crypton-2.1.8: cbits/mlkem/import.sh
#!/bin/sh
# Re-import the vendored parts of the PQ Code Package's mlkem-native.
#
# The files are kept unmodified. Everything crypton decides -- which
# parameter sets exist, what the symbols are called, that there is no
# randomised API -- is decided in cbits/mlkem/crypton_mlkem.c and in
# crypton.cabal, not by editing anything here. Run this from cbits/mlkem:
#
# ./import.sh [tag-or-commit]
#
# and commit the result together with the COMMIT line it writes, so that the
# tree always says which upstream revision it holds.
set -eu
REPO=https://github.com/pq-code-package/mlkem-native
REV=${1:-v2.0.0}
HERE=$(cd "$(dirname "$0")" && pwd)
TMP=$(mktemp -d)
trap 'rm -rf "$TMP"' EXIT
git clone -q "$REPO" "$TMP/u"
git -C "$TMP/u" checkout -q "$REV"
rm -rf "$HERE/src"
cp "$TMP/u/mlkem/mlkem_native.c" "$HERE/"
cp "$TMP/u/mlkem/mlkem_native.h" "$HERE/"
cp "$TMP/u/mlkem/mlkem_native_asm.S" "$HERE/"
cp "$TMP/u/mlkem/mlkem_native_config.h" "$HERE/"
cp -R "$TMP/u/mlkem/src" "$HERE/src"
cp "$TMP/u/LICENSE" "$HERE/LICENSE"
# The backends for architectures crypton does not build for. Every
# reference to them is behind an MLK_SYS_ guard that cannot be true on the
# two it does, so dropping them changes no build and keeps a few dozen files
# of unreachable assembly out of the release tarball. If crypton ever
# wants one of them, delete its line here rather than patching anything.
rm -rf "$HERE/src/native/riscv64" "$HERE/src/native/ppc64le"
rm -rf "$HERE/src/fips202/native/armv81m"
git -C "$TMP/u" rev-parse HEAD > "$HERE/COMMIT"
git -C "$TMP/u" describe --tags --exact-match 2>/dev/null >> "$HERE/COMMIT" || true
echo "imported $(head -1 "$HERE/COMMIT")"