2022-05-24 20:39:40 +02:00
|
|
|
// Copyright 2018 The go-ethereum Authors
|
|
|
|
// This file is part of the go-ethereum library.
|
|
|
|
//
|
|
|
|
// The go-ethereum library is free software: you can redistribute it and/or modify
|
|
|
|
// it under the terms of the GNU Lesser General Public License as published by
|
|
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
|
|
// (at your option) any later version.
|
|
|
|
//
|
|
|
|
// The go-ethereum library is distributed in the hope that it will be useful,
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
// GNU Lesser General Public License for more details.
|
|
|
|
//
|
|
|
|
// You should have received a copy of the GNU Lesser General Public License
|
|
|
|
// along with the go-ethereum library. If not, see <http://www.gnu.org/licenses/>.
|
2018-03-20 01:13:54 +09:00
|
|
|
|
|
|
|
package bn256
|
|
|
|
|
|
|
|
import (
|
|
|
|
"bytes"
|
2020-11-13 09:27:57 +01:00
|
|
|
"fmt"
|
|
|
|
"io"
|
2018-03-20 01:13:54 +09:00
|
|
|
"math/big"
|
|
|
|
|
2021-04-28 05:04:25 -05:00
|
|
|
"github.com/consensys/gnark-crypto/ecc/bn254"
|
2018-03-20 01:13:54 +09:00
|
|
|
cloudflare "github.com/ethereum/go-ethereum/crypto/bn256/cloudflare"
|
|
|
|
google "github.com/ethereum/go-ethereum/crypto/bn256/google"
|
|
|
|
)
|
|
|
|
|
2021-04-28 05:04:25 -05:00
|
|
|
func getG1Points(input io.Reader) (*cloudflare.G1, *google.G1, *bn254.G1Affine) {
|
2020-11-13 09:27:57 +01:00
|
|
|
_, xc, err := cloudflare.RandomG1(input)
|
|
|
|
if err != nil {
|
|
|
|
// insufficient input
|
2021-02-03 15:04:28 +01:00
|
|
|
return nil, nil, nil
|
2018-03-20 01:13:54 +09:00
|
|
|
}
|
|
|
|
xg := new(google.G1)
|
2020-11-13 09:27:57 +01:00
|
|
|
if _, err := xg.Unmarshal(xc.Marshal()); err != nil {
|
2021-04-28 05:04:25 -05:00
|
|
|
panic(fmt.Sprintf("Could not marshal cloudflare -> google: %v", err))
|
2021-02-03 15:04:28 +01:00
|
|
|
}
|
2021-04-28 05:04:25 -05:00
|
|
|
xs := new(bn254.G1Affine)
|
2021-02-03 15:04:28 +01:00
|
|
|
if err := xs.Unmarshal(xc.Marshal()); err != nil {
|
2021-04-28 05:04:25 -05:00
|
|
|
panic(fmt.Sprintf("Could not marshal cloudflare -> gnark: %v", err))
|
2018-03-20 01:13:54 +09:00
|
|
|
}
|
2021-02-03 15:04:28 +01:00
|
|
|
return xc, xg, xs
|
2020-11-13 09:27:57 +01:00
|
|
|
}
|
2018-03-20 01:13:54 +09:00
|
|
|
|
2021-04-28 05:04:25 -05:00
|
|
|
func getG2Points(input io.Reader) (*cloudflare.G2, *google.G2, *bn254.G2Affine) {
|
2020-11-13 09:27:57 +01:00
|
|
|
_, xc, err := cloudflare.RandomG2(input)
|
|
|
|
if err != nil {
|
|
|
|
// insufficient input
|
2021-02-03 15:04:28 +01:00
|
|
|
return nil, nil, nil
|
2020-11-13 09:27:57 +01:00
|
|
|
}
|
|
|
|
xg := new(google.G2)
|
|
|
|
if _, err := xg.Unmarshal(xc.Marshal()); err != nil {
|
2021-04-28 05:04:25 -05:00
|
|
|
panic(fmt.Sprintf("Could not marshal cloudflare -> google: %v", err))
|
2020-11-13 09:27:57 +01:00
|
|
|
}
|
2021-04-28 05:04:25 -05:00
|
|
|
xs := new(bn254.G2Affine)
|
2021-02-03 15:04:28 +01:00
|
|
|
if err := xs.Unmarshal(xc.Marshal()); err != nil {
|
2021-04-28 05:04:25 -05:00
|
|
|
panic(fmt.Sprintf("Could not marshal cloudflare -> gnark: %v", err))
|
2021-02-03 15:04:28 +01:00
|
|
|
}
|
|
|
|
return xc, xg, xs
|
2020-11-13 09:27:57 +01:00
|
|
|
}
|
2018-03-20 01:13:54 +09:00
|
|
|
|
2023-10-18 15:01:16 +02:00
|
|
|
// fuzzAdd fuzzez bn256 addition between the Google and Cloudflare libraries.
|
|
|
|
func fuzzAdd(data []byte) int {
|
2020-11-13 09:27:57 +01:00
|
|
|
input := bytes.NewReader(data)
|
2021-02-03 15:04:28 +01:00
|
|
|
xc, xg, xs := getG1Points(input)
|
2020-11-13 09:27:57 +01:00
|
|
|
if xc == nil {
|
2018-03-20 01:13:54 +09:00
|
|
|
return 0
|
|
|
|
}
|
2021-02-03 15:04:28 +01:00
|
|
|
yc, yg, ys := getG1Points(input)
|
2020-11-13 09:27:57 +01:00
|
|
|
if yc == nil {
|
|
|
|
return 0
|
|
|
|
}
|
|
|
|
// Ensure both libs can parse the second curve point
|
2018-03-20 01:13:54 +09:00
|
|
|
// Add the two points and ensure they result in the same output
|
|
|
|
rc := new(cloudflare.G1)
|
|
|
|
rc.Add(xc, yc)
|
|
|
|
|
|
|
|
rg := new(google.G1)
|
|
|
|
rg.Add(xg, yg)
|
|
|
|
|
2021-04-28 05:04:25 -05:00
|
|
|
tmpX := new(bn254.G1Jac).FromAffine(xs)
|
|
|
|
tmpY := new(bn254.G1Jac).FromAffine(ys)
|
|
|
|
rs := new(bn254.G1Affine).FromJacobian(tmpX.AddAssign(tmpY))
|
2021-02-03 15:04:28 +01:00
|
|
|
|
2018-03-20 01:13:54 +09:00
|
|
|
if !bytes.Equal(rc.Marshal(), rg.Marshal()) {
|
2021-02-03 15:04:28 +01:00
|
|
|
panic("add mismatch: cloudflare/google")
|
|
|
|
}
|
|
|
|
|
|
|
|
if !bytes.Equal(rc.Marshal(), rs.Marshal()) {
|
2021-04-28 05:04:25 -05:00
|
|
|
panic("add mismatch: cloudflare/gnark")
|
2018-03-20 01:13:54 +09:00
|
|
|
}
|
2020-11-13 09:27:57 +01:00
|
|
|
return 1
|
2018-03-20 01:13:54 +09:00
|
|
|
}
|
|
|
|
|
2023-10-18 15:01:16 +02:00
|
|
|
// fuzzMul fuzzez bn256 scalar multiplication between the Google and Cloudflare
|
2018-03-20 01:13:54 +09:00
|
|
|
// libraries.
|
2023-10-18 15:01:16 +02:00
|
|
|
func fuzzMul(data []byte) int {
|
2020-11-13 09:27:57 +01:00
|
|
|
input := bytes.NewReader(data)
|
2021-02-03 15:04:28 +01:00
|
|
|
pc, pg, ps := getG1Points(input)
|
2020-11-13 09:27:57 +01:00
|
|
|
if pc == nil {
|
2018-03-20 01:13:54 +09:00
|
|
|
return 0
|
|
|
|
}
|
2020-11-13 09:27:57 +01:00
|
|
|
// Add the two points and ensure they result in the same output
|
|
|
|
remaining := input.Len()
|
|
|
|
if remaining == 0 {
|
2018-03-20 01:13:54 +09:00
|
|
|
return 0
|
|
|
|
}
|
2020-11-20 08:53:10 +01:00
|
|
|
if remaining > 128 {
|
|
|
|
// The evm only ever uses 32 byte integers, we need to cap this otherwise
|
|
|
|
// we run into slow exec. A 236Kb byte integer cause oss-fuzz to report it as slow.
|
|
|
|
// 128 bytes should be fine though
|
|
|
|
return 0
|
|
|
|
}
|
2020-11-13 09:27:57 +01:00
|
|
|
buf := make([]byte, remaining)
|
|
|
|
input.Read(buf)
|
|
|
|
|
2018-03-20 01:13:54 +09:00
|
|
|
rc := new(cloudflare.G1)
|
2020-11-13 09:27:57 +01:00
|
|
|
rc.ScalarMult(pc, new(big.Int).SetBytes(buf))
|
2018-03-20 01:13:54 +09:00
|
|
|
|
|
|
|
rg := new(google.G1)
|
2020-11-13 09:27:57 +01:00
|
|
|
rg.ScalarMult(pg, new(big.Int).SetBytes(buf))
|
2018-03-20 01:13:54 +09:00
|
|
|
|
2021-04-28 05:04:25 -05:00
|
|
|
rs := new(bn254.G1Jac)
|
|
|
|
psJac := new(bn254.G1Jac).FromAffine(ps)
|
2021-02-03 15:04:28 +01:00
|
|
|
rs.ScalarMultiplication(psJac, new(big.Int).SetBytes(buf))
|
2021-04-28 05:04:25 -05:00
|
|
|
rsAffine := new(bn254.G1Affine).FromJacobian(rs)
|
2021-02-03 15:04:28 +01:00
|
|
|
|
2018-03-20 01:13:54 +09:00
|
|
|
if !bytes.Equal(rc.Marshal(), rg.Marshal()) {
|
2021-02-03 15:04:28 +01:00
|
|
|
panic("scalar mul mismatch: cloudflare/google")
|
|
|
|
}
|
|
|
|
if !bytes.Equal(rc.Marshal(), rsAffine.Marshal()) {
|
2021-04-28 05:04:25 -05:00
|
|
|
panic("scalar mul mismatch: cloudflare/gnark")
|
2018-03-20 01:13:54 +09:00
|
|
|
}
|
2020-11-13 09:27:57 +01:00
|
|
|
return 1
|
2018-03-20 01:13:54 +09:00
|
|
|
}
|
|
|
|
|
2023-10-18 15:01:16 +02:00
|
|
|
func fuzzPair(data []byte) int {
|
2020-11-13 09:27:57 +01:00
|
|
|
input := bytes.NewReader(data)
|
2021-02-03 15:04:28 +01:00
|
|
|
pc, pg, ps := getG1Points(input)
|
2020-11-13 09:27:57 +01:00
|
|
|
if pc == nil {
|
2018-03-20 01:13:54 +09:00
|
|
|
return 0
|
|
|
|
}
|
2021-02-03 15:04:28 +01:00
|
|
|
tc, tg, ts := getG2Points(input)
|
2020-11-13 09:27:57 +01:00
|
|
|
if tc == nil {
|
2018-03-20 01:13:54 +09:00
|
|
|
return 0
|
|
|
|
}
|
2021-04-28 05:04:25 -05:00
|
|
|
|
2021-02-03 15:04:28 +01:00
|
|
|
// Pair the two points and ensure they result in the same output
|
2021-04-28 05:04:25 -05:00
|
|
|
clPair := cloudflare.Pair(pc, tc).Marshal()
|
|
|
|
gPair := google.Pair(pg, tg).Marshal()
|
|
|
|
if !bytes.Equal(clPair, gPair) {
|
2021-02-03 15:04:28 +01:00
|
|
|
panic("pairing mismatch: cloudflare/google")
|
|
|
|
}
|
2021-04-28 05:04:25 -05:00
|
|
|
cPair, err := bn254.Pair([]bn254.G1Affine{*ps}, []bn254.G2Affine{*ts})
|
2021-02-03 15:04:28 +01:00
|
|
|
if err != nil {
|
2021-04-28 05:04:25 -05:00
|
|
|
panic(fmt.Sprintf("gnark/bn254 encountered error: %v", err))
|
2021-02-03 15:04:28 +01:00
|
|
|
}
|
2023-05-16 13:27:54 +02:00
|
|
|
|
|
|
|
// gnark uses a different pairing algorithm which might produce
|
|
|
|
// different but also correct outputs, we need to scale the output by s
|
|
|
|
|
|
|
|
u, _ := new(big.Int).SetString("0x44e992b44a6909f1", 0)
|
|
|
|
u_exp2 := new(big.Int).Exp(u, big.NewInt(2), nil) // u^2
|
|
|
|
u_6_exp2 := new(big.Int).Mul(big.NewInt(6), u_exp2) // 6*u^2
|
|
|
|
u_3 := new(big.Int).Mul(big.NewInt(3), u) // 3*u
|
|
|
|
inner := u_6_exp2.Add(u_6_exp2, u_3) // 6*u^2 + 3*u
|
|
|
|
inner.Add(inner, big.NewInt(1)) // 6*u^2 + 3*u + 1
|
|
|
|
u_2 := new(big.Int).Mul(big.NewInt(2), u) // 2*u
|
|
|
|
s := u_2.Mul(u_2, inner) // 2*u(6*u^2 + 3*u + 1)
|
|
|
|
|
|
|
|
gRes := new(bn254.GT)
|
|
|
|
if err := gRes.SetBytes(clPair); err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
gRes = gRes.Exp(*gRes, s)
|
|
|
|
if !bytes.Equal(cPair.Marshal(), gRes.Marshal()) {
|
2021-04-28 05:04:25 -05:00
|
|
|
panic("pairing mismatch: cloudflare/gnark")
|
2018-03-20 01:13:54 +09:00
|
|
|
}
|
2021-02-03 15:04:28 +01:00
|
|
|
|
2020-11-13 09:27:57 +01:00
|
|
|
return 1
|
2018-03-20 01:13:54 +09:00
|
|
|
}
|