|
20 | 20 | #endif |
21 | 21 | #endif /* !NUM_RANDOM_TESTS */ |
22 | 22 |
|
| 23 | +#ifndef NUM_RANDOM_TESTS_REJ_UNIFORM |
| 24 | +#ifdef MLDSA_DEBUG |
| 25 | +#define NUM_RANDOM_TESTS_REJ_UNIFORM 100 |
| 26 | +#else |
| 27 | +#define NUM_RANDOM_TESTS_REJ_UNIFORM 1000 |
| 28 | +#endif |
| 29 | +#endif /* !NUM_RANDOM_TESTS_REJ_UNIFORM */ |
| 30 | + |
23 | 31 | #define CHECK(x) \ |
24 | 32 | do \ |
25 | 33 | { \ |
@@ -581,6 +589,99 @@ static int test_backend_units(void) |
581 | 589 | MLD_USE_NATIVE_POLYVECL_POINTWISE_ACC_MONTGOMERY_L7 || \ |
582 | 590 | MLD_USE_NATIVE_POLYZ_UNPACK_17 || MLD_USE_NATIVE_POLYZ_UNPACK_19 */ |
583 | 591 |
|
| 592 | +static int test_poly_uniform_gamma1_consistency(void) |
| 593 | +{ |
| 594 | + mld_poly r0_x4, r1_x4, r2_x4, r3_x4, r0_x1, r1_x1, r2_x1, r3_x1; |
| 595 | + MLD_ALIGN uint8_t seed[MLDSA_CRHBYTES]; |
| 596 | + uint16_t nonce0, nonce1, nonce2, nonce3; |
| 597 | + int i; |
| 598 | + for (i = 0; i < NUM_RANDOM_TESTS_REJ_UNIFORM; i++) |
| 599 | + { |
| 600 | + randombytes(seed, MLDSA_CRHBYTES); |
| 601 | + randombytes((uint8_t *)&nonce0, sizeof(uint16_t)); |
| 602 | + randombytes((uint8_t *)&nonce1, sizeof(uint16_t)); |
| 603 | + randombytes((uint8_t *)&nonce2, sizeof(uint16_t)); |
| 604 | + randombytes((uint8_t *)&nonce3, sizeof(uint16_t)); |
| 605 | + /* Call 4x version */ |
| 606 | + mld_poly_uniform_gamma1_4x(&r0_x4, &r1_x4, &r2_x4, &r3_x4, seed, nonce0, |
| 607 | + nonce1, nonce2, nonce3); |
| 608 | + /* Call scalar version 4 times */ |
| 609 | + mld_poly_uniform_gamma1(&r0_x1, seed, nonce0); |
| 610 | + mld_poly_uniform_gamma1(&r1_x1, seed, nonce1); |
| 611 | + mld_poly_uniform_gamma1(&r2_x1, seed, nonce2); |
| 612 | + mld_poly_uniform_gamma1(&r3_x1, seed, nonce3); |
| 613 | + |
| 614 | + CHECK(memcmp(r0_x4.coeffs, r0_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 615 | + CHECK(memcmp(r1_x4.coeffs, r1_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 616 | + CHECK(memcmp(r2_x4.coeffs, r2_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 617 | + CHECK(memcmp(r3_x4.coeffs, r3_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 618 | + } |
| 619 | + return 0; |
| 620 | +} |
| 621 | + |
| 622 | +static int test_poly_uniform_consistency(void) |
| 623 | +{ |
| 624 | + mld_poly r0_x4, r1_x4, r2_x4, r3_x4, r0_x1, r1_x1, r2_x1, r3_x1; |
| 625 | + MLD_ALIGN uint8_t seed[4][MLD_ALIGN_UP(MLDSA_SEEDBYTES + 2)]; |
| 626 | + int i, j; |
| 627 | + |
| 628 | + for (i = 0; i < NUM_RANDOM_TESTS_REJ_UNIFORM; i++) |
| 629 | + { |
| 630 | + for (j = 0; j < 4; j++) |
| 631 | + { |
| 632 | + randombytes(seed[j], MLDSA_SEEDBYTES + 2); |
| 633 | + } |
| 634 | + |
| 635 | + /* Call 4x version */ |
| 636 | + mld_poly_uniform_4x(&r0_x4, &r1_x4, &r2_x4, &r3_x4, seed); |
