Completed
Push — develop ( 5c5420...47dd43 )
by Zack
18:40 queued 12s
created
vendor/paragonie/sodium_compat/src/Crypto32.php 3 patches
Indentation   +1638 added lines, -1638 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Crypto32', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -14,1641 +14,1641 @@  discard block
 block discarded – undo
14 14
  */
15 15
 abstract class ParagonIE_Sodium_Crypto32
16 16
 {
17
-    const aead_chacha20poly1305_KEYBYTES = 32;
18
-    const aead_chacha20poly1305_NSECBYTES = 0;
19
-    const aead_chacha20poly1305_NPUBBYTES = 8;
20
-    const aead_chacha20poly1305_ABYTES = 16;
21
-
22
-    const aead_chacha20poly1305_IETF_KEYBYTES = 32;
23
-    const aead_chacha20poly1305_IETF_NSECBYTES = 0;
24
-    const aead_chacha20poly1305_IETF_NPUBBYTES = 12;
25
-    const aead_chacha20poly1305_IETF_ABYTES = 16;
26
-
27
-    const aead_xchacha20poly1305_IETF_KEYBYTES = 32;
28
-    const aead_xchacha20poly1305_IETF_NSECBYTES = 0;
29
-    const aead_xchacha20poly1305_IETF_NPUBBYTES = 24;
30
-    const aead_xchacha20poly1305_IETF_ABYTES = 16;
31
-
32
-    const box_curve25519xsalsa20poly1305_SEEDBYTES = 32;
33
-    const box_curve25519xsalsa20poly1305_PUBLICKEYBYTES = 32;
34
-    const box_curve25519xsalsa20poly1305_SECRETKEYBYTES = 32;
35
-    const box_curve25519xsalsa20poly1305_BEFORENMBYTES = 32;
36
-    const box_curve25519xsalsa20poly1305_NONCEBYTES = 24;
37
-    const box_curve25519xsalsa20poly1305_MACBYTES = 16;
38
-    const box_curve25519xsalsa20poly1305_BOXZEROBYTES = 16;
39
-    const box_curve25519xsalsa20poly1305_ZEROBYTES = 32;
40
-
41
-    const onetimeauth_poly1305_BYTES = 16;
42
-    const onetimeauth_poly1305_KEYBYTES = 32;
43
-
44
-    const secretbox_xsalsa20poly1305_KEYBYTES = 32;
45
-    const secretbox_xsalsa20poly1305_NONCEBYTES = 24;
46
-    const secretbox_xsalsa20poly1305_MACBYTES = 16;
47
-    const secretbox_xsalsa20poly1305_BOXZEROBYTES = 16;
48
-    const secretbox_xsalsa20poly1305_ZEROBYTES = 32;
49
-
50
-    const secretbox_xchacha20poly1305_KEYBYTES = 32;
51
-    const secretbox_xchacha20poly1305_NONCEBYTES = 24;
52
-    const secretbox_xchacha20poly1305_MACBYTES = 16;
53
-    const secretbox_xchacha20poly1305_BOXZEROBYTES = 16;
54
-    const secretbox_xchacha20poly1305_ZEROBYTES = 32;
55
-
56
-    const stream_salsa20_KEYBYTES = 32;
57
-
58
-    /**
59
-     * AEAD Decryption with ChaCha20-Poly1305
60
-     *
61
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
62
-     *
63
-     * @param string $message
64
-     * @param string $ad
65
-     * @param string $nonce
66
-     * @param string $key
67
-     * @return string
68
-     * @throws SodiumException
69
-     * @throws TypeError
70
-     */
71
-    public static function aead_chacha20poly1305_decrypt(
72
-        $message = '',
73
-        $ad = '',
74
-        $nonce = '',
75
-        $key = ''
76
-    ) {
77
-        /** @var int $len - Length of message (ciphertext + MAC) */
78
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
79
-
80
-        /** @var int  $clen - Length of ciphertext */
81
-        $clen = $len - self::aead_chacha20poly1305_ABYTES;
82
-
83
-        /** @var int $adlen - Length of associated data */
84
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
85
-
86
-        /** @var string $mac - Message authentication code */
87
-        $mac = ParagonIE_Sodium_Core32_Util::substr(
88
-            $message,
89
-            $clen,
90
-            self::aead_chacha20poly1305_ABYTES
91
-        );
92
-
93
-        /** @var string $ciphertext - The encrypted message (sans MAC) */
94
-        $ciphertext = ParagonIE_Sodium_Core32_Util::substr($message, 0, $clen);
95
-
96
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
97
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
98
-            32,
99
-            $nonce,
100
-            $key
101
-        );
102
-
103
-        /* Recalculate the Poly1305 authentication tag (MAC): */
104
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
105
-        try {
106
-            ParagonIE_Sodium_Compat::memzero($block0);
107
-        } catch (SodiumException $ex) {
108
-            $block0 = null;
109
-        }
110
-        $state->update($ad);
111
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
112
-        $state->update($ciphertext);
113
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($clen));
114
-        $computed_mac = $state->finish();
115
-
116
-        /* Compare the given MAC with the recalculated MAC: */
117
-        if (!ParagonIE_Sodium_Core32_Util::verify_16($computed_mac, $mac)) {
118
-            throw new SodiumException('Invalid MAC');
119
-        }
120
-
121
-        // Here, we know that the MAC is valid, so we decrypt and return the plaintext
122
-        return ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
123
-            $ciphertext,
124
-            $nonce,
125
-            $key,
126
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
127
-        );
128
-    }
129
-
130
-    /**
131
-     * AEAD Encryption with ChaCha20-Poly1305
132
-     *
133
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
134
-     *
135
-     * @param string $message
136
-     * @param string $ad
137
-     * @param string $nonce
138
-     * @param string $key
139
-     * @return string
140
-     * @throws SodiumException
141
-     * @throws TypeError
142
-     */
143
-    public static function aead_chacha20poly1305_encrypt(
144
-        $message = '',
145
-        $ad = '',
146
-        $nonce = '',
147
-        $key = ''
148
-    ) {
149
-        /** @var int $len - Length of the plaintext message */
150
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
151
-
152
-        /** @var int $adlen - Length of the associated data */
153
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
154
-
155
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
156
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
157
-            32,
158
-            $nonce,
159
-            $key
160
-        );
161
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
162
-        try {
163
-            ParagonIE_Sodium_Compat::memzero($block0);
164
-        } catch (SodiumException $ex) {
165
-            $block0 = null;
166
-        }
167
-
168
-        /** @var string $ciphertext - Raw encrypted data */
169
-        $ciphertext = ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
170
-            $message,
171
-            $nonce,
172
-            $key,
173
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
174
-        );
175
-
176
-        $state->update($ad);
177
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
178
-        $state->update($ciphertext);
179
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($len));
180
-        return $ciphertext . $state->finish();
181
-    }
182
-
183
-    /**
184
-     * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
185
-     *
186
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
187
-     *
188
-     * @param string $message
189
-     * @param string $ad
190
-     * @param string $nonce
191
-     * @param string $key
192
-     * @return string
193
-     * @throws SodiumException
194
-     * @throws TypeError
195
-     */
196
-    public static function aead_chacha20poly1305_ietf_decrypt(
197
-        $message = '',
198
-        $ad = '',
199
-        $nonce = '',
200
-        $key = ''
201
-    ) {
202
-        /** @var int $adlen - Length of associated data */
203
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
204
-
205
-        /** @var int $len - Length of message (ciphertext + MAC) */
206
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
207
-
208
-        /** @var int  $clen - Length of ciphertext */
209
-        $clen = $len - self::aead_chacha20poly1305_IETF_ABYTES;
210
-
211
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
212
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::ietfStream(
213
-            32,
214
-            $nonce,
215
-            $key
216
-        );
217
-
218
-        /** @var string $mac - Message authentication code */
219
-        $mac = ParagonIE_Sodium_Core32_Util::substr(
220
-            $message,
221
-            $len - self::aead_chacha20poly1305_IETF_ABYTES,
222
-            self::aead_chacha20poly1305_IETF_ABYTES
223
-        );
224
-
225
-        /** @var string $ciphertext - The encrypted message (sans MAC) */
226
-        $ciphertext = ParagonIE_Sodium_Core32_Util::substr(
227
-            $message,
228
-            0,
229
-            $len - self::aead_chacha20poly1305_IETF_ABYTES
230
-        );
231
-
232
-        /* Recalculate the Poly1305 authentication tag (MAC): */
233
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
234
-        try {
235
-            ParagonIE_Sodium_Compat::memzero($block0);
236
-        } catch (SodiumException $ex) {
237
-            $block0 = null;
238
-        }
239
-        $state->update($ad);
240
-        $state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
241
-        $state->update($ciphertext);
242
-        $state->update(str_repeat("\x00", (0x10 - $clen) & 0xf));
243
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
244
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($clen));
245
-        $computed_mac = $state->finish();
246
-
247
-        /* Compare the given MAC with the recalculated MAC: */
248
-        if (!ParagonIE_Sodium_Core32_Util::verify_16($computed_mac, $mac)) {
249
-            throw new SodiumException('Invalid MAC');
250
-        }
251
-
252
-        // Here, we know that the MAC is valid, so we decrypt and return the plaintext
253
-        return ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
254
-            $ciphertext,
255
-            $nonce,
256
-            $key,
257
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
258
-        );
259
-    }
260
-
261
-    /**
262
-     * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
263
-     *
264
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
265
-     *
266
-     * @param string $message
267
-     * @param string $ad
268
-     * @param string $nonce
269
-     * @param string $key
270
-     * @return string
271
-     * @throws SodiumException
272
-     * @throws TypeError
273
-     */
274
-    public static function aead_chacha20poly1305_ietf_encrypt(
275
-        $message = '',
276
-        $ad = '',
277
-        $nonce = '',
278
-        $key = ''
279
-    ) {
280
-        /** @var int $len - Length of the plaintext message */
281
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
282
-
283
-        /** @var int $adlen - Length of the associated data */
284
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
285
-
286
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
287
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::ietfStream(
288
-            32,
289
-            $nonce,
290
-            $key
291
-        );
292
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
293
-        try {
294
-            ParagonIE_Sodium_Compat::memzero($block0);
295
-        } catch (SodiumException $ex) {
296
-            $block0 = null;
297
-        }
298
-
299
-        /** @var string $ciphertext - Raw encrypted data */
300
-        $ciphertext = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
301
-            $message,
302
-            $nonce,
303
-            $key,
304
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
305
-        );
306
-
307
-        $state->update($ad);
308
-        $state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
309
-        $state->update($ciphertext);
310
-        $state->update(str_repeat("\x00", ((0x10 - $len) & 0xf)));
311
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
312
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($len));
313
-        return $ciphertext . $state->finish();
314
-    }
315
-
316
-    /**
317
-     * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
318
-     *
319
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
320
-     *
321
-     * @param string $message
322
-     * @param string $ad
323
-     * @param string $nonce
324
-     * @param string $key
325
-     * @return string
326
-     * @throws SodiumException
327
-     * @throws TypeError
328
-     */
329
-    public static function aead_xchacha20poly1305_ietf_decrypt(
330
-        $message = '',
331
-        $ad = '',
332
-        $nonce = '',
333
-        $key = ''
334
-    ) {
335
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
336
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
337
-            $key
338
-        );
339
-        $nonceLast = "\x00\x00\x00\x00" .
340
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
341
-
342
-        return self::aead_chacha20poly1305_ietf_decrypt($message, $ad, $nonceLast, $subkey);
343
-    }
344
-
345
-    /**
346
-     * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
347
-     *
348
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
349
-     *
350
-     * @param string $message
351
-     * @param string $ad
352
-     * @param string $nonce
353
-     * @param string $key
354
-     * @return string
355
-     * @throws SodiumException
356
-     * @throws TypeError
357
-     */
358
-    public static function aead_xchacha20poly1305_ietf_encrypt(
359
-        $message = '',
360
-        $ad = '',
361
-        $nonce = '',
362
-        $key = ''
363
-    ) {
364
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
365
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
366
-            $key
367
-        );
368
-        $nonceLast = "\x00\x00\x00\x00" .
369
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
370
-
371
-        return self::aead_chacha20poly1305_ietf_encrypt($message, $ad, $nonceLast, $subkey);
372
-    }
373
-
374
-    /**
375
-     * HMAC-SHA-512-256 (a.k.a. the leftmost 256 bits of HMAC-SHA-512)
376
-     *
377
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
378
-     *
379
-     * @param string $message
380
-     * @param string $key
381
-     * @return string
382
-     * @throws TypeError
383
-     */
384
-    public static function auth($message, $key)
385
-    {
386
-        return ParagonIE_Sodium_Core32_Util::substr(
387
-            hash_hmac('sha512', $message, $key, true),
388
-            0,
389
-            32
390
-        );
391
-    }
392
-
393
-    /**
394
-     * HMAC-SHA-512-256 validation. Constant-time via hash_equals().
395
-     *
396
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
397
-     *
398
-     * @param string $mac
399
-     * @param string $message
400
-     * @param string $key
401
-     * @return bool
402
-     * @throws SodiumException
403
-     * @throws TypeError
404
-     */
405
-    public static function auth_verify($mac, $message, $key)
406
-    {
407
-        return ParagonIE_Sodium_Core32_Util::hashEquals(
408
-            $mac,
409
-            self::auth($message, $key)
410
-        );
411
-    }
412
-
413
-    /**
414
-     * X25519 key exchange followed by XSalsa20Poly1305 symmetric encryption
415
-     *
416
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
417
-     *
418
-     * @param string $plaintext
419
-     * @param string $nonce
420
-     * @param string $keypair
421
-     * @return string
422
-     * @throws SodiumException
423
-     * @throws TypeError
424
-     */
425
-    public static function box($plaintext, $nonce, $keypair)
426
-    {
427
-        return self::secretbox(
428
-            $plaintext,
429
-            $nonce,
430
-            self::box_beforenm(
431
-                self::box_secretkey($keypair),
432
-                self::box_publickey($keypair)
433
-            )
434
-        );
435
-    }
436
-
437
-    /**
438
-     * X25519-XSalsa20-Poly1305 with one ephemeral X25519 keypair.
439
-     *
440
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
441
-     *
442
-     * @param string $message
443
-     * @param string $publicKey
444
-     * @return string
445
-     * @throws SodiumException
446
-     * @throws TypeError
447
-     */
448
-    public static function box_seal($message, $publicKey)
449
-    {
450
-        /** @var string $ephemeralKeypair */
451
-        $ephemeralKeypair = self::box_keypair();
452
-
453
-        /** @var string $ephemeralSK */
454
-        $ephemeralSK = self::box_secretkey($ephemeralKeypair);
455
-
456
-        /** @var string $ephemeralPK */
457
-        $ephemeralPK = self::box_publickey($ephemeralKeypair);
458
-
459
-        /** @var string $nonce */
460
-        $nonce = self::generichash(
461
-            $ephemeralPK . $publicKey,
462
-            '',
463
-            24
464
-        );
465
-
466
-        /** @var string $keypair - The combined keypair used in crypto_box() */
467
-        $keypair = self::box_keypair_from_secretkey_and_publickey($ephemeralSK, $publicKey);
468
-
469
-        /** @var string $ciphertext Ciphertext + MAC from crypto_box */
470
-        $ciphertext = self::box($message, $nonce, $keypair);
471
-        try {
472
-            ParagonIE_Sodium_Compat::memzero($ephemeralKeypair);
473
-            ParagonIE_Sodium_Compat::memzero($ephemeralSK);
474
-            ParagonIE_Sodium_Compat::memzero($nonce);
475
-        } catch (SodiumException $ex) {
476
-            $ephemeralKeypair = null;
477
-            $ephemeralSK = null;
478
-            $nonce = null;
479
-        }
480
-        return $ephemeralPK . $ciphertext;
481
-    }
482
-
483
-    /**
484
-     * Opens a message encrypted via box_seal().
485
-     *
486
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
487
-     *
488
-     * @param string $message
489
-     * @param string $keypair
490
-     * @return string
491
-     * @throws SodiumException
492
-     * @throws TypeError
493
-     */
494
-    public static function box_seal_open($message, $keypair)
495
-    {
496
-        /** @var string $ephemeralPK */
497
-        $ephemeralPK = ParagonIE_Sodium_Core32_Util::substr($message, 0, 32);
498
-
499
-        /** @var string $ciphertext (ciphertext + MAC) */
500
-        $ciphertext = ParagonIE_Sodium_Core32_Util::substr($message, 32);
501
-
502
-        /** @var string $secretKey */
503
-        $secretKey = self::box_secretkey($keypair);
504
-
505
-        /** @var string $publicKey */
506
-        $publicKey = self::box_publickey($keypair);
507
-
508
-        /** @var string $nonce */
509
-        $nonce = self::generichash(
510
-            $ephemeralPK . $publicKey,
511
-            '',
512
-            24
513
-        );
514
-
515
-        /** @var string $keypair */
516
-        $keypair = self::box_keypair_from_secretkey_and_publickey($secretKey, $ephemeralPK);
517
-
518
-        /** @var string $m */
519
-        $m = self::box_open($ciphertext, $nonce, $keypair);
520
-        try {
521
-            ParagonIE_Sodium_Compat::memzero($secretKey);
522
-            ParagonIE_Sodium_Compat::memzero($ephemeralPK);
523
-            ParagonIE_Sodium_Compat::memzero($nonce);
524
-        } catch (SodiumException $ex) {
525
-            $secretKey = null;
526
-            $ephemeralPK = null;
527
-            $nonce = null;
528
-        }
529
-        return $m;
530
-    }
531
-
532
-    /**
533
-     * Used by crypto_box() to get the crypto_secretbox() key.
534
-     *
535
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
536
-     *
537
-     * @param string $sk
538
-     * @param string $pk
539
-     * @return string
540
-     * @throws SodiumException
541
-     * @throws TypeError
542
-     */
543
-    public static function box_beforenm($sk, $pk)
544
-    {
545
-        return ParagonIE_Sodium_Core32_HSalsa20::hsalsa20(
546
-            str_repeat("\x00", 16),
547
-            self::scalarmult($sk, $pk)
548
-        );
549
-    }
550
-
551
-    /**
552
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
553
-     *
554
-     * @return string
555
-     * @throws Exception
556
-     * @throws SodiumException
557
-     * @throws TypeError
558
-     */
559
-    public static function box_keypair()
560
-    {
561
-        $sKey = random_bytes(32);
562
-        $pKey = self::scalarmult_base($sKey);
563
-        return $sKey . $pKey;
564
-    }
565
-
566
-    /**
567
-     * @param string $seed
568
-     * @return string
569
-     * @throws SodiumException
570
-     * @throws TypeError
571
-     */
572
-    public static function box_seed_keypair($seed)
573
-    {
574
-        $sKey = ParagonIE_Sodium_Core32_Util::substr(
575
-            hash('sha512', $seed, true),
576
-            0,
577
-            32
578
-        );
579
-        $pKey = self::scalarmult_base($sKey);
580
-        return $sKey . $pKey;
581
-    }
582
-
583
-    /**
584
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
585
-     *
586
-     * @param string $sKey
587
-     * @param string $pKey
588
-     * @return string
589
-     * @throws TypeError
590
-     */
591
-    public static function box_keypair_from_secretkey_and_publickey($sKey, $pKey)
592
-    {
593
-        return ParagonIE_Sodium_Core32_Util::substr($sKey, 0, 32) .
594
-            ParagonIE_Sodium_Core32_Util::substr($pKey, 0, 32);
595
-    }
596
-
597
-    /**
598
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
599
-     *
600
-     * @param string $keypair
601
-     * @return string
602
-     * @throws RangeException
603
-     * @throws TypeError
604
-     */
605
-    public static function box_secretkey($keypair)
606
-    {
607
-        if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== 64) {
608
-            throw new RangeException(
609
-                'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
610
-            );
611
-        }
612
-        return ParagonIE_Sodium_Core32_Util::substr($keypair, 0, 32);
613
-    }
614
-
615
-    /**
616
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
617
-     *
618
-     * @param string $keypair
619
-     * @return string
620
-     * @throws RangeException
621
-     * @throws TypeError
622
-     */
623
-    public static function box_publickey($keypair)
624
-    {
625
-        if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
626
-            throw new RangeException(
627
-                'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
628
-            );
629
-        }
630
-        return ParagonIE_Sodium_Core32_Util::substr($keypair, 32, 32);
631
-    }
632
-
633
-    /**
634
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
635
-     *
636
-     * @param string $sKey
637
-     * @return string
638
-     * @throws RangeException
639
-     * @throws SodiumException
640
-     * @throws TypeError
641
-     */
642
-    public static function box_publickey_from_secretkey($sKey)
643
-    {
644
-        if (ParagonIE_Sodium_Core32_Util::strlen($sKey) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES) {
645
-            throw new RangeException(
646
-                'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES bytes long.'
647
-            );
648
-        }
649
-        return self::scalarmult_base($sKey);
650
-    }
651
-
652
-    /**
653
-     * Decrypt a message encrypted with box().
654
-     *
655
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
656
-     *
657
-     * @param string $ciphertext
658
-     * @param string $nonce
659
-     * @param string $keypair
660
-     * @return string
661
-     * @throws SodiumException
662
-     * @throws TypeError
663
-     */
664
-    public static function box_open($ciphertext, $nonce, $keypair)
665
-    {
666
-        return self::secretbox_open(
667
-            $ciphertext,
668
-            $nonce,
669
-            self::box_beforenm(
670
-                self::box_secretkey($keypair),
671
-                self::box_publickey($keypair)
672
-            )
673
-        );
674
-    }
675
-
676
-    /**
677
-     * Calculate a BLAKE2b hash.
678
-     *
679
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
680
-     *
681
-     * @param string $message
682
-     * @param string|null $key
683
-     * @param int $outlen
684
-     * @return string
685
-     * @throws RangeException
686
-     * @throws SodiumException
687
-     * @throws TypeError
688
-     */
689
-    public static function generichash($message, $key = '', $outlen = 32)
690
-    {
691
-        // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
692
-        ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
693
-
694
-        $k = null;
695
-        if (!empty($key)) {
696
-            /** @var SplFixedArray $k */
697
-            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
698
-            if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
699
-                throw new RangeException('Invalid key size');
700
-            }
701
-        }
702
-
703
-        /** @var SplFixedArray $in */
704
-        $in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($message);
705
-
706
-        /** @var SplFixedArray $ctx */
707
-        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outlen);
708
-        ParagonIE_Sodium_Core32_BLAKE2b::update($ctx, $in, $in->count());
709
-
710
-        /** @var SplFixedArray $out */
711
-        $out = new SplFixedArray($outlen);
712
-        $out = ParagonIE_Sodium_Core32_BLAKE2b::finish($ctx, $out);
713
-
714
-        /** @var array<int, int> */
715
-        $outArray = $out->toArray();
716
-        return ParagonIE_Sodium_Core32_Util::intArrayToString($outArray);
717
-    }
718
-
719
-    /**
720
-     * Finalize a BLAKE2b hashing context, returning the hash.
721
-     *
722
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
723
-     *
724
-     * @param string $ctx
725
-     * @param int $outlen
726
-     * @return string
727
-     * @throws SodiumException
728
-     * @throws TypeError
729
-     */
730
-    public static function generichash_final($ctx, $outlen = 32)
731
-    {
732
-        if (!is_string($ctx)) {
733
-            throw new TypeError('Context must be a string');
734
-        }
735
-        $out = new SplFixedArray($outlen);
736
-
737
-        /** @var SplFixedArray $context */
738
-        $context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext($ctx);
739
-
740
-        /** @var SplFixedArray $out */
741
-        $out = ParagonIE_Sodium_Core32_BLAKE2b::finish($context, $out);
742
-
743
-        /** @var array<int, int> */
744
-        $outArray = $out->toArray();
745
-        return ParagonIE_Sodium_Core32_Util::intArrayToString($outArray);
746
-    }
747
-
748
-    /**
749
-     * Initialize a hashing context for BLAKE2b.
750
-     *
751
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
752
-     *
753
-     * @param string $key
754
-     * @param int $outputLength
755
-     * @return string
756
-     * @throws RangeException
757
-     * @throws SodiumException
758
-     * @throws TypeError
759
-     */
760
-    public static function generichash_init($key = '', $outputLength = 32)
761
-    {
762
-        // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
763
-        ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
764
-
765
-        $k = null;
766
-        if (!empty($key)) {
767
-            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
768
-            if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
769
-                throw new RangeException('Invalid key size');
770
-            }
771
-        }
772
-
773
-        /** @var SplFixedArray $ctx */
774
-        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outputLength);
775
-
776
-        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($ctx);
777
-    }
778
-
779
-    /**
780
-     * Initialize a hashing context for BLAKE2b.
781
-     *
782
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
783
-     *
784
-     * @param string $key
785
-     * @param int $outputLength
786
-     * @param string $salt
787
-     * @param string $personal
788
-     * @return string
789
-     * @throws RangeException
790
-     * @throws SodiumException
791
-     * @throws TypeError
792
-     */
793
-    public static function generichash_init_salt_personal(
794
-        $key = '',
795
-        $outputLength = 32,
796
-        $salt = '',
797
-        $personal = ''
798
-    ) {
799
-        // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
800
-        ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
801
-
802
-        $k = null;
803
-        if (!empty($key)) {
804
-            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
805
-            if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
806
-                throw new RangeException('Invalid key size');
807
-            }
808
-        }
809
-        if (!empty($salt)) {
810
-            $s = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($salt);
811
-        } else {
812
-            $s = null;
813
-        }
814
-        if (!empty($salt)) {
815
-            $p = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($personal);
816
-        } else {
817
-            $p = null;
818
-        }
819
-
820
-        /** @var SplFixedArray $ctx */
821
-        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outputLength, $s, $p);
822
-
823
-        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($ctx);
824
-    }
825
-
826
-    /**
827
-     * Update a hashing context for BLAKE2b with $message
828
-     *
829
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
830
-     *
831
-     * @param string $ctx
832
-     * @param string $message
833
-     * @return string
834
-     * @throws SodiumException
835
-     * @throws TypeError
836
-     */
837
-    public static function generichash_update($ctx, $message)
838
-    {
839
-        // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
840
-        ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
841
-
842
-        /** @var SplFixedArray $context */
843
-        $context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext($ctx);
844
-
845
-        /** @var SplFixedArray $in */
846
-        $in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($message);
847
-
848
-        ParagonIE_Sodium_Core32_BLAKE2b::update($context, $in, $in->count());
849
-
850
-        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($context);
851
-    }
852
-
853
-    /**
854
-     * Libsodium's crypto_kx().
855
-     *
856
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
857
-     *
858
-     * @param string $my_sk
859
-     * @param string $their_pk
860
-     * @param string $client_pk
861
-     * @param string $server_pk
862
-     * @return string
863
-     * @throws SodiumException
864
-     * @throws TypeError
865
-     */
866
-    public static function keyExchange($my_sk, $their_pk, $client_pk, $server_pk)
867
-    {
868
-        return self::generichash(
869
-            self::scalarmult($my_sk, $their_pk) .
870
-            $client_pk .
871
-            $server_pk
872
-        );
873
-    }
874
-
875
-    /**
876
-     * ECDH over Curve25519
877
-     *
878
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
879
-     *
880
-     * @param string $sKey
881
-     * @param string $pKey
882
-     * @return string
883
-     *
884
-     * @throws SodiumException
885
-     * @throws TypeError
886
-     */
887
-    public static function scalarmult($sKey, $pKey)
888
-    {
889
-        $q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10($sKey, $pKey);
890
-        self::scalarmult_throw_if_zero($q);
891
-        return $q;
892
-    }
893
-
894
-    /**
895
-     * ECDH over Curve25519, using the basepoint.
896
-     * Used to get a secret key from a public key.
897
-     *
898
-     * @param string $secret
899
-     * @return string
900
-     *
901
-     * @throws SodiumException
902
-     * @throws TypeError
903
-     */
904
-    public static function scalarmult_base($secret)
905
-    {
906
-        $q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10_base($secret);
907
-        self::scalarmult_throw_if_zero($q);
908
-        return $q;
909
-    }
910
-
911
-    /**
912
-     * This throws an Error if a zero public key was passed to the function.
913
-     *
914
-     * @param string $q
915
-     * @return void
916
-     * @throws SodiumException
917
-     * @throws TypeError
918
-     */
919
-    protected static function scalarmult_throw_if_zero($q)
920
-    {
921
-        $d = 0;
922
-        for ($i = 0; $i < self::box_curve25519xsalsa20poly1305_SECRETKEYBYTES; ++$i) {
923
-            $d |= ParagonIE_Sodium_Core32_Util::chrToInt($q[$i]);
924
-        }
925
-
926
-        /* branch-free variant of === 0 */
927
-        if (-(1 & (($d - 1) >> 8))) {
928
-            throw new SodiumException('Zero public key is not allowed');
929
-        }
930
-    }
931
-
932
-    /**
933
-     * XSalsa20-Poly1305 authenticated symmetric-key encryption.
934
-     *
935
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
936
-     *
937
-     * @param string $plaintext
938
-     * @param string $nonce
939
-     * @param string $key
940
-     * @return string
941
-     * @throws SodiumException
942
-     * @throws TypeError
943
-     */
944
-    public static function secretbox($plaintext, $nonce, $key)
945
-    {
946
-        /** @var string $subkey */
947
-        $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
948
-
949
-        /** @var string $block0 */
950
-        $block0 = str_repeat("\x00", 32);
951
-
952
-        /** @var int $mlen - Length of the plaintext message */
953
-        $mlen = ParagonIE_Sodium_Core32_Util::strlen($plaintext);
954
-        $mlen0 = $mlen;
955
-        if ($mlen0 > 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES) {
956
-            $mlen0 = 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES;
957
-        }
958
-        $block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
959
-
960
-        /** @var string $block0 */
961
-        $block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor(
962
-            $block0,
963
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
964
-            $subkey
965
-        );
966
-
967
-        /** @var string $c */
968
-        $c = ParagonIE_Sodium_Core32_Util::substr(
969
-            $block0,
970
-            self::secretbox_xsalsa20poly1305_ZEROBYTES
971
-        );
972
-        if ($mlen > $mlen0) {
973
-            $c .= ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
974
-                ParagonIE_Sodium_Core32_Util::substr(
975
-                    $plaintext,
976
-                    self::secretbox_xsalsa20poly1305_ZEROBYTES
977
-                ),
978
-                ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
979
-                1,
980
-                $subkey
981
-            );
982
-        }
983
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State(
984
-            ParagonIE_Sodium_Core32_Util::substr(
985
-                $block0,
986
-                0,
987
-                self::onetimeauth_poly1305_KEYBYTES
988
-            )
989
-        );
990
-        try {
991
-            ParagonIE_Sodium_Compat::memzero($block0);
992
-            ParagonIE_Sodium_Compat::memzero($subkey);
993
-        } catch (SodiumException $ex) {
994
-            $block0 = null;
995
-            $subkey = null;
996
-        }
997
-
998
-        $state->update($c);
999
-
1000
-        /** @var string $c - MAC || ciphertext */
1001
-        $c = $state->finish() . $c;
1002
-        unset($state);
1003
-
1004
-        return $c;
1005
-    }
1006
-
1007
-    /**
1008
-     * Decrypt a ciphertext generated via secretbox().
1009
-     *
1010
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1011
-     *
1012
-     * @param string $ciphertext
1013
-     * @param string $nonce
1014
-     * @param string $key
1015
-     * @return string
1016
-     * @throws SodiumException
1017
-     * @throws TypeError
1018
-     */
1019
-    public static function secretbox_open($ciphertext, $nonce, $key)
1020
-    {
1021
-        /** @var string $mac */
1022
-        $mac = ParagonIE_Sodium_Core32_Util::substr(
1023
-            $ciphertext,
1024
-            0,
1025
-            self::secretbox_xsalsa20poly1305_MACBYTES
1026
-        );
1027
-
1028
-        /** @var string $c */
1029
-        $c = ParagonIE_Sodium_Core32_Util::substr(
1030
-            $ciphertext,
1031
-            self::secretbox_xsalsa20poly1305_MACBYTES
1032
-        );
1033
-
1034
-        /** @var int $clen */
1035
-        $clen = ParagonIE_Sodium_Core32_Util::strlen($c);
1036
-
1037
-        /** @var string $subkey */
1038
-        $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
1039
-
1040
-        /** @var string $block0 */
1041
-        $block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20(
1042
-            64,
1043
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1044
-            $subkey
1045
-        );
1046
-        $verified = ParagonIE_Sodium_Core32_Poly1305::onetimeauth_verify(
1047
-            $mac,
1048
-            $c,
1049
-            ParagonIE_Sodium_Core32_Util::substr($block0, 0, 32)
1050
-        );
1051
-        if (!$verified) {
1052
-            try {
1053
-                ParagonIE_Sodium_Compat::memzero($subkey);
1054
-            } catch (SodiumException $ex) {
1055
-                $subkey = null;
1056
-            }
1057
-            throw new SodiumException('Invalid MAC');
1058
-        }
1059
-
1060
-        /** @var string $m - Decrypted message */
1061
-        $m = ParagonIE_Sodium_Core32_Util::xorStrings(
1062
-            ParagonIE_Sodium_Core32_Util::substr($block0, self::secretbox_xsalsa20poly1305_ZEROBYTES),
1063
-            ParagonIE_Sodium_Core32_Util::substr($c, 0, self::secretbox_xsalsa20poly1305_ZEROBYTES)
1064
-        );
1065
-        if ($clen > self::secretbox_xsalsa20poly1305_ZEROBYTES) {
1066
-            // We had more than 1 block, so let's continue to decrypt the rest.
1067
-            $m .= ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
1068
-                ParagonIE_Sodium_Core32_Util::substr(
1069
-                    $c,
1070
-                    self::secretbox_xsalsa20poly1305_ZEROBYTES
1071
-                ),
1072
-                ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1073
-                1,
1074
-                (string) $subkey
1075
-            );
1076
-        }
1077
-        return $m;
1078
-    }
1079
-
1080
-    /**
1081
-     * XChaCha20-Poly1305 authenticated symmetric-key encryption.
1082
-     *
1083
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1084
-     *
1085
-     * @param string $plaintext
1086
-     * @param string $nonce
1087
-     * @param string $key
1088
-     * @return string
1089
-     * @throws SodiumException
1090
-     * @throws TypeError
1091
-     */
1092
-    public static function secretbox_xchacha20poly1305($plaintext, $nonce, $key)
1093
-    {
1094
-        /** @var string $subkey */
1095
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1096
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
1097
-            $key
1098
-        );
1099
-        $nonceLast = ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
1100
-
1101
-        /** @var string $block0 */
1102
-        $block0 = str_repeat("\x00", 32);
1103
-
1104
-        /** @var int $mlen - Length of the plaintext message */
1105
-        $mlen = ParagonIE_Sodium_Core32_Util::strlen($plaintext);
1106
-        $mlen0 = $mlen;
1107
-        if ($mlen0 > 64 - self::secretbox_xchacha20poly1305_ZEROBYTES) {
1108
-            $mlen0 = 64 - self::secretbox_xchacha20poly1305_ZEROBYTES;
1109
-        }
1110
-        $block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
1111
-
1112
-        /** @var string $block0 */
1113
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1114
-            $block0,
1115
-            $nonceLast,
1116
-            $subkey
1117
-        );
1118
-
1119
-        /** @var string $c */
1120
-        $c = ParagonIE_Sodium_Core32_Util::substr(
1121
-            $block0,
1122
-            self::secretbox_xchacha20poly1305_ZEROBYTES
1123
-        );
1124
-        if ($mlen > $mlen0) {
1125
-            $c .= ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1126
-                ParagonIE_Sodium_Core32_Util::substr(
1127
-                    $plaintext,
1128
-                    self::secretbox_xchacha20poly1305_ZEROBYTES
1129
-                ),
1130
-                $nonceLast,
1131
-                $subkey,
1132
-                ParagonIE_Sodium_Core32_Util::store64_le(1)
1133
-            );
1134
-        }
1135
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State(
1136
-            ParagonIE_Sodium_Core32_Util::substr(
1137
-                $block0,
1138
-                0,
1139
-                self::onetimeauth_poly1305_KEYBYTES
1140
-            )
1141
-        );
1142
-        try {
1143
-            ParagonIE_Sodium_Compat::memzero($block0);
1144
-            ParagonIE_Sodium_Compat::memzero($subkey);
1145
-        } catch (SodiumException $ex) {
1146
-            $block0 = null;
1147
-            $subkey = null;
1148
-        }
1149
-
1150
-        $state->update($c);
1151
-
1152
-        /** @var string $c - MAC || ciphertext */
1153
-        $c = $state->finish() . $c;
1154
-        unset($state);
1155
-
1156
-        return $c;
1157
-    }
1158
-
1159
-    /**
1160
-     * Decrypt a ciphertext generated via secretbox_xchacha20poly1305().
1161
-     *
1162
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1163
-     *
1164
-     * @param string $ciphertext
1165
-     * @param string $nonce
1166
-     * @param string $key
1167
-     * @return string
1168
-     * @throws SodiumException
1169
-     * @throws TypeError
1170
-     */
1171
-    public static function secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key)
1172
-    {
1173
-        /** @var string $mac */
1174
-        $mac = ParagonIE_Sodium_Core32_Util::substr(
1175
-            $ciphertext,
1176
-            0,
1177
-            self::secretbox_xchacha20poly1305_MACBYTES
1178
-        );
1179
-
1180
-        /** @var string $c */
1181
-        $c = ParagonIE_Sodium_Core32_Util::substr(
1182
-            $ciphertext,
1183
-            self::secretbox_xchacha20poly1305_MACBYTES
1184
-        );
1185
-
1186
-        /** @var int $clen */
1187
-        $clen = ParagonIE_Sodium_Core32_Util::strlen($c);
1188
-
1189
-        /** @var string $subkey */
1190
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hchacha20($nonce, $key);
1191
-
1192
-        /** @var string $block0 */
1193
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
1194
-            64,
1195
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1196
-            $subkey
1197
-        );
1198
-        $verified = ParagonIE_Sodium_Core32_Poly1305::onetimeauth_verify(
1199
-            $mac,
1200
-            $c,
1201
-            ParagonIE_Sodium_Core32_Util::substr($block0, 0, 32)
1202
-        );
1203
-
1204
-        if (!$verified) {
1205
-            try {
1206
-                ParagonIE_Sodium_Compat::memzero($subkey);
1207
-            } catch (SodiumException $ex) {
1208
-                $subkey = null;
1209
-            }
1210
-            throw new SodiumException('Invalid MAC');
1211
-        }
1212
-
1213
-        /** @var string $m - Decrypted message */
1214
-        $m = ParagonIE_Sodium_Core32_Util::xorStrings(
1215
-            ParagonIE_Sodium_Core32_Util::substr($block0, self::secretbox_xchacha20poly1305_ZEROBYTES),
1216
-            ParagonIE_Sodium_Core32_Util::substr($c, 0, self::secretbox_xchacha20poly1305_ZEROBYTES)
1217
-        );
1218
-
1219
-        if ($clen > self::secretbox_xchacha20poly1305_ZEROBYTES) {
1220
-            // We had more than 1 block, so let's continue to decrypt the rest.
1221
-            $m .= ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1222
-                ParagonIE_Sodium_Core32_Util::substr(
1223
-                    $c,
1224
-                    self::secretbox_xchacha20poly1305_ZEROBYTES
1225
-                ),
1226
-                ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1227
-                (string) $subkey,
1228
-                ParagonIE_Sodium_Core32_Util::store64_le(1)
1229
-            );
1230
-        }
1231
-        return $m;
1232
-    }
1233
-
1234
-    /**
1235
-     * @param string $key
1236
-     * @return array<int, string> Returns a state and a header.
1237
-     * @throws Exception
1238
-     * @throws SodiumException
1239
-     */
1240
-    public static function secretstream_xchacha20poly1305_init_push($key)
1241
-    {
1242
-        # randombytes_buf(out, crypto_secretstream_xchacha20poly1305_HEADERBYTES);
1243
-        $out = random_bytes(24);
1244
-
1245
-        # crypto_core_hchacha20(state->k, out, k, NULL);
1246
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20($out, $key);
1247
-        $state = new ParagonIE_Sodium_Core32_SecretStream_State(
1248
-            $subkey,
1249
-            ParagonIE_Sodium_Core32_Util::substr($out, 16, 8) . str_repeat("\0", 4)
1250
-        );
1251
-
1252
-        # _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1253
-        $state->counterReset();
1254
-
1255
-        # memcpy(STATE_INONCE(state), out + crypto_core_hchacha20_INPUTBYTES,
1256
-        #        crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1257
-        # memset(state->_pad, 0, sizeof state->_pad);
1258
-        return array(
1259
-            $state->toString(),
1260
-            $out
1261
-        );
1262
-    }
1263
-
1264
-    /**
1265
-     * @param string $key
1266
-     * @param string $header
1267
-     * @return string Returns a state.
1268
-     * @throws Exception
1269
-     */
1270
-    public static function secretstream_xchacha20poly1305_init_pull($key, $header)
1271
-    {
1272
-        # crypto_core_hchacha20(state->k, in, k, NULL);
1273
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1274
-            ParagonIE_Sodium_Core32_Util::substr($header, 0, 16),
1275
-            $key
1276
-        );
1277
-        $state = new ParagonIE_Sodium_Core32_SecretStream_State(
1278
-            $subkey,
1279
-            ParagonIE_Sodium_Core32_Util::substr($header, 16)
1280
-        );
1281
-        $state->counterReset();
1282
-        # memcpy(STATE_INONCE(state), in + crypto_core_hchacha20_INPUTBYTES,
1283
-        #     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1284
-        # memset(state->_pad, 0, sizeof state->_pad);
1285
-        # return 0;
1286
-        return $state->toString();
1287
-    }
1288
-
1289
-    /**
1290
-     * @param string $state
1291
-     * @param string $msg
1292
-     * @param string $aad
1293
-     * @param int $tag
1294
-     * @return string
1295
-     * @throws SodiumException
1296
-     */
1297
-    public static function secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0)
1298
-    {
1299
-        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1300
-        # crypto_onetimeauth_poly1305_state poly1305_state;
1301
-        # unsigned char                     block[64U];
1302
-        # unsigned char                     slen[8U];
1303
-        # unsigned char                    *c;
1304
-        # unsigned char                    *mac;
1305
-
1306
-        $msglen = ParagonIE_Sodium_Core32_Util::strlen($msg);
1307
-        $aadlen = ParagonIE_Sodium_Core32_Util::strlen($aad);
1308
-
1309
-        if ((($msglen + 63) >> 6) > 0xfffffffe) {
1310
-            throw new SodiumException(
1311
-                'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1312
-            );
1313
-        }
1314
-
1315
-        # if (outlen_p != NULL) {
1316
-        #     *outlen_p = 0U;
1317
-        # }
1318
-        # if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1319
-        #     sodium_misuse();
1320
-        # }
1321
-
1322
-        # crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1323
-        # crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1324
-        # sodium_memzero(block, sizeof block);
1325
-        $auth = new ParagonIE_Sodium_Core32_Poly1305_State(
1326
-            ParagonIE_Sodium_Core32_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1327
-        );
1328
-
1329
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1330
-        $auth->update($aad);
1331
-
1332
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1333
-        #     (0x10 - adlen) & 0xf);
1334
-        $auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1335
-
1336
-        # memset(block, 0, sizeof block);
1337
-        # block[0] = tag;
1338
-        # crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1339
-        #                                    state->nonce, 1U, state->k);
1340
-        $block = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1341
-            ParagonIE_Sodium_Core32_Util::intToChr($tag) . str_repeat("\0", 63),
1342
-            $st->getCombinedNonce(),
1343
-            $st->getKey(),
1344
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
1345
-        );
1346
-
1347
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1348
-        $auth->update($block);
1349
-
1350
-        # out[0] = block[0];
1351
-        $out = $block[0];
1352
-        # c = out + (sizeof tag);
1353
-        # crypto_stream_chacha20_ietf_xor_ic(c, m, mlen, state->nonce, 2U, state->k);
1354
-        $cipher = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1355
-            $msg,
1356
-            $st->getCombinedNonce(),
1357
-            $st->getKey(),
1358
-            ParagonIE_Sodium_Core32_Util::store64_le(2)
1359
-        );
1360
-
1361
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1362
-        $auth->update($cipher);
1363
-
1364
-        $out .= $cipher;
1365
-        unset($cipher);
1366
-
1367
-        # crypto_onetimeauth_poly1305_update
1368
-        # (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1369
-        $auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1370
-
1371
-        # STORE64_LE(slen, (uint64_t) adlen);
1372
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le($aadlen);
1373
-
1374
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1375
-        $auth->update($slen);
1376
-
1377
-        # STORE64_LE(slen, (sizeof block) + mlen);
1378
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le(64 + $msglen);
1379
-
1380
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1381
-        $auth->update($slen);
1382
-
1383
-        # mac = c + mlen;
1384
-        # crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1385
-        $mac = $auth->finish();
1386
-        $out .= $mac;
1387
-
1388
-        # sodium_memzero(&poly1305_state, sizeof poly1305_state);
1389
-        unset($auth);
1390
-
1391
-
1392
-        # XOR_BUF(STATE_INONCE(state), mac,
1393
-        #     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1394
-        $st->xorNonce($mac);
1395
-
1396
-        # sodium_increment(STATE_COUNTER(state),
1397
-        #     crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1398
-        $st->incrementCounter();
1399
-        // Overwrite by reference:
1400
-        $state = $st->toString();
1401
-
1402
-        /** @var bool $rekey */
1403
-        $rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1404
-        # if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1405
-        #     sodium_is_zero(STATE_COUNTER(state),
1406
-        #         crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1407
-        #     crypto_secretstream_xchacha20poly1305_rekey(state);
1408
-        # }
1409
-        if ($rekey || $st->needsRekey()) {
1410
-            // DO REKEY
1411
-            self::secretstream_xchacha20poly1305_rekey($state);
1412
-        }
1413
-        # if (outlen_p != NULL) {
1414
-        #     *outlen_p = crypto_secretstream_xchacha20poly1305_ABYTES + mlen;
1415
-        # }
1416
-        return $out;
1417
-    }
1418
-
1419
-    /**
1420
-     * @param string $state
1421
-     * @param string $cipher
1422
-     * @param string $aad
1423
-     * @return bool|array{0: string, 1: int}
1424
-     * @throws SodiumException
1425
-     */
1426
-    public static function secretstream_xchacha20poly1305_pull(&$state, $cipher, $aad = '')
1427
-    {
1428
-        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1429
-
1430
-        $cipherlen = ParagonIE_Sodium_Core32_Util::strlen($cipher);
1431
-        #     mlen = inlen - crypto_secretstream_xchacha20poly1305_ABYTES;
1432
-        $msglen = $cipherlen - ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_ABYTES;
1433
-        $aadlen = ParagonIE_Sodium_Core32_Util::strlen($aad);
1434
-
1435
-        #     if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1436
-        #         sodium_misuse();
1437
-        #     }
1438
-        if ((($msglen + 63) >> 6) > 0xfffffffe) {
1439
-            throw new SodiumException(
1440
-                'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1441
-            );
1442
-        }
1443
-
1444
-        #     crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1445
-        #     crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1446
-        #     sodium_memzero(block, sizeof block);
1447
-        $auth = new ParagonIE_Sodium_Core32_Poly1305_State(
1448
-            ParagonIE_Sodium_Core32_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1449
-        );
1450
-
1451
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1452
-        $auth->update($aad);
1453
-
1454
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1455
-        #         (0x10 - adlen) & 0xf);
1456
-        $auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1457
-
1458
-
1459
-        #     memset(block, 0, sizeof block);
1460
-        #     block[0] = in[0];
1461
-        #     crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1462
-        #                                        state->nonce, 1U, state->k);
1463
-        $block = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1464
-            $cipher[0] . str_repeat("\0", 63),
1465
-            $st->getCombinedNonce(),
1466
-            $st->getKey(),
1467
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
1468
-        );
1469
-        #     tag = block[0];
1470
-        #     block[0] = in[0];
1471
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1472
-        $tag = ParagonIE_Sodium_Core32_Util::chrToInt($block[0]);
1473
-        $block[0] = $cipher[0];
1474
-        $auth->update($block);
1475
-
1476
-
1477
-        #     c = in + (sizeof tag);
1478
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1479
-        $auth->update(ParagonIE_Sodium_Core32_Util::substr($cipher, 1, $msglen));
1480
-
1481
-        #     crypto_onetimeauth_poly1305_update
1482
-        #     (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1483
-        $auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1484
-
1485
-        #     STORE64_LE(slen, (uint64_t) adlen);
1486
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1487
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le($aadlen);
1488
-        $auth->update($slen);
1489
-
1490
-        #     STORE64_LE(slen, (sizeof block) + mlen);
1491
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1492
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le(64 + $msglen);
1493
-        $auth->update($slen);
1494
-
1495
-        #     crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1496
-        #     sodium_memzero(&poly1305_state, sizeof poly1305_state);
1497
-        $mac = $auth->finish();
1498
-
1499
-        #     stored_mac = c + mlen;
1500
-        #     if (sodium_memcmp(mac, stored_mac, sizeof mac) != 0) {
1501
-        #     sodium_memzero(mac, sizeof mac);
1502
-        #         return -1;
1503
-        #     }
1504
-
1505
-        $stored = ParagonIE_Sodium_Core32_Util::substr($cipher, $msglen + 1, 16);
1506
-        if (!ParagonIE_Sodium_Core32_Util::hashEquals($mac, $stored)) {
1507
-            return false;
1508
-        }
1509
-
1510
-        #     crypto_stream_chacha20_ietf_xor_ic(m, c, mlen, state->nonce, 2U, state->k);
1511
-        $out = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1512
-            ParagonIE_Sodium_Core32_Util::substr($cipher, 1, $msglen),
1513
-            $st->getCombinedNonce(),
1514
-            $st->getKey(),
1515
-            ParagonIE_Sodium_Core32_Util::store64_le(2)
1516
-        );
1517
-
1518
-        #     XOR_BUF(STATE_INONCE(state), mac,
1519
-        #         crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1520
-        $st->xorNonce($mac);
1521
-
1522
-        #     sodium_increment(STATE_COUNTER(state),
1523
-        #         crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1524
-        $st->incrementCounter();
1525
-
1526
-        #     if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1527
-        #         sodium_is_zero(STATE_COUNTER(state),
1528
-        #             crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1529
-        #         crypto_secretstream_xchacha20poly1305_rekey(state);
1530
-        #     }
1531
-
1532
-        // Overwrite by reference:
1533
-        $state = $st->toString();
1534
-
1535
-        /** @var bool $rekey */
1536
-        $rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1537
-        if ($rekey || $st->needsRekey()) {
1538
-            // DO REKEY
1539
-            self::secretstream_xchacha20poly1305_rekey($state);
1540
-        }
1541
-        return array($out, $tag);
1542
-    }
1543
-
1544
-    /**
1545
-     * @param string $state
1546
-     * @return void
1547
-     * @throws SodiumException
1548
-     */
1549
-    public static function secretstream_xchacha20poly1305_rekey(&$state)
1550
-    {
1551
-        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1552
-        # unsigned char new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES +
1553
-        # crypto_secretstream_xchacha20poly1305_INONCEBYTES];
1554
-        # size_t        i;
1555
-        # for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1556
-        #     new_key_and_inonce[i] = state->k[i];
1557
-        # }
1558
-        $new_key_and_inonce = $st->getKey();
1559
-
1560
-        # for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1561
-        #     new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i] =
1562
-        #         STATE_INONCE(state)[i];
1563
-        # }
1564
-        $new_key_and_inonce .= ParagonIE_Sodium_Core32_Util::substR($st->getNonce(), 0, 8);
1565
-
1566
-        # crypto_stream_chacha20_ietf_xor(new_key_and_inonce, new_key_and_inonce,
1567
-        #                                 sizeof new_key_and_inonce,
1568
-        #                                 state->nonce, state->k);
1569
-
1570
-        $st->rekey(ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1571
-            $new_key_and_inonce,
1572
-            $st->getCombinedNonce(),
1573
-            $st->getKey(),
1574
-            ParagonIE_Sodium_Core32_Util::store64_le(0)
1575
-        ));
1576
-
1577
-        # for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1578
-        #     state->k[i] = new_key_and_inonce[i];
1579
-        # }
1580
-        # for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1581
-        #     STATE_INONCE(state)[i] =
1582
-        #          new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i];
1583
-        # }
1584
-        # _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1585
-        $st->counterReset();
1586
-
1587
-        $state = $st->toString();
1588
-    }
1589
-
1590
-    /**
1591
-     * Detached Ed25519 signature.
1592
-     *
1593
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1594
-     *
1595
-     * @param string $message
1596
-     * @param string $sk
1597
-     * @return string
1598
-     * @throws SodiumException
1599
-     * @throws TypeError
1600
-     */
1601
-    public static function sign_detached($message, $sk)
1602
-    {
1603
-        return ParagonIE_Sodium_Core32_Ed25519::sign_detached($message, $sk);
1604
-    }
1605
-
1606
-    /**
1607
-     * Attached Ed25519 signature. (Returns a signed message.)
1608
-     *
1609
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1610
-     *
1611
-     * @param string $message
1612
-     * @param string $sk
1613
-     * @return string
1614
-     * @throws SodiumException
1615
-     * @throws TypeError
1616
-     */
1617
-    public static function sign($message, $sk)
1618
-    {
1619
-        return ParagonIE_Sodium_Core32_Ed25519::sign($message, $sk);
1620
-    }
1621
-
1622
-    /**
1623
-     * Opens a signed message. If valid, returns the message.
1624
-     *
1625
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1626
-     *
1627
-     * @param string $signedMessage
1628
-     * @param string $pk
1629
-     * @return string
1630
-     * @throws SodiumException
1631
-     * @throws TypeError
1632
-     */
1633
-    public static function sign_open($signedMessage, $pk)
1634
-    {
1635
-        return ParagonIE_Sodium_Core32_Ed25519::sign_open($signedMessage, $pk);
1636
-    }
1637
-
1638
-    /**
1639
-     * Verify a detached signature of a given message and public key.
1640
-     *
1641
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1642
-     *
1643
-     * @param string $signature
1644
-     * @param string $message
1645
-     * @param string $pk
1646
-     * @return bool
1647
-     * @throws SodiumException
1648
-     * @throws TypeError
1649
-     */
1650
-    public static function sign_verify_detached($signature, $message, $pk)
1651
-    {
1652
-        return ParagonIE_Sodium_Core32_Ed25519::verify_detached($signature, $message, $pk);
1653
-    }
17
+	const aead_chacha20poly1305_KEYBYTES = 32;
18
+	const aead_chacha20poly1305_NSECBYTES = 0;
19
+	const aead_chacha20poly1305_NPUBBYTES = 8;
20
+	const aead_chacha20poly1305_ABYTES = 16;
21
+
22
+	const aead_chacha20poly1305_IETF_KEYBYTES = 32;
23
+	const aead_chacha20poly1305_IETF_NSECBYTES = 0;
24
+	const aead_chacha20poly1305_IETF_NPUBBYTES = 12;
25
+	const aead_chacha20poly1305_IETF_ABYTES = 16;
26
+
27
+	const aead_xchacha20poly1305_IETF_KEYBYTES = 32;
28
+	const aead_xchacha20poly1305_IETF_NSECBYTES = 0;
29
+	const aead_xchacha20poly1305_IETF_NPUBBYTES = 24;
30
+	const aead_xchacha20poly1305_IETF_ABYTES = 16;
31
+
32
+	const box_curve25519xsalsa20poly1305_SEEDBYTES = 32;
33
+	const box_curve25519xsalsa20poly1305_PUBLICKEYBYTES = 32;
34
+	const box_curve25519xsalsa20poly1305_SECRETKEYBYTES = 32;
35
+	const box_curve25519xsalsa20poly1305_BEFORENMBYTES = 32;
36
+	const box_curve25519xsalsa20poly1305_NONCEBYTES = 24;
37
+	const box_curve25519xsalsa20poly1305_MACBYTES = 16;
38
+	const box_curve25519xsalsa20poly1305_BOXZEROBYTES = 16;
39
+	const box_curve25519xsalsa20poly1305_ZEROBYTES = 32;
40
+
41
+	const onetimeauth_poly1305_BYTES = 16;
42
+	const onetimeauth_poly1305_KEYBYTES = 32;
43
+
44
+	const secretbox_xsalsa20poly1305_KEYBYTES = 32;
45
+	const secretbox_xsalsa20poly1305_NONCEBYTES = 24;
46
+	const secretbox_xsalsa20poly1305_MACBYTES = 16;
47
+	const secretbox_xsalsa20poly1305_BOXZEROBYTES = 16;
48
+	const secretbox_xsalsa20poly1305_ZEROBYTES = 32;
49
+
50
+	const secretbox_xchacha20poly1305_KEYBYTES = 32;
51
+	const secretbox_xchacha20poly1305_NONCEBYTES = 24;
52
+	const secretbox_xchacha20poly1305_MACBYTES = 16;
53
+	const secretbox_xchacha20poly1305_BOXZEROBYTES = 16;
54
+	const secretbox_xchacha20poly1305_ZEROBYTES = 32;
55
+
56
+	const stream_salsa20_KEYBYTES = 32;
57
+
58
+	/**
59
+	 * AEAD Decryption with ChaCha20-Poly1305
60
+	 *
61
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
62
+	 *
63
+	 * @param string $message
64
+	 * @param string $ad
65
+	 * @param string $nonce
66
+	 * @param string $key
67
+	 * @return string
68
+	 * @throws SodiumException
69
+	 * @throws TypeError
70
+	 */
71
+	public static function aead_chacha20poly1305_decrypt(
72
+		$message = '',
73
+		$ad = '',
74
+		$nonce = '',
75
+		$key = ''
76
+	) {
77
+		/** @var int $len - Length of message (ciphertext + MAC) */
78
+		$len = ParagonIE_Sodium_Core32_Util::strlen($message);
79
+
80
+		/** @var int  $clen - Length of ciphertext */
81
+		$clen = $len - self::aead_chacha20poly1305_ABYTES;
82
+
83
+		/** @var int $adlen - Length of associated data */
84
+		$adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
85
+
86
+		/** @var string $mac - Message authentication code */
87
+		$mac = ParagonIE_Sodium_Core32_Util::substr(
88
+			$message,
89
+			$clen,
90
+			self::aead_chacha20poly1305_ABYTES
91
+		);
92
+
93
+		/** @var string $ciphertext - The encrypted message (sans MAC) */
94
+		$ciphertext = ParagonIE_Sodium_Core32_Util::substr($message, 0, $clen);
95
+
96
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
97
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
98
+			32,
99
+			$nonce,
100
+			$key
101
+		);
102
+
103
+		/* Recalculate the Poly1305 authentication tag (MAC): */
104
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
105
+		try {
106
+			ParagonIE_Sodium_Compat::memzero($block0);
107
+		} catch (SodiumException $ex) {
108
+			$block0 = null;
109
+		}
110
+		$state->update($ad);
111
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
112
+		$state->update($ciphertext);
113
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($clen));
114
+		$computed_mac = $state->finish();
115
+
116
+		/* Compare the given MAC with the recalculated MAC: */
117
+		if (!ParagonIE_Sodium_Core32_Util::verify_16($computed_mac, $mac)) {
118
+			throw new SodiumException('Invalid MAC');
119
+		}
120
+
121
+		// Here, we know that the MAC is valid, so we decrypt and return the plaintext
122
+		return ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
123
+			$ciphertext,
124
+			$nonce,
125
+			$key,
126
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
127
+		);
128
+	}
129
+
130
+	/**
131
+	 * AEAD Encryption with ChaCha20-Poly1305
132
+	 *
133
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
134
+	 *
135
+	 * @param string $message
136
+	 * @param string $ad
137
+	 * @param string $nonce
138
+	 * @param string $key
139
+	 * @return string
140
+	 * @throws SodiumException
141
+	 * @throws TypeError
142
+	 */
143
+	public static function aead_chacha20poly1305_encrypt(
144
+		$message = '',
145
+		$ad = '',
146
+		$nonce = '',
147
+		$key = ''
148
+	) {
149
+		/** @var int $len - Length of the plaintext message */
150
+		$len = ParagonIE_Sodium_Core32_Util::strlen($message);
151
+
152
+		/** @var int $adlen - Length of the associated data */
153
+		$adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
154
+
155
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
156
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
157
+			32,
158
+			$nonce,
159
+			$key
160
+		);
161
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
162
+		try {
163
+			ParagonIE_Sodium_Compat::memzero($block0);
164
+		} catch (SodiumException $ex) {
165
+			$block0 = null;
166
+		}
167
+
168
+		/** @var string $ciphertext - Raw encrypted data */
169
+		$ciphertext = ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
170
+			$message,
171
+			$nonce,
172
+			$key,
173
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
174
+		);
175
+
176
+		$state->update($ad);
177
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
178
+		$state->update($ciphertext);
179
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($len));
180
+		return $ciphertext . $state->finish();
181
+	}
182
+
183
+	/**
184
+	 * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
185
+	 *
186
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
187
+	 *
188
+	 * @param string $message
189
+	 * @param string $ad
190
+	 * @param string $nonce
191
+	 * @param string $key
192
+	 * @return string
193
+	 * @throws SodiumException
194
+	 * @throws TypeError
195
+	 */
196
+	public static function aead_chacha20poly1305_ietf_decrypt(
197
+		$message = '',
198
+		$ad = '',
199
+		$nonce = '',
200
+		$key = ''
201
+	) {
202
+		/** @var int $adlen - Length of associated data */
203
+		$adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
204
+
205
+		/** @var int $len - Length of message (ciphertext + MAC) */
206
+		$len = ParagonIE_Sodium_Core32_Util::strlen($message);
207
+
208
+		/** @var int  $clen - Length of ciphertext */
209
+		$clen = $len - self::aead_chacha20poly1305_IETF_ABYTES;
210
+
211
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
212
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::ietfStream(
213
+			32,
214
+			$nonce,
215
+			$key
216
+		);
217
+
218
+		/** @var string $mac - Message authentication code */
219
+		$mac = ParagonIE_Sodium_Core32_Util::substr(
220
+			$message,
221
+			$len - self::aead_chacha20poly1305_IETF_ABYTES,
222
+			self::aead_chacha20poly1305_IETF_ABYTES
223
+		);
224
+
225
+		/** @var string $ciphertext - The encrypted message (sans MAC) */
226
+		$ciphertext = ParagonIE_Sodium_Core32_Util::substr(
227
+			$message,
228
+			0,
229
+			$len - self::aead_chacha20poly1305_IETF_ABYTES
230
+		);
231
+
232
+		/* Recalculate the Poly1305 authentication tag (MAC): */
233
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
234
+		try {
235
+			ParagonIE_Sodium_Compat::memzero($block0);
236
+		} catch (SodiumException $ex) {
237
+			$block0 = null;
238
+		}
239
+		$state->update($ad);
240
+		$state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
241
+		$state->update($ciphertext);
242
+		$state->update(str_repeat("\x00", (0x10 - $clen) & 0xf));
243
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
244
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($clen));
245
+		$computed_mac = $state->finish();
246
+
247
+		/* Compare the given MAC with the recalculated MAC: */
248
+		if (!ParagonIE_Sodium_Core32_Util::verify_16($computed_mac, $mac)) {
249
+			throw new SodiumException('Invalid MAC');
250
+		}
251
+
252
+		// Here, we know that the MAC is valid, so we decrypt and return the plaintext
253
+		return ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
254
+			$ciphertext,
255
+			$nonce,
256
+			$key,
257
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
258
+		);
259
+	}
260
+
261
+	/**
262
+	 * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
263
+	 *
264
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
265
+	 *
266
+	 * @param string $message
267
+	 * @param string $ad
268
+	 * @param string $nonce
269
+	 * @param string $key
270
+	 * @return string
271
+	 * @throws SodiumException
272
+	 * @throws TypeError
273
+	 */
274
+	public static function aead_chacha20poly1305_ietf_encrypt(
275
+		$message = '',
276
+		$ad = '',
277
+		$nonce = '',
278
+		$key = ''
279
+	) {
280
+		/** @var int $len - Length of the plaintext message */
281
+		$len = ParagonIE_Sodium_Core32_Util::strlen($message);
282
+
283
+		/** @var int $adlen - Length of the associated data */
284
+		$adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
285
+
286
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
287
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::ietfStream(
288
+			32,
289
+			$nonce,
290
+			$key
291
+		);
292
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
293
+		try {
294
+			ParagonIE_Sodium_Compat::memzero($block0);
295
+		} catch (SodiumException $ex) {
296
+			$block0 = null;
297
+		}
298
+
299
+		/** @var string $ciphertext - Raw encrypted data */
300
+		$ciphertext = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
301
+			$message,
302
+			$nonce,
303
+			$key,
304
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
305
+		);
306
+
307
+		$state->update($ad);
308
+		$state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
309
+		$state->update($ciphertext);
310
+		$state->update(str_repeat("\x00", ((0x10 - $len) & 0xf)));
311
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
312
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($len));
313
+		return $ciphertext . $state->finish();
314
+	}
315
+
316
+	/**
317
+	 * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
318
+	 *
319
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
320
+	 *
321
+	 * @param string $message
322
+	 * @param string $ad
323
+	 * @param string $nonce
324
+	 * @param string $key
325
+	 * @return string
326
+	 * @throws SodiumException
327
+	 * @throws TypeError
328
+	 */
329
+	public static function aead_xchacha20poly1305_ietf_decrypt(
330
+		$message = '',
331
+		$ad = '',
332
+		$nonce = '',
333
+		$key = ''
334
+	) {
335
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
336
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
337
+			$key
338
+		);
339
+		$nonceLast = "\x00\x00\x00\x00" .
340
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
341
+
342
+		return self::aead_chacha20poly1305_ietf_decrypt($message, $ad, $nonceLast, $subkey);
343
+	}
344
+
345
+	/**
346
+	 * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
347
+	 *
348
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
349
+	 *
350
+	 * @param string $message
351
+	 * @param string $ad
352
+	 * @param string $nonce
353
+	 * @param string $key
354
+	 * @return string
355
+	 * @throws SodiumException
356
+	 * @throws TypeError
357
+	 */
358
+	public static function aead_xchacha20poly1305_ietf_encrypt(
359
+		$message = '',
360
+		$ad = '',
361
+		$nonce = '',
362
+		$key = ''
363
+	) {
364
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
365
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
366
+			$key
367
+		);
368
+		$nonceLast = "\x00\x00\x00\x00" .
369
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
370
+
371
+		return self::aead_chacha20poly1305_ietf_encrypt($message, $ad, $nonceLast, $subkey);
372
+	}
373
+
374
+	/**
375
+	 * HMAC-SHA-512-256 (a.k.a. the leftmost 256 bits of HMAC-SHA-512)
376
+	 *
377
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
378
+	 *
379
+	 * @param string $message
380
+	 * @param string $key
381
+	 * @return string
382
+	 * @throws TypeError
383
+	 */
384
+	public static function auth($message, $key)
385
+	{
386
+		return ParagonIE_Sodium_Core32_Util::substr(
387
+			hash_hmac('sha512', $message, $key, true),
388
+			0,
389
+			32
390
+		);
391
+	}
392
+
393
+	/**
394
+	 * HMAC-SHA-512-256 validation. Constant-time via hash_equals().
395
+	 *
396
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
397
+	 *
398
+	 * @param string $mac
399
+	 * @param string $message
400
+	 * @param string $key
401
+	 * @return bool
402
+	 * @throws SodiumException
403
+	 * @throws TypeError
404
+	 */
405
+	public static function auth_verify($mac, $message, $key)
406
+	{
407
+		return ParagonIE_Sodium_Core32_Util::hashEquals(
408
+			$mac,
409
+			self::auth($message, $key)
410
+		);
411
+	}
412
+
413
+	/**
414
+	 * X25519 key exchange followed by XSalsa20Poly1305 symmetric encryption
415
+	 *
416
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
417
+	 *
418
+	 * @param string $plaintext
419
+	 * @param string $nonce
420
+	 * @param string $keypair
421
+	 * @return string
422
+	 * @throws SodiumException
423
+	 * @throws TypeError
424
+	 */
425
+	public static function box($plaintext, $nonce, $keypair)
426
+	{
427
+		return self::secretbox(
428
+			$plaintext,
429
+			$nonce,
430
+			self::box_beforenm(
431
+				self::box_secretkey($keypair),
432
+				self::box_publickey($keypair)
433
+			)
434
+		);
435
+	}
436
+
437
+	/**
438
+	 * X25519-XSalsa20-Poly1305 with one ephemeral X25519 keypair.
439
+	 *
440
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
441
+	 *
442
+	 * @param string $message
443
+	 * @param string $publicKey
444
+	 * @return string
445
+	 * @throws SodiumException
446
+	 * @throws TypeError
447
+	 */
448
+	public static function box_seal($message, $publicKey)
449
+	{
450
+		/** @var string $ephemeralKeypair */
451
+		$ephemeralKeypair = self::box_keypair();
452
+
453
+		/** @var string $ephemeralSK */
454
+		$ephemeralSK = self::box_secretkey($ephemeralKeypair);
455
+
456
+		/** @var string $ephemeralPK */
457
+		$ephemeralPK = self::box_publickey($ephemeralKeypair);
458
+
459
+		/** @var string $nonce */
460
+		$nonce = self::generichash(
461
+			$ephemeralPK . $publicKey,
462
+			'',
463
+			24
464
+		);
465
+
466
+		/** @var string $keypair - The combined keypair used in crypto_box() */
467
+		$keypair = self::box_keypair_from_secretkey_and_publickey($ephemeralSK, $publicKey);
468
+
469
+		/** @var string $ciphertext Ciphertext + MAC from crypto_box */
470
+		$ciphertext = self::box($message, $nonce, $keypair);
471
+		try {
472
+			ParagonIE_Sodium_Compat::memzero($ephemeralKeypair);
473
+			ParagonIE_Sodium_Compat::memzero($ephemeralSK);
474
+			ParagonIE_Sodium_Compat::memzero($nonce);
475
+		} catch (SodiumException $ex) {
476
+			$ephemeralKeypair = null;
477
+			$ephemeralSK = null;
478
+			$nonce = null;
479
+		}
480
+		return $ephemeralPK . $ciphertext;
481
+	}
482
+
483
+	/**
484
+	 * Opens a message encrypted via box_seal().
485
+	 *
486
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
487
+	 *
488
+	 * @param string $message
489
+	 * @param string $keypair
490
+	 * @return string
491
+	 * @throws SodiumException
492
+	 * @throws TypeError
493
+	 */
494
+	public static function box_seal_open($message, $keypair)
495
+	{
496
+		/** @var string $ephemeralPK */
497
+		$ephemeralPK = ParagonIE_Sodium_Core32_Util::substr($message, 0, 32);
498
+
499
+		/** @var string $ciphertext (ciphertext + MAC) */
500
+		$ciphertext = ParagonIE_Sodium_Core32_Util::substr($message, 32);
501
+
502
+		/** @var string $secretKey */
503
+		$secretKey = self::box_secretkey($keypair);
504
+
505
+		/** @var string $publicKey */
506
+		$publicKey = self::box_publickey($keypair);
507
+
508
+		/** @var string $nonce */
509
+		$nonce = self::generichash(
510
+			$ephemeralPK . $publicKey,
511
+			'',
512
+			24
513
+		);
514
+
515
+		/** @var string $keypair */
516
+		$keypair = self::box_keypair_from_secretkey_and_publickey($secretKey, $ephemeralPK);
517
+
518
+		/** @var string $m */
519
+		$m = self::box_open($ciphertext, $nonce, $keypair);
520
+		try {
521
+			ParagonIE_Sodium_Compat::memzero($secretKey);
522
+			ParagonIE_Sodium_Compat::memzero($ephemeralPK);
523
+			ParagonIE_Sodium_Compat::memzero($nonce);
524
+		} catch (SodiumException $ex) {
525
+			$secretKey = null;
526
+			$ephemeralPK = null;
527
+			$nonce = null;
528
+		}
529
+		return $m;
530
+	}
531
+
532
+	/**
533
+	 * Used by crypto_box() to get the crypto_secretbox() key.
534
+	 *
535
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
536
+	 *
537
+	 * @param string $sk
538
+	 * @param string $pk
539
+	 * @return string
540
+	 * @throws SodiumException
541
+	 * @throws TypeError
542
+	 */
543
+	public static function box_beforenm($sk, $pk)
544
+	{
545
+		return ParagonIE_Sodium_Core32_HSalsa20::hsalsa20(
546
+			str_repeat("\x00", 16),
547
+			self::scalarmult($sk, $pk)
548
+		);
549
+	}
550
+
551
+	/**
552
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
553
+	 *
554
+	 * @return string
555
+	 * @throws Exception
556
+	 * @throws SodiumException
557
+	 * @throws TypeError
558
+	 */
559
+	public static function box_keypair()
560
+	{
561
+		$sKey = random_bytes(32);
562
+		$pKey = self::scalarmult_base($sKey);
563
+		return $sKey . $pKey;
564
+	}
565
+
566
+	/**
567
+	 * @param string $seed
568
+	 * @return string
569
+	 * @throws SodiumException
570
+	 * @throws TypeError
571
+	 */
572
+	public static function box_seed_keypair($seed)
573
+	{
574
+		$sKey = ParagonIE_Sodium_Core32_Util::substr(
575
+			hash('sha512', $seed, true),
576
+			0,
577
+			32
578
+		);
579
+		$pKey = self::scalarmult_base($sKey);
580
+		return $sKey . $pKey;
581
+	}
582
+
583
+	/**
584
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
585
+	 *
586
+	 * @param string $sKey
587
+	 * @param string $pKey
588
+	 * @return string
589
+	 * @throws TypeError
590
+	 */
591
+	public static function box_keypair_from_secretkey_and_publickey($sKey, $pKey)
592
+	{
593
+		return ParagonIE_Sodium_Core32_Util::substr($sKey, 0, 32) .
594
+			ParagonIE_Sodium_Core32_Util::substr($pKey, 0, 32);
595
+	}
596
+
597
+	/**
598
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
599
+	 *
600
+	 * @param string $keypair
601
+	 * @return string
602
+	 * @throws RangeException
603
+	 * @throws TypeError
604
+	 */
605
+	public static function box_secretkey($keypair)
606
+	{
607
+		if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== 64) {
608
+			throw new RangeException(
609
+				'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
610
+			);
611
+		}
612
+		return ParagonIE_Sodium_Core32_Util::substr($keypair, 0, 32);
613
+	}
614
+
615
+	/**
616
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
617
+	 *
618
+	 * @param string $keypair
619
+	 * @return string
620
+	 * @throws RangeException
621
+	 * @throws TypeError
622
+	 */
623
+	public static function box_publickey($keypair)
624
+	{
625
+		if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
626
+			throw new RangeException(
627
+				'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
628
+			);
629
+		}
630
+		return ParagonIE_Sodium_Core32_Util::substr($keypair, 32, 32);
631
+	}
632
+
633
+	/**
634
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
635
+	 *
636
+	 * @param string $sKey
637
+	 * @return string
638
+	 * @throws RangeException
639
+	 * @throws SodiumException
640
+	 * @throws TypeError
641
+	 */
642
+	public static function box_publickey_from_secretkey($sKey)
643
+	{
644
+		if (ParagonIE_Sodium_Core32_Util::strlen($sKey) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES) {
645
+			throw new RangeException(
646
+				'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES bytes long.'
647
+			);
648
+		}
649
+		return self::scalarmult_base($sKey);
650
+	}
651
+
652
+	/**
653
+	 * Decrypt a message encrypted with box().
654
+	 *
655
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
656
+	 *
657
+	 * @param string $ciphertext
658
+	 * @param string $nonce
659
+	 * @param string $keypair
660
+	 * @return string
661
+	 * @throws SodiumException
662
+	 * @throws TypeError
663
+	 */
664
+	public static function box_open($ciphertext, $nonce, $keypair)
665
+	{
666
+		return self::secretbox_open(
667
+			$ciphertext,
668
+			$nonce,
669
+			self::box_beforenm(
670
+				self::box_secretkey($keypair),
671
+				self::box_publickey($keypair)
672
+			)
673
+		);
674
+	}
675
+
676
+	/**
677
+	 * Calculate a BLAKE2b hash.
678
+	 *
679
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
680
+	 *
681
+	 * @param string $message
682
+	 * @param string|null $key
683
+	 * @param int $outlen
684
+	 * @return string
685
+	 * @throws RangeException
686
+	 * @throws SodiumException
687
+	 * @throws TypeError
688
+	 */
689
+	public static function generichash($message, $key = '', $outlen = 32)
690
+	{
691
+		// This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
692
+		ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
693
+
694
+		$k = null;
695
+		if (!empty($key)) {
696
+			/** @var SplFixedArray $k */
697
+			$k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
698
+			if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
699
+				throw new RangeException('Invalid key size');
700
+			}
701
+		}
702
+
703
+		/** @var SplFixedArray $in */
704
+		$in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($message);
705
+
706
+		/** @var SplFixedArray $ctx */
707
+		$ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outlen);
708
+		ParagonIE_Sodium_Core32_BLAKE2b::update($ctx, $in, $in->count());
709
+
710
+		/** @var SplFixedArray $out */
711
+		$out = new SplFixedArray($outlen);
712
+		$out = ParagonIE_Sodium_Core32_BLAKE2b::finish($ctx, $out);
713
+
714
+		/** @var array<int, int> */
715
+		$outArray = $out->toArray();
716
+		return ParagonIE_Sodium_Core32_Util::intArrayToString($outArray);
717
+	}
718
+
719
+	/**
720
+	 * Finalize a BLAKE2b hashing context, returning the hash.
721
+	 *
722
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
723
+	 *
724
+	 * @param string $ctx
725
+	 * @param int $outlen
726
+	 * @return string
727
+	 * @throws SodiumException
728
+	 * @throws TypeError
729
+	 */
730
+	public static function generichash_final($ctx, $outlen = 32)
731
+	{
732
+		if (!is_string($ctx)) {
733
+			throw new TypeError('Context must be a string');
734
+		}
735
+		$out = new SplFixedArray($outlen);
736
+
737
+		/** @var SplFixedArray $context */
738
+		$context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext($ctx);
739
+
740
+		/** @var SplFixedArray $out */
741
+		$out = ParagonIE_Sodium_Core32_BLAKE2b::finish($context, $out);
742
+
743
+		/** @var array<int, int> */
744
+		$outArray = $out->toArray();
745
+		return ParagonIE_Sodium_Core32_Util::intArrayToString($outArray);
746
+	}
747
+
748
+	/**
749
+	 * Initialize a hashing context for BLAKE2b.
750
+	 *
751
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
752
+	 *
753
+	 * @param string $key
754
+	 * @param int $outputLength
755
+	 * @return string
756
+	 * @throws RangeException
757
+	 * @throws SodiumException
758
+	 * @throws TypeError
759
+	 */
760
+	public static function generichash_init($key = '', $outputLength = 32)
761
+	{
762
+		// This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
763
+		ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
764
+
765
+		$k = null;
766
+		if (!empty($key)) {
767
+			$k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
768
+			if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
769
+				throw new RangeException('Invalid key size');
770
+			}
771
+		}
772
+
773
+		/** @var SplFixedArray $ctx */
774
+		$ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outputLength);
775
+
776
+		return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($ctx);
777
+	}
778
+
779
+	/**
780
+	 * Initialize a hashing context for BLAKE2b.
781
+	 *
782
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
783
+	 *
784
+	 * @param string $key
785
+	 * @param int $outputLength
786
+	 * @param string $salt
787
+	 * @param string $personal
788
+	 * @return string
789
+	 * @throws RangeException
790
+	 * @throws SodiumException
791
+	 * @throws TypeError
792
+	 */
793
+	public static function generichash_init_salt_personal(
794
+		$key = '',
795
+		$outputLength = 32,
796
+		$salt = '',
797
+		$personal = ''
798
+	) {
799
+		// This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
800
+		ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
801
+
802
+		$k = null;
803
+		if (!empty($key)) {
804
+			$k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
805
+			if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
806
+				throw new RangeException('Invalid key size');
807
+			}
808
+		}
809
+		if (!empty($salt)) {
810
+			$s = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($salt);
811
+		} else {
812
+			$s = null;
813
+		}
814
+		if (!empty($salt)) {
815
+			$p = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($personal);
816
+		} else {
817
+			$p = null;
818
+		}
819
+
820
+		/** @var SplFixedArray $ctx */
821
+		$ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outputLength, $s, $p);
822
+
823
+		return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($ctx);
824
+	}
825
+
826
+	/**
827
+	 * Update a hashing context for BLAKE2b with $message
828
+	 *
829
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
830
+	 *
831
+	 * @param string $ctx
832
+	 * @param string $message
833
+	 * @return string
834
+	 * @throws SodiumException
835
+	 * @throws TypeError
836
+	 */
837
+	public static function generichash_update($ctx, $message)
838
+	{
839
+		// This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
840
+		ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
841
+
842
+		/** @var SplFixedArray $context */
843
+		$context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext($ctx);
844
+
845
+		/** @var SplFixedArray $in */
846
+		$in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($message);
847
+
848
+		ParagonIE_Sodium_Core32_BLAKE2b::update($context, $in, $in->count());
849
+
850
+		return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($context);
851
+	}
852
+
853
+	/**
854
+	 * Libsodium's crypto_kx().
855
+	 *
856
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
857
+	 *
858
+	 * @param string $my_sk
859
+	 * @param string $their_pk
860
+	 * @param string $client_pk
861
+	 * @param string $server_pk
862
+	 * @return string
863
+	 * @throws SodiumException
864
+	 * @throws TypeError
865
+	 */
866
+	public static function keyExchange($my_sk, $their_pk, $client_pk, $server_pk)
867
+	{
868
+		return self::generichash(
869
+			self::scalarmult($my_sk, $their_pk) .
870
+			$client_pk .
871
+			$server_pk
872
+		);
873
+	}
874
+
875
+	/**
876
+	 * ECDH over Curve25519
877
+	 *
878
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
879
+	 *
880
+	 * @param string $sKey
881
+	 * @param string $pKey
882
+	 * @return string
883
+	 *
884
+	 * @throws SodiumException
885
+	 * @throws TypeError
886
+	 */
887
+	public static function scalarmult($sKey, $pKey)
888
+	{
889
+		$q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10($sKey, $pKey);
890
+		self::scalarmult_throw_if_zero($q);
891
+		return $q;
892
+	}
893
+
894
+	/**
895
+	 * ECDH over Curve25519, using the basepoint.
896
+	 * Used to get a secret key from a public key.
897
+	 *
898
+	 * @param string $secret
899
+	 * @return string
900
+	 *
901
+	 * @throws SodiumException
902
+	 * @throws TypeError
903
+	 */
904
+	public static function scalarmult_base($secret)
905
+	{
906
+		$q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10_base($secret);
907
+		self::scalarmult_throw_if_zero($q);
908
+		return $q;
909
+	}
910
+
911
+	/**
912
+	 * This throws an Error if a zero public key was passed to the function.
913
+	 *
914
+	 * @param string $q
915
+	 * @return void
916
+	 * @throws SodiumException
917
+	 * @throws TypeError
918
+	 */
919
+	protected static function scalarmult_throw_if_zero($q)
920
+	{
921
+		$d = 0;
922
+		for ($i = 0; $i < self::box_curve25519xsalsa20poly1305_SECRETKEYBYTES; ++$i) {
923
+			$d |= ParagonIE_Sodium_Core32_Util::chrToInt($q[$i]);
924
+		}
925
+
926
+		/* branch-free variant of === 0 */
927
+		if (-(1 & (($d - 1) >> 8))) {
928
+			throw new SodiumException('Zero public key is not allowed');
929
+		}
930
+	}
931
+
932
+	/**
933
+	 * XSalsa20-Poly1305 authenticated symmetric-key encryption.
934
+	 *
935
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
936
+	 *
937
+	 * @param string $plaintext
938
+	 * @param string $nonce
939
+	 * @param string $key
940
+	 * @return string
941
+	 * @throws SodiumException
942
+	 * @throws TypeError
943
+	 */
944
+	public static function secretbox($plaintext, $nonce, $key)
945
+	{
946
+		/** @var string $subkey */
947
+		$subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
948
+
949
+		/** @var string $block0 */
950
+		$block0 = str_repeat("\x00", 32);
951
+
952
+		/** @var int $mlen - Length of the plaintext message */
953
+		$mlen = ParagonIE_Sodium_Core32_Util::strlen($plaintext);
954
+		$mlen0 = $mlen;
955
+		if ($mlen0 > 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES) {
956
+			$mlen0 = 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES;
957
+		}
958
+		$block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
959
+
960
+		/** @var string $block0 */
961
+		$block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor(
962
+			$block0,
963
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
964
+			$subkey
965
+		);
966
+
967
+		/** @var string $c */
968
+		$c = ParagonIE_Sodium_Core32_Util::substr(
969
+			$block0,
970
+			self::secretbox_xsalsa20poly1305_ZEROBYTES
971
+		);
972
+		if ($mlen > $mlen0) {
973
+			$c .= ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
974
+				ParagonIE_Sodium_Core32_Util::substr(
975
+					$plaintext,
976
+					self::secretbox_xsalsa20poly1305_ZEROBYTES
977
+				),
978
+				ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
979
+				1,
980
+				$subkey
981
+			);
982
+		}
983
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State(
984
+			ParagonIE_Sodium_Core32_Util::substr(
985
+				$block0,
986
+				0,
987
+				self::onetimeauth_poly1305_KEYBYTES
988
+			)
989
+		);
990
+		try {
991
+			ParagonIE_Sodium_Compat::memzero($block0);
992
+			ParagonIE_Sodium_Compat::memzero($subkey);
993
+		} catch (SodiumException $ex) {
994
+			$block0 = null;
995
+			$subkey = null;
996
+		}
997
+
998
+		$state->update($c);
999
+
1000
+		/** @var string $c - MAC || ciphertext */
1001
+		$c = $state->finish() . $c;
1002
+		unset($state);
1003
+
1004
+		return $c;
1005
+	}
1006
+
1007
+	/**
1008
+	 * Decrypt a ciphertext generated via secretbox().
1009
+	 *
1010
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1011
+	 *
1012
+	 * @param string $ciphertext
1013
+	 * @param string $nonce
1014
+	 * @param string $key
1015
+	 * @return string
1016
+	 * @throws SodiumException
1017
+	 * @throws TypeError
1018
+	 */
1019
+	public static function secretbox_open($ciphertext, $nonce, $key)
1020
+	{
1021
+		/** @var string $mac */
1022
+		$mac = ParagonIE_Sodium_Core32_Util::substr(
1023
+			$ciphertext,
1024
+			0,
1025
+			self::secretbox_xsalsa20poly1305_MACBYTES
1026
+		);
1027
+
1028
+		/** @var string $c */
1029
+		$c = ParagonIE_Sodium_Core32_Util::substr(
1030
+			$ciphertext,
1031
+			self::secretbox_xsalsa20poly1305_MACBYTES
1032
+		);
1033
+
1034
+		/** @var int $clen */
1035
+		$clen = ParagonIE_Sodium_Core32_Util::strlen($c);
1036
+
1037
+		/** @var string $subkey */
1038
+		$subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
1039
+
1040
+		/** @var string $block0 */
1041
+		$block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20(
1042
+			64,
1043
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1044
+			$subkey
1045
+		);
1046
+		$verified = ParagonIE_Sodium_Core32_Poly1305::onetimeauth_verify(
1047
+			$mac,
1048
+			$c,
1049
+			ParagonIE_Sodium_Core32_Util::substr($block0, 0, 32)
1050
+		);
1051
+		if (!$verified) {
1052
+			try {
1053
+				ParagonIE_Sodium_Compat::memzero($subkey);
1054
+			} catch (SodiumException $ex) {
1055
+				$subkey = null;
1056
+			}
1057
+			throw new SodiumException('Invalid MAC');
1058
+		}
1059
+
1060
+		/** @var string $m - Decrypted message */
1061
+		$m = ParagonIE_Sodium_Core32_Util::xorStrings(
1062
+			ParagonIE_Sodium_Core32_Util::substr($block0, self::secretbox_xsalsa20poly1305_ZEROBYTES),
1063
+			ParagonIE_Sodium_Core32_Util::substr($c, 0, self::secretbox_xsalsa20poly1305_ZEROBYTES)
1064
+		);
1065
+		if ($clen > self::secretbox_xsalsa20poly1305_ZEROBYTES) {
1066
+			// We had more than 1 block, so let's continue to decrypt the rest.
1067
+			$m .= ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
1068
+				ParagonIE_Sodium_Core32_Util::substr(
1069
+					$c,
1070
+					self::secretbox_xsalsa20poly1305_ZEROBYTES
1071
+				),
1072
+				ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1073
+				1,
1074
+				(string) $subkey
1075
+			);
1076
+		}
1077
+		return $m;
1078
+	}
1079
+
1080
+	/**
1081
+	 * XChaCha20-Poly1305 authenticated symmetric-key encryption.
1082
+	 *
1083
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1084
+	 *
1085
+	 * @param string $plaintext
1086
+	 * @param string $nonce
1087
+	 * @param string $key
1088
+	 * @return string
1089
+	 * @throws SodiumException
1090
+	 * @throws TypeError
1091
+	 */
1092
+	public static function secretbox_xchacha20poly1305($plaintext, $nonce, $key)
1093
+	{
1094
+		/** @var string $subkey */
1095
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1096
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
1097
+			$key
1098
+		);
1099
+		$nonceLast = ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
1100
+
1101
+		/** @var string $block0 */
1102
+		$block0 = str_repeat("\x00", 32);
1103
+
1104
+		/** @var int $mlen - Length of the plaintext message */
1105
+		$mlen = ParagonIE_Sodium_Core32_Util::strlen($plaintext);
1106
+		$mlen0 = $mlen;
1107
+		if ($mlen0 > 64 - self::secretbox_xchacha20poly1305_ZEROBYTES) {
1108
+			$mlen0 = 64 - self::secretbox_xchacha20poly1305_ZEROBYTES;
1109
+		}
1110
+		$block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
1111
+
1112
+		/** @var string $block0 */
1113
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1114
+			$block0,
1115
+			$nonceLast,
1116
+			$subkey
1117
+		);
1118
+
1119
+		/** @var string $c */
1120
+		$c = ParagonIE_Sodium_Core32_Util::substr(
1121
+			$block0,
1122
+			self::secretbox_xchacha20poly1305_ZEROBYTES
1123
+		);
1124
+		if ($mlen > $mlen0) {
1125
+			$c .= ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1126
+				ParagonIE_Sodium_Core32_Util::substr(
1127
+					$plaintext,
1128
+					self::secretbox_xchacha20poly1305_ZEROBYTES
1129
+				),
1130
+				$nonceLast,
1131
+				$subkey,
1132
+				ParagonIE_Sodium_Core32_Util::store64_le(1)
1133
+			);
1134
+		}
1135
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State(
1136
+			ParagonIE_Sodium_Core32_Util::substr(
1137
+				$block0,
1138
+				0,
1139
+				self::onetimeauth_poly1305_KEYBYTES
1140
+			)
1141
+		);
1142
+		try {
1143
+			ParagonIE_Sodium_Compat::memzero($block0);
1144
+			ParagonIE_Sodium_Compat::memzero($subkey);
1145
+		} catch (SodiumException $ex) {
1146
+			$block0 = null;
1147
+			$subkey = null;
1148
+		}
1149
+
1150
+		$state->update($c);
1151
+
1152
+		/** @var string $c - MAC || ciphertext */
1153
+		$c = $state->finish() . $c;
1154
+		unset($state);
1155
+
1156
+		return $c;
1157
+	}
1158
+
1159
+	/**
1160
+	 * Decrypt a ciphertext generated via secretbox_xchacha20poly1305().
1161
+	 *
1162
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1163
+	 *
1164
+	 * @param string $ciphertext
1165
+	 * @param string $nonce
1166
+	 * @param string $key
1167
+	 * @return string
1168
+	 * @throws SodiumException
1169
+	 * @throws TypeError
1170
+	 */
1171
+	public static function secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key)
1172
+	{
1173
+		/** @var string $mac */
1174
+		$mac = ParagonIE_Sodium_Core32_Util::substr(
1175
+			$ciphertext,
1176
+			0,
1177
+			self::secretbox_xchacha20poly1305_MACBYTES
1178
+		);
1179
+
1180
+		/** @var string $c */
1181
+		$c = ParagonIE_Sodium_Core32_Util::substr(
1182
+			$ciphertext,
1183
+			self::secretbox_xchacha20poly1305_MACBYTES
1184
+		);
1185
+
1186
+		/** @var int $clen */
1187
+		$clen = ParagonIE_Sodium_Core32_Util::strlen($c);
1188
+
1189
+		/** @var string $subkey */
1190
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hchacha20($nonce, $key);
1191
+
1192
+		/** @var string $block0 */
1193
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
1194
+			64,
1195
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1196
+			$subkey
1197
+		);
1198
+		$verified = ParagonIE_Sodium_Core32_Poly1305::onetimeauth_verify(
1199
+			$mac,
1200
+			$c,
1201
+			ParagonIE_Sodium_Core32_Util::substr($block0, 0, 32)
1202
+		);
1203
+
1204
+		if (!$verified) {
1205
+			try {
1206
+				ParagonIE_Sodium_Compat::memzero($subkey);
1207
+			} catch (SodiumException $ex) {
1208
+				$subkey = null;
1209
+			}
1210
+			throw new SodiumException('Invalid MAC');
1211
+		}
1212
+
1213
+		/** @var string $m - Decrypted message */
1214
+		$m = ParagonIE_Sodium_Core32_Util::xorStrings(
1215
+			ParagonIE_Sodium_Core32_Util::substr($block0, self::secretbox_xchacha20poly1305_ZEROBYTES),
1216
+			ParagonIE_Sodium_Core32_Util::substr($c, 0, self::secretbox_xchacha20poly1305_ZEROBYTES)
1217
+		);
1218
+
1219
+		if ($clen > self::secretbox_xchacha20poly1305_ZEROBYTES) {
1220
+			// We had more than 1 block, so let's continue to decrypt the rest.
1221
+			$m .= ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1222
+				ParagonIE_Sodium_Core32_Util::substr(
1223
+					$c,
1224
+					self::secretbox_xchacha20poly1305_ZEROBYTES
1225
+				),
1226
+				ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1227
+				(string) $subkey,
1228
+				ParagonIE_Sodium_Core32_Util::store64_le(1)
1229
+			);
1230
+		}
1231
+		return $m;
1232
+	}
1233
+
1234
+	/**
1235
+	 * @param string $key
1236
+	 * @return array<int, string> Returns a state and a header.
1237
+	 * @throws Exception
1238
+	 * @throws SodiumException
1239
+	 */
1240
+	public static function secretstream_xchacha20poly1305_init_push($key)
1241
+	{
1242
+		# randombytes_buf(out, crypto_secretstream_xchacha20poly1305_HEADERBYTES);
1243
+		$out = random_bytes(24);
1244
+
1245
+		# crypto_core_hchacha20(state->k, out, k, NULL);
1246
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20($out, $key);
1247
+		$state = new ParagonIE_Sodium_Core32_SecretStream_State(
1248
+			$subkey,
1249
+			ParagonIE_Sodium_Core32_Util::substr($out, 16, 8) . str_repeat("\0", 4)
1250
+		);
1251
+
1252
+		# _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1253
+		$state->counterReset();
1254
+
1255
+		# memcpy(STATE_INONCE(state), out + crypto_core_hchacha20_INPUTBYTES,
1256
+		#        crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1257
+		# memset(state->_pad, 0, sizeof state->_pad);
1258
+		return array(
1259
+			$state->toString(),
1260
+			$out
1261
+		);
1262
+	}
1263
+
1264
+	/**
1265
+	 * @param string $key
1266
+	 * @param string $header
1267
+	 * @return string Returns a state.
1268
+	 * @throws Exception
1269
+	 */
1270
+	public static function secretstream_xchacha20poly1305_init_pull($key, $header)
1271
+	{
1272
+		# crypto_core_hchacha20(state->k, in, k, NULL);
1273
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1274
+			ParagonIE_Sodium_Core32_Util::substr($header, 0, 16),
1275
+			$key
1276
+		);
1277
+		$state = new ParagonIE_Sodium_Core32_SecretStream_State(
1278
+			$subkey,
1279
+			ParagonIE_Sodium_Core32_Util::substr($header, 16)
1280
+		);
1281
+		$state->counterReset();
1282
+		# memcpy(STATE_INONCE(state), in + crypto_core_hchacha20_INPUTBYTES,
1283
+		#     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1284
+		# memset(state->_pad, 0, sizeof state->_pad);
1285
+		# return 0;
1286
+		return $state->toString();
1287
+	}
1288
+
1289
+	/**
1290
+	 * @param string $state
1291
+	 * @param string $msg
1292
+	 * @param string $aad
1293
+	 * @param int $tag
1294
+	 * @return string
1295
+	 * @throws SodiumException
1296
+	 */
1297
+	public static function secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0)
1298
+	{
1299
+		$st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1300
+		# crypto_onetimeauth_poly1305_state poly1305_state;
1301
+		# unsigned char                     block[64U];
1302
+		# unsigned char                     slen[8U];
1303
+		# unsigned char                    *c;
1304
+		# unsigned char                    *mac;
1305
+
1306
+		$msglen = ParagonIE_Sodium_Core32_Util::strlen($msg);
1307
+		$aadlen = ParagonIE_Sodium_Core32_Util::strlen($aad);
1308
+
1309
+		if ((($msglen + 63) >> 6) > 0xfffffffe) {
1310
+			throw new SodiumException(
1311
+				'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1312
+			);
1313
+		}
1314
+
1315
+		# if (outlen_p != NULL) {
1316
+		#     *outlen_p = 0U;
1317
+		# }
1318
+		# if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1319
+		#     sodium_misuse();
1320
+		# }
1321
+
1322
+		# crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1323
+		# crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1324
+		# sodium_memzero(block, sizeof block);
1325
+		$auth = new ParagonIE_Sodium_Core32_Poly1305_State(
1326
+			ParagonIE_Sodium_Core32_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1327
+		);
1328
+
1329
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1330
+		$auth->update($aad);
1331
+
1332
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1333
+		#     (0x10 - adlen) & 0xf);
1334
+		$auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1335
+
1336
+		# memset(block, 0, sizeof block);
1337
+		# block[0] = tag;
1338
+		# crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1339
+		#                                    state->nonce, 1U, state->k);
1340
+		$block = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1341
+			ParagonIE_Sodium_Core32_Util::intToChr($tag) . str_repeat("\0", 63),
1342
+			$st->getCombinedNonce(),
1343
+			$st->getKey(),
1344
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
1345
+		);
1346
+
1347
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1348
+		$auth->update($block);
1349
+
1350
+		# out[0] = block[0];
1351
+		$out = $block[0];
1352
+		# c = out + (sizeof tag);
1353
+		# crypto_stream_chacha20_ietf_xor_ic(c, m, mlen, state->nonce, 2U, state->k);
1354
+		$cipher = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1355
+			$msg,
1356
+			$st->getCombinedNonce(),
1357
+			$st->getKey(),
1358
+			ParagonIE_Sodium_Core32_Util::store64_le(2)
1359
+		);
1360
+
1361
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1362
+		$auth->update($cipher);
1363
+
1364
+		$out .= $cipher;
1365
+		unset($cipher);
1366
+
1367
+		# crypto_onetimeauth_poly1305_update
1368
+		# (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1369
+		$auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1370
+
1371
+		# STORE64_LE(slen, (uint64_t) adlen);
1372
+		$slen = ParagonIE_Sodium_Core32_Util::store64_le($aadlen);
1373
+
1374
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1375
+		$auth->update($slen);
1376
+
1377
+		# STORE64_LE(slen, (sizeof block) + mlen);
1378
+		$slen = ParagonIE_Sodium_Core32_Util::store64_le(64 + $msglen);
1379
+
1380
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1381
+		$auth->update($slen);
1382
+
1383
+		# mac = c + mlen;
1384
+		# crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1385
+		$mac = $auth->finish();
1386
+		$out .= $mac;
1387
+
1388
+		# sodium_memzero(&poly1305_state, sizeof poly1305_state);
1389
+		unset($auth);
1390
+
1391
+
1392
+		# XOR_BUF(STATE_INONCE(state), mac,
1393
+		#     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1394
+		$st->xorNonce($mac);
1395
+
1396
+		# sodium_increment(STATE_COUNTER(state),
1397
+		#     crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1398
+		$st->incrementCounter();
1399
+		// Overwrite by reference:
1400
+		$state = $st->toString();
1401
+
1402
+		/** @var bool $rekey */
1403
+		$rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1404
+		# if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1405
+		#     sodium_is_zero(STATE_COUNTER(state),
1406
+		#         crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1407
+		#     crypto_secretstream_xchacha20poly1305_rekey(state);
1408
+		# }
1409
+		if ($rekey || $st->needsRekey()) {
1410
+			// DO REKEY
1411
+			self::secretstream_xchacha20poly1305_rekey($state);
1412
+		}
1413
+		# if (outlen_p != NULL) {
1414
+		#     *outlen_p = crypto_secretstream_xchacha20poly1305_ABYTES + mlen;
1415
+		# }
1416
+		return $out;
1417
+	}
1418
+
1419
+	/**
1420
+	 * @param string $state
1421
+	 * @param string $cipher
1422
+	 * @param string $aad
1423
+	 * @return bool|array{0: string, 1: int}
1424
+	 * @throws SodiumException
1425
+	 */
1426
+	public static function secretstream_xchacha20poly1305_pull(&$state, $cipher, $aad = '')
1427
+	{
1428
+		$st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1429
+
1430
+		$cipherlen = ParagonIE_Sodium_Core32_Util::strlen($cipher);
1431
+		#     mlen = inlen - crypto_secretstream_xchacha20poly1305_ABYTES;
1432
+		$msglen = $cipherlen - ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_ABYTES;
1433
+		$aadlen = ParagonIE_Sodium_Core32_Util::strlen($aad);
1434
+
1435
+		#     if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1436
+		#         sodium_misuse();
1437
+		#     }
1438
+		if ((($msglen + 63) >> 6) > 0xfffffffe) {
1439
+			throw new SodiumException(
1440
+				'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1441
+			);
1442
+		}
1443
+
1444
+		#     crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1445
+		#     crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1446
+		#     sodium_memzero(block, sizeof block);
1447
+		$auth = new ParagonIE_Sodium_Core32_Poly1305_State(
1448
+			ParagonIE_Sodium_Core32_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1449
+		);
1450
+
1451
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1452
+		$auth->update($aad);
1453
+
1454
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1455
+		#         (0x10 - adlen) & 0xf);
1456
+		$auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1457
+
1458
+
1459
+		#     memset(block, 0, sizeof block);
1460
+		#     block[0] = in[0];
1461
+		#     crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1462
+		#                                        state->nonce, 1U, state->k);
1463
+		$block = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1464
+			$cipher[0] . str_repeat("\0", 63),
1465
+			$st->getCombinedNonce(),
1466
+			$st->getKey(),
1467
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
1468
+		);
1469
+		#     tag = block[0];
1470
+		#     block[0] = in[0];
1471
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1472
+		$tag = ParagonIE_Sodium_Core32_Util::chrToInt($block[0]);
1473
+		$block[0] = $cipher[0];
1474
+		$auth->update($block);
1475
+
1476
+
1477
+		#     c = in + (sizeof tag);
1478
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1479
+		$auth->update(ParagonIE_Sodium_Core32_Util::substr($cipher, 1, $msglen));
1480
+
1481
+		#     crypto_onetimeauth_poly1305_update
1482
+		#     (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1483
+		$auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1484
+
1485
+		#     STORE64_LE(slen, (uint64_t) adlen);
1486
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1487
+		$slen = ParagonIE_Sodium_Core32_Util::store64_le($aadlen);
1488
+		$auth->update($slen);
1489
+
1490
+		#     STORE64_LE(slen, (sizeof block) + mlen);
1491
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1492
+		$slen = ParagonIE_Sodium_Core32_Util::store64_le(64 + $msglen);
1493
+		$auth->update($slen);
1494
+
1495
+		#     crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1496
+		#     sodium_memzero(&poly1305_state, sizeof poly1305_state);
1497
+		$mac = $auth->finish();
1498
+
1499
+		#     stored_mac = c + mlen;
1500
+		#     if (sodium_memcmp(mac, stored_mac, sizeof mac) != 0) {
1501
+		#     sodium_memzero(mac, sizeof mac);
1502
+		#         return -1;
1503
+		#     }
1504
+
1505
+		$stored = ParagonIE_Sodium_Core32_Util::substr($cipher, $msglen + 1, 16);
1506
+		if (!ParagonIE_Sodium_Core32_Util::hashEquals($mac, $stored)) {
1507
+			return false;
1508
+		}
1509
+
1510
+		#     crypto_stream_chacha20_ietf_xor_ic(m, c, mlen, state->nonce, 2U, state->k);
1511
+		$out = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1512
+			ParagonIE_Sodium_Core32_Util::substr($cipher, 1, $msglen),
1513
+			$st->getCombinedNonce(),
1514
+			$st->getKey(),
1515
+			ParagonIE_Sodium_Core32_Util::store64_le(2)
1516
+		);
1517
+
1518
+		#     XOR_BUF(STATE_INONCE(state), mac,
1519
+		#         crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1520
+		$st->xorNonce($mac);
1521
+
1522
+		#     sodium_increment(STATE_COUNTER(state),
1523
+		#         crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1524
+		$st->incrementCounter();
1525
+
1526
+		#     if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1527
+		#         sodium_is_zero(STATE_COUNTER(state),
1528
+		#             crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1529
+		#         crypto_secretstream_xchacha20poly1305_rekey(state);
1530
+		#     }
1531
+
1532
+		// Overwrite by reference:
1533
+		$state = $st->toString();
1534
+
1535
+		/** @var bool $rekey */
1536
+		$rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1537
+		if ($rekey || $st->needsRekey()) {
1538
+			// DO REKEY
1539
+			self::secretstream_xchacha20poly1305_rekey($state);
1540
+		}
1541
+		return array($out, $tag);
1542
+	}
1543
+
1544
+	/**
1545
+	 * @param string $state
1546
+	 * @return void
1547
+	 * @throws SodiumException
1548
+	 */
1549
+	public static function secretstream_xchacha20poly1305_rekey(&$state)
1550
+	{
1551
+		$st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1552
+		# unsigned char new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES +
1553
+		# crypto_secretstream_xchacha20poly1305_INONCEBYTES];
1554
+		# size_t        i;
1555
+		# for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1556
+		#     new_key_and_inonce[i] = state->k[i];
1557
+		# }
1558
+		$new_key_and_inonce = $st->getKey();
1559
+
1560
+		# for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1561
+		#     new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i] =
1562
+		#         STATE_INONCE(state)[i];
1563
+		# }
1564
+		$new_key_and_inonce .= ParagonIE_Sodium_Core32_Util::substR($st->getNonce(), 0, 8);
1565
+
1566
+		# crypto_stream_chacha20_ietf_xor(new_key_and_inonce, new_key_and_inonce,
1567
+		#                                 sizeof new_key_and_inonce,
1568
+		#                                 state->nonce, state->k);
1569
+
1570
+		$st->rekey(ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1571
+			$new_key_and_inonce,
1572
+			$st->getCombinedNonce(),
1573
+			$st->getKey(),
1574
+			ParagonIE_Sodium_Core32_Util::store64_le(0)
1575
+		));
1576
+
1577
+		# for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1578
+		#     state->k[i] = new_key_and_inonce[i];
1579
+		# }
1580
+		# for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1581
+		#     STATE_INONCE(state)[i] =
1582
+		#          new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i];
1583
+		# }
1584
+		# _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1585
+		$st->counterReset();
1586
+
1587
+		$state = $st->toString();
1588
+	}
1589
+
1590
+	/**
1591
+	 * Detached Ed25519 signature.
1592
+	 *
1593
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1594
+	 *
1595
+	 * @param string $message
1596
+	 * @param string $sk
1597
+	 * @return string
1598
+	 * @throws SodiumException
1599
+	 * @throws TypeError
1600
+	 */
1601
+	public static function sign_detached($message, $sk)
1602
+	{
1603
+		return ParagonIE_Sodium_Core32_Ed25519::sign_detached($message, $sk);
1604
+	}
1605
+
1606
+	/**
1607
+	 * Attached Ed25519 signature. (Returns a signed message.)
1608
+	 *
1609
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1610
+	 *
1611
+	 * @param string $message
1612
+	 * @param string $sk
1613
+	 * @return string
1614
+	 * @throws SodiumException
1615
+	 * @throws TypeError
1616
+	 */
1617
+	public static function sign($message, $sk)
1618
+	{
1619
+		return ParagonIE_Sodium_Core32_Ed25519::sign($message, $sk);
1620
+	}
1621
+
1622
+	/**
1623
+	 * Opens a signed message. If valid, returns the message.
1624
+	 *
1625
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1626
+	 *
1627
+	 * @param string $signedMessage
1628
+	 * @param string $pk
1629
+	 * @return string
1630
+	 * @throws SodiumException
1631
+	 * @throws TypeError
1632
+	 */
1633
+	public static function sign_open($signedMessage, $pk)
1634
+	{
1635
+		return ParagonIE_Sodium_Core32_Ed25519::sign_open($signedMessage, $pk);
1636
+	}
1637
+
1638
+	/**
1639
+	 * Verify a detached signature of a given message and public key.
1640
+	 *
1641
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1642
+	 *
1643
+	 * @param string $signature
1644
+	 * @param string $message
1645
+	 * @param string $pk
1646
+	 * @return bool
1647
+	 * @throws SodiumException
1648
+	 * @throws TypeError
1649
+	 */
1650
+	public static function sign_verify_detached($signature, $message, $pk)
1651
+	{
1652
+		return ParagonIE_Sodium_Core32_Ed25519::verify_detached($signature, $message, $pk);
1653
+	}
1654 1654
 }
Please login to merge, or discard this patch.
Spacing   +290 added lines, -290 removed lines patch added patch discarded remove patch
@@ -1,6 +1,6 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3
-if (class_exists('ParagonIE_Sodium_Crypto32', false)) {
3
+if ( class_exists( 'ParagonIE_Sodium_Crypto32', false ) ) {
4 4
     return;
5 5
 }
6 6
 
