Checkpoint the party/runtime stack before share-program and malicious-mode work.
Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
parent
695f8e84f7
commit
0d22946a0e
1835 changed files with 170291 additions and 2849 deletions
|
|
@ -18,6 +18,7 @@
|
|||
#include "simde/simde/x86/avx2.h"
|
||||
#include "portable-snippets/exact-int/exact-int.h"
|
||||
|
||||
#include "dpf/prg_count.hpp"
|
||||
#include "dpf/utils.hpp"
|
||||
|
||||
namespace dpf
|
||||
|
|
@ -44,19 +45,28 @@ struct aes final
|
|||
{
|
||||
using block_type = simde__m128i;
|
||||
|
||||
static constexpr primitive counted_as =
|
||||
AesKey::rounds == 14 ? primitive::aes256 : primitive::aes128;
|
||||
|
||||
HEDLEY_NO_THROW
|
||||
HEDLEY_ALWAYS_INLINE
|
||||
static void require_block_aligned(const void * p) noexcept
|
||||
{
|
||||
(void)p;
|
||||
assert(p == nullptr
|
||||
|| reinterpret_cast<std::uintptr_t>(p) % alignof(block_type) == 0);
|
||||
}
|
||||
|
||||
/// @brief One AES block in Matyas–Meyer–Oseas mode.
|
||||
/// @param seed the PRG seed
|
||||
/// @param pos the block counter mixed into the first round key
|
||||
/// @return the 128-bit block
|
||||
/// \complexity One block: `key.rounds - 1` `aesenc` calls plus one `aesenclast`. `rounds` is 10 for `aes128` and 14 for `aes256`.
|
||||
HEDLEY_NO_THROW
|
||||
HEDLEY_ALWAYS_INLINE
|
||||
HEDLEY_PURE
|
||||
static block_type eval(block_type seed, psnip_uint32_t pos) noexcept
|
||||
{
|
||||
note_eval(1, counted_as);
|
||||
block_type rd_key0 = simde_mm_xor_si128(key.rd_key[0],
|
||||
simde_mm_set_epi64x(0, pos));
|
||||
block_type output = simde_mm_xor_si128(seed, rd_key0);
|
||||
|
|
@ -73,9 +83,9 @@ struct aes final
|
|||
|
||||
HEDLEY_NO_THROW
|
||||
HEDLEY_ALWAYS_INLINE
|
||||
HEDLEY_PURE
|
||||
static auto eval01(block_type seed) noexcept
|
||||
{
|
||||
note_eval(2, counted_as);
|
||||
block_type rd_key00 = key.rd_key[0];
|
||||
block_type rd_key01 = simde_mm_xor_si128(rd_key00,
|
||||
simde_mm_set_epi64x(0, 1));
|
||||
|
|
@ -99,6 +109,99 @@ HEDLEY_PRAGMA(GCC diagnostic ignored "-Wignored-attributes")
|
|||
HEDLEY_PRAGMA(GCC diagnostic pop)
|
||||
}
|
||||
|
||||
/// @brief Four independent MMO blocks, round-major so `aesenc` throughput
|
||||
/// covers the latency of a single `eval`.
|
||||
/// @param seeds four PRG seeds
|
||||
/// @param pos lane index for each seed (`0` or `1` for a tree child)
|
||||
/// @param out four blocks, same order as `seeds`
|
||||
HEDLEY_NO_THROW
|
||||
HEDLEY_ALWAYS_INLINE
|
||||
static void eval_indep4(const block_type seeds[4], const psnip_uint32_t pos[4],
|
||||
block_type out[4]) noexcept
|
||||
{
|
||||
note_eval(4, counted_as);
|
||||
block_type o0, o1, o2, o3;
|
||||
{
|
||||
const block_type k0 = key.rd_key[0];
|
||||
o0 = simde_mm_xor_si128(seeds[0],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[0])));
|
||||
o1 = simde_mm_xor_si128(seeds[1],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[1])));
|
||||
o2 = simde_mm_xor_si128(seeds[2],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[2])));
|
||||
o3 = simde_mm_xor_si128(seeds[3],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[3])));
|
||||
}
|
||||
HEDLEY_PRAGMA(GCC unroll(14))
|
||||
for (std::size_t j = 1; j < key.rounds; ++j)
|
||||
{
|
||||
const block_type rk = key.rd_key[j];
|
||||
o0 = simde_mm_aesenc_si128(o0, rk);
|
||||
o1 = simde_mm_aesenc_si128(o1, rk);
|
||||
o2 = simde_mm_aesenc_si128(o2, rk);
|
||||
o3 = simde_mm_aesenc_si128(o3, rk);
|
||||
}
|
||||
const block_type last = key.rd_key[key.rounds];
|
||||
o0 = simde_mm_xor_si128(simde_mm_aesenclast_si128(o0, last), seeds[0]);
|
||||
o1 = simde_mm_xor_si128(simde_mm_aesenclast_si128(o1, last), seeds[1]);
|
||||
o2 = simde_mm_xor_si128(simde_mm_aesenclast_si128(o2, last), seeds[2]);
|
||||
o3 = simde_mm_xor_si128(simde_mm_aesenclast_si128(o3, last), seeds[3]);
|
||||
out[0] = o0;
|
||||
out[1] = o1;
|
||||
out[2] = o2;
|
||||
out[3] = o3;
|
||||
}
|
||||
|
||||
/// @brief Eight independent MMO blocks. Zen's AES unit retires two
|
||||
/// `aesenc`s per cycle at four-cycle latency, so eight in flight
|
||||
/// fills it; four does not.
