# Pseudorandom number generator with key erasure / forward secrecy / # backtracking resistance using ChaCha20. # Copyright (c) 2015, 2016 Taylor R. Campbell # All rights reserved. # # Redistribution and use in source and binary forms, with or without # modification, are permitted provided that the following conditions # are met: # 1. Redistributions of source code must retain the above copyright # notice, this list of conditions and the following disclaimer. # 2. Redistributions in binary form must reproduce the above copyright # notice, this list of conditions and the following disclaimer in the # documentation and/or other materials provided with the distribution. # # THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND # ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE # IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE # ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE # FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL # DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS # OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) # HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT # LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY # OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF # SUCH DAMAGE. import chacha import os import struct import threading class PRNG(object): _const32 = chacha.const32 _zero = [0,0,0,0, 0,0,0,0] def __init__(self, seed): self._key = list(struct.unpack('1 word. r |= self.random32() if r < l: continue return (r % n) def random_bytearray(self, buf, start, end): assert end <= len(buf) assert start <= end key = self._key zero = self._zero const32 = self._const32 nbytes = end - start nblocks = nbytes//32 if nblocks < 2: for i in range(nblocks): chacha.core(20, key, zero, key, const32) buf[start + 32*i : start + 32*(i + 1)] = \ struct.pack('> 32 buf[start + 64*i : start + 64*(i + 1)] = \ struct.pack('