@@ -131,14 +131,13 @@ static void TestAES256CBC(const std::string &hexkey, const std::string &hexiv, b
131131 }
132132}
133133
134- static void TestChaCha20 (const std::string &hex_message, const std::string &hexkey, uint64_t nonce, uint64_t seek, const std::string& hexout)
134+ static void TestChaCha20 (const std::string &hex_message, const std::string &hexkey, ChaCha20::Nonce96 nonce, uint32_t seek, const std::string& hexout)
135135{
136136 std::vector<unsigned char > key = ParseHex (hexkey);
137137 assert (key.size () == 32 );
138138 std::vector<unsigned char > m = ParseHex (hex_message);
139139 ChaCha20 rng (key.data ());
140- rng.SetIV (nonce);
141- rng.Seek64 (seek);
140+ rng.Seek64 (nonce, seek);
142141 std::vector<unsigned char > outres;
143142 outres.resize (hexout.size () / 2 );
144143 assert (hex_message.empty () || m.size () * 2 == hexout.size ());
@@ -152,8 +151,7 @@ static void TestChaCha20(const std::string &hex_message, const std::string &hexk
152151 BOOST_CHECK_EQUAL (hexout, HexStr (outres));
153152 if (!hex_message.empty ()) {
154153 // Manually XOR with the keystream and compare the output
155- rng.SetIV (nonce);
156- rng.Seek64 (seek);
154+ rng.Seek64 (nonce, seek);
157155 std::vector<unsigned char > only_keystream (outres.size ());
158156 rng.Keystream (only_keystream.data (), only_keystream.size ());
159157 for (size_t i = 0 ; i != m.size (); i++) {
@@ -169,7 +167,7 @@ static void TestChaCha20(const std::string &hex_message, const std::string &hexk
169167 lens[1 ] = InsecureRandRange (hexout.size () / 2U + 1U - lens[0 ]);
170168 lens[2 ] = hexout.size () / 2U - lens[0 ] - lens[1 ];
171169
172- rng.Seek64 (seek);
170+ rng.Seek64 (nonce, seek);
173171 outres.assign (hexout.size () / 2U , 0 );
174172 size_t pos = 0 ;
175173 for (int j = 0 ; j < 3 ; ++j) {
@@ -485,43 +483,43 @@ BOOST_AUTO_TEST_CASE(chacha20_testvector)
485483 // RFC 7539/8439 A.1 Test Vector #1:
486484 TestChaCha20 (" " ,
487485 " 0000000000000000000000000000000000000000000000000000000000000000" ,
488- 0 , 0 ,
486+ { 0 , 0 } , 0 ,
489487 " 76b8e0ada0f13d90405d6ae55386bd28bdd219b8a08ded1aa836efcc8b770dc7"
490488 " da41597c5157488d7724e03fb8d84a376a43b8f41518a11cc387b669b2ee6586" );
491489
492490 // RFC 7539/8439 A.1 Test Vector #2:
493491 TestChaCha20 (" " ,
494492 " 0000000000000000000000000000000000000000000000000000000000000000" ,
495- 0 , 1 ,
493+ { 0 , 0 } , 1 ,
496494 " 9f07e7be5551387a98ba977c732d080dcb0f29a048e3656912c6533e32ee7aed"
497495 " 29b721769ce64e43d57133b074d839d531ed1f28510afb45ace10a1f4b794d6f" );
498496
499497 // RFC 7539/8439 A.1 Test Vector #3:
500498 TestChaCha20 (" " ,
501499 " 0000000000000000000000000000000000000000000000000000000000000001" ,
502- 0 , 1 ,
500+ { 0 , 0 } , 1 ,
503501 " 3aeb5224ecf849929b9d828db1ced4dd832025e8018b8160b82284f3c949aa5a"
504502 " 8eca00bbb4a73bdad192b5c42f73f2fd4e273644c8b36125a64addeb006c13a0" );
505503
506504 // RFC 7539/8439 A.1 Test Vector #4:
507505 TestChaCha20 (" " ,
508506 " 00ff000000000000000000000000000000000000000000000000000000000000" ,
509- 0 , 2 ,
507+ { 0 , 0 } , 2 ,
510508 " 72d54dfbf12ec44b362692df94137f328fea8da73990265ec1bbbea1ae9af0ca"
511509 " 13b25aa26cb4a648cb9b9d1be65b2c0924a66c54d545ec1b7374f4872e99f096" );
512510
513511 // RFC 7539/8439 A.1 Test Vector #5:
514512 TestChaCha20 (" " ,
515513 " 0000000000000000000000000000000000000000000000000000000000000000" ,
516- 0x200000000000000 , 0 ,
514+ { 0 , 0x200000000000000 } , 0 ,
517515 " c2c64d378cd536374ae204b9ef933fcd1a8b2288b3dfa49672ab765b54ee27c7"
518516 " 8a970e0e955c14f3a88e741b97c286f75f8fc299e8148362fa198a39531bed6d" );
519517
520518 // RFC 7539/8439 A.2 Test Vector #1:
521519 TestChaCha20 (" 0000000000000000000000000000000000000000000000000000000000000000"
522520 " 0000000000000000000000000000000000000000000000000000000000000000" ,
523521 " 0000000000000000000000000000000000000000000000000000000000000000" ,
