mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-20 23:37:33 +09:00
Replace NSS with Pale Moon's
This commit is contained in:
parent
ff1e5e48bf
commit
8c2e376f94
2870 changed files with 1762232 additions and 1374220 deletions
0
security/nss/lib/freebl/mpi/doc/build
Normal file → Executable file
0
security/nss/lib/freebl/mpi/doc/build
Normal file → Executable file
|
|
@ -198,7 +198,7 @@ L18:
|
|||
mov dword ptr [8+rbx], edi
|
||||
je L9
|
||||
lea r10d, dword ptr [-2+rdx]
|
||||
cmp dword ptr [r11+r10*8], 0
|
||||
cmp qword ptr [r11+r10*8], 0
|
||||
je L18
|
||||
L9:
|
||||
mov edx, dword ptr [8+rbx]
|
||||
|
|
@ -689,7 +689,7 @@ L43:
|
|||
mov dword ptr [8+rbx], edi
|
||||
je L35
|
||||
lea eax, dword ptr [-2+rdx]
|
||||
cmp dword ptr [r11+rax*8], 0
|
||||
cmp qword ptr [r11+rax*8], 0
|
||||
je L43
|
||||
L35:
|
||||
mov r11d, dword ptr [8+rbx]
|
||||
|
|
@ -2268,7 +2268,7 @@ L84:
|
|||
mov dword ptr [8+rbx], edi
|
||||
je L76
|
||||
lea eax, dword ptr [-2+rdx]
|
||||
cmp dword ptr [r11+rax*8], 0
|
||||
cmp qword ptr [r11+rax*8], 0
|
||||
je L84
|
||||
L76:
|
||||
mov edx, dword ptr [8+rbx]
|
||||
|
|
@ -7830,7 +7830,7 @@ L157:
|
|||
mov dword ptr [8+r13], ebx
|
||||
je L149
|
||||
lea r12d, dword ptr [-2+rdx]
|
||||
cmp dword ptr [r9+r12*8], 0
|
||||
cmp qword ptr [r9+r12*8], 0
|
||||
je L157
|
||||
L149:
|
||||
mov r9d, dword ptr [8+r13]
|
||||
|
|
@ -7990,7 +7990,7 @@ s_mp_sqr_comba_4 PROC
|
|||
lea ecx, dword ptr [-1+rdx]
|
||||
mov rsi, qword ptr [16+r11]
|
||||
mov r10d, ecx
|
||||
cmp dword ptr [rsi+r10*8], 0
|
||||
cmp qword ptr [rsi+r10*8], 0
|
||||
jne L166
|
||||
mov edx, ecx
|
||||
ALIGN 16
|
||||
|
|
@ -8000,7 +8000,7 @@ L167:
|
|||
je L171
|
||||
dec edx
|
||||
mov eax, edx
|
||||
cmp dword ptr [rsi+rax*8], 0
|
||||
cmp qword ptr [rsi+rax*8], 0
|
||||
je L167
|
||||
mov dword ptr [8+r11], ecx
|
||||
mov edx, ecx
|
||||
|
|
@ -8415,7 +8415,7 @@ s_mp_sqr_comba_8 PROC
|
|||
lea ecx, dword ptr [-1+rdx]
|
||||
mov rsi, qword ptr [16+rbp]
|
||||
mov r14d, ecx
|
||||
cmp dword ptr [rsi+r14*8], 0
|
||||
cmp qword ptr [rsi+r14*8], 0
|
||||
jne L190
|
||||
mov edx, ecx
|
||||
ALIGN 16
|
||||
|
|
@ -8425,7 +8425,7 @@ L191:
|
|||
je L195
|
||||
dec edx
|
||||
mov r9d, edx
|
||||
cmp dword ptr [rsi+r9*8], 0
|
||||
cmp qword ptr [rsi+r9*8], 0
|
||||
je L191
|
||||
mov dword ptr [8+rbp], ecx
|
||||
mov edx, ecx
|
||||
|
|
@ -9511,7 +9511,7 @@ s_mp_sqr_comba_16 PROC ; A "FRAME" function
|
|||
lea ecx, dword ptr [-1+rdx]
|
||||
mov rsi, qword ptr [16+r14]
|
||||
mov r9d, ecx
|
||||
cmp dword ptr [rsi+r9*8], 0
|
||||
cmp qword ptr [rsi+r9*8], 0
|
||||
jne L230
|
||||
mov edx, ecx
|
||||
ALIGN 16
|
||||
|
|
@ -9521,7 +9521,7 @@ L231:
|
|||
je L235
|
||||
dec edx
|
||||
mov eax, edx
|
||||
cmp dword ptr [rsi+rax*8], 0
|
||||
cmp qword ptr [rsi+rax*8], 0
|
||||
je L231
|
||||
mov dword ptr [8+r14], ecx
|
||||
mov edx, ecx
|
||||
|
|
@ -13023,7 +13023,7 @@ s_mp_sqr_comba_32 PROC ; A "FRAME" function
|
|||
lea ecx, dword ptr [-1+rdx]
|
||||
mov rsi, qword ptr [16+r14]
|
||||
mov r10d, ecx
|
||||
cmp dword ptr [rsi+r10*8], 0
|
||||
cmp qword ptr [rsi+r10*8], 0
|
||||
jne L302
|
||||
mov edx, ecx
|
||||
ALIGN 16
|
||||
|
|
@ -13033,7 +13033,7 @@ L303:
|
|||
je L307
|
||||
dec edx
|
||||
mov eax, edx
|
||||
cmp dword ptr [rsi+rax*8], 0
|
||||
cmp qword ptr [rsi+rax*8], 0
|
||||
je L303
|
||||
mov dword ptr [8+r14], ecx
|
||||
mov edx, ecx
|
||||
|
|
|
|||
|
|
@ -7,11 +7,10 @@
|
|||
#include "mplogic.h"
|
||||
#include "mpi-priv.h"
|
||||
|
||||
const mp_digit mp_gf2m_sqr_tb[16] =
|
||||
{
|
||||
0, 1, 4, 5, 16, 17, 20, 21,
|
||||
64, 65, 68, 69, 80, 81, 84, 85
|
||||
};
|
||||
const mp_digit mp_gf2m_sqr_tb[16] = {
|
||||
0, 1, 4, 5, 16, 17, 20, 21,
|
||||
64, 65, 68, 69, 80, 81, 84, 85
|
||||
};
|
||||
|
||||
/* Multiply two binary polynomials mp_digits a, b.
|
||||
* Result is a polynomial with degree < 2 * MP_DIGIT_BITS - 1.
