2 * Author......: Jens Steube <jens.steube@gmail.com>
8 #include "include/constants.h"
9 #include "include/kernel_vendor.h"
16 #include "include/kernel_functions.c"
17 #include "types_ocl.c"
20 #define COMPARE_S "check_single_comp4.c"
21 #define COMPARE_M "check_multi_comp4.c"
23 static void sha1_transform (const u32 w0[4], const u32 w1[4], const u32 w2[4], const u32 w3[4], u32 digest[5])
51 SHA1_STEP (SHA1_F0o, A, B, C, D, E, w0_t);
52 SHA1_STEP (SHA1_F0o, E, A, B, C, D, w1_t);
53 SHA1_STEP (SHA1_F0o, D, E, A, B, C, w2_t);
54 SHA1_STEP (SHA1_F0o, C, D, E, A, B, w3_t);
55 SHA1_STEP (SHA1_F0o, B, C, D, E, A, w4_t);
56 SHA1_STEP (SHA1_F0o, A, B, C, D, E, w5_t);
57 SHA1_STEP (SHA1_F0o, E, A, B, C, D, w6_t);
58 SHA1_STEP (SHA1_F0o, D, E, A, B, C, w7_t);
59 SHA1_STEP (SHA1_F0o, C, D, E, A, B, w8_t);
60 SHA1_STEP (SHA1_F0o, B, C, D, E, A, w9_t);
61 SHA1_STEP (SHA1_F0o, A, B, C, D, E, wa_t);
62 SHA1_STEP (SHA1_F0o, E, A, B, C, D, wb_t);
63 SHA1_STEP (SHA1_F0o, D, E, A, B, C, wc_t);
64 SHA1_STEP (SHA1_F0o, C, D, E, A, B, wd_t);
65 SHA1_STEP (SHA1_F0o, B, C, D, E, A, we_t);
66 SHA1_STEP (SHA1_F0o, A, B, C, D, E, wf_t);
67 w0_t = rotl32 ((wd_t ^ w8_t ^ w2_t ^ w0_t), 1u); SHA1_STEP (SHA1_F0o, E, A, B, C, D, w0_t);
68 w1_t = rotl32 ((we_t ^ w9_t ^ w3_t ^ w1_t), 1u); SHA1_STEP (SHA1_F0o, D, E, A, B, C, w1_t);
69 w2_t = rotl32 ((wf_t ^ wa_t ^ w4_t ^ w2_t), 1u); SHA1_STEP (SHA1_F0o, C, D, E, A, B, w2_t);
70 w3_t = rotl32 ((w0_t ^ wb_t ^ w5_t ^ w3_t), 1u); SHA1_STEP (SHA1_F0o, B, C, D, E, A, w3_t);
75 w4_t = rotl32 ((w1_t ^ wc_t ^ w6_t ^ w4_t), 1u); SHA1_STEP (SHA1_F1, A, B, C, D, E, w4_t);
76 w5_t = rotl32 ((w2_t ^ wd_t ^ w7_t ^ w5_t), 1u); SHA1_STEP (SHA1_F1, E, A, B, C, D, w5_t);
77 w6_t = rotl32 ((w3_t ^ we_t ^ w8_t ^ w6_t), 1u); SHA1_STEP (SHA1_F1, D, E, A, B, C, w6_t);
78 w7_t = rotl32 ((w4_t ^ wf_t ^ w9_t ^ w7_t), 1u); SHA1_STEP (SHA1_F1, C, D, E, A, B, w7_t);
79 w8_t = rotl32 ((w5_t ^ w0_t ^ wa_t ^ w8_t), 1u); SHA1_STEP (SHA1_F1, B, C, D, E, A, w8_t);
80 w9_t = rotl32 ((w6_t ^ w1_t ^ wb_t ^ w9_t), 1u); SHA1_STEP (SHA1_F1, A, B, C, D, E, w9_t);
81 wa_t = rotl32 ((w7_t ^ w2_t ^ wc_t ^ wa_t), 1u); SHA1_STEP (SHA1_F1, E, A, B, C, D, wa_t);
82 wb_t = rotl32 ((w8_t ^ w3_t ^ wd_t ^ wb_t), 1u); SHA1_STEP (SHA1_F1, D, E, A, B, C, wb_t);
83 wc_t = rotl32 ((w9_t ^ w4_t ^ we_t ^ wc_t), 1u); SHA1_STEP (SHA1_F1, C, D, E, A, B, wc_t);
84 wd_t = rotl32 ((wa_t ^ w5_t ^ wf_t ^ wd_t), 1u); SHA1_STEP (SHA1_F1, B, C, D, E, A, wd_t);
85 we_t = rotl32 ((wb_t ^ w6_t ^ w0_t ^ we_t), 1u); SHA1_STEP (SHA1_F1, A, B, C, D, E, we_t);
86 wf_t = rotl32 ((wc_t ^ w7_t ^ w1_t ^ wf_t), 1u); SHA1_STEP (SHA1_F1, E, A, B, C, D, wf_t);
87 w0_t = rotl32 ((wd_t ^ w8_t ^ w2_t ^ w0_t), 1u); SHA1_STEP (SHA1_F1, D, E, A, B, C, w0_t);
