123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399(*****************************************************************************)(* *)(* Copyright (c) 2020-2021 Danny Willems <be.danny.willems@gmail.com> *)(* *)(* Permission is hereby granted, free of charge, to any person obtaining a *)(* copy of this software and associated documentation files (the "Software"),*)(* to deal in the Software without restriction, including without limitation *)(* the rights to use, copy, modify, merge, publish, distribute, sublicense, *)(* and/or sell copies of the Software, and to permit persons to whom the *)(* Software is furnished to do so, subject to the following conditions: *)(* *)(* The above copyright notice and this permission notice shall be included *)(* in all copies or substantial portions of the Software. *)(* *)(* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR*)(* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, *)(* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL *)(* THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER*)(* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING *)(* FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER *)(* DEALINGS IN THE SOFTWARE. *)(* *)(*****************************************************************************)moduleStubs=structtypeaffine_arraytypeaffinetypejacobianexternalallocate_g1:unit->jacobian="allocate_p1_stubs"externalallocate_g1_affine_contiguous_array:int->affine_array="allocate_p1_affine_array_stubs"externalp1_affine_array_set_p1_points:affine_array->jacobianarray->int->int="caml_blst_p1_affine_array_set_p1_points_stubs"externalallocate_g1_affine:unit->affine="allocate_p1_affine_stubs"externalfrom_affine:jacobian->affine->int="caml_blst_p1_from_affine_stubs"externalto_affine:affine->jacobian->int="caml_blst_p1_to_affine_stubs"externaldouble:jacobian->jacobian->int="caml_blst_p1_double_stubs"externaldadd:jacobian->jacobian->jacobian->int="caml_blst_p1_add_or_double_stubs"externalis_zero:jacobian->bool="caml_blst_p1_is_inf_stubs"externalin_g1:jacobian->bool="caml_blst_p1_in_g1_stubs"externalequal:jacobian->jacobian->bool="caml_blst_p1_equal_stubs"externalcneg:jacobian->bool->int="caml_blst_p1_cneg_stubs"externalmult:jacobian->jacobian->Bytes.t->Unsigned.Size_t.t->int="caml_blst_p1_mult_stubs"externaldeserialize:affine->Bytes.t->int="caml_blst_p1_deserialize_stubs"externalserialize:Bytes.t->jacobian->int="caml_blst_p1_serialize_stubs"externalcompress:Bytes.t->jacobian->int="caml_blst_p1_compress_stubs"externaluncompress:affine->Bytes.t->int="caml_blst_p1_uncompress_stubs"externalhash_to_curve:jacobian->Bytes.t->Unsigned.Size_t.t->Bytes.t->Unsigned.Size_t.t->Bytes.t->Unsigned.Size_t.t->int="caml_blst_p1_hash_to_curve_stubs_bytecode""caml_blst_p1_hash_to_curve_stubs"externalmemcpy:jacobian->jacobian->int="caml_blst_p1_memcpy_stubs"externalset_affine_coordinates:affine->Fq.t->Fq.t->int="caml_blst_p1_set_coordinates_stubs"externalfft_inplace:jacobianarray->Fr.Stubs.frarray->int->int="caml_fft_g1_inplace_stubs"externalpippenger:jacobian->jacobianarray->Fr.tarray->Unsigned.Size_t.t->