524- 0 , 0 ,
522+ { 0 , 0 } , 0 ,
525523 " 76b8e0ada0f13d90405d6ae55386bd28bdd219b8a08ded1aa836efcc8b770dc7"
526524 " da41597c5157488d7724e03fb8d84a376a43b8f41518a11cc387b669b2ee6586" );
527525
@@ -539,7 +537,7 @@ BOOST_AUTO_TEST_CASE(chacha20_testvector)
539537 " 74696f6e73206d61646520617420616e792074696d65206f7220706c6163652c"
540538 " 207768696368206172652061646472657373656420746f" ,
541539 " 0000000000000000000000000000000000000000000000000000000000000001" ,
542- 0x200000000000000 , 1 ,
540+ { 0 , 0x200000000000000 } , 1 ,
543541 " a3fbf07df3fa2fde4f376ca23e82737041605d9f4f4f57bd8cff2c1d4b7955ec"
544542 " 2a97948bd3722915c8f3d337f7d370050e9e96d647b7c39f56e031ca5eb6250d"
545543 " 4042e02785ececfa4b4bb5e8ead0440e20b6e8db09d881a7c6132f420e527950"
@@ -559,7 +557,7 @@ BOOST_AUTO_TEST_CASE(chacha20_testvector)
559557 " 6162653a0a416c6c206d696d737920776572652074686520626f726f676f7665"
560558 " 732c0a416e6420746865206d6f6d65207261746873206f757467726162652e" ,
561559 " 1c9240a5eb55d38af333888604f6b5f0473917c1402b80099dca5cbc207075c0" ,
562- 0x200000000000000 , 42 ,
560+ { 0 , 0x200000000000000 } , 42 ,
563561 " 62e6347f95ed87a45ffae7426f27a1df5fb69110044c0d73118effa95b01e5cf"
564562 " 166d3df2d721caf9b21e5fb14c616871fd84c54f9d65b283196c7fe4f60553eb"
565563 " f39c6402c42234e32a356b3e764312a61a5532055716ead6962568f87d3f3f77"
@@ -569,14 +567,14 @@ BOOST_AUTO_TEST_CASE(chacha20_testvector)
569567 TestChaCha20 (" 4c616469657320616e642047656e746c656d656e206f662074686520636c617373206f66202739393a204966204920636f756"
570568 " c64206f6666657220796f75206f6e6c79206f6e652074697020666f7220746865206675747572652c2073756e73637265656e"
571569 " 20776f756c642062652069742e" ,
572- " 000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f" , 0x4a000000UL , 1 ,
570+ " 000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f" , { 0 , 0x4a000000UL } , 1 ,
573571 " 6e2e359a2568f98041ba0728dd0d6981e97e7aec1d4360c20a27afccfd9fae0bf91b65c5524733ab8f593dabcd62b3571639d"
574572 " 624e65152ab8f530c359f0861d807ca0dbf500d6a6156a38e088a22b65e52bc514d16ccf806818ce91ab77937365af90bbf74"
575573 " a35be6b40b8eedf2785e42874d"
576574 );
577575
578576 // test keystream output
579- TestChaCha20 (" " , " 000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f" , 0x4a000000UL , 1 ,
577+ TestChaCha20 (" " , " 000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f" , { 0 , 0x4a000000UL } , 1 ,
580578 " 224f51f3401bd9e12fde276fb8631ded8c131f823d2c06e27e4fcaec9ef3cf788a3b0aa372600a92b57974cded2b9334794cb"
581579 " a40c63e34cdea212c4cf07d41b769a6749f3f630f4122cafe28ec4dc47e26d4346d70b98c73f3e9c53ac40c5945398b6eda1a"
582580 " 832c89c167eacd901d7e2bf363" );
@@ -730,8 +728,7 @@ static void TestChaCha20Poly1305AEAD(bool must_succeed, unsigned int expected_aa
730728 BOOST_CHECK (memcmp (ciphertext_buf.data (), expected_ciphertext_and_mac.data (), ciphertext_buf.size ()) == 0 );
731729
732730 // manually construct the AAD keystream
733- cmp_ctx.SetIV (seqnr_aad);
734- cmp_ctx.Seek64 (0 );
731+ cmp_ctx.Seek64 ({0 , seqnr_aad}, 0 );
735732 cmp_ctx.Keystream (cmp_ctx_buffer.data (), 64 );
736733 BOOST_CHECK (memcmp (expected_aad_keystream.data (), cmp_ctx_buffer.data (), expected_aad_keystream.size ()) == 0 );
737734 // crypt the 3 length bytes and compare the length
@@ -758,8 +755,7 @@ static void TestChaCha20Poly1305AEAD(bool must_succeed, unsigned int expected_aa
758755 BOOST_CHECK (memcmp (ciphertext_buf.data (), expected_ciphertext_and_mac_sequence999.data (), expected_ciphertext_and_mac_sequence999.size ()) == 0 );
759756 }
760757 // set nonce and block counter, output the keystream
761- cmp_ctx.SetIV (seqnr_aad);
762- cmp_ctx.Seek64 (0 );
758+ cmp_ctx.Seek64 ({0 , seqnr_aad}, 0 );
763759 cmp_ctx.Keystream (cmp_ctx_buffer.data (), 64 );
764760
765761 // crypt the 3 length bytes and compare the length
0 commit comments