From 40ca3711df303b60f3740711d5dbe91b25afc8b1 Mon Sep 17 00:00:00 2001 From: Dusan Klinec Date: Wed, 15 Aug 2018 10:08:02 +0200 Subject: [PATCH] xmr: bp last mask fix (+20 squashed commits) Squashed commits: [fa1c3623] xmr: black [3f3e31f3] xmr: bulletproofs added to signer [d23d9284] xmr: protocol.tsx_sign_builder - logger collects [a28eb55f] xmr: bp - memory optimizations [d2fcb23a] xmr: tests for bulletproofs added [82eef146] xmr: bp - gc (+14 squashed commits) Squashed commits: [4cf70d97] xmr: bp - gc [42877b05] xmr: bp - minor memory optimization [2c612e45] xmr: bp - use sc_inv_into [d7e9dab4] xmr: bp - KeyVEval fix [1523f400] xmr: bp - blacked [b264a65b] xmr: bp - KeyVEval - caching current element, avoid allocations [83ba7a65] xmr: bp - memory view optimized [b517906c] xmr: bp - gc() during inversion [92d37c88] xmr: bp - gc.collect() after expensive inversion [e7fad558] xmr: bp - hashing memory optimization [4c278152] xmr: bp - deterministic masks optimization, prove_s1 optim [cbf74a70] xmr: bp - detect which modular inversion is usable [8ea1ec43] xmr: better memory tracing for bulletproofs [2f4dd552] xmr: bulletproofs added [1928e2d3] xmr: crypto - sc_inv_into added (+2 squashed commits) Squashed commits: [f895fa6e] xmr: crypto - hash to existing buffer [b76c6b09] xmr: crypto - in-place crypto functions added - required for Bulletproof to minimize the heap fragmentation [cab4366e] extmod: monero - modular inversion mod curve order added (+2 squashed commits) Squashed commits: [52a6e487] extmod: monero - hash into buffer added [695a3827] extmod: monero module - muladd256_modm added - required for Bulletproof [3f4498d7] xmr: crypto tests added - basic unit tests for crypto, tests monero module and underlying trezor-crypto + basic address manipulation [820d012d] pb sync [49eeddd1] vendor: trezor-common version bump [30382440] xmr: crypto - point norm not needed [89701c41] tests: xmr - serializer tests added [bfee46db] tests: support async unit tests, assertListEqual added [55c14487] xmr: serialize - serialization logic cleaned, refactored [4b771638] xmr: simplification, do not ask to confirm change tx output - change address checked to match main address in the builder [f334d8ad] xmr: protocol: simplification - require change address to equal the main address [1a3416eb] xmr: unpack256_modm_noreduce added - 32B array to integer mod curve order, without modular reduction after conversion - required for bulletproofs [1c94b5d4] xmr: readme added [3cc9f9fa] extmod/monero: mul256_modm added, required for BP --- .../modtrezorcrypto/modtrezorcrypto-monero.h | 94 +- src/apps/monero/README.md | 320 +++++ src/apps/monero/controller/iface.py | 6 +- src/apps/monero/controller/misc.py | 5 + src/apps/monero/protocol/tsx_sign_builder.py | 73 +- .../monero/protocol/tsx_sign_state_holder.py | 1 + src/apps/monero/xmr/bulletproof.py | 1071 +++++++++++++++++ src/apps/monero/xmr/crypto.py | 230 +++- src/apps/monero/xmr/monero.py | 45 +- src/apps/monero/xmr/ring_ct.py | 19 + src/apps/monero/xmr/serialize/xmrserialize.py | 627 +++++----- src/trezor/messages/MessageType.py | 12 + src/trezor/messages/OntologyAddress.py | 16 + src/trezor/messages/OntologyAsset.py | 4 + src/trezor/messages/OntologyGetAddress.py | 25 + src/trezor/messages/OntologyGetPublicKey.py | 25 + .../messages/OntologyOntIdAddAttributes.py | 29 + src/trezor/messages/OntologyOntIdAttribute.py | 21 + src/trezor/messages/OntologyOntIdRegister.py | 18 + src/trezor/messages/OntologyPublicKey.py | 16 + .../OntologySignOntIdAddAttributes.py | 31 + .../messages/OntologySignOntIdRegister.py | 31 + src/trezor/messages/OntologySignTransfer.py | 31 + .../messages/OntologySignWithdrawOng.py | 31 + .../OntologySignedOntIdAddAttributes.py | 19 + .../messages/OntologySignedOntIdRegister.py | 19 + src/trezor/messages/OntologySignedTransfer.py | 19 + .../messages/OntologySignedWithdrawOng.py | 19 + src/trezor/messages/OntologyTransaction.py | 41 + src/trezor/messages/OntologyTransfer.py | 24 + src/trezor/messages/OntologyTxAttribute.py | 18 + src/trezor/messages/OntologyWithdrawOng.py | 21 + src/trezor/messages/TezosCurveType.py | 5 + ...perationCommon.py => TezosDelegationOp.py} | 21 +- src/trezor/messages/TezosDelegationType.py | 15 - src/trezor/messages/TezosGetAddress.py | 5 +- src/trezor/messages/TezosGetPublicKey.py | 5 +- src/trezor/messages/TezosOperationType.py | 5 - src/trezor/messages/TezosOriginationOp.py | 47 + src/trezor/messages/TezosOriginationType.py | 30 - src/trezor/messages/TezosPublicKey.py | 4 +- src/trezor/messages/TezosRevealOp.py | 32 + src/trezor/messages/TezosSignTx.py | 32 +- src/trezor/messages/TezosSignedTx.py | 4 +- src/trezor/messages/TezosTransactionOp.py | 38 + src/trezor/messages/TezosTransactionType.py | 23 - tests/test_apps.monero.bulletproof.py | 149 +++ tests/test_apps.monero.crypto.py | 218 ++++ tests/test_apps.monero.serializer.py | 362 ++++++ tests/unittest.py | 16 +- vendor/trezor-common | 2 +- 51 files changed, 3462 insertions(+), 512 deletions(-) create mode 100644 src/apps/monero/README.md create mode 100644 src/apps/monero/xmr/bulletproof.py create mode 100644 src/trezor/messages/OntologyAddress.py create mode 100644 src/trezor/messages/OntologyAsset.py create mode 100644 src/trezor/messages/OntologyGetAddress.py create mode 100644 src/trezor/messages/OntologyGetPublicKey.py create mode 100644 src/trezor/messages/OntologyOntIdAddAttributes.py create mode 100644 src/trezor/messages/OntologyOntIdAttribute.py create mode 100644 src/trezor/messages/OntologyOntIdRegister.py create mode 100644 src/trezor/messages/OntologyPublicKey.py create mode 100644 src/trezor/messages/OntologySignOntIdAddAttributes.py create mode 100644 src/trezor/messages/OntologySignOntIdRegister.py create mode 100644 src/trezor/messages/OntologySignTransfer.py create mode 100644 src/trezor/messages/OntologySignWithdrawOng.py create mode 100644 src/trezor/messages/OntologySignedOntIdAddAttributes.py create mode 100644 src/trezor/messages/OntologySignedOntIdRegister.py create mode 100644 src/trezor/messages/OntologySignedTransfer.py create mode 100644 src/trezor/messages/OntologySignedWithdrawOng.py create mode 100644 src/trezor/messages/OntologyTransaction.py create mode 100644 src/trezor/messages/OntologyTransfer.py create mode 100644 src/trezor/messages/OntologyTxAttribute.py create mode 100644 src/trezor/messages/OntologyWithdrawOng.py create mode 100644 src/trezor/messages/TezosCurveType.py rename src/trezor/messages/{TezosOperationCommon.py => TezosDelegationOp.py} (53%) delete mode 100644 src/trezor/messages/TezosDelegationType.py delete mode 100644 src/trezor/messages/TezosOperationType.py create mode 100644 src/trezor/messages/TezosOriginationOp.py delete mode 100644 src/trezor/messages/TezosOriginationType.py create mode 100644 src/trezor/messages/TezosRevealOp.py create mode 100644 src/trezor/messages/TezosTransactionOp.py delete mode 100644 src/trezor/messages/TezosTransactionType.py create mode 100644 tests/test_apps.monero.bulletproof.py create mode 100644 tests/test_apps.monero.crypto.py create mode 100644 tests/test_apps.monero.serializer.py diff --git a/embed/extmod/modtrezorcrypto/modtrezorcrypto-monero.h b/embed/extmod/modtrezorcrypto/modtrezorcrypto-monero.h index 52e789be0..ea9b97a86 100644 --- a/embed/extmod/modtrezorcrypto/modtrezorcrypto-monero.h +++ b/embed/extmod/modtrezorcrypto/modtrezorcrypto-monero.h @@ -22,6 +22,8 @@ #include "py/mpz.h" #include "monero/monero.h" +#include "bignum.h" + #define RSIG_SIZE 6176 typedef struct _mp_obj_hasher_t { @@ -368,6 +370,19 @@ STATIC mp_obj_t mod_trezorcrypto_monero_sub256_modm(size_t n_args, const mp_obj_ } STATIC MP_DEFINE_CONST_FUN_OBJ_VAR_BETWEEN(mod_trezorcrypto_monero_sub256_modm_obj, 2, 3, mod_trezorcrypto_monero_sub256_modm); +//void sub256_modm +STATIC mp_obj_t mod_trezorcrypto_monero_mul256_modm(size_t n_args, const mp_obj_t *args){ + mp_obj_t res = n_args == 3 ? args[0] : mp_obj_new_scalar(); + const int off = n_args == 3 ? 0 : -1; + + assert_scalar(res); + assert_scalar(args[1+off]); + assert_scalar(args[2+off]); + mul256_modm(MP_OBJ_SCALAR(res), MP_OBJ_C_SCALAR(args[1+off]), MP_OBJ_C_SCALAR(args[2+off])); + return res; +} +STATIC MP_DEFINE_CONST_FUN_OBJ_VAR_BETWEEN(mod_trezorcrypto_monero_mul256_modm_obj, 2, 3, mod_trezorcrypto_monero_mul256_modm); + //void mulsub256_modm STATIC mp_obj_t mod_trezorcrypto_monero_mulsub256_modm(size_t n_args, const mp_obj_t *args){ mp_obj_t res = n_args == 4 ? args[0] : mp_obj_new_scalar(); @@ -382,6 +397,43 @@ STATIC mp_obj_t mod_trezorcrypto_monero_mulsub256_modm(size_t n_args, const mp_o } STATIC MP_DEFINE_CONST_FUN_OBJ_VAR_BETWEEN(mod_trezorcrypto_monero_mulsub256_modm_obj, 3, 4, mod_trezorcrypto_monero_mulsub256_modm); +//void muladd256_modm +STATIC mp_obj_t mod_trezorcrypto_monero_muladd256_modm(size_t n_args, const mp_obj_t *args){ + mp_obj_t res = n_args == 4 ? args[0] : mp_obj_new_scalar(); + const int off = n_args == 4 ? 0 : -1; + + assert_scalar(res); + assert_scalar(args[1+off]); + assert_scalar(args[2+off]); + assert_scalar(args[3+off]); + muladd256_modm(MP_OBJ_SCALAR(res), MP_OBJ_C_SCALAR(args[1+off]), MP_OBJ_C_SCALAR(args[2+off]), MP_OBJ_C_SCALAR(args[3+off])); + return res; +} +STATIC MP_DEFINE_CONST_FUN_OBJ_VAR_BETWEEN(mod_trezorcrypto_monero_muladd256_modm_obj, 3, 4, mod_trezorcrypto_monero_muladd256_modm); + +//void inv256_modm +STATIC mp_obj_t mod_trezorcrypto_monero_inv256_modm(size_t n_args, const mp_obj_t *args){ + mp_obj_t res = n_args == 2 ? args[0] : mp_obj_new_scalar(); + const int off = n_args == 2 ? 0 : -1; + + assert_scalar(res); + assert_scalar(args[1+off]); + + uint8_t buff[32]; + bignum256 bn_prime; + bignum256 bn_x; + const char * L = "\xed\xd3\xf5\x5c\x1a\x63\x12\x58\xd6\x9c\xf7\xa2\xde\xf9\xde\x14\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10"; + + contract256_modm(buff, MP_OBJ_C_SCALAR(args[1+off])); + bn_read_le((const uint8_t *)L, &bn_prime); + bn_read_le(buff, &bn_x); + bn_inverse(&bn_x, &bn_prime); + bn_write_le(&bn_x, buff); + expand_raw256_modm(MP_OBJ_SCALAR(res), buff); + return res; +} +STATIC MP_DEFINE_CONST_FUN_OBJ_VAR_BETWEEN(mod_trezorcrypto_monero_inv256_modm_obj, 1, 2, mod_trezorcrypto_monero_inv256_modm); + //void contract256_modm_r STATIC mp_obj_t mod_trezorcrypto_monero_pack256_modm(const mp_obj_t arg){ assert_scalar(arg); @@ -415,6 +467,23 @@ STATIC mp_obj_t mod_trezorcrypto_monero_unpack256_modm(size_t n_args, const mp_o } STATIC MP_DEFINE_CONST_FUN_OBJ_VAR_BETWEEN(mod_trezorcrypto_monero_unpack256_modm_obj, 1, 2, mod_trezorcrypto_monero_unpack256_modm); +//expand256_modm_r +STATIC mp_obj_t mod_trezorcrypto_monero_unpack256_modm_noreduce(size_t n_args, const mp_obj_t *args){ + mp_obj_t res = n_args == 2 ? args[0] : mp_obj_new_scalar(); + const int off = n_args == 2 ? 0 : -1; + assert_scalar(res); + + mp_buffer_info_t buff; + mp_get_buffer_raise(args[1+off], &buff, MP_BUFFER_READ); + if (buff.len != 32) { + mp_raise_ValueError("Invalid length of secret key"); + } + + expand_raw256_modm(MP_OBJ_SCALAR(res), buff.buf); + return res; +} +STATIC MP_DEFINE_CONST_FUN_OBJ_VAR_BETWEEN(mod_trezorcrypto_monero_unpack256_modm_noreduce_obj, 1, 2, mod_trezorcrypto_monero_unpack256_modm_noreduce); + // // GE25519 Defs // @@ -679,14 +748,25 @@ STATIC mp_obj_t mod_trezorcrypto_monero_xmr_random_scalar(size_t n_args, const m STATIC MP_DEFINE_CONST_FUN_OBJ_VAR_BETWEEN(mod_trezorcrypto_monero_xmr_random_scalar_obj, 0, 1, mod_trezorcrypto_monero_xmr_random_scalar); //xmr_fast_hash -STATIC mp_obj_t mod_trezorcrypto_monero_xmr_fast_hash(const mp_obj_t arg){ +STATIC mp_obj_t mod_trezorcrypto_monero_xmr_fast_hash(size_t n_args, const mp_obj_t *args){ + const int off = n_args == 2 ? 0 : -1; uint8_t buff[32]; + uint8_t * buff_use = buff; + if (n_args > 1){ + mp_buffer_info_t odata; + mp_get_buffer_raise(args[0], &odata, MP_BUFFER_WRITE); + if (odata.len < 32){ + mp_raise_ValueError("Output buffer too small"); + } + buff_use = odata.buf; + } + mp_buffer_info_t data; - mp_get_buffer_raise(arg, &data, MP_BUFFER_READ); - xmr_fast_hash(buff, data.buf, data.len); - return mp_obj_new_bytes(buff, 32); + mp_get_buffer_raise(args[1+off], &data, MP_BUFFER_READ); + xmr_fast_hash(buff_use, data.buf, data.len); + return n_args == 2 ? args[0] : mp_obj_new_bytes(buff, 32); } -STATIC MP_DEFINE_CONST_FUN_OBJ_1(mod_trezorcrypto_monero_xmr_fast_hash_obj, mod_trezorcrypto_monero_xmr_fast_hash); +STATIC MP_DEFINE_CONST_FUN_OBJ_VAR_BETWEEN(mod_trezorcrypto_monero_xmr_fast_hash_obj, 1, 2, mod_trezorcrypto_monero_xmr_fast_hash); //xmr_hash_to_ec STATIC mp_obj_t mod_trezorcrypto_monero_xmr_hash_to_ec(size_t n_args, const mp_obj_t *args){ @@ -991,10 +1071,14 @@ STATIC const mp_rom_map_elem_t mod_trezorcrypto_monero_globals_table[] = { { MP_ROM_QSTR(MP_QSTR_reduce256_modm), MP_ROM_PTR(&mod_trezorcrypto_monero_reduce256_modm_obj) }, { MP_ROM_QSTR(MP_QSTR_add256_modm), MP_ROM_PTR(&mod_trezorcrypto_monero_add256_modm_obj) }, { MP_ROM_QSTR(MP_QSTR_sub256_modm), MP_ROM_PTR(&mod_trezorcrypto_monero_sub256_modm_obj) }, + { MP_ROM_QSTR(MP_QSTR_mul256_modm), MP_ROM_PTR(&mod_trezorcrypto_monero_mul256_modm_obj) }, { MP_ROM_QSTR(MP_QSTR_mulsub256_modm), MP_ROM_PTR(&mod_trezorcrypto_monero_mulsub256_modm_obj) }, + { MP_ROM_QSTR(MP_QSTR_muladd256_modm), MP_ROM_PTR(&mod_trezorcrypto_monero_muladd256_modm_obj) }, + { MP_ROM_QSTR(MP_QSTR_inv256_modm), MP_ROM_PTR(&mod_trezorcrypto_monero_inv256_modm_obj) }, { MP_ROM_QSTR(MP_QSTR_pack256_modm), MP_ROM_PTR(&mod_trezorcrypto_monero_pack256_modm_obj) }, { MP_ROM_QSTR(MP_QSTR_pack256_modm_into), MP_ROM_PTR(&mod_trezorcrypto_monero_pack256_modm_into_obj) }, { MP_ROM_QSTR(MP_QSTR_unpack256_modm), MP_ROM_PTR(&mod_trezorcrypto_monero_unpack256_modm_obj) }, + { MP_ROM_QSTR(MP_QSTR_unpack256_modm_noreduce), MP_ROM_PTR(&mod_trezorcrypto_monero_unpack256_modm_noreduce_obj) }, { MP_ROM_QSTR(MP_QSTR_ge25519_set_neutral), MP_ROM_PTR(&mod_trezorcrypto_monero_ge25519_set_neutral_obj) }, { MP_ROM_QSTR(MP_QSTR_ge25519_set_h), MP_ROM_PTR(&mod_trezorcrypto_monero_ge25519_set_xmr_h_obj) }, { MP_ROM_QSTR(MP_QSTR_ge25519_pack), MP_ROM_PTR(&mod_trezorcrypto_monero_ge25519_pack_obj) }, diff --git a/src/apps/monero/README.md b/src/apps/monero/README.md new file mode 100644 index 000000000..eed7c8ba9 --- /dev/null +++ b/src/apps/monero/README.md @@ -0,0 +1,320 @@ +# Monero + +MAINTAINER = ... + +AUTHOR = Dusan Klinec + +REVIEWER = ... + +ADVISORS = + +----- + +This Monero implementation was implemented from scratch originally for TREZOR by porting Monero C++ code to the Python codebase. + +The implementation heavily relies on the [trezor-crypto] Monero functionality which implements basic crypto primitives and +other Monero related functionality (e.g., monero base58, accelerated and optimized Borromean range signatures) + +A general high level description of the integration proposal is described in the documentation: [monero-doc]. + +## Features + +The implementation provides the following features: + +### Transaction signature + +Signs a Monero transaction on the TREZOR. + +- Designed so number of UTXO is practically unlimited (hundreds to thousands) +- Maximal number of outputs per transaction is 8 (usually there are only 2) +- Supports 8 B encrypted payment ID and 32 B unencrypted payment ID. + +### Key Image sync + +Key Image is computed with the spend key which is stored on the TREZOR. + +In order to detect if the UTXO has been already spent (thus computing balance due to change transactions) +and correct spending UTXOs the key images are required. + +Key image sync is a protocol that allows to compute key images for incoming transfers by TREZOR. + + +## Integration rationale + +The Monero codebase already contains cold wallet support. I.e., wallet not connected to the Internet, which should provide +better security guarantees as it minimizes attack surface compared to the hot wallet - always connected wallet. + +As the cold wallet is not connected to the Internet and does not have access nor to the blockchain neither to the monero +full node the all information for transaction construction have to be prepared by the hot wallet. + +When using the cold wallet, hot wallet is watch-only. It has only the view-key so it can scan blockchain for incoming +transactions but is not able to spend any transaction. + +Transaction signature with cold wallet works like this: + +- Create transaction construction data on hot wallet. `transfer
`. Works similar to the normal wallet operation +but instead of the signed transaction, the watch-only hot wallet generates `unsigned_txset` file which contains +transaction construction data. + +- Cold wallet opens `unsigned_txset`, verifies the signature on the transaction construction data and creates Monero transaction +using the data. Cold wallet creates `signed_txset` + +- Hot wallet opens `signed_txset`, verifies the transaction and asks user whether to submit transaction to the full node. + +### Cold wallet protocols + +As cold wallet support is already present in Monero codebase, the protocols were well designed and analyzed. +We decided to reuse the cold wallet approach when signing the transaction as the TREZOR pretty much behaves as the cold wallet, +i.e., does not have access to the blockchain or full Monero node. The whole transaction is built in the TREZOR thus +the integration has security properties of the cold wallet (which is belevied to be secure). This integration approach +makes security analysis easier and enables to use existing codebase and protocols. This makes merging TREZOR support to +the Monero codebase easier. +We believe that by choosing a bit more high-level approach in the protocol design we could easily add more advanced features, + +TREZOR implements cold wallet protocols in this integration scheme. + + +## Description + +Main high level protocol logic is implemented in `apps/monero/protocol/` directory. + +### Serialization + +The serialization in `apps/monero/xmr/serialize` is the cryptonote serialization format used to serialize data to blockchain. +The serialization was ported from Monero C++. Source comes from the library [monero-serialize]. + +Serialization scheme was inspired by protobuf serialization scheme. Later it was subject to optimizations as +scheme definition with `FIELDS` attribute was quite memory hungry. Serialization was refactred to specify +fields as a classmethod which is easier to `gc.collect()` after serialization is done compared to static `FIELDS` +which are not easy to deallocate. + +```python + @classmethod + def f_specs(cls): + return (("size", SizeT),) +``` + +Serialization works in `async/wait` manner, uses `reader/writer` interface as protobuf uses. + +Moreover the serialization funtionality is encapsulated in so-called Archive object which encapsulates serialization logic. +Archive works in a symmetric way, i.e., the same API is used for serialization and deserialization. + + +### Protocols + +Transaction signing and Key Image (KI) sync are multi-step stateful protocols. +The protocol have several roundtrips. + +In the signing protocol the connected host mainly serves as a dumb storage providing values to the TREZOR when needed, +mainly due to memory constrains on TREZOR. The offloaded data can be in plaintext. In this case data is HMACed with unique HMAC +key to avoid data tampering, reordering, replay, reuse, etc... Some data are offloaded as protected, encrypted and authenticated +with Chacha20Poly1305 with unique key (derived from the protocol step, message, purpose, counter, master secret). + +TREZOR builds the signed Monero transaction incrementally, i.e., one UTXO per round trip, one transaction output per roundtrip. + +### Protocol wrapping messages + +Due to the dispatcher design we decided to use wrapping message for the multi-step protocols. +The top wrapping message contains sub-message field for each possible message in the protocol. In this way we can register +one simple dispatcher on the wrapping message and do the sub-message multiplexing in the code, hidden in the abstraction. + +Without wrapping message we would have to register each sub-message to the same handler and then de-multiplex it again +in the protocol logic which is error prone and duplicates the code. When