Replace NSS with Pale Moon's

This commit is contained in:
wuggy 2026-06-29 21:29:25 +01:00
commit 8c2e376f94
2870 changed files with 1762232 additions and 1374220 deletions

0
security/nss/lib/freebl/mpi/doc/build Normal file → Executable file
View file

View file

@ -198,7 +198,7 @@ L18:
mov dword ptr [8+rbx], edi
je L9
lea r10d, dword ptr [-2+rdx]
cmp dword ptr [r11+r10*8], 0
cmp qword ptr [r11+r10*8], 0
je L18
L9:
mov edx, dword ptr [8+rbx]
@ -689,7 +689,7 @@ L43:
mov dword ptr [8+rbx], edi
je L35
lea eax, dword ptr [-2+rdx]
cmp dword ptr [r11+rax*8], 0
cmp qword ptr [r11+rax*8], 0
je L43
L35:
mov r11d, dword ptr [8+rbx]
@ -2268,7 +2268,7 @@ L84:
mov dword ptr [8+rbx], edi
je L76
lea eax, dword ptr [-2+rdx]
cmp dword ptr [r11+rax*8], 0
cmp qword ptr [r11+rax*8], 0
je L84
L76:
mov edx, dword ptr [8+rbx]
@ -7830,7 +7830,7 @@ L157:
mov dword ptr [8+r13], ebx
je L149
lea r12d, dword ptr [-2+rdx]
cmp dword ptr [r9+r12*8], 0
cmp qword ptr [r9+r12*8], 0
je L157
L149:
mov r9d, dword ptr [8+r13]
@ -7990,7 +7990,7 @@ s_mp_sqr_comba_4 PROC
lea ecx, dword ptr [-1+rdx]
mov rsi, qword ptr [16+r11]
mov r10d, ecx
cmp dword ptr [rsi+r10*8], 0
cmp qword ptr [rsi+r10*8], 0
jne L166
mov edx, ecx
ALIGN 16
@ -8000,7 +8000,7 @@ L167:
je L171
dec edx
mov eax, edx
cmp dword ptr [rsi+rax*8], 0
cmp qword ptr [rsi+rax*8], 0
je L167
mov dword ptr [8+r11], ecx
mov edx, ecx
@ -8415,7 +8415,7 @@ s_mp_sqr_comba_8 PROC
lea ecx, dword ptr [-1+rdx]
mov rsi, qword ptr [16+rbp]
mov r14d, ecx
cmp dword ptr [rsi+r14*8], 0
cmp qword ptr [rsi+r14*8], 0
jne L190
mov edx, ecx
ALIGN 16
@ -8425,7 +8425,7 @@ L191:
je L195
dec edx
mov r9d, edx
cmp dword ptr [rsi+r9*8], 0
cmp qword ptr [rsi+r9*8], 0
je L191
mov dword ptr [8+rbp], ecx
mov edx, ecx
@ -9511,7 +9511,7 @@ s_mp_sqr_comba_16 PROC ; A "FRAME" function
lea ecx, dword ptr [-1+rdx]
mov rsi, qword ptr [16+r14]
mov r9d, ecx
cmp dword ptr [rsi+r9*8], 0
cmp qword ptr [rsi+r9*8], 0
jne L230
mov edx, ecx
ALIGN 16
@ -9521,7 +9521,7 @@ L231:
je L235
dec edx
mov eax, edx
cmp dword ptr [rsi+rax*8], 0
cmp qword ptr [rsi+rax*8], 0
je L231
mov dword ptr [8+r14], ecx
mov edx, ecx
@ -13023,7 +13023,7 @@ s_mp_sqr_comba_32 PROC ; A "FRAME" function
lea ecx, dword ptr [-1+rdx]
mov rsi, qword ptr [16+r14]
mov r10d, ecx
cmp dword ptr [rsi+r10*8], 0
cmp qword ptr [rsi+r10*8], 0
jne L302
mov edx, ecx
ALIGN 16
@ -13033,7 +13033,7 @@ L303:
je L307
dec edx
mov eax, edx
cmp dword ptr [rsi+rax*8], 0
cmp qword ptr [rsi+rax*8], 0
je L303
mov dword ptr [8+r14], ecx
mov edx, ecx

View file

@ -7,11 +7,10 @@
#include "mplogic.h"
#include "mpi-priv.h"
const mp_digit mp_gf2m_sqr_tb[16] =
{
0, 1, 4, 5, 16, 17, 20, 21,
64, 65, 68, 69, 80, 81, 84, 85
};
const mp_digit mp_gf2m_sqr_tb[16] = {
0, 1, 4, 5, 16, 17, 20, 21,
64, 65, 68, 69, 80, 81, 84, 85
};
/* Multiply two binary polynomials mp_digits a, b.
* Result is a polynomial with degree < 2 * MP_DIGIT_BITS - 1.

