Coverage Report

Created: 2025-09-19 18:31

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/root/bitcoin/src/crypto/siphash.cpp
Line
Count
Source
1
// Copyright (c) 2016-present The Bitcoin Core developers
2
// Distributed under the MIT software license, see the accompanying
3
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4
5
#include <crypto/siphash.h>
6
7
#include <bit>
8
9
1.05G
#define SIPROUND do { \
10
1.05G
    v0 += v1; v1 = std::rotl(v1, 13); v1 ^= v0; \
11
1.05G
    v0 = std::rotl(v0, 32); \
12
1.05G
    v2 += v3; v3 = std::rotl(v3, 16); v3 ^= v2; \
13
1.05G
    v0 += v3; v3 = std::rotl(v3, 21); v3 ^= v0; \
14
1.05G
    v2 += v1; v1 = std::rotl(v1, 17); v1 ^= v2; \
15
1.05G
    v2 = std::rotl(v2, 32); \
16
1.05G
} while (0)
17
18
CSipHasher::CSipHasher(uint64_t k0, uint64_t k1)
19
0
{
20
0
    v[0] = 0x736f6d6570736575ULL ^ k0;
21
0
    v[1] = 0x646f72616e646f6dULL ^ k1;
22
0
    v[2] = 0x6c7967656e657261ULL ^ k0;
23
0
    v[3] = 0x7465646279746573ULL ^ k1;
24
0
    count = 0;
25
0
    tmp = 0;
26
0
}
27
28
CSipHasher& CSipHasher::Write(uint64_t data)
29
0
{
30
0
    uint64_t v0 = v[0], v1 = v[1], v2 = v[2], v3 = v[3];
31
32
0
    assert(count % 8 == 0);
33
34
0
    v3 ^= data;
35
0
    SIPROUND;
36
0
    SIPROUND;
37
0
    v0 ^= data;
38
39
0
    v[0] = v0;
40
0
    v[1] = v1;
41
0
    v[2] = v2;
42
0
    v[3] = v3;
43
44
0
    count += 8;
45
0
    return *this;
46
0
}
47
48
CSipHasher& CSipHasher::Write(std::span<const unsigned char> data)
49
0
{
50
0
    uint64_t v0 = v[0], v1 = v[1], v2 = v[2], v3 = v[3];
51
0
    uint64_t t = tmp;
52
0
    uint8_t c = count;
53
54
0
    while (data.size() > 0) {
55
0
        t |= uint64_t{data.front()} << (8 * (c % 8));
56
0
        c++;
57
0
        if ((c & 7) == 0) {
58
0
            v3 ^= t;
59
0
            SIPROUND;
60
0
            SIPROUND;
61
0
            v0 ^= t;
62
0
            t = 0;
63
0
        }
64
0
        data = data.subspan(1);
65
0
    }
66
67
0
    v[0] = v0;
68
0
    v[1] = v1;
69
0
    v[2] = v2;
70
0
    v[3] = v3;
71
0
    count = c;
72
0
    tmp = t;
73
74
0
    return *this;
75
0
}
76
77
uint64_t CSipHasher::Finalize() const
78
0
{
79
0
    uint64_t v0 = v[0], v1 = v[1], v2 = v[2], v3 = v[3];
80
81
0
    uint64_t t = tmp | (((uint64_t)count) << 56);
82
83
0
    v3 ^= t;
84
0
    SIPROUND;
85
0
    SIPROUND;
86
0
    v0 ^= t;
87
0
    v2 ^= 0xFF;
88
0
    SIPROUND;
89
0
    SIPROUND;
90
0
    SIPROUND;
91
0
    SIPROUND;
92
0
    return v0 ^ v1 ^ v2 ^ v3;
93
0
}
94
95
uint64_t SipHashUint256(uint64_t k0, uint64_t k1, const uint256& val)
96
17.8M
{
97
    /* Specialized implementation for efficiency */
98
17.8M
    uint64_t d = val.GetUint64(0);
99
100
17.8M
    uint64_t v0 = 0x736f6d6570736575ULL ^ k0;
101
17.8M
    uint64_t v1 = 0x646f72616e646f6dULL ^ k1;
102
17.8M
    uint64_t v2 = 0x6c7967656e657261ULL ^ k0;
103
17.8M
    uint64_t v3 = 0x7465646279746573ULL ^ k1 ^ d;
104
105
17.8M
    SIPROUND;
106
17.8M
    SIPROUND;
107
17.8M
    v0 ^= d;
108
17.8M
    d = val.GetUint64(1);
109
17.8M
    v3 ^= d;
110
17.8M
    SIPROUND;
111
17.8M
    SIPROUND;
112
17.8M
    v0 ^= d;
113
17.8M
    d = val.GetUint64(2);
114
17.8M
    v3 ^= d;
115
17.8M
    SIPROUND;
116
17.8M
    SIPROUND;
117
17.8M
    v0 ^= d;
118
17.8M
    d = val.GetUint64(3);
119
17.8M
    v3 ^= d;
120
17.8M
    SIPROUND;
121
17.8M
    SIPROUND;
122
17.8M
    v0 ^= d;
123
17.8M
    v3 ^= (uint64_t{4}) << 59;
124
17.8M
    SIPROUND;
125
17.8M
    SIPROUND;
126
17.8M
    v0 ^= (uint64_t{4}) << 59;
127
17.8M
    v2 ^= 0xFF;
128
17.8M
    SIPROUND;
129
17.8M
    SIPROUND;
130
17.8M
    SIPROUND;
131
17.8M
    SIPROUND;
132
17.8M
    return v0 ^ v1 ^ v2 ^ v3;
133
17.8M
}
134
135
uint64_t SipHashUint256Extra(uint64_t k0, uint64_t k1, const uint256& val, uint32_t extra)
136
57.1M
{
137
    /* Specialized implementation for efficiency */
138
57.1M
    uint64_t d = val.GetUint64(0);
139
140
57.1M
    uint64_t v0 = 0x736f6d6570736575ULL ^ k0;
141
57.1M
    uint64_t v1 = 0x646f72616e646f6dULL ^ k1;
142
57.1M
    uint64_t v2 = 0x6c7967656e657261ULL ^ k0;
143
57.1M
    uint64_t v3 = 0x7465646279746573ULL ^ k1 ^ d;
144
145
57.1M
    SIPROUND;
146
57.1M
    SIPROUND;
147
57.1M
    v0 ^= d;
148
57.1M
    d = val.GetUint64(1);
149
57.1M
    v3 ^= d;
150
57.1M
    SIPROUND;
151
57.1M
    SIPROUND;
152
57.1M
    v0 ^= d;
153
57.1M
    d = val.GetUint64(2);
154
57.1M
    v3 ^= d;
155
57.1M
    SIPROUND;
156
57.1M
    SIPROUND;
157
57.1M
    v0 ^= d;
158
57.1M
    d = val.GetUint64(3);
159
57.1M
    v3 ^= d;
160
57.1M
    SIPROUND;
161
57.1M
    SIPROUND;
162
57.1M
    v0 ^= d;
163
57.1M
    d = ((uint64_t{36}) << 56) | extra;
164
57.1M
    v3 ^= d;
165
57.1M
    SIPROUND;
166
57.1M
    SIPROUND;
167
57.1M
    v0 ^= d;
168
57.1M
    v2 ^= 0xFF;
169
57.1M
    SIPROUND;
170
57.1M
    SIPROUND;
171
57.1M
    SIPROUND;
172
57.1M
    SIPROUND;
173
57.1M
    return v0 ^ v1 ^ v2 ^ v3;
174
57.1M
}