xref: /openbsd-src/lib/libcrypto/sm3/sm3.c (revision c18e04ad920918958912f30a26b4d8cbb7002e4d)
1*c18e04adStb /*	$OpenBSD: sm3.c,v 1.18 2024/12/12 09:54:44 tb Exp $	*/
243f50545Stb /*
343f50545Stb  * Copyright (c) 2018, Ribose Inc
443f50545Stb  *
543f50545Stb  * Permission to use, copy, modify, and/or distribute this software for any
643f50545Stb  * purpose with or without fee is hereby granted, provided that the above
743f50545Stb  * copyright notice and this permission notice appear in all copies.
843f50545Stb  *
943f50545Stb  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
1043f50545Stb  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
1143f50545Stb  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
1243f50545Stb  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
1343f50545Stb  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
1443f50545Stb  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1543f50545Stb  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
1643f50545Stb  */
1743f50545Stb 
18472d7f5aSjsing #include <string.h>
19472d7f5aSjsing 
20472d7f5aSjsing #include <openssl/opensslconf.h>
21472d7f5aSjsing 
227d8388ebSjsing #include <openssl/sm3.h>
237d8388ebSjsing 
24acba64a9Sjsing #include "crypto_internal.h"
25acba64a9Sjsing 
26a1643a46Sjsing /* Ensure that SM3_WORD and uint32_t are equivalent size. */
27a1643a46Sjsing CTASSERT(sizeof(SM3_WORD) == sizeof(uint32_t));
28a1643a46Sjsing 
297d8388ebSjsing #ifndef OPENSSL_NO_SM3
307d8388ebSjsing 
31acba64a9Sjsing #define P0(X) (X ^ crypto_rol_u32(X, 9) ^ crypto_rol_u32(X, 17))
32acba64a9Sjsing #define P1(X) (X ^ crypto_rol_u32(X, 15) ^ crypto_rol_u32(X, 23))
33472d7f5aSjsing 
34472d7f5aSjsing #define FF0(X, Y, Z) (X ^ Y ^ Z)
35472d7f5aSjsing #define GG0(X, Y, Z) (X ^ Y ^ Z)
36472d7f5aSjsing 
37472d7f5aSjsing #define FF1(X, Y, Z) ((X & Y) | ((X | Y) & Z))
38472d7f5aSjsing #define GG1(X, Y, Z) ((Z ^ (X & (Y ^ Z))))
39472d7f5aSjsing 
40472d7f5aSjsing #define EXPAND(W0, W7, W13, W3, W10) \
41acba64a9Sjsing 	(P1(W0 ^ W7 ^ crypto_rol_u32(W13, 15)) ^ crypto_rol_u32(W3, 7) ^ W10)
42472d7f5aSjsing 
43472d7f5aSjsing #define ROUND(A, B, C, D, E, F, G, H, TJ, Wi, Wj, FF, GG)	do {	\
44acba64a9Sjsing 	const SM3_WORD A12 = crypto_rol_u32(A, 12);				\
45472d7f5aSjsing 	const SM3_WORD A12_SM = A12 + E + TJ;				\
46acba64a9Sjsing 	const SM3_WORD SS1 = crypto_rol_u32(A12_SM, 7);				\
47472d7f5aSjsing 	const SM3_WORD TT1 = FF(A, B, C) + D + (SS1 ^ A12) + (Wj);	\
48472d7f5aSjsing 	const SM3_WORD TT2 = GG(E, F, G) + H + SS1 + Wi;		\
49acba64a9Sjsing 	B = crypto_rol_u32(B, 9);						\
