Bitcoin Core 31.99.0
P2P Digital Currency
main_impl.h
Go to the documentation of this file.
1/***********************************************************************
2 * Copyright (c) 2020 Jonas Nick *
3 * Distributed under the MIT software license, see the accompanying *
4 * file COPYING or https://www.opensource.org/licenses/mit-license.php.*
5 ***********************************************************************/
6
7#ifndef SECP256K1_MODULE_EXTRAKEYS_MAIN_H
8#define SECP256K1_MODULE_EXTRAKEYS_MAIN_H
9
10#include "../../../include/secp256k1.h"
11#include "../../../include/secp256k1_extrakeys.h"
12#include "../../util.h"
13
15 return secp256k1_pubkey_load(ctx, ge, (const secp256k1_pubkey *) pubkey);
16}
17
19#ifdef VERIFY
20 /* ensure that the group element's Y coordinate is even, as per definition of x-only public keys */
21 secp256k1_fe y = ge->y;
24#endif
25
27}
28
29int secp256k1_xonly_pubkey_parse(const secp256k1_context* ctx, secp256k1_xonly_pubkey *pubkey, const unsigned char *input32) {
32
33 VERIFY_CHECK(ctx != NULL);
34 ARG_CHECK(pubkey != NULL);
35 memset(pubkey, 0, sizeof(*pubkey));
36 ARG_CHECK(input32 != NULL);
37
38 if (!secp256k1_fe_set_b32_limit(&x, input32)) {
39 return 0;
40 }
41 if (!secp256k1_ge_set_xo_var(&pk, &x, 0)) {
42 return 0;
43 }
45 return 0;
46 }
48 return 1;
49}
50
51int secp256k1_xonly_pubkey_serialize(const secp256k1_context* ctx, unsigned char *output32, const secp256k1_xonly_pubkey *pubkey) {
53
54 VERIFY_CHECK(ctx != NULL);
55 ARG_CHECK(output32 != NULL);
56 memset(output32, 0, 32);
57 ARG_CHECK(pubkey != NULL);
58
59 if (!secp256k1_xonly_pubkey_load(ctx, &pk, pubkey)) {
60 return 0;
61 }
62 secp256k1_fe_get_b32(output32, &pk.x);
63 return 1;
64}
65
67 unsigned char out[2][32];
68 const secp256k1_xonly_pubkey* pk[2];
69 int i;
70
71 VERIFY_CHECK(ctx != NULL);
72 pk[0] = pk0; pk[1] = pk1;
73 for (i = 0; i < 2; i++) {
74 /* If the public key is NULL or invalid, xonly_pubkey_serialize will
75 * call the illegal_callback and return 0. In that case we will
76 * serialize the key as all zeros which is less than any valid public
77 * key. This results in consistent comparisons even if NULL or invalid
78 * pubkeys are involved and prevents edge cases such as sorting
79 * algorithms that use this function and do not terminate as a
80 * result. */
81 if (!secp256k1_xonly_pubkey_serialize(ctx, out[i], pk[i])) {
82 /* Note that xonly_pubkey_serialize should already set the output to
83 * zero in that case, but it's not guaranteed by the API, we can't
84 * test it and writing a VERIFY_CHECK is more complex than
85 * explicitly memsetting (again). */
86 memset(out[i], 0, sizeof(out[i]));
87 }
88 }
89 return secp256k1_memcmp_var(out[0], out[1], sizeof(out[1]));
90}
91
96 int y_parity = 0;
98
99 if (secp256k1_fe_is_odd(&r->y)) {
100 secp256k1_fe_negate(&r->y, &r->y, 1);
101 y_parity = 1;
102 }
103 return y_parity;
104}
105
106int secp256k1_xonly_pubkey_from_pubkey(const secp256k1_context* ctx, secp256k1_xonly_pubkey *xonly_pubkey, int *pk_parity, const secp256k1_pubkey *pubkey) {
108 int tmp;
109
110 VERIFY_CHECK(ctx != NULL);
111 ARG_CHECK(xonly_pubkey != NULL);
112 ARG_CHECK(pubkey != NULL);
113
114 if (!secp256k1_pubkey_load(ctx, &pk, pubkey)) {
115 return 0;
116 }
118 if (pk_parity != NULL) {
119 *pk_parity = tmp;
120 }
121 secp256k1_xonly_pubkey_save(xonly_pubkey, &pk);
122 return 1;
123}
124
