387e32b244709",
  979. "33vt8ViH5jsr115AGkW6cEmEz9MpvJSwDk",
  980. "6f1694f5bc1a7295b600f40018a618a6ea48eeb498",
  981. "mhaMcBxNh5cqXm4aTQ6EcVbKtfL6LGyK2H",
  982. "c43b9b3fd7a50d4f08d1a5b0f62f644fa7115ae2f3",
  983. "2MxgPqX1iThW3oZVk9KoFcE5M4JpiETssVN",
  984. "80091035445ef105fa1bb125eccfb1882f3fe69592265956ade751fd095033d8d0",
  985. "5HtH6GdcwCJA4ggWEL1B3jzBBUB8HPiBi9SBc5h9i4Wk4PSeApR",
  986. "80ab2b4bcdfc91d34dee0ae2a8c6b6668dadaeb3a88b9859743156f462325187af01",
  987. "L2xSYmMeVo3Zek3ZTsv9xUrXVAmrWxJ8Ua4cw8pkfbQhcEFhkXT8",
  988. "efb4204389cef18bbe2b353623cbf93e8678fbc92a475b664ae98ed594e6cf0856",
  989. "92xFEve1Z9N8Z641KQQS7ByCSb8kGjsDzw6fAmjHN1LZGKQXyMq",
  990. "efe7b230133f1b5489843260236b06edca25f66adb1be455fbd38d4010d48faeef01",
  991. "cVM65tdYu1YK37tNoAyGoJTR13VBYFva1vg9FLuPAsJijGvG6NEA",
  992. "00c4c1b72491ede1eedaca00618407ee0b772cad0d",
  993. "1JwMWBVLtiqtscbaRHai4pqHokhFCbtoB4",
  994. "05f6fe69bcb548a829cce4c57bf6fff8af3a5981f9",
  995. "3QCzvfL4ZRvmJFiWWBVwxfdaNBT8EtxB5y",
  996. "6f261f83568a098a8638844bd7aeca039d5f2352c0",
  997. "mizXiucXRCsEriQCHUkCqef9ph9qtPbZZ6",
  998. "c4e930e1834a4d234702773951d627cce82fbb5d2e",
  999. "2NEWDzHWwY5ZZp8CQWbB7ouNMLqCia6YRda",
  1000. "80d1fab7ab7385ad26872237f1eb9789aa25cc986bacc695e07ac571d6cdac8bc0",
  1001. "5KQmDryMNDcisTzRp3zEq9e4awRmJrEVU1j5vFRTKpRNYPqYrMg",
  1002. "80b0bbede33ef254e8376aceb1510253fc3550efd0fcf84dcd0c9998b288f166b301",
  1003. "L39Fy7AC2Hhj95gh3Yb2AU5YHh1mQSAHgpNixvm27poizcJyLtUi",
  1004. "ef037f4192c630f399d9271e26c575269b1d15be553ea1a7217f0cb8513cef41cb",
  1005. "91cTVUcgydqyZLgaANpf1fvL55FH53QMm4BsnCADVNYuWuqdVys",
  1006. "ef6251e205e8ad508bab5596bee086ef16cd4b239e0cc0c5d7c4e6035441e7d5de01",
  1007. "cQspfSzsgLeiJGB2u8vrAiWpCU4MxUT6JseWo2SjXy4Qbzn2fwDw",
  1008. "005eadaf9bb7121f0f192561a5a62f5e5f54210292",
  1009. "19dcawoKcZdQz365WpXWMhX6QCUpR9SY4r",
  1010. "053f210e7277c899c3a155cc1c90f4106cbddeec6e",
  1011. "37Sp6Rv3y4kVd1nQ1JV5pfqXccHNyZm1x3",
  1012. "6fc8a3c2a09a298592c3e180f02487cd91ba3400b5",
  1013. "myoqcgYiehufrsnnkqdqbp69dddVDMopJu",
  1014. "c499b31df7c9068d1481b596578ddbb4d3bd90baeb",
  1015. "2N7FuwuUuoTBrDFdrAZ9KxBmtqMLxce9i1C",
  1016. "80c7666842503db6dc6ea061f092cfb9c388448629a6fe868d068c42a488b478ae",
  1017. "5KL6zEaMtPRXZKo1bbMq7JDjjo1bJuQcsgL33je3oY8uSJCR5b4",
  1018. "8007f0803fc5399e773555ab1e8939907e9badacc17ca129e67a2f5f2ff84351dd01",
  1019. "KwV9KAfwbwt51veZWNscRTeZs9CKpojyu1MsPnaKTF5kz69H1UN2",
  1020. "efea577acfb5d1d14d3b7b195c321566f12f87d2b77ea3a53f68df7ebf8604a801",
  1021. "93N87D6uxSBzwXvpokpzg8FFmfQPmvX4xHoWQe3pLdYpbiwT5YV",
  1022. "ef0b3b34f0958d8a268193a9814da92c3e8b58b4a4378a542863e34ac289cd830c01",
  1023. "cMxXusSihaX58wpJ3tNuuUcZEQGt6DKJ1wEpxys88FFaQCYjku9h",
  1024. "001ed467017f043e91ed4c44b4e8dd674db211c4e6",
  1025. "13p1ijLwsnrcuyqcTvJXkq2ASdXqcnEBLE",
  1026. "055ece0cadddc415b1980f001785947120acdb36fc",
  1027. "3ALJH9Y951VCGcVZYAdpA3KchoP9McEj1G",
  1028. 0,
  1029. 0,
  1030. };
  1031. const char **raw = base58_vector;
  1032. const char **str = base58_vector + 1;
  1033. uint8_t rawn[34];
  1034. char strn[53];
  1035. int r;
  1036. while (*raw && *str) {
  1037. int len = strlen(*raw) / 2;
  1038. memcpy(rawn, fromhex(*raw), len);
  1039. r = base58_encode_check(rawn, len, HASHER_SHA2D, strn, sizeof(strn));
  1040. ck_assert_int_eq((size_t)r, strlen(*str) + 1);
  1041. ck_assert_str_eq(strn, *str);
  1042. r = base58_decode_check(strn, HASHER_SHA2D, rawn, len);
  1043. ck_assert_int_eq(r, len);
  1044. ck_assert_mem_eq(rawn, fromhex(*raw), len);
  1045. raw += 2;
  1046. str += 2;
  1047. }
  1048. }
  1049. END_TEST
  1050. START_TEST(test_bignum_divmod) {
  1051. uint32_t r;
  1052. int i;
  1053. bignum256 a;
  1054. uint32_t ar[] = {15, 14, 55, 29, 44, 24, 53, 49, 18, 55, 2, 28, 5, 4, 12,
  1055. 43, 18, 37, 28, 14, 30, 46, 12, 11, 17, 10, 10, 13, 24, 45,
  1056. 4, 33, 44, 42, 2, 46, 34, 43, 45, 28, 21, 18, 13, 17};
  1057. bn_read_be(
  1058. fromhex(
  1059. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  1060. &a);
  1061. i = 0;
  1062. while (!bn_is_zero(&a) && i < 44) {
  1063. bn_divmod58(&a, &r);
  1064. ck_assert_uint_eq(r, ar[i]);
  1065. i++;
  1066. }
  1067. ck_assert_int_eq(i, 44);
  1068. bignum256 b;
  1069. uint32_t br[] = {935, 639, 129, 913, 7, 584, 457, 39, 564,
  1070. 640, 665, 984, 269, 853, 907, 687, 8, 985,
  1071. 570, 423, 195, 316, 237, 89, 792, 115};
  1072. bn_read_be(
  1073. fromhex(
  1074. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  1075. &b);
  1076. i = 0;
  1077. while (!bn_is_zero(&b) && i < 26) {
  1078. bn_divmod1000(&b, &r);
  1079. ck_assert_uint_eq(r, br[i]);
  1080. i++;
  1081. }
  1082. ck_assert_int_eq(i, 26);
  1083. }
  1084. END_TEST
  1085. // test vector 1 from
  1086. // https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki#test-vector-1
  1087. START_TEST(test_bip32_vector_1) {
  1088. HDNode node, node2, node3;
  1089. uint32_t fingerprint;
  1090. char str[XPUB_MAXLEN];
  1091. int r;
  1092. // init m
  1093. hdnode_from_seed(fromhex("000102030405060708090a0b0c0d0e0f"), 16,
  1094. SECP256K1_NAME, &node);
  1095. // [Chain m]
  1096. fingerprint = 0;
  1097. ck_assert_uint_eq(fingerprint, 0x00000000);
  1098. ck_assert_mem_eq(
  1099. node.chain_code,
  1100. fromhex(
  1101. "873dff81c02f525623fd1fe5167eac3a55a049de3d314bb42ee227ffed37d508"),
  1102. 32);
  1103. ck_assert_mem_eq(
  1104. node.private_key,
  1105. fromhex(
  1106. "e8f32e723decf4051aefac8e2c93c9c5b214313817cdb01a1494b917c8436b35"),
  1107. 32);
  1108. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1109. ck_assert_mem_eq(
  1110. node.public_key,
  1111. fromhex(
  1112. "0339a36013301597daef41fbe593a02cc513d0b55527ec2df1050e2e8ff49c85c2"),
  1113. 33);
  1114. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1115. sizeof(str));
  1116. ck_assert_str_eq(str,
  1117. "xprv9s21ZrQH143K3QTDL4LXw2F7HEK3wJUD2nW2nRk4stbPy6cq3jPPqji"
  1118. "ChkVvvNKmPGJxWUtg6LnF5kejMRNNU3TGtRBeJgk33yuGBxrMPHi");
  1119. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1120. NULL);
  1121. ck_assert_int_eq(r, 0);
  1122. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1123. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1124. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1125. ck_assert_str_eq(str,
  1126. "xpub661MyMwAqRbcFtXgS5sYJABqqG9YLmC4Q1Rdap9gSE8NqtwybGhePY2"
  1127. "gZ29ESFjqJoCu1Rupje8YtGqsefD265TMg7usUDFdp6W1EGMcet8");
  1128. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1129. NULL);
  1130. ck_assert_int_eq(r, 0);
  1131. memcpy(&node3, &node, sizeof(HDNode));
  1132. memzero(&node3.private_key, 32);
  1133. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1134. // [Chain m/0']
  1135. fingerprint = hdnode_fingerprint(&node);
  1136. hdnode_private_ckd_prime(&node, 0);
  1137. ck_assert_uint_eq(fingerprint, 0x3442193e);
  1138. ck_assert_mem_eq(
  1139. node.chain_code,
  1140. fromhex(
  1141. "47fdacbd0f1097043b78c63c20c34ef4ed9a111d980047ad16282c7ae6236141"),
  1142. 32);
  1143. ck_assert_mem_eq(
  1144. node.private_key,
  1145. fromhex(
  1146. "edb2e14f9ee77d26dd93b4ecede8d16ed408ce149b6cd80b0715a2d911a0afea"),
  1147. 32);
  1148. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1149. ck_assert_mem_eq(
  1150. node.public_key,
  1151. fromhex(
  1152. "035a784662a4a20a65bf6aab9ae98a6c068a81c52e4b032c0fb5400c706cfccc56"),
  1153. 33);
  1154. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1155. sizeof(str));
  1156. ck_assert_str_eq(str,
  1157. "xprv9uHRZZhk6KAJC1avXpDAp4MDc3sQKNxDiPvvkX8Br5ngLNv1TxvUxt4"
  1158. "cV1rGL5hj6KCesnDYUhd7oWgT11eZG7XnxHrnYeSvkzY7d2bhkJ7");
  1159. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1160. NULL);
  1161. ck_assert_int_eq(r, 0);
  1162. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1163. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1164. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1165. ck_assert_str_eq(str,
  1166. "xpub68Gmy5EdvgibQVfPdqkBBCHxA5htiqg55crXYuXoQRKfDBFA1WEjWgP"
  1167. "6LHhwBZeNK1VTsfTFUHCdrfp1bgwQ9xv5ski8PX9rL2dZXvgGDnw");
  1168. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1169. NULL);
  1170. ck_assert_int_eq(r, 0);
  1171. memcpy(&node3, &node, sizeof(HDNode));
  1172. memzero(&node3.private_key, 32);
  1173. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1174. // [Chain m/0'/1]
  1175. fingerprint = hdnode_fingerprint(&node);
  1176. hdnode_private_ckd(&node, 1);
  1177. ck_assert_uint_eq(fingerprint, 0x5c1bd648);
  1178. ck_assert_mem_eq(
  1179. node.chain_code,
  1180. fromhex(
  1181. "2a7857631386ba23dacac34180dd1983734e444fdbf774041578e9b6adb37c19"),
  1182. 32);
  1183. ck_assert_mem_eq(
  1184. node.private_key,
  1185. fromhex(
  1186. "3c6cb8d0f6a264c91ea8b5030fadaa8e538b020f0a387421a12de9319dc93368"),
  1187. 32);
  1188. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1189. ck_assert_mem_eq(
  1190. node.public_key,
  1191. fromhex(
  1192. "03501e454bf00751f24b1b489aa925215d66af2234e3891c3b21a52bedb3cd711c"),
  1193. 33);
  1194. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1195. sizeof(str));
  1196. ck_assert_str_eq(str,
  1197. "xprv9wTYmMFdV23N2TdNG573QoEsfRrWKQgWeibmLntzniatZvR9BmLnvSx"
  1198. "qu53Kw1UmYPxLgboyZQaXwTCg8MSY3H2EU4pWcQDnRnrVA1xe8fs");
  1199. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1200. NULL);
  1201. ck_assert_int_eq(r, 0);
  1202. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1203. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1204. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1205. ck_assert_str_eq(str,
  1206. "xpub6ASuArnXKPbfEwhqN6e3mwBcDTgzisQN1wXN9BJcM47sSikHjJf3UFH"
  1207. "KkNAWbWMiGj7Wf5uMash7SyYq527Hqck2AxYysAA7xmALppuCkwQ");
  1208. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1209. NULL);
  1210. ck_assert_int_eq(r, 0);
  1211. memcpy(&node3, &node, sizeof(HDNode));
  1212. memzero(&node3.private_key, 32);
  1213. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1214. // [Chain m/0'/1/2']
  1215. fingerprint = hdnode_fingerprint(&node);
  1216. hdnode_private_ckd_prime(&node, 2);
  1217. ck_assert_uint_eq(fingerprint, 0xbef5a2f9);
  1218. ck_assert_mem_eq(
  1219. node.chain_code,
  1220. fromhex(
  1221. "04466b9cc8e161e966409ca52986c584f07e9dc81f735db683c3ff6ec7b1503f"),
  1222. 32);
  1223. ck_assert_mem_eq(
  1224. node.private_key,
  1225. fromhex(
  1226. "cbce0d719ecf7431d88e6a89fa1483e02e35092af60c042b1df2ff59fa424dca"),
  1227. 32);
  1228. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1229. ck_assert_mem_eq(
  1230. node.public_key,
  1231. fromhex(
  1232. "0357bfe1e341d01c69fe5654309956cbea516822fba8a601743a012a7896ee8dc2"),
  1233. 33);
  1234. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1235. sizeof(str));
  1236. ck_assert_str_eq(str,
  1237. "xprv9z4pot5VBttmtdRTWfWQmoH1taj2axGVzFqSb8C9xaxKymcFzXBDptW"
  1238. "mT7FwuEzG3ryjH4ktypQSAewRiNMjANTtpgP4mLTj34bhnZX7UiM");
  1239. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1240. NULL);
  1241. ck_assert_int_eq(r, 0);
  1242. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1243. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1244. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1245. ck_assert_str_eq(str,
  1246. "xpub6D4BDPcP2GT577Vvch3R8wDkScZWzQzMMUm3PWbmWvVJrZwQY4VUNgq"
  1247. "FJPMM3No2dFDFGTsxxpG5uJh7n7epu4trkrX7x7DogT5Uv6fcLW5");
  1248. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1249. NULL);
  1250. ck_assert_int_eq(r, 0);
  1251. memcpy(&node3, &node, sizeof(HDNode));
  1252. memzero(&node3.private_key, 32);
  1253. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1254. // [Chain m/0'/1/2'/2]
  1255. fingerprint = hdnode_fingerprint(&node);
  1256. hdnode_private_ckd(&node, 2);
  1257. ck_assert_uint_eq(fingerprint, 0xee7ab90c);
  1258. ck_assert_mem_eq(
  1259. node.chain_code,
  1260. fromhex(
  1261. "cfb71883f01676f587d023cc53a35bc7f88f724b1f8c2892ac1275ac822a3edd"),
  1262. 32);
  1263. ck_assert_mem_eq(
  1264. node.private_key,
  1265. fromhex(
  1266. "0f479245fb19a38a1954c5c7c0ebab2f9bdfd96a17563ef28a6a4b1a2a764ef4"),
  1267. 32);
  1268. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1269. ck_assert_mem_eq(
  1270. node.public_key,
  1271. fromhex(
  1272. "02e8445082a72f29b75ca48748a914df60622a609cacfce8ed0e35804560741d29"),
  1273. 33);
  1274. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1275. sizeof(str));
  1276. ck_assert_str_eq(str,
  1277. "xprvA2JDeKCSNNZky6uBCviVfJSKyQ1mDYahRjijr5idH2WwLsEd4Hsb2Ty"
  1278. "h8RfQMuPh7f7RtyzTtdrbdqqsunu5Mm3wDvUAKRHSC34sJ7in334");
  1279. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1280. NULL);
  1281. ck_assert_int_eq(r, 0);
  1282. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1283. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1284. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1285. ck_assert_str_eq(str,
  1286. "xpub6FHa3pjLCk84BayeJxFW2SP4XRrFd1JYnxeLeU8EqN3vDfZmbqBqaGJ"
  1287. "AyiLjTAwm6ZLRQUMv1ZACTj37sR62cfN7fe5JnJ7dh8zL4fiyLHV");
  1288. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1289. NULL);
  1290. ck_assert_int_eq(r, 0);
  1291. memcpy(&node3, &node, sizeof(HDNode));
  1292. memzero(&node3.private_key, 32);
  1293. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1294. // [Chain m/0'/1/2'/2/1000000000]
  1295. fingerprint = hdnode_fingerprint(&node);
  1296. hdnode_private_ckd(&node, 1000000000);
  1297. ck_assert_uint_eq(fingerprint, 0xd880d7d8);
  1298. ck_assert_mem_eq(
  1299. node.chain_code,
  1300. fromhex(
  1301. "c783e67b921d2beb8f6b389cc646d7263b4145701dadd2161548a8b078e65e9e"),
  1302. 32);
  1303. ck_assert_mem_eq(
  1304. node.private_key,
  1305. fromhex(
  1306. "471b76e389e528d6de6d816857e012c5455051cad6660850e58372a6c3e6e7c8"),
  1307. 32);
  1308. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1309. ck_assert_mem_eq(
  1310. node.public_key,
  1311. fromhex(
  1312. "022a471424da5e657499d1ff51cb43c47481a03b1e77f951fe64cec9f5a48f7011"),
  1313. 33);
  1314. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1315. sizeof(str));
  1316. ck_assert_str_eq(str,
  1317. "xprvA41z7zogVVwxVSgdKUHDy1SKmdb533PjDz7J6N6mV6uS3ze1ai8FHa8"
  1318. "kmHScGpWmj4WggLyQjgPie1rFSruoUihUZREPSL39UNdE3BBDu76");
  1319. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1320. NULL);
  1321. ck_assert_int_eq(r, 0);
  1322. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1323. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1324. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1325. ck_assert_str_eq(str,
  1326. "xpub6H1LXWLaKsWFhvm6RVpEL9P4KfRZSW7abD2ttkWP3SSQvnyA8FSVqNT"
  1327. "EcYFgJS2UaFcxupHiYkro49S8yGasTvXEYBVPamhGW6cFJodrTHy");
  1328. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1329. NULL);
  1330. ck_assert_int_eq(r, 0);
  1331. memcpy(&node3, &node, sizeof(HDNode));
  1332. memzero(&node3.private_key, 32);
  1333. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1334. }
  1335. END_TEST
  1336. // test vector 2 from
  1337. // https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki#test-vector-2
  1338. START_TEST(test_bip32_vector_2) {
  1339. HDNode node, node2, node3;
  1340. uint32_t fingerprint;
  1341. char str[XPUB_MAXLEN];
  1342. int r;
  1343. // init m
  1344. hdnode_from_seed(
  1345. fromhex(
  1346. "fffcf9f6f3f0edeae7e4e1dedbd8d5d2cfccc9c6c3c0bdbab7b4b1aeaba8a5a29f9c"
  1347. "999693908d8a8784817e7b7875726f6c696663605d5a5754514e4b484542"),
  1348. 64, SECP256K1_NAME, &node);
  1349. // [Chain m]
  1350. fingerprint = 0;
  1351. ck_assert_uint_eq(fingerprint, 0x00000000);
  1352. ck_assert_mem_eq(
  1353. node.chain_code,
  1354. fromhex(
  1355. "60499f801b896d83179a4374aeb7822aaeaceaa0db1f85ee3e904c4defbd9689"),
  1356. 32);
  1357. ck_assert_mem_eq(
  1358. node.private_key,
  1359. fromhex(
  1360. "4b03d6fc340455b363f51020ad3ecca4f0850280cf436c70c727923f6db46c3e"),
  1361. 32);
  1362. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1363. ck_assert_mem_eq(
  1364. node.public_key,
  1365. fromhex(
  1366. "03cbcaa9c98c877a26977d00825c956a238e8dddfbd322cce4f74b0b5bd6ace4a7"),
  1367. 33);
  1368. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1369. sizeof(str));
  1370. ck_assert_str_eq(str,
  1371. "xprv9s21ZrQH143K31xYSDQpPDxsXRTUcvj2iNHm5NUtrGiGG5e2DtALGds"
  1372. "o3pGz6ssrdK4PFmM8NSpSBHNqPqm55Qn3LqFtT2emdEXVYsCzC2U");
  1373. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1374. NULL);
  1375. ck_assert_int_eq(r, 0);
  1376. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1377. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1378. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1379. ck_assert_str_eq(str,
  1380. "xpub661MyMwAqRbcFW31YEwpkMuc5THy2PSt5bDMsktWQcFF8syAmRUapSC"
  1381. "Gu8ED9W6oDMSgv6Zz8idoc4a6mr8BDzTJY47LJhkJ8UB7WEGuduB");
  1382. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1383. NULL);
  1384. ck_assert_int_eq(r, 0);
  1385. memcpy(&node3, &node, sizeof(HDNode));
  1386. memzero(&node3.private_key, 32);
  1387. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1388. // [Chain m/0]
  1389. fingerprint = hdnode_fingerprint(&node);
  1390. r = hdnode_private_ckd(&node, 0);
  1391. ck_assert_int_eq(r, 1);
  1392. ck_assert_uint_eq(fingerprint, 0xbd16bee5);
  1393. ck_assert_mem_eq(
  1394. node.chain_code,
  1395. fromhex(
  1396. "f0909affaa7ee7abe5dd4e100598d4dc53cd709d5a5c2cac40e7412f232f7c9c"),
  1397. 32);
  1398. ck_assert_mem_eq(
  1399. node.private_key,
  1400. fromhex(
  1401. "abe74a98f6c7eabee0428f53798f0ab8aa1bd37873999041703c742f15ac7e1e"),
  1402. 32);
  1403. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1404. ck_assert_mem_eq(
  1405. node.public_key,
  1406. fromhex(
  1407. "02fc9e5af0ac8d9b3cecfe2a888e2117ba3d089d8585886c9c826b6b22a98d12ea"),
  1408. 33);
  1409. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1410. sizeof(str));
  1411. ck_assert_str_eq(str,
  1412. "xprv9vHkqa6EV4sPZHYqZznhT2NPtPCjKuDKGY38FBWLvgaDx45zo9WQRUT"
  1413. "3dKYnjwih2yJD9mkrocEZXo1ex8G81dwSM1fwqWpWkeS3v86pgKt");
  1414. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1415. NULL);
  1416. ck_assert_int_eq(r, 0);
  1417. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1418. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1419. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1420. ck_assert_str_eq(str,
  1421. "xpub69H7F5d8KSRgmmdJg2KhpAK8SR3DjMwAdkxj3ZuxV27CprR9LgpeyGm"
  1422. "XUbC6wb7ERfvrnKZjXoUmmDznezpbZb7ap6r1D3tgFxHmwMkQTPH");
  1423. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1424. NULL);
  1425. ck_assert_int_eq(r, 0);
  1426. memcpy(&node3, &node, sizeof(HDNode));
  1427. memzero(&node3.private_key, 32);
  1428. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1429. // [Chain m/0/2147483647']
  1430. fingerprint = hdnode_fingerprint(&node);
  1431. r = hdnode_private_ckd_prime(&node, 2147483647);
  1432. ck_assert_int_eq(r, 1);
  1433. ck_assert_uint_eq(fingerprint, 0x5a61ff8e);
  1434. ck_assert_mem_eq(
  1435. node.chain_code,
  1436. fromhex(
  1437. "be17a268474a6bb9c61e1d720cf6215e2a88c5406c4aee7b38547f585c9a37d9"),
  1438. 32);
  1439. ck_assert_mem_eq(
  1440. node.private_key,
  1441. fromhex(
  1442. "877c779ad9687164e9c2f4f0f4ff0340814392330693ce95a58fe18fd52e6e93"),
  1443. 32);
  1444. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1445. ck_assert_mem_eq(
  1446. node.public_key,
  1447. fromhex(
  1448. "03c01e7425647bdefa82b12d9bad5e3e6865bee0502694b94ca58b666abc0a5c3b"),
  1449. 33);
  1450. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1451. sizeof(str));
  1452. ck_assert_str_eq(str,
  1453. "xprv9wSp6B7kry3Vj9m1zSnLvN3xH8RdsPP1Mh7fAaR7aRLcQMKTR2vidYE"
  1454. "eEg2mUCTAwCd6vnxVrcjfy2kRgVsFawNzmjuHc2YmYRmagcEPdU9");
  1455. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1456. NULL);
  1457. ck_assert_int_eq(r, 0);
  1458. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1459. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1460. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1461. ck_assert_str_eq(str,
  1462. "xpub6ASAVgeehLbnwdqV6UKMHVzgqAG8Gr6riv3Fxxpj8ksbH9ebxaEyBLZ"
  1463. "85ySDhKiLDBrQSARLq1uNRts8RuJiHjaDMBU4Zn9h8LZNnBC5y4a");
  1464. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1465. NULL);
  1466. ck_assert_int_eq(r, 0);
  1467. memcpy(&node3, &node, sizeof(HDNode));
  1468. memzero(&node3.private_key, 32);
  1469. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1470. // [Chain m/0/2147483647'/1]
  1471. fingerprint = hdnode_fingerprint(&node);
  1472. r = hdnode_private_ckd(&node, 1);
  1473. ck_assert_int_eq(r, 1);
  1474. ck_assert_uint_eq(fingerprint, 0xd8ab4937);
  1475. ck_assert_mem_eq(
  1476. node.chain_code,
  1477. fromhex(
  1478. "f366f48f1ea9f2d1d3fe958c95ca84ea18e4c4ddb9366c336c927eb246fb38cb"),
  1479. 32);
  1480. ck_assert_mem_eq(
  1481. node.private_key,
  1482. fromhex(
  1483. "704addf544a06e5ee4bea37098463c23613da32020d604506da8c0518e1da4b7"),
  1484. 32);
  1485. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1486. ck_assert_mem_eq(
  1487. node.public_key,
  1488. fromhex(
  1489. "03a7d1d856deb74c508e05031f9895dab54626251b3806e16b4bd12e781a7df5b9"),
  1490. 33);
  1491. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1492. sizeof(str));
  1493. ck_assert_str_eq(str,
  1494. "xprv9zFnWC6h2cLgpmSA46vutJzBcfJ8yaJGg8cX1e5StJh45BBciYTRXSd"
  1495. "25UEPVuesF9yog62tGAQtHjXajPPdbRCHuWS6T8XA2ECKADdw4Ef");
  1496. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1497. NULL);
  1498. ck_assert_int_eq(r, 0);
  1499. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1500. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1501. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1502. ck_assert_str_eq(str,
  1503. "xpub6DF8uhdarytz3FWdA8TvFSvvAh8dP3283MY7p2V4SeE2wyWmG5mg5Ew"
  1504. "VvmdMVCQcoNJxGoWaU9DCWh89LojfZ537wTfunKau47EL2dhHKon");
  1505. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1506. NULL);
  1507. ck_assert_int_eq(r, 0);
  1508. memcpy(&node3, &node, sizeof(HDNode));
  1509. memzero(&node3.private_key, 32);
  1510. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1511. // [Chain m/0/2147483647'/1/2147483646']
  1512. fingerprint = hdnode_fingerprint(&node);
  1513. r = hdnode_private_ckd_prime(&node, 2147483646);
  1514. ck_assert_int_eq(r, 1);
  1515. ck_assert_uint_eq(fingerprint, 0x78412e3a);
  1516. ck_assert_mem_eq(
  1517. node.chain_code,
  1518. fromhex(
  1519. "637807030d55d01f9a0cb3a7839515d796bd07706386a6eddf06cc29a65a0e29"),
  1520. 32);
  1521. ck_assert_mem_eq(
  1522. node.private_key,
  1523. fromhex(
  1524. "f1c7c871a54a804afe328b4c83a1c33b8e5ff48f5087273f04efa83b247d6a2d"),
  1525. 32);
  1526. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1527. ck_assert_mem_eq(
  1528. node.public_key,
  1529. fromhex(
  1530. "02d2b36900396c9282fa14628566582f206a5dd0bcc8d5e892611806cafb0301f0"),
  1531. 33);
  1532. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1533. sizeof(str));
  1534. ck_assert_str_eq(str,
  1535. "xprvA1RpRA33e1JQ7ifknakTFpgNXPmW2YvmhqLQYMmrj4xJXXWYpDPS3xz"
  1536. "7iAxn8L39njGVyuoseXzU6rcxFLJ8HFsTjSyQbLYnMpCqE2VbFWc");
  1537. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1538. NULL);
  1539. ck_assert_int_eq(r, 0);
  1540. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1541. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1542. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1543. ck_assert_str_eq(str,
  1544. "xpub6ERApfZwUNrhLCkDtcHTcxd75RbzS1ed54G1LkBUHQVHQKqhMkhgbmJ"
  1545. "bZRkrgZw4koxb5JaHWkY4ALHY2grBGRjaDMzQLcgJvLJuZZvRcEL");
  1546. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1547. NULL);
  1548. ck_assert_int_eq(r, 0);
  1549. memcpy(&node3, &node, sizeof(HDNode));
  1550. memzero(&node3.private_key, 32);
  1551. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1552. // [Chain m/0/2147483647'/1/2147483646'/2]
  1553. fingerprint = hdnode_fingerprint(&node);
  1554. r = hdnode_private_ckd(&node, 2);
  1555. ck_assert_int_eq(r, 1);
  1556. ck_assert_uint_eq(fingerprint, 0x31a507b8);
  1557. ck_assert_mem_eq(
  1558. node.chain_code,
  1559. fromhex(
  1560. "9452b549be8cea3ecb7a84bec10dcfd94afe4d129ebfd3b3cb58eedf394ed271"),
  1561. 32);
  1562. ck_assert_mem_eq(
  1563. node.private_key,
  1564. fromhex(
  1565. "bb7d39bdb83ecf58f2fd82b6d918341cbef428661ef01ab97c28a4842125ac23"),
  1566. 32);
  1567. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1568. ck_assert_mem_eq(
  1569. node.public_key,
  1570. fromhex(
  1571. "024d902e1a2fc7a8755ab5b694c575fce742c48d9ff192e63df5193e4c7afe1f9c"),
  1572. 33);
  1573. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1574. sizeof(str));
  1575. ck_assert_str_eq(str,
  1576. "xprvA2nrNbFZABcdryreWet9Ea4LvTJcGsqrMzxHx98MMrotbir7yrKCEXw"
  1577. "7nadnHM8Dq38EGfSh6dqA9QWTyefMLEcBYJUuekgW4BYPJcr9E7j");
  1578. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1579. NULL);
  1580. ck_assert_int_eq(r, 0);
  1581. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1582. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1583. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1584. ck_assert_str_eq(str,
  1585. "xpub6FnCn6nSzZAw5Tw7cgR9bi15UV96gLZhjDstkXXxvCLsUXBGXPdSnLF"
  1586. "bdpq8p9HmGsApME5hQTZ3emM2rnY5agb9rXpVGyy3bdW6EEgAtqt");
  1587. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1588. NULL);
  1589. ck_assert_int_eq(r, 0);
  1590. memcpy(&node3, &node, sizeof(HDNode));
  1591. memzero(&node3.private_key, 32);
  1592. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1593. // init m
  1594. hdnode_from_seed(
  1595. fromhex(
  1596. "fffcf9f6f3f0edeae7e4e1dedbd8d5d2cfccc9c6c3c0bdbab7b4b1aeaba8a5a29f9c"
  1597. "999693908d8a8784817e7b7875726f6c696663605d5a5754514e4b484542"),
  1598. 64, SECP256K1_NAME, &node);
  1599. // test public derivation
  1600. // [Chain m/0]
  1601. fingerprint = hdnode_fingerprint(&node);
  1602. r = hdnode_public_ckd(&node, 0);
  1603. ck_assert_int_eq(r, 1);
  1604. ck_assert_uint_eq(fingerprint, 0xbd16bee5);
  1605. ck_assert_mem_eq(
  1606. node.chain_code,
  1607. fromhex(
  1608. "f0909affaa7ee7abe5dd4e100598d4dc53cd709d5a5c2cac40e7412f232f7c9c"),
  1609. 32);
  1610. ck_assert_mem_eq(
  1611. node.private_key,
  1612. fromhex(
  1613. "0000000000000000000000000000000000000000000000000000000000000000"),
  1614. 32);
  1615. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1616. ck_assert_mem_eq(
  1617. node.public_key,
  1618. fromhex(
  1619. "02fc9e5af0ac8d9b3cecfe2a888e2117ba3d089d8585886c9c826b6b22a98d12ea"),
  1620. 33);
  1621. }
  1622. END_TEST
  1623. // test vector 3 from
  1624. // https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki#test-vector-3
  1625. START_TEST(test_bip32_vector_3) {
  1626. HDNode node, node2, node3;
  1627. uint32_t fingerprint;
  1628. char str[XPUB_MAXLEN];
  1629. int r;
  1630. // init m
  1631. hdnode_from_seed(
  1632. fromhex(
  1633. "4b381541583be4423346c643850da4b320e46a87ae3d2a4e6da11eba819cd4acba45"
  1634. "d239319ac14f863b8d5ab5a0d0c64d2e8a1e7d1457df2e5a3c51c73235be"),
  1635. 64, SECP256K1_NAME, &node);
  1636. // [Chain m]
  1637. fingerprint = 0;
  1638. ck_assert_uint_eq(fingerprint, 0x00000000);
  1639. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1640. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1641. sizeof(str));
  1642. ck_assert_str_eq(str,
  1643. "xprv9s21ZrQH143K25QhxbucbDDuQ4naNntJRi4KUfWT7xo4EKsHt2QJDu7"
  1644. "KXp1A3u7Bi1j8ph3EGsZ9Xvz9dGuVrtHHs7pXeTzjuxBrCmmhgC6");
  1645. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1646. NULL);
  1647. ck_assert_int_eq(r, 0);
  1648. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1649. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1650. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1651. ck_assert_str_eq(str,
  1652. "xpub661MyMwAqRbcEZVB4dScxMAdx6d4nFc9nvyvH3v4gJL378CSRZiYmhR"
  1653. "oP7mBy6gSPSCYk6SzXPTf3ND1cZAceL7SfJ1Z3GC8vBgp2epUt13");
  1654. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1655. NULL);
  1656. ck_assert_int_eq(r, 0);
  1657. memcpy(&node3, &node, sizeof(HDNode));
  1658. memzero(&node3.private_key, 32);
  1659. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1660. // [Chain m/0']
  1661. fingerprint = hdnode_fingerprint(&node);
  1662. r = hdnode_private_ckd_prime(&node, 0);
  1663. ck_assert_int_eq(r, 1);
  1664. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1665. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1666. sizeof(str));
  1667. ck_assert_str_eq(str,
  1668. "xprv9uPDJpEQgRQfDcW7BkF7eTya6RPxXeJCqCJGHuCJ4GiRVLzkTXBAJMu"
  1669. "2qaMWPrS7AANYqdq6vcBcBUdJCVVFceUvJFjaPdGZ2y9WACViL4L");
  1670. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1671. NULL);
  1672. ck_assert_int_eq(r, 0);
  1673. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1674. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1675. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1676. ck_assert_str_eq(str,
  1677. "xpub68NZiKmJWnxxS6aaHmn81bvJeTESw724CRDs6HbuccFQN9Ku14VQrAD"
  1678. "WgqbhhTHBaohPX4CjNLf9fq9MYo6oDaPPLPxSb7gwQN3ih19Zm4Y");
  1679. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1680. NULL);
  1681. ck_assert_int_eq(r, 0);
  1682. memcpy(&node3, &node, sizeof(HDNode));
  1683. memzero(&node3.private_key, 32);
  1684. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1685. }
  1686. END_TEST
  1687. // test vector 4 from
  1688. // https://github.com/bitcoin/bips/blob/master/bip-0032.mediawiki#test-vector-4
  1689. START_TEST(test_bip32_vector_4) {
  1690. HDNode node, node2, node3;
  1691. uint32_t fingerprint;
  1692. char str[XPUB_MAXLEN];
  1693. int r;
  1694. // init m
  1695. hdnode_from_seed(
  1696. fromhex(
  1697. "3ddd5602285899a946114506157c7997e5444528f3003f6134712147db19b678"),
  1698. 32, SECP256K1_NAME, &node);
  1699. // [Chain m]
  1700. fingerprint = 0;
  1701. ck_assert_int_eq(fingerprint, 0x00000000);
  1702. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1703. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1704. sizeof(str));
  1705. ck_assert_str_eq(str,
  1706. "xprv9s21ZrQH143K48vGoLGRPxgo2JNkJ3J3fqkirQC2zVdk5Dgd5w14S7f"
  1707. "RDyHH4dWNHUgkvsvNDCkvAwcSHNAQwhwgNMgZhLtQC63zxwhQmRv");
  1708. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1709. NULL);
  1710. ck_assert_int_eq(r, 0);
  1711. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1712. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1713. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1714. ck_assert_str_eq(str,
  1715. "xpub661MyMwAqRbcGczjuMoRm6dXaLDEhW1u34gKenbeYqAix21mdUKJyuy"
  1716. "u5F1rzYGVxyL6tmgBUAEPrEz92mBXjByMRiJdba9wpnN37RLLAXa");
  1717. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1718. NULL);
  1719. ck_assert_int_eq(r, 0);
  1720. memcpy(&node3, &node, sizeof(HDNode));
  1721. memzero(&node3.private_key, 32);
  1722. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1723. // [Chain m/0']
  1724. fingerprint = hdnode_fingerprint(&node);
  1725. r = hdnode_private_ckd_prime(&node, 0);
  1726. ck_assert_int_eq(r, 1);
  1727. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1728. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1729. sizeof(str));
  1730. ck_assert_str_eq(str,
  1731. "xprv9vB7xEWwNp9kh1wQRfCCQMnZUEG21LpbR9NPCNN1dwhiZkjjeGRnaAL"
  1732. "mPXCX7SgjFTiCTT6bXes17boXtjq3xLpcDjzEuGLQBM5ohqkao9G");
  1733. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1734. NULL);
  1735. ck_assert_int_eq(r, 0);
  1736. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1737. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1738. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1739. ck_assert_str_eq(str,
  1740. "xpub69AUMk3qDBi3uW1sXgjCmVjJ2G6WQoYSnNHyzkmdCHEhSZ4tBok37xf"
  1741. "FEqHd2AddP56Tqp4o56AePAgCjYdvpW2PU2jbUPFKsav5ut6Ch1m");
  1742. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1743. NULL);
  1744. ck_assert_int_eq(r, 0);
  1745. memcpy(&node3, &node, sizeof(HDNode));
  1746. memzero(&node3.private_key, 32);
  1747. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1748. // [Chain m/0'/1']
  1749. fingerprint = hdnode_fingerprint(&node);
  1750. r = hdnode_private_ckd_prime(&node, 1);
  1751. ck_assert_int_eq(r, 1);
  1752. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1753. hdnode_serialize_private(&node, fingerprint, VERSION_PRIVATE, str,
  1754. sizeof(str));
  1755. ck_assert_str_eq(str,
  1756. "xprv9xJocDuwtYCMNAo3Zw76WENQeAS6WGXQ55RCy7tDJ8oALr4FWkuVoHJ"
  1757. "eHVAcAqiZLE7Je3vZJHxspZdFHfnBEjHqU5hG1Jaj32dVoS6XLT1");
  1758. r = hdnode_deserialize_private(str, VERSION_PRIVATE, SECP256K1_NAME, &node2,
  1759. NULL);
  1760. ck_assert_int_eq(r, 0);
  1761. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1762. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  1763. hdnode_serialize_public(&node, fingerprint, VERSION_PUBLIC, str, sizeof(str));
  1764. ck_assert_str_eq(str,
  1765. "xpub6BJA1jSqiukeaesWfxe6sNK9CCGaujFFSJLomWHprUL9DePQ4JDkM5d"
  1766. "88n49sMGJxrhpjazuXYWdMf17C9T5XnxkopaeS7jGk1GyyVziaMt");
  1767. r = hdnode_deserialize_public(str, VERSION_PUBLIC, SECP256K1_NAME, &node2,
  1768. NULL);
  1769. ck_assert_int_eq(r, 0);
  1770. memcpy(&node3, &node, sizeof(HDNode));
  1771. memzero(&node3.private_key, 32);
  1772. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  1773. }
  1774. END_TEST
  1775. START_TEST(test_bip32_compare) {
  1776. HDNode node1, node2, node3;
  1777. int i, r;
  1778. hdnode_from_seed(
  1779. fromhex(
  1780. "301133282ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d62788"
  1781. "f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  1782. 64, SECP256K1_NAME, &node1);
  1783. hdnode_from_seed(
  1784. fromhex(
  1785. "301133282ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d62788"
  1786. "f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  1787. 64, SECP256K1_NAME, &node2);
  1788. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  1789. for (i = 0; i < 100; i++) {
  1790. memcpy(&node3, &node1, sizeof(HDNode));
  1791. ck_assert_int_eq(hdnode_fill_public_key(&node3), 0);
  1792. r = hdnode_private_ckd(&node1, i);
  1793. ck_assert_int_eq(r, 1);
  1794. r = hdnode_public_ckd(&node2, i);
  1795. ck_assert_int_eq(r, 1);
  1796. r = hdnode_public_ckd(&node3, i);
  1797. ck_assert_int_eq(r, 1);
  1798. ck_assert_uint_eq(node1.depth, node2.depth);
  1799. ck_assert_uint_eq(node1.depth, node3.depth);
  1800. ck_assert_uint_eq(node1.child_num, node2.child_num);
  1801. ck_assert_uint_eq(node1.child_num, node3.child_num);
  1802. ck_assert_mem_eq(node1.chain_code, node2.chain_code, 32);
  1803. ck_assert_mem_eq(node1.chain_code, node3.chain_code, 32);
  1804. ck_assert_mem_eq(
  1805. node2.private_key,
  1806. fromhex(
  1807. "0000000000000000000000000000000000000000000000000000000000000000"),
  1808. 32);
  1809. ck_assert_mem_eq(
  1810. node3.private_key,
  1811. fromhex(
  1812. "0000000000000000000000000000000000000000000000000000000000000000"),
  1813. 32);
  1814. ck_assert_int_eq(hdnode_fill_public_key(&node1), 0);
  1815. ck_assert_mem_eq(node1.public_key, node2.public_key, 33);
  1816. ck_assert_mem_eq(node1.public_key, node3.public_key, 33);
  1817. }
  1818. }
  1819. END_TEST
  1820. START_TEST(test_bip32_optimized) {
  1821. HDNode root;
  1822. hdnode_from_seed((uint8_t *)"NothingToSeeHere", 16, SECP256K1_NAME, &root);
  1823. ck_assert_int_eq(hdnode_fill_public_key(&root), 0);
  1824. curve_point pub;
  1825. ecdsa_read_pubkey(&secp256k1, root.public_key, &pub);
  1826. HDNode node;
  1827. char addr1[MAX_ADDR_SIZE], addr2[MAX_ADDR_SIZE];
  1828. for (int i = 0; i < 40; i++) {
  1829. // unoptimized
  1830. memcpy(&node, &root, sizeof(HDNode));
  1831. hdnode_public_ckd(&node, i);
  1832. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1833. ecdsa_get_address(node.public_key, 0, HASHER_SHA2_RIPEMD, HASHER_SHA2D,
  1834. addr1, sizeof(addr1));
  1835. // optimized
  1836. hdnode_public_ckd_address_optimized(&pub, root.chain_code, i, 0,
  1837. HASHER_SHA2_RIPEMD, HASHER_SHA2D, addr2,
  1838. sizeof(addr2), 0);
  1839. // check
  1840. ck_assert_str_eq(addr1, addr2);
  1841. }
  1842. }
  1843. END_TEST
  1844. START_TEST(test_bip32_cache_1) {
  1845. HDNode node1, node2;
  1846. int i, r;
  1847. // test 1 .. 8
  1848. hdnode_from_seed(
  1849. fromhex(
  1850. "301133282ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d62788"
  1851. "f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  1852. 64, SECP256K1_NAME, &node1);
  1853. hdnode_from_seed(
  1854. fromhex(
  1855. "301133282ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d62788"
  1856. "f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  1857. 64, SECP256K1_NAME, &node2);
  1858. uint32_t ii[] = {0x80000001, 0x80000002, 0x80000003, 0x80000004,
  1859. 0x80000005, 0x80000006, 0x80000007, 0x80000008};
  1860. for (i = 0; i < 8; i++) {
  1861. r = hdnode_private_ckd(&node1, ii[i]);
  1862. ck_assert_int_eq(r, 1);
  1863. }
  1864. r = hdnode_private_ckd_cached(&node2, ii, 8, NULL);
  1865. ck_assert_int_eq(r, 1);
  1866. ck_assert_mem_eq(&node1, &node2, sizeof(HDNode));
  1867. hdnode_from_seed(
  1868. fromhex(
  1869. "301133282ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d62788"
  1870. "f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  1871. 64, SECP256K1_NAME, &node1);
  1872. hdnode_from_seed(
  1873. fromhex(
  1874. "301133282ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d62788"
  1875. "f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  1876. 64, SECP256K1_NAME, &node2);
  1877. // test 1 .. 7, 20
  1878. ii[7] = 20;
  1879. for (i = 0; i < 8; i++) {
  1880. r = hdnode_private_ckd(&node1, ii[i]);
  1881. ck_assert_int_eq(r, 1);
  1882. }
  1883. r = hdnode_private_ckd_cached(&node2, ii, 8, NULL);
  1884. ck_assert_int_eq(r, 1);
  1885. ck_assert_mem_eq(&node1, &node2, sizeof(HDNode));
  1886. // test different root node
  1887. hdnode_from_seed(
  1888. fromhex(
  1889. "000000002ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d62788"
  1890. "f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  1891. 64, SECP256K1_NAME, &node1);
  1892. hdnode_from_seed(
  1893. fromhex(
  1894. "000000002ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d62788"
  1895. "f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  1896. 64, SECP256K1_NAME, &node2);
  1897. for (i = 0; i < 8; i++) {
  1898. r = hdnode_private_ckd(&node1, ii[i]);
  1899. ck_assert_int_eq(r, 1);
  1900. }
  1901. r = hdnode_private_ckd_cached(&node2, ii, 8, NULL);
  1902. ck_assert_int_eq(r, 1);
  1903. ck_assert_mem_eq(&node1, &node2, sizeof(HDNode));
  1904. }
  1905. END_TEST
  1906. START_TEST(test_bip32_cache_2) {
  1907. HDNode nodea[9], nodeb[9];
  1908. int i, j, r;
  1909. for (j = 0; j < 9; j++) {
  1910. hdnode_from_seed(
  1911. fromhex(
  1912. "301133282ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d627"
  1913. "88f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  1914. 64, SECP256K1_NAME, &(nodea[j]));
  1915. hdnode_from_seed(
  1916. fromhex(
  1917. "301133282ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d627"
  1918. "88f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  1919. 64, SECP256K1_NAME, &(nodeb[j]));
  1920. }
  1921. uint32_t ii[] = {0x80000001, 0x80000002, 0x80000003, 0x80000004,
  1922. 0x80000005, 0x80000006, 0x80000007, 0x80000008};
  1923. for (j = 0; j < 9; j++) {
  1924. // non cached
  1925. for (i = 1; i <= j; i++) {
  1926. r = hdnode_private_ckd(&(nodea[j]), ii[i - 1]);
  1927. ck_assert_int_eq(r, 1);
  1928. }
  1929. // cached
  1930. r = hdnode_private_ckd_cached(&(nodeb[j]), ii, j, NULL);
  1931. ck_assert_int_eq(r, 1);
  1932. }
  1933. ck_assert_mem_eq(&(nodea[0]), &(nodeb[0]), sizeof(HDNode));
  1934. ck_assert_mem_eq(&(nodea[1]), &(nodeb[1]), sizeof(HDNode));
  1935. ck_assert_mem_eq(&(nodea[2]), &(nodeb[2]), sizeof(HDNode));
  1936. ck_assert_mem_eq(&(nodea[3]), &(nodeb[3]), sizeof(HDNode));
  1937. ck_assert_mem_eq(&(nodea[4]), &(nodeb[4]), sizeof(HDNode));
  1938. ck_assert_mem_eq(&(nodea[5]), &(nodeb[5]), sizeof(HDNode));
  1939. ck_assert_mem_eq(&(nodea[6]), &(nodeb[6]), sizeof(HDNode));
  1940. ck_assert_mem_eq(&(nodea[7]), &(nodeb[7]), sizeof(HDNode));
  1941. ck_assert_mem_eq(&(nodea[8]), &(nodeb[8]), sizeof(HDNode));
  1942. }
  1943. END_TEST
  1944. START_TEST(test_bip32_nist_seed) {
  1945. HDNode node;
  1946. // init m
  1947. hdnode_from_seed(
  1948. fromhex(
  1949. "a7305bc8df8d0951f0cb224c0e95d7707cbdf2c6ce7e8d481fec69c7ff5e9446"),
  1950. 32, NIST256P1_NAME, &node);
  1951. // [Chain m]
  1952. ck_assert_mem_eq(
  1953. node.private_key,
  1954. fromhex(
  1955. "3b8c18469a4634517d6d0b65448f8e6c62091b45540a1743c5846be55d47d88f"),
  1956. 32);
  1957. ck_assert_mem_eq(
  1958. node.chain_code,
  1959. fromhex(
  1960. "7762f9729fed06121fd13f326884c82f59aa95c57ac492ce8c9654e60efd130c"),
  1961. 32);
  1962. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1963. ck_assert_mem_eq(
  1964. node.public_key,
  1965. fromhex(
  1966. "0383619fadcde31063d8c5cb00dbfe1713f3e6fa169d8541a798752a1c1ca0cb20"),
  1967. 33);
  1968. // init m
  1969. hdnode_from_seed(
  1970. fromhex(
  1971. "aa305bc8df8d0951f0cb29ad4568d7707cbdf2c6ce7e8d481fec69c7ff5e9446"),
  1972. 32, NIST256P1_NAME, &node);
  1973. // [Chain m]
  1974. ck_assert_mem_eq(
  1975. node.chain_code,
  1976. fromhex(
  1977. "a81d21f36f987fa0be3b065301bfb6aa9deefbf3dfef6744c37b9a4abc3c68f1"),
  1978. 32);
  1979. ck_assert_mem_eq(
  1980. node.private_key,
  1981. fromhex(
  1982. "0e49dc46ce1d8c29d9b80a05e40f5d0cd68cbf02ae98572186f5343be18084bf"),
  1983. 32);
  1984. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  1985. ck_assert_mem_eq(
  1986. node.public_key,
  1987. fromhex(
  1988. "03aaa4c89acd9a98935330773d3dae55122f3591bac4a40942681768de8df6ba63"),
  1989. 33);
  1990. }
  1991. END_TEST
  1992. START_TEST(test_bip32_nist_vector_1) {
  1993. HDNode node;
  1994. uint32_t fingerprint;
  1995. // init m
  1996. hdnode_from_seed(fromhex("000102030405060708090a0b0c0d0e0f"), 16,
  1997. NIST256P1_NAME, &node);
  1998. // [Chain m]
  1999. fingerprint = 0;
  2000. ck_assert_uint_eq(fingerprint, 0x00000000);
  2001. ck_assert_mem_eq(
  2002. node.chain_code,
  2003. fromhex(
  2004. "beeb672fe4621673f722f38529c07392fecaa61015c80c34f29ce8b41b3cb6ea"),
  2005. 32);
  2006. ck_assert_mem_eq(
  2007. node.private_key,
  2008. fromhex(
  2009. "612091aaa12e22dd2abef664f8a01a82cae99ad7441b7ef8110424915c268bc2"),
  2010. 32);
  2011. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2012. ck_assert_mem_eq(
  2013. node.public_key,
  2014. fromhex(
  2015. "0266874dc6ade47b3ecd096745ca09bcd29638dd52c2c12117b11ed3e458cfa9e8"),
  2016. 33);
  2017. // [Chain m/0']
  2018. fingerprint = hdnode_fingerprint(&node);
  2019. hdnode_private_ckd_prime(&node, 0);
  2020. ck_assert_uint_eq(fingerprint, 0xbe6105b5);
  2021. ck_assert_mem_eq(
  2022. node.chain_code,
  2023. fromhex(
  2024. "3460cea53e6a6bb5fb391eeef3237ffd8724bf0a40e94943c98b83825342ee11"),
  2025. 32);
  2026. ck_assert_mem_eq(
  2027. node.private_key,
  2028. fromhex(
  2029. "6939694369114c67917a182c59ddb8cafc3004e63ca5d3b84403ba8613debc0c"),
  2030. 32);
  2031. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2032. ck_assert_mem_eq(
  2033. node.public_key,
  2034. fromhex(
  2035. "0384610f5ecffe8fda089363a41f56a5c7ffc1d81b59a612d0d649b2d22355590c"),
  2036. 33);
  2037. // [Chain m/0'/1]
  2038. fingerprint = hdnode_fingerprint(&node);
  2039. hdnode_private_ckd(&node, 1);
  2040. ck_assert_uint_eq(fingerprint, 0x9b02312f);
  2041. ck_assert_mem_eq(
  2042. node.chain_code,
  2043. fromhex(
  2044. "4187afff1aafa8445010097fb99d23aee9f599450c7bd140b6826ac22ba21d0c"),
  2045. 32);
  2046. ck_assert_mem_eq(
  2047. node.private_key,
  2048. fromhex(
  2049. "284e9d38d07d21e4e281b645089a94f4cf5a5a81369acf151a1c3a57f18b2129"),
  2050. 32);
  2051. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2052. ck_assert_mem_eq(
  2053. node.public_key,
  2054. fromhex(
  2055. "03526c63f8d0b4bbbf9c80df553fe66742df4676b241dabefdef67733e070f6844"),
  2056. 33);
  2057. // [Chain m/0'/1/2']
  2058. fingerprint = hdnode_fingerprint(&node);
  2059. hdnode_private_ckd_prime(&node, 2);
  2060. ck_assert_uint_eq(fingerprint, 0xb98005c1);
  2061. ck_assert_mem_eq(
  2062. node.chain_code,
  2063. fromhex(
  2064. "98c7514f562e64e74170cc3cf304ee1ce54d6b6da4f880f313e8204c2a185318"),
  2065. 32);
  2066. ck_assert_mem_eq(
  2067. node.private_key,
  2068. fromhex(
  2069. "694596e8a54f252c960eb771a3c41e7e32496d03b954aeb90f61635b8e092aa7"),
  2070. 32);
  2071. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2072. ck_assert_mem_eq(
  2073. node.public_key,
  2074. fromhex(
  2075. "0359cf160040778a4b14c5f4d7b76e327ccc8c4a6086dd9451b7482b5a4972dda0"),
  2076. 33);
  2077. // [Chain m/0'/1/2'/2]
  2078. fingerprint = hdnode_fingerprint(&node);
  2079. hdnode_private_ckd(&node, 2);
  2080. ck_assert_uint_eq(fingerprint, 0x0e9f3274);
  2081. ck_assert_mem_eq(
  2082. node.chain_code,
  2083. fromhex(
  2084. "ba96f776a5c3907d7fd48bde5620ee374d4acfd540378476019eab70790c63a0"),
  2085. 32);
  2086. ck_assert_mem_eq(
  2087. node.private_key,
  2088. fromhex(
  2089. "5996c37fd3dd2679039b23ed6f70b506c6b56b3cb5e424681fb0fa64caf82aaa"),
  2090. 32);
  2091. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2092. ck_assert_mem_eq(
  2093. node.public_key,
  2094. fromhex(
  2095. "029f871f4cb9e1c97f9f4de9ccd0d4a2f2a171110c61178f84430062230833ff20"),
  2096. 33);
  2097. // [Chain m/0'/1/2'/2/1000000000]
  2098. fingerprint = hdnode_fingerprint(&node);
  2099. hdnode_private_ckd(&node, 1000000000);
  2100. ck_assert_uint_eq(fingerprint, 0x8b2b5c4b);
  2101. ck_assert_mem_eq(
  2102. node.chain_code,
  2103. fromhex(
  2104. "b9b7b82d326bb9cb5b5b121066feea4eb93d5241103c9e7a18aad40f1dde8059"),
  2105. 32);
  2106. ck_assert_mem_eq(
  2107. node.private_key,
  2108. fromhex(
  2109. "21c4f269ef0a5fd1badf47eeacebeeaa3de22eb8e5b0adcd0f27dd99d34d0119"),
  2110. 32);
  2111. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2112. ck_assert_mem_eq(
  2113. node.public_key,
  2114. fromhex(
  2115. "02216cd26d31147f72427a453c443ed2cde8a1e53c9cc44e5ddf739725413fe3f4"),
  2116. 33);
  2117. }
  2118. END_TEST
  2119. START_TEST(test_bip32_nist_vector_2) {
  2120. HDNode node;
  2121. uint32_t fingerprint;
  2122. int r;
  2123. // init m
  2124. hdnode_from_seed(
  2125. fromhex(
  2126. "fffcf9f6f3f0edeae7e4e1dedbd8d5d2cfccc9c6c3c0bdbab7b4b1aeaba8a5a29f9c"
  2127. "999693908d8a8784817e7b7875726f6c696663605d5a5754514e4b484542"),
  2128. 64, NIST256P1_NAME, &node);
  2129. // [Chain m]
  2130. fingerprint = 0;
  2131. ck_assert_uint_eq(fingerprint, 0x00000000);
  2132. ck_assert_mem_eq(
  2133. node.chain_code,
  2134. fromhex(
  2135. "96cd4465a9644e31528eda3592aa35eb39a9527769ce1855beafc1b81055e75d"),
  2136. 32);
  2137. ck_assert_mem_eq(
  2138. node.private_key,
  2139. fromhex(
  2140. "eaa31c2e46ca2962227cf21d73a7ef0ce8b31c756897521eb6c7b39796633357"),
  2141. 32);
  2142. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2143. ck_assert_mem_eq(
  2144. node.public_key,
  2145. fromhex(
  2146. "02c9e16154474b3ed5b38218bb0463e008f89ee03e62d22fdcc8014beab25b48fa"),
  2147. 33);
  2148. // [Chain m/0]
  2149. fingerprint = hdnode_fingerprint(&node);
  2150. r = hdnode_private_ckd(&node, 0);
  2151. ck_assert_int_eq(r, 1);
  2152. ck_assert_uint_eq(fingerprint, 0x607f628f);
  2153. ck_assert_mem_eq(
  2154. node.chain_code,
  2155. fromhex(
  2156. "84e9c258bb8557a40e0d041115b376dd55eda99c0042ce29e81ebe4efed9b86a"),
  2157. 32);
  2158. ck_assert_mem_eq(
  2159. node.private_key,
  2160. fromhex(
  2161. "d7d065f63a62624888500cdb4f88b6d59c2927fee9e6d0cdff9cad555884df6e"),
  2162. 32);
  2163. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2164. ck_assert_mem_eq(
  2165. node.public_key,
  2166. fromhex(
  2167. "039b6df4bece7b6c81e2adfeea4bcf5c8c8a6e40ea7ffa3cf6e8494c61a1fc82cc"),
  2168. 33);
  2169. // [Chain m/0/2147483647']
  2170. fingerprint = hdnode_fingerprint(&node);
  2171. r = hdnode_private_ckd_prime(&node, 2147483647);
  2172. ck_assert_int_eq(r, 1);
  2173. ck_assert_uint_eq(fingerprint, 0x946d2a54);
  2174. ck_assert_mem_eq(
  2175. node.chain_code,
  2176. fromhex(
  2177. "f235b2bc5c04606ca9c30027a84f353acf4e4683edbd11f635d0dcc1cd106ea6"),
  2178. 32);
  2179. ck_assert_mem_eq(
  2180. node.private_key,
  2181. fromhex(
  2182. "96d2ec9316746a75e7793684ed01e3d51194d81a42a3276858a5b7376d4b94b9"),
  2183. 32);
  2184. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2185. ck_assert_mem_eq(
  2186. node.public_key,
  2187. fromhex(
  2188. "02f89c5deb1cae4fedc9905f98ae6cbf6cbab120d8cb85d5bd9a91a72f4c068c76"),
  2189. 33);
  2190. // [Chain m/0/2147483647'/1]
  2191. fingerprint = hdnode_fingerprint(&node);
  2192. r = hdnode_private_ckd(&node, 1);
  2193. ck_assert_int_eq(r, 1);
  2194. ck_assert_uint_eq(fingerprint, 0x218182d8);
  2195. ck_assert_mem_eq(
  2196. node.chain_code,
  2197. fromhex(
  2198. "7c0b833106235e452eba79d2bdd58d4086e663bc8cc55e9773d2b5eeda313f3b"),
  2199. 32);
  2200. ck_assert_mem_eq(
  2201. node.private_key,
  2202. fromhex(
  2203. "974f9096ea6873a915910e82b29d7c338542ccde39d2064d1cc228f371542bbc"),
  2204. 32);
  2205. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2206. ck_assert_mem_eq(
  2207. node.public_key,