50472d7f5aSjsing 	D = TT1;							\
51acba64a9Sjsing 	F = crypto_rol_u32(F, 19);						\
52472d7f5aSjsing 	H = P0(TT2);							\
53472d7f5aSjsing } while(0)
54472d7f5aSjsing 
55472d7f5aSjsing #define R1(A, B, C, D, E, F, G, H, TJ, Wi, Wj) \
56472d7f5aSjsing 	ROUND(A, B, C, D, E, F, G, H, TJ, Wi, Wj, FF0, GG0)
57472d7f5aSjsing 
58472d7f5aSjsing #define R2(A, B, C, D, E, F, G, H, TJ, Wi, Wj) \
59472d7f5aSjsing 	ROUND(A, B, C, D, E, F, G, H, TJ, Wi, Wj, FF1, GG1)
60472d7f5aSjsing 
619bcde62cSjsing static void
629bcde62cSjsing sm3_block_data_order(SM3_CTX *ctx, const void *_in, size_t num)
6343f50545Stb {
64a1643a46Sjsing 	const uint8_t *in = _in;
65a1643a46Sjsing 	const SM3_WORD *in32;
6643f50545Stb 	SM3_WORD A, B, C, D, E, F, G, H;
6743f50545Stb 	SM3_WORD W00, W01, W02, W03, W04, W05, W06, W07;
6843f50545Stb 	SM3_WORD W08, W09, W10, W11, W12, W13, W14, W15;
6943f50545Stb 
7043f50545Stb 	while (num-- != 0) {
7143f50545Stb 		A = ctx->A;
7243f50545Stb 		B = ctx->B;
7343f50545Stb 		C = ctx->C;
7443f50545Stb 		D = ctx->D;
7543f50545Stb 		E = ctx->E;
7643f50545Stb 		F = ctx->F;
7743f50545Stb 		G = ctx->G;
7843f50545Stb 		H = ctx->H;
7943f50545Stb 
8043f50545Stb 		/*
8143f50545Stb 		 * We have to load all message bytes immediately since SM3 reads
8243f50545Stb 		 * them slightly out of order.
8343f50545Stb 		 */
84a1643a46Sjsing 		if ((uintptr_t)in % 4 == 0) {
85a1643a46Sjsing 			/* Input is 32 bit aligned. */
86a1643a46Sjsing 			in32 = (const SM3_WORD *)in;
87a1643a46Sjsing 			W00 = be32toh(in32[0]);
88a1643a46Sjsing 			W01 = be32toh(in32[1]);
89a1643a46Sjsing 			W02 = be32toh(in32[2]);
90a1643a46Sjsing 			W03 = be32toh(in32[3]);
91a1643a46Sjsing 			W04 = be32toh(in32[4]);
92a1643a46Sjsing 			W05 = be32toh(in32[5]);
93a1643a46Sjsing 			W06 = be32toh(in32[6]);
94a1643a46Sjsing 			W07 = be32toh(in32[7]);
95a1643a46Sjsing 			W08 = be32toh(in32[8]);
96a1643a46Sjsing 			W09 = be32toh(in32[9]);
97a1643a46Sjsing 			W10 = be32toh(in32[10]);
98a1643a46Sjsing 			W11 = be32toh(in32[11]);
99a1643a46Sjsing 			W12 = be32toh(in32[12]);
100a1643a46Sjsing 			W13 = be32toh(in32[13]);
101a1643a46Sjsing 			W14 = be32toh(in32[14]);
102a1643a46Sjsing 			W15 = be32toh(in32[15]);
103a1643a46Sjsing 		} else {
104a1643a46Sjsing 			/* Input is not 32 bit aligned. */
105a1643a46Sjsing 			W00 = crypto_load_be32toh(&in[0 * 4]);
106a1643a46Sjsing 			W01 = crypto_load_be32toh(&in[1 * 4]);
107a1643a46Sjsing 			W02 = crypto_load_be32toh(&in[2 * 4]);
108a1643a46Sjsing 			W03 = crypto_load_be32toh(&in[3 * 4]);
109a1643a46Sjsing 			W04 = crypto_load_be32toh(&in[4 * 4]);