@@ -75,13 +75,13 @@  discard block
 block discarded – undo
75 75
         $key = ''
76 76
     ) {
77 77
         /** @var int $len - Length of message (ciphertext + MAC) */
78
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
78
+        $len = ParagonIE_Sodium_Core32_Util::strlen( $message );
79 79
 
80 80
         /** @var int  $clen - Length of ciphertext */
81 81
         $clen = $len - self::aead_chacha20poly1305_ABYTES;
82 82
 
83 83
         /** @var int $adlen - Length of associated data */
84
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
84
+        $adlen = ParagonIE_Sodium_Core32_Util::strlen( $ad );
85 85
 
86 86
         /** @var string $mac - Message authentication code */
87 87
         $mac = ParagonIE_Sodium_Core32_Util::substr(
@@ -91,7 +91,7 @@  discard block
 block discarded – undo
91 91
         );
92 92
 
93 93
         /** @var string $ciphertext - The encrypted message (sans MAC) */
94
-        $ciphertext = ParagonIE_Sodium_Core32_Util::substr($message, 0, $clen);
94
+        $ciphertext = ParagonIE_Sodium_Core32_Util::substr( $message, 0, $clen );
95 95
 
96 96
         /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
97 97
         $block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
@@ -101,21 +101,21 @@  discard block
 block discarded – undo
101 101
         );
102 102
 
103 103
         /* Recalculate the Poly1305 authentication tag (MAC): */
104
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
104
+        $state = new ParagonIE_Sodium_Core32_Poly1305_State( $block0 );
105 105
         try {
106
-            ParagonIE_Sodium_Compat::memzero($block0);
107
-        } catch (SodiumException $ex) {
106
+            ParagonIE_Sodium_Compat::memzero( $block0 );
107
+        } catch ( SodiumException $ex ) {
108 108
             $block0 = null;
109 109
         }
110
-        $state->update($ad);
111
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
112
-        $state->update($ciphertext);
113
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($clen));
110
+        $state->update( $ad );
111
+        $state->update( ParagonIE_Sodium_Core32_Util::store64_le( $adlen ) );
112
+        $state->update( $ciphertext );
113
+        $state->update( ParagonIE_Sodium_Core32_Util::store64_le( $clen ) );
114 114
         $computed_mac = $state->finish();
115 115
 
116 116
         /* Compare the given MAC with the recalculated MAC: */
117
-        if (!ParagonIE_Sodium_Core32_Util::verify_16($computed_mac, $mac)) {
118
-            throw new SodiumException('Invalid MAC');
117
+        if ( ! ParagonIE_Sodium_Core32_Util::verify_16( $computed_mac, $mac ) ) {
118
+            throw new SodiumException( 'Invalid MAC' );
119 119
         }
120 120
 
121 121
         // Here, we know that the MAC is valid, so we decrypt and return the plaintext
@@ -123,7 +123,7 @@  discard block
 block discarded – undo
123 123
             $ciphertext,
124 124
             $nonce,
125 125
             $key,
126
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
126
+            ParagonIE_Sodium_Core32_Util::store64_le( 1 )
127 127
         );
128 128
     }
129 129
 
@@ -147,10 +147,10 @@  discard block
 block discarded – undo
147 147
         $key = ''
148 148
     ) {
149 149
         /** @var int $len - Length of the plaintext message */
150
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
150
+        $len = ParagonIE_Sodium_Core32_Util::strlen( $message );
151 151
 
152 152
         /** @var int $adlen - Length of the associated data */
153
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
153
+        $adlen = ParagonIE_Sodium_Core32_Util::strlen( $ad );
154 154
 
155 155
         /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
156 156
         $block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
@@ -158,10 +158,10 @@  discard block
 block discarded – undo
158 158
             $nonce,
159 159
             $key
160 160
         );
161
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
161
+        $state = new ParagonIE_Sodium_Core32_Poly1305_State( $block0 );
162 162
         try {
163
-            ParagonIE_Sodium_Compat::memzero($block0);
164
-        } catch (SodiumException $ex) {
163
+            ParagonIE_Sodium_Compat::memzero( $block0 );
164
+        } catch ( SodiumException $ex ) {
165 165
             $block0 = null;
166 166
         }
167 167
 
@@ -170,13 +170,13 @@  discard block
 block discarded – undo
170 170
             $message,
171 171
             $nonce,
172 172
             $key,
173
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
173
+            ParagonIE_Sodium_Core32_Util::store64_le( 1 )
174 174
         );
175 175
 
176
-        $state->update($ad);
177
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
178
-        $state->update($ciphertext);
179
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($len));
176
+        $state->update( $ad );
177
+        $state->update( ParagonIE_Sodium_Core32_Util::store64_le( $adlen ) );
178
+        $state->update( $ciphertext );
179
+        $state->update( ParagonIE_Sodium_Core32_Util::store64_le( $len ) );
180 180
         return $ciphertext . $state->finish();
181 181
     }
182 182
 
@@ -200,10 +200,10 @@  discard block
 block discarded – undo
200 200
         $key = ''
201 201
     ) {
202 202
         /** @var int $adlen - Length of associated data */
203
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
203
+        $adlen = ParagonIE_Sodium_Core32_Util::strlen( $ad );
204 204
 
205 205
         /** @var int $len - Length of message (ciphertext + MAC) */
206
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
206
+        $len = ParagonIE_Sodium_Core32_Util::strlen( $message );
207 207
 