  2208. fromhex(
  2209. "03abe0ad54c97c1d654c1852dfdc32d6d3e487e75fa16f0fd6304b9ceae4220c64"),
  2210. 33);
  2211. // [Chain m/0/2147483647'/1/2147483646']
  2212. fingerprint = hdnode_fingerprint(&node);
  2213. r = hdnode_private_ckd_prime(&node, 2147483646);
  2214. ck_assert_int_eq(r, 1);
  2215. ck_assert_uint_eq(fingerprint, 0x931223e4);
  2216. ck_assert_mem_eq(
  2217. node.chain_code,
  2218. fromhex(
  2219. "5794e616eadaf33413aa309318a26ee0fd5163b70466de7a4512fd4b1a5c9e6a"),
  2220. 32);
  2221. ck_assert_mem_eq(
  2222. node.private_key,
  2223. fromhex(
  2224. "da29649bbfaff095cd43819eda9a7be74236539a29094cd8336b07ed8d4eff63"),
  2225. 32);
  2226. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2227. ck_assert_mem_eq(
  2228. node.public_key,
  2229. fromhex(
  2230. "03cb8cb067d248691808cd6b5a5a06b48e34ebac4d965cba33e6dc46fe13d9b933"),
  2231. 33);
  2232. // [Chain m/0/2147483647'/1/2147483646'/2]
  2233. fingerprint = hdnode_fingerprint(&node);
  2234. r = hdnode_private_ckd(&node, 2);
  2235. ck_assert_int_eq(r, 1);
  2236. ck_assert_uint_eq(fingerprint, 0x956c4629);
  2237. ck_assert_mem_eq(
  2238. node.chain_code,
  2239. fromhex(
  2240. "3bfb29ee8ac4484f09db09c2079b520ea5616df7820f071a20320366fbe226a7"),
  2241. 32);
  2242. ck_assert_mem_eq(
  2243. node.private_key,
  2244. fromhex(
  2245. "bb0a77ba01cc31d77205d51d08bd313b979a71ef4de9b062f8958297e746bd67"),
  2246. 32);
  2247. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2248. ck_assert_mem_eq(
  2249. node.public_key,
  2250. fromhex(
  2251. "020ee02e18967237cf62672983b253ee62fa4dd431f8243bfeccdf39dbe181387f"),
  2252. 33);
  2253. // init m
  2254. hdnode_from_seed(
  2255. fromhex(
  2256. "fffcf9f6f3f0edeae7e4e1dedbd8d5d2cfccc9c6c3c0bdbab7b4b1aeaba8a5a29f9c"
  2257. "999693908d8a8784817e7b7875726f6c696663605d5a5754514e4b484542"),
  2258. 64, NIST256P1_NAME, &node);
  2259. // test public derivation
  2260. // [Chain m/0]
  2261. fingerprint = hdnode_fingerprint(&node);
  2262. r = hdnode_public_ckd(&node, 0);
  2263. ck_assert_int_eq(r, 1);
  2264. ck_assert_uint_eq(fingerprint, 0x607f628f);
  2265. ck_assert_mem_eq(
  2266. node.chain_code,
  2267. fromhex(
  2268. "84e9c258bb8557a40e0d041115b376dd55eda99c0042ce29e81ebe4efed9b86a"),
  2269. 32);
  2270. ck_assert_mem_eq(
  2271. node.private_key,
  2272. fromhex(
  2273. "0000000000000000000000000000000000000000000000000000000000000000"),
  2274. 32);
  2275. ck_assert_mem_eq(
  2276. node.public_key,
  2277. fromhex(
  2278. "039b6df4bece7b6c81e2adfeea4bcf5c8c8a6e40ea7ffa3cf6e8494c61a1fc82cc"),
  2279. 33);
  2280. }
  2281. END_TEST
  2282. START_TEST(test_bip32_nist_compare) {
  2283. HDNode node1, node2, node3;
  2284. int i, r;
  2285. hdnode_from_seed(
  2286. fromhex(
  2287. "301133282ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d62788"
  2288. "f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  2289. 64, NIST256P1_NAME, &node1);
  2290. hdnode_from_seed(
  2291. fromhex(
  2292. "301133282ad079cbeb59bc446ad39d333928f74c46997d3609cd3e2801ca69d62788"
  2293. "f9f174429946ff4e9be89f67c22fae28cb296a9b37734f75e73d1477af19"),
  2294. 64, NIST256P1_NAME, &node2);
  2295. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2296. for (i = 0; i < 100; i++) {
  2297. memcpy(&node3, &node1, sizeof(HDNode));
  2298. ck_assert_int_eq(hdnode_fill_public_key(&node3), 0);
  2299. r = hdnode_private_ckd(&node1, i);
  2300. ck_assert_int_eq(r, 1);
  2301. r = hdnode_public_ckd(&node2, i);
  2302. ck_assert_int_eq(r, 1);
  2303. r = hdnode_public_ckd(&node3, i);
  2304. ck_assert_int_eq(r, 1);
  2305. ck_assert_uint_eq(node1.depth, node2.depth);
  2306. ck_assert_uint_eq(node1.depth, node3.depth);
  2307. ck_assert_uint_eq(node1.child_num, node2.child_num);
  2308. ck_assert_uint_eq(node1.child_num, node3.child_num);
  2309. ck_assert_mem_eq(node1.chain_code, node2.chain_code, 32);
  2310. ck_assert_mem_eq(node1.chain_code, node3.chain_code, 32);
  2311. ck_assert_mem_eq(
  2312. node2.private_key,
  2313. fromhex(
  2314. "0000000000000000000000000000000000000000000000000000000000000000"),
  2315. 32);
  2316. ck_assert_mem_eq(
  2317. node3.private_key,
  2318. fromhex(
  2319. "0000000000000000000000000000000000000000000000000000000000000000"),
  2320. 32);
  2321. ck_assert_int_eq(hdnode_fill_public_key(&node1), 0);
  2322. ck_assert_mem_eq(node1.public_key, node2.public_key, 33);
  2323. ck_assert_mem_eq(node1.public_key, node3.public_key, 33);
  2324. }
  2325. }
  2326. END_TEST
  2327. START_TEST(test_bip32_nist_repeat) {
  2328. HDNode node, node2;
  2329. uint32_t fingerprint;
  2330. int r;
  2331. // init m
  2332. hdnode_from_seed(fromhex("000102030405060708090a0b0c0d0e0f"), 16,
  2333. NIST256P1_NAME, &node);
  2334. // [Chain m/28578']
  2335. fingerprint = hdnode_fingerprint(&node);
  2336. r = hdnode_private_ckd_prime(&node, 28578);
  2337. ck_assert_int_eq(r, 1);
  2338. ck_assert_uint_eq(fingerprint, 0xbe6105b5);
  2339. ck_assert_mem_eq(
  2340. node.chain_code,
  2341. fromhex(
  2342. "e94c8ebe30c2250a14713212f6449b20f3329105ea15b652ca5bdfc68f6c65c2"),
  2343. 32);
  2344. ck_assert_mem_eq(
  2345. node.private_key,
  2346. fromhex(
  2347. "06f0db126f023755d0b8d86d4591718a5210dd8d024e3e14b6159d63f53aa669"),
  2348. 32);
  2349. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2350. ck_assert_mem_eq(
  2351. node.public_key,
  2352. fromhex(
  2353. "02519b5554a4872e8c9c1c847115363051ec43e93400e030ba3c36b52a3e70a5b7"),
  2354. 33);
  2355. memcpy(&node2, &node, sizeof(HDNode));
  2356. fingerprint = hdnode_fingerprint(&node);
  2357. r = hdnode_private_ckd(&node2, 33941);
  2358. ck_assert_int_eq(r, 1);
  2359. ck_assert_uint_eq(fingerprint, 0x3e2b7bc6);
  2360. ck_assert_mem_eq(
  2361. node2.chain_code,
  2362. fromhex(
  2363. "9e87fe95031f14736774cd82f25fd885065cb7c358c1edf813c72af535e83071"),
  2364. 32);
  2365. ck_assert_mem_eq(
  2366. node2.private_key,
  2367. fromhex(
  2368. "092154eed4af83e078ff9b84322015aefe5769e31270f62c3f66c33888335f3a"),
  2369. 32);
  2370. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2371. ck_assert_mem_eq(
  2372. node2.public_key,
  2373. fromhex(
  2374. "0235bfee614c0d5b2cae260000bb1d0d84b270099ad790022c1ae0b2e782efe120"),
  2375. 33);
  2376. memcpy(&node2, &node, sizeof(HDNode));
  2377. memzero(&node2.private_key, 32);
  2378. r = hdnode_public_ckd(&node2, 33941);
  2379. ck_assert_int_eq(r, 1);
  2380. ck_assert_uint_eq(fingerprint, 0x3e2b7bc6);
  2381. ck_assert_mem_eq(
  2382. node2.chain_code,
  2383. fromhex(
  2384. "9e87fe95031f14736774cd82f25fd885065cb7c358c1edf813c72af535e83071"),
  2385. 32);
  2386. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2387. ck_assert_mem_eq(
  2388. node2.public_key,
  2389. fromhex(
  2390. "0235bfee614c0d5b2cae260000bb1d0d84b270099ad790022c1ae0b2e782efe120"),
  2391. 33);
  2392. }
  2393. END_TEST
  2394. // test vector 1 from https://en.bitcoin.it/wiki/BIP_0032_TestVectors
  2395. START_TEST(test_bip32_ed25519_vector_1) {
  2396. HDNode node;
  2397. // init m
  2398. hdnode_from_seed(fromhex("000102030405060708090a0b0c0d0e0f"), 16,
  2399. ED25519_NAME, &node);
  2400. // [Chain m]
  2401. ck_assert_mem_eq(
  2402. node.chain_code,
  2403. fromhex(
  2404. "90046a93de5380a72b5e45010748567d5ea02bbf6522f979e05c0d8d8ca9fffb"),
  2405. 32);
  2406. ck_assert_mem_eq(
  2407. node.private_key,
  2408. fromhex(
  2409. "2b4be7f19ee27bbf30c667b642d5f4aa69fd169872f8fc3059c08ebae2eb19e7"),
  2410. 32);
  2411. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2412. ck_assert_mem_eq(
  2413. node.public_key,
  2414. fromhex(
  2415. "01a4b2856bfec510abab89753fac1ac0e1112364e7d250545963f135f2a33188ed"),
  2416. 33);
  2417. // [Chain m/0']
  2418. hdnode_private_ckd_prime(&node, 0);
  2419. ck_assert_mem_eq(
  2420. node.chain_code,
  2421. fromhex(
  2422. "8b59aa11380b624e81507a27fedda59fea6d0b779a778918a2fd3590e16e9c69"),
  2423. 32);
  2424. ck_assert_mem_eq(
  2425. node.private_key,
  2426. fromhex(
  2427. "68e0fe46dfb67e368c75379acec591dad19df3cde26e63b93a8e704f1dade7a3"),
  2428. 32);
  2429. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2430. ck_assert_mem_eq(
  2431. node.public_key,
  2432. fromhex(
  2433. "018c8a13df77a28f3445213a0f432fde644acaa215fc72dcdf300d5efaa85d350c"),
  2434. 33);
  2435. // [Chain m/0'/1']
  2436. hdnode_private_ckd_prime(&node, 1);
  2437. ck_assert_mem_eq(
  2438. node.chain_code,
  2439. fromhex(
  2440. "a320425f77d1b5c2505a6b1b27382b37368ee640e3557c315416801243552f14"),
  2441. 32);
  2442. ck_assert_mem_eq(
  2443. node.private_key,
  2444. fromhex(
  2445. "b1d0bad404bf35da785a64ca1ac54b2617211d2777696fbffaf208f746ae84f2"),
  2446. 32);
  2447. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2448. ck_assert_mem_eq(
  2449. node.public_key,
  2450. fromhex(
  2451. "011932a5270f335bed617d5b935c80aedb1a35bd9fc1e31acafd5372c30f5c1187"),
  2452. 33);
  2453. // [Chain m/0'/1'/2']
  2454. hdnode_private_ckd_prime(&node, 2);
  2455. ck_assert_mem_eq(
  2456. node.chain_code,
  2457. fromhex(
  2458. "2e69929e00b5ab250f49c3fb1c12f252de4fed2c1db88387094a0f8c4c9ccd6c"),
  2459. 32);
  2460. ck_assert_mem_eq(
  2461. node.private_key,
  2462. fromhex(
  2463. "92a5b23c0b8a99e37d07df3fb9966917f5d06e02ddbd909c7e184371463e9fc9"),
  2464. 32);
  2465. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2466. ck_assert_mem_eq(
  2467. node.public_key,
  2468. fromhex(
  2469. "01ae98736566d30ed0e9d2f4486a64bc95740d89c7db33f52121f8ea8f76ff0fc1"),
  2470. 33);
  2471. // [Chain m/0'/1'/2'/2']
  2472. hdnode_private_ckd_prime(&node, 2);
  2473. ck_assert_mem_eq(
  2474. node.chain_code,
  2475. fromhex(
  2476. "8f6d87f93d750e0efccda017d662a1b31a266e4a6f5993b15f5c1f07f74dd5cc"),
  2477. 32);
  2478. ck_assert_mem_eq(
  2479. node.private_key,
  2480. fromhex(
  2481. "30d1dc7e5fc04c31219ab25a27ae00b50f6fd66622f6e9c913253d6511d1e662"),
  2482. 32);
  2483. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2484. ck_assert_mem_eq(
  2485. node.public_key,
  2486. fromhex(
  2487. "018abae2d66361c879b900d204ad2cc4984fa2aa344dd7ddc46007329ac76c429c"),
  2488. 33);
  2489. // [Chain m/0'/1'/2'/2'/1000000000']
  2490. hdnode_private_ckd_prime(&node, 1000000000);
  2491. ck_assert_mem_eq(
  2492. node.chain_code,
  2493. fromhex(
  2494. "68789923a0cac2cd5a29172a475fe9e0fb14cd6adb5ad98a3fa70333e7afa230"),
  2495. 32);
  2496. ck_assert_mem_eq(
  2497. node.private_key,
  2498. fromhex(
  2499. "8f94d394a8e8fd6b1bc2f3f49f5c47e385281d5c17e65324b0f62483e37e8793"),
  2500. 32);
  2501. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2502. ck_assert_mem_eq(
  2503. node.public_key,
  2504. fromhex(
  2505. "013c24da049451555d51a7014a37337aa4e12d41e485abccfa46b47dfb2af54b7a"),
  2506. 33);
  2507. }
  2508. END_TEST
  2509. // test vector 2 from https://en.bitcoin.it/wiki/BIP_0032_TestVectors
  2510. START_TEST(test_bip32_ed25519_vector_2) {
  2511. HDNode node;
  2512. int r;
  2513. // init m
  2514. hdnode_from_seed(
  2515. fromhex(
  2516. "fffcf9f6f3f0edeae7e4e1dedbd8d5d2cfccc9c6c3c0bdbab7b4b1aeaba8a5a29f9c"
  2517. "999693908d8a8784817e7b7875726f6c696663605d5a5754514e4b484542"),
  2518. 64, ED25519_NAME, &node);
  2519. // [Chain m]
  2520. ck_assert_mem_eq(
  2521. node.chain_code,
  2522. fromhex(
  2523. "ef70a74db9c3a5af931b5fe73ed8e1a53464133654fd55e7a66f8570b8e33c3b"),
  2524. 32);
  2525. ck_assert_mem_eq(
  2526. node.private_key,
  2527. fromhex(
  2528. "171cb88b1b3c1db25add599712e36245d75bc65a1a5c9e18d76f9f2b1eab4012"),
  2529. 32);
  2530. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2531. ck_assert_mem_eq(
  2532. node.public_key,
  2533. fromhex(
  2534. "018fe9693f8fa62a4305a140b9764c5ee01e455963744fe18204b4fb948249308a"),
  2535. 33);
  2536. // [Chain m/0']
  2537. r = hdnode_private_ckd_prime(&node, 0);
  2538. ck_assert_int_eq(r, 1);
  2539. ck_assert_mem_eq(
  2540. node.chain_code,
  2541. fromhex(
  2542. "0b78a3226f915c082bf118f83618a618ab6dec793752624cbeb622acb562862d"),
  2543. 32);
  2544. ck_assert_mem_eq(
  2545. node.private_key,
  2546. fromhex(
  2547. "1559eb2bbec5790b0c65d8693e4d0875b1747f4970ae8b650486ed7470845635"),
  2548. 32);
  2549. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2550. ck_assert_mem_eq(
  2551. node.public_key,
  2552. fromhex(
  2553. "0186fab68dcb57aa196c77c5f264f215a112c22a912c10d123b0d03c3c28ef1037"),
  2554. 33);
  2555. // [Chain m/0'/2147483647']
  2556. r = hdnode_private_ckd_prime(&node, 2147483647);
  2557. ck_assert_int_eq(r, 1);
  2558. ck_assert_mem_eq(
  2559. node.chain_code,
  2560. fromhex(
  2561. "138f0b2551bcafeca6ff2aa88ba8ed0ed8de070841f0c4ef0165df8181eaad7f"),
  2562. 32);
  2563. ck_assert_mem_eq(
  2564. node.private_key,
  2565. fromhex(
  2566. "ea4f5bfe8694d8bb74b7b59404632fd5968b774ed545e810de9c32a4fb4192f4"),
  2567. 32);
  2568. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2569. ck_assert_mem_eq(
  2570. node.public_key,
  2571. fromhex(
  2572. "015ba3b9ac6e90e83effcd25ac4e58a1365a9e35a3d3ae5eb07b9e4d90bcf7506d"),
  2573. 33);
  2574. // [Chain m/0'/2147483647'/1']
  2575. r = hdnode_private_ckd_prime(&node, 1);
  2576. ck_assert_int_eq(r, 1);
  2577. ck_assert_mem_eq(
  2578. node.chain_code,
  2579. fromhex(
  2580. "73bd9fff1cfbde33a1b846c27085f711c0fe2d66fd32e139d3ebc28e5a4a6b90"),
  2581. 32);
  2582. ck_assert_mem_eq(
  2583. node.private_key,
  2584. fromhex(
  2585. "3757c7577170179c7868353ada796c839135b3d30554bbb74a4b1e4a5a58505c"),
  2586. 32);
  2587. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2588. ck_assert_mem_eq(
  2589. node.public_key,
  2590. fromhex(
  2591. "012e66aa57069c86cc18249aecf5cb5a9cebbfd6fadeab056254763874a9352b45"),
  2592. 33);
  2593. // [Chain m/0'/2147483647'/1'/2147483646']
  2594. r = hdnode_private_ckd_prime(&node, 2147483646);
  2595. ck_assert_int_eq(r, 1);
  2596. ck_assert_mem_eq(
  2597. node.chain_code,
  2598. fromhex(
  2599. "0902fe8a29f9140480a00ef244bd183e8a13288e4412d8389d140aac1794825a"),
  2600. 32);
  2601. ck_assert_mem_eq(
  2602. node.private_key,
  2603. fromhex(
  2604. "5837736c89570de861ebc173b1086da4f505d4adb387c6a1b1342d5e4ac9ec72"),
  2605. 32);
  2606. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2607. ck_assert_mem_eq(
  2608. node.public_key,
  2609. fromhex(
  2610. "01e33c0f7d81d843c572275f287498e8d408654fdf0d1e065b84e2e6f157aab09b"),
  2611. 33);
  2612. // [Chain m/0'/2147483647'/1'/2147483646'/2']
  2613. r = hdnode_private_ckd_prime(&node, 2);
  2614. ck_assert_int_eq(r, 1);
  2615. ck_assert_mem_eq(
  2616. node.chain_code,
  2617. fromhex(
  2618. "5d70af781f3a37b829f0d060924d5e960bdc02e85423494afc0b1a41bbe196d4"),
  2619. 32);
  2620. ck_assert_mem_eq(
  2621. node.private_key,
  2622. fromhex(
  2623. "551d333177df541ad876a60ea71f00447931c0a9da16f227c11ea080d7391b8d"),
  2624. 32);
  2625. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2626. ck_assert_mem_eq(
  2627. node.public_key,
  2628. fromhex(
  2629. "0147150c75db263559a70d5778bf36abbab30fb061ad69f69ece61a72b0cfa4fc0"),
  2630. 33);
  2631. }
  2632. END_TEST
  2633. // test vector 1 from
  2634. // https://github.com/decred/dcrd/blob/master/hdkeychain/extendedkey_test.go
  2635. START_TEST(test_bip32_decred_vector_1) {
  2636. HDNode node, node2, node3;
  2637. uint32_t fingerprint;
  2638. char str[XPUB_MAXLEN];
  2639. int r;
  2640. // init m
  2641. hdnode_from_seed(fromhex("000102030405060708090a0b0c0d0e0f"), 16,
  2642. SECP256K1_NAME, &node);
  2643. // secp256k1_decred_info.bip32_name != "Bitcoin seed" so we cannot use it in
  2644. // hdnode_from_seed
  2645. node.curve = &secp256k1_decred_info;
  2646. // [Chain m]
  2647. fingerprint = 0;
  2648. ck_assert_uint_eq(fingerprint, 0x00000000);
  2649. ck_assert_mem_eq(
  2650. node.chain_code,
  2651. fromhex(
  2652. "873dff81c02f525623fd1fe5167eac3a55a049de3d314bb42ee227ffed37d508"),
  2653. 32);
  2654. ck_assert_mem_eq(
  2655. node.private_key,
  2656. fromhex(
  2657. "e8f32e723decf4051aefac8e2c93c9c5b214313817cdb01a1494b917c8436b35"),
  2658. 32);
  2659. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2660. ck_assert_mem_eq(
  2661. node.public_key,
  2662. fromhex(
  2663. "0339a36013301597daef41fbe593a02cc513d0b55527ec2df1050e2e8ff49c85c2"),
  2664. 33);
  2665. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  2666. sizeof(str));
  2667. ck_assert_str_eq(str,
  2668. "dprv3hCznBesA6jBtmoyVFPfyMSZ1qYZ3WdjdebquvkEfmRfxC9VFEFi2YD"
  2669. "aJqHnx7uGe75eGSa3Mn3oHK11hBW7KZUrPxwbCPBmuCi1nwm182s");
  2670. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  2671. SECP256K1_DECRED_NAME, &node2, NULL);
  2672. ck_assert_int_eq(r, 0);
  2673. ck_assert_int_eq(r, 0);
  2674. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2675. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  2676. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  2677. sizeof(str));
  2678. ck_assert_str_eq(str,
  2679. "dpubZ9169KDAEUnyoBhjjmT2VaEodr6pUTDoqCEAeqgbfr2JfkB88BbK77j"
  2680. "bTYbcYXb2FVz7DKBdW4P618yd51MwF8DjKVopSbS7Lkgi6bowX5w");
  2681. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  2682. SECP256K1_DECRED_NAME, &node2, NULL);
  2683. ck_assert_int_eq(r, 0);
  2684. memcpy(&node3, &node, sizeof(HDNode));
  2685. memzero(&node3.private_key, 32);
  2686. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  2687. // [Chain m/0']
  2688. fingerprint = hdnode_fingerprint(&node);
  2689. hdnode_private_ckd_prime(&node, 0);
  2690. ck_assert_uint_eq(fingerprint, 0xbc495588);
  2691. ck_assert_mem_eq(
  2692. node.chain_code,
  2693. fromhex(
  2694. "47fdacbd0f1097043b78c63c20c34ef4ed9a111d980047ad16282c7ae6236141"),
  2695. 32);
  2696. ck_assert_mem_eq(
  2697. node.private_key,
  2698. fromhex(
  2699. "edb2e14f9ee77d26dd93b4ecede8d16ed408ce149b6cd80b0715a2d911a0afea"),
  2700. 32);
  2701. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2702. ck_assert_mem_eq(
  2703. node.public_key,
  2704. fromhex(
  2705. "035a784662a4a20a65bf6aab9ae98a6c068a81c52e4b032c0fb5400c706cfccc56"),
  2706. 33);
  2707. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  2708. sizeof(str));
  2709. ck_assert_str_eq(str,
  2710. "dprv3kUQDBztdyjKuwnaL3hfKYpT7W6X2huYH5d61YSWFBebSYwEBHAXJkC"
  2711. "pQ7rvMAxPzKqxVCGLvBqWvGxXjAyMJsV1XwKkfnQCM9KctC8k8bk");
  2712. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  2713. SECP256K1_DECRED_NAME, &node2, NULL);
  2714. ck_assert_int_eq(r, 0);
  2715. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2716. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  2717. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  2718. sizeof(str));
  2719. ck_assert_str_eq(str,
  2720. "dpubZCGVaKZBiMo7pMgLaZm1qmchjWenTeVcUdFQkTNsFGFEA6xs4EW8PKi"
  2721. "qYqP7HBAitt9Hw16VQkQ1tjsZQSHNWFc6bEK6bLqrbco24FzBTY4");
  2722. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  2723. SECP256K1_DECRED_NAME, &node2, NULL);
  2724. ck_assert_int_eq(r, 0);
  2725. memcpy(&node3, &node, sizeof(HDNode));
  2726. memzero(&node3.private_key, 32);
  2727. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  2728. // [Chain m/0'/1]
  2729. fingerprint = hdnode_fingerprint(&node);
  2730. hdnode_private_ckd(&node, 1);
  2731. ck_assert_uint_eq(fingerprint, 0xc67bc2ef);
  2732. ck_assert_mem_eq(
  2733. node.chain_code,
  2734. fromhex(
  2735. "2a7857631386ba23dacac34180dd1983734e444fdbf774041578e9b6adb37c19"),
  2736. 32);
  2737. ck_assert_mem_eq(
  2738. node.private_key,
  2739. fromhex(
  2740. "3c6cb8d0f6a264c91ea8b5030fadaa8e538b020f0a387421a12de9319dc93368"),
  2741. 32);
  2742. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2743. ck_assert_mem_eq(
  2744. node.public_key,
  2745. fromhex(
  2746. "03501e454bf00751f24b1b489aa925215d66af2234e3891c3b21a52bedb3cd711c"),
  2747. 33);
  2748. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  2749. sizeof(str));
  2750. ck_assert_str_eq(str,
  2751. "dprv3nRtCZ5VAoHW4RUwQgRafSNRPUDFrmsgyY71A5eoZceVfuyL9SbZe2r"
  2752. "cbwDW2UwpkEniE4urffgbypegscNchPajWzy9QS4cRxF8QYXsZtq");
  2753. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  2754. SECP256K1_DECRED_NAME, &node2, NULL);
  2755. ck_assert_int_eq(r, 0);
  2756. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2757. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  2758. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  2759. sizeof(str));
  2760. ck_assert_str_eq(str,
  2761. "dpubZEDyZgdnFBMHxqNhfCUwBfAg1UmXHiTmB5jKtzbAZhF8PTzy2PwAicN"
  2762. "dkg1CmW6TARxQeUbgC7nAQenJts4YoG3KMiqcjsjgeMvwLc43w6C");
  2763. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  2764. SECP256K1_DECRED_NAME, &node2, NULL);
  2765. ck_assert_int_eq(r, 0);
  2766. memcpy(&node3, &node, sizeof(HDNode));
  2767. memzero(&node3.private_key, 32);
  2768. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  2769. // [Chain m/0'/1/2']
  2770. fingerprint = hdnode_fingerprint(&node);
  2771. hdnode_private_ckd_prime(&node, 2);
  2772. ck_assert_uint_eq(fingerprint, 0xe7072187);
  2773. ck_assert_mem_eq(
  2774. node.chain_code,
  2775. fromhex(
  2776. "04466b9cc8e161e966409ca52986c584f07e9dc81f735db683c3ff6ec7b1503f"),
  2777. 32);
  2778. ck_assert_mem_eq(
  2779. node.private_key,
  2780. fromhex(
  2781. "cbce0d719ecf7431d88e6a89fa1483e02e35092af60c042b1df2ff59fa424dca"),
  2782. 32);
  2783. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2784. ck_assert_mem_eq(
  2785. node.public_key,
  2786. fromhex(
  2787. "0357bfe1e341d01c69fe5654309956cbea516822fba8a601743a012a7896ee8dc2"),
  2788. 33);
  2789. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  2790. sizeof(str));
  2791. ck_assert_str_eq(str,
  2792. "dprv3pYtkZK168vgrU38gXkUSjHQ2LGpEUzQ9fXrR8fGUR59YviSnm6U82X"
  2793. "jQYhpJEUPnVcC9bguJBQU5xVM4VFcDHu9BgScGPA6mQMH4bn5Cth");
  2794. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  2795. SECP256K1_DECRED_NAME, &node2, NULL);
  2796. ck_assert_int_eq(r, 0);
  2797. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2798. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  2799. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  2800. sizeof(str));
  2801. ck_assert_str_eq(str,
  2802. "dpubZGLz7gsJAWzUksvtw3opxx5eeLq5fRaUMDABA3bdUVfnGUk5fiS5Cc3"
  2803. "kZGTjWtYr3jrEavQQnAF6jv2WCpZtFX4uFgifXqev6ED1TM9rTCB");
  2804. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  2805. SECP256K1_DECRED_NAME, &node2, NULL);
  2806. ck_assert_int_eq(r, 0);
  2807. memcpy(&node3, &node, sizeof(HDNode));
  2808. memzero(&node3.private_key, 32);
  2809. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  2810. // [Chain m/0'/1/2'/2]
  2811. fingerprint = hdnode_fingerprint(&node);
  2812. hdnode_private_ckd(&node, 2);
  2813. ck_assert_uint_eq(fingerprint, 0xbcbbc1c4);
  2814. ck_assert_mem_eq(
  2815. node.chain_code,
  2816. fromhex(
  2817. "cfb71883f01676f587d023cc53a35bc7f88f724b1f8c2892ac1275ac822a3edd"),
  2818. 32);
  2819. ck_assert_mem_eq(
  2820. node.private_key,
  2821. fromhex(
  2822. "0f479245fb19a38a1954c5c7c0ebab2f9bdfd96a17563ef28a6a4b1a2a764ef4"),
  2823. 32);
  2824. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2825. ck_assert_mem_eq(
  2826. node.public_key,
  2827. fromhex(
  2828. "02e8445082a72f29b75ca48748a914df60622a609cacfce8ed0e35804560741d29"),
  2829. 33);
  2830. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  2831. sizeof(str));
  2832. ck_assert_str_eq(str,
  2833. "dprv3r7zqYFjT3NiNzdnwGxGpYh6S1TJCp1zA6mSEGaqLBJFnCB94cRMp7Y"
  2834. "YLR49aTZHZ7ya1CXwQJ6rodKeU9NgQTxkPSK7pzgZRgjYkQ7rgJh");
  2835. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  2836. SECP256K1_DECRED_NAME, &node2, NULL);
  2837. ck_assert_int_eq(r, 0);
  2838. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2839. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  2840. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  2841. sizeof(str));
  2842. ck_assert_str_eq(str,
  2843. "dpubZHv6Cfp2XRSWHQXZBo1dLmVM421Zdkc4MePkyBXCLFttVkCmwZkxth4"
  2844. "ZV9PzkFP3DtD5xcVq2CPSYpJMWMaoxu1ixz4GNZFVcE2xnHP6chJ");
  2845. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  2846. SECP256K1_DECRED_NAME, &node2, NULL);
  2847. ck_assert_int_eq(r, 0);
  2848. memcpy(&node3, &node, sizeof(HDNode));
  2849. memzero(&node3.private_key, 32);
  2850. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  2851. // [Chain m/0'/1/2'/2/1000000000]
  2852. fingerprint = hdnode_fingerprint(&node);
  2853. hdnode_private_ckd(&node, 1000000000);
  2854. ck_assert_uint_eq(fingerprint, 0xe58b52e4);
  2855. ck_assert_mem_eq(
  2856. node.chain_code,
  2857. fromhex(
  2858. "c783e67b921d2beb8f6b389cc646d7263b4145701dadd2161548a8b078e65e9e"),
  2859. 32);
  2860. ck_assert_mem_eq(
  2861. node.private_key,
  2862. fromhex(
  2863. "471b76e389e528d6de6d816857e012c5455051cad6660850e58372a6c3e6e7c8"),
  2864. 32);
  2865. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2866. ck_assert_mem_eq(
  2867. node.public_key,
  2868. fromhex(
  2869. "022a471424da5e657499d1ff51cb43c47481a03b1e77f951fe64cec9f5a48f7011"),
  2870. 33);
  2871. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  2872. sizeof(str));
  2873. ck_assert_str_eq(str,
  2874. "dprv3tJXnTDSb3uE6Euo6WvvhFKfBMNfxuJt5smqyPoHEoomoBMQyhYoQSK"
  2875. "JAHWtWxmuqdUVb8q9J2NaTkF6rYm6XDrSotkJ55bM21fffa7VV97");
  2876. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  2877. SECP256K1_DECRED_NAME, &node2, NULL);
  2878. ck_assert_int_eq(r, 0);
  2879. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2880. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  2881. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  2882. sizeof(str));
  2883. ck_assert_str_eq(str,
  2884. "dpubZL6d9amjfRy1zeoZM2zHDU7uoMvwPqtxHRQAiJjeEtQQWjP3retQV1q"
  2885. "KJyzUd6ZJNgbJGXjtc5pdoBcTTYTLoxQzvV9JJCzCjB2eCWpRf8T");
  2886. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  2887. SECP256K1_DECRED_NAME, &node2, NULL);
  2888. ck_assert_int_eq(r, 0);
  2889. memcpy(&node3, &node, sizeof(HDNode));
  2890. memzero(&node3.private_key, 32);
  2891. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  2892. }
  2893. END_TEST
  2894. // test vector 2 from
  2895. // https://github.com/decred/dcrd/blob/master/hdkeychain/extendedkey_test.go
  2896. START_TEST(test_bip32_decred_vector_2) {
  2897. HDNode node, node2, node3;
  2898. uint32_t fingerprint;
  2899. char str[XPUB_MAXLEN];
  2900. int r;
  2901. // init m
  2902. hdnode_from_seed(
  2903. fromhex(
  2904. "fffcf9f6f3f0edeae7e4e1dedbd8d5d2cfccc9c6c3c0bdbab7b4b1aeaba8a5a29f9c"
  2905. "999693908d8a8784817e7b7875726f6c696663605d5a5754514e4b484542"),
  2906. 64, SECP256K1_NAME, &node);
  2907. // secp256k1_decred_info.bip32_name != "Bitcoin seed" so we cannot use it in
  2908. // hdnode_from_seed
  2909. node.curve = &secp256k1_decred_info;
  2910. // [Chain m]
  2911. fingerprint = 0;
  2912. ck_assert_uint_eq(fingerprint, 0x00000000);
  2913. ck_assert_mem_eq(
  2914. node.chain_code,
  2915. fromhex(
  2916. "60499f801b896d83179a4374aeb7822aaeaceaa0db1f85ee3e904c4defbd9689"),
  2917. 32);
  2918. ck_assert_mem_eq(
  2919. node.private_key,
  2920. fromhex(
  2921. "4b03d6fc340455b363f51020ad3ecca4f0850280cf436c70c727923f6db46c3e"),
  2922. 32);
  2923. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2924. ck_assert_mem_eq(
  2925. node.public_key,
  2926. fromhex(
  2927. "03cbcaa9c98c877a26977d00825c956a238e8dddfbd322cce4f74b0b5bd6ace4a7"),
  2928. 33);
  2929. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  2930. sizeof(str));
  2931. ck_assert_str_eq(str,
  2932. "dprv3hCznBesA6jBtPKJbQTxRZAKG2gyj8tZKEPaCsV4e9YYFBAgRP2eTSP"
  2933. "Aeu4r8dTMt9q51j2Vdt5zNqj7jbtovvocrP1qLj6WUTLF9xYQt4y");
  2934. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  2935. SECP256K1_DECRED_NAME, &node2, NULL);
  2936. ck_assert_int_eq(r, 0);
  2937. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2938. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  2939. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  2940. sizeof(str));
  2941. ck_assert_str_eq(str,
  2942. "dpubZ9169KDAEUnynoD4qvXJwmxZt3FFA5UdWn1twnRReE9AxjCKJLNFY1u"
  2943. "BoegbFmwzA4Du7yqnu8tLivhrCCH6P3DgBS1HH5vmf8MpNXvvYT9");
  2944. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  2945. SECP256K1_DECRED_NAME, &node2, NULL);
  2946. ck_assert_int_eq(r, 0);
  2947. memcpy(&node3, &node, sizeof(HDNode));
  2948. memzero(&node3.private_key, 32);
  2949. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  2950. // [Chain m/0]
  2951. fingerprint = hdnode_fingerprint(&node);
  2952. r = hdnode_private_ckd(&node, 0);
  2953. ck_assert_int_eq(r, 1);
  2954. ck_assert_uint_eq(fingerprint, 0x2524c9d3);
  2955. ck_assert_mem_eq(
  2956. node.chain_code,
  2957. fromhex(
  2958. "f0909affaa7ee7abe5dd4e100598d4dc53cd709d5a5c2cac40e7412f232f7c9c"),
  2959. 32);
  2960. ck_assert_mem_eq(
  2961. node.private_key,
  2962. fromhex(
  2963. "abe74a98f6c7eabee0428f53798f0ab8aa1bd37873999041703c742f15ac7e1e"),
  2964. 32);
  2965. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  2966. ck_assert_mem_eq(
  2967. node.public_key,
  2968. fromhex(
  2969. "02fc9e5af0ac8d9b3cecfe2a888e2117ba3d089d8585886c9c826b6b22a98d12ea"),
  2970. 33);
  2971. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  2972. sizeof(str));
  2973. ck_assert_str_eq(str,
  2974. "dprv3jMy45BuuDETfxi59P8NTSjHPrNVq4wPRfLgRd57923L2hosj5NUEqi"
  2975. "LYQ4i7fJtUpiXZLr2wUeToJY2Tm5sCpAJdajEHDmieVJiPQNXwu9");
  2976. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  2977. SECP256K1_DECRED_NAME, &node2, NULL);
  2978. ck_assert_int_eq(r, 0);
  2979. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  2980. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  2981. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  2982. sizeof(str));
  2983. ck_assert_str_eq(str,
  2984. "dpubZBA4RCkCybJFaNbqPuBiyfXY1rvmG1XTdCy1AY1U96dxkFqWc2i5KRE"
  2985. "Mh7NYPpy7ZPMhdpFMAesex3JdFDfX4J5FEW3HjSacqEYPfwb9Cj7");
  2986. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  2987. SECP256K1_DECRED_NAME, &node2, NULL);
  2988. ck_assert_int_eq(r, 0);
  2989. memcpy(&node3, &node, sizeof(HDNode));
  2990. memzero(&node3.private_key, 32);
  2991. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  2992. // [Chain m/0/2147483647']
  2993. fingerprint = hdnode_fingerprint(&node);
  2994. r = hdnode_private_ckd_prime(&node, 2147483647);
  2995. ck_assert_int_eq(r, 1);
  2996. ck_assert_uint_eq(fingerprint, 0x6035c6ad);
  2997. ck_assert_mem_eq(
  2998. node.chain_code,
  2999. fromhex(
  3000. "be17a268474a6bb9c61e1d720cf6215e2a88c5406c4aee7b38547f585c9a37d9"),
  3001. 32);
  3002. ck_assert_mem_eq(
  3003. node.private_key,
  3004. fromhex(
  3005. "877c779ad9687164e9c2f4f0f4ff0340814392330693ce95a58fe18fd52e6e93"),
  3006. 32);
  3007. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  3008. ck_assert_mem_eq(
  3009. node.public_key,
  3010. fromhex(
  3011. "03c01e7425647bdefa82b12d9bad5e3e6865bee0502694b94ca58b666abc0a5c3b"),
  3012. 33);
  3013. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  3014. sizeof(str));
  3015. ck_assert_str_eq(str,
  3016. "dprv3mgHPRgK838mLK6T1p6WeBoJoJtXA1pGTHjqFuyHekcM7UTuER8fGwe"
  3017. "RRsoLqSuHa98uskVPnJnfWZEBUC1AVmXnSCPDvUFKydXNnnPHTuQ");
  3018. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  3019. SECP256K1_DECRED_NAME, &node2, NULL);
  3020. ck_assert_int_eq(r, 0);
  3021. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  3022. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  3023. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  3024. sizeof(str));
  3025. ck_assert_str_eq(str,
  3026. "dpubZDUNkZEcCRCZEizDGL9sAQbZRKSnaxQLeqN9zpueeqCyq2VY7NUGMXA"
  3027. "SacsK96S8XzNjq3YgFgwLtj8MJBToW6To9U5zxuazEyh89bjR1xA");
  3028. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  3029. SECP256K1_DECRED_NAME, &node2, NULL);
  3030. ck_assert_int_eq(r, 0);
  3031. memcpy(&node3, &node, sizeof(HDNode));
  3032. memzero(&node3.private_key, 32);
  3033. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  3034. // [Chain m/0/2147483647'/1]
  3035. fingerprint = hdnode_fingerprint(&node);
  3036. r = hdnode_private_ckd(&node, 1);
  3037. ck_assert_int_eq(r, 1);
  3038. ck_assert_uint_eq(fingerprint, 0x36fc7080);
  3039. ck_assert_mem_eq(
  3040. node.chain_code,
  3041. fromhex(
  3042. "f366f48f1ea9f2d1d3fe958c95ca84ea18e4c4ddb9366c336c927eb246fb38cb"),
  3043. 32);
  3044. ck_assert_mem_eq(
  3045. node.private_key,
  3046. fromhex(
  3047. "704addf544a06e5ee4bea37098463c23613da32020d604506da8c0518e1da4b7"),
  3048. 32);
  3049. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  3050. ck_assert_mem_eq(
  3051. node.public_key,
  3052. fromhex(
  3053. "03a7d1d856deb74c508e05031f9895dab54626251b3806e16b4bd12e781a7df5b9"),
  3054. 33);
  3055. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  3056. sizeof(str));
  3057. ck_assert_str_eq(str,
  3058. "dprv3oFqwZZ9bJcUmhAeJyyshvrTWtrAsHfcRYQbEzNiiH5nGvM6wVTDn6w"
  3059. "oQEz92b2EHTYZBtLi82jKEnxSouA3cVaW8YWBsw5c3f4mwAhA3d2");
  3060. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  3061. SECP256K1_DECRED_NAME, &node2, NULL);
  3062. ck_assert_int_eq(r, 0);
  3063. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  3064. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  3065. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  3066. sizeof(str));
  3067. ck_assert_str_eq(str,
  3068. "dpubZF3wJh7SfggGg74QZW3EE9ei8uQSJEFgd62uyuK5iMgQzUNjpSnprgT"
  3069. "pYz3d6Q3fXXtEEXQqpzWcP4LUVuXFsgA8JKt1Hot5kyUk4pPRhDz");
  3070. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  3071. SECP256K1_DECRED_NAME, &node2, NULL);
  3072. ck_assert_int_eq(r, 0);
  3073. memcpy(&node3, &node, sizeof(HDNode));
  3074. memzero(&node3.private_key, 32);
  3075. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  3076. // [Chain m/0/2147483647'/1/2147483646']
  3077. fingerprint = hdnode_fingerprint(&node);
  3078. r = hdnode_private_ckd_prime(&node, 2147483646);
  3079. ck_assert_int_eq(r, 1);
  3080. ck_assert_uint_eq(fingerprint, 0x45309b4c);
  3081. ck_assert_mem_eq(
  3082. node.chain_code,
  3083. fromhex(
  3084. "637807030d55d01f9a0cb3a7839515d796bd07706386a6eddf06cc29a65a0e29"),
  3085. 32);
  3086. ck_assert_mem_eq(
  3087. node.private_key,
  3088. fromhex(
  3089. "f1c7c871a54a804afe328b4c83a1c33b8e5ff48f5087273f04efa83b247d6a2d"),
  3090. 32);
  3091. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  3092. ck_assert_mem_eq(
  3093. node.public_key,
  3094. fromhex(
  3095. "02d2b36900396c9282fa14628566582f206a5dd0bcc8d5e892611806cafb0301f0"),
  3096. 33);
  3097. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  3098. sizeof(str));
  3099. ck_assert_str_eq(str,
  3100. "dprv3qF3177i87wMirg6sraDvqty8yZg6THpXFPSXuM5AShBiiUQbq8FhSZ"
  3101. "DGkYmBNR3RKfBrxzkKDBpsRFJfTnQfLsvpPPqRnakat6hHQA43X9");
  3102. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  3103. SECP256K1_DECRED_NAME, &node2, NULL);
  3104. ck_assert_int_eq(r, 0);
  3105. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  3106. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  3107. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  3108. sizeof(str));
  3109. ck_assert_str_eq(str,
  3110. "dpubZH38NEg1CW19dGZs8NdaT4hDkz7wXPstio1mGpHSAXHpSGW3UnTrn25"
  3111. "ERT1Mp8ae5GMoQHMbgQiPrChMXQMdx3UqS8YqFkT1pqait8fY92u");
  3112. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  3113. SECP256K1_DECRED_NAME, &node2, NULL);
  3114. ck_assert_int_eq(r, 0);
  3115. memcpy(&node3, &node, sizeof(HDNode));
  3116. memzero(&node3.private_key, 32);
  3117. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  3118. // [Chain m/0/2147483647'/1/2147483646'/2]
  3119. fingerprint = hdnode_fingerprint(&node);
  3120. r = hdnode_private_ckd(&node, 2);
  3121. ck_assert_int_eq(r, 1);
  3122. ck_assert_uint_eq(fingerprint, 0x3491a5e6);
  3123. ck_assert_mem_eq(
  3124. node.chain_code,
  3125. fromhex(
  3126. "9452b549be8cea3ecb7a84bec10dcfd94afe4d129ebfd3b3cb58eedf394ed271"),
  3127. 32);
  3128. ck_assert_mem_eq(
  3129. node.private_key,
  3130. fromhex(
  3131. "bb7d39bdb83ecf58f2fd82b6d918341cbef428661ef01ab97c28a4842125ac23"),
  3132. 32);
  3133. ck_assert_int_eq(hdnode_fill_public_key(&node), 0);
  3134. ck_assert_mem_eq(
  3135. node.public_key,
  3136. fromhex(
  3137. "024d902e1a2fc7a8755ab5b694c575fce742c48d9ff192e63df5193e4c7afe1f9c"),
  3138. 33);
  3139. hdnode_serialize_private(&node, fingerprint, DECRED_VERSION_PRIVATE, str,
  3140. sizeof(str));
  3141. ck_assert_str_eq(str,
  3142. "dprv3s15tfqzxhw8Kmo7RBEqMeyvC7uGekLniSmvbs3bckpxQ6ks1KKqfmH"
  3143. "144Jgh3PLxkyZRcS367kp7DrtUmnG16NpnsoNhxSXRgKbJJ7MUQR");
  3144. r = hdnode_deserialize_private(str, DECRED_VERSION_PRIVATE,
  3145. SECP256K1_DECRED_NAME, &node2, NULL);
  3146. ck_assert_int_eq(r, 0);
  3147. ck_assert_int_eq(hdnode_fill_public_key(&node2), 0);
  3148. ck_assert_mem_eq(&node, &node2, sizeof(HDNode));
  3149. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  3150. sizeof(str));
  3151. ck_assert_str_eq(str,
  3152. "dpubZJoBFoQJ35zvEBgsfhJBssnAp8TY5gvruzQFLmyxcqRb7enVtGfSkLo"
  3153. "2CkAZJMpa6T2fx6fUtvTgXtUvSVgAZ56bEwGxQsToeZfFV8VadE1");
  3154. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  3155. SECP256K1_DECRED_NAME, &node2, NULL);
  3156. ck_assert_int_eq(r, 0);
  3157. memcpy(&node3, &node, sizeof(HDNode));
  3158. memzero(&node3.private_key, 32);
  3159. ck_assert_mem_eq(&node2, &node3, sizeof(HDNode));
  3160. // init m
  3161. hdnode_deserialize_public(
  3162. "dpubZF4LSCdF9YKZfNzTVYhz4RBxsjYXqms8AQnMBHXZ8GUKoRSigG7kQnKiJt5pzk93Q8Fx"
  3163. "cdVBEkQZruSXduGtWnkwXzGnjbSovQ97dCxqaXc",
  3164. DECRED_VERSION_PUBLIC, SECP256K1_DECRED_NAME, &node, NULL);
  3165. // test public derivation
  3166. // [Chain m/0]
  3167. fingerprint = hdnode_fingerprint(&node);
  3168. r = hdnode_public_ckd(&node, 0);
  3169. ck_assert_int_eq(r, 1);
  3170. ck_assert_uint_eq(fingerprint, 0x6a19cfb3);
  3171. ck_assert_mem_eq(
  3172. node.chain_code,
  3173. fromhex(
  3174. "dcfe00831741a3a4803955147cdfc7053d69b167b1d03b5f9e63934217a005fd"),
  3175. 32);
  3176. ck_assert_mem_eq(
  3177. node.public_key,
  3178. fromhex(
  3179. "029555ea7bde276cd2c42c4502f40b5d16469fb310ae3aeee2a9000455f41b0866"),
  3180. 33);
  3181. hdnode_serialize_public(&node, fingerprint, DECRED_VERSION_PUBLIC, str,
  3182. sizeof(str));
  3183. ck_assert_str_eq(str,
  3184. "dpubZHJs2Z3PtHbbpaXQCi5wBKPhU8tC5ztBKUYBCYNGKk8eZ1EmBs3MhnL"
  3185. "JbxHFMAahGnDnZT7qZxC7AXKP8PB6BDNUZgkG77moNMRmXyQ6s6s");
  3186. r = hdnode_deserialize_public(str, DECRED_VERSION_PUBLIC,
  3187. SECP256K1_DECRED_NAME, &node2, NULL);
  3188. ck_assert_int_eq(r, 0);
  3189. ck_assert_mem_eq(&node2, &node, sizeof(HDNode));
  3190. }
  3191. END_TEST
  3192. static void test_ecdsa_get_public_key33_helper(int (*ecdsa_get_public_key33_fn)(
  3193. const ecdsa_curve *, const uint8_t *, uint8_t *)) {
  3194. uint8_t privkey[32] = {0};
  3195. uint8_t pubkey[65] = {0};
  3196. const ecdsa_curve *curve = &secp256k1;
  3197. int res = 0;
  3198. memcpy(
  3199. privkey,
  3200. fromhex(
  3201. "c46f5b217f04ff28886a89d3c762ed84e5fa318d1c9a635d541131e69f1f49f5"),
  3202. 32);
  3203. res = ecdsa_get_public_key33_fn(curve, privkey, pubkey);
  3204. ck_assert_int_eq(res, 0);
  3205. ck_assert_mem_eq(
  3206. pubkey,
  3207. fromhex(
  3208. "0232b062e9153f573c220b1be0299d6447e81577274bf11a7c08dff71384c6b6ec"),
  3209. 33);
  3210. memcpy(
  3211. privkey,
  3212. fromhex(
  3213. "3b90a4de80fb00d77795762c389d1279d4b4ab5992ae3cde6bc12ca63116f74c"),
  3214. 32);
  3215. res = ecdsa_get_public_key33_fn(curve, privkey, pubkey);
  3216. ck_assert_int_eq(res, 0);
  3217. ck_assert_mem_eq(
  3218. pubkey,
  3219. fromhex(
  3220. "0332b062e9153f573c220b1be0299d6447e81577274bf11a7c08dff71384c6b6ec"),
  3221. 33);
  3222. }
  3223. START_TEST(test_ecdsa_get_public_key33) {
  3224. test_ecdsa_get_public_key33_helper(ecdsa_get_public_key33);
  3225. }
  3226. END_TEST
  3227. START_TEST(test_zkp_ecdsa_get_public_key33) {
  3228. test_ecdsa_get_public_key33_helper(zkp_ecdsa_get_public_key33);
  3229. }
  3230. END_TEST
  3231. static void test_ecdsa_get_public_key65_helper(int (*ecdsa_get_public_key65_fn)(
  3232. const ecdsa_curve *, const uint8_t *, uint8_t *)) {
  3233. uint8_t privkey[32] = {0};
  3234. uint8_t pubkey[65] = {0};
  3235. const ecdsa_curve *curve = &secp256k1;
  3236. int res = 0;
  3237. memcpy(
  3238. privkey,
  3239. fromhex(
  3240. "c46f5b217f04ff28886a89d3c762ed84e5fa318d1c9a635d541131e69f1f49f5"),
  3241. 32);
  3242. res = ecdsa_get_public_key65_fn(curve, privkey, pubkey);
  3243. ck_assert_int_eq(res, 0);
  3244. ck_assert_mem_eq(
  3245. pubkey,
  3246. fromhex(
  3247. "0432b062e9153f573c220b1be0299d6447e81577274bf11a7c08dff71384c6b6ec"
  3248. "179ca56b637a57e0fcd28cefa10c9433dc30532682647f4daa053d43d5cc960a"),
  3249. 65);
  3250. }
  3251. START_TEST(test_ecdsa_get_public_key65) {
  3252. test_ecdsa_get_public_key65_helper(ecdsa_get_public_key65);
  3253. }
  3254. END_TEST
  3255. START_TEST(test_zkp_ecdsa_get_public_key65) {
  3256. test_ecdsa_get_public_key65_helper(zkp_ecdsa_get_public_key65);
  3257. }
  3258. END_TEST
  3259. static void test_ecdsa_recover_pub_from_sig_helper(int (
  3260. *ecdsa_recover_pub_from_sig_fn)(const ecdsa_curve *, uint8_t *,
  3261. const uint8_t *, const uint8_t *, int)) {
  3262. int res;
  3263. uint8_t digest[32];
  3264. uint8_t pubkey[65];
  3265. const ecdsa_curve *curve = &secp256k1;
  3266. // sha2(sha2("\x18Bitcoin Signed Message:\n\x0cHello World!"))
  3267. memcpy(
  3268. digest,
  3269. fromhex(
  3270. "de4e9524586d6fce45667f9ff12f661e79870c4105fa0fb58af976619bb11432"),
  3271. 32);
  3272. // r = 2: Four points should exist
  3273. res = ecdsa_recover_pub_from_sig_fn(
  3274. curve, pubkey,
  3275. fromhex(
  3276. "00000000000000000000000000000000000000000000000000000000000000020123"
  3277. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3278. digest, 0);
  3279. ck_assert_int_eq(res, 0);
  3280. ck_assert_mem_eq(
  3281. pubkey,
  3282. fromhex(
  3283. "043fc5bf5fec35b6ffe6fd246226d312742a8c296bfa57dd22da509a2e348529b7dd"
  3284. "b9faf8afe1ecda3c05e7b2bda47ee1f5a87e952742b22afca560b29d972fcf"),
  3285. 65);
  3286. res = ecdsa_recover_pub_from_sig_fn(
  3287. curve, pubkey,
  3288. fromhex(
  3289. "00000000000000000000000000000000000000000000000000000000000000020123"
  3290. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3291. digest, 1);
  3292. ck_assert_int_eq(res, 0);
  3293. ck_assert_mem_eq(
  3294. pubkey,
  3295. fromhex(
  3296. "0456d8089137b1fd0d890f8c7d4a04d0fd4520a30b19518ee87bd168ea12ed809032"
  3297. "9274c4c6c0d9df04515776f2741eeffc30235d596065d718c3973e19711ad0"),
  3298. 65);
  3299. res = ecdsa_recover_pub_from_sig_fn(
  3300. curve, pubkey,
  3301. fromhex(
  3302. "00000000000000000000000000000000000000000000000000000000000000020123"
  3303. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3304. digest, 2);
  3305. ck_assert_int_eq(res, 0);
  3306. ck_assert_mem_eq(
  3307. pubkey,
  3308. fromhex(
  3309. "04cee0e740f41aab39156844afef0182dea2a8026885b10454a2d539df6f6df9023a"
  3310. "bfcb0f01c50bef3c0fa8e59a998d07441e18b1c60583ef75cc8b912fb21a15"),
  3311. 65);
  3312. res = ecdsa_recover_pub_from_sig_fn(
  3313. curve, pubkey,
  3314. fromhex(
  3315. "00000000000000000000000000000000000000000000000000000000000000020123"
  3316. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3317. digest, 3);
  3318. ck_assert_int_eq(res, 0);
  3319. ck_assert_mem_eq(
  3320. pubkey,
  3321. fromhex(
  3322. "0490d2bd2e9a564d6e1d8324fc6ad00aa4ae597684ecf4abea58bdfe7287ea4fa729"
  3323. "68c2e5b0b40999ede3d7898d94e82c3f8dc4536a567a4bd45998c826a4c4b2"),
  3324. 65);
  3325. // The point at infinity is not considered to be a valid public key.
  3326. res = ecdsa_recover_pub_from_sig_fn(
  3327. curve, pubkey,
  3328. fromhex(
  3329. "220cf4c7b6d568f2256a8c30cc1784a625a28c3627dac404aa9a9ecd08314ec81a88"
  3330. "828f20d69d102bab5de5f6ee7ef040cb0ff7b8e1ba3f29d79efb5250f47d"),
  3331. digest, 0);
  3332. ck_assert_int_eq(res, 1);
  3333. memcpy(
  3334. digest,
  3335. fromhex(
  3336. "0000000000000000000000000000000000000000000000000000000000000000"),
  3337. 32);
  3338. // r = 7: No point P with P.x = 7, but P.x = (order + 7) exists
  3339. res = ecdsa_recover_pub_from_sig_fn(
  3340. curve, pubkey,
  3341. fromhex(
  3342. "00000000000000000000000000000000000000000000000000000000000000070123"
  3343. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3344. digest, 2);
  3345. ck_assert_int_eq(res, 0);
  3346. ck_assert_mem_eq(
  3347. pubkey,
  3348. fromhex(
  3349. "044d81bb47a31ffc6cf1f780ecb1e201ec47214b651650867c07f13ad06e12a1b040"
  3350. "de78f8dbda700f4d3cd7ee21b3651a74c7661809699d2be7ea0992b0d39797"),
  3351. 65);
  3352. res = ecdsa_recover_pub_from_sig_fn(
  3353. curve, pubkey,
  3354. fromhex(
  3355. "00000000000000000000000000000000000000000000000000000000000000070123"
  3356. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3357. digest, 3);
  3358. ck_assert_int_eq(res, 0);
  3359. ck_assert_mem_eq(
  3360. pubkey,
  3361. fromhex(
  3362. "044d81bb47a31ffc6cf1f780ecb1e201ec47214b651650867c07f13ad06e12a1b0bf"
  3363. "21870724258ff0b2c32811de4c9ae58b3899e7f69662d41815f66c4f2c6498"),
  3364. 65);
  3365. res = ecdsa_recover_pub_from_sig_fn(
  3366. curve, pubkey,
  3367. fromhex(
  3368. "00000000000000000000000000000000000000000000000000000000000000070123"
  3369. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3370. digest, 0);
  3371. ck_assert_int_eq(res, 1);
  3372. memcpy(
  3373. digest,
  3374. fromhex(
  3375. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"),
  3376. 32);
  3377. // r = 1: Two points P with P.x = 1, but P.x = (order + 7) doesn't exist
  3378. res = ecdsa_recover_pub_from_sig_fn(
  3379. curve, pubkey,
  3380. fromhex(
  3381. "00000000000000000000000000000000000000000000000000000000000000010123"
  3382. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3383. digest, 0);
  3384. ck_assert_int_eq(res, 0);
  3385. ck_assert_mem_eq(
  3386. pubkey,
  3387. fromhex(
  3388. "045d330b2f89dbfca149828277bae852dd4aebfe136982cb531a88e9e7a89463fe71"
  3389. "519f34ea8feb9490c707f14bc38c9ece51762bfd034ea014719b7c85d2871b"),
  3390. 65);
  3391. res = ecdsa_recover_pub_from_sig_fn(
  3392. curve, pubkey,
  3393. fromhex(
  3394. "00000000000000000000000000000000000000000000000000000000000000010123"
  3395. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3396. digest, 1);
  3397. ck_assert_int_eq(res, 0);
  3398. ck_assert_mem_eq(
  3399. pubkey,
  3400. fromhex(
  3401. "049e609c3950e70d6f3e3f3c81a473b1d5ca72739d51debdd80230ae80cab05134a9"
  3402. "4285375c834a417e8115c546c41da83a263087b79ef1cae25c7b3c738daa2b"),
  3403. 65);
  3404. // r = 0 is always invalid
  3405. res = ecdsa_recover_pub_from_sig_fn(
  3406. curve, pubkey,
  3407. fromhex(
  3408. "00000000000000000000000000000000000000000000000000000000000000010123"
  3409. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3410. digest, 2);
  3411. ck_assert_int_eq(res, 1);
  3412. res = ecdsa_recover_pub_from_sig_fn(
  3413. curve, pubkey,
  3414. fromhex(
  3415. "00000000000000000000000000000000000000000000000000000000000000000123"
  3416. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3417. digest, 0);
  3418. ck_assert_int_eq(res, 1);
  3419. // r >= order is always invalid
  3420. res = ecdsa_recover_pub_from_sig_fn(
  3421. curve, pubkey,
  3422. fromhex(
  3423. "fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd03641410123"
  3424. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3425. digest, 0);
  3426. ck_assert_int_eq(res, 1);
  3427. // check that overflow of r is handled
  3428. res = ecdsa_recover_pub_from_sig_fn(
  3429. curve, pubkey,
  3430. fromhex(
  3431. "000000000000000000000000000000014551231950B75FC4402DA1722FC9BAEE0123"
  3432. "456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"),
  3433. digest, 2);
  3434. ck_assert_int_eq(res, 1);
  3435. // s = 0 is always invalid
  3436. res = ecdsa_recover_pub_from_sig_fn(
  3437. curve, pubkey,
  3438. fromhex(
  3439. "00000000000000000000000000000000000000000000000000000000000000020000"
  3440. "000000000000000000000000000000000000000000000000000000000000"),
  3441. digest, 0);
  3442. ck_assert_int_eq(res, 1);
  3443. // s >= order is always invalid
  3444. res = ecdsa_recover_pub_from_sig_fn(
  3445. curve, pubkey,
  3446. fromhex(
  3447. "0000000000000000000000000000000000000000000000000000000000000002ffff"
  3448. "fffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141"),
  3449. digest, 0);
  3450. ck_assert_int_eq(res, 1);
  3451. }
  3452. START_TEST(test_ecdsa_recover_pub_from_sig) {
  3453. test_ecdsa_recover_pub_from_sig_helper(ecdsa_recover_pub_from_sig);
  3454. }
  3455. END_TEST
  3456. START_TEST(test_zkp_ecdsa_recover_pub_from_sig) {
  3457. test_ecdsa_recover_pub_from_sig_helper(zkp_ecdsa_recover_pub_from_sig);
  3458. }
  3459. END_TEST
  3460. static void test_ecdsa_verify_digest_helper(int (*ecdsa_verify_digest_fn)(
  3461. const ecdsa_curve *, const uint8_t *, const uint8_t *, const uint8_t *)) {
  3462. int res;
  3463. uint8_t digest[32];
  3464. uint8_t pubkey[65];
  3465. uint8_t sig[64];
  3466. const ecdsa_curve *curve = &secp256k1;
  3467. // Signature verification for a digest which is equal to the group order.