110a1643a46Sjsing 			W05 = crypto_load_be32toh(&in[5 * 4]);
111a1643a46Sjsing 			W06 = crypto_load_be32toh(&in[6 * 4]);
112a1643a46Sjsing 			W07 = crypto_load_be32toh(&in[7 * 4]);
113a1643a46Sjsing 			W08 = crypto_load_be32toh(&in[8 * 4]);
114a1643a46Sjsing 			W09 = crypto_load_be32toh(&in[9 * 4]);
115a1643a46Sjsing 			W10 = crypto_load_be32toh(&in[10 * 4]);
116a1643a46Sjsing 			W11 = crypto_load_be32toh(&in[11 * 4]);
117a1643a46Sjsing 			W12 = crypto_load_be32toh(&in[12 * 4]);
118a1643a46Sjsing 			W13 = crypto_load_be32toh(&in[13 * 4]);
119a1643a46Sjsing 			W14 = crypto_load_be32toh(&in[14 * 4]);
120a1643a46Sjsing 			W15 = crypto_load_be32toh(&in[15 * 4]);
121a1643a46Sjsing 		}
122a1643a46Sjsing 		in += SM3_CBLOCK;
12343f50545Stb 
12443f50545Stb 		R1(A, B, C, D, E, F, G, H, 0x79cc4519, W00, W00 ^ W04);
12543f50545Stb 		W00 = EXPAND(W00, W07, W13, W03, W10);
12643f50545Stb 		R1(D, A, B, C, H, E, F, G, 0xf3988a32, W01, W01 ^ W05);
12743f50545Stb 		W01 = EXPAND(W01, W08, W14, W04, W11);
12843f50545Stb 		R1(C, D, A, B, G, H, E, F, 0xe7311465, W02, W02 ^ W06);
12943f50545Stb 		W02 = EXPAND(W02, W09, W15, W05, W12);
13043f50545Stb 		R1(B, C, D, A, F, G, H, E, 0xce6228cb, W03, W03 ^ W07);
13143f50545Stb 		W03 = EXPAND(W03, W10, W00, W06, W13);
13243f50545Stb 		R1(A, B, C, D, E, F, G, H, 0x9cc45197, W04, W04 ^ W08);
13343f50545Stb 		W04 = EXPAND(W04, W11, W01, W07, W14);
13443f50545Stb 		R1(D, A, B, C, H, E, F, G, 0x3988a32f, W05, W05 ^ W09);
13543f50545Stb 		W05 = EXPAND(W05, W12, W02, W08, W15);
13643f50545Stb 		R1(C, D, A, B, G, H, E, F, 0x7311465e, W06, W06 ^ W10);
13743f50545Stb 		W06 = EXPAND(W06, W13, W03, W09, W00);
13843f50545Stb 		R1(B, C, D, A, F, G, H, E, 0xe6228cbc, W07, W07 ^ W11);
13943f50545Stb 		W07 = EXPAND(W07, W14, W04, W10, W01);
14043f50545Stb 		R1(A, B, C, D, E, F, G, H, 0xcc451979, W08, W08 ^ W12);
14143f50545Stb 		W08 = EXPAND(W08, W15, W05, W11, W02);
14243f50545Stb 		R1(D, A, B, C, H, E, F, G, 0x988a32f3, W09, W09 ^ W13);
14343f50545Stb 		W09 = EXPAND(W09, W00, W06, W12, W03);
14443f50545Stb 		R1(C, D, A, B, G, H, E, F, 0x311465e7, W10, W10 ^ W14);
14543f50545Stb 		W10 = EXPAND(W10, W01, W07, W13, W04);
14643f50545Stb 		R1(B, C, D, A, F, G, H, E, 0x6228cbce, W11, W11 ^ W15);
14743f50545Stb 		W11 = EXPAND(W11, W02, W08, W14, W05);
14843f50545Stb 		R1(A, B, C, D, E, F, G, H, 0xc451979c, W12, W12 ^ W00);
14943f50545Stb 		W12 = EXPAND(W12, W03, W09, W15, W06);
15043f50545Stb 		R1(D, A, B, C, H, E, F, G, 0x88a32f39, W13, W13 ^ W01);
15143f50545Stb 		W13 = EXPAND(W13, W04, W10, W00, W07);