88 w1_t = rotl32 ((we_t ^ w9_t ^ w3_t ^ w1_t), 1u); SHA1_STEP (SHA1_F1, C, D, E, A, B, w1_t);
89 w2_t = rotl32 ((wf_t ^ wa_t ^ w4_t ^ w2_t), 1u); SHA1_STEP (SHA1_F1, B, C, D, E, A, w2_t);
90 w3_t = rotl32 ((w0_t ^ wb_t ^ w5_t ^ w3_t), 1u); SHA1_STEP (SHA1_F1, A, B, C, D, E, w3_t);
91 w4_t = rotl32 ((w1_t ^ wc_t ^ w6_t ^ w4_t), 1u); SHA1_STEP (SHA1_F1, E, A, B, C, D, w4_t);
92 w5_t = rotl32 ((w2_t ^ wd_t ^ w7_t ^ w5_t), 1u); SHA1_STEP (SHA1_F1, D, E, A, B, C, w5_t);
93 w6_t = rotl32 ((w3_t ^ we_t ^ w8_t ^ w6_t), 1u); SHA1_STEP (SHA1_F1, C, D, E, A, B, w6_t);
94 w7_t = rotl32 ((w4_t ^ wf_t ^ w9_t ^ w7_t), 1u); SHA1_STEP (SHA1_F1, B, C, D, E, A, w7_t);
99 w8_t = rotl32 ((w5_t ^ w0_t ^ wa_t ^ w8_t), 1u); SHA1_STEP (SHA1_F2o, A, B, C, D, E, w8_t);
100 w9_t = rotl32 ((w6_t ^ w1_t ^ wb_t ^ w9_t), 1u); SHA1_STEP (SHA1_F2o, E, A, B, C, D, w9_t);
101 wa_t = rotl32 ((w7_t ^ w2_t ^ wc_t ^ wa_t), 1u); SHA1_STEP (SHA1_F2o, D, E, A, B, C, wa_t);
102 wb_t = rotl32 ((w8_t ^ w3_t ^ wd_t ^ wb_t), 1u); SHA1_STEP (SHA1_F2o, C, D, E, A, B, wb_t);
103 wc_t = rotl32 ((w9_t ^ w4_t ^ we_t ^ wc_t), 1u); SHA1_STEP (SHA1_F2o, B, C, D, E, A, wc_t);
104 wd_t = rotl32 ((wa_t ^ w5_t ^ wf_t ^ wd_t), 1u); SHA1_STEP (SHA1_F2o, A, B, C, D, E, wd_t);
105 we_t = rotl32 ((wb_t ^ w6_t ^ w0_t ^ we_t), 1u); SHA1_STEP (SHA1_F2o, E, A, B, C, D, we_t);
106 wf_t = rotl32 ((wc_t ^ w7_t ^ w1_t ^ wf_t), 1u); SHA1_STEP (SHA1_F2o, D, E, A, B, C, wf_t);
107 w0_t = rotl32 ((wd_t ^ w8_t ^ w2_t ^ w0_t), 1u); SHA1_STEP (SHA1_F2o, C, D, E, A, B, w0_t);
108 w1_t = rotl32 ((we_t ^ w9_t ^ w3_t ^ w1_t), 1u); SHA1_STEP (SHA1_F2o, B, C, D, E, A, w1_t);
109 w2_t = rotl32 ((wf_t ^ wa_t ^ w4_t ^ w2_t), 1u); SHA1_STEP (SHA1_F2o, A, B, C, D, E, w2_t);
110 w3_t = rotl32 ((w0_t ^ wb_t ^ w5_t ^ w3_t), 1u); SHA1_STEP (SHA1_F2o, E, A, B, C, D, w3_t);
111 w4_t = rotl32 ((w1_t ^ wc_t ^ w6_t ^ w4_t), 1u); SHA1_STEP (SHA1_F2o, D, E, A, B, C, w4_t);
112 w5_t = rotl32 ((w2_t ^ wd_t ^ w7_t ^ w5_t), 1u); SHA1_STEP (SHA1_F2o, C, D, E, A, B, w5_t);
113 w6_t = rotl32 ((w3_t ^ we_t ^ w8_t ^ w6_t), 1u); SHA1_STEP (SHA1_F2o, B, C, D, E, A, w6_t);
114 w7_t = rotl32 ((w4_t ^ wf_t ^ w9_t ^ w7_t), 1u); SHA1_STEP (SHA1_F2o, A, B, C, D, E, w7_t);
115 w8_t = rotl32 ((w5_t ^ w0_t ^ wa_t ^ w8_t), 1u); SHA1_STEP (SHA1_F2o, E, A, B, C, D, w8_t);
116 w9_t = rotl32 ((w6_t ^ w1_t ^ wb_t ^ w9_t), 1u); SHA1_STEP (SHA1_F2o, D, E, A, B, C, w9_t);
117 wa_t = rotl32 ((w7_t ^ w2_t ^ wc_t ^ wa_t), 1u); SHA1_STEP (SHA1_F2o, C, D, E, A, B, wa_t);
118 wb_t = rotl32 ((w8_t ^ w3_t ^ wd_t ^ wb_t), 1u); SHA1_STEP (SHA1_F2o, B, C, D, E, A, wb_t);
123 wc_t = rotl32 ((w9_t ^ w4_t ^ we_t ^ wc_t), 1u); SHA1_STEP (SHA1_F1, A, B, C, D, E, wc_t);
124 wd_t = rotl32 ((wa_t ^ w5_t ^ wf_t ^ wd_t), 1u); SHA1_STEP (SHA1_F1, E, A, B, C, D, wd_t);
125 we_t = rotl32 ((wb_t ^ w6_t ^ w0_t ^ we_t), 1u); SHA1_STEP (SHA1_F1, D, E, A, B, C, we_t);
126 wf_t = rotl32 ((wc_t ^ w7_t ^ w1_t ^ wf_t), 1u); SHA1_STEP (SHA1_F1, C, D, E, A, B, wf_t);
127 w0_t = rotl32 ((wd_t ^ w8_t ^ w2_t ^ w0_t), 1u); SHA1_STEP (SHA1_F1, B, C, D, E, A, w0_t);
128 w1_t = rotl32 ((we_t ^ w9_t ^ w3_t ^ w1_t), 1u); SHA1_STEP (SHA1_F1, A, B, C, D, E, w1_t);
129 w2_t = rotl32 ((wf_t ^ wa_t ^ w4_t ^ w2_t), 1u); SHA1_STEP (SHA1_F1, E, A, B, C, D, w2_t);
130 w3_t = rotl32 ((w0_t ^ wb_t ^ w5_t ^ w3_t), 1u); SHA1_STEP (SHA1_F1, D, E, A, B, C, w3_t);
131 w4_t = rotl32 ((w1_t ^ wc_t ^ w6_t ^ w4_t), 1u); SHA1_STEP (SHA1_F1, C, D, E, A, B, w4_t);
132 w5_t = rotl32 ((w2_t ^ wd_t ^ w7_t ^ w5_t), 1u); SHA1_STEP (SHA1_F1, B, C, D, E, A, w5_t);
133 w6_t = rotl32 ((w3_t ^ we_t ^ w8_t ^ w6_t), 1u); SHA1_STEP (SHA1_F1, A, B, C, D, E, w6_t);
134 w7_t = rotl32 ((w4_t ^ wf_t ^ w9_t ^ w7_t), 1u); SHA1_STEP (SHA1_F1, E, A, B, C, D, w7_t);
135 w8_t = rotl32 ((w5_t ^ w0_t ^ wa_t ^ w8_t), 1u); SHA1_STEP (SHA1_F1, D, E, A, B, C, w8_t);
136 w9_t = rotl32 ((w6_t ^ w1_t ^ wb_t ^ w9_t), 1u); SHA1_STEP (SHA1_F1, C, D, E, A, B, w9_t);
137 wa_t = rotl32 ((w7_t ^ w2_t ^ wc_t ^ wa_t), 1u); SHA1_STEP (SHA1_F1, B, C, D, E, A, wa_t);
138 wb_t = rotl32 ((w8_t ^ w3_t ^ wd_t ^ wb_t), 1u); SHA1_STEP (SHA1_F1, A, B, C, D, E, wb_t);
139 wc_t = rotl32 ((w9_t ^ w4_t ^ we_t ^ wc_t), 1u); SHA1_STEP (SHA1_F1, E, A, B, C, D, wc_t);
140 wd_t = rotl32 ((wa_t ^ w5_t ^ wf_t ^ wd_t), 1u); SHA1_STEP (SHA1_F1, D, E, A, B, C, wd_t);
141 we_t = rotl32 ((wb_t ^ w6_t ^ w0_t ^ we_t), 1u); SHA1_STEP (SHA1_F1, C, D, E, A, B, we_t);
142 wf_t = rotl32 ((wc_t ^ w7_t ^ w1_t ^ wf_t), 1u); SHA1_STEP (SHA1_F1, B, C, D, E, A, wf_t);
151 static void hmac_sha1_pad (u32 w0[4], u32 w1[4], u32 w2[4], u32 w3[4], u32 ipad[5], u32 opad[5])
153 w0[0] = w0[0] ^ 0x36363636;
154 w0[1] = w0[1] ^ 0x36363636;
155 w0[2] = w0[2] ^ 0x36363636;
156 w0[3] = w0[3] ^ 0x36363636;
157 w1[0] = w1[0] ^ 0x36363636;
158 w1[1] = w1[1] ^ 0x36363636;
159 w1[2] = w1[2] ^ 0x36363636;
160 w1[3] = w1[3] ^ 0x36363636;
161 w2[0] = w2[0] ^ 0x36363636;
162 w2[1] = w2[1] ^ 0x36363636;
163 w2[2] = w2[2] ^ 0x36363636;
164 w2[3] = w2[3] ^ 0x36363636;
165 w3[0] = w3[0] ^ 0x36363636;
166 w3[1] = w3[1] ^ 0x36363636;
167 w3[2] = w3[2] ^ 0x36363636;
168 w3[3] = w3[3] ^ 0x36363636;
176 sha1_transform (w0, w1, w2, w3, ipad);
178 w0[0] = w0[0] ^ 0x6a6a6a6a;
179 w0[1] = w0[1] ^ 0x6a6a6a6a;
180 w0[2] = w0[2] ^ 0x6a6a6a6a;
181 w0[3] = w0[3] ^ 0x6a6a6a6a;
182 w1[0] = w1[0] ^ 0x6a6a6a6a;
183 w1[1] = w1[1] ^ 0x6a6a6a6a;
184 w1[2] = w1[2] ^ 0x6a6a6a6a;
185 w1[3] = w1[3] ^ 0x6a6a6a6a;
186 w2[0] = w2[0] ^ 0x6a6a6a6a;
187 w2[1] = w2[1] ^ 0x6a6a6a6a;
188 w2[2] = w2[2] ^ 0x6a6a6a6a;
189 w2[3] = w2[3] ^ 0x6a6a6a6a;
190 w3[0] = w3[0] ^ 0x6a6a6a6a;
191 w3[1] = w3[1] ^ 0x6a6a6a6a;
