clang -cc1 -cc1 -triple amd64-unknown-openbsd7.0 -analyze -disable-free -disable-llvm-verifier -discard-value-names -main-file-name bn_exp2.c -analyzer-store=region -analyzer-opt-analyze-nested-blocks -analyzer-checker=core -analyzer-checker=apiModeling -analyzer-checker=unix -analyzer-checker=deadcode -analyzer-checker=security.insecureAPI.UncheckedReturn -analyzer-checker=security.insecureAPI.getpw -analyzer-checker=security.insecureAPI.gets -analyzer-checker=security.insecureAPI.mktemp -analyzer-checker=security.insecureAPI.mkstemp -analyzer-checker=security.insecureAPI.vfork -analyzer-checker=nullability.NullPassedToNonnull -analyzer-checker=nullability.NullReturnedFromNonnull -analyzer-output plist -w -setup-static-analyzer -mrelocation-model pic -pic-level 1 -pic-is-pie -mframe-pointer=all -relaxed-aliasing -fno-rounding-math -mconstructor-aliases -munwind-tables -target-cpu x86-64 -target-feature +retpoline-indirect-calls -target-feature +retpoline-indirect-branches -tune-cpu generic -debugger-tuning=gdb -fcoverage-compilation-dir=/usr/src/lib/libcrypto/obj -resource-dir /usr/local/lib/clang/13.0.0 -D LIBRESSL_INTERNAL -D LIBRESSL_CRYPTO_INTERNAL -D DSO_DLFCN -D HAVE_DLFCN_H -D HAVE_FUNOPEN -D OPENSSL_NO_HW_PADLOCK -I /usr/src/lib/libcrypto -I /usr/src/lib/libcrypto/asn1 -I /usr/src/lib/libcrypto/bio -I /usr/src/lib/libcrypto/bn -I /usr/src/lib/libcrypto/bytestring -I /usr/src/lib/libcrypto/dh -I /usr/src/lib/libcrypto/dsa -I /usr/src/lib/libcrypto/ec -I /usr/src/lib/libcrypto/ecdh -I /usr/src/lib/libcrypto/ecdsa -I /usr/src/lib/libcrypto/evp -I /usr/src/lib/libcrypto/hmac -I /usr/src/lib/libcrypto/modes -I /usr/src/lib/libcrypto/ocsp -I /usr/src/lib/libcrypto/rsa -I /usr/src/lib/libcrypto/x509 -I /usr/src/lib/libcrypto/obj -D AES_ASM -D BSAES_ASM -D VPAES_ASM -D OPENSSL_IA32_SSE2 -D RSA_ASM -D OPENSSL_BN_ASM_MONT -D OPENSSL_BN_ASM_MONT5 -D OPENSSL_BN_ASM_GF2m -D MD5_ASM -D GHASH_ASM -D RC4_MD5_ASM -D SHA1_ASM -D SHA256_ASM -D SHA512_ASM -D WHIRLPOOL_ASM -D OPENSSL_CPUID_OBJ -internal-isystem /usr/local/lib/clang/13.0.0/include -internal-externc-isystem /usr/include -O2 -fdebug-compilation-dir=/usr/src/lib/libcrypto/obj -ferror-limit 19 -fwrapv -D_RET_PROTECTOR -ret-protector -fgnuc-version=4.2.1 -vectorize-loops -vectorize-slp -fno-builtin-malloc -fno-builtin-calloc -fno-builtin-realloc -fno-builtin-valloc -fno-builtin-free -fno-builtin-strdup -fno-builtin-strndup -analyzer-output=html -faddrsig -D__GCC_HAVE_DWARF2_CFI_ASM=1 -o /home/ben/Projects/vmm/scan-build/2022-01-12-194120-40624-1 -x c /usr/src/lib/libcrypto/bn/bn_exp2.c
| 1 | |
| 2 | |
| 3 | |
| 4 | |
| 5 | |
| 6 | |
| 7 | |
| 8 | |
| 9 | |
| 10 | |
| 11 | |
| 12 | |
| 13 | |
| 14 | |
| 15 | |
| 16 | |