208 208
         /** @var int  $clen - Length of ciphertext */
209 209
         $clen = $len - self::aead_chacha20poly1305_IETF_ABYTES;
@@ -230,23 +230,23 @@  discard block
 block discarded – undo
230 230
         );
231 231
 
232 232
         /* Recalculate the Poly1305 authentication tag (MAC): */
233
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
233
+        $state = new ParagonIE_Sodium_Core32_Poly1305_State( $block0 );
234 234
         try {
235
-            ParagonIE_Sodium_Compat::memzero($block0);
236
-        } catch (SodiumException $ex) {
235
+            ParagonIE_Sodium_Compat::memzero( $block0 );
236
+        } catch ( SodiumException $ex ) {
237 237
             $block0 = null;
238 238
         }
239
-        $state->update($ad);
240
-        $state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
241
-        $state->update($ciphertext);
242
-        $state->update(str_repeat("\x00", (0x10 - $clen) & 0xf));
243
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
244
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($clen));
239
+        $state->update( $ad );
240
+        $state->update( str_repeat( "\x00", ( ( 0x10 - $adlen ) & 0xf ) ) );
241
+        $state->update( $ciphertext );
242
+        $state->update( str_repeat( "\x00", ( 0x10 - $clen ) & 0xf ) );
243
+        $state->update( ParagonIE_Sodium_Core32_Util::store64_le( $adlen ) );
244
+        $state->update( ParagonIE_Sodium_Core32_Util::store64_le( $clen ) );
245 245
         $computed_mac = $state->finish();
246 246
 
247 247
         /* Compare the given MAC with the recalculated MAC: */
248
-        if (!ParagonIE_Sodium_Core32_Util::verify_16($computed_mac, $mac)) {
249
-            throw new SodiumException('Invalid MAC');
248
+        if ( ! ParagonIE_Sodium_Core32_Util::verify_16( $computed_mac, $mac ) ) {
249
+            throw new SodiumException( 'Invalid MAC' );
250 250
         }
251 251
 
252 252
         // Here, we know that the MAC is valid, so we decrypt and return the plaintext
@@ -254,7 +254,7 @@  discard block
 block discarded – undo
254 254
             $ciphertext,
255 255
             $nonce,
256 256
             $key,
257
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
257
+            ParagonIE_Sodium_Core32_Util::store64_le( 1 )
258 258
         );
259 259
     }
260 260
 
@@ -278,10 +278,10 @@  discard block
 block discarded – undo
278 278
         $key = ''
279 279
     ) {
280 280
         /** @var int $len - Length of the plaintext message */
281
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
281
+        $len = ParagonIE_Sodium_Core32_Util::strlen( $message );
282 282
 
283 283
         /** @var int $adlen - Length of the associated data */
284
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
284
+        $adlen = ParagonIE_Sodium_Core32_Util::strlen( $ad );
285 285
 
286 286
         /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
287 287
         $block0 = ParagonIE_Sodium_Core32_ChaCha20::ietfStream(
@@ -289,10 +289,10 @@  discard block
 block discarded – undo
289 289
             $nonce,
290 290
             $key
291 291
         );
292
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
292
+        $state = new ParagonIE_Sodium_Core32_Poly1305_State( $block0 );
293 293
         try {
294
-            ParagonIE_Sodium_Compat::memzero($block0);
295
-        } catch (SodiumException $ex) {
294
+            ParagonIE_Sodium_Compat::memzero( $block0 );
295
+        } catch ( SodiumException $ex ) {
296 296
             $block0 = null;
297 297
         }
298 298
 
@@ -301,15 +301,15 @@  discard block
 block discarded – undo
301 301
             $message,
302 302
             $nonce,
303 303
             $key,
304
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
304
+            ParagonIE_Sodium_Core32_Util::store64_le( 1 )
305 305
         );
306 306
 
307
-        $state->update($ad);
308
-        $state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
309
-        $state->update($ciphertext);
310
-        $state->update(str_repeat("\x00", ((0x10 - $len) & 0xf)));
311
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
312
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($len));
307
+        $state->update( $ad );
308
+        $state->update( str_repeat( "\x00", ( ( 0x10 - $adlen ) & 0xf ) ) );
309
+        $state->update( $ciphertext );
310
+        $state->update( str_repeat( "\x00", ( ( 0x10 - $len ) & 0xf ) ) );
311
+        $state->update( ParagonIE_Sodium_Core32_Util::store64_le( $adlen ) );
312
+        $state->update( ParagonIE_Sodium_Core32_Util::store64_le( $len ) );
313 313
         return $ciphertext . $state->finish();
314 314
     }
315 315
 
@@ -333,13 +333,13 @@  discard block
 block discarded – undo
333 333
         $key = ''
334 334
     ) {
335 335
         $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
336
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
336
+            ParagonIE_Sodium_Core32_Util::substr( $nonce, 0, 16 ),
337 337
             $key
338 338
         );
339 339
         $nonceLast = "\x00\x00\x00\x00" .
340
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
340
+            ParagonIE_Sodium_Core32_Util::substr( $nonce, 16, 8 );
341 341
 
342
-        return self::aead_chacha20poly1305_ietf_decrypt($message, $ad, $nonceLast, $subkey);
342
+        return self::aead_chacha20poly1305_ietf_decrypt( $message, $ad, $nonceLast, $subkey );
343 343
     }
344 344
 
345 345
     /**
@@ -362,13 +362,13 @@  discard block
 block discarded – undo
362 362
         $key = ''
363 363
     ) {
364 364
         $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
365
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
365
+            ParagonIE_Sodium_Core32_Util::substr( $nonce, 0, 16 ),
366 366
             $key
367 367
         );
368 368
         $nonceLast = "\x00\x00\x00\x00" .
369
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
369
+            ParagonIE_Sodium_Core32_Util::substr( $nonce, 16, 8 );
370 370
 
371
-        return self::aead_chacha20poly1305_ietf_encrypt($message, $ad, $nonceLast, $subkey);
371
+        return self::aead_chacha20poly1305_ietf_encrypt( $message, $ad, $nonceLast, $subkey );
372 372
     }
373 373
 
374 374
     /**
@@ -381,10 +381,10 @@  discard block
 block discarded – undo
381 381
      * @return string
382 382
      * @throws TypeError
383 383
      */
384
-    public static function auth($message, $key)
384
+    public static function auth( $message, $key )
385 385
     {
386 386
         return ParagonIE_Sodium_Core32_Util::substr(
387
-            hash_hmac('sha512', $message, $key, true),
387
+            hash_hmac( 'sha512', $message, $key, true ),
388 388
             0,
389 389
             32
390 390
         );
@@ -402,11 +402,11 @@  discard block
 block discarded – undo
402 402
      * @throws SodiumException
403 403
      * @throws TypeError
404 404
      */
405
-    public static function auth_verify($mac, $message, $key)
405
+    public static function auth_verify( $mac, $message, $key )
406 406
     {
407 407
         return ParagonIE_Sodium_Core32_Util::hashEquals(
408 408
             $mac,
409
-            self::auth($message, $key)
409
+            self::auth( $message, $key )
410 410
         );
411 411
     }
412 412
 
@@ -422,14 +422,14 @@  discard block
 block discarded – undo
422 422
      * @throws SodiumException
423 423
      * @throws TypeError
424 424
      */
425
-    public static function box($plaintext, $nonce, $keypair)
425
+    public static function box( $plaintext, $nonce, $keypair )
426 426
     {
427 427
         return self::secretbox(
428 428
             $plaintext,
429 429
             $nonce,
430 430
             self::box_beforenm(
431
-                self::box_secretkey($keypair),
432
-                self::box_publickey($keypair)
431
+                self::box_secretkey( $keypair ),
432
+                self::box_publickey( $keypair )
433 433
             )
434 434
         );
435 435
     }
@@ -445,16 +445,16 @@  discard block
 block discarded – undo
445 445
      * @throws SodiumException
446 446
      * @throws TypeError
447 447
      */
448
-    public static function box_seal($message, $publicKey)
448
+    public static function box_seal( $message, $publicKey )
449 449
     {
450 450
         /** @var string $ephemeralKeypair */
451 451
         $ephemeralKeypair = self::box_keypair();
452 452
 
453 453
         /** @var string $ephemeralSK */
454
-        $ephemeralSK = self::box_secretkey($ephemeralKeypair);
454
+        $ephemeralSK = self::box_secretkey( $ephemeralKeypair );
455 455
 
456 456
         /** @var string $ephemeralPK */
457
-        $ephemeralPK = self::box_publickey($ephemeralKeypair);
457
+        $ephemeralPK = self::box_publickey( $ephemeralKeypair );
458 458
 
459 459
         /** @var string $nonce */
460 460
         $nonce = self::generichash(
@@ -464,15 +464,15 @@  discard block
 block discarded – undo
464 464
         );
465 465
 
466 466
         /** @var string $keypair - The combined keypair used in crypto_box() */
467
-        $keypair = self::box_keypair_from_secretkey_and_publickey($ephemeralSK, $publicKey);
467
+        $keypair = self::box_keypair_from_secretkey_and_publickey( $ephemeralSK, $publicKey );
468 468
 
469 469
         /** @var string $ciphertext Ciphertext + MAC from crypto_box */
470
-        $ciphertext = self::box($message, $nonce, $keypair);
470
+        $ciphertext = self::box( $message, $nonce, $keypair );
471 471
         try {
472
-            ParagonIE_Sodium_Compat::memzero($ephemeralKeypair);
473
-            ParagonIE_Sodium_Compat::memzero($ephemeralSK);
474
-            ParagonIE_Sodium_Compat::memzero($nonce);
475
-        } catch (SodiumException $ex) {
472
+            ParagonIE_Sodium_Compat::memzero( $ephemeralKeypair );
473
+            ParagonIE_Sodium_Compat::memzero( $ephemeralSK );
474
+            ParagonIE_Sodium_Compat::memzero( $nonce );
475
+        } catch ( SodiumException $ex ) {
476 476
             $ephemeralKeypair = null;
477 477
             $ephemeralSK = null;
478 478
             $nonce = null;
@@ -491,19 +491,19 @@  discard block
 block discarded – undo
491 491
      * @throws SodiumException
492 492
      * @throws TypeError
493 493
      */
494
-    public static function box_seal_open($message, $keypair)
494
+    public static function box_seal_open( $message, $keypair )
495 495
     {
496 496
         /** @var string $ephemeralPK */
497
-        $ephemeralPK = ParagonIE_Sodium_Core32_Util::substr($message, 0, 32);
497
+        $ephemeralPK = ParagonIE_Sodium_Core32_Util::substr( $message, 0, 32 );
498 498
 
499 499
         /** @var string $ciphertext (ciphertext + MAC) */
500
-        $ciphertext = ParagonIE_Sodium_Core32_Util::substr($message, 32);
500
+        $ciphertext = ParagonIE_Sodium_Core32_Util::substr( $message, 32 );
501 501
 
502 502
         /** @var string $secretKey */
503
-        $secretKey = self::box_secretkey($keypair);
503
+        $secretKey = self::box_secretkey( $keypair );
504 504
 
505 505
         /** @var string $publicKey */
506
-        $publicKey = self::box_publickey($keypair);
506
+        $publicKey = self::box_publickey( $keypair );
507 507
 
508 508
         /** @var string $nonce */
509 509
         $nonce = self::generichash(
@@ -513,15 +513,15 @@  discard block
 block discarded – undo
513 513
         );
514 514
 
515 515
         /** @var string $keypair */
516
-        $keypair = self::box_keypair_from_secretkey_and_publickey($secretKey, $ephemeralPK);
516
+        $keypair = self::box_keypair_from_secretkey_and_publickey( $secretKey, $ephemeralPK );
517 517
 
518 518
         /** @var string $m */
519
-        $m = self::box_open($ciphertext, $nonce, $keypair);
519
+        $m = self::box_open( $ciphertext, $nonce, $keypair );
520 520
         try {
521
-            ParagonIE_Sodium_Compat::memzero($secretKey);
522
-            ParagonIE_Sodium_Compat::memzero($ephemeralPK);
523
-            ParagonIE_Sodium_Compat::memzero($nonce);
524
-        } catch (SodiumException $ex) {
521
+            ParagonIE_Sodium_Compat::memzero( $secretKey );
522
+            ParagonIE_Sodium_Compat::memzero( $ephemeralPK );
523
+            ParagonIE_Sodium_Compat::memzero( $nonce );
524
+        } catch ( SodiumException $ex ) {
525 525
             $secretKey = null;
526 526
             $ephemeralPK = null;
527 527
             $nonce = null;
@@ -540,11 +540,11 @@  discard block
 block discarded – undo
540 540
      * @throws SodiumException
541 541
      * @throws TypeError
542 542
      */
543
-    public static function box_beforenm($sk, $pk)
543
+    public static function box_beforenm( $sk, $pk )
544 544
     {
545 545
         return ParagonIE_Sodium_Core32_HSalsa20::hsalsa20(
546
-            str_repeat("\x00", 16),
547
-            self::scalarmult($sk, $pk)
546
+            str_repeat( "\x00", 16 ),
547
+            self::scalarmult( $sk, $pk )
548 548
         );
549 549
     }
550 550
 
@@ -558,8 +558,8 @@  discard block
 block discarded – undo
558 558
      */
559 559
     public static function box_keypair()
560 560
     {
561
-        $sKey = random_bytes(32);
562
-        $pKey = self::scalarmult_base($sKey);
561
+        $sKey = random_bytes( 32 );
562
+        $pKey = self::scalarmult_base( $sKey );
563 563
         return $sKey . $pKey;
564 564
     }
565 565
 
@@ -569,14 +569,14 @@  discard block
 block discarded – undo
569 569
      * @throws SodiumException
570 570
      * @throws TypeError
571 571
      */
572
-    public static function box_seed_keypair($seed)
572
+    public static function box_seed_keypair( $seed )
573 573
     {
574 574
         $sKey = ParagonIE_Sodium_Core32_Util::substr(
575
-            hash('sha512', $seed, true),
575
+            hash( 'sha512', $seed, true ),
576 576
             0,
577 577
             32
578 578
         );
579
-        $pKey = self::scalarmult_base($sKey);
579
+        $pKey = self::scalarmult_base( $sKey );
580 580
         return $sKey . $pKey;
581 581
     }
582 582
 
@@ -588,10 +588,10 @@  discard block
 block discarded – undo
588 588
      * @return string
589 589
      * @throws TypeError
590 590
      */
591
-    public static function box_keypair_from_secretkey_and_publickey($sKey, $pKey)
591
+    public static function box_keypair_from_secretkey_and_publickey( $sKey, $pKey )
592 592
     {
593
-        return ParagonIE_Sodium_Core32_Util::substr($sKey, 0, 32) .
594
-            ParagonIE_Sodium_Core32_Util::substr($pKey, 0, 32);
593
+        return ParagonIE_Sodium_Core32_Util::substr( $sKey, 0, 32 ) .
594
+            ParagonIE_Sodium_Core32_Util::substr( $pKey, 0, 32 );
595 595
     }
596 596
 
597 597
     /**
@@ -602,14 +602,14 @@  discard block
 block discarded – undo
602 602
      * @throws RangeException
603 603
      * @throws TypeError
604 604
      */
605
-    public static function box_secretkey($keypair)
605
+    public static function box_secretkey( $keypair )
606 606
     {
607
-        if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== 64) {
607
+        if ( ParagonIE_Sodium_Core32_Util::strlen( $keypair ) !== 64 ) {
608 608
             throw new RangeException(
609 609
                 'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
610 610
             );
611 611
         }
612
-        return ParagonIE_Sodium_Core32_Util::substr($keypair, 0, 32);
612
+        return ParagonIE_Sodium_Core32_Util::substr( $keypair, 0, 32 );
613 613
     }
614 614
 
615 615
     /**
@@ -620,14 +620,14 @@  discard block
 block discarded – undo
620 620
      * @throws RangeException
621 621
      * @throws TypeError
622 622
      */
623
-    public static function box_publickey($keypair)
623
+    public static function box_publickey( $keypair )
624 624
     {
625
-        if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
625
+        if ( ParagonIE_Sodium_Core32_Util::strlen( $keypair ) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES ) {
626 626
             throw new RangeException(
627 627
                 'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
628 628
             );
629 629
         }
630
-        return ParagonIE_Sodium_Core32_Util::substr($keypair, 32, 32);
630
+        return ParagonIE_Sodium_Core32_Util::substr( $keypair, 32, 32 );
631 631
     }
632 632
 
633 633
     /**
@@ -639,14 +639,14 @@  discard block
 block discarded – undo
639 639
      * @throws SodiumException
640 640
      * @throws TypeError
641 641
      */
642
-    public static function box_publickey_from_secretkey($sKey)
642
+    public static function box_publickey_from_secretkey( $sKey )
643 643
     {
644
-        if (ParagonIE_Sodium_Core32_Util::strlen($sKey) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES) {
644
+        if ( ParagonIE_Sodium_Core32_Util::strlen( $sKey ) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES ) {
645 645
             throw new RangeException(
646 646
                 'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES bytes long.'
647 647
             );
648 648
         }
649
-        return self::scalarmult_base($sKey);
649
+        return self::scalarmult_base( $sKey );
650 650
     }
651 651
 
652 652
     /**
@@ -661,14 +661,14 @@  discard block
 block discarded – undo
661 661
      * @throws SodiumException
662 662
      * @throws TypeError
663 663
      */
664
-    public static function box_open($ciphertext, $nonce, $keypair)
664
+    public static function box_open( $ciphertext, $nonce, $keypair )
665 665
     {
666 666
         return self::secretbox_open(
667 667
             $ciphertext,
668 668
             $nonce,
669 669
             self::box_beforenm(
670
-                self::box_secretkey($keypair),
671
-                self::box_publickey($keypair)
670
+                self::box_secretkey( $keypair ),
671
+                self::box_publickey( $keypair )
672 672
             )
673 673
         );
674 674
     }
@@ -686,34 +686,34 @@  discard block
 block discarded – undo
686 686
      * @throws SodiumException
687 687
      * @throws TypeError
688 688
      */
689
-    public static function generichash($message, $key = '', $outlen = 32)
689
+    public static function generichash( $message, $key = '', $outlen = 32 )
690 690
     {
691 691
         // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
692 692
         ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
693 693
 
694 694
         $k = null;
695
-        if (!empty($key)) {
695
+        if ( ! empty( $key ) ) {
696 696
             /** @var SplFixedArray $k */
697
-            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
698
-            if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
699
-                throw new RangeException('Invalid key size');
697
+            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray( $key );
698
+            if ( $k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES ) {
699
+                throw new RangeException( 'Invalid key size' );
700 700
             }
701 701
         }
702 702
 
703 703
         /** @var SplFixedArray $in */
704
-        $in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($message);
704
+        $in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray( $message );
705 705
 
706 706
         /** @var SplFixedArray $ctx */
707
-        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outlen);
708
-        ParagonIE_Sodium_Core32_BLAKE2b::update($ctx, $in, $in->count());
707
+        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init( $k, $outlen );
708
+        ParagonIE_Sodium_Core32_BLAKE2b::update( $ctx, $in, $in->count() );
709 709
 
710 710
         /** @var SplFixedArray $out */
711
-        $out = new SplFixedArray($outlen);
712
-        $out = ParagonIE_Sodium_Core32_BLAKE2b::finish($ctx, $out);
711
+        $out = new SplFixedArray( $outlen );
712
+        $out = ParagonIE_Sodium_Core32_BLAKE2b::finish( $ctx, $out );
713 713
 
714 714
         /** @var array<int, int> */
715 715
         $outArray = $out->toArray();
716
-        return ParagonIE_Sodium_Core32_Util::intArrayToString($outArray);
716
+        return ParagonIE_Sodium_Core32_Util::intArrayToString( $outArray );
717 717
     }
718 718
 
719 719
     /**
@@ -727,22 +727,22 @@  discard block
 block discarded – undo
727 727
      * @throws SodiumException
728 728
      * @throws TypeError
729 729
      */
730
-    public static function generichash_final($ctx, $outlen = 32)
730
+    public static function generichash_final( $ctx, $outlen = 32 )
731 731
     {
732
-        if (!is_string($ctx)) {
733
-            throw new TypeError('Context must be a string');
732
+        if ( ! is_string( $ctx ) ) {
733
+            throw new TypeError( 'Context must be a string' );
734 734
         }
735
-        $out = new SplFixedArray($outlen);
735
+        $out = new SplFixedArray( $outlen );
736 736
 
737 737
         /** @var SplFixedArray $context */
738
-        $context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext($ctx);
738
+        $context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext( $ctx );
739 739
 
740 740
         /** @var SplFixedArray $out */
741
-        $out = ParagonIE_Sodium_Core32_BLAKE2b::finish($context, $out);
741
+        $out = ParagonIE_Sodium_Core32_BLAKE2b::finish( $context, $out );
742 742
 
743 743
         /** @var array<int, int> */
744 744
         $outArray = $out->toArray();
745
-        return ParagonIE_Sodium_Core32_Util::intArrayToString($outArray);
745
+        return ParagonIE_Sodium_Core32_Util::intArrayToString( $outArray );
746 746
     }
747 747
 
748 748
     /**
@@ -757,23 +757,23 @@  discard block
 block discarded – undo
757 757
      * @throws SodiumException
758 758
      * @throws TypeError
759 759
      */
760
-    public static function generichash_init($key = '', $outputLength = 32)
760
+    public static function generichash_init( $key = '', $outputLength = 32 )
761 761
     {
762 762
         // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
763 763
         ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
764 764
 
765 765
         $k = null;
766
-        if (!empty($key)) {
767
-            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
768
-            if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
769
-                throw new RangeException('Invalid key size');
766
+        if ( ! empty( $key ) ) {
767
+            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray( $key );
768
+            if ( $k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES ) {
769
+                throw new RangeException( 'Invalid key size' );
770 770
             }
771 771
         }
772 772
 
773 773
         /** @var SplFixedArray $ctx */
774
-        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outputLength);
774
+        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init( $k, $outputLength );
775 775
 
776
-        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($ctx);
776
+        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString( $ctx );
777 777
     }
778 778
 
779 779
     /**
@@ -800,27 +800,27 @@  discard block
 block discarded – undo
800 800
         ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
801 801
 
802 802
         $k = null;
803
-        if (!empty($key)) {
804
-            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
805
-            if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
806
-                throw new RangeException('Invalid key size');
803
+        if ( ! empty( $key ) ) {
804
+            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray( $key );
805
+            if ( $k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES ) {
806
+                throw new RangeException( 'Invalid key size' );
807 807
             }
808 808
         }
809
-        if (!empty($salt)) {
810
-            $s = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($salt);
809
+        if ( ! empty( $salt ) ) {
810
+            $s = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray( $salt );
811 811
         } else {
812 812
             $s = null;
813 813
         }
814
-        if (!empty($salt)) {
815
-            $p = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($personal);
814
+        if ( ! empty( $salt ) ) {
815
+            $p = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray( $personal );
816 816
         } else {
817 817
             $p = null;
818 818
         }
819 819
 
820 820
         /** @var SplFixedArray $ctx */
821
-        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outputLength, $s, $p);
821
+        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init( $k, $outputLength, $s, $p );
822 822
 
823
-        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($ctx);
823
+        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString( $ctx );
824 824
     }
825 825
 
826 826
     /**
@@ -834,20 +834,20 @@  discard block
 block discarded – undo
834 834
      * @throws SodiumException
835 835
      * @throws TypeError
836 836
      */
837
-    public static function generichash_update($ctx, $message)
837
+    public static function generichash_update( $ctx, $message )
838 838
     {
839 839
         // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
840 840
         ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
841 841
 
842 842
         /** @var SplFixedArray $context */
843
-        $context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext($ctx);
843
+        $context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext( $ctx );
844 844
 
845 845
         /** @var SplFixedArray $in */
846
-        $in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($message);
846
+        $in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray( $message );
847 847
 
848
-        ParagonIE_Sodium_Core32_BLAKE2b::update($context, $in, $in->count());
848
+        ParagonIE_Sodium_Core32_BLAKE2b::update( $context, $in, $in->count() );
849 849
 
850
-        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($context);
850
+        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString( $context );
851 851
     }
852 852
 
853 853
     /**
@@ -863,10 +863,10 @@  discard block
 block discarded – undo
863 863
      * @throws SodiumException
864 864
      * @throws TypeError
865 865
      */
866
-    public static function keyExchange($my_sk, $their_pk, $client_pk, $server_pk)
866
+    public static function keyExchange( $my_sk, $their_pk, $client_pk, $server_pk )
867 867
     {
868 868
         return self::generichash(
869
-            self::scalarmult($my_sk, $their_pk) .
869
+            self::scalarmult( $my_sk, $their_pk ) .
870 870
             $client_pk .
871 871
             $server_pk
872 872
         );
@@ -884,10 +884,10 @@  discard block
 block discarded – undo
884 884
      * @throws SodiumException
885 885
      * @throws TypeError
886 886
      */
887
-    public static function scalarmult($sKey, $pKey)
887
+    public static function scalarmult( $sKey, $pKey )
888 888
     {
889
-        $q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10($sKey, $pKey);
890
-        self::scalarmult_throw_if_zero($q);
889
+        $q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10( $sKey, $pKey );
890
+        self::scalarmult_throw_if_zero( $q );
891 891
         return $q;
892 892
     }
893 893
 
@@ -901,10 +901,10 @@  discard block
 block discarded – undo
901 901
      * @throws SodiumException
902 902
      * @throws TypeError
903 903
      */
904
-    public static function scalarmult_base($secret)
904
+    public static function scalarmult_base( $secret )
905 905
     {
906
-        $q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10_base($secret);
907
-        self::scalarmult_throw_if_zero($q);
906
+        $q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10_base( $secret );
907
+        self::scalarmult_throw_if_zero( $q );
908 908
         return $q;
909 909
     }
910 910
 
@@ -916,16 +916,16 @@  discard block
 block discarded – undo
916 916
      * @throws SodiumException
917 917
      * @throws TypeError
918 918
      */
919
-    protected static function scalarmult_throw_if_zero($q)
919
+    protected static function scalarmult_throw_if_zero( $q )
920 920
     {
921 921
         $d = 0;
922
-        for ($i = 0; $i < self::box_curve25519xsalsa20poly1305_SECRETKEYBYTES; ++$i) {
923
-            $d |= ParagonIE_Sodium_Core32_Util::chrToInt($q[$i]);
922
+        for ( $i = 0; $i < self::box_curve25519xsalsa20poly1305_SECRETKEYBYTES; ++$i ) {
923
+            $d |= ParagonIE_Sodium_Core32_Util::chrToInt( $q[ $i ] );
924 924
         }
925 925
 
926 926
         /* branch-free variant of === 0 */
927
-        if (-(1 & (($d - 1) >> 8))) {
928
-            throw new SodiumException('Zero public key is not allowed');
927
+        if (-( 1 & ( ( $d - 1 ) >> 8 ) )) {
928
+            throw new SodiumException( 'Zero public key is not allowed' );
929 929
         }
930 930
     }
931 931
 
@@ -941,26 +941,26 @@  discard block
 block discarded – undo
941 941
      * @throws SodiumException
942 942
      * @throws TypeError
943 943
      */
944
-    public static function secretbox($plaintext, $nonce, $key)
944
+    public static function secretbox( $plaintext, $nonce, $key )
945 945
     {
946 946
         /** @var string $subkey */
947
-        $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
947
+        $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20( $nonce, $key );
948 948
 
949 949
         /** @var string $block0 */
950
-        $block0 = str_repeat("\x00", 32);
950
+        $block0 = str_repeat( "\x00", 32 );
951 951
 
952 952
         /** @var int $mlen - Length of the plaintext message */
953
-        $mlen = ParagonIE_Sodium_Core32_Util::strlen($plaintext);
953
+        $mlen = ParagonIE_Sodium_Core32_Util::strlen( $plaintext );
954 954
         $mlen0 = $mlen;
955
-        if ($mlen0 > 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES) {
955
+        if ( $mlen0 > 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES ) {
956 956
             $mlen0 = 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES;
957 957
         }
958
-        $block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
958
+        $block0 .= ParagonIE_Sodium_Core32_Util::substr( $plaintext, 0, $mlen0 );
959 959
 
960 960
         /** @var string $block0 */
961 961
         $block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor(
962 962
             $block0,
963
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
963
+            ParagonIE_Sodium_Core32_Util::substr( $nonce, 16, 8 ),
964 964
             $subkey
965 965
         );
966 966
 
@@ -969,13 +969,13 @@  discard block
 block discarded – undo
969 969
             $block0,
970 970
             self::secretbox_xsalsa20poly1305_ZEROBYTES
971 971
         );
972
-        if ($mlen > $mlen0) {
972
+        if ( $mlen > $mlen0 ) {
973 973
             $c .= ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
974 974
                 ParagonIE_Sodium_Core32_Util::substr(
975 975
                     $plaintext,
976 976
                     self::secretbox_xsalsa20poly1305_ZEROBYTES
977 977
                 ),
978
-                ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
978
+                ParagonIE_Sodium_Core32_Util::substr( $nonce, 16, 8 ),
979 979
                 1,
980 980
                 $subkey
981 981
             );
@@ -988,18 +988,18 @@  discard block
 block discarded – undo
988 988
             )
989 989
         );
990 990
         try {
991
-            ParagonIE_Sodium_Compat::memzero($block0);
992
-            ParagonIE_Sodium_Compat::memzero($subkey);
993
-        } catch (SodiumException $ex) {
991
+            ParagonIE_Sodium_Compat::memzero( $block0 );
992
+            ParagonIE_Sodium_Compat::memzero( $subkey );
993
+        } catch ( SodiumException $ex ) {
994 994
             $block0 = null;
995 995
             $subkey = null;
996 996
         }
997 997
 
998
-        $state->update($c);
998
+        $state->update( $c );
999 999
 
1000 1000
         /** @var string $c - MAC || ciphertext */
1001 1001
         $c = $state->finish() . $c;
1002
-        unset($state);
1002
+        unset( $state );
1003 1003
 
1004 1004
         return $c;
1005 1005
     }
@@ -1016,7 +1016,7 @@  discard block
 block discarded – undo
1016 1016
      * @throws SodiumException
1017 1017
      * @throws TypeError
1018 1018
      */
1019
-    public static function secretbox_open($ciphertext, $nonce, $key)
1019
+    public static function secretbox_open( $ciphertext, $nonce, $key )
1020 1020
     {
1021 1021
         /** @var string $mac */
1022 1022
         $mac = ParagonIE_Sodium_Core32_Util::substr(
@@ -1032,46 +1032,46 @@  discard block
 block discarded – undo
1032 1032
         );
1033 1033
 
1034 1034
         /** @var int $clen */
1035
-        $clen = ParagonIE_Sodium_Core32_Util::strlen($c);
1035
+        $clen = ParagonIE_Sodium_Core32_Util::strlen( $c );
1036 1036
 
1037 1037
         /** @var string $subkey */
1038
-        $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
1038
+        $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20( $nonce, $key );
1039 1039
 
1040 1040
         /** @var string $block0 */
1041 1041
         $block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20(
1042 1042
             64,
1043
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1043
+            ParagonIE_Sodium_Core32_Util::substr( $nonce, 16, 8 ),
1044 1044
             $subkey
1045 1045
         );
1046 1046
         $verified = ParagonIE_Sodium_Core32_Poly1305::onetimeauth_verify(
1047 1047
             $mac,
1048 1048
             $c,
1049
-            ParagonIE_Sodium_Core32_Util::substr($block0, 0, 32)
1049
+            ParagonIE_Sodium_Core32_Util::substr( $block0, 0, 32 )
1050 1050
         );
1051
-        if (!$verified) {
1051
+        if ( ! $verified ) {
1052 1052
             try {
1053
-                ParagonIE_Sodium_Compat::memzero($subkey);
1054
-            } catch (SodiumException $ex) {
1053
+                ParagonIE_Sodium_Compat::memzero( $subkey );
1054
+            } catch ( SodiumException $ex ) {
1055 1055
                 $subkey = null;
1056 1056
             }
1057
-            throw new SodiumException('Invalid MAC');
1057
+            throw new SodiumException( 'Invalid MAC' );
1058 1058
         }
1059 1059
 
1060 1060
         /** @var string $m - Decrypted message */
1061 1061
         $m = ParagonIE_Sodium_Core32_Util::xorStrings(
1062
-            ParagonIE_Sodium_Core32_Util::substr($block0, self::secretbox_xsalsa20poly1305_ZEROBYTES),
1063
-            ParagonIE_Sodium_Core32_Util::substr($c, 0, self::secretbox_xsalsa20poly1305_ZEROBYTES)
1062
+            ParagonIE_Sodium_Core32_Util::substr( $block0, self::secretbox_xsalsa20poly1305_ZEROBYTES ),
1063
+            ParagonIE_Sodium_Core32_Util::substr( $c, 0, self::secretbox_xsalsa20poly1305_ZEROBYTES )
1064 1064
         );
1065
-        if ($clen > self::secretbox_xsalsa20poly1305_ZEROBYTES) {
1065
+        if ( $clen > self::secretbox_xsalsa20poly1305_ZEROBYTES ) {
1066 1066
             // We had more than 1 block, so let's continue to decrypt the rest.
1067 1067
             $m .= ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
1068 1068
                 ParagonIE_Sodium_Core32_Util::substr(
1069 1069
                     $c,
1070 1070
                     self::secretbox_xsalsa20poly1305_ZEROBYTES
1071 1071
                 ),
1072
-                ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1072
+                ParagonIE_Sodium_Core32_Util::substr( $nonce, 16, 8 ),
1073 1073
                 1,
1074
-                (string) $subkey
1074
+                (string)$subkey
1075 1075
             );
1076 1076
         }
1077 1077
         return $m;
@@ -1089,25 +1089,25 @@  discard block
 block discarded – undo
1089 1089
      * @throws SodiumException
1090 1090
      * @throws TypeError
1091 1091
      */
1092
-    public static function secretbox_xchacha20poly1305($plaintext, $nonce, $key)
1092
+    public static function secretbox_xchacha20poly1305( $plaintext, $nonce, $key )
1093 1093
     {
1094 1094
         /** @var string $subkey */
1095 1095
         $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1096
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
1096
+            ParagonIE_Sodium_Core32_Util::substr( $nonce, 0, 16 ),
1097 1097
             $key
1098 1098
         );
1099
-        $nonceLast = ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
1099
+        $nonceLast = ParagonIE_Sodium_Core32_Util::substr( $nonce, 16, 8 );
1100 1100
 
1101 1101
         /** @var string $block0 */
1102
-        $block0 = str_repeat("\x00", 32);
1102
+        $block0 = str_repeat( "\x00", 32 );
1103 1103
 
1104 1104
         /** @var int $mlen - Length of the plaintext message */
1105
-        $mlen = ParagonIE_Sodium_Core32_Util::strlen($plaintext);
1105
+        $mlen = ParagonIE_Sodium_Core32_Util::strlen( $plaintext );
1106 1106
         $mlen0 = $mlen;
1107
-        if ($mlen0 > 64 - self::secretbox_xchacha20poly1305_ZEROBYTES) {
1107
+        if ( $mlen0 > 64 - self::secretbox_xchacha20poly1305_ZEROBYTES ) {
1108 1108
             $mlen0 = 64 - self::secretbox_xchacha20poly1305_ZEROBYTES;
1109 1109
         }
1110
-        $block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
1110
+        $block0 .= ParagonIE_Sodium_Core32_Util::substr( $plaintext, 0, $mlen0 );
1111 1111
 
1112 1112
         /** @var string $block0 */
1113 1113
         $block0 = ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
@@ -1121,7 +1121,7 @@  discard block
 block discarded – undo
1121 1121
             $block0,
1122 1122
             self::secretbox_xchacha20poly1305_ZEROBYTES
1123 1123
         );
1124
-        if ($mlen > $mlen0) {
1124
+        if ( $mlen > $mlen0 ) {
1125 1125
             $c .= ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1126 1126
                 ParagonIE_Sodium_Core32_Util::substr(
1127 1127
                     $plaintext,
@@ -1129,7 +1129,7 @@  discard block
 block discarded – undo
1129 1129
                 ),
1130 1130
                 $nonceLast,
1131 1131
                 $subkey,
1132
-                ParagonIE_Sodium_Core32_Util::store64_le(1)
1132
+                ParagonIE_Sodium_Core32_Util::store64_le( 1 )
1133 1133
             );
1134 1134
         }
1135 1135
         $state = new ParagonIE_Sodium_Core32_Poly1305_State(
@@ -1140,18 +1140,18 @@  discard block
 block discarded – undo
1140 1140
             )
1141 1141
         );
1142 1142
         try {
1143
-            ParagonIE_Sodium_Compat::memzero($block0);
1144
-            ParagonIE_Sodium_Compat::memzero($subkey);
1145
-        } catch (SodiumException $ex) {
1143
+            ParagonIE_Sodium_Compat::memzero( $block0 );
1144
+            ParagonIE_Sodium_Compat::memzero( $subkey );
1145
+        } catch ( SodiumException $ex ) {
1146 1146
             $block0 = null;
1147 1147
             $subkey = null;
1148 1148
         }
1149 1149
 
1150
-        $state->update($c);
1150
+        $state->update( $c );
1151 1151
 
1152 1152
         /** @var string $c - MAC || ciphertext */
1153 1153
         $c = $state->finish() . $c;
1154
-        unset($state);
1154
+        unset( $state );
1155 1155
 
1156 1156
         return $c;
1157 1157
     }
@@ -1168,7 +1168,7 @@  discard block
 block discarded – undo
1168 1168
      * @throws SodiumException
1169 1169
      * @throws TypeError
1170 1170
      */
1171
-    public static function secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key)
1171
+    public static function secretbox_xchacha20poly1305_open( $ciphertext, $nonce, $key )
1172 1172
     {
1173 1173
         /** @var string $mac */
1174 1174
         $mac = ParagonIE_Sodium_Core32_Util::substr(
@@ -1184,48 +1184,48 @@  discard block
 block discarded – undo
1184 1184
         );
1185 1185
 
1186 1186
         /** @var int $clen */
1187
-        $clen = ParagonIE_Sodium_Core32_Util::strlen($c);
1187
+        $clen = ParagonIE_Sodium_Core32_Util::strlen( $c );
1188 1188
 
1189 1189
         /** @var string $subkey */
1190
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hchacha20($nonce, $key);
1190
+        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hchacha20( $nonce, $key );
1191 1191
 
1192 1192
         /** @var string $block0 */
1193 1193
         $block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
1194 1194
             64,
1195
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1195
+            ParagonIE_Sodium_Core32_Util::substr( $nonce, 16, 8 ),
1196 1196
             $subkey
1197 1197
         );
1198 1198
         $verified = ParagonIE_Sodium_Core32_Poly1305::onetimeauth_verify(
1199 1199
             $mac,
1200 1200
             $c,
1201
-            ParagonIE_Sodium_Core32_Util::substr($block0, 0, 32)
1201
+            ParagonIE_Sodium_Core32_Util::substr( $block0, 0, 32 )
1202 1202
         );
1203 1203
 
1204
-        if (!$verified) {
1204
+        if ( ! $verified ) {
1205 1205
             try {
1206
-                ParagonIE_Sodium_Compat::memzero($subkey);
1207
-            } catch (SodiumException $ex) {
1206
+                ParagonIE_Sodium_Compat::memzero( $subkey );
1207
+            } catch ( SodiumException $ex ) {
1208 1208
                 $subkey = null;
1209 1209
             }
1210
-            throw new SodiumException('Invalid MAC');
1210
+            throw new SodiumException( 'Invalid MAC' );
1211 1211
         }
1212 1212
 
1213 1213
         /** @var string $m - Decrypted message */
1214 1214
         $m = ParagonIE_Sodium_Core32_Util::xorStrings(
1215
-            ParagonIE_Sodium_Core32_Util::substr($block0, self::secretbox_xchacha20poly1305_ZEROBYTES),
1216
-            ParagonIE_Sodium_Core32_Util::substr($c, 0, self::secretbox_xchacha20poly1305_ZEROBYTES)
1215
+            ParagonIE_Sodium_Core32_Util::substr( $block0, self::secretbox_xchacha20poly1305_ZEROBYTES ),
1216
+            ParagonIE_Sodium_Core32_Util::substr( $c, 0, self::secretbox_xchacha20poly1305_ZEROBYTES )
1217 1217
         );
1218 1218
 
1219
-        if ($clen > self::secretbox_xchacha20poly1305_ZEROBYTES) {
1219
+        if ( $clen > self::secretbox_xchacha20poly1305_ZEROBYTES ) {
1220 1220
             // We had more than 1 block, so let's continue to decrypt the rest.
1221 1221
             $m .= ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1222 1222
                 ParagonIE_Sodium_Core32_Util::substr(
1223 1223
                     $c,
1224 1224
                     self::secretbox_xchacha20poly1305_ZEROBYTES
1225 1225
                 ),
1226
-                ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1227
-                (string) $subkey,
1228
-                ParagonIE_Sodium_Core32_Util::store64_le(1)
1226
+                ParagonIE_Sodium_Core32_Util::substr( $nonce, 16, 8 ),
1227
+                (string)$subkey,
1228
+                ParagonIE_Sodium_Core32_Util::store64_le( 1 )
1229 1229
             );
1230 1230
         }
1231 1231
         return $m;
@@ -1237,16 +1237,16 @@  discard block
 block discarded – undo
1237 1237
      * @throws Exception
1238 1238
      * @throws SodiumException
1239 1239
      */
1240
-    public static function secretstream_xchacha20poly1305_init_push($key)
1240
+    public static function secretstream_xchacha20poly1305_init_push( $key )
1241 1241
     {
1242 1242
         # randombytes_buf(out, crypto_secretstream_xchacha20poly1305_HEADERBYTES);
1243
-        $out = random_bytes(24);
1243
+        $out = random_bytes( 24 );
1244 1244
 
1245 1245
         # crypto_core_hchacha20(state->k, out, k, NULL);
1246
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20($out, $key);
1246
+        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20( $out, $key );
1247 1247
         $state = new ParagonIE_Sodium_Core32_SecretStream_State(
1248 1248
             $subkey,
1249
-            ParagonIE_Sodium_Core32_Util::substr($out, 16, 8) . str_repeat("\0", 4)
1249
+            ParagonIE_Sodium_Core32_Util::substr( $out, 16, 8 ) . str_repeat( "\0", 4 )
1250 1250
         );
1251 1251
 
1252 1252
         # _crypto_secretstream_xchacha20poly1305_counter_reset(state);
@@ -1267,16 +1267,16 @@  discard block
 block discarded – undo
1267 1267
      * @return string Returns a state.
1268 1268
      * @throws Exception
1269 1269
      */
1270
-    public static function secretstream_xchacha20poly1305_init_pull($key, $header)
1270
+    public static function secretstream_xchacha20poly1305_init_pull( $key, $header )
1271 1271
     {
1272 1272
         # crypto_core_hchacha20(state->k, in, k, NULL);
1273 1273
         $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1274
-            ParagonIE_Sodium_Core32_Util::substr($header, 0, 16),
1274
+            ParagonIE_Sodium_Core32_Util::substr( $header, 0, 16 ),
1275 1275
             $key
1276 1276
         );
1277 1277
         $state = new ParagonIE_Sodium_Core32_SecretStream_State(
1278 1278
             $subkey,
1279
-            ParagonIE_Sodium_Core32_Util::substr($header, 16)
1279
+            ParagonIE_Sodium_Core32_Util::substr( $header, 16 )
1280 1280
         );
1281 1281
         $state->counterReset();
1282 1282
         # memcpy(STATE_INONCE(state), in + crypto_core_hchacha20_INPUTBYTES,
@@ -1294,19 +1294,19 @@  discard block
 block discarded – undo
1294 1294
      * @return string
1295 1295
      * @throws SodiumException
1296 1296
      */
1297
-    public static function secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0)
1297
+    public static function secretstream_xchacha20poly1305_push( &$state, $msg, $aad = '', $tag = 0 )
1298 1298
     {
1299
-        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1299
+        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString( $state );
1300 1300
         # crypto_onetimeauth_poly1305_state poly1305_state;
1301 1301
         # unsigned char                     block[64U];
1302 1302
         # unsigned char                     slen[8U];
1303 1303
         # unsigned char                    *c;
1304 1304
         # unsigned char                    *mac;
1305 1305
 
1306
-        $msglen = ParagonIE_Sodium_Core32_Util::strlen($msg);
1307
-        $aadlen = ParagonIE_Sodium_Core32_Util::strlen($aad);
1306
+        $msglen = ParagonIE_Sodium_Core32_Util::strlen( $msg );
1307
+        $aadlen = ParagonIE_Sodium_Core32_Util::strlen( $aad );
1308 1308
 
1309
-        if ((($msglen + 63) >> 6) > 0xfffffffe) {
1309
+        if ( ( ( $msglen + 63 ) >> 6 ) > 0xfffffffe ) {
1310 1310
             throw new SodiumException(
1311 1311
                 'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1312 1312
             );
@@ -1323,62 +1323,62 @@  discard block
 block discarded – undo
1323 1323
         # crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1324 1324
         # sodium_memzero(block, sizeof block);
1325 1325
         $auth = new ParagonIE_Sodium_Core32_Poly1305_State(
1326
-            ParagonIE_Sodium_Core32_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1326
+            ParagonIE_Sodium_Core32_ChaCha20::ietfStream( 32, $st->getCombinedNonce(), $st->getKey() )
1327 1327
         );
1328 1328
 
1329 1329
         # crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1330
-        $auth->update($aad);
1330
+        $auth->update( $aad );
1331 1331
 
1332 1332
         # crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1333 1333
         #     (0x10 - adlen) & 0xf);
1334
-        $auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1334
+        $auth->update( str_repeat( "\0", ( ( 0x10 - $aadlen ) & 0xf ) ) );
1335 1335
 
1336 1336
         # memset(block, 0, sizeof block);
1337 1337
         # block[0] = tag;
1338 1338
         # crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1339 1339
         #                                    state->nonce, 1U, state->k);
1340 1340
         $block = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1341
-            ParagonIE_Sodium_Core32_Util::intToChr($tag) . str_repeat("\0", 63),
1341
+            ParagonIE_Sodium_Core32_Util::intToChr( $tag ) . str_repeat( "\0", 63 ),
1342 1342
             $st->getCombinedNonce(),
1343 1343
             $st->getKey(),
1344
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
1344
+            ParagonIE_Sodium_Core32_Util::store64_le( 1 )
1345 1345
         );
1346 1346
 
1347 1347
         # crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1348
-        $auth->update($block);
1348
+        $auth->update( $block );
1349 1349
 
1350 1350
         # out[0] = block[0];
1351
-        $out = $block[0];
1351
+        $out = $block[ 0 ];
1352 1352
         # c = out + (sizeof tag);
1353 1353
         # crypto_stream_chacha20_ietf_xor_ic(c, m, mlen, state->nonce, 2U, state->k);
1354 1354
         $cipher = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1355 1355
             $msg,
1356 1356
             $st->getCombinedNonce(),
1357 1357
             $st->getKey(),
1358
-            ParagonIE_Sodium_Core32_Util::store64_le(2)
1358
+            ParagonIE_Sodium_Core32_Util::store64_le( 2 )
1359 1359
         );
1360 1360
 
1361 1361
         # crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1362
-        $auth->update($cipher);
1362
+        $auth->update( $cipher );
1363 1363
 
1364 1364
         $out .= $cipher;
1365
-        unset($cipher);
1365
+        unset( $cipher );
1366 1366
 
1367 1367
         # crypto_onetimeauth_poly1305_update
1368 1368
         # (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1369
-        $auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1369
+        $auth->update( str_repeat( "\0", ( ( 0x10 - 64 + $msglen ) & 0xf ) ) );
1370 1370
 
1371 1371
         # STORE64_LE(slen, (uint64_t) adlen);
1372
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le($aadlen);
1372
+        $slen = ParagonIE_Sodium_Core32_Util::store64_le( $aadlen );
1373 1373
 
1374 1374
         # crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1375
-        $auth->update($slen);
1375
+        $auth->update( $slen );
1376 1376
 
1377 1377
         # STORE64_LE(slen, (sizeof block) + mlen);
1378
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le(64 + $msglen);
1378
+        $slen = ParagonIE_Sodium_Core32_Util::store64_le( 64 + $msglen );
1379 1379
 
1380 1380
         # crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1381
-        $auth->update($slen);
1381
+        $auth->update( $slen );
1382 1382
 
1383 1383
         # mac = c + mlen;
1384 1384
         # crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
@@ -1386,12 +1386,12 @@  discard block
 block discarded – undo
1386 1386
         $out .= $mac;
1387 1387
 
1388 1388
         # sodium_memzero(&poly1305_state, sizeof poly1305_state);
1389
-        unset($auth);
1389
+        unset( $auth );
1390 1390
 
1391 1391
 
1392 1392
         # XOR_BUF(STATE_INONCE(state), mac,
1393 1393
         #     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1394
-        $st->xorNonce($mac);
1394
+        $st->xorNonce( $mac );
1395 1395
 
1396 1396
         # sodium_increment(STATE_COUNTER(state),
1397 1397
         #     crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
@@ -1400,15 +1400,15 @@  discard block
 block discarded – undo
1400 1400
         $state = $st->toString();
1401 1401
 
1402 1402
         /** @var bool $rekey */
1403
-        $rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1403
+        $rekey = ( $tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY ) !== 0;
1404 1404
         # if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1405 1405
         #     sodium_is_zero(STATE_COUNTER(state),
1406 1406
         #         crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1407 1407
         #     crypto_secretstream_xchacha20poly1305_rekey(state);
1408 1408
         # }
1409
-        if ($rekey || $st->needsRekey()) {
1409
+        if ( $rekey || $st->needsRekey() ) {
1410 1410
             // DO REKEY
1411
-            self::secretstream_xchacha20poly1305_rekey($state);
1411
+            self::secretstream_xchacha20poly1305_rekey( $state );
1412 1412
         }
1413 1413
         # if (outlen_p != NULL) {
1414 1414
         #     *outlen_p = crypto_secretstream_xchacha20poly1305_ABYTES + mlen;
@@ -1423,19 +1423,19 @@  discard block
 block discarded – undo
1423 1423
      * @return bool|array{0: string, 1: int}
1424 1424
      * @throws SodiumException
1425 1425
      */
1426
-    public static function secretstream_xchacha20poly1305_pull(&$state, $cipher, $aad = '')
1426
+    public static function secretstream_xchacha20poly1305_pull( &$state, $cipher, $aad = '' )
1427 1427
     {
1428
-        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1428
+        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString( $state );
1429 1429
 
1430
-        $cipherlen = ParagonIE_Sodium_Core32_Util::strlen($cipher);
1430
+        $cipherlen = ParagonIE_Sodium_Core32_Util::strlen( $cipher );
1431 1431
         #     mlen = inlen - crypto_secretstream_xchacha20poly1305_ABYTES;
1432 1432
         $msglen = $cipherlen - ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_ABYTES;
1433
-        $aadlen = ParagonIE_Sodium_Core32_Util::strlen($aad);
1433
+        $aadlen = ParagonIE_Sodium_Core32_Util::strlen( $aad );
1434 1434
 
1435 1435
         #     if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1436 1436
         #         sodium_misuse();
1437 1437
         #     }
1438
-        if ((($msglen + 63) >> 6) > 0xfffffffe) {
1438
+        if ( ( ( $msglen + 63 ) >> 6 ) > 0xfffffffe ) {
1439 1439
             throw new SodiumException(
1440 1440
                 'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1441 1441
             );
@@ -1445,15 +1445,15 @@  discard block
 block discarded – undo
1445 1445
         #     crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1446 1446
         #     sodium_memzero(block, sizeof block);
1447 1447
         $auth = new ParagonIE_Sodium_Core32_Poly1305_State(
1448
-            ParagonIE_Sodium_Core32_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1448
+            ParagonIE_Sodium_Core32_ChaCha20::ietfStream( 32, $st->getCombinedNonce(), $st->getKey() )
1449 1449
         );
1450 1450
 
1451 1451
         #     crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1452
-        $auth->update($aad);
1452
+        $auth->update( $aad );
1453 1453
 
1454 1454
         #     crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1455 1455
         #         (0x10 - adlen) & 0xf);
1456
-        $auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1456
+        $auth->update( str_repeat( "\0", ( ( 0x10 - $aadlen ) & 0xf ) ) );
1457 1457
 
1458 1458
 
1459 1459
         #     memset(block, 0, sizeof block);
@@ -1461,36 +1461,36 @@  discard block
 block discarded – undo
1461 1461
         #     crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1462 1462
         #                                        state->nonce, 1U, state->k);
1463 1463
         $block = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1464
-            $cipher[0] . str_repeat("\0", 63),
1464
+            $cipher[ 0 ] . str_repeat( "\0", 63 ),
1465 1465
             $st->getCombinedNonce(),
1466 1466
             $st->getKey(),
1467
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
1467
+            ParagonIE_Sodium_Core32_Util::store64_le( 1 )
1468 1468
         );
1469 1469
         #     tag = block[0];
1470 1470
         #     block[0] = in[0];
1471 1471
         #     crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1472
-        $tag = ParagonIE_Sodium_Core32_Util::chrToInt($block[0]);
1473
-        $block[0] = $cipher[0];
1474
-        $auth->update($block);
1472
+        $tag = ParagonIE_Sodium_Core32_Util::chrToInt( $block[ 0 ] );
1473
+        $block[ 0 ] = $cipher[ 0 ];
1474
+        $auth->update( $block );
1475 1475
 
1476 1476
 
1477 1477
         #     c = in + (sizeof tag);
1478 1478
         #     crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1479
-        $auth->update(ParagonIE_Sodium_Core32_Util::substr($cipher, 1, $msglen));
1479
+        $auth->update( ParagonIE_Sodium_Core32_Util::substr( $cipher, 1, $msglen ) );
1480 1480
 
1481 1481
         #     crypto_onetimeauth_poly1305_update
1482 1482
         #     (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1483
-        $auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1483
+        $auth->update( str_repeat( "\0", ( ( 0x10 - 64 + $msglen ) & 0xf ) ) );
1484 1484
 
1485 1485
         #     STORE64_LE(slen, (uint64_t) adlen);
1486 1486
         #     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1487
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le($aadlen);
1488
-        $auth->update($slen);
1487
+        $slen = ParagonIE_Sodium_Core32_Util::store64_le( $aadlen );
1488
+        $auth->update( $slen );
1489 1489
 
1490 1490
         #     STORE64_LE(slen, (sizeof block) + mlen);
1491 1491
         #     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1492
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le(64 + $msglen);
1493
-        $auth->update($slen);
1492
+        $slen = ParagonIE_Sodium_Core32_Util::store64_le( 64 + $msglen );
1493
+        $auth->update( $slen );
1494 1494
 
1495 1495
         #     crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1496 1496
         #     sodium_memzero(&poly1305_state, sizeof poly1305_state);
@@ -1502,22 +1502,22 @@  discard block
 block discarded – undo
1502 1502
         #         return -1;
1503 1503
         #     }
1504 1504
 
1505
-        $stored = ParagonIE_Sodium_Core32_Util::substr($cipher, $msglen + 1, 16);
1506
-        if (!ParagonIE_Sodium_Core32_Util::hashEquals($mac, $stored)) {
1505
+        $stored = ParagonIE_Sodium_Core32_Util::substr( $cipher, $msglen + 1, 16 );
1506
+        if ( ! ParagonIE_Sodium_Core32_Util::hashEquals( $mac, $stored ) ) {
1507 1507
             return false;
1508 1508
         }
1509 1509
 
1510 1510
         #     crypto_stream_chacha20_ietf_xor_ic(m, c, mlen, state->nonce, 2U, state->k);
1511 1511
         $out = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1512
-            ParagonIE_Sodium_Core32_Util::substr($cipher, 1, $msglen),
1512
+            ParagonIE_Sodium_Core32_Util::substr( $cipher, 1, $msglen ),
1513 1513
             $st->getCombinedNonce(),
1514 1514
             $st->getKey(),
1515
-            ParagonIE_Sodium_Core32_Util::store64_le(2)
1515
+            ParagonIE_Sodium_Core32_Util::store64_le( 2 )
1516 1516
         );
1517 1517
 
1518 1518
         #     XOR_BUF(STATE_INONCE(state), mac,
1519 1519
         #         crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1520
-        $st->xorNonce($mac);
1520
+        $st->xorNonce( $mac );
1521 1521
 
1522 1522
         #     sodium_increment(STATE_COUNTER(state),
1523 1523
         #         crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
@@ -1533,12 +1533,12 @@  discard block
 block discarded – undo
1533 1533
         $state = $st->toString();
1534 1534
 
1535 1535
         /** @var bool $rekey */
1536
-        $rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1537
-        if ($rekey || $st->needsRekey()) {
1536
+        $rekey = ( $tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY ) !== 0;
1537
+        if ( $rekey || $st->needsRekey() ) {
1538 1538
             // DO REKEY
1539
-            self::secretstream_xchacha20poly1305_rekey($state);
1539
+            self::secretstream_xchacha20poly1305_rekey( $state );
1540 1540
         }
1541
-        return array($out, $tag);
1541
+        return array( $out, $tag );
1542 1542
     }
1543 1543
 
1544 1544
     /**
@@ -1546,9 +1546,9 @@  discard block
 block discarded – undo
1546 1546
      * @return void
1547 1547
      * @throws SodiumException
1548 1548
      */
1549
-    public static function secretstream_xchacha20poly1305_rekey(&$state)
1549
+    public static function secretstream_xchacha20poly1305_rekey( &$state )
1550 1550
     {
1551
-        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1551
+        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString( $state );
1552 1552
         # unsigned char new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES +
1553 1553
         # crypto_secretstream_xchacha20poly1305_INONCEBYTES];
1554 1554
         # size_t        i;
@@ -1561,18 +1561,18 @@  discard block
 block discarded – undo
1561 1561
         #     new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i] =
1562 1562
         #         STATE_INONCE(state)[i];
1563 1563
         # }
1564
-        $new_key_and_inonce .= ParagonIE_Sodium_Core32_Util::substR($st->getNonce(), 0, 8);
1564
+        $new_key_and_inonce .= ParagonIE_Sodium_Core32_Util::substR( $st->getNonce(), 0, 8 );
1565 1565
 
