mirror of
https://github.com/luxfi/crypto.git
synced 2026-07-27 01:54:50 +00:00
luxfi/crypto becomes the single Go entry point for ALL Lux-family crypto. Every public function in this module now dispatches between three implementations through a runtime-selectable backend: - vanilla: pure-Go reference (always available) - cgo: native binding (blst, libsecp256k1, ckzg) where present - gpu: batch acceleration via github.com/luxfi/accel The dispatcher reads LUX_CRYPTO_BACKEND (auto|vanilla|cgo|gpu); auto picks the most capable backend the binary was compiled and linked with. New canonical packages: backend/ runtime backend selector (env + programmatic) internal/gpuhost/ accel session lifecycle, single per-process keccak/ Keccak-256 with batch GPU dispatch sha256/ SHA-256 with batch GPU dispatch sha3/ SHA3 / SHAKE family ripemd160/ RIPEMD-160 (Bitcoin/Lux address derivation) ed25519/ Ed25519 with batch GPU verify bn254/ canonical alias for bn256 (matches FIPS naming) modexp/ canonical alias for bigmodexp evm256/ EIP-196/197 precompile ABI wrappers poseidon/ Poseidon2 hash via gnark-crypto pedersen/ Pedersen commitments over BN254 ntt/ Number-Theoretic Transform reference polymul/ negacyclic polynomial multiplication Extended existing packages with batch GPU paths: bls/batch.go BatchVerify routes through accel.BLSVerifyBatch mldsa/batch.go BatchVerify (ML-DSA-65) via accel.DilithiumVerifyBatch mlkem/batch.go BatchEncapsulate / BatchDecapsulate via Kyber kernels secp256k1/batch.go BatchVerifySignature via accel.ECDSAVerifyBatch GPU dispatch is gated on (a) backend.Default(), (b) batch size threshold, and (c) accel.Available(). When any gate fails the call falls through to the vanilla CPU path; output is byte-identical. The legacy gpu/ stub is replaced with a thin probe surface (Available, Backend, Devices, Version) that delegates to the same gpuhost session. Tests show vanilla and gpu backends produce identical outputs across all batch entry points (-race clean). See AUDIT.md for the per-algorithm state matrix and honest gaps.
53 lines
1.0 KiB
Go
53 lines
1.0 KiB
Go
package mlkem
|
|
|
|
import (
|
|
"bytes"
|
|
"testing"
|
|
)
|
|
|
|
func TestBatchEncapDecap(t *testing.T) {
|
|
for _, mode := range []Mode{MLKEM512, MLKEM768, MLKEM1024} {
|
|
t.Run(mode.String(), func(t *testing.T) {
|
|
n := BatchThreshold + 2
|
|
pubs := make([]*PublicKey, n)
|
|
privs := make([]*PrivateKey, n)
|
|
for i := 0; i < n; i++ {
|
|
pub, priv, err := GenerateKey(mode)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
pubs[i] = pub
|
|
privs[i] = priv
|
|
}
|
|
|
|
cts, sss, err := BatchEncapsulate(pubs)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if len(cts) != n || len(sss) != n {
|
|
t.Fatalf("len(cts)=%d len(sss)=%d, want %d", len(cts), len(sss), n)
|
|
}
|
|
|
|
recovered, err := BatchDecapsulate(privs, cts)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
for i := 0; i < n; i++ {
|
|
if !bytes.Equal(recovered[i], sss[i]) {
|
|
t.Errorf("shared secret mismatch at %d", i)
|
|
}
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestBatchEmpty(t *testing.T) {
|
|
cts, sss, err := BatchEncapsulate(nil)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if cts != nil || sss != nil {
|
|
t.Fatal("expected nil/nil for empty input")
|
|
}
|
|
}
|