15243f50545Stb 		R1(C, D, A, B, G, H, E, F, 0x11465e73, W14, W14 ^ W02);
15343f50545Stb 		W14 = EXPAND(W14, W05, W11, W01, W08);
15443f50545Stb 		R1(B, C, D, A, F, G, H, E, 0x228cbce6, W15, W15 ^ W03);
15543f50545Stb 		W15 = EXPAND(W15, W06, W12, W02, W09);
15643f50545Stb 		R2(A, B, C, D, E, F, G, H, 0x9d8a7a87, W00, W00 ^ W04);
15743f50545Stb 		W00 = EXPAND(W00, W07, W13, W03, W10);
15843f50545Stb 		R2(D, A, B, C, H, E, F, G, 0x3b14f50f, W01, W01 ^ W05);
15943f50545Stb 		W01 = EXPAND(W01, W08, W14, W04, W11);
16043f50545Stb 		R2(C, D, A, B, G, H, E, F, 0x7629ea1e, W02, W02 ^ W06);
16143f50545Stb 		W02 = EXPAND(W02, W09, W15, W05, W12);
16243f50545Stb 		R2(B, C, D, A, F, G, H, E, 0xec53d43c, W03, W03 ^ W07);
16343f50545Stb 		W03 = EXPAND(W03, W10, W00, W06, W13);
16443f50545Stb 		R2(A, B, C, D, E, F, G, H, 0xd8a7a879, W04, W04 ^ W08);
16543f50545Stb 		W04 = EXPAND(W04, W11, W01, W07, W14);
16643f50545Stb 		R2(D, A, B, C, H, E, F, G, 0xb14f50f3, W05, W05 ^ W09);
16743f50545Stb 		W05 = EXPAND(W05, W12, W02, W08, W15);
16843f50545Stb 		R2(C, D, A, B, G, H, E, F, 0x629ea1e7, W06, W06 ^ W10);
16943f50545Stb 		W06 = EXPAND(W06, W13, W03, W09, W00);
17043f50545Stb 		R2(B, C, D, A, F, G, H, E, 0xc53d43ce, W07, W07 ^ W11);
17143f50545Stb 		W07 = EXPAND(W07, W14, W04, W10, W01);
17243f50545Stb 		R2(A, B, C, D, E, F, G, H, 0x8a7a879d, W08, W08 ^ W12);
17343f50545Stb 		W08 = EXPAND(W08, W15, W05, W11, W02);
17443f50545Stb 		R2(D, A, B, C, H, E, F, G, 0x14f50f3b, W09, W09 ^ W13);
17543f50545Stb 		W09 = EXPAND(W09, W00, W06, W12, W03);
17643f50545Stb 		R2(C, D, A, B, G, H, E, F, 0x29ea1e76, W10, W10 ^ W14);
17743f50545Stb 		W10 = EXPAND(W10, W01, W07, W13, W04);
17843f50545Stb 		R2(B, C, D, A, F, G, H, E, 0x53d43cec, W11, W11 ^ W15);
17943f50545Stb 		W11 = EXPAND(W11, W02, W08, W14, W05);
18043f50545Stb 		R2(A, B, C, D, E, F, G, H, 0xa7a879d8, W12, W12 ^ W00);
18143f50545Stb 		W12 = EXPAND(W12, W03, W09, W15, W06);
18243f50545Stb 		R2(D, A, B, C, H, E, F, G, 0x4f50f3b1, W13, W13 ^ W01);
18343f50545Stb 		W13 = EXPAND(W13, W04, W10, W00, W07);
18443f50545Stb 		R2(C, D, A, B, G, H, E, F, 0x9ea1e762, W14, W14 ^ W02);
18543f50545Stb 		W14 = EXPAND(W14, W05, W11, W01, W08);
18643f50545Stb 		R2(B, C, D, A, F, G, H, E, 0x3d43cec5, W15, W15 ^ W03);
18743f50545Stb 		W15 = EXPAND(W15, W06, W12, W02, W09);
18843f50545Stb 		R2(A, B, C, D, E, F, G, H, 0x7a879d8a, W00, W00 ^ W04);
18943f50545Stb 		W00 = EXPAND(W00, W07, W13, W03, W10);
19043f50545Stb 		R2(D, A, B, C, H, E, F, G, 0xf50f3b14, W01, W01 ^ W05);
19143f50545Stb 		W01 = EXPAND(W01, W08, W14, W04, W11);