125int secp256k1_xonly_pubkey_tweak_add(const secp256k1_context* ctx, secp256k1_pubkey *output_pubkey, const secp256k1_xonly_pubkey *internal_pubkey, const unsigned char *tweak32) {
127
128 VERIFY_CHECK(ctx != NULL);
129 ARG_CHECK(output_pubkey != NULL);
130 memset(output_pubkey, 0, sizeof(*output_pubkey));
131 ARG_CHECK(internal_pubkey != NULL);
132 ARG_CHECK(tweak32 != NULL);
133
134 if (!secp256k1_xonly_pubkey_load(ctx, &pk, internal_pubkey)
136 return 0;
137 }
138 secp256k1_pubkey_save(output_pubkey, &pk);
139 return 1;
140}
141
142int secp256k1_xonly_pubkey_tweak_add_check(const secp256k1_context* ctx, const unsigned char *tweaked_pubkey32, int tweaked_pk_parity, const secp256k1_xonly_pubkey *internal_pubkey, const unsigned char *tweak32) {
144 unsigned char pk_expected32[32];
145
146 VERIFY_CHECK(ctx != NULL);
147 ARG_CHECK(internal_pubkey != NULL);
148 ARG_CHECK(tweaked_pubkey32 != NULL);
149 ARG_CHECK(tweak32 != NULL);
150
151 if (!secp256k1_xonly_pubkey_load(ctx, &pk, internal_pubkey)
153 return 0;
154 }
157 secp256k1_fe_get_b32(pk_expected32, &pk.x);
158
159 return secp256k1_memcmp_var(&pk_expected32, tweaked_pubkey32, 32) == 0
160 && secp256k1_fe_is_odd(&pk.y) == tweaked_pk_parity;
161}
162
164 secp256k1_scalar_get_b32(&keypair->data[0], sk);
166}
167
168
170 int ret;
171
173 /* We can declassify ret here because sk is only zero if a keypair function
174 * failed (which zeroes the keypair) and its return value is ignored. */
175 secp256k1_declassify(ctx, &ret, sizeof(ret));
176 ARG_CHECK(ret);
177 return ret;
178}
179
180/* Load a keypair into pk and sk (if non-NULL). This function declassifies pk
181 * and ARG_CHECKs that the keypair is not invalid. It always initializes sk and
182 * pk with dummy values. */
184 int ret;
185 const secp256k1_pubkey *pubkey = (const secp256k1_pubkey *)&keypair->data[32];
186
187 /* Need to declassify the pubkey because pubkey_load ARG_CHECKs if it's
188 * invalid. */
189 secp256k1_declassify(ctx, pubkey, sizeof(*pubkey));
190 ret = secp256k1_pubkey_load(ctx, pk, pubkey);
191 if (sk != NULL) {
192 ret = ret && secp256k1_keypair_seckey_load(ctx, sk, keypair);
193 }
194 if (!ret) {
196 if (sk != NULL) {
198 }
199 }
200 return ret;
201}
202
203int secp256k1_keypair_create(const secp256k1_context* ctx, secp256k1_keypair *keypair, const unsigned char *seckey32) {
206 int ret = 0;
207 VERIFY_CHECK(ctx != NULL);
208 ARG_CHECK(keypair != NULL);
209 memset(keypair, 0, sizeof(*keypair));
211 ARG_CHECK(seckey32 != NULL);
212
214 secp256k1_keypair_save(keypair, &sk, &pk);
215 secp256k1_memczero(keypair, sizeof(*keypair), !ret);
216
218 return ret;
219}
220
221int secp256k1_keypair_sec(const secp256k1_context* ctx, unsigned char *seckey, const secp256k1_keypair *keypair) {
222 VERIFY_CHECK(ctx != NULL);
223 ARG_CHECK(seckey != NULL);
224 memset(seckey, 0, 32);
225 ARG_CHECK(keypair != NULL);
226
227 memcpy(seckey, &keypair->data[0], 32);
228 return 1;
229}
230
232 VERIFY_CHECK(ctx != NULL);
233 ARG_CHECK(pubkey != NULL);
234 memset(pubkey, 0, sizeof(*pubkey));
235 ARG_CHECK(keypair != NULL);
236
237 memcpy(pubkey->data, &keypair->data[32], sizeof(*pubkey));
238 return 1;
239}
240
241int secp256k1_keypair_xonly_pub(const secp256k1_context* ctx, secp256k1_xonly_pubkey *pubkey, int *pk_parity, const secp256k1_keypair *keypair) {
243 int tmp;
244
245 VERIFY_CHECK(ctx != NULL);
246 ARG_CHECK(pubkey != NULL);
247 memset(pubkey, 0, sizeof(*pubkey));
248 ARG_CHECK(keypair != NULL);
249
250 if (!secp256k1_keypair_load(ctx, NULL, &pk, keypair)) {
251 return 0;
252 }