View file

@ -39,7 +39,8 @@ freebl_cpuid(unsigned long op, unsigned long *eax,
unsigned long *ebx, unsigned long *ecx,
unsigned long *edx)
{
__asm__("cpuid\n\t"
__asm__("xor %%ecx, %%ecx\n\t"
"cpuid\n\t"
: "=a"(*eax),
"=b"(*ebx),
"=c"(*ecx),
@ -726,10 +727,10 @@ s_mpi_getProcessorLineSize()
static inline void
dcbzl(char *array)
{
register char *a asm("r2") = array;
__asm__ __volatile__("dcbzl %0,0"
: "=r"(a)
: "0"(a));
__asm__("dcbzl %0, %1"
: /*no result*/
: "b%"(array), "r"(0)
: "memory");
}
#define PPC_DO_ALIGN(x, y) ((char *)((((long long)(x)) + ((y)-1)) & ~((y)-1)))

View file

@ -157,7 +157,7 @@ mp_err s_mp_invmod_2d(const mp_int *a, mp_size k, mp_int *c);
mp_err s_mp_invmod_even_m(const mp_int *a, const mp_int *m, mp_int *c);
#ifdef NSS_USE_COMBA
PR_STATIC_ASSERT(sizeof(mp_digit) == 8);
#define IS_POWER_OF_2(a) ((a) && !((a) & ((a)-1)))
void s_mp_mul_comba_4(const mp_int *A, const mp_int *B, mp_int *C);
@ -204,6 +204,9 @@ void MPI_ASM_DECL s_mpv_mul_d_add(const mp_digit *a, mp_size a_len,
void MPI_ASM_DECL s_mpv_mul_d_add_prop(const mp_digit *a,
mp_size a_len, mp_digit b,
mp_digit *c);
void MPI_ASM_DECL s_mpv_mul_d_add_propCT(const mp_digit *a,
mp_size a_len, mp_digit b,
mp_digit *c, mp_size c_len);
void MPI_ASM_DECL s_mpv_sqr_add_prop(const mp_digit *a,
mp_size a_len,
mp_digit *sqrs);