19243f50545Stb 		R2(C, D, A, B, G, H, E, F, 0xea1e7629, W02, W02 ^ W06);
19343f50545Stb 		W02 = EXPAND(W02, W09, W15, W05, W12);
19443f50545Stb 		R2(B, C, D, A, F, G, H, E, 0xd43cec53, W03, W03 ^ W07);
19543f50545Stb 		W03 = EXPAND(W03, W10, W00, W06, W13);
19643f50545Stb 		R2(A, B, C, D, E, F, G, H, 0xa879d8a7, W04, W04 ^ W08);
19743f50545Stb 		W04 = EXPAND(W04, W11, W01, W07, W14);
19843f50545Stb 		R2(D, A, B, C, H, E, F, G, 0x50f3b14f, W05, W05 ^ W09);
19943f50545Stb 		W05 = EXPAND(W05, W12, W02, W08, W15);
20043f50545Stb 		R2(C, D, A, B, G, H, E, F, 0xa1e7629e, W06, W06 ^ W10);
20143f50545Stb 		W06 = EXPAND(W06, W13, W03, W09, W00);
20243f50545Stb 		R2(B, C, D, A, F, G, H, E, 0x43cec53d, W07, W07 ^ W11);
20343f50545Stb 		W07 = EXPAND(W07, W14, W04, W10, W01);
20443f50545Stb 		R2(A, B, C, D, E, F, G, H, 0x879d8a7a, W08, W08 ^ W12);
20543f50545Stb 		W08 = EXPAND(W08, W15, W05, W11, W02);
20643f50545Stb 		R2(D, A, B, C, H, E, F, G, 0x0f3b14f5, W09, W09 ^ W13);
20743f50545Stb 		W09 = EXPAND(W09, W00, W06, W12, W03);
20843f50545Stb 		R2(C, D, A, B, G, H, E, F, 0x1e7629ea, W10, W10 ^ W14);
20943f50545Stb 		W10 = EXPAND(W10, W01, W07, W13, W04);
21043f50545Stb 		R2(B, C, D, A, F, G, H, E, 0x3cec53d4, W11, W11 ^ W15);
21143f50545Stb 		W11 = EXPAND(W11, W02, W08, W14, W05);
21243f50545Stb 		R2(A, B, C, D, E, F, G, H, 0x79d8a7a8, W12, W12 ^ W00);
21343f50545Stb 		W12 = EXPAND(W12, W03, W09, W15, W06);
21443f50545Stb 		R2(D, A, B, C, H, E, F, G, 0xf3b14f50, W13, W13 ^ W01);
21543f50545Stb 		W13 = EXPAND(W13, W04, W10, W00, W07);
21643f50545Stb 		R2(C, D, A, B, G, H, E, F, 0xe7629ea1, W14, W14 ^ W02);
21743f50545Stb 		W14 = EXPAND(W14, W05, W11, W01, W08);
21843f50545Stb 		R2(B, C, D, A, F, G, H, E, 0xcec53d43, W15, W15 ^ W03);
21943f50545Stb 		W15 = EXPAND(W15, W06, W12, W02, W09);
22043f50545Stb 		R2(A, B, C, D, E, F, G, H, 0x9d8a7a87, W00, W00 ^ W04);
22143f50545Stb 		W00 = EXPAND(W00, W07, W13, W03, W10);
22243f50545Stb 		R2(D, A, B, C, H, E, F, G, 0x3b14f50f, W01, W01 ^ W05);
22343f50545Stb 		W01 = EXPAND(W01, W08, W14, W04, W11);
22443f50545Stb 		R2(C, D, A, B, G, H, E, F, 0x7629ea1e, W02, W02 ^ W06);
22543f50545Stb 		W02 = EXPAND(W02, W09, W15, W05, W12);
22643f50545Stb 		R2(B, C, D, A, F, G, H, E, 0xec53d43c, W03, W03 ^ W07);
22743f50545Stb 		W03 = EXPAND(W03, W10, W00, W06, W13);
22843f50545Stb 		R2(A, B, C, D, E, F, G, H, 0xd8a7a879, W04, W04 ^ W08);
22943f50545Stb 		R2(D, A, B, C, H, E, F, G, 0xb14f50f3, W05, W05 ^ W09);
23043f50545Stb 		R2(C, D, A, B, G, H, E, F, 0x629ea1e7, W06, W06 ^ W10);
23143f50545Stb 		R2(B, C, D, A, F, G, H, E, 0xc53d43ce, W07, W07 ^ W11);