  3468. // https://github.com/trezor/trezor-firmware/pull/1374
  3469. memcpy(
  3470. pubkey,
  3471. fromhex(
  3472. "0479be667ef9dcbbac55a06295ce870b07029bfcdb2dce28d959f2815b16f8179848"
  3473. "3ada7726a3c4655da4fbfc0e1108a8fd17b448a68554199c47d08ffb10d4b8"),
  3474. sizeof(pubkey));
  3475. memcpy(
  3476. digest,
  3477. fromhex(
  3478. "fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141"),
  3479. sizeof(digest));
  3480. memcpy(sig,
  3481. fromhex(
  3482. "a0b37f8fba683cc68f6574cd43b39f0343a50008bf6ccea9d13231d9e7e2e1e41"
  3483. "1edc8d307254296264aebfc3dc76cd8b668373a072fd64665b50000e9fcce52"),
  3484. sizeof(sig));
  3485. res = ecdsa_verify_digest_fn(curve, pubkey, sig, digest);
  3486. ck_assert_int_eq(res, 0);
  3487. }
  3488. START_TEST(test_ecdsa_verify_digest) {
  3489. test_ecdsa_verify_digest_helper(ecdsa_verify_digest);
  3490. }
  3491. END_TEST
  3492. START_TEST(test_zkp_ecdsa_verify_digest) {
  3493. test_ecdsa_verify_digest_helper(zkp_ecdsa_verify_digest);
  3494. }
  3495. END_TEST
  3496. #define test_deterministic(KEY, MSG, K) \
  3497. do { \
  3498. sha256_Raw((uint8_t *)MSG, strlen(MSG), buf); \
  3499. init_rfc6979(fromhex(KEY), buf, NULL, &rng); \
  3500. generate_k_rfc6979(&k, &rng); \
  3501. bn_write_be(&k, buf); \
  3502. ck_assert_mem_eq(buf, fromhex(K), 32); \
  3503. } while (0)
  3504. START_TEST(test_rfc6979) {
  3505. bignum256 k;
  3506. uint8_t buf[32];
  3507. rfc6979_state rng;
  3508. test_deterministic(
  3509. "c9afa9d845ba75166b5c215767b1d6934e50c3db36e89b127b8a622b120f6721",
  3510. "sample",
  3511. "a6e3c57dd01abe90086538398355dd4c3b17aa873382b0f24d6129493d8aad60");
  3512. test_deterministic(
  3513. "cca9fbcc1b41e5a95d369eaa6ddcff73b61a4efaa279cfc6567e8daa39cbaf50",
  3514. "sample",
  3515. "2df40ca70e639d89528a6b670d9d48d9165fdc0febc0974056bdce192b8e16a3");
  3516. test_deterministic(
  3517. "0000000000000000000000000000000000000000000000000000000000000001",
  3518. "Satoshi Nakamoto",
  3519. "8f8a276c19f4149656b280621e358cce24f5f52542772691ee69063b74f15d15");
  3520. test_deterministic(
  3521. "fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364140",
  3522. "Satoshi Nakamoto",
  3523. "33a19b60e25fb6f4435af53a3d42d493644827367e6453928554f43e49aa6f90");
  3524. test_deterministic(
  3525. "f8b8af8ce3c7cca5e300d33939540c10d45ce001b8f252bfbc57ba0342904181",
  3526. "Alan Turing",
  3527. "525a82b70e67874398067543fd84c83d30c175fdc45fdeee082fe13b1d7cfdf1");
  3528. test_deterministic(
  3529. "0000000000000000000000000000000000000000000000000000000000000001",
  3530. "All those moments will be lost in time, like tears in rain. Time to "
  3531. "die...",
  3532. "38aa22d72376b4dbc472e06c3ba403ee0a394da63fc58d88686c611aba98d6b3");
  3533. test_deterministic(
  3534. "e91671c46231f833a6406ccbea0e3e392c76c167bac1cb013f6f1013980455c2",
  3535. "There is a computer disease that anybody who works with computers knows "
  3536. "about. It's a very serious disease and it interferes completely with "
  3537. "the work. The trouble with computers is that you 'play' with them!",
  3538. "1f4b84c23a86a221d233f2521be018d9318639d5b8bbd6374a8a59232d16ad3d");
  3539. }
  3540. END_TEST
  3541. static void test_ecdsa_sign_digest_deterministic_helper(
  3542. int (*ecdsa_sign_digest_fn)(const ecdsa_curve *, const uint8_t *,
  3543. const uint8_t *, uint8_t *, uint8_t *,
  3544. int (*)(uint8_t by, uint8_t sig[64]))) {
  3545. static struct {
  3546. const char *priv_key;
  3547. const char *digest;
  3548. const char *sig;
  3549. } tests[] = {
  3550. {"312155017c70a204106e034520e0cdf17b3e54516e2ece38e38e38e38e38e38e",
  3551. "ffffffffffffffffffffffffffffffff20202020202020202020202020202020",
  3552. "e3d70248ea2fc771fc8d5e62d76b9cfd5402c96990333549eaadce1ae9f737eb"
  3553. "5cfbdc7d1e0ec18cc9b57bbb18f0a57dc929ec3c4dfac9073c581705015f6a8a"},
  3554. {"312155017c70a204106e034520e0cdf17b3e54516e2ece38e38e38e38e38e38e",
  3555. "2020202020202020202020202020202020202020202020202020202020202020",
  3556. "40666188895430715552a7e4c6b53851f37a93030fb94e043850921242db78e8"
  3557. "75aa2ac9fd7e5a19402973e60e64382cdc29a09ebf6cb37e92f23be5b9251aee"},
  3558. };
  3559. const ecdsa_curve *curve = &secp256k1;
  3560. uint8_t priv_key[32] = {0};
  3561. uint8_t digest[32] = {0};
  3562. uint8_t expected_sig[64] = {0};
  3563. uint8_t computed_sig[64] = {0};
  3564. int res = 0;
  3565. for (size_t i = 0; i < sizeof(tests) / sizeof(*tests); i++) {
  3566. memcpy(priv_key, fromhex(tests[i].priv_key), 32);
  3567. memcpy(digest, fromhex(tests[i].digest), 32);
  3568. memcpy(expected_sig, fromhex(tests[i].sig), 64);
  3569. res =
  3570. ecdsa_sign_digest_fn(curve, priv_key, digest, computed_sig, NULL, NULL);
  3571. ck_assert_int_eq(res, 0);
  3572. ck_assert_mem_eq(expected_sig, computed_sig, 64);
  3573. }
  3574. }
  3575. START_TEST(test_ecdsa_sign_digest_deterministic) {
  3576. test_ecdsa_sign_digest_deterministic_helper(ecdsa_sign_digest);
  3577. }
  3578. END_TEST
  3579. START_TEST(test_zkp_ecdsa_sign_digest_deterministic) {
  3580. test_ecdsa_sign_digest_deterministic_helper(zkp_ecdsa_sign_digest);
  3581. }
  3582. END_TEST
  3583. // test vectors from
  3584. // http://www.inconteam.com/software-development/41-encryption/55-aes-test-vectors
  3585. START_TEST(test_aes) {
  3586. aes_encrypt_ctx ctxe;
  3587. aes_decrypt_ctx ctxd;
  3588. uint8_t ibuf[16], obuf[16], iv[16], cbuf[16];
  3589. const char **ivp, **plainp, **cipherp;
  3590. // ECB
  3591. static const char *ecb_vector[] = {
  3592. // plain cipher
  3593. "6bc1bee22e409f96e93d7e117393172a",
  3594. "f3eed1bdb5d2a03c064b5a7e3db181f8",
  3595. "ae2d8a571e03ac9c9eb76fac45af8e51",
  3596. "591ccb10d410ed26dc5ba74a31362870",
  3597. "30c81c46a35ce411e5fbc1191a0a52ef",
  3598. "b6ed21b99ca6f4f9f153e7b1beafed1d",
  3599. "f69f2445df4f9b17ad2b417be66c3710",
  3600. "23304b7a39f9f3ff067d8d8f9e24ecc7",
  3601. 0,
  3602. 0,
  3603. };
  3604. plainp = ecb_vector;
  3605. cipherp = ecb_vector + 1;
  3606. while (*plainp && *cipherp) {
  3607. // encrypt
  3608. aes_encrypt_key256(
  3609. fromhex(
  3610. "603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4"),
  3611. &ctxe);
  3612. memcpy(ibuf, fromhex(*plainp), 16);
  3613. aes_ecb_encrypt(ibuf, obuf, 16, &ctxe);
  3614. ck_assert_mem_eq(obuf, fromhex(*cipherp), 16);
  3615. // decrypt
  3616. aes_decrypt_key256(
  3617. fromhex(
  3618. "603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4"),
  3619. &ctxd);
  3620. memcpy(ibuf, fromhex(*cipherp), 16);
  3621. aes_ecb_decrypt(ibuf, obuf, 16, &ctxd);
  3622. ck_assert_mem_eq(obuf, fromhex(*plainp), 16);
  3623. plainp += 2;
  3624. cipherp += 2;
  3625. }
  3626. // CBC
  3627. static const char *cbc_vector[] = {
  3628. // iv plain cipher
  3629. "000102030405060708090A0B0C0D0E0F",
  3630. "6bc1bee22e409f96e93d7e117393172a",
  3631. "f58c4c04d6e5f1ba779eabfb5f7bfbd6",
  3632. "F58C4C04D6E5F1BA779EABFB5F7BFBD6",
  3633. "ae2d8a571e03ac9c9eb76fac45af8e51",
  3634. "9cfc4e967edb808d679f777bc6702c7d",
  3635. "9CFC4E967EDB808D679F777BC6702C7D",
  3636. "30c81c46a35ce411e5fbc1191a0a52ef",
  3637. "39f23369a9d9bacfa530e26304231461",
  3638. "39F23369A9D9BACFA530E26304231461",
  3639. "f69f2445df4f9b17ad2b417be66c3710",
  3640. "b2eb05e2c39be9fcda6c19078c6a9d1b",
  3641. 0,
  3642. 0,
  3643. 0,
  3644. };
  3645. ivp = cbc_vector;
  3646. plainp = cbc_vector + 1;
  3647. cipherp = cbc_vector + 2;
  3648. while (*plainp && *cipherp) {
  3649. // encrypt
  3650. aes_encrypt_key256(
  3651. fromhex(
  3652. "603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4"),
  3653. &ctxe);
  3654. memcpy(iv, fromhex(*ivp), 16);
  3655. memcpy(ibuf, fromhex(*plainp), 16);
  3656. aes_cbc_encrypt(ibuf, obuf, 16, iv, &ctxe);
  3657. ck_assert_mem_eq(obuf, fromhex(*cipherp), 16);
  3658. // decrypt
  3659. aes_decrypt_key256(
  3660. fromhex(
  3661. "603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4"),
  3662. &ctxd);
  3663. memcpy(iv, fromhex(*ivp), 16);
  3664. memcpy(ibuf, fromhex(*cipherp), 16);
  3665. aes_cbc_decrypt(ibuf, obuf, 16, iv, &ctxd);
  3666. ck_assert_mem_eq(obuf, fromhex(*plainp), 16);
  3667. ivp += 3;
  3668. plainp += 3;
  3669. cipherp += 3;
  3670. }
  3671. // CFB
  3672. static const char *cfb_vector[] = {
  3673. "000102030405060708090A0B0C0D0E0F",
  3674. "6bc1bee22e409f96e93d7e117393172a",
  3675. "DC7E84BFDA79164B7ECD8486985D3860",
  3676. "DC7E84BFDA79164B7ECD8486985D3860",
  3677. "ae2d8a571e03ac9c9eb76fac45af8e51",
  3678. "39ffed143b28b1c832113c6331e5407b",
  3679. "39FFED143B28B1C832113C6331E5407B",
  3680. "30c81c46a35ce411e5fbc1191a0a52ef",
  3681. "df10132415e54b92a13ed0a8267ae2f9",
  3682. "DF10132415E54B92A13ED0A8267AE2F9",
  3683. "f69f2445df4f9b17ad2b417be66c3710",
  3684. "75a385741ab9cef82031623d55b1e471",
  3685. 0,
  3686. 0,
  3687. 0,
  3688. };
  3689. ivp = cfb_vector;
  3690. plainp = cfb_vector + 1;
  3691. cipherp = cfb_vector + 2;
  3692. while (*plainp && *cipherp) {
  3693. // encrypt
  3694. aes_encrypt_key256(
  3695. fromhex(
  3696. "603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4"),
  3697. &ctxe);
  3698. memcpy(iv, fromhex(*ivp), 16);
  3699. memcpy(ibuf, fromhex(*plainp), 16);
  3700. aes_cfb_encrypt(ibuf, obuf, 16, iv, &ctxe);
  3701. ck_assert_mem_eq(obuf, fromhex(*cipherp), 16);
  3702. // decrypt (uses encryption)
  3703. aes_encrypt_key256(
  3704. fromhex(
  3705. "603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4"),
  3706. &ctxe);
  3707. memcpy(iv, fromhex(*ivp), 16);
  3708. memcpy(ibuf, fromhex(*cipherp), 16);
  3709. aes_cfb_decrypt(ibuf, obuf, 16, iv, &ctxe);
  3710. ck_assert_mem_eq(obuf, fromhex(*plainp), 16);
  3711. ivp += 3;
  3712. plainp += 3;
  3713. cipherp += 3;
  3714. }
  3715. // OFB
  3716. static const char *ofb_vector[] = {
  3717. "000102030405060708090A0B0C0D0E0F",
  3718. "6bc1bee22e409f96e93d7e117393172a",
  3719. "dc7e84bfda79164b7ecd8486985d3860",
  3720. "B7BF3A5DF43989DD97F0FA97EBCE2F4A",
  3721. "ae2d8a571e03ac9c9eb76fac45af8e51",
  3722. "4febdc6740d20b3ac88f6ad82a4fb08d",
  3723. "E1C656305ED1A7A6563805746FE03EDC",
  3724. "30c81c46a35ce411e5fbc1191a0a52ef",
  3725. "71ab47a086e86eedf39d1c5bba97c408",
  3726. "41635BE625B48AFC1666DD42A09D96E7",
  3727. "f69f2445df4f9b17ad2b417be66c3710",
  3728. "0126141d67f37be8538f5a8be740e484",
  3729. 0,
  3730. 0,
  3731. 0,
  3732. };
  3733. ivp = ofb_vector;
  3734. plainp = ofb_vector + 1;
  3735. cipherp = ofb_vector + 2;
  3736. while (*plainp && *cipherp) {
  3737. // encrypt
  3738. aes_encrypt_key256(
  3739. fromhex(
  3740. "603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4"),
  3741. &ctxe);
  3742. memcpy(iv, fromhex(*ivp), 16);
  3743. memcpy(ibuf, fromhex(*plainp), 16);
  3744. aes_ofb_encrypt(ibuf, obuf, 16, iv, &ctxe);
  3745. ck_assert_mem_eq(obuf, fromhex(*cipherp), 16);
  3746. // decrypt (uses encryption)
  3747. aes_encrypt_key256(
  3748. fromhex(
  3749. "603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4"),
  3750. &ctxe);
  3751. memcpy(iv, fromhex(*ivp), 16);
  3752. memcpy(ibuf, fromhex(*cipherp), 16);
  3753. aes_ofb_decrypt(ibuf, obuf, 16, iv, &ctxe);
  3754. ck_assert_mem_eq(obuf, fromhex(*plainp), 16);
  3755. ivp += 3;
  3756. plainp += 3;
  3757. cipherp += 3;
  3758. }
  3759. // CTR
  3760. static const char *ctr_vector[] = {
  3761. // plain cipher
  3762. "6bc1bee22e409f96e93d7e117393172a",
  3763. "601ec313775789a5b7a7f504bbf3d228",
  3764. "ae2d8a571e03ac9c9eb76fac45af8e51",
  3765. "f443e3ca4d62b59aca84e990cacaf5c5",
  3766. "30c81c46a35ce411e5fbc1191a0a52ef",
  3767. "2b0930daa23de94ce87017ba2d84988d",
  3768. "f69f2445df4f9b17ad2b417be66c3710",
  3769. "dfc9c58db67aada613c2dd08457941a6",
  3770. 0,
  3771. 0,
  3772. };
  3773. // encrypt
  3774. plainp = ctr_vector;
  3775. cipherp = ctr_vector + 1;
  3776. memcpy(cbuf, fromhex("f0f1f2f3f4f5f6f7f8f9fafbfcfdfeff"), 16);
  3777. aes_encrypt_key256(
  3778. fromhex(
  3779. "603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4"),
  3780. &ctxe);
  3781. while (*plainp && *cipherp) {
  3782. memcpy(ibuf, fromhex(*plainp), 16);
  3783. aes_ctr_encrypt(ibuf, obuf, 16, cbuf, aes_ctr_cbuf_inc, &ctxe);
  3784. ck_assert_mem_eq(obuf, fromhex(*cipherp), 16);
  3785. plainp += 2;
  3786. cipherp += 2;
  3787. }
  3788. // decrypt (uses encryption)
  3789. plainp = ctr_vector;
  3790. cipherp = ctr_vector + 1;
  3791. memcpy(cbuf, fromhex("f0f1f2f3f4f5f6f7f8f9fafbfcfdfeff"), 16);
  3792. aes_encrypt_key256(
  3793. fromhex(
  3794. "603deb1015ca71be2b73aef0857d77811f352c073b6108d72d9810a30914dff4"),
  3795. &ctxe);
  3796. while (*plainp && *cipherp) {
  3797. memcpy(ibuf, fromhex(*cipherp), 16);
  3798. aes_ctr_decrypt(ibuf, obuf, 16, cbuf, aes_ctr_cbuf_inc, &ctxe);
  3799. ck_assert_mem_eq(obuf, fromhex(*plainp), 16);
  3800. plainp += 2;
  3801. cipherp += 2;
  3802. }
  3803. }
  3804. END_TEST
  3805. #define TEST1 "abc"
  3806. #define TEST2_1 "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq"
  3807. #define TEST2_2a "abcdefghbcdefghicdefghijdefghijkefghijklfghijklmghijklmn"
  3808. #define TEST2_2b "hijklmnoijklmnopjklmnopqklmnopqrlmnopqrsmnopqrstnopqrstu"
  3809. #define TEST2_2 TEST2_2a TEST2_2b
  3810. #define TEST3 "a" /* times 1000000 */
  3811. #define TEST4a "01234567012345670123456701234567"
  3812. #define TEST4b "01234567012345670123456701234567"
  3813. /* an exact multiple of 512 bits */
  3814. #define TEST4 TEST4a TEST4b /* times 10 */
  3815. #define TEST7_1 "\x49\xb2\xae\xc2\x59\x4b\xbe\x3a\x3b\x11\x75\x42\xd9\x4a\xc8"
  3816. #define TEST8_1 \
  3817. "\x9a\x7d\xfd\xf1\xec\xea\xd0\x6e\xd6\x46\xaa\x55\xfe\x75\x71\x46"
  3818. #define TEST9_1 \
  3819. "\x65\xf9\x32\x99\x5b\xa4\xce\x2c\xb1\xb4\xa2\xe7\x1a\xe7\x02\x20" \
  3820. "\xaa\xce\xc8\x96\x2d\xd4\x49\x9c\xbd\x7c\x88\x7a\x94\xea\xaa\x10" \
  3821. "\x1e\xa5\xaa\xbc\x52\x9b\x4e\x7e\x43\x66\x5a\x5a\xf2\xcd\x03\xfe" \
  3822. "\x67\x8e\xa6\xa5\x00\x5b\xba\x3b\x08\x22\x04\xc2\x8b\x91\x09\xf4" \
  3823. "\x69\xda\xc9\x2a\xaa\xb3\xaa\x7c\x11\xa1\xb3\x2a"
  3824. #define TEST10_1 \
  3825. "\xf7\x8f\x92\x14\x1b\xcd\x17\x0a\xe8\x9b\x4f\xba\x15\xa1\xd5\x9f" \
  3826. "\x3f\xd8\x4d\x22\x3c\x92\x51\xbd\xac\xbb\xae\x61\xd0\x5e\xd1\x15" \
  3827. "\xa0\x6a\x7c\xe1\x17\xb7\xbe\xea\xd2\x44\x21\xde\xd9\xc3\x25\x92" \
  3828. "\xbd\x57\xed\xea\xe3\x9c\x39\xfa\x1f\xe8\x94\x6a\x84\xd0\xcf\x1f" \
  3829. "\x7b\xee\xad\x17\x13\xe2\xe0\x95\x98\x97\x34\x7f\x67\xc8\x0b\x04" \
  3830. "\x00\xc2\x09\x81\x5d\x6b\x10\xa6\x83\x83\x6f\xd5\x56\x2a\x56\xca" \
  3831. "\xb1\xa2\x8e\x81\xb6\x57\x66\x54\x63\x1c\xf1\x65\x66\xb8\x6e\x3b" \
  3832. "\x33\xa1\x08\xb0\x53\x07\xc0\x0a\xff\x14\xa7\x68\xed\x73\x50\x60" \
  3833. "\x6a\x0f\x85\xe6\xa9\x1d\x39\x6f\x5b\x5c\xbe\x57\x7f\x9b\x38\x80" \
  3834. "\x7c\x7d\x52\x3d\x6d\x79\x2f\x6e\xbc\x24\xa4\xec\xf2\xb3\xa4\x27" \
  3835. "\xcd\xbb\xfb"
  3836. #define length(x) (sizeof(x) - 1)
  3837. // test vectors from rfc-4634
  3838. START_TEST(test_sha1) {
  3839. struct {
  3840. const char *test;
  3841. int length;
  3842. int repeatcount;
  3843. int extrabits;
  3844. int numberExtrabits;
  3845. const char *result;
  3846. } tests[] = {
  3847. /* 1 */ {TEST1, length(TEST1), 1, 0, 0,
  3848. "A9993E364706816ABA3E25717850C26C9CD0D89D"},
  3849. /* 2 */
  3850. {TEST2_1, length(TEST2_1), 1, 0, 0,
  3851. "84983E441C3BD26EBAAE4AA1F95129E5E54670F1"},
  3852. /* 3 */
  3853. {TEST3, length(TEST3), 1000000, 0, 0,
  3854. "34AA973CD4C4DAA4F61EEB2BDBAD27316534016F"},
  3855. /* 4 */
  3856. {TEST4, length(TEST4), 10, 0, 0,
  3857. "DEA356A2CDDD90C7A7ECEDC5EBB563934F460452"},
  3858. /* 5 */ {"", 0, 0, 0x98, 5, "29826B003B906E660EFF4027CE98AF3531AC75BA"},
  3859. /* 6 */ {"\x5e", 1, 1, 0, 0, "5E6F80A34A9798CAFC6A5DB96CC57BA4C4DB59C2"},
  3860. /* 7 */
  3861. {TEST7_1, length(TEST7_1), 1, 0x80, 3,
  3862. "6239781E03729919C01955B3FFA8ACB60B988340"},
  3863. /* 8 */
  3864. {TEST8_1, length(TEST8_1), 1, 0, 0,
  3865. "82ABFF6605DBE1C17DEF12A394FA22A82B544A35"},
  3866. /* 9 */
  3867. {TEST9_1, length(TEST9_1), 1, 0xE0, 3,
  3868. "8C5B2A5DDAE5A97FC7F9D85661C672ADBF7933D4"},
  3869. /* 10 */
  3870. {TEST10_1, length(TEST10_1), 1, 0, 0,
  3871. "CB0082C8F197D260991BA6A460E76E202BAD27B3"}};
  3872. for (int i = 0; i < 10; i++) {
  3873. SHA1_CTX ctx;
  3874. uint8_t digest[SHA1_DIGEST_LENGTH];
  3875. sha1_Init(&ctx);
  3876. /* extra bits are not supported */
  3877. if (tests[i].numberExtrabits) continue;
  3878. for (int j = 0; j < tests[i].repeatcount; j++) {
  3879. sha1_Update(&ctx, (const uint8_t *)tests[i].test, tests[i].length);
  3880. }
  3881. sha1_Final(&ctx, digest);
  3882. ck_assert_mem_eq(digest, fromhex(tests[i].result), SHA1_DIGEST_LENGTH);
  3883. }
  3884. }
  3885. END_TEST
  3886. #define TEST7_256 "\xbe\x27\x46\xc6\xdb\x52\x76\x5f\xdb\x2f\x88\x70\x0f\x9a\x73"
  3887. #define TEST8_256 \
  3888. "\xe3\xd7\x25\x70\xdc\xdd\x78\x7c\xe3\x88\x7a\xb2\xcd\x68\x46\x52"
  3889. #define TEST9_256 \
  3890. "\x3e\x74\x03\x71\xc8\x10\xc2\xb9\x9f\xc0\x4e\x80\x49\x07\xef\x7c" \
  3891. "\xf2\x6b\xe2\x8b\x57\xcb\x58\xa3\xe2\xf3\xc0\x07\x16\x6e\x49\xc1" \
  3892. "\x2e\x9b\xa3\x4c\x01\x04\x06\x91\x29\xea\x76\x15\x64\x25\x45\x70" \
  3893. "\x3a\x2b\xd9\x01\xe1\x6e\xb0\xe0\x5d\xeb\xa0\x14\xeb\xff\x64\x06" \
  3894. "\xa0\x7d\x54\x36\x4e\xff\x74\x2d\xa7\x79\xb0\xb3"
  3895. #define TEST10_256 \
  3896. "\x83\x26\x75\x4e\x22\x77\x37\x2f\x4f\xc1\x2b\x20\x52\x7a\xfe\xf0" \
  3897. "\x4d\x8a\x05\x69\x71\xb1\x1a\xd5\x71\x23\xa7\xc1\x37\x76\x00\x00" \
  3898. "\xd7\xbe\xf6\xf3\xc1\xf7\xa9\x08\x3a\xa3\x9d\x81\x0d\xb3\x10\x77" \
  3899. "\x7d\xab\x8b\x1e\x7f\x02\xb8\x4a\x26\xc7\x73\x32\x5f\x8b\x23\x74" \
  3900. "\xde\x7a\x4b\x5a\x58\xcb\x5c\x5c\xf3\x5b\xce\xe6\xfb\x94\x6e\x5b" \
  3901. "\xd6\x94\xfa\x59\x3a\x8b\xeb\x3f\x9d\x65\x92\xec\xed\xaa\x66\xca" \
  3902. "\x82\xa2\x9d\x0c\x51\xbc\xf9\x33\x62\x30\xe5\xd7\x84\xe4\xc0\xa4" \
  3903. "\x3f\x8d\x79\xa3\x0a\x16\x5c\xba\xbe\x45\x2b\x77\x4b\x9c\x71\x09" \
  3904. "\xa9\x7d\x13\x8f\x12\x92\x28\x96\x6f\x6c\x0a\xdc\x10\x6a\xad\x5a" \
  3905. "\x9f\xdd\x30\x82\x57\x69\xb2\xc6\x71\xaf\x67\x59\xdf\x28\xeb\x39" \
  3906. "\x3d\x54\xd6"
  3907. // test vectors from rfc-4634
  3908. START_TEST(test_sha256) {
  3909. struct {
  3910. const char *test;
  3911. int length;
  3912. int repeatcount;
  3913. int extrabits;
  3914. int numberExtrabits;
  3915. const char *result;
  3916. } tests[] = {
  3917. /* 1 */ {TEST1, length(TEST1), 1, 0, 0,
  3918. "BA7816BF8F01CFEA4141"
  3919. "40DE5DAE2223B00361A396177A9CB410FF61F20015AD"},
  3920. /* 2 */
  3921. {TEST2_1, length(TEST2_1), 1, 0, 0,
  3922. "248D6A61D20638B8"
  3923. "E5C026930C3E6039A33CE45964FF2167F6ECEDD419DB06C1"},
  3924. /* 3 */
  3925. {TEST3, length(TEST3), 1000000, 0, 0,
  3926. "CDC76E5C9914FB92"
  3927. "81A1C7E284D73E67F1809A48A497200E046D39CCC7112CD0"},
  3928. /* 4 */
  3929. {TEST4, length(TEST4), 10, 0, 0,
  3930. "594847328451BDFA"
  3931. "85056225462CC1D867D877FB388DF0CE35F25AB5562BFBB5"},
  3932. /* 5 */
  3933. {"", 0, 0, 0x68, 5,
  3934. "D6D3E02A31A84A8CAA9718ED6C2057BE"
  3935. "09DB45E7823EB5079CE7A573A3760F95"},
  3936. /* 6 */
  3937. {"\x19", 1, 1, 0, 0,
  3938. "68AA2E2EE5DFF96E3355E6C7EE373E3D"
  3939. "6A4E17F75F9518D843709C0C9BC3E3D4"},
  3940. /* 7 */
  3941. {TEST7_256, length(TEST7_256), 1, 0x60, 3,
  3942. "77EC1DC8"
  3943. "9C821FF2A1279089FA091B35B8CD960BCAF7DE01C6A7680756BEB972"},
  3944. /* 8 */
  3945. {TEST8_256, length(TEST8_256), 1, 0, 0,
  3946. "175EE69B02BA"
  3947. "9B58E2B0A5FD13819CEA573F3940A94F825128CF4209BEABB4E8"},
  3948. /* 9 */
  3949. {TEST9_256, length(TEST9_256), 1, 0xA0, 3,
  3950. "3E9AD646"
  3951. "8BBBAD2AC3C2CDC292E018BA5FD70B960CF1679777FCE708FDB066E9"},
  3952. /* 10 */
  3953. {TEST10_256, length(TEST10_256), 1, 0, 0,
  3954. "97DBCA7D"
  3955. "F46D62C8A422C941DD7E835B8AD3361763F7E9B2D95F4F0DA6E1CCBC"},
  3956. };
  3957. for (int i = 0; i < 10; i++) {
  3958. SHA256_CTX ctx;
  3959. uint8_t digest[SHA256_DIGEST_LENGTH];
  3960. sha256_Init(&ctx);
  3961. /* extra bits are not supported */
  3962. if (tests[i].numberExtrabits) continue;
  3963. for (int j = 0; j < tests[i].repeatcount; j++) {
  3964. sha256_Update(&ctx, (const uint8_t *)tests[i].test, tests[i].length);
  3965. }
  3966. sha256_Final(&ctx, digest);
  3967. ck_assert_mem_eq(digest, fromhex(tests[i].result), SHA256_DIGEST_LENGTH);
  3968. }
  3969. }
  3970. END_TEST
  3971. #define TEST7_512 "\x08\xec\xb5\x2e\xba\xe1\xf7\x42\x2d\xb6\x2b\xcd\x54\x26\x70"
  3972. #define TEST8_512 \
  3973. "\x8d\x4e\x3c\x0e\x38\x89\x19\x14\x91\x81\x6e\x9d\x98\xbf\xf0\xa0"
  3974. #define TEST9_512 \
  3975. "\x3a\xdd\xec\x85\x59\x32\x16\xd1\x61\x9a\xa0\x2d\x97\x56\x97\x0b" \
  3976. "\xfc\x70\xac\xe2\x74\x4f\x7c\x6b\x27\x88\x15\x10\x28\xf7\xb6\xa2" \
  3977. "\x55\x0f\xd7\x4a\x7e\x6e\x69\xc2\xc9\xb4\x5f\xc4\x54\x96\x6d\xc3" \
  3978. "\x1d\x2e\x10\xda\x1f\x95\xce\x02\xbe\xb4\xbf\x87\x65\x57\x4c\xbd" \
  3979. "\x6e\x83\x37\xef\x42\x0a\xdc\x98\xc1\x5c\xb6\xd5\xe4\xa0\x24\x1b" \
  3980. "\xa0\x04\x6d\x25\x0e\x51\x02\x31\xca\xc2\x04\x6c\x99\x16\x06\xab" \
  3981. "\x4e\xe4\x14\x5b\xee\x2f\xf4\xbb\x12\x3a\xab\x49\x8d\x9d\x44\x79" \
  3982. "\x4f\x99\xcc\xad\x89\xa9\xa1\x62\x12\x59\xed\xa7\x0a\x5b\x6d\xd4" \
  3983. "\xbd\xd8\x77\x78\xc9\x04\x3b\x93\x84\xf5\x49\x06"
  3984. #define TEST10_512 \
  3985. "\xa5\x5f\x20\xc4\x11\xaa\xd1\x32\x80\x7a\x50\x2d\x65\x82\x4e\x31" \
  3986. "\xa2\x30\x54\x32\xaa\x3d\x06\xd3\xe2\x82\xa8\xd8\x4e\x0d\xe1\xde" \
  3987. "\x69\x74\xbf\x49\x54\x69\xfc\x7f\x33\x8f\x80\x54\xd5\x8c\x26\xc4" \
  3988. "\x93\x60\xc3\xe8\x7a\xf5\x65\x23\xac\xf6\xd8\x9d\x03\xe5\x6f\xf2" \
  3989. "\xf8\x68\x00\x2b\xc3\xe4\x31\xed\xc4\x4d\xf2\xf0\x22\x3d\x4b\xb3" \
  3990. "\xb2\x43\x58\x6e\x1a\x7d\x92\x49\x36\x69\x4f\xcb\xba\xf8\x8d\x95" \
  3991. "\x19\xe4\xeb\x50\xa6\x44\xf8\xe4\xf9\x5e\xb0\xea\x95\xbc\x44\x65" \
  3992. "\xc8\x82\x1a\xac\xd2\xfe\x15\xab\x49\x81\x16\x4b\xbb\x6d\xc3\x2f" \
  3993. "\x96\x90\x87\xa1\x45\xb0\xd9\xcc\x9c\x67\xc2\x2b\x76\x32\x99\x41" \
  3994. "\x9c\xc4\x12\x8b\xe9\xa0\x77\xb3\xac\xe6\x34\x06\x4e\x6d\x99\x28" \
  3995. "\x35\x13\xdc\x06\xe7\x51\x5d\x0d\x73\x13\x2e\x9a\x0d\xc6\xd3\xb1" \
  3996. "\xf8\xb2\x46\xf1\xa9\x8a\x3f\xc7\x29\x41\xb1\xe3\xbb\x20\x98\xe8" \
  3997. "\xbf\x16\xf2\x68\xd6\x4f\x0b\x0f\x47\x07\xfe\x1e\xa1\xa1\x79\x1b" \
  3998. "\xa2\xf3\xc0\xc7\x58\xe5\xf5\x51\x86\x3a\x96\xc9\x49\xad\x47\xd7" \
  3999. "\xfb\x40\xd2"
  4000. // test vectors from rfc-4634
  4001. START_TEST(test_sha512) {
  4002. struct {
  4003. const char *test;
  4004. int length;
  4005. int repeatcount;
  4006. int extrabits;
  4007. int numberExtrabits;
  4008. const char *result;
  4009. } tests[] = {/* 1 */ {TEST1, length(TEST1), 1, 0, 0,
  4010. "DDAF35A193617ABACC417349AE20413112E6FA4E89A97EA2"
  4011. "0A9EEEE64B55D39A2192992A274FC1A836BA3C23A3FEEBBD"
  4012. "454D4423643CE80E2A9AC94FA54CA49F"},
  4013. /* 2 */
  4014. {TEST2_2, length(TEST2_2), 1, 0, 0,
  4015. "8E959B75DAE313DA8CF4F72814FC143F8F7779C6EB9F7FA1"
  4016. "7299AEADB6889018501D289E4900F7E4331B99DEC4B5433A"
  4017. "C7D329EEB6DD26545E96E55B874BE909"},
  4018. /* 3 */
  4019. {TEST3, length(TEST3), 1000000, 0, 0,
  4020. "E718483D0CE769644E2E42C7BC15B4638E1F98B13B204428"
  4021. "5632A803AFA973EBDE0FF244877EA60A4CB0432CE577C31B"
  4022. "EB009C5C2C49AA2E4EADB217AD8CC09B"},
  4023. /* 4 */
  4024. {TEST4, length(TEST4), 10, 0, 0,
  4025. "89D05BA632C699C31231DED4FFC127D5A894DAD412C0E024"
  4026. "DB872D1ABD2BA8141A0F85072A9BE1E2AA04CF33C765CB51"
  4027. "0813A39CD5A84C4ACAA64D3F3FB7BAE9"},
  4028. /* 5 */
  4029. {"", 0, 0, 0xB0, 5,
  4030. "D4EE29A9E90985446B913CF1D1376C836F4BE2C1CF3CADA0"
  4031. "720A6BF4857D886A7ECB3C4E4C0FA8C7F95214E41DC1B0D2"
  4032. "1B22A84CC03BF8CE4845F34DD5BDBAD4"},
  4033. /* 6 */
  4034. {"\xD0", 1, 1, 0, 0,
  4035. "9992202938E882E73E20F6B69E68A0A7149090423D93C81B"
  4036. "AB3F21678D4ACEEEE50E4E8CAFADA4C85A54EA8306826C4A"
  4037. "D6E74CECE9631BFA8A549B4AB3FBBA15"},
  4038. /* 7 */
  4039. {TEST7_512, length(TEST7_512), 1, 0x80, 3,
  4040. "ED8DC78E8B01B69750053DBB7A0A9EDA0FB9E9D292B1ED71"
  4041. "5E80A7FE290A4E16664FD913E85854400C5AF05E6DAD316B"
  4042. "7359B43E64F8BEC3C1F237119986BBB6"},
  4043. /* 8 */
  4044. {TEST8_512, length(TEST8_512), 1, 0, 0,
  4045. "CB0B67A4B8712CD73C9AABC0B199E9269B20844AFB75ACBD"
  4046. "D1C153C9828924C3DDEDAAFE669C5FDD0BC66F630F677398"
  4047. "8213EB1B16F517AD0DE4B2F0C95C90F8"},
  4048. /* 9 */
  4049. {TEST9_512, length(TEST9_512), 1, 0x80, 3,
  4050. "32BA76FC30EAA0208AEB50FFB5AF1864FDBF17902A4DC0A6"
  4051. "82C61FCEA6D92B783267B21080301837F59DE79C6B337DB2"
  4052. "526F8A0A510E5E53CAFED4355FE7C2F1"},
  4053. /* 10 */
  4054. {TEST10_512, length(TEST10_512), 1, 0, 0,
  4055. "C665BEFB36DA189D78822D10528CBF3B12B3EEF726039909"
  4056. "C1A16A270D48719377966B957A878E720584779A62825C18"
  4057. "DA26415E49A7176A894E7510FD1451F5"}};
  4058. for (int i = 0; i < 10; i++) {
  4059. SHA512_CTX ctx;
  4060. uint8_t digest[SHA512_DIGEST_LENGTH];
  4061. sha512_Init(&ctx);
  4062. /* extra bits are not supported */
  4063. if (tests[i].numberExtrabits) continue;
  4064. for (int j = 0; j < tests[i].repeatcount; j++) {
  4065. sha512_Update(&ctx, (const uint8_t *)tests[i].test, tests[i].length);
  4066. }
  4067. sha512_Final(&ctx, digest);
  4068. ck_assert_mem_eq(digest, fromhex(tests[i].result), SHA512_DIGEST_LENGTH);
  4069. }
  4070. }
  4071. END_TEST
  4072. // test vectors from http://www.di-mgt.com.au/sha_testvectors.html
  4073. START_TEST(test_sha3_256) {
  4074. static const struct {
  4075. const char *data;
  4076. const char *hash;
  4077. } tests[] = {
  4078. {
  4079. "",
  4080. "a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a",
  4081. },
  4082. {
  4083. "abc",
  4084. "3a985da74fe225b2045c172d6bd390bd855f086e3e9d525b46bfe24511431532",
  4085. },
  4086. {
  4087. "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq",
  4088. "41c0dba2a9d6240849100376a8235e2c82e1b9998a999e21db32dd97496d3376",
  4089. },
  4090. {
  4091. "abcdefghbcdefghicdefghijdefghijkefghijklfghijklmghijklmnhijklmnoijkl"
  4092. "mnopjklmnopqklmnopqrlmnopqrsmnopqrstnopqrstu",
  4093. "916f6061fe879741ca6469b43971dfdb28b1a32dc36cb3254e812be27aad1d18",
  4094. },
  4095. };
  4096. uint8_t digest[SHA3_256_DIGEST_LENGTH];
  4097. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  4098. size_t len = strlen(tests[i].data);
  4099. sha3_256((uint8_t *)tests[i].data, len, digest);
  4100. ck_assert_mem_eq(digest, fromhex(tests[i].hash), SHA3_256_DIGEST_LENGTH);
  4101. // Test progressive hashing.
  4102. size_t part_len = len;
  4103. SHA3_CTX ctx;
  4104. sha3_256_Init(&ctx);
  4105. sha3_Update(&ctx, (uint8_t *)tests[i].data, part_len);
  4106. sha3_Update(&ctx, NULL, 0);
  4107. sha3_Update(&ctx, (uint8_t *)tests[i].data + part_len, len - part_len);
  4108. sha3_Final(&ctx, digest);
  4109. ck_assert_mem_eq(digest, fromhex(tests[i].hash), SHA3_256_DIGEST_LENGTH);
  4110. }
  4111. }
  4112. END_TEST
  4113. // test vectors from http://www.di-mgt.com.au/sha_testvectors.html
  4114. START_TEST(test_sha3_512) {
  4115. static const struct {
  4116. const char *data;
  4117. const char *hash;
  4118. } tests[] = {
  4119. {
  4120. "",
  4121. "a69f73cca23a9ac5c8b567dc185a756e97c982164fe25859e0d1dcc1475c80a615b2"
  4122. "123af1f5f94c11e3e9402c3ac558f500199d95b6d3e301758586281dcd26",
  4123. },
  4124. {
  4125. "abc",
  4126. "b751850b1a57168a5693cd924b6b096e08f621827444f70d884f5d0240d2712e10e1"
  4127. "16e9192af3c91a7ec57647e3934057340b4cf408d5a56592f8274eec53f0",
  4128. },
  4129. {
  4130. "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq",
  4131. "04a371e84ecfb5b8b77cb48610fca8182dd457ce6f326a0fd3d7ec2f1e91636dee69"
  4132. "1fbe0c985302ba1b0d8dc78c086346b533b49c030d99a27daf1139d6e75e",
  4133. },
  4134. {
  4135. "abcdefghbcdefghicdefghijdefghijkefghijklfghijklmghijklmnhijklmnoijkl"
  4136. "mnopjklmnopqklmnopqrlmnopqrsmnopqrstnopqrstu",
  4137. "afebb2ef542e6579c50cad06d2e578f9f8dd6881d7dc824d26360feebf18a4fa73e3"
  4138. "261122948efcfd492e74e82e2189ed0fb440d187f382270cb455f21dd185",
  4139. },
  4140. };
  4141. uint8_t digest[SHA3_512_DIGEST_LENGTH];
  4142. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  4143. size_t len = strlen(tests[i].data);
  4144. sha3_512((uint8_t *)tests[i].data, len, digest);
  4145. ck_assert_mem_eq(digest, fromhex(tests[i].hash), SHA3_512_DIGEST_LENGTH);
  4146. // Test progressive hashing.
  4147. size_t part_len = len;
  4148. SHA3_CTX ctx;
  4149. sha3_512_Init(&ctx);
  4150. sha3_Update(&ctx, (const uint8_t *)tests[i].data, part_len);
  4151. sha3_Update(&ctx, NULL, 0);
  4152. sha3_Update(&ctx, (const uint8_t *)tests[i].data + part_len,
  4153. len - part_len);
  4154. sha3_Final(&ctx, digest);
  4155. ck_assert_mem_eq(digest, fromhex(tests[i].hash), SHA3_512_DIGEST_LENGTH);
  4156. }
  4157. }
  4158. END_TEST
  4159. // test vectors from
  4160. // https://raw.githubusercontent.com/NemProject/nem-test-vectors/master/0.test-sha3-256.dat
  4161. START_TEST(test_keccak_256) {
  4162. static const struct {
  4163. const char *hash;
  4164. size_t length;
  4165. const char *data;
  4166. } tests[] = {
  4167. {
  4168. "4e9e79ab7434f6c7401fb3305d55052ee829b9e46d5d05d43b59fefb32e9a619",
  4169. 293,
  4170. "a6151d4904e18ec288243028ceda30556e6c42096af7150d6a7232ca5dba52bd2192"
  4171. "e23daa5fa2bea3d4bd95efa2389cd193fcd3376e70a5c097b32c1c62c80af9d71021"
  4172. "1545f7cdddf63747420281d64529477c61e721273cfd78f8890abb4070e97baa52ac"
  4173. "8ff61c26d195fc54c077def7a3f6f79b36e046c1a83ce9674ba1983ec2fb58947de6"
  4174. "16dd797d6499b0385d5e8a213db9ad5078a8e0c940ff0cb6bf92357ea5609f778c3d"
  4175. "1fb1e7e36c35db873361e2be5c125ea7148eff4a035b0cce880a41190b2e22924ad9"
  4176. "d1b82433d9c023924f2311315f07b88bfd42850047bf3be785c4ce11c09d7e02065d"
  4177. "30f6324365f93c5e7e423a07d754eb314b5fe9db4614275be4be26af017abdc9c338"
  4178. "d01368226fe9af1fb1f815e7317bdbb30a0f36dc69",
  4179. },
  4180. {
  4181. "c1268babc42d00c3463dc388222100f7e525a74a64665c39f112f788ddb5da42",
  4182. 376,
  4183. "9db801077952c2324e0044a4994edfb09b3edfcf669bfdd029f4bf42d5b0eab3056b"
  4184. "0bf82708ca7bfadba43c9de806b10a19d0f00c2351ef1086b6b108f306e035c6b61b"
  4185. "2e70fd7087ba848601c8a3f626a66666423717ef305a1068bfa3a1f7ffc1e5a78cb6"
  4186. "182ffc8a577ca2a821630bf900d0fbba848bdf94b77c5946771b6c3f8c02269bc772"
  4187. "ca56098f724536d96be68c284ee1d81697989d40029b8ea63ac1fd85f8b3cae8b194"
  4188. "f6834ff65a5858f9498ddbb467995eb2d49cdfc6c05d92038c6e9aaeee85f8222b37"
  4189. "84165f12a2c3df4c7a142e26dddfd831d07e22dfecc0eded48a69c8a9e1b97f1a4e0"
  4190. "efcd4edd310de0edf82af38a6e4d5ab2a19da586e61210d4f75e7a07e2201f9c8154"
  4191. "ca52a414a70d2eb2ac1c5b9a2900b4d871f62fa56f70d03b3dd3704bd644808c45a1"
  4192. "3231918ea884645b8ec054e8bab2935a66811fe590ddc119ae901dfeb54fc2a87c1e"
  4193. "0a236778baab2fa8843709c6676d3c1888ba19d75ec52d73a7d035c143179b938237"
  4194. "26b7",
  4195. },
  4196. {
  4197. "e83b50e8c83cb676a7dd64c055f53e5110d5a4c62245ceb8f683fd87b2b3ec77",
  4198. 166,
  4199. "c070a957550b7b34113ee6543a1918d96d241f27123425db7f7b9004e047ffbe0561"
  4200. "2e7fa8c54b23c83ea427e625e97b7a28b09a70bf6d91e478eeed01d7907931c29ea8"
  4201. "6e70f2cdcfb243ccf7f24a1619abf4b5b9e6f75cbf63fc02baf4a820a9790a6b053e"
  4202. "50fd94e0ed57037cfc2bab4d95472b97d3c25f434f1cc0b1ede5ba7f15907a42a223"
  4203. "933e5e2dfcb518c3531975268c326d60fa911fbb7997eee3ba87656c4fe7",
  4204. },
  4205. {
  4206. "8ebd2c9d4ff00e285a9b6b140bfc3cef672016f0098100e1f6f250220af7ce1a",
  4207. 224,
  4208. "b502fbdce4045e49e147eff5463d4b3f37f43461518868368e2c78008c84c2db79d1"
  4209. "2b58107034f67e7d0abfee67add0342dd23dce623f26b9156def87b1d7ac15a6e073"
  4210. "01f832610fe869ada13a2b0e3d60aa6bb81bc04487e2e800f5106b0402ee0331df74"
  4211. "5e021b5ea5e32faf1c7fc1322041d221a54191c0af19948b5f34411937182e30d5cd"
  4212. "39b5a6c959d77d92d21bb1de51f1b3411cb6eec00600429916227fb62d2c88e69576"
  4213. "f4ac8e5efcde8efa512cc80ce7fb0dfaa6c74d26e898cefe9d4f7dce232a69f2a6a9"
  4214. "477aa08366efcdfca117c89cb79eba15a23755e0",
  4215. },
  4216. {
  4217. "db3961fdddd0c314289efed5d57363459a6700a7bd015e7a03d3e1d03f046401",
  4218. 262,
  4219. "22e203a98ba2c43d8bc3658f0a48a35766df356d6a5e98b0c7222d16d85a00b31720"
  4220. "7d4aef3fc7cabb67b9d8f5838de0b733e1fd59c31f0667e53286972d7090421ad90d"
  4221. "54db2ea40047d0d1700c86f53dbf48da532396307e68edad877dcae481848801b0a5"
  4222. "db44dbdba6fc7c63b5cd15281d57ca9e6be96f530b209b59d6127ad2bd8750f3f807"
  4223. "98f62521f0d5b42633c2f5a9aaefbed38779b7aded2338d66850b0bb0e33c48e040c"
  4224. "99f2dcee7a7ebb3d7416e1c5bf038c19d09682dab67c96dbbfad472e45980aa27d1b"
  4225. "301b15f7de4d4f549bad2501931c9d4f1a3b1692dcb4b1b834ddd4a636126702307d"
  4226. "daeec61841693b21887d56e76cc2069dafb557fd6682160f",
  4227. },
  4228. {
  4229. "25dd3acacd6bf688c0eace8d33eb7cc550271969142deb769a05b4012f7bb722",
  4230. 122,
  4231. "99e7f6e0ed46ec866c43a1ab494998d47e9309a79fde2a629eb63bb2160a5ffd0f22"
  4232. "06de9c32dd20e9b23e57ab7422cf82971cc2873ec0e173fe93281c7b33e1c76ac792"
  4233. "23a6f435f230bdd30260c00d00986c72a399d3ba70f6e783d834bbf8a6127844def5"
  4234. "59b8b6db742b2cfd715f7ff29e7b42bf7d567beb",
  4235. },
  4236. {
  4237. "00d747c9045c093484290afc161437f11c2ddf5f8a9fc2acae9c7ef5fcf511e5",
  4238. 440,
  4239. "50c392f97f8788377f0ab2e2aab196cb017ad157c6f9d022673d39072cc198b06622"
  4240. "a5cbd269d1516089fa59e28c3373a92bd54b2ebf1a79811c7e40fdd7bce200e80983"
  4241. "fda6e77fc44c44c1b5f87e01cef2f41e1141103f73364e9c2f25a4597e6517ef31b3"
  4242. "16300b770c69595e0fa6d011df1566a8676a88c7698562273bbfa217cc69d4b5c89a"
  4243. "8907b902f7dc14481fefc7da4a810c15a60f5641aae854d2f8cc50cbc393015560f0"
  4244. "1c94e0d0c075dbcb150ad6eba29dc747919edcaf0231dba3eb3f2b1a87e136a1f0fd"
  4245. "4b3d8ee61bad2729e9526a32884f7bcfa41e361add1b4c51dc81463528372b4ec321"
  4246. "244de0c541ba00df22b8773cdf4cf898510c867829fa6b4ff11f9627338b9686d905"
  4247. "cb7bcdf085080ab842146e0035c808be58cce97827d8926a98bd1ff7c529be3bc14f"
  4248. "68c91b2ca4d2f6fc748f56bcf14853b7f8b9aa6d388f0fd82f53fdc4bacf9d9ba10a"
  4249. "165f404cf427e199f51bf6773b7c82531e17933f6d8b8d9181e22f8921a2dbb20fc7"
  4250. "c8023a87e716e245017c399d0942934f5e085219b3f8d26a196bf8b239438b8e561c"
  4251. "28a61ff08872ecb052c5fcb19e2fdbc09565924a50ebee1461c4b414219d4257",
  4252. },
  4253. {
  4254. "dadcde7c3603ef419d319ba3d50cf00ad57f3e81566fd11b9b6f461cbb9dcb0f",
  4255. 338,
  4256. "18e1df97abccc91e07dc7b7ffab5ee8919d5610721453176aa2089fb96d9a477e147"
  4257. "6f507fa1129f04304e960e8017ff41246cacc0153055fc4b1dc6168a74067ebb077c"
  4258. "b5aa80a9df6e8b5b821e906531159668c4c164b9e511d8724aedbe17c1f41da88094"
  4259. "17d3c30b79ea5a2e3c961f6bac5436d9af6be24a36eebcb17863fed82c0eb8962339"
  4260. "eb612d58659dddd2ea06a120b3a2d8a17050be2de367db25a5bef4290c209bdb4c16"
  4261. "c4df5a1fe1ead635169a1c35f0a56bc07bcf6ef0e4c2d8573ed7a3b58030fa268c1a"
  4262. "5974b097288f01f34d5a1087946410688016882c6c7621aad680d9a25c7a3e5dbcbb"
  4263. "07ffdb7243b91031c08a121b40785e96b7ee46770c760f84aca8f36b7c7da64d25c8"
  4264. "f73b4d88ff3acb7eeefc0b75144dffea66d2d1f6b42b905b61929ab3f38538393ba5"
  4265. "ca9d3c62c61f46fa63789cac14e4e1d8722bf03cceef6e3de91f783b0072616c",
  4266. },
  4267. {
  4268. "d184e84a2507fc0f187b640dd5b849a366c0383d9cbdbc6fa30904f054111255",
  4269. 141,
  4270. "13b8df9c1bcfddd0aa39b3055f52e2bc36562b6677535994b173f07041d141699db4"
  4271. "2589d6091ef0e71b645b41ab57577f58c98da966562d24823158f8e1d43b54edea4e"
  4272. "61dd66fe8c59ad8405f5a0d9a3eb509a77ae3d8ae4adf926fd3d8d31c3dcccfc1408"
  4273. "14541010937024cc554e1daaee1b333a66316e7fbebb07ac8dfb134a918b9090b141"
  4274. "68012c4824",
  4275. },
  4276. {
  4277. "20c19635364a00b151d0168fe5ae03bac6dd7d06030475b40d2e8c577a192f53",
  4278. 84,
  4279. "e1e96da4b7d8dcc2b316006503a990ea26a5b200cb7a7edfc14f5ce827f06d8d232e"
  4280. "c95b1acdc1422ffc16da11d258f0c7b378f026d64c74b2fb41df8bfd3cd30066caec"
  4281. "dc6f76c8163de9309d9fd0cf33d54a29",
  4282. },
  4283. {
  4284. "86cc2c428d469e43fb4ee8d38dffbf5128d20d1659dbc45edf4a855399ca730e",
  4285. 319,
  4286. "30391840ad14e66c53e1a5aaa03989ff059940b60c44c3b21295a93d023f2e6c7cdc"
  4287. "f60208b7d87a7605fb5cee94630d94cad90bc6955328357fa37fea47c09f9cee759c"
  4288. "31537187321c7d572e3554eeb90f441a9494575454dfbf8cfd86128da15de9418821"
  4289. "ca158856eb84ff6a29a2c8380711e9e6d4955388374fcd3c1ca45b49e0679fc7157f"
  4290. "96bc6e4f86ce20a89c12d4449b1ca7056e0b7296fc646f68f6ddbfa6a48e384d63ab"
  4291. "68bc75fd69a2add59b8e41c4a0f753935df9a703d7df82a430798b0a67710a780614"
  4292. "85a9d15de16f154582082459b4462485ce8a82d35ac6b9498ae40df3a23d5f00e0e8"
  4293. "6661cb02c52f677fd374c32969ec63028b5dd2c1d4bce67a6d9f79ba5e7eeb5a2763"
  4294. "dc9fe2a05aa2ebaad36aaec2541e343a677fb4e6b6a180eff33c93744a4624f6a79f"
  4295. "054c6c9e9c5b6928dbe7ba5fca",
  4296. },
  4297. {
  4298. "e80eee72a76e6957f7cb7f68c41b92f0ad9aac6e58aa8fc272c1e7364af11c70",
  4299. 108,
  4300. "3c210ed15889ae938781d2cebd49d4a8007f163ffba1f7669bccdccf6ad5a1418299"
  4301. "d5f4348f5cd03b0ba9e6999ab154e46836c3546feb395d17bcc60f23d7ba0e8efe6a"
  4302. "a616c00b6bf552fe1cb5e28e3e7bc39dfc20c63ae3901035e91ddd110e43fe59ed74"
  4303. "4beeedb6bc1e",
  4304. },
  4305. {
  4306. "f971bbae97dd8a034835269fb246867de358a889de6de13672e771d6fb4c89b7",
  4307. 468,
  4308. "64e9a3a99c021df8bea59368cfe1cd3b0a4aca33ffcd5cf6028d9307c0b904b8037d"
  4309. "056a3c12803f196f74c4d360a3132452d365922b1157e5b0d76f91fb94bebfdcb4d5"
  4310. "0fa23ed5be3d3c5712219e8666debc8abcd5e6c69a542761a6cbbd1b3c0f05248752"
  4311. "04b64d2788465f90cb19b6f6da9f8bec6d6e684196e713549ec83e47cbaeff77838a"
  4312. "c4936b312562e2de17c970449d49d214ec2597c6d4f642e6c94a613a0c53285abccd"
  4313. "7794a3d72241808594fb4e6e4d5d2c310ef1cdcbfd34805ca2408f554797a6cfd49d"
  4314. "0f25ed8927f206acb127e6436e1234902489ec2e7f3058e26c0eba80341bc7ad0da8"
  4315. "b8bd80bd1b43c9099269e3f8b68445c69b79d8cf5693d4a0d47a44f9e9114dbb3399"
  4316. "2d2ea9d3b5b86e4ea57a44a638848de4ac365bb6bb7855305ade62b07ebf0954d70b"
  4317. "7c2fb5e6fcc154c7a36fb1756df5f20a84d35696627ebf22d44f40f805c0878ad110"
  4318. "bc17dcd66821084ca87902e05bc0afa61161086956b85a6ea900d35c7784d4c361a4"
  4319. "3fe294e267d5762408be58962cdb4f45a9c0efd7d2335916df3acb98ccfbcf5ee395"
  4320. "30540e5f3d3c5f3326a9a536d7bfa37aae2b143e2499b81bf0670e3a418c26c7dc82"
  4321. "b293d9bd182dd6435670514237df88d8286e19ce93e0a0db2790",
  4322. },
  4323. {
  4324. "b97fd51f4e4eaa40c7a2853010fc46be5be2f43b9520ea0c533b68f728c978a2",
  4325. 214,
  4326. "ced3a43193caceb269d2517f4ecb892bb7d57d7201869e28e669b0b17d1c44d286e0"
  4327. "2734e2210ea9009565832975cc6303b9b6008fe1165b99ae5f1b29962ef042ebad8b"
  4328. "676d7433ed2fe0d0d6f4f32b2cb4c519da61552328c2caea799bb2fd907308173a1c"
  4329. "d2b798fb0df7d2eaf2ff0be733af74f42889e211843fc80b09952ae7eb246725b91d"
  4330. "31c1f7a5503fdf3bc9c269c76519cf2dc3225e862436b587bb74adbad88c773056cf"
  4331. "ea3bddb1f6533c01125eeae0986e5c817359912c9d0472bf8320b824ee097f82a8e0"
  4332. "5b9f53a5be7d153225de",
  4333. },
  4334. {
  4335. "f0fecf766e4f7522568b3be71843cce3e5fcb10ea96b1a236c8c0a71c9ad55c9",
  4336. 159,
  4337. "8aca4de41275f5c4102f66266d70cff1a2d56f58df8d12061c64cb6cd8f616a5bf19"
  4338. "c2bb3c91585c695326f561a2d0eb4eef2e202d82dcc9089e4bee82b62a199a11963c"
  4339. "d08987d3abd5914def2cdd3c1e4748d46b654f338e3959121e869c18d5327e88090d"
  4340. "0ba0ac6762a2b14514cc505af7499f1a22f421dbe978494f9ffe1e88f1c59228f21d"
  4341. "a5bc9fcc911d022300a443bca17258bdd6cfbbf52fde61",
  4342. },
  4343. {
  4344. "5c4f16043c0084bf98499fc7dc4d674ce9c730b7135210acdbf5e41d3dcf317b",
  4345. 87,
  4346. "01bbc193d0ee2396a7d8267ad63f18149667b31d8f7f48c8bb0c634755febc9ef1a7"
  4347. "9e93c475f6cd137ee37d4dc243ea2fdcdc0d098844af2208337b7bbf6930e39e74e2"
  4348. "3952ac1a19b4d38b83810a10c3b069e4fafb06",
  4349. },
  4350. {
  4351. "14b61fc981f7d9449b7b6a2d57eb48cc8f7896f4dced2005291b2a2f38cb4a63",
  4352. 358,
  4353. "cbc1709a531438d5ead32cea20a9e4ddc0101ec555ab42b2e378145013cc05a97b9e"
  4354. "2c43c89bfa63ae5e9e9ce1fc022035c6b68f0a906ee1f53396d9dbe41cb2bc4bfeb1"
  4355. "44b005b0f40e0fec872d9c4aca9929ba3cbacd84c58ab43c26f10d345a24692bbd55"
  4356. "a76506876768e8e32a461bf160cee953da88920d36ad4aff6eea7126aa6f44a7a6fc"
  4357. "e770ce43f0f90a20590bdaad3ffcda30ca8e3700f832c62caa5df030c16bcf74aff4"
  4358. "92466f781eb69863a80663535fc154abd7cfdd02eef1019221cf608b9780f807e507"
  4359. "fbbf559b1dfe4e971b4d08fe45263a3c697ba90f9f71bec97e12438b4b12f6a84ab6"
  4360. "6872b888097089d76c9c2502d9ed2eece6bef8eee1d439782e218f5cc75d38f98860"
  4361. "12cdcb4bbe6caf812e97c5a336bcceae38b1109e3243a291ce23d097aaee7d9a711d"
  4362. "e6886749a7a6d15d7e7cbc4a51b1b4da9fcf139e4a6fd7dc0bc017db624b17fc9b8f"
  4363. "847592ed42467c25ad9fe96acbf20c0ffd18",
  4364. },
  4365. {
  4366. "47ec7f3a362becbb110867995a0f066a66152603c4d433f11bf51870c67e2864",
  4367. 354,
  4368. "0636983353c9ea3f75256ed00b70e8b7cfc6f4e4c0ba3aa9a8da59b6e6ad9dfb5bc2"
  4369. "c49f48cc0b4237f87dedf34b888e54ecebf1d435bcd4aab72eb4ce39e5262fb68c6f"
  4370. "86423dac123bf59e903989eda7df4a982822d0831521403cedcfe9a5bbea648bb2e7"
  4371. "ef8cd81442ea5abe468b3ee8b06376ef8099447255c2fdc1b73af37fe0e0b852ffbc"
  4372. "9339868db756680db99e6e9837dbd28c39a69f229044ad7ec772524a6e01f679d25f"
  4373. "dc2e736a2418e5dfd7c2ab1348d0f821b777c975244c6cfc2fca5c36ccae7cf1d07b"
  4374. "190a9d17a088a1276bd096250b92f53b29b6ef88ef69d744b56fb2ec5078cc0b68a9"
  4375. "106943ef242b466097b9e29df11eb5cb0c06c29d7917410ba1097215d6aa4dafd90a"
  4376. "dff0c3e7221b9e8832613bd9aca8bcc6b2aa7b43acedcbc11aee1b5ba56f77a210be"
  4377. "7cf3485ee813e1126c3eeccd8419bbf22c412cad32cc0fc7a73aca4e379651caac3d"
  4378. "13d6cf5ca05508fd2d96f3ad94e7",
  4379. },
  4380. {
  4381. "73778e7f1943646a89d3c78909e0afbe584071ba5230546a39cd73e44e36d78a",
  4382. 91,
  4383. "6217504a26b3395855eab6ddeb79f2e3490d74b80eff343721150ee0c1c02b071867"
  4384. "43589f93c22a03dc5ed29fb5bf592de0a089763e83e5b95f9dd524d66c8da3e04c18"
  4385. "14e65e68b2810c1b517648aabc266ad62896c51864a7f4",
  4386. },
  4387. {
  4388. "35ef6868e750cf0c1d5285992c231d93ec644670fb79cf85324067a9f77fde78",
  4389. 185,
  4390. "0118b7fb15f927a977e0b330b4fa351aeeec299d6ba090eb16e5114fc4a6749e5915"
  4391. "434a123c112697390c96ea2c26dc613eb5c75f5ecfb6c419317426367e34da0ddc6d"
  4392. "7b7612cefa70a22fea0025f5186593b22449dab71f90a49f7de7352e54e0c0bd8837"
  4393. "e661ca2127c3313a7268cafdd5ccfbf3bdd7c974b0e7551a2d96766579ef8d2e1f37"
  4394. "6af74cd1ab62162fc2dc61a8b7ed4163c1caccf20ed73e284da2ed257ec974eee96b"
  4395. "502acb2c60a04886465e44debb0317",
  4396. },
  4397. };
  4398. uint8_t hash[SHA3_256_DIGEST_LENGTH];
  4399. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  4400. keccak_256(fromhex(tests[i].data), tests[i].length, hash);
  4401. ck_assert_mem_eq(hash, fromhex(tests[i].hash), SHA3_256_DIGEST_LENGTH);
  4402. // Test progressive hashing.
