poly1305 internals: Remove unneeded I-U-F buffering. #2270
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
CRYPTO_poly1305_update
was designed to buffer any partial blocks, only passing full blocks to poly1305_update. ThenCRYPTO_poly1305_finish
would pass in the final partial block.chacha20_poly1305
's poly1305_update_padded_16 was working around that logic to ensure that a partial block never got buffered. Then it was doing extra work to pad the last block with zeros.These two mechanisms were basically cancelling each other out. Instead, just avoid all the work.
This removes some non-trivial buffer management from C.