|
||||
HEDLEY_NO_THROW
|
||||
HEDLEY_ALWAYS_INLINE
|
||||
static void eval_indep8(const block_type seeds[8], const psnip_uint32_t pos[8],
|
||||
block_type out[8]) noexcept
|
||||
{
|
||||
note_eval(8, counted_as);
|
||||
const block_type k0 = key.rd_key[0];
|
||||
block_type o0 = simde_mm_xor_si128(seeds[0],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[0])));
|
||||
block_type o1 = simde_mm_xor_si128(seeds[1],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[1])));
|
||||
block_type o2 = simde_mm_xor_si128(seeds[2],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[2])));
|
||||
block_type o3 = simde_mm_xor_si128(seeds[3],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[3])));
|
||||
block_type o4 = simde_mm_xor_si128(seeds[4],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[4])));
|
||||
block_type o5 = simde_mm_xor_si128(seeds[5],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[5])));
|
||||
block_type o6 = simde_mm_xor_si128(seeds[6],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[6])));
|
||||
block_type o7 = simde_mm_xor_si128(seeds[7],
|
||||
simde_mm_xor_si128(k0, simde_mm_set_epi64x(0, pos[7])));
|
||||
HEDLEY_PRAGMA(GCC unroll(14))
|
||||
for (std::size_t j = 1; j < key.rounds; ++j)
|
||||
{
|
||||
const block_type rk = key.rd_key[j];
|
||||
o0 = simde_mm_aesenc_si128(o0, rk);
|
||||
o1 = simde_mm_aesenc_si128(o1, rk);
|
||||
o2 = simde_mm_aesenc_si128(o2, rk);
|
||||
o3 = simde_mm_aesenc_si128(o3, rk);
|
||||
o4 = simde_mm_aesenc_si128(o4, rk);
|
||||
o5 = simde_mm_aesenc_si128(o5, rk);
|
||||
o6 = simde_mm_aesenc_si128(o6, rk);
|
||||
o7 = simde_mm_aesenc_si128(o7, rk);
|
||||
}
|
||||
const block_type last = key.rd_key[key.rounds];
|
||||
out[0] = simde_mm_xor_si128(simde_mm_aesenclast_si128(o0, last), seeds[0]);
|
||||
out[1] = simde_mm_xor_si128(simde_mm_aesenclast_si128(o1, last), seeds[1]);
|
||||
out[2] = simde_mm_xor_si128(simde_mm_aesenclast_si128(o2, last), seeds[2]);
|
||||
out[3] = simde_mm_xor_si128(simde_mm_aesenclast_si128(o3, last), seeds[3]);
|
||||
out[4] = simde_mm_xor_si128(simde_mm_aesenclast_si128(o4, last), seeds[4]);
|
||||
out[5] = simde_mm_xor_si128(simde_mm_aesenclast_si128(o5, last), seeds[5]);
|
||||
out[6] = simde_mm_xor_si128(simde_mm_aesenclast_si128(o6, last), seeds[6]);
|
||||
out[7] = simde_mm_xor_si128(simde_mm_aesenclast_si128(o7, last), seeds[7]);
|
||||
}
|
||||
|
||||
/// @brief Round-major multi-block MMO. Positions use the same lane as
|
||||
/// `eval` / `eval01` (`set_epi64x(0, pos)`). The first AddRoundKey
|
||||
/// includes `rd_key[0]` so this matches the one-block `eval` for any
|
||||
|
|
@ -142,6 +245,7 @@ HEDLEY_PRAGMA(GCC diagnostic pop)
|
|||
return;
|
||||
}
|
||||
|
||||
note_eval(count, counted_as);
|
||||
auto whitened = simde_mm_xor_si128(seed, key.rd_key[0]);
|
||||
DPF_UNROLL_LOOP
|
||||
for (psnip_uint32_t i = 0; i < count; ++i)
|
||||
|
|
@ -180,6 +284,7 @@ HEDLEY_PRAGMA(GCC diagnostic pop)
|
|||
block_type * HEDLEY_RESTRICT left,
|
||||
block_type * HEDLEY_RESTRICT right) noexcept
|
||||
{
|
||||
note_eval(8, counted_as);
|
||||
require_block_aligned(seeds);
|
||||
require_block_aligned(left);
|
||||
require_block_aligned(right);
|
||||
|
|
@ -215,6 +320,7 @@ HEDLEY_PRAGMA(GCC diagnostic pop)
|
|||
static void eval_x4(const block_type * HEDLEY_RESTRICT seeds,
|
||||
block_type * HEDLEY_RESTRICT output, psnip_uint32_t pos) noexcept
|
||||
{
|
||||
note_eval(4, counted_as);
|
||||
require_block_aligned(seeds);
|
||||
require_block_aligned(output);
|
||||
const block_type * HEDLEY_RESTRICT s =
|
||||
|
|
@ -249,6 +355,7 @@ HEDLEY_PRAGMA(GCC diagnostic pop)
|
|||
static void eval_x8(const block_type * HEDLEY_RESTRICT seeds,
|
||||
block_type * HEDLEY_RESTRICT output, psnip_uint32_t pos) noexcept
|
||||
{
|
||||
note_eval(8, counted_as);
|
||||
require_block_aligned(seeds);
|
||||
require_block_aligned(output);
|
||||
const block_type * HEDLEY_RESTRICT s =
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue