openssl/crypto/bn/asm
Bernd Edlinger 336923c0c8 Fix a carry overflow bug in bn_sqr_comba4/8 for mips 32-bit targets
bn_sqr_comba8 does for instance compute a wrong result for the value:
a=0x4aaac919 62056c84 fba7334e 1a6be678 022181ba fd3aa878 899b2346 ee210f45

The correct result is:
r=0x15c72e32 605a3061 d11b1012 3c187483 6df96999 bd0c22ba d3e7d437 4724a82f
    912c5e61 6a187efe 8f7c47fc f6945fe5 75be8e3d 97ed17d4 7950b465 3cb32899

but the actual result was:
r=0x15c72e32 605a3061 d11b1012 3c187483 6df96999 bd0c22ba d3e7d437 4724a82f
    912c5e61 6a187efe 8f7c47fc f6945fe5 75be8e3c 97ed17d4 7950b465 3cb32899

so the forth word of the result was 0x75be8e3c but should have been
0x75be8e3d instead.

Likewise bn_sqr_comba4 has an identical bug for the same value as well:
a=0x022181ba fd3aa878 899b2346 ee210f45

correct result:
r=0x00048a69 9fe82f8b 62bd2ed1 88781335 75be8e3d 97ed17d4 7950b465 3cb32899

wrong result:
r=0x00048a69 9fe82f8b 62bd2ed1 88781335 75be8e3c 97ed17d4 7950b465 3cb32899

Fortunately the bn_mul_comba4/8 code paths are not affected.

Also the mips64 target does in fact not handle the carry propagation
correctly.

Example:
a=0x4aaac91900000000 62056c8400000000 fba7334e00000000 1a6be67800000000
    022181ba00000000 fd3aa87800000000 899b234635dad283 ee210f4500000001

correct result:
r=0x15c72e32272c4471 392debf018c679c8 b85496496bf8254c d0204f36611e2be1
    0cdb3db8f3c081d8 c94ba0e1bacc5061 191b83d47ff929f6 5be0aebfc13ae68d
    3eea7a7fdf2f5758 42f7ec656cab3cb5 6a28095be34756f2 64f24687bf37de06
    2822309cd1d292f9 6fa698c972372f09 771e97d3a868cda0 dc421e8a00000001

wrong result:
r=0x15c72e32272c4471 392debf018c679c8 b85496496bf8254c d0204f36611e2be1
    0cdb3db8f3c081d8 c94ba0e1bacc5061 191b83d47ff929f6 5be0aebfc13ae68d
    3eea7a7fdf2f5758 42f7ec656cab3cb5 6a28095be34756f2 64f24687bf37de06
    2822309cd1d292f8 6fa698c972372f09 771e97d3a868cda0 dc421e8a00000001

Reviewed-by: Paul Dale <pauli@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/17258)
2021-12-14 06:43:04 +01:00
..
alpha-mont.pl Update copyright year 2020-04-23 13:55:52 +01:00
armv4-gf2m.pl Update copyright year 2020-04-23 13:55:52 +01:00
armv4-mont.pl Update copyright year 2020-04-23 13:55:52 +01:00
armv8-mont.pl aarch64: support BTI and pointer authentication in assembly 2021-10-01 09:35:38 +02:00
bn-586.pl Update copyright year 2020-04-23 13:55:52 +01:00
bn-c64xplus.asm Following the license change, modify the boilerplates in crypto/bn/ 2018-12-06 14:31:21 +01:00
c64xplus-gf2m.pl Update copyright year 2020-04-23 13:55:52 +01:00
co-586.pl Update copyright year 2020-04-23 13:55:52 +01:00
ia64-mont.pl Update copyright year 2020-04-23 13:55:52 +01:00
ia64.S Remove unnecessary trailing whitespace 2019-02-05 16:25:11 +01:00
mips-mont.pl Update copyright year 2020-04-23 13:55:52 +01:00
mips.pl Fix a carry overflow bug in bn_sqr_comba4/8 for mips 32-bit targets 2021-12-14 06:43:04 +01:00
parisc-mont.pl Update copyright year 2020-04-23 13:55:52 +01:00
ppc64-mont-fixed.pl bn: Fix .size directive 2021-07-06 10:49:01 +10:00
ppc64-mont.pl Update copyright year 2020-04-23 13:55:52 +01:00
ppc-mont.pl Update copyright year 2020-04-23 13:55:52 +01:00
ppc.pl Update copyright year 2020-04-23 13:55:52 +01:00
rsaz-2k-avx512.pl Dual 1536/2048-bit exponentiation optimization for Intel IceLake CPU 2021-11-19 12:50:34 +10:00
rsaz-3k-avx512.pl Dual 1536/2048-bit exponentiation optimization for Intel IceLake CPU 2021-11-19 12:50:34 +10:00
rsaz-4k-avx512.pl Dual 1536/2048-bit exponentiation optimization for Intel IceLake CPU 2021-11-19 12:50:34 +10:00
rsaz-avx2.pl Ignore vendor name in Clang version number. 2020-08-27 20:27:26 -07:00
rsaz-x86_64.pl Ignore vendor name in Clang version number. 2020-08-27 20:27:26 -07:00
s390x-gf2m.pl Update copyright year 2020-04-23 13:55:52 +01:00
s390x-mont.pl Update copyright year 2020-04-23 13:55:52 +01:00
s390x.S s390x assembly pack: fix bn_mul_comba4 2019-11-17 13:52:02 +01:00
sparct4-mont.pl Update copyright year 2021-07-29 15:41:35 +01:00
sparcv8.S fix some code with obvious wrong coding style 2021-10-28 13:10:46 +10:00
sparcv8plus.S fix some code with obvious wrong coding style 2021-10-28 13:10:46 +10:00
sparcv9-gf2m.pl Update copyright year 2021-07-29 15:41:35 +01:00
sparcv9-mont.pl Update copyright year 2021-07-29 15:41:35 +01:00
sparcv9a-mont.pl Update copyright year 2021-07-29 15:41:35 +01:00
via-mont.pl Update copyright year 2020-04-23 13:55:52 +01:00
vis3-mont.pl Update copyright year 2021-07-29 15:41:35 +01:00
x86_64-gcc.c Reorganize local header files 2019-09-28 20:26:35 +02:00
x86_64-gf2m.pl Update copyright year 2020-04-23 13:55:52 +01:00
x86_64-mont5.pl Ignore vendor name in Clang version number. 2020-08-27 20:27:26 -07:00
x86_64-mont.pl Ignore vendor name in Clang version number. 2020-08-27 20:27:26 -07:00
x86-gf2m.pl Update copyright year 2020-04-23 13:55:52 +01:00
x86-mont.pl Update copyright year 2020-04-23 13:55:52 +01:00