|
||||
|
|
|
|||
|
|
@ -39,7 +39,8 @@ freebl_cpuid(unsigned long op, unsigned long *eax,
|
|||
unsigned long *ebx, unsigned long *ecx,
|
||||
unsigned long *edx)
|
||||
{
|
||||
__asm__("cpuid\n\t"
|
||||
__asm__("xor %%ecx, %%ecx\n\t"
|
||||
"cpuid\n\t"
|
||||
: "=a"(*eax),
|
||||
"=b"(*ebx),
|
||||
"=c"(*ecx),
|
||||
|
|
@ -726,10 +727,10 @@ s_mpi_getProcessorLineSize()
|
|||
static inline void
|
||||
dcbzl(char *array)
|
||||
{
|
||||
register char *a asm("r2") = array;
|
||||
__asm__ __volatile__("dcbzl %0,0"
|
||||
: "=r"(a)
|
||||
: "0"(a));
|
||||
__asm__("dcbzl %0, %1"
|
||||
: /*no result*/
|
||||
: "b%"(array), "r"(0)
|
||||
: "memory");
|
||||
}
|
||||
|
||||
#define PPC_DO_ALIGN(x, y) ((char *)((((long long)(x)) + ((y)-1)) & ~((y)-1)))
|
||||
|
|
|
|||
|
|
@ -157,7 +157,7 @@ mp_err s_mp_invmod_2d(const mp_int *a, mp_size k, mp_int *c);
|
|||
mp_err s_mp_invmod_even_m(const mp_int *a, const mp_int *m, mp_int *c);
|
||||
|
||||
#ifdef NSS_USE_COMBA
|
||||
|
||||
PR_STATIC_ASSERT(sizeof(mp_digit) == 8);
|
||||
#define IS_POWER_OF_2(a) ((a) && !((a) & ((a)-1)))
|
||||
|
||||
void s_mp_mul_comba_4(const mp_int *A, const mp_int *B, mp_int *C);
|
||||
|
|
@ -204,6 +204,9 @@ void MPI_ASM_DECL s_mpv_mul_d_add(const mp_digit *a, mp_size a_len,
|
|||
void MPI_ASM_DECL s_mpv_mul_d_add_prop(const mp_digit *a,
|
||||
mp_size a_len, mp_digit b,
|
||||
mp_digit *c);
|
||||
void MPI_ASM_DECL s_mpv_mul_d_add_propCT(const mp_digit *a,
|
||||
mp_size a_len, mp_digit b,
|
||||
mp_digit *c, mp_size c_len);
|
||||
void MPI_ASM_DECL s_mpv_sqr_add_prop(const mp_digit *a,
|
||||
mp_size a_len,
|
||||
mp_digit *sqrs);
|
||||
|
|
|
|||
|
|
@ -9,9 +9,8 @@
|
|||
|
||||
#include "mpi-priv.h"
|
||||
#include "mplogic.h"
|
||||
#if defined(OSF1)
|
||||
#include <c_asm.h>
|
||||
#endif
|
||||
|
||||
#include <assert.h>
|
||||
|
||||
#if defined(__arm__) && \
|
||||
((defined(__thumb__) && !defined(__thumb2__)) || defined(__ARM_ARCH_3__))
|
||||
|
|
@ -805,15 +804,18 @@ CLEANUP:
|
|||
|
||||
/* }}} */
|
||||
|
||||
/* {{{ mp_mul(a, b, c) */
|
||||
/* {{{ s_mp_mulg(a, b, c) */
|
||||
|
||||
/*
|
||||
mp_mul(a, b, c)
|
||||
s_mp_mulg(a, b, c)
|
||||
|
||||
Compute c = a * b. All parameters may be identical.
|
||||
Compute c = a * b. All parameters may be identical. if constantTime is set,
|
||||
then the operations are done in constant time. The original is mostly
|
||||
constant time as long as s_mpv_mul_d_add() is constant time. This is true
|
||||
of the x86 assembler, as well as the current c code.
|
||||
*/
|
||||
mp_err
|
||||
mp_mul(const mp_int *a, const mp_int *b, mp_int *c)
|
||||
s_mp_mulg(const mp_int *a, const mp_int *b, mp_int *c, int constantTime)
|
||||
{
|
||||
mp_digit *pb;
|
||||
mp_int tmp;
|
||||
|
|
@ -849,7 +851,14 @@ mp_mul(const mp_int *a, const mp_int *b, mp_int *c)
|
|||
goto CLEANUP;
|
||||
|
||||
#ifdef NSS_USE_COMBA
|
||||
if ((MP_USED(a) == MP_USED(b)) && IS_POWER_OF_2(MP_USED(b))) {
|
||||
/* comba isn't constant time because it clamps! If we cared
|
||||
* (we needed a constant time version of multiply that was 'faster'
|
||||
* we could easily pass constantTime down to the comba code and
|
||||
* get it to skip the clamp... but here are assembler versions
|
||||
* which add comba to platforms that can't compile the normal
|
||||
* comba's imbedded assembler which would also need to change, so
|
||||
* for now we just skip comba when we are running constant time. */
|
||||
if (!constantTime && (MP_USED(a) == MP_USED(b)) && IS_POWER_OF_2(MP_USED(b))) {
|
||||
if (MP_USED(a) == 4) {
|
||||
s_mp_mul_comba_4(a, b, c);
|
||||
goto CLEANUP;
|
||||
|
|
@ -879,13 +888,15 @@ mp_mul(const mp_int *a, const mp_int *b, mp_int *c)
|
|||
mp_digit b_i = *pb++;
|
||||
|
||||
/* Inner product: Digits of a */
|
||||
if (b_i)
|
||||
if (constantTime || b_i)
|
||||
s_mpv_mul_d_add(MP_DIGITS(a), useda, b_i, MP_DIGITS(c) + ib);
|
||||
else
|
||||
MP_DIGIT(c, ib + useda) = b_i;
|
||||
}
|
||||
|
||||
s_mp_clamp(c);
|
||||
if (!constantTime) {
|
||||
s_mp_clamp(c);
|
||||
}
|
||||
|
||||
if (SIGN(a) == SIGN(b) || s_mp_cmp_d(c, 0) == MP_EQ)
|
||||
SIGN(c) = ZPOS;
|
||||
|
|
@ -895,10 +906,54 @@ mp_mul(const mp_int *a, const mp_int *b, mp_int *c)
|
|||
CLEANUP:
|
||||
mp_clear(&tmp);
|
||||
return res;
|
||||
} /* end smp_mulg() */
|
||||
|
||||
/* }}} */
|
||||
|
||||
/* {{{ mp_mul(a, b, c) */
|
||||
|
||||
/*
|
||||
mp_mul(a, b, c)
|
||||
|
||||
Compute c = a * b. All parameters may be identical.
|
||||
*/
|
||||
|
||||
mp_err
|
||||
mp_mul(const mp_int *a, const mp_int *b, mp_int *c)
|
||||
{
|
||||
return s_mp_mulg(a, b, c, 0);
|
||||
} /* end mp_mul() */
|
||||
|
||||
/* }}} */
|
||||
|
||||
/* {{{ mp_mulCT(a, b, c) */
|
||||
|
||||
/*
|
||||
mp_mulCT(a, b, c)
|
||||
|
||||
Compute c = a * b. In constant time. Parameters may not be identical.
|
||||
NOTE: a and b may be modified.
|
||||
*/
|
||||
|
||||
mp_err
|
||||
mp_mulCT(mp_int *a, mp_int *b, mp_int *c, mp_size setSize)
|
||||
{
|
||||
mp_err res;
|
||||
|
||||
/* make the multiply values fixed length so multiply
|
||||
* doesn't leak the length. at this point all the
|
||||
* values are blinded, but once we finish we want the
|
||||
* output size to be hidden (so no clamping the out put) */
|
||||
MP_CHECKOK(s_mp_pad(a, setSize));
|
||||
MP_CHECKOK(s_mp_pad(b, setSize));
|
||||
MP_CHECKOK(s_mp_pad(c, 2 * setSize));
|
||||
MP_CHECKOK(s_mp_mulg(a, b, c, 1));
|
||||
CLEANUP:
|
||||
return res;
|
||||
} /* end mp_mulCT() */
|
||||
|
||||
/* }}} */
|
||||
|
||||
/* {{{ mp_sqr(a, sqr) */
|
||||
|
||||
#if MP_SQUARE
|
||||
|
|
@ -1271,6 +1326,138 @@ mp_mod(const mp_int *a, const mp_int *m, mp_int *c)
|
|||
|
||||
/* }}} */
|
||||
|
||||
/* {{{ s_mp_subCT_d(a, b, borrow, c) */
|
||||
|
||||
/*
|
||||
s_mp_subCT_d(a, b, borrow, c)
|
||||
|
||||
Compute c = (a -b) - subtract in constant time. returns borrow
|
||||
*/
|
||||
mp_digit
|
||||
s_mp_subCT_d(mp_digit a, mp_digit b, mp_digit borrow, mp_digit *ret)
|
||||
{
|
||||
*ret = a - b - borrow;
|
||||
return MP_CT_LTU(a, *ret) | (MP_CT_EQ(a, *ret) & borrow);
|
||||
} /* s_mp_subCT_d() */
|
||||
|
||||
/* }}} */
|
||||
|
||||
/* {{{ mp_subCT(a, b, ret, borrow) */
|
||||
|
||||
/* return ret= a - b and borrow in borrow. done in constant time.
|
||||
* b could be modified.
|
||||
*/
|
||||
mp_err
|
||||
mp_subCT(const mp_int *a, mp_int *b, mp_int *ret, mp_digit *borrow)
|
||||
{
|
||||
mp_size used_a = MP_USED(a);
|
||||
mp_size i;
|
||||
mp_err res;
|
||||
|
||||
MP_CHECKOK(s_mp_pad(b, used_a));
|
||||
MP_CHECKOK(s_mp_pad(ret, used_a));
|
||||
*borrow = 0;
|
||||
for (i = 0; i < used_a; i++) {
|
||||
*borrow = s_mp_subCT_d(MP_DIGIT(a, i), MP_DIGIT(b, i), *borrow,
|
||||
&MP_DIGIT(ret, i));
|
||||
}
|
||||
|
||||
res = MP_OKAY;
|
||||
CLEANUP:
|
||||
return res;
|
||||
} /* end mp_subCT() */
|
||||
|
||||
/* }}} */
|
||||
|
||||
/* {{{ mp_selectCT(cond, a, b, ret) */
|
||||
|
||||
/*
|
||||
* return ret= cond ? a : b; cond should be either 0 or 1
|
||||
*/
|
||||
mp_err
|
||||
mp_selectCT(mp_digit cond, const mp_int *a, const mp_int *b, mp_int *ret)
|
||||
{
|
||||
mp_size used_a = MP_USED(a);
|
||||
mp_err res;
|
||||
mp_size i;
|
||||
|
||||
cond *= MP_DIGIT_MAX;
|
||||
|
||||
/* we currently require these to be equal on input,
|
||||
* we could use pad to extend one of them, but that might
|
||||
* leak data as it wouldn't be constant time */
|
||||
if (used_a != MP_USED(b)) {
|
||||
return MP_BADARG;
|
||||
}
|
||||
|
||||
MP_CHECKOK(s_mp_pad(ret, used_a));
|
||||
for (i = 0; i < used_a; i++) {
|
||||
MP_DIGIT(ret, i) = MP_CT_SEL_DIGIT(cond, MP_DIGIT(a, i), MP_DIGIT(b, i));
|
||||
}
|
||||
res = MP_OKAY;
|
||||
CLEANUP:
|
||||
return res;
|
||||
} /* end mp_selectCT() */
|
||||
|
||||
/* {{{ mp_reduceCT(a, m, c) */
|
||||
|
||||
/*
|
||||
mp_reduceCT(a, m, c)
|
||||
|
||||
Compute c = aR^-1 (mod m) in constant time.
|
||||
input should be in montgomery form. If input is the
|
||||
result of a montgomery multiply then out put will be
|
||||
in mongomery form.
|
||||
Result will be reduced to MP_USED(m), but not be
|
||||
clamped.
|
||||
*/
|
||||
|
||||
mp_err
|
||||
mp_reduceCT(const mp_int *a, const mp_int *m, mp_digit n0i, mp_int *c)
|
||||
{
|
||||
mp_size used_m = MP_USED(m);
|
||||
mp_size used_c = used_m * 2 + 1;
|
||||
mp_digit *m_digits, *c_digits;
|
||||
mp_size i;
|
||||
mp_digit borrow, carry;
|
||||
mp_err res;
|
||||
mp_int sub;
|
||||
|
||||
MP_DIGITS(&sub) = 0;
|
||||
MP_CHECKOK(mp_init_size(&sub, used_m));
|
||||
|
||||
if (a != c) {
|
||||
MP_CHECKOK(mp_copy(a, c));
|
||||
}
|
||||
MP_CHECKOK(s_mp_pad(c, used_c));
|
||||
m_digits = MP_DIGITS(m);
|
||||
c_digits = MP_DIGITS(c);
|
||||
for (i = 0; i < used_m; i++) {
|
||||
mp_digit m_i = MP_DIGIT(c, i) * n0i;
|
||||
s_mpv_mul_d_add_propCT(m_digits, used_m, m_i, c_digits++, used_c--);
|
||||
}
|
||||
s_mp_rshd(c, used_m);
|
||||
/* MP_USED(c) should be used_m+1 with the high word being any carry
|
||||
* from the previous multiply, save that carry and drop the high
|
||||
* word for the substraction below */
|
||||
carry = MP_DIGIT(c, used_m);
|
||||
MP_DIGIT(c, used_m) = 0;
|
||||
MP_USED(c) = used_m;
|
||||
/* mp_subCT wants c and m to be the same size, we've already
|
||||
* guarrenteed that in the previous statement, so mp_subCT won't actually
|
||||
* modify m, so it's safe to recast */
|
||||
MP_CHECKOK(mp_subCT(c, (mp_int *)m, &sub, &borrow));
|
||||
|
||||
/* we return c-m if c >= m no borrow or there was a borrow and a carry */
|
||||
MP_CHECKOK(mp_selectCT(borrow ^ carry, c, &sub, c));
|
||||
res = MP_OKAY;
|
||||
CLEANUP:
|
||||
mp_clear(&sub);
|
||||
return res;
|
||||
} /* end mp_reduceCT() */
|
||||
|
||||
/* }}} */
|
||||
|
||||
/* {{{ mp_mod_d(a, d, c) */
|
||||
|
||||
/*
|
||||
|
|
@ -1387,6 +1574,37 @@ mp_mulmod(const mp_int *a, const mp_int *b, const mp_int *m, mp_int *c)
|
|||
|
||||
/* }}} */
|
||||
|
||||
/* {{{ mp_mulmontmodCT(a, b, m, c) */
|
||||
|
||||
/*
|
||||
mp_mulmontmodCT(a, b, m, c)
|
||||
|
||||
Compute c = (a * b) mod m in constant time wrt a and b. either a or b
|
||||
should be in montgomery form and the output is native. If both a and b
|
||||
are in montgomery form, then the output will also be in montgomery form
|
||||
and can be recovered with an mp_reduceCT call.
|
||||
NOTE: a and b may be modified.