changing the flow later it would be prone to errors. + +Responses are not wrapped and each response has own wire ID. Response messages are not registered so we don't need wrapping. + +Protobuf messages are following the convention `MoneroXRequest`, `MoneroXAck`. + + +## Key Image sync work flow + +In the KI sync cold wallet protocol KIs are generated by the cold wallet. For each KI there is a ring signature +generated by the cold wallet (KI proof). + +KI sync is mainly needed to recover from some problem or when using a new hot-wallet (corruption of a wallet file or +using TREZOR on a different host). + +The KI protocol has 3 steps. Wrapping message `MoneroKeyImageSyncRequest`. + +### Init step + +- `MoneroKeyImageExportInitRequest` +- Contains commitment to all KIs we are going to compute (hash of all UTXOs). +- User can confirm / reject the KI sync in this step. Init message contains number of KIs for computation. + +### Sync + +- `MoneroKeyImageSyncStepRequest` +- Computes N KIs in this step. N = 10 for now. +- Returns encrypted result, `MoneroExportedKeyImage` + +### Finalization + +- `MoneroKeyImageSyncFinalRequest` +- When commitment on all KIs is correct (i.e, number of UTXOs matches, hashes match) the encryption key is released +to the agent/hot-wallet so it can decrypt computed KIs and import it + + +## Transaction signing + +For detailed description and rationale please refer to the [monero-doc]. + +- The wrapping message: `MoneroTransactionSignRequest`. +- The main multiplexor: `apps/monero/protocol/tsx_sign.py` +- The main signing logic is implemented in `apps/monero/protocol/tsx_sign_builder.py` +- State automaton watching correct state transitions: `apps/monero/protocol/tsx_sign_state.py` +- State hold between protocol messages: `apps/monero/protocol/tsx_sign_state_holder.py`. The state is externalized in the +dedicated class so the memory consumption is minimal between round trips. + + +### `MoneroTransactionInitRequest`: + +- Contains basic construction data for the transaction, e.g., transaction destinations, fee, mixin level. + +After receiving this message: +- The TREZOR prompts user for verification of the destination addresses and amounts. +- Commitments are computed thus later potential deviations from transaction destinations are detected and signing aborts. +- Secrets for HMACs / encryption are computed, TX key is computed. +- Precomputes sub-addresses if needed. + +### `MoneroTransactionSetInputRequest` + +- Sends one UTXO to the TREZOR for processing, encoded as `MoneroTransactionSourceEntry`. +- Contains construction data needed for signing the transaction, computing spending key for UTXO. + +TREZOR computes spending keys, `TxinToKey`, `pseudo_out`, HMACs for offloaded data + +### `MoneroTransactionInputsPermutationRequest` + +UTXOs have to be sorted by the key image in the valid blockchain transaction. +This message caries permutation on the key images so they are sorted in the desired way. + +### `MoneroTransactionInputViniRequest` + +- Step needed to correctly hash all transaction inputs, in the right order computed in the previous step. +- Contains `MoneroTransactionSourceEntry` and `TxinToKey` computed in the previous step. +- TREZOR Computes `tx_prefix_hash` is part of the signed data. + +### `MoneroTransactionSetOutputRequest` + +Sends transaction output, `MoneroTransactionDestinationEntry`, one per message. +HMAC prevents tampering with previously accepted data (in the init step). + +TREZOR computes data related to transaction output, e.g., range proofs, ECDH info for the receiver, output public key. + +### `MoneroTransactionAllOutSetRequest` + +Sent after all transaction outputs have been sent to the TREZOR for processing. +Request is empty, the response contains computed `extra` field (may contain additional public keys if sub-addresses are used), +computed `tx_prefix_hash` and basis for the final transaction signature `MoneroRingCtSig` (fee, transaction type). + +### `MoneroTransactionMlsagDoneRequest` + +Message sent to ask TREZOR to compute pre-MLSAG hash required for the signature. +Hash is computed incrementally by TREZOR since the init message and can be finalized in this step. +Request is empty, response contains message hash, required for the signature. + +### `MoneroTransactionSignInputRequest` + +- Caries `MoneroTransactionSourceEntry`, similarly as previous messages `MoneroTransactionSetInputRequest`, `MoneroTransactionInputViniRequest`. +- Caries computed transaction inputs, pseudo outputs, HMACs, encrypted spending keys and alpha masks +- TREZOR generates MLSAG for this UTXO, returns the signature. +- Code returns also `cout` value if the multisig mode is active - not fully implemented, will be needed later when implementing multisigs. + +### `MoneroTransactionFinalRequest` + +- Sent when all UTXOs have been signed properly +- Finalizes transaction signature +- Returns encrypted transaction private keys which are needed later, e.g. for TX proof. As TREZOR cannot store aux data +for all signed transactions its offloaded encrypted to the wallet. Later when TX proof is implemented in the TREZOR it +will load encrypted TX keys, decrypt it and generate the proof. + + +## Implementation notes + +Few notes on desing / implementation. + +### Cryptography + +Operation with Ed25519 points and scalars are implemented in [trezor-crypto] so the underlying cryptography layer +is fast, secure and constant-time. + +Ed Point coordinates are Extended Edwards, using type `ge25519` with coordinates `(x, y, z, t)`. Functions in Monero code +in the [trezor-crypto] use the `ge25519` for points (no other different point formats). + +Functions like `op256_modm` (e.g., `add256_modm`) operate on scalar values, i.e., 256 bit integers modulo curve order +`2**252 + 3*610042537739*15158679415041928064055629`. + +Functions `curve25519_*` operate on 256 bit integers modulo `2**255 - 19`, the coordinates of the point. +These are used mainly internally (e.g., for `hash_to_point()`) and not exported to the [trezor-core]. + +[trezor-crypto] contains also some Monero-specific functions, such as +`xmr_hash_to_scalar`, `xmr_hash_to_ec`, `xmr_generate_key_derivation`. Those are used in [trezor-core] where more high +level operations are implemented, such as MLSAG. + +#### Crypto API + +API bridging [trezor-crypto] and [trezor-core]: `embed/extmod/modtrezorcrypto/modtrezorcrypto-monero.h` + +It encapsulates Ed25519 points and scalars in corresponding Python classes which have memory-wiping destructor. +API provides basic functions for work with scalars and points and Monero specific functions. + +The API is designed in such a way it is easy to work with Ed25519 as there is only one point format which is always +normed to avoid complications when chaining operations such as `scalarmult`s. + +### Point normalization + +Points in [trezor-core] are normed, i.e., `z=1`. + +Normalization is mainly needed after `ge25519_scalarmult`, `ge25519_scalarmult_base_niels`, +which is already done in Monero code in [trezor-crypto]. + +if the norming is not performed, the operations could not be chained arbitrarily as the result is invalid. + +Note: +Point normalization operation is typically performed when compressing coordinate point representation to the 32 B array +as `z` needs to be 1. It requires to compute inversion which is not for free. + +On the other hand, the original Monero C++ code typically operates on 32 B keys by +decompressing and compressing it after each result so they are doing normalization in each step, basically. + +There are some optimized chunks, e.g., range sig verification, which improves blockchain scanning +(still takes 3 days to verify the blockchain). +Optimized chunks are using different point representations to avoid redundant normalizations but in general cases, +it is not a performance issue for the sake of correct computation, easy development and maintenance. + +### Range signatures + +Borromean range signatures were optimized and ported to [trezor-crypto]. + +Range signatures xmr_gen_range_sig are CPU intensive and memory intensive operations which were originally implemented +in python (trezor-core) but it was not feasible to run on the Trezor device due to a small amount of RAM and long +computation times. It was needed to optimize the algorithm and port it to C so it is feasible to run it on the real hardware and run it fast. + +Range signature is a well-contained problem with no allocations needed, simple API. +For memory and timing reasons its implemented directly in trezor-crypto (as it brings real benefit to the user). + +On the other hand, MLASG and other ring signatures are built from building blocks in python for easier development, +code readability, maintenance and debugging. Porting to C is not that straightforward and I don't see any benefit here. +The memory and CPU is not the problem as in the case of range signatures so I think it is fine to have it in Python. +Porting to C would also increase complexity of trezor-crypto and could lead to bugs. + +Using small and easily auditable & testable building blocks, such as ge25519_add (fast, in C) to build more complex +schemes in high level language is, in my opinion, a scalable and secure way to build the system. +Porting all Monero crypto schemes to C would be very time consuming and prone to errors. + +Having access to low-level features also speeds up development of new features, such as multisigs / bulletproofs. + +MLSAG may need to be slightly changed when implementing multisigs +(some preparations have been made already but we will see after this phase starts). + + + + + + + +[trezor-crypto]: https://github.com/trezor/trezor-crypto +[trezor-core]: https://github.com/trezor/trezor-core +[monero-doc]: https://github.com/ph4r05/monero-trezor-doc +[monero-serialize]: https://github.com/ph4r05/monero-serialize diff --git a/src/apps/monero/controller/iface.py b/src/apps/monero/controller/iface.py index 76acba6cc..0579b63eb 100644 --- a/src/apps/monero/controller/iface.py +++ b/src/apps/monero/controller/iface.py @@ -38,12 +38,16 @@ async def confirm_transaction(self, tsx_data, creds=None, ctx=None): from apps.monero import layout for idx, dst in enumerate(outs): + is_change = change_idx and idx == change_idx + if is_change: + continue + addr = encode_addr( net_version(creds.network_type), dst.addr.spend_public_key, dst.addr.view_public_key, ) - is_change = change_idx and idx == change_idx + await layout.require_confirm_tx( self.gctx(ctx), addr.decode("ascii"), dst.amount, is_change ) diff --git a/src/apps/monero/controller/misc.py b/src/apps/monero/controller/misc.py index 761e17c0c..22ab20543 100644 --- a/src/apps/monero/controller/misc.py +++ b/src/apps/monero/controller/misc.py @@ -20,6 +20,11 @@ def __init__(self, *args, **kwargs): super().__init__(*args, **kwargs) +class TrezorChangeAddressError(TrezorError): + def __init__(self, *args, **kwargs): + super().__init__(*args, **kwargs) + + class StdObj(object): def __init__(self, **kwargs): for kw in kwargs: diff --git a/src/apps/monero/protocol/tsx_sign_builder.py b/src/apps/monero/protocol/tsx_sign_builder.py index c6fcb7beb..27976a7bd 100644 --- a/src/apps/monero/protocol/tsx_sign_builder.py +++ b/src/apps/monero/protocol/tsx_sign_builder.py @@ -50,6 +50,7 @@ def __init__(self, trezor=None, creds=None, state=None, **kwargs): self.output_change = None self.mixin = 0 self.fee = 0 + self.account_idx = 0 self.additional_tx_private_keys = [] self.additional_tx_public_keys = [] @@ -142,7 +143,7 @@ def state_save(self): setattr(t, attr, cval) return t - def _log_trace(self, x=None): + def _log_trace(self, x=None, collect=False): log.debug( __name__, "Log trace %s, ... F: %s A: %s, S: %s", @@ -151,6 +152,8 @@ def _log_trace(self, x=None): gc.mem_alloc(), micropython.stack_use(), ) + if collect: + gc.collect() def assrt(self, condition, msg=None): """ @@ -179,9 +182,25 @@ def gen_r(self, use_r=None): self.r = crypto.random_scalar() if use_r is None else use_r self.r_pub = crypto.scalarmult_base(self.r) + def get_primary_change_address(self): + """ + Computes primary change address for the current account index + :return: + """ + D, C = monero.generate_sub_address_keys( + self.creds.view_key_private, + self.creds.spend_key_public, + self.account_idx, + 0, + ) + return misc.StdObj( + view_public_key=crypto.encodepoint(C), + spend_public_key=crypto.encodepoint(D), + ) + def check_change(self, outputs): """ - Checks if the change address is among tx outputs. + Checks if the change address is among tx outputs and it is equal to our address. :param outputs: :return: """ @@ -191,11 +210,20 @@ def check_change(self, outputs): if change_addr is None: return + found = False for out in outputs: if addr_eq(out.addr, change_addr): - return True + found = True + break + + if not found: + raise misc.TrezorChangeAddressError("Change address not found in outputs") + + my_addr = self.get_primary_change_address() + if not addr_eq(my_addr, change_addr): + raise misc.TrezorChangeAddressError("Change address differs from ours") - raise ValueError("Change address not found in outputs") + return True def in_memory(self): """ @@ -453,6 +481,7 @@ async def init_transaction(self, tsx_data, tsx_ctr): self.output_change = misc.dst_entry_to_stdobj(tsx_data.change_dts) self.mixin = tsx_data.mixin self.fee = tsx_data.fee + self.account_idx = tsx_data.account self.use_simple_rct = self.input_count > 1 self.use_bulletproof = tsx_data.is_bulletproof self.multi_sig = tsx_data.is_multisig @@ -893,9 +922,6 @@ async def range_proof(self, idx, dest_pub_key, amount, amount_key): """ from apps.monero.xmr import ring_ct - rsig = bytearray(32 * (64 + 64 + 64 + 1)) - rsig_mv = memoryview(rsig) - out_pk = misc.StdObj(dest=dest_pub_key, mask=None) is_last = idx + 1 == self.num_dests() last_mask = ( @@ -908,30 +934,35 @@ async def range_proof(self, idx, dest_pub_key, amount, amount_key): C, mask, rsig = None, 0, None # Rangeproof - gc.collect() + self._log_trace("pre-rproof", collect=True) + if self.use_bulletproof: - raise ValueError("Bulletproof not yet supported") + self._log_trace("pre-bp", collect=True) + C, mask, rsig = ring_ct.prove_range_bp(amount, last_mask) + self._log_trace("post-bp", collect=True) else: + rsig_buff = bytearray(32 * (64 + 64 + 64 + 1)) + rsig_mv = memoryview(rsig_buff) + C, mask, rsig = ring_ct.prove_range( amount, last_mask, backend_impl=True, byte_enc=True, rsig=rsig_mv ) rsig = memoryview(rsig) - self.assrt( - crypto.point_eq( - C, - crypto.point_add( - crypto.scalarmult_base(mask), crypto.scalarmult_h(amount) - ), + self.assrt( + crypto.point_eq( + C, + crypto.point_add( + crypto.scalarmult_base(mask), crypto.scalarmult_h(amount) ), - "rproof", - ) + ), + "rproof", + ) + + # Incremental hashing + await self.full_message_hasher.rsig_val(rsig, self.use_bulletproof, raw=True) - # Incremental hashing - await self.full_message_hasher.rsig_val( - rsig, self.use_bulletproof, raw=True - ) gc.collect() self._log_trace("rproof") diff --git a/src/apps/monero/protocol/tsx_sign_state_holder.py b/src/apps/monero/protocol/tsx_sign_state_holder.py index 3d0cd12fa..1d1797d93 100644 --- a/src/apps/monero/protocol/tsx_sign_state_holder.py +++ b/src/apps/monero/protocol/tsx_sign_state_holder.py @@ -26,6 +26,7 @@ def __init__(self, **kwargs): self.output_change = None self.mixin = 0 self.fee = 0 + self.account_idx = 0 self.additional_tx_private_keys = [] self.additional_tx_public_keys = [] diff --git a/src/apps/monero/xmr/bulletproof.py b/src/apps/monero/xmr/bulletproof.py new file mode 100644 index 000000000..aea255479 --- /dev/null +++ b/src/apps/monero/xmr/bulletproof.py @@ -0,0 +1,1071 @@ +#!/usr/bin/env python +# -*- coding: utf-8 -*- +# Author: Dusan Klinec, ph4r05, 2018 + +import gc + +from apps.monero.xmr import crypto +from apps.monero.xmr.serialize.int_serialize import dump_uvarint_b, dump_uvarint_b_into +from apps.monero.xmr.serialize_messages.tx_rsig_bulletproof import Bulletproof + +# Constants + +BP_LOG_N = 6 +BP_N = 1 << BP_LOG_N # 64 + +ZERO = b"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00" +ONE = b"\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00" +TWO = b"\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00" + +# Monero H point +XMR_H = b"\x8b\x65\x59\x70\x15\x37\x99\xaf\x2a\xea\xdc\x9f\xf1\xad\xd0\xea\x6c\x72\x51\xd5\x41\x54\xcf\xa9\x2c\x17\x3a\x0d\xd3\x9c\x1f\x94" + +# Generated by init_exponents() +BP_GI_PRE = b"\x0b\x48\xbe\x50\xe4\x9c\xad\x13\xfb\x3e\x01\x4f\x3f\xa7\xd6\x8b\xac\xa7\xc8\xa9\x10\x83\xdc\x9c\x59\xb3\x79\xaa\xab\x21\x8f\x15\xdf\x01\xa5\xd6\x3b\x3e\x3a\x38\x38\x2a\xfb\xd7\xbc\x68\x5f\x34\x3d\x61\x92\xda\x16\xed\x4b\x45\x1f\x15\xfd\xda\xb1\x70\xe2\x2d\x73\x69\xc8\xd5\xa7\x45\x42\x3d\x26\x06\x23\xa1\xf7\x5f\xae\x1f\xb1\xf8\x1b\x16\x9d\x42\x2a\xcd\x85\x58\xe9\xd5\x74\x25\x48\xbd\x81\xc0\x7d\x2b\xd8\x77\x1e\xb4\xbd\x84\x15\x5d\x38\xd7\x05\x31\xfe\x66\x2b\x78\xf0\xc4\x4a\x9a\xea\xea\x2e\xd2\xd6\xf0\xeb\xe1\x08\x96\xc5\xc2\x2f\x00\x70\xeb\xf0\x55\xdf\xe8\xdc\x1c\xb2\x05\x42\xef\x29\x15\x1a\xa0\x77\x1e\x58\x1e\x68\xfe\x78\x18\xef\x42\x35\xc8\xdf\x1a\x32\xae\xce\xed\xef\xcb\xdf\x6d\x91\xd5\x24\x92\x9b\x84\x02\xa0\x26\xcb\x85\x74\xe0\xe3\xa3\x34\x2c\xe2\x11\xbc\xd9\x67\xbc\x14\xe7\xab\xda\x6c\x17\xc2\xf2\x2a\x38\x1b\x84\xc2\x49\x75\x78\x52\xe9\x9d\x62\xc4\x5f\x16\x0e\x89\x15\xec\x21\xd4\xc8\xa3\x83\x1d\x7c\x2f\x24\x58\x1e\xc9\xd1\x50\x13\xdf\xcc\xb5\xeb\xa6\x9d\xf6\x91\xa0\x80\x02\xb3\x3d\x4f\x2f\xb0\x6c\xa9\xf2\x9c\xfb\xc7\x0d\xb0\x23\xa4\x8e\x45\x35\xf5\x83\x8f\x5e\xa2\x7f\x70\x98\x0d\x11\xec\xd9\x35\xb4\x78\x25\x8e\x2a\x4f\x10\x06\xb3\x2d\xa6\x38\x72\x92\x25\x9e\x69\xac\x0a\x82\x9e\xf3\x47\x69\x98\x96\x72\x8c\x0c\xc0\xca\xdc\x74\x6d\xae\x46\xfb\x31\x86\x4a\x59\xa5\xb9\xa1\x54\x9c\x77\xe4\xcf\x8a\xb8\xb2\x55\xa3\xa0\xae\xfa\xa4\xca\xd1\x25\xd2\x19\x94\x9c\x0a\xef\xf0\xc3\x56\x0a\xb1\x58\xed\x67\x17\x48\xa1\x75\x56\x41\x9e\xc9\x42\xe1\x6b\x90\x1d\xbb\x2f\xc6\xdf\x96\x60\x32\x4f\xcb\xcd\x6e\x40\xf2\x35\xd7\x5b\x76\x4f\xaf\xf6\x1c\x19\x05\x22\x2b\xaf\x87\xd5\x1d\x45\xf3\x55\x81\x38\xc8\x7c\xe5\x4c\x46\x4c\xc6\x40\xb9\x55\xe7\xfa\x33\x10\xf8\x3b\x13\xdd\x7b\x24\x73\x19\xe1\x3c\xe6\x19\x95\xbc\x77\x1e\xe1\xed\xe7\x36\x35\x99\xf0\x8f\xc5\xcf\xda\x89\x0e\xa8\x03\xe0\xec\xa7\x0a\x97\x70\x7e\x90\x56\x29\xa5\xe0\x6d\x18\x6a\x96\x4f\x32\x2f\xff\xba\xa7\xed\x2e\x78\x1d\x4d\x3f\xed\xe0\x74\x61\xf4\x4b\x2d\x98\xdb\xcc\x0c\xaa\x20\x55\x14\x6e\x13\xf5\x0e\xcf\x75\x49\x1d\xad\xd3\x6a\xd2\xba\xac\x56\xbc\x08\x56\x2e\xc6\x6c\xe1\x10\xb5\x44\x83\x1d\xbd\x34\xc6\xc2\x52\x95\x81\x51\xc4\x9a\x73\x4c\x6e\x62\x5e\x42\x60\x8c\x00\x5e\x79\x7e\xdb\x6d\x0a\x89\x34\xb3\x24\xa0\xe4\xd3\x1c\xba\x01\x57\x83\x50\x1e\xcd\xfa\x7a\x8e\xba\xe3\xa6\xbf\xd3\x2e\x6d\x1a\x36\x14\xb1\x11\x83\xc8\x09\x80\xd4\x54\x6c\xc3\xee\x5d\xb4\x7b\xfe\x97\x05\xaa\x95\xe2\xda\x29\xf2\x28\x23\x03\x53\x91\x7e\x5d\x2b\x19\x32\xfe\x48\x2f\xbc\xfe\xd7\x13\x4d\x55\x6d\x0c\x27\xf6\xcc\x6b\xf3\x01\x5c\x06\x61\x16\x25\x73\x9d\x88\x9c\x57\x89\xfa\x75\xb3\xc8\x39\x69\xcb\x88\xb1\xdf\x01\xc0\xac\xa4\x70\xf6\x65\xeb\x71\x82\xe0\x72\xbc\xa8\x9b\xc6\x69\xff\xe5\xb0\x29\x6f\xe2\x13\x43\xa8\xc3\x27\xc8\xa8\x41\x75\x02\x85\x5a\x25\xcc\xb7\x5b\x2f\x8e\xea\xc5\xd1\xdb\x25\x04\x4b\x0a\xea\xd2\xcf\x77\x02\x1e\xd9\x4f\x79\xf3\x00\x1e\x7b\x8e\x9d\xb7\x31\x1d\xb2\x8c\x45\xc9\x0d\x80\xa1\xe3\xd5\xb2\x7b\x43\xf8\xe3\x80\x21\x4d\x6a\x2c\x40\x46\xc8\xd4\x0f\x52\x4d\x47\x83\x53\x20\x4d\x01\xa1\x7c\x4f\xb7\xb1\x8c\x2f\x48\x27\x01\x50\xdb\x67\xd4\xb0\xb9\xce\x87\x86\xe0\x3c\x95\x50\xc5\x47\xfb\x18\x02\x9e\xf1\x6e\x56\x29\xe9\xa1\xc6\x68\xe1\xaa\x79\xc7\x88\x73\x55\xf5\xf5\x1b\x0c\xbb\x1f\x08\x35\xe0\x4e\x7a\xcc\x53\xac\x55\xa3\x57\x41\x97\xb5\x4c\x5a\xaa\xad\x47\xbe\x24\xdb\xbc\x11\xc1\xbd\x3e\xeb\x62\x46\x54\x2d\x2f\x5a\xe5\xf4\x39\x8d\xd4\xa7\x60\x17\x03\xcb\xbf\xd5\x9b\xad\xdd\x3a\x7c\xe6\xe3\x75\xe7\xd9\x00\x50\xe2\x71\xb1\x3f\x13\x2d\xf8\x5e\x1c\x12\xbe\x54\xfe\x66\xde\x81\xf6\x8a\x1c\x8f\x69\x6f\x3e\x77\x3c\x7e\xef\x57\xac\x13\x89\xbd\x02\x80\xd5\x58\xea\x78\x62\xf0\x1b\x64\x1e\xc6\xda\x0e\xfe\xfb\xee\xd0\x50\x9c\x53\x8a\x8c\x36\x16\x68\x1d\x76\x1a\xe5\xc6\xf9\xd2\xaa\xde\xd7\x18\x90\xda\x24\x96\x15\x60\x43\x08\x21\x82\xec\x85\x9c\x3a\xe4\x86\x93\xf9\x13\x43\xd0\xa5\xf0\xec\xbb\x7d\xec