Skip to content

Commit 80fb5c7

Browse files
committed
backport 339e44b: smallstack reduction for wc_ecc_import_point_der_ex();
backport 210eb62: "smallstack reduction for wc_ecc_import_x963_ex, mp_jacobi".
1 parent 3d0d20e commit 80fb5c7

1 file changed

Lines changed: 121 additions & 38 deletions

File tree

‎wolfcrypt/src/ecc.c‎

Lines changed: 121 additions & 38 deletions
Original file line numberDiff line numberDiff line change
@@ -7657,13 +7657,34 @@ int wc_ecc_import_point_der_ex(const byte* in, word32 inLen,
76577657
#if !defined(WOLFSSL_SP_MATH)
76587658
{
76597659
int did_init = 0;
7660-
mp_int t1, t2;
7660+
#ifdef WOLFSSL_SMALL_STACK
7661+
mp_int* t1 = NULL;
7662+
mp_int* t2 = NULL;
7663+
#else
7664+
mp_int t1[1], t2[1];
7665+
#endif
76617666
DECLARE_CURVE_SPECS(curve, 3);
76627667

76637668
ALLOC_CURVE_SPECS(3, err);
76647669

7670+
#ifdef WOLFSSL_SMALL_STACK
7671+
if (err == MP_OKAY) {
7672+
t1 = (mp_int*)XMALLOC(sizeof(mp_int), NULL,
7673+
DYNAMIC_TYPE_BIGINT);
7674+
if (t1 == NULL) {
7675+
err = MEMORY_E;
7676+
}
7677+
}
7678+
if (err == MP_OKAY) {
7679+
t2 = (mp_int*)XMALLOC(sizeof(mp_int), NULL,
7680+
DYNAMIC_TYPE_BIGINT);
7681+
if (t2 == NULL) {
7682+
err = MEMORY_E;
7683+
}
7684+
}
7685+
#endif
76657686
if (err == MP_OKAY) {
7666-
if (mp_init_multi(&t1, &t2, NULL, NULL, NULL, NULL) != MP_OKAY)
7687+
if (mp_init_multi(t1, t2, NULL, NULL, NULL, NULL) != MP_OKAY)
76677688
err = MEMORY_E;
76687689
else
76697690
did_init = 1;
@@ -7688,42 +7709,51 @@ int wc_ecc_import_point_der_ex(const byte* in, word32 inLen,
76887709

76897710
/* compute x^3 */
76907711
if (err == MP_OKAY)
7691-
err = mp_sqr(point->x, &t1);
7712+
err = mp_sqr(point->x, t1);
76927713
if (err == MP_OKAY)
7693-
err = mp_mulmod(&t1, point->x, curve->prime, &t1);
7714+
err = mp_mulmod(t1, point->x, curve->prime, t1);
76947715

76957716
/* compute x^3 + a*x */
76967717
if (err == MP_OKAY)
7697-
err = mp_mulmod(curve->Af, point->x, curve->prime, &t2);
7718+
err = mp_mulmod(curve->Af, point->x, curve->prime, t2);
76987719
if (err == MP_OKAY)
7699-
err = mp_add(&t1, &t2, &t1);
7720+
err = mp_add(t1, t2, t1);
77007721

77017722
/* compute x^3 + a*x + b */
77027723
if (err == MP_OKAY)
7703-
err = mp_add(&t1, curve->Bf, &t1);
7724+
err = mp_add(t1, curve->Bf, t1);
77047725

77057726
/* compute sqrt(x^3 + a*x + b) */
77067727
if (err == MP_OKAY)
7707-
err = mp_sqrtmod_prime(&t1, curve->prime, &t2);
7728+
err = mp_sqrtmod_prime(t1, curve->prime, t2);
77087729

77097730
/* adjust y */
77107731
if (err == MP_OKAY) {
7711-
if ((mp_isodd(&t2) == MP_YES &&
7732+
if ((mp_isodd(t2) == MP_YES &&
77127733
pointType == ECC_POINT_COMP_ODD) ||
7713-
(mp_isodd(&t2) == MP_NO &&
7734+
(mp_isodd(t2) == MP_NO &&
77147735
pointType == ECC_POINT_COMP_EVEN)) {
7715-
err = mp_mod(&t2, curve->prime, point->y);
7736+
err = mp_mod(t2, curve->prime, point->y);
77167737
}
77177738
else {
7718-
err = mp_submod(curve->prime, &t2, curve->prime, point->y);
7739+
err = mp_submod(curve->prime, t2, curve->prime, point->y);
77197740
}
77207741
}
77217742

77227743
if (did_init) {
7723-
mp_clear(&t2);
7724-
mp_clear(&t1);
7744+
mp_clear(t2);
7745+
mp_clear(t1);
77257746
}
77267747