|
||||
*/
|
||||
|
||||
mp_err
|
||||
mp_mulmontmodCT(mp_int *a, mp_int *b, const mp_int *m, mp_digit n0i,
|
||||
mp_int *c)
|
||||
{
|
||||
mp_err res;
|
||||
|
||||
ARGCHK(a != NULL && b != NULL && m != NULL && c != NULL, MP_BADARG);
|
||||
|
||||
if ((res = mp_mulCT(a, b, c, MP_USED(m))) != MP_OKAY)
|
||||
return res;
|
||||
|
||||
if ((res = mp_reduceCT(c, m, n0i, c)) != MP_OKAY)
|
||||
return res;
|
||||
|
||||
return MP_OKAY;
|
||||
}
|
||||
|
||||
/* }}} */
|
||||
|
||||
/* {{{ mp_sqrmod(a, m, c) */
|
||||
|
||||
#if MP_SQUARE
|
||||
|
|
@ -2523,12 +2741,6 @@ mp_read_raw(mp_int *mp, char *str, int len)
|
|||
|
||||
mp_zero(mp);
|
||||
|
||||
/* Get sign from first byte */
|
||||
if (ustr[0])
|
||||
SIGN(mp) = NEG;
|
||||
else
|
||||
SIGN(mp) = ZPOS;
|
||||
|
||||
/* Read the rest of the digits */
|
||||
for (ix = 1; ix < len; ix++) {
|
||||
if ((res = mp_mul_d(mp, 256, mp)) != MP_OKAY)
|
||||
|
|
@ -2537,6 +2749,12 @@ mp_read_raw(mp_int *mp, char *str, int len)
|
|||
return res;
|
||||
}
|
||||
|
||||
/* Get sign from first byte */
|
||||
if (ustr[0])
|
||||
SIGN(mp) = NEG;
|
||||
else
|
||||
SIGN(mp) = ZPOS;
|
||||
|
||||
return MP_OKAY;
|
||||
|
||||
} /* end mp_read_raw() */
|
||||
|
|
@ -2693,7 +2911,7 @@ mp_radix_size(mp_int *mp, int radix)
|
|||
|
||||
bits = USED(mp) * DIGIT_BIT - 1;
|
||||
|
||||
return s_mp_outlen(bits, radix);
|
||||
return SIGN(mp) + s_mp_outlen(bits, radix);
|
||||
|
||||
} /* end mp_radix_size() */
|
||||
|
||||
|
|
@ -3248,7 +3466,8 @@ CLEANUP:
|
|||
/* {{{ s_mp_add_d(mp, d) */
|
||||
|
||||
/* Add d to |mp| in place */
|
||||
mp_err s_mp_add_d(mp_int *mp, mp_digit d) /* unsigned digit addition */
|
||||
mp_err
|
||||
s_mp_add_d(mp_int *mp, mp_digit d) /* unsigned digit addition */
|
||||
{
|
||||
#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_ADD_WORD)
|
||||
mp_word w, k = 0;
|
||||
|
|
@ -3305,7 +3524,8 @@ CLEANUP:
|
|||
/* {{{ s_mp_sub_d(mp, d) */
|
||||
|
||||
/* Subtract d from |mp| in place, assumes |mp| > d */
|
||||
mp_err s_mp_sub_d(mp_int *mp, mp_digit d) /* unsigned digit subtract */
|
||||
mp_err
|
||||
s_mp_sub_d(mp_int *mp, mp_digit d) /* unsigned digit subtract */
|
||||
{
|
||||
#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
|
||||
mp_word w, b = 0;
|
||||
|
|
@ -3512,7 +3732,8 @@ CLEANUP:
|
|||
/* {{{ s_mp_add(a, b) */
|
||||
|
||||
/* Compute a = |a| + |b| */
|
||||
mp_err s_mp_add(mp_int *a, const mp_int *b) /* magnitude addition */
|
||||
mp_err
|
||||
s_mp_add(mp_int *a, const mp_int *b) /* magnitude addition */
|
||||
{
|
||||
#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_ADD_WORD)
|
||||
mp_word w = 0;
|
||||
|
|
@ -3775,7 +3996,8 @@ s_mp_add_offset(mp_int *a, mp_int *b, mp_size offset)
|
|||
/* {{{ s_mp_sub(a, b) */
|
||||
|
||||
/* Compute a = |a| - |b|, assumes |a| >= |b| */
|
||||
mp_err s_mp_sub(mp_int *a, const mp_int *b) /* magnitude subtract */
|
||||
mp_err
|
||||
s_mp_sub(mp_int *a, const mp_int *b) /* magnitude subtract */
|
||||
{
|
||||
mp_digit *pa, *pb, *limit;
|
||||
#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
|
||||
|
|
@ -3930,12 +4152,6 @@ s_mp_mul(mp_int *a, const mp_int *b)
|
|||
Plo = (mp_digit)product; \
|
||||
Phi = (mp_digit)(product >> MP_DIGIT_BIT); \
|
||||
}
|
||||
#elif defined(OSF1)
|
||||
#define MP_MUL_DxD(a, b, Phi, Plo) \
|
||||
{ \
|
||||
Plo = asm("mulq %a0, %a1, %v0", a, b); \
|
||||
Phi = asm("umulh %a0, %a1, %v0", a, b); \
|
||||
}
|
||||
#else
|
||||
#define MP_MUL_DxD(a, b, Phi, Plo) \
|
||||
{ \
|
||||
|
|
@ -3946,15 +4162,63 @@ s_mp_mul(mp_int *a, const mp_int *b)
|
|||
a1b0 = (a >> MP_HALF_DIGIT_BIT) * (b & MP_HALF_DIGIT_MAX); \
|
||||
a1b0 += a0b1; \
|
||||
Phi += a1b0 >> MP_HALF_DIGIT_BIT; \
|
||||
if (a1b0 < a0b1) \
|
||||
Phi += MP_HALF_RADIX; \
|
||||
Phi += (MP_CT_LTU(a1b0, a0b1)) << MP_HALF_DIGIT_BIT; \
|
||||
a1b0 <<= MP_HALF_DIGIT_BIT; \
|
||||
Plo += a1b0; \
|
||||
if (Plo < a1b0) \
|
||||
++Phi; \
|
||||
Phi += MP_CT_LTU(Plo, a1b0); \
|
||||
}
|
||||
#endif
|
||||
|
||||
/* Constant time version of s_mpv_mul_d_add_prop.
