| Line | Source | Count |
| 1 | | - |
| 2 | | - |
| 3 | | - |
| 4 | | - |
| 5 | | - |
| 6 | | - |
| 7 | | - |
| 8 | | - |
| 9 | | - |
| 10 | | - |
| 11 | | - |
| 12 | | - |
| 13 | | - |
| 14 | | - |
| 15 | | - |
| 16 | | - |
| 17 | | - |
| 18 | | - |
| 19 | | - |
| 20 | | - |
| 21 | | - |
| 22 | | - |
| 23 | | - |
| 24 | | - |
| 25 | | - |
| 26 | | - |
| 27 | | - |
| 28 | | - |
| 29 | | - |
| 30 | | - |
| 31 | | - |
| 32 | | - |
| 33 | | - |
| 34 | | - |
| 35 | | - |
| 36 | | - |
| 37 | | - |
| 38 | | - |
| 39 | | - |
| 40 | | - |
| 41 | | - |
| 42 | | - |
| 43 | | - |
| 44 | | - |
| 45 | | - |
| 46 | | - |
| 47 | | - |
| 48 | | - |
| 49 | | - |
| 50 | | - |
| 51 | | - |
| 52 | | - |
| 53 | | - |
| 54 | | - |
| 55 | | - |
| 56 | | - |
| 57 | | - |
| 58 | | - |
| 59 | | - |
| 60 | | - |
| 61 | | - |
| 62 | | - |
| 63 | | - |
| 64 | | - |
| 65 | | - |
| 66 | | - |
| 67 | | - |
| 68 | | - |
| 69 | | - |
| 70 | | - |
| 71 | | - |
| 72 | | - |
| 73 | | - |
| 74 | | - |
| 75 | | - |
| 76 | | - |
| 77 | | - |
| 78 | | - |
| 79 | | - |
| 80 | | - |
| 81 | | - |
| 82 | | - |
| 83 | | - |
| 84 | | - |
| 85 | | - |
| 86 | | - |
| 87 | | - |
| 88 | | - |
| 89 | | - |
| 90 | | - |
| 91 | | - |
| 92 | | - |
| 93 | | - |
| 94 | | - |
| 95 | | - |
| 96 | | - |
| 97 | | - |
| 98 | | - |
| 99 | | - |
| 100 | | - |
| 101 | | - |
| 102 | | - |
| 103 | | - |
| 104 | | - |
| 105 | | - |
| 106 | | - |
| 107 | | - |
| 108 | | - |
| 109 | | - |
| 110 | | - |
| 111 | | - |
| 112 | #include <stdio.h> | - |
| 113 | | - |
| 114 | #include <openssl/err.h> | - |
| 115 | | - |
| 116 | #include "bn_lcl.h" | - |
| 117 | | - |
| 118 | #define TABLE_SIZE 32 | - |
| 119 | | - |
| 120 | int | - |
| 121 | BN_mod_exp2_mont(BIGNUM *rr, const BIGNUM *a1, const BIGNUM *p1, | - |
| 122 | const BIGNUM *a2, const BIGNUM *p2, const BIGNUM *m, BN_CTX *ctx, | - |
| 123 | BN_MONT_CTX *in_mont) | - |
| 124 | { | - |
| 125 | int i, j, bits, b, bits1, bits2, ret = 0, wpos1, wpos2, window1, window2, wvalue1, wvalue2; | - |
| 126 | int r_is_one = 1; | - |
| 127 | BIGNUM *d, *r; | - |
| 128 | const BIGNUM *a_mod_m; | - |
| 129 | | - |
| 130 | BIGNUM *val1[TABLE_SIZE], *val2[TABLE_SIZE]; | - |
| 131 | BN_MONT_CTX *mont = NULL; | - |
| 132 | | - |
| 133 | bn_check_top(a1); | - |
| 134 | bn_check_top(p1); | - |
| 135 | bn_check_top(a2); | - |
| 136 | bn_check_top(p2); | - |
| 137 | bn_check_top(m); | - |
| 138 | | - |
| 139 | if (!(m->d[0] & 1)) {| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 140 | BNerror(BN_R_CALLED_WITH_EVEN_MODULUS); | - |
| 141 | return (0); never executed: return (0); | 0 |
| 142 | } | - |
| 143 | bits1 = BN_num_bits(p1); | - |
| 144 | bits2 = BN_num_bits(p2); | - |
| 145 | if ((bits1 == 0) && (bits2 == 0)) {| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| TRUE | never evaluated | | FALSE | never evaluated |
| 0-1 |
| 146 | ret = BN_one(rr); | - |
| 147 | return ret; never executed: return ret; | 0 |
| 148 | } | - |
| 149 | | - |
| 150 | bits = (bits1 > bits2) ? bits1 : bits2;| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 151 | | - |
| 152 | BN_CTX_start(ctx); | - |
| 153 | if ((d = BN_CTX_get(ctx)) == NULL)| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 154 | goto err; never executed: goto err; | 0 |
| 155 | if ((r = BN_CTX_get(ctx)) == NULL)| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 156 | goto err; never executed: goto err; | 0 |
| 157 | if ((val1[0] = BN_CTX_get(ctx)) == NULL)| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 158 | goto err; never executed: goto err; | 0 |
| 159 | if ((val2[0] = BN_CTX_get(ctx)) == NULL)| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 160 | goto err; never executed: goto err; | 0 |
| 161 | | - |
| 162 | if (in_mont != NULL)| TRUE | evaluated 1 time by 1 test | | FALSE | never evaluated |
| 0-1 |
| 163 | mont = in_mont;executed 1 time by 1 test: mont = in_mont; | 1 |
| 164 | else { | - |
| 165 | if ((mont = BN_MONT_CTX_new()) == NULL)| TRUE | never evaluated | | FALSE | never evaluated |
| 0 |
| 166 | goto err; never executed: goto err; | 0 |
| 167 | if (!BN_MONT_CTX_set(mont, m, ctx))| TRUE | never evaluated | | FALSE | never evaluated |
| 0 |
| 168 | goto err; never executed: goto err; | 0 |
| 169 | } never executed: end of block | 0 |
| 170 | | - |
| 171 | window1 = BN_window_bits_for_exponent_size(bits1);| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| TRUE | evaluated 1 time by 1 test | | FALSE | never evaluated |
| TRUE | never evaluated | | FALSE | never evaluated |
| 0-1 |
| 172 | window2 = BN_window_bits_for_exponent_size(bits2);| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| TRUE | evaluated 1 time by 1 test | | FALSE | never evaluated |
| TRUE | never evaluated | | FALSE | never evaluated |
| 0-1 |
| 173 | | - |
| 174 | | - |
| 175 | | - |
| 176 | | - |
| 177 | if (a1->neg || BN_ucmp(a1, m) >= 0) {| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 178 | if (!BN_mod_ct(val1[0], a1, m, ctx))| TRUE | never evaluated | | FALSE | never evaluated |
| 0 |
| 179 | goto err; never executed: goto err; | 0 |
| 180 | a_mod_m = val1[0]; | - |
| 181 | } else never executed: end of block | 0 |
| 182 | a_mod_m = a1;executed 1 time by 1 test: a_mod_m = a1; | 1 |
| 183 | if (BN_is_zero(a_mod_m)) {| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 184 | BN_zero(rr); | - |
| 185 | ret = 1; | - |
| 186 | goto err; never executed: goto err; | 0 |
| 187 | } | - |
| 188 | | - |
| 189 | if (!BN_to_montgomery(val1[0], a_mod_m, mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 190 | goto err; never executed: goto err; | 0 |
| 191 | if (window1 > 1) {| TRUE | evaluated 1 time by 1 test | | FALSE | never evaluated |
| 0-1 |
| 192 | if (!BN_mod_mul_montgomery(d, val1[0], val1[0], mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 193 | goto err; never executed: goto err; | 0 |
| 194 | | - |
| 195 | j = 1 << (window1 - 1); | - |
| 196 | for (i = 1; i < j; i++) {| TRUE | evaluated 7 times by 1 test | | FALSE | evaluated 1 time by 1 test |
| 1-7 |
| 197 | if (((val1[i] = BN_CTX_get(ctx)) == NULL) ||| TRUE | never evaluated | | FALSE | evaluated 7 times by 1 test |
| 0-7 |
| 198 | !BN_mod_mul_montgomery(val1[i], val1[i - 1],| TRUE | never evaluated | | FALSE | evaluated 7 times by 1 test |
| 0-7 |
| 199 | d, mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 7 times by 1 test |
| 0-7 |
| 200 | goto err; never executed: goto err; | 0 |
| 201 | }executed 7 times by 1 test: end of block | 7 |
| 202 | }executed 1 time by 1 test: end of block | 1 |
| 203 | | - |
| 204 | | - |
| 205 | | - |
| 206 | | - |
| 207 | | - |
| 208 | if (a2->neg || BN_ucmp(a2, m) >= 0) {| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 209 | if (!BN_mod_ct(val2[0], a2, m, ctx))| TRUE | never evaluated | | FALSE | never evaluated |
| 0 |
| 210 | goto err; never executed: goto err; | 0 |
| 211 | a_mod_m = val2[0]; | - |
| 212 | } else never executed: end of block | 0 |
| 213 | a_mod_m = a2;executed 1 time by 1 test: a_mod_m = a2; | 1 |
| 214 | if (BN_is_zero(a_mod_m)) {| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 215 | BN_zero(rr); | - |
| 216 | ret = 1; | - |
| 217 | goto err; never executed: goto err; | 0 |
| 218 | } | - |
| 219 | if (!BN_to_montgomery(val2[0], a_mod_m, mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 220 | goto err; never executed: goto err; | 0 |
| 221 | if (window2 > 1) {| TRUE | evaluated 1 time by 1 test | | FALSE | never evaluated |
| 0-1 |
| 222 | if (!BN_mod_mul_montgomery(d, val2[0], val2[0], mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 223 | goto err; never executed: goto err; | 0 |
| 224 | | - |
| 225 | j = 1 << (window2 - 1); | - |
| 226 | for (i = 1; i < j; i++) {| TRUE | evaluated 7 times by 1 test | | FALSE | evaluated 1 time by 1 test |
| 1-7 |
| 227 | if (((val2[i] = BN_CTX_get(ctx)) == NULL) ||| TRUE | never evaluated | | FALSE | evaluated 7 times by 1 test |
| 0-7 |
| 228 | !BN_mod_mul_montgomery(val2[i], val2[i - 1],| TRUE | never evaluated | | FALSE | evaluated 7 times by 1 test |
| 0-7 |
| 229 | d, mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 7 times by 1 test |
| 0-7 |
| 230 | goto err; never executed: goto err; | 0 |
| 231 | }executed 7 times by 1 test: end of block | 7 |
| 232 | }executed 1 time by 1 test: end of block | 1 |
| 233 | | - |
| 234 | | - |
| 235 | | - |
| 236 | r_is_one = 1; | - |
| 237 | wvalue1 = 0; | - |
| 238 | wvalue2 = 0; | - |
| 239 | wpos1 = 0; | - |
| 240 | wpos2 = 0; | - |
| 241 | | - |
| 242 | if (!BN_to_montgomery(r, BN_value_one(), mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 243 | goto err; never executed: goto err; | 0 |
| 244 | for (b = bits - 1; b >= 0; b--) {| TRUE | evaluated 160 times by 1 test | | FALSE | evaluated 1 time by 1 test |
| 1-160 |
| 245 | if (!r_is_one) {| TRUE | evaluated 156 times by 1 test | | FALSE | evaluated 4 times by 1 test |
| 4-156 |
| 246 | if (!BN_mod_mul_montgomery(r, r,r, mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 156 times by 1 test |
| 0-156 |
| 247 | goto err; never executed: goto err; | 0 |
| 248 | }executed 156 times by 1 test: end of block | 156 |
| 249 | | - |
| 250 | if (!wvalue1)| TRUE | evaluated 100 times by 1 test | | FALSE | evaluated 60 times by 1 test |
| 60-100 |
| 251 | if (BN_is_bit_set(p1, b)) {| TRUE | evaluated 31 times by 1 test | | FALSE | evaluated 69 times by 1 test |
| 31-69 |
| 252 | | - |
| 253 | i = b - window1 + 1; | - |
| 254 | while (!BN_is_bit_set(p1, i)) | TRUE | evaluated 33 times by 1 test | | FALSE | evaluated 31 times by 1 test |
| 31-33 |
| 255 | i++;executed 33 times by 1 test: i++; | 33 |
| 256 | wpos1 = i; | - |
| 257 | wvalue1 = 1; | - |
| 258 | for (i = b - 1; i >= wpos1; i--) {| TRUE | evaluated 60 times by 1 test | | FALSE | evaluated 31 times by 1 test |
| 31-60 |
| 259 | wvalue1 <<= 1; | - |
| 260 | if (BN_is_bit_set(p1, i))| TRUE | evaluated 39 times by 1 test | | FALSE | evaluated 21 times by 1 test |
| 21-39 |
| 261 | wvalue1++;executed 39 times by 1 test: wvalue1++; | 39 |
| 262 | }executed 60 times by 1 test: end of block | 60 |
| 263 | }executed 31 times by 1 test: end of block | 31 |
| 264 | | - |
| 265 | if (!wvalue2)| TRUE | evaluated 92 times by 1 test | | FALSE | evaluated 68 times by 1 test |
| 68-92 |
| 266 | if (BN_is_bit_set(p2, b)) {| TRUE | evaluated 33 times by 1 test | | FALSE | evaluated 59 times by 1 test |
| 33-59 |
| 267 | | - |
| 268 | i = b - window2 + 1; | - |
| 269 | while (!BN_is_bit_set(p2, i))| TRUE | evaluated 31 times by 1 test | | FALSE | evaluated 33 times by 1 test |
| 31-33 |
| 270 | i++;executed 31 times by 1 test: i++; | 31 |
| 271 | wpos2 = i; | - |
| 272 | wvalue2 = 1; | - |
| 273 | for (i = b - 1; i >= wpos2; i--) {| TRUE | evaluated 68 times by 1 test | | FALSE | evaluated 33 times by 1 test |
| 33-68 |
| 274 | wvalue2 <<= 1; | - |
| 275 | if (BN_is_bit_set(p2, i))| TRUE | evaluated 52 times by 1 test | | FALSE | evaluated 16 times by 1 test |
| 16-52 |
| 276 | wvalue2++;executed 52 times by 1 test: wvalue2++; | 52 |
| 277 | }executed 68 times by 1 test: end of block | 68 |
| 278 | }executed 33 times by 1 test: end of block | 33 |
| 279 | | - |
| 280 | if (wvalue1 && b == wpos1) {| TRUE | evaluated 91 times by 1 test | | FALSE | evaluated 69 times by 1 test |
| TRUE | evaluated 31 times by 1 test | | FALSE | evaluated 60 times by 1 test |
| 31-91 |
| 281 | | - |
| 282 | if (!BN_mod_mul_montgomery(r, r, val1[wvalue1 >> 1],| TRUE | never evaluated | | FALSE | evaluated 31 times by 1 test |
| 0-31 |
| 283 | mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 31 times by 1 test |
| 0-31 |
| 284 | goto err; never executed: goto err; | 0 |
| 285 | wvalue1 = 0; | - |
| 286 | r_is_one = 0; | - |
| 287 | }executed 31 times by 1 test: end of block | 31 |
| 288 | | - |
| 289 | if (wvalue2 && b == wpos2) {| TRUE | evaluated 101 times by 1 test | | FALSE | evaluated 59 times by 1 test |
| TRUE | evaluated 33 times by 1 test | | FALSE | evaluated 68 times by 1 test |
| 33-101 |
| 290 | | - |
| 291 | if (!BN_mod_mul_montgomery(r, r, val2[wvalue2 >> 1],| TRUE | never evaluated | | FALSE | evaluated 33 times by 1 test |
| 0-33 |
| 292 | mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 33 times by 1 test |
| 0-33 |
| 293 | goto err; never executed: goto err; | 0 |
| 294 | wvalue2 = 0; | - |
| 295 | r_is_one = 0; | - |
| 296 | }executed 33 times by 1 test: end of block | 33 |
| 297 | }executed 160 times by 1 test: end of block | 160 |
| 298 | if (!BN_from_montgomery(rr, r,mont, ctx))| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| 0-1 |
| 299 | goto err; never executed: goto err; | 0 |
| 300 | ret = 1; | - |
| 301 | | - |
| 302 | err:code before this statement executed 1 time by 1 test: err: | 1 |
| 303 | if ((in_mont == NULL) && (mont != NULL))| TRUE | never evaluated | | FALSE | evaluated 1 time by 1 test |
| TRUE | never evaluated | | FALSE | never evaluated |
| 0-1 |
| 304 | BN_MONT_CTX_free(mont); never executed: BN_MONT_CTX_free(mont); | 0 |
| 305 | BN_CTX_end(ctx); | - |
| 306 | bn_check_top(rr); | - |
| 307 | return (ret);executed 1 time by 1 test: return (ret); | 1 |
| 308 | } | - |
| | |