192 w3[2] = w3[2] ^ 0x6a6a6a6a;
193 w3[3] = w3[3] ^ 0x6a6a6a6a;
201 sha1_transform (w0, w1, w2, w3, opad);
204 static void hmac_sha1_run (u32 w0[4], u32 w1[4], u32 w2[4], u32 w3[4], u32 ipad[5], u32 opad[5], u32 digest[5])
212 sha1_transform (w0, w1, w2, w3, digest);
229 w3[3] = (64 + 20) * 8;
237 sha1_transform (w0, w1, w2, w3, digest);
240 __kernel void __attribute__((reqd_work_group_size (64, 1, 1))) m05400_m04 (__global pw_t *pws, __global gpu_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global ikepsk_t *ikepsk_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 combs_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
246 const u32 lid = get_local_id (0);
252 const u32 gid = get_global_id (0);
256 wordl0[0] = pws[gid].i[ 0];
257 wordl0[1] = pws[gid].i[ 1];
258 wordl0[2] = pws[gid].i[ 2];
259 wordl0[3] = pws[gid].i[ 3];
263 wordl1[0] = pws[gid].i[ 4];
264 wordl1[1] = pws[gid].i[ 5];
265 wordl1[2] = pws[gid].i[ 6];
266 wordl1[3] = pws[gid].i[ 7];
282 const u32 pw_l_len = pws[gid].pw_len;
284 if (combs_mode == COMBINATOR_MODE_BASE_RIGHT)
286 switch_buffer_by_offset (wordl0, wordl1, wordl2, wordl3, combs_buf[0].pw_len);
293 const u32 nr_len = ikepsk_bufs[salt_pos].nr_len;
294 const u32 msg_len = ikepsk_bufs[salt_pos].msg_len;
298 salt_buf0[0] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 0]);
299 salt_buf0[1] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 1]);
300 salt_buf0[2] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 2]);
301 salt_buf0[3] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 3]);
305 salt_buf1[0] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 4]);
306 salt_buf1[1] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 5]);
307 salt_buf1[2] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 6]);
308 salt_buf1[3] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 7]);
312 salt_buf2[0] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 8]);
313 salt_buf2[1] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 9]);
314 salt_buf2[2] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[10]);
315 salt_buf2[3] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[11]);
319 salt_buf3[0] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[12]);
320 salt_buf3[1] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[13]);
324 __local u32 s_msg_buf[128];
326 const u32 lid2 = lid * 2;
328 s_msg_buf[lid2 + 0] = swap_workaround (ikepsk_bufs[salt_pos].msg_buf[lid2 + 0]);
329 s_msg_buf[lid2 + 1] = swap_workaround (ikepsk_bufs[salt_pos].msg_buf[lid2 + 1]);
331 barrier (CLK_LOCAL_MEM_FENCE);
333 if (gid >= gid_max) return;
339 for (u32 il_pos = 0; il_pos < combs_cnt; il_pos++)
341 const u32 pw_r_len = combs_buf[il_pos].pw_len;
343 const u32 pw_len = pw_l_len + pw_r_len;
