blob: d798d9b04d5dfc9e852df3522143231d7e7aacc0 [file] [log] [blame]
<!DOCTYPE html><html lang="en"><head><meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><meta name="generator" content="rustdoc"><meta name="description" content="Source of the Rust file `rand_chacha&#x2F;src&#x2F;chacha.rs`."><meta name="keywords" content="rust, rustlang, rust-lang"><title>chacha.rs - source</title><link rel="preload" as="font" type="font/woff2" crossorigin href="../../SourceSerif4-Regular.ttf.woff2"><link rel="preload" as="font" type="font/woff2" crossorigin href="../../FiraSans-Regular.woff2"><link rel="preload" as="font" type="font/woff2" crossorigin href="../../FiraSans-Medium.woff2"><link rel="preload" as="font" type="font/woff2" crossorigin href="../../SourceCodePro-Regular.ttf.woff2"><link rel="preload" as="font" type="font/woff2" crossorigin href="../../SourceSerif4-Bold.ttf.woff2"><link rel="preload" as="font" type="font/woff2" crossorigin href="../../SourceCodePro-Semibold.ttf.woff2"><link rel="stylesheet" type="text/css" href="../../normalize.css"><link rel="stylesheet" type="text/css" href="../../rustdoc.css" id="mainThemeStyle"><link rel="stylesheet" type="text/css" href="../../ayu.css" disabled><link rel="stylesheet" type="text/css" href="../../dark.css" disabled><link rel="stylesheet" type="text/css" href="../../light.css" id="themeStyle"><script id="default-settings" ></script><script src="../../storage.js"></script><script src="../../crates.js"></script><script defer src="../../main.js"></script><script defer src="../../source-script.js"></script><script defer src="../../source-files.js"></script>
<noscript><link rel="stylesheet" href="../../noscript.css"></noscript><link rel="shortcut icon" href="https:&#x2F;&#x2F;www.rust-lang.org&#x2F;favicon.ico"></head><body class="rustdoc source"><!--[if lte IE 11]><div class="warning">This old browser is unsupported and will most likely display funky things.</div><![endif]--><nav class="sidebar"><div class="sidebar-menu" role="button">&#9776;</div><a class="sidebar-logo" href="../../rand_chacha/index.html"><div class="logo-container"><img src="https:&#x2F;&#x2F;www.rust-lang.org&#x2F;logos&#x2F;rust-logo-128x128-blk.png" alt="logo"></div>
</a></nav><main><div class="width-limiter"><div class="sub-container"><a class="sub-logo-container" href="../../rand_chacha/index.html"><img src="https:&#x2F;&#x2F;www.rust-lang.org&#x2F;logos&#x2F;rust-logo-128x128-blk.png" alt="logo"></a><nav class="sub"><div class="theme-picker"><button id="theme-picker" aria-label="Pick another theme!" aria-haspopup="menu" title="themes"><img width="18" height="18" alt="Pick another theme!" src="../../brush.svg"></button><div id="theme-choices" role="menu"></div></div><form class="search-form"><div class="search-container"><div>
<input class="search-input" name="search" autocomplete="off" spellcheck="false" placeholder="Click or press ‘S’ to search, ‘?’ for more options…" type="search"></div><button type="button" id="help-button" title="help">?</button><a id="settings-menu" href="../../settings.html" title="settings"><img width="18" height="18" alt="Change settings" src="../../wheel.svg"></a></div></form></nav></div><section id="main-content" class="content"><div class="example-wrap"><pre class="line-numbers"><span id="1"> 1</span>
<span id="2"> 2</span>
<span id="3"> 3</span>
<span id="4"> 4</span>
<span id="5"> 5</span>
<span id="6"> 6</span>
<span id="7"> 7</span>
<span id="8"> 8</span>
<span id="9"> 9</span>
<span id="10"> 10</span>
<span id="11"> 11</span>
<span id="12"> 12</span>
<span id="13"> 13</span>
<span id="14"> 14</span>
<span id="15"> 15</span>
<span id="16"> 16</span>
<span id="17"> 17</span>
<span id="18"> 18</span>
<span id="19"> 19</span>
<span id="20"> 20</span>
<span id="21"> 21</span>
<span id="22"> 22</span>
<span id="23"> 23</span>
<span id="24"> 24</span>
<span id="25"> 25</span>
<span id="26"> 26</span>
<span id="27"> 27</span>
<span id="28"> 28</span>
<span id="29"> 29</span>
<span id="30"> 30</span>
<span id="31"> 31</span>
<span id="32"> 32</span>
<span id="33"> 33</span>
<span id="34"> 34</span>
<span id="35"> 35</span>
<span id="36"> 36</span>
<span id="37"> 37</span>
<span id="38"> 38</span>
<span id="39"> 39</span>
<span id="40"> 40</span>
<span id="41"> 41</span>
<span id="42"> 42</span>
<span id="43"> 43</span>
<span id="44"> 44</span>
<span id="45"> 45</span>
<span id="46"> 46</span>
<span id="47"> 47</span>
<span id="48"> 48</span>
<span id="49"> 49</span>
<span id="50"> 50</span>
<span id="51"> 51</span>
<span id="52"> 52</span>
<span id="53"> 53</span>
<span id="54"> 54</span>
<span id="55"> 55</span>
<span id="56"> 56</span>
<span id="57"> 57</span>
<span id="58"> 58</span>
<span id="59"> 59</span>
<span id="60"> 60</span>
<span id="61"> 61</span>
<span id="62"> 62</span>
<span id="63"> 63</span>
<span id="64"> 64</span>
<span id="65"> 65</span>
<span id="66"> 66</span>
<span id="67"> 67</span>
<span id="68"> 68</span>
<span id="69"> 69</span>
<span id="70"> 70</span>
<span id="71"> 71</span>
<span id="72"> 72</span>
<span id="73"> 73</span>
<span id="74"> 74</span>
<span id="75"> 75</span>
<span id="76"> 76</span>
<span id="77"> 77</span>
<span id="78"> 78</span>
<span id="79"> 79</span>
<span id="80"> 80</span>
<span id="81"> 81</span>
<span id="82"> 82</span>
<span id="83"> 83</span>
<span id="84"> 84</span>
<span id="85"> 85</span>
<span id="86"> 86</span>
<span id="87"> 87</span>
<span id="88"> 88</span>
<span id="89"> 89</span>
<span id="90"> 90</span>
<span id="91"> 91</span>
<span id="92"> 92</span>
<span id="93"> 93</span>
<span id="94"> 94</span>
<span id="95"> 95</span>
<span id="96"> 96</span>
<span id="97"> 97</span>
<span id="98"> 98</span>
<span id="99"> 99</span>
<span id="100">100</span>
<span id="101">101</span>
<span id="102">102</span>
<span id="103">103</span>
<span id="104">104</span>
<span id="105">105</span>
<span id="106">106</span>
<span id="107">107</span>
<span id="108">108</span>
<span id="109">109</span>
<span id="110">110</span>
<span id="111">111</span>
<span id="112">112</span>
<span id="113">113</span>
<span id="114">114</span>
<span id="115">115</span>
<span id="116">116</span>
<span id="117">117</span>
<span id="118">118</span>
<span id="119">119</span>
<span id="120">120</span>
<span id="121">121</span>
<span id="122">122</span>
<span id="123">123</span>
<span id="124">124</span>
<span id="125">125</span>
<span id="126">126</span>
<span id="127">127</span>
<span id="128">128</span>
<span id="129">129</span>
<span id="130">130</span>
<span id="131">131</span>
<span id="132">132</span>
<span id="133">133</span>
<span id="134">134</span>
<span id="135">135</span>
<span id="136">136</span>
<span id="137">137</span>
<span id="138">138</span>
<span id="139">139</span>
<span id="140">140</span>
<span id="141">141</span>
<span id="142">142</span>
<span id="143">143</span>
<span id="144">144</span>
<span id="145">145</span>
<span id="146">146</span>
<span id="147">147</span>
<span id="148">148</span>
<span id="149">149</span>
<span id="150">150</span>
<span id="151">151</span>
<span id="152">152</span>
<span id="153">153</span>
<span id="154">154</span>
<span id="155">155</span>
<span id="156">156</span>
<span id="157">157</span>
<span id="158">158</span>
<span id="159">159</span>
<span id="160">160</span>
<span id="161">161</span>
<span id="162">162</span>
<span id="163">163</span>
<span id="164">164</span>
<span id="165">165</span>
<span id="166">166</span>
<span id="167">167</span>
<span id="168">168</span>
<span id="169">169</span>
<span id="170">170</span>
<span id="171">171</span>
<span id="172">172</span>
<span id="173">173</span>
<span id="174">174</span>
<span id="175">175</span>
<span id="176">176</span>
<span id="177">177</span>
<span id="178">178</span>
<span id="179">179</span>
<span id="180">180</span>
<span id="181">181</span>
<span id="182">182</span>
<span id="183">183</span>
<span id="184">184</span>
<span id="185">185</span>
<span id="186">186</span>
<span id="187">187</span>
<span id="188">188</span>
<span id="189">189</span>
<span id="190">190</span>
<span id="191">191</span>
<span id="192">192</span>
<span id="193">193</span>
<span id="194">194</span>
<span id="195">195</span>
<span id="196">196</span>
<span id="197">197</span>
<span id="198">198</span>
<span id="199">199</span>
<span id="200">200</span>
<span id="201">201</span>
<span id="202">202</span>
<span id="203">203</span>
<span id="204">204</span>
<span id="205">205</span>
<span id="206">206</span>
<span id="207">207</span>
<span id="208">208</span>
<span id="209">209</span>
<span id="210">210</span>
<span id="211">211</span>
<span id="212">212</span>
<span id="213">213</span>
<span id="214">214</span>
<span id="215">215</span>
<span id="216">216</span>
<span id="217">217</span>
<span id="218">218</span>
<span id="219">219</span>
<span id="220">220</span>
<span id="221">221</span>
<span id="222">222</span>
<span id="223">223</span>
<span id="224">224</span>
<span id="225">225</span>
<span id="226">226</span>
<span id="227">227</span>
<span id="228">228</span>
<span id="229">229</span>
<span id="230">230</span>
<span id="231">231</span>
<span id="232">232</span>
<span id="233">233</span>
<span id="234">234</span>
<span id="235">235</span>
<span id="236">236</span>
<span id="237">237</span>
<span id="238">238</span>
<span id="239">239</span>
<span id="240">240</span>
<span id="241">241</span>
<span id="242">242</span>
<span id="243">243</span>
<span id="244">244</span>
<span id="245">245</span>
<span id="246">246</span>
<span id="247">247</span>
<span id="248">248</span>
<span id="249">249</span>
<span id="250">250</span>
<span id="251">251</span>
<span id="252">252</span>
<span id="253">253</span>
<span id="254">254</span>
<span id="255">255</span>
<span id="256">256</span>
<span id="257">257</span>
<span id="258">258</span>
<span id="259">259</span>
<span id="260">260</span>
<span id="261">261</span>
<span id="262">262</span>
<span id="263">263</span>
<span id="264">264</span>
<span id="265">265</span>
<span id="266">266</span>
<span id="267">267</span>
<span id="268">268</span>
<span id="269">269</span>
<span id="270">270</span>
<span id="271">271</span>
<span id="272">272</span>
<span id="273">273</span>
<span id="274">274</span>
<span id="275">275</span>
<span id="276">276</span>
<span id="277">277</span>
<span id="278">278</span>
<span id="279">279</span>
<span id="280">280</span>
<span id="281">281</span>
<span id="282">282</span>
<span id="283">283</span>
<span id="284">284</span>
<span id="285">285</span>