View file

@ -9,9 +9,8 @@
#include "mpi-priv.h"
#include "mplogic.h"
#if defined(OSF1)
#include <c_asm.h>
#endif
#include <assert.h>
#if defined(__arm__) && \
((defined(__thumb__) && !defined(__thumb2__)) || defined(__ARM_ARCH_3__))
@ -805,15 +804,18 @@ CLEANUP:
/* }}} */
/* {{{ mp_mul(a, b, c) */
/* {{{ s_mp_mulg(a, b, c) */
/*
mp_mul(a, b, c)
s_mp_mulg(a, b, c)
Compute c = a * b. All parameters may be identical.
Compute c = a * b. All parameters may be identical. if constantTime is set,
then the operations are done in constant time. The original is mostly
constant time as long as s_mpv_mul_d_add() is constant time. This is true
of the x86 assembler, as well as the current c code.
*/
mp_err
mp_mul(const mp_int *a, const mp_int *b, mp_int *c)
s_mp_mulg(const mp_int *a, const mp_int *b, mp_int *c, int constantTime)
{
mp_digit *pb;
mp_int tmp;
@ -849,7 +851,14 @@ mp_mul(const mp_int *a, const mp_int *b, mp_int *c)
goto CLEANUP;
#ifdef NSS_USE_COMBA
if ((MP_USED(a) == MP_USED(b)) && IS_POWER_OF_2(MP_USED(b))) {
/* comba isn't constant time because it clamps! If we cared
* (we needed a constant time version of multiply that was 'faster'
* we could easily pass constantTime down to the comba code and
* get it to skip the clamp... but here are assembler versions
* which add comba to platforms that can't compile the normal
* comba's imbedded assembler which would also need to change, so
* for now we just skip comba when we are running constant time. */
if (!constantTime && (MP_USED(a) == MP_USED(b)) && IS_POWER_OF_2(MP_USED(b))) {
if (MP_USED(a) == 4) {
s_mp_mul_comba_4(a, b, c);
goto CLEANUP;
@ -879,13 +888,15 @@ mp_mul(const mp_int *a, const mp_int *b, mp_int *c)
mp_digit b_i = *pb++;
/* Inner product: Digits of a */
if (b_i)
if (constantTime || b_i)
s_mpv_mul_d_add(MP_DIGITS(a), useda, b_i, MP_DIGITS(c) + ib);
else
MP_DIGIT(c, ib + useda) = b_i;
}
s_mp_clamp(c);
if (!constantTime) {
s_mp_clamp(c);
}
if (SIGN(a) == SIGN(b) || s_mp_cmp_d(c, 0) == MP_EQ)
SIGN(c) = ZPOS;
@ -895,10 +906,54 @@ mp_mul(const mp_int *a, const mp_int *b, mp_int *c)
CLEANUP:
mp_clear(&tmp);
return res;
} /* end smp_mulg() */
/* }}} */
/* {{{ mp_mul(a, b, c) */
/*
mp_mul(a, b, c)
Compute c = a * b. All parameters may be identical.
*/
mp_err
mp_mul(const mp_int *a, const mp_int *b, mp_int *c)
{
return s_mp_mulg(a, b, c, 0);
} /* end mp_mul() */
/* }}} */
/* {{{ mp_mulCT(a, b, c) */
/*
mp_mulCT(a, b, c)
Compute c = a * b. In constant time. Parameters may not be identical.
NOTE: a and b may be modified.
*/
mp_err
mp_mulCT(mp_int *a, mp_int *b, mp_int *c, mp_size setSize)
{
mp_err res;
/* make the multiply values fixed length so multiply
* doesn't leak the length. at this point all the
* values are blinded, but once we finish we want the
* output size to be hidden (so no clamping the out put) */
MP_CHECKOK(s_mp_pad(a, setSize));
MP_CHECKOK(s_mp_pad(b, setSize));
MP_CHECKOK(s_mp_pad(c, 2 * setSize));
MP_CHECKOK(s_mp_mulg(a, b, c, 1));
CLEANUP:
return res;
} /* end mp_mulCT() */
/* }}} */
/* {{{ mp_sqr(a, sqr) */
#if MP_SQUARE
@ -1271,6 +1326,138 @@ mp_mod(const mp_int *a, const mp_int *m, mp_int *c)
/* }}} */
/* {{{ s_mp_subCT_d(a, b, borrow, c) */
/*
s_mp_subCT_d(a, b, borrow, c)
Compute c = (a -b) - subtract in constant time. returns borrow
*/
mp_digit
s_mp_subCT_d(mp_digit a, mp_digit b, mp_digit borrow, mp_digit *ret)
{
*ret = a - b - borrow;
return MP_CT_LTU(a, *ret) | (MP_CT_EQ(a, *ret) & borrow);
} /* s_mp_subCT_d() */
/* }}} */
/* {{{ mp_subCT(a, b, ret, borrow) */
/* return ret= a - b and borrow in borrow. done in constant time.
* b could be modified.
*/
mp_err
mp_subCT(const mp_int *a, mp_int *b, mp_int *ret, mp_digit *borrow)
{
mp_size used_a = MP_USED(a);
mp_size i;
mp_err res;
MP_CHECKOK(s_mp_pad(b, used_a));
MP_CHECKOK(s_mp_pad(ret, used_a));
*borrow = 0;
for (i = 0; i < used_a; i++) {
*borrow = s_mp_subCT_d(MP_DIGIT(a, i), MP_DIGIT(b, i), *borrow,
&MP_DIGIT(ret, i));
}
res = MP_OKAY;
CLEANUP:
return res;
} /* end mp_subCT() */
/* }}} */
/* {{{ mp_selectCT(cond, a, b, ret) */
/*
* return ret= cond ? a : b; cond should be either 0 or 1
*/
mp_err
mp_selectCT(mp_digit cond, const mp_int *a, const mp_int *b, mp_int *ret)
{
mp_size used_a = MP_USED(a);
mp_err res;
mp_size i;
cond *= MP_DIGIT_MAX;
/* we currently require these to be equal on input,
* we could use pad to extend one of them, but that might
* leak data as it wouldn't be constant time */
if (used_a != MP_USED(b)) {
return MP_BADARG;
}
MP_CHECKOK(s_mp_pad(ret, used_a));
for (i = 0; i < used_a; i++) {
MP_DIGIT(ret, i) = MP_CT_SEL_DIGIT(cond, MP_DIGIT(a, i), MP_DIGIT(b, i));
}
res = MP_OKAY;
CLEANUP:
return res;
} /* end mp_selectCT() */
/* {{{ mp_reduceCT(a, m, c) */
/*
mp_reduceCT(a, m, c)
Compute c = aR^-1 (mod m) in constant time.
input should be in montgomery form. If input is the
result of a montgomery multiply then out put will be
in mongomery form.
Result will be reduced to MP_USED(m), but not be
clamped.
*/
mp_err
mp_reduceCT(const mp_int *a, const mp_int *m, mp_digit n0i, mp_int *c)
{
mp_size used_m = MP_USED(m);
mp_size used_c = used_m * 2 + 1;
mp_digit *m_digits, *c_digits;
mp_size i;
mp_digit borrow, carry;
mp_err res;
mp_int sub;
MP_DIGITS(&sub) = 0;
MP_CHECKOK(mp_init_size(&sub, used_m));
if (a != c) {
MP_CHECKOK(mp_copy(a, c));
}
MP_CHECKOK(s_mp_pad(c, used_c));
m_digits = MP_DIGITS(m);
c_digits = MP_DIGITS(c);
for (i = 0; i < used_m; i++) {
mp_digit m_i = MP_DIGIT(c, i) * n0i;
s_mpv_mul_d_add_propCT(m_digits, used_m, m_i, c_digits++, used_c--);
}
s_mp_rshd(c, used_m);
/* MP_USED(c) should be used_m+1 with the high word being any carry
* from the previous multiply, save that carry and drop the high
* word for the substraction below */
carry = MP_DIGIT(c, used_m);
MP_DIGIT(c, used_m) = 0;
MP_USED(c) = used_m;
/* mp_subCT wants c and m to be the same size, we've already
* guarrenteed that in the previous statement, so mp_subCT won't actually
* modify m, so it's safe to recast */
MP_CHECKOK(mp_subCT(c, (mp_int *)m, &sub, &borrow));
/* we return c-m if c >= m no borrow or there was a borrow and a carry */