347 wordr0[0] = combs_buf[il_pos].i[0];
348 wordr0[1] = combs_buf[il_pos].i[1];
349 wordr0[2] = combs_buf[il_pos].i[2];
350 wordr0[3] = combs_buf[il_pos].i[3];
354 wordr1[0] = combs_buf[il_pos].i[4];
355 wordr1[1] = combs_buf[il_pos].i[5];
356 wordr1[2] = combs_buf[il_pos].i[6];
357 wordr1[3] = combs_buf[il_pos].i[7];
373 if (combs_mode == COMBINATOR_MODE_BASE_LEFT)
375 switch_buffer_by_offset (wordr0, wordr1, wordr2, wordr3, pw_l_len);
380 w0[0] = wordl0[0] | wordr0[0];
381 w0[1] = wordl0[1] | wordr0[1];
382 w0[2] = wordl0[2] | wordr0[2];
383 w0[3] = wordl0[3] | wordr0[3];
387 w1[0] = wordl1[0] | wordr1[0];
388 w1[1] = wordl1[1] | wordr1[1];
389 w1[2] = wordl1[2] | wordr1[2];
390 w1[3] = wordl1[3] | wordr1[3];
394 w2[0] = wordl2[0] | wordr2[0];
395 w2[1] = wordl2[1] | wordr2[1];
396 w2[2] = wordl2[2] | wordr2[2];
397 w2[3] = wordl2[3] | wordr2[3];
401 w3[0] = wordl3[0] | wordr3[0];
402 w3[1] = wordl3[1] | wordr3[1];
403 w3[2] = wordl3[2] | wordr3[2];
404 w3[3] = wordl3[3] | wordr3[3];
412 w0_t[0] = swap_workaround (w0[0]);
413 w0_t[1] = swap_workaround (w0[1]);
414 w0_t[2] = swap_workaround (w0[2]);
415 w0_t[3] = swap_workaround (w0[3]);
419 w1_t[0] = swap_workaround (w1[0]);
420 w1_t[1] = swap_workaround (w1[1]);
421 w1_t[2] = swap_workaround (w1[2]);
422 w1_t[3] = swap_workaround (w1[3]);
441 hmac_sha1_pad (w0_t, w1_t, w2_t, w3_t, ipad, opad);
443 w0_t[0] = salt_buf0[0];
444 w0_t[1] = salt_buf0[1];
445 w0_t[2] = salt_buf0[2];
446 w0_t[3] = salt_buf0[3];
447 w1_t[0] = salt_buf1[0];
448 w1_t[1] = salt_buf1[1];
449 w1_t[2] = salt_buf1[2];
450 w1_t[3] = salt_buf1[3];
451 w2_t[0] = salt_buf2[0];
452 w2_t[1] = salt_buf2[1];
453 w2_t[2] = salt_buf2[2];
454 w2_t[3] = salt_buf2[3];
455 w3_t[0] = salt_buf3[0];
456 w3_t[1] = salt_buf3[1];
458 w3_t[3] = (64 + nr_len) * 8;
462 hmac_sha1_run (w0_t, w1_t, w2_t, w3_t, ipad, opad, digest);
481 hmac_sha1_pad (w0_t, w1_t, w2_t, w3_t, ipad, opad);
486 for (left = ikepsk_bufs[salt_pos].msg_len, off = 0; left >= 56; left -= 64, off += 16)
488 w0_t[0] = s_msg_buf[off + 0];
489 w0_t[1] = s_msg_buf[off + 1];
490 w0_t[2] = s_msg_buf[off + 2];
491 w0_t[3] = s_msg_buf[off + 3];
492 w1_t[0] = s_msg_buf[off + 4];
493 w1_t[1] = s_msg_buf[off + 5];
494 w1_t[2] = s_msg_buf[off + 6];
495 w1_t[3] = s_msg_buf[off + 7];
496 w2_t[0] = s_msg_buf[off + 8];
497 w2_t[1] = s_msg_buf[off + 9];
498 w2_t[2] = s_msg_buf[off + 10];
499 w2_t[3] = s_msg_buf[off + 11];
500 w3_t[0] = s_msg_buf[off + 12];
501 w3_t[1] = s_msg_buf[off + 13];
502 w3_t[2] = s_msg_buf[off + 14];
503 w3_t[3] = s_msg_buf[off + 15];
505 sha1_transform (w0_t, w1_t, w2_t, w3_t, ipad);
508 w0_t[0] = s_msg_buf[off + 0];
509 w0_t[1] = s_msg_buf[off + 1];
510 w0_t[2] = s_msg_buf[off + 2];
511 w0_t[3] = s_msg_buf[off + 3];
512 w1_t[0] = s_msg_buf[off + 4];