1566 1566
         # crypto_stream_chacha20_ietf_xor(new_key_and_inonce, new_key_and_inonce,
1567 1567
         #                                 sizeof new_key_and_inonce,
1568 1568
         #                                 state->nonce, state->k);
1569 1569
 
1570
-        $st->rekey(ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1570
+        $st->rekey( ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1571 1571
             $new_key_and_inonce,
1572 1572
             $st->getCombinedNonce(),
1573 1573
             $st->getKey(),
1574
-            ParagonIE_Sodium_Core32_Util::store64_le(0)
1575
-        ));
1574
+            ParagonIE_Sodium_Core32_Util::store64_le( 0 )
1575
+        ) );
1576 1576
 
1577 1577
         # for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1578 1578
         #     state->k[i] = new_key_and_inonce[i];
@@ -1598,9 +1598,9 @@  discard block
 block discarded – undo
1598 1598
      * @throws SodiumException
1599 1599
      * @throws TypeError
1600 1600
      */
1601
-    public static function sign_detached($message, $sk)
1601
+    public static function sign_detached( $message, $sk )
1602 1602
     {
1603
-        return ParagonIE_Sodium_Core32_Ed25519::sign_detached($message, $sk);
1603
+        return ParagonIE_Sodium_Core32_Ed25519::sign_detached( $message, $sk );
1604 1604
     }
1605 1605
 
1606 1606
     /**
@@ -1614,9 +1614,9 @@  discard block
 block discarded – undo
1614 1614
      * @throws SodiumException
1615 1615
      * @throws TypeError
1616 1616
      */
1617
-    public static function sign($message, $sk)
1617
+    public static function sign( $message, $sk )
1618 1618
     {
1619
-        return ParagonIE_Sodium_Core32_Ed25519::sign($message, $sk);
1619
+        return ParagonIE_Sodium_Core32_Ed25519::sign( $message, $sk );
1620 1620
     }
1621 1621
 
1622 1622
     /**
@@ -1630,9 +1630,9 @@  discard block
 block discarded – undo
1630 1630
      * @throws SodiumException
1631 1631
      * @throws TypeError
1632 1632
      */
1633
-    public static function sign_open($signedMessage, $pk)
1633
+    public static function sign_open( $signedMessage, $pk )
1634 1634
     {
1635
-        return ParagonIE_Sodium_Core32_Ed25519::sign_open($signedMessage, $pk);
1635
+        return ParagonIE_Sodium_Core32_Ed25519::sign_open( $signedMessage, $pk );
1636 1636
     }
1637 1637
 
1638 1638
     /**
@@ -1647,8 +1647,8 @@  discard block
 block discarded – undo
1647 1647
      * @throws SodiumException
1648 1648
      * @throws TypeError
1649 1649
      */
1650
-    public static function sign_verify_detached($signature, $message, $pk)
1650
+    public static function sign_verify_detached( $signature, $message, $pk )
1651 1651
     {
1652
-        return ParagonIE_Sodium_Core32_Ed25519::verify_detached($signature, $message, $pk);
1652
+        return ParagonIE_Sodium_Core32_Ed25519::verify_detached( $signature, $message, $pk );
1653 1653
     }
1654 1654
 }
Please login to merge, or discard this patch.
Braces   +35 added lines, -70 removed lines patch added patch discarded remove patch
@@ -12,8 +12,7 @@  discard block
 block discarded – undo
12 12
  * If you are using this library, you should be using
13 13
  * ParagonIE_Sodium_Compat in your code, not this class.
14 14
  */
15
-abstract class ParagonIE_Sodium_Crypto32
16
-{
15
+abstract class ParagonIE_Sodium_Crypto32 {
17 16
     const aead_chacha20poly1305_KEYBYTES = 32;
18 17
     const aead_chacha20poly1305_NSECBYTES = 0;
19 18
     const aead_chacha20poly1305_NPUBBYTES = 8;
@@ -381,8 +380,7 @@  discard block
 block discarded – undo
381 380
      * @return string
382 381
      * @throws TypeError
383 382
      */
384
-    public static function auth($message, $key)
385
-    {
383
+    public static function auth($message, $key) {
386 384
         return ParagonIE_Sodium_Core32_Util::substr(
387 385
             hash_hmac('sha512', $message, $key, true),
388 386
             0,
@@ -402,8 +400,7 @@  discard block
 block discarded – undo
402 400
      * @throws SodiumException
403 401
      * @throws TypeError
404 402
      */
405
-    public static function auth_verify($mac, $message, $key)
406
-    {
403
+    public static function auth_verify($mac, $message, $key) {
407 404
         return ParagonIE_Sodium_Core32_Util::hashEquals(
408 405
             $mac,
409 406
             self::auth($message, $key)
@@ -422,8 +419,7 @@  discard block
 block discarded – undo
422 419
      * @throws SodiumException
423 420
      * @throws TypeError
424 421
      */
425
-    public static function box($plaintext, $nonce, $keypair)
426
-    {
422
+    public static function box($plaintext, $nonce, $keypair) {
427 423
         return self::secretbox(
428 424
             $plaintext,
429 425
             $nonce,
@@ -445,8 +441,7 @@  discard block
 block discarded – undo
445 441
      * @throws SodiumException
446 442
      * @throws TypeError
447 443
      */
448
-    public static function box_seal($message, $publicKey)
449
-    {
444
+    public static function box_seal($message, $publicKey) {
450 445
         /** @var string $ephemeralKeypair */
451 446
         $ephemeralKeypair = self::box_keypair();
452 447
 
@@ -491,8 +486,7 @@  discard block
 block discarded – undo
491 486
      * @throws SodiumException
492 487
      * @throws TypeError
493 488
      */
494
-    public static function box_seal_open($message, $keypair)
495
-    {
489
+    public static function box_seal_open($message, $keypair) {
496 490
         /** @var string $ephemeralPK */
497 491
         $ephemeralPK = ParagonIE_Sodium_Core32_Util::substr($message, 0, 32);
498 492
 
@@ -540,8 +534,7 @@  discard block
 block discarded – undo
540 534
      * @throws SodiumException
541 535
      * @throws TypeError
542 536
      */
543
-    public static function box_beforenm($sk, $pk)
544
-    {
537
+    public static function box_beforenm($sk, $pk) {
545 538
         return ParagonIE_Sodium_Core32_HSalsa20::hsalsa20(
546 539
             str_repeat("\x00", 16),
547 540
             self::scalarmult($sk, $pk)
@@ -556,8 +549,7 @@  discard block
 block discarded – undo
556 549
      * @throws SodiumException
557 550
      * @throws TypeError
558 551
      */
559
-    public static function box_keypair()
560
-    {
552
+    public static function box_keypair() {
561 553
         $sKey = random_bytes(32);
562 554
         $pKey = self::scalarmult_base($sKey);
563 555
         return $sKey . $pKey;
@@ -569,8 +561,7 @@  discard block
 block discarded – undo
569 561
      * @throws SodiumException
570 562
      * @throws TypeError
571 563
      */
572
-    public static function box_seed_keypair($seed)
573
-    {
564
+    public static function box_seed_keypair($seed) {
574 565
         $sKey = ParagonIE_Sodium_Core32_Util::substr(
575 566
             hash('sha512', $seed, true),
576 567
             0,
@@ -588,8 +579,7 @@  discard block
 block discarded – undo
588 579
      * @return string
589 580
      * @throws TypeError
590 581
      */
591
-    public static function box_keypair_from_secretkey_and_publickey($sKey, $pKey)
592
-    {
582
+    public static function box_keypair_from_secretkey_and_publickey($sKey, $pKey) {
593 583
         return ParagonIE_Sodium_Core32_Util::substr($sKey, 0, 32) .
594 584
             ParagonIE_Sodium_Core32_Util::substr($pKey, 0, 32);
595 585
     }
@@ -602,8 +592,7 @@  discard block
 block discarded – undo
602 592
      * @throws RangeException
603 593
      * @throws TypeError
604 594
      */
605
-    public static function box_secretkey($keypair)
606
-    {
595
+    public static function box_secretkey($keypair) {
607 596
         if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== 64) {
608 597
             throw new RangeException(
609 598
                 'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
@@ -620,8 +609,7 @@  discard block
 block discarded – undo
620 609
      * @throws RangeException
621 610
      * @throws TypeError
622 611
      */
623
-    public static function box_publickey($keypair)
624
-    {
612
+    public static function box_publickey($keypair) {
625 613
         if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
626 614
             throw new RangeException(
627 615
                 'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
@@ -639,8 +627,7 @@  discard block
 block discarded – undo
639 627
      * @throws SodiumException
640 628
      * @throws TypeError
641 629
      */
642
-    public static function box_publickey_from_secretkey($sKey)
643
-    {
630
+    public static function box_publickey_from_secretkey($sKey) {
644 631
         if (ParagonIE_Sodium_Core32_Util::strlen($sKey) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES) {
645 632
             throw new RangeException(
646 633
                 'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES bytes long.'
@@ -661,8 +648,7 @@  discard block
 block discarded – undo
661 648
      * @throws SodiumException
662 649
      * @throws TypeError
663 650
      */
664
-    public static function box_open($ciphertext, $nonce, $keypair)
665
-    {
651
+    public static function box_open($ciphertext, $nonce, $keypair) {
666 652
         return self::secretbox_open(
667 653
             $ciphertext,
668 654
             $nonce,
@@ -686,8 +672,7 @@  discard block
 block discarded – undo
686 672
      * @throws SodiumException
687 673
      * @throws TypeError
688 674
      */
689
-    public static function generichash($message, $key = '', $outlen = 32)
690
-    {
675
+    public static function generichash($message, $key = '', $outlen = 32) {
691 676
         // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
692 677
         ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
693 678
 
@@ -727,8 +712,7 @@  discard block
 block discarded – undo
727 712
      * @throws SodiumException
728 713
      * @throws TypeError
729 714
      */
730
-    public static function generichash_final($ctx, $outlen = 32)
731
-    {
715
+    public static function generichash_final($ctx, $outlen = 32) {
732 716
         if (!is_string($ctx)) {
733 717
             throw new TypeError('Context must be a string');
734 718
         }
@@ -757,8 +741,7 @@  discard block
 block discarded – undo
757 741
      * @throws SodiumException
758 742
      * @throws TypeError
759 743
      */
760
-    public static function generichash_init($key = '', $outputLength = 32)
761
-    {
744
+    public static function generichash_init($key = '', $outputLength = 32) {
762 745
         // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
763 746
         ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
764 747
 
@@ -834,8 +817,7 @@  discard block
 block discarded – undo
834 817
      * @throws SodiumException
835 818
      * @throws TypeError
836 819
      */
837
-    public static function generichash_update($ctx, $message)
838
-    {
820
+    public static function generichash_update($ctx, $message) {
839 821
         // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
840 822
         ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
841 823
 
@@ -863,8 +845,7 @@  discard block
 block discarded – undo
863 845
      * @throws SodiumException
864 846
      * @throws TypeError
865 847
      */
866
-    public static function keyExchange($my_sk, $their_pk, $client_pk, $server_pk)
867
-    {
848
+    public static function keyExchange($my_sk, $their_pk, $client_pk, $server_pk) {
868 849
         return self::generichash(
869 850
             self::scalarmult($my_sk, $their_pk) .
870 851
             $client_pk .
@@ -884,8 +865,7 @@  discard block
 block discarded – undo
884 865
      * @throws SodiumException
885 866
      * @throws TypeError
886 867
      */
887
-    public static function scalarmult($sKey, $pKey)
888
-    {
868
+    public static function scalarmult($sKey, $pKey) {
889 869
         $q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10($sKey, $pKey);
890 870
         self::scalarmult_throw_if_zero($q);
891 871
         return $q;
@@ -901,8 +881,7 @@  discard block
 block discarded – undo
901 881
      * @throws SodiumException
902 882
      * @throws TypeError
903 883
      */
904
-    public static function scalarmult_base($secret)
905
-    {
884
+    public static function scalarmult_base($secret) {
906 885
         $q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10_base($secret);
907 886
         self::scalarmult_throw_if_zero($q);
908 887
         return $q;
@@ -916,8 +895,7 @@  discard block
 block discarded – undo
916 895
      * @throws SodiumException
917 896
      * @throws TypeError
918 897
      */
919
-    protected static function scalarmult_throw_if_zero($q)
920
-    {
898
+    protected static function scalarmult_throw_if_zero($q) {
921 899
         $d = 0;
922 900
         for ($i = 0; $i < self::box_curve25519xsalsa20poly1305_SECRETKEYBYTES; ++$i) {
923 901
             $d |= ParagonIE_Sodium_Core32_Util::chrToInt($q[$i]);
@@ -941,8 +919,7 @@  discard block
 block discarded – undo
941 919
      * @throws SodiumException
942 920
      * @throws TypeError
943 921
      */
944
-    public static function secretbox($plaintext, $nonce, $key)
945
-    {
922
+    public static function secretbox($plaintext, $nonce, $key) {
946 923
         /** @var string $subkey */
947 924
         $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
948 925
 
@@ -1016,8 +993,7 @@  discard block
 block discarded – undo
1016 993
      * @throws SodiumException
1017 994
      * @throws TypeError
1018 995
      */
1019
-    public static function secretbox_open($ciphertext, $nonce, $key)
1020
-    {
996
+    public static function secretbox_open($ciphertext, $nonce, $key) {
1021 997
         /** @var string $mac */
1022 998
         $mac = ParagonIE_Sodium_Core32_Util::substr(
1023 999
             $ciphertext,
@@ -1089,8 +1065,7 @@  discard block
 block discarded – undo
1089 1065
      * @throws SodiumException
1090 1066
      * @throws TypeError
1091 1067
      */
1092
-    public static function secretbox_xchacha20poly1305($plaintext, $nonce, $key)
1093
-    {
1068
+    public static function secretbox_xchacha20poly1305($plaintext, $nonce, $key) {
1094 1069
         /** @var string $subkey */
1095 1070
         $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1096 1071
             ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
@@ -1168,8 +1143,7 @@  discard block
 block discarded – undo
1168 1143
      * @throws SodiumException
1169 1144
      * @throws TypeError
1170 1145
      */
1171
-    public static function secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key)
1172
-    {
1146
+    public static function secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key) {
1173 1147
         /** @var string $mac */
1174 1148
         $mac = ParagonIE_Sodium_Core32_Util::substr(
1175 1149
             $ciphertext,
@@ -1237,8 +1211,7 @@  discard block
 block discarded – undo
1237 1211
      * @throws Exception
1238 1212
      * @throws SodiumException
1239 1213
      */
1240
-    public static function secretstream_xchacha20poly1305_init_push($key)
1241
-    {
1214
+    public static function secretstream_xchacha20poly1305_init_push($key) {
1242 1215
         # randombytes_buf(out, crypto_secretstream_xchacha20poly1305_HEADERBYTES);
1243 1216
         $out = random_bytes(24);
1244 1217
 
@@ -1267,8 +1240,7 @@  discard block
 block discarded – undo
1267 1240
      * @return string Returns a state.
1268 1241
      * @throws Exception
1269 1242
      */
1270
-    public static function secretstream_xchacha20poly1305_init_pull($key, $header)
1271
-    {
1243
+    public static function secretstream_xchacha20poly1305_init_pull($key, $header) {
1272 1244
         # crypto_core_hchacha20(state->k, in, k, NULL);
1273 1245
         $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1274 1246
             ParagonIE_Sodium_Core32_Util::substr($header, 0, 16),
@@ -1294,8 +1266,7 @@  discard block
 block discarded – undo
1294 1266
      * @return string
1295 1267
      * @throws SodiumException
1296 1268
      */
1297
-    public static function secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0)
1298
-    {
1269
+    public static function secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0) {
1299 1270
         $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1300 1271
         # crypto_onetimeauth_poly1305_state poly1305_state;
1301 1272
         # unsigned char                     block[64U];
@@ -1423,8 +1394,7 @@  discard block
 block discarded – undo
1423 1394
      * @return bool|array{0: string, 1: int}
1424 1395
      * @throws SodiumException
1425 1396
      */
1426
-    public static function secretstream_xchacha20poly1305_pull(&$state, $cipher, $aad = '')
1427
-    {
1397
+    public static function secretstream_xchacha20poly1305_pull(&$state, $cipher, $aad = '') {
1428 1398
         $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1429 1399
 
1430 1400
         $cipherlen = ParagonIE_Sodium_Core32_Util::strlen($cipher);
@@ -1546,8 +1516,7 @@  discard block
 block discarded – undo
1546 1516
      * @return void
1547 1517
      * @throws SodiumException
1548 1518
      */
1549
-    public static function secretstream_xchacha20poly1305_rekey(&$state)
1550
-    {
1519
+    public static function secretstream_xchacha20poly1305_rekey(&$state) {
1551 1520
         $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1552 1521
         # unsigned char new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES +
1553 1522
         # crypto_secretstream_xchacha20poly1305_INONCEBYTES];
@@ -1598,8 +1567,7 @@  discard block
 block discarded – undo
1598 1567
      * @throws SodiumException
1599 1568
      * @throws TypeError
1600 1569
      */
1601
-    public static function sign_detached($message, $sk)
1602
-    {
1570
+    public static function sign_detached($message, $sk) {
1603 1571
         return ParagonIE_Sodium_Core32_Ed25519::sign_detached($message, $sk);
1604 1572
     }
1605 1573
 
@@ -1614,8 +1582,7 @@  discard block
 block discarded – undo
1614 1582
      * @throws SodiumException
1615 1583
      * @throws TypeError
1616 1584
      */
1617
-    public static function sign($message, $sk)
1618
-    {
1585
+    public static function sign($message, $sk) {
1619 1586
         return ParagonIE_Sodium_Core32_Ed25519::sign($message, $sk);
1620 1587
     }
1621 1588
 
@@ -1630,8 +1597,7 @@  discard block
 block discarded – undo
1630 1597
      * @throws SodiumException
1631 1598
      * @throws TypeError
1632 1599
      */
1633
-    public static function sign_open($signedMessage, $pk)
1634
-    {
1600
+    public static function sign_open($signedMessage, $pk) {
1635 1601
         return ParagonIE_Sodium_Core32_Ed25519::sign_open($signedMessage, $pk);
1636 1602
     }
1637 1603
 
@@ -1647,8 +1613,7 @@  discard block
 block discarded – undo
1647 1613
      * @throws SodiumException
1648 1614
      * @throws TypeError
1649 1615
      */
1650
-    public static function sign_verify_detached($signature, $message, $pk)
1651
-    {
1616
+    public static function sign_verify_detached($signature, $message, $pk) {
1652 1617
         return ParagonIE_Sodium_Core32_Ed25519::verify_detached($signature, $message, $pk);
1653 1618
     }
1654 1619
 }
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Core/Ed25519.php 3 patches
Braces   +19 added lines, -38 removed lines patch added patch discarded remove patch
@@ -7,8 +7,7 @@  discard block
 block discarded – undo
7 7
 /**
8 8
  * Class ParagonIE_Sodium_Core_Ed25519
9 9
  */
10
-abstract class ParagonIE_Sodium_Core_Ed25519 extends ParagonIE_Sodium_Core_Curve25519
11
-{
10
+abstract class ParagonIE_Sodium_Core_Ed25519 extends ParagonIE_Sodium_Core_Curve25519 {
12 11
     const KEYPAIR_BYTES = 96;
13 12
     const SEED_BYTES = 32;
14 13
     const SCALAR_BYTES = 32;
@@ -21,8 +20,7 @@  discard block
 block discarded – undo
21 20
      * @throws SodiumException
22 21
      * @throws TypeError
23 22
      */
24
-    public static function keypair()
25
-    {
23
+    public static function keypair() {
26 24
         $seed = random_bytes(self::SEED_BYTES);
27 25
         $pk = '';
28 26
         $sk = '';
@@ -40,8 +38,7 @@  discard block
 block discarded – undo
40 38
      * @throws SodiumException
41 39
      * @throws TypeError
42 40
      */
43
-    public static function seed_keypair(&$pk, &$sk, $seed)
44
-    {
41
+    public static function seed_keypair(&$pk, &$sk, $seed) {
45 42
         if (self::strlen($seed) !== self::SEED_BYTES) {
46 43
             throw new RangeException('crypto_sign keypair seed must be 32 bytes long');
47 44
         }
@@ -59,8 +56,7 @@  discard block
 block discarded – undo
59 56
      * @return string
60 57
      * @throws TypeError
61 58
      */
62
-    public static function secretkey($keypair)
63
-    {
59
+    public static function secretkey($keypair) {
64 60
         if (self::strlen($keypair) !== self::KEYPAIR_BYTES) {
65 61
             throw new RangeException('crypto_sign keypair must be 96 bytes long');
66 62
         }
@@ -74,8 +70,7 @@  discard block
 block discarded – undo
74 70
      * @return string
75 71
      * @throws TypeError
76 72
      */
77
-    public static function publickey($keypair)
78
-    {
73
+    public static function publickey($keypair) {
79 74
         if (self::strlen($keypair) !== self::KEYPAIR_BYTES) {
80 75
             throw new RangeException('crypto_sign keypair must be 96 bytes long');
81 76
         }
@@ -90,8 +85,7 @@  discard block
 block discarded – undo
90 85
      * @throws SodiumException
91 86
      * @throws TypeError
92 87
      */
93
-    public static function publickey_from_secretkey($sk)
94
-    {
88
+    public static function publickey_from_secretkey($sk) {
95 89
         /** @var string $sk */
96 90
         $sk = hash('sha512', self::substr($sk, 0, 32), true);
97 91
         $sk[0] = self::intToChr(
@@ -109,8 +103,7 @@  discard block
 block discarded – undo
109 103
      * @throws SodiumException
110 104
      * @throws TypeError
111 105
      */
112
-    public static function pk_to_curve25519($pk)
113
-    {
106
+    public static function pk_to_curve25519($pk) {
114 107
         if (self::small_order($pk)) {
115 108
             throw new SodiumException('Public key is on a small order');
116 109
         }
@@ -150,8 +143,7 @@  discard block
 block discarded – undo
150 143
      * @throws SodiumException
151 144
      * @throws TypeError
152 145
      */
153
-    public static function sk_to_pk($sk)
154
-    {
146
+    public static function sk_to_pk($sk) {
155 147
         return self::ge_p3_tobytes(
156 148
             self::ge_scalarmult_base(
157 149
                 self::substr($sk, 0, 32)
@@ -168,8 +160,7 @@  discard block
 block discarded – undo
168 160
      * @throws SodiumException
169 161
      * @throws TypeError
170 162
      */
171
-    public static function sign($message, $sk)
172
-    {
163
+    public static function sign($message, $sk) {
173 164
         /** @var string $signature */
174 165
         $signature = self::sign_detached($message, $sk);
175 166
         return $signature . $message;
@@ -184,8 +175,7 @@  discard block
 block discarded – undo
184 175
      * @throws SodiumException
185 176
      * @throws TypeError
186 177
      */
187
-    public static function sign_open($message, $pk)
188
-    {
178
+    public static function sign_open($message, $pk) {
189 179
         /** @var string $signature */
190 180
         $signature = self::substr($message, 0, 64);
191 181
 
@@ -207,8 +197,7 @@  discard block
 block discarded – undo
207 197
      * @throws SodiumException
208 198
      * @throws TypeError
209 199
      */
210
-    public static function sign_detached($message, $sk)
211
-    {
200
+    public static function sign_detached($message, $sk) {
212 201
         # crypto_hash_sha512(az, sk, 32);
213 202
         $az =  hash('sha512', self::substr($sk, 0, 32), true);
214 203
 
@@ -272,8 +261,7 @@  discard block
 block discarded – undo
272 261
      * @throws SodiumException
273 262
      * @throws TypeError
274 263
      */
275
-    public static function verify_detached($sig, $message, $pk)
276
-    {
264
+    public static function verify_detached($sig, $message, $pk) {
277 265
         if (self::strlen($sig) < 64) {
278 266
             throw new SodiumException('Signature is too short');
279 267
         }
@@ -339,8 +327,7 @@  discard block
 block discarded – undo
339 327
      * @throws SodiumException
340 328
      * @throws TypeError
341 329
      */
342
-    public static function check_S_lt_L($S)
343
-    {
330
+    public static function check_S_lt_L($S) {
344 331
         if (self::strlen($S) < 32) {
345 332
             throw new SodiumException('Signature must be 32 bytes');
346 333
         }
@@ -375,8 +362,7 @@  discard block
 block discarded – undo
375 362
      * @throws SodiumException
376 363
      * @throws TypeError
377 364
      */
378
-    public static function small_order($R)
379
-    {
365
+    public static function small_order($R) {
380 366
         /** @var array<int, array<int, int>> $blocklist */
381 367
         $blocklist = array(
382 368
             /* 0 (order 4) */
@@ -484,8 +470,7 @@  discard block
 block discarded – undo
484 470
      * @return string
485 471
      * @throws SodiumException
486 472
      */
487
-    public static function scalar_complement($s)
488
-    {
473
+    public static function scalar_complement($s) {
489 474
         $t_ = self::L . str_repeat("\x00", 32);
490 475
         sodium_increment($t_);
491 476
         $s_ = $s . str_repeat("\x00", 32);
@@ -497,8 +482,7 @@  discard block
 block discarded – undo
497 482
      * @return string
498 483
      * @throws SodiumException
499 484
      */
500
-    public static function scalar_random()
501
-    {
485
+    public static function scalar_random() {
502 486
         do {
503 487
             $r = ParagonIE_Sodium_Compat::randombytes_buf(self::SCALAR_BYTES);
504 488
             $r[self::SCALAR_BYTES - 1] = self::intToChr(
@@ -515,8 +499,7 @@  discard block
 block discarded – undo
515 499
      * @return string
516 500
      * @throws SodiumException
517 501
      */
518
-    public static function scalar_negate($s)
519
-    {
502
+    public static function scalar_negate($s) {
520 503
         $t_ = self::L . str_repeat("\x00", 32) ;
521 504
         $s_ = $s . str_repeat("\x00", 32) ;
522 505
         ParagonIE_Sodium_Compat::sub($t_, $s_);
@@ -529,8 +512,7 @@  discard block
 block discarded – undo
529 512
      * @return string
530 513
      * @throws SodiumException
531 514
      */
532
-    public static function scalar_add($a, $b)
533
-    {
515
+    public static function scalar_add($a, $b) {
534 516
         $a_ = $a . str_repeat("\x00", 32);
535 517
         $b_ = $b . str_repeat("\x00", 32);
536 518
         ParagonIE_Sodium_Compat::add($a_, $b_);
@@ -543,8 +525,7 @@  discard block
 block discarded – undo
543 525
      * @return string
544 526
      * @throws SodiumException
545 527
      */
546
-    public static function scalar_sub($x, $y)
547
-    {
528
+    public static function scalar_sub($x, $y) {
548 529
         $yn = self::scalar_negate($y);
549 530
         return self::scalar_add($x, $yn);
550 531
     }
Please login to merge, or discard this patch.
Indentation   +541 added lines, -541 removed lines patch added patch discarded remove patch
@@ -1,10 +1,10 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Core_Ed25519', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 if (!class_exists('ParagonIE_Sodium_Core_Curve25519', false)) {
7
-    require_once dirname(__FILE__) . '/Curve25519.php';
7
+	require_once dirname(__FILE__) . '/Curve25519.php';
8 8
 }
9 9
 
10 10
 /**
@@ -12,543 +12,543 @@  discard block
 block discarded – undo
12 12
  */
13 13
 abstract class ParagonIE_Sodium_Core_Ed25519 extends ParagonIE_Sodium_Core_Curve25519
14 14
 {
15
-    const KEYPAIR_BYTES = 96;
16
-    const SEED_BYTES = 32;
17
-    const SCALAR_BYTES = 32;
18
-
19
-    /**
20
-     * @internal You should not use this directly from another application
21
-     *
22
-     * @return string (96 bytes)
23
-     * @throws Exception
24
-     * @throws SodiumException
25
-     * @throws TypeError
26
-     */
27
-    public static function keypair()
28
-    {
29
-        $seed = random_bytes(self::SEED_BYTES);
30
-        $pk = '';
31
-        $sk = '';
32
-        self::seed_keypair($pk, $sk, $seed);
33
-        return $sk . $pk;
34
-    }
35
-
36
-    /**
37
-     * @internal You should not use this directly from another application
38
-     *
39
-     * @param string $pk
40
-     * @param string $sk
41
-     * @param string $seed
42
-     * @return string
43
-     * @throws SodiumException
44
-     * @throws TypeError
45
-     */
46
-    public static function seed_keypair(&$pk, &$sk, $seed)
47
-    {
48
-        if (self::strlen($seed) !== self::SEED_BYTES) {
49
-            throw new RangeException('crypto_sign keypair seed must be 32 bytes long');
50
-        }
51
-
52
-        /** @var string $pk */
53
-        $pk = self::publickey_from_secretkey($seed);
54
-        $sk = $seed . $pk;
55
-        return $sk;
56
-    }
57
-
58
-    /**
59
-     * @internal You should not use this directly from another application
60
-     *
61
-     * @param string $keypair
62
-     * @return string
63
-     * @throws TypeError
64
-     */
65
-    public static function secretkey($keypair)
66
-    {
67
-        if (self::strlen($keypair) !== self::KEYPAIR_BYTES) {
68
-            throw new RangeException('crypto_sign keypair must be 96 bytes long');
69
-        }
70
-        return self::substr($keypair, 0, 64);
71
-    }
72
-
73
-    /**
74
-     * @internal You should not use this directly from another application
75
-     *
76
-     * @param string $keypair
77
-     * @return string
78
-     * @throws TypeError
79
-     */
80
-    public static function publickey($keypair)
81
-    {
82
-        if (self::strlen($keypair) !== self::KEYPAIR_BYTES) {
83
-            throw new RangeException('crypto_sign keypair must be 96 bytes long');
84
-        }
85
-        return self::substr($keypair, 64, 32);
86
-    }
87
-
88
-    /**
89
-     * @internal You should not use this directly from another application
90
-     *
91
-     * @param string $sk
92
-     * @return string
93
-     * @throws SodiumException
94
-     * @throws TypeError
95
-     */
96
-    public static function publickey_from_secretkey($sk)
97
-    {
98
-        /** @var string $sk */
99
-        $sk = hash('sha512', self::substr($sk, 0, 32), true);
100
-        $sk[0] = self::intToChr(
101
-            self::chrToInt($sk[0]) & 248
102
-        );
103
-        $sk[31] = self::intToChr(
104
-            (self::chrToInt($sk[31]) & 63) | 64
105
-        );
106
-        return self::sk_to_pk($sk);
107
-    }
108
-
109
-    /**
110
-     * @param string $pk
111
-     * @return string
112
-     * @throws SodiumException
113
-     * @throws TypeError
114
-     */
115
-    public static function pk_to_curve25519($pk)
116
-    {
117
-        if (self::small_order($pk)) {
118
-            throw new SodiumException('Public key is on a small order');
119
-        }
120
-        $A = self::ge_frombytes_negate_vartime(self::substr($pk, 0, 32));
121
-        $p1 = self::ge_mul_l($A);
122
-        if (!self::fe_isnonzero($p1->X)) {
123
-            throw new SodiumException('Unexpected zero result');
124
-        }
125
-
126
-        # fe_1(one_minus_y);
127
-        # fe_sub(one_minus_y, one_minus_y, A.Y);
128
-        # fe_invert(one_minus_y, one_minus_y);
129
-        $one_minux_y = self::fe_invert(
130
-            self::fe_sub(
131
-                self::fe_1(),
132
-                $A->Y
133
-            )
134
-        );
135
-
136
-        # fe_1(x);
137
-        # fe_add(x, x, A.Y);
138
-        # fe_mul(x, x, one_minus_y);
139
-        $x = self::fe_mul(
140
-            self::fe_add(self::fe_1(), $A->Y),
141
-            $one_minux_y
142
-        );
143
-
144
-        # fe_tobytes(curve25519_pk, x);
145
-        return self::fe_tobytes($x);
146
-    }
147
-
148
-    /**
149
-     * @internal You should not use this directly from another application
150
-     *
151
-     * @param string $sk
152
-     * @return string
153
-     * @throws SodiumException
154
-     * @throws TypeError
155
-     */
156
-    public static function sk_to_pk($sk)
157
-    {
158
-        return self::ge_p3_tobytes(
159
-            self::ge_scalarmult_base(
160
-                self::substr($sk, 0, 32)
161
-            )
162
-        );
163
-    }
164
-
165
-    /**
166
-     * @internal You should not use this directly from another application
167
-     *
168
-     * @param string $message
169
-     * @param string $sk
170
-     * @return string
171
-     * @throws SodiumException
172
-     * @throws TypeError
173
-     */
174
-    public static function sign($message, $sk)
175
-    {
176
-        /** @var string $signature */
177
-        $signature = self::sign_detached($message, $sk);
178
-        return $signature . $message;
179
-    }
180
-
181
-    /**
182
-     * @internal You should not use this directly from another application
183
-     *
184
-     * @param string $message A signed message
185
-     * @param string $pk      Public key
186
-     * @return string         Message (without signature)
187
-     * @throws SodiumException
188
-     * @throws TypeError
189
-     */
190
-    public static function sign_open($message, $pk)
191
-    {
192
-        /** @var string $signature */
193
-        $signature = self::substr($message, 0, 64);
194
-
195
-        /** @var string $message */
196
-        $message = self::substr($message, 64);
197
-
198
-        if (self::verify_detached($signature, $message, $pk)) {
199
-            return $message;
200
-        }
201
-        throw new SodiumException('Invalid signature');
202
-    }
203
-
204
-    /**
205
-     * @internal You should not use this directly from another application
206
-     *
207
-     * @param string $message
208
-     * @param string $sk
209
-     * @return string
210
-     * @throws SodiumException
211
-     * @throws TypeError
212
-     */
213
-    public static function sign_detached($message, $sk)
214
-    {
215
-        # crypto_hash_sha512(az, sk, 32);
216
-        $az =  hash('sha512', self::substr($sk, 0, 32), true);
217
-
218
-        # az[0] &= 248;
219
-        # az[31] &= 63;
220
-        # az[31] |= 64;
221
-        $az[0] = self::intToChr(self::chrToInt($az[0]) & 248);
222
-        $az[31] = self::intToChr((self::chrToInt($az[31]) & 63) | 64);
223
-
224
-        # crypto_hash_sha512_init(&hs);
225
-        # crypto_hash_sha512_update(&hs, az + 32, 32);
226
-        # crypto_hash_sha512_update(&hs, m, mlen);
227
-        # crypto_hash_sha512_final(&hs, nonce);
228
-        $hs = hash_init('sha512');
229
-        hash_update($hs, self::substr($az, 32, 32));
230
-        hash_update($hs, $message);
231
-        $nonceHash = hash_final($hs, true);
232
-
233
-        # memmove(sig + 32, sk + 32, 32);
234
-        $pk = self::substr($sk, 32, 32);
235
-
236
-        # sc_reduce(nonce);
237
-        # ge_scalarmult_base(&R, nonce);
238
-        # ge_p3_tobytes(sig, &R);
239
-        $nonce = self::sc_reduce($nonceHash) . self::substr($nonceHash, 32);
240
-        $sig = self::ge_p3_tobytes(
241
-            self::ge_scalarmult_base($nonce)
242
-        );
243
-
244
-        # crypto_hash_sha512_init(&hs);
245
-        # crypto_hash_sha512_update(&hs, sig, 64);
246
-        # crypto_hash_sha512_update(&hs, m, mlen);
247
-        # crypto_hash_sha512_final(&hs, hram);
248
-        $hs = hash_init('sha512');
249
-        hash_update($hs, self::substr($sig, 0, 32));
250
-        hash_update($hs, self::substr($pk, 0, 32));
251
-        hash_update($hs, $message);
252
-        $hramHash = hash_final($hs, true);
253
-
254
-        # sc_reduce(hram);
255
-        # sc_muladd(sig + 32, hram, az, nonce);
256
-        $hram = self::sc_reduce($hramHash);
257
-        $sigAfter = self::sc_muladd($hram, $az, $nonce);
258
-        $sig = self::substr($sig, 0, 32) . self::substr($sigAfter, 0, 32);
259
-
260
-        try {
261
-            ParagonIE_Sodium_Compat::memzero($az);
262
-        } catch (SodiumException $ex) {
263
-            $az = null;
264
-        }
265
-        return $sig;
266
-    }
267
-
268
-    /**
269
-     * @internal You should not use this directly from another application
270
-     *
271
-     * @param string $sig
272
-     * @param string $message
273
-     * @param string $pk
274
-     * @return bool
275
-     * @throws SodiumException
276
-     * @throws TypeError
277
-     */
278
-    public static function verify_detached($sig, $message, $pk)
279
-    {
280
-        if (self::strlen($sig) < 64) {
281
-            throw new SodiumException('Signature is too short');
282
-        }
283
-        if ((self::chrToInt($sig[63]) & 240) && self::check_S_lt_L(self::substr($sig, 32, 32))) {
284
-            throw new SodiumException('S < L - Invalid signature');
285
-        }
286
-        if (self::small_order($sig)) {
287
-            throw new SodiumException('Signature is on too small of an order');
288
-        }
289
-        if ((self::chrToInt($sig[63]) & 224) !== 0) {
290
-            throw new SodiumException('Invalid signature');
291
-        }
292
-        $d = 0;
293
-        for ($i = 0; $i < 32; ++$i) {
294
-            $d |= self::chrToInt($pk[$i]);
295
-        }
296
-        if ($d === 0) {
297
-            throw new SodiumException('All zero public key');
298
-        }
299
-
300
-        /** @var bool The original value of ParagonIE_Sodium_Compat::$fastMult */
301
-        $orig = ParagonIE_Sodium_Compat::$fastMult;
302
-
303
-        // Set ParagonIE_Sodium_Compat::$fastMult to true to speed up verification.
304
-        ParagonIE_Sodium_Compat::$fastMult = true;
305
-
306
-        /** @var ParagonIE_Sodium_Core_Curve25519_Ge_P3 $A */
307
-        $A = self::ge_frombytes_negate_vartime($pk);
308
-
309
-        /** @var string $hDigest */
310
-        $hDigest = hash(
311
-            'sha512',
312
-            self::substr($sig, 0, 32) .
313
-                self::substr($pk, 0, 32) .
314
-                $message,
315
-            true
316
-        );
317
-
318
-        /** @var string $h */
319
-        $h = self::sc_reduce($hDigest) . self::substr($hDigest, 32);
320
-
321
-        /** @var ParagonIE_Sodium_Core_Curve25519_Ge_P2 $R */
322
-        $R = self::ge_double_scalarmult_vartime(
323
-            $h,
324
-            $A,
325
-            self::substr($sig, 32)
326
-        );
327
-
328
-        /** @var string $rcheck */
329
-        $rcheck = self::ge_tobytes($R);
330
-
331
-        // Reset ParagonIE_Sodium_Compat::$fastMult to what it was before.
332
-        ParagonIE_Sodium_Compat::$fastMult = $orig;
333
-
334
-        return self::verify_32($rcheck, self::substr($sig, 0, 32));
335
-    }
336
-
337
-    /**
338
-     * @internal You should not use this directly from another application
339
-     *
340
-     * @param string $S
341
-     * @return bool
342
-     * @throws SodiumException
343
-     * @throws TypeError
344
-     */
345
-    public static function check_S_lt_L($S)
346
-    {
347
-        if (self::strlen($S) < 32) {
348
-            throw new SodiumException('Signature must be 32 bytes');
349
-        }
350
-        $L = array(
351
-            0xed, 0xd3, 0xf5, 0x5c, 0x1a, 0x63, 0x12, 0x58,
352
-            0xd6, 0x9c, 0xf7, 0xa2, 0xde, 0xf9, 0xde, 0x14,
353
-            0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
354
-            0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x10
355
-        );
356
-        $c = 0;
357
-        $n = 1;
358
-        $i = 32;
359
-
360
-        /** @var array<int, int> $L */
361
-        do {
362
-            --$i;
363
-            $x = self::chrToInt($S[$i]);
364
-            $c |= (
365
-                (($x - $L[$i]) >> 8) & $n
366
-            );
367
-            $n &= (
368
-                (($x ^ $L[$i]) - 1) >> 8
369
-            );
370
-        } while ($i !== 0);
371
-
372
-        return $c === 0;
373
-    }
374
-
375
-    /**
376
-     * @param string $R
377
-     * @return bool
378
-     * @throws SodiumException
379
-     * @throws TypeError
380
-     */
381
-    public static function small_order($R)
382
-    {
383
-        /** @var array<int, array<int, int>> $blocklist */
384
-        $blocklist = array(
385
-            /* 0 (order 4) */
386
-            array(
387
-                0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
388
-                0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
389
-                0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
390
-                0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00
391
-            ),
392
-            /* 1 (order 1) */
393
-            array(
394
-                0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
395
-                0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
396
-                0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
397
-                0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00
398
-            ),
399
-            /* 2707385501144840649318225287225658788936804267575313519463743609750303402022 (order 8) */
400
-            array(
401
-                0x26, 0xe8, 0x95, 0x8f, 0xc2, 0xb2, 0x27, 0xb0,
402
-                0x45, 0xc3, 0xf4, 0x89, 0xf2, 0xef, 0x98, 0xf0,
403
-                0xd5, 0xdf, 0xac, 0x05, 0xd3, 0xc6, 0x33, 0x39,
404
-                0xb1, 0x38, 0x02, 0x88, 0x6d, 0x53, 0xfc, 0x05
405
-            ),
406
-            /* 55188659117513257062467267217118295137698188065244968500265048394206261417927 (order 8) */
407
-            array(
408
-                0xc7, 0x17, 0x6a, 0x70, 0x3d, 0x4d, 0xd8, 0x4f,
409
-                0xba, 0x3c, 0x0b, 0x76, 0x0d, 0x10, 0x67, 0x0f,
410
-                0x2a, 0x20, 0x53, 0xfa, 0x2c, 0x39, 0xcc, 0xc6,
411
-                0x4e, 0xc7, 0xfd, 0x77, 0x92, 0xac, 0x03, 0x7a
412
-            ),
413
-            /* p-1 (order 2) */
414
-            array(
415
-                0x13, 0xe8, 0x95, 0x8f, 0xc2, 0xb2, 0x27, 0xb0,
416
-                0x45, 0xc3, 0xf4, 0x89, 0xf2, 0xef, 0x98, 0xf0,
417
-                0xd5, 0xdf, 0xac, 0x05, 0xd3, 0xc6, 0x33, 0x39,
418
-                0xb1, 0x38, 0x02, 0x88, 0x6d, 0x53, 0xfc, 0x85
419
-            ),
420
-            /* p (order 4) */
421
-            array(
422
-                0xb4, 0x17, 0x6a, 0x70, 0x3d, 0x4d, 0xd8, 0x4f,
423
-                0xba, 0x3c, 0x0b, 0x76, 0x0d, 0x10, 0x67, 0x0f,
424
-                0x2a, 0x20, 0x53, 0xfa, 0x2c, 0x39, 0xcc, 0xc6,
425
-                0x4e, 0xc7, 0xfd, 0x77, 0x92, 0xac, 0x03, 0xfa
426
-            ),
427
-            /* p+1 (order 1) */
428
-            array(
429
-                0xec, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
430
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
431
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
432
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f
433
-            ),
434
-            /* p+2707385501144840649318225287225658788936804267575313519463743609750303402022 (order 8) */
435
-            array(
436
-                0xed, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
437
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
438
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
439
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f
440
-            ),
441
-            /* p+55188659117513257062467267217118295137698188065244968500265048394206261417927 (order 8) */
442
-            array(
443
-                0xee, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
444
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
445
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
446
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f
447
-            ),
448
-            /* 2p-1 (order 2) */
449
-            array(
450
-                0xd9, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
451
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
452
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
453
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff
454
-            ),
455
-            /* 2p (order 4) */
456
-            array(
457
-                0xda, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
458
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
459
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
460
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff
461
-            ),
462
-            /* 2p+1 (order 1) */
463
-            array(
464
-                0xdb, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
465
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
466
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
467
-                0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff
468
-            )
469
-        );
470
-        /** @var int $countBlocklist */
471
-        $countBlocklist = count($blocklist);
472
-
473
-        for ($i = 0; $i < $countBlocklist; ++$i) {
474
-            $c = 0;
475
-            for ($j = 0; $j < 32; ++$j) {
476
-                $c |= self::chrToInt($R[$j]) ^ (int) $blocklist[$i][$j];
477
-            }
478
-            if ($c === 0) {
479
-                return true;
480
-            }
481
-        }
482
-        return false;
483
-    }
484
-
485
-    /**
486
-     * @param string $s
487
-     * @return string
488
-     * @throws SodiumException
489
-     */
490
-    public static function scalar_complement($s)
491
-    {
492
-        $t_ = self::L . str_repeat("\x00", 32);
493
-        sodium_increment($t_);
494
-        $s_ = $s . str_repeat("\x00", 32);
495
-        ParagonIE_Sodium_Compat::sub($t_, $s_);
496
-        return self::sc_reduce($t_);
497
-    }
498
-
499
-    /**
500
-     * @return string
501
-     * @throws SodiumException
502
-     */
503
-    public static function scalar_random()
504
-    {
505
-        do {
506
-            $r = ParagonIE_Sodium_Compat::randombytes_buf(self::SCALAR_BYTES);
507
-            $r[self::SCALAR_BYTES - 1] = self::intToChr(
508
-                self::chrToInt($r[self::SCALAR_BYTES - 1]) & 0x1f
509
-            );
510
-        } while (
511
-            !self::check_S_lt_L($r) || ParagonIE_Sodium_Compat::is_zero($r)
512
-        );
513
-        return $r;
514
-    }
515
-
516
-    /**
517
-     * @param string $s
518
-     * @return string
519
-     * @throws SodiumException
520
-     */
521
-    public static function scalar_negate($s)
522
-    {
523
-        $t_ = self::L . str_repeat("\x00", 32) ;
524
-        $s_ = $s . str_repeat("\x00", 32) ;
525
-        ParagonIE_Sodium_Compat::sub($t_, $s_);
526
-        return self::sc_reduce($t_);
527
-    }
528
-
529
-    /**
530
-     * @param string $a
531
-     * @param string $b
532
-     * @return string
533
-     * @throws SodiumException
534
-     */
535
-    public static function scalar_add($a, $b)
536
-    {
537
-        $a_ = $a . str_repeat("\x00", 32);
538
-        $b_ = $b . str_repeat("\x00", 32);
539
-        ParagonIE_Sodium_Compat::add($a_, $b_);
540
-        return self::sc_reduce($a_);
541
-    }
542
-
543
-    /**
544
-     * @param string $x
545
-     * @param string $y
546
-     * @return string
547
-     * @throws SodiumException
548
-     */
549
-    public static function scalar_sub($x, $y)
550
-    {
551
-        $yn = self::scalar_negate($y);
552
-        return self::scalar_add($x, $yn);
553
-    }
15
+	const KEYPAIR_BYTES = 96;
16
+	const SEED_BYTES = 32;
17
+	const SCALAR_BYTES = 32;
18
+
19
+	/**
20
+	 * @internal You should not use this directly from another application
21
+	 *
22
+	 * @return string (96 bytes)
23
+	 * @throws Exception
24
+	 * @throws SodiumException
25
+	 * @throws TypeError
26
+	 */
27
+	public static function keypair()
28
+	{
29
+		$seed = random_bytes(self::SEED_BYTES);
30
+		$pk = '';
31
+		$sk = '';
32
+		self::seed_keypair($pk, $sk, $seed);
33
+		return $sk . $pk;
34
+	}
35
+
36
+	/**
37
+	 * @internal You should not use this directly from another application
38
+	 *
39
+	 * @param string $pk
40
+	 * @param string $sk
41
+	 * @param string $seed
42
+	 * @return string
43
+	 * @throws SodiumException
44
+	 * @throws TypeError
45
+	 */
46
+	public static function seed_keypair(&$pk, &$sk, $seed)
47
+	{
48
+		if (self::strlen($seed) !== self::SEED_BYTES) {
49
+			throw new RangeException('crypto_sign keypair seed must be 32 bytes long');
50
+		}
51
+
52
+		/** @var string $pk */
53
+		$pk = self::publickey_from_secretkey($seed);
54
+		$sk = $seed . $pk;
55
+		return $sk;
56
+	}
57
+
58
+	/**
59
+	 * @internal You should not use this directly from another application
60
+	 *
61
+	 * @param string $keypair
62
+	 * @return string
63
+	 * @throws TypeError
64
+	 */
65
+	public static function secretkey($keypair)
66
+	{
67
+		if (self::strlen($keypair) !== self::KEYPAIR_BYTES) {
68
+			throw new RangeException('crypto_sign keypair must be 96 bytes long');
69
+		}
70
+		return self::substr($keypair, 0, 64);
71
+	}
72
+
73
+	/**
74
+	 * @internal You should not use this directly from another application
75
+	 *
76
+	 * @param string $keypair
77
+	 * @return string
78
+	 * @throws TypeError
79
+	 */
80
+	public static function publickey($keypair)
81
+	{
82
+		if (self::strlen($keypair) !== self::KEYPAIR_BYTES) {
83
+			throw new RangeException('crypto_sign keypair must be 96 bytes long');
84
+		}
85
+		return self::substr($keypair, 64, 32);
86
+	}
87
+
88
+	/**
89
+	 * @internal You should not use this directly from another application
90
+	 *
91
+	 * @param string $sk
92
+	 * @return string
93
+	 * @throws SodiumException
94
+	 * @throws TypeError
95
+	 */
96
+	public static function publickey_from_secretkey($sk)
97
+	{
98
+		/** @var string $sk */
99
+		$sk = hash('sha512', self::substr($sk, 0, 32), true);
100
+		$sk[0] = self::intToChr(
101
+			self::chrToInt($sk[0]) & 248
102
+		);
103
+		$sk[31] = self::intToChr(
104
+			(self::chrToInt($sk[31]) & 63) | 64
105
+		);
106
+		return self::sk_to_pk($sk);
107
+	}
108
+
109
+	/**
110
+	 * @param string $pk
111
+	 * @return string
112
+	 * @throws SodiumException
113
+	 * @throws TypeError
114
+	 */
115
+	public static function pk_to_curve25519($pk)
116
+	{
117
+		if (self::small_order($pk)) {
118
+			throw new SodiumException('Public key is on a small order');
119
+		}
120
+		$A = self::ge_frombytes_negate_vartime(self::substr($pk, 0, 32));
121
+		$p1 = self::ge_mul_l($A);
122
+		if (!self::fe_isnonzero($p1->X)) {
123
+			throw new SodiumException('Unexpected zero result');
124
+		}
125
+
126
+		# fe_1(one_minus_y);
127
+		# fe_sub(one_minus_y, one_minus_y, A.Y);
128
+		# fe_invert(one_minus_y, one_minus_y);
129
+		$one_minux_y = self::fe_invert(
130
+			self::fe_sub(
131
+				self::fe_1(),
132
+				$A->Y
133
+			)
134
+		);
135
+
136
+		# fe_1(x);
137
+		# fe_add(x, x, A.Y);
138
+		# fe_mul(x, x, one_minus_y);
139
+		$x = self::fe_mul(
140
+			self::fe_add(self::fe_1(), $A->Y),
141
+			$one_minux_y
142
+		);
143
+
144
+		# fe_tobytes(curve25519_pk, x);
145
+		return self::fe_tobytes($x);
146
+	}
147
+
148
+	/**
149
+	 * @internal You should not use this directly from another application
150
+	 *
151
+	 * @param string $sk
152
+	 * @return string
153
+	 * @throws SodiumException
154
+	 * @throws TypeError
155
+	 */
156
+	public static function sk_to_pk($sk)
157
+	{
158
+		return self::ge_p3_tobytes(
159
+			self::ge_scalarmult_base(
160
+				self::substr($sk, 0, 32)
161
+			)
162
+		);
163
+	}
164
+
165
+	/**
166
+	 * @internal You should not use this directly from another application
167
+	 *
168
+	 * @param string $message
169
+	 * @param string $sk
170
+	 * @return string
171
+	 * @throws SodiumException
172
+	 * @throws TypeError
173
+	 */
174
+	public static function sign($message, $sk)
175
+	{
176
+		/** @var string $signature */
177
+		$signature = self::sign_detached($message, $sk);
178
+		return $signature . $message;
179
+	}
180
+
181
+	/**
182
+	 * @internal You should not use this directly from another application
183
+	 *
184
+	 * @param string $message A signed message
185
+	 * @param string $pk      Public key
186
+	 * @return string         Message (without signature)
187
+	 * @throws SodiumException
188
+	 * @throws TypeError
189
+	 */
190
+	public static function sign_open($message, $pk)
191
+	{
192
+		/** @var string $signature */
193
+		$signature = self::substr($message, 0, 64);
194
+
195
+		/** @var string $message */
196
+		$message = self::substr($message, 64);
197
+
198
+		if (self::verify_detached($signature, $message, $pk)) {
199
+			return $message;
200
+		}
201
+		throw new SodiumException('Invalid signature');
202
+	}
203
+
204
+	/**
205
+	 * @internal You should not use this directly from another application
206
+	 *
207
+	 * @param string $message
208
+	 * @param string $sk
209
+	 * @return string
210
+	 * @throws SodiumException
211
+	 * @throws TypeError
212
+	 */
213
+	public static function sign_detached($message, $sk)
214
+	{
215
+		# crypto_hash_sha512(az, sk, 32);
216
+		$az =  hash('sha512', self::substr($sk, 0, 32), true);
217
+
218
+		# az[0] &= 248;
219
+		# az[31] &= 63;
220
+		# az[31] |= 64;
221
+		$az[0] = self::intToChr(self::chrToInt($az[0]) & 248);
222
+		$az[31] = self::intToChr((self::chrToInt($az[31]) & 63) | 64);
223
+
224
+		# crypto_hash_sha512_init(&hs);
225
+		# crypto_hash_sha512_update(&hs, az + 32, 32);
226
+		# crypto_hash_sha512_update(&hs, m, mlen);
227
+		# crypto_hash_sha512_final(&hs, nonce);
228
+		$hs = hash_init('sha512');
229
+		hash_update($hs, self::substr($az, 32, 32));
230
+		hash_update($hs, $message);
231
+		$nonceHash = hash_final($hs, true);
232
+
233
+		# memmove(sig + 32, sk + 32, 32);
234
+		$pk = self::substr($sk, 32, 32);
235
+
236
+		# sc_reduce(nonce);
237
+		# ge_scalarmult_base(&R, nonce);
238
+		# ge_p3_tobytes(sig, &R);
239
+		$nonce = self::sc_reduce($nonceHash) . self::substr($nonceHash, 32);
240
+		$sig = self::ge_p3_tobytes(
241
+			self::ge_scalarmult_base($nonce)
242
+		);
243
+
244
+		# crypto_hash_sha512_init(&hs);
245
+		# crypto_hash_sha512_update(&hs, sig, 64);
246
+		# crypto_hash_sha512_update(&hs, m, mlen);
247
+		# crypto_hash_sha512_final(&hs, hram);
248
+		$hs = hash_init('sha512');
249
+		hash_update($hs, self::substr($sig, 0, 32));
250
+		hash_update($hs, self::substr($pk, 0, 32));
251
+		hash_update($hs, $message);
252
+		$hramHash = hash_final($hs, true);
253
+
254
+		# sc_reduce(hram);
255
+		# sc_muladd(sig + 32, hram, az, nonce);
256
+		$hram = self::sc_reduce($hramHash);
257
+		$sigAfter = self::sc_muladd($hram, $az, $nonce);
258
+		$sig = self::substr($sig, 0, 32) . self::substr($sigAfter, 0, 32);
259
+
260
+		try {
261
+			ParagonIE_Sodium_Compat::memzero($az);
262
+		} catch (SodiumException $ex) {
263
+			$az = null;
264
+		}
265
+		return $sig;
266
+	}
267
+
268
+	/**
269
+	 * @internal You should not use this directly from another application
270
+	 *
271
+	 * @param string $sig
272
+	 * @param string $message
273
+	 * @param string $pk
274
+	 * @return bool
275
+	 * @throws SodiumException
276
+	 * @throws TypeError
277
+	 */
278
+	public static function verify_detached($sig, $message, $pk)
279
+	{
280
+		if (self::strlen($sig) < 64) {
281
+			throw new SodiumException('Signature is too short');
282
+		}
283
+		if ((self::chrToInt($sig[63]) & 240) && self::check_S_lt_L(self::substr($sig, 32, 32))) {
284
+			throw new SodiumException('S < L - Invalid signature');
285
+		}
286
+		if (self::small_order($sig)) {
287
+			throw new SodiumException('Signature is on too small of an order');
288
+		}
289
+		if ((self::chrToInt($sig[63]) & 224) !== 0) {
290
+			throw new SodiumException('Invalid signature');
291
+		}
292
+		$d = 0;
293
+		for ($i = 0; $i < 32; ++$i) {
294
+			$d |= self::chrToInt($pk[$i]);
295
+		}
296
+		if ($d === 0) {
297
+			throw new SodiumException('All zero public key');
298
+		}
299
+
300
+		/** @var bool The original value of ParagonIE_Sodium_Compat::$fastMult */
301
+		$orig = ParagonIE_Sodium_Compat::$fastMult;
302
+
303
+		// Set ParagonIE_Sodium_Compat::$fastMult to true to speed up verification.
304
+		ParagonIE_Sodium_Compat::$fastMult = true;
305
+
306
+		/** @var ParagonIE_Sodium_Core_Curve25519_Ge_P3 $A */
307
+		$A = self::ge_frombytes_negate_vartime($pk);
308
+
309
+		/** @var string $hDigest */
310
+		$hDigest = hash(
311
+			'sha512',
312
+			self::substr($sig, 0, 32) .
313
+				self::substr($pk, 0, 32) .
314
+				$message,
315
+			true
316
+		);
317
+
318
+		/** @var string $h */
319
+		$h = self::sc_reduce($hDigest) . self::substr($hDigest, 32);
320
+
321
+		/** @var ParagonIE_Sodium_Core_Curve25519_Ge_P2 $R */
322
+		$R = self::ge_double_scalarmult_vartime(
323
+			$h,
324
+			$A,
325
+			self::substr($sig, 32)
326
+		);
327
+
328
+		/** @var string $rcheck */
329
+		$rcheck = self::ge_tobytes($R);
330
+
331
+		// Reset ParagonIE_Sodium_Compat::$fastMult to what it was before.
332
+		ParagonIE_Sodium_Compat::$fastMult = $orig;
333
+
334
+		return self::verify_32($rcheck, self::substr($sig, 0, 32));
335
+	}
336
+
337
+	/**
338
+	 * @internal You should not use this directly from another application
339
+	 *
340
+	 * @param string $S
341
+	 * @return bool
342
+	 * @throws SodiumException
343
+	 * @throws TypeError
344
+	 */
345
+	public static function check_S_lt_L($S)
346
+	{
347
+		if (self::strlen($S) < 32) {
348
+			throw new SodiumException('Signature must be 32 bytes');
349
+		}
350
+		$L = array(
351
+			0xed, 0xd3, 0xf5, 0x5c, 0x1a, 0x63, 0x12, 0x58,
352
+			0xd6, 0x9c, 0xf7, 0xa2, 0xde, 0xf9, 0xde, 0x14,
353
+			0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
354
+			0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x10
355
+		);
356
+		$c = 0;
357
+		$n = 1;
358
+		$i = 32;
359
+
360
+		/** @var array<int, int> $L */
361
+		do {
362
+			--$i;
363
+			$x = self::chrToInt($S[$i]);
364
+			$c |= (
365
+				(($x - $L[$i]) >> 8) & $n
366
+			);
367
+			$n &= (
368
+				(($x ^ $L[$i]) - 1) >> 8
369
+			);
370
+		} while ($i !== 0);
371
+
372
+		return $c === 0;
373
+	}
374
+
375
+	/**
376
+	 * @param string $R
377
+	 * @return bool
378
+	 * @throws SodiumException
379
+	 * @throws TypeError
380
+	 */
381
+	public static function small_order($R)
382
+	{
383
+		/** @var array<int, array<int, int>> $blocklist */
384
+		$blocklist = array(
385
+			/* 0 (order 4) */
386
+			array(
387
+				0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
388
+				0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
389
+				0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
390
+				0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00
391
+			),
392
+			/* 1 (order 1) */
393
+			array(
394
+				0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
395
+				0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
396
+				0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
397
+				0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00
398
+			),
399
+			/* 2707385501144840649318225287225658788936804267575313519463743609750303402022 (order 8) */
400
+			array(
401
+				0x26, 0xe8, 0x95, 0x8f, 0xc2, 0xb2, 0x27, 0xb0,
402
+				0x45, 0xc3, 0xf4, 0x89, 0xf2, 0xef, 0x98, 0xf0,
403
+				0xd5, 0xdf, 0xac, 0x05, 0xd3, 0xc6, 0x33, 0x39,
404
+				0xb1, 0x38, 0x02, 0x88, 0x6d, 0x53, 0xfc, 0x05
405
+			),
406
+			/* 55188659117513257062467267217118295137698188065244968500265048394206261417927 (order 8) */
407
+			array(
408
+				0xc7, 0x17, 0x6a, 0x70, 0x3d, 0x4d, 0xd8, 0x4f,
409
+				0xba, 0x3c, 0x0b, 0x76, 0x0d, 0x10, 0x67, 0x0f,
410
+				0x2a, 0x20, 0x53, 0xfa, 0x2c, 0x39, 0xcc, 0xc6,
411
+				0x4e, 0xc7, 0xfd, 0x77, 0x92, 0xac, 0x03, 0x7a
412
+			),
413
+			/* p-1 (order 2) */
414
+			array(
415
+				0x13, 0xe8, 0x95, 0x8f, 0xc2, 0xb2, 0x27, 0xb0,
416
+				0x45, 0xc3, 0xf4, 0x89, 0xf2, 0xef, 0x98, 0xf0,
417
+				0xd5, 0xdf, 0xac, 0x05, 0xd3, 0xc6, 0x33, 0x39,
418
+				0xb1, 0x38, 0x02, 0x88, 0x6d, 0x53, 0xfc, 0x85
419
+			),
420
+			/* p (order 4) */
421
+			array(
422
+				0xb4, 0x17, 0x6a, 0x70, 0x3d, 0x4d, 0xd8, 0x4f,
423
+				0xba, 0x3c, 0x0b, 0x76, 0x0d, 0x10, 0x67, 0x0f,
424
+				0x2a, 0x20, 0x53, 0xfa, 0x2c, 0x39, 0xcc, 0xc6,
425
+				0x4e, 0xc7, 0xfd, 0x77, 0x92, 0xac, 0x03, 0xfa
426
+			),
427
+			/* p+1 (order 1) */
428
+			array(
429
+				0xec, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
430
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
431
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
432
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f
433
+			),
434
+			/* p+2707385501144840649318225287225658788936804267575313519463743609750303402022 (order 8) */
435
+			array(
436
+				0xed, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
437
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
438
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
439
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f
440
+			),
441
+			/* p+55188659117513257062467267217118295137698188065244968500265048394206261417927 (order 8) */
442
+			array(
443
+				0xee, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
444
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
445
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
446
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f
447
+			),
448
+			/* 2p-1 (order 2) */
449
+			array(
450
+				0xd9, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
451
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
452
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
453
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff
454
+			),
455
+			/* 2p (order 4) */
456
+			array(
457
+				0xda, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
458
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
459
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
460
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff
461
+			),
462
+			/* 2p+1 (order 1) */
463
+			array(
464
+				0xdb, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
465
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
466
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
467
+				0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff
468
+			)
469
+		);
470
+		/** @var int $countBlocklist */
471
+		$countBlocklist = count($blocklist);
472
+
473
+		for ($i = 0; $i < $countBlocklist; ++$i) {
474
+			$c = 0;
475
+			for ($j = 0; $j < 32; ++$j) {
476
+				$c |= self::chrToInt($R[$j]) ^ (int) $blocklist[$i][$j];
477
+			}
478
+			if ($c === 0) {
479
+				return true;
480
+			}
481
+		}
482
+		return false;
483
+	}
484
+
485
+	/**
486
+	 * @param string $s
487
+	 * @return string
488
+	 * @throws SodiumException
489
+	 */
490
+	public static function scalar_complement($s)
491
+	{
492
+		$t_ = self::L . str_repeat("\x00", 32);
493
+		sodium_increment($t_);
494
+		$s_ = $s . str_repeat("\x00", 32);
495
+		ParagonIE_Sodium_Compat::sub($t_, $s_);
496
+		return self::sc_reduce($t_);
497
+	}
498
+
499
+	/**
500
+	 * @return string
501
+	 * @throws SodiumException
502
+	 */
503
+	public static function scalar_random()
504
+	{
505
+		do {
506
+			$r = ParagonIE_Sodium_Compat::randombytes_buf(self::SCALAR_BYTES);
507
+			$r[self::SCALAR_BYTES - 1] = self::intToChr(
508
+				self::chrToInt($r[self::SCALAR_BYTES - 1]) & 0x1f
509
+			);
510
+		} while (
511
+			!self::check_S_lt_L($r) || ParagonIE_Sodium_Compat::is_zero($r)
512
+		);
513
+		return $r;
514
+	}
515
+
516
+	/**
517
+	 * @param string $s
518
+	 * @return string
519
+	 * @throws SodiumException
520
+	 */
521
+	public static function scalar_negate($s)
522
+	{
523
+		$t_ = self::L . str_repeat("\x00", 32) ;
524
+		$s_ = $s . str_repeat("\x00", 32) ;
525
+		ParagonIE_Sodium_Compat::sub($t_, $s_);
526
+		return self::sc_reduce($t_);
527
+	}
528
+
529
+	/**
530
+	 * @param string $a
531
+	 * @param string $b
532
+	 * @return string
533
+	 * @throws SodiumException
534
+	 */
535
+	public static function scalar_add($a, $b)
536
+	{
537
+		$a_ = $a . str_repeat("\x00", 32);
538
+		$b_ = $b . str_repeat("\x00", 32);
539
+		ParagonIE_Sodium_Compat::add($a_, $b_);
540
+		return self::sc_reduce($a_);
541
+	}
542
+
543
+	/**
544
+	 * @param string $x
545
+	 * @param string $y
546
+	 * @return string
547
+	 * @throws SodiumException
548
+	 */
549
+	public static function scalar_sub($x, $y)
550
+	{
551
+		$yn = self::scalar_negate($y);
552
+		return self::scalar_add($x, $yn);
553
+	}
554 554
 }
Please login to merge, or discard this patch.
Spacing   +119 added lines, -119 removed lines patch added patch discarded remove patch
@@ -1,10 +1,10 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3
-if (class_exists('ParagonIE_Sodium_Core_Ed25519', false)) {
3
+if ( class_exists( 'ParagonIE_Sodium_Core_Ed25519', false ) ) {
4 4
     return;
5 5
 }
6
-if (!class_exists('ParagonIE_Sodium_Core_Curve25519', false)) {
7
-    require_once dirname(__FILE__) . '/Curve25519.php';
6
+if ( ! class_exists( 'ParagonIE_Sodium_Core_Curve25519', false ) ) {
7
+    require_once dirname( __FILE__ ) . '/Curve25519.php';
8 8
 }
9 9
 