7748+
#ifdef WOLFSSL_SMALL_STACK
7749+
if (t1 != NULL) {
7750+
XFREE(t1, NULL, DYNAMIC_TYPE_BIGINT);
7751+
}
7752+
if (t2 != NULL) {
7753+
XFREE(t2, NULL, DYNAMIC_TYPE_BIGINT);
7754+
}
7755+
#endif
7756+
77277757
wc_ecc_curve_free(curve);
77287758
FREE_CURVE_SPECS();
77297759
}
@@ -8777,14 +8807,33 @@ int wc_ecc_import_x963_ex(const byte* in, word32 inLen, ecc_key* key,
87778807
#ifdef HAVE_COMP_KEY
87788808
if (err == MP_OKAY && compressed == 1) { /* build y */
87798809
#if !defined(WOLFSSL_SP_MATH)
8780-
mp_int t1, t2;
8810+
#ifdef WOLFSSL_SMALL_STACK
8811+
mp_int* t1 = NULL;
8812+
mp_int* t2 = NULL;
8813+
#else
8814+
mp_int t1[1], t2[1];
8815+
#endif
87818816
int did_init = 0;
87828817

87838818
DECLARE_CURVE_SPECS(curve, 3);
87848819
ALLOC_CURVE_SPECS(3, err);
87858820

8821+
#ifdef WOLFSSL_SMALL_STACK
87868822
if (err == MP_OKAY) {
8787-
if (mp_init_multi(&t1, &t2, NULL, NULL, NULL, NULL) != MP_OKAY)
8823+
t1 = (mp_int*)XMALLOC(sizeof(mp_int), NULL, DYNAMIC_TYPE_BIGINT);
8824+
if (t1 == NULL) {
8825+
err = MEMORY_E;
8826+
}
8827+
}
8828+
if (err == MP_OKAY) {
8829+
t2 = (mp_int*)XMALLOC(sizeof(mp_int), NULL, DYNAMIC_TYPE_BIGINT);
8830+
if (t2 == NULL) {
8831+
err = MEMORY_E;
8832+
}
8833+
}
8834+
#endif
8835+
if (err == MP_OKAY) {
8836+
if (mp_init_multi(t1, t2, NULL, NULL, NULL, NULL) != MP_OKAY)
87888837
err = MEMORY_E;
87898838
else
87908839
did_init = 1;
@@ -8809,41 +8858,49 @@ int wc_ecc_import_x963_ex(const byte* in, word32 inLen, ecc_key* key,
88098858

88108859
/* compute x^3 */
88118860
if (err == MP_OKAY)
8812-
err = mp_sqr(key->pubkey.x, &t1);
8861+
err = mp_sqr(key->pubkey.x, t1);
88138862
if (err == MP_OKAY)
8814-
err = mp_mulmod(&t1, key->pubkey.x, curve->prime, &t1);
8863+
err = mp_mulmod(t1, key->pubkey.x, curve->prime, t1);
88158864

88168865
/* compute x^3 + a*x */
88178866
if (err == MP_OKAY)
8818-
err = mp_mulmod(curve->Af, key->pubkey.x, curve->prime, &t2);
8867+
err = mp_mulmod(curve->Af, key->pubkey.x, curve->prime, t2);
88198868
if (err == MP_OKAY)
8820-
err = mp_add(&t1, &t2, &t1);
8869+
err = mp_add(t1, t2, t1);
88218870

88228871
/* compute x^3 + a*x + b */
88238872
if (err == MP_OKAY)
8824-
err = mp_add(&t1, curve->Bf, &t1);
8873+
err = mp_add(t1, curve->Bf, t1);
88258874

88268875
/* compute sqrt(x^3 + a*x + b) */
88278876
if (err == MP_OKAY)
8828-
err = mp_sqrtmod_prime(&t1, curve->prime, &t2);
8877+
err = mp_sqrtmod_prime(t1, curve->prime, t2);
88298878

88308879
/* adjust y */
88318880
if (err == MP_OKAY) {
8832-
if ((mp_isodd(&t2) == MP_YES && pointType == ECC_POINT_COMP_ODD) ||
8833-
(mp_isodd(&t2) == MP_NO && pointType == ECC_POINT_COMP_EVEN)) {
8834-
err = mp_mod(&t2, curve->prime, &t2);
8881+
if ((mp_isodd(t2) == MP_YES && pointType == ECC_POINT_COMP_ODD) ||
8882+
(mp_isodd(t2) == MP_NO && pointType == ECC_POINT_COMP_EVEN)) {
8883+
err = mp_mod(t2, curve->prime, t2);
88358884
}
88368885
else {
8837-
err = mp_submod(curve->prime, &t2, curve->prime, &t2);
8886+
err = mp_submod(curve->prime, t2, curve->prime, t2);
88388887
}
88398888
if (err == MP_OKAY)
8840-
err = mp_copy(&t2, key->pubkey.y);
8889+
err = mp_copy(t2, key->pubkey.y);
88418890
}
88428891