\x9b\x97\x3b\xf2\x13\x67\x8a\x65\x3b\x0d\x9d\xf5\x10\x65\x2a\x23\xc0\xb8\x06\x53\x67\x92\x4a\x4c\xfc\x78\x60\x36\xc0\x66\xca\xa7\x38\x34\x9c\xf1\xcd\xa7\x0d\xbf\xa8\x5c\xce\xb4\xa0\x9f\x85\x03\x9b\x6f\x77\x27\x4f\xa6\xe2\x79\x35\xbf\x89\xae\x37\x3a\x3b\x5a\xda\x58\x24\xbd\x4b\x2a\xec\x22\x2a\xeb\xd7\xfe\xe7\xa4\x82\xe9\xc1\x33\x58\xea\xb2\x5f\x94\x22\x36\xf3\xf4\xb6\xeb\xaf\xe1\xc3\xee\xee\xf7\x93\x83\x66\x80\x66\x7c\x66\x94\x64\xc3\xd4\xa0\x84\x7d\xf3\x02\x4b\xd5\xdf\x2a\xa4\xaa\x4d\x19\xe5\x51\xed\xe9\x3d\xd0\x75\xf7\x95\x3a\xca\xe5\x3f\x0f\x9e\x8a\x38\x4e\x49\x6c\x52\x50\xb0\x7e\x76\x17\xe8\x9e\x28\xf9\x53\xd0\x96\xec\x29\x87\xeb\xd8\xf3\xe7\x4d\x93\x39\x63\xb8\x27\x73\xd3\x7a\xb1\xb7\xa3\x60\x1d\xc8\x97\x13\x34\x82\x5d\xd1\xd6\x7e\x4c\x48\x29\x72\x92\xa0\x7a\x40\x62\x96\x75\xb3\xe8\x78\x8e\xfc\x68\x73\x85\x30\x04\x81\xae\x69\x74\x06\xd2\x4e\xf8\x8e\xbf\x9c\xa1\x97\x2c\x1d\x52\x84\x78\x85\x8e\xad\x85\x78\x2e\xd4\x10\xeb\xbc\x1f\x3d\xa4\x8b\xa8\x07\x83\x62\x36\xaa\xc0\xa8\xf0\x8a\x50\x29\x11\x5d\x57\xe7\xef\x18\xcb\x27\xcc\xe8\xd2\xc1\x57\xa9\xf4\xf5\x61\x5d\xcc\x34\x8a\xea\xc8\x0d\x0f\x28\xdf\x33\xba\xbe\x39\xf6\xec\xbd\x19\xa4\xa6\xaf\xa8\x53\xaa\x4d\xa0\x3b\x6b\xd7\xa8\x06\x22\x9d\xed\x76\xd2\xc5\xb9\xde\x11\x76\xd5\x19\xa7\x93\x94\x67\x92\xb5\x41\x7e\xaf\x7d\x2d\x51\x26\x97\x7c\x57\x04\xfc\x0f\xcd\x8e\x1b\x2f\x58\x9b\x1d\x41\x8d\x19\xdd\x28\xf7\xe9\x4c\x51\xa1\x78\x2d\x32\x2e\x03\xcb\xa4\x78\x85\x74\x24\x49\x7b\x4a\x37\x3f\xde\x0f\xba\xe4\xcc\xd9\x38\xcb\xbf\xa0\xf4\xad\x23\x97\xee\xd7\xf7\x6d\xc3\xcd\xb6\xb0\x6a\x36\x66\x0c\x07\x75\xd3\x91\xca\x47\x21\x33\x41\xf6\x59\xe9\x01\x4f\x70\x28\x4e\xfa\xa5\xfa\xab\xa4\xbb\x83\x79\xce\x02\x04\xf5\xae\xdc\x28\x26\x8d\x82\x43\x8b\x5b\x88\x1f\xdf\x2d\xee\x4a\xd7\xd4\x0e\xd1\x3d\xad\x57\xca\x92\x96\x14\xa6\x3a\x00\xfe\x3a\x78\xf3\x3b\x30\xb6\xfd\x5f\x39\xe4\x43\x70\x36\xdc\xed\x8d\x87\xaf\x43\x28\x2f\x43\xfa\x14\xab\xaf\x6c\x84\x15\xfc\x05\xee\x1a\xd1\x71\xd8\x1f\xaa\x46\x7d\xdf\xe5\xe0\x2e\xb6\x89\x5e\x56\x88\xde\xc0\x48\xf6\x66\x0e\x3a\x2f\xd8\xbd\xec\x60\x2a\xf5\x95\x90\xec\x4c\x6e\xab\x83\x4c\xc0\xde\xc8\x62\x1e\xb5\x10\xfb\xa6\xf7\xad\xf4\x76\x93\xc2\xfd\x57\x4d\x82\x20\xa2\xe7\x0e\x73\xad\x68\xe4\xc3\x32\x48\x8e\xb8\xe7\x31\xfe\x60\x0d\x1e\x9f\x6b\x8f\x5c\xbf\x69\x9c\x18\xd0\x6b\xcd\x73\xb7\xcf\xce\xf4\x2e\x68\xaf\x7a\xe6\x7f\xea\x46\xe9\x46\xde\x6a\x61\xfa\xa4\x2c\x53\x5c\xfc\xae\xaa\xd5\x33\x4f\xc1\xa9\xba\xd4\xa5\x3e\x57\xd1\x1c\x6a\xcc\xfc\xef\xd2\xe8\xab\x44\xcb\x12\xfb\x2e\x66\x4f\xcb\xdf\x5c\x82\xb2\x12\x89\x62\x6a\xc2\xa1\x40\x2b\xde\x7a\x86\x9e\xb9\xed\x78\x07\x33\x8d\xd3\xb2\xba\x82\x37\x84\x5d\xb9\x67\x71\xcc\x98\x80\x08\x1a\xcf\x05\x3d\x9b\xd5\x1c\x01\x01\x94\x1c\x4c\x26\xf6\x6a\xa5\xdb\xad\x3f\x53\x54\x60\x85\x77\xf9\xe5\x1a\xfe\x74\x3a\xdd\x50\xf1\xb5\x90\x1b\xea\x7b\xeb\x5a\xe7\x80\xb6\xec\xe9\x77\xf6\x5b\x9c\x62\x8e\x1d\xce\x0a\xd1\xe0\x78\xc7\x46\xc2\xf3\x8d\x0e\x7f\x06\xb0\x88\x70\x8a\xe9\xac\x11\x17\xe3\xa3\x79\x99\xc1\xd7\x5a\x62\xe9\xc9\xe0\x17\x01\x8e\x08\x8a\xeb\xfb\x37\x8d\xe2\x9c\x78\x93\xac\xf1\x09\x42\x58\x4b\xf5\x58\xa2\xd0\x2d\x75\x1e\x34\xf3\xf4\x84\xb0\x01\xe3\x19\x24\xcc\x21\x84\x8b\xf0\xdd\xaf\x1f\x3d\x8a\x31\x00\x49\x73\x6f\xf7\xf0\x49\x29\x4d\x8a\x59\x5f\x2c\xa7\x26\x3a\x36\x13\x84\x0c\x14\xb3\x3e\xf4\x83\xcd\xca\x5b\xbb\x8a\x4c\x70\x04\xcc\xb8\xf6\x71\x56\x26\x7e\xe3\x5f\x28\x0d\xb1\x26\x45\xde\x8e\x55\x2a\x93\x12\xdf\x57\x69\xa0\x30\xa6\xb4\x6d\x80\xdb\x2e\x6c\x06\xb3\xc7\x6c\x1a\xda\x42\x37\x3b\x29\xa0\x59\x1f\x39\x85\x67\x49\xdf\xdf\xb2\x66\x81\x16\x6a\x28\x6f\xb4\xf2\x09\x7a\x3b\x6f\x8f\xeb\xdb\xe4\x41\x3b\x67\xb5\x58\x68\x9c\x2e\x7c\x1d\x6d\x64\x08\xf4\x6a\x60\x94\xc7\x4b\x22\x81\xe7\x96\xe1\xd9\x00\xcc\x83\x53\x37\xa3\x1b\x53\x50\xca\xa9\xc4\x44\xc6\x70\xf7\x8f\x86\x6e\x03\xef\x6e\xc2\xcb\xcb\xc1\x79\x97\x41\x45\xb2\x39\xb9\x09\x12\xbb\xee\xf8\xf5\x76\x96\x1b\x5e\xfc\x69\x64\x1f\x7a\x71\x51\x70\x87\x75\xb6\x7c\x9e\x65\xed\x9b\xb9\xf5\xa8\x7b\xb7\x90\xda\x20\x35\x57\xbe\xd2\x67\x40\x55\xe8\xa6\xab\x36\x46\xc4\xe1\xa8\x45\xea\x53\xd8\x61\x4a\xe4\x90\x06\x5d\xef\x75\x76\x15\xa2\x65\xf2\xab\x98\x38\x80\x29\xae\xc3\xaf\xb5\xcc\xa3\xa6\x66\xab\x29\xb6\xd2\xc0\x02\x97\x9c\x63\x6a\x3b\x41\xb8\x83\x7a\x43\x2a\x81\xd6\xdb\x55\xcf\x40\x6b\x1f\x58\x42\xb0\xa8\x87\xfe\x6b\x2b\xd8\x8e\x46\x29\x8e\xd3\xec\xc3\x87\x4c\x98\x37\x73\x46\x33\x1f\xde\x7a\x2f\xf7\xf1\x04\x26\x5b\xbd\x2d\x02\x74\xc0\x33\xc7\x58\x38\x51\x00\x1d\xcd\xb3\xde\xd9\x0a\x9c\x09\x77\xc1\xf8\x6d" + +# Generated by init_exponents() +BP_HI_PRE = b"\x42\xba\x66\x8a\x00\x7d\x0f\xcd\x6f\xea\x40\x09\xde\x8a\x64\x37\x24\x8f\x2d\x44\x52\x30\xaf\x00\x4a\x89\xfd\x04\x27\x9b\xc2\x97\xe5\x22\x4e\xf8\x71\xee\xb8\x72\x11\x51\x1d\x2a\x5c\xb8\x1e\xea\xa1\x60\xa8\xa5\x40\x8e\xab\x5d\xea\xeb\x9d\x45\x58\x78\x09\x47\x8f\xc5\x47\xc0\xc5\x2e\x90\xe0\x1e\xcd\x2c\xe4\x1b\xfc\x62\x40\x86\xf0\xec\xdc\x26\x0c\xf3\x0e\x1b\x9c\xae\x3b\x18\xed\x6b\x2c\x9f\x11\x04\x41\x45\xda\x98\xe3\x11\x1b\x40\xa1\x07\x8e\xa9\x04\x57\xb2\x8b\x01\x46\x2c\x90\xe3\xd8\x47\x94\x9e\xd8\xc1\xd3\x1d\x17\x96\x37\xec\x75\x65\xf7\x6f\xa2\x0a\xcc\x47\x1b\x16\x94\xb7\x95\xca\x44\x61\x8e\x4c\xc6\x8e\x0a\x46\xb2\x0f\x91\xe8\x67\x77\x25\x1d\xad\x91\xf0\xd5\xd4\x51\xd7\xe9\x4b\xfc\xd4\x13\x93\x4c\x1d\xa1\x73\xa9\x2d\xdc\x0d\x5e\x0e\x4c\x2c\xfb\xe5\x92\x5b\x0b\x88\x9c\x80\x22\xf3\xa7\xe4\x2f\xcf\xd4\xea\xcd\x06\x31\x63\x15\xc8\xc0\x6c\xb6\x67\x17\x6e\x8f\xd6\x75\xe1\x8a\x22\x96\x10\x0a\xd3\x42\x06\xfc\xf4\x44\x35\x7b\xe1\xe9\x87\x2f\x59\xd7\x1c\x4e\x66\xaf\xdf\x7c\x19\x6b\x6a\x59\x6b\xe2\x89\x0c\x0a\xea\x92\x8a\x9c\x69\xd2\xc4\xdf\x3b\x9c\x52\x8b\xce\x2c\x0c\x30\x6b\x62\x91\xde\xa2\x8d\xe1\xc0\x23\x32\x87\x19\xe9\xa1\xba\x1d\x84\x9c\x1b\xb4\x46\xbc\x0b\x0d\x37\x76\x25\x0d\xd6\x6d\x97\x27\xc2\x5d\x0e\xfe\xb0\xf9\x31\xfc\x53\x7a\xb2\xbd\x9f\x89\x78\x21\x6f\x6e\xb6\xe4\x23\xfa\xe0\xd3\x74\xd3\x4a\x20\x69\x4e\x39\x7a\x70\xb8\x4b\x75\xe3\xbe\x14\xb2\xcf\x53\x01\xc7\xcb\xc6\x62\x50\x96\x71\xa5\xe5\x93\x73\x6f\x61\x13\xc3\xf2\x88\xec\x00\xa1\xcc\x2f\xc7\x15\x6f\x4f\xff\xa1\x74\x8e\x9b\x2c\x2d\xdf\x2f\x43\x03\xbb\xfe\x7f\xfc\xee\x5e\x57\xb3\xb8\x42\x06\xa9\x1b\xcf\x32\xf7\x12\xc7\x5e\x5f\xa5\x10\x87\x85\xb8\xcc\x24\x47\x99\x83\x12\xca\x31\xab\x85\x00\xc8\x2c\x62\x68\x45\x39\xa2\x70\x01\xfb\x17\xf2\xa5\x64\x9d\xb2\xe2\xd6\x4b\x6b\x88\xf0\xd6\x81\x00\x9a\xe7\x8e\xae\xce\x9c\x73\x57\x80\x2c\x6c\x1c\xd8\x1e\xf6\x24\x86\x89\x85\x40\x89\xaa\xd6\x94\x47\x33\x91\xba\xd6\x18\xef\x01\xdf\xd6\x80\x98\x1a\x78\x97\x18\xe9\xd7\xca\xef\x06\x3d\xeb\x2d\x67\x5f\xe8\x43\xea\x63\x4d\xcf\x96\x77\xc1\xd3\xee\x92\x51\x39\x71\xb7\x24\xc7\x88\xe4\x10\x7a\x42\x40\xfe\x26\xe5\xfb\x36\xcc\x00\x7e\x76\x58\x96\x48\x82\xf7\x69\xf1\x8c\x78\x6a\xb1\x52\xf2\x5c\x5d\x2a\xe4\x72\xf7\x1e\x40\x13\xc4\xb0\xc5\x78\x7d\xc1\xd7\x8b\xdc\x8d\x52\x33\x10\x39\xaf\x41\x24\x11\x2e\xe9\x34\x6f\x11\x0a\x4e\x81\x18\xe8\x64\x11\x5d\x49\xb0\x82\xc8\x38\x51\xd4\xd5\xe1\x10\xa4\xab\xda\xdd\xbd\xa9\xb0\x22\x7f\x5b\x26\xbf\x52\xd5\xa2\x25\x25\x23\x59\x72\x84\x3d\xe9\x1d\x99\xd0\x09\x1f\x17\xf4\x78\x2d\x4f\xeb\x2b\x76\x0c\xd5\x8b\x6f\x24\x76\xe8\xb0\x2d\x90\x8a\x15\x15\x07\x8a\xa8\x08\xaa\x3a\x56\x5e\xfc\xb7\x16\x9f\xe0\xcb\xf7\x2c\x12\xce\x17\x50\xf2\x86\x1f\xb6\xc6\x85\x16\x13\xcb\xe9\x74\xef\xc1\x68\x4a\xeb\xbe\x8b\x8a\x52\x2a\xbb\xe7\x82\x77\xd0\xda\xa7\x89\x2d\x9d\xa8\x7c\x27\xbe\xcd\x3e\xc0\x38\x95\x23\x3a\xd4\x66\x31\x8c\x44\x3c\x4d\x6d\x5c\xf1\x2e\xba\x7d\xbd\x3e\x84\x32\x9d\xf6\x1a\xfc\x9b\x7e\x08\xfc\x13\x32\xa6\x82\x34\x42\x73\x39\x6e\xc7\xdc\xdc\xbe\xae\x48\xff\x70\xa1\x9a\x31\xd6\x62\x44\x3c\xce\x57\xf7\x7a\xfe\x05\x0b\x81\x22\x48\x60\x25\x5b\xcb\xc8\xf4\x80\xc4\x3c\xfd\xeb\xb1\xb2\xa6\x89\x72\xb7\xd3\x32\x3b\x03\x61\xf3\xa1\x14\x2f\x8b\x45\x2e\x92\x98\x77\x3d\xef\x56\x35\xc2\xe2\xef\xa3\x70\x0e\x4c\xc9\xe5\xd8\xde\x78\x96\x7e\x57\x35\x82\xcf\x7c\x74\x97\x7c\x30\xb5\x46\x9b\x2c\x0b\xac\xe8\xec\x25\x9f\x71\xba\x25\xc8\xdd\x1c\x51\xe5\xb0\x24\x1c\xca\x7c\x86\xf7\x18\xb7\xd2\xc3\xd4\x57\xa6\xe5\xe0\xb3\x9f\x1f\x39\xeb\xaf\xbb\x08\x83\xd4\x27\xd9\x36\x47\x60\x15\xad\x88\xb7\x92\xa0\x31\xe4\xdd\x98\x37\x57\xc9\x9a\xea\x39\x12\xe8\xf8\xc2\xf6\x59\xde\x4b\xc1\xa2\x20\x4c\xea\x13\x2e\x4f\x9e\xf7\x17\x77\x11\x91\x53\x63\x9a\x71\xff\x24\x17\xf5\x22\xfe\x41\xb8\x7e\x9c\x1c\xb7\x66\x9f\x40\xf9\xd6\x85\x88\x7d\xff\x81\x92\x7a\xa4\x2e\xda\x7f\x2a\x69\x67\x89\x09\x10\x33\xcf\x5b\xe2\xfc\x1f\x5f\x3a\x2d\xe2\x27\x15\xeb\x33\xd6\x28\x28\x92\x2d\xac\x86\x2e\xfc\x7f\xc6\xd5\x4c\x99\xe6\xec\x6e\x58\xc0\xb6\x4d\xa9\x57\xe7\x36\xd3\x00\x93\xc8\x67\xa1\x20\xd5\xdb\xfc\x55\x03\xca\x27\x64\x05\xdf\x4b\x2d\xbe\x6c\xfe\x7c\x2c\x56\xbc\xd2\x66\x9f\x1b\x7d\x82\xc9\xf9\x29\x91\xbf\x41\x02\xaf\x61\x10\xbf\x1b\xf5\xbd\xae\x89\x7f\x9a\x06\x42\x09\xcf\x31\x29\x96\x53\x13\x7e\x86\x5f\x90\x5c\x89\x29\x44\x91\x39\x54\x5a\xc8\x25\x3c\x32\xbe\x19\xcc\x8b\xd8\x54\xca\x7c\xdb\x07\xc2\xae\xba\x12\xa1\x4c\xcf\xa3\x08\x5f\x9f\xfd\x9f\x75\x39\x80\xc9\xd4\x5b\x7b\x4e\x0f\x5b\xe4\x6d\xf3\xae\x5c\x10\xc1\x89\xf1\xdc\x9e\xd2\x59\x2e\x24\x6b\xd2\x44\x9a\xa0\xda\xae\x45\x8a\xe8\xbf\xbd\x52\xf9\x83\xc3\xde\x44\x12\x37\x26\x71\x9c\x08\xd4\xc3\x7c\x8c\x9b\x0b\xe1\x7b\x6b\x49\x82\x61\x36\xaa\x7b\x90\x85\x31\xbc\x91\x73\x2b\x08\x7a\x41\x36\x03\x0b\xad\x7b\x5b\x1c\xfa\x7d\x9c\x98\xa9\xdc\x34\x7a\x92\x65\x1f\x29\xc2\xe1\x10\xaf\xf8\x89\x7f\x26\x7c\x04\x22\x10\xa6\xb7\x0a\x31\x3c\xc0\x6a\xfa\x2b\xd9\xc2\x91\x15\x37\xd6\x09\xd6\x8b\xec\x94\x32\xe8\x4b\x96\x79\x52\x7d\x6a\xbb\x58\x8b\xa7\x2b\xb2\x14\x98\x70\x69\xd8\x0b\x0a\xbc\x2b\xbd\x68\xeb\xa0\x33\x1e\x3a\xe5\xf4\x10\x6f\x7f\xc1\xe2\xe7\xb8\xd6\xe5\x37\x0e\x32\x01\xcc\xe2\xa0\x36\xb6\x8e\xd3\x54\x31\x63\x39\xf0\x92\xde\xc7\x66\x2b\xce\xbd\xd2\x06\x61\x11\xd1\x6c\xe5\x5a\x93\x7e\x2c\x61\x90\x7b\xc3\x66\xc8\x85\xda\xa3\x74\x95\xbe\x67\x1e\xf6\xc2\xf2\xe5\x54\xed\xe3\xb5\x3c\xe2\x80\xcb\xe8\x8a\x48\xb9\xd9\x74\x0e\x98\x0c\xea\xf8\x04\xed\xcd\x8c\x96\x85\x81\x93\xe6\xd5\x17\x8b\xf6\x04\xcc\x73\xbd\x8f\xaa\xd5\x0d\x53\x15\x49\x99\x31\x97\xcc\x27\x28\x27\x21\x6d\x1a\xf9\xdc\xc6\xe9\x86\x2a\x6e\x53\xa0\xa2\xc7\x32\x98\xe1\xfa\xdc\x0f\x91\x48\xcb\xc8\x5e\xc0\x56\x7c\x38\x76\x9c\x27\x65\xd6\x54\xc4\x26\x9f\x6e\xf1\x39\x47\xf1\x3c\x23\x9c\xbb\x08\xb7\xcf\x67\xa2\x5b\xac\x03\x0a\xd1\xb8\x92\xc4\x34\x79\x24\x64\x49\xf5\x32\x8d\xac\x31\x41\xd3\xd7\xc8\xa9\xa2\x54\x0d\xca\xc2\xcb\xc9\x8e\x27\x84\x31\x43\xe7\xd4\xb9\x6d\xde\x75\x21\xfc\x70\xb3\x28\x0a\x2a\x4c\x5f\x39\x28\x7f\x5d\x24\xd7\xa7\x59\xea\x03\x7b\x11\x44\x87\x39\xee\x2a\x28\xfc\x4b\x16\x0e\xac\x40\x61\x08\xae\xe6\xb5\x80\x62\x13\x11\xfe\x03\x0b\xf0\x8b\x4f\x6e\xed\x3d\x7d\x3d\x86\x93\xd3\xac\x52\x4d\xa2\xb4\xeb\xf1\x9e\x25\x59\xdc\x50\xff\x35\xe6\x2d\xa6\x20\xdc\x0a\x02\xed\xcb\xe4\xf3\x98\xb1\xbd\x86\xea\x15\x4b\x6a\x94\x00\x57\x9e\x3f\x1c\xd5\x7f\xdc\x2f\x10\xbd\x8c\xdb\x16\x7c\x0b\x28\x3f\x90\x07\xe6\x20\xd9\xca\x28\x06\x7f\xe2\xb0\x15\xed\x65\x7c\x91\x53\xb8\x44\x3d\x77\xe8\xe2\x5f\xf3\x48\xf4\xdf\x78\xbb\xc1\xce\x20\xa7\xba\xbd\xe4\x0e\xd2\xbd\xbe\xaf\x2b\x5c\xd9\x8e\x52\x02\xba\xf7\xe3\xdc\xf1\x8b\xa1\x15\x62\x0c\x51\xae\x8b\x58\xb4\x92\x3b\x9a\x86\x94\xc9\x3d\xf6\x4b\x17\x8c\x4c\xd2\xf9\xf6\xef\xc5\x1f\x45\x8b\x0c\x5e\xe8\x60\xa4\x0a\xc8\xce\xc3\x50\x6e\xc8\x5b\x99\xdc\x71\x6b\x95\xcb\xb3\x42\xdb\x91\xad\xe4\xb6\x1e\x17\x7f\x60\xf9\xfa\xbb\xff\x2c\x9b\xad\xee\x04\xcf\xd7\x41\xd6\x6d\x2f\x26\x32\x1e\x2c\xf5\x0a\x3c\xd0\x21\xf6\x28\x88\x63\xde\x2d\xad\xf8\xd5\x2d\x1f\x8b\x9f\x51\x42\x43\x05\xa3\xd4\x07\x96\x29\x63\xc1\xd0\xbe\xeb\x81\x13\xf8\x03\x07\xec\xc2\x19\x23\x94\x7f\xe8\xcb\xaf\x5c\x2c\x05\xae\x63\x69\x85\x21\x99\xc5\x2a\x17\x97\xb9\xaf\xf2\xa9\x24\x5d\x7a\x8b\x91\x72\xd5\x72\xb4\x43\x2f\x63\x44\x1f\xf5\x1c\x4a\x4e\x27\x0e\x3b\x61\xea\xe6\xe1\x3e\xef\xe3\x5e\x85\x42\x7b\xc7\x58\xef\x4a\xf4\xc0\x0f\x9c\x77\x52\x1c\x03\x61\xd2\x99\x43\x1f\x9d\x8e\x29\x8c\x13\x41\x4c\x46\x17\x0a\x1d\x82\xa1\x38\x0f\xba\xfe\x53\x1c\xa7\x01\x84\xab\x89\x65\xc4\xc8\x07\x06\x0e\x80\x39\xfe\xc4\x61\x5e\x59\x09\xd2\x7a\xc5\xca\x80\x41\xe3\xf9\x5b\x27\xf1\xc3\xd4\xd4\x06\xa2\x04\x8b\x1e\x6c\xe1\xe6\x37\xcb\x87\xc0\xf9\x7d\x36\x17\xd4\x6a\xef\xfd\xd1\xe8\x13\xc2\x55\xfb\x8b\x3e\xf9\x39\xa2\xc5\xfa\xd4\xd1\x09\x73\xc0\x8c\x05\x5f\x79\x13\xc5\x16\x64\x58\x9d\xa5\x14\x5a\x9c\x59\x72\xf4\xb2\x12\xeb\xf5\x11\x71\xd9\x23\x43\x83\x3a\x08\x95\x3c\xd8\x0c\xd0\xd9\x08\x90\x4c\x56\x3e\xdc\x34\x29\x42\x21\x86\x56\x33\xd8\xcf\x6f\xf5\x04\x44\xb9\xd2\x9b\xeb\x05\xa4\x7b\x8b\xb1\x21\xcb\x11\x8d\x6c\xb1\x6b\x24\xc4\x45\x09\x8a\xa9\x0e\x6d\x5a\x10\xea\xe0\xa0\xf3\x97\x7a\x28\x08\xf7\x9c\xaf\xe8\xf8\x70\x52\x97\xbd\x91\xeb\xbf\x27\x92\xa1\x89\x2c\xb0\x09\xdb\x0b\x7a\xc3\x51\xd0\x35\x3f\x43\xfe\x3a\xa9\x71\x92\xe8\xb9\xd7\xfe\xf5\xba\xec\x41\x5b\x0c\xa4\x8c\x92\x0e\x7c\xdd\x78\xf9\x24\x6a\xd2\x54\xe8\x7e\xe1\xb0\x65\x84\xb8\x60\xb0\xb8\x80\x0a\xae\xe1\x78\x96\xf0\x29\x0c\xb7\x89\xb0\xd7" + +# oneN = vector_powers(rct::identity(), maxN); Generated by init_constants() +BP_ONE_N = b"\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00" + +# twoN = vector_powers(TWO, maxN); Generated by init_constants() +BP_TWO_N = b"\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x20\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x40\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x20\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x40\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x20\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x40\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x20\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x40\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x20\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x40\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x20\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x40\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x20\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x40\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x08\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x20\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x40\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x80\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00" + +# ip12 = inner_product(oneN, twoN); Generated by init_constants() +BP_IP12 = b"\xff\xff\xff\xff\xff\xff\xff\xff\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00" + + +# +# Rct keys operation +# + +tmp_bf_1 = bytearray(32) +tmp_bf_2 = bytearray(32) + +tmp_pt_1 = crypto.new_point() +tmp_pt_2 = crypto.new_point() +tmp_pt_3 = crypto.new_point() +tmp_pt_4 = crypto.new_point() + +tmp_sc_1 = crypto.new_scalar() +tmp_sc_2 = crypto.new_scalar() +tmp_sc_3 = crypto.new_scalar() +tmp_sc_4 = crypto.new_scalar() + + +def memcpy(dst, dst_off, src, src_off, len): + for i in range(len): + dst[dst_off + i] = src[src_off + i] + return dst + + +def _ensure_dst_key(dst=None): + if dst is None: + dst = bytearray(32) + return dst + + +def copy_key(dst, src): + for i in range(32): + dst[i] = src[i] + + +def copy_vector(dst, src): + for i in range(len(src)): + copy_key(dst[i], src[i]) + + +def invert(dst, x): + """ + Modular inversion mod curve order. + + Naive approach using large arithmetics in Python. + Should be moved to the crypto provider later. + :param x: 32byte contracted + :param dst: + :return: + """ + dst = _ensure_dst_key(dst) + crypto.decodeint_into_noreduce(tmp_sc_1, x) + crypto.sc_inv_into(tmp_sc_2, tmp_sc_1) + crypto.encodeint_into(tmp_sc_2, dst) + return dst + + +def scalarmult_key(dst, P, s): + dst = _ensure_dst_key(dst) + crypto.decodepoint_into(tmp_pt_1, P) + crypto.decodeint_into_noreduce(tmp_sc_1, s) + crypto.scalarmult_into(tmp_pt_2, tmp_pt_1, tmp_sc_1) + crypto.encodepoint_into(tmp_pt_2, dst) + return dst + + +def scalarmult_base(dst, x): + dst = _ensure_dst_key(dst) + crypto.decodeint_into_noreduce(tmp_sc_1, x) + crypto.scalarmult_base_into(tmp_pt_1, tmp_sc_1) + crypto.encodepoint_into(tmp_pt_1, dst) + return dst + + +def sc_gen(dst=None): + dst = _ensure_dst_key(dst) + crypto.random_scalar_into(tmp_sc_1) + crypto.encodeint_into(tmp_sc_1, dst) + return dst + + +def full_gen(dst=None): + dst = _ensure_dst_key(dst) + b = crypto.random_bytes(32) + copy_key(dst, b) + return dst + + +def sc_add(dst, a, b): + dst = _ensure_dst_key(dst) + crypto.decodeint_into_noreduce(tmp_sc_1, a) + crypto.decodeint_into_noreduce(tmp_sc_2, b) + crypto.sc_add_into(tmp_sc_3, tmp_sc_1, tmp_sc_2) + crypto.encodeint_into(tmp_sc_3, dst) + return dst + + +def sc_sub(dst, a, b): + dst = _ensure_dst_key(dst) + crypto.decodeint_into_noreduce(tmp_sc_1, a) + crypto.decodeint_into_noreduce(tmp_sc_2, b) + crypto.sc_sub_into(tmp_sc_3, tmp_sc_1, tmp_sc_2) + crypto.encodeint_into(tmp_sc_3, dst) + return dst + + +def sc_mul(dst, a, b): + dst = _ensure_dst_key(dst) + crypto.decodeint_into_noreduce(tmp_sc_1, a) + crypto.decodeint_into_noreduce(tmp_sc_2, b) + crypto.sc_mul_into(tmp_sc_3, tmp_sc_1, tmp_sc_2) + crypto.encodeint_into(tmp_sc_3, dst) + return dst + + +def sc_muladd(dst, a, b, c): + dst = _ensure_dst_key(dst) + crypto.decodeint_into_noreduce(tmp_sc_1, a) + crypto.decodeint_into_noreduce(tmp_sc_2, b) + crypto.decodeint_into_noreduce(tmp_sc_3, c) + crypto.sc_muladd_into(tmp_sc_4, tmp_sc_1, tmp_sc_2, tmp_sc_3) + crypto.encodeint_into(tmp_sc_4, dst) + return dst + + +def sc_mulsub(dst, a, b, c): + dst = _ensure_dst_key(dst) + crypto.decodeint_into_noreduce(tmp_sc_1, a) + crypto.decodeint_into_noreduce(tmp_sc_2, b) + crypto.decodeint_into_noreduce(tmp_sc_3, c) + crypto.sc_mulsub_into(tmp_sc_4, tmp_sc_1, tmp_sc_2, tmp_sc_3) + crypto.encodeint_into(tmp_sc_4, dst) + return dst + + +def add_keys(dst, A, B): + dst = _ensure_dst_key(dst) + crypto.decodepoint_into(tmp_pt_1, A) + crypto.decodepoint_into(tmp_pt_2, B) + crypto.point_add_into(tmp_pt_3, tmp_pt_1, tmp_pt_2) + crypto.encodepoint_into(tmp_pt_3, dst) + return dst + + +def add_keys2(dst, a, b, B): + dst = _ensure_dst_key(dst) + crypto.decodeint_into_noreduce(tmp_sc_1, a) + crypto.decodeint_into_noreduce(tmp_sc_2, b) + crypto.decodepoint_into(tmp_pt_1, B) + crypto.add_keys2_into(tmp_pt_2, tmp_sc_1, tmp_sc_2, tmp_pt_1) + crypto.encodepoint_into(tmp_pt_2, dst) + return dst + + +def add_keys3(dst, a, A, b, B): + dst = _ensure_dst_key(dst) + crypto.decodeint_into_noreduce(tmp_sc_1, a) + crypto.decodeint_into_noreduce(tmp_sc_2, b) + crypto.decodepoint_into(tmp_pt_1, A) + crypto.decodepoint_into(tmp_pt_2, B) + crypto.add_keys3_into(tmp_pt_3, tmp_sc_1, tmp_pt_1, tmp_sc_2, tmp_pt_2) + crypto.encodepoint_into(tmp_pt_3, dst) + return dst + + +def hash_to_scalar(dst, data): + dst = _ensure_dst_key(dst) + crypto.hash_to_scalar_into(tmp_sc_1, data) + crypto.encodeint_into(tmp_sc_1, dst) + return dst + + +def get_exponent(dst, base, idx): + dst = _ensure_dst_key(dst) + salt = b"bulletproof" + buff = bytearray(len(salt) + 32 + 1) # assume varint occupies 1 B + memcpy(buff, 0, base, 0, 32) + memcpy(buff, 32, salt, 0, len(salt)) + dump_uvarint_b_into(idx, buff, 32 + len(salt)) + h1 = crypto.cn_fast_hash(buff) + pt = crypto.hash_to_ec(h1) + crypto.encodepoint_into(pt, dst) + return dst + + +# +# +# + + +class KeyV(object): + """ + KeyVector abstraction + Constant precomputed buffers = bytes, frozen. Same operation as normal. + """ + + def __init__(self, elems=64, src=None, buffer=None, const=False): + self.current_idx = 0 + self.d = None + self.mv = None + self.size = elems + self.const = const + if src: + self.d = bytearray(src.d) + self.size = src.size + elif buffer: + self.d = buffer # can be immutable (bytes) + self.size = len(buffer) // 32 + else: + self.d = bytearray(32 * elems) + self._set_mv() + + def _set_mv(self): + self.mv = memoryview(self.d) + + def __getitem__(self, item): + """ + Returns corresponding 32 byte array + :param item: + :return: + """ + return self.mv[item * 32 : (item + 1) * 32] + + def __setitem__(self, key, value): + """ + Sets given key to the particular place + :param key: + :param value: + :return: + """ + if self.const: + raise ValueError("Constant KeyV") + ck = self[key] + for i in range(32): + ck[i] = value[i] + + def __iter__(self): + self.current_idx = 0 + return self + + def __next__(self): + if self.current_idx > self.size: + raise StopIteration + else: + self.current_idx += 1 + return self[self.current_idx - 1] + + def __len__(self): + return self.size + + def slice(self, res, start, stop): + for i in range(start, stop): + res[i - start] = self[i] + return res + + def slice_r(self, start, stop): + res = KeyV(stop - start) + return self.slice(res, start, stop) + + def copy_from(self, src): + self.size = self.size + self.d = bytearray(self.d) + self._set_mv() + + def copy(self, dst=None): + if dst: + dst.copy_from(self) + else: + dst = KeyV(src=self) + return dst + + def resize(self, nsize, chop=False): + if self.size == nsize: + return self + elif self.size > nsize and not chop: + self.d = self.d[: nsize * 32] + else: + self.d = bytearray(nsize * 32) + self.size = nsize + self._set_mv() + + +class KeyVEval(KeyV): + """ + KeyVector computed / evaluated on demand + """ + + def __init__(self, elems=64, src=None): + self.size = elems + self.fnc = src + self.buff = _ensure_dst_key() + self.mv = memoryview(self.buff) + + def __getitem__(self, item): + self.fnc(item, self.mv) + return self.mv + + def __setitem__(self, key, value): + raise ValueError("Constant vector") + + def slice(self, res, start, stop): + raise ValueError("Not supported") + + def slice_r(self, start, stop): + raise ValueError("Not supported") + + def copy(self, dst=None): + raise ValueError("Not supported") + + def resize(self, nsize, chop=False): + raise ValueError("Not supported") + + +def _ensure_dst_keyvect(dst=None, size=None): + if dst is None: + dst = KeyV(elems=size) + if size is not None: + dst.resize(size) + return dst + + +def vector_exponent_custom(A, B, a, b, dst=None): + dst = _ensure_dst_key(dst) + + crypto.sc_init_into(tmp_sc_1, 0) + crypto.scalarmult_base_into(tmp_pt_1, tmp_sc_1) # identity set + crypto.scalarmult_base_into(tmp_pt_2, tmp_sc_1) + + for i in range(len(a)): + crypto.decodeint_into_noreduce(tmp_sc_1, a[i]) + crypto.decodepoint_into(tmp_pt_3, A[i]) + crypto.decodeint_into_noreduce(tmp_sc_2, b[i]) + crypto.decodepoint_into(tmp_pt_4, B[i]) + crypto.add_keys3_into(tmp_pt_1, tmp_sc_1, tmp_pt_3, tmp_sc_2, tmp_pt_4) + crypto.point_add_into(tmp_pt_2, tmp_pt_2, tmp_pt_1) + crypto.encodepoint_into(tmp_pt_2, dst) + return dst + + +def vector_powers(x, n, dst=None): + dst = _ensure_dst_keyvect(dst, n) + if n == 0: + return dst + dst[0] = ONE + if n == 1: + return dst + dst[1] = x + for i in range(2, n): + sc_mul(dst[i], dst[i - 1], x) + return dst + + +def inner_product(a, b, dst=None): + if len(a) != len(b): + raise ValueError("Incompatible sizes of a and b") + dst = _ensure_dst_key(dst) + crypto.sc_init_into(tmp_sc_1, 0) + + for i in range(len(a)): + crypto.decodeint_into_noreduce(tmp_sc_2, a[i]) + crypto.decodeint_into_noreduce(tmp_sc_3, b[i]) + crypto.sc_muladd_into(tmp_sc_1, tmp_sc_2, tmp_sc_3, tmp_sc_1) + crypto.encodeint_into(tmp_sc_1, dst) + return dst + + +def hadamard(a, b, dst=None): + dst = _ensure_dst_keyvect(dst, len(a)) + for i in range(len(a)): + sc_mul(dst[i], a[i], b[i]) + return dst + + +def hadamard2(a, b, dst=None): + dst = _ensure_dst_keyvect(dst, len(a)) + for i in range(len(a)): + add_keys(dst[i], a[i], b[i]) + return dst + + +def vector_add(a, b, dst=None): + dst = _ensure_dst_keyvect(dst, len(a)) + for i in range(len(a)): + sc_add(dst[i], a[i], b[i]) + return dst + + +def vector_subtract(a, b, dst=None): + dst = _ensure_dst_keyvect(dst, len(a)) + for i in range(len(a)): + sc_sub(dst[i], a[i], b[i]) + return dst + + +def vector_scalar(a, x, dst=None): + dst = _ensure_dst_keyvect(dst, len(a)) + for i in range(len(a)): + sc_mul(dst[i], a[i], x) + return dst + + +def vector_scalar2(a, x, dst=None): + dst = _ensure_dst_keyvect(dst, len(a)) + for i in range(len(a)): + scalarmult_key(dst[i], a[i], x) + return dst + + +def hash_cache_mash(dst, hash_cache, *args): + dst = _ensure_dst_key(dst) + ctx = crypto.get_keccak() + ctx.update(hash_cache) + + for x in args: + if x is None: + break + ctx.update(x) + hsh = ctx.digest() + + crypto.decodeint_into(tmp_sc_1, hsh) + crypto.encodeint_into(tmp_sc_1, tmp_bf_1) + + copy_key(dst, tmp_bf_1) + copy_key(hash_cache, tmp_bf_1) + return dst + + +def init_exponents(): + Gi = KeyV() + Hi = KeyV() + for i in range(64): + get_exponent(Hi[i], XMR_H, i * 2) + get_exponent(Gi[i], XMR_H, i * 2 + 1) + return Gi, Hi + + +def vect2buff(vect): + buff = b"" + for i in range(len(vect)): + cur = vect[i] + for j in range(32): + buff += b"\\x%02x" % cur[j] + return buff + + +def key2buff(hx): + hxs = b"" + for i in hx: + hxs += b"\\x%02x" % i + return hxs + + +def init_constants(): + Gi, Hi = init_exponents() + GiB = vect2buff(Gi) + HiB = vect2buff(Hi) + oneN = vector_powers(ONE, 64) + oneNB = vect2buff(oneN) + twoN = vector_powers(TWO, 64) + twoNB = vect2buff(twoN) + ip12 = inner_product(oneN, twoN) + ip12B = key2buff(ip12) + return Gi, GiB, Hi, HiB, oneN, oneNB, twoN, twoNB, ip12, ip12B + + +class BulletProofBuilder(object): + def __init__(self): + self.use_det_masks = True + self.value = None + self.value_enc = None + self.gamma = None + self.gamma_enc = None + self.proof_sec = None + self.Gprec = KeyV(buffer=BP_GI_PRE, const=True) + self.Hprec = KeyV(buffer=BP_HI_PRE, const=True) + self.oneN = KeyV(buffer=BP_ONE_N, const=True) + self.twoN = KeyV(buffer=BP_TWO_N, const=True) + self.ip12 = BP_IP12 + self.v_aL = None + self.v_aR = None + self.v_sL = None + self.v_sR = None + self.tmp_sc_1 = crypto.new_scalar() + self.tmp_det_buff = bytearray(64 + 1 + 1) + self.tmp_h_buff1 = bytearray(32) + self.gc_fnc = gc.collect + self.gc_trace = None + + def gc(self, *args): + if self.gc_trace: + self.gc_trace(*args) + if self.gc_fnc: + self.gc_fnc() + + def set_input(self, value=None, mask=None): + self.value = value + self.value_enc = crypto.encodeint(value) + self.gamma = mask + self.gamma_enc = crypto.encodeint(mask) + self.proof_sec = crypto.random_bytes(64) + + def aL(self, i, dst=None): + dst = _ensure_dst_key(dst) + if self.value_enc[i // 8] & (1 << (i % 8)): + copy_key(dst, ONE) + else: + copy_key(dst, ZERO) + return dst + + def aR(self, i, dst=None): + dst = _ensure_dst_key(dst) + self.aL(i, tmp_bf_1) + sc_sub(dst, tmp_bf_1, ONE) + return dst + + def aL_vct(self): + return KeyVEval(64, lambda x, r: self.aL(x, r)) + + def aR_vct(self): + return KeyVEval(64, lambda x, r: self.aR(x, r)) + + def _det_mask(self, i, is_sL=True, dst=None): + dst = _ensure_dst_key(dst) + self.tmp_det_buff[0] = int(is_sL) + memcpy(self.tmp_det_buff, 1, self.proof_sec, 0, len(self.proof_sec)) + dump_uvarint_b_into(i, self.tmp_det_buff, 65) + crypto.keccak_hash_into(self.tmp_h_buff1, self.tmp_det_buff) + crypto.keccak_hash_into(self.tmp_h_buff1, self.tmp_h_buff1) + crypto.decodeint_into(self.tmp_sc_1, self.tmp_h_buff1) + crypto.encodeint_into(self.tmp_sc_1, dst) + return dst + + def sL(self, i, dst=None): + return self._det_mask(i, True, dst) + + def sR(self, i, dst=None): + return self._det_mask(i, False, dst) + + def sL_vct(self): + return ( + KeyVEval(64, lambda x, r: self.sL(x, r)) + if self.use_det_masks + else self.sX_gen() + ) + + def sR_vct(self): + return ( + KeyVEval(64, lambda x, r: self.sR(x, r)) + if self.use_det_masks + else self.sX_gen() + ) + + def sX_gen(self): + buff = bytearray(64 * 32) + buff_mv = memoryview(buff) + sc = crypto.new_scalar() + for i in range(64): + crypto.random_scalar_into(sc) + crypto.encodeint_into(sc, buff_mv[i * 32 : (i + 1) * 32]) + return KeyV(buffer=buff) + + def vector_exponent(self, a, b, dst=None): + return vector_exponent_custom(self.Gprec, self.Hprec, a, b, dst) + + def prove_s1(self, V, A, S, T1, T2, taux, mu, t, x_ip, y, hash_cache, l, r): + add_keys2(V, self.gamma_enc, self.value_enc, XMR_H) + hash_to_scalar(hash_cache, V) + + # PAPER LINES 38-39 + alpha = sc_gen() + ve = _ensure_dst_key() + self.vector_exponent(self.v_aL, self.v_aR, ve) + add_keys(A, ve, scalarmult_base(tmp_bf_1, alpha)) + + # PAPER LINES 40-42 + rho = sc_gen() + self.vector_exponent(self.v_sL, self.v_sR, ve) + add_keys(S, ve, scalarmult_base(tmp_bf_1, rho)) + + # PAPER LINES 43-45 + z = _ensure_dst_key() + hash_cache_mash(y, hash_cache, A, S) + hash_to_scalar(hash_cache, y) + copy_key(z, hash_cache) + self.gc(1) + + # Polynomial construction before PAPER LINE 46 + t0 = _ensure_dst_key() + t1 = _ensure_dst_key() + t2 = _ensure_dst_key() + + yN = vector_powers(y, BP_N) + self.gc(2) + + ip1y = inner_product(self.oneN, yN) + sc_muladd(t0, z, ip1y, t0) + + zsq = _ensure_dst_key() + sc_mul(zsq, z, z) + sc_muladd(t0, zsq, self.value_enc, t0) + + k = _ensure_dst_key() + copy_key(k, ZERO) + sc_mulsub(k, zsq, ip1y, k) + + zcu = _ensure_dst_key() + sc_mul(zcu, zsq, z) + sc_mulsub(k, zcu, self.ip12, k) + sc_add(t0, t0, k) + self.gc(3) + + # step 2, tmp_vct = vpIz + tmp_vct = _ensure_dst_keyvect(None, BP_N) + vector_scalar(self.oneN, z, tmp_vct) + aL_vpIz = vector_subtract(self.v_aL, tmp_vct) + aR_vpIz = vector_add(self.v_aR, tmp_vct) + self.v_aL = None + self.v_aR = None + self.gc(4) + + # tmp_vct = HyNsR + hadamard(yN, self.v_sR, tmp_vct) + ip1 = inner_product(aL_vpIz, tmp_vct) + ip3 = inner_product(self.v_sL, tmp_vct) + self.gc(5) + + sc_add(t1, t1, ip1) + + vp2zsq = vector_scalar(self.twoN, zsq) + + # Originally: + # ip2 = inner_product(self.v_sL, vector_add(hadamard(yN, aR_vpIz), vp2zsq)) + hadamard(yN, aR_vpIz, tmp_vct) + vector_add(tmp_vct, vp2zsq, tmp_vct) + ip2 = inner_product(self.v_sL, tmp_vct) + + self.gc(6) + sc_add(t1, t1, ip2) + sc_add(t2, t2, ip3) + + # PAPER LINES 47-48 + tau1 = sc_gen() + tau2 = sc_gen() + + add_keys( + T1, scalarmult_key(tmp_bf_1, XMR_H, t1), scalarmult_base(tmp_bf_2, tau1) + ) + add_keys( + T2, scalarmult_key(tmp_bf_1, XMR_H, t2), scalarmult_base(tmp_bf_2, tau2) + ) + + # PAPER LINES 49-51 + x = _ensure_dst_key() + hash_cache_mash(x, hash_cache, z, T1, T2) + + # PAPER LINES 52-53 + copy_key(taux, ZERO) + sc_mul(taux, tau1, x) + xsq = _ensure_dst_key() + sc_mul(xsq, x, x) + sc_muladd(taux, tau2, xsq, taux) + sc_muladd(taux, self.gamma_enc, zsq, taux) + sc_muladd(mu, x, rho, alpha) + self.gc(7) + + # PAPER LINES 54-57 + vector_scalar(self.v_sL, x, tmp_vct) + vector_add(aL_vpIz, tmp_vct, l) + self.v_sL = None + del aL_vpIz + self.gc(8) + + # Originally: + # vector_add(hadamard(yN, vector_add(aR_vpIz, vector_scalar(self.v_sR, x))), vp2zsq, r) + vector_scalar(self.v_sR, x, tmp_vct) + vector_add(aR_vpIz, tmp_vct, tmp_vct) + del aR_vpIz + self.gc(9) + + hadamard(yN, tmp_vct, tmp_vct) + del yN + self.gc(10) + + vector_add(tmp_vct, vp2zsq, r) + self.v_sR = None + del vp2zsq + del tmp_vct + self.gc(11) + + inner_product(l, r, t) + hash_cache_mash(x_ip, hash_cache, x, taux, mu, t) + + def prove_s2(self, x_ip, y, hash_cache, l, r, L, R, aprime0, bprime0): + Gprime = _ensure_dst_keyvect(None, BP_N) + Hprime = _ensure_dst_keyvect(None, BP_N) + + aprime = l + bprime = r + + yinv = invert(None, y) + self.gc(20) + + yinvpow = _ensure_dst_key() + copy_key(yinvpow, ONE) + for i in range(BP_N): + Gprime[i] = self.Gprec[i] + scalarmult_key(Hprime[i], self.Hprec[i], yinvpow) + sc_mul(yinvpow, yinvpow, yinv) + self.gc(21) + + round = 0 + nprime = BP_N + + _tmp_k_1 = _ensure_dst_key() + _tmp_vct_1 = _ensure_dst_keyvect(None, nprime // 2) + _tmp_vct_2 = _ensure_dst_keyvect(None, nprime // 2) + _tmp_vct_3 = _ensure_dst_keyvect(None, nprime // 2) + _tmp_vct_4 = _ensure_dst_keyvect(None, nprime // 2) + + tmp = _ensure_dst_key() + winv = _ensure_dst_key() + w = _ensure_dst_keyvect(None, BP_LOG_N) + cL = _ensure_dst_key() + cR = _ensure_dst_key() + + # PAPER LINE 13 + while nprime > 1: + # PAPER LINE 15 + nprime >>= 1 + _tmp_vct_1.resize(nprime, chop=True) + _tmp_vct_2.resize(nprime, chop=True) + _tmp_vct_3.resize(nprime, chop=True) + _tmp_vct_4.resize(nprime, chop=True) + self.gc(22) + + # PAPER LINES 16-17 + inner_product( + aprime.slice(_tmp_vct_1, 0, nprime), + bprime.slice(_tmp_vct_2, nprime, bprime.size), + cL, + ) + + inner_product( + aprime.slice(_tmp_vct_1, nprime, aprime.size), + bprime.slice(_tmp_vct_2, 0, nprime), + cR, + ) + + self.gc(23) + + # PAPER LINES 18-19 + vector_exponent_custom( + Gprime.slice(_tmp_vct_1, nprime, len(Gprime)), + Hprime.slice(_tmp_vct_2, 0, nprime), + aprime.slice(_tmp_vct_3, 0, nprime), + bprime.slice(_tmp_vct_4, nprime, len(bprime)), + L[round], + ) + + sc_mul(tmp, cL, x_ip) + add_keys(L[round], L[round], scalarmult_key(_tmp_k_1, XMR_H, tmp)) + self.gc(24) + + vector_exponent_custom( + Gprime.slice(_tmp_vct_1, 0, nprime), + Hprime.slice(_tmp_vct_2, nprime, len(Hprime)), + aprime.slice(_tmp_vct_3, nprime, len(aprime)), + bprime.slice(_tmp_vct_4, 0, nprime), + R[round], + ) + + sc_mul(tmp, cR, x_ip) + add_keys(R[round], R[round], scalarmult_key(_tmp_k_1, XMR_H, tmp)) + self.gc(25) + + # PAPER LINES 21-22 + hash_cache_mash(w[round], hash_cache, L[round], R[round]) + + # PAPER LINES 24-25 + invert(winv, w[round]) + self.gc(26) + + vector_scalar2(Gprime.slice(_tmp_vct_1, 0, nprime), winv, _tmp_vct_3) + vector_scalar2( + Gprime.slice(_tmp_vct_2, nprime, len(Gprime)), w[round], _tmp_vct_4 + ) + hadamard2(_tmp_vct_3, _tmp_vct_4, Gprime) + self.gc(27) + + vector_scalar2(Hprime.slice(_tmp_vct_1, 0, nprime), w[round], _tmp_vct_3) + vector_scalar2( + Hprime.slice(_tmp_vct_2, nprime, len(Hprime)), winv, _tmp_vct_4 + ) + hadamard2(_tmp_vct_3, _tmp_vct_4, Hprime) + self.gc(28) + + # PAPER LINES 28-29 + vector_scalar(aprime.slice(_tmp_vct_1, 0, nprime), w[round], _tmp_vct_3) + vector_scalar( + aprime.slice(_tmp_vct_2, nprime, len(aprime)), winv, _tmp_vct_4 + ) + vector_add(_tmp_vct_3, _tmp_vct_4, aprime) + self.gc(29) + + vector_scalar(bprime.slice(_tmp_vct_1, 0, nprime), winv, _tmp_vct_3) + vector_scalar( + bprime.slice(_tmp_vct_2, nprime, len(bprime)), w[round], _tmp_vct_4 + ) + vector_add(_tmp_vct_3, _tmp_vct_4, bprime) + + round += 1 + self.gc(30) + + copy_key(aprime0, aprime[0]) + copy_key(bprime0, bprime[0]) + + def init_vct(self): + self.v_aL = self.aL_vct() + self.v_aR = self.aR_vct() + self.v_sL = self.sL_vct() + self.v_sR = self.sR_vct() + + def prove(self): + # Prover state + V = _ensure_dst_key() + A = _ensure_dst_key() + S = _ensure_dst_key() + T1 = _ensure_dst_key() + T2 = _ensure_dst_key() + taux = _ensure_dst_key() + mu = _ensure_dst_key() + t = _ensure_dst_key() + x_ip = _ensure_dst_key() + y = _ensure_dst_key() + hash_cache = _ensure_dst_key() + aprime0 = _ensure_dst_key() + bprime0 = _ensure_dst_key() + + L = _ensure_dst_keyvect(None, BP_LOG_N) + R = _ensure_dst_keyvect(None, BP_LOG_N) + l = _ensure_dst_keyvect(None, BP_N) + r = _ensure_dst_keyvect(None, BP_N) + + self.init_vct() + self.gc(50) + + self.prove_s1(V, A, S, T1, T2, taux, mu, t, x_ip, y, hash_cache, l, r) + self.gc(51) + + self.prove_s2(x_ip, y, hash_cache, l, r, L, R, aprime0, bprime0) + self.gc(52) + + return Bulletproof( + V=[V], + A=A, + S=S, + T1=T1, + T2=T2, + taux=taux, + mu=mu, + L=L, + R=R, + a=aprime0, + b=bprime0, + t=t, + ) + + def verify(self, proof): + if len(proof.V) != 1: + raise ValueError("len(V) != 1") + if len(proof.L) != len(proof.R): + raise ValueError("|L| != |R|") + if len(proof.L) == 0: + raise ValueError("Empty proof") + if len(proof.L) != 6: + raise ValueError("Proof is not for 64 bits") + + hash_cache = _ensure_dst_key() + hash_to_scalar(hash_cache, proof.V[0]) + + x = _ensure_dst_key() + y = _ensure_dst_key() + z = _ensure_dst_key() + + # Reconstruct the challenges + hash_cache_mash(y, hash_cache, proof.A, proof.S) + hash_to_scalar(hash_cache, y) + copy_key(z, hash_cache) + hash_cache_mash(x, hash_cache, z, proof.T1, proof.T2) + + # Reconstruct the challenges + x_ip = _ensure_dst_key() + hash_cache_mash(x_ip, hash_cache, x, proof.taux, proof.mu, proof.t) + + # PAPER LINE 61 + _tmp_k_1 = _ensure_dst_key() + _tmp_k_2 = _ensure_dst_key() + L61Left = _ensure_dst_key() + add_keys( + L61Left, + scalarmult_base(_tmp_k_1, proof.taux), + scalarmult_key(_tmp_k_2, XMR_H, proof.t), + ) + + k = _ensure_dst_key() + yN = vector_powers(y, BP_N) + ip1y = inner_product(self.oneN, yN) + del yN + + zsq = _ensure_dst_key() + sc_mul(zsq, z, z) + + zcu = _ensure_dst_key() + tmp = _ensure_dst_key() + tmp2 = _ensure_dst_key() + sc_mulsub(k, zsq, ip1y, k) + sc_mul(zcu, zsq, z) + sc_mulsub(k, zcu, self.ip12, k) + sc_muladd(tmp, z, ip1y, k) + + L61Right = _ensure_dst_key() + scalarmult_key(L61Right, XMR_H, tmp) + scalarmult_key(tmp, proof.V[0], zsq) + add_keys(L61Right, L61Right, tmp) + + scalarmult_key(tmp, proof.T1, x) + add_keys(L61Right, L61Right, tmp) + + xsq = _ensure_dst_key() + sc_mul(xsq, x, x) + scalarmult_key(tmp, proof.T2, xsq) + add_keys(L61Right, L61Right, tmp) + self.gc(60) + + if L61Right != L61Left: + raise ValueError("Verification failure 1") + + del k + del ip1y + del zcu + del L61Left + del L61Right + + # PAPER LINE 62 + P = _ensure_dst_key() + add_keys(P, proof.A, scalarmult_key(_tmp_k_1, proof.S, x)) + + # Compute the number of rounds for the inner product + rounds = len(proof.L) + + # PAPER LINES 21-22 + w = _ensure_dst_keyvect(None, rounds) + for i in range(rounds): + hash_cache_mash(w[i], hash_cache, proof.L[i], proof.R[i]) + + # Basically PAPER LINES 24-25 + # Compute the curvepoints from G[i] and H[i] + inner_prod = _ensure_dst_key() + yinvpow = _ensure_dst_key() + ypow = _ensure_dst_key() + yinv = _ensure_dst_key() + + copy_key(inner_prod, ONE) + copy_key(yinvpow, ONE) + copy_key(ypow, ONE) + + invert(yinv, y) + self.gc(61) + + winv = _ensure_dst_keyvect(None, rounds) + for i in range(rounds): + invert(winv[i], w[i]) + self.gc(62) + + g_scalar = _ensure_dst_key() + h_scalar = _ensure_dst_key() + for i in range(BP_N): + copy_key(g_scalar, proof.a) + sc_mul(h_scalar, proof.b, yinvpow) + + for j in range(rounds - 1, -1, -1): + J = len(w) - j - 1 + + if (i & (1 << j)) == 0: + sc_mul(g_scalar, g_scalar, winv[J]) + sc_mul(h_scalar, h_scalar, w[J]) + else: + sc_mul(g_scalar, g_scalar, w[J]) + sc_mul(h_scalar, h_scalar, winv[J]) + + # Adjust the scalars using the exponents from PAPER LINE 62 + sc_add(g_scalar, g_scalar, z) + sc_mul(tmp, zsq, self.twoN[i]) + sc_muladd(tmp, z, ypow, tmp) + sc_mulsub(h_scalar, tmp, yinvpow, h_scalar) + + # Now compute the basepoint's scalar multiplication + # Each of these could be written as a multiexp operation instead + add_keys3(tmp, g_scalar, self.Gprec[i], h_scalar, self.Hprec[i]) + add_keys(inner_prod, inner_prod, tmp) + + if i != BP_N - 1: + sc_mul(yinvpow, yinvpow, yinv) + sc_mul(ypow, ypow, y) + + del g_scalar + del h_scalar + self.gc(63) + + # PAPER LINE 26 + pprime = _ensure_dst_key() + sc_sub(tmp, ZERO, proof.mu) + add_keys(pprime, P, scalarmult_base(_tmp_k_1, tmp)) + + for i in range(rounds): + sc_mul(tmp, w[i], w[i]) + sc_mul(tmp2, winv[i], winv[i]) + + add_keys3(tmp, tmp, proof.L[i], tmp2, proof.R[i]) + add_keys(pprime, pprime, tmp) + + sc_mul(tmp, proof.t, x_ip) + add_keys(pprime, pprime, scalarmult_key(_tmp_k_1, XMR_H, tmp)) + + sc_mul(tmp, proof.a, proof.b) + sc_mul(tmp, tmp, x_ip) + scalarmult_key(tmp, XMR_H, tmp) + add_keys(tmp, tmp, inner_prod) + self.gc(64) + + if pprime != tmp: + raise ValueError("Verification failure step 2") + return True diff --git a/src/apps/monero/xmr/crypto.py b/src/apps/monero/xmr/crypto.py index 7fa8908f1..3d4226c83 100644 --- a/src/apps/monero/xmr/crypto.py +++ b/src/apps/monero/xmr/crypto.py @@ -46,6 +46,14 @@ def keccak_hash(inp): return tcry.xmr_fast_hash(inp) +def keccak_hash_into(r, inp): + """ + Hashesh input in one call + :return: + """ + return tcry.xmr_fast_hash(r, inp) + + def keccak_2hash(inp): """ Keccak double hashing @@ -96,10 +104,22 @@ def pbkdf2(inp, salt, length=32, count=1000, prf=None): # +def new_point(): + return tcry.ge25519_set_neutral() + + +def new_scalar(): + return tcry.init256_modm(0) + + def decodepoint(x): return tcry.ge25519_unpack_vartime(x) +def decodepoint_into(r, x): + return tcry.ge25519_unpack_vartime(r, x) + + def encodepoint(pt): return tcry.ge25519_pack(pt) @@ -112,6 +132,14 @@ def decodeint(x): return tcry.unpack256_modm(x) +def decodeint_into_noreduce(r, x): + return tcry.unpack256_modm_noreduce(r, x) + + +def decodeint_into(r, x): + return tcry.unpack256_modm(r, x) + + def encodeint(x): return tcry.pack256_modm(x) @@ -128,18 +156,34 @@ def scalarmult_base(a): return tcry.ge25519_scalarmult_base(a) +def scalarmult_base_into(r, a): + return tcry.ge25519_scalarmult_base(r, a) + + def scalarmult(P, e): return tcry.ge25519_scalarmult(P, e) +def scalarmult_into(r, P, e): + return tcry.ge25519_scalarmult(r, P, e) + + def point_add(P, Q): return tcry.ge25519_add(P, Q, 0) +def point_add_into(r, P, Q): + return tcry.ge25519_add(r, P, Q, 0) + + def point_sub(P, Q): return tcry.ge25519_add(P, Q, 1) +def point_sub_into(r, P, Q): + return tcry.ge25519_add(r, P, Q, 1) + + def point_eq(P, Q): return tcry.ge25519_eq(P, Q) @@ -148,16 +192,6 @@ def point_double(P): return tcry.ge25519_double(P) -def point_norm(P): - """ - Normalizes point after multiplication - Extended edwards coordinates (X,Y,Z,T) - :param P: - :return: - """ - return tcry.ge25519_norm(P) - - # # Zmod(order), scalar values field # @@ -171,6 +205,14 @@ def sc_0(): return tcry.init256_modm(0) +def sc_0_into(r): + """ + Sets 0 to the scalar value Zmod(m) + :return: + """ + return tcry.init256_modm(r, 0) + + def sc_init(x): """ Sets x to the scalar value Zmod(m) @@ -181,6 +223,16 @@ def sc_init(x): return tcry.init256_modm(x) +def sc_init_into(r, x): + """ + Sets x to the scalar value Zmod(m) + :return: + """ + if x >= (1 << 64): + raise ValueError("Initialization works up to 64-bit only") + return tcry.init256_modm(r, x) + + def sc_get64(x): """ Returns 64bit value from the sc @@ -235,6 +287,17 @@ def sc_add(aa, bb): return tcry.add256_modm(aa, bb) +def sc_add_into(r, aa, bb): + """ + Scalar addition + :param r: + :param aa: + :param bb: + :return: + """ + return tcry.add256_modm(r, aa, bb) + + def sc_sub(aa, bb): """ Scalar subtraction @@ -245,6 +308,38 @@ def sc_sub(aa, bb): return tcry.sub256_modm(aa, bb) +def sc_sub_into(r, aa, bb): + """ + Scalar subtraction + :param r: + :param aa: + :param bb: + :return: + """ + return tcry.sub256_modm(r, aa, bb) + + +def sc_mul(aa, bb): + """ + Scalar multiplication + :param aa: + :param bb: + :return: + """ + return tcry.mul256_modm(aa, bb) + + +def sc_mul_into(r, aa, bb): + """ + Scalar multiplication + :param r: + :param aa: + :param bb: + :return: + """ + return tcry.mul256_modm(r, aa, bb) + + def sc_isnonzero(c): """ Returns true if scalar is non-zero @@ -275,10 +370,59 @@ def sc_mulsub(aa, bb, cc): return tcry.mulsub256_modm(aa, bb, cc) +def sc_mulsub_into(r, aa, bb, cc): + """ + (cc - aa * bb) % l + :param r: + :param aa: + :param bb: + :param cc: + :return: + """ + return tcry.mulsub256_modm(r, aa, bb, cc) + + +def sc_muladd(aa, bb, cc): + """ + (cc + aa * bb) % l + :param aa: + :param bb: + :param cc: + :return: + """ + return tcry.muladd256_modm(aa, bb, cc) + + +def sc_muladd_into(r, aa, bb, cc): + """ + (cc + aa * bb) % l + :param r: + :param aa: + :param bb: + :param cc: + :return: + """ + return tcry.muladd256_modm(r, aa, bb, cc) + + +def sc_inv_into(r, x): + """ + Modular inversion mod curve order L + :param r: + :param x: + :return: + """ + return tcry.inv256_modm(r, x) + + def random_scalar(): return tcry.xmr_random_scalar() +def random_scalar_into(r): + return tcry.xmr_random_scalar(r) + + # # GE - ed25519 group # @@ -443,6 +587,18 @@ def hash_to_scalar(data, length=None): return tcry.xmr_hash_to_scalar(bytes(dt)) +def hash_to_scalar_into(r, data, length=None): + """ + H_s(P) + :param r: + :param data: + :param length: + :return: + """ + dt = data[:length] if length else data + return tcry.xmr_hash_to_scalar(r, bytes(dt)) + + def hash_to_ec(buf): """ H_p(buf) @@ -456,6 +612,20 @@ def hash_to_ec(buf): return tcry.xmr_hash_to_ec(buf) +def hash_to_ec_into(r, buf): + """ + H_p(buf) + + Code adapted from MiniNero: https://github.com/monero-project/mininero + https://github.com/monero-project/research-lab/blob/master/whitepaper/ge_fromfe_writeup/ge_fromfe.pdf + http://archive.is/yfINb + :param r: + :param buf: + :return: + """ + return tcry.xmr_hash_to_ec(r, buf) + + # # XMR # @@ -485,6 +655,18 @@ def add_keys2(a, b, B): return tcry.xmr_add_keys2_vartime(a, b, B) +def add_keys2_into(r, a, b, B): + """ + aG + bB, G is basepoint + :param r: + :param a: + :param b: + :param B: + :return: + """ + return tcry.xmr_add_keys2_vartime(r, a, b, B) + + def add_keys3(a, A, b, B): """ aA + bB @@ -497,6 +679,19 @@ def add_keys3(a, A, b, B): return tcry.xmr_add_keys3_vartime(a, A, b, B) +def add_keys3_into(r, a, A, b, B): + """ + aA + bB + :param r: + :param a: + :param A: + :param b: + :param B: + :return: + """ + return tcry.xmr_add_keys3_vartime(r, a, A, b, B) + + def gen_c(a, amount): """ Generates Pedersen commitment @@ -566,6 +761,21 @@ def derive_secret_key(derivation, output_index, base): return tcry.xmr_derive_private_key(derivation, output_index, base) +def get_subaddress_secret_key(secret_key, major=0, minor=0): + """ + Builds subaddress secret key from the subaddress index + Hs(SubAddr || a || index_major || index_minor) + + :param secret_key: + :param index: + :param major: + :param minor: + :param little_endian: + :return: + """ + return tcry.xmr_get_subaddress_secret_key(major, minor, secret_key) + + def prove_range(amount, last_mask=None, *args, **kwargs): """ Range proof provided by the backend. Implemented in C for speed. diff --git a/src/apps/monero/xmr/monero.py b/src/apps/monero/xmr/monero.py index 9aca64c73..c8b6ae04c 100644 --- a/src/apps/monero/xmr/monero.py +++ b/src/apps/monero/xmr/monero.py @@ -22,17 +22,6 @@ def get_subaddress_secret_key( Builds subaddress secret key from the subaddress index Hs(SubAddr || a || index_major || index_minor) - UPDATE: Monero team fixed this problem. Always use little endian. - Note: need to handle endianity in the index - C-code simply does: memcpy(data + sizeof(prefix) + sizeof(crypto::secret_key), &index, sizeof(subaddress_index)); - Where the index has the following form: - - struct subaddress_index { - uint32_t major; - uint32_t minor; - } - - https://docs.python.org/3/library/struct.html#byte-order-size-and-alignment :param secret_key: :param index: :param major: @@ -43,20 +32,7 @@ def get_subaddress_secret_key( if index: major = index.major minor = index.minor - endianity = "<" if little_endian else ">" - prefix = b"SubAddr" - buffer = bytearray(len(prefix) + 1 + 32 + 4 + 4) - struct.pack_into( - "%s7sb32sLL" % endianity, - buffer, - 0, - prefix, - 0, - crypto.encodeint(secret_key), - major, - minor, - ) - return crypto.hash_to_scalar(buffer) + return crypto.get_subaddress_secret_key(secret_key, major, minor) def get_subaddress_spend_public_key(view_private, spend_public, major, minor): @@ -301,3 +277,22 @@ def generate_monero_keys(seed): hash = crypto.cn_fast_hash(crypto.encodeint(spend_sec)) view_sec, view_pub = generate_keys(crypto.decodeint(hash)) return spend_sec, spend_pub, view_sec, view_pub + + +def generate_sub_address_keys(view_sec, spend_pub, major, minor): + """ + Computes generic public sub-address + :param view_sec: + :param spend_pub: + :param major: + :param minor: + :return: spend public, view public + """ + if major == 0 and minor == 0: # special case, Monero-defined + return spend_pub, crypto.scalarmult_base(view_sec) + + m = get_subaddress_secret_key(view_sec, major=major, minor=minor) + M = crypto.scalarmult_base(m) + D = crypto.point_add(spend_pub, M) + C = crypto.ge_scalarmult(view_sec, D) + return D, C diff --git a/src/apps/monero/xmr/ring_ct.py b/src/apps/monero/xmr/ring_ct.py index 420e727ac..103a11e4b 100644 --- a/src/apps/monero/xmr/ring_ct.py +++ b/src/apps/monero/xmr/ring_ct.py @@ -3,9 +3,28 @@ # Author: https://github.com/monero-project/mininero # Author: Dusan Klinec, ph4r05, 2018 +import gc + from apps.monero.xmr import crypto +def prove_range_bp(amount, last_mask=None): + from apps.monero.xmr import bulletproof as bp + + bpi = bp.BulletProofBuilder() + + mask = last_mask if last_mask is not None else crypto.random_scalar() + bpi.set_input(amount, mask) + bp_proof = bpi.prove() + C = bp_proof.V[0] + + gc.collect() + from apps.monero.controller.misc import dump_msg + + bp_ser = dump_msg(bp_proof, preallocate=9 * 32 + 2 * 6 * 32 + 64) + return C, mask, bp_ser + + def prove_range( amount, last_mask=None, decode=False, backend_impl=True, byte_enc=True, rsig=None ): diff --git a/src/apps/monero/xmr/serialize/xmrserialize.py b/src/apps/monero/xmr/serialize/xmrserialize.py index 7d9c4a00d..bc6e731da 100644 --- a/src/apps/monero/xmr/serialize/xmrserialize.py +++ b/src/apps/monero/xmr/serialize/xmrserialize.py @@ -180,20 +180,12 @@ async def container(self, container=None, container_type=None, params=None): ) if self.writing: - return await dump_container( - self.iobj, - container, - container_type, - params, - field_archiver=self.dump_field, + return await self._dump_container( + self.iobj, container, container_type, params ) else: - return await load_container( - self.iobj, - container_type, - params=params, - container=container, - field_archiver=self.load_field, + return await self._load_container( + self.iobj, container_type, params=params, container=container ) async def container_size( @@ -210,7 +202,7 @@ async def container_size( raise ValueError("not supported") if self.writing: - return await dump_container_size( + return await self._dump_container_size( self.iobj, container_len, container_type, params ) else: @@ -227,7 +219,9 @@ async def container_val(self, elem, container_type, params=None): if hasattr(container_type, "serialize_archive"): raise ValueError("not supported") if self.writing: - return await dump_container_val(self.iobj, elem, container_type, params) + return await self._dump_container_val( + self.iobj, elem, container_type, params + ) else: raise ValueError("Not supported") @@ -243,19 +237,13 @@ async def tuple(self, elem=None, elem_type=None, params=None): ) if self.writing: - return await dump_tuple( - self.iobj, elem, elem_type, params, field_archiver=self.dump_field - ) + return await self._dump_tuple(self.iobj, elem, elem_type, params) else: - return await load_tuple( - self.iobj, - elem_type, - params=params, - elem=elem, - field_archiver=self.load_field, + return await self._load_tuple( + self.iobj, elem_type, params=params, elem=elem ) - async def variant(self, elem=None, elem_type=None, params=None): + async def variant(self, elem=None, elem_type=None, params=None, wrapped=None): """ Loads/dumps variant type :param elem: @@ -271,20 +259,19 @@ async def variant(self, elem=None, elem_type=None, params=None): ) if self.writing: - return await dump_variant( + return await self._dump_variant( self.iobj, elem=elem, elem_type=elem_type if elem_type else elem.__class__, params=params, - field_archiver=self.dump_field, ) else: - return await load_variant( + return await self._load_variant( self.iobj, elem_type=elem_type if elem_type else elem.__class__, params=params, elem=elem, - field_archiver=self.load_field, + wrapped=wrapped, ) async def message(self, msg, msg_type=None): @@ -300,13 +287,9 @@ async def message(self, msg, msg_type=None): return await msg.serialize_archive(self) if self.writing: - return await dump_message( - self.iobj, msg, msg_type=msg_type, field_archiver=self.dump_field - ) + return await self._dump_message(self.iobj, msg, msg_type=msg_type) else: - return await load_message( - self.iobj, msg_type, msg=msg, field_archiver=self.load_field - ) + return await self._load_message(self.iobj, msg_type, msg=msg) async def message_field(self, msg, field, fvalue=None): """ @@ -317,13 +300,9 @@ async def message_field(self, msg, field, fvalue=None): :return: """ if self.writing: - await dump_message_field( - self.iobj, msg, field, fvalue=fvalue, field_archiver=self.dump_field - ) + await self._dump_message_field(self.iobj, msg, field, fvalue=fvalue) else: - await load_message_field( - self.iobj, msg, field, field_archiver=self.load_field - ) + await self._load_message_field(self.iobj, msg, field) async def message_fields(self, msg, fields): """ @@ -337,9 +316,6 @@ async def message_fields(self, msg, fields): return msg def _get_type(self, elem_type): - # log.info(__name__, 'elem: %s %s %s %s %s | %s %s', - # type(elem_type), elem_type.__name__, elem_type.__module__, elem_type, issubclass(elem_type, XmrType), id(elem_type), id(XmrType)) - # If part of our hierarchy - return the object if issubclass(elem_type, XmrType): return elem_type @@ -454,6 +430,270 @@ async def root(self): :return: """ + async def _dump_container_size( + self, writer, container_len, container_type, params=None + ): + """ + Dumps container size - per element streaming + :param writer: + :param container_len: + :param container_type: + :param params: + :return: + """ + if not container_type or not container_type.FIX_SIZE: + await dump_uvarint(writer, container_len) + elif container_len != container_type.SIZE: + raise ValueError( + "Fixed size container has not defined size: %s" % container_type.SIZE + ) + + async def _dump_container_val(self, writer, elem, container_type, params=None): + """ + Single elem dump + :param writer: + :param elem: + :param container_type: + :param params: + :return: + """ + elem_type = container_elem_type(container_type, params) + await self.dump_field(writer, elem, elem_type, params[1:] if params else None) + + async def _dump_container(self, writer, container, container_type, params=None): + """ + Dumps container of elements to the writer. + + :param writer: + :param container: + :param container_type: + :param params: + :return: + """ + await self._dump_container_size(writer, len(container), container_type) + + elem_type = container_elem_type(container_type, params) + + for elem in container: + await self.dump_field( + writer, elem, elem_type, params[1:] if params else None + ) + + async def _load_container( + self, reader, container_type, params=None, container=None + ): + """ + Loads container of elements from the reader. Supports the container ref. + Returns loaded container. + + :param reader: + :param container_type: + :param params: + :param container: + :return: + """ + + c_len = ( + container_type.SIZE + if container_type.FIX_SIZE + else await load_uvarint(reader) + ) + if container and c_len != len(container): + raise ValueError("Size mismatch") + + elem_type = container_elem_type(container_type, params) + res = container if container else [] + for i in range(c_len): + fvalue = await self.load_field( + reader, + elem_type, + params[1:] if params else None, + eref(res, i) if container else None, + ) + if not container: + res.append(fvalue) + return res + + async def _dump_tuple(self, writer, elem, elem_type, params=None): + """ + Dumps tuple of elements to the writer. + + :param writer: + :param elem: + :param elem_type: + :param params: + :return: + """ + if len(elem) != len(elem_type.f_specs()): + raise ValueError( + "Fixed size tuple has not defined size: %s" % len(elem_type.f_specs()) + ) + await dump_uvarint(writer, len(elem)) + + elem_fields = params[0] if params else None + if elem_fields is None: + elem_fields = elem_type.f_specs() + for idx, elem in enumerate(elem): + await self.dump_field( + writer, elem, elem_fields[idx], params[1:] if params else None + ) + + async def _load_tuple(self, reader, elem_type, params=None, elem=None): + """ + Loads tuple of elements from the reader. Supports the tuple ref. + Returns loaded tuple. + + :param reader: + :param elem_type: + :param params: + :param container: + :return: + """ + + c_len = await load_uvarint(reader) + if elem and c_len != len(elem): + raise ValueError("Size mismatch") + if c_len != len(elem_type.f_specs()): + raise ValueError("Tuple size mismatch") + + elem_fields = params[0] if params else None + if elem_fields is None: + elem_fields = elem_type.f_specs() + + res = elem if elem else [] + for i in range(c_len): + fvalue = await self.load_field( + reader, + elem_fields[i], + params[1:] if params else None, + eref(res, i) if elem else None, + ) + if not elem: + res.append(fvalue) + return res + + async def _dump_message_field(self, writer, msg, field, fvalue=None): + """ + Dumps a message field to the writer. Field is defined by the message field specification. + + :param writer: + :param msg: + :param field: + :param fvalue: + :return: + """ + fname, ftype, params = field[0], field[1], field[2:] + fvalue = getattr(msg, fname, None) if fvalue is None else fvalue + await self.dump_field(writer, fvalue, ftype, params) + + async def _load_message_field(self, reader, msg, field): + """ + Loads message field from the reader. Field is defined by the message field specification. + Returns loaded value, supports field reference. + + :param reader: + :param msg: + :param field: + :return: + """ + fname, ftype, params = field[0], field[1], field[2:] + await self.load_field(reader, ftype, params, eref(msg, fname)) + + async def _dump_message(self, writer, msg, msg_type=None): + """ + Dumps message to the writer. + + :param writer: + :param msg: + :param msg_type: + :return: + """ + mtype = msg.__class__ if msg_type is None else msg_type + fields = mtype.f_specs() + if hasattr(mtype, "serialize_archive"): + raise ValueError("Cannot directly load, has to use archive with %s" % mtype) + + for field in fields: + await self._dump_message_field(writer, msg=msg, field=field) + + async def _load_message(self, reader, msg_type, msg=None): + """ + Loads message if the given type from the reader. + Supports reading directly to existing message. + + :param reader: + :param msg_type: + :param msg: + :return: + """ + msg = msg_type() if msg is None else msg + fields = msg_type.f_specs() if msg_type else msg.__class__.f_specs() + if hasattr(msg_type, "serialize_archive"): + raise ValueError( + "Cannot directly load, has to use archive with %s" % msg_type + ) + + for field in fields: + await self._load_message_field(reader, msg, field) + + return msg + + async def _dump_variant(self, writer, elem, elem_type=None, params=None): + """ + Dumps variant type to the writer. + Supports both wrapped and raw variant. + + :param writer: + :param elem: + :param elem_type: + :param params: + :return: + """ + if isinstance(elem, VariantType) or elem_type.WRAPS_VALUE: + await dump_uint(writer, elem.variant_elem_type.VARIANT_CODE, 1) + await self.dump_field( + writer, getattr(elem, elem.variant_elem), elem.variant_elem_type + ) + + else: + fdef = find_variant_fdef(elem_type, elem) + await dump_uint(writer, fdef[1].VARIANT_CODE, 1) + await self.dump_field(writer, elem, fdef[1]) + + async def _load_variant( + self, reader, elem_type, params=None, elem=None, wrapped=None + ): + """ + Loads variant type from the reader. + Supports both wrapped and raw variant. + + :param reader: + :param elem_type: + :param params: + :param elem: + :param wrapped: + :return: + """ + is_wrapped = ( + (isinstance(elem, VariantType) or elem_type.WRAPS_VALUE) + if wrapped is None + else wrapped + ) + if is_wrapped: + elem = elem_type() if elem is None else elem + + tag = await load_uint(reader, 1) + for field in elem_type.f_specs(): + ftype = field[1] + if ftype.VARIANT_CODE == tag: + fvalue = await self.load_field( + reader, ftype, field[2:], elem if not is_wrapped else None + ) + if is_wrapped: + elem.set_variant(field[0], fvalue) + return elem if is_wrapped else fvalue + raise ValueError("Unknown tag: %s" % tag) + async def dump_blob(writer, elem, elem_type, params=None): """ @@ -527,237 +767,6 @@ async def load_unicode(reader): return str(fvalue, "utf8") -async def dump_container_size(writer, container_len, container_type, params=None): - """ - Dumps container size - per element streaming - :param writer: - :param container_len: - :param container_type: - :param params: - :return: - """ - if not container_type or not container_type.FIX_SIZE: - await dump_uvarint(writer, container_len) - elif container_len != container_type.SIZE: - raise ValueError( - "Fixed size container has not defined size: %s" % container_type.SIZE - ) - - -async def dump_container_val( - writer, elem, container_type, params=None, field_archiver=None -): - """ - Single elem dump - :param writer: - :param elem: - :param container_type: - :param params: - :return: - """ - field_archiver = field_archiver if field_archiver else dump_field - elem_type = container_elem_type(container_type, params) - await field_archiver(writer, elem, elem_type, params[1:] if params else None) - - -async def dump_container( - writer, container, container_type, params=None, field_archiver=None -): - """ - Dumps container of elements to the writer. - - :param writer: - :param container: - :param container_type: - :param params: - :param field_archiver: - :return: - """ - await dump_container_size(writer, len(container), container_type) - - field_archiver = field_archiver if field_archiver else dump_field - elem_type = container_elem_type(container_type, params) - - for