513 w1_t[1] = s_msg_buf[off + 5];
514 w1_t[2] = s_msg_buf[off + 6];
515 w1_t[3] = s_msg_buf[off + 7];
516 w2_t[0] = s_msg_buf[off + 8];
517 w2_t[1] = s_msg_buf[off + 9];
518 w2_t[2] = s_msg_buf[off + 10];
519 w2_t[3] = s_msg_buf[off + 11];
520 w3_t[0] = s_msg_buf[off + 12];
521 w3_t[1] = s_msg_buf[off + 13];
523 w3_t[3] = (64 + msg_len) * 8;
525 hmac_sha1_run (w0_t, w1_t, w2_t, w3_t, ipad, opad, digest);
527 const u32 r0 = digest[3];
528 const u32 r1 = digest[4];
529 const u32 r2 = digest[2];
530 const u32 r3 = digest[1];
536 __kernel void __attribute__((reqd_work_group_size (64, 1, 1))) m05400_m08 (__global pw_t *pws, __global gpu_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global ikepsk_t *ikepsk_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 combs_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
540 __kernel void __attribute__((reqd_work_group_size (64, 1, 1))) m05400_m16 (__global pw_t *pws, __global gpu_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global ikepsk_t *ikepsk_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 combs_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
544 __kernel void __attribute__((reqd_work_group_size (64, 1, 1))) m05400_s04 (__global pw_t *pws, __global gpu_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global ikepsk_t *ikepsk_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 combs_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
550 const u32 lid = get_local_id (0);
556 const u32 gid = get_global_id (0);
560 wordl0[0] = pws[gid].i[ 0];
561 wordl0[1] = pws[gid].i[ 1];
562 wordl0[2] = pws[gid].i[ 2];
563 wordl0[3] = pws[gid].i[ 3];
567 wordl1[0] = pws[gid].i[ 4];
568 wordl1[1] = pws[gid].i[ 5];
569 wordl1[2] = pws[gid].i[ 6];
570 wordl1[3] = pws[gid].i[ 7];
586 const u32 pw_l_len = pws[gid].pw_len;
588 if (combs_mode == COMBINATOR_MODE_BASE_RIGHT)
590 switch_buffer_by_offset (wordl0, wordl1, wordl2, wordl3, combs_buf[0].pw_len);
597 const u32 nr_len = ikepsk_bufs[salt_pos].nr_len;
598 const u32 msg_len = ikepsk_bufs[salt_pos].msg_len;
602 salt_buf0[0] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 0]);
603 salt_buf0[1] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 1]);
604 salt_buf0[2] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 2]);
605 salt_buf0[3] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 3]);
609 salt_buf1[0] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 4]);
610 salt_buf1[1] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 5]);
611 salt_buf1[2] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 6]);
612 salt_buf1[3] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 7]);
616 salt_buf2[0] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 8]);
617 salt_buf2[1] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[ 9]);
