Completed
Pull Request — develop (#1742)
by
unknown
18:03
created
vendor/paragonie/sodium_compat/autoload.php 1 patch
Indentation   +51 added lines, -51 removed lines patch added patch discarded remove patch
@@ -1,72 +1,72 @@
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (PHP_VERSION_ID < 70000) {
4
-    if (!is_callable('sodiumCompatAutoloader')) {
5
-        /**
6
-         * Sodium_Compat autoloader.
7
-         *
8
-         * @param string $class Class name to be autoloaded.
9
-         *
10
-         * @return bool         Stop autoloading?
11
-         */
12
-        function sodiumCompatAutoloader($class)
13
-        {
14
-            $namespace = 'ParagonIE_Sodium_';
15
-            // Does the class use the namespace prefix?
16
-            $len = strlen($namespace);
17
-            if (strncmp($namespace, $class, $len) !== 0) {
18
-                // no, move to the next registered autoloader
19
-                return false;
20
-            }
4
+	if (!is_callable('sodiumCompatAutoloader')) {
5
+		/**
6
+		 * Sodium_Compat autoloader.
7
+		 *
8
+		 * @param string $class Class name to be autoloaded.
9
+		 *
10
+		 * @return bool         Stop autoloading?
11
+		 */
12
+		function sodiumCompatAutoloader($class)
13
+		{
14
+			$namespace = 'ParagonIE_Sodium_';
15
+			// Does the class use the namespace prefix?
16
+			$len = strlen($namespace);
17
+			if (strncmp($namespace, $class, $len) !== 0) {
18
+				// no, move to the next registered autoloader
19
+				return false;
20
+			}
21 21
 
22
-            // Get the relative class name
23
-            $relative_class = substr($class, $len);
22
+			// Get the relative class name
23
+			$relative_class = substr($class, $len);
24 24
 
25
-            // Replace the namespace prefix with the base directory, replace namespace
26
-            // separators with directory separators in the relative class name, append
27
-            // with .php
28
-            $file = dirname(__FILE__) . '/src/' . str_replace('_', '/', $relative_class) . '.php';
29
-            // if the file exists, require it
30
-            if (file_exists($file)) {
31
-                require_once $file;
32
-                return true;
33
-            }
34
-            return false;
35
-        }
25
+			// Replace the namespace prefix with the base directory, replace namespace
26
+			// separators with directory separators in the relative class name, append
27
+			// with .php
28
+			$file = dirname(__FILE__) . '/src/' . str_replace('_', '/', $relative_class) . '.php';
29
+			// if the file exists, require it
30
+			if (file_exists($file)) {
31
+				require_once $file;
32
+				return true;
33
+			}
34
+			return false;
35
+		}
36 36
 
37
-        // Now that we have an autoloader, let's register it!
38
-        spl_autoload_register('sodiumCompatAutoloader');
39
-    }
37
+		// Now that we have an autoloader, let's register it!
38
+		spl_autoload_register('sodiumCompatAutoloader');
39
+	}
40 40
 } else {
41
-    require_once dirname(__FILE__) . '/autoload-php7.php';
41
+	require_once dirname(__FILE__) . '/autoload-php7.php';
42 42
 }
43 43
 
44 44
 /* Explicitly, always load the Compat class: */
45 45
 require_once dirname(__FILE__) . '/src/Compat.php';
46 46
 
47 47
 if (!class_exists('SodiumException', false)) {
48
-    require_once dirname(__FILE__) . '/src/SodiumException.php';
48
+	require_once dirname(__FILE__) . '/src/SodiumException.php';
49 49
 }
50 50
 if (PHP_VERSION_ID >= 50300) {
51
-    // Namespaces didn't exist before 5.3.0, so don't even try to use this
52
-    // unless PHP >= 5.3.0
53
-    require_once dirname(__FILE__) . '/lib/namespaced.php';
54
-    require_once dirname(__FILE__) . '/lib/sodium_compat.php';
51
+	// Namespaces didn't exist before 5.3.0, so don't even try to use this
52
+	// unless PHP >= 5.3.0
53
+	require_once dirname(__FILE__) . '/lib/namespaced.php';
54
+	require_once dirname(__FILE__) . '/lib/sodium_compat.php';
55 55
 } else {
56
-    require_once dirname(__FILE__) . '/src/PHP52/SplFixedArray.php';
56
+	require_once dirname(__FILE__) . '/src/PHP52/SplFixedArray.php';
57 57
 }
58 58
 if (PHP_VERSION_ID < 70200 || !extension_loaded('sodium')) {
59
-    if (PHP_VERSION_ID >= 50300 && !defined('SODIUM_CRYPTO_SCALARMULT_BYTES')) {
60
-        require_once dirname(__FILE__) . '/lib/php72compat_const.php';
61
-    }
62
-    if (PHP_VERSION_ID >= 70000) {
63
-        assert(class_exists('ParagonIE_Sodium_Compat'), 'Possible filesystem/autoloader bug?');
64
-    } else {
65
-        assert(class_exists('ParagonIE_Sodium_Compat'));
66
-    }
67
-    require_once(dirname(__FILE__) . '/lib/php72compat.php');
59
+	if (PHP_VERSION_ID >= 50300 && !defined('SODIUM_CRYPTO_SCALARMULT_BYTES')) {
60
+		require_once dirname(__FILE__) . '/lib/php72compat_const.php';
61
+	}
62
+	if (PHP_VERSION_ID >= 70000) {
63
+		assert(class_exists('ParagonIE_Sodium_Compat'), 'Possible filesystem/autoloader bug?');
64
+	} else {
65
+		assert(class_exists('ParagonIE_Sodium_Compat'));
66
+	}
67
+	require_once(dirname(__FILE__) . '/lib/php72compat.php');
68 68
 } elseif (!function_exists('sodium_crypto_stream_xchacha20_xor')) {
69
-    // Older versions of {PHP, ext/sodium} will not define these
70
-    require_once(dirname(__FILE__) . '/lib/php72compat.php');
69
+	// Older versions of {PHP, ext/sodium} will not define these
70
+	require_once(dirname(__FILE__) . '/lib/php72compat.php');
71 71
 }
72 72
 require_once(dirname(__FILE__) . '/lib/ristretto255.php');
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/autoload-php7.php 1 patch
Indentation   +20 added lines, -20 removed lines patch added patch discarded remove patch
@@ -3,29 +3,29 @@
 block discarded – undo
3 3
  This file should only ever be loaded on PHP 7+
4 4
  */
5 5
 if (PHP_VERSION_ID < 70000) {
6
-    return;
6
+	return;
7 7
 }
8 8
 
9 9
 spl_autoload_register(function ($class) {
10
-    $namespace = 'ParagonIE_Sodium_';
11
-    // Does the class use the namespace prefix?
12
-    $len = strlen($namespace);
13
-    if (strncmp($namespace, $class, $len) !== 0) {
14
-        // no, move to the next registered autoloader
15
-        return false;
16
-    }
10
+	$namespace = 'ParagonIE_Sodium_';
11
+	// Does the class use the namespace prefix?
12
+	$len = strlen($namespace);
13
+	if (strncmp($namespace, $class, $len) !== 0) {
14
+		// no, move to the next registered autoloader
15
+		return false;
16
+	}
17 17
 
18
-    // Get the relative class name
19
-    $relative_class = substr($class, $len);
18
+	// Get the relative class name
19
+	$relative_class = substr($class, $len);
20 20
 
21
-    // Replace the namespace prefix with the base directory, replace namespace
22
-    // separators with directory separators in the relative class name, append
23
-    // with .php
24
-    $file = dirname(__FILE__) . '/src/' . str_replace('_', '/', $relative_class) . '.php';
25
-    // if the file exists, require it
26
-    if (file_exists($file)) {
27
-        require_once $file;
28
-        return true;
29
-    }
30
-    return false;
21
+	// Replace the namespace prefix with the base directory, replace namespace
22
+	// separators with directory separators in the relative class name, append
23
+	// with .php
24
+	$file = dirname(__FILE__) . '/src/' . str_replace('_', '/', $relative_class) . '.php';
25
+	// if the file exists, require it
26
+	if (file_exists($file)) {
27
+		require_once $file;
28
+		return true;
29
+	}
30
+	return false;
31 31
 });
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/autoload-phpunit.php 1 patch
Indentation   +1 added lines, -1 removed lines patch added patch discarded remove patch
@@ -3,6 +3,6 @@
 block discarded – undo
3 3
 require_once (dirname(__FILE__) . '/vendor/autoload.php');
4 4
 
5 5
 if (PHP_VERSION_ID >= 50300) {
6
-    require_once (dirname(__FILE__) . '/tests/phpunit-shim.php');
6
+	require_once (dirname(__FILE__) . '/tests/phpunit-shim.php');
7 7
 }
8 8
 require_once (dirname(__FILE__) . '/autoload.php');
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Crypto.php 1 patch
Indentation   +1639 added lines, -1639 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Crypto', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -14,1642 +14,1642 @@  discard block
 block discarded – undo
14 14
  */
15 15
 abstract class ParagonIE_Sodium_Crypto
16 16
 {
17
-    const aead_chacha20poly1305_KEYBYTES = 32;
18
-    const aead_chacha20poly1305_NSECBYTES = 0;
19
-    const aead_chacha20poly1305_NPUBBYTES = 8;
20
-    const aead_chacha20poly1305_ABYTES = 16;
21
-
22
-    const aead_chacha20poly1305_IETF_KEYBYTES = 32;
23
-    const aead_chacha20poly1305_IETF_NSECBYTES = 0;
24
-    const aead_chacha20poly1305_IETF_NPUBBYTES = 12;
25
-    const aead_chacha20poly1305_IETF_ABYTES = 16;
26
-
27
-    const aead_xchacha20poly1305_IETF_KEYBYTES = 32;
28
-    const aead_xchacha20poly1305_IETF_NSECBYTES = 0;
29
-    const aead_xchacha20poly1305_IETF_NPUBBYTES = 24;
30
-    const aead_xchacha20poly1305_IETF_ABYTES = 16;
31
-
32
-    const box_curve25519xsalsa20poly1305_SEEDBYTES = 32;
33
-    const box_curve25519xsalsa20poly1305_PUBLICKEYBYTES = 32;
34
-    const box_curve25519xsalsa20poly1305_SECRETKEYBYTES = 32;
35
-    const box_curve25519xsalsa20poly1305_BEFORENMBYTES = 32;
36
-    const box_curve25519xsalsa20poly1305_NONCEBYTES = 24;
37
-    const box_curve25519xsalsa20poly1305_MACBYTES = 16;
38
-    const box_curve25519xsalsa20poly1305_BOXZEROBYTES = 16;
39
-    const box_curve25519xsalsa20poly1305_ZEROBYTES = 32;
40
-
41
-    const onetimeauth_poly1305_BYTES = 16;
42
-    const onetimeauth_poly1305_KEYBYTES = 32;
43
-
44
-    const secretbox_xsalsa20poly1305_KEYBYTES = 32;
45
-    const secretbox_xsalsa20poly1305_NONCEBYTES = 24;
46
-    const secretbox_xsalsa20poly1305_MACBYTES = 16;
47
-    const secretbox_xsalsa20poly1305_BOXZEROBYTES = 16;
48
-    const secretbox_xsalsa20poly1305_ZEROBYTES = 32;
49
-
50
-    const secretbox_xchacha20poly1305_KEYBYTES = 32;
51
-    const secretbox_xchacha20poly1305_NONCEBYTES = 24;
52
-    const secretbox_xchacha20poly1305_MACBYTES = 16;
53
-    const secretbox_xchacha20poly1305_BOXZEROBYTES = 16;
54
-    const secretbox_xchacha20poly1305_ZEROBYTES = 32;
55
-
56
-    const stream_salsa20_KEYBYTES = 32;
57
-
58
-    /**
59
-     * AEAD Decryption with ChaCha20-Poly1305
60
-     *
61
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
62
-     *
63
-     * @param string $message
64
-     * @param string $ad
65
-     * @param string $nonce
66
-     * @param string $key
67
-     * @return string
68
-     * @throws SodiumException
69
-     * @throws TypeError
70
-     */
71
-    public static function aead_chacha20poly1305_decrypt(
72
-        $message = '',
73
-        $ad = '',
74
-        $nonce = '',
75
-        $key = ''
76
-    ) {
77
-        /** @var int $len - Length of message (ciphertext + MAC) */
78
-        $len = ParagonIE_Sodium_Core_Util::strlen($message);
79
-
80
-        /** @var int  $clen - Length of ciphertext */
81
-        $clen = $len - self::aead_chacha20poly1305_ABYTES;
82
-
83
-        /** @var int $adlen - Length of associated data */
84
-        $adlen = ParagonIE_Sodium_Core_Util::strlen($ad);
85
-
86
-        /** @var string $mac - Message authentication code */
87
-        $mac = ParagonIE_Sodium_Core_Util::substr(
88
-            $message,
89
-            $clen,
90
-            self::aead_chacha20poly1305_ABYTES
91
-        );
92
-
93
-        /** @var string $ciphertext - The encrypted message (sans MAC) */
94
-        $ciphertext = ParagonIE_Sodium_Core_Util::substr($message, 0, $clen);
95
-
96
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
97
-        $block0 = ParagonIE_Sodium_Core_ChaCha20::stream(
98
-            32,
99
-            $nonce,
100
-            $key
101
-        );
102
-
103
-        /* Recalculate the Poly1305 authentication tag (MAC): */
104
-        $state = new ParagonIE_Sodium_Core_Poly1305_State($block0);
105
-        try {
106
-            ParagonIE_Sodium_Compat::memzero($block0);
107
-        } catch (SodiumException $ex) {
108
-            $block0 = null;
109
-        }
110
-        $state->update($ad);
111
-        $state->update(ParagonIE_Sodium_Core_Util::store64_le($adlen));
112
-        $state->update($ciphertext);
113
-        $state->update(ParagonIE_Sodium_Core_Util::store64_le($clen));
114
-        $computed_mac = $state->finish();
115
-
116
-        /* Compare the given MAC with the recalculated MAC: */
117
-        if (!ParagonIE_Sodium_Core_Util::verify_16($computed_mac, $mac)) {
118
-            throw new SodiumException('Invalid MAC');
119
-        }
120
-
121
-        // Here, we know that the MAC is valid, so we decrypt and return the plaintext
122
-        return ParagonIE_Sodium_Core_ChaCha20::streamXorIc(
123
-            $ciphertext,
124
-            $nonce,
125
-            $key,
126
-            ParagonIE_Sodium_Core_Util::store64_le(1)
127
-        );
128
-    }
129
-
130
-    /**
131
-     * AEAD Encryption with ChaCha20-Poly1305
132
-     *
133
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
134
-     *
135
-     * @param string $message
136
-     * @param string $ad
137
-     * @param string $nonce
138
-     * @param string $key
139
-     * @return string
140
-     * @throws SodiumException
141
-     * @throws TypeError
142
-     */
143
-    public static function aead_chacha20poly1305_encrypt(
144
-        $message = '',
145
-        $ad = '',
146
-        $nonce = '',
147
-        $key = ''
148
-    ) {
149
-        /** @var int $len - Length of the plaintext message */
150
-        $len = ParagonIE_Sodium_Core_Util::strlen($message);
151
-
152
-        /** @var int $adlen - Length of the associated data */
153
-        $adlen = ParagonIE_Sodium_Core_Util::strlen($ad);
154
-
155
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
156
-        $block0 = ParagonIE_Sodium_Core_ChaCha20::stream(
157
-            32,
158
-            $nonce,
159
-            $key
160
-        );
161
-        $state = new ParagonIE_Sodium_Core_Poly1305_State($block0);
162
-        try {
163
-            ParagonIE_Sodium_Compat::memzero($block0);
164
-        } catch (SodiumException $ex) {
165
-            $block0 = null;
166
-        }
167
-
168
-        /** @var string $ciphertext - Raw encrypted data */
169
-        $ciphertext = ParagonIE_Sodium_Core_ChaCha20::streamXorIc(
170
-            $message,
171
-            $nonce,
172
-            $key,
173
-            ParagonIE_Sodium_Core_Util::store64_le(1)
174
-        );
175
-
176
-        $state->update($ad);
177
-        $state->update(ParagonIE_Sodium_Core_Util::store64_le($adlen));
178
-        $state->update($ciphertext);
179
-        $state->update(ParagonIE_Sodium_Core_Util::store64_le($len));
180
-        return $ciphertext . $state->finish();
181
-    }
182
-
183
-    /**
184
-     * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
185
-     *
186
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
187
-     *
188
-     * @param string $message
189
-     * @param string $ad
190
-     * @param string $nonce
191
-     * @param string $key
192
-     * @return string
193
-     * @throws SodiumException
194
-     * @throws TypeError
195
-     */
196
-    public static function aead_chacha20poly1305_ietf_decrypt(
197
-        $message = '',
198
-        $ad = '',
199
-        $nonce = '',
200
-        $key = ''
201
-    ) {
202
-        /** @var int $adlen - Length of associated data */
203
-        $adlen = ParagonIE_Sodium_Core_Util::strlen($ad);
204
-
205
-        /** @var int $len - Length of message (ciphertext + MAC) */
206
-        $len = ParagonIE_Sodium_Core_Util::strlen($message);
207
-
208
-        /** @var int  $clen - Length of ciphertext */
209
-        $clen = $len - self::aead_chacha20poly1305_IETF_ABYTES;
210
-
211
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
212
-        $block0 = ParagonIE_Sodium_Core_ChaCha20::ietfStream(
213
-            32,
214
-            $nonce,
215
-            $key
216
-        );
217
-
218
-        /** @var string $mac - Message authentication code */
219
-        $mac = ParagonIE_Sodium_Core_Util::substr(
220
-            $message,
221
-            $len - self::aead_chacha20poly1305_IETF_ABYTES,
222
-            self::aead_chacha20poly1305_IETF_ABYTES
223
-        );
224
-
225
-        /** @var string $ciphertext - The encrypted message (sans MAC) */
226
-        $ciphertext = ParagonIE_Sodium_Core_Util::substr(
227
-            $message,
228
-            0,
229
-            $len - self::aead_chacha20poly1305_IETF_ABYTES
230
-        );
231
-
232
-        /* Recalculate the Poly1305 authentication tag (MAC): */
233
-        $state = new ParagonIE_Sodium_Core_Poly1305_State($block0);
234
-        try {
235
-            ParagonIE_Sodium_Compat::memzero($block0);
236
-        } catch (SodiumException $ex) {
237
-            $block0 = null;
238
-        }
239
-        $state->update($ad);
240
-        $state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
241
-        $state->update($ciphertext);
242
-        $state->update(str_repeat("\x00", (0x10 - $clen) & 0xf));
243
-        $state->update(ParagonIE_Sodium_Core_Util::store64_le($adlen));
244
-        $state->update(ParagonIE_Sodium_Core_Util::store64_le($clen));
245
-        $computed_mac = $state->finish();
246
-
247
-        /* Compare the given MAC with the recalculated MAC: */
248
-        if (!ParagonIE_Sodium_Core_Util::verify_16($computed_mac, $mac)) {
249
-            throw new SodiumException('Invalid MAC');
250
-        }
251
-
252
-        // Here, we know that the MAC is valid, so we decrypt and return the plaintext
253
-        return ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
254
-            $ciphertext,
255
-            $nonce,
256
-            $key,
257
-            ParagonIE_Sodium_Core_Util::store64_le(1)
258
-        );
259
-    }
260
-
261
-    /**
262
-     * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
263
-     *
264
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
265
-     *
266
-     * @param string $message
267
-     * @param string $ad
268
-     * @param string $nonce
269
-     * @param string $key
270
-     * @return string
271
-     * @throws SodiumException
272
-     * @throws TypeError
273
-     */
274
-    public static function aead_chacha20poly1305_ietf_encrypt(
275
-        $message = '',
276
-        $ad = '',
277
-        $nonce = '',
278
-        $key = ''
279
-    ) {
280
-        /** @var int $len - Length of the plaintext message */
281
-        $len = ParagonIE_Sodium_Core_Util::strlen($message);
282
-
283
-        /** @var int $adlen - Length of the associated data */
284
-        $adlen = ParagonIE_Sodium_Core_Util::strlen($ad);
285
-
286
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
287
-        $block0 = ParagonIE_Sodium_Core_ChaCha20::ietfStream(
288
-            32,
289
-            $nonce,
290
-            $key
291
-        );
292
-        $state = new ParagonIE_Sodium_Core_Poly1305_State($block0);
293
-        try {
294
-            ParagonIE_Sodium_Compat::memzero($block0);
295
-        } catch (SodiumException $ex) {
296
-            $block0 = null;
297
-        }
298
-
299
-        /** @var string $ciphertext - Raw encrypted data */
300
-        $ciphertext = ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
301
-            $message,
302
-            $nonce,
303
-            $key,
304
-            ParagonIE_Sodium_Core_Util::store64_le(1)
305
-        );
306
-
307
-        $state->update($ad);
308
-        $state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
309
-        $state->update($ciphertext);
310
-        $state->update(str_repeat("\x00", ((0x10 - $len) & 0xf)));
311
-        $state->update(ParagonIE_Sodium_Core_Util::store64_le($adlen));
312
-        $state->update(ParagonIE_Sodium_Core_Util::store64_le($len));
313
-        return $ciphertext . $state->finish();
314
-    }
315
-
316
-    /**
317
-     * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
318
-     *
319
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
320
-     *
321
-     * @param string $message
322
-     * @param string $ad
323
-     * @param string $nonce
324
-     * @param string $key
325
-     * @return string
326
-     * @throws SodiumException
327
-     * @throws TypeError
328
-     */
329
-    public static function aead_xchacha20poly1305_ietf_decrypt(
330
-        $message = '',
331
-        $ad = '',
332
-        $nonce = '',
333
-        $key = ''
334
-    ) {
335
-        $subkey = ParagonIE_Sodium_Core_HChaCha20::hChaCha20(
336
-            ParagonIE_Sodium_Core_Util::substr($nonce, 0, 16),
337
-            $key
338
-        );
339
-        $nonceLast = "\x00\x00\x00\x00" .
340
-            ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8);
341
-
342
-        return self::aead_chacha20poly1305_ietf_decrypt($message, $ad, $nonceLast, $subkey);
343
-    }
344
-
345
-    /**
346
-     * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
347
-     *
348
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
349
-     *
350
-     * @param string $message
351
-     * @param string $ad
352
-     * @param string $nonce
353
-     * @param string $key
354
-     * @return string
355
-     * @throws SodiumException
356
-     * @throws TypeError
357
-     */
358
-    public static function aead_xchacha20poly1305_ietf_encrypt(
359
-        $message = '',
360
-        $ad = '',
361
-        $nonce = '',
362
-        $key = ''
363
-    ) {
364
-        $subkey = ParagonIE_Sodium_Core_HChaCha20::hChaCha20(
365
-            ParagonIE_Sodium_Core_Util::substr($nonce, 0, 16),
366
-            $key
367
-        );
368
-        $nonceLast = "\x00\x00\x00\x00" .
369
-            ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8);
370
-
371
-        return self::aead_chacha20poly1305_ietf_encrypt($message, $ad, $nonceLast, $subkey);
372
-    }
373
-
374
-    /**
375
-     * HMAC-SHA-512-256 (a.k.a. the leftmost 256 bits of HMAC-SHA-512)
376
-     *
377
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
378
-     *
379
-     * @param string $message
380
-     * @param string $key
381
-     * @return string
382
-     * @throws TypeError
383
-     */
384
-    public static function auth($message, $key)
385
-    {
386
-        return ParagonIE_Sodium_Core_Util::substr(
387
-            hash_hmac('sha512', $message, $key, true),
388
-            0,
389
-            32
390
-        );
391
-    }
392
-
393
-    /**
394
-     * HMAC-SHA-512-256 validation. Constant-time via hash_equals().
395
-     *
396
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
397
-     *
398
-     * @param string $mac
399
-     * @param string $message
400
-     * @param string $key
401
-     * @return bool
402
-     * @throws SodiumException
403
-     * @throws TypeError
404
-     */
405
-    public static function auth_verify($mac, $message, $key)
406
-    {
407
-        return ParagonIE_Sodium_Core_Util::hashEquals(
408
-            $mac,
409
-            self::auth($message, $key)
410
-        );
411
-    }
412
-
413
-    /**
414
-     * X25519 key exchange followed by XSalsa20Poly1305 symmetric encryption
415
-     *
416
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
417
-     *
418
-     * @param string $plaintext
419
-     * @param string $nonce
420
-     * @param string $keypair
421
-     * @return string
422
-     * @throws SodiumException
423
-     * @throws TypeError
424
-     */
425
-    public static function box($plaintext, $nonce, $keypair)
426
-    {
427
-        $c = self::secretbox(
428
-            $plaintext,
429
-            $nonce,
430
-            self::box_beforenm(
431
-                self::box_secretkey($keypair),
432
-                self::box_publickey($keypair)
433
-            )
434
-        );
435
-        return $c;
436
-    }
437
-
438
-    /**
439
-     * X25519-XSalsa20-Poly1305 with one ephemeral X25519 keypair.
440
-     *
441
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
442
-     *
443
-     * @param string $message
444
-     * @param string $publicKey
445
-     * @return string
446
-     * @throws SodiumException
447
-     * @throws TypeError
448
-     */
449
-    public static function box_seal($message, $publicKey)
450
-    {
451
-        /** @var string $ephemeralKeypair */
452
-        $ephemeralKeypair = self::box_keypair();
453
-
454
-        /** @var string $ephemeralSK */
455
-        $ephemeralSK = self::box_secretkey($ephemeralKeypair);
456
-
457
-        /** @var string $ephemeralPK */
458
-        $ephemeralPK = self::box_publickey($ephemeralKeypair);
459
-
460
-        /** @var string $nonce */
461
-        $nonce = self::generichash(
462
-            $ephemeralPK . $publicKey,
463
-            '',
464
-            24
465
-        );
466
-
467
-        /** @var string $keypair - The combined keypair used in crypto_box() */
468
-        $keypair = self::box_keypair_from_secretkey_and_publickey($ephemeralSK, $publicKey);
469
-
470
-        /** @var string $ciphertext Ciphertext + MAC from crypto_box */
471
-        $ciphertext = self::box($message, $nonce, $keypair);
472
-        try {
473
-            ParagonIE_Sodium_Compat::memzero($ephemeralKeypair);
474
-            ParagonIE_Sodium_Compat::memzero($ephemeralSK);
475
-            ParagonIE_Sodium_Compat::memzero($nonce);
476
-        } catch (SodiumException $ex) {
477
-            $ephemeralKeypair = null;
478
-            $ephemeralSK = null;
479
-            $nonce = null;
480
-        }
481
-        return $ephemeralPK . $ciphertext;
482
-    }
483
-
484
-    /**
485
-     * Opens a message encrypted via box_seal().
486
-     *
487
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
488
-     *
489
-     * @param string $message
490
-     * @param string $keypair
491
-     * @return string
492
-     * @throws SodiumException
493
-     * @throws TypeError
494
-     */
495
-    public static function box_seal_open($message, $keypair)
496
-    {
497
-        /** @var string $ephemeralPK */
498
-        $ephemeralPK = ParagonIE_Sodium_Core_Util::substr($message, 0, 32);
499
-
500
-        /** @var string $ciphertext (ciphertext + MAC) */
501
-        $ciphertext = ParagonIE_Sodium_Core_Util::substr($message, 32);
502
-
503
-        /** @var string $secretKey */
504
-        $secretKey = self::box_secretkey($keypair);
505
-
506
-        /** @var string $publicKey */
507
-        $publicKey = self::box_publickey($keypair);
508
-
509
-        /** @var string $nonce */
510
-        $nonce = self::generichash(
511
-            $ephemeralPK . $publicKey,
512
-            '',
513
-            24
514
-        );
515
-
516
-        /** @var string $keypair */
517
-        $keypair = self::box_keypair_from_secretkey_and_publickey($secretKey, $ephemeralPK);
518
-
519
-        /** @var string $m */
520
-        $m = self::box_open($ciphertext, $nonce, $keypair);
521
-        try {
522
-            ParagonIE_Sodium_Compat::memzero($secretKey);
523
-            ParagonIE_Sodium_Compat::memzero($ephemeralPK);
524
-            ParagonIE_Sodium_Compat::memzero($nonce);
525
-        } catch (SodiumException $ex) {
526
-            $secretKey = null;
527
-            $ephemeralPK = null;
528
-            $nonce = null;
529
-        }
530
-        return $m;
531
-    }
532
-
533
-    /**
534
-     * Used by crypto_box() to get the crypto_secretbox() key.
535
-     *
536
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
537
-     *
538
-     * @param string $sk
539
-     * @param string $pk
540
-     * @return string
541
-     * @throws SodiumException
542
-     * @throws TypeError
543
-     */
544
-    public static function box_beforenm($sk, $pk)
545
-    {
546
-        return ParagonIE_Sodium_Core_HSalsa20::hsalsa20(
547
-            str_repeat("\x00", 16),
548
-            self::scalarmult($sk, $pk)
549
-        );
550
-    }
551
-
552
-    /**
553
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
554
-     *
555
-     * @return string
556
-     * @throws Exception
557
-     * @throws SodiumException
558
-     * @throws TypeError
559
-     */
560
-    public static function box_keypair()
561
-    {
562
-        $sKey = random_bytes(32);
563
-        $pKey = self::scalarmult_base($sKey);
564
-        return $sKey . $pKey;
565
-    }
566
-
567
-    /**
568
-     * @param string $seed
569
-     * @return string
570
-     * @throws SodiumException
571
-     * @throws TypeError
572
-     */
573
-    public static function box_seed_keypair($seed)
574
-    {
575
-        $sKey = ParagonIE_Sodium_Core_Util::substr(
576
-            hash('sha512', $seed, true),
577
-            0,
578
-            32
579
-        );
580
-        $pKey = self::scalarmult_base($sKey);
581
-        return $sKey . $pKey;
582
-    }
583
-
584
-    /**
585
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
586
-     *
587
-     * @param string $sKey
588
-     * @param string $pKey
589
-     * @return string
590
-     * @throws TypeError
591
-     */
592
-    public static function box_keypair_from_secretkey_and_publickey($sKey, $pKey)
593
-    {
594
-        return ParagonIE_Sodium_Core_Util::substr($sKey, 0, 32) .
595
-            ParagonIE_Sodium_Core_Util::substr($pKey, 0, 32);
596
-    }
597
-
598
-    /**
599
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
600
-     *
601
-     * @param string $keypair
602
-     * @return string
603
-     * @throws RangeException
604
-     * @throws TypeError
605
-     */
606
-    public static function box_secretkey($keypair)
607
-    {
608
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== 64) {
609
-            throw new RangeException(
610
-                'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
611
-            );
612
-        }
613
-        return ParagonIE_Sodium_Core_Util::substr($keypair, 0, 32);
614
-    }
615
-
616
-    /**
617
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
618
-     *
619
-     * @param string $keypair
620
-     * @return string
621
-     * @throws RangeException
622
-     * @throws TypeError
623
-     */
624
-    public static function box_publickey($keypair)
625
-    {
626
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
627
-            throw new RangeException(
628
-                'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
629
-            );
630
-        }
631
-        return ParagonIE_Sodium_Core_Util::substr($keypair, 32, 32);
632
-    }
633
-
634
-    /**
635
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
636
-     *
637
-     * @param string $sKey
638
-     * @return string
639
-     * @throws RangeException
640
-     * @throws SodiumException
641
-     * @throws TypeError
642
-     */
643
-    public static function box_publickey_from_secretkey($sKey)
644
-    {
645
-        if (ParagonIE_Sodium_Core_Util::strlen($sKey) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES) {
646
-            throw new RangeException(
647
-                'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES bytes long.'
648
-            );
649
-        }
650
-        return self::scalarmult_base($sKey);
651
-    }
652
-
653
-    /**
654
-     * Decrypt a message encrypted with box().
655
-     *
656
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
657
-     *
658
-     * @param string $ciphertext
659
-     * @param string $nonce
660
-     * @param string $keypair
661
-     * @return string
662
-     * @throws SodiumException
663
-     * @throws TypeError
664
-     */
665
-    public static function box_open($ciphertext, $nonce, $keypair)
666
-    {
667
-        return self::secretbox_open(
668
-            $ciphertext,
669
-            $nonce,
670
-            self::box_beforenm(
671
-                self::box_secretkey($keypair),
672
-                self::box_publickey($keypair)
673
-            )
674
-        );
675
-    }
676
-
677
-    /**
678
-     * Calculate a BLAKE2b hash.
679
-     *
680
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
681
-     *
682
-     * @param string $message
683
-     * @param string|null $key
684
-     * @param int $outlen
685
-     * @return string
686
-     * @throws RangeException
687
-     * @throws SodiumException
688
-     * @throws TypeError
689
-     */
690
-    public static function generichash($message, $key = '', $outlen = 32)
691
-    {
692
-        // This ensures that ParagonIE_Sodium_Core_BLAKE2b::$iv is initialized
693
-        ParagonIE_Sodium_Core_BLAKE2b::pseudoConstructor();
694
-
695
-        $k = null;
696
-        if (!empty($key)) {
697
-            /** @var SplFixedArray $k */
698
-            $k = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($key);
699
-            if ($k->count() > ParagonIE_Sodium_Core_BLAKE2b::KEYBYTES) {
700
-                throw new RangeException('Invalid key size');
701
-            }
702
-        }
703
-
704
-        /** @var SplFixedArray $in */
705
-        $in = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($message);
706
-
707
-        /** @var SplFixedArray $ctx */
708
-        $ctx = ParagonIE_Sodium_Core_BLAKE2b::init($k, $outlen);
709
-        ParagonIE_Sodium_Core_BLAKE2b::update($ctx, $in, $in->count());
710
-
711
-        /** @var SplFixedArray $out */
712
-        $out = new SplFixedArray($outlen);
713
-        $out = ParagonIE_Sodium_Core_BLAKE2b::finish($ctx, $out);
714
-
715
-        /** @var array<int, int> */
716
-        $outArray = $out->toArray();
717
-        return ParagonIE_Sodium_Core_Util::intArrayToString($outArray);
718
-    }
719
-
720
-    /**
721
-     * Finalize a BLAKE2b hashing context, returning the hash.
722
-     *
723
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
724
-     *
725
-     * @param string $ctx
726
-     * @param int $outlen
727
-     * @return string
728
-     * @throws SodiumException
729
-     * @throws TypeError
730
-     */
731
-    public static function generichash_final($ctx, $outlen = 32)
732
-    {
733
-        if (!is_string($ctx)) {
734
-            throw new TypeError('Context must be a string');
735
-        }
736
-        $out = new SplFixedArray($outlen);
737
-
738
-        /** @var SplFixedArray $context */
739
-        $context = ParagonIE_Sodium_Core_BLAKE2b::stringToContext($ctx);
740
-
741
-        /** @var SplFixedArray $out */
742
-        $out = ParagonIE_Sodium_Core_BLAKE2b::finish($context, $out);
743
-
744
-        /** @var array<int, int> */
745
-        $outArray = $out->toArray();
746
-        return ParagonIE_Sodium_Core_Util::intArrayToString($outArray);
747
-    }
748
-
749
-    /**
750
-     * Initialize a hashing context for BLAKE2b.
751
-     *
752
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
753
-     *
754
-     * @param string $key
755
-     * @param int $outputLength
756
-     * @return string
757
-     * @throws RangeException
758
-     * @throws SodiumException
759
-     * @throws TypeError
760
-     */
761
-    public static function generichash_init($key = '', $outputLength = 32)
762
-    {
763
-        // This ensures that ParagonIE_Sodium_Core_BLAKE2b::$iv is initialized
764
-        ParagonIE_Sodium_Core_BLAKE2b::pseudoConstructor();
765
-
766
-        $k = null;
767
-        if (!empty($key)) {
768
-            $k = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($key);
769
-            if ($k->count() > ParagonIE_Sodium_Core_BLAKE2b::KEYBYTES) {
770
-                throw new RangeException('Invalid key size');
771
-            }
772
-        }
773
-
774
-        /** @var SplFixedArray $ctx */
775
-        $ctx = ParagonIE_Sodium_Core_BLAKE2b::init($k, $outputLength);
776
-
777
-        return ParagonIE_Sodium_Core_BLAKE2b::contextToString($ctx);
778
-    }
779
-
780
-    /**
781
-     * Initialize a hashing context for BLAKE2b.
782
-     *
783
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
784
-     *
785
-     * @param string $key
786
-     * @param int $outputLength
787
-     * @param string $salt
788
-     * @param string $personal
789
-     * @return string
790
-     * @throws RangeException
791
-     * @throws SodiumException
792
-     * @throws TypeError
793
-     */
794
-    public static function generichash_init_salt_personal(
795
-        $key = '',
796
-        $outputLength = 32,
797
-        $salt = '',
798
-        $personal = ''
799
-    ) {
800
-        // This ensures that ParagonIE_Sodium_Core_BLAKE2b::$iv is initialized
801
-        ParagonIE_Sodium_Core_BLAKE2b::pseudoConstructor();
802
-
803
-        $k = null;
804
-        if (!empty($key)) {
805
-            $k = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($key);
806
-            if ($k->count() > ParagonIE_Sodium_Core_BLAKE2b::KEYBYTES) {
807
-                throw new RangeException('Invalid key size');
808
-            }
809
-        }
810
-        if (!empty($salt)) {
811
-            $s = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($salt);
812
-        } else {
813
-            $s = null;
814
-        }
815
-        if (!empty($salt)) {
816
-            $p = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($personal);
817
-        } else {
818
-            $p = null;
819
-        }
820
-
821
-        /** @var SplFixedArray $ctx */
822
-        $ctx = ParagonIE_Sodium_Core_BLAKE2b::init($k, $outputLength, $s, $p);
823
-
824
-        return ParagonIE_Sodium_Core_BLAKE2b::contextToString($ctx);
825
-    }
826
-
827
-    /**
828
-     * Update a hashing context for BLAKE2b with $message
829
-     *
830
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
831
-     *
832
-     * @param string $ctx
833
-     * @param string $message
834
-     * @return string
835
-     * @throws SodiumException
836
-     * @throws TypeError
837
-     */
838
-    public static function generichash_update($ctx, $message)
839
-    {
840
-        // This ensures that ParagonIE_Sodium_Core_BLAKE2b::$iv is initialized
841
-        ParagonIE_Sodium_Core_BLAKE2b::pseudoConstructor();
842
-
843
-        /** @var SplFixedArray $context */
844
-        $context = ParagonIE_Sodium_Core_BLAKE2b::stringToContext($ctx);
845
-
846
-        /** @var SplFixedArray $in */
847
-        $in = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($message);
848
-
849
-        ParagonIE_Sodium_Core_BLAKE2b::update($context, $in, $in->count());
850
-
851
-        return ParagonIE_Sodium_Core_BLAKE2b::contextToString($context);
852
-    }
853
-
854
-    /**
855
-     * Libsodium's crypto_kx().
856
-     *
857
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
858
-     *
859
-     * @param string $my_sk
860
-     * @param string $their_pk
861
-     * @param string $client_pk
862
-     * @param string $server_pk
863
-     * @return string
864
-     * @throws SodiumException
865
-     * @throws TypeError
866
-     */
867
-    public static function keyExchange($my_sk, $their_pk, $client_pk, $server_pk)
868
-    {
869
-        return ParagonIE_Sodium_Compat::crypto_generichash(
870
-            ParagonIE_Sodium_Compat::crypto_scalarmult($my_sk, $their_pk) .
871
-            $client_pk .
872
-            $server_pk
873
-        );
874
-    }
875
-
876
-    /**
877
-     * ECDH over Curve25519
878
-     *
879
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
880
-     *
881
-     * @param string $sKey
882
-     * @param string $pKey
883
-     * @return string
884
-     *
885
-     * @throws SodiumException
886
-     * @throws TypeError
887
-     */
888
-    public static function scalarmult($sKey, $pKey)
889
-    {
890
-        $q = ParagonIE_Sodium_Core_X25519::crypto_scalarmult_curve25519_ref10($sKey, $pKey);
891
-        self::scalarmult_throw_if_zero($q);
892
-        return $q;
893
-    }
894
-
895
-    /**
896
-     * ECDH over Curve25519, using the basepoint.
897
-     * Used to get a secret key from a public key.
898
-     *
899
-     * @param string $secret
900
-     * @return string
901
-     *
902
-     * @throws SodiumException
903
-     * @throws TypeError
904
-     */
905
-    public static function scalarmult_base($secret)
906
-    {
907
-        $q = ParagonIE_Sodium_Core_X25519::crypto_scalarmult_curve25519_ref10_base($secret);
908
-        self::scalarmult_throw_if_zero($q);
909
-        return $q;
910
-    }
911
-
912
-    /**
913
-     * This throws an Error if a zero public key was passed to the function.
914
-     *
915
-     * @param string $q
916
-     * @return void
917
-     * @throws SodiumException
918
-     * @throws TypeError
919
-     */
920
-    protected static function scalarmult_throw_if_zero($q)
921
-    {
922
-        $d = 0;
923
-        for ($i = 0; $i < self::box_curve25519xsalsa20poly1305_SECRETKEYBYTES; ++$i) {
924
-            $d |= ParagonIE_Sodium_Core_Util::chrToInt($q[$i]);
925
-        }
926
-
927
-        /* branch-free variant of === 0 */
928
-        if (-(1 & (($d - 1) >> 8))) {
929
-            throw new SodiumException('Zero public key is not allowed');
930
-        }
931
-    }
932
-
933
-    /**
934
-     * XSalsa20-Poly1305 authenticated symmetric-key encryption.
935
-     *
936
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
937
-     *
938
-     * @param string $plaintext
939
-     * @param string $nonce
940
-     * @param string $key
941
-     * @return string
942
-     * @throws SodiumException
943
-     * @throws TypeError
944
-     */
945
-    public static function secretbox($plaintext, $nonce, $key)
946
-    {
947
-        /** @var string $subkey */
948
-        $subkey = ParagonIE_Sodium_Core_HSalsa20::hsalsa20($nonce, $key);
949
-
950
-        /** @var string $block0 */
951
-        $block0 = str_repeat("\x00", 32);
952
-
953
-        /** @var int $mlen - Length of the plaintext message */
954
-        $mlen = ParagonIE_Sodium_Core_Util::strlen($plaintext);
955
-        $mlen0 = $mlen;
956
-        if ($mlen0 > 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES) {
957
-            $mlen0 = 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES;
958
-        }
959
-        $block0 .= ParagonIE_Sodium_Core_Util::substr($plaintext, 0, $mlen0);
960
-
961
-        /** @var string $block0 */
962
-        $block0 = ParagonIE_Sodium_Core_Salsa20::salsa20_xor(
963
-            $block0,
964
-            ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
965
-            $subkey
966
-        );
967
-
968
-        /** @var string $c */
969
-        $c = ParagonIE_Sodium_Core_Util::substr(
970
-            $block0,
971
-            self::secretbox_xsalsa20poly1305_ZEROBYTES
972
-        );
973
-        if ($mlen > $mlen0) {
974
-            $c .= ParagonIE_Sodium_Core_Salsa20::salsa20_xor_ic(
975
-                ParagonIE_Sodium_Core_Util::substr(
976
-                    $plaintext,
977
-                    self::secretbox_xsalsa20poly1305_ZEROBYTES
978
-                ),
979
-                ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
980
-                1,
981
-                $subkey
982
-            );
983
-        }
984
-        $state = new ParagonIE_Sodium_Core_Poly1305_State(
985
-            ParagonIE_Sodium_Core_Util::substr(
986
-                $block0,
987
-                0,
988
-                self::onetimeauth_poly1305_KEYBYTES
989
-            )
990
-        );
991
-        try {
992
-            ParagonIE_Sodium_Compat::memzero($block0);
993
-            ParagonIE_Sodium_Compat::memzero($subkey);
994
-        } catch (SodiumException $ex) {
995
-            $block0 = null;
996
-            $subkey = null;
997
-        }
998
-
999
-        $state->update($c);
1000
-
1001
-        /** @var string $c - MAC || ciphertext */
1002
-        $c = $state->finish() . $c;
1003
-        unset($state);
1004
-
1005
-        return $c;
1006
-    }
1007
-
1008
-    /**
1009
-     * Decrypt a ciphertext generated via secretbox().
1010
-     *
1011
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1012
-     *
1013
-     * @param string $ciphertext
1014
-     * @param string $nonce
1015
-     * @param string $key
1016
-     * @return string
1017
-     * @throws SodiumException
1018
-     * @throws TypeError
1019
-     */
1020
-    public static function secretbox_open($ciphertext, $nonce, $key)
1021
-    {
1022
-        /** @var string $mac */
1023
-        $mac = ParagonIE_Sodium_Core_Util::substr(
1024
-            $ciphertext,
1025
-            0,
1026
-            self::secretbox_xsalsa20poly1305_MACBYTES
1027
-        );
1028
-
1029
-        /** @var string $c */
1030
-        $c = ParagonIE_Sodium_Core_Util::substr(
1031
-            $ciphertext,
1032
-            self::secretbox_xsalsa20poly1305_MACBYTES
1033
-        );
1034
-
1035
-        /** @var int $clen */
1036
-        $clen = ParagonIE_Sodium_Core_Util::strlen($c);
1037
-
1038
-        /** @var string $subkey */
1039
-        $subkey = ParagonIE_Sodium_Core_HSalsa20::hsalsa20($nonce, $key);
1040
-
1041
-        /** @var string $block0 */
1042
-        $block0 = ParagonIE_Sodium_Core_Salsa20::salsa20(
1043
-            64,
1044
-            ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
1045
-            $subkey
1046
-        );
1047
-        $verified = ParagonIE_Sodium_Core_Poly1305::onetimeauth_verify(
1048
-            $mac,
1049
-            $c,
1050
-            ParagonIE_Sodium_Core_Util::substr($block0, 0, 32)
1051
-        );
1052
-        if (!$verified) {
1053
-            try {
1054
-                ParagonIE_Sodium_Compat::memzero($subkey);
1055
-            } catch (SodiumException $ex) {
1056
-                $subkey = null;
1057
-            }
1058
-            throw new SodiumException('Invalid MAC');
1059
-        }
1060
-
1061
-        /** @var string $m - Decrypted message */
1062
-        $m = ParagonIE_Sodium_Core_Util::xorStrings(
1063
-            ParagonIE_Sodium_Core_Util::substr($block0, self::secretbox_xsalsa20poly1305_ZEROBYTES),
1064
-            ParagonIE_Sodium_Core_Util::substr($c, 0, self::secretbox_xsalsa20poly1305_ZEROBYTES)
1065
-        );
1066
-        if ($clen > self::secretbox_xsalsa20poly1305_ZEROBYTES) {
1067
-            // We had more than 1 block, so let's continue to decrypt the rest.
1068
-            $m .= ParagonIE_Sodium_Core_Salsa20::salsa20_xor_ic(
1069
-                ParagonIE_Sodium_Core_Util::substr(
1070
-                    $c,
1071
-                    self::secretbox_xsalsa20poly1305_ZEROBYTES
1072
-                ),
1073
-                ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
1074
-                1,
1075
-                (string) $subkey
1076
-            );
1077
-        }
1078
-        return $m;
1079
-    }
1080
-
1081
-    /**
1082
-     * XChaCha20-Poly1305 authenticated symmetric-key encryption.
1083
-     *
1084
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1085
-     *
1086
-     * @param string $plaintext
1087
-     * @param string $nonce
1088
-     * @param string $key
1089
-     * @return string
1090
-     * @throws SodiumException
1091
-     * @throws TypeError
1092
-     */
1093
-    public static function secretbox_xchacha20poly1305($plaintext, $nonce, $key)
1094
-    {
1095
-        /** @var string $subkey */
1096
-        $subkey = ParagonIE_Sodium_Core_HChaCha20::hChaCha20(
1097
-            ParagonIE_Sodium_Core_Util::substr($nonce, 0, 16),
1098
-            $key
1099
-        );
1100
-        $nonceLast = ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8);
1101
-
1102
-        /** @var string $block0 */
1103
-        $block0 = str_repeat("\x00", 32);
1104
-
1105
-        /** @var int $mlen - Length of the plaintext message */
1106
-        $mlen = ParagonIE_Sodium_Core_Util::strlen($plaintext);
1107
-        $mlen0 = $mlen;
1108
-        if ($mlen0 > 64 - self::secretbox_xchacha20poly1305_ZEROBYTES) {
1109
-            $mlen0 = 64 - self::secretbox_xchacha20poly1305_ZEROBYTES;
1110
-        }
1111
-        $block0 .= ParagonIE_Sodium_Core_Util::substr($plaintext, 0, $mlen0);
1112
-
1113
-        /** @var string $block0 */
1114
-        $block0 = ParagonIE_Sodium_Core_ChaCha20::streamXorIc(
1115
-            $block0,
1116
-            $nonceLast,
1117
-            $subkey
1118
-        );
1119
-
1120
-        /** @var string $c */
1121
-        $c = ParagonIE_Sodium_Core_Util::substr(
1122
-            $block0,
1123
-            self::secretbox_xchacha20poly1305_ZEROBYTES
1124
-        );
1125
-        if ($mlen > $mlen0) {
1126
-            $c .= ParagonIE_Sodium_Core_ChaCha20::streamXorIc(
1127
-                ParagonIE_Sodium_Core_Util::substr(
1128
-                    $plaintext,
1129
-                    self::secretbox_xchacha20poly1305_ZEROBYTES
1130
-                ),
1131
-                $nonceLast,
1132
-                $subkey,
1133
-                ParagonIE_Sodium_Core_Util::store64_le(1)
1134
-            );
1135
-        }
1136
-        $state = new ParagonIE_Sodium_Core_Poly1305_State(
1137
-            ParagonIE_Sodium_Core_Util::substr(
1138
-                $block0,
1139
-                0,
1140
-                self::onetimeauth_poly1305_KEYBYTES
1141
-            )
1142
-        );
1143
-        try {
1144
-            ParagonIE_Sodium_Compat::memzero($block0);
1145
-            ParagonIE_Sodium_Compat::memzero($subkey);
1146
-        } catch (SodiumException $ex) {
1147
-            $block0 = null;
1148
-            $subkey = null;
1149
-        }
1150
-
1151
-        $state->update($c);
1152
-
1153
-        /** @var string $c - MAC || ciphertext */
1154
-        $c = $state->finish() . $c;
1155
-        unset($state);
1156
-
1157
-        return $c;
1158
-    }
1159
-
1160
-    /**
1161
-     * Decrypt a ciphertext generated via secretbox_xchacha20poly1305().
1162
-     *
1163
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1164
-     *
1165
-     * @param string $ciphertext
1166
-     * @param string $nonce
1167
-     * @param string $key
1168
-     * @return string
1169
-     * @throws SodiumException
1170
-     * @throws TypeError
1171
-     */
1172
-    public static function secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key)
1173
-    {
1174
-        /** @var string $mac */
1175
-        $mac = ParagonIE_Sodium_Core_Util::substr(
1176
-            $ciphertext,
1177
-            0,
1178
-            self::secretbox_xchacha20poly1305_MACBYTES
1179
-        );
1180
-
1181
-        /** @var string $c */
1182
-        $c = ParagonIE_Sodium_Core_Util::substr(
1183
-            $ciphertext,
1184
-            self::secretbox_xchacha20poly1305_MACBYTES
1185
-        );
1186
-
1187
-        /** @var int $clen */
1188
-        $clen = ParagonIE_Sodium_Core_Util::strlen($c);
1189
-
1190
-        /** @var string $subkey */
1191
-        $subkey = ParagonIE_Sodium_Core_HChaCha20::hchacha20($nonce, $key);
1192
-
1193
-        /** @var string $block0 */
1194
-        $block0 = ParagonIE_Sodium_Core_ChaCha20::stream(
1195
-            64,
1196
-            ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
1197
-            $subkey
1198
-        );
1199
-        $verified = ParagonIE_Sodium_Core_Poly1305::onetimeauth_verify(
1200
-            $mac,
1201
-            $c,
1202
-            ParagonIE_Sodium_Core_Util::substr($block0, 0, 32)
1203
-        );
1204
-
1205
-        if (!$verified) {
1206
-            try {
1207
-                ParagonIE_Sodium_Compat::memzero($subkey);
1208
-            } catch (SodiumException $ex) {
1209
-                $subkey = null;
1210
-            }
1211
-            throw new SodiumException('Invalid MAC');
1212
-        }
1213
-
1214
-        /** @var string $m - Decrypted message */
1215
-        $m = ParagonIE_Sodium_Core_Util::xorStrings(
1216
-            ParagonIE_Sodium_Core_Util::substr($block0, self::secretbox_xchacha20poly1305_ZEROBYTES),
1217
-            ParagonIE_Sodium_Core_Util::substr($c, 0, self::secretbox_xchacha20poly1305_ZEROBYTES)
1218
-        );
1219
-
1220
-        if ($clen > self::secretbox_xchacha20poly1305_ZEROBYTES) {
1221
-            // We had more than 1 block, so let's continue to decrypt the rest.
1222
-            $m .= ParagonIE_Sodium_Core_ChaCha20::streamXorIc(
1223
-                ParagonIE_Sodium_Core_Util::substr(
1224
-                    $c,
1225
-                    self::secretbox_xchacha20poly1305_ZEROBYTES
1226
-                ),
1227
-                ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
1228
-                (string) $subkey,
1229
-                ParagonIE_Sodium_Core_Util::store64_le(1)
1230
-            );
1231
-        }
1232
-        return $m;
1233
-    }
1234
-
1235
-    /**
1236
-     * @param string $key
1237
-     * @return array<int, string> Returns a state and a header.
1238
-     * @throws Exception
1239
-     * @throws SodiumException
1240
-     */
1241
-    public static function secretstream_xchacha20poly1305_init_push($key)
1242
-    {
1243
-        # randombytes_buf(out, crypto_secretstream_xchacha20poly1305_HEADERBYTES);
1244
-        $out = random_bytes(24);
1245
-
1246
-        # crypto_core_hchacha20(state->k, out, k, NULL);
1247
-        $subkey = ParagonIE_Sodium_Core_HChaCha20::hChaCha20($out, $key);
1248
-        $state = new ParagonIE_Sodium_Core_SecretStream_State(
1249
-            $subkey,
1250
-            ParagonIE_Sodium_Core_Util::substr($out, 16, 8) . str_repeat("\0", 4)
1251
-        );
1252
-
1253
-        # _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1254
-        $state->counterReset();
1255
-
1256
-        # memcpy(STATE_INONCE(state), out + crypto_core_hchacha20_INPUTBYTES,
1257
-        #        crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1258
-        # memset(state->_pad, 0, sizeof state->_pad);
1259
-        return array(
1260
-            $state->toString(),
1261
-            $out
1262
-        );
1263
-    }
1264
-
1265
-    /**
1266
-     * @param string $key
1267
-     * @param string $header
1268
-     * @return string Returns a state.
1269
-     * @throws Exception
1270
-     */
1271
-    public static function secretstream_xchacha20poly1305_init_pull($key, $header)
1272
-    {
1273
-        # crypto_core_hchacha20(state->k, in, k, NULL);
1274
-        $subkey = ParagonIE_Sodium_Core_HChaCha20::hChaCha20(
1275
-            ParagonIE_Sodium_Core_Util::substr($header, 0, 16),
1276
-            $key
1277
-        );
1278
-        $state = new ParagonIE_Sodium_Core_SecretStream_State(
1279
-            $subkey,
1280
-            ParagonIE_Sodium_Core_Util::substr($header, 16)
1281
-        );
1282
-        $state->counterReset();
1283
-        # memcpy(STATE_INONCE(state), in + crypto_core_hchacha20_INPUTBYTES,
1284
-        #     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1285
-        # memset(state->_pad, 0, sizeof state->_pad);
1286
-        # return 0;
1287
-        return $state->toString();
1288
-    }
1289
-
1290
-    /**
1291
-     * @param string $state
1292
-     * @param string $msg
1293
-     * @param string $aad
1294
-     * @param int $tag
1295
-     * @return string
1296
-     * @throws SodiumException
1297
-     */
1298
-    public static function secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0)
1299
-    {
1300
-        $st = ParagonIE_Sodium_Core_SecretStream_State::fromString($state);
1301
-        # crypto_onetimeauth_poly1305_state poly1305_state;
1302
-        # unsigned char                     block[64U];
1303
-        # unsigned char                     slen[8U];
1304
-        # unsigned char                    *c;
1305
-        # unsigned char                    *mac;
1306
-
1307
-        $msglen = ParagonIE_Sodium_Core_Util::strlen($msg);
1308
-        $aadlen = ParagonIE_Sodium_Core_Util::strlen($aad);
1309
-
1310
-        if ((($msglen + 63) >> 6) > 0xfffffffe) {
1311
-            throw new SodiumException(
1312
-                'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1313
-            );
1314
-        }
1315
-
1316
-        # if (outlen_p != NULL) {
1317
-        #     *outlen_p = 0U;
1318
-        # }
1319
-        # if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1320
-        #     sodium_misuse();
1321
-        # }
1322
-
1323
-        # crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1324
-        # crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1325
-        # sodium_memzero(block, sizeof block);
1326
-        $auth = new ParagonIE_Sodium_Core_Poly1305_State(
1327
-            ParagonIE_Sodium_Core_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1328
-        );
1329
-
1330
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1331
-        $auth->update($aad);
1332
-
1333
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1334
-        #     (0x10 - adlen) & 0xf);
1335
-        $auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1336
-
1337
-        # memset(block, 0, sizeof block);
1338
-        # block[0] = tag;
1339
-        # crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1340
-        #                                    state->nonce, 1U, state->k);
1341
-        $block = ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
1342
-            ParagonIE_Sodium_Core_Util::intToChr($tag) . str_repeat("\0", 63),
1343
-            $st->getCombinedNonce(),
1344
-            $st->getKey(),
1345
-            ParagonIE_Sodium_Core_Util::store64_le(1)
1346
-        );
1347
-
1348
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1349
-        $auth->update($block);
1350
-
1351
-        # out[0] = block[0];
1352
-        $out = $block[0];
1353
-        # c = out + (sizeof tag);
1354
-        # crypto_stream_chacha20_ietf_xor_ic(c, m, mlen, state->nonce, 2U, state->k);
1355
-        $cipher = ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
1356
-            $msg,
1357
-            $st->getCombinedNonce(),
1358
-            $st->getKey(),
1359
-            ParagonIE_Sodium_Core_Util::store64_le(2)
1360
-        );
1361
-
1362
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1363
-        $auth->update($cipher);
1364
-
1365
-        $out .= $cipher;
1366
-        unset($cipher);
1367
-
1368
-        # crypto_onetimeauth_poly1305_update
1369
-        # (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1370
-        $auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1371
-
1372
-        # STORE64_LE(slen, (uint64_t) adlen);
1373
-        $slen = ParagonIE_Sodium_Core_Util::store64_le($aadlen);
1374
-
1375
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1376
-        $auth->update($slen);
1377
-
1378
-        # STORE64_LE(slen, (sizeof block) + mlen);
1379
-        $slen = ParagonIE_Sodium_Core_Util::store64_le(64 + $msglen);
1380
-
1381
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1382
-        $auth->update($slen);
1383
-
1384
-        # mac = c + mlen;
1385
-        # crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1386
-        $mac = $auth->finish();
1387
-        $out .= $mac;
1388
-
1389
-        # sodium_memzero(&poly1305_state, sizeof poly1305_state);
1390
-        unset($auth);
1391
-
1392
-
1393
-        # XOR_BUF(STATE_INONCE(state), mac,
1394
-        #     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1395
-        $st->xorNonce($mac);
1396
-
1397
-        # sodium_increment(STATE_COUNTER(state),
1398
-        #     crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1399
-        $st->incrementCounter();
1400
-        // Overwrite by reference:
1401
-        $state = $st->toString();
1402
-
1403
-        /** @var bool $rekey */
1404
-        $rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1405
-        # if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1406
-        #     sodium_is_zero(STATE_COUNTER(state),
1407
-        #         crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1408
-        #     crypto_secretstream_xchacha20poly1305_rekey(state);
1409
-        # }
1410
-        if ($rekey || $st->needsRekey()) {
1411
-            // DO REKEY
1412
-            self::secretstream_xchacha20poly1305_rekey($state);
1413
-        }
1414
-        # if (outlen_p != NULL) {
1415
-        #     *outlen_p = crypto_secretstream_xchacha20poly1305_ABYTES + mlen;
1416
-        # }
1417
-        return $out;
1418
-    }
1419
-
1420
-    /**
1421
-     * @param string $state
1422
-     * @param string $cipher
1423
-     * @param string $aad
1424
-     * @return bool|array{0: string, 1: int}
1425
-     * @throws SodiumException
1426
-     */
1427
-    public static function secretstream_xchacha20poly1305_pull(&$state, $cipher, $aad = '')
1428
-    {
1429
-        $st = ParagonIE_Sodium_Core_SecretStream_State::fromString($state);
1430
-
1431
-        $cipherlen = ParagonIE_Sodium_Core_Util::strlen($cipher);
1432
-        #     mlen = inlen - crypto_secretstream_xchacha20poly1305_ABYTES;
1433
-        $msglen = $cipherlen - ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_ABYTES;
1434
-        $aadlen = ParagonIE_Sodium_Core_Util::strlen($aad);
1435
-
1436
-        #     if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1437
-        #         sodium_misuse();
1438
-        #     }
1439
-        if ((($msglen + 63) >> 6) > 0xfffffffe) {
1440
-            throw new SodiumException(
1441
-                'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1442
-            );
1443
-        }
1444
-
1445
-        #     crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1446
-        #     crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1447
-        #     sodium_memzero(block, sizeof block);
1448
-        $auth = new ParagonIE_Sodium_Core_Poly1305_State(
1449
-            ParagonIE_Sodium_Core_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1450
-        );
1451
-
1452
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1453
-        $auth->update($aad);
1454
-
1455
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1456
-        #         (0x10 - adlen) & 0xf);
1457
-        $auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1458
-
1459
-
1460
-        #     memset(block, 0, sizeof block);
1461
-        #     block[0] = in[0];
1462
-        #     crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1463
-        #                                        state->nonce, 1U, state->k);
1464
-        $block = ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
1465
-            $cipher[0] . str_repeat("\0", 63),
1466
-            $st->getCombinedNonce(),
1467
-            $st->getKey(),
1468
-            ParagonIE_Sodium_Core_Util::store64_le(1)
1469
-        );
1470
-        #     tag = block[0];
1471
-        #     block[0] = in[0];
1472
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1473
-        $tag = ParagonIE_Sodium_Core_Util::chrToInt($block[0]);
1474
-        $block[0] = $cipher[0];
1475
-        $auth->update($block);
1476
-
1477
-
1478
-        #     c = in + (sizeof tag);
1479
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1480
-        $auth->update(ParagonIE_Sodium_Core_Util::substr($cipher, 1, $msglen));
1481
-
1482
-        #     crypto_onetimeauth_poly1305_update
1483
-        #     (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1484
-        $auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1485
-
1486
-        #     STORE64_LE(slen, (uint64_t) adlen);
1487
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1488
-        $slen = ParagonIE_Sodium_Core_Util::store64_le($aadlen);
1489
-        $auth->update($slen);
1490
-
1491
-        #     STORE64_LE(slen, (sizeof block) + mlen);
1492
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1493
-        $slen = ParagonIE_Sodium_Core_Util::store64_le(64 + $msglen);
1494
-        $auth->update($slen);
1495
-
1496
-        #     crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1497
-        #     sodium_memzero(&poly1305_state, sizeof poly1305_state);
1498
-        $mac = $auth->finish();
1499
-
1500
-        #     stored_mac = c + mlen;
1501
-        #     if (sodium_memcmp(mac, stored_mac, sizeof mac) != 0) {
1502
-        #     sodium_memzero(mac, sizeof mac);
1503
-        #         return -1;
1504
-        #     }
1505
-
1506
-        $stored = ParagonIE_Sodium_Core_Util::substr($cipher, $msglen + 1, 16);
1507
-        if (!ParagonIE_Sodium_Core_Util::hashEquals($mac, $stored)) {
1508
-            return false;
1509
-        }
1510
-
1511
-        #     crypto_stream_chacha20_ietf_xor_ic(m, c, mlen, state->nonce, 2U, state->k);
1512
-        $out = ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
1513
-            ParagonIE_Sodium_Core_Util::substr($cipher, 1, $msglen),
1514
-            $st->getCombinedNonce(),
1515
-            $st->getKey(),
1516
-            ParagonIE_Sodium_Core_Util::store64_le(2)
1517
-        );
1518
-
1519
-        #     XOR_BUF(STATE_INONCE(state), mac,
1520
-        #         crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1521
-        $st->xorNonce($mac);
1522
-
1523
-        #     sodium_increment(STATE_COUNTER(state),
1524
-        #         crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1525
-        $st->incrementCounter();
1526
-
1527
-        #     if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1528
-        #         sodium_is_zero(STATE_COUNTER(state),
1529
-        #             crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1530
-        #         crypto_secretstream_xchacha20poly1305_rekey(state);
1531
-        #     }
1532
-
1533
-        // Overwrite by reference:
1534
-        $state = $st->toString();
1535
-
1536
-        /** @var bool $rekey */
1537
-        $rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1538
-        if ($rekey || $st->needsRekey()) {
1539
-            // DO REKEY
1540
-            self::secretstream_xchacha20poly1305_rekey($state);
1541
-        }
1542
-        return array($out, $tag);
1543
-    }
1544
-
1545
-    /**
1546
-     * @param string $state
1547
-     * @return void
1548
-     * @throws SodiumException
1549
-     */
1550
-    public static function secretstream_xchacha20poly1305_rekey(&$state)
1551
-    {
1552
-        $st = ParagonIE_Sodium_Core_SecretStream_State::fromString($state);
1553
-        # unsigned char new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES +
1554
-        # crypto_secretstream_xchacha20poly1305_INONCEBYTES];
1555
-        # size_t        i;
1556
-        # for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1557
-        #     new_key_and_inonce[i] = state->k[i];
1558
-        # }
1559
-        $new_key_and_inonce = $st->getKey();
1560
-
1561
-        # for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1562
-        #     new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i] =
1563
-        #         STATE_INONCE(state)[i];
1564
-        # }
1565
-        $new_key_and_inonce .= ParagonIE_Sodium_Core_Util::substR($st->getNonce(), 0, 8);
1566
-
1567
-        # crypto_stream_chacha20_ietf_xor(new_key_and_inonce, new_key_and_inonce,
1568
-        #                                 sizeof new_key_and_inonce,
1569
-        #                                 state->nonce, state->k);
1570
-
1571
-        $st->rekey(ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
1572
-            $new_key_and_inonce,
1573
-            $st->getCombinedNonce(),
1574
-            $st->getKey(),
1575
-            ParagonIE_Sodium_Core_Util::store64_le(0)
1576
-        ));
1577
-
1578
-        # for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1579
-        #     state->k[i] = new_key_and_inonce[i];
1580
-        # }
1581
-        # for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1582
-        #     STATE_INONCE(state)[i] =
1583
-        #          new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i];
1584
-        # }
1585
-        # _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1586
-        $st->counterReset();
1587
-
1588
-        $state = $st->toString();
1589
-    }
1590
-
1591
-    /**
1592
-     * Detached Ed25519 signature.
1593
-     *
1594
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1595
-     *
1596
-     * @param string $message
1597
-     * @param string $sk
1598
-     * @return string
1599
-     * @throws SodiumException
1600
-     * @throws TypeError
1601
-     */
1602
-    public static function sign_detached($message, $sk)
1603
-    {
1604
-        return ParagonIE_Sodium_Core_Ed25519::sign_detached($message, $sk);
1605
-    }
1606
-
1607
-    /**
1608
-     * Attached Ed25519 signature. (Returns a signed message.)
1609
-     *
1610
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1611
-     *
1612
-     * @param string $message
1613
-     * @param string $sk
1614
-     * @return string
1615
-     * @throws SodiumException
1616
-     * @throws TypeError
1617
-     */
1618
-    public static function sign($message, $sk)
1619
-    {
1620
-        return ParagonIE_Sodium_Core_Ed25519::sign($message, $sk);
1621
-    }
1622
-
1623
-    /**
1624
-     * Opens a signed message. If valid, returns the message.
1625
-     *
1626
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1627
-     *
1628
-     * @param string $signedMessage
1629
-     * @param string $pk
1630
-     * @return string
1631
-     * @throws SodiumException
1632
-     * @throws TypeError
1633
-     */
1634
-    public static function sign_open($signedMessage, $pk)
1635
-    {
1636
-        return ParagonIE_Sodium_Core_Ed25519::sign_open($signedMessage, $pk);
1637
-    }
1638
-
1639
-    /**
1640
-     * Verify a detached signature of a given message and public key.
1641
-     *
1642
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1643
-     *
1644
-     * @param string $signature
1645
-     * @param string $message
1646
-     * @param string $pk
1647
-     * @return bool
1648
-     * @throws SodiumException
1649
-     * @throws TypeError
1650
-     */
1651
-    public static function sign_verify_detached($signature, $message, $pk)
1652
-    {
1653
-        return ParagonIE_Sodium_Core_Ed25519::verify_detached($signature, $message, $pk);
1654
-    }
17
+	const aead_chacha20poly1305_KEYBYTES = 32;
18
+	const aead_chacha20poly1305_NSECBYTES = 0;
19
+	const aead_chacha20poly1305_NPUBBYTES = 8;
20
+	const aead_chacha20poly1305_ABYTES = 16;
21
+
22
+	const aead_chacha20poly1305_IETF_KEYBYTES = 32;
23
+	const aead_chacha20poly1305_IETF_NSECBYTES = 0;
24
+	const aead_chacha20poly1305_IETF_NPUBBYTES = 12;
25
+	const aead_chacha20poly1305_IETF_ABYTES = 16;
26
+
27
+	const aead_xchacha20poly1305_IETF_KEYBYTES = 32;
28
+	const aead_xchacha20poly1305_IETF_NSECBYTES = 0;
29
+	const aead_xchacha20poly1305_IETF_NPUBBYTES = 24;
30
+	const aead_xchacha20poly1305_IETF_ABYTES = 16;
31
+
32
+	const box_curve25519xsalsa20poly1305_SEEDBYTES = 32;
33
+	const box_curve25519xsalsa20poly1305_PUBLICKEYBYTES = 32;
34
+	const box_curve25519xsalsa20poly1305_SECRETKEYBYTES = 32;
35
+	const box_curve25519xsalsa20poly1305_BEFORENMBYTES = 32;
36
+	const box_curve25519xsalsa20poly1305_NONCEBYTES = 24;
37
+	const box_curve25519xsalsa20poly1305_MACBYTES = 16;
38
+	const box_curve25519xsalsa20poly1305_BOXZEROBYTES = 16;
39
+	const box_curve25519xsalsa20poly1305_ZEROBYTES = 32;
40
+
41
+	const onetimeauth_poly1305_BYTES = 16;
42
+	const onetimeauth_poly1305_KEYBYTES = 32;
43
+
44
+	const secretbox_xsalsa20poly1305_KEYBYTES = 32;
45
+	const secretbox_xsalsa20poly1305_NONCEBYTES = 24;
46
+	const secretbox_xsalsa20poly1305_MACBYTES = 16;
47
+	const secretbox_xsalsa20poly1305_BOXZEROBYTES = 16;
48
+	const secretbox_xsalsa20poly1305_ZEROBYTES = 32;
49
+
50
+	const secretbox_xchacha20poly1305_KEYBYTES = 32;
51
+	const secretbox_xchacha20poly1305_NONCEBYTES = 24;
52
+	const secretbox_xchacha20poly1305_MACBYTES = 16;
53
+	const secretbox_xchacha20poly1305_BOXZEROBYTES = 16;
54
+	const secretbox_xchacha20poly1305_ZEROBYTES = 32;
55
+
56
+	const stream_salsa20_KEYBYTES = 32;
57
+
58
+	/**
59
+	 * AEAD Decryption with ChaCha20-Poly1305
60
+	 *
61
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
62
+	 *
63
+	 * @param string $message
64
+	 * @param string $ad
65
+	 * @param string $nonce
66
+	 * @param string $key
67
+	 * @return string
68
+	 * @throws SodiumException
69
+	 * @throws TypeError
70
+	 */
71
+	public static function aead_chacha20poly1305_decrypt(
72
+		$message = '',
73
+		$ad = '',
74
+		$nonce = '',
75
+		$key = ''
76
+	) {
77
+		/** @var int $len - Length of message (ciphertext + MAC) */
78
+		$len = ParagonIE_Sodium_Core_Util::strlen($message);
79
+
80
+		/** @var int  $clen - Length of ciphertext */
81
+		$clen = $len - self::aead_chacha20poly1305_ABYTES;
82
+
83
+		/** @var int $adlen - Length of associated data */
84
+		$adlen = ParagonIE_Sodium_Core_Util::strlen($ad);
85
+
86
+		/** @var string $mac - Message authentication code */
87
+		$mac = ParagonIE_Sodium_Core_Util::substr(
88
+			$message,
89
+			$clen,
90
+			self::aead_chacha20poly1305_ABYTES
91
+		);
92
+
93
+		/** @var string $ciphertext - The encrypted message (sans MAC) */
94
+		$ciphertext = ParagonIE_Sodium_Core_Util::substr($message, 0, $clen);
95
+
96
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
97
+		$block0 = ParagonIE_Sodium_Core_ChaCha20::stream(
98
+			32,
99
+			$nonce,
100
+			$key
101
+		);
102
+
103
+		/* Recalculate the Poly1305 authentication tag (MAC): */
104
+		$state = new ParagonIE_Sodium_Core_Poly1305_State($block0);
105
+		try {
106
+			ParagonIE_Sodium_Compat::memzero($block0);
107
+		} catch (SodiumException $ex) {
108
+			$block0 = null;
109
+		}
110
+		$state->update($ad);
111
+		$state->update(ParagonIE_Sodium_Core_Util::store64_le($adlen));
112
+		$state->update($ciphertext);
113
+		$state->update(ParagonIE_Sodium_Core_Util::store64_le($clen));
114
+		$computed_mac = $state->finish();
115
+
116
+		/* Compare the given MAC with the recalculated MAC: */
117
+		if (!ParagonIE_Sodium_Core_Util::verify_16($computed_mac, $mac)) {
118
+			throw new SodiumException('Invalid MAC');
119
+		}
120
+
121
+		// Here, we know that the MAC is valid, so we decrypt and return the plaintext
122
+		return ParagonIE_Sodium_Core_ChaCha20::streamXorIc(
123
+			$ciphertext,
124
+			$nonce,
125
+			$key,
126
+			ParagonIE_Sodium_Core_Util::store64_le(1)
127
+		);
128
+	}
129
+
130
+	/**
131
+	 * AEAD Encryption with ChaCha20-Poly1305
132
+	 *
133
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
134
+	 *
135
+	 * @param string $message
136
+	 * @param string $ad
137
+	 * @param string $nonce
138
+	 * @param string $key
139
+	 * @return string
140
+	 * @throws SodiumException
141
+	 * @throws TypeError
142
+	 */
143
+	public static function aead_chacha20poly1305_encrypt(
144
+		$message = '',
145
+		$ad = '',
146
+		$nonce = '',
147
+		$key = ''
148
+	) {
149
+		/** @var int $len - Length of the plaintext message */
150
+		$len = ParagonIE_Sodium_Core_Util::strlen($message);
151
+
152
+		/** @var int $adlen - Length of the associated data */
153
+		$adlen = ParagonIE_Sodium_Core_Util::strlen($ad);
154
+
155
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
156
+		$block0 = ParagonIE_Sodium_Core_ChaCha20::stream(
157
+			32,
158
+			$nonce,
159
+			$key
160
+		);
161
+		$state = new ParagonIE_Sodium_Core_Poly1305_State($block0);
162
+		try {
163
+			ParagonIE_Sodium_Compat::memzero($block0);
164
+		} catch (SodiumException $ex) {
165
+			$block0 = null;
166
+		}
167
+
168
+		/** @var string $ciphertext - Raw encrypted data */
169
+		$ciphertext = ParagonIE_Sodium_Core_ChaCha20::streamXorIc(
170
+			$message,
171
+			$nonce,
172
+			$key,
173
+			ParagonIE_Sodium_Core_Util::store64_le(1)
174
+		);
175
+
176
+		$state->update($ad);
177
+		$state->update(ParagonIE_Sodium_Core_Util::store64_le($adlen));
178
+		$state->update($ciphertext);
179
+		$state->update(ParagonIE_Sodium_Core_Util::store64_le($len));
180
+		return $ciphertext . $state->finish();
181
+	}
182
+
183
+	/**
184
+	 * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
185
+	 *
186
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
187
+	 *
188
+	 * @param string $message
189
+	 * @param string $ad
190
+	 * @param string $nonce
191
+	 * @param string $key
192
+	 * @return string
193
+	 * @throws SodiumException
194
+	 * @throws TypeError
195
+	 */
196
+	public static function aead_chacha20poly1305_ietf_decrypt(
197
+		$message = '',
198
+		$ad = '',
199
+		$nonce = '',
200
+		$key = ''
201
+	) {
202
+		/** @var int $adlen - Length of associated data */
203
+		$adlen = ParagonIE_Sodium_Core_Util::strlen($ad);
204
+
205
+		/** @var int $len - Length of message (ciphertext + MAC) */
206
+		$len = ParagonIE_Sodium_Core_Util::strlen($message);
207
+
208
+		/** @var int  $clen - Length of ciphertext */
209
+		$clen = $len - self::aead_chacha20poly1305_IETF_ABYTES;
210
+
211
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
212
+		$block0 = ParagonIE_Sodium_Core_ChaCha20::ietfStream(
213
+			32,
214
+			$nonce,
215
+			$key
216
+		);
217
+
218
+		/** @var string $mac - Message authentication code */
219
+		$mac = ParagonIE_Sodium_Core_Util::substr(
220
+			$message,
221
+			$len - self::aead_chacha20poly1305_IETF_ABYTES,
222
+			self::aead_chacha20poly1305_IETF_ABYTES
223
+		);
224
+
225
+		/** @var string $ciphertext - The encrypted message (sans MAC) */
226
+		$ciphertext = ParagonIE_Sodium_Core_Util::substr(
227
+			$message,
228
+			0,
229
+			$len - self::aead_chacha20poly1305_IETF_ABYTES
230
+		);
231
+
232
+		/* Recalculate the Poly1305 authentication tag (MAC): */
233
+		$state = new ParagonIE_Sodium_Core_Poly1305_State($block0);
234
+		try {
235
+			ParagonIE_Sodium_Compat::memzero($block0);
236
+		} catch (SodiumException $ex) {
237
+			$block0 = null;
238
+		}
239
+		$state->update($ad);
240
+		$state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
241
+		$state->update($ciphertext);
242
+		$state->update(str_repeat("\x00", (0x10 - $clen) & 0xf));
243
+		$state->update(ParagonIE_Sodium_Core_Util::store64_le($adlen));
244
+		$state->update(ParagonIE_Sodium_Core_Util::store64_le($clen));
245
+		$computed_mac = $state->finish();
246
+
247
+		/* Compare the given MAC with the recalculated MAC: */
248
+		if (!ParagonIE_Sodium_Core_Util::verify_16($computed_mac, $mac)) {
249
+			throw new SodiumException('Invalid MAC');
250
+		}
251
+
252
+		// Here, we know that the MAC is valid, so we decrypt and return the plaintext
253
+		return ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
254
+			$ciphertext,
255
+			$nonce,
256
+			$key,
257
+			ParagonIE_Sodium_Core_Util::store64_le(1)
258
+		);
259
+	}
260
+
261
+	/**
262
+	 * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
263
+	 *
264
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
265
+	 *
266
+	 * @param string $message
267
+	 * @param string $ad
268
+	 * @param string $nonce
269
+	 * @param string $key
270
+	 * @return string
271
+	 * @throws SodiumException
272
+	 * @throws TypeError
273
+	 */
274
+	public static function aead_chacha20poly1305_ietf_encrypt(
275
+		$message = '',
276
+		$ad = '',
277
+		$nonce = '',
278
+		$key = ''
279
+	) {
280
+		/** @var int $len - Length of the plaintext message */
281
+		$len = ParagonIE_Sodium_Core_Util::strlen($message);
282
+
283
+		/** @var int $adlen - Length of the associated data */
284
+		$adlen = ParagonIE_Sodium_Core_Util::strlen($ad);
285
+
286
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
287
+		$block0 = ParagonIE_Sodium_Core_ChaCha20::ietfStream(
288
+			32,
289
+			$nonce,
290
+			$key
291
+		);
292
+		$state = new ParagonIE_Sodium_Core_Poly1305_State($block0);
293
+		try {
294
+			ParagonIE_Sodium_Compat::memzero($block0);
295
+		} catch (SodiumException $ex) {
296
+			$block0 = null;
297
+		}
298
+
299
+		/** @var string $ciphertext - Raw encrypted data */
300
+		$ciphertext = ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
301
+			$message,
302
+			$nonce,
303
+			$key,
304
+			ParagonIE_Sodium_Core_Util::store64_le(1)
305
+		);
306
+
307
+		$state->update($ad);
308
+		$state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
309
+		$state->update($ciphertext);
310
+		$state->update(str_repeat("\x00", ((0x10 - $len) & 0xf)));
311
+		$state->update(ParagonIE_Sodium_Core_Util::store64_le($adlen));
312
+		$state->update(ParagonIE_Sodium_Core_Util::store64_le($len));
313
+		return $ciphertext . $state->finish();
314
+	}
315
+
316
+	/**
317
+	 * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
318
+	 *
319
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
320
+	 *
321
+	 * @param string $message
322
+	 * @param string $ad
323
+	 * @param string $nonce
324
+	 * @param string $key
325
+	 * @return string
326
+	 * @throws SodiumException
327
+	 * @throws TypeError
328
+	 */
329
+	public static function aead_xchacha20poly1305_ietf_decrypt(
330
+		$message = '',
331
+		$ad = '',
332
+		$nonce = '',
333
+		$key = ''
334
+	) {
335
+		$subkey = ParagonIE_Sodium_Core_HChaCha20::hChaCha20(
336
+			ParagonIE_Sodium_Core_Util::substr($nonce, 0, 16),
337
+			$key
338
+		);
339
+		$nonceLast = "\x00\x00\x00\x00" .
340
+			ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8);
341
+
342
+		return self::aead_chacha20poly1305_ietf_decrypt($message, $ad, $nonceLast, $subkey);
343
+	}
344
+
345
+	/**
346
+	 * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
347
+	 *
348
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
349
+	 *
350
+	 * @param string $message
351
+	 * @param string $ad
352
+	 * @param string $nonce
353
+	 * @param string $key
354
+	 * @return string
355
+	 * @throws SodiumException
356
+	 * @throws TypeError
357
+	 */
358
+	public static function aead_xchacha20poly1305_ietf_encrypt(
359
+		$message = '',
360
+		$ad = '',
361
+		$nonce = '',
362
+		$key = ''
363
+	) {
364
+		$subkey = ParagonIE_Sodium_Core_HChaCha20::hChaCha20(
365
+			ParagonIE_Sodium_Core_Util::substr($nonce, 0, 16),
366
+			$key
367
+		);
368
+		$nonceLast = "\x00\x00\x00\x00" .
369
+			ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8);
370
+
371
+		return self::aead_chacha20poly1305_ietf_encrypt($message, $ad, $nonceLast, $subkey);
372
+	}
373
+
374
+	/**
375
+	 * HMAC-SHA-512-256 (a.k.a. the leftmost 256 bits of HMAC-SHA-512)
376
+	 *
377
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
378
+	 *
379
+	 * @param string $message
380
+	 * @param string $key
381
+	 * @return string
382
+	 * @throws TypeError
383
+	 */
384
+	public static function auth($message, $key)
385
+	{
386
+		return ParagonIE_Sodium_Core_Util::substr(
387
+			hash_hmac('sha512', $message, $key, true),
388
+			0,
389
+			32
390
+		);
391
+	}
392
+
393
+	/**
394
+	 * HMAC-SHA-512-256 validation. Constant-time via hash_equals().
395
+	 *
396
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
397
+	 *
398
+	 * @param string $mac
399
+	 * @param string $message
400
+	 * @param string $key
401
+	 * @return bool
402
+	 * @throws SodiumException
403
+	 * @throws TypeError
404
+	 */
405
+	public static function auth_verify($mac, $message, $key)
406
+	{
407
+		return ParagonIE_Sodium_Core_Util::hashEquals(
408
+			$mac,
409
+			self::auth($message, $key)
410
+		);
411
+	}
412
+
413
+	/**
414
+	 * X25519 key exchange followed by XSalsa20Poly1305 symmetric encryption
415
+	 *
416
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
417
+	 *
418
+	 * @param string $plaintext
419
+	 * @param string $nonce
420
+	 * @param string $keypair
421
+	 * @return string
422
+	 * @throws SodiumException
423
+	 * @throws TypeError
424
+	 */
425
+	public static function box($plaintext, $nonce, $keypair)
426
+	{
427
+		$c = self::secretbox(
428
+			$plaintext,
429
+			$nonce,
430
+			self::box_beforenm(
431
+				self::box_secretkey($keypair),
432
+				self::box_publickey($keypair)
433
+			)
434
+		);
435
+		return $c;
436
+	}
437
+
438
+	/**
439
+	 * X25519-XSalsa20-Poly1305 with one ephemeral X25519 keypair.
440
+	 *
441
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
442
+	 *
443
+	 * @param string $message
444
+	 * @param string $publicKey
445
+	 * @return string
446
+	 * @throws SodiumException
447
+	 * @throws TypeError
448
+	 */
449
+	public static function box_seal($message, $publicKey)
450
+	{
451
+		/** @var string $ephemeralKeypair */
452
+		$ephemeralKeypair = self::box_keypair();
453
+
454
+		/** @var string $ephemeralSK */
455
+		$ephemeralSK = self::box_secretkey($ephemeralKeypair);
456
+
457
+		/** @var string $ephemeralPK */
458
+		$ephemeralPK = self::box_publickey($ephemeralKeypair);
459
+
460
+		/** @var string $nonce */
461
+		$nonce = self::generichash(
462
+			$ephemeralPK . $publicKey,
463
+			'',
464
+			24
465
+		);
466
+
467
+		/** @var string $keypair - The combined keypair used in crypto_box() */
468
+		$keypair = self::box_keypair_from_secretkey_and_publickey($ephemeralSK, $publicKey);
469
+
470
+		/** @var string $ciphertext Ciphertext + MAC from crypto_box */
471
+		$ciphertext = self::box($message, $nonce, $keypair);
472
+		try {
473
+			ParagonIE_Sodium_Compat::memzero($ephemeralKeypair);
474
+			ParagonIE_Sodium_Compat::memzero($ephemeralSK);
475
+			ParagonIE_Sodium_Compat::memzero($nonce);
476
+		} catch (SodiumException $ex) {
477
+			$ephemeralKeypair = null;
478
+			$ephemeralSK = null;
479
+			$nonce = null;
480
+		}
481
+		return $ephemeralPK . $ciphertext;
482
+	}
483
+
484
+	/**
485
+	 * Opens a message encrypted via box_seal().
486
+	 *
487
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
488
+	 *
489
+	 * @param string $message
490
+	 * @param string $keypair
491
+	 * @return string
492
+	 * @throws SodiumException
493
+	 * @throws TypeError
494
+	 */
495
+	public static function box_seal_open($message, $keypair)
496
+	{
497
+		/** @var string $ephemeralPK */
498
+		$ephemeralPK = ParagonIE_Sodium_Core_Util::substr($message, 0, 32);
499
+
500
+		/** @var string $ciphertext (ciphertext + MAC) */
501
+		$ciphertext = ParagonIE_Sodium_Core_Util::substr($message, 32);
502
+
503
+		/** @var string $secretKey */
504
+		$secretKey = self::box_secretkey($keypair);
505
+
506
+		/** @var string $publicKey */
507
+		$publicKey = self::box_publickey($keypair);
508
+
509
+		/** @var string $nonce */
510
+		$nonce = self::generichash(
511
+			$ephemeralPK . $publicKey,
512
+			'',
513
+			24
514
+		);
515
+
516
+		/** @var string $keypair */
517
+		$keypair = self::box_keypair_from_secretkey_and_publickey($secretKey, $ephemeralPK);
518
+
519
+		/** @var string $m */
520
+		$m = self::box_open($ciphertext, $nonce, $keypair);
521
+		try {
522
+			ParagonIE_Sodium_Compat::memzero($secretKey);
523
+			ParagonIE_Sodium_Compat::memzero($ephemeralPK);
524
+			ParagonIE_Sodium_Compat::memzero($nonce);
525
+		} catch (SodiumException $ex) {
526
+			$secretKey = null;
527
+			$ephemeralPK = null;
528
+			$nonce = null;
529
+		}
530
+		return $m;
531
+	}
532
+
533
+	/**
534
+	 * Used by crypto_box() to get the crypto_secretbox() key.
535
+	 *
536
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
537
+	 *
538
+	 * @param string $sk
539
+	 * @param string $pk
540
+	 * @return string
541
+	 * @throws SodiumException
542
+	 * @throws TypeError
543
+	 */
544
+	public static function box_beforenm($sk, $pk)
545
+	{
546
+		return ParagonIE_Sodium_Core_HSalsa20::hsalsa20(
547
+			str_repeat("\x00", 16),
548
+			self::scalarmult($sk, $pk)
549
+		);
550
+	}
551
+
552
+	/**
553
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
554
+	 *
555
+	 * @return string
556
+	 * @throws Exception
557
+	 * @throws SodiumException
558
+	 * @throws TypeError
559
+	 */
560
+	public static function box_keypair()
561
+	{
562
+		$sKey = random_bytes(32);
563
+		$pKey = self::scalarmult_base($sKey);
564
+		return $sKey . $pKey;
565
+	}
566
+
567
+	/**
568
+	 * @param string $seed
569
+	 * @return string
570
+	 * @throws SodiumException
571
+	 * @throws TypeError
572
+	 */
573
+	public static function box_seed_keypair($seed)
574
+	{
575
+		$sKey = ParagonIE_Sodium_Core_Util::substr(
576
+			hash('sha512', $seed, true),
577
+			0,
578
+			32
579
+		);
580
+		$pKey = self::scalarmult_base($sKey);
581
+		return $sKey . $pKey;
582
+	}
583
+
584
+	/**
585
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
586
+	 *
587
+	 * @param string $sKey
588
+	 * @param string $pKey
589
+	 * @return string
590
+	 * @throws TypeError
591
+	 */
592
+	public static function box_keypair_from_secretkey_and_publickey($sKey, $pKey)
593
+	{
594
+		return ParagonIE_Sodium_Core_Util::substr($sKey, 0, 32) .
595
+			ParagonIE_Sodium_Core_Util::substr($pKey, 0, 32);
596
+	}
597
+
598
+	/**
599
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
600
+	 *
601
+	 * @param string $keypair
602
+	 * @return string
603
+	 * @throws RangeException
604
+	 * @throws TypeError
605
+	 */
606
+	public static function box_secretkey($keypair)
607
+	{
608
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== 64) {
609
+			throw new RangeException(
610
+				'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
611
+			);
612
+		}
613
+		return ParagonIE_Sodium_Core_Util::substr($keypair, 0, 32);
614
+	}
615
+
616
+	/**
617
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
618
+	 *
619
+	 * @param string $keypair
620
+	 * @return string
621
+	 * @throws RangeException
622
+	 * @throws TypeError
623
+	 */
624
+	public static function box_publickey($keypair)
625
+	{
626
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
627
+			throw new RangeException(
628
+				'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
629
+			);
630
+		}
631
+		return ParagonIE_Sodium_Core_Util::substr($keypair, 32, 32);
632
+	}
633
+
634
+	/**
635
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
636
+	 *
637
+	 * @param string $sKey
638
+	 * @return string
639
+	 * @throws RangeException
640
+	 * @throws SodiumException
641
+	 * @throws TypeError
642
+	 */
643
+	public static function box_publickey_from_secretkey($sKey)
644
+	{
645
+		if (ParagonIE_Sodium_Core_Util::strlen($sKey) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES) {
646
+			throw new RangeException(
647
+				'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES bytes long.'
648
+			);
649
+		}
650
+		return self::scalarmult_base($sKey);
651
+	}
652
+
653
+	/**
654
+	 * Decrypt a message encrypted with box().
655
+	 *
656
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
657
+	 *
658
+	 * @param string $ciphertext
659
+	 * @param string $nonce
660
+	 * @param string $keypair
661
+	 * @return string
662
+	 * @throws SodiumException
663
+	 * @throws TypeError
664
+	 */
665
+	public static function box_open($ciphertext, $nonce, $keypair)
666
+	{
667
+		return self::secretbox_open(
668
+			$ciphertext,
669
+			$nonce,
670
+			self::box_beforenm(
671
+				self::box_secretkey($keypair),
672
+				self::box_publickey($keypair)
673
+			)
674
+		);
675
+	}
676
+
677
+	/**
678
+	 * Calculate a BLAKE2b hash.
679
+	 *
680
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
681
+	 *
682
+	 * @param string $message
683
+	 * @param string|null $key
684
+	 * @param int $outlen
685
+	 * @return string
686
+	 * @throws RangeException
687
+	 * @throws SodiumException
688
+	 * @throws TypeError
689
+	 */
690
+	public static function generichash($message, $key = '', $outlen = 32)
691
+	{
692
+		// This ensures that ParagonIE_Sodium_Core_BLAKE2b::$iv is initialized
693
+		ParagonIE_Sodium_Core_BLAKE2b::pseudoConstructor();
694
+
695
+		$k = null;
696
+		if (!empty($key)) {
697
+			/** @var SplFixedArray $k */
698
+			$k = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($key);
699
+			if ($k->count() > ParagonIE_Sodium_Core_BLAKE2b::KEYBYTES) {
700
+				throw new RangeException('Invalid key size');
701
+			}
702
+		}
703
+
704
+		/** @var SplFixedArray $in */
705
+		$in = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($message);
706
+
707
+		/** @var SplFixedArray $ctx */
708
+		$ctx = ParagonIE_Sodium_Core_BLAKE2b::init($k, $outlen);
709
+		ParagonIE_Sodium_Core_BLAKE2b::update($ctx, $in, $in->count());
710
+
711
+		/** @var SplFixedArray $out */
712
+		$out = new SplFixedArray($outlen);
713
+		$out = ParagonIE_Sodium_Core_BLAKE2b::finish($ctx, $out);
714
+
715
+		/** @var array<int, int> */
716
+		$outArray = $out->toArray();
717
+		return ParagonIE_Sodium_Core_Util::intArrayToString($outArray);
718
+	}
719
+
720
+	/**
721
+	 * Finalize a BLAKE2b hashing context, returning the hash.
722
+	 *
723
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
724
+	 *
725
+	 * @param string $ctx
726
+	 * @param int $outlen
727
+	 * @return string
728
+	 * @throws SodiumException
729
+	 * @throws TypeError
730
+	 */
731
+	public static function generichash_final($ctx, $outlen = 32)
732
+	{
733
+		if (!is_string($ctx)) {
734
+			throw new TypeError('Context must be a string');
735
+		}
736
+		$out = new SplFixedArray($outlen);
737
+
738
+		/** @var SplFixedArray $context */
739
+		$context = ParagonIE_Sodium_Core_BLAKE2b::stringToContext($ctx);
740
+
741
+		/** @var SplFixedArray $out */
742
+		$out = ParagonIE_Sodium_Core_BLAKE2b::finish($context, $out);
743
+
744
+		/** @var array<int, int> */
745
+		$outArray = $out->toArray();
746
+		return ParagonIE_Sodium_Core_Util::intArrayToString($outArray);
747
+	}
748
+
749
+	/**
750
+	 * Initialize a hashing context for BLAKE2b.
751
+	 *
752
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
753
+	 *
754
+	 * @param string $key
755
+	 * @param int $outputLength
756
+	 * @return string
757
+	 * @throws RangeException
758
+	 * @throws SodiumException
759
+	 * @throws TypeError
760
+	 */
761
+	public static function generichash_init($key = '', $outputLength = 32)
762
+	{
763
+		// This ensures that ParagonIE_Sodium_Core_BLAKE2b::$iv is initialized
764
+		ParagonIE_Sodium_Core_BLAKE2b::pseudoConstructor();
765
+
766
+		$k = null;
767
+		if (!empty($key)) {
768
+			$k = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($key);
769
+			if ($k->count() > ParagonIE_Sodium_Core_BLAKE2b::KEYBYTES) {
770
+				throw new RangeException('Invalid key size');
771
+			}
772
+		}
773
+
774
+		/** @var SplFixedArray $ctx */
775
+		$ctx = ParagonIE_Sodium_Core_BLAKE2b::init($k, $outputLength);
776
+
777
+		return ParagonIE_Sodium_Core_BLAKE2b::contextToString($ctx);
778
+	}
779
+
780
+	/**
781
+	 * Initialize a hashing context for BLAKE2b.