|
||||
* Presently, this is only used by the Constant time Montgomery arithmetic code. */
|
||||
/* c += a * b */
|
||||
void
|
||||
s_mpv_mul_d_add_propCT(const mp_digit *a, mp_size a_len, mp_digit b,
|
||||
mp_digit *c, mp_size c_len)
|
||||
{
|
||||
#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_MUL_WORD)
|
||||
mp_digit d = 0;
|
||||
|
||||
c_len -= a_len;
|
||||
/* Inner product: Digits of a */
|
||||
while (a_len--) {
|
||||
mp_word w = ((mp_word)b * *a++) + *c + d;
|
||||
*c++ = ACCUM(w);
|
||||
d = CARRYOUT(w);
|
||||
}
|
||||
|
||||
/* propagate the carry to the end, even if carry is zero */
|
||||
while (c_len--) {
|
||||
mp_word w = (mp_word)*c + d;
|
||||
*c++ = ACCUM(w);
|
||||
d = CARRYOUT(w);
|
||||
}
|
||||
#else
|
||||
mp_digit carry = 0;
|
||||
c_len -= a_len;
|
||||
while (a_len--) {
|
||||
mp_digit a_i = *a++;
|
||||
mp_digit a0b0, a1b1;
|
||||
MP_MUL_DxD(a_i, b, a1b1, a0b0);
|
||||
|
||||
a0b0 += carry;
|
||||
a1b1 += MP_CT_LTU(a0b0, carry);
|
||||
a0b0 += a_i = *c;
|
||||
a1b1 += MP_CT_LTU(a0b0, a_i);
|
||||
|
||||
*c++ = a0b0;
|
||||
carry = a1b1;
|
||||
}
|
||||
/* propagate the carry to the end, even if carry is zero */
|
||||
while (c_len--) {
|
||||
mp_digit c_i = *c;
|
||||
carry += c_i;
|
||||
*c++ = carry;
|
||||
carry = MP_CT_LTU(carry, c_i);
|
||||
}
|
||||
#endif
|
||||
}
|
||||
|
||||
#if !defined(MP_ASSEMBLY_MULTIPLY)
|
||||
/* c = a * b */
|
||||
void
|
||||
|
|
@ -3979,8 +4243,7 @@ s_mpv_mul_d(const mp_digit *a, mp_size a_len, mp_digit b, mp_digit *c)
|
|||
MP_MUL_DxD(a_i, b, a1b1, a0b0);
|
||||
|
||||
a0b0 += carry;
|
||||
if (a0b0 < carry)
|
||||
++a1b1;
|
||||
a1b1 += MP_CT_LTU(a0b0, carry);
|
||||
*c++ = a0b0;
|
||||
carry = a1b1;
|
||||
}
|
||||
|
|
@ -4012,11 +4275,9 @@ s_mpv_mul_d_add(const mp_digit *a, mp_size a_len, mp_digit b,
|
|||
MP_MUL_DxD(a_i, b, a1b1, a0b0);
|
||||
|
||||
a0b0 += carry;
|
||||
if (a0b0 < carry)
|
||||
++a1b1;
|
||||
a1b1 += MP_CT_LTU(a0b0, carry);
|
||||
a0b0 += a_i = *c;
|
||||
if (a0b0 < a_i)
|
||||
++a1b1;
|
||||
a1b1 += MP_CT_LTU(a0b0, a_i);
|
||||
*c++ = a0b0;
|
||||
carry = a1b1;
|
||||
}
|
||||
|
|
@ -4081,12 +4342,6 @@ s_mpv_mul_d_add_prop(const mp_digit *a, mp_size a_len, mp_digit b, mp_digit *c)
|
|||
Plo = (mp_digit)square; \
|
||||
Phi = (mp_digit)(square >> MP_DIGIT_BIT); \
|
||||
}
|
||||
#elif defined(OSF1)
|
||||
#define MP_SQR_D(a, Phi, Plo) \
|
||||
{ \
|
||||
Plo = asm("mulq %a0, %a0, %v0", a); \
|
||||
Phi = asm("umulh %a0, %a0, %v0", a); \
|
||||
}
|
||||
#else
|
||||
#define MP_SQR_D(a, Phi, Plo) \
|
||||
{ \
|
||||
|
|
@ -4253,9 +4508,10 @@ s_mp_sqr(mp_int *a)
|
|||
Compute a = a / b and b = a mod b. Assumes b > a.
|
||||
*/
|
||||
|
||||
mp_err s_mp_div(mp_int *rem, /* i: dividend, o: remainder */
|
||||
mp_int *div, /* i: divisor */
|
||||
mp_int *quot) /* i: 0; o: quotient */
|
||||
mp_err
|
||||
s_mp_div(mp_int *rem, /* i: dividend, o: remainder */
|
||||
mp_int *div, /* i: divisor */
|
||||
mp_int *quot) /* i: 0; o: quotient */
|
||||
{
|
||||
mp_int part, t;
|
||||
mp_digit q_msd;
|
||||
|
|
|
|||
|
|
@ -64,7 +64,7 @@ typedef int mp_err;
|
|||
/* MP_ULONG_LONG_MAX was defined to be ULLONG_MAX */
|
||||
#elif defined(ULONG_LONG_MAX) /* HPUX */
|
||||
#define MP_ULONG_LONG_MAX ULONG_LONG_MAX
|
||||
#elif defined(ULONGLONG_MAX) /* IRIX, AIX */
|
||||
#elif defined(ULONGLONG_MAX) /* AIX */
|
||||
#define MP_ULONG_LONG_MAX ULONGLONG_MAX
|
||||
#endif
|
||||
|
||||
|
|
@ -150,6 +150,38 @@ typedef int mp_sword;
|
|||
/* This defines the maximum I/O base (minimum is 2) */
|
||||
#define MP_MAX_RADIX 64
|
||||
|
||||
/* Constant Time Macros on mp_digits */
|
||||
#define MP_CT_HIGH_TO_LOW(x) ((mp_digit)((mp_digit)(x) >> (MP_DIGIT_BIT - 1)))
|
||||
#define MP_CT_TRUE ((mp_digit)1)
|
||||
#define MP_CT_FALSE ((mp_digit)0)
|
||||
|
||||
/* basic zero and non zero tests */
|
||||
#define MP_CT_NOT_ZERO(x) (MP_CT_HIGH_TO_LOW(((x) | (((mp_digit)0) - (x)))))
|
||||
#define MP_CT_ZERO(x) (MP_CT_TRUE ^ MP_CT_HIGH_TO_LOW(((x) | (((mp_digit)0) - (x)))))
|
||||
|
||||
/* basic constant-time helper macro for equalities and inequalities.