elem in container: - await field_archiver(writer, elem, elem_type, params[1:] if params else None) - - -async def load_container( - reader, container_type, params=None, container=None, field_archiver=None -): - """ - Loads container of elements from the reader. Supports the container ref. - Returns loaded container. - - :param reader: - :param container_type: - :param params: - :param container: - :param field_archiver: - :return: - """ - field_archiver = field_archiver if field_archiver else load_field - - c_len = ( - container_type.SIZE if container_type.FIX_SIZE else await load_uvarint(reader) - ) - if container and c_len != len(container): - raise ValueError("Size mismatch") - - elem_type = container_elem_type(container_type, params) - res = container if container else [] - for i in range(c_len): - fvalue = await field_archiver( - reader, - elem_type, - params[1:] if params else None, - eref(res, i) if container else None, - ) - if not container: - res.append(fvalue) - return res - - -async def dump_tuple(writer, elem, elem_type, params=None, field_archiver=None): - """ - Dumps tuple of elements to the writer. - - :param writer: - :param elem: - :param elem_type: - :param params: - :param field_archiver: - :return: - """ - if len(elem) != len(elem_type.f_specs()): - raise ValueError( - "Fixed size tuple has not defined size: %s" % len(elem_type.f_specs()) - ) - await dump_uvarint(writer, len(elem)) - - field_archiver = field_archiver if field_archiver else dump_field - elem_fields = params[0] if params else None - if elem_fields is None: - elem_fields = elem_type.f_specs() - for idx, elem in enumerate(elem): - await field_archiver( - writer, elem, elem_fields[idx], params[1:] if params else None - ) - - -async def load_tuple(reader, elem_type, params=None, elem=None, field_archiver=None): - """ - Loads tuple of elements from the reader. Supports the tuple ref. - Returns loaded tuple. - - :param reader: - :param elem_type: - :param params: - :param container: - :param field_archiver: - :return: - """ - field_archiver = field_archiver if field_archiver else load_field - - c_len = await load_uvarint(reader) - if elem and c_len != len(elem): - raise ValueError("Size mismatch") - if c_len != len(elem_type.f_specs()): - raise ValueError("Tuple size mismatch") - - elem_fields = params[0] if params else None - if elem_fields is None: - elem_fields = elem_type.f_specs() - - res = elem if elem else [] - for i in range(c_len): - fvalue = await field_archiver( - reader, - elem_fields[i], - params[1:] if params else None, - eref(res, i) if elem else None, - ) - if not elem: - res.append(fvalue) - return res - - -async def dump_message_field(writer, msg, field, fvalue=None, field_archiver=None): - """ - Dumps a message field to the writer. Field is defined by the message field specification. - - :param writer: - :param msg: - :param field: - :param fvalue: - :param field_archiver: - :return: - """ - fname, ftype, params = field[0], field[1], field[2:] - fvalue = getattr(msg, fname, None) if fvalue is None else fvalue - field_archiver = field_archiver if field_archiver else dump_field - await field_archiver(writer, fvalue, ftype, params) - - -async def load_message_field(reader, msg, field, field_archiver=None): - """ - Loads message field from the reader. Field is defined by the message field specification. - Returns loaded value, supports field reference. - - :param reader: - :param msg: - :param field: - :param field_archiver: - :return: - """ - fname, ftype, params = field[0], field[1], field[2:] - field_archiver = field_archiver if field_archiver else load_field - await field_archiver(reader, ftype, params, eref(msg, fname)) - - -async def dump_message(writer, msg, msg_type=None, field_archiver=None): - """ - Dumps message to the writer. - - :param writer: - :param msg: - :param msg_type: - :param field_archiver: - :return: - """ - mtype = msg.__class__ if msg_type is None else msg_type - fields = mtype.f_specs() - if hasattr(mtype, "serialize_archive"): - raise ValueError("Cannot directly load, has to use archive with %s" % mtype) - - for field in fields: - await dump_message_field( - writer, msg=msg, field=field, field_archiver=field_archiver - ) - - -async def load_message(reader, msg_type, msg=None, field_archiver=None): - """ - Loads message if the given type from the reader. - Supports reading directly to existing message. - - :param reader: - :param msg_type: - :param msg: - :param field_archiver: - :return: - """ - msg = msg_type() if msg is None else msg - fields = msg_type.f_specs() if msg_type else msg.__class__.f_specs() - if hasattr(msg_type, "serialize_archive"): - raise ValueError("Cannot directly load, has to use archive with %s" % msg_type) - - for field in fields: - await load_message_field(reader, msg, field, field_archiver=field_archiver) - - return msg - - def find_variant_fdef(elem_type, elem): fields = elem_type.f_specs() for x in fields: @@ -771,73 +780,3 @@ def find_variant_fdef(elem_type, elem): return x raise ValueError("Unrecognized variant: %s" % elem) - - -async def dump_variant(writer, elem, elem_type=None, params=None, field_archiver=None): - """ - Dumps variant type to the writer. - Supports both wrapped and raw variant. - - :param writer: - :param elem: - :param elem_type: - :param params: - :param field_archiver: - :return: - """ - field_archiver = field_archiver if field_archiver else dump_field - if isinstance(elem, VariantType) or elem_type.WRAPS_VALUE: - await dump_uint(writer, elem.variant_elem_type.VARIANT_CODE, 1) - await field_archiver( - writer, getattr(elem, elem.variant_elem), elem.variant_elem_type - ) - - else: - fdef = find_variant_fdef(elem_type, elem) - await dump_uint(writer, fdef[1].VARIANT_CODE, 1) - await field_archiver(writer, elem, fdef[1]) - - -async def load_variant( - reader, elem_type, params=None, elem=None, wrapped=None, field_archiver=None -): - """ - Loads variant type from the reader. - Supports both wrapped and raw variant. - - :param reader: - :param elem_type: - :param params: - :param elem: - :param wrapped: - :param field_archiver: - :return: - """ - is_wrapped = ( - (isinstance(elem, VariantType) or elem_type.WRAPS_VALUE) - if wrapped is None - else wrapped - ) - if is_wrapped: - elem = elem_type() if elem is None else elem - - field_archiver = field_archiver if field_archiver else load_field - tag = await load_uint(reader, 1) - for field in elem_type.f_specs(): - ftype = field[1] - if ftype.VARIANT_CODE == tag: - fvalue = await field_archiver( - reader, ftype, field[2:], elem if not is_wrapped else None - ) - if is_wrapped: - elem.set_variant(field[0], fvalue) - return elem if is_wrapped else fvalue - raise ValueError("Unknown tag: %s" % tag) - - -async def dump_field(writer, elem, elem_type, params=None): - raise TypeError("type") - - -async def load_field(reader, elem_type, params=None, elem=None): - raise TypeError("type") diff --git a/src/trezor/messages/MessageType.py b/src/trezor/messages/MessageType.py index 2c46a341d..c07d8eaeb 100644 --- a/src/trezor/messages/MessageType.py +++ b/src/trezor/messages/MessageType.py @@ -122,6 +122,18 @@ CardanoAddress = 308 CardanoTxAck = 309 CardanoSignedTransaction = 310 +OntologyGetAddress = 350 +OntologyAddress = 351 +OntologyGetPublicKey = 352 +OntologyPublicKey = 353 +OntologySignTransfer = 354 +OntologySignedTransfer = 355 +OntologySignWithdrawOng = 356 +OntologySignedWithdrawOng = 357 +OntologySignOntIdRegister = 358 +OntologySignedOntIdRegister = 359 +OntologySignOntIdAddAttributes = 360 +OntologySignedOntIdAddAttributes = 361 RippleGetAddress = 400 RippleAddress = 401 RippleSignTx = 402 diff --git a/src/trezor/messages/OntologyAddress.py b/src/trezor/messages/OntologyAddress.py new file mode 100644 index 000000000..f45422878 --- /dev/null +++ b/src/trezor/messages/OntologyAddress.py @@ -0,0 +1,16 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologyAddress(p.MessageType): + MESSAGE_WIRE_TYPE = 351 + FIELDS = { + 1: ('address', p.UnicodeType, 0), + } + + def __init__( + self, + address: str = None, + ) -> None: + self.address = address diff --git a/src/trezor/messages/OntologyAsset.py b/src/trezor/messages/OntologyAsset.py new file mode 100644 index 000000000..daa8b0786 --- /dev/null +++ b/src/trezor/messages/OntologyAsset.py @@ -0,0 +1,4 @@ +# Automatically generated by pb2py +# fmt: off +ONT = 1 +ONG = 2 diff --git a/src/trezor/messages/OntologyGetAddress.py b/src/trezor/messages/OntologyGetAddress.py new file mode 100644 index 000000000..38388b000 --- /dev/null +++ b/src/trezor/messages/OntologyGetAddress.py @@ -0,0 +1,25 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +if __debug__: + try: + from typing import List + except ImportError: + List = None # type: ignore + + +class OntologyGetAddress(p.MessageType): + MESSAGE_WIRE_TYPE = 350 + FIELDS = { + 1: ('address_n', p.UVarintType, p.FLAG_REPEATED), + 2: ('show_display', p.BoolType, 0), + } + + def __init__( + self, + address_n: List[int] = None, + show_display: bool = None, + ) -> None: + self.address_n = address_n if address_n is not None else [] + self.show_display = show_display diff --git a/src/trezor/messages/OntologyGetPublicKey.py b/src/trezor/messages/OntologyGetPublicKey.py new file mode 100644 index 000000000..c1727741c --- /dev/null +++ b/src/trezor/messages/OntologyGetPublicKey.py @@ -0,0 +1,25 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +if __debug__: + try: + from typing import List + except ImportError: + List = None # type: ignore + + +class OntologyGetPublicKey(p.MessageType): + MESSAGE_WIRE_TYPE = 352 + FIELDS = { + 1: ('address_n', p.UVarintType, p.FLAG_REPEATED), + 2: ('show_display', p.BoolType, 0), + } + + def __init__( + self, + address_n: List[int] = None, + show_display: bool = None, + ) -> None: + self.address_n = address_n if address_n is not None else [] + self.show_display = show_display diff --git a/src/trezor/messages/OntologyOntIdAddAttributes.py b/src/trezor/messages/OntologyOntIdAddAttributes.py new file mode 100644 index 000000000..9982538a4 --- /dev/null +++ b/src/trezor/messages/OntologyOntIdAddAttributes.py @@ -0,0 +1,29 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +from .OntologyOntIdAttribute import OntologyOntIdAttribute + +if __debug__: + try: + from typing import List + except ImportError: + List = None # type: ignore + + +class OntologyOntIdAddAttributes(p.MessageType): + FIELDS = { + 1: ('ont_id', p.UnicodeType, 0), + 2: ('public_key', p.BytesType, 0), + 3: ('ont_id_attributes', OntologyOntIdAttribute, p.FLAG_REPEATED), + } + + def __init__( + self, + ont_id: str = None, + public_key: bytes = None, + ont_id_attributes: List[OntologyOntIdAttribute] = None, + ) -> None: + self.ont_id = ont_id + self.public_key = public_key + self.ont_id_attributes = ont_id_attributes if ont_id_attributes is not None else [] diff --git a/src/trezor/messages/OntologyOntIdAttribute.py b/src/trezor/messages/OntologyOntIdAttribute.py new file mode 100644 index 000000000..48cbd7db5 --- /dev/null +++ b/src/trezor/messages/OntologyOntIdAttribute.py @@ -0,0 +1,21 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologyOntIdAttribute(p.MessageType): + FIELDS = { + 1: ('key', p.UnicodeType, 0), + 2: ('type', p.UnicodeType, 0), + 3: ('value', p.UnicodeType, 0), + } + + def __init__( + self, + key: str = None, + type: str = None, + value: str = None, + ) -> None: + self.key = key + self.type = type + self.value = value diff --git a/src/trezor/messages/OntologyOntIdRegister.py b/src/trezor/messages/OntologyOntIdRegister.py new file mode 100644 index 000000000..ebe434346 --- /dev/null +++ b/src/trezor/messages/OntologyOntIdRegister.py @@ -0,0 +1,18 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologyOntIdRegister(p.MessageType): + FIELDS = { + 1: ('ont_id', p.UnicodeType, 0), + 2: ('public_key', p.BytesType, 0), + } + + def __init__( + self, + ont_id: str = None, + public_key: bytes = None, + ) -> None: + self.ont_id = ont_id + self.public_key = public_key diff --git a/src/trezor/messages/OntologyPublicKey.py b/src/trezor/messages/OntologyPublicKey.py new file mode 100644 index 000000000..d62a65a66 --- /dev/null +++ b/src/trezor/messages/OntologyPublicKey.py @@ -0,0 +1,16 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologyPublicKey(p.MessageType): + MESSAGE_WIRE_TYPE = 353 + FIELDS = { + 1: ('public_key', p.BytesType, 0), + } + + def __init__( + self, + public_key: bytes = None, + ) -> None: + self.public_key = public_key diff --git a/src/trezor/messages/OntologySignOntIdAddAttributes.py b/src/trezor/messages/OntologySignOntIdAddAttributes.py new file mode 100644 index 000000000..b42dee1b9 --- /dev/null +++ b/src/trezor/messages/OntologySignOntIdAddAttributes.py @@ -0,0 +1,31 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +from .OntologyOntIdAddAttributes import OntologyOntIdAddAttributes +from .OntologyTransaction import OntologyTransaction + +if __debug__: + try: + from typing import List + except ImportError: + List = None # type: ignore + + +class OntologySignOntIdAddAttributes(p.MessageType): + MESSAGE_WIRE_TYPE = 360 + FIELDS = { + 1: ('address_n', p.UVarintType, p.FLAG_REPEATED), + 2: ('transaction', OntologyTransaction, 0), + 3: ('ont_id_add_attributes', OntologyOntIdAddAttributes, 0), + } + + def __init__( + self, + address_n: List[int] = None, + transaction: OntologyTransaction = None, + ont_id_add_attributes: OntologyOntIdAddAttributes = None, + ) -> None: + self.address_n = address_n if address_n is not None else [] + self.transaction = transaction + self.ont_id_add_attributes = ont_id_add_attributes diff --git a/src/trezor/messages/OntologySignOntIdRegister.py b/src/trezor/messages/OntologySignOntIdRegister.py new file mode 100644 index 000000000..cf83aae5b --- /dev/null +++ b/src/trezor/messages/OntologySignOntIdRegister.py @@ -0,0 +1,31 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +from .OntologyOntIdRegister import OntologyOntIdRegister +from .OntologyTransaction import OntologyTransaction + +if __debug__: + try: + from typing import List + except ImportError: + List = None # type: ignore + + +class OntologySignOntIdRegister(p.MessageType): + MESSAGE_WIRE_TYPE = 358 + FIELDS = { + 1: ('address_n', p.UVarintType, p.FLAG_REPEATED), + 2: ('transaction', OntologyTransaction, 0), + 3: ('ont_id_register', OntologyOntIdRegister, 0), + } + + def __init__( + self, + address_n: List[int] = None, + transaction: OntologyTransaction = None, + ont_id_register: OntologyOntIdRegister = None, + ) -> None: + self.address_n = address_n if address_n is not None else [] + self.transaction = transaction + self.ont_id_register = ont_id_register diff --git a/src/trezor/messages/OntologySignTransfer.py b/src/trezor/messages/OntologySignTransfer.py new file mode 100644 index 000000000..78758cae6 --- /dev/null +++ b/src/trezor/messages/OntologySignTransfer.py @@ -0,0 +1,31 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +from .OntologyTransaction import OntologyTransaction +from .OntologyTransfer import OntologyTransfer + +if __debug__: + try: + from typing import List + except ImportError: + List = None # type: ignore + + +class OntologySignTransfer(p.MessageType): + MESSAGE_WIRE_TYPE = 354 + FIELDS = { + 1: ('address_n', p.UVarintType, p.FLAG_REPEATED), + 2: ('transaction', OntologyTransaction, 0), + 3: ('transfer', OntologyTransfer, 0), + } + + def __init__( + self, + address_n: List[int] = None, + transaction: OntologyTransaction = None, + transfer: OntologyTransfer = None, + ) -> None: + self.address_n = address_n if address_n is not None else [] + self.transaction = transaction + self.transfer = transfer diff --git a/src/trezor/messages/OntologySignWithdrawOng.py b/src/trezor/messages/OntologySignWithdrawOng.py new file mode 100644 index 000000000..b9a99b7d4 --- /dev/null +++ b/src/trezor/messages/OntologySignWithdrawOng.py @@ -0,0 +1,31 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +from .OntologyTransaction import OntologyTransaction +from .OntologyWithdrawOng import OntologyWithdrawOng + +if __debug__: + try: + from typing import List + except ImportError: + List = None # type: ignore + + +class OntologySignWithdrawOng(p.MessageType): + MESSAGE_WIRE_TYPE = 356 + FIELDS = { + 1: ('address_n', p.UVarintType, p.FLAG_REPEATED), + 2: ('transaction', OntologyTransaction, 0), + 3: ('withdraw_ong', OntologyWithdrawOng, 0), + } + + def __init__( + self, + address_n: List[int] = None, + transaction: OntologyTransaction = None, + withdraw_ong: OntologyWithdrawOng = None, + ) -> None: + self.address_n = address_n if address_n is not None else [] + self.transaction = transaction + self.withdraw_ong = withdraw_ong diff --git a/src/trezor/messages/OntologySignedOntIdAddAttributes.py b/src/trezor/messages/OntologySignedOntIdAddAttributes.py new file mode 100644 index 000000000..e88436442 --- /dev/null +++ b/src/trezor/messages/OntologySignedOntIdAddAttributes.py @@ -0,0 +1,19 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologySignedOntIdAddAttributes(p.MessageType): + MESSAGE_WIRE_TYPE = 361 + FIELDS = { + 1: ('signature', p.BytesType, 0), + 2: ('payload', p.BytesType, 0), + } + + def __init__( + self, + signature: bytes = None, + payload: bytes = None, + ) -> None: + self.signature = signature + self.payload = payload diff --git a/src/trezor/messages/OntologySignedOntIdRegister.py b/src/trezor/messages/OntologySignedOntIdRegister.py new file mode 100644 index 000000000..0b6fd3845 --- /dev/null +++ b/src/trezor/messages/OntologySignedOntIdRegister.py @@ -0,0 +1,19 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologySignedOntIdRegister(p.MessageType): + MESSAGE_WIRE_TYPE = 359 + FIELDS = { + 1: ('signature', p.BytesType, 0), + 2: ('payload', p.BytesType, 0), + } + + def __init__( + self, + signature: bytes = None, + payload: bytes = None, + ) -> None: + self.signature = signature + self.payload = payload diff --git a/src/trezor/messages/OntologySignedTransfer.py b/src/trezor/messages/OntologySignedTransfer.py new file mode 100644 index 000000000..40e24eabb --- /dev/null +++ b/src/trezor/messages/OntologySignedTransfer.py @@ -0,0 +1,19 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologySignedTransfer(p.MessageType): + MESSAGE_WIRE_TYPE = 355 + FIELDS = { + 1: ('signature', p.BytesType, 0), + 2: ('payload', p.BytesType, 0), + } + + def __init__( + self, + signature: bytes = None, + payload: bytes = None, + ) -> None: + self.signature = signature + self.payload = payload diff --git a/src/trezor/messages/OntologySignedWithdrawOng.py b/src/trezor/messages/OntologySignedWithdrawOng.py new file mode 100644 index 000000000..54d729abe --- /dev/null +++ b/src/trezor/messages/OntologySignedWithdrawOng.py @@ -0,0 +1,19 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologySignedWithdrawOng(p.MessageType): + MESSAGE_WIRE_TYPE = 357 + FIELDS = { + 1: ('signature', p.BytesType, 0), + 2: ('payload', p.BytesType, 0), + } + + def __init__( + self, + signature: bytes = None, + payload: bytes = None, + ) -> None: + self.signature = signature + self.payload = payload diff --git a/src/trezor/messages/OntologyTransaction.py b/src/trezor/messages/OntologyTransaction.py new file mode 100644 index 000000000..d2d6f1a7b --- /dev/null +++ b/src/trezor/messages/OntologyTransaction.py @@ -0,0 +1,41 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +from .OntologyTxAttribute import OntologyTxAttribute + +if __debug__: + try: + from typing import List + except ImportError: + List = None # type: ignore + + +class OntologyTransaction(p.MessageType): + FIELDS = { + 1: ('version', p.UVarintType, 0), + 2: ('type', p.UVarintType, 0), + 3: ('nonce', p.UVarintType, 0), + 4: ('gas_price', p.UVarintType, 0), + 5: ('gas_limit', p.UVarintType, 0), + 6: ('payer', p.UnicodeType, 0), + 7: ('tx_attributes', OntologyTxAttribute, p.FLAG_REPEATED), + } + + def __init__( + self, + version: int = None, + type: int = None, + nonce: int = None, + gas_price: int = None, + gas_limit: int = None, + payer: str = None, + tx_attributes: List[OntologyTxAttribute] = None, + ) -> None: + self.version = version + self.type = type + self.nonce = nonce + self.gas_price = gas_price + self.gas_limit = gas_limit + self.payer = payer + self.tx_attributes = tx_attributes