782
+	 *
783
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
784
+	 *
785
+	 * @param string $key
786
+	 * @param int $outputLength
787
+	 * @param string $salt
788
+	 * @param string $personal
789
+	 * @return string
790
+	 * @throws RangeException
791
+	 * @throws SodiumException
792
+	 * @throws TypeError
793
+	 */
794
+	public static function generichash_init_salt_personal(
795
+		$key = '',
796
+		$outputLength = 32,
797
+		$salt = '',
798
+		$personal = ''
799
+	) {
800
+		// This ensures that ParagonIE_Sodium_Core_BLAKE2b::$iv is initialized
801
+		ParagonIE_Sodium_Core_BLAKE2b::pseudoConstructor();
802
+
803
+		$k = null;
804
+		if (!empty($key)) {
805
+			$k = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($key);
806
+			if ($k->count() > ParagonIE_Sodium_Core_BLAKE2b::KEYBYTES) {
807
+				throw new RangeException('Invalid key size');
808
+			}
809
+		}
810
+		if (!empty($salt)) {
811
+			$s = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($salt);
812
+		} else {
813
+			$s = null;
814
+		}
815
+		if (!empty($salt)) {
816
+			$p = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($personal);
817
+		} else {
818
+			$p = null;
819
+		}
820
+
821
+		/** @var SplFixedArray $ctx */
822
+		$ctx = ParagonIE_Sodium_Core_BLAKE2b::init($k, $outputLength, $s, $p);
823
+
824
+		return ParagonIE_Sodium_Core_BLAKE2b::contextToString($ctx);
825
+	}
826
+
827
+	/**
828
+	 * Update a hashing context for BLAKE2b with $message
829
+	 *
830
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
831
+	 *
832
+	 * @param string $ctx
833
+	 * @param string $message
834
+	 * @return string
835
+	 * @throws SodiumException
836
+	 * @throws TypeError
837
+	 */
838
+	public static function generichash_update($ctx, $message)
839
+	{
840
+		// This ensures that ParagonIE_Sodium_Core_BLAKE2b::$iv is initialized
841
+		ParagonIE_Sodium_Core_BLAKE2b::pseudoConstructor();
842
+
843
+		/** @var SplFixedArray $context */
844
+		$context = ParagonIE_Sodium_Core_BLAKE2b::stringToContext($ctx);
845
+
846
+		/** @var SplFixedArray $in */
847
+		$in = ParagonIE_Sodium_Core_BLAKE2b::stringToSplFixedArray($message);
848
+
849
+		ParagonIE_Sodium_Core_BLAKE2b::update($context, $in, $in->count());
850
+
851
+		return ParagonIE_Sodium_Core_BLAKE2b::contextToString($context);
852
+	}
853
+
854
+	/**
855
+	 * Libsodium's crypto_kx().
856
+	 *
857
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
858
+	 *
859
+	 * @param string $my_sk
860
+	 * @param string $their_pk
861
+	 * @param string $client_pk
862
+	 * @param string $server_pk
863
+	 * @return string
864
+	 * @throws SodiumException
865
+	 * @throws TypeError
866
+	 */
867
+	public static function keyExchange($my_sk, $their_pk, $client_pk, $server_pk)
868
+	{
869
+		return ParagonIE_Sodium_Compat::crypto_generichash(
870
+			ParagonIE_Sodium_Compat::crypto_scalarmult($my_sk, $their_pk) .
871
+			$client_pk .
872
+			$server_pk
873
+		);
874
+	}
875
+
876
+	/**
877
+	 * ECDH over Curve25519
878
+	 *
879
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
880
+	 *
881
+	 * @param string $sKey
882
+	 * @param string $pKey
883
+	 * @return string
884
+	 *
885
+	 * @throws SodiumException
886
+	 * @throws TypeError
887
+	 */
888
+	public static function scalarmult($sKey, $pKey)
889
+	{
890
+		$q = ParagonIE_Sodium_Core_X25519::crypto_scalarmult_curve25519_ref10($sKey, $pKey);
891
+		self::scalarmult_throw_if_zero($q);
892
+		return $q;
893
+	}
894
+
895
+	/**
896
+	 * ECDH over Curve25519, using the basepoint.
897
+	 * Used to get a secret key from a public key.
898
+	 *
899
+	 * @param string $secret
900
+	 * @return string
901
+	 *
902
+	 * @throws SodiumException
903
+	 * @throws TypeError
904
+	 */
905
+	public static function scalarmult_base($secret)
906
+	{
907
+		$q = ParagonIE_Sodium_Core_X25519::crypto_scalarmult_curve25519_ref10_base($secret);
908
+		self::scalarmult_throw_if_zero($q);
909
+		return $q;
910
+	}
911
+
912
+	/**
913
+	 * This throws an Error if a zero public key was passed to the function.
914
+	 *
915
+	 * @param string $q
916
+	 * @return void
917
+	 * @throws SodiumException
918
+	 * @throws TypeError
919
+	 */
920
+	protected static function scalarmult_throw_if_zero($q)
921
+	{
922
+		$d = 0;
923
+		for ($i = 0; $i < self::box_curve25519xsalsa20poly1305_SECRETKEYBYTES; ++$i) {
924
+			$d |= ParagonIE_Sodium_Core_Util::chrToInt($q[$i]);
925
+		}
926
+
927
+		/* branch-free variant of === 0 */
928
+		if (-(1 & (($d - 1) >> 8))) {
929
+			throw new SodiumException('Zero public key is not allowed');
930
+		}
931
+	}
932
+
933
+	/**
934
+	 * XSalsa20-Poly1305 authenticated symmetric-key encryption.
935
+	 *
936
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
937
+	 *
938
+	 * @param string $plaintext
939
+	 * @param string $nonce
940
+	 * @param string $key
941
+	 * @return string
942
+	 * @throws SodiumException
943
+	 * @throws TypeError
944
+	 */
945
+	public static function secretbox($plaintext, $nonce, $key)
946
+	{
947
+		/** @var string $subkey */
948
+		$subkey = ParagonIE_Sodium_Core_HSalsa20::hsalsa20($nonce, $key);
949
+
950
+		/** @var string $block0 */
951
+		$block0 = str_repeat("\x00", 32);
952
+
953
+		/** @var int $mlen - Length of the plaintext message */
954
+		$mlen = ParagonIE_Sodium_Core_Util::strlen($plaintext);
955
+		$mlen0 = $mlen;
956
+		if ($mlen0 > 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES) {
957
+			$mlen0 = 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES;
958
+		}
959
+		$block0 .= ParagonIE_Sodium_Core_Util::substr($plaintext, 0, $mlen0);
960
+
961
+		/** @var string $block0 */
962
+		$block0 = ParagonIE_Sodium_Core_Salsa20::salsa20_xor(
963
+			$block0,
964
+			ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
965
+			$subkey
966
+		);
967
+
968
+		/** @var string $c */
969
+		$c = ParagonIE_Sodium_Core_Util::substr(
970
+			$block0,
971
+			self::secretbox_xsalsa20poly1305_ZEROBYTES
972
+		);
973
+		if ($mlen > $mlen0) {
974
+			$c .= ParagonIE_Sodium_Core_Salsa20::salsa20_xor_ic(
975
+				ParagonIE_Sodium_Core_Util::substr(
976
+					$plaintext,
977
+					self::secretbox_xsalsa20poly1305_ZEROBYTES
978
+				),
979
+				ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
980
+				1,
981
+				$subkey
982
+			);
983
+		}
984
+		$state = new ParagonIE_Sodium_Core_Poly1305_State(
985
+			ParagonIE_Sodium_Core_Util::substr(
986
+				$block0,
987
+				0,
988
+				self::onetimeauth_poly1305_KEYBYTES
989
+			)
990
+		);
991
+		try {
992
+			ParagonIE_Sodium_Compat::memzero($block0);
993
+			ParagonIE_Sodium_Compat::memzero($subkey);
994
+		} catch (SodiumException $ex) {
995
+			$block0 = null;
996
+			$subkey = null;
997
+		}
998
+
999
+		$state->update($c);
1000
+
1001
+		/** @var string $c - MAC || ciphertext */
1002
+		$c = $state->finish() . $c;
1003
+		unset($state);
1004
+
1005
+		return $c;
1006
+	}
1007
+
1008
+	/**
1009
+	 * Decrypt a ciphertext generated via secretbox().
1010
+	 *
1011
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1012
+	 *
1013
+	 * @param string $ciphertext
1014
+	 * @param string $nonce
1015
+	 * @param string $key
1016
+	 * @return string
1017
+	 * @throws SodiumException
1018
+	 * @throws TypeError
1019
+	 */
1020
+	public static function secretbox_open($ciphertext, $nonce, $key)
1021
+	{
1022
+		/** @var string $mac */
1023
+		$mac = ParagonIE_Sodium_Core_Util::substr(
1024
+			$ciphertext,
1025
+			0,
1026
+			self::secretbox_xsalsa20poly1305_MACBYTES
1027
+		);
1028
+
1029
+		/** @var string $c */
1030
+		$c = ParagonIE_Sodium_Core_Util::substr(
1031
+			$ciphertext,
1032
+			self::secretbox_xsalsa20poly1305_MACBYTES
1033
+		);
1034
+
1035
+		/** @var int $clen */
1036
+		$clen = ParagonIE_Sodium_Core_Util::strlen($c);
1037
+
1038
+		/** @var string $subkey */
1039
+		$subkey = ParagonIE_Sodium_Core_HSalsa20::hsalsa20($nonce, $key);
1040
+
1041
+		/** @var string $block0 */
1042
+		$block0 = ParagonIE_Sodium_Core_Salsa20::salsa20(
1043
+			64,
1044
+			ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
1045
+			$subkey
1046
+		);
1047
+		$verified = ParagonIE_Sodium_Core_Poly1305::onetimeauth_verify(
1048
+			$mac,
1049
+			$c,
1050
+			ParagonIE_Sodium_Core_Util::substr($block0, 0, 32)
1051
+		);
1052
+		if (!$verified) {
1053
+			try {
1054
+				ParagonIE_Sodium_Compat::memzero($subkey);
1055
+			} catch (SodiumException $ex) {
1056
+				$subkey = null;
1057
+			}
1058
+			throw new SodiumException('Invalid MAC');
1059
+		}
1060
+
1061
+		/** @var string $m - Decrypted message */
1062
+		$m = ParagonIE_Sodium_Core_Util::xorStrings(
1063
+			ParagonIE_Sodium_Core_Util::substr($block0, self::secretbox_xsalsa20poly1305_ZEROBYTES),
1064
+			ParagonIE_Sodium_Core_Util::substr($c, 0, self::secretbox_xsalsa20poly1305_ZEROBYTES)
1065
+		);
1066
+		if ($clen > self::secretbox_xsalsa20poly1305_ZEROBYTES) {
1067
+			// We had more than 1 block, so let's continue to decrypt the rest.
1068
+			$m .= ParagonIE_Sodium_Core_Salsa20::salsa20_xor_ic(
1069
+				ParagonIE_Sodium_Core_Util::substr(
1070
+					$c,
1071
+					self::secretbox_xsalsa20poly1305_ZEROBYTES
1072
+				),
1073
+				ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
1074
+				1,
1075
+				(string) $subkey
1076
+			);
1077
+		}
1078
+		return $m;
1079
+	}
1080
+
1081
+	/**
1082
+	 * XChaCha20-Poly1305 authenticated symmetric-key encryption.
1083
+	 *
1084
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1085
+	 *
1086
+	 * @param string $plaintext
1087
+	 * @param string $nonce
1088
+	 * @param string $key
1089
+	 * @return string
1090
+	 * @throws SodiumException
1091
+	 * @throws TypeError
1092
+	 */
1093
+	public static function secretbox_xchacha20poly1305($plaintext, $nonce, $key)
1094
+	{
1095
+		/** @var string $subkey */
1096
+		$subkey = ParagonIE_Sodium_Core_HChaCha20::hChaCha20(
1097
+			ParagonIE_Sodium_Core_Util::substr($nonce, 0, 16),
1098
+			$key
1099
+		);
1100
+		$nonceLast = ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8);
1101
+
1102
+		/** @var string $block0 */
1103
+		$block0 = str_repeat("\x00", 32);
1104
+
1105
+		/** @var int $mlen - Length of the plaintext message */
1106
+		$mlen = ParagonIE_Sodium_Core_Util::strlen($plaintext);
1107
+		$mlen0 = $mlen;
1108
+		if ($mlen0 > 64 - self::secretbox_xchacha20poly1305_ZEROBYTES) {
1109
+			$mlen0 = 64 - self::secretbox_xchacha20poly1305_ZEROBYTES;
1110
+		}
1111
+		$block0 .= ParagonIE_Sodium_Core_Util::substr($plaintext, 0, $mlen0);
1112
+
1113
+		/** @var string $block0 */
1114
+		$block0 = ParagonIE_Sodium_Core_ChaCha20::streamXorIc(
1115
+			$block0,
1116
+			$nonceLast,
1117
+			$subkey
1118
+		);
1119
+
1120
+		/** @var string $c */
1121
+		$c = ParagonIE_Sodium_Core_Util::substr(
1122
+			$block0,
1123
+			self::secretbox_xchacha20poly1305_ZEROBYTES
1124
+		);
1125
+		if ($mlen > $mlen0) {
1126
+			$c .= ParagonIE_Sodium_Core_ChaCha20::streamXorIc(
1127
+				ParagonIE_Sodium_Core_Util::substr(
1128
+					$plaintext,
1129
+					self::secretbox_xchacha20poly1305_ZEROBYTES
1130
+				),
1131
+				$nonceLast,
1132
+				$subkey,
1133
+				ParagonIE_Sodium_Core_Util::store64_le(1)
1134
+			);
1135
+		}
1136
+		$state = new ParagonIE_Sodium_Core_Poly1305_State(
1137
+			ParagonIE_Sodium_Core_Util::substr(
1138
+				$block0,
1139
+				0,
1140
+				self::onetimeauth_poly1305_KEYBYTES
1141
+			)
1142
+		);
1143
+		try {
1144
+			ParagonIE_Sodium_Compat::memzero($block0);
1145
+			ParagonIE_Sodium_Compat::memzero($subkey);
1146
+		} catch (SodiumException $ex) {
1147
+			$block0 = null;
1148
+			$subkey = null;
1149
+		}
1150
+
1151
+		$state->update($c);
1152
+
1153
+		/** @var string $c - MAC || ciphertext */
1154
+		$c = $state->finish() . $c;
1155
+		unset($state);
1156
+
1157
+		return $c;
1158
+	}
1159
+
1160
+	/**
1161
+	 * Decrypt a ciphertext generated via secretbox_xchacha20poly1305().
1162
+	 *
1163
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1164
+	 *
1165
+	 * @param string $ciphertext
1166
+	 * @param string $nonce
1167
+	 * @param string $key
1168
+	 * @return string
1169
+	 * @throws SodiumException
1170
+	 * @throws TypeError
1171
+	 */
1172
+	public static function secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key)
1173
+	{
1174
+		/** @var string $mac */
1175
+		$mac = ParagonIE_Sodium_Core_Util::substr(
1176
+			$ciphertext,
1177
+			0,
1178
+			self::secretbox_xchacha20poly1305_MACBYTES
1179
+		);
1180
+
1181
+		/** @var string $c */
1182
+		$c = ParagonIE_Sodium_Core_Util::substr(
1183
+			$ciphertext,
1184
+			self::secretbox_xchacha20poly1305_MACBYTES
1185
+		);
1186
+
1187
+		/** @var int $clen */
1188
+		$clen = ParagonIE_Sodium_Core_Util::strlen($c);
1189
+
1190
+		/** @var string $subkey */
1191
+		$subkey = ParagonIE_Sodium_Core_HChaCha20::hchacha20($nonce, $key);
1192
+
1193
+		/** @var string $block0 */
1194
+		$block0 = ParagonIE_Sodium_Core_ChaCha20::stream(
1195
+			64,
1196
+			ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
1197
+			$subkey
1198
+		);
1199
+		$verified = ParagonIE_Sodium_Core_Poly1305::onetimeauth_verify(
1200
+			$mac,
1201
+			$c,
1202
+			ParagonIE_Sodium_Core_Util::substr($block0, 0, 32)
1203
+		);
1204
+
1205
+		if (!$verified) {
1206
+			try {
1207
+				ParagonIE_Sodium_Compat::memzero($subkey);
1208
+			} catch (SodiumException $ex) {
1209
+				$subkey = null;
1210
+			}
1211
+			throw new SodiumException('Invalid MAC');
1212
+		}
1213
+
1214
+		/** @var string $m - Decrypted message */
1215
+		$m = ParagonIE_Sodium_Core_Util::xorStrings(
1216
+			ParagonIE_Sodium_Core_Util::substr($block0, self::secretbox_xchacha20poly1305_ZEROBYTES),
1217
+			ParagonIE_Sodium_Core_Util::substr($c, 0, self::secretbox_xchacha20poly1305_ZEROBYTES)
1218
+		);
1219
+
1220
+		if ($clen > self::secretbox_xchacha20poly1305_ZEROBYTES) {
1221
+			// We had more than 1 block, so let's continue to decrypt the rest.
1222
+			$m .= ParagonIE_Sodium_Core_ChaCha20::streamXorIc(
1223
+				ParagonIE_Sodium_Core_Util::substr(
1224
+					$c,
1225
+					self::secretbox_xchacha20poly1305_ZEROBYTES
1226
+				),
1227
+				ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
1228
+				(string) $subkey,
1229
+				ParagonIE_Sodium_Core_Util::store64_le(1)
1230
+			);
1231
+		}
1232
+		return $m;
1233
+	}
1234
+
1235
+	/**
1236
+	 * @param string $key
1237
+	 * @return array<int, string> Returns a state and a header.
1238
+	 * @throws Exception
1239
+	 * @throws SodiumException
1240
+	 */
1241
+	public static function secretstream_xchacha20poly1305_init_push($key)
1242
+	{
1243
+		# randombytes_buf(out, crypto_secretstream_xchacha20poly1305_HEADERBYTES);
1244
+		$out = random_bytes(24);
1245
+
1246
+		# crypto_core_hchacha20(state->k, out, k, NULL);
1247
+		$subkey = ParagonIE_Sodium_Core_HChaCha20::hChaCha20($out, $key);
1248
+		$state = new ParagonIE_Sodium_Core_SecretStream_State(
1249
+			$subkey,
1250
+			ParagonIE_Sodium_Core_Util::substr($out, 16, 8) . str_repeat("\0", 4)
1251
+		);
1252
+
1253
+		# _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1254
+		$state->counterReset();
1255
+
1256
+		# memcpy(STATE_INONCE(state), out + crypto_core_hchacha20_INPUTBYTES,
1257
+		#        crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1258
+		# memset(state->_pad, 0, sizeof state->_pad);
1259
+		return array(
1260
+			$state->toString(),
1261
+			$out
1262
+		);
1263
+	}
1264
+
1265
+	/**
1266
+	 * @param string $key
1267
+	 * @param string $header
1268
+	 * @return string Returns a state.
1269
+	 * @throws Exception
1270
+	 */
1271
+	public static function secretstream_xchacha20poly1305_init_pull($key, $header)
1272
+	{
1273
+		# crypto_core_hchacha20(state->k, in, k, NULL);
1274
+		$subkey = ParagonIE_Sodium_Core_HChaCha20::hChaCha20(
1275
+			ParagonIE_Sodium_Core_Util::substr($header, 0, 16),
1276
+			$key
1277
+		);
1278
+		$state = new ParagonIE_Sodium_Core_SecretStream_State(
1279
+			$subkey,
1280
+			ParagonIE_Sodium_Core_Util::substr($header, 16)
1281
+		);
1282
+		$state->counterReset();
1283
+		# memcpy(STATE_INONCE(state), in + crypto_core_hchacha20_INPUTBYTES,
1284
+		#     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1285
+		# memset(state->_pad, 0, sizeof state->_pad);
1286
+		# return 0;
1287
+		return $state->toString();
1288
+	}
1289
+
1290
+	/**
1291
+	 * @param string $state
1292
+	 * @param string $msg
1293
+	 * @param string $aad
1294
+	 * @param int $tag
1295
+	 * @return string
1296
+	 * @throws SodiumException
1297
+	 */
1298
+	public static function secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0)
1299
+	{
1300
+		$st = ParagonIE_Sodium_Core_SecretStream_State::fromString($state);
1301
+		# crypto_onetimeauth_poly1305_state poly1305_state;
1302
+		# unsigned char                     block[64U];
1303
+		# unsigned char                     slen[8U];
1304
+		# unsigned char                    *c;
1305
+		# unsigned char                    *mac;
1306
+
1307
+		$msglen = ParagonIE_Sodium_Core_Util::strlen($msg);
1308
+		$aadlen = ParagonIE_Sodium_Core_Util::strlen($aad);
1309
+
1310
+		if ((($msglen + 63) >> 6) > 0xfffffffe) {
1311
+			throw new SodiumException(
1312
+				'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1313
+			);
1314
+		}
1315
+
1316
+		# if (outlen_p != NULL) {
1317
+		#     *outlen_p = 0U;
1318
+		# }
1319
+		# if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1320
+		#     sodium_misuse();
1321
+		# }
1322
+
1323
+		# crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1324
+		# crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1325
+		# sodium_memzero(block, sizeof block);
1326
+		$auth = new ParagonIE_Sodium_Core_Poly1305_State(
1327
+			ParagonIE_Sodium_Core_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1328
+		);
1329
+
1330
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1331
+		$auth->update($aad);
1332
+
1333
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1334
+		#     (0x10 - adlen) & 0xf);
1335
+		$auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1336
+
1337
+		# memset(block, 0, sizeof block);
1338
+		# block[0] = tag;
1339
+		# crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1340
+		#                                    state->nonce, 1U, state->k);
1341
+		$block = ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
1342
+			ParagonIE_Sodium_Core_Util::intToChr($tag) . str_repeat("\0", 63),
1343
+			$st->getCombinedNonce(),
1344
+			$st->getKey(),
1345
+			ParagonIE_Sodium_Core_Util::store64_le(1)
1346
+		);
1347
+
1348
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1349
+		$auth->update($block);
1350
+
1351
+		# out[0] = block[0];
1352
+		$out = $block[0];
1353
+		# c = out + (sizeof tag);
1354
+		# crypto_stream_chacha20_ietf_xor_ic(c, m, mlen, state->nonce, 2U, state->k);
1355
+		$cipher = ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
1356
+			$msg,
1357
+			$st->getCombinedNonce(),
1358
+			$st->getKey(),
1359
+			ParagonIE_Sodium_Core_Util::store64_le(2)
1360
+		);
1361
+
1362
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1363
+		$auth->update($cipher);
1364
+
1365
+		$out .= $cipher;
1366
+		unset($cipher);
1367
+
1368
+		# crypto_onetimeauth_poly1305_update
1369
+		# (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1370
+		$auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1371
+
1372
+		# STORE64_LE(slen, (uint64_t) adlen);
1373
+		$slen = ParagonIE_Sodium_Core_Util::store64_le($aadlen);
1374
+
1375
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1376
+		$auth->update($slen);
1377
+
1378
+		# STORE64_LE(slen, (sizeof block) + mlen);
1379
+		$slen = ParagonIE_Sodium_Core_Util::store64_le(64 + $msglen);
1380
+
1381
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1382
+		$auth->update($slen);
1383
+
1384
+		# mac = c + mlen;
1385
+		# crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1386
+		$mac = $auth->finish();
1387
+		$out .= $mac;
1388
+
1389
+		# sodium_memzero(&poly1305_state, sizeof poly1305_state);
1390
+		unset($auth);
1391
+
1392
+
1393
+		# XOR_BUF(STATE_INONCE(state), mac,
1394
+		#     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1395
+		$st->xorNonce($mac);
1396
+
1397
+		# sodium_increment(STATE_COUNTER(state),
1398
+		#     crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1399
+		$st->incrementCounter();
1400
+		// Overwrite by reference:
1401
+		$state = $st->toString();
1402
+
1403
+		/** @var bool $rekey */
1404
+		$rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1405
+		# if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1406
+		#     sodium_is_zero(STATE_COUNTER(state),
1407
+		#         crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1408
+		#     crypto_secretstream_xchacha20poly1305_rekey(state);
1409
+		# }
1410
+		if ($rekey || $st->needsRekey()) {
1411
+			// DO REKEY
1412
+			self::secretstream_xchacha20poly1305_rekey($state);
1413
+		}
1414
+		# if (outlen_p != NULL) {
1415
+		#     *outlen_p = crypto_secretstream_xchacha20poly1305_ABYTES + mlen;
1416
+		# }
1417
+		return $out;
1418
+	}
1419
+
1420
+	/**
1421
+	 * @param string $state
1422
+	 * @param string $cipher
1423
+	 * @param string $aad
1424
+	 * @return bool|array{0: string, 1: int}
1425
+	 * @throws SodiumException
1426
+	 */
1427
+	public static function secretstream_xchacha20poly1305_pull(&$state, $cipher, $aad = '')
1428
+	{
1429
+		$st = ParagonIE_Sodium_Core_SecretStream_State::fromString($state);
1430
+
1431
+		$cipherlen = ParagonIE_Sodium_Core_Util::strlen($cipher);
1432
+		#     mlen = inlen - crypto_secretstream_xchacha20poly1305_ABYTES;
1433
+		$msglen = $cipherlen - ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_ABYTES;
1434
+		$aadlen = ParagonIE_Sodium_Core_Util::strlen($aad);
1435
+
1436
+		#     if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1437
+		#         sodium_misuse();
1438
+		#     }
1439
+		if ((($msglen + 63) >> 6) > 0xfffffffe) {
1440
+			throw new SodiumException(
1441
+				'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1442
+			);
1443
+		}
1444
+
1445
+		#     crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1446
+		#     crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1447
+		#     sodium_memzero(block, sizeof block);
1448
+		$auth = new ParagonIE_Sodium_Core_Poly1305_State(
1449
+			ParagonIE_Sodium_Core_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1450
+		);
1451
+
1452
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1453
+		$auth->update($aad);
1454
+
1455
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1456
+		#         (0x10 - adlen) & 0xf);
1457
+		$auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1458
+
1459
+
1460
+		#     memset(block, 0, sizeof block);
1461
+		#     block[0] = in[0];
1462
+		#     crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1463
+		#                                        state->nonce, 1U, state->k);
1464
+		$block = ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
1465
+			$cipher[0] . str_repeat("\0", 63),
1466
+			$st->getCombinedNonce(),
1467
+			$st->getKey(),
1468
+			ParagonIE_Sodium_Core_Util::store64_le(1)
1469
+		);
1470
+		#     tag = block[0];
1471
+		#     block[0] = in[0];
1472
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1473
+		$tag = ParagonIE_Sodium_Core_Util::chrToInt($block[0]);
1474
+		$block[0] = $cipher[0];
1475
+		$auth->update($block);
1476
+
1477
+
1478
+		#     c = in + (sizeof tag);
1479
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1480
+		$auth->update(ParagonIE_Sodium_Core_Util::substr($cipher, 1, $msglen));
1481
+
1482
+		#     crypto_onetimeauth_poly1305_update
1483
+		#     (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1484
+		$auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1485
+
1486
+		#     STORE64_LE(slen, (uint64_t) adlen);
1487
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1488
+		$slen = ParagonIE_Sodium_Core_Util::store64_le($aadlen);
1489
+		$auth->update($slen);
1490
+
1491
+		#     STORE64_LE(slen, (sizeof block) + mlen);
1492
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1493
+		$slen = ParagonIE_Sodium_Core_Util::store64_le(64 + $msglen);
1494
+		$auth->update($slen);
1495
+
1496
+		#     crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1497
+		#     sodium_memzero(&poly1305_state, sizeof poly1305_state);
1498
+		$mac = $auth->finish();
1499
+
1500
+		#     stored_mac = c + mlen;
1501
+		#     if (sodium_memcmp(mac, stored_mac, sizeof mac) != 0) {
1502
+		#     sodium_memzero(mac, sizeof mac);
1503
+		#         return -1;
1504
+		#     }
1505
+
1506
+		$stored = ParagonIE_Sodium_Core_Util::substr($cipher, $msglen + 1, 16);
1507
+		if (!ParagonIE_Sodium_Core_Util::hashEquals($mac, $stored)) {
1508
+			return false;
1509
+		}
1510
+
1511
+		#     crypto_stream_chacha20_ietf_xor_ic(m, c, mlen, state->nonce, 2U, state->k);
1512
+		$out = ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
1513
+			ParagonIE_Sodium_Core_Util::substr($cipher, 1, $msglen),
1514
+			$st->getCombinedNonce(),
1515
+			$st->getKey(),
1516
+			ParagonIE_Sodium_Core_Util::store64_le(2)
1517
+		);
1518
+
1519
+		#     XOR_BUF(STATE_INONCE(state), mac,
1520
+		#         crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1521
+		$st->xorNonce($mac);
1522
+
1523
+		#     sodium_increment(STATE_COUNTER(state),
1524
+		#         crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1525
+		$st->incrementCounter();
1526
+
1527
+		#     if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1528
+		#         sodium_is_zero(STATE_COUNTER(state),
1529
+		#             crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1530
+		#         crypto_secretstream_xchacha20poly1305_rekey(state);
1531
+		#     }
1532
+
1533
+		// Overwrite by reference:
1534
+		$state = $st->toString();
1535
+
1536
+		/** @var bool $rekey */
1537
+		$rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1538
+		if ($rekey || $st->needsRekey()) {
1539
+			// DO REKEY
1540
+			self::secretstream_xchacha20poly1305_rekey($state);
1541
+		}
1542
+		return array($out, $tag);
1543
+	}
1544
+
1545
+	/**
1546
+	 * @param string $state
1547
+	 * @return void
1548
+	 * @throws SodiumException
1549
+	 */
1550
+	public static function secretstream_xchacha20poly1305_rekey(&$state)
1551
+	{
1552
+		$st = ParagonIE_Sodium_Core_SecretStream_State::fromString($state);
1553
+		# unsigned char new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES +
1554
+		# crypto_secretstream_xchacha20poly1305_INONCEBYTES];
1555
+		# size_t        i;
1556
+		# for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1557
+		#     new_key_and_inonce[i] = state->k[i];
1558
+		# }
1559
+		$new_key_and_inonce = $st->getKey();
1560
+
1561
+		# for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1562
+		#     new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i] =
1563
+		#         STATE_INONCE(state)[i];
1564
+		# }
1565
+		$new_key_and_inonce .= ParagonIE_Sodium_Core_Util::substR($st->getNonce(), 0, 8);
1566
+
1567
+		# crypto_stream_chacha20_ietf_xor(new_key_and_inonce, new_key_and_inonce,
1568
+		#                                 sizeof new_key_and_inonce,
1569
+		#                                 state->nonce, state->k);
1570
+
1571
+		$st->rekey(ParagonIE_Sodium_Core_ChaCha20::ietfStreamXorIc(
1572
+			$new_key_and_inonce,
1573
+			$st->getCombinedNonce(),
1574
+			$st->getKey(),
1575
+			ParagonIE_Sodium_Core_Util::store64_le(0)
1576
+		));
1577
+
1578
+		# for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1579
+		#     state->k[i] = new_key_and_inonce[i];
1580
+		# }
1581
+		# for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1582
+		#     STATE_INONCE(state)[i] =
1583
+		#          new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i];
1584
+		# }
1585
+		# _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1586
+		$st->counterReset();
1587
+
1588
+		$state = $st->toString();
1589
+	}
1590
+
1591
+	/**
1592
+	 * Detached Ed25519 signature.
1593
+	 *
1594
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1595
+	 *
1596
+	 * @param string $message
1597
+	 * @param string $sk
1598
+	 * @return string
1599
+	 * @throws SodiumException
1600
+	 * @throws TypeError
1601
+	 */
1602
+	public static function sign_detached($message, $sk)
1603
+	{
1604
+		return ParagonIE_Sodium_Core_Ed25519::sign_detached($message, $sk);
1605
+	}
1606
+
1607
+	/**
1608
+	 * Attached Ed25519 signature. (Returns a signed message.)
1609
+	 *
1610
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1611
+	 *
1612
+	 * @param string $message
1613
+	 * @param string $sk
1614
+	 * @return string
1615
+	 * @throws SodiumException
1616
+	 * @throws TypeError
1617
+	 */
1618
+	public static function sign($message, $sk)
1619
+	{
1620
+		return ParagonIE_Sodium_Core_Ed25519::sign($message, $sk);
1621
+	}
1622
+
1623
+	/**
1624
+	 * Opens a signed message. If valid, returns the message.
1625
+	 *
1626
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1627
+	 *
1628
+	 * @param string $signedMessage
1629
+	 * @param string $pk
1630
+	 * @return string
1631
+	 * @throws SodiumException
1632
+	 * @throws TypeError
1633
+	 */
1634
+	public static function sign_open($signedMessage, $pk)
1635
+	{
1636
+		return ParagonIE_Sodium_Core_Ed25519::sign_open($signedMessage, $pk);
1637
+	}
1638
+
1639
+	/**
1640
+	 * Verify a detached signature of a given message and public key.
1641
+	 *
1642
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1643
+	 *
1644
+	 * @param string $signature
1645
+	 * @param string $message
1646
+	 * @param string $pk
1647
+	 * @return bool
1648
+	 * @throws SodiumException
1649
+	 * @throws TypeError
1650
+	 */
1651
+	public static function sign_verify_detached($signature, $message, $pk)
1652
+	{
1653
+		return ParagonIE_Sodium_Core_Ed25519::verify_detached($signature, $message, $pk);
1654
+	}
1655 1655
 }
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/File.php 1 patch
Indentation   +1532 added lines, -1532 removed lines patch added patch discarded remove patch
@@ -1,1560 +1,1560 @@
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_File', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 /**
7 7
  * Class ParagonIE_Sodium_File
8 8
  */
9 9
 class ParagonIE_Sodium_File extends ParagonIE_Sodium_Core_Util
10 10
 {
11
-    /* PHP's default buffer size is 8192 for fread()/fwrite(). */
12
-    const BUFFER_SIZE = 8192;
13
-
14
-    /**
15
-     * Box a file (rather than a string). Uses less memory than
16
-     * ParagonIE_Sodium_Compat::crypto_box(), but produces
17
-     * the same result.
18
-     *
19
-     * @param string $inputFile  Absolute path to a file on the filesystem
20
-     * @param string $outputFile Absolute path to a file on the filesystem
21
-     * @param string $nonce      Number to be used only once
22
-     * @param string $keyPair    ECDH secret key and ECDH public key concatenated
23
-     *
24
-     * @return bool
25
-     * @throws SodiumException
26
-     * @throws TypeError
27
-     */
28
-    public static function box($inputFile, $outputFile, $nonce, $keyPair)
29
-    {
30
-        /* Type checks: */
31
-        if (!is_string($inputFile)) {
32
-            throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given.');
33
-        }
34
-        if (!is_string($outputFile)) {
35
-            throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
36
-        }
37
-        if (!is_string($nonce)) {
38
-            throw new TypeError('Argument 3 must be a string, ' . gettype($nonce) . ' given.');
39
-        }
40
-
41
-        /* Input validation: */
42
-        if (!is_string($keyPair)) {
43
-            throw new TypeError('Argument 4 must be a string, ' . gettype($keyPair) . ' given.');
44
-        }
45
-        if (self::strlen($nonce) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_NONCEBYTES) {
46
-            throw new TypeError('Argument 3 must be CRYPTO_BOX_NONCEBYTES bytes');
47
-        }
48
-        if (self::strlen($keyPair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
49
-            throw new TypeError('Argument 4 must be CRYPTO_BOX_KEYPAIRBYTES bytes');
50
-        }
51
-
52
-        /** @var int $size */
53
-        $size = filesize($inputFile);
54
-        if (!is_int($size)) {
55
-            throw new SodiumException('Could not obtain the file size');
56
-        }
57
-
58
-        /** @var resource $ifp */
59
-        $ifp = fopen($inputFile, 'rb');
60
-        if (!is_resource($ifp)) {
61
-            throw new SodiumException('Could not open input file for reading');
62
-        }
63
-
64
-        /** @var resource $ofp */
65
-        $ofp = fopen($outputFile, 'wb');
66
-        if (!is_resource($ofp)) {
67
-            fclose($ifp);
68
-            throw new SodiumException('Could not open output file for writing');
69
-        }
70
-
71
-        $res = self::box_encrypt($ifp, $ofp, $size, $nonce, $keyPair);
72
-        fclose($ifp);
73
-        fclose($ofp);
74
-        return $res;
75
-    }
76
-
77
-    /**
78
-     * Open a boxed file (rather than a string). Uses less memory than
79
-     * ParagonIE_Sodium_Compat::crypto_box_open(), but produces
80
-     * the same result.
81
-     *
82
-     * Warning: Does not protect against TOCTOU attacks. You should
83
-     * just load the file into memory and use crypto_box_open() if
84
-     * you are worried about those.
85
-     *
86
-     * @param string $inputFile
87
-     * @param string $outputFile
88
-     * @param string $nonce
89
-     * @param string $keypair
90
-     * @return bool
91
-     * @throws SodiumException
92
-     * @throws TypeError
93
-     */
94
-    public static function box_open($inputFile, $outputFile, $nonce, $keypair)
95
-    {
96
-        /* Type checks: */
97
-        if (!is_string($inputFile)) {
98
-            throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given.');
99
-        }
100
-        if (!is_string($outputFile)) {
101
-            throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
102
-        }
103
-        if (!is_string($nonce)) {
104
-            throw new TypeError('Argument 3 must be a string, ' . gettype($nonce) . ' given.');
105
-        }
106
-        if (!is_string($keypair)) {
107
-            throw new TypeError('Argument 4 must be a string, ' . gettype($keypair) . ' given.');
108
-        }
109
-
110
-        /* Input validation: */
111
-        if (self::strlen($nonce) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_NONCEBYTES) {
112
-            throw new TypeError('Argument 4 must be CRYPTO_BOX_NONCEBYTES bytes');
113
-        }
114
-        if (self::strlen($keypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
115
-            throw new TypeError('Argument 4 must be CRYPTO_BOX_KEYPAIRBYTES bytes');
116
-        }
117
-
118
-        /** @var int $size */
119
-        $size = filesize($inputFile);
120
-        if (!is_int($size)) {
121
-            throw new SodiumException('Could not obtain the file size');
122
-        }
123
-
124
-        /** @var resource $ifp */
125
-        $ifp = fopen($inputFile, 'rb');
126
-        if (!is_resource($ifp)) {
127
-            throw new SodiumException('Could not open input file for reading');
128
-        }
129
-
130
-        /** @var resource $ofp */
131
-        $ofp = fopen($outputFile, 'wb');
132
-        if (!is_resource($ofp)) {
133
-            fclose($ifp);
134
-            throw new SodiumException('Could not open output file for writing');
135
-        }
136
-
137
-        $res = self::box_decrypt($ifp, $ofp, $size, $nonce, $keypair);
138
-        fclose($ifp);
139
-        fclose($ofp);
140
-        try {
141
-            ParagonIE_Sodium_Compat::memzero($nonce);
142
-            ParagonIE_Sodium_Compat::memzero($ephKeypair);
143
-        } catch (SodiumException $ex) {
144
-            if (isset($ephKeypair)) {
145
-                unset($ephKeypair);
146
-            }
147
-        }
148
-        return $res;
149
-    }
150
-
151
-    /**
152
-     * Seal a file (rather than a string). Uses less memory than
153
-     * ParagonIE_Sodium_Compat::crypto_box_seal(), but produces
154
-     * the same result.
155
-     *
156
-     * @param string $inputFile  Absolute path to a file on the filesystem
157
-     * @param string $outputFile Absolute path to a file on the filesystem
158
-     * @param string $publicKey  ECDH public key
159
-     *
160
-     * @return bool
161
-     * @throws SodiumException
162
-     * @throws TypeError
163
-     */
164
-    public static function box_seal($inputFile, $outputFile, $publicKey)
165
-    {
166
-        /* Type checks: */
167
-        if (!is_string($inputFile)) {
168
-            throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given.');
169
-        }
170
-        if (!is_string($outputFile)) {
171
-            throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
172
-        }
173
-        if (!is_string($publicKey)) {
174
-            throw new TypeError('Argument 3 must be a string, ' . gettype($publicKey) . ' given.');
175
-        }
176
-
177
-        /* Input validation: */
178
-        if (self::strlen($publicKey) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_PUBLICKEYBYTES) {
179
-            throw new TypeError('Argument 3 must be CRYPTO_BOX_PUBLICKEYBYTES bytes');
180
-        }
181
-
182
-        /** @var int $size */
183
-        $size = filesize($inputFile);
184
-        if (!is_int($size)) {
185
-            throw new SodiumException('Could not obtain the file size');
186
-        }
187
-
188
-        /** @var resource $ifp */
189
-        $ifp = fopen($inputFile, 'rb');
190
-        if (!is_resource($ifp)) {
191
-            throw new SodiumException('Could not open input file for reading');
192
-        }
193
-
194
-        /** @var resource $ofp */
195
-        $ofp = fopen($outputFile, 'wb');
196
-        if (!is_resource($ofp)) {
197
-            fclose($ifp);
198
-            throw new SodiumException('Could not open output file for writing');
199
-        }
200
-
201
-        /** @var string $ephKeypair */
202
-        $ephKeypair = ParagonIE_Sodium_Compat::crypto_box_keypair();
203
-
204
-        /** @var string $msgKeypair */
205
-        $msgKeypair = ParagonIE_Sodium_Compat::crypto_box_keypair_from_secretkey_and_publickey(
206
-            ParagonIE_Sodium_Compat::crypto_box_secretkey($ephKeypair),
207
-            $publicKey
208
-        );
209
-
210
-        /** @var string $ephemeralPK */
211
-        $ephemeralPK = ParagonIE_Sodium_Compat::crypto_box_publickey($ephKeypair);
212
-
213
-        /** @var string $nonce */
214
-        $nonce = ParagonIE_Sodium_Compat::crypto_generichash(
215
-            $ephemeralPK . $publicKey,
216
-            '',
217
-            24
218
-        );
219
-
220
-        /** @var int $firstWrite */
221
-        $firstWrite = fwrite(
222
-            $ofp,
223
-            $ephemeralPK,
224
-            ParagonIE_Sodium_Compat::CRYPTO_BOX_PUBLICKEYBYTES
225
-        );
226
-        if (!is_int($firstWrite)) {
227
-            fclose($ifp);
228
-            fclose($ofp);
229
-            ParagonIE_Sodium_Compat::memzero($ephKeypair);
230
-            throw new SodiumException('Could not write to output file');
231
-        }
232
-        if ($firstWrite !== ParagonIE_Sodium_Compat::CRYPTO_BOX_PUBLICKEYBYTES) {
233
-            ParagonIE_Sodium_Compat::memzero($ephKeypair);
234
-            fclose($ifp);
235
-            fclose($ofp);
236
-            throw new SodiumException('Error writing public key to output file');
237
-        }
238
-
239
-        $res = self::box_encrypt($ifp, $ofp, $size, $nonce, $msgKeypair);
240
-        fclose($ifp);
241
-        fclose($ofp);
242
-        try {
243
-            ParagonIE_Sodium_Compat::memzero($nonce);
244
-            ParagonIE_Sodium_Compat::memzero($ephKeypair);
245
-        } catch (SodiumException $ex) {
246
-            /** @psalm-suppress PossiblyUndefinedVariable */
247
-            unset($ephKeypair);
248
-        }
249
-        return $res;
250
-    }
251
-
252
-    /**
253
-     * Open a sealed file (rather than a string). Uses less memory than
254
-     * ParagonIE_Sodium_Compat::crypto_box_seal_open(), but produces
255
-     * the same result.
256
-     *
257
-     * Warning: Does not protect against TOCTOU attacks. You should
258
-     * just load the file into memory and use crypto_box_seal_open() if
259
-     * you are worried about those.
260
-     *
261
-     * @param string $inputFile
262
-     * @param string $outputFile
263
-     * @param string $ecdhKeypair
264
-     * @return bool
265
-     * @throws SodiumException
266
-     * @throws TypeError
267
-     */
268
-    public static function box_seal_open($inputFile, $outputFile, $ecdhKeypair)
269
-    {
270
-        /* Type checks: */
271
-        if (!is_string($inputFile)) {
272
-            throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given.');
273
-        }
274
-        if (!is_string($outputFile)) {
275
-            throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
276
-        }
277
-        if (!is_string($ecdhKeypair)) {
278
-            throw new TypeError('Argument 3 must be a string, ' . gettype($ecdhKeypair) . ' given.');
279
-        }
280
-
281
-        /* Input validation: */
282
-        if (self::strlen($ecdhKeypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
283
-            throw new TypeError('Argument 3 must be CRYPTO_BOX_KEYPAIRBYTES bytes');
284
-        }
285
-
286
-        $publicKey = ParagonIE_Sodium_Compat::crypto_box_publickey($ecdhKeypair);
287
-
288
-        /** @var int $size */
289
-        $size = filesize($inputFile);
290
-        if (!is_int($size)) {
291
-            throw new SodiumException('Could not obtain the file size');
292
-        }
293
-
294
-        /** @var resource $ifp */
295
-        $ifp = fopen($inputFile, 'rb');
296
-        if (!is_resource($ifp)) {
297
-            throw new SodiumException('Could not open input file for reading');
298
-        }
299
-
300
-        /** @var resource $ofp */
301
-        $ofp = fopen($outputFile, 'wb');
302
-        if (!is_resource($ofp)) {
303
-            fclose($ifp);
304
-            throw new SodiumException('Could not open output file for writing');
305
-        }
306
-
307
-        $ephemeralPK = fread($ifp, ParagonIE_Sodium_Compat::CRYPTO_BOX_PUBLICKEYBYTES);
308
-        if (!is_string($ephemeralPK)) {
309
-            throw new SodiumException('Could not read input file');
310
-        }
311
-        if (self::strlen($ephemeralPK) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_PUBLICKEYBYTES) {
312
-            fclose($ifp);
313
-            fclose($ofp);
314
-            throw new SodiumException('Could not read public key from sealed file');
315
-        }
316
-
317
-        $nonce = ParagonIE_Sodium_Compat::crypto_generichash(
318
-            $ephemeralPK . $publicKey,
319
-            '',
320
-            24
321
-        );
322
-        $msgKeypair = ParagonIE_Sodium_Compat::crypto_box_keypair_from_secretkey_and_publickey(
323
-            ParagonIE_Sodium_Compat::crypto_box_secretkey($ecdhKeypair),
324
-            $ephemeralPK
325
-        );
326
-
327
-        $res = self::box_decrypt($ifp, $ofp, $size, $nonce, $msgKeypair);
328
-        fclose($ifp);
329
-        fclose($ofp);
330
-        try {
331
-            ParagonIE_Sodium_Compat::memzero($nonce);
332
-            ParagonIE_Sodium_Compat::memzero($ephKeypair);
333
-        } catch (SodiumException $ex) {
334
-            if (isset($ephKeypair)) {
335
-                unset($ephKeypair);
336
-            }
337
-        }
338
-        return $res;
339
-    }
340
-
341
-    /**
342
-     * Calculate the BLAKE2b hash of a file.
343
-     *
344
-     * @param string      $filePath     Absolute path to a file on the filesystem
345
-     * @param string|null $key          BLAKE2b key
346
-     * @param int         $outputLength Length of hash output
347
-     *
348
-     * @return string                   BLAKE2b hash
349
-     * @throws SodiumException
350
-     * @throws TypeError
351
-     * @psalm-suppress FailedTypeResolution
352
-     */
353
-    public static function generichash($filePath, $key = '', $outputLength = 32)
354
-    {
355
-        /* Type checks: */
356
-        if (!is_string($filePath)) {
357
-            throw new TypeError('Argument 1 must be a string, ' . gettype($filePath) . ' given.');
358
-        }
359
-        if (!is_string($key)) {
360
-            if (is_null($key)) {
361
-                $key = '';
362
-            } else {
363
-                throw new TypeError('Argument 2 must be a string, ' . gettype($key) . ' given.');
364
-            }
365
-        }
366
-        if (!is_int($outputLength)) {
367
-            if (!is_numeric($outputLength)) {
368
-                throw new TypeError('Argument 3 must be an integer, ' . gettype($outputLength) . ' given.');
369
-            }
370
-            $outputLength = (int) $outputLength;
371
-        }
372
-
373
-        /* Input validation: */
374
-        if (!empty($key)) {
375
-            if (self::strlen($key) < ParagonIE_Sodium_Compat::CRYPTO_GENERICHASH_KEYBYTES_MIN) {
376
-                throw new TypeError('Argument 2 must be at least CRYPTO_GENERICHASH_KEYBYTES_MIN bytes');
377
-            }
378
-            if (self::strlen($key) > ParagonIE_Sodium_Compat::CRYPTO_GENERICHASH_KEYBYTES_MAX) {
379
-                throw new TypeError('Argument 2 must be at most CRYPTO_GENERICHASH_KEYBYTES_MAX bytes');
380
-            }
381
-        }
382
-        if ($outputLength < ParagonIE_Sodium_Compat::CRYPTO_GENERICHASH_BYTES_MIN) {
383
-            throw new SodiumException('Argument 3 must be at least CRYPTO_GENERICHASH_BYTES_MIN');
384
-        }
385
-        if ($outputLength > ParagonIE_Sodium_Compat::CRYPTO_GENERICHASH_BYTES_MAX) {
386
-            throw new SodiumException('Argument 3 must be at least CRYPTO_GENERICHASH_BYTES_MAX');
387
-        }
388
-
389
-        /** @var int $size */
390
-        $size = filesize($filePath);
391
-        if (!is_int($size)) {
392
-            throw new SodiumException('Could not obtain the file size');
393
-        }
394
-
395
-        /** @var resource $fp */
396
-        $fp = fopen($filePath, 'rb');
397
-        if (!is_resource($fp)) {
398
-            throw new SodiumException('Could not open input file for reading');
399
-        }
400
-        $ctx = ParagonIE_Sodium_Compat::crypto_generichash_init($key, $outputLength);
401
-        while ($size > 0) {
402
-            $blockSize = $size > 64
403
-                ? 64
404
-                : $size;
405
-            $read = fread($fp, $blockSize);
406
-            if (!is_string($read)) {
407
-                throw new SodiumException('Could not read input file');
408
-            }
409
-            ParagonIE_Sodium_Compat::crypto_generichash_update($ctx, $read);
410
-            $size -= $blockSize;
411
-        }
412
-
413
-        fclose($fp);
414
-        return ParagonIE_Sodium_Compat::crypto_generichash_final($ctx, $outputLength);
415
-    }
416
-
417
-    /**
418
-     * Encrypt a file (rather than a string). Uses less memory than
419
-     * ParagonIE_Sodium_Compat::crypto_secretbox(), but produces
420
-     * the same result.
421
-     *
422
-     * @param string $inputFile  Absolute path to a file on the filesystem
423
-     * @param string $outputFile Absolute path to a file on the filesystem
424
-     * @param string $nonce      Number to be used only once
425
-     * @param string $key        Encryption key
426
-     *
427
-     * @return bool
428
-     * @throws SodiumException
429
-     * @throws TypeError
430
-     */
431
-    public static function secretbox($inputFile, $outputFile, $nonce, $key)
432
-    {
433
-        /* Type checks: */
434
-        if (!is_string($inputFile)) {
435
-            throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given..');
436
-        }
437
-        if (!is_string($outputFile)) {
438
-            throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
439
-        }
440
-        if (!is_string($nonce)) {
441
-            throw new TypeError('Argument 3 must be a string, ' . gettype($nonce) . ' given.');
442
-        }
443
-
444
-        /* Input validation: */
445
-        if (self::strlen($nonce) !== ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_NONCEBYTES) {
446
-            throw new TypeError('Argument 3 must be CRYPTO_SECRETBOX_NONCEBYTES bytes');
447
-        }
448
-        if (!is_string($key)) {
449
-            throw new TypeError('Argument 4 must be a string, ' . gettype($key) . ' given.');
450
-        }
451
-        if (self::strlen($key) !== ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_KEYBYTES) {
452
-            throw new TypeError('Argument 4 must be CRYPTO_SECRETBOX_KEYBYTES bytes');
453
-        }
454
-
455
-        /** @var int $size */
456
-        $size = filesize($inputFile);
457
-        if (!is_int($size)) {
458
-            throw new SodiumException('Could not obtain the file size');
459
-        }
460
-
461
-        /** @var resource $ifp */
462
-        $ifp = fopen($inputFile, 'rb');
463
-        if (!is_resource($ifp)) {
464
-            throw new SodiumException('Could not open input file for reading');
465
-        }
466
-
467
-        /** @var resource $ofp */
468
-        $ofp = fopen($outputFile, 'wb');
469
-        if (!is_resource($ofp)) {
470
-            fclose($ifp);
471
-            throw new SodiumException('Could not open output file for writing');
472
-        }
473
-
474
-        $res = self::secretbox_encrypt($ifp, $ofp, $size, $nonce, $key);
475
-        fclose($ifp);
476
-        fclose($ofp);
477
-        return $res;
478
-    }
479
-    /**
480
-     * Seal a file (rather than a string). Uses less memory than
481
-     * ParagonIE_Sodium_Compat::crypto_secretbox_open(), but produces
482
-     * the same result.
483
-     *
484
-     * Warning: Does not protect against TOCTOU attacks. You should
485
-     * just load the file into memory and use crypto_secretbox_open() if
486
-     * you are worried about those.
487
-     *
488
-     * @param string $inputFile
489
-     * @param string $outputFile
490
-     * @param string $nonce
491
-     * @param string $key
492
-     * @return bool
493
-     * @throws SodiumException
494
-     * @throws TypeError
495
-     */
496
-    public static function secretbox_open($inputFile, $outputFile, $nonce, $key)
497
-    {
498
-        /* Type checks: */
499
-        if (!is_string($inputFile)) {
500
-            throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given.');
501
-        }
502
-        if (!is_string($outputFile)) {
503
-            throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
504
-        }
505
-        if (!is_string($nonce)) {
506
-            throw new TypeError('Argument 3 must be a string, ' . gettype($nonce) . ' given.');
507
-        }
508
-        if (!is_string($key)) {
509
-            throw new TypeError('Argument 4 must be a string, ' . gettype($key) . ' given.');
510
-        }
511
-
512
-        /* Input validation: */
513
-        if (self::strlen($nonce) !== ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_NONCEBYTES) {
514
-            throw new TypeError('Argument 4 must be CRYPTO_SECRETBOX_NONCEBYTES bytes');
515
-        }
516
-        if (self::strlen($key) !== ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_KEYBYTES) {
517
-            throw new TypeError('Argument 4 must be CRYPTO_SECRETBOXBOX_KEYBYTES bytes');
518
-        }
519
-
520
-        /** @var int $size */
521
-        $size = filesize($inputFile);
522
-        if (!is_int($size)) {
523
-            throw new SodiumException('Could not obtain the file size');
524
-        }
525
-
526
-        /** @var resource $ifp */
527
-        $ifp = fopen($inputFile, 'rb');
528
-        if (!is_resource($ifp)) {
529
-            throw new SodiumException('Could not open input file for reading');
530
-        }
531
-
532
-        /** @var resource $ofp */
533
-        $ofp = fopen($outputFile, 'wb');
534
-        if (!is_resource($ofp)) {
535
-            fclose($ifp);
536
-            throw new SodiumException('Could not open output file for writing');
537
-        }
538
-
539
-        $res = self::secretbox_decrypt($ifp, $ofp, $size, $nonce, $key);
540
-        fclose($ifp);
541
-        fclose($ofp);
542
-        try {
543
-            ParagonIE_Sodium_Compat::memzero($key);
544
-        } catch (SodiumException $ex) {
545
-            /** @psalm-suppress PossiblyUndefinedVariable */
546
-            unset($key);
547
-        }
548
-        return $res;
549
-    }
550
-
551
-    /**
552
-     * Sign a file (rather than a string). Uses less memory than
553
-     * ParagonIE_Sodium_Compat::crypto_sign_detached(), but produces
554
-     * the same result.
555
-     *
556
-     * @param string $filePath  Absolute path to a file on the filesystem
557
-     * @param string $secretKey Secret signing key
558
-     *
559
-     * @return string           Ed25519 signature
560
-     * @throws SodiumException
561
-     * @throws TypeError
562
-     */
563
-    public static function sign($filePath, $secretKey)
564
-    {
565
-        /* Type checks: */
566
-        if (!is_string($filePath)) {
567
-            throw new TypeError('Argument 1 must be a string, ' . gettype($filePath) . ' given.');
568
-        }
569
-        if (!is_string($secretKey)) {
570
-            throw new TypeError('Argument 2 must be a string, ' . gettype($secretKey) . ' given.');
571
-        }
572
-
573
-        /* Input validation: */
574
-        if (self::strlen($secretKey) !== ParagonIE_Sodium_Compat::CRYPTO_SIGN_SECRETKEYBYTES) {
575
-            throw new TypeError('Argument 2 must be CRYPTO_SIGN_SECRETKEYBYTES bytes');
576
-        }
577
-        if (PHP_INT_SIZE === 4) {
578
-            return self::sign_core32($filePath, $secretKey);
579
-        }
580
-
581
-        /** @var int $size */
582
-        $size = filesize($filePath);
583
-        if (!is_int($size)) {
584
-            throw new SodiumException('Could not obtain the file size');
585
-        }
586
-
587
-        /** @var resource $fp */
588
-        $fp = fopen($filePath, 'rb');
589
-        if (!is_resource($fp)) {
590
-            throw new SodiumException('Could not open input file for reading');
591
-        }
592
-
593
-        /** @var string $az */
594
-        $az = hash('sha512', self::substr($secretKey, 0, 32), true);
595
-
596
-        $az[0] = self::intToChr(self::chrToInt($az[0]) & 248);
597
-        $az[31] = self::intToChr((self::chrToInt($az[31]) & 63) | 64);
598
-
599
-        $hs = hash_init('sha512');
600
-        self::hash_update($hs, self::substr($az, 32, 32));
601
-        /** @var resource $hs */
602
-        $hs = self::updateHashWithFile($hs, $fp, $size);
603
-
604
-        /** @var string $nonceHash */
605
-        $nonceHash = hash_final($hs, true);
606
-
607
-        /** @var string $pk */
608
-        $pk = self::substr($secretKey, 32, 32);
609
-
610
-        /** @var string $nonce */
611
-        $nonce = ParagonIE_Sodium_Core_Ed25519::sc_reduce($nonceHash) . self::substr($nonceHash, 32);
612
-
613
-        /** @var string $sig */
614
-        $sig = ParagonIE_Sodium_Core_Ed25519::ge_p3_tobytes(
615
-            ParagonIE_Sodium_Core_Ed25519::ge_scalarmult_base($nonce)
616
-        );
617
-
618
-        $hs = hash_init('sha512');
619
-        self::hash_update($hs, self::substr($sig, 0, 32));
620
-        self::hash_update($hs, self::substr($pk, 0, 32));
621
-        /** @var resource $hs */
622
-        $hs = self::updateHashWithFile($hs, $fp, $size);
623
-
624
-        /** @var string $hramHash */
625
-        $hramHash = hash_final($hs, true);
626
-
627
-        /** @var string $hram */
628
-        $hram = ParagonIE_Sodium_Core_Ed25519::sc_reduce($hramHash);
629
-
630
-        /** @var string $sigAfter */
631
-        $sigAfter = ParagonIE_Sodium_Core_Ed25519::sc_muladd($hram, $az, $nonce);
632
-
633
-        /** @var string $sig */
634
-        $sig = self::substr($sig, 0, 32) . self::substr($sigAfter, 0, 32);
635
-
636
-        try {
637
-            ParagonIE_Sodium_Compat::memzero($az);
638
-        } catch (SodiumException $ex) {
639
-            $az = null;
640
-        }
641
-        fclose($fp);
642
-        return $sig;
643
-    }
644
-
645
-    /**
646
-     * Verify a file (rather than a string). Uses less memory than
647
-     * ParagonIE_Sodium_Compat::crypto_sign_verify_detached(), but
648
-     * produces the same result.
649
-     *
650
-     * @param string $sig       Ed25519 signature
651
-     * @param string $filePath  Absolute path to a file on the filesystem
652
-     * @param string $publicKey Signing public key
653
-     *
654
-     * @return bool
655
-     * @throws SodiumException
656
-     * @throws TypeError
657
-     * @throws Exception
658
-     */
659
-    public static function verify($sig, $filePath, $publicKey)
660
-    {
661
-        /* Type checks: */
662
-        if (!is_string($sig)) {
663
-            throw new TypeError('Argument 1 must be a string, ' . gettype($sig) . ' given.');
664
-        }
665
-        if (!is_string($filePath)) {
666
-            throw new TypeError('Argument 2 must be a string, ' . gettype($filePath) . ' given.');
667
-        }
668
-        if (!is_string($publicKey)) {
669
-            throw new TypeError('Argument 3 must be a string, ' . gettype($publicKey) . ' given.');
670
-        }
671
-
672
-        /* Input validation: */
673
-        if (self::strlen($sig) !== ParagonIE_Sodium_Compat::CRYPTO_SIGN_BYTES) {
674
-            throw new TypeError('Argument 1 must be CRYPTO_SIGN_BYTES bytes');
675
-        }
676
-        if (self::strlen($publicKey) !== ParagonIE_Sodium_Compat::CRYPTO_SIGN_PUBLICKEYBYTES) {
677
-            throw new TypeError('Argument 3 must be CRYPTO_SIGN_PUBLICKEYBYTES bytes');
678
-        }
679
-        if (self::strlen($sig) < 64) {
680
-            throw new SodiumException('Signature is too short');
681
-        }
682
-
683
-        if (PHP_INT_SIZE === 4) {
684
-            return self::verify_core32($sig, $filePath, $publicKey);
685
-        }
686
-
687
-        /* Security checks */
688
-        if (
689
-            (ParagonIE_Sodium_Core_Ed25519::chrToInt($sig[63]) & 240)
690
-                &&
691
-            ParagonIE_Sodium_Core_Ed25519::check_S_lt_L(self::substr($sig, 32, 32))
692
-        ) {
693
-            throw new SodiumException('S < L - Invalid signature');
694
-        }
695
-        if (ParagonIE_Sodium_Core_Ed25519::small_order($sig)) {
696
-            throw new SodiumException('Signature is on too small of an order');
697
-        }
698
-        if ((self::chrToInt($sig[63]) & 224) !== 0) {
699
-            throw new SodiumException('Invalid signature');
700
-        }
701
-        $d = 0;
702
-        for ($i = 0; $i < 32; ++$i) {
703
-            $d |= self::chrToInt($publicKey[$i]);
704
-        }
705
-        if ($d === 0) {
706
-            throw new SodiumException('All zero public key');
707
-        }
708
-
709
-        /** @var int $size */
710
-        $size = filesize($filePath);
711
-        if (!is_int($size)) {
712
-            throw new SodiumException('Could not obtain the file size');
713
-        }
714
-
715
-        /** @var resource $fp */
716
-        $fp = fopen($filePath, 'rb');
717
-        if (!is_resource($fp)) {
718
-            throw new SodiumException('Could not open input file for reading');
719
-        }
720
-
721
-        /** @var bool The original value of ParagonIE_Sodium_Compat::$fastMult */
722
-        $orig = ParagonIE_Sodium_Compat::$fastMult;
723
-
724
-        // Set ParagonIE_Sodium_Compat::$fastMult to true to speed up verification.
725
-        ParagonIE_Sodium_Compat::$fastMult = true;
726
-
727
-        /** @var ParagonIE_Sodium_Core_Curve25519_Ge_P3 $A */
728
-        $A = ParagonIE_Sodium_Core_Ed25519::ge_frombytes_negate_vartime($publicKey);
729
-
730
-        $hs = hash_init('sha512');
731
-        self::hash_update($hs, self::substr($sig, 0, 32));
732
-        self::hash_update($hs, self::substr($publicKey, 0, 32));
733
-        /** @var resource $hs */
734
-        $hs = self::updateHashWithFile($hs, $fp, $size);
735
-        /** @var string $hDigest */
736
-        $hDigest = hash_final($hs, true);
737
-
738
-        /** @var string $h */
739
-        $h = ParagonIE_Sodium_Core_Ed25519::sc_reduce($hDigest) . self::substr($hDigest, 32);
740
-
741
-        /** @var ParagonIE_Sodium_Core_Curve25519_Ge_P2 $R */
742
-        $R = ParagonIE_Sodium_Core_Ed25519::ge_double_scalarmult_vartime(
743
-            $h,
744
-            $A,
745
-            self::substr($sig, 32)
746
-        );
747
-
748
-        /** @var string $rcheck */
749
-        $rcheck = ParagonIE_Sodium_Core_Ed25519::ge_tobytes($R);
750
-
751
-        // Close the file handle
752
-        fclose($fp);
753
-
754
-        // Reset ParagonIE_Sodium_Compat::$fastMult to what it was before.
755
-        ParagonIE_Sodium_Compat::$fastMult = $orig;
756
-        return self::verify_32($rcheck, self::substr($sig, 0, 32));
757
-    }
758
-
759
-    /**
760
-     * @param resource $ifp
761
-     * @param resource $ofp
762
-     * @param int      $mlen
763
-     * @param string   $nonce
764
-     * @param string   $boxKeypair
765
-     * @return bool
766
-     * @throws SodiumException
767
-     * @throws TypeError
768
-     */
769
-    protected static function box_encrypt($ifp, $ofp, $mlen, $nonce, $boxKeypair)
770
-    {
771
-        if (PHP_INT_SIZE === 4) {
772
-            return self::secretbox_encrypt(
773
-                $ifp,
774
-                $ofp,
775
-                $mlen,
776
-                $nonce,
777
-                ParagonIE_Sodium_Crypto32::box_beforenm(
778
-                    ParagonIE_Sodium_Crypto32::box_secretkey($boxKeypair),
779
-                    ParagonIE_Sodium_Crypto32::box_publickey($boxKeypair)
780
-                )
781
-            );
782
-        }
783
-        return self::secretbox_encrypt(
784
-            $ifp,
785
-            $ofp,
786
-            $mlen,
787
-            $nonce,
788
-            ParagonIE_Sodium_Crypto::box_beforenm(
789
-                ParagonIE_Sodium_Crypto::box_secretkey($boxKeypair),
790
-                ParagonIE_Sodium_Crypto::box_publickey($boxKeypair)
791
-            )
792
-        );
793
-    }
794
-
795
-
796
-    /**
797
-     * @param resource $ifp
798
-     * @param resource $ofp
799
-     * @param int      $mlen
800
-     * @param string   $nonce
801
-     * @param string   $boxKeypair
802
-     * @return bool
803
-     * @throws SodiumException
804
-     * @throws TypeError
805
-     */
806
-    protected static function box_decrypt($ifp, $ofp, $mlen, $nonce, $boxKeypair)
807
-    {
808
-        if (PHP_INT_SIZE === 4) {
809
-            return self::secretbox_decrypt(
810
-                $ifp,
811
-                $ofp,
812
-                $mlen,
813
-                $nonce,
814
-                ParagonIE_Sodium_Crypto32::box_beforenm(
815
-                    ParagonIE_Sodium_Crypto32::box_secretkey($boxKeypair),
816
-                    ParagonIE_Sodium_Crypto32::box_publickey($boxKeypair)
817
-                )
818
-            );
819
-        }
820
-        return self::secretbox_decrypt(
821
-            $ifp,
822
-            $ofp,
823
-            $mlen,
824
-            $nonce,
825
-            ParagonIE_Sodium_Crypto::box_beforenm(
826
-                ParagonIE_Sodium_Crypto::box_secretkey($boxKeypair),
827
-                ParagonIE_Sodium_Crypto::box_publickey($boxKeypair)
828
-            )
829
-        );
830
-    }
831
-
832
-    /**
833
-     * Encrypt a file
834
-     *
835
-     * @param resource $ifp
836
-     * @param resource $ofp
837
-     * @param int $mlen
838
-     * @param string $nonce
839
-     * @param string $key
840
-     * @return bool
841
-     * @throws SodiumException
842
-     * @throws TypeError
843
-     */
844
-    protected static function secretbox_encrypt($ifp, $ofp, $mlen, $nonce, $key)
845
-    {
846
-        if (PHP_INT_SIZE === 4) {
847
-            return self::secretbox_encrypt_core32($ifp, $ofp, $mlen, $nonce, $key);
848
-        }
849
-
850
-        $plaintext = fread($ifp, 32);
851
-        if (!is_string($plaintext)) {
852
-            throw new SodiumException('Could not read input file');
853
-        }
854
-        $first32 = self::ftell($ifp);
855
-
856
-        /** @var string $subkey */
857
-        $subkey = ParagonIE_Sodium_Core_HSalsa20::hsalsa20($nonce, $key);
858
-
859
-        /** @var string $realNonce */
860
-        $realNonce = ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8);
861
-
862
-        /** @var string $block0 */
863
-        $block0 = str_repeat("\x00", 32);
864
-
865
-        /** @var int $mlen - Length of the plaintext message */
866
-        $mlen0 = $mlen;
867
-        if ($mlen0 > 64 - ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES) {
868
-            $mlen0 = 64 - ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES;
869
-        }
870
-        $block0 .= ParagonIE_Sodium_Core_Util::substr($plaintext, 0, $mlen0);
871
-
872
-        /** @var string $block0 */
873
-        $block0 = ParagonIE_Sodium_Core_Salsa20::salsa20_xor(
874
-            $block0,
875
-            $realNonce,
876
-            $subkey
877
-        );
878
-
879
-        $state = new ParagonIE_Sodium_Core_Poly1305_State(
880
-            ParagonIE_Sodium_Core_Util::substr(
881
-                $block0,
882
-                0,
883
-                ParagonIE_Sodium_Crypto::onetimeauth_poly1305_KEYBYTES
884
-            )
885
-        );
886
-
887
-        // Pre-write 16 blank bytes for the Poly1305 tag
888
-        $start = self::ftell($ofp);
889
-        fwrite($ofp, str_repeat("\x00", 16));
890
-
891
-        /** @var string $c */
892
-        $cBlock = ParagonIE_Sodium_Core_Util::substr(
893
-            $block0,
894
-            ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES
895
-        );
896
-        $state->update($cBlock);
897
-        fwrite($ofp, $cBlock);
898
-        $mlen -= 32;
899
-
900
-        /** @var int $iter */
901
-        $iter = 1;
902
-
903
-        /** @var int $incr */
904
-        $incr = self::BUFFER_SIZE >> 6;
905
-
906
-        /*
11
+	/* PHP's default buffer size is 8192 for fread()/fwrite(). */
12
+	const BUFFER_SIZE = 8192;
13
+
14
+	/**
15
+	 * Box a file (rather than a string). Uses less memory than
16
+	 * ParagonIE_Sodium_Compat::crypto_box(), but produces
17
+	 * the same result.
18
+	 *
19
+	 * @param string $inputFile  Absolute path to a file on the filesystem
20
+	 * @param string $outputFile Absolute path to a file on the filesystem
21
+	 * @param string $nonce      Number to be used only once
22
+	 * @param string $keyPair    ECDH secret key and ECDH public key concatenated
23
+	 *
24
+	 * @return bool
25
+	 * @throws SodiumException
26
+	 * @throws TypeError
27
+	 */
28
+	public static function box($inputFile, $outputFile, $nonce, $keyPair)
29
+	{
30
+		/* Type checks: */
31
+		if (!is_string($inputFile)) {
32
+			throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given.');
33
+		}
34
+		if (!is_string($outputFile)) {
35
+			throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
36
+		}
37
+		if (!is_string($nonce)) {
38
+			throw new TypeError('Argument 3 must be a string, ' . gettype($nonce) . ' given.');
39
+		}
40
+
41
+		/* Input validation: */
42
+		if (!is_string($keyPair)) {
43
+			throw new TypeError('Argument 4 must be a string, ' . gettype($keyPair) . ' given.');
44
+		}
45
+		if (self::strlen($nonce) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_NONCEBYTES) {
46
+			throw new TypeError('Argument 3 must be CRYPTO_BOX_NONCEBYTES bytes');
47
+		}
48
+		if (self::strlen($keyPair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
49
+			throw new TypeError('Argument 4 must be CRYPTO_BOX_KEYPAIRBYTES bytes');
50
+		}
51
+
52
+		/** @var int $size */
53
+		$size = filesize($inputFile);
54
+		if (!is_int($size)) {
55
+			throw new SodiumException('Could not obtain the file size');
56
+		}
57
+
58
+		/** @var resource $ifp */
59
+		$ifp = fopen($inputFile, 'rb');
60
+		if (!is_resource($ifp)) {
61
+			throw new SodiumException('Could not open input file for reading');
62
+		}
63
+
64
+		/** @var resource $ofp */
65
+		$ofp = fopen($outputFile, 'wb');
66
+		if (!is_resource($ofp)) {
67
+			fclose($ifp);
68
+			throw new SodiumException('Could not open output file for writing');
69
+		}
70
+
71
+		$res = self::box_encrypt($ifp, $ofp, $size, $nonce, $keyPair);
72
+		fclose($ifp);
73
+		fclose($ofp);
74
+		return $res;
75
+	}
76
+
77
+	/**
78
+	 * Open a boxed file (rather than a string). Uses less memory than
79
+	 * ParagonIE_Sodium_Compat::crypto_box_open(), but produces
80
+	 * the same result.
81
+	 *
82
+	 * Warning: Does not protect against TOCTOU attacks. You should
83
+	 * just load the file into memory and use crypto_box_open() if
84
+	 * you are worried about those.
85
+	 *
86
+	 * @param string $inputFile
87
+	 * @param string $outputFile
88
+	 * @param string $nonce
89
+	 * @param string $keypair
90
+	 * @return bool
91
+	 * @throws SodiumException
92
+	 * @throws TypeError
93
+	 */
94
+	public static function box_open($inputFile, $outputFile, $nonce, $keypair)
95
+	{
96
+		/* Type checks: */
97
+		if (!is_string($inputFile)) {
98
+			throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given.');
99
+		}
100
+		if (!is_string($outputFile)) {
101
+			throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
102
+		}
103
+		if (!is_string($nonce)) {
104
+			throw new TypeError('Argument 3 must be a string, ' . gettype($nonce) . ' given.');
105
+		}
106
+		if (!is_string($keypair)) {
107
+			throw new TypeError('Argument 4 must be a string, ' . gettype($keypair) . ' given.');
108
+		}
109
+
110
+		/* Input validation: */
111
+		if (self::strlen($nonce) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_NONCEBYTES) {
112
+			throw new TypeError('Argument 4 must be CRYPTO_BOX_NONCEBYTES bytes');
113
+		}
114
+		if (self::strlen($keypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
115
+			throw new TypeError('Argument 4 must be CRYPTO_BOX_KEYPAIRBYTES bytes');
116
+		}
117
+
118
+		/** @var int $size */
119
+		$size = filesize($inputFile);
120
+		if (!is_int($size)) {
121
+			throw new SodiumException('Could not obtain the file size');
122
+		}
123
+
124
+		/** @var resource $ifp */
125
+		$ifp = fopen($inputFile, 'rb');
126
+		if (!is_resource($ifp)) {
127
+			throw new SodiumException('Could not open input file for reading');
128
+		}
129
+
130
+		/** @var resource $ofp */
131
+		$ofp = fopen($outputFile, 'wb');
132
+		if (!is_resource($ofp)) {
133
+			fclose($ifp);
134
+			throw new SodiumException('Could not open output file for writing');
135
+		}
136
+
137
+		$res = self::box_decrypt($ifp, $ofp, $size, $nonce, $keypair);
138
+		fclose($ifp);
139
+		fclose($ofp);
140
+		try {
141
+			ParagonIE_Sodium_Compat::memzero($nonce);
142
+			ParagonIE_Sodium_Compat::memzero($ephKeypair);
143
+		} catch (SodiumException $ex) {
144
+			if (isset($ephKeypair)) {
145
+				unset($ephKeypair);
146
+			}
147
+		}
148
+		return $res;
149
+	}
150
+
151
+	/**
152
+	 * Seal a file (rather than a string). Uses less memory than
153
+	 * ParagonIE_Sodium_Compat::crypto_box_seal(), but produces
154
+	 * the same result.
155
+	 *
156
+	 * @param string $inputFile  Absolute path to a file on the filesystem
157
+	 * @param string $outputFile Absolute path to a file on the filesystem
158
+	 * @param string $publicKey  ECDH public key
159
+	 *
160
+	 * @return bool
161
+	 * @throws SodiumException
162
+	 * @throws TypeError
163
+	 */
164
+	public static function box_seal($inputFile, $outputFile, $publicKey)
165
+	{
166
+		/* Type checks: */
167
+		if (!is_string($inputFile)) {
168
+			throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given.');
169
+		}
170
+		if (!is_string($outputFile)) {
171
+			throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
172
+		}
173
+		if (!is_string($publicKey)) {
174
+			throw new TypeError('Argument 3 must be a string, ' . gettype($publicKey) . ' given.');
175
+		}
176
+
177
+		/* Input validation: */
178
+		if (self::strlen($publicKey) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_PUBLICKEYBYTES) {
179
+			throw new TypeError('Argument 3 must be CRYPTO_BOX_PUBLICKEYBYTES bytes');
180
+		}
181
+
182
+		/** @var int $size */
183
+		$size = filesize($inputFile);
184
+		if (!is_int($size)) {
185
+			throw new SodiumException('Could not obtain the file size');
186
+		}
187
+
188
+		/** @var resource $ifp */
189
+		$ifp = fopen($inputFile, 'rb');
190
+		if (!is_resource($ifp)) {
191
+			throw new SodiumException('Could not open input file for reading');
192
+		}
193
+
194
+		/** @var resource $ofp */
195
+		$ofp = fopen($outputFile, 'wb');
196
+		if (!is_resource($ofp)) {
197
+			fclose($ifp);
198
+			throw new SodiumException('Could not open output file for writing');
199
+		}
200
+
201
+		/** @var string $ephKeypair */
202
+		$ephKeypair = ParagonIE_Sodium_Compat::crypto_box_keypair();
203
+
204
+		/** @var string $msgKeypair */
205
+		$msgKeypair = ParagonIE_Sodium_Compat::crypto_box_keypair_from_secretkey_and_publickey(
206
+			ParagonIE_Sodium_Compat::crypto_box_secretkey($ephKeypair),
207
+			$publicKey
208
+		);
209
+
210
+		/** @var string $ephemeralPK */
211
+		$ephemeralPK = ParagonIE_Sodium_Compat::crypto_box_publickey($ephKeypair);
212
+
213
+		/** @var string $nonce */
214
+		$nonce = ParagonIE_Sodium_Compat::crypto_generichash(
215
+			$ephemeralPK . $publicKey,
216
+			'',
217
+			24
218
+		);
219
+
220
+		/** @var int $firstWrite */
221
+		$firstWrite = fwrite(
222
+			$ofp,
223
+			$ephemeralPK,
224
+			ParagonIE_Sodium_Compat::CRYPTO_BOX_PUBLICKEYBYTES
225
+		);
226
+		if (!is_int($firstWrite)) {
227
+			fclose($ifp);
228
+			fclose($ofp);
229
+			ParagonIE_Sodium_Compat::memzero($ephKeypair);
230
+			throw new SodiumException('Could not write to output file');
231
+		}
232
+		if ($firstWrite !== ParagonIE_Sodium_Compat::CRYPTO_BOX_PUBLICKEYBYTES) {
233
+			ParagonIE_Sodium_Compat::memzero($ephKeypair);
234
+			fclose($ifp);
235
+			fclose($ofp);
236
+			throw new SodiumException('Error writing public key to output file');
237
+		}
238
+
239
+		$res = self::box_encrypt($ifp, $ofp, $size, $nonce, $msgKeypair);
240
+		fclose($ifp);
241
+		fclose($ofp);
242
+		try {
243
+			ParagonIE_Sodium_Compat::memzero($nonce);
244
+			ParagonIE_Sodium_Compat::memzero($ephKeypair);
245
+		} catch (SodiumException $ex) {
246
+			/** @psalm-suppress PossiblyUndefinedVariable */
247
+			unset($ephKeypair);
248
+		}
249
+		return $res;
250
+	}
251
+
252
+	/**
253
+	 * Open a sealed file (rather than a string). Uses less memory than
254
+	 * ParagonIE_Sodium_Compat::crypto_box_seal_open(), but produces
255
+	 * the same result.
256
+	 *
257
+	 * Warning: Does not protect against TOCTOU attacks. You should
258
+	 * just load the file into memory and use crypto_box_seal_open() if
259
+	 * you are worried about those.
260
+	 *
261
+	 * @param string $inputFile
262
+	 * @param string $outputFile
263
+	 * @param string $ecdhKeypair
264
+	 * @return bool
265
+	 * @throws SodiumException
266
+	 * @throws TypeError
267
+	 */
268
+	public static function box_seal_open($inputFile, $outputFile, $ecdhKeypair)
269
+	{
270
+		/* Type checks: */
271
+		if (!is_string($inputFile)) {
272
+			throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given.');
273
+		}
274
+		if (!is_string($outputFile)) {
275
+			throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
276
+		}
277
+		if (!is_string($ecdhKeypair)) {
278
+			throw new TypeError('Argument 3 must be a string, ' . gettype($ecdhKeypair) . ' given.');
279
+		}
280
+
281
+		/* Input validation: */
282
+		if (self::strlen($ecdhKeypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
283
+			throw new TypeError('Argument 3 must be CRYPTO_BOX_KEYPAIRBYTES bytes');
284
+		}
285
+
286
+		$publicKey = ParagonIE_Sodium_Compat::crypto_box_publickey($ecdhKeypair);
287
+
288
+		/** @var int $size */
289
+		$size = filesize($inputFile);
290
+		if (!is_int($size)) {
291
+			throw new SodiumException('Could not obtain the file size');
292
+		}
293
+
294
+		/** @var resource $ifp */
295
+		$ifp = fopen($inputFile, 'rb');
296
+		if (!is_resource($ifp)) {
297
+			throw new SodiumException('Could not open input file for reading');
298
+		}
299
+
300
+		/** @var resource $ofp */
301
+		$ofp = fopen($outputFile, 'wb');
302
+		if (!is_resource($ofp)) {
303
+			fclose($ifp);
304
+			throw new SodiumException('Could not open output file for writing');
305
+		}
306
+
307
+		$ephemeralPK = fread($ifp, ParagonIE_Sodium_Compat::CRYPTO_BOX_PUBLICKEYBYTES);
308
+		if (!is_string($ephemeralPK)) {
309
+			throw new SodiumException('Could not read input file');
310
+		}
311
+		if (self::strlen($ephemeralPK) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_PUBLICKEYBYTES) {
312
+			fclose($ifp);
313
+			fclose($ofp);
314
+			throw new SodiumException('Could not read public key from sealed file');
315
+		}
316
+
317
+		$nonce = ParagonIE_Sodium_Compat::crypto_generichash(
318
+			$ephemeralPK . $publicKey,
319
+			'',
320
+			24
321
+		);
322
+		$msgKeypair = ParagonIE_Sodium_Compat::crypto_box_keypair_from_secretkey_and_publickey(
323
+			ParagonIE_Sodium_Compat::crypto_box_secretkey($ecdhKeypair),
324
+			$ephemeralPK
325
+		);
326
+
327
+		$res = self::box_decrypt($ifp, $ofp, $size, $nonce, $msgKeypair);
328
+		fclose($ifp);
329
+		fclose($ofp);
330
+		try {
331
+			ParagonIE_Sodium_Compat::memzero($nonce);
332
+			ParagonIE_Sodium_Compat::memzero($ephKeypair);
333
+		} catch (SodiumException $ex) {
334
+			if (isset($ephKeypair)) {
335
+				unset($ephKeypair);
336
+			}
337
+		}
338
+		return $res;
339
+	}
340
+
341
+	/**
342
+	 * Calculate the BLAKE2b hash of a file.
343
+	 *
344
+	 * @param string      $filePath     Absolute path to a file on the filesystem
345
+	 * @param string|null $key          BLAKE2b key
346
+	 * @param int         $outputLength Length of hash output
347
+	 *
348
+	 * @return string                   BLAKE2b hash
349
+	 * @throws SodiumException
350
+	 * @throws TypeError
351
+	 * @psalm-suppress FailedTypeResolution
352
+	 */
353
+	public static function generichash($filePath, $key = '', $outputLength = 32)
354
+	{
355
+		/* Type checks: */
356
+		if (!is_string($filePath)) {
357
+			throw new TypeError('Argument 1 must be a string, ' . gettype($filePath) . ' given.');
358
+		}
359
+		if (!is_string($key)) {
360
+			if (is_null($key)) {
361
+				$key = '';
362
+			} else {
363
+				throw new TypeError('Argument 2 must be a string, ' . gettype($key) . ' given.');
364
+			}
365
+		}
366
+		if (!is_int($outputLength)) {
367
+			if (!is_numeric($outputLength)) {
368
+				throw new TypeError('Argument 3 must be an integer, ' . gettype($outputLength) . ' given.');
369
+			}
370
+			$outputLength = (int) $outputLength;
371
+		}
372
+
373
+		/* Input validation: */
374
+		if (!empty($key)) {
375
+			if (self::strlen($key) < ParagonIE_Sodium_Compat::CRYPTO_GENERICHASH_KEYBYTES_MIN) {
376
+				throw new TypeError('Argument 2 must be at least CRYPTO_GENERICHASH_KEYBYTES_MIN bytes');
377
+			}
378
+			if (self::strlen($key) > ParagonIE_Sodium_Compat::CRYPTO_GENERICHASH_KEYBYTES_MAX) {
379
+				throw new TypeError('Argument 2 must be at most CRYPTO_GENERICHASH_KEYBYTES_MAX bytes');
380
+			}
381
+		}
382
+		if ($outputLength < ParagonIE_Sodium_Compat::CRYPTO_GENERICHASH_BYTES_MIN) {
383
+			throw new SodiumException('Argument 3 must be at least CRYPTO_GENERICHASH_BYTES_MIN');
384
+		}
385
+		if ($outputLength > ParagonIE_Sodium_Compat::CRYPTO_GENERICHASH_BYTES_MAX) {
386
+			throw new SodiumException('Argument 3 must be at least CRYPTO_GENERICHASH_BYTES_MAX');
387
+		}
388
+
389
+		/** @var int $size */
390
+		$size = filesize($filePath);
391
+		if (!is_int($size)) {
392
+			throw new SodiumException('Could not obtain the file size');
393
+		}
394
+
395
+		/** @var resource $fp */
396
+		$fp = fopen($filePath, 'rb');
397
+		if (!is_resource($fp)) {
398
+			throw new SodiumException('Could not open input file for reading');
399
+		}
400
+		$ctx = ParagonIE_Sodium_Compat::crypto_generichash_init($key, $outputLength);
401
+		while ($size > 0) {
402
+			$blockSize = $size > 64
403
+				? 64
404
+				: $size;
405
+			$read = fread($fp, $blockSize);
406
+			if (!is_string($read)) {
407
+				throw new SodiumException('Could not read input file');
408
+			}
409
+			ParagonIE_Sodium_Compat::crypto_generichash_update($ctx, $read);
410
+			$size -= $blockSize;
411
+		}
412
+
413
+		fclose($fp);
414
+		return ParagonIE_Sodium_Compat::crypto_generichash_final($ctx, $outputLength);
415
+	}
416
+
417
+	/**
418
+	 * Encrypt a file (rather than a string). Uses less memory than
419
+	 * ParagonIE_Sodium_Compat::crypto_secretbox(), but produces
420
+	 * the same result.
421
+	 *
422
+	 * @param string $inputFile  Absolute path to a file on the filesystem
423
+	 * @param string $outputFile Absolute path to a file on the filesystem
424
+	 * @param string $nonce      Number to be used only once
425
+	 * @param string $key        Encryption key
426
+	 *
427
+	 * @return bool
428
+	 * @throws SodiumException
429
+	 * @throws TypeError
430
+	 */
431
+	public static function secretbox($inputFile, $outputFile, $nonce, $key)
432
+	{
433
+		/* Type checks: */
434
+		if (!is_string($inputFile)) {
435
+			throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given..');
436
+		}
437
+		if (!is_string($outputFile)) {
438
+			throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
439
+		}
440
+		if (!is_string($nonce)) {
441
+			throw new TypeError('Argument 3 must be a string, ' . gettype($nonce) . ' given.');
442
+		}
443
+
444
+		/* Input validation: */
445
+		if (self::strlen($nonce) !== ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_NONCEBYTES) {
446
+			throw new TypeError('Argument 3 must be CRYPTO_SECRETBOX_NONCEBYTES bytes');
447
+		}
448
+		if (!is_string($key)) {
449
+			throw new TypeError('Argument 4 must be a string, ' . gettype($key) . ' given.');
450
+		}
451
+		if (self::strlen($key) !== ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_KEYBYTES) {
452
+			throw new TypeError('Argument 4 must be CRYPTO_SECRETBOX_KEYBYTES bytes');
453
+		}
454
+
455
+		/** @var int $size */
456
+		$size = filesize($inputFile);
457
+		if (!is_int($size)) {
458
+			throw new SodiumException('Could not obtain the file size');
459
+		}
460
+
461
+		/** @var resource $ifp */
462
+		$ifp = fopen($inputFile, 'rb');
463
+		if (!is_resource($ifp)) {
464
+			throw new SodiumException('Could not open input file for reading');
465
+		}
466
+
467
+		/** @var resource $ofp */
468
+		$ofp = fopen($outputFile, 'wb');
469
+		if (!is_resource($ofp)) {
470
+			fclose($ifp);
471
+			throw new SodiumException('Could not open output file for writing');
472
+		}
473
+
474
+		$res = self::secretbox_encrypt($ifp, $ofp, $size, $nonce, $key);
475
+		fclose($ifp);
476
+		fclose($ofp);
477
+		return $res;
478
+	}
479
+	/**
480
+	 * Seal a file (rather than a string). Uses less memory than
481
+	 * ParagonIE_Sodium_Compat::crypto_secretbox_open(), but produces
482
+	 * the same result.
483
+	 *
484
+	 * Warning: Does not protect against TOCTOU attacks. You should
485
+	 * just load the file into memory and use crypto_secretbox_open() if
486
+	 * you are worried about those.
487
+	 *
488
+	 * @param string $inputFile
489
+	 * @param string $outputFile
490
+	 * @param string $nonce
491
+	 * @param string $key
492
+	 * @return bool
493
+	 * @throws SodiumException
494
+	 * @throws TypeError
495
+	 */
496
+	public static function secretbox_open($inputFile, $outputFile, $nonce, $key)
497
+	{
498
+		/* Type checks: */
499
+		if (!is_string($inputFile)) {
500
+			throw new TypeError('Argument 1 must be a string, ' . gettype($inputFile) . ' given.');
501
+		}
502
+		if (!is_string($outputFile)) {
503
+			throw new TypeError('Argument 2 must be a string, ' . gettype($outputFile) . ' given.');
504
+		}
505
+		if (!is_string($nonce)) {
506
+			throw new TypeError('Argument 3 must be a string, ' . gettype($nonce) . ' given.');
507
+		}
508
+		if (!is_string($key)) {
509
+			throw new TypeError('Argument 4 must be a string, ' . gettype($key) . ' given.');
510
+		}
511
+
512
+		/* Input validation: */
513
+		if (self::strlen($nonce) !== ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_NONCEBYTES) {
514
+			throw new TypeError('Argument 4 must be CRYPTO_SECRETBOX_NONCEBYTES bytes');
515
+		}
516
+		if (self::strlen($key) !== ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_KEYBYTES) {
517
+			throw new TypeError('Argument 4 must be CRYPTO_SECRETBOXBOX_KEYBYTES bytes');
518
+		}
519
+
520
+		/** @var int $size */
521
+		$size = filesize($inputFile);
522
+		if (!is_int($size)) {
523
+			throw new SodiumException('Could not obtain the file size');
524
+		}
525
+
526
+		/** @var resource $ifp */
527
+		$ifp = fopen($inputFile, 'rb');
528
+		if (!is_resource($ifp)) {
529
+			throw new SodiumException('Could not open input file for reading');
530
+		}
531
+
532
+		/** @var resource $ofp */
533
+		$ofp = fopen($outputFile, 'wb');
534
+		if (!is_resource($ofp)) {
535
+			fclose($ifp);
536
+			throw new SodiumException('Could not open output file for writing');
537
+		}
538
+
539
+		$res = self::secretbox_decrypt($ifp, $ofp, $size, $nonce, $key);
540
+		fclose($ifp);
541
+		fclose($ofp);
542
+		try {
543
+			ParagonIE_Sodium_Compat::memzero($key);
544
+		} catch (SodiumException $ex) {
545
+			/** @psalm-suppress PossiblyUndefinedVariable */
546
+			unset($key);
547
+		}
548
+		return $res;
549
+	}
550
+
551
+	/**
552
+	 * Sign a file (rather than a string). Uses less memory than
553
+	 * ParagonIE_Sodium_Compat::crypto_sign_detached(), but produces
554
+	 * the same result.
555
+	 *
556
+	 * @param string $filePath  Absolute path to a file on the filesystem
557
+	 * @param string $secretKey Secret signing key
558
+	 *
559
+	 * @return string           Ed25519 signature
560
+	 * @throws SodiumException
561
+	 * @throws TypeError
562
+	 */
563
+	public static function sign($filePath, $secretKey)
564
+	{
565
+		/* Type checks: */
566
+		if (!is_string($filePath)) {
567
+			throw new TypeError('Argument 1 must be a string, ' . gettype($filePath) . ' given.');
568
+		}
569
+		if (!is_string($secretKey)) {
570
+			throw new TypeError('Argument 2 must be a string, ' . gettype($secretKey) . ' given.');
571
+		}
572
+
573
+		/* Input validation: */
574
+		if (self::strlen($secretKey) !== ParagonIE_Sodium_Compat::CRYPTO_SIGN_SECRETKEYBYTES) {
575
+			throw new TypeError('Argument 2 must be CRYPTO_SIGN_SECRETKEYBYTES bytes');
576
+		}
577
+		if (PHP_INT_SIZE === 4) {
578
+			return self::sign_core32($filePath, $secretKey);
579
+		}
580
+
581
+		/** @var int $size */
582
+		$size = filesize($filePath);
583
+		if (!is_int($size)) {
584
+			throw new SodiumException('Could not obtain the file size');
585
+		}
586
+
587
+		/** @var resource $fp */
588
+		$fp = fopen($filePath, 'rb');
589
+		if (!is_resource($fp)) {
590
+			throw new SodiumException('Could not open input file for reading');
591
+		}
592
+
593
+		/** @var string $az */
594
+		$az = hash('sha512', self::substr($secretKey, 0, 32), true);
595
+
596
+		$az[0] = self::intToChr(self::chrToInt($az[0]) & 248);
597
+		$az[31] = self::intToChr((self::chrToInt($az[31]) & 63) | 64);
598
+
599
+		$hs = hash_init('sha512');
600
+		self::hash_update($hs, self::substr($az, 32, 32));
601
+		/** @var resource $hs */
602
+		$hs = self::updateHashWithFile($hs, $fp, $size);
603
+
604
+		/** @var string $nonceHash */
605
+		$nonceHash = hash_final($hs, true);
606
+
607
+		/** @var string $pk */
608
+		$pk = self::substr($secretKey, 32, 32);
609
+
610
+		/** @var string $nonce */
611
+		$nonce = ParagonIE_Sodium_Core_Ed25519::sc_reduce($nonceHash) . self::substr($nonceHash, 32);
612
+
613
+		/** @var string $sig */
614
+		$sig = ParagonIE_Sodium_Core_Ed25519::ge_p3_tobytes(
615
+			ParagonIE_Sodium_Core_Ed25519::ge_scalarmult_base($nonce)
616
+		);
617
+
618
+		$hs = hash_init('sha512');
619
+		self::hash_update($hs, self::substr($sig, 0, 32));
620
+		self::hash_update($hs, self::substr($pk, 0, 32));
621
+		/** @var resource $hs */
622
+		$hs = self::updateHashWithFile($hs, $fp, $size);
623
+
624
+		/** @var string $hramHash */
625
+		$hramHash = hash_final($hs, true);
626
+
627
+		/** @var string $hram */
628
+		$hram = ParagonIE_Sodium_Core_Ed25519::sc_reduce($hramHash);
629
+
630
+		/** @var string $sigAfter */
631
+		$sigAfter = ParagonIE_Sodium_Core_Ed25519::sc_muladd($hram, $az, $nonce);
632
+
633
+		/** @var string $sig */
634
+		$sig = self::substr($sig, 0, 32) . self::substr($sigAfter, 0, 32);
635
+
636
+		try {
637
+			ParagonIE_Sodium_Compat::memzero($az);
638
+		} catch (SodiumException $ex) {
639
+			$az = null;
640
+		}
641
+		fclose($fp);
642
+		return $sig;
643
+	}
644
+
645
+	/**
646
+	 * Verify a file (rather than a string). Uses less memory than
647
+	 * ParagonIE_Sodium_Compat::crypto_sign_verify_detached(), but
648
+	 * produces the same result.