MP_CHECKOK(mp_selectCT(borrow ^ carry, c, &sub, c));
res = MP_OKAY;
CLEANUP:
mp_clear(&sub);
return res;
} /* end mp_reduceCT() */
/* }}} */
/* {{{ mp_mod_d(a, d, c) */
/*
@ -1387,6 +1574,37 @@ mp_mulmod(const mp_int *a, const mp_int *b, const mp_int *m, mp_int *c)
/* }}} */
/* {{{ mp_mulmontmodCT(a, b, m, c) */
/*
mp_mulmontmodCT(a, b, m, c)
Compute c = (a * b) mod m in constant time wrt a and b. either a or b
should be in montgomery form and the output is native. If both a and b
are in montgomery form, then the output will also be in montgomery form
and can be recovered with an mp_reduceCT call.
NOTE: a and b may be modified.
*/
mp_err
mp_mulmontmodCT(mp_int *a, mp_int *b, const mp_int *m, mp_digit n0i,
mp_int *c)
{
mp_err res;
ARGCHK(a != NULL && b != NULL && m != NULL && c != NULL, MP_BADARG);
if ((res = mp_mulCT(a, b, c, MP_USED(m))) != MP_OKAY)
return res;
if ((res = mp_reduceCT(c, m, n0i, c)) != MP_OKAY)
return res;
return MP_OKAY;
}
/* }}} */
/* {{{ mp_sqrmod(a, m, c) */
#if MP_SQUARE
@ -2523,12 +2741,6 @@ mp_read_raw(mp_int *mp, char *str, int len)
mp_zero(mp);
/* Get sign from first byte */
if (ustr[0])
SIGN(mp) = NEG;
else
SIGN(mp) = ZPOS;
/* Read the rest of the digits */
for (ix = 1; ix < len; ix++) {
if ((res = mp_mul_d(mp, 256, mp)) != MP_OKAY)
@ -2537,6 +2749,12 @@ mp_read_raw(mp_int *mp, char *str, int len)
return res;
}
/* Get sign from first byte */
if (ustr[0])
SIGN(mp) = NEG;
else
SIGN(mp) = ZPOS;
return MP_OKAY;
} /* end mp_read_raw() */
@ -2693,7 +2911,7 @@ mp_radix_size(mp_int *mp, int radix)
bits = USED(mp) * DIGIT_BIT - 1;
return s_mp_outlen(bits, radix);
return SIGN(mp) + s_mp_outlen(bits, radix);
} /* end mp_radix_size() */
@ -3248,7 +3466,8 @@ CLEANUP:
/* {{{ s_mp_add_d(mp, d) */
/* Add d to |mp| in place */
mp_err s_mp_add_d(mp_int *mp, mp_digit d) /* unsigned digit addition */
mp_err
s_mp_add_d(mp_int *mp, mp_digit d) /* unsigned digit addition */
{
#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_ADD_WORD)
mp_word w, k = 0;
@ -3305,7 +3524,8 @@ CLEANUP:
/* {{{ s_mp_sub_d(mp, d) */
/* Subtract d from |mp| in place, assumes |mp| > d */
mp_err s_mp_sub_d(mp_int *mp, mp_digit d) /* unsigned digit subtract */
mp_err
s_mp_sub_d(mp_int *mp, mp_digit d) /* unsigned digit subtract */
{
#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
mp_word w, b = 0;
@ -3512,7 +3732,8 @@ CLEANUP:
/* {{{ s_mp_add(a, b) */
/* Compute a = |a| + |b| */
mp_err s_mp_add(mp_int *a, const mp_int *b) /* magnitude addition */
mp_err
s_mp_add(mp_int *a, const mp_int *b) /* magnitude addition */
{
#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_ADD_WORD)
mp_word w = 0;
@ -3775,7 +3996,8 @@ s_mp_add_offset(mp_int *a, mp_int *b, mp_size offset)
/* {{{ s_mp_sub(a, b) */
/* Compute a = |a| - |b|, assumes |a| >= |b| */
mp_err s_mp_sub(mp_int *a, const mp_int *b) /* magnitude subtract */
mp_err
s_mp_sub(mp_int *a, const mp_int *b) /* magnitude subtract */
{
mp_digit *pa, *pb, *limit;
#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
@ -3930,12 +4152,6 @@ s_mp_mul(mp_int *a, const mp_int *b)
Plo = (mp_digit)product; \
Phi = (mp_digit)(product >> MP_DIGIT_BIT); \
}
#elif defined(OSF1)
#define MP_MUL_DxD(a, b, Phi, Plo) \
{ \
Plo = asm("mulq %a0, %a1, %v0", a, b); \
Phi = asm("umulh %a0, %a1, %v0", a, b); \
}
#else
#define MP_MUL_DxD(a, b, Phi, Plo) \
{ \
@ -3946,15 +4162,63 @@ s_mp_mul(mp_int *a, const mp_int *b)
a1b0 = (a >> MP_HALF_DIGIT_BIT) * (b & MP_HALF_DIGIT_MAX); \
a1b0 += a0b1; \
Phi += a1b0 >> MP_HALF_DIGIT_BIT; \
if (a1b0 < a0b1) \
Phi += MP_HALF_RADIX; \
Phi += (MP_CT_LTU(a1b0, a0b1)) << MP_HALF_DIGIT_BIT; \
a1b0 <<= MP_HALF_DIGIT_BIT; \
Plo += a1b0; \
if (Plo < a1b0) \
++Phi; \
Phi += MP_CT_LTU(Plo, a1b0); \
}
#endif
/* Constant time version of s_mpv_mul_d_add_prop.
* Presently, this is only used by the Constant time Montgomery arithmetic code. */
/* c += a * b */
void
s_mpv_mul_d_add_propCT(const mp_digit *a, mp_size a_len, mp_digit b,
mp_digit *c, mp_size c_len)
{
#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_MUL_WORD)
mp_digit d = 0;
c_len -= a_len;
/* Inner product: Digits of a */
while (a_len--) {
mp_word w = ((mp_word)b * *a++) + *c + d;
*c++ = ACCUM(w);
d = CARRYOUT(w);
}
/* propagate the carry to the end, even if carry is zero */
while (c_len--) {
mp_word w = (mp_word)*c + d;
*c++ = ACCUM(w);
d = CARRYOUT(w);
}
#else
mp_digit carry = 0;
c_len -= a_len;
while (a_len--) {
mp_digit a_i = *a++;
mp_digit a0b0, a1b1;
MP_MUL_DxD(a_i, b, a1b1, a0b0);
a0b0 += carry;
a1b1 += MP_CT_LTU(a0b0, carry);
a0b0 += a_i = *c;
a1b1 += MP_CT_LTU(a0b0, a_i);
*c++ = a0b0;
carry = a1b1;
}
/* propagate the carry to the end, even if carry is zero */
while (c_len--) {
mp_digit c_i = *c;
carry += c_i;
*c++ = carry;
carry = MP_CT_LTU(carry, c_i);
}
#endif
}
#if !defined(MP_ASSEMBLY_MULTIPLY)
/* c = a * b */
void
@ -3979,8 +4243,7 @@ s_mpv_mul_d(const mp_digit *a, mp_size a_len, mp_digit b, mp_digit *c)
MP_MUL_DxD(a_i, b, a1b1, a0b0);
a0b0 += carry;
if (a0b0 < carry)
++a1b1;
a1b1 += MP_CT_LTU(a0b0, carry);
*c++ = a0b0;
carry = a1b1;
}
@ -4012,11 +4275,9 @@ s_mpv_mul_d_add(const mp_digit *a, mp_size a_len, mp_digit b,
MP_MUL_DxD(a_i, b, a1b1, a0b0);
a0b0 += carry;
if (a0b0 < carry)
++a1b1;
a1b1 += MP_CT_LTU(a0b0, carry);
a0b0 += a_i = *c;
if (a0b0 < a_i)
++a1b1;
a1b1 += MP_CT_LTU(a0b0, a_i);
*c++ = a0b0;
carry = a1b1;
}
@ -4081,12 +4342,6 @@ s_mpv_mul_d_add_prop(const mp_digit *a, mp_size a_len, mp_digit b, mp_digit *c)
Plo = (mp_digit)square; \
Phi = (mp_digit)(square >> MP_DIGIT_BIT); \
}
#elif defined(OSF1)
#define MP_SQR_D(a, Phi, Plo) \
{ \
Plo = asm("mulq %a0, %a0, %v0", a); \
Phi = asm("umulh %a0, %a0, %v0", a); \
}
#else
#define MP_SQR_D(a, Phi, Plo) \
{ \
@ -4253,9 +4508,10 @@ s_mp_sqr(mp_int *a)
Compute a = a / b and b = a mod b. Assumes b > a.
*/
mp_err s_mp_div(mp_int *rem, /* i: dividend, o: remainder */
mp_int *div, /* i: divisor */
mp_int *quot) /* i: 0; o: quotient */
mp_err
s_mp_div(mp_int *rem, /* i: dividend, o: remainder */
mp_int *div, /* i: divisor */
mp_int *quot) /* i: 0; o: quotient */
{
mp_int part, t;
mp_digit q_msd;

View file

@ -64,7 +64,7 @@ typedef int mp_err;
/* MP_ULONG_LONG_MAX was defined to be ULLONG_MAX */
#elif defined(ULONG_LONG_MAX) /* HPUX */
#define MP_ULONG_LONG_MAX ULONG_LONG_MAX
#elif defined(ULONGLONG_MAX) /* IRIX, AIX */
#elif defined(ULONGLONG_MAX) /* AIX */
#define MP_ULONG_LONG_MAX ULONGLONG_MAX
#endif
@ -150,6 +150,38 @@ typedef int mp_sword;
/* This defines the maximum I/O base (minimum is 2) */
#define MP_MAX_RADIX 64
/* Constant Time Macros on mp_digits */
#define MP_CT_HIGH_TO_LOW(x) ((mp_digit)((mp_digit)(x) >> (MP_DIGIT_BIT - 1)))
#define MP_CT_TRUE ((mp_digit)1)
#define MP_CT_FALSE ((mp_digit)0)
/* basic zero and non zero tests */
#define MP_CT_NOT_ZERO(x) (MP_CT_HIGH_TO_LOW(((x) | (((mp_digit)0) - (x)))))
#define MP_CT_ZERO(x) (MP_CT_TRUE ^ MP_CT_HIGH_TO_LOW(((x) | (((mp_digit)0) - (x)))))
/* basic constant-time helper macro for equalities and inequalities.
* The inequalities will produce incorrect results if
* abs(a-b) >= MP_DIGIT_SIZE/2. This can be avoided if unsigned values stay
* within the range 0-MP_DIGIT_MAX/2. */
#define MP_CT_EQ(a, b) MP_CT_ZERO(((a) ^ (b)))
#define MP_CT_NE(a, b) MP_CT_NOT_ZERO(((a) ^ (b)))
#define MP_CT_GT(a, b) MP_CT_HIGH_TO_LOW((b) - (a))
#define MP_CT_LT(a, b) MP_CT_HIGH_TO_LOW((a) - (b))
#define MP_CT_GE(a, b) (MP_CT_TRUE ^ MP_CT_LT(a, b))
#define MP_CT_LE(a, b) (MP_CT_TRUE ^ MP_CT_GT(a, b))
/* use constant time result to select a boolean value
* or an mp digit depending on the args */
#define MP_CT_SEL(m, l, r) ((r) ^ ((m) & ((r) ^ (l))))
#define MP_CT_SELB(m, l, r) MP_CT_SEL(m, l, r) /* mask, l and r are booleans */
#define MP_CT_SEL_DIGIT(m, l, r) MP_CT_SEL(m, l, r) /*mask, l, and r are mp_digit */
/* full inequalities that work with full mp_digit values */
#define MP_CT_OVERFLOW(a, b, c, d) \
MP_CT_SELB(MP_CT_HIGH_TO_LOW((a) ^ (b)), \
(MP_CT_HIGH_TO_LOW(d)), c)
#define MP_CT_LTU(a, b) MP_CT_OVERFLOW(a, b, MP_CT_LT(a, b), b)
typedef struct {
mp_sign sign; /* sign of this quantity */
mp_size alloc; /* how many digits allocated */
@ -190,7 +222,9 @@ mp_err mp_neg(const mp_int *a, mp_int *b);
/* Full arithmetic */
mp_err mp_add(const mp_int *a, const mp_int *b, mp_int *c);
mp_err mp_sub(const mp_int *a, const mp_int *b, mp_int *c);
mp_err mp_subCT(const mp_int *a, mp_int *b, mp_int *c, mp_digit *borrow);
mp_err mp_mul(const mp_int *a, const mp_int *b, mp_int *c);
mp_err mp_mulCT(mp_int *a, mp_int *b, mp_int *c, mp_size setSize);
#if MP_SQUARE
mp_err mp_sqr(const mp_int *a, mp_int *b);
#else
@ -217,6 +251,12 @@ mp_err mp_exptmod(const mp_int *a, const mp_int *b, const mp_int *m, mp_int *c);
mp_err mp_exptmod_d(const mp_int *a, mp_digit d, const mp_int *m, mp_int *c);
#endif /* MP_MODARITH */
/* montgomery math */
mp_err mp_to_mont(const mp_int *x, const mp_int *N, mp_int *xMont);
mp_digit mp_calculate_mont_n0i(const mp_int *N);
mp_err mp_reduceCT(const mp_int *a, const mp_int *m, mp_digit n0i, mp_int *ct);
mp_err mp_mulmontmodCT(mp_int *a, mp_int *b, const mp_int *m, mp_digit n0i, mp_int *c);
/* Comparisons */
int mp_cmp_z(const mp_int *a);
int mp_cmp_d(const mp_int *a, mp_digit d);
@ -224,6 +264,7 @@ int mp_cmp(const mp_int *a, const mp_int *b);
int mp_cmp_mag(const mp_int *a, const mp_int *b);
int mp_isodd(const mp_int *a);
int mp_iseven(const mp_int *a);
mp_err mp_selectCT(mp_digit cond, const mp_int *a, const mp_int *b, mp_int *ret);
/* Number theoretic */
mp_err mp_gcd(mp_int *a, mp_int *b, mp_int *c);