10 10
 /**
@@ -26,10 +26,10 @@  discard block
 block discarded – undo
26 26
      */
27 27
     public static function keypair()
28 28
     {
29
-        $seed = random_bytes(self::SEED_BYTES);
29
+        $seed = random_bytes( self::SEED_BYTES );
30 30
         $pk = '';
31 31
         $sk = '';
32
-        self::seed_keypair($pk, $sk, $seed);
32
+        self::seed_keypair( $pk, $sk, $seed );
33 33
         return $sk . $pk;
34 34
     }
35 35
 
@@ -43,14 +43,14 @@  discard block
 block discarded – undo
43 43
      * @throws SodiumException
44 44
      * @throws TypeError
45 45
      */
46
-    public static function seed_keypair(&$pk, &$sk, $seed)
46
+    public static function seed_keypair( &$pk, &$sk, $seed )
47 47
     {
48
-        if (self::strlen($seed) !== self::SEED_BYTES) {
49
-            throw new RangeException('crypto_sign keypair seed must be 32 bytes long');
48
+        if ( self::strlen( $seed ) !== self::SEED_BYTES ) {
49
+            throw new RangeException( 'crypto_sign keypair seed must be 32 bytes long' );
50 50
         }
51 51
 
52 52
         /** @var string $pk */
53
-        $pk = self::publickey_from_secretkey($seed);
53
+        $pk = self::publickey_from_secretkey( $seed );
54 54
         $sk = $seed . $pk;
55 55
         return $sk;
56 56
     }
@@ -62,12 +62,12 @@  discard block
 block discarded – undo
62 62
      * @return string
63 63
      * @throws TypeError
64 64
      */
65
-    public static function secretkey($keypair)
65
+    public static function secretkey( $keypair )
66 66
     {
67
-        if (self::strlen($keypair) !== self::KEYPAIR_BYTES) {
68
-            throw new RangeException('crypto_sign keypair must be 96 bytes long');
67
+        if ( self::strlen( $keypair ) !== self::KEYPAIR_BYTES ) {
68
+            throw new RangeException( 'crypto_sign keypair must be 96 bytes long' );
69 69
         }
70
-        return self::substr($keypair, 0, 64);
70
+        return self::substr( $keypair, 0, 64 );
71 71
     }
72 72
 
73 73
     /**
@@ -77,12 +77,12 @@  discard block
 block discarded – undo
77 77
      * @return string
78 78
      * @throws TypeError
79 79
      */
80
-    public static function publickey($keypair)
80
+    public static function publickey( $keypair )
81 81
     {
82
-        if (self::strlen($keypair) !== self::KEYPAIR_BYTES) {
83
-            throw new RangeException('crypto_sign keypair must be 96 bytes long');
82
+        if ( self::strlen( $keypair ) !== self::KEYPAIR_BYTES ) {
83
+            throw new RangeException( 'crypto_sign keypair must be 96 bytes long' );
84 84
         }
85
-        return self::substr($keypair, 64, 32);
85
+        return self::substr( $keypair, 64, 32 );
86 86
     }
87 87
 
88 88
     /**
@@ -93,17 +93,17 @@  discard block
 block discarded – undo
93 93
      * @throws SodiumException
94 94
      * @throws TypeError
95 95
      */
96
-    public static function publickey_from_secretkey($sk)
96
+    public static function publickey_from_secretkey( $sk )
97 97
     {
98 98
         /** @var string $sk */
99
-        $sk = hash('sha512', self::substr($sk, 0, 32), true);
100
-        $sk[0] = self::intToChr(
101
-            self::chrToInt($sk[0]) & 248
99
+        $sk = hash( 'sha512', self::substr( $sk, 0, 32 ), true );
100
+        $sk[ 0 ] = self::intToChr(
101
+            self::chrToInt( $sk[ 0 ] ) & 248
102 102
         );
103
-        $sk[31] = self::intToChr(
104
-            (self::chrToInt($sk[31]) & 63) | 64
103
+        $sk[ 31 ] = self::intToChr(
104
+            ( self::chrToInt( $sk[ 31 ] ) & 63 ) | 64
105 105
         );
106
-        return self::sk_to_pk($sk);
106
+        return self::sk_to_pk( $sk );
107 107
     }
108 108
 
109 109
     /**
@@ -112,15 +112,15 @@  discard block
 block discarded – undo
112 112
      * @throws SodiumException
113 113
      * @throws TypeError
114 114
      */
115
-    public static function pk_to_curve25519($pk)
115
+    public static function pk_to_curve25519( $pk )
116 116
     {
117
-        if (self::small_order($pk)) {
118
-            throw new SodiumException('Public key is on a small order');
117
+        if ( self::small_order( $pk ) ) {
118
+            throw new SodiumException( 'Public key is on a small order' );
119 119
         }
120
-        $A = self::ge_frombytes_negate_vartime(self::substr($pk, 0, 32));
121
-        $p1 = self::ge_mul_l($A);
122
-        if (!self::fe_isnonzero($p1->X)) {
123
-            throw new SodiumException('Unexpected zero result');
120
+        $A = self::ge_frombytes_negate_vartime( self::substr( $pk, 0, 32 ) );
121
+        $p1 = self::ge_mul_l( $A );
122
+        if ( ! self::fe_isnonzero( $p1->X ) ) {
123
+            throw new SodiumException( 'Unexpected zero result' );
124 124
         }
125 125
 
126 126
         # fe_1(one_minus_y);
@@ -137,12 +137,12 @@  discard block
 block discarded – undo
137 137
         # fe_add(x, x, A.Y);
138 138
         # fe_mul(x, x, one_minus_y);
139 139
         $x = self::fe_mul(
140
-            self::fe_add(self::fe_1(), $A->Y),
140
+            self::fe_add( self::fe_1(), $A->Y ),
141 141
             $one_minux_y
142 142
         );
143 143
 
144 144
         # fe_tobytes(curve25519_pk, x);
145
-        return self::fe_tobytes($x);
145
+        return self::fe_tobytes( $x );
146 146
     }
147 147
 
148 148
     /**
@@ -153,11 +153,11 @@  discard block
 block discarded – undo
153 153
      * @throws SodiumException
154 154
      * @throws TypeError
155 155
      */
156
-    public static function sk_to_pk($sk)
156
+    public static function sk_to_pk( $sk )
157 157
     {
158 158
         return self::ge_p3_tobytes(
159 159
             self::ge_scalarmult_base(
160
-                self::substr($sk, 0, 32)
160
+                self::substr( $sk, 0, 32 )
161 161
             )
162 162
         );
163 163
     }
@@ -171,10 +171,10 @@  discard block
 block discarded – undo
171 171
      * @throws SodiumException
172 172
      * @throws TypeError
173 173
      */
174
-    public static function sign($message, $sk)
174
+    public static function sign( $message, $sk )
175 175
     {
176 176
         /** @var string $signature */
177
-        $signature = self::sign_detached($message, $sk);
177
+        $signature = self::sign_detached( $message, $sk );
178 178
         return $signature . $message;
179 179
     }
180 180
 
@@ -187,18 +187,18 @@  discard block
 block discarded – undo
187 187
      * @throws SodiumException
188 188
      * @throws TypeError
189 189
      */
190
-    public static function sign_open($message, $pk)
190
+    public static function sign_open( $message, $pk )
191 191
     {
192 192
         /** @var string $signature */
193
-        $signature = self::substr($message, 0, 64);
193
+        $signature = self::substr( $message, 0, 64 );
194 194
 
195 195
         /** @var string $message */
196
-        $message = self::substr($message, 64);
196
+        $message = self::substr( $message, 64 );
197 197
 
198
-        if (self::verify_detached($signature, $message, $pk)) {
198
+        if ( self::verify_detached( $signature, $message, $pk ) ) {
199 199
             return $message;
200 200
         }
201
-        throw new SodiumException('Invalid signature');
201
+        throw new SodiumException( 'Invalid signature' );
202 202
     }
203 203
 
204 204
     /**
@@ -210,56 +210,56 @@  discard block
 block discarded – undo
210 210
      * @throws SodiumException
211 211
      * @throws TypeError
212 212
      */
213
-    public static function sign_detached($message, $sk)
213
+    public static function sign_detached( $message, $sk )
214 214
     {
215 215
         # crypto_hash_sha512(az, sk, 32);
216
-        $az =  hash('sha512', self::substr($sk, 0, 32), true);
216
+        $az = hash( 'sha512', self::substr( $sk, 0, 32 ), true );
217 217
 
218 218
         # az[0] &= 248;
219 219
         # az[31] &= 63;
220 220
         # az[31] |= 64;
221
-        $az[0] = self::intToChr(self::chrToInt($az[0]) & 248);
222
-        $az[31] = self::intToChr((self::chrToInt($az[31]) & 63) | 64);
221
+        $az[ 0 ] = self::intToChr( self::chrToInt( $az[ 0 ] ) & 248 );
222
+        $az[ 31 ] = self::intToChr( ( self::chrToInt( $az[ 31 ] ) & 63 ) | 64 );
223 223
 
224 224
         # crypto_hash_sha512_init(&hs);
225 225
         # crypto_hash_sha512_update(&hs, az + 32, 32);
226 226
         # crypto_hash_sha512_update(&hs, m, mlen);
227 227
         # crypto_hash_sha512_final(&hs, nonce);
228
-        $hs = hash_init('sha512');
229
-        hash_update($hs, self::substr($az, 32, 32));
230
-        hash_update($hs, $message);
231
-        $nonceHash = hash_final($hs, true);
228
+        $hs = hash_init( 'sha512' );
229
+        hash_update( $hs, self::substr( $az, 32, 32 ) );
230
+        hash_update( $hs, $message );
231
+        $nonceHash = hash_final( $hs, true );
232 232
 
233 233
         # memmove(sig + 32, sk + 32, 32);
234
-        $pk = self::substr($sk, 32, 32);
234
+        $pk = self::substr( $sk, 32, 32 );
235 235
 
236 236
         # sc_reduce(nonce);
237 237
         # ge_scalarmult_base(&R, nonce);
238 238
         # ge_p3_tobytes(sig, &R);
239
-        $nonce = self::sc_reduce($nonceHash) . self::substr($nonceHash, 32);
239
+        $nonce = self::sc_reduce( $nonceHash ) . self::substr( $nonceHash, 32 );
240 240
         $sig = self::ge_p3_tobytes(
241
-            self::ge_scalarmult_base($nonce)
241
+            self::ge_scalarmult_base( $nonce )
242 242
         );
243 243
 
244 244
         # crypto_hash_sha512_init(&hs);
245 245
         # crypto_hash_sha512_update(&hs, sig, 64);
246 246
         # crypto_hash_sha512_update(&hs, m, mlen);
247 247
         # crypto_hash_sha512_final(&hs, hram);
248
-        $hs = hash_init('sha512');
249
-        hash_update($hs, self::substr($sig, 0, 32));
250
-        hash_update($hs, self::substr($pk, 0, 32));
251
-        hash_update($hs, $message);
252
-        $hramHash = hash_final($hs, true);
248
+        $hs = hash_init( 'sha512' );
249
+        hash_update( $hs, self::substr( $sig, 0, 32 ) );
250
+        hash_update( $hs, self::substr( $pk, 0, 32 ) );
251
+        hash_update( $hs, $message );
252
+        $hramHash = hash_final( $hs, true );
253 253
 
254 254
         # sc_reduce(hram);
255 255
         # sc_muladd(sig + 32, hram, az, nonce);
256
-        $hram = self::sc_reduce($hramHash);
257
-        $sigAfter = self::sc_muladd($hram, $az, $nonce);
258
-        $sig = self::substr($sig, 0, 32) . self::substr($sigAfter, 0, 32);
256
+        $hram = self::sc_reduce( $hramHash );
257
+        $sigAfter = self::sc_muladd( $hram, $az, $nonce );
258
+        $sig = self::substr( $sig, 0, 32 ) . self::substr( $sigAfter, 0, 32 );
259 259
 
260 260
         try {
261
-            ParagonIE_Sodium_Compat::memzero($az);
262
-        } catch (SodiumException $ex) {
261
+            ParagonIE_Sodium_Compat::memzero( $az );
262
+        } catch ( SodiumException $ex ) {
263 263
             $az = null;
264 264
         }
265 265
         return $sig;
@@ -275,26 +275,26 @@  discard block
 block discarded – undo
275 275
      * @throws SodiumException
276 276
      * @throws TypeError
277 277
      */
278
-    public static function verify_detached($sig, $message, $pk)
278
+    public static function verify_detached( $sig, $message, $pk )
279 279
     {
280
-        if (self::strlen($sig) < 64) {
281
-            throw new SodiumException('Signature is too short');
280
+        if ( self::strlen( $sig ) < 64 ) {
281
+            throw new SodiumException( 'Signature is too short' );
282 282
         }
283
-        if ((self::chrToInt($sig[63]) & 240) && self::check_S_lt_L(self::substr($sig, 32, 32))) {
284
-            throw new SodiumException('S < L - Invalid signature');
283
+        if ( ( self::chrToInt( $sig[ 63 ] ) & 240 ) && self::check_S_lt_L( self::substr( $sig, 32, 32 ) ) ) {
284
+            throw new SodiumException( 'S < L - Invalid signature' );
285 285
         }
286
-        if (self::small_order($sig)) {
287
-            throw new SodiumException('Signature is on too small of an order');
286
+        if ( self::small_order( $sig ) ) {
287
+            throw new SodiumException( 'Signature is on too small of an order' );
288 288
         }
289
-        if ((self::chrToInt($sig[63]) & 224) !== 0) {
290
-            throw new SodiumException('Invalid signature');
289
+        if ( ( self::chrToInt( $sig[ 63 ] ) & 224 ) !== 0 ) {
290
+            throw new SodiumException( 'Invalid signature' );
291 291
         }
292 292
         $d = 0;
293
-        for ($i = 0; $i < 32; ++$i) {
294
-            $d |= self::chrToInt($pk[$i]);
293
+        for ( $i = 0; $i < 32; ++$i ) {
294
+            $d |= self::chrToInt( $pk[ $i ] );
295 295
         }
296
-        if ($d === 0) {
297
-            throw new SodiumException('All zero public key');
296
+        if ( $d === 0 ) {
297
+            throw new SodiumException( 'All zero public key' );
298 298
         }
299 299
 
300 300
         /** @var bool The original value of ParagonIE_Sodium_Compat::$fastMult */
@@ -304,34 +304,34 @@  discard block
 block discarded – undo
304 304
         ParagonIE_Sodium_Compat::$fastMult = true;
305 305
 
306 306
         /** @var ParagonIE_Sodium_Core_Curve25519_Ge_P3 $A */
307
-        $A = self::ge_frombytes_negate_vartime($pk);
307
+        $A = self::ge_frombytes_negate_vartime( $pk );
308 308
 
309 309
         /** @var string $hDigest */
310 310
         $hDigest = hash(
311 311
             'sha512',
312
-            self::substr($sig, 0, 32) .
313
-                self::substr($pk, 0, 32) .
312
+            self::substr( $sig, 0, 32 ) .
313
+                self::substr( $pk, 0, 32 ) .
314 314
                 $message,
315 315
             true
316 316
         );
317 317
 
318 318
         /** @var string $h */
319
-        $h = self::sc_reduce($hDigest) . self::substr($hDigest, 32);
319
+        $h = self::sc_reduce( $hDigest ) . self::substr( $hDigest, 32 );
320 320
 
321 321
         /** @var ParagonIE_Sodium_Core_Curve25519_Ge_P2 $R */
322 322
         $R = self::ge_double_scalarmult_vartime(
323 323
             $h,
324 324
             $A,
325
-            self::substr($sig, 32)
325
+            self::substr( $sig, 32 )
326 326
         );
327 327
 
328 328
         /** @var string $rcheck */
329
-        $rcheck = self::ge_tobytes($R);
329
+        $rcheck = self::ge_tobytes( $R );
330 330
 
331 331
         // Reset ParagonIE_Sodium_Compat::$fastMult to what it was before.
332 332
         ParagonIE_Sodium_Compat::$fastMult = $orig;
333 333
 
334
-        return self::verify_32($rcheck, self::substr($sig, 0, 32));
334
+        return self::verify_32( $rcheck, self::substr( $sig, 0, 32 ) );
335 335
     }
336 336
 
337 337
     /**
@@ -342,10 +342,10 @@  discard block
 block discarded – undo
342 342
      * @throws SodiumException
343 343
      * @throws TypeError
344 344
      */
345
-    public static function check_S_lt_L($S)
345
+    public static function check_S_lt_L( $S )
346 346
     {
347
-        if (self::strlen($S) < 32) {
348
-            throw new SodiumException('Signature must be 32 bytes');
347
+        if ( self::strlen( $S ) < 32 ) {
348
+            throw new SodiumException( 'Signature must be 32 bytes' );
349 349
         }
350 350
         $L = array(
351 351
             0xed, 0xd3, 0xf5, 0x5c, 0x1a, 0x63, 0x12, 0x58,
@@ -360,14 +360,14 @@  discard block
 block discarded – undo
360 360
         /** @var array<int, int> $L */
361 361
         do {
362 362
             --$i;
363
-            $x = self::chrToInt($S[$i]);
363
+            $x = self::chrToInt( $S[ $i ] );
364 364
             $c |= (
365
-                (($x - $L[$i]) >> 8) & $n
365
+                ( ( $x - $L[ $i ] ) >> 8 ) & $n
366 366
             );
367 367
             $n &= (
368
-                (($x ^ $L[$i]) - 1) >> 8
368
+                ( ( $x ^ $L[ $i ] ) - 1 ) >> 8
369 369
             );
370
-        } while ($i !== 0);
370
+        } while ( $i !== 0 );
371 371
 
372 372
         return $c === 0;
373 373
     }
@@ -378,7 +378,7 @@  discard block
 block discarded – undo
378 378
      * @throws SodiumException
379 379
      * @throws TypeError
380 380
      */
381
-    public static function small_order($R)
381
+    public static function small_order( $R )
382 382
     {
383 383
         /** @var array<int, array<int, int>> $blocklist */
384 384
         $blocklist = array(
@@ -468,14 +468,14 @@  discard block
 block discarded – undo
468 468
             )
469 469
         );
470 470
         /** @var int $countBlocklist */
471
-        $countBlocklist = count($blocklist);
471
+        $countBlocklist = count( $blocklist );
472 472
 
473
-        for ($i = 0; $i < $countBlocklist; ++$i) {
473
+        for ( $i = 0; $i < $countBlocklist; ++$i ) {
474 474
             $c = 0;
475
-            for ($j = 0; $j < 32; ++$j) {
476
-                $c |= self::chrToInt($R[$j]) ^ (int) $blocklist[$i][$j];
475
+            for ( $j = 0; $j < 32; ++$j ) {
476
+                $c |= self::chrToInt( $R[ $j ] ) ^ (int)$blocklist[ $i ][ $j ];
477 477
             }
478
-            if ($c === 0) {
478
+            if ( $c === 0 ) {
479 479
                 return true;
480 480
             }
481 481
         }
@@ -487,13 +487,13 @@  discard block
 block discarded – undo
487 487
      * @return string
488 488
      * @throws SodiumException
489 489
      */
490
-    public static function scalar_complement($s)
490
+    public static function scalar_complement( $s )
491 491
     {
492
-        $t_ = self::L . str_repeat("\x00", 32);
493
-        sodium_increment($t_);
494
-        $s_ = $s . str_repeat("\x00", 32);
495
-        ParagonIE_Sodium_Compat::sub($t_, $s_);
496
-        return self::sc_reduce($t_);
492
+        $t_ = self::L . str_repeat( "\x00", 32 );
493
+        sodium_increment( $t_ );
494
+        $s_ = $s . str_repeat( "\x00", 32 );
495
+        ParagonIE_Sodium_Compat::sub( $t_, $s_ );
496
+        return self::sc_reduce( $t_ );
497 497
     }
498 498
 
499 499
     /**
@@ -503,12 +503,12 @@  discard block
 block discarded – undo
503 503
     public static function scalar_random()
504 504
     {
505 505
         do {
506
-            $r = ParagonIE_Sodium_Compat::randombytes_buf(self::SCALAR_BYTES);
507
-            $r[self::SCALAR_BYTES - 1] = self::intToChr(
508
-                self::chrToInt($r[self::SCALAR_BYTES - 1]) & 0x1f
506
+            $r = ParagonIE_Sodium_Compat::randombytes_buf( self::SCALAR_BYTES );
507
+            $r[ self::SCALAR_BYTES - 1 ] = self::intToChr(
508
+                self::chrToInt( $r[ self::SCALAR_BYTES - 1 ] ) & 0x1f
509 509
             );
510 510
         } while (
511
-            !self::check_S_lt_L($r) || ParagonIE_Sodium_Compat::is_zero($r)
511
+            ! self::check_S_lt_L( $r ) || ParagonIE_Sodium_Compat::is_zero( $r )
512 512
         );
513 513
         return $r;
514 514
     }
@@ -518,12 +518,12 @@  discard block
 block discarded – undo
518 518
      * @return string
519 519
      * @throws SodiumException
520 520
      */
521
-    public static function scalar_negate($s)
521
+    public static function scalar_negate( $s )
522 522
     {
523
-        $t_ = self::L . str_repeat("\x00", 32) ;
524
-        $s_ = $s . str_repeat("\x00", 32) ;
525
-        ParagonIE_Sodium_Compat::sub($t_, $s_);
526
-        return self::sc_reduce($t_);
523
+        $t_ = self::L . str_repeat( "\x00", 32 );
524
+        $s_ = $s . str_repeat( "\x00", 32 );
525
+        ParagonIE_Sodium_Compat::sub( $t_, $s_ );
526
+        return self::sc_reduce( $t_ );
527 527
     }
528 528
 
529 529
     /**
@@ -532,12 +532,12 @@  discard block
 block discarded – undo
532 532
      * @return string
533 533
      * @throws SodiumException
534 534
      */
535
-    public static function scalar_add($a, $b)
535
+    public static function scalar_add( $a, $b )
536 536
     {
537
-        $a_ = $a . str_repeat("\x00", 32);
538
-        $b_ = $b . str_repeat("\x00", 32);
539
-        ParagonIE_Sodium_Compat::add($a_, $b_);
540
-        return self::sc_reduce($a_);
537
+        $a_ = $a . str_repeat( "\x00", 32 );
538
+        $b_ = $b . str_repeat( "\x00", 32 );
539
+        ParagonIE_Sodium_Compat::add( $a_, $b_ );
540
+        return self::sc_reduce( $a_ );
541 541
     }
542 542
 
543 543
     /**
@@ -546,9 +546,9 @@  discard block
 block discarded – undo
546 546
      * @return string
547 547
      * @throws SodiumException
548 548
      */
549
-    public static function scalar_sub($x, $y)
549
+    public static function scalar_sub( $x, $y )
550 550
     {
551
-        $yn = self::scalar_negate($y);
552
-        return self::scalar_add($x, $yn);
551
+        $yn = self::scalar_negate( $y );
552
+        return self::scalar_add( $x, $yn );
553 553
     }
554 554
 }
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Core/SipHash.php 3 patches
Indentation   +293 added lines, -293 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Core_SipHash', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -11,296 +11,296 @@  discard block
 block discarded – undo
11 11
  */
12 12
 class ParagonIE_Sodium_Core_SipHash extends ParagonIE_Sodium_Core_Util
13 13
 {
14
-    /**
15
-     * @internal You should not use this directly from another application
16
-     *
17
-     * @param int[] $v
18
-     * @return int[]
19
-     *
20
-     */
21
-    public static function sipRound(array $v)
22
-    {
23
-        # v0 += v1;
24
-        list($v[0], $v[1]) = self::add(
25
-            array($v[0], $v[1]),
26
-            array($v[2], $v[3])
27
-        );
28
-
29
-        #  v1=ROTL(v1,13);
30
-        list($v[2], $v[3]) = self::rotl_64((int) $v[2], (int) $v[3], 13);
31
-
32
-        #  v1 ^= v0;
33
-        $v[2] = (int) $v[2] ^ (int) $v[0];
34
-        $v[3] = (int) $v[3] ^ (int) $v[1];
35
-
36
-        #  v0=ROTL(v0,32);
37
-        list($v[0], $v[1]) = self::rotl_64((int) $v[0], (int) $v[1], 32);
38
-
39
-        # v2 += v3;
40
-        list($v[4], $v[5]) = self::add(
41
-            array((int) $v[4], (int) $v[5]),
42
-            array((int) $v[6], (int) $v[7])
43
-        );
44
-
45
-        # v3=ROTL(v3,16);
46
-        list($v[6], $v[7]) = self::rotl_64((int) $v[6], (int) $v[7], 16);
47
-
48
-        #  v3 ^= v2;
49
-        $v[6] = (int) $v[6] ^ (int) $v[4];
50
-        $v[7] = (int) $v[7] ^ (int) $v[5];
51
-
52
-        # v0 += v3;
53
-        list($v[0], $v[1]) = self::add(
54
-            array((int) $v[0], (int) $v[1]),
55
-            array((int) $v[6], (int) $v[7])
56
-        );
57
-
58
-        # v3=ROTL(v3,21);
59
-        list($v[6], $v[7]) = self::rotl_64((int) $v[6], (int) $v[7], 21);
60
-
61
-        # v3 ^= v0;
62
-        $v[6] = (int) $v[6] ^ (int) $v[0];
63
-        $v[7] = (int) $v[7] ^ (int) $v[1];
64
-
65
-        # v2 += v1;
66
-        list($v[4], $v[5]) = self::add(
67
-            array((int) $v[4], (int) $v[5]),
68
-            array((int) $v[2], (int) $v[3])
69
-        );
70
-
71
-        # v1=ROTL(v1,17);
72
-        list($v[2], $v[3]) = self::rotl_64((int) $v[2], (int) $v[3], 17);
73
-
74
-        #  v1 ^= v2;;
75
-        $v[2] = (int) $v[2] ^ (int) $v[4];
76
-        $v[3] = (int) $v[3] ^ (int) $v[5];
77
-
78
-        # v2=ROTL(v2,32)
79
-        list($v[4], $v[5]) = self::rotl_64((int) $v[4], (int) $v[5], 32);
80
-
81
-        return $v;
82
-    }
83
-
84
-    /**
85
-     * Add two 32 bit integers representing a 64-bit integer.
86
-     *
87
-     * @internal You should not use this directly from another application
88
-     *
89
-     * @param int[] $a
90
-     * @param int[] $b
91
-     * @return array<int, mixed>
92
-     */
93
-    public static function add(array $a, array $b)
94
-    {
95
-        /** @var int $x1 */
96
-        $x1 = $a[1] + $b[1];
97
-        /** @var int $c */
98
-        $c = $x1 >> 32; // Carry if ($a + $b) > 0xffffffff
99
-        /** @var int $x0 */
100
-        $x0 = $a[0] + $b[0] + $c;
101
-        return array(
102
-            $x0 & 0xffffffff,
103
-            $x1 & 0xffffffff
104
-        );
105
-    }
106
-
107
-    /**
108
-     * @internal You should not use this directly from another application
109
-     *
110
-     * @param int $int0
111
-     * @param int $int1
112
-     * @param int $c
113
-     * @return array<int, mixed>
114
-     */
115
-    public static function rotl_64($int0, $int1, $c)
116
-    {
117
-        $int0 &= 0xffffffff;
118
-        $int1 &= 0xffffffff;
119
-        $c &= 63;
120
-        if ($c === 32) {
121
-            return array($int1, $int0);
122
-        }
123
-        if ($c > 31) {
124
-            $tmp = $int1;
125
-            $int1 = $int0;
126
-            $int0 = $tmp;
127
-            $c &= 31;
128
-        }
129
-        if ($c === 0) {
130
-            return array($int0, $int1);
131
-        }
132
-        return array(
133
-            0xffffffff & (
134
-                ($int0 << $c)
135
-                    |
136
-                ($int1 >> (32 - $c))
137
-            ),
138
-            0xffffffff & (
139
-                ($int1 << $c)
140
-                    |
141
-                ($int0 >> (32 - $c))
142
-            ),
143
-        );
144
-    }
145
-
146
-    /**
147
-     * Implements Siphash-2-4 using only 32-bit numbers.
148
-     *
149
-     * When we split an int into two, the higher bits go to the lower index.
150
-     * e.g. 0xDEADBEEFAB10C92D becomes [
151
-     *     0 => 0xDEADBEEF,
152
-     *     1 => 0xAB10C92D
153
-     * ].
154
-     *
155
-     * @internal You should not use this directly from another application
156
-     *
157
-     * @param string $in
158
-     * @param string $key
159
-     * @return string
160
-     * @throws SodiumException
161
-     * @throws TypeError
162
-     */
163
-    public static function sipHash24($in, $key)
164
-    {
165
-        $inlen = self::strlen($in);
166
-
167
-        # /* "somepseudorandomlygeneratedbytes" */
168
-        # u64 v0 = 0x736f6d6570736575ULL;
169
-        # u64 v1 = 0x646f72616e646f6dULL;
170
-        # u64 v2 = 0x6c7967656e657261ULL;
171
-        # u64 v3 = 0x7465646279746573ULL;
172
-        $v = array(
173
-            0x736f6d65, // 0
174
-            0x70736575, // 1
175
-            0x646f7261, // 2
176
-            0x6e646f6d, // 3
177
-            0x6c796765, // 4
178
-            0x6e657261, // 5
179
-            0x74656462, // 6
180
-            0x79746573  // 7
181
-        );
182
-        // v0 => $v[0], $v[1]
183
-        // v1 => $v[2], $v[3]
184
-        // v2 => $v[4], $v[5]
185
-        // v3 => $v[6], $v[7]
186
-
187
-        # u64 k0 = LOAD64_LE( k );
188
-        # u64 k1 = LOAD64_LE( k + 8 );
189
-        $k = array(
190
-            self::load_4(self::substr($key, 4, 4)),
191
-            self::load_4(self::substr($key, 0, 4)),
192
-            self::load_4(self::substr($key, 12, 4)),
193
-            self::load_4(self::substr($key, 8, 4))
194
-        );
195
-        // k0 => $k[0], $k[1]
196
-        // k1 => $k[2], $k[3]
197
-
198
-        # b = ( ( u64 )inlen ) << 56;
199
-        $b = array(
200
-            $inlen << 24,
201
-            0
202
-        );
203
-        // See docblock for why the 0th index gets the higher bits.
204
-
205
-        # v3 ^= k1;
206
-        $v[6] ^= $k[2];
207
-        $v[7] ^= $k[3];
208
-        # v2 ^= k0;
209
-        $v[4] ^= $k[0];
210
-        $v[5] ^= $k[1];
211
-        # v1 ^= k1;
212
-        $v[2] ^= $k[2];
213
-        $v[3] ^= $k[3];
214
-        # v0 ^= k0;
215
-        $v[0] ^= $k[0];
216
-        $v[1] ^= $k[1];
217
-
218
-        $left = $inlen;
219
-        # for ( ; in != end; in += 8 )
220
-        while ($left >= 8) {
221
-            # m = LOAD64_LE( in );
222
-            $m = array(
223
-                self::load_4(self::substr($in, 4, 4)),
224
-                self::load_4(self::substr($in, 0, 4))
225
-            );
226
-
227
-            # v3 ^= m;
228
-            $v[6] ^= $m[0];
229
-            $v[7] ^= $m[1];
230
-
231
-            # SIPROUND;
232
-            # SIPROUND;
233
-            $v = self::sipRound($v);
234
-            $v = self::sipRound($v);
235
-
236
-            # v0 ^= m;
237
-            $v[0] ^= $m[0];
238
-            $v[1] ^= $m[1];
239
-
240
-            $in = self::substr($in, 8);
241
-            $left -= 8;
242
-        }
243
-
244
-        # switch( left )
245
-        #  {
246
-        #     case 7: b |= ( ( u64 )in[ 6] )  << 48;
247
-        #     case 6: b |= ( ( u64 )in[ 5] )  << 40;
248
-        #     case 5: b |= ( ( u64 )in[ 4] )  << 32;
249
-        #     case 4: b |= ( ( u64 )in[ 3] )  << 24;
250
-        #     case 3: b |= ( ( u64 )in[ 2] )  << 16;
251
-        #     case 2: b |= ( ( u64 )in[ 1] )  <<  8;
252
-        #     case 1: b |= ( ( u64 )in[ 0] ); break;
253
-        #     case 0: break;
254
-        # }
255
-        switch ($left) {
256
-            case 7:
257
-                $b[0] |= self::chrToInt($in[6]) << 16;
258
-            case 6:
259
-                $b[0] |= self::chrToInt($in[5]) << 8;
260
-            case 5:
261
-                $b[0] |= self::chrToInt($in[4]);
262
-            case 4:
263
-                $b[1] |= self::chrToInt($in[3]) << 24;
264
-            case 3:
265
-                $b[1] |= self::chrToInt($in[2]) << 16;
266
-            case 2:
267
-                $b[1] |= self::chrToInt($in[1]) << 8;
268
-            case 1:
269
-                $b[1] |= self::chrToInt($in[0]);
270
-            case 0:
271
-                break;
272
-        }
273
-        // See docblock for why the 0th index gets the higher bits.
274
-
275
-        # v3 ^= b;
276
-        $v[6] ^= $b[0];
277
-        $v[7] ^= $b[1];
278
-
279
-        # SIPROUND;
280
-        # SIPROUND;
281
-        $v = self::sipRound($v);
282
-        $v = self::sipRound($v);
283
-
284
-        # v0 ^= b;
285
-        $v[0] ^= $b[0];
286
-        $v[1] ^= $b[1];
287
-
288
-        // Flip the lower 8 bits of v2 which is ($v[4], $v[5]) in our implementation
289
-        # v2 ^= 0xff;
290
-        $v[5] ^= 0xff;
291
-
292
-        # SIPROUND;
293
-        # SIPROUND;
294
-        # SIPROUND;
295
-        # SIPROUND;
296
-        $v = self::sipRound($v);
297
-        $v = self::sipRound($v);
298
-        $v = self::sipRound($v);
299
-        $v = self::sipRound($v);
300
-
301
-        # b = v0 ^ v1 ^ v2 ^ v3;
302
-        # STORE64_LE( out, b );
303
-        return  self::store32_le($v[1] ^ $v[3] ^ $v[5] ^ $v[7]) .
304
-            self::store32_le($v[0] ^ $v[2] ^ $v[4] ^ $v[6]);
305
-    }
14
+	/**
15
+	 * @internal You should not use this directly from another application
16
+	 *
17
+	 * @param int[] $v
18
+	 * @return int[]
19
+	 *
20
+	 */
21
+	public static function sipRound(array $v)
22
+	{
23
+		# v0 += v1;
24
+		list($v[0], $v[1]) = self::add(
25
+			array($v[0], $v[1]),
26
+			array($v[2], $v[3])
27
+		);
28
+
29
+		#  v1=ROTL(v1,13);
30
+		list($v[2], $v[3]) = self::rotl_64((int) $v[2], (int) $v[3], 13);
31
+
32
+		#  v1 ^= v0;
33
+		$v[2] = (int) $v[2] ^ (int) $v[0];
34
+		$v[3] = (int) $v[3] ^ (int) $v[1];
35
+
36
+		#  v0=ROTL(v0,32);
37
+		list($v[0], $v[1]) = self::rotl_64((int) $v[0], (int) $v[1], 32);
38
+
39
+		# v2 += v3;
40
+		list($v[4], $v[5]) = self::add(
41
+			array((int) $v[4], (int) $v[5]),
42
+			array((int) $v[6], (int) $v[7])
43
+		);
44
+
45
+		# v3=ROTL(v3,16);
46
+		list($v[6], $v[7]) = self::rotl_64((int) $v[6], (int) $v[7], 16);
47
+
48
+		#  v3 ^= v2;
49
+		$v[6] = (int) $v[6] ^ (int) $v[4];
50
+		$v[7] = (int) $v[7] ^ (int) $v[5];
51
+
52
+		# v0 += v3;
53
+		list($v[0], $v[1]) = self::add(
54
+			array((int) $v[0], (int) $v[1]),
55
+			array((int) $v[6], (int) $v[7])
56
+		);
57
+
58
+		# v3=ROTL(v3,21);
59
+		list($v[6], $v[7]) = self::rotl_64((int) $v[6], (int) $v[7], 21);
60
+
61
+		# v3 ^= v0;
62
+		$v[6] = (int) $v[6] ^ (int) $v[0];
63
+		$v[7] = (int) $v[7] ^ (int) $v[1];
64
+
65
+		# v2 += v1;
66
+		list($v[4], $v[5]) = self::add(
67
+			array((int) $v[4], (int) $v[5]),
68
+			array((int) $v[2], (int) $v[3])
69
+		);
70
+
71
+		# v1=ROTL(v1,17);
72
+		list($v[2], $v[3]) = self::rotl_64((int) $v[2], (int) $v[3], 17);
73
+
74
+		#  v1 ^= v2;;
75
+		$v[2] = (int) $v[2] ^ (int) $v[4];
76
+		$v[3] = (int) $v[3] ^ (int) $v[5];
77
+
78
+		# v2=ROTL(v2,32)
79
+		list($v[4], $v[5]) = self::rotl_64((int) $v[4], (int) $v[5], 32);
80
+
81
+		return $v;
82
+	}
83
+
84
+	/**
85
+	 * Add two 32 bit integers representing a 64-bit integer.
86
+	 *
87
+	 * @internal You should not use this directly from another application
88
+	 *
89
+	 * @param int[] $a
90
+	 * @param int[] $b
91
+	 * @return array<int, mixed>
92
+	 */
93
+	public static function add(array $a, array $b)
94
+	{
95
+		/** @var int $x1 */
96
+		$x1 = $a[1] + $b[1];
97
+		/** @var int $c */
98
+		$c = $x1 >> 32; // Carry if ($a + $b) > 0xffffffff
99
+		/** @var int $x0 */
100
+		$x0 = $a[0] + $b[0] + $c;
101
+		return array(
102
+			$x0 & 0xffffffff,
103
+			$x1 & 0xffffffff
104
+		);
105
+	}
106
+
107
+	/**
108
+	 * @internal You should not use this directly from another application
109
+	 *
110
+	 * @param int $int0
111
+	 * @param int $int1
112
+	 * @param int $c
113
+	 * @return array<int, mixed>
114
+	 */
115
+	public static function rotl_64($int0, $int1, $c)
116
+	{
117
+		$int0 &= 0xffffffff;
118
+		$int1 &= 0xffffffff;
119
+		$c &= 63;
120
+		if ($c === 32) {
121
+			return array($int1, $int0);
122
+		}
123
+		if ($c > 31) {
124
+			$tmp = $int1;
125
+			$int1 = $int0;
126
+			$int0 = $tmp;
127
+			$c &= 31;
128
+		}
129
+		if ($c === 0) {
130
+			return array($int0, $int1);
131
+		}
132
+		return array(
133
+			0xffffffff & (
134
+				($int0 << $c)
135
+					|
136
+				($int1 >> (32 - $c))
137
+			),
138
+			0xffffffff & (
139
+				($int1 << $c)
140
+					|
141
+				($int0 >> (32 - $c))
142
+			),
143
+		);
144
+	}
145
+
146
+	/**
147
+	 * Implements Siphash-2-4 using only 32-bit numbers.
148
+	 *
149
+	 * When we split an int into two, the higher bits go to the lower index.
150
+	 * e.g. 0xDEADBEEFAB10C92D becomes [
151
+	 *     0 => 0xDEADBEEF,
152
+	 *     1 => 0xAB10C92D
153
+	 * ].
154
+	 *
155
+	 * @internal You should not use this directly from another application
156
+	 *
157
+	 * @param string $in
158
+	 * @param string $key
159
+	 * @return string
160
+	 * @throws SodiumException
161
+	 * @throws TypeError
162
+	 */
163
+	public static function sipHash24($in, $key)
164
+	{
165
+		$inlen = self::strlen($in);
166
+
167
+		# /* "somepseudorandomlygeneratedbytes" */
168
+		# u64 v0 = 0x736f6d6570736575ULL;
169
+		# u64 v1 = 0x646f72616e646f6dULL;
170
+		# u64 v2 = 0x6c7967656e657261ULL;
171
+		# u64 v3 = 0x7465646279746573ULL;
172
+		$v = array(
173
+			0x736f6d65, // 0
174
+			0x70736575, // 1
175
+			0x646f7261, // 2
176
+			0x6e646f6d, // 3
177
+			0x6c796765, // 4
178
+			0x6e657261, // 5
179
+			0x74656462, // 6
180
+			0x79746573  // 7
181
+		);
182
+		// v0 => $v[0], $v[1]
183
+		// v1 => $v[2], $v[3]
184
+		// v2 => $v[4], $v[5]
185
+		// v3 => $v[6], $v[7]
186
+
187
+		# u64 k0 = LOAD64_LE( k );
188
+		# u64 k1 = LOAD64_LE( k + 8 );
189
+		$k = array(
190
+			self::load_4(self::substr($key, 4, 4)),
191
+			self::load_4(self::substr($key, 0, 4)),
192
+			self::load_4(self::substr($key, 12, 4)),
193
+			self::load_4(self::substr($key, 8, 4))
194
+		);
195
+		// k0 => $k[0], $k[1]
196
+		// k1 => $k[2], $k[3]
197
+
198
+		# b = ( ( u64 )inlen ) << 56;
199
+		$b = array(
200
+			$inlen << 24,
201
+			0
202
+		);
203
+		// See docblock for why the 0th index gets the higher bits.
204
+
205
+		# v3 ^= k1;
206
+		$v[6] ^= $k[2];
207
+		$v[7] ^= $k[3];
208
+		# v2 ^= k0;
209
+		$v[4] ^= $k[0];
210
+		$v[5] ^= $k[1];
211
+		# v1 ^= k1;
212
+		$v[2] ^= $k[2];
213
+		$v[3] ^= $k[3];
214
+		# v0 ^= k0;
215
+		$v[0] ^= $k[0];
216
+		$v[1] ^= $k[1];
217
+
218
+		$left = $inlen;
219
+		# for ( ; in != end; in += 8 )
220
+		while ($left >= 8) {
221
+			# m = LOAD64_LE( in );
222
+			$m = array(
223
+				self::load_4(self::substr($in, 4, 4)),
224
+				self::load_4(self::substr($in, 0, 4))
225
+			);
226
+
227
+			# v3 ^= m;
228
+			$v[6] ^= $m[0];
229
+			$v[7] ^= $m[1];
230
+
231
+			# SIPROUND;
232
+			# SIPROUND;
233
+			$v = self::sipRound($v);
234
+			$v = self::sipRound($v);
235
+
236
+			# v0 ^= m;
237
+			$v[0] ^= $m[0];
238
+			$v[1] ^= $m[1];
239
+
240
+			$in = self::substr($in, 8);
241
+			$left -= 8;
242
+		}
243
+
244
+		# switch( left )
245
+		#  {
246
+		#     case 7: b |= ( ( u64 )in[ 6] )  << 48;
247
+		#     case 6: b |= ( ( u64 )in[ 5] )  << 40;
248
+		#     case 5: b |= ( ( u64 )in[ 4] )  << 32;
249
+		#     case 4: b |= ( ( u64 )in[ 3] )  << 24;
250
+		#     case 3: b |= ( ( u64 )in[ 2] )  << 16;
251
+		#     case 2: b |= ( ( u64 )in[ 1] )  <<  8;
252
+		#     case 1: b |= ( ( u64 )in[ 0] ); break;
253
+		#     case 0: break;
254
+		# }
255
+		switch ($left) {
256
+			case 7:
257
+				$b[0] |= self::chrToInt($in[6]) << 16;
258
+			case 6:
259
+				$b[0] |= self::chrToInt($in[5]) << 8;
260
+			case 5:
261
+				$b[0] |= self::chrToInt($in[4]);
262
+			case 4:
263
+				$b[1] |= self::chrToInt($in[3]) << 24;
264
+			case 3:
265
+				$b[1] |= self::chrToInt($in[2]) << 16;
266
+			case 2:
267
+				$b[1] |= self::chrToInt($in[1]) << 8;
268
+			case 1:
269
+				$b[1] |= self::chrToInt($in[0]);
270
+			case 0:
271
+				break;
272
+		}
273
+		// See docblock for why the 0th index gets the higher bits.
274
+
275
+		# v3 ^= b;
276
+		$v[6] ^= $b[0];
277
+		$v[7] ^= $b[1];
278
+
279
+		# SIPROUND;
280
+		# SIPROUND;
281
+		$v = self::sipRound($v);
282
+		$v = self::sipRound($v);
283
+
284
+		# v0 ^= b;
285
+		$v[0] ^= $b[0];
286
+		$v[1] ^= $b[1];
287
+
288
+		// Flip the lower 8 bits of v2 which is ($v[4], $v[5]) in our implementation
289
+		# v2 ^= 0xff;
290
+		$v[5] ^= 0xff;
291
+
292
+		# SIPROUND;
293
+		# SIPROUND;
294
+		# SIPROUND;
295
+		# SIPROUND;
296
+		$v = self::sipRound($v);
297
+		$v = self::sipRound($v);
298
+		$v = self::sipRound($v);
299
+		$v = self::sipRound($v);
300
+
301
+		# b = v0 ^ v1 ^ v2 ^ v3;
302
+		# STORE64_LE( out, b );
303
+		return  self::store32_le($v[1] ^ $v[3] ^ $v[5] ^ $v[7]) .
304
+			self::store32_le($v[0] ^ $v[2] ^ $v[4] ^ $v[6]);
305
+	}
306 306
 }
Please login to merge, or discard this patch.
Spacing   +86 added lines, -86 removed lines patch added patch discarded remove patch
@@ -1,6 +1,6 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3
-if (class_exists('ParagonIE_Sodium_Core_SipHash', false)) {
3
+if ( class_exists( 'ParagonIE_Sodium_Core_SipHash', false ) ) {
4 4
     return;
5 5
 }
6 6
 
@@ -18,65 +18,65 @@  discard block
 block discarded – undo
18 18
      * @return int[]
19 19
      *
20 20
      */
21
-    public static function sipRound(array $v)
21
+    public static function sipRound( array $v )
22 22
     {
23 23
         # v0 += v1;
24
-        list($v[0], $v[1]) = self::add(
25
-            array($v[0], $v[1]),
26
-            array($v[2], $v[3])
24
+        list( $v[ 0 ], $v[ 1 ] ) = self::add(
25
+            array( $v[ 0 ], $v[ 1 ] ),
26
+            array( $v[ 2 ], $v[ 3 ] )
27 27
         );
28 28
 
29 29
         #  v1=ROTL(v1,13);
30
-        list($v[2], $v[3]) = self::rotl_64((int) $v[2], (int) $v[3], 13);
30
+        list( $v[ 2 ], $v[ 3 ] ) = self::rotl_64( (int)$v[ 2 ], (int)$v[ 3 ], 13 );
31 31
 
32 32
         #  v1 ^= v0;
33
-        $v[2] = (int) $v[2] ^ (int) $v[0];
34
-        $v[3] = (int) $v[3] ^ (int) $v[1];
33
+        $v[ 2 ] = (int)$v[ 2 ] ^ (int)$v[ 0 ];
34
+        $v[ 3 ] = (int)$v[ 3 ] ^ (int)$v[ 1 ];
35 35
 
36 36
         #  v0=ROTL(v0,32);
37
-        list($v[0], $v[1]) = self::rotl_64((int) $v[0], (int) $v[1], 32);
37
+        list( $v[ 0 ], $v[ 1 ] ) = self::rotl_64( (int)$v[ 0 ], (int)$v[ 1 ], 32 );
38 38
 
39 39
         # v2 += v3;
40
-        list($v[4], $v[5]) = self::add(
41
-            array((int) $v[4], (int) $v[5]),
42
-            array((int) $v[6], (int) $v[7])
40
+        list( $v[ 4 ], $v[ 5 ] ) = self::add(
41
+            array( (int)$v[ 4 ], (int)$v[ 5 ] ),
42
+            array( (int)$v[ 6 ], (int)$v[ 7 ] )
43 43
         );
44 44
 