| 17 | |
| 18 | |
| 19 | |
| 20 | |
| 21 | |
| 22 | |
| 23 | |
| 24 | |
| 25 | |
| 26 | |
| 27 | |
| 28 | |
| 29 | |
| 30 | |
| 31 | |
| 32 | |
| 33 | |
| 34 | |
| 35 | |
| 36 | |
| 37 | |
| 38 | |
| 39 | |
| 40 | |
| 41 | |
| 42 | |
| 43 | |
| 44 | |
| 45 | |
| 46 | |
| 47 | |
| 48 | |
| 49 | |
| 50 | |
| 51 | |
| 52 | |
| 53 | |
| 54 | |
| 55 | |
| 56 | |
| 57 | |
| 58 | |
| 59 | |
| 60 | |
| 61 | |
| 62 | |
| 63 | |
| 64 | |
| 65 | |
| 66 | |
| 67 | |
| 68 | |
| 69 | |
| 70 | |
| 71 | |
| 72 | |
| 73 | |
| 74 | |
| 75 | |
| 76 | |
| 77 | |
| 78 | |
| 79 | |
| 80 | |
| 81 | |
| 82 | |
| 83 | |
| 84 | |
| 85 | |
| 86 | |
| 87 | |
| 88 | |
| 89 | |
| 90 | |
| 91 | |
| 92 | |
| 93 | |
| 94 | |
| 95 | |
| 96 | |
| 97 | |
| 98 | |
| 99 | |
| 100 | |
| 101 | |
| 102 | |
| 103 | |
| 104 | |
| 105 | |
| 106 | |
| 107 | |
| 108 | |
| 109 | |
| 110 | |
| 111 | |
| 112 | #include <stdio.h> |
| 113 | |
| 114 | #include <openssl/err.h> |
| 115 | |
| 116 | #include "bn_lcl.h" |
| 117 | |
| 118 | #define TABLE_SIZE 32 |
| 119 | |
| 120 | int |
| 121 | BN_mod_exp2_mont(BIGNUM *rr, const BIGNUM *a1, const BIGNUM *p1, |
| 122 | const BIGNUM *a2, const BIGNUM *p2, const BIGNUM *m, BN_CTX *ctx, |
| 123 | BN_MONT_CTX *in_mont) |
| 124 | { |
| 125 | int i, j, bits, b, bits1, bits2, ret = 0, wpos1, wpos2, window1, window2, wvalue1, wvalue2; |
| 126 | int r_is_one = 1; |
| 127 | BIGNUM *d, *r; |
| 128 | const BIGNUM *a_mod_m; |
| 129 | |
| 130 | BIGNUM *val1[TABLE_SIZE], *val2[TABLE_SIZE]; |
| 131 | BN_MONT_CTX *mont = NULL; |
| 132 | |
| 133 | bn_check_top(a1); |
| 134 | bn_check_top(p1); |
| 135 | bn_check_top(a2); |
| 136 | bn_check_top(p2); |
| 137 | bn_check_top(m); |
| 138 | |
| 139 | if (!(m->d[0] & 1)) { |
| 1 | Assuming the condition is false | |
|
| |
| 140 | BNerror(BN_R_CALLED_WITH_EVEN_MODULUS); |
| 141 | return (0); |
| 142 | } |
| 143 | bits1 = BN_num_bits(p1); |
| 144 | bits2 = BN_num_bits(p2); |
| 145 | if ((bits1 == 0) && (bits2 == 0)) { |
| 3 | | Assuming 'bits1' is not equal to 0 | |
|
| 146 | ret = BN_one(rr); |
| 147 | return ret; |
| 148 | } |
| 149 | |
| 150 | bits = (bits1 > bits2) ? bits1 : bits2; |
| 4 | | Assuming 'bits1' is <= 'bits2' | |
|
| |
| 151 | |
| 152 | BN_CTX_start(ctx); |
| 153 | if ((d = BN_CTX_get(ctx)) == NULL) |
| 6 | | Assuming the condition is false | |
|
| |
| 154 | goto err; |
| 155 | if ((r = BN_CTX_get(ctx)) == NULL) |
| 8 | | Assuming the condition is false | |
|
| |
| 156 | goto err; |
| 157 | if ((val1[0] = BN_CTX_get(ctx)) == NULL) |
| 10 | | Assuming the condition is false | |
|
| |
| 158 | goto err; |
| 159 | if ((val2[0] = BN_CTX_get(ctx)) == NULL) |
| 12 | | Assuming the condition is false | |
|
| |
| 160 | goto err; |
| 161 | |
