123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394(*****************************************************************************)(* *)(* Copyright (c) 2020-2021 Danny Willems <be.danny.willems@gmail.com> *)(* *)(* Permission is hereby granted, free of charge, to any person obtaining a *)(* copy of this software and associated documentation files (the "Software"),*)(* to deal in the Software without restriction, including without limitation *)(* the rights to use, copy, modify, merge, publish, distribute, sublicense, *)(* and/or sell copies of the Software, and to permit persons to whom the *)(* Software is furnished to do so, subject to the following conditions: *)(* *)(* The above copyright notice and this permission notice shall be included *)(* in all copies or substantial portions of the Software. *)(* *)(* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR*)(* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, *)(* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL *)(* THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER*)(* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING *)(* FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER *)(* DEALINGS IN THE SOFTWARE. *)(* *)(*****************************************************************************)moduleStubs=structtypeaffinetypeaffine_arraytypejacobianexternalallocate_g2:unit->jacobian="allocate_p2_stubs"externalallocate_g2_affine:unit->affine="allocate_p2_affine_stubs"externalallocate_g2_affine_contiguous_array:int->affine_array="allocate_p2_affine_array_stubs"externalp2_affine_array_set_p2_points:affine_array->jacobianarray->int->int="caml_blst_p2_affine_array_set_p2_points_stubs"externalfrom_affine:jacobian->affine->int="caml_blst_p2_from_affine_stubs"externalto_affine:affine->jacobian->int="caml_blst_p2_to_affine_stubs"externaldouble:jacobian->jacobian->int="caml_blst_p2_double_stubs"externaldadd:jacobian->jacobian->jacobian->int="caml_blst_p2_add_or_double_stubs"externalis_zero:jacobian->bool="caml_blst_p2_is_inf_stubs"externalin_g2:jacobian->bool="caml_blst_p2_in_g2_stubs"externalequal:jacobian->jacobian->bool="caml_blst_p2_equal_stubs"externalcneg:jacobian->bool->int="caml_blst_p2_cneg_stubs"externalmult:jacobian->jacobian->Bytes.t->Unsigned.Size_t.t->int="caml_blst_p2_mult_stubs"externaldeserialize:affine->Bytes.t->int="caml_blst_p2_deserialize_stubs"externalserialize:Bytes.t->jacobian->int="caml_blst_p2_serialize_stubs"externalcompress:Bytes.t->jacobian->int="caml_blst_p2_compress_stubs"externaluncompress:affine->Bytes.t->int="caml_blst_p2_uncompress_stubs"externalhash_to_curve:jacobian->Bytes.t->Unsigned.Size_t.t->Bytes.t->Unsigned.Size_t.t->Bytes.t->Unsigned.Size_t.t->int="caml_blst_p2_hash_to_curve_stubs_bytecode""caml_blst_p2_hash_to_curve_stubs"externalmemcpy:jacobian->jacobian->int="caml_blst_p2_memcpy_stubs"externalset_affine_coordinates:affine->Fq2.t->Fq2.t->int="caml_blst_p2_set_coordinates_stubs"externalpippenger:jacobian->jacobianarray->Fr.tarray->Unsigned.Size_t.t->Unsigned.Size_t.t->int="caml_blst_g2_pippenger_stubs"externalcontinuous_array_get:jacobian->affine_array->int->int="caml_blst_p2_affine_array_get_stubs"externalpippenger_with_affine_array:jacobian->affine_array->Fr.tarray->Unsigned.Size_t.t->Unsigned.Size_t.t->int="caml_blst_g2_pippenger_contiguous_affine_array_stubs"endmoduleG2=structtypet=Stubs.jacobiantypeaffine=Stubs.affinetypeaffine_array=Stubs.affine_array*intexceptionNot_on_curveofBytes.tletsize_in_bytes=192letcompressed_size_in_bytes=96letaffine_of_jacobianj=letb=Stubs.allocate_g2_affine()inignore@@Stubs.to_affinebj;bletjacobian_of_affinea=letb=Stubs.allocate_g2()inignore@@Stubs.from_affineba;bletmemcpydstsrc=ignore@@Stubs.memcpydstsrcletto_affine_arrayl=letlength=Array.lengthlinletbuffer=Stubs.allocate_g2_affine_contiguous_arraylengthinignore@@Stubs.p2_affine_array_set_p2_pointsbufferllength;(buffer,length)letof_affine_array(l,n)=Array.initn(funi->letp=Stubs.allocate_g2()inignore@@Stubs.continuous_array_getpli;p)letsize_of_affine_array(_,n)=nletcopysrc=letdst=Stubs.allocate_g2()inmemcpydstsrc;dstletglobal_buffer=Stubs.allocate_g2()moduleScalar=Frletcheck_bytesbs=letbuffer=Stubs.allocate_g2_affine()inStubs.deserializebufferbs=0letof_bytes_optbs=letbuffer_affine=Stubs.allocate_g2_affine()inifBytes.lengthbs<>size_in_bytesthenNoneelseletres=Stubs.deserializebuffer_affinebsinifres=0then(letbuffer=Stubs.allocate_g2()inignore@@Stubs.from_affinebufferbuffer_affine;letis_in_prime_subgroup=Stubs.in_g2bufferinifis_in_prime_subgroupthenSomebufferelseNone)elseNoneletof_bytes_exnbs=matchof_bytes_optbswithNone->raise(Not_on_curvebs)|Somep->pletof_compressed_bytes_optbs=letbuffer_affine=Stubs.allocate_g2_affine()inletres=Stubs.uncompressbuffer_affinebsinifres=0then(letbuffer=Stubs.allocate_g2()inignore@@Stubs.from_affinebufferbuffer_affine;letis_in_prime_subgroup=Stubs.in_g2bufferinifis_in_prime_subgroupthenSomebufferelseNone)elseNoneletof_compressed_bytes_exnbs=matchof_compressed_bytes_optbswith|None->raise(Not_on_curvebs)|Somep->pletzero=letbytes=Bytes.of_string"\192\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000\000"inof_compressed_bytes_exnbytesletone=letbytes=Bytes.of_string"\147\224+`Rq\159`}\172\211\160\136'OeYk\208\208\153 \
\182\026\181\218a\187\220\127PI3L\241\018\019\148]W\229\172}\005]\004+~\002J\162\178\240\143\n\
\145&\b\005'-\197\016Q\198\228z\212\250@;\
\002\180Q\011dz\227\209w\011\172\003&\168\005\187\239\212\128V\200\193!\189\184"inof_compressed_bytes_exnbytesletsize_in_memory=Obj.reachable_words(Obj.reprone)*8letto_bytesp=letbuffer=Bytes.makesize_in_bytes'\000'inignore@@Stubs.serializebufferp;bufferletto_compressed_bytesp=letbuffer=Bytes.make(size_in_bytes/2)'\000'inignore@@Stubs.compressbufferp;bufferletaddxy=(* dadd must be used to be complete. add does not work when it is the same