23243f50545Stb 		R2(A, B, C, D, E, F, G, H, 0x8a7a879d, W08, W08 ^ W12);
23343f50545Stb 		R2(D, A, B, C, H, E, F, G, 0x14f50f3b, W09, W09 ^ W13);
23443f50545Stb 		R2(C, D, A, B, G, H, E, F, 0x29ea1e76, W10, W10 ^ W14);
23543f50545Stb 		R2(B, C, D, A, F, G, H, E, 0x53d43cec, W11, W11 ^ W15);
23643f50545Stb 		R2(A, B, C, D, E, F, G, H, 0xa7a879d8, W12, W12 ^ W00);
23743f50545Stb 		R2(D, A, B, C, H, E, F, G, 0x4f50f3b1, W13, W13 ^ W01);
23843f50545Stb 		R2(C, D, A, B, G, H, E, F, 0x9ea1e762, W14, W14 ^ W02);
23943f50545Stb 		R2(B, C, D, A, F, G, H, E, 0x3d43cec5, W15, W15 ^ W03);
24043f50545Stb 
24143f50545Stb 		ctx->A ^= A;
24243f50545Stb 		ctx->B ^= B;
24343f50545Stb 		ctx->C ^= C;
24443f50545Stb 		ctx->D ^= D;
24543f50545Stb 		ctx->E ^= E;
24643f50545Stb 		ctx->F ^= F;
24743f50545Stb 		ctx->G ^= G;
24843f50545Stb 		ctx->H ^= H;
24943f50545Stb 	}
25043f50545Stb }
25143f50545Stb 
2524fdabbcdSjsing int
2534fdabbcdSjsing SM3_Init(SM3_CTX *c)
2544fdabbcdSjsing {
2554fdabbcdSjsing 	memset(c, 0, sizeof(*c));
256a73890b6Sjsing 
257a73890b6Sjsing 	c->A = 0x7380166fUL;
258a73890b6Sjsing 	c->B = 0x4914b2b9UL;
259a73890b6Sjsing 	c->C = 0x172442d7UL;
260a73890b6Sjsing 	c->D = 0xda8a0600UL;
261a73890b6Sjsing 	c->E = 0xa96f30bcUL;
262a73890b6Sjsing 	c->F = 0x163138aaUL;
263a73890b6Sjsing 	c->G = 0xe38dee4dUL;
264a73890b6Sjsing 	c->H = 0xb0fb0e4eUL;
265a73890b6Sjsing 
2664fdabbcdSjsing 	return 1;
2674fdabbcdSjsing }
2684fdabbcdSjsing LCRYPTO_ALIAS(SM3_Init);
2694fdabbcdSjsing 
2704fdabbcdSjsing int
271fffffb53Sjsing SM3_Update(SM3_CTX *c, const void *data_, size_t len)
2724fdabbcdSjsing {
2734fdabbcdSjsing 	const unsigned char *data = data_;
2744fdabbcdSjsing 	unsigned char *p;
275fffffb53Sjsing 	SM3_WORD l;
2764fdabbcdSjsing 	size_t n;
2774fdabbcdSjsing 
2784fdabbcdSjsing 	if (len == 0)
2794fdabbcdSjsing 		return 1;
2804fdabbcdSjsing 
281fffffb53Sjsing 	l = (c->Nl + (((SM3_WORD)len) << 3))&0xffffffffUL;
2824fdabbcdSjsing 	/* 95-05-24 eay Fixed a bug with the overflow handling, thanks to
2834fdabbcdSjsing 	 * Wei Dai <weidai@eskimo.com> for pointing it out. */
2844fdabbcdSjsing 	if (l < c->Nl) /* overflow */
2854fdabbcdSjsing 		c->Nh++;
286fffffb53Sjsing 	c->Nh+=(SM3_WORD)(len>>29);	/* might cause compiler warning on 16-bit */
2874fdabbcdSjsing 	c->Nl = l;
2884fdabbcdSjsing 
2894fdabbcdSjsing 	n = c->num;
2904fdabbcdSjsing 	if (n != 0) {
2914fdabbcdSjsing 		p = (unsigned char *)c->data;
2924fdabbcdSjsing 
293fffffb53Sjsing 		if (len >= SM3_CBLOCK || len + n >= SM3_CBLOCK) {
294fffffb53Sjsing 			memcpy(p + n, data, SM3_CBLOCK - n);
