Skip to content

Releases: paragonie/sodium_compat

Version 1.11.0

Choose a tag to compare

@paragonie-scott paragonie-scott released this 12 Sep 00:02
v1.11.0
  • #91, #93, #96 - We now use PHPStan in addition to Psalm in Travis CI
  • #92, #95 - Added missing features from polyfill
    • sodium_add()
    • sodium_base642bin()
    • sodium_bin2base64()
    • sodium_crypto_kdf_derive_from_key()
    • sodium_crypto_kdf_keygen()
    • sodium_crypto_kx_client_session_keys()
    • sodium_crypto_kx_keypair()
    • sodium_crypto_kx_publickey()
    • sodium_crypto_kx_secretkey()
    • sodium_crypto_kx_seed_keypair()
    • sodium_crypto_kx_server_session_keys()
    • sodium_crypto_pwhash_str_needs_rehash()
    • sodium_crypto_secretstream_xchacha20poly1305_keygen()
    • sodium_crypto_secretstream_xchacha20poly1305_init_push()
    • sodium_crypto_secretstream_xchacha20poly1305_push()
    • sodium_crypto_secretstream_xchacha20poly1305_init_pull()
    • sodium_crypto_secretstream_xchacha20poly1305_pull()
    • sodium_crypto_secretstream_xchacha20poly1305_rekey()
    • sodium_crypto_sign_keypair_from_secretkey_and_publickey()
    • sodium_pad()
    • sodium_unpad()

Version 1.10.1

Choose a tag to compare

@paragonie-scott paragonie-scott released this 12 Jul 16:40
v1.10.1

This merely exposes an internal API used by the the XChaCha20 RFC test vectors.

Version 1.10.0

Choose a tag to compare

@paragonie-scott paragonie-scott released this 13 May 16:21
v1.10.0

New method:

  • ParagonIE_Sodium_Compat::runtime_speed_test() for estimating if our 32-bit implementation is slow enough to risk timeouts on e.g. Ed25519 verification.
    • Returns TRUE is everything is safe.
    • Returns FALSE if performance is a concern.

Version 1.9.4

Choose a tag to compare

@paragonie-scott paragonie-scott released this 10 May 03:07
v1.9.4
  • Applied the same optimizations from ParagonIE_Sodium_Core32_Int64 to ParagonIE_Sodium_Core32_Int32. This won't have as much of an impact on performance as v1.9.2 did, but it helps.

Version 1.9.3

Choose a tag to compare

@paragonie-scott paragonie-scott released this 09 May 19:18

Almost identical to v1.9.2 except I added a type-hint so Psalm won't report a false positive to projects that use our library.

Version 1.9.2

Choose a tag to compare

@paragonie-scott paragonie-scott released this 09 May 19:09
v1.9.2
d30e880
  • The ParagonIE_Sodium_Compat::$fastMult flag now exposes an optimized integer multiplication implementation on 32-bit systems. Previously it only optimized 64-bit platforms. This should result in a 9x-10x speedup on average.

Version 1.9.1

Choose a tag to compare

@paragonie-scott paragonie-scott released this 20 Mar 17:30
v1.9.1

Fix performance issue with crypto_kx() polyfill. It was always calling the PHP implementation of scalarmult() instead of trying the PHP extension instead.

Version 1.9.0

Choose a tag to compare

@paragonie-scott paragonie-scott released this 06 Mar 17:23
v1.9.0
  • The crypto_aead_xchacha20poly1305_ietf_* polyfill will now correctly use the native (ext/sodium) API if the functions exist.

Version 1.8.0

Choose a tag to compare

@paragonie-scott paragonie-scott released this 30 Nov 05:16
v1.8.0
  • Added ParagonIE_Sodium_Compat::polyfill_is_fast() for runtime decision-making. It will return FALSE if the 32-bit implementation is going to be invoked.
  • Added missing version constants #81
  • sodium_crypto_box_seal_open() will no longer silently catch all exceptions and return false, only the ones necessary for behavior compatibility with ext/sodium

Version 1.7.0

Choose a tag to compare

@paragonie-scott paragonie-scott released this 22 Sep 04:15
v1.7.0
  • Improved performance on 32-bit and 64-bit platforms by reducing the number of cycles needed for constant-time multiplication in our Curve25519 and Poly1305 implementations. The actual numbers will vary depending on machine jitter. That being said:
    • 32-bit:
      • Curve25519 should be to 10% faster than in v1.6.6
      • Poly1305 should be up to 25% faster than in v1.6.6
    • 64-bit (these numbers are mostly irrelevant if you already set ParagonIE_Sodium_Compat::$fastMult to true):
      • Curve25519 should be to 15% faster than in v1.6.6
      • Poly1305 should be up to 20% faster than in v1.6.6
  • Removed dead code (including the Field Element constructor, which was a vestige of an earlier design; Field Elements always have 10 integers in them).
  • Comments, docblocks, and whitespace consistency.

This should be the last release for a while. A hypothetical v1.8.0 would include optional GMP support (which should get performance closer to what libsodium itself offers, and should be available to both 32-bit and 64-bit platforms).

That being said, we're much happier with the stability and performance of ParagonIE_Sodium_Core32_* than we were with v1.6.0.

I'd like to thank everyone who has reported bugs, sent patches, or shared optimization strategies with our team over the years. You've helped to bring open source, state-of-the-art cryptography to the hands every PHP developer (one way or another) and had an immeasurable positive impact on many software developer ecosystems. You all rock!