649
+	 *
650
+	 * @param string $sig       Ed25519 signature
651
+	 * @param string $filePath  Absolute path to a file on the filesystem
652
+	 * @param string $publicKey Signing public key
653
+	 *
654
+	 * @return bool
655
+	 * @throws SodiumException
656
+	 * @throws TypeError
657
+	 * @throws Exception
658
+	 */
659
+	public static function verify($sig, $filePath, $publicKey)
660
+	{
661
+		/* Type checks: */
662
+		if (!is_string($sig)) {
663
+			throw new TypeError('Argument 1 must be a string, ' . gettype($sig) . ' given.');
664
+		}
665
+		if (!is_string($filePath)) {
666
+			throw new TypeError('Argument 2 must be a string, ' . gettype($filePath) . ' given.');
667
+		}
668
+		if (!is_string($publicKey)) {
669
+			throw new TypeError('Argument 3 must be a string, ' . gettype($publicKey) . ' given.');
670
+		}
671
+
672
+		/* Input validation: */
673
+		if (self::strlen($sig) !== ParagonIE_Sodium_Compat::CRYPTO_SIGN_BYTES) {
674
+			throw new TypeError('Argument 1 must be CRYPTO_SIGN_BYTES bytes');
675
+		}
676
+		if (self::strlen($publicKey) !== ParagonIE_Sodium_Compat::CRYPTO_SIGN_PUBLICKEYBYTES) {
677
+			throw new TypeError('Argument 3 must be CRYPTO_SIGN_PUBLICKEYBYTES bytes');
678
+		}
679
+		if (self::strlen($sig) < 64) {
680
+			throw new SodiumException('Signature is too short');
681
+		}
682
+
683
+		if (PHP_INT_SIZE === 4) {
684
+			return self::verify_core32($sig, $filePath, $publicKey);
685
+		}
686
+
687
+		/* Security checks */
688
+		if (
689
+			(ParagonIE_Sodium_Core_Ed25519::chrToInt($sig[63]) & 240)
690
+				&&
691
+			ParagonIE_Sodium_Core_Ed25519::check_S_lt_L(self::substr($sig, 32, 32))
692
+		) {
693
+			throw new SodiumException('S < L - Invalid signature');
694
+		}
695
+		if (ParagonIE_Sodium_Core_Ed25519::small_order($sig)) {
696
+			throw new SodiumException('Signature is on too small of an order');
697
+		}
698
+		if ((self::chrToInt($sig[63]) & 224) !== 0) {
699
+			throw new SodiumException('Invalid signature');
700
+		}
701
+		$d = 0;
702
+		for ($i = 0; $i < 32; ++$i) {
703
+			$d |= self::chrToInt($publicKey[$i]);
704
+		}
705
+		if ($d === 0) {
706
+			throw new SodiumException('All zero public key');
707
+		}
708
+
709
+		/** @var int $size */
710
+		$size = filesize($filePath);
711
+		if (!is_int($size)) {
712
+			throw new SodiumException('Could not obtain the file size');
713
+		}
714
+
715
+		/** @var resource $fp */
716
+		$fp = fopen($filePath, 'rb');
717
+		if (!is_resource($fp)) {
718
+			throw new SodiumException('Could not open input file for reading');
719
+		}
720
+
721
+		/** @var bool The original value of ParagonIE_Sodium_Compat::$fastMult */
722
+		$orig = ParagonIE_Sodium_Compat::$fastMult;
723
+
724
+		// Set ParagonIE_Sodium_Compat::$fastMult to true to speed up verification.
725
+		ParagonIE_Sodium_Compat::$fastMult = true;
726
+
727
+		/** @var ParagonIE_Sodium_Core_Curve25519_Ge_P3 $A */
728
+		$A = ParagonIE_Sodium_Core_Ed25519::ge_frombytes_negate_vartime($publicKey);
729
+
730
+		$hs = hash_init('sha512');
731
+		self::hash_update($hs, self::substr($sig, 0, 32));
732
+		self::hash_update($hs, self::substr($publicKey, 0, 32));
733
+		/** @var resource $hs */
734
+		$hs = self::updateHashWithFile($hs, $fp, $size);
735
+		/** @var string $hDigest */
736
+		$hDigest = hash_final($hs, true);
737
+
738
+		/** @var string $h */
739
+		$h = ParagonIE_Sodium_Core_Ed25519::sc_reduce($hDigest) . self::substr($hDigest, 32);
740
+
741
+		/** @var ParagonIE_Sodium_Core_Curve25519_Ge_P2 $R */
742
+		$R = ParagonIE_Sodium_Core_Ed25519::ge_double_scalarmult_vartime(
743
+			$h,
744
+			$A,
745
+			self::substr($sig, 32)
746
+		);
747
+
748
+		/** @var string $rcheck */
749
+		$rcheck = ParagonIE_Sodium_Core_Ed25519::ge_tobytes($R);
750
+
751
+		// Close the file handle
752
+		fclose($fp);
753
+
754
+		// Reset ParagonIE_Sodium_Compat::$fastMult to what it was before.
755
+		ParagonIE_Sodium_Compat::$fastMult = $orig;
756
+		return self::verify_32($rcheck, self::substr($sig, 0, 32));
757
+	}
758
+
759
+	/**
760
+	 * @param resource $ifp
761
+	 * @param resource $ofp
762
+	 * @param int      $mlen
763
+	 * @param string   $nonce
764
+	 * @param string   $boxKeypair
765
+	 * @return bool
766
+	 * @throws SodiumException
767
+	 * @throws TypeError
768
+	 */
769
+	protected static function box_encrypt($ifp, $ofp, $mlen, $nonce, $boxKeypair)
770
+	{
771
+		if (PHP_INT_SIZE === 4) {
772
+			return self::secretbox_encrypt(
773
+				$ifp,
774
+				$ofp,
775
+				$mlen,
776
+				$nonce,
777
+				ParagonIE_Sodium_Crypto32::box_beforenm(
778
+					ParagonIE_Sodium_Crypto32::box_secretkey($boxKeypair),
779
+					ParagonIE_Sodium_Crypto32::box_publickey($boxKeypair)
780
+				)
781
+			);
782
+		}
783
+		return self::secretbox_encrypt(
784
+			$ifp,
785
+			$ofp,
786
+			$mlen,
787
+			$nonce,
788
+			ParagonIE_Sodium_Crypto::box_beforenm(
789
+				ParagonIE_Sodium_Crypto::box_secretkey($boxKeypair),
790
+				ParagonIE_Sodium_Crypto::box_publickey($boxKeypair)
791
+			)
792
+		);
793
+	}
794
+
795
+
796
+	/**
797
+	 * @param resource $ifp
798
+	 * @param resource $ofp
799
+	 * @param int      $mlen
800
+	 * @param string   $nonce
801
+	 * @param string   $boxKeypair
802
+	 * @return bool
803
+	 * @throws SodiumException
804
+	 * @throws TypeError
805
+	 */
806
+	protected static function box_decrypt($ifp, $ofp, $mlen, $nonce, $boxKeypair)
807
+	{
808
+		if (PHP_INT_SIZE === 4) {
809
+			return self::secretbox_decrypt(
810
+				$ifp,
811
+				$ofp,
812
+				$mlen,
813
+				$nonce,
814
+				ParagonIE_Sodium_Crypto32::box_beforenm(
815
+					ParagonIE_Sodium_Crypto32::box_secretkey($boxKeypair),
816
+					ParagonIE_Sodium_Crypto32::box_publickey($boxKeypair)
817
+				)
818
+			);
819
+		}
820
+		return self::secretbox_decrypt(
821
+			$ifp,
822
+			$ofp,
823
+			$mlen,
824
+			$nonce,
825
+			ParagonIE_Sodium_Crypto::box_beforenm(
826
+				ParagonIE_Sodium_Crypto::box_secretkey($boxKeypair),
827
+				ParagonIE_Sodium_Crypto::box_publickey($boxKeypair)
828
+			)
829
+		);
830
+	}
831
+
832
+	/**
833
+	 * Encrypt a file
834
+	 *
835
+	 * @param resource $ifp
836
+	 * @param resource $ofp
837
+	 * @param int $mlen
838
+	 * @param string $nonce
839
+	 * @param string $key
840
+	 * @return bool
841
+	 * @throws SodiumException
842
+	 * @throws TypeError
843
+	 */
844
+	protected static function secretbox_encrypt($ifp, $ofp, $mlen, $nonce, $key)
845
+	{
846
+		if (PHP_INT_SIZE === 4) {
847
+			return self::secretbox_encrypt_core32($ifp, $ofp, $mlen, $nonce, $key);
848
+		}
849
+
850
+		$plaintext = fread($ifp, 32);
851
+		if (!is_string($plaintext)) {
852
+			throw new SodiumException('Could not read input file');
853
+		}
854
+		$first32 = self::ftell($ifp);
855
+
856
+		/** @var string $subkey */
857
+		$subkey = ParagonIE_Sodium_Core_HSalsa20::hsalsa20($nonce, $key);
858
+
859
+		/** @var string $realNonce */
860
+		$realNonce = ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8);
861
+
862
+		/** @var string $block0 */
863
+		$block0 = str_repeat("\x00", 32);
864
+
865
+		/** @var int $mlen - Length of the plaintext message */
866
+		$mlen0 = $mlen;
867
+		if ($mlen0 > 64 - ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES) {
868
+			$mlen0 = 64 - ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES;
869
+		}
870
+		$block0 .= ParagonIE_Sodium_Core_Util::substr($plaintext, 0, $mlen0);
871
+
872
+		/** @var string $block0 */
873
+		$block0 = ParagonIE_Sodium_Core_Salsa20::salsa20_xor(
874
+			$block0,
875
+			$realNonce,
876
+			$subkey
877
+		);
878
+
879
+		$state = new ParagonIE_Sodium_Core_Poly1305_State(
880
+			ParagonIE_Sodium_Core_Util::substr(
881
+				$block0,
882
+				0,
883
+				ParagonIE_Sodium_Crypto::onetimeauth_poly1305_KEYBYTES
884
+			)
885
+		);
886
+
887
+		// Pre-write 16 blank bytes for the Poly1305 tag
888
+		$start = self::ftell($ofp);
889
+		fwrite($ofp, str_repeat("\x00", 16));
890
+
891
+		/** @var string $c */
892
+		$cBlock = ParagonIE_Sodium_Core_Util::substr(
893
+			$block0,
894
+			ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES
895
+		);
896
+		$state->update($cBlock);
897
+		fwrite($ofp, $cBlock);
898
+		$mlen -= 32;
899
+
900
+		/** @var int $iter */
901
+		$iter = 1;
902
+
903
+		/** @var int $incr */
904
+		$incr = self::BUFFER_SIZE >> 6;
905
+
906
+		/*
907 907
          * Set the cursor to the end of the first half-block. All future bytes will
908 908
          * generated from salsa20_xor_ic, starting from 1 (second block).
909 909
          */
910
-        fseek($ifp, $first32, SEEK_SET);
911
-
912
-        while ($mlen > 0) {
913
-            $blockSize = $mlen > self::BUFFER_SIZE
914
-                ? self::BUFFER_SIZE
915
-                : $mlen;
916
-            $plaintext = fread($ifp, $blockSize);
917
-            if (!is_string($plaintext)) {
918
-                throw new SodiumException('Could not read input file');
919
-            }
920
-            $cBlock = ParagonIE_Sodium_Core_Salsa20::salsa20_xor_ic(
921
-                $plaintext,
922
-                $realNonce,
923
-                $iter,
924
-                $subkey
925
-            );
926
-            fwrite($ofp, $cBlock, $blockSize);
927
-            $state->update($cBlock);
928
-
929
-            $mlen -= $blockSize;
930
-            $iter += $incr;
931
-        }
932
-        try {
933
-            ParagonIE_Sodium_Compat::memzero($block0);
934
-            ParagonIE_Sodium_Compat::memzero($subkey);
935
-        } catch (SodiumException $ex) {
936
-            $block0 = null;
937
-            $subkey = null;
938
-        }
939
-        $end = self::ftell($ofp);
940
-
941
-        /*
910
+		fseek($ifp, $first32, SEEK_SET);
911
+
912
+		while ($mlen > 0) {
913
+			$blockSize = $mlen > self::BUFFER_SIZE
914
+				? self::BUFFER_SIZE
915
+				: $mlen;
916
+			$plaintext = fread($ifp, $blockSize);
917
+			if (!is_string($plaintext)) {
918
+				throw new SodiumException('Could not read input file');
919
+			}
920
+			$cBlock = ParagonIE_Sodium_Core_Salsa20::salsa20_xor_ic(
921
+				$plaintext,
922
+				$realNonce,
923
+				$iter,
924
+				$subkey
925
+			);
926
+			fwrite($ofp, $cBlock, $blockSize);
927
+			$state->update($cBlock);
928
+
929
+			$mlen -= $blockSize;
930
+			$iter += $incr;
931
+		}
932
+		try {
933
+			ParagonIE_Sodium_Compat::memzero($block0);
934
+			ParagonIE_Sodium_Compat::memzero($subkey);
935
+		} catch (SodiumException $ex) {
936
+			$block0 = null;
937
+			$subkey = null;
938
+		}
939
+		$end = self::ftell($ofp);
940
+
941
+		/*
942 942
          * Write the Poly1305 authentication tag that provides integrity
943 943
          * over the ciphertext (encrypt-then-MAC)
944 944
          */
945
-        fseek($ofp, $start, SEEK_SET);
946
-        fwrite($ofp, $state->finish(), ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_MACBYTES);
947
-        fseek($ofp, $end, SEEK_SET);
948
-        unset($state);
949
-
950
-        return true;
951
-    }
952
-
953
-    /**
954
-     * Decrypt a file
955
-     *
956
-     * @param resource $ifp
957
-     * @param resource $ofp
958
-     * @param int $mlen
959
-     * @param string $nonce
960
-     * @param string $key
961
-     * @return bool
962
-     * @throws SodiumException
963
-     * @throws TypeError
964
-     */
965
-    protected static function secretbox_decrypt($ifp, $ofp, $mlen, $nonce, $key)
966
-    {
967
-        if (PHP_INT_SIZE === 4) {
968
-            return self::secretbox_decrypt_core32($ifp, $ofp, $mlen, $nonce, $key);
969
-        }
970
-        $tag = fread($ifp, 16);
971
-        if (!is_string($tag)) {
972
-            throw new SodiumException('Could not read input file');
973
-        }
974
-
975
-        /** @var string $subkey */
976
-        $subkey = ParagonIE_Sodium_Core_HSalsa20::hsalsa20($nonce, $key);
977
-
978
-        /** @var string $realNonce */
979
-        $realNonce = ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8);
980
-
981
-        /** @var string $block0 */
982
-        $block0 = ParagonIE_Sodium_Core_Salsa20::salsa20(
983
-            64,
984
-            ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
985
-            $subkey
986
-        );
987
-
988
-        /* Verify the Poly1305 MAC -before- attempting to decrypt! */
989
-        $state = new ParagonIE_Sodium_Core_Poly1305_State(self::substr($block0, 0, 32));
990
-        if (!self::onetimeauth_verify($state, $ifp, $tag, $mlen)) {
991
-            throw new SodiumException('Invalid MAC');
992
-        }
993
-
994
-        /*
945
+		fseek($ofp, $start, SEEK_SET);
946
+		fwrite($ofp, $state->finish(), ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_MACBYTES);
947
+		fseek($ofp, $end, SEEK_SET);
948
+		unset($state);
949
+
950
+		return true;
951
+	}
952
+
953
+	/**
954
+	 * Decrypt a file
955
+	 *
956
+	 * @param resource $ifp
957
+	 * @param resource $ofp
958
+	 * @param int $mlen
959
+	 * @param string $nonce
960
+	 * @param string $key
961
+	 * @return bool
962
+	 * @throws SodiumException
963
+	 * @throws TypeError
964
+	 */
965
+	protected static function secretbox_decrypt($ifp, $ofp, $mlen, $nonce, $key)
966
+	{
967
+		if (PHP_INT_SIZE === 4) {
968
+			return self::secretbox_decrypt_core32($ifp, $ofp, $mlen, $nonce, $key);
969
+		}
970
+		$tag = fread($ifp, 16);
971
+		if (!is_string($tag)) {
972
+			throw new SodiumException('Could not read input file');
973
+		}
974
+
975
+		/** @var string $subkey */
976
+		$subkey = ParagonIE_Sodium_Core_HSalsa20::hsalsa20($nonce, $key);
977
+
978
+		/** @var string $realNonce */
979
+		$realNonce = ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8);
980
+
981
+		/** @var string $block0 */
982
+		$block0 = ParagonIE_Sodium_Core_Salsa20::salsa20(
983
+			64,
984
+			ParagonIE_Sodium_Core_Util::substr($nonce, 16, 8),
985
+			$subkey
986
+		);
987
+
988
+		/* Verify the Poly1305 MAC -before- attempting to decrypt! */
989
+		$state = new ParagonIE_Sodium_Core_Poly1305_State(self::substr($block0, 0, 32));
990
+		if (!self::onetimeauth_verify($state, $ifp, $tag, $mlen)) {
991
+			throw new SodiumException('Invalid MAC');
992
+		}
993
+
994
+		/*
995 995
          * Set the cursor to the end of the first half-block. All future bytes will
996 996
          * generated from salsa20_xor_ic, starting from 1 (second block).
997 997
          */
998
-        $first32 = fread($ifp, 32);
999
-        if (!is_string($first32)) {
1000
-            throw new SodiumException('Could not read input file');
1001
-        }
1002
-        $first32len = self::strlen($first32);
1003
-        fwrite(
1004
-            $ofp,
1005
-            self::xorStrings(
1006
-                self::substr($block0, 32, $first32len),
1007
-                self::substr($first32, 0, $first32len)
1008
-            )
1009
-        );
1010
-        $mlen -= 32;
1011
-
1012
-        /** @var int $iter */
1013
-        $iter = 1;
1014
-
1015
-        /** @var int $incr */
1016
-        $incr = self::BUFFER_SIZE >> 6;
1017
-
1018
-        /* Decrypts ciphertext, writes to output file. */
1019
-        while ($mlen > 0) {
1020
-            $blockSize = $mlen > self::BUFFER_SIZE
1021
-                ? self::BUFFER_SIZE
1022
-                : $mlen;
1023
-            $ciphertext = fread($ifp, $blockSize);
1024
-            if (!is_string($ciphertext)) {
1025
-                throw new SodiumException('Could not read input file');
1026
-            }
1027
-            $pBlock = ParagonIE_Sodium_Core_Salsa20::salsa20_xor_ic(
1028
-                $ciphertext,
1029
-                $realNonce,
1030
-                $iter,
1031
-                $subkey
1032
-            );
1033
-            fwrite($ofp, $pBlock, $blockSize);
1034
-            $mlen -= $blockSize;
1035
-            $iter += $incr;
1036
-        }
1037
-        return true;
1038
-    }
1039
-
1040
-    /**
1041
-     * @param ParagonIE_Sodium_Core_Poly1305_State $state
1042
-     * @param resource $ifp
1043
-     * @param string $tag
1044
-     * @param int $mlen
1045
-     * @return bool
1046
-     * @throws SodiumException
1047
-     * @throws TypeError
1048
-     */
1049
-    protected static function onetimeauth_verify(
1050
-        ParagonIE_Sodium_Core_Poly1305_State $state,
1051
-        $ifp,
1052
-        $tag = '',
1053
-        $mlen = 0
1054
-    ) {
1055
-        /** @var int $pos */
1056
-        $pos = self::ftell($ifp);
1057
-
1058
-        /** @var int $iter */
1059
-        $iter = 1;
1060
-
1061
-        /** @var int $incr */
1062
-        $incr = self::BUFFER_SIZE >> 6;
1063
-
1064
-        while ($mlen > 0) {
1065
-            $blockSize = $mlen > self::BUFFER_SIZE
1066
-                ? self::BUFFER_SIZE
1067
-                : $mlen;
1068
-            $ciphertext = fread($ifp, $blockSize);
1069
-            if (!is_string($ciphertext)) {
1070
-                throw new SodiumException('Could not read input file');
1071
-            }
1072
-            $state->update($ciphertext);
1073
-            $mlen -= $blockSize;
1074
-            $iter += $incr;
1075
-        }
1076
-        $res = ParagonIE_Sodium_Core_Util::verify_16($tag, $state->finish());
1077
-
1078
-        fseek($ifp, $pos, SEEK_SET);
1079
-        return $res;
1080
-    }
1081
-
1082
-    /**
1083
-     * Update a hash context with the contents of a file, without
1084
-     * loading the entire file into memory.
1085
-     *
1086
-     * @param resource|HashContext $hash
1087
-     * @param resource $fp
1088
-     * @param int $size
1089
-     * @return resource|object Resource on PHP < 7.2, HashContext object on PHP >= 7.2
1090
-     * @throws SodiumException
1091
-     * @throws TypeError
1092
-     * @psalm-suppress PossiblyInvalidArgument
1093
-     *                 PHP 7.2 changes from a resource to an object,
1094
-     *                 which causes Psalm to complain about an error.
1095
-     * @psalm-suppress TypeCoercion
1096
-     *                 Ditto.
1097
-     */
1098
-    public static function updateHashWithFile($hash, $fp, $size = 0)
1099
-    {
1100
-        /* Type checks: */
1101
-        if (PHP_VERSION_ID < 70200) {
1102
-            if (!is_resource($hash)) {
1103
-                throw new TypeError('Argument 1 must be a resource, ' . gettype($hash) . ' given.');
1104
-            }
1105
-        } else {
1106
-            if (!is_object($hash)) {
1107
-                throw new TypeError('Argument 1 must be an object (PHP 7.2+), ' . gettype($hash) . ' given.');
1108
-            }
1109
-        }
1110
-
1111
-        if (!is_resource($fp)) {
1112
-            throw new TypeError('Argument 2 must be a resource, ' . gettype($fp) . ' given.');
1113
-        }
1114
-        if (!is_int($size)) {
1115
-            throw new TypeError('Argument 3 must be an integer, ' . gettype($size) . ' given.');
1116
-        }
1117
-
1118
-        /** @var int $originalPosition */
1119
-        $originalPosition = self::ftell($fp);
1120
-
1121
-        // Move file pointer to beginning of file
1122
-        fseek($fp, 0, SEEK_SET);
1123
-        for ($i = 0; $i < $size; $i += self::BUFFER_SIZE) {
1124
-            /** @var string|bool $message */
1125
-            $message = fread(
1126
-                $fp,
1127
-                ($size - $i) > self::BUFFER_SIZE
1128
-                    ? $size - $i
1129
-                    : self::BUFFER_SIZE
1130
-            );
1131
-            if (!is_string($message)) {
1132
-                throw new SodiumException('Unexpected error reading from file.');
1133
-            }
1134
-            /** @var string $message */
1135
-            /** @psalm-suppress InvalidArgument */
1136
-            self::hash_update($hash, $message);
1137
-        }
1138
-        // Reset file pointer's position
1139
-        fseek($fp, $originalPosition, SEEK_SET);
1140
-        return $hash;
1141
-    }
1142
-
1143
-    /**
1144
-     * Sign a file (rather than a string). Uses less memory than
1145
-     * ParagonIE_Sodium_Compat::crypto_sign_detached(), but produces
1146
-     * the same result. (32-bit)
1147
-     *
1148
-     * @param string $filePath  Absolute path to a file on the filesystem
1149
-     * @param string $secretKey Secret signing key
1150
-     *
1151
-     * @return string           Ed25519 signature
1152
-     * @throws SodiumException
1153
-     * @throws TypeError
1154
-     */
1155
-    private static function sign_core32($filePath, $secretKey)
1156
-    {
1157
-        /** @var int|bool $size */
1158
-        $size = filesize($filePath);
1159
-        if (!is_int($size)) {
1160
-            throw new SodiumException('Could not obtain the file size');
1161
-        }
1162
-        /** @var int $size */
1163
-
1164
-        /** @var resource|bool $fp */
1165
-        $fp = fopen($filePath, 'rb');
1166
-        if (!is_resource($fp)) {
1167
-            throw new SodiumException('Could not open input file for reading');
1168
-        }
1169
-        /** @var resource $fp */
1170
-
1171
-        /** @var string $az */
1172
-        $az = hash('sha512', self::substr($secretKey, 0, 32), true);
1173
-
1174
-        $az[0] = self::intToChr(self::chrToInt($az[0]) & 248);
1175
-        $az[31] = self::intToChr((self::chrToInt($az[31]) & 63) | 64);
1176
-
1177
-        $hs = hash_init('sha512');
1178
-        self::hash_update($hs, self::substr($az, 32, 32));
1179
-        /** @var resource $hs */
1180
-        $hs = self::updateHashWithFile($hs, $fp, $size);
1181
-
1182
-        /** @var string $nonceHash */
1183
-        $nonceHash = hash_final($hs, true);
1184
-
1185
-        /** @var string $pk */
1186
-        $pk = self::substr($secretKey, 32, 32);
1187
-
1188
-        /** @var string $nonce */
1189
-        $nonce = ParagonIE_Sodium_Core32_Ed25519::sc_reduce($nonceHash) . self::substr($nonceHash, 32);
1190
-
1191
-        /** @var string $sig */
1192
-        $sig = ParagonIE_Sodium_Core32_Ed25519::ge_p3_tobytes(
1193
-            ParagonIE_Sodium_Core32_Ed25519::ge_scalarmult_base($nonce)
1194
-        );
1195
-
1196
-        $hs = hash_init('sha512');
1197
-        self::hash_update($hs, self::substr($sig, 0, 32));
1198
-        self::hash_update($hs, self::substr($pk, 0, 32));
1199
-        /** @var resource $hs */
1200
-        $hs = self::updateHashWithFile($hs, $fp, $size);
1201
-
1202
-        /** @var string $hramHash */
1203
-        $hramHash = hash_final($hs, true);
1204
-
1205
-        /** @var string $hram */
1206
-        $hram = ParagonIE_Sodium_Core32_Ed25519::sc_reduce($hramHash);
1207
-
1208
-        /** @var string $sigAfter */
1209
-        $sigAfter = ParagonIE_Sodium_Core32_Ed25519::sc_muladd($hram, $az, $nonce);
1210
-
1211
-        /** @var string $sig */
1212
-        $sig = self::substr($sig, 0, 32) . self::substr($sigAfter, 0, 32);
1213
-
1214
-        try {
1215
-            ParagonIE_Sodium_Compat::memzero($az);
1216
-        } catch (SodiumException $ex) {
1217
-            $az = null;
1218
-        }
1219
-        fclose($fp);
1220
-        return $sig;
1221
-    }
1222
-
1223
-    /**
1224
-     *
1225
-     * Verify a file (rather than a string). Uses less memory than
1226
-     * ParagonIE_Sodium_Compat::crypto_sign_verify_detached(), but
1227
-     * produces the same result. (32-bit)
1228
-     *
1229
-     * @param string $sig       Ed25519 signature
1230
-     * @param string $filePath  Absolute path to a file on the filesystem
1231
-     * @param string $publicKey Signing public key
1232
-     *
1233
-     * @return bool
1234
-     * @throws SodiumException
1235
-     * @throws Exception
1236
-     */
1237
-    public static function verify_core32($sig, $filePath, $publicKey)
1238
-    {
1239
-        /* Security checks */
1240
-        if (ParagonIE_Sodium_Core32_Ed25519::check_S_lt_L(self::substr($sig, 32, 32))) {
1241
-            throw new SodiumException('S < L - Invalid signature');
1242
-        }
1243
-        if (ParagonIE_Sodium_Core32_Ed25519::small_order($sig)) {
1244
-            throw new SodiumException('Signature is on too small of an order');
1245
-        }
1246
-        if ((self::chrToInt($sig[63]) & 224) !== 0) {
1247
-            throw new SodiumException('Invalid signature');
1248
-        }
1249
-        $d = 0;
1250
-        for ($i = 0; $i < 32; ++$i) {
1251
-            $d |= self::chrToInt($publicKey[$i]);
1252
-        }
1253
-        if ($d === 0) {
1254
-            throw new SodiumException('All zero public key');
1255
-        }
1256
-
1257
-        /** @var int|bool $size */
1258
-        $size = filesize($filePath);
1259
-        if (!is_int($size)) {
1260
-            throw new SodiumException('Could not obtain the file size');
1261
-        }
1262
-        /** @var int $size */
1263
-
1264
-        /** @var resource|bool $fp */
1265
-        $fp = fopen($filePath, 'rb');
1266
-        if (!is_resource($fp)) {
1267
-            throw new SodiumException('Could not open input file for reading');
1268
-        }
1269
-        /** @var resource $fp */
1270
-
1271
-        /** @var bool The original value of ParagonIE_Sodium_Compat::$fastMult */
1272
-        $orig = ParagonIE_Sodium_Compat::$fastMult;
1273
-
1274
-        // Set ParagonIE_Sodium_Compat::$fastMult to true to speed up verification.
1275
-        ParagonIE_Sodium_Compat::$fastMult = true;
1276
-
1277
-        /** @var ParagonIE_Sodium_Core32_Curve25519_Ge_P3 $A */
1278
-        $A = ParagonIE_Sodium_Core32_Ed25519::ge_frombytes_negate_vartime($publicKey);
1279
-
1280
-        $hs = hash_init('sha512');
1281
-        self::hash_update($hs, self::substr($sig, 0, 32));
1282
-        self::hash_update($hs, self::substr($publicKey, 0, 32));
1283
-        /** @var resource $hs */
1284
-        $hs = self::updateHashWithFile($hs, $fp, $size);
1285
-        /** @var string $hDigest */
1286
-        $hDigest = hash_final($hs, true);
1287
-
1288
-        /** @var string $h */
1289
-        $h = ParagonIE_Sodium_Core32_Ed25519::sc_reduce($hDigest) . self::substr($hDigest, 32);
1290
-
1291
-        /** @var ParagonIE_Sodium_Core32_Curve25519_Ge_P2 $R */
1292
-        $R = ParagonIE_Sodium_Core32_Ed25519::ge_double_scalarmult_vartime(
1293
-            $h,
1294
-            $A,
1295
-            self::substr($sig, 32)
1296
-        );
1297
-
1298
-        /** @var string $rcheck */
1299
-        $rcheck = ParagonIE_Sodium_Core32_Ed25519::ge_tobytes($R);
1300
-
1301
-        // Close the file handle
1302
-        fclose($fp);
1303
-
1304
-        // Reset ParagonIE_Sodium_Compat::$fastMult to what it was before.
1305
-        ParagonIE_Sodium_Compat::$fastMult = $orig;
1306
-        return self::verify_32($rcheck, self::substr($sig, 0, 32));
1307
-    }
1308
-
1309
-    /**
1310
-     * Encrypt a file (32-bit)
1311
-     *
1312
-     * @param resource $ifp
1313
-     * @param resource $ofp
1314
-     * @param int $mlen
1315
-     * @param string $nonce
1316
-     * @param string $key
1317
-     * @return bool
1318
-     * @throws SodiumException
1319
-     * @throws TypeError
1320
-     */
1321
-    protected static function secretbox_encrypt_core32($ifp, $ofp, $mlen, $nonce, $key)
1322
-    {
1323
-        $plaintext = fread($ifp, 32);
1324
-        if (!is_string($plaintext)) {
1325
-            throw new SodiumException('Could not read input file');
1326
-        }
1327
-        $first32 = self::ftell($ifp);
1328
-
1329
-        /** @var string $subkey */
1330
-        $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
1331
-
1332
-        /** @var string $realNonce */
1333
-        $realNonce = ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
1334
-
1335
-        /** @var string $block0 */
1336
-        $block0 = str_repeat("\x00", 32);
1337
-
1338
-        /** @var int $mlen - Length of the plaintext message */
1339
-        $mlen0 = $mlen;
1340
-        if ($mlen0 > 64 - ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES) {
1341
-            $mlen0 = 64 - ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES;
1342
-        }
1343
-        $block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
1344
-
1345
-        /** @var string $block0 */
1346
-        $block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor(
1347
-            $block0,
1348
-            $realNonce,
1349
-            $subkey
1350
-        );
1351
-
1352
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State(
1353
-            ParagonIE_Sodium_Core32_Util::substr(
1354
-                $block0,
1355
-                0,
1356
-                ParagonIE_Sodium_Crypto::onetimeauth_poly1305_KEYBYTES
1357
-            )
1358
-        );
1359
-
1360
-        // Pre-write 16 blank bytes for the Poly1305 tag
1361
-        $start = self::ftell($ofp);
1362
-        fwrite($ofp, str_repeat("\x00", 16));
1363
-
1364
-        /** @var string $c */
1365
-        $cBlock = ParagonIE_Sodium_Core32_Util::substr(
1366
-            $block0,
1367
-            ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES
1368
-        );
1369
-        $state->update($cBlock);
1370
-        fwrite($ofp, $cBlock);
1371
-        $mlen -= 32;
1372
-
1373
-        /** @var int $iter */
1374
-        $iter = 1;
1375
-
1376
-        /** @var int $incr */
1377
-        $incr = self::BUFFER_SIZE >> 6;
1378
-
1379
-        /*
998
+		$first32 = fread($ifp, 32);
999
+		if (!is_string($first32)) {
1000
+			throw new SodiumException('Could not read input file');
1001
+		}
1002
+		$first32len = self::strlen($first32);
1003
+		fwrite(
1004
+			$ofp,
1005
+			self::xorStrings(
1006
+				self::substr($block0, 32, $first32len),
1007
+				self::substr($first32, 0, $first32len)
1008
+			)
1009
+		);
1010
+		$mlen -= 32;
1011
+
1012
+		/** @var int $iter */
1013
+		$iter = 1;
1014
+
1015
+		/** @var int $incr */
1016
+		$incr = self::BUFFER_SIZE >> 6;
1017
+
1018
+		/* Decrypts ciphertext, writes to output file. */
1019
+		while ($mlen > 0) {
1020
+			$blockSize = $mlen > self::BUFFER_SIZE
1021
+				? self::BUFFER_SIZE
1022
+				: $mlen;
1023
+			$ciphertext = fread($ifp, $blockSize);
1024
+			if (!is_string($ciphertext)) {
1025
+				throw new SodiumException('Could not read input file');
1026
+			}
1027
+			$pBlock = ParagonIE_Sodium_Core_Salsa20::salsa20_xor_ic(
1028
+				$ciphertext,
1029
+				$realNonce,
1030
+				$iter,
1031
+				$subkey
1032
+			);
1033
+			fwrite($ofp, $pBlock, $blockSize);
1034
+			$mlen -= $blockSize;
1035
+			$iter += $incr;
1036
+		}
1037
+		return true;
1038
+	}
1039
+
1040
+	/**
1041
+	 * @param ParagonIE_Sodium_Core_Poly1305_State $state
1042
+	 * @param resource $ifp
1043
+	 * @param string $tag
1044
+	 * @param int $mlen
1045
+	 * @return bool
1046
+	 * @throws SodiumException
1047
+	 * @throws TypeError
1048
+	 */
1049
+	protected static function onetimeauth_verify(
1050
+		ParagonIE_Sodium_Core_Poly1305_State $state,
1051
+		$ifp,
1052
+		$tag = '',
1053
+		$mlen = 0
1054
+	) {
1055
+		/** @var int $pos */
1056
+		$pos = self::ftell($ifp);
1057
+
1058
+		/** @var int $iter */
1059
+		$iter = 1;
1060
+
1061
+		/** @var int $incr */
1062
+		$incr = self::BUFFER_SIZE >> 6;
1063
+
1064
+		while ($mlen > 0) {
1065
+			$blockSize = $mlen > self::BUFFER_SIZE
1066
+				? self::BUFFER_SIZE
1067
+				: $mlen;
1068
+			$ciphertext = fread($ifp, $blockSize);
1069
+			if (!is_string($ciphertext)) {
1070
+				throw new SodiumException('Could not read input file');
1071
+			}
1072
+			$state->update($ciphertext);
1073
+			$mlen -= $blockSize;
1074
+			$iter += $incr;
1075
+		}
1076
+		$res = ParagonIE_Sodium_Core_Util::verify_16($tag, $state->finish());
1077
+
1078
+		fseek($ifp, $pos, SEEK_SET);
1079
+		return $res;
1080
+	}
1081
+
1082
+	/**
1083
+	 * Update a hash context with the contents of a file, without
1084
+	 * loading the entire file into memory.
1085
+	 *
1086
+	 * @param resource|HashContext $hash
1087
+	 * @param resource $fp
1088
+	 * @param int $size
1089
+	 * @return resource|object Resource on PHP < 7.2, HashContext object on PHP >= 7.2
1090
+	 * @throws SodiumException
1091
+	 * @throws TypeError
1092
+	 * @psalm-suppress PossiblyInvalidArgument
1093
+	 *                 PHP 7.2 changes from a resource to an object,
1094
+	 *                 which causes Psalm to complain about an error.
1095
+	 * @psalm-suppress TypeCoercion
1096
+	 *                 Ditto.
1097
+	 */
1098
+	public static function updateHashWithFile($hash, $fp, $size = 0)
1099
+	{
1100
+		/* Type checks: */
1101
+		if (PHP_VERSION_ID < 70200) {
1102
+			if (!is_resource($hash)) {
1103
+				throw new TypeError('Argument 1 must be a resource, ' . gettype($hash) . ' given.');
1104
+			}
1105
+		} else {
1106
+			if (!is_object($hash)) {
1107
+				throw new TypeError('Argument 1 must be an object (PHP 7.2+), ' . gettype($hash) . ' given.');
1108
+			}
1109
+		}
1110
+
1111
+		if (!is_resource($fp)) {
1112
+			throw new TypeError('Argument 2 must be a resource, ' . gettype($fp) . ' given.');
1113
+		}
1114
+		if (!is_int($size)) {
1115
+			throw new TypeError('Argument 3 must be an integer, ' . gettype($size) . ' given.');
1116
+		}
1117
+
1118
+		/** @var int $originalPosition */
1119
+		$originalPosition = self::ftell($fp);
1120
+
1121
+		// Move file pointer to beginning of file
1122
+		fseek($fp, 0, SEEK_SET);
1123
+		for ($i = 0; $i < $size; $i += self::BUFFER_SIZE) {
1124
+			/** @var string|bool $message */
1125
+			$message = fread(
1126
+				$fp,
1127
+				($size - $i) > self::BUFFER_SIZE
1128
+					? $size - $i
1129
+					: self::BUFFER_SIZE
1130
+			);
1131
+			if (!is_string($message)) {
1132
+				throw new SodiumException('Unexpected error reading from file.');
1133
+			}
1134
+			/** @var string $message */
1135
+			/** @psalm-suppress InvalidArgument */
1136
+			self::hash_update($hash, $message);
1137
+		}
1138
+		// Reset file pointer's position
1139
+		fseek($fp, $originalPosition, SEEK_SET);
1140
+		return $hash;
1141
+	}
1142
+
1143
+	/**
1144
+	 * Sign a file (rather than a string). Uses less memory than
1145
+	 * ParagonIE_Sodium_Compat::crypto_sign_detached(), but produces
1146
+	 * the same result. (32-bit)
1147
+	 *
1148
+	 * @param string $filePath  Absolute path to a file on the filesystem
1149
+	 * @param string $secretKey Secret signing key
1150
+	 *
1151
+	 * @return string           Ed25519 signature
1152
+	 * @throws SodiumException
1153
+	 * @throws TypeError
1154
+	 */
1155
+	private static function sign_core32($filePath, $secretKey)
1156
+	{
1157
+		/** @var int|bool $size */
1158
+		$size = filesize($filePath);
1159
+		if (!is_int($size)) {
1160
+			throw new SodiumException('Could not obtain the file size');
1161
+		}
1162
+		/** @var int $size */
1163
+
1164
+		/** @var resource|bool $fp */
1165
+		$fp = fopen($filePath, 'rb');
1166
+		if (!is_resource($fp)) {
1167
+			throw new SodiumException('Could not open input file for reading');
1168
+		}
1169
+		/** @var resource $fp */
1170
+
1171
+		/** @var string $az */
1172
+		$az = hash('sha512', self::substr($secretKey, 0, 32), true);
1173
+
1174
+		$az[0] = self::intToChr(self::chrToInt($az[0]) & 248);
1175
+		$az[31] = self::intToChr((self::chrToInt($az[31]) & 63) | 64);
1176
+
1177
+		$hs = hash_init('sha512');
1178
+		self::hash_update($hs, self::substr($az, 32, 32));
1179
+		/** @var resource $hs */
1180
+		$hs = self::updateHashWithFile($hs, $fp, $size);
1181
+
1182
+		/** @var string $nonceHash */
1183
+		$nonceHash = hash_final($hs, true);
1184
+
1185
+		/** @var string $pk */
1186
+		$pk = self::substr($secretKey, 32, 32);
1187
+
1188
+		/** @var string $nonce */
1189
+		$nonce = ParagonIE_Sodium_Core32_Ed25519::sc_reduce($nonceHash) . self::substr($nonceHash, 32);
1190
+
1191
+		/** @var string $sig */
1192
+		$sig = ParagonIE_Sodium_Core32_Ed25519::ge_p3_tobytes(
1193
+			ParagonIE_Sodium_Core32_Ed25519::ge_scalarmult_base($nonce)
1194
+		);
1195
+
1196
+		$hs = hash_init('sha512');
1197
+		self::hash_update($hs, self::substr($sig, 0, 32));
1198
+		self::hash_update($hs, self::substr($pk, 0, 32));
1199
+		/** @var resource $hs */
1200
+		$hs = self::updateHashWithFile($hs, $fp, $size);
1201
+
1202
+		/** @var string $hramHash */
1203
+		$hramHash = hash_final($hs, true);
1204
+
1205
+		/** @var string $hram */
1206
+		$hram = ParagonIE_Sodium_Core32_Ed25519::sc_reduce($hramHash);
1207
+
1208
+		/** @var string $sigAfter */
1209
+		$sigAfter = ParagonIE_Sodium_Core32_Ed25519::sc_muladd($hram, $az, $nonce);
1210
+
1211
+		/** @var string $sig */
1212
+		$sig = self::substr($sig, 0, 32) . self::substr($sigAfter, 0, 32);
1213
+
1214
+		try {
1215
+			ParagonIE_Sodium_Compat::memzero($az);
1216
+		} catch (SodiumException $ex) {
1217
+			$az = null;
1218
+		}
1219
+		fclose($fp);
1220
+		return $sig;
1221
+	}
1222
+
1223
+	/**
1224
+	 *
1225
+	 * Verify a file (rather than a string). Uses less memory than
1226
+	 * ParagonIE_Sodium_Compat::crypto_sign_verify_detached(), but
1227
+	 * produces the same result. (32-bit)
1228
+	 *
1229
+	 * @param string $sig       Ed25519 signature
1230
+	 * @param string $filePath  Absolute path to a file on the filesystem
1231
+	 * @param string $publicKey Signing public key
1232
+	 *
1233
+	 * @return bool
1234
+	 * @throws SodiumException
1235
+	 * @throws Exception
1236
+	 */
1237
+	public static function verify_core32($sig, $filePath, $publicKey)
1238
+	{
1239
+		/* Security checks */
1240
+		if (ParagonIE_Sodium_Core32_Ed25519::check_S_lt_L(self::substr($sig, 32, 32))) {
1241
+			throw new SodiumException('S < L - Invalid signature');
1242
+		}
1243
+		if (ParagonIE_Sodium_Core32_Ed25519::small_order($sig)) {
1244
+			throw new SodiumException('Signature is on too small of an order');
1245
+		}
1246
+		if ((self::chrToInt($sig[63]) & 224) !== 0) {
1247
+			throw new SodiumException('Invalid signature');
1248
+		}
1249
+		$d = 0;
1250
+		for ($i = 0; $i < 32; ++$i) {
1251
+			$d |= self::chrToInt($publicKey[$i]);
1252
+		}
1253
+		if ($d === 0) {
1254
+			throw new SodiumException('All zero public key');
1255
+		}
1256
+
1257
+		/** @var int|bool $size */
1258
+		$size = filesize($filePath);
1259
+		if (!is_int($size)) {
1260
+			throw new SodiumException('Could not obtain the file size');
1261
+		}
1262
+		/** @var int $size */
1263
+
1264
+		/** @var resource|bool $fp */
1265
+		$fp = fopen($filePath, 'rb');
1266
+		if (!is_resource($fp)) {
1267
+			throw new SodiumException('Could not open input file for reading');
1268
+		}
1269
+		/** @var resource $fp */
1270
+
1271
+		/** @var bool The original value of ParagonIE_Sodium_Compat::$fastMult */
1272
+		$orig = ParagonIE_Sodium_Compat::$fastMult;
1273
+
1274
+		// Set ParagonIE_Sodium_Compat::$fastMult to true to speed up verification.
1275
+		ParagonIE_Sodium_Compat::$fastMult = true;
1276
+
1277
+		/** @var ParagonIE_Sodium_Core32_Curve25519_Ge_P3 $A */
1278
+		$A = ParagonIE_Sodium_Core32_Ed25519::ge_frombytes_negate_vartime($publicKey);
1279
+
1280
+		$hs = hash_init('sha512');
1281
+		self::hash_update($hs, self::substr($sig, 0, 32));
1282
+		self::hash_update($hs, self::substr($publicKey, 0, 32));
1283
+		/** @var resource $hs */
1284
+		$hs = self::updateHashWithFile($hs, $fp, $size);
1285
+		/** @var string $hDigest */
1286
+		$hDigest = hash_final($hs, true);
1287
+
1288
+		/** @var string $h */
1289
+		$h = ParagonIE_Sodium_Core32_Ed25519::sc_reduce($hDigest) . self::substr($hDigest, 32);
1290
+
1291
+		/** @var ParagonIE_Sodium_Core32_Curve25519_Ge_P2 $R */
1292
+		$R = ParagonIE_Sodium_Core32_Ed25519::ge_double_scalarmult_vartime(
1293
+			$h,
1294
+			$A,
1295
+			self::substr($sig, 32)
1296
+		);
1297
+
1298
+		/** @var string $rcheck */
1299
+		$rcheck = ParagonIE_Sodium_Core32_Ed25519::ge_tobytes($R);
1300
+
1301
+		// Close the file handle
1302
+		fclose($fp);
1303
+
1304
+		// Reset ParagonIE_Sodium_Compat::$fastMult to what it was before.
1305
+		ParagonIE_Sodium_Compat::$fastMult = $orig;
1306
+		return self::verify_32($rcheck, self::substr($sig, 0, 32));
1307
+	}
1308
+
1309
+	/**
1310
+	 * Encrypt a file (32-bit)
1311
+	 *
1312
+	 * @param resource $ifp
1313
+	 * @param resource $ofp
1314
+	 * @param int $mlen
1315
+	 * @param string $nonce
1316
+	 * @param string $key
1317
+	 * @return bool
1318
+	 * @throws SodiumException
1319
+	 * @throws TypeError
1320
+	 */
1321
+	protected static function secretbox_encrypt_core32($ifp, $ofp, $mlen, $nonce, $key)
1322
+	{
1323
+		$plaintext = fread($ifp, 32);
1324
+		if (!is_string($plaintext)) {
1325
+			throw new SodiumException('Could not read input file');
1326
+		}
1327
+		$first32 = self::ftell($ifp);
1328
+
1329
+		/** @var string $subkey */
1330
+		$subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
1331
+
1332
+		/** @var string $realNonce */
1333
+		$realNonce = ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
1334
+
1335
+		/** @var string $block0 */
1336
+		$block0 = str_repeat("\x00", 32);
1337
+
1338
+		/** @var int $mlen - Length of the plaintext message */
1339
+		$mlen0 = $mlen;
1340
+		if ($mlen0 > 64 - ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES) {
1341
+			$mlen0 = 64 - ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES;
1342
+		}
1343
+		$block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
1344
+
1345
+		/** @var string $block0 */
1346
+		$block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor(
1347
+			$block0,
1348
+			$realNonce,
1349
+			$subkey
1350
+		);
1351
+
1352
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State(
1353
+			ParagonIE_Sodium_Core32_Util::substr(
1354
+				$block0,
1355
+				0,
1356
+				ParagonIE_Sodium_Crypto::onetimeauth_poly1305_KEYBYTES
1357
+			)
1358
+		);
1359
+
1360
+		// Pre-write 16 blank bytes for the Poly1305 tag
1361
+		$start = self::ftell($ofp);
1362
+		fwrite($ofp, str_repeat("\x00", 16));
1363
+
1364
+		/** @var string $c */
1365
+		$cBlock = ParagonIE_Sodium_Core32_Util::substr(
1366
+			$block0,
1367
+			ParagonIE_Sodium_Crypto::secretbox_xsalsa20poly1305_ZEROBYTES
1368
+		);
1369
+		$state->update($cBlock);
1370
+		fwrite($ofp, $cBlock);
1371
+		$mlen -= 32;
1372
+
1373
+		/** @var int $iter */
1374
+		$iter = 1;
1375
+
1376
+		/** @var int $incr */
1377
+		$incr = self::BUFFER_SIZE >> 6;
1378
+
1379
+		/*
1380 1380
          * Set the cursor to the end of the first half-block. All future bytes will
1381 1381
          * generated from salsa20_xor_ic, starting from 1 (second block).
1382 1382
          */
1383
-        fseek($ifp, $first32, SEEK_SET);
1384
-
1385
-        while ($mlen > 0) {
1386
-            $blockSize = $mlen > self::BUFFER_SIZE
1387
-                ? self::BUFFER_SIZE
1388
-                : $mlen;
1389
-            $plaintext = fread($ifp, $blockSize);
1390
-            if (!is_string($plaintext)) {
1391
-                throw new SodiumException('Could not read input file');
1392
-            }
1393
-            $cBlock = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
1394
-                $plaintext,
1395
-                $realNonce,
1396
-                $iter,
1397
-                $subkey
1398
-            );
1399
-            fwrite($ofp, $cBlock, $blockSize);
1400
-            $state->update($cBlock);
1401
-
1402
-            $mlen -= $blockSize;
1403
-            $iter += $incr;
1404
-        }
1405
-        try {
1406
-            ParagonIE_Sodium_Compat::memzero($block0);
1407
-            ParagonIE_Sodium_Compat::memzero($subkey);
1408
-        } catch (SodiumException $ex) {
1409
-            $block0 = null;
1410
-            $subkey = null;
1411
-        }
1412
-        $end = self::ftell($ofp);
1413
-
1414
-        /*
1383
+		fseek($ifp, $first32, SEEK_SET);
1384
+
1385
+		while ($mlen > 0) {
1386
+			$blockSize = $mlen > self::BUFFER_SIZE
1387
+				? self::BUFFER_SIZE
1388
+				: $mlen;
1389
+			$plaintext = fread($ifp, $blockSize);
1390
+			if (!is_string($plaintext)) {
1391
+				throw new SodiumException('Could not read input file');
1392
+			}
1393
+			$cBlock = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
1394
+				$plaintext,
1395
+				$realNonce,
1396
+				$iter,
1397
+				$subkey
1398
+			);
1399
+			fwrite($ofp, $cBlock, $blockSize);
1400
+			$state->update($cBlock);
1401
+
1402
+			$mlen -= $blockSize;
1403
+			$iter += $incr;
1404
+		}
1405
+		try {
1406
+			ParagonIE_Sodium_Compat::memzero($block0);
1407
+			ParagonIE_Sodium_Compat::memzero($subkey);
1408
+		} catch (SodiumException $ex) {
1409
+			$block0 = null;
1410
+			$subkey = null;
1411
+		}
1412
+		$end = self::ftell($ofp);
1413
+
1414
+		/*
1415 1415
          * Write the Poly1305 authentication tag that provides integrity
1416 1416
          * over the ciphertext (encrypt-then-MAC)
1417 1417
          */
1418
-        fseek($ofp, $start, SEEK_SET);
1419
-        fwrite($ofp, $state->finish(), ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_MACBYTES);
1420
-        fseek($ofp, $end, SEEK_SET);
1421
-        unset($state);
1422
-
1423
-        return true;
1424
-    }
1425
-
1426
-    /**
1427
-     * Decrypt a file (32-bit)
1428
-     *
1429
-     * @param resource $ifp
1430
-     * @param resource $ofp
1431
-     * @param int $mlen
1432
-     * @param string $nonce
1433
-     * @param string $key
1434
-     * @return bool
1435
-     * @throws SodiumException
1436
-     * @throws TypeError
1437
-     */
1438
-    protected static function secretbox_decrypt_core32($ifp, $ofp, $mlen, $nonce, $key)
1439
-    {
1440
-        $tag = fread($ifp, 16);
1441
-        if (!is_string($tag)) {
1442
-            throw new SodiumException('Could not read input file');
1443
-        }
1444
-
1445
-        /** @var string $subkey */
1446
-        $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
1447
-
1448
-        /** @var string $realNonce */
1449
-        $realNonce = ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
1450
-
1451
-        /** @var string $block0 */
1452
-        $block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20(
1453
-            64,
1454
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1455
-            $subkey
1456
-        );
1457
-
1458
-        /* Verify the Poly1305 MAC -before- attempting to decrypt! */
1459
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State(self::substr($block0, 0, 32));
1460
-        if (!self::onetimeauth_verify_core32($state, $ifp, $tag, $mlen)) {
1461
-            throw new SodiumException('Invalid MAC');
1462
-        }
1463
-
1464
-        /*
1418
+		fseek($ofp, $start, SEEK_SET);
1419
+		fwrite($ofp, $state->finish(), ParagonIE_Sodium_Compat::CRYPTO_SECRETBOX_MACBYTES);
1420
+		fseek($ofp, $end, SEEK_SET);
1421
+		unset($state);
1422
+
1423
+		return true;
1424
+	}
1425
+
1426
+	/**
1427
+	 * Decrypt a file (32-bit)
1428
+	 *
1429
+	 * @param resource $ifp
1430
+	 * @param resource $ofp
1431
+	 * @param int $mlen
1432
+	 * @param string $nonce
1433
+	 * @param string $key
1434
+	 * @return bool
1435
+	 * @throws SodiumException
1436
+	 * @throws TypeError
1437
+	 */
1438
+	protected static function secretbox_decrypt_core32($ifp, $ofp, $mlen, $nonce, $key)
1439
+	{
1440
+		$tag = fread($ifp, 16);
1441
+		if (!is_string($tag)) {
1442
+			throw new SodiumException('Could not read input file');
1443
+		}
1444
+
1445
+		/** @var string $subkey */
1446
+		$subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
1447
+
1448
+		/** @var string $realNonce */
1449
+		$realNonce = ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
1450
+
1451
+		/** @var string $block0 */
1452
+		$block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20(
1453
+			64,
1454
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1455
+			$subkey
1456
+		);
1457
+
1458
+		/* Verify the Poly1305 MAC -before- attempting to decrypt! */
1459
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State(self::substr($block0, 0, 32));
1460
+		if (!self::onetimeauth_verify_core32($state, $ifp, $tag, $mlen)) {
1461
+			throw new SodiumException('Invalid MAC');
1462
+		}
1463
+
1464
+		/*
1465 1465
          * Set the cursor to the end of the first half-block. All future bytes will
1466 1466
          * generated from salsa20_xor_ic, starting from 1 (second block).
1467 1467
          */
1468
-        $first32 = fread($ifp, 32);
1469
-        if (!is_string($first32)) {
1470
-            throw new SodiumException('Could not read input file');
1471
-        }
1472
-        $first32len = self::strlen($first32);
1473
-        fwrite(
1474
-            $ofp,
1475
-            self::xorStrings(
1476
-                self::substr($block0, 32, $first32len),
1477
-                self::substr($first32, 0, $first32len)
1478
-            )
1479
-        );
1480
-        $mlen -= 32;
1481
-
1482
-        /** @var int $iter */
1483
-        $iter = 1;
1484
-
1485
-        /** @var int $incr */
1486
-        $incr = self::BUFFER_SIZE >> 6;
1487
-
1488
-        /* Decrypts ciphertext, writes to output file. */
1489
-        while ($mlen > 0) {
1490
-            $blockSize = $mlen > self::BUFFER_SIZE
1491
-                ? self::BUFFER_SIZE
1492
-                : $mlen;
1493
-            $ciphertext = fread($ifp, $blockSize);
1494
-            if (!is_string($ciphertext)) {
1495
-                throw new SodiumException('Could not read input file');
1496
-            }
1497
-            $pBlock = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
1498
-                $ciphertext,
1499
-                $realNonce,
1500
-                $iter,
1501
-                $subkey
1502
-            );
1503
-            fwrite($ofp, $pBlock, $blockSize);
1504
-            $mlen -= $blockSize;
1505
-            $iter += $incr;
1506
-        }
1507
-        return true;
1508
-    }
1509
-
1510
-    /**
1511
-     * One-time message authentication for 32-bit systems
1512
-     *
1513
-     * @param ParagonIE_Sodium_Core32_Poly1305_State $state
1514
-     * @param resource $ifp
1515
-     * @param string $tag
1516
-     * @param int $mlen
1517
-     * @return bool
1518
-     * @throws SodiumException
1519
-     * @throws TypeError
1520
-     */
1521
-    protected static function onetimeauth_verify_core32(
1522
-        ParagonIE_Sodium_Core32_Poly1305_State $state,
1523
-        $ifp,
1524
-        $tag = '',
1525
-        $mlen = 0
1526
-    ) {
1527
-        /** @var int $pos */
1528
-        $pos = self::ftell($ifp);
1529
-
1530
-        while ($mlen > 0) {
1531
-            $blockSize = $mlen > self::BUFFER_SIZE
1532
-                ? self::BUFFER_SIZE
1533
-                : $mlen;
1534
-            $ciphertext = fread($ifp, $blockSize);
1535
-            if (!is_string($ciphertext)) {
1536
-                throw new SodiumException('Could not read input file');
1537
-            }
1538
-            $state->update($ciphertext);
1539
-            $mlen -= $blockSize;
1540
-        }
1541
-        $res = ParagonIE_Sodium_Core32_Util::verify_16($tag, $state->finish());
1542
-
1543
-        fseek($ifp, $pos, SEEK_SET);
1544
-        return $res;
1545
-    }
1546
-
1547
-    /**
1548
-     * @param resource $resource
1549
-     * @return int
1550
-     * @throws SodiumException
1551
-     */
1552
-    private static function ftell($resource)
1553
-    {
1554
-        $return = ftell($resource);
1555
-        if (!is_int($return)) {
1556
-            throw new SodiumException('ftell() returned false');
1557
-        }
1558
-        return (int) $return;
1559
-    }
1468
+		$first32 = fread($ifp, 32);
1469
+		if (!is_string($first32)) {
1470
+			throw new SodiumException('Could not read input file');
1471
+		}
1472
+		$first32len = self::strlen($first32);
1473
+		fwrite(
1474
+			$ofp,
1475
+			self::xorStrings(
1476
+				self::substr($block0, 32, $first32len),
1477
+				self::substr($first32, 0, $first32len)
1478
+			)
1479
+		);
1480
+		$mlen -= 32;
1481
+
1482
+		/** @var int $iter */
1483
+		$iter = 1;
1484
+
1485
+		/** @var int $incr */
1486
+		$incr = self::BUFFER_SIZE >> 6;
1487
+
1488
+		/* Decrypts ciphertext, writes to output file. */
1489
+		while ($mlen > 0) {
1490
+			$blockSize = $mlen > self::BUFFER_SIZE
1491
+				? self::BUFFER_SIZE
1492
+				: $mlen;
1493
+			$ciphertext = fread($ifp, $blockSize);
1494
+			if (!is_string($ciphertext)) {
1495
+				throw new SodiumException('Could not read input file');
1496
+			}
1497
+			$pBlock = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
1498
+				$ciphertext,
1499
+				$realNonce,
1500
+				$iter,
1501
+				$subkey
1502
+			);
1503
+			fwrite($ofp, $pBlock, $blockSize);
1504
+			$mlen -= $blockSize;
1505
+			$iter += $incr;
1506
+		}
1507
+		return true;
1508
+	}
1509
+
1510
+	/**
1511
+	 * One-time message authentication for 32-bit systems
1512
+	 *
1513
+	 * @param ParagonIE_Sodium_Core32_Poly1305_State $state
1514
+	 * @param resource $ifp
1515
+	 * @param string $tag
1516
+	 * @param int $mlen
1517
+	 * @return bool
1518
+	 * @throws SodiumException
1519
+	 * @throws TypeError
1520
+	 */
1521
+	protected static function onetimeauth_verify_core32(
1522
+		ParagonIE_Sodium_Core32_Poly1305_State $state,
1523
+		$ifp,
1524
+		$tag = '',
1525
+		$mlen = 0
1526
+	) {
1527
+		/** @var int $pos */
1528
+		$pos = self::ftell($ifp);
1529
+
1530
+		while ($mlen > 0) {
1531
+			$blockSize = $mlen > self::BUFFER_SIZE
1532
+				? self::BUFFER_SIZE
1533
+				: $mlen;
1534
+			$ciphertext = fread($ifp, $blockSize);
1535
+			if (!is_string($ciphertext)) {
1536
+				throw new SodiumException('Could not read input file');
1537
+			}
1538
+			$state->update($ciphertext);
1539
+			$mlen -= $blockSize;
1540
+		}
1541
+		$res = ParagonIE_Sodium_Core32_Util::verify_16($tag, $state->finish());
1542
+
1543
+		fseek($ifp, $pos, SEEK_SET);
1544
+		return $res;
1545
+	}
1546
+
1547
+	/**
1548
+	 * @param resource $resource
1549
+	 * @return int
1550
+	 * @throws SodiumException
1551
+	 */
1552
+	private static function ftell($resource)
1553
+	{
1554
+		$return = ftell($resource);
1555
+		if (!is_int($return)) {
1556
+			throw new SodiumException('ftell() returned false');
1557
+		}
1558
+		return (int) $return;
1559
+	}
1560 1560
 }
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/PHP52/SplFixedArray.php 1 patch
Indentation   +174 added lines, -174 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('SplFixedArray')) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -13,177 +13,177 @@  discard block
 block discarded – undo
13 13
  */
14 14
 class SplFixedArray implements Iterator, ArrayAccess, Countable
15 15
 {
16
-    /** @var array<int, mixed> */
17
-    private $internalArray = array();
18
-
19
-    /** @var int $size */
20
-    private $size = 0;
21
-
22
-    /**
23
-     * SplFixedArray constructor.
24
-     * @param int $size
25
-     */
26
-    public function __construct($size = 0)
27
-    {
28
-        $this->size = $size;
29
-        $this->internalArray = array();
30
-    }
31
-
32
-    /**
33
-     * @return int
34
-     */
35
-    public function count()
36
-    {
37
-        return count($this->internalArray);
38
-    }
39
-
40
-    /**
41
-     * @return array
42
-     */
43
-    public function toArray()
44
-    {
45
-        ksort($this->internalArray);
46
-        return (array) $this->internalArray;
47
-    }
48
-
49
-    /**
50
-     * @param array $array
51
-     * @param bool $save_indexes
52
-     * @return SplFixedArray
53
-     * @psalm-suppress MixedAssignment
54
-     */
55
-    public static function fromArray(array $array, $save_indexes = true)
56
-    {
57
-        $self = new SplFixedArray(count($array));
58
-        if($save_indexes) {
59
-            foreach($array as $key => $value) {
60
-                $self[(int) $key] = $value;
61
-            }
62
-        } else {
63
-            $i = 0;
64
-            foreach (array_values($array) as $value) {
65
-                $self[$i] = $value;
66
-                $i++;
67
-            }
68
-        }
69
-        return $self;
70
-    }
71
-
72
-    /**
73
-     * @return int
74
-     */
75
-    public function getSize()
76
-    {
77
-        return $this->size;
78
-    }
79
-
80
-    /**
81
-     * @param int $size
82
-     * @return bool
83
-     */
84
-    public function setSize($size)
85
-    {
86
-        $this->size = $size;
87
-        return true;
88
-    }
89
-
90
-    /**
91
-     * @param string|int $index
92
-     * @return bool
93
-     */
94
-    public function offsetExists($index)
95
-    {
96
-        return array_key_exists((int) $index, $this->internalArray);
97
-    }
98
-
99
-    /**
100
-     * @param string|int $index
101
-     * @return mixed
102
-     */
103
-    public function offsetGet($index)
104
-    {
105
-        /** @psalm-suppress MixedReturnStatement */
106
-        return $this->internalArray[(int) $index];
107
-    }
108
-
109
-    /**
110
-     * @param string|int $index
111
-     * @param mixed $newval
112
-     * @psalm-suppress MixedAssignment
113
-     */
114
-    public function offsetSet($index, $newval)
115
-    {
116
-        $this->internalArray[(int) $index] = $newval;
117
-    }
118
-
119
-    /**
120
-     * @param string|int $index
121
-     */
122
-    public function offsetUnset($index)
123
-    {
124
-        unset($this->internalArray[(int) $index]);
125
-    }
126
-
127
-    /**
128
-     * Rewind iterator back to the start
129
-     * @link https://php.net/manual/en/splfixedarray.rewind.php
130
-     * @return void
131
-     * @since 5.3.0
132
-     */
133
-    public function rewind()
134
-    {
135
-        reset($this->internalArray);
136
-    }
137
-
138
-    /**
139
-     * Return current array entry
140
-     * @link https://php.net/manual/en/splfixedarray.current.php
141
-     * @return mixed The current element value.
142
-     * @since 5.3.0
143
-     */
144
-    public function current()
145
-    {
146
-        /** @psalm-suppress MixedReturnStatement */
147
-        return current($this->internalArray);
148
-    }
149
-
150
-    /**
151
-     * Return current array index
152
-     * @return int The current array index.
153
-     */
154
-    public function key()
155
-    {
156
-        return key($this->internalArray);
157
-    }
158
-
159
-    /**
160
-     * @return void
161
-     */
162
-    public function next()
163
-    {
164
-        next($this->internalArray);
165
-    }
166
-
167
-    /**
168
-     * Check whether the array contains more elements
169
-     * @link https://php.net/manual/en/splfixedarray.valid.php
170
-     * @return bool true if the array contains any more elements, false otherwise.
171
-     */
172
-    public function valid()
173
-    {
174
-        if (empty($this->internalArray)) {
175
-            return false;
176
-        }
177
-        $result = next($this->internalArray) !== false;
178
-        prev($this->internalArray);
179
-        return $result;
180
-    }
181
-
182
-    /**
183
-     * Do nothing.
184
-     */
185
-    public function __wakeup()
186
-    {
187
-        // NOP
188
-    }
16
+	/** @var array<int, mixed> */
17
+	private $internalArray = array();
18
+
19
+	/** @var int $size */
20
+	private $size = 0;
21
+
22
+	/**
23
+	 * SplFixedArray constructor.
24
+	 * @param int $size
25
+	 */
26
+	public function __construct($size = 0)
27
+	{
28
+		$this->size = $size;
29
+		$this->internalArray = array();
30
+	}
31
+
32
+	/**
33
+	 * @return int
34
+	 */
35
+	public function count()
36
+	{
37
+		return count($this->internalArray);
38
+	}
39
+
40
+	/**
41
+	 * @return array
42
+	 */
43
+	public function toArray()
44
+	{
45
+		ksort($this->internalArray);
46
+		return (array) $this->internalArray;
47
+	}
48
+
49
+	/**
50
+	 * @param array $array
51
+	 * @param bool $save_indexes
52
+	 * @return SplFixedArray
53
+	 * @psalm-suppress MixedAssignment
54
+	 */
55
+	public static function fromArray(array $array, $save_indexes = true)
56
+	{
57
+		$self = new SplFixedArray(count($array));
58
+		if($save_indexes) {
59
+			foreach($array as $key => $value) {
60
+				$self[(int) $key] = $value;
61
+			}
62
+		} else {
63
+			$i = 0;
64
+			foreach (array_values($array) as $value) {
65
+				$self[$i] = $value;
66
+				$i++;
67
+			}
68
+		}
69
+		return $self;
70
+	}
71
+
72
+	/**
73
+	 * @return int
74
+	 */
75
+	public function getSize()
76
+	{
77
+		return $this->size;
78
+	}
79
+
80
+	/**
81
+	 * @param int $size
82
+	 * @return bool
83
+	 */
84
+	public function setSize($size)
85
+	{
86
+		$this->size = $size;
87
+		return true;
88
+	}
89
+
90
+	/**
91
+	 * @param string|int $index
92
+	 * @return bool
93
+	 */
94
+	public function offsetExists($index)
95
+	{
96
+		return array_key_exists((int) $index, $this->internalArray);
97
+	}
98
+
99
+	/**
100
+	 * @param string|int $index
101
+	 * @return mixed
102
+	 */
103
+	public function offsetGet($index)
104
+	{
105
+		/** @psalm-suppress MixedReturnStatement */
106
+		return $this->internalArray[(int) $index];
107
+	}
108
+
109
+	/**
110
+	 * @param string|int $index
111
+	 * @param mixed $newval
112
+	 * @psalm-suppress MixedAssignment
113
+	 */
114
+	public function offsetSet($index, $newval)
115
+	{
116
+		$this->internalArray[(int) $index] = $newval;
117
+	}
118
+
119
+	/**
120
+	 * @param string|int $index
121
+	 */
122
+	public function offsetUnset($index)
123
+	{
124
+		unset($this->internalArray[(int) $index]);
125
+	}
126
+
127
+	/**
128
+	 * Rewind iterator back to the start
129
+	 * @link https://php.net/manual/en/splfixedarray.rewind.php
130
+	 * @return void
131
+	 * @since 5.3.0
132
+	 */
133
+	public function rewind()
134
+	{
135
+		reset($this->internalArray);
136
+	}
137
+
138
+	/**
139
+	 * Return current array entry
140
+	 * @link https://php.net/manual/en/splfixedarray.current.php
141
+	 * @return mixed The current element value.
142
+	 * @since 5.3.0
143
+	 */
144
+	public function current()
145
+	{
146
+		/** @psalm-suppress MixedReturnStatement */
147
+		return current($this->internalArray);
148
+	}
149
+
150
+	/**
151
+	 * Return current array index
152
+	 * @return int The current array index.
153
+	 */
154
+	public function key()
155
+	{
156
+		return key($this->internalArray);
157
+	}
158
+
159
+	/**
160
+	 * @return void
161
+	 */
162
+	public function next()
163
+	{
164
+		next($this->internalArray);
165
+	}
166
+
167
+	/**
168
+	 * Check whether the array contains more elements
169
+	 * @link https://php.net/manual/en/splfixedarray.valid.php
170
+	 * @return bool true if the array contains any more elements, false otherwise.
171
+	 */
172
+	public function valid()
173
+	{
174
+		if (empty($this->internalArray)) {
175
+			return false;
176
+		}
177
+		$result = next($this->internalArray) !== false;
178
+		prev($this->internalArray);
179
+		return $result;
180
+	}
181
+
182
+	/**
183
+	 * Do nothing.
184
+	 */
185
+	public function __wakeup()
186
+	{
187
+		// NOP
188
+	}
189 189
 }
190 190
\ No newline at end of file
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Compat.php 1 patch
Indentation   +3914 added lines, -3914 removed lines patch added patch discarded remove patch
@@ -22,3926 +22,3926 @@
 block discarded – undo
22 22
  */
23 23
 
24 24
 if (class_exists('ParagonIE_Sodium_Compat', false)) {
25
-    return;
25
+	return;
26 26
 }
27 27
 
28 28
 class ParagonIE_Sodium_Compat
29 29
 {
30
-    /**
31
-     * This parameter prevents the use of the PECL extension.
32
-     * It should only be used for unit testing.
33
-     *
34
-     * @var bool
35
-     */
36
-    public static $disableFallbackForUnitTests = false;
37
-
38
-    /**
39
-     * Use fast multiplication rather than our constant-time multiplication
40
-     * implementation. Can be enabled at runtime. Only enable this if you
41
-     * are absolutely certain that there is no timing leak on your platform.
42
-     *
43
-     * @var bool
44
-     */
45
-    public static $fastMult = false;
46
-
47
-    const LIBRARY_MAJOR_VERSION = 9;
48
-    const LIBRARY_MINOR_VERSION = 1;
49
-    const LIBRARY_VERSION_MAJOR = 9;
50
-    const LIBRARY_VERSION_MINOR = 1;
51
-    const VERSION_STRING = 'polyfill-1.0.8';
52
-
53
-    // From libsodium
54
-    const BASE64_VARIANT_ORIGINAL = 1;
55
-    const BASE64_VARIANT_ORIGINAL_NO_PADDING = 3;
56
-    const BASE64_VARIANT_URLSAFE = 5;
57
-    const BASE64_VARIANT_URLSAFE_NO_PADDING = 7;
58
-    const CRYPTO_AEAD_AES256GCM_KEYBYTES = 32;
59
-    const CRYPTO_AEAD_AES256GCM_NSECBYTES = 0;
60
-    const CRYPTO_AEAD_AES256GCM_NPUBBYTES = 12;
61
-    const CRYPTO_AEAD_AES256GCM_ABYTES = 16;
62
-    const CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES = 32;
63
-    const CRYPTO_AEAD_CHACHA20POLY1305_NSECBYTES = 0;
64
-    const CRYPTO_AEAD_CHACHA20POLY1305_NPUBBYTES = 8;
65
-    const CRYPTO_AEAD_CHACHA20POLY1305_ABYTES = 16;
66
-    const CRYPTO_AEAD_CHACHA20POLY1305_IETF_KEYBYTES = 32;
67
-    const CRYPTO_AEAD_CHACHA20POLY1305_IETF_NSECBYTES = 0;
68
-    const CRYPTO_AEAD_CHACHA20POLY1305_IETF_NPUBBYTES = 12;
69
-    const CRYPTO_AEAD_CHACHA20POLY1305_IETF_ABYTES = 16;
70
-    const CRYPTO_AEAD_XCHACHA20POLY1305_IETF_KEYBYTES = 32;
71
-    const CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NSECBYTES = 0;
72
-    const CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NPUBBYTES = 24;
73
-    const CRYPTO_AEAD_XCHACHA20POLY1305_IETF_ABYTES = 16;
74
-    const CRYPTO_AUTH_BYTES = 32;
75
-    const CRYPTO_AUTH_KEYBYTES = 32;
76
-    const CRYPTO_BOX_SEALBYTES = 16;
77
-    const CRYPTO_BOX_SECRETKEYBYTES = 32;
78
-    const CRYPTO_BOX_PUBLICKEYBYTES = 32;
79
-    const CRYPTO_BOX_KEYPAIRBYTES = 64;
80
-    const CRYPTO_BOX_MACBYTES = 16;
81
-    const CRYPTO_BOX_NONCEBYTES = 24;
82
-    const CRYPTO_BOX_SEEDBYTES = 32;
83
-    const CRYPTO_CORE_RISTRETTO255_BYTES = 32;
84
-    const CRYPTO_CORE_RISTRETTO255_SCALARBYTES = 32;
85
-    const CRYPTO_CORE_RISTRETTO255_HASHBYTES = 64;
86
-    const CRYPTO_CORE_RISTRETTO255_NONREDUCEDSCALARBYTES = 64;
87
-    const CRYPTO_KDF_BYTES_MIN = 16;
88
-    const CRYPTO_KDF_BYTES_MAX = 64;
89
-    const CRYPTO_KDF_CONTEXTBYTES = 8;
90
-    const CRYPTO_KDF_KEYBYTES = 32;
91
-    const CRYPTO_KX_BYTES = 32;
92
-    const CRYPTO_KX_PRIMITIVE = 'x25519blake2b';
93
-    const CRYPTO_KX_SEEDBYTES = 32;
94
-    const CRYPTO_KX_KEYPAIRBYTES = 64;
95
-    const CRYPTO_KX_PUBLICKEYBYTES = 32;
96
-    const CRYPTO_KX_SECRETKEYBYTES = 32;
97
-    const CRYPTO_KX_SESSIONKEYBYTES = 32;
98
-    const CRYPTO_GENERICHASH_BYTES = 32;
99
-    const CRYPTO_GENERICHASH_BYTES_MIN = 16;
100
-    const CRYPTO_GENERICHASH_BYTES_MAX = 64;
101
-    const CRYPTO_GENERICHASH_KEYBYTES = 32;
102
-    const CRYPTO_GENERICHASH_KEYBYTES_MIN = 16;
103
-    const CRYPTO_GENERICHASH_KEYBYTES_MAX = 64;
104
-    const CRYPTO_PWHASH_SALTBYTES = 16;
105
-    const CRYPTO_PWHASH_STRPREFIX = '$argon2id$';
106
-    const CRYPTO_PWHASH_ALG_ARGON2I13 = 1;
107
-    const CRYPTO_PWHASH_ALG_ARGON2ID13 = 2;
108
-    const CRYPTO_PWHASH_MEMLIMIT_INTERACTIVE = 33554432;
109
-    const CRYPTO_PWHASH_OPSLIMIT_INTERACTIVE = 4;
110
-    const CRYPTO_PWHASH_MEMLIMIT_MODERATE = 134217728;
111
-    const CRYPTO_PWHASH_OPSLIMIT_MODERATE = 6;
112
-    const CRYPTO_PWHASH_MEMLIMIT_SENSITIVE = 536870912;
113
-    const CRYPTO_PWHASH_OPSLIMIT_SENSITIVE = 8;
114
-    const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_SALTBYTES = 32;
115
-    const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_STRPREFIX = '$7$';
116
-    const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_OPSLIMIT_INTERACTIVE = 534288;
117
-    const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_MEMLIMIT_INTERACTIVE = 16777216;
118
-    const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_OPSLIMIT_SENSITIVE = 33554432;
119
-    const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_MEMLIMIT_SENSITIVE = 1073741824;
120
-    const CRYPTO_SCALARMULT_BYTES = 32;
121
-    const CRYPTO_SCALARMULT_SCALARBYTES = 32;
122
-    const CRYPTO_SCALARMULT_RISTRETTO255_BYTES = 32;
123
-    const CRYPTO_SCALARMULT_RISTRETTO255_SCALARBYTES = 32;
124
-    const CRYPTO_SHORTHASH_BYTES = 8;
125
-    const CRYPTO_SHORTHASH_KEYBYTES = 16;
126
-    const CRYPTO_SECRETBOX_KEYBYTES = 32;
127
-    const CRYPTO_SECRETBOX_MACBYTES = 16;
128
-    const CRYPTO_SECRETBOX_NONCEBYTES = 24;
129
-    const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_ABYTES = 17;
130
-    const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_HEADERBYTES = 24;
131
-    const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_KEYBYTES = 32;
132
-    const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_PUSH = 0;
133
-    const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_PULL = 1;
134
-    const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY = 2;
135
-    const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_FINAL = 3;
136
-    const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX = 0x3fffffff80;
137
-    const CRYPTO_SIGN_BYTES = 64;
138
-    const CRYPTO_SIGN_SEEDBYTES = 32;
139
-    const CRYPTO_SIGN_PUBLICKEYBYTES = 32;
140
-    const CRYPTO_SIGN_SECRETKEYBYTES = 64;
141
-    const CRYPTO_SIGN_KEYPAIRBYTES = 96;
142
-    const CRYPTO_STREAM_KEYBYTES = 32;
143
-    const CRYPTO_STREAM_NONCEBYTES = 24;
144
-    const CRYPTO_STREAM_XCHACHA20_KEYBYTES = 32;
145
-    const CRYPTO_STREAM_XCHACHA20_NONCEBYTES = 24;
146
-
147
-    /**
148
-     * Add two numbers (little-endian unsigned), storing the value in the first
149
-     * parameter.
150
-     *
151
-     * This mutates $val.
152
-     *
153
-     * @param string $val
154
-     * @param string $addv
155
-     * @return void
156
-     * @throws SodiumException
157
-     */
158
-    public static function add(&$val, $addv)
159
-    {
160
-        $val_len = ParagonIE_Sodium_Core_Util::strlen($val);
161
-        $addv_len = ParagonIE_Sodium_Core_Util::strlen($addv);
162
-        if ($val_len !== $addv_len) {
163
-            throw new SodiumException('values must have the same length');
164
-        }
165
-        $A = ParagonIE_Sodium_Core_Util::stringToIntArray($val);
166
-        $B = ParagonIE_Sodium_Core_Util::stringToIntArray($addv);
167
-
168
-        $c = 0;
169
-        for ($i = 0; $i < $val_len; $i++) {
170
-            $c += ($A[$i] + $B[$i]);
171
-            $A[$i] = ($c & 0xff);
172
-            $c >>= 8;
173
-        }
174
-        $val = ParagonIE_Sodium_Core_Util::intArrayToString($A);
175
-    }
176
-
177
-    /**
178
-     * @param string $encoded
179
-     * @param int $variant
180
-     * @param string $ignore
181
-     * @return string
182
-     * @throws SodiumException
183
-     */
184
-    public static function base642bin($encoded, $variant, $ignore = '')
185
-    {
186
-        /* Type checks: */
187
-        ParagonIE_Sodium_Core_Util::declareScalarType($encoded, 'string', 1);
188
-
189
-        /** @var string $encoded */
190
-        $encoded = (string) $encoded;
191
-        if (ParagonIE_Sodium_Core_Util::strlen($encoded) === 0) {
192
-            return '';
193
-        }
194
-
195
-        // Just strip before decoding
196
-        if (!empty($ignore)) {
197
-            $encoded = str_replace($ignore, '', $encoded);
198
-        }
199
-
200
-        try {
201
-            switch ($variant) {
202
-                case self::BASE64_VARIANT_ORIGINAL:
203
-                    return ParagonIE_Sodium_Core_Base64_Original::decode($encoded, true);
204
-                case self::BASE64_VARIANT_ORIGINAL_NO_PADDING:
205
-                    return ParagonIE_Sodium_Core_Base64_Original::decode($encoded, false);
206
-                case self::BASE64_VARIANT_URLSAFE:
207
-                    return ParagonIE_Sodium_Core_Base64_UrlSafe::decode($encoded, true);
208
-                case self::BASE64_VARIANT_URLSAFE_NO_PADDING:
209
-                    return ParagonIE_Sodium_Core_Base64_UrlSafe::decode($encoded, false);
210
-                default:
211
-                    throw new SodiumException('invalid base64 variant identifier');
212
-            }
213
-        } catch (Exception $ex) {
214
-            if ($ex instanceof SodiumException) {
215
-                throw $ex;
216
-            }
217
-            throw new SodiumException('invalid base64 string');
218
-        }
219
-    }
220
-
221
-    /**
222
-     * @param string $decoded
223
-     * @param int $variant
224
-     * @return string
225
-     * @throws SodiumException
226
-     */
227
-    public static function bin2base64($decoded, $variant)
228
-    {
229
-        /* Type checks: */
230
-        ParagonIE_Sodium_Core_Util::declareScalarType($decoded, 'string', 1);
231
-        /** @var string $decoded */
232
-        $decoded = (string) $decoded;
233
-        if (ParagonIE_Sodium_Core_Util::strlen($decoded) === 0) {
234
-            return '';
235
-        }
236
-
237
-        switch ($variant) {
238
-            case self::BASE64_VARIANT_ORIGINAL:
239
-                return ParagonIE_Sodium_Core_Base64_Original::encode($decoded);
240
-            case self::BASE64_VARIANT_ORIGINAL_NO_PADDING:
241
-                return ParagonIE_Sodium_Core_Base64_Original::encodeUnpadded($decoded);
242
-            case self::BASE64_VARIANT_URLSAFE:
243
-                return ParagonIE_Sodium_Core_Base64_UrlSafe::encode($decoded);
244
-            case self::BASE64_VARIANT_URLSAFE_NO_PADDING:
245
-                return ParagonIE_Sodium_Core_Base64_UrlSafe::encodeUnpadded($decoded);
246
-            default:
247
-                throw new SodiumException('invalid base64 variant identifier');
248
-        }
249
-    }
250
-
251
-    /**
252
-     * Cache-timing-safe implementation of bin2hex().
253
-     *
254
-     * @param string $string A string (probably raw binary)
255
-     * @return string        A hexadecimal-encoded string
256
-     * @throws SodiumException
257
-     * @throws TypeError
258
-     * @psalm-suppress MixedArgument
259
-     */
260
-    public static function bin2hex($string)
261
-    {
262
-        /* Type checks: */
263
-        ParagonIE_Sodium_Core_Util::declareScalarType($string, 'string', 1);
264
-
265
-        if (self::useNewSodiumAPI()) {
266
-            return (string) sodium_bin2hex($string);
267
-        }
268
-        if (self::use_fallback('bin2hex')) {
269
-            return (string) call_user_func('\\Sodium\\bin2hex', $string);
270
-        }
271
-        return ParagonIE_Sodium_Core_Util::bin2hex($string);
272
-    }
273
-
274
-    /**
275
-     * Compare two strings, in constant-time.
276
-     * Compared to memcmp(), compare() is more useful for sorting.
277
-     *
278
-     * @param string $left  The left operand; must be a string
279
-     * @param string $right The right operand; must be a string
280
-     * @return int          If < 0 if the left operand is less than the right
281
-     *                      If = 0 if both strings are equal
282
-     *                      If > 0 if the right operand is less than the left
283
-     * @throws SodiumException
284
-     * @throws TypeError
285
-     * @psalm-suppress MixedArgument
286
-     */
287
-    public static function compare($left, $right)
288
-    {
289
-        /* Type checks: */
290
-        ParagonIE_Sodium_Core_Util::declareScalarType($left, 'string', 1);
291
-        ParagonIE_Sodium_Core_Util::declareScalarType($right, 'string', 2);
292
-
293
-        if (self::useNewSodiumAPI()) {
294
-            return (int) sodium_compare($left, $right);
295
-        }
296
-        if (self::use_fallback('compare')) {
297
-            return (int) call_user_func('\\Sodium\\compare', $left, $right);
298
-        }
299
-        return ParagonIE_Sodium_Core_Util::compare($left, $right);
300
-    }
301
-
302
-    /**
303
-     * Is AES-256-GCM even available to use?
304
-     *
305
-     * @return bool
306
-     * @psalm-suppress UndefinedFunction
307
-     * @psalm-suppress MixedInferredReturnType
308
-     * @psalm-suppress MixedReturnStatement
309
-     */
310
-    public static function crypto_aead_aes256gcm_is_available()
311
-    {
312
-        if (self::useNewSodiumAPI()) {
313
-            return sodium_crypto_aead_aes256gcm_is_available();
314
-        }
315
-        if (self::use_fallback('crypto_aead_aes256gcm_is_available')) {
316
-            return call_user_func('\\Sodium\\crypto_aead_aes256gcm_is_available');
317
-        }
318
-        if (PHP_VERSION_ID < 70100) {
319
-            // OpenSSL doesn't support AEAD before 7.1.0
320
-            return false;
321
-        }
322
-        if (!is_callable('openssl_encrypt') || !is_callable('openssl_decrypt')) {
323
-            // OpenSSL isn't installed
324
-            return false;
325
-        }
326
-        return (bool) in_array('aes-256-gcm', openssl_get_cipher_methods());
327
-    }
328
-
329
-    /**
330
-     * Authenticated Encryption with Associated Data: Decryption
331
-     *
332
-     * Algorithm:
333
-     *     AES-256-GCM
334
-     *
335
-     * This mode uses a 64-bit random nonce with a 64-bit counter.
336
-     * IETF mode uses a 96-bit random nonce with a 32-bit counter.
337
-     *
338
-     * @param string $ciphertext Encrypted message (with Poly1305 MAC appended)
339
-     * @param string $assocData  Authenticated Associated Data (unencrypted)
340
-     * @param string $nonce      Number to be used only Once; must be 8 bytes
341
-     * @param string $key        Encryption key
342
-     *
343
-     * @return string|bool       The original plaintext message
344
-     * @throws SodiumException
345
-     * @throws TypeError
346
-     * @psalm-suppress MixedArgument
347
-     * @psalm-suppress MixedInferredReturnType
348
-     * @psalm-suppress MixedReturnStatement
349
-     */
350
-    public static function crypto_aead_aes256gcm_decrypt(
351
-        $ciphertext = '',
352
-        $assocData = '',
353
-        $nonce = '',
354
-        $key = ''
355
-    ) {
356
-        if (!self::crypto_aead_aes256gcm_is_available()) {
357
-            throw new SodiumException('AES-256-GCM is not available');
358
-        }
359
-        ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
360
-        ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
361
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
362
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
363
-
364
-        /* Input validation: */
365
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_AES256GCM_NPUBBYTES) {
366
-            throw new SodiumException('Nonce must be CRYPTO_AEAD_AES256GCM_NPUBBYTES long');
367
-        }
368
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_AES256GCM_KEYBYTES) {
369
-            throw new SodiumException('Key must be CRYPTO_AEAD_AES256GCM_KEYBYTES long');
370
-        }
371
-        if (ParagonIE_Sodium_Core_Util::strlen($ciphertext) < self::CRYPTO_AEAD_AES256GCM_ABYTES) {
372
-            throw new SodiumException('Message must be at least CRYPTO_AEAD_AES256GCM_ABYTES long');
373
-        }
374
-        if (!is_callable('openssl_decrypt')) {
375
-            throw new SodiumException('The OpenSSL extension is not installed, or openssl_decrypt() is not available');
376
-        }
377
-
378
-        /** @var string $ctext */
379
-        $ctext = ParagonIE_Sodium_Core_Util::substr($ciphertext, 0, -self::CRYPTO_AEAD_AES256GCM_ABYTES);
380
-        /** @var string $authTag */
381
-        $authTag = ParagonIE_Sodium_Core_Util::substr($ciphertext, -self::CRYPTO_AEAD_AES256GCM_ABYTES, 16);
382
-        return openssl_decrypt(
383
-            $ctext,
384
-            'aes-256-gcm',
385
-            $key,
386
-            OPENSSL_RAW_DATA,
387
-            $nonce,
388
-            $authTag,
389
-            $assocData
390
-        );
391
-    }
392
-
393
-    /**
394
-     * Authenticated Encryption with Associated Data: Encryption
395
-     *
396
-     * Algorithm:
397
-     *     AES-256-GCM
398
-     *
399
-     * @param string $plaintext Message to be encrypted
400
-     * @param string $assocData Authenticated Associated Data (unencrypted)
401
-     * @param string $nonce     Number to be used only Once; must be 8 bytes
402
-     * @param string $key       Encryption key
403
-     *
404
-     * @return string           Ciphertext with a 16-byte GCM message
405
-     *                          authentication code appended
406
-     * @throws SodiumException
407
-     * @throws TypeError
408
-     * @psalm-suppress MixedArgument
409
-     */
410
-    public static function crypto_aead_aes256gcm_encrypt(
411
-        $plaintext = '',
412
-        $assocData = '',
413
-        $nonce = '',
414
-        $key = ''
415
-    ) {
416
-        if (!self::crypto_aead_aes256gcm_is_available()) {
417
-            throw new SodiumException('AES-256-GCM is not available');
418
-        }
419
-        ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
420
-        ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
421
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
422
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
423
-
424
-        /* Input validation: */
425
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_AES256GCM_NPUBBYTES) {
426
-            throw new SodiumException('Nonce must be CRYPTO_AEAD_AES256GCM_NPUBBYTES long');
427
-        }
428
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_AES256GCM_KEYBYTES) {
429
-            throw new SodiumException('Key must be CRYPTO_AEAD_AES256GCM_KEYBYTES long');
430
-        }
431
-
432
-        if (!is_callable('openssl_encrypt')) {
433
-            throw new SodiumException('The OpenSSL extension is not installed, or openssl_encrypt() is not available');
434
-        }
435
-
436
-        $authTag = '';
437
-        $ciphertext = openssl_encrypt(
438
-            $plaintext,
439
-            'aes-256-gcm',
440
-            $key,
441
-            OPENSSL_RAW_DATA,
442
-            $nonce,
443
-            $authTag,
444
-            $assocData
445
-        );
446
-        return $ciphertext . $authTag;
447
-    }
448
-
449
-    /**
450
-     * Return a secure random key for use with the AES-256-GCM
451
-     * symmetric AEAD interface.
452
-     *
453
-     * @return string
454
-     * @throws Exception
455
-     * @throws Error
456
-     */
457
-    public static function crypto_aead_aes256gcm_keygen()
458
-    {
459
-        return random_bytes(self::CRYPTO_AEAD_AES256GCM_KEYBYTES);
460
-    }
461
-
462
-    /**
463
-     * Authenticated Encryption with Associated Data: Decryption
464
-     *
465
-     * Algorithm:
466
-     *     ChaCha20-Poly1305
467
-     *
468
-     * This mode uses a 64-bit random nonce with a 64-bit counter.
469
-     * IETF mode uses a 96-bit random nonce with a 32-bit counter.
470
-     *
471
-     * @param string $ciphertext Encrypted message (with Poly1305 MAC appended)
472
-     * @param string $assocData  Authenticated Associated Data (unencrypted)
473
-     * @param string $nonce      Number to be used only Once; must be 8 bytes
474
-     * @param string $key        Encryption key
475
-     *
476
-     * @return string            The original plaintext message
477
-     * @throws SodiumException
478
-     * @throws TypeError
479
-     * @psalm-suppress MixedArgument
480
-     * @psalm-suppress MixedInferredReturnType
481
-     * @psalm-suppress MixedReturnStatement
482
-     */
483
-    public static function crypto_aead_chacha20poly1305_decrypt(
484
-        $ciphertext = '',
485
-        $assocData = '',
486
-        $nonce = '',
487
-        $key = ''
488
-    ) {
489
-        /* Type checks: */
490
-        ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
491
-        ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
492
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
493
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
494
-
495
-        /* Input validation: */
496
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_CHACHA20POLY1305_NPUBBYTES) {
497
-            throw new SodiumException('Nonce must be CRYPTO_AEAD_CHACHA20POLY1305_NPUBBYTES long');
498
-        }
499
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES) {
500
-            throw new SodiumException('Key must be CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES long');
501
-        }
502
-        if (ParagonIE_Sodium_Core_Util::strlen($ciphertext) < self::CRYPTO_AEAD_CHACHA20POLY1305_ABYTES) {
503
-            throw new SodiumException('Message must be at least CRYPTO_AEAD_CHACHA20POLY1305_ABYTES long');
504
-        }
505
-
506
-        if (self::useNewSodiumAPI()) {
507
-            /**
508
-             * @psalm-suppress InvalidReturnStatement
509
-             * @psalm-suppress FalsableReturnStatement
510
-             */
511
-            return sodium_crypto_aead_chacha20poly1305_decrypt(
512
-                $ciphertext,
513
-                $assocData,
514
-                $nonce,
515
-                $key
516
-            );
517
-        }
518
-        if (self::use_fallback('crypto_aead_chacha20poly1305_decrypt')) {
519
-            return call_user_func(
520
-                '\\Sodium\\crypto_aead_chacha20poly1305_decrypt',
521
-                $ciphertext,
522
-                $assocData,
523
-                $nonce,
524
-                $key
525
-            );
526
-        }
527
-        if (PHP_INT_SIZE === 4) {
528
-            return ParagonIE_Sodium_Crypto32::aead_chacha20poly1305_decrypt(
529
-                $ciphertext,
530
-                $assocData,
531
-                $nonce,
532
-                $key
533
-            );
534
-        }
535
-        return ParagonIE_Sodium_Crypto::aead_chacha20poly1305_decrypt(
536
-            $ciphertext,
537
-            $assocData,
538
-            $nonce,
539
-            $key
540
-        );
541
-    }
542
-
543
-    /**
544
-     * Authenticated Encryption with Associated Data
545
-     *
546
-     * Algorithm:
547
-     *     ChaCha20-Poly1305
548
-     *
549
-     * This mode uses a 64-bit random nonce with a 64-bit counter.
550
-     * IETF mode uses a 96-bit random nonce with a 32-bit counter.
551
-     *
552
-     * @param string $plaintext Message to be encrypted
553
-     * @param string $assocData Authenticated Associated Data (unencrypted)
554
-     * @param string $nonce     Number to be used only Once; must be 8 bytes
555
-     * @param string $key       Encryption key
556
-     *
557
-     * @return string           Ciphertext with a 16-byte Poly1305 message
558
-     *                          authentication code appended
559
-     * @throws SodiumException
560
-     * @throws TypeError
561
-     * @psalm-suppress MixedArgument
562
-     */
563
-    public static function crypto_aead_chacha20poly1305_encrypt(
564
-        $plaintext = '',
565
-        $assocData = '',
566
-        $nonce = '',
567
-        $key = ''
568
-    ) {
569
-        /* Type checks: */
570
-        ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
571
-        ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
572
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
573
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
574
-
575
-        /* Input validation: */
576
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_CHACHA20POLY1305_NPUBBYTES) {
577
-            throw new SodiumException('Nonce must be CRYPTO_AEAD_CHACHA20POLY1305_NPUBBYTES long');
578
-        }
579
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES) {
580
-            throw new SodiumException('Key must be CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES long');
581
-        }
582
-
583
-        if (self::useNewSodiumAPI()) {
584
-            return (string) sodium_crypto_aead_chacha20poly1305_encrypt(
585
-                $plaintext,
586
-                $assocData,
587
-                $nonce,
588
-                $key
589
-            );
590
-        }
591
-        if (self::use_fallback('crypto_aead_chacha20poly1305_encrypt')) {
592
-            return (string) call_user_func(
593
-                '\\Sodium\\crypto_aead_chacha20poly1305_encrypt',
594
-                $plaintext,
595
-                $assocData,
596
-                $nonce,
597
-                $key
598
-            );
599
-        }
600
-        if (PHP_INT_SIZE === 4) {
601
-            return ParagonIE_Sodium_Crypto32::aead_chacha20poly1305_encrypt(
602
-                $plaintext,
603
-                $assocData,
604
-                $nonce,
605
-                $key
606
-            );
607
-        }
608
-        return ParagonIE_Sodium_Crypto::aead_chacha20poly1305_encrypt(
609
-            $plaintext,
610
-            $assocData,
611
-            $nonce,
612
-            $key
613
-        );
614
-    }
615
-
616
-    /**
617
-     * Authenticated Encryption with Associated Data: Decryption
618
-     *
619
-     * Algorithm:
620
-     *     ChaCha20-Poly1305
621
-     *
622
-     * IETF mode uses a 96-bit random nonce with a 32-bit counter.
623
-     * Regular mode uses a 64-bit random nonce with a 64-bit counter.