618 salt_buf2[2] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[10]);
619 salt_buf2[3] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[11]);
623 salt_buf3[0] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[12]);
624 salt_buf3[1] = swap_workaround (ikepsk_bufs[salt_pos].nr_buf[13]);
628 __local u32 s_msg_buf[128];
630 const u32 lid2 = lid * 2;
632 s_msg_buf[lid2 + 0] = swap_workaround (ikepsk_bufs[salt_pos].msg_buf[lid2 + 0]);
633 s_msg_buf[lid2 + 1] = swap_workaround (ikepsk_bufs[salt_pos].msg_buf[lid2 + 1]);
635 barrier (CLK_LOCAL_MEM_FENCE);
637 if (gid >= gid_max) return;
643 const u32 search[4] =
645 digests_buf[digests_offset].digest_buf[DGST_R0],
646 digests_buf[digests_offset].digest_buf[DGST_R1],
647 digests_buf[digests_offset].digest_buf[DGST_R2],
648 digests_buf[digests_offset].digest_buf[DGST_R3]
655 for (u32 il_pos = 0; il_pos < combs_cnt; il_pos++)
657 const u32 pw_r_len = combs_buf[il_pos].pw_len;
659 const u32 pw_len = pw_l_len + pw_r_len;
663 wordr0[0] = combs_buf[il_pos].i[0];
664 wordr0[1] = combs_buf[il_pos].i[1];
665 wordr0[2] = combs_buf[il_pos].i[2];
666 wordr0[3] = combs_buf[il_pos].i[3];
670 wordr1[0] = combs_buf[il_pos].i[4];
671 wordr1[1] = combs_buf[il_pos].i[5];
672 wordr1[2] = combs_buf[il_pos].i[6];
673 wordr1[3] = combs_buf[il_pos].i[7];
689 if (combs_mode == COMBINATOR_MODE_BASE_LEFT)
691 switch_buffer_by_offset (wordr0, wordr1, wordr2, wordr3, pw_l_len);
696 w0[0] = wordl0[0] | wordr0[0];
697 w0[1] = wordl0[1] | wordr0[1];
698 w0[2] = wordl0[2] | wordr0[2];
699 w0[3] = wordl0[3] | wordr0[3];
703 w1[0] = wordl1[0] | wordr1[0];
704 w1[1] = wordl1[1] | wordr1[1];
705 w1[2] = wordl1[2] | wordr1[2];
706 w1[3] = wordl1[3] | wordr1[3];
710 w2[0] = wordl2[0] | wordr2[0];
711 w2[1] = wordl2[1] | wordr2[1];
712 w2[2] = wordl2[2] | wordr2[2];
713 w2[3] = wordl2[3] | wordr2[3];
717 w3[0] = wordl3[0] | wordr3[0];
718 w3[1] = wordl3[1] | wordr3[1];
719 w3[2] = wordl3[2] | wordr3[2];
720 w3[3] = wordl3[3] | wordr3[3];
728 w0_t[0] = swap_workaround (w0[0]);
729 w0_t[1] = swap_workaround (w0[1]);
730 w0_t[2] = swap_workaround (w0[2]);
731 w0_t[3] = swap_workaround (w0[3]);
735 w1_t[0] = swap_workaround (w1[0]);
736 w1_t[1] = swap_workaround (w1[1]);
737 w1_t[2] = swap_workaround (w1[2]);
738 w1_t[3] = swap_workaround (w1[3]);
757 hmac_sha1_pad (w0_t, w1_t, w2_t, w3_t, ipad, opad);
759 w0_t[0] = salt_buf0[0];
760 w0_t[1] = salt_buf0[1];
761 w0_t[2] = salt_buf0[2];
762 w0_t[3] = salt_buf0[3];
763 w1_t[0] = salt_buf1[0];
764 w1_t[1] = salt_buf1[1];
765 w1_t[2] = salt_buf1[2];
766 w1_t[3] = salt_buf1[3];
767 w2_t[0] = salt_buf2[0];
768 w2_t[1] = salt_buf2[1];
769 w2_t[2] = salt_buf2[2];
770 w2_t[3] = salt_buf2[3];
771 w3_t[0] = salt_buf3[0];
772 w3_t[1] = salt_buf3[1];