|
||||
* The inequalities will produce incorrect results if
|
||||
* abs(a-b) >= MP_DIGIT_SIZE/2. This can be avoided if unsigned values stay
|
||||
* within the range 0-MP_DIGIT_MAX/2. */
|
||||
#define MP_CT_EQ(a, b) MP_CT_ZERO(((a) ^ (b)))
|
||||
#define MP_CT_NE(a, b) MP_CT_NOT_ZERO(((a) ^ (b)))
|
||||
#define MP_CT_GT(a, b) MP_CT_HIGH_TO_LOW((b) - (a))
|
||||
#define MP_CT_LT(a, b) MP_CT_HIGH_TO_LOW((a) - (b))
|
||||
#define MP_CT_GE(a, b) (MP_CT_TRUE ^ MP_CT_LT(a, b))
|
||||
#define MP_CT_LE(a, b) (MP_CT_TRUE ^ MP_CT_GT(a, b))
|
||||
|
||||
/* use constant time result to select a boolean value
|
||||
* or an mp digit depending on the args */
|
||||
#define MP_CT_SEL(m, l, r) ((r) ^ ((m) & ((r) ^ (l))))
|
||||
#define MP_CT_SELB(m, l, r) MP_CT_SEL(m, l, r) /* mask, l and r are booleans */
|
||||
#define MP_CT_SEL_DIGIT(m, l, r) MP_CT_SEL(m, l, r) /*mask, l, and r are mp_digit */
|
||||
|
||||
/* full inequalities that work with full mp_digit values */
|
||||
#define MP_CT_OVERFLOW(a, b, c, d) \
|
||||
MP_CT_SELB(MP_CT_HIGH_TO_LOW((a) ^ (b)), \
|
||||
(MP_CT_HIGH_TO_LOW(d)), c)
|
||||
#define MP_CT_LTU(a, b) MP_CT_OVERFLOW(a, b, MP_CT_LT(a, b), b)
|
||||
|
||||
typedef struct {
|
||||
mp_sign sign; /* sign of this quantity */
|
||||
mp_size alloc; /* how many digits allocated */
|
||||
|
|
@ -190,7 +222,9 @@ mp_err mp_neg(const mp_int *a, mp_int *b);
|
|||
/* Full arithmetic */
|
||||
mp_err mp_add(const mp_int *a, const mp_int *b, mp_int *c);
|
||||
mp_err mp_sub(const mp_int *a, const mp_int *b, mp_int *c);
|
||||
mp_err mp_subCT(const mp_int *a, mp_int *b, mp_int *c, mp_digit *borrow);
|
||||
mp_err mp_mul(const mp_int *a, const mp_int *b, mp_int *c);
|
||||
mp_err mp_mulCT(mp_int *a, mp_int *b, mp_int *c, mp_size setSize);
|
||||
#if MP_SQUARE
|
||||
mp_err mp_sqr(const mp_int *a, mp_int *b);
|
||||
#else
|
||||
|
|
@ -217,6 +251,12 @@ mp_err mp_exptmod(const mp_int *a, const mp_int *b, const mp_int *m, mp_int *c);
|
|||
mp_err mp_exptmod_d(const mp_int *a, mp_digit d, const mp_int *m, mp_int *c);
|
||||
#endif /* MP_MODARITH */
|
||||
|
||||
/* montgomery math */
|
||||
mp_err mp_to_mont(const mp_int *x, const mp_int *N, mp_int *xMont);
|
||||
mp_digit mp_calculate_mont_n0i(const mp_int *N);
|
||||
mp_err mp_reduceCT(const mp_int *a, const mp_int *m, mp_digit n0i, mp_int *ct);
|
||||
mp_err mp_mulmontmodCT(mp_int *a, mp_int *b, const mp_int *m, mp_digit n0i, mp_int *c);
|
||||
|
||||
/* Comparisons */
|
||||
int mp_cmp_z(const mp_int *a);
|
||||
int mp_cmp_d(const mp_int *a, mp_digit d);
|
||||
|
|
@ -224,6 +264,7 @@ int mp_cmp(const mp_int *a, const mp_int *b);
|
|||
int mp_cmp_mag(const mp_int *a, const mp_int *b);
|
||||
int mp_isodd(const mp_int *a);
|
||||
int mp_iseven(const mp_int *a);
|
||||
mp_err mp_selectCT(mp_digit cond, const mp_int *a, const mp_int *b, mp_int *ret);
|
||||
|
||||
/* Number theoretic */
|
||||
mp_err mp_gcd(mp_int *a, mp_int *b, mp_int *c);
|
||||
|
|
|
|||
|
|
@ -18,7 +18,15 @@
|
|||
# s_mpv_mul_set_vec64(uint64_t *r, uint64_t *a, int len, uint64_t digit)
|
||||
#
|
||||
|
||||
.text; .align 16; .globl s_mpv_mul_set_vec64; .type s_mpv_mul_set_vec64, @function; s_mpv_mul_set_vec64:
|
||||
.text; .align 16; .globl s_mpv_mul_set_vec64;
|
||||
|
||||
#ifdef DARWIN
|
||||
#define s_mpv_mul_set_vec64 _s_mpv_mul_set_vec64
|
||||
.private_extern s_mpv_mul_set_vec64
|
||||
s_mpv_mul_set_vec64:
|
||||
#else
|
||||
.type s_mpv_mul_set_vec64, @function; s_mpv_mul_set_vec64:
|
||||
#endif
|
||||
|
||||
xorq %rax, %rax # if (len == 0) return (0)
|
||||
testq %rdx, %rdx
|
||||
|
|
@ -169,7 +177,9 @@
|
|||
movq %r9, %rax
|
||||
ret
|
||||
|
||||
#ifndef DARWIN
|
||||
.size s_mpv_mul_set_vec64, .-s_mpv_mul_set_vec64
|
||||
#endif
|
||||
|
||||
# ------------------------------------------------------------------------
|
||||
#
|
||||
|
|
@ -186,7 +196,15 @@
|
|||
# s_mpv_mul_add_vec64(uint64_t *r, uint64_t *a, int len, uint64_t digit)
|
||||
#
|
||||
|
||||
.text; .align 16; .globl s_mpv_mul_add_vec64; .type s_mpv_mul_add_vec64, @function; s_mpv_mul_add_vec64:
|
||||
.text; .align 16; .globl s_mpv_mul_add_vec64;
|
||||
|
||||
#ifdef DARWIN
|
||||
#define s_mpv_mul_add_vec64 _s_mpv_mul_add_vec64
|
||||
.private_extern s_mpv_mul_add_vec64
|
||||
s_mpv_mul_add_vec64:
|
||||
#else
|
||||
.type s_mpv_mul_add_vec64, @function; s_mpv_mul_add_vec64:
|
||||
#endif
|
||||
|
||||
xorq %rax, %rax # if (len == 0) return (0)
|
||||
testq %rdx, %rdx
|
||||
|
|
@ -381,9 +399,11 @@
|
|||
.L27:
|
||||
movq %r9, %rax
|
||||
ret
|
||||
|
||||
|
||||
#ifndef DARWIN
|
||||
.size s_mpv_mul_add_vec64, .-s_mpv_mul_add_vec64
|
||||
|
||||
# Magic indicating no need for an executable stack
|
||||
.section .note.GNU-stack, "", @progbits
|
||||
.previous
|
||||
#endif
|
||||
|
|
@ -222,10 +222,9 @@ mpl_lsh(const mp_int *a, mp_int *b, mp_digit d)
|
|||
/* {{{ mpl_num_set(a, num) */
|
||||
|
||||
mp_err
|
||||
mpl_num_set(mp_int *a, int *num)
|
||||
mpl_num_set(mp_int *a, unsigned int *num)
|
||||
{
|
||||
unsigned int ix;
|
||||
int db, nset = 0;
|
||||
unsigned int ix, db, nset = 0;
|
||||
mp_digit cur;
|
||||
unsigned char reg;
|
||||
|
||||
|
|
@ -253,10 +252,9 @@ mpl_num_set(mp_int *a, int *num)
|
|||
/* {{{ mpl_num_clear(a, num) */
|
||||
|
||||
mp_err
|
||||
mpl_num_clear(mp_int *a, int *num)
|
||||
mpl_num_clear(mp_int *a, unsigned int *num)
|
||||
{
|
||||
unsigned int ix;
|
||||
int db, nset = 0;
|
||||
unsigned int ix, db, nset = 0;
|
||||
mp_digit cur;
|
||||
unsigned char reg;
|
||||
|
||||
|
|
|
|||
|
|
@ -11,6 +11,7 @@
|
|||
#define _H_MPLOGIC_
|
||||
|
||||
