Files
LithosAnanake/include/starkernel/scalar25519.h
T
Robert Allan JamesandClaude Sonnet 5 2e7e957680 Milestone 6 (ACL/PKI): Ed25519 verify + SHA-512, built from scratch
New freestanding, verify-only Ed25519 (RFC 8032) implementation:
include/starkernel/{sha512,fe25519,scalar25519,ed25519}.h +
src/starkernel/crypto/{sha512,fe25519,scalar25519,ed25519}.c, wired into
Makefile.starkernel. Kernel never signs or generates keys -- only
ed25519_verify() is needed; signing happens in the host-side mkcapsule
build tool via libsodium/OpenSSL.

Confirmed __int128 multiply/add/shift-by-constant compile with zero
undefined symbols on all three target toolchains (only division needs
libgcc's __udivti3, per timer.c's existing documented finding -- that
file's comment updated to narrow the claim, since it had been read as
"avoid __int128 entirely"). This enabled the standard 5-limb radix-2^51
field arithmetic representation.

An abandoned first attempt (10-limb radix-2^26, avoiding __int128 out of
premature caution) hit two real bugs, both invisible on inspection and
found only by property-based testing against Python's own bignum
arithmetic: a non-uniform-radix limb misalignment in multiplication, and
a double-counted carry. Verification chain: SHA-512 against known +
boundary vectors (7/7); field arithmetic property-tested 25,045 cases;
scalar-mod-L arithmetic 300 cases (L confirmed prime via Miller-Rabin
first); full verify() end-to-end against 110 real signatures from
Python's cryptography library, including tampered inputs and the RFC
8032 S>=L malleability attack -- all correctly accepted/rejected.

Compiles clean (zero warnings) and links on all three architectures,
confirmed via the mandatory three-arch QEMU boot. The code is linked but
not yet called from anywhere -- wiring into capsule_birth.c needs a
from-scratch X.509/DER parser first (Captain Bob chose real X.509 over a
raw-blob cert format this session), which is the next open item.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HZ8kNoTuP63pbQtro4qvrm
2026-08-22 12:41:26 -04:00

30 lines
1.2 KiB
C

/* scalar25519.h -- arithmetic mod L (the Ed25519 base point's order),
* for reducing SHA-512 output to a valid scalar and checking a
* signature's S component for the RFC 8032 malleability requirement
* (S < L, not just S < 2^256).
*
* Deliberately NOT the intricate hand-tuned "sc_reduce" reduction most
* reference implementations use (a bespoke Barrett-style reduction with
* constants specific to L, notoriously easy to transcribe wrong) --
* this is a plain binary long-division reduction, one bit at a time.
* O(512) steps per reduction; this is a verify-only, non-hot-path
* library (one reduction per signature check), so the simpler,
* more obviously-correct approach is the right tradeoff here.
*/
#ifndef SCALAR25519_H
#define SCALAR25519_H
#include <stdint.h>
/* 32-byte little-endian scalars, reduced mod L where noted. */
/* Reduce a 64-byte little-endian value (e.g. raw SHA-512 output) mod L,
* producing a 32-byte little-endian result < L. */
void scalar_reduce512(uint8_t out[32], const uint8_t in[64]);
/* 1 if the 32-byte little-endian scalar is < L (a well-formed,
* non-malleable signature component per RFC 8032), else 0. */
int scalar_lt_L(const uint8_t s[32]);
#endif /* SCALAR25519_H */