774 w3_t[3] = (64 + nr_len) * 8;
778 hmac_sha1_run (w0_t, w1_t, w2_t, w3_t, ipad, opad, digest);
797 hmac_sha1_pad (w0_t, w1_t, w2_t, w3_t, ipad, opad);
802 for (left = ikepsk_bufs[salt_pos].msg_len, off = 0; left >= 56; left -= 64, off += 16)
804 w0_t[0] = s_msg_buf[off + 0];
805 w0_t[1] = s_msg_buf[off + 1];
806 w0_t[2] = s_msg_buf[off + 2];
807 w0_t[3] = s_msg_buf[off + 3];
808 w1_t[0] = s_msg_buf[off + 4];
809 w1_t[1] = s_msg_buf[off + 5];
810 w1_t[2] = s_msg_buf[off + 6];
811 w1_t[3] = s_msg_buf[off + 7];
812 w2_t[0] = s_msg_buf[off + 8];
813 w2_t[1] = s_msg_buf[off + 9];
814 w2_t[2] = s_msg_buf[off + 10];
815 w2_t[3] = s_msg_buf[off + 11];
816 w3_t[0] = s_msg_buf[off + 12];
817 w3_t[1] = s_msg_buf[off + 13];
818 w3_t[2] = s_msg_buf[off + 14];
819 w3_t[3] = s_msg_buf[off + 15];
821 sha1_transform (w0_t, w1_t, w2_t, w3_t, ipad);
824 w0_t[0] = s_msg_buf[off + 0];
825 w0_t[1] = s_msg_buf[off + 1];
826 w0_t[2] = s_msg_buf[off + 2];
827 w0_t[3] = s_msg_buf[off + 3];
828 w1_t[0] = s_msg_buf[off + 4];
829 w1_t[1] = s_msg_buf[off + 5];
830 w1_t[2] = s_msg_buf[off + 6];
831 w1_t[3] = s_msg_buf[off + 7];
832 w2_t[0] = s_msg_buf[off + 8];
833 w2_t[1] = s_msg_buf[off + 9];
834 w2_t[2] = s_msg_buf[off + 10];
835 w2_t[3] = s_msg_buf[off + 11];
836 w3_t[0] = s_msg_buf[off + 12];
837 w3_t[1] = s_msg_buf[off + 13];
839 w3_t[3] = (64 + msg_len) * 8;
841 hmac_sha1_run (w0_t, w1_t, w2_t, w3_t, ipad, opad, digest);
843 const u32 r0 = digest[3];
844 const u32 r1 = digest[4];
845 const u32 r2 = digest[2];
846 const u32 r3 = digest[1];
852 __kernel void __attribute__((reqd_work_group_size (64, 1, 1))) m05400_s08 (__global pw_t *pws, __global gpu_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global ikepsk_t *ikepsk_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 combs_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)
856 __kernel void __attribute__((reqd_work_group_size (64, 1, 1))) m05400_s16 (__global pw_t *pws, __global gpu_rule_t *rules_buf, __global comb_t *combs_buf, __global bf_t *bfs_buf, __global void *tmps, __global void *hooks, __global u32 *bitmaps_buf_s1_a, __global u32 *bitmaps_buf_s1_b, __global u32 *bitmaps_buf_s1_c, __global u32 *bitmaps_buf_s1_d, __global u32 *bitmaps_buf_s2_a, __global u32 *bitmaps_buf_s2_b, __global u32 *bitmaps_buf_s2_c, __global u32 *bitmaps_buf_s2_d, __global plain_t *plains_buf, __global digest_t *digests_buf, __global u32 *hashes_shown, __global salt_t *salt_bufs, __global ikepsk_t *ikepsk_bufs, __global u32 *d_return_buf, __global u32 *d_scryptV_buf, const u32 bitmap_mask, const u32 bitmap_shift1, const u32 bitmap_shift2, const u32 salt_pos, const u32 loop_pos, const u32 loop_cnt, const u32 combs_cnt, const u32 digests_cnt, const u32 digests_offset, const u32 combs_mode, const u32 gid_max)