point *)letbuffer=Stubs.allocate_g2()inignore@@Stubs.daddbufferxy;bufferletadd_inplacexy=ignore@@Stubs.daddglobal_bufferxy;memcpyxglobal_bufferletadd_bulkxs=letbuffer=Stubs.allocate_g2()inList.iter(funx->ignore@@Stubs.daddbufferbufferx)xs;bufferletdoublex=letbuffer=Stubs.allocate_g2()inignore@@Stubs.doublebufferx;bufferletmul_bitsgbytes=letbuffer=Stubs.allocate_g2()inignore@@Stubs.multbuffergbytes(Unsigned.Size_t.of_int(Bytes.lengthbytes*8));bufferletmulgn=letbytes=Fr.to_bytesninmul_bitsgbytesletmul_inplacegn=letbytes=Fr.to_bytesninignore@@Stubs.multglobal_buffergbytes(Unsigned.Size_t.of_int(Bytes.lengthbytes*8));memcpygglobal_bufferletb=letbuffer=Fq2.Stubs.allocate_fp2()inletfq_four=Fq.(one+one+one+one)inletbytes=Fq.to_bytesfq_fourinignore@@Fq2.Stubs.of_bytes_componentsbufferbytesbytes;bufferletclear_cofactorp=letbytes=Z.of_string_base16"5d543a95414e7f1091d50792876a202cd91de4547085abaa68a205b2e5a7ddfa628f1cb4d9e82ef21537e293a6691ae1616ec6e786f0c70cf1c38e31c7238e5"inletbytes=Bytes.of_string(Z.to_bitsbytes)inletres=mul_bitspbytesinresletrecrandom?state()=letx=Fq2.random?state()inletxx=Fq2.(x*x)inletxxx=Fq2.(x*xx)inletxxx_plus_b=Fq2.(xxx+b)inlety_opt=Fq2.sqrt_optxxx_plus_binmatchy_optwith|None->random?state()|Somey->letrandom_bool=matchstatewith|None->Random.bool()|Somestate->Random.State.boolstateinlety=ifrandom_boolthenyelseFq2.negateyinletp_affine=Stubs.allocate_g2_affine()inignore@@Stubs.set_affine_coordinatesp_affinexy;letp=Stubs.allocate_g2()inignore@@Stubs.from_affinepp_affine;letp=clear_cofactorpinpleteqg1g2=Stubs.equalg1g2letis_zerox=eqxzeroletorder_minus_one=Scalar.(negateone)letnegateg=letbuffer=copyginignore@@Stubs.cnegbuffertrue;bufferletof_z_opt~x~y=letx1,x2=xinlety1,y2=yinletx1_bytes=Bytes.of_string(Z.to_bitsx1)inletx2_bytes=Bytes.of_string(Z.to_bitsx2)inlety1_bytes=Bytes.of_string(Z.to_bitsy1)inlety2_bytes=Bytes.of_string(Z.to_bitsy2)inletx=Fq2.Stubs.allocate_fp2()inlety=Fq2.Stubs.allocate_fp2()inignore@@Fq2.Stubs.of_bytes_componentsxx1_bytesx2_bytes;ignore@@Fq2.Stubs.of_bytes_componentsyy1_bytesy2_bytes;letp_affine=Stubs.allocate_g2_affine()inignore@@Stubs.set_affine_coordinatesp_affinexy;letp=Stubs.allocate_g2()inignore@@Stubs.from_affinepp_affine;letis_ok=Stubs.in_g2pinifis_okthenSomepelseNonelethash_to_curvemessagedst=letmessage_length=Bytes.lengthmessageinletdst_length=Bytes.lengthdstinletbuffer=Stubs.allocate_g2()inignore@@Stubs.hash_to_curvebuffermessage(Unsigned.Size_t.of_intmessage_length)dst(Unsigned.Size_t.of_intdst_length)Bytes.emptyUnsigned.Size_t.zero;bufferletpippenger?(start=0)?lenpsss=letl_ss=Array.lengthssinletl_ps=Array.lengthpsinletl=minl_ssl_psinletlen=Option.value~default:(l-start)leninifstart<0||len<1||start+len>lthenraise@@Invalid_argument(Format.sprintf"start %i len %i"startlen);iflen=1thenmulps.(start)ss.(start)elseletbuffer=Stubs.allocate_g2()inletres=Stubs.pippengerbufferpsss(Unsigned.Size_t.of_intstart)(Unsigned.Size_t.of_intlen)inassert(res=0);bufferletpippenger_with_affine_array?(start=0)?len(ps,n)ss=letl=minn(Array.lengthss)inletbuffer=Stubs.allocate_g2()inletlen=Option.value~default:(l-start)leninifstart<0||len<1||start+len>nthenraise@@Invalid_argument(Format.sprintf"start %i len %i"startlen);(iflen=1then(ignore@@Stubs.continuous_array_getbufferpsstart;mul_inplacebufferss.(start))elseletres=Stubs.pippenger_with_affine_arraybufferpsss(Unsigned.Size_t.of_intstart)(Unsigned.Size_t.of_intlen)inassert(res=0));bufferendincludeG2