2018-11-27 23:10:09 +00:00
|
|
|
# beacon_chain
|
2020-01-22 12:48:06 +00:00
|
|
|
# Copyright (c) 2018-2020 Status Research & Development GmbH
|
2018-11-27 23:10:09 +00:00
|
|
|
# Licensed and distributed under either of
|
2019-11-25 15:30:02 +00:00
|
|
|
# * MIT license (license terms in the root directory or at https://opensource.org/licenses/MIT).
|
|
|
|
# * Apache v2 license (license terms in the root directory or at https://www.apache.org/licenses/LICENSE-2.0).
|
2018-11-27 23:10:09 +00:00
|
|
|
# at your option. This file may not be copied, modified, or distributed except according to those terms.
|
|
|
|
|
|
|
|
# Serenity hash function / digest
|
|
|
|
#
|
2020-11-09 14:18:55 +00:00
|
|
|
# https://github.com/ethereum/eth2.0-specs/blob/v1.0.0/specs/phase0/beacon-chain.md#hash
|
2018-11-27 23:10:09 +00:00
|
|
|
#
|
2019-05-10 08:14:01 +00:00
|
|
|
# In Phase 0 the beacon chain is deployed with SHA256 (SHA2-256).
|
|
|
|
# Note that is is different from Keccak256 (often mistakenly called SHA3-256)
|
|
|
|
# and SHA3-256.
|
2019-03-09 20:34:08 +00:00
|
|
|
#
|
2019-05-10 08:14:01 +00:00
|
|
|
# In Eth1.0, the default hash function is Keccak256 and SHA256 is available as a precompiled contract.
|
2019-03-09 20:34:08 +00:00
|
|
|
#
|
2019-05-10 08:14:01 +00:00
|
|
|
# In our code base, to enable a smooth transition
|
|
|
|
# (already did Blake2b --> Keccak256 --> SHA2-256),
|
2020-06-16 12:16:43 +00:00
|
|
|
# we call this function `eth2digest`, and it outputs a `Eth2Digest`. Easy to sed :)
|
2018-11-27 23:10:09 +00:00
|
|
|
|
2020-04-11 08:51:07 +00:00
|
|
|
{.push raises: [Defect].}
|
|
|
|
|
2018-12-19 12:58:53 +00:00
|
|
|
import
|
2020-09-18 14:55:55 +00:00
|
|
|
# Standard library
|
|
|
|
std/hashes,
|
|
|
|
#Status libraries
|
2020-04-11 08:51:07 +00:00
|
|
|
chronicles,
|
|
|
|
nimcrypto/[sha2, hash],
|
|
|
|
stew/byteutils,
|
2020-09-18 14:55:55 +00:00
|
|
|
eth/common/eth_types_json_serialization,
|
|
|
|
blscurve
|
2018-11-27 23:10:09 +00:00
|
|
|
|
2018-12-19 12:58:53 +00:00
|
|
|
export
|
2020-04-23 15:35:42 +00:00
|
|
|
hash.`$`, sha2, readValue, writeValue
|
2018-12-13 16:00:55 +00:00
|
|
|
|
2018-11-27 23:10:09 +00:00
|
|
|
type
|
|
|
|
Eth2Digest* = MDigest[32 * 8] ## `hash32` from spec
|
2020-09-18 14:55:55 +00:00
|
|
|
|
|
|
|
when BLS_BACKEND == BLST:
|
|
|
|
export blscurve.update
|
|
|
|
type Eth2DigestCtx* = BLST_SHA256_CTX
|
|
|
|
else:
|
|
|
|
type Eth2DigestCtx* = sha2.sha256
|
2018-11-27 23:10:09 +00:00
|
|
|
|
2019-02-28 21:21:29 +00:00
|
|
|
func shortLog*(x: Eth2Digest): string =
|
2020-08-27 06:32:51 +00:00
|
|
|
x.data.toOpenArray(0, 3).toHex()
|
2019-02-28 21:21:29 +00:00
|
|
|
|
2020-04-29 20:12:07 +00:00
|
|
|
chronicles.formatIt Eth2Digest:
|
|
|
|
shortLog(it)