624
-     *
625
-     * @param string $ciphertext Encrypted message (with Poly1305 MAC appended)
626
-     * @param string $assocData  Authenticated Associated Data (unencrypted)
627
-     * @param string $nonce      Number to be used only Once; must be 12 bytes
628
-     * @param string $key        Encryption key
629
-     *
630
-     * @return string            The original plaintext message
631
-     * @throws SodiumException
632
-     * @throws TypeError
633
-     * @psalm-suppress MixedArgument
634
-     * @psalm-suppress MixedInferredReturnType
635
-     * @psalm-suppress MixedReturnStatement
636
-     */
637
-    public static function crypto_aead_chacha20poly1305_ietf_decrypt(
638
-        $ciphertext = '',
639
-        $assocData = '',
640
-        $nonce = '',
641
-        $key = ''
642
-    ) {
643
-        /* Type checks: */
644
-        ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
645
-        ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
646
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
647
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
648
-
649
-        /* Input validation: */
650
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_CHACHA20POLY1305_IETF_NPUBBYTES) {
651
-            throw new SodiumException('Nonce must be CRYPTO_AEAD_CHACHA20POLY1305_IETF_NPUBBYTES long');
652
-        }
653
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES) {
654
-            throw new SodiumException('Key must be CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES long');
655
-        }
656
-        if (ParagonIE_Sodium_Core_Util::strlen($ciphertext) < self::CRYPTO_AEAD_CHACHA20POLY1305_ABYTES) {
657
-            throw new SodiumException('Message must be at least CRYPTO_AEAD_CHACHA20POLY1305_ABYTES long');
658
-        }
659
-
660
-        if (self::useNewSodiumAPI()) {
661
-            /**
662
-             * @psalm-suppress InvalidReturnStatement
663
-             * @psalm-suppress FalsableReturnStatement
664
-             */
665
-            return sodium_crypto_aead_chacha20poly1305_ietf_decrypt(
666
-                $ciphertext,
667
-                $assocData,
668
-                $nonce,
669
-                $key
670
-            );
671
-        }
672
-        if (self::use_fallback('crypto_aead_chacha20poly1305_ietf_decrypt')) {
673
-            return call_user_func(
674
-                '\\Sodium\\crypto_aead_chacha20poly1305_ietf_decrypt',
675
-                $ciphertext,
676
-                $assocData,
677
-                $nonce,
678
-                $key
679
-            );
680
-        }
681
-        if (PHP_INT_SIZE === 4) {
682
-            return ParagonIE_Sodium_Crypto32::aead_chacha20poly1305_ietf_decrypt(
683
-                $ciphertext,
684
-                $assocData,
685
-                $nonce,
686
-                $key
687
-            );
688
-        }
689
-        return ParagonIE_Sodium_Crypto::aead_chacha20poly1305_ietf_decrypt(
690
-            $ciphertext,
691
-            $assocData,
692
-            $nonce,
693
-            $key
694
-        );
695
-    }
696
-
697
-    /**
698
-     * Return a secure random key for use with the ChaCha20-Poly1305
699
-     * symmetric AEAD interface.
700
-     *
701
-     * @return string
702
-     * @throws Exception
703
-     * @throws Error
704
-     */
705
-    public static function crypto_aead_chacha20poly1305_keygen()
706
-    {
707
-        return random_bytes(self::CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES);
708
-    }
709
-
710
-    /**
711
-     * Authenticated Encryption with Associated Data
712
-     *
713
-     * Algorithm:
714
-     *     ChaCha20-Poly1305
715
-     *
716
-     * IETF mode uses a 96-bit random nonce with a 32-bit counter.
717
-     * Regular mode uses a 64-bit random nonce with a 64-bit counter.
718
-     *
719
-     * @param string $plaintext Message to be encrypted
720
-     * @param string $assocData Authenticated Associated Data (unencrypted)
721
-     * @param string $nonce Number to be used only Once; must be 8 bytes
722
-     * @param string $key Encryption key
723
-     *
724
-     * @return string           Ciphertext with a 16-byte Poly1305 message
725
-     *                          authentication code appended
726
-     * @throws SodiumException
727
-     * @throws TypeError
728
-     * @psalm-suppress MixedArgument
729
-     */
730
-    public static function crypto_aead_chacha20poly1305_ietf_encrypt(
731
-        $plaintext = '',
732
-        $assocData = '',
733
-        $nonce = '',
734
-        $key = ''
735
-    ) {
736
-        /* Type checks: */
737
-        ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
738
-        if (!is_null($assocData)) {
739
-            ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
740
-        }
741
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
742
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
743
-
744
-        /* Input validation: */
745
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_CHACHA20POLY1305_IETF_NPUBBYTES) {
746
-            throw new SodiumException('Nonce must be CRYPTO_AEAD_CHACHA20POLY1305_IETF_NPUBBYTES long');
747
-        }
748
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES) {
749
-            throw new SodiumException('Key must be CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES long');
750
-        }
751
-
752
-        if (self::useNewSodiumAPI()) {
753
-            return (string) sodium_crypto_aead_chacha20poly1305_ietf_encrypt(
754
-                $plaintext,
755
-                $assocData,
756
-                $nonce,
757
-                $key
758
-            );
759
-        }
760
-        if (self::use_fallback('crypto_aead_chacha20poly1305_ietf_encrypt')) {
761
-            return (string) call_user_func(
762
-                '\\Sodium\\crypto_aead_chacha20poly1305_ietf_encrypt',
763
-                $plaintext,
764
-                $assocData,
765
-                $nonce,
766
-                $key
767
-            );
768
-        }
769
-        if (PHP_INT_SIZE === 4) {
770
-            return ParagonIE_Sodium_Crypto32::aead_chacha20poly1305_ietf_encrypt(
771
-                $plaintext,
772
-                $assocData,
773
-                $nonce,
774
-                $key
775
-            );
776
-        }
777
-        return ParagonIE_Sodium_Crypto::aead_chacha20poly1305_ietf_encrypt(
778
-            $plaintext,
779
-            $assocData,
780
-            $nonce,
781
-            $key
782
-        );
783
-    }
784
-
785
-    /**
786
-     * Return a secure random key for use with the ChaCha20-Poly1305
787
-     * symmetric AEAD interface. (IETF version)
788
-     *
789
-     * @return string
790
-     * @throws Exception
791
-     * @throws Error
792
-     */
793
-    public static function crypto_aead_chacha20poly1305_ietf_keygen()
794
-    {
795
-        return random_bytes(self::CRYPTO_AEAD_CHACHA20POLY1305_IETF_KEYBYTES);
796
-    }
797
-
798
-    /**
799
-     * Authenticated Encryption with Associated Data: Decryption
800
-     *
801
-     * Algorithm:
802
-     *     XChaCha20-Poly1305
803
-     *
804
-     * This mode uses a 64-bit random nonce with a 64-bit counter.
805
-     * IETF mode uses a 96-bit random nonce with a 32-bit counter.
806
-     *
807
-     * @param string $ciphertext   Encrypted message (with Poly1305 MAC appended)
808
-     * @param string $assocData    Authenticated Associated Data (unencrypted)
809
-     * @param string $nonce        Number to be used only Once; must be 8 bytes
810
-     * @param string $key          Encryption key
811
-     * @param bool   $dontFallback Don't fallback to ext/sodium
812
-     *
813
-     * @return string|bool         The original plaintext message
814
-     * @throws SodiumException
815
-     * @throws TypeError
816
-     * @psalm-suppress MixedArgument
817
-     */
818
-    public static function crypto_aead_xchacha20poly1305_ietf_decrypt(
819
-        $ciphertext = '',
820
-        $assocData = '',
821
-        $nonce = '',
822
-        $key = '',
823
-        $dontFallback = false
824
-    ) {
825
-        /* Type checks: */
826
-        ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
827
-        if (!is_null($assocData)) {
828
-            ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
829
-        } else {
830
-            $assocData = '';
831
-        }
832
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
833
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
834
-
835
-        /* Input validation: */
836
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NPUBBYTES) {
837
-            throw new SodiumException('Nonce must be CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NPUBBYTES long');
838
-        }
839
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_KEYBYTES) {
840
-            throw new SodiumException('Key must be CRYPTO_AEAD_XCHACHA20POLY1305_IETF_KEYBYTES long');
841
-        }
842
-        if (ParagonIE_Sodium_Core_Util::strlen($ciphertext) < self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_ABYTES) {
843
-            throw new SodiumException('Message must be at least CRYPTO_AEAD_XCHACHA20POLY1305_IETF_ABYTES long');
844
-        }
845
-        if (self::useNewSodiumAPI() && !$dontFallback) {
846
-            if (is_callable('sodium_crypto_aead_xchacha20poly1305_ietf_decrypt')) {
847
-                return sodium_crypto_aead_xchacha20poly1305_ietf_decrypt(
848
-                    $ciphertext,
849
-                    $assocData,
850
-                    $nonce,
851
-                    $key
852
-                );
853
-            }
854
-        }
855
-
856
-        if (PHP_INT_SIZE === 4) {
857
-            return ParagonIE_Sodium_Crypto32::aead_xchacha20poly1305_ietf_decrypt(
858
-                $ciphertext,
859
-                $assocData,
860
-                $nonce,
861
-                $key
862
-            );
863
-        }
864
-        return ParagonIE_Sodium_Crypto::aead_xchacha20poly1305_ietf_decrypt(
865
-            $ciphertext,
866
-            $assocData,
867
-            $nonce,
868
-            $key
869
-        );
870
-    }
871
-
872
-    /**
873
-     * Authenticated Encryption with Associated Data
874
-     *
875
-     * Algorithm:
876
-     *     XChaCha20-Poly1305
877
-     *
878
-     * This mode uses a 64-bit random nonce with a 64-bit counter.
879
-     * IETF mode uses a 96-bit random nonce with a 32-bit counter.
880
-     *
881
-     * @param string $plaintext    Message to be encrypted
882
-     * @param string $assocData    Authenticated Associated Data (unencrypted)
883
-     * @param string $nonce        Number to be used only Once; must be 8 bytes
884
-     * @param string $key          Encryption key
885
-     * @param bool   $dontFallback Don't fallback to ext/sodium
886
-     *
887
-     * @return string           Ciphertext with a 16-byte Poly1305 message
888
-     *                          authentication code appended
889
-     * @throws SodiumException
890
-     * @throws TypeError
891
-     * @psalm-suppress MixedArgument
892
-     */
893
-    public static function crypto_aead_xchacha20poly1305_ietf_encrypt(
894
-        $plaintext = '',
895
-        $assocData = '',
896
-        $nonce = '',
897
-        $key = '',
898
-        $dontFallback = false
899
-    ) {
900
-        /* Type checks: */
901
-        ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
902
-        if (!is_null($assocData)) {
903
-            ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
904
-        } else {
905
-            $assocData = '';
906
-        }
907
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
908
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
909
-
910
-        /* Input validation: */
911
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NPUBBYTES) {
912
-            throw new SodiumException('Nonce must be CRYPTO_AEAD_XCHACHA20POLY1305_NPUBBYTES long');
913
-        }
914
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_KEYBYTES) {
915
-            throw new SodiumException('Key must be CRYPTO_AEAD_XCHACHA20POLY1305_KEYBYTES long');
916
-        }
917
-        if (self::useNewSodiumAPI() && !$dontFallback) {
918
-            if (is_callable('sodium_crypto_aead_xchacha20poly1305_ietf_encrypt')) {
919
-                return sodium_crypto_aead_xchacha20poly1305_ietf_encrypt(
920
-                    $plaintext,
921
-                    $assocData,
922
-                    $nonce,
923
-                    $key
924
-                );
925
-            }
926
-        }
927
-
928
-        if (PHP_INT_SIZE === 4) {
929
-            return ParagonIE_Sodium_Crypto32::aead_xchacha20poly1305_ietf_encrypt(
930
-                $plaintext,
931
-                $assocData,
932
-                $nonce,
933
-                $key
934
-            );
935
-        }
936
-        return ParagonIE_Sodium_Crypto::aead_xchacha20poly1305_ietf_encrypt(
937
-            $plaintext,
938
-            $assocData,
939
-            $nonce,
940
-            $key
941
-        );
942
-    }
943
-
944
-    /**
945
-     * Return a secure random key for use with the XChaCha20-Poly1305
946
-     * symmetric AEAD interface.
947
-     *
948
-     * @return string
949
-     * @throws Exception
950
-     * @throws Error
951
-     */
952
-    public static function crypto_aead_xchacha20poly1305_ietf_keygen()
953
-    {
954
-        return random_bytes(self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_KEYBYTES);
955
-    }
956
-
957
-    /**
958
-     * Authenticate a message. Uses symmetric-key cryptography.
959
-     *
960
-     * Algorithm:
961
-     *     HMAC-SHA512-256. Which is HMAC-SHA-512 truncated to 256 bits.
962
-     *     Not to be confused with HMAC-SHA-512/256 which would use the
963
-     *     SHA-512/256 hash function (uses different initial parameters
964
-     *     but still truncates to 256 bits to sidestep length-extension
965
-     *     attacks).
966
-     *
967
-     * @param string $message Message to be authenticated
968
-     * @param string $key Symmetric authentication key
969
-     * @return string         Message authentication code
970
-     * @throws SodiumException
971
-     * @throws TypeError
972
-     * @psalm-suppress MixedArgument
973
-     */
974
-    public static function crypto_auth($message, $key)
975
-    {
976
-        /* Type checks: */
977
-        ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
978
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 2);
979
-
980
-        /* Input validation: */
981
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AUTH_KEYBYTES) {
982
-            throw new SodiumException('Argument 2 must be CRYPTO_AUTH_KEYBYTES long.');
983
-        }
984
-
985
-        if (self::useNewSodiumAPI()) {
986
-            return (string) sodium_crypto_auth($message, $key);
987
-        }
988
-        if (self::use_fallback('crypto_auth')) {
989
-            return (string) call_user_func('\\Sodium\\crypto_auth', $message, $key);
990
-        }
991
-        if (PHP_INT_SIZE === 4) {
992
-            return ParagonIE_Sodium_Crypto32::auth($message, $key);
993
-        }
994
-        return ParagonIE_Sodium_Crypto::auth($message, $key);
995
-    }
996
-
997
-    /**
998
-     * @return string
999
-     * @throws Exception
1000
-     * @throws Error
1001
-     */
1002
-    public static function crypto_auth_keygen()
1003
-    {
1004
-        return random_bytes(self::CRYPTO_AUTH_KEYBYTES);
1005
-    }
1006
-
1007
-    /**
1008
-     * Verify the MAC of a message previously authenticated with crypto_auth.
1009
-     *
1010
-     * @param string $mac Message authentication code
1011
-     * @param string $message Message whose authenticity you are attempting to
1012
-     *                        verify (with a given MAC and key)
1013
-     * @param string $key Symmetric authentication key
1014
-     * @return bool           TRUE if authenticated, FALSE otherwise
1015
-     * @throws SodiumException
1016
-     * @throws TypeError
1017
-     * @psalm-suppress MixedArgument
1018
-     */
1019
-    public static function crypto_auth_verify($mac, $message, $key)
1020
-    {
1021
-        /* Type checks: */
1022
-        ParagonIE_Sodium_Core_Util::declareScalarType($mac, 'string', 1);
1023
-        ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 2);
1024
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
1025
-
1026
-        /* Input validation: */
1027
-        if (ParagonIE_Sodium_Core_Util::strlen($mac) !== self::CRYPTO_AUTH_BYTES) {
1028
-            throw new SodiumException('Argument 1 must be CRYPTO_AUTH_BYTES long.');
1029
-        }
1030
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AUTH_KEYBYTES) {
1031
-            throw new SodiumException('Argument 3 must be CRYPTO_AUTH_KEYBYTES long.');
1032
-        }
1033
-
1034
-        if (self::useNewSodiumAPI()) {
1035
-            return (bool) sodium_crypto_auth_verify($mac, $message, $key);
1036
-        }
1037
-        if (self::use_fallback('crypto_auth_verify')) {
1038
-            return (bool) call_user_func('\\Sodium\\crypto_auth_verify', $mac, $message, $key);
1039
-        }
1040
-        if (PHP_INT_SIZE === 4) {
1041
-            return ParagonIE_Sodium_Crypto32::auth_verify($mac, $message, $key);
1042
-        }
1043
-        return ParagonIE_Sodium_Crypto::auth_verify($mac, $message, $key);
1044
-    }
1045
-
1046
-    /**
1047
-     * Authenticated asymmetric-key encryption. Both the sender and recipient
1048
-     * may decrypt messages.
1049
-     *
1050
-     * Algorithm: X25519-XSalsa20-Poly1305.
1051
-     *     X25519: Elliptic-Curve Diffie Hellman over Curve25519.
1052
-     *     XSalsa20: Extended-nonce variant of salsa20.
1053
-     *     Poyl1305: Polynomial MAC for one-time message authentication.
1054
-     *
1055
-     * @param string $plaintext The message to be encrypted
1056
-     * @param string $nonce A Number to only be used Once; must be 24 bytes
1057
-     * @param string $keypair Your secret key and your recipient's public key
1058
-     * @return string           Ciphertext with 16-byte Poly1305 MAC
1059
-     * @throws SodiumException
1060
-     * @throws TypeError
1061
-     * @psalm-suppress MixedArgument
1062
-     */
1063
-    public static function crypto_box($plaintext, $nonce, $keypair)
1064
-    {
1065
-        /* Type checks: */
1066
-        ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
1067
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
1068
-        ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 3);
1069
-
1070
-        /* Input validation: */
1071
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_BOX_NONCEBYTES) {
1072
-            throw new SodiumException('Argument 2 must be CRYPTO_BOX_NONCEBYTES long.');
1073
-        }
1074
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_BOX_KEYPAIRBYTES) {
1075
-            throw new SodiumException('Argument 3 must be CRYPTO_BOX_KEYPAIRBYTES long.');
1076
-        }
1077
-
1078
-        if (self::useNewSodiumAPI()) {
1079
-            return (string) sodium_crypto_box($plaintext, $nonce, $keypair);
1080
-        }
1081
-        if (self::use_fallback('crypto_box')) {
1082
-            return (string) call_user_func('\\Sodium\\crypto_box', $plaintext, $nonce, $keypair);
1083
-        }
1084
-        if (PHP_INT_SIZE === 4) {
1085
-            return ParagonIE_Sodium_Crypto32::box($plaintext, $nonce, $keypair);
1086
-        }
1087
-        return ParagonIE_Sodium_Crypto::box($plaintext, $nonce, $keypair);
1088
-    }
1089
-
1090
-    /**
1091
-     * Anonymous public-key encryption. Only the recipient may decrypt messages.
1092
-     *
1093
-     * Algorithm: X25519-XSalsa20-Poly1305, as with crypto_box.
1094
-     *     The sender's X25519 keypair is ephemeral.
1095
-     *     Nonce is generated from the BLAKE2b hash of both public keys.
1096
-     *
1097
-     * This provides ciphertext integrity.
1098
-     *
1099
-     * @param string $plaintext Message to be sealed
1100
-     * @param string $publicKey Your recipient's public key
1101
-     * @return string           Sealed message that only your recipient can
1102
-     *                          decrypt
1103
-     * @throws SodiumException
1104
-     * @throws TypeError
1105
-     * @psalm-suppress MixedArgument
1106
-     */
1107
-    public static function crypto_box_seal($plaintext, $publicKey)
1108
-    {
1109
-        /* Type checks: */
1110
-        ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
1111
-        ParagonIE_Sodium_Core_Util::declareScalarType($publicKey, 'string', 2);
1112
-
1113
-        /* Input validation: */
1114
-        if (ParagonIE_Sodium_Core_Util::strlen($publicKey) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
1115
-            throw new SodiumException('Argument 2 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
1116
-        }
1117
-
1118
-        if (self::useNewSodiumAPI()) {
1119
-            return (string) sodium_crypto_box_seal($plaintext, $publicKey);
1120
-        }
1121
-        if (self::use_fallback('crypto_box_seal')) {
1122
-            return (string) call_user_func('\\Sodium\\crypto_box_seal', $plaintext, $publicKey);
1123
-        }
1124
-        if (PHP_INT_SIZE === 4) {
1125
-            return ParagonIE_Sodium_Crypto32::box_seal($plaintext, $publicKey);
1126
-        }
1127
-        return ParagonIE_Sodium_Crypto::box_seal($plaintext, $publicKey);
1128
-    }
1129
-
1130
-    /**
1131
-     * Opens a message encrypted with crypto_box_seal(). Requires
1132
-     * the recipient's keypair (sk || pk) to decrypt successfully.
1133
-     *
1134
-     * This validates ciphertext integrity.
1135
-     *
1136
-     * @param string $ciphertext Sealed message to be opened
1137
-     * @param string $keypair    Your crypto_box keypair
1138
-     * @return string            The original plaintext message
1139
-     * @throws SodiumException
1140
-     * @throws TypeError
1141
-     * @psalm-suppress MixedArgument
1142
-     * @psalm-suppress MixedInferredReturnType
1143
-     * @psalm-suppress MixedReturnStatement
1144
-     */
1145
-    public static function crypto_box_seal_open($ciphertext, $keypair)
1146
-    {
1147
-        /* Type checks: */
1148
-        ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
1149
-        ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 2);
1150
-
1151
-        /* Input validation: */
1152
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_BOX_KEYPAIRBYTES) {
1153
-            throw new SodiumException('Argument 2 must be CRYPTO_BOX_KEYPAIRBYTES long.');
1154
-        }
1155
-
1156
-        if (self::useNewSodiumAPI()) {
1157
-            /**
1158
-             * @psalm-suppress InvalidReturnStatement
1159
-             * @psalm-suppress FalsableReturnStatement
1160
-             */
1161
-            return sodium_crypto_box_seal_open($ciphertext, $keypair);
1162
-        }
1163
-        if (self::use_fallback('crypto_box_seal_open')) {
1164
-            return call_user_func('\\Sodium\\crypto_box_seal_open', $ciphertext, $keypair);
1165
-        }
1166
-        if (PHP_INT_SIZE === 4) {
1167
-            return ParagonIE_Sodium_Crypto32::box_seal_open($ciphertext, $keypair);
1168
-        }
1169
-        return ParagonIE_Sodium_Crypto::box_seal_open($ciphertext, $keypair);
1170
-    }
1171
-
1172
-    /**
1173
-     * Generate a new random X25519 keypair.
1174
-     *
1175
-     * @return string A 64-byte string; the first 32 are your secret key, while
1176
-     *                the last 32 are your public key. crypto_box_secretkey()
1177
-     *                and crypto_box_publickey() exist to separate them so you
1178
-     *                don't accidentally get them mixed up!
1179
-     * @throws SodiumException
1180
-     * @throws TypeError
1181
-     * @psalm-suppress MixedArgument
1182
-     */
1183
-    public static function crypto_box_keypair()
1184
-    {
1185
-        if (self::useNewSodiumAPI()) {
1186
-            return (string) sodium_crypto_box_keypair();
1187
-        }
1188
-        if (self::use_fallback('crypto_box_keypair')) {
1189
-            return (string) call_user_func('\\Sodium\\crypto_box_keypair');
1190
-        }
1191
-        if (PHP_INT_SIZE === 4) {
1192
-            return ParagonIE_Sodium_Crypto32::box_keypair();
1193
-        }
1194
-        return ParagonIE_Sodium_Crypto::box_keypair();
1195
-    }
1196
-
1197
-    /**
1198
-     * Combine two keys into a keypair for use in library methods that expect
1199
-     * a keypair. This doesn't necessarily have to be the same person's keys.
1200
-     *
1201
-     * @param string $secretKey Secret key
1202
-     * @param string $publicKey Public key
1203
-     * @return string    Keypair
1204
-     * @throws SodiumException
1205
-     * @throws TypeError
1206
-     * @psalm-suppress MixedArgument
1207
-     */
1208
-    public static function crypto_box_keypair_from_secretkey_and_publickey($secretKey, $publicKey)
1209
-    {
1210
-        /* Type checks: */
1211
-        ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 1);
1212
-        ParagonIE_Sodium_Core_Util::declareScalarType($publicKey, 'string', 2);
1213
-
1214
-        /* Input validation: */
1215
-        if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_BOX_SECRETKEYBYTES) {
1216
-            throw new SodiumException('Argument 1 must be CRYPTO_BOX_SECRETKEYBYTES long.');
1217
-        }
1218
-        if (ParagonIE_Sodium_Core_Util::strlen($publicKey) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
1219
-            throw new SodiumException('Argument 2 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
1220
-        }
1221
-
1222
-        if (self::useNewSodiumAPI()) {
1223
-            return (string) sodium_crypto_box_keypair_from_secretkey_and_publickey($secretKey, $publicKey);
1224
-        }
1225
-        if (self::use_fallback('crypto_box_keypair_from_secretkey_and_publickey')) {
1226
-            return (string) call_user_func('\\Sodium\\crypto_box_keypair_from_secretkey_and_publickey', $secretKey, $publicKey);
1227
-        }
1228
-        if (PHP_INT_SIZE === 4) {
1229
-            return ParagonIE_Sodium_Crypto32::box_keypair_from_secretkey_and_publickey($secretKey, $publicKey);
1230
-        }
1231
-        return ParagonIE_Sodium_Crypto::box_keypair_from_secretkey_and_publickey($secretKey, $publicKey);
1232
-    }
1233
-
1234
-    /**
1235
-     * Decrypt a message previously encrypted with crypto_box().
1236
-     *
1237
-     * @param string $ciphertext Encrypted message
1238
-     * @param string $nonce      Number to only be used Once; must be 24 bytes
1239
-     * @param string $keypair    Your secret key and the sender's public key
1240
-     * @return string            The original plaintext message
1241
-     * @throws SodiumException
1242
-     * @throws TypeError
1243
-     * @psalm-suppress MixedArgument
1244
-     * @psalm-suppress MixedInferredReturnType
1245
-     * @psalm-suppress MixedReturnStatement
1246
-     */
1247
-    public static function crypto_box_open($ciphertext, $nonce, $keypair)
1248
-    {
1249
-        /* Type checks: */
1250
-        ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
1251
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
1252
-        ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 3);
1253
-
1254
-        /* Input validation: */
1255
-        if (ParagonIE_Sodium_Core_Util::strlen($ciphertext) < self::CRYPTO_BOX_MACBYTES) {
1256
-            throw new SodiumException('Argument 1 must be at least CRYPTO_BOX_MACBYTES long.');
1257
-        }
1258
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_BOX_NONCEBYTES) {
1259
-            throw new SodiumException('Argument 2 must be CRYPTO_BOX_NONCEBYTES long.');
1260
-        }
1261
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_BOX_KEYPAIRBYTES) {
1262
-            throw new SodiumException('Argument 3 must be CRYPTO_BOX_KEYPAIRBYTES long.');
1263
-        }
1264
-
1265
-        if (self::useNewSodiumAPI()) {
1266
-            /**
1267
-             * @psalm-suppress InvalidReturnStatement
1268
-             * @psalm-suppress FalsableReturnStatement
1269
-             */
1270
-            return sodium_crypto_box_open($ciphertext, $nonce, $keypair);
1271
-        }
1272
-        if (self::use_fallback('crypto_box_open')) {
1273
-            return call_user_func('\\Sodium\\crypto_box_open', $ciphertext, $nonce, $keypair);
1274
-        }
1275
-        if (PHP_INT_SIZE === 4) {
1276
-            return ParagonIE_Sodium_Crypto32::box_open($ciphertext, $nonce, $keypair);
1277
-        }
1278
-        return ParagonIE_Sodium_Crypto::box_open($ciphertext, $nonce, $keypair);
1279
-    }
1280
-
1281
-    /**
1282
-     * Extract the public key from a crypto_box keypair.
1283
-     *
1284
-     * @param string $keypair Keypair containing secret and public key
1285
-     * @return string         Your crypto_box public key
1286
-     * @throws SodiumException
1287
-     * @throws TypeError
1288
-     * @psalm-suppress MixedArgument
1289
-     */
1290
-    public static function crypto_box_publickey($keypair)
1291
-    {
1292
-        /* Type checks: */
1293
-        ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
1294
-
1295
-        /* Input validation: */
1296
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_BOX_KEYPAIRBYTES) {
1297
-            throw new SodiumException('Argument 1 must be CRYPTO_BOX_KEYPAIRBYTES long.');
1298
-        }
1299
-
1300
-        if (self::useNewSodiumAPI()) {
1301
-            return (string) sodium_crypto_box_publickey($keypair);
1302
-        }
1303
-        if (self::use_fallback('crypto_box_publickey')) {
1304
-            return (string) call_user_func('\\Sodium\\crypto_box_publickey', $keypair);
1305
-        }
1306
-        if (PHP_INT_SIZE === 4) {
1307
-            return ParagonIE_Sodium_Crypto32::box_publickey($keypair);
1308
-        }
1309
-        return ParagonIE_Sodium_Crypto::box_publickey($keypair);
1310
-    }
1311
-
1312
-    /**
1313
-     * Calculate the X25519 public key from a given X25519 secret key.
1314
-     *
1315
-     * @param string $secretKey Any X25519 secret key
1316
-     * @return string           The corresponding X25519 public key
1317
-     * @throws SodiumException
1318
-     * @throws TypeError
1319
-     * @psalm-suppress MixedArgument
1320
-     */
1321
-    public static function crypto_box_publickey_from_secretkey($secretKey)
1322
-    {
1323
-        /* Type checks: */
1324
-        ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 1);
1325
-
1326
-        /* Input validation: */
1327
-        if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_BOX_SECRETKEYBYTES) {
1328
-            throw new SodiumException('Argument 1 must be CRYPTO_BOX_SECRETKEYBYTES long.');
1329
-        }
1330
-
1331
-        if (self::useNewSodiumAPI()) {
1332
-            return (string) sodium_crypto_box_publickey_from_secretkey($secretKey);
1333
-        }
1334
-        if (self::use_fallback('crypto_box_publickey_from_secretkey')) {
1335
-            return (string) call_user_func('\\Sodium\\crypto_box_publickey_from_secretkey', $secretKey);
1336
-        }
1337
-        if (PHP_INT_SIZE === 4) {
1338
-            return ParagonIE_Sodium_Crypto32::box_publickey_from_secretkey($secretKey);
1339
-        }
1340
-        return ParagonIE_Sodium_Crypto::box_publickey_from_secretkey($secretKey);
1341
-    }
1342
-
1343
-    /**
1344
-     * Extract the secret key from a crypto_box keypair.
1345
-     *
1346
-     * @param string $keypair
1347
-     * @return string         Your crypto_box secret key
1348
-     * @throws SodiumException
1349
-     * @throws TypeError
1350
-     * @psalm-suppress MixedArgument
1351
-     */
1352
-    public static function crypto_box_secretkey($keypair)
1353
-    {
1354
-        /* Type checks: */
1355
-        ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
1356
-
1357
-        /* Input validation: */
1358
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_BOX_KEYPAIRBYTES) {
1359
-            throw new SodiumException('Argument 1 must be CRYPTO_BOX_KEYPAIRBYTES long.');
1360
-        }
1361
-
1362
-        if (self::useNewSodiumAPI()) {
1363
-            return (string) sodium_crypto_box_secretkey($keypair);
1364
-        }
1365
-        if (self::use_fallback('crypto_box_secretkey')) {
1366
-            return (string) call_user_func('\\Sodium\\crypto_box_secretkey', $keypair);
1367
-        }
1368
-        if (PHP_INT_SIZE === 4) {
1369
-            return ParagonIE_Sodium_Crypto32::box_secretkey($keypair);
1370
-        }
1371
-        return ParagonIE_Sodium_Crypto::box_secretkey($keypair);
1372
-    }
1373
-
1374
-    /**
1375
-     * Generate an X25519 keypair from a seed.
1376
-     *
1377
-     * @param string $seed
1378
-     * @return string
1379
-     * @throws SodiumException
1380
-     * @throws TypeError
1381
-     * @psalm-suppress MixedArgument
1382
-     * @psalm-suppress UndefinedFunction
1383
-     */
1384
-    public static function crypto_box_seed_keypair($seed)
1385
-    {
1386
-        /* Type checks: */
1387
-        ParagonIE_Sodium_Core_Util::declareScalarType($seed, 'string', 1);
1388
-
1389
-        if (self::useNewSodiumAPI()) {
1390
-            return (string) sodium_crypto_box_seed_keypair($seed);
1391
-        }
1392
-        if (self::use_fallback('crypto_box_seed_keypair')) {
1393
-            return (string) call_user_func('\\Sodium\\crypto_box_seed_keypair', $seed);
1394
-        }
1395
-        if (PHP_INT_SIZE === 4) {
1396
-            return ParagonIE_Sodium_Crypto32::box_seed_keypair($seed);
1397
-        }
1398
-        return ParagonIE_Sodium_Crypto::box_seed_keypair($seed);
1399
-    }
1400
-
1401
-    /**
1402
-     * Calculates a BLAKE2b hash, with an optional key.
1403
-     *
1404
-     * @param string      $message The message to be hashed
1405
-     * @param string|null $key     If specified, must be a string between 16
1406
-     *                             and 64 bytes long
1407
-     * @param int         $length  Output length in bytes; must be between 16
1408
-     *                             and 64 (default = 32)
1409
-     * @return string              Raw binary
1410
-     * @throws SodiumException
1411
-     * @throws TypeError
1412
-     * @psalm-suppress MixedArgument
1413
-     */
1414
-    public static function crypto_generichash($message, $key = '', $length = self::CRYPTO_GENERICHASH_BYTES)
1415
-    {
1416
-        /* Type checks: */
1417
-        ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
1418
-        if (is_null($key)) {
1419
-            $key = '';
1420
-        }
1421
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 2);
1422
-        ParagonIE_Sodium_Core_Util::declareScalarType($length, 'int', 3);
1423
-
1424
-        /* Input validation: */
1425
-        if (!empty($key)) {
1426
-            if (ParagonIE_Sodium_Core_Util::strlen($key) < self::CRYPTO_GENERICHASH_KEYBYTES_MIN) {
1427
-                throw new SodiumException('Unsupported key size. Must be at least CRYPTO_GENERICHASH_KEYBYTES_MIN bytes long.');
1428
-            }
1429
-            if (ParagonIE_Sodium_Core_Util::strlen($key) > self::CRYPTO_GENERICHASH_KEYBYTES_MAX) {
1430
-                throw new SodiumException('Unsupported key size. Must be at most CRYPTO_GENERICHASH_KEYBYTES_MAX bytes long.');
1431
-            }
1432
-        }
1433
-
1434
-        if (self::useNewSodiumAPI()) {
1435
-            return (string) sodium_crypto_generichash($message, $key, $length);
1436
-        }
1437
-        if (self::use_fallback('crypto_generichash')) {
1438
-            return (string) call_user_func('\\Sodium\\crypto_generichash', $message, $key, $length);
1439
-        }
1440
-        if (PHP_INT_SIZE === 4) {
1441
-            return ParagonIE_Sodium_Crypto32::generichash($message, $key, $length);
1442
-        }
1443
-        return ParagonIE_Sodium_Crypto::generichash($message, $key, $length);
1444
-    }
1445
-
1446
-    /**
1447
-     * Get the final BLAKE2b hash output for a given context.
1448
-     *
1449
-     * @param string $ctx BLAKE2 hashing context. Generated by crypto_generichash_init().
1450
-     * @param int $length Hash output size.
1451
-     * @return string     Final BLAKE2b hash.
1452
-     * @throws SodiumException
1453
-     * @throws TypeError
1454
-     * @psalm-suppress MixedArgument
1455
-     * @psalm-suppress ReferenceConstraintViolation
1456
-     * @psalm-suppress ConflictingReferenceConstraint
1457
-     */
1458
-    public static function crypto_generichash_final(&$ctx, $length = self::CRYPTO_GENERICHASH_BYTES)
1459
-    {
1460
-        /* Type checks: */
1461
-        ParagonIE_Sodium_Core_Util::declareScalarType($ctx, 'string', 1);
1462
-        ParagonIE_Sodium_Core_Util::declareScalarType($length, 'int', 2);
1463
-
1464
-        if (self::useNewSodiumAPI()) {
1465
-            return sodium_crypto_generichash_final($ctx, $length);
1466
-        }
1467
-        if (self::use_fallback('crypto_generichash_final')) {
1468
-            $func = '\\Sodium\\crypto_generichash_final';
1469
-            return (string) $func($ctx, $length);
1470
-        }
1471
-        if ($length < 1) {
1472
-            try {
1473
-                self::memzero($ctx);
1474
-            } catch (SodiumException $ex) {
1475
-                unset($ctx);
1476
-            }
1477
-            return '';
1478
-        }
1479
-        if (PHP_INT_SIZE === 4) {
1480
-            $result = ParagonIE_Sodium_Crypto32::generichash_final($ctx, $length);
1481
-        } else {
1482
-            $result = ParagonIE_Sodium_Crypto::generichash_final($ctx, $length);
1483
-        }
1484
-        try {
1485
-            self::memzero($ctx);
1486
-        } catch (SodiumException $ex) {
1487
-            unset($ctx);
1488
-        }
1489
-        return $result;
1490
-    }
1491
-
1492
-    /**
1493
-     * Initialize a BLAKE2b hashing context, for use in a streaming interface.
1494
-     *
1495
-     * @param string|null $key If specified must be a string between 16 and 64 bytes
1496
-     * @param int $length      The size of the desired hash output
1497
-     * @return string          A BLAKE2 hashing context, encoded as a string
1498
-     *                         (To be 100% compatible with ext/libsodium)
1499
-     * @throws SodiumException
1500
-     * @throws TypeError
1501
-     * @psalm-suppress MixedArgument
1502
-     */
1503
-    public static function crypto_generichash_init($key = '', $length = self::CRYPTO_GENERICHASH_BYTES)
1504
-    {
1505
-        /* Type checks: */
1506
-        if (is_null($key)) {
1507
-            $key = '';
1508
-        }
1509
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 1);
1510
-        ParagonIE_Sodium_Core_Util::declareScalarType($length, 'int', 2);
1511
-
1512
-        /* Input validation: */
1513
-        if (!empty($key)) {
1514
-            if (ParagonIE_Sodium_Core_Util::strlen($key) < self::CRYPTO_GENERICHASH_KEYBYTES_MIN) {
1515
-                throw new SodiumException('Unsupported key size. Must be at least CRYPTO_GENERICHASH_KEYBYTES_MIN bytes long.');
1516
-            }
1517
-            if (ParagonIE_Sodium_Core_Util::strlen($key) > self::CRYPTO_GENERICHASH_KEYBYTES_MAX) {
1518
-                throw new SodiumException('Unsupported key size. Must be at most CRYPTO_GENERICHASH_KEYBYTES_MAX bytes long.');
1519
-            }
1520
-        }
1521
-
1522
-        if (self::useNewSodiumAPI()) {
1523
-            return sodium_crypto_generichash_init($key, $length);
1524
-        }
1525
-        if (self::use_fallback('crypto_generichash_init')) {
1526
-            return (string) call_user_func('\\Sodium\\crypto_generichash_init', $key, $length);
1527
-        }
1528
-        if (PHP_INT_SIZE === 4) {
1529
-            return ParagonIE_Sodium_Crypto32::generichash_init($key, $length);
1530
-        }
1531
-        return ParagonIE_Sodium_Crypto::generichash_init($key, $length);
1532
-    }
1533
-
1534
-    /**
1535
-     * Initialize a BLAKE2b hashing context, for use in a streaming interface.
1536
-     *
1537
-     * @param string|null $key If specified must be a string between 16 and 64 bytes
1538
-     * @param int $length      The size of the desired hash output
1539
-     * @param string $salt     Salt (up to 16 bytes)
1540
-     * @param string $personal Personalization string (up to 16 bytes)
1541
-     * @return string          A BLAKE2 hashing context, encoded as a string
1542
-     *                         (To be 100% compatible with ext/libsodium)
1543
-     * @throws SodiumException
1544
-     * @throws TypeError
1545
-     * @psalm-suppress MixedArgument
1546
-     */
1547
-    public static function crypto_generichash_init_salt_personal(
1548
-        $key = '',
1549
-        $length = self::CRYPTO_GENERICHASH_BYTES,
1550
-        $salt = '',
1551
-        $personal = ''
1552
-    ) {
1553
-        /* Type checks: */
1554
-        if (is_null($key)) {
1555
-            $key = '';
1556
-        }
1557
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 1);
1558
-        ParagonIE_Sodium_Core_Util::declareScalarType($length, 'int', 2);
1559
-        ParagonIE_Sodium_Core_Util::declareScalarType($salt, 'string', 3);
1560
-        ParagonIE_Sodium_Core_Util::declareScalarType($personal, 'string', 4);
1561
-        $salt = str_pad($salt, 16, "\0", STR_PAD_RIGHT);
1562
-        $personal = str_pad($personal, 16, "\0", STR_PAD_RIGHT);
1563
-
1564
-        /* Input validation: */
1565
-        if (!empty($key)) {
1566
-            /*
30
+	/**
31
+	 * This parameter prevents the use of the PECL extension.
32
+	 * It should only be used for unit testing.
33
+	 *
34
+	 * @var bool
35
+	 */
36
+	public static $disableFallbackForUnitTests = false;
37
+
38
+	/**
39
+	 * Use fast multiplication rather than our constant-time multiplication
40
+	 * implementation. Can be enabled at runtime. Only enable this if you
41
+	 * are absolutely certain that there is no timing leak on your platform.
42
+	 *
43
+	 * @var bool
44
+	 */
45
+	public static $fastMult = false;
46
+
47
+	const LIBRARY_MAJOR_VERSION = 9;
48
+	const LIBRARY_MINOR_VERSION = 1;
49
+	const LIBRARY_VERSION_MAJOR = 9;
50
+	const LIBRARY_VERSION_MINOR = 1;
51
+	const VERSION_STRING = 'polyfill-1.0.8';
52
+
53
+	// From libsodium
54
+	const BASE64_VARIANT_ORIGINAL = 1;
55
+	const BASE64_VARIANT_ORIGINAL_NO_PADDING = 3;
56
+	const BASE64_VARIANT_URLSAFE = 5;
57
+	const BASE64_VARIANT_URLSAFE_NO_PADDING = 7;
58
+	const CRYPTO_AEAD_AES256GCM_KEYBYTES = 32;
59
+	const CRYPTO_AEAD_AES256GCM_NSECBYTES = 0;
60
+	const CRYPTO_AEAD_AES256GCM_NPUBBYTES = 12;
61
+	const CRYPTO_AEAD_AES256GCM_ABYTES = 16;
62
+	const CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES = 32;
63
+	const CRYPTO_AEAD_CHACHA20POLY1305_NSECBYTES = 0;
64
+	const CRYPTO_AEAD_CHACHA20POLY1305_NPUBBYTES = 8;
65
+	const CRYPTO_AEAD_CHACHA20POLY1305_ABYTES = 16;
66
+	const CRYPTO_AEAD_CHACHA20POLY1305_IETF_KEYBYTES = 32;
67
+	const CRYPTO_AEAD_CHACHA20POLY1305_IETF_NSECBYTES = 0;
68
+	const CRYPTO_AEAD_CHACHA20POLY1305_IETF_NPUBBYTES = 12;
69
+	const CRYPTO_AEAD_CHACHA20POLY1305_IETF_ABYTES = 16;
70
+	const CRYPTO_AEAD_XCHACHA20POLY1305_IETF_KEYBYTES = 32;
71
+	const CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NSECBYTES = 0;
72
+	const CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NPUBBYTES = 24;
73
+	const CRYPTO_AEAD_XCHACHA20POLY1305_IETF_ABYTES = 16;
74
+	const CRYPTO_AUTH_BYTES = 32;
75
+	const CRYPTO_AUTH_KEYBYTES = 32;
76
+	const CRYPTO_BOX_SEALBYTES = 16;
77
+	const CRYPTO_BOX_SECRETKEYBYTES = 32;
78
+	const CRYPTO_BOX_PUBLICKEYBYTES = 32;
79
+	const CRYPTO_BOX_KEYPAIRBYTES = 64;
80
+	const CRYPTO_BOX_MACBYTES = 16;
81
+	const CRYPTO_BOX_NONCEBYTES = 24;
82
+	const CRYPTO_BOX_SEEDBYTES = 32;
83
+	const CRYPTO_CORE_RISTRETTO255_BYTES = 32;
84
+	const CRYPTO_CORE_RISTRETTO255_SCALARBYTES = 32;
85
+	const CRYPTO_CORE_RISTRETTO255_HASHBYTES = 64;
86
+	const CRYPTO_CORE_RISTRETTO255_NONREDUCEDSCALARBYTES = 64;
87
+	const CRYPTO_KDF_BYTES_MIN = 16;
88
+	const CRYPTO_KDF_BYTES_MAX = 64;
89
+	const CRYPTO_KDF_CONTEXTBYTES = 8;
90
+	const CRYPTO_KDF_KEYBYTES = 32;
91
+	const CRYPTO_KX_BYTES = 32;
92
+	const CRYPTO_KX_PRIMITIVE = 'x25519blake2b';
93
+	const CRYPTO_KX_SEEDBYTES = 32;
94
+	const CRYPTO_KX_KEYPAIRBYTES = 64;
95
+	const CRYPTO_KX_PUBLICKEYBYTES = 32;
96
+	const CRYPTO_KX_SECRETKEYBYTES = 32;
97
+	const CRYPTO_KX_SESSIONKEYBYTES = 32;
98
+	const CRYPTO_GENERICHASH_BYTES = 32;
99
+	const CRYPTO_GENERICHASH_BYTES_MIN = 16;
100
+	const CRYPTO_GENERICHASH_BYTES_MAX = 64;
101
+	const CRYPTO_GENERICHASH_KEYBYTES = 32;
102
+	const CRYPTO_GENERICHASH_KEYBYTES_MIN = 16;
103
+	const CRYPTO_GENERICHASH_KEYBYTES_MAX = 64;
104
+	const CRYPTO_PWHASH_SALTBYTES = 16;
105
+	const CRYPTO_PWHASH_STRPREFIX = '$argon2id$';
106
+	const CRYPTO_PWHASH_ALG_ARGON2I13 = 1;
107
+	const CRYPTO_PWHASH_ALG_ARGON2ID13 = 2;
108
+	const CRYPTO_PWHASH_MEMLIMIT_INTERACTIVE = 33554432;
109
+	const CRYPTO_PWHASH_OPSLIMIT_INTERACTIVE = 4;
110
+	const CRYPTO_PWHASH_MEMLIMIT_MODERATE = 134217728;
111
+	const CRYPTO_PWHASH_OPSLIMIT_MODERATE = 6;
112
+	const CRYPTO_PWHASH_MEMLIMIT_SENSITIVE = 536870912;
113
+	const CRYPTO_PWHASH_OPSLIMIT_SENSITIVE = 8;
114
+	const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_SALTBYTES = 32;
115
+	const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_STRPREFIX = '$7$';
116
+	const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_OPSLIMIT_INTERACTIVE = 534288;
117
+	const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_MEMLIMIT_INTERACTIVE = 16777216;
118
+	const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_OPSLIMIT_SENSITIVE = 33554432;
119
+	const CRYPTO_PWHASH_SCRYPTSALSA208SHA256_MEMLIMIT_SENSITIVE = 1073741824;
120
+	const CRYPTO_SCALARMULT_BYTES = 32;
121
+	const CRYPTO_SCALARMULT_SCALARBYTES = 32;
122
+	const CRYPTO_SCALARMULT_RISTRETTO255_BYTES = 32;
123
+	const CRYPTO_SCALARMULT_RISTRETTO255_SCALARBYTES = 32;
124
+	const CRYPTO_SHORTHASH_BYTES = 8;
125
+	const CRYPTO_SHORTHASH_KEYBYTES = 16;
126
+	const CRYPTO_SECRETBOX_KEYBYTES = 32;
127
+	const CRYPTO_SECRETBOX_MACBYTES = 16;
128
+	const CRYPTO_SECRETBOX_NONCEBYTES = 24;
129
+	const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_ABYTES = 17;
130
+	const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_HEADERBYTES = 24;
131
+	const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_KEYBYTES = 32;
132
+	const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_PUSH = 0;
133
+	const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_PULL = 1;
134
+	const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY = 2;
135
+	const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_FINAL = 3;
136
+	const CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX = 0x3fffffff80;
137
+	const CRYPTO_SIGN_BYTES = 64;
138
+	const CRYPTO_SIGN_SEEDBYTES = 32;
139
+	const CRYPTO_SIGN_PUBLICKEYBYTES = 32;
140
+	const CRYPTO_SIGN_SECRETKEYBYTES = 64;
141
+	const CRYPTO_SIGN_KEYPAIRBYTES = 96;
142
+	const CRYPTO_STREAM_KEYBYTES = 32;
143
+	const CRYPTO_STREAM_NONCEBYTES = 24;
144
+	const CRYPTO_STREAM_XCHACHA20_KEYBYTES = 32;
145
+	const CRYPTO_STREAM_XCHACHA20_NONCEBYTES = 24;
146
+
147
+	/**
148
+	 * Add two numbers (little-endian unsigned), storing the value in the first
149
+	 * parameter.
150
+	 *
151
+	 * This mutates $val.
152
+	 *
153
+	 * @param string $val
154
+	 * @param string $addv
155
+	 * @return void
156
+	 * @throws SodiumException
157
+	 */
158
+	public static function add(&$val, $addv)
159
+	{
160
+		$val_len = ParagonIE_Sodium_Core_Util::strlen($val);
161
+		$addv_len = ParagonIE_Sodium_Core_Util::strlen($addv);
162
+		if ($val_len !== $addv_len) {
163
+			throw new SodiumException('values must have the same length');
164
+		}
165
+		$A = ParagonIE_Sodium_Core_Util::stringToIntArray($val);
166
+		$B = ParagonIE_Sodium_Core_Util::stringToIntArray($addv);
167
+
168
+		$c = 0;
169
+		for ($i = 0; $i < $val_len; $i++) {
170
+			$c += ($A[$i] + $B[$i]);
171
+			$A[$i] = ($c & 0xff);
172
+			$c >>= 8;
173
+		}
174
+		$val = ParagonIE_Sodium_Core_Util::intArrayToString($A);
175
+	}
176
+
177
+	/**
178
+	 * @param string $encoded
179
+	 * @param int $variant
180
+	 * @param string $ignore
181
+	 * @return string
182
+	 * @throws SodiumException
183
+	 */
184
+	public static function base642bin($encoded, $variant, $ignore = '')
185
+	{
186
+		/* Type checks: */
187
+		ParagonIE_Sodium_Core_Util::declareScalarType($encoded, 'string', 1);
188
+
189
+		/** @var string $encoded */
190
+		$encoded = (string) $encoded;
191
+		if (ParagonIE_Sodium_Core_Util::strlen($encoded) === 0) {
192
+			return '';
193
+		}
194
+
195
+		// Just strip before decoding
196
+		if (!empty($ignore)) {
197
+			$encoded = str_replace($ignore, '', $encoded);
198
+		}
199
+
200
+		try {
201
+			switch ($variant) {
202
+				case self::BASE64_VARIANT_ORIGINAL:
203
+					return ParagonIE_Sodium_Core_Base64_Original::decode($encoded, true);
204
+				case self::BASE64_VARIANT_ORIGINAL_NO_PADDING:
205
+					return ParagonIE_Sodium_Core_Base64_Original::decode($encoded, false);
206
+				case self::BASE64_VARIANT_URLSAFE:
207
+					return ParagonIE_Sodium_Core_Base64_UrlSafe::decode($encoded, true);
208
+				case self::BASE64_VARIANT_URLSAFE_NO_PADDING:
209
+					return ParagonIE_Sodium_Core_Base64_UrlSafe::decode($encoded, false);
210
+				default:
211
+					throw new SodiumException('invalid base64 variant identifier');
212
+			}
213
+		} catch (Exception $ex) {
214
+			if ($ex instanceof SodiumException) {
215
+				throw $ex;
216
+			}
217
+			throw new SodiumException('invalid base64 string');
218
+		}
219
+	}
220
+
221
+	/**
222
+	 * @param string $decoded
223
+	 * @param int $variant
224
+	 * @return string
225
+	 * @throws SodiumException
226
+	 */
227
+	public static function bin2base64($decoded, $variant)
228
+	{
229
+		/* Type checks: */
230
+		ParagonIE_Sodium_Core_Util::declareScalarType($decoded, 'string', 1);
231
+		/** @var string $decoded */
232
+		$decoded = (string) $decoded;
233
+		if (ParagonIE_Sodium_Core_Util::strlen($decoded) === 0) {
234
+			return '';
235
+		}
236
+
237
+		switch ($variant) {
238
+			case self::BASE64_VARIANT_ORIGINAL:
239
+				return ParagonIE_Sodium_Core_Base64_Original::encode($decoded);
240
+			case self::BASE64_VARIANT_ORIGINAL_NO_PADDING:
241
+				return ParagonIE_Sodium_Core_Base64_Original::encodeUnpadded($decoded);
242
+			case self::BASE64_VARIANT_URLSAFE:
243
+				return ParagonIE_Sodium_Core_Base64_UrlSafe::encode($decoded);
244
+			case self::BASE64_VARIANT_URLSAFE_NO_PADDING:
245
+				return ParagonIE_Sodium_Core_Base64_UrlSafe::encodeUnpadded($decoded);
246
+			default:
247
+				throw new SodiumException('invalid base64 variant identifier');
248
+		}
249
+	}
250
+
251
+	/**
252
+	 * Cache-timing-safe implementation of bin2hex().
253
+	 *
254
+	 * @param string $string A string (probably raw binary)
255
+	 * @return string        A hexadecimal-encoded string
256
+	 * @throws SodiumException
257
+	 * @throws TypeError
258
+	 * @psalm-suppress MixedArgument
259
+	 */
260
+	public static function bin2hex($string)
261
+	{
262
+		/* Type checks: */
263
+		ParagonIE_Sodium_Core_Util::declareScalarType($string, 'string', 1);
264
+
265
+		if (self::useNewSodiumAPI()) {
266
+			return (string) sodium_bin2hex($string);
267
+		}
268
+		if (self::use_fallback('bin2hex')) {
269
+			return (string) call_user_func('\\Sodium\\bin2hex', $string);
270
+		}
271
+		return ParagonIE_Sodium_Core_Util::bin2hex($string);
272
+	}
273
+
274
+	/**
275
+	 * Compare two strings, in constant-time.
276
+	 * Compared to memcmp(), compare() is more useful for sorting.
277
+	 *
278
+	 * @param string $left  The left operand; must be a string
279
+	 * @param string $right The right operand; must be a string
280
+	 * @return int          If < 0 if the left operand is less than the right
281
+	 *                      If = 0 if both strings are equal
282
+	 *                      If > 0 if the right operand is less than the left
283
+	 * @throws SodiumException
284
+	 * @throws TypeError
285
+	 * @psalm-suppress MixedArgument
286
+	 */
287
+	public static function compare($left, $right)
288
+	{
289
+		/* Type checks: */
290
+		ParagonIE_Sodium_Core_Util::declareScalarType($left, 'string', 1);
291
+		ParagonIE_Sodium_Core_Util::declareScalarType($right, 'string', 2);
292
+
293
+		if (self::useNewSodiumAPI()) {
294
+			return (int) sodium_compare($left, $right);
295
+		}
296
+		if (self::use_fallback('compare')) {
297
+			return (int) call_user_func('\\Sodium\\compare', $left, $right);
298
+		}
299
+		return ParagonIE_Sodium_Core_Util::compare($left, $right);
300
+	}
301
+
302
+	/**
303
+	 * Is AES-256-GCM even available to use?
304
+	 *
305
+	 * @return bool
306
+	 * @psalm-suppress UndefinedFunction
307
+	 * @psalm-suppress MixedInferredReturnType
308
+	 * @psalm-suppress MixedReturnStatement
309
+	 */
310
+	public static function crypto_aead_aes256gcm_is_available()
311
+	{
312
+		if (self::useNewSodiumAPI()) {
313
+			return sodium_crypto_aead_aes256gcm_is_available();
314
+		}
315
+		if (self::use_fallback('crypto_aead_aes256gcm_is_available')) {
316
+			return call_user_func('\\Sodium\\crypto_aead_aes256gcm_is_available');
317
+		}
318
+		if (PHP_VERSION_ID < 70100) {
319
+			// OpenSSL doesn't support AEAD before 7.1.0
320
+			return false;
321
+		}
322
+		if (!is_callable('openssl_encrypt') || !is_callable('openssl_decrypt')) {
323
+			// OpenSSL isn't installed
324
+			return false;
325
+		}
326
+		return (bool) in_array('aes-256-gcm', openssl_get_cipher_methods());
327
+	}
328
+
329
+	/**
330
+	 * Authenticated Encryption with Associated Data: Decryption
331
+	 *
332
+	 * Algorithm:
333
+	 *     AES-256-GCM
334
+	 *
335
+	 * This mode uses a 64-bit random nonce with a 64-bit counter.
336
+	 * IETF mode uses a 96-bit random nonce with a 32-bit counter.
337
+	 *
338
+	 * @param string $ciphertext Encrypted message (with Poly1305 MAC appended)
339
+	 * @param string $assocData  Authenticated Associated Data (unencrypted)
340
+	 * @param string $nonce      Number to be used only Once; must be 8 bytes
341
+	 * @param string $key        Encryption key
342
+	 *
343
+	 * @return string|bool       The original plaintext message
344
+	 * @throws SodiumException
345
+	 * @throws TypeError
346
+	 * @psalm-suppress MixedArgument
347
+	 * @psalm-suppress MixedInferredReturnType
348
+	 * @psalm-suppress MixedReturnStatement
349
+	 */
350
+	public static function crypto_aead_aes256gcm_decrypt(
351
+		$ciphertext = '',
352
+		$assocData = '',
353
+		$nonce = '',
354
+		$key = ''
355
+	) {
356
+		if (!self::crypto_aead_aes256gcm_is_available()) {
357
+			throw new SodiumException('AES-256-GCM is not available');
358
+		}
359
+		ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
360
+		ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
361
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
362
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
363
+
364
+		/* Input validation: */
365
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_AES256GCM_NPUBBYTES) {
366
+			throw new SodiumException('Nonce must be CRYPTO_AEAD_AES256GCM_NPUBBYTES long');
367
+		}
368
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_AES256GCM_KEYBYTES) {
369
+			throw new SodiumException('Key must be CRYPTO_AEAD_AES256GCM_KEYBYTES long');
370
+		}
371
+		if (ParagonIE_Sodium_Core_Util::strlen($ciphertext) < self::CRYPTO_AEAD_AES256GCM_ABYTES) {
372
+			throw new SodiumException('Message must be at least CRYPTO_AEAD_AES256GCM_ABYTES long');
373
+		}
374
+		if (!is_callable('openssl_decrypt')) {
375
+			throw new SodiumException('The OpenSSL extension is not installed, or openssl_decrypt() is not available');
376
+		}
377
+
378
+		/** @var string $ctext */
379
+		$ctext = ParagonIE_Sodium_Core_Util::substr($ciphertext, 0, -self::CRYPTO_AEAD_AES256GCM_ABYTES);
380
+		/** @var string $authTag */
381
+		$authTag = ParagonIE_Sodium_Core_Util::substr($ciphertext, -self::CRYPTO_AEAD_AES256GCM_ABYTES, 16);
382
+		return openssl_decrypt(
383
+			$ctext,
384
+			'aes-256-gcm',
385
+			$key,
386
+			OPENSSL_RAW_DATA,
387
+			$nonce,
388
+			$authTag,
389
+			$assocData
390
+		);
391
+	}
392
+
393
+	/**
394
+	 * Authenticated Encryption with Associated Data: Encryption
395
+	 *
396
+	 * Algorithm:
397
+	 *     AES-256-GCM
398
+	 *
399
+	 * @param string $plaintext Message to be encrypted
400
+	 * @param string $assocData Authenticated Associated Data (unencrypted)
401
+	 * @param string $nonce     Number to be used only Once; must be 8 bytes
402
+	 * @param string $key       Encryption key
403
+	 *
404
+	 * @return string           Ciphertext with a 16-byte GCM message
405
+	 *                          authentication code appended
406
+	 * @throws SodiumException
407
+	 * @throws TypeError
408
+	 * @psalm-suppress MixedArgument
409
+	 */
410
+	public static function crypto_aead_aes256gcm_encrypt(
411
+		$plaintext = '',
412
+		$assocData = '',
413
+		$nonce = '',
414
+		$key = ''
415
+	) {
416
+		if (!self::crypto_aead_aes256gcm_is_available()) {
417
+			throw new SodiumException('AES-256-GCM is not available');
418
+		}
419
+		ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
420
+		ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
421
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
422
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
423
+
424
+		/* Input validation: */
425
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_AES256GCM_NPUBBYTES) {
426
+			throw new SodiumException('Nonce must be CRYPTO_AEAD_AES256GCM_NPUBBYTES long');
427
+		}
428
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_AES256GCM_KEYBYTES) {
429
+			throw new SodiumException('Key must be CRYPTO_AEAD_AES256GCM_KEYBYTES long');
430
+		}
431
+
432
+		if (!is_callable('openssl_encrypt')) {
433
+			throw new SodiumException('The OpenSSL extension is not installed, or openssl_encrypt() is not available');
434
+		}
435
+
436
+		$authTag = '';
437
+		$ciphertext = openssl_encrypt(
438
+			$plaintext,
439
+			'aes-256-gcm',
440
+			$key,
441
+			OPENSSL_RAW_DATA,
442
+			$nonce,
443
+			$authTag,
444
+			$assocData
445
+		);
446
+		return $ciphertext . $authTag;
447
+	}
448
+
449
+	/**
450
+	 * Return a secure random key for use with the AES-256-GCM
451
+	 * symmetric AEAD interface.
452
+	 *
453
+	 * @return string
454
+	 * @throws Exception
455
+	 * @throws Error
456
+	 */
457
+	public static function crypto_aead_aes256gcm_keygen()
458
+	{
459
+		return random_bytes(self::CRYPTO_AEAD_AES256GCM_KEYBYTES);
460
+	}
461
+
462
+	/**
463
+	 * Authenticated Encryption with Associated Data: Decryption
464
+	 *
465
+	 * Algorithm:
466
+	 *     ChaCha20-Poly1305
467
+	 *
468
+	 * This mode uses a 64-bit random nonce with a 64-bit counter.
469
+	 * IETF mode uses a 96-bit random nonce with a 32-bit counter.
470
+	 *
471
+	 * @param string $ciphertext Encrypted message (with Poly1305 MAC appended)
472
+	 * @param string $assocData  Authenticated Associated Data (unencrypted)
473
+	 * @param string $nonce      Number to be used only Once; must be 8 bytes
474
+	 * @param string $key        Encryption key
475
+	 *
476
+	 * @return string            The original plaintext message
477
+	 * @throws SodiumException
478
+	 * @throws TypeError
479
+	 * @psalm-suppress MixedArgument
480
+	 * @psalm-suppress MixedInferredReturnType
481
+	 * @psalm-suppress MixedReturnStatement
482
+	 */
483
+	public static function crypto_aead_chacha20poly1305_decrypt(
484
+		$ciphertext = '',
485
+		$assocData = '',
486
+		$nonce = '',
487
+		$key = ''
488
+	) {
489
+		/* Type checks: */
490
+		ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
491
+		ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
492
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
493
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
494
+
495
+		/* Input validation: */
496
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_CHACHA20POLY1305_NPUBBYTES) {
497
+			throw new SodiumException('Nonce must be CRYPTO_AEAD_CHACHA20POLY1305_NPUBBYTES long');
498
+		}
499
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES) {
500
+			throw new SodiumException('Key must be CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES long');
501
+		}
502
+		if (ParagonIE_Sodium_Core_Util::strlen($ciphertext) < self::CRYPTO_AEAD_CHACHA20POLY1305_ABYTES) {
503
+			throw new SodiumException('Message must be at least CRYPTO_AEAD_CHACHA20POLY1305_ABYTES long');
504
+		}
505
+
506
+		if (self::useNewSodiumAPI()) {
507
+			/**
508
+			 * @psalm-suppress InvalidReturnStatement
509
+			 * @psalm-suppress FalsableReturnStatement
510
+			 */
511
+			return sodium_crypto_aead_chacha20poly1305_decrypt(
512
+				$ciphertext,
513
+				$assocData,
514
+				$nonce,
515
+				$key
516
+			);
517
+		}
518
+		if (self::use_fallback('crypto_aead_chacha20poly1305_decrypt')) {
519
+			return call_user_func(
520
+				'\\Sodium\\crypto_aead_chacha20poly1305_decrypt',
521
+				$ciphertext,
522
+				$assocData,
523
+				$nonce,
524
+				$key
525
+			);
526
+		}
527
+		if (PHP_INT_SIZE === 4) {
528
+			return ParagonIE_Sodium_Crypto32::aead_chacha20poly1305_decrypt(
529
+				$ciphertext,
530
+				$assocData,
531
+				$nonce,
532
+				$key
533
+			);
534
+		}
535
+		return ParagonIE_Sodium_Crypto::aead_chacha20poly1305_decrypt(
536
+			$ciphertext,
537
+			$assocData,
538
+			$nonce,
539
+			$key
540
+		);
541
+	}
542
+
543
+	/**
544
+	 * Authenticated Encryption with Associated Data
545
+	 *
546
+	 * Algorithm:
547
+	 *     ChaCha20-Poly1305
548
+	 *
549
+	 * This mode uses a 64-bit random nonce with a 64-bit counter.
550
+	 * IETF mode uses a 96-bit random nonce with a 32-bit counter.
551
+	 *
552
+	 * @param string $plaintext Message to be encrypted
553
+	 * @param string $assocData Authenticated Associated Data (unencrypted)
554
+	 * @param string $nonce     Number to be used only Once; must be 8 bytes
555
+	 * @param string $key       Encryption key
556
+	 *
557
+	 * @return string           Ciphertext with a 16-byte Poly1305 message
558
+	 *                          authentication code appended
559
+	 * @throws SodiumException
560
+	 * @throws TypeError
561
+	 * @psalm-suppress MixedArgument
562
+	 */
563
+	public static function crypto_aead_chacha20poly1305_encrypt(
564
+		$plaintext = '',
565
+		$assocData = '',
566
+		$nonce = '',
567
+		$key = ''
568
+	) {
569
+		/* Type checks: */
570
+		ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
571
+		ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
572
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
573
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
574
+
575
+		/* Input validation: */
576
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_CHACHA20POLY1305_NPUBBYTES) {
577
+			throw new SodiumException('Nonce must be CRYPTO_AEAD_CHACHA20POLY1305_NPUBBYTES long');
578
+		}
579
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES) {
580
+			throw new SodiumException('Key must be CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES long');
581
+		}
582
+
583
+		if (self::useNewSodiumAPI()) {
584
+			return (string) sodium_crypto_aead_chacha20poly1305_encrypt(
585
+				$plaintext,
586
+				$assocData,
587
+				$nonce,
588
+				$key
589
+			);
590
+		}
591
+		if (self::use_fallback('crypto_aead_chacha20poly1305_encrypt')) {
592
+			return (string) call_user_func(
593
+				'\\Sodium\\crypto_aead_chacha20poly1305_encrypt',
594
+				$plaintext,
595
+				$assocData,
596
+				$nonce,
597
+				$key
598
+			);
599
+		}
600
+		if (PHP_INT_SIZE === 4) {
601
+			return ParagonIE_Sodium_Crypto32::aead_chacha20poly1305_encrypt(
602
+				$plaintext,
603
+				$assocData,
604
+				$nonce,
605
+				$key
606
+			);
607
+		}
608
+		return ParagonIE_Sodium_Crypto::aead_chacha20poly1305_encrypt(
609
+			$plaintext,
610
+			$assocData,
611
+			$nonce,
612
+			$key
613
+		);
614
+	}
615
+
616
+	/**
617
+	 * Authenticated Encryption with Associated Data: Decryption
618
+	 *
619
+	 * Algorithm:
620
+	 *     ChaCha20-Poly1305
621
+	 *
622
+	 * IETF mode uses a 96-bit random nonce with a 32-bit counter.
623
+	 * Regular mode uses a 64-bit random nonce with a 64-bit counter.
624
+	 *
625
+	 * @param string $ciphertext Encrypted message (with Poly1305 MAC appended)
626
+	 * @param string $assocData  Authenticated Associated Data (unencrypted)
627
+	 * @param string $nonce      Number to be used only Once; must be 12 bytes
628
+	 * @param string $key        Encryption key
629
+	 *
630
+	 * @return string            The original plaintext message
631
+	 * @throws SodiumException
632
+	 * @throws TypeError
633
+	 * @psalm-suppress MixedArgument
634
+	 * @psalm-suppress MixedInferredReturnType
635
+	 * @psalm-suppress MixedReturnStatement
636
+	 */
637
+	public static function crypto_aead_chacha20poly1305_ietf_decrypt(
638
+		$ciphertext = '',
639
+		$assocData = '',
640
+		$nonce = '',
641
+		$key = ''
642
+	) {
643
+		/* Type checks: */
644
+		ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
645
+		ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
646
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
647
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
648
+
649
+		/* Input validation: */
650
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_CHACHA20POLY1305_IETF_NPUBBYTES) {
651
+			throw new SodiumException('Nonce must be CRYPTO_AEAD_CHACHA20POLY1305_IETF_NPUBBYTES long');
652
+		}
653
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES) {
654
+			throw new SodiumException('Key must be CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES long');
655
+		}
656
+		if (ParagonIE_Sodium_Core_Util::strlen($ciphertext) < self::CRYPTO_AEAD_CHACHA20POLY1305_ABYTES) {
657
+			throw new SodiumException('Message must be at least CRYPTO_AEAD_CHACHA20POLY1305_ABYTES long');
658
+		}
659
+
660
+		if (self::useNewSodiumAPI()) {
661
+			/**
662
+			 * @psalm-suppress InvalidReturnStatement
663
+			 * @psalm-suppress FalsableReturnStatement
664
+			 */
665
+			return sodium_crypto_aead_chacha20poly1305_ietf_decrypt(
666
+				$ciphertext,
667
+				$assocData,
668
+				$nonce,
669
+				$key
670
+			);
671
+		}
672
+		if (self::use_fallback('crypto_aead_chacha20poly1305_ietf_decrypt')) {
673
+			return call_user_func(
674
+				'\\Sodium\\crypto_aead_chacha20poly1305_ietf_decrypt',
675
+				$ciphertext,
676
+				$assocData,
677
+				$nonce,
678
+				$key
679
+			);
680
+		}
681
+		if (PHP_INT_SIZE === 4) {
682
+			return ParagonIE_Sodium_Crypto32::aead_chacha20poly1305_ietf_decrypt(
683
+				$ciphertext,
684
+				$assocData,
685
+				$nonce,
686
+				$key
687
+			);
688
+		}
689
+		return ParagonIE_Sodium_Crypto::aead_chacha20poly1305_ietf_decrypt(
690
+			$ciphertext,
691
+			$assocData,
692
+			$nonce,
693
+			$key
694
+		);
695
+	}
696
+
697
+	/**
698
+	 * Return a secure random key for use with the ChaCha20-Poly1305
699
+	 * symmetric AEAD interface.
700
+	 *
701
+	 * @return string
702
+	 * @throws Exception
703
+	 * @throws Error
704
+	 */
705
+	public static function crypto_aead_chacha20poly1305_keygen()
706
+	{
707
+		return random_bytes(self::CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES);
708
+	}
709
+
710
+	/**
711
+	 * Authenticated Encryption with Associated Data
712
+	 *
713
+	 * Algorithm:
714
+	 *     ChaCha20-Poly1305
715
+	 *
716
+	 * IETF mode uses a 96-bit random nonce with a 32-bit counter.
717
+	 * Regular mode uses a 64-bit random nonce with a 64-bit counter.
718
+	 *
719
+	 * @param string $plaintext Message to be encrypted
720
+	 * @param string $assocData Authenticated Associated Data (unencrypted)
721
+	 * @param string $nonce Number to be used only Once; must be 8 bytes
722
+	 * @param string $key Encryption key
723
+	 *
724
+	 * @return string           Ciphertext with a 16-byte Poly1305 message
725
+	 *                          authentication code appended
726
+	 * @throws SodiumException
727
+	 * @throws TypeError
728
+	 * @psalm-suppress MixedArgument
729
+	 */
730
+	public static function crypto_aead_chacha20poly1305_ietf_encrypt(
731
+		$plaintext = '',
732
+		$assocData = '',
733
+		$nonce = '',
734
+		$key = ''
735
+	) {
736
+		/* Type checks: */
737
+		ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
738
+		if (!is_null($assocData)) {
739
+			ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
740
+		}
741
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
742
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
743
+
744
+		/* Input validation: */
745
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_CHACHA20POLY1305_IETF_NPUBBYTES) {
746
+			throw new SodiumException('Nonce must be CRYPTO_AEAD_CHACHA20POLY1305_IETF_NPUBBYTES long');
747
+		}
748
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES) {
749
+			throw new SodiumException('Key must be CRYPTO_AEAD_CHACHA20POLY1305_KEYBYTES long');
750
+		}
751
+
752
+		if (self::useNewSodiumAPI()) {
753
+			return (string) sodium_crypto_aead_chacha20poly1305_ietf_encrypt(
754
+				$plaintext,
755
+				$assocData,
756
+				$nonce,
757
+				$key
758
+			);
759
+		}
760
+		if (self::use_fallback('crypto_aead_chacha20poly1305_ietf_encrypt')) {
761
+			return (string) call_user_func(
762
+				'\\Sodium\\crypto_aead_chacha20poly1305_ietf_encrypt',
763
+				$plaintext,
764
+				$assocData,
765
+				$nonce,
766
+				$key
767
+			);
768
+		}
769
+		if (PHP_INT_SIZE === 4) {
770
+			return ParagonIE_Sodium_Crypto32::aead_chacha20poly1305_ietf_encrypt(
771
+				$plaintext,
772
+				$assocData,
773
+				$nonce,
774
+				$key
775
+			);
776
+		}
777
+		return ParagonIE_Sodium_Crypto::aead_chacha20poly1305_ietf_encrypt(
778
+			$plaintext,
779
+			$assocData,
780
+			$nonce,
781
+			$key
782
+		);
783
+	}
784
+
785
+	/**
786
+	 * Return a secure random key for use with the ChaCha20-Poly1305
787
+	 * symmetric AEAD interface. (IETF version)
788
+	 *
789
+	 * @return string
790
+	 * @throws Exception
791
+	 * @throws Error
792
+	 */
793
+	public static function crypto_aead_chacha20poly1305_ietf_keygen()
794
+	{
795
+		return random_bytes(self::CRYPTO_AEAD_CHACHA20POLY1305_IETF_KEYBYTES);
796
+	}
797
+
798
+	/**
799
+	 * Authenticated Encryption with Associated Data: Decryption
800
+	 *
801
+	 * Algorithm:
802
+	 *     XChaCha20-Poly1305
803
+	 *
804
+	 * This mode uses a 64-bit random nonce with a 64-bit counter.
805
+	 * IETF mode uses a 96-bit random nonce with a 32-bit counter.
806
+	 *
807
+	 * @param string $ciphertext   Encrypted message (with Poly1305 MAC appended)
808
+	 * @param string $assocData    Authenticated Associated Data (unencrypted)
809
+	 * @param string $nonce        Number to be used only Once; must be 8 bytes
810
+	 * @param string $key          Encryption key
811
+	 * @param bool   $dontFallback Don't fallback to ext/sodium
812
+	 *
813
+	 * @return string|bool         The original plaintext message
814
+	 * @throws SodiumException
815
+	 * @throws TypeError
816
+	 * @psalm-suppress MixedArgument
817
+	 */
818
+	public static function crypto_aead_xchacha20poly1305_ietf_decrypt(
819
+		$ciphertext = '',
820
+		$assocData = '',
821
+		$nonce = '',
822
+		$key = '',
823
+		$dontFallback = false
824
+	) {
825
+		/* Type checks: */
826
+		ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
827
+		if (!is_null($assocData)) {
828
+			ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
829
+		} else {
830
+			$assocData = '';
831
+		}
832
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
833
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
834
+
835
+		/* Input validation: */
836
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NPUBBYTES) {
837
+			throw new SodiumException('Nonce must be CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NPUBBYTES long');
838
+		}
839
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_KEYBYTES) {
840
+			throw new SodiumException('Key must be CRYPTO_AEAD_XCHACHA20POLY1305_IETF_KEYBYTES long');
841
+		}
842
+		if (ParagonIE_Sodium_Core_Util::strlen($ciphertext) < self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_ABYTES) {
843
+			throw new SodiumException('Message must be at least CRYPTO_AEAD_XCHACHA20POLY1305_IETF_ABYTES long');
844
+		}
845
+		if (self::useNewSodiumAPI() && !$dontFallback) {
846
+			if (is_callable('sodium_crypto_aead_xchacha20poly1305_ietf_decrypt')) {
847
+				return sodium_crypto_aead_xchacha20poly1305_ietf_decrypt(
848
+					$ciphertext,
849
+					$assocData,
850
+					$nonce,
851
+					$key
852
+				);
853
+			}
854
+		}
855
+
856
+		if (PHP_INT_SIZE === 4) {
857
+			return ParagonIE_Sodium_Crypto32::aead_xchacha20poly1305_ietf_decrypt(
858
+				$ciphertext,
859
+				$assocData,
860
+				$nonce,
861
+				$key
862
+			);
863
+		}
864
+		return ParagonIE_Sodium_Crypto::aead_xchacha20poly1305_ietf_decrypt(
865
+			$ciphertext,
866
+			$assocData,
867
+			$nonce,
868
+			$key
869
+		);
870
+	}
871
+
872
+	/**
873
+	 * Authenticated Encryption with Associated Data
874
+	 *
875
+	 * Algorithm:
876
+	 *     XChaCha20-Poly1305
877
+	 *
878
+	 * This mode uses a 64-bit random nonce with a 64-bit counter.
879
+	 * IETF mode uses a 96-bit random nonce with a 32-bit counter.
880
+	 *
881
+	 * @param string $plaintext    Message to be encrypted
882
+	 * @param string $assocData    Authenticated Associated Data (unencrypted)
883
+	 * @param string $nonce        Number to be used only Once; must be 8 bytes
884
+	 * @param string $key          Encryption key
885
+	 * @param bool   $dontFallback Don't fallback to ext/sodium
886
+	 *
887
+	 * @return string           Ciphertext with a 16-byte Poly1305 message
888
+	 *                          authentication code appended
889
+	 * @throws SodiumException
890
+	 * @throws TypeError
891
+	 * @psalm-suppress MixedArgument
892
+	 */
893
+	public static function crypto_aead_xchacha20poly1305_ietf_encrypt(
894
+		$plaintext = '',
895
+		$assocData = '',
896
+		$nonce = '',
897
+		$key = '',
898
+		$dontFallback = false
899
+	) {
900
+		/* Type checks: */
901
+		ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
902
+		if (!is_null($assocData)) {
903
+			ParagonIE_Sodium_Core_Util::declareScalarType($assocData, 'string', 2);
904
+		} else {
905
+			$assocData = '';
906
+		}
907
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 3);
908
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
909
+
910
+		/* Input validation: */
911
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_NPUBBYTES) {
912
+			throw new SodiumException('Nonce must be CRYPTO_AEAD_XCHACHA20POLY1305_NPUBBYTES long');
913
+		}
914
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_KEYBYTES) {
915
+			throw new SodiumException('Key must be CRYPTO_AEAD_XCHACHA20POLY1305_KEYBYTES long');
916
+		}
917
+		if (self::useNewSodiumAPI() && !$dontFallback) {
918
+			if (is_callable('sodium_crypto_aead_xchacha20poly1305_ietf_encrypt')) {
919
+				return sodium_crypto_aead_xchacha20poly1305_ietf_encrypt(
920
+					$plaintext,
921
+					$assocData,
922
+					$nonce,
923
+					$key
924
+				);
925
+			}
926
+		}
927
+
928
+		if (PHP_INT_SIZE === 4) {
929
+			return ParagonIE_Sodium_Crypto32::aead_xchacha20poly1305_ietf_encrypt(
930
+				$plaintext,
931
+				$assocData,
932
+				$nonce,
933
+				$key
934
+			);
935
+		}
936
+		return ParagonIE_Sodium_Crypto::aead_xchacha20poly1305_ietf_encrypt(
937
+			$plaintext,
938
+			$assocData,
939
+			$nonce,
940
+			$key
941
+		);
942
+	}
943
+
944
+	/**
945
+	 * Return a secure random key for use with the XChaCha20-Poly1305
946
+	 * symmetric AEAD interface.
947
+	 *
948
+	 * @return string
949
+	 * @throws Exception
950
+	 * @throws Error
951
+	 */
952
+	public static function crypto_aead_xchacha20poly1305_ietf_keygen()
953
+	{
954
+		return random_bytes(self::CRYPTO_AEAD_XCHACHA20POLY1305_IETF_KEYBYTES);
955
+	}
956
+
957
+	/**
958
+	 * Authenticate a message. Uses symmetric-key cryptography.
959
+	 *
960
+	 * Algorithm:
961
+	 *     HMAC-SHA512-256. Which is HMAC-SHA-512 truncated to 256 bits.
962
+	 *     Not to be confused with HMAC-SHA-512/256 which would use the
963
+	 *     SHA-512/256 hash function (uses different initial parameters
964
+	 *     but still truncates to 256 bits to sidestep length-extension
965
+	 *     attacks).
966
+	 *
967
+	 * @param string $message Message to be authenticated
968
+	 * @param string $key Symmetric authentication key
969
+	 * @return string         Message authentication code
970
+	 * @throws SodiumException
971
+	 * @throws TypeError
972
+	 * @psalm-suppress MixedArgument
973
+	 */
974
+	public static function crypto_auth($message, $key)
975
+	{
976
+		/* Type checks: */
977
+		ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
978
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 2);
979
+
980
+		/* Input validation: */
981
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AUTH_KEYBYTES) {
982
+			throw new SodiumException('Argument 2 must be CRYPTO_AUTH_KEYBYTES long.');
983
+		}
984
+
985
+		if (self::useNewSodiumAPI()) {
986
+			return (string) sodium_crypto_auth($message, $key);
987
+		}
988
+		if (self::use_fallback('crypto_auth')) {
989
+			return (string) call_user_func('\\Sodium\\crypto_auth', $message, $key);
990
+		}
991
+		if (PHP_INT_SIZE === 4) {
992
+			return ParagonIE_Sodium_Crypto32::auth($message, $key);
993
+		}
994
+		return ParagonIE_Sodium_Crypto::auth($message, $key);
995
+	}
996
+
997
+	/**
998
+	 * @return string
999
+	 * @throws Exception
1000
+	 * @throws Error
1001
+	 */
1002
+	public static function crypto_auth_keygen()
1003
+	{
1004
+		return random_bytes(self::CRYPTO_AUTH_KEYBYTES);
1005
+	}
1006
+
1007
+	/**
1008
+	 * Verify the MAC of a message previously authenticated with crypto_auth.
1009
+	 *
1010
+	 * @param string $mac Message authentication code
1011
+	 * @param string $message Message whose authenticity you are attempting to
1012
+	 *                        verify (with a given MAC and key)
1013
+	 * @param string $key Symmetric authentication key
1014
+	 * @return bool           TRUE if authenticated, FALSE otherwise
1015
+	 * @throws SodiumException
1016
+	 * @throws TypeError
1017
+	 * @psalm-suppress MixedArgument
1018
+	 */
1019
+	public static function crypto_auth_verify($mac, $message, $key)
1020
+	{
1021
+		/* Type checks: */
1022
+		ParagonIE_Sodium_Core_Util::declareScalarType($mac, 'string', 1);
1023
+		ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 2);
1024
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
1025
+
1026
+		/* Input validation: */
1027
+		if (ParagonIE_Sodium_Core_Util::strlen($mac) !== self::CRYPTO_AUTH_BYTES) {
1028
+			throw new SodiumException('Argument 1 must be CRYPTO_AUTH_BYTES long.');
1029
+		}
1030
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_AUTH_KEYBYTES) {
1031
+			throw new SodiumException('Argument 3 must be CRYPTO_AUTH_KEYBYTES long.');
1032
+		}
1033
+
1034
+		if (self::useNewSodiumAPI()) {
1035
+			return (bool) sodium_crypto_auth_verify($mac, $message, $key);
1036
+		}
1037
+		if (self::use_fallback('crypto_auth_verify')) {
1038
+			return (bool) call_user_func('\\Sodium\\crypto_auth_verify', $mac, $message, $key);
1039
+		}
1040
+		if (PHP_INT_SIZE === 4) {
1041
+			return ParagonIE_Sodium_Crypto32::auth_verify($mac, $message, $key);
1042
+		}
1043
+		return ParagonIE_Sodium_Crypto::auth_verify($mac, $message, $key);
1044
+	}
1045
+
1046
+	/**
1047
+	 * Authenticated asymmetric-key encryption. Both the sender and recipient
1048
+	 * may decrypt messages.
1049
+	 *
1050
+	 * Algorithm: X25519-XSalsa20-Poly1305.
1051
+	 *     X25519: Elliptic-Curve Diffie Hellman over Curve25519.
1052
+	 *     XSalsa20: Extended-nonce variant of salsa20.
1053
+	 *     Poyl1305: Polynomial MAC for one-time message authentication.
1054
+	 *
1055
+	 * @param string $plaintext The message to be encrypted
1056
+	 * @param string $nonce A Number to only be used Once; must be 24 bytes
1057
+	 * @param string $keypair Your secret key and your recipient's public key
1058
+	 * @return string           Ciphertext with 16-byte Poly1305 MAC
1059
+	 * @throws SodiumException
1060
+	 * @throws TypeError
1061
+	 * @psalm-suppress MixedArgument
1062
+	 */
1063
+	public static function crypto_box($plaintext, $nonce, $keypair)
1064
+	{
1065
+		/* Type checks: */
1066
+		ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
1067
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
1068
+		ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 3);
1069
+
1070
+		/* Input validation: */
1071
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_BOX_NONCEBYTES) {
1072
+			throw new SodiumException('Argument 2 must be CRYPTO_BOX_NONCEBYTES long.');
1073
+		}
1074
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_BOX_KEYPAIRBYTES) {
1075
+			throw new SodiumException('Argument 3 must be CRYPTO_BOX_KEYPAIRBYTES long.');
1076
+		}
1077
+
1078
+		if (self::useNewSodiumAPI()) {
1079
+			return (string) sodium_crypto_box($plaintext, $nonce, $keypair);
1080
+		}
1081
+		if (self::use_fallback('crypto_box')) {
1082
+			return (string) call_user_func('\\Sodium\\crypto_box', $plaintext, $nonce, $keypair);
1083
+		}
1084
+		if (PHP_INT_SIZE === 4) {
1085
+			return ParagonIE_Sodium_Crypto32::box($plaintext, $nonce, $keypair);
1086
+		}
1087
+		return ParagonIE_Sodium_Crypto::box($plaintext, $nonce, $keypair);
1088
+	}
1089
+
1090
+	/**
1091
+	 * Anonymous public-key encryption. Only the recipient may decrypt messages.
1092
+	 *
1093
+	 * Algorithm: X25519-XSalsa20-Poly1305, as with crypto_box.
1094
+	 *     The sender's X25519 keypair is ephemeral.
1095
+	 *     Nonce is generated from the BLAKE2b hash of both public keys.
1096
+	 *
1097
+	 * This provides ciphertext integrity.
1098
+	 *
1099
+	 * @param string $plaintext Message to be sealed
1100
+	 * @param string $publicKey Your recipient's public key
1101
+	 * @return string           Sealed message that only your recipient can
1102
+	 *                          decrypt
1103
+	 * @throws SodiumException
1104
+	 * @throws TypeError
1105
+	 * @psalm-suppress MixedArgument
1106
+	 */
1107
+	public static function crypto_box_seal($plaintext, $publicKey)
1108
+	{
1109
+		/* Type checks: */
1110
+		ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
1111
+		ParagonIE_Sodium_Core_Util::declareScalarType($publicKey, 'string', 2);
1112
+
1113
+		/* Input validation: */
1114
+		if (ParagonIE_Sodium_Core_Util::strlen($publicKey) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
1115
+			throw new SodiumException('Argument 2 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
1116
+		}
1117
+
1118
+		if (self::useNewSodiumAPI()) {
1119
+			return (string) sodium_crypto_box_seal($plaintext, $publicKey);
1120
+		}
1121
+		if (self::use_fallback('crypto_box_seal')) {
1122
+			return (string) call_user_func('\\Sodium\\crypto_box_seal', $plaintext, $publicKey);
1123
+		}
1124
+		if (PHP_INT_SIZE === 4) {
1125
+			return ParagonIE_Sodium_Crypto32::box_seal($plaintext, $publicKey);
1126
+		}
1127
+		return ParagonIE_Sodium_Crypto::box_seal($plaintext, $publicKey);
1128
+	}
1129
+
1130
+	/**
1131
+	 * Opens a message encrypted with crypto_box_seal(). Requires
1132
+	 * the recipient's keypair (sk || pk) to decrypt successfully.
1133
+	 *
1134
+	 * This validates ciphertext integrity.
1135
+	 *
1136
+	 * @param string $ciphertext Sealed message to be opened
1137
+	 * @param string $keypair    Your crypto_box keypair
1138
+	 * @return string            The original plaintext message
1139
+	 * @throws SodiumException
1140
+	 * @throws TypeError
1141
+	 * @psalm-suppress MixedArgument
1142
+	 * @psalm-suppress MixedInferredReturnType
1143
+	 * @psalm-suppress MixedReturnStatement
1144
+	 */
1145
+	public static function crypto_box_seal_open($ciphertext, $keypair)
1146
+	{
1147
+		/* Type checks: */
1148
+		ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
1149
+		ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 2);
1150
+
1151
+		/* Input validation: */
1152
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_BOX_KEYPAIRBYTES) {
1153
+			throw new SodiumException('Argument 2 must be CRYPTO_BOX_KEYPAIRBYTES long.');
1154
+		}
1155
+
1156
+		if (self::useNewSodiumAPI()) {
1157
+			/**
1158
+			 * @psalm-suppress InvalidReturnStatement
1159
+			 * @psalm-suppress FalsableReturnStatement
1160
+			 */
1161
+			return sodium_crypto_box_seal_open($ciphertext, $keypair);
1162
+		}
1163
+		if (self::use_fallback('crypto_box_seal_open')) {
1164
+			return call_user_func('\\Sodium\\crypto_box_seal_open', $ciphertext, $keypair);
1165
+		}
1166
+		if (PHP_INT_SIZE === 4) {
1167
+			return ParagonIE_Sodium_Crypto32::box_seal_open($ciphertext, $keypair);
1168
+		}
1169
+		return ParagonIE_Sodium_Crypto::box_seal_open($ciphertext, $keypair);
1170
+	}
1171
+
1172
+	/**
1173
+	 * Generate a new random X25519 keypair.
1174
+	 *
1175
+	 * @return string A 64-byte string; the first 32 are your secret key, while
1176
+	 *                the last 32 are your public key. crypto_box_secretkey()
1177
+	 *                and crypto_box_publickey() exist to separate them so you
1178
+	 *                don't accidentally get them mixed up!
1179
+	 * @throws SodiumException
1180
+	 * @throws TypeError
1181
+	 * @psalm-suppress MixedArgument
1182
+	 */
1183
+	public static function crypto_box_keypair()
1184
+	{
1185
+		if (self::useNewSodiumAPI()) {
1186
+			return (string) sodium_crypto_box_keypair();
1187
+		}
1188
+		if (self::use_fallback('crypto_box_keypair')) {
1189
+			return (string) call_user_func('\\Sodium\\crypto_box_keypair');
1190
+		}
1191
+		if (PHP_INT_SIZE === 4) {
1192
+			return ParagonIE_Sodium_Crypto32::box_keypair();
1193
+		}
1194
+		return ParagonIE_Sodium_Crypto::box_keypair();
1195
+	}
1196
+
1197
+	/**
1198
+	 * Combine two keys into a keypair for use in library methods that expect
1199
+	 * a keypair. This doesn't necessarily have to be the same person's keys.
1200
+	 *
1201
+	 * @param string $secretKey Secret key
1202
+	 * @param string $publicKey Public key
1203
+	 * @return string    Keypair
1204
+	 * @throws SodiumException
1205
+	 * @throws TypeError
1206
+	 * @psalm-suppress MixedArgument
1207
+	 */
1208
+	public static function crypto_box_keypair_from_secretkey_and_publickey($secretKey, $publicKey)
1209
+	{
1210
+		/* Type checks: */
1211
+		ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 1);
1212
+		ParagonIE_Sodium_Core_Util::declareScalarType($publicKey, 'string', 2);
1213
+
1214
+		/* Input validation: */
1215
+		if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_BOX_SECRETKEYBYTES) {
1216
+			throw new SodiumException('Argument 1 must be CRYPTO_BOX_SECRETKEYBYTES long.');
1217
+		}
1218
+		if (ParagonIE_Sodium_Core_Util::strlen($publicKey) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
1219
+			throw new SodiumException('Argument 2 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
1220
+		}
1221
+
1222
+		if (self::useNewSodiumAPI()) {
1223
+			return (string) sodium_crypto_box_keypair_from_secretkey_and_publickey($secretKey, $publicKey);
1224
+		}
1225
+		if (self::use_fallback('crypto_box_keypair_from_secretkey_and_publickey')) {
1226
+			return (string) call_user_func('\\Sodium\\crypto_box_keypair_from_secretkey_and_publickey', $secretKey, $publicKey);
1227
+		}
1228
+		if (PHP_INT_SIZE === 4) {
1229
+			return ParagonIE_Sodium_Crypto32::box_keypair_from_secretkey_and_publickey($secretKey, $publicKey);
1230
+		}
1231
+		return ParagonIE_Sodium_Crypto::box_keypair_from_secretkey_and_publickey($secretKey, $publicKey);
1232
+	}
1233
+
1234
+	/**
1235
+	 * Decrypt a message previously encrypted with crypto_box().
1236
+	 *
1237
+	 * @param string $ciphertext Encrypted message
1238
+	 * @param string $nonce      Number to only be used Once; must be 24 bytes
1239
+	 * @param string $keypair    Your secret key and the sender's public key
1240
+	 * @return string            The original plaintext message
1241
+	 * @throws SodiumException
1242
+	 * @throws TypeError
1243
+	 * @psalm-suppress MixedArgument
1244
+	 * @psalm-suppress MixedInferredReturnType
1245
+	 * @psalm-suppress MixedReturnStatement
1246
+	 */
1247
+	public static function crypto_box_open($ciphertext, $nonce, $keypair)
1248
+	{
1249
+		/* Type checks: */
1250
+		ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
1251
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
1252
+		ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 3);
1253
+
1254
+		/* Input validation: */
1255
+		if (ParagonIE_Sodium_Core_Util::strlen($ciphertext) < self::CRYPTO_BOX_MACBYTES) {
1256
+			throw new SodiumException('Argument 1 must be at least CRYPTO_BOX_MACBYTES long.');
1257
+		}
1258
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_BOX_NONCEBYTES) {
1259
+			throw new SodiumException('Argument 2 must be CRYPTO_BOX_NONCEBYTES long.');
1260
+		}
1261
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_BOX_KEYPAIRBYTES) {
1262
+			throw new SodiumException('Argument 3 must be CRYPTO_BOX_KEYPAIRBYTES long.');
1263
+		}
1264
+
1265
+		if (self::useNewSodiumAPI()) {
1266
+			/**
1267
+			 * @psalm-suppress InvalidReturnStatement
1268
+			 * @psalm-suppress FalsableReturnStatement
1269
+			 */
1270
+			return sodium_crypto_box_open($ciphertext, $nonce, $keypair);
1271
+		}
1272
+		if (self::use_fallback('crypto_box_open')) {
1273
+			return call_user_func('\\Sodium\\crypto_box_open', $ciphertext, $nonce, $keypair);
1274
+		}
1275
+		if (PHP_INT_SIZE === 4) {
1276
+			return ParagonIE_Sodium_Crypto32::box_open($ciphertext, $nonce, $keypair);
1277
+		}
1278
+		return ParagonIE_Sodium_Crypto::box_open($ciphertext, $nonce, $keypair);
1279
+	}
1280
+
1281
+	/**
1282
+	 * Extract the public key from a crypto_box keypair.
1283
+	 *
1284
+	 * @param string $keypair Keypair containing secret and public key
1285
+	 * @return string         Your crypto_box public key
1286
+	 * @throws SodiumException
1287
+	 * @throws TypeError
1288
+	 * @psalm-suppress MixedArgument
1289
+	 */
1290
+	public static function crypto_box_publickey($keypair)
1291
+	{
1292
+		/* Type checks: */
1293
+		ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
1294
+
1295
+		/* Input validation: */
1296
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_BOX_KEYPAIRBYTES) {
1297
+			throw new SodiumException('Argument 1 must be CRYPTO_BOX_KEYPAIRBYTES long.');
1298
+		}
1299
+
1300
+		if (self::useNewSodiumAPI()) {
1301
+			return (string) sodium_crypto_box_publickey($keypair);
1302
+		}
1303
+		if (self::use_fallback('crypto_box_publickey')) {
1304
+			return (string) call_user_func('\\Sodium\\crypto_box_publickey', $keypair);
1305
+		}
1306
+		if (PHP_INT_SIZE === 4) {
1307
+			return ParagonIE_Sodium_Crypto32::box_publickey($keypair);
1308
+		}
1309
+		return ParagonIE_Sodium_Crypto::box_publickey($keypair);
1310
+	}
1311
+
1312
+	/**
1313
+	 * Calculate the X25519 public key from a given X25519 secret key.
1314
+	 *
1315
+	 * @param string $secretKey Any X25519 secret key
1316
+	 * @return string           The corresponding X25519 public key
1317
+	 * @throws SodiumException
1318
+	 * @throws TypeError
1319
+	 * @psalm-suppress MixedArgument
1320
+	 */
1321
+	public static function crypto_box_publickey_from_secretkey($secretKey)
1322
+	{
1323
+		/* Type checks: */
1324
+		ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 1);
1325
+
1326
+		/* Input validation: */
1327
+		if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_BOX_SECRETKEYBYTES) {
1328
+			throw new SodiumException('Argument 1 must be CRYPTO_BOX_SECRETKEYBYTES long.');
1329
+		}
1330
+
1331
+		if (self::useNewSodiumAPI()) {
1332
+			return (string) sodium_crypto_box_publickey_from_secretkey($secretKey);
1333
+		}
1334
+		if (self::use_fallback('crypto_box_publickey_from_secretkey')) {
1335
+			return (string) call_user_func('\\Sodium\\crypto_box_publickey_from_secretkey', $secretKey);
1336
+		}
1337
+		if (PHP_INT_SIZE === 4) {
1338
+			return ParagonIE_Sodium_Crypto32::box_publickey_from_secretkey($secretKey);
1339
+		}
1340
+		return ParagonIE_Sodium_Crypto::box_publickey_from_secretkey($secretKey);
1341
+	}
1342
+
1343
+	/**
1344
+	 * Extract the secret key from a crypto_box keypair.