Unsigned.Size_t.t->int="caml_blst_g1_pippenger_stubs"externalcontinuous_array_get:jacobian->affine_array->int->int="caml_blst_p1_affine_array_get_stubs"externalpippenger_with_affine_array:jacobian->affine_array->Fr.tarray->Unsigned.Size_t.t->Unsigned.Size_t.t->int="caml_blst_g1_pippenger_contiguous_affine_array_stubs"externalmul_map_inplace:jacobianarray->Fr.Stubs.fr->int->int="caml_mul_map_g1_inplace_stubs"endmoduleG1=structexceptionNot_on_curveofBytes.ttypet=Stubs.jacobiantypeaffine=Stubs.affinetypeaffine_array=Stubs.affine_array*intletglobal_buffer=Stubs.allocate_g1()letsize_in_bytes=96letmemcpydstsrc=ignore@@Stubs.memcpydstsrcletaffine_of_jacobianj=letb=Stubs.allocate_g1_affine()inignore@@Stubs.to_affinebj;bletjacobian_of_affinea=letb=Stubs.allocate_g1()inignore@@Stubs.from_affineba;bletto_affine_arrayl=letlength=Array.lengthlinletbuffer=Stubs.allocate_g1_affine_contiguous_arraylengthinignore@@Stubs.p1_affine_array_set_p1_pointsbufferllength;(buffer,length)letof_affine_array(l,n)=Array.initn(funi->letp=Stubs.allocate_g1()inignore@@Stubs.continuous_array_getpli;p)letsize_of_affine_array(_,n)=nletcopysrc=letdst=Stubs.allocate_g1()inmemcpydstsrc;dstmoduleScalar=Frletcofactor_fr=Scalar.of_string"76329603384216526031706109802092473003"letcheck_bytesbs=letbuffer=Stubs.allocate_g1_affine()inStubs.deserializebufferbs=0letof_bytes_optbs=letbuffer_affine=Stubs.allocate_g1_affine()inifBytes.lengthbs<>size_in_bytesthenNoneelseletres=Stubs.deserializebuffer_affinebsinifres=0then(letbuffer=Stubs.allocate_g1()inignore@@Stubs.from_affinebufferbuffer_affine;letis_in_prime_subgroup=Stubs.in_g1bufferinifis_in_prime_subgroupthenSomebufferelseNone)elseNoneletof_bytes_exnbs=matchof_bytes_optbswithNone->raise(Not_on_curvebs)|Somep->pletzero=letbytes=Bytes.of_string"@\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000"inof_bytes_exnbytesletone=letbytes=Bytes.of_string"\023\241\211\1671\151\215\148&\149c\140O\169\172\015\195h\140O\151t\185\005\161N:?\023\027\172XlU\232?\249z\026\239\251:\240\n\
\219\"\198\187\b\179\244\129\227\170\160\241\160\1580\237t\029\138\228\252\245\224\149\213\208\n\
\246\000\219\024\203,\004\179\237\208<\199D\162\136\138\228\012\170#)F\197\231\225"inof_bytes_exnbytesletsize_in_memory=Obj.reachable_words(Obj.magicone)*8letof_compressed_bytes_optbs=letbuffer_affine=Stubs.allocate_g1_affine()inletres=Stubs.uncompressbuffer_affinebsinifres=0then(letbuffer=Stubs.allocate_g1()inignore@@Stubs.from_affinebufferbuffer_affine;letis_in_prime_subgroup=Stubs.in_g1bufferinifis_in_prime_subgroupthenSomebufferelseNone)elseNoneletof_compressed_bytes_exnbs=matchof_compressed_bytes_optbswith|None->raise(Not_on_curvebs)|Somep->pletto_bytesp=letbuffer=Bytes.makesize_in_bytes'\000'inignore@@Stubs.serializebufferp;bufferletto_compressed_bytesp=letbuffer=Bytes.make(size_in_bytes/2)'\000'inignore@@Stubs.compressbufferp;bufferletaddxy=(* dadd must be used to be complete. add does not work when it is the same
point *)letbuffer=Stubs.allocate_g1()inignore@@Stubs.daddbufferxy;bufferletadd_inplacexy=ignore@@Stubs.daddglobal_bufferxy;memcpyxglobal_bufferletadd_bulkxs=letbuffer=Stubs.allocate_g1()inList.iter(funx->ignore@@Stubs.daddbufferbufferx)xs;bufferletdoublex=letbuffer=Stubs.allocate_g1()inignore@@Stubs.doublebufferx;bufferletmulgn=letbuffer=Stubs.allocate_g1()inletbytes=Fr.to_bytesninignore@@Stubs.multbuffergbytes(Unsigned.Size_t.of_int(32*8));bufferletmul_inplacegn=ignore@@Stubs.multglobal_bufferg(Fr.to_bytesn)(Unsigned.Size_t.of_int(32*8));memcpygglobal_bufferletb=Fq.(one+one+one+one)letrecrandom?state()=letx=Fq.random?state()inletxx=Fq.(x*x)inletxxx=Fq.(x*xx)inletxxx_plus_b=Fq.(xxx+b)inlety_opt=Fq.sqrt_optxxx_plus_binmatchy_optwith|None->random?state()|Somey->letrandom_bool=matchstatewith|None->Random.bool()|Somestate->Random.State.boolstateinlety=ifrandom_boolthenyelseFq.negateyinletp_affine=Stubs.allocate_g1_affine()inignore@@Stubs.set_affine_coordinatesp_affinexy;letp=Stubs.allocate_g1()inignore@@Stubs.from_affinepp_affine;mulpcofactor_frleteqg1g2=Stubs.equalg1g2letis_zerox=eqxzeroletorder_minus_one=Scalar.(negateone)letnegateg=letbuffer=copyginignore@@Stubs.cnegbuffertrue;bufferletof_z_opt~x~y=letx=Fq.of_zxinlety=Fq.of_zyinletbuffer_affine=Stubs.allocate_g1_affine()inignore@@Stubs.set_affine_coordinatesbuffer_affinexy;letbuffer=Stubs.allocate_g1()inignore@@Stubs.from_affinebufferbuffer_affine;ifStubs.in_g1bufferthenSomebufferelseNonemoduleM=structtypegroup=ttypescalar=Scalar.tletzero=zeroletinverse_exn_scalar=Scalar.inverse_exnletscalar_of_z=Scalar.of_zletfft_inplace=Stubs.fft_inplaceletmul_map_inplace=Stubs.mul_map_inplaceletcopy=copyendletfft~domain~points=Fft.fft(moduleM)~domain~pointsletfft_inplace~domain~points=letlogn=Z.log2(Z.of_int(Array.lengthpoints))inignore@@Stubs.fft_inplacepointsdomainlognletifft~domain~points=Fft.ifft(moduleM)~domain~pointsletifft_inplace~domain~points=letn=Array.lengthpointsinletlogn=Z.log2(Z.of_intn)inletn_inv=Fr.inverse_exn(Fr.of_z(Z.of_intn))inignore@@Stubs.fft_inplacepointsdomainlogn;ignore@@Stubs.mul_map_inplacepointsn_invnlethash_to_curvemessagedst=letmessage_length=Bytes.lengthmessageinletdst_length=Bytes.lengthdstinletbuffer=Stubs.allocate_g1()inignore@@Stubs.hash_to_curvebuffermessage(Unsigned.Size_t.of_intmessage_length)dst(Unsigned.Size_t.of_intdst_length)Bytes.emptyUnsigned.Size_t.zero;bufferletpippenger?(start=0)?lenpsss=letl_ss=Array.lengthssinletl_ps=Array.lengthpsinletl=minl_ssl_psinletlen=Option.value~default:(l-start)leninifstart<0||len<1||start+len>lthenraise@@Invalid_argument(Format.sprintf"start %i len %i"startlen);iflen=1thenmulps.(start)ss.(start)elseletbuffer=Stubs.allocate_g1()inletres=Stubs.pippengerbufferpsss(Unsigned.Size_t.of_intstart)(Unsigned.Size_t.of_intlen)inassert(res=0);bufferletpippenger_with_affine_array?(start=0)?len(ps,n)ss=letl=minn(Array.lengthss)inletbuffer=Stubs.allocate_g1()inletlen=Option.value~default:(l-start)leninifstart<0||len<1||start+len>nthenraise@@Invalid_argument(Format.sprintf"start %i len %i"startlen);(iflen=1then(ignore@@Stubs.continuous_array_getbufferpsstart;mul_inplacebufferss.(start))elseletres=Stubs.pippenger_with_affine_arraybufferpsss(Unsigned.Size_t.of_intstart)(Unsigned.Size_t.of_intlen)inassert(res=0));bufferendincludeG1