254 if (pk_parity != NULL) {
255 *pk_parity = tmp;
256 }
258
259 return 1;
260}
261
262int secp256k1_keypair_xonly_tweak_add(const secp256k1_context* ctx, secp256k1_keypair *keypair, const unsigned char *tweak32) {
265 int y_parity;
266 int ret;
267
268 VERIFY_CHECK(ctx != NULL);
269 ARG_CHECK(keypair != NULL);
270 ARG_CHECK(tweak32 != NULL);
271
272 ret = secp256k1_keypair_load(ctx, &sk, &pk, keypair);
273 memset(keypair, 0, sizeof(*keypair));
274
276 if (y_parity == 1) {
278 }
279
282
283 secp256k1_declassify(ctx, &ret, sizeof(ret));
284 if (ret) {
285 secp256k1_keypair_save(keypair, &sk, &pk);
286 }
287
289 return ret;
290}
291
292#endif
int ret
static int secp256k1_ecmult_gen_context_is_built(const secp256k1_ecmult_gen_context *ctx)
static int secp256k1_keypair_load(const secp256k1_context *ctx, secp256k1_scalar *sk, secp256k1_ge *pk, const secp256k1_keypair *keypair)
Definition: main_impl.h:183
int secp256k1_keypair_create(const secp256k1_context *ctx, secp256k1_keypair *keypair, const unsigned char *seckey32)
Compute the keypair for a valid secret key.
Definition: main_impl.h:203
static void secp256k1_keypair_save(secp256k1_keypair *keypair, const secp256k1_scalar *sk, secp256k1_ge *pk)
Definition: main_impl.h:163
int secp256k1_keypair_xonly_tweak_add(const secp256k1_context *ctx, secp256k1_keypair *keypair, const unsigned char *tweak32)
Tweak a keypair by adding tweak32 to the secret key and updating the public key accordingly.
Definition: main_impl.h:262
int secp256k1_xonly_pubkey_tweak_add_check(const secp256k1_context *ctx, const unsigned char *tweaked_pubkey32, int tweaked_pk_parity, const secp256k1_xonly_pubkey *internal_pubkey, const unsigned char *tweak32)
Checks that a tweaked pubkey is the result of calling secp256k1_xonly_pubkey_tweak_add with internal_...
Definition: main_impl.h:142
int secp256k1_xonly_pubkey_tweak_add(const secp256k1_context *ctx, secp256k1_pubkey *output_pubkey, const secp256k1_xonly_pubkey *internal_pubkey, const unsigned char *tweak32)
Tweak an x-only public key by adding the generator multiplied with tweak32 to it.
Definition: main_impl.h:125
int secp256k1_xonly_pubkey_serialize(const secp256k1_context *ctx, unsigned char *output32, const secp256k1_xonly_pubkey *pubkey)
Serialize an xonly_pubkey object into a 32-byte sequence.
Definition: main_impl.h:51
int secp256k1_keypair_sec(const secp256k1_context *ctx, unsigned char *seckey, const secp256k1_keypair *keypair)
Get the secret key from a keypair.
Definition: main_impl.h:221
int secp256k1_keypair_xonly_pub(const secp256k1_context *ctx, secp256k1_xonly_pubkey *pubkey, int *pk_parity, const secp256k1_keypair *keypair)
Get the x-only public key from a keypair.
Definition: main_impl.h:241
static int secp256k1_keypair_seckey_load(const secp256k1_context *ctx, secp256k1_scalar *sk, const secp256k1_keypair *keypair)
Definition: main_impl.h:169
int secp256k1_xonly_pubkey_from_pubkey(const secp256k1_context *ctx, secp256k1_xonly_pubkey *xonly_pubkey, int *pk_parity, const secp256k1_pubkey *pubkey)
Converts a secp256k1_pubkey into a secp256k1_xonly_pubkey.
Definition: main_impl.h:106
int secp256k1_keypair_pub(const secp256k1_context *ctx, secp256k1_pubkey *pubkey, const secp256k1_keypair *keypair)
Get the public key from a keypair.
Definition: main_impl.h:231
int secp256k1_xonly_pubkey_parse(const secp256k1_context *ctx, secp256k1_xonly_pubkey *pubkey, const unsigned char *input32)
Parse a 32-byte sequence into a xonly_pubkey object.