88438892
if (did_init) {
8844-
mp_clear(&t2);
8845-
mp_clear(&t1);
8893+
mp_clear(t2);
8894+
mp_clear(t1);
88468895
}
8896+
#ifdef WOLFSSL_SMALL_STACK
8897+
if (t1 != NULL) {
8898+
XFREE(t1, NULL, DYNAMIC_TYPE_BIGINT);
8899+
}
8900+
if (t2 != NULL) {
8901+
XFREE(t2, NULL, DYNAMIC_TYPE_BIGINT);
8902+
}
8903+
#endif
88478904

88488905
wc_ecc_curve_free(curve);
88498906
FREE_CURVE_SPECS();
@@ -12296,7 +12353,12 @@ int wc_ecc_decrypt(ecc_key* privKey, ecc_key* pubKey, const byte* msg,
1229612353
*/
1229712354
int mp_jacobi(mp_int* a, mp_int* n, int* c)
1229812355
{
12299-
mp_int a1, n1;
12356+
#ifdef WOLFSSL_SMALL_STACK
12357+
mp_int* a1 = NULL;
12358+
mp_int* n1 = NULL;
12359+
#else
12360+
mp_int a1[1], n1[1];
12361+
#endif
1230012362
int res;
1230112363
int s = 1;
1230212364
int k;
@@ -12314,22 +12376,38 @@ int mp_jacobi(mp_int* a, mp_int* n, int* c)
1231412376
return MP_VAL;
1231512377
}
1231612378

12317-
if ((res = mp_init_multi(&a1, &n1, NULL, NULL, NULL, NULL)) != MP_OKAY) {
12379+
#ifdef WOLFSSL_SMALL_STACK
12380+
a1 = (mp_int*)XMALLOC(sizeof(mp_int), NULL, DYNAMIC_TYPE_BIGINT);
12381+
if (a1 == NULL) {
12382+
return MP_MEM;
12383+
}
12384+
n1 = (mp_int*)XMALLOC(sizeof(mp_int), NULL, DYNAMIC_TYPE_BIGINT);
12385+
if (n1 == NULL) {
12386+
XFREE(a1, NULL, DYNAMIC_TYPE_BIGINT);
12387+
return MP_MEM;
12388+
}
12389+
#endif
12390+
12391+
if ((res = mp_init_multi(a1, n1, NULL, NULL, NULL, NULL)) != MP_OKAY) {
12392+
#ifdef WOLFSSL_SMALL_STACK
12393+
XFREE(a1, NULL, DYNAMIC_TYPE_BIGINT);
12394+
XFREE(n1, NULL, DYNAMIC_TYPE_BIGINT);
12395+
#endif
1231812396
return res;
1231912397
}
1232012398

1232112399
SAVE_VECTOR_REGISTERS(return _svr_ret;);
1232212400

12323-
if ((res = mp_mod(a, n, &a1)) != MP_OKAY) {
12401+
if ((res = mp_mod(a, n, a1)) != MP_OKAY) {
1232412402
goto done;
1232512403
}
1232612404

12327-
if ((res = mp_copy(n, &n1)) != MP_OKAY) {
12405+
if ((res = mp_copy(n, n1)) != MP_OKAY) {
1232812406
goto done;
1232912407
}
1233012408

12331-
t[0] = &a1;
12332-
t[1] = &n1;
12409+
t[0] = a1;
12410+
t[1] = n1;
1233312411

1233412412
/* Keep reducing until first number is 0. */
1233512413
while (!mp_iszero(t[0])) {
@@ -12379,9 +12457,14 @@ int mp_jacobi(mp_int* a, mp_int* n, int* c)
1237912457

1238012458
RESTORE_VECTOR_REGISTERS();
1238112459

12382-
/* cleanup */
12383-
mp_clear(&n1);
12384-
mp_clear(&a1);
12460+
/* cleanup */
12461+
mp_clear(n1);
12462+
mp_clear(a1);
12463+
12464+
#ifdef WOLFSSL_SMALL_STACK
12465+
XFREE(a1, NULL, DYNAMIC_TYPE_BIGINT);
12466+
XFREE(n1, NULL, DYNAMIC_TYPE_BIGINT);
12467+
#endif
1238512468

1238612469
return res;
1238712470
}

0 commit comments

Comments
 (0)