1345
+	 *
1346
+	 * @param string $keypair
1347
+	 * @return string         Your crypto_box secret key
1348
+	 * @throws SodiumException
1349
+	 * @throws TypeError
1350
+	 * @psalm-suppress MixedArgument
1351
+	 */
1352
+	public static function crypto_box_secretkey($keypair)
1353
+	{
1354
+		/* Type checks: */
1355
+		ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
1356
+
1357
+		/* Input validation: */
1358
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_BOX_KEYPAIRBYTES) {
1359
+			throw new SodiumException('Argument 1 must be CRYPTO_BOX_KEYPAIRBYTES long.');
1360
+		}
1361
+
1362
+		if (self::useNewSodiumAPI()) {
1363
+			return (string) sodium_crypto_box_secretkey($keypair);
1364
+		}
1365
+		if (self::use_fallback('crypto_box_secretkey')) {
1366
+			return (string) call_user_func('\\Sodium\\crypto_box_secretkey', $keypair);
1367
+		}
1368
+		if (PHP_INT_SIZE === 4) {
1369
+			return ParagonIE_Sodium_Crypto32::box_secretkey($keypair);
1370
+		}
1371
+		return ParagonIE_Sodium_Crypto::box_secretkey($keypair);
1372
+	}
1373
+
1374
+	/**
1375
+	 * Generate an X25519 keypair from a seed.
1376
+	 *
1377
+	 * @param string $seed
1378
+	 * @return string
1379
+	 * @throws SodiumException
1380
+	 * @throws TypeError
1381
+	 * @psalm-suppress MixedArgument
1382
+	 * @psalm-suppress UndefinedFunction
1383
+	 */
1384
+	public static function crypto_box_seed_keypair($seed)
1385
+	{
1386
+		/* Type checks: */
1387
+		ParagonIE_Sodium_Core_Util::declareScalarType($seed, 'string', 1);
1388
+
1389
+		if (self::useNewSodiumAPI()) {
1390
+			return (string) sodium_crypto_box_seed_keypair($seed);
1391
+		}
1392
+		if (self::use_fallback('crypto_box_seed_keypair')) {
1393
+			return (string) call_user_func('\\Sodium\\crypto_box_seed_keypair', $seed);
1394
+		}
1395
+		if (PHP_INT_SIZE === 4) {
1396
+			return ParagonIE_Sodium_Crypto32::box_seed_keypair($seed);
1397
+		}
1398
+		return ParagonIE_Sodium_Crypto::box_seed_keypair($seed);
1399
+	}
1400
+
1401
+	/**
1402
+	 * Calculates a BLAKE2b hash, with an optional key.
1403
+	 *
1404
+	 * @param string      $message The message to be hashed
1405
+	 * @param string|null $key     If specified, must be a string between 16
1406
+	 *                             and 64 bytes long
1407
+	 * @param int         $length  Output length in bytes; must be between 16
1408
+	 *                             and 64 (default = 32)
1409
+	 * @return string              Raw binary
1410
+	 * @throws SodiumException
1411
+	 * @throws TypeError
1412
+	 * @psalm-suppress MixedArgument
1413
+	 */
1414
+	public static function crypto_generichash($message, $key = '', $length = self::CRYPTO_GENERICHASH_BYTES)
1415
+	{
1416
+		/* Type checks: */
1417
+		ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
1418
+		if (is_null($key)) {
1419
+			$key = '';
1420
+		}
1421
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 2);
1422
+		ParagonIE_Sodium_Core_Util::declareScalarType($length, 'int', 3);
1423
+
1424
+		/* Input validation: */
1425
+		if (!empty($key)) {
1426
+			if (ParagonIE_Sodium_Core_Util::strlen($key) < self::CRYPTO_GENERICHASH_KEYBYTES_MIN) {
1427
+				throw new SodiumException('Unsupported key size. Must be at least CRYPTO_GENERICHASH_KEYBYTES_MIN bytes long.');
1428
+			}
1429
+			if (ParagonIE_Sodium_Core_Util::strlen($key) > self::CRYPTO_GENERICHASH_KEYBYTES_MAX) {
1430
+				throw new SodiumException('Unsupported key size. Must be at most CRYPTO_GENERICHASH_KEYBYTES_MAX bytes long.');
1431
+			}
1432
+		}
1433
+
1434
+		if (self::useNewSodiumAPI()) {
1435
+			return (string) sodium_crypto_generichash($message, $key, $length);
1436
+		}
1437
+		if (self::use_fallback('crypto_generichash')) {
1438
+			return (string) call_user_func('\\Sodium\\crypto_generichash', $message, $key, $length);
1439
+		}
1440
+		if (PHP_INT_SIZE === 4) {
1441
+			return ParagonIE_Sodium_Crypto32::generichash($message, $key, $length);
1442
+		}
1443
+		return ParagonIE_Sodium_Crypto::generichash($message, $key, $length);
1444
+	}
1445
+
1446
+	/**
1447
+	 * Get the final BLAKE2b hash output for a given context.
1448
+	 *
1449
+	 * @param string $ctx BLAKE2 hashing context. Generated by crypto_generichash_init().
1450
+	 * @param int $length Hash output size.
1451
+	 * @return string     Final BLAKE2b hash.
1452
+	 * @throws SodiumException
1453
+	 * @throws TypeError
1454
+	 * @psalm-suppress MixedArgument
1455
+	 * @psalm-suppress ReferenceConstraintViolation
1456
+	 * @psalm-suppress ConflictingReferenceConstraint
1457
+	 */
1458
+	public static function crypto_generichash_final(&$ctx, $length = self::CRYPTO_GENERICHASH_BYTES)
1459
+	{
1460
+		/* Type checks: */
1461
+		ParagonIE_Sodium_Core_Util::declareScalarType($ctx, 'string', 1);
1462
+		ParagonIE_Sodium_Core_Util::declareScalarType($length, 'int', 2);
1463
+
1464
+		if (self::useNewSodiumAPI()) {
1465
+			return sodium_crypto_generichash_final($ctx, $length);
1466
+		}
1467
+		if (self::use_fallback('crypto_generichash_final')) {
1468
+			$func = '\\Sodium\\crypto_generichash_final';
1469
+			return (string) $func($ctx, $length);
1470
+		}
1471
+		if ($length < 1) {
1472
+			try {
1473
+				self::memzero($ctx);
1474
+			} catch (SodiumException $ex) {
1475
+				unset($ctx);
1476
+			}
1477
+			return '';
1478
+		}
1479
+		if (PHP_INT_SIZE === 4) {
1480
+			$result = ParagonIE_Sodium_Crypto32::generichash_final($ctx, $length);
1481
+		} else {
1482
+			$result = ParagonIE_Sodium_Crypto::generichash_final($ctx, $length);
1483
+		}
1484
+		try {
1485
+			self::memzero($ctx);
1486
+		} catch (SodiumException $ex) {
1487
+			unset($ctx);
1488
+		}
1489
+		return $result;
1490
+	}
1491
+
1492
+	/**
1493
+	 * Initialize a BLAKE2b hashing context, for use in a streaming interface.
1494
+	 *
1495
+	 * @param string|null $key If specified must be a string between 16 and 64 bytes
1496
+	 * @param int $length      The size of the desired hash output
1497
+	 * @return string          A BLAKE2 hashing context, encoded as a string
1498
+	 *                         (To be 100% compatible with ext/libsodium)
1499
+	 * @throws SodiumException
1500
+	 * @throws TypeError
1501
+	 * @psalm-suppress MixedArgument
1502
+	 */
1503
+	public static function crypto_generichash_init($key = '', $length = self::CRYPTO_GENERICHASH_BYTES)
1504
+	{
1505
+		/* Type checks: */
1506
+		if (is_null($key)) {
1507
+			$key = '';
1508
+		}
1509
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 1);
1510
+		ParagonIE_Sodium_Core_Util::declareScalarType($length, 'int', 2);
1511
+
1512
+		/* Input validation: */
1513
+		if (!empty($key)) {
1514
+			if (ParagonIE_Sodium_Core_Util::strlen($key) < self::CRYPTO_GENERICHASH_KEYBYTES_MIN) {
1515
+				throw new SodiumException('Unsupported key size. Must be at least CRYPTO_GENERICHASH_KEYBYTES_MIN bytes long.');
1516
+			}
1517
+			if (ParagonIE_Sodium_Core_Util::strlen($key) > self::CRYPTO_GENERICHASH_KEYBYTES_MAX) {
1518
+				throw new SodiumException('Unsupported key size. Must be at most CRYPTO_GENERICHASH_KEYBYTES_MAX bytes long.');
1519
+			}
1520
+		}
1521
+
1522
+		if (self::useNewSodiumAPI()) {
1523
+			return sodium_crypto_generichash_init($key, $length);
1524
+		}
1525
+		if (self::use_fallback('crypto_generichash_init')) {
1526
+			return (string) call_user_func('\\Sodium\\crypto_generichash_init', $key, $length);
1527
+		}
1528
+		if (PHP_INT_SIZE === 4) {
1529
+			return ParagonIE_Sodium_Crypto32::generichash_init($key, $length);
1530
+		}
1531
+		return ParagonIE_Sodium_Crypto::generichash_init($key, $length);
1532
+	}
1533
+
1534
+	/**
1535
+	 * Initialize a BLAKE2b hashing context, for use in a streaming interface.
1536
+	 *
1537
+	 * @param string|null $key If specified must be a string between 16 and 64 bytes
1538
+	 * @param int $length      The size of the desired hash output
1539
+	 * @param string $salt     Salt (up to 16 bytes)
1540
+	 * @param string $personal Personalization string (up to 16 bytes)
1541
+	 * @return string          A BLAKE2 hashing context, encoded as a string
1542
+	 *                         (To be 100% compatible with ext/libsodium)
1543
+	 * @throws SodiumException
1544
+	 * @throws TypeError
1545
+	 * @psalm-suppress MixedArgument
1546
+	 */
1547
+	public static function crypto_generichash_init_salt_personal(
1548
+		$key = '',
1549
+		$length = self::CRYPTO_GENERICHASH_BYTES,
1550
+		$salt = '',
1551
+		$personal = ''
1552
+	) {
1553
+		/* Type checks: */
1554
+		if (is_null($key)) {
1555
+			$key = '';
1556
+		}
1557
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 1);
1558
+		ParagonIE_Sodium_Core_Util::declareScalarType($length, 'int', 2);
1559
+		ParagonIE_Sodium_Core_Util::declareScalarType($salt, 'string', 3);
1560
+		ParagonIE_Sodium_Core_Util::declareScalarType($personal, 'string', 4);
1561
+		$salt = str_pad($salt, 16, "\0", STR_PAD_RIGHT);
1562
+		$personal = str_pad($personal, 16, "\0", STR_PAD_RIGHT);
1563
+
1564
+		/* Input validation: */
1565
+		if (!empty($key)) {
1566
+			/*
1567 1567
             if (ParagonIE_Sodium_Core_Util::strlen($key) < self::CRYPTO_GENERICHASH_KEYBYTES_MIN) {
1568 1568
                 throw new SodiumException('Unsupported key size. Must be at least CRYPTO_GENERICHASH_KEYBYTES_MIN bytes long.');
1569 1569
             }
1570 1570
             */
1571
-            if (ParagonIE_Sodium_Core_Util::strlen($key) > self::CRYPTO_GENERICHASH_KEYBYTES_MAX) {
1572
-                throw new SodiumException('Unsupported key size. Must be at most CRYPTO_GENERICHASH_KEYBYTES_MAX bytes long.');
1573
-            }
1574
-        }
1575
-        if (PHP_INT_SIZE === 4) {
1576
-            return ParagonIE_Sodium_Crypto32::generichash_init_salt_personal($key, $length, $salt, $personal);
1577
-        }
1578
-        return ParagonIE_Sodium_Crypto::generichash_init_salt_personal($key, $length, $salt, $personal);
1579
-    }
1580
-
1581
-    /**
1582
-     * Update a BLAKE2b hashing context with additional data.
1583
-     *
1584
-     * @param string $ctx    BLAKE2 hashing context. Generated by crypto_generichash_init().
1585
-     *                       $ctx is passed by reference and gets updated in-place.
1586
-     * @param-out string $ctx
1587
-     * @param string $message The message to append to the existing hash state.
1588
-     * @return void
1589
-     * @throws SodiumException
1590
-     * @throws TypeError
1591
-     * @psalm-suppress MixedArgument
1592
-     * @psalm-suppress ReferenceConstraintViolation
1593
-     */
1594
-    public static function crypto_generichash_update(&$ctx, $message)
1595
-    {
1596
-        /* Type checks: */
1597
-        ParagonIE_Sodium_Core_Util::declareScalarType($ctx, 'string', 1);
1598
-        ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 2);
1599
-
1600
-        if (self::useNewSodiumAPI()) {
1601
-            sodium_crypto_generichash_update($ctx, $message);
1602
-            return;
1603
-        }
1604
-        if (self::use_fallback('crypto_generichash_update')) {
1605
-            $func = '\\Sodium\\crypto_generichash_update';
1606
-            $func($ctx, $message);
1607
-            return;
1608
-        }
1609
-        if (PHP_INT_SIZE === 4) {
1610
-            $ctx = ParagonIE_Sodium_Crypto32::generichash_update($ctx, $message);
1611
-        } else {
1612
-            $ctx = ParagonIE_Sodium_Crypto::generichash_update($ctx, $message);
1613
-        }
1614
-    }
1615
-
1616
-    /**
1617
-     * @return string
1618
-     * @throws Exception
1619
-     * @throws Error
1620
-     */
1621
-    public static function crypto_generichash_keygen()
1622
-    {
1623
-        return random_bytes(self::CRYPTO_GENERICHASH_KEYBYTES);
1624
-    }
1625
-
1626
-    /**
1627
-     * @param int $subkey_len
1628
-     * @param int $subkey_id
1629
-     * @param string $context
1630
-     * @param string $key
1631
-     * @return string
1632
-     * @throws SodiumException
1633
-     */
1634
-    public static function crypto_kdf_derive_from_key(
1635
-        $subkey_len,
1636
-        $subkey_id,
1637
-        $context,
1638
-        $key
1639
-    ) {
1640
-        ParagonIE_Sodium_Core_Util::declareScalarType($subkey_len, 'int', 1);
1641
-        ParagonIE_Sodium_Core_Util::declareScalarType($subkey_id, 'int', 2);
1642
-        ParagonIE_Sodium_Core_Util::declareScalarType($context, 'string', 3);
1643
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
1644
-        $subkey_id = (int) $subkey_id;
1645
-        $subkey_len = (int) $subkey_len;
1646
-        $context = (string) $context;
1647
-        $key = (string) $key;
1648
-
1649
-        if ($subkey_len < self::CRYPTO_KDF_BYTES_MIN) {
1650
-            throw new SodiumException('subkey cannot be smaller than SODIUM_CRYPTO_KDF_BYTES_MIN');
1651
-        }
1652
-        if ($subkey_len > self::CRYPTO_KDF_BYTES_MAX) {
1653
-            throw new SodiumException('subkey cannot be larger than SODIUM_CRYPTO_KDF_BYTES_MAX');
1654
-        }
1655
-        if ($subkey_id < 0) {
1656
-            throw new SodiumException('subkey_id cannot be negative');
1657
-        }
1658
-        if (ParagonIE_Sodium_Core_Util::strlen($context) !== self::CRYPTO_KDF_CONTEXTBYTES) {
1659
-            throw new SodiumException('context should be SODIUM_CRYPTO_KDF_CONTEXTBYTES bytes');
1660
-        }
1661
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_KDF_KEYBYTES) {
1662
-            throw new SodiumException('key should be SODIUM_CRYPTO_KDF_KEYBYTES bytes');
1663
-        }
1664
-
1665
-        $salt = ParagonIE_Sodium_Core_Util::store64_le($subkey_id);
1666
-        $state = self::crypto_generichash_init_salt_personal(
1667
-            $key,
1668
-            $subkey_len,
1669
-            $salt,
1670
-            $context
1671
-        );
1672
-        return self::crypto_generichash_final($state, $subkey_len);
1673
-    }
1674
-
1675
-    /**
1676
-     * @return string
1677
-     * @throws Exception
1678
-     * @throws Error
1679
-     */
1680
-    public static function crypto_kdf_keygen()
1681
-    {
1682
-        return random_bytes(self::CRYPTO_KDF_KEYBYTES);
1683
-    }
1684
-
1685
-    /**
1686
-     * Perform a key exchange, between a designated client and a server.
1687
-     *
1688
-     * Typically, you would designate one machine to be the client and the
1689
-     * other to be the server. The first two keys are what you'd expect for
1690
-     * scalarmult() below, but the latter two public keys don't swap places.
1691
-     *
1692
-     * | ALICE                          | BOB                                 |
1693
-     * | Client                         | Server                              |
1694
-     * |--------------------------------|-------------------------------------|
1695
-     * | shared = crypto_kx(            | shared = crypto_kx(                 |
1696
-     * |     alice_sk,                  |     bob_sk,                         | <- contextual
1697
-     * |     bob_pk,                    |     alice_pk,                       | <- contextual
1698
-     * |     alice_pk,                  |     alice_pk,                       | <----- static
1699
-     * |     bob_pk                     |     bob_pk                          | <----- static
1700
-     * | )                              | )                                   |
1701
-     *
1702
-     * They are used along with the scalarmult product to generate a 256-bit
1703
-     * BLAKE2b hash unique to the client and server keys.
1704
-     *
1705
-     * @param string $my_secret
1706
-     * @param string $their_public
1707
-     * @param string $client_public
1708
-     * @param string $server_public
1709
-     * @param bool $dontFallback
1710
-     * @return string
1711
-     * @throws SodiumException
1712
-     * @throws TypeError
1713
-     * @psalm-suppress MixedArgument
1714
-     */
1715
-    public static function crypto_kx($my_secret, $their_public, $client_public, $server_public, $dontFallback = false)
1716
-    {
1717
-        /* Type checks: */
1718
-        ParagonIE_Sodium_Core_Util::declareScalarType($my_secret, 'string', 1);
1719
-        ParagonIE_Sodium_Core_Util::declareScalarType($their_public, 'string', 2);
1720
-        ParagonIE_Sodium_Core_Util::declareScalarType($client_public, 'string', 3);
1721
-        ParagonIE_Sodium_Core_Util::declareScalarType($server_public, 'string', 4);
1722
-
1723
-        /* Input validation: */
1724
-        if (ParagonIE_Sodium_Core_Util::strlen($my_secret) !== self::CRYPTO_BOX_SECRETKEYBYTES) {
1725
-            throw new SodiumException('Argument 1 must be CRYPTO_BOX_SECRETKEYBYTES long.');
1726
-        }
1727
-        if (ParagonIE_Sodium_Core_Util::strlen($their_public) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
1728
-            throw new SodiumException('Argument 2 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
1729
-        }
1730
-        if (ParagonIE_Sodium_Core_Util::strlen($client_public) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
1731
-            throw new SodiumException('Argument 3 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
1732
-        }
1733
-        if (ParagonIE_Sodium_Core_Util::strlen($server_public) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
1734
-            throw new SodiumException('Argument 4 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
1735
-        }
1736
-
1737
-        if (self::useNewSodiumAPI() && !$dontFallback) {
1738
-            if (is_callable('sodium_crypto_kx')) {
1739
-                return (string) sodium_crypto_kx(
1740
-                    $my_secret,
1741
-                    $their_public,
1742
-                    $client_public,
1743
-                    $server_public
1744
-                );
1745
-            }
1746
-        }
1747
-        if (self::use_fallback('crypto_kx')) {
1748
-            return (string) call_user_func(
1749
-                '\\Sodium\\crypto_kx',
1750
-                $my_secret,
1751
-                $their_public,
1752
-                $client_public,
1753
-                $server_public
1754
-            );
1755
-        }
1756
-        if (PHP_INT_SIZE === 4) {
1757
-            return ParagonIE_Sodium_Crypto32::keyExchange(
1758
-                $my_secret,
1759
-                $their_public,
1760
-                $client_public,
1761
-                $server_public
1762
-            );
1763
-        }
1764
-        return ParagonIE_Sodium_Crypto::keyExchange(
1765
-            $my_secret,
1766
-            $their_public,
1767
-            $client_public,
1768
-            $server_public
1769
-        );
1770
-    }
1771
-
1772
-    /**
1773
-     * @param string $seed
1774
-     * @return string
1775
-     * @throws SodiumException
1776
-     */
1777
-    public static function crypto_kx_seed_keypair($seed)
1778
-    {
1779
-        ParagonIE_Sodium_Core_Util::declareScalarType($seed, 'string', 1);
1780
-
1781
-        $seed = (string) $seed;
1782
-
1783
-        if (ParagonIE_Sodium_Core_Util::strlen($seed) !== self::CRYPTO_KX_SEEDBYTES) {
1784
-            throw new SodiumException('seed must be SODIUM_CRYPTO_KX_SEEDBYTES bytes');
1785
-        }
1786
-
1787
-        $sk = self::crypto_generichash($seed, '', self::CRYPTO_KX_SECRETKEYBYTES);
1788
-        $pk = self::crypto_scalarmult_base($sk);
1789
-        return $sk . $pk;
1790
-    }
1791
-
1792
-    /**
1793
-     * @return string
1794
-     * @throws Exception
1795
-     */
1796
-    public static function crypto_kx_keypair()
1797
-    {
1798
-        $sk = self::randombytes_buf(self::CRYPTO_KX_SECRETKEYBYTES);
1799
-        $pk = self::crypto_scalarmult_base($sk);
1800
-        return $sk . $pk;
1801
-    }
1802
-
1803
-    /**
1804
-     * @param string $keypair
1805
-     * @param string $serverPublicKey
1806
-     * @return array{0: string, 1: string}
1807
-     * @throws SodiumException
1808
-     */
1809
-    public static function crypto_kx_client_session_keys($keypair, $serverPublicKey)
1810
-    {
1811
-        ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
1812
-        ParagonIE_Sodium_Core_Util::declareScalarType($serverPublicKey, 'string', 2);
1813
-
1814
-        $keypair = (string) $keypair;
1815
-        $serverPublicKey = (string) $serverPublicKey;
1816
-
1817
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_KX_KEYPAIRBYTES) {
1818
-            throw new SodiumException('keypair should be SODIUM_CRYPTO_KX_KEYPAIRBYTES bytes');
1819
-        }
1820
-        if (ParagonIE_Sodium_Core_Util::strlen($serverPublicKey) !== self::CRYPTO_KX_PUBLICKEYBYTES) {
1821
-            throw new SodiumException('public keys must be SODIUM_CRYPTO_KX_PUBLICKEYBYTES bytes');
1822
-        }
1823
-
1824
-        $sk = self::crypto_kx_secretkey($keypair);
1825
-        $pk = self::crypto_kx_publickey($keypair);
1826
-        $h = self::crypto_generichash_init(null, self::CRYPTO_KX_SESSIONKEYBYTES * 2);
1827
-        self::crypto_generichash_update($h, self::crypto_scalarmult($sk, $serverPublicKey));
1828
-        self::crypto_generichash_update($h, $pk);
1829
-        self::crypto_generichash_update($h, $serverPublicKey);
1830
-        $sessionKeys = self::crypto_generichash_final($h, self::CRYPTO_KX_SESSIONKEYBYTES * 2);
1831
-        return array(
1832
-            ParagonIE_Sodium_Core_Util::substr(
1833
-                $sessionKeys,
1834
-                0,
1835
-                self::CRYPTO_KX_SESSIONKEYBYTES
1836
-            ),
1837
-            ParagonIE_Sodium_Core_Util::substr(
1838
-                $sessionKeys,
1839
-                self::CRYPTO_KX_SESSIONKEYBYTES,
1840
-                self::CRYPTO_KX_SESSIONKEYBYTES
1841
-            )
1842
-        );
1843
-    }
1844
-
1845
-    /**
1846
-     * @param string $keypair
1847
-     * @param string $clientPublicKey
1848
-     * @return array{0: string, 1: string}
1849
-     * @throws SodiumException
1850
-     */
1851
-    public static function crypto_kx_server_session_keys($keypair, $clientPublicKey)
1852
-    {
1853
-        ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
1854
-        ParagonIE_Sodium_Core_Util::declareScalarType($clientPublicKey, 'string', 2);
1855
-
1856
-        $keypair = (string) $keypair;
1857
-        $clientPublicKey = (string) $clientPublicKey;
1858
-
1859
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_KX_KEYPAIRBYTES) {
1860
-            throw new SodiumException('keypair should be SODIUM_CRYPTO_KX_KEYPAIRBYTES bytes');
1861
-        }
1862
-        if (ParagonIE_Sodium_Core_Util::strlen($clientPublicKey) !== self::CRYPTO_KX_PUBLICKEYBYTES) {
1863
-            throw new SodiumException('public keys must be SODIUM_CRYPTO_KX_PUBLICKEYBYTES bytes');
1864
-        }
1865
-
1866
-        $sk = self::crypto_kx_secretkey($keypair);
1867
-        $pk = self::crypto_kx_publickey($keypair);
1868
-        $h = self::crypto_generichash_init(null, self::CRYPTO_KX_SESSIONKEYBYTES * 2);
1869
-        self::crypto_generichash_update($h, self::crypto_scalarmult($sk, $clientPublicKey));
1870
-        self::crypto_generichash_update($h, $clientPublicKey);
1871
-        self::crypto_generichash_update($h, $pk);
1872
-        $sessionKeys = self::crypto_generichash_final($h, self::CRYPTO_KX_SESSIONKEYBYTES * 2);
1873
-        return array(
1874
-            ParagonIE_Sodium_Core_Util::substr(
1875
-                $sessionKeys,
1876
-                self::CRYPTO_KX_SESSIONKEYBYTES,
1877
-                self::CRYPTO_KX_SESSIONKEYBYTES
1878
-            ),
1879
-            ParagonIE_Sodium_Core_Util::substr(
1880
-                $sessionKeys,
1881
-                0,
1882
-                self::CRYPTO_KX_SESSIONKEYBYTES
1883
-            )
1884
-        );
1885
-    }
1886
-
1887
-    /**
1888
-     * @param string $kp
1889
-     * @return string
1890
-     * @throws SodiumException
1891
-     */
1892
-    public static function crypto_kx_secretkey($kp)
1893
-    {
1894
-        return ParagonIE_Sodium_Core_Util::substr(
1895
-            $kp,
1896
-            0,
1897
-            self::CRYPTO_KX_SECRETKEYBYTES
1898
-        );
1899
-    }
1900
-
1901
-    /**
1902
-     * @param string $kp
1903
-     * @return string
1904
-     * @throws SodiumException
1905
-     */
1906
-    public static function crypto_kx_publickey($kp)
1907
-    {
1908
-        return ParagonIE_Sodium_Core_Util::substr(
1909
-            $kp,
1910
-            self::CRYPTO_KX_SECRETKEYBYTES,
1911
-            self::CRYPTO_KX_PUBLICKEYBYTES
1912
-        );
1913
-    }
1914
-
1915
-    /**
1916
-     * @param int $outlen
1917
-     * @param string $passwd
1918
-     * @param string $salt
1919
-     * @param int $opslimit
1920
-     * @param int $memlimit
1921
-     * @param int|null $alg
1922
-     * @return string
1923
-     * @throws SodiumException
1924
-     * @throws TypeError
1925
-     * @psalm-suppress MixedArgument
1926
-     */
1927
-    public static function crypto_pwhash($outlen, $passwd, $salt, $opslimit, $memlimit, $alg = null)
1928
-    {
1929
-        ParagonIE_Sodium_Core_Util::declareScalarType($outlen, 'int', 1);
1930
-        ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 2);
1931
-        ParagonIE_Sodium_Core_Util::declareScalarType($salt,  'string', 3);
1932
-        ParagonIE_Sodium_Core_Util::declareScalarType($opslimit, 'int', 4);
1933
-        ParagonIE_Sodium_Core_Util::declareScalarType($memlimit, 'int', 5);
1934
-
1935
-        if (self::useNewSodiumAPI()) {
1936
-            if (!is_null($alg)) {
1937
-                ParagonIE_Sodium_Core_Util::declareScalarType($alg, 'int', 6);
1938
-                return sodium_crypto_pwhash($outlen, $passwd, $salt, $opslimit, $memlimit, $alg);
1939
-            }
1940
-            return sodium_crypto_pwhash($outlen, $passwd, $salt, $opslimit, $memlimit);
1941
-        }
1942
-        if (self::use_fallback('crypto_pwhash')) {
1943
-            return (string) call_user_func('\\Sodium\\crypto_pwhash', $outlen, $passwd, $salt, $opslimit, $memlimit);
1944
-        }
1945
-        // This is the best we can do.
1946
-        throw new SodiumException(
1947
-            'This is not implemented, as it is not possible to implement Argon2i with acceptable performance in pure-PHP'
1948
-        );
1949
-    }
1950
-
1951
-    /**
1952
-     * !Exclusive to sodium_compat!
1953
-     *
1954
-     * This returns TRUE if the native crypto_pwhash API is available by libsodium.
1955
-     * This returns FALSE if only sodium_compat is available.
1956
-     *
1957
-     * @return bool
1958
-     */
1959
-    public static function crypto_pwhash_is_available()
1960
-    {
1961
-        if (self::useNewSodiumAPI()) {
1962
-            return true;
1963
-        }
1964
-        if (self::use_fallback('crypto_pwhash')) {
1965
-            return true;
1966
-        }
1967
-        return false;
1968
-    }
1969
-
1970
-    /**
1971
-     * @param string $passwd
1972
-     * @param int $opslimit
1973
-     * @param int $memlimit
1974
-     * @return string
1975
-     * @throws SodiumException
1976
-     * @throws TypeError
1977
-     * @psalm-suppress MixedArgument
1978
-     */
1979
-    public static function crypto_pwhash_str($passwd, $opslimit, $memlimit)
1980
-    {
1981
-        ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 1);
1982
-        ParagonIE_Sodium_Core_Util::declareScalarType($opslimit, 'int', 2);
1983
-        ParagonIE_Sodium_Core_Util::declareScalarType($memlimit, 'int', 3);
1984
-
1985
-        if (self::useNewSodiumAPI()) {
1986
-            return sodium_crypto_pwhash_str($passwd, $opslimit, $memlimit);
1987
-        }
1988
-        if (self::use_fallback('crypto_pwhash_str')) {
1989
-            return (string) call_user_func('\\Sodium\\crypto_pwhash_str', $passwd, $opslimit, $memlimit);
1990
-        }
1991
-        // This is the best we can do.
1992
-        throw new SodiumException(
1993
-            'This is not implemented, as it is not possible to implement Argon2i with acceptable performance in pure-PHP'
1994
-        );
1995
-    }
1996
-
1997
-    /**
1998
-     * Do we need to rehash this password?
1999
-     *
2000
-     * @param string $hash
2001
-     * @param int $opslimit
2002
-     * @param int $memlimit
2003
-     * @return bool
2004
-     * @throws SodiumException
2005
-     */
2006
-    public static function crypto_pwhash_str_needs_rehash($hash, $opslimit, $memlimit)
2007
-    {
2008
-        ParagonIE_Sodium_Core_Util::declareScalarType($hash, 'string', 1);
2009
-        ParagonIE_Sodium_Core_Util::declareScalarType($opslimit, 'int', 2);
2010
-        ParagonIE_Sodium_Core_Util::declareScalarType($memlimit, 'int', 3);
2011
-
2012
-        // Just grab the first 4 pieces.
2013
-        $pieces = explode('$', (string) $hash);
2014
-        $prefix = implode('$', array_slice($pieces, 0, 4));
2015
-
2016
-        // Rebuild the expected header.
2017
-        /** @var int $ops */
2018
-        $ops = (int) $opslimit;
2019
-        /** @var int $mem */
2020
-        $mem = (int) $memlimit >> 10;
2021
-        $encoded = self::CRYPTO_PWHASH_STRPREFIX . 'v=19$m=' . $mem . ',t=' . $ops . ',p=1';
2022
-
2023
-        // Do they match? If so, we don't need to rehash, so return false.
2024
-        return !ParagonIE_Sodium_Core_Util::hashEquals($encoded, $prefix);
2025
-    }
2026
-
2027
-    /**
2028
-     * @param string $passwd
2029
-     * @param string $hash
2030
-     * @return bool
2031
-     * @throws SodiumException
2032
-     * @throws TypeError
2033
-     * @psalm-suppress MixedArgument
2034
-     */
2035
-    public static function crypto_pwhash_str_verify($passwd, $hash)
2036
-    {
2037
-        ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 1);
2038
-        ParagonIE_Sodium_Core_Util::declareScalarType($hash, 'string', 2);
2039
-
2040
-        if (self::useNewSodiumAPI()) {
2041
-            return (bool) sodium_crypto_pwhash_str_verify($passwd, $hash);
2042
-        }
2043
-        if (self::use_fallback('crypto_pwhash_str_verify')) {
2044
-            return (bool) call_user_func('\\Sodium\\crypto_pwhash_str_verify', $passwd, $hash);
2045
-        }
2046
-        // This is the best we can do.
2047
-        throw new SodiumException(
2048
-            'This is not implemented, as it is not possible to implement Argon2i with acceptable performance in pure-PHP'
2049
-        );
2050
-    }
2051
-
2052
-    /**
2053
-     * @param int $outlen
2054
-     * @param string $passwd
2055
-     * @param string $salt
2056
-     * @param int $opslimit
2057
-     * @param int $memlimit
2058
-     * @return string
2059
-     * @throws SodiumException
2060
-     * @throws TypeError
2061
-     */
2062
-    public static function crypto_pwhash_scryptsalsa208sha256($outlen, $passwd, $salt, $opslimit, $memlimit)
2063
-    {
2064
-        ParagonIE_Sodium_Core_Util::declareScalarType($outlen, 'int', 1);
2065
-        ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 2);
2066
-        ParagonIE_Sodium_Core_Util::declareScalarType($salt,  'string', 3);
2067
-        ParagonIE_Sodium_Core_Util::declareScalarType($opslimit, 'int', 4);
2068
-        ParagonIE_Sodium_Core_Util::declareScalarType($memlimit, 'int', 5);
2069
-
2070
-        if (self::useNewSodiumAPI()) {
2071
-            return (string) sodium_crypto_pwhash_scryptsalsa208sha256(
2072
-                (int) $outlen,
2073
-                (string) $passwd,
2074
-                (string) $salt,
2075
-                (int) $opslimit,
2076
-                (int) $memlimit
2077
-            );
2078
-        }
2079
-        if (self::use_fallback('crypto_pwhash_scryptsalsa208sha256')) {
2080
-            return (string) call_user_func(
2081
-                '\\Sodium\\crypto_pwhash_scryptsalsa208sha256',
2082
-                (int) $outlen,
2083
-                (string) $passwd,
2084
-                (string) $salt,
2085
-                (int) $opslimit,
2086
-                (int) $memlimit
2087
-            );
2088
-        }
2089
-        // This is the best we can do.
2090
-        throw new SodiumException(
2091
-            'This is not implemented, as it is not possible to implement Scrypt with acceptable performance in pure-PHP'
2092
-        );
2093
-    }
2094
-
2095
-    /**
2096
-     * !Exclusive to sodium_compat!
2097
-     *
2098
-     * This returns TRUE if the native crypto_pwhash API is available by libsodium.
2099
-     * This returns FALSE if only sodium_compat is available.
2100
-     *
2101
-     * @return bool
2102
-     */
2103
-    public static function crypto_pwhash_scryptsalsa208sha256_is_available()
2104
-    {
2105
-        if (self::useNewSodiumAPI()) {
2106
-            return true;
2107
-        }
2108
-        if (self::use_fallback('crypto_pwhash_scryptsalsa208sha256')) {
2109
-            return true;
2110
-        }
2111
-        return false;
2112
-    }
2113
-
2114
-    /**
2115
-     * @param string $passwd
2116
-     * @param int $opslimit
2117
-     * @param int $memlimit
2118
-     * @return string
2119
-     * @throws SodiumException
2120
-     * @throws TypeError
2121
-     */
2122
-    public static function crypto_pwhash_scryptsalsa208sha256_str($passwd, $opslimit, $memlimit)
2123
-    {
2124
-        ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 1);
2125
-        ParagonIE_Sodium_Core_Util::declareScalarType($opslimit, 'int', 2);
2126
-        ParagonIE_Sodium_Core_Util::declareScalarType($memlimit, 'int', 3);
2127
-
2128
-        if (self::useNewSodiumAPI()) {
2129
-            return (string) sodium_crypto_pwhash_scryptsalsa208sha256_str(
2130
-                (string) $passwd,
2131
-                (int) $opslimit,
2132
-                (int) $memlimit
2133
-            );
2134
-        }
2135
-        if (self::use_fallback('crypto_pwhash_scryptsalsa208sha256_str')) {
2136
-            return (string) call_user_func(
2137
-                '\\Sodium\\crypto_pwhash_scryptsalsa208sha256_str',
2138
-                (string) $passwd,
2139
-                (int) $opslimit,
2140
-                (int) $memlimit
2141
-            );
2142
-        }
2143
-        // This is the best we can do.
2144
-        throw new SodiumException(
2145
-            'This is not implemented, as it is not possible to implement Scrypt with acceptable performance in pure-PHP'
2146
-        );
2147
-    }
2148
-
2149
-    /**
2150
-     * @param string $passwd
2151
-     * @param string $hash
2152
-     * @return bool
2153
-     * @throws SodiumException
2154
-     * @throws TypeError
2155
-     */
2156
-    public static function crypto_pwhash_scryptsalsa208sha256_str_verify($passwd, $hash)
2157
-    {
2158
-        ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 1);
2159
-        ParagonIE_Sodium_Core_Util::declareScalarType($hash, 'string', 2);
2160
-
2161
-        if (self::useNewSodiumAPI()) {
2162
-            return (bool) sodium_crypto_pwhash_scryptsalsa208sha256_str_verify(
2163
-                (string) $passwd,
2164
-                (string) $hash
2165
-            );
2166
-        }
2167
-        if (self::use_fallback('crypto_pwhash_scryptsalsa208sha256_str_verify')) {
2168
-            return (bool) call_user_func(
2169
-                '\\Sodium\\crypto_pwhash_scryptsalsa208sha256_str_verify',
2170
-                (string) $passwd,
2171
-                (string) $hash
2172
-            );
2173
-        }
2174
-        // This is the best we can do.
2175
-        throw new SodiumException(
2176
-            'This is not implemented, as it is not possible to implement Scrypt with acceptable performance in pure-PHP'
2177
-        );
2178
-    }
2179
-
2180
-    /**
2181
-     * Calculate the shared secret between your secret key and your
2182
-     * recipient's public key.
2183
-     *
2184
-     * Algorithm: X25519 (ECDH over Curve25519)
2185
-     *
2186
-     * @param string $secretKey
2187
-     * @param string $publicKey
2188
-     * @return string
2189
-     * @throws SodiumException
2190
-     * @throws TypeError
2191
-     * @psalm-suppress MixedArgument
2192
-     */
2193
-    public static function crypto_scalarmult($secretKey, $publicKey)
2194
-    {
2195
-        /* Type checks: */
2196
-        ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 1);
2197
-        ParagonIE_Sodium_Core_Util::declareScalarType($publicKey, 'string', 2);
2198
-
2199
-        /* Input validation: */
2200
-        if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_BOX_SECRETKEYBYTES) {
2201
-            throw new SodiumException('Argument 1 must be CRYPTO_BOX_SECRETKEYBYTES long.');
2202
-        }
2203
-        if (ParagonIE_Sodium_Core_Util::strlen($publicKey) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
2204
-            throw new SodiumException('Argument 2 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
2205
-        }
2206
-
2207
-        if (self::useNewSodiumAPI()) {
2208
-            return sodium_crypto_scalarmult($secretKey, $publicKey);
2209
-        }
2210
-        if (self::use_fallback('crypto_scalarmult')) {
2211
-            return (string) call_user_func('\\Sodium\\crypto_scalarmult', $secretKey, $publicKey);
2212
-        }
2213
-
2214
-        /* Output validation: Forbid all-zero keys */
2215
-        if (ParagonIE_Sodium_Core_Util::hashEquals($secretKey, str_repeat("\0", self::CRYPTO_BOX_SECRETKEYBYTES))) {
2216
-            throw new SodiumException('Zero secret key is not allowed');
2217
-        }
2218
-        if (ParagonIE_Sodium_Core_Util::hashEquals($publicKey, str_repeat("\0", self::CRYPTO_BOX_PUBLICKEYBYTES))) {
2219
-            throw new SodiumException('Zero public key is not allowed');
2220
-        }
2221
-        if (PHP_INT_SIZE === 4) {
2222
-            return ParagonIE_Sodium_Crypto32::scalarmult($secretKey, $publicKey);
2223
-        }
2224
-        return ParagonIE_Sodium_Crypto::scalarmult($secretKey, $publicKey);
2225
-    }
2226
-
2227
-    /**
2228
-     * Calculate an X25519 public key from an X25519 secret key.
2229
-     *
2230
-     * @param string $secretKey
2231
-     * @return string
2232
-     * @throws SodiumException
2233
-     * @throws TypeError
2234
-     * @psalm-suppress TooFewArguments
2235
-     * @psalm-suppress MixedArgument
2236
-     */
2237
-    public static function crypto_scalarmult_base($secretKey)
2238
-    {
2239
-        /* Type checks: */
2240
-        ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 1);
2241
-
2242
-        /* Input validation: */
2243
-        if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_BOX_SECRETKEYBYTES) {
2244
-            throw new SodiumException('Argument 1 must be CRYPTO_BOX_SECRETKEYBYTES long.');
2245
-        }
2246
-
2247
-        if (self::useNewSodiumAPI()) {
2248
-            return sodium_crypto_scalarmult_base($secretKey);
2249
-        }
2250
-        if (self::use_fallback('crypto_scalarmult_base')) {
2251
-            return (string) call_user_func('\\Sodium\\crypto_scalarmult_base', $secretKey);
2252
-        }
2253
-        if (ParagonIE_Sodium_Core_Util::hashEquals($secretKey, str_repeat("\0", self::CRYPTO_BOX_SECRETKEYBYTES))) {
2254
-            throw new SodiumException('Zero secret key is not allowed');
2255
-        }
2256
-        if (PHP_INT_SIZE === 4) {
2257
-            return ParagonIE_Sodium_Crypto32::scalarmult_base($secretKey);
2258
-        }
2259
-        return ParagonIE_Sodium_Crypto::scalarmult_base($secretKey);
2260
-    }
2261
-
2262
-    /**
2263
-     * Authenticated symmetric-key encryption.
2264
-     *
2265
-     * Algorithm: XSalsa20-Poly1305
2266
-     *
2267
-     * @param string $plaintext The message you're encrypting
2268
-     * @param string $nonce A Number to be used Once; must be 24 bytes
2269
-     * @param string $key Symmetric encryption key
2270
-     * @return string           Ciphertext with Poly1305 MAC
2271
-     * @throws SodiumException
2272
-     * @throws TypeError
2273
-     * @psalm-suppress MixedArgument
2274
-     */
2275
-    public static function crypto_secretbox($plaintext, $nonce, $key)
2276
-    {
2277
-        /* Type checks: */
2278
-        ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
2279
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
2280
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
2281
-
2282
-        /* Input validation: */
2283
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_SECRETBOX_NONCEBYTES) {
2284
-            throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
2285
-        }
2286
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_SECRETBOX_KEYBYTES) {
2287
-            throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_KEYBYTES long.');
2288
-        }
2289
-
2290
-        if (self::useNewSodiumAPI()) {
2291
-            return sodium_crypto_secretbox($plaintext, $nonce, $key);
2292
-        }
2293
-        if (self::use_fallback('crypto_secretbox')) {
2294
-            return (string) call_user_func('\\Sodium\\crypto_secretbox', $plaintext, $nonce, $key);
2295
-        }
2296
-        if (PHP_INT_SIZE === 4) {
2297
-            return ParagonIE_Sodium_Crypto32::secretbox($plaintext, $nonce, $key);
2298
-        }
2299
-        return ParagonIE_Sodium_Crypto::secretbox($plaintext, $nonce, $key);
2300
-    }
2301
-
2302
-    /**
2303
-     * Decrypts a message previously encrypted with crypto_secretbox().
2304
-     *
2305
-     * @param string $ciphertext Ciphertext with Poly1305 MAC
2306
-     * @param string $nonce      A Number to be used Once; must be 24 bytes
2307
-     * @param string $key        Symmetric encryption key
2308
-     * @return string            Original plaintext message
2309
-     * @throws SodiumException
2310
-     * @throws TypeError
2311
-     * @psalm-suppress MixedArgument
2312
-     * @psalm-suppress MixedInferredReturnType
2313
-     * @psalm-suppress MixedReturnStatement
2314
-     */
2315
-    public static function crypto_secretbox_open($ciphertext, $nonce, $key)
2316
-    {
2317
-        /* Type checks: */
2318
-        ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
2319
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
2320
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
2321
-
2322
-        /* Input validation: */
2323
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_SECRETBOX_NONCEBYTES) {
2324
-            throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
2325
-        }
2326
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_SECRETBOX_KEYBYTES) {
2327
-            throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_KEYBYTES long.');
2328
-        }
2329
-
2330
-        if (self::useNewSodiumAPI()) {
2331
-            /**
2332
-             * @psalm-suppress InvalidReturnStatement
2333
-             * @psalm-suppress FalsableReturnStatement
2334
-             */
2335
-            return sodium_crypto_secretbox_open($ciphertext, $nonce, $key);
2336
-        }
2337
-        if (self::use_fallback('crypto_secretbox_open')) {
2338
-            return call_user_func('\\Sodium\\crypto_secretbox_open', $ciphertext, $nonce, $key);
2339
-        }
2340
-        if (PHP_INT_SIZE === 4) {
2341
-            return ParagonIE_Sodium_Crypto32::secretbox_open($ciphertext, $nonce, $key);
2342
-        }
2343
-        return ParagonIE_Sodium_Crypto::secretbox_open($ciphertext, $nonce, $key);
2344
-    }
2345
-
2346
-    /**
2347
-     * Return a secure random key for use with crypto_secretbox
2348
-     *
2349
-     * @return string
2350
-     * @throws Exception
2351
-     * @throws Error
2352
-     */
2353
-    public static function crypto_secretbox_keygen()
2354
-    {
2355
-        return random_bytes(self::CRYPTO_SECRETBOX_KEYBYTES);
2356
-    }
2357
-
2358
-    /**
2359
-     * Authenticated symmetric-key encryption.
2360
-     *
2361
-     * Algorithm: XChaCha20-Poly1305
2362
-     *
2363
-     * @param string $plaintext The message you're encrypting
2364
-     * @param string $nonce     A Number to be used Once; must be 24 bytes
2365
-     * @param string $key       Symmetric encryption key
2366
-     * @return string           Ciphertext with Poly1305 MAC
2367
-     * @throws SodiumException
2368
-     * @throws TypeError
2369
-     * @psalm-suppress MixedArgument
2370
-     */
2371
-    public static function crypto_secretbox_xchacha20poly1305($plaintext, $nonce, $key)
2372
-    {
2373
-        /* Type checks: */
2374
-        ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
2375
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
2376
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
2377
-
2378
-        /* Input validation: */
2379
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_SECRETBOX_NONCEBYTES) {
2380
-            throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
2381
-        }
2382
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_SECRETBOX_KEYBYTES) {
2383
-            throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_KEYBYTES long.');
2384
-        }
2385
-        if (PHP_INT_SIZE === 4) {
2386
-            return ParagonIE_Sodium_Crypto32::secretbox_xchacha20poly1305($plaintext, $nonce, $key);
2387
-        }
2388
-        return ParagonIE_Sodium_Crypto::secretbox_xchacha20poly1305($plaintext, $nonce, $key);
2389
-    }
2390
-    /**
2391
-     * Decrypts a message previously encrypted with crypto_secretbox_xchacha20poly1305().
2392
-     *
2393
-     * @param string $ciphertext Ciphertext with Poly1305 MAC
2394
-     * @param string $nonce      A Number to be used Once; must be 24 bytes
2395
-     * @param string $key        Symmetric encryption key
2396
-     * @return string            Original plaintext message
2397
-     * @throws SodiumException
2398
-     * @throws TypeError
2399
-     * @psalm-suppress MixedArgument
2400
-     */
2401
-    public static function crypto_secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key)
2402
-    {
2403
-        /* Type checks: */
2404
-        ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
2405
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
2406
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
2407
-
2408
-        /* Input validation: */
2409
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_SECRETBOX_NONCEBYTES) {
2410
-            throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
2411
-        }
2412
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_SECRETBOX_KEYBYTES) {
2413
-            throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_KEYBYTES long.');
2414
-        }
2415
-
2416
-        if (PHP_INT_SIZE === 4) {
2417
-            return ParagonIE_Sodium_Crypto32::secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key);
2418
-        }
2419
-        return ParagonIE_Sodium_Crypto::secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key);
2420
-    }
2421
-
2422
-    /**
2423
-     * @param string $key
2424
-     * @return array<int, string> Returns a state and a header.
2425
-     * @throws Exception
2426
-     * @throws SodiumException
2427
-     */
2428
-    public static function crypto_secretstream_xchacha20poly1305_init_push($key)
2429
-    {
2430
-        if (PHP_INT_SIZE === 4) {
2431
-            return ParagonIE_Sodium_Crypto32::secretstream_xchacha20poly1305_init_push($key);
2432
-        }
2433
-        return ParagonIE_Sodium_Crypto::secretstream_xchacha20poly1305_init_push($key);
2434
-    }
2435
-
2436
-    /**
2437
-     * @param string $header
2438
-     * @param string $key
2439
-     * @return string Returns a state.
2440
-     * @throws Exception
2441
-     */
2442
-    public static function crypto_secretstream_xchacha20poly1305_init_pull($header, $key)
2443
-    {
2444
-        if (ParagonIE_Sodium_Core_Util::strlen($header) < self::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_HEADERBYTES) {
2445
-            throw new SodiumException(
2446
-                'header size should be SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_HEADERBYTES bytes'
2447
-            );
2448
-        }
2449
-        if (PHP_INT_SIZE === 4) {
2450
-            return ParagonIE_Sodium_Crypto32::secretstream_xchacha20poly1305_init_pull($key, $header);
2451
-        }
2452
-        return ParagonIE_Sodium_Crypto::secretstream_xchacha20poly1305_init_pull($key, $header);
2453
-    }
2454
-
2455
-    /**
2456
-     * @param string $state
2457
-     * @param string $msg
2458
-     * @param string $aad
2459
-     * @param int $tag
2460
-     * @return string
2461
-     * @throws SodiumException
2462
-     */
2463
-    public static function crypto_secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0)
2464
-    {
2465
-        if (PHP_INT_SIZE === 4) {
2466
-            return ParagonIE_Sodium_Crypto32::secretstream_xchacha20poly1305_push(
2467
-                $state,
2468
-                $msg,
2469
-                $aad,
2470
-                $tag
2471
-            );
2472
-        }
2473
-        return ParagonIE_Sodium_Crypto::secretstream_xchacha20poly1305_push(
2474
-            $state,
2475
-            $msg,
2476
-            $aad,
2477
-            $tag
2478
-        );
2479
-    }
2480
-
2481
-    /**
2482
-     * @param string $state
2483
-     * @param string $msg
2484
-     * @param string $aad
2485
-     * @return bool|array{0: string, 1: int}
2486
-     * @throws SodiumException
2487
-     */
2488
-    public static function crypto_secretstream_xchacha20poly1305_pull(&$state, $msg, $aad = '')
2489
-    {
2490
-        if (PHP_INT_SIZE === 4) {
2491
-            return ParagonIE_Sodium_Crypto32::secretstream_xchacha20poly1305_pull(
2492
-                $state,
2493
-                $msg,
2494
-                $aad
2495
-            );
2496
-        }
2497
-        return ParagonIE_Sodium_Crypto::secretstream_xchacha20poly1305_pull(
2498
-            $state,
2499
-            $msg,
2500
-            $aad
2501
-        );
2502
-    }
2503
-
2504
-    /**
2505
-     * @return string
2506
-     * @throws Exception
2507
-     */
2508
-    public static function crypto_secretstream_xchacha20poly1305_keygen()
2509
-    {
2510
-        return random_bytes(self::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_KEYBYTES);
2511
-    }
2512
-
2513
-    /**
2514
-     * @param string $state
2515
-     * @return void
2516
-     * @throws SodiumException
2517
-     */
2518
-    public static function crypto_secretstream_xchacha20poly1305_rekey(&$state)
2519
-    {
2520
-        if (PHP_INT_SIZE === 4) {
2521
-            ParagonIE_Sodium_Crypto32::secretstream_xchacha20poly1305_rekey($state);
2522
-        } else {
2523
-            ParagonIE_Sodium_Crypto::secretstream_xchacha20poly1305_rekey($state);
2524
-        }
2525
-    }
2526
-
2527
-    /**
2528
-     * Calculates a SipHash-2-4 hash of a message for a given key.
2529
-     *
2530
-     * @param string $message Input message
2531
-     * @param string $key SipHash-2-4 key
2532
-     * @return string         Hash
2533
-     * @throws SodiumException
2534
-     * @throws TypeError
2535
-     * @psalm-suppress MixedArgument
2536
-     * @psalm-suppress MixedInferredReturnType
2537
-     * @psalm-suppress MixedReturnStatement
2538
-     */
2539
-    public static function crypto_shorthash($message, $key)
2540
-    {
2541
-        /* Type checks: */
2542
-        ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
2543
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 2);
2544
-
2545
-        /* Input validation: */
2546
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_SHORTHASH_KEYBYTES) {
2547
-            throw new SodiumException('Argument 2 must be CRYPTO_SHORTHASH_KEYBYTES long.');
2548
-        }
2549
-
2550
-        if (self::useNewSodiumAPI()) {
2551
-            return sodium_crypto_shorthash($message, $key);
2552
-        }
2553
-        if (self::use_fallback('crypto_shorthash')) {
2554
-            return (string) call_user_func('\\Sodium\\crypto_shorthash', $message, $key);
2555
-        }
2556
-        if (PHP_INT_SIZE === 4) {
2557
-            return ParagonIE_Sodium_Core32_SipHash::sipHash24($message, $key);
2558
-        }
2559
-        return ParagonIE_Sodium_Core_SipHash::sipHash24($message, $key);
2560
-    }
2561
-
2562
-    /**
2563
-     * Return a secure random key for use with crypto_shorthash
2564
-     *
2565
-     * @return string
2566
-     * @throws Exception
2567
-     * @throws Error
2568
-     */
2569
-    public static function crypto_shorthash_keygen()
2570
-    {
2571
-        return random_bytes(self::CRYPTO_SHORTHASH_KEYBYTES);
2572
-    }
2573
-
2574
-    /**
2575
-     * Returns a signed message. You probably want crypto_sign_detached()
2576
-     * instead, which only returns the signature.
2577
-     *
2578
-     * Algorithm: Ed25519 (EdDSA over Curve25519)
2579
-     *
2580
-     * @param string $message Message to be signed.
2581
-     * @param string $secretKey Secret signing key.
2582
-     * @return string           Signed message (signature is prefixed).
2583
-     * @throws SodiumException
2584
-     * @throws TypeError
2585
-     * @psalm-suppress MixedArgument
2586
-     * @psalm-suppress MixedInferredReturnType
2587
-     * @psalm-suppress MixedReturnStatement
2588
-     */
2589
-    public static function crypto_sign($message, $secretKey)
2590
-    {
2591
-        /* Type checks: */
2592
-        ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
2593
-        ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 2);
2594
-
2595
-        /* Input validation: */
2596
-        if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_SIGN_SECRETKEYBYTES) {
2597
-            throw new SodiumException('Argument 2 must be CRYPTO_SIGN_SECRETKEYBYTES long.');
2598
-        }
2599
-
2600
-        if (self::useNewSodiumAPI()) {
2601
-            return sodium_crypto_sign($message, $secretKey);
2602
-        }
2603
-        if (self::use_fallback('crypto_sign')) {
2604
-            return (string) call_user_func('\\Sodium\\crypto_sign', $message, $secretKey);
2605
-        }
2606
-        if (PHP_INT_SIZE === 4) {
2607
-            return ParagonIE_Sodium_Crypto32::sign($message, $secretKey);
2608
-        }
2609
-        return ParagonIE_Sodium_Crypto::sign($message, $secretKey);
2610
-    }
2611
-
2612
-    /**
2613
-     * Validates a signed message then returns the message.
2614
-     *
2615
-     * @param string $signedMessage A signed message
2616
-     * @param string $publicKey A public key
2617
-     * @return string               The original message (if the signature is
2618
-     *                              valid for this public key)
2619
-     * @throws SodiumException
2620
-     * @throws TypeError
2621
-     * @psalm-suppress MixedArgument
2622
-     * @psalm-suppress MixedInferredReturnType
2623
-     * @psalm-suppress MixedReturnStatement
2624
-     */
2625
-    public static function crypto_sign_open($signedMessage, $publicKey)
2626
-    {
2627
-        /* Type checks: */
2628
-        ParagonIE_Sodium_Core_Util::declareScalarType($signedMessage, 'string', 1);
2629
-        ParagonIE_Sodium_Core_Util::declareScalarType($publicKey, 'string', 2);
2630
-
2631
-        /* Input validation: */
2632
-        if (ParagonIE_Sodium_Core_Util::strlen($signedMessage) < self::CRYPTO_SIGN_BYTES) {
2633
-            throw new SodiumException('Argument 1 must be at least CRYPTO_SIGN_BYTES long.');
2634
-        }
2635
-        if (ParagonIE_Sodium_Core_Util::strlen($publicKey) !== self::CRYPTO_SIGN_PUBLICKEYBYTES) {
2636
-            throw new SodiumException('Argument 2 must be CRYPTO_SIGN_PUBLICKEYBYTES long.');
2637
-        }
2638
-
2639
-        if (self::useNewSodiumAPI()) {
2640
-            /**
2641
-             * @psalm-suppress InvalidReturnStatement
2642
-             * @psalm-suppress FalsableReturnStatement
2643
-             */
2644
-            return sodium_crypto_sign_open($signedMessage, $publicKey);
2645
-        }
2646
-        if (self::use_fallback('crypto_sign_open')) {
2647
-            return call_user_func('\\Sodium\\crypto_sign_open', $signedMessage, $publicKey);
2648
-        }
2649
-        if (PHP_INT_SIZE === 4) {
2650
-            return ParagonIE_Sodium_Crypto32::sign_open($signedMessage, $publicKey);
2651
-        }
2652
-        return ParagonIE_Sodium_Crypto::sign_open($signedMessage, $publicKey);
2653
-    }
2654
-
2655
-    /**
2656
-     * Generate a new random Ed25519 keypair.
2657
-     *
2658
-     * @return string
2659
-     * @throws SodiumException
2660
-     * @throws TypeError
2661
-     */
2662
-    public static function crypto_sign_keypair()
2663
-    {
2664
-        if (self::useNewSodiumAPI()) {
2665
-            return sodium_crypto_sign_keypair();
2666
-        }
2667
-        if (self::use_fallback('crypto_sign_keypair')) {
2668
-            return (string) call_user_func('\\Sodium\\crypto_sign_keypair');
2669
-        }
2670
-        if (PHP_INT_SIZE === 4) {
2671
-            return ParagonIE_Sodium_Core32_Ed25519::keypair();
2672
-        }
2673
-        return ParagonIE_Sodium_Core_Ed25519::keypair();
2674
-    }
2675
-
2676
-    /**
2677
-     * @param string $sk
2678
-     * @param string $pk
2679
-     * @return string
2680
-     * @throws SodiumException
2681
-     */
2682
-    public static function crypto_sign_keypair_from_secretkey_and_publickey($sk, $pk)
2683
-    {
2684
-        ParagonIE_Sodium_Core_Util::declareScalarType($sk, 'string', 1);
2685
-        ParagonIE_Sodium_Core_Util::declareScalarType($pk, 'string', 1);
2686
-        $sk = (string) $sk;
2687
-        $pk = (string) $pk;
2688
-
2689
-        if (ParagonIE_Sodium_Core_Util::strlen($sk) !== self::CRYPTO_SIGN_SECRETKEYBYTES) {
2690
-            throw new SodiumException('secretkey should be SODIUM_CRYPTO_SIGN_SECRETKEYBYTES bytes');
2691
-        }
2692
-        if (ParagonIE_Sodium_Core_Util::strlen($pk) !== self::CRYPTO_SIGN_PUBLICKEYBYTES) {
2693
-            throw new SodiumException('publickey should be SODIUM_CRYPTO_SIGN_PUBLICKEYBYTES bytes');
2694
-        }
2695
-
2696
-        if (self::useNewSodiumAPI()) {
2697
-            return sodium_crypto_sign_keypair_from_secretkey_and_publickey($sk, $pk);
2698
-        }
2699
-        return $sk . $pk;
2700
-    }
2701
-
2702
-    /**
2703
-     * Generate an Ed25519 keypair from a seed.
2704
-     *
2705
-     * @param string $seed Input seed
2706
-     * @return string      Keypair
2707
-     * @throws SodiumException
2708
-     * @throws TypeError
2709
-     * @psalm-suppress MixedArgument
2710
-     */
2711
-    public static function crypto_sign_seed_keypair($seed)
2712
-    {
2713
-        ParagonIE_Sodium_Core_Util::declareScalarType($seed, 'string', 1);
2714
-
2715
-        if (self::useNewSodiumAPI()) {
2716
-            return sodium_crypto_sign_seed_keypair($seed);
2717
-        }
2718
-        if (self::use_fallback('crypto_sign_keypair')) {
2719
-            return (string) call_user_func('\\Sodium\\crypto_sign_seed_keypair', $seed);
2720
-        }
2721
-        $publicKey = '';
2722
-        $secretKey = '';
2723
-        if (PHP_INT_SIZE === 4) {
2724
-            ParagonIE_Sodium_Core32_Ed25519::seed_keypair($publicKey, $secretKey, $seed);
2725
-        } else {
2726
-            ParagonIE_Sodium_Core_Ed25519::seed_keypair($publicKey, $secretKey, $seed);
2727
-        }
2728
-        return $secretKey . $publicKey;
2729
-    }
2730
-
2731
-    /**
2732
-     * Extract an Ed25519 public key from an Ed25519 keypair.
2733
-     *
2734
-     * @param string $keypair Keypair
2735
-     * @return string         Public key
2736
-     * @throws SodiumException
2737
-     * @throws TypeError
2738
-     * @psalm-suppress MixedArgument
2739
-     */
2740
-    public static function crypto_sign_publickey($keypair)
2741
-    {
2742
-        /* Type checks: */
2743
-        ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
2744
-
2745
-        /* Input validation: */
2746
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_SIGN_KEYPAIRBYTES) {
2747
-            throw new SodiumException('Argument 1 must be CRYPTO_SIGN_KEYPAIRBYTES long.');
2748
-        }
2749
-
2750
-        if (self::useNewSodiumAPI()) {
2751
-            return sodium_crypto_sign_publickey($keypair);
2752
-        }
2753
-        if (self::use_fallback('crypto_sign_publickey')) {
2754
-            return (string) call_user_func('\\Sodium\\crypto_sign_publickey', $keypair);
2755
-        }
2756
-        if (PHP_INT_SIZE === 4) {
2757
-            return ParagonIE_Sodium_Core32_Ed25519::publickey($keypair);
2758
-        }
2759
-        return ParagonIE_Sodium_Core_Ed25519::publickey($keypair);
2760
-    }
2761
-
2762
-    /**
2763
-     * Calculate an Ed25519 public key from an Ed25519 secret key.
2764
-     *
2765
-     * @param string $secretKey Your Ed25519 secret key
2766
-     * @return string           The corresponding Ed25519 public key
2767
-     * @throws SodiumException
2768
-     * @throws TypeError
2769
-     * @psalm-suppress MixedArgument
2770
-     */
2771
-    public static function crypto_sign_publickey_from_secretkey($secretKey)
2772
-    {
2773
-        /* Type checks: */
2774
-        ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 1);
2775
-
2776
-        /* Input validation: */
2777
-        if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_SIGN_SECRETKEYBYTES) {
2778
-            throw new SodiumException('Argument 1 must be CRYPTO_SIGN_SECRETKEYBYTES long.');
2779
-        }
2780
-
2781
-        if (self::useNewSodiumAPI()) {
2782
-            return sodium_crypto_sign_publickey_from_secretkey($secretKey);
2783
-        }
2784
-        if (self::use_fallback('crypto_sign_publickey_from_secretkey')) {
2785
-            return (string) call_user_func('\\Sodium\\crypto_sign_publickey_from_secretkey', $secretKey);
2786
-        }
2787
-        if (PHP_INT_SIZE === 4) {
2788
-            return ParagonIE_Sodium_Core32_Ed25519::publickey_from_secretkey($secretKey);
2789
-        }
2790
-        return ParagonIE_Sodium_Core_Ed25519::publickey_from_secretkey($secretKey);
2791
-    }
2792
-
2793
-    /**
2794
-     * Extract an Ed25519 secret key from an Ed25519 keypair.
2795
-     *
2796
-     * @param string $keypair Keypair
2797
-     * @return string         Secret key
2798
-     * @throws SodiumException
2799
-     * @throws TypeError
2800
-     * @psalm-suppress MixedArgument
2801
-     */
2802
-    public static function crypto_sign_secretkey($keypair)
2803
-    {
2804
-        /* Type checks: */
2805
-        ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
2806
-
2807
-        /* Input validation: */
2808
-        if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_SIGN_KEYPAIRBYTES) {
2809
-            throw new SodiumException('Argument 1 must be CRYPTO_SIGN_KEYPAIRBYTES long.');
2810
-        }
2811
-
2812
-        if (self::useNewSodiumAPI()) {
2813
-            return sodium_crypto_sign_secretkey($keypair);
2814
-        }
2815
-        if (self::use_fallback('crypto_sign_secretkey')) {
2816
-            return (string) call_user_func('\\Sodium\\crypto_sign_secretkey', $keypair);
2817
-        }
2818
-        if (PHP_INT_SIZE === 4) {
2819
-            return ParagonIE_Sodium_Core32_Ed25519::secretkey($keypair);
2820
-        }
2821
-        return ParagonIE_Sodium_Core_Ed25519::secretkey($keypair);
2822
-    }
2823
-
2824
-    /**
2825
-     * Calculate the Ed25519 signature of a message and return ONLY the signature.
2826
-     *
2827
-     * Algorithm: Ed25519 (EdDSA over Curve25519)
2828
-     *
2829
-     * @param string $message Message to be signed
2830
-     * @param string $secretKey Secret signing key
2831
-     * @return string           Digital signature
2832
-     * @throws SodiumException
2833
-     * @throws TypeError
2834
-     * @psalm-suppress MixedArgument
2835
-     */
2836
-    public static function crypto_sign_detached($message, $secretKey)
2837
-    {
2838
-        /* Type checks: */
2839
-        ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
2840
-        ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 2);
2841
-
2842
-        /* Input validation: */
2843
-        if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_SIGN_SECRETKEYBYTES) {
2844
-            throw new SodiumException('Argument 2 must be CRYPTO_SIGN_SECRETKEYBYTES long.');
2845
-        }
2846
-
2847
-        if (self::useNewSodiumAPI()) {
2848
-            return sodium_crypto_sign_detached($message, $secretKey);
2849
-        }
2850
-        if (self::use_fallback('crypto_sign_detached')) {
2851
-            return (string) call_user_func('\\Sodium\\crypto_sign_detached', $message, $secretKey);
2852
-        }
2853
-        if (PHP_INT_SIZE === 4) {
2854
-            return ParagonIE_Sodium_Crypto32::sign_detached($message, $secretKey);
2855
-        }
2856
-        return ParagonIE_Sodium_Crypto::sign_detached($message, $secretKey);
2857
-    }
2858
-
2859
-    /**
2860
-     * Verify the Ed25519 signature of a message.
2861
-     *
2862
-     * @param string $signature Digital sginature
2863
-     * @param string $message Message to be verified
2864
-     * @param string $publicKey Public key
2865
-     * @return bool             TRUE if this signature is good for this public key;
2866
-     *                          FALSE otherwise
2867
-     * @throws SodiumException
2868
-     * @throws TypeError
2869
-     * @psalm-suppress MixedArgument
2870
-     */
2871
-    public static function crypto_sign_verify_detached($signature, $message, $publicKey)
2872
-    {
2873
-        /* Type checks: */
2874
-        ParagonIE_Sodium_Core_Util::declareScalarType($signature, 'string', 1);
2875
-        ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 2);
2876
-        ParagonIE_Sodium_Core_Util::declareScalarType($publicKey, 'string', 3);
2877
-
2878
-        /* Input validation: */
2879
-        if (ParagonIE_Sodium_Core_Util::strlen($signature) !== self::CRYPTO_SIGN_BYTES) {
2880
-            throw new SodiumException('Argument 1 must be CRYPTO_SIGN_BYTES long.');
2881
-        }
2882
-        if (ParagonIE_Sodium_Core_Util::strlen($publicKey) !== self::CRYPTO_SIGN_PUBLICKEYBYTES) {
2883
-            throw new SodiumException('Argument 3 must be CRYPTO_SIGN_PUBLICKEYBYTES long.');
2884
-        }
2885
-
2886
-        if (self::useNewSodiumAPI()) {
2887
-            return sodium_crypto_sign_verify_detached($signature, $message, $publicKey);
2888
-        }
2889
-        if (self::use_fallback('crypto_sign_verify_detached')) {
2890
-            return (bool) call_user_func(
2891
-                '\\Sodium\\crypto_sign_verify_detached',
2892
-                $signature,
2893
-                $message,
2894
-                $publicKey
2895
-            );
2896
-        }
2897
-        if (PHP_INT_SIZE === 4) {
2898
-            return ParagonIE_Sodium_Crypto32::sign_verify_detached($signature, $message, $publicKey);
2899
-        }
2900
-        return ParagonIE_Sodium_Crypto::sign_verify_detached($signature, $message, $publicKey);
2901
-    }
2902
-
2903
-    /**
2904
-     * Convert an Ed25519 public key to a Curve25519 public key
2905
-     *
2906
-     * @param string $pk
2907
-     * @return string
2908
-     * @throws SodiumException
2909
-     * @throws TypeError
2910
-     * @psalm-suppress MixedArgument
2911
-     */
2912
-    public static function crypto_sign_ed25519_pk_to_curve25519($pk)
2913
-    {
2914
-        /* Type checks: */
2915
-        ParagonIE_Sodium_Core_Util::declareScalarType($pk, 'string', 1);
2916
-
2917
-        /* Input validation: */
2918
-        if (ParagonIE_Sodium_Core_Util::strlen($pk) < self::CRYPTO_SIGN_PUBLICKEYBYTES) {
2919
-            throw new SodiumException('Argument 1 must be at least CRYPTO_SIGN_PUBLICKEYBYTES long.');
2920
-        }
2921
-        if (self::useNewSodiumAPI()) {
2922
-            if (is_callable('crypto_sign_ed25519_pk_to_curve25519')) {
2923
-                return (string) sodium_crypto_sign_ed25519_pk_to_curve25519($pk);
2924
-            }
2925
-        }
2926
-        if (self::use_fallback('crypto_sign_ed25519_pk_to_curve25519')) {
2927
-            return (string) call_user_func('\\Sodium\\crypto_sign_ed25519_pk_to_curve25519', $pk);
2928
-        }
2929
-        if (PHP_INT_SIZE === 4) {
2930
-            return ParagonIE_Sodium_Core32_Ed25519::pk_to_curve25519($pk);
2931
-        }
2932
-        return ParagonIE_Sodium_Core_Ed25519::pk_to_curve25519($pk);
2933
-    }
2934
-
2935
-    /**
2936
-     * Convert an Ed25519 secret key to a Curve25519 secret key
2937
-     *
2938
-     * @param string $sk
2939
-     * @return string
2940
-     * @throws SodiumException
2941
-     * @throws TypeError
2942
-     * @psalm-suppress MixedArgument
2943
-     */
2944
-    public static function crypto_sign_ed25519_sk_to_curve25519($sk)
2945
-    {
2946
-        /* Type checks: */
2947
-        ParagonIE_Sodium_Core_Util::declareScalarType($sk, 'string', 1);
2948
-
2949
-        /* Input validation: */
2950
-        if (ParagonIE_Sodium_Core_Util::strlen($sk) < self::CRYPTO_SIGN_SEEDBYTES) {
2951
-            throw new SodiumException('Argument 1 must be at least CRYPTO_SIGN_SEEDBYTES long.');
2952
-        }
2953
-        if (self::useNewSodiumAPI()) {
2954
-            if (is_callable('crypto_sign_ed25519_sk_to_curve25519')) {
2955
-                return sodium_crypto_sign_ed25519_sk_to_curve25519($sk);
2956
-            }
2957
-        }
2958
-        if (self::use_fallback('crypto_sign_ed25519_sk_to_curve25519')) {
2959
-            return (string) call_user_func('\\Sodium\\crypto_sign_ed25519_sk_to_curve25519', $sk);
2960
-        }
2961
-
2962
-        $h = hash('sha512', ParagonIE_Sodium_Core_Util::substr($sk, 0, 32), true);
2963
-        $h[0] = ParagonIE_Sodium_Core_Util::intToChr(
2964
-            ParagonIE_Sodium_Core_Util::chrToInt($h[0]) & 248
2965
-        );
2966
-        $h[31] = ParagonIE_Sodium_Core_Util::intToChr(
2967
-            (ParagonIE_Sodium_Core_Util::chrToInt($h[31]) & 127) | 64
2968
-        );
2969
-        return ParagonIE_Sodium_Core_Util::substr($h, 0, 32);
2970
-    }
2971
-
2972
-    /**
2973
-     * Expand a key and nonce into a keystream of pseudorandom bytes.
2974
-     *
2975
-     * @param int $len Number of bytes desired
2976
-     * @param string $nonce Number to be used Once; must be 24 bytes
2977
-     * @param string $key XSalsa20 key
2978
-     * @return string       Pseudorandom stream that can be XORed with messages
2979
-     *                      to provide encryption (but not authentication; see
2980
-     *                      Poly1305 or crypto_auth() for that, which is not
2981
-     *                      optional for security)
2982
-     * @throws SodiumException
2983
-     * @throws TypeError
2984
-     * @psalm-suppress MixedArgument
2985
-     */
2986
-    public static function crypto_stream($len, $nonce, $key)
2987
-    {
2988
-        /* Type checks: */
2989
-        ParagonIE_Sodium_Core_Util::declareScalarType($len, 'int', 1);
2990
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
2991
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
2992
-
2993
-        /* Input validation: */
2994
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_STREAM_NONCEBYTES) {
2995
-            throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
2996
-        }
2997
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_STREAM_KEYBYTES) {
2998
-            throw new SodiumException('Argument 3 must be CRYPTO_STREAM_KEYBYTES long.');
2999
-        }
3000
-
3001
-        if (self::useNewSodiumAPI()) {
3002
-            return sodium_crypto_stream($len, $nonce, $key);
3003
-        }
3004
-        if (self::use_fallback('crypto_stream')) {
3005
-            return (string) call_user_func('\\Sodium\\crypto_stream', $len, $nonce, $key);
3006
-        }
3007
-        if (PHP_INT_SIZE === 4) {
3008
-            return ParagonIE_Sodium_Core32_XSalsa20::xsalsa20($len, $nonce, $key);
3009
-        }
3010
-        return ParagonIE_Sodium_Core_XSalsa20::xsalsa20($len, $nonce, $key);
3011
-    }
3012
-
3013
-    /**
3014
-     * DANGER! UNAUTHENTICATED ENCRYPTION!
3015
-     *
3016
-     * Unless you are following expert advice, do not use this feature.
3017
-     *
3018
-     * Algorithm: XSalsa20
3019
-     *
3020
-     * This DOES NOT provide ciphertext integrity.
3021
-     *
3022
-     * @param string $message Plaintext message
3023
-     * @param string $nonce Number to be used Once; must be 24 bytes
3024
-     * @param string $key Encryption key
3025
-     * @return string         Encrypted text which is vulnerable to chosen-
3026
-     *                        ciphertext attacks unless you implement some
3027
-     *                        other mitigation to the ciphertext (i.e.
3028
-     *                        Encrypt then MAC)
3029
-     * @throws SodiumException
3030
-     * @throws TypeError
3031
-     * @psalm-suppress MixedArgument
3032
-     */
3033
-    public static function crypto_stream_xor($message, $nonce, $key)
3034
-    {
3035
-        /* Type checks: */
3036
-        ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
3037
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
3038
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
3039
-
3040
-        /* Input validation: */
3041
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_STREAM_NONCEBYTES) {
3042
-            throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
3043
-        }
3044
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_STREAM_KEYBYTES) {
3045
-            throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_KEYBYTES long.');
3046
-        }
3047
-
3048
-        if (self::useNewSodiumAPI()) {
3049
-            return sodium_crypto_stream_xor($message, $nonce, $key);
3050
-        }
3051
-        if (self::use_fallback('crypto_stream_xor')) {
3052
-            return (string) call_user_func('\\Sodium\\crypto_stream_xor', $message, $nonce, $key);
3053
-        }
3054
-        if (PHP_INT_SIZE === 4) {
3055
-            return ParagonIE_Sodium_Core32_XSalsa20::xsalsa20_xor($message, $nonce, $key);
3056
-        }
3057
-        return ParagonIE_Sodium_Core_XSalsa20::xsalsa20_xor($message, $nonce, $key);
3058
-    }
3059
-
3060
-    /**
3061
-     * Return a secure random key for use with crypto_stream
3062
-     *
3063
-     * @return string
3064
-     * @throws Exception
3065
-     * @throws Error
3066
-     */
3067
-    public static function crypto_stream_keygen()
3068
-    {
3069
-        return random_bytes(self::CRYPTO_STREAM_KEYBYTES);
3070
-    }
3071
-
3072
-
3073
-    /**
3074
-     * Expand a key and nonce into a keystream of pseudorandom bytes.
3075
-     *
3076
-     * @param int $len Number of bytes desired
3077
-     * @param string $nonce Number to be used Once; must be 24 bytes
3078
-     * @param string $key XChaCha20 key
3079
-     * @param bool $dontFallback
3080
-     * @return string       Pseudorandom stream that can be XORed with messages
3081
-     *                      to provide encryption (but not authentication; see
3082
-     *                      Poly1305 or crypto_auth() for that, which is not
3083
-     *                      optional for security)
3084
-     * @throws SodiumException
3085
-     * @throws TypeError
3086
-     * @psalm-suppress MixedArgument
3087
-     */
3088
-    public static function crypto_stream_xchacha20($len, $nonce, $key, $dontFallback = false)
3089
-    {
3090
-        /* Type checks: */
3091
-        ParagonIE_Sodium_Core_Util::declareScalarType($len, 'int', 1);
3092
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
3093
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
3094
-
3095
-        /* Input validation: */
3096
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_STREAM_XCHACHA20_NONCEBYTES) {
3097
-            throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_XCHACHA20_NONCEBYTES long.');
3098
-        }
3099
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_STREAM_XCHACHA20_KEYBYTES) {
3100
-            throw new SodiumException('Argument 3 must be CRYPTO_STREAM_XCHACHA20_KEYBYTES long.');
3101
-        }
3102
-
3103
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3104
-            return sodium_crypto_stream_xchacha20($len, $nonce, $key);
3105
-        }
3106
-        if (PHP_INT_SIZE === 4) {
3107
-            return ParagonIE_Sodium_Core32_XChaCha20::stream($len, $nonce, $key);
3108
-        }
3109
-        return ParagonIE_Sodium_Core_XChaCha20::stream($len, $nonce, $key);
3110
-    }
3111
-
3112
-    /**
3113
-     * DANGER! UNAUTHENTICATED ENCRYPTION!
3114
-     *
3115
-     * Unless you are following expert advice, do not use this feature.
3116
-     *
3117
-     * Algorithm: XChaCha20
3118
-     *
3119
-     * This DOES NOT provide ciphertext integrity.
3120
-     *
3121
-     * @param string $message Plaintext message
3122
-     * @param string $nonce Number to be used Once; must be 24 bytes
3123
-     * @param string $key Encryption key
3124
-     * @return string         Encrypted text which is vulnerable to chosen-
3125
-     *                        ciphertext attacks unless you implement some
3126
-     *                        other mitigation to the ciphertext (i.e.
3127
-     *                        Encrypt then MAC)
3128
-     * @param bool $dontFallback
3129
-     * @throws SodiumException
3130
-     * @throws TypeError
3131
-     * @psalm-suppress MixedArgument
3132
-     */
3133
-    public static function crypto_stream_xchacha20_xor($message, $nonce, $key, $dontFallback = false)
3134
-    {
3135
-        /* Type checks: */
3136
-        ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
3137
-        ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
3138
-        ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
3139
-
3140
-        /* Input validation: */
3141
-        if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_STREAM_XCHACHA20_NONCEBYTES) {
3142
-            throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_XCHACHA20_NONCEBYTES long.');
3143
-        }
3144
-        if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_STREAM_XCHACHA20_KEYBYTES) {
3145
-            throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_XCHACHA20_KEYBYTES long.');
3146
-        }
3147
-
3148
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3149
-            return sodium_crypto_stream_xchacha20_xor($message, $nonce, $key);
3150
-        }
3151
-        if (PHP_INT_SIZE === 4) {
3152
-            return ParagonIE_Sodium_Core32_XChaCha20::streamXorIc($message, $nonce, $key);
3153
-        }
3154
-        return ParagonIE_Sodium_Core_XChaCha20::streamXorIc($message, $nonce, $key);
3155
-    }
3156
-
3157
-    /**
3158
-     * Return a secure random key for use with crypto_stream_xchacha20
3159
-     *
3160
-     * @return string
3161
-     * @throws Exception
3162
-     * @throws Error
3163
-     */
3164
-    public static function crypto_stream_xchacha20_keygen()
3165
-    {
3166
-        return random_bytes(self::CRYPTO_STREAM_XCHACHA20_KEYBYTES);
3167
-    }
3168
-
3169
-    /**
3170
-     * Cache-timing-safe implementation of hex2bin().
3171
-     *
3172
-     * @param string $string Hexadecimal string
3173
-     * @return string        Raw binary string
3174
-     * @throws SodiumException
3175
-     * @throws TypeError
3176
-     * @psalm-suppress TooFewArguments
3177
-     * @psalm-suppress MixedArgument
3178
-     */
3179
-    public static function hex2bin($string)
3180
-    {
3181
-        /* Type checks: */
3182
-        ParagonIE_Sodium_Core_Util::declareScalarType($string, 'string', 1);
3183
-
3184
-        if (self::useNewSodiumAPI()) {
3185
-            if (is_callable('sodium_hex2bin')) {
3186
-                return (string) sodium_hex2bin($string);
3187
-            }
3188
-        }
3189
-        if (self::use_fallback('hex2bin')) {
3190
-            return (string) call_user_func('\\Sodium\\hex2bin', $string);
3191
-        }
3192
-        return ParagonIE_Sodium_Core_Util::hex2bin($string);
3193
-    }
3194
-
3195
-    /**
3196
-     * Increase a string (little endian)
3197
-     *
3198
-     * @param string $var
3199
-     *
3200
-     * @return void
3201
-     * @throws SodiumException
3202
-     * @throws TypeError
3203
-     * @psalm-suppress MixedArgument
3204
-     */
3205
-    public static function increment(&$var)
3206
-    {
3207
-        /* Type checks: */
3208
-        ParagonIE_Sodium_Core_Util::declareScalarType($var, 'string', 1);
3209
-
3210
-        if (self::useNewSodiumAPI()) {
3211
-            sodium_increment($var);
3212
-            return;
3213
-        }
3214
-        if (self::use_fallback('increment')) {
3215
-            $func = '\\Sodium\\increment';
3216
-            $func($var);
3217
-            return;
3218
-        }
3219
-
3220
-        $len = ParagonIE_Sodium_Core_Util::strlen($var);
3221
-        $c = 1;
3222
-        $copy = '';
3223
-        for ($i = 0; $i < $len; ++$i) {
3224
-            $c += ParagonIE_Sodium_Core_Util::chrToInt(
3225
-                ParagonIE_Sodium_Core_Util::substr($var, $i, 1)
3226
-            );
3227
-            $copy .= ParagonIE_Sodium_Core_Util::intToChr($c);
3228
-            $c >>= 8;
3229
-        }
3230
-        $var = $copy;
3231
-    }
3232
-
3233
-    /**
3234
-     * @param string $str
3235
-     * @return bool
3236
-     *
3237
-     * @throws SodiumException
3238
-     */
3239
-    public static function is_zero($str)
3240
-    {
3241
-        $d = 0;
3242
-        for ($i = 0; $i < 32; ++$i) {
3243
-            $d |= ParagonIE_Sodium_Core_Util::chrToInt($str[$i]);
3244
-        }
3245
-        return ((($d - 1) >> 31) & 1) === 1;
3246
-    }
3247
-
3248
-    /**
3249
-     * The equivalent to the libsodium minor version we aim to be compatible
3250
-     * with (sans pwhash and memzero).
3251
-     *
3252
-     * @return int
3253
-     */
3254
-    public static function library_version_major()
3255
-    {
3256
-        if (self::useNewSodiumAPI() && defined('SODIUM_LIBRARY_MAJOR_VERSION')) {
3257
-            return SODIUM_LIBRARY_MAJOR_VERSION;
3258
-        }
3259
-        if (self::use_fallback('library_version_major')) {
3260
-            /** @psalm-suppress UndefinedFunction */
3261
-            return (int) call_user_func('\\Sodium\\library_version_major');
3262
-        }
3263
-        return self::LIBRARY_VERSION_MAJOR;
3264
-    }
3265
-
3266
-    /**
3267
-     * The equivalent to the libsodium minor version we aim to be compatible
3268
-     * with (sans pwhash and memzero).
3269
-     *
3270
-     * @return int
3271
-     */
3272
-    public static function library_version_minor()
3273
-    {
3274
-        if (self::useNewSodiumAPI() && defined('SODIUM_LIBRARY_MINOR_VERSION')) {
3275
-            return SODIUM_LIBRARY_MINOR_VERSION;
3276
-        }
3277
-        if (self::use_fallback('library_version_minor')) {
3278
-            /** @psalm-suppress UndefinedFunction */
3279
-            return (int) call_user_func('\\Sodium\\library_version_minor');
3280
-        }
3281
-        return self::LIBRARY_VERSION_MINOR;
3282
-    }
3283
-
3284
-    /**
3285
-     * Compare two strings.
3286
-     *
3287
-     * @param string $left
3288
-     * @param string $right
3289
-     * @return int
3290
-     * @throws SodiumException
3291
-     * @throws TypeError
3292
-     * @psalm-suppress MixedArgument
3293
-     */
3294
-    public static function memcmp($left, $right)
3295
-    {
3296
-        /* Type checks: */
3297
-        ParagonIE_Sodium_Core_Util::declareScalarType($left, 'string', 1);
3298
-        ParagonIE_Sodium_Core_Util::declareScalarType($right, 'string', 2);
3299
-
3300
-        if (self::useNewSodiumAPI()) {
3301
-            return sodium_memcmp($left, $right);
3302
-        }
3303
-        if (self::use_fallback('memcmp')) {
3304
-            return (int) call_user_func('\\Sodium\\memcmp', $left, $right);
3305
-        }
3306
-        /** @var string $left */
3307
-        /** @var string $right */
3308
-        return ParagonIE_Sodium_Core_Util::memcmp($left, $right);
3309
-    }
3310
-
3311
-    /**
3312
-     * It's actually not possible to zero memory buffers in PHP. You need the
3313
-     * native library for that.
3314
-     *
3315
-     * @param string|null $var
3316
-     * @param-out string|null $var
3317
-     *
3318
-     * @return void
3319
-     * @throws SodiumException (Unless libsodium is installed)
3320
-     * @throws TypeError
3321
-     * @psalm-suppress TooFewArguments
3322
-     */
3323
-    public static function memzero(&$var)
3324
-    {
3325
-        /* Type checks: */
3326
-        ParagonIE_Sodium_Core_Util::declareScalarType($var, 'string', 1);
3327
-
3328
-        if (self::useNewSodiumAPI()) {
3329
-            /** @psalm-suppress MixedArgument */
3330
-            sodium_memzero($var);
3331
-            return;
3332
-        }
3333
-        if (self::use_fallback('memzero')) {
3334
-            $func = '\\Sodium\\memzero';
3335
-            $func($var);
3336
-            if ($var === null) {
3337
-                return;
3338
-            }
3339
-        }
3340
-        // This is the best we can do.
3341
-        throw new SodiumException(
3342
-            'This is not implemented in sodium_compat, as it is not possible to securely wipe memory from PHP. ' .
3343
-            'To fix this error, make sure libsodium is installed and the PHP extension is enabled.'
3344
-        );
3345
-    }
3346
-
3347
-    /**
3348
-     * @param string $unpadded
3349
-     * @param int $blockSize
3350
-     * @param bool $dontFallback
3351
-     * @return string
3352
-     * @throws SodiumException
3353
-     */
3354
-    public static function pad($unpadded, $blockSize, $dontFallback = false)
3355
-    {
3356
-        /* Type checks: */
3357
-        ParagonIE_Sodium_Core_Util::declareScalarType($unpadded, 'string', 1);
3358
-        ParagonIE_Sodium_Core_Util::declareScalarType($blockSize, 'int', 2);
3359
-
3360
-        $unpadded = (string) $unpadded;
3361
-        $blockSize = (int) $blockSize;
3362
-
3363
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3364
-            return (string) sodium_pad($unpadded, $blockSize);
3365
-        }
3366
-
3367
-        if ($blockSize <= 0) {
3368
-            throw new SodiumException(
3369
-                'block size cannot be less than 1'
3370
-            );
3371
-        }
3372
-        $unpadded_len = ParagonIE_Sodium_Core_Util::strlen($unpadded);
3373
-        $xpadlen = ($blockSize - 1);
3374
-        if (($blockSize & ($blockSize - 1)) === 0) {
3375
-            $xpadlen -= $unpadded_len & ($blockSize - 1);
3376
-        } else {
3377
-            $xpadlen -= $unpadded_len % $blockSize;
3378
-        }
3379
-
3380
-        $xpadded_len = $unpadded_len + $xpadlen;
3381
-        $padded = str_repeat("\0", $xpadded_len - 1);
3382
-        if ($unpadded_len > 0) {
3383
-            $st = 1;
3384
-            $i = 0;
3385
-            $k = $unpadded_len;
3386
-            for ($j = 0; $j <= $xpadded_len; ++$j) {
3387
-                $i = (int) $i;
3388
-                $k = (int) $k;
3389
-                $st = (int) $st;
3390
-                if ($j >= $unpadded_len) {
3391
-                    $padded[$j] = "\0";
3392
-                } else {
3393
-                    $padded[$j] = $unpadded[$j];
3394
-                }
3395
-                /** @var int $k */
3396
-                $k -= $st;
3397
-                $st = (int) (~(
3398
-                            (
3399
-                                (
3400
-                                    ($k >> 48)
3401
-                                        |
3402
-                                    ($k >> 32)
3403
-                                        |
3404
-                                    ($k >> 16)
3405
-                                        |
3406
-                                    $k
3407
-                                ) - 1
3408
-                            ) >> 16
3409
-                        )
3410
-                    ) & 1;
3411
-                $i += $st;
3412
-            }
3413
-        }
3414
-
3415
-        $mask = 0;
3416
-        $tail = $xpadded_len;
3417
-        for ($i = 0; $i < $blockSize; ++$i) {
3418
-            # barrier_mask = (unsigned char)
3419
-            #     (((i ^ xpadlen) - 1U) >> ((sizeof(size_t) - 1U) * CHAR_BIT));
3420
-            $barrier_mask = (($i ^ $xpadlen) -1) >> ((PHP_INT_SIZE << 3) - 1);
3421
-            # tail[-i] = (tail[-i] & mask) | (0x80 & barrier_mask);
3422
-            $padded[$tail - $i] = ParagonIE_Sodium_Core_Util::intToChr(
3423
-                (ParagonIE_Sodium_Core_Util::chrToInt($padded[$tail - $i]) & $mask)
3424
-                    |
3425
-                (0x80 & $barrier_mask)
3426
-            );
3427
-            # mask |= barrier_mask;
3428
-            $mask |= $barrier_mask;
3429
-        }
3430
-        return $padded;
3431
-    }
3432
-
3433
-    /**
3434
-     * @param string $padded
3435
-     * @param int $blockSize
3436
-     * @param bool $dontFallback
3437
-     * @return string
3438
-     * @throws SodiumException
3439
-     */
3440
-    public static function unpad($padded, $blockSize, $dontFallback = false)
3441
-    {
3442
-        /* Type checks: */
3443
-        ParagonIE_Sodium_Core_Util::declareScalarType($padded, 'string', 1);
3444
-        ParagonIE_Sodium_Core_Util::declareScalarType($blockSize, 'int', 2);
3445
-
3446
-        $padded = (string) $padded;
3447
-        $blockSize = (int) $blockSize;
3448
-
3449
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3450
-            return (string) sodium_unpad($padded, $blockSize);
3451
-        }
3452
-        if ($blockSize <= 0) {
3453
-            throw new SodiumException('block size cannot be less than 1');
3454
-        }
3455
-        $padded_len = ParagonIE_Sodium_Core_Util::strlen($padded);
3456
-        if ($padded_len < $blockSize) {
3457
-            throw new SodiumException('invalid padding');
3458
-        }
3459
-
3460
-        # tail = &padded[padded_len - 1U];
3461
-        $tail = $padded_len - 1;
3462
-
3463
-        $acc = 0;
3464
-        $valid = 0;
3465
-        $pad_len = 0;
3466
-
3467
-        $found = 0;
3468
-        for ($i = 0; $i < $blockSize; ++$i) {
3469
-            # c = tail[-i];
3470
-            $c = ParagonIE_Sodium_Core_Util::chrToInt($padded[$tail - $i]);
3471
-
3472
-            # is_barrier =
3473
-            #     (( (acc - 1U) & (pad_len - 1U) & ((c ^ 0x80) - 1U) ) >> 8) & 1U;
3474
-            $is_barrier = (
3475
-                (
3476
-                    ($acc - 1) & ($pad_len - 1) & (($c ^ 80) - 1)
3477
-                ) >> 7
3478
-            ) & 1;
3479
-            $is_barrier &= ~$found;
3480
-            $found |= $is_barrier;
3481
-
3482
-            # acc |= c;
3483
-            $acc |= $c;
3484
-
3485
-            # pad_len |= i & (1U + ~is_barrier);
3486
-            $pad_len |= $i & (1 + ~$is_barrier);
3487
-
3488
-            # valid |= (unsigned char) is_barrier;
3489
-            $valid |= ($is_barrier & 0xff);
3490
-        }
3491
-        # unpadded_len = padded_len - 1U - pad_len;
3492
-        $unpadded_len = $padded_len - 1 - $pad_len;
3493
-        if ($valid !== 1) {
3494
-            throw new SodiumException('invalid padding');
3495
-        }
3496
-        return ParagonIE_Sodium_Core_Util::substr($padded, 0, $unpadded_len);
3497
-    }
3498
-
3499
-    /**
3500
-     * Will sodium_compat run fast on the current hardware and PHP configuration?
3501
-     *
3502
-     * @return bool
3503
-     */
3504
-    public static function polyfill_is_fast()
3505
-    {
3506
-        if (extension_loaded('sodium')) {
3507
-            return true;
3508
-        }
3509
-        if (extension_loaded('libsodium')) {
3510
-            return true;
3511
-        }
3512
-        return PHP_INT_SIZE === 8;
3513
-    }
3514
-
3515
-    /**
3516
-     * Generate a string of bytes from the kernel's CSPRNG.
3517
-     * Proudly uses /dev/urandom (if getrandom(2) is not available).
3518
-     *
3519
-     * @param int $numBytes
3520
-     * @return string
3521
-     * @throws Exception
3522
-     * @throws TypeError
3523
-     */
3524
-    public static function randombytes_buf($numBytes)
3525
-    {
3526
-        /* Type checks: */
3527
-        if (!is_int($numBytes)) {
3528
-            if (is_numeric($numBytes)) {
3529
-                $numBytes = (int) $numBytes;
3530
-            } else {
3531
-                throw new TypeError(
3532
-                    'Argument 1 must be an integer, ' . gettype($numBytes) . ' given.'
3533
-                );
3534
-            }
3535
-        }
3536
-        if (self::use_fallback('randombytes_buf')) {
3537
-            return (string) call_user_func('\\Sodium\\randombytes_buf', $numBytes);
3538
-        }
3539
-        return random_bytes($numBytes);
3540
-    }
3541
-
3542
-    /**
3543
-     * Generate an integer between 0 and $range (non-inclusive).
3544
-     *
3545
-     * @param int $range
3546
-     * @return int
3547
-     * @throws Exception
3548
-     * @throws Error
3549
-     * @throws TypeError
3550
-     */
3551
-    public static function randombytes_uniform($range)
3552
-    {
3553
-        /* Type checks: */
3554
-        if (!is_int($range)) {
3555
-            if (is_numeric($range)) {
3556
-                $range = (int) $range;
3557
-            } else {
3558
-                throw new TypeError(
3559
-                    'Argument 1 must be an integer, ' . gettype($range) . ' given.'