2959bcde62cSjsing 			sm3_block_data_order(c, p, 1);
296fffffb53Sjsing 			n = SM3_CBLOCK - n;
2974fdabbcdSjsing 			data += n;
2984fdabbcdSjsing 			len -= n;
2994fdabbcdSjsing 			c->num = 0;
300fffffb53Sjsing 			memset(p, 0, SM3_CBLOCK);	/* keep it zeroed */
3014fdabbcdSjsing 		} else {
3024fdabbcdSjsing 			memcpy(p + n, data, len);
3034fdabbcdSjsing 			c->num += (unsigned int)len;
3044fdabbcdSjsing 			return 1;
3054fdabbcdSjsing 		}
3064fdabbcdSjsing 	}
3074fdabbcdSjsing 
308fffffb53Sjsing 	n = len / SM3_CBLOCK;
3094fdabbcdSjsing 	if (n > 0) {
3109bcde62cSjsing 		sm3_block_data_order(c, data, n);
311fffffb53Sjsing 		n *= SM3_CBLOCK;
3124fdabbcdSjsing 		data += n;
3134fdabbcdSjsing 		len -= n;
3144fdabbcdSjsing 	}
3154fdabbcdSjsing 
3164fdabbcdSjsing 	if (len != 0) {
3174fdabbcdSjsing 		p = (unsigned char *)c->data;
3184fdabbcdSjsing 		c->num = (unsigned int)len;
3194fdabbcdSjsing 		memcpy(p, data, len);
3204fdabbcdSjsing 	}
3214fdabbcdSjsing 	return 1;
3224fdabbcdSjsing }
3234fdabbcdSjsing LCRYPTO_ALIAS(SM3_Update);
3244fdabbcdSjsing 
325fffffb53Sjsing int
326fffffb53Sjsing SM3_Final(unsigned char *md, SM3_CTX *c)
3274fdabbcdSjsing {
3284fdabbcdSjsing 	unsigned char *p = (unsigned char *)c->data;
3294fdabbcdSjsing 	size_t n = c->num;
3304fdabbcdSjsing 
3314fdabbcdSjsing 	p[n] = 0x80; /* there is always room for one */
3324fdabbcdSjsing 	n++;
3334fdabbcdSjsing 
334fffffb53Sjsing 	if (n > (SM3_CBLOCK - 8)) {
335fffffb53Sjsing 		memset(p + n, 0, SM3_CBLOCK - n);
3364fdabbcdSjsing 		n = 0;
3379bcde62cSjsing 		sm3_block_data_order(c, p, 1);
3384fdabbcdSjsing 	}
3394fdabbcdSjsing 
340a1643a46Sjsing 	memset(p + n, 0, SM3_CBLOCK - 8 - n);
341a1643a46Sjsing 	c->data[SM3_LBLOCK - 2] = htobe32(c->Nh);
342a1643a46Sjsing 	c->data[SM3_LBLOCK - 1] = htobe32(c->Nl);
343a1643a46Sjsing 
3449bcde62cSjsing 	sm3_block_data_order(c, p, 1);
3454fdabbcdSjsing 	c->num = 0;
346fffffb53Sjsing 	memset(p, 0, SM3_CBLOCK);
3474fdabbcdSjsing 
348a1643a46Sjsing 	crypto_store_htobe32(&md[0 * 4], c->A);
349a1643a46Sjsing 	crypto_store_htobe32(&md[1 * 4], c->B);
350a1643a46Sjsing 	crypto_store_htobe32(&md[2 * 4], c->C);
351a1643a46Sjsing 	crypto_store_htobe32(&md[3 * 4], c->D);
352a1643a46Sjsing 	crypto_store_htobe32(&md[4 * 4], c->E);
353a1643a46Sjsing 	crypto_store_htobe32(&md[5 * 4], c->F);
354a1643a46Sjsing 	crypto_store_htobe32(&md[6 * 4], c->G);
355a1643a46Sjsing 	crypto_store_htobe32(&md[7 * 4], c->H);
3564fdabbcdSjsing 
3574fdabbcdSjsing 	return 1;
3584fdabbcdSjsing }
3594fdabbcdSjsing LCRYPTO_ALIAS(SM3_Final);
3604fdabbcdSjsing 
36143f50545Stb #endif /* !OPENSSL_NO_SM3 */
362