| 637 | + |
| 638 | + /* Call scalar version 4 times */ |
| 639 | + mld_poly_uniform(&r0_x1, seed[0]); |
| 640 | + mld_poly_uniform(&r1_x1, seed[1]); |
| 641 | + mld_poly_uniform(&r2_x1, seed[2]); |
| 642 | + mld_poly_uniform(&r3_x1, seed[3]); |
| 643 | + |
| 644 | + CHECK(memcmp(r0_x4.coeffs, r0_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 645 | + CHECK(memcmp(r1_x4.coeffs, r1_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 646 | + CHECK(memcmp(r2_x4.coeffs, r2_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 647 | + CHECK(memcmp(r3_x4.coeffs, r3_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 648 | + } |
| 649 | + return 0; |
| 650 | +} |
| 651 | + |
| 652 | +static int test_poly_uniform_eta_consistency(void) |
| 653 | +{ |
| 654 | + mld_poly r0_x4, r1_x4, r2_x4, r3_x4, r0_x1, r1_x1, r2_x1, r3_x1; |
| 655 | + MLD_ALIGN uint8_t seed[MLDSA_CRHBYTES]; |
| 656 | + uint8_t nonce0, nonce1, nonce2, nonce3; |
| 657 | + int i; |
| 658 | + |
| 659 | + for (i = 0; i < NUM_RANDOM_TESTS_REJ_UNIFORM; i++) |
| 660 | + { |
| 661 | + randombytes(seed, MLDSA_CRHBYTES); |
| 662 | + randombytes(&nonce0, sizeof(uint8_t)); |
| 663 | + randombytes(&nonce1, sizeof(uint8_t)); |
| 664 | + randombytes(&nonce2, sizeof(uint8_t)); |
| 665 | + randombytes(&nonce3, sizeof(uint8_t)); |
| 666 | + |
| 667 | + /* Call 4x version */ |
| 668 | + mld_poly_uniform_eta_4x(&r0_x4, &r1_x4, &r2_x4, &r3_x4, seed, nonce0, |
| 669 | + nonce1, nonce2, nonce3); |
| 670 | + |
| 671 | + /* Call scalar version 4 times */ |
| 672 | + mld_poly_uniform_eta(&r0_x1, seed, nonce0); |
| 673 | + mld_poly_uniform_eta(&r1_x1, seed, nonce1); |
| 674 | + mld_poly_uniform_eta(&r2_x1, seed, nonce2); |
| 675 | + mld_poly_uniform_eta(&r3_x1, seed, nonce3); |
| 676 | + |
| 677 | + CHECK(memcmp(r0_x4.coeffs, r0_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 678 | + CHECK(memcmp(r1_x4.coeffs, r1_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 679 | + CHECK(memcmp(r2_x4.coeffs, r2_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 680 | + CHECK(memcmp(r3_x4.coeffs, r3_x1.coeffs, MLDSA_N * sizeof(int32_t)) == 0); |
| 681 | + } |
| 682 | + return 0; |
| 683 | +} |
| 684 | + |
584 | 685 | int main(void) |
585 | 686 | { |
586 | 687 | /* WARNING: Test-only |
@@ -612,6 +713,9 @@ int main(void) |
612 | 713 | MLD_USE_NATIVE_POLYVECL_POINTWISE_ACC_MONTGOMERY_L7 || \ |
613 | 714 | MLD_USE_NATIVE_POLYZ_UNPACK_17 || MLD_USE_NATIVE_POLYZ_UNPACK_19 */ |
614 | 715 |
|
| 716 | + CHECK(test_poly_uniform_gamma1_consistency() == 0); |
| 717 | + CHECK(test_poly_uniform_eta_consistency() == 0); |
| 718 | + CHECK(test_poly_uniform_consistency() == 0); |
615 | 719 |
|
616 | 720 | return 0; |
617 | 721 | } |
0 commit comments