|
|
|
|
|
2019-05-10 08:14:01 +00:00
|
|
|
# TODO: expose an in-place digest function
|
|
|
|
# when hashing in loop or into a buffer
|
|
|
|
# See: https://github.com/cheatfate/nimcrypto/blob/b90ba3abd/nimcrypto/sha2.nim#L570
|
2020-09-18 14:55:55 +00:00
|
|
|
func eth2digest*(v: openArray[byte]): Eth2Digest {.noInit.} =
|
|
|
|
## Apply the Eth2 Hash function
|
|
|
|
## Do NOT use for secret data.
|
|
|
|
when BLS_BACKEND == BLST:
|
|
|
|
# BLST has a fast assembly optimized SHA256
|
|
|
|
result.data.bls_sha256_digest(v)
|
|
|
|
else:
|
|
|
|
# We use the init-update-finish interface to avoid
|
|
|
|
# the expensive burning/clearing memory (20~30% perf)
|
|
|
|
var ctx: Eth2DigestCtx
|
|
|
|
ctx.init()
|
|
|
|
ctx.update(v)
|
|
|
|
ctx.finish()
|
2018-11-27 23:10:09 +00:00
|
|
|
|
2020-09-18 14:55:55 +00:00
|
|
|
when BLS_BACKEND == BLST:
|
|
|
|
func update*(ctx: var BLST_SHA256_CTX; digest: Eth2Digest) =
|
|
|
|
ctx.update digest.data
|
|
|
|
func update*(ctx: var sha256; digest: Eth2Digest) =
|
2019-08-28 12:07:00 +00:00
|
|
|
ctx.update digest.data
|
|
|
|
|
2020-12-23 09:36:43 +00:00
|
|
|
# TODO: not sure why but the "init", "update", "final" from BLST
|
|
|
|
# seem to require LTO, even though proper indirection was added in the wrapper
|
2018-11-27 23:10:09 +00:00
|
|
|
template withEth2Hash*(body: untyped): Eth2Digest =
|
|
|
|
## This little helper will init the hash function and return the sliced
|
|
|
|
## hash:
|
|
|
|
## let hashOfData = withHash: h.update(data)
|
2020-09-18 14:55:55 +00:00
|
|
|
when nimvm:
|
|
|
|
# In SSZ, computeZeroHashes require compile-time SHA256
|
|
|
|
block:
|
|
|
|
var h {.inject.}: sha256
|
|
|
|
init(h)
|
|
|
|
body
|
|
|
|
finish(h)
|
|
|
|
else:
|
|
|
|
when BLS_BACKEND == BLST:
|
|
|
|
block:
|
|
|
|
var h {.inject, noInit.}: Eth2DigestCtx
|
|
|
|
init(h)
|
|
|
|
body
|
|
|
|
var res {.noInit.}: Eth2Digest
|
|
|
|
finalize(res.data, h)
|
|
|
|
res
|
|
|
|
else:
|
|
|
|
block:
|
|
|
|
var h {.inject, noInit.}: Eth2DigestCtx
|
|
|
|
init(h)
|
|
|
|
body
|
|
|
|
finish(h)
|
2019-01-08 17:28:21 +00:00
|
|
|
|
|
|
|
func hash*(x: Eth2Digest): Hash =
|
2019-05-10 08:14:01 +00:00
|
|
|
## Hash for digests for Nim hash tables
|
2019-01-08 17:28:21 +00:00
|
|
|
# Stub for BeaconChainDB
|
|
|
|
|
|
|
|
# We just slice the first 4 or 8 bytes of the block hash
|
|
|
|
# depending of if we are on a 32 or 64-bit platform
|
2019-01-11 16:41:57 +00:00
|
|
|
result = cast[ptr Hash](unsafeAddr x)[]
|