  4403. size_t part_len = tests[i].length / 2;
  4404. SHA3_CTX ctx = {0};
  4405. keccak_256_Init(&ctx);
  4406. keccak_Update(&ctx, fromhex(tests[i].data), part_len);
  4407. keccak_Update(&ctx, fromhex(tests[i].data), 0);
  4408. keccak_Update(&ctx, fromhex(tests[i].data) + part_len,
  4409. tests[i].length - part_len);
  4410. keccak_Final(&ctx, hash);
  4411. ck_assert_mem_eq(hash, fromhex(tests[i].hash), SHA3_256_DIGEST_LENGTH);
  4412. }
  4413. }
  4414. END_TEST
  4415. // test vectors from
  4416. // https://raw.githubusercontent.com/monero-project/monero/master/tests/hash/tests-extra-blake.txt
  4417. START_TEST(test_blake256) {
  4418. static const struct {
  4419. const char *hash;
  4420. const char *data;
  4421. } tests[] = {
  4422. {
  4423. "716f6e863f744b9ac22c97ec7b76ea5f5908bc5b2f67c61510bfc4751384ea7a",
  4424. "",
  4425. },
  4426. {
  4427. "e104256a2bc501f459d03fac96b9014f593e22d30f4de525fa680c3aa189eb4f",
  4428. "cc",
  4429. },
  4430. {
  4431. "8f341148be7e354fdf38b693d8c6b4e0bd57301a734f6fd35cd85b8491c3ddcd",
  4432. "41fb",
  4433. },
  4434. {
  4435. "bc334d1069099f10c601883ac6f3e7e9787c6aa53171f76a21923cc5ad3ab937",
  4436. "1f877c",
  4437. },
  4438. {
  4439. "b672a16f53982bab1e77685b71c0a5f6703ffd46a1c834be69f614bd128d658e",
  4440. "c1ecfdfc",
  4441. },
  4442. {
  4443. "d9134b2899057a7d8d320cc99e3e116982bc99d3c69d260a7f1ed3da8be68d99",
  4444. "21f134ac57",
  4445. },
  4446. {
  4447. "637923bd29a35aa3ecbbd2a50549fc32c14cf0fdcaf41c3194dd7414fd224815",
  4448. "c6f50bb74e29",
  4449. },
  4450. {
  4451. "70c092fd5c8c21e9ef4bbc82a5c7819e262a530a748caf285ff0cba891954f1e",
  4452. "119713cc83eeef",
  4453. },
  4454. {
  4455. "fdf092993edbb7a0dc7ca67f04051bbd14481639da0808947aff8bfab5abed4b",
  4456. "4a4f202484512526",
  4457. },
  4458. {
  4459. "6f6fc234bf35beae1a366c44c520c59ad5aa70351b5f5085e21e1fe2bfcee709",
  4460. "1f66ab4185ed9b6375",
  4461. },
  4462. {
  4463. "4fdaf89e2a0e78c000061b59455e0ea93a4445b440e7562c8f0cfa165c93de2e",
  4464. "eed7422227613b6f53c9",
  4465. },
  4466. {
  4467. "d6b780eee9c811f664393dc2c58b5a68c92b3c9fe9ceb70371d33ece63b5787e",
  4468. "eaeed5cdffd89dece455f1",
  4469. },
  4470. {
  4471. "d0015071d3e7ed048c764850d76406eceae52b8e2e6e5a2c3aa92ae880485b34",
  4472. "5be43c90f22902e4fe8ed2d3",
  4473. },
  4474. {
  4475. "9b0207902f9932f7a85c24722e93e31f6ed2c75c406509aa0f2f6d1cab046ce4",
  4476. "a746273228122f381c3b46e4f1",
  4477. },
  4478. {
  4479. "258020d5b04a814f2b72c1c661e1f5a5c395d9799e5eee8b8519cf7300e90cb1",
  4480. "3c5871cd619c69a63b540eb5a625",
  4481. },
  4482. {
  4483. "4adae3b55baa907fefc253365fdd99d8398befd0551ed6bf9a2a2784d3c304d1",
  4484. "fa22874bcc068879e8ef11a69f0722",
  4485. },
  4486. {
  4487. "6dd10d772f8d5b4a96c3c5d30878cd9a1073fa835bfe6d2b924fa64a1fab1711",
  4488. "52a608ab21ccdd8a4457a57ede782176",
  4489. },
  4490. {
  4491. "0b8741ddf2259d3af2901eb1ae354f22836442c965556f5c1eb89501191cb46a",
  4492. "82e192e4043ddcd12ecf52969d0f807eed",
  4493. },
  4494. {
  4495. "f48a754ca8193a82643150ab94038b5dd170b4ebd1e0751b78cfb0a98fa5076a",
  4496. "75683dcb556140c522543bb6e9098b21a21e",
  4497. },
  4498. {
  4499. "5698409ab856b74d9fa5e9b259dfa46001f89041752da424e56e491577b88c86",
  4500. "06e4efe45035e61faaf4287b4d8d1f12ca97e5",
  4501. },
  4502. };
  4503. uint8_t hash[BLAKE256_DIGEST_LENGTH];
  4504. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  4505. size_t len = strlen(tests[i].data) / 2;
  4506. blake256(fromhex(tests[i].data), len, hash);
  4507. ck_assert_mem_eq(hash, fromhex(tests[i].hash), BLAKE256_DIGEST_LENGTH);
  4508. // Test progressive hashing.
  4509. size_t part_len = len / 2;
  4510. BLAKE256_CTX ctx;
  4511. blake256_Init(&ctx);
  4512. blake256_Update(&ctx, fromhex(tests[i].data), part_len);
  4513. blake256_Update(&ctx, NULL, 0);
  4514. blake256_Update(&ctx, fromhex(tests[i].data) + part_len, len - part_len);
  4515. blake256_Final(&ctx, hash);
  4516. ck_assert_mem_eq(hash, fromhex(tests[i].hash), BLAKE256_DIGEST_LENGTH);
  4517. }
  4518. }
  4519. END_TEST
  4520. // test vectors from
  4521. // https://raw.githubusercontent.com/BLAKE2/BLAKE2/master/testvectors/blake2b-kat.txt
  4522. START_TEST(test_blake2b) {
  4523. static const struct {
  4524. const char *msg;
  4525. const char *hash;
  4526. } tests[] = {
  4527. {
  4528. "",
  4529. "10ebb67700b1868efb4417987acf4690ae9d972fb7a590c2f02871799aaa4786b5e9"
  4530. "96e8f0f4eb981fc214b005f42d2ff4233499391653df7aefcbc13fc51568",
  4531. },
  4532. {
  4533. "000102",
  4534. "33d0825dddf7ada99b0e7e307104ad07ca9cfd9692214f1561356315e784f3e5a17e"
  4535. "364ae9dbb14cb2036df932b77f4b292761365fb328de7afdc6d8998f5fc1",
  4536. },
  4537. {
  4538. "000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f2021"
  4539. "22232425262728292a2b2c2d2e2f3031323334353637",
  4540. "f8f3726ac5a26cc80132493a6fedcb0e60760c09cfc84cad178175986819665e7684"
  4541. "2d7b9fedf76dddebf5d3f56faaad4477587af21606d396ae570d8e719af2",
  4542. },
  4543. {
  4544. "000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f2021"
  4545. "22232425262728292a2b2c2d2e2f303132333435363738393a3b3c3d3e3f40414243"
  4546. "4445464748494a4b4c4d4e4f505152535455565758595a5b5c5d5e5f606162636465"
  4547. "666768696a6b6c6d6e6f",
  4548. "227e3aed8d2cb10b918fcb04f9de3e6d0a57e08476d93759cd7b2ed54a1cbf0239c5"
  4549. "28fb04bbf288253e601d3bc38b21794afef90b17094a182cac557745e75f",
  4550. },
  4551. };
  4552. uint8_t key[BLAKE2B_KEY_LENGTH];
  4553. memcpy(key,
  4554. fromhex(
  4555. "000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f2"
  4556. "02122232425262728292a2b2c2d2e2f303132333435363738393a3b3c3d3e3f"),
  4557. BLAKE2B_KEY_LENGTH);
  4558. uint8_t digest[BLAKE2B_DIGEST_LENGTH];
  4559. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  4560. size_t msg_len = strlen(tests[i].msg) / 2;
  4561. blake2b_Key(fromhex(tests[i].msg), msg_len, key, sizeof(key), digest,
  4562. sizeof(digest));
  4563. ck_assert_mem_eq(digest, fromhex(tests[i].hash), sizeof(digest));
  4564. // Test progressive hashing.
  4565. size_t part_len = msg_len / 2;
  4566. BLAKE2B_CTX ctx;
  4567. ck_assert_int_eq(blake2b_InitKey(&ctx, sizeof(digest), key, sizeof(key)),
  4568. 0);
  4569. ck_assert_int_eq(blake2b_Update(&ctx, fromhex(tests[i].msg), part_len), 0);
  4570. ck_assert_int_eq(blake2b_Update(&ctx, NULL, 0), 0);
  4571. ck_assert_int_eq(blake2b_Update(&ctx, fromhex(tests[i].msg) + part_len,
  4572. msg_len - part_len),
  4573. 0);
  4574. ck_assert_int_eq(blake2b_Final(&ctx, digest, sizeof(digest)), 0);
  4575. ck_assert_mem_eq(digest, fromhex(tests[i].hash), BLAKE2B_DIGEST_LENGTH);
  4576. }
  4577. }
  4578. END_TEST
  4579. // Blake2b-256 personalized, a la ZCash
  4580. // Test vectors from https://zips.z.cash/zip-0243
  4581. START_TEST(test_blake2bp) {
  4582. static const struct {
  4583. const char *msg;
  4584. const char *personal;
  4585. const char *hash;
  4586. } tests[] = {
  4587. {
  4588. "",
  4589. "ZcashPrevoutHash",
  4590. "d53a633bbecf82fe9e9484d8a0e727c73bb9e68c96e72dec30144f6a84afa136",
  4591. },
  4592. {
  4593. "",
  4594. "ZcashSequencHash",
  4595. "a5f25f01959361ee6eb56a7401210ee268226f6ce764a4f10b7f29e54db37272",
  4596. },
  4597. {
  4598. "e7719811893e0000095200ac6551ac636565b2835a0805750200025151",
  4599. "ZcashOutputsHash",
  4600. "ab6f7f6c5ad6b56357b5f37e16981723db6c32411753e28c175e15589172194a",
  4601. },
  4602. {
  4603. "0bbe32a598c22adfb48cef72ba5d4287c0cefbacfd8ce195b4963c34a94bba7a1"
  4604. "75dae4b090f47a068e227433f9e49d3aa09e356d8d66d0c0121e91a3c4aa3f27fa1b"
  4605. "63396e2b41d",
  4606. "ZcashPrevoutHash",
  4607. "cacf0f5210cce5fa65a59f314292b3111d299e7d9d582753cf61e1e408552ae4",
  4608. }};
  4609. uint8_t digest[32];
  4610. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  4611. size_t msg_len = strlen(tests[i].msg) / 2;
  4612. // Test progressive hashing.
  4613. size_t part_len = msg_len / 2;
  4614. BLAKE2B_CTX ctx;
  4615. ck_assert_int_eq(
  4616. blake2b_InitPersonal(&ctx, sizeof(digest), tests[i].personal,
  4617. strlen(tests[i].personal)),
  4618. 0);
  4619. ck_assert_int_eq(blake2b_Update(&ctx, fromhex(tests[i].msg), part_len), 0);
  4620. ck_assert_int_eq(blake2b_Update(&ctx, NULL, 0), 0);
  4621. ck_assert_int_eq(blake2b_Update(&ctx, fromhex(tests[i].msg) + part_len,
  4622. msg_len - part_len),
  4623. 0);
  4624. ck_assert_int_eq(blake2b_Final(&ctx, digest, sizeof(digest)), 0);
  4625. ck_assert_mem_eq(digest, fromhex(tests[i].hash), sizeof(digest));
  4626. }
  4627. }
  4628. END_TEST
  4629. // test vectors from
  4630. // https://raw.githubusercontent.com/BLAKE2/BLAKE2/master/testvectors/blake2s-kat.txt
  4631. START_TEST(test_blake2s) {
  4632. static const struct {
  4633. const char *msg;
  4634. const char *hash;
  4635. } tests[] = {
  4636. {
  4637. "",
  4638. "48a8997da407876b3d79c0d92325ad3b89cbb754d86ab71aee047ad345fd2c49",
  4639. },
  4640. {
  4641. "000102",
  4642. "1d220dbe2ee134661fdf6d9e74b41704710556f2f6e5a091b227697445dbea6b",
  4643. },
  4644. {
  4645. "000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f2021"
  4646. "22232425262728292a2b2c2d2e2f3031323334353637",
  4647. "2966b3cfae1e44ea996dc5d686cf25fa053fb6f67201b9e46eade85d0ad6b806",
  4648. },
  4649. {
  4650. "000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f2021"
  4651. "22232425262728292a2b2c2d2e2f303132333435363738393a3b3c3d3e3f40414243"
  4652. "4445464748494a4b4c4d4e4f505152535455565758595a5b5c5d5e5f606162636465"
  4653. "666768696a6b6c6d6e6f",
  4654. "90a83585717b75f0e9b725e055eeeeb9e7a028ea7e6cbc07b20917ec0363e38c",
  4655. },
  4656. };
  4657. uint8_t key[BLAKE2S_KEY_LENGTH];
  4658. memcpy(
  4659. key,
  4660. fromhex(
  4661. "000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f"),
  4662. BLAKE2S_KEY_LENGTH);
  4663. uint8_t digest[BLAKE2S_DIGEST_LENGTH];
  4664. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  4665. size_t msg_len = strlen(tests[i].msg) / 2;
  4666. blake2s_Key(fromhex(tests[i].msg), msg_len, key, sizeof(key), digest,
  4667. sizeof(digest));
  4668. ck_assert_mem_eq(digest, fromhex(tests[i].hash), sizeof(digest));
  4669. // Test progressive hashing.
  4670. size_t part_len = msg_len / 2;
  4671. BLAKE2S_CTX ctx;
  4672. ck_assert_int_eq(blake2s_InitKey(&ctx, sizeof(digest), key, sizeof(key)),
  4673. 0);
  4674. ck_assert_int_eq(blake2s_Update(&ctx, fromhex(tests[i].msg), part_len), 0);
  4675. ck_assert_int_eq(blake2s_Update(&ctx, NULL, 0), 0);
  4676. ck_assert_int_eq(blake2s_Update(&ctx, fromhex(tests[i].msg) + part_len,
  4677. msg_len - part_len),
  4678. 0);
  4679. ck_assert_int_eq(blake2s_Final(&ctx, digest, sizeof(digest)), 0);
  4680. ck_assert_mem_eq(digest, fromhex(tests[i].hash), BLAKE2S_DIGEST_LENGTH);
  4681. }
  4682. }
  4683. END_TEST
  4684. #include <stdio.h>
  4685. START_TEST(test_chacha_drbg) {
  4686. char entropy[] =
  4687. "06032cd5eed33f39265f49ecb142c511da9aff2af71203bffaf34a9ca5bd9c0d";
  4688. char nonce[] = "0e66f71edc43e42a45ad3c6fc6cdc4df";
  4689. char reseed[] =
  4690. "01920a4e669ed3a85ae8a33b35a74ad7fb2a6bb4cf395ce00334a9c9a5a5d552";
  4691. char expected[] =
  4692. "e172c5d18f3e8c77e9f66f9e1c24560772117161a9a0a237ab490b0769ad5d910f5dfb36"
  4693. "22edc06c18be0495c52588b200893d90fd80ff2149ead0c45d062c90f5890149c0f9591c"
  4694. "41bf4110865129a0fe524f210cca1340bd16f71f57906946cbaaf1fa863897d70d203b5a"
  4695. "f9996f756eec08861ee5875f9d915adcddc38719";
  4696. uint8_t result[128];
  4697. uint8_t null_bytes[128] = {0};
  4698. uint8_t nonce_bytes[16];
  4699. memcpy(nonce_bytes, fromhex(nonce), sizeof(nonce_bytes));
  4700. CHACHA_DRBG_CTX ctx;
  4701. chacha_drbg_init(&ctx, fromhex(entropy), strlen(entropy) / 2, nonce_bytes,
  4702. strlen(nonce) / 2);
  4703. chacha_drbg_reseed(&ctx, fromhex(reseed), strlen(reseed) / 2, NULL, 0);
  4704. chacha_drbg_generate(&ctx, result, sizeof(result));
  4705. chacha_drbg_generate(&ctx, result, sizeof(result));
  4706. ck_assert_mem_eq(result, fromhex(expected), sizeof(result));
  4707. for (size_t i = 0; i <= sizeof(result); ++i) {
  4708. chacha_drbg_init(&ctx, fromhex(entropy), strlen(entropy) / 2, nonce_bytes,
  4709. strlen(nonce) / 2);
  4710. chacha_drbg_reseed(&ctx, fromhex(reseed), strlen(reseed) / 2, NULL, 0);
  4711. chacha_drbg_generate(&ctx, result, sizeof(result) - 13);
  4712. memset(result, 0, sizeof(result));
  4713. chacha_drbg_generate(&ctx, result, i);
  4714. ck_assert_mem_eq(result, fromhex(expected), i);
  4715. ck_assert_mem_eq(result + i, null_bytes, sizeof(result) - i);
  4716. }
  4717. }
  4718. END_TEST
  4719. START_TEST(test_pbkdf2_hmac_sha256) {
  4720. uint8_t k[64];
  4721. // test vectors from
  4722. // https://stackoverflow.com/questions/5130513/pbkdf2-hmac-sha2-test-vectors
  4723. pbkdf2_hmac_sha256((const uint8_t *)"password", 8, (const uint8_t *)"salt", 4,
  4724. 1, k, 32);
  4725. ck_assert_mem_eq(
  4726. k,
  4727. fromhex(
  4728. "120fb6cffcf8b32c43e7225256c4f837a86548c92ccc35480805987cb70be17b"),
  4729. 32);
  4730. pbkdf2_hmac_sha256((const uint8_t *)"password", 8, (const uint8_t *)"salt", 4,
  4731. 2, k, 32);
  4732. ck_assert_mem_eq(
  4733. k,
  4734. fromhex(
  4735. "ae4d0c95af6b46d32d0adff928f06dd02a303f8ef3c251dfd6e2d85a95474c43"),
  4736. 32);
  4737. pbkdf2_hmac_sha256((const uint8_t *)"password", 8, (const uint8_t *)"salt", 4,
  4738. 4096, k, 32);
  4739. ck_assert_mem_eq(
  4740. k,
  4741. fromhex(
  4742. "c5e478d59288c841aa530db6845c4c8d962893a001ce4e11a4963873aa98134a"),
  4743. 32);
  4744. pbkdf2_hmac_sha256((const uint8_t *)"passwordPASSWORDpassword", 3 * 8,
  4745. (const uint8_t *)"saltSALTsaltSALTsaltSALTsaltSALTsalt",
  4746. 9 * 4, 4096, k, 40);
  4747. ck_assert_mem_eq(k,
  4748. fromhex("348c89dbcbd32b2f32d814b8116e84cf2b17347ebc1800181c4"
  4749. "e2a1fb8dd53e1c635518c7dac47e9"),
  4750. 40);
  4751. pbkdf2_hmac_sha256((const uint8_t *)"pass\x00word", 9,
  4752. (const uint8_t *)"sa\x00lt", 5, 4096, k, 16);
  4753. ck_assert_mem_eq(k, fromhex("89b69d0516f829893c696226650a8687"), 16);
  4754. // test vector from https://tools.ietf.org/html/rfc7914.html#section-11
  4755. pbkdf2_hmac_sha256((const uint8_t *)"passwd", 6, (const uint8_t *)"salt", 4,
  4756. 1, k, 64);
  4757. ck_assert_mem_eq(
  4758. k,
  4759. fromhex(
  4760. "55ac046e56e3089fec1691c22544b605f94185216dde0465e68b9d57c20dacbc49ca"
  4761. "9cccf179b645991664b39d77ef317c71b845b1e30bd509112041d3a19783"),
  4762. 64);
  4763. }
  4764. END_TEST
  4765. // test vectors from
  4766. // http://stackoverflow.com/questions/15593184/pbkdf2-hmac-sha-512-test-vectors
  4767. START_TEST(test_pbkdf2_hmac_sha512) {
  4768. uint8_t k[64];
  4769. pbkdf2_hmac_sha512((uint8_t *)"password", 8, (const uint8_t *)"salt", 4, 1, k,
  4770. 64);
  4771. ck_assert_mem_eq(
  4772. k,
  4773. fromhex(
  4774. "867f70cf1ade02cff3752599a3a53dc4af34c7a669815ae5d513554e1c8cf252c02d"
  4775. "470a285a0501bad999bfe943c08f050235d7d68b1da55e63f73b60a57fce"),
  4776. 64);
  4777. pbkdf2_hmac_sha512((uint8_t *)"password", 8, (const uint8_t *)"salt", 4, 2, k,
  4778. 64);
  4779. ck_assert_mem_eq(
  4780. k,
  4781. fromhex(
  4782. "e1d9c16aa681708a45f5c7c4e215ceb66e011a2e9f0040713f18aefdb866d53cf76c"
  4783. "ab2868a39b9f7840edce4fef5a82be67335c77a6068e04112754f27ccf4e"),
  4784. 64);
  4785. pbkdf2_hmac_sha512((uint8_t *)"password", 8, (const uint8_t *)"salt", 4, 4096,
  4786. k, 64);
  4787. ck_assert_mem_eq(
  4788. k,
  4789. fromhex(
  4790. "d197b1b33db0143e018b12f3d1d1479e6cdebdcc97c5c0f87f6902e072f457b5143f"
  4791. "30602641b3d55cd335988cb36b84376060ecd532e039b742a239434af2d5"),
  4792. 64);
  4793. pbkdf2_hmac_sha512((uint8_t *)"passwordPASSWORDpassword", 3 * 8,
  4794. (const uint8_t *)"saltSALTsaltSALTsaltSALTsaltSALTsalt",
  4795. 9 * 4, 4096, k, 64);
  4796. ck_assert_mem_eq(
  4797. k,
  4798. fromhex(
  4799. "8c0511f4c6e597c6ac6315d8f0362e225f3c501495ba23b868c005174dc4ee71115b"
  4800. "59f9e60cd9532fa33e0f75aefe30225c583a186cd82bd4daea9724a3d3b8"),
  4801. 64);
  4802. }
  4803. END_TEST
  4804. START_TEST(test_hmac_drbg) {
  4805. char entropy[] =
  4806. "06032cd5eed33f39265f49ecb142c511da9aff2af71203bffaf34a9ca5bd9c0d";
  4807. char nonce[] = "0e66f71edc43e42a45ad3c6fc6cdc4df";
  4808. char reseed[] =
  4809. "01920a4e669ed3a85ae8a33b35a74ad7fb2a6bb4cf395ce00334a9c9a5a5d552";
  4810. char expected[] =
  4811. "76fc79fe9b50beccc991a11b5635783a83536add03c157fb30645e611c2898bb2b1bc215"
  4812. "000209208cd506cb28da2a51bdb03826aaf2bd2335d576d519160842e7158ad0949d1a9e"
  4813. "c3e66ea1b1a064b005de914eac2e9d4f2d72a8616a80225422918250ff66a41bd2f864a6"
  4814. "a38cc5b6499dc43f7f2bd09e1e0f8f5885935124";
  4815. uint8_t result[128];
  4816. uint8_t null_bytes[128] = {0};
  4817. uint8_t nonce_bytes[16];
  4818. memcpy(nonce_bytes, fromhex(nonce), sizeof(nonce_bytes));
  4819. HMAC_DRBG_CTX ctx;
  4820. hmac_drbg_init(&ctx, fromhex(entropy), strlen(entropy) / 2, nonce_bytes,
  4821. strlen(nonce) / 2);
  4822. hmac_drbg_reseed(&ctx, fromhex(reseed), strlen(reseed) / 2, NULL, 0);
  4823. hmac_drbg_generate(&ctx, result, sizeof(result));
  4824. hmac_drbg_generate(&ctx, result, sizeof(result));
  4825. ck_assert_mem_eq(result, fromhex(expected), sizeof(result));
  4826. for (size_t i = 0; i <= sizeof(result); ++i) {
  4827. hmac_drbg_init(&ctx, fromhex(entropy), strlen(entropy) / 2, nonce_bytes,
  4828. strlen(nonce) / 2);
  4829. hmac_drbg_reseed(&ctx, fromhex(reseed), strlen(reseed) / 2, NULL, 0);
  4830. hmac_drbg_generate(&ctx, result, sizeof(result) - 13);
  4831. memset(result, 0, sizeof(result));
  4832. hmac_drbg_generate(&ctx, result, i);
  4833. ck_assert_mem_eq(result, fromhex(expected), i);
  4834. ck_assert_mem_eq(result + i, null_bytes, sizeof(result) - i);
  4835. }
  4836. }
  4837. END_TEST
  4838. START_TEST(test_mnemonic) {
  4839. static const char *vectors[] = {
  4840. "00000000000000000000000000000000",
  4841. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  4842. "abandon abandon about",
  4843. "c55257c360c07c72029aebc1b53c05ed0362ada38ead3e3e9efa3708e53495531f09a698"
  4844. "7599d18264c1e1c92f2cf141630c7a3c4ab7c81b2f001698e7463b04",
  4845. "7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f",
  4846. "legal winner thank year wave sausage worth useful legal winner thank "
  4847. "yellow",
  4848. "2e8905819b8723fe2c1d161860e5ee1830318dbf49a83bd451cfb8440c28bd6fa457fe12"
  4849. "96106559a3c80937a1c1069be3a3a5bd381ee6260e8d9739fce1f607",
  4850. "80808080808080808080808080808080",
  4851. "letter advice cage absurd amount doctor acoustic avoid letter advice "
  4852. "cage above",
  4853. "d71de856f81a8acc65e6fc851a38d4d7ec216fd0796d0a6827a3ad6ed5511a30fa280f12"
  4854. "eb2e47ed2ac03b5c462a0358d18d69fe4f985ec81778c1b370b652a8",
  4855. "ffffffffffffffffffffffffffffffff",
  4856. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo wrong",
  4857. "ac27495480225222079d7be181583751e86f571027b0497b5b5d11218e0a8a1333257291"
  4858. "7f0f8e5a589620c6f15b11c61dee327651a14c34e18231052e48c069",
  4859. "000000000000000000000000000000000000000000000000",
  4860. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  4861. "abandon abandon abandon abandon abandon abandon abandon abandon agent",
  4862. "035895f2f481b1b0f01fcf8c289c794660b289981a78f8106447707fdd9666ca06da5a9a"
  4863. "565181599b79f53b844d8a71dd9f439c52a3d7b3e8a79c906ac845fa",
  4864. "7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f",
  4865. "legal winner thank year wave sausage worth useful legal winner thank "
  4866. "year wave sausage worth useful legal will",
  4867. "f2b94508732bcbacbcc020faefecfc89feafa6649a5491b8c952cede496c214a0c7b3c39"
  4868. "2d168748f2d4a612bada0753b52a1c7ac53c1e93abd5c6320b9e95dd",
  4869. "808080808080808080808080808080808080808080808080",
  4870. "letter advice cage absurd amount doctor acoustic avoid letter advice "
  4871. "cage absurd amount doctor acoustic avoid letter always",
  4872. "107d7c02a5aa6f38c58083ff74f04c607c2d2c0ecc55501dadd72d025b751bc27fe913ff"
  4873. "b796f841c49b1d33b610cf0e91d3aa239027f5e99fe4ce9e5088cd65",
  4874. "ffffffffffffffffffffffffffffffffffffffffffffffff",
  4875. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo "
  4876. "when",
  4877. "0cd6e5d827bb62eb8fc1e262254223817fd068a74b5b449cc2f667c3f1f985a76379b433"
  4878. "48d952e2265b4cd129090758b3e3c2c49103b5051aac2eaeb890a528",
  4879. "0000000000000000000000000000000000000000000000000000000000000000",
  4880. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  4881. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  4882. "abandon abandon abandon abandon abandon art",
  4883. "bda85446c68413707090a52022edd26a1c9462295029f2e60cd7c4f2bbd3097170af7a4d"
  4884. "73245cafa9c3cca8d561a7c3de6f5d4a10be8ed2a5e608d68f92fcc8",
  4885. "7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f",
  4886. "legal winner thank year wave sausage worth useful legal winner thank "
  4887. "year wave sausage worth useful legal winner thank year wave sausage "
  4888. "worth title",
  4889. "bc09fca1804f7e69da93c2f2028eb238c227f2e9dda30cd63699232578480a4021b146ad"
  4890. "717fbb7e451ce9eb835f43620bf5c514db0f8add49f5d121449d3e87",
  4891. "8080808080808080808080808080808080808080808080808080808080808080",
  4892. "letter advice cage absurd amount doctor acoustic avoid letter advice "
  4893. "cage absurd amount doctor acoustic avoid letter advice cage absurd "
  4894. "amount doctor acoustic bless",
  4895. "c0c519bd0e91a2ed54357d9d1ebef6f5af218a153624cf4f2da911a0ed8f7a09e2ef61af"
  4896. "0aca007096df430022f7a2b6fb91661a9589097069720d015e4e982f",
  4897. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
  4898. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo "
  4899. "zoo zoo zoo zoo zoo vote",
  4900. "dd48c104698c30cfe2b6142103248622fb7bb0ff692eebb00089b32d22484e1613912f0a"
  4901. "5b694407be899ffd31ed3992c456cdf60f5d4564b8ba3f05a69890ad",
  4902. "77c2b00716cec7213839159e404db50d",
  4903. "jelly better achieve collect unaware mountain thought cargo oxygen act "
  4904. "hood bridge",
  4905. "b5b6d0127db1a9d2226af0c3346031d77af31e918dba64287a1b44b8ebf63cdd52676f67"
  4906. "2a290aae502472cf2d602c051f3e6f18055e84e4c43897fc4e51a6ff",
  4907. "b63a9c59a6e641f288ebc103017f1da9f8290b3da6bdef7b",
  4908. "renew stay biology evidence goat welcome casual join adapt armor "
  4909. "shuffle fault little machine walk stumble urge swap",
  4910. "9248d83e06f4cd98debf5b6f010542760df925ce46cf38a1bdb4e4de7d21f5c39366941c"
  4911. "69e1bdbf2966e0f6e6dbece898a0e2f0a4c2b3e640953dfe8b7bbdc5",
  4912. "3e141609b97933b66a060dcddc71fad1d91677db872031e85f4c015c5e7e8982",
  4913. "dignity pass list indicate nasty swamp pool script soccer toe leaf "
  4914. "photo multiply desk host tomato cradle drill spread actor shine dismiss "
  4915. "champion exotic",
  4916. "ff7f3184df8696d8bef94b6c03114dbee0ef89ff938712301d27ed8336ca89ef9635da20"
  4917. "af07d4175f2bf5f3de130f39c9d9e8dd0472489c19b1a020a940da67",
  4918. "0460ef47585604c5660618db2e6a7e7f",
  4919. "afford alter spike radar gate glance object seek swamp infant panel "
  4920. "yellow",
  4921. "65f93a9f36b6c85cbe634ffc1f99f2b82cbb10b31edc7f087b4f6cb9e976e9faf76ff41f"
  4922. "8f27c99afdf38f7a303ba1136ee48a4c1e7fcd3dba7aa876113a36e4",
  4923. "72f60ebac5dd8add8d2a25a797102c3ce21bc029c200076f",
  4924. "indicate race push merry suffer human cruise dwarf pole review arch "
  4925. "keep canvas theme poem divorce alter left",
  4926. "3bbf9daa0dfad8229786ace5ddb4e00fa98a044ae4c4975ffd5e094dba9e0bb289349dbe"
  4927. "2091761f30f382d4e35c4a670ee8ab50758d2c55881be69e327117ba",
  4928. "2c85efc7f24ee4573d2b81a6ec66cee209b2dcbd09d8eddc51e0215b0b68e416",
  4929. "clutch control vehicle tonight unusual clog visa ice plunge glimpse "
  4930. "recipe series open hour vintage deposit universe tip job dress radar "
  4931. "refuse motion taste",
  4932. "fe908f96f46668b2d5b37d82f558c77ed0d69dd0e7e043a5b0511c48c2f1064694a956f8"
  4933. "6360c93dd04052a8899497ce9e985ebe0c8c52b955e6ae86d4ff4449",
  4934. "eaebabb2383351fd31d703840b32e9e2",
  4935. "turtle front uncle idea crush write shrug there lottery flower risk "
  4936. "shell",
  4937. "bdfb76a0759f301b0b899a1e3985227e53b3f51e67e3f2a65363caedf3e32fde42a66c40"
  4938. "4f18d7b05818c95ef3ca1e5146646856c461c073169467511680876c",
  4939. "7ac45cfe7722ee6c7ba84fbc2d5bd61b45cb2fe5eb65aa78",
  4940. "kiss carry display unusual confirm curtain upgrade antique rotate hello "
  4941. "void custom frequent obey nut hole price segment",
  4942. "ed56ff6c833c07982eb7119a8f48fd363c4a9b1601cd2de736b01045c5eb8ab4f57b0794"
  4943. "03485d1c4924f0790dc10a971763337cb9f9c62226f64fff26397c79",
  4944. "4fa1a8bc3e6d80ee1316050e862c1812031493212b7ec3f3bb1b08f168cabeef",
  4945. "exile ask congress lamp submit jacket era scheme attend cousin alcohol "
  4946. "catch course end lucky hurt sentence oven short ball bird grab wing top",
  4947. "095ee6f817b4c2cb30a5a797360a81a40ab0f9a4e25ecd672a3f58a0b5ba0687c096a6b1"
  4948. "4d2c0deb3bdefce4f61d01ae07417d502429352e27695163f7447a8c",
  4949. "18ab19a9f54a9274f03e5209a2ac8a91",
  4950. "board flee heavy tunnel powder denial science ski answer betray cargo "
  4951. "cat",
  4952. "6eff1bb21562918509c73cb990260db07c0ce34ff0e3cc4a8cb3276129fbcb300bddfe00"
  4953. "5831350efd633909f476c45c88253276d9fd0df6ef48609e8bb7dca8",
  4954. "18a2e1d81b8ecfb2a333adcb0c17a5b9eb76cc5d05db91a4",
  4955. "board blade invite damage undo sun mimic interest slam gaze truly "
  4956. "inherit resist great inject rocket museum chief",
  4957. "f84521c777a13b61564234bf8f8b62b3afce27fc4062b51bb5e62bdfecb23864ee6ecf07"
  4958. "c1d5a97c0834307c5c852d8ceb88e7c97923c0a3b496bedd4e5f88a9",
  4959. "15da872c95a13dd738fbf50e427583ad61f18fd99f628c417a61cf8343c90419",
  4960. "beyond stage sleep clip because twist token leaf atom beauty genius "
  4961. "food business side grid unable middle armed observe pair crouch tonight "
  4962. "away coconut",
  4963. "b15509eaa2d09d3efd3e006ef42151b30367dc6e3aa5e44caba3fe4d3e352e65101fbdb8"
  4964. "6a96776b91946ff06f8eac594dc6ee1d3e82a42dfe1b40fef6bcc3fd",
  4965. 0,
  4966. 0,
  4967. 0,
  4968. };
  4969. const char **a, **b, **c, *m;
  4970. uint8_t seed[64];
  4971. a = vectors;
  4972. b = vectors + 1;
  4973. c = vectors + 2;
  4974. while (*a && *b && *c) {
  4975. m = mnemonic_from_data(fromhex(*a), strlen(*a) / 2);
  4976. ck_assert_str_eq(m, *b);
  4977. mnemonic_to_seed(m, "TREZOR", seed, 0);
  4978. ck_assert_mem_eq(seed, fromhex(*c), strlen(*c) / 2);
  4979. #if USE_BIP39_CACHE
  4980. // try second time to check whether caching results work
  4981. mnemonic_to_seed(m, "TREZOR", seed, 0);
  4982. ck_assert_mem_eq(seed, fromhex(*c), strlen(*c) / 2);
  4983. #endif
  4984. a += 3;
  4985. b += 3;
  4986. c += 3;
  4987. }
  4988. }
  4989. END_TEST
  4990. START_TEST(test_mnemonic_check) {
  4991. static const char *vectors_ok[] = {
  4992. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  4993. "abandon abandon about",
  4994. "legal winner thank year wave sausage worth useful legal winner thank "
  4995. "yellow",
  4996. "letter advice cage absurd amount doctor acoustic avoid letter advice "
  4997. "cage above",
  4998. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo wrong",
  4999. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5000. "abandon abandon abandon abandon abandon abandon abandon abandon agent",
  5001. "legal winner thank year wave sausage worth useful legal winner thank "
  5002. "year wave sausage worth useful legal will",
  5003. "letter advice cage absurd amount doctor acoustic avoid letter advice "
  5004. "cage absurd amount doctor acoustic avoid letter always",
  5005. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo "
  5006. "when",
  5007. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5008. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5009. "abandon abandon abandon abandon abandon art",
  5010. "legal winner thank year wave sausage worth useful legal winner thank "
  5011. "year wave sausage worth useful legal winner thank year wave sausage "
  5012. "worth title",
  5013. "letter advice cage absurd amount doctor acoustic avoid letter advice "
  5014. "cage absurd amount doctor acoustic avoid letter advice cage absurd "
  5015. "amount doctor acoustic bless",
  5016. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo "
  5017. "zoo zoo zoo zoo zoo vote",
  5018. "jelly better achieve collect unaware mountain thought cargo oxygen act "
  5019. "hood bridge",
  5020. "renew stay biology evidence goat welcome casual join adapt armor "
  5021. "shuffle fault little machine walk stumble urge swap",
  5022. "dignity pass list indicate nasty swamp pool script soccer toe leaf "
  5023. "photo multiply desk host tomato cradle drill spread actor shine dismiss "
  5024. "champion exotic",
  5025. "afford alter spike radar gate glance object seek swamp infant panel "
  5026. "yellow",
  5027. "indicate race push merry suffer human cruise dwarf pole review arch "
  5028. "keep canvas theme poem divorce alter left",
  5029. "clutch control vehicle tonight unusual clog visa ice plunge glimpse "
  5030. "recipe series open hour vintage deposit universe tip job dress radar "
  5031. "refuse motion taste",
  5032. "turtle front uncle idea crush write shrug there lottery flower risk "
  5033. "shell",
  5034. "kiss carry display unusual confirm curtain upgrade antique rotate hello "
  5035. "void custom frequent obey nut hole price segment",
  5036. "exile ask congress lamp submit jacket era scheme attend cousin alcohol "
  5037. "catch course end lucky hurt sentence oven short ball bird grab wing top",
  5038. "board flee heavy tunnel powder denial science ski answer betray cargo "
  5039. "cat",
  5040. "board blade invite damage undo sun mimic interest slam gaze truly "
  5041. "inherit resist great inject rocket museum chief",
  5042. "beyond stage sleep clip because twist token leaf atom beauty genius "
  5043. "food business side grid unable middle armed observe pair crouch tonight "
  5044. "away coconut",
  5045. 0,
  5046. };
  5047. static const char *vectors_fail[] = {
  5048. "above abandon abandon abandon abandon abandon abandon abandon abandon "
  5049. "abandon abandon about",
  5050. "above winner thank year wave sausage worth useful legal winner thank "
  5051. "yellow",
  5052. "above advice cage absurd amount doctor acoustic avoid letter advice "
  5053. "cage above",
  5054. "above zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo wrong",
  5055. "above abandon abandon abandon abandon abandon abandon abandon abandon "
  5056. "abandon abandon abandon abandon abandon abandon abandon abandon agent",
  5057. "above winner thank year wave sausage worth useful legal winner thank "
  5058. "year wave sausage worth useful legal will",
  5059. "above advice cage absurd amount doctor acoustic avoid letter advice "
  5060. "cage absurd amount doctor acoustic avoid letter always",
  5061. "above zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo "
  5062. "when",
  5063. "above abandon abandon abandon abandon abandon abandon abandon abandon "
  5064. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5065. "abandon abandon abandon abandon abandon art",
  5066. "above winner thank year wave sausage worth useful legal winner thank "
  5067. "year wave sausage worth useful legal winner thank year wave sausage "
  5068. "worth title",
  5069. "above advice cage absurd amount doctor acoustic avoid letter advice "
  5070. "cage absurd amount doctor acoustic avoid letter advice cage absurd "
  5071. "amount doctor acoustic bless",
  5072. "above zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo "
  5073. "zoo zoo zoo zoo zoo zoo vote",
  5074. "above better achieve collect unaware mountain thought cargo oxygen act "
  5075. "hood bridge",
  5076. "above stay biology evidence goat welcome casual join adapt armor "
  5077. "shuffle fault little machine walk stumble urge swap",
  5078. "above pass list indicate nasty swamp pool script soccer toe leaf photo "
  5079. "multiply desk host tomato cradle drill spread actor shine dismiss "
  5080. "champion exotic",
  5081. "above alter spike radar gate glance object seek swamp infant panel "
  5082. "yellow",
  5083. "above race push merry suffer human cruise dwarf pole review arch keep "
  5084. "canvas theme poem divorce alter left",
  5085. "above control vehicle tonight unusual clog visa ice plunge glimpse "
  5086. "recipe series open hour vintage deposit universe tip job dress radar "
  5087. "refuse motion taste",
  5088. "above front uncle idea crush write shrug there lottery flower risk "
  5089. "shell",
  5090. "above carry display unusual confirm curtain upgrade antique rotate "
  5091. "hello void custom frequent obey nut hole price segment",
  5092. "above ask congress lamp submit jacket era scheme attend cousin alcohol "
  5093. "catch course end lucky hurt sentence oven short ball bird grab wing top",
  5094. "above flee heavy tunnel powder denial science ski answer betray cargo "
  5095. "cat",
  5096. "above blade invite damage undo sun mimic interest slam gaze truly "
  5097. "inherit resist great inject rocket museum chief",
  5098. "above stage sleep clip because twist token leaf atom beauty genius food "
  5099. "business side grid unable middle armed observe pair crouch tonight away "
  5100. "coconut",
  5101. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5102. "abandon about",
  5103. "winner thank year wave sausage worth useful legal winner thank yellow",
  5104. "advice cage absurd amount doctor acoustic avoid letter advice cage "
  5105. "above",
  5106. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo wrong",
  5107. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5108. "abandon abandon abandon abandon abandon abandon abandon agent",
  5109. "winner thank year wave sausage worth useful legal winner thank year "
  5110. "wave sausage worth useful legal will",
  5111. "advice cage absurd amount doctor acoustic avoid letter advice cage "
  5112. "absurd amount doctor acoustic avoid letter always",
  5113. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo when",
  5114. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5115. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5116. "abandon abandon abandon abandon art",
  5117. "winner thank year wave sausage worth useful legal winner thank year "
  5118. "wave sausage worth useful legal winner thank year wave sausage worth "
  5119. "title",
  5120. "advice cage absurd amount doctor acoustic avoid letter advice cage "
  5121. "absurd amount doctor acoustic avoid letter advice cage absurd amount "
  5122. "doctor acoustic bless",
  5123. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo "
  5124. "zoo zoo zoo zoo vote",
  5125. "better achieve collect unaware mountain thought cargo oxygen act hood "
  5126. "bridge",
  5127. "stay biology evidence goat welcome casual join adapt armor shuffle "
  5128. "fault little machine walk stumble urge swap",
  5129. "pass list indicate nasty swamp pool script soccer toe leaf photo "
  5130. "multiply desk host tomato cradle drill spread actor shine dismiss "
  5131. "champion exotic",
  5132. "alter spike radar gate glance object seek swamp infant panel yellow",
  5133. "race push merry suffer human cruise dwarf pole review arch keep canvas "
  5134. "theme poem divorce alter left",
  5135. "control vehicle tonight unusual clog visa ice plunge glimpse recipe "
  5136. "series open hour vintage deposit universe tip job dress radar refuse "
  5137. "motion taste",
  5138. "front uncle idea crush write shrug there lottery flower risk shell",
  5139. "carry display unusual confirm curtain upgrade antique rotate hello void "
  5140. "custom frequent obey nut hole price segment",
  5141. "ask congress lamp submit jacket era scheme attend cousin alcohol catch "
  5142. "course end lucky hurt sentence oven short ball bird grab wing top",
  5143. "flee heavy tunnel powder denial science ski answer betray cargo cat",
  5144. "blade invite damage undo sun mimic interest slam gaze truly inherit "
  5145. "resist great inject rocket museum chief",
  5146. "stage sleep clip because twist token leaf atom beauty genius food "
  5147. "business side grid unable middle armed observe pair crouch tonight away "
  5148. "coconut",
  5149. 0,
  5150. };
  5151. const char **m;
  5152. int r;
  5153. m = vectors_ok;
  5154. while (*m) {
  5155. r = mnemonic_check(*m);
  5156. ck_assert_int_eq(r, 1);
  5157. m++;
  5158. }
  5159. m = vectors_fail;
  5160. while (*m) {
  5161. r = mnemonic_check(*m);
  5162. ck_assert_int_eq(r, 0);
  5163. m++;
  5164. }
  5165. }
  5166. END_TEST
  5167. START_TEST(test_mnemonic_to_bits) {
  5168. static const char *vectors[] = {
  5169. "00000000000000000000000000000000",
  5170. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5171. "abandon abandon about",
  5172. "7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f",
  5173. "legal winner thank year wave sausage worth useful legal winner thank "
  5174. "yellow",
  5175. "80808080808080808080808080808080",
  5176. "letter advice cage absurd amount doctor acoustic avoid letter advice "
  5177. "cage above",
  5178. "ffffffffffffffffffffffffffffffff",
  5179. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo wrong",
  5180. "000000000000000000000000000000000000000000000000",
  5181. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5182. "abandon abandon abandon abandon abandon abandon abandon abandon agent",
  5183. "7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f",
  5184. "legal winner thank year wave sausage worth useful legal winner thank "
  5185. "year wave sausage worth useful legal will",
  5186. "808080808080808080808080808080808080808080808080",
  5187. "letter advice cage absurd amount doctor acoustic avoid letter advice "
  5188. "cage absurd amount doctor acoustic avoid letter always",
  5189. "ffffffffffffffffffffffffffffffffffffffffffffffff",
  5190. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo "
  5191. "when",
  5192. "0000000000000000000000000000000000000000000000000000000000000000",
  5193. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5194. "abandon abandon abandon abandon abandon abandon abandon abandon abandon "
  5195. "abandon abandon abandon abandon abandon art",
  5196. "7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f7f",
  5197. "legal winner thank year wave sausage worth useful legal winner thank "
  5198. "year wave sausage worth useful legal winner thank year wave sausage "
  5199. "worth title",
  5200. "8080808080808080808080808080808080808080808080808080808080808080",
  5201. "letter advice cage absurd amount doctor acoustic avoid letter advice "
  5202. "cage absurd amount doctor acoustic avoid letter advice cage absurd "
  5203. "amount doctor acoustic bless",
  5204. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
  5205. "zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo zoo "
  5206. "zoo zoo zoo zoo zoo vote",
  5207. "77c2b00716cec7213839159e404db50d",
  5208. "jelly better achieve collect unaware mountain thought cargo oxygen act "
  5209. "hood bridge",
  5210. "b63a9c59a6e641f288ebc103017f1da9f8290b3da6bdef7b",
  5211. "renew stay biology evidence goat welcome casual join adapt armor "
  5212. "shuffle fault little machine walk stumble urge swap",
  5213. "3e141609b97933b66a060dcddc71fad1d91677db872031e85f4c015c5e7e8982",
  5214. "dignity pass list indicate nasty swamp pool script soccer toe leaf "
  5215. "photo multiply desk host tomato cradle drill spread actor shine dismiss "
  5216. "champion exotic",
  5217. "0460ef47585604c5660618db2e6a7e7f",
  5218. "afford alter spike radar gate glance object seek swamp infant panel "
  5219. "yellow",
  5220. "72f60ebac5dd8add8d2a25a797102c3ce21bc029c200076f",
  5221. "indicate race push merry suffer human cruise dwarf pole review arch "
  5222. "keep canvas theme poem divorce alter left",
  5223. "2c85efc7f24ee4573d2b81a6ec66cee209b2dcbd09d8eddc51e0215b0b68e416",
  5224. "clutch control vehicle tonight unusual clog visa ice plunge glimpse "
  5225. "recipe series open hour vintage deposit universe tip job dress radar "
  5226. "refuse motion taste",
  5227. "eaebabb2383351fd31d703840b32e9e2",
  5228. "turtle front uncle idea crush write shrug there lottery flower risk "
  5229. "shell",
  5230. "7ac45cfe7722ee6c7ba84fbc2d5bd61b45cb2fe5eb65aa78",
  5231. "kiss carry display unusual confirm curtain upgrade antique rotate hello "
  5232. "void custom frequent obey nut hole price segment",
  5233. "4fa1a8bc3e6d80ee1316050e862c1812031493212b7ec3f3bb1b08f168cabeef",
  5234. "exile ask congress lamp submit jacket era scheme attend cousin alcohol "
  5235. "catch course end lucky hurt sentence oven short ball bird grab wing top",
  5236. "18ab19a9f54a9274f03e5209a2ac8a91",
  5237. "board flee heavy tunnel powder denial science ski answer betray cargo "
  5238. "cat",
  5239. "18a2e1d81b8ecfb2a333adcb0c17a5b9eb76cc5d05db91a4",
  5240. "board blade invite damage undo sun mimic interest slam gaze truly "
  5241. "inherit resist great inject rocket museum chief",
  5242. "15da872c95a13dd738fbf50e427583ad61f18fd99f628c417a61cf8343c90419",
  5243. "beyond stage sleep clip because twist token leaf atom beauty genius "
  5244. "food business side grid unable middle armed observe pair crouch tonight "
  5245. "away coconut",
  5246. 0,
  5247. 0,
  5248. };
  5249. const char **a, **b;
  5250. uint8_t mnemonic_bits[64];
  5251. a = vectors;
  5252. b = vectors + 1;
  5253. while (*a && *b) {
  5254. int mnemonic_bits_len = mnemonic_to_bits(*b, mnemonic_bits);
  5255. ck_assert_int_eq(mnemonic_bits_len % 33, 0);
  5256. mnemonic_bits_len = mnemonic_bits_len * 4 / 33;
  5257. ck_assert_uint_eq((size_t)mnemonic_bits_len, strlen(*a) / 2);
  5258. ck_assert_mem_eq(mnemonic_bits, fromhex(*a), mnemonic_bits_len);
  5259. a += 2;
  5260. b += 2;
  5261. }
  5262. }
  5263. END_TEST
  5264. START_TEST(test_mnemonic_find_word) {
  5265. ck_assert_int_eq(-1, mnemonic_find_word("aaaa"));
  5266. ck_assert_int_eq(-1, mnemonic_find_word("zzzz"));
  5267. for (int i = 0; i < BIP39_WORD_COUNT; i++) {
  5268. const char *word = mnemonic_get_word(i);
  5269. int index = mnemonic_find_word(word);
  5270. ck_assert_int_eq(i, index);
  5271. }
  5272. }
  5273. END_TEST
  5274. START_TEST(test_slip39_get_word) {
  5275. static const struct {
  5276. const int index;
  5277. const char *expected_word;
  5278. } vectors[] = {{573, "member"},
  5279. {0, "academic"},
  5280. {1023, "zero"},
  5281. {245, "drove"},
  5282. {781, "satoshi"}};
  5283. for (size_t i = 0; i < (sizeof(vectors) / sizeof(*vectors)); i++) {
  5284. const char *a = get_word(vectors[i].index);
  5285. ck_assert_str_eq(a, vectors[i].expected_word);
  5286. }
  5287. }
  5288. END_TEST
  5289. START_TEST(test_slip39_word_index) {
  5290. uint16_t index;
  5291. static const struct {
  5292. const char *word;
  5293. bool expected_result;
  5294. uint16_t expected_index;
  5295. } vectors[] = {{"academic", true, 0},
  5296. {"zero", true, 1023},
  5297. {"drove", true, 245},
  5298. {"satoshi", true, 781},
  5299. {"member", true, 573},
  5300. // 9999 value is never checked since the word is not in list
  5301. {"fakeword", false, 9999}};
  5302. for (size_t i = 0; i < (sizeof(vectors) / sizeof(*vectors)); i++) {
  5303. bool result = word_index(&index, vectors[i].word, strlen(vectors[i].word));
  5304. ck_assert_int_eq(result, vectors[i].expected_result);
  5305. if (result) {
  5306. ck_assert_uint_eq(index, vectors[i].expected_index);
  5307. }
  5308. }
  5309. }
  5310. END_TEST
  5311. START_TEST(test_slip39_word_completion_mask) {
  5312. static const struct {
  5313. const uint16_t prefix;
  5314. const uint16_t expected_mask;
  5315. } vectors[] = {
  5316. {12, 0xFD}, // 011111101
  5317. {21, 0xF8}, // 011111000
  5318. {75, 0xAD}, // 010101101
  5319. {4, 0x1F7}, // 111110111
  5320. {738, 0x6D}, // 001101101
  5321. {9, 0x6D}, // 001101101