if tx_attributes is not None else [] diff --git a/src/trezor/messages/OntologyTransfer.py b/src/trezor/messages/OntologyTransfer.py new file mode 100644 index 000000000..679a6dbc6 --- /dev/null +++ b/src/trezor/messages/OntologyTransfer.py @@ -0,0 +1,24 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologyTransfer(p.MessageType): + FIELDS = { + 1: ('asset', p.UVarintType, 0), + 2: ('amount', p.UVarintType, 0), + 3: ('from_address', p.UnicodeType, 0), + 4: ('to_address', p.UnicodeType, 0), + } + + def __init__( + self, + asset: int = None, + amount: int = None, + from_address: str = None, + to_address: str = None, + ) -> None: + self.asset = asset + self.amount = amount + self.from_address = from_address + self.to_address = to_address diff --git a/src/trezor/messages/OntologyTxAttribute.py b/src/trezor/messages/OntologyTxAttribute.py new file mode 100644 index 000000000..fce579c7f --- /dev/null +++ b/src/trezor/messages/OntologyTxAttribute.py @@ -0,0 +1,18 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologyTxAttribute(p.MessageType): + FIELDS = { + 1: ('usage', p.UVarintType, 0), + 2: ('data', p.BytesType, 0), + } + + def __init__( + self, + usage: int = None, + data: bytes = None, + ) -> None: + self.usage = usage + self.data = data diff --git a/src/trezor/messages/OntologyWithdrawOng.py b/src/trezor/messages/OntologyWithdrawOng.py new file mode 100644 index 000000000..b4977f59f --- /dev/null +++ b/src/trezor/messages/OntologyWithdrawOng.py @@ -0,0 +1,21 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + + +class OntologyWithdrawOng(p.MessageType): + FIELDS = { + 1: ('amount', p.UVarintType, 0), + 2: ('from_address', p.UnicodeType, 0), + 3: ('to_address', p.UnicodeType, 0), + } + + def __init__( + self, + amount: int = None, + from_address: str = None, + to_address: str = None, + ) -> None: + self.amount = amount + self.from_address = from_address + self.to_address = to_address diff --git a/src/trezor/messages/TezosCurveType.py b/src/trezor/messages/TezosCurveType.py new file mode 100644 index 000000000..3c1415d30 --- /dev/null +++ b/src/trezor/messages/TezosCurveType.py @@ -0,0 +1,5 @@ +# Automatically generated by pb2py +# fmt: off +Ed25519 = 0 +Secp256k1 = 1 +P256 = 2 diff --git a/src/trezor/messages/TezosOperationCommon.py b/src/trezor/messages/TezosDelegationOp.py similarity index 53% rename from src/trezor/messages/TezosOperationCommon.py rename to src/trezor/messages/TezosDelegationOp.py index bdcc8a99b..0058bc953 100644 --- a/src/trezor/messages/TezosOperationCommon.py +++ b/src/trezor/messages/TezosDelegationOp.py @@ -5,31 +5,28 @@ from .TezosContractID import TezosContractID -class TezosOperationCommon(p.MessageType): +class TezosDelegationOp(p.MessageType): FIELDS = { - 1: ('branch', p.BytesType, 0), - 2: ('tag', p.UVarintType, 0), - 3: ('source', TezosContractID, 0), - 4: ('fee', p.UVarintType, 0), - 5: ('counter', p.UVarintType, 0), - 6: ('gas_limit', p.UVarintType, 0), - 7: ('storage_limit', p.UVarintType, 0), + 1: ('source', TezosContractID, 0), + 2: ('fee', p.UVarintType, 0), + 3: ('counter', p.UVarintType, 0), + 4: ('gas_limit', p.UVarintType, 0), + 5: ('storage_limit', p.UVarintType, 0), + 6: ('delegate', p.BytesType, 0), } def __init__( self, - branch: bytes = None, - tag: int = None, source: TezosContractID = None, fee: int = None, counter: int = None, gas_limit: int = None, storage_limit: int = None, + delegate: bytes = None, ) -> None: - self.branch = branch - self.tag = tag self.source = source self.fee = fee self.counter = counter self.gas_limit = gas_limit self.storage_limit = storage_limit + self.delegate = delegate diff --git a/src/trezor/messages/TezosDelegationType.py b/src/trezor/messages/TezosDelegationType.py deleted file mode 100644 index a0d43a728..000000000 --- a/src/trezor/messages/TezosDelegationType.py +++ /dev/null @@ -1,15 +0,0 @@ -# Automatically generated by pb2py -# fmt: off -import protobuf as p - - -class TezosDelegationType(p.MessageType): - FIELDS = { - 1: ('delegate', p.BytesType, 0), - } - - def __init__( - self, - delegate: bytes = None, - ) -> None: - self.delegate = delegate diff --git a/src/trezor/messages/TezosGetAddress.py b/src/trezor/messages/TezosGetAddress.py index fa57b39b2..06569c835 100644 --- a/src/trezor/messages/TezosGetAddress.py +++ b/src/trezor/messages/TezosGetAddress.py @@ -13,13 +13,16 @@ class TezosGetAddress(p.MessageType): MESSAGE_WIRE_TYPE = 150 FIELDS = { 1: ('address_n', p.UVarintType, p.FLAG_REPEATED), - 2: ('show_display', p.BoolType, 0), + 2: ('curve', p.UVarintType, 0), # default=Ed25519 + 3: ('show_display', p.BoolType, 0), } def __init__( self, address_n: List[int] = None, + curve: int = None, show_display: bool = None, ) -> None: self.address_n = address_n if address_n is not None else [] + self.curve = curve self.show_display = show_display diff --git a/src/trezor/messages/TezosGetPublicKey.py b/src/trezor/messages/TezosGetPublicKey.py index 548b49f13..2daa9c56a 100644 --- a/src/trezor/messages/TezosGetPublicKey.py +++ b/src/trezor/messages/TezosGetPublicKey.py @@ -13,13 +13,16 @@ class TezosGetPublicKey(p.MessageType): MESSAGE_WIRE_TYPE = 154 FIELDS = { 1: ('address_n', p.UVarintType, p.FLAG_REPEATED), - 2: ('show_display', p.BoolType, 0), + 2: ('curve', p.UVarintType, 0), # default=Ed25519 + 3: ('show_display', p.BoolType, 0), } def __init__( self, address_n: List[int] = None, + curve: int = None, show_display: bool = None, ) -> None: self.address_n = address_n if address_n is not None else [] + self.curve = curve self.show_display = show_display diff --git a/src/trezor/messages/TezosOperationType.py b/src/trezor/messages/TezosOperationType.py deleted file mode 100644 index d84d4f3b9..000000000 --- a/src/trezor/messages/TezosOperationType.py +++ /dev/null @@ -1,5 +0,0 @@ -# Automatically generated by pb2py -# fmt: off -Transaction = 8 -Origination = 9 -Delegation = 10 diff --git a/src/trezor/messages/TezosOriginationOp.py b/src/trezor/messages/TezosOriginationOp.py new file mode 100644 index 000000000..65585500d --- /dev/null +++ b/src/trezor/messages/TezosOriginationOp.py @@ -0,0 +1,47 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +from .TezosContractID import TezosContractID + + +class TezosOriginationOp(p.MessageType): + FIELDS = { + 1: ('source', TezosContractID, 0), + 2: ('fee', p.UVarintType, 0), + 3: ('counter', p.UVarintType, 0), + 4: ('gas_limit', p.UVarintType, 0), + 5: ('storage_limit', p.UVarintType, 0), + 6: ('manager_pubkey', p.BytesType, 0), + 7: ('balance', p.UVarintType, 0), + 8: ('spendable', p.BoolType, 0), + 9: ('delegatable', p.BoolType, 0), + 10: ('delegate', p.BytesType, 0), + 11: ('script', p.BytesType, 0), + } + + def __init__( + self, + source: TezosContractID = None, + fee: int = None, + counter: int = None, + gas_limit: int = None, + storage_limit: int = None, + manager_pubkey: bytes = None, + balance: int = None, + spendable: bool = None, + delegatable: bool = None, + delegate: bytes = None, + script: bytes = None, + ) -> None: + self.source = source + self.fee = fee + self.counter = counter + self.gas_limit = gas_limit + self.storage_limit = storage_limit + self.manager_pubkey = manager_pubkey + self.balance = balance + self.spendable = spendable + self.delegatable = delegatable + self.delegate = delegate + self.script = script diff --git a/src/trezor/messages/TezosOriginationType.py b/src/trezor/messages/TezosOriginationType.py deleted file mode 100644 index 854717b2f..000000000 --- a/src/trezor/messages/TezosOriginationType.py +++ /dev/null @@ -1,30 +0,0 @@ -# Automatically generated by pb2py -# fmt: off -import protobuf as p - - -class TezosOriginationType(p.MessageType): - FIELDS = { - 1: ('manager_pubkey', p.BytesType, 0), - 2: ('balance', p.UVarintType, 0), - 3: ('spendable', p.BoolType, 0), - 4: ('delegatable', p.BoolType, 0), - 5: ('delegate', p.BytesType, 0), - 6: ('script', p.BytesType, 0), - } - - def __init__( - self, - manager_pubkey: bytes = None, - balance: int = None, - spendable: bool = None, - delegatable: bool = None, - delegate: bytes = None, - script: bytes = None, - ) -> None: - self.manager_pubkey = manager_pubkey - self.balance = balance - self.spendable = spendable - self.delegatable = delegatable - self.delegate = delegate - self.script = script diff --git a/src/trezor/messages/TezosPublicKey.py b/src/trezor/messages/TezosPublicKey.py index 99c4fdc5b..9a4a40d0c 100644 --- a/src/trezor/messages/TezosPublicKey.py +++ b/src/trezor/messages/TezosPublicKey.py @@ -6,11 +6,11 @@ class TezosPublicKey(p.MessageType): MESSAGE_WIRE_TYPE = 155 FIELDS = { - 1: ('public_key', p.BytesType, 0), + 1: ('public_key', p.UnicodeType, 0), } def __init__( self, - public_key: bytes = None, + public_key: str = None, ) -> None: self.public_key = public_key diff --git a/src/trezor/messages/TezosRevealOp.py b/src/trezor/messages/TezosRevealOp.py new file mode 100644 index 000000000..2d2111a8a --- /dev/null +++ b/src/trezor/messages/TezosRevealOp.py @@ -0,0 +1,32 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +from .TezosContractID import TezosContractID + + +class TezosRevealOp(p.MessageType): + FIELDS = { + 1: ('source', TezosContractID, 0), + 2: ('fee', p.UVarintType, 0), + 3: ('counter', p.UVarintType, 0), + 4: ('gas_limit', p.UVarintType, 0), + 5: ('storage_limit', p.UVarintType, 0), + 6: ('public_key', p.BytesType, 0), + } + + def __init__( + self, + source: TezosContractID = None, + fee: int = None, + counter: int = None, + gas_limit: int = None, + storage_limit: int = None, + public_key: bytes = None, + ) -> None: + self.source = source + self.fee = fee + self.counter = counter + self.gas_limit = gas_limit + self.storage_limit = storage_limit + self.public_key = public_key diff --git a/src/trezor/messages/TezosSignTx.py b/src/trezor/messages/TezosSignTx.py index eaaebab25..b7c963456 100644 --- a/src/trezor/messages/TezosSignTx.py +++ b/src/trezor/messages/TezosSignTx.py @@ -2,10 +2,10 @@ # fmt: off import protobuf as p -from .TezosDelegationType import TezosDelegationType -from .TezosOperationCommon import TezosOperationCommon -from .TezosOriginationType import TezosOriginationType -from .TezosTransactionType import TezosTransactionType +from .TezosDelegationOp import TezosDelegationOp +from .TezosOriginationOp import TezosOriginationOp +from .TezosRevealOp import TezosRevealOp +from .TezosTransactionOp import TezosTransactionOp if __debug__: try: @@ -18,22 +18,28 @@ class TezosSignTx(p.MessageType): MESSAGE_WIRE_TYPE = 152 FIELDS = { 1: ('address_n', p.UVarintType, p.FLAG_REPEATED), - 2: ('operation', TezosOperationCommon, 0), - 3: ('transaction', TezosTransactionType, 0), - 4: ('origination', TezosOriginationType, 0), - 5: ('delegation', TezosDelegationType, 0), + 2: ('curve', p.UVarintType, 0), # default=Ed25519 + 3: ('branch', p.BytesType, 0), + 4: ('reveal', TezosRevealOp, 0), + 5: ('transaction', TezosTransactionOp, 0), + 6: ('origination', TezosOriginationOp, 0), + 7: ('delegation', TezosDelegationOp, 0), } def __init__( self, address_n: List[int] = None, - operation: TezosOperationCommon = None, - transaction: TezosTransactionType = None, - origination: TezosOriginationType = None, - delegation: TezosDelegationType = None, + curve: int = None, + branch: bytes = None, + reveal: TezosRevealOp = None, + transaction: TezosTransactionOp = None, + origination: TezosOriginationOp = None, + delegation: TezosDelegationOp = None, ) -> None: self.address_n = address_n if address_n is not None else [] - self.operation = operation + self.curve = curve + self.branch = branch + self.reveal = reveal self.transaction = transaction self.origination = origination self.delegation = delegation diff --git a/src/trezor/messages/TezosSignedTx.py b/src/trezor/messages/TezosSignedTx.py index e6dd9555c..3db0c180e 100644 --- a/src/trezor/messages/TezosSignedTx.py +++ b/src/trezor/messages/TezosSignedTx.py @@ -6,14 +6,14 @@ class TezosSignedTx(p.MessageType): MESSAGE_WIRE_TYPE = 153 FIELDS = { - 1: ('signature', p.BytesType, 0), + 1: ('signature', p.UnicodeType, 0), 2: ('sig_op_contents', p.BytesType, 0), 3: ('operation_hash', p.UnicodeType, 0), } def __init__( self, - signature: bytes = None, + signature: str = None, sig_op_contents: bytes = None, operation_hash: str = None, ) -> None: diff --git a/src/trezor/messages/TezosTransactionOp.py b/src/trezor/messages/TezosTransactionOp.py new file mode 100644 index 000000000..1b196fd70 --- /dev/null +++ b/src/trezor/messages/TezosTransactionOp.py @@ -0,0 +1,38 @@ +# Automatically generated by pb2py +# fmt: off +import protobuf as p + +from .TezosContractID import TezosContractID + + +class TezosTransactionOp(p.MessageType): + FIELDS = { + 1: ('source', TezosContractID, 0), + 2: ('fee', p.UVarintType, 0), + 3: ('counter', p.UVarintType, 0), + 4: ('gas_limit', p.UVarintType, 0), + 5: ('storage_limit', p.UVarintType, 0), + 6: ('amount', p.UVarintType, 0), + 7: ('destination', TezosContractID, 0), + 8: ('parameters', p.BytesType, 0), + } + + def __init__( + self, + source: TezosContractID = None, + fee: int = None, + counter: int = None, + gas_limit: int = None, + storage_limit: int = None, + amount: int = None, + destination: TezosContractID = None, + parameters: bytes = None, + ) -> None: + self.source = source + self.fee = fee + self.counter = counter + self.gas_limit = gas_limit + self.storage_limit = storage_limit + self.amount = amount + self.destination = destination + self.parameters = parameters diff --git a/src/trezor/messages/TezosTransactionType.py b/src/trezor/messages/TezosTransactionType.py deleted file mode 100644 index 12e88a0fa..000000000 --- a/src/trezor/messages/TezosTransactionType.py +++ /dev/null @@ -1,23 +0,0 @@ -# Automatically generated by pb2py -# fmt: off -import protobuf as p - -from .TezosContractID import TezosContractID - - -class TezosTransactionType(p.MessageType): - FIELDS = { - 1: ('amount', p.UVarintType, 0), - 2: ('destination', TezosContractID, 0), - 3: ('parameters', p.BytesType, 0), - } - - def __init__( - self, - amount: int = None, - destination: TezosContractID = None, - parameters: bytes = None, - ) -> None: - self.amount = amount - self.destination = destination - self.parameters = parameters diff --git a/tests/test_apps.monero.bulletproof.py b/tests/test_apps.monero.bulletproof.py new file mode 100644 index 000000000..e079d1722 --- /dev/null +++ b/tests/test_apps.monero.bulletproof.py @@ -0,0 +1,149 @@ +from common import * + +from apps.monero.xmr import bulletproof as bp, common, crypto, monero +from apps.monero.xmr.serialize_messages.tx_rsig_bulletproof import Bulletproof + + +class TestMoneroBulletproof(unittest.TestCase): + def test_1(self): + pass + + def mask_consistency_check(self, bpi): + self.assertEqual(bpi.sL(0), bpi.sL(0)) + self.assertEqual(bpi.sL(1), bpi.sL(1)) + self.assertEqual(bpi.sL(63), bpi.sL(63)) + self.assertNotEqual(bpi.sL(1), bpi.sL(0)) + + self.assertEqual(bpi.sR(0), bpi.sR(0)) + self.assertEqual(bpi.sR(1), bpi.sR(1)) + self.assertEqual(bpi.sR(63), bpi.sR(63)) + self.assertNotEqual(bpi.sR(1), bpi.sR(0)) + + self.assertNotEqual(bpi.sL(0), bpi.sR(0)) + self.assertNotEqual(bpi.sL(1), bpi.sR(1)) + self.assertNotEqual(bpi.sL(63), bpi.sR(63)) + + bpi.init_vct() + ve1 = bp._ensure_dst_key() + ve2 = bp._ensure_dst_key() + bpi.vector_exponent(bpi.v_aL, bpi.v_aR, ve1) + bpi.vector_exponent(bpi.v_aL, bpi.v_aR, ve2) + + bpi.vector_exponent(bpi.v_sL, bpi.v_sR, ve1) + bpi.vector_exponent(bpi.v_sL, bpi.v_sR, ve2) + self.assertEqual(ve1, ve2) + + def test_masks(self): + bpi = bp.BulletProofBuilder() + val = crypto.sc_init(123) + mask = crypto.sc_init(432) + bpi.set_input(val, mask) + self.mask_consistency_check(bpi) + + # Randomized masks + bpi.use_det_masks = False + self.mask_consistency_check(bpi) + + def test_verify(self): + bpi = bp.BulletProofBuilder() + + # fmt: off + bp_proof = Bulletproof( + V=[bytes( + [0x67, 0x54, 0xbf, 0x40, 0xcb, 0x45, 0x63, 0x0d, 0x4b, 0xea, 0x08, 0x9e, 0xd7, 0x86, 0xec, 0x3c, 0xe5, + 0xbd, 0x4e, 0xed, 0x8f, 0xf3, 0x25, 0x76, 0xae, 0xca, 0xb8, 0x9e, 0xf2, 0x5e, 0x41, 0x16])], + A=bytes( + [0x96, 0x10, 0x17, 0x66, 0x87, 0x7e, 0xef, 0x97, 0xb3, 0x82, 0xfb, 0x8e, 0x0c, 0x2a, 0x93, 0x68, 0x9e, + 0x05, 0x22, 0x07, 0xe3, 0x30, 0x94, 0x20, 0x58, 0x6f, 0x5d, 0x01, 0x6d, 0x4e, 0xd5, 0x88]), + S=bytes( + [0x50, 0x51, 0x38, 0x32, 0x96, 0x20, 0x7c, 0xc9, 0x60, 0x4d, 0xac, 0x7c, 0x7c, 0x21, 0xf9, 0xad, 0x1c, + 0xc2, 0x2d, 0xee, 0x88, 0x7b, 0xa2, 0xe2, 0x61, 0x81, 0x46, 0xf5, 0x99, 0xc3, 0x12, 0x57]), + T1=bytes( + [0x1a, 0x7d, 0x06, 0x51, 0x41, 0xe6, 0x12, 0xbe, 0xad, 0xd7, 0x68, 0x60, 0x85, 0xfc, 0xc4, 0x86, 0x0b, + 0x39, 0x4b, 0x06, 0xf7, 0xca, 0xb3, 0x29, 0xdf, 0x1d, 0xbf, 0x96, 0x5f, 0xbe, 0x8c, 0x87]), + T2=bytes( + [0x57, 0xae, 0x91, 0x04, 0xfa, 0xac, 0xf3, 0x73, 0x75, 0xf2, 0x83, 0xd6, 0x9a, 0xcb, 0xef, 0xe4, 0xfc, + 0xe5, 0x37, 0x55, 0x52, 0x09, 0xb5, 0x60, 0x6d, 0xab, 0x46, 0x85, 0x01, 0x23, 0x9e, 0x47]), + taux=bytes( + [0x44, 0x7a, 0x87, 0xd9, 0x5f, 0x1b, 0x17, 0xed, 0x53, 0x7f, 0xc1, 0x4f, 0x91, 0x9b, 0xca, 0x68, 0xce, + 0x20, 0x43, 0xc0, 0x88, 0xf1, 0xdf, 0x12, 0x7b, 0xd7, 0x7f, 0xe0, 0x27, 0xef, 0xef, 0x0d]), + mu=bytes( + [0x32, 0xf9, 0xe4, 0xe1, 0xc2, 0xd8, 0xe4, 0xb0, 0x0d, 0x49, 0xd1, 0x02, 0xbc, 0xcc, 0xf7, 0xa2, 0x5a, + 0xc7, 0x28, 0xf3, 0x05, 0xb5, 0x64, 0x2e, 0xde, 0xcf, 0x01, 0x61, 0xb8, 0x62, 0xfb, 0x0d]), + L=[ + bytes([0xde, 0x71, 0xca, 0x09, 0xf9, 0xd9, 0x1f, 0xa2, 0xae, 0xdf, 0x39, 0x49, 0x04, 0xaa, 0x6b, 0x58, + 0x67, 0x9d, 0x61, 0xa6, 0xfa, 0xec, 0x81, 0xf6, 0x4c, 0x15, 0x09, 0x9d, 0x10, 0x21, 0xff, 0x39]), + bytes([0x90, 0x47, 0xbf, 0xf0, 0x1f, 0x72, 0x47, 0x4e, 0xd5, 0x58, 0xfb, 0xc1, 0x16, 0x43, 0xb7, 0xd8, + 0xb1, 0x00, 0xa4, 0xa3, 0x19, 0x9b, 0xda, 0x5b, 0x27, 0xd3, 0x6c, 0x5a, 0x87, 0xf8, 0xf0, 0x28]), + bytes([0x03, 0x45, 0xef, 0x57, 0x19, 0x8b, 0xc7, 0x38, 0xb7, 0xcb, 0x9c, 0xe7, 0xe8, 0x23, 0x27, 0xbb, + 0xd3, 0x54, 0xcb, 0x38, 0x3c, 0x24, 0x8a, 0x60, 0x11, 0x20, 0x92, 0x99, 0xec, 0x35, 0x71, 0x9f]), + bytes([0x7a, 0xb6, 0x36, 0x42, 0x36, 0x83, 0xf3, 0xa6, 0xc1, 0x24, 0xc5, 0x63, 0xb0, 0x4c, 0x8b, 0xef, + 0x7c, 0x77, 0x25, 0x83, 0xa8, 0xbb, 0x8b, 0x57, 0x75, 0x1c, 0xb6, 0xd7, 0xca, 0xc9, 0x0d, 0x78]), + bytes([0x9d, 0x79, 0x66, 0x21, 0x64, 0x72, 0x97, 0x08, 0xa0, 0x5a, 0x94, 0x5a, 0x94, 0x7b, 0x11, 0xeb, + 0x4e, 0xe9, 0x43, 0x2f, 0x08, 0xa2, 0x57, 0xa5, 0xd5, 0x99, 0xb0, 0xa7, 0xde, 0x78, 0x80, 0xb7]), + bytes([0x9f, 0x88, 0x5c, 0xa5, 0xeb, 0x08, 0xef, 0x1a, 0xcf, 0xbb, 0x1d, 0x04, 0xc5, 0x47, 0x24, 0x37, + 0x49, 0xe4, 0x4e, 0x9c, 0x5d, 0x56, 0xd0, 0x97, 0xfd, 0x8a, 0xe3, 0x23, 0x1d, 0xab, 0x16, 0x03]), + ], + R=[ + bytes([0xae, 0x89, 0xeb, 0xa8, 0x5b, 0xd5, 0x65, 0xd6, 0x9f, 0x2a, 0xfd, 0x04, 0x66, 0xad, 0xb1, 0xf3, + 0x5e, 0xf6, 0x60, 0xa7, 0x26, 0x94, 0x3b, 0x72, 0x5a, 0x5c, 0x80, 0xfa, 0x0f, 0x75, 0x48, 0x27]), + bytes([0xc9, 0x1a, 0x61, 0x70, 0x6d, 0xea, 0xea, 0xb2, 0x42, 0xff, 0x27, 0x3b, 0x8e, 0x94, 0x07, 0x75, + 0x40, 0x7d, 0x33, 0xde, 0xfc, 0xbd, 0x53, 0xa0, 0x2a, 0xf9, 0x0c, 0x36, 0xb0, 0xdd, 0xbe, 0x8d]), + bytes([0xb7, 0x39, 0x7a, 0x0e, 0xa1, 0x42, 0x0f, 0x94, 0x62, 0x24, 0xcf, 0x54, 0x75, 0xe3, 0x0b, 0x0f, + 0xfb, 0xcb, 0x67, 0x7b, 0xbc, 0x98, 0x36, 0x01, 0x9f, 0x73, 0xa0, 0x70, 0xa1, 0x7e, 0xf0, 0xcf]), + bytes([0x40, 0x06, 0xd4, 0xfa, 0x22, 0x7c, 0x82, 0xbf, 0xe8, 0xe0, 0x35, 0x13, 0x28, 0xa2, 0xb9, 0x51, + 0xa3, 0x37, 0x34, 0xc0, 0xa6, 0x43, 0xd6, 0xb7, 0x7a, 0x40, 0xae, 0xf9, 0x36, 0x0e, 0xe3, 0xcc]), + bytes([0x88, 0x38, 0x64, 0xe9, 0x63, 0xe3, 0x33, 0xd9, 0xf6, 0xca, 0x47, 0xc4, 0xc7, 0x36, 0x70, 0x01, + 0xd2, 0xe4, 0x8c, 0x9f, 0x25, 0xc2, 0xce, 0xcf, 0x81, 0x89, 0x4f, 0x24, 0xcb, 0xb8, 0x40, 0x73]), + bytes([0xdc, 0x35, 0x65, 0xed, 0x6b, 0xb0, 0xa7, 0x1a, 0x1b, 0xf3, 0xd6, 0xfb, 0x47, 0x00, 0x48, 0x00, + 0x20, 0x6d, 0xd4, 0xeb, 0xff, 0xb9, 0xdc, 0x43, 0x30, 0x8a, 0x90, 0xfe, 0x43, 0x74, 0x75, 0x68]), + ], + a=bytes( + [0xb4, 0x8e, 0xc2, 0x31, 0xce, 0x05, 0x9a, 0x7a, 0xbc, 0x82, 0x8c, 0x30, 0xb3, 0xe3, 0x80, 0x86, 0x05, + 0xb8, 0x4c, 0x93, 0x9a, 0x8e, 0xce, 0x39, 0x0f, 0xb6, 0xee, 0x28, 0xf6, 0x7e, 0xd5, 0x07]), + b=bytes( + [0x47, 0x10, 0x62, 0xc2, 0xad, 0xc7, 0xe2, 0xc9, 0x14, 0x6f, 0xf4, 0xd1, 0xfe, 0x52, 0xa9, 0x1a, 0xe4, + 0xb6, 0xd0, 0x25, 0x4b, 0x19, 0x80, 0x7c, 0xcd, 0x62, 0x62, 0x1d, 0x97, 0x20, 0x71, 0x0b]), + t=bytes( + [0x47, 0x06, 