45 45
         # v3=ROTL(v3,16);
46
-        list($v[6], $v[7]) = self::rotl_64((int) $v[6], (int) $v[7], 16);
46
+        list( $v[ 6 ], $v[ 7 ] ) = self::rotl_64( (int)$v[ 6 ], (int)$v[ 7 ], 16 );
47 47
 
48 48
         #  v3 ^= v2;
49
-        $v[6] = (int) $v[6] ^ (int) $v[4];
50
-        $v[7] = (int) $v[7] ^ (int) $v[5];
49
+        $v[ 6 ] = (int)$v[ 6 ] ^ (int)$v[ 4 ];
50
+        $v[ 7 ] = (int)$v[ 7 ] ^ (int)$v[ 5 ];
51 51
 
52 52
         # v0 += v3;
53
-        list($v[0], $v[1]) = self::add(
54
-            array((int) $v[0], (int) $v[1]),
55
-            array((int) $v[6], (int) $v[7])
53
+        list( $v[ 0 ], $v[ 1 ] ) = self::add(
54
+            array( (int)$v[ 0 ], (int)$v[ 1 ] ),
55
+            array( (int)$v[ 6 ], (int)$v[ 7 ] )
56 56
         );
57 57
 
58 58
         # v3=ROTL(v3,21);
59
-        list($v[6], $v[7]) = self::rotl_64((int) $v[6], (int) $v[7], 21);
59
+        list( $v[ 6 ], $v[ 7 ] ) = self::rotl_64( (int)$v[ 6 ], (int)$v[ 7 ], 21 );
60 60
 
61 61
         # v3 ^= v0;
62
-        $v[6] = (int) $v[6] ^ (int) $v[0];
63
-        $v[7] = (int) $v[7] ^ (int) $v[1];
62
+        $v[ 6 ] = (int)$v[ 6 ] ^ (int)$v[ 0 ];
63
+        $v[ 7 ] = (int)$v[ 7 ] ^ (int)$v[ 1 ];
64 64
 
65 65
         # v2 += v1;
66
-        list($v[4], $v[5]) = self::add(
67
-            array((int) $v[4], (int) $v[5]),
68
-            array((int) $v[2], (int) $v[3])
66
+        list( $v[ 4 ], $v[ 5 ] ) = self::add(
67
+            array( (int)$v[ 4 ], (int)$v[ 5 ] ),
68
+            array( (int)$v[ 2 ], (int)$v[ 3 ] )
69 69
         );
70 70
 
71 71
         # v1=ROTL(v1,17);
72
-        list($v[2], $v[3]) = self::rotl_64((int) $v[2], (int) $v[3], 17);
72
+        list( $v[ 2 ], $v[ 3 ] ) = self::rotl_64( (int)$v[ 2 ], (int)$v[ 3 ], 17 );
73 73
 
74 74
         #  v1 ^= v2;;
75
-        $v[2] = (int) $v[2] ^ (int) $v[4];
76
-        $v[3] = (int) $v[3] ^ (int) $v[5];
75
+        $v[ 2 ] = (int)$v[ 2 ] ^ (int)$v[ 4 ];
76
+        $v[ 3 ] = (int)$v[ 3 ] ^ (int)$v[ 5 ];
77 77
 
78 78
         # v2=ROTL(v2,32)
79
-        list($v[4], $v[5]) = self::rotl_64((int) $v[4], (int) $v[5], 32);
79
+        list( $v[ 4 ], $v[ 5 ] ) = self::rotl_64( (int)$v[ 4 ], (int)$v[ 5 ], 32 );
80 80
 
81 81
         return $v;
82 82
     }
@@ -90,14 +90,14 @@  discard block
 block discarded – undo
90 90
      * @param int[] $b
91 91
      * @return array<int, mixed>
92 92
      */
93
-    public static function add(array $a, array $b)
93
+    public static function add( array $a, array $b )
94 94
     {
95 95
         /** @var int $x1 */
96
-        $x1 = $a[1] + $b[1];
96
+        $x1 = $a[ 1 ] + $b[ 1 ];
97 97
         /** @var int $c */
98 98
         $c = $x1 >> 32; // Carry if ($a + $b) > 0xffffffff
99 99
         /** @var int $x0 */
100
-        $x0 = $a[0] + $b[0] + $c;
100
+        $x0 = $a[ 0 ] + $b[ 0 ] + $c;
101 101
         return array(
102 102
             $x0 & 0xffffffff,
103 103
             $x1 & 0xffffffff
@@ -112,33 +112,33 @@  discard block
 block discarded – undo
112 112
      * @param int $c
113 113
      * @return array<int, mixed>
114 114
      */
115
-    public static function rotl_64($int0, $int1, $c)
115
+    public static function rotl_64( $int0, $int1, $c )
116 116
     {
117 117
         $int0 &= 0xffffffff;
118 118
         $int1 &= 0xffffffff;
119 119
         $c &= 63;
120
-        if ($c === 32) {
121
-            return array($int1, $int0);
120
+        if ( $c === 32 ) {
121
+            return array( $int1, $int0 );
122 122
         }
123
-        if ($c > 31) {
123
+        if ( $c > 31 ) {
124 124
             $tmp = $int1;
125 125
             $int1 = $int0;
126 126
             $int0 = $tmp;
127 127
             $c &= 31;
128 128
         }
129
-        if ($c === 0) {
130
-            return array($int0, $int1);
129
+        if ( $c === 0 ) {
130
+            return array( $int0, $int1 );
131 131
         }
132 132
         return array(
133 133
             0xffffffff & (
134
-                ($int0 << $c)
134
+                ( $int0 << $c )
135 135
                     |
136
-                ($int1 >> (32 - $c))
136
+                ( $int1 >> ( 32 - $c ) )
137 137
             ),
138 138
             0xffffffff & (
139
-                ($int1 << $c)
139
+                ( $int1 << $c )
140 140
                     |
141
-                ($int0 >> (32 - $c))
141
+                ( $int0 >> ( 32 - $c ) )
142 142
             ),
143 143
         );
144 144
     }
@@ -160,9 +160,9 @@  discard block
 block discarded – undo
160 160
      * @throws SodiumException
161 161
      * @throws TypeError
162 162
      */
163
-    public static function sipHash24($in, $key)
163
+    public static function sipHash24( $in, $key )
164 164
     {
165
-        $inlen = self::strlen($in);
165
+        $inlen = self::strlen( $in );
166 166
 
167 167
         # /* "somepseudorandomlygeneratedbytes" */
168 168
         # u64 v0 = 0x736f6d6570736575ULL;
@@ -187,10 +187,10 @@  discard block
 block discarded – undo
187 187
         # u64 k0 = LOAD64_LE( k );
188 188
         # u64 k1 = LOAD64_LE( k + 8 );
189 189
         $k = array(
190
-            self::load_4(self::substr($key, 4, 4)),
191
-            self::load_4(self::substr($key, 0, 4)),
192
-            self::load_4(self::substr($key, 12, 4)),
193
-            self::load_4(self::substr($key, 8, 4))
190
+            self::load_4( self::substr( $key, 4, 4 ) ),
191
+            self::load_4( self::substr( $key, 0, 4 ) ),
192
+            self::load_4( self::substr( $key, 12, 4 ) ),
193
+            self::load_4( self::substr( $key, 8, 4 ) )
194 194
         );
195 195
         // k0 => $k[0], $k[1]
196 196
         // k1 => $k[2], $k[3]
@@ -203,41 +203,41 @@  discard block
 block discarded – undo
203 203
         // See docblock for why the 0th index gets the higher bits.
204 204
 
205 205
         # v3 ^= k1;
206
-        $v[6] ^= $k[2];
207
-        $v[7] ^= $k[3];
206
+        $v[ 6 ] ^= $k[ 2 ];
207
+        $v[ 7 ] ^= $k[ 3 ];
208 208
         # v2 ^= k0;
209
-        $v[4] ^= $k[0];
210
-        $v[5] ^= $k[1];
209
+        $v[ 4 ] ^= $k[ 0 ];
210
+        $v[ 5 ] ^= $k[ 1 ];
211 211
         # v1 ^= k1;
212
-        $v[2] ^= $k[2];
213
-        $v[3] ^= $k[3];
212
+        $v[ 2 ] ^= $k[ 2 ];
213
+        $v[ 3 ] ^= $k[ 3 ];
214 214
         # v0 ^= k0;
215
-        $v[0] ^= $k[0];
216
-        $v[1] ^= $k[1];
215
+        $v[ 0 ] ^= $k[ 0 ];
216
+        $v[ 1 ] ^= $k[ 1 ];
217 217
 
218 218
         $left = $inlen;
219 219
         # for ( ; in != end; in += 8 )
220
-        while ($left >= 8) {
220
+        while ( $left >= 8 ) {
221 221
             # m = LOAD64_LE( in );
222 222
             $m = array(
223
-                self::load_4(self::substr($in, 4, 4)),
224
-                self::load_4(self::substr($in, 0, 4))
223
+                self::load_4( self::substr( $in, 4, 4 ) ),
224
+                self::load_4( self::substr( $in, 0, 4 ) )
225 225
             );
226 226
 
227 227
             # v3 ^= m;
228
-            $v[6] ^= $m[0];
229
-            $v[7] ^= $m[1];
228
+            $v[ 6 ] ^= $m[ 0 ];
229
+            $v[ 7 ] ^= $m[ 1 ];
230 230
 
231 231
             # SIPROUND;
232 232
             # SIPROUND;
233
-            $v = self::sipRound($v);
234
-            $v = self::sipRound($v);
233
+            $v = self::sipRound( $v );
234
+            $v = self::sipRound( $v );
235 235
 
236 236
             # v0 ^= m;
237
-            $v[0] ^= $m[0];
238
-            $v[1] ^= $m[1];
237
+            $v[ 0 ] ^= $m[ 0 ];
238
+            $v[ 1 ] ^= $m[ 1 ];
239 239
 
240
-            $in = self::substr($in, 8);
240
+            $in = self::substr( $in, 8 );
241 241
             $left -= 8;
242 242
         }
243 243
 
@@ -252,55 +252,55 @@  discard block
 block discarded – undo
252 252
         #     case 1: b |= ( ( u64 )in[ 0] ); break;
253 253
         #     case 0: break;
254 254
         # }
255
-        switch ($left) {
255
+        switch ( $left ) {
256 256
             case 7:
257
-                $b[0] |= self::chrToInt($in[6]) << 16;
257
+                $b[ 0 ] |= self::chrToInt( $in[ 6 ] ) << 16;
258 258
             case 6:
259
-                $b[0] |= self::chrToInt($in[5]) << 8;
259
+                $b[ 0 ] |= self::chrToInt( $in[ 5 ] ) << 8;
260 260
             case 5:
261
-                $b[0] |= self::chrToInt($in[4]);
261
+                $b[ 0 ] |= self::chrToInt( $in[ 4 ] );
262 262
             case 4:
263
-                $b[1] |= self::chrToInt($in[3]) << 24;
263
+                $b[ 1 ] |= self::chrToInt( $in[ 3 ] ) << 24;
264 264
             case 3:
265
-                $b[1] |= self::chrToInt($in[2]) << 16;
265
+                $b[ 1 ] |= self::chrToInt( $in[ 2 ] ) << 16;
266 266
             case 2:
267
-                $b[1] |= self::chrToInt($in[1]) << 8;
267
+                $b[ 1 ] |= self::chrToInt( $in[ 1 ] ) << 8;
268 268
             case 1:
269
-                $b[1] |= self::chrToInt($in[0]);
269
+                $b[ 1 ] |= self::chrToInt( $in[ 0 ] );
270 270
             case 0:
271 271
                 break;
272 272
         }
273 273
         // See docblock for why the 0th index gets the higher bits.
274 274
 
275 275
         # v3 ^= b;
276
-        $v[6] ^= $b[0];
277
-        $v[7] ^= $b[1];
276
+        $v[ 6 ] ^= $b[ 0 ];
277
+        $v[ 7 ] ^= $b[ 1 ];
278 278
 
279 279
         # SIPROUND;
280 280
         # SIPROUND;
281
-        $v = self::sipRound($v);
282
-        $v = self::sipRound($v);
281
+        $v = self::sipRound( $v );
282
+        $v = self::sipRound( $v );
283 283
 
284 284
         # v0 ^= b;
285
-        $v[0] ^= $b[0];
286
-        $v[1] ^= $b[1];
285
+        $v[ 0 ] ^= $b[ 0 ];
286
+        $v[ 1 ] ^= $b[ 1 ];
287 287
 
288 288
         // Flip the lower 8 bits of v2 which is ($v[4], $v[5]) in our implementation
289 289
         # v2 ^= 0xff;
290
-        $v[5] ^= 0xff;
290
+        $v[ 5 ] ^= 0xff;
291 291
 
292 292
         # SIPROUND;
293 293
         # SIPROUND;
294 294
         # SIPROUND;
295 295
         # SIPROUND;
296
-        $v = self::sipRound($v);
297
-        $v = self::sipRound($v);
298
-        $v = self::sipRound($v);
299
-        $v = self::sipRound($v);
296
+        $v = self::sipRound( $v );
297
+        $v = self::sipRound( $v );
298
+        $v = self::sipRound( $v );
299
+        $v = self::sipRound( $v );
300 300
 
301 301
         # b = v0 ^ v1 ^ v2 ^ v3;
302 302
         # STORE64_LE( out, b );
303
-        return  self::store32_le($v[1] ^ $v[3] ^ $v[5] ^ $v[7]) .
304
-            self::store32_le($v[0] ^ $v[2] ^ $v[4] ^ $v[6]);
303
+        return  self::store32_le( $v[ 1 ] ^ $v[ 3 ] ^ $v[ 5 ] ^ $v[ 7 ] ) .
304
+            self::store32_le( $v[ 0 ] ^ $v[ 2 ] ^ $v[ 4 ] ^ $v[ 6 ] );
305 305
     }
306 306
 }
Please login to merge, or discard this patch.
Braces   +5 added lines, -10 removed lines patch added patch discarded remove patch
@@ -9,8 +9,7 @@  discard block
 block discarded – undo
9 9
  *
10 10
  * Only uses 32-bit arithmetic, while the original SipHash used 64-bit integers
11 11
  */
12
-class ParagonIE_Sodium_Core_SipHash extends ParagonIE_Sodium_Core_Util
13
-{
12
+class ParagonIE_Sodium_Core_SipHash extends ParagonIE_Sodium_Core_Util {
14 13
     /**
15 14
      * @internal You should not use this directly from another application
16 15
      *
@@ -18,8 +17,7 @@  discard block
 block discarded – undo
18 17
      * @return int[]
19 18
      *
20 19
      */
21
-    public static function sipRound(array $v)
22
-    {
20
+    public static function sipRound(array $v) {
23 21
         # v0 += v1;
24 22
         list($v[0], $v[1]) = self::add(
25 23
             array($v[0], $v[1]),
@@ -90,8 +88,7 @@  discard block
 block discarded – undo
90 88
      * @param int[] $b
91 89
      * @return array<int, mixed>
92 90
      */
93
-    public static function add(array $a, array $b)
94
-    {
91
+    public static function add(array $a, array $b) {
95 92
         /** @var int $x1 */
96 93
         $x1 = $a[1] + $b[1];
97 94
         /** @var int $c */
@@ -112,8 +109,7 @@  discard block
 block discarded – undo
112 109
      * @param int $c
113 110
      * @return array<int, mixed>
114 111
      */
115
-    public static function rotl_64($int0, $int1, $c)
116
-    {
112
+    public static function rotl_64($int0, $int1, $c) {
117 113
         $int0 &= 0xffffffff;
118 114
         $int1 &= 0xffffffff;
119 115
         $c &= 63;
@@ -160,8 +156,7 @@  discard block
 block discarded – undo
160 156
      * @throws SodiumException
161 157
      * @throws TypeError
162 158
      */
163
-    public static function sipHash24($in, $key)
164
-    {
159
+    public static function sipHash24($in, $key) {
165 160
         $inlen = self::strlen($in);
166 161
 
167 162
         # /* "somepseudorandomlygeneratedbytes" */
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Core/XChaCha20.php 3 patches
Indentation   +103 added lines, -103 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Core_XChaCha20', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -9,109 +9,109 @@  discard block
 block discarded – undo
9 9
  */
10 10
 class ParagonIE_Sodium_Core_XChaCha20 extends ParagonIE_Sodium_Core_HChaCha20
11 11
 {
12
-    /**
13
-     * @internal You should not use this directly from another application
14
-     *
15
-     * @param int $len
16
-     * @param string $nonce
17
-     * @param string $key
18
-     * @return string
19
-     * @throws SodiumException
20
-     * @throws TypeError
21
-     */
22
-    public static function stream($len = 64, $nonce = '', $key = '')
23
-    {
24
-        if (self::strlen($nonce) !== 24) {
25
-            throw new SodiumException('Nonce must be 24 bytes long');
26
-        }
27
-        return self::encryptBytes(
28
-            new ParagonIE_Sodium_Core_ChaCha20_Ctx(
29
-                self::hChaCha20(
30
-                    self::substr($nonce, 0, 16),
31
-                    $key
32
-                ),
33
-                self::substr($nonce, 16, 8)
34
-            ),
35
-            str_repeat("\x00", $len)
36
-        );
37
-    }
12
+	/**
13
+	 * @internal You should not use this directly from another application
14
+	 *
15
+	 * @param int $len
16
+	 * @param string $nonce
17
+	 * @param string $key
18
+	 * @return string
19
+	 * @throws SodiumException
20
+	 * @throws TypeError
21
+	 */
22
+	public static function stream($len = 64, $nonce = '', $key = '')
23
+	{
24
+		if (self::strlen($nonce) !== 24) {
25
+			throw new SodiumException('Nonce must be 24 bytes long');
26
+		}
27
+		return self::encryptBytes(
28
+			new ParagonIE_Sodium_Core_ChaCha20_Ctx(
29
+				self::hChaCha20(
30
+					self::substr($nonce, 0, 16),
31
+					$key
32
+				),
33
+				self::substr($nonce, 16, 8)
34
+			),
35
+			str_repeat("\x00", $len)
36
+		);
37
+	}
38 38
 
39
-    /**
40
-     * @internal You should not use this directly from another application
41
-     *
42
-     * @param int $len
43
-     * @param string $nonce
44
-     * @param string $key
45
-     * @return string
46
-     * @throws SodiumException
47
-     * @throws TypeError
48
-     */
49
-    public static function ietfStream($len = 64, $nonce = '', $key = '')
50
-    {
51
-        if (self::strlen($nonce) !== 24) {
52
-            throw new SodiumException('Nonce must be 24 bytes long');
53
-        }
54
-        return self::encryptBytes(
55
-            new ParagonIE_Sodium_Core_ChaCha20_IetfCtx(
56
-                self::hChaCha20(
57
-                    self::substr($nonce, 0, 16),
58
-                    $key
59
-                ),
60
-                "\x00\x00\x00\x00" . self::substr($nonce, 16, 8)
61
-            ),
62
-            str_repeat("\x00", $len)
63
-        );
64
-    }
39
+	/**
40
+	 * @internal You should not use this directly from another application
41
+	 *
42
+	 * @param int $len
43
+	 * @param string $nonce
44
+	 * @param string $key
45
+	 * @return string
46
+	 * @throws SodiumException
47
+	 * @throws TypeError
48
+	 */
49
+	public static function ietfStream($len = 64, $nonce = '', $key = '')
50
+	{
51
+		if (self::strlen($nonce) !== 24) {
52
+			throw new SodiumException('Nonce must be 24 bytes long');
53
+		}
54
+		return self::encryptBytes(
55
+			new ParagonIE_Sodium_Core_ChaCha20_IetfCtx(
56
+				self::hChaCha20(
57
+					self::substr($nonce, 0, 16),
58
+					$key
59
+				),
60
+				"\x00\x00\x00\x00" . self::substr($nonce, 16, 8)
61
+			),
62
+			str_repeat("\x00", $len)
63
+		);
64
+	}
65 65
 
66
-    /**
67
-     * @internal You should not use this directly from another application
68
-     *
69
-     * @param string $message
70
-     * @param string $nonce
71
-     * @param string $key
72
-     * @param string $ic
73
-     * @return string
74
-     * @throws SodiumException
75
-     * @throws TypeError
76
-     */
77
-    public static function streamXorIc($message, $nonce = '', $key = '', $ic = '')
78
-    {
79
-        if (self::strlen($nonce) !== 24) {
80
-            throw new SodiumException('Nonce must be 24 bytes long');
81
-        }
82
-        return self::encryptBytes(
83
-            new ParagonIE_Sodium_Core_ChaCha20_Ctx(
84
-                self::hChaCha20(self::substr($nonce, 0, 16), $key),
85
-                self::substr($nonce, 16, 8),
86
-                $ic
87
-            ),
88
-            $message
89
-        );
90
-    }
66
+	/**
67
+	 * @internal You should not use this directly from another application
68
+	 *
69
+	 * @param string $message
70
+	 * @param string $nonce
71
+	 * @param string $key
72
+	 * @param string $ic
73
+	 * @return string
74
+	 * @throws SodiumException
75
+	 * @throws TypeError
76
+	 */
77
+	public static function streamXorIc($message, $nonce = '', $key = '', $ic = '')
78
+	{
79
+		if (self::strlen($nonce) !== 24) {
80
+			throw new SodiumException('Nonce must be 24 bytes long');
81
+		}
82
+		return self::encryptBytes(
83
+			new ParagonIE_Sodium_Core_ChaCha20_Ctx(
84
+				self::hChaCha20(self::substr($nonce, 0, 16), $key),
85
+				self::substr($nonce, 16, 8),
86
+				$ic
87
+			),
88
+			$message
89
+		);
90
+	}
91 91
 
92
-    /**
93
-     * @internal You should not use this directly from another application
94
-     *
95
-     * @param string $message
96
-     * @param string $nonce
97
-     * @param string $key
98
-     * @param string $ic
99
-     * @return string
100
-     * @throws SodiumException
101
-     * @throws TypeError
102
-     */
103
-    public static function ietfStreamXorIc($message, $nonce = '', $key = '', $ic = '')
104
-    {
105
-        if (self::strlen($nonce) !== 24) {
106
-            throw new SodiumException('Nonce must be 24 bytes long');
107
-        }
108
-        return self::encryptBytes(
109
-            new ParagonIE_Sodium_Core_ChaCha20_IetfCtx(
110
-                self::hChaCha20(self::substr($nonce, 0, 16), $key),
111
-                "\x00\x00\x00\x00" . self::substr($nonce, 16, 8),
112
-                $ic
113
-            ),
114
-            $message
115
-        );
116
-    }
92
+	/**
93
+	 * @internal You should not use this directly from another application
94
+	 *
95
+	 * @param string $message
96
+	 * @param string $nonce
97
+	 * @param string $key
98
+	 * @param string $ic
99
+	 * @return string
100
+	 * @throws SodiumException
101
+	 * @throws TypeError
102
+	 */
103
+	public static function ietfStreamXorIc($message, $nonce = '', $key = '', $ic = '')
104
+	{
105
+		if (self::strlen($nonce) !== 24) {
106
+			throw new SodiumException('Nonce must be 24 bytes long');
107
+		}
108
+		return self::encryptBytes(
109
+			new ParagonIE_Sodium_Core_ChaCha20_IetfCtx(
110
+				self::hChaCha20(self::substr($nonce, 0, 16), $key),
111
+				"\x00\x00\x00\x00" . self::substr($nonce, 16, 8),
112
+				$ic
113
+			),
114
+			$message
115
+		);
116
+	}
117 117
 }
Please login to merge, or discard this patch.
Spacing   +23 added lines, -23 removed lines patch added patch discarded remove patch
@@ -1,6 +1,6 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3
-if (class_exists('ParagonIE_Sodium_Core_XChaCha20', false)) {
3
+if ( class_exists( 'ParagonIE_Sodium_Core_XChaCha20', false ) ) {
4 4
     return;
5 5
 }
6 6
 
@@ -19,20 +19,20 @@  discard block
 block discarded – undo
19 19
      * @throws SodiumException
20 20
      * @throws TypeError
21 21
      */
22
-    public static function stream($len = 64, $nonce = '', $key = '')
22
+    public static function stream( $len = 64, $nonce = '', $key = '' )
23 23
     {
24
-        if (self::strlen($nonce) !== 24) {
25
-            throw new SodiumException('Nonce must be 24 bytes long');
24
+        if ( self::strlen( $nonce ) !== 24 ) {
25
+            throw new SodiumException( 'Nonce must be 24 bytes long' );
26 26
         }
27 27
         return self::encryptBytes(
28 28
             new ParagonIE_Sodium_Core_ChaCha20_Ctx(
29 29
                 self::hChaCha20(
30
-                    self::substr($nonce, 0, 16),
30
+                    self::substr( $nonce, 0, 16 ),
31 31
                     $key
32 32
                 ),
33
-                self::substr($nonce, 16, 8)
33
+                self::substr( $nonce, 16, 8 )
34 34
             ),
35
-            str_repeat("\x00", $len)
35
+            str_repeat( "\x00", $len )
36 36
         );
37 37
     }
38 38
 
@@ -46,20 +46,20 @@  discard block
 block discarded – undo
46 46
      * @throws SodiumException
47 47
      * @throws TypeError
48 48
      */
49
-    public static function ietfStream($len = 64, $nonce = '', $key = '')
49
+    public static function ietfStream( $len = 64, $nonce = '', $key = '' )
50 50
     {
51
-        if (self::strlen($nonce) !== 24) {
52
-            throw new SodiumException('Nonce must be 24 bytes long');
51
+        if ( self::strlen( $nonce ) !== 24 ) {
52
+            throw new SodiumException( 'Nonce must be 24 bytes long' );
53 53
         }
54 54
         return self::encryptBytes(
55 55
             new ParagonIE_Sodium_Core_ChaCha20_IetfCtx(
56 56
                 self::hChaCha20(
57
-                    self::substr($nonce, 0, 16),
57
+                    self::substr( $nonce, 0, 16 ),
58 58
                     $key
59 59
                 ),
60
-                "\x00\x00\x00\x00" . self::substr($nonce, 16, 8)
60
+                "\x00\x00\x00\x00" . self::substr( $nonce, 16, 8 )
61 61
             ),
62
-            str_repeat("\x00", $len)
62
+            str_repeat( "\x00", $len )
63 63
         );
64 64
     }
65 65
 
@@ -74,15 +74,15 @@  discard block
 block discarded – undo
74 74
      * @throws SodiumException
75 75
      * @throws TypeError
76 76
      */
77
-    public static function streamXorIc($message, $nonce = '', $key = '', $ic = '')
77
+    public static function streamXorIc( $message, $nonce = '', $key = '', $ic = '' )
78 78
     {
79
-        if (self::strlen($nonce) !== 24) {
80
-            throw new SodiumException('Nonce must be 24 bytes long');
79
+        if ( self::strlen( $nonce ) !== 24 ) {
80
+            throw new SodiumException( 'Nonce must be 24 bytes long' );
81 81
         }
82 82
         return self::encryptBytes(
83 83
             new ParagonIE_Sodium_Core_ChaCha20_Ctx(
84
-                self::hChaCha20(self::substr($nonce, 0, 16), $key),
85
-                self::substr($nonce, 16, 8),
84
+                self::hChaCha20( self::substr( $nonce, 0, 16 ), $key ),
85
+                self::substr( $nonce, 16, 8 ),
86 86
                 $ic
87 87
             ),
88 88
             $message
@@ -100,15 +100,15 @@  discard block
 block discarded – undo
100 100
      * @throws SodiumException
101 101
      * @throws TypeError
102 102
      */
103
-    public static function ietfStreamXorIc($message, $nonce = '', $key = '', $ic = '')
103
+    public static function ietfStreamXorIc( $message, $nonce = '', $key = '', $ic = '' )
104 104
     {
105
-        if (self::strlen($nonce) !== 24) {
106
-            throw new SodiumException('Nonce must be 24 bytes long');
105
+        if ( self::strlen( $nonce ) !== 24 ) {
106
+            throw new SodiumException( 'Nonce must be 24 bytes long' );
107 107
         }
108 108
         return self::encryptBytes(
109 109
             new ParagonIE_Sodium_Core_ChaCha20_IetfCtx(
110
-                self::hChaCha20(self::substr($nonce, 0, 16), $key),
111
-                "\x00\x00\x00\x00" . self::substr($nonce, 16, 8),
110
+                self::hChaCha20( self::substr( $nonce, 0, 16 ), $key ),
111
+                "\x00\x00\x00\x00" . self::substr( $nonce, 16, 8 ),
112 112
                 $ic
113 113
             ),
114 114
             $message
Please login to merge, or discard this patch.
Braces   +5 added lines, -10 removed lines patch added patch discarded remove patch
@@ -7,8 +7,7 @@  discard block
 block discarded – undo
7 7
 /**
8 8
  * Class ParagonIE_Sodium_Core_XChaCha20
9 9
  */
10
-class ParagonIE_Sodium_Core_XChaCha20 extends ParagonIE_Sodium_Core_HChaCha20
11
-{
10
+class ParagonIE_Sodium_Core_XChaCha20 extends ParagonIE_Sodium_Core_HChaCha20 {
12 11
     /**
13 12
      * @internal You should not use this directly from another application
14 13
      *
@@ -19,8 +18,7 @@  discard block
 block discarded – undo
19 18
      * @throws SodiumException
20 19
      * @throws TypeError
21 20
      */
22
-    public static function stream($len = 64, $nonce = '', $key = '')
23
-    {
21
+    public static function stream($len = 64, $nonce = '', $key = '') {
24 22
         if (self::strlen($nonce) !== 24) {
25 23
             throw new SodiumException('Nonce must be 24 bytes long');
26 24
         }
@@ -46,8 +44,7 @@  discard block
 block discarded – undo
46 44
      * @throws SodiumException
47 45
      * @throws TypeError
48 46
      */
49
-    public static function ietfStream($len = 64, $nonce = '', $key = '')
50
-    {
47
+    public static function ietfStream($len = 64, $nonce = '', $key = '') {
51 48
         if (self::strlen($nonce) !== 24) {
52 49
             throw new SodiumException('Nonce must be 24 bytes long');
53 50
         }
@@ -74,8 +71,7 @@  discard block
 block discarded – undo
74 71
      * @throws SodiumException
75 72
      * @throws TypeError
76 73
      */
77
-    public static function streamXorIc($message, $nonce = '', $key = '', $ic = '')
78
-    {
74
+    public static function streamXorIc($message, $nonce = '', $key = '', $ic = '') {
79 75
         if (self::strlen($nonce) !== 24) {
80 76
             throw new SodiumException('Nonce must be 24 bytes long');
81 77
         }
@@ -100,8 +96,7 @@  discard block
 block discarded – undo
100 96
      * @throws SodiumException
101 97
      * @throws TypeError
102 98
      */
103
-    public static function ietfStreamXorIc($message, $nonce = '', $key = '', $ic = '')
104
-    {
99
+    public static function ietfStreamXorIc($message, $nonce = '', $key = '', $ic = '') {
105 100
         if (self::strlen($nonce) !== 24) {
106 101
             throw new SodiumException('Nonce must be 24 bytes long');
107 102
         }
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Core/X25519.php 3 patches
Indentation   +316 added lines, -316 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Core_X25519', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -9,319 +9,319 @@  discard block
 block discarded – undo
9 9
  */
10 10
 abstract class ParagonIE_Sodium_Core_X25519 extends ParagonIE_Sodium_Core_Curve25519
11 11
 {
12
-    /**
13
-     * Alters the objects passed to this method in place.
14
-     *
15
-     * @internal You should not use this directly from another application
16
-     *
17
-     * @param ParagonIE_Sodium_Core_Curve25519_Fe $f
18
-     * @param ParagonIE_Sodium_Core_Curve25519_Fe $g
19
-     * @param int $b
20
-     * @return void
21
-     * @psalm-suppress MixedAssignment
22
-     */
23
-    public static function fe_cswap(
24
-        ParagonIE_Sodium_Core_Curve25519_Fe $f,
25
-        ParagonIE_Sodium_Core_Curve25519_Fe $g,
26
-        $b = 0
27
-    ) {
28
-        $f0 = (int) $f[0];
29
-        $f1 = (int) $f[1];
30
-        $f2 = (int) $f[2];
31
-        $f3 = (int) $f[3];
32
-        $f4 = (int) $f[4];
33
-        $f5 = (int) $f[5];
34
-        $f6 = (int) $f[6];
35
-        $f7 = (int) $f[7];
36
-        $f8 = (int) $f[8];
37
-        $f9 = (int) $f[9];
38
-        $g0 = (int) $g[0];
39
-        $g1 = (int) $g[1];
40
-        $g2 = (int) $g[2];
41
-        $g3 = (int) $g[3];
42
-        $g4 = (int) $g[4];
43
-        $g5 = (int) $g[5];
44
-        $g6 = (int) $g[6];
45
-        $g7 = (int) $g[7];
46
-        $g8 = (int) $g[8];
47
-        $g9 = (int) $g[9];
48
-        $b = -$b;
49
-        $x0 = ($f0 ^ $g0) & $b;
50
-        $x1 = ($f1 ^ $g1) & $b;
51
-        $x2 = ($f2 ^ $g2) & $b;
52
-        $x3 = ($f3 ^ $g3) & $b;
53
-        $x4 = ($f4 ^ $g4) & $b;
54
-        $x5 = ($f5 ^ $g5) & $b;
55
-        $x6 = ($f6 ^ $g6) & $b;
56
-        $x7 = ($f7 ^ $g7) & $b;
57
-        $x8 = ($f8 ^ $g8) & $b;
58
-        $x9 = ($f9 ^ $g9) & $b;
59
-        $f[0] = $f0 ^ $x0;
60
-        $f[1] = $f1 ^ $x1;
61
-        $f[2] = $f2 ^ $x2;
62
-        $f[3] = $f3 ^ $x3;
63
-        $f[4] = $f4 ^ $x4;
64
-        $f[5] = $f5 ^ $x5;
65
-        $f[6] = $f6 ^ $x6;
66
-        $f[7] = $f7 ^ $x7;
67
-        $f[8] = $f8 ^ $x8;
68
-        $f[9] = $f9 ^ $x9;
69
-        $g[0] = $g0 ^ $x0;
70
-        $g[1] = $g1 ^ $x1;
71
-        $g[2] = $g2 ^ $x2;
72
-        $g[3] = $g3 ^ $x3;
73
-        $g[4] = $g4 ^ $x4;
74
-        $g[5] = $g5 ^ $x5;
75
-        $g[6] = $g6 ^ $x6;
76
-        $g[7] = $g7 ^ $x7;
77
-        $g[8] = $g8 ^ $x8;
78
-        $g[9] = $g9 ^ $x9;
79
-    }
80
-
81
-    /**
82
-     * @internal You should not use this directly from another application
83
-     *
84
-     * @param ParagonIE_Sodium_Core_Curve25519_Fe $f
85
-     * @return ParagonIE_Sodium_Core_Curve25519_Fe
86
-     */
87
-    public static function fe_mul121666(ParagonIE_Sodium_Core_Curve25519_Fe $f)
88
-    {
89
-        $h = array(
90
-            self::mul((int) $f[0], 121666, 17),
91
-            self::mul((int) $f[1], 121666, 17),
92
-            self::mul((int) $f[2], 121666, 17),
93
-            self::mul((int) $f[3], 121666, 17),
94
-            self::mul((int) $f[4], 121666, 17),
95
-            self::mul((int) $f[5], 121666, 17),
96
-            self::mul((int) $f[6], 121666, 17),
97
-            self::mul((int) $f[7], 121666, 17),
98
-            self::mul((int) $f[8], 121666, 17),
99
-            self::mul((int) $f[9], 121666, 17)
100
-        );
101
-
102
-        /** @var int $carry9 */
103
-        $carry9 = ($h[9] + (1 << 24)) >> 25;
104
-        $h[0] += self::mul($carry9, 19, 5);
105
-        $h[9] -= $carry9 << 25;
106
-        /** @var int $carry1 */
107
-        $carry1 = ($h[1] + (1 << 24)) >> 25;
108
-        $h[2] += $carry1;
109
-        $h[1] -= $carry1 << 25;
110
-        /** @var int $carry3 */
111
-        $carry3 = ($h[3] + (1 << 24)) >> 25;
112
-        $h[4] += $carry3;
113
-        $h[3] -= $carry3 << 25;
114
-        /** @var int $carry5 */
115
-        $carry5 = ($h[5] + (1 << 24)) >> 25;
116
-        $h[6] += $carry5;
117
-        $h[5] -= $carry5 << 25;
118
-        /** @var int $carry7 */
119
-        $carry7 = ($h[7] + (1 << 24)) >> 25;
120
-        $h[8] += $carry7;
121
-        $h[7] -= $carry7 << 25;
122
-
123
-        /** @var int $carry0 */
124
-        $carry0 = ($h[0] + (1 << 25)) >> 26;
125
-        $h[1] += $carry0;
126
-        $h[0] -= $carry0 << 26;
127
-        /** @var int $carry2 */
128
-        $carry2 = ($h[2] + (1 << 25)) >> 26;
129
-        $h[3] += $carry2;
130
-        $h[2] -= $carry2 << 26;
131
-        /** @var int $carry4 */
132
-        $carry4 = ($h[4] + (1 << 25)) >> 26;
133
-        $h[5] += $carry4;
134
-        $h[4] -= $carry4 << 26;
135
-        /** @var int $carry6 */
136
-        $carry6 = ($h[6] + (1 << 25)) >> 26;
137
-        $h[7] += $carry6;
138
-        $h[6] -= $carry6 << 26;
139
-        /** @var int $carry8 */
140
-        $carry8 = ($h[8] + (1 << 25)) >> 26;
141
-        $h[9] += $carry8;
142
-        $h[8] -= $carry8 << 26;
143
-
144
-        foreach ($h as $i => $value) {
145
-            $h[$i] = (int) $value;
146
-        }
147
-        return ParagonIE_Sodium_Core_Curve25519_Fe::fromArray($h);
148
-    }
149
-
150
-    /**
151
-     * @internal You should not use this directly from another application
152
-     *
153
-     * Inline comments preceded by # are from libsodium's ref10 code.
154
-     *
155
-     * @param string $n
156
-     * @param string $p
157
-     * @return string
158
-     * @throws SodiumException
159
-     * @throws TypeError
160
-     */
161
-    public static function crypto_scalarmult_curve25519_ref10($n, $p)
162
-    {
163
-        # for (i = 0;i < 32;++i) e[i] = n[i];
164
-        $e = '' . $n;
165
-        # e[0] &= 248;
166
-        $e[0] = self::intToChr(
167
-            self::chrToInt($e[0]) & 248
168
-        );
169
-        # e[31] &= 127;
170
-        # e[31] |= 64;
171
-        $e[31] = self::intToChr(
172
-            (self::chrToInt($e[31]) & 127) | 64
173
-        );
174
-        # fe_frombytes(x1,p);
175
-        $x1 = self::fe_frombytes($p);
176
-        # fe_1(x2);
177
-        $x2 = self::fe_1();
178
-        # fe_0(z2);
179
-        $z2 = self::fe_0();
180
-        # fe_copy(x3,x1);
181
-        $x3 = self::fe_copy($x1);
182
-        # fe_1(z3);
183
-        $z3 = self::fe_1();
184
-
185
-        # swap = 0;
186
-        /** @var int $swap */
187
-        $swap = 0;
188
-
189
-        # for (pos = 254;pos >= 0;--pos) {
190
-        for ($pos = 254; $pos >= 0; --$pos) {
191
-            # b = e[pos / 8] >> (pos & 7);
192
-            /** @var int $b */
193
-            $b = self::chrToInt(
194
-                    $e[(int) floor($pos / 8)]
195
-                ) >> ($pos & 7);
196
-            # b &= 1;
197
-            $b &= 1;
198
-            # swap ^= b;
199
-            $swap ^= $b;
200
-            # fe_cswap(x2,x3,swap);
201
-            self::fe_cswap($x2, $x3, $swap);
202
-            # fe_cswap(z2,z3,swap);
203
-            self::fe_cswap($z2, $z3, $swap);
204
-            # swap = b;
205
-            $swap = $b;
206
-            # fe_sub(tmp0,x3,z3);
207
-            $tmp0 = self::fe_sub($x3, $z3);
208
-            # fe_sub(tmp1,x2,z2);
209
-            $tmp1 = self::fe_sub($x2, $z2);
210
-
211
-            # fe_add(x2,x2,z2);
212
-            $x2 = self::fe_add($x2, $z2);
213
-
214
-            # fe_add(z2,x3,z3);
215
-            $z2 = self::fe_add($x3, $z3);
216
-
217
-            # fe_mul(z3,tmp0,x2);
218
-            $z3 = self::fe_mul($tmp0, $x2);
219
-
220
-            # fe_mul(z2,z2,tmp1);
221
-            $z2 = self::fe_mul($z2, $tmp1);
222
-
223
-            # fe_sq(tmp0,tmp1);
224
-            $tmp0 = self::fe_sq($tmp1);
225
-
226
-            # fe_sq(tmp1,x2);
227
-            $tmp1 = self::fe_sq($x2);
228
-
229
-            # fe_add(x3,z3,z2);
230
-            $x3 = self::fe_add($z3, $z2);
231
-
232
-            # fe_sub(z2,z3,z2);
233
-            $z2 = self::fe_sub($z3, $z2);
234
-
235
-            # fe_mul(x2,tmp1,tmp0);
236
-            $x2 = self::fe_mul($tmp1, $tmp0);
237
-
238
-            # fe_sub(tmp1,tmp1,tmp0);
239
-            $tmp1 = self::fe_sub($tmp1, $tmp0);
240
-
241
-            # fe_sq(z2,z2);
242
-            $z2 = self::fe_sq($z2);
243
-
244
-            # fe_mul121666(z3,tmp1);
245
-            $z3 = self::fe_mul121666($tmp1);
246
-
247
-            # fe_sq(x3,x3);
248
-            $x3 = self::fe_sq($x3);
249
-
250
-            # fe_add(tmp0,tmp0,z3);
251
-            $tmp0 = self::fe_add($tmp0, $z3);
252
-
253
-            # fe_mul(z3,x1,z2);
254
-            $z3 = self::fe_mul($x1, $z2);
255
-
256
-            # fe_mul(z2,tmp1,tmp0);
257
-            $z2 = self::fe_mul($tmp1, $tmp0);
258
-        }
259
-
260
-        # fe_cswap(x2,x3,swap);
261
-        self::fe_cswap($x2, $x3, $swap);
262
-
263
-        # fe_cswap(z2,z3,swap);
264
-        self::fe_cswap($z2, $z3, $swap);
265
-
266
-        # fe_invert(z2,z2);
267
-        $z2 = self::fe_invert($z2);
268
-
269
-        # fe_mul(x2,x2,z2);
270
-        $x2 = self::fe_mul($x2, $z2);
271
-        # fe_tobytes(q,x2);
272
-        return self::fe_tobytes($x2);
273
-    }
274
-
275
-    /**
276
-     * @internal You should not use this directly from another application
277
-     *
278
-     * @param ParagonIE_Sodium_Core_Curve25519_Fe $edwardsY
279
-     * @param ParagonIE_Sodium_Core_Curve25519_Fe $edwardsZ
280
-     * @return ParagonIE_Sodium_Core_Curve25519_Fe
281
-     */
282
-    public static function edwards_to_montgomery(
283
-        ParagonIE_Sodium_Core_Curve25519_Fe $edwardsY,
284
-        ParagonIE_Sodium_Core_Curve25519_Fe $edwardsZ
285
-    ) {
286
-        $tempX = self::fe_add($edwardsZ, $edwardsY);
287
-        $tempZ = self::fe_sub($edwardsZ, $edwardsY);
288
-        $tempZ = self::fe_invert($tempZ);
289
-        return self::fe_mul($tempX, $tempZ);
290
-    }
291
-
292
-    /**
293
-     * @internal You should not use this directly from another application
294
-     *
295
-     * @param string $n
296
-     * @return string
297
-     * @throws SodiumException
298
-     * @throws TypeError
299
-     */
300
-    public static function crypto_scalarmult_curve25519_ref10_base($n)
301
-    {
302
-        # for (i = 0;i < 32;++i) e[i] = n[i];
303
-        $e = '' . $n;
304
-
305
-        # e[0] &= 248;
306
-        $e[0] = self::intToChr(
307
-            self::chrToInt($e[0]) & 248
308
-        );
309
-
310
-        # e[31] &= 127;
311
-        # e[31] |= 64;
312
-        $e[31] = self::intToChr(
313
-            (self::chrToInt($e[31]) & 127) | 64
314
-        );
315
-
316
-        $A = self::ge_scalarmult_base($e);
317
-        if (
318
-            !($A->Y instanceof ParagonIE_Sodium_Core_Curve25519_Fe)
319
-                ||
320
-            !($A->Z instanceof ParagonIE_Sodium_Core_Curve25519_Fe)
321
-        ) {
322
-            throw new TypeError('Null points encountered');
323
-        }
324
-        $pk = self::edwards_to_montgomery($A->Y, $A->Z);
325
-        return self::fe_tobytes($pk);
326
-    }
12
+	/**
13
+	 * Alters the objects passed to this method in place.
14
+	 *
15
+	 * @internal You should not use this directly from another application
16
+	 *
17
+	 * @param ParagonIE_Sodium_Core_Curve25519_Fe $f
18
+	 * @param ParagonIE_Sodium_Core_Curve25519_Fe $g
19
+	 * @param int $b
20
+	 * @return void
21
+	 * @psalm-suppress MixedAssignment
22
+	 */
23
+	public static function fe_cswap(
24
+		ParagonIE_Sodium_Core_Curve25519_Fe $f,
25
+		ParagonIE_Sodium_Core_Curve25519_Fe $g,
26
+		$b = 0
27
+	) {
28
+		$f0 = (int) $f[0];
29
+		$f1 = (int) $f[1];
30
+		$f2 = (int) $f[2];
31
+		$f3 = (int) $f[3];
32
+		$f4 = (int) $f[4];
33
+		$f5 = (int) $f[5];
34
+		$f6 = (int) $f[6];
35
+		$f7 = (int) $f[7];
36
+		$f8 = (int) $f[8];
37
+		$f9 = (int) $f[9];
38
+		$g0 = (int) $g[0];
39
+		$g1 = (int) $g[1];
40
+		$g2 = (int) $g[2];
41
+		$g3 = (int) $g[3];
42
+		$g4 = (int) $g[4];
43
+		$g5 = (int) $g[5];
44
+		$g6 = (int) $g[6];
45
+		$g7 = (int) $g[7];
46
+		$g8 = (int) $g[8];
47
+		$g9 = (int) $g[9];
48
+		$b = -$b;
49
+		$x0 = ($f0 ^ $g0) & $b;
50
+		$x1 = ($f1 ^ $g1) & $b;
51
+		$x2 = ($f2 ^ $g2) & $b;
52
+		$x3 = ($f3 ^ $g3) & $b;
53
+		$x4 = ($f4 ^ $g4) & $b;
54
+		$x5 = ($f5 ^ $g5) & $b;
55
+		$x6 = ($f6 ^ $g6) & $b;
56
+		$x7 = ($f7 ^ $g7) & $b;
57
+		$x8 = ($f8 ^ $g8) & $b;
58
+		$x9 = ($f9 ^ $g9) & $b;
59
+		$f[0] = $f0 ^ $x0;
60
+		$f[1] = $f1 ^ $x1;
61
+		$f[2] = $f2 ^ $x2;
62
+		$f[3] = $f3 ^ $x3;
63
+		$f[4] = $f4 ^ $x4;
64
+		$f[5] = $f5 ^ $x5;
65
+		$f[6] = $f6 ^ $x6;
66
+		$f[7] = $f7 ^ $x7;
67
+		$f[8] = $f8 ^ $x8;
68
+		$f[9] = $f9 ^ $x9;
69
+		$g[0] = $g0 ^ $x0;
70
+		$g[1] = $g1 ^ $x1;
71
+		$g[2] = $g2 ^ $x2;
72
+		$g[3] = $g3 ^ $x3;
73
+		$g[4] = $g4 ^ $x4;
74
+		$g[5] = $g5 ^ $x5;
75
+		$g[6] = $g6 ^ $x6;
76
+		$g[7] = $g7 ^ $x7;
77
+		$g[8] = $g8 ^ $x8;
78
+		$g[9] = $g9 ^ $x9;
79
+	}
80
+
81
+	/**
82
+	 * @internal You should not use this directly from another application
83
+	 *
84
+	 * @param ParagonIE_Sodium_Core_Curve25519_Fe $f
85
+	 * @return ParagonIE_Sodium_Core_Curve25519_Fe
86
+	 */
87
+	public static function fe_mul121666(ParagonIE_Sodium_Core_Curve25519_Fe $f)
88
+	{
89
+		$h = array(
90
+			self::mul((int) $f[0], 121666, 17),
91
+			self::mul((int) $f[1], 121666, 17),
92
+			self::mul((int) $f[2], 121666, 17),
93
+			self::mul((int) $f[3], 121666, 17),
94
+			self::mul((int) $f[4], 121666, 17),
95
+			self::mul((int) $f[5], 121666, 17),
96
+			self::mul((int) $f[6], 121666, 17),
97
+			self::mul((int) $f[7], 121666, 17),
98
+			self::mul((int) $f[8], 121666, 17),
99
+			self::mul((int) $f[9], 121666, 17)
100
+		);
101
+
102
+		/** @var int $carry9 */
103
+		$carry9 = ($h[9] + (1 << 24)) >> 25;
104
+		$h[0] += self::mul($carry9, 19, 5);
105
+		$h[9] -= $carry9 << 25;
106
+		/** @var int $carry1 */
107
+		$carry1 = ($h[1] + (1 << 24)) >> 25;
108
+		$h[2] += $carry1;
109
+		$h[1] -= $carry1 << 25;
110
+		/** @var int $carry3 */
111
+		$carry3 = ($h[3] + (1 << 24)) >> 25;
112
+		$h[4] += $carry3;
113
+		$h[3] -= $carry3 << 25;
114
+		/** @var int $carry5 */
115
+		$carry5 = ($h[5] + (1 << 24)) >> 25;
116
+		$h[6] += $carry5;
117
+		$h[5] -= $carry5 << 25;
118
+		/** @var int $carry7 */
119
+		$carry7 = ($h[7] + (1 << 24)) >> 25;
120
+		$h[8] += $carry7;
121
+		$h[7] -= $carry7 << 25;
122
+
123
+		/** @var int $carry0 */
124
+		$carry0 = ($h[0] + (1 << 25)) >> 26;
125
+		$h[1] += $carry0;
126
+		$h[0] -= $carry0 << 26;
127
+		/** @var int $carry2 */
128
+		$carry2 = ($h[2] + (1 << 25)) >> 26;
129
+		$h[3] += $carry2;
130
+		$h[2] -= $carry2 << 26;
131
+		/** @var int $carry4 */
132
+		$carry4 = ($h[4] + (1 << 25)) >> 26;
133
+		$h[5] += $carry4;
134
+		$h[4] -= $carry4 << 26;
135
+		/** @var int $carry6 */
136
+		$carry6 = ($h[6] + (1 << 25)) >> 26;
137
+		$h[7] += $carry6;
138
+		$h[6] -= $carry6 << 26;
139
+		/** @var int $carry8 */
140
+		$carry8 = ($h[8] + (1 << 25)) >> 26;
141
+		$h[9] += $carry8;
142
+		$h[8] -= $carry8 << 26;
143
+
144
+		foreach ($h as $i => $value) {
145
+			$h[$i] = (int) $value;
146
+		}
147
+		return ParagonIE_Sodium_Core_Curve25519_Fe::fromArray($h);
148
+	}
149
+
150
+	/**
151
+	 * @internal You should not use this directly from another application
152
+	 *
153
+	 * Inline comments preceded by # are from libsodium's ref10 code.
154
+	 *
155
+	 * @param string $n
156
+	 * @param string $p
157
+	 * @return string
158
+	 * @throws SodiumException
159
+	 * @throws TypeError
160
+	 */
161
+	public static function crypto_scalarmult_curve25519_ref10($n, $p)
162
+	{
163
+		# for (i = 0;i < 32;++i) e[i] = n[i];
164
+		$e = '' . $n;
165
+		# e[0] &= 248;
166
+		$e[0] = self::intToChr(
167
+			self::chrToInt($e[0]) & 248
168
+		);
169
+		# e[31] &= 127;
170
+		# e[31] |= 64;
171
+		$e[31] = self::intToChr(
172
+			(self::chrToInt($e[31]) & 127) | 64
173
+		);
174
+		# fe_frombytes(x1,p);
175
+		$x1 = self::fe_frombytes($p);
176
+		# fe_1(x2);
177
+		$x2 = self::fe_1();
178
+		# fe_0(z2);
179
+		$z2 = self::fe_0();
180
+		# fe_copy(x3,x1);
181
+		$x3 = self::fe_copy($x1);
182
+		# fe_1(z3);
183
+		$z3 = self::fe_1();
184
+
185
+		# swap = 0;
186
+		/** @var int $swap */
187
+		$swap = 0;
188
+
189
+		# for (pos = 254;pos >= 0;--pos) {
190
+		for ($pos = 254; $pos >= 0; --$pos) {
191
+			# b = e[pos / 8] >> (pos & 7);
192
+			/** @var int $b */
193
+			$b = self::chrToInt(
194
+					$e[(int) floor($pos / 8)]
195
+				) >> ($pos & 7);
196
+			# b &= 1;
197
+			$b &= 1;
198
+			# swap ^= b;
199
+			$swap ^= $b;
200
+			# fe_cswap(x2,x3,swap);
201
+			self::fe_cswap($x2, $x3, $swap);
202
+			# fe_cswap(z2,z3,swap);
203
+			self::fe_cswap($z2, $z3, $swap);
204
+			# swap = b;
205
+			$swap = $b;
206
+			# fe_sub(tmp0,x3,z3);
207
+			$tmp0 = self::fe_sub($x3, $z3);
208
+			# fe_sub(tmp1,x2,z2);
209
+			$tmp1 = self::fe_sub($x2, $z2);
210
+
211
+			# fe_add(x2,x2,z2);
212
+			$x2 = self::fe_add($x2, $z2);
213
+
214
+			# fe_add(z2,x3,z3);
215
+			$z2 = self::fe_add($x3, $z3);
216
+
217
+			# fe_mul(z3,tmp0,x2);
218
+			$z3 = self::fe_mul($tmp0, $x2);
219
+
220
+			# fe_mul(z2,z2,tmp1);
221
+			$z2 = self::fe_mul($z2, $tmp1);
222
+
223
+			# fe_sq(tmp0,tmp1);
224
+			$tmp0 = self::fe_sq($tmp1);
225
+
226
+			# fe_sq(tmp1,x2);
227
+			$tmp1 = self::fe_sq($x2);
228
+
229
+			# fe_add(x3,z3,z2);
230
+			$x3 = self::fe_add($z3, $z2);
231
+
232
+			# fe_sub(z2,z3,z2);
233
+			$z2 = self::fe_sub($z3, $z2);
234
+
235
+			# fe_mul(x2,tmp1,tmp0);
236
+			$x2 = self::fe_mul($tmp1, $tmp0);
237
+
238
+			# fe_sub(tmp1,tmp1,tmp0);
239
+			$tmp1 = self::fe_sub($tmp1, $tmp0);
240
+
241
+			# fe_sq(z2,z2);
242
+			$z2 = self::fe_sq($z2);
243
+
244
+			# fe_mul121666(z3,tmp1);
245
+			$z3 = self::fe_mul121666($tmp1);
246
+
247
+			# fe_sq(x3,x3);
248
+			$x3 = self::fe_sq($x3);
249
+
250
+			# fe_add(tmp0,tmp0,z3);
251
+			$tmp0 = self::fe_add($tmp0, $z3);
252
+
253
+			# fe_mul(z3,x1,z2);
254
+			$z3 = self::fe_mul($x1, $z2);
255
+
256
+			# fe_mul(z2,tmp1,tmp0);
257
+			$z2 = self::fe_mul($tmp1, $tmp0);
258
+		}
259
+
260
+		# fe_cswap(x2,x3,swap);
261
+		self::fe_cswap($x2, $x3, $swap);
262
+
263
+		# fe_cswap(z2,z3,swap);
264
+		self::fe_cswap($z2, $z3, $swap);
265
+
266
+		# fe_invert(z2,z2);
267
+		$z2 = self::fe_invert($z2);
268
+
269
+		# fe_mul(x2,x2,z2);
270
+		$x2 = self::fe_mul($x2, $z2);
271
+		# fe_tobytes(q,x2);
272
+		return self::fe_tobytes($x2);
273
+	}
274
+
275
+	/**
276
+	 * @internal You should not use this directly from another application
277
+	 *
278
+	 * @param ParagonIE_Sodium_Core_Curve25519_Fe $edwardsY
279
+	 * @param ParagonIE_Sodium_Core_Curve25519_Fe $edwardsZ
280
+	 * @return ParagonIE_Sodium_Core_Curve25519_Fe
281
+	 */
282
+	public static function edwards_to_montgomery(
283
+		ParagonIE_Sodium_Core_Curve25519_Fe $edwardsY,
284
+		ParagonIE_Sodium_Core_Curve25519_Fe $edwardsZ
285
+	) {
286
+		$tempX = self::fe_add($edwardsZ, $edwardsY);
287
+		$tempZ = self::fe_sub($edwardsZ, $edwardsY);
288
+		$tempZ = self::fe_invert($tempZ);
289
+		return self::fe_mul($tempX, $tempZ);
290
+	}
291
+
292
+	/**
293
+	 * @internal You should not use this directly from another application
294
+	 *
295
+	 * @param string $n
296
+	 * @return string
297
+	 * @throws SodiumException
298
+	 * @throws TypeError
299
+	 */
300
+	public static function crypto_scalarmult_curve25519_ref10_base($n)
301
+	{
302
+		# for (i = 0;i < 32;++i) e[i] = n[i];
303
+		$e = '' . $n;
304
+
305
+		# e[0] &= 248;
306
+		$e[0] = self::intToChr(
307
+			self::chrToInt($e[0]) & 248
308
+		);
309
+
310
+		# e[31] &= 127;
311
+		# e[31] |= 64;
312
+		$e[31] = self::intToChr(
313
+			(self::chrToInt($e[31]) & 127) | 64
314
+		);
315
+
316
+		$A = self::ge_scalarmult_base($e);
317
+		if (
318
+			!($A->Y instanceof ParagonIE_Sodium_Core_Curve25519_Fe)
319
+				||
320
+			!($A->Z instanceof ParagonIE_Sodium_Core_Curve25519_Fe)
321
+		) {
322
+			throw new TypeError('Null points encountered');
323
+		}
324
+		$pk = self::edwards_to_montgomery($A->Y, $A->Z);
325
+		return self::fe_tobytes($pk);
326
+	}
327 327
 }
Please login to merge, or discard this patch.
Spacing   +145 added lines, -145 removed lines patch added patch discarded remove patch
@@ -1,6 +1,6 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3
-if (class_exists('ParagonIE_Sodium_Core_X25519', false)) {
3
+if ( class_exists( 'ParagonIE_Sodium_Core_X25519', false ) ) {
4 4
     return;
5 5
 }
6 6
 