  5322. {0, 0x1FF}, // 111111111
  5323. {10, 0x00}, // 000000000
  5324. {255, 0x00}, // 000000000
  5325. {203, 0x00}, // 000000000
  5326. {9999, 0x00}, // 000000000
  5327. {20000, 0x00}, // 000000000
  5328. };
  5329. for (size_t i = 0; i < (sizeof(vectors) / sizeof(*vectors)); i++) {
  5330. uint16_t mask = slip39_word_completion_mask(vectors[i].prefix);
  5331. ck_assert_uint_eq(mask, vectors[i].expected_mask);
  5332. }
  5333. }
  5334. END_TEST
  5335. START_TEST(test_slip39_sequence_to_word) {
  5336. static const struct {
  5337. const uint16_t prefix;
  5338. const char *expected_word;
  5339. } vectors[] = {
  5340. {7945, "swimming"}, {646, "pipeline"}, {5, "laden"}, {34, "fiber"},
  5341. {62, "ocean"}, {0, "academic"}, {10, NULL}, {255, NULL},
  5342. {203, NULL}, {9999, NULL}, {20000, NULL},
  5343. };
  5344. for (size_t i = 0; i < (sizeof(vectors) / sizeof(*vectors)); i++) {
  5345. const char *word = button_sequence_to_word(vectors[i].prefix);
  5346. if (vectors[i].expected_word != NULL) {
  5347. ck_assert_str_eq(word, vectors[i].expected_word);
  5348. } else {
  5349. ck_assert_ptr_eq(word, NULL);
  5350. }
  5351. }
  5352. }
  5353. END_TEST
  5354. START_TEST(test_slip39_word_completion) {
  5355. const char t9[] = {1, 1, 2, 2, 3, 3, 4, 4, 4, 4, 5, 5, 5,
  5356. 6, 6, 6, 6, 7, 7, 8, 8, 8, 9, 9, 9, 9};
  5357. for (size_t i = 0; i < WORDS_COUNT; ++i) {
  5358. const char *word = slip39_wordlist[i];
  5359. uint16_t prefix = t9[word[0] - 'a'];
  5360. for (size_t j = 1; j < 4; ++j) {
  5361. uint16_t mask = slip39_word_completion_mask(prefix);
  5362. uint8_t next = t9[word[j] - 'a'];
  5363. ck_assert_uint_ne(mask & (1 << (next - 1)), 0);
  5364. prefix = prefix * 10 + next;
  5365. }
  5366. ck_assert_str_eq(button_sequence_to_word(prefix), word);
  5367. }
  5368. }
  5369. END_TEST
  5370. START_TEST(test_shamir) {
  5371. #define SHAMIR_MAX_COUNT 16
  5372. static const struct {
  5373. const uint8_t result[SHAMIR_MAX_LEN];
  5374. uint8_t result_index;
  5375. const uint8_t share_indices[SHAMIR_MAX_COUNT];
  5376. const uint8_t share_values[SHAMIR_MAX_COUNT][SHAMIR_MAX_LEN];
  5377. uint8_t share_count;
  5378. size_t len;
  5379. bool ret;
  5380. } vectors[] = {{{7, 151, 168, 57, 186, 104, 218, 21, 209, 96, 106,
  5381. 152, 252, 35, 210, 208, 43, 47, 13, 21, 142, 122,
  5382. 24, 42, 149, 192, 95, 24, 240, 24, 148, 110},
  5383. 0,
  5384. {2},
  5385. {
  5386. {7, 151, 168, 57, 186, 104, 218, 21, 209, 96, 106,
  5387. 152, 252, 35, 210, 208, 43, 47, 13, 21, 142, 122,
  5388. 24, 42, 149, 192, 95, 24, 240, 24, 148, 110},
  5389. },
  5390. 1,
  5391. 32,
  5392. true},
  5393. {{53},
  5394. 255,
  5395. {14, 10, 1, 13, 8, 7, 3, 11, 9, 4, 6, 0, 5, 12, 15, 2},
  5396. {
  5397. {114},
  5398. {41},
  5399. {116},
  5400. {67},
  5401. {198},
  5402. {109},
  5403. {232},
  5404. {39},
  5405. {90},
  5406. {241},
  5407. {156},
  5408. {75},
  5409. {46},
  5410. {181},
  5411. {144},
  5412. {175},
  5413. },
  5414. 16,
  5415. 1,
  5416. true},
  5417. {{91, 188, 226, 91, 254, 197, 225},
  5418. 1,
  5419. {5, 1, 10},
  5420. {
  5421. {129, 18, 104, 86, 236, 73, 176},
  5422. {91, 188, 226, 91, 254, 197, 225},
  5423. {69, 53, 151, 204, 224, 37, 19},
  5424. },
  5425. 3,
  5426. 7,
  5427. true},
  5428. {{0},
  5429. 1,
  5430. {5, 1, 1},
  5431. {
  5432. {129, 18, 104, 86, 236, 73, 176},
  5433. {91, 188, 226, 91, 254, 197, 225},
  5434. {69, 53, 151, 204, 224, 37, 19},
  5435. },
  5436. 3,
  5437. 7,
  5438. false},
  5439. {{0},
  5440. 255,
  5441. {3, 12, 3},
  5442. {
  5443. {100, 176, 99, 142, 115, 192, 138},
  5444. {54, 139, 99, 172, 29, 137, 58},
  5445. {216, 119, 222, 40, 87, 25, 147},
  5446. },
  5447. 3,
  5448. 7,
  5449. false},
  5450. {{163, 120, 30, 243, 179, 172, 196, 137, 119, 17},
  5451. 3,
  5452. {1, 0, 12},
  5453. {{80, 180, 198, 131, 111, 251, 45, 181, 2, 242},
  5454. {121, 9, 79, 98, 132, 164, 9, 165, 19, 230},
  5455. {86, 52, 173, 138, 189, 223, 122, 102, 248, 157}},
  5456. 3,
  5457. 10,
  5458. true}};
  5459. for (size_t i = 0; i < (sizeof(vectors) / sizeof(*vectors)); ++i) {
  5460. uint8_t result[SHAMIR_MAX_LEN];
  5461. const uint8_t *share_values[SHAMIR_MAX_COUNT];
  5462. for (size_t j = 0; j < vectors[i].share_count; ++j) {
  5463. share_values[j] = vectors[i].share_values[j];
  5464. }
  5465. ck_assert_int_eq(shamir_interpolate(result, vectors[i].result_index,
  5466. vectors[i].share_indices, share_values,
  5467. vectors[i].share_count, vectors[i].len),
  5468. vectors[i].ret);
  5469. if (vectors[i].ret == true) {
  5470. ck_assert_mem_eq(result, vectors[i].result, vectors[i].len);
  5471. }
  5472. }
  5473. }
  5474. END_TEST
  5475. START_TEST(test_address) {
  5476. char address[36];
  5477. uint8_t pub_key[65];
  5478. memcpy(
  5479. pub_key,
  5480. fromhex(
  5481. "0226659c1cf7321c178c07437150639ff0c5b7679c7ea195253ed9abda2e081a37"),
  5482. 33);
  5483. ecdsa_get_address(pub_key, 0, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5484. sizeof(address));
  5485. ck_assert_str_eq(address, "139MaMHp3Vjo8o4x8N1ZLWEtovLGvBsg6s");
  5486. ecdsa_get_address(pub_key, 111, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5487. sizeof(address));
  5488. ck_assert_str_eq(address, "mhfJsQNnrXB3uuYZqvywARTDfuvyjg4RBh");
  5489. ecdsa_get_address(pub_key, 52, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5490. sizeof(address));
  5491. ck_assert_str_eq(address, "MxiimznnxsqMfLKTQBL8Z2PoY9jKpjgkCu");
  5492. ecdsa_get_address(pub_key, 48, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5493. sizeof(address));
  5494. ck_assert_str_eq(address, "LMNJqZbe89yrPbm7JVzrcXJf28hZ1rKPaH");
  5495. ecdsa_get_address(pub_key, 36, HASHER_SHA2_RIPEMD, HASHER_GROESTLD_TRUNC,
  5496. address, sizeof(address));
  5497. ck_assert_str_eq(address, "FXK52G2BbzRLaQ651U12o23DU5cEQdhvU6");
  5498. ecdsa_get_address_segwit_p2sh(pub_key, 5, HASHER_SHA2_RIPEMD, HASHER_SHA2D,
  5499. address, sizeof(address));
  5500. ck_assert_str_eq(address, "34PyTHn74syS796eTgsyoLfwoBC3cwLn6p");
  5501. memcpy(
  5502. pub_key,
  5503. fromhex(
  5504. "025b1654a0e78d28810094f6c5a96b8efb8a65668b578f170ac2b1f83bc63ba856"),
  5505. 33);
  5506. ecdsa_get_address(pub_key, 0, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5507. sizeof(address));
  5508. ck_assert_str_eq(address, "19Ywfm3witp6C1yBMy4NRYHY2347WCRBfQ");
  5509. ecdsa_get_address(pub_key, 111, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5510. sizeof(address));
  5511. ck_assert_str_eq(address, "mp4txp8vXvFLy8So5Y2kFTVrt2epN6YzdP");
  5512. ecdsa_get_address(pub_key, 52, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5513. sizeof(address));
  5514. ck_assert_str_eq(address, "N58JsQYveGueiZDgdnNwe4SSkGTAToutAY");
  5515. ecdsa_get_address(pub_key, 48, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5516. sizeof(address));
  5517. ck_assert_str_eq(address, "LTmtvyMmoZ49SpfLY73fhZMJEFRPdyohKh");
  5518. ecdsa_get_address(pub_key, 36, HASHER_SHA2_RIPEMD, HASHER_GROESTLD_TRUNC,
  5519. address, sizeof(address));
  5520. ck_assert_str_eq(address, "Fdif7fnKHPVddczJF53qt45rgCL51yWN6x");
  5521. ecdsa_get_address_segwit_p2sh(pub_key, 5, HASHER_SHA2_RIPEMD, HASHER_SHA2D,
  5522. address, sizeof(address));
  5523. ck_assert_str_eq(address, "35trq6eeuHf6VL9L8pQv46x3vegHnHoTuB");
  5524. memcpy(
  5525. pub_key,
  5526. fromhex(
  5527. "03433f246a12e6486a51ff08802228c61cf895175a9b49ed4766ea9a9294a3c7fe"),
  5528. 33);
  5529. ecdsa_get_address(pub_key, 0, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5530. sizeof(address));
  5531. ck_assert_str_eq(address, "1FWE2bn3MWhc4QidcF6AvEWpK77sSi2cAP");
  5532. ecdsa_get_address(pub_key, 111, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5533. sizeof(address));
  5534. ck_assert_str_eq(address, "mv2BKes2AY8rqXCFKp4Yk9j9B6iaMfWRLN");
  5535. ecdsa_get_address(pub_key, 52, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5536. sizeof(address));
  5537. ck_assert_str_eq(address, "NB5bEFH2GtoAawy8t4Qk8kfj3LWvQs3MhB");
  5538. ecdsa_get_address(pub_key, 48, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5539. sizeof(address));
  5540. ck_assert_str_eq(address, "LZjBHp5sSAwfKDQnnP5UCFaaXKV9YheGxQ");
  5541. ecdsa_get_address(pub_key, 36, HASHER_SHA2_RIPEMD, HASHER_GROESTLD_TRUNC,
  5542. address, sizeof(address));
  5543. ck_assert_str_eq(address, "FjfwUWWQv1P9W1jkVM5eNkK8yGPq5XyZZy");
  5544. ecdsa_get_address_segwit_p2sh(pub_key, 5, HASHER_SHA2_RIPEMD, HASHER_SHA2D,
  5545. address, sizeof(address));
  5546. ck_assert_str_eq(address, "3456DYaKUWuY6RWWw8Hp5CftHLcQN29h9Y");
  5547. memcpy(
  5548. pub_key,
  5549. fromhex(
  5550. "03aeb03abeee0f0f8b4f7a5d65ce31f9570cef9f72c2dd8a19b4085a30ab033d48"),
  5551. 33);
  5552. ecdsa_get_address(pub_key, 0, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5553. sizeof(address));
  5554. ck_assert_str_eq(address, "1yrZb8dhdevoqpUEGi2tUccUEeiMKeLcs");
  5555. ecdsa_get_address(pub_key, 111, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5556. sizeof(address));
  5557. ck_assert_str_eq(address, "mgVoreDcWf6BaxJ5wqgQiPpwLEFRLSr8U8");
  5558. ecdsa_get_address(pub_key, 52, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5559. sizeof(address));
  5560. ck_assert_str_eq(address, "MwZDmEdcd1kVLP4yW62c6zmXCU3mNbveDo");
  5561. ecdsa_get_address(pub_key, 48, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5562. sizeof(address));
  5563. ck_assert_str_eq(address, "LLCopoSTnHtz4eWdQQhLAVgNgT1zTi4QBK");
  5564. ecdsa_get_address(pub_key, 36, HASHER_SHA2_RIPEMD, HASHER_GROESTLD_TRUNC,
  5565. address, sizeof(address));
  5566. ck_assert_str_eq(address, "FW9a1Vs1G8LUFSqb7NhWLzQw8PvfwAxmxA");
  5567. ecdsa_get_address_segwit_p2sh(pub_key, 5, HASHER_SHA2_RIPEMD, HASHER_SHA2D,
  5568. address, sizeof(address));
  5569. ck_assert_str_eq(address, "3DBU4tJ9tkMR9fnmCtjW48kjvseoNLQZXd");
  5570. memcpy(
  5571. pub_key,
  5572. fromhex(
  5573. "0496e8f2093f018aff6c2e2da5201ee528e2c8accbf9cac51563d33a7bb74a016054"
  5574. "201c025e2a5d96b1629b95194e806c63eb96facaedc733b1a4b70ab3b33e3a"),
  5575. 65);
  5576. ecdsa_get_address(pub_key, 0, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5577. sizeof(address));
  5578. ck_assert_str_eq(address, "194SZbL75xCCGBbKtMsyWLE5r9s2V6mhVM");
  5579. ecdsa_get_address(pub_key, 111, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5580. sizeof(address));
  5581. ck_assert_str_eq(address, "moaPreR5tydT3J4wbvrMLFSQi9TjPCiZc6");
  5582. ecdsa_get_address(pub_key, 52, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5583. sizeof(address));
  5584. ck_assert_str_eq(address, "N4domEq61LHkniqqABCYirNzaPG5NRU8GH");
  5585. ecdsa_get_address(pub_key, 48, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5586. sizeof(address));
  5587. ck_assert_str_eq(address, "LTHPpodwAcSFWzHV4VsGnMHr4NEJajMnKX");
  5588. ecdsa_get_address(pub_key, 36, HASHER_SHA2_RIPEMD, HASHER_GROESTLD_TRUNC,
  5589. address, sizeof(address));
  5590. ck_assert_str_eq(address, "FdEA1W4UeSsjhncSmTsSxr2QWK8z2xGkjc");
  5591. memcpy(
  5592. pub_key,
  5593. fromhex(
  5594. "0498010f8a687439ff497d3074beb4519754e72c4b6220fb669224749591dde416f3"
  5595. "961f8ece18f8689bb32235e436874d2174048b86118a00afbd5a4f33a24f0f"),
  5596. 65);
  5597. ecdsa_get_address(pub_key, 0, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5598. sizeof(address));
  5599. ck_assert_str_eq(address, "1A2WfBD4BJFwYHFPc5KgktqtbdJLBuVKc4");
  5600. ecdsa_get_address(pub_key, 111, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5601. sizeof(address));
  5602. ck_assert_str_eq(address, "mpYTxEJ2zKhCKPj1KeJ4ap4DTcu39T3uzD");
  5603. ecdsa_get_address(pub_key, 52, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5604. sizeof(address));
  5605. ck_assert_str_eq(address, "N5bsrpi36gMW4pVtsteFyQzoKrhPE7nkxK");
  5606. ecdsa_get_address(pub_key, 48, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5607. sizeof(address));
  5608. ck_assert_str_eq(address, "LUFTvPWtFxVzo5wYnDJz2uueoqfcMYiuxH");
  5609. ecdsa_get_address(pub_key, 36, HASHER_SHA2_RIPEMD, HASHER_GROESTLD_TRUNC,
  5610. address, sizeof(address));
  5611. ck_assert_str_eq(address, "FeCE75wRjnwUytGWVBKADQeDFnaHpJ8t3B");
  5612. memcpy(
  5613. pub_key,
  5614. fromhex(
  5615. "04f80490839af36d13701ec3f9eebdac901b51c362119d74553a3c537faff31b17e2"
  5616. "a59ebddbdac9e87b816307a7ed5b826b8f40b92719086238e1bebf19b77a4d"),
  5617. 65);
  5618. ecdsa_get_address(pub_key, 0, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5619. sizeof(address));
  5620. ck_assert_str_eq(address, "19J81hrPnQxg9UGx45ibTieCkb2ttm8CLL");
  5621. ecdsa_get_address(pub_key, 111, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5622. sizeof(address));
  5623. ck_assert_str_eq(address, "mop5JkwNbSPvvakZmegyHdrXcadbjLazww");
  5624. ecdsa_get_address(pub_key, 52, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5625. sizeof(address));
  5626. ck_assert_str_eq(address, "N4sVDMMNho4Eg1XTKu3AgEo7UpRwq3aNbn");
  5627. ecdsa_get_address(pub_key, 48, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  5628. sizeof(address));
  5629. ck_assert_str_eq(address, "LTX5GvADs5CjQGy7EDhtjjhxxoQB2Uhicd");
  5630. ecdsa_get_address(pub_key, 36, HASHER_SHA2_RIPEMD, HASHER_GROESTLD_TRUNC,
  5631. address, sizeof(address));
  5632. ck_assert_str_eq(address, "FdTqTcamLueDb5J4wBi4vESXQkJrS54H6k");
  5633. }
  5634. END_TEST
  5635. START_TEST(test_pubkey_validity) {
  5636. uint8_t pub_key[65];
  5637. curve_point pub;
  5638. int res;
  5639. const ecdsa_curve *curve = &secp256k1;
  5640. memcpy(
  5641. pub_key,
  5642. fromhex(
  5643. "0226659c1cf7321c178c07437150639ff0c5b7679c7ea195253ed9abda2e081a37"),
  5644. 33);
  5645. res = ecdsa_read_pubkey(curve, pub_key, &pub);
  5646. ck_assert_int_eq(res, 1);
  5647. memcpy(
  5648. pub_key,
  5649. fromhex(
  5650. "025b1654a0e78d28810094f6c5a96b8efb8a65668b578f170ac2b1f83bc63ba856"),
  5651. 33);
  5652. res = ecdsa_read_pubkey(curve, pub_key, &pub);
  5653. ck_assert_int_eq(res, 1);
  5654. memcpy(
  5655. pub_key,
  5656. fromhex(
  5657. "03433f246a12e6486a51ff08802228c61cf895175a9b49ed4766ea9a9294a3c7fe"),
  5658. 33);
  5659. res = ecdsa_read_pubkey(curve, pub_key, &pub);
  5660. ck_assert_int_eq(res, 1);
  5661. memcpy(
  5662. pub_key,
  5663. fromhex(
  5664. "03aeb03abeee0f0f8b4f7a5d65ce31f9570cef9f72c2dd8a19b4085a30ab033d48"),
  5665. 33);
  5666. res = ecdsa_read_pubkey(curve, pub_key, &pub);
  5667. ck_assert_int_eq(res, 1);
  5668. memcpy(
  5669. pub_key,
  5670. fromhex(
  5671. "0496e8f2093f018aff6c2e2da5201ee528e2c8accbf9cac51563d33a7bb74a016054"
  5672. "201c025e2a5d96b1629b95194e806c63eb96facaedc733b1a4b70ab3b33e3a"),
  5673. 65);
  5674. res = ecdsa_read_pubkey(curve, pub_key, &pub);
  5675. ck_assert_int_eq(res, 1);
  5676. memcpy(
  5677. pub_key,
  5678. fromhex(
  5679. "0498010f8a687439ff497d3074beb4519754e72c4b6220fb669224749591dde416f3"
  5680. "961f8ece18f8689bb32235e436874d2174048b86118a00afbd5a4f33a24f0f"),
  5681. 65);
  5682. res = ecdsa_read_pubkey(curve, pub_key, &pub);
  5683. ck_assert_int_eq(res, 1);
  5684. memcpy(
  5685. pub_key,
  5686. fromhex(
  5687. "04f80490839af36d13701ec3f9eebdac901b51c362119d74553a3c537faff31b17e2"
  5688. "a59ebddbdac9e87b816307a7ed5b826b8f40b92719086238e1bebf19b77a4d"),
  5689. 65);
  5690. res = ecdsa_read_pubkey(curve, pub_key, &pub);
  5691. ck_assert_int_eq(res, 1);
  5692. memcpy(
  5693. pub_key,
  5694. fromhex(
  5695. "04f80490839af36d13701ec3f9eebdac901b51c362119d74553a3c537faff31b17e2"
  5696. "a59ebddbdac9e87b816307a7ed5b826b8f40b92719086238e1bebf00000000"),
  5697. 65);
  5698. res = ecdsa_read_pubkey(curve, pub_key, &pub);
  5699. ck_assert_int_eq(res, 0);
  5700. memcpy(
  5701. pub_key,
  5702. fromhex(
  5703. "04f80490839af36d13701ec3f9eebdac901b51c362119d74553a3c537faff31b17e2"
  5704. "a59ebddbdac9e87b816307a7ed5b8211111111111111111111111111111111"),
  5705. 65);
  5706. res = ecdsa_read_pubkey(curve, pub_key, &pub);
  5707. ck_assert_int_eq(res, 0);
  5708. memcpy(pub_key, fromhex("00"), 1);
  5709. res = ecdsa_read_pubkey(curve, pub_key, &pub);
  5710. ck_assert_int_eq(res, 0);
  5711. }
  5712. END_TEST
  5713. START_TEST(test_pubkey_uncompress) {
  5714. uint8_t pub_key[65];
  5715. uint8_t uncompressed[65];
  5716. int res;
  5717. const ecdsa_curve *curve = &secp256k1;
  5718. memcpy(
  5719. pub_key,
  5720. fromhex(
  5721. "0226659c1cf7321c178c07437150639ff0c5b7679c7ea195253ed9abda2e081a37"),
  5722. 33);
  5723. res = ecdsa_uncompress_pubkey(curve, pub_key, uncompressed);
  5724. ck_assert_int_eq(res, 1);
  5725. ck_assert_mem_eq(
  5726. uncompressed,
  5727. fromhex(
  5728. "0426659c1cf7321c178c07437150639ff0c5b7679c7ea195253ed9abda2e081a37b3"
  5729. "cfbad6b39a8ce8cb3a675f53b7b57e120fe067b8035d771fd99e3eba7cf4de"),
  5730. 65);
  5731. memcpy(
  5732. pub_key,
  5733. fromhex(
  5734. "03433f246a12e6486a51ff08802228c61cf895175a9b49ed4766ea9a9294a3c7fe"),
  5735. 33);
  5736. res = ecdsa_uncompress_pubkey(curve, pub_key, uncompressed);
  5737. ck_assert_int_eq(res, 1);
  5738. ck_assert_mem_eq(
  5739. uncompressed,
  5740. fromhex(
  5741. "04433f246a12e6486a51ff08802228c61cf895175a9b49ed4766ea9a9294a3c7feeb"
  5742. "4c25bcb840f720a16e8857a011e6b91e0ab2d03dbb5f9762844bb21a7b8ca7"),
  5743. 65);
  5744. memcpy(
  5745. pub_key,
  5746. fromhex(
  5747. "0496e8f2093f018aff6c2e2da5201ee528e2c8accbf9cac51563d33a7bb74a016054"
  5748. "201c025e2a5d96b1629b95194e806c63eb96facaedc733b1a4b70ab3b33e3a"),
  5749. 65);
  5750. res = ecdsa_uncompress_pubkey(curve, pub_key, uncompressed);
  5751. ck_assert_int_eq(res, 1);
  5752. ck_assert_mem_eq(
  5753. uncompressed,
  5754. fromhex(
  5755. "0496e8f2093f018aff6c2e2da5201ee528e2c8accbf9cac51563d33a7bb74a016054"
  5756. "201c025e2a5d96b1629b95194e806c63eb96facaedc733b1a4b70ab3b33e3a"),
  5757. 65);
  5758. memcpy(pub_key, fromhex("00"), 1);
  5759. res = ecdsa_uncompress_pubkey(curve, pub_key, uncompressed);
  5760. ck_assert_int_eq(res, 0);
  5761. }
  5762. END_TEST
  5763. START_TEST(test_wif) {
  5764. uint8_t priv_key[32];
  5765. char wif[53];
  5766. memcpy(
  5767. priv_key,
  5768. fromhex(
  5769. "1111111111111111111111111111111111111111111111111111111111111111"),
  5770. 32);
  5771. ecdsa_get_wif(priv_key, 0x80, HASHER_SHA2D, wif, sizeof(wif));
  5772. ck_assert_str_eq(wif, "KwntMbt59tTsj8xqpqYqRRWufyjGunvhSyeMo3NTYpFYzZbXJ5Hp");
  5773. ecdsa_get_wif(priv_key, 0xEF, HASHER_SHA2D, wif, sizeof(wif));
  5774. ck_assert_str_eq(wif, "cN9spWsvaxA8taS7DFMxnk1yJD2gaF2PX1npuTpy3vuZFJdwavaw");
  5775. memcpy(
  5776. priv_key,
  5777. fromhex(
  5778. "dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd"),
  5779. 32);
  5780. ecdsa_get_wif(priv_key, 0x80, HASHER_SHA2D, wif, sizeof(wif));
  5781. ck_assert_str_eq(wif, "L4ezQvyC6QoBhxB4GVs9fAPhUKtbaXYUn8YTqoeXwbevQq4U92vN");
  5782. ecdsa_get_wif(priv_key, 0xEF, HASHER_SHA2D, wif, sizeof(wif));
  5783. ck_assert_str_eq(wif, "cV1ysqy3XUVSsPeKeugH2Utm6ZC1EyeArAgvxE73SiJvfa6AJng7");
  5784. memcpy(
  5785. priv_key,
  5786. fromhex(
  5787. "47f7616ea6f9b923076625b4488115de1ef1187f760e65f89eb6f4f7ff04b012"),
  5788. 32);
  5789. ecdsa_get_wif(priv_key, 0x80, HASHER_SHA2D, wif, sizeof(wif));
  5790. ck_assert_str_eq(wif, "KydbzBtk6uc7M6dXwEgTEH2sphZxSPbmDSz6kUUHi4eUpSQuhEbq");
  5791. ecdsa_get_wif(priv_key, 0xEF, HASHER_SHA2D, wif, sizeof(wif));
  5792. ck_assert_str_eq(wif, "cPzbT6tbXyJNWY6oKeVabbXwSvsN6qhTHV8ZrtvoDBJV5BRY1G5Q");
  5793. }
  5794. END_TEST
  5795. START_TEST(test_address_decode) {
  5796. int res;
  5797. uint8_t decode[MAX_ADDR_RAW_SIZE];
  5798. res = ecdsa_address_decode("1JwSSubhmg6iPtRjtyqhUYYH7bZg3Lfy1T", 0,
  5799. HASHER_SHA2D, decode);
  5800. ck_assert_int_eq(res, 1);
  5801. ck_assert_mem_eq(decode,
  5802. fromhex("00c4c5d791fcb4654a1ef5e03fe0ad3d9c598f9827"), 21);
  5803. res = ecdsa_address_decode("myTPjxggahXyAzuMcYp5JTkbybANyLsYBW", 111,
  5804. HASHER_SHA2D, decode);
  5805. ck_assert_int_eq(res, 1);
  5806. ck_assert_mem_eq(decode,
  5807. fromhex("6fc4c5d791fcb4654a1ef5e03fe0ad3d9c598f9827"), 21);
  5808. res = ecdsa_address_decode("NEWoeZ6gh4CGvRgFAoAGh4hBqpxizGT6gZ", 52,
  5809. HASHER_SHA2D, decode);
  5810. ck_assert_int_eq(res, 1);
  5811. ck_assert_mem_eq(decode,
  5812. fromhex("34c4c5d791fcb4654a1ef5e03fe0ad3d9c598f9827"), 21);
  5813. res = ecdsa_address_decode("LdAPi7uXrLLmeh7u57pzkZc3KovxEDYRJq", 48,
  5814. HASHER_SHA2D, decode);
  5815. ck_assert_int_eq(res, 1);
  5816. ck_assert_mem_eq(decode,
  5817. fromhex("30c4c5d791fcb4654a1ef5e03fe0ad3d9c598f9827"), 21);
  5818. res = ecdsa_address_decode("1C7zdTfnkzmr13HfA2vNm5SJYRK6nEKyq8", 0,
  5819. HASHER_SHA2D, decode);
  5820. ck_assert_int_eq(res, 1);
  5821. ck_assert_mem_eq(decode,
  5822. fromhex("0079fbfc3f34e7745860d76137da68f362380c606c"), 21);
  5823. res = ecdsa_address_decode("mrdwvWkma2D6n9mGsbtkazedQQuoksnqJV", 111,
  5824. HASHER_SHA2D, decode);
  5825. ck_assert_int_eq(res, 1);
  5826. ck_assert_mem_eq(decode,
  5827. fromhex("6f79fbfc3f34e7745860d76137da68f362380c606c"), 21);
  5828. res = ecdsa_address_decode("N7hMq7AmgNsQXaYARrEwybbDGei9mcPNqr", 52,
  5829. HASHER_SHA2D, decode);
  5830. ck_assert_int_eq(res, 1);
  5831. ck_assert_mem_eq(decode,
  5832. fromhex("3479fbfc3f34e7745860d76137da68f362380c606c"), 21);
  5833. res = ecdsa_address_decode("LWLwtfycqf1uFqypLAug36W4kdgNwrZdNs", 48,
  5834. HASHER_SHA2D, decode);
  5835. ck_assert_int_eq(res, 1);
  5836. ck_assert_mem_eq(decode,
  5837. fromhex("3079fbfc3f34e7745860d76137da68f362380c606c"), 21);
  5838. // invalid char
  5839. res = ecdsa_address_decode("1JwSSubhmg6i000jtyqhUYYH7bZg3Lfy1T", 0,
  5840. HASHER_SHA2D, decode);
  5841. ck_assert_int_eq(res, 0);
  5842. // invalid address
  5843. res = ecdsa_address_decode("1111Subhmg6iPtRjtyqhUYYH7bZg3Lfy1T", 0,
  5844. HASHER_SHA2D, decode);
  5845. ck_assert_int_eq(res, 0);
  5846. // invalid version
  5847. res = ecdsa_address_decode("LWLwtfycqf1uFqypLAug36W4kdgNwrZdNs", 0,
  5848. HASHER_SHA2D, decode);
  5849. ck_assert_int_eq(res, 0);
  5850. }
  5851. END_TEST
  5852. START_TEST(test_ecdsa_der) {
  5853. static const struct {
  5854. const char *r;
  5855. const char *s;
  5856. const char *der;
  5857. } vectors[] = {
  5858. {
  5859. "9a0b7be0d4ed3146ee262b42202841834698bb3ee39c24e7437df208b8b70771",
  5860. "2b79ab1e7736219387dffe8d615bbdba87e11477104b867ef47afed1a5ede781",
  5861. "30450221009a0b7be0d4ed3146ee262b42202841834698bb3ee39c24e7437df208b8"
  5862. "b7077102202b79ab1e7736219387dffe8d615bbdba87e11477104b867ef47afed1a5"
  5863. "ede781",
  5864. },
  5865. {
  5866. "6666666666666666666666666666666666666666666666666666666666666666",
  5867. "7777777777777777777777777777777777777777777777777777777777777777",
  5868. "30440220666666666666666666666666666666666666666666666666666666666666"
  5869. "66660220777777777777777777777777777777777777777777777777777777777777"
  5870. "7777",
  5871. },
  5872. {
  5873. "6666666666666666666666666666666666666666666666666666666666666666",
  5874. "eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee",
  5875. "30450220666666666666666666666666666666666666666666666666666666666666"
  5876. "6666022100eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"
  5877. "eeeeee",
  5878. },
  5879. {
  5880. "eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee",
  5881. "7777777777777777777777777777777777777777777777777777777777777777",
  5882. "3045022100eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"
  5883. "eeeeee02207777777777777777777777777777777777777777777777777777777777"
  5884. "777777",
  5885. },
  5886. {
  5887. "eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee",
  5888. "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",
  5889. "3046022100eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"
  5890. "eeeeee022100ffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
  5891. "ffffffff",
  5892. },
  5893. {
  5894. "0000000000000000000000000000000000000000000000000000000000000066",
  5895. "0000000000000000000000000000000000000000000000000000000000000077",
  5896. "3006020166020177",
  5897. },
  5898. {
  5899. "0000000000000000000000000000000000000000000000000000000000000066",
  5900. "00000000000000000000000000000000000000000000000000000000000000ee",
  5901. "3007020166020200ee",
  5902. },
  5903. {
  5904. "00000000000000000000000000000000000000000000000000000000000000ee",
  5905. "0000000000000000000000000000000000000000000000000000000000000077",
  5906. "3007020200ee020177",
  5907. },
  5908. {
  5909. "00000000000000000000000000000000000000000000000000000000000000ee",
  5910. "00000000000000000000000000000000000000000000000000000000000000ff",
  5911. "3008020200ee020200ff",
  5912. },
  5913. {
  5914. "0000000000000000000000000000000000000000000000000000000000000000",
  5915. "0000000000000000000000000000000000000000000000000000000000000000",
  5916. "3006020100020100",
  5917. },
  5918. };
  5919. uint8_t sig[64];
  5920. uint8_t der[72];
  5921. uint8_t out[72];
  5922. for (size_t i = 0; i < (sizeof(vectors) / sizeof(*vectors)); ++i) {
  5923. size_t der_len = strlen(vectors[i].der) / 2;
  5924. memcpy(der, fromhex(vectors[i].der), der_len);
  5925. memcpy(sig, fromhex(vectors[i].r), 32);
  5926. memcpy(sig + 32, fromhex(vectors[i].s), 32);
  5927. ck_assert_int_eq(ecdsa_sig_to_der(sig, out), der_len);
  5928. ck_assert_mem_eq(out, der, der_len);
  5929. ck_assert_int_eq(ecdsa_sig_from_der(der, der_len, out), 0);
  5930. ck_assert_mem_eq(out, sig, 64);
  5931. }
  5932. }
  5933. END_TEST
  5934. static void test_codepoints_curve(const ecdsa_curve *curve) {
  5935. int i, j;
  5936. bignum256 a;
  5937. curve_point p, p1;
  5938. for (i = 0; i < 64; i++) {
  5939. for (j = 0; j < 8; j++) {
  5940. bn_zero(&a);
  5941. a.val[(4 * i) / BN_BITS_PER_LIMB] = (uint32_t)(2 * j + 1)
  5942. << (4 * i % BN_BITS_PER_LIMB);
  5943. bn_normalize(&a);
  5944. // note that this is not a trivial test. We add 64 curve
  5945. // points in the table to get that particular curve point.
  5946. scalar_multiply(curve, &a, &p);
  5947. ck_assert_mem_eq(&p, &curve->cp[i][j], sizeof(curve_point));
  5948. bn_zero(&p.y); // test that point_multiply curve, is not a noop
  5949. point_multiply(curve, &a, &curve->G, &p);
  5950. ck_assert_mem_eq(&p, &curve->cp[i][j], sizeof(curve_point));
  5951. // mul 2 test. this should catch bugs
  5952. bn_lshift(&a);
  5953. bn_mod(&a, &curve->order);
  5954. p1 = curve->cp[i][j];
  5955. point_double(curve, &p1);
  5956. // note that this is not a trivial test. We add 64 curve
  5957. // points in the table to get that particular curve point.
  5958. scalar_multiply(curve, &a, &p);
  5959. ck_assert_mem_eq(&p, &p1, sizeof(curve_point));
  5960. bn_zero(&p.y); // test that point_multiply curve, is not a noop
  5961. point_multiply(curve, &a, &curve->G, &p);
  5962. ck_assert_mem_eq(&p, &p1, sizeof(curve_point));
  5963. }
  5964. }
  5965. }
  5966. START_TEST(test_codepoints_secp256k1) { test_codepoints_curve(&secp256k1); }
  5967. END_TEST
  5968. START_TEST(test_codepoints_nist256p1) { test_codepoints_curve(&nist256p1); }
  5969. END_TEST
  5970. static void test_mult_border_cases_curve(const ecdsa_curve *curve) {
  5971. bignum256 a;
  5972. curve_point p;
  5973. curve_point expected;
  5974. bn_zero(&a); // a == 0
  5975. scalar_multiply(curve, &a, &p);
  5976. ck_assert(point_is_infinity(&p));
  5977. point_multiply(curve, &a, &p, &p);
  5978. ck_assert(point_is_infinity(&p));
  5979. point_multiply(curve, &a, &curve->G, &p);
  5980. ck_assert(point_is_infinity(&p));
  5981. bn_addi(&a, 1); // a == 1
  5982. scalar_multiply(curve, &a, &p);
  5983. ck_assert_mem_eq(&p, &curve->G, sizeof(curve_point));
  5984. point_multiply(curve, &a, &curve->G, &p);
  5985. ck_assert_mem_eq(&p, &curve->G, sizeof(curve_point));
  5986. bn_subtract(&curve->order, &a, &a); // a == -1
  5987. expected = curve->G;
  5988. bn_subtract(&curve->prime, &expected.y, &expected.y);
  5989. scalar_multiply(curve, &a, &p);
  5990. ck_assert_mem_eq(&p, &expected, sizeof(curve_point));
  5991. point_multiply(curve, &a, &curve->G, &p);
  5992. ck_assert_mem_eq(&p, &expected, sizeof(curve_point));
  5993. bn_subtract(&curve->order, &a, &a);
  5994. bn_addi(&a, 1); // a == 2
  5995. expected = curve->G;
  5996. point_add(curve, &expected, &expected);
  5997. scalar_multiply(curve, &a, &p);
  5998. ck_assert_mem_eq(&p, &expected, sizeof(curve_point));
  5999. point_multiply(curve, &a, &curve->G, &p);
  6000. ck_assert_mem_eq(&p, &expected, sizeof(curve_point));
  6001. bn_subtract(&curve->order, &a, &a); // a == -2
  6002. expected = curve->G;
  6003. point_add(curve, &expected, &expected);
  6004. bn_subtract(&curve->prime, &expected.y, &expected.y);
  6005. scalar_multiply(curve, &a, &p);
  6006. ck_assert_mem_eq(&p, &expected, sizeof(curve_point));
  6007. point_multiply(curve, &a, &curve->G, &p);
  6008. ck_assert_mem_eq(&p, &expected, sizeof(curve_point));
  6009. }
  6010. START_TEST(test_mult_border_cases_secp256k1) {
  6011. test_mult_border_cases_curve(&secp256k1);
  6012. }
  6013. END_TEST
  6014. START_TEST(test_mult_border_cases_nist256p1) {
  6015. test_mult_border_cases_curve(&nist256p1);
  6016. }
  6017. END_TEST
  6018. static void test_scalar_mult_curve(const ecdsa_curve *curve) {
  6019. int i;
  6020. // get two "random" numbers
  6021. bignum256 a = curve->G.x;
  6022. bignum256 b = curve->G.y;
  6023. curve_point p1, p2, p3;
  6024. for (i = 0; i < 1000; i++) {
  6025. /* test distributivity: (a + b)G = aG + bG */
  6026. bn_mod(&a, &curve->order);
  6027. bn_mod(&b, &curve->order);
  6028. scalar_multiply(curve, &a, &p1);
  6029. scalar_multiply(curve, &b, &p2);
  6030. bn_addmod(&a, &b, &curve->order);
  6031. bn_mod(&a, &curve->order);
  6032. scalar_multiply(curve, &a, &p3);
  6033. point_add(curve, &p1, &p2);
  6034. ck_assert_mem_eq(&p2, &p3, sizeof(curve_point));
  6035. // new "random" numbers
  6036. a = p3.x;
  6037. b = p3.y;
  6038. }
  6039. }
  6040. START_TEST(test_scalar_mult_secp256k1) { test_scalar_mult_curve(&secp256k1); }
  6041. END_TEST
  6042. START_TEST(test_scalar_mult_nist256p1) { test_scalar_mult_curve(&nist256p1); }
  6043. END_TEST
  6044. static void test_point_mult_curve(const ecdsa_curve *curve) {
  6045. int i;
  6046. // get two "random" numbers and a "random" point
  6047. bignum256 a = curve->G.x;
  6048. bignum256 b = curve->G.y;
  6049. curve_point p = curve->G;
  6050. curve_point p1, p2, p3;
  6051. for (i = 0; i < 200; i++) {
  6052. /* test distributivity: (a + b)P = aP + bP */
  6053. bn_mod(&a, &curve->order);
  6054. bn_mod(&b, &curve->order);
  6055. ck_assert_int_eq(point_multiply(curve, &a, &p, &p1), 0);
  6056. ck_assert_int_eq(point_multiply(curve, &b, &p, &p2), 0);
  6057. bn_addmod(&a, &b, &curve->order);
  6058. bn_mod(&a, &curve->order);
  6059. ck_assert_int_eq(point_multiply(curve, &a, &p, &p3), 0);
  6060. point_add(curve, &p1, &p2);
  6061. ck_assert_mem_eq(&p2, &p3, sizeof(curve_point));
  6062. // new "random" numbers and a "random" point
  6063. a = p1.x;
  6064. b = p1.y;
  6065. p = p3;
  6066. }
  6067. }
  6068. START_TEST(test_point_mult_secp256k1) { test_point_mult_curve(&secp256k1); }
  6069. END_TEST
  6070. START_TEST(test_point_mult_nist256p1) { test_point_mult_curve(&nist256p1); }
  6071. END_TEST
  6072. static void test_scalar_point_mult_curve(const ecdsa_curve *curve) {
  6073. int i;
  6074. // get two "random" numbers
  6075. bignum256 a = curve->G.x;
  6076. bignum256 b = curve->G.y;
  6077. curve_point p1, p2;
  6078. for (i = 0; i < 200; i++) {
  6079. /* test commutativity and associativity:
  6080. * a(bG) = (ab)G = b(aG)
  6081. */
  6082. bn_mod(&a, &curve->order);
  6083. bn_mod(&b, &curve->order);
  6084. ck_assert_int_eq(scalar_multiply(curve, &a, &p1), 0);
  6085. ck_assert_int_eq(point_multiply(curve, &b, &p1, &p1), 0);
  6086. ck_assert_int_eq(scalar_multiply(curve, &b, &p2), 0);
  6087. ck_assert_int_eq(point_multiply(curve, &a, &p2, &p2), 0);
  6088. ck_assert_mem_eq(&p1, &p2, sizeof(curve_point));
  6089. bn_multiply(&a, &b, &curve->order);
  6090. bn_mod(&b, &curve->order);
  6091. ck_assert_int_eq(scalar_multiply(curve, &b, &p2), 0);
  6092. ck_assert_mem_eq(&p1, &p2, sizeof(curve_point));
  6093. // new "random" numbers
  6094. a = p1.x;
  6095. b = p1.y;
  6096. }
  6097. }
  6098. START_TEST(test_scalar_point_mult_secp256k1) {
  6099. test_scalar_point_mult_curve(&secp256k1);
  6100. }
  6101. END_TEST
  6102. START_TEST(test_scalar_point_mult_nist256p1) {
  6103. test_scalar_point_mult_curve(&nist256p1);
  6104. }
  6105. END_TEST
  6106. START_TEST(test_ed25519) {
  6107. // test vectors from
  6108. // https://github.com/torproject/tor/blob/master/src/test/ed25519_vectors.inc
  6109. static const char *vectors[] = {
  6110. "26c76712d89d906e6672dafa614c42e5cb1caac8c6568e4d2493087db51f0d3"
  6111. "6", // secret
  6112. "c2247870536a192d142d056abefca68d6193158e7c1a59c1654c954eccaff89"
  6113. "4", // public
  6114. "d23188eac3773a316d46006fa59c095060be8b1a23582a0dd99002a82a0662bd"
  6115. "246d8449e172e04c5f46ac0d1404cebe4aabd8a75a1457aa06cae41f3334f10"
  6116. "4", // selfsig
  6117. "fba7a5366b5cb98c2667a18783f5cf8f4f8d1a2ce939ad22a6e685edde85128"
  6118. "d",
  6119. "1519a3b15816a1aafab0b213892026ebf5c0dc232c58b21088d88cb90e9b940"
  6120. "d",
  6121. "3a785ac1201c97ee5f6f0d99323960d5f264c7825e61aa7cc81262f15bef75eb"
  6122. "4fa5723add9b9d45b12311b6d403eb3ac79ff8e4e631fc3cd51e4ad2185b200"
  6123. "b",
  6124. "67e3aa7a14fac8445d15e45e38a523481a69ae35513c9e4143eb1c2196729a0"
  6125. "e",
  6126. "081faa81992e360ea22c06af1aba096e7a73f1c665bc8b3e4e531c46455fd1d"
  6127. "d",
  6128. "cf431fd0416bfbd20c9d95ef9b723e2acddffb33900edc72195dea95965d52d8"
  6129. "88d30b7b8a677c0bd8ae1417b1e1a0ec6700deadd5d8b54b6689275e04a0450"
  6130. "9",
  6131. "d51385942033a76dc17f089a59e6a5a7fe80d9c526ae8ddd8c3a506b99d3d0a"
  6132. "6",
  6133. "73cfa1189a723aad7966137cbffa35140bb40d7e16eae4c40b79b5f0360dd65"
  6134. "a",
  6135. "2375380cd72d1a6c642aeddff862be8a5804b916acb72c02d9ed052c1561881a"
  6136. "a658a5af856fcd6d43113e42f698cd6687c99efeef7f2ce045824440d26c5d0"
  6137. "0",
  6138. "5c8eac469bb3f1b85bc7cd893f52dc42a9ab66f1b02b5ce6a68e9b175d3bb43"
  6139. "3",
  6140. "66c1a77104d86461b6f98f73acf3cd229c80624495d2d74d6fda1e940080a96"
  6141. "b",
  6142. "2385a472f599ca965bbe4d610e391cdeabeba9c336694b0d6249e551458280be"
  6143. "122c2441dd9746a81bbfb9cd619364bab0df37ff4ceb7aefd24469c39d3bc50"
  6144. "8",
  6145. "eda433d483059b6d1ff8b7cfbd0fe406bfb23722c8f3c8252629284573b61b8"
  6146. "6",
  6147. "d21c294db0e64cb2d8976625786ede1d9754186ae8197a64d72f68c792eecc1"
  6148. "9",
  6149. "e500cd0b8cfff35442f88008d894f3a2fa26ef7d3a0ca5714ae0d3e2d40caae5"
  6150. "8ba7cdf69dd126994dad6be536fcda846d89dd8138d1683cc144c8853dce760"
  6151. "7",
  6152. "4377c40431c30883c5fbd9bc92ae48d1ed8a47b81d13806beac5351739b5533"
  6153. "d",
  6154. "c4d58b4cf85a348ff3d410dd936fa460c4f18da962c01b1963792b9dcc8a6ea"
  6155. "6",
  6156. "d187b9e334b0050154de10bf69b3e4208a584e1a65015ec28b14bcc252cf84b8"
  6157. "baa9c94867daa60f2a82d09ba9652d41e8dde292b624afc8d2c26441b95e3c0"
  6158. "e",
  6159. "c6bbcce615839756aed2cc78b1de13884dd3618f48367a17597a16c1cd7a290"
  6160. "b",
  6161. "95126f14d86494020665face03f2d42ee2b312a85bc729903eb17522954a1c4"
  6162. "a",
  6163. "815213640a643d198bd056e02bba74e1c8d2d931643e84497adf3347eb485079"
  6164. "c9afe0afce9284cdc084946b561abbb214f1304ca11228ff82702185cf28f60"
  6165. "d",
  6166. 0,
  6167. 0,
  6168. 0,
  6169. };
  6170. const char **ssk, **spk, **ssig;
  6171. ssk = vectors;
  6172. spk = vectors + 1;
  6173. ssig = vectors + 2;
  6174. ed25519_public_key pk;
  6175. ed25519_secret_key sk;
  6176. ed25519_signature sig;
  6177. while (*ssk && *spk && *ssig) {
  6178. memcpy(sk, fromhex(*ssk), 32);
  6179. MARK_SECRET_DATA(sk, sizeof(sk));
  6180. ed25519_publickey(sk, pk);
  6181. UNMARK_SECRET_DATA(pk, sizeof(pk));
  6182. ck_assert_mem_eq(pk, fromhex(*spk), 32);
  6183. ed25519_sign(pk, 32, sk, sig);
  6184. UNMARK_SECRET_DATA(sig, sizeof(sig));
  6185. ck_assert_mem_eq(sig, fromhex(*ssig), 64);
  6186. ssk += 3;
  6187. spk += 3;
  6188. ssig += 3;
  6189. UNMARK_SECRET_DATA(sk, sizeof(sk));
  6190. }
  6191. }
  6192. END_TEST
  6193. // test vectors from
  6194. // https://raw.githubusercontent.com/NemProject/nem-test-vectors/master/2.test-sign.dat
  6195. START_TEST(test_ed25519_keccak) {
  6196. static const struct {
  6197. const char *private_key;
  6198. const char *public_key;
  6199. const char *signature;
  6200. size_t length;
  6201. const char *data;
  6202. } tests[] = {
  6203. {
  6204. "abf4cf55a2b3f742d7543d9cc17f50447b969e6e06f5ea9195d428ab12b7318d",
  6205. "8a558c728c21c126181e5e654b404a45b4f0137ce88177435a69978cc6bec1f4",
  6206. "d9cec0cc0e3465fab229f8e1d6db68ab9cc99a18cb0435f70deb6100948576cd5c0a"
  6207. "a1feb550bdd8693ef81eb10a556a622db1f9301986827b96716a7134230c",
  6208. 41,
  6209. "8ce03cd60514233b86789729102ea09e867fc6d964dea8c2018ef7d0a2e0e24bf7e3"
  6210. "48e917116690b9",
  6211. },
  6212. {
  6213. "6aa6dad25d3acb3385d5643293133936cdddd7f7e11818771db1ff2f9d3f9215",
  6214. "bbc8cbb43dda3ecf70a555981a351a064493f09658fffe884c6fab2a69c845c6",
  6215. "98bca58b075d1748f1c3a7ae18f9341bc18e90d1beb8499e8a654c65d8a0b4fbd2e0"
  6216. "84661088d1e5069187a2811996ae31f59463668ef0f8cb0ac46a726e7902",
  6217. 49,
  6218. "e4a92208a6fc52282b620699191ee6fb9cf04daf48b48fd542c5e43daa9897763a19"
  6219. "9aaa4b6f10546109f47ac3564fade0",
  6220. },
  6221. {
  6222. "8e32bc030a4c53de782ec75ba7d5e25e64a2a072a56e5170b77a4924ef3c32a9",
  6223. "72d0e65f1ede79c4af0ba7ec14204e10f0f7ea09f2bc43259cd60ea8c3a087e2",
  6224. "ef257d6e73706bb04878875c58aa385385bf439f7040ea8297f7798a0ea30c1c5eff"
  6225. "5ddc05443f801849c68e98111ae65d088e726d1d9b7eeca2eb93b677860c",
  6226. 40,
  6227. "13ed795344c4448a3b256f23665336645a853c5c44dbff6db1b9224b5303b6447fbf"
  6228. "8240a2249c55",
  6229. },
  6230. {
  6231. "c83ce30fcb5b81a51ba58ff827ccbc0142d61c13e2ed39e78e876605da16d8d7",
  6232. "3ec8923f9ea5ea14f8aaa7e7c2784653ed8c7de44e352ef9fc1dee81fc3fa1a3",
  6233. "0c684e71b35fed4d92b222fc60561db34e0d8afe44bdd958aaf4ee965911bef59912"
  6234. "36f3e1bced59fc44030693bcac37f34d29e5ae946669dc326e706e81b804",
  6235. 49,
  6236. "a2704638434e9f7340f22d08019c4c8e3dbee0df8dd4454a1d70844de11694f4c8ca"
  6237. "67fdcb08fed0cec9abb2112b5e5f89",
  6238. },
  6239. {
  6240. "2da2a0aae0f37235957b51d15843edde348a559692d8fa87b94848459899fc27",
  6241. "d73d0b14a9754eec825fcb25ef1cfa9ae3b1370074eda53fc64c22334a26c254",
  6242. "6f17f7b21ef9d6907a7ab104559f77d5a2532b557d95edffd6d88c073d87ac00fc83"
  6243. "8fc0d05282a0280368092a4bd67e95c20f3e14580be28d8b351968c65e03",
  6244. 40,
  6245. "d2488e854dbcdfdb2c9d16c8c0b2fdbc0abb6bac991bfe2b14d359a6bc99d66c00fd"
  6246. "60d731ae06d0",
  6247. },
  6248. {
  6249. "0c066261fb1b18ebf2a9bcdeda81eb47d5a3745438b3d0b9d19b75885ad0a154",
  6250. "2e5773f0e725024bc0359ce93a44e15d6507e7b160b6c592200385fee4a269cf",
  6251. "13b5d2dd1b04f62cc2ec1544fed256423684f2dbca4538ceddda1d15c59dc7196c87"
  6252. "840ea303ea30f4f6914a6ec9167841980c1d717f47fd641225068de88507",
  6253. 41,
  6254. "f15cb706e29fcfbcb324e38cbac62bb355deddb845c142e970f0c029ea4d05e59fd6"
  6255. "adf85573cf1775",
  6256. },
  6257. {
  6258. "ef3d8e22a592f04c3a31aa736e10901757a821d053f1a49a525b4ec91eacdee3",
  6259. "72a2b4910a502b30e13a96aba643c59c79328c1ba1462be6f254e817ef157fee",
  6260. "95f2437a0210d2d2f125a3c377ed666c0d596cd104185e70204924a182a11a6eb3bd"
  6261. "ba4395bbfc3f4e827d38805752657ee52d1ce0f17e70f59bfd4999282509",
  6262. 50,
  6263. "6c3e4387345740b8d62cf0c9dec48f98c292539431b2b54020d8072d9cb55f0197f7"
  6264. "d99ff066afcf9e41ea8b7aea78eb082d",
  6265. },
  6266. {
  6267. "f7fb79743e9ba957d2a4f1bd95ceb1299552abecaf758bf840d2dc2c09f3e3cb",
  6268. "8b7d7531280f76a8abac8293d87508e3953894087112ae01b6ad32485d4e9b67",
  6269. "c868ecf31cee783fe8799ac7e6a662431c822967351d8b79687f4ddf608f79a080c4"
  6270. "ff9eed4fdee8c99fe1be905f734cae2a172f1cfdb00771625c0695a5260e",
  6271. 42,
  6272. "55d8e60c307ee533b1af9ff677a2de40a6eace722bcc9eb5d79907b420e533bc06db"
  6273. "674dafbd9f43d672",
  6274. },
  6275. {
  6276. "8cc9a2469a77fad18b44b871b2b6932cd354641d2d1e84403f746c4fff829791",
  6277. "aed5da202d4983dac560faf6704dc76ac111616318570e244043e82ed1bbcd2b",
  6278. "aee9616db4135150818eaffa3e4503c2d7e9e834847a4c7d0a8856e952761d361a65"
  6279. "7104d36950c9b75770ded00d56a96e06f383fa2406bc935dcf51f272300e",
  6280. 42,
  6281. "d9b8be2f71b83261304e333d6e35563dc3c36c2eb5a23e1461b6e95aa7c6f381f9c3"
  6282. "bd39deaa1b6df2f9",
  6283. },
  6284. {
  6285. "a247abbef0c1affbf021d1aff128888550532fc0edd77bc39f6ef5312317ec47",
  6286. "98ededbad1e5ad7a0d5a0cf4fcd7a794eb5c6900a65e7e921884a636f19b131d",
  6287. "f8cc02933851432f0c5df0b70f2067f740ccb72de7d6fa1e9a9b0d6de1402b9c6c52"
  6288. "5fd848e45aaaac1423b52880ec3474a2f64b38db6fc8e008d95a310e6e0c",
  6289. 47,
  6290. "4a5f07eb713932532fc3132c96efdc45862fe7a954c1d2ae4640afdf4728fb58c65e"
  6291. "8a4ebfe0d53d5797d5146442b9",
  6292. },
  6293. {
  6294. "163d69079ddad1f16695c47d81c3b72f869b2fdd50e6e47113db6c85051a6ede",
  6295. "93fe602642ee5773f4aaf6a3bc21e98e354035225353f419e78e43c3ec36c88a",
  6296. "da747fa2cb47aae1effc1e4cfde0e39fa79937948592a712a7665bf948b8311e7f3f"
  6297. "80f966301679520d5c2afa3eadd60e061f0d264887500d8d03a17e10fd02",
  6298. 41,
  6299. "65fe5c1a0214a59644892e5ac4216f09fbb4e191b89bfb63d6540177d25ef9e37148"
  6300. "50b8453bd6b2b6",
  6301. },
  6302. {
  6303. "7b061bf90eb760971b9ec66a96fd6609635ca4b531f33e3c126b9ae6fdb3d491",
  6304. "cb392ebb6912df4111efeeb1278160daf9da396e9291b83979a5ac479f7276d2",
  6305. "f6eebe86f7ea672e0707ee518e1798d6fbd118c11b2aa30be07d10e3882e3721f203"
  6306. "0f9f044b77c3a7a9a2f1feba7e7ce75d1f7f3807a96a764fded35d341d02",
  6307. 45,
  6308. "a17f5ce39b9ba7b7cf1147e515d6aa84b22fd0e2d8323a91367198fc6c3aff04ebb2"
  6309. "1fc2bdbe7bc0364e8040a9",
  6310. },
  6311. {
  6312. "c9f8ccbf761cec00ab236c52651e76b5f46d90f8936d44d40561ed5c277104de",
  6313. "a3192641e343b669ffd43677c2e5cd4efaed174e876141f1d773bd6cfe30d875",
  6314. "d44f884ec9eae2e99e74194b5acc769b7aa369aaad359e92ba6ff0fe629af2a9a715"
  6315. "6c19b720e7de8c7f03c039563f160948073cab6f99b26a56a8bb1023ba08",
  6316. 47,
  6317. "3d7e33b0ecead8269966e9dcd192b73eb8a12573fc8a5fdfbe5753541026ef2e49f5"
  6318. "280cba9bc2515a049b3a1c1b49",
  6319. },
  6320. {
  6321. "ebfa409ac6f987df476858dd35310879bf564eeb62984a52115d2e6c24590124",
  6322. "7bb1601fe7215f3f4da9c8ab5e804dc58f57ba41b03223f57ec80d9c9a2dd0e1",
  6323. "f3e7c1abfcc9f35556cb1e4c5a2b34445177ac188312d9148f1d1d8467ea8411fa3c"
  6324. "da031d023034e45bbe407ef7d1b937bfb098266138857d35cb4efe407306",
  6325. 52,
  6326. "0c37564f718eda683aa6f3e9ab2487620b1a8b5c8f20adb3b2d7550af0d635371e53"
  6327. "1f27cebe76a2abcc96de0875bdae987a45ac",
  6328. },
  6329. {
  6330. "f993f61902b7da332f2bb001baa7accaf764d824eb0cd073315f7ec43158b8fb",
  6331. "55fc8e0da1b454cab6ddefb235311db2b01504bf9ac3f71c7e3f3d0d1f09f80b",
  6332. "178bd147673c0ca330e45da63cbd1f1811906bd5284bb44e4bb00f7d7163d1f39697"
  6333. "5610b6f71c1ae4686466fad4c5e7bb9685099e21ca4f1a45bb3fcf56ae0c",
  6334. 42,
  6335. "b7dd613bc9c364d9eeb9a52636d72bc881dfc81a836b6537bbb928bff5b738313589"
  6336. "47ea9edea1570550",
  6337. },
  6338. {
  6339. "05188c09c31b4bb63f0d49b47ccc1654c2aba907b8c6c0a82ee403e950169167",
  6340. "e096d808dfabe8e44eb74950199dadcd586f9de6b141a0ce85ab94b3d97866eb",
  6341. "669491c8eb7cedbbc0252f3eafb048b39a2a37f60ac87837777c72c879ac8b726c39"
  6342. "e10060750c2f539102999b71889746111bc5f71ec8c158cc81cf566aef03",
  6343. 44,
  6344. "bb8e22469d1c7f1d5418563e8781f69eccb56678bd36d8919f358c2778562ff6b50d"
  6345. "e916c12d44f1a778a7f3",
  6346. },
  6347. {
  6348. "eabe57e1a916ebbffa4ba7abc7f23e83d4deb1338816cc1784d7495d92e98d0b",
  6349. "3aad275642f48a46ed1032f3de9f4053e0fd35cf217e065d2e4579c3683932f7",
  6350. "b2e9dac2c83942ca374f29c8eff5a30c377c3db3c1c645e593e524d17484e7705b11"
  6351. "f79573e2d63495fc3ce3bf216a209f0cb7bea477ae0f8bd297f193af8805",
