Skip to content

Commit fcb4df2

Browse files
wangweijferakocz
andcommittedNov 20, 2023
8320192: SHAKE256 does not work correctly if n >= 137
Co-authored-by: Ferenc Rakoczi <ferenc.r.rakoczi@oracle.com> Reviewed-by: mpowers, valeriep
1 parent 2b4e991 commit fcb4df2

File tree

2 files changed

+60
-3
lines changed

2 files changed

+60
-3
lines changed
 

‎src/java.base/share/classes/sun/security/provider/SHA3.java

+11-3
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/*
2-
* Copyright (c) 2016, 2022, Oracle and/or its affiliates. All rights reserved.
2+
* Copyright (c) 2016, 2023, Oracle and/or its affiliates. All rights reserved.
33
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
44
*
55
* This code is free software; you can redistribute it and/or modify it
@@ -108,7 +108,15 @@ void implDigest(byte[] out, int ofs) {
108108
throw new ProviderException("Incorrect pad size: " + numOfPadding);
109109
}
110110
implCompress(buffer, 0);
111-
System.arraycopy(state, 0, out, ofs, engineGetDigestLength());
111+
int availableBytes = buffer.length;
112+
int numBytes = engineGetDigestLength();
113+
while (numBytes > availableBytes) {
114+
System.arraycopy(state, 0, out, ofs, availableBytes);
115+
numBytes -= availableBytes;
116+
ofs += availableBytes;
117+
keccak();
118+
}
119+
System.arraycopy(state, 0, out, ofs, numBytes);
112120
}
113121

114122
/**
@@ -162,7 +170,7 @@ private static void lanes2Bytes(long[] m, byte[] s) {
162170

163171
/**
164172
* The function Keccak as defined in section 5.2 with
165-
* rate r = 1600 and capacity c = (digest length x 2).
173+
* rate r = 1600 and capacity c.
166174
*/
167175
private void keccak() {
168176
// convert the 200-byte state into 25 lanes
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
/*
2+
* Copyright (c) 2023, Oracle and/or its affiliates. All rights reserved.
3+
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
4+
*
5+
* This code is free software; you can redistribute it and/or modify it
6+
* under the terms of the GNU General Public License version 2 only, as
7+
* published by the Free Software Foundation. Oracle designates this
8+
* particular file as subject to the "Classpath" exception as provided
9+
* by Oracle in the LICENSE file that accompanied this code.
10+
*
11+
* This code is distributed in the hope that it will be useful, but WITHOUT
12+
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
13+
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
14+
* version 2 for more details (a copy is included in the LICENSE file that
15+
* accompanied this code).
16+
*
17+
* You should have received a copy of the GNU General Public License version
18+
* 2 along with this work; if not, write to the Free Software Foundation,
19+
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
20+
*
21+
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
22+
* or visit www.oracle.com if you need additional information or have any
23+
* questions.
24+
*/
25+
package sun.security.provider;
26+
27+
/*
28+
* The SHAKE128 extendable output function.
29+
*/
30+
public final class SHAKE128 extends SHA3 {
31+
public SHAKE128(int d) {
32+
super("SHAKE128", d, (byte) 0x1F, 32);
33+
}
34+
35+
public void update(byte in) {
36+
engineUpdate(in);
37+
}
38+
public void update(byte[] in, int off, int len) {
39+
engineUpdate(in, off, len);
40+
}
41+
42+
public byte[] digest() {
43+
return engineDigest();
44+
}
45+
46+
public void reset() {
47+
engineReset();
48+
}
49+
}

0 commit comments

Comments
 (0)
Please sign in to comment.