|
20 | 20 | #endif |
21 | 21 | #endif /* !NUM_RANDOM_TESTS */ |
22 | 22 |
|
| 23 | +#ifndef NUM_RANDOM_TESTS_UNIFORM |
| 24 | +#ifdef MLDSA_DEBUG |
| 25 | +#define NUM_RANDOM_TESTS_UNIFORM 100 |
| 26 | +#else |
| 27 | +#define NUM_RANDOM_TESTS_UNIFORM 1000 |
| 28 | +#endif |
| 29 | +#endif /* !NUM_RANDOM_TESTS_UNIFORM */ |
| 30 | + |
23 | 31 | #define CHECK(x) \ |
24 | 32 | do \ |
25 | 33 | { \ |
@@ -581,6 +589,107 @@ static int test_backend_units(void) |
581 | 589 | MLD_USE_NATIVE_POLYVECL_POINTWISE_ACC_MONTGOMERY_L7 || \ |
582 | 590 | MLD_USE_NATIVE_POLYZ_UNPACK_17 || MLD_USE_NATIVE_POLYZ_UNPACK_19 */ |
583 | 591 |
|
| 592 | + |
| 593 | +#if !defined(MLD_CONFIG_SERIAL_FIPS202_ONLY) && MLD_CONFIG_PARAMETER_SET == 65 |
| 594 | +static int test_poly_uniform_gamma1_consistency(void) |
| 595 | +{ |
| 596 | + mld_poly r0_x4, r1_x4, r2_x4, r3_x4, r0_x1, r1_x1, r2_x1, r3_x1; |
| 597 | + uint8_t seed[MLDSA_CRHBYTES]; |
| 598 | + uint16_t nonce0, nonce1, nonce2, nonce3; |
| 599 | + int i; |
| 600 | + for (i = 0; i < NUM_RANDOM_TESTS_UNIFORM; i++) |
| 601 | + { |
| 602 | + randombytes(seed, MLDSA_CRHBYTES); |
| 603 | + randombytes((uint8_t *)&nonce0, sizeof(uint16_t)); |
| 604 | + nonce1 = nonce0 + 1; |
| 605 | + nonce2 = nonce0 + 2; |
| 606 | + nonce3 = nonce0 + 3; |
| 607 | + /* Call 4x version */ |
| 608 | + mld_poly_uniform_gamma1_4x(&r0_x4, &r1_x4, &r2_x4, &r3_x4, seed, nonce0, |
| 609 | + nonce1, nonce2, nonce3); |
| 610 | + /* Call scalar version 4 times */ |
| 611 | + mld_poly_uniform_gamma1(&r0_x1, seed, nonce0); |
| 612 | + mld_poly_uniform_gamma1(&r1_x1, seed, nonce1); |
| 613 | + mld_poly_uniform_gamma1(&r2_x1, seed, nonce2); |
| 614 | + mld_poly_uniform_gamma1(&r3_x1, seed, nonce3); |
| 615 | + |
| 616 | + CHECK(memcmp(r0_x4.coeffs, r0_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 617 | + CHECK(memcmp(r1_x4.coeffs, r1_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 618 | + CHECK(memcmp(r2_x4.coeffs, r2_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 619 | + CHECK(memcmp(r3_x4.coeffs, r3_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 620 | + } |
| 621 | + return 0; |
| 622 | +} |
| 623 | +#endif /* !MLD_CONFIG_SERIAL_FIPS202_ONLY && MLD_CONFIG_PARAMETER_SET == 65 */ |
| 624 | + |
| 625 | +#if !defined(MLD_CONFIG_SERIAL_FIPS202_ONLY) && !defined(MLD_CONFIG_REDUCE_RAM) |
| 626 | +static int test_poly_uniform_consistency(void) |
| 627 | +{ |
| 628 | + mld_poly r0_x4, r1_x4, r2_x4, r3_x4, r0_x1, r1_x1, r2_x1, r3_x1; |
| 629 | + MLD_ALIGN uint8_t seed[4][MLD_ALIGN_UP(MLDSA_SEEDBYTES + 2)]; |
| 630 | + int i, j; |
| 631 | + |
| 632 | + for (i = 0; i < NUM_RANDOM_TESTS_UNIFORM; i++) |
| 633 | + { |
| 634 | + for (j = 0; j < 4; j++) |
| 635 | + { |
| 636 | + randombytes(seed[j], MLDSA_SEEDBYTES + 2); |
| 637 | + } |
| 638 | + |
| 639 | + /* Call 4x version */ |
| 640 | + mld_poly_uniform_4x(&r0_x4, &r1_x4, &r2_x4, &r3_x4, seed); |
| 641 | + |
| 642 | + /* Call scalar version 4 times */ |
| 643 | + mld_poly_uniform(&r0_x1, seed[0]); |