  6352. 44,
  6353. "3f2c2d6682ee597f2a92d7e560ac53d5623550311a4939d68adfb904045ed8d215a9"
  6354. "fdb757a2368ea4d89f5f",
  6355. },
  6356. {
  6357. "fef7b893b4b517fab68ca12d36b603bc00826bf3c9b31a05149642ae10bb3f55",
  6358. "b3fb891868708dfa5da5b9b5234058767ab42c117f12c3228c02a1976d1c0f83",
  6359. "6243e289314b7c7587802909a9be6173a916b36f9de1e164954dfe5d1ebd57c869a7"
  6360. "9552d770e13b51855502be6b15e7be42a3675298a81284df58e609b06503",
  6361. 47,
  6362. "38c69f884045cdbeebe4478fdbd1ccc6cf00a08d8a3120c74e7167d3a2e26a67a043"
  6363. "b8e5bd198f7b0ce0358cef7cf9",
  6364. },
  6365. {
  6366. "16228bec9b724300a37e88e535fc1c58548d34d7148b57c226f2b3af974c1822",
  6367. "3c92423a8360c9a5d9a093730d72831bec4601dcadfe84de19fc8c8f91fc3d4b",
  6368. "6aebfa9a4294ec888d54bcb517fcb6821e4c16d2708a2afe701f431a28149ff4f139"
  6369. "f9d16a52a63f1f91baf4c8dea37710c73f25c263a8035a39cc118ad0280f",
  6370. 44,
  6371. "a3d7b122cd4431b396b20d8cc46cc73ed4a5253a44a76fc83db62cdc845a2bf7081d"
  6372. "069a857955a161cccf84",
  6373. },
  6374. {
  6375. "2dc3f5f0a0bc32c6632534e1e8f27e59cbe0bf7617d31aff98098e974c828be7",
  6376. "b998a416edc28ded988dcacb1caf2bd96c87354b0d1eeccb6980e54a3104f21f",
  6377. "76a2ddfc4bea48c47e0c82bcbfee28a37c61ec626af39a468e643e0ef9f6533056a5"
  6378. "a0b44e64d614ba3c641a40e5b003a99463445ae2c3c8e1e9882092d74b07",
  6379. 42,
  6380. "bdae276d738b9758ea3d322b54fd12fe82b767e8d817d8ef3d41f78705748e28d15e"
  6381. "9c506962a1b85901",
  6382. },
  6383. };
  6384. ed25519_secret_key private_key;
  6385. ed25519_public_key public_key;
  6386. ed25519_signature signature;
  6387. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  6388. nem_private_key(tests[i].private_key, private_key);
  6389. MARK_SECRET_DATA(private_key, sizeof(private_key));
  6390. ed25519_publickey_keccak(private_key, public_key);
  6391. UNMARK_SECRET_DATA(public_key, sizeof(public_key));
  6392. ck_assert_mem_eq(public_key, fromhex(tests[i].public_key), 32);
  6393. ed25519_sign_keccak(fromhex(tests[i].data), tests[i].length, private_key,
  6394. signature);
  6395. UNMARK_SECRET_DATA(signature, sizeof(signature));
  6396. ck_assert_mem_eq(signature, fromhex(tests[i].signature), 64);
  6397. UNMARK_SECRET_DATA(private_key, sizeof(private_key));
  6398. }
  6399. }
  6400. END_TEST
  6401. START_TEST(test_ed25519_cosi) {
  6402. const int MAXN = 10;
  6403. ed25519_secret_key keys[MAXN];
  6404. ed25519_public_key pubkeys[MAXN];
  6405. ed25519_secret_key nonces[MAXN];
  6406. ed25519_public_key Rs[MAXN];
  6407. ed25519_cosi_signature sigs[MAXN];
  6408. uint8_t msg[32];
  6409. rfc6979_state rng;
  6410. int res;
  6411. init_rfc6979(
  6412. fromhex(
  6413. "26c76712d89d906e6672dafa614c42e5cb1caac8c6568e4d2493087db51f0d36"),
  6414. fromhex(
  6415. "26659c1cf7321c178c07437150639ff0c5b7679c7ea195253ed9abda2e081a37"),
  6416. NULL, &rng);
  6417. for (int N = 1; N < 11; N++) {
  6418. ed25519_public_key pk;
  6419. ed25519_public_key R;
  6420. ed25519_signature sig;
  6421. /* phase 0: create priv/pubkeys and combine pubkeys */
  6422. for (int j = 0; j < N; j++) {
  6423. generate_rfc6979(keys[j], &rng);
  6424. ed25519_publickey(keys[j], pubkeys[j]);
  6425. }
  6426. res = ed25519_cosi_combine_publickeys(pk, pubkeys, N);
  6427. ck_assert_int_eq(res, 0);
  6428. generate_rfc6979(msg, &rng);
  6429. /* phase 1: create nonces, commitments (R values) and combine commitments */
  6430. for (int j = 0; j < N; j++) {
  6431. ed25519_cosi_commit(nonces[j], Rs[j]);
  6432. }
  6433. res = ed25519_cosi_combine_publickeys(R, Rs, N);
  6434. ck_assert_int_eq(res, 0);
  6435. MARK_SECRET_DATA(keys, sizeof(keys));
  6436. /* phase 2: sign and combine signatures */
  6437. for (int j = 0; j < N; j++) {
  6438. res = ed25519_cosi_sign(msg, sizeof(msg), keys[j], nonces[j], R, pk,
  6439. sigs[j]);
  6440. ck_assert_int_eq(res, 0);
  6441. }
  6442. UNMARK_SECRET_DATA(sigs, sizeof(sigs));
  6443. ed25519_cosi_combine_signatures(sig, R, sigs, N);
  6444. /* check signature */
  6445. res = ed25519_sign_open(msg, sizeof(msg), pk, sig);
  6446. ck_assert_int_eq(res, 0);
  6447. UNMARK_SECRET_DATA(keys, sizeof(keys));
  6448. }
  6449. }
  6450. END_TEST
  6451. START_TEST(test_ed25519_modl_add) {
  6452. char tests[][3][65] = {
  6453. {
  6454. "0000000000000000000000000000000000000000000000000000000000000000",
  6455. "0000000000000000000000000000000000000000000000000000000000000000",
  6456. "0000000000000000000000000000000000000000000000000000000000000000",
  6457. },
  6458. {"eef80ad5a9aad8b35b84f6a4eb3a7e2b222f403d455d8cdf40ad27e4cd5ae90a",
  6459. "0000000000000000000000000000000000000000000000000000000000000000",
  6460. "eef80ad5a9aad8b35b84f6a4eb3a7e2b222f403d455d8cdf40ad27e4cd5ae90a"},
  6461. {"0000000000000000000000000000000000000000000000000000000000000000",
  6462. "eef80ad5a9aad8b35b84f6a4eb3a7e2b222f403d455d8cdf40ad27e4cd5ae90a",
  6463. "eef80ad5a9aad8b35b84f6a4eb3a7e2b222f403d455d8cdf40ad27e4cd5ae90a"},
  6464. {"0100000000000000000000000000000000000000000000000000000000000000",
  6465. "0200000000000000000000000000000000000000000000000000000000000000",
  6466. "0300000000000000000000000000000000000000000000000000000000000000"},
  6467. {"e3d3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010",
  6468. "0a00000000000000000000000000000000000000000000000000000000000000",
  6469. "0000000000000000000000000000000000000000000000000000000000000000"},
  6470. {"f7bb3bf42b3e58e2edd06f173fc7bfbc7aaf657217946b75648447101136aa08",
  6471. "3c16b013109cc27ff39805be2abe04ba4cd6a8526a1d3023047693e950936c06",
  6472. "33d2eb073cda1a62e16975d56985c476c7850ec581b19b9868fadaf961c9160f"},
  6473. };
  6474. unsigned char buff[32];
  6475. bignum256modm a = {0}, b = {0}, c = {0};
  6476. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  6477. expand256_modm(a, fromhex(tests[i][0]), 32);
  6478. expand256_modm(b, fromhex(tests[i][1]), 32);
  6479. add256_modm(c, a, b);
  6480. contract256_modm(buff, c);
  6481. ck_assert_mem_eq(buff, fromhex(tests[i][2]), 32);
  6482. }
  6483. }
  6484. END_TEST
  6485. START_TEST(test_ed25519_modl_neg) {
  6486. char tests[][2][65] = {
  6487. {"05d0f55c1a631258d69cf7a2def9de1400000000000000000000000000000010",
  6488. "e803000000000000000000000000000000000000000000000000000000000000"},
  6489. {"4d4df45c1a631258d69cf7a2def9de1400000000000000000000000000000010",
  6490. "a086010000000000000000000000000000000000000000000000000000000000"},
  6491. {"25958944a1b7d4073975ca48996a1d740d0ed98ceec366760c5358da681e9608",
  6492. "c83e6c1879ab3d509d272d5a458fc1a0f2f12673113c9989f3aca72597e16907"},
  6493. {"0100000000000000000000000000000000000000000000000000000000000000",
  6494. "ecd3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010"},
  6495. {"ecd3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010",
  6496. "0100000000000000000000000000000000000000000000000000000000000000"},
  6497. {"0000000000000000000000000000000000000000000000000000000000000000",
  6498. "0000000000000000000000000000000000000000000000000000000000000000"},
  6499. };
  6500. unsigned char buff[32];
  6501. bignum256modm a = {0}, b = {0};
  6502. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  6503. expand256_modm(a, fromhex(tests[i][0]), 32);
  6504. neg256_modm(b, a);
  6505. contract256_modm((unsigned char *)buff, b);
  6506. ck_assert_mem_eq(buff, fromhex(tests[i][1]), 32);
  6507. }
  6508. }
  6509. END_TEST
  6510. START_TEST(test_ed25519_modl_sub) {
  6511. char tests[][3][65] = {
  6512. {
  6513. "0000000000000000000000000000000000000000000000000000000000000000",
  6514. "0000000000000000000000000000000000000000000000000000000000000000",
  6515. "0000000000000000000000000000000000000000000000000000000000000000",
  6516. },
  6517. {"eef80ad5a9aad8b35b84f6a4eb3a7e2b222f403d455d8cdf40ad27e4cd5ae90a",
  6518. "53732f60e51ee3a48d21d2d526548c0dadbb79a185678fd7710613d0e76aad0c",
  6519. "8859d1d1deee0767a4ff1b72a3e0d0327573c69bbff5fc07cfa61414e6ef3b0e"},
  6520. {"9d91e26dbe7a14fdca9f5b20d13e828dc8c1ffe03fe90136a6bba507436ce500",
  6521. "9ca406705ccce65eb8cbf63706d3df09fcc67216c0dc3990270731aacbb2e607",
  6522. "eec0d15a7c1140f6e8705c8ba9658198ccfa8cca7f0cc8a57eb4745d77b9fe08"},
  6523. {"eef80ad5a9aad8b35b84f6a4eb3a7e2b222f403d455d8cdf40ad27e4cd5ae90a",
  6524. "0000000000000000000000000000000000000000000000000000000000000000",
  6525. "eef80ad5a9aad8b35b84f6a4eb3a7e2b222f403d455d8cdf40ad27e4cd5ae90a"},
  6526. {"0000000000000000000000000000000000000000000000000000000000000000",
  6527. "39897fbebf137a34572b014b0638ac0186d17874e3cc142ebdfe24327f5b8509",
  6528. "b44a769e5a4f98237f71f657d8c132137a2e878b1c33ebd14201dbcd80a47a06"},
  6529. {"0200000000000000000000000000000000000000000000000000000000000000",
  6530. "e3d3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010",
  6531. "0c00000000000000000000000000000000000000000000000000000000000000"},
  6532. {"e3d3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010",
  6533. "0800000000000000000000000000000000000000000000000000000000000000",
  6534. "dbd3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010"},
  6535. {"ecd3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010",
  6536. "0000000000000000000000000000000000000000000000000000000000000000",
  6537. "ecd3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010"},
  6538. {"0000000000000000000000000000000000000000000000000000000000000000",
  6539. "ecd3f55c1a631258d69cf7a2def9de1400000000000000000000000000000010",
  6540. "0100000000000000000000000000000000000000000000000000000000000000"},
  6541. {"0000000000000000000000000000000000000000000000000000000000000000",
  6542. "0000000000000000000000000000000000000000000000000000000000000010",
  6543. "edd3f55c1a631258d69cf7a2def9de1400000000000000000000000000000000"},
  6544. {"0000000000000000000000000000000000000000000000000000000000000000",
  6545. "ffffff3f00000000000000000000000000000000000000000000000000000010",
  6546. "eed3f51c1a631258d69cf7a2def9de1400000000000000000000000000000000"},
  6547. {"0000000000000000000000000000000000000000000000000000000000000000",
  6548. "edd3f55c1a631258d69cf7a2def9de1400000000000000000000000000000000",
  6549. "0000000000000000000000000000000000000000000000000000000000000010"},
  6550. {"0000000000000000000000000000000000000000000000000000000000000000",
  6551. "e75f947f11d49d25a137fac8757538a980dec23811235cf63c48ee6bc6e4ed03",
  6552. "067461dd088f74323565fdd96884a66b7f213dc7eedca309c3b71194391b120c"},
  6553. {"0000000000000000000000000000000000000000000000000000000000000000",
  6554. "ecd3f55c1a631258d69cf7a2def9de140000000000000000000000000000ff0f",
  6555. "0100000000000000000000000000000000000000000000000000000000000100"},
  6556. {"0000000000000000000000000000000000000000000000000000000000000000",
  6557. "edd3f55c1a631258d69cf7a2def9de140000000000000000000004000000ff0f",
  6558. "0000000000000000000000000000000000000000000000000000fcffffff0000"},
  6559. {"0000000000000000000000000000000000000000000000000000000000000000",
  6560. "edd3f55c1a631258d69cf7a2def9de150000c0ffffffffffffffffffffffff0f",
  6561. "000000000000000000000000000000ffffff3f00000000000000000000000000"},
  6562. {"0000000000000000000000000000000000000000000000000000000000000000",
  6563. "edd3f55c1a631258d69cf7a2def9de1200000000000000000000000000000110",
  6564. "edd3f55c1a631258d69cf7a2def9de160000000000000000000000000000ff0f"},
  6565. {"0000000000000000000000000000000000000000000000000000000000000000",
  6566. "edd3f55c1a631258d69cf7a2def9de1300000000000000000000000000000010",
  6567. "0000000000000000000000000000000100000000000000000000000000000000"},
  6568. };
  6569. unsigned char buff[32];
  6570. bignum256modm a = {0}, b = {0}, c = {0};
  6571. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  6572. expand256_modm(a, fromhex(tests[i][0]), 32);
  6573. expand256_modm(b, fromhex(tests[i][1]), 32);
  6574. sub256_modm(c, a, b);
  6575. contract256_modm(buff, c);
  6576. ck_assert_mem_eq(buff, fromhex(tests[i][2]), 32);
  6577. }
  6578. }
  6579. END_TEST
  6580. START_TEST(test_ge25519_double_scalarmult_vartime2) {
  6581. char tests[][5][65] = {
  6582. {"c537208ed4985e66e9f7a35c9a69448a732ba93960bbbd2823604f7ae9e3ed08",
  6583. "365233e5af17c8888d5ce508787464f4642e91a6212b1b104e6c3769535601b1",
  6584. "a84f871580176708b4ac21843cb197ad96e8456034442b50859c83c5807b9901",
  6585. "f022360d1bce903fa3ac58ae42f997328b31f477b8d576a9f6d26fc1d08f14ea",
  6586. "bf25da82c6b210948b823ae48422a2dcd205d3c94842e68ac27e5cbeaa704ebc"},
  6587. {"4abfabc0dda33588a98127ef3bfe724fed286395fe15932e898b5621661ea102",
  6588. "e5fd79d03f5df8edfc8def663dcb96bba6cadf857f2ae6f6f51f52f8d14079b7",
  6589. "4754c286b23e3c1b50054fe3937ebdc4ec01b28da5d05fb6111798b42fc5bf06",
  6590. "b7e7f9464b98de5bfcf6b02c1b7053cc359df407ad59d943523c6d2ee773b2f6",
  6591. "6d7d5f729bfa4882dbff8e477cd2b4c354ba347f10e7b178a24f3f16a4e0fec6"},
  6592. {"19f2af4d04cb8181f1fe0d01fe9bb9ecc476c67ceb4a9830dae1bc7fe5fe3b04",
  6593. "d3c462f4f30991220387a1fbbd1ba1dc45ce058c70a8fb1475071e7b4f0fc463",
  6594. "577790e025c1fd2014db44a8d613c4e2ab1f248a4a6d14b5d39cbbafd7b20f06",
  6595. "1376c6837f131f6cd1a45b1056297d2314aa0ac5f7d581d2d878261eb3259b4d",
  6596. "ce790760ada87dd819b59e4f6765d836d346567ec34f02bbcfcae0585c1d758f"},
  6597. {"cf209db9e7ee85f1e648924ec97edd86b56a833b25707519d4fbe64fd50e150a",
  6598. "804f0806087dc665a26230ed5fd44c062980ee182a6bd7dbdb33df018c983778",
  6599. "30d3c448cb08935309753b3051366f52328ca1d9a0b63c72b989edee0da32b0e",
  6600. "98e3c973a7e85b5eab8111521c66ca584bed5597f060ab0c6b5cdeece502ac48",
  6601. "2646276e1305396a1b2473690066011a39789570a09e10ce1a013c8f32cd5bea"},
  6602. {"b0a0ffeea67b656c4c585ba58ff528a6f45d2f915db98e4a14a8ff17f27fc105",
  6603. "4fabe16274f6af526ee053028485db6acd13804e02dcdddccc4183a319ab9e1c",
  6604. "1e140bb08a936ac6b7437644ca0769f3c165c7aa5501d49f064a0346179b4008",
  6605. "68fc1be64fb68761542a655b8dbebf50980f1fbc1845528df8d8a06bf89a1495",
  6606. "7dab86994b47014efe38493fc2b62ffcead806da6e0d73c992db8cb5618a19dc"},
  6607. {"0fee422c2294b06ca83bc3704384dffc580e7ff5921881e51a755e5f9b80af03",
  6608. "4359a663ead3f7ffc3a0ead5c3c2bde348017e7bfa620f21759c32e469a16dfe",
  6609. "532066e3eec29334fffc37b17178dfbac3bee15f7845f01449ddbaf5e57a7b0c",
  6610. "32e46c2fb99402837631c8175db31cdd334c145f922be9070d62e6d9c493c3ea",
  6611. "8c7b7d2d61cdb648960434d894787426a76d16dd46949c7aa4b85dcf1054b4d5"},
  6612. {"3a712d5b7ceb5257dcf6e6bb06548de6ef3deba5d456cd91fc305a12b46b5d01",
  6613. "5e7da62e3ec42cf3e554639dd4d2006754ee6839b720cadba94a26b73b1665ee",
  6614. "2a518ecab17a2d9dde219c775bcf4f2306b190bef2dea34fb65b8e4dccc13405",
  6615. "3b5d66a4dfb068923b3bc21cc8b40b59e12f845e0b85a86d394db0fa310bf185",
  6616. "2ec17f1cc0be093e9cdb741a991c0f417230dea275cd7babdad35e949e250521"},
  6617. {"5f815f2d65cef584c5e5d48b2d3d3e4cae310d70b328f88af6e9f63c52b4c90d",
  6618. "8a539a8c6b2339922b31cf4bc064f1fedeb3912fd89585d79dfcff2a60aee295",
  6619. "385f7132b72db04146b9e472736b32adfca29556b4775a743c18e2bfab939007",
  6620. "884aaf96d625968ddb2582922a87abca131272884c47f6b86890ebccf0a79d5b",
  6621. "a7afdaf24fe8472d8b89e95c3ce4a40bdf700af7cedee44ed3aa5ccca09839bd"},
  6622. {"a043340d072df16a8ab5135f8c1d601bff14c5aba01b9212b886ad71fe164506",
  6623. "52f6de5fa0fae32d4020a54d395319509d6b92092a0bf849fb34e73f8e71fc99",
  6624. "37d7472d360164da29e6dcb8f9796976022571c5df4ddf7e30e9a579ba13d509",
  6625. "8c369e3fd5b1112e4437b1f09e987acca4966f2f8c5227eb15ace240a2c64cc7",
  6626. "fc795fe7baff5c3ac98366e6882f25874ea2b0a649d16f139e5c54ea47042a1e"},
  6627. {"97a3268db03fa184c8cba020bf216fc789292fa9615a28962385b86870ffd70f",
  6628. "a76c215587022bb9252ece4c5afeb0e65b820834cd41ac76e6c062d3eea75dc6",
  6629. "8310271017154cbddf7005e24eb9a9a86777b3f42fa5e35095eafaac4eb24802",
  6630. "b822665c2406083c851ecaa91ea67aa740c057e7679b5755cee60a6c63f17fd6",
  6631. "f83e2444527056eba595d49bde40b2e8da76d2c145f203331d26e94560993fbc"},
  6632. {"edaad13efad39f26298e86ba8d06a46e59122232c9529bd22f2f656595421e00",
  6633. "f38e56a79f5159eb3b581dea537ec12c9c6fac381b2cf6073e27fc621197cb62",
  6634. "1eea79485954b5958d9d5478f86133af1088806d923535d483b115ab23099a0f",
  6635. "b32c5e57d57db7a349f4ab845f12a5045c52b4a7a5bce7fd54a1a255b0118185",
  6636. "3bfb42b4ffd2c6cfc8cce9e4187dc6fbcaecd9d44a4ca1d2b68b97410bb25b81"},
  6637. {"b15eaebe0fc83cb11d755a6f067b710204d4a59101078d8286454b652879080a",
  6638. "4667a2e61d9df1690f5c33c4168e480f7e26d2f0998168ebdc0a39712946f741",
  6639. "125379da1a88bfdf5b928f8795d3ea5415ef8c3d9106eb16934c3842873fd707",
  6640. "8727a692a25e38b1afa98e3dd5bf88815dec6d9810c1fd8a31b56b3de8630f1e",
  6641. "540883dde400b909e9955a276c20e13d99252ebe542750b8bfbbe5c3b87c51e3"},
  6642. {"e42bdd4af3121bea644a90a76b2007615621ee5b842b9a74c4334ac309478706",
  6643. "6dc4ab715d3bb975ebfd0f08e2b6f3f39922d0121ae518a8f8d2952ea2fe0b5d",
  6644. "0285059b0095c97f4a50d43c7726c64c2830bf2b55dfa934ebba7ad71064dc07",
  6645. "f738c0a3cee31fd8f438f282aa6c823fccfa49cf7b5c86fbf9d56bf0394b6d8d",
  6646. "a1bd106841e55010decd95a170a1d0dd11780fd00759819e024b15ea3a83b4be"},
  6647. {"5077c30fd08795dbdc7a230c050ca07e316fa3b040fd0dac45907036ab25dd0e",
  6648. "96f0897f000e49e2439a9166cab40ebc125a31b82851f0541516c19683e7bfaf",
  6649. "2b67d79a2efdc6451508e7f3c97c4a61b135bb839c02338bb444ef8208dd970b",
  6650. "7ef4cd7cdc29c2b88ccff49898b5d0b7be5993f93c5772476feec9dc57d7b6e3",
  6651. "62449b901b25760c964704b28efc184fbd5947e83851ebaf3bbfeb6f742f679f"},
  6652. {"a4b3ce6928fe8f77d13e65ae255eee8310ab0d75bca47028b4570f0511a66006",
  6653. "4e9da8d77ee337e3bcce3730ccfff2121728641c7bb4fdeb2155890f998af09a",
  6654. "ff01a5075569d0f6afee45da065c72f5841f46ce772917ef75eb4d230473580f",
  6655. "36ca32da8a10f4083f5a60ee21868d9d448548d49c56f19cbe6005005e34f816",
  6656. "99df362a3b762cc1cbb70bc5ddff3c8614ed306037013102e387ef32e7f2494f"},
  6657. {"074aa76351dceb752aa09887d9aca932d5821f58eedb4988fd64d8548e3f2c09",
  6658. "588b4552f3b98b2f77aee2ef8cc72f88acd424c4373b3e3626393ed2ea24cbda",
  6659. "f2d9175633f2e3c661b01172b4b4176850cd5b3098ffb0f927e0a5e19c1c8a02",
  6660. "a6c34868736b2517fd46f57a4e30805ffd475e44a8b1413078f43d9cb3d6edd6",
  6661. "46e1e7d7b1e939dd5c07c8363af01f4f9dae7c3d10f237ff9776ddc4a1903771"},
  6662. {"ae1c8abd5a542208ee0aa93ffbf0b8e5a957edc4854fe2b48153c5c85bbf3d08",
  6663. "5e084b9541a70bd5bef400be6525c5a806a5b7fb12de38b07dcd35a22c57edbe",
  6664. "d95f179a215fb322d81720bf3aecde78d6d676d6f941455d0e0920f1e3619707",
  6665. "c3e5d43221824de51d8f95705de69c80a2440c0483ca88549d639aee15390429",
  6666. "df9fea42d3b5ac243244abb4ca4948a69493becddc5d5906f9a4e4c5645b0eab"},
  6667. {"2f1c5adedb7341dc7638bafacc6024bd48255197ea2347fc05714b9341dd4403",
  6668. "47f55263001542f796c928988f641f59d0cd43294fc8d8616b184bfe9dddf368",
  6669. "aa5e884e782ab116151c609680c37b1a49b52f23bce5e2ebf28dd8532510d20b",
  6670. "ef2d6d97ad1a18edfce6450c1e70295b2c7ed2bc749ea8b438a523eae078d1f3",
  6671. "2396a355c6ae8e2ac24da8f55a674c96fc4cc69b38678b2bd8eb91b96f462bca"},
  6672. {"0242e14105ced74e91cf4d4dcd22a9c09279018901d2fb8319eb54c2a1c4900a",
  6673. "fcb62a6c520d31fa46efeb4a1000330653b3402f575c2ddc0c688f527e7b97be",
  6674. "73a7e2e0602e5345f040dedc4db67f6d8e37c5fca3bbb124fa43963d76dbbb08",
  6675. "152bf4a3305c656f77e292b1256cc470da4d3f6efc3667199db4316d7f431174",
  6676. "c21ba2080013dfb225e06378d9ac27df623df552526cfddbf9e71bb1d4705dd9"},
  6677. {"07fab4fc7b02fbcf868ffb0326cf60425fef2af1fbad83a8926cc62c2b5dff05",
  6678. "29ff12c5e052eb5829e8334e0e082c5edde1f293d2b4ed499a79bcca20e48010",
  6679. "97afb3dd9167877b432a23503aad1ab39188b9be07cc124ceb3fbdbd8d8b890a",
  6680. "ed121240a2f4591eeedbfd880305ccd17e522673900b03279fb66e73583514ae",
  6681. "b27f209e88ce5701766565e231e8123adb1df9c9f1dc461920acbc2b38d9f6d7"},
  6682. };
  6683. unsigned char buff[32];
  6684. bignum256modm a = {0}, b = {0};
  6685. ge25519 A, B, R;
  6686. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  6687. expand256_modm(a, fromhex(tests[i][0]), 32);
  6688. expand256_modm(b, fromhex(tests[i][2]), 32);
  6689. ge25519_unpack_negative_vartime(&A, fromhex(tests[i][1]));
  6690. curve25519_neg(A.x, A.x);
  6691. curve25519_neg(A.t, A.t);
  6692. ge25519_unpack_negative_vartime(&B, fromhex(tests[i][3]));
  6693. curve25519_neg(B.x, B.x);
  6694. curve25519_neg(B.t, B.t);
  6695. ge25519_double_scalarmult_vartime2(&R, &A, a, &B, b);
  6696. ge25519_pack(buff, &R);
  6697. ck_assert_mem_eq(buff, fromhex(tests[i][4]), 32);
  6698. }
  6699. }
  6700. END_TEST
  6701. static void test_bip32_ecdh_init_node(HDNode *node, const char *seed_str,
  6702. const char *curve_name) {
  6703. hdnode_from_seed((const uint8_t *)seed_str, strlen(seed_str), curve_name,
  6704. node);
  6705. ck_assert_int_eq(hdnode_fill_public_key(node), 0);
  6706. if (node->public_key[0] == 1) {
  6707. node->public_key[0] = 0x40; // Curve25519 public keys start with 0x40 byte
  6708. }
  6709. }
  6710. static void test_bip32_ecdh(const char *curve_name, int expected_key_size,
  6711. const uint8_t *expected_key) {
  6712. int res, key_size;
  6713. HDNode alice, bob;
  6714. uint8_t session_key1[expected_key_size], session_key2[expected_key_size];
  6715. test_bip32_ecdh_init_node(&alice, "Alice", curve_name);
  6716. test_bip32_ecdh_init_node(&bob, "Bob", curve_name);
  6717. // Generate shared key from Alice's secret key and Bob's public key
  6718. res = hdnode_get_shared_key(&alice, bob.public_key, session_key1, &key_size);
  6719. ck_assert_int_eq(res, 0);
  6720. ck_assert_int_eq(key_size, expected_key_size);
  6721. ck_assert_mem_eq(session_key1, expected_key, key_size);
  6722. // Generate shared key from Bob's secret key and Alice's public key
  6723. res = hdnode_get_shared_key(&bob, alice.public_key, session_key2, &key_size);
  6724. ck_assert_int_eq(res, 0);
  6725. ck_assert_int_eq(key_size, expected_key_size);
  6726. ck_assert_mem_eq(session_key2, expected_key, key_size);
  6727. }
  6728. START_TEST(test_bip32_ecdh_nist256p1) {
  6729. test_bip32_ecdh(
  6730. NIST256P1_NAME, 65,
  6731. fromhex(
  6732. "044aa56f917323f071148cd29aa423f6bee96e7fe87f914d0b91a0f95388c6631646"
  6733. "ea92e882773d7b0b1bec356b842c8559a1377673d3965fb931c8fe51e64873"));
  6734. }
  6735. END_TEST
  6736. START_TEST(test_bip32_ecdh_curve25519) {
  6737. test_bip32_ecdh(CURVE25519_NAME, 33,
  6738. fromhex("04f34e35516325bb0d4a58507096c444a05ba13524ccf66910f1"
  6739. "1ce96c62224169"));
  6740. }
  6741. END_TEST
  6742. START_TEST(test_bip32_ecdh_errors) {
  6743. HDNode node;
  6744. const uint8_t peer_public_key[65] = {0}; // invalid public key
  6745. uint8_t session_key[65];
  6746. int res, key_size = 0;
  6747. test_bip32_ecdh_init_node(&node, "Seed", ED25519_NAME);
  6748. res = hdnode_get_shared_key(&node, peer_public_key, session_key, &key_size);
  6749. ck_assert_int_eq(res, 1);
  6750. ck_assert_int_eq(key_size, 0);
  6751. test_bip32_ecdh_init_node(&node, "Seed", CURVE25519_NAME);
  6752. res = hdnode_get_shared_key(&node, peer_public_key, session_key, &key_size);
  6753. ck_assert_int_eq(res, 1);
  6754. ck_assert_int_eq(key_size, 0);
  6755. test_bip32_ecdh_init_node(&node, "Seed", NIST256P1_NAME);
  6756. res = hdnode_get_shared_key(&node, peer_public_key, session_key, &key_size);
  6757. ck_assert_int_eq(res, 1);
  6758. ck_assert_int_eq(key_size, 0);
  6759. }
  6760. END_TEST
  6761. START_TEST(test_output_script) {
  6762. static const char *vectors[] = {
  6763. "76A914010966776006953D5567439E5E39F86A0D273BEE88AC",
  6764. "16UwLL9Risc3QfPqBUvKofHmBQ7wMtjvM",
  6765. "A914010966776006953D5567439E5E39F86A0D273BEE87",
  6766. "31nVrspaydBz8aMpxH9WkS2DuhgqS1fCuG",
  6767. "0014010966776006953D5567439E5E39F86A0D273BEE",
  6768. "p2xtZoXeX5X8BP8JfFhQK2nD3emtjch7UeFm",
  6769. "00200102030405060708090A0B0C0D0E0F101112131415161718191A1B1C1D1E1F20",
  6770. "7XhPD7te3C6CVKnJWUhrTJbFTwudhHqfrjpS59AS6sMzL4RYFiCNg",
  6771. 0,
  6772. 0,
  6773. };
  6774. const char **scr, **adr;
  6775. scr = vectors;
  6776. adr = vectors + 1;
  6777. char address[60];
  6778. while (*scr && *adr) {
  6779. int r =
  6780. script_output_to_address(fromhex(*scr), strlen(*scr) / 2, address, 60);
  6781. ck_assert_uint_eq((size_t)r, strlen(*adr) + 1);
  6782. ck_assert_str_eq(address, *adr);
  6783. scr += 2;
  6784. adr += 2;
  6785. }
  6786. }
  6787. END_TEST
  6788. START_TEST(test_ethereum_pubkeyhash) {
  6789. uint8_t pubkeyhash[20];
  6790. int res;
  6791. HDNode node;
  6792. // init m
  6793. hdnode_from_seed(fromhex("000102030405060708090a0b0c0d0e0f"), 16,
  6794. SECP256K1_NAME, &node);
  6795. // [Chain m]
  6796. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6797. ck_assert_int_eq(res, 1);
  6798. ck_assert_mem_eq(pubkeyhash,
  6799. fromhex("056db290f8ba3250ca64a45d16284d04bc6f5fbf"), 20);
  6800. // [Chain m/0']
  6801. hdnode_private_ckd_prime(&node, 0);
  6802. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6803. ck_assert_int_eq(res, 1);
  6804. ck_assert_mem_eq(pubkeyhash,
  6805. fromhex("bf6e48966d0dcf553b53e7b56cb2e0e72dca9e19"), 20);
  6806. // [Chain m/0'/1]
  6807. hdnode_private_ckd(&node, 1);
  6808. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6809. ck_assert_int_eq(res, 1);
  6810. ck_assert_mem_eq(pubkeyhash,
  6811. fromhex("29379f45f515c494483298225d1b347f73d1babf"), 20);
  6812. // [Chain m/0'/1/2']
  6813. hdnode_private_ckd_prime(&node, 2);
  6814. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6815. ck_assert_int_eq(res, 1);
  6816. ck_assert_mem_eq(pubkeyhash,
  6817. fromhex("d8e85fbbb4b3b3c71c4e63a5580d0c12fb4d2f71"), 20);
  6818. // [Chain m/0'/1/2'/2]
  6819. hdnode_private_ckd(&node, 2);
  6820. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6821. ck_assert_int_eq(res, 1);
  6822. ck_assert_mem_eq(pubkeyhash,
  6823. fromhex("1d3462d2319ac0bfc1a52e177a9d372492752130"), 20);
  6824. // [Chain m/0'/1/2'/2/1000000000]
  6825. hdnode_private_ckd(&node, 1000000000);
  6826. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6827. ck_assert_int_eq(res, 1);
  6828. ck_assert_mem_eq(pubkeyhash,
  6829. fromhex("73659c60270d326c06ac204f1a9c63f889a3d14b"), 20);
  6830. // init m
  6831. hdnode_from_seed(
  6832. fromhex(
  6833. "fffcf9f6f3f0edeae7e4e1dedbd8d5d2cfccc9c6c3c0bdbab7b4b1aeaba8a5a29f9c"
  6834. "999693908d8a8784817e7b7875726f6c696663605d5a5754514e4b484542"),
  6835. 64, SECP256K1_NAME, &node);
  6836. // [Chain m]
  6837. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6838. ck_assert_int_eq(res, 1);
  6839. ck_assert_mem_eq(pubkeyhash,
  6840. fromhex("6dd2a6f3b05fd15d901fbeec61b87a34bdcfb843"), 20);
  6841. // [Chain m/0]
  6842. hdnode_private_ckd(&node, 0);
  6843. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6844. ck_assert_int_eq(res, 1);
  6845. ck_assert_mem_eq(pubkeyhash,
  6846. fromhex("abbcd4471a0b6e76a2f6fdc44008fe53831e208e"), 20);
  6847. // [Chain m/0/2147483647']
  6848. hdnode_private_ckd_prime(&node, 2147483647);
  6849. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6850. ck_assert_int_eq(res, 1);
  6851. ck_assert_mem_eq(pubkeyhash,
  6852. fromhex("40ef2cef1b2588ae862e7a511162ec7ff33c30fd"), 20);
  6853. // [Chain m/0/2147483647'/1]
  6854. hdnode_private_ckd(&node, 1);
  6855. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6856. ck_assert_int_eq(res, 1);
  6857. ck_assert_mem_eq(pubkeyhash,
  6858. fromhex("3f2e8905488f795ebc84a39560d133971ccf9b50"), 20);
  6859. // [Chain m/0/2147483647'/1/2147483646']
  6860. hdnode_private_ckd_prime(&node, 2147483646);
  6861. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6862. ck_assert_int_eq(res, 1);
  6863. ck_assert_mem_eq(pubkeyhash,
  6864. fromhex("a5016fdf975f767e4e6f355c7a82efa69bf42ea7"), 20);
  6865. // [Chain m/0/2147483647'/1/2147483646'/2]
  6866. hdnode_private_ckd(&node, 2);
  6867. res = hdnode_get_ethereum_pubkeyhash(&node, pubkeyhash);
  6868. ck_assert_int_eq(res, 1);
  6869. ck_assert_mem_eq(pubkeyhash,
  6870. fromhex("8ff2a9f7e7917804e8c8ec150d931d9c5a6fbc50"), 20);
  6871. }
  6872. END_TEST
  6873. START_TEST(test_ethereum_address) {
  6874. static const char *vectors[] = {"0x52908400098527886E0F7030069857D2E4169EE7",
  6875. "0x8617E340B3D01FA5F11F306F4090FD50E238070D",
  6876. "0xde709f2102306220921060314715629080e2fb77",
  6877. "0x27b1fdb04752bbc536007a920d24acb045561c26",
  6878. "0x5aAeb6053F3E94C9b9A09f33669435E7Ef1BeAed",
  6879. "0xfB6916095ca1df60bB79Ce92cE3Ea74c37c5d359",
  6880. "0xdbF03B407c01E7cD3CBea99509d93f8DDDC8C6FB",
  6881. "0xD1220A0cf47c7B9Be7A2E6BA89F429762e7b9aDb",
  6882. "0x5A4EAB120fB44eb6684E5e32785702FF45ea344D",
  6883. "0x5be4BDC48CeF65dbCbCaD5218B1A7D37F58A0741",
  6884. "0xa7dD84573f5ffF821baf2205745f768F8edCDD58",
  6885. "0x027a49d11d118c0060746F1990273FcB8c2fC196",
  6886. "0xCD2a3d9F938E13CD947Ec05AbC7FE734Df8DD826",
  6887. 0};
  6888. uint8_t addr[20];
  6889. char address[43];
  6890. const char **vec = vectors;
  6891. while (*vec) {
  6892. memcpy(addr, fromhex(*vec + 2), 20);
  6893. ethereum_address_checksum(addr, address, false, 0);
  6894. ck_assert_str_eq(address, *vec);
  6895. vec++;
  6896. }
  6897. }
  6898. END_TEST
  6899. // test vectors from
  6900. // https://github.com/rsksmart/RSKIPs/blob/master/IPs/RSKIP60.md
  6901. START_TEST(test_rsk_address) {
  6902. uint8_t addr[20];
  6903. char address[43];
  6904. static const char *rskip60_chain30[] = {
  6905. "0x5aaEB6053f3e94c9b9a09f33669435E7ef1bEAeD",
  6906. "0xFb6916095cA1Df60bb79ce92cE3EA74c37c5d359",
  6907. "0xDBF03B407c01E7CD3cBea99509D93F8Dddc8C6FB",
  6908. "0xD1220A0Cf47c7B9BE7a2e6ba89F429762E7B9adB", 0};
  6909. const char **vec = rskip60_chain30;
  6910. while (*vec) {
  6911. memcpy(addr, fromhex(*vec + 2), 20);
  6912. ethereum_address_checksum(addr, address, true, 30);
  6913. ck_assert_str_eq(address, *vec);
  6914. vec++;
  6915. }
  6916. static const char *rskip60_chain31[] = {
  6917. "0x5aAeb6053F3e94c9b9A09F33669435E7EF1BEaEd",
  6918. "0xFb6916095CA1dF60bb79CE92ce3Ea74C37c5D359",
  6919. "0xdbF03B407C01E7cd3cbEa99509D93f8dDDc8C6fB",
  6920. "0xd1220a0CF47c7B9Be7A2E6Ba89f429762E7b9adB", 0};
  6921. vec = rskip60_chain31;
  6922. while (*vec) {
  6923. memcpy(addr, fromhex(*vec + 2), 20);
  6924. ethereum_address_checksum(addr, address, true, 31);
  6925. ck_assert_str_eq(address, *vec);
  6926. vec++;
  6927. }
  6928. }
  6929. END_TEST
  6930. // test vectors from
  6931. // https://raw.githubusercontent.com/NemProject/nem-test-vectors/master/1.test-keys.dat
  6932. START_TEST(test_nem_address) {
  6933. static const struct {
  6934. const char *private_key;
  6935. const char *public_key;
  6936. const char *address;
  6937. } tests[] = {
  6938. {
  6939. "575dbb3062267eff57c970a336ebbc8fbcfe12c5bd3ed7bc11eb0481d7704ced",
  6940. "c5f54ba980fcbb657dbaaa42700539b207873e134d2375efeab5f1ab52f87844",
  6941. "NDD2CT6LQLIYQ56KIXI3ENTM6EK3D44P5JFXJ4R4",
  6942. },
  6943. {
  6944. "5b0e3fa5d3b49a79022d7c1e121ba1cbbf4db5821f47ab8c708ef88defc29bfe",
  6945. "96eb2a145211b1b7ab5f0d4b14f8abc8d695c7aee31a3cfc2d4881313c68eea3",
  6946. "NABHFGE5ORQD3LE4O6B7JUFN47ECOFBFASC3SCAC",
  6947. },
  6948. {
  6949. "738ba9bb9110aea8f15caa353aca5653b4bdfca1db9f34d0efed2ce1325aeeda",
  6950. "2d8425e4ca2d8926346c7a7ca39826acd881a8639e81bd68820409c6e30d142a",
  6951. "NAVOZX4HDVOAR4W6K4WJHWPD3MOFU27DFHC7KZOZ",
  6952. },
  6953. {
  6954. "e8bf9bc0f35c12d8c8bf94dd3a8b5b4034f1063948e3cc5304e55e31aa4b95a6",
  6955. "4feed486777ed38e44c489c7c4e93a830e4c4a907fa19a174e630ef0f6ed0409",
  6956. "NBZ6JK5YOCU6UPSSZ5D3G27UHAPHTY5HDQMGE6TT",
  6957. },
  6958. {
  6959. "c325ea529674396db5675939e7988883d59a5fc17a28ca977e3ba85370232a83",
  6960. "83ee32e4e145024d29bca54f71fa335a98b3e68283f1a3099c4d4ae113b53e54",
  6961. "NCQW2P5DNZ5BBXQVGS367DQ4AHC3RXOEVGRCLY6V",
  6962. },
  6963. {
  6964. "a811cb7a80a7227ae61f6da536534ee3c2744e3c7e4b85f3e0df3c6a9c5613df",
  6965. "6d34c04f3a0e42f0c3c6f50e475ae018cfa2f56df58c481ad4300424a6270cbb",
  6966. "NA5IG3XFXZHIPJ5QLKX2FBJPEZYPMBPPK2ZRC3EH",
  6967. },
  6968. {
  6969. "9c66de1ec77f4dfaaebdf9c8bc599ca7e8e6f0bc71390ffee2c9dd3f3619242a",
  6970. "a8fefd72a3b833dc7c7ed7d57ed86906dac22f88f1f4331873eb2da3152a3e77",
  6971. "NAABHVFJDBM74XMJJ52R7QN2MTTG2ZUXPQS62QZ7",
  6972. },
  6973. {
  6974. "c56bc16ecf727878c15e24f4ae68569600ac7b251218a44ef50ce54175776edc",
  6975. "c92f761e6d83d20068fd46fe4bd5b97f4c6ba05d23180679b718d1f3e4fb066e",
  6976. "NCLK3OLMHR3F2E3KSBUIZ4K5PNWUDN37MLSJBJZP",
  6977. },
  6978. {
  6979. "9dd73599283882fa1561ddfc9be5830b5dd453c90465d3fe5eeb646a3606374e",
  6980. "eaf16a4833e59370a04ccd5c63395058de34877b48c17174c71db5ed37b537ed",
  6981. "ND3AHW4VTI5R5QE5V44KIGPRU5FBJ5AFUCJXOY5H",
  6982. },
  6983. {
  6984. "d9639dc6f49dad02a42fd8c217f1b1b4f8ce31ccd770388b645e639c72ff24fa",
  6985. "0f74a2f537cd9c986df018994dde75bdeee05e35eb9fe27adf506ca8475064f7",
  6986. "NCTZ4YAP43ONK3UYTASQVNDMBO24ZHJE65F3QPYE",
  6987. },
  6988. {
  6989. "efc1992cd50b70ca55ac12c07aa5d026a8b78ffe28a7dbffc9228b26e02c38c1",
  6990. "2ebff201255f6cf948c78f528658b99a7c13ac791942fa22d59af610558111f5",
  6991. "NDQ2TMCMXBSFPZQPE2YKH6XLC24HD6LUMN6Z4GIC",
  6992. },
  6993. {
  6994. "143a815e92e43f3ed1a921ee48cd143931b88b7c3d8e1e981f743c2a5be3c5ba",
  6995. "419ed11d48730e4ae2c93f0ea4df853b8d578713a36dab227517cf965861af4e",
  6996. "NA32IDDW2C53BDSBJNFL3Z6UU3J5CJZJMCZDXCF4",
  6997. },
  6998. {
  6999. "bc1a082f5ac6fdd3a83ade211e5986ac0551bad6c7da96727ec744e5df963e2a",
  7000. "a160e6f9112233a7ce94202ed7a4443e1dac444b5095f9fecbb965fba3f92cac",
  7001. "NADUCEQLC3FTGB25GTA5HOUTB53CBVQNVOIP7NTJ",
  7002. },
  7003. {
  7004. "4e47b4c6f4c7886e49ec109c61f4af5cfbb1637283218941d55a7f9fe1053f72",
  7005. "fbb91b16df828e21a9802980a44fc757c588bc1382a4cea429d6fa2ae0333f56",
  7006. "NBAF3BFLLPWH33MYE6VUPP5T6DQBZBKIDEQKZQOE",
  7007. },
  7008. {
  7009. "efc4389da48ce49f85365cfa578c746530e9eac42db1b64ec346119b1becd347",
  7010. "2232f24dda0f2ded3ecd831210d4e8521a096b50cadd5a34f3f7083374e1ec12",
  7011. "NBOGTK2I2ATOGGD7ZFJHROG5MWL7XCKAUKSWIVSA",
  7012. },
  7013. {
  7014. "bdba57c78ca7da16a3360efd13f06276284db8c40351de7fcd38ba0c35ac754d",
  7015. "c334c6c0dad5aaa2a0d0fb4c6032cb6a0edd96bf61125b5ea9062d5a00ee0eee",
  7016. "NCLERTEFYXKLK7RA4MVACEFMXMK3P7QMWTM7FBW2",
  7017. },
  7018. {
  7019. "20694c1ec3c4a311bcdb29ed2edc428f6d4f9a4c429ad6a5bf3222084e35695f",
  7020. "518c4de412efa93de06a55947d11f697639443916ec8fcf04ebc3e6d17d0bd93",
  7021. "NB5V4BPIJHXVONO7UGMJDPFARMFA73BOBNOOYCOV",
  7022. },
  7023. {
  7024. "e0d4f3760ac107b33c22c2cac24ab2f520b282684f5f66a4212ff95d926323ce",
  7025. "b3d16f4ead9de67c290144da535a0ed2504b03c05e5f1ceb8c7863762f786857",
  7026. "NC4PBAO5TPCAVQKBVOC4F6DMZP3CFSQBU46PSKBD",
  7027. },
  7028. {
  7029. "efa9afc617412093c9c7a7c211a5332dd556f941e1a88c494ec860608610eea2",
  7030. "7e7716e4cebceb731d6f1fd28676f34888e9a0000fcfa1471db1c616c2ddf559",
  7031. "NCFW2LPXIWLBWAQN2QVIWEOD7IVDO3HQBD2OU56K",
  7032. },
  7033. {
  7034. "d98499b3db61944684ce06a91735af4e14105338473fcf6ebe2b0bcada3dfd21",
  7035. "114171230ad6f8522a000cdc73fbc5c733b30bb71f2b146ccbdf34499f79a810",
  7036. "NCUKWDY3J3THKQHAKOK5ALF6ANJQABZHCH7VN6DP",
  7037. },
  7038. };
  7039. HDNode node;
  7040. ed25519_secret_key private_key;
  7041. uint8_t chain_code[32];
  7042. char address[41];
  7043. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  7044. nem_private_key(tests[i].private_key, private_key);
  7045. ck_assert(hdnode_from_xprv(0, 0, chain_code, private_key,
  7046. ED25519_KECCAK_NAME, &node));
  7047. ck_assert(hdnode_get_nem_address(&node, NEM_NETWORK_MAINNET, address));
  7048. ck_assert_str_eq(address, tests[i].address);
  7049. ck_assert_mem_eq(&node.public_key[1], fromhex(tests[i].public_key), 32);
  7050. }
  7051. }
  7052. END_TEST
  7053. // test vectors from
  7054. // https://raw.githubusercontent.com/NemProject/nem-test-vectors/master/3.test-derive.dat
  7055. START_TEST(test_nem_derive) {
  7056. static const struct {
  7057. const char *salt;
  7058. const char *private_key;
  7059. const char *public_key;
  7060. const char *mul;
  7061. const char *shared_key;
  7062. } tests[] = {
  7063. {
  7064. "ad63ac08f9afc85eb0bf4f8881ca6eaa0215924c87aa2f137d56109bb76c6f98",
  7065. "e8857f8e488d4e6d4b71bcd44bb4cff49208c32651e1f6500c3b58cafeb8def6",
  7066. "9d8e5f200b05a2638fb084a375408cabd6d5989590d96e3eea5f2cb34668178e",
  7067. "a8352060ba5718745ee4d78b9df564e0fbe13f50d50ab15a8dd524159d81d18b",
  7068. "990a5f611c65fbcde735378bdec38e1039c5466503511e8c645bbe42795c752b",
  7069. },
  7070. {
  7071. "96104f0a28f9cca40901c066cd435134662a3b053eb6c8df80ee0d05dc941963",
  7072. "d7f67b5f52cbcd1a1367e0376a8eb1012b634acfcf35e8322bae8b22bb9e8dea",
  7073. "9735c92d150dcee0ade5a8d1822f46a4db22c9cda25f33773ae856fe374a3e8a",
  7074. "ea14d521d83328dba70982d42094300585818cc2da609fdb1f73bb32235576ff",
  7075. "b498aa21d4ba4879ea9fd4225e93bacc760dcd9c119f8f38ab0716457d1a6f85",
  7076. },
  7077. {
  7078. "d8f94a0bbb1de80aea17aab42e2ffb982e73fc49b649a318479e951e392d8728",
  7079. "d026ddb445fb3bbf3020e4b55ed7b5f9b7fd1278c34978ca1a6ed6b358dadbae",
  7080. "d19e6beca3b26b9d1abc127835ebeb7a6c19c33dec8ec472e1c4d458202f4ec8",
  7081. "0d561f54728ad837ae108ec66c2ece2bb3b26041d3ee9b77fdc6d36d9ebfb2e3",
  7082. "d012afe3d1d932304e613c91545bf571cf2c7281d6cafa8e81393a551f675540",
  7083. },
  7084. {
  7085. "3f8c969678a8abdbfb76866a142c284a6f01636c1c1607947436e0d2c30d5245",
  7086. "c522b38c391d1c3fa539cc58802bc66ac34bb3c73accd7f41b47f539bedcd016",
  7087. "ea5b6a0053237f7712b1d2347c447d3e83e0f2191762d07e1f53f8eb7f2dfeaa",
  7088. "23cccd3b63a9456e4425098b6df36f28c8999461a85e4b2b0c8d8f53c62c9ea9",
  7089. "7e27efa50eed1c2ac51a12089cbab6a192624709c7330c016d5bc9af146584c1",
  7090. },
  7091. {
  7092. "e66415c58b981c7f1f2b8f45a42149e9144616ff6de49ff83d97000ac6f6f992",
  7093. "2f1b82be8e65d610a4e588f000a89a733a9de98ffc1ac9d55e138b3b0a855da0",
  7094. "65aeda1b47f66c978a4a41d4dcdfbd8eab5cdeb135695c2b0c28f54417b1486d",
  7095. "43e5b0a5cc8146c03ac63e6f8cf3d8825a9ca1ed53ea4a88304af4ddf5461b33",
  7096. "bb4ab31c334e55d378937978c90bb33779b23cd5ef4c68342a394f4ec8fa1ada",
  7097. },
  7098. {
  7099. "58487c9818c9d28ddf97cb09c13331941e05d0b62bf4c35ee368de80b552e4d1",
  7100. "f3869b68183b2e4341307653e8f659bd7cd20e37ea5c00f5a9e203a8fa92359a",
  7101. "c7e4153a18b4162f5c1f60e1ba483264aa5bb3f4889dca45b434fcd30b9cf56f",
  7102. "5ae9408ab3156b8828c3e639730bd5e5db93d7afe2cee3fcda98079316c5bb3a",
  7103. "0224d85ae8f17bfe127ec24b8960b7639a0dbde9c8c39a0575b939448687bb14",
  7104. },
  7105. {
  7106. "ad66f3b654844e53d6fb3568134fae75672ba63868c113659d3ca58c2c39d24f",
  7107. "d38f2ef8dfdc7224fef596130c3f4ff68ac83d3f932a56ee908061466ac28572",
  7108. "d0c79d0340dc66f0a895ce5ad60a933cf6be659569096fb9d4b81e5d32292372",
  7109. "1ea22db4708ed585ab541a4c70c3069f8e2c0c1faa188ddade3efaa53c8329f6",
  7110. "886a7187246934aedf2794748deadfe038c9fd7e78d4b7be76c5a651440ac843",
  7111. },
  7112. {
  7113. "eed48604eab279c6ad8128aa83483a3da0928271a4cae1a5745671284e1fb89d",
  7114. "e2342a8450fc0adfa0ea2fbd0b1d28f100f0a3a905a3da29de34d1353afa7df7",
  7115. "d2dbe07e0f2dbc3dbb01c70092e3c4247d12827ddcd8d76534fd740a65c30de2",
  7116. "4c4b30eb6a2bfa17312f5729b4212cb51c2eee8fbfaea82a0e957ca68f4f6a30",
  7117. "dcae613ac5641ff9d4c3ca58632245f93b0b8657fe4d48bac7b062cc53dd21ad",
  7118. },
  7119. {
  7120. "f35b315287b268c0d0b386fb5b31810f65e1c4497cffae24527f69a3abac3884",
  7121. "049016230dbef7a14a439e5ab2f6d12e78cb8df127db4e0c312673b3c361e350",
  7122. "1b3b1925a8a535cd7d78725d25298f45bba8ca3dee2cdaabf14241c9b51b37c4",
  7123. "04c9685dae1f8eb72a6438f24a87dc83a56d79c9024edf7e01aa1ae34656f29e",
  7124. "b48469d0428c223b93cd1fe34bb2cafd3fb78a8fa15f98f89f1ac9c0ce7c9001",
  7125. },
  7126. {
  7127. "d6cf082c5d9a96e756a94a2e27703138580a7c7c1af505c96c3abf7ab6802e1d",
  7128. "67cd02b0b8b0adcf6fdd4d4d64a1f4193ced68bb8605d0ec941a62011326d140",
  7129. "a842d5127c93a435e4672dcadd9fccbfd0e9208c79c5404848b298597eccdbdb",
  7130. "d5c6bd6d81b99659d0bafe91025b6ecf73b16c6b07931cf44718b13f00fde3f7",
  7131. "8aa160795b587f4be53aa35d26e9b618b4cd6ec765b523bc908e53c258ca8fd4",
  7132. },
  7133. {
  7134. "dda32c91c95527a645b00dd05d13f0b98ed612a726ce5f5221431430b7660944",
  7135. "eba026f92a8ffb5e95060a22e15d597fe838a99a0b2bbcb423c933b6bc718c50",
  7136. "7dbaf9c313a1ff9128c54d6cd740c7d0cc46bca588e7910d438dd619ca4fd69a",
  7137. "5bb20a145de83ba27a0c261e1f54bfd7dcea61888fc2eebbe6166876f7b000b8",
  7138. "3a96f152ad8bf355cccb307e4a40108aa17f8e925522a2b5bb0b3f1e1a262914",
  7139. },
  7140. {
  7141. "63c500acbd4ff747f7dadde7d3286482894ac4d7fe68f396712bca29879aa65c",
  7142. "9663cd3c2030a5fe4a3ea3cc9a1d182b3a63ade68616aaeb4caf40b495f6f227",
  7143. "b1e7d9070ac820d986d839b79f7aa594dcf708473529dad87af8682cc6197374",
  7144. "1f7a97584d8db9f395b9ac4447de4b33c5c1f5020187cd4996286a49b07eb8a7",
  7145. "4d2a974ec12dcf525b5654d31053460850c3092648b7e15598b7131d2930e9fb",
  7146. },
  7147. {
  7148. "91f340961029398cc8bcd906388044a6801d24328efdf919d8ed0c609862a073",
  7149. "45a588500d00142e2226231c01fd11ac6f842ab6a85872418f5b6a1999f8bd98",
  7150. "397233c96069b6f4a57d6e93f759fa327222eaef71fc981afa673b248206df3f",
  7151. "062123ef9782e3893f7b2e1d557b4ecce92b9f9aa8577e76380f228b75152f84",
  7152. "235848cb04230a16d8978aa7c19fe7fbff3ebe29389ea6eb24fb8bc3cb50afc6",
  7153. },
  7154. {
  7155. "46120b4da6ba4eb54fb65213cfef99b812c86f7c42a1de1107f8e8c12c0c3b6b",
  7156. "cc19a97a99ad71ce348bcf831c0218e6a1f0a8d52186cabe6298b56f24e640f9",
  7157. "c54631bb62f0f9d86b3301fcb2a671621e655e578c95504af5f78da83f7fec4f",
  7158. "ab73cc20c75260ff3a7cefea8039291d4d15114a07a9250375628cca32225bb6",
  7159. "70040a360b6a2dfa881272ef4fa6616e2e8fcc45194fa2a21a1eef1160271cd5",
  7160. },
  7161. {
  7162. "f0a69ded09f1d731ab9561d0c3a40b7ef30bcb2bf60f92beccd8734e2441403d",
  7163. "ea732822a381c46a7ac9999bf5ef85e16b7460b26aaf6c1a1c6ffa8c8c82c923",
  7164. "110decbff79c382b1e60af4259564a3c473087792350b24fca98ae9a74ba9dd9",
  7165. "81bdee95aecdcf821a9d682f79056f1abdcf1245d2f3b55244447881a283e0d4",
  7166. "1bc29d4470ccf97d4e35e8d3cd4b12e3ebf2cb0a82425d35984aeedf7ad0f6f9",
  7167. },
  7168. {
  7169. "e79cf4536fb1547e57626c0f1a87f71a396fdfb985b00731c0c2876a00645eda",
  7170. "04213fc02b59c372e3e7f53faa71a2f73b31064102cb6fc8b68432ba7cdf7eb4",
  7171. "ca1c750aaed53bc30dac07d0696ed86bcd7cdbbcbd3d15bb90d90cb5c6117bac",
  7172. "c68cd0872a42a3a64e8a229ef7fcad3d722047d5af966f7dda4d4e32d0d57203",
  7173. "bfdd3d07563d966d95afe4b8abea4b567265fceea8c4ecddb0946256c33e07b2",
  7174. },
  7175. {
  7176. "81a40db4cddaf076e0206bd2b0fa7470a72cc456bad34aa3a0469a4859f286be",
  7177. "52156799fd86cc63345cdbffd65ef4f5f8df0ffd9906a40af5f41d269bbcff5d",
  7178. "54d61aa0b0b17a87f1376fe89cd8cd6b314827c1f1b9e5e7b20e7a7eee2a8335",
  7179. "4553fb2cab8555068c32f86ceb692bbf1c2beeaf21627ef1b1be57344b52eea8",
  7180. "55096b6710ade3bbe38702458ee13faa10c24413261bc076f17675dcbf2c4ee6",
  7181. },
  7182. {
  7183. "d28e4a9e6832a3a4dad014a2bf1f666f01093cbba8b9ad4d1dcad3ea10cb42b9",
  7184. "8ca134404c8fa199b0c72cb53cfa0adcf196dfa560fb521017cce5cbace3ba59",
  7185. "3a6c39a1e5f9f550f1debedd9a0bc84210cce5f9834797db8f14122bf5817e45",
  7186. "eb632ca818b4f659630226a339a3ce536b31c8e1e686fea8da3760e8abc20b8e",
  7187. "9fbb3fbaf1cd54ee0cd90685f59b082545983f1f662ef701332379306a6ad546",
  7188. },
  7189. {
  7190. "f9c4bfad9e2a3d98c44c12734881a6f217d6c9523cc210772fad1297993454b4",
  7191. "b85960fcadda8d0a0960559b6b7818a0d8d4574b4e928b17c9b498fa9ffab4ef",
  7192. "6a1d0ef23ce0b40a7077ecb7b7264945054e3bdb58ee25e1b0ee8b3e19dbfcdc",
  7193. "bb145dddcb75074a6a03249fca1aa7d6fa9549e3ed965f138ca5e7071b7878f2",
  7194. "87d3faea4a98e41009eb8625611ea0fc12094c295af540c126c14a0f55afa76e",
  7195. },
  7196. {
  7197. "656df4789a369d220aceb7b318517787d27004ecccedea019d623bcb2d79f5ff",
  7198. "acf83e30afb2a5066728ec5d93564c08abe5e68e3a2a2ff953bdcf4d44f9da06",
  7199. "bdda65efe56d7890286aada1452f62f85ba157d0b4621ba641de15d8d1c9e331",
  7200. "958beef5dc6babc6de383c32ad7dd3a6d6eb8bb3236ed5558eec0f9eb31e5458",
  7201. "6f6d4ee36d9d76e462c9635adfbb6073134a276cfc7cb86762004ec47197afa0",