#include "mpi.h"
|
||||
SEC_BEGIN_PROTOS
|
||||
|
||||
/*
|
||||
The logical operations treat an mp_int as if it were a bit vector,
|
||||
|
|
@ -38,9 +39,9 @@ mp_err mpl_lsh(const mp_int *a, mp_int *b, mp_digit d); /* left shift */
|
|||
|
||||
/* Bit count and parity */
|
||||
|
||||
mp_err mpl_num_set(mp_int *a, int *num); /* count set bits */
|
||||
mp_err mpl_num_clear(mp_int *a, int *num); /* count clear bits */
|
||||
mp_err mpl_parity(mp_int *a); /* determine parity */
|
||||
mp_err mpl_num_set(mp_int *a, unsigned int *num); /* count set bits */
|
||||
mp_err mpl_num_clear(mp_int *a, unsigned int *num); /* count clear bits */
|
||||
mp_err mpl_parity(mp_int *a); /* determine parity */
|
||||
|
||||
/* Get & Set the value of a bit */
|
||||
|
||||
|
|
@ -49,4 +50,6 @@ mp_err mpl_get_bit(const mp_int *a, mp_size bitNum);
|
|||
mp_err mpl_get_bits(const mp_int *a, mp_size lsbNum, mp_size numBits);
|
||||
mp_size mpl_significant_bits(const mp_int *a);
|
||||
|
||||
SEC_END_PROTOS
|
||||
|
||||
#endif /* end _H_MPLOGIC_ */
|
||||
|
|
|
|||
|
|
@ -129,20 +129,27 @@ CLEANUP:
|
|||
}
|
||||
#endif
|
||||
|
||||
STATIC
|
||||
mp_err
|
||||
s_mp_to_mont(const mp_int *x, mp_mont_modulus *mmm, mp_int *xMont)
|
||||
mp_to_mont(const mp_int *x, const mp_int *N, mp_int *xMont)
|
||||
{
|
||||
mp_err res;
|
||||
|
||||
/* xMont = x * R mod N where N is modulus */
|
||||
MP_CHECKOK(mp_copy(x, xMont));
|
||||
MP_CHECKOK(s_mp_lshd(xMont, MP_USED(&mmm->N))); /* xMont = x << b */
|
||||
MP_CHECKOK(mp_div(xMont, &mmm->N, 0, xMont)); /* mod N */
|
||||
if (x != xMont) {
|
||||
MP_CHECKOK(mp_copy(x, xMont));
|
||||
}
|
||||
MP_CHECKOK(s_mp_lshd(xMont, MP_USED(N))); /* xMont = x << b */
|
||||
MP_CHECKOK(mp_div(xMont, N, 0, xMont)); /* mod N */
|
||||
CLEANUP:
|
||||
return res;
|
||||
}
|
||||
|
||||
mp_digit
|
||||
mp_calculate_mont_n0i(const mp_int *N)
|
||||
{
|
||||
return 0 - s_mp_invmod_radix(MP_DIGIT(N, 0));
|
||||
}
|
||||
|
||||
#ifdef MP_USING_MONT_MULF
|
||||
|
||||
/* the floating point multiply is already cache safe,
|
||||
|
|
@ -198,7 +205,7 @@ mp_exptmod_f(const mp_int *montBase,
|
|||
MP_CHECKOK(mp_init_size(&accum1, 3 * nLen + 2));
|
||||
|
||||
mp_set(&accum1, 1);
|
||||
MP_CHECKOK(s_mp_to_mont(&accum1, mmm, &accum1));
|
||||
MP_CHECKOK(mp_to_mont(&accum1, &(mmm->N), &accum1));
|
||||
MP_CHECKOK(s_mp_pad(&accum1, nLen));
|
||||
|
||||
oddPowSize = 2 * nLen + 1;
|
||||
|
|
@ -478,7 +485,7 @@ mp_exptmod_i(const mp_int *montBase,
|
|||
|
||||
/* set accumulator to montgomery residue of 1 */
|
||||
mp_set(&accum1, 1);
|
||||
MP_CHECKOK(s_mp_to_mont(&accum1, mmm, &accum1));
|
||||
MP_CHECKOK(mp_to_mont(&accum1, &(mmm->N), &accum1));
|
||||
pa1 = &accum1;
|
||||
pa2 = &accum2;
|
||||
|
||||
|
|
@ -723,10 +730,11 @@ mp_set_safe_modexp(int value)
|
|||
* mp_ints that use less than nDigits digits are logically padded with zeros
|
||||
* while being stored in the weaved array.
|
||||
*/
|
||||
mp_err mpi_to_weave(const mp_int *bignums,
|
||||
mp_digit *weaved,
|
||||
mp_size nDigits, /* in each mp_int of input */
|
||||
mp_size nBignums) /* in the entire source array */
|
||||
mp_err
|
||||
mpi_to_weave(const mp_int *bignums,
|
||||
mp_digit *weaved,
|
||||
mp_size nDigits, /* in each mp_int of input */
|
||||
mp_size nBignums) /* in the entire source array */
|
||||
{
|
||||
mp_size i;
|
||||
mp_digit *endDest = weaved + (nDigits * nBignums);
|
||||
|
|
@ -765,11 +773,12 @@ mp_err mpi_to_weave(const mp_int *bignums,
|
|||
* Every read accesses every element of the weaved array, in order to
|
||||
* avoid timing attacks based on patterns of memory accesses.
|
||||
*/
|
||||
mp_err weave_to_mpi(mp_int *a, /* out, result */
|
||||
const mp_digit *weaved, /* in, byte matrix */
|
||||
mp_size index, /* which column to read */
|
||||
mp_size nDigits, /* number of mp_digits in each bignum */
|
||||
mp_size nBignums) /* width of the matrix */
|
||||
mp_err
|
||||
weave_to_mpi(mp_int *a, /* out, result */
|
||||
const mp_digit *weaved, /* in, byte matrix */
|
||||
mp_size index, /* which column to read */
|
||||
mp_size nDigits, /* number of mp_digits in each bignum */
|
||||
mp_size nBignums) /* width of the matrix */
|
||||
{
|
||||
/* these are indices, but need to be the same size as mp_digit
|
||||
* because of the CONST_TIME operations */
|
||||
|
|
@ -865,7 +874,7 @@ mp_exptmod_safe_i(const mp_int *montBase,
|
|||
MP_CHECKOK(mp_init_size(&accum[2], 3 * nLen + 2));
|
||||
MP_CHECKOK(mp_init_size(&accum[3], 3 * nLen + 2));
|
||||
mp_set(&accum[0], 1);
|
||||
MP_CHECKOK(s_mp_to_mont(&accum[0], mmm, &accum[0]));
|
||||
MP_CHECKOK(mp_to_mont(&accum[0], &(mmm->N), &accum[0]));
|
||||
MP_CHECKOK(mp_copy(montBase, &accum[1]));
|
||||
SQR(montBase, &accum[2]);
|
||||
MUL_NOWEAVE(montBase, &accum[2], &accum[3]);
|
||||
|
|
@ -884,7 +893,7 @@ mp_exptmod_safe_i(const mp_int *montBase,
|
|||
} else {
|
||||
if (first_window == 0) {
|
||||
mp_set(&accum1, 1);
|
||||
MP_CHECKOK(s_mp_to_mont(&accum1, mmm, &accum1));
|
||||
MP_CHECKOK(mp_to_mont(&accum1, &(mmm->N), &accum1));
|
||||
} else {
|
||||
/* assert first_window == 1? */
|
||||
MP_CHECKOK(mp_copy(montBase, &accum1));
|
||||
|
|
@ -1006,7 +1015,11 @@ CLEANUP:
|
|||
mp_clear(&accum[2]);
|
||||
mp_clear(&accum[3]);
|
||||
mp_clear(&tmp);
|
||||
/* PORT_Memset(powers,0,num_powers*nLen*sizeof(mp_digit)); */
|
||||
/* zero required by FIPS here, can't use PORT_ZFree
|
||||
* because mpi doesn't link with util */
|
||||
if (powers) {
|
||||
PORT_Memset(powers, 0, num_powers * sizeof(mp_digit));
|
||||
}
|
||||
free(powersArray);
|
||||
return res;