| 644 | + mld_poly_uniform(&r1_x1, seed[1]); |
| 645 | + mld_poly_uniform(&r2_x1, seed[2]); |
| 646 | + mld_poly_uniform(&r3_x1, seed[3]); |
| 647 | + |
| 648 | + CHECK(memcmp(r0_x4.coeffs, r0_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 649 | + CHECK(memcmp(r1_x4.coeffs, r1_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 650 | + CHECK(memcmp(r2_x4.coeffs, r2_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 651 | + CHECK(memcmp(r3_x4.coeffs, r3_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 652 | + } |
| 653 | + return 0; |
| 654 | +} |
| 655 | +#endif /* !MLD_CONFIG_SERIAL_FIPS202_ONLY && !MLD_CONFIG_REDUCE_RAM */ |
| 656 | + |
| 657 | +#if defined(MLD_UNIT_TEST) |
| 658 | +static int test_poly_uniform_eta_consistency(void) |
| 659 | +{ |
| 660 | + mld_poly r0_x4, r1_x4, r2_x4, r3_x4, r0_x1, r1_x1, r2_x1, r3_x1; |
| 661 | + uint8_t seed[MLDSA_CRHBYTES]; |
| 662 | + uint8_t nonce0, nonce1, nonce2, nonce3; |
| 663 | + int i; |
| 664 | + |
| 665 | + for (i = 0; i < NUM_RANDOM_TESTS_UNIFORM; i++) |
| 666 | + { |
| 667 | + randombytes(seed, MLDSA_CRHBYTES); |
| 668 | + randombytes(&nonce0, sizeof(uint8_t)); |
| 669 | + nonce1 = (uint8_t)(nonce0 + 1); |
| 670 | + nonce2 = (uint8_t)(nonce0 + 2); |
| 671 | + nonce3 = (uint8_t)(nonce0 + 3); |
| 672 | + |
| 673 | + /* Call 4x version */ |
| 674 | + mld_poly_uniform_eta_4x(&r0_x4, &r1_x4, &r2_x4, &r3_x4, seed, nonce0, |
| 675 | + nonce1, nonce2, nonce3); |
| 676 | + |
| 677 | + /* Call scalar version 4 times */ |
| 678 | + mld_poly_uniform_eta(&r0_x1, seed, nonce0); |
| 679 | + mld_poly_uniform_eta(&r1_x1, seed, nonce1); |
| 680 | + mld_poly_uniform_eta(&r2_x1, seed, nonce2); |
| 681 | + mld_poly_uniform_eta(&r3_x1, seed, nonce3); |
| 682 | + |
| 683 | + CHECK(memcmp(r0_x4.coeffs, r0_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 684 | + CHECK(memcmp(r1_x4.coeffs, r1_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 685 | + CHECK(memcmp(r2_x4.coeffs, r2_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 686 | + CHECK(memcmp(r3_x4.coeffs, r3_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 687 | + } |
| 688 | + return 0; |
| 689 | +} |
| 690 | +#endif /* MLD_UNIT_TEST */ |
| 691 | + |
| 692 | + |
584 | 693 | int main(void) |
585 | 694 | { |
586 | 695 | /* WARNING: Test-only |
@@ -612,6 +721,17 @@ int main(void) |
612 | 721 | MLD_USE_NATIVE_POLYVECL_POINTWISE_ACC_MONTGOMERY_L7 || \ |
613 | 722 | MLD_USE_NATIVE_POLYZ_UNPACK_17 || MLD_USE_NATIVE_POLYZ_UNPACK_19 */ |
614 | 723 |
|
| 724 | +#if !defined(MLD_CONFIG_SERIAL_FIPS202_ONLY) && MLD_CONFIG_PARAMETER_SET == 65 |
| 725 | + CHECK(test_poly_uniform_gamma1_consistency() == 0); |
| 726 | +#endif |
| 727 | + |
| 728 | +#if !defined(MLD_CONFIG_SERIAL_FIPS202_ONLY) && !defined(MLD_CONFIG_REDUCE_RAM) |
| 729 | + CHECK(test_poly_uniform_consistency() == 0); |
| 730 | +#endif |
| 731 | + |
| 732 | +#if defined(MLD_UNIT_TEST) |
| 733 | + CHECK(test_poly_uniform_eta_consistency() == 0); |
| 734 | +#endif |
615 | 735 |
|
616 | 736 | return 0; |
617 | 737 | } |
0 commit comments