  7202. },
  7203. };
  7204. HDNode node;
  7205. ed25519_secret_key private_key;
  7206. uint8_t chain_code[32];
  7207. ed25519_public_key public_key, mul;
  7208. uint8_t shared_key[SHA3_256_DIGEST_LENGTH];
  7209. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  7210. nem_private_key(tests[i].private_key, private_key);
  7211. ck_assert(hdnode_from_xprv(0, 0, chain_code, private_key,
  7212. ED25519_KECCAK_NAME, &node));
  7213. memcpy(public_key, fromhex(tests[i].public_key), 32);
  7214. ck_assert(hdnode_get_nem_shared_key(
  7215. &node, public_key, fromhex(tests[i].salt), mul, shared_key));
  7216. ck_assert_mem_eq(mul, fromhex(tests[i].mul), sizeof(mul));
  7217. ck_assert_mem_eq(shared_key, fromhex(tests[i].shared_key),
  7218. sizeof(shared_key));
  7219. }
  7220. }
  7221. END_TEST
  7222. // test vectors from
  7223. // https://raw.githubusercontent.com/NemProject/nem-test-vectors/master/4.test-cipher.dat
  7224. START_TEST(test_nem_cipher) {
  7225. static const struct {
  7226. const char *private_key;
  7227. const char *public_key;
  7228. const char *salt;
  7229. const char *iv;
  7230. const char *input;
  7231. const char *output;
  7232. } tests[] = {
  7233. {
  7234. "3140f94c79f249787d1ec75a97a885980eb8f0a7d9b7aa03e7200296e422b2b6",
  7235. "57a70eb553a7b3fd621f0dba6abf51312ea2e2a2a1e19d0305516730f4bcbd21",
  7236. "83616c67f076d356fd1288a6e0fd7a60488ba312a3adf0088b1b33c7655c3e6a",
  7237. "a73ff5c32f8fd055b09775817a6a3f95",
  7238. "86ddb9e713a8ebf67a51830eff03b837e147c20d75e67b2a54aa29e98c",
  7239. "70815da779b1b954d7a7f00c16940e9917a0412a06a444b539bf147603eef87f",
  7240. },
  7241. {
  7242. "3140f94c79f249787d1ec75a97a885980eb8f0a7d9b7aa03e7200296e422b2b6",
  7243. "57a70eb553a7b3fd621f0dba6abf51312ea2e2a2a1e19d0305516730f4bcbd21",
  7244. "703ce0b1d276b10eef35672df03234385a903460db18ba9d4e05b3ad31abb284",
  7245. "91246c2d5493867c4fa3e78f85963677",
  7246. "86ddb9e713a8ebf67a51830eff03b837e147c20d75e67b2a54aa29e98c",
  7247. "564b2f40d42c0efc1bd6f057115a5abd1564cae36d7ccacf5d825d38401aa894",
  7248. },
  7249. {
  7250. "3140f94c79f249787d1ec75a97a885980eb8f0a7d9b7aa03e7200296e422b2b6",
  7251. "57a70eb553a7b3fd621f0dba6abf51312ea2e2a2a1e19d0305516730f4bcbd21",
  7252. "b22e8e8e7373ac31ca7f0f6eb8b93130aba5266772a658593f3a11792e7e8d92",
  7253. "9f8e33d82374dad6aac0e3dbe7aea704",
  7254. "86ddb9e713a8ebf67a51830eff03b837e147c20d75e67b2a54aa29e98c",
  7255. "7cab88d00a3fc656002eccbbd966e1d5d14a3090d92cf502cdbf843515625dcf",
  7256. },
  7257. {
  7258. "3140f94c79f249787d1ec75a97a885980eb8f0a7d9b7aa03e7200296e422b2b6",
  7259. "57a70eb553a7b3fd621f0dba6abf51312ea2e2a2a1e19d0305516730f4bcbd21",
  7260. "af646c54cd153dffe453b60efbceeb85c1e95a414ea0036c4da94afb3366f5d9",
  7261. "6acdf8e01acc8074ddc807281b6af888",
  7262. "86ddb9e713a8ebf67a51830eff03b837e147c20d75e67b2a54aa29e98c",
  7263. "aa70543a485b63a4dd141bb7fd78019092ac6fad731e914280a287c7467bae1a",
  7264. },
  7265. {
  7266. "3140f94c79f249787d1ec75a97a885980eb8f0a7d9b7aa03e7200296e422b2b6",
  7267. "57a70eb553a7b3fd621f0dba6abf51312ea2e2a2a1e19d0305516730f4bcbd21",
  7268. "d9c0d386636c8a024935c024589f9cd39e820a16485b14951e690a967830e269",
  7269. "f2e9f18aeb374965f54d2f4e31189a8f",
  7270. "86ddb9e713a8ebf67a51830eff03b837e147c20d75e67b2a54aa29e98c",
  7271. "33d97c216ea6498dfddabf94c2e2403d73efc495e9b284d9d90aaff840217d25",
  7272. },
  7273. {
  7274. "d5c0762ecea2cd6b5c56751b58debcb32713aab348f4a59c493e38beb3244f3a",
  7275. "66a35941d615b5644d19c2a602c363ada8b1a8a0dac3682623852dcab4afac04",
  7276. "06c227baac1ae3b0b1dc583f4850f13f9ba5d53be4a98fa5c3ea16217847530d",
  7277. "3735123e78c44895df6ea33fa57e9a72",
  7278. "86ddb9e713a8ebf67a51830eff03b837e147c20d75e67b2a54aa29e98c",
  7279. "d5b5d66ba8cee0eb7ecf95b143fa77a46d6de13749e12eff40f5a7e649167ccb",
  7280. },
  7281. {
  7282. "d5c0762ecea2cd6b5c56751b58debcb32713aab348f4a59c493e38beb3244f3a",
  7283. "66a35941d615b5644d19c2a602c363ada8b1a8a0dac3682623852dcab4afac04",
  7284. "92f55ba5bc6fc2f23e3eedc299357c71518e36ba2447a4da7a9dfe9dfeb107b5",
  7285. "1cbc4982e53e370052af97ab088fa942",
  7286. "86ddb9e713a8ebf67a51830eff03b837e147c20d75e67b2a54aa29e98c",
  7287. "d48ef1ef526d805656cfc932aff259eadb17aa3391dde1877a722cba31d935b2",
  7288. },
  7289. {
  7290. "d5c0762ecea2cd6b5c56751b58debcb32713aab348f4a59c493e38beb3244f3a",
  7291. "66a35941d615b5644d19c2a602c363ada8b1a8a0dac3682623852dcab4afac04",
  7292. "10f15a39ba49866292a43b7781bc71ca8bbd4889f1616461caf056bcb91b0158",
  7293. "c40d531d92bfee969dce91417346c892",
  7294. "49de3cd5890e0cd0559f143807ff688ff62789b7236a332b7d7255ec0b4e73e6b3a"
  7295. "4",
  7296. "e6d75afdb542785669b42198577c5b358d95397d71ec6f5835dca46d332cc08dbf73"
  7297. "ea790b7bcb169a65719c0d55054c",
  7298. },
  7299. {
  7300. "d5c0762ecea2cd6b5c56751b58debcb32713aab348f4a59c493e38beb3244f3a",
  7301. "66a35941d615b5644d19c2a602c363ada8b1a8a0dac3682623852dcab4afac04",
  7302. "9c01ed42b219b3bbe1a43ae9d7af5c1dd09363baacfdba8f4d03d1046915e26e",
  7303. "059a35d5f83249e632790015ed6518b9",
  7304. "49de3cd5890e0cd0559f143807ff688ff62789b7236a332b7d7255ec0b4e73e6b3a"
  7305. "4",
  7306. "5ef11aadff2eccee8b712dab968fa842eb770818ec0e6663ed242ea8b6bbc1c66d62"
  7307. "85ee5b5f03d55dfee382fb4fa25d",
  7308. },
  7309. {
  7310. "d5c0762ecea2cd6b5c56751b58debcb32713aab348f4a59c493e38beb3244f3a",
  7311. "66a35941d615b5644d19c2a602c363ada8b1a8a0dac3682623852dcab4afac04",
  7312. "bc1067e2a7415ea45ff1ca9894338c591ff15f2e57ae2789ae31b9d5bea0f11e",
  7313. "8c73f0d6613898daeefa3cf8b0686d37",
  7314. "49de3cd5890e0cd0559f143807ff688ff62789b7236a332b7d7255ec0b4e73e6b3a"
  7315. "4",
  7316. "6d220213b1878cd40a458f2a1e6e3b48040455fdf504dcd857f4f2ca1ad642e3a44f"
  7317. "c401d04e339d302f66a9fad3d919",
  7318. },
  7319. {
  7320. "9ef87ba8aa2e664bdfdb978b98bc30fb61773d9298e7b8c72911683eeff41921",
  7321. "441e76d7e53be0a967181076a842f69c20fd8c0e3f0ce3aa421b490b059fe094",
  7322. "cf4a21cb790552165827b678ca9695fcaf77566d382325112ff79483455de667",
  7323. "bfbf5482e06f55b88bdd9e053b7eee6e",
  7324. "49de3cd5890e0cd0559f143807ff688ff62789b7236a332b7d7255ec0b4e73e6b3a"
  7325. "4",
  7326. "1198a78c29c215d5c450f7b8513ead253160bc9fde80d9cc8e6bee2efe9713cf5a09"
  7327. "d6293c41033271c9e8c22036a28b",
  7328. },
  7329. {
  7330. "9ef87ba8aa2e664bdfdb978b98bc30fb61773d9298e7b8c72911683eeff41921",
  7331. "441e76d7e53be0a967181076a842f69c20fd8c0e3f0ce3aa421b490b059fe094",
  7332. "eba5eae8aef79114082c3e70baef95bb02edf13b3897e8be7a70272962ef8838",
  7333. "af9a56da3da18e2fbd2948a16332532b",
  7334. "49de3cd5890e0cd0559f143807ff688ff62789b7236a332b7d7255ec0b4e73e6b3a"
  7335. "4",
  7336. "1062ab5fbbdee9042ad35bdadfd3047c0a2127fe0f001da1be1b0582185edfc9687b"
  7337. "e8d68f85795833bb04af9cedd3bb",
  7338. },
  7339. {
  7340. "9ef87ba8aa2e664bdfdb978b98bc30fb61773d9298e7b8c72911683eeff41921",
  7341. "441e76d7e53be0a967181076a842f69c20fd8c0e3f0ce3aa421b490b059fe094",
  7342. "518f8dfd0c138f1ffb4ea8029db15441d70abd893c3d767dc668f23ba7770e27",
  7343. "42d28307974a1b2a2d921d270cfce03b",
  7344. "49de3cd5890e0cd0559f143807ff688ff62789b7236a332b7d7255ec0b4e73e6b3a"
  7345. "4",
  7346. "005e49fb7c5da540a84b034c853fc9f78a6b901ea495aed0c2abd4f08f1a96f9ffef"
  7347. "c6a57f1ac09e0aea95ca0f03ffd8",
  7348. },
  7349. {
  7350. "9ef87ba8aa2e664bdfdb978b98bc30fb61773d9298e7b8c72911683eeff41921",
  7351. "441e76d7e53be0a967181076a842f69c20fd8c0e3f0ce3aa421b490b059fe094",
  7352. "582fdf58b53715c26e10ba809e8f2ab70502e5a3d4e9a81100b7227732ab0bbc",
  7353. "91f2aad3189bb2edc93bc891e73911ba",
  7354. "49de3cd5890e0cd0559f143807ff688ff62789b7236a332b7d7255ec0b4e73e6b3a"
  7355. "4",
  7356. "821a69cb16c57f0cb866e590b38069e35faec3ae18f158bb067db83a11237d29ab1e"
  7357. "6b868b3147236a0958f15c2e2167",
  7358. },
  7359. {
  7360. "9ef87ba8aa2e664bdfdb978b98bc30fb61773d9298e7b8c72911683eeff41921",
  7361. "441e76d7e53be0a967181076a842f69c20fd8c0e3f0ce3aa421b490b059fe094",
  7362. "a415b4c006118fb72fc37b2746ef288e23ac45c8ff7ade5f368a31557b6ac93a",
  7363. "2b7c5f75606c0b8106c6489ea5657a9e",
  7364. "24512b714aefd5cbc4bcc4ef44ce6c67ffc447c65460a6c6e4a92e85",
  7365. "2781d5ee8ef1cb1596f8902b33dfae5045f84a987ca58173af5830dbce386062",
  7366. },
  7367. {
  7368. "ed93c5a101ab53382ceee4f7e6b5aa112621d3bb9d18891509b1834ede235bcc",
  7369. "5a5e14c633d7d269302849d739d80344ff14db51d7bcda86045723f05c4e4541",
  7370. "47e73ec362ea82d3a7c5d55532ad51d2cdf5316b981b2b2bd542b0efa027e8ea",
  7371. "b2193f59030c8d05a7d3577b7f64dd33",
  7372. "24512b714aefd5cbc4bcc4ef44ce6c67ffc447c65460a6c6e4a92e85",
  7373. "3f43912db8dd6672b9996e5272e18c4b88fec9d7e8372db9c5f4709a4af1d86f",
  7374. },
  7375. {
  7376. "ed93c5a101ab53382ceee4f7e6b5aa112621d3bb9d18891509b1834ede235bcc",
  7377. "5a5e14c633d7d269302849d739d80344ff14db51d7bcda86045723f05c4e4541",
  7378. "aaa006c57b6d1e402650577fe9787d8d285f4bacd7c01f998be49c766f8860c7",
  7379. "130304ddb9adc8870cf56bcae9487b7f",
  7380. "24512b714aefd5cbc4bcc4ef44ce6c67ffc447c65460a6c6e4a92e85",
  7381. "878cc7d8c0ef8dac0182a78eedc8080a402f59d8062a6b4ca8f4a74f3c3b3de7",
  7382. },
  7383. {
  7384. "ed93c5a101ab53382ceee4f7e6b5aa112621d3bb9d18891509b1834ede235bcc",
  7385. "5a5e14c633d7d269302849d739d80344ff14db51d7bcda86045723f05c4e4541",
  7386. "28dc7ccd6c2a939eef64b8be7b9ae248295e7fcd8471c22fa2f98733fea97611",
  7387. "cb13890d3a11bc0a7433738263006710",
  7388. "24512b714aefd5cbc4bcc4ef44ce6c67ffc447c65460a6c6e4a92e85",
  7389. "e74ded846bebfa912fa1720e4c1415e6e5df7e7a1a7fedb5665d68f1763209a4",
  7390. },
  7391. {
  7392. "ed93c5a101ab53382ceee4f7e6b5aa112621d3bb9d18891509b1834ede235bcc",
  7393. "5a5e14c633d7d269302849d739d80344ff14db51d7bcda86045723f05c4e4541",
  7394. "79974fa2cad95154d0873902c153ccc3e7d54b17f2eeb3f29b6344cad9365a9a",
  7395. "22123357979d20f44cc8eb0263d84e0e",
  7396. "24512b714aefd5cbc4bcc4ef44ce6c67ffc447c65460a6c6e4a92e85",
  7397. "eb14dec7b8b64d81a2ee4db07b0adf144d4f79a519bbf332b823583fa2d45405",
  7398. },
  7399. {
  7400. "ed93c5a101ab53382ceee4f7e6b5aa112621d3bb9d18891509b1834ede235bcc",
  7401. "5a5e14c633d7d269302849d739d80344ff14db51d7bcda86045723f05c4e4541",
  7402. "3409a6f8c4dcd9bd04144eb67e55a98696b674735b01bf1196191f29871ef966",
  7403. "a823a0965969380ea1f8659ea5fd8fdd",
  7404. "24512b714aefd5cbc4bcc4ef44ce6c67ffc447c65460a6c6e4a92e85",
  7405. "00a7eb708eae745847173f8217efb05be13059710aee632e3f471ac3c6202b51",
  7406. },
  7407. {
  7408. "a73a0b2686f7d699c018b6b08a352856e556070caa329c26241aec889eefde10",
  7409. "9b493403bee45ae6277430ef8d0c4163ffd81ace2db6c7821205da09a664a86c",
  7410. "c25701b9b7328c4ac3d23223d10623bd527c0a98e38ae9c62fbc403c80ab20ae",
  7411. "4b4ee0e4443779f3af429a749212f476",
  7412. "b6926d0ec82cec86c0d27ec9a33a0e0f",
  7413. "f39f7d66e0fde39ecdf58be2c0ef361a17cfd6843e310adbe0ec3118cd72800d",
  7414. },
  7415. {
  7416. "a73a0b2686f7d699c018b6b08a352856e556070caa329c26241aec889eefde10",
  7417. "9b493403bee45ae6277430ef8d0c4163ffd81ace2db6c7821205da09a664a86c",
  7418. "31d18fdffc480310828778496ff817039df5d6f30bf6d9edd0b4396863d05f93",
  7419. "418bcbdf52860a450bfacc96920d02cf",
  7420. "b6926d0ec82cec86c0d27ec9a33a0e0f",
  7421. "0e6ce9889fe7b3cd82794b0ae27c1f5985d2f2a1f398371a138f8db1df1f54de",
  7422. },
  7423. {
  7424. "e2e4dee102fad0f47f60202269605589cd9cf70f816b34016796c74b766f3041",
  7425. "c5ce283033a3255ae14d42dff1e4c18a224ac79d084b285123421b105ee654c9",
  7426. "56b4c645f81dbfb6ba0c6d3f1626e1e5cd648eeb36562715f7cd7e9ea86a0d7f",
  7427. "dc9bdce76d68d2e4d72267cf4e72b022",
  7428. "b6926d0ec82cec86c0d27ec9a33a0e0f",
  7429. "dc6f046c3008002041517a7c4f3ababe609cf02616fcccda39c075d1be4175f5",
  7430. },
  7431. {
  7432. "e2e4dee102fad0f47f60202269605589cd9cf70f816b34016796c74b766f3041",
  7433. "c5ce283033a3255ae14d42dff1e4c18a224ac79d084b285123421b105ee654c9",
  7434. "df180b91986c8c7000792f96d1faa61e30138330430a402322be1855089b0e7f",
  7435. "ccf9b77341c866465b474e2f4a3b1cf8",
  7436. "b6926d0ec82cec86c0d27ec9a33a0e0f",
  7437. "94e4ae89041437f39826704f02cb5d775226f34344635e592846417497a5020b",
  7438. },
  7439. {
  7440. "e2e4dee102fad0f47f60202269605589cd9cf70f816b34016796c74b766f3041",
  7441. "c5ce283033a3255ae14d42dff1e4c18a224ac79d084b285123421b105ee654c9",
  7442. "a0eee7e84c76e63fdae6e938b43330775eaf17d260e40b98c9e6616b668102a7",
  7443. "662c681cfec6f6d052ff0e2c1255f2c2",
  7444. "b6926d0ec82cec86c0d27ec9a33a0e0f",
  7445. "70bba3c48be9c75a144b1888ca3d21a6b21f52eec133981a024390a6a0ba36f9",
  7446. },
  7447. {
  7448. "e2e4dee102fad0f47f60202269605589cd9cf70f816b34016796c74b766f3041",
  7449. "c5ce283033a3255ae14d42dff1e4c18a224ac79d084b285123421b105ee654c9",
  7450. "c6acd2d90eb782c3053b366680ffa0e148de81fea198c87bb643869fd97e5cb0",
  7451. "908dc33ba80520f2f0f04e7890e3a3c0",
  7452. "b6926d0ec82cec86c0d27ec9a33a0e0f",
  7453. "f6efe1d76d270aac264aa35d03049d9ce63be1996d543aef00559219c8666f71",
  7454. },
  7455. };
  7456. HDNode node;
  7457. ed25519_secret_key private_key;
  7458. uint8_t chain_code[32];
  7459. ed25519_public_key public_key;
  7460. uint8_t salt[sizeof(public_key)];
  7461. uint8_t iv[AES_BLOCK_SIZE];
  7462. uint8_t buffer[FROMHEX_MAXLEN];
  7463. uint8_t input[FROMHEX_MAXLEN];
  7464. uint8_t output[FROMHEX_MAXLEN];
  7465. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  7466. nem_private_key(tests[i].private_key, private_key);
  7467. ck_assert(hdnode_from_xprv(0, 0, chain_code, private_key,
  7468. ED25519_KECCAK_NAME, &node));
  7469. memcpy(public_key, fromhex(tests[i].public_key), 32);
  7470. memcpy(salt, fromhex(tests[i].salt), sizeof(salt));
  7471. size_t input_size = strlen(tests[i].input) / 2;
  7472. size_t output_size = strlen(tests[i].output) / 2;
  7473. memcpy(input, fromhex(tests[i].input), input_size);
  7474. memcpy(output, fromhex(tests[i].output), output_size);
  7475. memcpy(iv, fromhex(tests[i].iv), sizeof(iv));
  7476. ck_assert(hdnode_nem_encrypt(&node, public_key, iv, salt, input, input_size,
  7477. buffer));
  7478. ck_assert_uint_eq(output_size, NEM_ENCRYPTED_SIZE(input_size));
  7479. ck_assert_mem_eq(buffer, output, output_size);
  7480. memcpy(iv, fromhex(tests[i].iv), sizeof(iv));
  7481. ck_assert(hdnode_nem_decrypt(&node, public_key, iv, salt, output,
  7482. output_size, buffer));
  7483. ck_assert_uint_eq(input_size, NEM_DECRYPTED_SIZE(buffer, output_size));
  7484. ck_assert_mem_eq(buffer, input, input_size);
  7485. }
  7486. }
  7487. END_TEST
  7488. START_TEST(test_nem_transaction_transfer) {
  7489. nem_transaction_ctx ctx;
  7490. uint8_t buffer[1024], hash[SHA3_256_DIGEST_LENGTH];
  7491. // http://bob.nem.ninja:8765/#/transfer/0acbf8df91e6a65dc56c56c43d65f31ff2a6a48d06fc66e78c7f3436faf3e74f
  7492. nem_transaction_start(
  7493. &ctx,
  7494. fromhex(
  7495. "e59ef184a612d4c3c4d89b5950eb57262c69862b2f96e59c5043bf41765c482f"),
  7496. buffer, sizeof(buffer));
  7497. ck_assert(nem_transaction_create_transfer(
  7498. &ctx, NEM_NETWORK_TESTNET, 0, NULL, 0, 0,
  7499. "TBGIMRE4SBFRUJXMH7DVF2IBY36L2EDWZ37GVSC4", 50000000000000, NULL, 0,
  7500. false, 0));
  7501. keccak_256(ctx.buffer, ctx.offset, hash);
  7502. ck_assert_mem_eq(
  7503. hash,
  7504. fromhex(
  7505. "0acbf8df91e6a65dc56c56c43d65f31ff2a6a48d06fc66e78c7f3436faf3e74f"),
  7506. sizeof(hash));
  7507. // http://bob.nem.ninja:8765/#/transfer/3409d9ece28d6296d6d5e220a7e3cb8641a3fb235ffcbd20c95da64f003ace6c
  7508. nem_transaction_start(
  7509. &ctx,
  7510. fromhex(
  7511. "994793ba1c789fa9bdea918afc9b06e2d0309beb1081ac5b6952991e4defd324"),
  7512. buffer, sizeof(buffer));
  7513. ck_assert(nem_transaction_create_transfer(
  7514. &ctx, NEM_NETWORK_TESTNET, 14072100, NULL, 194000000, 14075700,
  7515. "TBLOODPLWOWMZ2TARX4RFPOSOWLULHXMROBN2WXI", 3000000,
  7516. (uint8_t *)"sending you 3 pairs of paddles\n", 31, false, 2));
  7517. ck_assert(
  7518. nem_transaction_write_mosaic(&ctx, "gimre.games.pong", "paddles", 2));
  7519. ck_assert(nem_transaction_write_mosaic(&ctx, "nem", "xem", 44000000));
  7520. keccak_256(ctx.buffer, ctx.offset, hash);
  7521. ck_assert_mem_eq(
  7522. hash,
  7523. fromhex(
  7524. "3409d9ece28d6296d6d5e220a7e3cb8641a3fb235ffcbd20c95da64f003ace6c"),
  7525. sizeof(hash));
  7526. // http://chain.nem.ninja/#/transfer/e90e98614c7598fbfa4db5411db1b331d157c2f86b558fb7c943d013ed9f71cb
  7527. nem_transaction_start(
  7528. &ctx,
  7529. fromhex(
  7530. "8d07f90fb4bbe7715fa327c926770166a11be2e494a970605f2e12557f66c9b9"),
  7531. buffer, sizeof(buffer));
  7532. ck_assert(nem_transaction_create_transfer(
  7533. &ctx, NEM_NETWORK_MAINNET, 0, NULL, 0, 0,
  7534. "NBT3WHA2YXG2IR4PWKFFMO772JWOITTD2V4PECSB", 5175000000000,
  7535. (uint8_t *)"Good luck!", 10, false, 0));
  7536. keccak_256(ctx.buffer, ctx.offset, hash);
  7537. ck_assert_mem_eq(
  7538. hash,
  7539. fromhex(
  7540. "e90e98614c7598fbfa4db5411db1b331d157c2f86b558fb7c943d013ed9f71cb"),
  7541. sizeof(hash));
  7542. // http://chain.nem.ninja/#/transfer/40e89160e6f83d37f7c82defc0afe2c1605ae8c919134570a51dd27ea1bb516c
  7543. nem_transaction_start(
  7544. &ctx,
  7545. fromhex(
  7546. "f85ab43dad059b9d2331ddacc384ad925d3467f03207182e01296bacfb242d01"),
  7547. buffer, sizeof(buffer));
  7548. ck_assert(nem_transaction_create_transfer(
  7549. &ctx, NEM_NETWORK_MAINNET, 77229, NULL, 30000000, 80829,
  7550. "NALICEPFLZQRZGPRIJTMJOCPWDNECXTNNG7QLSG3", 30000000,
  7551. fromhex("4d9dcf9186967d30be93d6d5404ded22812dbbae7c3f0de5"
  7552. "01bcd7228cba45bded13000eec7b4c6215fc4d3588168c92"
  7553. "18167cec98e6977359153a4132e050f594548e61e0dc61c1"
  7554. "53f0f53c5e65c595239c9eb7c4e7d48e0f4bb8b1dd2f5ddc"),
  7555. 96, true, 0));
  7556. keccak_256(ctx.buffer, ctx.offset, hash);
  7557. ck_assert_mem_eq(
  7558. hash,
  7559. fromhex(
  7560. "40e89160e6f83d37f7c82defc0afe2c1605ae8c919134570a51dd27ea1bb516c"),
  7561. sizeof(hash));
  7562. // http://chain.nem.ninja/#/transfer/882dca18dcbe075e15e0ec5a1d7e6ccd69cc0f1309ffd3fde227bfbc107b3f6e
  7563. nem_transaction_start(
  7564. &ctx,
  7565. fromhex(
  7566. "f85ab43dad059b9d2331ddacc384ad925d3467f03207182e01296bacfb242d01"),
  7567. buffer, sizeof(buffer));
  7568. ck_assert(nem_transaction_create_transfer(
  7569. &ctx, NEM_NETWORK_MAINNET, 26730750, NULL, 179500000, 26734350,
  7570. "NBE223WPKEBHQPCYUC4U4CDUQCRRFMPZLOQLB5OP", 1000000,
  7571. (uint8_t *)"enjoy! :)", 9, false, 1));
  7572. ck_assert(nem_transaction_write_mosaic(&ctx, "imre.g", "tokens", 1));
  7573. keccak_256(ctx.buffer, ctx.offset, hash);
  7574. ck_assert_mem_eq(
  7575. hash,
  7576. fromhex(
  7577. "882dca18dcbe075e15e0ec5a1d7e6ccd69cc0f1309ffd3fde227bfbc107b3f6e"),
  7578. sizeof(hash));
  7579. }
  7580. END_TEST
  7581. START_TEST(test_nem_transaction_multisig) {
  7582. nem_transaction_ctx ctx, other_trans;
  7583. uint8_t buffer[1024], inner[1024];
  7584. const uint8_t *signature;
  7585. // http://bob.nem.ninja:8765/#/multisig/7d3a7087023ee29005262016706818579a2b5499eb9ca76bad98c1e6f4c46642
  7586. nem_transaction_start(
  7587. &other_trans,
  7588. fromhex(
  7589. "abac2ee3d4aaa7a3bfb65261a00cc04c761521527dd3f2cf741e2815cbba83ac"),
  7590. inner, sizeof(inner));
  7591. ck_assert(nem_transaction_create_aggregate_modification(
  7592. &other_trans, NEM_NETWORK_TESTNET, 3939039, NULL, 16000000, 3960639, 1,
  7593. false));
  7594. ck_assert(nem_transaction_write_cosignatory_modification(
  7595. &other_trans, 2,
  7596. fromhex(
  7597. "e6cff9b3725a91f31089c3acca0fac3e341c00b1c8c6e9578f66c4514509c3b3")));
  7598. nem_transaction_start(
  7599. &ctx,
  7600. fromhex(
  7601. "59d89076964742ef2a2089d26a5aa1d2c7a7bb052a46c1de159891e91ad3d76e"),
  7602. buffer, sizeof(buffer));
  7603. ck_assert(nem_transaction_create_multisig(&ctx, NEM_NETWORK_TESTNET, 3939039,
  7604. NULL, 6000000, 3960639,
  7605. &other_trans));
  7606. signature = fromhex(
  7607. "933930a8828b560168bddb3137df9252048678d829aa5135fa27bb306ff6562efb927554"
  7608. "62988b852b0314bde058487d00e47816b6fb7df6bcfd7e1f150d1d00");
  7609. ck_assert_int_eq(ed25519_sign_open_keccak(ctx.buffer, ctx.offset,
  7610. ctx.public_key, signature),
  7611. 0);
  7612. nem_transaction_start(
  7613. &ctx,
  7614. fromhex(
  7615. "71cba4f2a28fd19f902ba40e9937994154d9eeaad0631d25d525ec37922567d4"),
  7616. buffer, sizeof(buffer));
  7617. ck_assert(nem_transaction_create_multisig_signature(&ctx, NEM_NETWORK_TESTNET,
  7618. 3939891, NULL, 6000000,
  7619. 3961491, &other_trans));
  7620. signature = fromhex(
  7621. "a849f13bfeeba808a8a4a79d579febe584d831a3a6ad03da3b9d008530b3d7a79fcf7156"
  7622. "121cd7ee847029d94af7ea7a683ca8e643dc5e5f489557c2054b830b");
  7623. ck_assert_int_eq(ed25519_sign_open_keccak(ctx.buffer, ctx.offset,
  7624. ctx.public_key, signature),
  7625. 0);
  7626. // http://chain.nem.ninja/#/multisig/1016cf3bdd61bd57b9b2b07b6ff2dee390279d8d899265bdc23d42360abe2e6c
  7627. nem_transaction_start(
  7628. &other_trans,
  7629. fromhex(
  7630. "a1df5306355766bd2f9a64efdc089eb294be265987b3359093ae474c051d7d5a"),
  7631. inner, sizeof(inner));
  7632. ck_assert(nem_transaction_create_provision_namespace(
  7633. &other_trans, NEM_NETWORK_MAINNET, 59414272, NULL, 20000000, 59500672,
  7634. "dim", NULL, "NAMESPACEWH4MKFMBCVFERDPOOP4FK7MTBXDPZZA", 5000000000));
  7635. nem_transaction_start(
  7636. &ctx,
  7637. fromhex(
  7638. "cfe58463f0eaebceb5d00717f8aead49171a5d7c08f6b1299bd534f11715acc9"),
  7639. buffer, sizeof(buffer));
  7640. ck_assert(nem_transaction_create_multisig(&ctx, NEM_NETWORK_MAINNET, 59414272,
  7641. NULL, 6000000, 59500672,
  7642. &other_trans));
  7643. signature = fromhex(
  7644. "52a876a37511068fe214bd710b2284823921ec7318c01e083419a062eae5369c9c11c3ab"
  7645. "fdb590f65c717fab82873431d52be62e10338cb5656d1833bbdac70c");
  7646. ck_assert_int_eq(ed25519_sign_open_keccak(ctx.buffer, ctx.offset,
  7647. ctx.public_key, signature),
  7648. 0);
  7649. nem_transaction_start(
  7650. &ctx,
  7651. fromhex(
  7652. "1b49b80203007117d034e45234ffcdf402c044aeef6dbb06351f346ca892bce2"),
  7653. buffer, sizeof(buffer));
  7654. ck_assert(nem_transaction_create_multisig_signature(&ctx, NEM_NETWORK_MAINNET,
  7655. 59414342, NULL, 6000000,
  7656. 59500742, &other_trans));
  7657. signature = fromhex(
  7658. "b9a59239e5d06992c28840034ff7a7f13da9c4e6f4a6f72c1b1806c3b602f83a7d727a34"
  7659. "5371f5d15abf958208a32359c6dd77bde92273ada8ea6fda3dc76b00");
  7660. ck_assert_int_eq(ed25519_sign_open_keccak(ctx.buffer, ctx.offset,
  7661. ctx.public_key, signature),
  7662. 0);
  7663. nem_transaction_start(
  7664. &ctx,
  7665. fromhex(
  7666. "7ba4b39209f1b9846b098fe43f74381e43cb2882ccde780f558a63355840aa87"),
  7667. buffer, sizeof(buffer));
  7668. ck_assert(nem_transaction_create_multisig_signature(&ctx, NEM_NETWORK_MAINNET,
  7669. 59414381, NULL, 6000000,
  7670. 59500781, &other_trans));
  7671. signature = fromhex(
  7672. "e874ae9f069f0538008631d2df9f2e8a59944ff182e8672f743d2700fb99224aafb7a0ab"
  7673. "09c4e9ea39ee7c8ca04a8a3d6103ae1122d87772e871761d4f00ca01");
  7674. ck_assert_int_eq(ed25519_sign_open_keccak(ctx.buffer, ctx.offset,
  7675. ctx.public_key, signature),
  7676. 0);
  7677. }
  7678. END_TEST
  7679. START_TEST(test_nem_transaction_provision_namespace) {
  7680. nem_transaction_ctx ctx;
  7681. uint8_t buffer[1024], hash[SHA3_256_DIGEST_LENGTH];
  7682. // http://bob.nem.ninja:8765/#/namespace/f7cab28da57204d01a907c697836577a4ae755e6c9bac60dcc318494a22debb3
  7683. nem_transaction_start(
  7684. &ctx,
  7685. fromhex(
  7686. "84afa1bbc993b7f5536344914dde86141e61f8cbecaf8c9cefc07391f3287cf5"),
  7687. buffer, sizeof(buffer));
  7688. ck_assert(nem_transaction_create_provision_namespace(
  7689. &ctx, NEM_NETWORK_TESTNET, 56999445, NULL, 20000000, 57003045, "gimre",
  7690. NULL, "TAMESPACEWH4MKFMBCVFERDPOOP4FK7MTDJEYP35", 5000000000));
  7691. keccak_256(ctx.buffer, ctx.offset, hash);
  7692. ck_assert_mem_eq(
  7693. hash,
  7694. fromhex(
  7695. "f7cab28da57204d01a907c697836577a4ae755e6c9bac60dcc318494a22debb3"),
  7696. sizeof(hash));
  7697. // http://bob.nem.ninja:8765/#/namespace/7ddd5fe607e1bfb5606e0ac576024c318c8300d237273117d4db32a60c49524d
  7698. nem_transaction_start(
  7699. &ctx,
  7700. fromhex(
  7701. "244fa194e2509ac0d2fbc18779c2618d8c2ebb61c16a3bcbebcf448c661ba8dc"),
  7702. buffer, sizeof(buffer));
  7703. ck_assert(nem_transaction_create_provision_namespace(
  7704. &ctx, NEM_NETWORK_TESTNET, 21496797, NULL, 108000000, 21500397, "misc",
  7705. "alice", "TAMESPACEWH4MKFMBCVFERDPOOP4FK7MTDJEYP35", 5000000000));
  7706. keccak_256(ctx.buffer, ctx.offset, hash);
  7707. ck_assert_mem_eq(
  7708. hash,
  7709. fromhex(
  7710. "7ddd5fe607e1bfb5606e0ac576024c318c8300d237273117d4db32a60c49524d"),
  7711. sizeof(hash));
  7712. // http://chain.nem.ninja/#/namespace/57071aad93ca125dc231dc02c07ad8610cd243d35068f9b36a7d231383907569
  7713. nem_transaction_start(
  7714. &ctx,
  7715. fromhex(
  7716. "9f3c14f304309c8b72b2821339c4428793b1518bea72d58dd01f19d523518614"),
  7717. buffer, sizeof(buffer));
  7718. ck_assert(nem_transaction_create_provision_namespace(
  7719. &ctx, NEM_NETWORK_MAINNET, 26699717, NULL, 108000000, 26703317, "sex",
  7720. NULL, "NAMESPACEWH4MKFMBCVFERDPOOP4FK7MTBXDPZZA", 50000000000));
  7721. keccak_256(ctx.buffer, ctx.offset, hash);
  7722. ck_assert_mem_eq(
  7723. hash,
  7724. fromhex(
  7725. "57071aad93ca125dc231dc02c07ad8610cd243d35068f9b36a7d231383907569"),
  7726. sizeof(hash));
  7727. }
  7728. END_TEST
  7729. START_TEST(test_nem_transaction_mosaic_creation) {
  7730. nem_transaction_ctx ctx;
  7731. uint8_t buffer[1024], hash[SHA3_256_DIGEST_LENGTH];
  7732. // http://bob.nem.ninja:8765/#/mosaic/68364353c29105e6d361ad1a42abbccbf419cfc7adb8b74c8f35d8f8bdaca3fa/0
  7733. nem_transaction_start(
  7734. &ctx,
  7735. fromhex(
  7736. "994793ba1c789fa9bdea918afc9b06e2d0309beb1081ac5b6952991e4defd324"),
  7737. buffer, sizeof(buffer));
  7738. ck_assert(nem_transaction_create_mosaic_creation(
  7739. &ctx, NEM_NETWORK_TESTNET, 14070896, NULL, 108000000, 14074496,
  7740. "gimre.games.pong", "paddles", "Paddles for the bong game.\n", 0, 10000,
  7741. true, true, 0, 0, NULL, NULL, NULL,
  7742. "TBMOSAICOD4F54EE5CDMR23CCBGOAM2XSJBR5OLC", 50000000000));
  7743. keccak_256(ctx.buffer, ctx.offset, hash);
  7744. ck_assert_mem_eq(
  7745. hash,
  7746. fromhex(
  7747. "68364353c29105e6d361ad1a42abbccbf419cfc7adb8b74c8f35d8f8bdaca3fa"),
  7748. sizeof(hash));
  7749. // http://bob.nem.ninja:8765/#/mosaic/b2f4a98113ff1f3a8f1e9d7197aa982545297fe0aa3fa6094af8031569953a55/0
  7750. nem_transaction_start(
  7751. &ctx,
  7752. fromhex(
  7753. "244fa194e2509ac0d2fbc18779c2618d8c2ebb61c16a3bcbebcf448c661ba8dc"),
  7754. buffer, sizeof(buffer));
  7755. ck_assert(nem_transaction_create_mosaic_creation(
  7756. &ctx, NEM_NETWORK_TESTNET, 21497248, NULL, 108000000, 21500848,
  7757. "alice.misc", "bar", "Special offer: get one bar extra by bying one foo!",
  7758. 0, 1000, false, true, 1, 1, "TALICE2GMA34CXHD7XLJQ536NM5UNKQHTORNNT2J",
  7759. "nem", "xem", "TBMOSAICOD4F54EE5CDMR23CCBGOAM2XSJBR5OLC", 50000000000));
  7760. keccak_256(ctx.buffer, ctx.offset, hash);
  7761. ck_assert_mem_eq(
  7762. hash,
  7763. fromhex(
  7764. "b2f4a98113ff1f3a8f1e9d7197aa982545297fe0aa3fa6094af8031569953a55"),
  7765. sizeof(hash));
  7766. // http://chain.nem.ninja/#/mosaic/269c6fda657aba3053a0e5b138c075808cc20e244e1182d9b730798b60a1f77b/0
  7767. nem_transaction_start(
  7768. &ctx,
  7769. fromhex(
  7770. "58956ac77951622dc5f1c938affbf017c458e30e6b21ddb5783d38b302531f23"),
  7771. buffer, sizeof(buffer));
  7772. ck_assert(nem_transaction_create_mosaic_creation(
  7773. &ctx, NEM_NETWORK_MAINNET, 26729938, NULL, 108000000, 26733538, "jabo38",
  7774. "red_token",
  7775. "This token is to celebrate the release of Namespaces and Mosaics on the "
  7776. "NEM system. "
  7777. "This token was the fist ever mosaic created other than nem.xem. "
  7778. "There are only 10,000 Red Tokens that will ever be created. "
  7779. "It has no levy and can be traded freely among third parties.",
  7780. 2, 10000, false, true, 0, 0, NULL, NULL, NULL,
  7781. "NBMOSAICOD4F54EE5CDMR23CCBGOAM2XSIUX6TRS", 50000000000));
  7782. keccak_256(ctx.buffer, ctx.offset, hash);
  7783. ck_assert_mem_eq(
  7784. hash,
  7785. fromhex(
  7786. "269c6fda657aba3053a0e5b138c075808cc20e244e1182d9b730798b60a1f77b"),
  7787. sizeof(hash));
  7788. // http://chain.nem.ninja/#/mosaic/e8dc14821dbea4831d9051f86158ef348001447968fc22c01644fdaf2bda75c6/0
  7789. nem_transaction_start(
  7790. &ctx,
  7791. fromhex(
  7792. "a1df5306355766bd2f9a64efdc089eb294be265987b3359093ae474c051d7d5a"),
  7793. buffer, sizeof(buffer));
  7794. ck_assert(nem_transaction_create_mosaic_creation(
  7795. &ctx, NEM_NETWORK_MAINNET, 69251020, NULL, 20000000, 69337420, "dim",
  7796. "coin", "DIM COIN", 6, 9000000000, false, true, 2, 10,
  7797. "NCGGLVO2G3CUACVI5GNX2KRBJSQCN4RDL2ZWJ4DP", "dim", "coin",
  7798. "NBMOSAICOD4F54EE5CDMR23CCBGOAM2XSIUX6TRS", 500000000));
  7799. keccak_256(ctx.buffer, ctx.offset, hash);
  7800. ck_assert_mem_eq(
  7801. hash,
  7802. fromhex(
  7803. "e8dc14821dbea4831d9051f86158ef348001447968fc22c01644fdaf2bda75c6"),
  7804. sizeof(hash));
  7805. }
  7806. END_TEST
  7807. START_TEST(test_nem_transaction_mosaic_supply_change) {
  7808. nem_transaction_ctx ctx;
  7809. uint8_t buffer[1024], hash[SHA3_256_DIGEST_LENGTH];
  7810. // http://bigalice2.nem.ninja:7890/transaction/get?hash=33a50fdd4a54913643a580b2af08b9a5b51b7cee922bde380e84c573a7969c50
  7811. nem_transaction_start(
  7812. &ctx,
  7813. fromhex(
  7814. "994793ba1c789fa9bdea918afc9b06e2d0309beb1081ac5b6952991e4defd324"),
  7815. buffer, sizeof(buffer));
  7816. ck_assert(nem_transaction_create_mosaic_supply_change(
  7817. &ctx, NEM_NETWORK_TESTNET, 14071648, NULL, 108000000, 14075248,
  7818. "gimre.games.pong", "paddles", 1, 1234));
  7819. keccak_256(ctx.buffer, ctx.offset, hash);
  7820. ck_assert_mem_eq(
  7821. hash,
  7822. fromhex(
  7823. "33a50fdd4a54913643a580b2af08b9a5b51b7cee922bde380e84c573a7969c50"),
  7824. sizeof(hash));
  7825. // http://bigalice2.nem.ninja:7890/transaction/get?hash=1ce8e8894d077a66ff22294b000825d090a60742ec407efd80eb8b19657704f2
  7826. nem_transaction_start(
  7827. &ctx,
  7828. fromhex(
  7829. "84afa1bbc993b7f5536344914dde86141e61f8cbecaf8c9cefc07391f3287cf5"),
  7830. buffer, sizeof(buffer));
  7831. ck_assert(nem_transaction_create_mosaic_supply_change(
  7832. &ctx, NEM_NETWORK_TESTNET, 14126909, NULL, 108000000, 14130509,
  7833. "jabo38_ltd.fuzzy_kittens_cafe", "coupons", 2, 1));
  7834. keccak_256(ctx.buffer, ctx.offset, hash);
  7835. ck_assert_mem_eq(
  7836. hash,
  7837. fromhex(
  7838. "1ce8e8894d077a66ff22294b000825d090a60742ec407efd80eb8b19657704f2"),
  7839. sizeof(hash));
  7840. // http://bigalice3.nem.ninja:7890/transaction/get?hash=694e493e9576d2bcf60d85747e302ac2e1cc27783187947180d4275a713ff1ff
  7841. nem_transaction_start(
  7842. &ctx,
  7843. fromhex(
  7844. "b7ccc27b21ba6cf5c699a8dc86ba6ba98950442597ff9fa30e0abe0f5f4dd05d"),
  7845. buffer, sizeof(buffer));
  7846. ck_assert(nem_transaction_create_mosaic_supply_change(
  7847. &ctx, NEM_NETWORK_MAINNET, 53377685, NULL, 20000000, 53464085, "abvapp",
  7848. "abv", 1, 9000000));
  7849. keccak_256(ctx.buffer, ctx.offset, hash);
  7850. ck_assert_mem_eq(
  7851. hash,
  7852. fromhex(
  7853. "694e493e9576d2bcf60d85747e302ac2e1cc27783187947180d4275a713ff1ff"),
  7854. sizeof(hash));
  7855. // http://bigalice3.nem.ninja:7890/transaction/get?hash=09836334e123970e068d5b411e4d1df54a3ead10acf1ad5935a2cdd9f9680185
  7856. nem_transaction_start(
  7857. &ctx,
  7858. fromhex(
  7859. "75f001a8641e2ce5c4386883dda561399ed346177411b492a677b73899502f13"),
  7860. buffer, sizeof(buffer));
  7861. ck_assert(nem_transaction_create_mosaic_supply_change(
  7862. &ctx, NEM_NETWORK_MAINNET, 55176304, NULL, 20000000, 55262704, "sushi",
  7863. "wasabi", 2, 20));
  7864. keccak_256(ctx.buffer, ctx.offset, hash);
  7865. ck_assert_mem_eq(
  7866. hash,
  7867. fromhex(
  7868. "09836334e123970e068d5b411e4d1df54a3ead10acf1ad5935a2cdd9f9680185"),
  7869. sizeof(hash));
  7870. }
  7871. END_TEST
  7872. START_TEST(test_nem_transaction_aggregate_modification) {
  7873. nem_transaction_ctx ctx;
  7874. uint8_t buffer[1024], hash[SHA3_256_DIGEST_LENGTH];
  7875. // http://bob.nem.ninja:8765/#/aggregate/6a55471b17159e5b6cd579c421e95a4e39d92e3f78b0a55ee337e785a601d3a2
  7876. nem_transaction_start(
  7877. &ctx,
  7878. fromhex(
  7879. "462ee976890916e54fa825d26bdd0235f5eb5b6a143c199ab0ae5ee9328e08ce"),
  7880. buffer, sizeof(buffer));
  7881. ck_assert(nem_transaction_create_aggregate_modification(
  7882. &ctx, NEM_NETWORK_TESTNET, 0, NULL, 22000000, 0, 2, false));
  7883. ck_assert(nem_transaction_write_cosignatory_modification(
  7884. &ctx, 1,
  7885. fromhex(
  7886. "994793ba1c789fa9bdea918afc9b06e2d0309beb1081ac5b6952991e4defd324")));
  7887. ck_assert(nem_transaction_write_cosignatory_modification(
  7888. &ctx, 1,
  7889. fromhex(
  7890. "c54d6e33ed1446eedd7f7a80a588dd01857f723687a09200c1917d5524752f8b")));
  7891. keccak_256(ctx.buffer, ctx.offset, hash);
  7892. ck_assert_mem_eq(
  7893. hash,
  7894. fromhex(
  7895. "6a55471b17159e5b6cd579c421e95a4e39d92e3f78b0a55ee337e785a601d3a2"),
  7896. sizeof(hash));
  7897. // http://bob.nem.ninja:8765/#/aggregate/1fbdae5ba753e68af270930413ae90f671eb8ab58988116684bac0abd5726584
  7898. nem_transaction_start(
  7899. &ctx,
  7900. fromhex(
  7901. "6bf7849c1eec6a2002995cc457dc00c4e29bad5c88de63f51e42dfdcd7b2131d"),
  7902. buffer, sizeof(buffer));
  7903. ck_assert(nem_transaction_create_aggregate_modification(
  7904. &ctx, NEM_NETWORK_TESTNET, 6542254, NULL, 40000000, 6545854, 4, true));
  7905. ck_assert(nem_transaction_write_cosignatory_modification(
  7906. &ctx, 1,
  7907. fromhex(
  7908. "5f53d076c8c3ec3110b98364bc423092c3ec2be2b1b3c40fd8ab68d54fa39295")));
  7909. ck_assert(nem_transaction_write_cosignatory_modification(
  7910. &ctx, 1,
  7911. fromhex(
  7912. "9eb199c2b4d406f64cb7aa5b2b0815264b56ba8fe44d558a6cb423a31a33c4c2")));
  7913. ck_assert(nem_transaction_write_cosignatory_modification(
  7914. &ctx, 1,
  7915. fromhex(
  7916. "94b2323dab23a3faba24fa6ddda0ece4fbb06acfedd74e76ad9fae38d006882b")));
  7917. ck_assert(nem_transaction_write_cosignatory_modification(
  7918. &ctx, 1,
  7919. fromhex(
  7920. "d88c6ee2a2cd3929d0d76b6b14ecb549d21296ab196a2b3a4cb2536bcce32e87")));
  7921. ck_assert(nem_transaction_write_minimum_cosignatories(&ctx, 2));
  7922. keccak_256(ctx.buffer, ctx.offset, hash);
  7923. ck_assert_mem_eq(
  7924. hash,
  7925. fromhex(
  7926. "1fbdae5ba753e68af270930413ae90f671eb8ab58988116684bac0abd5726584"),
  7927. sizeof(hash));
  7928. // http://chain.nem.ninja/#/aggregate/cc64ca69bfa95db2ff7ac1e21fe6d27ece189c603200ebc9778d8bb80ca25c3c
  7929. nem_transaction_start(
  7930. &ctx,
  7931. fromhex(
  7932. "f41b99320549741c5cce42d9e4bb836d98c50ed5415d0c3c2912d1bb50e6a0e5"),
  7933. buffer, sizeof(buffer));
  7934. ck_assert(nem_transaction_create_aggregate_modification(
  7935. &ctx, NEM_NETWORK_MAINNET, 0, NULL, 40000000, 0, 5, false));
  7936. ck_assert(nem_transaction_write_cosignatory_modification(
  7937. &ctx, 1,
  7938. fromhex(
  7939. "1fbdbdde28daf828245e4533765726f0b7790e0b7146e2ce205df3e86366980b")));
  7940. ck_assert(nem_transaction_write_cosignatory_modification(
  7941. &ctx, 1,
  7942. fromhex(
  7943. "f94e8702eb1943b23570b1b83be1b81536df35538978820e98bfce8f999e2d37")));
  7944. ck_assert(nem_transaction_write_cosignatory_modification(
  7945. &ctx, 1,
  7946. fromhex(
  7947. "826cedee421ff66e708858c17815fcd831a4bb68e3d8956299334e9e24380ba8")));
  7948. ck_assert(nem_transaction_write_cosignatory_modification(
  7949. &ctx, 1,
  7950. fromhex(
  7951. "719862cd7d0f4e875a6a0274c9a1738f38f40ad9944179006a54c34724c1274d")));
  7952. ck_assert(nem_transaction_write_cosignatory_modification(
  7953. &ctx, 1,
  7954. fromhex(
  7955. "43aa69177018fc3e2bdbeb259c81cddf24be50eef9c5386db51d82386c41475a")));
  7956. keccak_256(ctx.buffer, ctx.offset, hash);
  7957. ck_assert_mem_eq(
  7958. hash,
  7959. fromhex(
  7960. "cc64ca69bfa95db2ff7ac1e21fe6d27ece189c603200ebc9778d8bb80ca25c3c"),
  7961. sizeof(hash));
  7962. }
  7963. END_TEST
  7964. START_TEST(test_multibyte_address) {
  7965. uint8_t priv_key[32];
  7966. char wif[57];
  7967. uint8_t pub_key[33];
  7968. char address[40];
  7969. uint8_t decode[24];
  7970. int res;
  7971. memcpy(
  7972. priv_key,
  7973. fromhex(
  7974. "47f7616ea6f9b923076625b4488115de1ef1187f760e65f89eb6f4f7ff04b012"),
  7975. 32);
  7976. ecdsa_get_wif(priv_key, 0, HASHER_SHA2D, wif, sizeof(wif));
  7977. ck_assert_str_eq(wif, "13QtoXmbhELWcrwD9YA9KzvXy5rTaptiNuFR8L8ArpBNn4xmQj4N");
  7978. ecdsa_get_wif(priv_key, 0x12, HASHER_SHA2D, wif, sizeof(wif));
  7979. ck_assert_str_eq(wif, "3hrF6SFnqzpzABB36uGDf8dJSuUCcMmoJrTmCWMshRkBr2Vx86qJ");
  7980. ecdsa_get_wif(priv_key, 0x1234, HASHER_SHA2D, wif, sizeof(wif));
  7981. ck_assert_str_eq(wif,
  7982. "CtPTF9awbVbfDWGepGdVhB3nBhr4HktUGya8nf8dLxgC8tbqBreB9");
  7983. ecdsa_get_wif(priv_key, 0x123456, HASHER_SHA2D, wif, sizeof(wif));
  7984. ck_assert_str_eq(wif,
  7985. "uTrDevVQt5QZgoL3iJ1cPWHaCz7ZMBncM7QXZfCegtxiMHqBvWoYJa");
  7986. ecdsa_get_wif(priv_key, 0x12345678, HASHER_SHA2D, wif, sizeof(wif));
  7987. ck_assert_str_eq(wif,
  7988. "4zZWMzv1SVbs95pmLXWrXJVp9ntPEam1mfwb6CXBLn9MpWNxLg9huYgv");
  7989. ecdsa_get_wif(priv_key, 0xffffffff, HASHER_SHA2D, wif, sizeof(wif));
  7990. ck_assert_str_eq(wif,
  7991. "y9KVfV1RJXcTxpVjeuh6WYWh8tMwnAUeyUwDEiRviYdrJ61njTmnfUjE");
  7992. memcpy(
  7993. pub_key,
  7994. fromhex(
  7995. "0378d430274f8c5ec1321338151e9f27f4c676a008bdf8638d07c0b6be9ab35c71"),
  7996. 33);
  7997. ecdsa_get_address(pub_key, 0, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  7998. sizeof(address));
  7999. ck_assert_str_eq(address, "1C7zdTfnkzmr13HfA2vNm5SJYRK6nEKyq8");
  8000. ecdsa_get_address(pub_key, 0x12, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  8001. sizeof(address));
  8002. ck_assert_str_eq(address, "8SCrMR2yYF7ciqoDbav7VLLTsVx5dTVPPq");
  8003. ecdsa_get_address(pub_key, 0x1234, HASHER_SHA2_RIPEMD, HASHER_SHA2D, address,
  8004. sizeof(address));
  8005. ck_assert_str_eq(address, "ZLH8q1UgMPg8o2s1MD55YVMpPV7vqms9kiV");
  8006. ecdsa_get_address(pub_key, 0x123456, HASHER_SHA2_RIPEMD, HASHER_SHA2D,
  8007. address, sizeof(address));
  8008. ck_assert_str_eq(address, "3ThqvsQVFnbiF66NwHtfe2j6AKn75DpLKpQSq");
  8009. ecdsa_get_address(pub_key, 0x12345678, HASHER_SHA2_RIPEMD, HASHER_SHA2D,
  8010. address, sizeof(address));
  8011. ck_assert_str_eq(address, "BrsGxAHga3VbopvSnb3gmLvMBhJNCGuDxBZL44");
  8012. ecdsa_get_address(pub_key, 0xffffffff, HASHER_SHA2_RIPEMD, HASHER_SHA2D,
  8013. address, sizeof(address));
  8014. ck_assert_str_eq(address, "3diW7paWGJyZRLGqMJZ55DMfPExob8QxQHkrfYT");
  8015. res = ecdsa_address_decode("1C7zdTfnkzmr13HfA2vNm5SJYRK6nEKyq8", 0,
  8016. HASHER_SHA2D, decode);
  8017. ck_assert_int_eq(res, 1);
  8018. ck_assert_mem_eq(decode,
  8019. fromhex("0079fbfc3f34e7745860d76137da68f362380c606c"), 21);
  8020. res = ecdsa_address_decode("8SCrMR2yYF7ciqoDbav7VLLTsVx5dTVPPq", 0x12,
  8021. HASHER_SHA2D, decode);
  8022. ck_assert_int_eq(res, 1);
  8023. ck_assert_mem_eq(decode,
  8024. fromhex("1279fbfc3f34e7745860d76137da68f362380c606c"), 21);
  8025. res = ecdsa_address_decode("ZLH8q1UgMPg8o2s1MD55YVMpPV7vqms9kiV", 0x1234,
  8026. HASHER_SHA2D, decode);
  8027. ck_assert_int_eq(res, 1);
  8028. ck_assert_mem_eq(decode,
  8029. fromhex("123479fbfc3f34e7745860d76137da68f362380c606c"), 21);
  8030. res = ecdsa_address_decode("3ThqvsQVFnbiF66NwHtfe2j6AKn75DpLKpQSq", 0x123456,
  8031. HASHER_SHA2D, decode);
  8032. ck_assert_int_eq(res, 1);
  8033. ck_assert_mem_eq(
  8034. decode, fromhex("12345679fbfc3f34e7745860d76137da68f362380c606c"), 21);
  8035. res = ecdsa_address_decode("BrsGxAHga3VbopvSnb3gmLvMBhJNCGuDxBZL44",
  8036. 0x12345678, HASHER_SHA2D, decode);
  8037. ck_assert_int_eq(res, 1);
  8038. ck_assert_mem_eq(
  8039. decode, fromhex("1234567879fbfc3f34e7745860d76137da68f362380c606c"), 21);
  8040. res = ecdsa_address_decode("3diW7paWGJyZRLGqMJZ55DMfPExob8QxQHkrfYT",
  8041. 0xffffffff, HASHER_SHA2D, decode);
  8042. ck_assert_int_eq(res, 1);
  8043. ck_assert_mem_eq(
  8044. decode, fromhex("ffffffff79fbfc3f34e7745860d76137da68f362380c606c"), 21);
  8045. // wrong length
  8046. res = ecdsa_address_decode("BrsGxAHga3VbopvSnb3gmLvMBhJNCGuDxBZL44", 0x123456,
  8047. HASHER_SHA2D, decode);
  8048. ck_assert_int_eq(res, 0);
  8049. // wrong address prefix
  8050. res = ecdsa_address_decode("BrsGxAHga3VbopvSnb3gmLvMBhJNCGuDxBZL44",
  8051. 0x22345678, HASHER_SHA2D, decode);
  8052. ck_assert_int_eq(res, 0);
  8053. // wrong checksum
  8054. res = ecdsa_address_decode("BrsGxAHga3VbopvSnb3gmLvMBhJNCGuDxBZL45",
  8055. 0x12345678, HASHER_SHA2D, decode);
  8056. ck_assert_int_eq(res, 0);
  8057. }
  8058. END_TEST
  8059. // https://tools.ietf.org/html/rfc6229#section-2
  8060. START_TEST(test_rc4_rfc6229) {
  8061. static const size_t offsets[] = {
  8062. 0x0, 0xf0, 0x1f0, 0x2f0, 0x3f0, 0x5f0, 0x7f0, 0xbf0, 0xff0,
  8063. };
  8064. static const struct {
  8065. char key[65];
  8066. char vectors[sizeof(offsets) / sizeof(*offsets)][65];
  8067. } tests[] = {
  8068. {"0102030405",
  8069. {
  8070. "b2396305f03dc027ccc3524a0a1118a8"
  8071. "6982944f18fc82d589c403a47a0d0919",
  8072. "28cb1132c96ce286421dcaadb8b69eae"
  8073. "1cfcf62b03eddb641d77dfcf7f8d8c93",
  8074. "42b7d0cdd918a8a33dd51781c81f4041"
  8075. "6459844432a7da923cfb3eb4980661f6",
  8076. "ec10327bde2beefd18f9277680457e22"
  8077. "eb62638d4f0ba1fe9fca20e05bf8ff2b",
  8078. "45129048e6a0ed0b56b490338f078da5"
  8079. "30abbcc7c20b01609f23ee2d5f6bb7df",
  8080. "3294f744d8f9790507e70f62e5bbceea"
  8081. "d8729db41882259bee4f825325f5a130",
  8082. "1eb14a0c13b3bf47fa2a0ba93ad45b8b"
  8083. "cc582f8ba9f265e2b1be9112e975d2d7",
  8084. "f2e30f9bd102ecbf75aaade9bc35c43c"
  8085. "ec0e11c479dc329dc8da7968fe965681",
  8086. "068326a2118416d21f9d04b2cd1ca050"
  8087. "ff25b58995996707e51fbdf08b34d875",
  8088. }},
  8089. {"01020304050607",
  8090. {
  8091. "293f02d47f37c9b633f2af5285feb46b"
  8092. "e620f1390d19bd84e2e0fd752031afc1",
  8093. "914f02531c9218810df60f67e338154c"
  8094. "d0fdb583073ce85ab83917740ec011d5",
  8095. "75f81411e871cffa70b90c74c592e454"
  8096. "0bb87202938dad609e87a5a1b079e5e4",
  8097. "c2911246b612e7e7b903dfeda1dad866"
  8098. "32828f91502b6291368de8081de36fc2",
  8099. "f3b9a7e3b297bf9ad804512f9063eff1"
  8100. "8ecb67a9ba1f55a5a067e2b026a3676f",
  8101. "d2aa902bd42d0d7cfd340cd45810529f"
  8102. "78b272c96e42eab4c60bd914e39d06e3",
  8103. "f4332fd31a079396ee3cee3f2a4ff049"
  8104. "05459781d41fda7f30c1be7e1246c623",
  8105. "adfd3868b8e51485d5e610017e3dd609"
  8106. "ad26581c0c5be45f4cea01db2f3805d5",
  8107. "f3172ceffc3b3d997c85ccd5af1a950c"
  8108. "e74b0b9731227fd37c0ec08a47ddd8b8",
  8109. }},
  8110. {"0102030405060708",
  8111. {
  8112. "97ab8a1bf0afb96132f2f67258da15a8"
  8113. "8263efdb45c4a18684ef87e6b19e5b09",
  8114. "9636ebc9841926f4f7d1f362bddf6e18"
  8115. "d0a990ff2c05fef5b90373c9ff4b870a",
  8116. "73239f1db7f41d80b643c0c52518ec63"
  8117. "163b319923a6bdb4527c626126703c0f",
  8118. "49d6c8af0f97144a87df21d91472f966"
  8119. "44173a103b6616c5d5ad1cee40c863d0",
  8120. "273c9c4b27f322e4e716ef53a47de7a4"
  8121. "c6d0e7b226259fa9023490b26167ad1d",
  8122. "1fe8986713f07c3d9ae1c163ff8cf9d3"
  8123. "8369e1a965610be887fbd0c79162aafb",
  8124. "0a0127abb44484b9fbef5abcae1b579f"
  8125. "c2cdadc6402e8ee866e1f37bdb47e42c",
  8126. "26b51ea37df8e1d6f76fc3b66a7429b3"
  8127. "bc7683205d4f443dc1f29dda3315c87b",
  8128. "d5fa5a3469d29aaaf83d23589db8c85b"
  8129. "3fb46e2c8f0f068edce8cdcd7dfc5862",
  8130. }},
  8131. {"0102030405060708090a",
  8132. {
  8133. "ede3b04643e586cc907dc21851709902"
  8134. "03516ba78f413beb223aa5d4d2df6711",
  8135. "3cfd6cb58ee0fdde640176ad0000044d"
  8136. "48532b21fb6079c9114c0ffd9c04a1ad",
  8137. "3e8cea98017109979084b1ef92f99d86"
  8138. "e20fb49bdb337ee48b8d8dc0f4afeffe",