Definition: main_impl.h:29
static SECP256K1_INLINE void secp256k1_xonly_pubkey_save(secp256k1_xonly_pubkey *pubkey, secp256k1_ge *ge)
Definition: main_impl.h:18
static SECP256K1_INLINE int secp256k1_xonly_pubkey_load(const secp256k1_context *ctx, secp256k1_ge *ge, const secp256k1_xonly_pubkey *pubkey)
Definition: main_impl.h:14
static int secp256k1_extrakeys_ge_even_y(secp256k1_ge *r)
Keeps a group element as is if it has an even Y and otherwise negates it.
Definition: main_impl.h:95
int secp256k1_xonly_pubkey_cmp(const secp256k1_context *ctx, const secp256k1_xonly_pubkey *pk0, const secp256k1_xonly_pubkey *pk1)
Compare two x-only public keys using lexicographic order.
Definition: main_impl.h:66
#define secp256k1_fe_negate(r, a, m)
Negate a field element.
Definition: field.h:211
#define secp256k1_fe_is_odd
Definition: field.h:85
#define secp256k1_fe_normalize_var
Definition: field.h:80
#define secp256k1_fe_set_b32_limit
Definition: field.h:88
#define secp256k1_fe_get_b32
Definition: field.h:89
static int secp256k1_ge_set_xo_var(secp256k1_ge *r, const secp256k1_fe *x, int odd)
Set a group element (affine) equal to the point with the given X coordinate, and given oddness for Y.
static int secp256k1_ge_is_in_correct_subgroup(const secp256k1_ge *ge)
Determine if a point (which is assumed to be on the curve) is in the correct (sub)group of the curve.
static int secp256k1_ge_is_infinity(const secp256k1_ge *a)
Check whether a group element is the point at infinity.
static const secp256k1_ge secp256k1_ge_const_g
Definition: group_impl.h:72
static int secp256k1_scalar_set_b32_seckey(secp256k1_scalar *r, const unsigned char *bin)
Set a scalar from a big endian byte array and returns 1 if it is a valid seckey and 0 otherwise.
static void secp256k1_scalar_get_b32(unsigned char *bin, const secp256k1_scalar *a)
Convert a scalar to a byte array.
static void secp256k1_scalar_negate(secp256k1_scalar *r, const secp256k1_scalar *a)
Compute the complement of a scalar (modulo the group order).
static void secp256k1_scalar_clear(secp256k1_scalar *r)
Clear a scalar to prevent the leak of sensitive data.
static const secp256k1_scalar secp256k1_scalar_one
Definition: scalar_impl.h:27
static SECP256K1_INLINE int secp256k1_memcmp_var(const void *s1, const void *s2, size_t n)
Semantics like memcmp.
Definition: util.h:282
#define SECP256K1_INLINE
Definition: util.h:54
#define VERIFY_CHECK(cond)
Definition: util.h:170
static SECP256K1_INLINE void secp256k1_memczero(void *s, size_t len, int flag)
Definition: util.h:221
static int secp256k1_ec_seckey_tweak_add_helper(secp256k1_scalar *sec, const unsigned char *tweak32)
Definition: secp256k1.c:686
#define ARG_CHECK(cond)
Definition: secp256k1.c:45
static int secp256k1_ec_pubkey_create_helper(const secp256k1_ecmult_gen_context *ecmult_gen_ctx, secp256k1_scalar *seckey_scalar, secp256k1_ge *p, const unsigned char *seckey)
Definition: secp256k1.c:627
static SECP256K1_INLINE void secp256k1_declassify(const secp256k1_context *ctx, const void *p, size_t len)
Definition: secp256k1.c:255
static int secp256k1_pubkey_load(const secp256k1_context *ctx, secp256k1_ge *ge, const secp256k1_pubkey *pubkey)
Definition: secp256k1.c:259
static void secp256k1_pubkey_save(secp256k1_pubkey *pubkey, secp256k1_ge *ge)
Definition: secp256k1.c:265
static int secp256k1_ec_pubkey_tweak_add_helper(secp256k1_ge *p, const unsigned char *tweak32)
Definition: secp256k1.c:713
secp256k1_ecmult_gen_context ecmult_gen_ctx
Definition: secp256k1.c:62
This field implementation represents the value as 10 uint32_t limbs in base 2^26.
Definition: field_10x26.h:14
A group element in affine coordinates on the secp256k1 curve, or occasionally on an isomorphic curve ...
Definition: group.h:16
secp256k1_fe y
Definition: group.h:18
Opaque data structure that holds a keypair consisting of a secret and a public key.
unsigned char data[96]
Opaque data structure that holds a parsed and valid public key.
Definition: secp256k1.h:62
unsigned char data[64]
Definition: secp256k1.h:63
A scalar modulo the group order of the secp256k1 curve.
Definition: scalar_4x64.h:13
Opaque data structure that holds a parsed and valid "x-only" public key.