<span id="286">286</span>
<span id="287">287</span>
<span id="288">288</span>
<span id="289">289</span>
<span id="290">290</span>
<span id="291">291</span>
<span id="292">292</span>
<span id="293">293</span>
<span id="294">294</span>
<span id="295">295</span>
<span id="296">296</span>
<span id="297">297</span>
<span id="298">298</span>
<span id="299">299</span>
<span id="300">300</span>
<span id="301">301</span>
<span id="302">302</span>
<span id="303">303</span>
<span id="304">304</span>
<span id="305">305</span>
<span id="306">306</span>
<span id="307">307</span>
<span id="308">308</span>
<span id="309">309</span>
<span id="310">310</span>
<span id="311">311</span>
<span id="312">312</span>
<span id="313">313</span>
<span id="314">314</span>
<span id="315">315</span>
<span id="316">316</span>
<span id="317">317</span>
<span id="318">318</span>
<span id="319">319</span>
<span id="320">320</span>
<span id="321">321</span>
<span id="322">322</span>
<span id="323">323</span>
<span id="324">324</span>
<span id="325">325</span>
<span id="326">326</span>
<span id="327">327</span>
<span id="328">328</span>
<span id="329">329</span>
<span id="330">330</span>
<span id="331">331</span>
<span id="332">332</span>
<span id="333">333</span>
<span id="334">334</span>
<span id="335">335</span>
<span id="336">336</span>
<span id="337">337</span>
<span id="338">338</span>
<span id="339">339</span>
<span id="340">340</span>
<span id="341">341</span>
<span id="342">342</span>
<span id="343">343</span>
<span id="344">344</span>
<span id="345">345</span>
<span id="346">346</span>
<span id="347">347</span>
<span id="348">348</span>
<span id="349">349</span>
<span id="350">350</span>
<span id="351">351</span>
<span id="352">352</span>
<span id="353">353</span>
<span id="354">354</span>
<span id="355">355</span>
<span id="356">356</span>
<span id="357">357</span>
<span id="358">358</span>
<span id="359">359</span>
<span id="360">360</span>
<span id="361">361</span>
<span id="362">362</span>
<span id="363">363</span>
<span id="364">364</span>
<span id="365">365</span>
<span id="366">366</span>
<span id="367">367</span>
<span id="368">368</span>
<span id="369">369</span>
<span id="370">370</span>
<span id="371">371</span>
<span id="372">372</span>
<span id="373">373</span>
<span id="374">374</span>
<span id="375">375</span>
<span id="376">376</span>
<span id="377">377</span>
<span id="378">378</span>
<span id="379">379</span>
<span id="380">380</span>
<span id="381">381</span>
<span id="382">382</span>
<span id="383">383</span>
<span id="384">384</span>
<span id="385">385</span>
<span id="386">386</span>
<span id="387">387</span>
<span id="388">388</span>
<span id="389">389</span>
<span id="390">390</span>
<span id="391">391</span>
<span id="392">392</span>
<span id="393">393</span>
<span id="394">394</span>
<span id="395">395</span>
<span id="396">396</span>
<span id="397">397</span>
<span id="398">398</span>
<span id="399">399</span>
<span id="400">400</span>
<span id="401">401</span>
<span id="402">402</span>
<span id="403">403</span>
<span id="404">404</span>
<span id="405">405</span>
<span id="406">406</span>
<span id="407">407</span>
<span id="408">408</span>
<span id="409">409</span>
<span id="410">410</span>
<span id="411">411</span>
<span id="412">412</span>
<span id="413">413</span>
<span id="414">414</span>
<span id="415">415</span>
<span id="416">416</span>
<span id="417">417</span>
<span id="418">418</span>
<span id="419">419</span>
<span id="420">420</span>
<span id="421">421</span>
<span id="422">422</span>
<span id="423">423</span>
<span id="424">424</span>
<span id="425">425</span>
<span id="426">426</span>
<span id="427">427</span>
<span id="428">428</span>
<span id="429">429</span>
<span id="430">430</span>
<span id="431">431</span>
<span id="432">432</span>
<span id="433">433</span>
<span id="434">434</span>
<span id="435">435</span>
<span id="436">436</span>
<span id="437">437</span>
<span id="438">438</span>
<span id="439">439</span>
<span id="440">440</span>
<span id="441">441</span>
<span id="442">442</span>
<span id="443">443</span>
<span id="444">444</span>
<span id="445">445</span>
<span id="446">446</span>
<span id="447">447</span>
<span id="448">448</span>
<span id="449">449</span>
<span id="450">450</span>
<span id="451">451</span>
<span id="452">452</span>
<span id="453">453</span>
<span id="454">454</span>
<span id="455">455</span>
<span id="456">456</span>
<span id="457">457</span>
<span id="458">458</span>
<span id="459">459</span>
<span id="460">460</span>
<span id="461">461</span>
<span id="462">462</span>
<span id="463">463</span>
<span id="464">464</span>
<span id="465">465</span>
<span id="466">466</span>
<span id="467">467</span>
<span id="468">468</span>
<span id="469">469</span>
<span id="470">470</span>
<span id="471">471</span>
<span id="472">472</span>
<span id="473">473</span>
<span id="474">474</span>
<span id="475">475</span>
<span id="476">476</span>
<span id="477">477</span>
<span id="478">478</span>
<span id="479">479</span>
<span id="480">480</span>
<span id="481">481</span>
<span id="482">482</span>
<span id="483">483</span>
<span id="484">484</span>
<span id="485">485</span>
<span id="486">486</span>
<span id="487">487</span>
<span id="488">488</span>
<span id="489">489</span>
<span id="490">490</span>
<span id="491">491</span>
<span id="492">492</span>
<span id="493">493</span>
<span id="494">494</span>
<span id="495">495</span>
<span id="496">496</span>
<span id="497">497</span>
<span id="498">498</span>
<span id="499">499</span>
<span id="500">500</span>
<span id="501">501</span>
<span id="502">502</span>
<span id="503">503</span>
<span id="504">504</span>
<span id="505">505</span>
<span id="506">506</span>
<span id="507">507</span>
<span id="508">508</span>
<span id="509">509</span>
<span id="510">510</span>
<span id="511">511</span>
<span id="512">512</span>
<span id="513">513</span>
<span id="514">514</span>
<span id="515">515</span>
<span id="516">516</span>
<span id="517">517</span>
<span id="518">518</span>
<span id="519">519</span>
<span id="520">520</span>
<span id="521">521</span>
<span id="522">522</span>
<span id="523">523</span>
<span id="524">524</span>
<span id="525">525</span>
<span id="526">526</span>
<span id="527">527</span>
<span id="528">528</span>
<span id="529">529</span>
<span id="530">530</span>
<span id="531">531</span>
<span id="532">532</span>
<span id="533">533</span>
<span id="534">534</span>
<span id="535">535</span>
<span id="536">536</span>
<span id="537">537</span>
<span id="538">538</span>
<span id="539">539</span>
<span id="540">540</span>
<span id="541">541</span>
<span id="542">542</span>
<span id="543">543</span>
<span id="544">544</span>
<span id="545">545</span>
<span id="546">546</span>
<span id="547">547</span>
<span id="548">548</span>
<span id="549">549</span>
<span id="550">550</span>
<span id="551">551</span>
<span id="552">552</span>
<span id="553">553</span>
<span id="554">554</span>
<span id="555">555</span>
<span id="556">556</span>
<span id="557">557</span>
<span id="558">558</span>
<span id="559">559</span>
<span id="560">560</span>
<span id="561">561</span>
<span id="562">562</span>
<span id="563">563</span>
<span id="564">564</span>
<span id="565">565</span>
<span id="566">566</span>
<span id="567">567</span>
<span id="568">568</span>
<span id="569">569</span>
<span id="570">570</span>
<span id="571">571</span>
<span id="572">572</span>
<span id="573">573</span>
<span id="574">574</span>
<span id="575">575</span>
<span id="576">576</span>
<span id="577">577</span>
<span id="578">578</span>
<span id="579">579</span>
<span id="580">580</span>
<span id="581">581</span>
<span id="582">582</span>
<span id="583">583</span>
<span id="584">584</span>
<span id="585">585</span>
<span id="586">586</span>
<span id="587">587</span>
<span id="588">588</span>
<span id="589">589</span>
<span id="590">590</span>
<span id="591">591</span>
<span id="592">592</span>
<span id="593">593</span>
<span id="594">594</span>
<span id="595">595</span>
<span id="596">596</span>
<span id="597">597</span>
<span id="598">598</span>
<span id="599">599</span>
<span id="600">600</span>
<span id="601">601</span>
<span id="602">602</span>
<span id="603">603</span>
<span id="604">604</span>
<span id="605">605</span>
<span id="606">606</span>
<span id="607">607</span>
<span id="608">608</span>
<span id="609">609</span>
<span id="610">610</span>
<span id="611">611</span>
<span id="612">612</span>
<span id="613">613</span>
<span id="614">614</span>
<span id="615">615</span>
<span id="616">616</span>
<span id="617">617</span>
<span id="618">618</span>
<span id="619">619</span>
<span id="620">620</span>
<span id="621">621</span>
<span id="622">622</span>
<span id="623">623</span>
<span id="624">624</span>
<span id="625">625</span>
<span id="626">626</span>
<span id="627">627</span>
<span id="628">628</span>
<span id="629">629</span>
<span id="630">630</span>
<span id="631">631</span>
<span id="632">632</span>
<span id="633">633</span>
<span id="634">634</span>
<span id="635">635</span>
<span id="636">636</span>
<span id="637">637</span>
</pre><pre class="rust"><code><span class="comment">// Copyright 2018 Developers of the Rand project.</span>
<span class="comment">//</span>
<span class="comment">// Licensed under the Apache License, Version 2.0 &lt;LICENSE-APACHE or</span>
<span class="comment">// https://www.apache.org/licenses/LICENSE-2.0&gt; or the MIT license</span>
<span class="comment">// &lt;LICENSE-MIT or https://opensource.org/licenses/MIT&gt;, at your</span>
<span class="comment">// option. This file may not be copied, modified, or distributed</span>
<span class="comment">// except according to those terms.</span>
<span class="doccomment">//! The ChaCha random number generator.</span>
<span class="attribute">#[<span class="ident">cfg</span>(<span class="ident">not</span>(<span class="ident">feature</span> <span class="op">=</span> <span class="string">&quot;std&quot;</span>))]</span> <span class="kw">use</span> <span class="ident">core</span>;
<span class="attribute">#[<span class="ident">cfg</span>(<span class="ident">feature</span> <span class="op">=</span> <span class="string">&quot;std&quot;</span>)]</span> <span class="kw">use</span> <span class="ident">std</span> <span class="kw">as</span> <span class="ident">core</span>;
<span class="kw">use</span> <span class="ident"><span class="self">self</span>::core::fmt</span>;
<span class="kw">use</span> <span class="ident"><span class="kw">crate</span>::guts::ChaCha</span>;
<span class="kw">use</span> <span class="ident">rand_core::block</span>::{<span class="ident">BlockRng</span>, <span class="ident">BlockRngCore</span>};
<span class="kw">use</span> <span class="ident">rand_core</span>::{<span class="ident">CryptoRng</span>, <span class="ident">Error</span>, <span class="ident">RngCore</span>, <span class="ident">SeedableRng</span>};
<span class="attribute">#[<span class="ident">cfg</span>(<span class="ident">feature</span> <span class="op">=</span> <span class="string">&quot;serde1&quot;</span>)]</span> <span class="kw">use</span> <span class="ident">serde</span>::{<span class="ident">Serialize</span>, <span class="ident">Deserialize</span>, <span class="ident">Serializer</span>, <span class="ident">Deserializer</span>};
<span class="comment">// NB. this must remain consistent with some currently hard-coded numbers in this module</span>
<span class="kw">const</span> <span class="ident">BUF_BLOCKS</span>: <span class="ident">u8</span> <span class="op">=</span> <span class="number">4</span>;
<span class="comment">// number of 32-bit words per ChaCha block (fixed by algorithm definition)</span>
<span class="kw">const</span> <span class="ident">BLOCK_WORDS</span>: <span class="ident">u8</span> <span class="op">=</span> <span class="number">16</span>;
<span class="attribute">#[<span class="ident">repr</span>(<span class="ident">transparent</span>)]</span>
<span class="kw">pub</span> <span class="kw">struct</span> <span class="ident">Array64</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span>([<span class="ident">T</span>; <span class="number">64</span>]);
<span class="kw">impl</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span> <span class="ident">Default</span> <span class="kw">for</span> <span class="ident">Array64</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span>
<span class="kw">where</span> <span class="ident">T</span>: <span class="ident">Default</span>
{
<span class="attribute">#[<span class="ident">rustfmt::skip</span>]</span>
<span class="kw">fn</span> <span class="ident">default</span>() -&gt; <span class="self">Self</span> {
<span class="self">Self</span>([
<span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(),
<span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(),
<span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(),
<span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(),
<span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(),
<span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(),
<span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(),
<span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(), <span class="ident">T::default</span>(),
])
}
}
<span class="kw">impl</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span> <span class="ident">AsRef</span><span class="op">&lt;</span>[<span class="ident">T</span>]<span class="op">&gt;</span> <span class="kw">for</span> <span class="ident">Array64</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span> {
<span class="kw">fn</span> <span class="ident">as_ref</span>(<span class="kw-2">&amp;</span><span class="self">self</span>) -&gt; <span class="kw-2">&amp;</span>[<span class="ident">T</span>] {
<span class="kw-2">&amp;</span><span class="self">self</span>.<span class="number">0</span>
}
}
<span class="kw">impl</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span> <span class="ident">AsMut</span><span class="op">&lt;</span>[<span class="ident">T</span>]<span class="op">&gt;</span> <span class="kw">for</span> <span class="ident">Array64</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span> {
<span class="kw">fn</span> <span class="ident">as_mut</span>(<span class="kw-2">&amp;mut</span> <span class="self">self</span>) -&gt; <span class="kw-2">&amp;mut</span> [<span class="ident">T</span>] {
<span class="kw-2">&amp;mut</span> <span class="self">self</span>.<span class="number">0</span>
}
}
<span class="kw">impl</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span> <span class="ident">Clone</span> <span class="kw">for</span> <span class="ident">Array64</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span>
<span class="kw">where</span> <span class="ident">T</span>: <span class="ident">Copy</span> <span class="op">+</span> <span class="ident">Default</span>
{
<span class="kw">fn</span> <span class="ident">clone</span>(<span class="kw-2">&amp;</span><span class="self">self</span>) -&gt; <span class="self">Self</span> {
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">new</span> <span class="op">=</span> <span class="ident"><span class="self">Self</span>::default</span>();
<span class="ident">new</span>.<span class="number">0</span>.<span class="ident">copy_from_slice</span>(<span class="kw-2">&amp;</span><span class="self">self</span>.<span class="number">0</span>);
<span class="ident">new</span>
}
}
<span class="kw">impl</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span> <span class="ident">fmt::Debug</span> <span class="kw">for</span> <span class="ident">Array64</span><span class="op">&lt;</span><span class="ident">T</span><span class="op">&gt;</span> {
<span class="kw">fn</span> <span class="ident">fmt</span>(<span class="kw-2">&amp;</span><span class="self">self</span>, <span class="ident">f</span>: <span class="kw-2">&amp;mut</span> <span class="ident">fmt::Formatter</span>) -&gt; <span class="ident">fmt::Result</span> {
<span class="macro">write!</span>(<span class="ident">f</span>, <span class="string">&quot;Array64 {{}}&quot;</span>)
}
}
<span class="macro">macro_rules!</span> <span class="ident">chacha_impl</span> {
(<span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore</span>:<span class="ident">ident</span>, <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span>:<span class="ident">ident</span>, <span class="macro-nonterminal">$</span><span class="macro-nonterminal">rounds</span>:<span class="ident">expr</span>, <span class="macro-nonterminal">$</span><span class="macro-nonterminal">doc</span>:<span class="ident">expr</span>, <span class="macro-nonterminal">$</span><span class="macro-nonterminal">abst</span>:<span class="ident">ident</span>) =&gt; {
<span class="attribute">#[<span class="ident">doc</span><span class="op">=</span><span class="macro-nonterminal">$</span><span class="macro-nonterminal">doc</span>]</span>
<span class="attribute">#[<span class="ident">derive</span>(<span class="ident">Clone</span>, <span class="ident">PartialEq</span>, <span class="ident">Eq</span>)]</span>
<span class="kw">pub</span> <span class="kw">struct</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore</span> {
<span class="ident">state</span>: <span class="ident">ChaCha</span>,
}
<span class="comment">// Custom Debug implementation that does not expose the internal state</span>
<span class="kw">impl</span> <span class="ident">fmt::Debug</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore</span> {
<span class="kw">fn</span> <span class="ident">fmt</span>(<span class="kw-2">&amp;</span><span class="self">self</span>, <span class="ident">f</span>: <span class="kw-2">&amp;mut</span> <span class="ident">fmt::Formatter</span>) -&gt; <span class="ident">fmt::Result</span> {
<span class="macro">write!</span>(<span class="ident">f</span>, <span class="string">&quot;ChaChaXCore {{}}&quot;</span>)
}
}
<span class="kw">impl</span> <span class="ident">BlockRngCore</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore</span> {
<span class="kw">type</span> <span class="ident">Item</span> <span class="op">=</span> <span class="ident">u32</span>;
<span class="kw">type</span> <span class="ident">Results</span> <span class="op">=</span> <span class="ident">Array64</span><span class="op">&lt;</span><span class="ident">u32</span><span class="op">&gt;</span>;
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">fn</span> <span class="ident">generate</span>(<span class="kw-2">&amp;mut</span> <span class="self">self</span>, <span class="ident">r</span>: <span class="kw-2">&amp;mut</span> <span class="ident"><span class="self">Self</span>::Results</span>) {
<span class="self">self</span>.<span class="ident">state</span>.<span class="ident">refill4</span>(<span class="macro-nonterminal">$</span><span class="macro-nonterminal">rounds</span>, <span class="kw-2">&amp;mut</span> <span class="ident">r</span>.<span class="number">0</span>);
}
}
<span class="kw">impl</span> <span class="ident">SeedableRng</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore</span> {
<span class="kw">type</span> <span class="ident">Seed</span> <span class="op">=</span> [<span class="ident">u8</span>; <span class="number">32</span>];
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">fn</span> <span class="ident">from_seed</span>(<span class="ident">seed</span>: <span class="ident"><span class="self">Self</span>::Seed</span>) -&gt; <span class="self">Self</span> {
<span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore</span> { <span class="ident">state</span>: <span class="ident">ChaCha::new</span>(<span class="kw-2">&amp;</span><span class="ident">seed</span>, <span class="kw-2">&amp;</span>[<span class="number">0u8</span>; <span class="number">8</span>]) }
}
}
<span class="kw">impl</span> <span class="ident">CryptoRng</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore</span> {}
<span class="doccomment">/// A cryptographically secure random number generator that uses the ChaCha algorithm.</span>
<span class="doccomment">///</span>
<span class="doccomment">/// ChaCha is a stream cipher designed by Daniel J. Bernstein[^1], that we use as an RNG. It is</span>
<span class="doccomment">/// an improved variant of the Salsa20 cipher family, which was selected as one of the &quot;stream</span>
<span class="doccomment">/// ciphers suitable for widespread adoption&quot; by eSTREAM[^2].</span>
<span class="doccomment">///</span>
<span class="doccomment">/// ChaCha uses add-rotate-xor (ARX) operations as its basis. These are safe against timing</span>
<span class="doccomment">/// attacks, although that is mostly a concern for ciphers and not for RNGs. We provide a SIMD</span>
<span class="doccomment">/// implementation to support high throughput on a variety of common hardware platforms.</span>
<span class="doccomment">///</span>
<span class="doccomment">/// With the ChaCha algorithm it is possible to choose the number of rounds the core algorithm</span>
<span class="doccomment">/// should run. The number of rounds is a tradeoff between performance and security, where 8</span>
<span class="doccomment">/// rounds is the minimum potentially secure configuration, and 20 rounds is widely used as a</span>
<span class="doccomment">/// conservative choice.</span>
<span class="doccomment">///</span>
<span class="doccomment">/// We use a 64-bit counter and 64-bit stream identifier as in Bernstein&#39;s implementation[^1]</span>
<span class="doccomment">/// except that we use a stream identifier in place of a nonce. A 64-bit counter over 64-byte</span>
<span class="doccomment">/// (16 word) blocks allows 1 ZiB of output before cycling, and the stream identifier allows</span>
<span class="doccomment">/// 2&lt;sup&gt;64&lt;/sup&gt; unique streams of output per seed. Both counter and stream are initialized</span>
<span class="doccomment">/// to zero but may be set via the `set_word_pos` and `set_stream` methods.</span>
<span class="doccomment">///</span>
<span class="doccomment">/// The word layout is:</span>
<span class="doccomment">///</span>
<span class="doccomment">/// ```text</span>
<span class="doccomment">/// constant constant constant constant</span>
<span class="doccomment">/// seed seed seed seed</span>
<span class="doccomment">/// seed seed seed seed</span>
<span class="doccomment">/// counter counter stream_id stream_id</span>
<span class="doccomment">/// ```</span>
<span class="doccomment">///</span>
<span class="doccomment">/// This implementation uses an output buffer of sixteen `u32` words, and uses</span>
<span class="doccomment">/// [`BlockRng`] to implement the [`RngCore`] methods.</span>
<span class="doccomment">///</span>
<span class="doccomment">/// [^1]: D. J. Bernstein, [*ChaCha, a variant of Salsa20*](</span>
<span class="doccomment">/// https://cr.yp.to/chacha.html)</span>
<span class="doccomment">///</span>
<span class="doccomment">/// [^2]: [eSTREAM: the ECRYPT Stream Cipher Project](</span>
<span class="doccomment">/// http://www.ecrypt.eu.org/stream/)</span>
<span class="attribute">#[<span class="ident">derive</span>(<span class="ident">Clone</span>, <span class="ident">Debug</span>)]</span>
<span class="kw">pub</span> <span class="kw">struct</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="ident">rng</span>: <span class="ident">BlockRng</span><span class="op">&lt;</span><span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore</span><span class="op">&gt;</span>,
}
<span class="kw">impl</span> <span class="ident">SeedableRng</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="kw">type</span> <span class="ident">Seed</span> <span class="op">=</span> [<span class="ident">u8</span>; <span class="number">32</span>];
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">fn</span> <span class="ident">from_seed</span>(<span class="ident">seed</span>: <span class="ident"><span class="self">Self</span>::Seed</span>) -&gt; <span class="self">Self</span> {
<span class="kw">let</span> <span class="ident">core</span> <span class="op">=</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore::from_seed</span>(<span class="ident">seed</span>);
<span class="self">Self</span> {
<span class="ident">rng</span>: <span class="ident">BlockRng::new</span>(<span class="ident">core</span>),
}
}
}
<span class="kw">impl</span> <span class="ident">RngCore</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">fn</span> <span class="ident">next_u32</span>(<span class="kw-2">&amp;mut</span> <span class="self">self</span>) -&gt; <span class="ident">u32</span> {
<span class="self">self</span>.<span class="ident">rng</span>.<span class="ident">next_u32</span>()
}
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">fn</span> <span class="ident">next_u64</span>(<span class="kw-2">&amp;mut</span> <span class="self">self</span>) -&gt; <span class="ident">u64</span> {
<span class="self">self</span>.<span class="ident">rng</span>.<span class="ident">next_u64</span>()
}
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">fn</span> <span class="ident">fill_bytes</span>(<span class="kw-2">&amp;mut</span> <span class="self">self</span>, <span class="ident">bytes</span>: <span class="kw-2">&amp;mut</span> [<span class="ident">u8</span>]) {
<span class="self">self</span>.<span class="ident">rng</span>.<span class="ident">fill_bytes</span>(<span class="ident">bytes</span>)
}
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">fn</span> <span class="ident">try_fill_bytes</span>(<span class="kw-2">&amp;mut</span> <span class="self">self</span>, <span class="ident">bytes</span>: <span class="kw-2">&amp;mut</span> [<span class="ident">u8</span>]) -&gt; <span class="prelude-ty">Result</span><span class="op">&lt;</span>(), <span class="ident">Error</span><span class="op">&gt;</span> {
<span class="self">self</span>.<span class="ident">rng</span>.<span class="ident">try_fill_bytes</span>(<span class="ident">bytes</span>)
}
}
<span class="kw">impl</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="comment">// The buffer is a 4-block window, i.e. it is always at a block-aligned position in the</span>
<span class="comment">// stream but if the stream has been sought it may not be self-aligned.</span>
<span class="doccomment">/// Get the offset from the start of the stream, in 32-bit words.</span>
<span class="doccomment">///</span>
<span class="doccomment">/// Since the generated blocks are 16 words (2&lt;sup&gt;4&lt;/sup&gt;) long and the</span>
<span class="doccomment">/// counter is 64-bits, the offset is a 68-bit number. Sub-word offsets are</span>
<span class="doccomment">/// not supported, hence the result can simply be multiplied by 4 to get a</span>
<span class="doccomment">/// byte-offset.</span>
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">pub</span> <span class="kw">fn</span> <span class="ident">get_word_pos</span>(<span class="kw-2">&amp;</span><span class="self">self</span>) -&gt; <span class="ident">u128</span> {
<span class="kw">let</span> <span class="ident">buf_start_block</span> <span class="op">=</span> {
<span class="kw">let</span> <span class="ident">buf_end_block</span> <span class="op">=</span> <span class="self">self</span>.<span class="ident">rng</span>.<span class="ident">core</span>.<span class="ident">state</span>.<span class="ident">get_block_pos</span>();
<span class="ident">u64::wrapping_sub</span>(<span class="ident">buf_end_block</span>, <span class="ident">BUF_BLOCKS</span>.<span class="ident">into</span>())
};
<span class="kw">let</span> (<span class="ident">buf_offset_blocks</span>, <span class="ident">block_offset_words</span>) <span class="op">=</span> {
<span class="kw">let</span> <span class="ident">buf_offset_words</span> <span class="op">=</span> <span class="self">self</span>.<span class="ident">rng</span>.<span class="ident">index</span>() <span class="kw">as</span> <span class="ident">u64</span>;
<span class="kw">let</span> <span class="ident">blocks_part</span> <span class="op">=</span> <span class="ident">buf_offset_words</span> <span class="op">/</span> <span class="ident">u64::from</span>(<span class="ident">BLOCK_WORDS</span>);
<span class="kw">let</span> <span class="ident">words_part</span> <span class="op">=</span> <span class="ident">buf_offset_words</span> <span class="op">%</span> <span class="ident">u64::from</span>(<span class="ident">BLOCK_WORDS</span>);
(<span class="ident">blocks_part</span>, <span class="ident">words_part</span>)
};
<span class="kw">let</span> <span class="ident">pos_block</span> <span class="op">=</span> <span class="ident">u64::wrapping_add</span>(<span class="ident">buf_start_block</span>, <span class="ident">buf_offset_blocks</span>);
<span class="kw">let</span> <span class="ident">pos_block_words</span> <span class="op">=</span> <span class="ident">u128::from</span>(<span class="ident">pos_block</span>) <span class="op">*</span> <span class="ident">u128::from</span>(<span class="ident">BLOCK_WORDS</span>);
<span class="ident">pos_block_words</span> <span class="op">+</span> <span class="ident">u128::from</span>(<span class="ident">block_offset_words</span>)
}
<span class="doccomment">/// Set the offset from the start of the stream, in 32-bit words.</span>
<span class="doccomment">///</span>
<span class="doccomment">/// As with `get_word_pos`, we use a 68-bit number. Since the generator</span>
<span class="doccomment">/// simply cycles at the end of its period (1 ZiB), we ignore the upper</span>
<span class="doccomment">/// 60 bits.</span>
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">pub</span> <span class="kw">fn</span> <span class="ident">set_word_pos</span>(<span class="kw-2">&amp;mut</span> <span class="self">self</span>, <span class="ident">word_offset</span>: <span class="ident">u128</span>) {
<span class="kw">let</span> <span class="ident">block</span> <span class="op">=</span> (<span class="ident">word_offset</span> <span class="op">/</span> <span class="ident">u128::from</span>(<span class="ident">BLOCK_WORDS</span>)) <span class="kw">as</span> <span class="ident">u64</span>;
<span class="self">self</span>.<span class="ident">rng</span>
.<span class="ident">core</span>
.<span class="ident">state</span>
.<span class="ident">set_block_pos</span>(<span class="ident">block</span>);
<span class="self">self</span>.<span class="ident">rng</span>.<span class="ident">generate_and_set</span>((<span class="ident">word_offset</span> <span class="op">%</span> <span class="ident">u128::from</span>(<span class="ident">BLOCK_WORDS</span>)) <span class="kw">as</span> <span class="ident">usize</span>);
}
<span class="doccomment">/// Set the stream number.</span>
<span class="doccomment">///</span>
<span class="doccomment">/// This is initialized to zero; 2&lt;sup&gt;64&lt;/sup&gt; unique streams of output</span>
<span class="doccomment">/// are available per seed/key.</span>
<span class="doccomment">///</span>
<span class="doccomment">/// Note that in order to reproduce ChaCha output with a specific 64-bit</span>
<span class="doccomment">/// nonce, one can convert that nonce to a `u64` in little-endian fashion</span>
<span class="doccomment">/// and pass to this function. In theory a 96-bit nonce can be used by</span>
<span class="doccomment">/// passing the last 64-bits to this function and using the first 32-bits as</span>
<span class="doccomment">/// the most significant half of the 64-bit counter (which may be set</span>
<span class="doccomment">/// indirectly via `set_word_pos`), but this is not directly supported.</span>
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">pub</span> <span class="kw">fn</span> <span class="ident">set_stream</span>(<span class="kw-2">&amp;mut</span> <span class="self">self</span>, <span class="ident">stream</span>: <span class="ident">u64</span>) {
<span class="self">self</span>.<span class="ident">rng</span>
.<span class="ident">core</span>
.<span class="ident">state</span>
.<span class="ident">set_nonce</span>(<span class="ident">stream</span>);
<span class="kw">if</span> <span class="self">self</span>.<span class="ident">rng</span>.<span class="ident">index</span>() <span class="op">!</span><span class="op">=</span> <span class="number">64</span> {
<span class="kw">let</span> <span class="ident">wp</span> <span class="op">=</span> <span class="self">self</span>.<span class="ident">get_word_pos</span>();
<span class="self">self</span>.<span class="ident">set_word_pos</span>(<span class="ident">wp</span>);
}
}
<span class="doccomment">/// Get the stream number.</span>
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">pub</span> <span class="kw">fn</span> <span class="ident">get_stream</span>(<span class="kw-2">&amp;</span><span class="self">self</span>) -&gt; <span class="ident">u64</span> {
<span class="self">self</span>.<span class="ident">rng</span>
.<span class="ident">core</span>
.<span class="ident">state</span>
.<span class="ident">get_nonce</span>()
}
<span class="doccomment">/// Get the seed.</span>
<span class="attribute">#[<span class="ident">inline</span>]</span>
<span class="kw">pub</span> <span class="kw">fn</span> <span class="ident">get_seed</span>(<span class="kw-2">&amp;</span><span class="self">self</span>) -&gt; [<span class="ident">u8</span>; <span class="number">32</span>] {
<span class="self">self</span>.<span class="ident">rng</span>
.<span class="ident">core</span>
.<span class="ident">state</span>
.<span class="ident">get_seed</span>()
}
}
<span class="kw">impl</span> <span class="ident">CryptoRng</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {}
<span class="kw">impl</span> <span class="ident">From</span><span class="op">&lt;</span><span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore</span><span class="op">&gt;</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="kw">fn</span> <span class="ident">from</span>(<span class="ident">core</span>: <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXCore</span>) -&gt; <span class="self">Self</span> {
<span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="ident">rng</span>: <span class="ident">BlockRng::new</span>(<span class="ident">core</span>),
}
}
}
<span class="kw">impl</span> <span class="ident">PartialEq</span><span class="op">&lt;</span><span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span><span class="op">&gt;</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="kw">fn</span> <span class="ident">eq</span>(<span class="kw-2">&amp;</span><span class="self">self</span>, <span class="ident">rhs</span>: <span class="kw-2">&amp;</span><span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span>) -&gt; <span class="ident">bool</span> {
<span class="kw">let</span> <span class="ident">a</span>: <span class="macro-nonterminal">$</span><span class="macro-nonterminal">abst</span>::<span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> <span class="op">=</span> <span class="self">self</span>.<span class="ident">into</span>();
<span class="kw">let</span> <span class="ident">b</span>: <span class="macro-nonterminal">$</span><span class="macro-nonterminal">abst</span>::<span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> <span class="op">=</span> <span class="ident">rhs</span>.<span class="ident">into</span>();
<span class="ident">a</span> <span class="op">==</span> <span class="ident">b</span>
}
}
<span class="kw">impl</span> <span class="ident">Eq</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {}
<span class="attribute">#[<span class="ident">cfg</span>(<span class="ident">feature</span> <span class="op">=</span> <span class="string">&quot;serde1&quot;</span>)]</span>
<span class="kw">impl</span> <span class="ident">Serialize</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="kw">fn</span> <span class="ident">serialize</span><span class="op">&lt;</span><span class="ident">S</span><span class="op">&gt;</span>(<span class="kw-2">&amp;</span><span class="self">self</span>, <span class="ident">s</span>: <span class="ident">S</span>) -&gt; <span class="prelude-ty">Result</span><span class="op">&lt;</span><span class="ident">S::Ok</span>, <span class="ident">S::Error</span><span class="op">&gt;</span>
<span class="kw">where</span> <span class="ident">S</span>: <span class="ident">Serializer</span> {
<span class="macro-nonterminal">$</span><span class="macro-nonterminal">abst</span>::<span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng::from</span>(<span class="self">self</span>).<span class="ident">serialize</span>(<span class="ident">s</span>)
}
}
<span class="attribute">#[<span class="ident">cfg</span>(<span class="ident">feature</span> <span class="op">=</span> <span class="string">&quot;serde1&quot;</span>)]</span>
<span class="kw">impl</span><span class="op">&lt;</span><span class="lifetime">&#39;de</span><span class="op">&gt;</span> <span class="ident">Deserialize</span><span class="op">&lt;</span><span class="lifetime">&#39;de</span><span class="op">&gt;</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="kw">fn</span> <span class="ident">deserialize</span><span class="op">&lt;</span><span class="ident">D</span><span class="op">&gt;</span>(<span class="ident">d</span>: <span class="ident">D</span>) -&gt; <span class="prelude-ty">Result</span><span class="op">&lt;</span><span class="self">Self</span>, <span class="ident">D::Error</span><span class="op">&gt;</span> <span class="kw">where</span> <span class="ident">D</span>: <span class="ident">Deserializer</span><span class="op">&lt;</span><span class="lifetime">&#39;de</span><span class="op">&gt;</span> {
<span class="macro-nonterminal">$</span><span class="macro-nonterminal">abst</span>::<span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng::deserialize</span>(<span class="ident">d</span>).<span class="ident">map</span>(<span class="op">|</span><span class="ident">x</span><span class="op">|</span> <span class="ident"><span class="self">Self</span>::from</span>(<span class="kw-2">&amp;</span><span class="ident">x</span>))
}
}
<span class="kw">mod</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">abst</span> {
<span class="attribute">#[<span class="ident">cfg</span>(<span class="ident">feature</span> <span class="op">=</span> <span class="string">&quot;serde1&quot;</span>)]</span> <span class="kw">use</span> <span class="ident">serde</span>::{<span class="ident">Serialize</span>, <span class="ident">Deserialize</span>};
<span class="comment">// The abstract state of a ChaCha stream, independent of implementation choices. The</span>
<span class="comment">// comparison and serialization of this object is considered a semver-covered part of</span>
<span class="comment">// the API.</span>
<span class="attribute">#[<span class="ident">derive</span>(<span class="ident">Debug</span>, <span class="ident">PartialEq</span>, <span class="ident">Eq</span>)]</span>
<span class="attribute">#[<span class="ident">cfg_attr</span>(
<span class="ident">feature</span> <span class="op">=</span> <span class="string">&quot;serde1&quot;</span>,
<span class="ident">derive</span>(<span class="ident">Serialize</span>, <span class="ident">Deserialize</span>),
)]</span>
<span class="kw">pub</span>(<span class="kw">crate</span>) <span class="kw">struct</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="ident">seed</span>: [<span class="ident">u8</span>; <span class="number">32</span>],
<span class="ident">stream</span>: <span class="ident">u64</span>,
<span class="ident">word_pos</span>: <span class="ident">u128</span>,
}
<span class="kw">impl</span> <span class="ident">From</span><span class="op">&lt;</span><span class="kw-2">&amp;</span><span class="kw">super</span>::<span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span><span class="op">&gt;</span> <span class="kw">for</span> <span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="comment">// Forget all information about the input except what is necessary to determine the</span>
<span class="comment">// outputs of any sequence of pub API calls.</span>
<span class="kw">fn</span> <span class="ident">from</span>(<span class="ident">r</span>: <span class="kw-2">&amp;</span><span class="kw">super</span>::<span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span>) -&gt; <span class="self">Self</span> {
<span class="self">Self</span> {
<span class="ident">seed</span>: <span class="ident">r</span>.<span class="ident">get_seed</span>(),
<span class="ident">stream</span>: <span class="ident">r</span>.<span class="ident">get_stream</span>(),
<span class="ident">word_pos</span>: <span class="ident">r</span>.<span class="ident">get_word_pos</span>(),
}
}
}
<span class="kw">impl</span> <span class="ident">From</span><span class="op">&lt;</span><span class="kw-2">&amp;</span><span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span><span class="op">&gt;</span> <span class="kw">for</span> <span class="kw">super</span>::<span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span> {
<span class="comment">// Construct one of the possible concrete RNGs realizing an abstract state.</span>
<span class="kw">fn</span> <span class="ident">from</span>(<span class="ident">a</span>: <span class="kw-2">&amp;</span><span class="macro-nonterminal">$</span><span class="macro-nonterminal">ChaChaXRng</span>) -&gt; <span class="self">Self</span> {
<span class="kw">use</span> <span class="ident">rand_core::SeedableRng</span>;
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">r</span> <span class="op">=</span> <span class="ident"><span class="self">Self</span>::from_seed</span>(<span class="ident">a</span>.<span class="ident">seed</span>);
<span class="ident">r</span>.<span class="ident">set_stream</span>(<span class="ident">a</span>.<span class="ident">stream</span>);
<span class="ident">r</span>.<span class="ident">set_word_pos</span>(<span class="ident">a</span>.<span class="ident">word_pos</span>);
<span class="ident">r</span>
}
}
}
}
}
<span class="macro">chacha_impl!</span>(<span class="ident">ChaCha20Core</span>, <span class="ident">ChaCha20Rng</span>, <span class="number">10</span>, <span class="string">&quot;ChaCha with 20 rounds&quot;</span>, <span class="ident">abstract20</span>);
<span class="macro">chacha_impl!</span>(<span class="ident">ChaCha12Core</span>, <span class="ident">ChaCha12Rng</span>, <span class="number">6</span>, <span class="string">&quot;ChaCha with 12 rounds&quot;</span>, <span class="ident">abstract12</span>);
<span class="macro">chacha_impl!</span>(<span class="ident">ChaCha8Core</span>, <span class="ident">ChaCha8Rng</span>, <span class="number">4</span>, <span class="string">&quot;ChaCha with 8 rounds&quot;</span>, <span class="ident">abstract8</span>);
<span class="attribute">#[<span class="ident">cfg</span>(<span class="ident">test</span>)]</span>
<span class="kw">mod</span> <span class="ident">test</span> {
<span class="kw">use</span> <span class="ident">rand_core</span>::{<span class="ident">RngCore</span>, <span class="ident">SeedableRng</span>};
<span class="attribute">#[<span class="ident">cfg</span>(<span class="ident">feature</span> <span class="op">=</span> <span class="string">&quot;serde1&quot;</span>)]</span> <span class="kw">use</span> <span class="kw">super</span>::{<span class="ident">ChaCha20Rng</span>, <span class="ident">ChaCha12Rng</span>, <span class="ident">ChaCha8Rng</span>};
<span class="kw">type</span> <span class="ident">ChaChaRng</span> <span class="op">=</span> <span class="ident"><span class="kw">super</span>::ChaCha20Rng</span>;
<span class="attribute">#[<span class="ident">cfg</span>(<span class="ident">feature</span> <span class="op">=</span> <span class="string">&quot;serde1&quot;</span>)]</span>
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_serde_roundtrip</span>() {
<span class="kw">let</span> <span class="ident">seed</span> <span class="op">=</span> [
<span class="number">1</span>, <span class="number">0</span>, <span class="number">52</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">1</span>, <span class="number">0</span>, <span class="number">10</span>, <span class="number">0</span>, <span class="number">22</span>, <span class="number">32</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">2</span>, <span class="number">0</span>, <span class="number">55</span>, <span class="number">49</span>, <span class="number">0</span>, <span class="number">11</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">3</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>,
<span class="number">0</span>, <span class="number">2</span>, <span class="number">92</span>,
];
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng1</span> <span class="op">=</span> <span class="ident">ChaCha20Rng::from_seed</span>(<span class="ident">seed</span>);
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng2</span> <span class="op">=</span> <span class="ident">ChaCha12Rng::from_seed</span>(<span class="ident">seed</span>);
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng3</span> <span class="op">=</span> <span class="ident">ChaCha8Rng::from_seed</span>(<span class="ident">seed</span>);
<span class="kw">let</span> <span class="ident">encoded1</span> <span class="op">=</span> <span class="ident">serde_json::to_string</span>(<span class="kw-2">&amp;</span><span class="ident">rng1</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="ident">encoded2</span> <span class="op">=</span> <span class="ident">serde_json::to_string</span>(<span class="kw-2">&amp;</span><span class="ident">rng2</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="ident">encoded3</span> <span class="op">=</span> <span class="ident">serde_json::to_string</span>(<span class="kw-2">&amp;</span><span class="ident">rng3</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">decoded1</span>: <span class="ident">ChaCha20Rng</span> <span class="op">=</span> <span class="ident">serde_json::from_str</span>(<span class="kw-2">&amp;</span><span class="ident">encoded1</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">decoded2</span>: <span class="ident">ChaCha12Rng</span> <span class="op">=</span> <span class="ident">serde_json::from_str</span>(<span class="kw-2">&amp;</span><span class="ident">encoded2</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">decoded3</span>: <span class="ident">ChaCha8Rng</span> <span class="op">=</span> <span class="ident">serde_json::from_str</span>(<span class="kw-2">&amp;</span><span class="ident">encoded3</span>).<span class="ident">unwrap</span>();
<span class="macro">assert_eq!</span>(<span class="ident">rng1</span>, <span class="ident">decoded1</span>);
<span class="macro">assert_eq!</span>(<span class="ident">rng2</span>, <span class="ident">decoded2</span>);
<span class="macro">assert_eq!</span>(<span class="ident">rng3</span>, <span class="ident">decoded3</span>);
<span class="macro">assert_eq!</span>(<span class="ident">rng1</span>.<span class="ident">next_u32</span>(), <span class="ident">decoded1</span>.<span class="ident">next_u32</span>());
<span class="macro">assert_eq!</span>(<span class="ident">rng2</span>.<span class="ident">next_u32</span>(), <span class="ident">decoded2</span>.<span class="ident">next_u32</span>());
<span class="macro">assert_eq!</span>(<span class="ident">rng3</span>.<span class="ident">next_u32</span>(), <span class="ident">decoded3</span>.<span class="ident">next_u32</span>());
}
<span class="comment">// This test validates that:</span>
<span class="comment">// 1. a hard-coded serialization demonstrating the format at time of initial release can still</span>
<span class="comment">// be deserialized to a ChaChaRng</span>
<span class="comment">// 2. re-serializing the resultant object produces exactly the original string</span>
<span class="comment">//</span>
<span class="comment">// Condition 2 is stronger than necessary: an equivalent serialization (e.g. with field order</span>
<span class="comment">// permuted, or whitespace differences) would also be admissible, but would fail this test.</span>
<span class="comment">// However testing for equivalence of serialized data is difficult, and there shouldn&#39;t be any</span>
<span class="comment">// reason we need to violate the stronger-than-needed condition, e.g. by changing the field</span>
<span class="comment">// definition order.</span>
<span class="attribute">#[<span class="ident">cfg</span>(<span class="ident">feature</span> <span class="op">=</span> <span class="string">&quot;serde1&quot;</span>)]</span>
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_serde_format_stability</span>() {
<span class="kw">let</span> <span class="ident">j</span> <span class="op">=</span> <span class="string">r#&quot;{&quot;seed&quot;:[4,8,15,16,23,42,4,8,15,16,23,42,4,8,15,16,23,42,4,8,15,16,23,42,4,8,15,16,23,42,4,8],&quot;stream&quot;:27182818284,&quot;word_pos&quot;:314159265359}&quot;#</span>;
<span class="kw">let</span> <span class="ident">r</span>: <span class="ident">ChaChaRng</span> <span class="op">=</span> <span class="ident">serde_json::from_str</span>(<span class="kw-2">&amp;</span><span class="ident">j</span>).<span class="ident">unwrap</span>();
<span class="kw">let</span> <span class="ident">j1</span> <span class="op">=</span> <span class="ident">serde_json::to_string</span>(<span class="kw-2">&amp;</span><span class="ident">r</span>).<span class="ident">unwrap</span>();
<span class="macro">assert_eq!</span>(<span class="ident">j</span>, <span class="ident">j1</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_construction</span>() {
<span class="kw">let</span> <span class="ident">seed</span> <span class="op">=</span> [
<span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">1</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">2</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">3</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>,
<span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>,
];
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng1</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">seed</span>);
<span class="macro">assert_eq!</span>(<span class="ident">rng1</span>.<span class="ident">next_u32</span>(), <span class="number">137206642</span>);
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng2</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_rng</span>(<span class="ident">rng1</span>).<span class="ident">unwrap</span>();
<span class="macro">assert_eq!</span>(<span class="ident">rng2</span>.<span class="ident">next_u32</span>(), <span class="number">1325750369</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_true_values_a</span>() {
<span class="comment">// Test vectors 1 and 2 from</span>
<span class="comment">// https://tools.ietf.org/html/draft-nir-cfrg-chacha20-poly1305-04</span>
<span class="kw">let</span> <span class="ident">seed</span> <span class="op">=</span> [<span class="number">0u8</span>; <span class="number">32</span>];
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">seed</span>);
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">results</span> <span class="op">=</span> [<span class="number">0u32</span>; <span class="number">16</span>];
<span class="kw">for</span> <span class="ident">i</span> <span class="kw">in</span> <span class="ident">results</span>.<span class="ident">iter_mut</span>() {
<span class="kw-2">*</span><span class="ident">i</span> <span class="op">=</span> <span class="ident">rng</span>.<span class="ident">next_u32</span>();
}
<span class="kw">let</span> <span class="ident">expected</span> <span class="op">=</span> [
<span class="number">0xade0b876</span>, <span class="number">0x903df1a0</span>, <span class="number">0xe56a5d40</span>, <span class="number">0x28bd8653</span>, <span class="number">0xb819d2bd</span>, <span class="number">0x1aed8da0</span>, <span class="number">0xccef36a8</span>,
<span class="number">0xc70d778b</span>, <span class="number">0x7c5941da</span>, <span class="number">0x8d485751</span>, <span class="number">0x3fe02477</span>, <span class="number">0x374ad8b8</span>, <span class="number">0xf4b8436a</span>, <span class="number">0x1ca11815</span>,
<span class="number">0x69b687c3</span>, <span class="number">0x8665eeb2</span>,
];
<span class="macro">assert_eq!</span>(<span class="ident">results</span>, <span class="ident">expected</span>);
<span class="kw">for</span> <span class="ident">i</span> <span class="kw">in</span> <span class="ident">results</span>.<span class="ident">iter_mut</span>() {
<span class="kw-2">*</span><span class="ident">i</span> <span class="op">=</span> <span class="ident">rng</span>.<span class="ident">next_u32</span>();
}
<span class="kw">let</span> <span class="ident">expected</span> <span class="op">=</span> [
<span class="number">0xbee7079f</span>, <span class="number">0x7a385155</span>, <span class="number">0x7c97ba98</span>, <span class="number">0x0d082d73</span>, <span class="number">0xa0290fcb</span>, <span class="number">0x6965e348</span>, <span class="number">0x3e53c612</span>,
<span class="number">0xed7aee32</span>, <span class="number">0x7621b729</span>, <span class="number">0x434ee69c</span>, <span class="number">0xb03371d5</span>, <span class="number">0xd539d874</span>, <span class="number">0x281fed31</span>, <span class="number">0x45fb0a51</span>,
<span class="number">0x1f0ae1ac</span>, <span class="number">0x6f4d794b</span>,
];
<span class="macro">assert_eq!</span>(<span class="ident">results</span>, <span class="ident">expected</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_true_values_b</span>() {
<span class="comment">// Test vector 3 from</span>
<span class="comment">// https://tools.ietf.org/html/draft-nir-cfrg-chacha20-poly1305-04</span>
<span class="kw">let</span> <span class="ident">seed</span> <span class="op">=</span> [
<span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>,
<span class="number">0</span>, <span class="number">0</span>, <span class="number">1</span>,
];
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">seed</span>);
<span class="comment">// Skip block 0</span>
<span class="kw">for</span> <span class="kw">_</span> <span class="kw">in</span> <span class="number">0</span>..<span class="number">16</span> {
<span class="ident">rng</span>.<span class="ident">next_u32</span>();
}
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">results</span> <span class="op">=</span> [<span class="number">0u32</span>; <span class="number">16</span>];
<span class="kw">for</span> <span class="ident">i</span> <span class="kw">in</span> <span class="ident">results</span>.<span class="ident">iter_mut</span>() {
<span class="kw-2">*</span><span class="ident">i</span> <span class="op">=</span> <span class="ident">rng</span>.<span class="ident">next_u32</span>();
}
<span class="kw">let</span> <span class="ident">expected</span> <span class="op">=</span> [
<span class="number">0x2452eb3a</span>, <span class="number">0x9249f8ec</span>, <span class="number">0x8d829d9b</span>, <span class="number">0xddd4ceb1</span>, <span class="number">0xe8252083</span>, <span class="number">0x60818b01</span>, <span class="number">0xf38422b8</span>,
<span class="number">0x5aaa49c9</span>, <span class="number">0xbb00ca8e</span>, <span class="number">0xda3ba7b4</span>, <span class="number">0xc4b592d1</span>, <span class="number">0xfdf2732f</span>, <span class="number">0x4436274e</span>, <span class="number">0x2561b3c8</span>,
<span class="number">0xebdd4aa6</span>, <span class="number">0xa0136c00</span>,
];
<span class="macro">assert_eq!</span>(<span class="ident">results</span>, <span class="ident">expected</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_true_values_c</span>() {
<span class="comment">// Test vector 4 from</span>
<span class="comment">// https://tools.ietf.org/html/draft-nir-cfrg-chacha20-poly1305-04</span>
<span class="kw">let</span> <span class="ident">seed</span> <span class="op">=</span> [
<span class="number">0</span>, <span class="number">0xff</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>,
<span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>,
];
<span class="kw">let</span> <span class="ident">expected</span> <span class="op">=</span> [
<span class="number">0xfb4dd572</span>, <span class="number">0x4bc42ef1</span>, <span class="number">0xdf922636</span>, <span class="number">0x327f1394</span>, <span class="number">0xa78dea8f</span>, <span class="number">0x5e269039</span>, <span class="number">0xa1bebbc1</span>,
<span class="number">0xcaf09aae</span>, <span class="number">0xa25ab213</span>, <span class="number">0x48a6b46c</span>, <span class="number">0x1b9d9bcb</span>, <span class="number">0x092c5be6</span>, <span class="number">0x546ca624</span>, <span class="number">0x1bec45d5</span>,
<span class="number">0x87f47473</span>, <span class="number">0x96f0992e</span>,
];
<span class="kw">let</span> <span class="ident">expected_end</span> <span class="op">=</span> <span class="number">3</span> <span class="op">*</span> <span class="number">16</span>;
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">results</span> <span class="op">=</span> [<span class="number">0u32</span>; <span class="number">16</span>];
<span class="comment">// Test block 2 by skipping block 0 and 1</span>
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng1</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">seed</span>);
<span class="kw">for</span> <span class="kw">_</span> <span class="kw">in</span> <span class="number">0</span>..<span class="number">32</span> {
<span class="ident">rng1</span>.<span class="ident">next_u32</span>();
}
<span class="kw">for</span> <span class="ident">i</span> <span class="kw">in</span> <span class="ident">results</span>.<span class="ident">iter_mut</span>() {
<span class="kw-2">*</span><span class="ident">i</span> <span class="op">=</span> <span class="ident">rng1</span>.<span class="ident">next_u32</span>();
}
<span class="macro">assert_eq!</span>(<span class="ident">results</span>, <span class="ident">expected</span>);
<span class="macro">assert_eq!</span>(<span class="ident">rng1</span>.<span class="ident">get_word_pos</span>(), <span class="ident">expected_end</span>);
<span class="comment">// Test block 2 by using `set_word_pos`</span>
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng2</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">seed</span>);
<span class="ident">rng2</span>.<span class="ident">set_word_pos</span>(<span class="number">2</span> <span class="op">*</span> <span class="number">16</span>);
<span class="kw">for</span> <span class="ident">i</span> <span class="kw">in</span> <span class="ident">results</span>.<span class="ident">iter_mut</span>() {
<span class="kw-2">*</span><span class="ident">i</span> <span class="op">=</span> <span class="ident">rng2</span>.<span class="ident">next_u32</span>();
}
<span class="macro">assert_eq!</span>(<span class="ident">results</span>, <span class="ident">expected</span>);
<span class="macro">assert_eq!</span>(<span class="ident">rng2</span>.<span class="ident">get_word_pos</span>(), <span class="ident">expected_end</span>);
<span class="comment">// Test skipping behaviour with other types</span>
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">buf</span> <span class="op">=</span> [<span class="number">0u8</span>; <span class="number">32</span>];
<span class="ident">rng2</span>.<span class="ident">fill_bytes</span>(<span class="kw-2">&amp;mut</span> <span class="ident">buf</span>[..]);
<span class="macro">assert_eq!</span>(<span class="ident">rng2</span>.<span class="ident">get_word_pos</span>(), <span class="ident">expected_end</span> <span class="op">+</span> <span class="number">8</span>);
<span class="ident">rng2</span>.<span class="ident">fill_bytes</span>(<span class="kw-2">&amp;mut</span> <span class="ident">buf</span>[<span class="number">0</span>..<span class="number">25</span>]);
<span class="macro">assert_eq!</span>(<span class="ident">rng2</span>.<span class="ident">get_word_pos</span>(), <span class="ident">expected_end</span> <span class="op">+</span> <span class="number">15</span>);
<span class="ident">rng2</span>.<span class="ident">next_u64</span>();
<span class="macro">assert_eq!</span>(<span class="ident">rng2</span>.<span class="ident">get_word_pos</span>(), <span class="ident">expected_end</span> <span class="op">+</span> <span class="number">17</span>);
<span class="ident">rng2</span>.<span class="ident">next_u32</span>();
<span class="ident">rng2</span>.<span class="ident">next_u64</span>();
<span class="macro">assert_eq!</span>(<span class="ident">rng2</span>.<span class="ident">get_word_pos</span>(), <span class="ident">expected_end</span> <span class="op">+</span> <span class="number">20</span>);
<span class="ident">rng2</span>.<span class="ident">fill_bytes</span>(<span class="kw-2">&amp;mut</span> <span class="ident">buf</span>[<span class="number">0</span>..<span class="number">1</span>]);
<span class="macro">assert_eq!</span>(<span class="ident">rng2</span>.<span class="ident">get_word_pos</span>(), <span class="ident">expected_end</span> <span class="op">+</span> <span class="number">21</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_multiple_blocks</span>() {
<span class="kw">let</span> <span class="ident">seed</span> <span class="op">=</span> [
<span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">1</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">2</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">3</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">4</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">5</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">6</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">7</span>,
<span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>,
];
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">seed</span>);
<span class="comment">// Store the 17*i-th 32-bit word,</span>
<span class="comment">// i.e., the i-th word of the i-th 16-word block</span>
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">results</span> <span class="op">=</span> [<span class="number">0u32</span>; <span class="number">16</span>];
<span class="kw">for</span> <span class="ident">i</span> <span class="kw">in</span> <span class="ident">results</span>.<span class="ident">iter_mut</span>() {
<span class="kw-2">*</span><span class="ident">i</span> <span class="op">=</span> <span class="ident">rng</span>.<span class="ident">next_u32</span>();
<span class="kw">for</span> <span class="kw">_</span> <span class="kw">in</span> <span class="number">0</span>..<span class="number">16</span> {
<span class="ident">rng</span>.<span class="ident">next_u32</span>();
}
}
<span class="kw">let</span> <span class="ident">expected</span> <span class="op">=</span> [
<span class="number">0xf225c81a</span>, <span class="number">0x6ab1be57</span>, <span class="number">0x04d42951</span>, <span class="number">0x70858036</span>, <span class="number">0x49884684</span>, <span class="number">0x64efec72</span>, <span class="number">0x4be2d186</span>,
<span class="number">0x3615b384</span>, <span class="number">0x11cfa18e</span>, <span class="number">0xd3c50049</span>, <span class="number">0x75c775f6</span>, <span class="number">0x434c6530</span>, <span class="number">0x2c5bad8f</span>, <span class="number">0x898881dc</span>,
<span class="number">0x5f1c86d9</span>, <span class="number">0xc1f8e7f4</span>,
];