View file

@ -18,7 +18,15 @@
# s_mpv_mul_set_vec64(uint64_t *r, uint64_t *a, int len, uint64_t digit)
#
.text; .align 16; .globl s_mpv_mul_set_vec64; .type s_mpv_mul_set_vec64, @function; s_mpv_mul_set_vec64:
.text; .align 16; .globl s_mpv_mul_set_vec64;
#ifdef DARWIN
#define s_mpv_mul_set_vec64 _s_mpv_mul_set_vec64
.private_extern s_mpv_mul_set_vec64
s_mpv_mul_set_vec64:
#else
.type s_mpv_mul_set_vec64, @function; s_mpv_mul_set_vec64:
#endif
xorq %rax, %rax # if (len == 0) return (0)
testq %rdx, %rdx
@ -169,7 +177,9 @@
movq %r9, %rax
ret
#ifndef DARWIN
.size s_mpv_mul_set_vec64, .-s_mpv_mul_set_vec64
#endif
# ------------------------------------------------------------------------
#
@ -186,7 +196,15 @@
# s_mpv_mul_add_vec64(uint64_t *r, uint64_t *a, int len, uint64_t digit)
#
.text; .align 16; .globl s_mpv_mul_add_vec64; .type s_mpv_mul_add_vec64, @function; s_mpv_mul_add_vec64:
.text; .align 16; .globl s_mpv_mul_add_vec64;
#ifdef DARWIN
#define s_mpv_mul_add_vec64 _s_mpv_mul_add_vec64
.private_extern s_mpv_mul_add_vec64
s_mpv_mul_add_vec64:
#else
.type s_mpv_mul_add_vec64, @function; s_mpv_mul_add_vec64:
#endif
xorq %rax, %rax # if (len == 0) return (0)
testq %rdx, %rdx
@ -381,9 +399,11 @@
.L27:
movq %r9, %rax
ret
#ifndef DARWIN
.size s_mpv_mul_add_vec64, .-s_mpv_mul_add_vec64
# Magic indicating no need for an executable stack
.section .note.GNU-stack, "", @progbits
.previous
#endif

View file

@ -222,10 +222,9 @@ mpl_lsh(const mp_int *a, mp_int *b, mp_digit d)
/* {{{ mpl_num_set(a, num) */
mp_err
mpl_num_set(mp_int *a, int *num)
mpl_num_set(mp_int *a, unsigned int *num)
{
unsigned int ix;
int db, nset = 0;
unsigned int ix, db, nset = 0;
mp_digit cur;
unsigned char reg;
@ -253,10 +252,9 @@ mpl_num_set(mp_int *a, int *num)
/* {{{ mpl_num_clear(a, num) */
mp_err
mpl_num_clear(mp_int *a, int *num)
mpl_num_clear(mp_int *a, unsigned int *num)
{
unsigned int ix;
int db, nset = 0;
unsigned int ix, db, nset = 0;
mp_digit cur;
unsigned char reg;

View file

@ -11,6 +11,7 @@
#define _H_MPLOGIC_
#include "mpi.h"
SEC_BEGIN_PROTOS
/*
The logical operations treat an mp_int as if it were a bit vector,
@ -38,9 +39,9 @@ mp_err mpl_lsh(const mp_int *a, mp_int *b, mp_digit d); /* left shift */
/* Bit count and parity */
mp_err mpl_num_set(mp_int *a, int *num); /* count set bits */
mp_err mpl_num_clear(mp_int *a, int *num); /* count clear bits */
mp_err mpl_parity(mp_int *a); /* determine parity */
mp_err mpl_num_set(mp_int *a, unsigned int *num); /* count set bits */
mp_err mpl_num_clear(mp_int *a, unsigned int *num); /* count clear bits */
mp_err mpl_parity(mp_int *a); /* determine parity */
/* Get & Set the value of a bit */
@ -49,4 +50,6 @@ mp_err mpl_get_bit(const mp_int *a, mp_size bitNum);
mp_err mpl_get_bits(const mp_int *a, mp_size lsbNum, mp_size numBits);
mp_size mpl_significant_bits(const mp_int *a);
SEC_END_PROTOS
#endif /* end _H_MPLOGIC_ */

View file

@ -129,20 +129,27 @@ CLEANUP:
}
#endif
STATIC
mp_err
s_mp_to_mont(const mp_int *x, mp_mont_modulus *mmm, mp_int *xMont)
mp_to_mont(const mp_int *x, const mp_int *N, mp_int *xMont)
{
mp_err res;
/* xMont = x * R mod N where N is modulus */
MP_CHECKOK(mp_copy(x, xMont));
MP_CHECKOK(s_mp_lshd(xMont, MP_USED(&mmm->N))); /* xMont = x << b */
MP_CHECKOK(mp_div(xMont, &mmm->N, 0, xMont)); /* mod N */
if (x != xMont) {
MP_CHECKOK(mp_copy(x, xMont));
}
MP_CHECKOK(s_mp_lshd(xMont, MP_USED(N))); /* xMont = x << b */
MP_CHECKOK(mp_div(xMont, N, 0, xMont)); /* mod N */
CLEANUP:
return res;
}
mp_digit
mp_calculate_mont_n0i(const mp_int *N)
{
return 0 - s_mp_invmod_radix(MP_DIGIT(N, 0));
}
#ifdef MP_USING_MONT_MULF
/* the floating point multiply is already cache safe,
@ -198,7 +205,7 @@ mp_exptmod_f(const mp_int *montBase,
MP_CHECKOK(mp_init_size(&accum1, 3 * nLen + 2));
mp_set(&accum1, 1);
MP_CHECKOK(s_mp_to_mont(&accum1, mmm, &accum1));
MP_CHECKOK(mp_to_mont(&accum1, &(mmm->N), &accum1));
MP_CHECKOK(s_mp_pad(&accum1, nLen));
oddPowSize = 2 * nLen + 1;
@ -478,7 +485,7 @@ mp_exptmod_i(const mp_int *montBase,
/* set accumulator to montgomery residue of 1 */
mp_set(&accum1, 1);
MP_CHECKOK(s_mp_to_mont(&accum1, mmm, &accum1));
MP_CHECKOK(mp_to_mont(&accum1, &(mmm->N), &accum1));
pa1 = &accum1;
pa2 = &accum2;
@ -723,10 +730,11 @@ mp_set_safe_modexp(int value)
* mp_ints that use less than nDigits digits are logically padded with zeros
* while being stored in the weaved array.
*/
mp_err mpi_to_weave(const mp_int *bignums,
mp_digit *weaved,
mp_size nDigits, /* in each mp_int of input */
mp_size nBignums) /* in the entire source array */
mp_err
mpi_to_weave(const mp_int *bignums,
mp_digit *weaved,
mp_size nDigits, /* in each mp_int of input */
mp_size nBignums) /* in the entire source array */
{
mp_size i;
mp_digit *endDest = weaved + (nDigits * nBignums);
@ -765,11 +773,12 @@ mp_err mpi_to_weave(const mp_int *bignums,
* Every read accesses every element of the weaved array, in order to
* avoid timing attacks based on patterns of memory accesses.
*/
mp_err weave_to_mpi(mp_int *a, /* out, result */
const mp_digit *weaved, /* in, byte matrix */
mp_size index, /* which column to read */
mp_size nDigits, /* number of mp_digits in each bignum */
mp_size nBignums) /* width of the matrix */
mp_err
weave_to_mpi(mp_int *a, /* out, result */
const mp_digit *weaved, /* in, byte matrix */
mp_size index, /* which column to read */
mp_size nDigits, /* number of mp_digits in each bignum */
mp_size nBignums) /* width of the matrix */
{
/* these are indices, but need to be the same size as mp_digit
* because of the CONST_TIME operations */
@ -865,7 +874,7 @@ mp_exptmod_safe_i(const mp_int *montBase,
MP_CHECKOK(mp_init_size(&accum[2], 3 * nLen + 2));
MP_CHECKOK(mp_init_size(&accum[3], 3 * nLen + 2));
mp_set(&accum[0], 1);
MP_CHECKOK(s_mp_to_mont(&accum[0], mmm, &accum[0]));
MP_CHECKOK(mp_to_mont(&accum[0], &(mmm->N), &accum[0]));
MP_CHECKOK(mp_copy(montBase, &accum[1]));
SQR(montBase, &accum[2]);
MUL_NOWEAVE(montBase, &accum[2], &accum[3]);
@ -884,7 +893,7 @@ mp_exptmod_safe_i(const mp_int *montBase,
} else {
if (first_window == 0) {
mp_set(&accum1, 1);
MP_CHECKOK(s_mp_to_mont(&accum1, mmm, &accum1));
MP_CHECKOK(mp_to_mont(&accum1, &(mmm->N), &accum1));
} else {
/* assert first_window == 1? */
MP_CHECKOK(mp_copy(montBase, &accum1));
@ -1006,7 +1015,11 @@ CLEANUP:
mp_clear(&accum[2]);
mp_clear(&accum[3]);
mp_clear(&tmp);
/* PORT_Memset(powers,0,num_powers*nLen*sizeof(mp_digit)); */
/* zero required by FIPS here, can't use PORT_ZFree
* because mpi doesn't link with util */
if (powers) {
PORT_Memset(powers, 0, num_powers * sizeof(mp_digit));
}
free(powersArray);
return res;
}
@ -1051,9 +1064,9 @@ mp_exptmod(const mp_int *inBase, const mp_int *exponent,
/* compute n0', given n0, n0' = -(n0 ** -1) mod MP_RADIX
** where n0 = least significant mp_digit of N, the modulus.
*/
mmm.n0prime = 0 - s_mp_invmod_radix(MP_DIGIT(modulus, 0));
mmm.n0prime = mp_calculate_mont_n0i(modulus);
MP_CHECKOK(s_mp_to_mont(base, &mmm, &montBase));
MP_CHECKOK(mp_to_mont(base, modulus, &montBase));
bits_in_exponent = mpl_significant_bits(exponent);
#ifdef MP_USING_CACHE_SAFE_MOD_EXP

View file

@ -126,6 +126,8 @@ mpp_random(mp_int *a)
/* }}} */
static mpp_random_fn mpp_random_insecure = &mpp_random;
/* {{{ mpp_random_size(a, prec) */
mp_err
@ -138,7 +140,7 @@ mpp_random_size(mp_int *a, mp_size prec)
if ((res = s_mp_pad(a, prec)) != MP_OKAY)
return res;
return mpp_random(a);
return (*mpp_random_insecure)(a);
} /* end mpp_random_size() */
@ -271,6 +273,12 @@ mpp_fermat_list(mp_int *a, const mp_digit *primes, mp_size nPrimes)
mp_err
mpp_pprime(mp_int *a, int nt)
{
return mpp_pprime_ext_random(a, nt, mpp_random_insecure);
}
mp_err
mpp_pprime_ext_random(mp_int *a, int nt, mpp_random_fn random)
{
mp_err res;
mp_int x, amo, m, z; /* "amo" = "a minus one" */
@ -306,7 +314,7 @@ mpp_pprime(mp_int *a, int nt)
/* Choose a random value for 1 < x < a */
MP_CHECKOK(s_mp_pad(&x, USED(a)));
mpp_random(&x);
MP_CHECKOK((*random)(&x));
MP_CHECKOK(mp_mod(&x, a, &x));
if (mp_cmp_d(&x, 1) <= 0) {
iter--; /* don't count this iteration */
@ -403,6 +411,12 @@ mpp_sieve(mp_int *trial, const mp_digit *primes, mp_size nPrimes,
mp_err
mpp_make_prime(mp_int *start, mp_size nBits, mp_size strong)
{
return mpp_make_prime_ext_random(start, nBits, strong, mpp_random_insecure);
}
mp_err
mpp_make_prime_ext_random(mp_int *start, mp_size nBits, mp_size strong, mpp_random_fn random)
{
mp_digit np;
mp_err res;
@ -490,7 +504,7 @@ mpp_make_prime(mp_int *start, mp_size nBits, mp_size strong)
FPUTC('+', stderr);
/* If that passed, run some Miller-Rabin tests */
res = mpp_pprime(&trial, num_tests);
res = mpp_pprime_ext_random(&trial, num_tests, random);
if (res != MP_OKAY) {
if (res == MP_NO)
continue; /* was composite */
@ -528,7 +542,7 @@ mpp_make_prime(mp_int *start, mp_size nBits, mp_size strong)
}
/* And test with Miller-Rabin, as with its parent ... */
res = mpp_pprime(&q, num_tests);
res = mpp_pprime_ext_random(&q, num_tests, random);
if (res != MP_YES) {
mp_clear(&q);
if (res == MP_NO)

View file

@ -26,6 +26,9 @@ mp_err mpp_divis_d(mp_int *a, mp_digit d);
mp_err mpp_random(mp_int *a);
mp_err mpp_random_size(mp_int *a, mp_size prec);
/* Type for a pointer to a user-provided mpp_random implementation */
typedef mp_err (*mpp_random_fn)(mp_int *);
/* Pseudo-primality testing */
mp_err mpp_divis_vector(mp_int *a, const mp_digit *vec, int size, int *which);
mp_err mpp_divis_primes(mp_int *a, mp_digit *np);
@ -36,6 +39,10 @@ mp_err mpp_sieve(mp_int *trial, const mp_digit *primes, mp_size nPrimes,
unsigned char *sieve, mp_size nSieve);
mp_err mpp_make_prime(mp_int *start, mp_size nBits, mp_size strong);
/* Pseudo-primality tests using a user-provided mpp_random implementation */
mp_err mpp_pprime_ext_random(mp_int *a, int nt, mpp_random_fn random);
mp_err mpp_make_prime_ext_random(mp_int *start, mp_size nBits, mp_size strong, mpp_random_fn random);
SEC_END_PROTOS
#endif /* end _H_MP_PRIME_ */

View file

@ -836,6 +836,6 @@ const mp_digit prime_tab[] = {
0xFE95, 0xFE9B, 0xFE9F, 0xFEB3, 0xFEBD, 0xFED7, 0xFEE9, 0xFEF3,
0xFEF5, 0xFF07, 0xFF0D, 0xFF1D, 0xFF2B, 0xFF2F, 0xFF49, 0xFF4D,
0xFF5B, 0xFF65, 0xFF71, 0xFF7F, 0xFF85, 0xFF8B, 0xFF8F, 0xFF9D,
0xFFA7, 0xFFA9, 0xFFC7, 0xFFD9, 0xFFEF, 0xFFF1,
0xFFA7, 0xFFA9, 0xFFC7, 0xFFD9, 0xFFEF, 0xFFF1
#endif
};