3560
-                );
3561
-            }
3562
-        }
3563
-        if (self::use_fallback('randombytes_uniform')) {
3564
-            return (int) call_user_func('\\Sodium\\randombytes_uniform', $range);
3565
-        }
3566
-        return random_int(0, $range - 1);
3567
-    }
3568
-
3569
-    /**
3570
-     * Generate a random 16-bit integer.
3571
-     *
3572
-     * @return int
3573
-     * @throws Exception
3574
-     * @throws Error
3575
-     * @throws TypeError
3576
-     */
3577
-    public static function randombytes_random16()
3578
-    {
3579
-        if (self::use_fallback('randombytes_random16')) {
3580
-            return (int) call_user_func('\\Sodium\\randombytes_random16');
3581
-        }
3582
-        return random_int(0, 65535);
3583
-    }
3584
-
3585
-    /**
3586
-     * @param string $p
3587
-     * @param bool $dontFallback
3588
-     * @return bool
3589
-     * @throws SodiumException
3590
-     */
3591
-    public static function ristretto255_is_valid_point($p, $dontFallback = false)
3592
-    {
3593
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3594
-            return sodium_crypto_core_ristretto255_is_valid_point($p);
3595
-        }
3596
-        try {
3597
-            $r = ParagonIE_Sodium_Core_Ristretto255::ristretto255_frombytes($p);
3598
-            return $r['res'] === 0 &&
3599
-                ParagonIE_Sodium_Core_Ristretto255::ristretto255_point_is_canonical($p) === 1;
3600
-        } catch (SodiumException $ex) {
3601
-            if ($ex->getMessage() === 'S is not canonical') {
3602
-                return false;
3603
-            }
3604
-            throw $ex;
3605
-        }
3606
-    }
3607
-
3608
-    /**
3609
-     * @param string $p
3610
-     * @param string $q
3611
-     * @param bool $dontFallback
3612
-     * @return string
3613
-     * @throws SodiumException
3614
-     */
3615
-    public static function ristretto255_add($p, $q, $dontFallback = false)
3616
-    {
3617
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3618
-            return sodium_crypto_core_ristretto255_add($p, $q);
3619
-        }
3620
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_add($p, $q);
3621
-    }
3622
-
3623
-    /**
3624
-     * @param string $p
3625
-     * @param string $q
3626
-     * @param bool $dontFallback
3627
-     * @return string
3628
-     * @throws SodiumException
3629
-     */
3630
-    public static function ristretto255_sub($p, $q, $dontFallback = false)
3631
-    {
3632
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3633
-            return sodium_crypto_core_ristretto255_sub($p, $q);
3634
-        }
3635
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_sub($p, $q);
3636
-    }
3637
-
3638
-    /**
3639
-     * @param string $r
3640
-     * @param bool $dontFallback
3641
-     * @return string
3642
-     *
3643
-     * @throws SodiumException
3644
-     */
3645
-    public static function ristretto255_from_hash($r, $dontFallback = false)
3646
-    {
3647
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3648
-            return sodium_crypto_core_ristretto255_from_hash($r);
3649
-        }
3650
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_from_hash($r);
3651
-    }
3652
-
3653
-    /**
3654
-     * @param bool $dontFallback
3655
-     * @return string
3656
-     *
3657
-     * @throws SodiumException
3658
-     */
3659
-    public static function ristretto255_random($dontFallback = false)
3660
-    {
3661
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3662
-            return sodium_crypto_core_ristretto255_random();
3663
-        }
3664
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_random();
3665
-    }
3666
-
3667
-    /**
3668
-     * @param bool $dontFallback
3669
-     * @return string
3670
-     *
3671
-     * @throws SodiumException
3672
-     */
3673
-    public static function ristretto255_scalar_random($dontFallback = false)
3674
-    {
3675
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3676
-            return sodium_crypto_core_ristretto255_scalar_random();
3677
-        }
3678
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_random();
3679
-    }
3680
-
3681
-    /**
3682
-     * @param string $s
3683
-     * @param bool $dontFallback
3684
-     * @return string
3685
-     * @throws SodiumException
3686
-     */
3687
-    public static function ristretto255_scalar_invert($s, $dontFallback = false)
3688
-    {
3689
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3690
-            return sodium_crypto_core_ristretto255_scalar_invert($s);
3691
-        }
3692
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_invert($s);
3693
-    }
3694
-    /**
3695
-     * @param string $s
3696
-     * @param bool $dontFallback
3697
-     * @return string
3698
-     * @throws SodiumException
3699
-     */
3700
-    public static function ristretto255_scalar_negate($s, $dontFallback = false)
3701
-    {
3702
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3703
-            return sodium_crypto_core_ristretto255_scalar_negate($s);
3704
-        }
3705
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_negate($s);
3706
-    }
3707
-
3708
-    /**
3709
-     * @param string $s
3710
-     * @param bool $dontFallback
3711
-     * @return string
3712
-     * @throws SodiumException
3713
-     */
3714
-    public static function ristretto255_scalar_complement($s, $dontFallback = false)
3715
-    {
3716
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3717
-            return sodium_crypto_core_ristretto255_scalar_complement($s);
3718
-        }
3719
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_complement($s);
3720
-    }
3721
-
3722
-    /**
3723
-     * @param string $x
3724
-     * @param string $y
3725
-     * @param bool $dontFallback
3726
-     * @return string
3727
-     * @throws SodiumException
3728
-     */
3729
-    public static function ristretto255_scalar_add($x, $y, $dontFallback = false)
3730
-    {
3731
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3732
-            return sodium_crypto_core_ristretto255_scalar_add($x, $y);
3733
-        }
3734
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_add($x, $y);
3735
-    }
3736
-
3737
-    /**
3738
-     * @param string $x
3739
-     * @param string $y
3740
-     * @param bool $dontFallback
3741
-     * @return string
3742
-     * @throws SodiumException
3743
-     */
3744
-    public static function ristretto255_scalar_sub($x, $y, $dontFallback = false)
3745
-    {
3746
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3747
-            return sodium_crypto_core_ristretto255_scalar_sub($x, $y);
3748
-        }
3749
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_sub($x, $y);
3750
-    }
3751
-
3752
-    /**
3753
-     * @param string $x
3754
-     * @param string $y
3755
-     * @param bool $dontFallback
3756
-     * @return string
3757
-     * @throws SodiumException
3758
-     */
3759
-    public static function ristretto255_scalar_mul($x, $y, $dontFallback = false)
3760
-    {
3761
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3762
-            return sodium_crypto_core_ristretto255_scalar_mul($x, $y);
3763
-        }
3764
-        return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_mul($x, $y);
3765
-    }
3766
-
3767
-    /**
3768
-     * @param string $n
3769
-     * @param string $p
3770
-     * @param bool $dontFallback
3771
-     * @return string
3772
-     * @throws SodiumException
3773
-     */
3774
-    public static function scalarmult_ristretto255($n, $p, $dontFallback = false)
3775
-    {
3776
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3777
-            return sodium_crypto_scalarmult_ristretto255($n, $p);
3778
-        }
3779
-        return ParagonIE_Sodium_Core_Ristretto255::scalarmult_ristretto255($n, $p);
3780
-    }
3781
-
3782
-    /**
3783
-     * @param string $n
3784
-     * @param string $p
3785
-     * @param bool $dontFallback
3786
-     * @return string
3787
-     * @throws SodiumException
3788
-     */
3789
-    public static function scalarmult_ristretto255_base($n, $dontFallback = false)
3790
-    {
3791
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3792
-            return sodium_crypto_scalarmult_ristretto255_base($n);
3793
-        }
3794
-        return ParagonIE_Sodium_Core_Ristretto255::scalarmult_ristretto255_base($n);
3795
-    }
3796
-
3797
-    /**
3798
-     * @param string $s
3799
-     * @param bool $dontFallback
3800
-     * @return string
3801
-     * @throws SodiumException
3802
-     */
3803
-    public static function ristretto255_scalar_reduce($s, $dontFallback = false)
3804
-    {
3805
-        if (self::useNewSodiumAPI() && !$dontFallback) {
3806
-            return sodium_crypto_core_ristretto255_scalar_reduce($s);
3807
-        }
3808
-        return ParagonIE_Sodium_Core_Ristretto255::sc_reduce($s);
3809
-    }
3810
-
3811
-    /**
3812
-     * Runtime testing method for 32-bit platforms.
3813
-     *
3814
-     * Usage: If runtime_speed_test() returns FALSE, then our 32-bit
3815
-     *        implementation is to slow to use safely without risking timeouts.
3816
-     *        If this happens, install sodium from PECL to get acceptable
3817
-     *        performance.
3818
-     *
3819
-     * @param int $iterations Number of multiplications to attempt
3820
-     * @param int $maxTimeout Milliseconds
3821
-     * @return bool           TRUE if we're fast enough, FALSE is not
3822
-     * @throws SodiumException
3823
-     */
3824
-    public static function runtime_speed_test($iterations, $maxTimeout)
3825
-    {
3826
-        if (self::polyfill_is_fast()) {
3827
-            return true;
3828
-        }
3829
-        /** @var float $end */
3830
-        $end = 0.0;
3831
-        /** @var float $start */
3832
-        $start = microtime(true);
3833
-        /** @var ParagonIE_Sodium_Core32_Int64 $a */
3834
-        $a = ParagonIE_Sodium_Core32_Int64::fromInt(random_int(3, 1 << 16));
3835
-        for ($i = 0; $i < $iterations; ++$i) {
3836
-            /** @var ParagonIE_Sodium_Core32_Int64 $b */
3837
-            $b = ParagonIE_Sodium_Core32_Int64::fromInt(random_int(3, 1 << 16));
3838
-            $a->mulInt64($b);
3839
-        }
3840
-        /** @var float $end */
3841
-        $end = microtime(true);
3842
-        /** @var int $diff */
3843
-        $diff = (int) ceil(($end - $start) * 1000);
3844
-        return $diff < $maxTimeout;
3845
-    }
3846
-
3847
-    /**
3848
-     * Add two numbers (little-endian unsigned), storing the value in the first
3849
-     * parameter.
3850
-     *
3851
-     * This mutates $val.
3852
-     *
3853
-     * @param string $val
3854
-     * @param string $addv
3855
-     * @return void
3856
-     * @throws SodiumException
3857
-     */
3858
-    public static function sub(&$val, $addv)
3859
-    {
3860
-        $val_len = ParagonIE_Sodium_Core_Util::strlen($val);
3861
-        $addv_len = ParagonIE_Sodium_Core_Util::strlen($addv);
3862
-        if ($val_len !== $addv_len) {
3863
-            throw new SodiumException('values must have the same length');
3864
-        }
3865
-        $A = ParagonIE_Sodium_Core_Util::stringToIntArray($val);
3866
-        $B = ParagonIE_Sodium_Core_Util::stringToIntArray($addv);
3867
-
3868
-        $c = 0;
3869
-        for ($i = 0; $i < $val_len; $i++) {
3870
-            $c = ($A[$i] - $B[$i] - $c);
3871
-            $A[$i] = ($c & 0xff);
3872
-            $c = ($c >> 8) & 1;
3873
-        }
3874
-        $val = ParagonIE_Sodium_Core_Util::intArrayToString($A);
3875
-    }
3876
-
3877
-    /**
3878
-     * This emulates libsodium's version_string() function, except ours is
3879
-     * prefixed with 'polyfill-'.
3880
-     *
3881
-     * @return string
3882
-     * @psalm-suppress MixedInferredReturnType
3883
-     * @psalm-suppress UndefinedFunction
3884
-     */
3885
-    public static function version_string()
3886
-    {
3887
-        if (self::useNewSodiumAPI()) {
3888
-            return (string) sodium_version_string();
3889
-        }
3890
-        if (self::use_fallback('version_string')) {
3891
-            return (string) call_user_func('\\Sodium\\version_string');
3892
-        }
3893
-        return (string) self::VERSION_STRING;
3894
-    }
3895
-
3896
-    /**
3897
-     * Should we use the libsodium core function instead?
3898
-     * This is always a good idea, if it's available. (Unless we're in the
3899
-     * middle of running our unit test suite.)
3900
-     *
3901
-     * If ext/libsodium is available, use it. Return TRUE.
3902
-     * Otherwise, we have to use the code provided herein. Return FALSE.
3903
-     *
3904
-     * @param string $sodium_func_name
3905
-     *
3906
-     * @return bool
3907
-     */
3908
-    protected static function use_fallback($sodium_func_name = '')
3909
-    {
3910
-        static $res = null;
3911
-        if ($res === null) {
3912
-            $res = extension_loaded('libsodium') && PHP_VERSION_ID >= 50300;
3913
-        }
3914
-        if ($res === false) {
3915
-            // No libsodium installed
3916
-            return false;
3917
-        }
3918
-        if (self::$disableFallbackForUnitTests) {
3919
-            // Don't fallback. Use the PHP implementation.
3920
-            return false;
3921
-        }
3922
-        if (!empty($sodium_func_name)) {
3923
-            return is_callable('\\Sodium\\' . $sodium_func_name);
3924
-        }
3925
-        return true;
3926
-    }
3927
-
3928
-    /**
3929
-     * Libsodium as implemented in PHP 7.2
3930
-     * and/or ext/sodium (via PECL)
3931
-     *
3932
-     * @ref https://wiki.php.net/rfc/libsodium
3933
-     * @return bool
3934
-     */
3935
-    protected static function useNewSodiumAPI()
3936
-    {
3937
-        static $res = null;
3938
-        if ($res === null) {
3939
-            $res = PHP_VERSION_ID >= 70000 && extension_loaded('sodium');
3940
-        }
3941
-        if (self::$disableFallbackForUnitTests) {
3942
-            // Don't fallback. Use the PHP implementation.
3943
-            return false;
3944
-        }
3945
-        return (bool) $res;
3946
-    }
1571
+			if (ParagonIE_Sodium_Core_Util::strlen($key) > self::CRYPTO_GENERICHASH_KEYBYTES_MAX) {
1572
+				throw new SodiumException('Unsupported key size. Must be at most CRYPTO_GENERICHASH_KEYBYTES_MAX bytes long.');
1573
+			}
1574
+		}
1575
+		if (PHP_INT_SIZE === 4) {
1576
+			return ParagonIE_Sodium_Crypto32::generichash_init_salt_personal($key, $length, $salt, $personal);
1577
+		}
1578
+		return ParagonIE_Sodium_Crypto::generichash_init_salt_personal($key, $length, $salt, $personal);
1579
+	}
1580
+
1581
+	/**
1582
+	 * Update a BLAKE2b hashing context with additional data.
1583
+	 *
1584
+	 * @param string $ctx    BLAKE2 hashing context. Generated by crypto_generichash_init().
1585
+	 *                       $ctx is passed by reference and gets updated in-place.
1586
+	 * @param-out string $ctx
1587
+	 * @param string $message The message to append to the existing hash state.
1588
+	 * @return void
1589
+	 * @throws SodiumException
1590
+	 * @throws TypeError
1591
+	 * @psalm-suppress MixedArgument
1592
+	 * @psalm-suppress ReferenceConstraintViolation
1593
+	 */
1594
+	public static function crypto_generichash_update(&$ctx, $message)
1595
+	{
1596
+		/* Type checks: */
1597
+		ParagonIE_Sodium_Core_Util::declareScalarType($ctx, 'string', 1);
1598
+		ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 2);
1599
+
1600
+		if (self::useNewSodiumAPI()) {
1601
+			sodium_crypto_generichash_update($ctx, $message);
1602
+			return;
1603
+		}
1604
+		if (self::use_fallback('crypto_generichash_update')) {
1605
+			$func = '\\Sodium\\crypto_generichash_update';
1606
+			$func($ctx, $message);
1607
+			return;
1608
+		}
1609
+		if (PHP_INT_SIZE === 4) {
1610
+			$ctx = ParagonIE_Sodium_Crypto32::generichash_update($ctx, $message);
1611
+		} else {
1612
+			$ctx = ParagonIE_Sodium_Crypto::generichash_update($ctx, $message);
1613
+		}
1614
+	}
1615
+
1616
+	/**
1617
+	 * @return string
1618
+	 * @throws Exception
1619
+	 * @throws Error
1620
+	 */
1621
+	public static function crypto_generichash_keygen()
1622
+	{
1623
+		return random_bytes(self::CRYPTO_GENERICHASH_KEYBYTES);
1624
+	}
1625
+
1626
+	/**
1627
+	 * @param int $subkey_len
1628
+	 * @param int $subkey_id
1629
+	 * @param string $context
1630
+	 * @param string $key
1631
+	 * @return string
1632
+	 * @throws SodiumException
1633
+	 */
1634
+	public static function crypto_kdf_derive_from_key(
1635
+		$subkey_len,
1636
+		$subkey_id,
1637
+		$context,
1638
+		$key
1639
+	) {
1640
+		ParagonIE_Sodium_Core_Util::declareScalarType($subkey_len, 'int', 1);
1641
+		ParagonIE_Sodium_Core_Util::declareScalarType($subkey_id, 'int', 2);
1642
+		ParagonIE_Sodium_Core_Util::declareScalarType($context, 'string', 3);
1643
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 4);
1644
+		$subkey_id = (int) $subkey_id;
1645
+		$subkey_len = (int) $subkey_len;
1646
+		$context = (string) $context;
1647
+		$key = (string) $key;
1648
+
1649
+		if ($subkey_len < self::CRYPTO_KDF_BYTES_MIN) {
1650
+			throw new SodiumException('subkey cannot be smaller than SODIUM_CRYPTO_KDF_BYTES_MIN');
1651
+		}
1652
+		if ($subkey_len > self::CRYPTO_KDF_BYTES_MAX) {
1653
+			throw new SodiumException('subkey cannot be larger than SODIUM_CRYPTO_KDF_BYTES_MAX');
1654
+		}
1655
+		if ($subkey_id < 0) {
1656
+			throw new SodiumException('subkey_id cannot be negative');
1657
+		}
1658
+		if (ParagonIE_Sodium_Core_Util::strlen($context) !== self::CRYPTO_KDF_CONTEXTBYTES) {
1659
+			throw new SodiumException('context should be SODIUM_CRYPTO_KDF_CONTEXTBYTES bytes');
1660
+		}
1661
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_KDF_KEYBYTES) {
1662
+			throw new SodiumException('key should be SODIUM_CRYPTO_KDF_KEYBYTES bytes');
1663
+		}
1664
+
1665
+		$salt = ParagonIE_Sodium_Core_Util::store64_le($subkey_id);
1666
+		$state = self::crypto_generichash_init_salt_personal(
1667
+			$key,
1668
+			$subkey_len,
1669
+			$salt,
1670
+			$context
1671
+		);
1672
+		return self::crypto_generichash_final($state, $subkey_len);
1673
+	}
1674
+
1675
+	/**
1676
+	 * @return string
1677
+	 * @throws Exception
1678
+	 * @throws Error
1679
+	 */
1680
+	public static function crypto_kdf_keygen()
1681
+	{
1682
+		return random_bytes(self::CRYPTO_KDF_KEYBYTES);
1683
+	}
1684
+
1685
+	/**
1686
+	 * Perform a key exchange, between a designated client and a server.
1687
+	 *
1688
+	 * Typically, you would designate one machine to be the client and the
1689
+	 * other to be the server. The first two keys are what you'd expect for
1690
+	 * scalarmult() below, but the latter two public keys don't swap places.
1691
+	 *
1692
+	 * | ALICE                          | BOB                                 |
1693
+	 * | Client                         | Server                              |
1694
+	 * |--------------------------------|-------------------------------------|
1695
+	 * | shared = crypto_kx(            | shared = crypto_kx(                 |
1696
+	 * |     alice_sk,                  |     bob_sk,                         | <- contextual
1697
+	 * |     bob_pk,                    |     alice_pk,                       | <- contextual
1698
+	 * |     alice_pk,                  |     alice_pk,                       | <----- static
1699
+	 * |     bob_pk                     |     bob_pk                          | <----- static
1700
+	 * | )                              | )                                   |
1701
+	 *
1702
+	 * They are used along with the scalarmult product to generate a 256-bit
1703
+	 * BLAKE2b hash unique to the client and server keys.
1704
+	 *
1705
+	 * @param string $my_secret
1706
+	 * @param string $their_public
1707
+	 * @param string $client_public
1708
+	 * @param string $server_public
1709
+	 * @param bool $dontFallback
1710
+	 * @return string
1711
+	 * @throws SodiumException
1712
+	 * @throws TypeError
1713
+	 * @psalm-suppress MixedArgument
1714
+	 */
1715
+	public static function crypto_kx($my_secret, $their_public, $client_public, $server_public, $dontFallback = false)
1716
+	{
1717
+		/* Type checks: */
1718
+		ParagonIE_Sodium_Core_Util::declareScalarType($my_secret, 'string', 1);
1719
+		ParagonIE_Sodium_Core_Util::declareScalarType($their_public, 'string', 2);
1720
+		ParagonIE_Sodium_Core_Util::declareScalarType($client_public, 'string', 3);
1721
+		ParagonIE_Sodium_Core_Util::declareScalarType($server_public, 'string', 4);
1722
+
1723
+		/* Input validation: */
1724
+		if (ParagonIE_Sodium_Core_Util::strlen($my_secret) !== self::CRYPTO_BOX_SECRETKEYBYTES) {
1725
+			throw new SodiumException('Argument 1 must be CRYPTO_BOX_SECRETKEYBYTES long.');
1726
+		}
1727
+		if (ParagonIE_Sodium_Core_Util::strlen($their_public) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
1728
+			throw new SodiumException('Argument 2 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
1729
+		}
1730
+		if (ParagonIE_Sodium_Core_Util::strlen($client_public) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
1731
+			throw new SodiumException('Argument 3 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
1732
+		}
1733
+		if (ParagonIE_Sodium_Core_Util::strlen($server_public) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
1734
+			throw new SodiumException('Argument 4 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
1735
+		}
1736
+
1737
+		if (self::useNewSodiumAPI() && !$dontFallback) {
1738
+			if (is_callable('sodium_crypto_kx')) {
1739
+				return (string) sodium_crypto_kx(
1740
+					$my_secret,
1741
+					$their_public,
1742
+					$client_public,
1743
+					$server_public
1744
+				);
1745
+			}
1746
+		}
1747
+		if (self::use_fallback('crypto_kx')) {
1748
+			return (string) call_user_func(
1749
+				'\\Sodium\\crypto_kx',
1750
+				$my_secret,
1751
+				$their_public,
1752
+				$client_public,
1753
+				$server_public
1754
+			);
1755
+		}
1756
+		if (PHP_INT_SIZE === 4) {
1757
+			return ParagonIE_Sodium_Crypto32::keyExchange(
1758
+				$my_secret,
1759
+				$their_public,
1760
+				$client_public,
1761
+				$server_public
1762
+			);
1763
+		}
1764
+		return ParagonIE_Sodium_Crypto::keyExchange(
1765
+			$my_secret,
1766
+			$their_public,
1767
+			$client_public,
1768
+			$server_public
1769
+		);
1770
+	}
1771
+
1772
+	/**
1773
+	 * @param string $seed
1774
+	 * @return string
1775
+	 * @throws SodiumException
1776
+	 */
1777
+	public static function crypto_kx_seed_keypair($seed)
1778
+	{
1779
+		ParagonIE_Sodium_Core_Util::declareScalarType($seed, 'string', 1);
1780
+
1781
+		$seed = (string) $seed;
1782
+
1783
+		if (ParagonIE_Sodium_Core_Util::strlen($seed) !== self::CRYPTO_KX_SEEDBYTES) {
1784
+			throw new SodiumException('seed must be SODIUM_CRYPTO_KX_SEEDBYTES bytes');
1785
+		}
1786
+
1787
+		$sk = self::crypto_generichash($seed, '', self::CRYPTO_KX_SECRETKEYBYTES);
1788
+		$pk = self::crypto_scalarmult_base($sk);
1789
+		return $sk . $pk;
1790
+	}
1791
+
1792
+	/**
1793
+	 * @return string
1794
+	 * @throws Exception
1795
+	 */
1796
+	public static function crypto_kx_keypair()
1797
+	{
1798
+		$sk = self::randombytes_buf(self::CRYPTO_KX_SECRETKEYBYTES);
1799
+		$pk = self::crypto_scalarmult_base($sk);
1800
+		return $sk . $pk;
1801
+	}
1802
+
1803
+	/**
1804
+	 * @param string $keypair
1805
+	 * @param string $serverPublicKey
1806
+	 * @return array{0: string, 1: string}
1807
+	 * @throws SodiumException
1808
+	 */
1809
+	public static function crypto_kx_client_session_keys($keypair, $serverPublicKey)
1810
+	{
1811
+		ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
1812
+		ParagonIE_Sodium_Core_Util::declareScalarType($serverPublicKey, 'string', 2);
1813
+
1814
+		$keypair = (string) $keypair;
1815
+		$serverPublicKey = (string) $serverPublicKey;
1816
+
1817
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_KX_KEYPAIRBYTES) {
1818
+			throw new SodiumException('keypair should be SODIUM_CRYPTO_KX_KEYPAIRBYTES bytes');
1819
+		}
1820
+		if (ParagonIE_Sodium_Core_Util::strlen($serverPublicKey) !== self::CRYPTO_KX_PUBLICKEYBYTES) {
1821
+			throw new SodiumException('public keys must be SODIUM_CRYPTO_KX_PUBLICKEYBYTES bytes');
1822
+		}
1823
+
1824
+		$sk = self::crypto_kx_secretkey($keypair);
1825
+		$pk = self::crypto_kx_publickey($keypair);
1826
+		$h = self::crypto_generichash_init(null, self::CRYPTO_KX_SESSIONKEYBYTES * 2);
1827
+		self::crypto_generichash_update($h, self::crypto_scalarmult($sk, $serverPublicKey));
1828
+		self::crypto_generichash_update($h, $pk);
1829
+		self::crypto_generichash_update($h, $serverPublicKey);
1830
+		$sessionKeys = self::crypto_generichash_final($h, self::CRYPTO_KX_SESSIONKEYBYTES * 2);
1831
+		return array(
1832
+			ParagonIE_Sodium_Core_Util::substr(
1833
+				$sessionKeys,
1834
+				0,
1835
+				self::CRYPTO_KX_SESSIONKEYBYTES
1836
+			),
1837
+			ParagonIE_Sodium_Core_Util::substr(
1838
+				$sessionKeys,
1839
+				self::CRYPTO_KX_SESSIONKEYBYTES,
1840
+				self::CRYPTO_KX_SESSIONKEYBYTES
1841
+			)
1842
+		);
1843
+	}
1844
+
1845
+	/**
1846
+	 * @param string $keypair
1847
+	 * @param string $clientPublicKey
1848
+	 * @return array{0: string, 1: string}
1849
+	 * @throws SodiumException
1850
+	 */
1851
+	public static function crypto_kx_server_session_keys($keypair, $clientPublicKey)
1852
+	{
1853
+		ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
1854
+		ParagonIE_Sodium_Core_Util::declareScalarType($clientPublicKey, 'string', 2);
1855
+
1856
+		$keypair = (string) $keypair;
1857
+		$clientPublicKey = (string) $clientPublicKey;
1858
+
1859
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_KX_KEYPAIRBYTES) {
1860
+			throw new SodiumException('keypair should be SODIUM_CRYPTO_KX_KEYPAIRBYTES bytes');
1861
+		}
1862
+		if (ParagonIE_Sodium_Core_Util::strlen($clientPublicKey) !== self::CRYPTO_KX_PUBLICKEYBYTES) {
1863
+			throw new SodiumException('public keys must be SODIUM_CRYPTO_KX_PUBLICKEYBYTES bytes');
1864
+		}
1865
+
1866
+		$sk = self::crypto_kx_secretkey($keypair);
1867
+		$pk = self::crypto_kx_publickey($keypair);
1868
+		$h = self::crypto_generichash_init(null, self::CRYPTO_KX_SESSIONKEYBYTES * 2);
1869
+		self::crypto_generichash_update($h, self::crypto_scalarmult($sk, $clientPublicKey));
1870
+		self::crypto_generichash_update($h, $clientPublicKey);
1871
+		self::crypto_generichash_update($h, $pk);
1872
+		$sessionKeys = self::crypto_generichash_final($h, self::CRYPTO_KX_SESSIONKEYBYTES * 2);
1873
+		return array(
1874
+			ParagonIE_Sodium_Core_Util::substr(
1875
+				$sessionKeys,
1876
+				self::CRYPTO_KX_SESSIONKEYBYTES,
1877
+				self::CRYPTO_KX_SESSIONKEYBYTES
1878
+			),
1879
+			ParagonIE_Sodium_Core_Util::substr(
1880
+				$sessionKeys,
1881
+				0,
1882
+				self::CRYPTO_KX_SESSIONKEYBYTES
1883
+			)
1884
+		);
1885
+	}
1886
+
1887
+	/**
1888
+	 * @param string $kp
1889
+	 * @return string
1890
+	 * @throws SodiumException
1891
+	 */
1892
+	public static function crypto_kx_secretkey($kp)
1893
+	{
1894
+		return ParagonIE_Sodium_Core_Util::substr(
1895
+			$kp,
1896
+			0,
1897
+			self::CRYPTO_KX_SECRETKEYBYTES
1898
+		);
1899
+	}
1900
+
1901
+	/**
1902
+	 * @param string $kp
1903
+	 * @return string
1904
+	 * @throws SodiumException
1905
+	 */
1906
+	public static function crypto_kx_publickey($kp)
1907
+	{
1908
+		return ParagonIE_Sodium_Core_Util::substr(
1909
+			$kp,
1910
+			self::CRYPTO_KX_SECRETKEYBYTES,
1911
+			self::CRYPTO_KX_PUBLICKEYBYTES
1912
+		);
1913
+	}
1914
+
1915
+	/**
1916
+	 * @param int $outlen
1917
+	 * @param string $passwd
1918
+	 * @param string $salt
1919
+	 * @param int $opslimit
1920
+	 * @param int $memlimit
1921
+	 * @param int|null $alg
1922
+	 * @return string
1923
+	 * @throws SodiumException
1924
+	 * @throws TypeError
1925
+	 * @psalm-suppress MixedArgument
1926
+	 */
1927
+	public static function crypto_pwhash($outlen, $passwd, $salt, $opslimit, $memlimit, $alg = null)
1928
+	{
1929
+		ParagonIE_Sodium_Core_Util::declareScalarType($outlen, 'int', 1);
1930
+		ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 2);
1931
+		ParagonIE_Sodium_Core_Util::declareScalarType($salt,  'string', 3);
1932
+		ParagonIE_Sodium_Core_Util::declareScalarType($opslimit, 'int', 4);
1933
+		ParagonIE_Sodium_Core_Util::declareScalarType($memlimit, 'int', 5);
1934
+
1935
+		if (self::useNewSodiumAPI()) {
1936
+			if (!is_null($alg)) {
1937
+				ParagonIE_Sodium_Core_Util::declareScalarType($alg, 'int', 6);
1938
+				return sodium_crypto_pwhash($outlen, $passwd, $salt, $opslimit, $memlimit, $alg);
1939
+			}
1940
+			return sodium_crypto_pwhash($outlen, $passwd, $salt, $opslimit, $memlimit);
1941
+		}
1942
+		if (self::use_fallback('crypto_pwhash')) {
1943
+			return (string) call_user_func('\\Sodium\\crypto_pwhash', $outlen, $passwd, $salt, $opslimit, $memlimit);
1944
+		}
1945
+		// This is the best we can do.
1946
+		throw new SodiumException(
1947
+			'This is not implemented, as it is not possible to implement Argon2i with acceptable performance in pure-PHP'
1948
+		);
1949
+	}
1950
+
1951
+	/**
1952
+	 * !Exclusive to sodium_compat!
1953
+	 *
1954
+	 * This returns TRUE if the native crypto_pwhash API is available by libsodium.
1955
+	 * This returns FALSE if only sodium_compat is available.
1956
+	 *
1957
+	 * @return bool
1958
+	 */
1959
+	public static function crypto_pwhash_is_available()
1960
+	{
1961
+		if (self::useNewSodiumAPI()) {
1962
+			return true;
1963
+		}
1964
+		if (self::use_fallback('crypto_pwhash')) {
1965
+			return true;
1966
+		}
1967
+		return false;
1968
+	}
1969
+
1970
+	/**
1971
+	 * @param string $passwd
1972
+	 * @param int $opslimit
1973
+	 * @param int $memlimit
1974
+	 * @return string
1975
+	 * @throws SodiumException
1976
+	 * @throws TypeError
1977
+	 * @psalm-suppress MixedArgument
1978
+	 */
1979
+	public static function crypto_pwhash_str($passwd, $opslimit, $memlimit)
1980
+	{
1981
+		ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 1);
1982
+		ParagonIE_Sodium_Core_Util::declareScalarType($opslimit, 'int', 2);
1983
+		ParagonIE_Sodium_Core_Util::declareScalarType($memlimit, 'int', 3);
1984
+
1985
+		if (self::useNewSodiumAPI()) {
1986
+			return sodium_crypto_pwhash_str($passwd, $opslimit, $memlimit);
1987
+		}
1988
+		if (self::use_fallback('crypto_pwhash_str')) {
1989
+			return (string) call_user_func('\\Sodium\\crypto_pwhash_str', $passwd, $opslimit, $memlimit);
1990
+		}
1991
+		// This is the best we can do.
1992
+		throw new SodiumException(
1993
+			'This is not implemented, as it is not possible to implement Argon2i with acceptable performance in pure-PHP'
1994
+		);
1995
+	}
1996
+
1997
+	/**
1998
+	 * Do we need to rehash this password?
1999
+	 *
2000
+	 * @param string $hash
2001
+	 * @param int $opslimit
2002
+	 * @param int $memlimit
2003
+	 * @return bool
2004
+	 * @throws SodiumException
2005
+	 */
2006
+	public static function crypto_pwhash_str_needs_rehash($hash, $opslimit, $memlimit)
2007
+	{
2008
+		ParagonIE_Sodium_Core_Util::declareScalarType($hash, 'string', 1);
2009
+		ParagonIE_Sodium_Core_Util::declareScalarType($opslimit, 'int', 2);
2010
+		ParagonIE_Sodium_Core_Util::declareScalarType($memlimit, 'int', 3);
2011
+
2012
+		// Just grab the first 4 pieces.
2013
+		$pieces = explode('$', (string) $hash);
2014
+		$prefix = implode('$', array_slice($pieces, 0, 4));
2015
+
2016
+		// Rebuild the expected header.
2017
+		/** @var int $ops */
2018
+		$ops = (int) $opslimit;
2019
+		/** @var int $mem */
2020
+		$mem = (int) $memlimit >> 10;
2021
+		$encoded = self::CRYPTO_PWHASH_STRPREFIX . 'v=19$m=' . $mem . ',t=' . $ops . ',p=1';
2022
+
2023
+		// Do they match? If so, we don't need to rehash, so return false.
2024
+		return !ParagonIE_Sodium_Core_Util::hashEquals($encoded, $prefix);
2025
+	}
2026
+
2027
+	/**
2028
+	 * @param string $passwd
2029
+	 * @param string $hash
2030
+	 * @return bool
2031
+	 * @throws SodiumException
2032
+	 * @throws TypeError
2033
+	 * @psalm-suppress MixedArgument
2034
+	 */
2035
+	public static function crypto_pwhash_str_verify($passwd, $hash)
2036
+	{
2037
+		ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 1);
2038
+		ParagonIE_Sodium_Core_Util::declareScalarType($hash, 'string', 2);
2039
+
2040
+		if (self::useNewSodiumAPI()) {
2041
+			return (bool) sodium_crypto_pwhash_str_verify($passwd, $hash);
2042
+		}
2043
+		if (self::use_fallback('crypto_pwhash_str_verify')) {
2044
+			return (bool) call_user_func('\\Sodium\\crypto_pwhash_str_verify', $passwd, $hash);
2045
+		}
2046
+		// This is the best we can do.
2047
+		throw new SodiumException(
2048
+			'This is not implemented, as it is not possible to implement Argon2i with acceptable performance in pure-PHP'
2049
+		);
2050
+	}
2051
+
2052
+	/**
2053
+	 * @param int $outlen
2054
+	 * @param string $passwd
2055
+	 * @param string $salt
2056
+	 * @param int $opslimit
2057
+	 * @param int $memlimit
2058
+	 * @return string
2059
+	 * @throws SodiumException
2060
+	 * @throws TypeError
2061
+	 */
2062
+	public static function crypto_pwhash_scryptsalsa208sha256($outlen, $passwd, $salt, $opslimit, $memlimit)
2063
+	{
2064
+		ParagonIE_Sodium_Core_Util::declareScalarType($outlen, 'int', 1);
2065
+		ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 2);
2066
+		ParagonIE_Sodium_Core_Util::declareScalarType($salt,  'string', 3);
2067
+		ParagonIE_Sodium_Core_Util::declareScalarType($opslimit, 'int', 4);
2068
+		ParagonIE_Sodium_Core_Util::declareScalarType($memlimit, 'int', 5);
2069
+
2070
+		if (self::useNewSodiumAPI()) {
2071
+			return (string) sodium_crypto_pwhash_scryptsalsa208sha256(
2072
+				(int) $outlen,
2073
+				(string) $passwd,
2074
+				(string) $salt,
2075
+				(int) $opslimit,
2076
+				(int) $memlimit
2077
+			);
2078
+		}
2079
+		if (self::use_fallback('crypto_pwhash_scryptsalsa208sha256')) {
2080
+			return (string) call_user_func(
2081
+				'\\Sodium\\crypto_pwhash_scryptsalsa208sha256',
2082
+				(int) $outlen,
2083
+				(string) $passwd,
2084
+				(string) $salt,
2085
+				(int) $opslimit,
2086
+				(int) $memlimit
2087
+			);
2088
+		}
2089
+		// This is the best we can do.
2090
+		throw new SodiumException(
2091
+			'This is not implemented, as it is not possible to implement Scrypt with acceptable performance in pure-PHP'
2092
+		);
2093
+	}
2094
+
2095
+	/**
2096
+	 * !Exclusive to sodium_compat!
2097
+	 *
2098
+	 * This returns TRUE if the native crypto_pwhash API is available by libsodium.
2099
+	 * This returns FALSE if only sodium_compat is available.
2100
+	 *
2101
+	 * @return bool
2102
+	 */
2103
+	public static function crypto_pwhash_scryptsalsa208sha256_is_available()
2104
+	{
2105
+		if (self::useNewSodiumAPI()) {
2106
+			return true;
2107
+		}
2108
+		if (self::use_fallback('crypto_pwhash_scryptsalsa208sha256')) {
2109
+			return true;
2110
+		}
2111
+		return false;
2112
+	}
2113
+
2114
+	/**
2115
+	 * @param string $passwd
2116
+	 * @param int $opslimit
2117
+	 * @param int $memlimit
2118
+	 * @return string
2119
+	 * @throws SodiumException
2120
+	 * @throws TypeError
2121
+	 */
2122
+	public static function crypto_pwhash_scryptsalsa208sha256_str($passwd, $opslimit, $memlimit)
2123
+	{
2124
+		ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 1);
2125
+		ParagonIE_Sodium_Core_Util::declareScalarType($opslimit, 'int', 2);
2126
+		ParagonIE_Sodium_Core_Util::declareScalarType($memlimit, 'int', 3);
2127
+
2128
+		if (self::useNewSodiumAPI()) {
2129
+			return (string) sodium_crypto_pwhash_scryptsalsa208sha256_str(
2130
+				(string) $passwd,
2131
+				(int) $opslimit,
2132
+				(int) $memlimit
2133
+			);
2134
+		}
2135
+		if (self::use_fallback('crypto_pwhash_scryptsalsa208sha256_str')) {
2136
+			return (string) call_user_func(
2137
+				'\\Sodium\\crypto_pwhash_scryptsalsa208sha256_str',
2138
+				(string) $passwd,
2139
+				(int) $opslimit,
2140
+				(int) $memlimit
2141
+			);
2142
+		}
2143
+		// This is the best we can do.
2144
+		throw new SodiumException(
2145
+			'This is not implemented, as it is not possible to implement Scrypt with acceptable performance in pure-PHP'
2146
+		);
2147
+	}
2148
+
2149
+	/**
2150
+	 * @param string $passwd
2151
+	 * @param string $hash
2152
+	 * @return bool
2153
+	 * @throws SodiumException
2154
+	 * @throws TypeError
2155
+	 */
2156
+	public static function crypto_pwhash_scryptsalsa208sha256_str_verify($passwd, $hash)
2157
+	{
2158
+		ParagonIE_Sodium_Core_Util::declareScalarType($passwd, 'string', 1);
2159
+		ParagonIE_Sodium_Core_Util::declareScalarType($hash, 'string', 2);
2160
+
2161
+		if (self::useNewSodiumAPI()) {
2162
+			return (bool) sodium_crypto_pwhash_scryptsalsa208sha256_str_verify(
2163
+				(string) $passwd,
2164
+				(string) $hash
2165
+			);
2166
+		}
2167
+		if (self::use_fallback('crypto_pwhash_scryptsalsa208sha256_str_verify')) {
2168
+			return (bool) call_user_func(
2169
+				'\\Sodium\\crypto_pwhash_scryptsalsa208sha256_str_verify',
2170
+				(string) $passwd,
2171
+				(string) $hash
2172
+			);
2173
+		}
2174
+		// This is the best we can do.
2175
+		throw new SodiumException(
2176
+			'This is not implemented, as it is not possible to implement Scrypt with acceptable performance in pure-PHP'
2177
+		);
2178
+	}
2179
+
2180
+	/**
2181
+	 * Calculate the shared secret between your secret key and your
2182
+	 * recipient's public key.
2183
+	 *
2184
+	 * Algorithm: X25519 (ECDH over Curve25519)
2185
+	 *
2186
+	 * @param string $secretKey
2187
+	 * @param string $publicKey
2188
+	 * @return string
2189
+	 * @throws SodiumException
2190
+	 * @throws TypeError
2191
+	 * @psalm-suppress MixedArgument
2192
+	 */
2193
+	public static function crypto_scalarmult($secretKey, $publicKey)
2194
+	{
2195
+		/* Type checks: */
2196
+		ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 1);
2197
+		ParagonIE_Sodium_Core_Util::declareScalarType($publicKey, 'string', 2);
2198
+
2199
+		/* Input validation: */
2200
+		if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_BOX_SECRETKEYBYTES) {
2201
+			throw new SodiumException('Argument 1 must be CRYPTO_BOX_SECRETKEYBYTES long.');
2202
+		}
2203
+		if (ParagonIE_Sodium_Core_Util::strlen($publicKey) !== self::CRYPTO_BOX_PUBLICKEYBYTES) {
2204
+			throw new SodiumException('Argument 2 must be CRYPTO_BOX_PUBLICKEYBYTES long.');
2205
+		}
2206
+
2207
+		if (self::useNewSodiumAPI()) {
2208
+			return sodium_crypto_scalarmult($secretKey, $publicKey);
2209
+		}
2210
+		if (self::use_fallback('crypto_scalarmult')) {
2211
+			return (string) call_user_func('\\Sodium\\crypto_scalarmult', $secretKey, $publicKey);
2212
+		}
2213
+
2214
+		/* Output validation: Forbid all-zero keys */
2215
+		if (ParagonIE_Sodium_Core_Util::hashEquals($secretKey, str_repeat("\0", self::CRYPTO_BOX_SECRETKEYBYTES))) {
2216
+			throw new SodiumException('Zero secret key is not allowed');
2217
+		}
2218
+		if (ParagonIE_Sodium_Core_Util::hashEquals($publicKey, str_repeat("\0", self::CRYPTO_BOX_PUBLICKEYBYTES))) {
2219
+			throw new SodiumException('Zero public key is not allowed');
2220
+		}
2221
+		if (PHP_INT_SIZE === 4) {
2222
+			return ParagonIE_Sodium_Crypto32::scalarmult($secretKey, $publicKey);
2223
+		}
2224
+		return ParagonIE_Sodium_Crypto::scalarmult($secretKey, $publicKey);
2225
+	}
2226
+
2227
+	/**
2228
+	 * Calculate an X25519 public key from an X25519 secret key.
2229
+	 *
2230
+	 * @param string $secretKey
2231
+	 * @return string
2232
+	 * @throws SodiumException
2233
+	 * @throws TypeError
2234
+	 * @psalm-suppress TooFewArguments
2235
+	 * @psalm-suppress MixedArgument
2236
+	 */
2237
+	public static function crypto_scalarmult_base($secretKey)
2238
+	{
2239
+		/* Type checks: */
2240
+		ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 1);
2241
+
2242
+		/* Input validation: */
2243
+		if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_BOX_SECRETKEYBYTES) {
2244
+			throw new SodiumException('Argument 1 must be CRYPTO_BOX_SECRETKEYBYTES long.');
2245
+		}
2246
+
2247
+		if (self::useNewSodiumAPI()) {
2248
+			return sodium_crypto_scalarmult_base($secretKey);
2249
+		}
2250
+		if (self::use_fallback('crypto_scalarmult_base')) {
2251
+			return (string) call_user_func('\\Sodium\\crypto_scalarmult_base', $secretKey);
2252
+		}
2253
+		if (ParagonIE_Sodium_Core_Util::hashEquals($secretKey, str_repeat("\0", self::CRYPTO_BOX_SECRETKEYBYTES))) {
2254
+			throw new SodiumException('Zero secret key is not allowed');
2255
+		}
2256
+		if (PHP_INT_SIZE === 4) {
2257
+			return ParagonIE_Sodium_Crypto32::scalarmult_base($secretKey);
2258
+		}
2259
+		return ParagonIE_Sodium_Crypto::scalarmult_base($secretKey);
2260
+	}
2261
+
2262
+	/**
2263
+	 * Authenticated symmetric-key encryption.
2264
+	 *
2265
+	 * Algorithm: XSalsa20-Poly1305
2266
+	 *
2267
+	 * @param string $plaintext The message you're encrypting
2268
+	 * @param string $nonce A Number to be used Once; must be 24 bytes
2269
+	 * @param string $key Symmetric encryption key
2270
+	 * @return string           Ciphertext with Poly1305 MAC
2271
+	 * @throws SodiumException
2272
+	 * @throws TypeError
2273
+	 * @psalm-suppress MixedArgument
2274
+	 */
2275
+	public static function crypto_secretbox($plaintext, $nonce, $key)
2276
+	{
2277
+		/* Type checks: */
2278
+		ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
2279
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
2280
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
2281
+
2282
+		/* Input validation: */
2283
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_SECRETBOX_NONCEBYTES) {
2284
+			throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
2285
+		}
2286
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_SECRETBOX_KEYBYTES) {
2287
+			throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_KEYBYTES long.');
2288
+		}
2289
+
2290
+		if (self::useNewSodiumAPI()) {
2291
+			return sodium_crypto_secretbox($plaintext, $nonce, $key);
2292
+		}
2293
+		if (self::use_fallback('crypto_secretbox')) {
2294
+			return (string) call_user_func('\\Sodium\\crypto_secretbox', $plaintext, $nonce, $key);
2295
+		}
2296
+		if (PHP_INT_SIZE === 4) {
2297
+			return ParagonIE_Sodium_Crypto32::secretbox($plaintext, $nonce, $key);
2298
+		}
2299
+		return ParagonIE_Sodium_Crypto::secretbox($plaintext, $nonce, $key);
2300
+	}
2301
+
2302
+	/**
2303
+	 * Decrypts a message previously encrypted with crypto_secretbox().
2304
+	 *
2305
+	 * @param string $ciphertext Ciphertext with Poly1305 MAC
2306
+	 * @param string $nonce      A Number to be used Once; must be 24 bytes
2307
+	 * @param string $key        Symmetric encryption key
2308
+	 * @return string            Original plaintext message
2309
+	 * @throws SodiumException
2310
+	 * @throws TypeError
2311
+	 * @psalm-suppress MixedArgument
2312
+	 * @psalm-suppress MixedInferredReturnType
2313
+	 * @psalm-suppress MixedReturnStatement
2314
+	 */
2315
+	public static function crypto_secretbox_open($ciphertext, $nonce, $key)
2316
+	{
2317
+		/* Type checks: */
2318
+		ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
2319
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
2320
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
2321
+
2322
+		/* Input validation: */
2323
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_SECRETBOX_NONCEBYTES) {
2324
+			throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
2325
+		}
2326
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_SECRETBOX_KEYBYTES) {
2327
+			throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_KEYBYTES long.');
2328
+		}
2329
+
2330
+		if (self::useNewSodiumAPI()) {
2331
+			/**
2332
+			 * @psalm-suppress InvalidReturnStatement
2333
+			 * @psalm-suppress FalsableReturnStatement
2334
+			 */
2335
+			return sodium_crypto_secretbox_open($ciphertext, $nonce, $key);
2336
+		}
2337
+		if (self::use_fallback('crypto_secretbox_open')) {
2338
+			return call_user_func('\\Sodium\\crypto_secretbox_open', $ciphertext, $nonce, $key);
2339
+		}
2340
+		if (PHP_INT_SIZE === 4) {
2341
+			return ParagonIE_Sodium_Crypto32::secretbox_open($ciphertext, $nonce, $key);
2342
+		}
2343
+		return ParagonIE_Sodium_Crypto::secretbox_open($ciphertext, $nonce, $key);
2344
+	}
2345
+
2346
+	/**
2347
+	 * Return a secure random key for use with crypto_secretbox
2348
+	 *
2349
+	 * @return string
2350
+	 * @throws Exception
2351
+	 * @throws Error
2352
+	 */
2353
+	public static function crypto_secretbox_keygen()
2354
+	{
2355
+		return random_bytes(self::CRYPTO_SECRETBOX_KEYBYTES);
2356
+	}
2357
+
2358
+	/**
2359
+	 * Authenticated symmetric-key encryption.
2360
+	 *
2361
+	 * Algorithm: XChaCha20-Poly1305
2362
+	 *
2363
+	 * @param string $plaintext The message you're encrypting
2364
+	 * @param string $nonce     A Number to be used Once; must be 24 bytes
2365
+	 * @param string $key       Symmetric encryption key
2366
+	 * @return string           Ciphertext with Poly1305 MAC
2367
+	 * @throws SodiumException
2368
+	 * @throws TypeError
2369
+	 * @psalm-suppress MixedArgument
2370
+	 */
2371
+	public static function crypto_secretbox_xchacha20poly1305($plaintext, $nonce, $key)
2372
+	{
2373
+		/* Type checks: */
2374
+		ParagonIE_Sodium_Core_Util::declareScalarType($plaintext, 'string', 1);
2375
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
2376
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
2377
+
2378
+		/* Input validation: */
2379
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_SECRETBOX_NONCEBYTES) {
2380
+			throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
2381
+		}
2382
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_SECRETBOX_KEYBYTES) {
2383
+			throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_KEYBYTES long.');
2384
+		}
2385
+		if (PHP_INT_SIZE === 4) {
2386
+			return ParagonIE_Sodium_Crypto32::secretbox_xchacha20poly1305($plaintext, $nonce, $key);
2387
+		}
2388
+		return ParagonIE_Sodium_Crypto::secretbox_xchacha20poly1305($plaintext, $nonce, $key);
2389
+	}
2390
+	/**
2391
+	 * Decrypts a message previously encrypted with crypto_secretbox_xchacha20poly1305().
2392
+	 *
2393
+	 * @param string $ciphertext Ciphertext with Poly1305 MAC
2394
+	 * @param string $nonce      A Number to be used Once; must be 24 bytes
2395
+	 * @param string $key        Symmetric encryption key
2396
+	 * @return string            Original plaintext message
2397
+	 * @throws SodiumException
2398
+	 * @throws TypeError
2399
+	 * @psalm-suppress MixedArgument
2400
+	 */
2401
+	public static function crypto_secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key)
2402
+	{
2403
+		/* Type checks: */
2404
+		ParagonIE_Sodium_Core_Util::declareScalarType($ciphertext, 'string', 1);
2405
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
2406
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
2407
+
2408
+		/* Input validation: */
2409
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_SECRETBOX_NONCEBYTES) {
2410
+			throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
2411
+		}
2412
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_SECRETBOX_KEYBYTES) {
2413
+			throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_KEYBYTES long.');
2414
+		}
2415
+
2416
+		if (PHP_INT_SIZE === 4) {
2417
+			return ParagonIE_Sodium_Crypto32::secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key);
2418
+		}
2419
+		return ParagonIE_Sodium_Crypto::secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key);
2420
+	}
2421
+
2422
+	/**
2423
+	 * @param string $key
2424
+	 * @return array<int, string> Returns a state and a header.
2425
+	 * @throws Exception
2426
+	 * @throws SodiumException
2427
+	 */
2428
+	public static function crypto_secretstream_xchacha20poly1305_init_push($key)
2429
+	{
2430
+		if (PHP_INT_SIZE === 4) {
2431
+			return ParagonIE_Sodium_Crypto32::secretstream_xchacha20poly1305_init_push($key);
2432
+		}
2433
+		return ParagonIE_Sodium_Crypto::secretstream_xchacha20poly1305_init_push($key);
2434
+	}
2435
+
2436
+	/**
2437
+	 * @param string $header
2438
+	 * @param string $key
2439
+	 * @return string Returns a state.
2440
+	 * @throws Exception
2441
+	 */
2442
+	public static function crypto_secretstream_xchacha20poly1305_init_pull($header, $key)
2443
+	{
2444
+		if (ParagonIE_Sodium_Core_Util::strlen($header) < self::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_HEADERBYTES) {
2445
+			throw new SodiumException(
2446
+				'header size should be SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_HEADERBYTES bytes'
2447
+			);
2448
+		}
2449
+		if (PHP_INT_SIZE === 4) {
2450
+			return ParagonIE_Sodium_Crypto32::secretstream_xchacha20poly1305_init_pull($key, $header);
2451
+		}
2452
+		return ParagonIE_Sodium_Crypto::secretstream_xchacha20poly1305_init_pull($key, $header);
2453
+	}
2454
+
2455
+	/**
2456
+	 * @param string $state
2457
+	 * @param string $msg
2458
+	 * @param string $aad
2459
+	 * @param int $tag
2460
+	 * @return string
2461
+	 * @throws SodiumException
2462
+	 */
2463
+	public static function crypto_secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0)
2464
+	{
2465
+		if (PHP_INT_SIZE === 4) {
2466
+			return ParagonIE_Sodium_Crypto32::secretstream_xchacha20poly1305_push(
2467
+				$state,
2468
+				$msg,
2469
+				$aad,
2470
+				$tag
2471
+			);
2472
+		}
2473
+		return ParagonIE_Sodium_Crypto::secretstream_xchacha20poly1305_push(
2474
+			$state,
2475
+			$msg,
2476
+			$aad,
2477
+			$tag
2478
+		);
2479
+	}
2480
+
2481
+	/**
2482
+	 * @param string $state
2483
+	 * @param string $msg
2484
+	 * @param string $aad
2485
+	 * @return bool|array{0: string, 1: int}
2486
+	 * @throws SodiumException
2487
+	 */
2488
+	public static function crypto_secretstream_xchacha20poly1305_pull(&$state, $msg, $aad = '')
2489
+	{
2490
+		if (PHP_INT_SIZE === 4) {
2491
+			return ParagonIE_Sodium_Crypto32::secretstream_xchacha20poly1305_pull(
2492
+				$state,
2493
+				$msg,
2494
+				$aad
2495
+			);
2496
+		}
2497
+		return ParagonIE_Sodium_Crypto::secretstream_xchacha20poly1305_pull(
2498
+			$state,
2499
+			$msg,
2500
+			$aad
2501
+		);
2502
+	}
2503
+
2504
+	/**
2505
+	 * @return string
2506
+	 * @throws Exception
2507
+	 */
2508
+	public static function crypto_secretstream_xchacha20poly1305_keygen()
2509
+	{
2510
+		return random_bytes(self::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_KEYBYTES);
2511
+	}
2512
+
2513
+	/**
2514
+	 * @param string $state
2515
+	 * @return void
2516
+	 * @throws SodiumException
2517
+	 */
2518
+	public static function crypto_secretstream_xchacha20poly1305_rekey(&$state)
2519
+	{
2520
+		if (PHP_INT_SIZE === 4) {
2521
+			ParagonIE_Sodium_Crypto32::secretstream_xchacha20poly1305_rekey($state);
2522
+		} else {
2523
+			ParagonIE_Sodium_Crypto::secretstream_xchacha20poly1305_rekey($state);
2524
+		}
2525
+	}
2526
+
2527
+	/**
2528
+	 * Calculates a SipHash-2-4 hash of a message for a given key.
2529
+	 *
2530
+	 * @param string $message Input message
2531
+	 * @param string $key SipHash-2-4 key
2532
+	 * @return string         Hash
2533
+	 * @throws SodiumException
2534
+	 * @throws TypeError
2535
+	 * @psalm-suppress MixedArgument
2536
+	 * @psalm-suppress MixedInferredReturnType
2537
+	 * @psalm-suppress MixedReturnStatement
2538
+	 */
2539
+	public static function crypto_shorthash($message, $key)
2540
+	{
2541
+		/* Type checks: */
2542
+		ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
2543
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 2);
2544
+
2545
+		/* Input validation: */
2546
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_SHORTHASH_KEYBYTES) {
2547
+			throw new SodiumException('Argument 2 must be CRYPTO_SHORTHASH_KEYBYTES long.');
2548
+		}
2549
+
2550
+		if (self::useNewSodiumAPI()) {
2551
+			return sodium_crypto_shorthash($message, $key);
2552
+		}
2553
+		if (self::use_fallback('crypto_shorthash')) {
2554
+			return (string) call_user_func('\\Sodium\\crypto_shorthash', $message, $key);
2555
+		}
2556
+		if (PHP_INT_SIZE === 4) {
2557
+			return ParagonIE_Sodium_Core32_SipHash::sipHash24($message, $key);
2558
+		}
2559
+		return ParagonIE_Sodium_Core_SipHash::sipHash24($message, $key);
2560
+	}
2561
+
2562
+	/**
2563
+	 * Return a secure random key for use with crypto_shorthash
2564
+	 *
2565
+	 * @return string
2566
+	 * @throws Exception
2567
+	 * @throws Error
2568
+	 */
2569
+	public static function crypto_shorthash_keygen()
2570
+	{
2571
+		return random_bytes(self::CRYPTO_SHORTHASH_KEYBYTES);
2572
+	}
2573
+
2574
+	/**
2575
+	 * Returns a signed message. You probably want crypto_sign_detached()
2576
+	 * instead, which only returns the signature.
2577
+	 *
2578
+	 * Algorithm: Ed25519 (EdDSA over Curve25519)
2579
+	 *
2580
+	 * @param string $message Message to be signed.
2581
+	 * @param string $secretKey Secret signing key.
2582
+	 * @return string           Signed message (signature is prefixed).
2583
+	 * @throws SodiumException
2584
+	 * @throws TypeError
2585
+	 * @psalm-suppress MixedArgument
2586
+	 * @psalm-suppress MixedInferredReturnType
2587
+	 * @psalm-suppress MixedReturnStatement
2588
+	 */
2589
+	public static function crypto_sign($message, $secretKey)
2590
+	{
2591
+		/* Type checks: */
2592
+		ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
2593
+		ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 2);
2594
+
2595
+		/* Input validation: */
2596
+		if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_SIGN_SECRETKEYBYTES) {
2597
+			throw new SodiumException('Argument 2 must be CRYPTO_SIGN_SECRETKEYBYTES long.');
2598
+		}
2599
+
2600
+		if (self::useNewSodiumAPI()) {
2601
+			return sodium_crypto_sign($message, $secretKey);
2602
+		}
2603
+		if (self::use_fallback('crypto_sign')) {
2604
+			return (string) call_user_func('\\Sodium\\crypto_sign', $message, $secretKey);
2605
+		}
2606
+		if (PHP_INT_SIZE === 4) {
2607
+			return ParagonIE_Sodium_Crypto32::sign($message, $secretKey);
2608
+		}
2609
+		return ParagonIE_Sodium_Crypto::sign($message, $secretKey);
2610
+	}
2611
+
2612
+	/**
2613
+	 * Validates a signed message then returns the message.
2614
+	 *
2615
+	 * @param string $signedMessage A signed message
2616
+	 * @param string $publicKey A public key
2617
+	 * @return string               The original message (if the signature is
2618
+	 *                              valid for this public key)
2619
+	 * @throws SodiumException
2620
+	 * @throws TypeError
2621
+	 * @psalm-suppress MixedArgument
2622
+	 * @psalm-suppress MixedInferredReturnType
2623
+	 * @psalm-suppress MixedReturnStatement
2624
+	 */
2625
+	public static function crypto_sign_open($signedMessage, $publicKey)
2626
+	{
2627
+		/* Type checks: */
2628
+		ParagonIE_Sodium_Core_Util::declareScalarType($signedMessage, 'string', 1);
2629
+		ParagonIE_Sodium_Core_Util::declareScalarType($publicKey, 'string', 2);
2630
+
2631
+		/* Input validation: */
2632
+		if (ParagonIE_Sodium_Core_Util::strlen($signedMessage) < self::CRYPTO_SIGN_BYTES) {
2633
+			throw new SodiumException('Argument 1 must be at least CRYPTO_SIGN_BYTES long.');
2634
+		}
2635
+		if (ParagonIE_Sodium_Core_Util::strlen($publicKey) !== self::CRYPTO_SIGN_PUBLICKEYBYTES) {
2636
+			throw new SodiumException('Argument 2 must be CRYPTO_SIGN_PUBLICKEYBYTES long.');
2637
+		}
2638
+
2639
+		if (self::useNewSodiumAPI()) {
2640
+			/**
2641
+			 * @psalm-suppress InvalidReturnStatement
2642
+			 * @psalm-suppress FalsableReturnStatement
2643
+			 */
2644
+			return sodium_crypto_sign_open($signedMessage, $publicKey);
2645
+		}
2646
+		if (self::use_fallback('crypto_sign_open')) {
2647
+			return call_user_func('\\Sodium\\crypto_sign_open', $signedMessage, $publicKey);
2648
+		}
2649
+		if (PHP_INT_SIZE === 4) {
2650
+			return ParagonIE_Sodium_Crypto32::sign_open($signedMessage, $publicKey);
2651
+		}
2652
+		return ParagonIE_Sodium_Crypto::sign_open($signedMessage, $publicKey);
2653
+	}
2654
+
2655
+	/**
2656
+	 * Generate a new random Ed25519 keypair.
2657
+	 *
2658
+	 * @return string
2659
+	 * @throws SodiumException
2660
+	 * @throws TypeError
2661
+	 */
2662
+	public static function crypto_sign_keypair()
2663
+	{
2664
+		if (self::useNewSodiumAPI()) {
2665
+			return sodium_crypto_sign_keypair();
2666
+		}
2667
+		if (self::use_fallback('crypto_sign_keypair')) {
2668
+			return (string) call_user_func('\\Sodium\\crypto_sign_keypair');
2669
+		}
2670
+		if (PHP_INT_SIZE === 4) {
2671
+			return ParagonIE_Sodium_Core32_Ed25519::keypair();
2672
+		}
2673
+		return ParagonIE_Sodium_Core_Ed25519::keypair();
2674
+	}
2675
+
2676
+	/**
2677
+	 * @param string $sk
2678
+	 * @param string $pk
2679
+	 * @return string
2680
+	 * @throws SodiumException
2681
+	 */
2682
+	public static function crypto_sign_keypair_from_secretkey_and_publickey($sk, $pk)
2683
+	{
2684
+		ParagonIE_Sodium_Core_Util::declareScalarType($sk, 'string', 1);
2685
+		ParagonIE_Sodium_Core_Util::declareScalarType($pk, 'string', 1);
2686
+		$sk = (string) $sk;
2687
+		$pk = (string) $pk;
2688
+
2689
+		if (ParagonIE_Sodium_Core_Util::strlen($sk) !== self::CRYPTO_SIGN_SECRETKEYBYTES) {
2690
+			throw new SodiumException('secretkey should be SODIUM_CRYPTO_SIGN_SECRETKEYBYTES bytes');
2691
+		}
2692
+		if (ParagonIE_Sodium_Core_Util::strlen($pk) !== self::CRYPTO_SIGN_PUBLICKEYBYTES) {
2693
+			throw new SodiumException('publickey should be SODIUM_CRYPTO_SIGN_PUBLICKEYBYTES bytes');
2694
+		}
2695
+
2696
+		if (self::useNewSodiumAPI()) {
2697
+			return sodium_crypto_sign_keypair_from_secretkey_and_publickey($sk, $pk);
2698
+		}
2699
+		return $sk . $pk;
2700
+	}
2701
+
2702
+	/**
2703
+	 * Generate an Ed25519 keypair from a seed.
2704
+	 *
2705
+	 * @param string $seed Input seed
2706
+	 * @return string      Keypair
2707
+	 * @throws SodiumException
2708
+	 * @throws TypeError
2709
+	 * @psalm-suppress MixedArgument
2710
+	 */
2711
+	public static function crypto_sign_seed_keypair($seed)
2712
+	{
2713
+		ParagonIE_Sodium_Core_Util::declareScalarType($seed, 'string', 1);
2714
+
2715
+		if (self::useNewSodiumAPI()) {
2716
+			return sodium_crypto_sign_seed_keypair($seed);
2717
+		}
2718
+		if (self::use_fallback('crypto_sign_keypair')) {
2719
+			return (string) call_user_func('\\Sodium\\crypto_sign_seed_keypair', $seed);
2720
+		}
2721
+		$publicKey = '';
2722
+		$secretKey = '';
2723
+		if (PHP_INT_SIZE === 4) {
2724
+			ParagonIE_Sodium_Core32_Ed25519::seed_keypair($publicKey, $secretKey, $seed);
2725
+		} else {
2726
+			ParagonIE_Sodium_Core_Ed25519::seed_keypair($publicKey, $secretKey, $seed);
2727
+		}
2728
+		return $secretKey . $publicKey;
2729
+	}
2730
+
2731
+	/**
2732
+	 * Extract an Ed25519 public key from an Ed25519 keypair.
2733
+	 *
2734
+	 * @param string $keypair Keypair
2735
+	 * @return string         Public key
2736
+	 * @throws SodiumException
2737
+	 * @throws TypeError
2738
+	 * @psalm-suppress MixedArgument
2739
+	 */
2740
+	public static function crypto_sign_publickey($keypair)
2741
+	{
2742
+		/* Type checks: */
2743
+		ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
2744
+
2745
+		/* Input validation: */
2746
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_SIGN_KEYPAIRBYTES) {
2747
+			throw new SodiumException('Argument 1 must be CRYPTO_SIGN_KEYPAIRBYTES long.');
2748
+		}
2749
+
2750
+		if (self::useNewSodiumAPI()) {
2751
+			return sodium_crypto_sign_publickey($keypair);
2752
+		}
2753
+		if (self::use_fallback('crypto_sign_publickey')) {
2754
+			return (string) call_user_func('\\Sodium\\crypto_sign_publickey', $keypair);
2755
+		}
2756
+		if (PHP_INT_SIZE === 4) {
2757
+			return ParagonIE_Sodium_Core32_Ed25519::publickey($keypair);
2758
+		}
2759
+		return ParagonIE_Sodium_Core_Ed25519::publickey($keypair);
2760
+	}
2761
+
2762
+	/**
2763
+	 * Calculate an Ed25519 public key from an Ed25519 secret key.
2764
+	 *
2765
+	 * @param string $secretKey Your Ed25519 secret key
2766
+	 * @return string           The corresponding Ed25519 public key
2767
+	 * @throws SodiumException
2768
+	 * @throws TypeError
2769
+	 * @psalm-suppress MixedArgument
2770
+	 */
2771
+	public static function crypto_sign_publickey_from_secretkey($secretKey)
2772
+	{
2773
+		/* Type checks: */
2774
+		ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 1);
2775
+
2776
+		/* Input validation: */
2777
+		if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_SIGN_SECRETKEYBYTES) {
2778
+			throw new SodiumException('Argument 1 must be CRYPTO_SIGN_SECRETKEYBYTES long.');
2779
+		}
2780
+
2781
+		if (self::useNewSodiumAPI()) {
2782
+			return sodium_crypto_sign_publickey_from_secretkey($secretKey);
2783
+		}
2784
+		if (self::use_fallback('crypto_sign_publickey_from_secretkey')) {
2785
+			return (string) call_user_func('\\Sodium\\crypto_sign_publickey_from_secretkey', $secretKey);
2786
+		}
2787
+		if (PHP_INT_SIZE === 4) {
2788
+			return ParagonIE_Sodium_Core32_Ed25519::publickey_from_secretkey($secretKey);
2789
+		}
2790
+		return ParagonIE_Sodium_Core_Ed25519::publickey_from_secretkey($secretKey);
2791
+	}
2792
+
2793
+	/**
2794
+	 * Extract an Ed25519 secret key from an Ed25519 keypair.
2795
+	 *
2796
+	 * @param string $keypair Keypair
2797
+	 * @return string         Secret key
2798
+	 * @throws SodiumException
2799
+	 * @throws TypeError
2800
+	 * @psalm-suppress MixedArgument
2801
+	 */
2802
+	public static function crypto_sign_secretkey($keypair)
2803
+	{
2804
+		/* Type checks: */
2805
+		ParagonIE_Sodium_Core_Util::declareScalarType($keypair, 'string', 1);
2806
+
2807
+		/* Input validation: */
2808
+		if (ParagonIE_Sodium_Core_Util::strlen($keypair) !== self::CRYPTO_SIGN_KEYPAIRBYTES) {
2809
+			throw new SodiumException('Argument 1 must be CRYPTO_SIGN_KEYPAIRBYTES long.');
2810
+		}
2811
+
2812
+		if (self::useNewSodiumAPI()) {
2813
+			return sodium_crypto_sign_secretkey($keypair);
2814
+		}
2815
+		if (self::use_fallback('crypto_sign_secretkey')) {
2816
+			return (string) call_user_func('\\Sodium\\crypto_sign_secretkey', $keypair);
2817
+		}
2818
+		if (PHP_INT_SIZE === 4) {
2819
+			return ParagonIE_Sodium_Core32_Ed25519::secretkey($keypair);
2820
+		}
2821
+		return ParagonIE_Sodium_Core_Ed25519::secretkey($keypair);
2822
+	}
2823
+
2824
+	/**
2825
+	 * Calculate the Ed25519 signature of a message and return ONLY the signature.
2826
+	 *
2827
+	 * Algorithm: Ed25519 (EdDSA over Curve25519)
2828
+	 *
2829
+	 * @param string $message Message to be signed
2830
+	 * @param string $secretKey Secret signing key
2831
+	 * @return string           Digital signature
2832
+	 * @throws SodiumException
2833
+	 * @throws TypeError
2834
+	 * @psalm-suppress MixedArgument
2835
+	 */
2836
+	public static function crypto_sign_detached($message, $secretKey)
2837
+	{
2838
+		/* Type checks: */
2839
+		ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
2840
+		ParagonIE_Sodium_Core_Util::declareScalarType($secretKey, 'string', 2);
2841
+
2842
+		/* Input validation: */
2843
+		if (ParagonIE_Sodium_Core_Util::strlen($secretKey) !== self::CRYPTO_SIGN_SECRETKEYBYTES) {
2844
+			throw new SodiumException('Argument 2 must be CRYPTO_SIGN_SECRETKEYBYTES long.');
2845
+		}
2846
+
2847
+		if (self::useNewSodiumAPI()) {
2848
+			return sodium_crypto_sign_detached($message, $secretKey);
2849
+		}
2850
+		if (self::use_fallback('crypto_sign_detached')) {
2851
+			return (string) call_user_func('\\Sodium\\crypto_sign_detached', $message, $secretKey);
2852
+		}
2853
+		if (PHP_INT_SIZE === 4) {
2854
+			return ParagonIE_Sodium_Crypto32::sign_detached($message, $secretKey);
2855
+		}
2856
+		return ParagonIE_Sodium_Crypto::sign_detached($message, $secretKey);
2857
+	}
2858
+
2859
+	/**
2860
+	 * Verify the Ed25519 signature of a message.
2861
+	 *
2862
+	 * @param string $signature Digital sginature
2863
+	 * @param string $message Message to be verified
2864
+	 * @param string $publicKey Public key
2865
+	 * @return bool             TRUE if this signature is good for this public key;
2866
+	 *                          FALSE otherwise
2867
+	 * @throws SodiumException
2868
+	 * @throws TypeError
2869
+	 * @psalm-suppress MixedArgument
2870
+	 */
2871
+	public static function crypto_sign_verify_detached($signature, $message, $publicKey)
2872
+	{
2873
+		/* Type checks: */
2874
+		ParagonIE_Sodium_Core_Util::declareScalarType($signature, 'string', 1);
2875
+		ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 2);
2876
+		ParagonIE_Sodium_Core_Util::declareScalarType($publicKey, 'string', 3);
2877
+
2878
+		/* Input validation: */
2879
+		if (ParagonIE_Sodium_Core_Util::strlen($signature) !== self::CRYPTO_SIGN_BYTES) {
2880
+			throw new SodiumException('Argument 1 must be CRYPTO_SIGN_BYTES long.');
2881
+		}
2882
+		if (ParagonIE_Sodium_Core_Util::strlen($publicKey) !== self::CRYPTO_SIGN_PUBLICKEYBYTES) {
2883
+			throw new SodiumException('Argument 3 must be CRYPTO_SIGN_PUBLICKEYBYTES long.');
2884
+		}
2885
+
2886
+		if (self::useNewSodiumAPI()) {
2887
+			return sodium_crypto_sign_verify_detached($signature, $message, $publicKey);
2888
+		}
2889
+		if (self::use_fallback('crypto_sign_verify_detached')) {
2890
+			return (bool) call_user_func(
2891
+				'\\Sodium\\crypto_sign_verify_detached',
2892
+				$signature,
2893
+				$message,
2894
+				$publicKey
2895
+			);
2896
+		}
2897
+		if (PHP_INT_SIZE === 4) {
2898
+			return ParagonIE_Sodium_Crypto32::sign_verify_detached($signature, $message, $publicKey);
2899
+		}
2900
+		return ParagonIE_Sodium_Crypto::sign_verify_detached($signature, $message, $publicKey);
2901
+	}
2902
+
2903
+	/**
2904
+	 * Convert an Ed25519 public key to a Curve25519 public key
2905
+	 *
2906
+	 * @param string $pk
2907
+	 * @return string
2908
+	 * @throws SodiumException
2909
+	 * @throws TypeError
2910
+	 * @psalm-suppress MixedArgument
2911
+	 */
2912
+	public static function crypto_sign_ed25519_pk_to_curve25519($pk)
2913
+	{
2914
+		/* Type checks: */
2915
+		ParagonIE_Sodium_Core_Util::declareScalarType($pk, 'string', 1);
2916
+
2917
+		/* Input validation: */
2918
+		if (ParagonIE_Sodium_Core_Util::strlen($pk) < self::CRYPTO_SIGN_PUBLICKEYBYTES) {
2919
+			throw new SodiumException('Argument 1 must be at least CRYPTO_SIGN_PUBLICKEYBYTES long.');
2920
+		}
2921
+		if (self::useNewSodiumAPI()) {
2922
+			if (is_callable('crypto_sign_ed25519_pk_to_curve25519')) {
2923
+				return (string) sodium_crypto_sign_ed25519_pk_to_curve25519($pk);
2924
+			}
2925
+		}
2926
+		if (self::use_fallback('crypto_sign_ed25519_pk_to_curve25519')) {
2927
+			return (string) call_user_func('\\Sodium\\crypto_sign_ed25519_pk_to_curve25519', $pk);
2928
+		}
2929
+		if (PHP_INT_SIZE === 4) {
2930
+			return ParagonIE_Sodium_Core32_Ed25519::pk_to_curve25519($pk);
2931
+		}
2932
+		return ParagonIE_Sodium_Core_Ed25519::pk_to_curve25519($pk);
2933
+	}
2934
+
2935
+	/**
2936
+	 * Convert an Ed25519 secret key to a Curve25519 secret key
2937
+	 *
2938
+	 * @param string $sk
2939
+	 * @return string
2940
+	 * @throws SodiumException
2941
+	 * @throws TypeError
2942
+	 * @psalm-suppress MixedArgument
2943
+	 */
2944
+	public static function crypto_sign_ed25519_sk_to_curve25519($sk)
2945
+	{
2946
+		/* Type checks: */
2947
+		ParagonIE_Sodium_Core_Util::declareScalarType($sk, 'string', 1);
2948
+
2949
+		/* Input validation: */
2950
+		if (ParagonIE_Sodium_Core_Util::strlen($sk) < self::CRYPTO_SIGN_SEEDBYTES) {
2951
+			throw new SodiumException('Argument 1 must be at least CRYPTO_SIGN_SEEDBYTES long.');
2952
+		}
2953
+		if (self::useNewSodiumAPI()) {
2954
+			if (is_callable('crypto_sign_ed25519_sk_to_curve25519')) {
2955
+				return sodium_crypto_sign_ed25519_sk_to_curve25519($sk);
2956
+			}
2957
+		}
2958
+		if (self::use_fallback('crypto_sign_ed25519_sk_to_curve25519')) {
2959
+			return (string) call_user_func('\\Sodium\\crypto_sign_ed25519_sk_to_curve25519', $sk);
2960
+		}
2961
+
2962
+		$h = hash('sha512', ParagonIE_Sodium_Core_Util::substr($sk, 0, 32), true);
2963
+		$h[0] = ParagonIE_Sodium_Core_Util::intToChr(
2964
+			ParagonIE_Sodium_Core_Util::chrToInt($h[0]) & 248
2965
+		);
2966
+		$h[31] = ParagonIE_Sodium_Core_Util::intToChr(
2967
+			(ParagonIE_Sodium_Core_Util::chrToInt($h[31]) & 127) | 64
2968
+		);
2969
+		return ParagonIE_Sodium_Core_Util::substr($h, 0, 32);
2970
+	}
2971
+
2972
+	/**
2973
+	 * Expand a key and nonce into a keystream of pseudorandom bytes.
2974
+	 *
2975
+	 * @param int $len Number of bytes desired
2976
+	 * @param string $nonce Number to be used Once; must be 24 bytes
2977
+	 * @param string $key XSalsa20 key
2978
+	 * @return string       Pseudorandom stream that can be XORed with messages
2979
+	 *                      to provide encryption (but not authentication; see
2980
+	 *                      Poly1305 or crypto_auth() for that, which is not
2981
+	 *                      optional for security)
2982
+	 * @throws SodiumException
2983
+	 * @throws TypeError
2984
+	 * @psalm-suppress MixedArgument
2985
+	 */
2986
+	public static function crypto_stream($len, $nonce, $key)
2987
+	{
2988
+		/* Type checks: */
2989
+		ParagonIE_Sodium_Core_Util::declareScalarType($len, 'int', 1);
2990
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
2991
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
2992
+
2993
+		/* Input validation: */
2994
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_STREAM_NONCEBYTES) {
2995
+			throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
2996
+		}
2997
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_STREAM_KEYBYTES) {
2998
+			throw new SodiumException('Argument 3 must be CRYPTO_STREAM_KEYBYTES long.');
2999
+		}
3000
+
3001
+		if (self::useNewSodiumAPI()) {
3002
+			return sodium_crypto_stream($len, $nonce, $key);
3003
+		}
3004
+		if (self::use_fallback('crypto_stream')) {
3005
+			return (string) call_user_func('\\Sodium\\crypto_stream', $len, $nonce, $key);
3006
+		}
3007
+		if (PHP_INT_SIZE === 4) {
3008
+			return ParagonIE_Sodium_Core32_XSalsa20::xsalsa20($len, $nonce, $key);
3009
+		}
3010
+		return ParagonIE_Sodium_Core_XSalsa20::xsalsa20($len, $nonce, $key);
3011
+	}
3012
+
3013
+	/**
3014
+	 * DANGER! UNAUTHENTICATED ENCRYPTION!
3015
+	 *
3016
+	 * Unless you are following expert advice, do not use this feature.
3017
+	 *
3018
+	 * Algorithm: XSalsa20
3019
+	 *
3020
+	 * This DOES NOT provide ciphertext integrity.
3021
+	 *
3022
+	 * @param string $message Plaintext message
3023
+	 * @param string $nonce Number to be used Once; must be 24 bytes
3024
+	 * @param string $key Encryption key
3025
+	 * @return string         Encrypted text which is vulnerable to chosen-
3026
+	 *                        ciphertext attacks unless you implement some
3027
+	 *                        other mitigation to the ciphertext (i.e.
3028
+	 *                        Encrypt then MAC)
3029
+	 * @throws SodiumException
3030
+	 * @throws TypeError
3031
+	 * @psalm-suppress MixedArgument
3032
+	 */
3033
+	public static function crypto_stream_xor($message, $nonce, $key)
3034
+	{
3035
+		/* Type checks: */
3036
+		ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
3037
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
3038
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
3039
+
3040
+		/* Input validation: */
3041
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_STREAM_NONCEBYTES) {
3042
+			throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_NONCEBYTES long.');
3043
+		}
3044
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_STREAM_KEYBYTES) {
3045
+			throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_KEYBYTES long.');
3046
+		}
3047
+
3048
+		if (self::useNewSodiumAPI()) {
3049
+			return sodium_crypto_stream_xor($message, $nonce, $key);
3050
+		}
3051
+		if (self::use_fallback('crypto_stream_xor')) {
3052
+			return (string) call_user_func('\\Sodium\\crypto_stream_xor', $message, $nonce, $key);
3053
+		}
3054
+		if (PHP_INT_SIZE === 4) {
3055
+			return ParagonIE_Sodium_Core32_XSalsa20::xsalsa20_xor($message, $nonce, $key);
3056
+		}
3057
+		return ParagonIE_Sodium_Core_XSalsa20::xsalsa20_xor($message, $nonce, $key);
3058
+	}
3059
+
3060
+	/**
3061
+	 * Return a secure random key for use with crypto_stream
3062
+	 *
3063
+	 * @return string
3064
+	 * @throws Exception
3065
+	 * @throws Error
3066
+	 */
3067
+	public static function crypto_stream_keygen()
3068
+	{
3069
+		return random_bytes(self::CRYPTO_STREAM_KEYBYTES);
3070
+	}
3071
+
3072
+
3073
+	/**
3074
+	 * Expand a key and nonce into a keystream of pseudorandom bytes.
3075
+	 *
3076
+	 * @param int $len Number of bytes desired
3077
+	 * @param string $nonce Number to be used Once; must be 24 bytes
3078
+	 * @param string $key XChaCha20 key
3079
+	 * @param bool $dontFallback
3080
+	 * @return string       Pseudorandom stream that can be XORed with messages
3081
+	 *                      to provide encryption (but not authentication; see
3082
+	 *                      Poly1305 or crypto_auth() for that, which is not
3083
+	 *                      optional for security)
3084
+	 * @throws SodiumException
3085
+	 * @throws TypeError
3086
+	 * @psalm-suppress MixedArgument
3087
+	 */
3088
+	public static function crypto_stream_xchacha20($len, $nonce, $key, $dontFallback = false)
3089
+	{
3090
+		/* Type checks: */
3091
+		ParagonIE_Sodium_Core_Util::declareScalarType($len, 'int', 1);
3092
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
3093
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
3094
+
3095
+		/* Input validation: */
3096
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_STREAM_XCHACHA20_NONCEBYTES) {
3097
+			throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_XCHACHA20_NONCEBYTES long.');
3098
+		}
3099
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_STREAM_XCHACHA20_KEYBYTES) {
3100
+			throw new SodiumException('Argument 3 must be CRYPTO_STREAM_XCHACHA20_KEYBYTES long.');
3101
+		}
3102
+
3103
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3104
+			return sodium_crypto_stream_xchacha20($len, $nonce, $key);
3105
+		}
3106
+		if (PHP_INT_SIZE === 4) {
3107
+			return ParagonIE_Sodium_Core32_XChaCha20::stream($len, $nonce, $key);
3108
+		}
3109
+		return ParagonIE_Sodium_Core_XChaCha20::stream($len, $nonce, $key);
3110
+	}
3111
+
3112
+	/**
3113
+	 * DANGER! UNAUTHENTICATED ENCRYPTION!
3114
+	 *
3115
+	 * Unless you are following expert advice, do not use this feature.
3116
+	 *
3117
+	 * Algorithm: XChaCha20
3118
+	 *
3119
+	 * This DOES NOT provide ciphertext integrity.
3120
+	 *
3121
+	 * @param string $message Plaintext message
3122
+	 * @param string $nonce Number to be used Once; must be 24 bytes
3123
+	 * @param string $key Encryption key
3124
+	 * @return string         Encrypted text which is vulnerable to chosen-
3125
+	 *                        ciphertext attacks unless you implement some
3126
+	 *                        other mitigation to the ciphertext (i.e.
3127
+	 *                        Encrypt then MAC)
3128
+	 * @param bool $dontFallback
3129
+	 * @throws SodiumException
3130
+	 * @throws TypeError
3131
+	 * @psalm-suppress MixedArgument
3132
+	 */
3133
+	public static function crypto_stream_xchacha20_xor($message, $nonce, $key, $dontFallback = false)
3134
+	{
3135
+		/* Type checks: */
3136
+		ParagonIE_Sodium_Core_Util::declareScalarType($message, 'string', 1);
3137
+		ParagonIE_Sodium_Core_Util::declareScalarType($nonce, 'string', 2);
3138
+		ParagonIE_Sodium_Core_Util::declareScalarType($key, 'string', 3);
3139
+
3140
+		/* Input validation: */
3141
+		if (ParagonIE_Sodium_Core_Util::strlen($nonce) !== self::CRYPTO_STREAM_XCHACHA20_NONCEBYTES) {
3142
+			throw new SodiumException('Argument 2 must be CRYPTO_SECRETBOX_XCHACHA20_NONCEBYTES long.');
3143
+		}
3144
+		if (ParagonIE_Sodium_Core_Util::strlen($key) !== self::CRYPTO_STREAM_XCHACHA20_KEYBYTES) {
3145
+			throw new SodiumException('Argument 3 must be CRYPTO_SECRETBOX_XCHACHA20_KEYBYTES long.');
3146
+		}
3147
+
3148
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3149
+			return sodium_crypto_stream_xchacha20_xor($message, $nonce, $key);
3150
+		}
3151
+		if (PHP_INT_SIZE === 4) {
3152
+			return ParagonIE_Sodium_Core32_XChaCha20::streamXorIc($message, $nonce, $key);
3153
+		}
3154
+		return ParagonIE_Sodium_Core_XChaCha20::streamXorIc($message, $nonce, $key);
3155
+	}
3156
+
3157
+	/**
3158
+	 * Return a secure random key for use with crypto_stream_xchacha20
3159
+	 *
3160
+	 * @return string
3161
+	 * @throws Exception
3162
+	 * @throws Error
3163
+	 */
3164
+	public static function crypto_stream_xchacha20_keygen()
3165
+	{
3166
+		return random_bytes(self::CRYPTO_STREAM_XCHACHA20_KEYBYTES);
3167
+	}
3168
+
3169
+	/**
3170
+	 * Cache-timing-safe implementation of hex2bin().
3171
+	 *
3172
+	 * @param string $string Hexadecimal string
3173
+	 * @return string        Raw binary string
3174
+	 * @throws SodiumException
3175
+	 * @throws TypeError
3176
+	 * @psalm-suppress TooFewArguments
3177
+	 * @psalm-suppress MixedArgument
3178
+	 */
3179
+	public static function hex2bin($string)
3180
+	{
3181
+		/* Type checks: */
3182
+		ParagonIE_Sodium_Core_Util::declareScalarType($string, 'string', 1);
3183
+
3184
+		if (self::useNewSodiumAPI()) {
3185
+			if (is_callable('sodium_hex2bin')) {
3186
+				return (string) sodium_hex2bin($string);
3187
+			}
3188
+		}
3189
+		if (self::use_fallback('hex2bin')) {
3190
+			return (string) call_user_func('\\Sodium\\hex2bin', $string);
3191
+		}
3192
+		return ParagonIE_Sodium_Core_Util::hex2bin($string);
3193
+	}
3194
+
3195
+	/**
3196
+	 * Increase a string (little endian)
3197
+	 *
3198
+	 * @param string $var
3199
+	 *
3200
+	 * @return void
3201
+	 * @throws SodiumException
3202
+	 * @throws TypeError
3203
+	 * @psalm-suppress MixedArgument
3204
+	 */
3205
+	public static function increment(&$var)
3206
+	{
3207
+		/* Type checks: */
3208
+		ParagonIE_Sodium_Core_Util::declareScalarType($var, 'string', 1);
3209
+
3210
+		if (self::useNewSodiumAPI()) {
3211
+			sodium_increment($var);
3212
+			return;
3213
+		}
3214
+		if (self::use_fallback('increment')) {
3215
+			$func = '\\Sodium\\increment';
3216
+			$func($var);
3217
+			return;
3218
+		}
3219
+
3220
+		$len = ParagonIE_Sodium_Core_Util::strlen($var);
3221
+		$c = 1;
3222
+		$copy = '';
3223
+		for ($i = 0; $i < $len; ++$i) {
3224
+			$c += ParagonIE_Sodium_Core_Util::chrToInt(
3225
+				ParagonIE_Sodium_Core_Util::substr($var, $i, 1)
3226
+			);
3227
+			$copy .= ParagonIE_Sodium_Core_Util::intToChr($c);
3228
+			$c >>= 8;
3229
+		}
3230
+		$var = $copy;
3231
+	}
3232
+
3233
+	/**
3234
+	 * @param string $str
3235
+	 * @return bool
3236
+	 *
3237
+	 * @throws SodiumException
3238
+	 */
3239
+	public static function is_zero($str)
3240
+	{
3241
+		$d = 0;
3242
+		for ($i = 0; $i < 32; ++$i) {
3243
+			$d |= ParagonIE_Sodium_Core_Util::chrToInt($str[$i]);
3244
+		}
3245
+		return ((($d - 1) >> 31) & 1) === 1;
3246
+	}
3247
+
3248
+	/**
3249
+	 * The equivalent to the libsodium minor version we aim to be compatible
3250
+	 * with (sans pwhash and memzero).
3251
+	 *
3252
+	 * @return int
3253
+	 */
3254
+	public static function library_version_major()
3255
+	{
3256
+		if (self::useNewSodiumAPI() && defined('SODIUM_LIBRARY_MAJOR_VERSION')) {
3257
+			return SODIUM_LIBRARY_MAJOR_VERSION;
3258
+		}
3259
+		if (self::use_fallback('library_version_major')) {
3260
+			/** @psalm-suppress UndefinedFunction */
3261
+			return (int) call_user_func('\\Sodium\\library_version_major');
3262
+		}
3263
+		return self::LIBRARY_VERSION_MAJOR;
3264
+	}
3265
+
3266
+	/**
3267
+	 * The equivalent to the libsodium minor version we aim to be compatible
3268
+	 * with (sans pwhash and memzero).
3269
+	 *
3270
+	 * @return int
3271
+	 */
3272
+	public static function library_version_minor()
3273
+	{
3274
+		if (self::useNewSodiumAPI() && defined('SODIUM_LIBRARY_MINOR_VERSION')) {
3275
+			return SODIUM_LIBRARY_MINOR_VERSION;
3276
+		}
3277
+		if (self::use_fallback('library_version_minor')) {
3278
+			/** @psalm-suppress UndefinedFunction */
3279
+			return (int) call_user_func('\\Sodium\\library_version_minor');
3280
+		}
3281
+		return self::LIBRARY_VERSION_MINOR;
3282
+	}
3283
+
3284
+	/**
3285
+	 * Compare two strings.
3286
+	 *
3287
+	 * @param string $left
3288
+	 * @param string $right
3289
+	 * @return int
3290
+	 * @throws SodiumException
3291
+	 * @throws TypeError
3292
+	 * @psalm-suppress MixedArgument
3293
+	 */
3294
+	public static function memcmp($left, $right)
3295
+	{
3296
+		/* Type checks: */
3297
+		ParagonIE_Sodium_Core_Util::declareScalarType($left, 'string', 1);
3298
+		ParagonIE_Sodium_Core_Util::declareScalarType($right, 'string', 2);
3299
+
3300
+		if (self::useNewSodiumAPI()) {
3301
+			return sodium_memcmp($left, $right);
3302
+		}
3303
+		if (self::use_fallback('memcmp')) {
3304
+			return (int) call_user_func('\\Sodium\\memcmp', $left, $right);
3305
+		}
3306
+		/** @var string $left */
3307
+		/** @var string $right */
3308
+		return ParagonIE_Sodium_Core_Util::memcmp($left, $right);
3309
+	}
3310
+
3311
+	/**
3312
+	 * It's actually not possible to zero memory buffers in PHP. You need the
3313
+	 * native library for that.
3314
+	 *
3315
+	 * @param string|null $var
3316
+	 * @param-out string|null $var
3317
+	 *
3318
+	 * @return void
3319
+	 * @throws SodiumException (Unless libsodium is installed)
3320
+	 * @throws TypeError
3321
+	 * @psalm-suppress TooFewArguments
3322
+	 */
3323
+	public static function memzero(&$var)
3324
+	{
3325
+		/* Type checks: */
3326
+		ParagonIE_Sodium_Core_Util::declareScalarType($var, 'string', 1);
3327
+
3328
+		if (self::useNewSodiumAPI()) {
3329
+			/** @psalm-suppress MixedArgument */
3330
+			sodium_memzero($var);
3331
+			return;
3332
+		}
3333
+		if (self::use_fallback('memzero')) {
3334
+			$func = '\\Sodium\\memzero';
3335
+			$func($var);
3336
+			if ($var === null) {
3337
+				return;
3338
+			}
3339
+		}
3340
+		// This is the best we can do.
3341
+		throw new SodiumException(
3342
+			'This is not implemented in sodium_compat, as it is not possible to securely wipe memory from PHP. ' .
3343
+			'To fix this error, make sure libsodium is installed and the PHP extension is enabled.'
3344
+		);
3345
+	}
3346
+
3347
+	/**
3348
+	 * @param string $unpadded
3349
+	 * @param int $blockSize
3350
+	 * @param bool $dontFallback
3351
+	 * @return string
3352
+	 * @throws SodiumException
3353
+	 */
3354
+	public static function pad($unpadded, $blockSize, $dontFallback = false)
3355
+	{
3356
+		/* Type checks: */
3357
+		ParagonIE_Sodium_Core_Util::declareScalarType($unpadded, 'string', 1);
3358
+		ParagonIE_Sodium_Core_Util::declareScalarType($blockSize, 'int', 2);
3359
+
3360
+		$unpadded = (string) $unpadded;
3361
+		$blockSize = (int) $blockSize;
3362
+
3363
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3364
+			return (string) sodium_pad($unpadded, $blockSize);
3365
+		}
3366
+
3367
+		if ($blockSize <= 0) {
3368
+			throw new SodiumException(
3369
+				'block size cannot be less than 1'
3370
+			);
3371
+		}
3372
+		$unpadded_len = ParagonIE_Sodium_Core_Util::strlen($unpadded);
3373
+		$xpadlen = ($blockSize - 1);
3374
+		if (($blockSize & ($blockSize - 1)) === 0) {
3375
+			$xpadlen -= $unpadded_len & ($blockSize - 1);
3376
+		} else {
3377
+			$xpadlen -= $unpadded_len % $blockSize;
3378
+		}
3379
+
3380
+		$xpadded_len = $unpadded_len + $xpadlen;
3381
+		$padded = str_repeat("\0", $xpadded_len - 1);
3382
+		if ($unpadded_len > 0) {
3383
+			$st = 1;
3384
+			$i = 0;
3385
+			$k = $unpadded_len;
3386
+			for ($j = 0; $j <= $xpadded_len; ++$j) {
3387
+				$i = (int) $i;
3388
+				$k = (int) $k;
3389
+				$st = (int) $st;
3390
+				if ($j >= $unpadded_len) {
3391
+					$padded[$j] = "\0";
3392
+				} else {
3393
+					$padded[$j] = $unpadded[$j];
3394
+				}
3395
+				/** @var int $k */
3396
+				$k -= $st;
3397
+				$st = (int) (~(
3398
+							(
3399
+								(
3400
+									($k >> 48)
3401
+										|
3402
+									($k >> 32)
3403
+										|
3404
+									($k >> 16)
3405
+										|
3406
+									$k
3407
+								) - 1
3408
+							) >> 16
3409
+						)
3410
+					) & 1;
3411
+				$i += $st;
3412
+			}
3413
+		}
3414
+
3415
+		$mask = 0;
3416
+		$tail = $xpadded_len;
3417
+		for ($i = 0; $i < $blockSize; ++$i) {
3418
+			# barrier_mask = (unsigned char)
3419
+			#     (((i ^ xpadlen) - 1U) >> ((sizeof(size_t) - 1U) * CHAR_BIT));
3420
+			$barrier_mask = (($i ^ $xpadlen) -1) >> ((PHP_INT_SIZE << 3) - 1);
3421
+			# tail[-i] = (tail[-i] & mask) | (0x80 & barrier_mask);
3422
+			$padded[$tail - $i] = ParagonIE_Sodium_Core_Util::intToChr(
3423
+				(ParagonIE_Sodium_Core_Util::chrToInt($padded[$tail - $i]) & $mask)
3424
+					|
3425
+				(0x80 & $barrier_mask)
3426
+			);
3427
+			# mask |= barrier_mask;
3428
+			$mask |= $barrier_mask;
3429
+		}
3430
+		return $padded;
3431
+	}
3432
+
3433
+	/**
3434
+	 * @param string $padded
3435
+	 * @param int $blockSize
3436
+	 * @param bool $dontFallback
3437
+	 * @return string
3438
+	 * @throws SodiumException
3439
+	 */
3440
+	public static function unpad($padded, $blockSize, $dontFallback = false)
3441
+	{
3442
+		/* Type checks: */
3443
+		ParagonIE_Sodium_Core_Util::declareScalarType($padded, 'string', 1);
3444
+		ParagonIE_Sodium_Core_Util::declareScalarType($blockSize, 'int', 2);
3445
+
3446
+		$padded = (string) $padded;
3447
+		$blockSize = (int) $blockSize;
3448
+
3449
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3450
+			return (string) sodium_unpad($padded, $blockSize);
3451
+		}
3452
+		if ($blockSize <= 0) {
3453
+			throw new SodiumException('block size cannot be less than 1');
3454
+		}
3455
+		$padded_len = ParagonIE_Sodium_Core_Util::strlen($padded);
3456
+		if ($padded_len < $blockSize) {
3457
+			throw new SodiumException('invalid padding');
3458
+		}
3459
+
3460
+		# tail = &padded[padded_len - 1U];
3461
+		$tail = $padded_len - 1;
3462
+
3463
+		$acc = 0;
3464
+		$valid = 0;
3465
+		$pad_len = 0;
3466
+
3467
+		$found = 0;
3468
+		for ($i = 0; $i < $blockSize; ++$i) {
3469
+			# c = tail[-i];
3470
+			$c = ParagonIE_Sodium_Core_Util::chrToInt($padded[$tail - $i]);
3471
+
3472
+			# is_barrier =
3473
+			#     (( (acc - 1U) & (pad_len - 1U) & ((c ^ 0x80) - 1U) ) >> 8) & 1U;
3474
+			$is_barrier = (
3475
+				(
3476
+					($acc - 1) & ($pad_len - 1) & (($c ^ 80) - 1)
3477
+				) >> 7
3478
+			) & 1;
3479
+			$is_barrier &= ~$found;
3480
+			$found |= $is_barrier;
3481
+
3482
+			# acc |= c;
3483
+			$acc |= $c;
3484
+
3485
+			# pad_len |= i & (1U + ~is_barrier);
3486
+			$pad_len |= $i & (1 + ~$is_barrier);
3487
+
3488
+			# valid |= (unsigned char) is_barrier;
3489
+			$valid |= ($is_barrier & 0xff);
3490
+		}
3491
+		# unpadded_len = padded_len - 1U - pad_len;
3492
+		$unpadded_len = $padded_len - 1 - $pad_len;
3493
+		if ($valid !== 1) {
3494
+			throw new SodiumException('invalid padding');
3495
+		}
3496
+		return ParagonIE_Sodium_Core_Util::substr($padded, 0, $unpadded_len);
3497
+	}
3498
+
3499
+	/**
3500
+	 * Will sodium_compat run fast on the current hardware and PHP configuration?
3501
+	 *
3502
+	 * @return bool
3503
+	 */
3504
+	public static function polyfill_is_fast()
3505
+	{
3506
+		if (extension_loaded('sodium')) {
3507
+			return true;
3508
+		}
3509
+		if (extension_loaded('libsodium')) {
3510
+			return true;
3511
+		}
3512
+		return PHP_INT_SIZE === 8;
3513
+	}
3514
+
3515
+	/**
3516
+	 * Generate a string of bytes from the kernel's CSPRNG.
3517
+	 * Proudly uses /dev/urandom (if getrandom(2) is not available).
3518
+	 *
3519
+	 * @param int $numBytes
3520
+	 * @return string
3521
+	 * @throws Exception
3522
+	 * @throws TypeError
3523
+	 */
3524
+	public static function randombytes_buf($numBytes)
3525
+	{
3526
+		/* Type checks: */
3527
+		if (!is_int($numBytes)) {
3528
+			if (is_numeric($numBytes)) {
3529
+				$numBytes = (int) $numBytes;
3530
+			} else {
3531
+				throw new TypeError(
3532
+					'Argument 1 must be an integer, ' . gettype($numBytes) . ' given.'
3533
+				);
3534
+			}
3535
+		}
3536
+		if (self::use_fallback('randombytes_buf')) {
3537
+			return (string) call_user_func('\\Sodium\\randombytes_buf', $numBytes);
3538
+		}
3539
+		return random_bytes($numBytes);
3540
+	}
3541
+
3542
+	/**
3543
+	 * Generate an integer between 0 and $range (non-inclusive).
3544
+	 *
3545
+	 * @param int $range
3546
+	 * @return int
3547
+	 * @throws Exception
3548
+	 * @throws Error
3549
+	 * @throws TypeError
3550
+	 */
3551
+	public static function randombytes_uniform($range)
3552
+	{
3553
+		/* Type checks: */
3554
+		if (!is_int($range)) {
3555
+			if (is_numeric($range)) {
3556
+				$range = (int) $range;
3557
+			} else {
3558
+				throw new TypeError(
3559
+					'Argument 1 must be an integer, ' . gettype($range) . ' given.'
3560
+				);
3561
+			}
3562
+		}
3563
+		if (self::use_fallback('randombytes_uniform')) {
3564
+			return (int) call_user_func('\\Sodium\\randombytes_uniform', $range);
3565
+		}
3566
+		return random_int(0, $range - 1);
3567
+	}
3568
+
3569
+	/**
3570
+	 * Generate a random 16-bit integer.
3571
+	 *
3572
+	 * @return int
3573
+	 * @throws Exception
3574
+	 * @throws Error
3575
+	 * @throws TypeError
3576
+	 */
3577
+	public static function randombytes_random16()
3578
+	{
3579
+		if (self::use_fallback('randombytes_random16')) {
3580
+			return (int) call_user_func('\\Sodium\\randombytes_random16');
3581
+		}
3582
+		return random_int(0, 65535);
3583
+	}
3584
+
3585
+	/**
3586
+	 * @param string $p
3587
+	 * @param bool $dontFallback
3588
+	 * @return bool
3589
+	 * @throws SodiumException
3590
+	 */
3591
+	public static function ristretto255_is_valid_point($p, $dontFallback = false)
3592
+	{
3593
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3594
+			return sodium_crypto_core_ristretto255_is_valid_point($p);
3595
+		}
3596
+		try {
3597
+			$r = ParagonIE_Sodium_Core_Ristretto255::ristretto255_frombytes($p);
3598
+			return $r['res'] === 0 &&
3599
+				ParagonIE_Sodium_Core_Ristretto255::ristretto255_point_is_canonical($p) === 1;
3600
+		} catch (SodiumException $ex) {
3601
+			if ($ex->getMessage() === 'S is not canonical') {
3602
+				return false;
3603
+			}
3604
+			throw $ex;
3605
+		}
3606
+	}
3607
+
3608
+	/**
3609
+	 * @param string $p
3610
+	 * @param string $q
3611
+	 * @param bool $dontFallback
3612
+	 * @return string
3613
+	 * @throws SodiumException
3614
+	 */
3615
+	public static function ristretto255_add($p, $q, $dontFallback = false)
3616
+	{
3617
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3618
+			return sodium_crypto_core_ristretto255_add($p, $q);
3619
+		}
3620
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_add($p, $q);
3621
+	}
3622
+
3623
+	/**
3624
+	 * @param string $p
3625
+	 * @param string $q
3626
+	 * @param bool $dontFallback
3627
+	 * @return string
3628
+	 * @throws SodiumException
3629
+	 */
3630
+	public static function ristretto255_sub($p, $q, $dontFallback = false)
3631
+	{
3632
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3633
+			return sodium_crypto_core_ristretto255_sub($p, $q);
3634
+		}
3635
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_sub($p, $q);
3636
+	}
3637
+
3638
+	/**
3639
+	 * @param string $r
3640
+	 * @param bool $dontFallback
3641
+	 * @return string
3642
+	 *
3643
+	 * @throws SodiumException
3644
+	 */
3645
+	public static function ristretto255_from_hash($r, $dontFallback = false)
3646
+	{
3647
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3648
+			return sodium_crypto_core_ristretto255_from_hash($r);
3649
+		}
3650
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_from_hash($r);
3651
+	}
3652
+
3653
+	/**
3654
+	 * @param bool $dontFallback
3655
+	 * @return string
3656
+	 *
3657
+	 * @throws SodiumException
3658
+	 */
3659
+	public static function ristretto255_random($dontFallback = false)
3660
+	{
3661
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3662
+			return sodium_crypto_core_ristretto255_random();
3663
+		}
3664
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_random();
3665
+	}
3666
+
3667
+	/**
3668
+	 * @param bool $dontFallback
3669
+	 * @return string
3670
+	 *
3671
+	 * @throws SodiumException
3672
+	 */
3673
+	public static function ristretto255_scalar_random($dontFallback = false)
3674
+	{
3675
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3676
+			return sodium_crypto_core_ristretto255_scalar_random();
3677
+		}
3678
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_random();
3679
+	}
3680
+
3681
+	/**
3682
+	 * @param string $s
3683
+	 * @param bool $dontFallback
3684
+	 * @return string
3685
+	 * @throws SodiumException
3686
+	 */
3687
+	public static function ristretto255_scalar_invert($s, $dontFallback = false)
3688
+	{
3689
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3690
+			return sodium_crypto_core_ristretto255_scalar_invert($s);
3691
+		}
3692
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_invert($s);
3693
+	}
3694
+	/**
3695
+	 * @param string $s
3696
+	 * @param bool $dontFallback
3697
+	 * @return string
3698
+	 * @throws SodiumException
3699
+	 */
3700
+	public static function ristretto255_scalar_negate($s, $dontFallback = false)
3701
+	{
3702
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3703
+			return sodium_crypto_core_ristretto255_scalar_negate($s);
3704
+		}
3705
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_negate($s);
3706
+	}
3707
+
3708
+	/**
3709
+	 * @param string $s
3710
+	 * @param bool $dontFallback
3711
+	 * @return string
3712
+	 * @throws SodiumException
3713
+	 */
3714
+	public static function ristretto255_scalar_complement($s, $dontFallback = false)
3715
+	{
3716
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3717
+			return sodium_crypto_core_ristretto255_scalar_complement($s);
3718
+		}
3719
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_complement($s);
3720
+	}
3721
+
3722
+	/**
3723
+	 * @param string $x
3724
+	 * @param string $y
3725
+	 * @param bool $dontFallback
3726
+	 * @return string
3727
+	 * @throws SodiumException
3728
+	 */
3729
+	public static function ristretto255_scalar_add($x, $y, $dontFallback = false)
3730
+	{
3731
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3732
+			return sodium_crypto_core_ristretto255_scalar_add($x, $y);
3733
+		}
3734
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_add($x, $y);
3735
+	}
3736
+
3737
+	/**
3738
+	 * @param string $x
3739
+	 * @param string $y
3740
+	 * @param bool $dontFallback
3741
+	 * @return string
3742
+	 * @throws SodiumException
3743
+	 */
3744
+	public static function ristretto255_scalar_sub($x, $y, $dontFallback = false)
3745
+	{
3746
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3747
+			return sodium_crypto_core_ristretto255_scalar_sub($x, $y);
3748
+		}
3749
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_sub($x, $y);
3750
+	}
3751
+
3752
+	/**
3753
+	 * @param string $x
3754
+	 * @param string $y
3755
+	 * @param bool $dontFallback
3756
+	 * @return string
3757
+	 * @throws SodiumException
3758
+	 */
3759
+	public static function ristretto255_scalar_mul($x, $y, $dontFallback = false)
3760
+	{
3761
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3762
+			return sodium_crypto_core_ristretto255_scalar_mul($x, $y);
3763
+		}
3764
+		return ParagonIE_Sodium_Core_Ristretto255::ristretto255_scalar_mul($x, $y);
3765
+	}
3766
+
3767
+	/**
3768
+	 * @param string $n
3769
+	 * @param string $p
3770
+	 * @param bool $dontFallback
3771
+	 * @return string
3772
+	 * @throws SodiumException
3773
+	 */
3774
+	public static function scalarmult_ristretto255($n, $p, $dontFallback = false)
3775
+	{
3776
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3777
+			return sodium_crypto_scalarmult_ristretto255($n, $p);
3778
+		}
3779
+		return ParagonIE_Sodium_Core_Ristretto255::scalarmult_ristretto255($n, $p);
3780
+	}
3781
+
3782
+	/**
3783
+	 * @param string $n
3784
+	 * @param string $p
3785
+	 * @param bool $dontFallback
3786
+	 * @return string
3787
+	 * @throws SodiumException
3788
+	 */
3789
+	public static function scalarmult_ristretto255_base($n, $dontFallback = false)
3790
+	{
3791
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3792
+			return sodium_crypto_scalarmult_ristretto255_base($n);
3793
+		}
3794
+		return ParagonIE_Sodium_Core_Ristretto255::scalarmult_ristretto255_base($n);
3795
+	}
3796
+
3797
+	/**
3798
+	 * @param string $s
3799
+	 * @param bool $dontFallback
3800
+	 * @return string
3801
+	 * @throws SodiumException
3802
+	 */
3803
+	public static function ristretto255_scalar_reduce($s, $dontFallback = false)
3804
+	{
3805
+		if (self::useNewSodiumAPI() && !$dontFallback) {
3806
+			return sodium_crypto_core_ristretto255_scalar_reduce($s);
3807
+		}
3808
+		return ParagonIE_Sodium_Core_Ristretto255::sc_reduce($s);
3809
+	}
3810
+
3811
+	/**
3812
+	 * Runtime testing method for 32-bit platforms.
3813
+	 *
3814
+	 * Usage: If runtime_speed_test() returns FALSE, then our 32-bit
3815
+	 *        implementation is to slow to use safely without risking timeouts.
3816
+	 *        If this happens, install sodium from PECL to get acceptable
3817
+	 *        performance.
3818
+	 *
3819
+	 * @param int $iterations Number of multiplications to attempt
3820
+	 * @param int $maxTimeout Milliseconds
3821
+	 * @return bool           TRUE if we're fast enough, FALSE is not
3822
+	 * @throws SodiumException
3823
+	 */
3824
+	public static function runtime_speed_test($iterations, $maxTimeout)
3825
+	{
3826
+		if (self::polyfill_is_fast()) {
3827
+			return true;
3828
+		}
3829
+		/** @var float $end */
3830
+		$end = 0.0;
3831
+		/** @var float $start */
3832
+		$start = microtime(true);
3833
+		/** @var ParagonIE_Sodium_Core32_Int64 $a */
3834
+		$a = ParagonIE_Sodium_Core32_Int64::fromInt(random_int(3, 1 << 16));
3835
+		for ($i = 0; $i < $iterations; ++$i) {
3836
+			/** @var ParagonIE_Sodium_Core32_Int64 $b */
3837
+			$b = ParagonIE_Sodium_Core32_Int64::fromInt(random_int(3, 1 << 16));
3838
+			$a->mulInt64($b);
3839
+		}
3840
+		/** @var float $end */
3841
+		$end = microtime(true);
3842
+		/** @var int $diff */
3843
+		$diff = (int) ceil(($end - $start) * 1000);
3844
+		return $diff < $maxTimeout;
3845
+	}
3846
+
3847
+	/**
3848
+	 * Add two numbers (little-endian unsigned), storing the value in the first
3849
+	 * parameter.
3850
+	 *
3851
+	 * This mutates $val.
3852
+	 *
3853
+	 * @param string $val
3854
+	 * @param string $addv
3855
+	 * @return void
3856
+	 * @throws SodiumException
3857
+	 */
3858
+	public static function sub(&$val, $addv)
3859
+	{
3860
+		$val_len = ParagonIE_Sodium_Core_Util::strlen($val);
3861
+		$addv_len = ParagonIE_Sodium_Core_Util::strlen($addv);
3862
+		if ($val_len !== $addv_len) {
3863
+			throw new SodiumException('values must have the same length');
3864
+		}
3865
+		$A = ParagonIE_Sodium_Core_Util::stringToIntArray($val);
3866
+		$B = ParagonIE_Sodium_Core_Util::stringToIntArray($addv);
3867
+
3868
+		$c = 0;
3869
+		for ($i = 0; $i < $val_len; $i++) {
3870
+			$c = ($A[$i] - $B[$i] - $c);
3871
+			$A[$i] = ($c & 0xff);
3872
+			$c = ($c >> 8) & 1;
3873
+		}
3874
+		$val = ParagonIE_Sodium_Core_Util::intArrayToString($A);
3875
+	}
3876
+
3877
+	/**
3878
+	 * This emulates libsodium's version_string() function, except ours is
3879
+	 * prefixed with 'polyfill-'.
3880
+	 *
3881
+	 * @return string
3882
+	 * @psalm-suppress MixedInferredReturnType
3883
+	 * @psalm-suppress UndefinedFunction
3884
+	 */
3885
+	public static function version_string()
3886
+	{
3887
+		if (self::useNewSodiumAPI()) {
3888
+			return (string) sodium_version_string();
3889
+		}
3890
+		if (self::use_fallback('version_string')) {
3891
+			return (string) call_user_func('\\Sodium\\version_string');
3892
+		}
3893
+		return (string) self::VERSION_STRING;
3894
+	}
3895
+
3896
+	/**
3897
+	 * Should we use the libsodium core function instead?
3898
+	 * This is always a good idea, if it's available. (Unless we're in the
3899
+	 * middle of running our unit test suite.)
3900
+	 *
3901
+	 * If ext/libsodium is available, use it. Return TRUE.
3902
+	 * Otherwise, we have to use the code provided herein. Return FALSE.
3903
+	 *
3904
+	 * @param string $sodium_func_name
3905
+	 *
3906
+	 * @return bool
3907
+	 */
3908
+	protected static function use_fallback($sodium_func_name = '')
3909
+	{
3910
+		static $res = null;
3911
+		if ($res === null) {
3912
+			$res = extension_loaded('libsodium') && PHP_VERSION_ID >= 50300;
3913
+		}
3914
+		if ($res === false) {
3915
+			// No libsodium installed
3916
+			return false;
3917
+		}
3918
+		if (self::$disableFallbackForUnitTests) {
3919
+			// Don't fallback. Use the PHP implementation.
3920
+			return false;
3921
+		}
3922
+		if (!empty($sodium_func_name)) {
3923
+			return is_callable('\\Sodium\\' . $sodium_func_name);
3924
+		}
3925
+		return true;
3926
+	}
3927
+
3928
+	/**
3929
+	 * Libsodium as implemented in PHP 7.2
3930
+	 * and/or ext/sodium (via PECL)
3931
+	 *
3932
+	 * @ref https://wiki.php.net/rfc/libsodium
3933
+	 * @return bool
3934
+	 */
3935
+	protected static function useNewSodiumAPI()
3936
+	{
3937
+		static $res = null;
3938
+		if ($res === null) {
3939
+			$res = PHP_VERSION_ID >= 70000 && extension_loaded('sodium');
3940
+		}
3941
+		if (self::$disableFallbackForUnitTests) {
3942
+			// Don't fallback. Use the PHP implementation.
3943
+			return false;
3944
+		}
3945
+		return (bool) $res;
3946
+	}
3947 3947
 }
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Crypto32.php 1 patch
Indentation   +1638 added lines, -1638 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Crypto32', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -14,1641 +14,1641 @@  discard block
 block discarded – undo
14 14
  */
15 15
 abstract class ParagonIE_Sodium_Crypto32
16 16
 {
17
-    const aead_chacha20poly1305_KEYBYTES = 32;
18
-    const aead_chacha20poly1305_NSECBYTES = 0;
19
-    const aead_chacha20poly1305_NPUBBYTES = 8;
20
-    const aead_chacha20poly1305_ABYTES = 16;
21
-
22
-    const aead_chacha20poly1305_IETF_KEYBYTES = 32;
23
-    const aead_chacha20poly1305_IETF_NSECBYTES = 0;
24
-    const aead_chacha20poly1305_IETF_NPUBBYTES = 12;
25
-    const aead_chacha20poly1305_IETF_ABYTES = 16;
26
-
27
-    const aead_xchacha20poly1305_IETF_KEYBYTES = 32;
28
-    const aead_xchacha20poly1305_IETF_NSECBYTES = 0;
29
-    const aead_xchacha20poly1305_IETF_NPUBBYTES = 24;
30
-    const aead_xchacha20poly1305_IETF_ABYTES = 16;
31
-
32
-    const box_curve25519xsalsa20poly1305_SEEDBYTES = 32;
33
-    const box_curve25519xsalsa20poly1305_PUBLICKEYBYTES = 32;
34
-    const box_curve25519xsalsa20poly1305_SECRETKEYBYTES = 32;
35
-    const box_curve25519xsalsa20poly1305_BEFORENMBYTES = 32;
36
-    const box_curve25519xsalsa20poly1305_NONCEBYTES = 24;
37
-    const box_curve25519xsalsa20poly1305_MACBYTES = 16;
38
-    const box_curve25519xsalsa20poly1305_BOXZEROBYTES = 16;
39
-    const box_curve25519xsalsa20poly1305_ZEROBYTES = 32;
40
-
41
-    const onetimeauth_poly1305_BYTES = 16;
42
-    const onetimeauth_poly1305_KEYBYTES = 32;
43
-
44
-    const secretbox_xsalsa20poly1305_KEYBYTES = 32;
45
-    const secretbox_xsalsa20poly1305_NONCEBYTES = 24;
46
-    const secretbox_xsalsa20poly1305_MACBYTES = 16;
47
-    const secretbox_xsalsa20poly1305_BOXZEROBYTES = 16;
48
-    const secretbox_xsalsa20poly1305_ZEROBYTES = 32;
49
-
50
-    const secretbox_xchacha20poly1305_KEYBYTES = 32;
51
-    const secretbox_xchacha20poly1305_NONCEBYTES = 24;
52
-    const secretbox_xchacha20poly1305_MACBYTES = 16;
53
-    const secretbox_xchacha20poly1305_BOXZEROBYTES = 16;
54
-    const secretbox_xchacha20poly1305_ZEROBYTES = 32;
55
-
56
-    const stream_salsa20_KEYBYTES = 32;
57
-
58
-    /**
59
-     * AEAD Decryption with ChaCha20-Poly1305
60
-     *
61
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
62
-     *
63
-     * @param string $message
64
-     * @param string $ad
65
-     * @param string $nonce
66
-     * @param string $key
67
-     * @return string
68
-     * @throws SodiumException
69
-     * @throws TypeError
70
-     */
71
-    public static function aead_chacha20poly1305_decrypt(
72
-        $message = '',
73
-        $ad = '',
74
-        $nonce = '',
75
-        $key = ''
76
-    ) {
77
-        /** @var int $len - Length of message (ciphertext + MAC) */
78
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
79
-
80
-        /** @var int  $clen - Length of ciphertext */
81
-        $clen = $len - self::aead_chacha20poly1305_ABYTES;
82
-
83
-        /** @var int $adlen - Length of associated data */
84
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
85
-
86
-        /** @var string $mac - Message authentication code */
87
-        $mac = ParagonIE_Sodium_Core32_Util::substr(
88
-            $message,
89
-            $clen,
90
-            self::aead_chacha20poly1305_ABYTES
91
-        );
92
-
93
-        /** @var string $ciphertext - The encrypted message (sans MAC) */
94
-        $ciphertext = ParagonIE_Sodium_Core32_Util::substr($message, 0, $clen);
95
-
96
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
97
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
98
-            32,
99
-            $nonce,
100
-            $key
101
-        );
102
-
103
-        /* Recalculate the Poly1305 authentication tag (MAC): */
104
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
105
-        try {
106
-            ParagonIE_Sodium_Compat::memzero($block0);
107
-        } catch (SodiumException $ex) {
108
-            $block0 = null;
109
-        }
110
-        $state->update($ad);
111
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
112
-        $state->update($ciphertext);
113
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($clen));
114
-        $computed_mac = $state->finish();
115
-
116
-        /* Compare the given MAC with the recalculated MAC: */
117
-        if (!ParagonIE_Sodium_Core32_Util::verify_16($computed_mac, $mac)) {
118
-            throw new SodiumException('Invalid MAC');
119
-        }
120
-
121
-        // Here, we know that the MAC is valid, so we decrypt and return the plaintext
122
-        return ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
123
-            $ciphertext,
124
-            $nonce,
125
-            $key,
126
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
127
-        );
128
-    }
129
-
130
-    /**
131
-     * AEAD Encryption with ChaCha20-Poly1305
132
-     *
133
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
134
-     *
135
-     * @param string $message
136
-     * @param string $ad
137
-     * @param string $nonce
138
-     * @param string $key
139
-     * @return string
140
-     * @throws SodiumException
141
-     * @throws TypeError
142
-     */
143
-    public static function aead_chacha20poly1305_encrypt(
144
-        $message = '',
145
-        $ad = '',
146
-        $nonce = '',
147
-        $key = ''
148
-    ) {
149
-        /** @var int $len - Length of the plaintext message */
150
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
151
-
152
-        /** @var int $adlen - Length of the associated data */
153
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
154
-
155
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
156
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
157
-            32,
158
-            $nonce,
159
-            $key
160
-        );
161
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
162
-        try {
163
-            ParagonIE_Sodium_Compat::memzero($block0);
164
-        } catch (SodiumException $ex) {
165
-            $block0 = null;
166
-        }
167
-
168
-        /** @var string $ciphertext - Raw encrypted data */
169
-        $ciphertext = ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
170
-            $message,
171
-            $nonce,
172
-            $key,
173
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
174
-        );
175
-
176
-        $state->update($ad);
177
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
178
-        $state->update($ciphertext);
179
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($len));
180
-        return $ciphertext . $state->finish();
181
-    }
182
-
183
-    /**
184
-     * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
185
-     *
186
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
187
-     *
188
-     * @param string $message
189
-     * @param string $ad
190
-     * @param string $nonce
191
-     * @param string $key
192
-     * @return string
193
-     * @throws SodiumException
194
-     * @throws TypeError
195
-     */
196
-    public static function aead_chacha20poly1305_ietf_decrypt(
197
-        $message = '',
198
-        $ad = '',
199
-        $nonce = '',
200
-        $key = ''
201
-    ) {
202
-        /** @var int $adlen - Length of associated data */
203
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
204
-
205
-        /** @var int $len - Length of message (ciphertext + MAC) */
206
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
207
-
208
-        /** @var int  $clen - Length of ciphertext */
209
-        $clen = $len - self::aead_chacha20poly1305_IETF_ABYTES;
210
-
211
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
212
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::ietfStream(
213
-            32,
214
-            $nonce,
215
-            $key
216
-        );
217
-
218
-        /** @var string $mac - Message authentication code */
219
-        $mac = ParagonIE_Sodium_Core32_Util::substr(
220
-            $message,
221
-            $len - self::aead_chacha20poly1305_IETF_ABYTES,
222
-            self::aead_chacha20poly1305_IETF_ABYTES
223
-        );
224
-
225
-        /** @var string $ciphertext - The encrypted message (sans MAC) */
226
-        $ciphertext = ParagonIE_Sodium_Core32_Util::substr(
227
-            $message,
228
-            0,
229
-            $len - self::aead_chacha20poly1305_IETF_ABYTES
230
-        );
231
-
232
-        /* Recalculate the Poly1305 authentication tag (MAC): */
233
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
234
-        try {
235
-            ParagonIE_Sodium_Compat::memzero($block0);
236
-        } catch (SodiumException $ex) {
237
-            $block0 = null;
238
-        }
239
-        $state->update($ad);
240
-        $state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
241
-        $state->update($ciphertext);
242
-        $state->update(str_repeat("\x00", (0x10 - $clen) & 0xf));
243
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
244
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($clen));
245
-        $computed_mac = $state->finish();
246
-
247
-        /* Compare the given MAC with the recalculated MAC: */
248
-        if (!ParagonIE_Sodium_Core32_Util::verify_16($computed_mac, $mac)) {
249
-            throw new SodiumException('Invalid MAC');
250
-        }
251
-
252
-        // Here, we know that the MAC is valid, so we decrypt and return the plaintext
253
-        return ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
254
-            $ciphertext,
255
-            $nonce,
256
-            $key,
257
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
258
-        );
259
-    }
260
-
261
-    /**
262
-     * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
263
-     *
264
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
265
-     *
266
-     * @param string $message
267
-     * @param string $ad
268
-     * @param string $nonce
269
-     * @param string $key
270
-     * @return string
271
-     * @throws SodiumException
272
-     * @throws TypeError
273
-     */
274
-    public static function aead_chacha20poly1305_ietf_encrypt(
275
-        $message = '',
276
-        $ad = '',
277
-        $nonce = '',
278
-        $key = ''
279
-    ) {
280
-        /** @var int $len - Length of the plaintext message */
281
-        $len = ParagonIE_Sodium_Core32_Util::strlen($message);
282
-
283
-        /** @var int $adlen - Length of the associated data */
284
-        $adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
285
-
286
-        /** @var string The first block of the chacha20 keystream, used as a poly1305 key */
287
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::ietfStream(
288
-            32,
289
-            $nonce,
290
-            $key
291
-        );
292
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
293
-        try {
294
-            ParagonIE_Sodium_Compat::memzero($block0);
295
-        } catch (SodiumException $ex) {
296
-            $block0 = null;
297
-        }
298
-
299
-        /** @var string $ciphertext - Raw encrypted data */
300
-        $ciphertext = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
301
-            $message,
302
-            $nonce,
303
-            $key,
304
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
305
-        );
306
-
307
-        $state->update($ad);
308
-        $state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
309
-        $state->update($ciphertext);
310
-        $state->update(str_repeat("\x00", ((0x10 - $len) & 0xf)));
311
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
312
-        $state->update(ParagonIE_Sodium_Core32_Util::store64_le($len));
313
-        return $ciphertext . $state->finish();
314
-    }
315
-
316
-    /**
317
-     * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
318
-     *
319
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
320
-     *
321
-     * @param string $message
322
-     * @param string $ad
323
-     * @param string $nonce
324
-     * @param string $key
325
-     * @return string
326
-     * @throws SodiumException
327
-     * @throws TypeError
328
-     */
329
-    public static function aead_xchacha20poly1305_ietf_decrypt(
330
-        $message = '',
331
-        $ad = '',
332
-        $nonce = '',
333
-        $key = ''
334
-    ) {
335
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
336
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
337
-            $key
338
-        );
339
-        $nonceLast = "\x00\x00\x00\x00" .
340
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
341
-
342
-        return self::aead_chacha20poly1305_ietf_decrypt($message, $ad, $nonceLast, $subkey);
343
-    }
344
-
345
-    /**
346
-     * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
347
-     *
348
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
349
-     *
350
-     * @param string $message
351
-     * @param string $ad
352
-     * @param string $nonce
353
-     * @param string $key
354
-     * @return string
355
-     * @throws SodiumException
356
-     * @throws TypeError
357
-     */
358
-    public static function aead_xchacha20poly1305_ietf_encrypt(
359
-        $message = '',
360
-        $ad = '',
361
-        $nonce = '',
362
-        $key = ''
363
-    ) {
364
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
365
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
366
-            $key
367
-        );
368
-        $nonceLast = "\x00\x00\x00\x00" .
369
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
370
-
371
-        return self::aead_chacha20poly1305_ietf_encrypt($message, $ad, $nonceLast, $subkey);
372
-    }
373
-
374
-    /**
375
-     * HMAC-SHA-512-256 (a.k.a. the leftmost 256 bits of HMAC-SHA-512)
376
-     *
377
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
378
-     *
379
-     * @param string $message
380
-     * @param string $key
381
-     * @return string
382
-     * @throws TypeError
383
-     */
384
-    public static function auth($message, $key)
385
-    {
386
-        return ParagonIE_Sodium_Core32_Util::substr(
387
-            hash_hmac('sha512', $message, $key, true),
388
-            0,
389
-            32
390
-        );
391
-    }
392
-
393
-    /**
394
-     * HMAC-SHA-512-256 validation. Constant-time via hash_equals().
395
-     *
396
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
397
-     *
398
-     * @param string $mac
399
-     * @param string $message
400
-     * @param string $key
401
-     * @return bool
402
-     * @throws SodiumException
403
-     * @throws TypeError
404
-     */
405
-    public static function auth_verify($mac, $message, $key)
406
-    {
407
-        return ParagonIE_Sodium_Core32_Util::hashEquals(
408
-            $mac,
409
-            self::auth($message, $key)
410
-        );
411
-    }
412
-
413
-    /**
414
-     * X25519 key exchange followed by XSalsa20Poly1305 symmetric encryption
415
-     *
416
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
417
-     *
418
-     * @param string $plaintext
419
-     * @param string $nonce
420
-     * @param string $keypair
421
-     * @return string
422
-     * @throws SodiumException
423
-     * @throws TypeError
424
-     */
425
-    public static function box($plaintext, $nonce, $keypair)
426
-    {
427
-        return self::secretbox(
428
-            $plaintext,
429
-            $nonce,
430
-            self::box_beforenm(
431
-                self::box_secretkey($keypair),
432
-                self::box_publickey($keypair)
433
-            )
434
-        );
435
-    }
436
-
437
-    /**
438
-     * X25519-XSalsa20-Poly1305 with one ephemeral X25519 keypair.
439
-     *
440
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
441
-     *
442
-     * @param string $message
443
-     * @param string $publicKey
444
-     * @return string
445
-     * @throws SodiumException
446
-     * @throws TypeError
447
-     */
448
-    public static function box_seal($message, $publicKey)
449
-    {
450
-        /** @var string $ephemeralKeypair */
451
-        $ephemeralKeypair = self::box_keypair();
452
-
453
-        /** @var string $ephemeralSK */
454
-        $ephemeralSK = self::box_secretkey($ephemeralKeypair);
455
-
456
-        /** @var string $ephemeralPK */
457
-        $ephemeralPK = self::box_publickey($ephemeralKeypair);
458
-
459
-        /** @var string $nonce */
460
-        $nonce = self::generichash(
461
-            $ephemeralPK . $publicKey,
462
-            '',
463
-            24
464
-        );
465
-
466
-        /** @var string $keypair - The combined keypair used in crypto_box() */
467
-        $keypair = self::box_keypair_from_secretkey_and_publickey($ephemeralSK, $publicKey);
468
-
469
-        /** @var string $ciphertext Ciphertext + MAC from crypto_box */
470
-        $ciphertext = self::box($message, $nonce, $keypair);
471
-        try {
472
-            ParagonIE_Sodium_Compat::memzero($ephemeralKeypair);
473
-            ParagonIE_Sodium_Compat::memzero($ephemeralSK);
474
-            ParagonIE_Sodium_Compat::memzero($nonce);
475
-        } catch (SodiumException $ex) {
476
-            $ephemeralKeypair = null;
477
-            $ephemeralSK = null;
478
-            $nonce = null;
479
-        }
480
-        return $ephemeralPK . $ciphertext;
481
-    }
482
-
483
-    /**
484
-     * Opens a message encrypted via box_seal().
485
-     *
486
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
487
-     *
488
-     * @param string $message
489
-     * @param string $keypair
490
-     * @return string
491
-     * @throws SodiumException
492
-     * @throws TypeError
493
-     */
494
-    public static function box_seal_open($message, $keypair)
495
-    {
496
-        /** @var string $ephemeralPK */
497
-        $ephemeralPK = ParagonIE_Sodium_Core32_Util::substr($message, 0, 32);
498
-
499
-        /** @var string $ciphertext (ciphertext + MAC) */
500
-        $ciphertext = ParagonIE_Sodium_Core32_Util::substr($message, 32);
501
-
502
-        /** @var string $secretKey */
503
-        $secretKey = self::box_secretkey($keypair);
504
-
505
-        /** @var string $publicKey */
506
-        $publicKey = self::box_publickey($keypair);
507
-
508
-        /** @var string $nonce */
509
-        $nonce = self::generichash(
510
-            $ephemeralPK . $publicKey,
511
-            '',
512
-            24
513
-        );
514
-
515
-        /** @var string $keypair */
516
-        $keypair = self::box_keypair_from_secretkey_and_publickey($secretKey, $ephemeralPK);
517
-
518
-        /** @var string $m */
519
-        $m = self::box_open($ciphertext, $nonce, $keypair);
520
-        try {
521
-            ParagonIE_Sodium_Compat::memzero($secretKey);
522
-            ParagonIE_Sodium_Compat::memzero($ephemeralPK);
523
-            ParagonIE_Sodium_Compat::memzero($nonce);
524
-        } catch (SodiumException $ex) {
525
-            $secretKey = null;
526
-            $ephemeralPK = null;
527
-            $nonce = null;
528
-        }
529
-        return $m;
530
-    }
531
-
532
-    /**
533
-     * Used by crypto_box() to get the crypto_secretbox() key.
534
-     *
535
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
536
-     *
537
-     * @param string $sk
538
-     * @param string $pk
539
-     * @return string
540
-     * @throws SodiumException
541
-     * @throws TypeError
542
-     */
543
-    public static function box_beforenm($sk, $pk)
544
-    {
545
-        return ParagonIE_Sodium_Core32_HSalsa20::hsalsa20(
546
-            str_repeat("\x00", 16),
547
-            self::scalarmult($sk, $pk)
548
-        );
549
-    }
550
-
551
-    /**
552
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
553
-     *
554
-     * @return string
555
-     * @throws Exception
556
-     * @throws SodiumException
557
-     * @throws TypeError
558
-     */
559
-    public static function box_keypair()
560
-    {
561
-        $sKey = random_bytes(32);
562
-        $pKey = self::scalarmult_base($sKey);
563
-        return $sKey . $pKey;
564
-    }
565
-
566
-    /**
567
-     * @param string $seed
568
-     * @return string
569
-     * @throws SodiumException
570
-     * @throws TypeError
571
-     */
572
-    public static function box_seed_keypair($seed)
573
-    {
574
-        $sKey = ParagonIE_Sodium_Core32_Util::substr(
575
-            hash('sha512', $seed, true),
576
-            0,
577
-            32
578
-        );
579
-        $pKey = self::scalarmult_base($sKey);
580
-        return $sKey . $pKey;
581
-    }
582
-
583
-    /**
584
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
585
-     *
586
-     * @param string $sKey
587
-     * @param string $pKey
588
-     * @return string
589
-     * @throws TypeError
590
-     */
591
-    public static function box_keypair_from_secretkey_and_publickey($sKey, $pKey)
592
-    {
593
-        return ParagonIE_Sodium_Core32_Util::substr($sKey, 0, 32) .
594
-            ParagonIE_Sodium_Core32_Util::substr($pKey, 0, 32);
595
-    }
596
-
597
-    /**
598
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
599
-     *
600
-     * @param string $keypair
601
-     * @return string
602
-     * @throws RangeException
603
-     * @throws TypeError
604
-     */
605
-    public static function box_secretkey($keypair)
606
-    {
607
-        if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== 64) {
608
-            throw new RangeException(
609
-                'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
610
-            );
611
-        }
612
-        return ParagonIE_Sodium_Core32_Util::substr($keypair, 0, 32);
613
-    }
614
-
615
-    /**
616
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
617
-     *
618
-     * @param string $keypair
619
-     * @return string
620
-     * @throws RangeException
621
-     * @throws TypeError
622
-     */
623
-    public static function box_publickey($keypair)
624
-    {
625
-        if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
626
-            throw new RangeException(
627
-                'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
628
-            );
629
-        }
630
-        return ParagonIE_Sodium_Core32_Util::substr($keypair, 32, 32);
631
-    }
632
-
633
-    /**
634
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
635
-     *
636
-     * @param string $sKey
637
-     * @return string
638
-     * @throws RangeException
639
-     * @throws SodiumException
640
-     * @throws TypeError
641
-     */
642
-    public static function box_publickey_from_secretkey($sKey)
643
-    {
644
-        if (ParagonIE_Sodium_Core32_Util::strlen($sKey) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES) {
645
-            throw new RangeException(
646
-                'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES bytes long.'
647
-            );
648
-        }
649
-        return self::scalarmult_base($sKey);
650
-    }
651
-
652
-    /**
653
-     * Decrypt a message encrypted with box().
654
-     *
655
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
656
-     *
657
-     * @param string $ciphertext
658
-     * @param string $nonce
659
-     * @param string $keypair
660
-     * @return string
661
-     * @throws SodiumException
662
-     * @throws TypeError
663
-     */
664
-    public static function box_open($ciphertext, $nonce, $keypair)
665
-    {
666
-        return self::secretbox_open(
667
-            $ciphertext,
668
-            $nonce,
669
-            self::box_beforenm(
670
-                self::box_secretkey($keypair),
671
-                self::box_publickey($keypair)
672
-            )
673
-        );
674
-    }
675
-
676
-    /**
677
-     * Calculate a BLAKE2b hash.
678
-     *
679
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
680
-     *
681
-     * @param string $message
682
-     * @param string|null $key
683
-     * @param int $outlen
684
-     * @return string
685
-     * @throws RangeException
686
-     * @throws SodiumException
687
-     * @throws TypeError
688
-     */
689
-    public static function generichash($message, $key = '', $outlen = 32)
690
-    {
691
-        // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
692
-        ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
693
-
694
-        $k = null;
695
-        if (!empty($key)) {
696
-            /** @var SplFixedArray $k */
697
-            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
698
-            if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
699
-                throw new RangeException('Invalid key size');
700
-            }
701
-        }
702
-
703
-        /** @var SplFixedArray $in */
704
-        $in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($message);
705
-
706
-        /** @var SplFixedArray $ctx */
707
-        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outlen);
708
-        ParagonIE_Sodium_Core32_BLAKE2b::update($ctx, $in, $in->count());
709
-
710
-        /** @var SplFixedArray $out */
711
-        $out = new SplFixedArray($outlen);
712
-        $out = ParagonIE_Sodium_Core32_BLAKE2b::finish($ctx, $out);
713
-
714
-        /** @var array<int, int> */
715
-        $outArray = $out->toArray();
716
-        return ParagonIE_Sodium_Core32_Util::intArrayToString($outArray);
717
-    }
718
-
719
-    /**
720
-     * Finalize a BLAKE2b hashing context, returning the hash.
721
-     *
722
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
723
-     *
724
-     * @param string $ctx
725
-     * @param int $outlen
726
-     * @return string
727
-     * @throws SodiumException
728
-     * @throws TypeError
729
-     */
730
-    public static function generichash_final($ctx, $outlen = 32)
731
-    {
732
-        if (!is_string($ctx)) {
733
-            throw new TypeError('Context must be a string');
734
-        }
735
-        $out = new SplFixedArray($outlen);
736
-
737
-        /** @var SplFixedArray $context */
738
-        $context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext($ctx);
739
-
740
-        /** @var SplFixedArray $out */
741
-        $out = ParagonIE_Sodium_Core32_BLAKE2b::finish($context, $out);
742
-
743
-        /** @var array<int, int> */
744
-        $outArray = $out->toArray();
745
-        return ParagonIE_Sodium_Core32_Util::intArrayToString($outArray);
746
-    }
747
-
748
-    /**
749
-     * Initialize a hashing context for BLAKE2b.
750
-     *
751
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
752
-     *
753
-     * @param string $key
754
-     * @param int $outputLength
755
-     * @return string
756
-     * @throws RangeException
757
-     * @throws SodiumException
758
-     * @throws TypeError
759
-     */
760
-    public static function generichash_init($key = '', $outputLength = 32)
761
-    {
762
-        // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
763
-        ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
764
-
765
-        $k = null;
766
-        if (!empty($key)) {
767
-            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
768
-            if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
769
-                throw new RangeException('Invalid key size');
770
-            }
771
-        }
772
-
773
-        /** @var SplFixedArray $ctx */
774
-        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outputLength);
775
-
776
-        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($ctx);
777
-    }
778
-
779
-    /**
780
-     * Initialize a hashing context for BLAKE2b.
781
-     *
782
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
783
-     *
784
-     * @param string $key
785
-     * @param int $outputLength
786
-     * @param string $salt
787
-     * @param string $personal
788
-     * @return string
789
-     * @throws RangeException
790
-     * @throws SodiumException
791
-     * @throws TypeError
792
-     */
793
-    public static function generichash_init_salt_personal(
794
-        $key = '',
795
-        $outputLength = 32,
796
-        $salt = '',
797
-        $personal = ''
798
-    ) {
799
-        // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
800
-        ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
801
-
802
-        $k = null;
803
-        if (!empty($key)) {
804
-            $k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
805
-            if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
806
-                throw new RangeException('Invalid key size');
807
-            }
808
-        }
809
-        if (!empty($salt)) {
810
-            $s = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($salt);
811
-        } else {
812
-            $s = null;
813
-        }
814
-        if (!empty($salt)) {
815
-            $p = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($personal);
816
-        } else {
817
-            $p = null;
818
-        }
819
-
820
-        /** @var SplFixedArray $ctx */
821
-        $ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outputLength, $s, $p);
822
-
823
-        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($ctx);
824
-    }
825
-
826
-    /**
827
-     * Update a hashing context for BLAKE2b with $message
828
-     *
829
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
830
-     *
831
-     * @param string $ctx
832
-     * @param string $message
833
-     * @return string
834
-     * @throws SodiumException
835
-     * @throws TypeError
836
-     */
837
-    public static function generichash_update($ctx, $message)
838
-    {
839
-        // This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
840
-        ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
841
-
842
-        /** @var SplFixedArray $context */
843
-        $context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext($ctx);
844
-
845
-        /** @var SplFixedArray $in */
846
-        $in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($message);
847
-
848
-        ParagonIE_Sodium_Core32_BLAKE2b::update($context, $in, $in->count());
849
-
850
-        return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($context);
851
-    }
852
-
853
-    /**
854
-     * Libsodium's crypto_kx().
855
-     *
856
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
857
-     *
858
-     * @param string $my_sk
859
-     * @param string $their_pk
860
-     * @param string $client_pk
861
-     * @param string $server_pk
862
-     * @return string
863
-     * @throws SodiumException
864
-     * @throws TypeError
865
-     */
866
-    public static function keyExchange($my_sk, $their_pk, $client_pk, $server_pk)
867
-    {
868
-        return self::generichash(
869
-            self::scalarmult($my_sk, $their_pk) .
870
-            $client_pk .
871
-            $server_pk
872
-        );
873
-    }
874
-
875
-    /**
876
-     * ECDH over Curve25519
877
-     *
878
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
879
-     *
880
-     * @param string $sKey
881
-     * @param string $pKey
882
-     * @return string
883
-     *
884
-     * @throws SodiumException
885
-     * @throws TypeError
886
-     */
887
-    public static function scalarmult($sKey, $pKey)
888
-    {
889
-        $q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10($sKey, $pKey);
890
-        self::scalarmult_throw_if_zero($q);
891
-        return $q;
892
-    }
893
-
894
-    /**
895
-     * ECDH over Curve25519, using the basepoint.
896
-     * Used to get a secret key from a public key.
897
-     *
898
-     * @param string $secret
899
-     * @return string
900
-     *
901
-     * @throws SodiumException
902
-     * @throws TypeError
903
-     */
904
-    public static function scalarmult_base($secret)
905
-    {
906
-        $q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10_base($secret);
907
-        self::scalarmult_throw_if_zero($q);
908
-        return $q;
909
-    }
910
-
911
-    /**
912
-     * This throws an Error if a zero public key was passed to the function.
913
-     *
914
-     * @param string $q
915
-     * @return void
916
-     * @throws SodiumException
917
-     * @throws TypeError
918
-     */
919
-    protected static function scalarmult_throw_if_zero($q)
920
-    {
921
-        $d = 0;
922
-        for ($i = 0; $i < self::box_curve25519xsalsa20poly1305_SECRETKEYBYTES; ++$i) {
923
-            $d |= ParagonIE_Sodium_Core32_Util::chrToInt($q[$i]);
924
-        }
925
-
926
-        /* branch-free variant of === 0 */
927
-        if (-(1 & (($d - 1) >> 8))) {
928
-            throw new SodiumException('Zero public key is not allowed');
929
-        }
930
-    }
931
-
932
-    /**
933
-     * XSalsa20-Poly1305 authenticated symmetric-key encryption.
934
-     *
935
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
936
-     *
937
-     * @param string $plaintext
938
-     * @param string $nonce
939
-     * @param string $key
940
-     * @return string
941
-     * @throws SodiumException
942
-     * @throws TypeError
943
-     */
944
-    public static function secretbox($plaintext, $nonce, $key)
945
-    {
946
-        /** @var string $subkey */
947
-        $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
948
-
949
-        /** @var string $block0 */
950
-        $block0 = str_repeat("\x00", 32);
951
-
952
-        /** @var int $mlen - Length of the plaintext message */
953
-        $mlen = ParagonIE_Sodium_Core32_Util::strlen($plaintext);
954
-        $mlen0 = $mlen;
955
-        if ($mlen0 > 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES) {
956
-            $mlen0 = 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES;
957
-        }
958
-        $block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
959
-
960
-        /** @var string $block0 */
961
-        $block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor(
962
-            $block0,
963
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
964
-            $subkey
965
-        );
966
-
967
-        /** @var string $c */
968
-        $c = ParagonIE_Sodium_Core32_Util::substr(
969
-            $block0,
970
-            self::secretbox_xsalsa20poly1305_ZEROBYTES
971
-        );
972
-        if ($mlen > $mlen0) {
973
-            $c .= ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
974
-                ParagonIE_Sodium_Core32_Util::substr(
975
-                    $plaintext,
976
-                    self::secretbox_xsalsa20poly1305_ZEROBYTES
977
-                ),
978
-                ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
979
-                1,
980
-                $subkey
981
-            );
982
-        }
983
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State(
984
-            ParagonIE_Sodium_Core32_Util::substr(
985
-                $block0,
986
-                0,
987
-                self::onetimeauth_poly1305_KEYBYTES
988
-            )
989
-        );
990
-        try {
991
-            ParagonIE_Sodium_Compat::memzero($block0);
992
-            ParagonIE_Sodium_Compat::memzero($subkey);
993
-        } catch (SodiumException $ex) {
994
-            $block0 = null;
995
-            $subkey = null;
996
-        }
997
-
998
-        $state->update($c);
999
-
1000
-        /** @var string $c - MAC || ciphertext */
1001
-        $c = $state->finish() . $c;
1002
-        unset($state);
1003
-
1004
-        return $c;
1005
-    }
1006
-
1007
-    /**
1008
-     * Decrypt a ciphertext generated via secretbox().
1009
-     *
1010
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1011
-     *
1012
-     * @param string $ciphertext
1013
-     * @param string $nonce
1014
-     * @param string $key
1015
-     * @return string
1016
-     * @throws SodiumException
1017
-     * @throws TypeError
1018
-     */
1019
-    public static function secretbox_open($ciphertext, $nonce, $key)
1020
-    {
1021
-        /** @var string $mac */
1022
-        $mac = ParagonIE_Sodium_Core32_Util::substr(
1023
-            $ciphertext,
1024
-            0,
1025
-            self::secretbox_xsalsa20poly1305_MACBYTES
1026
-        );
1027
-
1028
-        /** @var string $c */
1029
-        $c = ParagonIE_Sodium_Core32_Util::substr(
1030
-            $ciphertext,
1031
-            self::secretbox_xsalsa20poly1305_MACBYTES
1032
-        );
1033
-
1034
-        /** @var int $clen */
1035
-        $clen = ParagonIE_Sodium_Core32_Util::strlen($c);
1036
-
1037
-        /** @var string $subkey */
1038
-        $subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
1039
-
1040
-        /** @var string $block0 */
1041
-        $block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20(
1042
-            64,
1043
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1044
-            $subkey
1045
-        );
1046
-        $verified = ParagonIE_Sodium_Core32_Poly1305::onetimeauth_verify(
1047
-            $mac,
1048
-            $c,
1049
-            ParagonIE_Sodium_Core32_Util::substr($block0, 0, 32)
1050
-        );
1051
-        if (!$verified) {
1052
-            try {
1053
-                ParagonIE_Sodium_Compat::memzero($subkey);
1054
-            } catch (SodiumException $ex) {
1055
-                $subkey = null;
1056
-            }
1057
-            throw new SodiumException('Invalid MAC');
1058
-        }
1059
-
1060
-        /** @var string $m - Decrypted message */
1061
-        $m = ParagonIE_Sodium_Core32_Util::xorStrings(
1062
-            ParagonIE_Sodium_Core32_Util::substr($block0, self::secretbox_xsalsa20poly1305_ZEROBYTES),
1063
-            ParagonIE_Sodium_Core32_Util::substr($c, 0, self::secretbox_xsalsa20poly1305_ZEROBYTES)
1064
-        );
1065
-        if ($clen > self::secretbox_xsalsa20poly1305_ZEROBYTES) {
1066
-            // We had more than 1 block, so let's continue to decrypt the rest.
1067
-            $m .= ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
1068
-                ParagonIE_Sodium_Core32_Util::substr(
1069
-                    $c,
1070
-                    self::secretbox_xsalsa20poly1305_ZEROBYTES
1071
-                ),
1072
-                ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1073
-                1,
1074
-                (string) $subkey
1075
-            );
1076
-        }
1077
-        return $m;
1078
-    }
1079
-
1080
-    /**
1081
-     * XChaCha20-Poly1305 authenticated symmetric-key encryption.
1082
-     *
1083
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1084
-     *
1085
-     * @param string $plaintext
1086
-     * @param string $nonce
1087
-     * @param string $key
1088
-     * @return string
1089
-     * @throws SodiumException
1090
-     * @throws TypeError
1091
-     */
1092
-    public static function secretbox_xchacha20poly1305($plaintext, $nonce, $key)
1093
-    {
1094
-        /** @var string $subkey */
1095
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1096
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
1097
-            $key
1098
-        );
1099
-        $nonceLast = ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
1100
-
1101
-        /** @var string $block0 */
1102
-        $block0 = str_repeat("\x00", 32);
1103
-
1104
-        /** @var int $mlen - Length of the plaintext message */
1105
-        $mlen = ParagonIE_Sodium_Core32_Util::strlen($plaintext);
1106
-        $mlen0 = $mlen;
1107
-        if ($mlen0 > 64 - self::secretbox_xchacha20poly1305_ZEROBYTES) {
1108
-            $mlen0 = 64 - self::secretbox_xchacha20poly1305_ZEROBYTES;
1109
-        }
1110
-        $block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
1111
-
1112
-        /** @var string $block0 */
1113
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1114
-            $block0,
1115
-            $nonceLast,
1116
-            $subkey
1117
-        );
1118
-
1119
-        /** @var string $c */
1120
-        $c = ParagonIE_Sodium_Core32_Util::substr(
1121
-            $block0,
1122
-            self::secretbox_xchacha20poly1305_ZEROBYTES
1123
-        );
1124
-        if ($mlen > $mlen0) {
1125
-            $c .= ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1126
-                ParagonIE_Sodium_Core32_Util::substr(
1127
-                    $plaintext,
1128
-                    self::secretbox_xchacha20poly1305_ZEROBYTES
1129
-                ),
1130
-                $nonceLast,
1131
-                $subkey,
1132
-                ParagonIE_Sodium_Core32_Util::store64_le(1)
1133
-            );
1134
-        }
1135
-        $state = new ParagonIE_Sodium_Core32_Poly1305_State(
1136
-            ParagonIE_Sodium_Core32_Util::substr(
1137
-                $block0,
1138
-                0,
1139
-                self::onetimeauth_poly1305_KEYBYTES
1140
-            )
1141
-        );
1142
-        try {
1143
-            ParagonIE_Sodium_Compat::memzero($block0);
1144
-            ParagonIE_Sodium_Compat::memzero($subkey);
1145
-        } catch (SodiumException $ex) {
1146
-            $block0 = null;
1147
-            $subkey = null;
1148
-        }
1149
-
1150
-        $state->update($c);
1151
-
1152
-        /** @var string $c - MAC || ciphertext */
1153
-        $c = $state->finish() . $c;
1154
-        unset($state);
1155
-
1156
-        return $c;
1157
-    }
1158
-
1159
-    /**
1160
-     * Decrypt a ciphertext generated via secretbox_xchacha20poly1305().
1161
-     *
1162
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1163
-     *
1164
-     * @param string $ciphertext
1165
-     * @param string $nonce
1166
-     * @param string $key
1167
-     * @return string
1168
-     * @throws SodiumException
1169
-     * @throws TypeError
1170
-     */
1171
-    public static function secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key)
1172
-    {
1173
-        /** @var string $mac */
1174
-        $mac = ParagonIE_Sodium_Core32_Util::substr(
1175
-            $ciphertext,
1176
-            0,
1177
-            self::secretbox_xchacha20poly1305_MACBYTES
1178
-        );
1179
-
1180
-        /** @var string $c */
1181
-        $c = ParagonIE_Sodium_Core32_Util::substr(
1182
-            $ciphertext,
1183
-            self::secretbox_xchacha20poly1305_MACBYTES
1184
-        );
1185
-
1186
-        /** @var int $clen */
1187
-        $clen = ParagonIE_Sodium_Core32_Util::strlen($c);
1188
-
1189
-        /** @var string $subkey */
1190
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hchacha20($nonce, $key);
1191
-
1192
-        /** @var string $block0 */
1193
-        $block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
1194
-            64,
1195
-            ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1196
-            $subkey
1197
-        );
1198
-        $verified = ParagonIE_Sodium_Core32_Poly1305::onetimeauth_verify(
1199
-            $mac,
1200
-            $c,
1201
-            ParagonIE_Sodium_Core32_Util::substr($block0, 0, 32)
1202
-        );
1203
-
1204
-        if (!$verified) {
1205
-            try {
1206
-                ParagonIE_Sodium_Compat::memzero($subkey);
1207
-            } catch (SodiumException $ex) {
1208
-                $subkey = null;
1209
-            }
1210
-            throw new SodiumException('Invalid MAC');
1211
-        }
1212
-
1213
-        /** @var string $m - Decrypted message */
1214
-        $m = ParagonIE_Sodium_Core32_Util::xorStrings(
1215
-            ParagonIE_Sodium_Core32_Util::substr($block0, self::secretbox_xchacha20poly1305_ZEROBYTES),
1216
-            ParagonIE_Sodium_Core32_Util::substr($c, 0, self::secretbox_xchacha20poly1305_ZEROBYTES)
1217
-        );
1218
-
1219
-        if ($clen > self::secretbox_xchacha20poly1305_ZEROBYTES) {
1220
-            // We had more than 1 block, so let's continue to decrypt the rest.
1221
-            $m .= ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1222
-                ParagonIE_Sodium_Core32_Util::substr(
1223
-                    $c,
1224
-                    self::secretbox_xchacha20poly1305_ZEROBYTES
1225
-                ),
1226
-                ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1227
-                (string) $subkey,
1228
-                ParagonIE_Sodium_Core32_Util::store64_le(1)
1229
-            );
1230
-        }
1231
-        return $m;
1232
-    }
1233
-
1234
-    /**
1235
-     * @param string $key
1236
-     * @return array<int, string> Returns a state and a header.
1237
-     * @throws Exception
1238
-     * @throws SodiumException
1239
-     */
1240
-    public static function secretstream_xchacha20poly1305_init_push($key)
1241
-    {
1242
-        # randombytes_buf(out, crypto_secretstream_xchacha20poly1305_HEADERBYTES);
1243
-        $out = random_bytes(24);
1244
-
1245
-        # crypto_core_hchacha20(state->k, out, k, NULL);
1246
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20($out, $key);
1247
-        $state = new ParagonIE_Sodium_Core32_SecretStream_State(
1248
-            $subkey,
1249
-            ParagonIE_Sodium_Core32_Util::substr($out, 16, 8) . str_repeat("\0", 4)
1250
-        );
1251
-
1252
-        # _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1253
-        $state->counterReset();
1254
-
1255
-        # memcpy(STATE_INONCE(state), out + crypto_core_hchacha20_INPUTBYTES,
1256
-        #        crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1257
-        # memset(state->_pad, 0, sizeof state->_pad);
1258
-        return array(
1259
-            $state->toString(),
1260
-            $out
1261
-        );
1262
-    }
1263
-
1264
-    /**
1265
-     * @param string $key
1266
-     * @param string $header
1267
-     * @return string Returns a state.
1268
-     * @throws Exception
1269
-     */
1270
-    public static function secretstream_xchacha20poly1305_init_pull($key, $header)
1271
-    {
1272
-        # crypto_core_hchacha20(state->k, in, k, NULL);
1273
-        $subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1274
-            ParagonIE_Sodium_Core32_Util::substr($header, 0, 16),
1275
-            $key
1276
-        );
1277
-        $state = new ParagonIE_Sodium_Core32_SecretStream_State(
1278
-            $subkey,
1279
-            ParagonIE_Sodium_Core32_Util::substr($header, 16)
1280
-        );
1281
-        $state->counterReset();
1282
-        # memcpy(STATE_INONCE(state), in + crypto_core_hchacha20_INPUTBYTES,
1283
-        #     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1284
-        # memset(state->_pad, 0, sizeof state->_pad);
1285
-        # return 0;
1286
-        return $state->toString();
1287
-    }
1288
-
1289
-    /**
1290
-     * @param string $state
1291
-     * @param string $msg
1292
-     * @param string $aad
1293
-     * @param int $tag
1294
-     * @return string
1295
-     * @throws SodiumException
1296
-     */
1297
-    public static function secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0)
1298
-    {
1299
-        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1300
-        # crypto_onetimeauth_poly1305_state poly1305_state;
1301
-        # unsigned char                     block[64U];
1302
-        # unsigned char                     slen[8U];
1303
-        # unsigned char                    *c;
1304
-        # unsigned char                    *mac;
1305
-
1306
-        $msglen = ParagonIE_Sodium_Core32_Util::strlen($msg);
1307
-        $aadlen = ParagonIE_Sodium_Core32_Util::strlen($aad);
1308
-
1309
-        if ((($msglen + 63) >> 6) > 0xfffffffe) {
1310
-            throw new SodiumException(
1311
-                'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1312
-            );
1313
-        }
1314
-
1315
-        # if (outlen_p != NULL) {
1316
-        #     *outlen_p = 0U;
1317
-        # }
1318
-        # if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1319
-        #     sodium_misuse();
1320
-        # }
1321
-
1322
-        # crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1323
-        # crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1324
-        # sodium_memzero(block, sizeof block);
1325
-        $auth = new ParagonIE_Sodium_Core32_Poly1305_State(
1326
-            ParagonIE_Sodium_Core32_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1327
-        );
1328
-
1329
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1330
-        $auth->update($aad);
1331
-
1332
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1333
-        #     (0x10 - adlen) & 0xf);
1334
-        $auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1335
-
1336
-        # memset(block, 0, sizeof block);
1337
-        # block[0] = tag;
1338
-        # crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1339
-        #                                    state->nonce, 1U, state->k);
1340
-        $block = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1341
-            ParagonIE_Sodium_Core32_Util::intToChr($tag) . str_repeat("\0", 63),
1342
-            $st->getCombinedNonce(),
1343
-            $st->getKey(),
1344
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
1345
-        );
1346
-
1347
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1348
-        $auth->update($block);
1349
-
1350
-        # out[0] = block[0];
1351
-        $out = $block[0];
1352
-        # c = out + (sizeof tag);
1353
-        # crypto_stream_chacha20_ietf_xor_ic(c, m, mlen, state->nonce, 2U, state->k);
1354
-        $cipher = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1355
-            $msg,
1356
-            $st->getCombinedNonce(),
1357
-            $st->getKey(),
1358
-            ParagonIE_Sodium_Core32_Util::store64_le(2)
1359
-        );
1360
-
1361
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1362
-        $auth->update($cipher);
1363
-
1364
-        $out .= $cipher;
1365
-        unset($cipher);
1366
-
1367
-        # crypto_onetimeauth_poly1305_update
1368
-        # (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1369
-        $auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1370
-
1371
-        # STORE64_LE(slen, (uint64_t) adlen);
1372
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le($aadlen);
1373
-
1374
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1375
-        $auth->update($slen);
1376
-
1377
-        # STORE64_LE(slen, (sizeof block) + mlen);
1378
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le(64 + $msglen);
1379
-
1380
-        # crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1381
-        $auth->update($slen);
1382
-
1383
-        # mac = c + mlen;
1384
-        # crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1385
-        $mac = $auth->finish();
1386
-        $out .= $mac;
1387
-
1388
-        # sodium_memzero(&poly1305_state, sizeof poly1305_state);
1389
-        unset($auth);
1390
-
1391
-
1392
-        # XOR_BUF(STATE_INONCE(state), mac,
1393
-        #     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1394
-        $st->xorNonce($mac);
1395
-
1396
-        # sodium_increment(STATE_COUNTER(state),
1397
-        #     crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1398
-        $st->incrementCounter();
1399
-        // Overwrite by reference:
1400
-        $state = $st->toString();
1401
-
1402
-        /** @var bool $rekey */
1403
-        $rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1404
-        # if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1405
-        #     sodium_is_zero(STATE_COUNTER(state),
1406
-        #         crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1407
-        #     crypto_secretstream_xchacha20poly1305_rekey(state);
1408
-        # }
1409
-        if ($rekey || $st->needsRekey()) {
1410
-            // DO REKEY
1411
-            self::secretstream_xchacha20poly1305_rekey($state);
1412
-        }
1413
-        # if (outlen_p != NULL) {
1414
-        #     *outlen_p = crypto_secretstream_xchacha20poly1305_ABYTES + mlen;
1415
-        # }
1416
-        return $out;
1417
-    }
1418
-
1419
-    /**
1420
-     * @param string $state
1421
-     * @param string $cipher
1422
-     * @param string $aad
1423
-     * @return bool|array{0: string, 1: int}
1424
-     * @throws SodiumException
1425
-     */
1426
-    public static function secretstream_xchacha20poly1305_pull(&$state, $cipher, $aad = '')
1427
-    {
1428
-        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1429
-
1430
-        $cipherlen = ParagonIE_Sodium_Core32_Util::strlen($cipher);
1431
-        #     mlen = inlen - crypto_secretstream_xchacha20poly1305_ABYTES;
1432
-        $msglen = $cipherlen - ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_ABYTES;
1433
-        $aadlen = ParagonIE_Sodium_Core32_Util::strlen($aad);
1434
-
1435
-        #     if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1436
-        #         sodium_misuse();
1437
-        #     }
1438
-        if ((($msglen + 63) >> 6) > 0xfffffffe) {
1439
-            throw new SodiumException(
1440
-                'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1441
-            );
1442
-        }
1443
-
1444
-        #     crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1445
-        #     crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1446
-        #     sodium_memzero(block, sizeof block);
1447
-        $auth = new ParagonIE_Sodium_Core32_Poly1305_State(
1448
-            ParagonIE_Sodium_Core32_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1449
-        );
1450
-
1451
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1452
-        $auth->update($aad);
1453
-
1454
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1455
-        #         (0x10 - adlen) & 0xf);
1456
-        $auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1457
-
1458
-
1459
-        #     memset(block, 0, sizeof block);
1460
-        #     block[0] = in[0];
1461
-        #     crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1462
-        #                                        state->nonce, 1U, state->k);
1463
-        $block = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1464
-            $cipher[0] . str_repeat("\0", 63),
1465
-            $st->getCombinedNonce(),
1466
-            $st->getKey(),
1467
-            ParagonIE_Sodium_Core32_Util::store64_le(1)
1468
-        );
1469
-        #     tag = block[0];
1470
-        #     block[0] = in[0];
1471
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1472
-        $tag = ParagonIE_Sodium_Core32_Util::chrToInt($block[0]);
1473
-        $block[0] = $cipher[0];
1474
-        $auth->update($block);
1475
-
1476
-
1477
-        #     c = in + (sizeof tag);
1478
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1479
-        $auth->update(ParagonIE_Sodium_Core32_Util::substr($cipher, 1, $msglen));
1480
-
1481
-        #     crypto_onetimeauth_poly1305_update
1482
-        #     (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1483
-        $auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1484
-
1485
-        #     STORE64_LE(slen, (uint64_t) adlen);
1486
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1487
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le($aadlen);
1488
-        $auth->update($slen);
1489
-
1490
-        #     STORE64_LE(slen, (sizeof block) + mlen);
1491
-        #     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1492
-        $slen = ParagonIE_Sodium_Core32_Util::store64_le(64 + $msglen);
1493
-        $auth->update($slen);
1494
-
1495
-        #     crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1496
-        #     sodium_memzero(&poly1305_state, sizeof poly1305_state);
1497
-        $mac = $auth->finish();
1498
-
1499
-        #     stored_mac = c + mlen;
1500
-        #     if (sodium_memcmp(mac, stored_mac, sizeof mac) != 0) {
1501
-        #     sodium_memzero(mac, sizeof mac);
1502
-        #         return -1;
1503
-        #     }
1504
-
1505
-        $stored = ParagonIE_Sodium_Core32_Util::substr($cipher, $msglen + 1, 16);
1506
-        if (!ParagonIE_Sodium_Core32_Util::hashEquals($mac, $stored)) {
1507
-            return false;
1508
-        }
1509
-
1510
-        #     crypto_stream_chacha20_ietf_xor_ic(m, c, mlen, state->nonce, 2U, state->k);
1511
-        $out = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1512
-            ParagonIE_Sodium_Core32_Util::substr($cipher, 1, $msglen),
1513
-            $st->getCombinedNonce(),
1514
-            $st->getKey(),
1515
-            ParagonIE_Sodium_Core32_Util::store64_le(2)
1516
-        );
1517
-
1518
-        #     XOR_BUF(STATE_INONCE(state), mac,
1519
-        #         crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1520
-        $st->xorNonce($mac);
1521
-
1522
-        #     sodium_increment(STATE_COUNTER(state),
1523
-        #         crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1524
-        $st->incrementCounter();
1525
-
1526
-        #     if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1527
-        #         sodium_is_zero(STATE_COUNTER(state),
1528
-        #             crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1529
-        #         crypto_secretstream_xchacha20poly1305_rekey(state);
1530
-        #     }
1531
-
1532
-        // Overwrite by reference:
1533
-        $state = $st->toString();
1534
-
1535
-        /** @var bool $rekey */
1536
-        $rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1537
-        if ($rekey || $st->needsRekey()) {
1538
-            // DO REKEY
1539
-            self::secretstream_xchacha20poly1305_rekey($state);
1540
-        }
1541
-        return array($out, $tag);
1542
-    }
1543
-
1544
-    /**
1545
-     * @param string $state
1546
-     * @return void
1547
-     * @throws SodiumException
1548
-     */
1549
-    public static function secretstream_xchacha20poly1305_rekey(&$state)
1550
-    {
1551
-        $st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1552
-        # unsigned char new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES +
1553
-        # crypto_secretstream_xchacha20poly1305_INONCEBYTES];
1554
-        # size_t        i;
1555
-        # for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1556
-        #     new_key_and_inonce[i] = state->k[i];
1557
-        # }
1558
-        $new_key_and_inonce = $st->getKey();
1559
-
1560
-        # for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1561
-        #     new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i] =
1562
-        #         STATE_INONCE(state)[i];
1563
-        # }
1564
-        $new_key_and_inonce .= ParagonIE_Sodium_Core32_Util::substR($st->getNonce(), 0, 8);
1565
-
1566
-        # crypto_stream_chacha20_ietf_xor(new_key_and_inonce, new_key_and_inonce,
1567
-        #                                 sizeof new_key_and_inonce,
1568
-        #                                 state->nonce, state->k);
1569
-
1570
-        $st->rekey(ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1571
-            $new_key_and_inonce,
1572
-            $st->getCombinedNonce(),
1573
-            $st->getKey(),
1574
-            ParagonIE_Sodium_Core32_Util::store64_le(0)
1575
-        ));
1576
-
1577
-        # for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1578
-        #     state->k[i] = new_key_and_inonce[i];
1579
-        # }
1580
-        # for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1581
-        #     STATE_INONCE(state)[i] =
1582
-        #          new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i];
1583
-        # }
1584
-        # _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1585
-        $st->counterReset();
1586
-
1587
-        $state = $st->toString();
1588
-    }
1589
-
1590
-    /**
1591
-     * Detached Ed25519 signature.
1592
-     *
1593
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1594
-     *
1595
-     * @param string $message
1596
-     * @param string $sk
1597
-     * @return string
1598
-     * @throws SodiumException
1599
-     * @throws TypeError
1600
-     */
1601
-    public static function sign_detached($message, $sk)
1602
-    {
1603
-        return ParagonIE_Sodium_Core32_Ed25519::sign_detached($message, $sk);
1604
-    }
1605
-
1606
-    /**
1607
-     * Attached Ed25519 signature. (Returns a signed message.)
1608
-     *
1609
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1610
-     *
1611
-     * @param string $message
1612
-     * @param string $sk
1613
-     * @return string
1614
-     * @throws SodiumException
1615
-     * @throws TypeError
1616
-     */
1617
-    public static function sign($message, $sk)
1618
-    {
1619
-        return ParagonIE_Sodium_Core32_Ed25519::sign($message, $sk);
1620
-    }
1621
-
1622
-    /**
1623
-     * Opens a signed message. If valid, returns the message.
1624
-     *
1625
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1626
-     *
1627
-     * @param string $signedMessage
1628
-     * @param string $pk
1629
-     * @return string
1630
-     * @throws SodiumException
1631
-     * @throws TypeError
1632
-     */
1633
-    public static function sign_open($signedMessage, $pk)
1634
-    {
1635
-        return ParagonIE_Sodium_Core32_Ed25519::sign_open($signedMessage, $pk);
1636
-    }
1637
-
1638
-    /**
1639
-     * Verify a detached signature of a given message and public key.
1640
-     *
1641
-     * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1642
-     *
1643
-     * @param string $signature
1644
-     * @param string $message
1645
-     * @param string $pk
1646
-     * @return bool
1647
-     * @throws SodiumException
1648
-     * @throws TypeError
1649
-     */
1650
-    public static function sign_verify_detached($signature, $message, $pk)
1651
-    {
1652
-        return ParagonIE_Sodium_Core32_Ed25519::verify_detached($signature, $message, $pk);
1653
-    }
17
+	const aead_chacha20poly1305_KEYBYTES = 32;
18
+	const aead_chacha20poly1305_NSECBYTES = 0;
19
+	const aead_chacha20poly1305_NPUBBYTES = 8;
20
+	const aead_chacha20poly1305_ABYTES = 16;
21
+
22
+	const aead_chacha20poly1305_IETF_KEYBYTES = 32;
23
+	const aead_chacha20poly1305_IETF_NSECBYTES = 0;
24
+	const aead_chacha20poly1305_IETF_NPUBBYTES = 12;
25
+	const aead_chacha20poly1305_IETF_ABYTES = 16;
26
+
27
+	const aead_xchacha20poly1305_IETF_KEYBYTES = 32;
28
+	const aead_xchacha20poly1305_IETF_NSECBYTES = 0;
29
+	const aead_xchacha20poly1305_IETF_NPUBBYTES = 24;
30
+	const aead_xchacha20poly1305_IETF_ABYTES = 16;
31
+
32
+	const box_curve25519xsalsa20poly1305_SEEDBYTES = 32;
33
+	const box_curve25519xsalsa20poly1305_PUBLICKEYBYTES = 32;
34
+	const box_curve25519xsalsa20poly1305_SECRETKEYBYTES = 32;
35
+	const box_curve25519xsalsa20poly1305_BEFORENMBYTES = 32;
36
+	const box_curve25519xsalsa20poly1305_NONCEBYTES = 24;
37
+	const box_curve25519xsalsa20poly1305_MACBYTES = 16;
38
+	const box_curve25519xsalsa20poly1305_BOXZEROBYTES = 16;
39
+	const box_curve25519xsalsa20poly1305_ZEROBYTES = 32;
40
+
41
+	const onetimeauth_poly1305_BYTES = 16;
42
+	const onetimeauth_poly1305_KEYBYTES = 32;
43
+
44
+	const secretbox_xsalsa20poly1305_KEYBYTES = 32;
45
+	const secretbox_xsalsa20poly1305_NONCEBYTES = 24;
46
+	const secretbox_xsalsa20poly1305_MACBYTES = 16;
47
+	const secretbox_xsalsa20poly1305_BOXZEROBYTES = 16;
48
+	const secretbox_xsalsa20poly1305_ZEROBYTES = 32;
49
+
50
+	const secretbox_xchacha20poly1305_KEYBYTES = 32;
51
+	const secretbox_xchacha20poly1305_NONCEBYTES = 24;
52
+	const secretbox_xchacha20poly1305_MACBYTES = 16;
53
+	const secretbox_xchacha20poly1305_BOXZEROBYTES = 16;
54
+	const secretbox_xchacha20poly1305_ZEROBYTES = 32;
55
+
56
+	const stream_salsa20_KEYBYTES = 32;
57
+
58
+	/**
59
+	 * AEAD Decryption with ChaCha20-Poly1305
60
+	 *
61
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
62
+	 *
63
+	 * @param string $message
64
+	 * @param string $ad
65
+	 * @param string $nonce
66
+	 * @param string $key
67
+	 * @return string
68
+	 * @throws SodiumException
69
+	 * @throws TypeError
70
+	 */
71
+	public static function aead_chacha20poly1305_decrypt(
72
+		$message = '',
73
+		$ad = '',
74
+		$nonce = '',
75
+		$key = ''
76
+	) {
77
+		/** @var int $len - Length of message (ciphertext + MAC) */
78
+		$len = ParagonIE_Sodium_Core32_Util::strlen($message);
79
+
80
+		/** @var int  $clen - Length of ciphertext */
81
+		$clen = $len - self::aead_chacha20poly1305_ABYTES;
82
+
83
+		/** @var int $adlen - Length of associated data */
84
+		$adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
85
+
86
+		/** @var string $mac - Message authentication code */
87
+		$mac = ParagonIE_Sodium_Core32_Util::substr(
88
+			$message,
89
+			$clen,
90
+			self::aead_chacha20poly1305_ABYTES
91
+		);
92
+
93
+		/** @var string $ciphertext - The encrypted message (sans MAC) */
94
+		$ciphertext = ParagonIE_Sodium_Core32_Util::substr($message, 0, $clen);
95
+
96
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
97
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
98
+			32,
99
+			$nonce,
100
+			$key
101
+		);
102
+
103
+		/* Recalculate the Poly1305 authentication tag (MAC): */
104
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
105
+		try {
106
+			ParagonIE_Sodium_Compat::memzero($block0);
107
+		} catch (SodiumException $ex) {
108
+			$block0 = null;
109
+		}
110
+		$state->update($ad);
111
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
112
+		$state->update($ciphertext);
113
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($clen));
114
+		$computed_mac = $state->finish();
115
+
116
+		/* Compare the given MAC with the recalculated MAC: */
117
+		if (!ParagonIE_Sodium_Core32_Util::verify_16($computed_mac, $mac)) {
118
+			throw new SodiumException('Invalid MAC');
119
+		}
120
+
121
+		// Here, we know that the MAC is valid, so we decrypt and return the plaintext
122
+		return ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
123
+			$ciphertext,
124
+			$nonce,
125
+			$key,
126
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
127
+		);
128
+	}
129
+
130
+	/**
131
+	 * AEAD Encryption with ChaCha20-Poly1305
132
+	 *
133
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
134
+	 *
135
+	 * @param string $message
136
+	 * @param string $ad
137
+	 * @param string $nonce
138
+	 * @param string $key
139
+	 * @return string
140
+	 * @throws SodiumException
141
+	 * @throws TypeError
142
+	 */
143
+	public static function aead_chacha20poly1305_encrypt(
144
+		$message = '',
145
+		$ad = '',
146
+		$nonce = '',
147
+		$key = ''
148
+	) {
149
+		/** @var int $len - Length of the plaintext message */
150
+		$len = ParagonIE_Sodium_Core32_Util::strlen($message);
151
+
152
+		/** @var int $adlen - Length of the associated data */
153
+		$adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
154
+
155
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
156
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
157
+			32,
158
+			$nonce,
159
+			$key
160
+		);
161
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
162
+		try {
163
+			ParagonIE_Sodium_Compat::memzero($block0);
164
+		} catch (SodiumException $ex) {
165
+			$block0 = null;
166
+		}
167
+
168
+		/** @var string $ciphertext - Raw encrypted data */
169
+		$ciphertext = ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
170
+			$message,
171
+			$nonce,
172
+			$key,
173
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
174
+		);
175
+
176
+		$state->update($ad);
177
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
178
+		$state->update($ciphertext);
179
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($len));
180
+		return $ciphertext . $state->finish();
181
+	}
182
+
183
+	/**
184
+	 * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
185
+	 *
186
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
187
+	 *
188
+	 * @param string $message
189
+	 * @param string $ad
190
+	 * @param string $nonce
191
+	 * @param string $key
192
+	 * @return string
193
+	 * @throws SodiumException
194
+	 * @throws TypeError
195
+	 */
196
+	public static function aead_chacha20poly1305_ietf_decrypt(
197
+		$message = '',
198
+		$ad = '',
199
+		$nonce = '',
200
+		$key = ''
201
+	) {
202
+		/** @var int $adlen - Length of associated data */
203
+		$adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
204
+
205
+		/** @var int $len - Length of message (ciphertext + MAC) */
206
+		$len = ParagonIE_Sodium_Core32_Util::strlen($message);
207
+
208
+		/** @var int  $clen - Length of ciphertext */
209
+		$clen = $len - self::aead_chacha20poly1305_IETF_ABYTES;
210
+
211
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
212
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::ietfStream(
213
+			32,
214
+			$nonce,
215
+			$key
216
+		);
217
+
218
+		/** @var string $mac - Message authentication code */
219
+		$mac = ParagonIE_Sodium_Core32_Util::substr(
220
+			$message,
221
+			$len - self::aead_chacha20poly1305_IETF_ABYTES,
222
+			self::aead_chacha20poly1305_IETF_ABYTES
223
+		);
224
+
225
+		/** @var string $ciphertext - The encrypted message (sans MAC) */
226
+		$ciphertext = ParagonIE_Sodium_Core32_Util::substr(
227
+			$message,
228
+			0,
229
+			$len - self::aead_chacha20poly1305_IETF_ABYTES
230
+		);
231
+
232
+		/* Recalculate the Poly1305 authentication tag (MAC): */
233
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
234
+		try {
235
+			ParagonIE_Sodium_Compat::memzero($block0);
236
+		} catch (SodiumException $ex) {
237
+			$block0 = null;
238
+		}
239
+		$state->update($ad);
240
+		$state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
241
+		$state->update($ciphertext);
242
+		$state->update(str_repeat("\x00", (0x10 - $clen) & 0xf));
243
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
244
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($clen));
245
+		$computed_mac = $state->finish();
246
+
247
+		/* Compare the given MAC with the recalculated MAC: */
248
+		if (!ParagonIE_Sodium_Core32_Util::verify_16($computed_mac, $mac)) {
249
+			throw new SodiumException('Invalid MAC');
250
+		}
251
+
252
+		// Here, we know that the MAC is valid, so we decrypt and return the plaintext
253
+		return ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
254
+			$ciphertext,
255
+			$nonce,
256
+			$key,
257
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
258
+		);
259
+	}
260
+
261
+	/**
262
+	 * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
263
+	 *
264
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
265
+	 *
266
+	 * @param string $message
267
+	 * @param string $ad
268
+	 * @param string $nonce
269
+	 * @param string $key
270
+	 * @return string
271
+	 * @throws SodiumException
272
+	 * @throws TypeError
273
+	 */
274
+	public static function aead_chacha20poly1305_ietf_encrypt(
275
+		$message = '',
276
+		$ad = '',
277
+		$nonce = '',
278
+		$key = ''
279
+	) {
280
+		/** @var int $len - Length of the plaintext message */
281
+		$len = ParagonIE_Sodium_Core32_Util::strlen($message);
282
+
283
+		/** @var int $adlen - Length of the associated data */
284
+		$adlen = ParagonIE_Sodium_Core32_Util::strlen($ad);
285
+
286
+		/** @var string The first block of the chacha20 keystream, used as a poly1305 key */
287
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::ietfStream(
288
+			32,
289
+			$nonce,
290
+			$key
291
+		);
292
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State($block0);
293
+		try {
294
+			ParagonIE_Sodium_Compat::memzero($block0);
295
+		} catch (SodiumException $ex) {
296
+			$block0 = null;
297
+		}
298
+
299
+		/** @var string $ciphertext - Raw encrypted data */
300
+		$ciphertext = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
301
+			$message,
302
+			$nonce,
303
+			$key,
304
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
305
+		);
306
+
307
+		$state->update($ad);
308
+		$state->update(str_repeat("\x00", ((0x10 - $adlen) & 0xf)));
309
+		$state->update($ciphertext);
310
+		$state->update(str_repeat("\x00", ((0x10 - $len) & 0xf)));
311
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($adlen));
312
+		$state->update(ParagonIE_Sodium_Core32_Util::store64_le($len));
313
+		return $ciphertext . $state->finish();
314
+	}
315
+
316
+	/**
317
+	 * AEAD Decryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
318
+	 *
319
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
320
+	 *
321
+	 * @param string $message
322
+	 * @param string $ad
323
+	 * @param string $nonce
324
+	 * @param string $key
325
+	 * @return string
326
+	 * @throws SodiumException
327
+	 * @throws TypeError
328
+	 */
329
+	public static function aead_xchacha20poly1305_ietf_decrypt(
330
+		$message = '',
331
+		$ad = '',
332
+		$nonce = '',
333
+		$key = ''
334
+	) {
335
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
336
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
337
+			$key
338
+		);
339
+		$nonceLast = "\x00\x00\x00\x00" .
340
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
341
+
342
+		return self::aead_chacha20poly1305_ietf_decrypt($message, $ad, $nonceLast, $subkey);
343
+	}
344
+
345
+	/**
346
+	 * AEAD Encryption with ChaCha20-Poly1305, IETF mode (96-bit nonce)
347
+	 *
348
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
349
+	 *
350
+	 * @param string $message
351
+	 * @param string $ad
352
+	 * @param string $nonce
353
+	 * @param string $key
354
+	 * @return string
355
+	 * @throws SodiumException
356
+	 * @throws TypeError
357
+	 */
358
+	public static function aead_xchacha20poly1305_ietf_encrypt(
359
+		$message = '',
360
+		$ad = '',
361
+		$nonce = '',
362
+		$key = ''
363
+	) {
364
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
365
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
366
+			$key
367
+		);
368
+		$nonceLast = "\x00\x00\x00\x00" .
369
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
370
+
371
+		return self::aead_chacha20poly1305_ietf_encrypt($message, $ad, $nonceLast, $subkey);
372
+	}
373
+
374
+	/**
375
+	 * HMAC-SHA-512-256 (a.k.a. the leftmost 256 bits of HMAC-SHA-512)
376
+	 *
377
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
378
+	 *
379
+	 * @param string $message
380
+	 * @param string $key
381
+	 * @return string
382
+	 * @throws TypeError
383
+	 */
384
+	public static function auth($message, $key)
385
+	{
386
+		return ParagonIE_Sodium_Core32_Util::substr(
387
+			hash_hmac('sha512', $message, $key, true),
388
+			0,
389
+			32
390
+		);
391
+	}
392
+
393
+	/**
394
+	 * HMAC-SHA-512-256 validation. Constant-time via hash_equals().
395
+	 *
396
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
397
+	 *
398
+	 * @param string $mac
399
+	 * @param string $message
400
+	 * @param string $key
401
+	 * @return bool
402
+	 * @throws SodiumException
403
+	 * @throws TypeError
404
+	 */
405
+	public static function auth_verify($mac, $message, $key)
406
+	{
407
+		return ParagonIE_Sodium_Core32_Util::hashEquals(
408
+			$mac,
409
+			self::auth($message, $key)
410
+		);
411
+	}
412
+
413
+	/**
414
+	 * X25519 key exchange followed by XSalsa20Poly1305 symmetric encryption
415
+	 *
416
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
417
+	 *
418
+	 * @param string $plaintext
419
+	 * @param string $nonce
420
+	 * @param string $keypair
421
+	 * @return string
422
+	 * @throws SodiumException
423
+	 * @throws TypeError
424
+	 */
425
+	public static function box($plaintext, $nonce, $keypair)
426
+	{
427
+		return self::secretbox(
428
+			$plaintext,
429
+			$nonce,
430
+			self::box_beforenm(
431
+				self::box_secretkey($keypair),
432
+				self::box_publickey($keypair)
433
+			)
434
+		);
435
+	}
436
+
437
+	/**
438
+	 * X25519-XSalsa20-Poly1305 with one ephemeral X25519 keypair.
439
+	 *
440
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
441
+	 *
442
+	 * @param string $message
443
+	 * @param string $publicKey
444
+	 * @return string
445
+	 * @throws SodiumException
446
+	 * @throws TypeError
447
+	 */
448
+	public static function box_seal($message, $publicKey)
449
+	{
450
+		/** @var string $ephemeralKeypair */
451
+		$ephemeralKeypair = self::box_keypair();
452
+
453
+		/** @var string $ephemeralSK */
454
+		$ephemeralSK = self::box_secretkey($ephemeralKeypair);
455
+
456
+		/** @var string $ephemeralPK */
457
+		$ephemeralPK = self::box_publickey($ephemeralKeypair);
458
+
459
+		/** @var string $nonce */
460
+		$nonce = self::generichash(
461
+			$ephemeralPK . $publicKey,
462
+			'',
463
+			24
464
+		);
465
+
466
+		/** @var string $keypair - The combined keypair used in crypto_box() */
467
+		$keypair = self::box_keypair_from_secretkey_and_publickey($ephemeralSK, $publicKey);
468
+
469
+		/** @var string $ciphertext Ciphertext + MAC from crypto_box */
470
+		$ciphertext = self::box($message, $nonce, $keypair);
471
+		try {
472
+			ParagonIE_Sodium_Compat::memzero($ephemeralKeypair);
473
+			ParagonIE_Sodium_Compat::memzero($ephemeralSK);
474
+			ParagonIE_Sodium_Compat::memzero($nonce);
475
+		} catch (SodiumException $ex) {
476
+			$ephemeralKeypair = null;
477
+			$ephemeralSK = null;
478
+			$nonce = null;
479
+		}
480
+		return $ephemeralPK . $ciphertext;
481
+	}
482
+
483
+	/**
484
+	 * Opens a message encrypted via box_seal().
485
+	 *
486
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
487
+	 *
488
+	 * @param string $message
489
+	 * @param string $keypair
490
+	 * @return string
491
+	 * @throws SodiumException
492
+	 * @throws TypeError
493
+	 */
494
+	public static function box_seal_open($message, $keypair)
495
+	{
496
+		/** @var string $ephemeralPK */
497
+		$ephemeralPK = ParagonIE_Sodium_Core32_Util::substr($message, 0, 32);
498
+
499
+		/** @var string $ciphertext (ciphertext + MAC) */
500
+		$ciphertext = ParagonIE_Sodium_Core32_Util::substr($message, 32);
501
+
502
+		/** @var string $secretKey */
503
+		$secretKey = self::box_secretkey($keypair);
504
+
505
+		/** @var string $publicKey */
506
+		$publicKey = self::box_publickey($keypair);
507
+
508
+		/** @var string $nonce */
509
+		$nonce = self::generichash(
510
+			$ephemeralPK . $publicKey,
511
+			'',
512
+			24
513
+		);
514
+
515
+		/** @var string $keypair */
516
+		$keypair = self::box_keypair_from_secretkey_and_publickey($secretKey, $ephemeralPK);
517
+
518
+		/** @var string $m */
519
+		$m = self::box_open($ciphertext, $nonce, $keypair);
520
+		try {
521
+			ParagonIE_Sodium_Compat::memzero($secretKey);
522
+			ParagonIE_Sodium_Compat::memzero($ephemeralPK);
523
+			ParagonIE_Sodium_Compat::memzero($nonce);
524
+		} catch (SodiumException $ex) {
525
+			$secretKey = null;
526
+			$ephemeralPK = null;
527
+			$nonce = null;
528
+		}
529
+		return $m;
530
+	}
531
+
532
+	/**
533
+	 * Used by crypto_box() to get the crypto_secretbox() key.
534
+	 *
535
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
536
+	 *
537
+	 * @param string $sk
538
+	 * @param string $pk
539
+	 * @return string
540
+	 * @throws SodiumException
541
+	 * @throws TypeError
542
+	 */
543
+	public static function box_beforenm($sk, $pk)
544
+	{
545
+		return ParagonIE_Sodium_Core32_HSalsa20::hsalsa20(
546
+			str_repeat("\x00", 16),
547
+			self::scalarmult($sk, $pk)
548
+		);
549
+	}
550
+
551
+	/**
552
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
553
+	 *
554
+	 * @return string
555
+	 * @throws Exception
556
+	 * @throws SodiumException
557
+	 * @throws TypeError
558
+	 */
559
+	public static function box_keypair()
560
+	{
561
+		$sKey = random_bytes(32);
562
+		$pKey = self::scalarmult_base($sKey);
563
+		return $sKey . $pKey;
564
+	}
565
+
566
+	/**
567
+	 * @param string $seed
568
+	 * @return string
569
+	 * @throws SodiumException
570
+	 * @throws TypeError
571
+	 */
572
+	public static function box_seed_keypair($seed)
573
+	{
574
+		$sKey = ParagonIE_Sodium_Core32_Util::substr(
575
+			hash('sha512', $seed, true),
576
+			0,
577
+			32
578
+		);
579
+		$pKey = self::scalarmult_base($sKey);
580
+		return $sKey . $pKey;
581
+	}
582
+
583
+	/**
584
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
585
+	 *
586
+	 * @param string $sKey
587
+	 * @param string $pKey
588
+	 * @return string
589
+	 * @throws TypeError
590
+	 */
591
+	public static function box_keypair_from_secretkey_and_publickey($sKey, $pKey)
592
+	{
593
+		return ParagonIE_Sodium_Core32_Util::substr($sKey, 0, 32) .
594
+			ParagonIE_Sodium_Core32_Util::substr($pKey, 0, 32);
595
+	}
596
+
597
+	/**
598
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
599
+	 *
600
+	 * @param string $keypair
601
+	 * @return string
602
+	 * @throws RangeException
603
+	 * @throws TypeError
604
+	 */
605
+	public static function box_secretkey($keypair)
606
+	{
607
+		if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== 64) {
608
+			throw new RangeException(
609
+				'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
610
+			);
611
+		}
612
+		return ParagonIE_Sodium_Core32_Util::substr($keypair, 0, 32);
613
+	}
614
+
615
+	/**
616
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
617
+	 *
618
+	 * @param string $keypair
619
+	 * @return string
620
+	 * @throws RangeException
621
+	 * @throws TypeError
622
+	 */
623
+	public static function box_publickey($keypair)
624
+	{
625
+		if (ParagonIE_Sodium_Core32_Util::strlen($keypair) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES) {
626
+			throw new RangeException(
627
+				'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_KEYPAIRBYTES bytes long.'
628
+			);
629
+		}
630
+		return ParagonIE_Sodium_Core32_Util::substr($keypair, 32, 32);
631
+	}
632
+
633
+	/**
634
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
635
+	 *
636
+	 * @param string $sKey
637
+	 * @return string
638
+	 * @throws RangeException
639
+	 * @throws SodiumException
640
+	 * @throws TypeError
641
+	 */
642
+	public static function box_publickey_from_secretkey($sKey)
643
+	{
644
+		if (ParagonIE_Sodium_Core32_Util::strlen($sKey) !== ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES) {
645
+			throw new RangeException(
646
+				'Must be ParagonIE_Sodium_Compat::CRYPTO_BOX_SECRETKEYBYTES bytes long.'
647
+			);
648
+		}
649
+		return self::scalarmult_base($sKey);
650
+	}
651
+
652
+	/**
653
+	 * Decrypt a message encrypted with box().
654
+	 *
655
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
656
+	 *
657
+	 * @param string $ciphertext
658
+	 * @param string $nonce
659
+	 * @param string $keypair
660
+	 * @return string
661
+	 * @throws SodiumException
662
+	 * @throws TypeError
663
+	 */
664
+	public static function box_open($ciphertext, $nonce, $keypair)
665
+	{
666
+		return self::secretbox_open(
667
+			$ciphertext,
668
+			$nonce,
669
+			self::box_beforenm(
670
+				self::box_secretkey($keypair),
671
+				self::box_publickey($keypair)
672
+			)
673
+		);
674
+	}
675
+
676
+	/**
677
+	 * Calculate a BLAKE2b hash.
678
+	 *
679
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
680
+	 *
681
+	 * @param string $message
682
+	 * @param string|null $key
683
+	 * @param int $outlen
684
+	 * @return string
685
+	 * @throws RangeException
686
+	 * @throws SodiumException
687
+	 * @throws TypeError
688
+	 */
689
+	public static function generichash($message, $key = '', $outlen = 32)
690
+	{
691
+		// This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
692
+		ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
693
+
694
+		$k = null;
695
+		if (!empty($key)) {
696
+			/** @var SplFixedArray $k */
697
+			$k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
698
+			if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
699
+				throw new RangeException('Invalid key size');
700
+			}
701
+		}
702
+
703
+		/** @var SplFixedArray $in */
704
+		$in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($message);
705
+
706
+		/** @var SplFixedArray $ctx */
707
+		$ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outlen);
708
+		ParagonIE_Sodium_Core32_BLAKE2b::update($ctx, $in, $in->count());
709
+
710
+		/** @var SplFixedArray $out */
711
+		$out = new SplFixedArray($outlen);
712
+		$out = ParagonIE_Sodium_Core32_BLAKE2b::finish($ctx, $out);
713
+
714
+		/** @var array<int, int> */
715
+		$outArray = $out->toArray();
716
+		return ParagonIE_Sodium_Core32_Util::intArrayToString($outArray);
717
+	}
718
+
719
+	/**
720
+	 * Finalize a BLAKE2b hashing context, returning the hash.