<span class="macro">assert_eq!</span>(<span class="ident">results</span>, <span class="ident">expected</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_true_bytes</span>() {
<span class="kw">let</span> <span class="ident">seed</span> <span class="op">=</span> [<span class="number">0u8</span>; <span class="number">32</span>];
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">seed</span>);
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">results</span> <span class="op">=</span> [<span class="number">0u8</span>; <span class="number">32</span>];
<span class="ident">rng</span>.<span class="ident">fill_bytes</span>(<span class="kw-2">&amp;mut</span> <span class="ident">results</span>);
<span class="kw">let</span> <span class="ident">expected</span> <span class="op">=</span> [
<span class="number">118</span>, <span class="number">184</span>, <span class="number">224</span>, <span class="number">173</span>, <span class="number">160</span>, <span class="number">241</span>, <span class="number">61</span>, <span class="number">144</span>, <span class="number">64</span>, <span class="number">93</span>, <span class="number">106</span>, <span class="number">229</span>, <span class="number">83</span>, <span class="number">134</span>, <span class="number">189</span>, <span class="number">40</span>, <span class="number">189</span>, <span class="number">210</span>,
<span class="number">25</span>, <span class="number">184</span>, <span class="number">160</span>, <span class="number">141</span>, <span class="number">237</span>, <span class="number">26</span>, <span class="number">168</span>, <span class="number">54</span>, <span class="number">239</span>, <span class="number">204</span>, <span class="number">139</span>, <span class="number">119</span>, <span class="number">13</span>, <span class="number">199</span>,
];
<span class="macro">assert_eq!</span>(<span class="ident">results</span>, <span class="ident">expected</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_nonce</span>() {
<span class="comment">// Test vector 5 from</span>
<span class="comment">// https://tools.ietf.org/html/draft-nir-cfrg-chacha20-poly1305-04</span>
<span class="comment">// Although we do not support setting a nonce, we try it here anyway so</span>
<span class="comment">// we can use this test vector.</span>
<span class="kw">let</span> <span class="ident">seed</span> <span class="op">=</span> [<span class="number">0u8</span>; <span class="number">32</span>];
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">seed</span>);
<span class="comment">// 96-bit nonce in LE order is: 0,0,0,0, 0,0,0,0, 0,0,0,2</span>
<span class="ident">rng</span>.<span class="ident">set_stream</span>(<span class="number">2u64</span> <span class="op">&lt;</span><span class="op">&lt;</span> (<span class="number">24</span> <span class="op">+</span> <span class="number">32</span>));
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">results</span> <span class="op">=</span> [<span class="number">0u32</span>; <span class="number">16</span>];
<span class="kw">for</span> <span class="ident">i</span> <span class="kw">in</span> <span class="ident">results</span>.<span class="ident">iter_mut</span>() {
<span class="kw-2">*</span><span class="ident">i</span> <span class="op">=</span> <span class="ident">rng</span>.<span class="ident">next_u32</span>();
}
<span class="kw">let</span> <span class="ident">expected</span> <span class="op">=</span> [
<span class="number">0x374dc6c2</span>, <span class="number">0x3736d58c</span>, <span class="number">0xb904e24a</span>, <span class="number">0xcd3f93ef</span>, <span class="number">0x88228b1a</span>, <span class="number">0x96a4dfb3</span>, <span class="number">0x5b76ab72</span>,
<span class="number">0xc727ee54</span>, <span class="number">0x0e0e978a</span>, <span class="number">0xf3145c95</span>, <span class="number">0x1b748ea8</span>, <span class="number">0xf786c297</span>, <span class="number">0x99c28f5f</span>, <span class="number">0x628314e8</span>,
<span class="number">0x398a19fa</span>, <span class="number">0x6ded1b53</span>,
];
<span class="macro">assert_eq!</span>(<span class="ident">results</span>, <span class="ident">expected</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_clone_streams</span>() {
<span class="kw">let</span> <span class="ident">seed</span> <span class="op">=</span> [
<span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">1</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">2</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">3</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">4</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">5</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">6</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>, <span class="number">7</span>,
<span class="number">0</span>, <span class="number">0</span>, <span class="number">0</span>,
];
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">seed</span>);
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">clone</span> <span class="op">=</span> <span class="ident">rng</span>.<span class="ident">clone</span>();
<span class="kw">for</span> <span class="kw">_</span> <span class="kw">in</span> <span class="number">0</span>..<span class="number">16</span> {
<span class="macro">assert_eq!</span>(<span class="ident">rng</span>.<span class="ident">next_u64</span>(), <span class="ident">clone</span>.<span class="ident">next_u64</span>());
}
<span class="ident">rng</span>.<span class="ident">set_stream</span>(<span class="number">51</span>);
<span class="kw">for</span> <span class="kw">_</span> <span class="kw">in</span> <span class="number">0</span>..<span class="number">7</span> {
<span class="macro">assert!</span>(<span class="ident">rng</span>.<span class="ident">next_u32</span>() <span class="op">!</span><span class="op">=</span> <span class="ident">clone</span>.<span class="ident">next_u32</span>());
}
<span class="ident">clone</span>.<span class="ident">set_stream</span>(<span class="number">51</span>); <span class="comment">// switch part way through block</span>
<span class="kw">for</span> <span class="kw">_</span> <span class="kw">in</span> <span class="number">7</span>..<span class="number">16</span> {
<span class="macro">assert_eq!</span>(<span class="ident">rng</span>.<span class="ident">next_u32</span>(), <span class="ident">clone</span>.<span class="ident">next_u32</span>());
}
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_word_pos_wrap_exact</span>() {
<span class="kw">use</span> <span class="kw">super</span>::{<span class="ident">BUF_BLOCKS</span>, <span class="ident">BLOCK_WORDS</span>};
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">Default::default</span>());
<span class="comment">// refilling the buffer in set_word_pos will wrap the block counter to 0</span>
<span class="kw">let</span> <span class="ident">last_block</span> <span class="op">=</span> (<span class="number">1</span> <span class="op">&lt;</span><span class="op">&lt;</span> <span class="number">68</span>) <span class="op">-</span> <span class="ident">u128::from</span>(<span class="ident">BUF_BLOCKS</span> <span class="op">*</span> <span class="ident">BLOCK_WORDS</span>);
<span class="ident">rng</span>.<span class="ident">set_word_pos</span>(<span class="ident">last_block</span>);
<span class="macro">assert_eq!</span>(<span class="ident">rng</span>.<span class="ident">get_word_pos</span>(), <span class="ident">last_block</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_word_pos_wrap_excess</span>() {
<span class="kw">use</span> <span class="ident"><span class="kw">super</span>::BLOCK_WORDS</span>;
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">Default::default</span>());
<span class="comment">// refilling the buffer in set_word_pos will wrap the block counter past 0</span>
<span class="kw">let</span> <span class="ident">last_block</span> <span class="op">=</span> (<span class="number">1</span> <span class="op">&lt;</span><span class="op">&lt;</span> <span class="number">68</span>) <span class="op">-</span> <span class="ident">u128::from</span>(<span class="ident">BLOCK_WORDS</span>);
<span class="ident">rng</span>.<span class="ident">set_word_pos</span>(<span class="ident">last_block</span>);
<span class="macro">assert_eq!</span>(<span class="ident">rng</span>.<span class="ident">get_word_pos</span>(), <span class="ident">last_block</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_chacha_word_pos_zero</span>() {
<span class="kw">let</span> <span class="kw-2">mut</span> <span class="ident">rng</span> <span class="op">=</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">Default::default</span>());
<span class="macro">assert_eq!</span>(<span class="ident">rng</span>.<span class="ident">get_word_pos</span>(), <span class="number">0</span>);
<span class="ident">rng</span>.<span class="ident">set_word_pos</span>(<span class="number">0</span>);
<span class="macro">assert_eq!</span>(<span class="ident">rng</span>.<span class="ident">get_word_pos</span>(), <span class="number">0</span>);
}
<span class="attribute">#[<span class="ident">test</span>]</span>
<span class="kw">fn</span> <span class="ident">test_trait_objects</span>() {
<span class="kw">use</span> <span class="ident">rand_core::CryptoRngCore</span>;
<span class="kw">let</span> <span class="ident">rng</span> <span class="op">=</span> <span class="kw-2">&amp;mut</span> <span class="ident">ChaChaRng::from_seed</span>(<span class="ident">Default::default</span>()) <span class="kw">as</span> <span class="kw-2">&amp;mut</span> <span class="kw">dyn</span> <span class="ident">CryptoRngCore</span>;
<span class="kw">let</span> <span class="ident">r1</span> <span class="op">=</span> <span class="ident">rng</span>.<span class="ident">next_u64</span>();
<span class="kw">let</span> <span class="ident">rng</span>: <span class="kw-2">&amp;mut</span> <span class="kw">dyn</span> <span class="ident">RngCore</span> <span class="op">=</span> <span class="ident">rng</span>.<span class="ident">as_rngcore</span>();
<span class="kw">let</span> <span class="ident">r2</span> <span class="op">=</span> <span class="ident">rng</span>.<span class="ident">next_u64</span>();
<span class="macro">assert_ne!</span>(<span class="ident">r1</span>, <span class="ident">r2</span>);
}
}
</code></pre></div>
</section><section id="search" class="content hidden"></section></div></main><div id="rustdoc-vars" data-root-path="../../" data-current-crate="rand_chacha" data-themes="ayu,dark,light" data-resource-suffix="" data-rustdoc-version="1.60.0-nightly (1bd4fdc94 2022-01-12)" ></div>
</body></html>