| 162 | if (in_mont != NULL) |
| 14 | | Assuming 'in_mont' is equal to NULL | |
|
| |
| 163 | mont = in_mont; |
| 164 | else { |
| 165 | if ((mont = BN_MONT_CTX_new()) == NULL) |
| 16 | | Assuming the condition is false | |
|
| |
| 166 | goto err; |
| 167 | if (!BN_MONT_CTX_set(mont, m, ctx)) |
| 18 | | Assuming the condition is false | |
|
| |
| 168 | goto err; |
| 169 | } |
| 170 | |
| 171 | window1 = BN_window_bits_for_exponent_size(bits1); |
| 20 | | Assuming 'bits1' is <= 671 | |
|
| |
| 22 | | Assuming 'bits1' is <= 239 | |
|
| |
| 24 | | Assuming 'bits1' is <= 79 | |
|
| |
| 26 | | Assuming 'bits1' is <= 23 | |
|
| |
| 172 | window2 = BN_window_bits_for_exponent_size(bits2); |
| 28 | | Assuming 'bits2' is <= 671 | |
|
| |
| 30 | | Assuming 'bits2' is <= 239 | |
|
| |
| 32 | | Assuming 'bits2' is <= 79 | |
|
| |
| 34 | | Assuming 'bits2' is <= 23 | |
|
| |
| 173 | |
| 174 | |
| 175 | |
| 176 | |
| 177 | if (a1->neg || BN_ucmp(a1, m) >= 0) { |
| 36 | | Assuming field 'neg' is 0 | |
|
| 37 | | Assuming the condition is false | |
|
| |
| 178 | if (!BN_mod_ct(val1[0], a1, m, ctx)) |
| 179 | goto err; |
| 180 | a_mod_m = val1[0]; |
| 181 | } else |
| 182 | a_mod_m = a1; |
| 183 | if (BN_is_zero(a_mod_m)) { |
| 39 | | Assuming the condition is false | |
|
| |
| 184 | BN_zero(rr); |
| 185 | ret = 1; |
| 186 | goto err; |
| 187 | } |
| 188 | |
| 189 | if (!BN_to_montgomery(val1[0], a_mod_m, mont, ctx)) |
| 41 | | Assuming the condition is false | |
|
| |
| 190 | goto err; |
| 191 | if (window1 > 1) { |
| |
| 192 | if (!BN_mod_mul_montgomery(d, val1[0], val1[0], mont, ctx)) |
| 193 | goto err; |
| 194 | |
| 195 | j = 1 << (window1 - 1); |
| 196 | for (i = 1; i < j; i++) { |
| 197 | if (((val1[i] = BN_CTX_get(ctx)) == NULL) || |
| 198 | !BN_mod_mul_montgomery(val1[i], val1[i - 1], |
| 199 | d, mont, ctx)) |
| 200 | goto err; |
| 201 | } |
| 202 | } |
| 203 | |
| 204 | |
| 205 | |
| 206 | |
| 207 | |
| 208 | if (a2->neg || BN_ucmp(a2, m) >= 0) { |
| 44 | | Assuming field 'neg' is 0 | |
|
| 45 | | Assuming the condition is false | |
|
| |
| 209 | if (!BN_mod_ct(val2[0], a2, m, ctx)) |
| 210 | goto err; |
| 211 | a_mod_m = val2[0]; |
| 212 | } else |
| 213 | a_mod_m = a2; |
| 214 | if (BN_is_zero(a_mod_m)) { |
| 47 | | Assuming the condition is false | |
|
| |
| 215 | BN_zero(rr); |
| 216 | ret = 1; |
| 217 | goto err; |
| 218 | } |
| 219 | if (!BN_to_montgomery(val2[0], a_mod_m, mont, ctx)) |
| 49 | | Assuming the condition is false | |
|
| |
| 220 | goto err; |
| 221 | if (window2 > 1) { |
| |
| 222 | if (!BN_mod_mul_montgomery(d, val2[0], val2[0], mont, ctx)) |
| 223 | goto err; |
| 224 | |
| 225 | j = 1 << (window2 - 1); |
| 226 | for (i = 1; i < j; i++) { |
| 227 | if (((val2[i] = BN_CTX_get(ctx)) == NULL) || |
| 228 | !BN_mod_mul_montgomery(val2[i], val2[i - 1], |
| 229 | d, mont, ctx)) |
| 230 | goto err; |
| 231 | } |
| 232 | } |
| 233 | |
| 234 | |
| 235 | |
| 236 | r_is_one = 1; |
| 237 | wvalue1 = 0; |
| 238 | wvalue2 = 0; |
| 239 | wpos1 = 0; |
| 240 | wpos2 = 0; |
| 241 | |
| 242 | if (!BN_to_montgomery(r, BN_value_one(), mont, ctx)) |
| 52 | | Assuming the condition is false | |
|
| |
| 243 | goto err; |
| 244 | for (b = bits - 1; b >= 0; b--) { |
| |
| 55 | | Loop condition is true. Entering loop body | |
|
| 245 | if (!r_is_one) { |
| |
| 246 | if (!BN_mod_mul_montgomery(r, r,r, mont, ctx)) |
| 247 | goto err; |
| 248 | } |
| 249 | |
| 250 | if (!wvalue1) |
| |
| 251 | if (BN_is_bit_set(p1, b)) { |
| 58 | | Assuming the condition is true | |
|
| |
| 252 | |
| 253 | i = b - window1 + 1; |
| 254 | while (!BN_is_bit_set(p1, i)) |
| 60 | | Assuming the condition is false | |
|
| 61 | | Loop condition is false. Execution continues on line 256 | |
|
| 255 | i++; |
| 256 | wpos1 = i; |
| 257 | wvalue1 = 1; |
| 258 | for (i = b - 1; i >= wpos1; i--) { |
| 62 | | Assuming 'i' is >= 'wpos1' | |
|
| 63 | | Loop condition is true. Entering loop body | |
|
| 66 | | Assuming 'i' is < 'wpos1' | |
|
| 67 | | Loop condition is false. Execution continues on line 265 | |
|
| 259 | wvalue1 <<= 1; |
| 260 | if (BN_is_bit_set(p1, i)) |
| 64 | | Assuming the condition is false | |
|
| |
| 261 | wvalue1++; |
| 262 | } |
| 263 | } |
| 264 | |
| 265 | if (!wvalue2) |
| |
| 266 | if (BN_is_bit_set(p2, b)) { |
| 69 | | Assuming the condition is false | |
|
| |
| 267 | |
| 268 | i = b - window2 + 1; |
| 269 | while (!BN_is_bit_set(p2, i)) |
| 270 | i++; |
| 271 | wpos2 = i; |
| 272 | wvalue2 = 1; |
| 273 | for (i = b - 1; i >= wpos2; i--) { |
| 274 | wvalue2 <<= 1; |
| 275 | if (BN_is_bit_set(p2, i)) |
| 276 | wvalue2++; |
| 277 | } |
| 278 | } |
| 279 | |
| 280 | if (wvalue1 && b == wpos1) { |
| |
| 281 | |
| 282 | if (!BN_mod_mul_montgomery(r, r, val1[wvalue1 >> 1], |
| 72 | | 3rd function call argument is an uninitialized value |
|
| 283 | mont, ctx)) |
| 284 | goto err; |
| 285 | wvalue1 = 0; |
| 286 | r_is_one = 0; |
| 287 | } |
| 288 | |
| 289 | if (wvalue2 && b == wpos2) { |
| 290 | |
| 291 | if (!BN_mod_mul_montgomery(r, r, val2[wvalue2 >> 1], |
| 292 | mont, ctx)) |
| 293 | goto err; |
| 294 | wvalue2 = 0; |
| 295 | r_is_one = 0; |
| 296 | } |
| 297 | } |
| 298 | if (!BN_from_montgomery(rr, r,mont, ctx)) |
| 299 | goto err; |
| 300 | ret = 1; |
| 301 | |
| 302 | err: |
| 303 | if ((in_mont == NULL) && (mont != NULL)) |
| 304 | BN_MONT_CTX_free(mont); |
| 305 | BN_CTX_end(ctx); |
| 306 | bn_check_top(rr); |
| 307 | return (ret); |
| 308 | } |