721
+	 *
722
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
723
+	 *
724
+	 * @param string $ctx
725
+	 * @param int $outlen
726
+	 * @return string
727
+	 * @throws SodiumException
728
+	 * @throws TypeError
729
+	 */
730
+	public static function generichash_final($ctx, $outlen = 32)
731
+	{
732
+		if (!is_string($ctx)) {
733
+			throw new TypeError('Context must be a string');
734
+		}
735
+		$out = new SplFixedArray($outlen);
736
+
737
+		/** @var SplFixedArray $context */
738
+		$context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext($ctx);
739
+
740
+		/** @var SplFixedArray $out */
741
+		$out = ParagonIE_Sodium_Core32_BLAKE2b::finish($context, $out);
742
+
743
+		/** @var array<int, int> */
744
+		$outArray = $out->toArray();
745
+		return ParagonIE_Sodium_Core32_Util::intArrayToString($outArray);
746
+	}
747
+
748
+	/**
749
+	 * Initialize a hashing context for BLAKE2b.
750
+	 *
751
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
752
+	 *
753
+	 * @param string $key
754
+	 * @param int $outputLength
755
+	 * @return string
756
+	 * @throws RangeException
757
+	 * @throws SodiumException
758
+	 * @throws TypeError
759
+	 */
760
+	public static function generichash_init($key = '', $outputLength = 32)
761
+	{
762
+		// This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
763
+		ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
764
+
765
+		$k = null;
766
+		if (!empty($key)) {
767
+			$k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
768
+			if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
769
+				throw new RangeException('Invalid key size');
770
+			}
771
+		}
772
+
773
+		/** @var SplFixedArray $ctx */
774
+		$ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outputLength);
775
+
776
+		return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($ctx);
777
+	}
778
+
779
+	/**
780
+	 * Initialize a hashing context for BLAKE2b.
781
+	 *
782
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
783
+	 *
784
+	 * @param string $key
785
+	 * @param int $outputLength
786
+	 * @param string $salt
787
+	 * @param string $personal
788
+	 * @return string
789
+	 * @throws RangeException
790
+	 * @throws SodiumException
791
+	 * @throws TypeError
792
+	 */
793
+	public static function generichash_init_salt_personal(
794
+		$key = '',
795
+		$outputLength = 32,
796
+		$salt = '',
797
+		$personal = ''
798
+	) {
799
+		// This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
800
+		ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
801
+
802
+		$k = null;
803
+		if (!empty($key)) {
804
+			$k = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($key);
805
+			if ($k->count() > ParagonIE_Sodium_Core32_BLAKE2b::KEYBYTES) {
806
+				throw new RangeException('Invalid key size');
807
+			}
808
+		}
809
+		if (!empty($salt)) {
810
+			$s = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($salt);
811
+		} else {
812
+			$s = null;
813
+		}
814
+		if (!empty($salt)) {
815
+			$p = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($personal);
816
+		} else {
817
+			$p = null;
818
+		}
819
+
820
+		/** @var SplFixedArray $ctx */
821
+		$ctx = ParagonIE_Sodium_Core32_BLAKE2b::init($k, $outputLength, $s, $p);
822
+
823
+		return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($ctx);
824
+	}
825
+
826
+	/**
827
+	 * Update a hashing context for BLAKE2b with $message
828
+	 *
829
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
830
+	 *
831
+	 * @param string $ctx
832
+	 * @param string $message
833
+	 * @return string
834
+	 * @throws SodiumException
835
+	 * @throws TypeError
836
+	 */
837
+	public static function generichash_update($ctx, $message)
838
+	{
839
+		// This ensures that ParagonIE_Sodium_Core32_BLAKE2b::$iv is initialized
840
+		ParagonIE_Sodium_Core32_BLAKE2b::pseudoConstructor();
841
+
842
+		/** @var SplFixedArray $context */
843
+		$context = ParagonIE_Sodium_Core32_BLAKE2b::stringToContext($ctx);
844
+
845
+		/** @var SplFixedArray $in */
846
+		$in = ParagonIE_Sodium_Core32_BLAKE2b::stringToSplFixedArray($message);
847
+
848
+		ParagonIE_Sodium_Core32_BLAKE2b::update($context, $in, $in->count());
849
+
850
+		return ParagonIE_Sodium_Core32_BLAKE2b::contextToString($context);
851
+	}
852
+
853
+	/**
854
+	 * Libsodium's crypto_kx().
855
+	 *
856
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
857
+	 *
858
+	 * @param string $my_sk
859
+	 * @param string $their_pk
860
+	 * @param string $client_pk
861
+	 * @param string $server_pk
862
+	 * @return string
863
+	 * @throws SodiumException
864
+	 * @throws TypeError
865
+	 */
866
+	public static function keyExchange($my_sk, $their_pk, $client_pk, $server_pk)
867
+	{
868
+		return self::generichash(
869
+			self::scalarmult($my_sk, $their_pk) .
870
+			$client_pk .
871
+			$server_pk
872
+		);
873
+	}
874
+
875
+	/**
876
+	 * ECDH over Curve25519
877
+	 *
878
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
879
+	 *
880
+	 * @param string $sKey
881
+	 * @param string $pKey
882
+	 * @return string
883
+	 *
884
+	 * @throws SodiumException
885
+	 * @throws TypeError
886
+	 */
887
+	public static function scalarmult($sKey, $pKey)
888
+	{
889
+		$q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10($sKey, $pKey);
890
+		self::scalarmult_throw_if_zero($q);
891
+		return $q;
892
+	}
893
+
894
+	/**
895
+	 * ECDH over Curve25519, using the basepoint.
896
+	 * Used to get a secret key from a public key.
897
+	 *
898
+	 * @param string $secret
899
+	 * @return string
900
+	 *
901
+	 * @throws SodiumException
902
+	 * @throws TypeError
903
+	 */
904
+	public static function scalarmult_base($secret)
905
+	{
906
+		$q = ParagonIE_Sodium_Core32_X25519::crypto_scalarmult_curve25519_ref10_base($secret);
907
+		self::scalarmult_throw_if_zero($q);
908
+		return $q;
909
+	}
910
+
911
+	/**
912
+	 * This throws an Error if a zero public key was passed to the function.
913
+	 *
914
+	 * @param string $q
915
+	 * @return void
916
+	 * @throws SodiumException
917
+	 * @throws TypeError
918
+	 */
919
+	protected static function scalarmult_throw_if_zero($q)
920
+	{
921
+		$d = 0;
922
+		for ($i = 0; $i < self::box_curve25519xsalsa20poly1305_SECRETKEYBYTES; ++$i) {
923
+			$d |= ParagonIE_Sodium_Core32_Util::chrToInt($q[$i]);
924
+		}
925
+
926
+		/* branch-free variant of === 0 */
927
+		if (-(1 & (($d - 1) >> 8))) {
928
+			throw new SodiumException('Zero public key is not allowed');
929
+		}
930
+	}
931
+
932
+	/**
933
+	 * XSalsa20-Poly1305 authenticated symmetric-key encryption.
934
+	 *
935
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
936
+	 *
937
+	 * @param string $plaintext
938
+	 * @param string $nonce
939
+	 * @param string $key
940
+	 * @return string
941
+	 * @throws SodiumException
942
+	 * @throws TypeError
943
+	 */
944
+	public static function secretbox($plaintext, $nonce, $key)
945
+	{
946
+		/** @var string $subkey */
947
+		$subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
948
+
949
+		/** @var string $block0 */
950
+		$block0 = str_repeat("\x00", 32);
951
+
952
+		/** @var int $mlen - Length of the plaintext message */
953
+		$mlen = ParagonIE_Sodium_Core32_Util::strlen($plaintext);
954
+		$mlen0 = $mlen;
955
+		if ($mlen0 > 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES) {
956
+			$mlen0 = 64 - self::secretbox_xsalsa20poly1305_ZEROBYTES;
957
+		}
958
+		$block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
959
+
960
+		/** @var string $block0 */
961
+		$block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20_xor(
962
+			$block0,
963
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
964
+			$subkey
965
+		);
966
+
967
+		/** @var string $c */
968
+		$c = ParagonIE_Sodium_Core32_Util::substr(
969
+			$block0,
970
+			self::secretbox_xsalsa20poly1305_ZEROBYTES
971
+		);
972
+		if ($mlen > $mlen0) {
973
+			$c .= ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
974
+				ParagonIE_Sodium_Core32_Util::substr(
975
+					$plaintext,
976
+					self::secretbox_xsalsa20poly1305_ZEROBYTES
977
+				),
978
+				ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
979
+				1,
980
+				$subkey
981
+			);
982
+		}
983
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State(
984
+			ParagonIE_Sodium_Core32_Util::substr(
985
+				$block0,
986
+				0,
987
+				self::onetimeauth_poly1305_KEYBYTES
988
+			)
989
+		);
990
+		try {
991
+			ParagonIE_Sodium_Compat::memzero($block0);
992
+			ParagonIE_Sodium_Compat::memzero($subkey);
993
+		} catch (SodiumException $ex) {
994
+			$block0 = null;
995
+			$subkey = null;
996
+		}
997
+
998
+		$state->update($c);
999
+
1000
+		/** @var string $c - MAC || ciphertext */
1001
+		$c = $state->finish() . $c;
1002
+		unset($state);
1003
+
1004
+		return $c;
1005
+	}
1006
+
1007
+	/**
1008
+	 * Decrypt a ciphertext generated via secretbox().
1009
+	 *
1010
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1011
+	 *
1012
+	 * @param string $ciphertext
1013
+	 * @param string $nonce
1014
+	 * @param string $key
1015
+	 * @return string
1016
+	 * @throws SodiumException
1017
+	 * @throws TypeError
1018
+	 */
1019
+	public static function secretbox_open($ciphertext, $nonce, $key)
1020
+	{
1021
+		/** @var string $mac */
1022
+		$mac = ParagonIE_Sodium_Core32_Util::substr(
1023
+			$ciphertext,
1024
+			0,
1025
+			self::secretbox_xsalsa20poly1305_MACBYTES
1026
+		);
1027
+
1028
+		/** @var string $c */
1029
+		$c = ParagonIE_Sodium_Core32_Util::substr(
1030
+			$ciphertext,
1031
+			self::secretbox_xsalsa20poly1305_MACBYTES
1032
+		);
1033
+
1034
+		/** @var int $clen */
1035
+		$clen = ParagonIE_Sodium_Core32_Util::strlen($c);
1036
+
1037
+		/** @var string $subkey */
1038
+		$subkey = ParagonIE_Sodium_Core32_HSalsa20::hsalsa20($nonce, $key);
1039
+
1040
+		/** @var string $block0 */
1041
+		$block0 = ParagonIE_Sodium_Core32_Salsa20::salsa20(
1042
+			64,
1043
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1044
+			$subkey
1045
+		);
1046
+		$verified = ParagonIE_Sodium_Core32_Poly1305::onetimeauth_verify(
1047
+			$mac,
1048
+			$c,
1049
+			ParagonIE_Sodium_Core32_Util::substr($block0, 0, 32)
1050
+		);
1051
+		if (!$verified) {
1052
+			try {
1053
+				ParagonIE_Sodium_Compat::memzero($subkey);
1054
+			} catch (SodiumException $ex) {
1055
+				$subkey = null;
1056
+			}
1057
+			throw new SodiumException('Invalid MAC');
1058
+		}
1059
+
1060
+		/** @var string $m - Decrypted message */
1061
+		$m = ParagonIE_Sodium_Core32_Util::xorStrings(
1062
+			ParagonIE_Sodium_Core32_Util::substr($block0, self::secretbox_xsalsa20poly1305_ZEROBYTES),
1063
+			ParagonIE_Sodium_Core32_Util::substr($c, 0, self::secretbox_xsalsa20poly1305_ZEROBYTES)
1064
+		);
1065
+		if ($clen > self::secretbox_xsalsa20poly1305_ZEROBYTES) {
1066
+			// We had more than 1 block, so let's continue to decrypt the rest.
1067
+			$m .= ParagonIE_Sodium_Core32_Salsa20::salsa20_xor_ic(
1068
+				ParagonIE_Sodium_Core32_Util::substr(
1069
+					$c,
1070
+					self::secretbox_xsalsa20poly1305_ZEROBYTES
1071
+				),
1072
+				ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1073
+				1,
1074
+				(string) $subkey
1075
+			);
1076
+		}
1077
+		return $m;
1078
+	}
1079
+
1080
+	/**
1081
+	 * XChaCha20-Poly1305 authenticated symmetric-key encryption.
1082
+	 *
1083
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1084
+	 *
1085
+	 * @param string $plaintext
1086
+	 * @param string $nonce
1087
+	 * @param string $key
1088
+	 * @return string
1089
+	 * @throws SodiumException
1090
+	 * @throws TypeError
1091
+	 */
1092
+	public static function secretbox_xchacha20poly1305($plaintext, $nonce, $key)
1093
+	{
1094
+		/** @var string $subkey */
1095
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1096
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 0, 16),
1097
+			$key
1098
+		);
1099
+		$nonceLast = ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8);
1100
+
1101
+		/** @var string $block0 */
1102
+		$block0 = str_repeat("\x00", 32);
1103
+
1104
+		/** @var int $mlen - Length of the plaintext message */
1105
+		$mlen = ParagonIE_Sodium_Core32_Util::strlen($plaintext);
1106
+		$mlen0 = $mlen;
1107
+		if ($mlen0 > 64 - self::secretbox_xchacha20poly1305_ZEROBYTES) {
1108
+			$mlen0 = 64 - self::secretbox_xchacha20poly1305_ZEROBYTES;
1109
+		}
1110
+		$block0 .= ParagonIE_Sodium_Core32_Util::substr($plaintext, 0, $mlen0);
1111
+
1112
+		/** @var string $block0 */
1113
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1114
+			$block0,
1115
+			$nonceLast,
1116
+			$subkey
1117
+		);
1118
+
1119
+		/** @var string $c */
1120
+		$c = ParagonIE_Sodium_Core32_Util::substr(
1121
+			$block0,
1122
+			self::secretbox_xchacha20poly1305_ZEROBYTES
1123
+		);
1124
+		if ($mlen > $mlen0) {
1125
+			$c .= ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1126
+				ParagonIE_Sodium_Core32_Util::substr(
1127
+					$plaintext,
1128
+					self::secretbox_xchacha20poly1305_ZEROBYTES
1129
+				),
1130
+				$nonceLast,
1131
+				$subkey,
1132
+				ParagonIE_Sodium_Core32_Util::store64_le(1)
1133
+			);
1134
+		}
1135
+		$state = new ParagonIE_Sodium_Core32_Poly1305_State(
1136
+			ParagonIE_Sodium_Core32_Util::substr(
1137
+				$block0,
1138
+				0,
1139
+				self::onetimeauth_poly1305_KEYBYTES
1140
+			)
1141
+		);
1142
+		try {
1143
+			ParagonIE_Sodium_Compat::memzero($block0);
1144
+			ParagonIE_Sodium_Compat::memzero($subkey);
1145
+		} catch (SodiumException $ex) {
1146
+			$block0 = null;
1147
+			$subkey = null;
1148
+		}
1149
+
1150
+		$state->update($c);
1151
+
1152
+		/** @var string $c - MAC || ciphertext */
1153
+		$c = $state->finish() . $c;
1154
+		unset($state);
1155
+
1156
+		return $c;
1157
+	}
1158
+
1159
+	/**
1160
+	 * Decrypt a ciphertext generated via secretbox_xchacha20poly1305().
1161
+	 *
1162
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1163
+	 *
1164
+	 * @param string $ciphertext
1165
+	 * @param string $nonce
1166
+	 * @param string $key
1167
+	 * @return string
1168
+	 * @throws SodiumException
1169
+	 * @throws TypeError
1170
+	 */
1171
+	public static function secretbox_xchacha20poly1305_open($ciphertext, $nonce, $key)
1172
+	{
1173
+		/** @var string $mac */
1174
+		$mac = ParagonIE_Sodium_Core32_Util::substr(
1175
+			$ciphertext,
1176
+			0,
1177
+			self::secretbox_xchacha20poly1305_MACBYTES
1178
+		);
1179
+
1180
+		/** @var string $c */
1181
+		$c = ParagonIE_Sodium_Core32_Util::substr(
1182
+			$ciphertext,
1183
+			self::secretbox_xchacha20poly1305_MACBYTES
1184
+		);
1185
+
1186
+		/** @var int $clen */
1187
+		$clen = ParagonIE_Sodium_Core32_Util::strlen($c);
1188
+
1189
+		/** @var string $subkey */
1190
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hchacha20($nonce, $key);
1191
+
1192
+		/** @var string $block0 */
1193
+		$block0 = ParagonIE_Sodium_Core32_ChaCha20::stream(
1194
+			64,
1195
+			ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1196
+			$subkey
1197
+		);
1198
+		$verified = ParagonIE_Sodium_Core32_Poly1305::onetimeauth_verify(
1199
+			$mac,
1200
+			$c,
1201
+			ParagonIE_Sodium_Core32_Util::substr($block0, 0, 32)
1202
+		);
1203
+
1204
+		if (!$verified) {
1205
+			try {
1206
+				ParagonIE_Sodium_Compat::memzero($subkey);
1207
+			} catch (SodiumException $ex) {
1208
+				$subkey = null;
1209
+			}
1210
+			throw new SodiumException('Invalid MAC');
1211
+		}
1212
+
1213
+		/** @var string $m - Decrypted message */
1214
+		$m = ParagonIE_Sodium_Core32_Util::xorStrings(
1215
+			ParagonIE_Sodium_Core32_Util::substr($block0, self::secretbox_xchacha20poly1305_ZEROBYTES),
1216
+			ParagonIE_Sodium_Core32_Util::substr($c, 0, self::secretbox_xchacha20poly1305_ZEROBYTES)
1217
+		);
1218
+
1219
+		if ($clen > self::secretbox_xchacha20poly1305_ZEROBYTES) {
1220
+			// We had more than 1 block, so let's continue to decrypt the rest.
1221
+			$m .= ParagonIE_Sodium_Core32_ChaCha20::streamXorIc(
1222
+				ParagonIE_Sodium_Core32_Util::substr(
1223
+					$c,
1224
+					self::secretbox_xchacha20poly1305_ZEROBYTES
1225
+				),
1226
+				ParagonIE_Sodium_Core32_Util::substr($nonce, 16, 8),
1227
+				(string) $subkey,
1228
+				ParagonIE_Sodium_Core32_Util::store64_le(1)
1229
+			);
1230
+		}
1231
+		return $m;
1232
+	}
1233
+
1234
+	/**
1235
+	 * @param string $key
1236
+	 * @return array<int, string> Returns a state and a header.
1237
+	 * @throws Exception
1238
+	 * @throws SodiumException
1239
+	 */
1240
+	public static function secretstream_xchacha20poly1305_init_push($key)
1241
+	{
1242
+		# randombytes_buf(out, crypto_secretstream_xchacha20poly1305_HEADERBYTES);
1243
+		$out = random_bytes(24);
1244
+
1245
+		# crypto_core_hchacha20(state->k, out, k, NULL);
1246
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20($out, $key);
1247
+		$state = new ParagonIE_Sodium_Core32_SecretStream_State(
1248
+			$subkey,
1249
+			ParagonIE_Sodium_Core32_Util::substr($out, 16, 8) . str_repeat("\0", 4)
1250
+		);
1251
+
1252
+		# _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1253
+		$state->counterReset();
1254
+
1255
+		# memcpy(STATE_INONCE(state), out + crypto_core_hchacha20_INPUTBYTES,
1256
+		#        crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1257
+		# memset(state->_pad, 0, sizeof state->_pad);
1258
+		return array(
1259
+			$state->toString(),
1260
+			$out
1261
+		);
1262
+	}
1263
+
1264
+	/**
1265
+	 * @param string $key
1266
+	 * @param string $header
1267
+	 * @return string Returns a state.
1268
+	 * @throws Exception
1269
+	 */
1270
+	public static function secretstream_xchacha20poly1305_init_pull($key, $header)
1271
+	{
1272
+		# crypto_core_hchacha20(state->k, in, k, NULL);
1273
+		$subkey = ParagonIE_Sodium_Core32_HChaCha20::hChaCha20(
1274
+			ParagonIE_Sodium_Core32_Util::substr($header, 0, 16),
1275
+			$key
1276
+		);
1277
+		$state = new ParagonIE_Sodium_Core32_SecretStream_State(
1278
+			$subkey,
1279
+			ParagonIE_Sodium_Core32_Util::substr($header, 16)
1280
+		);
1281
+		$state->counterReset();
1282
+		# memcpy(STATE_INONCE(state), in + crypto_core_hchacha20_INPUTBYTES,
1283
+		#     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1284
+		# memset(state->_pad, 0, sizeof state->_pad);
1285
+		# return 0;
1286
+		return $state->toString();
1287
+	}
1288
+
1289
+	/**
1290
+	 * @param string $state
1291
+	 * @param string $msg
1292
+	 * @param string $aad
1293
+	 * @param int $tag
1294
+	 * @return string
1295
+	 * @throws SodiumException
1296
+	 */
1297
+	public static function secretstream_xchacha20poly1305_push(&$state, $msg, $aad = '', $tag = 0)
1298
+	{
1299
+		$st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1300
+		# crypto_onetimeauth_poly1305_state poly1305_state;
1301
+		# unsigned char                     block[64U];
1302
+		# unsigned char                     slen[8U];
1303
+		# unsigned char                    *c;
1304
+		# unsigned char                    *mac;
1305
+
1306
+		$msglen = ParagonIE_Sodium_Core32_Util::strlen($msg);
1307
+		$aadlen = ParagonIE_Sodium_Core32_Util::strlen($aad);
1308
+
1309
+		if ((($msglen + 63) >> 6) > 0xfffffffe) {
1310
+			throw new SodiumException(
1311
+				'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1312
+			);
1313
+		}
1314
+
1315
+		# if (outlen_p != NULL) {
1316
+		#     *outlen_p = 0U;
1317
+		# }
1318
+		# if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1319
+		#     sodium_misuse();
1320
+		# }
1321
+
1322
+		# crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1323
+		# crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1324
+		# sodium_memzero(block, sizeof block);
1325
+		$auth = new ParagonIE_Sodium_Core32_Poly1305_State(
1326
+			ParagonIE_Sodium_Core32_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1327
+		);
1328
+
1329
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1330
+		$auth->update($aad);
1331
+
1332
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1333
+		#     (0x10 - adlen) & 0xf);
1334
+		$auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1335
+
1336
+		# memset(block, 0, sizeof block);
1337
+		# block[0] = tag;
1338
+		# crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1339
+		#                                    state->nonce, 1U, state->k);
1340
+		$block = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1341
+			ParagonIE_Sodium_Core32_Util::intToChr($tag) . str_repeat("\0", 63),
1342
+			$st->getCombinedNonce(),
1343
+			$st->getKey(),
1344
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
1345
+		);
1346
+
1347
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1348
+		$auth->update($block);
1349
+
1350
+		# out[0] = block[0];
1351
+		$out = $block[0];
1352
+		# c = out + (sizeof tag);
1353
+		# crypto_stream_chacha20_ietf_xor_ic(c, m, mlen, state->nonce, 2U, state->k);
1354
+		$cipher = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1355
+			$msg,
1356
+			$st->getCombinedNonce(),
1357
+			$st->getKey(),
1358
+			ParagonIE_Sodium_Core32_Util::store64_le(2)
1359
+		);
1360
+
1361
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1362
+		$auth->update($cipher);
1363
+
1364
+		$out .= $cipher;
1365
+		unset($cipher);
1366
+
1367
+		# crypto_onetimeauth_poly1305_update
1368
+		# (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1369
+		$auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1370
+
1371
+		# STORE64_LE(slen, (uint64_t) adlen);
1372
+		$slen = ParagonIE_Sodium_Core32_Util::store64_le($aadlen);
1373
+
1374
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1375
+		$auth->update($slen);
1376
+
1377
+		# STORE64_LE(slen, (sizeof block) + mlen);
1378
+		$slen = ParagonIE_Sodium_Core32_Util::store64_le(64 + $msglen);
1379
+
1380
+		# crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1381
+		$auth->update($slen);
1382
+
1383
+		# mac = c + mlen;
1384
+		# crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1385
+		$mac = $auth->finish();
1386
+		$out .= $mac;
1387
+
1388
+		# sodium_memzero(&poly1305_state, sizeof poly1305_state);
1389
+		unset($auth);
1390
+
1391
+
1392
+		# XOR_BUF(STATE_INONCE(state), mac,
1393
+		#     crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1394
+		$st->xorNonce($mac);
1395
+
1396
+		# sodium_increment(STATE_COUNTER(state),
1397
+		#     crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1398
+		$st->incrementCounter();
1399
+		// Overwrite by reference:
1400
+		$state = $st->toString();
1401
+
1402
+		/** @var bool $rekey */
1403
+		$rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1404
+		# if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1405
+		#     sodium_is_zero(STATE_COUNTER(state),
1406
+		#         crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1407
+		#     crypto_secretstream_xchacha20poly1305_rekey(state);
1408
+		# }
1409
+		if ($rekey || $st->needsRekey()) {
1410
+			// DO REKEY
1411
+			self::secretstream_xchacha20poly1305_rekey($state);
1412
+		}
1413
+		# if (outlen_p != NULL) {
1414
+		#     *outlen_p = crypto_secretstream_xchacha20poly1305_ABYTES + mlen;
1415
+		# }
1416
+		return $out;
1417
+	}
1418
+
1419
+	/**
1420
+	 * @param string $state
1421
+	 * @param string $cipher
1422
+	 * @param string $aad
1423
+	 * @return bool|array{0: string, 1: int}
1424
+	 * @throws SodiumException
1425
+	 */
1426
+	public static function secretstream_xchacha20poly1305_pull(&$state, $cipher, $aad = '')
1427
+	{
1428
+		$st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1429
+
1430
+		$cipherlen = ParagonIE_Sodium_Core32_Util::strlen($cipher);
1431
+		#     mlen = inlen - crypto_secretstream_xchacha20poly1305_ABYTES;
1432
+		$msglen = $cipherlen - ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_ABYTES;
1433
+		$aadlen = ParagonIE_Sodium_Core32_Util::strlen($aad);
1434
+
1435
+		#     if (mlen > crypto_secretstream_xchacha20poly1305_MESSAGEBYTES_MAX) {
1436
+		#         sodium_misuse();
1437
+		#     }
1438
+		if ((($msglen + 63) >> 6) > 0xfffffffe) {
1439
+			throw new SodiumException(
1440
+				'message cannot be larger than SODIUM_CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_MESSAGEBYTES_MAX bytes'
1441
+			);
1442
+		}
1443
+
1444
+		#     crypto_stream_chacha20_ietf(block, sizeof block, state->nonce, state->k);
1445
+		#     crypto_onetimeauth_poly1305_init(&poly1305_state, block);
1446
+		#     sodium_memzero(block, sizeof block);
1447
+		$auth = new ParagonIE_Sodium_Core32_Poly1305_State(
1448
+			ParagonIE_Sodium_Core32_ChaCha20::ietfStream(32, $st->getCombinedNonce(), $st->getKey())
1449
+		);
1450
+
1451
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, ad, adlen);
1452
+		$auth->update($aad);
1453
+
1454
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, _pad0,
1455
+		#         (0x10 - adlen) & 0xf);
1456
+		$auth->update(str_repeat("\0", ((0x10 - $aadlen) & 0xf)));
1457
+
1458
+
1459
+		#     memset(block, 0, sizeof block);
1460
+		#     block[0] = in[0];
1461
+		#     crypto_stream_chacha20_ietf_xor_ic(block, block, sizeof block,
1462
+		#                                        state->nonce, 1U, state->k);
1463
+		$block = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1464
+			$cipher[0] . str_repeat("\0", 63),
1465
+			$st->getCombinedNonce(),
1466
+			$st->getKey(),
1467
+			ParagonIE_Sodium_Core32_Util::store64_le(1)
1468
+		);
1469
+		#     tag = block[0];
1470
+		#     block[0] = in[0];
1471
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, block, sizeof block);
1472
+		$tag = ParagonIE_Sodium_Core32_Util::chrToInt($block[0]);
1473
+		$block[0] = $cipher[0];
1474
+		$auth->update($block);
1475
+
1476
+
1477
+		#     c = in + (sizeof tag);
1478
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, c, mlen);
1479
+		$auth->update(ParagonIE_Sodium_Core32_Util::substr($cipher, 1, $msglen));
1480
+
1481
+		#     crypto_onetimeauth_poly1305_update
1482
+		#     (&poly1305_state, _pad0, (0x10 - (sizeof block) + mlen) & 0xf);
1483
+		$auth->update(str_repeat("\0", ((0x10 - 64 + $msglen) & 0xf)));
1484
+
1485
+		#     STORE64_LE(slen, (uint64_t) adlen);
1486
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1487
+		$slen = ParagonIE_Sodium_Core32_Util::store64_le($aadlen);
1488
+		$auth->update($slen);
1489
+
1490
+		#     STORE64_LE(slen, (sizeof block) + mlen);
1491
+		#     crypto_onetimeauth_poly1305_update(&poly1305_state, slen, sizeof slen);
1492
+		$slen = ParagonIE_Sodium_Core32_Util::store64_le(64 + $msglen);
1493
+		$auth->update($slen);
1494
+
1495
+		#     crypto_onetimeauth_poly1305_final(&poly1305_state, mac);
1496
+		#     sodium_memzero(&poly1305_state, sizeof poly1305_state);
1497
+		$mac = $auth->finish();
1498
+
1499
+		#     stored_mac = c + mlen;
1500
+		#     if (sodium_memcmp(mac, stored_mac, sizeof mac) != 0) {
1501
+		#     sodium_memzero(mac, sizeof mac);
1502
+		#         return -1;
1503
+		#     }
1504
+
1505
+		$stored = ParagonIE_Sodium_Core32_Util::substr($cipher, $msglen + 1, 16);
1506
+		if (!ParagonIE_Sodium_Core32_Util::hashEquals($mac, $stored)) {
1507
+			return false;
1508
+		}
1509
+
1510
+		#     crypto_stream_chacha20_ietf_xor_ic(m, c, mlen, state->nonce, 2U, state->k);
1511
+		$out = ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1512
+			ParagonIE_Sodium_Core32_Util::substr($cipher, 1, $msglen),
1513
+			$st->getCombinedNonce(),
1514
+			$st->getKey(),
1515
+			ParagonIE_Sodium_Core32_Util::store64_le(2)
1516
+		);
1517
+
1518
+		#     XOR_BUF(STATE_INONCE(state), mac,
1519
+		#         crypto_secretstream_xchacha20poly1305_INONCEBYTES);
1520
+		$st->xorNonce($mac);
1521
+
1522
+		#     sodium_increment(STATE_COUNTER(state),
1523
+		#         crypto_secretstream_xchacha20poly1305_COUNTERBYTES);
1524
+		$st->incrementCounter();
1525
+
1526
+		#     if ((tag & crypto_secretstream_xchacha20poly1305_TAG_REKEY) != 0 ||
1527
+		#         sodium_is_zero(STATE_COUNTER(state),
1528
+		#             crypto_secretstream_xchacha20poly1305_COUNTERBYTES)) {
1529
+		#         crypto_secretstream_xchacha20poly1305_rekey(state);
1530
+		#     }
1531
+
1532
+		// Overwrite by reference:
1533
+		$state = $st->toString();
1534
+
1535
+		/** @var bool $rekey */
1536
+		$rekey = ($tag & ParagonIE_Sodium_Compat::CRYPTO_SECRETSTREAM_XCHACHA20POLY1305_TAG_REKEY) !== 0;
1537
+		if ($rekey || $st->needsRekey()) {
1538
+			// DO REKEY
1539
+			self::secretstream_xchacha20poly1305_rekey($state);
1540
+		}
1541
+		return array($out, $tag);
1542
+	}
1543
+
1544
+	/**
1545
+	 * @param string $state
1546
+	 * @return void
1547
+	 * @throws SodiumException
1548
+	 */
1549
+	public static function secretstream_xchacha20poly1305_rekey(&$state)
1550
+	{
1551
+		$st = ParagonIE_Sodium_Core32_SecretStream_State::fromString($state);
1552
+		# unsigned char new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES +
1553
+		# crypto_secretstream_xchacha20poly1305_INONCEBYTES];
1554
+		# size_t        i;
1555
+		# for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1556
+		#     new_key_and_inonce[i] = state->k[i];
1557
+		# }
1558
+		$new_key_and_inonce = $st->getKey();
1559
+
1560
+		# for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1561
+		#     new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i] =
1562
+		#         STATE_INONCE(state)[i];
1563
+		# }
1564
+		$new_key_and_inonce .= ParagonIE_Sodium_Core32_Util::substR($st->getNonce(), 0, 8);
1565
+
1566
+		# crypto_stream_chacha20_ietf_xor(new_key_and_inonce, new_key_and_inonce,
1567
+		#                                 sizeof new_key_and_inonce,
1568
+		#                                 state->nonce, state->k);
1569
+
1570
+		$st->rekey(ParagonIE_Sodium_Core32_ChaCha20::ietfStreamXorIc(
1571
+			$new_key_and_inonce,
1572
+			$st->getCombinedNonce(),
1573
+			$st->getKey(),
1574
+			ParagonIE_Sodium_Core32_Util::store64_le(0)
1575
+		));
1576
+
1577
+		# for (i = 0U; i < crypto_stream_chacha20_ietf_KEYBYTES; i++) {
1578
+		#     state->k[i] = new_key_and_inonce[i];
1579
+		# }
1580
+		# for (i = 0U; i < crypto_secretstream_xchacha20poly1305_INONCEBYTES; i++) {
1581
+		#     STATE_INONCE(state)[i] =
1582
+		#          new_key_and_inonce[crypto_stream_chacha20_ietf_KEYBYTES + i];
1583
+		# }
1584
+		# _crypto_secretstream_xchacha20poly1305_counter_reset(state);
1585
+		$st->counterReset();
1586
+
1587
+		$state = $st->toString();
1588
+	}
1589
+
1590
+	/**
1591
+	 * Detached Ed25519 signature.
1592
+	 *
1593
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1594
+	 *
1595
+	 * @param string $message
1596
+	 * @param string $sk
1597
+	 * @return string
1598
+	 * @throws SodiumException
1599
+	 * @throws TypeError
1600
+	 */
1601
+	public static function sign_detached($message, $sk)
1602
+	{
1603
+		return ParagonIE_Sodium_Core32_Ed25519::sign_detached($message, $sk);
1604
+	}
1605
+
1606
+	/**
1607
+	 * Attached Ed25519 signature. (Returns a signed message.)
1608
+	 *
1609
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1610
+	 *
1611
+	 * @param string $message
1612
+	 * @param string $sk
1613
+	 * @return string
1614
+	 * @throws SodiumException
1615
+	 * @throws TypeError
1616
+	 */
1617
+	public static function sign($message, $sk)
1618
+	{
1619
+		return ParagonIE_Sodium_Core32_Ed25519::sign($message, $sk);
1620
+	}
1621
+
1622
+	/**
1623
+	 * Opens a signed message. If valid, returns the message.
1624
+	 *
1625
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1626
+	 *
1627
+	 * @param string $signedMessage
1628
+	 * @param string $pk
1629
+	 * @return string
1630
+	 * @throws SodiumException
1631
+	 * @throws TypeError
1632
+	 */
1633
+	public static function sign_open($signedMessage, $pk)
1634
+	{
1635
+		return ParagonIE_Sodium_Core32_Ed25519::sign_open($signedMessage, $pk);
1636
+	}
1637
+
1638
+	/**
1639
+	 * Verify a detached signature of a given message and public key.
1640
+	 *
1641
+	 * @internal Do not use this directly. Use ParagonIE_Sodium_Compat.
1642
+	 *
1643
+	 * @param string $signature
1644
+	 * @param string $message
1645
+	 * @param string $pk
1646
+	 * @return bool
1647
+	 * @throws SodiumException
1648
+	 * @throws TypeError
1649
+	 */
1650
+	public static function sign_verify_detached($signature, $message, $pk)
1651
+	{
1652
+		return ParagonIE_Sodium_Core32_Ed25519::verify_detached($signature, $message, $pk);
1653
+	}
1654 1654
 }
Please login to merge, or discard this patch.
vendor/paragonie/sodium_compat/src/Core/BLAKE2b.php 1 patch
Indentation   +773 added lines, -773 removed lines patch added patch discarded remove patch
@@ -1,7 +1,7 @@  discard block
 block discarded – undo
1 1
 <?php
2 2
 
3 3
 if (class_exists('ParagonIE_Sodium_Core_BLAKE2b', false)) {
4
-    return;
4
+	return;
5 5
 }
6 6
 
7 7
 /**
@@ -11,780 +11,780 @@  discard block
 block discarded – undo
11 11
  */
12 12
 abstract class ParagonIE_Sodium_Core_BLAKE2b extends ParagonIE_Sodium_Core_Util
13 13
 {
14
-    /**
15
-     * @var SplFixedArray
16
-     */
17
-    protected static $iv;
18
-
19
-    /**
20
-     * @var array<int, array<int, int>>
21
-     */
22
-    protected static $sigma = array(
23
-        array(  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14, 15),
24
-        array( 14, 10,  4,  8,  9, 15, 13,  6,  1, 12,  0,  2, 11,  7,  5,  3),
25
-        array( 11,  8, 12,  0,  5,  2, 15, 13, 10, 14,  3,  6,  7,  1,  9,  4),
26
-        array(  7,  9,  3,  1, 13, 12, 11, 14,  2,  6,  5, 10,  4,  0, 15,  8),
27
-        array(  9,  0,  5,  7,  2,  4, 10, 15, 14,  1, 11, 12,  6,  8,  3, 13),
28
-        array(  2, 12,  6, 10,  0, 11,  8,  3,  4, 13,  7,  5, 15, 14,  1,  9),
29
-        array( 12,  5,  1, 15, 14, 13,  4, 10,  0,  7,  6,  3,  9,  2,  8, 11),
30
-        array( 13, 11,  7, 14, 12,  1,  3,  9,  5,  0, 15,  4,  8,  6,  2, 10),
31
-        array(  6, 15, 14,  9, 11,  3,  0,  8, 12,  2, 13,  7,  1,  4, 10,  5),
32
-        array( 10,  2,  8,  4,  7,  6,  1,  5, 15, 11,  9, 14,  3, 12, 13 , 0),
33
-        array(  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14, 15),
34
-        array( 14, 10,  4,  8,  9, 15, 13,  6,  1, 12,  0,  2, 11,  7,  5,  3)
35
-    );
36
-
37
-    const BLOCKBYTES = 128;
38
-    const OUTBYTES   = 64;
39
-    const KEYBYTES   = 64;
40
-
41
-    /**
42
-     * Turn two 32-bit integers into a fixed array representing a 64-bit integer.
43
-     *
44
-     * @internal You should not use this directly from another application
45
-     *
46
-     * @param int $high
47
-     * @param int $low
48
-     * @return SplFixedArray
49
-     * @psalm-suppress MixedAssignment
50
-     */
51
-    public static function new64($high, $low)
52
-    {
53
-        $i64 = new SplFixedArray(2);
54
-        $i64[0] = $high & 0xffffffff;
55
-        $i64[1] = $low & 0xffffffff;
56
-        return $i64;
57
-    }
58
-
59
-    /**
60
-     * Convert an arbitrary number into an SplFixedArray of two 32-bit integers
61
-     * that represents a 64-bit integer.
62
-     *
63
-     * @internal You should not use this directly from another application
64
-     *
65
-     * @param int $num
66
-     * @return SplFixedArray
67
-     */
68
-    protected static function to64($num)
69
-    {
70
-        list($hi, $lo) = self::numericTo64BitInteger($num);
71
-        return self::new64($hi, $lo);
72
-    }
73
-
74
-    /**
75
-     * Adds two 64-bit integers together, returning their sum as a SplFixedArray
76
-     * containing two 32-bit integers (representing a 64-bit integer).
77
-     *
78
-     * @internal You should not use this directly from another application
79
-     *
80
-     * @param SplFixedArray $x
81
-     * @param SplFixedArray $y
82
-     * @return SplFixedArray
83
-     * @psalm-suppress MixedArgument
84
-     * @psalm-suppress MixedAssignment
85
-     * @psalm-suppress MixedOperand
86
-     */
87
-    protected static function add64($x, $y)
88
-    {
89
-        $l = ($x[1] + $y[1]) & 0xffffffff;
90
-        return self::new64(
91
-            (int) ($x[0] + $y[0] + (
92
-                ($l < $x[1]) ? 1 : 0
93
-            )),
94
-            (int) $l
95
-        );
96
-    }
97
-
98
-    /**
99
-     * @internal You should not use this directly from another application
100
-     *
101
-     * @param SplFixedArray $x
102
-     * @param SplFixedArray $y
103
-     * @param SplFixedArray $z
104
-     * @return SplFixedArray
105
-     */
106
-    protected static function add364($x, $y, $z)
107
-    {
108
-        return self::add64($x, self::add64($y, $z));
109
-    }
110
-
111
-    /**
112
-     * @internal You should not use this directly from another application
113
-     *
114
-     * @param SplFixedArray $x
115
-     * @param SplFixedArray $y
116
-     * @return SplFixedArray
117
-     * @throws SodiumException
118
-     * @throws TypeError
119
-     */
120
-    protected static function xor64(SplFixedArray $x, SplFixedArray $y)
121
-    {
122
-        if (!is_numeric($x[0])) {
123
-            throw new SodiumException('x[0] is not an integer');
124
-        }
125
-        if (!is_numeric($x[1])) {
126
-            throw new SodiumException('x[1] is not an integer');
127
-        }
128
-        if (!is_numeric($y[0])) {
129
-            throw new SodiumException('y[0] is not an integer');
130
-        }
131
-        if (!is_numeric($y[1])) {
132
-            throw new SodiumException('y[1] is not an integer');
133
-        }
134
-        return self::new64(
135
-            (int) (($x[0] ^ $y[0]) & 0xffffffff),
136
-            (int) (($x[1] ^ $y[1]) & 0xffffffff)
137
-        );
138
-    }
139
-
140
-    /**
141
-     * @internal You should not use this directly from another application
142
-     *
143
-     * @param SplFixedArray $x
144
-     * @param int $c
145
-     * @return SplFixedArray
146
-     * @psalm-suppress MixedAssignment
147
-     */
148
-    public static function rotr64($x, $c)
149
-    {
150
-        if ($c >= 64) {
151
-            $c %= 64;
152
-        }
153
-        if ($c >= 32) {
154
-            /** @var int $tmp */
155
-            $tmp = $x[0];
156
-            $x[0] = $x[1];
157
-            $x[1] = $tmp;
158
-            $c -= 32;
159
-        }
160
-        if ($c === 0) {
161
-            return $x;
162
-        }
163
-
164
-        $l0 = 0;
165
-        $c = 64 - $c;
166
-
167
-        if ($c < 32) {
168
-            /** @var int $h0 */
169
-            $h0 = ((int) ($x[0]) << $c) | (
170
-                (
171
-                    (int) ($x[1]) & ((1 << $c) - 1)
172
-                        <<
173
-                    (32 - $c)
174
-                ) >> (32 - $c)
175
-            );
176
-            /** @var int $l0 */
177
-            $l0 = (int) ($x[1]) << $c;
178
-        } else {
179
-            /** @var int $h0 */
180
-            $h0 = (int) ($x[1]) << ($c - 32);
181
-        }
182
-
183
-        $h1 = 0;
184
-        $c1 = 64 - $c;
185
-
186
-        if ($c1 < 32) {
187
-            /** @var int $h1 */
188
-            $h1 = (int) ($x[0]) >> $c1;
189
-            /** @var int $l1 */
190
-            $l1 = ((int) ($x[1]) >> $c1) | ((int) ($x[0]) & ((1 << $c1) - 1)) << (32 - $c1);
191
-        } else {
192
-            /** @var int $l1 */
193
-            $l1 = (int) ($x[0]) >> ($c1 - 32);
194
-        }
195
-
196
-        return self::new64($h0 | $h1, $l0 | $l1);
197
-    }
198
-
199
-    /**
200
-     * @internal You should not use this directly from another application
201
-     *
202
-     * @param SplFixedArray $x
203
-     * @return int
204
-     * @psalm-suppress MixedOperand
205
-     */
206
-    protected static function flatten64($x)
207
-    {
208
-        return (int) ($x[0] * 4294967296 + $x[1]);
209
-    }
210
-
211
-    /**
212
-     * @internal You should not use this directly from another application
213
-     *
214
-     * @param SplFixedArray $x
215
-     * @param int $i
216
-     * @return SplFixedArray
217
-     * @psalm-suppress MixedArgument
218
-     * @psalm-suppress MixedArrayOffset
219
-     */
220
-    protected static function load64(SplFixedArray $x, $i)
221
-    {
222
-        /** @var int $l */
223
-        $l = (int) ($x[$i])
224
-             | ((int) ($x[$i+1]) << 8)
225
-             | ((int) ($x[$i+2]) << 16)
226
-             | ((int) ($x[$i+3]) << 24);
227
-        /** @var int $h */
228
-        $h = (int) ($x[$i+4])
229
-             | ((int) ($x[$i+5]) << 8)
230
-             | ((int) ($x[$i+6]) << 16)
231
-             | ((int) ($x[$i+7]) << 24);
232
-        return self::new64($h, $l);
233
-    }
234
-
235
-    /**
236
-     * @internal You should not use this directly from another application
237
-     *
238
-     * @param SplFixedArray $x
239
-     * @param int $i
240
-     * @param SplFixedArray $u
241
-     * @return void
242
-     * @psalm-suppress MixedAssignment
243
-     */
244
-    protected static function store64(SplFixedArray $x, $i, SplFixedArray $u)
245
-    {
246
-        $maxLength = $x->getSize() - 1;
247
-        for ($j = 0; $j < 8; ++$j) {
248
-            /*
14
+	/**
15
+	 * @var SplFixedArray
16
+	 */
17
+	protected static $iv;
18
+
19
+	/**
20
+	 * @var array<int, array<int, int>>
21
+	 */
22
+	protected static $sigma = array(
23
+		array(  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14, 15),
24
+		array( 14, 10,  4,  8,  9, 15, 13,  6,  1, 12,  0,  2, 11,  7,  5,  3),
25
+		array( 11,  8, 12,  0,  5,  2, 15, 13, 10, 14,  3,  6,  7,  1,  9,  4),
26
+		array(  7,  9,  3,  1, 13, 12, 11, 14,  2,  6,  5, 10,  4,  0, 15,  8),
27
+		array(  9,  0,  5,  7,  2,  4, 10, 15, 14,  1, 11, 12,  6,  8,  3, 13),
28
+		array(  2, 12,  6, 10,  0, 11,  8,  3,  4, 13,  7,  5, 15, 14,  1,  9),
29
+		array( 12,  5,  1, 15, 14, 13,  4, 10,  0,  7,  6,  3,  9,  2,  8, 11),
30
+		array( 13, 11,  7, 14, 12,  1,  3,  9,  5,  0, 15,  4,  8,  6,  2, 10),
31
+		array(  6, 15, 14,  9, 11,  3,  0,  8, 12,  2, 13,  7,  1,  4, 10,  5),
32
+		array( 10,  2,  8,  4,  7,  6,  1,  5, 15, 11,  9, 14,  3, 12, 13 , 0),
33
+		array(  0,  1,  2,  3,  4,  5,  6,  7,  8,  9, 10, 11, 12, 13, 14, 15),
34
+		array( 14, 10,  4,  8,  9, 15, 13,  6,  1, 12,  0,  2, 11,  7,  5,  3)
35
+	);
36
+
37
+	const BLOCKBYTES = 128;
38
+	const OUTBYTES   = 64;
39
+	const KEYBYTES   = 64;
40
+
41
+	/**
42
+	 * Turn two 32-bit integers into a fixed array representing a 64-bit integer.
43
+	 *
44
+	 * @internal You should not use this directly from another application
45
+	 *
46
+	 * @param int $high
47
+	 * @param int $low
48
+	 * @return SplFixedArray
49
+	 * @psalm-suppress MixedAssignment
50
+	 */
51
+	public static function new64($high, $low)
52
+	{
53
+		$i64 = new SplFixedArray(2);
54
+		$i64[0] = $high & 0xffffffff;
55
+		$i64[1] = $low & 0xffffffff;
56
+		return $i64;
57
+	}
58
+
59
+	/**
60
+	 * Convert an arbitrary number into an SplFixedArray of two 32-bit integers
61
+	 * that represents a 64-bit integer.
62
+	 *
63
+	 * @internal You should not use this directly from another application
64
+	 *
65
+	 * @param int $num
66
+	 * @return SplFixedArray
67
+	 */
68
+	protected static function to64($num)
69
+	{
70
+		list($hi, $lo) = self::numericTo64BitInteger($num);
71
+		return self::new64($hi, $lo);
72
+	}
73
+
74
+	/**
75
+	 * Adds two 64-bit integers together, returning their sum as a SplFixedArray
76
+	 * containing two 32-bit integers (representing a 64-bit integer).
77
+	 *
78
+	 * @internal You should not use this directly from another application
79
+	 *
80
+	 * @param SplFixedArray $x
81
+	 * @param SplFixedArray $y
82
+	 * @return SplFixedArray
83
+	 * @psalm-suppress MixedArgument
84
+	 * @psalm-suppress MixedAssignment
85
+	 * @psalm-suppress MixedOperand
86
+	 */
87
+	protected static function add64($x, $y)
88
+	{
89
+		$l = ($x[1] + $y[1]) & 0xffffffff;
90
+		return self::new64(
91
+			(int) ($x[0] + $y[0] + (
92
+				($l < $x[1]) ? 1 : 0
93
+			)),
94
+			(int) $l
95
+		);
96
+	}
97
+
98
+	/**
99
+	 * @internal You should not use this directly from another application
100
+	 *
101
+	 * @param SplFixedArray $x
102
+	 * @param SplFixedArray $y
103
+	 * @param SplFixedArray $z
104
+	 * @return SplFixedArray
105
+	 */
106
+	protected static function add364($x, $y, $z)
107
+	{
108
+		return self::add64($x, self::add64($y, $z));
109
+	}
110
+
111
+	/**
112
+	 * @internal You should not use this directly from another application
113
+	 *
114
+	 * @param SplFixedArray $x
115
+	 * @param SplFixedArray $y
116
+	 * @return SplFixedArray
117
+	 * @throws SodiumException
118
+	 * @throws TypeError
119
+	 */
120
+	protected static function xor64(SplFixedArray $x, SplFixedArray $y)
121
+	{
122
+		if (!is_numeric($x[0])) {
123
+			throw new SodiumException('x[0] is not an integer');
124
+		}
125
+		if (!is_numeric($x[1])) {
126
+			throw new SodiumException('x[1] is not an integer');
127
+		}
128
+		if (!is_numeric($y[0])) {
129
+			throw new SodiumException('y[0] is not an integer');
130
+		}
131
+		if (!is_numeric($y[1])) {
132
+			throw new SodiumException('y[1] is not an integer');
133
+		}
134
+		return self::new64(
135
+			(int) (($x[0] ^ $y[0]) & 0xffffffff),
136
+			(int) (($x[1] ^ $y[1]) & 0xffffffff)
137
+		);
138
+	}
139
+
140
+	/**
141
+	 * @internal You should not use this directly from another application
142
+	 *
143
+	 * @param SplFixedArray $x
144
+	 * @param int $c
145
+	 * @return SplFixedArray
146
+	 * @psalm-suppress MixedAssignment
147
+	 */
148
+	public static function rotr64($x, $c)
149
+	{
150
+		if ($c >= 64) {
151
+			$c %= 64;
152
+		}
153
+		if ($c >= 32) {
154
+			/** @var int $tmp */
155
+			$tmp = $x[0];
156
+			$x[0] = $x[1];
157
+			$x[1] = $tmp;
158
+			$c -= 32;
159
+		}
160
+		if ($c === 0) {
161
+			return $x;
162
+		}
163
+
164
+		$l0 = 0;
165
+		$c = 64 - $c;
166
+
167
+		if ($c < 32) {
168
+			/** @var int $h0 */
169
+			$h0 = ((int) ($x[0]) << $c) | (
170
+				(
171
+					(int) ($x[1]) & ((1 << $c) - 1)
172
+						<<
173
+					(32 - $c)
174
+				) >> (32 - $c)
175
+			);
176
+			/** @var int $l0 */
177
+			$l0 = (int) ($x[1]) << $c;
178
+		} else {
179
+			/** @var int $h0 */
180
+			$h0 = (int) ($x[1]) << ($c - 32);
181
+		}
182
+
183
+		$h1 = 0;
184
+		$c1 = 64 - $c;
185
+
186
+		if ($c1 < 32) {
187
+			/** @var int $h1 */
188
+			$h1 = (int) ($x[0]) >> $c1;
189
+			/** @var int $l1 */
190
+			$l1 = ((int) ($x[1]) >> $c1) | ((int) ($x[0]) & ((1 << $c1) - 1)) << (32 - $c1);
191
+		} else {
192
+			/** @var int $l1 */
193
+			$l1 = (int) ($x[0]) >> ($c1 - 32);
194
+		}
195
+
196
+		return self::new64($h0 | $h1, $l0 | $l1);
197
+	}
198
+
199
+	/**
200
+	 * @internal You should not use this directly from another application
201
+	 *
202
+	 * @param SplFixedArray $x
203
+	 * @return int
204
+	 * @psalm-suppress MixedOperand
205
+	 */
206
+	protected static function flatten64($x)
207
+	{
208
+		return (int) ($x[0] * 4294967296 + $x[1]);
209
+	}
210
+
211
+	/**
212
+	 * @internal You should not use this directly from another application
213
+	 *
214
+	 * @param SplFixedArray $x
215
+	 * @param int $i
216
+	 * @return SplFixedArray
217
+	 * @psalm-suppress MixedArgument
218
+	 * @psalm-suppress MixedArrayOffset
219
+	 */
220
+	protected static function load64(SplFixedArray $x, $i)
221
+	{
222
+		/** @var int $l */
223
+		$l = (int) ($x[$i])
224
+			 | ((int) ($x[$i+1]) << 8)
225
+			 | ((int) ($x[$i+2]) << 16)
226
+			 | ((int) ($x[$i+3]) << 24);
227
+		/** @var int $h */
228
+		$h = (int) ($x[$i+4])
229
+			 | ((int) ($x[$i+5]) << 8)
230
+			 | ((int) ($x[$i+6]) << 16)
231
+			 | ((int) ($x[$i+7]) << 24);
232
+		return self::new64($h, $l);
233
+	}
234
+
235
+	/**
236
+	 * @internal You should not use this directly from another application
237
+	 *
238
+	 * @param SplFixedArray $x
239
+	 * @param int $i
240
+	 * @param SplFixedArray $u
241
+	 * @return void
242
+	 * @psalm-suppress MixedAssignment
243
+	 */
244
+	protected static function store64(SplFixedArray $x, $i, SplFixedArray $u)
245
+	{
246
+		$maxLength = $x->getSize() - 1;
247
+		for ($j = 0; $j < 8; ++$j) {
248
+			/*
249 249
                [0, 1, 2, 3, 4, 5, 6, 7]
250 250
                     ... becomes ...
251 251
                [0, 0, 0, 0, 1, 1, 1, 1]
252 252
             */
253
-            /** @var int $uIdx */
254
-            $uIdx = ((7 - $j) & 4) >> 2;
255
-            $x[$i]   = ((int) ($u[$uIdx]) & 0xff);
256
-            if (++$i > $maxLength) {
257
-                return;
258
-            }
259
-            /** @psalm-suppress MixedOperand */
260
-            $u[$uIdx] >>= 8;
261
-        }
262
-    }
263
-
264
-    /**
265
-     * This just sets the $iv static variable.
266
-     *
267
-     * @internal You should not use this directly from another application
268
-     *
269
-     * @return void
270
-     */
271
-    public static function pseudoConstructor()
272
-    {
273
-        static $called = false;
274
-        if ($called) {
275
-            return;
276
-        }
277
-        self::$iv = new SplFixedArray(8);
278
-        self::$iv[0] = self::new64(0x6a09e667, 0xf3bcc908);
279
-        self::$iv[1] = self::new64(0xbb67ae85, 0x84caa73b);
280
-        self::$iv[2] = self::new64(0x3c6ef372, 0xfe94f82b);
281
-        self::$iv[3] = self::new64(0xa54ff53a, 0x5f1d36f1);
282
-        self::$iv[4] = self::new64(0x510e527f, 0xade682d1);
283
-        self::$iv[5] = self::new64(0x9b05688c, 0x2b3e6c1f);
284
-        self::$iv[6] = self::new64(0x1f83d9ab, 0xfb41bd6b);
285
-        self::$iv[7] = self::new64(0x5be0cd19, 0x137e2179);
286
-
287
-        $called = true;
288
-    }
289
-
290
-    /**
291
-     * Returns a fresh BLAKE2 context.
292
-     *
293
-     * @internal You should not use this directly from another application
294
-     *
295
-     * @return SplFixedArray
296
-     * @psalm-suppress MixedAssignment
297
-     * @psalm-suppress MixedArrayAccess
298
-     * @psalm-suppress MixedArrayAssignment
299
-     */
300
-    protected static function context()
301
-    {
302
-        $ctx    = new SplFixedArray(6);
303
-        $ctx[0] = new SplFixedArray(8);   // h
304
-        $ctx[1] = new SplFixedArray(2);   // t
305
-        $ctx[2] = new SplFixedArray(2);   // f
306
-        $ctx[3] = new SplFixedArray(256); // buf
307
-        $ctx[4] = 0;                      // buflen
308
-        $ctx[5] = 0;                      // last_node (uint8_t)
309
-
310
-        for ($i = 8; $i--;) {
311
-            $ctx[0][$i] = self::$iv[$i];
312
-        }
313
-        for ($i = 256; $i--;) {
314
-            $ctx[3][$i] = 0;
315
-        }
316
-
317
-        $zero = self::new64(0, 0);
318
-        $ctx[1][0] = $zero;
319
-        $ctx[1][1] = $zero;
320
-        $ctx[2][0] = $zero;
321
-        $ctx[2][1] = $zero;
322
-
323
-        return $ctx;
324
-    }
325
-
326
-    /**
327
-     * @internal You should not use this directly from another application
328
-     *
329
-     * @param SplFixedArray $ctx
330
-     * @param SplFixedArray $buf
331
-     * @return void
332
-     * @throws SodiumException
333
-     * @throws TypeError
334
-     * @psalm-suppress MixedArgument
335
-     * @psalm-suppress MixedAssignment
336
-     * @psalm-suppress MixedArrayAccess
337
-     * @psalm-suppress MixedArrayAssignment
338
-     * @psalm-suppress MixedArrayOffset
339
-     */
340
-    protected static function compress(SplFixedArray $ctx, SplFixedArray $buf)
341
-    {
342
-        $m = new SplFixedArray(16);
343
-        $v = new SplFixedArray(16);
344
-
345
-        for ($i = 16; $i--;) {
346
-            $m[$i] = self::load64($buf, $i << 3);
347
-        }
348
-
349
-        for ($i = 8; $i--;) {
350
-            $v[$i] = $ctx[0][$i];
351
-        }
352
-
353
-        $v[ 8] = self::$iv[0];
354
-        $v[ 9] = self::$iv[1];
355
-        $v[10] = self::$iv[2];
356
-        $v[11] = self::$iv[3];
357
-
358
-        $v[12] = self::xor64($ctx[1][0], self::$iv[4]);
359
-        $v[13] = self::xor64($ctx[1][1], self::$iv[5]);
360
-        $v[14] = self::xor64($ctx[2][0], self::$iv[6]);
361
-        $v[15] = self::xor64($ctx[2][1], self::$iv[7]);
362
-
363
-        for ($r = 0; $r < 12; ++$r) {
364
-            $v = self::G($r, 0, 0, 4, 8, 12, $v, $m);
365
-            $v = self::G($r, 1, 1, 5, 9, 13, $v, $m);
366
-            $v = self::G($r, 2, 2, 6, 10, 14, $v, $m);
367
-            $v = self::G($r, 3, 3, 7, 11, 15, $v, $m);
368
-            $v = self::G($r, 4, 0, 5, 10, 15, $v, $m);
369
-            $v = self::G($r, 5, 1, 6, 11, 12, $v, $m);
370
-            $v = self::G($r, 6, 2, 7, 8, 13, $v, $m);
371
-            $v = self::G($r, 7, 3, 4, 9, 14, $v, $m);
372
-        }
373
-
374
-        for ($i = 8; $i--;) {
375
-            $ctx[0][$i] = self::xor64(
376
-                $ctx[0][$i], self::xor64($v[$i], $v[$i+8])
377
-            );
378
-        }
379
-    }
380
-
381
-    /**
382
-     * @internal You should not use this directly from another application
383
-     *
384
-     * @param int $r
385
-     * @param int $i
386
-     * @param int $a
387
-     * @param int $b
388
-     * @param int $c
389
-     * @param int $d
390
-     * @param SplFixedArray $v
391
-     * @param SplFixedArray $m
392
-     * @return SplFixedArray
393
-     * @throws SodiumException
394
-     * @throws TypeError
395
-     * @psalm-suppress MixedArgument
396
-     * @psalm-suppress MixedArrayOffset
397
-     */
398
-    public static function G($r, $i, $a, $b, $c, $d, SplFixedArray $v, SplFixedArray $m)
399
-    {
400
-        $v[$a] = self::add364($v[$a], $v[$b], $m[self::$sigma[$r][$i << 1]]);
401
-        $v[$d] = self::rotr64(self::xor64($v[$d], $v[$a]), 32);
402
-        $v[$c] = self::add64($v[$c], $v[$d]);
403
-        $v[$b] = self::rotr64(self::xor64($v[$b], $v[$c]), 24);
404
-        $v[$a] = self::add364($v[$a], $v[$b], $m[self::$sigma[$r][($i << 1) + 1]]);
405
-        $v[$d] = self::rotr64(self::xor64($v[$d], $v[$a]), 16);
406
-        $v[$c] = self::add64($v[$c], $v[$d]);
407
-        $v[$b] = self::rotr64(self::xor64($v[$b], $v[$c]), 63);
408
-        return $v;
409
-    }
410
-
411
-    /**
412
-     * @internal You should not use this directly from another application
413
-     *
414
-     * @param SplFixedArray $ctx
415
-     * @param int $inc
416
-     * @return void
417
-     * @throws SodiumException
418
-     * @psalm-suppress MixedArgument
419
-     * @psalm-suppress MixedArrayAccess
420
-     * @psalm-suppress MixedArrayAssignment
421
-     */
422
-    public static function increment_counter($ctx, $inc)
423
-    {
424
-        if ($inc < 0) {
425
-            throw new SodiumException('Increasing by a negative number makes no sense.');
426
-        }
427
-        $t = self::to64($inc);
428
-        # S->t is $ctx[1] in our implementation
429
-
430
-        # S->t[0] = ( uint64_t )( t >> 0 );
431
-        $ctx[1][0] = self::add64($ctx[1][0], $t);
432
-
433
-        # S->t[1] += ( S->t[0] < inc );
434
-        if (self::flatten64($ctx[1][0]) < $inc) {
435
-            $ctx[1][1] = self::add64($ctx[1][1], self::to64(1));
436
-        }
437
-    }
438
-
439
-    /**
440
-     * @internal You should not use this directly from another application
441
-     *
442
-     * @param SplFixedArray $ctx
443
-     * @param SplFixedArray $p
444
-     * @param int $plen
445
-     * @return void
446
-     * @throws SodiumException
447
-     * @throws TypeError
448
-     * @psalm-suppress MixedArgument
449
-     * @psalm-suppress MixedAssignment
450
-     * @psalm-suppress MixedArrayAccess
451
-     * @psalm-suppress MixedArrayAssignment
452
-     * @psalm-suppress MixedArrayOffset
453
-     * @psalm-suppress MixedOperand
454
-     */
455
-    public static function update(SplFixedArray $ctx, SplFixedArray $p, $plen)
456
-    {
457
-        self::pseudoConstructor();
458
-
459
-        $offset = 0;
460
-        while ($plen > 0) {
461
-            $left = $ctx[4];
462
-            $fill = 256 - $left;
463
-
464
-            if ($plen > $fill) {
465
-                # memcpy( S->buf + left, in, fill ); /* Fill buffer */
466
-                for ($i = $fill; $i--;) {
467
-                    $ctx[3][$i + $left] = $p[$i + $offset];
468
-                }
469
-
470
-                # S->buflen += fill;
471
-                $ctx[4] += $fill;
472
-
473
-                # blake2b_increment_counter( S, BLAKE2B_BLOCKBYTES );
474
-                self::increment_counter($ctx, 128);
475
-
476
-                # blake2b_compress( S, S->buf ); /* Compress */
477
-                self::compress($ctx, $ctx[3]);
478
-
479
-                # memcpy( S->buf, S->buf + BLAKE2B_BLOCKBYTES, BLAKE2B_BLOCKBYTES ); /* Shift buffer left */
480
-                for ($i = 128; $i--;) {
481
-                    $ctx[3][$i] = $ctx[3][$i + 128];
482
-                }
483
-
484
-                # S->buflen -= BLAKE2B_BLOCKBYTES;
485
-                $ctx[4] -= 128;
486
-
487
-                # in += fill;
488
-                $offset += $fill;
489
-
490
-                # inlen -= fill;
491
-                $plen -= $fill;
492
-            } else {
493
-                for ($i = $plen; $i--;) {
494
-                    $ctx[3][$i + $left] = $p[$i + $offset];
495
-                }
496
-                $ctx[4] += $plen;
497
-                $offset += $plen;
498
-                $plen -= $plen;
499
-            }
500
-        }
501
-    }
502
-
503
-    /**
504
-     * @internal You should not use this directly from another application
505
-     *
506
-     * @param SplFixedArray $ctx
507
-     * @param SplFixedArray $out
508
-     * @return SplFixedArray
509
-     * @throws SodiumException
510
-     * @throws TypeError
511
-     * @psalm-suppress MixedArgument
512
-     * @psalm-suppress MixedAssignment
513
-     * @psalm-suppress MixedArrayAccess
514
-     * @psalm-suppress MixedArrayAssignment
515
-     * @psalm-suppress MixedArrayOffset
516
-     * @psalm-suppress MixedOperand
517
-     */
518
-    public static function finish(SplFixedArray $ctx, SplFixedArray $out)
519
-    {
520
-        self::pseudoConstructor();
521
-        if ($ctx[4] > 128) {
522
-            self::increment_counter($ctx, 128);
523
-            self::compress($ctx, $ctx[3]);
524
-            $ctx[4] -= 128;
525
-            if ($ctx[4] > 128) {
526
-                throw new SodiumException('Failed to assert that buflen <= 128 bytes');
527
-            }
528
-            for ($i = $ctx[4]; $i--;) {
529
-                $ctx[3][$i] = $ctx[3][$i + 128];
530
-            }
531
-        }
532
-
533
-        self::increment_counter($ctx, $ctx[4]);
534
-        $ctx[2][0] = self::new64(0xffffffff, 0xffffffff);
535
-
536
-        for ($i = 256 - $ctx[4]; $i--;) {
537
-            $ctx[3][$i+$ctx[4]] = 0;
538
-        }
539
-
540
-        self::compress($ctx, $ctx[3]);
541
-
542
-        $i = (int) (($out->getSize() - 1) / 8);
543
-        for (; $i >= 0; --$i) {
544
-            self::store64($out, $i << 3, $ctx[0][$i]);
545
-        }
546
-        return $out;
547
-    }
548
-
549
-    /**
550
-     * @internal You should not use this directly from another application
551
-     *
552
-     * @param SplFixedArray|null $key
553
-     * @param int $outlen
554
-     * @param SplFixedArray|null $salt
555
-     * @param SplFixedArray|null $personal
556
-     * @return SplFixedArray
557
-     * @throws SodiumException
558
-     * @throws TypeError
559
-     * @psalm-suppress MixedArgument
560
-     * @psalm-suppress MixedAssignment
561
-     * @psalm-suppress MixedArrayAccess
562
-     * @psalm-suppress MixedArrayAssignment
563
-     * @psalm-suppress MixedArrayOffset
564
-     */
565
-    public static function init(
566
-        $key = null,
567
-        $outlen = 64,
568
-        $salt = null,
569
-        $personal = null
570
-    ) {
571
-        self::pseudoConstructor();
572
-        $klen = 0;
573
-
574
-        if ($key !== null) {
575
-            if (count($key) > 64) {
576
-                throw new SodiumException('Invalid key size');
577
-            }
578
-            $klen = count($key);
579
-        }
580
-
581
-        if ($outlen > 64) {
582
-            throw new SodiumException('Invalid output size');
583
-        }
584
-
585
-        $ctx = self::context();
586
-
587
-        $p = new SplFixedArray(64);
588
-        // Zero our param buffer...
589
-        for ($i = 64; --$i;) {
590
-            $p[$i] = 0;
591
-        }
592
-
593
-        $p[0] = $outlen; // digest_length
594
-        $p[1] = $klen;   // key_length
595
-        $p[2] = 1;       // fanout
596
-        $p[3] = 1;       // depth
597
-
598
-        if ($salt instanceof SplFixedArray) {
599
-            // salt: [32] through [47]
600
-            for ($i = 0; $i < 16; ++$i) {
601
-                $p[32 + $i] = (int) $salt[$i];
602
-            }
603
-        }
604
-        if ($personal instanceof SplFixedArray) {
605
-            // personal: [48] through [63]
606
-            for ($i = 0; $i < 16; ++$i) {
607
-                $p[48 + $i] = (int) $personal[$i];
608
-            }
609
-        }
610
-
611
-        $ctx[0][0] = self::xor64(
612
-            $ctx[0][0],
613
-            self::load64($p, 0)
614
-        );
615
-        if ($salt instanceof SplFixedArray || $personal instanceof SplFixedArray) {
616
-            // We need to do what blake2b_init_param() does:
617
-            for ($i = 1; $i < 8; ++$i) {
618
-                $ctx[0][$i] = self::xor64(
619
-                    $ctx[0][$i],
620
-                    self::load64($p, $i << 3)
621
-                );
622
-            }
623
-        }
624
-
625
-        if ($klen > 0 && $key instanceof SplFixedArray) {
626
-            $block = new SplFixedArray(128);
627
-            for ($i = 128; $i--;) {
628
-                $block[$i] = 0;
629
-            }
630
-            for ($i = $klen; $i--;) {
631
-                $block[$i] = $key[$i];
632
-            }
633
-            self::update($ctx, $block, 128);
634
-            $ctx[4] = 128;
635
-        }
636
-
637
-        return $ctx;
638
-    }
639
-
640
-    /**
641
-     * Convert a string into an SplFixedArray of integers
642
-     *
643
-     * @internal You should not use this directly from another application
644
-     *
645
-     * @param string $str
646
-     * @return SplFixedArray
647
-     * @psalm-suppress MixedArgumentTypeCoercion
648
-     */
649
-    public static function stringToSplFixedArray($str = '')
650
-    {
651
-        $values = unpack('C*', $str);
652
-        return SplFixedArray::fromArray(array_values($values));
653
-    }
654
-
655
-    /**
656
-     * Convert an SplFixedArray of integers into a string
657
-     *
658
-     * @internal You should not use this directly from another application
659
-     *
660
-     * @param SplFixedArray $a
661
-     * @return string
662
-     * @throws TypeError
663
-     */
664
-    public static function SplFixedArrayToString(SplFixedArray $a)
665
-    {
666
-        /**
667
-         * @var array<int, int|string> $arr
668
-         */
669
-        $arr = $a->toArray();
670
-        $c = $a->count();
671
-        array_unshift($arr, str_repeat('C', $c));
672
-        return (string) (call_user_func_array('pack', $arr));
673
-    }
674
-
675
-    /**
676
-     * @internal You should not use this directly from another application
677
-     *
678
-     * @param SplFixedArray $ctx
679
-     * @return string
680
-     * @throws TypeError
681
-     * @psalm-suppress MixedArgument
682
-     * @psalm-suppress MixedAssignment
683
-     * @psalm-suppress MixedArrayAccess
684
-     * @psalm-suppress MixedArrayAssignment
685
-     * @psalm-suppress MixedArrayOffset
686
-     * @psalm-suppress MixedMethodCall
687
-     */
688
-    public static function contextToString(SplFixedArray $ctx)
689
-    {
690
-        $str = '';
691
-        /** @var array<int, array<int, int>> $ctxA */
692
-        $ctxA = $ctx[0]->toArray();
693
-
694
-        # uint64_t h[8];
695
-        for ($i = 0; $i < 8; ++$i) {
696
-            $str .= self::store32_le($ctxA[$i][1]);
697
-            $str .= self::store32_le($ctxA[$i][0]);
698
-        }
699
-
700
-        # uint64_t t[2];
701
-        # uint64_t f[2];
702
-        for ($i = 1; $i < 3; ++$i) {
703
-            $ctxA = $ctx[$i]->toArray();
704
-            $str .= self::store32_le($ctxA[0][1]);
705
-            $str .= self::store32_le($ctxA[0][0]);
706
-            $str .= self::store32_le($ctxA[1][1]);
707
-            $str .= self::store32_le($ctxA[1][0]);
708
-        }
709
-
710
-        # uint8_t buf[2 * 128];
711
-        $str .= self::SplFixedArrayToString($ctx[3]);
712
-
713
-        /** @var int $ctx4 */
714
-        $ctx4 = (int) $ctx[4];
715
-
716
-        # size_t buflen;
717
-        $str .= implode('', array(
718
-            self::intToChr($ctx4 & 0xff),
719
-            self::intToChr(($ctx4 >> 8) & 0xff),
720
-            self::intToChr(($ctx4 >> 16) & 0xff),
721
-            self::intToChr(($ctx4 >> 24) & 0xff),
722
-            self::intToChr(($ctx4 >> 32) & 0xff),
723
-            self::intToChr(($ctx4 >> 40) & 0xff),
724
-            self::intToChr(($ctx4 >> 48) & 0xff),
725
-            self::intToChr(($ctx4 >> 56) & 0xff)
726
-        ));
727
-        # uint8_t last_node;
728
-        return $str . self::intToChr($ctx[5]) . str_repeat("\x00", 23);
729
-    }
730
-
731
-    /**
732
-     * Creates an SplFixedArray containing other SplFixedArray elements, from
733
-     * a string (compatible with \Sodium\crypto_generichash_{init, update, final})
734
-     *
735
-     * @internal You should not use this directly from another application
736
-     *
737
-     * @param string $string
738
-     * @return SplFixedArray
739
-     * @throws SodiumException
740
-     * @throws TypeError
741
-     * @psalm-suppress MixedArrayAssignment
742
-     */
743
-    public static function stringToContext($string)
744
-    {
745
-        $ctx = self::context();
746
-
747
-        # uint64_t h[8];
748
-        for ($i = 0; $i < 8; ++$i) {
749
-            $ctx[0][$i] = SplFixedArray::fromArray(
750
-                array(
751
-                    self::load_4(
752
-                        self::substr($string, (($i << 3) + 4), 4)
753
-                    ),
754
-                    self::load_4(
755
-                        self::substr($string, (($i << 3) + 0), 4)
756
-                    )
757
-                )
758
-            );
759
-        }
760
-
761
-        # uint64_t t[2];
762
-        # uint64_t f[2];
763
-        for ($i = 1; $i < 3; ++$i) {
764
-            $ctx[$i][1] = SplFixedArray::fromArray(
765
-                array(
766
-                    self::load_4(self::substr($string, 76 + (($i - 1) << 4), 4)),
767
-                    self::load_4(self::substr($string, 72 + (($i - 1) << 4), 4))
768
-                )
769
-            );
770
-            $ctx[$i][0] = SplFixedArray::fromArray(
771
-                array(
772
-                    self::load_4(self::substr($string, 68 + (($i - 1) << 4), 4)),
773
-                    self::load_4(self::substr($string, 64 + (($i - 1) << 4), 4))
774
-                )
775
-            );
776
-        }
777
-
778
-        # uint8_t buf[2 * 128];
779
-        $ctx[3] = self::stringToSplFixedArray(self::substr($string, 96, 256));
780
-
781
-        # uint8_t buf[2 * 128];
782
-        $int = 0;
783
-        for ($i = 0; $i < 8; ++$i) {
784
-            $int |= self::chrToInt($string[352 + $i]) << ($i << 3);
785
-        }
786
-        $ctx[4] = $int;
787
-
788
-        return $ctx;
789
-    }
253
+			/** @var int $uIdx */
254
+			$uIdx = ((7 - $j) & 4) >> 2;
255
+			$x[$i]   = ((int) ($u[$uIdx]) & 0xff);
256
+			if (++$i > $maxLength) {
257
+				return;
258
+			}
259
+			/** @psalm-suppress MixedOperand */
260
+			$u[$uIdx] >>= 8;
261
+		}
262
+	}
263
+
264
+	/**
265
+	 * This just sets the $iv static variable.
266
+	 *
267
+	 * @internal You should not use this directly from another application
268
+	 *
269
+	 * @return void
270
+	 */
271
+	public static function pseudoConstructor()
272
+	{
273
+		static $called = false;
274
+		if ($called) {
275
+			return;
276
+		}
277
+		self::$iv = new SplFixedArray(8);
278
+		self::$iv[0] = self::new64(0x6a09e667, 0xf3bcc908);
279
+		self::$iv[1] = self::new64(0xbb67ae85, 0x84caa73b);
280
+		self::$iv[2] = self::new64(0x3c6ef372, 0xfe94f82b);
281
+		self::$iv[3] = self::new64(0xa54ff53a, 0x5f1d36f1);
282
+		self::$iv[4] = self::new64(0x510e527f, 0xade682d1);
283
+		self::$iv[5] = self::new64(0x9b05688c, 0x2b3e6c1f);
284
+		self::$iv[6] = self::new64(0x1f83d9ab, 0xfb41bd6b);
285
+		self::$iv[7] = self::new64(0x5be0cd19, 0x137e2179);
286
+
287
+		$called = true;
288
+	}
289
+
290
+	/**
291
+	 * Returns a fresh BLAKE2 context.
292
+	 *
293
+	 * @internal You should not use this directly from another application
294
+	 *
295
+	 * @return SplFixedArray
296
+	 * @psalm-suppress MixedAssignment
297
+	 * @psalm-suppress MixedArrayAccess
298
+	 * @psalm-suppress MixedArrayAssignment
299
+	 */
300
+	protected static function context()
301
+	{
302
+		$ctx    = new SplFixedArray(6);
303
+		$ctx[0] = new SplFixedArray(8);   // h
304
+		$ctx[1] = new SplFixedArray(2);   // t
305
+		$ctx[2] = new SplFixedArray(2);   // f
306
+		$ctx[3] = new SplFixedArray(256); // buf
307
+		$ctx[4] = 0;                      // buflen
308
+		$ctx[5] = 0;                      // last_node (uint8_t)
309
+
310
+		for ($i = 8; $i--;) {
311
+			$ctx[0][$i] = self::$iv[$i];
312
+		}
313
+		for ($i = 256; $i--;) {
314
+			$ctx[3][$i] = 0;
315
+		}
316
+
317
+		$zero = self::new64(0, 0);
318
+		$ctx[1][0] = $zero;
319
+		$ctx[1][1] = $zero;
320
+		$ctx[2][0] = $zero;
321
+		$ctx[2][1] = $zero;
322
+
323
+		return $ctx;
324
+	}
325
+
326
+	/**
327
+	 * @internal You should not use this directly from another application
328
+	 *
329
+	 * @param SplFixedArray $ctx
330
+	 * @param SplFixedArray $buf
331
+	 * @return void
332
+	 * @throws SodiumException
333
+	 * @throws TypeError
334
+	 * @psalm-suppress MixedArgument
335
+	 * @psalm-suppress MixedAssignment
336
+	 * @psalm-suppress MixedArrayAccess
337
+	 * @psalm-suppress MixedArrayAssignment
338
+	 * @psalm-suppress MixedArrayOffset
339
+	 */
340
+	protected static function compress(SplFixedArray $ctx, SplFixedArray $buf)
341
+	{
342
+		$m = new SplFixedArray(16);
343
+		$v = new SplFixedArray(16);
344
+
345
+		for ($i = 16; $i--;) {
346
+			$m[$i] = self::load64($buf, $i << 3);
347
+		}
348
+
349
+		for ($i = 8; $i--;) {
350
+			$v[$i] = $ctx[0][$i];
351
+		}
352
+
353
+		$v[ 8] = self::$iv[0];
354
+		$v[ 9] = self::$iv[1];
355
+		$v[10] = self::$iv[2];
356
+		$v[11] = self::$iv[3];
357
+
358
+		$v[12] = self::xor64($ctx[1][0], self::$iv[4]);
359
+		$v[13] = self::xor64($ctx[1][1], self::$iv[5]);
360
+		$v[14] = self::xor64($ctx[2][0], self::$iv[6]);
361
+		$v[15] = self::xor64($ctx[2][1], self::$iv[7]);
362
+
363
+		for ($r = 0; $r < 12; ++$r) {
364
+			$v = self::G($r, 0, 0, 4, 8, 12, $v, $m);
365
+			$v = self::G($r, 1, 1, 5, 9, 13, $v, $m);
366
+			$v = self::G($r, 2, 2, 6, 10, 14, $v, $m);
367
+			$v = self::G($r, 3, 3, 7, 11, 15, $v, $m);
368
+			$v = self::G($r, 4, 0, 5, 10, 15, $v, $m);
369
+			$v = self::G($r, 5, 1, 6, 11, 12, $v, $m);
370
+			$v = self::G($r, 6, 2, 7, 8, 13, $v, $m);
371
+			$v = self::G($r, 7, 3, 4, 9, 14, $v, $m);
372
+		}
373
+
374
+		for ($i = 8; $i--;) {
375
+			$ctx[0][$i] = self::xor64(
376
+				$ctx[0][$i], self::xor64($v[$i], $v[$i+8])
377
+			);
378
+		}
379
+	}
380
+
381
+	/**
382
+	 * @internal You should not use this directly from another application
383
+	 *
384
+	 * @param int $r
385
+	 * @param int $i
386
+	 * @param int $a
387
+	 * @param int $b
388
+	 * @param int $c
389
+	 * @param int $d
390
+	 * @param SplFixedArray $v
391
+	 * @param SplFixedArray $m
392
+	 * @return SplFixedArray
393
+	 * @throws SodiumException
394
+	 * @throws TypeError
395
+	 * @psalm-suppress MixedArgument
396
+	 * @psalm-suppress MixedArrayOffset
397
+	 */
398
+	public static function G($r, $i, $a, $b, $c, $d, SplFixedArray $v, SplFixedArray $m)
399
+	{
400
+		$v[$a] = self::add364($v[$a], $v[$b], $m[self::$sigma[$r][$i << 1]]);
401
+		$v[$d] = self::rotr64(self::xor64($v[$d], $v[$a]), 32);
402
+		$v[$c] = self::add64($v[$c], $v[$d]);
403
+		$v[$b] = self::rotr64(self::xor64($v[$b], $v[$c]), 24);
404
+		$v[$a] = self::add364($v[$a], $v[$b], $m[self::$sigma[$r][($i << 1) + 1]]);
405
+		$v[$d] = self::rotr64(self::xor64($v[$d], $v[$a]), 16);
406
+		$v[$c] = self::add64($v[$c], $v[$d]);
407
+		$v[$b] = self::rotr64(self::xor64($v[$b], $v[$c]), 63);
408
+		return $v;
409
+	}
410
+
411
+	/**
412
+	 * @internal You should not use this directly from another application
413
+	 *
414
+	 * @param SplFixedArray $ctx
415
+	 * @param int $inc
416
+	 * @return void
417
+	 * @throws SodiumException
418
+	 * @psalm-suppress MixedArgument
419
+	 * @psalm-suppress MixedArrayAccess
420
+	 * @psalm-suppress MixedArrayAssignment
421
+	 */
422
+	public static function increment_counter($ctx, $inc)
423
+	{
424
+		if ($inc < 0) {
425
+			throw new SodiumException('Increasing by a negative number makes no sense.');
426
+		}
427
+		$t = self::to64($inc);
428
+		# S->t is $ctx[1] in our implementation
429
+
430
+		# S->t[0] = ( uint64_t )( t >> 0 );
431
+		$ctx[1][0] = self::add64($ctx[1][0], $t);
432
+
433
+		# S->t[1] += ( S->t[0] < inc );
434
+		if (self::flatten64($ctx[1][0]) < $inc) {
435
+			$ctx[1][1] = self::add64($ctx[1][1], self::to64(1));
436
+		}
437
+	}
438
+
439
+	/**
440
+	 * @internal You should not use this directly from another application
441
+	 *
442
+	 * @param SplFixedArray $ctx
443
+	 * @param SplFixedArray $p
444
+	 * @param int $plen
445
+	 * @return void
446
+	 * @throws SodiumException
447
+	 * @throws TypeError
448
+	 * @psalm-suppress MixedArgument
449
+	 * @psalm-suppress MixedAssignment
450
+	 * @psalm-suppress MixedArrayAccess
451
+	 * @psalm-suppress MixedArrayAssignment
452
+	 * @psalm-suppress MixedArrayOffset
453
+	 * @psalm-suppress MixedOperand
454
+	 */
455
+	public static function update(SplFixedArray $ctx, SplFixedArray $p, $plen)
456
+	{
457
+		self::pseudoConstructor();
458
+
459
+		$offset = 0;
460
+		while ($plen > 0) {
461
+			$left = $ctx[4];
462
+			$fill = 256 - $left;
463
+
464
+			if ($plen > $fill) {
465
+				# memcpy( S->buf + left, in, fill ); /* Fill buffer */
466
+				for ($i = $fill; $i--;) {
467
+					$ctx[3][$i + $left] = $p[$i + $offset];
468
+				}
469
+
470
+				# S->buflen += fill;
471
+				$ctx[4] += $fill;
472
+
473
+				# blake2b_increment_counter( S, BLAKE2B_BLOCKBYTES );
474
+				self::increment_counter($ctx, 128);
475
+
476
+				# blake2b_compress( S, S->buf ); /* Compress */
477
+				self::compress($ctx, $ctx[3]);
478
+
479
+				# memcpy( S->buf, S->buf + BLAKE2B_BLOCKBYTES, BLAKE2B_BLOCKBYTES ); /* Shift buffer left */
480
+				for ($i = 128; $i--;) {
481
+					$ctx[3][$i] = $ctx[3][$i + 128];
482
+				}
483
+
484
+				# S->buflen -= BLAKE2B_BLOCKBYTES;
485
+				$ctx[4] -= 128;
486
+
487
+				# in += fill;
488
+				$offset += $fill;
489
+
490
+				# inlen -= fill;
491
+				$plen -= $fill;
492
+			} else {
493
+				for ($i = $plen; $i--;) {
494
+					$ctx[3][$i + $left] = $p[$i + $offset];
495
+				}
496
+				$ctx[4] += $plen;
497
+				$offset += $plen;
498
+				$plen -= $plen;
499
+			}
500
+		}
501
+	}
502
+
503
+	/**
504
+	 * @internal You should not use this directly from another application
505
+	 *
506
+	 * @param SplFixedArray $ctx
507
+	 * @param SplFixedArray $out
508
+	 * @return SplFixedArray
509
+	 * @throws SodiumException
510
+	 * @throws TypeError
511
+	 * @psalm-suppress MixedArgument
512
+	 * @psalm-suppress MixedAssignment
513
+	 * @psalm-suppress MixedArrayAccess
514
+	 * @psalm-suppress MixedArrayAssignment
515
+	 * @psalm-suppress MixedArrayOffset
516
+	 * @psalm-suppress MixedOperand
517
+	 */
518
+	public static function finish(SplFixedArray $ctx, SplFixedArray $out)
519
+	{
520
+		self::pseudoConstructor();
521
+		if ($ctx[4] > 128) {
522
+			self::increment_counter($ctx, 128);
523
+			self::compress($ctx, $ctx[3]);
524
+			$ctx[4] -= 128;
525
+			if ($ctx[4] > 128) {
526
+				throw new SodiumException('Failed to assert that buflen <= 128 bytes');
527
+			}
528
+			for ($i = $ctx[4]; $i--;) {
529
+				$ctx[3][$i] = $ctx[3][$i + 128];
530
+			}
531
+		}
532
+
533
+		self::increment_counter($ctx, $ctx[4]);
534
+		$ctx[2][0] = self::new64(0xffffffff, 0xffffffff);
535
+
536
+		for ($i = 256 - $ctx[4]; $i--;) {
537
+			$ctx[3][$i+$ctx[4]] = 0;
538
+		}
539
+
540
+		self::compress($ctx, $ctx[3]);
541
+
542
+		$i = (int) (($out->getSize() - 1) / 8);
543
+		for (; $i >= 0; --$i) {
544
+			self::store64($out, $i << 3, $ctx[0][$i]);
545
+		}
546
+		return $out;
547
+	}
548
+
549
+	/**
550
+	 * @internal You should not use this directly from another application
551
+	 *
552
+	 * @param SplFixedArray|null $key
553
+	 * @param int $outlen
554
+	 * @param SplFixedArray|null $salt
555
+	 * @param SplFixedArray|null $personal
556
+	 * @return SplFixedArray
557
+	 * @throws SodiumException
558
+	 * @throws TypeError
559
+	 * @psalm-suppress MixedArgument
560
+	 * @psalm-suppress MixedAssignment
561
+	 * @psalm-suppress MixedArrayAccess
562
+	 * @psalm-suppress MixedArrayAssignment
563
+	 * @psalm-suppress MixedArrayOffset
564
+	 */
565
+	public static function init(
566
+		$key = null,
567
+		$outlen = 64,
568
+		$salt = null,
569
+		$personal = null
570
+	) {
571
+		self::pseudoConstructor();
572
+		$klen = 0;
573
+
574
+		if ($key !== null) {
575
+			if (count($key) > 64) {
576
+				throw new SodiumException('Invalid key size');
577
+			}
578
+			$klen = count($key);
579
+		}
580
+
581
+		if ($outlen > 64) {
582
+			throw new SodiumException('Invalid output size');
583
+		}
584
+
585
+		$ctx = self::context();
586
+
587
+		$p = new SplFixedArray(64);
588
+		// Zero our param buffer...
589
+		for ($i = 64; --$i;) {
590
+			$p[$i] = 0;
591
+		}
592
+
593
+		$p[0] = $outlen; // digest_length
594
+		$p[1] = $klen;   // key_length
595
+		$p[2] = 1;       // fanout
596
+		$p[3] = 1;       // depth
597
+
598
+		if ($salt instanceof SplFixedArray) {
599
+			// salt: [32] through [47]
600
+			for ($i = 0; $i < 16; ++$i) {
601
+				$p[32 + $i] = (int) $salt[$i];
602
+			}
603
+		}
604
+		if ($personal instanceof SplFixedArray) {
605
+			// personal: [48] through [63]
606
+			for ($i = 0; $i < 16; ++$i) {
607
+				$p[48 + $i] = (int) $personal[$i];
608
+			}
609
+		}
610
+
611
+		$ctx[0][0] = self::xor64(
612
+			$ctx[0][0],
613
+			self::load64($p, 0)
614
+		);
615
+		if ($salt instanceof SplFixedArray || $personal instanceof SplFixedArray) {
616
+			// We need to do what blake2b_init_param() does:
617
+			for ($i = 1; $i < 8; ++$i) {
618
+				$ctx[0][$i] = self::xor64(
619
+					$ctx[0][$i],
620
+					self::load64($p, $i << 3)
621
+				);
622
+			}
623
+		}
624
+
625
+		if ($klen > 0 && $key instanceof SplFixedArray) {
626
+			$block = new SplFixedArray(128);
627
+			for ($i = 128; $i--;) {
628
+				$block[$i] = 0;
629
+			}
630
+			for ($i = $klen; $i--;) {
631
+				$block[$i] = $key[$i];
632
+			}
633
+			self::update($ctx, $block, 128);
634
+			$ctx[4] = 128;
635
+		}
636
+
637
+		return $ctx;
638
+	}
639
+
640
+	/**
641
+	 * Convert a string into an SplFixedArray of integers
642
+	 *
643
+	 * @internal You should not use this directly from another application
644
+	 *
645
+	 * @param string $str
646
+	 * @return SplFixedArray
647
+	 * @psalm-suppress MixedArgumentTypeCoercion
648
+	 */
649
+	public static function stringToSplFixedArray($str = '')
650
+	{
651
+		$values = unpack('C*', $str);
652
+		return SplFixedArray::fromArray(array_values($values));
653
+	}
654
+
655
+	/**
656
+	 * Convert an SplFixedArray of integers into a string
657
+	 *
658
+	 * @internal You should not use this directly from another application
659
+	 *
660
+	 * @param SplFixedArray $a
661
+	 * @return string
662
+	 * @throws TypeError
663
+	 */
664
+	public static function SplFixedArrayToString(SplFixedArray $a)
665
+	{
666
+		/**
667
+		 * @var array<int, int|string> $arr
668
+		 */
669
+		$arr = $a->toArray();
670
+		$c = $a->count();
671
+		array_unshift($arr, str_repeat('C', $c));
672
+		return (string) (call_user_func_array('pack', $arr));
673
+	}
674
+
675
+	/**
676
+	 * @internal You should not use this directly from another application
677
+	 *
678
+	 * @param SplFixedArray $ctx
679
+	 * @return string
680
+	 * @throws TypeError
681
+	 * @psalm-suppress MixedArgument
682
+	 * @psalm-suppress MixedAssignment
683
+	 * @psalm-suppress MixedArrayAccess
684
+	 * @psalm-suppress MixedArrayAssignment
685
+	 * @psalm-suppress MixedArrayOffset
686
+	 * @psalm-suppress MixedMethodCall
687
+	 */
688
+	public static function contextToString(SplFixedArray $ctx)
689
+	{
690
+		$str = '';
691
+		/** @var array<int, array<int, int>> $ctxA */
692
+		$ctxA = $ctx[0]->toArray();
693
+
694
+		# uint64_t h[8];
695
+		for ($i = 0; $i < 8; ++$i) {
696
+			$str .= self::store32_le($ctxA[$i][1]);
697
+			$str .= self::store32_le($ctxA[$i][0]);
698
+		}
699
+
700
+		# uint64_t t[2];
701
+		# uint64_t f[2];
702
+		for ($i = 1; $i < 3; ++$i) {
703
+			$ctxA = $ctx[$i]->toArray();
704
+			$str .= self::store32_le($ctxA[0][1]);
705
+			$str .= self::store32_le($ctxA[0][0]);
706
+			$str .= self::store32_le($ctxA[1][1]);
707
+			$str .= self::store32_le($ctxA[1][0]);
708
+		}
709
+
710
+		# uint8_t buf[2 * 128];
711
+		$str .= self::SplFixedArrayToString($ctx[3]);
712
+
713
+		/** @var int $ctx4 */
714
+		$ctx4 = (int) $ctx[4];
715
+
716
+		# size_t buflen;
717
+		$str .= implode('', array(
718
+			self::intToChr($ctx4 & 0xff),
719
+			self::intToChr(($ctx4 >> 8) & 0xff),
720
+			self::intToChr(($ctx4 >> 16) & 0xff),
721
+			self::intToChr(($ctx4 >> 24) & 0xff),
722
+			self::intToChr(($ctx4 >> 32) & 0xff),
723
+			self::intToChr(($ctx4 >> 40) & 0xff),
724
+			self::intToChr(($ctx4 >> 48) & 0xff),
725
+			self::intToChr(($ctx4 >> 56) & 0xff)
726
+		));
727
+		# uint8_t last_node;
728
+		return $str . self::intToChr($ctx[5]) . str_repeat("\x00", 23);
729
+	}
730
+
731
+	/**
732
+	 * Creates an SplFixedArray containing other SplFixedArray elements, from
733
+	 * a string (compatible with \Sodium\crypto_generichash_{init, update, final})
734
+	 *
735
+	 * @internal You should not use this directly from another application
736
+	 *
737
+	 * @param string $string
738
+	 * @return SplFixedArray
739
+	 * @throws SodiumException
740
+	 * @throws TypeError
741
+	 * @psalm-suppress MixedArrayAssignment
742
+	 */
743
+	public static function stringToContext($string)
744
+	{
745
+		$ctx = self::context();
746
+
747
+		# uint64_t h[8];
748
+		for ($i = 0; $i < 8; ++$i) {
749
+			$ctx[0][$i] = SplFixedArray::fromArray(
750
+				array(
751
+					self::load_4(
752
+						self::substr($string, (($i << 3) + 4), 4)
753
+					),
754
+					self::load_4(
755
+						self::substr($string, (($i << 3) + 0), 4)
756
+					)
757
+				)
758
+			);
759
+		}
760
+
761
+		# uint64_t t[2];
762
+		# uint64_t f[2];
763
+		for ($i = 1; $i < 3; ++$i) {
764
+			$ctx[$i][1] = SplFixedArray::fromArray(
765
+				array(
766
+					self::load_4(self::substr($string, 76 + (($i - 1) << 4), 4)),
767
+					self::load_4(self::substr($string, 72 + (($i - 1) << 4), 4))
768
+				)
769
+			);
770
+			$ctx[$i][0] = SplFixedArray::fromArray(
771
+				array(
772
+					self::load_4(self::substr($string, 68 + (($i - 1) << 4), 4)),
773
+					self::load_4(self::substr($string, 64 + (($i - 1) << 4), 4))
774
+				)
775
+			);
776
+		}
777
+
778
+		# uint8_t buf[2 * 128];
779
+		$ctx[3] = self::stringToSplFixedArray(self::substr($string, 96, 256));
780
+
781
+		# uint8_t buf[2 * 128];
782
+		$int = 0;
783
+		for ($i = 0; $i < 8; ++$i) {
784
+			$int |= self::chrToInt($string[352 + $i]) << ($i << 3);
785
+		}
786
+		$ctx[4] = $int;
787
+
788
+		return $ctx;
789
+	}
790 790
 }
Please login to merge, or discard this patch.