0xea, 0x76, 0x8f, 0xdb, 0xa3, 0x15, 0xe0, 0x2c, 0x6b, 0x25, 0xa1, 0xf7, 0x3c, 0xc8, 0x1d, + 0x97, 0xa6, 0x52, 0x48, 0x75, 0x37, 0xf9, 0x1e, 0x14, 0xac, 0xb1, 0x2a, 0x34, 0xc6, 0x06]) + ) + # fmt: on + + self.assertTrue(bpi.verify(bp_proof)) + + def test_prove(self): + bpi = bp.BulletProofBuilder() + val = crypto.sc_init(123) + mask = crypto.sc_init(432) + bpi.set_input(val, mask) + bp_res = bpi.prove() + bpi.verify(bp_res) + + try: + bp_res.S[0] += 1 + bpi.verify(bp_res) + self.fail("Verification should have failed") + except: + pass + + def test_prove_2(self): + bpi = bp.BulletProofBuilder() + val = crypto.sc_init((1 << 30) - 1 + 16) + mask = crypto.random_scalar() + bpi.set_input(val, mask) + bp_res = bpi.prove() + bpi.verify(bp_res) + + def test_prove_random_masks(self): + bpi = bp.BulletProofBuilder() + bpi.use_det_masks = False # trully randomly generated mask vectors + val = crypto.sc_init((1 << 30) - 1 + 16) + mask = crypto.random_scalar() + bpi.set_input(val, mask) + bp_res = bpi.prove() + bpi.verify(bp_res) + + +if __name__ == "__main__": + unittest.main() diff --git a/tests/test_apps.monero.crypto.py b/tests/test_apps.monero.crypto.py new file mode 100644 index 000000000..61ff44b2a --- /dev/null +++ b/tests/test_apps.monero.crypto.py @@ -0,0 +1,218 @@ +from common import * + +from apps.monero.xmr import common, crypto, monero +from apps.monero.xmr.sub.addr import encode_addr +from apps.monero.xmr.sub.xmr_net import net_version, NetworkTypes +from apps.monero.xmr.sub.creds import AccountCreds + + +class TestMoneroCrypto(unittest.TestCase): + def test_encoding(self): + point = unhexlify( + b"2486224797d05cae3cba4be043be2db0df381f3f19cfa113f86ab38e3d8d2bd0" + ) + self.assertEqual(point, crypto.encodepoint(crypto.decodepoint(point))) + self.assertTrue( + crypto.point_eq( + crypto.decodepoint(point), + crypto.decodepoint(crypto.encodepoint(crypto.decodepoint(point))), + ) + ) + + def test_scalarmult_base(self): + scalar = crypto.decodeint( + unhexlify( + b"a0eea49140a3b036da30eacf64bd9d56ce3ef68ba82ef13571ec511edbcf8303" + ) + ) + exp = unhexlify( + b"16bb4a3c44e2ced511fc0d4cd86b13b3af21efc99fb0356199fac489f2544c09" + ) + + res = crypto.scalarmult_base(scalar) + self.assertEqual(exp, crypto.encodepoint(res)) + self.assertTrue(crypto.point_eq(crypto.decodepoint(exp), res)) + + scalar = crypto.decodeint( + unhexlify( + b"fd290dce39f781aebbdbd24584ed6d48bd300de19d9c3decfda0a6e2c6751d0f" + ) + ) + exp = unhexlify( + b"123daf90fc26f13c6529e6b49bfed498995ac383ef19c0db6771143f24ba8dd5" + ) + + res = crypto.scalarmult_base(scalar) + self.assertEqual(exp, crypto.encodepoint(res)) + self.assertTrue(crypto.point_eq(crypto.decodepoint(exp), res)) + + def test_scalarmult(self): + priv = unhexlify( + b"3482fb9735ef879fcae5ec7721b5d3646e155c4fb58d6cc11c732c9c9b76620a" + ) + pub = unhexlify( + b"2486224797d05cae3cba4be043be2db0df381f3f19cfa113f86ab38e3d8d2bd0" + ) + exp = unhexlify( + b"adcd1f5881f46f254900a03c654e71950a88a0236fa0a3a946c9b8daed6ef43d" + ) + + res = crypto.scalarmult(crypto.decodepoint(pub), crypto.decodeint(priv)) + self.assertEqual(exp, crypto.encodepoint(res)) + self.assertTrue(crypto.point_eq(crypto.decodepoint(exp), res)) + + def test_cn_fast_hash(self): + inp = unhexlify( + b"259ef2aba8feb473cf39058a0fe30b9ff6d245b42b6826687ebd6b63128aff6405" + ) + res = crypto.cn_fast_hash(inp) + self.assertEqual( + res, + unhexlify( + b"86db87b83fb1246efca5f3b0db09ce3fa4d605b0d10e6507cac253dd31a3ec16" + ), + ) + + def test_hash_to_scalar(self): + inp = unhexlify( + b"259ef2aba8feb473cf39058a0fe30b9ff6d245b42b6826687ebd6b63128aff6405" + ) + + res = crypto.hash_to_scalar(inp) + exp = crypto.decodeint( + unhexlify( + b"9907925b254e12162609fc0dfd0fef2aa4d605b0d10e6507cac253dd31a3ec06" + ) + ) + self.assertTrue(crypto.sc_eq(res, exp)) + + def test_hash_to_point(self): + data = unhexlify( + b"42f6835bf83114a1f5f6076fe79bdfa0bd67c74b88f127d54572d3910dd09201" + ) + res = crypto.hash_to_ec(data) + res_p = crypto.encodepoint(res) + self.assertEqual( + res_p, + unhexlify( + b"54863a0464c008acc99cffb179bc6cf34eb1bbdf6c29f7a070a7c6376ae30ab5" + ), + ) + + def test_derivation_to_scalar(self): + derivation = unhexlify( + b"e720a09f2e3a0bbf4e4ba7ad93653bb296885510121f806acb2a5f9168fafa01" + ) + scalar = unhexlify( + b"25d08763414c379aa9cf989cdcb3cadd36bd5193b500107d6bf5f921f18e470e" + ) + + sc_int = crypto.derivation_to_scalar(crypto.decodepoint(derivation), 0) + self.assertEqual(scalar, crypto.encodeint(sc_int)) + + def test_generate_key_derivation(self): + key_pub = crypto.decodepoint( + unhexlify( + b"7739c95d3298e2f87362dba9e0e0b3980a692ae8e2f16796b0e382098cd6bd83" + ) + ) + key_priv = crypto.decodeint( + unhexlify( + b"3482fb9735ef879fcae5ec7721b5d3646e155c4fb58d6cc11c732c9c9b76620a" + ) + ) + deriv_exp = unhexlify( + b"fa188a45a0e4daccc0e6d4f6f6858fd46392104be74183ec0047e7e9f4eaf739" + ) + + self.assertEqual( + deriv_exp, + crypto.encodepoint(crypto.generate_key_derivation(key_pub, key_priv)), + ) + + def test_h(self): + H = unhexlify( + b"8b655970153799af2aeadc9ff1add0ea6c7251d54154cfa92c173a0dd39c1f94" + ) + self.assertEqual(crypto.encodepoint(crypto.gen_H()), H) + + def test_wallet_addr(self): + addr = encode_addr( + net_version(), + unhexlify( + b"3bec484c5d7f0246af520aab550452b5b6013733feabebd681c4a60d457b7fc1" + ), + unhexlify( + b"2d5918e31d3c003da3c778592c07b398ad6f961a67082a75fd49394d51e69bbe" + ), + ) + + self.assertEqual( + addr, + b"43tpGG9PKbwCpjRvNLn1jwXPpnacw2uVUcszAtgmDiVcZK4VgHwjJT9BJz1WGF9eMxSYASp8yNMkuLjeQfWqJn3CNWdWfzV", + ) + + w = AccountCreds.new_wallet( + crypto.b16_to_scalar( + b"4ce88c168e0f5f8d6524f712d5f8d7d83233b1e7a2a60b5aba5206cc0ea2bc08" + ), + crypto.b16_to_scalar( + b"f2644a3dd97d43e87887e74d1691d52baa0614206ad1b0c239ff4aa3b501750a" + ), + network_type=NetworkTypes.TESTNET, + ) + self.assertEqual( + w.address, + b"9vacMKaj8JJV6MnwDzh2oNVdwTLJfTDyNRiB6NzV9TT7fqvzLivH2dB8Tv7VYR3ncn8vCb3KdNMJzQWrPAF1otYJ9cPKpkr", + ) + + def test_derive_subaddress_public_key(self): + out_key = crypto.decodepoint( + unhexlify( + b"f4efc29da4ccd6bc6e81f52a6f47b2952966442a7efb49901cce06a7a3bef3e5" + ) + ) + deriv = crypto.decodepoint( + unhexlify( + b"259ef2aba8feb473cf39058a0fe30b9ff6d245b42b6826687ebd6b63128aff64" + ) + ) + res = crypto.encodepoint(monero.derive_subaddress_public_key(out_key, deriv, 5)) + self.assertEqual( + res, + unhexlify( + b"5a10cca900ee47a7f412cd661b29f5ab356d6a1951884593bb170b5ec8b6f2e8" + ), + ) + + def test_get_subaddress_secret_key(self): + a = crypto.b16_to_scalar( + b"4ce88c168e0f5f8d6524f712d5f8d7d83233b1e7a2a60b5aba5206cc0ea2bc08" + ) + m = monero.get_subaddress_secret_key(secret_key=a, major=0, minor=1) + self.assertEqual( + crypto.encodeint(m), + unhexlify( + b"b6ff4d689b95e3310efbf683850c075bcde46361923054e42ef30016b287ff0c" + ), + ) + + def test_public_spend(self): + derivation = unhexlify( + b"e720a09f2e3a0bbf4e4ba7ad93653bb296885510121f806acb2a5f9168fafa01" + ) + base = unhexlify( + b"7d996b0f2db6dbb5f2a086211f2399a4a7479b2c911af307fdc3f7f61a88cb0e" + ) + pkey_ex = unhexlify( + b"0846cae7405077b6b7800f0b932c10a186448370b6db318f8c9e13f781dab546" + ) + + pkey_comp = crypto.derive_public_key( + crypto.decodepoint(derivation), 0, crypto.decodepoint(base) + ) + self.assertEqual(pkey_ex, crypto.encodepoint(pkey_comp)) + + +if __name__ == "__main__": + unittest.main() diff --git a/tests/test_apps.monero.serializer.py b/tests/test_apps.monero.serializer.py new file mode 100644 index 000000000..def666c46 --- /dev/null +++ b/tests/test_apps.monero.serializer.py @@ -0,0 +1,362 @@ +from common import * +import utest + +from trezor import log, loop, utils +from apps.monero.xmr.serialize import xmrserialize as xms +from apps.monero.xmr.serialize.readwriter import MemoryReaderWriter +from apps.monero.xmr.serialize_messages.base import ECPoint +from apps.monero.xmr.serialize_messages.ct_keys import CtKey +from apps.monero.xmr.serialize_messages.tx_full import Transaction +from apps.monero.xmr.serialize_messages.tx_prefix import ( + TxinToKey, + TxinGen, + TxInV, + TxOut, + TxoutToKey, + TransactionPrefix, +) +from apps.monero.xmr.serialize_messages.tx_rsig_boro import BoroSig +from apps.monero.xmr.serialize_messages.tx_src_entry import OutputEntry + + +class XmrTstData(object): + """Simple tests data generator""" + + def __init__(self, *args, **kwargs): + super(XmrTstData, self).__init__() + self.ec_offset = 0 + + def reset(self): + self.ec_offset = 0 + + def generate_ec_key(self, use_offset=True): + """ + Returns test EC key, 32 element byte array + :param use_offset: + :return: + """ + offset = 0 + if use_offset: + offset = self.ec_offset + self.ec_offset += 1 + + return bytearray(range(offset, offset + 32)) + + def gen_transaction_prefix(self): + """ + Returns test transaction prefix + :return: + """ + vin = [ + TxinToKey( + amount=123, key_offsets=[1, 2, 3, 2 ** 76], k_image=bytearray(range(32)) + ), + TxinToKey( + amount=456, key_offsets=[9, 8, 7, 6], k_image=bytearray(range(32, 64)) + ), + TxinGen(height=99), + ] + + vout = [ + TxOut(amount=11, target=TxoutToKey(key=bytearray(range(32)))), + TxOut(amount=34, target=TxoutToKey(key=bytearray(range(64, 96)))), + ] + + msg = TransactionPrefix( + version=2, unlock_time=10, vin=vin, vout=vout, extra=list(range(31)) + ) + return msg + + def gen_borosig(self): + """ + Returns a BoroSig message + :return: + """ + ee = self.generate_ec_key() + s0 = [self.generate_ec_key() for _ in range(64)] + s1 = [self.generate_ec_key() for _ in range(64)] + msg = BoroSig(s0=s0, s1=s1, ee=ee) + return msg + + +class TestMoneroSerializer(unittest.TestCase): + def __init__(self, *args, **kwargs): + super(TestMoneroSerializer, self).__init__(*args, **kwargs) + self.tdata = XmrTstData() + + def setUp(self): + self.tdata.reset() + + async def test_async_varint(self): + """ + Var int + :return: + """ + # fmt: off + test_nums = [0, 1, 12, 44, 32, 63, 64, 127, 128, 255, 256, 1023, 1024, 8191, 8192, + 2**16, 2**16 - 1, 2**32, 2**32 - 1, 2**64, 2**64 - 1, 2**72 - 1, 2**112] + # fmt: on + + for test_num in test_nums: + writer = MemoryReaderWriter() + + await xms.dump_uvarint(writer, test_num) + test_deser = await xms.load_uvarint(MemoryReaderWriter(writer.get_buffer())) + + self.assertEqual(test_num, test_deser) + + async def test_async_ecpoint(self): + """ + Ec point + :return: + """ + ec_data = bytearray(range(32)) + writer = MemoryReaderWriter() + + await xms.dump_blob(writer, ec_data, ECPoint) + self.assertTrue(len(writer.get_buffer()), ECPoint.SIZE) + + test_deser = await xms.load_blob( + MemoryReaderWriter(writer.get_buffer()), ECPoint + ) + self.assertEqual(ec_data, test_deser) + + async def test_async_ecpoint_obj(self): + """ + EC point into + :return: + """ + ec_data = bytearray(list(range(32))) + ec_point = ECPoint() + ec_point.data = ec_data + writer = MemoryReaderWriter() + + await xms.dump_blob(writer, ec_point, ECPoint) + self.assertTrue(len(writer.get_buffer()), ECPoint.SIZE) + + ec_point2 = ECPoint() + test_deser = await xms.load_blob( + MemoryReaderWriter(writer.get_buffer()), ECPoint, elem=ec_point2 + ) + + self.assertEqual(ec_data, ec_point2.data) + self.assertEqual(ec_point, ec_point2) + + async def test_async_simple_msg(self): + """ + TxinGen + :return: + """ + msg = TxinGen(height=42) + + writer = MemoryReaderWriter() + ar1 = xms.Archive(writer, True) + await ar1.message(msg) + + ar2 = xms.Archive(MemoryReaderWriter(writer.get_buffer()), False) + test_deser = await ar2.message(None, msg_type=TxinGen) + self.assertEqual(msg.height, test_deser.height) + + async def test_async_simple_msg_into(self): + """ + TxinGen + :return: + """ + msg = TxinGen(height=42) + + writer = MemoryReaderWriter() + ar1 = xms.Archive(writer, True) + await ar1.message(msg) + + msg2 = TxinGen() + ar2 = xms.Archive(MemoryReaderWriter(writer.get_buffer()), False) + test_deser = await ar2.message(msg2, TxinGen) + self.assertEqual(msg.height, test_deser.height) + self.assertEqual(msg.height, msg2.height) + self.assertEqual(msg2, test_deser) + + async def test_async_tuple(self): + """ + Simple tuple type + :return: + """ + out_entry = [ + 123, + CtKey(dest=self.tdata.generate_ec_key(), mask=self.tdata.generate_ec_key()), + ] + writer = MemoryReaderWriter() + ar1 = xms.Archive(writer, True) + + await ar1.tuple(out_entry, OutputEntry) + ar2 = xms.Archive(MemoryReaderWriter(writer.get_buffer()), False) + test_deser = await ar2.tuple(None, OutputEntry) + + self.assertEqual(out_entry, test_deser) + + async def test_async_txin_to_key(self): + """ + TxinToKey + :return: + """ + msg = TxinToKey( + amount=123, key_offsets=[1, 2, 3, 2 ** 76], k_image=bytearray(range(32)) + ) + + writer = MemoryReaderWriter() + ar1 = xms.Archive(writer, True) + await ar1.message(msg) + + ar2 = xms.Archive(MemoryReaderWriter(writer.get_buffer()), False) + test_deser = await ar2.message(None, TxinToKey) + self.assertEqual(msg.amount, test_deser.amount) + self.assertEqual(msg, test_deser) + + async def test_async_txin_variant(self): + """ + TxInV + :return: + """ + msg1 = TxinToKey( + amount=123, key_offsets=[1, 2, 3, 2 ** 76], k_image=bytearray(range(32)) + ) + msg = TxInV() + msg.set_variant("txin_to_key", msg1) + + writer = MemoryReaderWriter() + ar1 = xms.Archive(writer, True) + await ar1.variant(msg) + + ar2 = xms.Archive(MemoryReaderWriter(writer.get_buffer()), False) + test_deser = await ar2.variant(None, TxInV, wrapped=True) + self.assertEqual(test_deser.__class__, TxInV) + self.assertEqual(msg, test_deser) + self.assertEqual(msg.variant_elem, test_deser.variant_elem) + self.assertEqual(msg.variant_elem_type, test_deser.variant_elem_type) + + async def test_async_tx_prefix(self): + """ + TransactionPrefix + :return: + """ + msg = self.tdata.gen_transaction_prefix() + + writer = MemoryReaderWriter() + ar1 = xms.Archive(writer, True) + await ar1.message(msg) + + ar2 = xms.Archive(MemoryReaderWriter(writer.get_buffer()), False) + test_deser = await ar2.message(None, TransactionPrefix) + self.assertEqual(test_deser.__class__, TransactionPrefix) + self.assertEqual(test_deser.version, msg.version) + self.assertEqual(test_deser.unlock_time, msg.unlock_time) + self.assertEqual(len(test_deser.vin), len(msg.vin)) + self.assertEqual(len(test_deser.vout), len(msg.vout)) + self.assertEqual(len(test_deser.extra), len(msg.extra)) + self.assertEqual(test_deser.extra, msg.extra) + self.assertListEqual(test_deser.vin, msg.vin) + self.assertListEqual(test_deser.vout, msg.vout) + self.assertEqual(test_deser, msg) + + async def test_async_boro_sig(self): + """ + BoroSig + :return: + """ + msg = self.tdata.gen_borosig() + + writer = MemoryReaderWriter() + ar1 = xms.Archive(writer, True) + await ar1.message(msg) + + ar2 = xms.Archive(MemoryReaderWriter(writer.get_buffer()), False) + test_deser = await ar2.message(None, BoroSig) + self.assertEqual(msg, test_deser) + + async def test_async_transaction_prefix(self): + """ + + :return: + """ + tsx_hex = b"013D01FF010680A0DB5002A9243CF5459DE5114E6A1AC08F9180C9F40A3CF9880778878104E9FEA578B6A780A8D6B90702AFEBACD6A4456AF979CCBE08D37A9A670BA421B5E39AB2968DF4219DD086018B8088ACA3CF020251748BADE758D1DD65A867FA3CEDD4878485BBC8307F905E3090A030290672798090CAD2C60E020C823CCBD4AB1A1F9240844400D72CDC8B498B3181B182B0B54A405B695406A680E08D84DDCB01022A9A926097548A723863923FBFEA4913B1134B2E4AE54946268DDA99564B5D8280C0CAF384A30202A868709A8BB91734AD3EBAC127638E018139E375C1987E01CCC2A8B04427727E2101F74BF5FB3DA064F48090D9B6705E598925313875B2B4F2A50EB0517264B0721C" + tsx_bin = unhexlify(tsx_hex) + + reader = MemoryReaderWriter(bytearray(tsx_bin)) + ar1 = xms.Archive(reader, False) + + test_deser = await ar1.message(None, TransactionPrefix) + self.assertIsNotNone(test_deser) + self.assertEqual(len(reader.get_buffer()), 0) # no data left to read + self.assertEqual(len(test_deser.extra), 33) + self.assertEqual(test_deser.extra[0], 1) + self.assertEqual(test_deser.extra[32], 28) + self.assertEqual(test_deser.unlock_time, 61) + self.assertEqual(test_deser.version, 1) + self.assertEqual(len(test_deser.vin), 1) + self.assertEqual(len(test_deser.vout), 6) + self.assertEqual(test_deser.vin[0].height, 1) + self.assertEqual(test_deser.vout[0].amount, 169267200) + self.assertEqual(len(test_deser.vout[0].target.key), 32) + self.assertEqual(test_deser.vout[1].amount, 2000000000) + self.assertEqual(len(test_deser.vout[1].target.key), 32) + self.assertEqual(test_deser.vout[5].amount, 10000000000000) + self.assertEqual(len(test_deser.vout[5].target.key), 32) + + async def test_async_transaction(self): + """ + + :return: + """ + tsx_hex = b"" + tsx_bin = unhexlify(tsx_hex) + reader = MemoryReaderWriter(bytearray(tsx_bin)) + ar = xms.Archive(reader, False) + + msg = Transaction() + await ar.message(msg) + self.assertIsNotNone(msg) + self.assertEqual(len(reader.get_buffer()), 0) # no data left to read + self.assertEqual(len(msg.extra), 44) + self.assertEqual(msg.extra[0], 2) + self.assertEqual(msg.extra[43], 199) + self.assertEqual(msg.version, 2) + self.assertEqual(msg.unlock_time, 0) + self.assertEqual(len(msg.vin), 2) + self.assertEqual(len(msg.vout), 2) + self.assertEqual(msg.vin[0].amount, 90000000000) + self.assertEqual(msg.vin[1].amount, 7000000000000) + self.assertEqual(msg.vin[0].key_offsets, [0, 45, 68]) + self.assertEqual(msg.vin[1].key_offsets, [5, 79, 38]) + self.assertEqual(len(msg.vin[0].k_image), 32) + self.assertEqual(msg.vout[0].amount, 0) + self.assertEqual(msg.vout[1].amount, 0) + self.assertIsNotNone(msg.rct_signatures) + + self.assertEqual(msg.rct_signatures.type, 2) + self.assertEqual(msg.rct_signatures.txnFee, 26000000000) + self.assertEqual(len(msg.rct_signatures.pseudoOuts), 2) + self.assertEqual(msg.rct_signatures.pseudoOuts[0][0], 161) + self.assertEqual(msg.rct_signatures.pseudoOuts[1][0], 229) + self.assertEqual(len(msg.rct_signatures.outPk), 2) + self.assertEqual(msg.rct_signatures.outPk[0].mask[0], 0x8f) + self.assertEqual(msg.rct_signatures.outPk[1].mask[0], 0xfd) + self.assertEqual(len(msg.rct_signatures.ecdhInfo), 2) + self.assertEqual(msg.rct_signatures.ecdhInfo[0].mask[0], 0xf6) + self.assertEqual(msg.rct_signatures.ecdhInfo[1].mask[0], 0x85) + + self.assertEqual(msg.rct_signatures.p.MGs[0].cc[0], 0x17) + self.assertEqual(len(msg.rct_signatures.p.MGs[0].ss), 3) + self.assertEqual(len(msg.rct_signatures.p.MGs[0].ss[0]), 2) + self.assertEqual(msg.rct_signatures.p.MGs[0].ss[0][0][0], 243) + self.assertEqual(msg.rct_signatures.p.MGs[0].ss[0][1][0], 2) + self.assertEqual(msg.rct_signatures.p.MGs[0].ss[1][0][0], 114) + self.assertEqual(msg.rct_signatures.p.MGs[0].ss[1][1][0], 109) + self.assertEqual(msg.rct_signatures.p.MGs[0].ss[2][0][0], 218) + self.assertEqual(msg.rct_signatures.p.MGs[0].ss[2][1][0], 131) + self.assertEqual(msg.rct_signatures.p.MGs[1].cc[0], 0x12) + self.assertEqual(msg.rct_signatures.p.rangeSigs[1].Ci[0][0], 0xeb) + self.assertEqual(msg.rct_signatures.p.rangeSigs[1].Ci[63][0], 0xfc) + self.assertEqual(msg.rct_signatures.p.rangeSigs[1].asig.ee[0], 0xe7) + + +if __name__ == "__main__": + unittest.main() diff --git a/tests/unittest.py b/tests/unittest.py index dad094971..0c52a08da 100644 --- a/tests/unittest.py +++ b/tests/unittest.py @@ -1,4 +1,5 @@ from trezor.utils import ensure +from utest import assert_async class SkipTest(Exception): @@ -125,6 +126,15 @@ def assertRaises(self, exc, func=None, *args, **kwargs): return raise + def assertListEqual(self, x, y, msg=''): + if len(x) != len(y): + if not msg: + msg = "List lengths not equal" + ensure(False, msg) + + for i in range(len(x)): + self.assertEqual(x[i], y[i], msg) + def skip(msg): def _decor(fun): @@ -178,12 +188,16 @@ def run_class(c, test_result): print('class', c.__qualname__) for name in dir(o): if name.startswith("test"): + is_async = name.startswith("test_async") print(' ', name, end=' ...') m = getattr(o, name) try: set_up() test_result.testsRun += 1 - m() + if is_async: + assert_async(m(), [(None, StopIteration()), ]) + else: + m() tear_down() print(" ok") except SkipTest as e: diff --git a/vendor/trezor-common b/vendor/trezor-common index 3a7bdf684..efed61b91 160000 --- a/vendor/trezor-common +++ b/vendor/trezor-common @@ -1 +1 @@ -Subproject commit 3a7bdf684a64d3e1eb98a7f6eaa73d8f53b7f51a +Subproject commit efed61b91c3056f040505e8151b2ea45638b2bba