@@ -25,57 +25,57 @@  discard block
 block discarded – undo
25 25
         ParagonIE_Sodium_Core_Curve25519_Fe $g,
26 26
         $b = 0
27 27
     ) {
28
-        $f0 = (int) $f[0];
29
-        $f1 = (int) $f[1];
30
-        $f2 = (int) $f[2];
31
-        $f3 = (int) $f[3];
32
-        $f4 = (int) $f[4];
33
-        $f5 = (int) $f[5];
34
-        $f6 = (int) $f[6];
35
-        $f7 = (int) $f[7];
36
-        $f8 = (int) $f[8];
37
-        $f9 = (int) $f[9];
38
-        $g0 = (int) $g[0];
39
-        $g1 = (int) $g[1];
40
-        $g2 = (int) $g[2];
41
-        $g3 = (int) $g[3];
42
-        $g4 = (int) $g[4];
43
-        $g5 = (int) $g[5];
44
-        $g6 = (int) $g[6];
45
-        $g7 = (int) $g[7];
46
-        $g8 = (int) $g[8];
47
-        $g9 = (int) $g[9];
28
+        $f0 = (int)$f[ 0 ];
29
+        $f1 = (int)$f[ 1 ];
30
+        $f2 = (int)$f[ 2 ];
31
+        $f3 = (int)$f[ 3 ];
32
+        $f4 = (int)$f[ 4 ];
33
+        $f5 = (int)$f[ 5 ];
34
+        $f6 = (int)$f[ 6 ];
35
+        $f7 = (int)$f[ 7 ];
36
+        $f8 = (int)$f[ 8 ];
37
+        $f9 = (int)$f[ 9 ];
38
+        $g0 = (int)$g[ 0 ];
39
+        $g1 = (int)$g[ 1 ];
40
+        $g2 = (int)$g[ 2 ];
41
+        $g3 = (int)$g[ 3 ];
42
+        $g4 = (int)$g[ 4 ];
43
+        $g5 = (int)$g[ 5 ];
44
+        $g6 = (int)$g[ 6 ];
45
+        $g7 = (int)$g[ 7 ];
46
+        $g8 = (int)$g[ 8 ];
47
+        $g9 = (int)$g[ 9 ];
48 48
         $b = -$b;
49
-        $x0 = ($f0 ^ $g0) & $b;
50
-        $x1 = ($f1 ^ $g1) & $b;
51
-        $x2 = ($f2 ^ $g2) & $b;
52
-        $x3 = ($f3 ^ $g3) & $b;
53
-        $x4 = ($f4 ^ $g4) & $b;
54
-        $x5 = ($f5 ^ $g5) & $b;
55
-        $x6 = ($f6 ^ $g6) & $b;
56
-        $x7 = ($f7 ^ $g7) & $b;
57
-        $x8 = ($f8 ^ $g8) & $b;
58
-        $x9 = ($f9 ^ $g9) & $b;
59
-        $f[0] = $f0 ^ $x0;
60
-        $f[1] = $f1 ^ $x1;
61
-        $f[2] = $f2 ^ $x2;
62
-        $f[3] = $f3 ^ $x3;
63
-        $f[4] = $f4 ^ $x4;
64
-        $f[5] = $f5 ^ $x5;
65
-        $f[6] = $f6 ^ $x6;
66
-        $f[7] = $f7 ^ $x7;
67
-        $f[8] = $f8 ^ $x8;
68
-        $f[9] = $f9 ^ $x9;
69
-        $g[0] = $g0 ^ $x0;
70
-        $g[1] = $g1 ^ $x1;
71
-        $g[2] = $g2 ^ $x2;
72
-        $g[3] = $g3 ^ $x3;
73
-        $g[4] = $g4 ^ $x4;
74
-        $g[5] = $g5 ^ $x5;
75
-        $g[6] = $g6 ^ $x6;
76
-        $g[7] = $g7 ^ $x7;
77
-        $g[8] = $g8 ^ $x8;
78
-        $g[9] = $g9 ^ $x9;
49
+        $x0 = ( $f0 ^ $g0 ) & $b;
50
+        $x1 = ( $f1 ^ $g1 ) & $b;
51
+        $x2 = ( $f2 ^ $g2 ) & $b;
52
+        $x3 = ( $f3 ^ $g3 ) & $b;
53
+        $x4 = ( $f4 ^ $g4 ) & $b;
54
+        $x5 = ( $f5 ^ $g5 ) & $b;
55
+        $x6 = ( $f6 ^ $g6 ) & $b;
56
+        $x7 = ( $f7 ^ $g7 ) & $b;
57
+        $x8 = ( $f8 ^ $g8 ) & $b;
58
+        $x9 = ( $f9 ^ $g9 ) & $b;
59
+        $f[ 0 ] = $f0 ^ $x0;
60
+        $f[ 1 ] = $f1 ^ $x1;
61
+        $f[ 2 ] = $f2 ^ $x2;
62
+        $f[ 3 ] = $f3 ^ $x3;
63
+        $f[ 4 ] = $f4 ^ $x4;
64
+        $f[ 5 ] = $f5 ^ $x5;
65
+        $f[ 6 ] = $f6 ^ $x6;
66
+        $f[ 7 ] = $f7 ^ $x7;
67
+        $f[ 8 ] = $f8 ^ $x8;
68
+        $f[ 9 ] = $f9 ^ $x9;
69
+        $g[ 0 ] = $g0 ^ $x0;
70
+        $g[ 1 ] = $g1 ^ $x1;
71
+        $g[ 2 ] = $g2 ^ $x2;
72
+        $g[ 3 ] = $g3 ^ $x3;
73
+        $g[ 4 ] = $g4 ^ $x4;
74
+        $g[ 5 ] = $g5 ^ $x5;
75
+        $g[ 6 ] = $g6 ^ $x6;
76
+        $g[ 7 ] = $g7 ^ $x7;
77
+        $g[ 8 ] = $g8 ^ $x8;
78
+        $g[ 9 ] = $g9 ^ $x9;
79 79
     }
80 80
 
81 81
     /**
@@ -84,67 +84,67 @@  discard block
 block discarded – undo
84 84
      * @param ParagonIE_Sodium_Core_Curve25519_Fe $f
85 85
      * @return ParagonIE_Sodium_Core_Curve25519_Fe
86 86
      */
87
-    public static function fe_mul121666(ParagonIE_Sodium_Core_Curve25519_Fe $f)
87
+    public static function fe_mul121666( ParagonIE_Sodium_Core_Curve25519_Fe $f )
88 88
     {
89 89
         $h = array(
90
-            self::mul((int) $f[0], 121666, 17),
91
-            self::mul((int) $f[1], 121666, 17),
92
-            self::mul((int) $f[2], 121666, 17),
93
-            self::mul((int) $f[3], 121666, 17),
94
-            self::mul((int) $f[4], 121666, 17),
95
-            self::mul((int) $f[5], 121666, 17),
96
-            self::mul((int) $f[6], 121666, 17),
97
-            self::mul((int) $f[7], 121666, 17),
98
-            self::mul((int) $f[8], 121666, 17),
99
-            self::mul((int) $f[9], 121666, 17)
90
+            self::mul( (int)$f[ 0 ], 121666, 17 ),
91
+            self::mul( (int)$f[ 1 ], 121666, 17 ),
92
+            self::mul( (int)$f[ 2 ], 121666, 17 ),
93
+            self::mul( (int)$f[ 3 ], 121666, 17 ),
94
+            self::mul( (int)$f[ 4 ], 121666, 17 ),
95
+            self::mul( (int)$f[ 5 ], 121666, 17 ),
96
+            self::mul( (int)$f[ 6 ], 121666, 17 ),
97
+            self::mul( (int)$f[ 7 ], 121666, 17 ),
98
+            self::mul( (int)$f[ 8 ], 121666, 17 ),
99
+            self::mul( (int)$f[ 9 ], 121666, 17 )
100 100
         );
101 101
 
102 102
         /** @var int $carry9 */
103
-        $carry9 = ($h[9] + (1 << 24)) >> 25;
104
-        $h[0] += self::mul($carry9, 19, 5);
105
-        $h[9] -= $carry9 << 25;
103
+        $carry9 = ( $h[ 9 ] + ( 1 << 24 ) ) >> 25;
104
+        $h[ 0 ] += self::mul( $carry9, 19, 5 );
105
+        $h[ 9 ] -= $carry9 << 25;
106 106
         /** @var int $carry1 */
107
-        $carry1 = ($h[1] + (1 << 24)) >> 25;
108
-        $h[2] += $carry1;
109
-        $h[1] -= $carry1 << 25;
107
+        $carry1 = ( $h[ 1 ] + ( 1 << 24 ) ) >> 25;
108
+        $h[ 2 ] += $carry1;
109
+        $h[ 1 ] -= $carry1 << 25;
110 110
         /** @var int $carry3 */
111
-        $carry3 = ($h[3] + (1 << 24)) >> 25;
112
-        $h[4] += $carry3;
113
-        $h[3] -= $carry3 << 25;
111
+        $carry3 = ( $h[ 3 ] + ( 1 << 24 ) ) >> 25;
112
+        $h[ 4 ] += $carry3;
113
+        $h[ 3 ] -= $carry3 << 25;
114 114
         /** @var int $carry5 */
115
-        $carry5 = ($h[5] + (1 << 24)) >> 25;
116
-        $h[6] += $carry5;
117
-        $h[5] -= $carry5 << 25;
115
+        $carry5 = ( $h[ 5 ] + ( 1 << 24 ) ) >> 25;
116
+        $h[ 6 ] += $carry5;
117
+        $h[ 5 ] -= $carry5 << 25;
118 118
         /** @var int $carry7 */
119
-        $carry7 = ($h[7] + (1 << 24)) >> 25;
120
-        $h[8] += $carry7;
121
-        $h[7] -= $carry7 << 25;
119
+        $carry7 = ( $h[ 7 ] + ( 1 << 24 ) ) >> 25;
120
+        $h[ 8 ] += $carry7;
121
+        $h[ 7 ] -= $carry7 << 25;
122 122
 
123 123
         /** @var int $carry0 */
124
-        $carry0 = ($h[0] + (1 << 25)) >> 26;
125
-        $h[1] += $carry0;
126
-        $h[0] -= $carry0 << 26;
124
+        $carry0 = ( $h[ 0 ] + ( 1 << 25 ) ) >> 26;
125
+        $h[ 1 ] += $carry0;
126
+        $h[ 0 ] -= $carry0 << 26;
127 127
         /** @var int $carry2 */
128
-        $carry2 = ($h[2] + (1 << 25)) >> 26;
129
-        $h[3] += $carry2;
130
-        $h[2] -= $carry2 << 26;
128
+        $carry2 = ( $h[ 2 ] + ( 1 << 25 ) ) >> 26;
129
+        $h[ 3 ] += $carry2;
130
+        $h[ 2 ] -= $carry2 << 26;
131 131
         /** @var int $carry4 */
132
-        $carry4 = ($h[4] + (1 << 25)) >> 26;
133
-        $h[5] += $carry4;
134
-        $h[4] -= $carry4 << 26;
132
+        $carry4 = ( $h[ 4 ] + ( 1 << 25 ) ) >> 26;
133
+        $h[ 5 ] += $carry4;
134
+        $h[ 4 ] -= $carry4 << 26;
135 135
         /** @var int $carry6 */
136
-        $carry6 = ($h[6] + (1 << 25)) >> 26;
137
-        $h[7] += $carry6;
138
-        $h[6] -= $carry6 << 26;
136
+        $carry6 = ( $h[ 6 ] + ( 1 << 25 ) ) >> 26;
137
+        $h[ 7 ] += $carry6;
138
+        $h[ 6 ] -= $carry6 << 26;
139 139
         /** @var int $carry8 */
140
-        $carry8 = ($h[8] + (1 << 25)) >> 26;
141
-        $h[9] += $carry8;
142
-        $h[8] -= $carry8 << 26;
140
+        $carry8 = ( $h[ 8 ] + ( 1 << 25 ) ) >> 26;
141
+        $h[ 9 ] += $carry8;
142
+        $h[ 8 ] -= $carry8 << 26;
143 143
 
144
-        foreach ($h as $i => $value) {
145
-            $h[$i] = (int) $value;
144
+        foreach ( $h as $i => $value ) {
145
+            $h[ $i ] = (int)$value;
146 146
         }
147
-        return ParagonIE_Sodium_Core_Curve25519_Fe::fromArray($h);
147
+        return ParagonIE_Sodium_Core_Curve25519_Fe::fromArray( $h );
148 148
     }
149 149
 
150 150
     /**
@@ -158,27 +158,27 @@  discard block
 block discarded – undo
158 158
      * @throws SodiumException
159 159
      * @throws TypeError
160 160
      */
161
-    public static function crypto_scalarmult_curve25519_ref10($n, $p)
161
+    public static function crypto_scalarmult_curve25519_ref10( $n, $p )
162 162
     {
163 163
         # for (i = 0;i < 32;++i) e[i] = n[i];
164 164
         $e = '' . $n;
165 165
         # e[0] &= 248;
166
-        $e[0] = self::intToChr(
167
-            self::chrToInt($e[0]) & 248
166
+        $e[ 0 ] = self::intToChr(
167
+            self::chrToInt( $e[ 0 ] ) & 248
168 168
         );
169 169
         # e[31] &= 127;
170 170
         # e[31] |= 64;
171
-        $e[31] = self::intToChr(
172
-            (self::chrToInt($e[31]) & 127) | 64
171
+        $e[ 31 ] = self::intToChr(
172
+            ( self::chrToInt( $e[ 31 ] ) & 127 ) | 64
173 173
         );
174 174
         # fe_frombytes(x1,p);
175
-        $x1 = self::fe_frombytes($p);
175
+        $x1 = self::fe_frombytes( $p );
176 176
         # fe_1(x2);
177 177
         $x2 = self::fe_1();
178 178
         # fe_0(z2);
179 179
         $z2 = self::fe_0();
180 180
         # fe_copy(x3,x1);
181
-        $x3 = self::fe_copy($x1);
181
+        $x3 = self::fe_copy( $x1 );
182 182
         # fe_1(z3);
183 183
         $z3 = self::fe_1();
184 184
 
@@ -187,89 +187,89 @@  discard block
 block discarded – undo
187 187
         $swap = 0;
188 188
 
189 189
         # for (pos = 254;pos >= 0;--pos) {
190
-        for ($pos = 254; $pos >= 0; --$pos) {
190
+        for ( $pos = 254; $pos >= 0; --$pos ) {
191 191
             # b = e[pos / 8] >> (pos & 7);
192 192
             /** @var int $b */
193 193
             $b = self::chrToInt(
194
-                    $e[(int) floor($pos / 8)]
195
-                ) >> ($pos & 7);
194
+                    $e[ (int)floor( $pos / 8 ) ]
195
+                ) >> ( $pos & 7 );
196 196
             # b &= 1;
197 197
             $b &= 1;
198 198
             # swap ^= b;
199 199
             $swap ^= $b;
200 200
             # fe_cswap(x2,x3,swap);
201
-            self::fe_cswap($x2, $x3, $swap);
201
+            self::fe_cswap( $x2, $x3, $swap );
202 202
             # fe_cswap(z2,z3,swap);
203
-            self::fe_cswap($z2, $z3, $swap);
203
+            self::fe_cswap( $z2, $z3, $swap );
204 204
             # swap = b;
205 205
             $swap = $b;
206 206
             # fe_sub(tmp0,x3,z3);
207
-            $tmp0 = self::fe_sub($x3, $z3);
207
+            $tmp0 = self::fe_sub( $x3, $z3 );
208 208
             # fe_sub(tmp1,x2,z2);
209
-            $tmp1 = self::fe_sub($x2, $z2);
209
+            $tmp1 = self::fe_sub( $x2, $z2 );
210 210
 
211 211
             # fe_add(x2,x2,z2);
212
-            $x2 = self::fe_add($x2, $z2);
212
+            $x2 = self::fe_add( $x2, $z2 );
213 213
 
214 214
             # fe_add(z2,x3,z3);
215
-            $z2 = self::fe_add($x3, $z3);
215
+            $z2 = self::fe_add( $x3, $z3 );
216 216
 
217 217
             # fe_mul(z3,tmp0,x2);
218
-            $z3 = self::fe_mul($tmp0, $x2);
218
+            $z3 = self::fe_mul( $tmp0, $x2 );
219 219
 
220 220
             # fe_mul(z2,z2,tmp1);
221
-            $z2 = self::fe_mul($z2, $tmp1);
221
+            $z2 = self::fe_mul( $z2, $tmp1 );
222 222
 
223 223
             # fe_sq(tmp0,tmp1);
224
-            $tmp0 = self::fe_sq($tmp1);
224
+            $tmp0 = self::fe_sq( $tmp1 );
225 225
 
226 226
             # fe_sq(tmp1,x2);
227
-            $tmp1 = self::fe_sq($x2);
227
+            $tmp1 = self::fe_sq( $x2 );
228 228
 
229 229
             # fe_add(x3,z3,z2);
230
-            $x3 = self::fe_add($z3, $z2);
230
+            $x3 = self::fe_add( $z3, $z2 );
231 231
 
232 232
             # fe_sub(z2,z3,z2);
233
-            $z2 = self::fe_sub($z3, $z2);
233
+            $z2 = self::fe_sub( $z3, $z2 );
234 234
 
235 235
             # fe_mul(x2,tmp1,tmp0);
236
-            $x2 = self::fe_mul($tmp1, $tmp0);
236
+            $x2 = self::fe_mul( $tmp1, $tmp0 );
237 237
 
238 238
             # fe_sub(tmp1,tmp1,tmp0);
239
-            $tmp1 = self::fe_sub($tmp1, $tmp0);
239
+            $tmp1 = self::fe_sub( $tmp1, $tmp0 );
240 240
 
241 241
             # fe_sq(z2,z2);
242
-            $z2 = self::fe_sq($z2);
242
+            $z2 = self::fe_sq( $z2 );
243 243
 
244 244
             # fe_mul121666(z3,tmp1);
245
-            $z3 = self::fe_mul121666($tmp1);
245
+            $z3 = self::fe_mul121666( $tmp1 );
246 246
 
247 247
             # fe_sq(x3,x3);
248
-            $x3 = self::fe_sq($x3);
248
+            $x3 = self::fe_sq( $x3 );
249 249
 
250 250
             # fe_add(tmp0,tmp0,z3);
251
-            $tmp0 = self::fe_add($tmp0, $z3);
251
+            $tmp0 = self::fe_add( $tmp0, $z3 );
252 252
 
253 253
             # fe_mul(z3,x1,z2);
254
-            $z3 = self::fe_mul($x1, $z2);
254
+            $z3 = self::fe_mul( $x1, $z2 );
255 255
 
256 256
             # fe_mul(z2,tmp1,tmp0);
257
-            $z2 = self::fe_mul($tmp1, $tmp0);
257
+            $z2 = self::fe_mul( $tmp1, $tmp0 );
258 258
         }
259 259
 
260 260
         # fe_cswap(x2,x3,swap);
261
-        self::fe_cswap($x2, $x3, $swap);
261
+        self::fe_cswap( $x2, $x3, $swap );
262 262
 
263 263
         # fe_cswap(z2,z3,swap);
264
-        self::fe_cswap($z2, $z3, $swap);
264
+        self::fe_cswap( $z2, $z3, $swap );
265 265
 
266 266
         # fe_invert(z2,z2);
267
-        $z2 = self::fe_invert($z2);
267
+        $z2 = self::fe_invert( $z2 );
268 268
 
269 269
         # fe_mul(x2,x2,z2);
270
-        $x2 = self::fe_mul($x2, $z2);
270
+        $x2 = self::fe_mul( $x2, $z2 );
271 271
         # fe_tobytes(q,x2);
272
-        return self::fe_tobytes($x2);
272
+        return self::fe_tobytes( $x2 );
273 273
     }
274 274
 
275 275
     /**
@@ -283,10 +283,10 @@  discard block
 block discarded – undo
283 283
         ParagonIE_Sodium_Core_Curve25519_Fe $edwardsY,
284 284
         ParagonIE_Sodium_Core_Curve25519_Fe $edwardsZ
285 285
     ) {
286
-        $tempX = self::fe_add($edwardsZ, $edwardsY);
287
-        $tempZ = self::fe_sub($edwardsZ, $edwardsY);
288
-        $tempZ = self::fe_invert($tempZ);
289
-        return self::fe_mul($tempX, $tempZ);
286
+        $tempX = self::fe_add( $edwardsZ, $edwardsY );
287
+        $tempZ = self::fe_sub( $edwardsZ, $edwardsY );
288
+        $tempZ = self::fe_invert( $tempZ );
289
+        return self::fe_mul( $tempX, $tempZ );
290 290
     }
291 291
 
292 292
     /**
@@ -297,31 +297,31 @@  discard block
 block discarded – undo
297 297
      * @throws SodiumException
298 298
      * @throws TypeError
299 299
      */
300
-    public static function crypto_scalarmult_curve25519_ref10_base($n)
300
+    public static function crypto_scalarmult_curve25519_ref10_base( $n )
301 301
     {
302 302
         # for (i = 0;i < 32;++i) e[i] = n[i];
303 303
         $e = '' . $n;
304 304
 
305 305
         # e[0] &= 248;
306
-        $e[0] = self::intToChr(
307
-            self::chrToInt($e[0]) & 248
306
+        $e[ 0 ] = self::intToChr(
307
+            self::chrToInt( $e[ 0 ] ) & 248
308 308
         );
309 309
 
310 310
         # e[31] &= 127;
311 311
         # e[31] |= 64;
312
-        $e[31] = self::intToChr(
313
-            (self::chrToInt($e[31]) & 127) | 64
312
+        $e[ 31 ] = self::intToChr(
313
+            ( self::chrToInt( $e[ 31 ] ) & 127 ) | 64
314 314
         );
315 315
 
316
-        $A = self::ge_scalarmult_base($e);
316
+        $A = self::ge_scalarmult_base( $e );
317 317
         if (
318
-            !($A->Y instanceof ParagonIE_Sodium_Core_Curve25519_Fe)
318
+            ! ( $A->Y instanceof ParagonIE_Sodium_Core_Curve25519_Fe )
319 319
                 ||
320
-            !($A->Z instanceof ParagonIE_Sodium_Core_Curve25519_Fe)
320
+            ! ( $A->Z instanceof ParagonIE_Sodium_Core_Curve25519_Fe )
321 321
         ) {
322
-            throw new TypeError('Null points encountered');
322
+            throw new TypeError( 'Null points encountered' );
323 323
         }
324
-        $pk = self::edwards_to_montgomery($A->Y, $A->Z);
325
-        return self::fe_tobytes($pk);
324
+        $pk = self::edwards_to_montgomery( $A->Y, $A->Z );
325
+        return self::fe_tobytes( $pk );
326 326
     }
327 327
 }
Please login to merge, or discard this patch.
Braces   +4 added lines, -8 removed lines patch added patch discarded remove patch
@@ -7,8 +7,7 @@  discard block
 block discarded – undo
7 7
 /**
8 8
  * Class ParagonIE_Sodium_Core_X25519
9 9
  */
10
-abstract class ParagonIE_Sodium_Core_X25519 extends ParagonIE_Sodium_Core_Curve25519
11
-{
10
+abstract class ParagonIE_Sodium_Core_X25519 extends ParagonIE_Sodium_Core_Curve25519 {
12 11
     /**
13 12
      * Alters the objects passed to this method in place.
14 13
      *
@@ -84,8 +83,7 @@  discard block
 block discarded – undo
84 83
      * @param ParagonIE_Sodium_Core_Curve25519_Fe $f
85 84
      * @return ParagonIE_Sodium_Core_Curve25519_Fe
86 85
      */
87
-    public static function fe_mul121666(ParagonIE_Sodium_Core_Curve25519_Fe $f)
88
-    {
86
+    public static function fe_mul121666(ParagonIE_Sodium_Core_Curve25519_Fe $f) {
89 87
         $h = array(
90 88
             self::mul((int) $f[0], 121666, 17),
91 89
             self::mul((int) $f[1], 121666, 17),
@@ -158,8 +156,7 @@  discard block
 block discarded – undo
158 156
      * @throws SodiumException
159 157
      * @throws TypeError
160 158
      */
161
-    public static function crypto_scalarmult_curve25519_ref10($n, $p)
162
-    {
159
+    public static function crypto_scalarmult_curve25519_ref10($n, $p) {
163 160
         # for (i = 0;i < 32;++i) e[i] = n[i];
164 161
         $e = '' . $n;
165 162
         # e[0] &= 248;
@@ -297,8 +294,7 @@  discard block
 block discarded – undo
297 294
      * @throws SodiumException
298 295
      * @throws TypeError
299 296
      */
300
-    public static function crypto_scalarmult_curve25519_ref10_base($n)
301
-    {
297
+    public static function crypto_scalarmult_curve25519_ref10_base($n) {
302 298
         # for (i = 0;i < 32;++i) e[i] = n[i];
303 299
         $e = '' . $n;
304 300
 
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Core/Poly1305.php 3 patches
Indentation   +50 added lines, -50 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Core_Poly1305', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -9,55 +9,55 @@  discard block
 block discarded – undo
9 9
  */
10 10
 abstract class ParagonIE_Sodium_Core_Poly1305 extends ParagonIE_Sodium_Core_Util
11 11
 {
12
-    const BLOCK_SIZE = 16;
12
+	const BLOCK_SIZE = 16;
13 13
 
14
-    /**
15
-     * @internal You should not use this directly from another application
16
-     *
17
-     * @param string $m
18
-     * @param string $key
19
-     * @return string
20
-     * @throws SodiumException
21
-     * @throws TypeError
22
-     */
23
-    public static function onetimeauth($m, $key)
24
-    {
25
-        if (self::strlen($key) < 32) {
26
-            throw new InvalidArgumentException(
27
-                'Key must be 32 bytes long.'
28
-            );
29
-        }
30
-        $state = new ParagonIE_Sodium_Core_Poly1305_State(
31
-            self::substr($key, 0, 32)
32
-        );
33
-        return $state
34
-            ->update($m)
35
-            ->finish();
36
-    }
14
+	/**
15
+	 * @internal You should not use this directly from another application
16
+	 *
17
+	 * @param string $m
18
+	 * @param string $key
19
+	 * @return string
20
+	 * @throws SodiumException
21
+	 * @throws TypeError
22
+	 */
23
+	public static function onetimeauth($m, $key)
24
+	{
25
+		if (self::strlen($key) < 32) {
26
+			throw new InvalidArgumentException(
27
+				'Key must be 32 bytes long.'
28
+			);
29
+		}
30
+		$state = new ParagonIE_Sodium_Core_Poly1305_State(
31
+			self::substr($key, 0, 32)
32
+		);
33
+		return $state
34
+			->update($m)
35
+			->finish();
36
+	}
37 37
 
38
-    /**
39
-     * @internal You should not use this directly from another application
40
-     *
41
-     * @param string $mac
42
-     * @param string $m
43
-     * @param string $key
44
-     * @return bool
45
-     * @throws SodiumException
46
-     * @throws TypeError
47
-     */
48
-    public static function onetimeauth_verify($mac, $m, $key)
49
-    {
50
-        if (self::strlen($key) < 32) {
51
-            throw new InvalidArgumentException(
52
-                'Key must be 32 bytes long.'
53
-            );
54
-        }
55
-        $state = new ParagonIE_Sodium_Core_Poly1305_State(
56
-            self::substr($key, 0, 32)
57
-        );
58
-        $calc = $state
59
-            ->update($m)
60
-            ->finish();
61
-        return self::verify_16($calc, $mac);
62
-    }
38
+	/**
39
+	 * @internal You should not use this directly from another application
40
+	 *
41
+	 * @param string $mac
42
+	 * @param string $m
43
+	 * @param string $key
44
+	 * @return bool
45
+	 * @throws SodiumException
46
+	 * @throws TypeError
47
+	 */
48
+	public static function onetimeauth_verify($mac, $m, $key)
49
+	{
50
+		if (self::strlen($key) < 32) {
51
+			throw new InvalidArgumentException(
52
+				'Key must be 32 bytes long.'
53
+			);
54
+		}
55
+		$state = new ParagonIE_Sodium_Core_Poly1305_State(
56
+			self::substr($key, 0, 32)
57
+		);
58
+		$calc = $state
59
+			->update($m)
60
+			->finish();
61
+		return self::verify_16($calc, $mac);
62
+	}
63 63
 }
Please login to merge, or discard this patch.
Spacing   +10 added lines, -10 removed lines patch added patch discarded remove patch
@@ -1,6 +1,6 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3
-if (class_exists('ParagonIE_Sodium_Core_Poly1305', false)) {
3
+if ( class_exists( 'ParagonIE_Sodium_Core_Poly1305', false ) ) {
4 4
     return;
5 5
 }
6 6
 
@@ -20,18 +20,18 @@  discard block
 block discarded – undo
20 20
      * @throws SodiumException
21 21
      * @throws TypeError
22 22
      */
23
-    public static function onetimeauth($m, $key)
23
+    public static function onetimeauth( $m, $key )
24 24
     {
25
-        if (self::strlen($key) < 32) {
25
+        if ( self::strlen( $key ) < 32 ) {
26 26
             throw new InvalidArgumentException(
27 27
                 'Key must be 32 bytes long.'
28 28
             );
29 29
         }
30 30
         $state = new ParagonIE_Sodium_Core_Poly1305_State(
31
-            self::substr($key, 0, 32)
31
+            self::substr( $key, 0, 32 )
32 32
         );
33 33
         return $state
34
-            ->update($m)
34
+            ->update( $m )
35 35
             ->finish();
36 36
     }
37 37
 
@@ -45,19 +45,19 @@  discard block
 block discarded – undo
45 45
      * @throws SodiumException
46 46
      * @throws TypeError
47 47
      */
48
-    public static function onetimeauth_verify($mac, $m, $key)
48
+    public static function onetimeauth_verify( $mac, $m, $key )
49 49
     {
50
-        if (self::strlen($key) < 32) {
50
+        if ( self::strlen( $key ) < 32 ) {
51 51
             throw new InvalidArgumentException(
52 52
                 'Key must be 32 bytes long.'
53 53
             );
54 54
         }
55 55
         $state = new ParagonIE_Sodium_Core_Poly1305_State(
56
-            self::substr($key, 0, 32)
56
+            self::substr( $key, 0, 32 )
57 57
         );
58 58
         $calc = $state
59
-            ->update($m)
59
+            ->update( $m )
60 60
             ->finish();
61
-        return self::verify_16($calc, $mac);
61
+        return self::verify_16( $calc, $mac );
62 62
     }
63 63
 }
Please login to merge, or discard this patch.
Braces   +3 added lines, -6 removed lines patch added patch discarded remove patch
@@ -7,8 +7,7 @@  discard block
 block discarded – undo
7 7
 /**
8 8
  * Class ParagonIE_Sodium_Core_Poly1305
9 9
  */
10
-abstract class ParagonIE_Sodium_Core_Poly1305 extends ParagonIE_Sodium_Core_Util
11
-{
10
+abstract class ParagonIE_Sodium_Core_Poly1305 extends ParagonIE_Sodium_Core_Util {
12 11
     const BLOCK_SIZE = 16;
13 12
 
14 13
     /**
@@ -20,8 +19,7 @@  discard block
 block discarded – undo
20 19
      * @throws SodiumException
21 20
      * @throws TypeError
22 21
      */
23
-    public static function onetimeauth($m, $key)
24
-    {
22
+    public static function onetimeauth($m, $key) {
25 23
         if (self::strlen($key) < 32) {
26 24
             throw new InvalidArgumentException(
27 25
                 'Key must be 32 bytes long.'
@@ -45,8 +43,7 @@  discard block
 block discarded – undo
45 43
      * @throws SodiumException
46 44
      * @throws TypeError
47 45
      */
48
-    public static function onetimeauth_verify($mac, $m, $key)
49
-    {
46
+    public static function onetimeauth_verify($mac, $m, $key) {
50 47
         if (self::strlen($key) < 32) {
51 48
             throw new InvalidArgumentException(
52 49
                 'Key must be 32 bytes long.'
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Core/XSalsa20.php 3 patches
Indentation   +45 added lines, -45 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Core_XSalsa20', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -9,49 +9,49 @@  discard block
 block discarded – undo
9 9
  */
10 10
 abstract class ParagonIE_Sodium_Core_XSalsa20 extends ParagonIE_Sodium_Core_HSalsa20
11 11
 {
12
-    /**
13
-     * Expand a key and nonce into an xsalsa20 keystream.
14
-     *
15
-     * @internal You should not use this directly from another application
16
-     *
17
-     * @param int $len
18
-     * @param string $nonce
19
-     * @param string $key
20
-     * @return string
21
-     * @throws SodiumException
22
-     * @throws TypeError
23
-     */
24
-    public static function xsalsa20($len, $nonce, $key)
25
-    {
26
-        $ret = self::salsa20(
27
-            $len,
28
-            self::substr($nonce, 16, 8),
29
-            self::hsalsa20($nonce, $key)
30
-        );
31
-        return $ret;
32
-    }
12
+	/**
13
+	 * Expand a key and nonce into an xsalsa20 keystream.
14
+	 *
15
+	 * @internal You should not use this directly from another application
16
+	 *
17
+	 * @param int $len
18
+	 * @param string $nonce
19
+	 * @param string $key
20
+	 * @return string
21
+	 * @throws SodiumException
22
+	 * @throws TypeError
23
+	 */
24
+	public static function xsalsa20($len, $nonce, $key)
25
+	{
26
+		$ret = self::salsa20(
27
+			$len,
28
+			self::substr($nonce, 16, 8),
29
+			self::hsalsa20($nonce, $key)
30
+		);
31
+		return $ret;
32
+	}
33 33
 
34
-    /**
35
-     * Encrypt a string with XSalsa20. Doesn't provide integrity.
36
-     *
37
-     * @internal You should not use this directly from another application
38
-     *
39
-     * @param string $message
40
-     * @param string $nonce
41
-     * @param string $key
42
-     * @return string
43
-     * @throws SodiumException
44
-     * @throws TypeError
45
-     */
46
-    public static function xsalsa20_xor($message, $nonce, $key)
47
-    {
48
-        return self::xorStrings(
49
-            $message,
50
-            self::xsalsa20(
51
-                self::strlen($message),
52
-                $nonce,
53
-                $key
54
-            )
55
-        );
56
-    }
34
+	/**
35
+	 * Encrypt a string with XSalsa20. Doesn't provide integrity.
36
+	 *
37
+	 * @internal You should not use this directly from another application
38
+	 *
39
+	 * @param string $message
40
+	 * @param string $nonce
41
+	 * @param string $key
42
+	 * @return string
43
+	 * @throws SodiumException
44
+	 * @throws TypeError
45
+	 */
46
+	public static function xsalsa20_xor($message, $nonce, $key)
47
+	{
48
+		return self::xorStrings(
49
+			$message,
50
+			self::xsalsa20(
51
+				self::strlen($message),
52
+				$nonce,
53
+				$key
54
+			)
55
+		);
56
+	}
57 57
 }
Please login to merge, or discard this patch.
Spacing   +6 added lines, -6 removed lines patch added patch discarded remove patch
@@ -1,6 +1,6 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3
-if (class_exists('ParagonIE_Sodium_Core_XSalsa20', false)) {
3
+if ( class_exists( 'ParagonIE_Sodium_Core_XSalsa20', false ) ) {
4 4
     return;
5 5
 }
6 6
 
@@ -21,12 +21,12 @@  discard block
 block discarded – undo
21 21
      * @throws SodiumException
22 22
      * @throws TypeError
23 23
      */
24
-    public static function xsalsa20($len, $nonce, $key)
24
+    public static function xsalsa20( $len, $nonce, $key )
25 25
     {
26 26
         $ret = self::salsa20(
27 27
             $len,
28
-            self::substr($nonce, 16, 8),
29
-            self::hsalsa20($nonce, $key)
28
+            self::substr( $nonce, 16, 8 ),
29
+            self::hsalsa20( $nonce, $key )
30 30
         );
31 31
         return $ret;
32 32
     }
@@ -43,12 +43,12 @@  discard block
 block discarded – undo
43 43
      * @throws SodiumException
44 44
      * @throws TypeError
45 45
      */
46
-    public static function xsalsa20_xor($message, $nonce, $key)
46
+    public static function xsalsa20_xor( $message, $nonce, $key )
47 47
     {
48 48
         return self::xorStrings(
49 49
             $message,
50 50
             self::xsalsa20(
51
-                self::strlen($message),
51
+                self::strlen( $message ),
52 52
                 $nonce,
53 53
                 $key
54 54
             )
Please login to merge, or discard this patch.
Braces   +3 added lines, -6 removed lines patch added patch discarded remove patch
@@ -7,8 +7,7 @@  discard block
 block discarded – undo
7 7
 /**
8 8
  * Class ParagonIE_Sodium_Core_XSalsa20
9 9
  */
10
-abstract class ParagonIE_Sodium_Core_XSalsa20 extends ParagonIE_Sodium_Core_HSalsa20
11
-{
10
+abstract class ParagonIE_Sodium_Core_XSalsa20 extends ParagonIE_Sodium_Core_HSalsa20 {
12 11
     /**
13 12
      * Expand a key and nonce into an xsalsa20 keystream.
14 13
      *
@@ -21,8 +20,7 @@  discard block
 block discarded – undo
21 20
      * @throws SodiumException
22 21
      * @throws TypeError
23 22
      */
24
-    public static function xsalsa20($len, $nonce, $key)
25
-    {
23
+    public static function xsalsa20($len, $nonce, $key) {
26 24
         $ret = self::salsa20(
27 25
             $len,
28 26
             self::substr($nonce, 16, 8),
@@ -43,8 +41,7 @@  discard block
 block discarded – undo
43 41
      * @throws SodiumException
44 42
      * @throws TypeError
45 43
      */
46
-    public static function xsalsa20_xor($message, $nonce, $key)
47
-    {
44
+    public static function xsalsa20_xor($message, $nonce, $key) {
48 45
         return self::xorStrings(
49 46
             $message,
50 47
             self::xsalsa20(
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Core/ChaCha20.php 3 patches
Indentation   +285 added lines, -285 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Core_ChaCha20', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -9,80 +9,80 @@  discard block
 block discarded – undo
9 9
  */
10 10
 class ParagonIE_Sodium_Core_ChaCha20 extends ParagonIE_Sodium_Core_Util
11 11
 {
12
-    /**
13
-     * Bitwise left rotation
14
-     *
15
-     * @internal You should not use this directly from another application
16
-     *
17
-     * @param int $v
18
-     * @param int $n
19
-     * @return int
20
-     */
21
-    public static function rotate($v, $n)
22
-    {
23
-        $v &= 0xffffffff;
24
-        $n &= 31;
25
-        return (int) (
26
-            0xffffffff & (
27
-                ($v << $n)
28
-                    |
29
-                ($v >> (32 - $n))
30
-            )
31
-        );
32
-    }
12
+	/**
13
+	 * Bitwise left rotation
14
+	 *
15
+	 * @internal You should not use this directly from another application
16
+	 *
17
+	 * @param int $v
18
+	 * @param int $n
19
+	 * @return int
20
+	 */
21
+	public static function rotate($v, $n)
22
+	{
23
+		$v &= 0xffffffff;
24
+		$n &= 31;
25
+		return (int) (
26
+			0xffffffff & (
27
+				($v << $n)
28
+					|
29
+				($v >> (32 - $n))
30
+			)
31
+		);
32
+	}
33 33
 
34
-    /**
35
-     * The ChaCha20 quarter round function. Works on four 32-bit integers.
36
-     *
37
-     * @internal You should not use this directly from another application
38
-     *
39
-     * @param int $a
40
-     * @param int $b
41
-     * @param int $c
42
-     * @param int $d
43
-     * @return array<int, int>
44
-     */
45
-    protected static function quarterRound($a, $b, $c, $d)
46
-    {
47
-        # a = PLUS(a,b); d = ROTATE(XOR(d,a),16);
48
-        /** @var int $a */
49
-        $a = ($a + $b) & 0xffffffff;
50
-        $d = self::rotate($d ^ $a, 16);
34
+	/**
35
+	 * The ChaCha20 quarter round function. Works on four 32-bit integers.
36
+	 *
37
+	 * @internal You should not use this directly from another application
38
+	 *
39
+	 * @param int $a
40
+	 * @param int $b
41
+	 * @param int $c
42
+	 * @param int $d
43
+	 * @return array<int, int>
44
+	 */
45
+	protected static function quarterRound($a, $b, $c, $d)
46
+	{
47
+		# a = PLUS(a,b); d = ROTATE(XOR(d,a),16);
48
+		/** @var int $a */
49
+		$a = ($a + $b) & 0xffffffff;
50
+		$d = self::rotate($d ^ $a, 16);
51 51
 
52
-        # c = PLUS(c,d); b = ROTATE(XOR(b,c),12);
53
-        /** @var int $c */
54
-        $c = ($c + $d) & 0xffffffff;
55
-        $b = self::rotate($b ^ $c, 12);
52
+		# c = PLUS(c,d); b = ROTATE(XOR(b,c),12);
53
+		/** @var int $c */
54
+		$c = ($c + $d) & 0xffffffff;
55
+		$b = self::rotate($b ^ $c, 12);
56 56
 
57
-        # a = PLUS(a,b); d = ROTATE(XOR(d,a), 8);
58
-        /** @var int $a */
59
-        $a = ($a + $b) & 0xffffffff;
60
-        $d = self::rotate($d ^ $a, 8);
57
+		# a = PLUS(a,b); d = ROTATE(XOR(d,a), 8);
58
+		/** @var int $a */
59
+		$a = ($a + $b) & 0xffffffff;
60
+		$d = self::rotate($d ^ $a, 8);
61 61
 
62
-        # c = PLUS(c,d); b = ROTATE(XOR(b,c), 7);
63
-        /** @var int $c */
64
-        $c = ($c + $d) & 0xffffffff;
65
-        $b = self::rotate($b ^ $c, 7);
66
-        return array((int) $a, (int) $b, (int) $c, (int) $d);
67
-    }
62
+		# c = PLUS(c,d); b = ROTATE(XOR(b,c), 7);
63
+		/** @var int $c */
64
+		$c = ($c + $d) & 0xffffffff;
65
+		$b = self::rotate($b ^ $c, 7);
66
+		return array((int) $a, (int) $b, (int) $c, (int) $d);
67
+	}
68 68
 
69
-    /**
70
-     * @internal You should not use this directly from another application
71
-     *
72
-     * @param ParagonIE_Sodium_Core_ChaCha20_Ctx $ctx
73
-     * @param string $message
74
-     *
75
-     * @return string
76
-     * @throws TypeError
77
-     * @throws SodiumException
78
-     */
79
-    public static function encryptBytes(
80
-        ParagonIE_Sodium_Core_ChaCha20_Ctx $ctx,
81
-        $message = ''
82
-    ) {
83
-        $bytes = self::strlen($message);
69
+	/**
70
+	 * @internal You should not use this directly from another application
71
+	 *
72
+	 * @param ParagonIE_Sodium_Core_ChaCha20_Ctx $ctx
73
+	 * @param string $message
74
+	 *
75
+	 * @return string
76
+	 * @throws TypeError
77
+	 * @throws SodiumException
78
+	 */
79
+	public static function encryptBytes(
80
+		ParagonIE_Sodium_Core_ChaCha20_Ctx $ctx,
81
+		$message = ''
82
+	) {
83
+		$bytes = self::strlen($message);
84 84
 
85
-        /*
85
+		/*
86 86
         j0 = ctx->input[0];
87 87
         j1 = ctx->input[1];
88 88
         j2 = ctx->input[2];
@@ -100,73 +100,73 @@  discard block
 block discarded – undo
100 100
         j14 = ctx->input[14];
101 101
         j15 = ctx->input[15];
102 102
         */
103
-        $j0  = (int) $ctx[0];
104
-        $j1  = (int) $ctx[1];
105
-        $j2  = (int) $ctx[2];
106
-        $j3  = (int) $ctx[3];
107
-        $j4  = (int) $ctx[4];
108
-        $j5  = (int) $ctx[5];
109
-        $j6  = (int) $ctx[6];
110
-        $j7  = (int) $ctx[7];
111
-        $j8  = (int) $ctx[8];
112
-        $j9  = (int) $ctx[9];
113
-        $j10 = (int) $ctx[10];
114
-        $j11 = (int) $ctx[11];
115
-        $j12 = (int) $ctx[12];
116
-        $j13 = (int) $ctx[13];
117
-        $j14 = (int) $ctx[14];
118
-        $j15 = (int) $ctx[15];
103
+		$j0  = (int) $ctx[0];
104
+		$j1  = (int) $ctx[1];
105
+		$j2  = (int) $ctx[2];
106
+		$j3  = (int) $ctx[3];
107
+		$j4  = (int) $ctx[4];
108
+		$j5  = (int) $ctx[5];
109
+		$j6  = (int) $ctx[6];
110
+		$j7  = (int) $ctx[7];
111
+		$j8  = (int) $ctx[8];
112
+		$j9  = (int) $ctx[9];
113
+		$j10 = (int) $ctx[10];
114
+		$j11 = (int) $ctx[11];
115
+		$j12 = (int) $ctx[12];
116
+		$j13 = (int) $ctx[13];
117
+		$j14 = (int) $ctx[14];
118
+		$j15 = (int) $ctx[15];
119 119
 
120
-        $c = '';
121
-        for (;;) {
122
-            if ($bytes < 64) {
123
-                $message .= str_repeat("\x00", 64 - $bytes);
124
-            }
120
+		$c = '';
121
+		for (;;) {
122
+			if ($bytes < 64) {
123
+				$message .= str_repeat("\x00", 64 - $bytes);
124
+			}
125 125
 
126
-            $x0 =  (int) $j0;
127
-            $x1 =  (int) $j1;
128
-            $x2 =  (int) $j2;
129
-            $x3 =  (int) $j3;
130
-            $x4 =  (int) $j4;
131
-            $x5 =  (int) $j5;
132
-            $x6 =  (int) $j6;
133
-            $x7 =  (int) $j7;
134
-            $x8 =  (int) $j8;
135
-            $x9 =  (int) $j9;
136
-            $x10 = (int) $j10;
137
-            $x11 = (int) $j11;
138
-            $x12 = (int) $j12;
139
-            $x13 = (int) $j13;
140
-            $x14 = (int) $j14;
141
-            $x15 = (int) $j15;
126
+			$x0 =  (int) $j0;
127
+			$x1 =  (int) $j1;
128
+			$x2 =  (int) $j2;
129
+			$x3 =  (int) $j3;
130
+			$x4 =  (int) $j4;
131
+			$x5 =  (int) $j5;
132
+			$x6 =  (int) $j6;
133
+			$x7 =  (int) $j7;
134
+			$x8 =  (int) $j8;
135
+			$x9 =  (int) $j9;
136
+			$x10 = (int) $j10;
137
+			$x11 = (int) $j11;
138
+			$x12 = (int) $j12;
139
+			$x13 = (int) $j13;
140
+			$x14 = (int) $j14;
141
+			$x15 = (int) $j15;
142 142
 
143
-            # for (i = 20; i > 0; i -= 2) {
144
-            for ($i = 20; $i > 0; $i -= 2) {
145
-                # QUARTERROUND( x0,  x4,  x8,  x12)
146
-                list($x0, $x4, $x8, $x12) = self::quarterRound($x0, $x4, $x8, $x12);
143
+			# for (i = 20; i > 0; i -= 2) {
144
+			for ($i = 20; $i > 0; $i -= 2) {
145
+				# QUARTERROUND( x0,  x4,  x8,  x12)
146
+				list($x0, $x4, $x8, $x12) = self::quarterRound($x0, $x4, $x8, $x12);
147 147
 
148
-                # QUARTERROUND( x1,  x5,  x9,  x13)
149
-                list($x1, $x5, $x9, $x13) = self::quarterRound($x1, $x5, $x9, $x13);
148
+				# QUARTERROUND( x1,  x5,  x9,  x13)
149
+				list($x1, $x5, $x9, $x13) = self::quarterRound($x1, $x5, $x9, $x13);
150 150
 
151
-                # QUARTERROUND( x2,  x6,  x10,  x14)
152
-                list($x2, $x6, $x10, $x14) = self::quarterRound($x2, $x6, $x10, $x14);
151
+				# QUARTERROUND( x2,  x6,  x10,  x14)
152
+				list($x2, $x6, $x10, $x14) = self::quarterRound($x2, $x6, $x10, $x14);
153 153
 
154
-                # QUARTERROUND( x3,  x7,  x11,  x15)
155
-                list($x3, $x7, $x11, $x15) = self::quarterRound($x3, $x7, $x11, $x15);
154
+				# QUARTERROUND( x3,  x7,  x11,  x15)
155
+				list($x3, $x7, $x11, $x15) = self::quarterRound($x3, $x7, $x11, $x15);
156 156
 
157
-                # QUARTERROUND( x0,  x5,  x10,  x15)
158
-                list($x0, $x5, $x10, $x15) = self::quarterRound($x0, $x5, $x10, $x15);
157
+				# QUARTERROUND( x0,  x5,  x10,  x15)
158
+				list($x0, $x5, $x10, $x15) = self::quarterRound($x0, $x5, $x10, $x15);
159 159
 
160
-                # QUARTERROUND( x1,  x6,  x11,  x12)
161
-                list($x1, $x6, $x11, $x12) = self::quarterRound($x1, $x6, $x11, $x12);
160
+				# QUARTERROUND( x1,  x6,  x11,  x12)
161
+				list($x1, $x6, $x11, $x12) = self::quarterRound($x1, $x6, $x11, $x12);
162 162
 
163
-                # QUARTERROUND( x2,  x7,  x8,  x13)
164
-                list($x2, $x7, $x8, $x13) = self::quarterRound($x2, $x7, $x8, $x13);
163
+				# QUARTERROUND( x2,  x7,  x8,  x13)
164
+				list($x2, $x7, $x8, $x13) = self::quarterRound($x2, $x7, $x8, $x13);
165 165
 
166
-                # QUARTERROUND( x3,  x4,  x9,  x14)
167
-                list($x3, $x4, $x9, $x14) = self::quarterRound($x3, $x4, $x9, $x14);
168
-            }
169
-            /*
166
+				# QUARTERROUND( x3,  x4,  x9,  x14)
167
+				list($x3, $x4, $x9, $x14) = self::quarterRound($x3, $x4, $x9, $x14);
168
+			}
169
+			/*
170 170
             x0 = PLUS(x0, j0);
171 171
             x1 = PLUS(x1, j1);
172 172
             x2 = PLUS(x2, j2);
@@ -184,40 +184,40 @@  discard block
 block discarded – undo
184 184
             x14 = PLUS(x14, j14);
185 185
             x15 = PLUS(x15, j15);
186 186
             */
187
-            /** @var int $x0 */
188
-            $x0  = ($x0 & 0xffffffff) + $j0;
189
-            /** @var int $x1 */
190
-            $x1  = ($x1 & 0xffffffff) + $j1;
191
-            /** @var int $x2 */
192
-            $x2  = ($x2 & 0xffffffff) + $j2;
193
-            /** @var int $x3 */
194
-            $x3  = ($x3 & 0xffffffff) + $j3;
195
-            /** @var int $x4 */
196
-            $x4  = ($x4 & 0xffffffff) + $j4;
197
-            /** @var int $x5 */
198
-            $x5  = ($x5 & 0xffffffff) + $j5;
199
-            /** @var int $x6 */
200
-            $x6  = ($x6 & 0xffffffff) + $j6;
201
-            /** @var int $x7 */
202
-            $x7  = ($x7 & 0xffffffff) + $j7;
203
-            /** @var int $x8 */
204
-            $x8  = ($x8 & 0xffffffff) + $j8;
205
-            /** @var int $x9 */
206
-            $x9  = ($x9 & 0xffffffff) + $j9;
207
-            /** @var int $x10 */
208
-            $x10 = ($x10 & 0xffffffff) + $j10;
209
-            /** @var int $x11 */
210
-            $x11 = ($x11 & 0xffffffff) + $j11;
211
-            /** @var int $x12 */
212
-            $x12 = ($x12 & 0xffffffff) + $j12;
213
-            /** @var int $x13 */
214
-            $x13 = ($x13 & 0xffffffff) + $j13;
215
-            /** @var int $x14 */
216
-            $x14 = ($x14 & 0xffffffff) + $j14;
217
-            /** @var int $x15 */
218
-            $x15 = ($x15 & 0xffffffff) + $j15;
187
+			/** @var int $x0 */
188
+			$x0  = ($x0 & 0xffffffff) + $j0;
189
+			/** @var int $x1 */
190
+			$x1  = ($x1 & 0xffffffff) + $j1;
191
+			/** @var int $x2 */
192
+			$x2  = ($x2 & 0xffffffff) + $j2;
193
+			/** @var int $x3 */
194
+			$x3  = ($x3 & 0xffffffff) + $j3;
195
+			/** @var int $x4 */
196
+			$x4  = ($x4 & 0xffffffff) + $j4;
197
+			/** @var int $x5 */
198
+			$x5  = ($x5 & 0xffffffff) + $j5;
199
+			/** @var int $x6 */
200
+			$x6  = ($x6 & 0xffffffff) + $j6;
201
+			/** @var int $x7 */
202
+			$x7  = ($x7 & 0xffffffff) + $j7;
203
+			/** @var int $x8 */
204
+			$x8  = ($x8 & 0xffffffff) + $j8;
205
+			/** @var int $x9 */
206
+			$x9  = ($x9 & 0xffffffff) + $j9;
207
+			/** @var int $x10 */
208
+			$x10 = ($x10 & 0xffffffff) + $j10;
209
+			/** @var int $x11 */
210
+			$x11 = ($x11 & 0xffffffff) + $j11;
211
+			/** @var int $x12 */
212
+			$x12 = ($x12 & 0xffffffff) + $j12;
213
+			/** @var int $x13 */
214
+			$x13 = ($x13 & 0xffffffff) + $j13;
215
+			/** @var int $x14 */
216
+			$x14 = ($x14 & 0xffffffff) + $j14;
217
+			/** @var int $x15 */
218
+			$x15 = ($x15 & 0xffffffff) + $j15;
219 219
 
220
-            /*
220
+			/*
221 221
             x0 = XOR(x0, LOAD32_LE(m + 0));
222 222
             x1 = XOR(x1, LOAD32_LE(m + 4));
223 223
             x2 = XOR(x2, LOAD32_LE(m + 8));
@@ -235,35 +235,35 @@  discard block
 block discarded – undo
235 235
             x14 = XOR(x14, LOAD32_LE(m + 56));
236 236
             x15 = XOR(x15, LOAD32_LE(m + 60));
237 237
             */
238
-            $x0  ^= self::load_4(self::substr($message, 0, 4));
239
-            $x1  ^= self::load_4(self::substr($message, 4, 4));
240
-            $x2  ^= self::load_4(self::substr($message, 8, 4));
241
-            $x3  ^= self::load_4(self::substr($message, 12, 4));
242
-            $x4  ^= self::load_4(self::substr($message, 16, 4));
243
-            $x5  ^= self::load_4(self::substr($message, 20, 4));
244
-            $x6  ^= self::load_4(self::substr($message, 24, 4));
245
-            $x7  ^= self::load_4(self::substr($message, 28, 4));
246
-            $x8  ^= self::load_4(self::substr($message, 32, 4));
247
-            $x9  ^= self::load_4(self::substr($message, 36, 4));
248
-            $x10 ^= self::load_4(self::substr($message, 40, 4));
249
-            $x11 ^= self::load_4(self::substr($message, 44, 4));
250
-            $x12 ^= self::load_4(self::substr($message, 48, 4));
251
-            $x13 ^= self::load_4(self::substr($message, 52, 4));
252
-            $x14 ^= self::load_4(self::substr($message, 56, 4));
253
-            $x15 ^= self::load_4(self::substr($message, 60, 4));
238
+			$x0  ^= self::load_4(self::substr($message, 0, 4));
239
+			$x1  ^= self::load_4(self::substr($message, 4, 4));
240
+			$x2  ^= self::load_4(self::substr($message, 8, 4));
241
+			$x3  ^= self::load_4(self::substr($message, 12, 4));
242
+			$x4  ^= self::load_4(self::substr($message, 16, 4));
243
+			$x5  ^= self::load_4(self::substr($message, 20, 4));
244
+			$x6  ^= self::load_4(self::substr($message, 24, 4));
245
+			$x7  ^= self::load_4(self::substr($message, 28, 4));
246
+			$x8  ^= self::load_4(self::substr($message, 32, 4));
247
+			$x9  ^= self::load_4(self::substr($message, 36, 4));
248
+			$x10 ^= self::load_4(self::substr($message, 40, 4));
249
+			$x11 ^= self::load_4(self::substr($message, 44, 4));
250
+			$x12 ^= self::load_4(self::substr($message, 48, 4));
251
+			$x13 ^= self::load_4(self::substr($message, 52, 4));
252
+			$x14 ^= self::load_4(self::substr($message, 56, 4));
253
+			$x15 ^= self::load_4(self::substr($message, 60, 4));
254 254
 
255
-            /*
255
+			/*
256 256
                 j12 = PLUSONE(j12);
257 257
                 if (!j12) {
258 258
                     j13 = PLUSONE(j13);
259 259
                 }
260 260
              */
261
-            ++$j12;
262
-            if ($j12 & 0xf0000000) {
263
-                throw new SodiumException('Overflow');
264
-            }
261
+			++$j12;
262
+			if ($j12 & 0xf0000000) {
263
+				throw new SodiumException('Overflow');
264
+			}
265 265
 
266
-            /*
266
+			/*
267 267
             STORE32_LE(c + 0, x0);
268 268
             STORE32_LE(c + 4, x1);
269 269
             STORE32_LE(c + 8, x2);
@@ -281,115 +281,115 @@  discard block
 block discarded – undo
281 281
             STORE32_LE(c + 56, x14);
282 282
             STORE32_LE(c + 60, x15);
283 283
             */
284
-            $block = self::store32_le((int) ($x0  & 0xffffffff)) .
285
-                 self::store32_le((int) ($x1  & 0xffffffff)) .
286
-                 self::store32_le((int) ($x2  & 0xffffffff)) .
287
-                 self::store32_le((int) ($x3  & 0xffffffff)) .
288
-                 self::store32_le((int) ($x4  & 0xffffffff)) .
289
-                 self::store32_le((int) ($x5  & 0xffffffff)) .
290
-                 self::store32_le((int) ($x6  & 0xffffffff)) .
291
-                 self::store32_le((int) ($x7  & 0xffffffff)) .
292
-                 self::store32_le((int) ($x8  & 0xffffffff)) .
293
-                 self::store32_le((int) ($x9  & 0xffffffff)) .
294
-                 self::store32_le((int) ($x10 & 0xffffffff)) .
295
-                 self::store32_le((int) ($x11 & 0xffffffff)) .
296
-                 self::store32_le((int) ($x12 & 0xffffffff)) .
297
-                 self::store32_le((int) ($x13 & 0xffffffff)) .
298
-                 self::store32_le((int) ($x14 & 0xffffffff)) .
299
-                 self::store32_le((int) ($x15 & 0xffffffff));
284
+			$block = self::store32_le((int) ($x0  & 0xffffffff)) .
285
+				 self::store32_le((int) ($x1  & 0xffffffff)) .
286
+				 self::store32_le((int) ($x2  & 0xffffffff)) .
287
+				 self::store32_le((int) ($x3  & 0xffffffff)) .
288
+				 self::store32_le((int) ($x4  & 0xffffffff)) .
289
+				 self::store32_le((int) ($x5  & 0xffffffff)) .
290
+				 self::store32_le((int) ($x6  & 0xffffffff)) .
291
+				 self::store32_le((int) ($x7  & 0xffffffff)) .
292
+				 self::store32_le((int) ($x8  & 0xffffffff)) .
293
+				 self::store32_le((int) ($x9  & 0xffffffff)) .
294
+				 self::store32_le((int) ($x10 & 0xffffffff)) .
295
+				 self::store32_le((int) ($x11 & 0xffffffff)) .
296
+				 self::store32_le((int) ($x12 & 0xffffffff)) .
297
+				 self::store32_le((int) ($x13 & 0xffffffff)) .
298
+				 self::store32_le((int) ($x14 & 0xffffffff)) .
299
+				 self::store32_le((int) ($x15 & 0xffffffff));
300 300
 
301
-            /* Partial block */
302
-            if ($bytes < 64) {
303
-                $c .= self::substr($block, 0, $bytes);
304
-                break;
305
-            }
301
+			/* Partial block */
302
+			if ($bytes < 64) {
303
+				$c .= self::substr($block, 0, $bytes);
304
+				break;
305
+			}
306 306
 
307
-            /* Full block */
308
-            $c .= $block;
309
-            $bytes -= 64;
310
-            if ($bytes <= 0) {
311
-                break;
312
-            }
313
-            $message = self::substr($message, 64);
314
-        }
315
-        /* end for(;;) loop */
307
+			/* Full block */
308
+			$c .= $block;
309
+			$bytes -= 64;
310
+			if ($bytes <= 0) {
311
+				break;
312
+			}
313
+			$message = self::substr($message, 64);
314
+		}
315
+		/* end for(;;) loop */
316 316
 
317
-        $ctx[12] = $j12;
318
-        $ctx[13] = $j13;
319
-        return $c;
320
-    }
317
+		$ctx[12] = $j12;
318
+		$ctx[13] = $j13;
319
+		return $c;
320
+	}
321 321
 
322
-    /**
323
-     * @internal You should not use this directly from another application
324
-     *
325
-     * @param int $len
326
-     * @param string $nonce
327
-     * @param string $key
328
-     * @return string
329
-     * @throws SodiumException
330
-     * @throws TypeError
331
-     */
332
-    public static function stream($len = 64, $nonce = '', $key = '')
333
-    {
334
-        return self::encryptBytes(
335
-            new ParagonIE_Sodium_Core_ChaCha20_Ctx($key, $nonce),
336
-            str_repeat("\x00", $len)
337
-        );
338
-    }
322
+	/**
323
+	 * @internal You should not use this directly from another application
324
+	 *
325
+	 * @param int $len
326
+	 * @param string $nonce
327
+	 * @param string $key
328
+	 * @return string
329
+	 * @throws SodiumException
330
+	 * @throws TypeError
331
+	 */
332
+	public static function stream($len = 64, $nonce = '', $key = '')
333
+	{
334
+		return self::encryptBytes(
335
+			new ParagonIE_Sodium_Core_ChaCha20_Ctx($key, $nonce),
336
+			str_repeat("\x00", $len)
337
+		);
338
+	}
339 339
 
340
-    /**
341
-     * @internal You should not use this directly from another application
342
-     *
343
-     * @param int $len
344
-     * @param string $nonce
345
-     * @param string $key
346
-     * @return string
347
-     * @throws SodiumException
348
-     * @throws TypeError
349
-     */
350
-    public static function ietfStream($len, $nonce = '', $key = '')
351
-    {
352
-        return self::encryptBytes(
353
-            new ParagonIE_Sodium_Core_ChaCha20_IetfCtx($key, $nonce),
354
-            str_repeat("\x00", $len)
355
-        );
356
-    }
340
+	/**
341
+	 * @internal You should not use this directly from another application
342
+	 *
343
+	 * @param int $len
344
+	 * @param string $nonce
345
+	 * @param string $key
346
+	 * @return string
347
+	 * @throws SodiumException
348
+	 * @throws TypeError
349
+	 */
350
+	public static function ietfStream($len, $nonce = '', $key = '')
351
+	{
352
+		return self::encryptBytes(
353
+			new ParagonIE_Sodium_Core_ChaCha20_IetfCtx($key, $nonce),
354
+			str_repeat("\x00", $len)
355
+		);
356
+	}
357 357
 
358
-    /**
359
-     * @internal You should not use this directly from another application
360
-     *
361
-     * @param string $message
362
-     * @param string $nonce
363
-     * @param string $key
364
-     * @param string $ic
365
-     * @return string
366
-     * @throws SodiumException
367
-     * @throws TypeError
368
-     */
369
-    public static function ietfStreamXorIc($message, $nonce = '', $key = '', $ic = '')
370
-    {
371
-        return self::encryptBytes(
372
-            new ParagonIE_Sodium_Core_ChaCha20_IetfCtx($key, $nonce, $ic),
373
-            $message
374
-        );
375
-    }
358
+	/**
359
+	 * @internal You should not use this directly from another application
360
+	 *
361
+	 * @param string $message
362
+	 * @param string $nonce
363
+	 * @param string $key
364
+	 * @param string $ic
365
+	 * @return string
366
+	 * @throws SodiumException
367
+	 * @throws TypeError
368
+	 */
369
+	public static function ietfStreamXorIc($message, $nonce = '', $key = '', $ic = '')
370
+	{
371
+		return self::encryptBytes(
372
+			new ParagonIE_Sodium_Core_ChaCha20_IetfCtx($key, $nonce, $ic),
373
+			$message
374
+		);
375
+	}
376 376
 
377
-    /**
378
-     * @internal You should not use this directly from another application
379
-     *
380
-     * @param string $message
381
-     * @param string $nonce
382
-     * @param string $key
383
-     * @param string $ic
384
-     * @return string
385
-     * @throws SodiumException
386
-     * @throws TypeError
387
-     */
388
-    public static function streamXorIc($message, $nonce = '', $key = '', $ic = '')
389
-    {
390
-        return self::encryptBytes(
391
-            new ParagonIE_Sodium_Core_ChaCha20_Ctx($key, $nonce, $ic),
392
-            $message
393
-        );
394
-    }
377
+	/**
378
+	 * @internal You should not use this directly from another application
379
+	 *
380
+	 * @param string $message
381
+	 * @param string $nonce
382
+	 * @param string $key
383
+	 * @param string $ic
384
+	 * @return string
385
+	 * @throws SodiumException
386
+	 * @throws TypeError
387
+	 */
388
+	public static function streamXorIc($message, $nonce = '', $key = '', $ic = '')
389
+	{
390
+		return self::encryptBytes(
391
+			new ParagonIE_Sodium_Core_ChaCha20_Ctx($key, $nonce, $ic),
392
+			$message
393
+		);
394
+	}
395 395
 }
Please login to merge, or discard this patch.
Braces   +7 added lines, -14 removed lines patch added patch discarded remove patch
@@ -7,8 +7,7 @@  discard block
 block discarded – undo
7 7
 /**
8 8
  * Class ParagonIE_Sodium_Core_ChaCha20
9 9
  */
10
-class ParagonIE_Sodium_Core_ChaCha20 extends ParagonIE_Sodium_Core_Util
11
-{
10
+class ParagonIE_Sodium_Core_ChaCha20 extends ParagonIE_Sodium_Core_Util {
12 11
     /**
13 12
      * Bitwise left rotation
14 13
      *
@@ -18,8 +17,7 @@  discard block
 block discarded – undo
18 17
      * @param int $n
19 18
      * @return int
20 19
      */
21
-    public static function rotate($v, $n)
22
-    {
20
+    public static function rotate($v, $n) {
23 21
         $v &= 0xffffffff;
24 22
         $n &= 31;
25 23
         return (int) (
@@ -42,8 +40,7 @@  discard block
 block discarded – undo
42 40
      * @param int $d
43 41
      * @return array<int, int>
44 42
      */
45
-    protected static function quarterRound($a, $b, $c, $d)
46
-    {
43
+    protected static function quarterRound($a, $b, $c, $d) {
47 44
         # a = PLUS(a,b); d = ROTATE(XOR(d,a),16);
48 45
         /** @var int $a */
49 46
         $a = ($a + $b) & 0xffffffff;
@@ -329,8 +326,7 @@  discard block
 block discarded – undo
329 326
      * @throws SodiumException
330 327
      * @throws TypeError
331 328
      */
332
-    public static function stream($len = 64, $nonce = '', $key = '')
333
-    {
329
+    public static function stream($len = 64, $nonce = '', $key = '') {
334 330
         return self::encryptBytes(
335 331
             new ParagonIE_Sodium_Core_ChaCha20_Ctx($key, $nonce),
336 332
             str_repeat("\x00", $len)
@@ -347,8 +343,7 @@  discard block
 block discarded – undo
347 343
      * @throws SodiumException
348 344
      * @throws TypeError
349 345
      */
350
-    public static function ietfStream($len, $nonce = '', $key = '')
351
-    {
346
+    public static function ietfStream($len, $nonce = '', $key = '') {
352 347
         return self::encryptBytes(
353 348
             new ParagonIE_Sodium_Core_ChaCha20_IetfCtx($key, $nonce),
354 349
             str_repeat("\x00", $len)
@@ -366,8 +361,7 @@  discard block
 block discarded – undo
366 361
      * @throws SodiumException
367 362
      * @throws TypeError
368 363
      */
369
-    public static function ietfStreamXorIc($message, $nonce = '', $key = '', $ic = '')
370
-    {
364
+    public static function ietfStreamXorIc($message, $nonce = '', $key = '', $ic = '') {
371 365
         return self::encryptBytes(
372 366
             new ParagonIE_Sodium_Core_ChaCha20_IetfCtx($key, $nonce, $ic),
373 367
             $message
@@ -385,8 +379,7 @@  discard block
 block discarded – undo
385 379
      * @throws SodiumException
386 380
      * @throws TypeError
387 381
      */
388
-    public static function streamXorIc($message, $nonce = '', $key = '', $ic = '')
389
-    {
382
+    public static function streamXorIc($message, $nonce = '', $key = '', $ic = '') {
390 383
         return self::encryptBytes(
391 384
             new ParagonIE_Sodium_Core_ChaCha20_Ctx($key, $nonce, $ic),
392 385
             $message
Please login to merge, or discard this patch.
Spacing   +126 added lines, -126 removed lines patch added patch discarded remove patch
@@ -1,6 +1,6 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3
-if (class_exists('ParagonIE_Sodium_Core_ChaCha20', false)) {
3
+if ( class_exists( 'ParagonIE_Sodium_Core_ChaCha20', false ) ) {
4 4
     return;
5 5
 }
6 6
 
@@ -18,15 +18,15 @@  discard block
 block discarded – undo
18 18
      * @param int $n
19 19
      * @return int
20 20
      */
21
-    public static function rotate($v, $n)
21
+    public static function rotate( $v, $n )
22 22
     {
23 23
         $v &= 0xffffffff;
24 24
         $n &= 31;
25
-        return (int) (
25
+        return (int)(
26 26
             0xffffffff & (
27
-                ($v << $n)
27
+                ( $v << $n )
28 28
                     |
29
-                ($v >> (32 - $n))
29
+                ( $v >> ( 32 - $n ) )
30 30
             )
31 31
         );
32 32
     }
@@ -42,28 +42,28 @@  discard block
 block discarded – undo
42 42
      * @param int $d
43 43
      * @return array<int, int>
44 44
      */
45
-    protected static function quarterRound($a, $b, $c, $d)
45
+    protected static function quarterRound( $a, $b, $c, $d )
46 46
     {
47 47
         # a = PLUS(a,b); d = ROTATE(XOR(d,a),16);
48 48
         /** @var int $a */
49
-        $a = ($a + $b) & 0xffffffff;
50
-        $d = self::rotate($d ^ $a, 16);
49
+        $a = ( $a + $b ) & 0xffffffff;
50
+        $d = self::rotate( $d ^ $a, 16 );
51 51
 
52 52
         # c = PLUS(c,d); b = ROTATE(XOR(b,c),12);
53 53
         /** @var int $c */
54
-        $c = ($c + $d) & 0xffffffff;
55
-        $b = self::rotate($b ^ $c, 12);
54
+        $c = ( $c + $d ) & 0xffffffff;
55
+        $b = self::rotate( $b ^ $c, 12 );
56 56
 
57 57
         # a = PLUS(a,b); d = ROTATE(XOR(d,a), 8);
58 58
         /** @var int $a */
59
-        $a = ($a + $b) & 0xffffffff;
60
-        $d = self::rotate($d ^ $a, 8);
59
+        $a = ( $a + $b ) & 0xffffffff;
60
+        $d = self::rotate( $d ^ $a, 8 );
61 61
 
62 62
         # c = PLUS(c,d); b = ROTATE(XOR(b,c), 7);
63 63
         /** @var int $c */
64
-        $c = ($c + $d) & 0xffffffff;
65
-        $b = self::rotate($b ^ $c, 7);
66
-        return array((int) $a, (int) $b, (int) $c, (int) $d);
64
+        $c = ( $c + $d ) & 0xffffffff;
65
+        $b = self::rotate( $b ^ $c, 7 );
66
+        return array( (int)$a, (int)$b, (int)$c, (int)$d );
67 67
     }
68 68
 
69 69
     /**
@@ -80,7 +80,7 @@  discard block
 block discarded – undo
80 80
         ParagonIE_Sodium_Core_ChaCha20_Ctx $ctx,
81 81
         $message = ''
82 82
     ) {
83
-        $bytes = self::strlen($message);
83
+        $bytes = self::strlen( $message );
84 84
 
85 85
         /*
86 86
         j0 = ctx->input[0];
@@ -100,71 +100,71 @@  discard block
 block discarded – undo
100 100
         j14 = ctx->input[14];
101 101
         j15 = ctx->input[15];
102 102
         */
103
-        $j0  = (int) $ctx[0];
104
-        $j1  = (int) $ctx[1];
105
-        $j2  = (int) $ctx[2];
106
-        $j3  = (int) $ctx[3];
107
-        $j4  = (int) $ctx[4];
108
-        $j5  = (int) $ctx[5];
109
-        $j6  = (int) $ctx[6];
110
-        $j7  = (int) $ctx[7];
111
-        $j8  = (int) $ctx[8];
112
-        $j9  = (int) $ctx[9];
113
-        $j10 = (int) $ctx[10];
114
-        $j11 = (int) $ctx[11];
115
-        $j12 = (int) $ctx[12];
116
-        $j13 = (int) $ctx[13];
117
-        $j14 = (int) $ctx[14];
118
-        $j15 = (int) $ctx[15];
103
+        $j0  = (int)$ctx[ 0 ];
104
+        $j1  = (int)$ctx[ 1 ];
105
+        $j2  = (int)$ctx[ 2 ];
106
+        $j3  = (int)$ctx[ 3 ];
107
+        $j4  = (int)$ctx[ 4 ];
108
+        $j5  = (int)$ctx[ 5 ];
109
+        $j6  = (int)$ctx[ 6 ];
110
+        $j7  = (int)$ctx[ 7 ];
111
+        $j8  = (int)$ctx[ 8 ];
112
+        $j9  = (int)$ctx[ 9 ];
113
+        $j10 = (int)$ctx[ 10 ];
114
+        $j11 = (int)$ctx[ 11 ];
115
+        $j12 = (int)$ctx[ 12 ];
116
+        $j13 = (int)$ctx[ 13 ];
117
+        $j14 = (int)$ctx[ 14 ];
118
+        $j15 = (int)$ctx[ 15 ];
119 119
 
120 120
         $c = '';
121
-        for (;;) {
122
-            if ($bytes < 64) {
123
-                $message .= str_repeat("\x00", 64 - $bytes);
121
+        for ( ;; ) {
122
+            if ( $bytes < 64 ) {
123
+                $message .= str_repeat( "\x00", 64 - $bytes );
124 124
             }
125 125
 
126
-            $x0 =  (int) $j0;
127
-            $x1 =  (int) $j1;
128
-            $x2 =  (int) $j2;
129
-            $x3 =  (int) $j3;
130
-            $x4 =  (int) $j4;
131
-            $x5 =  (int) $j5;
132
-            $x6 =  (int) $j6;
133
-            $x7 =  (int) $j7;
134
-            $x8 =  (int) $j8;
135
-            $x9 =  (int) $j9;
136
-            $x10 = (int) $j10;
137
-            $x11 = (int) $j11;
138
-            $x12 = (int) $j12;
139
-            $x13 = (int) $j13;
140
-            $x14 = (int) $j14;
141
-            $x15 = (int) $j15;
126
+            $x0 = (int)$j0;
127
+            $x1 = (int)$j1;
128
+            $x2 = (int)$j2;
129
+            $x3 = (int)$j3;
130
+            $x4 = (int)$j4;
131
+            $x5 = (int)$j5;
132
+            $x6 = (int)$j6;
133
+            $x7 = (int)$j7;
134
+            $x8 = (int)$j8;
135
+            $x9 = (int)$j9;
136
+            $x10 = (int)$j10;
137
+            $x11 = (int)$j11;
138
+            $x12 = (int)$j12;
139
+            $x13 = (int)$j13;
140
+            $x14 = (int)$j14;
141
+            $x15 = (int)$j15;
142 142
 
143 143
             # for (i = 20; i > 0; i -= 2) {
144
-            for ($i = 20; $i > 0; $i -= 2) {
144
+            for ( $i = 20; $i > 0; $i -= 2 ) {
145 145
                 # QUARTERROUND( x0,  x4,  x8,  x12)
146
-                list($x0, $x4, $x8, $x12) = self::quarterRound($x0, $x4, $x8, $x12);
146
+                list( $x0, $x4, $x8, $x12 ) = self::quarterRound( $x0, $x4, $x8, $x12 );
147 147
 
148 148
                 # QUARTERROUND( x1,  x5,  x9,  x13)
149
-                list($x1, $x5, $x9, $x13) = self::quarterRound($x1, $x5, $x9, $x13);
149
+                list( $x1, $x5, $x9, $x13 ) = self::quarterRound( $x1, $x5, $x9, $x13 );
150 150
 
151 151
                 # QUARTERROUND( x2,  x6,  x10,  x14)
152
-                list($x2, $x6, $x10, $x14) = self::quarterRound($x2, $x6, $x10, $x14);
152
+                list( $x2, $x6, $x10, $x14 ) = self::quarterRound( $x2, $x6, $x10, $x14 );
153 153
 
154 154
                 # QUARTERROUND( x3,  x7,  x11,  x15)
155
-                list($x3, $x7, $x11, $x15) = self::quarterRound($x3, $x7, $x11, $x15);
155
+                list( $x3, $x7, $x11, $x15 ) = self::quarterRound( $x3, $x7, $x11, $x15 );
156 156
 
157 157
                 # QUARTERROUND( x0,  x5,  x10,  x15)
158
-                list($x0, $x5, $x10, $x15) = self::quarterRound($x0, $x5, $x10, $x15);
158
+                list( $x0, $x5, $x10, $x15 ) = self::quarterRound( $x0, $x5, $x10, $x15 );
159 159
 
160 160
                 # QUARTERROUND( x1,  x6,  x11,  x12)
161
-                list($x1, $x6, $x11, $x12) = self::quarterRound($x1, $x6, $x11, $x12);
161
+                list( $x1, $x6, $x11, $x12 ) = self::quarterRound( $x1, $x6, $x11, $x12 );
162 162
 
163 163
                 # QUARTERROUND( x2,  x7,  x8,  x13)
164
-                list($x2, $x7, $x8, $x13) = self::quarterRound($x2, $x7, $x8, $x13);
164
+                list( $x2, $x7, $x8, $x13 ) = self::quarterRound( $x2, $x7, $x8, $x13 );
165 165
 
166 166
                 # QUARTERROUND( x3,  x4,  x9,  x14)
167
-                list($x3, $x4, $x9, $x14) = self::quarterRound($x3, $x4, $x9, $x14);
167
+                list( $x3, $x4, $x9, $x14 ) = self::quarterRound( $x3, $x4, $x9, $x14 );
168 168
             }
169 169
             /*
170 170
             x0 = PLUS(x0, j0);
@@ -185,37 +185,37 @@  discard block
 block discarded – undo
185 185
             x15 = PLUS(x15, j15);
186 186
             */
187 187
             /** @var int $x0 */
188
-            $x0  = ($x0 & 0xffffffff) + $j0;
188
+            $x0  = ( $x0 & 0xffffffff ) + $j0;
189 189
             /** @var int $x1 */
190
-            $x1  = ($x1 & 0xffffffff) + $j1;
190
+            $x1  = ( $x1 & 0xffffffff ) + $j1;
191 191
             /** @var int $x2 */
192
-            $x2  = ($x2 & 0xffffffff) + $j2;
192
+            $x2  = ( $x2 & 0xffffffff ) + $j2;
193 193
             /** @var int $x3 */
194
-            $x3  = ($x3 & 0xffffffff) + $j3;
194
+            $x3  = ( $x3 & 0xffffffff ) + $j3;
195 195
             /** @var int $x4 */
196
-            $x4  = ($x4 & 0xffffffff) + $j4;
196
+            $x4  = ( $x4 & 0xffffffff ) + $j4;
197 197
             /** @var int $x5 */
198
-            $x5  = ($x5 & 0xffffffff) + $j5;
198
+            $x5  = ( $x5 & 0xffffffff ) + $j5;
199 199
             /** @var int $x6 */
200
-            $x6  = ($x6 & 0xffffffff) + $j6;
200
+            $x6  = ( $x6 & 0xffffffff ) + $j6;
201 201
             /** @var int $x7 */
202
-            $x7  = ($x7 & 0xffffffff) + $j7;
202
+            $x7  = ( $x7 & 0xffffffff ) + $j7;
203 203
             /** @var int $x8 */
204
-            $x8  = ($x8 & 0xffffffff) + $j8;
204
+            $x8  = ( $x8 & 0xffffffff ) + $j8;
205 205
             /** @var int $x9 */
206
-            $x9  = ($x9 & 0xffffffff) + $j9;
206
+            $x9  = ( $x9 & 0xffffffff ) + $j9;
207 207
             /** @var int $x10 */
208
-            $x10 = ($x10 & 0xffffffff) + $j10;
208
+            $x10 = ( $x10 & 0xffffffff ) + $j10;
209 209
             /** @var int $x11 */
210
-            $x11 = ($x11 & 0xffffffff) + $j11;
210
+            $x11 = ( $x11 & 0xffffffff ) + $j11;
211 211
             /** @var int $x12 */
212
-            $x12 = ($x12 & 0xffffffff) + $j12;
212
+            $x12 = ( $x12 & 0xffffffff ) + $j12;
213 213
             /** @var int $x13 */
214
-            $x13 = ($x13 & 0xffffffff) + $j13;
214
+            $x13 = ( $x13 & 0xffffffff ) + $j13;
215 215
             /** @var int $x14 */
216
-            $x14 = ($x14 & 0xffffffff) + $j14;
216
+            $x14 = ( $x14 & 0xffffffff ) + $j14;
217 217
             /** @var int $x15 */
218
-            $x15 = ($x15 & 0xffffffff) + $j15;
218
+            $x15 = ( $x15 & 0xffffffff ) + $j15;
219 219
 
220 220
             /*
221 221
             x0 = XOR(x0, LOAD32_LE(m + 0));
@@ -235,22 +235,22 @@  discard block
 block discarded – undo
235 235
             x14 = XOR(x14, LOAD32_LE(m + 56));
236 236
             x15 = XOR(x15, LOAD32_LE(m + 60));
237 237
             */
238
-            $x0  ^= self::load_4(self::substr($message, 0, 4));
239
-            $x1  ^= self::load_4(self::substr($message, 4, 4));
240
-            $x2  ^= self::load_4(self::substr($message, 8, 4));
241
-            $x3  ^= self::load_4(self::substr($message, 12, 4));
242
-            $x4  ^= self::load_4(self::substr($message, 16, 4));
243
-            $x5  ^= self::load_4(self::substr($message, 20, 4));
244
-            $x6  ^= self::load_4(self::substr($message, 24, 4));
245
-            $x7  ^= self::load_4(self::substr($message, 28, 4));
246
-            $x8  ^= self::load_4(self::substr($message, 32, 4));
247
-            $x9  ^= self::load_4(self::substr($message, 36, 4));
248
-            $x10 ^= self::load_4(self::substr($message, 40, 4));
249
-            $x11 ^= self::load_4(self::substr($message, 44, 4));
250
-            $x12 ^= self::load_4(self::substr($message, 48, 4));
251
-            $x13 ^= self::load_4(self::substr($message, 52, 4));
252
-            $x14 ^= self::load_4(self::substr($message, 56, 4));
253
-            $x15 ^= self::load_4(self::substr($message, 60, 4));
238
+            $x0  ^= self::load_4( self::substr( $message, 0, 4 ) );
239
+            $x1  ^= self::load_4( self::substr( $message, 4, 4 ) );
240
+            $x2  ^= self::load_4( self::substr( $message, 8, 4 ) );
241
+            $x3  ^= self::load_4( self::substr( $message, 12, 4 ) );
242
+            $x4  ^= self::load_4( self::substr( $message, 16, 4 ) );
243
+            $x5  ^= self::load_4( self::substr( $message, 20, 4 ) );
244
+            $x6  ^= self::load_4( self::substr( $message, 24, 4 ) );
245
+            $x7  ^= self::load_4( self::substr( $message, 28, 4 ) );
246
+            $x8  ^= self::load_4( self::substr( $message, 32, 4 ) );
247
+            $x9  ^= self::load_4( self::substr( $message, 36, 4 ) );
248
+            $x10 ^= self::load_4( self::substr( $message, 40, 4 ) );
249
+            $x11 ^= self::load_4( self::substr( $message, 44, 4 ) );
250
+            $x12 ^= self::load_4( self::substr( $message, 48, 4 ) );
251
+            $x13 ^= self::load_4( self::substr( $message, 52, 4 ) );
252
+            $x14 ^= self::load_4( self::substr( $message, 56, 4 ) );
253
+            $x15 ^= self::load_4( self::substr( $message, 60, 4 ) );
254 254
 
255 255
             /*
256 256
                 j12 = PLUSONE(j12);
@@ -259,8 +259,8 @@  discard block
 block discarded – undo
259 259
                 }
260 260
              */
261 261
             ++$j12;
262
-            if ($j12 & 0xf0000000) {
263
-                throw new SodiumException('Overflow');
262
+            if ( $j12 & 0xf0000000 ) {
263
+                throw new SodiumException( 'Overflow' );
264 264
             }
265 265
 
266 266
             /*
@@ -281,41 +281,41 @@  discard block
 block discarded – undo
281 281
             STORE32_LE(c + 56, x14);
282 282
             STORE32_LE(c + 60, x15);
283 283
             */
284
-            $block = self::store32_le((int) ($x0  & 0xffffffff)) .
285
-                 self::store32_le((int) ($x1  & 0xffffffff)) .
286
-                 self::store32_le((int) ($x2  & 0xffffffff)) .
287
-                 self::store32_le((int) ($x3  & 0xffffffff)) .
288
-                 self::store32_le((int) ($x4  & 0xffffffff)) .
289
-                 self::store32_le((int) ($x5  & 0xffffffff)) .
290
-                 self::store32_le((int) ($x6  & 0xffffffff)) .
291
-                 self::store32_le((int) ($x7  & 0xffffffff)) .
292
-                 self::store32_le((int) ($x8  & 0xffffffff)) .
293
-                 self::store32_le((int) ($x9  & 0xffffffff)) .
294
-                 self::store32_le((int) ($x10 & 0xffffffff)) .
295
-                 self::store32_le((int) ($x11 & 0xffffffff)) .
296
-                 self::store32_le((int) ($x12 & 0xffffffff)) .
297
-                 self::store32_le((int) ($x13 & 0xffffffff)) .
298
-                 self::store32_le((int) ($x14 & 0xffffffff)) .
299
-                 self::store32_le((int) ($x15 & 0xffffffff));
284
+            $block = self::store32_le( (int)( $x0  & 0xffffffff ) ) .
285
+                 self::store32_le( (int)( $x1  & 0xffffffff ) ) .
286
+                 self::store32_le( (int)( $x2  & 0xffffffff ) ) .
287
+                 self::store32_le( (int)( $x3  & 0xffffffff ) ) .
288
+                 self::store32_le( (int)( $x4  & 0xffffffff ) ) .
289
+                 self::store32_le( (int)( $x5  & 0xffffffff ) ) .
290
+                 self::store32_le( (int)( $x6  & 0xffffffff ) ) .
291
+                 self::store32_le( (int)( $x7  & 0xffffffff ) ) .
292
+                 self::store32_le( (int)( $x8  & 0xffffffff ) ) .
293
+                 self::store32_le( (int)( $x9  & 0xffffffff ) ) .
294
+                 self::store32_le( (int)( $x10 & 0xffffffff ) ) .
295
+                 self::store32_le( (int)( $x11 & 0xffffffff ) ) .
296
+                 self::store32_le( (int)( $x12 & 0xffffffff ) ) .
297
+                 self::store32_le( (int)( $x13 & 0xffffffff ) ) .
298
+                 self::store32_le( (int)( $x14 & 0xffffffff ) ) .
299
+                 self::store32_le( (int)( $x15 & 0xffffffff ) );
300 300
 
301 301
             /* Partial block */
302
-            if ($bytes < 64) {
303
-                $c .= self::substr($block, 0, $bytes);
302
+            if ( $bytes < 64 ) {
303
+                $c .= self::substr( $block, 0, $bytes );
304 304
                 break;
305 305
             }
306 306
 
307 307
             /* Full block */
308 308
             $c .= $block;
309 309
             $bytes -= 64;
310
-            if ($bytes <= 0) {
310
+            if ( $bytes <= 0 ) {
311 311
                 break;
312 312
             }
313
-            $message = self::substr($message, 64);
313
+            $message = self::substr( $message, 64 );
314 314
         }
315 315
         /* end for(;;) loop */
316 316
 
317
-        $ctx[12] = $j12;
318
-        $ctx[13] = $j13;
317
+        $ctx[ 12 ] = $j12;
318
+        $ctx[ 13 ] = $j13;
319 319
         return $c;
320 320
     }
321 321
 
@@ -329,11 +329,11 @@  discard block
 block discarded – undo
329 329
      * @throws SodiumException
330 330
      * @throws TypeError
331 331
      */
332
-    public static function stream($len = 64, $nonce = '', $key = '')
332
+    public static function stream( $len = 64, $nonce = '', $key = '' )
333 333
     {
334 334
         return self::encryptBytes(
335
-            new ParagonIE_Sodium_Core_ChaCha20_Ctx($key, $nonce),
336
-            str_repeat("\x00", $len)
335
+            new ParagonIE_Sodium_Core_ChaCha20_Ctx( $key, $nonce ),
336
+            str_repeat( "\x00", $len )
337 337
         );
338 338
     }
339 339
 
@@ -347,11 +347,11 @@  discard block
 block discarded – undo
347 347
      * @throws SodiumException
348 348
      * @throws TypeError
349 349
      */
350
-    public static function ietfStream($len, $nonce = '', $key = '')
350
+    public static function ietfStream( $len, $nonce = '', $key = '' )
351 351
     {
352 352
         return self::encryptBytes(
353
-            new ParagonIE_Sodium_Core_ChaCha20_IetfCtx($key, $nonce),
354
-            str_repeat("\x00", $len)
353
+            new ParagonIE_Sodium_Core_ChaCha20_IetfCtx( $key, $nonce ),
354
+            str_repeat( "\x00", $len )
355 355
         );
356 356
     }
357 357
 
@@ -366,10 +366,10 @@  discard block
 block discarded – undo
366 366
      * @throws SodiumException
367 367
      * @throws TypeError
368 368
      */
369
-    public static function ietfStreamXorIc($message, $nonce = '', $key = '', $ic = '')
369
+    public static function ietfStreamXorIc( $message, $nonce = '', $key = '', $ic = '' )
370 370
     {
371 371
         return self::encryptBytes(
372
-            new ParagonIE_Sodium_Core_ChaCha20_IetfCtx($key, $nonce, $ic),
372
+            new ParagonIE_Sodium_Core_ChaCha20_IetfCtx( $key, $nonce, $ic ),
373 373
             $message
374 374
         );
375 375
     }
@@ -385,10 +385,10 @@  discard block
 block discarded – undo
385 385
      * @throws SodiumException
386 386
      * @throws TypeError
387 387
      */
388
-    public static function streamXorIc($message, $nonce = '', $key = '', $ic = '')
388
+    public static function streamXorIc( $message, $nonce = '', $key = '', $ic = '' )
389 389
     {
390 390
         return self::encryptBytes(
391
-            new ParagonIE_Sodium_Core_ChaCha20_Ctx($key, $nonce, $ic),
391
+            new ParagonIE_Sodium_Core_ChaCha20_Ctx( $key, $nonce, $ic ),
392 392
             $message
393 393
         );
394 394
     }
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Core/HChaCha20.php 3 patches
Indentation   +86 added lines, -86 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Core_HChaCha20', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -9,100 +9,100 @@  discard block
 block discarded – undo
9 9
  */
10 10
 class ParagonIE_Sodium_Core_HChaCha20 extends ParagonIE_Sodium_Core_ChaCha20
11 11
 {
12
-    /**
13
-     * @param string $in
14
-     * @param string $key
15
-     * @param string|null $c
16
-     * @return string
17
-     * @throws TypeError
18
-     */
19
-    public static function hChaCha20($in = '', $key = '', $c = null)
20
-    {
21
-        $ctx = array();
12
+	/**
13
+	 * @param string $in
14
+	 * @param string $key
15
+	 * @param string|null $c
16
+	 * @return string
17
+	 * @throws TypeError
18
+	 */
19
+	public static function hChaCha20($in = '', $key = '', $c = null)
20
+	{
21
+		$ctx = array();
22 22
 
23
-        if ($c === null) {
24
-            $ctx[0] = 0x61707865;
25
-            $ctx[1] = 0x3320646e;
26
-            $ctx[2] = 0x79622d32;
27
-            $ctx[3] = 0x6b206574;
28
-        } else {
29
-            $ctx[0] = self::load_4(self::substr($c,  0, 4));
30
-            $ctx[1] = self::load_4(self::substr($c,  4, 4));
31
-            $ctx[2] = self::load_4(self::substr($c,  8, 4));
32
-            $ctx[3] = self::load_4(self::substr($c, 12, 4));
33
-        }
34
-        $ctx[4]  = self::load_4(self::substr($key,  0, 4));
35
-        $ctx[5]  = self::load_4(self::substr($key,  4, 4));
36
-        $ctx[6]  = self::load_4(self::substr($key,  8, 4));
37
-        $ctx[7]  = self::load_4(self::substr($key, 12, 4));
38
-        $ctx[8]  = self::load_4(self::substr($key, 16, 4));
39
-        $ctx[9]  = self::load_4(self::substr($key, 20, 4));
40
-        $ctx[10] = self::load_4(self::substr($key, 24, 4));
41
-        $ctx[11] = self::load_4(self::substr($key, 28, 4));
42
-        $ctx[12] = self::load_4(self::substr($in,   0, 4));
43
-        $ctx[13] = self::load_4(self::substr($in,   4, 4));
44
-        $ctx[14] = self::load_4(self::substr($in,   8, 4));
45
-        $ctx[15] = self::load_4(self::substr($in,  12, 4));
46
-        return self::hChaCha20Bytes($ctx);
47
-    }
23
+		if ($c === null) {
24
+			$ctx[0] = 0x61707865;
25
+			$ctx[1] = 0x3320646e;
26
+			$ctx[2] = 0x79622d32;
27
+			$ctx[3] = 0x6b206574;
28
+		} else {
29
+			$ctx[0] = self::load_4(self::substr($c,  0, 4));
30
+			$ctx[1] = self::load_4(self::substr($c,  4, 4));
31
+			$ctx[2] = self::load_4(self::substr($c,  8, 4));
32
+			$ctx[3] = self::load_4(self::substr($c, 12, 4));
33
+		}
34
+		$ctx[4]  = self::load_4(self::substr($key,  0, 4));
35
+		$ctx[5]  = self::load_4(self::substr($key,  4, 4));
36
+		$ctx[6]  = self::load_4(self::substr($key,  8, 4));
37
+		$ctx[7]  = self::load_4(self::substr($key, 12, 4));
38
+		$ctx[8]  = self::load_4(self::substr($key, 16, 4));
39
+		$ctx[9]  = self::load_4(self::substr($key, 20, 4));
40
+		$ctx[10] = self::load_4(self::substr($key, 24, 4));
41
+		$ctx[11] = self::load_4(self::substr($key, 28, 4));
42
+		$ctx[12] = self::load_4(self::substr($in,   0, 4));
43
+		$ctx[13] = self::load_4(self::substr($in,   4, 4));
44
+		$ctx[14] = self::load_4(self::substr($in,   8, 4));
45
+		$ctx[15] = self::load_4(self::substr($in,  12, 4));
46
+		return self::hChaCha20Bytes($ctx);
47
+	}
48 48
 
49
-    /**
50
-     * @param array $ctx
51
-     * @return string
52
-     * @throws TypeError
53
-     */
54
-    protected static function hChaCha20Bytes(array $ctx)
55
-    {
56
-        $x0  = (int) $ctx[0];
57
-        $x1  = (int) $ctx[1];
58
-        $x2  = (int) $ctx[2];
59
-        $x3  = (int) $ctx[3];
60
-        $x4  = (int) $ctx[4];
61
-        $x5  = (int) $ctx[5];
62
-        $x6  = (int) $ctx[6];
63
-        $x7  = (int) $ctx[7];
64
-        $x8  = (int) $ctx[8];
65
-        $x9  = (int) $ctx[9];
66
-        $x10 = (int) $ctx[10];
67
-        $x11 = (int) $ctx[11];
68
-        $x12 = (int) $ctx[12];
69
-        $x13 = (int) $ctx[13];
70
-        $x14 = (int) $ctx[14];
71
-        $x15 = (int) $ctx[15];
49
+	/**
50
+	 * @param array $ctx
51
+	 * @return string
52
+	 * @throws TypeError
53
+	 */
54
+	protected static function hChaCha20Bytes(array $ctx)
55
+	{
56
+		$x0  = (int) $ctx[0];
57
+		$x1  = (int) $ctx[1];
58
+		$x2  = (int) $ctx[2];
59
+		$x3  = (int) $ctx[3];
60
+		$x4  = (int) $ctx[4];
61
+		$x5  = (int) $ctx[5];
62
+		$x6  = (int) $ctx[6];
63
+		$x7  = (int) $ctx[7];
64
+		$x8  = (int) $ctx[8];
65
+		$x9  = (int) $ctx[9];
66
+		$x10 = (int) $ctx[10];
67
+		$x11 = (int) $ctx[11];
68
+		$x12 = (int) $ctx[12];
69
+		$x13 = (int) $ctx[13];
70
+		$x14 = (int) $ctx[14];
71
+		$x15 = (int) $ctx[15];
72 72
 
73
-        for ($i = 0; $i < 10; ++$i) {
74
-            # QUARTERROUND( x0,  x4,  x8,  x12)
75
-            list($x0, $x4, $x8, $x12) = self::quarterRound($x0, $x4, $x8, $x12);
73
+		for ($i = 0; $i < 10; ++$i) {
74
+			# QUARTERROUND( x0,  x4,  x8,  x12)
75
+			list($x0, $x4, $x8, $x12) = self::quarterRound($x0, $x4, $x8, $x12);
76 76
 
77
-            # QUARTERROUND( x1,  x5,  x9,  x13)
78
-            list($x1, $x5, $x9, $x13) = self::quarterRound($x1, $x5, $x9, $x13);
77
+			# QUARTERROUND( x1,  x5,  x9,  x13)
78
+			list($x1, $x5, $x9, $x13) = self::quarterRound($x1, $x5, $x9, $x13);
79 79
 
80
-            # QUARTERROUND( x2,  x6,  x10,  x14)
81
-            list($x2, $x6, $x10, $x14) = self::quarterRound($x2, $x6, $x10, $x14);
80
+			# QUARTERROUND( x2,  x6,  x10,  x14)
81
+			list($x2, $x6, $x10, $x14) = self::quarterRound($x2, $x6, $x10, $x14);
82 82
 
83
-            # QUARTERROUND( x3,  x7,  x11,  x15)
84
-            list($x3, $x7, $x11, $x15) = self::quarterRound($x3, $x7, $x11, $x15);
83
+			# QUARTERROUND( x3,  x7,  x11,  x15)
84
+			list($x3, $x7, $x11, $x15) = self::quarterRound($x3, $x7, $x11, $x15);
85 85
 
86
-            # QUARTERROUND( x0,  x5,  x10,  x15)
87
-            list($x0, $x5, $x10, $x15) = self::quarterRound($x0, $x5, $x10, $x15);
86
+			# QUARTERROUND( x0,  x5,  x10,  x15)
87
+			list($x0, $x5, $x10, $x15) = self::quarterRound($x0, $x5, $x10, $x15);
88 88
 
89
-            # QUARTERROUND( x1,  x6,  x11,  x12)
90
-            list($x1, $x6, $x11, $x12) = self::quarterRound($x1, $x6, $x11, $x12);
89
+			# QUARTERROUND( x1,  x6,  x11,  x12)
90
+			list($x1, $x6, $x11, $x12) = self::quarterRound($x1, $x6, $x11, $x12);
91 91
 
92
-            # QUARTERROUND( x2,  x7,  x8,  x13)
93
-            list($x2, $x7, $x8, $x13) = self::quarterRound($x2, $x7, $x8, $x13);
92
+			# QUARTERROUND( x2,  x7,  x8,  x13)
93
+			list($x2, $x7, $x8, $x13) = self::quarterRound($x2, $x7, $x8, $x13);
94 94
 
95
-            # QUARTERROUND( x3,  x4,  x9,  x14)
96
-            list($x3, $x4, $x9, $x14) = self::quarterRound($x3, $x4, $x9, $x14);
97
-        }
95
+			# QUARTERROUND( x3,  x4,  x9,  x14)
96
+			list($x3, $x4, $x9, $x14) = self::quarterRound($x3, $x4, $x9, $x14);
97
+		}
98 98
 
99
-        return self::store32_le((int) ($x0  & 0xffffffff)) .
100
-            self::store32_le((int) ($x1  & 0xffffffff)) .
101
-            self::store32_le((int) ($x2  & 0xffffffff)) .
102
-            self::store32_le((int) ($x3  & 0xffffffff)) .
103
-            self::store32_le((int) ($x12 & 0xffffffff)) .
104
-            self::store32_le((int) ($x13 & 0xffffffff)) .
105
-            self::store32_le((int) ($x14 & 0xffffffff)) .
106
-            self::store32_le((int) ($x15 & 0xffffffff));
107
-    }
99
+		return self::store32_le((int) ($x0  & 0xffffffff)) .
100
+			self::store32_le((int) ($x1  & 0xffffffff)) .
101
+			self::store32_le((int) ($x2  & 0xffffffff)) .
102
+			self::store32_le((int) ($x3  & 0xffffffff)) .
103
+			self::store32_le((int) ($x12 & 0xffffffff)) .
104
+			self::store32_le((int) ($x13 & 0xffffffff)) .
105
+			self::store32_le((int) ($x14 & 0xffffffff)) .
106
+			self::store32_le((int) ($x15 & 0xffffffff));
107
+	}
108 108
 }
Please login to merge, or discard this patch.
Braces   +3 added lines, -6 removed lines patch added patch discarded remove patch
@@ -7,8 +7,7 @@  discard block
 block discarded – undo
7 7
 /**
8 8
  * Class ParagonIE_Sodium_Core_HChaCha20
9 9
  */
10
-class ParagonIE_Sodium_Core_HChaCha20 extends ParagonIE_Sodium_Core_ChaCha20
11
-{
10
+class ParagonIE_Sodium_Core_HChaCha20 extends ParagonIE_Sodium_Core_ChaCha20 {
12 11
     /**
13 12
      * @param string $in
14 13
      * @param string $key
@@ -16,8 +15,7 @@  discard block
 block discarded – undo
16 15
      * @return string
17 16
      * @throws TypeError
18 17
      */
19
-    public static function hChaCha20($in = '', $key = '', $c = null)
20
-    {
18
+    public static function hChaCha20($in = '', $key = '', $c = null) {
21 19
         $ctx = array();
22 20
 
23 21
         if ($c === null) {
@@ -51,8 +49,7 @@  discard block
 block discarded – undo
51 49
      * @return string
52 50
      * @throws TypeError
53 51
      */
54
-    protected static function hChaCha20Bytes(array $ctx)
55
-    {
52
+    protected static function hChaCha20Bytes(array $ctx) {
56 53
         $x0  = (int) $ctx[0];
57 54
         $x1  = (int) $ctx[1];
58 55
         $x2  = (int) $ctx[2];
Please login to merge, or discard this patch.
Spacing   +58 added lines, -58 removed lines patch added patch discarded remove patch
@@ -1,6 +1,6 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3
-if (class_exists('ParagonIE_Sodium_Core_HChaCha20', false)) {
3
+if ( class_exists( 'ParagonIE_Sodium_Core_HChaCha20', false ) ) {
4 4
     return;
5 5
 }
6 6
 
@@ -16,34 +16,34 @@  discard block
 block discarded – undo
16 16
      * @return string
17 17
      * @throws TypeError
18 18
      */
19
-    public static function hChaCha20($in = '', $key = '', $c = null)
19
+    public static function hChaCha20( $in = '', $key = '', $c = null )
20 20
     {
21 21
         $ctx = array();
22 22
 
23
-        if ($c === null) {
24
-            $ctx[0] = 0x61707865;
25
-            $ctx[1] = 0x3320646e;
26
-            $ctx[2] = 0x79622d32;
27
-            $ctx[3] = 0x6b206574;
23
+        if ( $c === null ) {
24
+            $ctx[ 0 ] = 0x61707865;
25
+            $ctx[ 1 ] = 0x3320646e;
26
+            $ctx[ 2 ] = 0x79622d32;
27
+            $ctx[ 3 ] = 0x6b206574;
28 28
         } else {
29
-            $ctx[0] = self::load_4(self::substr($c,  0, 4));
30
-            $ctx[1] = self::load_4(self::substr($c,  4, 4));
31
-            $ctx[2] = self::load_4(self::substr($c,  8, 4));
32
-            $ctx[3] = self::load_4(self::substr($c, 12, 4));
29
+            $ctx[ 0 ] = self::load_4( self::substr( $c, 0, 4 ) );
30
+            $ctx[ 1 ] = self::load_4( self::substr( $c, 4, 4 ) );
31
+            $ctx[ 2 ] = self::load_4( self::substr( $c, 8, 4 ) );
32
+            $ctx[ 3 ] = self::load_4( self::substr( $c, 12, 4 ) );
33 33
         }
34
-        $ctx[4]  = self::load_4(self::substr($key,  0, 4));
35
-        $ctx[5]  = self::load_4(self::substr($key,  4, 4));
36
-        $ctx[6]  = self::load_4(self::substr($key,  8, 4));
37
-        $ctx[7]  = self::load_4(self::substr($key, 12, 4));
38
-        $ctx[8]  = self::load_4(self::substr($key, 16, 4));
39
-        $ctx[9]  = self::load_4(self::substr($key, 20, 4));
40
-        $ctx[10] = self::load_4(self::substr($key, 24, 4));
41
-        $ctx[11] = self::load_4(self::substr($key, 28, 4));
42
-        $ctx[12] = self::load_4(self::substr($in,   0, 4));
43
-        $ctx[13] = self::load_4(self::substr($in,   4, 4));
44
-        $ctx[14] = self::load_4(self::substr($in,   8, 4));
45
-        $ctx[15] = self::load_4(self::substr($in,  12, 4));
46
-        return self::hChaCha20Bytes($ctx);
34
+        $ctx[ 4 ]  = self::load_4( self::substr( $key, 0, 4 ) );
35
+        $ctx[ 5 ]  = self::load_4( self::substr( $key, 4, 4 ) );
36
+        $ctx[ 6 ]  = self::load_4( self::substr( $key, 8, 4 ) );
37
+        $ctx[ 7 ]  = self::load_4( self::substr( $key, 12, 4 ) );
38
+        $ctx[ 8 ]  = self::load_4( self::substr( $key, 16, 4 ) );
39
+        $ctx[ 9 ]  = self::load_4( self::substr( $key, 20, 4 ) );
40
+        $ctx[ 10 ] = self::load_4( self::substr( $key, 24, 4 ) );
41
+        $ctx[ 11 ] = self::load_4( self::substr( $key, 28, 4 ) );
42
+        $ctx[ 12 ] = self::load_4( self::substr( $in, 0, 4 ) );
43
+        $ctx[ 13 ] = self::load_4( self::substr( $in, 4, 4 ) );
44
+        $ctx[ 14 ] = self::load_4( self::substr( $in, 8, 4 ) );
45
+        $ctx[ 15 ] = self::load_4( self::substr( $in, 12, 4 ) );
46
+        return self::hChaCha20Bytes( $ctx );
47 47
     }
48 48
 
49 49
     /**
@@ -51,58 +51,58 @@  discard block
 block discarded – undo
51 51
      * @return string
52 52
      * @throws TypeError
53 53
      */
54
-    protected static function hChaCha20Bytes(array $ctx)
54
+    protected static function hChaCha20Bytes( array $ctx )
55 55
     {
56
-        $x0  = (int) $ctx[0];
57
-        $x1  = (int) $ctx[1];
58
-        $x2  = (int) $ctx[2];
59
-        $x3  = (int) $ctx[3];
60
-        $x4  = (int) $ctx[4];
61
-        $x5  = (int) $ctx[5];
62
-        $x6  = (int) $ctx[6];
63
-        $x7  = (int) $ctx[7];
64
-        $x8  = (int) $ctx[8];
65
-        $x9  = (int) $ctx[9];
66
-        $x10 = (int) $ctx[10];
67
-        $x11 = (int) $ctx[11];
68
-        $x12 = (int) $ctx[12];
69
-        $x13 = (int) $ctx[13];
70
-        $x14 = (int) $ctx[14];
71
-        $x15 = (int) $ctx[15];
56
+        $x0  = (int)$ctx[ 0 ];
57
+        $x1  = (int)$ctx[ 1 ];
58
+        $x2  = (int)$ctx[ 2 ];
59
+        $x3  = (int)$ctx[ 3 ];
60
+        $x4  = (int)$ctx[ 4 ];
61
+        $x5  = (int)$ctx[ 5 ];
62
+        $x6  = (int)$ctx[ 6 ];
63
+        $x7  = (int)$ctx[ 7 ];
64
+        $x8  = (int)$ctx[ 8 ];
65
+        $x9  = (int)$ctx[ 9 ];
66
+        $x10 = (int)$ctx[ 10 ];
67
+        $x11 = (int)$ctx[ 11 ];
68
+        $x12 = (int)$ctx[ 12 ];
69
+        $x13 = (int)$ctx[ 13 ];
70
+        $x14 = (int)$ctx[ 14 ];
71
+        $x15 = (int)$ctx[ 15 ];
72 72
 
73
-        for ($i = 0; $i < 10; ++$i) {
73
+        for ( $i = 0; $i < 10; ++$i ) {
74 74
             # QUARTERROUND( x0,  x4,  x8,  x12)
75
-            list($x0, $x4, $x8, $x12) = self::quarterRound($x0, $x4, $x8, $x12);
75
+            list( $x0, $x4, $x8, $x12 ) = self::quarterRound( $x0, $x4, $x8, $x12 );
76 76
 
77 77
             # QUARTERROUND( x1,  x5,  x9,  x13)
78
-            list($x1, $x5, $x9, $x13) = self::quarterRound($x1, $x5, $x9, $x13);
78
+            list( $x1, $x5, $x9, $x13 ) = self::quarterRound( $x1, $x5, $x9, $x13 );
79 79
 
80 80
             # QUARTERROUND( x2,  x6,  x10,  x14)
81
-            list($x2, $x6, $x10, $x14) = self::quarterRound($x2, $x6, $x10, $x14);
81
+            list( $x2, $x6, $x10, $x14 ) = self::quarterRound( $x2, $x6, $x10, $x14 );
82 82
 
83 83
             # QUARTERROUND( x3,  x7,  x11,  x15)
84
-            list($x3, $x7, $x11, $x15) = self::quarterRound($x3, $x7, $x11, $x15);
84
+            list( $x3, $x7, $x11, $x15 ) = self::quarterRound( $x3, $x7, $x11, $x15 );
85 85
 
86 86
             # QUARTERROUND( x0,  x5,  x10,  x15)
87
-            list($x0, $x5, $x10, $x15) = self::quarterRound($x0, $x5, $x10, $x15);
87
+            list( $x0, $x5, $x10, $x15 ) = self::quarterRound( $x0, $x5, $x10, $x15 );
88 88
 
89 89
             # QUARTERROUND( x1,  x6,  x11,  x12)
90
-            list($x1, $x6, $x11, $x12) = self::quarterRound($x1, $x6, $x11, $x12);
90
+            list( $x1, $x6, $x11, $x12 ) = self::quarterRound( $x1, $x6, $x11, $x12 );
91 91
 
92 92
             # QUARTERROUND( x2,  x7,  x8,  x13)
93
-            list($x2, $x7, $x8, $x13) = self::quarterRound($x2, $x7, $x8, $x13);
93
+            list( $x2, $x7, $x8, $x13 ) = self::quarterRound( $x2, $x7, $x8, $x13 );
94 94
 
95 95
             # QUARTERROUND( x3,  x4,  x9,  x14)
96
-            list($x3, $x4, $x9, $x14) = self::quarterRound($x3, $x4, $x9, $x14);
96
+            list( $x3, $x4, $x9, $x14 ) = self::quarterRound( $x3, $x4, $x9, $x14 );
97 97
         }
98 98
 
99
-        return self::store32_le((int) ($x0  & 0xffffffff)) .
100
-            self::store32_le((int) ($x1  & 0xffffffff)) .
101
-            self::store32_le((int) ($x2  & 0xffffffff)) .
102
-            self::store32_le((int) ($x3  & 0xffffffff)) .
103
-            self::store32_le((int) ($x12 & 0xffffffff)) .
104
-            self::store32_le((int) ($x13 & 0xffffffff)) .
105
-            self::store32_le((int) ($x14 & 0xffffffff)) .
106
-            self::store32_le((int) ($x15 & 0xffffffff));
99
+        return self::store32_le( (int)( $x0  & 0xffffffff ) ) .
100
+            self::store32_le( (int)( $x1  & 0xffffffff ) ) .
101
+            self::store32_le( (int)( $x2  & 0xffffffff ) ) .
102
+            self::store32_le( (int)( $x3  & 0xffffffff ) ) .
103
+            self::store32_le( (int)( $x12 & 0xffffffff ) ) .
104
+            self::store32_le( (int)( $x13 & 0xffffffff ) ) .
105
+            self::store32_le( (int)( $x14 & 0xffffffff ) ) .
106
+            self::store32_le( (int)( $x15 & 0xffffffff ) );
107 107
     }
108 108
 }
Please login to merge, or discard this patch.