  8139. "5c2521eacd7966f15e056544bea0d315"
  8140. "e067a7031931a246a6c3875d2f678acb",
  8141. "a64f70af88ae56b6f87581c0e23e6b08"
  8142. "f449031de312814ec6f319291f4a0516",
  8143. "bdae85924b3cb1d0a2e33a30c6d79599"
  8144. "8a0feddbac865a09bcd127fb562ed60a",
  8145. "b55a0a5b51a12a8be34899c3e047511a"
  8146. "d9a09cea3ce75fe39698070317a71339",
  8147. "552225ed1177f44584ac8cfa6c4eb5fc"
  8148. "7e82cbabfc95381b080998442129c2f8",
  8149. "1f135ed14ce60a91369d2322bef25e3c"
  8150. "08b6be45124a43e2eb77953f84dc8553",
  8151. }},
  8152. {"0102030405060708090a0b0c0d0e0f10",
  8153. {
  8154. "9ac7cc9a609d1ef7b2932899cde41b97"
  8155. "5248c4959014126a6e8a84f11d1a9e1c",
  8156. "065902e4b620f6cc36c8589f66432f2b"
  8157. "d39d566bc6bce3010768151549f3873f",
  8158. "b6d1e6c4a5e4771cad79538df295fb11"
  8159. "c68c1d5c559a974123df1dbc52a43b89",
  8160. "c5ecf88de897fd57fed301701b82a259"
  8161. "eccbe13de1fcc91c11a0b26c0bc8fa4d",
  8162. "e7a72574f8782ae26aabcf9ebcd66065"
  8163. "bdf0324e6083dcc6d3cedd3ca8c53c16",
  8164. "b40110c4190b5622a96116b0017ed297"
  8165. "ffa0b514647ec04f6306b892ae661181",
  8166. "d03d1bc03cd33d70dff9fa5d71963ebd"
  8167. "8a44126411eaa78bd51e8d87a8879bf5",
  8168. "fabeb76028ade2d0e48722e46c4615a3"
  8169. "c05d88abd50357f935a63c59ee537623",
  8170. "ff38265c1642c1abe8d3c2fe5e572bf8"
  8171. "a36a4c301ae8ac13610ccbc12256cacc",
  8172. }},
  8173. {"0102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f20",
  8174. {
  8175. "eaa6bd25880bf93d3f5d1e4ca2611d91"
  8176. "cfa45c9f7e714b54bdfa80027cb14380",
  8177. "114ae344ded71b35f2e60febad727fd8"
  8178. "02e1e7056b0f623900496422943e97b6",
  8179. "91cb93c787964e10d9527d999c6f936b"
  8180. "49b18b42f8e8367cbeb5ef104ba1c7cd",
  8181. "87084b3ba700bade955610672745b374"
  8182. "e7a7b9e9ec540d5ff43bdb12792d1b35",
  8183. "c799b596738f6b018c76c74b1759bd90"
  8184. "7fec5bfd9f9b89ce6548309092d7e958",
  8185. "40f250b26d1f096a4afd4c340a588815"
  8186. "3e34135c79db010200767651cf263073",
  8187. "f656abccf88dd827027b2ce917d464ec"
  8188. "18b62503bfbc077fbabb98f20d98ab34",
  8189. "8aed95ee5b0dcbfbef4eb21d3a3f52f9"
  8190. "625a1ab00ee39a5327346bddb01a9c18",
  8191. "a13a7c79c7e119b5ab0296ab28c300b9"
  8192. "f3e4c0a2e02d1d01f7f0a74618af2b48",
  8193. }},
  8194. {"833222772a",
  8195. {
  8196. "80ad97bdc973df8a2e879e92a497efda"
  8197. "20f060c2f2e5126501d3d4fea10d5fc0",
  8198. "faa148e99046181fec6b2085f3b20ed9"
  8199. "f0daf5bab3d596839857846f73fbfe5a",
  8200. "1c7e2fc4639232fe297584b296996bc8"
  8201. "3db9b249406cc8edffac55ccd322ba12",
  8202. "e4f9f7e0066154bbd125b745569bc897"
  8203. "75d5ef262b44c41a9cf63ae14568e1b9",
  8204. "6da453dbf81e82334a3d8866cb50a1e3"
  8205. "7828d074119cab5c22b294d7a9bfa0bb",
  8206. "adb89cea9a15fbe617295bd04b8ca05c"
  8207. "6251d87fd4aaae9a7e4ad5c217d3f300",
  8208. "e7119bd6dd9b22afe8f89585432881e2"
  8209. "785b60fd7ec4e9fcb6545f350d660fab",
  8210. "afecc037fdb7b0838eb3d70bcd268382"
  8211. "dbc1a7b49d57358cc9fa6d61d73b7cf0",
  8212. "6349d126a37afcba89794f9804914fdc"
  8213. "bf42c3018c2f7c66bfde524975768115",
  8214. }},
  8215. {"1910833222772a",
  8216. {
  8217. "bc9222dbd3274d8fc66d14ccbda6690b"
  8218. "7ae627410c9a2be693df5bb7485a63e3",
  8219. "3f0931aa03defb300f060103826f2a64"
  8220. "beaa9ec8d59bb68129f3027c96361181",
  8221. "74e04db46d28648d7dee8a0064b06cfe"
  8222. "9b5e81c62fe023c55be42f87bbf932b8",
  8223. "ce178fc1826efecbc182f57999a46140"
  8224. "8bdf55cd55061c06dba6be11de4a578a",
  8225. "626f5f4dce652501f3087d39c92cc349"
  8226. "42daac6a8f9ab9a7fd137c6037825682",
  8227. "cc03fdb79192a207312f53f5d4dc33d9"
  8228. "f70f14122a1c98a3155d28b8a0a8a41d",
  8229. "2a3a307ab2708a9c00fe0b42f9c2d6a1"
  8230. "862617627d2261eab0b1246597ca0ae9",
  8231. "55f877ce4f2e1ddbbf8e13e2cde0fdc8"
  8232. "1b1556cb935f173337705fbb5d501fc1",
  8233. "ecd0e96602be7f8d5092816cccf2c2e9"
  8234. "027881fab4993a1c262024a94fff3f61",
  8235. }},
  8236. {"641910833222772a",
  8237. {
  8238. "bbf609de9413172d07660cb680716926"
  8239. "46101a6dab43115d6c522b4fe93604a9",
  8240. "cbe1fff21c96f3eef61e8fe0542cbdf0"
  8241. "347938bffa4009c512cfb4034b0dd1a7",
  8242. "7867a786d00a7147904d76ddf1e520e3"
  8243. "8d3e9e1caefcccb3fbf8d18f64120b32",
  8244. "942337f8fd76f0fae8c52d7954810672"
  8245. "b8548c10f51667f6e60e182fa19b30f7",
  8246. "0211c7c6190c9efd1237c34c8f2e06c4"
  8247. "bda64f65276d2aacb8f90212203a808e",
  8248. "bd3820f732ffb53ec193e79d33e27c73"
  8249. "d0168616861907d482e36cdac8cf5749",
  8250. "97b0f0f224b2d2317114808fb03af7a0"
  8251. "e59616e469787939a063ceea9af956d1",
  8252. "c47e0dc1660919c11101208f9e69aa1f"
  8253. "5ae4f12896b8379a2aad89b5b553d6b0",
  8254. "6b6b098d0c293bc2993d80bf0518b6d9"
  8255. "8170cc3ccd92a698621b939dd38fe7b9",
  8256. }},
  8257. {"8b37641910833222772a",
  8258. {
  8259. "ab65c26eddb287600db2fda10d1e605c"
  8260. "bb759010c29658f2c72d93a2d16d2930",
  8261. "b901e8036ed1c383cd3c4c4dd0a6ab05"
  8262. "3d25ce4922924c55f064943353d78a6c",
  8263. "12c1aa44bbf87e75e611f69b2c38f49b"
  8264. "28f2b3434b65c09877470044c6ea170d",
  8265. "bd9ef822de5288196134cf8af7839304"
  8266. "67559c23f052158470a296f725735a32",
  8267. "8bab26fbc2c12b0f13e2ab185eabf241"
  8268. "31185a6d696f0cfa9b42808b38e132a2",
  8269. "564d3dae183c5234c8af1e51061c44b5"
  8270. "3c0778a7b5f72d3c23a3135c7d67b9f4",
  8271. "f34369890fcf16fb517dcaae4463b2dd"
  8272. "02f31c81e8200731b899b028e791bfa7",
  8273. "72da646283228c14300853701795616f"
  8274. "4e0a8c6f7934a788e2265e81d6d0c8f4",
  8275. "438dd5eafea0111b6f36b4b938da2a68"
  8276. "5f6bfc73815874d97100f086979357d8",
  8277. }},
  8278. {"ebb46227c6cc8b37641910833222772a",
  8279. {
  8280. "720c94b63edf44e131d950ca211a5a30"
  8281. "c366fdeacf9ca80436be7c358424d20b",
  8282. "b3394a40aabf75cba42282ef25a0059f"
  8283. "4847d81da4942dbc249defc48c922b9f",
  8284. "08128c469f275342adda202b2b58da95"
  8285. "970dacef40ad98723bac5d6955b81761",
  8286. "3cb89993b07b0ced93de13d2a11013ac"
  8287. "ef2d676f1545c2c13dc680a02f4adbfe",
  8288. "b60595514f24bc9fe522a6cad7393644"
  8289. "b515a8c5011754f59003058bdb81514e",
  8290. "3c70047e8cbc038e3b9820db601da495"
  8291. "1175da6ee756de46a53e2b075660b770",
  8292. "00a542bba02111cc2c65b38ebdba587e"
  8293. "5865fdbb5b48064104e830b380f2aede",
  8294. "34b21ad2ad44e999db2d7f0863f0d9b6"
  8295. "84a9218fc36e8a5f2ccfbeae53a27d25",
  8296. "a2221a11b833ccb498a59540f0545f4a"
  8297. "5bbeb4787d59e5373fdbea6c6f75c29b",
  8298. }},
  8299. {"c109163908ebe51debb46227c6cc8b37641910833222772a",
  8300. {
  8301. "54b64e6b5a20b5e2ec84593dc7989da7"
  8302. "c135eee237a85465ff97dc03924f45ce",
  8303. "cfcc922fb4a14ab45d6175aabbf2d201"
  8304. "837b87e2a446ad0ef798acd02b94124f",
  8305. "17a6dbd664926a0636b3f4c37a4f4694"
  8306. "4a5f9f26aeeed4d4a25f632d305233d9",
  8307. "80a3d01ef00c8e9a4209c17f4eeb358c"
  8308. "d15e7d5ffaaabc0207bf200a117793a2",
  8309. "349682bf588eaa52d0aa1560346aeafa"
  8310. "f5854cdb76c889e3ad63354e5f7275e3",
  8311. "532c7ceccb39df3236318405a4b1279c"
  8312. "baefe6d9ceb651842260e0d1e05e3b90",
  8313. "e82d8c6db54e3c633f581c952ba04207"
  8314. "4b16e50abd381bd70900a9cd9a62cb23",
  8315. "3682ee33bd148bd9f58656cd8f30d9fb"
  8316. "1e5a0b8475045d9b20b2628624edfd9e",
  8317. "63edd684fb826282fe528f9c0e9237bc"
  8318. "e4dd2e98d6960fae0b43545456743391",
  8319. }},
  8320. {"1ada31d5cf688221c109163908ebe51debb46227c6cc8b37641910833222772a",
  8321. {
  8322. "dd5bcb0018e922d494759d7c395d02d3"
  8323. "c8446f8f77abf737685353eb89a1c9eb",
  8324. "af3e30f9c095045938151575c3fb9098"
  8325. "f8cb6274db99b80b1d2012a98ed48f0e",
  8326. "25c3005a1cb85de076259839ab7198ab"
  8327. "9dcbc183e8cb994b727b75be3180769c",
  8328. "a1d3078dfa9169503ed9d4491dee4eb2"
  8329. "8514a5495858096f596e4bcd66b10665",
  8330. "5f40d59ec1b03b33738efa60b2255d31"
  8331. "3477c7f764a41baceff90bf14f92b7cc",
  8332. "ac4e95368d99b9eb78b8da8f81ffa795"
  8333. "8c3c13f8c2388bb73f38576e65b7c446",
  8334. "13c4b9c1dfb66579eddd8a280b9f7316"
  8335. "ddd27820550126698efaadc64b64f66e",
  8336. "f08f2e66d28ed143f3a237cf9de73559"
  8337. "9ea36c525531b880ba124334f57b0b70",
  8338. "d5a39e3dfcc50280bac4a6b5aa0dca7d"
  8339. "370b1c1fe655916d97fd0d47ca1d72b8",
  8340. }}};
  8341. RC4_CTX ctx;
  8342. uint8_t key[64];
  8343. uint8_t buffer[0x1010];
  8344. for (size_t i = 0; i < (sizeof(tests) / sizeof(*tests)); i++) {
  8345. size_t length = strlen(tests[i].key) / 2;
  8346. memcpy(key, fromhex(tests[i].key), length);
  8347. memzero(buffer, sizeof(buffer));
  8348. rc4_init(&ctx, key, length);
  8349. rc4_encrypt(&ctx, buffer, sizeof(buffer));
  8350. for (size_t j = 0; j < (sizeof(offsets) / sizeof(*offsets)); j++) {
  8351. size_t size = strlen(tests[i].vectors[j]) / 2;
  8352. ck_assert_mem_eq(&buffer[offsets[j]], fromhex(tests[i].vectors[j]), size);
  8353. }
  8354. }
  8355. }
  8356. END_TEST
  8357. static void test_compress_coord(const char *k_raw) {
  8358. const ecdsa_curve *curve = &secp256k1;
  8359. curve_point expected_coords;
  8360. bignum256 k = {0};
  8361. bn_read_be(fromhex(k_raw), &k);
  8362. point_multiply(curve, &k, &curve->G, &expected_coords);
  8363. uint8_t compress[33] = {0};
  8364. compress_coords(&expected_coords, compress);
  8365. bignum256 x = {0}, y = {0};
  8366. bn_read_be(compress + 1, &x);
  8367. uncompress_coords(curve, compress[0], &x, &y);
  8368. ck_assert(bn_is_equal(&expected_coords.x, &x));
  8369. ck_assert(bn_is_equal(&expected_coords.y, &y));
  8370. }
  8371. START_TEST(test_compress_coords) {
  8372. static const char *k_raw[] = {
  8373. "dc05960ac673fd59554c98655e26722d007bb7ada0c8ff00883fdee70783d0be",
  8374. "41e41e0a218c980411108a0a58cf88f528c828b4d6f0d2c86234bc2504bdc3cd",
  8375. "1d963ddcb79f6028a32cadd2421ff7fff969bff5774f73063dab41519b3da175",
  8376. "2414141f96da0874dbc374b58861589935b7f940806ddf8d2e6b911f62e240f3",
  8377. "01cc1fb182e29f60fe43e22d250de34f2d3f956bbef2aa9b182d09e5d9176873",
  8378. "89b3d621d813682692fd61b2baea6b2ea696a44abc76925d29c4887fc4db9367",
  8379. "20c80c633e05a3a7dfac05fa0e0a7c7a6b708b02323e687735cff81ea5944f59",
  8380. "5a803c263aa93a4f74648066c03e63fb00641193bae93dfa254dabd634e8b49c",
  8381. "05efbcc87007797dca68315b9271ac8fb75bddbece53f4dcbfb83fc21cb91fc0",
  8382. "0bed78ef43474630bd646eef2d7ec19a1acb8e9eecf6a0a3ac7241ac40a7706f",
  8383. };
  8384. for (int i = 0; i < (int)(sizeof(k_raw) / sizeof(*k_raw)); i++)
  8385. test_compress_coord(k_raw[i]);
  8386. }
  8387. END_TEST
  8388. START_TEST(test_zkp_bip340_sign) {
  8389. static struct {
  8390. const char *priv_key;
  8391. const char *pub_key;
  8392. const char *aux_input;
  8393. const char *digest;
  8394. const char *sig;
  8395. } tests[] = {
  8396. // Test vectors from
  8397. // https://github.com/bitcoin/bips/blob/master/bip-0340/test-vectors.csv
  8398. {"0000000000000000000000000000000000000000000000000000000000000003",
  8399. "F9308A019258C31049344F85F89D5229B531C845836F99B08601F113BCE036F9",
  8400. "0000000000000000000000000000000000000000000000000000000000000000",
  8401. "0000000000000000000000000000000000000000000000000000000000000000",
  8402. "E907831F80848D1069A5371B402410364BDF1C5F8307B0084C55F1CE2DCA821525F66A4"
  8403. "A85EA8B71E482A74F382D2CE5EBEEE8FDB2172F477DF4900D310536C0"},
  8404. {"B7E151628AED2A6ABF7158809CF4F3C762E7160F38B4DA56A784D9045190CFEF",
  8405. "DFF1D77F2A671C5F36183726DB2341BE58FEAE1DA2DECED843240F7B502BA659",
  8406. "0000000000000000000000000000000000000000000000000000000000000001",
  8407. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8408. "6896BD60EEAE296DB48A229FF71DFE071BDE413E6D43F917DC8DCF8C78DE33418906D11"
  8409. "AC976ABCCB20B091292BFF4EA897EFCB639EA871CFA95F6DE339E4B0A"},
  8410. {"C90FDAA22168C234C4C6628B80DC1CD129024E088A67CC74020BBEA63B14E5C9",
  8411. "DD308AFEC5777E13121FA72B9CC1B7CC0139715309B086C960E18FD969774EB8",
  8412. "C87AA53824B4D7AE2EB035A2B5BBBCCC080E76CDC6D1692C4B0B62D798E6D906",
  8413. "7E2D58D8B3BCDF1ABADEC7829054F90DDA9805AAB56C77333024B9D0A508B75C",
  8414. "5831AAEED7B44BB74E5EAB94BA9D4294C49BCF2A60728D8B4C200F50DD313C1BAB74587"
  8415. "9A5AD954A72C45A91C3A51D3C7ADEA98D82F8481E0E1E03674A6F3FB7"},
  8416. {"0B432B2677937381AEF05BB02A66ECD012773062CF3FA2549E44F58ED2401710",
  8417. "25D1DFF95105F5253C4022F628A996AD3A0D95FBF21D468A1B33F8C160D8F517",
  8418. "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF",
  8419. "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF",
  8420. "7EB0509757E246F19449885651611CB965ECC1A187DD51B64FDA1EDC9637D5EC97582B9"
  8421. "CB13DB3933705B32BA982AF5AF25FD78881EBB32771FC5922EFC66EA3"},
  8422. // https://github.com/bitcoin/bips/pull/1225/commits/f7af1f73b287c14cf2f63afcb8d199feaf6ab5e1
  8423. {"2405b971772ad26915c8dcdf10f238753a9b837e5f8e6a86fd7c0cce5b7296d9",
  8424. "53a1f6e454df1aa2776a2814a721372d6258050de330b3c6d10ee8f4e0dda343",
  8425. "0000000000000000000000000000000000000000000000000000000000000000",
  8426. "7e584883b084ace0469c6962a9a7d2a9060e1f3c218ab40d32c77651482122bc",
  8427. "aab8fce3c4d7f359577a338676c9580d6946d7d8f899a48a4e1dcc63611e8f654eab719"
  8428. "2d43e6d6b9c7c95322338edbc5af21e88b43df36a989ba559d473f32a"},
  8429. {"ea260c3b10e60f6de018455cd0278f2f5b7e454be1999572789e6a9565d26080",
  8430. "147c9c57132f6e7ecddba9800bb0c4449251c92a1e60371ee77557b6620f3ea3",
  8431. "0000000000000000000000000000000000000000000000000000000000000000",
  8432. "325a644af47e8a5a2591cda0ab0723978537318f10e6a63d4eed783b96a71a4d",
  8433. "052aedffc554b41f52b521071793a6b88d6dbca9dba94cf34c83696de0c1ec35ca9c5ed"
  8434. "4ab28059bd606a4f3a657eec0bb96661d42921b5f50a95ad33675b54f"},
  8435. {"97323385e57015b75b0339a549c56a948eb961555973f0951f555ae6039ef00d",
  8436. "e4d810fd50586274face62b8a807eb9719cef49c04177cc6b76a9a4251d5450e",
  8437. "0000000000000000000000000000000000000000000000000000000000000000",
  8438. "6ffd256e108685b41831385f57eebf2fca041bc6b5e607ea11b3e03d4cf9d9ba",
  8439. "f78cf3fe8410326ba95b7119cac657b2d86a461dc0767d7b68cb516f3d8bac64ed027fb"
  8440. "710b5962d01c42dadaf4dec5731371c6c7850854cc68054eb8f4de80b"},
  8441. {"a8e7aa924f0d58854185a490e6c41f6efb7b675c0f3331b7f14b549400b4d501",
  8442. "91b64d5324723a985170e4dc5a0f84c041804f2cd12660fa5dec09fc21783605",
  8443. "0000000000000000000000000000000000000000000000000000000000000000",
  8444. "9f90136737540ccc18707e1fd398ad222a1a7e4dd65cbfd22dbe4660191efa58",
  8445. "69599256a182e89be95c098b03200b958220ee400c42779cd05cdbf9fa2d5c8060a48c1"
  8446. "463c9fadf6aea0395b70ebf937fbae0dd2d83185c1d9f675dac8d06f5"},
  8447. {"241c14f2639d0d7139282aa6abde28dd8a067baa9d633e4e7230287ec2d02901",
  8448. "75169f4001aa68f15bbed28b218df1d0a62cbbcf1188c6665110c293c907b831",
  8449. "0000000000000000000000000000000000000000000000000000000000000000",
  8450. "835c9ab6084ed9a8ae9b7cda21e0aa797aca3b76a54bd1e3c7db093f6c57e23f",
  8451. "882a50af428ea47ee84462fcb481033db9c8b1ea6f2b77c9a8e4d8135a1c0771ee8dbcd"
  8452. "24ea671576ab441bdb2ab3f85f20675ca4c59889bab719b062abfd064"},
  8453. {"9822270935e156a1b9b28940e7b94a06934a51ddabdd49dd43e8010adc98dfa3",
  8454. "0f63ca2c7639b9bb4be0465cc0aa3ee78a0761ba5f5f7d6ff8eab340f09da561",
  8455. "0000000000000000000000000000000000000000000000000000000000000000",
  8456. "df1cca638283c667084b8ffe6bf6e116cc5a53cf7ae1202c5fee45a9085f1ba5",
  8457. "1ec324f9ccc982286a10017daa22ead5087d9f2eff58dd6173d7d608eb959be6be2f3df"
  8458. "0a25a7890c99a9259c9eab33d71a6c163cabb442aa3a5e5d613611420"},
  8459. {"8e575b74b70d573b05558883743a72d1ccc326b4c299ea3412a29d3b83e801e4",
  8460. "053690babeabbb7850c32eead0acf8df990ced79f7a31e358fabf2658b4bc587",
  8461. "0000000000000000000000000000000000000000000000000000000000000000",
  8462. "30319859ca79ea1b7a9782e9daebc46e4ca4ca2bc04c9c53b2ec87fa83a526bd",
  8463. "7e6c212ebe04e8241bee0151b0d3230aa22dec9dbdd8197ebd3ff616b9e4b47dccee08a"
  8464. "32a52a77d60587a77e7d7b5d1d113235d38921740ffdbe795459637ff"}};
  8465. int res = 0;
  8466. uint8_t priv_key[32] = {0};
  8467. uint8_t expected_pub_key[32] = {0};
  8468. uint8_t aux_input[32] = {0};
  8469. uint8_t digest[32] = {0};
  8470. uint8_t expected_sig[64] = {0};
  8471. uint8_t pub_key[32] = {0};
  8472. uint8_t sig[64] = {0};
  8473. for (size_t i = 0; i < sizeof(tests) / sizeof(*tests); i++) {
  8474. memcpy(priv_key, fromhex(tests[i].priv_key), 32);
  8475. memcpy(expected_pub_key, fromhex(tests[i].pub_key), 32);
  8476. memcpy(aux_input, fromhex(tests[i].aux_input), 32);
  8477. memcpy(digest, fromhex(tests[i].digest), 32);
  8478. memcpy(expected_sig, fromhex(tests[i].sig), 64);
  8479. zkp_bip340_get_public_key(priv_key, pub_key);
  8480. ck_assert_mem_eq(expected_pub_key, pub_key, 32);
  8481. res = zkp_bip340_sign_digest(priv_key, digest, sig, aux_input);
  8482. ck_assert_mem_eq(expected_sig, sig, 64);
  8483. ck_assert_int_eq(res, 0);
  8484. }
  8485. }
  8486. END_TEST
  8487. START_TEST(test_zkp_bip340_verify) {
  8488. static struct {
  8489. const char *pub_key;
  8490. const char *digest;
  8491. const char *sig;
  8492. const int res;
  8493. } tests[] = {
  8494. // Test vectors from
  8495. // https://github.com/bitcoin/bips/blob/master/bip-0340/test-vectors.csv
  8496. {"D69C3509BB99E412E68B0FE8544E72837DFA30746D8BE2AA65975F29D22DC7B9",
  8497. "4DF3C3F68FCC83B27E9D42C90431A72499F17875C81A599B566C9889B9696703",
  8498. "00000000000000000000003B78CE563F89A0ED9414F5AA28AD0D96D6795F9C6376AFB15"
  8499. "48AF603B3EB45C9F8207DEE1060CB71C04E80F593060B07D28308D7F4",
  8500. 0},
  8501. {"EEFDEA4CDB677750A420FEE807EACF21EB9898AE79B9768766E4FAA04A2D4A34",
  8502. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8503. "6CFF5C3BA86C69EA4B7376F31A9BCB4F74C1976089B2D9963DA2E5543E17776969E89B4"
  8504. "C5564D00349106B8497785DD7D1D713A8AE82B32FA79D5F7FC407D39B",
  8505. 1},
  8506. {"DFF1D77F2A671C5F36183726DB2341BE58FEAE1DA2DECED843240F7B502BA659",
  8507. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8508. "FFF97BD5755EEEA420453A14355235D382F6472F8568A18B2F057A14602975563CC2794"
  8509. "4640AC607CD107AE10923D9EF7A73C643E166BE5EBEAFA34B1AC553E2",
  8510. 5},
  8511. {"DFF1D77F2A671C5F36183726DB2341BE58FEAE1DA2DECED843240F7B502BA659",
  8512. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8513. "1FA62E331EDBC21C394792D2AB1100A7B432B013DF3F6FF4F99FCB33E0E1515F28890B3"
  8514. "EDB6E7189B630448B515CE4F8622A954CFE545735AAEA5134FCCDB2BD",
  8515. 5},
  8516. {"DFF1D77F2A671C5F36183726DB2341BE58FEAE1DA2DECED843240F7B502BA659",
  8517. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8518. "6CFF5C3BA86C69EA4B7376F31A9BCB4F74C1976089B2D9963DA2E5543E177769961764B"
  8519. "3AA9B2FFCB6EF947B6887A226E8D7C93E00C5ED0C1834FF0D0C2E6DA6",
  8520. 5},
  8521. {"DFF1D77F2A671C5F36183726DB2341BE58FEAE1DA2DECED843240F7B502BA659",
  8522. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8523. "0000000000000000000000000000000000000000000000000000000000000000123DDA8"
  8524. "328AF9C23A94C1FEECFD123BA4FB73476F0D594DCB65C6425BD186051",
  8525. 5},
  8526. {"DFF1D77F2A671C5F36183726DB2341BE58FEAE1DA2DECED843240F7B502BA659",
  8527. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8528. "00000000000000000000000000000000000000000000000000000000000000017615FBA"
  8529. "F5AE28864013C099742DEADB4DBA87F11AC6754F93780D5A1837CF197",
  8530. 5},
  8531. {"DFF1D77F2A671C5F36183726DB2341BE58FEAE1DA2DECED843240F7B502BA659",
  8532. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8533. "4A298DACAE57395A15D0795DDBFD1DCB564DA82B0F269BC70A74F8220429BA1D69E89B4"
  8534. "C5564D00349106B8497785DD7D1D713A8AE82B32FA79D5F7FC407D39B",
  8535. 5},
  8536. {"DFF1D77F2A671C5F36183726DB2341BE58FEAE1DA2DECED843240F7B502BA659",
  8537. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8538. "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F69E89B4"
  8539. "C5564D00349106B8497785DD7D1D713A8AE82B32FA79D5F7FC407D39B",
  8540. 5},
  8541. {"DFF1D77F2A671C5F36183726DB2341BE58FEAE1DA2DECED843240F7B502BA659",
  8542. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8543. "6CFF5C3BA86C69EA4B7376F31A9BCB4F74C1976089B2D9963DA2E5543E177769FFFFFFF"
  8544. "FFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141",
  8545. 5},
  8546. {"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC30",
  8547. "243F6A8885A308D313198A2E03707344A4093822299F31D0082EFA98EC4E6C89",
  8548. "6CFF5C3BA86C69EA4B7376F31A9BCB4F74C1976089B2D9963DA2E5543E17776969E89B4"
  8549. "C5564D00349106B8497785DD7D1D713A8AE82B32FA79D5F7FC407D39B",
  8550. 1},
  8551. // https://github.com/bitcoin/bips/pull/1225/commits/f7af1f73b287c14cf2f63afcb8d199feaf6ab5e1
  8552. {"53a1f6e454df1aa2776a2814a721372d6258050de330b3c6d10ee8f4e0dda343",
  8553. "7e584883b084ace0469c6962a9a7d2a9060e1f3c218ab40d32c77651482122bc",
  8554. "aab8fce3c4d7f359577a338676c9580d6946d7d8f899a48a4e1dcc63611e8f654eab719"
  8555. "2d43e6d6b9c7c95322338edbc5af21e88b43df36a989ba559d473f32a",
  8556. 0},
  8557. {"147c9c57132f6e7ecddba9800bb0c4449251c92a1e60371ee77557b6620f3ea3",
  8558. "325a644af47e8a5a2591cda0ab0723978537318f10e6a63d4eed783b96a71a4d",
  8559. "052aedffc554b41f52b521071793a6b88d6dbca9dba94cf34c83696de0c1ec35ca9c5ed"
  8560. "4ab28059bd606a4f3a657eec0bb96661d42921b5f50a95ad33675b54f",
  8561. 0},
  8562. {"e4d810fd50586274face62b8a807eb9719cef49c04177cc6b76a9a4251d5450e",
  8563. "6ffd256e108685b41831385f57eebf2fca041bc6b5e607ea11b3e03d4cf9d9ba",
  8564. "f78cf3fe8410326ba95b7119cac657b2d86a461dc0767d7b68cb516f3d8bac64ed027fb"
  8565. "710b5962d01c42dadaf4dec5731371c6c7850854cc68054eb8f4de80b",
  8566. 0},
  8567. {"91b64d5324723a985170e4dc5a0f84c041804f2cd12660fa5dec09fc21783605",
  8568. "9f90136737540ccc18707e1fd398ad222a1a7e4dd65cbfd22dbe4660191efa58",
  8569. "69599256a182e89be95c098b03200b958220ee400c42779cd05cdbf9fa2d5c8060a48c1"
  8570. "463c9fadf6aea0395b70ebf937fbae0dd2d83185c1d9f675dac8d06f5",
  8571. 0},
  8572. {"75169f4001aa68f15bbed28b218df1d0a62cbbcf1188c6665110c293c907b831",
  8573. "835c9ab6084ed9a8ae9b7cda21e0aa797aca3b76a54bd1e3c7db093f6c57e23f",
  8574. "882a50af428ea47ee84462fcb481033db9c8b1ea6f2b77c9a8e4d8135a1c0771ee8dbcd"
  8575. "24ea671576ab441bdb2ab3f85f20675ca4c59889bab719b062abfd064",
  8576. 0},
  8577. {"0f63ca2c7639b9bb4be0465cc0aa3ee78a0761ba5f5f7d6ff8eab340f09da561",
  8578. "df1cca638283c667084b8ffe6bf6e116cc5a53cf7ae1202c5fee45a9085f1ba5",
  8579. "1ec324f9ccc982286a10017daa22ead5087d9f2eff58dd6173d7d608eb959be6be2f3df"
  8580. "0a25a7890c99a9259c9eab33d71a6c163cabb442aa3a5e5d613611420",
  8581. 0},
  8582. {"053690babeabbb7850c32eead0acf8df990ced79f7a31e358fabf2658b4bc587",
  8583. "30319859ca79ea1b7a9782e9daebc46e4ca4ca2bc04c9c53b2ec87fa83a526bd",
  8584. "7e6c212ebe04e8241bee0151b0d3230aa22dec9dbdd8197ebd3ff616b9e4b47dccee08a"
  8585. "32a52a77d60587a77e7d7b5d1d113235d38921740ffdbe795459637ff",
  8586. 0},
  8587. };
  8588. int res = 0;
  8589. uint8_t pub_key[32] = {0};
  8590. uint8_t digest[32] = {0};
  8591. uint8_t sig[64] = {0};
  8592. for (size_t i = 0; i < sizeof(tests) / sizeof(*tests); i++) {
  8593. memcpy(pub_key, fromhex(tests[i].pub_key), 32);
  8594. memcpy(digest, fromhex(tests[i].digest), 32);
  8595. memcpy(sig, fromhex(tests[i].sig), 64);
  8596. res = zkp_bip340_verify_digest(pub_key, sig, digest);
  8597. ck_assert_int_eq(res, tests[i].res);
  8598. }
  8599. }
  8600. END_TEST
  8601. START_TEST(test_zkp_bip340_tweak) {
  8602. static struct {
  8603. const char *root_hash;
  8604. const char *internal_priv;
  8605. const char *output_priv;
  8606. const char *internal_pub;
  8607. const char *output_pub;
  8608. } tests[] = {
  8609. // https://github.com/bitcoin/bips/blob/master/bip-0086/
  8610. {NULL, "41f41d69260df4cf277826a9b65a3717e4eeddbeedf637f212ca096576479361",
  8611. "eaac016f36e8c18347fbacf05ab7966708fbfce7ce3bf1dc32a09dd0645db038",
  8612. "cc8a4bc64d897bddc5fbc2f670f7a8ba0b386779106cf1223c6fc5d7cd6fc115",
  8613. "a60869f0dbcf1dc659c9cecbaf8050135ea9e8cdc487053f1dc6880949dc684c"},
  8614. {NULL, "86c68ac0ed7df88cbdd08a847c6d639f87d1234d40503abf3ac178ef7ddc05dd",
  8615. "0b6f18573f75c454efb43d2bfc7c91f7f88cb802c45a7821e820402fcf2836d3",
  8616. "83dfe85a3151d2517290da461fe2815591ef69f2b18a2ce63f01697a8b313145",
  8617. "a82f29944d65b86ae6b5e5cc75e294ead6c59391a1edc5e016e3498c67fc7bbb"},
  8618. {NULL, "6ccbca4a02ac648702dde463d9c1b0d328a4df1e068ef9dc2bc788b33a4f0412",
  8619. "c3074682f4c54d9801da58a52aaf0e28c089d5f8c6847dc8829734bbe3f60647",
  8620. "399f1b2f4393f29a18c937859c5dd8a77350103157eb880f02e8c08214277cef",
  8621. "882d74e5d0572d5a816cef0041a96b6c1de832f6f9676d9605c44d5e9a97d3dc"},
  8622. // https://github.com/bitcoin-core/btcdeb/blob/master/doc/tapscript-example-with-tap.md
  8623. {"41646f8c1fe2a96ddad7f5471bc4fee7da98794ef8c45a4f4fc6a559d60c9f6b",
  8624. "1229101a0fcf2104e8808dab35661134aa5903867d44deb73ce1c7e4eb925be8",
  8625. "4fe6b3e5fbd61870577980ad5e4e13080776069f0fb3c1e353572e0c4993abc1",
  8626. "f30544d6009c8d8d94f5d030b2e844b1a3ca036255161c479db1cca5b374dd1c",
  8627. "a5ba0871796eb49fb4caa6bf78e675b9455e2d66e751676420f8381d5dda8951"},
  8628. // https://github.com/bitcoin/bips/pull/1225/commits/f7af1f73b287c14cf2f63afcb8d199feaf6ab5e1
  8629. {NULL, "6b973d88838f27366ed61c9ad6367663045cb456e28335c109e30717ae0c6baa",
  8630. "2405b971772ad26915c8dcdf10f238753a9b837e5f8e6a86fd7c0cce5b7296d9",
  8631. "d6889cb081036e0faefa3a35157ad71086b123b2b144b649798b494c300a961d",
  8632. "53a1f6e454df1aa2776a2814a721372d6258050de330b3c6d10ee8f4e0dda343"},
  8633. {"5b75adecf53548f3ec6ad7d78383bf84cc57b55a3127c72b9a2481752dd88b21",
  8634. "1e4da49f6aaf4e5cd175fe08a32bb5cb4863d963921255f33d3bc31e1343907f",
  8635. "ea260c3b10e60f6de018455cd0278f2f5b7e454be1999572789e6a9565d26080",
  8636. "187791b6f712a8ea41c8ecdd0ee77fab3e85263b37e1ec18a3651926b3a6cf27",
  8637. "147c9c57132f6e7ecddba9800bb0c4449251c92a1e60371ee77557b6620f3ea3"},
  8638. {"c525714a7f49c28aedbbba78c005931a81c234b2f6c99a73e4d06082adc8bf2b",
  8639. "d3c7af07da2d54f7a7735d3d0fc4f0a73164db638b2f2f7c43f711f6d4aa7e64",
  8640. "97323385e57015b75b0339a549c56a948eb961555973f0951f555ae6039ef00d",
  8641. "93478e9488f956df2396be2ce6c5cced75f900dfa18e7dabd2428aae78451820",
  8642. "e4d810fd50586274face62b8a807eb9719cef49c04177cc6b76a9a4251d5450e"},
  8643. {"ccbd66c6f7e8fdab47b3a486f59d28262be857f30d4773f2d5ea47f7761ce0e2",
  8644. "f36bb07a11e469ce941d16b63b11b9b9120a84d9d87cff2c84a8d4affb438f4e",
  8645. "a8e7aa924f0d58854185a490e6c41f6efb7b675c0f3331b7f14b549400b4d501",
  8646. "e0dfe2300b0dd746a3f8674dfd4525623639042569d829c7f0eed9602d263e6f",
  8647. "91b64d5324723a985170e4dc5a0f84c041804f2cd12660fa5dec09fc21783605"},
  8648. {"2f6b2c5397b6d68ca18e09a3f05161668ffe93a988582d55c6f07bd5b3329def",
  8649. "415cfe9c15d9cea27d8104d5517c06e9de48e2f986b695e4f5ffebf230e725d8",
  8650. "241c14f2639d0d7139282aa6abde28dd8a067baa9d633e4e7230287ec2d02901",
  8651. "55adf4e8967fbd2e29f20ac896e60c3b0f1d5b0efa9d34941b5958c7b0a0312d",
  8652. "75169f4001aa68f15bbed28b218df1d0a62cbbcf1188c6665110c293c907b831"},
  8653. {"f3004d6c183e038105d436db1424f321613366cbb7b05939bf05d763a9ebb962",
  8654. "c7b0e81f0a9a0b0499e112279d718cca98e79a12e2f137c72ae5b213aad0d103",
  8655. "9822270935e156a1b9b28940e7b94a06934a51ddabdd49dd43e8010adc98dfa3",
  8656. "ee4fe085983462a184015d1f782d6a5f8b9c2b60130aff050ce221ecf3786592",
  8657. "0f63ca2c7639b9bb4be0465cc0aa3ee78a0761ba5f5f7d6ff8eab340f09da561"},
  8658. {"d9c2c32808b41c0301d876d49c0af72e1d98e84b99ca9b4bb67fea1a7424b755",
  8659. "77863416be0d0665e517e1c375fd6f75839544eca553675ef7fdf4949518ebaa",
  8660. "8e575b74b70d573b05558883743a72d1ccc326b4c299ea3412a29d3b83e801e4",
  8661. "f9f400803e683727b14f463836e1e78e1c64417638aa066919291a225f0e8dd8",
  8662. "053690babeabbb7850c32eead0acf8df990ced79f7a31e358fabf2658b4bc587"},
  8663. };
  8664. int res = 0;
  8665. uint8_t internal_priv[32] = {0};
  8666. uint8_t output_priv[32] = {0};
  8667. uint8_t internal_pub[32] = {0};
  8668. uint8_t output_pub[32] = {0};
  8669. uint8_t result[32] = {0};
  8670. for (size_t i = 0; i < sizeof(tests) / sizeof(*tests); i++) {
  8671. memcpy(internal_priv, fromhex(tests[i].internal_priv), 32);
  8672. memcpy(output_priv, fromhex(tests[i].output_priv), 32);
  8673. memcpy(internal_pub, fromhex(tests[i].internal_pub), 32);
  8674. memcpy(output_pub, fromhex(tests[i].output_pub), 32);
  8675. const uint8_t *root_hash = NULL;
  8676. if (tests[i].root_hash != NULL) {
  8677. root_hash = fromhex(tests[i].root_hash);
  8678. }
  8679. res = zkp_bip340_get_public_key(internal_priv, result);
  8680. ck_assert_int_eq(res, 0);
  8681. ck_assert_mem_eq(internal_pub, result, 32);
  8682. res = zkp_bip340_get_public_key(output_priv, result);
  8683. ck_assert_int_eq(res, 0);
  8684. ck_assert_mem_eq(output_pub, result, 32);
  8685. res = zkp_bip340_tweak_private_key(internal_priv, root_hash, result);
  8686. ck_assert_int_eq(res, 0);
  8687. ck_assert_mem_eq(output_priv, result, 32);
  8688. res = zkp_bip340_tweak_public_key(internal_pub, root_hash, result);
  8689. ck_assert_int_eq(res, 0);
  8690. ck_assert_mem_eq(output_pub, result, 32);
  8691. }
  8692. }
  8693. END_TEST
  8694. START_TEST(test_zkp_bip340_verify_publickey) {
  8695. static struct {
  8696. const char *public_key;
  8697. const int result;
  8698. } tests[] = {
  8699. // Test vectors 0, 5 and 14 from
  8700. // https://github.com/bitcoin/bips/blob/afa13249ed45826c2d7086714026c9bc1ccbf963/bip-0340/test-vectors.csv
  8701. {"F9308A019258C31049344F85F89D5229B531C845836F99B08601F113BCE036F9", 0},
  8702. {"EEFDEA4CDB677750A420FEE807EACF21EB9898AE79B9768766E4FAA04A2D4A34", 1},
  8703. {"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC30", 1}};
  8704. int result = 0;
  8705. uint8_t public_key[32] = {0};
  8706. for (size_t i = 0; i < sizeof(tests) / sizeof(*tests); i++) {
  8707. memcpy(public_key, fromhex(tests[i].public_key), 32);
  8708. result = zkp_bip340_verify_publickey(public_key);
  8709. ck_assert_int_eq(result, tests[i].result);
  8710. }
  8711. }
  8712. END_TEST
  8713. static int my_strncasecmp(const char *s1, const char *s2, size_t n) {
  8714. size_t i = 0;
  8715. while (i < n) {
  8716. char c1 = s1[i];
  8717. char c2 = s2[i];
  8718. if (c1 >= 'A' && c1 <= 'Z') c1 = (c1 - 'A') + 'a';
  8719. if (c2 >= 'A' && c2 <= 'Z') c2 = (c2 - 'A') + 'a';
  8720. if (c1 < c2) return -1;
  8721. if (c1 > c2) return 1;
  8722. if (c1 == 0) return 0;
  8723. ++i;
  8724. }
  8725. return 0;
  8726. }
  8727. #include "test_check_cashaddr.h"
  8728. #include "test_check_segwit.h"
  8729. #if USE_CARDANO
  8730. #include "test_check_cardano.h"
  8731. #endif
  8732. #if USE_MONERO
  8733. #include "test_check_monero.h"
  8734. #endif
  8735. // define test suite and cases
  8736. Suite *test_suite(void) {
  8737. Suite *s = suite_create("trezor-crypto");
  8738. TCase *tc;
  8739. tc = tcase_create("bignum");
  8740. tcase_add_test(tc, test_bignum_read_be);
  8741. tcase_add_test(tc, test_bignum_write_be);
  8742. tcase_add_test(tc, test_bignum_is_equal);
  8743. tcase_add_test(tc, test_bignum_zero);
  8744. tcase_add_test(tc, test_bignum_is_zero);
  8745. tcase_add_test(tc, test_bignum_one);
  8746. tcase_add_test(tc, test_bignum_read_le);
  8747. tcase_add_test(tc, test_bignum_write_le);
  8748. tcase_add_test(tc, test_bignum_read_uint32);
  8749. tcase_add_test(tc, test_bignum_read_uint64);
  8750. tcase_add_test(tc, test_bignum_write_uint32);
  8751. tcase_add_test(tc, test_bignum_write_uint64);
  8752. tcase_add_test(tc, test_bignum_copy);
  8753. tcase_add_test(tc, test_bignum_is_even);
  8754. tcase_add_test(tc, test_bignum_is_odd);
  8755. tcase_add_test(tc, test_bignum_bitcount);
  8756. tcase_add_test(tc, test_bignum_digitcount);
  8757. tcase_add_test(tc, test_bignum_is_less);
  8758. tcase_add_test(tc, test_bignum_format);
  8759. tcase_add_test(tc, test_bignum_format_uint64);
  8760. tcase_add_test(tc, test_bignum_sqrt);
  8761. suite_add_tcase(s, tc);
  8762. tc = tcase_create("base32");
  8763. tcase_add_test(tc, test_base32_rfc4648);
  8764. suite_add_tcase(s, tc);
  8765. tc = tcase_create("base58");
  8766. tcase_add_test(tc, test_base58);
  8767. suite_add_tcase(s, tc);
  8768. tc = tcase_create("bignum_divmod");
  8769. tcase_add_test(tc, test_bignum_divmod);
  8770. suite_add_tcase(s, tc);
  8771. tc = tcase_create("bip32");
  8772. tcase_add_test(tc, test_bip32_vector_1);
  8773. tcase_add_test(tc, test_bip32_vector_2);
  8774. tcase_add_test(tc, test_bip32_vector_3);
  8775. tcase_add_test(tc, test_bip32_vector_4);
  8776. tcase_add_test(tc, test_bip32_compare);
  8777. tcase_add_test(tc, test_bip32_optimized);
  8778. tcase_add_test(tc, test_bip32_cache_1);
  8779. tcase_add_test(tc, test_bip32_cache_2);
  8780. suite_add_tcase(s, tc);
  8781. tc = tcase_create("bip32-nist");
  8782. tcase_add_test(tc, test_bip32_nist_seed);
  8783. tcase_add_test(tc, test_bip32_nist_vector_1);
  8784. tcase_add_test(tc, test_bip32_nist_vector_2);
  8785. tcase_add_test(tc, test_bip32_nist_compare);
  8786. tcase_add_test(tc, test_bip32_nist_repeat);
  8787. suite_add_tcase(s, tc);
  8788. tc = tcase_create("bip32-ed25519");
  8789. tcase_add_test(tc, test_bip32_ed25519_vector_1);
  8790. tcase_add_test(tc, test_bip32_ed25519_vector_2);
  8791. suite_add_tcase(s, tc);
  8792. tc = tcase_create("bip32-ecdh");
  8793. tcase_add_test(tc, test_bip32_ecdh_nist256p1);
  8794. tcase_add_test(tc, test_bip32_ecdh_curve25519);
  8795. tcase_add_test(tc, test_bip32_ecdh_errors);
  8796. suite_add_tcase(s, tc);
  8797. tc = tcase_create("bip32-decred");
  8798. tcase_add_test(tc, test_bip32_decred_vector_1);
  8799. tcase_add_test(tc, test_bip32_decred_vector_2);
  8800. suite_add_tcase(s, tc);
  8801. tc = tcase_create("ecdsa");
  8802. tcase_add_test(tc, test_ecdsa_get_public_key33);
  8803. tcase_add_test(tc, test_ecdsa_get_public_key65);
  8804. tcase_add_test(tc, test_ecdsa_recover_pub_from_sig);
  8805. tcase_add_test(tc, test_ecdsa_verify_digest);
  8806. tcase_add_test(tc, test_zkp_ecdsa_get_public_key33);
  8807. tcase_add_test(tc, test_zkp_ecdsa_get_public_key65);
  8808. tcase_add_test(tc, test_zkp_ecdsa_recover_pub_from_sig);
  8809. tcase_add_test(tc, test_zkp_ecdsa_verify_digest);
  8810. #if USE_RFC6979
  8811. tcase_add_test(tc, test_ecdsa_sign_digest_deterministic);
  8812. tcase_add_test(tc, test_zkp_ecdsa_sign_digest_deterministic);
  8813. #endif
  8814. suite_add_tcase(s, tc);
  8815. tc = tcase_create("rfc6979");
  8816. tcase_add_test(tc, test_rfc6979);
  8817. suite_add_tcase(s, tc);
  8818. tc = tcase_create("address");
  8819. tcase_add_test(tc, test_address);
  8820. suite_add_tcase(s, tc);
  8821. tc = tcase_create("address_decode");
  8822. tcase_add_test(tc, test_address_decode);
  8823. suite_add_tcase(s, tc);
  8824. tc = tcase_create("ethereum_address");
  8825. tcase_add_test(tc, test_ethereum_address);
  8826. suite_add_tcase(s, tc);
  8827. tc = tcase_create("rsk_address");
  8828. tcase_add_test(tc, test_rsk_address);
  8829. suite_add_tcase(s, tc);
  8830. tc = tcase_create("wif");
  8831. tcase_add_test(tc, test_wif);
  8832. suite_add_tcase(s, tc);
  8833. tc = tcase_create("ecdsa_der");
  8834. tcase_add_test(tc, test_ecdsa_der);
  8835. suite_add_tcase(s, tc);
  8836. tc = tcase_create("aes");
  8837. tcase_add_test(tc, test_aes);
  8838. suite_add_tcase(s, tc);
  8839. tc = tcase_create("sha2");
  8840. tcase_add_test(tc, test_sha1);
  8841. tcase_add_test(tc, test_sha256);
  8842. tcase_add_test(tc, test_sha512);
  8843. suite_add_tcase(s, tc);
  8844. tc = tcase_create("sha3");
  8845. tcase_add_test(tc, test_sha3_256);
  8846. tcase_add_test(tc, test_sha3_512);
  8847. tcase_add_test(tc, test_keccak_256);
  8848. suite_add_tcase(s, tc);
  8849. tc = tcase_create("blake");
  8850. tcase_add_test(tc, test_blake256);
  8851. suite_add_tcase(s, tc);
  8852. tc = tcase_create("blake2");
  8853. tcase_add_test(tc, test_blake2b);
  8854. tcase_add_test(tc, test_blake2bp);
  8855. tcase_add_test(tc, test_blake2s);
  8856. suite_add_tcase(s, tc);
  8857. tc = tcase_create("chacha_drbg");
  8858. tcase_add_test(tc, test_chacha_drbg);
  8859. suite_add_tcase(s, tc);
  8860. tc = tcase_create("pbkdf2");
  8861. tcase_add_test(tc, test_pbkdf2_hmac_sha256);
  8862. tcase_add_test(tc, test_pbkdf2_hmac_sha512);
  8863. suite_add_tcase(s, tc);
  8864. tc = tcase_create("hmac_drbg");
  8865. tcase_add_test(tc, test_hmac_drbg);
  8866. suite_add_tcase(s, tc);
  8867. tc = tcase_create("bip39");
  8868. tcase_add_test(tc, test_mnemonic);
  8869. tcase_add_test(tc, test_mnemonic_check);
  8870. tcase_add_test(tc, test_mnemonic_to_bits);
  8871. tcase_add_test(tc, test_mnemonic_find_word);
  8872. suite_add_tcase(s, tc);
  8873. tc = tcase_create("slip39");
  8874. tcase_add_test(tc, test_slip39_get_word);
  8875. tcase_add_test(tc, test_slip39_word_index);
  8876. tcase_add_test(tc, test_slip39_word_completion_mask);
  8877. tcase_add_test(tc, test_slip39_sequence_to_word);
  8878. tcase_add_test(tc, test_slip39_word_completion);
  8879. suite_add_tcase(s, tc);
  8880. tc = tcase_create("shamir");
  8881. tcase_add_test(tc, test_shamir);
  8882. suite_add_tcase(s, tc);
  8883. tc = tcase_create("pubkey_validity");
  8884. tcase_add_test(tc, test_pubkey_validity);
  8885. suite_add_tcase(s, tc);
  8886. tc = tcase_create("pubkey_uncompress");
  8887. tcase_add_test(tc, test_pubkey_uncompress);
  8888. suite_add_tcase(s, tc);
  8889. tc = tcase_create("codepoints");
  8890. tcase_add_test(tc, test_codepoints_secp256k1);
  8891. tcase_add_test(tc, test_codepoints_nist256p1);
  8892. suite_add_tcase(s, tc);
  8893. tc = tcase_create("mult_border_cases");
  8894. tcase_add_test(tc, test_mult_border_cases_secp256k1);
  8895. tcase_add_test(tc, test_mult_border_cases_nist256p1);
  8896. suite_add_tcase(s, tc);
  8897. tc = tcase_create("scalar_mult");
  8898. tcase_add_test(tc, test_scalar_mult_secp256k1);
  8899. tcase_add_test(tc, test_scalar_mult_nist256p1);
  8900. suite_add_tcase(s, tc);
  8901. tc = tcase_create("point_mult");
  8902. tcase_add_test(tc, test_point_mult_secp256k1);
  8903. tcase_add_test(tc, test_point_mult_nist256p1);
  8904. suite_add_tcase(s, tc);
  8905. tc = tcase_create("scalar_point_mult");
  8906. tcase_add_test(tc, test_scalar_point_mult_secp256k1);
  8907. tcase_add_test(tc, test_scalar_point_mult_nist256p1);
  8908. suite_add_tcase(s, tc);
  8909. tc = tcase_create("ed25519");
  8910. tcase_add_test(tc, test_ed25519);
  8911. suite_add_tcase(s, tc);
  8912. tc = tcase_create("ed25519_keccak");
  8913. tcase_add_test(tc, test_ed25519_keccak);
  8914. suite_add_tcase(s, tc);
  8915. tc = tcase_create("ed25519_cosi");
  8916. tcase_add_test(tc, test_ed25519_cosi);
  8917. suite_add_tcase(s, tc);
  8918. tc = tcase_create("ed25519_modm");
  8919. tcase_add_test(tc, test_ed25519_modl_add);
  8920. tcase_add_test(tc, test_ed25519_modl_neg);
  8921. tcase_add_test(tc, test_ed25519_modl_sub);
  8922. suite_add_tcase(s, tc);
  8923. #if USE_MONERO
  8924. tc = tcase_create("ed25519_ge");
  8925. tcase_add_test(tc, test_ge25519_double_scalarmult_vartime2);
  8926. suite_add_tcase(s, tc);
  8927. #endif
  8928. tc = tcase_create("script");
  8929. tcase_add_test(tc, test_output_script);
  8930. suite_add_tcase(s, tc);
  8931. tc = tcase_create("ethereum_pubkeyhash");
  8932. tcase_add_test(tc, test_ethereum_pubkeyhash);
  8933. suite_add_tcase(s, tc);
  8934. tc = tcase_create("nem_address");
  8935. tcase_add_test(tc, test_nem_address);
  8936. suite_add_tcase(s, tc);
  8937. tc = tcase_create("nem_encryption");
  8938. tcase_add_test(tc, test_nem_derive);
  8939. tcase_add_test(tc, test_nem_cipher);
  8940. suite_add_tcase(s, tc);
  8941. tc = tcase_create("nem_transaction");
  8942. tcase_add_test(tc, test_nem_transaction_transfer);
  8943. tcase_add_test(tc, test_nem_transaction_multisig);
  8944. tcase_add_test(tc, test_nem_transaction_provision_namespace);
  8945. tcase_add_test(tc, test_nem_transaction_mosaic_creation);
  8946. tcase_add_test(tc, test_nem_transaction_mosaic_supply_change);
  8947. tcase_add_test(tc, test_nem_transaction_aggregate_modification);
  8948. suite_add_tcase(s, tc);
  8949. tc = tcase_create("multibyte_address");
  8950. tcase_add_test(tc, test_multibyte_address);
  8951. suite_add_tcase(s, tc);
  8952. tc = tcase_create("rc4");
  8953. tcase_add_test(tc, test_rc4_rfc6229);
  8954. suite_add_tcase(s, tc);
  8955. tc = tcase_create("segwit");
  8956. tcase_add_test(tc, test_segwit);
  8957. suite_add_tcase(s, tc);
  8958. tc = tcase_create("cashaddr");
  8959. tcase_add_test(tc, test_cashaddr);
  8960. suite_add_tcase(s, tc);
  8961. tc = tcase_create("compress_coords");
  8962. tcase_add_test(tc, test_compress_coords);
  8963. suite_add_tcase(s, tc);
  8964. tc = tcase_create("zkp_bip340");
  8965. tcase_add_test(tc, test_zkp_bip340_sign);
  8966. tcase_add_test(tc, test_zkp_bip340_verify);
  8967. tcase_add_test(tc, test_zkp_bip340_tweak);
  8968. tcase_add_test(tc, test_zkp_bip340_verify_publickey);
  8969. suite_add_tcase(s, tc);
  8970. #if USE_CARDANO
  8971. tc = tcase_create("bip32-cardano");
  8972. tcase_add_test(tc, test_bip32_cardano_hdnode_vector_1);
  8973. tcase_add_test(tc, test_bip32_cardano_hdnode_vector_2);
  8974. tcase_add_test(tc, test_bip32_cardano_hdnode_vector_3);
  8975. tcase_add_test(tc, test_bip32_cardano_hdnode_vector_4);
  8976. tcase_add_test(tc, test_bip32_cardano_hdnode_vector_5);
  8977. tcase_add_test(tc, test_bip32_cardano_hdnode_vector_6);
  8978. tcase_add_test(tc, test_bip32_cardano_hdnode_vector_7);
  8979. tcase_add_test(tc, test_bip32_cardano_hdnode_vector_8);
  8980. tcase_add_test(tc, test_bip32_cardano_hdnode_vector_9);
  8981. tcase_add_test(tc, test_cardano_ledger_vector_1);
  8982. tcase_add_test(tc, test_cardano_ledger_vector_2);
  8983. tcase_add_test(tc, test_cardano_ledger_vector_3);
  8984. tcase_add_test(tc, test_ed25519_cardano_sign_vectors);
  8985. suite_add_tcase(s, tc);
  8986. #endif
  8987. #if USE_MONERO
  8988. tc = tcase_create("xmr_base58");
  8989. tcase_add_test(tc, test_xmr_base58);
  8990. suite_add_tcase(s, tc);
  8991. tc = tcase_create("xmr_crypto");
  8992. tcase_add_test(tc, test_xmr_getset256_modm);
  8993. tcase_add_test(tc, test_xmr_cmp256_modm);
  8994. tcase_add_test(tc, test_xmr_copy_check_modm);
  8995. tcase_add_test(tc, test_xmr_mulsub256_modm);
  8996. tcase_add_test(tc, test_xmr_muladd256_modm);
  8997. tcase_add_test(tc, test_xmr_curve25519_set);
  8998. tcase_add_test(tc, test_xmr_curve25519_consts);
  8999. tcase_add_test(tc, test_xmr_curve25519_tests);
  9000. tcase_add_test(tc, test_xmr_curve25519_expand_reduce);
  9001. tcase_add_test(tc, test_xmr_ge25519_base);
  9002. tcase_add_test(tc, test_xmr_ge25519_check);
  9003. tcase_add_test(tc, test_xmr_ge25519_scalarmult_base_wrapper);
  9004. tcase_add_test(tc, test_xmr_ge25519_scalarmult);
  9005. tcase_add_test(tc, test_xmr_ge25519_ops);
  9006. suite_add_tcase(s, tc);
  9007. tc = tcase_create("xmr_xmr");
  9008. tcase_add_test(tc, test_xmr_check_point);
  9009. tcase_add_test(tc, test_xmr_h);
  9010. tcase_add_test(tc, test_xmr_fast_hash);
  9011. tcase_add_test(tc, test_xmr_hasher);
  9012. tcase_add_test(tc, test_xmr_hash_to_scalar);
  9013. tcase_add_test(tc, test_xmr_hash_to_ec);
  9014. tcase_add_test(tc, test_xmr_derivation_to_scalar);
  9015. tcase_add_test(tc, test_xmr_generate_key_derivation);
  9016. tcase_add_test(tc, test_xmr_derive_private_key);
  9017. tcase_add_test(tc, test_xmr_derive_public_key);
  9018. tcase_add_test(tc, test_xmr_add_keys2);
  9019. tcase_add_test(tc, test_xmr_add_keys3);
  9020. tcase_add_test(tc, test_xmr_get_subaddress_secret_key);
  9021. tcase_add_test(tc, test_xmr_gen_c);
  9022. tcase_add_test(tc, test_xmr_varint);
  9023. suite_add_tcase(s, tc);
  9024. #endif
  9025. return s;
  9026. }
  9027. // run suite
  9028. int main(void) {
  9029. assert(zkp_context_init() == 0);
  9030. int number_failed;
  9031. Suite *s = test_suite();
  9032. SRunner *sr = srunner_create(s);
  9033. srunner_run_all(sr, CK_VERBOSE);
  9034. number_failed = srunner_ntests_failed(sr);
  9035. srunner_free(sr);
  9036. if (number_failed == 0) {
  9037. printf("PASSED ALL TESTS\n");
  9038. }
  9039. return number_failed;
  9040. }