|
||||
}
|
||||
|
|
@ -1051,9 +1064,9 @@ mp_exptmod(const mp_int *inBase, const mp_int *exponent,
|
|||
/* compute n0', given n0, n0' = -(n0 ** -1) mod MP_RADIX
|
||||
** where n0 = least significant mp_digit of N, the modulus.
|
||||
*/
|
||||
mmm.n0prime = 0 - s_mp_invmod_radix(MP_DIGIT(modulus, 0));
|
||||
mmm.n0prime = mp_calculate_mont_n0i(modulus);
|
||||
|
||||
MP_CHECKOK(s_mp_to_mont(base, &mmm, &montBase));
|
||||
MP_CHECKOK(mp_to_mont(base, modulus, &montBase));
|
||||
|
||||
bits_in_exponent = mpl_significant_bits(exponent);
|
||||
#ifdef MP_USING_CACHE_SAFE_MOD_EXP
|
||||
|
|
|
|||
|
|
@ -126,6 +126,8 @@ mpp_random(mp_int *a)
|
|||
|
||||
/* }}} */
|
||||
|
||||
static mpp_random_fn mpp_random_insecure = &mpp_random;
|
||||
|
||||
/* {{{ mpp_random_size(a, prec) */
|
||||
|
||||
mp_err
|
||||
|
|
@ -138,7 +140,7 @@ mpp_random_size(mp_int *a, mp_size prec)
|
|||
if ((res = s_mp_pad(a, prec)) != MP_OKAY)
|
||||
return res;
|
||||
|
||||
return mpp_random(a);
|
||||
return (*mpp_random_insecure)(a);
|
||||
|
||||
} /* end mpp_random_size() */
|
||||
|
||||
|
|
@ -271,6 +273,12 @@ mpp_fermat_list(mp_int *a, const mp_digit *primes, mp_size nPrimes)
|
|||
|
||||
mp_err
|
||||
mpp_pprime(mp_int *a, int nt)
|
||||
{
|
||||
return mpp_pprime_ext_random(a, nt, mpp_random_insecure);
|
||||
}
|
||||
|
||||
mp_err
|
||||
mpp_pprime_ext_random(mp_int *a, int nt, mpp_random_fn random)
|
||||
{
|
||||
mp_err res;
|
||||
mp_int x, amo, m, z; /* "amo" = "a minus one" */
|
||||
|
|
@ -306,7 +314,7 @@ mpp_pprime(mp_int *a, int nt)
|
|||
|
||||
/* Choose a random value for 1 < x < a */
|
||||
MP_CHECKOK(s_mp_pad(&x, USED(a)));
|
||||
mpp_random(&x);
|
||||
MP_CHECKOK((*random)(&x));
|
||||
MP_CHECKOK(mp_mod(&x, a, &x));
|
||||
if (mp_cmp_d(&x, 1) <= 0) {
|
||||
iter--; /* don't count this iteration */
|
||||
|
|
@ -403,6 +411,12 @@ mpp_sieve(mp_int *trial, const mp_digit *primes, mp_size nPrimes,
|
|||
|
||||
mp_err
|
||||
mpp_make_prime(mp_int *start, mp_size nBits, mp_size strong)
|
||||
{
|
||||
return mpp_make_prime_ext_random(start, nBits, strong, mpp_random_insecure);
|
||||
}
|
||||
|
||||
mp_err
|
||||
mpp_make_prime_ext_random(mp_int *start, mp_size nBits, mp_size strong, mpp_random_fn random)
|
||||
{
|
||||
mp_digit np;
|
||||
mp_err res;
|
||||
|
|
@ -490,7 +504,7 @@ mpp_make_prime(mp_int *start, mp_size nBits, mp_size strong)
|
|||
|
||||
FPUTC('+', stderr);
|
||||
/* If that passed, run some Miller-Rabin tests */
|
||||
res = mpp_pprime(&trial, num_tests);
|
||||
res = mpp_pprime_ext_random(&trial, num_tests, random);
|
||||
if (res != MP_OKAY) {
|
||||
if (res == MP_NO)
|
||||
continue; /* was composite */
|
||||
|
|
@ -528,7 +542,7 @@ mpp_make_prime(mp_int *start, mp_size nBits, mp_size strong)
|
|||
}
|
||||
|
||||
/* And test with Miller-Rabin, as with its parent ... */
|
||||
res = mpp_pprime(&q, num_tests);
|
||||
res = mpp_pprime_ext_random(&q, num_tests, random);
|
||||
if (res != MP_YES) {
|
||||
mp_clear(&q);
|
||||
if (res == MP_NO)
|
||||
|
|
|
|||
|
|
@ -26,6 +26,9 @@ mp_err mpp_divis_d(mp_int *a, mp_digit d);
|
|||
mp_err mpp_random(mp_int *a);
|
||||
mp_err mpp_random_size(mp_int *a, mp_size prec);
|
||||
|
||||
/* Type for a pointer to a user-provided mpp_random implementation */
|
||||
typedef mp_err (*mpp_random_fn)(mp_int *);
|
||||
|
||||
/* Pseudo-primality testing */
|
||||
mp_err mpp_divis_vector(mp_int *a, const mp_digit *vec, int size, int *which);
|
||||
mp_err mpp_divis_primes(mp_int *a, mp_digit *np);
|
||||
|
|
@ -36,6 +39,10 @@ mp_err mpp_sieve(mp_int *trial, const mp_digit *primes, mp_size nPrimes,
|
|||
unsigned char *sieve, mp_size nSieve);
|
||||
mp_err mpp_make_prime(mp_int *start, mp_size nBits, mp_size strong);
|
||||
|
||||
/* Pseudo-primality tests using a user-provided mpp_random implementation */
|
||||
mp_err mpp_pprime_ext_random(mp_int *a, int nt, mpp_random_fn random);
|
||||
mp_err mpp_make_prime_ext_random(mp_int *start, mp_size nBits, mp_size strong, mpp_random_fn random);
|
||||
|
||||
SEC_END_PROTOS
|
||||
|
||||
#endif /* end _H_MP_PRIME_ */
|
||||
|
|
|
|||
|
|
@ -836,6 +836,6 @@ const mp_digit prime_tab[] = {
|
|||
0xFE95, 0xFE9B, 0xFE9F, 0xFEB3, 0xFEBD, 0xFED7, 0xFEE9, 0xFEF3,
|
||||
0xFEF5, 0xFF07, 0xFF0D, 0xFF1D, 0xFF2B, 0xFF2F, 0xFF49, 0xFF4D,
|
||||
0xFF5B, 0xFF65, 0xFF71, 0xFF7F, 0xFF85, 0xFF8B, 0xFF8F, 0xFF9D,
|
||||
0xFFA7, 0xFFA9, 0xFFC7, 0xFFD9, 0xFFEF, 0xFFF1,
|
||||
0xFFA7, 0xFFA9, 0xFFC7, 0xFFD9, 0xFFEF, 0xFFF1
|
||||
#endif
|
||||
};
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue