clang -cc1 -cc1 -triple amd64-unknown-openbsd7.0 -analyze -disable-free -disable-llvm-verifier -discard-value-names -main-file-name bn_exp2.c -analyzer-store=region -analyzer-opt-analyze-nested-blocks -analyzer-checker=core -analyzer-checker=apiModeling -analyzer-checker=unix -analyzer-checker=deadcode -analyzer-checker=security.insecureAPI.UncheckedReturn -analyzer-checker=security.insecureAPI.getpw -analyzer-checker=security.insecureAPI.gets -analyzer-checker=security.insecureAPI.mktemp -analyzer-checker=security.insecureAPI.mkstemp -analyzer-checker=security.insecureAPI.vfork -analyzer-checker=nullability.NullPassedToNonnull -analyzer-checker=nullability.NullReturnedFromNonnull -analyzer-output plist -w -setup-static-analyzer -mrelocation-model pic -pic-level 1 -fhalf-no-semantic-interposition -mframe-pointer=all -relaxed-aliasing -fno-rounding-math -mconstructor-aliases -munwind-tables -target-cpu x86-64 -target-feature +retpoline-indirect-calls -target-feature +retpoline-indirect-branches -tune-cpu generic -debugger-tuning=gdb -fcoverage-compilation-dir=/usr/src/lib/libcrypto/obj -resource-dir /usr/local/lib/clang/13.0.0 -D LIBRESSL_INTERNAL -D LIBRESSL_CRYPTO_INTERNAL -D DSO_DLFCN -D HAVE_DLFCN_H -D HAVE_FUNOPEN -D OPENSSL_NO_HW_PADLOCK -I /usr/src/lib/libcrypto -I /usr/src/lib/libcrypto/asn1 -I /usr/src/lib/libcrypto/bio -I /usr/src/lib/libcrypto/bn -I /usr/src/lib/libcrypto/bytestring -I /usr/src/lib/libcrypto/dh -I /usr/src/lib/libcrypto/dsa -I /usr/src/lib/libcrypto/ec -I /usr/src/lib/libcrypto/ecdh -I /usr/src/lib/libcrypto/ecdsa -I /usr/src/lib/libcrypto/evp -I /usr/src/lib/libcrypto/hmac -I /usr/src/lib/libcrypto/modes -I /usr/src/lib/libcrypto/ocsp -I /usr/src/lib/libcrypto/rsa -I /usr/src/lib/libcrypto/x509 -I /usr/src/lib/libcrypto/obj -D AES_ASM -D BSAES_ASM -D VPAES_ASM -D OPENSSL_IA32_SSE2 -D RSA_ASM -D OPENSSL_BN_ASM_MONT -D OPENSSL_BN_ASM_MONT5 -D OPENSSL_BN_ASM_GF2m -D MD5_ASM -D GHASH_ASM -D RC4_MD5_ASM -D SHA1_ASM -D SHA256_ASM -D SHA512_ASM -D WHIRLPOOL_ASM -D OPENSSL_CPUID_OBJ -D PIC -internal-isystem /usr/local/lib/clang/13.0.0/include -internal-externc-isystem /usr/include -O2 -fdebug-compilation-dir=/usr/src/lib/libcrypto/obj -ferror-limit 19 -fwrapv -D_RET_PROTECTOR -ret-protector -fgnuc-version=4.2.1 -vectorize-loops -vectorize-slp -fno-builtin-malloc -fno-builtin-calloc -fno-builtin-realloc -fno-builtin-valloc -fno-builtin-free -fno-builtin-strdup -fno-builtin-strndup -analyzer-output=html -faddrsig -D__GCC_HAVE_DWARF2_CFI_ASM=1 -o /home/ben/Projects/vmm/scan-build/2022-01-12-194120-40624-1 -x c /usr/src/lib/libcrypto/bn/bn_exp2.c
1 | |
2 | |
3 | |
4 | |
5 | |
6 | |
7 | |
8 | |
9 | |
10 | |
11 | |
12 | |
13 | |
14 | |
15 | |
16 | |
17 | |
18 | |
19 | |
20 | |
21 | |
22 | |
23 | |
24 | |
25 | |
26 | |
27 | |
28 | |
29 | |
30 | |
31 | |
32 | |
33 | |
34 | |
35 | |
36 | |
37 | |
38 | |
39 | |
40 | |
41 | |
42 | |
43 | |
44 | |
45 | |
46 | |
47 | |
48 | |
49 | |
50 | |
51 | |
52 | |
53 | |
54 | |
55 | |
56 | |
57 | |
58 | |
59 | |
60 | |
61 | |
62 | |
63 | |
64 | |
65 | |
66 | |
67 | |
68 | |
69 | |
70 | |
71 | |
72 | |
73 | |
74 | |
75 | |
76 | |
77 | |
78 | |
79 | |
80 | |
81 | |
82 | |
83 | |
84 | |
85 | |
86 | |
87 | |
88 | |
89 | |
90 | |
91 | |
92 | |
93 | |
94 | |
95 | |
96 | |
97 | |
98 | |
99 | |
100 | |
101 | |
102 | |
103 | |
104 | |
105 | |
106 | |
107 | |
108 | |
109 | |
110 | |
111 | |
112 | #include <stdio.h> |
113 | |
114 | #include <openssl/err.h> |
115 | |
116 | #include "bn_lcl.h" |
117 | |
118 | #define TABLE_SIZE 32 |
119 | |
120 | int |
121 | BN_mod_exp2_mont(BIGNUM *rr, const BIGNUM *a1, const BIGNUM *p1, |
122 | const BIGNUM *a2, const BIGNUM *p2, const BIGNUM *m, BN_CTX *ctx, |
123 | BN_MONT_CTX *in_mont) |
124 | { |
125 | int i, j, bits, b, bits1, bits2, ret = 0, wpos1, wpos2, window1, window2, wvalue1, wvalue2; |
126 | int r_is_one = 1; |
127 | BIGNUM *d, *r; |
128 | const BIGNUM *a_mod_m; |
129 | |
130 | BIGNUM *val1[TABLE_SIZE], *val2[TABLE_SIZE]; |
131 | BN_MONT_CTX *mont = NULL; |
132 | |
133 | bn_check_top(a1); |
134 | bn_check_top(p1); |
135 | bn_check_top(a2); |
136 | bn_check_top(p2); |
137 | bn_check_top(m); |
138 | |
139 | if (!(m->d[0] & 1)) { |
| 1 | Assuming the condition is false | |
|
| |
140 | BNerror(BN_R_CALLED_WITH_EVEN_MODULUS); |
141 | return (0); |
142 | } |
143 | bits1 = BN_num_bits(p1); |
144 | bits2 = BN_num_bits(p2); |
145 | if ((bits1 == 0) && (bits2 == 0)) { |
| 3 | | Assuming 'bits1' is not equal to 0 | |
|
146 | ret = BN_one(rr); |
147 | return ret; |
148 | } |
149 | |
150 | bits = (bits1 > bits2) ? bits1 : bits2; |
| 4 | | Assuming 'bits1' is <= 'bits2' | |
|
| |
151 | |
152 | BN_CTX_start(ctx); |
153 | if ((d = BN_CTX_get(ctx)) == NULL) |
| 6 | | Assuming the condition is false | |
|
| |
154 | goto err; |
155 | if ((r = BN_CTX_get(ctx)) == NULL) |
| 8 | | Assuming the condition is false | |
|
| |
156 | goto err; |
157 | if ((val1[0] = BN_CTX_get(ctx)) == NULL) |
| 10 | | Assuming the condition is false | |
|
| |
158 | goto err; |
159 | if ((val2[0] = BN_CTX_get(ctx)) == NULL) |
| 12 | | Assuming the condition is false | |
|
| |
160 | goto err; |
161 | |
162 | if (in_mont != NULL) |
| 14 | | Assuming 'in_mont' is equal to NULL | |
|
| |
163 | mont = in_mont; |
164 | else { |
165 | if ((mont = BN_MONT_CTX_new()) == NULL) |
| 16 | | Assuming the condition is false | |
|
| |
166 | goto err; |
167 | if (!BN_MONT_CTX_set(mont, m, ctx)) |
| 18 | | Assuming the condition is false | |
|
| |
168 | goto err; |
169 | } |
170 | |
171 | window1 = BN_window_bits_for_exponent_size(bits1); |
| 20 | | Assuming 'bits1' is <= 671 | |
|
| |
| 22 | | Assuming 'bits1' is <= 239 | |
|
| |
| 24 | | Assuming 'bits1' is <= 79 | |
|
| |
| 26 | | Assuming 'bits1' is <= 23 | |
|
| |
172 | window2 = BN_window_bits_for_exponent_size(bits2); |
| 28 | | Assuming 'bits2' is <= 671 | |
|
| |
| 30 | | Assuming 'bits2' is <= 239 | |
|
| |
| 32 | | Assuming 'bits2' is <= 79 | |
|
| |
| 34 | | Assuming 'bits2' is <= 23 | |
|
| |
173 | |
174 | |
175 | |
176 | |
177 | if (a1->neg || BN_ucmp(a1, m) >= 0) { |
| 36 | | Assuming field 'neg' is 0 | |
|
| 37 | | Assuming the condition is false | |
|
| |
178 | if (!BN_mod_ct(val1[0], a1, m, ctx)) |
179 | goto err; |
180 | a_mod_m = val1[0]; |
181 | } else |
182 | a_mod_m = a1; |
183 | if (BN_is_zero(a_mod_m)) { |
| 39 | | Assuming the condition is false | |
|
| |
184 | BN_zero(rr); |
185 | ret = 1; |
186 | goto err; |
187 | } |
188 | |
189 | if (!BN_to_montgomery(val1[0], a_mod_m, mont, ctx)) |
| 41 | | Assuming the condition is false | |
|
| |
190 | goto err; |
191 | if (window1 > 1) { |
| |
192 | if (!BN_mod_mul_montgomery(d, val1[0], val1[0], mont, ctx)) |
193 | goto err; |
194 | |
195 | j = 1 << (window1 - 1); |
196 | for (i = 1; i < j; i++) { |
197 | if (((val1[i] = BN_CTX_get(ctx)) == NULL) || |
198 | !BN_mod_mul_montgomery(val1[i], val1[i - 1], |
199 | d, mont, ctx)) |
200 | goto err; |
201 | } |
202 | } |
203 | |
204 | |
205 | |
206 | |
207 | |
208 | if (a2->neg || BN_ucmp(a2, m) >= 0) { |
| 44 | | Assuming field 'neg' is 0 | |
|
| 45 | | Assuming the condition is false | |
|
| |
209 | if (!BN_mod_ct(val2[0], a2, m, ctx)) |
210 | goto err; |
211 | a_mod_m = val2[0]; |
212 | } else |
213 | a_mod_m = a2; |
214 | if (BN_is_zero(a_mod_m)) { |
| 47 | | Assuming the condition is false | |
|
| |
215 | BN_zero(rr); |
216 | ret = 1; |
217 | goto err; |
218 | } |
219 | if (!BN_to_montgomery(val2[0], a_mod_m, mont, ctx)) |
| 49 | | Assuming the condition is false | |
|
| |
220 | goto err; |
221 | if (window2 > 1) { |
| |
222 | if (!BN_mod_mul_montgomery(d, val2[0], val2[0], mont, ctx)) |
223 | goto err; |
224 | |
225 | j = 1 << (window2 - 1); |
226 | for (i = 1; i < j; i++) { |
227 | if (((val2[i] = BN_CTX_get(ctx)) == NULL) || |
228 | !BN_mod_mul_montgomery(val2[i], val2[i - 1], |
229 | d, mont, ctx)) |
230 | goto err; |
231 | } |
232 | } |
233 | |
234 | |
235 | |
236 | r_is_one = 1; |
237 | wvalue1 = 0; |
238 | wvalue2 = 0; |
239 | wpos1 = 0; |
240 | wpos2 = 0; |
241 | |
242 | if (!BN_to_montgomery(r, BN_value_one(), mont, ctx)) |
| 52 | | Assuming the condition is false | |
|
| |
243 | goto err; |
244 | for (b = bits - 1; b >= 0; b--) { |
| |
| 55 | | Loop condition is true. Entering loop body | |
|
245 | if (!r_is_one) { |
| |
246 | if (!BN_mod_mul_montgomery(r, r,r, mont, ctx)) |
247 | goto err; |
248 | } |
249 | |
250 | if (!wvalue1) |
| |
251 | if (BN_is_bit_set(p1, b)) { |
| 58 | | Assuming the condition is true | |
|
| |
252 | |
253 | i = b - window1 + 1; |
254 | while (!BN_is_bit_set(p1, i)) |
| 60 | | Assuming the condition is false | |
|
| 61 | | Loop condition is false. Execution continues on line 256 | |
|
255 | i++; |
256 | wpos1 = i; |
257 | wvalue1 = 1; |
258 | for (i = b - 1; i >= wpos1; i--) { |
| 62 | | Assuming 'i' is >= 'wpos1' | |
|
| 63 | | Loop condition is true. Entering loop body | |
|
| 66 | | Assuming 'i' is < 'wpos1' | |
|
| 67 | | Loop condition is false. Execution continues on line 265 | |
|
259 | wvalue1 <<= 1; |
260 | if (BN_is_bit_set(p1, i)) |
| 64 | | Assuming the condition is false | |
|
| |
261 | wvalue1++; |
262 | } |
263 | } |
264 | |
265 | if (!wvalue2) |
| |
266 | if (BN_is_bit_set(p2, b)) { |
| 69 | | Assuming the condition is false | |
|
| |
267 | |
268 | i = b - window2 + 1; |
269 | while (!BN_is_bit_set(p2, i)) |
270 | i++; |
271 | wpos2 = i; |
272 | wvalue2 = 1; |
273 | for (i = b - 1; i >= wpos2; i--) { |
274 | wvalue2 <<= 1; |
275 | if (BN_is_bit_set(p2, i)) |
276 | wvalue2++; |
277 | } |
278 | } |
279 | |
280 | if (wvalue1 && b == wpos1) { |
| |
281 | |
282 | if (!BN_mod_mul_montgomery(r, r, val1[wvalue1 >> 1], |
| 72 | | 3rd function call argument is an uninitialized value |
|
283 | mont, ctx)) |
284 | goto err; |
285 | wvalue1 = 0; |
286 | r_is_one = 0; |
287 | } |
288 | |
289 | if (wvalue2 && b == wpos2) { |
290 | |
291 | if (!BN_mod_mul_montgomery(r, r, val2[wvalue2 >> 1], |
292 | mont, ctx)) |
293 | goto err; |
294 | wvalue2 = 0; |
295 | r_is_one = 0; |
296 | } |
297 | } |
298 | if (!BN_from_montgomery(rr, r,mont, ctx)) |
299 | goto err; |
300 | ret = 1; |
301 | |
302 | err: |
303 | if ((in_mont == NULL) && (mont != NULL)) |
304 | BN_MONT_CTX_free(mont); |
305 | BN_CTX_end(ctx); |
306 | bn_check_top(rr); |
307 | return (ret); |
308 | } |